[list=1][*]
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [D:\Kingston\BSODDmpFiles\gbu\Windows_NT6_BSOD_jcgriff2\031212-40887-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`0300b000 PsLoadedModuleList = 0xfffff800`03250670
Debug session time: Mon Mar 12 03:42:53.498 2012 (UTC - 6:00)
System Uptime: 0 days 0:05:16.825
Loading Kernel Symbols
...............................................................
................................................................
...............................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {fffffa80278c51b4, 1, fffff88001122700, 2}
Could not read faulting driver name
Probably caused by : fltmgr.sys ( fltmgr!FltpReleaseStreamListCtrl+0 )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: fffffa80278c51b4, memory referenced.
Arg2: 0000000000000001, value 0 = read operation, 1 = write operation.
Arg3: fffff88001122700, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000002, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff800032ba100
fffffa80278c51b4
FAULTING_IP:
fltmgr!FltpReleaseStreamListCtrl+0
fffff880`01122700 f0834144ff lock add dword ptr [rcx+44h],0FFFFFFFFh
MM_INTERNAL_CODE: 2
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: System
CURRENT_IRQL: 0
TRAP_FRAME: fffff8800317e6d0 -- (.trap 0xfffff8800317e6d0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffffa80278c5170 rbx=0000000000000000 rcx=fffffa80278c5170
rdx=000000000000384e rsi=0000000000000000 rdi=0000000000000000
rip=fffff88001122700 rsp=fffff8800317e868 rbp=fffff8800111d000
r8=fffffa8007b134a8 r9=00000000000000c0 r10=fffff8000300b000
r11=0000000000000398 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na pe nc
fltmgr!FltpReleaseStreamListCtrl:
fffff880`01122700 f0834144ff lock add dword ptr [rcx+44h],0FFFFFFFFh ds:0ec0:fffffa80`278c51b4=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff800030323f0 to fffff80003087c40
STACK_TEXT:
fffff880`0317e568 fffff800`030323f0 : 00000000`00000050 fffffa80`278c51b4 00000000`00000001 fffff880`0317e6d0 : nt!KeBugCheckEx
fffff880`0317e570 fffff800`03085d6e : 00000000`00000001 fffffa80`278c51b4 00000000`00000000 fffff8a0`0e6f2788 : nt! ?? ::FNODOBFM::`string'+0x447c6
fffff880`0317e6d0 fffff880`01122700 : fffff880`01147177 fffff8a0`0e5c0ed8 fffff880`0111d000 00000000`00000000 : nt!KiPageFault+0x16e
fffff880`0317e868 fffff880`01147177 : fffff8a0`0e5c0ed8 fffff880`0111d000 00000000`00000000 00000000`00000090 : fltmgr!FltpReleaseStreamListCtrl
fffff880`0317e870 fffff880`01142311 : fffffa80`06d29800 00000000`00000130 fffff8a0`0e720c70 00000000`00000000 : fltmgr! ?? ::NNGAKEGL::`string'+0x1100
fffff880`0317e8a0 fffff880`011423fb : fffffa80`06d29800 fffff8a0`0e720ed8 fffffa80`06d29800 fffff800`0307009d : fltmgr!CleanupStreamListCtrl+0x21
fffff880`0317e8e0 fffff800`0334090e : 00000000`00000001 fffff880`012b71b3 fffff8a0`0e720da0 fffff880`01233f49 : fltmgr!DeleteStreamListCtrlCallback+0x6b
fffff880`0317e910 fffff880`012b6bac : fffff8a0`0e720c70 fffffa80`06d77040 fffff880`0317e9e8 00000000`00000706 : nt!FsRtlTeardownPerStreamContexts+0xe2
fffff880`0317e960 fffff880`012bbcc1 : 00000000`00000000 00000000`00000000 fffff800`03228200 00000000`00000001 : Ntfs!NtfsDeleteScb+0x108
fffff880`0317e9a0 fffff880`0123485c : fffff8a0`0e720b70 fffff8a0`0e720c70 fffff800`03228200 fffff880`0317eb12 : Ntfs!NtfsRemoveScb+0x61
fffff880`0317e9e0 fffff880`012b964c : fffff8a0`0e720b40 fffff800`03228260 fffff880`0317eb12 fffffa80`0724be40 : Ntfs!NtfsPrepareFcbForRemoval+0x50
fffff880`0317ea10 fffff880`0123b0e2 : fffffa80`0724be40 fffffa80`0724be40 fffff8a0`0e720b40 00000000`00000000 : Ntfs!NtfsTeardownStructures+0xdc
fffff880`0317ea90 fffff880`012c9193 : fffffa80`0724be40 fffff800`03228260 fffff8a0`0e720b40 00000000`00000009 : Ntfs!NtfsDecrementCloseCounts+0xa2
fffff880`0317ead0 fffff880`012b8357 : fffffa80`0724be40 fffff8a0`0e720c70 fffff8a0`0e720b40 fffffa80`081cf180 : Ntfs!NtfsCommonClose+0x353
fffff880`0317eba0 fffff800`03092001 : 00000000`00000000 fffff800`03228200 fffffa80`06d77001 00000000`00000002 : Ntfs!NtfsFspClose+0x15f
fffff880`0317ec70 fffff800`03322fee : 00000000`00000000 fffffa80`06d77040 00000000`00000080 fffffa80`06d089e0 : nt!ExpWorkerThread+0x111
fffff880`0317ed00 fffff800`030795e6 : fffff880`02f64180 fffffa80`06d77040 fffff880`02f6efc0 00000000`00000000 : nt!PspSystemThreadStartup+0x5a
fffff880`0317ed40 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KxStartSystemThread+0x16
STACK_COMMAND: kb
FOLLOWUP_IP:
fltmgr!FltpReleaseStreamListCtrl+0
fffff880`01122700 f0834144ff lock add dword ptr [rcx+44h],0FFFFFFFFh
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: fltmgr!FltpReleaseStreamListCtrl+0
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: fltmgr
IMAGE_NAME: fltmgr.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4ce7929c
FAILURE_BUCKET_ID: X64_0x50_fltmgr!FltpReleaseStreamListCtrl+0
BUCKET_ID: X64_0x50_fltmgr!FltpReleaseStreamListCtrl+0
Followup: MachineOwner
---------
[*]
Loading Dump File [D:\Kingston\BSODDmpFiles\gbu\Windows_NT6_BSOD_jcgriff2\031112-26925-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`03063000 PsLoadedModuleList = 0xfffff800`032a8670
Debug session time: Sun Mar 11 09:54:31.863 2012 (UTC - 6:00)
System Uptime: 1 days 0:13:28.966
Loading Kernel Symbols
...............................................................
................................................................
...............................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1A, {41790, fffffa8003bc06a0, ffff, 0}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+36024 )
Followup: MachineOwner
---------
3: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041790, The subtype of the bugcheck.
Arg2: fffffa8003bc06a0
Arg3: 000000000000ffff
Arg4: 0000000000000000
Debugging Details:
------------------
BUGCHECK_STR: 0x1a_41790
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff8000314f150 to fffff800030dfc40
STACK_TEXT:
fffff880`07412918 fffff800`0314f150 : 00000000`0000001a 00000000`00041790 fffffa80`03bc06a0 00000000`0000ffff : nt!KeBugCheckEx
fffff880`07412920 fffff800`030cd0ff : fffffa80`00000000 00000000`39ecffff 00000000`00000000 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x36024
fffff880`07412ae0 fffff800`030deed3 : ffffffff`ffffffff 00000000`0195f858 00000000`0195f850 00000000`00008000 : nt!NtFreeVirtualMemory+0x61f
fffff880`07412be0 00000000`779f14fa : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0195f818 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x779f14fa
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+36024
fffff800`0314f150 cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+36024
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4e02aaa3
FAILURE_BUCKET_ID: X64_0x1a_41790_nt!_??_::FNODOBFM::_string_+36024
BUCKET_ID: X64_0x1a_41790_nt!_??_::FNODOBFM::_string_+36024
Followup: MachineOwner
---------
[/list]