Loading Dump File [C:\Users\Gkn\Desktop\GOKHANPC-13_04_2014_124610,24\041214-11481-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*
http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.18247.amd64fre.win7sp1_gdr.130828-1532
Machine Name:
Kernel base = 0xfffff800`0305c000 PsLoadedModuleList = 0xfffff800`0329f6d0
Debug session time: Sat Apr 12 23:31:46.573 2014 (UTC + 6:00)
System Uptime: 0 days 1:16:56.806
Loading Kernel Symbols
...............................................................
................................................................
.......................
Loading User Symbols
Loading unloaded module list
...
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {fffff68040000900, 0, fffff800030bb55b, 5}
Could not read faulting driver name
Probably caused by : memory_corruption ( nt!MiAgeWorkingSet+1d1 )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: fffff68040000900, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff800030bb55b, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000005, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80003309100
fffff68040000900
FAULTING_IP:
nt!MiAgeWorkingSet+1d1
fffff800`030bb55b 488b19 mov rbx,qword ptr [rcx]
MM_INTERNAL_CODE: 5
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 0
TRAP_FRAME: fffff8800375c680 -- (.trap 0xfffff8800375c680)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000007ffffffff8 rbx=0000000000000000 rcx=fffff68040000900
rdx=0000000000000001 rsi=0000000000000000 rdi=0000000000000000
rip=fffff800030bb55b rsp=fffff8800375c810 rbp=0000000040000906
r8=0000000000000001 r9=fffffa800a65aec8 r10=0000000000000005
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na po cy
nt!MiAgeWorkingSet+0x1d1:
fffff800`030bb55b 488b19 mov rbx,qword ptr [rcx] ds:fffff680`40000900=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff8000314e5b3 to fffff800030d1bc0
STACK_TEXT:
fffff880`0375c518 fffff800`0314e5b3 : 00000000`00000050 fffff680`40000900 00000000`00000000 fffff880`0375c680 : nt!KeBugCheckEx
fffff880`0375c520 fffff800`030cfcee : 00000000`00000000 fffff680`40000900 00000000`00000000 00000980`00000000 : nt! ?? ::FNODOBFM::`string'+0x43801
fffff880`0375c680 fffff800`030bb55b : 00000000`00000002 00000000`00000001 fffff880`0375ca60 00000000`000004e5 : nt!KiPageFault+0x16e
fffff880`0375c810 fffff800`03152f25 : fffffa80`0a65aec8 fffff880`00000001 00000000`00000001 fffff880`0375ca70 : nt!MiAgeWorkingSet+0x1d1
fffff880`0375c9c0 fffff800`030bbb06 : 00000000`0000120a 00000000`00000000 fffffa80`00000000 00000000`00000001 : nt! ?? ::FNODOBFM::`string'+0x4c7f6
fffff880`0375ca40 fffff800`030bbfb3 : 00000000`00000008 fffff880`0375cad0 00000000`00000001 fffffa80`00000000 : nt!MmWorkingSetManager+0x6e
fffff880`0375ca90 fffff800`0336e2ea : fffffa80`066dbb50 00000000`00000080 fffffa80`066b8040 00000000`00000001 : nt!KeBalanceSetManager+0x1c3
fffff880`0375cc00 fffff800`030c28e6 : fffff880`03365180 fffffa80`066dbb50 fffff880`0336ffc0 00000000`00000000 : nt!PspSystemThreadStartup+0x5a
fffff880`0375cc40 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x16
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!MiAgeWorkingSet+1d1
fffff800`030bb55b 488b19 mov rbx,qword ptr [rcx]
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: nt!MiAgeWorkingSet+1d1
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 521ea035
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: X64_0x50_nt!MiAgeWorkingSet+1d1
BUCKET_ID: X64_0x50_nt!MiAgeWorkingSet+1d1
Followup: MachineOwner
---------
Loading Dump File [C:\Users\Gkn\Desktop\GOKHANPC-13_04_2014_124610,24\041214-14102-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*
http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.18247.amd64fre.win7sp1_gdr.130828-1532
Machine Name:
Kernel base = 0xfffff800`03055000 PsLoadedModuleList = 0xfffff800`032986d0
Debug session time: Sat Apr 12 22:13:55.259 2014 (UTC + 6:00)
System Uptime: 0 days 0:51:41.492
Loading Kernel Symbols
...............................................................
................................................................
.......................
Loading User Symbols
Loading unloaded module list
...
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck D1, {fffff804030c05f2, 2, 8, fffff804030c05f2}
Probably caused by : ntkrnlmp.exe ( nt!KiPageFault+260 )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: fffff804030c05f2, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000008, value 0 = read operation, 1 = write operation
Arg4: fffff804030c05f2, address which referenced memory
Debugging Details:
------------------
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80003302100
fffff804030c05f2
CURRENT_IRQL: 2
FAULTING_IP:
+6630666564323236
fffff804`030c05f2 ?? ???
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xD1
PROCESS_NAME: svchost.exe
TRAP_FRAME: fffff88003c82e70 -- (.trap 0xfffff88003c82e70)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=000007fffff9e000 rbx=0000000000000000 rcx=fffff88003c82fc0
rdx=00000000000007ff rsi=0000000000000000 rdi=0000000000000000
rip=fffff804030c05f2 rsp=fffff88003c83000 rbp=fffffa80067ec640
r8=fffffa8006763bb8 r9=0000000000000000 r10=fffffffffffffffd
r11=fffff880009eb180 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na pe nc
fffff804`030c05f2 ?? ???
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff800030ca169 to fffff800030cabc0
FAILED_INSTRUCTION_ADDRESS:
+6630666564323236
fffff804`030c05f2 ?? ???
STACK_TEXT:
fffff880`03c82d28 fffff800`030ca169 : 00000000`0000000a fffff804`030c05f2 00000000`00000002 00000000`00000008 : nt!KeBugCheckEx
fffff880`03c82d30 fffff800`030c8de0 : fffff880`03c82e80 fffff800`030cde53 fffffa80`00000001 fffffa80`067ec640 : nt!KiBugCheckDispatch+0x69
fffff880`03c82e70 fffff804`030c05f2 : 00000000`00000000 fffffa80`067ec640 00000000`00000000 00000000`00000007 : nt!KiPageFault+0x260
fffff880`03c83000 00000000`00000000 : fffffa80`067ec640 00000000`00000000 00000000`00000007 00000000`00bb9600 : 0xfffff804`030c05f2
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!KiPageFault+260
fffff800`030c8de0 440f20c0 mov rax,cr8
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: nt!KiPageFault+260
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 521ea035
FAILURE_BUCKET_ID: X64_0xD1_CODE_AV_BAD_IP_nt!KiPageFault+260
BUCKET_ID: X64_0xD1_CODE_AV_BAD_IP_nt!KiPageFault+260
Followup: MachineOwner
---------
Loading Dump File [C:\Users\Gkn\Desktop\GOKHANPC-13_04_2014_124610,24\041214-14804-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*
http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.18247.amd64fre.win7sp1_gdr.130828-1532
Machine Name:
Kernel base = 0xfffff800`0300d000 PsLoadedModuleList = 0xfffff800`032506d0
Debug session time: Sat Apr 12 21:21:19.572 2014 (UTC + 6:00)
System Uptime: 0 days 3:16:24.805
Loading Kernel Symbols
...............................................................
................................................................
.......................
Loading User Symbols
Loading unloaded module list
...
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {fffffa81853b9f6b, 0, fffff8000306c7af, 5}
Could not read faulting driver name
Probably caused by : memory_corruption ( nt!MiAgeWorkingSet+425 )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: fffffa81853b9f6b, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff8000306c7af, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000005, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800032ba100
fffffa81853b9f6b
FAULTING_IP:
nt!MiAgeWorkingSet+425
fffff800`0306c7af 410fb65e1b movzx ebx,byte ptr [r14+1Bh]
MM_INTERNAL_CODE: 5
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: LMS.exe
CURRENT_IRQL: 0
TRAP_FRAME: fffff8800375c680 -- (.trap 0xfffff8800375c680)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000058000000000 rbx=0000000000000000 rcx=fffff680003b7fc0
rdx=0000000000000001 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8000306c7af rsp=fffff8800375c810 rbp=00000000003b7fc6
r8=0000000000000001 r9=fffffa800af31918 r10=0000000000000005
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
nt!MiAgeWorkingSet+0x425:
fffff800`0306c7af 410fb65e1b movzx ebx,byte ptr [r14+1Bh] ds:00000000`0000001b=??
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff800030ff5b3 to fffff80003082bc0
STACK_TEXT:
fffff880`0375c518 fffff800`030ff5b3 : 00000000`00000050 fffffa81`853b9f6b 00000000`00000000 fffff880`0375c680 : nt!KeBugCheckEx
fffff880`0375c520 fffff800`03080cee : 00000000`00000000 fffffa81`853b9f6b 00000000`00000000 1fc00081`be8a7005 : nt! ?? ::FNODOBFM::`string'+0x43801
fffff880`0375c680 fffff800`0306c7af : 00000000`00000002 00000000`00000001 fffff880`0375ca60 00000000`000000bd : nt!KiPageFault+0x16e
fffff880`0375c810 fffff800`03103f25 : fffffa80`0af31918 fffff880`00000001 00000000`00000001 fffff880`0375ca70 : nt!MiAgeWorkingSet+0x425
fffff880`0375c9c0 fffff800`0306cb06 : 00000000`00002e0a 00000000`00000000 fffffa80`00000000 00000000`00000001 : nt! ?? ::FNODOBFM::`string'+0x4c7f6
fffff880`0375ca40 fffff800`0306cfb3 : 00000000`00000008 fffff880`0375cad0 00000000`00000001 fffffa80`00000000 : nt!MmWorkingSetManager+0x6e
fffff880`0375ca90 fffff800`0331f2ea : fffffa80`066dbb50 00000000`00000080 fffffa80`066b8040 00000000`00000001 : nt!KeBalanceSetManager+0x1c3
fffff880`0375cc00 fffff800`030738e6 : fffff880`03365180 fffffa80`066dbb50 fffff880`0336ffc0 00000000`00000000 : nt!PspSystemThreadStartup+0x5a
fffff880`0375cc40 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x16
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!MiAgeWorkingSet+425
fffff800`0306c7af 410fb65e1b movzx ebx,byte ptr [r14+1Bh]
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: nt!MiAgeWorkingSet+425
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 521ea035
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: X64_0x50_nt!MiAgeWorkingSet+425
BUCKET_ID: X64_0x50_nt!MiAgeWorkingSet+425
Followup: MachineOwner
---------
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {fffffa8184ff7f2b, 0, fffff800030c38b5, 5}
Could not read faulting driver name
Probably caused by : memory_corruption ( nt!MiAgeWorkingSet+52b )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: fffffa8184ff7f2b, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff800030c38b5, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000005, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80003311100
fffffa8184ff7f2b
FAULTING_IP:
nt!MiAgeWorkingSet+52b
fffff800`030c38b5 410fb6461b movzx eax,byte ptr [r14+1Bh]
MM_INTERNAL_CODE: 5
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: raptr.exe
CURRENT_IRQL: 0
TRAP_FRAME: fffff8800375c680 -- (.trap 0xfffff8800375c680)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=00000000ffffffff rbx=0000000000000000 rcx=fffff6800001df50
rdx=0000000000000001 rsi=0000000000000000 rdi=0000000000000000
rip=fffff800030c38b5 rsp=fffff8800375c810 rbp=0000000000000000
r8=0000000000000001 r9=fffffa8006f8c3f8 r10=0000000000000005
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz ac po cy
nt!MiAgeWorkingSet+0x52b:
fffff800`030c38b5 410fb6461b movzx eax,byte ptr [r14+1Bh] ds:00000000`0000001b=??
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff800031565b3 to fffff800030d9bc0
STACK_TEXT:
fffff880`0375c518 fffff800`031565b3 : 00000000`00000050 fffffa81`84ff7f2b 00000000`00000000 fffff880`0375c680 : nt!KeBugCheckEx
fffff880`0375c520 fffff800`030d7cee : 00000000`00000000 fffffa81`84ff7f2b 00000000`00000000 b0b00081`aa7fb867 : nt! ?? ::FNODOBFM::`string'+0x43801
fffff880`0375c680 fffff800`030c38b5 : 00000003`00000000 30a00001`d9bc5025 00000000`00000000 00000000`0000030a : nt!KiPageFault+0x16e
fffff880`0375c810 fffff800`0315af25 : fffffa80`06f8c3f8 fffff880`00000001 00000000`00000001 fffff880`0375ca70 : nt!MiAgeWorkingSet+0x52b
fffff880`0375c9c0 fffff800`030c3b06 : 00000000`000029a7 00000000`00000000 fffffa80`00000000 00000000`00000004 : nt! ?? ::FNODOBFM::`string'+0x4c7f6
fffff880`0375ca40 fffff800`030c3fb3 : 00000000`00000008 fffff880`0375cad0 00000000`00000001 fffffa80`00000000 : nt!MmWorkingSetManager+0x6e
fffff880`0375ca90 fffff800`033762ea : fffffa80`066e6b50 00000000`00000080 fffffa80`066c3040 00000000`00000001 : nt!KeBalanceSetManager+0x1c3
fffff880`0375cc00 fffff800`030ca8e6 : fffff880`03365180 fffffa80`066e6b50 fffff880`0336ffc0 00000000`00000000 : nt!PspSystemThreadStartup+0x5a
fffff880`0375cc40 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x16
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!MiAgeWorkingSet+52b
fffff800`030c38b5 410fb6461b movzx eax,byte ptr [r14+1Bh]
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: nt!MiAgeWorkingSet+52b
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 521ea035
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: X64_0x50_nt!MiAgeWorkingSet+52b
BUCKET_ID: X64_0x50_nt!MiAgeWorkingSet+52b
Followup: MachineOwner
---------
These are other 4 dmp..