Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\a\Minidump\D M P\121810-17706-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16385.x86fre.win7_rtm.090713-1255
Machine Name:
Kernel base = 0x81a49000 PsLoadedModuleList = 0x81b91810
Debug session time: Sun Dec 19 01:13:22.364 2010 (UTC - 5:00)
System Uptime: 0 days 0:25:03.160
Loading Kernel Symbols
...............................................................
................................................................
...................
Loading User Symbols
Loading unloaded module list
....
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 00008887, The subtype of the bugcheck.
Arg2: 8366b8ac
Arg3: 8366b7b0
Arg4: 00000205
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for eamon.sys
*** ERROR: Module load completed but symbols could not be loaded for eamon.sys
BUGCHECK_STR: 0x1a_8887
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: TrustedInstall
CURRENT_IRQL: 2
STACK_TEXT:
97ac183c 81ae3016 0000001a 00008887 8366b8ac nt!KeBugCheckEx+0x1e
97ac187c 81aaad7b 00000000 af8f0000 00530000 nt!MiUnlinkPageFromLockedList+0x51
97ac197c 81aff866 af8f0000 00010000 00000000 nt!MmCheckCachedPageStates+0x2c2
97ac19b4 81ca6d20 8499b408 00000001 97ac1a2c nt!CcFetchDataForRead+0xb6
97ac19f4 81ca8987 8499b408 00530000 00000000 nt!CcMapAndCopyFromCache+0x71
97ac1a34 88440c8b 8499b408 97ac1a78 00010000 nt!CcCopyRead+0x107
97ac1a60 8843e541 843802c0 8499b408 841b3550 Ntfs!NtfsCachedRead+0x13e
97ac1b3c 88441bae 843802c0 841b3550 1fea612f Ntfs!NtfsCommonRead+0x11a1
97ac1bac 81a854bc 84b22020 841b3550 841b3550 Ntfs!NtfsFsdRead+0x279
97ac1bc4 882e220c 84b20138 841b3550 00000000 nt!IofCallDriver+0x63
97ac1be8 882e23cb 97ac1c08 84b20138 00000000 fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x2aa
97ac1c20 81a854bc 84b20138 841b3550 981826ec fltmgr!FltpDispatch+0xc5
97ac1c38 9814d7dd 8550bb40 97ac1c5c 81a854bc nt!IofCallDriver+0x63
WARNING: Stack unwind information not available. Following frames may be wrong.
97ac1c44 81a854bc 8550bb40 841b3550 841b3550 eamon+0x37dd
97ac1c5c 81c86eee 841b3550 841b374c 8499b408 nt!IofCallDriver+0x63
97ac1c7c 81c98ea6 8550bb40 8499b408 00000001 nt!IopSynchronousServiceTail+0x1f8
97ac1d08 81a8c42a 8550bb40 841b3550 00000000 nt!NtReadFile+0x644
97ac1d08 775264f4 8550bb40 841b3550 00000000 nt!KiFastCallEntry+0x12a
0064e4d4 00000000 00000000 00000000 00000000 0x775264f4
STACK_COMMAND: kb
SYMBOL_NAME: ZEROED_PAGE_CORRUPTED
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: hardware
IMAGE_NAME: hardware_ram
DEBUG_FLR_IMAGE_TIMESTAMP: 0
FAILURE_BUCKET_ID: 0x1a_8887_ZEROED_PAGE_CORRUPTED
BUCKET_ID: 0x1a_8887_ZEROED_PAGE_CORRUPTED
Followup: MachineOwner
---------
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\a\Minidump\D M P\121810-22120-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16385.x86fre.win7_rtm.090713-1255
Machine Name:
Kernel base = 0x81a55000 PsLoadedModuleList = 0x81b9d810
Debug session time: Sun Dec 19 00:46:55.471 2010 (UTC - 5:00)
System Uptime: 0 days 1:57:06.283
Loading Kernel Symbols
...............................................................
................................................................
...................
Loading User Symbols
Loading unloaded module list
....
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 00008887, The subtype of the bugcheck.
Arg2: 8358ed48
Arg3: 83891448
Arg4: 00000500
Debugging Details:
------------------
BUGCHECK_STR: 0x1a_8887
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 2
STACK_TEXT:
8942f7b4 81aef016 0000001a 00008887 8358ed48 nt!KeBugCheckEx+0x1e
8942f7f4 81af7bc9 00000000 00000000 00000000 nt!MiUnlinkPageFromLockedList+0x51
8942f864 81b075b5 84120300 01000000 0004519e nt!MmPurgeSection+0x665
8942f894 8846ed8b 8403e738 00000000 00000000 nt!CcPurgeCacheSection+0xe2
8942f8e0 8849322b 8412f008 a4d2b9f8 00000000 Ntfs!NtfsFlushAndPurgeScb+0xc0
8942f94c 8849e129 8412f008 84cfb7a4 84db30d8 Ntfs!NtfsOpenAttribute+0x807
8942f9a8 88495217 8412f008 84cfb5f0 a4d2bba0 Ntfs!NtfsOpenExistingAttr+0x2e7
8942fa90 88495677 8412f008 84cfb5f0 a4d2bba0 Ntfs!NtfsOpenAttributeInExistingFile+0x7a4
8942fb3c 88494a2d 8412f008 84cfb5f0 a4d2bba0 Ntfs!NtfsOpenExistingPrefixFcb+0x26e
8942fb9c 88496c5c 8412f008 84cfb5f0 8d691528 Ntfs!NtfsFindStartingNode+0xb88
8942fc78 8841b426 8412f008 84cfb5f0 9a1978f0 Ntfs!NtfsCommonCreate+0x65f
8942fd00 81ac2f2b 0012f008 00000000 83c88518 Ntfs!NtfsFspDispatch+0x1b0
8942fd50 81c6366d 00000000 ab3b901b 00000000 nt!ExpWorkerThread+0x10d
8942fd90 81b150d9 81ac2e1e 00000000 00000000 nt!PspSystemThreadStartup+0x9e
00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x19
STACK_COMMAND: kb
SYMBOL_NAME: ZEROED_PAGE_CORRUPTED
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: hardware
IMAGE_NAME: hardware_ram
DEBUG_FLR_IMAGE_TIMESTAMP: 0
FAILURE_BUCKET_ID: 0x1a_8887_ZEROED_PAGE_CORRUPTED
BUCKET_ID: 0x1a_8887_ZEROED_PAGE_CORRUPTED
Followup: MachineOwner
---------
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\a\Minidump\D M P\121810-16333-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Mini Kernel Dump does not have process information
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Unable to load image Unknown_Module_4e3914fa, Win32 error 0n2
*** WARNING: Unable to verify timestamp for Unknown_Module_4e3914fa
*** ERROR: Module load completed but symbols could not be loaded for Unknown_Module_4e3914fa
Debugger can not determine kernel base address
Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16385.x86fre.win7_rtm.090713-1255
Machine Name:
Kernel base = 0x81a04000 PsLoadedModuleList = 0x81b4c810
Debug session time: Sat Dec 18 22:49:05.919 2010 (UTC - 5:00)
System Uptime: 0 days 0:21:09.731
Unable to load image Unknown_Module_4e3914fa, Win32 error 0n2
*** WARNING: Unable to verify timestamp for Unknown_Module_4e3914fa
*** ERROR: Module load completed but symbols could not be loaded for Unknown_Module_4e3914fa
Debugger can not determine kernel base address
Loading Kernel Symbols
.
Loading User Symbols
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: d43081a7, memory referenced.
Arg2: 00000008, value 0 = read operation, 1 = write operation.
Arg3: 8946fb96, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 00000002, (reserved)
Debugging Details:
------------------
***** Debugger could not find nt in module list, module list might be corrupt, error 0x80070057.
*** WARNING: Unable to verify timestamp for Unknown_Module_4e3914fa
*** ERROR: Module load completed but symbols could not be loaded for Unknown_Module_4e3914fa
WRITE_ADDRESS: unable to get nt!MmSpecialPoolStart
unable to get nt!MmSpecialPoolEnd
unable to get nt!MmPoolCodeStart
unable to get nt!MmPoolCodeEnd
d43081a7
FAULTING_IP:
+3034636636353132
8946fb96 46 inc esi
MM_INTERNAL_CODE: 2
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 81a4a5f8 to 81a898e3
STACK_TEXT:
WARNING: Frame IP not in any known module. Following frames may be wrong.
8946fb7e 81a4a5f8 00000008 d43081a7 00000000 0x81a898e3
8946fb96 d43081a7 badb0d00 00000000 6d4d81b3 0x81a4a5f8
8946fb9a badb0d00 00000000 6d4d81b3 d4300000 0xd43081a7
8946fb9e 00000000 6d4d81b3 d4300000 0d4483c8 0xbadb0d00
STACK_COMMAND: kb
SYMBOL_NAME: ANALYSIS_INCONCLUSIVE
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Unknown_Module
IMAGE_NAME: Unknown_Image
DEBUG_FLR_IMAGE_TIMESTAMP: 0
BUCKET_ID: CORRUPT_MODULELIST
Followup: MachineOwner
---------