.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1A, {403, fffff68000003ea8, bea0000024713867, fffff68000003ea0}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+31ef2 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000000403, The subtype of the bugcheck.
Arg2: fffff68000003ea8
Arg3: bea0000024713867
Arg4: fffff68000003ea0
Debugging Details:
------------------
BUGCHECK_STR: 0x1a_403
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: [COLOR=#b22222][U][B]avgdumpx.exe[/B][/U][/COLOR]
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff80002b466c8 to fffff80002ad4740
STACK_TEXT:
fffff880`084ba7b8 fffff800`02b466c8 : 00000000`0000001a 00000000`00000403 fffff680`00003ea8 bea00000`24713867 : nt!KeBugCheckEx
fffff880`084ba7c0 fffff800`02b05381 : 00000000`00000000 fffff680`00003ff8 fffffa80`0699f060 fffffa80`0699f060 : nt! ?? ::FNODOBFM::`string'+0x31ef2
fffff880`084ba970 fffff800`02b160da : 00000000`00000000 00000000`00840fff fffffa80`00000000 fffffa80`0699f060 : nt!MiDeleteVirtualAddresses+0x408
fffff880`084bab30 fffff800`02ad3993 : ffffffff`ffffffff 00000000`0016dbe0 00000000`0016dbd8 00000000`00008000 : nt!NtFreeVirtualMemory+0x5ca
fffff880`084bac20 00000000`7798f89a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0016dba8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7798f89a
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+31ef2
fffff800`02b466c8 cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+31ef2
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4cc791bd
FAILURE_BUCKET_ID: X64_0x1a_403_nt!_??_::FNODOBFM::_string_+31ef2
BUCKET_ID: X64_0x1a_403_nt!_??_::FNODOBFM::_string_+31ef2
Followup: MachineOwner