<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-2941007113477861308</id><updated>2012-01-12T03:48:33.664-08:00</updated><title type='text'>My Blue Screen Of Death - How to debug</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://mybluescreen.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2941007113477861308/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://mybluescreen.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Allex Radu</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>16</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2941007113477861308.post-4335367045216566744</id><published>2008-06-20T05:52:00.000-07:00</published><updated>2008-06-20T05:54:49.357-07:00</updated><title type='text'>Probably caused by : memory_corruption ( nt!MiRemoveUnusedSegments+3db )</title><content type='html'>&lt;code&gt;Microsoft (R) Windows Debugger Version 6.9.0003.113 X86&lt;br /&gt;Copyright (c) Microsoft Corporation. All rights reserved.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Loading Dump File [c:\windows\minidump\Mini061608-02.dmp]&lt;br /&gt;Mini Kernel Dump File: Only registers and stack trace are available&lt;br /&gt;&lt;br /&gt;Symbol search path is: c:\windows\symbols&lt;br /&gt;Executable search path is: c:\windows\i386&lt;br /&gt;Unable to load image ntoskrnl.exe, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for ntoskrnl.exe&lt;br /&gt;Windows XP Kernel Version 2600 (Service Pack 3) MP (4 procs) Free x86 compatible&lt;br /&gt;Product: WinNt, suite: TerminalServer SingleUserTS&lt;br /&gt;Kernel base = 0x804d7000 PsLoadedModuleList = 0x805634c0&lt;br /&gt;Debug session time: Mon Jun 16 00:45:48.359 2008 (GMT+3)&lt;br /&gt;System Uptime: 0 days 0:36:56.339&lt;br /&gt;Unable to load image ntoskrnl.exe, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for ntoskrnl.exe&lt;br /&gt;Loading Kernel Symbols&lt;br /&gt;......................................................................................................................................&lt;br /&gt;Loading User Symbols&lt;br /&gt;Loading unloaded module list&lt;br /&gt;...........&lt;br /&gt;*******************************************************************************&lt;br /&gt;*                                                                             *&lt;br /&gt;*                        Bugcheck Analysis                                    *&lt;br /&gt;*                                                                             *&lt;br /&gt;*******************************************************************************&lt;br /&gt;&lt;br /&gt;Use !analyze -v to get detailed debugging information.&lt;br /&gt;&lt;br /&gt;BugCheck C2, {7, cd4, 660072, e1badb58}&lt;br /&gt;&lt;br /&gt;GetUlongFromAddress: unable to read from 805637f0&lt;br /&gt;GetUlongFromAddress: unable to read from 805637f0&lt;br /&gt;Probably caused by : memory_corruption ( nt!MiRemoveUnusedSegments+3db )&lt;br /&gt;&lt;br /&gt;Followup: MachineOwner&lt;br /&gt;---------&lt;br /&gt;&lt;br /&gt;0: kd&gt; !analyze -v&lt;br /&gt;*******************************************************************************&lt;br /&gt;*                                                                             *&lt;br /&gt;*                        Bugcheck Analysis                                    *&lt;br /&gt;*                                                                             *&lt;br /&gt;*******************************************************************************&lt;br /&gt;&lt;br /&gt;BAD_POOL_CALLER (c2)&lt;br /&gt;The current thread is making a bad pool request.  Typically this is at a bad IRQL level or double freeing the same allocation, etc.&lt;br /&gt;Arguments:&lt;br /&gt;Arg1: 00000007, Attempt to free pool which was already freed&lt;br /&gt;Arg2: 00000cd4, (reserved)&lt;br /&gt;Arg3: 00660072, Memory contents of the pool block&lt;br /&gt;Arg4: e1badb58, Address of the block of pool being deallocated&lt;br /&gt;&lt;br /&gt;Debugging Details:&lt;br /&gt;------------------&lt;br /&gt;&lt;br /&gt;GetUlongFromAddress: unable to read from 805637f0&lt;br /&gt;GetUlongFromAddress: unable to read from 805637f0&lt;br /&gt;&lt;br /&gt;POOL_ADDRESS:  e1badb58&lt;br /&gt;&lt;br /&gt;BUGCHECK_STR:  0xc2_7&lt;br /&gt;&lt;br /&gt;CUSTOMER_CRASH_COUNT:  2&lt;br /&gt;&lt;br /&gt;DEFAULT_BUCKET_ID:  DRIVER_FAULT&lt;br /&gt;&lt;br /&gt;PROCESS_NAME:  TurokGame.exe&lt;br /&gt;&lt;br /&gt;LAST_CONTROL_TRANSFER:  from 80551fc5 to 80537672&lt;br /&gt;&lt;br /&gt;STACK_TEXT: &lt;br /&gt;b5c90aa0 80551fc5 000000c2 00000007 00000cd4 nt!MiRemoveUnusedSegments+0x3db&lt;br /&gt;b5c90af0 8056ec09 e1badb58 00000000 e1011328 nt!KiProfileLock+0x1&lt;br /&gt;b5c90b4c 8056d03b e1011340 00000000 899a53f0 nt!NtQueryInformationToken+0x89b&lt;br /&gt;b5c90bc4 80570402 00000000 b5c90c04 00000040 nt!NtQueryVolumeInformationFile+0x30&lt;br /&gt;b5c90c18 8057c24e 00000000 00000000 00000001 nt!CmpConstructName+0xb3&lt;br /&gt;b5c90c94 8057c31d 0203f914 80100080 0203f8b4 nt!NtQuerySystemInformation+0xd88&lt;br /&gt;b5c90cf0 8057c360 0203f914 80100080 0203f8b4 nt!NtQuerySystemInformation+0xe59&lt;br /&gt;b5c90d30 804dd98f 0203f914 80100080 0203f8b4 nt!NtQuerySystemInformation+0xe9c&lt;br /&gt;b5c90d44 00000000 00000080 00000001 00000001 nt!ZwSetSystemInformation+0x13&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;STACK_COMMAND:  kb&lt;br /&gt;&lt;br /&gt;FOLLOWUP_IP:&lt;br /&gt;nt!MiRemoveUnusedSegments+3db&lt;br /&gt;80537672 5d              pop     ebp&lt;br /&gt;&lt;br /&gt;SYMBOL_STACK_INDEX:  0&lt;br /&gt;&lt;br /&gt;SYMBOL_NAME:  nt!MiRemoveUnusedSegments+3db&lt;br /&gt;&lt;br /&gt;FOLLOWUP_NAME:  MachineOwner&lt;br /&gt;&lt;br /&gt;MODULE_NAME: nt&lt;br /&gt;&lt;br /&gt;DEBUG_FLR_IMAGE_TIMESTAMP:  48025de7&lt;br /&gt;&lt;br /&gt;IMAGE_NAME:  memory_corruption&lt;br /&gt;&lt;br /&gt;FAILURE_BUCKET_ID:  0xc2_7_nt!MiRemoveUnusedSegments+3db&lt;br /&gt;&lt;br /&gt;BUCKET_ID:  0xc2_7_nt!MiRemoveUnusedSegments+3db&lt;br /&gt;&lt;br /&gt;Followup: MachineOwner&lt;br /&gt;---------&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/code&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2941007113477861308-4335367045216566744?l=mybluescreen.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mybluescreen.blogspot.com/feeds/4335367045216566744/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2941007113477861308&amp;postID=4335367045216566744' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2941007113477861308/posts/default/4335367045216566744'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2941007113477861308/posts/default/4335367045216566744'/><link rel='alternate' type='text/html' href='http://mybluescreen.blogspot.com/2008/06/probably-caused-by-memorycorruption_9285.html' title='Probably caused by : memory_corruption ( nt!MiRemoveUnusedSegments+3db )'/><author><name>Allex Radu</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2941007113477861308.post-9018709872596871286</id><published>2008-06-20T05:51:00.000-07:00</published><updated>2008-06-20T05:52:36.411-07:00</updated><title type='text'>Probably caused by : aswSP.SYS ( aswSP+89c7 )</title><content type='html'>&lt;code&gt;Microsoft (R) Windows Debugger Version 6.9.0003.113 X86&lt;br /&gt;Copyright (c) Microsoft Corporation. All rights reserved.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Loading Dump File [c:\windows\minidump\Mini061608-01.dmp]&lt;br /&gt;Mini Kernel Dump File: Only registers and stack trace are available&lt;br /&gt;&lt;br /&gt;Symbol search path is: c:\windows\symbols&lt;br /&gt;Executable search path is: c:\windows\i386&lt;br /&gt;Unable to load image ntoskrnl.exe, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for ntoskrnl.exe&lt;br /&gt;Windows XP Kernel Version 2600 (Service Pack 3) MP (4 procs) Free x86 compatible&lt;br /&gt;Product: WinNt, suite: TerminalServer SingleUserTS&lt;br /&gt;Kernel base = 0x804d7000 PsLoadedModuleList = 0x805634c0&lt;br /&gt;Debug session time: Mon Jun 16 00:01:55.437 2008 (GMT+3)&lt;br /&gt;System Uptime: 0 days 12:23:47.431&lt;br /&gt;Unable to load image ntoskrnl.exe, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for ntoskrnl.exe&lt;br /&gt;Loading Kernel Symbols&lt;br /&gt;.....................................................................................................................................&lt;br /&gt;Loading User Symbols&lt;br /&gt;Loading unloaded module list&lt;br /&gt;....................&lt;br /&gt;*******************************************************************************&lt;br /&gt;*                                                                             *&lt;br /&gt;*                        Bugcheck Analysis                                    *&lt;br /&gt;*                                                                             *&lt;br /&gt;*******************************************************************************&lt;br /&gt;&lt;br /&gt;Use !analyze -v to get detailed debugging information.&lt;br /&gt;&lt;br /&gt;BugCheck C2, {7, cd4, 6e006f, e17c3980}&lt;br /&gt;&lt;br /&gt;Unable to load image aswSP.SYS, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for aswSP.SYS&lt;br /&gt;*** ERROR: Module load completed but symbols could not be loaded for aswSP.SYS&lt;br /&gt;GetUlongFromAddress: unable to read from 805637f0&lt;br /&gt;Probably caused by : aswSP.SYS ( aswSP+89c7 )&lt;br /&gt;&lt;br /&gt;Followup: MachineOwner&lt;br /&gt;---------&lt;br /&gt;&lt;br /&gt;2: kd&gt; !analyze -v&lt;br /&gt;*******************************************************************************&lt;br /&gt;*                                                                             *&lt;br /&gt;*                        Bugcheck Analysis                                    *&lt;br /&gt;*                                                                             *&lt;br /&gt;*******************************************************************************&lt;br /&gt;&lt;br /&gt;BAD_POOL_CALLER (c2)&lt;br /&gt;The current thread is making a bad pool request.  Typically this is at a bad IRQL level or double freeing the same allocation, etc.&lt;br /&gt;Arguments:&lt;br /&gt;Arg1: 00000007, Attempt to free pool which was already freed&lt;br /&gt;Arg2: 00000cd4, (reserved)&lt;br /&gt;Arg3: 006e006f, Memory contents of the pool block&lt;br /&gt;Arg4: e17c3980, Address of the block of pool being deallocated&lt;br /&gt;&lt;br /&gt;Debugging Details:&lt;br /&gt;------------------&lt;br /&gt;&lt;br /&gt;GetUlongFromAddress: unable to read from 805637f0&lt;br /&gt;&lt;br /&gt;POOL_ADDRESS:  e17c3980&lt;br /&gt;&lt;br /&gt;BUGCHECK_STR:  0xc2_7&lt;br /&gt;&lt;br /&gt;CUSTOMER_CRASH_COUNT:  1&lt;br /&gt;&lt;br /&gt;DEFAULT_BUCKET_ID:  DRIVER_FAULT&lt;br /&gt;&lt;br /&gt;PROCESS_NAME:  msiexec.exe&lt;br /&gt;&lt;br /&gt;LAST_CONTROL_TRANSFER:  from 80551fc5 to 80537672&lt;br /&gt;&lt;br /&gt;STACK_TEXT: &lt;br /&gt;9f949bd8 80551fc5 000000c2 00000007 00000cd4 nt!MiRemoveUnusedSegments+0x3db&lt;br /&gt;9f949c28 80585703 e17c3980 00000000 d56b2f4c nt!KiProfileLock+0x1&lt;br /&gt;9f949c44 805922ff e1055f08 e10470d8 00000000 nt!CcPfBuildDumpFromTrace+0x47&lt;br /&gt;9f949c9c 8059207f e1055f08 009a0098 06395df4 nt!FsRtlAddToTunnelCache+0x1a6&lt;br /&gt;9f949d14 b762d9c7 00000300 00beee68 28f7fab5 nt!RtlUnicodeToOemN+0x197&lt;br /&gt;WARNING: Stack unwind information not available. Following frames may be wrong.&lt;br /&gt;9f949d54 804dd98f 00000300 00beee68 00beee50 aswSP+0x89c7&lt;br /&gt;9f949d58 00000000 00beee68 00beee50 7c90e4f4 nt!ZwSetSystemInformation+0x13&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;STACK_COMMAND:  kb&lt;br /&gt;&lt;br /&gt;FOLLOWUP_IP:&lt;br /&gt;aswSP+89c7&lt;br /&gt;b762d9c7 ??              ???&lt;br /&gt;&lt;br /&gt;SYMBOL_STACK_INDEX:  5&lt;br /&gt;&lt;br /&gt;SYMBOL_NAME:  aswSP+89c7&lt;br /&gt;&lt;br /&gt;FOLLOWUP_NAME:  MachineOwner&lt;br /&gt;&lt;br /&gt;MODULE_NAME: aswSP&lt;br /&gt;&lt;br /&gt;IMAGE_NAME:  aswSP.SYS&lt;br /&gt;&lt;br /&gt;DEBUG_FLR_IMAGE_TIMESTAMP:  482cc53e&lt;br /&gt;&lt;br /&gt;FAILURE_BUCKET_ID:  0xc2_7_aswSP+89c7&lt;br /&gt;&lt;br /&gt;BUCKET_ID:  0xc2_7_aswSP+89c7&lt;br /&gt;&lt;br /&gt;Followup: MachineOwner&lt;br /&gt;---------&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/code&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2941007113477861308-9018709872596871286?l=mybluescreen.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mybluescreen.blogspot.com/feeds/9018709872596871286/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2941007113477861308&amp;postID=9018709872596871286' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2941007113477861308/posts/default/9018709872596871286'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2941007113477861308/posts/default/9018709872596871286'/><link rel='alternate' type='text/html' href='http://mybluescreen.blogspot.com/2008/06/probably-caused-by-aswspsys-aswsp89c7.html' title='Probably caused by : aswSP.SYS ( aswSP+89c7 )'/><author><name>Allex Radu</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2941007113477861308.post-5733812855579449916</id><published>2008-06-20T05:49:00.000-07:00</published><updated>2008-06-20T05:50:50.043-07:00</updated><title type='text'>Probably caused by : memory_corruption ( nt!MiRemoveUnusedSegments+3db )</title><content type='html'>&lt;code&gt;Microsoft (R) Windows Debugger Version 6.9.0003.113 X86&lt;br /&gt;Copyright (c) Microsoft Corporation. All rights reserved.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Loading Dump File [c:\windows\minidump\Mini061508-01.dmp]&lt;br /&gt;Mini Kernel Dump File: Only registers and stack trace are available&lt;br /&gt;&lt;br /&gt;Symbol search path is: c:\windows\symbols&lt;br /&gt;Executable search path is: c:\windows\i386&lt;br /&gt;Unable to load image ntoskrnl.exe, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for ntoskrnl.exe&lt;br /&gt;Windows XP Kernel Version 2600 (Service Pack 3) MP (4 procs) Free x86 compatible&lt;br /&gt;Product: WinNt, suite: TerminalServer SingleUserTS&lt;br /&gt;Kernel base = 0x804d7000 PsLoadedModuleList = 0x805634c0&lt;br /&gt;Debug session time: Sun Jun 15 10:34:01.031 2008 (GMT+3)&lt;br /&gt;System Uptime: 0 days 4:00:44.004&lt;br /&gt;Unable to load image ntoskrnl.exe, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for ntoskrnl.exe&lt;br /&gt;Loading Kernel Symbols&lt;br /&gt;.....................................................................................................................................&lt;br /&gt;Loading User Symbols&lt;br /&gt;Loading unloaded module list&lt;br /&gt;.............&lt;br /&gt;*******************************************************************************&lt;br /&gt;*                                                                             *&lt;br /&gt;*                        Bugcheck Analysis                                    *&lt;br /&gt;*                                                                             *&lt;br /&gt;*******************************************************************************&lt;br /&gt;&lt;br /&gt;Use !analyze -v to get detailed debugging information.&lt;br /&gt;&lt;br /&gt;BugCheck C2, {7, cd4, 660072, e35e6508}&lt;br /&gt;&lt;br /&gt;GetUlongFromAddress: unable to read from 805637f0&lt;br /&gt;GetUlongFromAddress: unable to read from 805637f0&lt;br /&gt;Probably caused by : memory_corruption ( nt!MiRemoveUnusedSegments+3db )&lt;br /&gt;&lt;br /&gt;Followup: MachineOwner&lt;br /&gt;---------&lt;br /&gt;&lt;br /&gt;1: kd&gt; !analyze -v&lt;br /&gt;*******************************************************************************&lt;br /&gt;*                                                                             *&lt;br /&gt;*                        Bugcheck Analysis                                    *&lt;br /&gt;*                                                                             *&lt;br /&gt;*******************************************************************************&lt;br /&gt;&lt;br /&gt;BAD_POOL_CALLER (c2)&lt;br /&gt;The current thread is making a bad pool request.  Typically this is at a bad IRQL level or double freeing the same allocation, etc.&lt;br /&gt;Arguments:&lt;br /&gt;Arg1: 00000007, Attempt to free pool which was already freed&lt;br /&gt;Arg2: 00000cd4, (reserved)&lt;br /&gt;Arg3: 00660072, Memory contents of the pool block&lt;br /&gt;Arg4: e35e6508, Address of the block of pool being deallocated&lt;br /&gt;&lt;br /&gt;Debugging Details:&lt;br /&gt;------------------&lt;br /&gt;&lt;br /&gt;GetUlongFromAddress: unable to read from 805637f0&lt;br /&gt;GetUlongFromAddress: unable to read from 805637f0&lt;br /&gt;&lt;br /&gt;POOL_ADDRESS:  e35e6508&lt;br /&gt;&lt;br /&gt;BUGCHECK_STR:  0xc2_7&lt;br /&gt;&lt;br /&gt;CUSTOMER_CRASH_COUNT:  1&lt;br /&gt;&lt;br /&gt;DEFAULT_BUCKET_ID:  DRIVER_FAULT&lt;br /&gt;&lt;br /&gt;PROCESS_NAME:  csrss.exe&lt;br /&gt;&lt;br /&gt;LAST_CONTROL_TRANSFER:  from 80551fc5 to 80537672&lt;br /&gt;&lt;br /&gt;STACK_TEXT: &lt;br /&gt;b9f51a54 80551fc5 000000c2 00000007 00000cd4 nt!MiRemoveUnusedSegments+0x3db&lt;br /&gt;b9f51aa4 8056ec09 e35e6508 00000000 e1616a60 nt!KiProfileLock+0x1&lt;br /&gt;b9f51b00 8056d03b e1616a78 00000000 88111538 nt!NtQueryInformationToken+0x89b&lt;br /&gt;b9f51b78 80570402 00000000 b9f51bb8 00000040 nt!NtQueryVolumeInformationFile+0x30&lt;br /&gt;b9f51bcc 80585018 00000000 00000000 00000001 nt!CmpConstructName+0xb3&lt;br /&gt;b9f51d54 804dd98f 00c8ead4 00c8ea9c 00c8eb00 nt!MiCreateImageFileMap+0x9ba&lt;br /&gt;b9f51d60 00c8eb00 7c90e4f4 badb0d00 00c8ea88 nt!ZwSetSystemInformation+0x13&lt;br /&gt;WARNING: Frame IP not in any known module. Following frames may be wrong.&lt;br /&gt;b9f51d64 7c90e4f4 badb0d00 00c8ea88 00000000 0xc8eb00&lt;br /&gt;b9f51d68 badb0d00 00c8ea88 00000000 00000000 0x7c90e4f4&lt;br /&gt;b9f51d6c 00c8ea88 00000000 00000000 00000000 0xbadb0d00&lt;br /&gt;b9f51d70 00000000 00000000 00000000 00000000 0xc8ea88&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;STACK_COMMAND:  kb&lt;br /&gt;&lt;br /&gt;FOLLOWUP_IP:&lt;br /&gt;nt!MiRemoveUnusedSegments+3db&lt;br /&gt;80537672 5d              pop     ebp&lt;br /&gt;&lt;br /&gt;SYMBOL_STACK_INDEX:  0&lt;br /&gt;&lt;br /&gt;SYMBOL_NAME:  nt!MiRemoveUnusedSegments+3db&lt;br /&gt;&lt;br /&gt;FOLLOWUP_NAME:  MachineOwner&lt;br /&gt;&lt;br /&gt;MODULE_NAME: nt&lt;br /&gt;&lt;br /&gt;DEBUG_FLR_IMAGE_TIMESTAMP:  48025de7&lt;br /&gt;&lt;br /&gt;IMAGE_NAME:  memory_corruption&lt;br /&gt;&lt;br /&gt;FAILURE_BUCKET_ID:  0xc2_7_nt!MiRemoveUnusedSegments+3db&lt;br /&gt;&lt;br /&gt;BUCKET_ID:  0xc2_7_nt!MiRemoveUnusedSegments+3db&lt;br /&gt;&lt;br /&gt;Followup: MachineOwner&lt;br /&gt;---------&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/code&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2941007113477861308-5733812855579449916?l=mybluescreen.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mybluescreen.blogspot.com/feeds/5733812855579449916/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2941007113477861308&amp;postID=5733812855579449916' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2941007113477861308/posts/default/5733812855579449916'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2941007113477861308/posts/default/5733812855579449916'/><link rel='alternate' type='text/html' href='http://mybluescreen.blogspot.com/2008/06/probably-caused-by-memorycorruption_1146.html' title='Probably caused by : memory_corruption ( nt!MiRemoveUnusedSegments+3db )'/><author><name>Allex Radu</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2941007113477861308.post-1830506977030073864</id><published>2008-06-20T05:46:00.000-07:00</published><updated>2008-06-20T05:47:46.382-07:00</updated><title type='text'>Probably caused by : win32k.sys ( win32k!AllocCallbackMessage+3 )</title><content type='html'>&lt;code&gt;Microsoft (R) Windows Debugger Version 6.9.0003.113 X86&lt;br /&gt;Copyright (c) Microsoft Corporation. All rights reserved.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Loading Dump File [c:\windows\minidump\Mini061408-02.dmp]&lt;br /&gt;Mini Kernel Dump File: Only registers and stack trace are available&lt;br /&gt;&lt;br /&gt;Symbol search path is: c:\windows\symbols&lt;br /&gt;Executable search path is: c:\windows\i386&lt;br /&gt;Unable to load image ntoskrnl.exe, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for ntoskrnl.exe&lt;br /&gt;Windows XP Kernel Version 2600 (Service Pack 3) MP (4 procs) Free x86 compatible&lt;br /&gt;Product: WinNt, suite: TerminalServer SingleUserTS&lt;br /&gt;Kernel base = 0x804d7000 PsLoadedModuleList = 0x805634c0&lt;br /&gt;Debug session time: Sat Jun 14 19:04:44.921 2008 (GMT+3)&lt;br /&gt;System Uptime: 0 days 3:25:17.532&lt;br /&gt;Unable to load image ntoskrnl.exe, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for ntoskrnl.exe&lt;br /&gt;Loading Kernel Symbols&lt;br /&gt;.....................................................................................................................................&lt;br /&gt;Loading User Symbols&lt;br /&gt;Loading unloaded module list&lt;br /&gt;...........&lt;br /&gt;Unable to load image win32k.sys, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for win32k.sys&lt;br /&gt;*******************************************************************************&lt;br /&gt;*                                                                             *&lt;br /&gt;*                        Bugcheck Analysis                                    *&lt;br /&gt;*                                                                             *&lt;br /&gt;*******************************************************************************&lt;br /&gt;&lt;br /&gt;Use !analyze -v to get detailed debugging information.&lt;br /&gt;&lt;br /&gt;BugCheck 1000007F, {d, 0, 0, 0}&lt;br /&gt;&lt;br /&gt;Probably caused by : win32k.sys ( win32k!AllocCallbackMessage+3 )&lt;br /&gt;&lt;br /&gt;Followup: MachineOwner&lt;br /&gt;---------&lt;br /&gt;&lt;br /&gt;3: kd&gt; !analyze -v&lt;br /&gt;*******************************************************************************&lt;br /&gt;*                                                                             *&lt;br /&gt;*                        Bugcheck Analysis                                    *&lt;br /&gt;*                                                                             *&lt;br /&gt;*******************************************************************************&lt;br /&gt;&lt;br /&gt;UNEXPECTED_KERNEL_MODE_TRAP_M (1000007f)&lt;br /&gt;This means a trap occurred in kernel mode, and it's a trap of a kind&lt;br /&gt;that the kernel isn't allowed to have/catch (bound trap) or that&lt;br /&gt;is always instant death (double fault).  The first number in the&lt;br /&gt;bugcheck params is the number of the trap (8 = double fault, etc)&lt;br /&gt;Consult an Intel x86 family manual to learn more about what these&lt;br /&gt;traps are. Here is a *portion* of those codes:&lt;br /&gt;If kv shows a taskGate&lt;br /&gt;       use .tss on the part before the colon, then kv.&lt;br /&gt;Else if kv shows a trapframe&lt;br /&gt;       use .trap on that value&lt;br /&gt;Else&lt;br /&gt;       .trap on the appropriate frame will show where the trap was taken&lt;br /&gt;       (on x86, this will be the ebp that goes with the procedure KiTrap)&lt;br /&gt;Endif&lt;br /&gt;kb will then show the corrected stack.&lt;br /&gt;Arguments:&lt;br /&gt;Arg1: 0000000d, EXCEPTION_GP_FAULT&lt;br /&gt;Arg2: 00000000&lt;br /&gt;Arg3: 00000000&lt;br /&gt;Arg4: 00000000&lt;br /&gt;&lt;br /&gt;Debugging Details:&lt;br /&gt;------------------&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;BUGCHECK_STR:  0x7f_d&lt;br /&gt;&lt;br /&gt;CUSTOMER_CRASH_COUNT:  2&lt;br /&gt;&lt;br /&gt;DEFAULT_BUCKET_ID:  DRIVER_FAULT&lt;br /&gt;&lt;br /&gt;PROCESS_NAME:  explorer.exe&lt;br /&gt;&lt;br /&gt;LAST_CONTROL_TRANSFER:  from bf8586fa to bf8346ec&lt;br /&gt;&lt;br /&gt;STACK_TEXT: &lt;br /&gt;a2fef920 bf8586fa 0000003c 00000001 000003c0 win32k!AllocCallbackMessage+0x3&lt;br /&gt;a2fefbf4 bf813f31 bc78cc10 0000004a 000102c6 win32k!SfnCOPYDATA+0x85&lt;br /&gt;a2fefc3c bf8419f1 0078cc10 0000004a 000102c6 win32k!xxxSendMessageToClient+0x176&lt;br /&gt;a2fefcac bf801eda e326e008 a2fefd64 00000000 win32k!xxxReceiveMessage+0x2b5&lt;br /&gt;a2fefce8 bf8036ec a2fefd14 000025ff 00000000 win32k!xxxRealInternalGetMessage+0x1d7&lt;br /&gt;a2fefd48 804dd98f 0148ff28 00000000 00000000 win32k!NtUserPeekMessage+0x40&lt;br /&gt;a2fefd60 0148fed4 7c90e4f4 badb0d00 0148feb4 nt!ZwSetSystemInformation+0x13&lt;br /&gt;WARNING: Frame IP not in any known module. Following frames may be wrong.&lt;br /&gt;a2fefd64 7c90e4f4 badb0d00 0148feb4 00000000 0x148fed4&lt;br /&gt;a2fefd68 badb0d00 0148feb4 00000000 00000000 0x7c90e4f4&lt;br /&gt;a2fefd6c 0148feb4 00000000 00000000 00000000 0xbadb0d00&lt;br /&gt;a2fefd70 00000000 00000000 00000000 00000000 0x148feb4&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;STACK_COMMAND:  kb&lt;br /&gt;&lt;br /&gt;FOLLOWUP_IP:&lt;br /&gt;win32k!AllocCallbackMessage+3&lt;br /&gt;bf8346ec cb              retf&lt;br /&gt;&lt;br /&gt;SYMBOL_STACK_INDEX:  0&lt;br /&gt;&lt;br /&gt;SYMBOL_NAME:  win32k!AllocCallbackMessage+3&lt;br /&gt;&lt;br /&gt;FOLLOWUP_NAME:  MachineOwner&lt;br /&gt;&lt;br /&gt;MODULE_NAME: win32k&lt;br /&gt;&lt;br /&gt;IMAGE_NAME:  win32k.sys&lt;br /&gt;&lt;br /&gt;DEBUG_FLR_IMAGE_TIMESTAMP:  48025f2a&lt;br /&gt;&lt;br /&gt;FAILURE_BUCKET_ID:  0x7f_d_win32k!AllocCallbackMessage+3&lt;br /&gt;&lt;br /&gt;BUCKET_ID:  0x7f_d_win32k!AllocCallbackMessage+3&lt;br /&gt;&lt;br /&gt;Followup: MachineOwner&lt;br /&gt;---------&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/code&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2941007113477861308-1830506977030073864?l=mybluescreen.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mybluescreen.blogspot.com/feeds/1830506977030073864/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2941007113477861308&amp;postID=1830506977030073864' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2941007113477861308/posts/default/1830506977030073864'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2941007113477861308/posts/default/1830506977030073864'/><link rel='alternate' type='text/html' href='http://mybluescreen.blogspot.com/2008/06/probably-caused-by-win32ksys.html' title='Probably caused by : win32k.sys ( win32k!AllocCallbackMessage+3 )'/><author><name>Allex Radu</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2941007113477861308.post-5668752323834620911</id><published>2008-06-20T05:43:00.000-07:00</published><updated>2008-06-20T05:46:00.866-07:00</updated><title type='text'>Probably caused by : a347bus.sys ( a347bus+1c2b )</title><content type='html'>&lt;code&gt;Microsoft (R) Windows Debugger Version 6.9.0003.113 X86&lt;br /&gt;Copyright (c) Microsoft Corporation. All rights reserved.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Loading Dump File [c:\windows\minidump\Mini061408-01.dmp]&lt;br /&gt;Mini Kernel Dump File: Only registers and stack trace are available&lt;br /&gt;&lt;br /&gt;Symbol search path is: c:\windows\symbols&lt;br /&gt;Executable search path is: c:\windows\i386&lt;br /&gt;Unable to load image ntoskrnl.exe, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for ntoskrnl.exe&lt;br /&gt;Windows XP Kernel Version 2600 (Service Pack 3) MP (4 procs) Free x86 compatible&lt;br /&gt;Product: WinNt, suite: TerminalServer SingleUserTS&lt;br /&gt;Kernel base = 0x804d7000 PsLoadedModuleList = 0x805634c0&lt;br /&gt;Debug session time: Sat Jun 14 15:38:50.828 2008 (GMT+3)&lt;br /&gt;System Uptime: 0 days 3:24:37.800&lt;br /&gt;Unable to load image ntoskrnl.exe, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for ntoskrnl.exe&lt;br /&gt;Loading Kernel Symbols&lt;br /&gt;.......................................................................................................................................&lt;br /&gt;Loading User Symbols&lt;br /&gt;Loading unloaded module list&lt;br /&gt;............&lt;br /&gt;*******************************************************************************&lt;br /&gt;*                                                                             *&lt;br /&gt;*                        Bugcheck Analysis                                    *&lt;br /&gt;*                                                                             *&lt;br /&gt;*******************************************************************************&lt;br /&gt;&lt;br /&gt;Use !analyze -v to get detailed debugging information.&lt;br /&gt;&lt;br /&gt;BugCheck C2, {7, cd4, 660072, e14bca08}&lt;br /&gt;&lt;br /&gt;Unable to load image a347bus.sys, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for a347bus.sys&lt;br /&gt;*** ERROR: Module load completed but symbols could not be loaded for a347bus.sys&lt;br /&gt;GetUlongFromAddress: unable to read from 805637f0&lt;br /&gt;Probably caused by : a347bus.sys ( a347bus+1c2b )&lt;br /&gt;&lt;br /&gt;Followup: MachineOwner&lt;br /&gt;---------&lt;br /&gt;&lt;br /&gt;1: kd&gt; !analyze -v&lt;br /&gt;*******************************************************************************&lt;br /&gt;*                                                                             *&lt;br /&gt;*                        Bugcheck Analysis                                    *&lt;br /&gt;*                                                                             *&lt;br /&gt;*******************************************************************************&lt;br /&gt;&lt;br /&gt;BAD_POOL_CALLER (c2)&lt;br /&gt;The current thread is making a bad pool request.  Typically this is at a bad IRQL level or double freeing the same allocation, etc.&lt;br /&gt;Arguments:&lt;br /&gt;Arg1: 00000007, Attempt to free pool which was already freed&lt;br /&gt;Arg2: 00000cd4, (reserved)&lt;br /&gt;Arg3: 00660072, Memory contents of the pool block&lt;br /&gt;Arg4: e14bca08, Address of the block of pool being deallocated&lt;br /&gt;&lt;br /&gt;Debugging Details:&lt;br /&gt;------------------&lt;br /&gt;&lt;br /&gt;GetUlongFromAddress: unable to read from 805637f0&lt;br /&gt;&lt;br /&gt;POOL_ADDRESS:  e14bca08&lt;br /&gt;&lt;br /&gt;BUGCHECK_STR:  0xc2_7&lt;br /&gt;&lt;br /&gt;CUSTOMER_CRASH_COUNT:  1&lt;br /&gt;&lt;br /&gt;DEFAULT_BUCKET_ID:  DRIVER_FAULT&lt;br /&gt;&lt;br /&gt;PROCESS_NAME:  csrss.exe&lt;br /&gt;&lt;br /&gt;LAST_CONTROL_TRANSFER:  from 80551fc5 to 80537672&lt;br /&gt;&lt;br /&gt;STACK_TEXT: &lt;br /&gt;b7596a68 80551fc5 000000c2 00000007 00000cd4 nt!MiRemoveUnusedSegments+0x3db&lt;br /&gt;b7596ab8 8056ec09 e14bca08 00000000 e100a3d8 nt!KiProfileLock+0x1&lt;br /&gt;b7596b14 8056d03b e100a3f0 00000000 879def30 nt!NtQueryInformationToken+0x89b&lt;br /&gt;b7596b8c 80570402 00000000 b7596bcc 00000040 nt!NtQueryVolumeInformationFile+0x30&lt;br /&gt;b7596be0 8057c24e 00000000 00000000 00000001 nt!CmpConstructName+0xb3&lt;br /&gt;b7596c5c 8057c31d 00c8e194 00100001 00c8e138 nt!NtQuerySystemInformation+0xd88&lt;br /&gt;b7596cb8 8057c4cb 00c8e194 00100001 00c8e138 nt!NtQuerySystemInformation+0xe59&lt;br /&gt;b7596cf8 f75afc2b 00c8e194 00100001 00c8e138 nt!NtQuerySystemInformation+0x192&lt;br /&gt;WARNING: Stack unwind information not available. Following frames may be wrong.&lt;br /&gt;b7596d0c 00000000 00004021 b7596d64 00c8e12c a347bus+0x1c2b&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;STACK_COMMAND:  kb&lt;br /&gt;&lt;br /&gt;FOLLOWUP_IP:&lt;br /&gt;a347bus+1c2b&lt;br /&gt;f75afc2b ??              ???&lt;br /&gt;&lt;br /&gt;SYMBOL_STACK_INDEX:  8&lt;br /&gt;&lt;br /&gt;SYMBOL_NAME:  a347bus+1c2b&lt;br /&gt;&lt;br /&gt;FOLLOWUP_NAME:  MachineOwner&lt;br /&gt;&lt;br /&gt;MODULE_NAME: a347bus&lt;br /&gt;&lt;br /&gt;IMAGE_NAME:  a347bus.sys&lt;br /&gt;&lt;br /&gt;DEBUG_FLR_IMAGE_TIMESTAMP:  4091f40d&lt;br /&gt;&lt;br /&gt;FAILURE_BUCKET_ID:  0xc2_7_a347bus+1c2b&lt;br /&gt;&lt;br /&gt;BUCKET_ID:  0xc2_7_a347bus+1c2b&lt;br /&gt;&lt;br /&gt;Followup: MachineOwner&lt;br /&gt;---------&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/code&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2941007113477861308-5668752323834620911?l=mybluescreen.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mybluescreen.blogspot.com/feeds/5668752323834620911/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2941007113477861308&amp;postID=5668752323834620911' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2941007113477861308/posts/default/5668752323834620911'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2941007113477861308/posts/default/5668752323834620911'/><link rel='alternate' type='text/html' href='http://mybluescreen.blogspot.com/2008/06/probably-caused-by-a347bussys_6622.html' title='Probably caused by : a347bus.sys ( a347bus+1c2b )'/><author><name>Allex Radu</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2941007113477861308.post-2812868710714673105</id><published>2008-06-20T05:41:00.000-07:00</published><updated>2008-06-20T05:43:37.477-07:00</updated><title type='text'>Probably caused by : memory_corruption ( nt!MiRemoveUnusedSegments+3db )</title><content type='html'>&lt;code&gt;Microsoft (R) Windows Debugger Version 6.9.0003.113 X86&lt;br /&gt;Copyright (c) Microsoft Corporation. All rights reserved.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Loading Dump File [c:\windows\minidump\Mini061208-01.dmp]&lt;br /&gt;Mini Kernel Dump File: Only registers and stack trace are available&lt;br /&gt;&lt;br /&gt;Symbol search path is: c:\windows\symbols&lt;br /&gt;Executable search path is: c:\windows\i386&lt;br /&gt;Unable to load image ntoskrnl.exe, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for ntoskrnl.exe&lt;br /&gt;Windows XP Kernel Version 2600 (Service Pack 3) MP (4 procs) Free x86 compatible&lt;br /&gt;Product: WinNt, suite: TerminalServer SingleUserTS&lt;br /&gt;Kernel base = 0x804d7000 PsLoadedModuleList = 0x805634c0&lt;br /&gt;Debug session time: Thu Jun 12 19:05:03.906 2008 (GMT+3)&lt;br /&gt;System Uptime: 0 days 9:03:26.523&lt;br /&gt;Unable to load image ntoskrnl.exe, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for ntoskrnl.exe&lt;br /&gt;Loading Kernel Symbols&lt;br /&gt;.....................................................................................................................................&lt;br /&gt;Loading User Symbols&lt;br /&gt;Loading unloaded module list&lt;br /&gt;......................&lt;br /&gt;*******************************************************************************&lt;br /&gt;*                                                                             *&lt;br /&gt;*                        Bugcheck Analysis                                    *&lt;br /&gt;*                                                                             *&lt;br /&gt;*******************************************************************************&lt;br /&gt;&lt;br /&gt;Use !analyze -v to get detailed debugging information.&lt;br /&gt;&lt;br /&gt;BugCheck C2, {7, cd4, 660072, e4045270}&lt;br /&gt;&lt;br /&gt;GetUlongFromAddress: unable to read from 805637f0&lt;br /&gt;GetUlongFromAddress: unable to read from 805637f0&lt;br /&gt;Probably caused by : memory_corruption ( nt!MiRemoveUnusedSegments+3db )&lt;br /&gt;&lt;br /&gt;Followup: MachineOwner&lt;br /&gt;---------&lt;br /&gt;&lt;br /&gt;1: kd&gt; !analyze -v&lt;br /&gt;*******************************************************************************&lt;br /&gt;*                                                                             *&lt;br /&gt;*                        Bugcheck Analysis                                    *&lt;br /&gt;*                                                                             *&lt;br /&gt;*******************************************************************************&lt;br /&gt;&lt;br /&gt;BAD_POOL_CALLER (c2)&lt;br /&gt;The current thread is making a bad pool request.  Typically this is at a bad IRQL level or double freeing the same allocation, etc.&lt;br /&gt;Arguments:&lt;br /&gt;Arg1: 00000007, Attempt to free pool which was already freed&lt;br /&gt;Arg2: 00000cd4, (reserved)&lt;br /&gt;Arg3: 00660072, Memory contents of the pool block&lt;br /&gt;Arg4: e4045270, Address of the block of pool being deallocated&lt;br /&gt;&lt;br /&gt;Debugging Details:&lt;br /&gt;------------------&lt;br /&gt;&lt;br /&gt;GetUlongFromAddress: unable to read from 805637f0&lt;br /&gt;GetUlongFromAddress: unable to read from 805637f0&lt;br /&gt;&lt;br /&gt;POOL_ADDRESS:  e4045270&lt;br /&gt;&lt;br /&gt;BUGCHECK_STR:  0xc2_7&lt;br /&gt;&lt;br /&gt;CUSTOMER_CRASH_COUNT:  1&lt;br /&gt;&lt;br /&gt;DEFAULT_BUCKET_ID:  DRIVER_FAULT&lt;br /&gt;&lt;br /&gt;PROCESS_NAME:  explorer.exe&lt;br /&gt;&lt;br /&gt;LAST_CONTROL_TRANSFER:  from 80551fc5 to 80537672&lt;br /&gt;&lt;br /&gt;STACK_TEXT: &lt;br /&gt;b7cefa58 80551fc5 000000c2 00000007 00000cd4 nt!MiRemoveUnusedSegments+0x3db&lt;br /&gt;b7cefaa8 8056ec09 e4045270 00000000 e1572e18 nt!KiProfileLock+0x1&lt;br /&gt;b7cefb04 8056d03b e1572e30 00000000 8805f128 nt!NtQueryInformationToken+0x89b&lt;br /&gt;b7cefb7c 80570402 00000000 b7cefbbc 00000040 nt!NtQueryVolumeInformationFile+0x30&lt;br /&gt;b7cefbd0 8057c7c4 00000000 00000000 00000001 nt!CmpConstructName+0xb3&lt;br /&gt;b7cefd54 804dd98f 0148dda4 0148dd7c 0148ddd0 nt!NtQuerySystemInformation+0x48b&lt;br /&gt;b7cefd68 badb0d00 0148dd68 00000000 00000000 nt!ZwSetSystemInformation+0x13&lt;br /&gt;WARNING: Frame IP not in any known module. Following frames may be wrong.&lt;br /&gt;b7cefd78 00000000 00000000 00000000 00000000 0xbadb0d00&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;STACK_COMMAND:  kb&lt;br /&gt;&lt;br /&gt;FOLLOWUP_IP:&lt;br /&gt;nt!MiRemoveUnusedSegments+3db&lt;br /&gt;80537672 5d              pop     ebp&lt;br /&gt;&lt;br /&gt;SYMBOL_STACK_INDEX:  0&lt;br /&gt;&lt;br /&gt;SYMBOL_NAME:  nt!MiRemoveUnusedSegments+3db&lt;br /&gt;&lt;br /&gt;FOLLOWUP_NAME:  MachineOwner&lt;br /&gt;&lt;br /&gt;MODULE_NAME: nt&lt;br /&gt;&lt;br /&gt;DEBUG_FLR_IMAGE_TIMESTAMP:  48025de7&lt;br /&gt;&lt;br /&gt;IMAGE_NAME:  memory_corruption&lt;br /&gt;&lt;br /&gt;FAILURE_BUCKET_ID:  0xc2_7_nt!MiRemoveUnusedSegments+3db&lt;br /&gt;&lt;br /&gt;BUCKET_ID:  0xc2_7_nt!MiRemoveUnusedSegments+3db&lt;br /&gt;&lt;br /&gt;Followup: MachineOwner&lt;br /&gt;---------&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/code&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2941007113477861308-2812868710714673105?l=mybluescreen.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mybluescreen.blogspot.com/feeds/2812868710714673105/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2941007113477861308&amp;postID=2812868710714673105' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2941007113477861308/posts/default/2812868710714673105'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2941007113477861308/posts/default/2812868710714673105'/><link rel='alternate' type='text/html' href='http://mybluescreen.blogspot.com/2008/06/probably-caused-by-memorycorruption_3133.html' title='Probably caused by : memory_corruption ( nt!MiRemoveUnusedSegments+3db )'/><author><name>Allex Radu</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2941007113477861308.post-2808886014613614183</id><published>2008-06-20T05:39:00.000-07:00</published><updated>2008-06-20T05:41:40.989-07:00</updated><title type='text'>Probably caused by : ntoskrnl.exe ( nt!RtlPrefetchCopyMemory32+2f )</title><content type='html'>&lt;code&gt;Microsoft (R) Windows Debugger Version 6.9.0003.113 X86&lt;br /&gt;Copyright (c) Microsoft Corporation. All rights reserved.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Loading Dump File [c:\windows\minidump\Mini061108-02.dmp]&lt;br /&gt;Mini Kernel Dump File: Only registers and stack trace are available&lt;br /&gt;&lt;br /&gt;Symbol search path is: c:\windows\symbols&lt;br /&gt;Executable search path is: c:\windows\i386&lt;br /&gt;Unable to load image ntoskrnl.exe, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for ntoskrnl.exe&lt;br /&gt;Windows XP Kernel Version 2600 (Service Pack 3) MP (4 procs) Free x86 compatible&lt;br /&gt;Product: WinNt, suite: TerminalServer SingleUserTS&lt;br /&gt;Kernel base = 0x804d7000 PsLoadedModuleList = 0x805634c0&lt;br /&gt;Debug session time: Wed Jun 11 13:05:27.593 2008 (GMT+3)&lt;br /&gt;System Uptime: 0 days 0:55:12.187&lt;br /&gt;Unable to load image ntoskrnl.exe, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for ntoskrnl.exe&lt;br /&gt;Loading Kernel Symbols&lt;br /&gt;.....................................................................................................................................&lt;br /&gt;Loading User Symbols&lt;br /&gt;Loading unloaded module list&lt;br /&gt;...........&lt;br /&gt;*******************************************************************************&lt;br /&gt;*                                                                             *&lt;br /&gt;*                        Bugcheck Analysis                                    *&lt;br /&gt;*                                                                             *&lt;br /&gt;*******************************************************************************&lt;br /&gt;&lt;br /&gt;Use !analyze -v to get detailed debugging information.&lt;br /&gt;&lt;br /&gt;BugCheck 10000050, {e3a90ffc, 1, 804dafed, 1}&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Could not read faulting driver name&lt;br /&gt;Probably caused by : ntoskrnl.exe ( nt!RtlPrefetchCopyMemory32+2f )&lt;br /&gt;&lt;br /&gt;Followup: MachineOwner&lt;br /&gt;---------&lt;br /&gt;&lt;br /&gt;2: kd&gt; !analyze -v&lt;br /&gt;*******************************************************************************&lt;br /&gt;*                                                                             *&lt;br /&gt;*                        Bugcheck Analysis                                    *&lt;br /&gt;*                                                                             *&lt;br /&gt;*******************************************************************************&lt;br /&gt;&lt;br /&gt;PAGE_FAULT_IN_NONPAGED_AREA (50)&lt;br /&gt;Invalid system memory was referenced.  This cannot be protected by try-except,&lt;br /&gt;it must be protected by a Probe.  Typically the address is just plain bad or it&lt;br /&gt;is pointing at freed memory.&lt;br /&gt;Arguments:&lt;br /&gt;Arg1: e3a90ffc, memory referenced.&lt;br /&gt;Arg2: 00000001, value 0 = read operation, 1 = write operation.&lt;br /&gt;Arg3: 804dafed, If non-zero, the instruction address which referenced the bad memory&lt;br /&gt;address.&lt;br /&gt;Arg4: 00000001, (reserved)&lt;br /&gt;&lt;br /&gt;Debugging Details:&lt;br /&gt;------------------&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Could not read faulting driver name&lt;br /&gt;&lt;br /&gt;WRITE_ADDRESS:  e3a90ffc&lt;br /&gt;&lt;br /&gt;FAULTING_IP:&lt;br /&gt;nt!RtlPrefetchCopyMemory32+2f&lt;br /&gt;804dafed f3a5            rep movs dword ptr es:[edi],dword ptr [esi]&lt;br /&gt;&lt;br /&gt;MM_INTERNAL_CODE:  1&lt;br /&gt;&lt;br /&gt;CUSTOMER_CRASH_COUNT:  2&lt;br /&gt;&lt;br /&gt;DEFAULT_BUCKET_ID:  DRIVER_FAULT&lt;br /&gt;&lt;br /&gt;BUGCHECK_STR:  0x50&lt;br /&gt;&lt;br /&gt;PROCESS_NAME:  iPodService.exe&lt;br /&gt;&lt;br /&gt;LAST_CONTROL_TRANSFER:  from 8056d84a to 804dafed&lt;br /&gt;&lt;br /&gt;STACK_TEXT:&lt;br /&gt;b6197bcc 8056d84a e3a9102a e3a91014 0000003c nt!RtlPrefetchCopyMemory32+0x2f&lt;br /&gt;b6197c2c 8056d03b e1713330 8a1af708 89e40a20 nt!HvpGetCellMap+0xc&lt;br /&gt;b6197c40 00000000 b6197ce4 b6197c70 00000000 nt!NtQueryVolumeInformationFile+0x30&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;STACK_COMMAND:  kb&lt;br /&gt;&lt;br /&gt;FOLLOWUP_IP:&lt;br /&gt;nt!RtlPrefetchCopyMemory32+2f&lt;br /&gt;804dafed f3a5            rep movs dword ptr es:[edi],dword ptr [esi]&lt;br /&gt;&lt;br /&gt;SYMBOL_STACK_INDEX:  0&lt;br /&gt;&lt;br /&gt;SYMBOL_NAME:  nt!RtlPrefetchCopyMemory32+2f&lt;br /&gt;&lt;br /&gt;FOLLOWUP_NAME:  MachineOwner&lt;br /&gt;&lt;br /&gt;MODULE_NAME: nt&lt;br /&gt;&lt;br /&gt;IMAGE_NAME:  ntoskrnl.exe&lt;br /&gt;&lt;br /&gt;DEBUG_FLR_IMAGE_TIMESTAMP:  48025de7&lt;br /&gt;&lt;br /&gt;FAILURE_BUCKET_ID:  0x50_W_nt!RtlPrefetchCopyMemory32+2f&lt;br /&gt;&lt;br /&gt;BUCKET_ID:  0x50_W_nt!RtlPrefetchCopyMemory32+2f&lt;br /&gt;&lt;br /&gt;Followup: MachineOwner&lt;br /&gt;---------&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/code&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2941007113477861308-2808886014613614183?l=mybluescreen.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mybluescreen.blogspot.com/feeds/2808886014613614183/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2941007113477861308&amp;postID=2808886014613614183' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2941007113477861308/posts/default/2808886014613614183'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2941007113477861308/posts/default/2808886014613614183'/><link rel='alternate' type='text/html' href='http://mybluescreen.blogspot.com/2008/06/analyze-v-bugcheck-analysis_20.html' title='Probably caused by : ntoskrnl.exe ( nt!RtlPrefetchCopyMemory32+2f )'/><author><name>Allex Radu</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2941007113477861308.post-3500428919871421501</id><published>2008-06-20T05:38:00.000-07:00</published><updated>2008-06-20T05:39:36.430-07:00</updated><title type='text'>Probably caused by : memory_corruption ( nt!MiRemoveUnusedSegments+3db )</title><content type='html'>&lt;code&gt;Microsoft (R) Windows Debugger Version 6.9.0003.113 X86&lt;br /&gt;Copyright (c) Microsoft Corporation. All rights reserved.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Loading Dump File [c:\windows\minidump\Mini061108-01.dmp]&lt;br /&gt;Mini Kernel Dump File: Only registers and stack trace are available&lt;br /&gt;&lt;br /&gt;Symbol search path is: c:\windows\symbols&lt;br /&gt;Executable search path is: c:\windows\i386&lt;br /&gt;Unable to load image ntoskrnl.exe, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for ntoskrnl.exe&lt;br /&gt;Windows XP Kernel Version 2600 (Service Pack 3) MP (4 procs) Free x86 compatible&lt;br /&gt;Product: WinNt, suite: TerminalServer SingleUserTS&lt;br /&gt;Kernel base = 0x804d7000 PsLoadedModuleList = 0x805634c0&lt;br /&gt;Debug session time: Wed Jun 11 12:09:47.015 2008 (GMT+3)&lt;br /&gt;System Uptime: 0 days 1:36:00.625&lt;br /&gt;Unable to load image ntoskrnl.exe, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for ntoskrnl.exe&lt;br /&gt;Loading Kernel Symbols&lt;br /&gt;.....................................................................................................................................&lt;br /&gt;Loading User Symbols&lt;br /&gt;Loading unloaded module list&lt;br /&gt;............&lt;br /&gt;*******************************************************************************&lt;br /&gt;*                                                                             *&lt;br /&gt;*                        Bugcheck Analysis                                    *&lt;br /&gt;*                                                                             *&lt;br /&gt;*******************************************************************************&lt;br /&gt;&lt;br /&gt;Use !analyze -v to get detailed debugging information.&lt;br /&gt;&lt;br /&gt;BugCheck C2, {7, cd4, 760045, e45823b8}&lt;br /&gt;&lt;br /&gt;GetUlongFromAddress: unable to read from 805637f0&lt;br /&gt;GetUlongFromAddress: unable to read from 805637f0&lt;br /&gt;Probably caused by : memory_corruption ( nt!MiRemoveUnusedSegments+3db )&lt;br /&gt;&lt;br /&gt;Followup: MachineOwner&lt;br /&gt;---------&lt;br /&gt;&lt;br /&gt;1: kd&gt; !analyze -v&lt;br /&gt;*******************************************************************************&lt;br /&gt;*                                                                             *&lt;br /&gt;*                        Bugcheck Analysis                                    *&lt;br /&gt;*                                                                             *&lt;br /&gt;*******************************************************************************&lt;br /&gt;&lt;br /&gt;BAD_POOL_CALLER (c2)&lt;br /&gt;The current thread is making a bad pool request.  Typically this is at a bad IRQL level or double freeing the same allocation, etc.&lt;br /&gt;Arguments:&lt;br /&gt;Arg1: 00000007, Attempt to free pool which was already freed&lt;br /&gt;Arg2: 00000cd4, (reserved)&lt;br /&gt;Arg3: 00760045, Memory contents of the pool block&lt;br /&gt;Arg4: e45823b8, Address of the block of pool being deallocated&lt;br /&gt;&lt;br /&gt;Debugging Details:&lt;br /&gt;------------------&lt;br /&gt;&lt;br /&gt;GetUlongFromAddress: unable to read from 805637f0&lt;br /&gt;GetUlongFromAddress: unable to read from 805637f0&lt;br /&gt;&lt;br /&gt;POOL_ADDRESS:  e45823b8&lt;br /&gt;&lt;br /&gt;BUGCHECK_STR:  0xc2_7&lt;br /&gt;&lt;br /&gt;CUSTOMER_CRASH_COUNT:  1&lt;br /&gt;&lt;br /&gt;DEFAULT_BUCKET_ID:  DRIVER_FAULT&lt;br /&gt;&lt;br /&gt;PROCESS_NAME:  ashServ.exe&lt;br /&gt;&lt;br /&gt;LAST_CONTROL_TRANSFER:  from 80551fc5 to 80537672&lt;br /&gt;&lt;br /&gt;STACK_TEXT: &lt;br /&gt;b72a5a58 80551fc5 000000c2 00000007 00000cd4 nt!MiRemoveUnusedSegments+0x3db&lt;br /&gt;b72a5aa8 8056ec09 e45823b8 00000000 e1604960 nt!KiProfileLock+0x1&lt;br /&gt;b72a5b04 8056d03b e1604978 00000000 87f8db48 nt!NtQueryInformationToken+0x89b&lt;br /&gt;b72a5b7c 80570402 00000000 b72a5bbc 00000040 nt!NtQueryVolumeInformationFile+0x30&lt;br /&gt;b72a5bd0 8057c7c4 00000000 00000000 00000001 nt!CmpConstructName+0xb3&lt;br /&gt;b72a5d54 804dd98f 018da398 018da370 018da3c4 nt!NtQuerySystemInformation+0x48b&lt;br /&gt;b72a5d68 badb0d00 018da35c 88181000 21010500 nt!ZwSetSystemInformation+0x13&lt;br /&gt;WARNING: Frame IP not in any known module. Following frames may be wrong.&lt;br /&gt;b72a5d78 00000000 00000000 00000000 00000000 0xbadb0d00&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;STACK_COMMAND:  kb&lt;br /&gt;&lt;br /&gt;FOLLOWUP_IP:&lt;br /&gt;nt!MiRemoveUnusedSegments+3db&lt;br /&gt;80537672 5d              pop     ebp&lt;br /&gt;&lt;br /&gt;SYMBOL_STACK_INDEX:  0&lt;br /&gt;&lt;br /&gt;SYMBOL_NAME:  nt!MiRemoveUnusedSegments+3db&lt;br /&gt;&lt;br /&gt;FOLLOWUP_NAME:  MachineOwner&lt;br /&gt;&lt;br /&gt;MODULE_NAME: nt&lt;br /&gt;&lt;br /&gt;DEBUG_FLR_IMAGE_TIMESTAMP:  48025de7&lt;br /&gt;&lt;br /&gt;IMAGE_NAME:  memory_corruption&lt;br /&gt;&lt;br /&gt;FAILURE_BUCKET_ID:  0xc2_7_nt!MiRemoveUnusedSegments+3db&lt;br /&gt;&lt;br /&gt;BUCKET_ID:  0xc2_7_nt!MiRemoveUnusedSegments+3db&lt;br /&gt;&lt;br /&gt;Followup: MachineOwner&lt;br /&gt;---------&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/code&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2941007113477861308-3500428919871421501?l=mybluescreen.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mybluescreen.blogspot.com/feeds/3500428919871421501/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2941007113477861308&amp;postID=3500428919871421501' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2941007113477861308/posts/default/3500428919871421501'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2941007113477861308/posts/default/3500428919871421501'/><link rel='alternate' type='text/html' href='http://mybluescreen.blogspot.com/2008/06/probably-caused-by-memorycorruption_20.html' title='Probably caused by : memory_corruption ( nt!MiRemoveUnusedSegments+3db )'/><author><name>Allex Radu</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2941007113477861308.post-620349431330546650</id><published>2008-06-20T05:33:00.000-07:00</published><updated>2008-06-20T05:36:41.123-07:00</updated><title type='text'>Probably caused by : aswMon2.SYS ( aswMon2+65a9 )</title><content type='html'>&lt;code&gt;Microsoft (R) Windows Debugger Version 6.9.0003.113 X86&lt;br /&gt;Copyright (c) Microsoft Corporation. All rights reserved.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Loading Dump File [c:\windows\minidump\Mini060908-03.dmp]&lt;br /&gt;Mini Kernel Dump File: Only registers and stack trace are available&lt;br /&gt;&lt;br /&gt;Symbol search path is: c:\windows\symbols&lt;br /&gt;Executable search path is: c:\windows\i386&lt;br /&gt;Unable to load image ntoskrnl.exe, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for ntoskrnl.exe&lt;br /&gt;Windows XP Kernel Version 2600 (Service Pack 3) MP (4 procs) Free x86 compatible&lt;br /&gt;Product: WinNt, suite: TerminalServer SingleUserTS&lt;br /&gt;Kernel base = 0x804d7000 PsLoadedModuleList = 0x805634c0&lt;br /&gt;Debug session time: Mon Jun  9 21:02:12.625 2008 (GMT+3)&lt;br /&gt;System Uptime: 0 days 0:10:53.611&lt;br /&gt;Unable to load image ntoskrnl.exe, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for ntoskrnl.exe&lt;br /&gt;Loading Kernel Symbols&lt;br /&gt;.....................................................................................................................................&lt;br /&gt;Loading User Symbols&lt;br /&gt;Loading unloaded module list&lt;br /&gt;...........&lt;br /&gt;*******************************************************************************&lt;br /&gt;*                                                                             *&lt;br /&gt;*                        Bugcheck Analysis                                    *&lt;br /&gt;*                                                                             *&lt;br /&gt;*******************************************************************************&lt;br /&gt;&lt;br /&gt;Use !analyze -v to get detailed debugging information.&lt;br /&gt;&lt;br /&gt;BugCheck C2, {7, cd4, 660072, e35c2738}&lt;br /&gt;&lt;br /&gt;Unable to load image aswMon2.SYS, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for aswMon2.SYS&lt;br /&gt;*** ERROR: Module load completed but symbols could not be loaded for aswMon2.SYS&lt;br /&gt;GetUlongFromAddress: unable to read from 805637f0&lt;br /&gt;Probably caused by : aswMon2.SYS ( aswMon2+65a9 )&lt;br /&gt;&lt;br /&gt;Followup: MachineOwner&lt;br /&gt;---------&lt;br /&gt;&lt;br /&gt;2: kd&gt; !analyze -v&lt;br /&gt;*******************************************************************************&lt;br /&gt;*                                                                             *&lt;br /&gt;*                        Bugcheck Analysis                                    *&lt;br /&gt;*                                                                             *&lt;br /&gt;*******************************************************************************&lt;br /&gt;&lt;br /&gt;BAD_POOL_CALLER (c2)&lt;br /&gt;The current thread is making a bad pool request.  Typically this is at a bad IRQL level or double freeing the same allocation, etc.&lt;br /&gt;Arguments:&lt;br /&gt;Arg1: 00000007, Attempt to free pool which was already freed&lt;br /&gt;Arg2: 00000cd4, (reserved)&lt;br /&gt;Arg3: 00660072, Memory contents of the pool block&lt;br /&gt;Arg4: e35c2738, Address of the block of pool being deallocated&lt;br /&gt;&lt;br /&gt;Debugging Details:&lt;br /&gt;------------------&lt;br /&gt;&lt;br /&gt;GetUlongFromAddress: unable to read from 805637f0&lt;br /&gt;&lt;br /&gt;POOL_ADDRESS:  e35c2738&lt;br /&gt;&lt;br /&gt;BUGCHECK_STR:  0xc2_7&lt;br /&gt;&lt;br /&gt;CUSTOMER_CRASH_COUNT:  3&lt;br /&gt;&lt;br /&gt;DEFAULT_BUCKET_ID:  DRIVER_FAULT&lt;br /&gt;&lt;br /&gt;PROCESS_NAME:  firefox.exe&lt;br /&gt;&lt;br /&gt;LAST_CONTROL_TRANSFER:  from 80551fc5 to 80537672&lt;br /&gt;&lt;br /&gt;STACK_TEXT:&lt;br /&gt;b766d69c 80551fc5 000000c2 00000007 00000cd4 nt!MiRemoveUnusedSegments+0x3db&lt;br /&gt;b766d6ec 8056ec09 e35c2738 00000000 e1557138 nt!KiProfileLock+0x1&lt;br /&gt;b766d748 8056d03b e1557150 00000000 899fc288 nt!NtQueryInformationToken+0x89b&lt;br /&gt;b766d7c0 80570402 00000000 b766d800 00000040 nt!NtQueryVolumeInformationFile+0x30&lt;br /&gt;b766d814 8057c24e 00000000 00000000 b94bf000 nt!CmpConstructName+0xb3&lt;br /&gt;b766d890 80584cc6 b766d9f4 00120089 b766d950 nt!NtQuerySystemInformation+0xd88&lt;br /&gt;b766d8d8 b68415a9 b766d9f4 00120089 b766d950 nt!MiCreateImageFileMap+0xa24&lt;br /&gt;WARNING: Stack unwind information not available. Following frames may be wrong.&lt;br /&gt;b766da18 b68419a4 898e0a60 898e0888 b766da4f aswMon2+0x65a9&lt;br /&gt;b766da50 b683b83c 89ab0020 008e0888 804e13c9 aswMon2+0x69a4&lt;br /&gt;b766db4c 8056d03b 8a14cc78 00000000 880bdd08 aswMon2+0x83c&lt;br /&gt;b766dbc4 80570402 00000000 b766dc04 00000040 nt!NtQueryVolumeInformationFile+0x30&lt;br /&gt;b766dc18 8057c24e 00000000 00000000 00000001 nt!CmpConstructName+0xb3&lt;br /&gt;b766dc94 8057c31d 0012e898 00100001 0012e858 nt!NtQuerySystemInformation+0xd88&lt;br /&gt;b766dcf0 8057c360 0012e898 00100001 0012e858 nt!NtQuerySystemInformation+0xe59&lt;br /&gt;b766dd30 804dd98f 0012e898 00100001 0012e858 nt!NtQuerySystemInformation+0xe9c&lt;br /&gt;b766dd44 00000000 00000080 00000003 00000002 nt!ZwSetSystemInformation+0x13&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;STACK_COMMAND:  kb&lt;br /&gt;&lt;br /&gt;FOLLOWUP_IP:&lt;br /&gt;aswMon2+65a9&lt;br /&gt;b68415a9 ??              ???&lt;br /&gt;&lt;br /&gt;SYMBOL_STACK_INDEX:  7&lt;br /&gt;&lt;br /&gt;SYMBOL_NAME:  aswMon2+65a9&lt;br /&gt;&lt;br /&gt;FOLLOWUP_NAME:  MachineOwner&lt;br /&gt;&lt;br /&gt;MODULE_NAME: aswMon2&lt;br /&gt;&lt;br /&gt;IMAGE_NAME:  aswMon2.SYS&lt;br /&gt;&lt;br /&gt;DEBUG_FLR_IMAGE_TIMESTAMP:  482c3a50&lt;br /&gt;&lt;br /&gt;FAILURE_BUCKET_ID:  0xc2_7_aswMon2+65a9&lt;br /&gt;&lt;br /&gt;BUCKET_ID:  0xc2_7_aswMon2+65a9&lt;br /&gt;&lt;br /&gt;Followup: MachineOwner&lt;br /&gt;---------&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/code&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2941007113477861308-620349431330546650?l=mybluescreen.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mybluescreen.blogspot.com/feeds/620349431330546650/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2941007113477861308&amp;postID=620349431330546650' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2941007113477861308/posts/default/620349431330546650'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2941007113477861308/posts/default/620349431330546650'/><link rel='alternate' type='text/html' href='http://mybluescreen.blogspot.com/2008/06/analyze-v-bugcheck-analysis.html' title='Probably caused by : aswMon2.SYS ( aswMon2+65a9 )'/><author><name>Allex Radu</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2941007113477861308.post-6781004422921270559</id><published>2008-06-20T05:31:00.000-07:00</published><updated>2008-06-20T05:33:42.174-07:00</updated><title type='text'>Probably caused by : sr.sys ( sr!SrpGetFileName+b4 )</title><content type='html'>&lt;code&gt;Microsoft (R) Windows Debugger Version 6.9.0003.113 X86&lt;br /&gt;Copyright (c) Microsoft Corporation. All rights reserved.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Loading Dump File [c:\windows\minidump\Mini060908-02.dmp]&lt;br /&gt;Mini Kernel Dump File: Only registers and stack trace are available&lt;br /&gt;&lt;br /&gt;Symbol search path is: c:\windows\symbols&lt;br /&gt;Executable search path is: c:\windows\i386&lt;br /&gt;Unable to load image ntoskrnl.exe, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for ntoskrnl.exe&lt;br /&gt;Windows XP Kernel Version 2600 (Service Pack 3) MP (4 procs) Free x86 compatible&lt;br /&gt;Product: WinNt, suite: TerminalServer SingleUserTS&lt;br /&gt;Kernel base = 0x804d7000 PsLoadedModuleList = 0x805634c0&lt;br /&gt;Debug session time: Mon Jun  9 20:50:51.265 2008 (GMT+3)&lt;br /&gt;System Uptime: 0 days 7:04:13.866&lt;br /&gt;Unable to load image ntoskrnl.exe, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for ntoskrnl.exe&lt;br /&gt;Loading Kernel Symbols&lt;br /&gt;.....................................................................................................................................&lt;br /&gt;Loading User Symbols&lt;br /&gt;Loading unloaded module list&lt;br /&gt;..............&lt;br /&gt;Unable to load image sr.sys, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for sr.sys&lt;br /&gt;*******************************************************************************&lt;br /&gt;*                                                                             *&lt;br /&gt;*                        Bugcheck Analysis                                    *&lt;br /&gt;*                                                                             *&lt;br /&gt;*******************************************************************************&lt;br /&gt;&lt;br /&gt;Use !analyze -v to get detailed debugging information.&lt;br /&gt;&lt;br /&gt;BugCheck 1000007F, {d, 0, 0, 0}&lt;br /&gt;&lt;br /&gt;Probably caused by : sr.sys ( sr!SrpGetFileName+b4 )&lt;br /&gt;&lt;br /&gt;Followup: MachineOwner&lt;br /&gt;---------&lt;br /&gt;&lt;br /&gt;3: kd&gt; !analyze -v&lt;br /&gt;*******************************************************************************&lt;br /&gt;*                                                                             *&lt;br /&gt;*                        Bugcheck Analysis                                    *&lt;br /&gt;*                                                                             *&lt;br /&gt;*******************************************************************************&lt;br /&gt;&lt;br /&gt;UNEXPECTED_KERNEL_MODE_TRAP_M (1000007f)&lt;br /&gt;This means a trap occurred in kernel mode, and it's a trap of a kind&lt;br /&gt;that the kernel isn't allowed to have/catch (bound trap) or that&lt;br /&gt;is always instant death (double fault).  The first number in the&lt;br /&gt;bugcheck params is the number of the trap (8 = double fault, etc)&lt;br /&gt;Consult an Intel x86 family manual to learn more about what these&lt;br /&gt;traps are. Here is a *portion* of those codes:&lt;br /&gt;If kv shows a taskGate&lt;br /&gt;       use .tss on the part before the colon, then kv.&lt;br /&gt;Else if kv shows a trapframe&lt;br /&gt;       use .trap on that value&lt;br /&gt;Else&lt;br /&gt;       .trap on the appropriate frame will show where the trap was taken&lt;br /&gt;       (on x86, this will be the ebp that goes with the procedure KiTrap)&lt;br /&gt;Endif&lt;br /&gt;kb will then show the corrected stack.&lt;br /&gt;Arguments:&lt;br /&gt;Arg1: 0000000d, EXCEPTION_GP_FAULT&lt;br /&gt;Arg2: 00000000&lt;br /&gt;Arg3: 00000000&lt;br /&gt;Arg4: 00000000&lt;br /&gt;&lt;br /&gt;Debugging Details:&lt;br /&gt;------------------&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;BUGCHECK_STR:  0x7f_d&lt;br /&gt;&lt;br /&gt;CUSTOMER_CRASH_COUNT:  2&lt;br /&gt;&lt;br /&gt;DEFAULT_BUCKET_ID:  DRIVER_FAULT&lt;br /&gt;&lt;br /&gt;PROCESS_NAME:  ashWebSv.exe&lt;br /&gt;&lt;br /&gt;LAST_CONTROL_TRANSFER:  from f74178ae to 804daf84&lt;br /&gt;&lt;br /&gt;STACK_TEXT: &lt;br /&gt;b075b6d4 f74178ae b075b7fc b075b7d2 0000004e nt!RtlPrefetchCopyMemory+0x31&lt;br /&gt;b075b6f4 f7418723 0000002e 0000007c 00000052 sr!SrpGetFileName+0xb4&lt;br /&gt;b075b708 f74187a0 8a03dc80 87a22778 00040020 sr!SrpExpandFileName+0x45&lt;br /&gt;b075b730 f74113e2 8a03dc80 87a22778 0141b500 sr!SrIsFileEligible+0x5a&lt;br /&gt;b075b8d0 f7411aef 8a03dc80 87a22778 00040020 sr!SrCreateContext+0x13e&lt;br /&gt;b075b8fc f7415169 00000000 8a03dd78 00040020 sr!SrGetContext+0xc9&lt;br /&gt;b075b948 f7413a22 8a03dc80 00040020 87a22778 sr!SrHandleEvent+0x35&lt;br /&gt;b075b9ac 804e13c9 00000000 00000002 87956bf0 sr!SrCreate+0x2fc&lt;br /&gt;b075b9ac 87946008 00000000 00000002 87956bf0 nt!KiTrap0D+0x483&lt;br /&gt;WARNING: Frame IP not in any known module. Following frames may be wrong.&lt;br /&gt;87956dc8 00000000 00000000 00000000 00000000 0x87946008&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;STACK_COMMAND:  kb&lt;br /&gt;&lt;br /&gt;FOLLOWUP_IP:&lt;br /&gt;sr!SrpGetFileName+b4&lt;br /&gt;f74178ae ??              ???&lt;br /&gt;&lt;br /&gt;SYMBOL_STACK_INDEX:  1&lt;br /&gt;&lt;br /&gt;SYMBOL_NAME:  sr!SrpGetFileName+b4&lt;br /&gt;&lt;br /&gt;FOLLOWUP_NAME:  MachineOwner&lt;br /&gt;&lt;br /&gt;MODULE_NAME: sr&lt;br /&gt;&lt;br /&gt;IMAGE_NAME:  sr.sys&lt;br /&gt;&lt;br /&gt;DEBUG_FLR_IMAGE_TIMESTAMP:  480252c2&lt;br /&gt;&lt;br /&gt;FAILURE_BUCKET_ID:  0x7f_d_sr!SrpGetFileName+b4&lt;br /&gt;&lt;br /&gt;BUCKET_ID:  0x7f_d_sr!SrpGetFileName+b4&lt;br /&gt;&lt;br /&gt;Followup: MachineOwner&lt;br /&gt;---------&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/code&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2941007113477861308-6781004422921270559?l=mybluescreen.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mybluescreen.blogspot.com/feeds/6781004422921270559/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2941007113477861308&amp;postID=6781004422921270559' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2941007113477861308/posts/default/6781004422921270559'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2941007113477861308/posts/default/6781004422921270559'/><link rel='alternate' type='text/html' href='http://mybluescreen.blogspot.com/2008/06/probably-caused-by-srsys.html' title='Probably caused by : sr.sys ( sr!SrpGetFileName+b4 )'/><author><name>Allex Radu</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2941007113477861308.post-1814583011438516242</id><published>2008-06-20T05:29:00.000-07:00</published><updated>2008-06-20T05:31:28.376-07:00</updated><title type='text'>Probably caused by : a347bus.sys ( a347bus+dfbc</title><content type='html'>&lt;code&gt;Microsoft (R) Windows Debugger Version 6.9.0003.113 X86&lt;br /&gt;Copyright (c) Microsoft Corporation. All rights reserved.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Loading Dump File [c:\windows\minidump\Mini060908-01.dmp]&lt;br /&gt;Mini Kernel Dump File: Only registers and stack trace are available&lt;br /&gt;&lt;br /&gt;Symbol search path is: c:\windows\symbols&lt;br /&gt;Executable search path is: c:\windows\i386&lt;br /&gt;Unable to load image ntoskrnl.exe, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for ntoskrnl.exe&lt;br /&gt;Windows XP Kernel Version 2600 (Service Pack 3) MP (4 procs) Free x86 compatible&lt;br /&gt;Product: WinNt, suite: TerminalServer SingleUserTS&lt;br /&gt;Kernel base = 0x804d7000 PsLoadedModuleList = 0x805634c0&lt;br /&gt;Debug session time: Mon Jun  9 01:22:51.250 2008 (GMT+3)&lt;br /&gt;System Uptime: 0 days 10:00:52.869&lt;br /&gt;Unable to load image ntoskrnl.exe, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for ntoskrnl.exe&lt;br /&gt;Loading Kernel Symbols&lt;br /&gt;....................................................................................................................................&lt;br /&gt;Loading User Symbols&lt;br /&gt;Loading unloaded module list&lt;br /&gt;...................&lt;br /&gt;*******************************************************************************&lt;br /&gt;*                                                                             *&lt;br /&gt;*                        Bugcheck Analysis                                    *&lt;br /&gt;*                                                                             *&lt;br /&gt;*******************************************************************************&lt;br /&gt;&lt;br /&gt;Use !analyze -v to get detailed debugging information.&lt;br /&gt;&lt;br /&gt;BugCheck C2, {7, cd4, 66004f, e6e7f008}&lt;br /&gt;&lt;br /&gt;Unable to load image a347bus.sys, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for a347bus.sys&lt;br /&gt;*** ERROR: Module load completed but symbols could not be loaded for a347bus.sys&lt;br /&gt;GetUlongFromAddress: unable to read from 805637f0&lt;br /&gt;Probably caused by : a347bus.sys ( a347bus+dfbc )&lt;br /&gt;&lt;br /&gt;Followup: MachineOwner&lt;br /&gt;---------&lt;br /&gt;&lt;br /&gt;3: kd&gt; !analyze -v&lt;br /&gt;*******************************************************************************&lt;br /&gt;*                                                                             *&lt;br /&gt;*                        Bugcheck Analysis                                    *&lt;br /&gt;*                                                                             *&lt;br /&gt;*******************************************************************************&lt;br /&gt;&lt;br /&gt;BAD_POOL_CALLER (c2)&lt;br /&gt;The current thread is making a bad pool request.  Typically this is at a bad IRQL level or double freeing the same allocation, etc.&lt;br /&gt;Arguments:&lt;br /&gt;Arg1: 00000007, Attempt to free pool which was already freed&lt;br /&gt;Arg2: 00000cd4, (reserved)&lt;br /&gt;Arg3: 0066004f, Memory contents of the pool block&lt;br /&gt;Arg4: e6e7f008, Address of the block of pool being deallocated&lt;br /&gt;&lt;br /&gt;Debugging Details:&lt;br /&gt;------------------&lt;br /&gt;&lt;br /&gt;GetUlongFromAddress: unable to read from 805637f0&lt;br /&gt;&lt;br /&gt;POOL_ADDRESS:  e6e7f008&lt;br /&gt;&lt;br /&gt;BUGCHECK_STR:  0xc2_7&lt;br /&gt;&lt;br /&gt;CUSTOMER_CRASH_COUNT:  1&lt;br /&gt;&lt;br /&gt;DEFAULT_BUCKET_ID:  DRIVER_FAULT&lt;br /&gt;&lt;br /&gt;PROCESS_NAME:  services.exe&lt;br /&gt;&lt;br /&gt;LAST_CONTROL_TRANSFER:  from 80551fc5 to 80537672&lt;br /&gt;&lt;br /&gt;STACK_TEXT: &lt;br /&gt;b51dc8fc 80551fc5 000000c2 00000007 00000cd4 nt!MiRemoveUnusedSegments+0x3db&lt;br /&gt;b51dc94c 8059afb6 e6e7f008 00000000 e3c43968 nt!KiProfileLock+0x1&lt;br /&gt;b51dc9a0 8057771f e1035758 b51dcc30 e3c43968 nt!RtlpSetSecurityObject+0x45c&lt;br /&gt;b51dcb78 80572e68 80000020 00000000 881700b8 nt!NtFlushInstructionCache+0xfc&lt;br /&gt;b51dcbf0 80570402 00000028 b51dcc30 00000040 nt!IopQueryOperationAccess+0x8&lt;br /&gt;b51dcc44 80572cfe 00000000 8a1d6040 0007e301 nt!CmpConstructName+0xb3&lt;br /&gt;b51dcd18 f75bbfbc 0007e460 00020019 0007e3b8 nt!NtQueryInformationFile+0xbe&lt;br /&gt;WARNING: Stack unwind information not available. Following frames may be wrong.&lt;br /&gt;b51dcd50 804dd98f 0007e460 00020019 0007e3b8 a347bus+0xdfbc&lt;br /&gt;b51dcd54 0007e460 00020019 0007e3b8 0007e3f8 nt!ZwSetSystemInformation+0x13&lt;br /&gt;b51dcd64 7c90e4f4 badb0d00 0007e3a0 b51dcd98 0x7e460&lt;br /&gt;b51dcd68 badb0d00 0007e3a0 b51dcd98 b51dcdcc 0x7c90e4f4&lt;br /&gt;b51dcd6c 0007e3a0 b51dcd98 b51dcdcc 00000000 0xbadb0d00&lt;br /&gt;b51dcd70 b51dcd98 b51dcdcc 00000000 00000000 0x7e3a0&lt;br /&gt;b51dcd74 b51dcdcc 00000000 00000000 00000000 0xb51dcd98&lt;br /&gt;b51dcd98 00000000 00000168 00000000 0007f2cc 0xb51dcdcc&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;STACK_COMMAND:  kb&lt;br /&gt;&lt;br /&gt;FOLLOWUP_IP:&lt;br /&gt;a347bus+dfbc&lt;br /&gt;f75bbfbc ??              ???&lt;br /&gt;&lt;br /&gt;SYMBOL_STACK_INDEX:  7&lt;br /&gt;&lt;br /&gt;SYMBOL_NAME:  a347bus+dfbc&lt;br /&gt;&lt;br /&gt;FOLLOWUP_NAME:  MachineOwner&lt;br /&gt;&lt;br /&gt;MODULE_NAME: a347bus&lt;br /&gt;&lt;br /&gt;IMAGE_NAME:  a347bus.sys&lt;br /&gt;&lt;br /&gt;DEBUG_FLR_IMAGE_TIMESTAMP:  4091f40d&lt;br /&gt;&lt;br /&gt;FAILURE_BUCKET_ID:  0xc2_7_a347bus+dfbc&lt;br /&gt;&lt;br /&gt;BUCKET_ID:  0xc2_7_a347bus+dfbc&lt;br /&gt;&lt;br /&gt;Followup: MachineOwner&lt;br /&gt;---------&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/code&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2941007113477861308-1814583011438516242?l=mybluescreen.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mybluescreen.blogspot.com/feeds/1814583011438516242/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2941007113477861308&amp;postID=1814583011438516242' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2941007113477861308/posts/default/1814583011438516242'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2941007113477861308/posts/default/1814583011438516242'/><link rel='alternate' type='text/html' href='http://mybluescreen.blogspot.com/2008/06/probably-caused-by-a347bussys_623.html' title='Probably caused by : a347bus.sys ( a347bus+dfbc'/><author><name>Allex Radu</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2941007113477861308.post-4965099090246081948</id><published>2008-06-20T05:22:00.000-07:00</published><updated>2008-06-20T05:29:13.123-07:00</updated><title type='text'>Probably caused by : a347bus.sys ( a347bus+1c2b )</title><content type='html'>&lt;code&gt;Microsoft (R) Windows Debugger Version 6.9.0003.113 X86&lt;br /&gt;Copyright (c) Microsoft Corporation. All rights reserved.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Loading Dump File [c:\windows\minidump\Mini060808-02.dmp]&lt;br /&gt;Mini Kernel Dump File: Only registers and stack trace are available&lt;br /&gt;&lt;br /&gt;Symbol search path is: c:\windows\symbols&lt;br /&gt;Executable search path is: c:\windows\i386&lt;br /&gt;Unable to load image ntoskrnl.exe, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for ntoskrnl.exe&lt;br /&gt;Windows XP Kernel Version 2600 (Service Pack 3) MP (4 procs) Free x86 compatible&lt;br /&gt;Product: WinNt, suite: TerminalServer SingleUserTS&lt;br /&gt;Kernel base = 0x804d7000 PsLoadedModuleList = 0x805634c0&lt;br /&gt;Debug session time: Sun Jun  8 14:06:56.546 2008 (GMT+3)&lt;br /&gt;System Uptime: 0 days 1:15:52.167&lt;br /&gt;Unable to load image ntoskrnl.exe, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for ntoskrnl.exe&lt;br /&gt;Loading Kernel Symbols&lt;br /&gt;..................................................................................................................................&lt;br /&gt;Loading User Symbols&lt;br /&gt;Loading unloaded module list&lt;br /&gt;................&lt;br /&gt;*******************************************************************************&lt;br /&gt;*                                                                             *&lt;br /&gt;*                        Bugcheck Analysis                                    *&lt;br /&gt;*                                                                             *&lt;br /&gt;*******************************************************************************&lt;br /&gt;&lt;br /&gt;Use !analyze -v to get detailed debugging information.&lt;br /&gt;&lt;br /&gt;BugCheck C2, {7, cd4, 69006c, e44873e0}&lt;br /&gt;&lt;br /&gt;Unable to load image a347bus.sys, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for a347bus.sys&lt;br /&gt;*** ERROR: Module load completed but symbols could not be loaded for a347bus.sys&lt;br /&gt;GetUlongFromAddress: unable to read from 805637f0&lt;br /&gt;Probably caused by : a347bus.sys ( a347bus+1c2b )&lt;br /&gt;&lt;br /&gt;Followup: MachineOwner&lt;br /&gt;---------&lt;br /&gt;&lt;br /&gt;3: kd&gt; !analyze -v&lt;br /&gt;*******************************************************************************&lt;br /&gt;*                                                                             *&lt;br /&gt;*                        Bugcheck Analysis                                    *&lt;br /&gt;*                                                                             *&lt;br /&gt;*******************************************************************************&lt;br /&gt;&lt;br /&gt;BAD_POOL_CALLER (c2)&lt;br /&gt;The current thread is making a bad pool request.  Typically this is at a bad IRQL level or double freeing the same allocation, etc.&lt;br /&gt;Arguments:&lt;br /&gt;Arg1: 00000007, Attempt to free pool which was already freed&lt;br /&gt;Arg2: 00000cd4, (reserved)&lt;br /&gt;Arg3: 0069006c, Memory contents of the pool block&lt;br /&gt;Arg4: e44873e0, Address of the block of pool being deallocated&lt;br /&gt;&lt;br /&gt;Debugging Details:&lt;br /&gt;------------------&lt;br /&gt;&lt;br /&gt;GetUlongFromAddress: unable to read from 805637f0&lt;br /&gt;&lt;br /&gt;POOL_ADDRESS:  e44873e0&lt;br /&gt;&lt;br /&gt;BUGCHECK_STR:  0xc2_7&lt;br /&gt;&lt;br /&gt;CUSTOMER_CRASH_COUNT:  2&lt;br /&gt;&lt;br /&gt;DEFAULT_BUCKET_ID:  DRIVER_FAULT&lt;br /&gt;&lt;br /&gt;PROCESS_NAME:  csrss.exe&lt;br /&gt;&lt;br /&gt;LAST_CONTROL_TRANSFER:  from 80551fc5 to 80537672&lt;br /&gt;&lt;br /&gt;STACK_TEXT: &lt;br /&gt;b6cd7a68 80551fc5 000000c2 00000007 00000cd4 nt!MiRemoveUnusedSegments+0x3db&lt;br /&gt;b6cd7ab8 8056ec09 e44873e0 00000000 e1035130 nt!KiProfileLock+0x1&lt;br /&gt;b6cd7b14 8056d03b e1035148 00000000 88034448 nt!NtQueryInformationToken+0x89b&lt;br /&gt;b6cd7b8c 80570402 00000000 b6cd7bcc 00000040 nt!NtQueryVolumeInformationFile+0x30&lt;br /&gt;b6cd7be0 8057c24e 00000000 00000000 00000001 nt!CmpConstructName+0xb3&lt;br /&gt;b6cd7c5c 8057c31d 00c8e194 00100001 00c8e138 nt!NtQuerySystemInformation+0xd88&lt;br /&gt;b6cd7cb8 8057c4cb 00c8e194 00100001 00c8e138 nt!NtQuerySystemInformation+0xe59&lt;br /&gt;b6cd7cf8 f75afc2b 00c8e194 00100001 00c8e138 nt!NtQuerySystemInformation+0x192&lt;br /&gt;WARNING: Stack unwind information not available. Following frames may be wrong.&lt;br /&gt;b6cd7d0c 00000000 00004021 b6cd7d64 00c8e12c a347bus+0x1c2b&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;STACK_COMMAND:  kb&lt;br /&gt;&lt;br /&gt;FOLLOWUP_IP:&lt;br /&gt;a347bus+1c2b&lt;br /&gt;f75afc2b ??              ???&lt;br /&gt;&lt;br /&gt;SYMBOL_STACK_INDEX:  8&lt;br /&gt;&lt;br /&gt;SYMBOL_NAME:  a347bus+1c2b&lt;br /&gt;&lt;br /&gt;FOLLOWUP_NAME:  MachineOwner&lt;br /&gt;&lt;br /&gt;MODULE_NAME: a347bus&lt;br /&gt;&lt;br /&gt;IMAGE_NAME:  a347bus.sys&lt;br /&gt;&lt;br /&gt;DEBUG_FLR_IMAGE_TIMESTAMP:  4091f40d&lt;br /&gt;&lt;br /&gt;FAILURE_BUCKET_ID:  0xc2_7_a347bus+1c2b&lt;br /&gt;&lt;br /&gt;BUCKET_ID:  0xc2_7_a347bus+1c2b&lt;br /&gt;&lt;br /&gt;Followup: MachineOwner&lt;br /&gt;---------&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/code&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2941007113477861308-4965099090246081948?l=mybluescreen.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mybluescreen.blogspot.com/feeds/4965099090246081948/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2941007113477861308&amp;postID=4965099090246081948' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2941007113477861308/posts/default/4965099090246081948'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2941007113477861308/posts/default/4965099090246081948'/><link rel='alternate' type='text/html' href='http://mybluescreen.blogspot.com/2008/06/probably-caused-by-a347bussys_6528.html' title='Probably caused by : a347bus.sys ( a347bus+1c2b )'/><author><name>Allex Radu</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2941007113477861308.post-1801272020027511022</id><published>2008-06-20T05:12:00.000-07:00</published><updated>2008-06-20T05:13:55.825-07:00</updated><title type='text'>Probably caused by : a347bus.sys ( a347bus+1c2b )</title><content type='html'>&lt;code&gt;Microsoft (R) Windows Debugger Version 6.9.0003.113 X86&lt;br /&gt;Copyright (c) Microsoft Corporation. All rights reserved.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Loading Dump File [c:\windows\minidump\Mini060808-01.dmp]&lt;br /&gt;Mini Kernel Dump File: Only registers and stack trace are available&lt;br /&gt;&lt;br /&gt;Symbol search path is: c:\windows\symbols&lt;br /&gt;Executable search path is: c:\windows\i386&lt;br /&gt;Unable to load image ntoskrnl.exe, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for ntoskrnl.exe&lt;br /&gt;Windows XP Kernel Version 2600 (Service Pack 3) MP (4 procs) Free x86 compatible&lt;br /&gt;Product: WinNt, suite: TerminalServer SingleUserTS&lt;br /&gt;Kernel base = 0x804d7000 PsLoadedModuleList = 0x805634c0&lt;br /&gt;Debug session time: Sun Jun  8 00:58:09.875 2008 (GMT+3)&lt;br /&gt;System Uptime: 0 days 5:36:08.876&lt;br /&gt;Unable to load image ntoskrnl.exe, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for ntoskrnl.exe&lt;br /&gt;Loading Kernel Symbols&lt;br /&gt;...............................................................................................................................&lt;br /&gt;Loading User Symbols&lt;br /&gt;Loading unloaded module list&lt;br /&gt;...............&lt;br /&gt;*******************************************************************************&lt;br /&gt;*                                                                             *&lt;br /&gt;*                        Bugcheck Analysis                                    *&lt;br /&gt;*                                                                             *&lt;br /&gt;*******************************************************************************&lt;br /&gt;&lt;br /&gt;Use !analyze -v to get detailed debugging information.&lt;br /&gt;&lt;br /&gt;BugCheck C2, {7, cd4, 660072, e1317a20}&lt;br /&gt;&lt;br /&gt;Unable to load image a347bus.sys, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for a347bus.sys&lt;br /&gt;*** ERROR: Module load completed but symbols could not be loaded for a347bus.sys&lt;br /&gt;GetUlongFromAddress: unable to read from 805637f0&lt;br /&gt;Probably caused by : a347bus.sys ( a347bus+1c2b )&lt;br /&gt;&lt;br /&gt;Followup: MachineOwner&lt;br /&gt;---------&lt;br /&gt;&lt;br /&gt;1: kd&gt; !analyze -v&lt;br /&gt;*******************************************************************************&lt;br /&gt;*                                                                             *&lt;br /&gt;*                        Bugcheck Analysis                                    *&lt;br /&gt;*                                                                             *&lt;br /&gt;*******************************************************************************&lt;br /&gt;&lt;br /&gt;BAD_POOL_CALLER (c2)&lt;br /&gt;The current thread is making a bad pool request.  Typically this is at a bad IRQL level or double freeing the same allocation, etc.&lt;br /&gt;Arguments:&lt;br /&gt;Arg1: 00000007, Attempt to free pool which was already freed&lt;br /&gt;Arg2: 00000cd4, (reserved)&lt;br /&gt;Arg3: 00660072, Memory contents of the pool block&lt;br /&gt;Arg4: e1317a20, Address of the block of pool being deallocated&lt;br /&gt;&lt;br /&gt;Debugging Details:&lt;br /&gt;------------------&lt;br /&gt;&lt;br /&gt;GetUlongFromAddress: unable to read from 805637f0&lt;br /&gt;&lt;br /&gt;POOL_ADDRESS:  e1317a20&lt;br /&gt;&lt;br /&gt;BUGCHECK_STR:  0xc2_7&lt;br /&gt;&lt;br /&gt;CUSTOMER_CRASH_COUNT:  1&lt;br /&gt;&lt;br /&gt;DEFAULT_BUCKET_ID:  DRIVER_FAULT&lt;br /&gt;&lt;br /&gt;PROCESS_NAME:  csrss.exe&lt;br /&gt;&lt;br /&gt;LAST_CONTROL_TRANSFER:  from 80551fc5 to 80537672&lt;br /&gt;&lt;br /&gt;STACK_TEXT: &lt;br /&gt;b6fb0a68 80551fc5 000000c2 00000007 00000cd4 nt!MiRemoveUnusedSegments+0x3db&lt;br /&gt;b6fb0ab8 8056ec09 e1317a20 00000000 e15e2aa8 nt!KiProfileLock+0x1&lt;br /&gt;b6fb0b14 8056d03b e15e2ac0 00000000 89e773d8 nt!NtQueryInformationToken+0x89b&lt;br /&gt;b6fb0b8c 80570402 00000000 b6fb0bcc 00000040 nt!NtQueryVolumeInformationFile+0x30&lt;br /&gt;b6fb0be0 8057c24e 00000000 00000000 00000001 nt!CmpConstructName+0xb3&lt;br /&gt;b6fb0c5c 8057c31d 0053e0b4 00100001 0053e058 nt!NtQuerySystemInformation+0xd88&lt;br /&gt;b6fb0cb8 8057c4cb 0053e0b4 00100001 0053e058 nt!NtQuerySystemInformation+0xe59&lt;br /&gt;b6fb0cf8 f75afc2b 0053e0b4 00100001 0053e058 nt!NtQuerySystemInformation+0x192&lt;br /&gt;WARNING: Stack unwind information not available. Following frames may be wrong.&lt;br /&gt;b6fb0d0c 00000000 00004021 b6fb0d64 0053e04c a347bus+0x1c2b&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;STACK_COMMAND:  kb&lt;br /&gt;&lt;br /&gt;FOLLOWUP_IP:&lt;br /&gt;a347bus+1c2b&lt;br /&gt;f75afc2b ??              ???&lt;br /&gt;&lt;br /&gt;SYMBOL_STACK_INDEX:  8&lt;br /&gt;&lt;br /&gt;SYMBOL_NAME:  a347bus+1c2b&lt;br /&gt;&lt;br /&gt;FOLLOWUP_NAME:  MachineOwner&lt;br /&gt;&lt;br /&gt;MODULE_NAME: a347bus&lt;br /&gt;&lt;br /&gt;IMAGE_NAME:  a347bus.sys&lt;br /&gt;&lt;br /&gt;DEBUG_FLR_IMAGE_TIMESTAMP:  4091f40d&lt;br /&gt;&lt;br /&gt;FAILURE_BUCKET_ID:  0xc2_7_a347bus+1c2b&lt;br /&gt;&lt;br /&gt;BUCKET_ID:  0xc2_7_a347bus+1c2b&lt;br /&gt;&lt;br /&gt;Followup: MachineOwner&lt;br /&gt;---------&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/code&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2941007113477861308-1801272020027511022?l=mybluescreen.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mybluescreen.blogspot.com/feeds/1801272020027511022/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2941007113477861308&amp;postID=1801272020027511022' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2941007113477861308/posts/default/1801272020027511022'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2941007113477861308/posts/default/1801272020027511022'/><link rel='alternate' type='text/html' href='http://mybluescreen.blogspot.com/2008/06/probably-caused-by-a347bussys_20.html' title='Probably caused by : a347bus.sys ( a347bus+1c2b )'/><author><name>Allex Radu</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2941007113477861308.post-5545604953568517617</id><published>2008-06-20T05:08:00.000-07:00</published><updated>2008-06-20T05:09:37.318-07:00</updated><title type='text'>Probably caused by : memory_corruption ( nt!MiRemoveUnusedSegments+3db )</title><content type='html'>&lt;code&gt;Microsoft (R) Windows Debugger Version 6.9.0003.113 X86&lt;br /&gt;Copyright (c) Microsoft Corporation. All rights reserved.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Loading Dump File [c:\windows\minidump\Mini060708-02.dmp]&lt;br /&gt;Mini Kernel Dump File: Only registers and stack trace are available&lt;br /&gt;&lt;br /&gt;Symbol search path is: c:\windows\symbols&lt;br /&gt;Executable search path is: c:\windows\i386&lt;br /&gt;Unable to load image ntoskrnl.exe, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for ntoskrnl.exe&lt;br /&gt;Windows XP Kernel Version 2600 (Service Pack 3) MP (4 procs) Free x86 compatible&lt;br /&gt;Product: WinNt, suite: TerminalServer SingleUserTS&lt;br /&gt;Kernel base = 0x804d7000 PsLoadedModuleList = 0x805634c0&lt;br /&gt;Debug session time: Sat Jun  7 13:54:31.921 2008 (GMT+3)&lt;br /&gt;System Uptime: 0 days 2:14:23.521&lt;br /&gt;Unable to load image ntoskrnl.exe, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for ntoskrnl.exe&lt;br /&gt;Loading Kernel Symbols&lt;br /&gt;...............................................................................................................................&lt;br /&gt;Loading User Symbols&lt;br /&gt;Loading unloaded module list&lt;br /&gt;..................&lt;br /&gt;*******************************************************************************&lt;br /&gt;*                                                                             *&lt;br /&gt;*                        Bugcheck Analysis                                    *&lt;br /&gt;*                                                                             *&lt;br /&gt;*******************************************************************************&lt;br /&gt;&lt;br /&gt;Use !analyze -v to get detailed debugging information.&lt;br /&gt;&lt;br /&gt;BugCheck C2, {7, cd4, 760045, e23bb728}&lt;br /&gt;&lt;br /&gt;GetUlongFromAddress: unable to read from 805637f0&lt;br /&gt;GetUlongFromAddress: unable to read from 805637f0&lt;br /&gt;Probably caused by : memory_corruption ( nt!MiRemoveUnusedSegments+3db )&lt;br /&gt;&lt;br /&gt;Followup: MachineOwner&lt;br /&gt;---------&lt;br /&gt;&lt;br /&gt;0: kd&gt; !analyze -v&lt;br /&gt;*******************************************************************************&lt;br /&gt;*                                                                             *&lt;br /&gt;*                        Bugcheck Analysis                                    *&lt;br /&gt;*                                                                             *&lt;br /&gt;*******************************************************************************&lt;br /&gt;&lt;br /&gt;BAD_POOL_CALLER (c2)&lt;br /&gt;The current thread is making a bad pool request.  Typically this is at a bad IRQL level or double freeing the same allocation, etc.&lt;br /&gt;Arguments:&lt;br /&gt;Arg1: 00000007, Attempt to free pool which was already freed&lt;br /&gt;Arg2: 00000cd4, (reserved)&lt;br /&gt;Arg3: 00760045, Memory contents of the pool block&lt;br /&gt;Arg4: e23bb728, Address of the block of pool being deallocated&lt;br /&gt;&lt;br /&gt;Debugging Details:&lt;br /&gt;------------------&lt;br /&gt;&lt;br /&gt;GetUlongFromAddress: unable to read from 805637f0&lt;br /&gt;GetUlongFromAddress: unable to read from 805637f0&lt;br /&gt;&lt;br /&gt;POOL_ADDRESS:  e23bb728&lt;br /&gt;&lt;br /&gt;BUGCHECK_STR:  0xc2_7&lt;br /&gt;&lt;br /&gt;CUSTOMER_CRASH_COUNT:  2&lt;br /&gt;&lt;br /&gt;DEFAULT_BUCKET_ID:  DRIVER_FAULT&lt;br /&gt;&lt;br /&gt;PROCESS_NAME:  csrss.exe&lt;br /&gt;&lt;br /&gt;LAST_CONTROL_TRANSFER:  from 80551fc5 to 80537672&lt;br /&gt;&lt;br /&gt;STACK_TEXT: &lt;br /&gt;b9eeda54 80551fc5 000000c2 00000007 00000cd4 nt!MiRemoveUnusedSegments+0x3db&lt;br /&gt;b9eedaa4 8056ec09 e23bb728 00000000 e1547958 nt!KiProfileLock+0x1&lt;br /&gt;b9eedb00 8056d03b e1547970 00000000 87b893a0 nt!NtQueryInformationToken+0x89b&lt;br /&gt;b9eedb78 80570402 00000000 b9eedbb8 00000040 nt!NtQueryVolumeInformationFile+0x30&lt;br /&gt;b9eedbcc 80585018 00000000 00000000 00000001 nt!CmpConstructName+0xb3&lt;br /&gt;b9eedd54 804dd98f 006aea44 006aea0c 006aea70 nt!MiCreateImageFileMap+0x9ba&lt;br /&gt;b9eedd60 006aea70 7c90e4f4 badb0d00 006ae9f8 nt!ZwSetSystemInformation+0x13&lt;br /&gt;WARNING: Frame IP not in any known module. Following frames may be wrong.&lt;br /&gt;b9eedd64 7c90e4f4 badb0d00 006ae9f8 00000000 0x6aea70&lt;br /&gt;b9eedd68 badb0d00 006ae9f8 00000000 32210020 0x7c90e4f4&lt;br /&gt;b9eedd6c 006ae9f8 00000000 32210020 00000000 0xbadb0d00&lt;br /&gt;b9eedd70 00000000 32210020 00000000 00000000 0x6ae9f8&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;STACK_COMMAND:  kb&lt;br /&gt;&lt;br /&gt;FOLLOWUP_IP:&lt;br /&gt;nt!MiRemoveUnusedSegments+3db&lt;br /&gt;80537672 5d              pop     ebp&lt;br /&gt;&lt;br /&gt;SYMBOL_STACK_INDEX:  0&lt;br /&gt;&lt;br /&gt;SYMBOL_NAME:  nt!MiRemoveUnusedSegments+3db&lt;br /&gt;&lt;br /&gt;FOLLOWUP_NAME:  MachineOwner&lt;br /&gt;&lt;br /&gt;MODULE_NAME: nt&lt;br /&gt;&lt;br /&gt;DEBUG_FLR_IMAGE_TIMESTAMP:  48025de7&lt;br /&gt;&lt;br /&gt;IMAGE_NAME:  memory_corruption&lt;br /&gt;&lt;br /&gt;FAILURE_BUCKET_ID:  0xc2_7_nt!MiRemoveUnusedSegments+3db&lt;br /&gt;&lt;br /&gt;BUCKET_ID:  0xc2_7_nt!MiRemoveUnusedSegments+3db&lt;br /&gt;&lt;br /&gt;Followup: MachineOwner&lt;br /&gt;---------&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/code&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2941007113477861308-5545604953568517617?l=mybluescreen.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mybluescreen.blogspot.com/feeds/5545604953568517617/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2941007113477861308&amp;postID=5545604953568517617' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2941007113477861308/posts/default/5545604953568517617'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2941007113477861308/posts/default/5545604953568517617'/><link rel='alternate' type='text/html' href='http://mybluescreen.blogspot.com/2008/06/probably-caused-by-memorycorruption.html' title='Probably caused by : memory_corruption ( nt!MiRemoveUnusedSegments+3db )'/><author><name>Allex Radu</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2941007113477861308.post-4152401214766457504</id><published>2008-06-20T03:28:00.000-07:00</published><updated>2008-06-20T03:33:17.607-07:00</updated><title type='text'>Probably caused by : a347bus.sys ( a347bus+1c2b )</title><content type='html'>&lt;code&gt; Microsoft (R) Windows Debugger Version 6.9.0003.113 X86&lt;br /&gt;Copyright (c) Microsoft Corporation. All rights reserved.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Loading Dump File [c:\windows\minidump\Mini060708-01.dmp]&lt;br /&gt;Mini Kernel Dump File: Only registers and stack trace are available&lt;br /&gt;&lt;br /&gt;Symbol search path is: c:\windows\symbols&lt;br /&gt;Executable search path is: c:\windows\i386&lt;br /&gt;Unable to load image ntoskrnl.exe, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for ntoskrnl.exe&lt;br /&gt;Windows XP Kernel Version 2600 (Service Pack 3) MP (4 procs) Free x86 compatible&lt;br /&gt;Product: WinNt, suite: TerminalServer SingleUserTS&lt;br /&gt;Kernel base = 0x804d7000 PsLoadedModuleList = 0x805634c0&lt;br /&gt;Debug session time: Sat Jun  7 01:36:58.984 2008 (GMT+3)&lt;br /&gt;System Uptime: 0 days 3:06:07.973&lt;br /&gt;Unable to load image ntoskrnl.exe, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for ntoskrnl.exe&lt;br /&gt;Loading Kernel Symbols&lt;br /&gt;..............................................................................................................................&lt;br /&gt;Loading User Symbols&lt;br /&gt;Loading unloaded module list&lt;br /&gt;..................&lt;br /&gt;*******************************************************************************&lt;br /&gt;*                                                                             *&lt;br /&gt;*                        Bugcheck Analysis                                    *&lt;br /&gt;*                                                                             *&lt;br /&gt;*******************************************************************************&lt;br /&gt;&lt;br /&gt;Use !analyze -v to get detailed debugging information.&lt;br /&gt;&lt;br /&gt;BugCheck C2, {7, cd4, 630061, e47a1290}&lt;br /&gt;&lt;br /&gt;Unable to load image a347bus.sys, Win32 error 0n2&lt;br /&gt;*** WARNING: Unable to verify timestamp for a347bus.sys&lt;br /&gt;*** ERROR: Module load completed but symbols could not be loaded for a347bus.sys&lt;br /&gt;GetUlongFromAddress: unable to read from 805637f0&lt;br /&gt;Probably caused by : a347bus.sys ( a347bus+1c2b )&lt;br /&gt;&lt;br /&gt;Followup: MachineOwner&lt;br /&gt;---------&lt;br /&gt;&lt;br /&gt;2: kd&gt; !analyze -v&lt;br /&gt;*******************************************************************************&lt;br /&gt;*                                                                             *&lt;br /&gt;*                        Bugcheck Analysis                                    *&lt;br /&gt;*                                                                             *&lt;br /&gt;*******************************************************************************&lt;br /&gt;&lt;br /&gt;BAD_POOL_CALLER (c2)&lt;br /&gt;The current thread is making a bad pool request.  Typically this is at a bad IRQL level or double freeing the same allocation, etc.&lt;br /&gt;Arguments:&lt;br /&gt;Arg1: 00000007, Attempt to free pool which was already freed&lt;br /&gt;Arg2: 00000cd4, (reserved)&lt;br /&gt;Arg3: 00630061, Memory contents of the pool block&lt;br /&gt;Arg4: e47a1290, Address of the block of pool being deallocated&lt;br /&gt;&lt;br /&gt;Debugging Details:&lt;br /&gt;------------------&lt;br /&gt;&lt;br /&gt;GetUlongFromAddress: unable to read from 805637f0&lt;br /&gt;&lt;br /&gt;POOL_ADDRESS:  e47a1290&lt;br /&gt;&lt;br /&gt;BUGCHECK_STR:  0xc2_7&lt;br /&gt;&lt;br /&gt;CUSTOMER_CRASH_COUNT:  1&lt;br /&gt;&lt;br /&gt;DEFAULT_BUCKET_ID:  DRIVER_FAULT&lt;br /&gt;&lt;br /&gt;PROCESS_NAME:  csrss.exe&lt;br /&gt;&lt;br /&gt;LAST_CONTROL_TRANSFER:  from 80551fc5 to 80537672&lt;br /&gt;&lt;br /&gt;STACK_TEXT: &lt;br /&gt;b6733a68 80551fc5 000000c2 00000007 00000cd4 nt!MiRemoveUnusedSegments+0x3db&lt;br /&gt;b6733ab8 8056ec09 e47a1290 00000000 e1546ab8 nt!KiProfileLock+0x1&lt;br /&gt;b6733b14 8056d03b e1546ad0 00000000 8795f650 nt!NtQueryInformationToken+0x89b&lt;br /&gt;b6733b8c 80570402 00000000 b6733bcc 00000040 nt!NtQueryVolumeInformationFile+0x30&lt;br /&gt;b6733be0 8057c24e 00000000 00000000 00000001 nt!CmpConstructName+0xb3&lt;br /&gt;b6733c5c 8057c31d 0114e194 00100001 0114e138 nt!NtQuerySystemInformation+0xd88&lt;br /&gt;b6733cb8 8057c4cb 0114e194 00100001 0114e138 nt!NtQuerySystemInformation+0xe59&lt;br /&gt;b6733cf8 f75afc2b 0114e194 00100001 0114e138 nt!NtQuerySystemInformation+0x192&lt;br /&gt;WARNING: Stack unwind information not available. Following frames may be wrong.&lt;br /&gt;b6733d0c 00000000 00004021 b6733d64 0114e12c a347bus+0x1c2b&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;STACK_COMMAND:  kb&lt;br /&gt;&lt;br /&gt;FOLLOWUP_IP:&lt;br /&gt;a347bus+1c2b&lt;br /&gt;f75afc2b ??              ???&lt;br /&gt;&lt;br /&gt;SYMBOL_STACK_INDEX:  8&lt;br /&gt;&lt;br /&gt;SYMBOL_NAME:  a347bus+1c2b&lt;br /&gt;&lt;br /&gt;FOLLOWUP_NAME:  MachineOwner&lt;br /&gt;&lt;br /&gt;MODULE_NAME: a347bus&lt;br /&gt;&lt;br /&gt;IMAGE_NAME:  a347bus.sys&lt;br /&gt;&lt;br /&gt;DEBUG_FLR_IMAGE_TIMESTAMP:  4091f40d&lt;br /&gt;&lt;br /&gt;FAILURE_BUCKET_ID:  0xc2_7_a347bus+1c2b&lt;br /&gt;&lt;br /&gt;BUCKET_ID:  0xc2_7_a347bus+1c2b&lt;br /&gt;&lt;br /&gt;Followup: MachineOwner&lt;br /&gt;---------&lt;br /&gt;&lt;br /&gt;&lt;/code&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2941007113477861308-4152401214766457504?l=mybluescreen.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mybluescreen.blogspot.com/feeds/4152401214766457504/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2941007113477861308&amp;postID=4152401214766457504' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2941007113477861308/posts/default/4152401214766457504'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2941007113477861308/posts/default/4152401214766457504'/><link rel='alternate' type='text/html' href='http://mybluescreen.blogspot.com/2008/06/probably-caused-by-a347bussys.html' title='Probably caused by : a347bus.sys ( a347bus+1c2b )'/><author><name>Allex Radu</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2941007113477861308.post-4353723072494522055</id><published>2008-06-19T04:13:00.000-07:00</published><updated>2009-01-11T12:44:44.353-08:00</updated><title type='text'>How to debug Blue Screens</title><content type='html'>Hello boys and girls, let me tell you my problem.&lt;br /&gt;&lt;br /&gt;A month ago I've upgraded to this new system:&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Intel Quad Core Q9300&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;AsRock Penryl 1600SLI-110DB&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Nvidia Gforce 9600 GT&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;I've kept the RAM, low quality DDR2 RAM (I think this is the reason for my BSODs).&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;I've got also a Firewire PCI card and an Audigy SE soundcard.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Until I'll show you my blue screen and my debug information I'll tell you how to debug Blue Screen Of Death information to see what is wrong.&lt;br /&gt;&lt;br /&gt;I'll copy some information from Microsoft support website, I hope they don't mind because they are the good guys.&lt;br /&gt;&lt;br /&gt;1) After the first blue screen go to your windows partition and look in windows directory for a subdirectory named &lt;span style="font-style: italic; font-weight: bold;"&gt;minidump&lt;/span&gt; and see if you've got any files win there.&lt;br /&gt;&lt;br /&gt;If you've got files like that Mini&lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;MM&lt;/span&gt;&lt;span style="color: rgb(51, 204, 0); font-weight: bold;"&gt;DD&lt;/span&gt;&lt;span style="color: rgb(204, 51, 204); font-weight: bold;"&gt;YY&lt;/span&gt;-01.dmp (&lt;span style="color: rgb(204, 0, 0);"&gt;M&lt;/span&gt;onth,&lt;span style="color: rgb(0, 153, 0);"&gt; D&lt;/span&gt;ay, &lt;span style="color: rgb(204, 51, 204);"&gt;Y&lt;/span&gt;ear), even if you don't see .dmp you are alright.&lt;br /&gt;&lt;br /&gt;2) Now that you know you have files to debug download first &lt;a href="http://www.microsoft.com/whdc/devtools/debugging/symbolpkg.mspx"&gt;&lt;span style="font-weight: bold; color: rgb(204, 0, 0);"&gt;Windows Symbol Packages&lt;/span&gt;&lt;/a&gt; (you'll see the link for your OS at the bottom of the page)  and install it, usually installs itself on&lt;span style="font-weight: bold;"&gt; c:\windows\symbols  &lt;/span&gt;if C is your windows drive and "windows" is your windows directory.&lt;br /&gt;&lt;br /&gt;3) Install &lt;span style="font-weight: bold;"&gt;Debugging tools for Windows&lt;/span&gt; &lt;a href="http://www.microsoft.com/whdc/devtools/debugging/installx86.mspx#a"&gt;32-bit&lt;/a&gt; version or &lt;a href="http://www.microsoft.com/whdc/devtools/debugging/install64bit.mspx#"&gt;64-bit&lt;/a&gt; versio, make sure you've downloaded the right one for your OS.&lt;br /&gt;&lt;br /&gt;4) (from Microsoft)&lt;br /&gt;&lt;br /&gt;1. Click Start, click Run, type &lt;span style="font-style: italic;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;code&gt;cmd&lt;/code&gt;&lt;/span&gt;,&lt;/span&gt; and then click OK.&lt;br /&gt;2. Change to the Debugging Tools for Windows folder. To do this, copy and pasting the following at the command prompt, and then press ENTER:&lt;br /&gt;&lt;span style="font-style: italic; font-weight: bold;"&gt;&lt;code&gt;cd c:\program files\debugging tools for windows (x86)&lt;/code&gt;&lt;/span&gt;&lt;br /&gt;or&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;code&gt;cd c:\program files\debugging tools for windows (x64)&lt;/code&gt;&lt;/span&gt;&lt;br /&gt;3. To load the dump file into a debugger, type one of the following commands, and then press ENTER:&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;windbg -y SymbolPath -i ImagePath -z DumpFilePath&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;If you have the windows installed on C drive and in directory Windows just modify and copy this line:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;windbg -y c:\windows\symbols -i c:\windows\i386 -z c:\windows\minidump\&lt;/span&gt;&lt;span style="font-size:180%;"&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Mini&lt;/span&gt;&lt;/span&gt;&lt;span style="color: rgb(255, 0, 0); font-weight: bold; font-style: italic;font-size:180%;" &gt;MM&lt;/span&gt;&lt;span style="color: rgb(51, 204, 0); font-weight: bold; font-style: italic;font-size:180%;" &gt;DD&lt;/span&gt;&lt;span style="color: rgb(204, 51, 204); font-weight: bold; font-style: italic;font-size:180%;" &gt;YY&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;span style="font-size:180%;"&gt;-XX&lt;/span&gt;.dmp&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;Replace Mini&lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;MM&lt;/span&gt;&lt;span style="color: rgb(51, 204, 0); font-weight: bold;"&gt;DD&lt;/span&gt;&lt;span style="color: rgb(204, 51, 204); font-weight: bold;"&gt;YY&lt;/span&gt;-01.dmp with your minidump file name and a windows like this will appear:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_ECfeuM753JQ/SFpHkYXcn_I/AAAAAAAAAI4/-wvksgcwZ_s/s1600-h/minidump.jpg"&gt;&lt;img style="cursor: pointer;" src="http://bp1.blogger.com/_ECfeuM753JQ/SFpHkYXcn_I/AAAAAAAAAI4/-wvksgcwZ_s/s400/minidump.jpg" alt="" id="BLOGGER_PHOTO_ID_5213558208976429042" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;And at the end of the page you'll see for example:&lt;br /&gt;&lt;br /&gt;&lt;code&gt; Use !analyze -v to get detailed debugging information.&lt;br /&gt;&lt;br /&gt;BugCheck 1000007F, {d, 0, 0, 0}&lt;br /&gt;&lt;br /&gt;Probably caused by : ntoskrnl.exe ( nt!RtlPrefetchCopyMemory+31 )&lt;br /&gt;&lt;br /&gt;Followup: MachineOwner&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;After that you can post everything on a forum and ask for help.&lt;br /&gt;&lt;br /&gt;You can click &lt;code&gt;!analyze -v for a deep inspection.&lt;/code&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2941007113477861308-4353723072494522055?l=mybluescreen.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://mybluescreen.blogspot.com/feeds/4353723072494522055/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2941007113477861308&amp;postID=4353723072494522055' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2941007113477861308/posts/default/4353723072494522055'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2941007113477861308/posts/default/4353723072494522055'/><link rel='alternate' type='text/html' href='http://mybluescreen.blogspot.com/2008/06/how-to-debug-blue-screens.html' title='How to debug Blue Screens'/><author><name>Allex Radu</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_ECfeuM753JQ/SFpHkYXcn_I/AAAAAAAAAI4/-wvksgcwZ_s/s72-c/minidump.jpg' height='72' width='72'/><thr:total>0</thr:total></entry></feed>
