Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\Yusra\Downloads\TreeFiddy350\SF_19-09-2012\091912-27066-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17803.x86fre.win7sp1_gdr.120330-1504
Machine Name:
Kernel base = 0x82c0c000 PsLoadedModuleList = 0x82d554d0
Debug session time: Thu Sep 20 03:46:00.923 2012 (UTC + 6:00)
System Uptime: 0 days 0:36:23.609
Loading Kernel Symbols
...............................................................
................................................................
...............................................
Loading User Symbols
Loading unloaded module list
.........
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
[COLOR="Red"]BugCheck A[/COLOR], {c0851a40, 0, 0, 82c73b7e}
*** WARNING: Unable to verify timestamp for SYMEVENT.SYS
*** ERROR: Module load completed but symbols could not be loaded for SYMEVENT.SYS
Probably caused by : [COLOR="red"]SYMEVENT.SYS ( SYMEVENT+17079 )[/COLOR]
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
[COLOR="red"]IRQL_NOT_LESS_OR_EQUAL (a)[/COLOR]
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: c0851a40, memory referenced
Arg2: 00000000, IRQL
Arg3: 00000000, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: 82c73b7e, address which referenced memory
Debugging Details:
------------------
READ_ADDRESS: GetPointerFromAddress: unable to read from 82d75848
Unable to read MiSystemVaType memory at 82d54e20
c0851a40
CURRENT_IRQL: 0
FAULTING_IP:
nt!MiLocateWsle+97
82c73b7e 8b049e mov eax,dword ptr [esi+ebx*4]
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xA
PROCESS_NAME: chrome.exe
TRAP_FRAME: b379d85c -- (.trap 0xffffffffb379d85c)
ErrCode = 00000000
eax=c0c0bf5c ebx=00013b4e ecx=00606058 edx=c0802000 esi=c0802d08 edi=02bd7001
eip=82c73b7e esp=b379d8d0 ebp=b379d8dc iopl=0 nv up ei pl nz na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010206
nt!MiLocateWsle+0x97:
82c73b7e 8b049e mov eax,dword ptr [esi+ebx*4] ds:0023:c0851a40=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from 82c73b7e to 82c4d65b
STACK_TEXT:
b379d85c 82c73b7e badb0d00 c0802000 c0802000 nt!KiTrap0E+0x2cf
b379d8dc 82caba55 c0c0bf5c 02c56fff 02bd0002 nt!MiLocateWsle+0x97
b379d9d8 82cac28c 02bd0002 02c56fff 86625808 nt!MiDeleteVirtualAddresses+0x1b5
b379daa8 82cabf41 86625808 865c6470 86539a40 nt!MiRemoveMappedView+0x325
b379dad0 82e53417 86539a40 00000000 c0000001 nt!MiRemoveVadAndView+0xe5
b379db30 82e718af 86625808 02bd0000 00000000 nt!MiUnmapViewOfSection+0x265
b379db50 b399e079 ffffffff 02bd0000 85e1d938 nt!NtUnmapViewOfSection+0x55
WARNING: Stack unwind information not available. Following frames may be wrong.
b379dbd4 82c4a27a ffffffff 02bd0000 b379dcec SYMEVENT+0x17079
b379dbd4 00400000 ffffffff 02bd0000 b379dcec nt!KiFastCallEntry+0x12a
b379dc44 00000000 82c495f9 00000008 00000202 0x400000
STACK_COMMAND: kb
FOLLOWUP_IP:
SYMEVENT+17079
b399e079 ?? ???
SYMBOL_STACK_INDEX: 7
SYMBOL_NAME: SYMEVENT+17079
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: SYMEVENT
IMAGE_NAME: SYMEVENT.SYS
DEBUG_FLR_IMAGE_TIMESTAMP: 4ecbea42
FAILURE_BUCKET_ID: 0xA_SYMEVENT+17079
BUCKET_ID: 0xA_SYMEVENT+17079
Followup: MachineOwner
---------
1: kd> lmvm SYMEVENT
start end module name
b3987000 b39b1000 SYMEVENT T (no symbols)
Loaded symbol image file: SYMEVENT.SYS
Image path: \??\C:\Windows\system32\Drivers\SYMEVENT.SYS
Image name: SYMEVENT.SYS
Timestamp: [COLOR="Red"]Wed Nov 23 00:30:26 2011[/COLOR] (4ECBEA42)
CheckSum: 00027540
ImageSize: 0002A000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4