Windows 7 Kernel Version 7600 MP (6 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`02c00000 PsLoadedModuleList = 0xfffff800`02e3de50
Debug session time: Mon Nov 1 13:37:04.700 2010 (GMT-4)
System Uptime: 0 days 0:24:47.604
Loading Kernel Symbols
...............................................................
................................................................
.......................
Loading User Symbols
Loading unloaded module list
.......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1A, {41287, 38, 0, 0}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+42ba5 )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041287, The subtype of the bugcheck.
Arg2: 0000000000000038
Arg3: 0000000000000000
Arg4: 0000000000000000
Debugging Details:
------------------
BUGCHECK_STR: 0x1a_41287
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: GoogleToolbarU
CURRENT_IRQL: 0
TRAP_FRAME: fffff880033088e0 -- (.trap 0xfffff880033088e0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffffa8008972dc0 rbx=0000000000000000 rcx=0000000000000000
rdx=fffff8a00251fab0 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002d76817 rsp=fffff88003308a70 rbp=0000000000000000
r8=fffffa800987000c r9=fffffa8007388048 r10=fffffa8006cd64b0
r11=fffffa8009ee3720 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na po nc
nt!MiEmptyPageAccessLog+0xe7:
fffff800`02d76817 8b4138 mov eax,dword ptr [rcx+38h] ds:00000000`00000038=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002c1cb7a to fffff80002c70740
STACK_TEXT:
fffff880`03308778 fffff800`02c1cb7a : 00000000`0000001a 00000000`00041287 00000000`00000038 00000000`00000000 : nt!KeBugCheckEx
fffff880`03308780 fffff800`02c6e82e : 00000000`00000000 00000000`00a6240c 00000000`00000000 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x42ba5
fffff880`033088e0 fffff800`02d76817 : 00000000`00000000 fffffa80`06cd64f0 fffffa80`0987e060 fffffa80`0987e060 : nt!KiPageFault+0x16e
fffff880`03308a70 fffff800`02cf2aac : fffffa80`0987e060 00000003`00000000 00000000`00000000 fffffa80`08972dc0 : nt!MiEmptyPageAccessLog+0xe7
fffff880`03308ae0 fffff800`02c84ee2 : 00000000`000005d0 00000000`00000000 fffffa80`00000000 00000000`00000003 : nt! ?? ::FNODOBFM::`string'+0x4972b
fffff880`03308b80 fffff800`02c85173 : 00000000`00000008 fffff880`03308c10 00000000`00000001 fffffa80`00000000 : nt!MmWorkingSetManager+0x6e
fffff880`03308bd0 fffff800`02f14c06 : fffffa80`06d258e0 00000000`00000080 fffffa80`06cad890 00000000`00000001 : nt!KeBalanceSetManager+0x1c3
fffff880`03308d40 fffff800`02c4ec26 : fffff880`02f64180 fffffa80`06d258e0 fffff880`02f6f040 89480000`0228249c : nt!PspSystemThreadStartup+0x5a
fffff880`03308d80 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KxStartSystemThread+0x16
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+42ba5
fffff800`02c1cb7a cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+42ba5
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
FAILURE_BUCKET_ID: X64_0x1a_41287_nt!_??_::FNODOBFM::_string_+42ba5
BUCKET_ID: X64_0x1a_41287_nt!_??_::FNODOBFM::_string_+42ba5
Followup: MachineOwner
---------
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fffff80002fb7d90, fffff8800bb8c090, 0}
Probably caused by : ntkrnlmp.exe ( nt!ObDereferenceSecurityDescriptor+20 )
Followup: MachineOwner
---------
3: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff80002fb7d90, Address of the exception record for the exception that caused the bugcheck
Arg3: fffff8800bb8c090, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!ObDereferenceSecurityDescriptor+20
fffff800`02fb7d90 8b4610 mov eax,dword ptr [rsi+10h]
CONTEXT: fffff8800bb8c090 -- (.cxr 0xfffff8800bb8c090)
rax=fffff8800bb8ca88 rbx=0000000000000000 rcx=0000000000000100
rdx=0000000000000001 rsi=00000000000000e0 rdi=0000000000000000
rip=fffff80002fb7d90 rsp=fffff8800bb8ca60 rbp=fffffa800a4871d0
r8=0000000000000000 r9=0000000000000000 r10=0000000000000000
r11=fffff8800bb8cb38 r12=0000000000000001 r13=fffffa800a462060
r14=00000000770a8b00 r15=fffff8a0025325f0
iopl=0 nv up ei ng nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010286
nt!ObDereferenceSecurityDescriptor+0x20:
fffff800`02fb7d90 8b4610 mov eax,dword ptr [rsi+10h] ds:002b:00000000`000000f0=????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: SearchProtocol
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff80002f822c4 to fffff80002fb7d90
STACK_TEXT:
fffff880`0bb8ca60 fffff800`02f822c4 : 00000000`00000000 fffffa80`0a4871d0 fffffa80`06d2b410 00000000`00000000 : nt!ObDereferenceSecurityDescriptor+0x20
fffff880`0bb8ca90 fffff800`02cc08ee : 00000000`00000000 fffffa80`0a462060 fffffa80`06d2b410 fffff880`0bb8cbc0 : nt!SeDefaultObjectMethod+0xa8
fffff880`0bb8cae0 fffff800`02fd1514 : fffffa80`0a462060 00000000`00000000 fffffa80`0a463060 00000000`00000000 : nt!ObfDereferenceObject+0x10e
fffff880`0bb8cb40 fffff800`02fd1414 : 00000000`000003d4 fffffa80`0a462060 fffff8a0`025325f0 00000000`000003d4 : nt!ObpCloseHandleTableEntry+0xc4
fffff880`0bb8cbd0 fffff800`02cba993 : fffffa80`0a463060 fffff880`0bb8cca0 000007fe`fb800000 00000000`00000001 : nt!ObpCloseHandle+0x94
fffff880`0bb8cc20 00000000`76fbfe4a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0020fa08 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x76fbfe4a
FOLLOWUP_IP:
nt!ObDereferenceSecurityDescriptor+20
fffff800`02fb7d90 8b4610 mov eax,dword ptr [rsi+10h]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!ObDereferenceSecurityDescriptor+20
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
STACK_COMMAND: .cxr 0xfffff8800bb8c090 ; kb
FAILURE_BUCKET_ID: X64_0x3B_nt!ObDereferenceSecurityDescriptor+20
BUCKET_ID: X64_0x3B_nt!ObDereferenceSecurityDescriptor+20
Followup: MachineOwner
---------