Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\DMP\051611-28782-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16385.amd64fre.win7_rtm.090713-1255
Machine Name:
Kernel base = 0xfffff800`02c65000 PsLoadedModuleList = 0xfffff800`02ea2e50
Debug session time: Mon May 16 15:12:42.077 2011 (UTC - 4:00)
System Uptime: 0 days 0:05:01.324
Loading Kernel Symbols
...............................................................
................................................................
...........................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1A, {41790, fffffa800098be30, ffff, 0}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+339d6 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041790, The subtype of the bugcheck.
Arg2: fffffa800098be30
Arg3: 000000000000ffff
Arg4: 0000000000000000
Debugging Details:
------------------
BUGCHECK_STR: 0x1a_41790
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: WMIADAP.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff80002d4926e to fffff80002cd6f00
STACK_TEXT:
fffff880`04472968 fffff800`02d4926e : 00000000`0000001a 00000000`00041790 fffffa80`0098be30 00000000`0000ffff : nt!KeBugCheckEx
fffff880`04472970 fffff800`02d18c4a : 00000000`00000000 00000000`01a62fff fffffa80`00000000 fffffa80`049b3060 : nt! ?? ::FNODOBFM::`string'+0x339d6
fffff880`04472b30 fffff800`02cd6153 : ffffffff`ffffffff 00000000`0024ef80 00000000`0024ef48 00000000`00008000 : nt!NtFreeVirtualMemory+0x5ca
fffff880`04472c20 00000000`7741009a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0024eeb8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7741009a
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+339d6
fffff800`02d4926e cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+339d6
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc600
FAILURE_BUCKET_ID: X64_0x1a_41790_nt!_??_::FNODOBFM::_string_+339d6
BUCKET_ID: X64_0x1a_41790_nt!_??_::FNODOBFM::_string_+339d6
Followup: MachineOwner
---------
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\DMP\051511-92758-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16385.amd64fre.win7_rtm.090713-1255
Machine Name:
Kernel base = 0xfffff800`02c59000 PsLoadedModuleList = 0xfffff800`02e96e50
Debug session time: Sun May 15 18:04:13.900 2011 (UTC - 4:00)
System Uptime: 0 days 0:03:05.023
Loading Kernel Symbols
...............................................................
................................................................
..........................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1A, {783, fffff88002fb67c0, fffff9802e580000, fffff8a00f2a7e40}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+2c2be )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000000783, The subtype of the bugcheck.
Arg2: fffff88002fb67c0
Arg3: fffff9802e580000
Arg4: fffff8a00f2a7e40
Debugging Details:
------------------
BUGCHECK_STR: 0x1a_783
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 2
LAST_CONTROL_TRANSFER: from fffff80002c6d4bf to fffff80002ccaf00
STACK_TEXT:
fffff880`02fb6728 fffff800`02c6d4bf : 00000000`0000001a 00000000`00000783 fffff880`02fb67c0 fffff980`2e580000 : nt!KeBugCheckEx
fffff880`02fb6730 fffff800`02fdee35 : fffff980`2e580000 fffff8a0`0f2a7e40 00000000`00000000 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x2c2be
fffff880`02fb6a10 fffff800`02ce3d47 : 00000000`00000000 fffffa80`03f0ebf0 00000000`00000000 00000000`00040000 : nt!CcUnmapVacb+0x5d
fffff880`02fb6a50 fffff800`02cbaad4 : 00000000`00000001 fffffa80`03f64720 fffffa80`03f63000 00000000`00000000 : nt!CcUnmapVacbArray+0x1b7
fffff880`02fb6ae0 fffff800`02cbe55c : fffffa80`03f63010 00000000`00000011 fffffa80`03f63010 fffff800`00000000 : nt!CcDeleteSharedCacheMap+0x140
fffff880`02fb6b50 fffff800`02cbed60 : fffff800`02ed0100 fffff880`02fb6c58 00000000`00000000 00000000`00000000 : nt!CcWriteBehind+0x5bc
fffff880`02fb6c00 fffff800`02cd8161 : fffffa80`039df930 fffff880`0123e270 fffff800`02ed0140 fffffa80`039e4b00 : nt!CcWorkerThread+0x1c8
fffff880`02fb6cb0 fffff800`02f6e166 : 00000000`00000000 fffffa80`039e4b60 00000000`00000080 fffffa80`0396d9e0 : nt!ExpWorkerThread+0x111
fffff880`02fb6d40 fffff800`02ca9486 : fffff880`009e7180 fffffa80`039e4b60 fffff880`009f1f40 00000000`000000e8 : nt!PspSystemThreadStartup+0x5a
fffff880`02fb6d80 00000000`00000000 : fffff880`02fb7000 fffff880`02fb1000 fffff880`02fb63b0 00000000`00000000 : nt!KxStartSystemThread+0x16
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+2c2be
fffff800`02c6d4bf cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+2c2be
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc600
FAILURE_BUCKET_ID: X64_0x1a_783_nt!_??_::FNODOBFM::_string_+2c2be
BUCKET_ID: X64_0x1a_783_nt!_??_::FNODOBFM::_string_+2c2be
Followup: MachineOwner
---------
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\DMP\051611-17456-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16385.amd64fre.win7_rtm.090713-1255
Machine Name:
Kernel base = 0xfffff800`02c0b000 PsLoadedModuleList = 0xfffff800`02e48e50
Debug session time: Mon May 16 14:55:18.713 2011 (UTC - 4:00)
System Uptime: 0 days 0:02:37.835
Loading Kernel Symbols
...............................................................
................................................................
.........................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {fffffa8803f8b1b0, 0, fffff80002caba79, 5}
Could not read faulting driver name
Probably caused by : memory_corruption ( nt!MmCopyToCachedPage+219 )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: fffffa8803f8b1b0, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff80002caba79, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000005, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002eb30e0
fffffa8803f8b1b0
FAULTING_IP:
nt!MmCopyToCachedPage+219
fffff800`02caba79 488b07 mov rax,qword ptr [rdi]
MM_INTERNAL_CODE: 5
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: WerFault.exe
CURRENT_IRQL: 0
TRAP_FRAME: fffff880072bd280 -- (.trap 0xfffff880072bd280)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=0000000fffffffff
rdx=fffff80002c0b000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002caba79 rsp=fffff880072bd410 rbp=fffff880072bd480
r8=0000098000000000 r9=00000000018ef040 r10=0000058000000000
r11=0000000000000002 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na pe nc
nt!MmCopyToCachedPage+0x219:
fffff800`02caba79 488b07 mov rax,qword ptr [rdi] ds:00000000`00000000=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002cfab91 to fffff80002c7cf00
STACK_TEXT:
fffff880`072bd118 fffff800`02cfab91 : 00000000`00000050 fffffa88`03f8b1b0 00000000`00000000 fffff880`072bd280 : nt!KeBugCheckEx
fffff880`072bd120 fffff800`02c7afee : 00000000`00000000 00000000`00000000 00000000`00000000 00001f80`00480000 : nt! ?? ::FNODOBFM::`string'+0x40f5b
fffff880`072bd280 fffff800`02caba79 : 00000000`00000002 ffffffff`ffffffff 00000000`00000002 ffffffff`ffffffff : nt!KiPageFault+0x16e
fffff880`072bd410 fffff800`02ca8e8e : fffff980`0293f000 00000000`018ef040 fffff880`00000000 00000000`00001000 : nt!MmCopyToCachedPage+0x219
fffff880`072bd600 fffff800`02ca8bf4 : fffffa80`051beb10 00000000`018ef040 fffff880`072bd740 fffff8a0`00000000 : nt!CcMapAndCopyInToCache+0x20e
fffff880`072bd6f0 fffff880`012b6fb8 : 00000000`02180000 fffffa80`051d3a00 fffff880`072bd7e0 fffffa80`00010000 : nt!CcCopyWrite+0x194
fffff880`072bd780 fffff880`01085132 : fffffa80`051d3a20 fffff880`01088732 00000000`00010000 00000000`00010001 : Ntfs!NtfsCopyWriteA+0x208
fffff880`072bd970 fffff880`01088c2a : fffff880`072bda40 fffffa80`03b6c0d8 00000000`018e0000 00000000`00010000 : fltmgr!FltpPerformFastIoCall+0xf2
fffff880`072bd9d0 fffff880`010a67fe : 00000000`00010000 00000000`00000000 fffffa80`051d3a20 fffff880`072bdb40 : fltmgr!FltpPassThroughFastIo+0xda
fffff880`072bda10 fffff800`02f9148e : fffffa80`051d3a94 fffffa80`00000002 fffffa80`03a1c080 fffffa80`051d3a94 : fltmgr!FltpFastIoWrite+0x1ce
fffff880`072bdab0 fffff800`02c7c153 : 00000000`00000701 00000000`000001a0 00000000`00000000 00000000`001da9d8 : nt!NtWriteFile+0x5ad
fffff880`072bdbb0 00000000`76f3ff3a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0010bda8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x76f3ff3a
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!MmCopyToCachedPage+219
fffff800`02caba79 488b07 mov rax,qword ptr [rdi]
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: nt!MmCopyToCachedPage+219
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc600
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: X64_0x50_nt!MmCopyToCachedPage+219
BUCKET_ID: X64_0x50_nt!MmCopyToCachedPage+219
Followup: MachineOwner
---------
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\DMP\051611-27284-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16385.amd64fre.win7_rtm.090713-1255
Machine Name:
Kernel base = 0xfffff800`02c09000 PsLoadedModuleList = 0xfffff800`02e46e50
Debug session time: Mon May 16 15:26:24.139 2011 (UTC - 4:00)
System Uptime: 0 days 0:03:18.386
Loading Kernel Symbols
...............................................................
................................................................
........................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1A, {41790, fffffa8000a05c30, ffff, 0}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+339d6 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041790, The subtype of the bugcheck.
Arg2: fffffa8000a05c30
Arg3: 000000000000ffff
Arg4: 0000000000000000
Debugging Details:
------------------
BUGCHECK_STR: 0x1a_41790
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: drvinst.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff80002ced26e to fffff80002c7af00
STACK_TEXT:
fffff880`038ff828 fffff800`02ced26e : 00000000`0000001a 00000000`00041790 fffffa80`00a05c30 00000000`0000ffff : nt!KeBugCheckEx
fffff880`038ff830 fffff800`02cae5d9 : 00000000`00000000 00000000`017bafff fffff880`00000000 fffffa80`043b1060 : nt! ?? ::FNODOBFM::`string'+0x339d6
fffff880`038ff9f0 fffff800`02f90e50 : fffffa80`068d1260 0007ffff`00000001 fffffa80`05cb1be0 fffffa80`066a18b0 : nt!MiRemoveMappedView+0xd9
fffff880`038ffb10 fffff800`02f9125b : 00000000`00000000 00000000`01120000 fffffa80`00000001 00000000`00000001 : nt!MiUnmapViewOfSection+0x1b0
fffff880`038ffbd0 fffff800`02c7a153 : 00000000`00000001 00000000`00000002 fffffa80`05029060 fffffa80`05718c60 : nt!NtUnmapViewOfSection+0x5f
fffff880`038ffc20 00000000`773e015a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`004edc68 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x773e015a
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+339d6
fffff800`02ced26e cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+339d6
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc600
FAILURE_BUCKET_ID: X64_0x1a_41790_nt!_??_::FNODOBFM::_string_+339d6
BUCKET_ID: X64_0x1a_41790_nt!_??_::FNODOBFM::_string_+339d6
Followup: MachineOwner
---------
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\DMP\051611-27830-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16385.amd64fre.win7_rtm.090713-1255
Machine Name:
Kernel base = 0xfffff800`02c13000 PsLoadedModuleList = 0xfffff800`02e50e50
Debug session time: Mon May 16 15:36:57.325 2011 (UTC - 4:00)
System Uptime: 0 days 0:02:58.572
Loading Kernel Symbols
.
Press ctrl-c (cdb, kd, ntsd) or ctrl-break (windbg) to abort symbol loads that take too long.
Run !sym noisy before .reload to track down problems loading symbols.
..............................................................
................................................................
.........................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1A, {41790, fffffa80009b05b0, ffff, 0}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+339d6 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041790, The subtype of the bugcheck.
Arg2: fffffa80009b05b0
Arg3: 000000000000ffff
Arg4: 0000000000000000
Debugging Details:
------------------
BUGCHECK_STR: 0x1a_41790
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: WerFault.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff80002cf726e to fffff80002c84f00
STACK_TEXT:
fffff880`02736828 fffff800`02cf726e : 00000000`0000001a 00000000`00041790 fffffa80`009b05b0 00000000`0000ffff : nt!KeBugCheckEx
fffff880`02736830 fffff800`02cb85d9 : 00000000`00000000 000007fe`f5d87fff fffffa80`00000000 fffffa80`059ff610 : nt! ?? ::FNODOBFM::`string'+0x339d6
fffff880`027369f0 fffff800`02f9ae50 : fffffa80`04b46ef0 0007ffff`00000000 00000000`00000000 00000000`00000000 : nt!MiRemoveMappedView+0xd9
fffff880`02736b10 fffff800`02f9b25b : 00000000`00000000 000007fe`f5cb0000 fffffa80`00000001 fffffa80`057b3010 : nt!MiUnmapViewOfSection+0x1b0
fffff880`02736bd0 fffff800`02c84153 : fffffa80`04b3f660 fffff880`02736ca0 fffffa80`04b3db30 00000000`00000000 : nt!NtUnmapViewOfSection+0x5f
fffff880`02736c20 00000000`76ea015a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0018ab58 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x76ea015a
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+339d6
fffff800`02cf726e cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+339d6
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc600
FAILURE_BUCKET_ID: X64_0x1a_41790_nt!_??_::FNODOBFM::_string_+339d6
BUCKET_ID: X64_0x1a_41790_nt!_??_::FNODOBFM::_string_+339d6
Followup: MachineOwner
---------