View Single Post
  #18 (permalink)  
Old January 28, 2010, 10:19 PM
flyingdutchman flyingdutchman is offline
Rookie
 
Join Date: Jan 2010
Posts: 19
Default

I installed Windows Debugging Tool and ran the dump file error that I got after I got my Blue Screen and this is what I got:


Microsoft (R) Windows Debugger Version 6.11.0001.404 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Windows\Minidump\010108-20280-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*c:\symbols*Symbol information
Executable search path is:
Windows 7 Kernel Version 7600 MP (3 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16385.amd64fre.win7_rtm.090713-1255
Machine Name:
Kernel base = 0xfffff800`02a51000 PsLoadedModuleList = 0xfffff800`02c8ee50
Debug session time: Wed Jan 27 21:14:23.585 2010 (GMT-5)
System Uptime: 0 days 3:32:30.801
Loading Kernel Symbols
.................................................. .............
.................................................. ..............
......................
Loading User Symbols
Loading unloaded module list
.........
************************************************** *****************************
* *
* Bugcheck Analysis *
* *
************************************************** *****************************

Use !analyze -v to get detailed debugging information.

BugCheck 1000007E, {ffffffffc0000005, fffff80002ac6105, fffff8800318d338, fffff8800318cb90}

Probably caused by : ntkrnlmp.exe ( nt!ExpInterlockedPopEntrySListFault16+0 )

Followup: MachineOwner
---------

0: kd> !analyze -v
************************************************** *****************************
* *
* Bugcheck Analysis *
* *
************************************************** *****************************

SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff80002ac6105, The address that the exception occurred at
Arg3: fffff8800318d338, Exception Record Address
Arg4: fffff8800318cb90, Context Record Address

Debugging Details:
------------------


EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

FAULTING_IP:
nt!ExpInterlockedPopEntrySListFault16+0
fffff800`02ac6105 498b08 mov rcx,qword ptr [r8]

EXCEPTION_RECORD: fffff8800318d338 -- (.exr 0xfffff8800318d338)
ExceptionAddress: fffff80002ac6105 (nt!ExpInterlockedPopEntrySListFault16)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff

CONTEXT: fffff8800318cb90 -- (.cxr 0xfffff8800318cb90)
rax=000000125384001c rbx=0000000000001000 rcx=fffff80002c49b90
rdx=00fffa8002f07001 rsi=0000000000000001 rdi=0000000000000000
rip=fffff80002ac6105 rsp=fffff8800318d570 rbp=fffff8800318d5c0
r8=00fffa8002f07000 r9=0000000063416d4d r10=fffff80002c49b90
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000063416d4d
iopl=0 nv up ei pl nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010206
nt!ExpInterlockedPopEntrySListFault16:
fffff800`02ac6105 498b08 mov rcx,qword ptr [r8] ds:002b:00fffa80`02f07000=????????????????
Resetting default scope

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

PROCESS_NAME: chrome.exe

CURRENT_IRQL: 0

ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

EXCEPTION_PARAMETER1: 0000000000000000

EXCEPTION_PARAMETER2: ffffffffffffffff

READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002cf90e0
ffffffffffffffff

FOLLOWUP_IP:
nt!ExpInterlockedPopEntrySListFault16+0
fffff800`02ac6105 498b08 mov rcx,qword ptr [r8]

BUGCHECK_STR: 0x7E

LAST_CONTROL_TRANSFER: from fffff80002bf24b1 to fffff80002ac6105

STACK_TEXT:
fffff880`0318d570 fffff800`02bf24b1 : 00000000`00000000 00000000`0000000e 00000000`00000001 00000000`00040004 : nt!ExpInterlockedPopEntrySListFault16
fffff880`0318d580 fffff800`02ad5860 : 00000000`00001000 fffff800`02c50880 00000000`00000000 655d2ac6`00000000 : nt!MiAllocatePoolPages+0xa1
fffff880`0318d6d0 fffff800`02bf5bfe : 00000000`00000000 00000000`00000000 00000000`00000000 fffff800`02c50880 : nt!ExpAllocateBigPool+0xb0
fffff880`0318d7c0 fffff800`02bc7a24 : fffffa80`00040004 00000000`00001000 00000000`00000000 00000000`00000000 : nt!ExAllocatePoolWithTag+0x82e
fffff880`0318d8b0 fffff800`02bc7bf6 : fffffa80`02afb000 00000000`00006485 fffff680`0009f5e8 00000000`00000000 : nt!MiAllocateAccessLog+0xb4
fffff880`0318d8e0 fffff800`02b2b1d8 : 00000003`00000000 c8500000`a6549867 00000000`00000000 00000000`00006485 : nt!MiLogPageAccess+0x46
fffff880`0318d930 fffff800`02b43a0e : fffffa80`060249c8 fffff880`00000001 00000000`00000001 fffff880`0318dbb0 : nt! ?? ::FNODOBFM::`string'+0x21846
fffff880`0318dae0 fffff800`02ad76e2 : 00000000`000031cf 00000000`00000000 fffffa80`00000000 00000000`00000004 : nt! ?? ::FNODOBFM::`string'+0x49926
fffff880`0318db80 fffff800`02ad796f : 00000000`00000008 fffff880`0318dc10 00000000`00000001 fffffa80`00000000 : nt!MmWorkingSetManager+0x6e
fffff880`0318dbd0 fffff800`02d66166 : fffffa80`025d9680 00000000`00000080 fffffa80`024d6040 00000000`00000001 : nt!KeBalanceSetManager+0x1c3
fffff880`0318dd40 fffff800`02aa1486 : fffff800`02c3be80 fffffa80`025d9680 fffff800`02c49c40 00000000`00000000 : nt!PspSystemThreadStartup+0x5a
fffff880`0318dd80 00000000`00000000 : fffff880`0318e000 fffff880`03188000 fffff880`0318d710 00000000`00000000 : nt!KxStartSystemThread+0x16


SYMBOL_STACK_INDEX: 0

SYMBOL_NAME: nt!ExpInterlockedPopEntrySListFault16+0

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: nt

IMAGE_NAME: ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc600

STACK_COMMAND: .cxr 0xfffff8800318cb90 ; kb

FAILURE_BUCKET_ID: X64_0x7E_nt!ExpInterlockedPopEntrySListFault16+0

BUCKET_ID: X64_0x7E_nt!ExpInterlockedPopEntrySListFault16+0

Followup: MachineOwner
---------



Looking from this I can see that ntkrnlmp.exe is causing the problem. But what the hell is that?
Reply With Quote