Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\Owner\Downloads\A-Rar\Dump Files\072910-24086-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\symbols*[URL="http://msdl.microsoft.com/download/symbols"]Symbol information[/URL]
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16539.x86fre.win7_gdr.100226-1909
Machine Name:
Kernel base = 0x82a39000 PsLoadedModuleList = 0x82b81810
Debug session time: Thu Jul 29 14:07:22.090 2010 (GMT-4)
System Uptime: 0 days 0:28:59.196
Loading Kernel Symbols
...............................................................
................................................................
....................
Loading User Symbols
Loading unloaded module list
......
1: kd> !analyze
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 19, {20, 8520d000, 8520d300, 8600000}
Probably caused by : fileinfo.sys ( fileinfo!FIStreamGetInfo+109 )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
BAD_POOL_HEADER (19)
The pool is already corrupt at the time of the current request.
This may or may not be due to the caller.
The internal pool links must be walked to figure out a possible cause of
the problem, and then special pool applied to the suspect tags or the driver
verifier to a suspect driver.
Arguments:
Arg1: 00000020, a pool block header size is corrupt.
Arg2: 8520d000, The pool entry we were looking for within the page.
Arg3: 8520d300, The next pool entry.
Arg4: 08600000, (reserved)
Debugging Details:
------------------
BUGCHECK_STR: 0x19_20
POOL_ADDRESS: GetPointerFromAddress: unable to read from 82ba1718
Unable to read MiSystemVaType memory at 82b81160
8520d000
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 82c7ae8a to 82b581b6
STACK_TEXT:
9960f080 82c7ae8a 8520d008 00000000 84ee4938 nt!ExFreePoolWithTag+0x1b1
9960f0cc 82c5a73c 851cc6e8 851cc6e8 851cc6d0 nt!IopDeleteFile+0x18f
9960f0e4 82aa1f60 00000000 8769a2c8 851cc6d0 nt!ObpRemoveObjectRoutine+0x59
9960f0f8 82aa1ed0 851cc6e8 82c7e7cc 8b801d10 nt!ObfDereferenceObjectWithTag+0x88
9960f100 82c7e7cc 8b801d10 8769a2c8 00002588 nt!ObfDereferenceObject+0xd
9960f144 82c7ffb2 8b801d10 a7479b10 84e607f0 nt!ObpCloseHandleTableEntry+0x21d
9960f174 82c8012a 84e607f0 00000000 9960f218 nt!ObpCloseHandle+0x7f
9960f190 82a7c44a 80002588 9960f238 82a79dad nt!NtClose+0x4e
9960f190 82a79dad 80002588 9960f238 82a79dad nt!KiFastCallEntry+0x12a
9960f20c 8a93c082 80002588 00000000 86dcb0b0 nt!ZwClose+0x11
9960f238 8a93cdf4 01dcb0b0 00000000 86dcb0b0 fltmgr!FltpExpandShortNames+0x304
9960f254 8a93d505 86dc0000 00000000 872dbefc fltmgr!FltpGetNormalizedFileNameWorker+0xae
9960f26c 8a93a765 86dcb0b0 00000000 86dcb0b0 fltmgr!FltpGetNormalizedFileName+0x19
9960f284 8a924b21 86dcb0b0 00000000 00000000 fltmgr!FltpCreateFileNameInformation+0x81
9960f2b4 8a924fa3 86867d64 00000000 9960f34c fltmgr!FltpGetFileNameInformation+0x321
9960f2dc 8a957c87 00143940 00000401 9960f310 fltmgr!FltGetFileNameInformation+0x12b
9960f32c 8a957edd 85143940 9960f34c 00002991 fileinfo!FIStreamGetInfo+0x109
9960f368 8a91e324 85143940 9960f38c 00000000 fileinfo!FIPostCreateCallback+0x171
9960f3d0 8a921512 001438e0 851438e0 1000000c fltmgr!FltpPerformPostCallbacks+0x24a
9960f3e4 8a921b46 851438e0 850fd548 9960f424 fltmgr!FltpProcessIoCompletion+0x10
9960f3f4 8a92229c 85d522a0 850fd548 851438e0 fltmgr!FltpPassThroughCompletion+0x98
9960f424 8a9358c9 9960f444 00000000 00000000 fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x33a
9960f470 82a754bc 85d522a0 86653288 8533c514 fltmgr!FltpCreate+0x2db
9960f488 82c7966d bf1fc90a 8505d570 85008008 nt!IofCallDriver+0x63
9960f560 82cc3071 85d522a0 84ee4938 84fda178 nt!IopParseDevice+0xed7
9960f5a0 82c5a21f 8505d570 84ee4938 84fda178 nt!IopParseFile+0x51
9960f61c 82c8028d 8000259c 9960f670 00000240 nt!ObpLookupObjectName+0x4fa
9960f678 82c785eb 9960f8d8 84ee4938 00000000 nt!ObOpenObjectByName+0x159
9960f6f4 82cafdd9 9960f8ac 00000020 9960f8d8 nt!IopCreateFile+0x673
9960f750 8a937b62 9960f8ac 00000020 9960f8d8 nt!IoCreateFileEx+0x9e
9960f7dc 8a95a2d3 84ed8b00 00000000 9960f8ac fltmgr!FltCreateFileEx2+0xba
9960f8bc 82c4f966 00000000 9960f9c0 9960f934 fileinfo!FIPfInterfaceOpen+0x2a9
9960f920 82c3dc73 9960f97c 8000259c 00000020 nt!PfpOpenHandleCreate+0xc0
9960f998 82c3d712 9960fa58 a8579bb0 00000201 nt!PfpFileBuildReadSupport+0x93
9960fa2c 82c3f0f2 0060fa58 9960fbb4 00000001 nt!PfpPrefetchFilesTrickle+0xdf
9960fad0 82c3edaf a8577000 bf1fc74e 9960fbc8 nt!PfpPrefetchRequestPerform+0x2a6
9960fb24 82c589c7 9960fbb4 82a07b01 bf1fc782 nt!PfpPrefetchRequest+0x16e
9960fbe8 82cc4936 0325fd38 00000014 82a07b01 nt!PfSetSuperfetchInformation+0x182
9960fd20 82a7c44a 0000004f 00000000 00000014 nt!NtSetSystemInformation+0xb00
9960fd20 775664f4 0000004f 00000000 00000014 nt!KiFastCallEntry+0x12a
WARNING: Frame IP not in any known module. Following frames may be wrong.
0325fd50 00000000 00000000 00000000 00000000 0x775664f4
STACK_COMMAND: kb
FOLLOWUP_IP:
fileinfo!FIStreamGetInfo+109
8a957c87 85c0 test eax,eax
SYMBOL_STACK_INDEX: 10
SYMBOL_NAME: fileinfo!FIStreamGetInfo+109
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: fileinfo
IMAGE_NAME: fileinfo.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc18f
FAILURE_BUCKET_ID: 0x19_20_fileinfo!FIStreamGetInfo+109
BUCKET_ID: 0x19_20_fileinfo!FIStreamGetInfo+109
Followup: MachineOwner
---------
Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\Owner\Downloads\A-Rar\Dump Files\072910-25365-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\symbols*[URL="http://msdl.microsoft.com/download/symbols"]Symbol information[/URL]
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16539.x86fre.win7_gdr.100226-1909
Machine Name:
Kernel base = 0x82a53000 PsLoadedModuleList = 0x82b9b810
Debug session time: Thu Jul 29 09:44:43.500 2010 (GMT-4)
System Uptime: 0 days 0:04:22.482
Loading Kernel Symbols
...............................................................
................................................................
.....................
Loading User Symbols
Loading unloaded module list
........
0: kd> !Analyze
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 19, {20, 8520d000, 8520d300, 8600000}
GetPointerFromAddress: unable to read from 82bbb718
Unable to read MiSystemVaType memory at 82b9b160
Probably caused by : ntkrpamp.exe ( nt!ExFreePoolWithTag+1b1 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
BAD_POOL_HEADER (19)
The pool is already corrupt at the time of the current request.
This may or may not be due to the caller.
The internal pool links must be walked to figure out a possible cause of
the problem, and then special pool applied to the suspect tags or the driver
verifier to a suspect driver.
Arguments:
Arg1: 00000020, a pool block header size is corrupt.
Arg2: 8520d000, The pool entry we were looking for within the page.
Arg3: 8520d300, The next pool entry.
Arg4: 08600000, (reserved)
Debugging Details:
------------------
GetPointerFromAddress: unable to read from 82bbb718
Unable to read MiSystemVaType memory at 82b9b160
BUGCHECK_STR: 0x19_20
POOL_ADDRESS: GetPointerFromAddress: unable to read from 82bbb718
Unable to read MiSystemVaType memory at 82b9b160
8520d000
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 82b73a76 to 82b721b6
STACK_TEXT:
9e56d5bc 82b73a76 8520d008 00000000 9e56d5d8 nt!ExFreePoolWithTag+0x1b1
9e56d5cc 8a91be8c 8520d008 9e56d5e8 8a922ed7 nt!ExFreePool+0xf
9e56d5d8 8a922ed7 8a92ac80 8520d008 9e56d5fc fltmgr!ExFreeToNPagedLookasideList+0x1e
9e56d5e8 8a93a9ba 8520d008 a62740f8 00000000 fltmgr!FltpReleaseStreamListCtrl+0x1f
9e56d5fc 82c71800 8520d00c ba11a687 00000000 fltmgr!DeleteStreamListCtrlCallback+0x60
9e56d63c 8aab4fb2 a62740f8 a6274008 a62740f8 nt!FsRtlTeardownPerStreamContexts+0x13a
9e56d658 8aaabb3b 00000705 a6274030 a6274008 Ntfs!NtfsDeleteScb+0x214
9e56d670 8aa1b71e 85076c68 a62740f8 00000000 Ntfs!NtfsRemoveScb+0xc5
9e56d68c 8aa9c0d2 85076c68 a6274008 00000000 Ntfs!NtfsPrepareFcbForRemoval+0x62
9e56d6d0 8aa18bec 85076c68 a62740f8 a62742a0 Ntfs!NtfsTeardownStructures+0x68
9e56d6f8 8aa9855b 85076c68 a62740f8 a62742a0 Ntfs!NtfsDecrementCloseCounts+0xaf
9e56d758 8aab74c3 85076c68 a62740f8 a6274008 Ntfs!NtfsCommonClose+0x4f2
9e56d7ec 8aa7751f 85d360d8 14f291e1 85276330 Ntfs!NtfsFspClose+0x118
9e56d87c 8aa85fab 87225008 85d360d8 00000001 Ntfs!NtfsFlushVolume+0x74
9e56d900 8aa8676b 87225008 85276330 14f290f5 Ntfs!NtfsCommonFlushBuffers+0x1a9
9e56d968 82a8f4bc 85d36020 85276330 85276330 Ntfs!NtfsFsdFlushBuffers+0xf7
9e56d980 8a91f20c 85d35a60 85276330 00000000 nt!IofCallDriver+0x63
9e56d9a4 8a91f3cb 9e56d9c4 85d35a60 00000000 fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x2aa
9e56d9dc 82a8f4bc 85d35a60 85276330 85276330 fltmgr!FltpDispatch+0xc5
9e56d9f4 82c90f2e 85276330 86bb8a48 00000000 nt!IofCallDriver+0x63
9e56da14 82c71ea2 85d35a60 86bb8a48 00000000 nt!IopSynchronousServiceTail+0x1f8
9e56da80 82a9644a 871b4ec8 9e56db40 9e56dd50 nt!NtFlushBuffersFile+0x1d7
9e56da80 82a94361 871b4ec8 9e56db40 9e56dd50 nt!KiFastCallEntry+0x12a
9e56db00 82d72712 800003a0 9e56db40 00000000 nt!ZwFlushBuffersFile+0x11
9e56dd50 82c616bb 8cac6ac0 ba11ad2b 00000000 nt!PopFlushVolumeWorker+0x13c
9e56dd90 82b130f9 82d725d6 8cac6ac0 00000000 nt!PspSystemThreadStartup+0x9e
00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x19
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!ExFreePoolWithTag+1b1
82b721b6 cc int 3
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!ExFreePoolWithTag+1b1
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrpamp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4b88cacf
FAILURE_BUCKET_ID: 0x19_20_nt!ExFreePoolWithTag+1b1
BUCKET_ID: 0x19_20_nt!ExFreePoolWithTag+1b1
Followup: MachineOwner
---------
0: kd> lmtsmn
start end module name
8a7b0000 8a7f8000 ACPI ACPI.sys Mon Jul 13 19:11:11 2009 (4A5BBF0F)
90228000 90282000 afd afd.sys Mon Jul 13 19:12:34 2009 (4A5BBF62)
9016c000 9017e000 AgileVpn AgileVpn.sys Mon Jul 13 19:55:00 2009 (4A5BC954)
914c0000 915c6000 AGRSM AGRSM.sys Mon Nov 10 09:56:37 2008 (49184BA5)
90041000 90053000 amdk8 amdk8.sys Mon Jul 13 19:11:03 2009 (4A5BBF07)
8a910000 8a919000 amdxata amdxata.sys Tue May 19 13:57:35 2009 (4A12F30F)
8a8e4000 8a8ed000 atapi atapi.sys Mon Jul 13 19:11:15 2009 (4A5BBF13)
8a8ed000 8a910000 ataport ataport.SYS Mon Jul 13 19:11:18 2009 (4A5BBF16)
90639000 90766000 athr athr.sys Mon Sep 21 13:58:25 2009 (4AB7BEC1)
90e0b000 913f3000 atikmdag atikmdag.sys Mon Dec 01 16:01:46 2008 (493450BA)
8a853000 8a85e000 BATTC BATTC.SYS Mon Jul 13 19:19:15 2009 (4A5BC0F3)
8ac26000 8ac2d000 Beep Beep.SYS Mon Jul 13 19:45:00 2009 (4A5BC6FC)
90200000 9020e000 blbdrive blbdrive.sys Mon Jul 13 19:23:04 2009 (4A5BC1D8)
8a63c000 8a644000 BOOTVID BOOTVID.dll Mon Jul 13 21:04:34 2009 (4A5BD9A2)
988ad000 988c6000 bowser bowser.sys Mon Jul 13 19:14:21 2009 (4A5BBFCD)
983a0000 983be000 cdd cdd.dll unavailable (00000000)
99791000 997a7000 cdfs cdfs.sys Mon Jul 13 19:11:14 2009 (4A5BBF12)
8a686000 8a731000 CI CI.dll Mon Jul 13 21:09:28 2009 (4A5BDAC8)
8adbb000 8ade0000 CLASSPNP CLASSPNP.SYS Mon Jul 13 19:11:20 2009 (4A5BBF18)
8a644000 8a686000 CLFS CLFS.SYS Mon Jul 13 19:11:10 2009 (4A5BBF0E)
90053000 90056700 CmBatt CmBatt.sys Mon Jul 13 19:19:18 2009 (4A5BC0F6)
8ab73000 8abd0000 cng cng.sys Mon Jul 13 19:32:55 2009 (4A5BC427)
8a84b000 8a853000 compbatt compbatt.sys Mon Jul 13 19:19:18 2009 (4A5BC0F6)
913f3000 91400000 CompositeBus CompositeBus.sys Mon Jul 13 19:45:26 2009 (4A5BC716)
968bc000 968c9000 crashdmp crashdmp.sys Mon Jul 13 19:45:50 2009 (4A5BC72E)
9037d000 903e1000 csc csc.sys Mon Jul 13 19:15:08 2009 (4A5BBFFC)
903e1000 903f9000 dfsc dfsc.sys Mon Jul 13 19:14:16 2009 (4A5BBFC8)
90371000 9037d000 discache discache.sys Mon Jul 13 19:24:04 2009 (4A5BC214)
8adaa000 8adbb000 disk disk.sys Mon Jul 13 19:11:28 2009 (4A5BBF20)
96899000 968b2000 drmk drmk.sys Mon Jul 13 20:36:05 2009 (4A5BD2F5)
968d4000 968dd000 dump_atapi dump_atapi.sys Mon Jul 13 19:11:15 2009 (4A5BBF13)
968c9000 968d4000 dump_dumpata dump_dumpata.sys Mon Jul 13 19:11:16 2009 (4A5BBF14)
968dd000 968ee000 dump_dumpfve dump_dumpfve.sys Mon Jul 13 19:12:47 2009 (4A5BBF6F)
968b2000 968bc000 Dxapi Dxapi.sys Mon Jul 13 19:25:25 2009 (4A5BC265)
90057000 9010e000 dxgkrnl dxgkrnl.sys Thu Oct 01 20:48:33 2009 (4AC54DE1)
9010e000 90147000 dxgmms1 dxgmms1.sys Mon Jul 13 19:25:25 2009 (4A5BC265)
99767000 99791000 fastfat fastfat.SYS Mon Jul 13 19:14:01 2009 (4A5BBFB9)
8a94d000 8a95e000 fileinfo fileinfo.sys Mon Jul 13 19:21:51 2009 (4A5BC18F)
8a919000 8a94d000 fltmgr fltmgr.sys Mon Jul 13 19:11:13 2009 (4A5BBF11)
8abde000 8abe7000 Fs_Rec Fs_Rec.sys Mon Jul 13 19:11:14 2009 (4A5BBF12)
8ad78000 8adaa000 fvevol fvevol.sys Fri Sep 25 22:24:21 2009 (4ABD7B55)
90039000 90041000 FwLnk FwLnk.sys Sun Nov 19 09:11:12 2006 (45606600)
8af71000 8afa2000 fwpkclnt fwpkclnt.sys Mon Jul 13 19:12:03 2009 (4A5BBF43)
907d4000 907db000 GEARAspiWDM GEARAspiWDM.sys Wed Feb 02 00:19:49 2005 (420062F5)
82a1c000 82a53000 hal halmacpi.dll Mon Jul 13 19:11:03 2009 (4A5BBF07)
907db000 907fa000 HDAudBus HDAudBus.sys Mon Jul 13 19:50:55 2009 (4A5BC85F)
9681a000 9686a000 HdAudio HdAudio.sys Mon Jul 13 19:51:46 2009 (4A5BC892)
98828000 988ad000 HTTP HTTP.sys Mon Jul 13 19:12:53 2009 (4A5BBF75)
8ae10000 8ae18000 hwpolicy hwpolicy.sys Mon Jul 13 19:11:01 2009 (4A5BBF05)
90600000 90618000 i8042prt i8042prt.sys Mon Jul 13 19:11:23 2009 (4A5BBF1B)
90618000 90625000 kbdclass kbdclass.sys Mon Jul 13 19:11:15 2009 (4A5BBF13)
80ba3000 80bab000 kdcom kdcom.dll Mon Jul 13 21:08:58 2009 (4A5BDAAA)
91429000 9145d000 ks ks.sys Mon Jul 13 19:45:13 2009 (4A5BC709)
8ab60000 8ab73000 ksecdd ksecdd.sys Mon Jul 13 19:11:56 2009 (4A5BBF3C)
8ad26000 8ad4b000 ksecpkg ksecpkg.sys Thu Dec 10 23:04:22 2009 (4B21C4C6)
96980000 96990000 lltdio lltdio.sys Mon Jul 13 19:53:18 2009 (4A5BC8EE)
9694b000 96966000 luafv luafv.sys Mon Jul 13 19:15:44 2009 (4A5BC020)
8a620000 8a62b000 mcupdate_AuthenticAMD mcupdate_AuthenticAMD.dll Mon Jul 13 19:13:13 2009 (4A5BBF89)
915c8000 915d5000 modem modem.sys Mon Jul 13 19:55:24 2009 (4A5BC96C)
96940000 9694b000 monitor monitor.sys Mon Jul 13 19:25:58 2009 (4A5BC286)
90625000 90632000 mouclass mouclass.sys Mon Jul 13 19:11:15 2009 (4A5BBF13)
8a8ce000 8a8e4000 mountmgr mountmgr.sys Mon Jul 13 19:11:27 2009 (4A5BBF1F)
8a95e000 8a981000 MpFilter MpFilter.sys Sat Mar 20 00:03:26 2010 (4BA4490E)
9975e000 99766e00 MpNWMon MpNWMon.sys Sat Mar 20 00:03:24 2010 (4BA4490C)
988c6000 988d8000 mpsdrv mpsdrv.sys Mon Jul 13 19:52:52 2009 (4A5BC8D4)
988d8000 988fb000 mrxsmb mrxsmb.sys Sat Feb 27 02:32:02 2010 (4B88CA72)
988fb000 98936000 mrxsmb10 mrxsmb10.sys Sat Feb 27 02:32:21 2010 (4B88CA85)
98936000 98951000 mrxsmb20 mrxsmb20.sys Sat Feb 27 02:32:11 2010 (4B88CA7B)
8a9ba000 8a9c5000 Msfs Msfs.SYS Mon Jul 13 19:11:26 2009 (4A5BBF1E)
8a609000 8a611000 msisadrv msisadrv.sys Mon Jul 13 19:11:09 2009 (4A5BBF0D)
8ab35000 8ab60000 msrpc msrpc.sys Mon Jul 13 19:11:59 2009 (4A5BBF3F)
90367000 90371000 mssmbios mssmbios.sys Mon Jul 13 19:19:25 2009 (4A5BC0FD)
8ae00000 8ae10000 mup mup.sys Mon Jul 13 19:14:14 2009 (4A5BBFC6)
8ac31000 8ace8000 ndis ndis.sys Mon Jul 13 19:12:24 2009 (4A5BBF58)
90e00000 90e0b000 ndistapi ndistapi.sys Mon Jul 13 19:54:24 2009 (4A5BC930)
969d6000 969e6000 ndisuio ndisuio.sys Mon Jul 13 19:53:51 2009 (4A5BC90F)
90196000 901b8000 ndiswan ndiswan.sys Mon Jul 13 19:54:34 2009 (4A5BC93A)
914af000 914c0000 NDProxy NDProxy.SYS Mon Jul 13 19:54:27 2009 (4A5BC933)
902eb000 902f9000 netbios netbios.sys Mon Jul 13 19:53:54 2009 (4A5BC912)
90282000 902b4000 netbt netbt.sys Mon Jul 13 19:12:18 2009 (4A5BBF52)
8ace8000 8ad26000 NETIO NETIO.SYS Mon Jul 13 19:12:35 2009 (4A5BBF63)
8a9c5000 8a9d3000 Npfs Npfs.SYS Mon Jul 13 19:11:31 2009 (4A5BBF23)
9035d000 90367000 nsiproxy nsiproxy.sys Mon Jul 13 19:12:08 2009 (4A5BBF48)
82a53000 82e63000 nt ntkrpamp.exe Sat Feb 27 02:33:35 2010 (4B88CACF)
8aa06000 8ab35000 Ntfs Ntfs.sys Mon Jul 13 19:12:05 2009 (4A5BBF45)
8ac1f000 8ac26000 Null Null.SYS Mon Jul 13 19:11:12 2009 (4A5BBF10)
96990000 969d6000 nwifi nwifi.sys Mon Jul 13 19:51:59 2009 (4A5BC89F)
902bb000 902da000 pacer pacer.sys Mon Jul 13 19:53:58 2009 (4A5BC916)
8a83a000 8a84b000 partmgr partmgr.sys Mon Jul 13 19:11:35 2009 (4A5BBF27)
8a805000 8a82f000 pci pci.sys Mon Jul 13 19:11:16 2009 (4A5BBF14)
8a8b9000 8a8c0000 pciide pciide.sys Mon Jul 13 19:11:19 2009 (4A5BBF17)
8a8c0000 8a8ce000 PCIIDEX PCIIDEX.SYS Mon Jul 13 19:11:15 2009 (4A5BBF13)
8abd0000 8abde000 pcw pcw.sys Mon Jul 13 19:11:10 2009 (4A5BBF0E)
98969000 98a00000 peauth peauth.sys Mon Jul 13 20:35:44 2009 (4A5BD2E0)
9686a000 96899000 portcls portcls.sys Mon Jul 13 19:51:00 2009 (4A5BC864)
8a62b000 8a63c000 PSHED PSHED.dll Mon Jul 13 21:09:36 2009 (4A5BDAD0)
9017e000 90196000 rasl2tp rasl2tp.sys Mon Jul 13 19:54:33 2009 (4A5BC939)
901b8000 901d0000 raspppoe raspppoe.sys Mon Jul 13 19:54:53 2009 (4A5BC94D)
901d0000 901e7000 raspptp raspptp.sys Mon Jul 13 19:54:47 2009 (4A5BC947)
901e7000 901fe000 rassstp rassstp.sys Mon Jul 13 19:54:57 2009 (4A5BC951)
9031c000 9035d000 rdbss rdbss.sys Mon Jul 13 19:14:26 2009 (4A5BBFD2)
90000000 9000a000 rdpbus rdpbus.sys Mon Jul 13 20:02:40 2009 (4A5BCB20)
8a9a2000 8a9aa000 RDPCDD RDPCDD.sys Mon Jul 13 20:01:40 2009 (4A5BCAE4)
8a9aa000 8a9b2000 rdpencdd rdpencdd.sys Mon Jul 13 20:01:39 2009 (4A5BCAE3)
8a9b2000 8a9ba000 rdprefmp rdprefmp.sys Mon Jul 13 20:01:41 2009 (4A5BCAE5)
8ad4b000 8ad78000 rdyboost rdyboost.sys Mon Jul 13 19:22:02 2009 (4A5BC19A)
969e6000 969f9000 rspndr rspndr.sys Mon Jul 13 19:53:20 2009 (4A5BC8F0)
90147000 9016c000 Rt86win7 Rt86win7.sys Thu Feb 26 04:04:22 2009 (49A65B16)
98800000 9880a000 secdrv secdrv.SYS Wed Sep 13 09:18:32 2006 (45080528)
8afef000 8aff7000 spldr spldr.sys Mon May 11 12:13:47 2009 (4A084EBB)
996ec000 9973d000 srv srv.sys Tue Dec 08 03:05:37 2009 (4B1E08D1)
9969d000 996ec000 srv2 srv2.sys Mon Jul 13 19:14:52 2009 (4A5BBFEC)
915d5000 915f6000 srvnet srvnet.sys Tue Dec 08 03:05:06 2009 (4B1E08B2)
90632000 90633380 swenum swenum.sys Mon Jul 13 19:45:08 2009 (4A5BC704)
8ae28000 8af71000 tcpip tcpip.sys Mon Jul 13 19:13:18 2009 (4A5BBF8E)
9880a000 98817000 tcpipreg tcpipreg.sys Mon Jul 13 19:54:14 2009 (4A5BC926)
8a9ea000 8a9f5000 TDI TDI.SYS Mon Jul 13 19:12:12 2009 (4A5BBF4C)
8a9d3000 8a9ea000 tdx tdx.sys Mon Jul 13 19:12:10 2009 (4A5BBF4A)
9030c000 9031c000 termdd termdd.sys Mon Jul 13 20:01:35 2009 (4A5BCADF)
98330000 98339000 TSDDD TSDDD.dll unavailable (00000000)
90018000 90039000 tunnel tunnel.sys Mon Jul 13 19:54:03 2009 (4A5BC91B)
8afea000 8afee180 TVALZ_O TVALZ_O.SYS Thu Nov 08 22:07:46 2007 (4733CF02)
9145d000 9146b000 umbus umbus.sys Mon Jul 13 19:51:38 2009 (4A5BC88A)
968ee000 96905000 usbccgp usbccgp.sys Mon Jul 13 19:51:31 2009 (4A5BC883)
915c6000 915c7700 USBD USBD.SYS Mon Jul 13 19:51:05 2009 (4A5BC869)
907c5000 907d4000 usbehci usbehci.sys Mon Jul 13 19:51:14 2009 (4A5BC872)
9146b000 914af000 usbhub usbhub.sys Mon Jul 13 19:52:06 2009 (4A5BC8A6)
90770000 9077a000 usbohci usbohci.sys Mon Jul 13 19:51:14 2009 (4A5BC872)
9077a000 907c5000 USBPORT USBPORT.SYS Mon Jul 13 19:51:13 2009 (4A5BC871)
96929000 96940000 USBSTOR USBSTOR.SYS Mon Jul 13 19:51:19 2009 (4A5BC877)
96905000 96928b00 usbvideo usbvideo.sys Mon Jul 13 19:51:51 2009 (4A5BC897)
8a82f000 8a83a000 vdrvroot vdrvroot.sys Mon Jul 13 19:46:19 2009 (4A5BC74B)
8abe7000 8abf3000 vga vga.sys Mon Jul 13 19:25:50 2009 (4A5BC27E)
8a981000 8a9a2000 VIDEOPRT VIDEOPRT.SYS Mon Jul 13 19:25:49 2009 (4A5BC27D)
8afa2000 8afaa380 vmstorfl vmstorfl.sys Mon Jul 13 19:28:44 2009 (4A5BC32C)
8a85e000 8a86e000 volmgr volmgr.sys Mon Jul 13 19:11:25 2009 (4A5BBF1D)
8a86e000 8a8b9000 volmgrx volmgrx.sys Mon Jul 13 19:11:41 2009 (4A5BBF2D)
8afab000 8afea000 volsnap volsnap.sys Mon Jul 13 19:11:34 2009 (4A5BBF26)
90766000 90770000 vwifibus vwifibus.sys Mon Jul 13 19:52:02 2009 (4A5BC8A2)
902da000 902eb000 vwififlt vwififlt.sys Mon Jul 13 19:52:03 2009 (4A5BC8A3)
902f9000 9030c000 wanarp wanarp.sys Mon Jul 13 19:55:02 2009 (4A5BC956)
8abf3000 8ac00000 watchdog watchdog.sys Mon Jul 13 19:24:10 2009 (4A5BC21A)
8a731000 8a7a2000 Wdf01000 Wdf01000.sys Mon Jul 13 19:11:36 2009 (4A5BBF28)
8a7a2000 8a7b0000 WDFLDR WDFLDR.SYS Mon Jul 13 19:11:25 2009 (4A5BBF1D)
902b4000 902bb000 wfplwf wfplwf.sys Mon Jul 13 19:53:51 2009 (4A5BC90F)
980d0000 9831a000 win32k win32k.sys unavailable (00000000)
8a600000 8a609000 WMILIB WMILIB.SYS Mon Jul 13 19:11:22 2009 (4A5BBF1A)
96966000 96980000 WudfPf WudfPf.sys Mon Jul 13 19:50:13 2009 (4A5BC835)
9973d000 9975d480 WUDFRd WUDFRd.sys Mon Jul 13 19:50:44 2009 (4A5BC854)
Unloaded modules:
997a7000 997c6000 cdrom.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
99633000 9969d000 spsys.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
8ac00000 8ac1f000 cdrom.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
98951000 98969000 parport.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
8ae18000 8ae25000 crashdmp.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
8ade0000 8adeb000 dump_ataport
Timestamp: unavailable (00000000)
Checksum: 00000000
8aff7000 8b000000 dump_atapi.s
Timestamp: unavailable (00000000)
Checksum: 00000000
8adeb000 8adfc000 dump_dumpfve
Timestamp: unavailable (00000000)
Checksum: 00000000