Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\a\Minidump\D M P\DMP\030811-35661-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16385.amd64fre.win7_rtm.090713-1255
Machine Name:
Kernel base = 0xfffff800`02800000 PsLoadedModuleList = 0xfffff800`02a3de50
Debug session time: Tue Mar 8 08:43:35.255 2011 (UTC - 5:00)
System Uptime: 0 days 0:05:52.019
Loading Kernel Symbols
...............................................................
................................................................
.......................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 34, {50830, fffff880065034a8, fffff88006502d00, fffff80002976c95}
Probably caused by : memory_corruption ( nt!MiLogPageAccess+e5 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
CACHE_MANAGER (34)
See the comment for FAT_FILE_SYSTEM (0x23)
Arguments:
Arg1: 0000000000050830
Arg2: fffff880065034a8
Arg3: fffff88006502d00
Arg4: fffff80002976c95
Debugging Details:
------------------
EXCEPTION_RECORD: fffff880065034a8 -- (.exr 0xfffff880065034a8)
ExceptionAddress: fffff80002976c95 (nt!MiLogPageAccess+0x00000000000000e5)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
CONTEXT: fffff88006502d00 -- (.cxr 0xfffff88006502d00)
rax=0000000000000001 rbx=fffffa8008733000 rcx=f8a00a36dba80000
rdx=fffff6fcc0086fa8 rsi=fffffa8003853520 rdi=fffff6fcc0086fa8
rip=fffff80002976c95 rsp=fffff880065036e0 rbp=0000000000000000
r8=fffff98010df5001 r9=0000000000002eb2 r10=fffff780c0000488
r11=fffff780c0000000 r12=fa80072cc3a004c0 r13=0000000000000035
r14=fffffa8008733ff8 r15=fffff8a00a36dba8
iopl=0 nv up ei pl nz na pe nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010202
nt!MiLogPageAccess+0xe5:
fffff800`02976c95 410fba64243814 bt dword ptr [r12+38h],14h ds:002b:fa80072c`c3a004f8=????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: ffffffffffffffff
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002aa80e0
ffffffffffffffff
FOLLOWUP_IP:
nt!MiLogPageAccess+e5
fffff800`02976c95 410fba64243814 bt dword ptr [r12+38h],14h
FAULTING_IP:
nt!MiLogPageAccess+e5
fffff800`02976c95 410fba64243814 bt dword ptr [r12+38h],14h
BUGCHECK_STR: 0x34
LAST_CONTROL_TRANSFER: from fffff8000281418b to fffff80002976c95
STACK_TEXT:
fffff880`065036e0 fffff800`0281418b : 00000003`00000000 00000000`00002eb2 fffffa80`03171a80 fffff880`06503968 : nt!MiLogPageAccess+0xe5
fffff880`06503730 fffff800`02b85e35 : fffff980`10df5000 fffff8a0`0a87e8b0 00000000`00000001 00000000`00000001 : nt! ?? ::FNODOBFM::`string'+0x2bf68
fffff880`06503a10 fffff800`0288ad47 : 00000000`00140000 fffffa80`066f9990 00000000`00000000 00000000`00200000 : nt!CcUnmapVacb+0x5d
fffff880`06503a50 fffff800`02861ad4 : 00000000`00000001 fffffa80`081d21f0 fffffa80`06d0de00 00000000`00000000 : nt!CcUnmapVacbArray+0x1b7
fffff880`06503ae0 fffff800`0286555c : fffffa80`06d0de10 00000000`00000011 fffffa80`06d0de10 fffffa80`00000000 : nt!CcDeleteSharedCacheMap+0x140
fffff880`06503b50 fffff800`02865d60 : fffff800`02a77100 fffff880`06503c58 00000000`00000000 fffffa80`00000000 : nt!CcWriteBehind+0x5bc
fffff880`06503c00 fffff800`0287f161 : fffffa80`06747190 fffff800`02b6b504 fffff800`02a77140 fffff880`00000000 : nt!CcWorkerThread+0x1c8
fffff880`06503cb0 fffff800`02b15166 : fffff880`00000103 fffffa80`06c0d760 00000000`00000080 fffffa80`066a8890 : nt!ExpWorkerThread+0x111
fffff880`06503d40 fffff800`02850486 : fffff800`029eae80 fffffa80`06c0d760 fffff800`029f8c40 fffff880`0123dbf0 : nt!PspSystemThreadStartup+0x5a
fffff880`06503d80 00000000`00000000 : fffff880`06504000 fffff880`064fe000 fffff880`06502f30 00000000`00000000 : nt!KxStartSystemThread+0x16
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!MiLogPageAccess+e5
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc600
STACK_COMMAND: .cxr 0xfffff88006502d00 ; kb
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: X64_0x34_nt!MiLogPageAccess+e5
BUCKET_ID: X64_0x34_nt!MiLogPageAccess+e5
Followup: MachineOwner
---------
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\a\Minidump\D M P\DMP\030811-30654-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16385.amd64fre.win7_rtm.090713-1255
Machine Name:
Kernel base = 0xfffff800`02802000 PsLoadedModuleList = 0xfffff800`02a3fe50
Debug session time: Tue Mar 8 08:48:45.818 2011 (UTC - 5:00)
System Uptime: 0 days 0:04:03.582
Loading Kernel Symbols
...............................................................
................................................................
.......................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 109, {a3a039d89844769f, b3b7465eeac148cd, fffff8000286dba0, 1}
*** WARNING: Unable to verify timestamp for win32k.sys
*** ERROR: Module load completed but symbols could not be loaded for win32k.sys
Probably caused by : memory_corruption
Followup: memory_corruption
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
CRITICAL_STRUCTURE_CORRUPTION (109)
This bugcheck is generated when the kernel detects that critical kernel code or
data have been corrupted. There are generally three causes for a corruption:
1) A driver has inadvertently or deliberately modified critical kernel code
or data. See http://www.microsoft.com/whdc/driver/kernel/64bitPatching.mspx
2) A developer attempted to set a normal kernel breakpoint using a kernel
debugger that was not attached when the system was booted. Normal breakpoints,
"bp", can only be set if the debugger is attached at boot time. Hardware
breakpoints, "ba", can be set at any time.
3) A hardware corruption occurred, e.g. failing RAM holding kernel code or data.
Arguments:
Arg1: a3a039d89844769f, Reserved
Arg2: b3b7465eeac148cd, Reserved
Arg3: fffff8000286dba0, Failure type dependent information
Arg4: 0000000000000001, Type of corrupted region, can be
0 : A generic data region
1 : Modification of a function or .pdata
2 : A processor IDT
3 : A processor GDT
4 : Type 1 process list corruption
5 : Type 2 process list corruption
6 : Debug routine modification
7 : Critical MSR modification
Debugging Details:
------------------
BUGCHECK_STR: 0x109
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: CODE_CORRUPTION
PROCESS_NAME: System
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff80002873f00
STACK_TEXT:
fffff880`02fef5d8 00000000`00000000 : 00000000`00000109 a3a039d8`9844769f b3b7465e`eac148cd fffff800`0286dba0 : nt!KeBugCheckEx
STACK_COMMAND: kb
CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
fffff8000286dbad - nt!ZwDisableLastKnownGood+d
[ 8d:89 ]
1 error : !nt (fffff8000286dbad)
MODULE_NAME: memory_corruption
IMAGE_NAME: memory_corruption
FOLLOWUP_NAME: memory_corruption
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MEMORY_CORRUPTOR: ONE_BIT
FAILURE_BUCKET_ID: X64_MEMORY_CORRUPTION_ONE_BIT
BUCKET_ID: X64_MEMORY_CORRUPTION_ONE_BIT
Followup: memory_corruption
---------
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\a\Minidump\D M P\DMP\030811-45973-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16695.amd64fre.win7_gdr.101026-1503
Machine Name:
Kernel base = 0xfffff800`02a1a000 PsLoadedModuleList = 0xfffff800`02c57e50
Debug session time: Tue Mar 8 09:42:54.102 2011 (UTC - 5:00)
System Uptime: 0 days 0:06:21.757
Loading Kernel Symbols
...............................................................
................................................................
...........................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1A, {41284, 7fef6492001, 1cec, fffff70001080000}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+4a83 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041284, A PTE or the working set list is corrupt.
Arg2: 000007fef6492001
Arg3: 0000000000001cec
Arg4: fffff70001080000
Debugging Details:
------------------
BUGCHECK_STR: 0x1a_41284
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: mscorsvw.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff80002adf3b3 to fffff80002a8a740
STACK_TEXT:
fffff880`0bf317e8 fffff800`02adf3b3 : 00000000`0000001a 00000000`00041284 000007fe`f6492001 00000000`00001cec : nt!KeBugCheckEx
fffff880`0bf317f0 fffff800`02afdcc3 : fffffa80`03bfacc0 4ec00001`3fe44025 000007fe`f648c000 5f400001`4e231025 : nt! ?? ::FNODOBFM::`string'+0x4a83
fffff880`0bf31830 fffff800`02abddf9 : 00000000`00000000 000007fe`f6496fff fffffa80`00000000 fffff800`02c04e80 : nt! ?? ::FNODOBFM::`string'+0x3360b
fffff880`0bf319f0 fffff800`02da1010 : fffffa80`096887f0 0007ffff`00000000 00000000`00000000 00000000`00000000 : nt!MiRemoveMappedView+0xd9
fffff880`0bf31b10 fffff800`02da141b : 00000000`00000000 000007fe`f6480000 fffffa80`00000001 fffffa80`06807df0 : nt!MiUnmapViewOfSection+0x1b0
fffff880`0bf31bd0 fffff800`02a89993 : fffffa80`06aa9060 fffff880`0bf31ca0 fffffa80`06a38b30 fffffa80`00008000 : nt!NtUnmapViewOfSection+0x5f
fffff880`0bf31c20 00000000`77a7f95a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0017de28 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77a7f95a
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+4a83
fffff800`02adf3b3 cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+4a83
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4cc791bd
FAILURE_BUCKET_ID: X64_0x1a_41284_nt!_??_::FNODOBFM::_string_+4a83
BUCKET_ID: X64_0x1a_41284_nt!_??_::FNODOBFM::_string_+4a83
Followup: MachineOwner
---------