PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: ffff0050, memory referenced.
Arg2: 00000000, value 0 = read operation, 1 = write operation.
Arg3: 8b83c4d3, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 00000000, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
READ_ADDRESS: GetPointerFromAddress: unable to read from 82f6d718
Unable to read MiSystemVaType memory at 82f4d160
ffff0050
FAULTING_IP:
Ntfs!NtfsSnapshotScbInternal+194
8b83c4d3 394f50 cmp dword ptr [edi+50h],ecx
MM_INTERNAL_CODE: 0
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 0
TRAP_FRAME: b17278a0 -- (.trap 0xffffffffb17278a0)
ErrCode = 00000000
eax=8586d6a0 ebx=00000727 ecx=8586d6a0 edx=b6172c88 esi=b6172d78 edi=ffff0000
eip=8b83c4d3 esp=b1727914 ebp=b1727920 iopl=0 nv up ei ng nz na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010286
Ntfs!NtfsSnapshotScbInternal+0x194:
8b83c4d3 394f50 cmp dword ptr [edi+50h],ecx ds:0023:ffff0050=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from 82e4b638 to 82e8a903
STACK_TEXT:
b1727888 82e4b638 00000000 ffff0050 00000000 nt!MmAccessFault+0x106
b1727888 8b83c4d3 00000000 ffff0050 00000000 nt!KiTrap0E+0xdc
b1727920 8b83c7a2 8586d6a0 b6172d78 00000000 Ntfs!NtfsSnapshotScbInternal+0x194
b1727934 8b8bba18 8586d6a0 b6172d78 3af492b7 Ntfs!NtfsSnapshotScb+0x12
b172799c 8b8d73de 8586d6a0 b6172c88 00000080 Ntfs!NtfsCreateScb+0x110
b17279d4 8b8c9eeb 8586d6a0 85e6be00 85e6bfb4 Ntfs!NtfsBreakBatchOplock+0x7e
b1727a0c 8b8c1217 8586d6a0 85e6be00 b6172f20 Ntfs!NtfsOpenExistingAttr+0xa9
b1727af4 8b8c1677 8586d6a0 85e6be00 b6172f20 Ntfs!NtfsOpenAttributeInExistingFile+0x7a4
b1727ba0 8b8c0a2d 8586d6a0 85e6be00 b6172f20 Ntfs!NtfsOpenExistingPrefixFcb+0x26e
b1727c00 8b8c2c5c 8586d6a0 85e6be00 8c7ced08 Ntfs!NtfsFindStartingNode+0xb88
b1727cdc 8b849210 8586d6a0 85e6be00 9ed99344 Ntfs!NtfsCommonCreate+0x65f
b1727d1c 82e7511e 9ed992dc 00000000 ffffffff Ntfs!NtfsCommonCreateCallout+0x20
b1727d1c 82e75215 9ed992dc 00000000 ffffffff nt!KiSwapKernelStackAndExit+0x15a
9ed99240 00000000 00000000 00000000 00000000 nt!KiSwitchKernelStackAndCallout+0x31
STACK_COMMAND: kb
FOLLOWUP_IP:
Ntfs!NtfsSnapshotScbInternal+194
8b83c4d3 394f50 cmp dword ptr [edi+50h],ecx
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: Ntfs!NtfsSnapshotScbInternal+194
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Ntfs
IMAGE_NAME: Ntfs.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bbf45
FAILURE_BUCKET_ID: 0x50_Ntfs!NtfsSnapshotScbInternal+194
BUCKET_ID: 0x50_Ntfs!NtfsSnapshotScbInternal+194
Followup: MachineOwner
---------
3: kd> lmvm Ntfs
start end module name
8b830000 8b95f000 Ntfs (pdb symbols) c:\symcache\ntfs.pdb\513BBB60430D411DBE02DF92418A2B272\ntfs.pdb
Loaded symbol image file: Ntfs.sys
Mapped memory image file: C:\SymCache\Ntfs.sys\4A5BBF4512f000\Ntfs.sys
Image path: \SystemRoot\System32\Drivers\Ntfs.sys
Image name: Ntfs.sys
Timestamp: Tue Jul 14 04:42:05 2009 (4A5BBF45)
CheckSum: 00127FFB
ImageSize: 0012F000
File version: 6.1.7600.16385
Product version: 6.1.7600.16385
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: ntfs.sys
OriginalFilename: ntfs.sys
ProductVersion: 6.1.7600.16385
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
FileDescription: NT File System Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.