*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1A, {41790, fffffa8005a31c20, ffff, 0}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+35084 )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041790, A page table page has been corrupted. On a 64 bit OS, parameter 2
contains the address of the PFN for the corrupted page table page.
On a 32 bit OS, parameter 2 contains a pointer to the number of used
PTEs, and parameter 3 contains the number of used PTEs.
Arg2: fffffa8005a31c20
Arg3: 000000000000ffff
Arg4: 0000000000000000
Debugging Details:
------------------
BUGCHECK_STR: 0x1a_41790
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
PROCESS_NAME: explorer.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff80002ee8e10 to fffff80002e77c40
STACK_TEXT:
fffff880`0a65e828 fffff800`02ee8e10 : 00000000`0000001a 00000000`00041790 fffffa80`05a31c20 00000000`0000ffff : nt!KeBugCheckEx
fffff880`0a65e830 fffff800`02eaa8e9 : 00000000`00000000 00000000`6b3f5fff fffffa80`00000000 fffff800`02e80b7b : nt! ?? ::FNODOBFM::`string'+0x35084
fffff880`0a65e9f0 fffff800`031932e1 : fffffa80`0f6b4610 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MiRemoveMappedView+0xd9
fffff880`0a65eb10 fffff800`031936ef : 00000040`00000000 00000000`6a0a0000 fffffa80`00000001 fffffa80`0ed69f10 : nt!MiUnmapViewOfSection+0x1b1
fffff880`0a65ebd0 fffff800`02e76ed3 : fffffa80`0c73e060 00000000`00000000 fffffa80`0ed4c060 00000000`05b429f0 : nt!NtUnmapViewOfSection+0x5f
fffff880`0a65ec20 00000000`76f515ba : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`08a4e738 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x76f515ba
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+35084
fffff800`02ee8e10 cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+35084
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 50e79935
FAILURE_BUCKET_ID: X64_0x1a_41790_nt!_??_::FNODOBFM::_string_+35084
BUCKET_ID: X64_0x1a_41790_nt!_??_::FNODOBFM::_string_+35084
Followup: MachineOwner
---------