Loading Dump File [D:\Kingston\BSODDmpFiles\MrRevolutionary\040412-36956-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`01a1b000 PsLoadedModuleList = 0xfffff800`01c60670
Debug session time: Wed Apr 4 12:01:35.919 2012 (UTC - 6:00)
System Uptime: 0 days 0:02:31.638
Loading Kernel Symbols
...............................................................
................................................................
..........
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {fffff80101cca4d8, 0, fffff80001bc6169, 5}
Could not read faulting driver name
Probably caused by : ntkrnlmp.exe ( nt!ExAllocatePoolWithTag+89 )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: fffff80101cca4d8, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff80001bc6169, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000005, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80001cca100
fffff80101cca4d8
FAULTING_IP:
nt!ExAllocatePoolWithTag+89
fffff800`01bc6169 4d8ba4c1d8f42a00 mov r12,qword ptr [r9+rax*8+2AF4D8h]
MM_INTERNAL_CODE: 5
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: ŒÍ
CURRENT_IRQL: 0
TRAP_FRAME: fffff880086f17e0 -- (.trap 0xfffff880086f17e0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=0000000000000000
rdx=0000000000000068 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80001bc6169 rsp=fffff880086f1970 rbp=0000000000000068
r8=0000000000000000 r9=fffff80101a1b000 r10=fffffa8006705900
r11=fffff880086f1aa0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
nt!ExAllocatePoolWithTag+0x89:
fffff800`01bc6169 4d8ba4c1d8f42a00 mov r12,qword ptr [r9+rax*8+2AF4D8h] ds:56f8:fffff801`01cca4d8=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80001a423bf to fffff80001a97c40
STACK_TEXT:
fffff880`086f1678 fffff800`01a423bf : 00000000`00000050 fffff801`01cca4d8 00000000`00000000 fffff880`086f17e0 : nt!KeBugCheckEx
fffff880`086f1680 fffff800`01a95d6e : 00000000`00000000 fffff801`01cca4d8 00000000`00000000 fffffa80`06709508 : nt! ?? ::FNODOBFM::`string'+0x44791
fffff880`086f17e0 fffff800`01bc6169 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x16e
fffff880`086f1970 fffff800`01d91a5f : fffff8a0`024d7fa0 fffffa80`06709508 fffff8a0`024d7ef0 00000000`000007ff : nt!ExAllocatePoolWithTag+0x89
fffff880`086f1a60 fffff800`01d9187b : fffffa80`00000000 fffffa80`06705901 fffff8a0`00000050 fffff880`086f1b08 : nt!ObpAllocateObject+0x12f
fffff880`086f1ad0 fffff800`01d5d98b : 00000000`001ee270 fffff880`086f1ca0 00000000`00000001 00000000`00000001 : nt!ObCreateObject+0xdb
fffff880`086f1b40 fffff800`01a96ed3 : fffffa80`06844b60 00000000`001ee258 fffff880`086f1bc8 00000000`00000001 : nt!NtCreateEvent+0x9b
fffff880`086f1bb0 00000000`7763179a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`001ee238 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7763179a
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!ExAllocatePoolWithTag+89
fffff800`01bc6169 4d8ba4c1d8f42a00 mov r12,qword ptr [r9+rax*8+2AF4D8h]
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: nt!ExAllocatePoolWithTag+89
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4e02aaa3
FAILURE_BUCKET_ID: X64_0x50_nt!ExAllocatePoolWithTag+89
BUCKET_ID: X64_0x50_nt!ExAllocatePoolWithTag+89
Followup: MachineOwner
---------