Windows 7 Kernel Version 7600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`02a63000 PsLoadedModuleList = 0xfffff800`02ca0e50
Debug session time: Sat Jan 1 22:29:02.731 2011 (GMT-5)
System Uptime: 1 days 18:49:26.197
Loading Kernel Symbols
...............................................................
................................................................
......................
Loading User Symbols
Loading unloaded module list
......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fffff80002d28b38, fffff88006eab020, 0}
Probably caused by : ntkrnlmp.exe ( nt!AlpcpFreeCompletionList+14 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff80002d28b38, Address of the exception record for the exception that caused the bugcheck
Arg3: fffff88006eab020, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!AlpcpFreeCompletionList+14
fffff800`02d28b38 488b4b18 mov rcx,qword ptr [rbx+18h]
CONTEXT: fffff88006eab020 -- (.cxr 0xfffff88006eab020)
rax=0000000000000000 rbx=0000000000000016 rcx=fffffa80067aee60
rdx=0000000000000000 rsi=fffffa80067aef78 rdi=fffffa80067aee60
rip=fffff80002d28b38 rsp=fffff88006eab9f0 rbp=fffffa80065a5b30
r8=0000000000000001 r9=0000000000000001 r10=fffffa80065cea30
r11=fffff88006eabaf8 r12=fffffa80065a5b30 r13=0000000000000001
r14=000007fefe020000 r15=fffff8a001d02e40
iopl=0 nv up ei ng nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010286
nt!AlpcpFreeCompletionList+0x14:
fffff800`02d28b38 488b4b18 mov rcx,qword ptr [rbx+18h] ds:002b:00000000`0000002e=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff80002d7896b to fffff80002d28b38
STACK_TEXT:
fffff880`06eab9f0 fffff800`02d7896b : 00000000`00000000 fffffa80`065a5b30 00000000`00000001 00000000`00000001 : nt!AlpcpFreeCompletionList+0x14
fffff880`06eaba20 fffff800`02d79578 : fffffa80`067aee60 00000000`00000001 fffffa80`00000030 00000000`00001000 : nt!AlpcpDoPortCleanup+0x127
fffff880`06eaba50 fffff800`02dcfa24 : 00000000`00000000 fffffa80`067aee30 00000000`000000ff 00000000`00000000 : nt!AlpcpClosePort+0x44
fffff880`06eaba80 fffff800`02de9501 : fffffa80`065a5b30 fffffa80`00000001 fffff8a0`01d02e40 00000000`00000000 : nt!ObpDecrementHandleCount+0xb4
fffff880`06eabb00 fffff800`02de9414 : 00000000`00000450 fffffa80`065a5b30 fffff8a0`01d02e40 00000000`00000450 : nt!ObpCloseHandleTableEntry+0xb1
fffff880`06eabb90 fffff800`02ad2993 : fffffa80`063c6800 fffff880`06eabc60 00000000`00265c50 fffffa80`06599fc0 : nt!ObpCloseHandle+0x94
fffff880`06eabbe0 00000000`779efe4a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0155f658 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x779efe4a
FOLLOWUP_IP:
nt!AlpcpFreeCompletionList+14
fffff800`02d28b38 488b4b18 mov rcx,qword ptr [rbx+18h]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!AlpcpFreeCompletionList+14
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
STACK_COMMAND: .cxr 0xfffff88006eab020 ; kb
FAILURE_BUCKET_ID: X64_0x3B_nt!AlpcpFreeCompletionList+14
BUCKET_ID: X64_0x3B_nt!AlpcpFreeCompletionList+14
Followup: MachineOwner
---------
Windows 7 Kernel Version 7600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`02a65000 PsLoadedModuleList = 0xfffff800`02ca2e50
Debug session time: Fri Jan 7 08:53:08.133 2011 (GMT-5)
System Uptime: 1 days 4:59:24.006
Loading Kernel Symbols
...............................................................
................................................................
.......................
Loading User Symbols
Loading unloaded module list
.......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 34, {50830, fffff88005d875f8, fffff88005d86e60, fffff80002c0a0f3}
Probably caused by : ntkrnlmp.exe ( nt!ExFreePoolWithTag+43 )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
CACHE_MANAGER (34)
See the comment for FAT_FILE_SYSTEM (0x23)
Arguments:
Arg1: 0000000000050830
Arg2: fffff88005d875f8
Arg3: fffff88005d86e60
Arg4: fffff80002c0a0f3
Debugging Details:
------------------
EXCEPTION_RECORD: fffff88005d875f8 -- (.exr 0xfffff88005d875f8)
ExceptionAddress: fffff80002c0a0f3 (nt!ExFreePoolWithTag+0x0000000000000043)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: 0000000000000080
Attempt to read from address 0000000000000080
CONTEXT: fffff88005d86e60 -- (.cxr 0xfffff88005d86e60)
rax=0000000000000000 rbx=fffffa8004a1f588 rcx=0000000000000090
rdx=0000000000000000 rsi=0000000000000001 rdi=fffffa8004a1f540
rip=fffff80002c0a0f3 rsp=fffff88005d87830 rbp=fffff88005d87a68
r8=0000000000000000 r9=0000000000699000 r10=00000000ffffffff
r11=00000000fffffff9 r12=0000000000000000 r13=0000000000000090
r14=00000000000002fd r15=0000000000000001
iopl=0 nv up ei pl nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010206
nt!ExFreePoolWithTag+0x43:
fffff800`02c0a0f3 418b45f0 mov eax,dword ptr [r13-10h] ds:002b:00000000`00000080=????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: 0000000000000080
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002d0d0e0
0000000000000080
FOLLOWUP_IP:
nt!ExFreePoolWithTag+43
fffff800`02c0a0f3 418b45f0 mov eax,dword ptr [r13-10h]
FAULTING_IP:
nt!ExFreePoolWithTag+43
fffff800`02c0a0f3 418b45f0 mov eax,dword ptr [r13-10h]
BUGCHECK_STR: 0x34
DEFAULT_BUCKET_ID: NULL_CLASS_PTR_DEREFERENCE
LAST_CONTROL_TRANSFER: from fffff80002ac20f0 to fffff80002c0a0f3
STACK_TEXT:
fffff880`05d87830 fffff800`02ac20f0 : 00000000`00000000 00000000`00001000 00000000`00000000 00000000`00002699 : nt!ExFreePoolWithTag+0x43
fffff880`05d878e0 fffff800`02aeacbe : 00000000`ffffffff fffff880`05d87a68 00000000`00000001 fffff8a0`003b04d0 : nt!ExDeleteResourceLite+0x190
fffff880`05d87940 fffff800`02ac50b7 : fffffa80`04896d90 fffff880`05d87a68 00000000`00000001 fffffa80`04896d90 : nt!CcUnpinFileDataEx+0x3fe
fffff880`05d879c0 fffff800`02ac12bb : 00000000`006614ab fffff880`05d87c18 00000000`00001000 00000000`00000000 : nt!CcReleaseByteRangeFromWrite+0xa7
fffff880`05d87a10 fffff800`02ac894b : fffffa80`04e2cd68 fffff800`00000001 00000000`00000001 fffff800`00001000 : nt!CcFlushCache+0x64b
fffff880`05d87b10 fffff800`02ac9520 : fffff880`05d87b00 fffff880`05d87c18 00000000`00000000 fffff800`00000000 : nt!CcWriteBehind+0x1eb
fffff880`05d87bc0 fffff800`02ae2961 : fffffa80`03d04800 fffff880`012dc230 fffff800`02cdc140 fffff880`00000005 : nt!CcWorkerThread+0x1c8
fffff880`05d87c70 fffff800`02d79c06 : fffff880`02a99650 fffffa80`04e1fb60 00000000`00000080 fffffa80`03c6e890 : nt!ExpWorkerThread+0x111
fffff880`05d87d00 fffff800`02ab3c26 : fffff880`02fd3180 fffffa80`04e1fb60 fffffa80`03cfc040 fffff880`01269a90 : nt!PspSystemThreadStartup+0x5a
fffff880`05d87d40 00000000`00000000 : fffff880`05d88000 fffff880`05d82000 fffff880`05d86ce0 00000000`00000000 : nt!KxStartSystemThread+0x16
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!ExFreePoolWithTag+43
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
STACK_COMMAND: .cxr 0xfffff88005d86e60 ; kb
FAILURE_BUCKET_ID: X64_0x34_nt!ExFreePoolWithTag+43
BUCKET_ID: X64_0x34_nt!ExFreePoolWithTag+43
Followup: MachineOwner
---------