[list=1]
[*]
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [D:\Kingston\BSODDmpFiles\halomademeapc\Windows_NT6_BSOD_jcgriff2\030312-46332-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (6 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16841.amd64fre.win7_gdr.110622-1503
Machine Name:
Kernel base = 0xfffff800`03001000 PsLoadedModuleList = 0xfffff800`0323ee70
Debug session time: Sat Mar 3 17:44:20.582 2012 (UTC - 7:00)
System Uptime: 0 days 0:03:44.564
Loading Kernel Symbols
...............................................................
................................................................
................................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1A, {41790, fffffa80054ee5c0, ffff, 0}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+338c6 )
Followup: MachineOwner
---------
5: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041790, The subtype of the bugcheck.
Arg2: fffffa80054ee5c0
Arg3: 000000000000ffff
Arg4: 0000000000000000
Debugging Details:
------------------
BUGCHECK_STR: 0x1a_41790
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: Steam.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff800030e4efe to fffff800030715c0
STACK_TEXT:
fffff880`084fb8c8 fffff800`030e4efe : 00000000`0000001a 00000000`00041790 fffffa80`054ee5c0 00000000`0000ffff : nt!KeBugCheckEx
fffff880`084fb8d0 fffff800`03044ba7 : ffffffff`00000000 00000000`0327ffff fffffa80`00000000 fffffa80`0a71ab60 : nt! ?? ::FNODOBFM::`string'+0x338c6
fffff880`084fba90 fffff800`03353a8b : fffff8a0`026a8060 00000000`00000001 00000000`00000000 fffffa80`0a71ab60 : nt!MmCleanProcessAddressSpace+0x62f
fffff880`084fbae0 fffff800`0332b35b : 00000000`00000000 00000000`00000001 00000000`7efdb000 00000000`00000000 : nt!PspExitThread+0x92f
fffff880`084fbba0 fffff800`03070813 : fffffa80`0a642b30 fffff880`00000000 00000000`7efdb000 fffffa80`0a71ab60 : nt!NtTerminateProcess+0x25b
fffff880`084fbc20 00000000`76fef97a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0008e308 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x76fef97a
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+338c6
fffff800`030e4efe cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+338c6
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4e02aa44
FAILURE_BUCKET_ID: X64_0x1a_41790_nt!_??_::FNODOBFM::_string_+338c6
BUCKET_ID: X64_0x1a_41790_nt!_??_::FNODOBFM::_string_+338c6
Followup: MachineOwner
---------
[*]
Loading Dump File [D:\Kingston\BSODDmpFiles\halomademeapc\Windows_NT6_BSOD_jcgriff2\030312-33134-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (6 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16841.amd64fre.win7_gdr.110622-1503
Machine Name:
Kernel base = 0xfffff800`0300e000 PsLoadedModuleList = 0xfffff800`0324be70
Debug session time: Sat Mar 3 17:39:42.529 2012 (UTC - 7:00)
System Uptime: 0 days 1:19:27.871
Loading Kernel Symbols
...............................................................
................................................................
..................................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {fffff8a0052256f0, 0, fffff88001260260, 0}
Could not read faulting driver name
Probably caused by : Ntfs.sys ( Ntfs!memmove+250 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: fffff8a0052256f0, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff88001260260, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000000, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800032b60e0
fffff8a0052256f0
FAULTING_IP:
Ntfs!memmove+250
fffff880`01260260 488b440af8 mov rax,qword ptr [rdx+rcx-8]
MM_INTERNAL_CODE: 0
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 0
TRAP_FRAME: fffff88008ba9cf0 -- (.trap 0xfffff88008ba9cf0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000048 rbx=0000000000000000 rcx=fffff9801fa96000
rdx=ffffff1fe578f6f8 rsi=0000000000000000 rdi=0000000000000000
rip=fffff88001260260 rsp=fffff88008ba9e88 rbp=fffff88008baa140
r8=0000000000000048 r9=0000000000000002 r10=fffff8a0052256b0
r11=fffff9801fa95fb8 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na pe cy
Ntfs!memmove+0x250:
fffff880`01260260 488b440af8 mov rax,qword ptr [rdx+rcx-8] ds:fffff8a0`052256f0=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff800030fedf4 to fffff8000307e5c0
STACK_TEXT:
fffff880`08ba9b88 fffff800`030fedf4 : 00000000`00000050 fffff8a0`052256f0 00000000`00000000 fffff880`08ba9cf0 : nt!KeBugCheckEx
fffff880`08ba9b90 fffff800`0307c6ae : 00000000`00000000 00000000`d06f2bec 00000000`00000000 fffff8a0`00228670 : nt! ?? ::FNODOBFM::`string'+0x426f7
fffff880`08ba9cf0 fffff880`01260260 : fffff880`01306124 00000000`00000000 fffff880`08baa130 00000000`00001028 : nt!KiPageFault+0x16e
fffff880`08ba9e88 fffff880`01306124 : 00000000`00000000 fffff880`08baa130 00000000`00001028 00000000`00000000 : Ntfs!memmove+0x250
fffff880`08ba9e90 fffff880`0130e5a5 : fffff8a0`00000048 fffff8a0`0021a700 fffff880`08baa900 fffff980`00000fb8 : Ntfs!LfsWriteLogRecordIntoLogPage+0x5e4
fffff880`08ba9f30 fffff880`01308b26 : fffff8a0`03661a90 fffffa80`00000002 00000000`d06f29d9 fffff880`08baa180 : Ntfs!LfsWrite+0x145
fffff880`08ba9ff0 fffff880`013188e9 : fffff880`08baa770 fffffa80`07cbeac0 00000000`042dd000 fffff8a0`001bf140 : Ntfs!NtfsWriteLog+0x466
fffff880`08baa240 fffff880`0131a250 : fffff880`08baa770 fffff880`08baa701 00000000`46706000 00000000`01bd8000 : Ntfs!NtOfsPutData+0x229
fffff880`08baa370 fffff880`01319d37 : fffff880`08baa770 01ccf752`dc126a00 fffff880`08baa770 00000000`00000000 : Ntfs!NtfsWriteFcbUsnRecordToJournal+0xa8
fffff880`08baa430 fffff880`01306b32 : 00000000`00000001 fffff8a0`0364e680 fffff8a0`001bf140 fffff8a0`03661a90 : Ntfs!NtfsWriteUsnJournalChanges+0x187
fffff880`08baa4b0 fffff880`012cbdc2 : 00000000`00000000 00000000`00000000 fffff880`08baa770 fffff880`08baa770 : Ntfs!NtfsCheckpointCurrentTransaction+0x72
fffff880`08baa4e0 fffff880`012cb980 : fffff880`08baa770 fffff8a0`03661e10 fffff8a0`03661a90 fffff8a0`03661e00 : Ntfs!NtfsModifySecurity+0x292
fffff880`08baa620 fffff880`012e6a69 : fffff880`08baa770 fffffa80`0f36cc10 fffff8a0`03661a90 fffffa80`08060180 : Ntfs!NtfsCommonSetSecurityInfo+0x150
fffff880`08baa6d0 fffff880`012e6fe1 : fffff880`08baa770 fffffa80`0f36cc10 fffffa80`0f36cc10 00000000`00000000 : Ntfs!NtfsFsdDispatchSwitch+0x169
fffff880`08baa750 fffff880`0101f23f : fffff880`08baa9f0 fffff880`0101ebe9 fffff880`08baa900 fffff880`0101f215 : Ntfs!NtfsFsdDispatch+0x2d
fffff880`08baa940 fffff880`0101d6df : fffffa80`07c89950 00000000`00000000 fffffa80`07c89900 fffffa80`0f36cc10 : fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x24f
fffff880`08baa9d0 fffff800`033620e4 : fffffa80`0d6a39c0 00000000`00000000 00000000`00000000 fffffa80`0f36cc10 : fltmgr!FltpDispatch+0xcf
fffff880`08baaa30 fffff800`0331941a : 00000000`00000000 00000000`03841e94 fffff880`08baab58 fffff8a0`215c0200 : nt!IopGetSetSecurityObject+0x174
fffff880`08baaaf0 fffff800`033197a8 : fffffa80`06e90000 00000000`00000004 00000000`00000001 fffffa80`0a880f01 : nt!ObSetSecurityObjectByPointer+0x5a
fffff880`08baab50 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!NtSetSecurityObject+0x108
STACK_COMMAND: kb
FOLLOWUP_IP:
Ntfs!memmove+250
fffff880`01260260 488b440af8 mov rax,qword ptr [rdx+rcx-8]
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: Ntfs!memmove+250
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Ntfs
IMAGE_NAME: Ntfs.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4d79996d
FAILURE_BUCKET_ID: X64_0x50_Ntfs!memmove+250
BUCKET_ID: X64_0x50_Ntfs!memmove+250
Followup: MachineOwner
---------
[/list]