[list=1]
[*]
Loading Dump File [C:\Users\Mike\Downloads\BSODDmpFiles\Ellendway\Windows_NT6_BSOD_jcgriff2\011612-20014-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\users\mike\documents\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (6 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`03207000 PsLoadedModuleList = 0xfffff800`0344c670
Debug session time: Mon Jan 16 12:30:59.731 2012 (UTC - 7:00)
System Uptime: 0 days 5:24:15.871
Loading Kernel Symbols
...............................................................
................................................................
.............................
Loading User Symbols
Loading unloaded module list
......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {fffff96000600001, 8, fffff96000600001, 0}
Could not read faulting driver name
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+4611f )
Followup: MachineOwner
---------
3: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: fffff96000600001, memory referenced.
Arg2: 0000000000000008, value 0 = read operation, 1 = write operation.
Arg3: fffff96000600001, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000000, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff800034b6100
fffff96000600001
FAULTING_IP:
+3034323862323064
fffff960`00600001 ?? ???
MM_INTERNAL_CODE: 0
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: perfmon.exe
CURRENT_IRQL: 0
TRAP_FRAME: fffff88003f08e20 -- (.trap 0xfffff88003f08e20)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffffa8006e71601 rbx=0000000000000000 rcx=fffffa8006e71601
rdx=fffffa800963a200 rsi=0000000000000000 rdi=0000000000000000
rip=fffff96000600001 rsp=fffff88003f08fb0 rbp=fffff88003f09520
r8=fffffa8009691e30 r9=00000000000000a0 r10=fffff88002fd5d60
r11=fffffa8006cc3e10 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na pe nc
fffff960`00600001 ?? ???
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff8000322f9fc to fffff80003283c40
STACK_TEXT:
fffff880`03f08cb8 fffff800`0322f9fc : 00000000`00000050 fffff960`00600001 00000000`00000008 fffff880`03f08e20 : nt!KeBugCheckEx
fffff880`03f08cc0 fffff800`03281d6e : 00000000`00000008 fffff960`00600001 00000000`00000000 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x4611f
fffff880`03f08e20 fffff960`00600001 : fffffa80`06aff570 00000000`00000001 00000000`00000000 fffffa80`06e71601 : nt!KiPageFault+0x16e
fffff880`03f08fb0 fffffa80`06aff570 : 00000000`00000001 00000000`00000000 fffffa80`06e71601 00000000`06a00101 : 0xfffff960`00600001
fffff880`03f08fb8 00000000`00000001 : 00000000`00000000 fffffa80`06e71601 00000000`06a00101 00000000`00000000 : 0xfffffa80`06aff570
fffff880`03f08fc0 00000000`00000000 : fffffa80`06e71601 00000000`06a00101 00000000`00000000 00000000`00000000 : 0x1
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+4611f
fffff800`0322f9fc cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+4611f
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4e02aaa3
FAILURE_BUCKET_ID: X64_0x50_nt!_??_::FNODOBFM::_string_+4611f
BUCKET_ID: X64_0x50_nt!_??_::FNODOBFM::_string_+4611f
Followup: MachineOwner
---------
[*]
Loading Dump File [C:\Users\Mike\Downloads\BSODDmpFiles\Ellendway\Windows_NT6_BSOD_jcgriff2\011712-30232-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\users\mike\documents\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (6 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`0321a000 PsLoadedModuleList = 0xfffff800`0345f670
Debug session time: Tue Jan 17 04:12:21.146 2012 (UTC - 7:00)
System Uptime: 0 days 0:01:30.301
Loading Kernel Symbols
...............................................................
................................................................
.......
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck F4, {3, fffffa800962eb30, fffffa800962ee10, fffff8000359a8b0}
Probably caused by : csrss.exe
Followup: MachineOwner
---------
3: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
CRITICAL_OBJECT_TERMINATION (f4)
A process or thread crucial to system operation has unexpectedly exited or been
terminated.
Several processes and threads are necessary for the operation of the
system; when they are terminated (for any reason), the system can no
longer function.
Arguments:
Arg1: 0000000000000003, Process
Arg2: fffffa800962eb30, Terminating object
Arg3: fffffa800962ee10, Process image file name
Arg4: fffff8000359a8b0, Explanatory message (ascii)
Debugging Details:
------------------
PROCESS_OBJECT: fffffa800962eb30
IMAGE_NAME: csrss.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MODULE_NAME: csrss
FAULTING_MODULE: 0000000000000000
PROCESS_NAME: csrss.exe
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
BUGCHECK_STR: 0xF4_C0000005
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
CURRENT_IRQL: 0
STACK_TEXT:
fffff880`03307b58 fffff800`036215e2 : 00000000`000000f4 00000000`00000003 fffffa80`0962eb30 fffffa80`0962ee10 : nt!KeBugCheckEx
fffff880`03307b60 fffff800`035ce99b : ffffffff`ffffffff fffffa80`09354b60 fffffa80`0962eb30 fffffa80`0962eb30 : nt!PspCatchCriticalBreak+0x92
fffff880`03307ba0 fffff800`0354e448 : ffffffff`ffffffff 00000000`00000001 fffffa80`0962eb30 fffffa80`00000008 : nt! ?? ::NNGAKEGL::`string'+0x176d6
fffff880`03307bf0 fffff800`03295ed3 : fffffa80`0962eb30 fffff980`c0000005 fffffa80`09354b60 fffff980`014431f8 : nt!NtTerminateProcess+0xf4
fffff880`03307c70 fffff800`03292470 : fffff800`032e267f fffff880`03308a00 fffff880`03308340 fffff880`03308c20 : nt!KiSystemServiceCopyEnd+0x13
fffff880`03307e08 fffff800`032e267f : fffff880`03308a00 fffff880`03308340 fffff880`03308c20 00000000`00000002 : nt!KiServiceLinkage
fffff880`03307e10 fffff800`032e4af8 : fffff880`03308a00 fffff880`03308a00 fffff880`03308c20 fffff880`033084e0 : nt! ?? ::FNODOBFM::`string'+0x49874
fffff880`033084b0 fffff800`032989fb : fffff880`03308a00 fffffa80`09354b60 00000000`003d1e88 fffff880`03308bc0 : nt!KiRaiseException+0x1b4
fffff880`03308ae0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!NtRaiseException+0x7b
STACK_COMMAND: kb
FOLLOWUP_NAME: MachineOwner
FAILURE_BUCKET_ID: X64_0xF4_C0000005_IMAGE_csrss.exe
BUCKET_ID: X64_0xF4_C0000005_IMAGE_csrss.exe
Followup: MachineOwner
---------
[/list]