Loading Dump File [D:\Kingston\BSODDmpFiles\ShaunMac\Lots More Dumps\Windows_NT6_BSOD_jcgriff2\030812-19593-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`02e4b000 PsLoadedModuleList = 0xfffff800`03090670
Debug session time: Wed Mar 7 18:15:52.497 2012 (UTC - 7:00)
System Uptime: 0 days 0:36:26.699
Loading Kernel Symbols
...............................................................
................................................................
............................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 24, {1904fb, fffff88002ecb348, fffff88002ecaba0, fffff880012d3f7f}
Probably caused by : Ntfs.sys ( Ntfs!NtfsAcquireAllFiles+7f )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
NTFS_FILE_SYSTEM (24)
If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
parameters are the exception record and context record. Do a .cxr
on the 3rd parameter and then kb to obtain a more informative stack
trace.
Arguments:
Arg1: 00000000001904fb
Arg2: fffff88002ecb348
Arg3: fffff88002ecaba0
Arg4: fffff880012d3f7f
Debugging Details:
------------------
EXCEPTION_RECORD: fffff88002ecb348 -- (.exr 0xfffff88002ecb348)
ExceptionAddress: fffff880012d3f7f (Ntfs!NtfsAcquireAllFiles+0x000000000000007f)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
CONTEXT: fffff88002ecaba0 -- (.cxr 0xfffff88002ecaba0)
rax=fffffa8006d839e0 rbx=dffff8a0093da010 rcx=fffffa80079ff370
rdx=fffffa80079ff370 rsi=fffff8a00009e5c0 rdi=fffffa80079ff180
rip=fffff880012d3f7f rsp=fffff88002ecb580 rbp=fffff88002ecb960
r8=fffff8a00944a5c0 r9=fffff8a00944a5e0 r10=fffff88002ecb5d8
r11=000000000000001a r12=fffffa80072c6900 r13=fffffa8008317500
r14=0000000000000000 r15=0000000000000001
iopl=0 nv up ei ng nz na pe nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010282
Ntfs!NtfsAcquireAllFiles+0x7f:
fffff880`012d3f7f 0fba630408 bt dword ptr [rbx+4],8 ds:002b:dffff8a0`093da014=????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: ffffffffffffffff
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800030fa100
ffffffffffffffff
FOLLOWUP_IP:
Ntfs!NtfsAcquireAllFiles+7f
fffff880`012d3f7f 0fba630408 bt dword ptr [rbx+4],8
FAULTING_IP:
Ntfs!NtfsAcquireAllFiles+7f
fffff880`012d3f7f 0fba630408 bt dword ptr [rbx+4],8
BUGCHECK_STR: 0x24
LAST_CONTROL_TRANSFER: from fffff880013434fb to fffff880012d3f7f
STACK_TEXT:
fffff880`02ecb580 fffff880`013434fb : fffffa80`083175a0 fffff8a0`0944a5c0 00000000`00000001 fffff880`02ecb960 : Ntfs!NtfsAcquireAllFiles+0x7f
fffff880`02ecb5d0 fffff880`013445be : fffffa80`072c6900 fffffa80`07ab9c10 fffffa80`083175a0 fffffa80`07188150 : Ntfs!NtfsDefragFileInternal+0xaa8
fffff880`02ecb7a0 fffff880`01304cf2 : fffff880`00000000 fffffa80`06e82370 fffffa80`079ff180 fffffa80`083175a0 : Ntfs!NtfsDefragFile+0x43e
fffff880`02ecb840 fffff880`012bd53d : fffffa80`072c6900 00000000`00000000 fffff880`02ecb960 00000000`00000000 : Ntfs! ?? ::NNGAKEGL::`string'+0x1d079
fffff880`02ecb880 fffff880`0105fbcf : fffff880`02ecb9d0 fffffa80`07ab9c10 fffff880`02ecb901 fffffa80`072c6900 : Ntfs!NtfsFsdFileSystemControl+0x13d
fffff880`02ecb920 fffff880`0107f95e : fffffa80`07963860 fffffa80`06c1ed10 fffffa80`07963800 fffffa80`07ab9c10 : fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x24f
fffff880`02ecb9b0 fffff800`031e2a97 : fffffa80`06c1ed10 fffff880`02ecbca0 fffffa80`07ab9ff8 fffffa80`07ab9c10 : fltmgr!FltpFsControl+0xee
fffff880`02ecba10 fffff800`031a2342 : fffff680`003b9f00 00000000`00000000 00000000`00000000 00000000`00000000 : nt!IopXxxControlFile+0x607
fffff880`02ecbb40 fffff800`02ec6ed3 : 00000000`00000000 0000007f`ffffffff fffff880`02ecbca0 00000980`00000000 : nt!NtFsControlFile+0x56
fffff880`02ecbbb0 00000000`773816aa : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`00f9eaf8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x773816aa
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: Ntfs!NtfsAcquireAllFiles+7f
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Ntfs
IMAGE_NAME: Ntfs.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4d79997b
STACK_COMMAND: .cxr 0xfffff88002ecaba0 ; kb
FAILURE_BUCKET_ID: X64_0x24_Ntfs!NtfsAcquireAllFiles+7f
BUCKET_ID: X64_0x24_Ntfs!NtfsAcquireAllFiles+7f
Followup: MachineOwner
---------