Wklejam odczyt z pliku minidump czy ktoś wie na jakie kody tam patrzeć
Microsoft ® Windows Debugger Version 6.11.0001.404 X86
Copyright © Microsoft Corporation. All rights reserved.
Loading Dump File [C]
Mini Kernel Dump File: Only registers and stack trace are available
WARNING: Whitespace at end of path element
Symbol search path is: SRV*c:\symbole*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows Server 2008/Windows Vista Kernel Version 6002 (Service Pack 2) MP (4 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 6002.18082.x86fre.vistasp2_gdr.090803-2339
Machine Name:
Kernel base = 0x81e0f000 PsLoadedModuleList = 0x81f26c70
Debug session time: Wed Oct 28 11:35:22.605 2009 (GMT+0)
System Uptime: 0 days 0:00:56.635
Loading Kernel Symbols
…
Loading User Symbols
Loading unloaded module list
…
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck A, {10, 2, 0, 81eccfd7}
Probably caused by : ecache.sys ( ecache!EcMemoryCacheIoRoutine+16e )
Followup: MachineOwner
3: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 00000010, memory referenced
Arg2: 00000002, IRQL
Arg3: 00000000, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: 81eccfd7, address which referenced memory
Debugging Details:
READ_ADDRESS: GetPointerFromAddress: unable to read from 81f46868
Unable to read MiSystemVaType memory at 81f26420
00000010
CURRENT_IRQL: 2
FAULTING_IP:
nt!MiReplicatePteChange+232
81eccfd7 8b19 mov ebx,dword ptr [ecx]
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xA
PROCESS_NAME: System
TRAP_FRAME: 8bb9ba2c – (.trap 0xffffffff8bb9ba2c)
ErrCode = 00000000
eax=fffffde8 ebx=000000c2 ecx=00000010 edx=00000000 esi=00000fff edi=c0602928
eip=81eccfd7 esp=8bb9baa0 ebp=8bb9baec iopl=0 nv up ei pl zr na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010246
nt!MiReplicatePteChange+0x232:
81eccfd7 8b19 mov ebx,dword ptr [ecx] ds:0023:00000010=???
Resetting default scope
LAST_CONTROL_TRANSFER: from 81eccfd7 to 81e5cfb9
STACK_TEXT:
8bb9ba2c 81eccfd7 badb0d00 00000000 02b9bafc nt!KiTrap0E+0x2e1
8bb9baec 81e98457 00525000 81f21ea0 00000200 nt!MiReplicatePteChange+0x232
8bb9bb54 81ecd3e1 c0526000 c0525ff8 00000000 nt!MiMakeZeroedPageTables+0x5eb
8bb9bb90 81e8e9ca 81f21ea0 00000200 88278398 nt!MiExpandPtes+0x1aa
8bb9bbec 8af76490 88278398 00000000 00000001 nt!MmMapLockedPagesSpecifyCache+0x20d
8bb9bc80 8af76ff0 859f41c0 861eb000 8af80680 ecache!EcMemoryCacheIoRoutine+0x16e
8bb9bd7c 81fe4c42 8af80540 b62a035f 00000000 ecache!EcCacheIoWorker+0xa22
8bb9bdc0 81e4defe 8af765ce 8af80540 00000000 nt!PspSystemThreadStartup+0x9d
00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x16
STACK_COMMAND: kb
FOLLOWUP_IP:
ecache!EcMemoryCacheIoRoutine+16e
8af76490 85c0 test eax,eax
SYMBOL_STACK_INDEX: 5
SYMBOL_NAME: ecache!EcMemoryCacheIoRoutine+16e
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: ecache
IMAGE_NAME: ecache.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 49e01f2c
FAILURE_BUCKET_ID: 0xA_ecache!EcMemoryCacheIoRoutine+16e
BUCKET_ID: 0xA_ecache!EcMemoryCacheIoRoutine+16e
Followup: MachineOwner
3: kd> lmvm ecache
start end module name
8af69000 8af90000 ecache (pdb symbols) c:\symbole\ecache.pdb\A5332849207B4A4ABE7D97508316FFEE1\ecache.pdb
Loaded symbol image file: ecache.sys
Mapped memory image file: c:\symbole\ecache.sys\49E01F2C27000\ecache.sys
Image path: \SystemRoot\System32\drivers\ecache.sys
Image name: ecache.sys
Timestamp: Sat Apr 11 05:40:12 2009 (49E01F2C)
CheckSum: 000270B9
ImageSize: 00027000
File version: 6.0.6002.18005
Product version: 6.0.6002.18005
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0000.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: ecache.sys
OriginalFilename: ecache.sys
ProductVersion: 6.0.6002.18005
FileVersion: 6.0.6002.18005 (lh_sp2rtm.090410-1830)
FileDescription: Special Memory Device Cache
LegalCopyright: © Microsoft Corporation. All rights reserved.