
Microsoft (R) Windows Debugger Version 6.10.0003.233 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Windows\Minidump\Mini020709-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*c:\windows\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is: 
Windows Server 2008/Windows Vista SP1 Kernel Version 6001 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 6001.18145.amd64fre.vistasp1_gdr.080917-1612
Machine Name:
Kernel base = 0xfffff800`01e50000 PsLoadedModuleList = 0xfffff800`02015db0
Debug session time: Sat Feb  7 12:53:38.366 2009 (GMT+1)
System Uptime: 0 days 6:34:47.838
Loading Kernel Symbols
...............................................................
................................................................
.............................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck A, {fffff6fc4804a880, 2, 0, fffff80001ebc4fc}

Probably caused by : memory_corruption ( nt!MiPfnShareCountIsZero+7c )

Followup: MachineOwner
---------

3: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high.  This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: fffff6fc4804a880, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, bitfield :
	bit 0 : value 0 = read operation, 1 = write operation
	bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff80001ebc4fc, address which referenced memory

Debugging Details:
------------------


READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002079080
 fffff6fc4804a880 

CURRENT_IRQL:  2

FAULTING_IP: 
nt!MiPfnShareCountIsZero+7c
fffff800`01ebc4fc f6043001        test    byte ptr [rax+rsi],1

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

BUGCHECK_STR:  0xA

PROCESS_NAME:  System

TRAP_FRAME:  fffffa6001b8e5e0 -- (.trap 0xfffffa6001b8e5e0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000007c4804a880 rbx=0000000000000000 rcx=fffffa8003591ff0
rdx=fffff89009510e60 rsi=0000000003596000 rdi=0000000000000000
rip=fffff80001ebc4fc rsp=fffffa6001b8e770 rbp=0000000000000040
 r8=0000000000000006  r9=020000000004ea1a r10=0000000000000000
r11=0000007ffffffff8 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei pl nz na pe nc
nt!MiPfnShareCountIsZero+0x7c:
fffff800`01ebc4fc f6043001        test    byte ptr [rax+rsi],1 ds:0000007c`4b5e0880=??
Resetting default scope

LAST_CONTROL_TRANSFER:  from fffff80001ea50ee to fffff80001ea5350

STACK_TEXT:  
fffffa60`01b8e498 fffff800`01ea50ee : 00000000`0000000a fffff6fc`4804a880 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
fffffa60`01b8e4a0 fffff800`01ea3fcb : 00000000`00000000 fffff980`0e642d2a fffff980`0e642c00 fffffa80`03591ff0 : nt!KiBugCheckDispatch+0x6e
fffffa60`01b8e5e0 fffff800`01ebc4fc : 00000000`0011dc14 00000000`00000000 fffffa80`035943c0 00000000`00000040 : nt!KiPageFault+0x20b
fffffa60`01b8e770 fffff800`01ec6eaf : fffff980`1b23f201 00000000`0000003f 00000000`00000040 00000000`000000ff : nt!MiPfnShareCountIsZero+0x7c
fffffa60`01b8e7f0 fffff800`02121f49 : 00000000`00000000 fffff880`0d936460 fffffa80`00000000 00000000`00012464 : nt!MmUnmapViewInSystemCache+0x59f
fffffa60`01b8eac0 fffff800`01eb779e : 00000000`005c0000 fffffa60`019d27f0 fffffa80`0399c988 00000000`03600000 : nt!CcUnmapVacb+0x59
fffffa60`01b8eb00 fffff800`01ebdcd3 : 00000000`00000000 fffffa80`05211a20 00000000`00000000 00000000`00000000 : nt!CcUnmapVacbArray+0x2be
fffffa60`01b8eb80 fffff800`01ebe89b : fffffa80`079ca010 00000000`00000000 00000000`00000000 00000000`00000000 : nt!CcDeleteSharedCacheMap+0x123
fffffa60`01b8ebe0 fffff800`01ebefbb : fffffa80`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!CcWriteBehind+0x5eb
fffffa60`01b8ec70 fffff800`01eb205a : fffffa80`03984010 fffff800`0204e8a0 fffffa80`044adb90 fffffa80`00000001 : nt!CcWorkerThread+0x17b
fffffa60`01b8ecf0 fffff800`020c7ff3 : fffffa80`03984010 00000000`00000000 fffffa80`039b2bb0 00000000`00000080 : nt!ExpWorkerThread+0x11a
fffffa60`01b8ed50 fffff800`01edf546 : fffffa60`005ec180 fffffa80`039b2bb0 fffffa60`005f5d40 00000000`00000001 : nt!PspSystemThreadStartup+0x57
fffffa60`01b8ed80 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KxStartSystemThread+0x16


STACK_COMMAND:  kb

FOLLOWUP_IP: 
nt!MiPfnShareCountIsZero+7c
fffff800`01ebc4fc f6043001        test    byte ptr [rax+rsi],1

SYMBOL_STACK_INDEX:  3

SYMBOL_NAME:  nt!MiPfnShareCountIsZero+7c

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

DEBUG_FLR_IMAGE_TIMESTAMP:  48d1ba35

IMAGE_NAME:  memory_corruption

FAILURE_BUCKET_ID:  X64_0xA_nt!MiPfnShareCountIsZero+7c

BUCKET_ID:  X64_0xA_nt!MiPfnShareCountIsZero+7c

Followup: MachineOwner
---------

3: kd> lmvm nt
start             end                 module name
fffff800`01e50000 fffff800`02368000   nt         (pdb symbols)          c:\windows\symbols\ntkrnlmp.pdb\149C563625CA49CEA2881CEDF5D55CCF2\ntkrnlmp.pdb
    Loaded symbol image file: ntkrnlmp.exe
    Mapped memory image file: c:\windows\symbols\ntoskrnl.exe\48D1BA35518000\ntoskrnl.exe
    Image path: ntkrnlmp.exe
    Image name: ntkrnlmp.exe
    Timestamp:        Thu Sep 18 04:17:25 2008 (48D1BA35)
    CheckSum:         0047E2D2
    ImageSize:        00518000
    File version:     6.0.6001.18145
    Product version:  6.0.6001.18145
    File flags:       0 (Mask 3F)
    File OS:          40004 NT Win32
    File type:        1.0 App
    File date:        00000000.00000000
    Translations:     0409.04b0
    CompanyName:      Microsoft Corporation
    ProductName:      Microsoft Windows Operating System
    InternalName:     ntkrnlmp.exe
    OriginalFilename: ntkrnlmp.exe
    ProductVersion:   6.0.6001.18145
    FileVersion:      6.0.6001.18145 (vistasp1_gdr.080917-1612)
    FileDescription:  NT Kernel & System
    LegalCopyright:    Microsoft Corporation. All rights reserved.
