Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\a\Minidump\D M P\DMP\030711-21013-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16695.amd64fre.win7_gdr.101026-1503
Machine Name:
Kernel base = 0xfffff800`02c16000 PsLoadedModuleList = 0xfffff800`02e53e50
Debug session time: Mon Mar 7 17:33:24.862 2011 (UTC - 5:00)
System Uptime: 0 days 3:33:34.954
Loading Kernel Symbols
...............................................................
................................................................
..............................
Loading User Symbols
Loading unloaded module list
........
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 9B, {14031c, fffff880088deb88, fffff880088de3f0, fffff80002e8b1ab}
Probably caused by : hardware ( udfs!UdfDetermineMediaType+46 )
Followup: MachineOwner
---------
3: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
UDFS_FILE_SYSTEM (9b)
If you see UdfExceptionFilter on the stack then the 2nd and 3rd
parameters are the exception record and context record. Do a .cxr
on the 3rd parameter and then kb to obtain a more helpful stack
trace.
Arguments:
Arg1: 000000000014031c
Arg2: fffff880088deb88
Arg3: fffff880088de3f0
Arg4: fffff80002e8b1ab
Debugging Details:
------------------
EXCEPTION_RECORD: fffff880088deb88 -- (.exr 0xfffff880088deb88)
ExceptionAddress: fffff80002e8b1ab (nt!IopNotifyLastChanceShutdownQueueHead+0x000000000000000b)
ExceptionCode: c000001d (Illegal instruction)
ExceptionFlags: 00000000
NumberParameters: 0
CONTEXT: fffff880088de3f0 -- (.cxr 0xfffff880088de3f0)
rax=0000000000000000 rbx=fffffa8008871514 rcx=fffffa8006b3910f
rdx=00000000ffffffff rsi=fffff80002e8b200 rdi=0000000000000000
rip=fffff80002e8b1ab rsp=fffff880088dedc0 rbp=0000000000000000
r8=fffffa800554c0b8 r9=00000000ffffffff r10=fffffa8009109000
r11=fffff880088dedb0 r12=fffffa8007c09820 r13=0000000000000000
r14=fffff8800441cc98 r15=fffffa8007352bd0
iopl=0 nv up ei ng nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010286
nt!IopNotifyLastChanceShutdownQueueHead+0xb:
fffff800`02e8b1ab 06 ???
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x9B
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc000001d - {EXCEPTION} Illegal Instruction An attempt was made to execute an illegal instruction.
EXCEPTION_CODE: (NTSTATUS) 0xc000001d - {EXCEPTION} Illegal Instruction An attempt was made to execute an illegal instruction.
LAST_CONTROL_TRANSFER: from fffffa8008871514 to fffff80002e8b1ab
MISALIGNED_IP:
nt!IopNotifyLastChanceShutdownQueueHead+b
fffff800`02e8b1ab 06 ???
STACK_TEXT:
fffff880`088dedc0 fffffa80`08871514 : fffff880`0442d17a fffffa80`08871514 fffff800`02e8b200 fffffa80`00000040 : nt!IopNotifyLastChanceShutdownQueueHead+0xb
fffff880`088dedc8 fffff880`0442d17a : fffffa80`08871514 fffff800`02e8b200 fffffa80`00000040 fffffa80`06aaed30 : 0xfffffa80`08871514
fffff880`088dedd0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : udfs!UdfDetermineMediaType+0x46
FOLLOWUP_IP:
udfs!UdfDetermineMediaType+46
fffff880`0442d17a 85c0 test eax,eax
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: udfs!UdfDetermineMediaType+46
FOLLOWUP_NAME: MachineOwner
IMAGE_NAME: hardware
DEBUG_FLR_IMAGE_TIMESTAMP: 0
STACK_COMMAND: .cxr 0xfffff880088de3f0 ; kb
MODULE_NAME: hardware
FAILURE_BUCKET_ID: X64_IP_MISALIGNED
BUCKET_ID: X64_IP_MISALIGNED
Followup: MachineOwner
---------
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\a\Minidump\D M P\DMP\030711-22854-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16695.amd64fre.win7_gdr.101026-1503
Machine Name:
Kernel base = 0xfffff800`02c4b000 PsLoadedModuleList = 0xfffff800`02e88e50
Debug session time: Mon Mar 7 17:58:02.907 2011 (UTC - 5:00)
System Uptime: 0 days 0:23:32.000
Loading Kernel Symbols
...............................................................
................................................................
.............................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1000007E, {ffffffffc0000005, fffff80002fad61c, fffff88003b85988, fffff88003b851f0}
Probably caused by : ntkrnlmp.exe ( nt!CmpRemoveKeyHash+4c )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff80002fad61c, The address that the exception occurred at
Arg3: fffff88003b85988, Exception Record Address
Arg4: fffff88003b851f0, Context Record Address
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!CmpRemoveKeyHash+4c
fffff800`02fad61c 488b01 mov rax,qword ptr [rcx]
EXCEPTION_RECORD: fffff88003b85988 -- (.exr 0xfffff88003b85988)
ExceptionAddress: fffff80002fad61c (nt!CmpRemoveKeyHash+0x000000000000004c)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
CONTEXT: fffff88003b851f0 -- (.cxr 0xfffff88003b851f0)
rax=f0fffff8a008a1c5 rbx=fffff8a008b9a380 rcx=f0fffff8a008a1cd
rdx=0000000000000ba0 rsi=0000000000000004 rdi=fffff88003b85c00
rip=fffff80002fad61c rsp=fffff88003b85bc8 rbp=fffff88003b85c8c
r8=0000000000000000 r9=00000000192e9be0 r10=fffff8a008b9a258
r11=fffff8a008b9a390 r12=0000000000000003 r13=0000000000000003
r14=0000000000000000 r15=0000000000000001
iopl=0 nv up ei ng nz na pe nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010282
nt!CmpRemoveKeyHash+0x4c:
fffff800`02fad61c 488b01 mov rax,qword ptr [rcx] ds:002b:f0fffff8`a008a1cd=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: ffffffffffffffff
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002ef30e0
ffffffffffffffff
FOLLOWUP_IP:
nt!CmpRemoveKeyHash+4c
fffff800`02fad61c 488b01 mov rax,qword ptr [rcx]
BUGCHECK_STR: 0x7E
LAST_CONTROL_TRANSFER: from fffff80002fad7e6 to fffff80002fad61c
STACK_TEXT:
fffff880`03b85bc8 fffff800`02fad7e6 : fffff8a0`08b9a380 fffff880`03b85c8c 00000000`00000004 00000000`00000000 : nt!CmpRemoveKeyHash+0x4c
fffff880`03b85bd0 fffff800`02f12fde : fffff8a0`08b9a380 fffff880`03b85c74 00000000`00000004 fffffa80`057a4400 : nt!CmpCleanUpKcbCacheWithLock+0x52
fffff880`03b85c00 fffff800`02cc8961 : fffff800`02f12ca4 fffff800`02e605f8 fffffa80`0552cb60 00000000`00000000 : nt!CmpDelayCloseWorker+0x33a
fffff880`03b85cb0 fffff800`02f5e7c6 : e7fde7fd`2c132c13 fffffa80`0552cb60 00000000`00000080 fffffa80`05491890 : nt!ExpWorkerThread+0x111
fffff880`03b85d40 fffff800`02c99c26 : fffff880`0396a180 fffffa80`0552cb60 fffff880`039750c0 04740474`48e748e7 : nt!PspSystemThreadStartup+0x5a
fffff880`03b85d80 00000000`00000000 : fffff880`03b86000 fffff880`03b80000 fffff880`03b859f0 00000000`00000000 : nt!KxStartSystemThread+0x16
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!CmpRemoveKeyHash+4c
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4cc791bd
STACK_COMMAND: .cxr 0xfffff88003b851f0 ; kb
FAILURE_BUCKET_ID: X64_0x7E_nt!CmpRemoveKeyHash+4c
BUCKET_ID: X64_0x7E_nt!CmpRemoveKeyHash+4c
Followup: MachineOwner
---------
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\a\Minidump\D M P\DMP\030811-20217-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16695.amd64fre.win7_gdr.101026-1503
Machine Name:
Kernel base = 0xfffff800`02c1e000 PsLoadedModuleList = 0xfffff800`02e5be50
Debug session time: Tue Mar 8 04:29:27.498 2011 (UTC - 5:00)
System Uptime: 0 days 10:27:44.591
Loading Kernel Symbols
...............................................................
................................................................
.................................
Loading User Symbols
Loading unloaded module list
........
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1, {7768f72a, 0, ffff, fffff880088b7ca0}
Probably caused by : ntkrnlmp.exe ( nt!KiSystemServiceExit+245 )
Followup: MachineOwner
---------
6: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
APC_INDEX_MISMATCH (1)
This is a kernel internal error. The most common reason to see this
bugcheck is when a filesystem or a driver has a mismatched number of
calls to disable and re-enable APCs. The key data item is the
Thread->KernelApcDisable field. A negative value indicates that a driver
has disabled APC calls without re-enabling them. A positive value indicates
that the reverse is true. This check is made on exit from a system call.
Arguments:
Arg1: 000000007768f72a, address of system function (system call)
Arg2: 0000000000000000, Thread->ApcStateIndex << 8 | Previous ApcStateIndex
Arg3: 000000000000ffff, Thread->KernelApcDisable
Arg4: fffff880088b7ca0, Previous KernelApcDisable
Debugging Details:
------------------
FAULTING_IP:
+3462396236393733
00000000`7768f72a ?? ???
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x1
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff80002c8dca9 to fffff80002c8e740
STACK_TEXT:
fffff880`088b7a68 fffff800`02c8dca9 : 00000000`00000001 00000000`7768f72a 00000000`00000000 00000000`0000ffff : nt!KeBugCheckEx
fffff880`088b7a70 fffff800`02c8dbe0 : 00000000`00003e62 00000000`01418ee8 00000000`01e4eea0 0000007f`ffffffff : nt!KiBugCheckDispatch+0x69
fffff880`088b7bb0 00000000`7768f72a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExit+0x245
00000000`01e4e608 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7768f72a
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!KiSystemServiceExit+245
fffff800`02c8dbe0 4883ec50 sub rsp,50h
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: nt!KiSystemServiceExit+245
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4cc791bd
FAILURE_BUCKET_ID: X64_0x1_SysCallNum_4_nt!KiSystemServiceExit+245
BUCKET_ID: X64_0x1_SysCallNum_4_nt!KiSystemServiceExit+245
Followup: MachineOwner
---------