Microsoft (R) Windows Debugger Version 6.11.0001.404 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\richc46\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5\VNFSFQ1J\071010-14617-01[1]\071010-14617-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16539.amd64fre.win7_gdr.100226-1909
Machine Name:
Kernel base = 0xfffff800`02c4d000 PsLoadedModuleList = 0xfffff800`02e8ae50
Debug session time: Fri Jul 9 19:30:59.951 2010 (GMT-4)
System Uptime: 0 days 3:31:19.636
Loading Kernel Symbols
...............................................................
................................................................
........................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1000007E, {ffffffffc0000005, fffff88000e6d141, fffff88003124628, fffff88003123e90}
[B]Probably caused by : fltmgr.sys[/B] ( fltmgr!TreeUnlinkMulti+51 )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff88000e6d141, The address that the exception occurred at
Arg3: fffff88003124628, Exception Record Address
Arg4: fffff88003123e90, Context Record Address
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
fltmgr!TreeUnlinkMulti+51
fffff880`00e6d141 488b4620 mov rax,qword ptr [rsi+20h]
EXCEPTION_RECORD: fffff88003124628 -- (.exr 0xfffff88003124628)
ExceptionAddress: fffff88000e6d141 (fltmgr!TreeUnlinkMulti+0x0000000000000051)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
CONTEXT: fffff88003123e90 -- (.cxr 0xfffff88003123e90)
rax=fffffa80039ec040 rbx=0000000000000000 rcx=fffffa8003ecc6a8
rdx=fffffa8003ed0a00 rsi=3c00000000000000 rdi=0000000000000000
rip=fffff88000e6d141 rsp=fffff88003124860 rbp=fffffa8003ecc6a8
r8=ffffffffffffffff r9=ffffffffffffffff r10=0000000000002af0
r11=0000000000000001 r12=fffffa8003ed0a00 r13=0000000000000000
r14=0000000000002000 r15=fffffa8004a6e6a0
iopl=0 nv up ei pl nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010206
fltmgr!TreeUnlinkMulti+0x51:
fffff880`00e6d141 488b4620 mov rax,qword ptr [rsi+20h] ds:002b:3c000000`00000020=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: ffffffffffffffff
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002ef50e0
ffffffffffffffff
FOLLOWUP_IP:
fltmgr!TreeUnlinkMulti+51
fffff880`00e6d141 488b4620 mov rax,qword ptr [rsi+20h]
BUGCHECK_STR: 0x7E
LAST_CONTROL_TRANSFER: from fffff88000e6a31e to fffff88000e6d141
STACK_TEXT:
fffff880`03124860 fffff880`00e6a31e : fffffa80`05f98cb0 fffffa80`03ed0a00 fffffa80`05f98cb0 fffffa80`05f98cb0 : fltmgr!TreeUnlinkMulti+0x51
fffff880`031248b0 fffff880`00e6abe9 : fffff880`03122000 fffff800`02e41102 fffff800`02e41000 fffff800`02cc0c00 : fltmgr!FltpPerformPreCallbacks+0x5ee
fffff880`031249b0 fffff880`00e696c7 : fffffa80`04297ac0 fffffa80`04a62760 fffffa80`04848940 00000000`00000000 : fltmgr!FltpPassThrough+0x2d9
fffff880`03124a30 fffff800`02fd472e : fffffa80`03ed0a00 fffffa80`049b2510 fffff8a0`076e18f0 fffffa80`04a62760 : fltmgr!FltpDispatch+0xb7
fffff880`03124a90 fffff800`02cc27b4 : 00000000`00000000 00000000`00000000 fffffa80`039dd8a0 00000000`00000000 : nt!IopDeleteFile+0x11e
fffff880`03124b20 fffff800`02faf229 : 00000000`00000000 00000000`0008c081 fffffa80`03ed2b10 fffffa80`0008c081 : nt!ObfDereferenceObject+0xd4
fffff880`03124b80 fffff800`02de4fcb : fffffa80`03ed2b18 00000000`00000001 00000000`00000000 f7ffffff`00000631 : nt!MiSegmentDelete+0xa1
fffff880`03124bc0 fffff800`02de563d : 00000000`00000000 00000000`00000080 fffffa80`039cd040 00000000`00000012 : nt!MiProcessDereferenceList+0x23b
fffff880`03124c80 fffff800`02f62a86 : fcffffff`ffffffff 00000014`00000000 ffffffef`ffffffff 00000000`00004000 : nt!MiDereferenceSegmentThread+0x10d
fffff880`03124d00 fffff800`02c9bb06 : fffff800`02e37e80 fffffa80`039ec040 fffff800`02e45c40 ffffffff`ffdfffbf : nt!PspSystemThreadStartup+0x5a
fffff880`03124d40 00000000`00000000 : fffff880`03125000 fffff880`0311f000 fffff880`031247c0 00000000`00000000 : nt!KxStartSystemThread+0x16
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: fltmgr!TreeUnlinkMulti+51
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: fltmgr
IMAGE_NAME: fltmgr.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc11f
STACK_COMMAND: .cxr 0xfffff88003123e90 ; kb
FAILURE_BUCKET_ID: X64_0x7E_fltmgr!TreeUnlinkMulti+51
BUCKET_ID: X64_0x7E_fltmgr!TreeUnlinkMulti+51
Followup: MachineOwner