Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\K\Desktop\Windows7_BSOD_jcgriff2\080310-26660-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\symbols;srv*e:\symbols
*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16539.amd64fre.win7_gdr.100226-1909
Machine Name:
Kernel base = 0xfffff800`03005000 PsLoadedModuleList = 0xfffff800`03242e50
Debug session time: Tue Aug 3 16:47:14.805 2010 (GMT-4)
System Uptime: 0 days 0:53:03.914
Loading Kernel Symbols
.
Press ctrl-c (cdb, kd, ntsd) or ctrl-break (windbg) to abort symbol loads that take too long.
Run !sym noisy before .reload to track down problems loading symbols.
..............................................................
................................................................
.........................................................
Loading User Symbols
Loading unloaded module list
.......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck C5, {fffff8800dce8890, 2, 0, fffff800031a90cd}
Unable to load image \SystemRoot\system32\drivers\NISx64\1107000.00C\SYMEFA64.SYS, Win32 error 0n2
*** WARNING: Unable to verify timestamp for SYMEFA64.SYS
*** ERROR: Module load completed but symbols could not be loaded for SYMEFA64.SYS
Probably caused by : Pool_Corruption ( nt!ExDeferredFreePool+241 )
Followup: Pool_corruption
---------
6: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_CORRUPTED_EXPOOL (c5)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is
caused by drivers that have corrupted the system pool. Run the driver
verifier against any new (or suspect) drivers, and if that doesn't turn up
the culprit, then use gflags to enable special pool.
Arguments:
Arg1: fffff8800dce8890, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, value 0 = read operation, 1 = write operation
Arg4: fffff800031a90cd, address which referenced memory
Debugging Details:
------------------
BUGCHECK_STR: 0xC5_2
CURRENT_IRQL: 2
FAULTING_IP:
nt!ExDeferredFreePool+241
fffff800`031a90cd 4c3910 cmp qword ptr [rax],r10
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: ccsvchst.exe
IRP_ADDRESS: ffffffffffffff89
TRAP_FRAME: fffff8800a402550 -- (.trap 0xfffff8800a402550)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffff8800dce8890 rbx=0000000000000000 rcx=fffffa800dce6890
rdx=fffffa800f62a000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff800031a90cd rsp=fffff8800a4026e0 rbp=000000000000000d
r8=fffffa800dce8010 r9=fffffa800f62a880 r10=fffffa800f62a890
r11=0000000000000001 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
nt!ExDeferredFreePool+0x241:
fffff800`031a90cd 4c3910 cmp qword ptr [rax],r10 ds:cbf8:fffff880`0dce8890=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80003074b69 to fffff80003075600
STACK_TEXT:
fffff880`0a402408 fffff800`03074b69 : 00000000`0000000a fffff880`0dce8890 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
fffff880`0a402410 fffff800`030737e0 : fffffa80`0dfaa590 00000000`00000000 fffff880`0128b100 00000000`00000001 : nt!KiBugCheckDispatch+0x69
fffff880`0a402550 fffff800`031a90cd : fffff8a0`08b36760 fffff8a0`0d34a498 fffffa80`0d0be660 fffff880`0128e120 : nt!KiPageFault+0x260
fffff880`0a4026e0 fffff800`031aa4c1 : fffffa80`0dce6000 fffffa80`0dce6000 00000000`00000000 fffff880`012a9000 : nt!ExDeferredFreePool+0x241
fffff880`0a402770 fffff800`03094c6e : 00000000`a0000003 fffff8a0`0895e820 fffffa80`20206f49 fffff880`0a402ca0 : nt!ExFreePoolWithTag+0x411
fffff880`0a402820 fffff800`03077fdd : 00000000`00000001 fffff880`0128bd60 fffff880`0a402901 fffff880`0a402900 : nt!IopCompleteRequest+0x5ce
fffff880`0a4028f0 fffff880`01293e63 : fffffa80`0dce6040 fffffa80`0b74f400 00000000`00000000 00000000`00000000 : nt!IopfCompleteRequest+0x75d
fffff880`0a4029d0 fffffa80`0dce6040 : fffffa80`0b74f400 00000000`00000000 00000000`00000000 00000000`00000064 : SYMEFA64+0x11e63
fffff880`0a4029d8 fffffa80`0b74f400 : 00000000`00000000 00000000`00000000 00000000`00000064 00000000`00000800 : 0xfffffa80`0dce6040
fffff880`0a4029e0 00000000`00000000 : 00000000`00000000 00000000`00000064 00000000`00000800 fffffa80`0b74f330 : 0xfffffa80`0b74f400
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!ExDeferredFreePool+241
fffff800`031a90cd 4c3910 cmp qword ptr [rax],r10
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: nt!ExDeferredFreePool+241
FOLLOWUP_NAME: Pool_corruption
IMAGE_NAME: Pool_Corruption
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MODULE_NAME: Pool_Corruption
FAILURE_BUCKET_ID: X64_0xC5_2_nt!ExDeferredFreePool+241
BUCKET_ID: X64_0xC5_2_nt!ExDeferredFreePool+241
Followup: Pool_corruption
---------