Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\a\Minidump\D M P\121510-27409-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`0300f000 PsLoadedModuleList = 0xfffff800`0324ce50
Debug session time: Wed Dec 15 03:52:04.138 2010 (UTC - 5:00)
System Uptime: 0 days 15:50:00.325
Loading Kernel Symbols
...............................................................
................................................................
..............................................
Loading User Symbols
Loading unloaded module list
..................................................
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1000007E, {ffffffffc0000005, fffff88001a07920, fffff880033b6958, fffff880033b61c0}
*** WARNING: Unable to verify timestamp for win32k.sys
*** ERROR: Module load completed but symbols could not be loaded for win32k.sys
Probably caused by : memory_corruption
Followup: memory_corruption
---------
3: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff88001a07920, The address that the exception occurred at
Arg3: fffff880033b6958, Exception Record Address
Arg4: fffff880033b61c0, Context Record Address
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text>
FAULTING_IP:
tcpip! ?? ::FNODOBFM::`string'+8a90
fffff880`01a07920 0000 add byte ptr [rax],al
EXCEPTION_RECORD: fffff880033b6958 -- (.exr 0xfffff880033b6958)
ExceptionAddress: fffff88001a07920 (tcpip! ?? ::FNODOBFM::`string'+0x0000000000008a90)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000001
Parameter[1]: 0000000000000000
Attempt to write to address 0000000000000000
CONTEXT: fffff880033b61c0 -- (.cxr 0xfffff880033b61c0)
rax=0000000000000000 rbx=fffffa800cb1b410 rcx=0000000000000003
rdx=fffffa800c6100e1 rsi=0000000000000003 rdi=fffffa800cb4a1f0
rip=fffff88001a07920 rsp=fffff880033b6b90 rbp=00000000c0010011
r8=fffffa800c6100e0 r9=0000000000000030 r10=fffff880031d5ac0
r11=fffffa800cb4a1f0 r12=0000000000000000 r13=0000000000000001
r14=0000000000000000 r15=0000000000000001
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010246
tcpip! ?? ::FNODOBFM::`string'+0x8a90:
fffff880`01a07920 0000 add byte ptr [rax],al ds:002b:00000000`00000000=??
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: CODE_CORRUPTION
PROCESS_NAME: System
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text>
EXCEPTION_PARAMETER1: 0000000000000001
EXCEPTION_PARAMETER2: 0000000000000000
WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff800032b70e0
0000000000000000
FOLLOWUP_IP:
tcpip! ?? ::FNODOBFM::`string'+8a90
fffff880`01a07920 0000 add byte ptr [rax],al
BUGCHECK_STR: 0x7E
LAST_CONTROL_TRANSFER: from fffff88001a828f0 to fffff88001a07920
STACK_TEXT:
fffff880`033b6b90 fffff880`01a828f0 : fffffa80`0cd47200 fffffa80`0cd47210 fffffa80`076ef080 fffffa80`0cb1b410 : tcpip! ?? ::FNODOBFM::`string'+0x8a90
fffff880`033b6be0 fffff880`01a0bed2 : fffffa80`04dd4e40 fffffa80`0cb1b410 fffffa80`0cb1b468 fffffa80`0cb1b468 : tcpip!FlpSerializedNdisAddGroupWorker+0x30
fffff880`033b6c30 fffff800`0337bc43 : fffffa80`04dd4e40 fffff800`032245f8 fffffa80`03e67040 fffffa80`03e67040 : tcpip!FlpSerializedNdisRequestWorkerRoutine+0x56
fffff880`033b6c80 fffff800`0308c961 : fffff800`03224500 fffff800`0337bc20 fffffa80`03e67040 fffffa80`03e67040 : nt!IopProcessWorkItem+0x23
fffff880`033b6cb0 fffff800`03323c06 : 00000000`00000000 fffffa80`03e67040 00000000`00000080 fffffa80`03e505f0 : nt!ExpWorkerThread+0x111
fffff880`033b6d40 fffff800`0305dc26 : fffff880`031d5180 fffffa80`03e67040 fffff880`031dffc0 00000000`00000000 : nt!PspSystemThreadStartup+0x5a
fffff880`033b6d80 00000000`00000000 : fffff880`033b7000 fffff880`033b1000 fffff880`033b69f0 00000000`00000000 : nt!KxStartSystemThread+0x16
CHKIMG_EXTENSION: !chkimg -lo 50 -d !tcpip
fffff88001a07920-fffff88001a07926 7 bytes - tcpip! ?? ::FNODOBFM::`string'+8a90
[ 85 c0 0f 85 01 ad 07:00 00 00 00 9c 10 00 ]
fffff88001a07928-fffff88001a0793b 20 bytes - tcpip! ?? ::FNODOBFM::`string'+8a98 (+0x08)
[ 83 c9 04 4c 8d 4c 24 58:00 00 00 00 00 00 00 00 ]
fffff88001a0793d-fffff88001a07943 7 bytes - tcpip! ?? ::FNODOBFM::`string'+8aad (+0x15)
[ 48 8b cb 4c 89 64 24:00 00 00 01 00 00 00 ]
34 errors : !tcpip (fffff88001a07920-fffff88001a07943)
MODULE_NAME: memory_corruption
IMAGE_NAME: memory_corruption
FOLLOWUP_NAME: memory_corruption
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MEMORY_CORRUPTOR: LARGE
STACK_COMMAND: .cxr 0xfffff880033b61c0 ; kb
FAILURE_BUCKET_ID: X64_MEMORY_CORRUPTION_LARGE
BUCKET_ID: X64_MEMORY_CORRUPTION_LARGE
Followup: memory_corruption
---------
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\a\Minidump\D M P\121510-76019-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`03059000 PsLoadedModuleList = 0xfffff800`03296e50
Debug session time: Wed Dec 15 12:15:05.390 2010 (UTC - 5:00)
System Uptime: 0 days 7:54:29.967
Loading Kernel Symbols
...............................................................
................................................................
...............................................
Loading User Symbols
Loading unloaded module list
...................
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 19, {3, fffff8800401ba70, 6afb86f92ab2229, f3b801c4459ef48b}
Probably caused by : Pool_Corruption ( nt!ExDeferredFreePool+a56 )
Followup: Pool_corruption
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
BAD_POOL_HEADER (19)
The pool is already corrupt at the time of the current request.
This may or may not be due to the caller.
The internal pool links must be walked to figure out a possible cause of
the problem, and then special pool applied to the suspect tags or the driver
verifier to a suspect driver.
Arguments:
Arg1: 0000000000000003, the pool freelist is corrupt.
Arg2: fffff8800401ba70, the pool entry being checked.
Arg3: 06afb86f92ab2229, the read back flink freelist value (should be the same as 2).
Arg4: f3b801c4459ef48b, the read back blink freelist value (should be the same as 2).
Debugging Details:
------------------
BUGCHECK_STR: 0x19_3
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: explorer.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff800031fcd6f to fffff800030c9740
STACK_TEXT:
fffff880`0d1bd938 fffff800`031fcd6f : 00000000`00000019 00000000`00000003 fffff880`0401ba70 06afb86f`92ab2229 : nt!KeBugCheckEx
fffff880`0d1bd940 fffff960`0019512e : 00000000`00000000 fffff900`c48803e0 00000000`6c777355 00000000`00000000 : nt!ExDeferredFreePool+0xa56
fffff880`0d1bda30 fffff960`000edb71 : fffff900`c48803e0 00000000`00000002 00000000`00000c18 00000000`00000002 : win32k!UserReAllocPoolWithTag+0x2e
fffff880`0d1bda60 fffff960`000eda0a : 00000000`00000000 fffff900`c0e08480 00000000`00000000 00000000`0000007f : win32k!InternalBuildHwndList+0x69
fffff880`0d1bda90 fffff960`00167f96 : 00000000`00000000 fffff880`0d1bdca0 00000000`00000000 00000000`00000000 : win32k!BuildHwndList+0x76
fffff880`0d1bdac0 fffff960`00140153 : 00000000`00000000 00000000`00000000 00000000`0000c0db 00000000`00000000 : win32k!FindWindowEx+0xda
fffff880`0d1bdb30 fffff800`030c8993 : fffffa80`0c04cb60 00000000`08d8d8c8 fffff880`0d1bdbc8 00000000`00000003 : win32k!NtUserFindWindowEx+0x167
fffff880`0d1bdbb0 00000000`776d020a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`08d8d8a8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x776d020a
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!ExDeferredFreePool+a56
fffff800`031fcd6f cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!ExDeferredFreePool+a56
FOLLOWUP_NAME: Pool_corruption
IMAGE_NAME: Pool_Corruption
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MODULE_NAME: Pool_Corruption
FAILURE_BUCKET_ID: X64_0x19_3_nt!ExDeferredFreePool+a56
BUCKET_ID: X64_0x19_3_nt!ExDeferredFreePool+a56
Followup: Pool_corruption
---------
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\a\Minidump\D M P\121610-26738-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`0305e000 PsLoadedModuleList = 0xfffff800`0329be50
Debug session time: Thu Dec 16 04:52:42.411 2010 (UTC - 5:00)
System Uptime: 0 days 16:37:01.987
Loading Kernel Symbols
...............................................................
................................................................
..........................................
Loading User Symbols
Loading unloaded module list
................................
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {fffff800193f50df, 8, fffff800193f50df, 2}
Could not read faulting driver name
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+40ec0 )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: fffff800193f50df, memory referenced.
Arg2: 0000000000000008, value 0 = read operation, 1 = write operation.
Arg3: fffff800193f50df, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000002, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff800033060e0
fffff800193f50df
FAULTING_IP:
+3937333939616430
fffff800`193f50df ?? ???
MM_INTERNAL_CODE: 2
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 0
TRAP_FRAME: fffff88002b42200 -- (.trap 0xfffff88002b42200)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffff8a00da82b80 rbx=0000000000000000 rcx=fffff8a00dce9f51
rdx=fffff8a00da82b81 rsi=0000000000000000 rdi=0000000000000000
rip=fffff800193f50df rsp=fffff88002b42390 rbp=fffffa8003ddd000
r8=fffff8a00da82b80 r9=fffff8000305e000 r10=fffff88003165a20
r11=fffff88002b424b0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na pe nc
fffff800`193f50df ?? ???
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff8000314d8f2 to fffff800030ce740
STACK_TEXT:
fffff880`02b42098 fffff800`0314d8f2 : 00000000`00000050 fffff800`193f50df 00000000`00000008 fffff880`02b42200 : nt!KeBugCheckEx
fffff880`02b420a0 fffff800`030cc82e : 00000000`00000008 fffff8a0`0da82b80 fffff8a0`00020200 fffff880`02b426c4 : nt! ?? ::FNODOBFM::`string'+0x40ec0
fffff880`02b42200 fffff800`193f50df : 00000000`00000000 fffffa80`0b1651a0 fffff880`02b426f0 fffffa80`04ca8780 : nt!KiPageFault+0x16e
fffff880`02b42390 00000000`00000000 : fffffa80`0b1651a0 fffff880`02b426f0 fffffa80`04ca8780 fffff800`030ca576 : 0xfffff800`193f50df
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+40ec0
fffff800`0314d8f2 cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+40ec0
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
FAILURE_BUCKET_ID: X64_0x50_nt!_??_::FNODOBFM::_string_+40ec0
BUCKET_ID: X64_0x50_nt!_??_::FNODOBFM::_string_+40ec0
Followup: MachineOwner
---------