Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\a\Minidump\D M P\DMP\030711-20061-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16695.amd64fre.win7_gdr.101026-1503
Machine Name:
Kernel base = 0xfffff800`0280e000 PsLoadedModuleList = 0xfffff800`02a4be50
Debug session time: Mon Mar 7 15:43:39.845 2011 (UTC - 5:00)
System Uptime: 0 days 0:00:30.515
Loading Kernel Symbols
...............................................................
................................................................
....................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fffff800029b290d, fffff88006d2ca80, 0}
Probably caused by : ntkrnlmp.exe ( nt!ExAllocatePoolWithTag+53d )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff800029b290d, Address of the instruction which caused the bugcheck
Arg3: fffff88006d2ca80, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!ExAllocatePoolWithTag+53d
fffff800`029b290d 48895808 mov qword ptr [rax+8],rbx
CONTEXT: fffff88006d2ca80 -- (.cxr 0xfffff88006d2ca80)
rax=fffbf8a00291efd0 rbx=fffffa80015302b0 rcx=fffff8a00288d580
rdx=0000000000000028 rsi=0000000000001000 rdi=0000000000000001
rip=fffff800029b290d rsp=fffff88006d2d450 rbp=fffffa8001530140
r8=0000000000000001 r9=fffffa80015302b0 r10=fffffa8001530148
r11=0000000000000001 r12=0000000000000004 r13=0000000000000000
r14=fffffa8004829060 r15=0000000069634d43
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010246
nt!ExAllocatePoolWithTag+0x53d:
fffff800`029b290d 48895808 mov qword ptr [rax+8],rbx ds:002b:fffbf8a0`0291efd8=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: MOM.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff800029b290d
STACK_TEXT:
fffff880`06d2d450 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!ExAllocatePoolWithTag+0x53d
FOLLOWUP_IP:
nt!ExAllocatePoolWithTag+53d
fffff800`029b290d 48895808 mov qword ptr [rax+8],rbx
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!ExAllocatePoolWithTag+53d
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4cc791bd
STACK_COMMAND: .cxr 0xfffff88006d2ca80 ; kb
FAILURE_BUCKET_ID: X64_0x3B_nt!ExAllocatePoolWithTag+53d
BUCKET_ID: X64_0x3B_nt!ExAllocatePoolWithTag+53d
Followup: MachineOwner
---------
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\a\Minidump\D M P\DMP\030711-19250-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16695.amd64fre.win7_gdr.101026-1503
Machine Name:
Kernel base = 0xfffff800`02862000 PsLoadedModuleList = 0xfffff800`02a9fe50
Debug session time: Mon Mar 7 16:13:57.631 2011 (UTC - 5:00)
System Uptime: 0 days 0:00:26.301
Loading Kernel Symbols
...............................................................
................................................................
...................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fffff80002a05f8c, fffff88002e18e40, 0}
Probably caused by : Pool_Corruption ( nt!ExDeferredFreePool+100 )
Followup: Pool_corruption
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff80002a05f8c, Address of the instruction which caused the bugcheck
Arg3: fffff88002e18e40, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!ExDeferredFreePool+100
fffff800`02a05f8c 4c8b02 mov r8,qword ptr [rdx]
CONTEXT: fffff88002e18e40 -- (.cxr 0xfffff88002e18e40)
rax=fffffa8001530330 rbx=0000000000000001 rcx=fffffa8001530330
rdx=fffbf8a0024aeb00 rsi=0000000000000000 rdi=fffff8a0025a7a80
rip=fffff80002a05f8c rsp=fffff88002e19810 rbp=0000000000000000
r8=fffbf8a0024aeb00 r9=0000000000000000 r10=fffff8a00259ea50
r11=0000000000000000 r12=fffffa8001530140 r13=0000000000000000
r14=000000000000001b r15=0000000000000001
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010246
nt!ExDeferredFreePool+0x100:
fffff800`02a05f8c 4c8b02 mov r8,qword ptr [rdx] ds:002b:fffbf8a0`024aeb00=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: services.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff80002a05f8c
STACK_TEXT:
fffff880`02e19810 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!ExDeferredFreePool+0x100
FOLLOWUP_IP:
nt!ExDeferredFreePool+100
fffff800`02a05f8c 4c8b02 mov r8,qword ptr [rdx]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!ExDeferredFreePool+100
FOLLOWUP_NAME: Pool_corruption
IMAGE_NAME: Pool_Corruption
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MODULE_NAME: Pool_Corruption
STACK_COMMAND: .cxr 0xfffff88002e18e40 ; kb
FAILURE_BUCKET_ID: X64_0x3B_nt!ExDeferredFreePool+100
BUCKET_ID: X64_0x3B_nt!ExDeferredFreePool+100
Followup: Pool_corruption
---------