» Click to show Spoiler - click again to hide... «
Microsoft ® Windows Debugger Version 6.9.0003.113 X86
Copyright © Microsoft Corporation. All rights reserved.
Loading Dump File [C:\WINDOWS\Minidump\Mini091308-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 2600.xpsp.080413-2111
Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720
Debug session time: Sat Sep 13 02:58:43.328 2008 (GMT+8)
System Uptime: 0 days 0:02:48.021
Loading Kernel Symbols
................................................................................................................................
Loading User Symbols
Loading unloaded module list
..........
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 10000050, {a9381190, 0, 8054b569, 0}
Could not read faulting driver name
Probably caused by : ntkrpamp.exe ( nt!ExFreePoolWithTag+289 )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: a9381190, memory referenced.
Arg2: 00000000, value 0 = read operation, 1 = write operation.
Arg3: 8054b569, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 00000000, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
READ_ADDRESS: a9381190
FAULTING_IP:
nt!ExFreePoolWithTag+289
8054b569 668b10 mov dx,word ptr [eax]
MM_INTERNAL_CODE: 0
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: System
LAST_CONTROL_TRANSFER: from 805c105f to 8054b569
STACK_TEXT:
ba50bbd0 805c105f a93807d8 e56c6946 8a617730 nt!ExFreePoolWithTag+0x289
ba50bbf0 805bb46e 00000000 a93807d8 a93807f0 nt!ObpFreeObject+0x18d
ba50bc08 805266ca a93807f0 00000000 00000000 nt!ObpRemoveObjectRoutine+0xe8
ba50bc20 8050a88a 00000000 8872eaf0 00000000 nt!ObfDereferenceObject+0x4c
ba50bc48 8050b416 e13f2700 00000000 e24772c0 nt!MiSegmentDelete+0xec
ba50bc6c 8050c019 8872eaf0 00000000 00000000 nt!MiCheckControlArea+0x1c4
ba50bc84 805a8a92 8872eaf0 00000000 00000000 nt!MiDereferenceControlAreaBySection+0x29
ba50bc9c 805bb466 8872eaf0 00000000 e24772a8 nt!MiSectionDelete+0x76
ba50bcb8 805266ca e24772c0 00000000 893bf06c nt!ObpRemoveObjectRoutine+0xe0
ba50bcd0 804e550a 806e6a4c 893bf008 806e6aa8 nt!ObfDereferenceObject+0x4c
ba50bcfc 804e4af3 00000001 80559690 8895eb68 nt!CcDeleteSharedCacheMap+0xde
ba50bd34 804e70cb 8a5f21a0 80564820 8a5fcb30 nt!CcWriteBehind+0x357
ba50bd7c 8053876d 8a5f21a0 00000000 8a5fcb30 nt!CcWorkerThread+0x12f
ba50bdac 805cff64 8a5f21a0 00000000 00000000 nt!ExpWorkerThread+0xef
ba50bddc 805460de 8053867e 00000000 00000000 nt!PspSystemThreadStartup+0x34
00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x16
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!ExFreePoolWithTag+289
8054b569 668b10 mov dx,word ptr [eax]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!ExFreePoolWithTag+289
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrpamp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4802516a
FAILURE_BUCKET_ID: 0x50_nt!ExFreePoolWithTag+289
BUCKET_ID: 0x50_nt!ExFreePoolWithTag+289
Followup: MachineOwner
---------
Advice please
Sep 13 2008, 03:07 AM
Quote

0.6022sec
0.60
7 queries
GZIP Disabled