Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\K\Desktop\Windows_NT6_BSOD_jcgriff2\092510-37565-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
WARNING: Whitespace at end of path element
Symbol search path is: SRV*C:\symbols;*[URL="http://msdl.microsoft.com/download/symbols"]Symbol information[/URL] ;srv*e:\symbols
*[URL="http://msdl.microsoft.com/download/symbols"]Symbol information[/URL]
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`0345c000 PsLoadedModuleList = 0xfffff800`03699e50
Debug session time: Sat Sep 25 23:34:19.890 2010 (GMT-4)
System Uptime: 0 days 13:16:17.356
Loading Kernel Symbols
...............................................................
................................................................
.............................................
Loading User Symbols
Loading unloaded module list
.......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {fffffa80091405e8, 0, fffff88008de7794, 0}
Unable to load image \??\C:\Program Files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for KernExplorer64.sys
*** ERROR: Module load completed but symbols could not be loaded for KernExplorer64.sys
Could not read faulting driver name
Probably caused by : KernExplorer64.sys ( KernExplorer64+1794 )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: fffffa80091405e8, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff88008de7794, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000000, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800037040e0
fffffa80091405e8
FAULTING_IP:
KernExplorer64+1794
fffff880`08de7794 0fb75058 movzx edx,word ptr [rax+58h]
MM_INTERNAL_CODE: 0
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: AAWService.exe
CURRENT_IRQL: 0
TRAP_FRAME: fffff8800915b760 -- (.trap 0xfffff8800915b760)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffffa8009140590 rbx=0000000000000000 rcx=fffff8a0001feeb1
rdx=fffff8a00edc86f1 rsi=0000000000000000 rdi=0000000000000000
rip=fffff88008de7794 rsp=fffff8800915b8f0 rbp=fffffa800874f000
r8=fffff8a00edc86f0 r9=0000000000000050 r10=fffff880009e9780
r11=fffff8a0001feeb0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na po nc
KernExplorer64+0x1794:
fffff880`08de7794 0fb75058 movzx edx,word ptr [rax+58h] ds:8530:fffffa80`091405e8=????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff8000354cf14 to fffff800034cc740
STACK_TEXT:
fffff880`0915b5f8 fffff800`0354cf14 : 00000000`00000050 fffffa80`091405e8 00000000`00000000 fffff880`0915b760 : nt!KeBugCheckEx
fffff880`0915b600 fffff800`034ca82e : 00000000`00000000 00000000`00000000 00000000`00000000 fffff800`037b2dad : nt! ?? ::FNODOBFM::`string'+0x42837
fffff880`0915b760 fffff880`08de7794 : 00000000`c0000001 fffffa80`0874f000 00000001`00000034 fffff880`0915b980 : nt!KiPageFault+0x16e
fffff880`0915b8f0 00000000`c0000001 : fffffa80`0874f000 00000001`00000034 fffff880`0915b980 00000000`00000000 : KernExplorer64+0x1794
fffff880`0915b8f8 fffffa80`0874f000 : 00000001`00000034 fffff880`0915b980 00000000`00000000 00000000`00240022 : 0xc0000001
fffff880`0915b900 00000001`00000034 : fffff880`0915b980 00000000`00000000 00000000`00240022 fffff8a0`05c946a0 : 0xfffffa80`0874f000
fffff880`0915b908 fffff880`0915b980 : 00000000`00000000 00000000`00240022 fffff8a0`05c946a0 00000000`00000000 : 0x1`00000034
fffff880`0915b910 00000000`00000000 : 00000000`00240022 fffff8a0`05c946a0 00000000`00000000 fffffa80`072f8530 : 0xfffff880`0915b980
STACK_COMMAND: kb
FOLLOWUP_IP:
KernExplorer64+1794
fffff880`08de7794 0fb75058 movzx edx,word ptr [rax+58h]
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: KernExplorer64+1794
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: KernExplorer64
IMAGE_NAME: KernExplorer64.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4be3e1d3
FAILURE_BUCKET_ID: X64_0x50_KernExplorer64+1794
BUCKET_ID: X64_0x50_KernExplorer64+1794
Followup: MachineOwner
---------