Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16617.x86fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0x82813000 PsLoadedModuleList = 0x8295b810
Debug session time: Sun Nov 7 22:15:52.279 2010 (GMT-5)
System Uptime: 0 days 6:50:20.678
Loading Kernel Symbols
...............................................................
................................................................
...............................
Loading User Symbols
Loading unloaded module list
........
1: kd> !Analyze
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 24, {1904fb, c403f9d0, c403f5b0, 957270ae}
[B]Probably caused by : SRTSP.SYS[/B] ( SRTSP+160ae )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
NTFS_FILE_SYSTEM (24)
If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
parameters are the exception record and context record. Do a .cxr
on the 3rd parameter and then kb to obtain a more informative stack
trace.
Arguments:
Arg1: 001904fb
Arg2: c403f9d0
Arg3: c403f5b0
Arg4: 957270ae
Debugging Details:
------------------
EXCEPTION_RECORD: c403f9d0 -- (.exr 0xffffffffc403f9d0)
ExceptionAddress: 957270ae (SRTSP+0x000160ae)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 00000000
Parameter[1]: 5aa55b89
Attempt to read from address 5aa55b89
CONTEXT: c403f5b0 -- (.cxr 0xffffffffc403f5b0)
eax=00000001 ebx=00000000 ecx=5aa55aa5 edx=00000003 esi=853fffb0 edi=855650d0
eip=957270ae esp=c403fa98 ebp=c403fa9c iopl=0 nv up ei ng nz ac pe cy
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010297
SRTSP+0x160ae:
957270ae 8b81e4000000 mov eax,dword ptr [ecx+0E4h] ds:0023:5aa55b89=????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_PARAMETER1: 00000000
EXCEPTION_PARAMETER2: 5aa55b89
READ_ADDRESS: GetPointerFromAddress: unable to read from 8297b718
Unable to read MiSystemVaType memory at 8295b160
5aa55b89
FOLLOWUP_IP:
SRTSP+160ae
957270ae 8b81e4000000 mov eax,dword ptr [ecx+0E4h]
FAULTING_IP:
SRTSP+160ae
957270ae 8b81e4000000 mov eax,dword ptr [ecx+0E4h]
BUGCHECK_STR: 0x24
LAST_CONTROL_TRANSFER: from 8357c5f4 to 957270ae
STACK_TEXT:
WARNING: Stack unwind information not available. Following frames may be wrong.
c403fa9c 8357c5f4 853fffb0 00000008 b81445a4 SRTSP+0x160ae
c403fab8 8357c7c0 853fff80 853fff80 c403fadc fltmgr!DoFreeContext+0x66
c403fac8 8358d722 853fff80 853fdb00 853fdad8 fltmgr!DoReleaseContext+0x42
c403fadc 8359a793 853fdb04 853fdb00 ffffffff fltmgr!FltpDeleteContextList+0x15c
c403fafc 8359a9b4 853fdad8 b43283b8 00000000 fltmgr!CleanupStreamListCtrl+0x1b
c403fb10 82a31818 853fdadc d8646ad0 00000000 fltmgr!DeleteStreamListCtrlCallback+0x5a
c403fb50 836bbfb2 b43283b8 b43282c8 b43283b8 nt!FsRtlTeardownPerStreamContexts+0x13a
c403fb6c 836b2b3b 00000705 b43282f0 b43282c8 Ntfs!NtfsDeleteScb+0x214
c403fb84 8362271e 854fcb38 b43283b8 00000000 Ntfs!NtfsRemoveScb+0xc5
c403fba0 836a30d2 854fcb38 b43282c8 00000000 Ntfs!NtfsPrepareFcbForRemoval+0x62
c403fbe4 8361fbec 854fcb38 b43283b8 b4328560 Ntfs!NtfsTeardownStructures+0x68
c403fc0c 8369f55b 854fcb38 b43283b8 b4328560 Ntfs!NtfsDecrementCloseCounts+0xaf
c403fc6c 836be4c3 854fcb38 b43283b8 b43282c8 Ntfs!NtfsCommonClose+0x4f2
c403fd00 82880f3b 00000000 00000000 85fc8690 Ntfs!NtfsFspClose+0x118
c403fd50 82a216d3 80000000 d8646c10 00000000 nt!ExpWorkerThread+0x10d
c403fd90 828d30f9 82880e2e 80000000 00000000 nt!PspSystemThreadStartup+0x9e
00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x19
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: SRTSP+160ae
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: SRTSP
IMAGE_NAME: SRTSP.SYS
DEBUG_FLR_IMAGE_TIMESTAMP: 4a80e37c
STACK_COMMAND: .cxr 0xffffffffc403f5b0 ; kb
FAILURE_BUCKET_ID: 0x24_SRTSP+160ae
BUCKET_ID: 0x24_SRTSP+160ae
Followup: MachineOwner
---------
Debug session time: Tue Nov 9 22:58:05.822 2010 (GMT-5)
System Uptime: 0 days 6:14:32.120
Loading Kernel Symbols
...............................................................
................................................................
...............................
Loading User Symbols
Loading unloaded module list
........
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck A, {5aa55acd, 2, 1, 828440e9}
Probably caused by : memory_corruption ( nt!MiIdentifyPfn+1ed )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 5aa55acd, memory referenced
Arg2: 00000002, IRQL
Arg3: 00000001, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: 828440e9, address which referenced memory
Debugging Details:
------------------
WRITE_ADDRESS: GetPointerFromAddress: unable to read from 82974718
Unable to read MiSystemVaType memory at 82954160
5aa55acd
CURRENT_IRQL: 2
FAULTING_IP:
nt!MiIdentifyPfn+1ed
828440e9 f00fba281f lock bts dword ptr [eax],1Fh
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xA
PROCESS_NAME: svchost.exe
TRAP_FRAME: 92f936ec -- (.trap 0xffffffff92f936ec)
ErrCode = 00000002
eax=5aa55acd ebx=855007d0 ecx=00000000 edx=0801ce16 esi=807c8120 edi=5aa55aa5
eip=828440e9 esp=92f93760 ebp=92f93798 iopl=0 nv up ei pl nz na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010206
nt!MiIdentifyPfn+0x1ed:
828440e9 f00fba281f lock bts dword ptr [eax],1Fh ds:0023:5aa55acd=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from 828440e9 to 8285282b
STACK_TEXT:
92f936ec 828440e9 badb0d00 0801ce16 00000002 nt!KiTrap0E+0x2cf
92f93798 82844562 855007d0 85500000 92f9383c nt!MiIdentifyPfn+0x1ed
92f937c0 82a28462 00500060 8e901dad 92f93850 nt!MmQueryPfnList+0xa6
92f93808 82a48e61 00000001 8e901d2d 00000000 nt!PfpPfnPrioRequest+0xde
92f93888 82a418a5 00000000 00000001 92f93cd0 nt!PfQuerySuperfetchInformation+0xea
92f93d00 82a4250c 0000004f 00000000 00000000 nt!ExpQuerySystemInformation+0x24ce
92f93d1c 8284f44a 0000004f 0140f410 00000014 nt!NtQuerySystemInformation+0x76
92f93d1c 77da64f4 0000004f 0140f410 00000014 nt!KiFastCallEntry+0x12a
WARNING: Frame IP not in any known module. Following frames may be wrong.
0140d2d0 00000000 00000000 00000000 00000000 0x77da64f4
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!MiIdentifyPfn+1ed
828440e9 f00fba281f lock bts dword ptr [eax],1Fh
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!MiIdentifyPfn+1ed
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c3fac
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: 0xA_nt!MiIdentifyPfn+1ed
BUCKET_ID: 0xA_nt!MiIdentifyPfn+1ed
Followup: MachineOwner
---------