Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\K\Desktop\112009-15600-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*d:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
[B]Windows 7 Kernel Version 7600 MP (4 procs) Free x64[/B]
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16385.amd64fre.win7_rtm.090713-1255
Machine Name:
Kernel base = 0xfffff800`02c1a000 PsLoadedModuleList = 0xfffff800`02e57e50
Debug session time: Fri Nov 20 19:59:47.961 2009 (GMT-5)
System Uptime: 0 days 0:28:24.991
Loading Kernel Symbols
...............................................................
................................................................
..................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {fffffa7fcda9483f, 1, fffff880012b8b97, 7}
[B]Could not read faulting driver name
Probably caused by : memory_corruption[/B]
Followup: memory_corruption
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
[B]Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.[/B]
Arguments:
Arg1: fffffa7fcda9483f, memory referenced.
Arg2: 0000000000000001, value 0 = read operation, 1 = write operation.
Arg3: fffff880012b8b97, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000007, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff80002ec20e0
fffffa7fcda9483f
FAULTING_IP:
Ntfs!NtfsOpenAttribute+347
fffff880`012b8b97 0989475048c7 or dword ptr [rcx-38B7AFB9h],ecx
MM_INTERNAL_CODE: 7
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: CODE_CORRUPTION
BUGCHECK_STR: 0x50
[B]
PROCESS_NAME: explorer.exe[/B]
CURRENT_IRQL: 0
TRAP_FRAME: fffff88007767930 -- (.trap 0xfffff88007767930)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=fffffa800660f7f8
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff880012b8b97 rsp=fffff88007767ac0 rbp=0000000000000000
r8=fffffa800660f7f8 r9=0000000000000000 r10=fffff88001263380
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na po nc
Ntfs!NtfsOpenAttribute+0x347:
fffff880`012b8b97 0989475048c7 or dword ptr [rcx-38B7AFB9h],ecx ds:fffffa7f`cda9483f=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002d09b19 to fffff80002c8bf00
STACK_TEXT:
fffff880`077677c8 fffff800`02d09b19 : 00000000`00000050 fffffa7f`cda9483f 00000000`00000001 fffff880`07767930 : nt!KeBugCheckEx
fffff880`077677d0 fffff800`02c89fee : 00000000`00000001 fffffa80`03eaf210 fffffa80`042a4b00 fffffa80`0561af70 : nt! ?? ::FNODOBFM::`string'+0x40edb
fffff880`07767930 fffff880`012b8b97 : fffffa80`03eaf210 fffff880`07768300 00000000`00000000 fffff8a0`034973a8 : nt!KiPageFault+0x16e
fffff880`07767ac0 fffff880`012a6e45 : fffffa80`040668f0 fffffa80`0561af70 fffffa80`055fb180 fffff8a0`034973a8 : Ntfs!NtfsOpenAttribute+0x347
fffff880`07767bd0 fffff880`012a378b : fffff880`07768390 fffffa80`040668f0 fffff8a0`034973a8 fffff8a0`00000024 : Ntfs!NtfsOpenExistingAttr+0x145
fffff880`07767c90 fffff880`012a3eff : fffffa80`040668f0 fffffa80`0561ac60 fffff8a0`034973a8 fffff880`00000024 : Ntfs!NtfsOpenAttributeInExistingFile+0x5ab
fffff880`07767e20 fffff880`012b4e76 : fffffa80`040668f0 fffffa80`0561ac60 fffff8a0`034973a8 00000000`00010201 : Ntfs!NtfsOpenExistingPrefixFcb+0x1ef
fffff880`07767f10 fffff880`012af28d : fffffa80`040668f0 fffffa80`0561ac60 fffff880`077680f0 fffff880`07768138 : Ntfs!NtfsFindStartingNode+0x5e6
fffff880`07767fe0 fffff880`01218c0d : fffffa80`040668f0 fffffa80`0561ac60 fffff880`07768390 fffff8a0`00022000 : Ntfs!NtfsCommonCreate+0x3dd
fffff880`077681c0 fffff800`02c9b64a : fffff880`07768300 fffff880`077686a4 fffff880`077686c0 fffff800`02f64b28 : Ntfs!NtfsCommonCreateCallout+0x1d
fffff880`077681f0 fffff880`01218b2f : fffff880`01218bf0 fffff880`07768300 fffff880`07768300 fffff880`012ba32d : nt!KeExpandKernelStackAndCalloutEx+0xda
fffff880`077682d0 fffff880`012b59c0 : 00000000`00000000 00000000`00000000 fffff880`07768520 fffffa80`0561ac60 : Ntfs!NtfsCommonCreateOnNewStack+0x4f
fffff880`07768330 fffff880`0119223f : fffffa80`055fb030 fffffa80`0561ac60 00000000`00000000 fffffa80`054dba30 : Ntfs!NtfsFsdCreate+0x1b0
fffff880`077684e0 fffff880`011b12b9 : fffffa80`0561ac60 fffffa80`05623010 fffffa80`0561ac00 fffffa80`054dba30 : fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x24f
fffff880`07768570 fffff800`02f8c477 : 00000000`00000045 fffff800`02f8bed0 fffff880`077689d0 00000000`00000000 : fltmgr!FltpCreate+0x2a9
fffff880`07768620 fffff800`02f82764 : fffffa80`054829a0 00000000`00000000 fffffa80`042a4b10 00000000`00000000 : nt!IopParseDevice+0x5a7
fffff880`077687b0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!ObpLookupObjectName+0x585
STACK_COMMAND: kb
CHKIMG_EXTENSION: !chkimg -lo 50 -db !Ntfs
5 errors : !Ntfs (fffff880012b8b97-fffff880012b8bbf)
fffff880012b8b90 8b 84 24 90 00 00 00 *09 89 47 50 48 c7 84 24 *d0 ..$......GPH..$.
fffff880012b8ba0 00 00 00 00 00 00 00 *e5 8b b4 24 88 01 00 00 49 ..........$....I
fffff880012b8bb0 89 3e 49 8b 45 50 f6 *a0 e8 0f 00 00 10 0f 85 *e4 .>I.EP..........
MODULE_NAME: memory_corruption
IMAGE_NAME: memory_corruption
FOLLOWUP_NAME: memory_corruption
DEBUG_FLR_IMAGE_TIMESTAMP: 0
[B]
MEMORY_CORRUPTOR: STRIDE[/B]
FAILURE_BUCKET_ID: X64_MEMORY_CORRUPTION_STRIDE
BUCKET_ID: X64_MEMORY_CORRUPTION_STRIDE
Followup: memory_corruption