Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\SibstLP\Desktop\090910-15802-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\symbols*
Symbol information
Executable search path is:
Windows 7 Kernel Version 7600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`02e17000 PsLoadedModuleList = 0xfffff800`03054e50
Debug session time: Thu Sep 9 12:40:36.653 2010 (UTC + 2:00)
System Uptime: 0 days 0:00:50.338
Loading Kernel Symbols
...............................................................
................................................................
..............................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck BE, {fffff8a0013c5ba0, 800000010fb68121, fffff88003997ff0, b}
Probably caused by : fileinfo.sys ( fileinfo!FIStreamLog+89 )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
ATTEMPTED_WRITE_TO_READONLY_MEMORY (be)
An attempt was made to write to readonly memory. The guilty driver is on the
stack trace (and is typically the current instruction pointer).
When possible, the guilty driver's name (Unicode string) is printed on
the bugcheck screen and saved in KiBugCheckDriver.
Arguments:
Arg1: fffff8a0013c5ba0, Virtual address for the attempted write.
Arg2: 800000010fb68121, PTE contents.
Arg3: fffff88003997ff0, (reserved)
Arg4: 000000000000000b, (reserved)
Debugging Details:
------------------
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xBE
PROCESS_NAME: avast.setup
CURRENT_IRQL: 0
TRAP_FRAME: fffff88003997ff0 -- (.trap 0xfffff88003997ff0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffff80003028c01 rbx=0000000000000000 rcx=00000000000001d1
rdx=0f5058789271d1d1 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8000320f93d rsp=fffff88003998180 rbp=0000000000000000
r8=fffff8a00243e000 r9=00000000000002fd r10=ffffffffffffffff
r11=fffff8a0013c5ba0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na po nc
nt!PfpRpRehashIfNeeded+0x15d:
fffff800`0320f93d 498903 mov qword ptr [r11],rax ds:0001:fffff8a0`013c5ba0=000000280000000c
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002f07ae2 to fffff80002e87740
STACK_TEXT:
fffff880`03997e88 fffff800`02f07ae2 : 00000000`000000be fffff8a0`013c5ba0 80000001`0fb68121 fffff880`03997ff0 : nt!KeBugCheckEx
fffff880`03997e90 fffff800`02e8582e : 00000000`00000001 00000000`00000800 fffffa80`03973800 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x4237e
fffff880`03997ff0 fffff800`0320f93d : 00000000`00000000 fffff8a0`0163aa80 fffff800`03028c88 fffff880`03998368 : nt!KiPageFault+0x16e
fffff880`03998180 fffff800`032d3aba : 0000000a`f673f310 00000000`00000000 18b9db8c`12e5cf47 fffff800`03028c00 : nt!PfpRpRehashIfNeeded+0x15d
fffff880`039981c0 fffff800`02fa85b1 : fffffa80`04d20050 00000000`00000800 fffffa80`00000001 fffff8a0`021f46a0 : nt!PfpRpFileKeyUpdate+0x39a
fffff880`03998250 fffff880`010c455d : 00000000`00000000 00000000`00000000 fffff880`039983e8 fffffa80`03a3fc70 : nt!PfFileInfoNotify+0x5a1
fffff880`039982e0 fffff880`010c4ba8 : fffffa80`04a7b800 fffff8a0`0166c680 fffff880`039984c0 fffff880`039984c0 : fileinfo!FIStreamLog+0x89
fffff880`039983b0 fffff880`010c43c8 : fffff8a0`0166c680 00000000`00000000 fffff880`039984c0 fffff880`039984c0 : fileinfo!FIStreamSetFileInfo+0x14c
fffff880`03998420 fffff880`010c2bdb : fffff140`03b8a9c7 00000000`00000001 00000000`00000000 00000000`00001001 : fileinfo!FIStreamGetInfo+0x17c
fffff880`039984a0 fffff880`01073242 : 00000000`00000000 fffff8a0`0166c680 fffffa80`04914fb0 00000000`00000000 : fileinfo!FIPostCreateCallback+0x1c7
fffff880`03998530 fffff880`0107238b : fffffa80`04be6030 fffffa80`062b6d80 fffffa80`04944bb0 fffffa80`04944dd0 : fltmgr!FltpPerformPostCallbacks+0x392
fffff880`03998600 fffff880`010912b9 : fffffa80`04914c10 fffffa80`04a7b800 fffffa80`04914c00 fffffa80`04917de0 : fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x39b
fffff880`03998690 fffff800`0318a807 : 00000000`00000005 fffff800`0318a260 fffffa80`05c32940 00000000`00000000 : fltmgr!FltpCreate+0x2a9
fffff880`03998740 fffff800`03180e84 : fffffa80`048ee8c0 00000000`00000000 fffffa80`05c14b10 fffffa80`06104701 : nt!IopParseDevice+0x5a7
fffff880`039988d0 fffff800`03185e4d : fffffa80`05c14b10 fffff880`03998a30 fffffa80`00000042 fffffa80`039e1c90 : nt!ObpLookupObjectName+0x585
fffff880`039989d0 fffff800`0318c917 : fffff880`03998a80 00000000`00000005 fffffa80`06104701 00000000`00000001 : nt!ObOpenObjectByName+0x1cd
fffff880`03998a80 fffff800`03196520 : 00000000`001ee068 fffff8a0`c0100080 fffff8a0`01b1da20 00000000`001ee080 : nt!IopCreateFile+0x2b7
fffff880`03998b20 fffff800`02e86993 : fffffa80`0608f5c0 00000000`00000001 fffffa80`06609440 fffff800`0319d414 : nt!NtCreateFile+0x78
fffff880`03998bb0 00000000`776702aa : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`001edff8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x776702aa
STACK_COMMAND: kb
FOLLOWUP_IP:
fileinfo!FIStreamLog+89
fffff880`010c455d 4c8b1534c5ffff mov r10,qword ptr [fileinfo!FIGlobals+0x798 (fffff880`010c0a98)]
SYMBOL_STACK_INDEX: 6
SYMBOL_NAME: fileinfo!FIStreamLog+89
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: fileinfo
IMAGE_NAME: fileinfo.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc481
FAILURE_BUCKET_ID: X64_0xBE_fileinfo!FIStreamLog+89
BUCKET_ID: X64_0xBE_fileinfo!FIStreamLog+89
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
ATTEMPTED_WRITE_TO_READONLY_MEMORY (be)
An attempt was made to write to readonly memory. The guilty driver is on the
stack trace (and is typically the current instruction pointer).
When possible, the guilty driver's name (Unicode string) is printed on
the bugcheck screen and saved in KiBugCheckDriver.
Arguments:
Arg1: fffff8a0013c5ba0, Virtual address for the attempted write.
Arg2: 800000010fb68121, PTE contents.
Arg3: fffff88003997ff0, (reserved)
Arg4: 000000000000000b, (reserved)
Debugging Details:
------------------
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xBE
PROCESS_NAME: avast.setup
CURRENT_IRQL: 0
TRAP_FRAME: fffff88003997ff0 -- (.trap 0xfffff88003997ff0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffff80003028c01 rbx=0000000000000000 rcx=00000000000001d1
rdx=0f5058789271d1d1 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8000320f93d rsp=fffff88003998180 rbp=0000000000000000
r8=fffff8a00243e000 r9=00000000000002fd r10=ffffffffffffffff
r11=fffff8a0013c5ba0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na po nc
nt!PfpRpRehashIfNeeded+0x15d:
fffff800`0320f93d 498903 mov qword ptr [r11],rax ds:0001:fffff8a0`013c5ba0=000000280000000c
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002f07ae2 to fffff80002e87740
STACK_TEXT:
fffff880`03997e88 fffff800`02f07ae2 : 00000000`000000be fffff8a0`013c5ba0 80000001`0fb68121 fffff880`03997ff0 : nt!KeBugCheckEx
fffff880`03997e90 fffff800`02e8582e : 00000000`00000001 00000000`00000800 fffffa80`03973800 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x4237e
fffff880`03997ff0 fffff800`0320f93d : 00000000`00000000 fffff8a0`0163aa80 fffff800`03028c88 fffff880`03998368 : nt!KiPageFault+0x16e
fffff880`03998180 fffff800`032d3aba : 0000000a`f673f310 00000000`00000000 18b9db8c`12e5cf47 fffff800`03028c00 : nt!PfpRpRehashIfNeeded+0x15d
fffff880`039981c0 fffff800`02fa85b1 : fffffa80`04d20050 00000000`00000800 fffffa80`00000001 fffff8a0`021f46a0 : nt!PfpRpFileKeyUpdate+0x39a
fffff880`03998250 fffff880`010c455d : 00000000`00000000 00000000`00000000 fffff880`039983e8 fffffa80`03a3fc70 : nt!PfFileInfoNotify+0x5a1
fffff880`039982e0 fffff880`010c4ba8 : fffffa80`04a7b800 fffff8a0`0166c680 fffff880`039984c0 fffff880`039984c0 : fileinfo!FIStreamLog+0x89
fffff880`039983b0 fffff880`010c43c8 : fffff8a0`0166c680 00000000`00000000 fffff880`039984c0 fffff880`039984c0 : fileinfo!FIStreamSetFileInfo+0x14c
fffff880`03998420 fffff880`010c2bdb : fffff140`03b8a9c7 00000000`00000001 00000000`00000000 00000000`00001001 : fileinfo!FIStreamGetInfo+0x17c
fffff880`039984a0 fffff880`01073242 : 00000000`00000000 fffff8a0`0166c680 fffffa80`04914fb0 00000000`00000000 : fileinfo!FIPostCreateCallback+0x1c7
fffff880`03998530 fffff880`0107238b : fffffa80`04be6030 fffffa80`062b6d80 fffffa80`04944bb0 fffffa80`04944dd0 : fltmgr!FltpPerformPostCallbacks+0x392
fffff880`03998600 fffff880`010912b9 : fffffa80`04914c10 fffffa80`04a7b800 fffffa80`04914c00 fffffa80`04917de0 : fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x39b
fffff880`03998690 fffff800`0318a807 : 00000000`00000005 fffff800`0318a260 fffffa80`05c32940 00000000`00000000 : fltmgr!FltpCreate+0x2a9
fffff880`03998740 fffff800`03180e84 : fffffa80`048ee8c0 00000000`00000000 fffffa80`05c14b10 fffffa80`06104701 : nt!IopParseDevice+0x5a7
fffff880`039988d0 fffff800`03185e4d : fffffa80`05c14b10 fffff880`03998a30 fffffa80`00000042 fffffa80`039e1c90 : nt!ObpLookupObjectName+0x585
fffff880`039989d0 fffff800`0318c917 : fffff880`03998a80 00000000`00000005 fffffa80`06104701 00000000`00000001 : nt!ObOpenObjectByName+0x1cd
fffff880`03998a80 fffff800`03196520 : 00000000`001ee068 fffff8a0`c0100080 fffff8a0`01b1da20 00000000`001ee080 : nt!IopCreateFile+0x2b7
fffff880`03998b20 fffff800`02e86993 : fffffa80`0608f5c0 00000000`00000001 fffffa80`06609440 fffff800`0319d414 : nt!NtCreateFile+0x78
fffff880`03998bb0 00000000`776702aa : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`001edff8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x776702aa
STACK_COMMAND: kb
FOLLOWUP_IP:
fileinfo!FIStreamLog+89
fffff880`010c455d 4c8b1534c5ffff mov r10,qword ptr [fileinfo!FIGlobals+0x798 (fffff880`010c0a98)]
SYMBOL_STACK_INDEX: 6
SYMBOL_NAME: fileinfo!FIStreamLog+89
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: fileinfo
IMAGE_NAME: fileinfo.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc481
FAILURE_BUCKET_ID: X64_0xBE_fileinfo!FIStreamLog+89
BUCKET_ID: X64_0xBE_fileinfo!FIStreamLog+89
Followup: MachineOwner
---------