Microsoft (R) Windows Debugger Version 6.12.0002.633 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\TUANTR~1\AppData\Local\Temp\Rar$DI00.102\062810-21138-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*e:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16539.x86fre.win7_gdr.100226-1909
Machine Name:
Kernel base = 0x82e3f000 PsLoadedModuleList = 0x82f87810
Debug session time: Tue Jun 29 07:22:01.746 2010 (UTC + 7:00)
System Uptime: 0 days 0:47:32.884
Loading Kernel Symbols
...............................................................
................................................................
..............................
Loading User Symbols
Loading unloaded module list
......
1: kd> !analyze
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 19, {20, 8560d000, 8560d300, 8600000}
GetPointerFromAddress: unable to read from 82fa7718
Unable to read MiSystemVaType memory at 82f87160
Probably caused by : ntkrpamp.exe ( nt!ExFreePoolWithTag+1b1 )
Followup: MachineOwner
---------