Windows 7 Kernel Version 7600 MP (4 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16617.x86fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0x82e17000 PsLoadedModuleList = 0x82f5f810
Debug session time: Sun Nov 21 19:26:40.318 2010 (GMT-5)
System Uptime: 0 days 5:00:52.004
Loading Kernel Symbols
...............................................................
................................................................
................................................
Loading User Symbols
Loading unloaded module list
..................
Unable to load image \??\C:\Program Files\GameClub\Philippines\SpecialForce\GameGuard\dump_wmimmc.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for dump_wmimmc.sys
*** ERROR: Module load completed but symbols could not be loaded for dump_wmimmc.sys
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1000008E, {c0000005, b018d4be, e258aba0, 0}
Probably caused by : dump_wmimmc.sys
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KERNEL_MODE_EXCEPTION_NOT_HANDLED_M (1000008e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: c0000005, The exception code that was not handled
Arg2: b018d4be, The address that the exception occurred at
Arg3: e258aba0, Trap Frame
Arg4: 00000000
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
dump_wmimmc+14be
b018d4be c7401000000000 mov dword ptr [eax+10h],0
TRAP_FRAME: e258aba0 -- (.trap 0xffffffffe258aba0)
ErrCode = 00000003
eax=00410057 ebx=83074510 ecx=00000000 edx=c0000000 esi=0b7dfe08 edi=000004b4
eip=b018d4be esp=e258ac14 ebp=e258ac34 iopl=0 nv up ei pl zr na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010246
dump_wmimmc+0x14be:
b018d4be c7401000000000 mov dword ptr [eax+10h],0 ds:0023:00410067=????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: CODE_CORRUPTION
BUGCHECK_STR: 0x8E
PROCESS_NAME: specialforce.e
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from b018d62c to b018d4be
STACK_TEXT:
WARNING: Stack unwind information not available. Following frames may be wrong.
e258ac34 b018d62c 88db2468 8a52f958 88db2468 dump_wmimmc+0x14be
e258ac50 b018df05 88de9760 00000000 000004b4 dump_wmimmc+0x162c
e258ac88 b019087e 000004b4 00012024 000004b4 dump_wmimmc+0x1f05
e258accc b0190996 74dc64b4 000004b4 00012024 dump_wmimmc+0x487e
e258ad34 772464f4 badb0d00 0b7dfde0 00000000 dump_wmimmc+0x4996
e258ad38 badb0d00 0b7dfde0 00000000 00000000 0x772464f4
e258ad3c 0b7dfde0 00000000 00000000 00000000 0xbadb0d00
e258ad40 00000000 00000000 00000000 00000000 0xb7dfde0
STACK_COMMAND: kb
CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
83074510-83074514 5 bytes - nt!NtDeviceIoControlFile
[ 8b ff 55 8b ec:e9 6b c4 11 2d ]
5 errors : !nt (83074510-83074514)
MODULE_NAME: dump_wmimmc
IMAGE_NAME: dump_wmimmc.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4ca16f18
FOLLOWUP_NAME: MachineOwner
MEMORY_CORRUPTOR: PATCH_dump_wmimmc
FAILURE_BUCKET_ID: MEMORY_CORRUPTION_PATCH_dump_wmimmc
BUCKET_ID: MEMORY_CORRUPTION_PATCH_dump_wmimmc
Followup: MachineOwner
---------
Debug session time: Sun Nov 21 09:27:13.587 2010 (GMT-5)
System Uptime: 0 days 1:37:20.050
Loading Kernel Symbols
...............................................................
................................................................
..................................................
Loading User Symbols
Loading unloaded module list
...........
2: kd> !Analyze
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck F4, {3, 896eb030, 896eb19c, 82e3add0}
*** WARNING: Unable to verify timestamp for klif.sys
*** ERROR: Module load completed but symbols could not be loaded for klif.sys
Probably caused by : csrss.exe
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
CRITICAL_OBJECT_TERMINATION (f4)
A process or thread crucial to system operation has unexpectedly exited or been
terminated.
Several processes and threads are necessary for the operation of the
system; when they are terminated (for any reason), the system can no
longer function.
Arguments:
Arg1: 00000003, Process
Arg2: 896eb030, Terminating object
Arg3: 896eb19c, Process image file name
Arg4: 82e3add0, Explanatory message (ascii)
Debugging Details:
------------------
PROCESS_OBJECT: 896eb030
IMAGE_NAME: csrss.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MODULE_NAME: csrss
FAULTING_MODULE: 00000000
PROCESS_NAME: csrss.exe
EXCEPTION_RECORD: 960ffce0 -- (.exr 0xffffffff960ffce0)
ExceptionAddress: 458a9a94
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 00000000
Parameter[1]: 0100fbf1
Attempt to read from address 0100fbf1
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_PARAMETER1: 00000000
EXCEPTION_PARAMETER2: 0100fbf1
READ_ADDRESS: GetPointerFromAddress: unable to read from 82d7a718
Unable to read MiSystemVaType memory at 82d5a160
0100fbf1
FOLLOWUP_IP:
+6143952f00dad984
458a9a94 ?? ???
FAULTING_IP:
+6143952f00dad984
458a9a94 ?? ???
FAILED_INSTRUCTION_ADDRESS:
+6143952f00dad984
458a9a94 ?? ???
BUGCHECK_STR: 0xF4_C0000005
STACK_TEXT:
960ff784 82eee0d7 000000f4 00000003 896eb030 nt!KeBugCheckEx+0x1e
960ff7a8 82e71ed2 82e3add0 896eb19c 896eb2a0 nt!PspCatchCriticalBreak+0x71
960ff7d8 82e73d6f 896eb030 85e97d48 c0000005 nt!PspTerminateAllThreads+0x2d
960ff80c 90169019 ffffffff c0000005 960ff8c0 nt!NtTerminateProcess+0x1a2
WARNING: Stack unwind information not available. Following frames may be wrong.
960ff830 82c5544a ffffffff c0000005 960ffcc4 klif+0x20019
960ff830 82c546ad ffffffff c0000005 960ffcc4 nt!KiFastCallEntry+0x12a
960ff8b0 82ccf66f ffffffff c0000005 0001003f nt!ZwTerminateProcess+0x11
960ffcc4 82c56036 960ffce0 00000000 960ffd34 nt!KiDispatchException+0x497
960ffd2c 82c55fea 0101fc4c 458a9a94 badb0d00 nt!CommonDispatchException+0x4a
960ffd34 458a9a94 badb0d00 0000004c 00000000 nt!Kei386EoiHelper+0x192
960ffd38 badb0d00 0000004c 00000000 00000000 0x458a9a94
960ffd3c 00000000 00000000 00000000 00000000 0xbadb0d00
STACK_COMMAND: kb
FOLLOWUP_NAME: MachineOwner
FAILURE_BUCKET_ID: 0xF4_C0000005_IMAGE_csrss.exe
BUCKET_ID: 0xF4_C0000005_IMAGE_csrss.exe
Followup: MachineOwner
---------
Debug session time: Mon Nov 15 09:10:29.805 2010 (GMT-5)
System Uptime: 0 days 4:14:03.491
Loading Kernel Symbols
...............................................................
................................................................
................................................
Loading User Symbols
Loading unloaded module list
...........
3: kd> !Analyze
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 24, {c08a2, 0, 0, 0}
Probably caused by : Ntfs.sys ( Ntfs!NtfsPagingFileIo+138 )
Followup: MachineOwner
---------
3: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
NTFS_FILE_SYSTEM (24)
If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
parameters are the exception record and context record. Do a .cxr
on the 3rd parameter and then kb to obtain a more informative stack
trace.
Arguments:
Arg1: 000c08a2
Arg2: 00000000
Arg3: 00000000
Arg4: 00000000
Debugging Details:
------------------
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x24
PROCESS_NAME: rundll32.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 8b04f97c to 82ceed10
STACK_TEXT:
8d05e800 8b04f97c 00000024 000c08a2 00000000 nt!KeBugCheckEx+0x1e
8d05e8bc 8b04e9e1 00001000 8994aa78 0602a21c Ntfs!NtfsPagingFileIo+0x138
8d05e92c 82c4e4bc 86cbd020 8c393008 8c393008 Ntfs!NtfsFsdRead+0xac
8d05e944 8af2f20c 86cca528 8c393008 00000000 nt!IofCallDriver+0x63
8d05e968 8af2f3cb 8d05e988 86cca528 00000000 fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x2aa
8d05e9a0 82c4e4bc 86cca528 8c393008 8c393008 fltmgr!FltpDispatch+0xc5
8d05e9b8 82cb7010 8c44c0d1 8c44c058 88c16a6a nt!IofCallDriver+0x63
8d05e9d4 82e230e2 88c16a68 d6424478 8c44c090 nt!IoPageRead+0x1f5
8d05ea08 82e24dce 00000000 00000000 aec80564 nt!MiPfExecuteReadList+0x10c
8d05ea38 82e29b6b 00000023 d8a46618 00000005 nt!MmPrefetchPages+0xf3
8d05eab4 82e9c5b7 0105ead4 00000000 00000000 nt!PfSnPrefetchSections+0x34c
8d05ec34 82e6ab56 aec80000 8d05ec64 8d05ec70 nt!PfSnPrefetchScenario+0x193
8d05ecc8 82e97266 82e75a4d 85f49c70 8d05ed20 nt!PfSnBeginAppLaunch+0x382
8d05ecd8 82e9176d afda06e2 00000000 00000000 nt!PfProcessCreateNotification+0x65
8d05ed20 82cd20f9 00000000 772464d8 00000001 nt!PspUserThreadStartup+0x113
00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x19
STACK_COMMAND: kb
FOLLOWUP_IP:
Ntfs!NtfsPagingFileIo+138
8b04f97c 0fbe8720010000 movsx eax,byte ptr [edi+120h]
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: Ntfs!NtfsPagingFileIo+138
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Ntfs
IMAGE_NAME: Ntfs.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bbf45
FAILURE_BUCKET_ID: 0x24_Ntfs!NtfsPagingFileIo+138
BUCKET_ID: 0x24_Ntfs!NtfsPagingFileIo+138
Followup: MachineOwner
---------