Kernel base = 0xfffff800`02e54000 PsLoadedModuleList = 0xfffff800`03091e50
Debug session time: Thu Sep 30 18:15:10.373 2010 (GMT-4)
System Uptime: 0 days 0:00:41.513
Loading Kernel Symbols
...............................................................
................................................................
.....................................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {fffffa804589042f, 0, fffff880091c1aa6, 5}
Unable to load image \??\C:\Windows\system32\Drivers\APPFLT64.SYS, Win32 error 0n2
*** WARNING: Unable to verify timestamp for APPFLT64.SYS
*** ERROR: Module load completed but symbols could not be loaded for APPFLT64.SYS
Could not read faulting driver name[B]
Probably caused by : APPFLT64.SYS [/B]( APPFLT64+daa6 )
Followup: MachineOwner
---------
4: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: fffffa804589042f, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff880091c1aa6, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000005, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800030fc0e0
fffffa804589042f
FAULTING_IP:
APPFLT64+daa6
fffff880`091c1aa6 833b00 cmp dword ptr [rbx],0
MM_INTERNAL_CODE: 5
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: System
CURRENT_IRQL: 0
TRAP_FRAME: fffff88003377720 -- (.trap 0xfffff88003377720)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=00000000b0cdb0cd rbx=0000000000000000 rcx=fffffa800a3f1801
rdx=fffffa800a3e6801 rsi=0000000000000000 rdi=0000000000000000
rip=fffff880091c1aa6 rsp=fffff880033778b0 rbp=0000000000000001
r8=fffffa800a3e6800 r9=fffffa8005207248 r10=fffff880091ceac0
r11=000000003aef3aef r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na pe nc
APPFLT64+0xdaa6:
fffff880`091c1aa6 833b00 cmp dword ptr [rbx],0 ds:00000000`00000000=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002f438c1 to fffff80002ec4740
STACK_TEXT:
fffff880`033775b8 fffff800`02f438c1 : 00000000`00000050 fffffa80`4589042f 00000000`00000000 fffff880`03377720 : nt!KeBugCheckEx
fffff880`033775c0 fffff800`02ec282e : 00000000`00000000 fffffa80`4589042f 00000000`00000000 fffffa80`526c5054 : nt! ?? ::FNODOBFM::`string'+0x40e8b
fffff880`03377720 fffff880`091c1aa6 : fffffa80`0a99c940 00000000`00000001 00000000`00000000 fffffa80`07093060 : nt!KiPageFault+0x16e
fffff880`033778b0 fffffa80`0a99c940 : 00000000`00000001 00000000`00000000 fffffa80`07093060 00000000`00000000 : APPFLT64+0xdaa6
fffff880`033778b8 00000000`00000001 : 00000000`00000000 fffffa80`07093060 00000000`00000000 fffff880`091c7f28 : 0xfffffa80`0a99c940
fffff880`033778c0 00000000`00000000 : fffffa80`07093060 00000000`00000000 fffff880`091c7f28 00000000`0000ca10 : 0x1
STACK_COMMAND: kb
FOLLOWUP_IP:
APPFLT64+daa6
fffff880`091c1aa6 833b00 cmp dword ptr [rbx],0
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: APPFLT64+daa6
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: APPFLT64
IMAGE_NAME: APPFLT64.SYS
DEBUG_FLR_IMAGE_TIMESTAMP: 4ac3c620
FAILURE_BUCKET_ID: X64_0x50_APPFLT64+daa6
BUCKET_ID: X64_0x50_APPFLT64+daa6
Followup: MachineOwner
---------
Kernel base = 0xfffff800`02e49000 PsLoadedModuleList = 0xfffff800`03086e50
Debug session time: Thu Sep 30 18:13:32.595 2010 (GMT-4)
System Uptime: 0 days 6:56:46.734
Loading Kernel Symbols
...............................................................
................................................................
....................................................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 4E, {99, dc4c, 2, dc4b}
Probably caused by : memory_corruption ( nt!MiBadShareCount+4c )
Followup: MachineOwner
---------
5: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PFN_LIST_CORRUPT (4e)
Typically caused by drivers passing bad memory descriptor lists (ie: calling
MmUnlockPages twice with the same list, etc). If a kernel debugger is
available get the stack trace.
Arguments:
Arg1: 0000000000000099, A PTE or PFN is corrupt
Arg2: 000000000000dc4c, page frame number
Arg3: 0000000000000002, current page state
Arg4: 000000000000dc4b, 0
Debugging Details:
------------------
BUGCHECK_STR: 0x4E_99
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: CAPTUR~3.EXE
CURRENT_IRQL: 2
LAST_CONTROL_TRANSFER: from fffff80002f4938c to fffff80002eb9740
STACK_TEXT:
fffff880`0d4431a8 fffff800`02f4938c : 00000000`0000004e 00000000`00000099 00000000`0000dc4c 00000000`00000002 : nt!KeBugCheckEx
fffff880`0d4431b0 fffff800`02f164d2 : fffffa80`031834e0 00000000`00000001 00000000`00000000 fffff800`030705a8 : nt!MiBadShareCount+0x4c
fffff880`0d4431f0 fffff800`02f7a29d : fffffa80`031834e0 fffff880`0d443340 00000000`00000080 00000000`000caca7 : nt! ?? ::FNODOBFM::`string'+0x11aa2
fffff880`0d443250 fffff800`02e6e40e : 00000000`00000000 fffff880`0d443340 ffffffff`ffffffff 00000000`00000530 : nt!MiRemoveLowestPriorityStandbyPage+0x2ad
fffff880`0d4432d0 fffff800`02ee56ce : fffff980`233ea000 00000000`0b05c160 fffff880`00000000 00000000`00001000 : nt! ?? ::FNODOBFM::`string'+0x44ef3
fffff880`0d4434c0 fffff800`02ee5434 : fffffa80`0745f010 00000000`0b05c160 fffff880`0d443600 00000000`00000000 : nt!CcMapAndCopyInToCache+0x20e
fffff880`0d4435b0 fffff880`012a8fb8 : 00000000`0b62d670 fffffa80`0ad31f00 fffff880`0d4436a0 fffffa80`00004970 : nt!CcCopyWrite+0x194
fffff880`0d443640 fffff880`01167132 : fffffa80`0ad31f20 fffff880`0116a732 fffffa80`00004970 00000000`00004901 : Ntfs!NtfsCopyWriteA+0x208
fffff880`0d443830 fffff880`0116ac2a : fffff880`0d443900 fffffa80`0b934d78 00000000`0b05ae00 00000000`00004900 : fltmgr!FltpPerformFastIoCall+0xf2
fffff880`0d443890 fffff880`011887fe : 00000000`00004970 00000000`00000000 fffffa80`0ad31f20 fffffa80`057080d8 : fltmgr!FltpPassThroughFastIo+0xda
fffff880`0d4438d0 fffff880`01167132 : 00000000`00000000 fffff880`0116a732 22549769`c86c5512 fffffa80`0ad31f20 : fltmgr!FltpFastIoWrite+0x1ce
fffff880`0d443970 fffff880`0116ac2a : fffff880`0d443a40 fffffa80`057080d8 00000000`0b05ae00 00000000`00004900 : fltmgr!FltpPerformFastIoCall+0xf2
fffff880`0d4439d0 fffff880`011887fe : 00000000`00004970 00000000`00000000 fffffa80`0ad31f20 fffff880`0d443b40 : fltmgr!FltpPassThroughFastIo+0xda
fffff880`0d443a10 fffff800`031d080e : fffffa80`0ad31f94 fffff880`0d443ad8 00000000`00000000 fffffa80`0ad31f94 : fltmgr!FltpFastIoWrite+0x1ce
fffff880`0d443ab0 fffff800`02eb8993 : 00000000`00000901 00000000`00000000 00000000`00000000 00000000`00000000 : nt!NtWriteFile+0x5ad
fffff880`0d443bb0 00000000`755a2dd9 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0aeaf0f8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x755a2dd9
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!MiBadShareCount+4c
fffff800`02f4938c cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!MiBadShareCount+4c
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: X64_0x4E_99_nt!MiBadShareCount+4c
BUCKET_ID: X64_0x4E_99_nt!MiBadShareCount+4c
Followup: MachineOwner
---------