*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1E, {ffffffffc0000005, fffff8000216af1c, 0, ffffffffffffffff}
Probably caused by : memory_corruption ( nt!MiApplyCompressedFixups+40 )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff8000216af1c, The address that the exception occurred at
Arg3: 0000000000000000, Parameter 0 of the exception
Arg4: ffffffffffffffff, Parameter 1 of the exception
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!MiApplyCompressedFixups+40
fffff800`0216af1c 0fb603 movzx eax,byte ptr [rbx]
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: ffffffffffffffff
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800020bd0e0
ffffffffffffffff
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
BUGCHECK_STR: 0x1E_c0000005
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: AAWService.exe
CURRENT_IRQL: 0
EXCEPTION_RECORD: fffff8800814f618 -- (.exr 0xfffff8800814f618)
ExceptionAddress: fffff8000216af1c (nt!MiApplyCompressedFixups+0x0000000000000040)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
TRAP_FRAME: fffff8800814f6c0 -- (.trap 0xfffff8800814f6c0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffff8a003eef000 rbx=0000000000000000 rcx=fffffa8005693230
rdx=fffff88007b4f000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8000216af1c rsp=fffff8800814f850 rbp=0000000000000003
r8=00fff8a003ef2738 r9=00000000723a0000 r10=0000000000000fff
r11=fffff88007b4f000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe nc
nt!MiApplyCompressedFixups+0x40:
fffff800`0216af1c 0fb603 movzx eax,byte ptr [rbx] ds:00000000`00000000=??
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80001ebfa39 to fffff80001e85740
STACK_TEXT:
fffff880`0814ee48 fffff800`01ebfa39 : 00000000`0000001e ffffffff`c0000005 fffff800`0216af1c 00000000`00000000 : nt!KeBugCheckEx
fffff880`0814ee50 fffff800`01e84d82 : fffff880`0814f618 00fff8a0`03ef2738 fffff880`0814f6c0 00000000`723a0000 : nt!KiDispatchException+0x1b9
fffff880`0814f4e0 fffff800`01e8368a : fffff880`0814f800 fffffa80`05603401 00000000`00000000 00001f80`01010000 : nt!KiExceptionDispatch+0xc2
fffff880`0814f6c0 fffff800`0216af1c : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiGeneralProtectionFault+0x10a
fffff880`0814f850 fffff800`0216ada1 : fffff880`07b4f000 00000000`723a0000 00000000`00070000 fffffa80`0238b360 : nt!MiApplyCompressedFixups+0x40
fffff880`0814f8a0 fffff800`02158034 : fffffa80`00000000 fffffa80`05380b60 00000000`00000000 fffffa80`00000000 : nt!MiPerformFixups+0x65
fffff880`0814f8f0 fffff800`01e76c4c : fffffa80`0238b360 fffffa80`056f7f50 00000000`00000000 fffffa80`05729c00 : nt!MiRelocateImagePfn+0x114
fffff880`0814f950 fffff800`01e7752b : fffffa80`056f7e90 fffff880`0814fa80 fffffa80`0535d3f8 fffffa80`0535d060 : nt!MiWaitForInPageComplete+0x89c
fffff880`0814fa30 fffff800`01ea08bb : 00000000`00000000 00000000`00000000 ffffffff`ffffffff fffff680`00000000 : nt!MiIssueHardFault+0x28b
fffff880`0814fac0 fffff800`01e8382e : 00000000`00000008 00000000`028dedbc fffffa80`05380b01 00000000`006d92a0 : nt!MmAccessFault+0x14bb
fffff880`0814fc20 00000000`7540f470 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x16e
00000000`028dd8bc 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7540f470
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!MiApplyCompressedFixups+40
fffff800`0216af1c 0fb603 movzx eax,byte ptr [rbx]
SYMBOL_STACK_INDEX: 4
SYMBOL_NAME: nt!MiApplyCompressedFixups+40
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 4cc791bd
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: X64_0x1E_c0000005_nt!MiApplyCompressedFixups+40
BUCKET_ID: X64_0x1E_c0000005_nt!MiApplyCompressedFixups+40
Followup: MachineOwner
---------
2: kd> lmtsmn
start end module name
fffff880`02a75000 fffff880`02ab3000 1394ohci 1394ohci.sys Tue Jul 14 12:07:12 2009 (4A5BCC30)
fffff880`00ea1000 fffff880`00ef8000 ACPI ACPI.sys Tue Jul 14 11:19:34 2009 (4A5BC106)
fffff880`00e4d000 fffff880`00e58000 amdxata amdxata.sys Wed May 20 05:56:59 2009 (4A12F2EB)
fffff880`00e1a000 fffff880`00e23000 atapi atapi.sys Tue Jul 14 11:19:47 2009 (4A5BC113)
fffff880`00e23000 fffff880`00e4d000 ataport ataport.SYS Tue Jul 14 11:19:52 2009 (4A5BC118)
fffff880`01809000 fffff880`01810000 Beep Beep.SYS Tue Jul 14 12:00:13 2009 (4A5BCA8D)
fffff880`0148b000 fffff880`014b5000 cdrom cdrom.sys Tue Jul 14 11:19:54 2009 (4A5BC11A)
fffff880`00d2e000 fffff880`00dee000 CI CI.dll Tue Jul 14 13:32:13 2009 (4A5BE01D)
fffff880`01997000 fffff880`019c7000 CLASSPNP CLASSPNP.SYS Tue Jul 14 11:19:58 2009 (4A5BC11E)
fffff880`00cd0000 fffff880`00d2e000 CLFS CLFS.SYS Tue Jul 14 11:19:57 2009 (4A5BC11D)
fffff880`01107000 fffff880`0117a000 cng cng.sys Tue Jul 14 11:49:40 2009 (4A5BC814)
fffff880`01981000 fffff880`01997000 disk disk.sys Tue Jul 14 11:19:57 2009 (4A5BC11D)
fffff880`02ab3000 fffff880`02ac0000 fdc fdc.sys Tue Jul 14 12:00:54 2009 (4A5BCAB6)
fffff880`01080000 fffff880`01094000 fileinfo fileinfo.sys Tue Jul 14 11:34:25 2009 (4A5BC481)
fffff880`01034000 fffff880`01080000 fltmgr fltmgr.sys Tue Jul 14 11:19:59 2009 (4A5BC11F)
fffff880`013d3000 fffff880`013dd000 Fs_Rec Fs_Rec.sys Tue Jul 14 11:19:45 2009 (4A5BC111)
fffff880`01947000 fffff880`01981000 fvevol fvevol.sys Sat Sep 26 14:34:26 2009 (4ABD7DB2)
fffff880`0117a000 fffff880`011c4000 fwpkclnt fwpkclnt.sys Tue Jul 14 11:21:08 2009 (4A5BC164)
fffff800`023f2000 fffff800`0243b000 hal hal.dll Tue Jul 14 13:27:36 2009 (4A5BDF08)
fffff880`01878000 fffff880`0189c000 HDAudBus HDAudBus.sys Tue Jul 14 12:06:13 2009 (4A5BCBF5)
fffff880`0193e000 fffff880`01947000 hwpolicy hwpolicy.sys Tue Jul 14 11:19:22 2009 (4A5BC0FA)
fffff880`02ac0000 fffff880`02ade000 i8042prt i8042prt.sys Tue Jul 14 11:19:57 2009 (4A5BC11D)
fffff800`00bb1000 fffff800`00bbb000 kdcom kdcom.dll Tue Jul 14 13:31:07 2009 (4A5BDFDB)
fffff880`013a8000 fffff880`013c2000 ksecdd ksecdd.sys Tue Jul 14 11:20:54 2009 (4A5BC156)
fffff880`01460000 fffff880`0148b000 ksecpkg ksecpkg.sys Fri Dec 11 19:03:32 2009 (4B21E0B4)
fffff880`01094000 fffff880`010a9000 Lbd Lbd.sys Tue May 25 19:45:36 2010 (4BFB8020)
fffff880`00caf000 fffff880`00cbc000 mcupdate_AuthenticAMD mcupdate_AuthenticAMD.dll Tue Jul 14 13:29:09 2009 (4A5BDF65)
fffff880`00e00000 fffff880`00e1a000 mountmgr mountmgr.sys Tue Jul 14 11:19:54 2009 (4A5BC11A)
fffff880`01853000 fffff880`0185e000 Msfs Msfs.SYS Tue Jul 14 11:19:47 2009 (4A5BC113)
fffff880`00f01000 fffff880`00f0b000 msisadrv msisadrv.sys Tue Jul 14 11:19:26 2009 (4A5BC0FE)
fffff880`010a9000 fffff880`01107000 msrpc msrpc.sys Tue Jul 14 11:21:32 2009 (4A5BC17C)
fffff880`0192c000 fffff880`0193e000 mup mup.sys Tue Jul 14 11:23:45 2009 (4A5BC201)
fffff880`014c8000 fffff880`015ba000 ndis ndis.sys Tue Jul 14 11:21:40 2009 (4A5BC184)
fffff880`01400000 fffff880`01460000 NETIO NETIO.SYS Tue Jul 14 11:21:46 2009 (4A5BC18A)
fffff880`0185e000 fffff880`0186f000 Npfs Npfs.SYS Tue Jul 14 11:19:48 2009 (4A5BC114)
fffff800`01e15000 fffff800`023f2000 nt ntkrnlmp.exe Wed Oct 27 15:43:09 2010 (4CC791BD)
fffff880`01205000 fffff880`013a8000 Ntfs Ntfs.sys Tue Jul 14 11:20:47 2009 (4A5BC14F)
fffff880`01800000 fffff880`01809000 Null Null.SYS Tue Jul 14 11:19:37 2009 (4A5BC109)
fffff880`00f4b000 fffff880`00f60000 partmgr partmgr.sys Tue Jul 14 11:19:58 2009 (4A5BC11E)
fffff880`00f0b000 fffff880`00f3e000 pci pci.sys Tue Jul 14 11:19:51 2009 (4A5BC117)
fffff880`00fd1000 fffff880`00fd8000 pciide pciide.sys Tue Jul 14 11:19:49 2009 (4A5BC115)
fffff880`00fd8000 fffff880`00fe8000 PCIIDEX PCIIDEX.SYS Tue Jul 14 11:19:48 2009 (4A5BC114)
fffff880`013c2000 fffff880`013d3000 pcw pcw.sys Tue Jul 14 11:19:27 2009 (4A5BC0FF)
fffff880`00cbc000 fffff880`00cd0000 PSHED PSHED.dll Tue Jul 14 13:32:23 2009 (4A5BE027)
fffff880`018f2000 fffff880`0192c000 rdyboost rdyboost.sys Tue Jul 14 11:34:34 2009 (4A5BC48A)
fffff880`01603000 fffff880`01800000 tcpip tcpip.sys Mon Jun 14 15:39:04 2010 (4C15A458)
00fff880`02ade000 00fff880`02aed000 Unknown_Module_00fff880_02ade000 Unknown_Module_00fff880`02ade000 unavailable (00000000)
fffff880`02a64000 fffff880`02a75000 usbehci usbehci.sys Tue Jul 14 12:06:30 2009 (4A5BCC06)
fffff880`014b5000 fffff880`014c0000 usbohci usbohci.sys Tue Jul 14 12:06:30 2009 (4A5BCC06)
fffff880`02a0e000 fffff880`02a64000 USBPORT USBPORT.SYS Tue Jul 14 12:06:31 2009 (4A5BCC07)
fffff880`00f3e000 fffff880`00f4b000 vdrvroot vdrvroot.sys Tue Jul 14 12:01:31 2009 (4A5BCADB)
fffff880`01810000 fffff880`0181e000 vga vga.sys Tue Jul 14 11:38:47 2009 (4A5BC587)
fffff880`0181e000 fffff880`01843000 VIDEOPRT VIDEOPRT.SYS Tue Jul 14 11:38:51 2009 (4A5BC58B)
fffff880`00f60000 fffff880`00f75000 volmgr volmgr.sys Tue Jul 14 11:19:57 2009 (4A5BC11D)
fffff880`00f75000 fffff880`00fd1000 volmgrx volmgrx.sys Tue Jul 14 11:20:33 2009 (4A5BC141)
fffff880`0189e000 fffff880`018ea000 volsnap volsnap.sys Tue Jul 14 11:20:08 2009 (4A5BC128)
fffff880`01843000 fffff880`01853000 watchdog watchdog.sys Tue Jul 14 11:37:35 2009 (4A5BC53F)
fffff880`00c00000 fffff880`00ca4000 Wdf01000 Wdf01000.sys Tue Jul 14 11:22:07 2009 (4A5BC19F)
fffff880`00dee000 fffff880`00dfd000 WDFLDR WDFLDR.SYS Tue Jul 14 11:19:54 2009 (4A5BC11A)
fffff880`0186f000 fffff880`01878000 wmiacpi wmiacpi.sys Tue Jul 14 11:31:02 2009 (4A5BC3B6)
fffff880`00ef8000 fffff880`00f01000 WMILIB WMILIB.SYS Tue Jul 14 11:19:51 2009 (4A5BC117)
Unloaded modules:
fffff880`019c7000 fffff880`019d5000 crashdmp.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0000E000
fffff880`019d5000 fffff880`019e1000 dump_ataport
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0000C000
fffff880`019e1000 fffff880`019ea000 dump_atapi.s
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 00009000
fffff880`019ea000 fffff880`019fd000 dump_dumpfve
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 00013000
fffff880`018ea000 fffff880`018f2000 spldr.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 00008000