Loading Dump File [C:\DUMPS\KTac\020711-18376-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) UP Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17514.x86fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0x82e02000 PsLoadedModuleList = 0x82f4c850
Debug session time: Mon Feb 7 19:11:32.456 2011 (UTC + 0:00)
System Uptime: 0 days 4:45:25.407
Loading Kernel Symbols
.
Press ctrl-c (cdb, kd, ntsd) or ctrl-break (windbg) to abort symbol loads that take too long.
Run !sym noisy before .reload to track down problems loading symbols.
..............................................................
................................................................
.........................
Loading User Symbols
Loading unloaded module list
.........
Unable to load image \SystemRoot\system32\DRIVERS\USA19H2k.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for USA19H2k.sys
*** ERROR: Module load completed but symbols could not be loaded for USA19H2k.sys
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1000007E, {c0000005, 8ee8c6e3, 807ed99c, 807ed580}
Probably caused by : USA19H2k.sys ( USA19H2k+46e3 )
Followup: MachineOwner
---------
kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: c0000005, The exception code that was not handled
Arg2: 8ee8c6e3, The address that the exception occurred at
Arg3: 807ed99c, Exception Record Address
Arg4: 807ed580, Context Record Address
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
USA19H2k+46e3
8ee8c6e3 8b5f08 mov ebx,dword ptr [edi+8]
EXCEPTION_RECORD: 807ed99c -- (.exr 0xffffffff807ed99c)
ExceptionAddress: 8ee8c6e3 (USA19H2k+0x000046e3)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 00000000
Parameter[1]: 00000008
Attempt to read from address 00000008
CONTEXT: 807ed580 -- (.cxr 0xffffffff807ed580)
eax=00000000 ebx=8eea8a17 ecx=8eea89d0 edx=b1898ed0 esi=8eea8a17 edi=00000000
eip=8ee8c6e3 esp=807eda64 ebp=807eda78 iopl=0 nv up ei ng nz na po nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010282
USA19H2k+0x46e3:
8ee8c6e3 8b5f08 mov ebx,dword ptr [edi+8] ds:0023:00000008=????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_PARAMETER1: 00000000
EXCEPTION_PARAMETER2: 00000008
READ_ADDRESS: GetPointerFromAddress: unable to read from 82f6c718
Unable to read MiSystemVaType memory at 82f4c1a0
00000008
FOLLOWUP_IP:
USA19H2k+46e3
8ee8c6e3 8b5f08 mov ebx,dword ptr [edi+8]
BUGCHECK_STR: 0x7E
DEFAULT_BUCKET_ID: NULL_CLASS_PTR_DEREFERENCE
LAST_CONTROL_TRANSFER: from 8ee8d1f7 to 8ee8c6e3
STACK_TEXT:
WARNING: Stack unwind information not available. Following frames may be wrong.
807eda78 8ee8d1f7 8eea8a17 8532c7b0 8532c7b0 USA19H2k+0x46e3
807edaa4 8ee8d336 8532c7b0 00000001 85a48e28 USA19H2k+0x51f7
807edabc 8ee8d7a5 8532c7b0 85a48e28 85a48f4c USA19H2k+0x5336
807edaf0 82e39593 8532c7b0 85a48e28 807edb8c USA19H2k+0x57a5
807edb08 82fdbf95 855e76a8 852d0140 855e76a8 nt!IofCallDriver+0x63
807edb38 830c8a3f 855e76a8 00000000 852d0140 nt!IopSynchronousCall+0xc2
807edb90 82ede346 855e76a8 00000002 b7c4ccb8 nt!IopRemoveDevice+0xd4
807edbbc 830c0787 0000000a b7c4ccb8 00000000 nt!PnpRemoveLockedDeviceNode+0x16c
807edbd0 830c0a3b 00000002 0000000a 00000000 nt!PnpDeleteLockedDeviceNode+0x2d
807edc04 830c4417 855e76a8 b7c4ccb8 00000002 nt!PnpDeleteLockedDeviceNodes+0x4c
807edcc4 82fb42ca 807edcf4 00000000 b08ef160 nt!PnpProcessQueryRemoveAndEject+0x946
807edcdc 82fc23ca 00000000 b189a0c0 84e40020 nt!PnpProcessTargetDeviceEvent+0x38
807edd00 82e7faab b189a0c0 00000000 84e40020 nt!PnpDeviceEventWorker+0x216
807edd50 8300bf5e 00000001 980f1095 00000000 nt!ExpWorkerThread+0x10d
807edd90 82eb3219 82e7f99e 00000001 00000000 nt!PspSystemThreadStartup+0x9e
00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x19
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: USA19H2k+46e3
FOLLOWUP_NAME: MachineOwner