*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 4E, {2, 254ad2, 25fdff, ffff}
Probably caused by : memory_corruption ( nt!MiUnlinkPageFromLockedList+8d )
Followup: MachineOwner
---------
4: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PFN_LIST_CORRUPT (4e)
Typically caused by drivers passing bad memory descriptor lists (ie: calling
MmUnlockPages twice with the same list, etc). If a kernel debugger is
available get the stack trace.
Arguments:
Arg1: 0000000000000002, A list entry was corrupt
Arg2: 0000000000254ad2, entry in list being removed
Arg3: 000000000025fdff, highest physical page number
Arg4: 000000000000ffff, reference count of entry being removed
Debugging Details:
------------------
BUGCHECK_STR: 0x4E_2
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 2
LAST_CONTROL_TRANSFER: from fffff800030e567d to fffff800030d4fc0
STACK_TEXT:
fffff880`037d9a08 fffff800`030e567d : 00000000`0000004e 00000000`00000002 00000000`00254ad2 00000000`0025fdff : nt!KeBugCheckEx
fffff880`037d9a10 fffff800`03062946 : fffffa80`0b373b30 fffffa80`04d3fa30 00000000`00000000 fffffa80`0b373b30 : nt!MiUnlinkPageFromLockedList+0x8d
fffff880`037d9a90 fffff800`03062398 : 00000000`00000000 fffffa80`0b6e6000 00000000`00000000 fffffa80`0b373b30 : nt!MiReferencePageForCluster+0x86
fffff880`037d9ac0 fffff800`03062b4b : fffffa80`0003be4e 00000000`00000000 fffffa80`0003be4e 00000000`00000000 : nt!MiGatherPagefilePages+0x398
fffff880`037d9ba0 fffff800`0336be5a : fffffa80`07325040 00000000`00000000 00000000`00000080 00000000`00000001 : nt!MiModifiedPageWriter+0x1bb
fffff880`037d9c00 fffff800`030c5d26 : fffff880`009b3180 fffffa80`07325040 fffff880`009be0c0 00000000`00000000 : nt!PspSystemThreadStartup+0x5a
fffff880`037d9c40 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x16
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!MiUnlinkPageFromLockedList+8d
fffff800`030e567d cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!MiUnlinkPageFromLockedList+8d
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 503f82be
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: X64_0x4E_2_nt!MiUnlinkPageFromLockedList+8d
BUCKET_ID: X64_0x4E_2_nt!MiUnlinkPageFromLockedList+8d
Followup: MachineOwner
---------
4: kd> lmvm nt
start end module name
fffff800`03056000 fffff800`0363e000 nt (pdb symbols) C:\ProgramData\dbg\sym\ntkrnlmp.pdb\B2DA40502FA744C18B9022FD187ADB592\ntkrnlmp.pdb
Loaded symbol image file: ntkrnlmp.exe
Mapped memory image file: C:\ProgramData\dbg\sym\ntoskrnl.exe\503F82BE5e8000\ntoskrnl.exe
Image path: ntkrnlmp.exe
Image name: ntkrnlmp.exe
Timestamp: Thu Aug 30 16:11:58 2012 (503F82BE)
CheckSum: 00554126
ImageSize: 005E8000
File version: 6.1.7601.17944
Product version: 6.1.7601.17944
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 1.0 App
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: ntkrnlmp.exe
OriginalFilename: ntkrnlmp.exe
ProductVersion: 6.1.7601.17944
FileVersion: 6.1.7601.17944 (win7sp1_gdr.120830-0333)
FileDescription: NT Kernel & System
LegalCopyright: © Microsoft Corporation. All rights reserved.