Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\Owner\Downloads\070510-40950-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\symbols*[URL]http://msdl.microsoft.com/download/symbols[/URL]
Executable search path is:
Windows 7 Kernel Version 7600 MP (4 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16539.x86fre.win7_gdr.100226-1909
Machine Name:
Kernel base = 0x82a4f000 PsLoadedModuleList = 0x82b97810
Debug session time: Mon Jul 5 16:23:51.837 2010 (GMT-4)
System Uptime: 0 days 0:06:05.476
Loading Kernel Symbols
...............................................................
................................................................
...........................................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck A, {c032de08, 0, 0, 82ac4296}
*** WARNING: Unable to verify timestamp for SYMEVENT.SYS
*** ERROR: Module load completed but symbols could not be loaded for SYMEVENT.SYS
[COLOR=Red]Probably caused by : SYMEVENT.SYS[/COLOR] ( SYMEVENT+14559 )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: c032de08, memory referenced
Arg2: 00000000, IRQL
Arg3: 00000000, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: 82ac4296, address which referenced memory
Debugging Details:
------------------
READ_ADDRESS: GetPointerFromAddress: unable to read from 82bb7718
Unable to read MiSystemVaType memory at 82b97160
c032de08
CURRENT_IRQL: 0
FAULTING_IP:
nt!MiPageMightBeZero+d
82ac4296 8b08 mov ecx,dword ptr [eax]
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xA
PROCESS_NAME: wmpnetwk.exe
TRAP_FRAME: a9bd55bc -- (.trap 0xffffffffa9bd55bc)
ErrCode = 00000000
eax=c032de08 ebx=1bdf4404 ecx=00000000 edx=83f0c6b0 esi=c03ade08 edi=83f0c6b0
eip=82ac4296 esp=a9bd5630 ebp=a9bd5638 iopl=0 nv up ei ng nz na po nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010282
nt!MiPageMightBeZero+0xd:
82ac4296 8b08 mov ecx,dword ptr [eax] ds:0023:c032de08=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from 82ac4296 to 82a9582b
STACK_TEXT:
a9bd55bc 82ac4296 badb0d00 83f0c6b0 00000001 nt!KiTrap0E+0x2cf
a9bd5638 82ac45b7 00000473 8920fd48 876e9c98 nt!MiPageMightBeZero+0xd
a9bd5860 82ac56a6 876e9c98 a9bd5890 ffffffff nt!MiFreeWsleList+0x1c4
a9bd5918 82d6b3b1 876e9c98 00000001 82b8fe28 nt!MiEmptyWorkingSet+0x1f7
a9bd5948 82c3afd2 ffffffff 00000000 ffffff00 nt!MmAdjustWorkingSetSizeEx+0x70
a9bd5a28 82c9c86e 00ffffff 01000038 0020fd01 nt!PspSetQuotaLimits+0x25f
a9bd5c88 91580559 ffffffff 00000001 00b6f668 nt!NtSetInformationProcess+0x424
WARNING: Stack unwind information not available. Following frames may be wrong.
a9bd5d1c 82a9244a ffffffff 00000001 00b6f668 [COLOR=Red]SYMEVENT[/COLOR]+0x14559
a9bd5d1c 0000003b ffffffff 00000001 00b6f668 nt!KiFastCallEntry+0x12a
00000001 00000000 00000000 00000000 00000000 0x3b
STACK_COMMAND: kb
FOLLOWUP_IP:
SYMEVENT+14559
91580559 ?? ???
SYMBOL_STACK_INDEX: 7
SYMBOL_NAME: SYMEVENT+14559
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: SYMEVENT
IMAGE_NAME: [COLOR=Red]SYMEVENT.SYS[/COLOR]
DEBUG_FLR_IMAGE_TIMESTAMP: 4a849231
FAILURE_BUCKET_ID: 0xA_[COLOR=Red]SYMEVENT[/COLOR]+14559
BUCKET_ID: 0xA_SYMEVENT+14559
Followup: MachineOwner
---------
Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\Owner\Downloads\070610-26738-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\symbols*[URL]http://msdl.microsoft.com/download/symbols[/URL]
Executable search path is:
Windows 7 Kernel Version 7600 MP (4 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16539.x86fre.win7_gdr.100226-1909
Machine Name:
Kernel base = 0x82a41000 PsLoadedModuleList = 0x82b89810
Debug session time: Tue Jul 6 10:22:04.141 2010 (GMT-4)
System Uptime: 0 days 11:16:14.436
Loading Kernel Symbols
...............................................................
................................................................
..............................
Loading User Symbols
Loading unloaded module list
.......
0: kd> !analyze
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 4E, {99, 1bf6f, 2, 1bd4d}
Probably caused by : memory_corruption ( nt!MiBadShareCount+24 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PFN_LIST_CORRUPT (4e)
Typically caused by drivers passing bad memory descriptor lists (ie: calling
MmUnlockPages twice with the same list, etc). If a kernel debugger is
available get the stack trace.
Arguments:
Arg1: 00000099, A PTE or PFN is corrupt
Arg2: 0001bf6f, page frame number
Arg3: 00000002, current page state
Arg4: 0001bd4d, 0
Debugging Details:
------------------
BUGCHECK_STR: 0x4E_99
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 2
LAST_CONTROL_TRANSFER: from 82b2a6dc to 82b1dd10
STACK_TEXT:
a49e2c10 82b2a6dc 0000004e 00000099 0001bf6f nt!KeBugCheckEx+0x1e
a49e2c28 82b01ee9 83f146a8 83f146a0 82a0fb48 nt!MiBadShareCount+0x24
a49e2c68 82b28673 00000000 82b28799 00000000 nt!MiRestoreTransitionPte+0x250
a49e2c70 82b28799 00000000 82b89bcc 000c7e8e nt!MiDiscardTransitionPte+0x9
a49e2ca8 82d66f3c 00000006 8d79bba0 00000000 nt!MiPurgeTransitionList+0xd2
a49e2d1c 82d60a7a a49e2d3c 00000000 854d66f8 nt!MmDuplicateMemory+0x957
a49e2d50 82c4f6bb 8d79bba0 97bc98af 00000000 nt!PopTransitionToSleep+0xce
a49e2d90 82b010f9 82d609ac 8d79bba0 00000000 nt!PspSystemThreadStartup+0x9e
00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x19
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!MiBadShareCount+24
82b2a6dc cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!MiBadShareCount+24
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 4b88cacf
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: 0x4E_99_nt!MiBadShareCount+24
BUCKET_ID: 0x4E_99_nt!MiBadShareCount+24
Followup: MachineOwner
---------