[font=lucida console]**************************Mon Nov 19 08:24:32.512 2012 (UTC - 5:00)**************************
Loading Dump File [C:\Users\John\_jcgriff2_\dbug\__Kernel__\111912-6006-01.dmp]
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Built by: [B]7601[/B].17944.amd64fre.win7sp1_gdr.120830-0333
System Uptime:[B]0 days 0:53:59.683[/B]
BugCheck Code: [B]BugCheck 4E, {99, 19e09b, 2, 19d79a}[/B]
Probably caused by :[B]memory_corruption ( nt!MiBadShareCount+4c )[/B]
BugCheck Info: [B]PFN_LIST_CORRUPT (4e)[/B]
Arguments:
Arg1: 0000000000000099, A PTE or PFN is corrupt
Arg2: 000000000019e09b, page frame number
Arg3: 0000000000000002, current page state
Arg4: 000000000019d79a, 0
BUGCHECK_STR: 0x4E_99
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
PROCESS_NAME: [B]chrome.exe[/B]
FAILURE_BUCKET_ID: [B]X64_0x4E_99_nt!MiBadShareCount+4c[/B]
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
**************************Sun Nov 18 21:37:26.047 2012 (UTC - 5:00)**************************
Loading Dump File [C:\Users\John\_jcgriff2_\dbug\__Kernel__\111912-5725-01.dmp]
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Built by: [B]7601[/B].17944.amd64fre.win7sp1_gdr.120830-0333
System Uptime:[B]0 days 0:54:21.233[/B]
BugCheck Code: [B]BugCheck 1A, {41790, fffffa8003993ea0, ffff, 0}[/B]
Probably caused by :[B]ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+35054 )[/B]
BugCheck Info: [B]MEMORY_MANAGEMENT (1a)[/B]
Arguments:
Arg1: 0000000000041790, A page table page has been corrupted. On a 64 bit OS, parameter 2
contains the address of the PFN for the corrupted page table page.
On a 32 bit OS, parameter 2 contains a pointer to the number of used
PTEs, and parameter 3 contains the number of used PTEs.
Arg2: fffffa8003993ea0
Arg3: 000000000000ffff
Arg4: 0000000000000000
BUGCHECK_STR: 0x1a_41790
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
PROCESS_NAME: [B]wermgr.exe[/B]
FAILURE_BUCKET_ID: [B]X64_0x1a_41790_nt!_??_::FNODOBFM::_string_+35054[/B]
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
**************************Sat Nov 17 20:04:06.590 2012 (UTC - 5:00)**************************
Loading Dump File [C:\Users\John\_jcgriff2_\dbug\__Kernel__\111812-5600-01.dmp]
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Built by: [B]7601[/B].17944.amd64fre.win7sp1_gdr.120830-0333
System Uptime:[B]0 days 2:48:18.211[/B]
BugCheck Code: [B]BugCheck 1A, {41790, fffffa8003993e40, ffff, 0}[/B]
Probably caused by :[B]ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+35054 )[/B]
BugCheck Info: [B]MEMORY_MANAGEMENT (1a)[/B]
Arguments:
Arg1: 0000000000041790, A page table page has been corrupted. On a 64 bit OS, parameter 2
contains the address of the PFN for the corrupted page table page.
On a 32 bit OS, parameter 2 contains a pointer to the number of used
PTEs, and parameter 3 contains the number of used PTEs.
Arg2: fffffa8003993e40
Arg3: 000000000000ffff
Arg4: 0000000000000000
BUGCHECK_STR: 0x1a_41790
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
PROCESS_NAME: [B]conhost.exe[/B]
FAILURE_BUCKET_ID: [B]X64_0x1a_41790_nt!_??_::FNODOBFM::_string_+35054[/B]
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
**************************Sat Nov 17 17:16:07.365 2012 (UTC - 5:00)**************************
Loading Dump File [C:\Users\John\_jcgriff2_\dbug\__Kernel__\111712-5522-01.dmp]
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Built by: [B]7601[/B].17944.amd64fre.win7sp1_gdr.120830-0333
System Uptime:[B]0 days 3:54:16.552[/B]
BugCheck Code: [B]BugCheck 3B, {c0000005, fffff80002cae383, fffff880098c58e0, 0}[/B]
Probably caused by :[B]memory_corruption ( nt!MmCopyToCachedPage+223 )[/B]
BugCheck Info: [B]SYSTEM_SERVICE_EXCEPTION (3b)[/B]
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff80002cae383, Address of the instruction which caused the bugcheck
Arg3: fffff880098c58e0, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: [B]UnRAR.exe[/B]
FAILURE_BUCKET_ID: [B]X64_0x3B_nt!MmCopyToCachedPage+223[/B]
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
**************************Sat Nov 17 08:22:37.542 2012 (UTC - 5:00)**************************
Loading Dump File [C:\Users\John\_jcgriff2_\dbug\__Kernel__\111712-6661-01.dmp]
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Built by: [B]7601[/B].17944.amd64fre.win7sp1_gdr.120830-0333
System Uptime:[B]0 days 0:32:02.728[/B]
BugCheck Code: [B]BugCheck 4E, {2, 43adf, 21f5ff, 1}[/B]
Probably caused by :[B]memory_corruption ( nt!MiUnlinkPageFromLockedList+8d )[/B]
BugCheck Info: [B]PFN_LIST_CORRUPT (4e)[/B]
Arguments:
Arg1: 0000000000000002, A list entry was corrupt
Arg2: 0000000000043adf, entry in list being removed
Arg3: 000000000021f5ff, highest physical page number
Arg4: 0000000000000001, reference count of entry being removed
BUGCHECK_STR: 0x4E_2
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
PROCESS_NAME: [B]MsMpEng.exe[/B]
FAILURE_BUCKET_ID: [B]X64_0x4E_2_nt!MiUnlinkPageFromLockedList+8d[/B]
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
**************************Fri Nov 16 17:46:14.633 2012 (UTC - 5:00)**************************
Loading Dump File [C:\Users\John\_jcgriff2_\dbug\__Kernel__\111612-5522-01.dmp]
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Built by: [B]7601[/B].17944.amd64fre.win7sp1_gdr.120830-0333
System Uptime:[B]0 days 0:15:46.819[/B]
BugCheck Code: [B]BugCheck 50, {fffff880e88a9f88, 0, fffff80002e01a9b, 5}[/B]
*** WARNING: Unable to verify timestamp for win32k.sys
*** ERROR: Module load completed but symbols could not be loaded for win32k.sys
Probably caused by :[B]Pool_Corruption ( nt!ExDeferredFreePool+1df )[/B]
BugCheck Info: [B]PAGE_FAULT_IN_NONPAGED_AREA (50)[/B]
Arguments:
Arg1: fffff880e88a9f88, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff80002e01a9b, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000005, (reserved)
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: [B]TubeDigger.exe[/B]
FAILURE_BUCKET_ID: [B]X64_0x50_nt!ExDeferredFreePool+1df[/B]
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
**************************Fri Nov 16 14:17:56.916 2012 (UTC - 5:00)**************************
Loading Dump File [C:\Users\John\_jcgriff2_\dbug\__Kernel__\111612-6770-01.dmp]
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Built by: [B]7601[/B].17944.amd64fre.win7sp1_gdr.120830-0333
System Uptime:[B]0 days 1:20:44.102[/B]
BugCheck Code: [B]BugCheck 1A, {41790, fffffa8003993e70, ffff, 0}[/B]
Probably caused by :[B]ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+35054 )[/B]
BugCheck Info: [B]MEMORY_MANAGEMENT (1a)[/B]
Arguments:
Arg1: 0000000000041790, A page table page has been corrupted. On a 64 bit OS, parameter 2
contains the address of the PFN for the corrupted page table page.
On a 32 bit OS, parameter 2 contains a pointer to the number of used
PTEs, and parameter 3 contains the number of used PTEs.
Arg2: fffffa8003993e70
Arg3: 000000000000ffff
Arg4: 0000000000000000
BUGCHECK_STR: 0x1a_41790
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
PROCESS_NAME: [B]wermgr.exe[/B]
FAILURE_BUCKET_ID: [B]X64_0x1a_41790_nt!_??_::FNODOBFM::_string_+35054[/B]
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
**************************Fri Nov 16 08:05:07.358 2012 (UTC - 5:00)**************************
Loading Dump File [C:\Users\John\_jcgriff2_\dbug\__Kernel__\111612-5943-01.dmp]
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Built by: [B]7601[/B].17944.amd64fre.win7sp1_gdr.120830-0333
System Uptime:[B]0 days 0:30:56.544[/B]
BugCheck Code: [B]BugCheck 1A, {41790, fffffa8003993ea0, ffff, 0}[/B]
Probably caused by :[B]ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+35054 )[/B]
BugCheck Info: [B]MEMORY_MANAGEMENT (1a)[/B]
Arguments:
Arg1: 0000000000041790, A page table page has been corrupted. On a 64 bit OS, parameter 2
contains the address of the PFN for the corrupted page table page.
On a 32 bit OS, parameter 2 contains a pointer to the number of used
PTEs, and parameter 3 contains the number of used PTEs.
Arg2: fffffa8003993ea0
Arg3: 000000000000ffff
Arg4: 0000000000000000
BUGCHECK_STR: 0x1a_41790
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
PROCESS_NAME: [B]rundll32.exe[/B]
FAILURE_BUCKET_ID: [B]X64_0x1a_41790_nt!_??_::FNODOBFM::_string_+35054[/B]
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
**************************Fri Nov 16 07:25:46.752 2012 (UTC - 5:00)**************************
Loading Dump File [C:\Users\John\_jcgriff2_\dbug\__Kernel__\111612-6208-01.dmp]
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Built by: [B]7601[/B].17944.amd64fre.win7sp1_gdr.120830-0333
System Uptime:[B]0 days 0:05:15.938[/B]
BugCheck Code: [B]BugCheck 1E, {ffffffffc0000005, fffff80002c91284, 0, ffffffffffffffff}[/B]
*** WARNING: Unable to verify timestamp for win32k.sys
*** ERROR: Module load completed but symbols could not be loaded for win32k.sys
Probably caused by :[B]ntkrnlmp.exe ( nt!SwapContext_PatchXRstor+0 )[/B]
BugCheck Info: [B]KMODE_EXCEPTION_NOT_HANDLED (1e)[/B]
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff80002c91284, The address that the exception occurred at
Arg3: 0000000000000000, Parameter 0 of the exception
Arg4: ffffffffffffffff, Parameter 1 of the exception
BUGCHECK_STR: 0x1E_c0000005_R
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
PROCESS_NAME: [B]msdt.exe[/B]
FAILURE_BUCKET_ID: [B]X64_0x1E_c0000005_R_nt!SwapContext_PatchXRstor+0[/B]
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
**************************Thu Nov 15 07:45:12.524 2012 (UTC - 5:00)**************************
Loading Dump File [C:\Users\John\_jcgriff2_\dbug\__Kernel__\111512-6224-01.dmp]
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Built by: [B]7601[/B].17944.amd64fre.win7sp1_gdr.120830-0333
System Uptime:[B]0 days 0:08:00.710[/B]
BugCheck Code: [B]BugCheck 50, {fffff8a0e0379cc4, 0, fffff80002fa993e, 5}[/B]
Probably caused by :[B]ntkrnlmp.exe ( nt!CmpKcbCacheLookup+1de )[/B]
BugCheck Info: [B]PAGE_FAULT_IN_NONPAGED_AREA (50)[/B]
Arguments:
Arg1: fffff8a0e0379cc4, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff80002fa993e, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000005, (reserved)
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: [B]checksur.exe[/B]
FAILURE_BUCKET_ID: [B]X64_0x50_nt!CmpKcbCacheLookup+1de[/B]
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
**************************Tue Nov 13 18:12:10.328 2012 (UTC - 5:00)**************************
Loading Dump File [C:\Users\John\_jcgriff2_\dbug\__Kernel__\111312-6240-01.dmp]
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Built by: [B]7601[/B].17944.amd64fre.win7sp1_gdr.120830-0333
System Uptime:[B]0 days 0:00:49.514[/B]
BugCheck Code: [B]BugCheck 50, {fffff8a08f580ab4, 1, fffff8800125cd5f, 5}[/B]
Probably caused by :[B]Ntfs.sys ( Ntfs!NtfsRemoveClose+a3 )[/B]
BugCheck Info: [B]PAGE_FAULT_IN_NONPAGED_AREA (50)[/B]
Arguments:
Arg1: fffff8a08f580ab4, memory referenced.
Arg2: 0000000000000001, value 0 = read operation, 1 = write operation.
Arg3: fffff8800125cd5f, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000005, (reserved)
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: [B]System[/B]
FAILURE_BUCKET_ID: [B]X64_0x50_Ntfs!NtfsRemoveClose+a3[/B]
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
**************************Tue Nov 13 16:46:43.039 2012 (UTC - 5:00)**************************
Loading Dump File [C:\Users\John\_jcgriff2_\dbug\__Kernel__\111312-6146-01.dmp]
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Built by: [B]7601[/B].17944.amd64fre.win7sp1_gdr.120830-0333
System Uptime:[B]0 days 0:04:09.836[/B]
BugCheck Code: [B]BugCheck 19, {3, fffffa8006674c80, fffffa80a8674c80, fffffa80a0674c80}[/B]
*** WARNING: Unable to verify timestamp for MpFilter.sys
*** ERROR: Module load completed but symbols could not be loaded for MpFilter.sys
Probably caused by :[B]Pool_Corruption ( nt!ExDeferredFreePool+a53 )[/B]
BugCheck Info: [B]BAD_POOL_HEADER (19)[/B]
Arguments:
Arg1: 0000000000000003, the pool freelist is corrupt.
Arg2: fffffa8006674c80, the pool entry being checked.
Arg3: fffffa80a8674c80, the read back flink freelist value (should be the same as 2).
Arg4: fffffa80a0674c80, the read back blink freelist value (should be the same as 2).
BUGCHECK_STR: 0x19_3
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
PROCESS_NAME: [B]SearchProtocol[/B]
FAILURE_BUCKET_ID: [B]X64_0x19_3_nt!ExDeferredFreePool+a53[/B]
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
**************************Tue Nov 13 14:02:25.307 2012 (UTC - 5:00)**************************
Loading Dump File [C:\Users\John\_jcgriff2_\dbug\__Kernel__\111312-6364-01.dmp]
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Built by: [B]7601[/B].17944.amd64fre.win7sp1_gdr.120830-0333
System Uptime:[B]0 days 0:24:37.494[/B]
BugCheck Code: [B]BugCheck 19, {3, fffffa8006676180, fffffa8027676180, fffffa8006676180}[/B]
Probably caused by :[B]Pool_Corruption ( nt!ExDeferredFreePool+a53 )[/B]
BugCheck Info: [B]BAD_POOL_HEADER (19)[/B]
Arguments:
Arg1: 0000000000000003, the pool freelist is corrupt.
Arg2: fffffa8006676180, the pool entry being checked.
Arg3: fffffa8027676180, the read back flink freelist value (should be the same as 2).
Arg4: fffffa8006676180, the read back blink freelist value (should be the same as 2).
BUGCHECK_STR: 0x19_3
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
PROCESS_NAME: [B]lsass.exe[/B]
FAILURE_BUCKET_ID: [B]X64_0x19_3_nt!ExDeferredFreePool+a53[/B]
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
[/font]