Microsoft (R) Windows Debugger Version 6.11.0001.404 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Windows\Minidump\Mini061309-04.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is:
http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows Server 2008/Windows Vista Kernel Version 6001 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 6001.18226.amd64fre.vistasp1_gdr.090302-1506
Machine Name:
Kernel base = 0xfffff800`01e08000 PsLoadedModuleList = 0xfffff800`01fcddb0
Debug session time: Sat Jun 13 21:41:19.363 2009 (GMT+2)
System Uptime: 0 days 1:34:41.728
Loading Kernel Symbols
.................................................. .............
.................................................. ..............
........................
Loading User Symbols
Loading unloaded module list
......
************************************************** *****************************
* *
* Bugcheck Analysis *
* *
************************************************** *****************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fffff80001eed6ea, fffffa600967df60, 0}
Probably caused by : memory_corruption ( nt!MiIdentifyPfn+6fa )
Followup: MachineOwner
---------
0: kd> !analyze -v
************************************************** *****************************
* *
* Bugcheck Analysis *
* *
************************************************** *****************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff80001eed6ea, Address of the exception record for the exception that caused the bugcheck
Arg3: fffffa600967df60, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - L'istruzione a 0x%08lx ha fatto riferimento alla memoria a 0x%08lx. La memoria non poteva essere %s.
FAULTING_IP:
nt!MiIdentifyPfn+6fa
fffff800`01eed6ea 488b5318 mov rdx,qword ptr [rbx+18h]
CONTEXT: fffffa600967df60 -- (.cxr 0xfffffa600967df60)
rax=0200000000000000 rbx=99c00000b0a37960 rcx=0000000000000002
rdx=00000000001c23d0 rsi=fffffa80043f52e0 rdi=02000000001020c0
rip=fffff80001eed6ea rsp=fffffa600967e7c0 rbp=fffffa600967e800
r8=0200000000000000 r9=0000000000000542 r10=fffffa8001a826a0
r11=fffff6fc40046080 r12=0000000000000000 r13=fffffffffffff000
r14=000fffffffffffff r15=0000000000000000
iopl=0 nv up ei ng nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010286
nt!MiIdentifyPfn+0x6fa:
fffff800`01eed6ea 488b5318 mov rdx,qword ptr [rbx+18h] ds:002b:99c00000`b0a37978=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 4
DEFAULT_BUCKET_ID: COMMON_SYSTEM_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 2
LAST_CONTROL_TRANSFER: from fffff80001f07fde to fffff80001eed6ea
STACK_TEXT:
fffffa60`0967e7c0 fffff800`01f07fde : 00000000`0003847a fffffa80`043f52e0 fffffa80`08836060 00000000`00000000 : nt!MiIdentifyPfn+0x6fa
fffffa60`0967e860 fffff800`021f6c05 : fffffa80`043f5000 fffffa60`0967eca0 fffffa60`0967e928 00000000`00000000 : nt!MmQueryPfnList+0x13e
fffffa60`0967e8a0 fffff800`0213e19c : 00000000`000000a8 00000000`00000000 fffffa80`043f5000 00000000`061d4f01 : nt!PfpPfnPrioRequest+0x115
fffffa60`0967e8f0 fffff800`020d39aa : 00000000`00000000 00000000`061d4ff0 00000000`03bdee50 fffffa80`08939001 : nt! ?? ::NNGAKEGL::`string'+0x467aa
fffffa60`0967e960 fffff800`01e5c0f3 : fffffa80`08836060 00000000`061d4ff0 00000000`04e81b01 00000000`00000000 : nt!NtQuerySystemInformation+0xd0a
fffffa60`0967ec20 00000000`76dd5dda : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`03bdeda8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x76dd5dda
FOLLOWUP_IP:
nt!MiIdentifyPfn+6fa
fffff800`01eed6ea 488b5318 mov rdx,qword ptr [rbx+18h]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!MiIdentifyPfn+6fa
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 49ac93e1
STACK_COMMAND: .cxr 0xfffffa600967df60 ; kb
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: X64_0x3B_nt!MiIdentifyPfn+6fa
BUCKET_ID: X64_0x3B_nt!MiIdentifyPfn+6fa
Followup: MachineOwner
---------
0: kd> .trap
0: kd> lmvm nt
start end module name
fffff800`01e08000 fffff800`02320000 nt (pdb symbols) C:\Program Files\Debugging Tools for Windows (x64)\sym\ntkrnlmp.pdb\3A429B43B3B34C5DBF2B896C4B2 E52E72\ntkrnlmp.pdb
Loaded symbol image file: ntkrnlmp.exe
Mapped memory image file: C:\Program Files\Debugging Tools for Windows (x64)\sym\ntoskrnl.exe\49AC93E1518000\ntoskrnl.exe
Image path: ntkrnlmp.exe
Image name: ntkrnlmp.exe
Timestamp: Tue Mar 03 03:20:17 2009 (49AC93E1)
CheckSum: 0047BEDF
ImageSize: 00518000
File version: 6.0.6001.18226
Product version: 6.0.6001.18226
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 1.0 App
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: ntkrnlmp.exe
OriginalFilename: ntkrnlmp.exe
ProductVersion: 6.0.6001.18226
FileVersion: 6.0.6001.18226 (vistasp1_gdr.090302-1506)
FileDescription: NT Kernel & System
LegalCopyright: © Microsoft Corporation. All rights reserved.