Microsoft ® Windows Debugger Version 6.11.0001.404 X86
Copyright © Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Windows\Minidump\040212-34984-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: srv*C:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is: srv*C:\symbols*http://msdl.microsoft.com/download/symbols
Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.17727.x86fre.win7sp1_gdr.111118-2330
Machine Name:
Kernel base = 0xe3006000 PsLoadedModuleList = 0xe3146230
Debug session time: Mon Apr 2 19:21:03.217 2012 (GMT+4)
System Uptime: 0 days 0:14:35.920
Loading Kernel Symbols
...............................................................
................................................................
.....................................
Loading User Symbols
Loading unloaded module list
......
0: kd> kd: Reading initial command '!analyze -v; q'
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 00041284, A PTE or the working set list is corrupt.
Arg2: e6585001
Arg3: 000066af
Arg4: b8800000
Debugging Details:
------------------
BUGCHECK_STR: 0x1a_41284
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 0
LOCK_ADDRESS: e3162f20 -- (!locks e3162f20)
Resource @ nt!PiEngineLock (0xe3162f20) Available
WARNING: SystemResourcesList->Flink chain invalid. Resource may be corrupted, or already deleted.
WARNING: SystemResourcesList->Blink chain invalid. Resource may be corrupted, or already deleted.
1 total locks
PNP_TRIAGE:
Lock address : 0xe3162f20
Thread Count : 0
Thread address: 0x00000000
Thread wait : 0x0
LAST_CONTROL_TRANSFER: from e307f232 to e30d83fc
STACK_TEXT:
cf6469b4 e307f232 0000001a 00041284 e6585001 nt!KeBugCheckEx+0x1e
cf6469dc e30ada14 b8cdd614 00037582 c0399608 nt!MiLocateWsle+0xc1
cf646ab8 e308a1df c0399614 00000005 00000000 nt!MiDeleteSystemPagableVm+0x146
cf646b94 e311d940 e6582000 00000000 00008000 nt!MiFreePagedPoolPages+0x393
cf646c5c e311eed5 e6582000 e6447500 00000000 nt!MiFreePoolPages+0x2ba
cf646cc4 e31d9f7f e6582000 00000000 cf646d18 nt!ExFreePoolWithTag+0x438
cf646cf0 e31da935 00000009 e6582000 00000018 nt!PiControlGetInterfaceDeviceList+0x145
cf646d20 e303b82a 00000009 00d8f268 00000018 nt!NtPlugPlayControl+0xbe
cf646d20 77417094 00000009 00d8f268 00000018 nt!KiFastCallEntry+0x12a
WARNING: Frame IP not in any known module. Following frames may be wrong.
00d8f2a0 00000000 00000000 00000000 00000000 0x77417094
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!MiLocateWsle+c1
e307f232 cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!MiLocateWsle+c1
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 4ec7982f
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: 0x1a_41284_nt!MiLocateWsle+c1
BUCKET_ID: 0x1a_41284_nt!MiLocateWsle+c1
Followup: MachineOwner
---------
quit:
„«п Їа®¤®«¦ҐЁп ¦¬ЁвҐ «оЎго Є« ўЁиг . . .