Windows 7 Kernel Version 7600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`02e0d000 PsLoadedModuleList = 0xfffff800`0304ae50
Debug session time: Sun Nov 14 04:58:35.120 2010 (GMT-5)
System Uptime: 0 days 0:00:34.432
Loading Kernel Symbols
...............................................................
................................................................
.........................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck D1, {46, 2, 0, fffff8800167b26d}
*** WARNING: Unable to verify timestamp for win32k.sys
*** ERROR: Module load completed but symbols could not be loaded for win32k.sys
Probably caused by : memory_corruption
Followup: memory_corruption
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: 0000000000000046, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, value 0 = read operation, 1 = write operation
Arg4: fffff8800167b26d, address which referenced memory
Debugging Details:
------------------
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800030b50e0
0000000000000046
CURRENT_IRQL: 2
FAULTING_IP:
tcpip!TcpPreValidatedReceive+2d
fffff880`0167b26d 8b4844 mov ecx,dword ptr [rax+44h]
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: CODE_CORRUPTION
BUGCHECK_STR: 0xD1
PROCESS_NAME: System
TRAP_FRAME: fffff88002fa17f0 -- (.trap 0xfffff88002fa17f0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000002 rbx=0000000000000000 rcx=0000000000000000
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8800167b26d rsp=fffff88002fa1980 rbp=fffffa80045188d0
r8=0000000000000001 r9=0000000000000000 r10=fffffa80060f35e8
r11=fffff88002fa1a10 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
tcpip!TcpPreValidatedReceive+0x2d:
fffff880`0167b26d 8b4844 mov ecx,dword ptr [rax+44h] ds:009a:00000000`00000046=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002e7cca9 to fffff80002e7d740
STACK_TEXT:
fffff880`02fa16a8 fffff800`02e7cca9 : 00000000`0000000a 00000000`00000046 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
fffff880`02fa16b0 fffff800`02e7b920 : fffffa80`063f8240 00000000`00000001 fffffa80`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
fffff880`02fa17f0 fffff880`0167b26d : fffffa80`04509840 fffffa80`05b08080 fffffa80`05b08080 fffff880`0165e77a : nt!KiPageFault+0x260
fffff880`02fa1980 fffff880`0165d6c7 : fffffa80`05b08080 fffffa80`045188d0 fffffa80`04509840 00000000`00000000 : tcpip!TcpPreValidatedReceive+0x2d
fffff880`02fa1a30 fffff880`0165d799 : fffff880`02fa1bb0 fffff880`0176b9a0 fffff880`02fa1bc0 fffff880`00800080 : tcpip!IppDeliverListToProtocol+0x97
fffff880`02fa1af0 fffff880`0165dc90 : 00000000`00000000 fffff800`02e84992 fffff880`00000001 fffff880`02fa1bb0 : tcpip!IppProcessDeliverList+0x59
fffff880`02fa1b60 fffff880`016347c2 : fffffa80`036e3b60 fffff880`00c28d20 00000000`00000000 fffffa80`044c4630 : tcpip!IppReceiveHeaderBatch+0x231
fffff880`02fa1c40 fffff800`03179c43 : fffffa80`044c4630 fffff800`030225f8 fffffa80`036e3b60 fffffa80`0465af00 : tcpip!IppLoopbackTransmit+0x72
fffff880`02fa1c80 fffff800`02e8a961 : fffff880`00c3be00 fffff880`00c3bed0 fffffa80`036e3b60 00000000`00000000 : nt!IopProcessWorkItem+0x23
fffff880`02fa1cb0 fffff800`03121c06 : 0000052a`00000000 fffffa80`036e3b60 00000000`00000080 fffffa80`03670990 : nt!ExpWorkerThread+0x111
fffff880`02fa1d40 fffff800`02e5bc26 : fffff880`02d63180 fffffa80`036e3b60 fffff880`02d6dfc0 0000052a`00000000 : nt!PspSystemThreadStartup+0x5a
fffff880`02fa1d80 00000000`00000000 : fffff880`02fa2000 fffff880`02f9c000 fffff880`02fa19f0 00000000`00000000 : nt!KxStartSystemThread+0x16
STACK_COMMAND: kb
CHKIMG_EXTENSION: !chkimg -lo 50 -db !tcpip
8 errors : !tcpip (fffff8800167b26e-fffff8800167bdee)
fffff8800167b260 8b d8 48 8b fa ff 15 a5 40 0c 00 33 d2 8b *48 44 [email protected]
...
fffff8800167b360 49 8b d1 32 c0 41 0f b7 f1 45 0f b7 e1 48 *0b 5f I..2.A...E...H._
...
fffff8800167b4e0 8b 73 02 66 44 8b 23 8a 43 0d 48 8b d7 e9 *16 fe .s.fD.#.C.H.....
...
fffff8800167b660 90 90 90 90 90 90 90 90 90 90 90 90 90 90 *10 90 ................
...
fffff8800167b6e0 01 c6 44 24 40 01 0f 85 5c 19 04 00 44 0f *37 25 ..D$@...\...D.7%
...
fffff8800167b760 8d 84 24 b0 00 00 00 49 8b cc 49 8b d6 4c *09 ac ..$....I..I..L..
...
fffff8800167b9e0 0d 5b 05 11 00 45 33 c9 48 8b d3 e8 c4 2d *7e ff .[...E3.H....-~.
...
fffff8800167bde0 04 8b 5c 24 40 8b c3 48 8b 5c 24 70 48 83 *44 68 ..\[email protected].\$pH.Dh
MODULE_NAME: memory_corruption
IMAGE_NAME: memory_corruption
FOLLOWUP_NAME: memory_corruption
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MEMORY_CORRUPTOR: STRIDE
FAILURE_BUCKET_ID: X64_MEMORY_CORRUPTION_STRIDE
BUCKET_ID: X64_MEMORY_CORRUPTION_STRIDE
Followup: memory_corruption
---------
Debug session time: Mon Nov 22 16:46:47.236 2010 (GMT-5)
System Uptime: 0 days 0:05:32.937
Loading Kernel Symbols
...............................................................
................................................................
....................................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1E, {0, 0, 0, 0}
Probably caused by : partmgr.sys ( partmgr!PmReadWriteCompletion+1d )
Followup: MachineOwner
---------
3: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: 0000000000000000, The exception code that was not handled
Arg2: 0000000000000000, The address that the exception occurred at
Arg3: 0000000000000000, Parameter 0 of the exception
Arg4: 0000000000000000, Parameter 1 of the exception
Debugging Details:
------------------
EXCEPTION_CODE: (Win32) 0 (0) - The operation completed successfully.
FAULTING_IP:
+52ed952f0199de28
00000000`00000000 ?? ???
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: 0000000000000000
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x1E
PROCESS_NAME: System
CURRENT_IRQL: 2
EXCEPTION_RECORD: fffff88002dfb4a8 -- (.exr 0xfffff88002dfb4a8)
ExceptionAddress: fffff88000fe5f4d (partmgr!PmReadWriteCompletion+0x000000000000001d)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
TRAP_FRAME: fffff88002dfb550 -- (.trap 0xfffff88002dfb550)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffff88002dfb708 rbx=0000000000000000 rcx=ff7ffa800470e2c0
rdx=fffffa80037f5010 rsi=0000000000000000 rdi=0000000000000000
rip=fffff88000fe5f4d rsp=fffff88002dfb6e0 rbp=0000000000000034
r8=0000000000000000 r9=fffffa80046b01b0 r10=fffff88003523000
r11=fffff88002dfb7e8 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe nc
partmgr!PmReadWriteCompletion+0x1d:
fffff880`00fe5f4d 488b7940 mov rdi,qword ptr [rcx+40h] ds:003c:ff7ffa80`0470e300=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff8000307646e to fffff8000307e710
STACK_TEXT:
fffff880`02dfa598 fffff800`0307646e : 000004ca`00000000 000004ca`00000000 fffff880`02dfad10 fffff800`030ab668 : nt!KeBugCheck
fffff880`02dfa5a0 fffff800`030a440d : fffff800`0328cb7c fffff800`031c6e84 fffff800`0300e000 fffff880`02dfb4a8 : nt!KiKernelCalloutExceptionHandler+0xe
fffff880`02dfa5d0 fffff800`030aba90 : fffff800`031cdb14 fffff880`02dfa648 fffff880`02dfb4a8 fffff800`0300e000 : nt!RtlpExecuteHandlerForException+0xd
fffff880`02dfa600 fffff800`030b89ef : fffff880`02dfb4a8 fffff880`02dfad10 fffff880`00000000 fffffa80`037f5010 : nt!RtlDispatchException+0x410
fffff880`02dface0 fffff800`0307dd82 : fffff880`02dfb4a8 fffffa80`037f51bb fffff880`02dfb550 ff7ffa80`0470e2c0 : nt!KiDispatchException+0x16f
fffff880`02dfb370 fffff800`0307c68a : fffffa80`0469d6a8 fffff880`00e79ee1 00000000`00000050 fffffa80`03792f68 : nt!KiExceptionDispatch+0xc2
fffff880`02dfb550 fffff880`00fe5f4d : fffffa80`00001002 00000000`00000000 fffffa80`0469d3f0 fffffa80`045eee20 : nt!KiGeneralProtectionFault+0x10a
fffff880`02dfb6e0 fffff800`03080d26 : fffffa80`037f51bb 00000000`00000034 ff7ffa80`0470e2c0 fffffa80`037f5010 : partmgr!PmReadWriteCompletion+0x1d
fffff880`02dfb710 fffff880`010018ee : 00000000`00000000 fffff800`03132001 fffffa80`03792f38 00000000`00000000 : nt!IopfCompleteRequest+0x3a6
fffff880`02dfb7f0 fffff800`03080d26 : 00000000`00000000 fffff800`035ef156 fffffa80`04594860 00000000`00020000 : CLASSPNP!TransferPktComplete+0x1ce
fffff880`02dfb870 fffff880`00d9341a : 00000000`00020000 00000000`00000001 fffffa80`0386fb80 00000000`00000000 : nt!IopfCompleteRequest+0x3a6
fffff880`02dfb950 fffff880`00d93242 : fffffa80`0386fb80 fffff880`00d95b3b fffffa80`03792b80 fffffa80`046b01b0 : ataport!IdeCompleteScsiIrp+0x62
fffff880`02dfb980 fffff880`00d8de32 : 00000000`00000000 00000000`00000000 fffffa80`0469d500 fffffa80`046b01b0 : ataport!IdeCommonCrbCompletion+0x5a
fffff880`02dfb9b0 fffff880`00d967ed : fffffa80`0469c1a0 fffffa80`0386fb80 00000000`00000000 fffffa80`0386fb80 : ataport!IdeTranslateCompletedRequest+0x236
fffff880`02dfbae0 fffff880`00d960ec : fffffa80`0469c1a0 00000000`00000000 fffffa80`0469c1a0 00000000`00000000 : ataport!IdeProcessCompletedRequests+0x4d5
fffff880`02dfbc10 fffff800`03089bfc : fffff880`02dd3180 00000000`3e5c8781 fffffa80`0469c050 fffffa80`0469c118 : ataport!IdePortCompletionDpc+0x1a8
fffff880`02dfbcd0 fffff800`03086eea : fffff880`02dd3180 fffff880`02dddfc0 00000000`00000000 fffff880`00d95f44 : nt!KiRetireDpcList+0x1bc
fffff880`02dfbd80 00000000`00000000 : fffff880`02dfc000 fffff880`02df6000 fffff880`02dfbd40 00000000`00000000 : nt!KiIdleLoop+0x5a
STACK_COMMAND: kb
FOLLOWUP_IP:
partmgr!PmReadWriteCompletion+1d
fffff880`00fe5f4d 488b7940 mov rdi,qword ptr [rcx+40h]
SYMBOL_STACK_INDEX: 7
SYMBOL_NAME: partmgr!PmReadWriteCompletion+1d
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: partmgr
IMAGE_NAME: partmgr.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc11e
FAILURE_BUCKET_ID: X64_0x1E_partmgr!PmReadWriteCompletion+1d
BUCKET_ID: X64_0x1E_partmgr!PmReadWriteCompletion+1d
Followup: MachineOwner
---------
Debug session time: Mon Nov 22 16:39:55.705 2010 (GMT-5)
System Uptime: 0 days 0:02:07.406
Loading Kernel Symbols
...............................................................
................................................................
..................................
Loading User Symbols
Loading unloaded module list
.......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1000007E, {ffffffffc0000005, fffff8000318f927, fffff88003316608, fffff88003315e70}
Probably caused by : memory_corruption ( nt!MiEmptyPageAccessLog+1f7 )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff8000318f927, The address that the exception occurred at
Arg3: fffff88003316608, Exception Record Address
Arg4: fffff88003315e70, Context Record Address
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!MiEmptyPageAccessLog+1f7
fffff800`0318f927 488b06 mov rax,qword ptr [rsi]
EXCEPTION_RECORD: fffff88003316608 -- (.exr 0xfffff88003316608)
ExceptionAddress: fffff8000318f927 (nt!MiEmptyPageAccessLog+0x00000000000001f7)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
CONTEXT: fffff88003315e70 -- (.cxr 0xfffff88003315e70)
rax=fffffa800584ab30 rbx=0000000000000000 rcx=00000000000001ff
rdx=0000000000000000 rsi=ff7ffa80037f5ff8 rdi=0000000000000000
rip=fffff8000318f927 rsp=fffff88003316840 rbp=fffffa80037f1000
r8=0000000000000000 r9=fffffa80037f5048 r10=0000000000000005
r11=0000000000000000 r12=fffffa80037f5ff0 r13=fffffa80037f5000
r14=000000000663c000 r15=0000000000000000
iopl=0 nv up ei ng nz na pe cy
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010283
nt!MiEmptyPageAccessLog+0x1f7:
fffff800`0318f927 488b06 mov rax,qword ptr [rsi] ds:002b:ff7ffa80`037f5ff8=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: ffffffffffffffff
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800032c10e0
ffffffffffffffff
FOLLOWUP_IP:
nt!MiEmptyPageAccessLog+1f7
fffff800`0318f927 488b06 mov rax,qword ptr [rsi]
BUGCHECK_STR: 0x7E
LAST_CONTROL_TRANSFER: from fffff8000318fa70 to fffff8000318f927
STACK_TEXT:
fffff880`03316840 fffff800`0318fa70 : fffffa80`0584ab30 00000003`00000000 00000000`00000000 00000000`00000000 : nt!MiEmptyPageAccessLog+0x1f7
fffff880`033168b0 fffff800`0318fc76 : fffffa80`037f5000 00000000`00002c91 fffff680`000312c8 fffff800`03256d60 : nt!MiAllocateAccessLog+0x80
fffff880`033168e0 fffff800`030f1628 : 00000003`00000000 c9100000`b542b867 00000000`00000000 00000000`00002c91 : nt!MiLogPageAccess+0x46
fffff880`03316930 fffff800`0310ba5e : fffffa80`0584aec8 fffff880`00000001 00000000`00000001 fffff880`03316bb0 : nt! ?? ::FNODOBFM::`string'+0x217c6
fffff880`03316ae0 fffff800`0309dee2 : 00000000`00000080 00000000`00000000 fffffa80`00000000 00000000`00000003 : nt! ?? ::FNODOBFM::`string'+0x496d6
fffff880`03316b80 fffff800`0309e173 : 00000000`00000008 fffff880`03316c10 00000000`00000001 fffffa80`00000000 : nt!MmWorkingSetManager+0x6e
fffff880`03316bd0 fffff800`0332dc06 : fffffa80`036ee680 00000000`00000080 fffffa80`03670890 00000000`00000001 : nt!KeBalanceSetManager+0x1c3
fffff880`03316d40 fffff800`03067c26 : fffff880`02f63180 fffffa80`036ee680 fffff880`02f6dfc0 00010000`00000741 : nt!PspSystemThreadStartup+0x5a
fffff880`03316d80 00000000`00000000 : fffff880`03317000 fffff880`03311000 fffff880`03316710 00000000`00000000 : nt!KxStartSystemThread+0x16
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!MiEmptyPageAccessLog+1f7
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
STACK_COMMAND: .cxr 0xfffff88003315e70 ; kb
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: X64_0x7E_nt!MiEmptyPageAccessLog+1f7
BUCKET_ID: X64_0x7E_nt!MiEmptyPageAccessLog+1f7
Followup: MachineOwner
---------
Kernel base = 0xfffff800`0305b000 PsLoadedModuleList = 0xfffff800`03298e50
Debug session time: Mon Nov 22 16:32:29.119 2010 (GMT-5)
System Uptime: 0 days 1:28:15.430
Loading Kernel Symbols
...............................................................
................................................................
....................................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fffff80003359a0f, fffff88008858930, 0}
Probably caused by : ntkrnlmp.exe ( nt!HvFreeHive+af )
Followup: MachineOwner
---------
3: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff80003359a0f, Address of the exception record for the exception that caused the bugcheck
Arg3: fffff88008858930, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!HvFreeHive+af
fffff800`03359a0f 448b5304 mov r10d,dword ptr [rbx+4]
CONTEXT: fffff88008858930 -- (.cxr 0xfffff88008858930)
rax=fffff8a010a5c060 rbx=ff7ff8a0110f8000 rcx=fffff8a00b3ff420
rdx=0000000000000002 rsi=fffff8a00b3ff4d0 rdi=fffff8a00b3ff420
rip=fffff80003359a0f rsp=fffff88008859300 rbp=0000000000483000
r8=fffff8a00b3ff420 r9=0000000000011000 r10=0000000000000000
r11=0000000001ffffff r12=0000000000000001 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010286
nt!HvFreeHive+0xaf:
fffff800`03359a0f 448b5304 mov r10d,dword ptr [rbx+4] ds:002b:ff7ff8a0`110f8004=????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: rundll32.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff80003359a0f
STACK_TEXT:
fffff880`08859300 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!HvFreeHive+0xaf
FOLLOWUP_IP:
nt!HvFreeHive+af
fffff800`03359a0f 448b5304 mov r10d,dword ptr [rbx+4]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!HvFreeHive+af
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
STACK_COMMAND: .cxr 0xfffff88008858930 ; kb
FAILURE_BUCKET_ID: X64_0x3B_nt!HvFreeHive+af
BUCKET_ID: X64_0x3B_nt!HvFreeHive+af
Followup: MachineOwner
---------
3: kd> lmtsmn
start end module name
fffff880`04190000 fffff880`041ce000 1394ohci 1394ohci.sys Mon Jul 13 20:07:12 2009 (4A5BCC30)
fffff880`00ed3000 fffff880`00f2a000 ACPI ACPI.sys Mon Jul 13 19:19:34 2009 (4A5BC106)
fffff880`02b19000 fffff880`02ba3000 afd afd.sys Mon Jul 13 19:21:40 2009 (4A5BC184)
fffff880`041de000 fffff880`041f4000 AgileVpn AgileVpn.sys Mon Jul 13 20:10:24 2009 (4A5BCCF0)
fffff880`040be000 fffff880`040d3000 amdppm amdppm.sys Mon Jul 13 19:19:25 2009 (4A5BC0FD)
fffff880`00ec0000 fffff880`00ecb000 amdxata amdxata.sys Tue May 19 13:56:59 2009 (4A12F2EB)
fffff880`04df3000 fffff880`04dfb000 ASACPI ASACPI.sys Wed Jul 15 23:31:29 2009 (4A5E9F11)
fffff880`04092000 fffff880`04098000 AsIO AsIO.sys Mon Aug 03 03:03:16 2009 (4A768BB4)
fffff880`0408c000 fffff880`04092000 AsUpIO AsUpIO.sys Sun Jul 05 22:21:38 2009 (4A515FB2)
fffff880`063f4000 fffff880`063fd000 aswFsBlk aswFsBlk.SYS Tue Sep 07 10:47:09 2010 (4C86506D)
fffff880`063ba000 fffff880`063f4000 aswMonFlt aswMonFlt.sys Tue Sep 07 10:47:32 2010 (4C865084)
fffff880`02ba3000 fffff880`02bad000 aswRdr aswRdr.SYS Tue Sep 07 10:47:47 2010 (4C865093)
fffff880`04069000 fffff880`0408c000 aswSP aswSP.SYS Tue Sep 07 10:52:07 2010 (4C865197)
fffff880`02b09000 fffff880`02b19000 aswTdi aswTdi.SYS Tue Sep 07 10:52:27 2010 (4C8651AB)
fffff880`068bf000 fffff880`068ca000 asyncmac asyncmac.sys Mon Jul 13 20:10:13 2009 (4A5BCCE5)
fffff880`00e8d000 fffff880`00e96000 atapi atapi.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`00e96000 fffff880`00ec0000 ataport ataport.SYS Mon Jul 13 19:19:52 2009 (4A5BC118)
fffff880`0460b000 fffff880`04c44000 atikmdag atikmdag.sys Fri Sep 18 22:44:52 2009 (4AB445A4)
fffff880`015eb000 fffff880`015f3000 AtiPcie AtiPcie.sys Tue May 05 11:00:22 2009 (4A005486)
fffff880`02a5d000 fffff880`02a64000 Beep Beep.SYS Mon Jul 13 20:00:13 2009 (4A5BCA8D)
fffff880`02a00000 fffff880`02a11000 blbdrive blbdrive.sys Mon Jul 13 19:35:59 2009 (4A5BC4DF)
fffff880`03789000 fffff880`037a7000 bowser bowser.sys Mon Jul 13 19:23:50 2009 (4A5BC206)
fffff960`00650000 fffff960`00677000 cdd cdd.dll unavailable (00000000)
fffff880`06831000 fffff880`0684e000 cdfs cdfs.sys Mon Jul 13 19:19:46 2009 (4A5BC112)
fffff880`02a2a000 fffff880`02a54000 cdrom cdrom.sys Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`00c00000 fffff880`00cc0000 CI CI.dll Mon Jul 13 21:32:13 2009 (4A5BE01D)
fffff880`011be000 fffff880`011ee000 CLASSPNP CLASSPNP.SYS Mon Jul 13 19:19:58 2009 (4A5BC11E)
fffff880`00ce6000 fffff880`00d44000 CLFS CLFS.SYS Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`0131d000 fffff880`01390000 cng cng.sys Mon Jul 13 19:49:40 2009 (4A5BC814)
fffff880`041ce000 fffff880`041de000 CompositeBus CompositeBus.sys Mon Jul 13 20:00:33 2009 (4A5BCAA1)
fffff880`065eb000 fffff880`065f9000 crashdmp crashdmp.sys Mon Jul 13 20:01:01 2009 (4A5BCABD)
fffff880`03c00000 fffff880`03c83000 csc csc.sys Mon Jul 13 19:24:26 2009 (4A5BC22A)
fffff880`03c83000 fffff880`03ca1000 dfsc dfsc.sys Mon Jul 13 19:23:44 2009 (4A5BC200)
fffff880`03deb000 fffff880`03dfa000 discache discache.sys Mon Jul 13 19:37:18 2009 (4A5BC52E)
fffff880`01286000 fffff880`0129c000 disk disk.sys Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`0633b000 fffff880`0635d000 drmk drmk.sys Mon Jul 13 21:01:25 2009 (4A5BD8E5)
fffff880`0640c000 fffff880`06415000 dump_atapi dump_atapi.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`06400000 fffff880`0640c000 dump_dumpata dump_dumpata.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`06415000 fffff880`06428000 dump_dumpfve dump_dumpfve.sys Mon Jul 13 19:21:51 2009 (4A5BC18F)
fffff880`065df000 fffff880`065eb000 Dxapi Dxapi.sys Mon Jul 13 19:38:28 2009 (4A5BC574)
fffff880`04c44000 fffff880`04d38000 dxgkrnl dxgkrnl.sys Thu Oct 01 21:00:14 2009 (4AC5509E)
fffff880`04d38000 fffff880`04d7e000 dxgmms1 dxgmms1.sys Mon Jul 13 19:38:32 2009 (4A5BC578)
fffff880`06979000 fffff880`06994e80 ewusbdev ewusbdev.sys Mon Oct 12 03:23:21 2009 (4AD2D969)
fffff880`069b2000 fffff880`069cea00 ewusbmdm ewusbmdm.sys Thu Sep 10 03:31:54 2009 (4AA8AB6A)
fffff880`01007000 fffff880`0101b000 fileinfo fileinfo.sys Mon Jul 13 19:34:25 2009 (4A5BC481)
fffff880`00fa7000 fffff880`00ff3000 fltmgr fltmgr.sys Mon Jul 13 19:19:59 2009 (4A5BC11F)
fffff880`013a1000 fffff880`013ab000 Fs_Rec Fs_Rec.sys Mon Jul 13 19:19:45 2009 (4A5BC111)
fffff880`0124c000 fffff880`01286000 fvevol fvevol.sys Fri Sep 25 22:34:26 2009 (4ABD7DB2)
fffff880`013ab000 fffff880`013f5000 fwpkclnt fwpkclnt.sys Mon Jul 13 19:21:08 2009 (4A5BC164)
fffff880`04ddb000 fffff880`04de8000 GEARAspiWDM GEARAspiWDM.sys Mon May 18 08:17:04 2009 (4A1151C0)
fffff800`03012000 fffff800`0305b000 hal hal.dll Mon Jul 13 21:27:36 2009 (4A5BDF08)
fffff880`04d7e000 fffff880`04da2000 HDAudBus HDAudBus.sys Mon Jul 13 20:06:13 2009 (4A5BCBF5)
fffff880`06363000 fffff880`0637c000 HIDCLASS HIDCLASS.SYS Mon Jul 13 20:06:21 2009 (4A5BCBFD)
fffff880`06436000 fffff880`0643e080 HIDPARSE HIDPARSE.SYS Mon Jul 13 20:06:17 2009 (4A5BCBF9)
fffff880`06428000 fffff880`06436000 hidusb hidusb.sys Mon Jul 13 20:06:22 2009 (4A5BCBFE)
fffff880`036c1000 fffff880`03789000 HTTP HTTP.sys Mon Jul 13 19:22:16 2009 (4A5BC1A8)
fffff880`015e2000 fffff880`015eb000 hwpolicy hwpolicy.sys Mon Jul 13 19:19:22 2009 (4A5BC0FA)
fffff880`04157000 fffff880`04175000 i8042prt i8042prt.sys Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`04175000 fffff880`04184000 kbdclass kbdclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff800`00b9a000 fffff800`00ba4000 kdcom kdcom.dll Mon Jul 13 21:31:07 2009 (4A5BDFDB)
fffff880`04f24000 fffff880`04f67000 ks ks.sys Wed Mar 03 23:32:25 2010 (4B8F37D9)
fffff880`01303000 fffff880`0131d000 ksecdd ksecdd.sys Mon Jul 13 19:20:54 2009 (4A5BC156)
fffff880`0158d000 fffff880`015b8000 ksecpkg ksecpkg.sys Fri Dec 11 01:03:32 2009 (4B21E0B4)
fffff880`0635d000 fffff880`06362200 ksthunk ksthunk.sys Mon Jul 13 20:00:19 2009 (4A5BCA93)
fffff880`06221000 fffff880`06236000 lltdio lltdio.sys Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`06397000 fffff880`063ba000 luafv luafv.sys Mon Jul 13 19:26:13 2009 (4A5BC295)
fffff880`00cc5000 fffff880`00cd2000 mcupdate_AuthenticAMD mcupdate_AuthenticAMD.dll Mon Jul 13 21:29:09 2009 (4A5BDF65)
fffff880`069cf000 fffff880`069de000 modem modem.sys Mon Jul 13 20:10:48 2009 (4A5BCD08)
fffff880`06389000 fffff880`06397000 monitor monitor.sys Mon Jul 13 19:38:52 2009 (4A5BC58C)
fffff880`04eec000 fffff880`04efb000 mouclass mouclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff880`0637c000 fffff880`06389000 mouhid mouhid.sys Mon Jul 13 20:00:20 2009 (4A5BCA94)
fffff880`00e73000 fffff880`00e8d000 mountmgr mountmgr.sys Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`037a7000 fffff880`037bf000 mpsdrv mpsdrv.sys Mon Jul 13 20:08:25 2009 (4A5BCC79)
fffff880`037bf000 fffff880`037ec000 mrxsmb mrxsmb.sys Sat Feb 27 02:52:19 2010 (4B88CF33)
fffff880`03600000 fffff880`0364e000 mrxsmb10 mrxsmb10.sys Sat Feb 27 02:52:28 2010 (4B88CF3C)
fffff880`0364e000 fffff880`03671000 mrxsmb20 mrxsmb20.sys Sat Feb 27 02:52:26 2010 (4B88CF3A)
fffff880`02ac2000 fffff880`02acd000 Msfs Msfs.SYS Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`00f33000 fffff880`00f3d000 msisadrv msisadrv.sys Mon Jul 13 19:19:26 2009 (4A5BC0FE)
fffff880`012a5000 fffff880`01303000 msrpc msrpc.sys Mon Jul 13 19:21:32 2009 (4A5BC17C)
fffff880`03de0000 fffff880`03deb000 mssmbios mssmbios.sys Mon Jul 13 19:31:10 2009 (4A5BC3BE)
fffff880`015d0000 fffff880`015e2000 mup mup.sys Mon Jul 13 19:23:45 2009 (4A5BC201)
fffff880`0143b000 fffff880`0152d000 ndis ndis.sys Mon Jul 13 19:21:40 2009 (4A5BC184)
fffff880`04024000 fffff880`04030000 ndistapi ndistapi.sys Mon Jul 13 20:10:00 2009 (4A5BCCD8)
fffff880`06289000 fffff880`0629c000 ndisuio ndisuio.sys Mon Jul 13 20:09:25 2009 (4A5BCCB5)
fffff880`04030000 fffff880`0405f000 ndiswan ndiswan.sys Mon Jul 13 20:10:11 2009 (4A5BCCE3)
fffff880`04fd3000 fffff880`04fe8000 NDProxy NDProxy.SYS Mon Jul 13 20:10:05 2009 (4A5BCCDD)
fffff880`03cec000 fffff880`03cfb000 netbios netbios.sys Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff880`02bad000 fffff880`02bf2000 netbt netbt.sys Mon Jul 13 19:21:28 2009 (4A5BC178)
fffff880`0152d000 fffff880`0158d000 NETIO NETIO.SYS Mon Jul 13 19:21:46 2009 (4A5BC18A)
fffff880`02acd000 fffff880`02ade000 Npfs Npfs.SYS Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`03dd4000 fffff880`03de0000 nsiproxy nsiproxy.sys Mon Jul 13 19:21:02 2009 (4A5BC15E)
fffff800`0305b000 fffff800`03637000 nt ntkrnlmp.exe Sat Jun 19 00:16:41 2010 (4C1C44A9)
fffff880`0101b000 fffff880`011be000 Ntfs Ntfs.sys Mon Jul 13 19:20:47 2009 (4A5BC14F)
fffff880`02a54000 fffff880`02a5d000 Null Null.SYS Mon Jul 13 19:19:37 2009 (4A5BC109)
fffff880`06236000 fffff880`06289000 nwifi nwifi.sys Mon Jul 13 20:07:23 2009 (4A5BCC3B)
fffff880`03cb0000 fffff880`03cd6000 pacer pacer.sys Mon Jul 13 20:09:41 2009 (4A5BCCC5)
fffff880`0413a000 fffff880`04157000 parport parport.sys Mon Jul 13 20:00:40 2009 (4A5BCAA8)
fffff880`00f7d000 fffff880`00f92000 partmgr partmgr.sys Mon Jul 13 19:19:58 2009 (4A5BC11E)
fffff880`00f3d000 fffff880`00f70000 pci pci.sys Mon Jul 13 19:19:51 2009 (4A5BC117)
fffff880`00e5c000 fffff880`00e63000 pciide pciide.sys Mon Jul 13 19:19:49 2009 (4A5BC115)
fffff880`00e63000 fffff880`00e73000 PCIIDEX PCIIDEX.SYS Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`01390000 fffff880`013a1000 pcw pcw.sys Mon Jul 13 19:19:27 2009 (4A5BC0FF)
fffff880`0441d000 fffff880`044c3000 peauth peauth.sys Mon Jul 13 21:01:19 2009 (4A5BD8DF)
fffff880`062fe000 fffff880`0633b000 portcls portcls.sys Mon Jul 13 20:06:27 2009 (4A5BCC03)
fffff880`00cd2000 fffff880`00ce6000 PSHED PSHED.dll Mon Jul 13 21:32:23 2009 (4A5BE027)
fffff880`04000000 fffff880`04024000 rasl2tp rasl2tp.sys Mon Jul 13 20:10:11 2009 (4A5BCCE3)
fffff880`04e69000 fffff880`04e84000 raspppoe raspppoe.sys Mon Jul 13 20:10:17 2009 (4A5BCCE9)
fffff880`04e84000 fffff880`04ea5000 raspptp raspptp.sys Mon Jul 13 20:10:18 2009 (4A5BCCEA)
fffff880`04ea5000 fffff880`04ebf000 rassstp rassstp.sys Mon Jul 13 20:10:25 2009 (4A5BCCF1)
fffff880`03d83000 fffff880`03dd4000 rdbss rdbss.sys Mon Jul 13 19:24:09 2009 (4A5BC219)
fffff880`04ee1000 fffff880`04eec000 rdpbus rdpbus.sys Mon Jul 13 20:17:46 2009 (4A5BCEAA)
fffff880`02aa7000 fffff880`02ab0000 RDPCDD RDPCDD.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`02ab0000 fffff880`02ab9000 rdpencdd rdpencdd.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`02ab9000 fffff880`02ac2000 rdprefmp rdprefmp.sys Mon Jul 13 20:16:35 2009 (4A5BCE63)
fffff880`01400000 fffff880`0143a000 rdyboost rdyboost.sys Mon Jul 13 19:34:34 2009 (4A5BC48A)
fffff880`0629c000 fffff880`062b4000 rspndr rspndr.sys Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`04da2000 fffff880`04ddb000 Rt64win7 Rt64win7.sys Fri May 22 10:52:30 2009 (4A16BC2E)
fffff880`04e00000 fffff880`04e30880 RtHDMIVX RtHDMIVX.sys Wed Jun 24 06:23:22 2009 (4A41FE9A)
fffff880`044c3000 fffff880`044ce000 secdrv secdrv.SYS Wed Sep 13 09:18:38 2006 (4508052E)
fffff880`04184000 fffff880`04190000 serenum serenum.sys Mon Jul 13 20:00:33 2009 (4A5BCAA1)
fffff880`03cfb000 fffff880`03d18000 serial serial.sys Mon Jul 13 20:00:40 2009 (4A5BCAA8)
fffff880`015c8000 fffff880`015d0000 spldr spldr.sys Mon May 11 12:56:27 2009 (4A0858BB)
fffff880`068e3000 fffff880`06979000 srv srv.sys Thu Aug 26 23:38:00 2010 (4C773318)
fffff880`0450d000 fffff880`04574000 srv2 srv2.sys Thu Aug 26 23:37:46 2010 (4C77330A)
fffff880`044ce000 fffff880`044fb000 srvnet srvnet.sys Thu Aug 26 23:37:24 2010 (4C7732F4)
fffff880`04f22000 fffff880`04f23480 swenum swenum.sys Mon Jul 13 20:00:18 2009 (4A5BCA92)
fffff880`01600000 fffff880`017fd000 tcpip tcpip.sys Sun Jun 13 23:39:04 2010 (4C15A458)
fffff880`044fb000 fffff880`0450d000 tcpipreg tcpipreg.sys Mon Jul 13 20:09:49 2009 (4A5BCCCD)
fffff880`02afc000 fffff880`02b09000 TDI TDI.SYS Mon Jul 13 19:21:18 2009 (4A5BC16E)
fffff880`02ade000 fffff880`02afc000 tdx tdx.sys Mon Jul 13 19:21:15 2009 (4A5BC16B)
fffff880`03d6f000 fffff880`03d83000 termdd termdd.sys Mon Jul 13 20:16:36 2009 (4A5BCE64)
fffff960`00490000 fffff960`0049a000 TSDDD TSDDD.dll Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`04098000 fffff880`040be000 tunnel tunnel.sys Mon Jul 13 20:09:37 2009 (4A5BCCC1)
fffff880`04f67000 fffff880`04f79000 umbus umbus.sys Mon Jul 13 20:06:56 2009 (4A5BCC20)
fffff880`06995000 fffff880`069b2000 usbccgp usbccgp.sys Mon Jul 13 20:06:45 2009 (4A5BCC15)
fffff880`0643f000 fffff880`06440f00 USBD USBD.SYS Mon Jul 13 20:06:23 2009 (4A5BCBFF)
fffff880`04129000 fffff880`0413a000 usbehci usbehci.sys Mon Jul 13 20:06:30 2009 (4A5BCC06)
fffff880`04f79000 fffff880`04fd3000 usbhub usbhub.sys Mon Jul 13 20:07:09 2009 (4A5BCC2D)
fffff880`04de8000 fffff880`04df3000 usbohci usbohci.sys Mon Jul 13 20:06:30 2009 (4A5BCC06)
fffff880`040d3000 fffff880`04129000 USBPORT USBPORT.SYS Mon Jul 13 20:06:31 2009 (4A5BCC07)
fffff880`069de000 fffff880`069f9000 USBSTOR USBSTOR.SYS Mon Jul 13 20:06:34 2009 (4A5BCC0A)
fffff880`03d3f000 fffff880`03d6ef00 VBoxDrv VBoxDrv.sys Fri Oct 08 09:52:29 2010 (4CAF221D)
fffff880`04ebf000 fffff880`04ee0b80 VBoxNetAdp VBoxNetAdp.sys Fri Oct 08 09:52:34 2010 (4CAF2222)
fffff880`04efb000 fffff880`04f217c0 VBoxNetFlt VBoxNetFlt.sys Fri Oct 08 09:52:29 2010 (4CAF221D)
fffff880`03d33000 fffff880`03d3e8c0 VBoxUSBMon VBoxUSBMon.sys Fri Oct 08 09:52:34 2010 (4CAF2222)
fffff880`00f70000 fffff880`00f7d000 vdrvroot vdrvroot.sys Mon Jul 13 20:01:31 2009 (4A5BCADB)
fffff880`02a64000 fffff880`02a72000 vga vga.sys Mon Jul 13 19:38:47 2009 (4A5BC587)
fffff880`06445000 fffff880`065df000 viahduaa viahduaa.sys Mon Aug 17 07:20:43 2009 (4A893D0B)
fffff880`02a72000 fffff880`02a97000 VIDEOPRT VIDEOPRT.SYS Mon Jul 13 19:38:51 2009 (4A5BC58B)
fffff880`015b8000 fffff880`015c8000 vmstorfl vmstorfl.sys Mon Jul 13 19:42:54 2009 (4A5BC67E)
fffff880`00f92000 fffff880`00fa7000 volmgr volmgr.sys Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`00e00000 fffff880`00e5c000 volmgrx volmgrx.sys Mon Jul 13 19:20:33 2009 (4A5BC141)
fffff880`01200000 fffff880`0124c000 volsnap volsnap.sys Mon Jul 13 19:20:08 2009 (4A5BC128)
fffff880`03cd6000 fffff880`03cec000 vwififlt vwififlt.sys Mon Jul 13 20:07:22 2009 (4A5BCC3A)
fffff880`03d18000 fffff880`03d33000 wanarp wanarp.sys Mon Jul 13 20:10:21 2009 (4A5BCCED)
fffff880`02a97000 fffff880`02aa7000 watchdog watchdog.sys Mon Jul 13 19:37:35 2009 (4A5BC53F)
fffff880`00d44000 fffff880`00de8000 Wdf01000 Wdf01000.sys Mon Jul 13 19:22:07 2009 (4A5BC19F)
fffff880`00de8000 fffff880`00df7000 WDFLDR WDFLDR.SYS Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`02bf2000 fffff880`02bfb000 wfplwf wfplwf.sys Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff960`00020000 fffff960`0032f000 win32k win32k.sys Tue Aug 31 22:58:04 2010 (4C7DC13C)
fffff880`04600000 fffff880`04609000 wmiacpi wmiacpi.sys Mon Jul 13 19:31:02 2009 (4A5BC3B6)
fffff880`00f2a000 fffff880`00f33000 WMILIB WMILIB.SYS Mon Jul 13 19:19:51 2009 (4A5BC117)
fffff880`06200000 fffff880`06221000 WudfPf WudfPf.sys Mon Jul 13 20:05:37 2009 (4A5BCBD1)
fffff880`06800000 fffff880`06831000 WUDFRd WUDFRd.sys Mon Jul 13 20:06:06 2009 (4A5BCBEE)
Unloaded modules:
fffff880`0684e000 fffff880`068bf000 spsys.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`011ee000 fffff880`011fc000 crashdmp.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`015f3000 fffff880`015ff000 dump_ataport
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`0129c000 fffff880`012a5000 dump_atapi.s
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`02a17000 fffff880`02a2a000 dump_dumpfve
Timestamp: unavailable (00000000)
Checksum: 00000000