Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\Jonathan\AppData\Local\Temp\Temp1_073110-22245-01.zip\073110-22245-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16539.amd64fre.win7_gdr.100226-1909
Machine Name:
Kernel base = 0xfffff800`03056000 PsLoadedModuleList = 0xfffff800`03293e50
Debug session time: Sat Jul 31 14:17:46.118 2010 (UTC - 4:00)
System Uptime: 0 days 0:00:52.554
Loading Kernel Symbols
...............................................................
................................................................
..........................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck BE, {fffff8800158c8a8, 43be121, fffff880084a07b0, a}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+409f4 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
ATTEMPTED_WRITE_TO_READONLY_MEMORY (be)
An attempt was made to write to readonly memory. The guilty driver is on the
stack trace (and is typically the current instruction pointer).
When possible, the guilty driver's name (Unicode string) is printed on
the bugcheck screen and saved in KiBugCheckDriver.
Arguments:
Arg1: fffff8800158c8a8, Virtual address for the attempted write.
Arg2: 00000000043be121, PTE contents.
Arg3: fffff880084a07b0, (reserved)
Arg4: 000000000000000a, (reserved)
Debugging Details:
------------------
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VERIFIER_ENABLED_VISTA_MINIDUMP
BUGCHECK_STR: 0xBE
PROCESS_NAME: CCC.exe
CURRENT_IRQL: 2
TRAP_FRAME: fffff880084a07b0 -- (.trap 0xfffff880084a07b0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000072ed8 rbx=0000000000000000 rcx=fdffffffffffffff
rdx=0000000000000043 rsi=0000000000000000 rdi=0000000000000000
rip=fffff800030ebb92 rsp=fffff880084a0940 rbp=fffffa8003f021c0
r8=fffff80003300400 r9=fffffa8003f00000 r10=fffffa8003f021e0
r11=fffff880084a0998 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz ac po cy
nt!MiReplenishPageSlist+0x23c:
fffff800`030ebb92 48214b28 and qword ptr [rbx+28h],rcx ds:00000000`00000028=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80003145388 to fffff800030c6600
STACK_TEXT:
fffff880`084a0648 fffff800`03145388 : 00000000`000000be fffff880`0158c8a8 00000000`043be121 fffff880`084a07b0 : nt!KeBugCheckEx
fffff880`084a0650 fffff800`030c46ee : fffffa80`0158c880 fffff880`0158c880 fffff800`03424000 fffff800`033b7000 : nt! ?? ::FNODOBFM::`string'+0x409f4
fffff880`084a07b0 fffff800`030ebb92 : ffffffff`ffffffff fffffa80`07e85400 00000000`00000000 00000000`000000fb : nt!KiPageFault+0x16e
fffff880`084a0940 fffff800`030ebf8f : fffff800`03300400 00000000`000000d8 fffffa80`01592880 fffffa80`0158f880 : nt!MiReplenishPageSlist+0x23c
fffff880`084a09a0 fffff800`030e197a : fffff680`000fbc48 00000000`00000002 00000000`00000000 ffffffff`ffffffff : nt!MiRemoveAnyPage+0x24f
fffff880`084a0ac0 fffff800`030c46ee : 00000000`00000001 00000000`1f788ff0 00000000`00000001 00000000`00000018 : nt!MmAccessFault+0x169a
fffff880`084a0c20 000007fe`f58037f2 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x16e
00000000`1cffabd0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7fe`f58037f2
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+409f4
fffff800`03145388 cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+409f4
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4b88cfeb
FAILURE_BUCKET_ID: X64_0xBE_VRF_nt!_??_::FNODOBFM::_string_+409f4
BUCKET_ID: X64_0xBE_VRF_nt!_??_::FNODOBFM::_string_+409f4
Followup: MachineOwner
---------