Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [D:\Kingston\BSODDmpFiles\BobbleHead\Windows_NT6_BSOD_jcgriff2\032412-30030-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17727.amd64fre.win7sp1_gdr.111118-2330
Machine Name:
Kernel base = 0xfffff800`03c4a000 PsLoadedModuleList = 0xfffff800`03e8e650
Debug session time: Sat Mar 24 22:05:00.190 2012 (UTC - 6:00)
System Uptime: 0 days 0:06:42.486
Loading Kernel Symbols
...............................................................
................................................................
...........................................
Loading User Symbols
Loading unloaded module list
................
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 24, {1904fb, fffff88003393758, fffff88003392fb0, fffff80003cd849a}
Probably caused by : Ntfs.sys ( Ntfs!NtfsTeardownFromLcb+fb )
Followup: MachineOwner
---------
3: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
NTFS_FILE_SYSTEM (24)
If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
parameters are the exception record and context record. Do a .cxr
on the 3rd parameter and then kb to obtain a more informative stack
trace.
Arguments:
Arg1: 00000000001904fb
Arg2: fffff88003393758
Arg3: fffff88003392fb0
Arg4: fffff80003cd849a
Debugging Details:
------------------
EXCEPTION_RECORD: fffff88003393758 -- (.exr 0xfffff88003393758)
ExceptionAddress: fffff80003cd849a (nt!ExAcquireFastMutex+0x000000000000001a)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000001
Parameter[1]: 0000000000000000
Attempt to write to address 0000000000000000
CONTEXT: fffff88003392fb0 -- (.cxr 0xfffff88003392fb0)
rax=0000000000000001 rbx=0000000000000000 rcx=0000000000000000
rdx=fffffa8006790b60 rsi=fffff88003393b01 rdi=0000000000000000
rip=fffff80003cd849a rsp=fffff88003393990 rbp=fffff80003e66260
r8=0000000000000000 r9=0000000000000000 r10=fffff80003c4a000
r11=fffff88003393990 r12=fffff8a00fdfeb40 r13=fffff8a00fd80940
r14=fffff8a00fdfee00 r15=0000000000000000
iopl=0 nv up ei ng nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010286
nt!ExAcquireFastMutex+0x1a:
fffff800`03cd849a f00fba3100 lock btr dword ptr [rcx],0 ds:002b:00000000`00000000=????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: NULL_DEREFERENCE
PROCESS_NAME: System
CURRENT_IRQL: 1
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_PARAMETER1: 0000000000000001
EXCEPTION_PARAMETER2: 0000000000000000
WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff80003ef8100
0000000000000000
FOLLOWUP_IP:
Ntfs!NtfsTeardownFromLcb+fb
fffff880`0125888b 83bfc000000000 cmp dword ptr [rdi+0C0h],0
FAULTING_IP:
nt!ExAcquireFastMutex+1a
fffff800`03cd849a f00fba3100 lock btr dword ptr [rcx],0
BUGCHECK_STR: 0x24
LAST_CONTROL_TRANSFER: from fffff8800125888b to fffff80003cd849a
STACK_TEXT:
fffff880`03393990 fffff880`0125888b : fffff8a0`0fdfeb40 fffff800`03e66260 fffff880`03393b01 fffff880`012e0cc1 : nt!ExAcquireFastMutex+0x1a
fffff880`033939c0 fffff880`012de63c : fffffa80`068b3490 fffffa80`08193180 fffff8a0`0fdfeb40 fffff8a0`0fdfeed8 : Ntfs!NtfsTeardownFromLcb+0xfb
fffff880`03393a50 fffff880`012600e2 : fffffa80`068b3490 fffffa80`068b3490 fffff8a0`0fdfeb40 00000000`00000000 : Ntfs!NtfsTeardownStructures+0xcc
fffff880`03393ad0 fffff880`012ee193 : fffffa80`068b3490 fffff800`03e66260 fffff8a0`0fdfeb40 00000000`00000009 : Ntfs!NtfsDecrementCloseCounts+0xa2
fffff880`03393b10 fffff880`012dd357 : fffffa80`068b3490 fffff8a0`0fdfec70 fffff8a0`0fdfeb40 fffffa80`08193180 : Ntfs!NtfsCommonClose+0x353
fffff880`03393be0 fffff800`03cd0471 : 00000000`00000000 fffff800`03fbc700 fffff800`03ec7800 fffff800`00000005 : Ntfs!NtfsFspClose+0x15f
fffff880`03393cb0 fffff800`03f60f7a : 00000000`00000000 fffffa80`06790b60 00000000`00000080 fffffa80`06710890 : nt!ExpWorkerThread+0x111
fffff880`03393d40 fffff800`03cb79c6 : fffff880`03164180 fffffa80`06790b60 fffff880`0316efc0 00000000`00000000 : nt!PspSystemThreadStartup+0x5a
fffff880`03393d80 00000000`00000000 : fffff880`03394000 fffff880`0338e000 fffff880`033939e0 00000000`00000000 : nt!KxStartSystemThread+0x16
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: Ntfs!NtfsTeardownFromLcb+fb
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Ntfs
IMAGE_NAME: Ntfs.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4d79997b
STACK_COMMAND: .cxr 0xfffff88003392fb0 ; kb
FAILURE_BUCKET_ID: X64_0x24_Ntfs!NtfsTeardownFromLcb+fb
BUCKET_ID: X64_0x24_Ntfs!NtfsTeardownFromLcb+fb
Followup: MachineOwner
---------