Loading Dump File [C:\DUMPS\MLT\021211-16489-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`03c0f000 PsLoadedModuleList = 0xfffff800`03e4ce50
Debug session time: Sat Feb 12 23:54:01.513 2011 (UTC + 0:00)
System Uptime: 0 days 0:00:22.574
Loading Kernel Symbols
..
Press ctrl-c (cdb, kd, ntsd) or ctrl-break (windbg) to abort symbol loads that take too long.
Run !sym noisy before .reload to track down problems loading symbols.
.............................................................
................................................................
....
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck A, {fffff8a001b8203e, 2, 1, fffff80003f65901}
Probably caused by : ntkrnlmp.exe ( nt!ObpQueryNameString+4ed )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: fffff8a001b8203e, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000001, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff80003f65901, address which referenced memory
Debugging Details:
------------------
WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff80003eb70e0
fffff8a001b8203e
CURRENT_IRQL: 2
FAULTING_IP:
nt!ObpQueryNameString+4ed
fffff800`03f65901 668939 mov word ptr [rcx],di
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xA
PROCESS_NAME: MpCmdRun.exe
TRAP_FRAME: fffff88002a4c240 -- (.trap 0xfffff88002a4c240)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000020 rbx=0000000000000000 rcx=fffff8a001b8203e
rdx=fffff8a00000b010 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80003f65901 rsp=fffff88002a4c3d0 rbp=fffff88002a4c780
r8=0000000000002000 r9=fffff88002a4c5d0 r10=0000000000000000
r11=00000000000001c8 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz ac pe nc
nt!ObpQueryNameString+0x4ed:
fffff800`03f65901 668939 mov word ptr [rcx],di ds:1c10:fffff8a0`01b8203e=????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80003c7eca9 to fffff80003c7f740
STACK_TEXT:
fffff880`02a4c0f8 fffff800`03c7eca9 : 00000000`0000000a fffff8a0`01b8203e 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
fffff880`02a4c100 fffff800`03c7d920 : ffffffff`fffffffe fffffa80`05c87c80 00000000`00000000 fffff800`03df9e80 : nt!KiBugCheckDispatch+0x69
fffff880`02a4c240 fffff800`03f65901 : fffff880`02a4c780 fffff8a0`0000b030 00000000`00000001 fffffa80`07bba000 : nt!KiPageFault+0x260
fffff880`02a4c3d0 fffff800`03f6656a : fffffa80`05c87cd0 fffff8a0`01b82000 fffffa80`00002000 fffff880`02a4c5d0 : nt!ObpQueryNameString+0x4ed
fffff880`02a4c4d0 fffff800`03f65ecf : fffff880`00401802 fffffa80`06aadd00 fffff8a0`20206f49 00000000`03c7ac13 : nt!ObQueryNameString+0xe
fffff880`02a4c510 fffff800`03f66612 : fffffa80`06aadd00 fffff960`00401802 00000000`00000000 fffffa80`07bba000 : nt!IopQueryNameInternal+0x9f
fffff880`02a4c5b0 fffff800`03f654c4 : 00000000`00000000 fffff800`00401802 00000000`00000000 fffffa80`07bba000 : nt!IopQueryName+0x26
fffff880`02a4c600 fffff800`03edada3 : fffffa80`06aadd00 fffffa80`07bba000 fffff8a0`00002000 fffff880`02a4c798 : nt!ObpQueryNameString+0xb0
fffff880`02a4c700 fffff800`03f3c43e : fffffa80`07b969d0 00000000`00000000 fffffa80`07bcb9a0 00000000`00000001 : nt! ?? ::NNGAKEGL::`string'+0x210a4
fffff880`02a4c8a0 fffff800`03f64cd4 : 000007ff`fffd8000 fffff880`02a4cc20 00000000`00000000 fffffa80`075ffa60 : nt!PspExitProcess+0x4e
fffff880`02a4c900 fffff800`03f3d635 : 00000000`00000000 fffffa80`07bcb901 000007ff`fffd8000 00000000`00000000 : nt!PspExitThread+0x834
fffff880`02a4c9c0 fffff800`03c5c1db : 00000000`00000000 00000000`00000000 fffffa80`07b905b0 00000000`00000000 : nt!PsExitSpecialApc+0x1d
fffff880`02a4c9f0 fffff800`03c5c620 : 00000000`0018ae90 fffff880`02a4ca70 fffff800`03f3d74c 00000000`00000001 : nt!KiDeliverApc+0x2eb
fffff880`02a4ca70 fffff800`03c7ea37 : ffffffff`ffffffff 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiInitiateUserApc+0x70
fffff880`02a4cbb0 00000000`777bfdba : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExit+0x9c
00000000`00efee98 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x777bfdba
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!ObpQueryNameString+4ed
fffff800`03f65901 668939 mov word ptr [rcx],di
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: nt!ObpQueryNameString+4ed
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
FAILURE_BUCKET_ID: X64_0xA_nt!ObpQueryNameString+4ed
BUCKET_ID: X64_0xA_nt!ObpQueryNameString+4ed
Followup: MachineOwner