Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\DMP\040811-10077-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (3 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0xfffff800`02e12000 PsLoadedModuleList = 0xfffff800`03057e90
Debug session time: Fri Apr 8 01:11:09.426 2011 (UTC - 4:00)
System Uptime: 0 days 4:26:55.862
Loading Kernel Symbols
...............................................................
................................................................
............................
Loading User Symbols
Loading unloaded module list
......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {ffffe8a0002a9024, 1, fffff880012bd043, 7}
Could not read faulting driver name
Probably caused by : Ntfs.sys ( Ntfs!NtfsDeleteFcb+233 )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: ffffe8a0002a9024, memory referenced.
Arg2: 0000000000000001, value 0 = read operation, 1 = write operation.
Arg3: fffff880012bd043, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000007, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff800030c30e8
ffffe8a0002a9024
FAULTING_IP:
Ntfs!NtfsDeleteFcb+233
fffff880`012bd043 f0834124ff lock add dword ptr [rcx+24h],0FFFFFFFFh
MM_INTERNAL_CODE: 7
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: System
CURRENT_IRQL: 0
TRAP_FRAME: fffff8800334d7d0 -- (.trap 0xfffff8800334d7d0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffff8a003e8b010 rbx=0000000000000000 rcx=ffffe8a0002a9000
rdx=0000000000000723 rsi=0000000000000000 rdi=0000000000000000
rip=fffff880012bd043 rsp=fffff8800334d960 rbp=fffff8000302f600
r8=fffff8a003e8b010 r9=0000000000000000 r10=fffffa800a18f420
r11=fffff8a003e8b010 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na po nc
Ntfs!NtfsDeleteFcb+0x233:
fffff880`012bd043 f0834124ff lock add dword ptr [rcx+24h],0FFFFFFFFh ds:c180:ffffe8a0`002a9024=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002e3cbf7 to fffff80002e92640
STACK_TEXT:
fffff880`0334d668 fffff800`02e3cbf7 : 00000000`00000050 ffffe8a0`002a9024 00000000`00000001 fffff880`0334d7d0 : nt!KeBugCheckEx
fffff880`0334d670 fffff800`02e9076e : 00000000`00000001 ffffe8a0`002a9024 fffffa80`09c10100 fffff880`0334d9f0 : nt! ?? ::FNODOBFM::`string'+0x44811
fffff880`0334d7d0 fffff880`012bd043 : fffff880`0334d9f0 fffff880`0334db01 fffffa80`0a18f370 fffffa80`0a18f370 : nt!KiPageFault+0x16e
fffff880`0334d960 fffff880`01239972 : fffff800`0302f600 fffff880`0334db01 fffff880`0334d9e1 fffff8a0`04006670 : Ntfs!NtfsDeleteFcb+0x233
fffff880`0334d9c0 fffff880`012bf63c : fffffa80`0a18f370 fffffa80`0a11c180 fffff8a0`04006670 fffff8a0`04006a08 : Ntfs!NtfsTeardownFromLcb+0x1e2
fffff880`0334da50 fffff880`012410e2 : fffffa80`0a18f370 fffffa80`0a18f370 fffff8a0`04006670 00000000`00000000 : Ntfs!NtfsTeardownStructures+0xcc
fffff880`0334dad0 fffff880`012cf193 : fffffa80`0a18f370 fffff800`0302f600 fffff8a0`04006670 00000000`00000009 : Ntfs!NtfsDecrementCloseCounts+0xa2
fffff880`0334db10 fffff880`012be357 : fffffa80`0a18f370 fffff8a0`040067a0 fffff8a0`04006670 fffffa80`0a11c180 : Ntfs!NtfsCommonClose+0x353
fffff880`0334dbe0 fffff800`02e9ca21 : 00000000`00000000 fffff800`0302f600 fffffa80`09a4f601 00000000`00000002 : Ntfs!NtfsFspClose+0x15f
fffff880`0334dcb0 fffff800`0312fcce : 00000000`00000000 fffffa80`09a4f680 00000000`00000080 fffffa80`09a3c5f0 : nt!ExpWorkerThread+0x111
fffff880`0334dd40 fffff800`02e83fe6 : fffff880`03164180 fffffa80`09a4f680 fffff880`0316ef80 00000000`00000000 : nt!PspSystemThreadStartup+0x5a
fffff880`0334dd80 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KxStartSystemThread+0x16
STACK_COMMAND: kb
FOLLOWUP_IP:
Ntfs!NtfsDeleteFcb+233
fffff880`012bd043 f0834124ff lock add dword ptr [rcx+24h],0FFFFFFFFh
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: Ntfs!NtfsDeleteFcb+233
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Ntfs
IMAGE_NAME: Ntfs.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4ce792f9
FAILURE_BUCKET_ID: X64_0x50_Ntfs!NtfsDeleteFcb+233
BUCKET_ID: X64_0x50_Ntfs!NtfsDeleteFcb+233
Followup: MachineOwner
---------
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\DMP\040111-10389-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (3 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0xfffff800`02e4e000 PsLoadedModuleList = 0xfffff800`03093e90
Debug session time: Fri Apr 1 07:49:44.880 2011 (UTC - 4:00)
System Uptime: 0 days 11:02:00.300
Loading Kernel Symbols
...............................................................
................................................................
.................................
Loading User Symbols
Loading unloaded module list
............
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {ffffe8a0100f0960, 0, fffff80002ffab13, 7}
Could not read faulting driver name
Probably caused by : Pool_Corruption ( nt!ExDeferredFreePool+257 )
Followup: Pool_corruption
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: ffffe8a0100f0960, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff80002ffab13, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000007, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800030ff0e8
ffffe8a0100f0960
FAULTING_IP:
nt!ExDeferredFreePool+257
fffff800`02ffab13 4c3918 cmp qword ptr [rax],r11
MM_INTERNAL_CODE: 7
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: System
CURRENT_IRQL: 0
TRAP_FRAME: fffff880057c1840 -- (.trap 0xfffff880057c1840)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffffe8a0100f0960 rbx=0000000000000000 rcx=fffffa80099ca3c0
rdx=fffff8a0141d9000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002ffab13 rsp=fffff880057c19d0 rbp=0000000000000000
r8=fffff8a009127a20 r9=fffff8a0141d9100 r10=0000000000000001
r11=fffff8a0141d9110 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
nt!ExDeferredFreePool+0x257:
fffff800`02ffab13 4c3918 cmp qword ptr [rax],r11 ds:e170:ffffe8a0`100f0960=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002e78bf7 to fffff80002ece640
STACK_TEXT:
fffff880`057c16d8 fffff800`02e78bf7 : 00000000`00000050 ffffe8a0`100f0960 00000000`00000000 fffff880`057c1840 : nt!KeBugCheckEx
fffff880`057c16e0 fffff800`02ecc76e : 00000000`00000000 ffffe8a0`100f0960 00000000`00000700 00000000`00000003 : nt! ?? ::FNODOBFM::`string'+0x44811
fffff880`057c1840 fffff800`02ffab13 : fffff880`057c19e1 fffff8a0`041d8010 00000000`01010000 00000000`0c63e100 : nt!KiPageFault+0x16e
fffff880`057c19d0 fffff800`02ffa1a1 : fffff8a0`041d8010 fffff8a0`1555fb30 fffffa80`0c63e170 fffff880`012469f4 : nt!ExDeferredFreePool+0x257
fffff880`057c1a60 fffff880`012d627a : fffffa80`0a13b180 fffff800`0306b600 fffff8a0`6446744e 00000000`00000009 : nt!ExFreePoolWithTag+0x411
fffff880`057c1b10 fffff880`012c5357 : fffffa80`0b503890 fffff8a0`0f656480 fffff8a0`0f656350 fffffa80`0a13b180 : Ntfs!NtfsCommonClose+0x43a
fffff880`057c1be0 fffff800`02ed8a21 : 00000000`00000000 fffff800`031c4f00 fffff800`030cd101 00000000`00000003 : Ntfs!NtfsFspClose+0x15f
fffff880`057c1cb0 fffff800`0316bcce : 00000000`00000001 fffffa80`0ccbb040 00000000`00000080 fffffa80`09a3c6f0 : nt!ExpWorkerThread+0x111
fffff880`057c1d40 fffff800`02ebffe6 : fffff880`009e6180 fffffa80`0ccbb040 fffffa80`0b732b60 00000000`00000246 : nt!PspSystemThreadStartup+0x5a
fffff880`057c1d80 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KxStartSystemThread+0x16
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!ExDeferredFreePool+257
fffff800`02ffab13 4c3918 cmp qword ptr [rax],r11
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: nt!ExDeferredFreePool+257
FOLLOWUP_NAME: Pool_corruption
IMAGE_NAME: Pool_Corruption
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MODULE_NAME: Pool_Corruption
FAILURE_BUCKET_ID: X64_0x50_nt!ExDeferredFreePool+257
BUCKET_ID: X64_0x50_nt!ExDeferredFreePool+257
Followup: Pool_corruption
---------
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\DMP\041411-10140-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (3 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0xfffff800`02e1a000 PsLoadedModuleList = 0xfffff800`0305fe90
Debug session time: Thu Apr 14 00:30:01.941 2011 (UTC - 4:00)
System Uptime: 0 days 16:52:33.424
Loading Kernel Symbols
...............................................................
................................................................
............................
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {ffffe8a000231050, 0, fffff880012a8f17, 7}
Could not read faulting driver name
Probably caused by : Ntfs.sys ( Ntfs!NtfsOpenExistingPrefixFcb+67 )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: ffffe8a000231050, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff880012a8f17, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000007, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800030cb0e8
ffffe8a000231050
FAULTING_IP:
Ntfs!NtfsOpenExistingPrefixFcb+67
fffff880`012a8f17 488b4a50 mov rcx,qword ptr [rdx+50h]
MM_INTERNAL_CODE: 7
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: rundll32.exe
CURRENT_IRQL: 0
TRAP_FRAME: fffff88009087da0 -- (.trap 0xfffff88009087da0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffff8a00ddde010 rbx=0000000000000000 rcx=fffffa800b409e40
rdx=ffffe8a000231000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff880012a8f17 rsp=fffff88009087f30 rbp=0000000000000000
r8=fffff8a00ddde450 r9=0000000000000000 r10=fffffa800b409e40
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
Ntfs!NtfsOpenExistingPrefixFcb+0x67:
fffff880`012a8f17 488b4a50 mov rcx,qword ptr [rdx+50h] ds:81f0:ffffe8a0`00231050=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002e44bf7 to fffff80002e9a640
STACK_TEXT:
fffff880`09087c38 fffff800`02e44bf7 : 00000000`00000050 ffffe8a0`00231050 00000000`00000000 fffff880`09087da0 : nt!KeBugCheckEx
fffff880`09087c40 fffff800`02e9876e : 00000000`00000000 ffffe8a0`00231050 00000000`00000000 fffff8a0`0ddde450 : nt! ?? ::FNODOBFM::`string'+0x44811
fffff880`09087da0 fffff880`012a8f17 : 00000008`00000010 00000000`00000000 00000000`03060000 fffff880`09087f48 : nt!KiPageFault+0x16e
fffff880`09087f30 fffff880`012b9166 : fffffa80`0b409e40 fffffa80`0b4b9010 fffff8a0`0ddde450 fffffa80`0bdc5101 : Ntfs!NtfsOpenExistingPrefixFcb+0x67
fffff880`09088020 fffff880`012b6911 : fffffa80`0b409e40 fffffa80`0b4b9010 fffff880`090881f0 fffff880`09088240 : Ntfs!NtfsFindStartingNode+0x5e6
fffff880`090880f0 fffff880`0121fa3d : fffffa80`0b409e40 fffffa80`0b4b9010 fffff880`090884a0 fffff880`01134b00 : Ntfs!NtfsCommonCreate+0x3e1
fffff880`090882d0 fffff800`02ea7078 : fffff880`09088410 00000000`00000001 00000000`00000001 00000000`00000001 : Ntfs!NtfsCommonCreateCallout+0x1d
fffff880`09088300 fffff880`012201bf : fffff880`0121fa20 fffff880`0121f020 fffff880`09088400 fffff880`012c0f00 : nt!KeExpandKernelStackAndCalloutEx+0xd8
fffff880`090883e0 fffff880`012b999c : 00000000`00000000 00000000`00000000 fffff880`09088640 fffffa80`0b4b9010 : Ntfs!NtfsCommonCreateOnNewStack+0x4f
fffff880`09088440 fffff880`01125bcf : fffffa80`0a137030 fffffa80`0b4b9010 00000000`00000000 fffffa80`0a2b6de0 : Ntfs!NtfsFsdCreate+0x1ac
fffff880`090885f0 fffff880`011452b9 : fffffa80`0b4b9010 fffffa80`0a2b65a0 fffffa80`0b4b9000 fffffa80`0a2b6de0 : fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x24f
fffff880`09088680 fffff800`03198495 : 00000000`00000005 fffffa80`0bf92cc8 fffffa80`0c1ca010 00000000`00000000 : fltmgr!FltpCreate+0x2a9
fffff880`09088730 fffff800`03194d38 : fffffa80`0a13e5f0 fffff800`00000000 fffffa80`0bf92b10 00000000`00000001 : nt!IopParseDevice+0x5a5
fffff880`090888c0 fffff800`03195f56 : 00000000`00000000 fffffa80`0bf92b10 fffff700`01080000 fffffa80`09a55de0 : nt!ObpLookupObjectName+0x588
fffff880`090889b0 fffff800`0319785c : 00000000`0027bc34 00000000`00000000 00000000`00000001 fffff880`09088ca0 : nt!ObOpenObjectByName+0x306
fffff880`09088a80 fffff800`03183134 : 00000000`0027b5e0 fffff880`00100001 00000000`0027b5f8 00000000`0027b628 : nt!IopCreateFile+0x2bc
fffff880`09088b20 fffff800`02e998d3 : ffffffff`ffffffff 00000000`0027bc70 00000000`0027bbe0 00000980`00000004 : nt!NtOpenFile+0x58
fffff880`09088bb0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
STACK_COMMAND: kb
FOLLOWUP_IP:
Ntfs!NtfsOpenExistingPrefixFcb+67
fffff880`012a8f17 488b4a50 mov rcx,qword ptr [rdx+50h]
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: Ntfs!NtfsOpenExistingPrefixFcb+67
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Ntfs
IMAGE_NAME: Ntfs.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4ce792f9
FAILURE_BUCKET_ID: X64_0x50_Ntfs!NtfsOpenExistingPrefixFcb+67
BUCKET_ID: X64_0x50_Ntfs!NtfsOpenExistingPrefixFcb+67
Followup: MachineOwner
---------