Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\Owner\Downloads\A-Rar\minidump\073010-16520-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\symbols*[URL="http://msdl.microsoft.com/download/symbols"]Symbol information[/URL]
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16385.x86fre.win7_rtm.090713-1255
Machine Name:
Kernel base = 0x83003000 PsLoadedModuleList = 0x8314b810
Debug session time: Fri Jul 30 13:03:01.609 2010 (GMT-4)
System Uptime: 0 days 21:51:55.341
Loading Kernel Symbols
...............................................................
................................................................
........................
Loading User Symbols
Loading unloaded module list
..........
0: kd> !Analyze
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1A, {3452, 7717a000, c0802e30, 767f0024}
*** WARNING: Unable to verify timestamp for mfehidk.sys
*** ERROR: Module load completed but symbols could not be loaded for mfehidk.sys
Probably caused by : mfehidk.sys ( mfehidk+2dc8c )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 00003452, The subtype of the bugcheck.
Arg2: 7717a000
Arg3: c0802e30
Arg4: 767f0024
Debugging Details:
------------------
BUGCHECK_STR: 0x1a_3452
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: IDMan.exe
CURRENT_IRQL: 0
EXCEPTION_RECORD: aae23ce0 -- (.exr 0xffffffffaae23ce0)
ExceptionAddress: 77166451
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 00000001
Parameter[1]: 02410ffc
Attempt to write to address 02410ffc
LAST_CONTROL_TRANSFER: from 830a8098 to 830a35ac
STACK_TEXT:
aae23744 830a8098 8531e8b8 8531e8b8 8777d184 nt!MiDeleteAddressesInWorkingSet+0x389
aae23774 8324bd22 8cd4fe85 00000000 854bccc0 nt!MmCleanProcessAddressSpace+0x8c
aae237e8 83264d37 8777d184 8531e8b8 aae238c0 nt!PspExitThread+0x683
aae23810 88f40c8c ffffffff c0000005 aae23840 nt!NtTerminateProcess+0x1fa
WARNING: Stack unwind information not available. Following frames may be wrong.
aae23830 8304642a ffffffff c0000005 aae23cc4 mfehidk+0x2dc8c
aae23830 8304568d ffffffff c0000005 aae23cc4 nt!KiFastCallEntry+0x12a
aae238b0 830c065f ffffffff c0000005 0001003f nt!ZwTerminateProcess+0x11
aae23cc4 83047016 aae23ce0 00000000 aae23d34 nt!KiDispatchException+0x497
aae23d2c 83046fca 02411354 77166451 badb0d00 nt!CommonDispatchException+0x4a
aae23d34 77166451 badb0d00 0241139c 00000000 nt!Kei386EoiHelper+0x192
aae23d38 badb0d00 0241139c 00000000 00000000 0x77166451
aae23d3c 0241139c 00000000 00000000 00000000 0xbadb0d00
aae23d40 00000000 00000000 00000000 00000000 0x241139c
STACK_COMMAND: kb
FOLLOWUP_IP:
mfehidk+2dc8c
88f40c8c ?? ???
SYMBOL_STACK_INDEX: 4
SYMBOL_NAME: mfehidk+2dc8c
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: mfehidk
IMAGE_NAME: mfehidk.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4bd1d9e2
FAILURE_BUCKET_ID: 0x1a_3452_mfehidk+2dc8c
BUCKET_ID: 0x1a_3452_mfehidk+2dc8c
Followup: MachineOwner
---------
Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\Owner\Downloads\A-Rar\minidump\080210-13057-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\symbols*[URL="http://msdl.microsoft.com/download/symbols"]Symbol information[/URL]
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16385.x86fre.win7_rtm.090713-1255
Machine Name:
Kernel base = 0x83001000 PsLoadedModuleList = 0x83149810
Debug session time: Mon Aug 2 13:08:14.760 2010 (GMT-4)
System Uptime: 0 days 0:05:57.367
Loading Kernel Symbols
...............................................................
................................................................
.....................
Loading User Symbols
Loading unloaded module list
......
0: kd> !Analyze
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1A, {41287, 18, 0, 0}
Probably caused by : ntkrpamp.exe ( nt!KiTrap0E+dc )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 00041287, The subtype of the bugcheck.
Arg2: 00000018
Arg3: 00000000
Arg4: 00000000
Debugging Details:
------------------
BUGCHECK_STR: 0x1a_41287
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: mchost.exe
CURRENT_IRQL: 0
TRAP_FRAME: ada8a948 -- (.trap 0xffffffffada8a948)
ErrCode = 00000000
eax=75b7a7c1 ebx=00000001 ecx=00000000 edx=00000001 esi=75b7a7c0 edi=ada8a9e8
eip=8303f904 esp=ada8a9bc ebp=ada8a9c4 iopl=0 nv up ei ng nz ac po cy
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010293
nt!memcpy+0x164:
8303f904 8a06 mov al,byte ptr [esi] ds:0023:75b7a7c0=??
Resetting default scope
LAST_CONTROL_TRANSFER: from 830475f8 to 830868e3
STACK_TEXT:
ada8a724 830475f8 00000000 00000018 00000000 nt!MmAccessFault+0x106
ada8a724 830ce825 00000000 00000018 00000000 nt!KiTrap0E+0xdc
ada8a828 8309198d 75b7a7c0 c03adbd0 85128780 nt!MiResolvePageFileFault+0xa8a
ada8a8a8 83088db5 75b7a7c0 00000000 85128780 nt!MiDispatchFault+0x66d
ada8a930 830475f8 00000000 75b7a7c0 00000000 nt!MmAccessFault+0x25cc
ada8a930 8303f904 00000000 75b7a7c0 00000000 nt!KiTrap0E+0xdc
ada8a9c4 832827ce ada8a9e8 75b7a7c0 00000001 nt!memcpy+0x164
ada8acbc 83284c4e 85128590 75b7a7c0 873c6030 nt!MmCopyVirtualMemory+0x1ad
ada8ad18 8304442a 00000158 75b7a7c0 0012d97f nt!NtReadVirtualMemory+0xd5
ada8ad18 774f64f4 00000158 75b7a7c0 0012d97f nt!KiFastCallEntry+0x12a
WARNING: Frame IP not in any known module. Following frames may be wrong.
0012d938 00000000 00000000 00000000 00000000 0x774f64f4
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!KiTrap0E+dc
830475f8 85c0 test eax,eax
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!KiTrap0E+dc
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrpamp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc007
FAILURE_BUCKET_ID: 0x1a_41287_nt!KiTrap0E+dc
BUCKET_ID: 0x1a_41287_nt!KiTrap0E+dc
Followup: MachineOwner
---------