Windows 7 Kernel Version 7600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`02e02000 PsLoadedModuleList = 0xfffff800`0303fe50
Debug session time: Wed Nov 10 04:47:06.668 2010 (GMT-5)
System Uptime: 0 days 0:03:18.400
Loading Kernel Symbols
...............................................................
................................................................
................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 24, {1904fb, fffff880067b63e8, fffff880067b5c50, fffff80002e75905}
Probably caused by : Ntfs.sys ( Ntfs!NtfsOpenAttribute+580 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
NTFS_FILE_SYSTEM (24)
If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
parameters are the exception record and context record. Do a .cxr
on the 3rd parameter and then kb to obtain a more informative stack
trace.
Arguments:
Arg1: 00000000001904fb
Arg2: fffff880067b63e8
Arg3: fffff880067b5c50
Arg4: fffff80002e75905
Debugging Details:
------------------
EXCEPTION_RECORD: fffff880067b63e8 -- (.exr 0xfffff880067b63e8)
ExceptionAddress: fffff80002e75905 (nt!ExpInterlockedPopEntrySListFault16)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
CONTEXT: fffff880067b5c50 -- (.cxr 0xfffff880067b5c50)
rax=0000000035680000 rbx=fffffa8005cda900 rcx=fffff88001277380
rdx=0200000000000001 rsi=fffffa80064897b8 rdi=fffff8a0001ced70
rip=fffff80002e75905 rsp=fffff880067b6620 rbp=0000000000000000
r8=0200000000000000 r9=fffff8a0001cec10 r10=fffff88001277380
r11=0000000000000001 r12=fffff88007e26b30 r13=fffff8a0001cea50
r14=0000000000000002 r15=fffff88007e26ac0
iopl=0 nv up ei pl nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010206
nt!ExpInterlockedPopEntrySListFault16:
fffff800`02e75905 498b08 mov rcx,qword ptr [r8] ds:002b:02000000`00000000=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: sppsvc.exe
CURRENT_IRQL: 0
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: ffffffffffffffff
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800030aa0e0
ffffffffffffffff
FOLLOWUP_IP:
Ntfs!NtfsOpenAttribute+580
fffff880`012ccdd0 488bf8 mov rdi,rax
FAULTING_IP:
nt!ExpInterlockedPopEntrySListFault16+0
fffff800`02e75905 498b08 mov rcx,qword ptr [r8]
BUGCHECK_STR: 0x24
LAST_CONTROL_TRANSFER: from fffff880012ccdd0 to fffff80002e75905
STACK_TEXT:
fffff880`067b6620 fffff880`012ccdd0 : 00000000`00000000 fffff880`07e26a00 fffff8a0`00000002 fffff8a0`001cede8 : nt!ExpInterlockedPopEntrySListFault16
fffff880`067b6630 fffff880`012bae45 : fffffa80`05cda910 fffffa80`064897b8 fffffa80`04b2d180 fffff8a0`001cede8 : Ntfs!NtfsOpenAttribute+0x580
fffff880`067b6740 fffff880`012b778b : fffff880`07e26ac0 fffffa80`05cda910 fffff8a0`001cede8 fffff8a0`00000024 : Ntfs!NtfsOpenExistingAttr+0x145
fffff880`067b6800 fffff880`012b7eff : fffffa80`05cda910 fffffa80`06489460 fffff8a0`001cede8 fffff880`00000024 : Ntfs!NtfsOpenAttributeInExistingFile+0x5ab
fffff880`067b6990 fffff880`012c8e76 : fffffa80`05cda910 fffffa80`06489460 fffff8a0`001cede8 00000000`00000701 : Ntfs!NtfsOpenExistingPrefixFcb+0x1ef
fffff880`067b6a80 fffff880`012c328d : fffffa80`05cda910 fffffa80`06489460 fffff880`067b6c60 fffff880`067b6ca8 : Ntfs!NtfsFindStartingNode+0x5e6
fffff880`067b6b50 fffff880`0122cc0d : fffffa80`05cda910 fffffa80`06489460 fffff880`07e26ac0 fffffa80`0646cb00 : Ntfs!NtfsCommonCreate+0x3dd
fffff880`067b6d30 fffff800`02e6a5c7 : fffff880`07e26a30 00000000`00000000 00000000`00000000 00000000`00000000 : Ntfs!NtfsCommonCreateCallout+0x1d
fffff880`067b6d60 fffff800`02e6a581 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KySwitchKernelStackCallout+0x27
fffff880`07e26900 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSwitchKernelStackContinue
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: Ntfs!NtfsOpenAttribute+580
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Ntfs
IMAGE_NAME: Ntfs.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc14f
STACK_COMMAND: .cxr 0xfffff880067b5c50 ; kb
FAILURE_BUCKET_ID: X64_0x24_Ntfs!NtfsOpenAttribute+580
BUCKET_ID: X64_0x24_Ntfs!NtfsOpenAttribute+580
Followup: MachineOwner
---------
Debug session time: Wed Nov 10 04:55:47.138 2010 (GMT-5)
System Uptime: 0 days 0:07:26.871
Loading Kernel Symbols
...............................................................
................................................................
.................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1A, {31, fffffa8003d416f0, fffff8800460a000, fffff8a0029182a8}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::NNGAKEGL::`string'+6368 )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000000031, The subtype of the bugcheck.
Arg2: fffffa8003d416f0
Arg3: fffff8800460a000
Arg4: fffff8a0029182a8
Debugging Details:
------------------
BUGCHECK_STR: 0x1a_31
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff800031f074d to fffff80002ec4740
STACK_TEXT:
fffff880`06baa168 fffff800`031f074d : 00000000`0000001a 00000000`00000031 fffffa80`03d416f0 fffff880`0460a000 : nt!KeBugCheckEx
fffff880`06baa170 fffff800`031ac0b1 : fffff880`0460a000 ffffffff`fffc0000 00000000`00001000 fffffa80`01f4cc40 : nt! ?? ::NNGAKEGL::`string'+0x6368
fffff880`06baa1c0 fffff800`03199344 : 00000000`00000000 00000000`00000000 fffff6fc`40023040 fffff800`00000000 : nt!MiPerformFixups+0x65
fffff880`06baa210 fffff800`02ea668d : 00000000`000a6eec 00000000`00000001 fffff8a0`018f09d0 00000000`00000002 : nt!MiRelocateImagePfn+0x114
fffff880`06baa270 fffff800`031ac00d : fffffa80`04031010 fffff6fc`40023040 fffff8a0`00000002 00000000`00000000 : nt!MiValidateImagePages+0x2bd
fffff880`06baa310 fffff800`031ab720 : ffffffff`ffffffff 00000000`00000001 fffff8a0`02918000 00000000`000000ba : nt!MiSwitchBaseAddress+0x61
fffff880`06baa340 fffff800`031bf7ce : 00000000`00000004 00000000`01000000 00000000`00000000 00000000`00000000 : nt!MiRelocateImageAgain+0x100
fffff880`06baa390 fffff800`031b5013 : fffff880`06baa5f0 00000000`00000000 fffff880`06baa698 fffff880`06baa5e8 : nt!MmCreateSection+0x302
fffff880`06baa5a0 fffff800`03321a23 : 00000000`00000000 fffff8a0`0214b5e0 00000000`00000000 00000000`00000001 : nt!NtCreateSection+0x162
fffff880`06baa620 fffff800`03321fb1 : 00000000`00000000 fffff8a0`0214b5e0 fffffa80`055214f0 fffff880`00000060 : nt!PfpFileBuildReadSupport+0x163
fffff880`06baa710 fffff800`0332a0ce : fffff8a0`00000000 fffff8a0`0000001c fffff8a0`00000071 00000000`00000000 : nt!PfpPrefetchFilesTrickle+0x121
fffff880`06baa810 fffff800`0332ac67 : 00000000`00000000 fffff880`06baaca0 fffff880`06baaa08 fffff8a0`00f61060 : nt!PfpPrefetchRequestPerform+0x30e
fffff880`06baa960 fffff800`0333723e : fffff880`06baaa08 fffff880`06baaa01 fffffa80`061c6710 00000000`00000000 : nt!PfpPrefetchRequest+0x176
fffff880`06baa9d0 fffff800`0333b96e : 00000000`00000000 00000000`0316f7e0 00000000`0000004f 00000000`05caf001 : nt!PfSetSuperfetchInformation+0x1ad
fffff880`06baaab0 fffff800`02ec3993 : fffffa80`05ecf060 00000000`00000000 00000000`00000001 00000000`00000001 : nt!NtSetSystemInformation+0xb91
fffff880`06baac20 00000000`7715144a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0316f7b8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7715144a
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::NNGAKEGL::`string'+6368
fffff800`031f074d cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::NNGAKEGL::`string'+6368
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
FAILURE_BUCKET_ID: X64_0x1a_31_nt!_??_::NNGAKEGL::_string_+6368
BUCKET_ID: X64_0x1a_31_nt!_??_::NNGAKEGL::_string_+6368
Followup: MachineOwner
---------
Debug session time: Tue Nov 30 07:06:55.650 2010 (GMT-5)
System Uptime: 0 days 22:35:11.383
Loading Kernel Symbols
...............................................................
................................................................
..................
Loading User Symbols
Loading unloaded module list
...........
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 19, {22, 200000000000000, 0, 0}
GetPointerFromAddress: unable to read from fffff800030b10e0
GetUlongFromAddress: unable to read from fffff8000301f1b0
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+72f8 )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
BAD_POOL_HEADER (19)
The pool is already corrupt at the time of the current request.
This may or may not be due to the caller.
The internal pool links must be walked to figure out a possible cause of
the problem, and then special pool applied to the suspect tags or the driver
verifier to a suspect driver.
Arguments:
Arg1: 0000000000000022,
Arg2: 0200000000000000
Arg3: 0000000000000000
Arg4: 0000000000000000
Debugging Details:
------------------
GetUlongFromAddress: unable to read from fffff8000301f1b0
BUGCHECK_STR: 0x19_22
POOL_ADDRESS: 0200000000000000
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 2
LAST_CONTROL_TRANSFER: from fffff80002ecec80 to fffff80002e79740
STACK_TEXT:
fffff880`02fa8ab8 fffff800`02ecec80 : 00000000`00000019 00000000`00000022 02000000`00000000 00000000`00000000 : nt!KeBugCheckEx
fffff880`02fa8ac0 fffff800`02fae518 : 00000000`00000000 fffff880`02fa8c10 fffff880`02fa8b80 00000000`00000001 : nt! ?? ::FNODOBFM::`string'+0x72f8
fffff880`02fa8b50 fffff800`031a9b8a : 00000000`09d62306 fffff880`02a8fbb4 00000000`6c414d43 00000000`00000000 : nt!ExFreePoolWithTag+0x468
fffff880`02fa8c00 fffff800`0316c74b : 00000000`00000000 00000000`00000001 fffff8a0`0365d420 fffff800`0316c217 : nt! ?? ::NNGAKEGL::`string'+0xc3ea
fffff880`02fa8c30 fffff800`0316c9c4 : 00000000`00000001 00000000`00000001 fffff8a0`0365d420 fffffa80`03b88b60 : nt!CmpDereferenceKeyControlBlock+0x25f
fffff880`02fa8c80 fffff800`02e86961 : fffff800`0316c8dc fffff800`0301e5f8 fffffa80`03b88b60 00000000`00000000 : nt!CmpDelayDerefKCBWorker+0xe8
fffff880`02fa8cb0 fffff800`0311dc06 : 006a6b75`0ad87d83 fffffa80`03b88b60 00000000`00000080 fffffa80`03af49e0 : nt!ExpWorkerThread+0x111
fffff880`02fa8d40 fffff800`02e57c26 : fffff880`02d63180 fffffa80`03b88b60 fffff880`02d6dfc0 75ff5614`75d07539 : nt!PspSystemThreadStartup+0x5a
fffff880`02fa8d80 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KxStartSystemThread+0x16
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+72f8
fffff800`02ecec80 cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+72f8
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
FAILURE_BUCKET_ID: X64_0x19_22_nt!_??_::FNODOBFM::_string_+72f8
BUCKET_ID: X64_0x19_22_nt!_??_::FNODOBFM::_string_+72f8
Followup: MachineOwner
---------
Debug session time: Wed Dec 1 06:00:29.624 2010 (GMT-5)
System Uptime: 0 days 0:01:16.357
Loading Kernel Symbols
...............................................................
................................................................
................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1A, {41284, 7fef8021001, 0, fffff70001080000}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+4a83 )
Followup: MachineOwner
---------
3: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041284, A PTE or the working set list is corrupt.
Arg2: 000007fef8021001
Arg3: 0000000000000000
Arg4: fffff70001080000
Debugging Details:
------------------
BUGCHECK_STR: 0x1a_41284
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: dllhost.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff80002f2b3b3 to fffff80002ed6740
STACK_TEXT:
fffff880`07e5e7e8 fffff800`02f2b3b3 : 00000000`0000001a 00000000`00041284 000007fe`f8021001 00000000`00000000 : nt!KeBugCheckEx
fffff880`07e5e7f0 fffff800`02f49cc3 : fffffa80`03013800 51b00001`00680025 000007fe`f8020000 d1800001`158f8025 : nt! ?? ::FNODOBFM::`string'+0x4a83
fffff880`07e5e830 fffff800`02f09df9 : 00000000`00000000 000007fe`f80bffff fffffa80`00000000 fffffa80`0507c4d0 : nt! ?? ::FNODOBFM::`string'+0x3360b
fffff880`07e5e9f0 fffff800`031ef1d0 : fffffa80`0674f7b0 0007ffff`00000000 00000000`00000000 00000000`00000000 : nt!MiRemoveMappedView+0xd9
fffff880`07e5eb10 fffff800`031ef5db : 00000980`00000000 000007fe`f8020000 fffffa80`00000001 fffffa80`0571e010 : nt!MiUnmapViewOfSection+0x1b0
fffff880`07e5ebd0 fffff800`02ed5993 : 00000000`00000008 00000000`0038e240 fffffa80`05ea0b30 000007fe`ff6a0000 : nt!NtUnmapViewOfSection+0x5f
fffff880`07e5ec20 00000000`7796fffa : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0264f788 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7796fffa
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+4a83
fffff800`02f2b3b3 cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+4a83
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
FAILURE_BUCKET_ID: X64_0x1a_41284_nt!_??_::FNODOBFM::_string_+4a83
BUCKET_ID: X64_0x1a_41284_nt!_??_::FNODOBFM::_string_+4a83
Followup: MachineOwner
---------
3: kd> lmtsmn
start end module name
fffff880`00f21000 fffff880`00f78000 ACPI ACPI.sys Mon Jul 13 19:19:34 2009 (4A5BC106)
fffff880`02a00000 fffff880`02a8a000 afd afd.sys Mon Jul 13 19:21:40 2009 (4A5BC184)
fffff880`03cdf000 fffff880`03cf5000 AgileVpn AgileVpn.sys Mon Jul 13 20:10:24 2009 (4A5BCCF0)
fffff880`03c3d000 fffff880`03c52000 amdppm amdppm.sys Mon Jul 13 19:19:25 2009 (4A5BC0FD)
fffff880`00ff5000 fffff880`01000000 amdxata amdxata.sys Tue May 19 13:56:59 2009 (4A12F2EB)
fffff880`03e97000 fffff880`03e9f000 ASACPI ASACPI.sys Wed Jul 15 23:31:29 2009 (4A5E9F11)
fffff880`03c11000 fffff880`03c17000 AsIO AsIO.sys Mon Aug 03 03:03:16 2009 (4A768BB4)
fffff880`00e63000 fffff880`00e6c000 atapi atapi.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`00d82000 fffff880`00dac000 ataport ataport.SYS Mon Jul 13 19:19:52 2009 (4A5BC118)
fffff880`01450000 fffff880`01458000 AtiPcie AtiPcie.sys Mon Aug 24 04:25:26 2009 (4A924E76)
fffff960`00710000 fffff960`00771000 ATMFD ATMFD.DLL Thu May 27 00:11:31 2010 (4BFDF0F3)
fffff880`02aee000 fffff880`02af5000 Beep Beep.SYS Mon Jul 13 20:00:13 2009 (4A5BCA8D)
fffff880`03c00000 fffff880`03c11000 blbdrive blbdrive.sys Mon Jul 13 19:35:59 2009 (4A5BC4DF)
fffff880`011e1000 fffff880`011ff000 bowser bowser.sys Mon Jul 13 19:23:50 2009 (4A5BC206)
fffff960`00980000 fffff960`009a7000 cdd cdd.dll Wed May 19 15:48:26 2010 (4BF4408A)
fffff880`02abb000 fffff880`02ae5000 cdrom cdrom.sys Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`00c00000 fffff880`00cc0000 CI CI.dll Mon Jul 13 21:32:13 2009 (4A5BE01D)
fffff880`01000000 fffff880`01030000 CLASSPNP CLASSPNP.SYS Mon Jul 13 19:19:58 2009 (4A5BC11E)
fffff880`00d0a000 fffff880`00d68000 CLFS CLFS.SYS Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`01374000 fffff880`013e7000 cng cng.sys Mon Jul 13 19:49:40 2009 (4A5BC814)
fffff880`03ccf000 fffff880`03cdf000 CompositeBus CompositeBus.sys Mon Jul 13 20:00:33 2009 (4A5BCAA1)
fffff880`067cb000 fffff880`067d9000 crashdmp crashdmp.sys Mon Jul 13 20:01:01 2009 (4A5BCABD)
fffff880`03ddc000 fffff880`03dfa000 dfsc dfsc.sys Mon Jul 13 19:23:44 2009 (4A5BC200)
fffff880`03dcd000 fffff880`03ddc000 discache discache.sys Mon Jul 13 19:37:18 2009 (4A5BC52E)
fffff880`0143a000 fffff880`01450000 disk disk.sys Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`064f2000 fffff880`06514000 drmk drmk.sys Mon Jul 13 21:01:25 2009 (4A5BD8E5)
fffff880`067e5000 fffff880`067ee000 dump_atapi dump_atapi.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`067d9000 fffff880`067e5000 dump_dumpata dump_dumpata.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`0651a000 fffff880`0652d000 dump_dumpfve dump_dumpfve.sys Mon Jul 13 19:21:51 2009 (4A5BC18F)
fffff880`067bf000 fffff880`067cb000 Dxapi Dxapi.sys Mon Jul 13 19:38:28 2009 (4A5BC574)
fffff880`03ea6000 fffff880`03f9a000 dxgkrnl dxgkrnl.sys Thu Oct 01 21:00:14 2009 (4AC5509E)
fffff880`03f9a000 fffff880`03fe0000 dxgmms1 dxgmms1.sys Mon Jul 13 19:38:32 2009 (4A5BC578)
fffff880`00cd0000 fffff880`00ce4000 fileinfo fileinfo.sys Mon Jul 13 19:34:25 2009 (4A5BC481)
fffff880`00dac000 fffff880`00df8000 fltmgr fltmgr.sys Mon Jul 13 19:19:59 2009 (4A5BC11F)
fffff880`01200000 fffff880`0120a000 Fs_Rec Fs_Rec.sys Mon Jul 13 19:19:45 2009 (4A5BC111)
fffff880`01400000 fffff880`0143a000 fvevol fvevol.sys Fri Sep 25 22:34:26 2009 (4ABD7DB2)
fffff880`014f9000 fffff880`01543000 fwpkclnt fwpkclnt.sys Mon Jul 13 19:21:08 2009 (4A5BC164)
fffff800`02e1d000 fffff800`02e66000 hal hal.dll Mon Jul 13 21:27:36 2009 (4A5BDF08)
fffff880`03e00000 fffff880`03e24000 HDAudBus HDAudBus.sys Mon Jul 13 20:06:13 2009 (4A5BCBF5)
fffff880`06556000 fffff880`0656f000 HIDCLASS HIDCLASS.SYS Mon Jul 13 20:06:21 2009 (4A5BCBFD)
fffff880`0656f000 fffff880`06577080 HIDPARSE HIDPARSE.SYS Mon Jul 13 20:06:17 2009 (4A5BCBF9)
fffff880`06548000 fffff880`06556000 hidusb hidusb.sys Mon Jul 13 20:06:22 2009 (4A5BCBFE)
fffff880`06418000 fffff880`064e0000 HTTP HTTP.sys Mon Jul 13 19:22:16 2009 (4A5BC1A8)
fffff880`015e3000 fffff880`015ec000 hwpolicy hwpolicy.sys Mon Jul 13 19:19:22 2009 (4A5BC0FA)
fffff880`03ca8000 fffff880`03cc6000 i8042prt i8042prt.sys Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`051ea000 fffff880`051f9000 kbdclass kbdclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff800`00ba3000 fffff800`00bad000 kdcom kdcom.dll Mon Jul 13 21:31:07 2009 (4A5BDFDB)
fffff880`0414d000 fffff880`04190000 ks ks.sys Wed Mar 03 23:32:25 2010 (4B8F37D9)
fffff880`0135a000 fffff880`01374000 ksecdd ksecdd.sys Mon Jul 13 19:20:54 2009 (4A5BC156)
fffff880`014ce000 fffff880`014f9000 ksecpkg ksecpkg.sys Fri Dec 11 01:03:32 2009 (4B21E0B4)
fffff880`06514000 fffff880`06519200 ksthunk ksthunk.sys Mon Jul 13 20:00:19 2009 (4A5BCA93)
fffff880`065d5000 fffff880`065ea000 lltdio lltdio.sys Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`06591000 fffff880`065b4000 luafv luafv.sys Mon Jul 13 19:26:13 2009 (4A5BC295)
fffff880`00ce9000 fffff880`00cf6000 mcupdate_AuthenticAMD mcupdate_AuthenticAMD.dll Mon Jul 13 21:29:09 2009 (4A5BDF65)
fffff880`067ee000 fffff880`067fc000 monitor monitor.sys Mon Jul 13 19:38:52 2009 (4A5BC58C)
fffff880`0413c000 fffff880`0414b000 mouclass mouclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff880`06578000 fffff880`06585000 mouhid mouhid.sys Mon Jul 13 20:00:20 2009 (4A5BCA94)
fffff880`00d68000 fffff880`00d82000 mountmgr mountmgr.sys Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`036a2000 fffff880`036ba000 mpsdrv mpsdrv.sys Mon Jul 13 20:08:25 2009 (4A5BCC79)
fffff880`036ba000 fffff880`036e7000 mrxsmb mrxsmb.sys Sat Feb 27 02:52:19 2010 (4B88CF33)
fffff880`036e7000 fffff880`03735000 mrxsmb10 mrxsmb10.sys Sat Feb 27 02:52:28 2010 (4B88CF3C)
fffff880`03735000 fffff880`03758000 mrxsmb20 mrxsmb20.sys Sat Feb 27 02:52:26 2010 (4B88CF3A)
fffff880`02b53000 fffff880`02b5e000 Msfs Msfs.SYS Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`00f81000 fffff880`00f8b000 msisadrv msisadrv.sys Mon Jul 13 19:19:26 2009 (4A5BC0FE)
fffff880`012fc000 fffff880`0135a000 msrpc msrpc.sys Mon Jul 13 19:21:32 2009 (4A5BC17C)
fffff880`03dc2000 fffff880`03dcd000 mssmbios mssmbios.sys Mon Jul 13 19:31:10 2009 (4A5BC3BE)
fffff880`015d1000 fffff880`015e3000 mup mup.sys Mon Jul 13 19:23:45 2009 (4A5BC201)
fffff880`0120a000 fffff880`012fc000 ndis ndis.sys Mon Jul 13 19:21:40 2009 (4A5BC184)
fffff880`040ab000 fffff880`040b7000 ndistapi ndistapi.sys Mon Jul 13 20:10:00 2009 (4A5BCCD8)
fffff880`040b7000 fffff880`040e6000 ndiswan ndiswan.sys Mon Jul 13 20:10:11 2009 (4A5BCCE3)
fffff880`04000000 fffff880`04015000 NDProxy NDProxy.SYS Mon Jul 13 20:10:05 2009 (4A5BCCDD)
fffff880`02be8000 fffff880`02bf7000 netbios netbios.sys Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff880`02b9a000 fffff880`02bdf000 netbt netbt.sys Mon Jul 13 19:21:28 2009 (4A5BC178)
fffff880`0146e000 fffff880`014ce000 NETIO NETIO.SYS Mon Jul 13 19:21:46 2009 (4A5BC18A)
fffff880`02b5e000 fffff880`02b6f000 Npfs Npfs.SYS Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`03db6000 fffff880`03dc2000 nsiproxy nsiproxy.sys Mon Jul 13 19:21:02 2009 (4A5BC15E)
fffff800`02e66000 fffff800`03442000 nt ntkrnlmp.exe Sat Jun 19 00:16:41 2010 (4C1C44A9)
fffff880`0103e000 fffff880`011e1000 Ntfs Ntfs.sys Mon Jul 13 19:20:47 2009 (4A5BC14F)
fffff880`02ae5000 fffff880`02aee000 Null Null.SYS Mon Jul 13 19:19:37 2009 (4A5BC109)
fffff880`051e8000 fffff880`051e9180 nvBridge nvBridge.kmd Sat Oct 16 13:06:16 2010 (4CB9DB88)
fffff880`04015000 fffff880`0403e000 nvhda64v nvhda64v.sys Tue Sep 07 16:08:40 2010 (4C869BC8)
fffff880`0460e000 fffff880`051e7a80 nvlddmkm nvlddmkm.sys Sat Oct 16 13:12:46 2010 (4CB9DD0E)
fffff880`02a8a000 fffff880`02ab0000 pacer pacer.sys Mon Jul 13 20:09:41 2009 (4A5BCCC5)
fffff880`03fe0000 fffff880`03ffd000 parport parport.sys Mon Jul 13 20:00:40 2009 (4A5BCAA8)
fffff880`00fcb000 fffff880`00fe0000 partmgr partmgr.sys Mon Jul 13 19:19:58 2009 (4A5BC11E)
fffff880`00f8b000 fffff880`00fbe000 pci pci.sys Mon Jul 13 19:19:51 2009 (4A5BC117)
fffff880`00e5c000 fffff880`00e63000 pciide pciide.sys Mon Jul 13 19:19:49 2009 (4A5BC115)
fffff880`00cc0000 fffff880`00cd0000 PCIIDEX PCIIDEX.SYS Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`013e7000 fffff880`013f8000 pcw pcw.sys Mon Jul 13 19:19:27 2009 (4A5BC0FF)
fffff880`03758000 fffff880`037fe000 peauth peauth.sys Mon Jul 13 21:01:19 2009 (4A5BD8DF)
fffff880`0403e000 fffff880`0407b000 portcls portcls.sys Mon Jul 13 20:06:27 2009 (4A5BCC03)
fffff880`00cf6000 fffff880`00d0a000 PSHED PSHED.dll Mon Jul 13 21:32:23 2009 (4A5BE027)
fffff880`04087000 fffff880`040ab000 rasl2tp rasl2tp.sys Mon Jul 13 20:10:11 2009 (4A5BCCE3)
fffff880`040e6000 fffff880`04101000 raspppoe raspppoe.sys Mon Jul 13 20:10:17 2009 (4A5BCCE9)
fffff880`04101000 fffff880`04122000 raspptp raspptp.sys Mon Jul 13 20:10:18 2009 (4A5BCCEA)
fffff880`04122000 fffff880`0413c000 rassstp rassstp.sys Mon Jul 13 20:10:25 2009 (4A5BCCF1)
fffff880`03d65000 fffff880`03db6000 rdbss rdbss.sys Mon Jul 13 19:24:09 2009 (4A5BC219)
fffff880`02b38000 fffff880`02b41000 RDPCDD RDPCDD.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`02b41000 fffff880`02b4a000 rdpencdd rdpencdd.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`02b4a000 fffff880`02b53000 rdprefmp rdprefmp.sys Mon Jul 13 20:16:35 2009 (4A5BCE63)
fffff880`01597000 fffff880`015d1000 rdyboost rdyboost.sys Mon Jul 13 19:34:34 2009 (4A5BC48A)
fffff880`06400000 fffff880`06418000 rspndr rspndr.sys Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`03e24000 fffff880`03e7b000 Rt64win7 Rt64win7.sys Mon Sep 20 03:38:09 2010 (4C970F61)
fffff880`03d4b000 fffff880`03d65000 SCDEmu SCDEmu.SYS Mon Apr 12 04:52:25 2010 (4BC2DF49)
fffff880`03600000 fffff880`0360b000 secdrv secdrv.SYS Wed Sep 13 09:18:38 2006 (4508052E)
fffff880`04600000 fffff880`0460c000 serenum serenum.sys Mon Jul 13 20:00:33 2009 (4A5BCAA1)
fffff880`03cff000 fffff880`03d1c000 serial serial.sys Mon Jul 13 20:00:40 2009 (4A5BCAA8)
fffff880`0158f000 fffff880`01597000 spldr spldr.sys Mon May 11 12:56:27 2009 (4A0858BB)
fffff880`0687a000 fffff880`06910000 srv srv.sys Thu Aug 26 23:38:00 2010 (4C773318)
fffff880`06813000 fffff880`0687a000 srv2 srv2.sys Thu Aug 26 23:37:46 2010 (4C77330A)
fffff880`0360b000 fffff880`03638000 srvnet srvnet.sys Thu Aug 26 23:37:24 2010 (4C7732F4)
fffff880`0414b000 fffff880`0414c480 swenum swenum.sys Mon Jul 13 20:00:18 2009 (4A5BCA92)
fffff880`01600000 fffff880`017fd000 tcpip tcpip.sys Sun Jun 13 23:39:04 2010 (4C15A458)
fffff880`03638000 fffff880`0364a000 tcpipreg tcpipreg.sys Mon Jul 13 20:09:49 2009 (4A5BCCCD)
fffff880`02b8d000 fffff880`02b9a000 TDI TDI.SYS Mon Jul 13 19:21:18 2009 (4A5BC16E)
fffff880`02b6f000 fffff880`02b8d000 tdx tdx.sys Mon Jul 13 19:21:15 2009 (4A5BC16B)
fffff880`03d37000 fffff880`03d4b000 termdd termdd.sys Mon Jul 13 20:16:36 2009 (4A5BCE64)
fffff960`00470000 fffff960`0047a000 TSDDD TSDDD.dll unavailable (00000000)
fffff880`03c17000 fffff880`03c3d000 tunnel tunnel.sys Mon Jul 13 20:09:37 2009 (4A5BCCC1)
fffff880`04190000 fffff880`041a2000 umbus umbus.sys Mon Jul 13 20:06:56 2009 (4A5BCC20)
fffff880`067fc000 fffff880`067fdf00 USBD USBD.SYS Mon Jul 13 20:06:23 2009 (4A5BCBFF)
fffff880`03e86000 fffff880`03e97000 usbehci usbehci.sys Mon Jul 13 20:06:30 2009 (4A5BCC06)
fffff880`041a2000 fffff880`041fc000 usbhub usbhub.sys Mon Jul 13 20:07:09 2009 (4A5BCC2D)
fffff880`03e7b000 fffff880`03e86000 usbohci usbohci.sys Mon Jul 13 20:06:30 2009 (4A5BCC06)
fffff880`03c52000 fffff880`03ca8000 USBPORT USBPORT.SYS Mon Jul 13 20:06:31 2009 (4A5BCC07)
fffff880`06585000 fffff880`06591000 usbprint usbprint.sys Mon Jul 13 20:38:18 2009 (4A5BD37A)
fffff880`06600000 fffff880`06611000 usbscan usbscan.sys Mon Jul 13 20:35:32 2009 (4A5BD2D4)
fffff880`0652d000 fffff880`06548000 USBSTOR USBSTOR.SYS Mon Jul 13 20:06:34 2009 (4A5BCC0A)
fffff880`00fbe000 fffff880`00fcb000 vdrvroot vdrvroot.sys Mon Jul 13 20:01:31 2009 (4A5BCADB)
fffff880`02af5000 fffff880`02b03000 vga vga.sys Mon Jul 13 19:38:47 2009 (4A5BC587)
fffff880`06611000 fffff880`067bf000 viahduaa viahduaa.sys Mon Jan 11 05:05:18 2010 (4B4AF7DE)
fffff880`02b03000 fffff880`02b28000 VIDEOPRT VIDEOPRT.SYS Mon Jul 13 19:38:51 2009 (4A5BC58B)
fffff880`00fe0000 fffff880`00ff5000 volmgr volmgr.sys Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`00e00000 fffff880`00e5c000 volmgrx volmgrx.sys Mon Jul 13 19:20:33 2009 (4A5BC141)
fffff880`01543000 fffff880`0158f000 volsnap volsnap.sys Mon Jul 13 19:20:08 2009 (4A5BC128)
fffff880`03d1c000 fffff880`03d37000 wanarp wanarp.sys Mon Jul 13 20:10:21 2009 (4A5BCCED)
fffff880`02b28000 fffff880`02b38000 watchdog watchdog.sys Mon Jul 13 19:37:35 2009 (4A5BC53F)
fffff880`00e6e000 fffff880`00f12000 Wdf01000 Wdf01000.sys Mon Jul 13 19:22:07 2009 (4A5BC19F)
fffff880`00f12000 fffff880`00f21000 WDFLDR WDFLDR.SYS Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`02bdf000 fffff880`02be8000 wfplwf wfplwf.sys Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff960`000a0000 fffff960`003af000 win32k win32k.sys Tue Aug 31 22:58:04 2010 (4C7DC13C)
fffff880`03cc6000 fffff880`03ccf000 wmiacpi wmiacpi.sys Mon Jul 13 19:31:02 2009 (4A5BC3B6)
fffff880`00f78000 fffff880`00f81000 WMILIB WMILIB.SYS Mon Jul 13 19:19:51 2009 (4A5BC117)
fffff880`065b4000 fffff880`065d5000 WudfPf WudfPf.sys Mon Jul 13 20:05:37 2009 (4A5BCBD1)
Unloaded modules:
fffff880`06910000 fffff880`06941000 WUDFRd.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`01458000 fffff880`01466000 crashdmp.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`015ec000 fffff880`015f8000 dump_ataport
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`01030000 fffff880`01039000 dump_atapi.s
Timestamp: unavailable (00000000)
Checksum: 00000000
fffff880`011e1000 fffff880`011f4000 dump_dumpfve
Timestamp: unavailable (00000000)
Checksum: 00000000