[code]
Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\Owner\AppData\Local\Temp\Temp1_Documents.zip\Windows7_BSOD_jcgriff2\080210-14336-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\symbols*[URL="http://msdl.microsoft.com/download/symbols"]Symbol information[/URL]
Executable search path is:
Windows 7 Kernel Version 7600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16539.amd64fre.win7_gdr.100226-1909
Machine Name:
Kernel base = 0xfffff800`02c52000 PsLoadedModuleList = 0xfffff800`02e8fe50
Debug session time: Mon Aug 2 17:59:12.680 2010 (GMT-4)
System Uptime: 0 days 3:14:15.381
Loading Kernel Symbols
................................................
Loading User Symbols
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 27, {baad0073, fffff8800ad211b8, fffff8800ad20a20, fffff88003f28a83}
Probably caused by : ntkrnlmp.exe ( nt!PoIdle+53a )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
RDR_FILE_SYSTEM (27)
If you see RxExceptionFilter on the stack then the 2nd and 3rd parameters are the
exception record and context record. Do a .cxr on the 3rd parameter and then kb to
obtain a more informative stack trace.
The high 16 bits of the first parameter is the RDBSS bugcheck code, which is defined
as follows:
RDBSS_BUG_CHECK_CACHESUP = 0xca550000,
RDBSS_BUG_CHECK_CLEANUP = 0xc1ee0000,
RDBSS_BUG_CHECK_CLOSE = 0xc10e0000,
RDBSS_BUG_CHECK_NTEXCEPT = 0xbaad0000,
Arguments:
Arg1: 00000000baad0073
Arg2: fffff8800ad211b8
Arg3: fffff8800ad20a20
Arg4: fffff88003f28a83
Debugging Details:
------------------
EXCEPTION_RECORD: fffff8800ad211b8 -- (.exr 0xfffff8800ad211b8)
Cannot read Exception record @ fffff8800ad211b8
CONTEXT: fffff8800ad20a20 -- (.cxr 0xfffff8800ad20a20)
Unable to read context, Win32 error 0n30
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x27
PROCESS_NAME: System
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff80002cd013a to fffff88003e877f2
STACK_TEXT:
fffff800`00b9cc98 fffff800`02cd013a : 00000000`ffffffed fffffa80`04e230a8 fffff800`02e4ac40 00000000`00000001 : 0xfffff880`03e877f2
fffff800`00b9cca0 fffff800`02ccadcc : fffff800`02e3ce80 fffff800`00000000 00000000`00000000 fffff880`00e984c0 : nt!PoIdle+0x53a
fffff800`00b9cd80 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x2c
FOLLOWUP_IP:
nt!PoIdle+53a
fffff800`02cd013a 0fba25061518000f bt dword ptr [nt!PerfGlobalGroupMask+0x8 (fffff800`02e51648)],0Fh
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!PoIdle+53a
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4b88cfeb
STACK_COMMAND: .cxr 0xfffff8800ad20a20 ; kb
FAILURE_BUCKET_ID: X64_0x27_nt!PoIdle+53a
BUCKET_ID: X64_0x27_nt!PoIdle+53a
Followup: MachineOwner
---------
Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\Owner\AppData\Local\Temp\Temp1_Documents.zip\Windows7_BSOD_jcgriff2\080310-16536-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\symbols*[URL="http://msdl.microsoft.com/download/symbols"]Symbol information[/URL]
Executable search path is:
Windows 7 Kernel Version 7600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16539.amd64fre.win7_gdr.100226-1909
Machine Name:
Kernel base = 0xfffff800`02c19000 PsLoadedModuleList = 0xfffff800`02e56e50
Debug session time: Tue Aug 3 03:09:35.611 2010 (GMT-4)
System Uptime: 0 days 0:02:59.922
Loading Kernel Symbols
...............................................................
................................................................
..................................................
Loading User Symbols
Loading unloaded module list
......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 24, {1904fb, fffff88007dbd1e8, fffff88007dbca50, fffff80002c3c90c}
Probably caused by : Ntfs.sys ( Ntfs!NtfsFlushVolume+436 )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
NTFS_FILE_SYSTEM (24)
If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
parameters are the exception record and context record. Do a .cxr
on the 3rd parameter and then kb to obtain a more informative stack
trace.
Arguments:
Arg1: 00000000001904fb
Arg2: fffff88007dbd1e8
Arg3: fffff88007dbca50
Arg4: fffff80002c3c90c
Debugging Details:
------------------
EXCEPTION_RECORD: fffff88007dbd1e8 -- (.exr 0xfffff88007dbd1e8)
ExceptionAddress: fffff80002c3c90c (nt!RealSuccessor+0x0000000000000030)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
CONTEXT: fffff88007dbca50 -- (.cxr 0xfffff88007dbca50)
rax=3bcc886cbbf8f73f rbx=0000000000000000 rcx=3bcc886cbbf8f73f
rdx=fffff88007dbd4f0 rsi=0000000000000001 rdi=fffffa80046129f0
rip=fffff80002c3c90c rsp=fffff88007dbd428 rbp=fffff88007dbd720
r8=0000000000000000 r9=0000000000000000 r10=fffff88007dbd4f0
r11=fffff88007dbd410 r12=fffff8a00403d010 r13=fffff8a00403d1c0
r14=fffffa80046c4180 r15=0000000000000702
iopl=0 nv up ei pl nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010206
nt!RealSuccessor+0x30:
fffff800`02c3c90c 488b4908 mov rcx,qword ptr [rcx+8] ds:002b:3bcc886c`bbf8f747=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: ffffffffffffffff
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002ec10e0
ffffffffffffffff
FOLLOWUP_IP:
Ntfs!NtfsFlushVolume+436
fffff880`012ccb56 483bc3 cmp rax,rbx
FAULTING_IP:
nt!RealSuccessor+30
fffff800`02c3c90c 488b4908 mov rcx,qword ptr [rcx+8]
BUGCHECK_STR: 0x24
LAST_CONTROL_TRANSFER: from fffff80002c5e29c to fffff80002c3c90c
STACK_TEXT:
fffff880`07dbd428 fffff800`02c5e29c : 00000000`00000001 fffffa80`046129f0 fffffa80`046129f0 00000000`00000001 : nt!RealSuccessor+0x30
fffff880`07dbd430 fffff880`012ccb56 : 00000000`00000000 00000000`00000001 00000000`00000000 00000000`00000001 : nt!RtlEnumerateGenericTableWithoutSplayingAvl+0x24
fffff880`07dbd460 fffff880`0131dbbd : fffffa80`046129f0 fffffa80`046c4180 00000000`00100001 00000000`00000000 : Ntfs!NtfsFlushVolume+0x436
fffff880`07dbd590 fffff880`0131e5f0 : fffffa80`046129f0 fffffa80`07b56c10 fffffa80`077f4bb0 00000000`00000000 : Ntfs!NtfsCommonFlushBuffers+0x459
fffff880`07dbd670 fffff880`010aa23f : fffffa80`07b56fb0 fffffa80`07b56c10 fffffa80`046129f0 fffff880`07dbd698 : Ntfs!NtfsFsdFlushBuffers+0x104
fffff880`07dbd6e0 fffff880`010a86df : fffffa80`046378e0 00000000`00000000 fffffa80`04637800 fffffa80`07b56c10 : fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x24f
fffff880`07dbd770 fffff800`02fa0c49 : 00000000`00000002 fffffa80`077f4bb0 00000000`00000000 fffffa80`07b56c10 : fltmgr!FltpDispatch+0xcf
fffff880`07dbd7d0 fffff800`02f2d1c1 : fffffa80`07b56c10 fffffa80`07300060 fffffa80`077f4bb0 00000000`000007ff : nt!IopSynchronousServiceTail+0xf9
fffff880`07dbd840 fffff800`02c88853 : fffffa80`07300060 fffffa80`036d0040 fffffa80`046378e0 fffffa80`077f4bb0 : nt!NtFlushBuffersFile+0x171
fffff880`07dbd8d0 fffff800`02c84df0 : fffff800`02ecf81d 00000000`00000002 fffffa80`045fab90 fffffa80`07575640 : nt!KiSystemServiceCopyEnd+0x13
fffff880`07dbda68 fffff800`02ecf81d : 00000000`00000002 fffffa80`045fab90 fffffa80`07575640 1c09fb59`05010004 : nt!KiServiceLinkage
fffff880`07dbda70 fffff800`02f2ea86 : 00000000`00000000 fffffa80`07300060 00000000`00000080 00000000`00000001 : nt!PopFlushVolumeWorker+0x1bd
fffff880`07dbdd40 fffff800`02c67b06 : fffff800`02e03e80 fffffa80`07300060 fffff800`02e11c40 fffff880`01260534 : nt!PspSystemThreadStartup+0x5a
fffff880`07dbdd80 00000000`00000000 : fffff880`07dbe000 fffff880`07db8000 fffff880`07dbc5b0 00000000`00000000 : nt!KxStartSystemThread+0x16
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: Ntfs!NtfsFlushVolume+436
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Ntfs
IMAGE_NAME: Ntfs.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc14f
STACK_COMMAND: .cxr 0xfffff88007dbca50 ; kb
FAILURE_BUCKET_ID: X64_0x24_Ntfs!NtfsFlushVolume+436
BUCKET_ID: X64_0x24_Ntfs!NtfsFlushVolume+436
Followup: MachineOwner
---------