1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
NTFS_FILE_SYSTEM (24)
If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
parameters are the exception record and context record. Do a .cxr
on the 3rd parameter and then kb to obtain a more informative stack
trace.
Arguments:
Arg1: 001904fb
Arg2: 8d9ea7bc
Arg3: 8d9ea3a0
Arg4: 8b83edf7
Debugging Details:
------------------
EXCEPTION_RECORD: 8d9ea7bc -- (.exr 0xffffffff8d9ea7bc)
ExceptionAddress: 8b83edf7 (Ntfs!NtfsCommonWrite+0x00001c0e)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 00000000
Parameter[1]: 50fb2fa4
Attempt to read from address 50fb2fa4
CONTEXT: 8d9ea3a0 -- (.cxr 0xffffffff8d9ea3a0)
eax=8b8cb004 ebx=93f5a908 ecx=00000000 edx=93f5a818 esi=8577e340 edi=002e0000
eip=8b83edf7 esp=8d9ea884 ebp=8d9ea978 iopl=0 nv up ei pl zr na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010246
Ntfs!NtfsCommonWrite+0x1c0e:
8b83edf7 58 pop eax
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_PARAMETER1: 00000000
EXCEPTION_PARAMETER2: 50fb2fa4
READ_ADDRESS: GetPointerFromAddress: unable to read from 82b7f718
Unable to read MiSystemVaType memory at 82b5f160
50fb2fa4
FOLLOWUP_IP:
Ntfs!NtfsCommonWrite+1c0e
8b83edf7 58 pop eax
FAULTING_IP:
Ntfs!NtfsCommonWrite+1c0e
8b83edf7 58 pop eax
BUGCHECK_STR: 0x24
MISALIGNED_IP:
Ntfs!NtfsCommonWrite+1c0e
8b83edf7 58 pop eax
LAST_CONTROL_TRANSFER: from 8b84085f to 8b83edf7
STACK_TEXT:
8d9ea978 8b84085f 8577e340 85641008 06187283 Ntfs!NtfsCommonWrite+0x1c0e
8d9ea9f0 82a534bc 85fe0020 85641008 85641008 Ntfs!NtfsFsdWrite+0x2e1
8d9eaa08 8b78920c 86953218 85641008 00000000 nt!IofCallDriver+0x63
8d9eaa2c 8b7893cb 8d9eaa4c 86953218 00000000 fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x2aa
8d9eaa64 82a534bc 86953218 85641008 85641008 fltmgr!FltpDispatch+0xc5
8d9eaa7c 82c54f4e 864e3ed8 85641008 856411e0 nt!IofCallDriver+0x63
8d9eaa9c 82c55802 86953218 864e3ed8 00000001 nt!IopSynchronousServiceTail+0x1f8
8d9eab38 82a5a41a 86953218 00000000 00000000 nt!NtWriteFile+0x6e8
8d9eab38 82a59879 86953218 00000000 00000000 nt!KiFastCallEntry+0x12a
8d9eabd4 82c066a4 8000006c 00000000 00000000 nt!ZwWriteFile+0x11
8d9eac1c 82c57fac 85d4d000 85d4d000 00000000 nt!EtwpFlushBufferToLogfile+0x81
8d9eac3c 82a89b76 00000000 00000001 85a86980 nt!EtwpFlushBuffer+0xc3
8d9ead08 82c49a3a 85a86980 00000000 00000000 nt!EtwpFlushActiveBuffers+0x2c0
8d9ead50 82c256cf 85a86980 b8af3ec4 00000000 nt!EtwpLogger+0x2a1
8d9ead90 82ad71b9 82c49799 85a86980 00000000 nt!PspSystemThreadStartup+0x9e
00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x19
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: Ntfs!NtfsCommonWrite+1c0e
FOLLOWUP_NAME: MachineOwner
IMAGE_NAME: hardware
DEBUG_FLR_IMAGE_TIMESTAMP: 0
STACK_COMMAND: .cxr 0xffffffff8d9ea3a0 ; kb
MODULE_NAME: hardware
FAILURE_BUCKET_ID: IP_MISALIGNED_Ntfs.sys
BUCKET_ID: IP_MISALIGNED_Ntfs.sys
Followup: MachineOwner
---------
1: kd> lmvm hardware
start end module name
1: kd> lmntsm
start end module name
940b7000 940e3000 1394ohci 1394ohci.sys Tue Jul 14 11:51:59 2009 (4A5BC89F)
8b629000 8b671000 ACPI ACPI.sys Tue Jul 14 11:11:11 2009 (4A5BBF0F)
9084b000 908a5000 afd afd.sys Tue Jul 14 11:12:34 2009 (4A5BBF62)
9411d000 9412f000 AgileVpn AgileVpn.sys Tue Jul 14 11:55:00 2009 (4A5BC954)
8b77a000 8b783000 amdxata amdxata.sys Wed May 20 05:57:35 2009 (4A12F30F)
8b74e000 8b757000 atapi atapi.sys Tue Jul 14 11:11:15 2009 (4A5BBF13)
8b757000 8b77a000 ataport ataport.SYS Tue Jul 14 11:11:18 2009 (4A5BBF16)
932a0000 932be000 AtiHdmi AtiHdmi.sys Fri Jan 29 14:03:29 2010 (4B6233E1)
90ee3000 90f0d000 atikmpag atikmpag.sys Wed Mar 03 16:07:15 2010 (4B8DD263)
94609000 94b70000 atipmdag atipmdag.sys Wed Mar 03 16:45:16 2010 (4B8DDB4C)
965d5000 965ea000 avgntflt avgntflt.sys Fri Feb 12 04:11:18 2010 (4B741E16)
90e8e000 90eb0000 avipbb avipbb.sys Fri Feb 26 23:07:18 2010 (4B879D56)
8bbf4000 8bbfb000 Beep Beep.SYS Tue Jul 14 11:45:00 2009 (4A5BC6FC)
90e80000 90e8e000 blbdrive blbdrive.sys Tue Jul 14 11:23:04 2009 (4A5BC1D8)
8b48c000 8b494000 BOOTVID BOOTVID.dll Tue Jul 14 13:04:34 2009 (4A5BD9A2)
96213000 9622c000 bowser bowser.sys Tue Jul 14 11:14:21 2009 (4A5BBFCD)
82740000 8275e000 cdd cdd.dll unavailable (00000000)
8ba00000 8ba1f000 cdrom cdrom.sys Tue Jul 21 18:32:53 2009 (4A656115)
8b4d6000 8b581000 CI CI.dll Tue Jul 14 13:09:28 2009 (4A5BDAC8)
8bbb5000 8bbda000 CLASSPNP CLASSPNP.SYS Tue Jul 14 11:11:20 2009 (4A5BBF18)
8b494000 8b4d6000 CLFS CLFS.SYS Tue Jul 14 11:11:10 2009 (4A5BBF0E)
8b99c000 8b9f9000 cng cng.sys Tue Jul 14 11:32:55 2009 (4A5BC427)
94110000 9411d000 CompositeBus CompositeBus.sys Tue Jul 14 11:45:26 2009 (4A5BC716)
93200000 93209000 cpuz133_x32 cpuz133_x32.sys Thu Mar 11 05:24:11 2010 (4B97C7AB)
96573000 96580000 crashdmp crashdmp.sys Tue Jul 14 11:45:50 2009 (4A5BC72E)
90e04000 90e68000 csc csc.sys Tue Jul 14 11:15:08 2009 (4A5BBFFC)
90e68000 90e80000 dfsc dfsc.sys Tue Jul 14 11:14:16 2009 (4A5BBFC8)
90800000 9080c000 discache discache.sys Tue Jul 14 11:24:04 2009 (4A5BC214)
8bba4000 8bbb5000 disk disk.sys Tue Jul 14 11:11:28 2009 (4A5BBF20)
932ed000 93306000 drmk drmk.sys Tue Jul 14 12:36:05 2009 (4A5BD2F5)
9658b000 96594000 dump_atapi dump_atapi.sys Tue Jul 14 11:11:15 2009 (4A5BBF13)
96580000 9658b000 dump_dumpata dump_dumpata.sys Tue Jul 14 11:11:16 2009 (4A5BBF14)
96594000 965a5000 dump_dumpfve dump_dumpfve.sys Tue Jul 14 11:12:47 2009 (4A5BBF6F)
965a5000 965af000 Dxapi Dxapi.sys Tue Jul 14 11:25:25 2009 (4A5BC265)
90f0d000 90fc4000 dxgkrnl dxgkrnl.sys Fri Oct 02 13:48:33 2009 (4AC54DE1)
94b70000 94ba9000 dxgmms1 dxgmms1.sys Tue Jul 14 11:25:25 2009 (4A5BC265)
9b570000 9b59a000 fastfat fastfat.SYS Tue Jul 14 11:14:01 2009 (4A5BBFB9)
940e3000 940ee000 fdc fdc.sys Tue Jul 14 11:45:45 2009 (4A5BC729)
8b7b7000 8b7c8000 fileinfo fileinfo.sys Tue Jul 14 11:21:51 2009 (4A5BC18F)
93285000 9328f000 flpydisk flpydisk.sys Tue Jul 14 11:45:45 2009 (4A5BC729)
8b783000 8b7b7000 fltmgr fltmgr.sys Tue Jul 14 11:11:13 2009 (4A5BBF11)
8b80e000 8b817000 Fs_Rec Fs_Rec.sys Tue Jul 14 11:11:14 2009 (4A5BBF12)
8bb72000 8bba4000 fvevol fvevol.sys Sat Sep 26 14:24:21 2009 (4ABD7B55)
8bd70000 8bda1000 fwpkclnt fwpkclnt.sys Fri Jul 24 17:52:20 2009 (4A694C14)
9b59a000 9b59c6c0 gdrv gdrv.sys Fri Mar 13 16:17:32 2009 (49B9D04C)
9b59d000 9b5a0e80 GVTDrv GVTDrv.sys Wed Nov 23 22:00:18 2005 (43842FA2)
82e27000 82e5e000 hal halmacpi.dll Tue Jul 21 18:32:34 2009 (4A656102)
94ba9000 94bc8000 HDAudBus HDAudBus.sys Tue Jul 14 11:50:55 2009 (4A5BC85F)
96542000 96555000 HIDCLASS HIDCLASS.SYS Tue Jul 14 11:51:01 2009 (4A5BC865)
96555000 9655b480 HIDPARSE HIDPARSE.SYS Tue Jul 14 11:50:59 2009 (4A5BC863)
96537000 96542000 hidusb hidusb.sys Tue Jul 14 11:51:04 2009 (4A5BC868)
93306000 9338b000 HTTP HTTP.sys Tue Jul 14 11:12:53 2009 (4A5BBF75)
8bc10000 8bc18000 hwpolicy hwpolicy.sys Tue Jul 14 11:11:01 2009 (4A5BBF05)
90ed1000 90ee3000 intelppm intelppm.sys Tue Jul 14 11:11:03 2009 (4A5BBF07)
941c4000 941d1000 kbdclass kbdclass.sys Tue Jul 14 11:11:15 2009 (4A5BBF13)
96567000 96573000 kbdhid kbdhid.sys Tue Jul 14 11:45:09 2009 (4A5BC705)
80bd0000 80bd8000 kdcom kdcom.dll Tue Jul 14 13:08:58 2009 (4A5BDAAA)
90fc4000 90ff8000 ks ks.sys Tue Jul 14 11:45:13 2009 (4A5BC709)
8b989000 8b99c000 ksecdd ksecdd.sys Tue Jul 14 11:11:56 2009 (4A5BBF3C)
8bb20000 8bb45000 ksecpkg ksecpkg.sys Fri Dec 11 17:04:22 2009 (4B21C4C6)
965ea000 965fa000 lltdio lltdio.sys Tue Jul 14 11:53:18 2009 (4A5BC8EE)
965ba000 965d5000 luafv luafv.sys Tue Jul 14 11:15:44 2009 (4A5BC020)
8b403000 8b47b000 mcupdate_GenuineIntel mcupdate_GenuineIntel.dll Tue Jul 14 13:06:41 2009 (4A5BDA21)
965af000 965ba000 monitor monitor.sys Tue Jul 14 11:25:58 2009 (4A5BC286)
941d1000 941de000 mouclass mouclass.sys Tue Jul 14 11:11:15 2009 (4A5BBF13)
9655c000 96567000 mouhid mouhid.sys Tue Jul 14 11:45:08 2009 (4A5BC704)
8b738000 8b74e000 mountmgr mountmgr.sys Tue Jul 14 11:11:27 2009 (4A5BBF1F)
9338b000 9339d000 mpsdrv mpsdrv.sys Tue Jul 14 11:52:52 2009 (4A5BC8D4)
9339d000 933c0000 mrxsmb mrxsmb.sys Sat Feb 27 20:32:02 2010 (4B88CA72)
933c0000 933fb000 mrxsmb10 mrxsmb10.sys Sat Feb 27 20:32:21 2010 (4B88CA85)
94bd3000 94bee000 mrxsmb20 mrxsmb20.sys Sat Feb 27 20:32:11 2010 (4B88CA7B)
8b608000 8b613000 Msfs Msfs.SYS Tue Jul 14 11:11:26 2009 (4A5BBF1E)
8b67a000 8b682000 msisadrv msisadrv.sys Tue Jul 14 11:11:09 2009 (4A5BBF0D)
8b95e000 8b989000 msrpc msrpc.sys Tue Jul 14 11:11:59 2009 (4A5BBF3F)
909f0000 909fa000 mssmbios mssmbios.sys Tue Jul 14 11:19:25 2009 (4A5BC0FD)
8bc00000 8bc10000 mup mup.sys Tue Jul 14 11:14:14 2009 (4A5BBFC6)
8ba2b000 8bae2000 ndis ndis.sys Fri Jul 24 17:52:34 2009 (4A694C22)
94147000 94152000 ndistapi ndistapi.sys Tue Jul 14 11:54:24 2009 (4A5BC930)
94152000 94174000 ndiswan ndiswan.sys Tue Jul 14 11:54:34 2009 (4A5BC93A)
9328f000 932a0000 NDProxy NDProxy.SYS Tue Jul 14 11:54:27 2009 (4A5BC933)
9090d000 9091b000 netbios netbios.sys Tue Jul 14 11:53:54 2009 (4A5BC912)
908a5000 908d7000 netbt netbt.sys Tue Jul 14 11:12:18 2009 (4A5BBF52)
8bae2000 8bb20000 NETIO NETIO.SYS Tue Jul 14 11:12:35 2009 (4A5BBF63)
8b613000 8b621000 Npfs Npfs.SYS Tue Jul 14 11:11:31 2009 (4A5BBF23)
909e6000 909f0000 nsiproxy nsiproxy.sys Tue Jul 14 11:12:08 2009 (4A5BBF48)
82a17000 82e27000 nt ntkrpamp.exe Sat Feb 27 20:35:13 2010 (4B88CB31)
8b82f000 8b95e000 Ntfs Ntfs.sys Tue Jul 14 11:12:05 2009 (4A5BBF45)
8ba1f000 8ba26000 Null Null.SYS Tue Jul 14 11:11:12 2009 (4A5BBF10)
908de000 908fd000 pacer pacer.sys Tue Jul 14 11:53:58 2009 (4A5BC916)
940f8000 94110000 parport parport.sys Tue Jul 14 11:45:34 2009 (4A5BC71E)
8b6b7000 8b6c8000 partmgr partmgr.sys Tue Jul 14 11:11:35 2009 (4A5BBF27)
9622c000 96233000 parvdm parvdm.sys Tue Jul 14 11:45:29 2009 (4A5BC719)
8b682000 8b6ac000 pci pci.sys Tue Jul 14 11:11:16 2009 (4A5BBF14)
8b723000 8b72a000 pciide pciide.sys Tue Jul 14 11:11:19 2009 (4A5BBF17)
8b72a000 8b738000 PCIIDEX PCIIDEX.SYS Tue Jul 14 11:11:15 2009 (4A5BBF13)
8b800000 8b80e000 pcw pcw.sys Tue Jul 14 11:11:10 2009 (4A5BBF0E)
9b401000 9b498000 peauth peauth.sys Tue Jul 14 12:35:44 2009 (4A5BD2E0)
932be000 932ed000 portcls portcls.sys Tue Jul 14 11:51:00 2009 (4A5BC864)
8b47b000 8b48c000 PSHED PSHED.dll Tue Jul 14 13:09:36 2009 (4A5BDAD0)
9412f000 94147000 rasl2tp rasl2tp.sys Tue Jul 14 11:54:33 2009 (4A5BC939)
94174000 9418c000 raspppoe raspppoe.sys Tue Jul 14 11:54:53 2009 (4A5BC94D)
9418c000 941a3000 raspptp raspptp.sys Tue Jul 14 11:54:47 2009 (4A5BC947)
941a3000 941ba000 rassstp rassstp.sys Tue Jul 14 11:54:57 2009 (4A5BC951)
909a5000 909e6000 rdbss rdbss.sys Tue Jul 14 11:14:26 2009 (4A5BBFD2)
941ba000 941c4000 rdpbus rdpbus.sys Tue Jul 14 12:02:40 2009 (4A5BCB20)
8b823000 8b82b000 RDPCDD RDPCDD.sys Tue Jul 14 12:01:40 2009 (4A5BCAE4)
8b7f6000 8b7fe000 rdpencdd rdpencdd.sys Tue Jul 14 12:01:39 2009 (4A5BCAE3)
8b600000 8b608000 rdprefmp rdprefmp.sys Tue Jul 14 12:01:41 2009 (4A5BCAE5)
8bb45000 8bb72000 rdyboost rdyboost.sys Tue Jul 14 11:22:02 2009 (4A5BC19A)
96200000 96213000 rspndr rspndr.sys Tue Jul 14 11:53:20 2009 (4A5BC8F0)
94072000 940b7000 Rt86win7 Rt86win7.sys Fri Mar 05 02:42:33 2010 (4B8FB8C9)
96239000 9651f880 RTKVHDA RTKVHDA.sys Fri Mar 26 23:24:53 2010 (4BAC8B75)
9b498000 9b4a2000 secdrv secdrv.SYS Thu Sep 14 01:18:32 2006 (45080528)
940ee000 940f8000 serenum serenum.sys Tue Jul 14 11:45:27 2009 (4A5BC717)
9091b000 90935000 serial serial.sys Tue Jul 14 11:45:33 2009 (4A5BC71D)
8bde9000 8bdf1000 spldr spldr.sys Tue May 12 04:13:47 2009 (4A084EBB)
9b51f000 9b570000 srv srv.sys Tue Dec 08 21:05:37 2009 (4B1E08D1)
9b4d0000 9b51f000 srv2 srv2.sys Tue Jul 14 11:14:52 2009 (4A5BBFEC)
9b4a2000 9b4c3000 srvnet srvnet.sys Tue Dec 08 21:05:06 2009 (4B1E08B2)
9099f000 909a4a00 ssmdrv ssmdrv.sys Tue May 05 22:05:18 2009 (4A000F5E)
941de000 941df380 swenum swenum.sys Tue Jul 14 11:45:08 2009 (4A5BC704)
8bc27000 8bd70000 tcpip tcpip.sys Fri Jul 24 17:53:23 2009 (4A694C53)
9b4c3000 9b4d0000 tcpipreg tcpipreg.sys Tue Jul 14 11:54:14 2009 (4A5BC926)
90840000 9084b000 TDI TDI.SYS Tue Jul 14 11:12:12 2009 (4A5BBF4C)
90829000 90840000 tdx tdx.sys Tue Jul 14 11:12:10 2009 (4A5BBF4A)
9098f000 9099f000 termdd termdd.sys Tue Jul 14 12:01:35 2009 (4A5BCADF)
82710000 82719000 TSDDD TSDDD.dll unavailable (00000000)
90eb0000 90ed1000 tunnel tunnel.sys Tue Jul 14 11:54:03 2009 (4A5BC91B)
941e0000 941ee000 umbus umbus.sys Tue Jul 21 19:14:01 2009 (4A656AB9)
96520000 96537000 usbccgp usbccgp.sys Tue Jul 14 11:51:31 2009 (4A5BC883)
941fb000 941fc700 USBD USBD.SYS Tue Jul 14 11:51:05 2009 (4A5BC869)
94063000 94072000 usbehci usbehci.sys Tue Jul 14 11:51:14 2009 (4A5BC872)
93241000 93285000 usbhub usbhub.sys Sat Sep 05 15:00:02 2009 (4AA1D432)
94018000 94063000 USBPORT USBPORT.SYS Tue Jul 14 11:51:13 2009 (4A5BC871)
941ee000 941fb000 usbrpm usbrpm.sys Tue Jul 14 12:14:30 2009 (4A5BCDE6)
94bc8000 94bd3000 usbuhci usbuhci.sys Tue Jul 14 11:51:10 2009 (4A5BC86E)
8b6ac000 8b6b7000 vdrvroot vdrvroot.sys Tue Jul 14 11:46:19 2009 (4A5BC74B)
8b817000 8b823000 vga vga.sys Tue Jul 14 11:25:50 2009 (4A5BC27E)
8b7c8000 8b7e9000 VIDEOPRT VIDEOPRT.SYS Tue Jul 14 11:25:49 2009 (4A5BC27D)
8bda1000 8bda9380 vmstorfl vmstorfl.sys Tue Jul 14 11:28:44 2009 (4A5BC32C)
8b6c8000 8b6d8000 volmgr volmgr.sys Tue Jul 14 11:11:25 2009 (4A5BBF1D)
8b6d8000 8b723000 volmgrx volmgrx.sys Tue Jul 14 11:11:41 2009 (4A5BBF2D)
8bdaa000 8bde9000 volsnap volsnap.sys Wed Sep 16 14:20:40 2009 (4AB04B78)
9320b000 93241000 vpchbus vpchbus.sys Wed Sep 23 13:18:06 2009 (4AB9774E)
908fd000 9090d000 vpcnfltr vpcnfltr.sys Wed Sep 23 13:18:04 2009 (4AB9774C)
94000000 94018000 vpcusb vpcusb.sys Wed Sep 23 13:18:08 2009 (4AB97750)
90948000 9098e500 vpcvmm vpcvmm.sys Wed Sep 23 13:18:05 2009 (4AB9774D)
90935000 90948000 wanarp wanarp.sys Tue Jul 14 11:55:02 2009 (4A5BC956)
8b7e9000 8b7f6000 watchdog watchdog.sys Tue Jul 14 11:24:10 2009 (4A5BC21A)
8b581000 8b5f2000 Wdf01000 Wdf01000.sys Tue Jul 14 11:11:36 2009 (4A5BBF28)
8b5f2000 8b600000 WDFLDR WDFLDR.SYS Tue Jul 14 11:11:25 2009 (4A5BBF1D)
908d7000 908de000 wfplwf wfplwf.sys Tue Jul 14 11:53:51 2009 (4A5BC90F)
824b0000 826fa000 win32k win32k.sys unavailable (00000000)
8b671000 8b67a000 WMILIB WMILIB.SYS Tue Jul 14 11:11:22 2009 (4A5BBF1A)