Windows 7 Kernel Version 7600 MP (6 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16539.amd64fre.win7_gdr.100226-1909
Machine Name:
Kernel base = 0xfffff800`02c1a000 PsLoadedModuleList = 0xfffff800`02e57e50
Debug session time: Fri Aug 5 23:07:34.732 2011 (GMT-8)
System Uptime: 0 days 0:13:42.090
Loading Kernel Symbols
...............................................................
................................................................
.....................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1E, {ffffffffc0000005, fffff80002c7c464, 0, ffffffffffffffff}
Probably caused by : memory_corruption
Followup: memory_corruption
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff80002c7c464, The address that the exception occurred at
Arg3: 0000000000000000, Parameter 0 of the exception
Arg4: ffffffffffffffff, Parameter 1 of the exception
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!MiIssueHardFault+2c4
fffff800`02c7c464 48c1a8394184c70f shr qword ptr [rax-387BBEC7h],0Fh
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: ffffffffffffffff
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002ec20e0
ffffffffffffffff
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: CODE_CORRUPTION
BUGCHECK_STR: 0x1E
PROCESS_NAME: MsMpEng.exe
CURRENT_IRQL: 0
EXCEPTION_RECORD: fffff880084657f8 -- (.exr 0xfffff880084657f8)
ExceptionAddress: fffff80002c7c464 (nt!MiIssueHardFault+0x00000000000002c4)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
TRAP_FRAME: fffff880084658a0 -- (.trap 0xfffff880084658a0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=02000000001b257a rbx=0000000000000000 rcx=fffffa8009399bb0
rdx=fffffa8006dbfe91 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002c7c464 rsp=fffff88008465a30 rbp=fffff88008465a60
r8=fffffa8006dbfe90 r9=0000000000000000 r10=fffff80002e0df60
r11=fffffa8006e191f0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
nt!MiIssueHardFault+0x2c4:
fffff800`02c7c464 48c1a8394184c70f shr qword ptr [rax-387BBEC7h],0Fh ds:06e0:01ffffff`c79f66b3=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002cc4929 to fffff80002c8a600
STACK_TEXT:
fffff880`08465028 fffff800`02cc4929 : 00000000`0000001e ffffffff`c0000005 fffff800`02c7c464 00000000`00000000 : nt!KeBugCheckEx
fffff880`08465030 fffff800`02c89c42 : fffff880`084657f8 00000000`00000000 fffff880`084658a0 fffffa80`09399b60 : nt!KiDispatchException+0x1b9
fffff880`084656c0 fffff800`02c8854a : fffff880`08465900 fffff880`010f623f fffffa80`07431fb0 fffffa80`07431c10 : nt!KiExceptionDispatch+0xc2
fffff880`084658a0 fffff800`02c7c464 : fffffa80`06e191f0 fffff880`08465a80 fffffa80`07a10ec8 fffffa80`09399b00 : nt!KiGeneralProtectionFault+0x10a
fffff880`08465a30 fffff800`02ca579b : 00000000`00000000 00000000`00000000 ffffffff`ffffffff fffff800`00000000 : nt!MiIssueHardFault+0x2c4
fffff880`08465ac0 fffff800`02c886ee : 00000000`00000000 00000000`74ec2828 00000000`00000001 fffffa80`09709880 : nt!MmAccessFault+0x14bb
fffff880`08465c20 000007fe`ff41117a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x16e
00000000`03d5e438 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7fe`ff41117a
STACK_COMMAND: kb
CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
fffff80002c7c466 - nt!MiIssueHardFault+2c6
[ e8:a8 ]
1 error : !nt (fffff80002c7c466)
MODULE_NAME: memory_corruption
IMAGE_NAME: memory_corruption
FOLLOWUP_NAME: memory_corruption
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MEMORY_CORRUPTOR: ONE_BIT
FAILURE_BUCKET_ID: X64_MEMORY_CORRUPTION_ONE_BIT
BUCKET_ID: X64_MEMORY_CORRUPTION_ONE_BIT
Followup: memory_corruption
---------