[FONT="Lucida Console"]Microsoft (R) Windows Debugger Version 6.3.9600.16384 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\YUSRA\Downloads\debug-FREELAND-PC-xxxx.zip\021615-40513-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
************* Symbol Path validation summary **************
Response Time (ms) Location
Deferred SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.18717.amd64fre.win7sp1_gdr.150113-1808
Machine Name:
Kernel base = 0xfffff800`0324e000 PsLoadedModuleList = 0xfffff800`03492890
Debug session time: Mon Feb 16 23:53:51.648 2015 (UTC + 6:00)
System Uptime: 0 days 0:59:08.959
Loading Kernel Symbols
.
Press ctrl-c (cdb, kd, ntsd) or ctrl-break (windbg) to abort symbol loads that take too long.
Run !sym noisy before .reload to track down problems loading symbols.
..............................................................
................................................................
................................................................
......
Loading User Symbols
Loading unloaded module list
......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1000007E, {ffffffffc0000005, fffff88001cfdd6e, fffff8800c08a7c8, fffff8800c08a020}
Probably caused by : volsnap.sys ( volsnap!VspCollectLazyOffsetsPass+1be )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff88001cfdd6e, The address that the exception occurred at
Arg3: fffff8800c08a7c8, Exception Record Address
Arg4: fffff8800c08a020, Context Record Address
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
volsnap!VspCollectLazyOffsetsPass+1be
fffff880`01cfdd6e 44892490 mov dword ptr [rax+rdx*4],r12d
EXCEPTION_RECORD: fffff8800c08a7c8 -- (.exr 0xfffff8800c08a7c8)
ExceptionAddress: fffff88001cfdd6e (volsnap!VspCollectLazyOffsetsPass+0x00000000000001be)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000001
Parameter[1]: 0000000000000000
Attempt to write to address 0000000000000000
CONTEXT: fffff8800c08a020 -- (.cxr 0xfffff8800c08a020;r)
rax=0000000000000000 rbx=0000000000000000 rcx=0000000000000007
rdx=0000000000000000 rsi=0000000000000002 rdi=fffff8800c08ab58
rip=fffff88001cfdd6e rsp=fffff8800c08aa00 rbp=0000000000000001
r8=0000000000000001 r9=0000000000000001 r10=fffff8800c08ab1c
r11=0000000000000007 r12=00000000000017fe r13=fffffa800754d7a8
r14=ffffffffffffffe0 r15=0000000000000000
iopl=0 nv up ei ng nz ac po cy
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010297
volsnap!VspCollectLazyOffsetsPass+0x1be:
fffff880`01cfdd6e 44892490 mov dword ptr [rax+rdx*4],r12d ds:002b:00000000`00000000=????????
Last set context:
rax=0000000000000000 rbx=0000000000000000 rcx=0000000000000007
rdx=0000000000000000 rsi=0000000000000002 rdi=fffff8800c08ab58
rip=fffff88001cfdd6e rsp=fffff8800c08aa00 rbp=0000000000000001
r8=0000000000000001 r9=0000000000000001 r10=fffff8800c08ab1c
r11=0000000000000007 r12=00000000000017fe r13=fffffa800754d7a8
r14=ffffffffffffffe0 r15=0000000000000000
iopl=0 nv up ei ng nz ac po cy
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010297
volsnap!VspCollectLazyOffsetsPass+0x1be:
fffff880`01cfdd6e 44892490 mov dword ptr [rax+rdx*4],r12d ds:002b:00000000`00000000=????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: NULL_DEREFERENCE
PROCESS_NAME: System
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_PARAMETER1: 0000000000000001
EXCEPTION_PARAMETER2: 0000000000000000
WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff800034fc100
GetUlongFromAddress: unable to read from fffff800034fc1c0
0000000000000000 Nonpaged pool
FOLLOWUP_IP:
volsnap!VspCollectLazyOffsetsPass+1be
fffff880`01cfdd6e 44892490 mov dword ptr [rax+rdx*4],r12d
BUGCHECK_STR: 0x7E
ANALYSIS_VERSION: 6.3.9600.16384 (debuggers(dbg).130821-1623) x86fre
LAST_CONTROL_TRANSFER: from fffff88001d1e14c to fffff88001cfdd6e
STACK_TEXT:
fffff880`0c08aa00 fffff880`01d1e14c : 00000000`00000002 fffff880`0c08ab00 fffff880`0c08aae0 fffff880`0c08ab20 : volsnap!VspCollectLazyOffsetsPass+0x1be
fffff880`0c08aa90 fffff880`01d1fcde : fffffa80`0015fb40 fffffa80`081ff190 fffff880`0c08ac00 fffffa80`0754d7f8 : volsnap!VspPopulateFreeBlocksBitmap+0x46c
fffff880`0c08abb0 fffff800`03561b8a : fffffa80`00000000 fffffa80`0d4e82e0 00000000`00000080 fffffa80`06ff9b30 : volsnap!VspLazyPreCopyOnWriteWorker+0xce
fffff880`0c08ac00 fffff800`032b48e6 : fffff800`0343fe80 fffffa80`0d4e82e0 fffff800`0344dcc0 00000000`ffffffff : nt!PspSystemThreadStartup+0x5a
fffff880`0c08ac40 00000000`00000000 : fffff880`0c08b000 fffff880`0c085000 fffff880`0c08a6e0 00000000`00000000 : nt!KxStartSystemThread+0x16
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: volsnap!VspCollectLazyOffsetsPass+1be
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: volsnap
IMAGE_NAME: volsnap.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4ce792c8
IMAGE_VERSION: 6.1.7601.17514
STACK_COMMAND: .cxr 0xfffff8800c08a020 ; kb
FAILURE_BUCKET_ID: X64_0x7E_volsnap!VspCollectLazyOffsetsPass+1be
BUCKET_ID: X64_0x7E_volsnap!VspCollectLazyOffsetsPass+1be
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:x64_0x7e_volsnap!vspcollectlazyoffsetspass+1be
FAILURE_ID_HASH: {c36379e8-0c82-cfd2-b688-8ec0884d4aed}
Followup: MachineOwner
---------
[/FONT]