ymbol search path is: srv*c:\mysymbols*http://msdl.microsoft.com/download/symbols;cache*c:\mysymbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (16 procs) Free x64
Product: Server, suite: Enterprise TerminalServer SingleUserTS
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`0165b000 PsLoadedModuleList = 0xfffff800`01898e50
Debug session time: Tue Feb 8 18:49:01.879 2011 (UTC + 8:00)
System Uptime: 9 days 7:37:09.542
Loading Kernel Symbols
...............................................................
................................................................
.................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1A, {41284, 221b001, 0, fffff70001080000}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+4a83 )
Followup: MachineOwner
---------
10: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041284, A PTE or the working set list is corrupt.
Arg2: 000000000221b001
Arg3: 0000000000000000
Arg4: fffff70001080000
Debugging Details:
------------------
BUGCHECK_STR: 0x1a_41284
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: DRIVER_FAULT_SERVER_MINIDUMP
PROCESS_NAME: WmiPrvSE.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff800017203b3 to fffff800016cb740
STACK_TEXT:
fffff880`0789b7e8 fffff800`017203b3 : 00000000`0000001a 00000000`00041284 00000000`0221b001 00000000`00000000 : nt!KeBugCheckEx
fffff880`0789b7f0 fffff800`016fc445 : fffff700`01080000 00000000`00000001 fffffa80`28c3fb30 fffffa80`57c2be40 : nt! ?? ::FNODOBFM::`string'+0x4a83
fffff880`0789b830 fffff800`016fedf9 : 00000000`00000000 00000000`023f8fff fffff8a0`00000000 fffff800`016dab7c : nt!MiDeleteVirtualAddresses+0x4cc
fffff880`0789b9f0 fffff800`019e41d0 : fffffa80`57247d80 0007ffff`00000000 fffffa80`5837e510 fffffa80`5837e510 : nt!MiRemoveMappedView+0xd9
fffff880`0789bb10 fffff800`019e45db : 00000000`00000000 00000000`01fb0000 fffffa80`00000001 00000000`00000201 : nt!MiUnmapViewOfSection+0x1b0
fffff880`0789bbd0 fffff800`016ca993 : fffffa80`5a586b60 fffff880`0789bca0 fffffa80`28c3fb30 fffffa80`57ebb580 : nt!NtUnmapViewOfSection+0x5f
fffff880`0789bc20 00000000`7754015a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0132d588 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7754015a
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+4a83
fffff800`017203b3 cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+4a83
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
FAILURE_BUCKET_ID: X64_0x1a_41284_nt!_??_::FNODOBFM::_string_+4a83
BUCKET_ID: X64_0x1a_41284_nt!_??_::FNODOBFM::_string_+4a83
Followup: MachineOwner
---------
10: kd> lmvm nt
start end module name
fffff800`0165b000 fffff800`01c37000 nt (pdb symbols) c:\mysymbols\ntkrnlmp.pdb\30092BE745B24FE2A311A936E7B7486F2\ntkrnlmp.pdb
Loaded symbol image file: ntkrnlmp.exe
Mapped memory image file: c:\mysymbols\ntoskrnl.exe\4C1C44A95dc000\ntoskrnl.exe
Image path: ntkrnlmp.exe
Image name: ntkrnlmp.exe
Timestamp: Sat Jun 19 12:16:41 2010 (4C1C44A9)
CheckSum: 005489D7
ImageSize: 005DC000
File version: 6.1.7600.16617
Product version: 6.1.7600.16617
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 1.0 App
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: ntkrnlmp.exe
OriginalFilename: ntkrnlmp.exe
ProductVersion: 6.1.7600.16617
FileVersion: 6.1.7600.16617 (win7_gdr.100618-1621)
FileDescription: NT Kernel & System
LegalCopyright: © Microsoft Corporation. All rights reserved.