Microsoft (R) Windows Debugger Version 6.2.9200.20512 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Windows\Minidump\010413-5421-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\symbols*
http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 8 Kernel Version 9200 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 9200.16461.amd64fre.win8_gdr.121119-1606
Machine Name:
Kernel base = 0xfffff801`2d089000 PsLoadedModuleList = 0xfffff801`2d353a80
Debug session time: Fri Jan 4 13:08:47.567 2013 (UTC + 1:00)
System Uptime: 0 days 0:02:07.203
Loading Kernel Symbols
...............................................................
................................................................
...........................
Loading User Symbols
Loading unloaded module list
..........
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1A, {41201, fffff6800d400548, 1, fffffa800645acf0}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+34264 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041201, The subtype of the bugcheck.
Arg2: fffff6800d400548
Arg3: 0000000000000001
Arg4: fffffa800645acf0
Debugging Details:
------------------
BUGCHECK_STR: 0x1a_41201
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
PROCESS_NAME: MsMpEng.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff8012d196194 to fffff8012d104340
STACK_TEXT:
fffff880`17c617a8 fffff801`2d196194 : 00000000`0000001a 00000000`00041201 fffff680`0d400548 00000000`00000001 : nt!KeBugCheckEx
fffff880`17c617b0 fffff801`2d174406 : 00000000`00000080 00000000`0000008a fffff680`0d400548 fffff801`2d14f406 : nt! ?? ::FNODOBFM::`string'+0x34264
fffff880`17c61800 fffff801`2d4f943b : fffffa80`0645acf0 00000000`00000000 fffff880`17c61b80 fffffa80`00000004 : nt!MiCommitExistingVad+0x396
fffff880`17c618e0 fffff801`2d103353 : 00000000`00000000 ffffffff`ffffffff fffff6fb`7dbed000 fffff6fb`7da00350 : nt!NtAllocateVirtualMemory+0x3ec
fffff880`17c61a90 000007fa`2e052d6a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
0000001a`f5c8e348 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x000007fa`2e052d6a
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+34264
fffff801`2d196194 cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+34264
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 50ab0e64
BUCKET_ID_FUNC_OFFSET: 34264
FAILURE_BUCKET_ID: 0x1a_41201_nt!_??_::FNODOBFM::_string_
BUCKET_ID: 0x1a_41201_nt!_??_::FNODOBFM::_string_
Followup: MachineOwner
---------