Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\a\Minidump\D M P\DMP\011511-22713-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (6 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16385.amd64fre.win7_rtm.090713-1255
Machine Name:
Kernel base = 0xfffff800`03008000 PsLoadedModuleList = 0xfffff800`03245e50
Debug session time: Sat Jan 15 00:51:51.333 2011 (UTC - 5:00)
System Uptime: 0 days 11:06:00.691
Loading Kernel Symbols
...............................................................
................................................................
.............
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 24, {1904fb, fffff88006376638, fffff88006375e90, fffff8000309fe93}
Probably caused by : Ntfs.sys ( Ntfs!NtfsCommonCleanup+580d )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
NTFS_FILE_SYSTEM (24)
If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
parameters are the exception record and context record. Do a .cxr
on the 3rd parameter and then kb to obtain a more informative stack
trace.
Arguments:
Arg1: 00000000001904fb
Arg2: fffff88006376638
Arg3: fffff88006375e90
Arg4: fffff8000309fe93
Debugging Details:
------------------
EXCEPTION_RECORD: fffff88006376638 -- (.exr 0xfffff88006376638)
ExceptionAddress: fffff8000309fe93 (nt!PromoteNode+0x0000000000000003)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
CONTEXT: fffff88006375e90 -- (.cxr 0xfffff88006375e90)
rax=7346744e03040409 rbx=fffff8a002fec620 rcx=fffff8a002fec620
rdx=00000000000000ff rsi=fffff8a001d48570 rdi=00000000ffffffff
rip=fffff8000309fe93 rsp=fffff88006376878 rbp=fffffa8007af6640
r8=0000000000000000 r9=0000ffffffffff01 r10=fffff8a007f08180
r11=fffff8a001d48570 r12=0000000000000001 r13=fffffa8007af6180
r14=fffff8800638b3ff r15=fffff8a000c755a0
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010246
nt!PromoteNode+0x3:
fffff800`0309fe93 488b10 mov rdx,qword ptr [rax] ds:002b:7346744e`03040409=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: ffffffffffffffff
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800032b00e0
ffffffffffffffff
FOLLOWUP_IP:
Ntfs!NtfsCommonCleanup+580d
fffff880`012f1e4e 836304bf and dword ptr [rbx+4],0FFFFFFBFh
FAULTING_IP:
nt!PromoteNode+3
fffff800`0309fe93 488b10 mov rdx,qword ptr [rax]
BUGCHECK_STR: 0x24
LAST_CONTROL_TRANSFER: from fffff8000309fe16 to fffff8000309fe93
STACK_TEXT:
fffff880`06376878 fffff800`0309fe16 : fffffa80`00000001 00000000`00000002 fffff8a0`006c7a90 00000000`00000000 : nt!PromoteNode+0x3
fffff880`06376880 fffff800`0304b1ee : fffff8a0`01835f40 fffff800`0309ecbd fffff880`0638b304 fffff8a0`00c753b0 : nt!RebalanceNode+0x42
fffff880`063768b0 fffff800`0304b269 : fffffa80`07af6640 fffff880`0638b600 fffff8a0`00c753b0 fffff8a0`00c753b0 : nt!DeleteNodeFromTree+0x15e
fffff880`063768f0 fffff880`012f1e4e : fffff8a0`00c75280 fffff8a0`00c75280 fffff8a0`00c659b0 00000000`00000000 : nt!RtlDeleteElementGenericTableAvl+0x39
fffff880`06376920 fffff880`0125baa9 : fffff880`0638abc8 fffffa80`072a4810 fffff880`0638b310 fffffa80`09ce3b60 : Ntfs!NtfsCommonCleanup+0x580d
fffff880`06376d30 fffff800`03071d87 : fffff880`0638b310 00000000`00000000 00000000`00000000 00000000`00000000 : Ntfs!NtfsCommonCleanupCallout+0x19
fffff880`06376d60 fffff800`03071d41 : 00000000`00000000 fffffa80`09ce3b60 fffff880`06377000 fffff800`0308980a : nt!KySwitchKernelStackCallout+0x27
fffff880`0638b1e0 fffff800`0308980a : fffffa80`09809110 fffffa80`09ce3b60 fffffa80`09809100 fffff800`031ad2dd : nt!KiSwitchKernelStackContinue
fffff880`0638b200 fffff880`0125b662 : fffff880`0125ba90 fffff880`0638b310 fffff880`0638b600 00000000`00000000 : nt!KeExpandKernelStackAndCalloutEx+0x29a
fffff880`0638b2e0 fffff880`012fd244 : fffff880`0638b3b0 fffff880`0638b3b0 fffff880`0638b3b0 00000000`00000000 : Ntfs!NtfsCommonCleanupOnNewStack+0x42
fffff880`0638b350 fffff880`0102023f : fffff880`0638b3b0 fffffa80`08b3a170 fffffa80`08b3a510 fffffa80`076d5850 : Ntfs!NtfsFsdCleanup+0x144
fffff880`0638b5c0 fffff880`0101e6df : fffffa80`079508e0 00000000`00000000 fffffa80`07823100 fffffa80`08b3a170 : fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x24f
fffff880`0638b650 fffff800`0338d68f : fffffa80`08b3a170 fffffa80`06a0a040 00000000`00000000 fffffa80`0917edc0 : fltmgr!FltpDispatch+0xcf
fffff880`0638b6b0 fffff800`03373304 : 00000000`00000001 fffffa80`072e9060 00000000`00000348 fffffa80`00000000 : nt!IopCloseFile+0x11f
fffff880`0638b740 fffff800`0338d181 : fffffa80`072e9060 fffffa80`00000001 fffff8a0`00001a20 00000000`00000000 : nt!ObpDecrementHandleCount+0xb4
fffff880`0638b7c0 fffff800`0338d094 : 00000000`0000027c fffffa80`072e9060 fffff8a0`00001a20 00000000`0000027c : nt!ObpCloseHandleTableEntry+0xb1
fffff880`0638b850 fffff800`03079153 : fffffa80`09ce3b60 fffff880`0638b920 fffff8a0`00c71010 00000000`00000001 : nt!ObpCloseHandle+0x94
fffff880`0638b8a0 fffff800`030756f0 : fffff800`034f9092 00000000`00000000 00000000`00000004 fffff8a0`30314d43 : nt!KiSystemServiceCopyEnd+0x13
fffff880`0638ba38 fffff800`034f9092 : 00000000`00000000 00000000`00000004 fffff8a0`30314d43 00000000`00000000 : nt!KiServiceLinkage
fffff880`0638ba40 fffff800`034f9f4b : 00000000`000004dc 00000000`00000000 00000000`00000001 00000000`00000001 : nt!CmpFlushBackupHive+0x2e2
fffff880`0638bb80 fffff800`032da205 : fffffa80`00000001 0000007f`00000000 00000000`00000000 fffff880`0638bca0 : nt!CmpSyncNextBackupHive+0xdb
fffff880`0638bbd0 fffff800`03079153 : fffffa80`09ce3b60 00000000`00000000 fffff880`0638bca0 00000000`001a7e80 : nt!NtInitializeRegistry+0x65
fffff880`0638bc20 00000000`77a60c5a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`00e0fa48 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77a60c5a
SYMBOL_STACK_INDEX: 4
SYMBOL_NAME: Ntfs!NtfsCommonCleanup+580d
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Ntfs
IMAGE_NAME: Ntfs.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc14f
STACK_COMMAND: .cxr 0xfffff88006375e90 ; kb
FAILURE_BUCKET_ID: X64_0x24_Ntfs!NtfsCommonCleanup+580d
BUCKET_ID: X64_0x24_Ntfs!NtfsCommonCleanup+580d
Followup: MachineOwner
---------