BugCheck 1A, {8886, fffffa80036cfa50, fffffa8002613a50, 200}
Probably caused by : memory_corruption ( nt!MiUnlinkPageFromLockedList+298 )
Followup: MachineOwner
---------
2: kd> .reload
Loading Kernel Symbols
...............................................................
................................................................
.......................
Loading User Symbols
Loading unloaded module list
...............
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000008886, The subtype of the bugcheck.
Arg2: fffffa80036cfa50
Arg3: fffffa8002613a50
Arg4: 0000000000000200
Debugging Details:
------------------
BUGCHECK_STR: 0x1a_8886
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: BFBC2Updater.e
CURRENT_IRQL: 2
LAST_CONTROL_TRANSFER: from fffff80002ee48c8 to fffff80002ec3740
STACK_TEXT:
fffff880`08aea4a8 fffff800`02ee48c8 : 00000000`0000001a 00000000`00008886 fffffa80`036cfa50 fffffa80`02613a50 : nt!KeBugCheckEx
fffff880`08aea4b0 fffff800`02ea842d : 00000000`00113c1e 00000000`00000000 fffffa80`00113c1e 00000580`00000000 : nt!MiUnlinkPageFromLockedList+0x298
fffff880`08aea540 fffff800`02ea8b82 : 00000000`00000000 fffffa80`041d3100 00000000`00000000 00000000`00000000 : nt!MmPurgeSection+0x4bd
fffff880`08aea630 fffff880`012be447 : fffffa80`0713cce8 00000000`00000000 fffff8a0`00000000 00000000`00000000 : nt!CcPurgeCacheSection+0x172
fffff880`08aea6a0 fffff880`012d7c0a : fffff880`0967f730 fffff8a0`0720db40 fffff8a0`07412140 fffff880`08aea99c : Ntfs!NtfsDeleteFile+0x57b
fffff880`08aea920 fffff880`01245aa9 : fffffa80`07390230 fffffa80`03c79c10 fffff880`0967f690 fffffa80`05365060 : Ntfs!NtfsCommonCleanup+0x15da
fffff880`08aead30 fffff800`02ebb5c7 : fffff880`0967f690 00000000`00000000 fffff800`0304bc40 fffff800`02ea1c26 : Ntfs!NtfsCommonCleanupCallout+0x19
fffff880`08aead60 fffff800`02ebb581 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KySwitchKernelStackCallout+0x27
fffff880`0967f560 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSwitchKernelStackContinue
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!MiUnlinkPageFromLockedList+298
fffff800`02ee48c8 cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!MiUnlinkPageFromLockedList+298
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: X64_0x1a_8886_nt!MiUnlinkPageFromLockedList+298
BUCKET_ID: X64_0x1a_8886_nt!MiUnlinkPageFromLockedList+298
Followup: MachineOwner
---------
Frequenz: 1333mhz (666mhz)
Timings: 9-9-9-24-33
Command Rate: 2T
Spannung der RAM: 1,65V (mehr nicht).
DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: 0000000000000113, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, value 0 = read operation, 1 = write operation
Arg4: fffff88004498ffe, address which referenced memory
Debugging Details:
------------------
Unable to load image \SystemRoot\system32\DRIVERS\athrx.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for athrx.sys
*** ERROR: Module load completed but symbols could not be loaded for athrx.sys
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002f0f0e0
0000000000000113
CURRENT_IRQL: 2
FAULTING_IP:
athrx+7effe
fffff880`04498ffe 488b ???
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xD1
PROCESS_NAME: System
TRAP_FRAME: fffff80000b9c2e0 -- (.trap 0xfffff80000b9c2e0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000113 rbx=0000000000000000 rcx=fffffa80056f1f78
rdx=0000000000000002 rsi=0000000000000000 rdi=0000000000000000
rip=fffff88004498ffe rsp=fffff80000b9c470 rbp=0000000000000004
r8=0000000000000000 r9=0000000000000000 r10=000000000000002b
r11=0000000000000002 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe nc
athrx+0x7effe:
fffff880`04498ffe 488b ???
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002cd8469 to fffff80002cd8f00
STACK_TEXT:
fffff800`00b9c198 fffff800`02cd8469 : 00000000`0000000a 00000000`00000113 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
fffff800`00b9c1a0 fffff800`02cd70e0 : 00000004`00000000 fffffa80`055ac1a0 00000000`00000000 00000000`0000003f : nt!KiBugCheckDispatch+0x69
fffff800`00b9c2e0 fffff880`04498ffe : fffffa80`0562b020 00000000`00000000 fffffa80`056f1bd0 fffffa80`055ac1a0 : nt!KiPageFault+0x260
fffff800`00b9c470 fffffa80`0562b020 : 00000000`00000000 fffffa80`056f1bd0 fffffa80`055ac1a0 00000000`00000113 : athrx+0x7effe
fffff800`00b9c478 00000000`00000000 : fffffa80`056f1bd0 fffffa80`055ac1a0 00000000`00000113 00000021`c940d64c : 0xfffffa80`0562b020
STACK_COMMAND: kb
FOLLOWUP_IP:
athrx+7effe
fffff880`04498ffe 488b ???
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: athrx+7effe
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: athrx
IMAGE_NAME: athrx.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4a2ea4b9
FAILURE_BUCKET_ID: X64_0xD1_athrx+7effe
BUCKET_ID: X64_0xD1_athrx+7effe
Followup: MachineOwner
---------