Windows 7 Kernel Version 7600 MP (8 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16385.x86fre.win7_rtm.090713-1255
Machine Name:
Kernel base = 0x8341e000 PsLoadedModuleList = 0x83566810
Debug session time: Wed Sep 7 07:38:09.714 2011 (UTC - 6:00)
System Uptime: 0 days 0:00:13.776
Loading Kernel Symbols
...............................................................
.......................
Loading User Symbols
Loading unloaded module list
.
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1000007E, {c0000005, 83640441, 8cc4f648, 8cc4f220}
[COLOR=Red]Probably caused by : ntkrpamp.exe[/COLOR] ( nt!RtlEqualUnicodeString+2f )
Followup: MachineOwner
---------
6: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: c0000005, The exception code that was not handled
Arg2: 83640441, The address that the exception occurred at
Arg3: 8cc4f648, Exception Record Address
Arg4: 8cc4f220, Context Record Address
Debugging Details:
------------------
OVERLAPPED_MODULE: Address regions for 'Msfs' and 'cdrom.sys' overlap
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!RtlEqualUnicodeString+2f
83640441 3b37 cmp esi,dword ptr [edi]
EXCEPTION_RECORD: 8cc4f648 -- (.exr 0xffffffff8cc4f648)
ExceptionAddress: 83640441 (nt!RtlEqualUnicodeString+0x0000002f)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 00000000
Parameter[1]: 0000ed40
Attempt to read from address 0000ed40
CONTEXT: 8cc4f220 -- (.cxr 0xffffffff8cc4f220)
eax=0000000e ebx=8b9d7a3e ecx=8b9d7a30 edx=00000004 esi=00540041 edi=0000ed40
eip=83640441 esp=8cc4f710 ebp=8cc4f71c iopl=0 nv up ei pl nz na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00210206
nt!RtlEqualUnicodeString+0x2f:
83640441 3b37 cmp esi,dword ptr [edi] ds:0023:0000ed40=????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_PARAMETER1: 00000000
EXCEPTION_PARAMETER2: 0000ed40
READ_ADDRESS: GetPointerFromAddress: unable to read from 83586718
Unable to read MiSystemVaType memory at 83566160
0000ed40
FOLLOWUP_IP:
nt!RtlEqualUnicodeString+2f
83640441 3b37 cmp esi,dword ptr [edi]
BUGCHECK_STR: 0x7E
LOCK_ADDRESS: 83583f60 -- (!locks 83583f60)
Resource @ nt!PiEngineLock (0x83583f60) Available
WARNING: SystemResourcesList->Flink chain invalid. Resource may be corrupted, or already deleted.
WARNING: SystemResourcesList->Blink chain invalid. Resource may be corrupted, or already deleted.
1 total locks
PNP_TRIAGE:
Lock address : 0x83583f60
Thread Count : 0
Thread address: 0x00000000
Thread wait : 0x0
LAST_CONTROL_TRANSFER: from 8364029d to 83640441
STACK_TEXT:
8cc4f71c 8364029d 0000ed40 8b9d7a3e 00000201 nt!RtlEqualUnicodeString+0x2f
8cc4f744 836400e4 0186ebf0 8cc4f790 00000201 nt!ObpLookupDirectoryUsingHash+0xa0
8cc4f768 8363f04e 8b86ebf0 8cc4f790 00000201 nt!ObpLookupDirectoryEntry+0x80
8cc4f7cc 8366524d 00000000 8cc4f820 00000240 nt!ObpLookupObjectName+0x371
8cc4f82c 835c9401 8cc4f858 85a5deb0 00000000 nt!ObOpenObjectByName+0x159
8cc4f878 835c8e06 8ebb148c 00000010 8cc4fa38 nt!IopReferenceDriverObjectByName+0x46
8cc4f918 8360de4e 8ebb14a0 00000001 8ebb148c nt!PipCallDriverAddDeviceQueryRoutine+0x16a
8cc4f950 836160a2 00000001 8cc4fa1c c0000034 nt!RtlpCallQueryRegistryRoutine+0x2cd
8cc4f9bc 835c6108 40000000 80000198 8cc4fa38 nt!RtlQueryRegistryValues+0x31d
8cc4fa98 835c5876 85a892a8 8cc4fcc8 00000000 nt!PipCallDriverAddDevice+0x383
8cc4fc94 835a9a2a 85a95518 86c39de8 8cc4fcc8 nt!PipProcessDevNodeTree+0x15d
8cc4fcd4 83431f99 86c39de8 83581e80 85a61d48 nt!PiProcessStartSystemDevices+0x6d
8cc4fd00 8348bf2b 00000000 00000000 85a61d48 nt!PnpDeviceActionWorker+0x241
8cc4fd50 8362c66d 00000001 afe2a5bf 00000000 nt!ExpWorkerThread+0x10d
8cc4fd90 834de0d9 8348be1e 00000001 00000000 nt!PspSystemThreadStartup+0x9e
00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x19
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!RtlEqualUnicodeString+2f
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrpamp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc007
STACK_COMMAND: .cxr 0xffffffff8cc4f220 ; kb
FAILURE_BUCKET_ID: 0x7E_nt!RtlEqualUnicodeString+2f
BUCKET_ID: 0x7E_nt!RtlEqualUnicodeString+2f
Followup: MachineOwner
---------