Windows 7 Kernel Version 7600 MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`0285b000 PsLoadedModuleList = 0xfffff800`02a98e50
Debug session time: Wed Nov 3 04:35:27.492 2010 (GMT-4)
System Uptime: 0 days 0:19:03.411
Loading Kernel Symbols
...............................................................
................................................................
......................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 24, {1904fb, fffff88002faf588, fffff88002faedf0, fffff800028aecbf}
Probably caused by : Ntfs.sys ( Ntfs!NtfsDeleteScb+108 )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
NTFS_FILE_SYSTEM (24)
If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
parameters are the exception record and context record. Do a .cxr
on the 3rd parameter and then kb to obtain a more informative stack
trace.
Arguments:
Arg1: 00000000001904fb
Arg2: fffff88002faf588
Arg3: fffff88002faedf0
Arg4: fffff800028aecbf
Debugging Details:
------------------
EXCEPTION_RECORD: fffff88002faf588 -- (.exr 0xfffff88002faf588)
ExceptionAddress: fffff800028aecbf (nt!RtlDeleteNoSplay+0x0000000000000093)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000001
Parameter[1]: 0000002000000000
Attempt to write to address 0000002000000000
CONTEXT: fffff88002faedf0 -- (.cxr 0xfffff88002faedf0)
rax=fffff8a007a3b348 rbx=fffffa8003b7dfc8 rcx=0000002000000000
rdx=fffffa8003b7dfc8 rsi=fffffa8003b7dfc0 rdi=0000000000000000
rip=fffff800028aecbf rsp=fffff88002faf7c0 rbp=fffffa8003b7dfc8
r8=ffffffffffffffff r9=ffffffffffffffff r10=fffffa8003b7df50
r11=fffff8a007a3b348 r12=ffffffffffffffff r13=fffffa8004945668
r14=0000000000008000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010246
nt!RtlDeleteNoSplay+0x93:
fffff800`028aecbf 488909 mov qword ptr [rcx],rcx ds:002b:00000020`00000000=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_PARAMETER1: 0000000000000001
EXCEPTION_PARAMETER2: 0000002000000000
WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff80002b030e0
0000002000000000
FOLLOWUP_IP:
Ntfs!NtfsDeleteScb+108
fffff880`012b0bcc 488b03 mov rax,qword ptr [rbx]
FAULTING_IP:
nt!RtlDeleteNoSplay+93
fffff800`028aecbf 488909 mov qword ptr [rcx],rcx
BUGCHECK_STR: 0x24
LAST_CONTROL_TRANSFER: from fffff880010ef373 to fffff800028aecbf
STACK_TEXT:
fffff880`02faf7c0 fffff880`010ef373 : 00000000`00000000 fffffa80`03b7df58 00000000`00000000 fffff8a0`073e8480 : nt!RtlDeleteNoSplay+0x93
fffff880`02faf7f0 fffff880`010eb238 : fffffa80`043f87a0 fffff880`010ed633 00000000`00000705 fffff880`0113b763 : fltmgr!TreeUnlinkNoBalance+0x13
fffff880`02faf820 fffff880`0110946f : fffff8a0`00000003 fffff8a0`073e8510 fffffa80`043f8760 fffff880`010f466e : fltmgr!TreeUnlinkMulti+0x148
fffff880`02faf870 fffff880`0110bc51 : fffffa80`03b7df50 fffffa80`04945010 00000000`00000130 fffff8a0`07b35640 : fltmgr!DeleteNameCacheNodes+0x9f
fffff880`02faf8b0 fffff880`0110bbe8 : fffffa80`04945010 00000000`00000130 fffff8a0`07b35640 fffff8a0`07b35640 : fltmgr!FltpFreeNameCacheList+0x21
fffff880`02faf8f0 fffff880`0110bb7b : fffffa80`04945010 00000000`00000000 fffffa80`04945010 fffff800`028a1c1a : fltmgr!CleanupStreamListCtrl+0x48
fffff880`02faf920 fffff800`02bba896 : 00000000`00000001 fffff880`012b10b8 fffff8a0`07b35770 fffff880`012246e1 : fltmgr!DeleteStreamListCtrlCallback+0x6b
fffff880`02faf950 fffff880`012b0bcc : fffff8a0`07b35640 fffffa80`039e7680 fffff880`02fafa28 00000000`00000706 : nt!FsRtlTeardownPerStreamContexts+0xe2
fffff880`02faf9a0 fffff880`012b08d5 : 00000000`01010000 00000000`00000000 fffff800`02a70500 00000000`00000001 : Ntfs!NtfsDeleteScb+0x108
fffff880`02faf9e0 fffff880`01223cb4 : fffff8a0`07b35540 fffff8a0`07b35640 fffff800`02a70500 fffff880`02fafb52 : Ntfs!NtfsRemoveScb+0x61
fffff880`02fafa20 fffff880`012ae2dc : fffff8a0`07b35510 fffff800`02a705a0 fffff880`02fafb52 fffffa80`0478b300 : Ntfs!NtfsPrepareFcbForRemoval+0x50
fffff880`02fafa50 fffff880`0122c882 : fffffa80`0478b300 fffffa80`0478b300 fffff8a0`07b35510 00000000`00000000 : Ntfs!NtfsTeardownStructures+0xdc
fffff880`02fafad0 fffff880`012c5813 : fffffa80`0478b300 fffff800`02a705a0 fffff8a0`07b35510 00000000`00000009 : Ntfs!NtfsDecrementCloseCounts+0xa2
fffff880`02fafb10 fffff880`0129f38f : fffffa80`0478b300 fffff8a0`07b35640 fffff8a0`07b35510 fffffa80`04956180 : Ntfs!NtfsCommonClose+0x353
fffff880`02fafbe0 fffff800`028d8961 : 00000000`00000000 fffff880`011b6500 fffffa80`04dde101 00000000`00000002 : Ntfs!NtfsFspClose+0x15f
fffff880`02fafcb0 fffff800`02b6fc06 : ffffff4f`070000df fffffa80`039e7680 00000000`00000080 fffffa80`0396d9e0 : nt!ExpWorkerThread+0x111
fffff880`02fafd40 fffff800`028a9c26 : fffff880`009e8180 fffffa80`039e7680 fffff880`009f2f40 ff0100ef`070000bf : nt!PspSystemThreadStartup+0x5a
fffff880`02fafd80 00000000`00000000 : fffff880`02fb0000 fffff880`02faa000 fffff880`02faf700 00000000`00000000 : nt!KxStartSystemThread+0x16
SYMBOL_STACK_INDEX: 8
SYMBOL_NAME: Ntfs!NtfsDeleteScb+108
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Ntfs
IMAGE_NAME: Ntfs.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc14f
STACK_COMMAND: .cxr 0xfffff88002faedf0 ; kb
FAILURE_BUCKET_ID: X64_0x24_Ntfs!NtfsDeleteScb+108
BUCKET_ID: X64_0x24_Ntfs!NtfsDeleteScb+108
Followup: MachineOwner
---------
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {fffffaa003d42c28, 0, fffff80002b61805, 5}
Unable to load image \SystemRoot\System32\win32k.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for win32k.sys
*** ERROR: Module load completed but symbols could not be loaded for win32k.sys
Could not read faulting driver name
Probably caused by : win32k.sys ( win32k+c541b )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: fffffaa003d42c28, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff80002b61805, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000005, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002af20e0
fffffaa003d42c28
FAULTING_IP:
nt!MiUnsecureVirtualMemory+85
fffff800`02b61805 488b4718 mov rax,qword ptr [rdi+18h]
MM_INTERNAL_CODE: 5
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: LogonUI.exe
CURRENT_IRQL: 0
TRAP_FRAME: fffff88008b16e30 -- (.trap 0xfffff88008b16e30)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000014000000 rbx=0000000000000000 rcx=fffffa8003b92821
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002b61805 rsp=fffff88008b16fc0 rbp=fffffa8003b927e0
r8=0000000000000000 r9=0000000000000000 r10=000000000000063f
r11=fffff88008b16fd0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na pe nc
nt!MiUnsecureVirtualMemory+0x85:
fffff800`02b61805 488b4718 mov rax,qword ptr [rdi+18h] ds:0215:00000000`00000018=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff800029398c1 to fffff800028ba740
STACK_TEXT:
fffff880`08b16cc8 fffff800`029398c1 : 00000000`00000050 fffffaa0`03d42c28 00000000`00000000 fffff880`08b16e30 : nt!KeBugCheckEx
fffff880`08b16cd0 fffff800`028b882e : 00000000`00000000 fffffa80`05c91b60 fffffa80`05c91b00 fffff800`028b9993 : nt! ?? ::FNODOBFM::`string'+0x40e8b
fffff880`08b16e30 fffff800`02b61805 : 00000215`08b17058 fffff900`c1f8ccd0 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x16e
fffff880`08b16fc0 fffff960`000f541b : 00000000`00000001 00000000`00000000 fffff900`c2b2ecd0 00000000`00000000 : nt!MiUnsecureVirtualMemory+0x85
fffff880`08b16ff0 00000000`00000001 : 00000000`00000000 fffff900`c2b2ecd0 00000000`00000000 fffffa80`05c91b05 : win32k+0xc541b
fffff880`08b16ff8 00000000`00000000 : fffff900`c2b2ecd0 00000000`00000000 fffffa80`05c91b05 ffffffff`ffffffff : 0x1
STACK_COMMAND: kb
FOLLOWUP_IP:
win32k+c541b
fffff960`000f541b ?? ???
SYMBOL_STACK_INDEX: 4
SYMBOL_NAME: win32k+c541b
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32k
IMAGE_NAME: win32k.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 0
FAILURE_BUCKET_ID: X64_0x50_win32k+c541b
BUCKET_ID: X64_0x50_win32k+c541b
Followup: MachineOwner
---------
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1A, {41790, fffffa8001146de0, ffff, 0}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+33906 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041790, The subtype of the bugcheck.
Arg2: fffffa8001146de0
Arg3: 000000000000ffff
Arg4: 0000000000000000
Debugging Details:
------------------
BUGCHECK_STR: 0x1a_41790
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: WerFault.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff80002902f9e to fffff8000288f740
STACK_TEXT:
fffff880`06bc6828 fffff800`02902f9e : 00000000`0000001a 00000000`00041790 fffffa80`01146de0 00000000`0000ffff : nt!KeBugCheckEx
fffff880`06bc6830 fffff800`028c2df9 : 00000000`00000000 00000000`03a94fff fffff8a0`00000000 fffff800`0289eb7c : nt! ?? ::FNODOBFM::`string'+0x33906
fffff880`06bc69f0 fffff800`02ba81d0 : fffffa80`04d1c860 0007ffff`00000000 fffffa80`041116d0 fffffa80`041116d0 : nt!MiRemoveMappedView+0xd9
fffff880`06bc6b10 fffff800`02ba85db : 00000000`00000000 00000000`02740000 fffffa80`00000001 00000000`00000101 : nt!MiUnmapViewOfSection+0x1b0
fffff880`06bc6bd0 fffff800`0288e993 : fffffa80`059d7b60 fffff880`06bc6ca0 fffffa80`04c76b30 00000000`7efdb000 : nt!NtUnmapViewOfSection+0x5f
fffff880`06bc6c20 00000000`76e4fffa : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`000ae148 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x76e4fffa
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+33906
fffff800`02902f9e cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+33906
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
FAILURE_BUCKET_ID: X64_0x1a_41790_nt!_??_::FNODOBFM::_string_+33906
BUCKET_ID: X64_0x1a_41790_nt!_??_::FNODOBFM::_string_+33906
Followup: MachineOwner
---------
0: kd> lmtsmn
start end module name
fffff880`03a00000 fffff880`03a3e000 1394ohci 1394ohci.sys Mon Jul 13 20:07:12 2009 (4A5BCC30)
fffff880`00f9a000 fffff880`00ff1000 ACPI ACPI.sys Mon Jul 13 19:19:34 2009 (4A5BC106)
fffff880`02cb3000 fffff880`02d3d000 afd afd.sys Mon Jul 13 19:21:40 2009 (4A5BC184)
fffff880`01881000 fffff880`01897000 AgileVpn AgileVpn.sys Mon Jul 13 20:10:24 2009 (4A5BCCF0)
fffff880`00deb000 fffff880`00df6000 amdxata amdxata.sys Tue May 19 13:56:59 2009 (4A12F2EB)
fffff880`03a3e000 fffff880`03a46000 ASACPI ASACPI.sys Sun Mar 27 22:30:36 2005 (42476C4C)
fffff880`05dad000 fffff880`05db8000 asyncmac asyncmac.sys Mon Jul 13 20:10:13 2009 (4A5BCCE5)
fffff880`00e1e000 fffff880`00e27000 atapi atapi.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`00dc1000 fffff880`00deb000 ataport ataport.SYS Mon Jul 13 19:19:52 2009 (4A5BC118)
fffff880`019b1000 fffff880`019b8000 Beep Beep.SYS Mon Jul 13 20:00:13 2009 (4A5BCA8D)
fffff880`03b05000 fffff880`03b16000 blbdrive blbdrive.sys Mon Jul 13 19:35:59 2009 (4A5BC4DF)
fffff880`05787000 fffff880`057a5000 bowser bowser.sys Mon Jul 13 19:23:50 2009 (4A5BC206)
fffff960`006a0000 fffff960`006c7000 cdd cdd.dll Wed May 19 15:48:26 2010 (4BF4408A)
fffff880`0197e000 fffff880`019a8000 cdrom cdrom.sys Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`00e27000 fffff880`00ee7000 CI CI.dll Mon Jul 13 21:32:13 2009 (4A5BE01D)
fffff880`01918000 fffff880`01948000 CLASSPNP CLASSPNP.SYS Mon Jul 13 19:19:58 2009 (4A5BC11E)
fffff880`00d06000 fffff880`00d64000 CLFS CLFS.SYS Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`01129000 fffff880`0119c000 cng cng.sys Mon Jul 13 19:49:40 2009 (4A5BC814)
fffff880`01871000 fffff880`01881000 CompositeBus CompositeBus.sys Mon Jul 13 20:00:33 2009 (4A5BCAA1)
fffff880`04d49000 fffff880`04d57000 crashdmp crashdmp.sys Mon Jul 13 20:01:01 2009 (4A5BCABD)
fffff880`03a64000 fffff880`03ae7000 csc csc.sys Mon Jul 13 19:24:26 2009 (4A5BC22A)
fffff880`03ae7000 fffff880`03b05000 dfsc dfsc.sys Mon Jul 13 19:23:44 2009 (4A5BC200)
fffff880`01862000 fffff880`01871000 discache discache.sys Mon Jul 13 19:37:18 2009 (4A5BC52E)
fffff880`01902000 fffff880`01918000 disk disk.sys Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`03e00000 fffff880`03e22000 drmk drmk.sys Mon Jul 13 21:01:25 2009 (4A5BD8E5)
fffff880`04d63000 fffff880`04d6c000 dump_atapi dump_atapi.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`04d57000 fffff880`04d63000 dump_dumpata dump_dumpata.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`04d6c000 fffff880`04d7f000 dump_dumpfve dump_dumpfve.sys Mon Jul 13 19:21:51 2009 (4A5BC18F)
fffff880`04d3d000 fffff880`04d49000 Dxapi Dxapi.sys Mon Jul 13 19:38:28 2009 (4A5BC574)
fffff880`0fe00000 fffff880`0fef4000 dxgkrnl dxgkrnl.sys Thu Oct 01 21:00:14 2009 (4AC5509E)
fffff880`10b89000 fffff880`10bcf000 dxgmms1 dxgmms1.sys Mon Jul 13 19:38:32 2009 (4A5BC578)
fffff880`05d06000 fffff880`05d3c000 fastfat fastfat.SYS Mon Jul 13 19:23:28 2009 (4A5BC1F0)
fffff880`10bed000 fffff880`10bfa000 fdc fdc.sys Mon Jul 13 20:00:54 2009 (4A5BCAB6)
fffff880`010b7000 fffff880`010cb000 fileinfo fileinfo.sys Mon Jul 13 19:34:25 2009 (4A5BC481)
fffff880`03f38000 fffff880`03f43000 flpydisk flpydisk.sys Mon Jul 13 20:00:54 2009 (4A5BCAB6)
fffff880`0106b000 fffff880`010b7000 fltmgr fltmgr.sys Mon Jul 13 19:19:59 2009 (4A5BC11F)
fffff880`0122b000 fffff880`01235000 Fs_Rec Fs_Rec.sys Mon Jul 13 19:19:45 2009 (4A5BC111)
fffff880`02c84000 fffff880`02c99380 fsdfw fsdfw.sys Mon Jun 14 07:04:05 2010 (4C160CA5)
fffff880`02c9a000 fffff880`02ca33a0 fses fses.sys Tue Mar 09 06:37:48 2010 (4B96330C)
fffff880`05ca2000 fffff880`05cd5000 fsgk fsgk.sys Sun Jul 18 05:06:56 2010 (4C42C430)
fffff880`02ca4000 fffff880`02cb0f60 fshs fshs.sys Fri Jun 04 04:39:19 2010 (4C08BBB7)
fffff880`02c7c000 fffff880`02c84000 fsvista fsvista.sys Tue Mar 18 02:37:07 2008 (47DF6313)
fffff880`018c8000 fffff880`01902000 fvevol fvevol.sys Fri Sep 25 22:34:26 2009 (4ABD7DB2)
fffff880`0159d000 fffff880`015e7000 fwpkclnt fwpkclnt.sys Mon Jul 13 19:21:08 2009 (4A5BC164)
fffff800`02dfb000 fffff800`02e44000 hal hal.dll Mon Jul 13 21:27:36 2009 (4A5BDF08)
fffff880`03ba8000 fffff880`03bcc000 HDAudBus HDAudBus.sys Mon Jul 13 20:06:13 2009 (4A5BCBF5)
fffff880`03f58000 fffff880`03fb4000 HdAudio HdAudio.sys Mon Jul 13 20:06:59 2009 (4A5BCC23)
fffff880`04daa000 fffff880`04dc3000 HIDCLASS HIDCLASS.SYS Mon Jul 13 20:06:21 2009 (4A5BCBFD)
fffff880`04dc3000 fffff880`04dcb080 HIDPARSE HIDPARSE.SYS Mon Jul 13 20:06:17 2009 (4A5BCBF9)
fffff880`04d9c000 fffff880`04daa000 hidusb hidusb.sys Mon Jul 13 20:06:22 2009 (4A5BCBFE)
fffff880`056bf000 fffff880`05787000 HTTP HTTP.sys Mon Jul 13 19:22:16 2009 (4A5BC1A8)
fffff880`01412000 fffff880`0141b000 hwpolicy hwpolicy.sys Mon Jul 13 19:19:22 2009 (4A5BC0FA)
fffff880`03be0000 fffff880`03bfe000 i8042prt i8042prt.sys Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`03b3c000 fffff880`03b52000 intelppm intelppm.sys Mon Jul 13 19:19:25 2009 (4A5BC0FD)
fffff880`03a52000 fffff880`03a61000 kbdclass kbdclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff800`00bd5000 fffff800`00bdf000 kdcom kdcom.dll Mon Jul 13 21:31:07 2009 (4A5BDFDB)
fffff880`03e89000 fffff880`03ecc000 ks ks.sys Wed Mar 03 23:32:25 2010 (4B8F37D9)
fffff880`01200000 fffff880`0121a000 ksecdd ksecdd.sys Mon Jul 13 19:20:54 2009 (4A5BC156)
fffff880`01572000 fffff880`0159d000 ksecpkg ksecpkg.sys Fri Dec 11 01:03:32 2009 (4B21E0B4)
fffff880`03e22000 fffff880`03e27200 ksthunk ksthunk.sys Mon Jul 13 20:00:19 2009 (4A5BCA93)
fffff880`03bcc000 fffff880`03be0000 l160x64 l160x64.sys Mon Oct 12 22:08:28 2009 (4AD3E11C)
fffff880`04c44000 fffff880`04c59000 lltdio lltdio.sys Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`04c00000 fffff880`04c23000 luafv luafv.sys Mon Jul 13 19:26:13 2009 (4A5BC295)
fffff880`00cae000 fffff880`00cf2000 mcupdate_GenuineIntel mcupdate_GenuineIntel.dll Mon Jul 13 21:29:10 2009 (4A5BDF66)
fffff880`04dd9000 fffff880`04de7000 monitor monitor.sys Mon Jul 13 19:38:52 2009 (4A5BC58C)
fffff880`03e78000 fffff880`03e87000 mouclass mouclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff880`04dcc000 fffff880`04dd9000 mouhid mouhid.sys Mon Jul 13 20:00:20 2009 (4A5BCA94)
fffff880`00c6c000 fffff880`00c86000 mountmgr mountmgr.sys Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`057a5000 fffff880`057bd000 mpsdrv mpsdrv.sys Mon Jul 13 20:08:25 2009 (4A5BCC79)
fffff880`057bd000 fffff880`057ea000 mrxsmb mrxsmb.sys Sat Feb 27 02:52:19 2010 (4B88CF33)
fffff880`05600000 fffff880`0564e000 mrxsmb10 mrxsmb10.sys Sat Feb 27 02:52:28 2010 (4B88CF3C)
fffff880`0564e000 fffff880`05671000 mrxsmb20 mrxsmb20.sys Sat Feb 27 02:52:26 2010 (4B88CF3A)
fffff880`0181b000 fffff880`01826000 Msfs Msfs.SYS Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`00e00000 fffff880`00e0a000 msisadrv msisadrv.sys Mon Jul 13 19:19:26 2009 (4A5BC0FE)
fffff880`010cb000 fffff880`01129000 msrpc msrpc.sys Mon Jul 13 19:21:32 2009 (4A5BC17C)
fffff880`02c71000 fffff880`02c7c000 mssmbios mssmbios.sys Mon Jul 13 19:31:10 2009 (4A5BC3BE)
fffff880`01400000 fffff880`01412000 mup mup.sys Mon Jul 13 19:23:45 2009 (4A5BC201)
fffff880`01420000 fffff880`01512000 ndis ndis.sys Mon Jul 13 19:21:40 2009 (4A5BC184)
fffff880`018bb000 fffff880`018c7000 ndistapi ndistapi.sys Mon Jul 13 20:10:00 2009 (4A5BCCD8)
fffff880`0103a000 fffff880`01069000 ndiswan ndiswan.sys Mon Jul 13 20:10:11 2009 (4A5BCCE3)
fffff880`03f43000 fffff880`03f58000 NDProxy NDProxy.SYS Mon Jul 13 20:10:05 2009 (4A5BCCDD)
fffff880`02db1000 fffff880`02dc0000 netbios netbios.sys Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff880`02d3d000 fffff880`02d82000 netbt netbt.sys Mon Jul 13 19:21:28 2009 (4A5BC178)
fffff880`01512000 fffff880`01572000 NETIO NETIO.SYS Mon Jul 13 19:21:46 2009 (4A5BC18A)
fffff880`01826000 fffff880`01837000 Npfs Npfs.SYS Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`02c65000 fffff880`02c71000 nsiproxy nsiproxy.sys Mon Jul 13 19:21:02 2009 (4A5BC15E)
fffff800`0281f000 fffff800`02dfb000 nt ntkrnlmp.exe Sat Jun 19 00:16:41 2010 (4C1C44A9)
fffff880`01245000 fffff880`013e8000 Ntfs Ntfs.sys Mon Jul 13 19:20:47 2009 (4A5BC14F)
fffff880`019a8000 fffff880`019b1000 Null Null.SYS Mon Jul 13 19:19:37 2009 (4A5BC109)
fffff880`10b87000 fffff880`10b88180 nvBridge nvBridge.kmd Fri Jul 09 17:07:54 2010 (4C378FAA)
fffff880`0fef5000 fffff880`10b86e00 nvlddmkm nvlddmkm.sys Fri Jul 09 17:15:58 2010 (4C37918E)
fffff880`02d8b000 fffff880`02db1000 pacer pacer.sys Mon Jul 13 20:09:41 2009 (4A5BCCC5)
fffff880`00d97000 fffff880`00dac000 partmgr partmgr.sys Mon Jul 13 19:19:58 2009 (4A5BC11E)
fffff880`00d64000 fffff880`00d97000 pci pci.sys Mon Jul 13 19:19:51 2009 (4A5BC117)
fffff880`00e17000 fffff880`00e1e000 pciide pciide.sys Mon Jul 13 19:19:49 2009 (4A5BC115)
fffff880`00c5c000 fffff880`00c6c000 PCIIDEX PCIIDEX.SYS Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`0121a000 fffff880`0122b000 pcw pcw.sys Mon Jul 13 19:19:27 2009 (4A5BC0FF)
fffff880`05acc000 fffff880`05b72000 peauth peauth.sys Mon Jul 13 21:01:19 2009 (4A5BD8DF)
fffff880`03fb4000 fffff880`03ff1000 portcls portcls.sys Mon Jul 13 20:06:27 2009 (4A5BCC03)
fffff880`00cf2000 fffff880`00d06000 PSHED PSHED.dll Mon Jul 13 21:32:23 2009 (4A5BE027)
fffff880`01897000 fffff880`018bb000 rasl2tp rasl2tp.sys Mon Jul 13 20:10:11 2009 (4A5BCCE3)
fffff880`00c86000 fffff880`00ca1000 raspppoe raspppoe.sys Mon Jul 13 20:10:17 2009 (4A5BCCE9)
fffff880`03e32000 fffff880`03e53000 raspptp raspptp.sys Mon Jul 13 20:10:18 2009 (4A5BCCEA)
fffff880`03e53000 fffff880`03e6d000 rassstp rassstp.sys Mon Jul 13 20:10:25 2009 (4A5BCCF1)
fffff880`02c14000 fffff880`02c65000 rdbss rdbss.sys Mon Jul 13 19:24:09 2009 (4A5BC219)
fffff880`03e6d000 fffff880`03e78000 rdpbus rdpbus.sys Mon Jul 13 20:17:46 2009 (4A5BCEAA)
fffff880`01800000 fffff880`01809000 RDPCDD RDPCDD.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`01809000 fffff880`01812000 rdpencdd rdpencdd.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`01812000 fffff880`0181b000 rdprefmp rdprefmp.sys Mon Jul 13 20:16:35 2009 (4A5BCE63)
fffff880`01000000 fffff880`0103a000 rdyboost rdyboost.sys Mon Jul 13 19:34:34 2009 (4A5BC48A)
fffff880`04c59000 fffff880`04c71000 rspndr rspndr.sys Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`05b72000 fffff880`05b7d000 secdrv secdrv.SYS Wed Sep 13 09:18:38 2006 (4508052E)
fffff880`03a46000 fffff880`03a52000 serenum serenum.sys Mon Jul 13 20:00:33 2009 (4A5BCAA1)
fffff880`02dc0000 fffff880`02ddd000 serial serial.sys Mon Jul 13 20:00:40 2009 (4A5BCAA8)
fffff880`015f7000 fffff880`015ff000 spldr spldr.sys Mon May 11 12:56:27 2009 (4A0858BB)
fffff880`05c0c000 fffff880`05ca2000 srv srv.sys Thu Aug 26 23:38:00 2010 (4C773318)
fffff880`05a00000 fffff880`05a67000 srv2 srv2.sys Thu Aug 26 23:37:46 2010 (4C77330A)
fffff880`05b7d000 fffff880`05baa000 srvnet srvnet.sys Thu Aug 26 23:37:24 2010 (4C7732F4)
fffff880`03e87000 fffff880`03e88480 swenum swenum.sys Mon Jul 13 20:00:18 2009 (4A5BCA92)
fffff880`01602000 fffff880`017ff000 tcpip tcpip.sys Sun Jun 13 23:39:04 2010 (4C15A458)
fffff880`05baa000 fffff880`05bbc000 tcpipreg tcpipreg.sys Mon Jul 13 20:09:49 2009 (4A5BCCCD)
fffff880`01855000 fffff880`01862000 TDI TDI.SYS Mon Jul 13 19:21:18 2009 (4A5BC16E)
fffff880`01837000 fffff880`01855000 tdx tdx.sys Mon Jul 13 19:21:15 2009 (4A5BC16B)
fffff880`02c00000 fffff880`02c14000 termdd termdd.sys Mon Jul 13 20:16:36 2009 (4A5BCE64)
fffff960`00450000 fffff960`0045a000 TSDDD TSDDD.dll unavailable (00000000)
fffff880`03b16000 fffff880`03b3c000 tunnel tunnel.sys Mon Jul 13 20:09:37 2009 (4A5BCCC1)
fffff880`04ce9000 fffff880`04d3d000 udfs udfs.sys Mon Jul 13 19:23:37 2009 (4A5BC1F9)
fffff880`03ecc000 fffff880`03ede000 umbus umbus.sys Mon Jul 13 20:06:56 2009 (4A5BCC20)
fffff880`04d9a000 fffff880`04d9bf00 USBD USBD.SYS Mon Jul 13 20:06:23 2009 (4A5BCBFF)
fffff880`10bdc000 fffff880`10bed000 usbehci usbehci.sys Mon Jul 13 20:06:30 2009 (4A5BCC06)
fffff880`03ede000 fffff880`03f38000 usbhub usbhub.sys Mon Jul 13 20:07:09 2009 (4A5BCC2D)
fffff880`03b52000 fffff880`03ba8000 USBPORT USBPORT.SYS Mon Jul 13 20:06:31 2009 (4A5BCC07)
fffff880`04d7f000 fffff880`04d9a000 USBSTOR USBSTOR.SYS Mon Jul 13 20:06:34 2009 (4A5BCC0A)
fffff880`10bcf000 fffff880`10bdc000 usbuhci usbuhci.sys Mon Jul 13 20:06:27 2009 (4A5BCC03)
fffff880`00e0a000 fffff880`00e17000 vdrvroot vdrvroot.sys Mon Jul 13 20:01:31 2009 (4A5BCADB)
fffff880`019b8000 fffff880`019c6000 vga vga.sys Mon Jul 13 19:38:47 2009 (4A5BC587)
fffff880`019c6000 fffff880`019eb000 VIDEOPRT VIDEOPRT.SYS Mon Jul 13 19:38:51 2009 (4A5BC58B)
fffff880`015e7000 fffff880`015f7000 vmstorfl vmstorfl.sys Mon Jul 13 19:42:54 2009 (4A5BC67E)
fffff880`00dac000 fffff880`00dc1000 volmgr volmgr.sys Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`00c00000 fffff880`00c5c000 volmgrx volmgrx.sys Mon Jul 13 19:20:33 2009 (4A5BC141)
fffff880`0119c000 fffff880`011e8000 volsnap volsnap.sys Mon Jul 13 19:20:08 2009 (4A5BC128)
fffff880`02ddd000 fffff880`02df8000 wanarp wanarp.sys Mon Jul 13 20:10:21 2009 (4A5BCCED)
fffff880`019eb000 fffff880`019fb000 watchdog watchdog.sys Mon Jul 13 19:37:35 2009 (4A5BC53F)
fffff880`00ee7000 fffff880`00f8b000 Wdf01000 Wdf01000.sys Mon Jul 13 19:22:07 2009 (4A5BC19F)
fffff880`00f8b000 fffff880`00f9a000 WDFLDR WDFLDR.SYS Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`02d82000 fffff880`02d8b000 wfplwf wfplwf.sys Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff960`000e0000 fffff960`003ef000 win32k win32k.sys Tue Aug 31 22:58:04 2010 (4C7DC13C)
fffff880`00ff1000 fffff880`00ffa000 WMILIB WMILIB.SYS Mon Jul 13 19:19:51 2009 (4A5BC117)
fffff880`04c23000 fffff880`04c44000 WudfPf WudfPf.sys Mon Jul 13 20:05:37 2009 (4A5BCBD1)
Unloaded modules:
fffff880`05cd5000 fffff880`05d06000 WUDFRd.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`05d3c000 fffff880`05dad000 spsys.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`01948000 fffff880`01956000 crashdmp.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`01956000 fffff880`01962000 dump_ataport
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`01962000 fffff880`0196b000 dump_atapi.s
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`0196b000 fffff880`0197e000 dump_dumpfve
Timestamp: unavailable (00000000)
Checksum: 00000000