.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 34, {50830, fffff8800333f4b8, fffff8800333ed20, fffff80002eafe4b}
Probably caused by : ntkrnlmp.exe ( nt!RtlDeleteNoSplay+93 )
Followup: MachineOwner
---------
7: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
CACHE_MANAGER (34)
See the comment for FAT_FILE_SYSTEM (0x23)
Arguments:
Arg1: 0000000000050830
Arg2: fffff8800333f4b8
Arg3: fffff8800333ed20
Arg4: fffff80002eafe4b
Debugging Details:
------------------
EXCEPTION_RECORD: fffff8800333f4b8 -- (.exr 0xfffff8800333f4b8)
ExceptionAddress: fffff80002eafe4b (nt!RtlDeleteNoSplay+0x0000000000000093)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
CONTEXT: fffff8800333ed20 -- (.cxr 0xfffff8800333ed20)
rax=fffff8a015463748 rbx=fffffa800b74cfe8 rcx=0000800000000000
rdx=fffffa800b74cfe8 rsi=fffff8a015463748 rdi=0000000000000000
rip=fffff80002eafe4b rsp=fffff8800333f6f0 rbp=fffffa800b74cfe8
r8=ffffffffffffffff r9=ffffffffffffffff r10=0000000000000e34
r11=fffff8a015463748 r12=fffffa800b1e3280 r13=fffff8a015463748
r14=fffff8a015463748 r15=0000000000000001
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010246
nt!RtlDeleteNoSplay+0x93:
fffff800`02eafe4b 488909 mov qword ptr [rcx],rcx ds:002b:00008000`00000000=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: ffffffffffffffff
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800031040e0
GetUlongFromAddress: unable to read from fffff80003104198
ffffffffffffffff
FOLLOWUP_IP:
nt!RtlDeleteNoSplay+93
fffff800`02eafe4b 488909 mov qword ptr [rcx],rcx
FAULTING_IP:
nt!RtlDeleteNoSplay+93
fffff800`02eafe4b 488909 mov qword ptr [rcx],rcx
BUGCHECK_STR: 0x34
LAST_CONTROL_TRANSFER: from fffff8800107c1a3 to fffff80002eafe4b
STACK_TEXT:
fffff880`0333f6f0 fffff880`0107c1a3 : ffffffff`ffffffff fffffa80`0b74cfa8 fffffa80`0b74cf98 fffff880`0109a388 : nt!RtlDeleteNoSplay+0x93
fffff880`0333f720 fffff880`01079460 : fffffa80`0aed4d30 fffffa80`0b1e3280 fffffa80`07d29684 00000000`00000001 : fltmgr!TreeUnlinkMulti+0xb3
fffff880`0333f770 fffff880`01079be9 : fffff880`03338000 fffffa80`07b93d02 0000555f`cf300600 00000000`00000000 : fltmgr!FltpPerformPreCallbacks+0x730
fffff880`0333f870 fffff880`010786c7 : fffffa80`0b55a6c0 fffffa80`07b93de0 fffffa80`076897c0 00000000`00000000 : fltmgr!FltpPassThrough+0x2d9
fffff880`0333f8f0 fffff800`031deb0e : fffffa80`0b1e3280 fffffa80`07af5a20 fffff8a0`111ae760 fffffa80`07b93de0 : fltmgr!FltpDispatch+0xb7
fffff880`0333f950 fffff800`02ed1a54 : 00000000`00000000 00000000`00000000 fffffa80`06b9df30 00000000`00000001 : nt!IopDeleteFile+0x11e
fffff880`0333f9e0 fffff800`031b7f11 : 00000000`00000000 00000000`0008c081 fffffa80`07f4dc50 fffff8a0`0008c081 : nt!ObfDereferenceObject+0xd4
fffff880`0333fa40 fffff800`02ed1a54 : 00000000`00000000 00000000`00000002 fffffa80`06bb5f30 fffffa80`06bb5f30 : nt!MiSegmentDelete+0xa1
fffff880`0333fa80 fffff800`02ebc44c : 00000000`00000002 fffffa80`0af8bf20 00000000`00000000 00000000`00000000 : nt!ObfDereferenceObject+0xd4
fffff880`0333fae0 fffff800`02ebfe58 : fffffa80`081ed010 00000000`00000011 fffffa80`081ed010 fffffa80`00000000 : nt!CcDeleteSharedCacheMap+0x1bc
fffff880`0333fb50 fffff800`02ec0678 : fffff800`030d3100 fffff880`0333fc58 00000000`00000000 00000000`00000000 : nt!CcWriteBehind+0x5bc
fffff880`0333fc00 fffff800`02ed9b21 : fffffa80`06ba8800 fffff800`031c3220 fffff800`030d3160 00000000`00000000 : nt!CcWorkerThread+0x1c8
fffff880`0333fcb0 fffff800`0316b47a : 00000000`00000000 fffffa80`06ba3b60 00000000`00000080 fffffa80`06b68740 : nt!ExpWorkerThread+0x111
fffff880`0333fd40 fffff800`02eaada6 : fffff880`03186180 fffffa80`06ba3b60 fffff880`031910c0 00000000`00000000 : nt!PspSystemThreadStartup+0x5a
fffff880`0333fd80 00000000`00000000 : fffff880`03340000 fffff880`0333a000 fffff880`0333f320 00000000`00000000 : nt!KxStartSystemThread+0x16
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!RtlDeleteNoSplay+93
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 5147dc36
STACK_COMMAND: .cxr 0xfffff8800333ed20 ; kb
FAILURE_BUCKET_ID: X64_0x34_nt!RtlDeleteNoSplay+93
BUCKET_ID: X64_0x34_nt!RtlDeleteNoSplay+93
Followup: MachineOwner
---------