
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Windows\Minidump\010109-40185-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*C:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is: 
Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17592.amd64fre.win7sp1_gdr.110408-1631
Machine Name:
Kernel base = 0xfffff800`03061000 PsLoadedModuleList = 0xfffff800`032a6650
Debug session time: Thu Jan  1 08:13:44.532 2009 (UTC + 2:00)
System Uptime: 0 days 0:00:39.686
Loading Kernel Symbols
...............................................................
................................................................
.............
Loading User Symbols
Loading unloaded module list
.....
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 4E, {99, 77d20, 2, 77d5f}

Probably caused by : memory_corruption ( nt!MiBadShareCount+4c )

Followup: MachineOwner
---------

1: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

PFN_LIST_CORRUPT (4e)
Typically caused by drivers passing bad memory descriptor lists (ie: calling
MmUnlockPages twice with the same list, etc).  If a kernel debugger is
available get the stack trace.
Arguments:
Arg1: 0000000000000099, A PTE or PFN is corrupt
Arg2: 0000000000077d20, page frame number
Arg3: 0000000000000002, current page state
Arg4: 0000000000077d5f, 0

Debugging Details:
------------------


BUGCHECK_STR:  0x4E_99

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

PROCESS_NAME:  MsMpEng.exe

CURRENT_IRQL:  2

LAST_CONTROL_TRANSFER:  from fffff80003166d7c to fffff800030e0d00

STACK_TEXT:  
fffff880`02925988 fffff800`03166d7c : 00000000`0000004e 00000000`00000099 00000000`00077d20 00000000`00000002 : nt!KeBugCheckEx
fffff880`02925990 fffff800`03141051 : fffffa80`01677600 fffffa80`01691a90 00000000`00000002 fffff880`02925a08 : nt!MiBadShareCount+0x4c
fffff880`029259d0 fffff800`031a994d : 00000000`00000001 fffff700`01080488 fffffa80`02ccdb30 fffffa80`02ccdec8 : nt! ?? ::FNODOBFM::`string'+0x18544
fffff880`02925af0 fffff800`031ef3c7 : ffffffff`ffffffff fffff880`02925ca0 fffffa80`043f3b60 00000000`00000001 : nt!MiFreeWsle+0xcd
fffff880`02925b30 fffff800`030dff93 : fffffa80`043f3b60 00000000`0087eed0 00000000`0087eed8 00000000`0000006f : nt!NtUnlockVirtualMemory+0x227
fffff880`02925c20 00000000`77482bda : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0087ee98 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77482bda


STACK_COMMAND:  kb

FOLLOWUP_IP: 
nt!MiBadShareCount+4c
fffff800`03166d7c cc              int     3

SYMBOL_STACK_INDEX:  1

SYMBOL_NAME:  nt!MiBadShareCount+4c

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

DEBUG_FLR_IMAGE_TIMESTAMP:  4d9fdd5b

IMAGE_NAME:  memory_corruption

FAILURE_BUCKET_ID:  X64_0x4E_99_nt!MiBadShareCount+4c

BUCKET_ID:  X64_0x4E_99_nt!MiBadShareCount+4c

Followup: MachineOwner
---------

1: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

PFN_LIST_CORRUPT (4e)
Typically caused by drivers passing bad memory descriptor lists (ie: calling
MmUnlockPages twice with the same list, etc).  If a kernel debugger is
available get the stack trace.
Arguments:
Arg1: 0000000000000099, A PTE or PFN is corrupt
Arg2: 0000000000077d20, page frame number
Arg3: 0000000000000002, current page state
Arg4: 0000000000077d5f, 0

Debugging Details:
------------------


BUGCHECK_STR:  0x4E_99

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

PROCESS_NAME:  MsMpEng.exe

CURRENT_IRQL:  2

LAST_CONTROL_TRANSFER:  from fffff80003166d7c to fffff800030e0d00

STACK_TEXT:  
fffff880`02925988 fffff800`03166d7c : 00000000`0000004e 00000000`00000099 00000000`00077d20 00000000`00000002 : nt!KeBugCheckEx
fffff880`02925990 fffff800`03141051 : fffffa80`01677600 fffffa80`01691a90 00000000`00000002 fffff880`02925a08 : nt!MiBadShareCount+0x4c
fffff880`029259d0 fffff800`031a994d : 00000000`00000001 fffff700`01080488 fffffa80`02ccdb30 fffffa80`02ccdec8 : nt! ?? ::FNODOBFM::`string'+0x18544
fffff880`02925af0 fffff800`031ef3c7 : ffffffff`ffffffff fffff880`02925ca0 fffffa80`043f3b60 00000000`00000001 : nt!MiFreeWsle+0xcd
fffff880`02925b30 fffff800`030dff93 : fffffa80`043f3b60 00000000`0087eed0 00000000`0087eed8 00000000`0000006f : nt!NtUnlockVirtualMemory+0x227
fffff880`02925c20 00000000`77482bda : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0087ee98 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77482bda


STACK_COMMAND:  kb

FOLLOWUP_IP: 
nt!MiBadShareCount+4c
fffff800`03166d7c cc              int     3

SYMBOL_STACK_INDEX:  1

SYMBOL_NAME:  nt!MiBadShareCount+4c

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

DEBUG_FLR_IMAGE_TIMESTAMP:  4d9fdd5b

IMAGE_NAME:  memory_corruption

FAILURE_BUCKET_ID:  X64_0x4E_99_nt!MiBadShareCount+4c

BUCKET_ID:  X64_0x4E_99_nt!MiBadShareCount+4c

Followup: MachineOwner
---------

1: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

PFN_LIST_CORRUPT (4e)
Typically caused by drivers passing bad memory descriptor lists (ie: calling
MmUnlockPages twice with the same list, etc).  If a kernel debugger is
available get the stack trace.
Arguments:
Arg1: 0000000000000099, A PTE or PFN is corrupt
Arg2: 0000000000077d20, page frame number
Arg3: 0000000000000002, current page state
Arg4: 0000000000077d5f, 0

Debugging Details:
------------------


BUGCHECK_STR:  0x4E_99

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

PROCESS_NAME:  MsMpEng.exe

CURRENT_IRQL:  2

LAST_CONTROL_TRANSFER:  from fffff80003166d7c to fffff800030e0d00

STACK_TEXT:  
fffff880`02925988 fffff800`03166d7c : 00000000`0000004e 00000000`00000099 00000000`00077d20 00000000`00000002 : nt!KeBugCheckEx
fffff880`02925990 fffff800`03141051 : fffffa80`01677600 fffffa80`01691a90 00000000`00000002 fffff880`02925a08 : nt!MiBadShareCount+0x4c
fffff880`029259d0 fffff800`031a994d : 00000000`00000001 fffff700`01080488 fffffa80`02ccdb30 fffffa80`02ccdec8 : nt! ?? ::FNODOBFM::`string'+0x18544
fffff880`02925af0 fffff800`031ef3c7 : ffffffff`ffffffff fffff880`02925ca0 fffffa80`043f3b60 00000000`00000001 : nt!MiFreeWsle+0xcd
fffff880`02925b30 fffff800`030dff93 : fffffa80`043f3b60 00000000`0087eed0 00000000`0087eed8 00000000`0000006f : nt!NtUnlockVirtualMemory+0x227
fffff880`02925c20 00000000`77482bda : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0087ee98 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77482bda


STACK_COMMAND:  kb

FOLLOWUP_IP: 
nt!MiBadShareCount+4c
fffff800`03166d7c cc              int     3

SYMBOL_STACK_INDEX:  1

SYMBOL_NAME:  nt!MiBadShareCount+4c

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

DEBUG_FLR_IMAGE_TIMESTAMP:  4d9fdd5b

IMAGE_NAME:  memory_corruption

FAILURE_BUCKET_ID:  X64_0x4E_99_nt!MiBadShareCount+4c

BUCKET_ID:  X64_0x4E_99_nt!MiBadShareCount+4c

Followup: MachineOwner
---------

1: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

PFN_LIST_CORRUPT (4e)
Typically caused by drivers passing bad memory descriptor lists (ie: calling
MmUnlockPages twice with the same list, etc).  If a kernel debugger is
available get the stack trace.
Arguments:
Arg1: 0000000000000099, A PTE or PFN is corrupt
Arg2: 0000000000077d20, page frame number
Arg3: 0000000000000002, current page state
Arg4: 0000000000077d5f, 0

Debugging Details:
------------------


BUGCHECK_STR:  0x4E_99

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

PROCESS_NAME:  MsMpEng.exe

CURRENT_IRQL:  2

LAST_CONTROL_TRANSFER:  from fffff80003166d7c to fffff800030e0d00

STACK_TEXT:  
fffff880`02925988 fffff800`03166d7c : 00000000`0000004e 00000000`00000099 00000000`00077d20 00000000`00000002 : nt!KeBugCheckEx
fffff880`02925990 fffff800`03141051 : fffffa80`01677600 fffffa80`01691a90 00000000`00000002 fffff880`02925a08 : nt!MiBadShareCount+0x4c
fffff880`029259d0 fffff800`031a994d : 00000000`00000001 fffff700`01080488 fffffa80`02ccdb30 fffffa80`02ccdec8 : nt! ?? ::FNODOBFM::`string'+0x18544
fffff880`02925af0 fffff800`031ef3c7 : ffffffff`ffffffff fffff880`02925ca0 fffffa80`043f3b60 00000000`00000001 : nt!MiFreeWsle+0xcd
fffff880`02925b30 fffff800`030dff93 : fffffa80`043f3b60 00000000`0087eed0 00000000`0087eed8 00000000`0000006f : nt!NtUnlockVirtualMemory+0x227
fffff880`02925c20 00000000`77482bda : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0087ee98 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77482bda


STACK_COMMAND:  kb

FOLLOWUP_IP: 
nt!MiBadShareCount+4c
fffff800`03166d7c cc              int     3

SYMBOL_STACK_INDEX:  1

SYMBOL_NAME:  nt!MiBadShareCount+4c

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

DEBUG_FLR_IMAGE_TIMESTAMP:  4d9fdd5b

IMAGE_NAME:  memory_corruption

FAILURE_BUCKET_ID:  X64_0x4E_99_nt!MiBadShareCount+4c

BUCKET_ID:  X64_0x4E_99_nt!MiBadShareCount+4c

Followup: MachineOwner
---------

