*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {fffff98113042698, 0, fffff8800162b460, 5}
Could not read faulting driver name
*** WARNING: Unable to verify timestamp for win32k.sys
*** ERROR: Module load completed but symbols could not be loaded for win32k.sys
Probably caused by : Ntfs.sys ( Ntfs!memcpy+250 )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: fffff98113042698, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff8800162b460, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000005, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002ebe100
GetUlongFromAddress: unable to read from fffff80002ebe1c0
fffff98113042698
FAULTING_IP:
Ntfs!memcpy+250
fffff880`0162b460 488b440af8 mov rax,qword ptr [rdx+rcx-8]
MM_INTERNAL_CODE: 5
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: System
CURRENT_IRQL: 0
TRAP_FRAME: fffff88003784da0 -- (.trap 0xfffff88003784da0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000020 rbx=0000000000000000 rcx=fffff981130426c8
rdx=ffffffffffffffd8 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8800162b460 rsp=fffff88003784f38 rbp=fffff98013042718
r8=00000000ffffff68 r9=0000000007fffffb r10=0000000000000001
r11=fffff98013042760 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na po nc
Ntfs!memcpy+0x250:
fffff880`0162b460 488b440af8 mov rax,qword ptr [rdx+rcx-8] ds:fffff981`13042698=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002c35f0f to fffff80002c8f1c0
STACK_TEXT:
fffff880`03784c38 fffff800`02c35f0f : 00000000`00000050 fffff981`13042698 00000000`00000000 fffff880`03784da0 : nt!KeBugCheckEx
fffff880`03784c40 fffff800`02c8d2ee : 00000000`00000000 fffff981`13042698 00000000`00000000 00000000`00000028 : nt! ?? ::FNODOBFM::`string'+0x43d51
fffff880`03784da0 fffff880`0162b460 : fffff880`016b75a8 00000000`00000028 fffff880`03784f90 fffff8a0`00000400 : nt!KiPageFault+0x16e
fffff880`03784f38 fffff880`016b75a8 : 00000000`00000028 fffff880`03784f90 fffff8a0`00000400 00000000`00000001 : Ntfs!memcpy+0x250
fffff880`03784f40 fffff880`016b7740 : fffff8a0`0444fdb0 fffff800`02e2c280 fffff8a0`0444fdb0 fffff980`13042400 : Ntfs!NtfsRestartInsertSimpleRoot+0x50
fffff880`03784f80 fffff880`016dba2f : fffffa80`09110470 fffffa80`099bc180 fffff880`03785118 fffff880`03785150 : Ntfs!InsertSimpleRoot+0xb8
fffff880`03785050 fffff880`01692d3b : 00000000`00000000 fffff8a0`0444fdb0 fffff880`03785118 fffff880`037851a8 : Ntfs!AddToIndex+0xcf
fffff880`037850d0 fffff880`016aeda5 : fffffa80`09110470 fffff8a0`0444fdb0 fffff8a0`040360d8 fffffa80`00000000 : Ntfs!NtOfsAddRecords+0x167
fffff880`037852b0 fffff880`016df520 : fffffa80`09110470 fffff8a0`040360d0 00000000`00038968 00000000`00038970 : Ntfs!GetSecurityIdFromSecurityDescriptorUnsafe+0x1fd
fffff880`03785360 fffff880`0168e532 : fffffa80`09110470 fffffa80`099bc180 00000000`00000000 fffff980`13042d00 : Ntfs!NtfsCacheSharedSecurityByDescriptor+0xa0
fffff880`037853b0 fffff880`016a65ed : fffffa80`09110470 fffffa80`099bc180 fffff800`02e2c280 00000000`00000000 : Ntfs! ?? ::NNGAKEGL::`string'+0x11530
fffff880`03785430 fffff880`01639b0c : fffffa80`09110470 fffff880`01663a00 fffffa80`09110470 fffff8a0`04546680 : Ntfs!NtfsUpdateFcbInfoFromDisk+0x4fe
fffff880`03785580 fffff880`01704592 : fffffa80`09110470 00000000`00000000 00000000`00000000 fffff8a0`04546680 : Ntfs!NtfsInitializeDirectory+0x254
fffff880`03785690 fffff880`016fe3fa : fffffa80`09110470 fffffa80`099bc180 00000000`00000000 fffffa80`099bc180 : Ntfs!NtfsInitializeExtendDirectory+0x3d6
fffff880`03785850 fffff880`0169980d : 00000000`00000000 fffffa80`044bc010 00000000`00000001 00000000`00000000 : Ntfs!NtfsMountVolume+0x1691
fffff880`03785b90 fffff880`01620985 : 00000000`00000000 00000000`00000000 fffffa80`09110470 fffff800`02c967d3 : Ntfs!NtfsCommonFileSystemControl+0x59
fffff880`03785bd0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : Ntfs!NtfsFspDispatch+0x2ad
STACK_COMMAND: kb
FOLLOWUP_IP:
Ntfs!memcpy+250
fffff880`0162b460 488b440af8 mov rax,qword ptr [rdx+rcx-8]
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: Ntfs!memcpy+250
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Ntfs
IMAGE_NAME: Ntfs.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4d79997b
FAILURE_BUCKET_ID: X64_0x50_Ntfs!memcpy+250
BUCKET_ID: X64_0x50_Ntfs!memcpy+250
Followup: MachineOwner
---------
2: kd> lmvm Ntfs
start end module name
fffff880`0161d000 fffff880`017c0000 Ntfs (pdb symbols) c:\symbols\ntfs.pdb\D51347AE03CB4523A2844EA865BA0BE92\ntfs.pdb
Loaded symbol image file: Ntfs.sys
Mapped memory image file: c:\symbols\Ntfs.sys\4D79997B1a3000\Ntfs.sys
Image path: \SystemRoot\System32\Drivers\Ntfs.sys
Image name: Ntfs.sys
Timestamp: Fri Mar 11 09:09:39 2011 (4D79997B)
CheckSum: 0019968A
ImageSize: 001A3000
File version: 6.1.7601.17577
Product version: 6.1.7601.17577
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: ntfs.sys
OriginalFilename: ntfs.sys
ProductVersion: 6.1.7601.17577
FileVersion: 6.1.7601.17577 (win7sp1_gdr.110310-1504)
FileDescription: NT File System Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.