Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\a\Minidump\D M P\122310-25802-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16617.x86fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0x82a39000 PsLoadedModuleList = 0x82b81810
Debug session time: Thu Dec 23 00:49:26.915 2010 (UTC - 5:00)
System Uptime: 0 days 0:01:13.881
Loading Kernel Symbols
...............................................................
................................................................
.................................
Loading User Symbols
Loading unloaded module list
.....
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
NTFS_FILE_SYSTEM (24)
If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
parameters are the exception record and context record. Do a .cxr
on the 3rd parameter and then kb to obtain a more informative stack
trace.
Arguments:
Arg1: 001904fb
Arg2: 9d992af8
Arg3: 9d9926d0
Arg4: 8c228773
Debugging Details:
------------------
EXCEPTION_RECORD: 9d992af8 -- (.exr 0xffffffff9d992af8)
ExceptionAddress: 8c228773 (Ntfs!NtfsFindRollbackStructByType+0x00000023)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 00000000
Parameter[1]: 0003fff8
Attempt to read from address 0003fff8
CONTEXT: 9d9926d0 -- (.cxr 0xffffffff9d9926d0)
eax=00000000 ebx=8873bd5c ecx=00040000 edx=0003fff8 esi=8873bd5c edi=00000000
eip=8c228773 esp=9d992bc0 ebp=9d992bc8 iopl=0 nv up ei pl nz ac po cy
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010213
Ntfs!NtfsFindRollbackStructByType+0x23:
8c228773 0fb73a movzx edi,word ptr [edx] ds:0023:0003fff8=????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text>
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text>
EXCEPTION_PARAMETER1: 00000000
EXCEPTION_PARAMETER2: 0003fff8
READ_ADDRESS: GetPointerFromAddress: unable to read from 82ba1718
Unable to read MiSystemVaType memory at 82b81160
0003fff8
FOLLOWUP_IP:
Ntfs!NtfsFindRollbackStructByType+23
8c228773 0fb73a movzx edi,word ptr [edx]
FAULTING_IP:
Ntfs!NtfsFindRollbackStructByType+23
8c228773 0fb73a movzx edi,word ptr [edx]
BUGCHECK_STR: 0x24
LAST_CONTROL_TRANSFER: from 8c227d53 to 8c228773
STACK_TEXT:
9d992bc8 8c227d53 8873bd5c 00000727 00000000 Ntfs!NtfsFindRollbackStructByType+0x23
9d992bec 8c2286d9 8873bcf0 a458a820 a458a820 Ntfs!NtfsFreeSnapshotsForFcb+0x25
9d992c04 8c22ec22 8873bcf0 a458a820 9d992cd0 Ntfs!NtfsReleaseFcb+0x35
9d992c1c 8c2ae5d7 8873bcf0 a458a820 8c2ae57c Ntfs!NtfsReleaseFcbWithPaging+0x2a
9d992c28 8c2ae57c 11bc871e 9d992ca4 8873bcf0 Ntfs!NtfsCommonClose+0x569
9d992c6c 8c2cd4c3 8873bcf0 a458a910 a458a820 Ntfs!NtfsCommonClose+0x513
9d992d00 82aa6f3b 00000000 00000000 886fd380 Ntfs!NtfsFspClose+0x118
9d992d50 82c476d3 80000000 b0ff03dc 00000000 nt!ExpWorkerThread+0x10d
9d992d90 82af90f9 82aa6e2e 80000000 00000000 nt!PspSystemThreadStartup+0x9e
00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x19
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: Ntfs!NtfsFindRollbackStructByType+23
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Ntfs
IMAGE_NAME: Ntfs.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bbf45
STACK_COMMAND: .cxr 0xffffffff9d9926d0 ; kb
FAILURE_BUCKET_ID: 0x24_Ntfs!NtfsFindRollbackStructByType+23
BUCKET_ID: 0x24_Ntfs!NtfsFindRollbackStructByType+23
Followup: MachineOwner
---------
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\a\Minidump\D M P\122310-25459-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16617.x86fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0x82a37000 PsLoadedModuleList = 0x82b7f810
Debug session time: Thu Dec 23 00:45:41.117 2010 (UTC - 5:00)
System Uptime: 0 days 0:01:26.099
Loading Kernel Symbols
...............................................................
................................................................
.................................
Loading User Symbols
Loading unloaded module list
.....
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 00001236, The subtype of the bugcheck.
Arg2: 8877ea60
Arg3: 8877ead4
Arg4: 00156792
Debugging Details:
------------------
BUGCHECK_STR: 0x1a_1236
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 82ab7ff4 to 82b13d10
STACK_TEXT:
977b9a9c 82ab7ff4 0000001a 00001236 8877ea60 nt!KeBugCheckEx+0x1e
977b9ad4 8c609c55 000002ad 00000f94 85382268 nt!MmFreePagesFromMdl+0x39
977b9ae8 8c60ae42 85382220 00000f94 8610cf28 rdyboost!SMKM_STORE<SMD_TRAITS>::SmStReleaseRegion+0x1f
977b9b00 8c60ea24 85382268 00000f94 8c6240b0 rdyboost!ST_STORE<SMD_TRAITS>::StReleaseRegion+0x24
977b9b20 8c60eae8 85382268 00000000 85382220 rdyboost!ST_STORE<SMD_TRAITS>::StDmCleanup+0xb4
977b9b34 8c60ebe9 85382220 85382220 85382220 rdyboost!ST_STORE<SMD_TRAITS>::StCleanup+0x14
977b9b48 8c60ec92 85382220 00000001 8c6240f8 rdyboost!SMKM_STORE<SMD_TRAITS>::SmStCleanup+0x57
977b9b64 8c62bc45 8c6240b0 85382220 00000001 rdyboost!SMKM_STORE_MGR<SMD_TRAITS>::SmStoreMgrCallback+0x2a
977b9b84 8c60b9cd 00000008 8c6240b0 977b9bb4 rdyboost!SmKmCleanup+0x79
977b9b94 8c626ab3 8c6240b0 00000000 87d2c0d0 rdyboost!SMKM_STORE_MGR<SMD_TRAITS>::SmCleanup+0xf
977b9bb4 8c6178f5 8c6240b0 00000000 1b19ab01 rdyboost!SmdRBContextShutdown+0x83
977b9bfc 82a734bc 85382120 87d2c0d0 87d2c0d0 rdyboost!SmdDispatchDeviceControl+0x273
977b9c14 82c74f6e 889c5918 87d2c0d0 87d2c140 nt!IofCallDriver+0x63
977b9c34 82c91d5f 85382120 889c5918 00000000 nt!IopSynchronousServiceTail+0x1f8
977b9cd0 82c9453a 85382120 87d2c0d0 00000000 nt!IopXxxControlFile+0x6aa
977b9d04 82a7a44a 000005cc 00000000 00000000 nt!NtDeviceIoControlFile+0x2a
977b9d04 776964f4 000005cc 00000000 00000000 nt!KiFastCallEntry+0x12a
WARNING: Frame IP not in any known module. Following frames may be wrong.
0162ee40 00000000 00000000 00000000 00000000 0x776964f4
STACK_COMMAND: kb
FOLLOWUP_IP:
rdyboost!SMKM_STORE<SMD_TRAITS>::SmStReleaseRegion+1f
8c609c55 6a00 push 0
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: rdyboost!SMKM_STORE<SMD_TRAITS>::SmStReleaseRegion+1f
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: rdyboost
IMAGE_NAME: rdyboost.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc19a
FAILURE_BUCKET_ID: 0x1a_1236_rdyboost!SMKM_STORE_SMD_TRAITS_::SmStReleaseRegion+1f
BUCKET_ID: 0x1a_1236_rdyboost!SMKM_STORE_SMD_TRAITS_::SmStReleaseRegion+1f
Followup: MachineOwner
---------
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\a\Minidump\D M P\122210-40061-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16617.x86fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0x82a46000 PsLoadedModuleList = 0x82b8e810
Debug session time: Thu Dec 16 00:13:29.229 2010 (UTC - 5:00)
System Uptime: 0 days 1:14:43.211
Loading Kernel Symbols
...............................................................
................................................................
.................................
Loading User Symbols
Loading unloaded module list
..........
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1000008E, {c0000005, 82c5eaf7, 99d36b30, 0}
Probably caused by : ntkrpamp.exe ( nt!CmpRemoveKeyHash+17 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KERNEL_MODE_EXCEPTION_NOT_HANDLED_M (1000008e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: c0000005, The exception code that was not handled
Arg2: 82c5eaf7, The address that the exception occurred at
Arg3: 99d36b30, Trap Frame
Arg4: 00000000
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text>
FAULTING_IP:
nt!CmpRemoveKeyHash+17
82c5eaf7 f7b12c030000 div eax,dword ptr [ecx+32Ch]
TRAP_FRAME: 99d36b30 -- (.trap 0xffffffff99d36b30)
ErrCode = 00000000
eax=0b8caca4 ebx=982339d0 ecx=00000000 edx=00000000 esi=a0d6b5b4 edi=a0d6b5a8
eip=82c5eaf7 esp=99d36ba4 ebp=99d36bbc iopl=0 nv up ei pl zr na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010246
nt!CmpRemoveKeyHash+0x17:
82c5eaf7 f7b12c030000 div eax,dword ptr [ecx+32Ch] ds:0023:0000032c=????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x8E
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 82c5eab3 to 82c5eaf7
STACK_TEXT:
99d36ba8 82c5eab3 a0d6b5c8 a0d6b5a8 86b2daa8 nt!CmpRemoveKeyHash+0x17
99d36bbc 82cdb66f 00000001 8d0f2968 9823c000 nt!CmpCleanUpKcbCacheWithLock+0x53
99d36bf0 82cdbc76 982339d0 00000000 00000001 nt!CmpCleanUpKCBCacheTable+0x16f
99d36c24 82cd3e15 00000000 00000000 b4a60bea nt!CmpSearchForOpenSubKeys+0x29
99d36d14 82cd2381 00000000 00000000 86b2daa8 nt!NtUnloadKey2+0x330
99d36d28 82a8944a 00e2f89c 00e2fadc 775064f4 nt!NtUnloadKey+0x10
99d36d28 775064f4 00e2f89c 00e2fadc 775064f4 nt!KiFastCallEntry+0x12a
WARNING: Frame IP not in any known module. Following frames may be wrong.
00e2fadc 00000000 00000000 00000000 00000000 0x775064f4
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!CmpRemoveKeyHash+17
82c5eaf7 f7b12c030000 div eax,dword ptr [ecx+32Ch]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!CmpRemoveKeyHash+17
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrpamp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c3fac
FAILURE_BUCKET_ID: 0x8E_nt!CmpRemoveKeyHash+17
BUCKET_ID: 0x8E_nt!CmpRemoveKeyHash+17
Followup: MachineOwner
---------
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\a\Minidump\D M P\122310-21746-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16617.x86fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0x82a3c000 PsLoadedModuleList = 0x82b84810
Debug session time: Thu Dec 23 00:47:40.501 2010 (UTC - 5:00)
System Uptime: 0 days 0:01:24.342
Loading Kernel Symbols
...............................................................
................................................................
.................................
Loading User Symbols
Loading unloaded module list
.....
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
NTFS_FILE_SYSTEM (24)
If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
parameters are the exception record and context record. Do a .cxr
on the 3rd parameter and then kb to obtain a more informative stack
trace.
Arguments:
Arg1: 001904fb
Arg2: 8e30ba40
Arg3: 8e30b620
Arg4: 8c2dae78
Debugging Details:
------------------
EXCEPTION_RECORD: 8e30ba40 -- (.exr 0xffffffff8e30ba40)
ExceptionAddress: 8c2dae78 (Ntfs!NtfsRemoveFcbFromSharedResourceList+0x0000002c)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 00000000
Parameter[1]: 00033000
Attempt to read from address 00033000
CONTEXT: 8e30b620 -- (.cxr 0xffffffff8e30b620)
eax=00000000 ebx=82aa67a3 ecx=00000000 edx=00000000 esi=00033000 edi=887ed180
eip=8c2dae78 esp=8e30bb08 ebp=8e30bb14 iopl=0 nv up ei ng nz na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010286
Ntfs!NtfsRemoveFcbFromSharedResourceList+0x2c:
8c2dae78 8b06 mov eax,dword ptr [esi] ds:0023:00033000=????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text>
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text>
EXCEPTION_PARAMETER1: 00000000
EXCEPTION_PARAMETER2: 00033000
READ_ADDRESS: GetPointerFromAddress: unable to read from 82ba4718
Unable to read MiSystemVaType memory at 82b84160
00033000
FOLLOWUP_IP:
Ntfs!NtfsRemoveFcbFromSharedResourceList+2c
8c2dae78 8b06 mov eax,dword ptr [esi]
FAULTING_IP:
Ntfs!NtfsRemoveFcbFromSharedResourceList+2c
8c2dae78 8b06 mov eax,dword ptr [esi]
BUGCHECK_STR: 0x24
LAST_CONTROL_TRANSFER: from 8c2d7b5f to 8c2dae78
STACK_TEXT:
8e30bb14 8c2d7b5f ffff7400 a5f69008 00000000 Ntfs!NtfsRemoveFcbFromSharedResourceList+0x2c
8e30bb40 8c243174 887ed180 8e30bb70 8e30bb7a Ntfs!NtfsDeleteFcb+0x6c
8e30bb94 8c2bf15d 887ed180 861780d8 a5f69008 Ntfs!NtfsTeardownFromLcb+0x24f
8e30bbe4 8c23bbec 887ed180 a5f690f8 01f692a0 Ntfs!NtfsTeardownStructures+0xf3
8e30bc0c 8c2bb55b 887ed180 a5f690f8 a5f692a0 Ntfs!NtfsDecrementCloseCounts+0xaf
8e30bc6c 8c2da4c3 887ed180 a5f690f8 a5f69008 Ntfs!NtfsCommonClose+0x4f2
8e30bd00 82aa9f3b 00000000 00000000 85367a70 Ntfs!NtfsFspClose+0x118
8e30bd50 82c4a6d3 00000000 a287e760 00000000 nt!ExpWorkerThread+0x10d
8e30bd90 82afc0f9 82aa9e2e 00000000 00000000 nt!PspSystemThreadStartup+0x9e
00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x19
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: Ntfs!NtfsRemoveFcbFromSharedResourceList+2c
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Ntfs
IMAGE_NAME: Ntfs.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bbf45
STACK_COMMAND: .cxr 0xffffffff8e30b620 ; kb
FAILURE_BUCKET_ID: 0x24_Ntfs!NtfsRemoveFcbFromSharedResourceList+2c
BUCKET_ID: 0x24_Ntfs!NtfsRemoveFcbFromSharedResourceList+2c
Followup: MachineOwner
---------