Microsoft (R) Windows Debugger Version 6.2.9200.16384 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [J:\tools\SystemTools\FileViewers\bsod\112612-12308-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17944.amd64fre.win7sp1_gdr.120830-0333
Machine Name:
Kernel base = 0xfffff800`02e0e000 PsLoadedModuleList = 0xfffff800`03052670
Debug session time: Mon Nov 26 14:40:37.494 2012 (UTC - 5:00)
System Uptime: 0 days 1:42:57.754
Loading Kernel Symbols
...............................................................
................................................................
....................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1000007E, {ffffffffc0000005, fffff8000310cb13, fffff88003376ca8, fffff88003376500}
Probably caused by : discache.sys ( discache!DisCreateObjectAttributeStore+ec )
Followup: MachineOwner
---------
4: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff8000310cb13, The address that the exception occurred at
Arg3: fffff88003376ca8, Exception Record Address
Arg4: fffff88003376500, Context Record Address
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!HvFreeHive+af
fffff800`0310cb13 448b5304 mov r10d,dword ptr [rbx+4]
EXCEPTION_RECORD: fffff88003376ca8 -- (.exr 0xfffff88003376ca8)
ExceptionAddress: fffff8000310cb13 (nt!HvFreeHive+0x00000000000000af)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
CONTEXT: fffff88003376500 -- (.cxr 0xfffff88003376500)
rax=fffff8a005c79640 rbx=ffff00a00ae27000 rcx=fffff8a005d23010
rdx=0000000000000001 rsi=fffff8a005d230c0 rdi=fffff8a005d23010
rip=fffff8000310cb13 rsp=fffff88003376ee0 rbp=0000000000232000
r8=fffff8a005d23010 r9=000000000000ae00 r10=0000000000000000
r11=0000000001ffffff r12=fffff8a005c78d20 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010286
nt!HvFreeHive+0xaf:
fffff800`0310cb13 448b5304 mov r10d,dword ptr [rbx+4] ds:002b:ffff00a0`0ae27004=????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: ffffffffffffffff
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800030bc100
GetUlongFromAddress: unable to read from fffff800030bc1c0
ffffffffffffffff
FOLLOWUP_IP:
discache!DisCreateObjectAttributeStore+ec
fffff880`03d67e98 3bc6 cmp eax,esi
BUGCHECK_STR: 0x7E
LAST_CONTROL_TRANSFER: from fffff800031ee833 to fffff8000310cb13
STACK_TEXT:
fffff880`03376ee0 fffff800`031ee833 : 00000000`00000000 00000000`00000001 fffff8a0`00000001 00000000`003bd000 : nt!HvFreeHive+0xaf
fffff880`03376f60 fffff800`030ffeca : fffff880`033770f0 fffff880`03377200 ffffffff`80000bc8 fffff880`03377638 : nt! ?? ::NNGAKEGL::`string'+0x5be5b
fffff880`03377050 fffff800`030ff7c6 : 00000000`00000010 20204d43`00000000 fffff880`033773e8 fffff880`033773e1 : nt!CmpInitHiveFromFile+0x246
fffff880`033771a0 fffff800`0310498f : 00000000`00000010 00000000`00000000 00000000`00000000 fffff800`03184fd7 : nt!CmpCmdHiveOpen+0x8a
fffff880`03377390 fffff800`031046c7 : fffff880`03370064 00000000`00000000 00000000`00000000 fffff880`03377a00 : nt!CmLoadKey+0x1a7
fffff880`03377580 fffff800`02e8c253 : 00000000`00000001 fffff880`03377a70 fffff880`00000010 00000000`00000000 : nt!NtLoadKeyEx+0x4c5
fffff880`033777e0 fffff800`02e88810 : fffff880`03d67e98 fffff880`03d6f3d0 00000000`00000000 00000000`00000001 : nt!KiSystemServiceCopyEnd+0x13
fffff880`033779e8 fffff880`03d67e98 : fffff880`03d6f3d0 00000000`00000000 00000000`00000001 00000000`00000001 : nt!KiServiceLinkage
fffff880`033779f0 fffff880`03d662b2 : 00000000`00000000 00000000`00000000 00000000`00000001 fffff8a0`04ee09c0 : discache!DisCreateObjectAttributeStore+0xec
fffff880`03377ab0 fffff880`03d6644b : fffff800`00000043 00000000`00000000 fffff800`0302a2d8 00000000`00000000 : discache!ScpInitializeCache+0x19a
fffff880`03377af0 fffff800`02e96641 : fffff880`03d66370 ffffffff`80000aa0 fffffa80`0cd72710 fffffa80`0ce50b50 : discache!ScpInitializationWorker+0xdb
fffff880`03377b70 fffff800`03123e5a : 010d0101`0d01010d fffffa80`0ce50b50 00000000`00000080 fffffa80`0ccee990 : nt!ExpWorkerThread+0x111
fffff880`03377c00 fffff800`02e7dd26 : fffff880`03189180 fffffa80`0ce50b50 fffff880`031940c0 01000201`00020100 : nt!PspSystemThreadStartup+0x5a
fffff880`03377c40 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x16
SYMBOL_STACK_INDEX: 8
SYMBOL_NAME: discache!DisCreateObjectAttributeStore+ec
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: discache
IMAGE_NAME: discache.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc52e
STACK_COMMAND: .cxr 0xfffff88003376500 ; kb
FAILURE_BUCKET_ID: X64_0x7E_discache!DisCreateObjectAttributeStore+ec
BUCKET_ID: X64_0x7E_discache!DisCreateObjectAttributeStore+ec
Followup: MachineOwner
---------
4: kd> lmvm discache
start end module name
fffff880`03d65000 fffff880`03d74000 discache (pdb symbols) c:\symcache\discache.pdb\D25ADE8D75E74290B3E5B421A4268DC31\discache.pdb
Loaded symbol image file: discache.sys
Mapped memory image file: c:\symcache\discache.sys\4A5BC52Ef000\discache.sys
Image path: \SystemRoot\System32\drivers\discache.sys
Image name: discache.sys
Timestamp: Mon Jul 13 19:37:18 2009 (4A5BC52E)
CheckSum: 00015F3F
ImageSize: 0000F000
File version: 6.1.7600.16385
Product version: 6.1.7600.16385
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 2.0 Dll
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: syscache.sys
OriginalFilename: syscache.sys
ProductVersion: 6.1.7600.16385
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
FileDescription: System Indexer/Cache Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.