Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\a\Minidump\D M P\120510-16536-02.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is: 
Windows 7 Kernel Version 7600 MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`02867000 PsLoadedModuleList = 0xfffff800`02aa4e50
Debug session time: Sun Dec  5 14:41:38.786 2010 (UTC - 5:00)
System Uptime: 0 days 0:06:52.097
Loading Kernel Symbols
...............................................................
................................................................
............
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1E, {ffffffffc000001d, fffff80002be87b9, 0, fffff8800a154700}
Probably caused by : memory_corruption
Followup: memory_corruption
---------
2: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************
KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common bugcheck.  Usually the exception address pinpoints
the driver/function that caused the problem.  Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc000001d, The exception code that was not handled
Arg2: fffff80002be87b9, The address that the exception occurred at
Arg3: 0000000000000000, Parameter 0 of the exception
Arg4: fffff8800a154700, Parameter 1 of the exception
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc000001d - {
FAULTING_IP: 
nt!RtlpInheritAcl2+89
fffff800`02be87b9 c4              ???
EXCEPTION_PARAMETER1:  0000000000000000
EXCEPTION_PARAMETER2:  fffff8800a154700
ERROR_CODE: (NTSTATUS) 0xc000001d - {
BUGCHECK_STR:  0x1E_c000001d
CUSTOMER_CRASH_COUNT:  2
DEFAULT_BUCKET_ID:  CODE_CORRUPTION
PROCESS_NAME:  SearchFilterHo
CURRENT_IRQL:  0
EXCEPTION_RECORD:  fffff8800a154268 -- (.exr 0xfffff8800a154268)
ExceptionAddress: fffff80002be87b9 (nt!RtlpInheritAcl2+0x0000000000000089)
   ExceptionCode: c000001d (Illegal instruction)
  ExceptionFlags: 00000000
NumberParameters: 0
TRAP_FRAME:  fffff8800a154310 -- (.trap 0xfffff8800a154310)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=00000000000000c8 rbx=0000000000000000 rcx=000000000000fffc
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002be87b9 rsp=fffff8800a1544a0 rbp=0000000000000000
 r8=0000000000000002  r9=fffff80002867000 r10=fffff8800a1547f0
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei pl nz na pe nc
nt!RtlpInheritAcl2+0x89:
fffff800`02be87b9 c4              ???
Resetting default scope
LAST_CONTROL_TRANSFER:  from fffff80002911a39 to fffff800028d7740
FAILED_INSTRUCTION_ADDRESS: 
nt!RtlpInheritAcl2+89
fffff800`02be87b9 c4              ???
STACK_TEXT:  
fffff880`0a153a98 fffff800`02911a39 : 00000000`0000001e ffffffff`c000001d fffff800`02be87b9 00000000`00000000 : nt!KeBugCheckEx
fffff880`0a153aa0 fffff800`028d6d82 : fffff880`0a154268 00000000`00000000 fffff880`0a154310 00000000`00000000 : nt!KiDispatchException+0x1b9
fffff880`0a154130 fffff800`028d4edf : fffff880`0a154310 fffff700`01080000 fffffa80`04142900 fffff800`00000000 : nt!KiExceptionDispatch+0xc2
fffff880`0a154310 fffff800`02be87b9 : fffff6fb`40000048 fffffa80`04142630 00000000`00000000 00000000`00000801 : nt!KiInvalidOpcodeFault+0x11f
fffff880`0a1544a0 fffff800`02be81b1 : 00000000`00000000 fffff880`0a154768 00000000`00000000 00000000`00000700 : nt!RtlpInheritAcl2+0x89
fffff880`0a154560 fffff800`02be7151 : 00000000`00000003 00000000`00000000 00000000`000000c8 fffff8a0`03172a7c : nt!RtlpInheritAcl+0x17d
fffff880`0a154620 fffff800`02b9e8b2 : fffff880`0a154d80 00000000`00000000 fffffa80`03c6ca30 00000000`00000000 : nt!RtlpNewSecurityObject+0x8c1
fffff880`0a1548b0 fffff800`02bc834e : 00000000`00000000 fffffa80`03f29720 00000000`00000000 00000000`00000000 : nt!ObpAssignSecurity+0x82
fffff880`0a154920 fffff800`02ba1b30 : ffffffff`ffffffff fffffa80`04142630 fffffa80`04142630 00000000`00000000 : nt!ObInsertObjectEx+0x20e
fffff880`0a154b60 fffff800`02ba5d86 : fffffa80`03c9a6e0 fffffa80`04142630 fffff880`0a155000 fffff880`0a154d40 : nt!PspInsertThread+0x3f0
fffff880`0a154ce0 fffff800`02ba608b : 00000000`00000000 00000000`00000000 00000000`00000001 fffff880`0a155510 : nt!PspCreateThread+0x246
fffff880`0a154f60 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!NtCreateThreadEx+0x243
STACK_COMMAND:  kb
CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
    fffff80002be87b9 - nt!RtlpInheritAcl2+89
	[ 44:c4 ]
1 error : !nt (fffff80002be87b9)
MODULE_NAME: memory_corruption
IMAGE_NAME:  memory_corruption
FOLLOWUP_NAME:  memory_corruption
DEBUG_FLR_IMAGE_TIMESTAMP:  0
MEMORY_CORRUPTOR:  ONE_BIT
FAILURE_BUCKET_ID:  X64_MEMORY_CORRUPTION_ONE_BIT
BUCKET_ID:  X64_MEMORY_CORRUPTION_ONE_BIT
Followup: memory_corruption
---------
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\a\Minidump\D M P\120610-17706-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is: 
Windows 7 Kernel Version 7600 MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`02a5f000 PsLoadedModuleList = 0xfffff800`02c9ce50
Debug session time: Mon Dec  6 21:46:40.020 2010 (UTC - 5:00)
System Uptime: 0 days 0:00:18.316
Loading Kernel Symbols
...............................................................
................................................................
.....
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {fffff8a0199fc6b0, 1, fffff8800103eb37, 2}
Could not read faulting driver name
Probably caused by : memory_corruption
Followup: memory_corruption
---------
6: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced.  This cannot be protected by try-except,
it must be protected by a Probe.  Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: fffff8a0199fc6b0, memory referenced.
Arg2: 0000000000000001, value 0 = read operation, 1 = write operation.
Arg3: fffff8800103eb37, If non-zero, the instruction address which referenced the bad memory
	address.
Arg4: 0000000000000002, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff80002d070e0
 fffff8a0199fc6b0 
FAULTING_IP: 
fltmgr!TreeInsert+7b
fffff880`0103eb37 4c899248894a18  mov     qword ptr [rdx+184A8948h],r10
MM_INTERNAL_CODE:  2
CUSTOMER_CRASH_COUNT:  1
DEFAULT_BUCKET_ID:  CODE_CORRUPTION
BUGCHECK_STR:  0x50
PROCESS_NAME:  services.exe
CURRENT_IRQL:  1
TRAP_FRAME:  fffff8800287fb10 -- (.trap 0xfffff8800287fb10)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffff8a001553d68 rbx=0000000000000000 rcx=fffffa8005ec0898
rdx=fffff8a001553d68 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8800103eb37 rsp=fffff8800287fca8 rbp=fffff8a001553da0
 r8=fffffa8005e37320  r9=fffffa8006123010 r10=fffff8a000efced8
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei pl nz na po nc
fltmgr!TreeInsert+0x7b:
fffff880`0103eb37 4c899248894a18  mov     qword ptr [rdx+184A8948h],r10 ds:cde0:fffff8a0`199fc6b0=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER:  from fffff80002b4e8f2 to fffff80002acf740
STACK_TEXT:  
fffff880`0287f9a8 fffff800`02b4e8f2 : 00000000`00000050 fffff8a0`199fc6b0 00000000`00000001 fffff880`0287fb10 : nt!KeBugCheckEx
fffff880`0287f9b0 fffff800`02acd82e : 00000000`00000001 00000000`00000000 fffff880`00000200 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x40ec0
fffff880`0287fb10 fffff880`0103eb37 : fffff880`0103e65f 00000000`00000000 fffffa80`05ec0820 fffffa80`0567cde0 : nt!KiPageFault+0x16e
fffff880`0287fca8 fffff880`0103e65f : 00000000`00000000 fffffa80`05ec0820 fffffa80`0567cde0 fffff880`02881000 : fltmgr!TreeInsert+0x7b
fffff880`0287fcb0 fffff880`0105b5ef : 00000000`00008000 fffffa80`05ec0820 fffffa80`06123010 fffff880`0287fee8 : fltmgr!FltpGetFileNameInformation+0x37f
fffff880`0287fd30 fffff880`0164eada : fffffa80`0567cde0 00000000`00000000 00000000`00000594 fffffa80`062abd40 : fltmgr!FltGetFileNameInformationUnsafe+0x7f
fffff880`0287fda0 fffff880`0164edb3 : 00000000`00000000 fffff880`02880ca0 00000000`00000594 00000000`00000000 : tcpip!WfpAleCaptureImageFileName+0x3a
fffff880`0287fdf0 fffff880`0164f02e : fffffa80`05e37320 00000000`00000000 00000000`00000000 00000000`00000000 : tcpip!WfpCreateProcessNotifyRoutine+0x63
fffff880`0287fed0 fffff800`02d99e8f : fffffa80`05e37320 fffff880`02880ca0 fffffa80`05e37320 00000000`00000002 : tcpip!CreateProcessNotifyRoutineEx+0xe
fffff880`0287ff00 fffff800`02d7b277 : fffffa80`05e6d060 fffffa80`05e3d060 fffff880`028801b0 fffff880`028800ec : nt!PspInsertThread+0x74f
fffff880`02880080 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!NtCreateUserProcess+0x732
STACK_COMMAND:  kb
CHKIMG_EXTENSION: !chkimg -lo 50 -d !fltmgr
    fffff8800103eb39 - fltmgr!TreeInsert+7d
	[ 12:92 ]
1 error : !fltmgr (fffff8800103eb39)
MODULE_NAME: memory_corruption
IMAGE_NAME:  memory_corruption
FOLLOWUP_NAME:  memory_corruption
DEBUG_FLR_IMAGE_TIMESTAMP:  0
MEMORY_CORRUPTOR:  ONE_BIT
FAILURE_BUCKET_ID:  X64_MEMORY_CORRUPTION_ONE_BIT
BUCKET_ID:  X64_MEMORY_CORRUPTION_ONE_BIT
Followup: memory_corruption
---------
6: kd> lmtn
start             end                 module name
fffff880`041b5000 fffff880`041f3000   1394ohci 1394ohci.sys Mon Jul 13 20:07:12 2009 (4A5BCC30)
fffff880`00f26000 fffff880`00f7d000   ACPI     ACPI.sys     Mon Jul 13 19:19:34 2009 (4A5BC106)
fffff880`02cfd000 fffff880`02d87000   afd      afd.sys      Mon Jul 13 19:21:40 2009 (4A5BC184)
fffff880`04fde000 fffff880`04ff4000   AgileVpn AgileVpn.sys Mon Jul 13 20:10:24 2009 (4A5BCCF0)
fffff880`00dd2000 fffff880`00ddd000   amdxata  amdxata.sys  Tue May 19 13:56:59 2009 (4A12F2EB)
fffff880`00d9f000 fffff880`00da8000   atapi    atapi.sys    Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`00da8000 fffff880`00dd2000   ataport  ataport.SYS  Mon Jul 13 19:19:52 2009 (4A5BC118)
fffff880`051c1000 fffff880`051e1000   AtihdW76 AtihdW76.sys Mon Aug 16 06:41:02 2010 (4C6915BE)
fffff880`04808000 fffff880`04fde000   atikmdag atikmdag.sys Tue Sep 28 21:41:26 2010 (4CA29946)
fffff880`0416a000 fffff880`041b5000   atikmpag atikmpag.sys Tue Sep 28 21:14:49 2010 (4CA29309)
fffff880`01951000 fffff880`01958000   Beep     Beep.SYS     Mon Jul 13 20:00:13 2009 (4A5BCA8D)
fffff880`0411d000 fffff880`0412e000   blbdrive blbdrive.sys Mon Jul 13 19:35:59 2009 (4A5BC4DF)
fffff880`02b89000 fffff880`02ba7000   bowser   bowser.sys   Mon Jul 13 19:23:50 2009 (4A5BC206)
fffff960`00740000 fffff960`00767000   cdd      cdd.dll      unavailable (00000000)
fffff880`0191e000 fffff880`01948000   cdrom    cdrom.sys    Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`00cc5000 fffff880`00d85000   CI       CI.dll       Mon Jul 13 21:32:13 2009 (4A5BE01D)
fffff880`018b8000 fffff880`018e8000   CLASSPNP CLASSPNP.SYS Mon Jul 13 19:19:58 2009 (4A5BC11E)
fffff880`00c67000 fffff880`00cc5000   CLFS     CLFS.SYS     Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`010f6000 fffff880`01169000   cng      cng.sys      Mon Jul 13 19:49:40 2009 (4A5BC814)
fffff880`04270000 fffff880`04280000   CompositeBus CompositeBus.sys Mon Jul 13 20:00:33 2009 (4A5BCAA1)
fffff880`050cd000 fffff880`050db000   crashdmp crashdmp.sys Mon Jul 13 20:01:01 2009 (4A5BCABD)
fffff880`0407c000 fffff880`040ff000   csc      csc.sys      Mon Jul 13 19:24:26 2009 (4A5BC22A)
fffff880`040ff000 fffff880`0411d000   dfsc     dfsc.sys     Mon Jul 13 19:23:44 2009 (4A5BC200)
fffff880`02ca6000 fffff880`02cb5000   discache discache.sys Mon Jul 13 19:37:18 2009 (4A5BC52E)
fffff880`018a2000 fffff880`018b8000   disk     disk.sys     Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`0503d000 fffff880`0505f000   drmk     drmk.sys     Mon Jul 13 21:01:25 2009 (4A5BD8E5)
fffff880`050e7000 fffff880`050f0000   dump_atapi dump_atapi.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`050db000 fffff880`050e7000   dump_dumpata dump_dumpata.sys Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`051e1000 fffff880`051f4000   dump_dumpfve dump_dumpfve.sys Mon Jul 13 19:21:51 2009 (4A5BC18F)
fffff880`050c1000 fffff880`050cd000   Dxapi    Dxapi.sys    Mon Jul 13 19:38:28 2009 (4A5BC574)
fffff880`0428e000 fffff880`04382000   dxgkrnl  dxgkrnl.sys  Thu Oct 01 21:00:14 2009 (4AC5509E)
fffff880`04382000 fffff880`043c8000   dxgmms1  dxgmms1.sys  Mon Jul 13 19:38:32 2009 (4A5BC578)
fffff880`01084000 fffff880`01098000   fileinfo fileinfo.sys Mon Jul 13 19:34:25 2009 (4A5BC481)
fffff880`01038000 fffff880`01084000   fltmgr   fltmgr.sys   Mon Jul 13 19:19:59 2009 (4A5BC11F)
fffff880`01211000 fffff880`0121b000   Fs_Rec   Fs_Rec.sys   Mon Jul 13 19:19:45 2009 (4A5BC111)
fffff880`01868000 fffff880`018a2000   fvevol   fvevol.sys   Fri Sep 25 22:34:26 2009 (4ABD7DB2)
fffff880`0148b000 fffff880`014d5000   fwpkclnt fwpkclnt.sys Mon Jul 13 19:21:08 2009 (4A5BC164)
fffff800`02a16000 fffff800`02a5f000   hal      hal.dll      Mon Jul 13 21:27:36 2009 (4A5BDF08)
fffff880`043c8000 fffff880`043ec000   HDAudBus HDAudBus.sys Mon Jul 13 20:06:13 2009 (4A5BCBF5)
fffff880`05065000 fffff880`050c1000   HdAudio  HdAudio.sys  Mon Jul 13 20:06:59 2009 (4A5BCC23)
fffff880`0101a000 fffff880`01033000   HIDCLASS HIDCLASS.SYS Mon Jul 13 20:06:21 2009 (4A5BCBFD)
fffff880`051f4000 fffff880`051fc080   HIDPARSE HIDPARSE.SYS Mon Jul 13 20:06:17 2009 (4A5BCBF9)
fffff880`01224000 fffff880`01232000   hidusb   hidusb.sys   Mon Jul 13 20:06:22 2009 (4A5BCBFE)
fffff880`02ac1000 fffff880`02b89000   HTTP     HTTP.sys     Mon Jul 13 19:22:16 2009 (4A5BC1A8)
fffff880`0121b000 fffff880`01224000   hwpolicy hwpolicy.sys Mon Jul 13 19:19:22 2009 (4A5BC0FA)
fffff880`04154000 fffff880`0416a000   intelppm intelppm.sys Mon Jul 13 19:19:25 2009 (4A5BC0FD)
fffff880`04063000 fffff880`04072000   kbdclass kbdclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff880`02a65000 fffff880`02a73000   kbdhid   kbdhid.sys   Mon Jul 13 20:00:20 2009 (4A5BCA94)
fffff800`00bbf000 fffff800`00bc9000   kdcom    kdcom.dll    Mon Jul 13 21:31:07 2009 (4A5BDFDB)
fffff880`050fd000 fffff880`05140000   ks       ks.sys       Mon Jul 13 20:00:31 2009 (4A5BCA9F)
fffff880`013da000 fffff880`013f4000   ksecdd   ksecdd.sys   Mon Jul 13 19:20:54 2009 (4A5BC156)
fffff880`01460000 fffff880`0148b000   ksecpkg  ksecpkg.sys  Fri Dec 11 01:03:32 2009 (4B21E0B4)
fffff880`0505f000 fffff880`05064200   ksthunk  ksthunk.sys  Mon Jul 13 20:00:19 2009 (4A5BCA93)
fffff880`02a51000 fffff880`02a65000   LHidFilt LHidFilt.Sys Tue Nov 10 06:46:17 2009 (4AF95289)
fffff880`02a94000 fffff880`02aa9000   lltdio   lltdio.sys   Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`02a80000 fffff880`02a94000   LMouFilt LMouFilt.Sys Tue Nov 10 06:46:23 2009 (4AF9528F)
fffff880`018f6000 fffff880`01919000   luafv    luafv.sys    Mon Jul 13 19:26:13 2009 (4A5BC295)
fffff880`00c0f000 fffff880`00c53000   mcupdate_GenuineIntel mcupdate_GenuineIntel.dll Mon Jul 13 21:29:10 2009 (4A5BDF66)
fffff880`018e8000 fffff880`018f6000   monitor  monitor.sys  Mon Jul 13 19:38:52 2009 (4A5BC58C)
fffff880`01850000 fffff880`0185f000   mouclass mouclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff880`02a73000 fffff880`02a80000   mouhid   mouhid.sys   Mon Jul 13 20:00:20 2009 (4A5BCA94)
fffff880`00d85000 fffff880`00d9f000   mountmgr mountmgr.sys Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`02ba7000 fffff880`02bbf000   mpsdrv   mpsdrv.sys   Mon Jul 13 20:08:25 2009 (4A5BCC79)
fffff880`02bbf000 fffff880`02bec000   mrxsmb   mrxsmb.sys   Sat Feb 27 02:52:19 2010 (4B88CF33)
fffff880`02a00000 fffff880`02a4e000   mrxsmb10 mrxsmb10.sys Sat Feb 27 02:52:28 2010 (4B88CF3C)
fffff880`06c09000 fffff880`06c2c000   mrxsmb20 mrxsmb20.sys Sat Feb 27 02:52:26 2010 (4B88CF3A)
fffff880`019b6000 fffff880`019c1000   Msfs     Msfs.SYS     Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`00f86000 fffff880`00f90000   msisadrv msisadrv.sys Mon Jul 13 19:19:26 2009 (4A5BC0FE)
fffff880`01098000 fffff880`010f6000   msrpc    msrpc.sys    Mon Jul 13 19:21:32 2009 (4A5BC17C)
fffff880`02c9b000 fffff880`02ca6000   mssmbios mssmbios.sys Mon Jul 13 19:31:10 2009 (4A5BC3BE)
fffff880`015e6000 fffff880`015f8000   mup      mup.sys      Mon Jul 13 19:23:45 2009 (4A5BC201)
fffff880`014f4000 fffff880`015e6000   ndis     ndis.sys     Mon Jul 13 19:21:40 2009 (4A5BC184)
fffff880`04280000 fffff880`0428c000   ndistapi ndistapi.sys Mon Jul 13 20:10:00 2009 (4A5BCCD8)
fffff880`01800000 fffff880`0182f000   ndiswan  ndiswan.sys  Mon Jul 13 20:10:11 2009 (4A5BCCE3)
fffff880`051ac000 fffff880`051c1000   NDProxy  NDProxy.SYS  Mon Jul 13 20:10:05 2009 (4A5BCCDD)
fffff880`02c00000 fffff880`02c0f000   netbios  netbios.sys  Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff880`02d87000 fffff880`02dcc000   netbt    netbt.sys    Mon Jul 13 19:21:28 2009 (4A5BC178)
fffff880`01400000 fffff880`01460000   NETIO    NETIO.SYS    Mon Jul 13 19:21:46 2009 (4A5BC18A)
fffff880`019c1000 fffff880`019d2000   Npfs     Npfs.SYS     Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`02c8f000 fffff880`02c9b000   nsiproxy nsiproxy.sys Mon Jul 13 19:21:02 2009 (4A5BC15E)
fffff800`02a5f000 fffff800`0303b000   nt       ntkrnlmp.exe Sat Jun 19 00:16:41 2010 (4C1C44A9)
fffff880`01237000 fffff880`013da000   Ntfs     Ntfs.sys     Mon Jul 13 19:20:47 2009 (4A5BC14F)
fffff880`01948000 fffff880`01951000   Null     Null.SYS     Mon Jul 13 19:19:37 2009 (4A5BC109)
fffff880`02dd5000 fffff880`02dfb000   pacer    pacer.sys    Mon Jul 13 20:09:41 2009 (4A5BCCC5)
fffff880`00fd0000 fffff880`00fe5000   partmgr  partmgr.sys  Mon Jul 13 19:19:58 2009 (4A5BC11E)
fffff880`00f90000 fffff880`00fc3000   pci      pci.sys      Mon Jul 13 19:19:51 2009 (4A5BC117)
fffff880`00e5c000 fffff880`00e63000   pciide   pciide.sys   Mon Jul 13 19:19:49 2009 (4A5BC115)
fffff880`00e63000 fffff880`00e73000   PCIIDEX  PCIIDEX.SYS  Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`01200000 fffff880`01211000   pcw      pcw.sys      Mon Jul 13 19:19:27 2009 (4A5BC0FF)
fffff880`05000000 fffff880`0503d000   portcls  portcls.sys  Mon Jul 13 20:06:27 2009 (4A5BCC03)
fffff880`00c53000 fffff880`00c67000   PSHED    PSHED.dll    Mon Jul 13 21:32:23 2009 (4A5BE027)
fffff880`02cb5000 fffff880`02cd9000   rasl2tp  rasl2tp.sys  Mon Jul 13 20:10:11 2009 (4A5BCCE3)
fffff880`02cd9000 fffff880`02cf4000   raspppoe raspppoe.sys Mon Jul 13 20:10:17 2009 (4A5BCCE9)
fffff880`0182f000 fffff880`01850000   raspptp  raspptp.sys  Mon Jul 13 20:10:18 2009 (4A5BCCEA)
fffff880`01000000 fffff880`0101a000   rassstp  rassstp.sys  Mon Jul 13 20:10:25 2009 (4A5BCCF1)
fffff880`02c3e000 fffff880`02c8f000   rdbss    rdbss.sys    Mon Jul 13 19:24:09 2009 (4A5BC219)
fffff880`04ff4000 fffff880`04fff000   rdpbus   rdpbus.sys   Mon Jul 13 20:17:46 2009 (4A5BCEAA)
fffff880`0199b000 fffff880`019a4000   RDPCDD   RDPCDD.sys   Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`019a4000 fffff880`019ad000   rdpencdd rdpencdd.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`019ad000 fffff880`019b6000   rdprefmp rdprefmp.sys Mon Jul 13 20:16:35 2009 (4A5BCE63)
fffff880`011b5000 fffff880`011ef000   rdyboost rdyboost.sys Mon Jul 13 19:34:34 2009 (4A5BC48A)
fffff880`02aa9000 fffff880`02ac1000   rspndr   rspndr.sys   Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`014e5000 fffff880`014ed000   spldr    spldr.sys    Mon May 11 12:56:27 2009 (4A0858BB)
fffff880`0428c000 fffff880`0428d480   swenum   swenum.sys   Mon Jul 13 20:00:18 2009 (4A5BCA92)
fffff880`01601000 fffff880`017fe000   tcpip    tcpip.sys    Sun Jun 13 23:39:04 2010 (4C15A458)
fffff880`019f0000 fffff880`019fd000   TDI      TDI.SYS      Mon Jul 13 19:21:18 2009 (4A5BC16E)
fffff880`019d2000 fffff880`019f0000   tdx      tdx.sys      Mon Jul 13 19:21:15 2009 (4A5BC16B)
fffff880`02c2a000 fffff880`02c3e000   termdd   termdd.sys   Mon Jul 13 20:16:36 2009 (4A5BCE64)
fffff960`00440000 fffff960`0044a000   TSDDD    TSDDD.dll    Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`0412e000 fffff880`04154000   tunnel   tunnel.sys   Mon Jul 13 20:09:37 2009 (4A5BCCC1)
fffff880`05140000 fffff880`05152000   umbus    umbus.sys    Mon Jul 13 20:06:56 2009 (4A5BCC20)
fffff880`051fd000 fffff880`051fef00   USBD     USBD.SYS     Mon Jul 13 20:06:23 2009 (4A5BCBFF)
fffff880`04256000 fffff880`04267000   usbehci  usbehci.sys  Mon Jul 13 20:06:30 2009 (4A5BCC06)
fffff880`05152000 fffff880`051ac000   usbhub   usbhub.sys   Mon Jul 13 20:07:09 2009 (4A5BCC2D)
fffff880`04200000 fffff880`04256000   USBPORT  USBPORT.SYS  Mon Jul 13 20:06:31 2009 (4A5BCC07)
fffff880`043ec000 fffff880`043f9000   usbuhci  usbuhci.sys  Mon Jul 13 20:06:27 2009 (4A5BCC03)
fffff880`00fc3000 fffff880`00fd0000   vdrvroot vdrvroot.sys Mon Jul 13 20:01:31 2009 (4A5BCADB)
fffff880`01958000 fffff880`01966000   vga      vga.sys      Mon Jul 13 19:38:47 2009 (4A5BC587)
fffff880`01966000 fffff880`0198b000   VIDEOPRT VIDEOPRT.SYS Mon Jul 13 19:38:51 2009 (4A5BC58B)
fffff880`014d5000 fffff880`014e5000   vmstorfl vmstorfl.sys Mon Jul 13 19:42:54 2009 (4A5BC67E)
fffff880`00fe5000 fffff880`00ffa000   volmgr   volmgr.sys   Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`00e00000 fffff880`00e5c000   volmgrx  volmgrx.sys  Mon Jul 13 19:20:33 2009 (4A5BC141)
fffff880`01169000 fffff880`011b5000   volsnap  volsnap.sys  Mon Jul 13 19:20:08 2009 (4A5BC128)
fffff880`02c0f000 fffff880`02c2a000   wanarp   wanarp.sys   Mon Jul 13 20:10:21 2009 (4A5BCCED)
fffff880`0198b000 fffff880`0199b000   watchdog watchdog.sys Mon Jul 13 19:37:35 2009 (4A5BC53F)
fffff880`00e73000 fffff880`00f17000   Wdf01000 Wdf01000.sys Mon Jul 13 19:22:07 2009 (4A5BC19F)
fffff880`00f17000 fffff880`00f26000   WDFLDR   WDFLDR.SYS   Mon Jul 13 19:19:54 2009 (4A5BC11A)
fffff880`02dcc000 fffff880`02dd5000   wfplwf   wfplwf.sys   Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff960`000d0000 fffff960`003df000   win32k   win32k.sys   Sat Jun 19 00:31:59 2010 (4C1C483F)
fffff880`04267000 fffff880`04270000   wmiacpi  wmiacpi.sys  Mon Jul 13 19:31:02 2009 (4A5BC3B6)
fffff880`00f7d000 fffff880`00f86000   WMILIB   WMILIB.SYS   Mon Jul 13 19:19:51 2009 (4A5BC117)
fffff880`00ddd000 fffff880`00dfe000   WudfPf   WudfPf.sys   Mon Jul 13 20:05:37 2009 (4A5BCBD1)
fffff880`04000000 fffff880`04063000   yk62x64  yk62x64.sys  Mon Feb 23 10:02:27 2009 (49A2BA83)
Unloaded modules:
fffff880`018e8000 fffff880`018f6000   crashdmp.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`018f6000 fffff880`01902000   dump_ataport
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000C000
fffff880`01902000 fffff880`0190b000   dump_atapi.s
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00009000
fffff880`0190b000 fffff880`0191e000   dump_dumpfve
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00013000