you Microsoft (R) Windows Debugger Version 6.11.0001.404 X86 Copyright (c) Microsoft Corporation. All rights reserved. Loading Dump File [C:/Windows/Minidump/061411-31218-01.dmp] Mini Kernel Dump File: Only registers and stack trace are available Symbol search path is: SRV*D:/down/TEMP*http://msdl.microsoft.com/download/symbols Executable search path is: Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatible Product: WinNt, suite: TerminalServer SingleUserTS Built by: 7600.16695.x86fre.win7_gdr.101026-1503 Machine Name: Kernel base = 0x8404a000 PsLoadedModuleList = 0x84192810 Debug session time: Tue Jun 14 00:39:18.577 2011 (GMT+8) System Uptime: 0 days 0:04:14.889 Loading Kernel Symbols ............................................................... ................................................................ ........................................... Loading User Symbols Loading unloaded module list ..... 0: kd> !analync -v No export analync found 0: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* PAGE_FAULT_IN_NONPAGED_AREA (50) Invalid system memory was referenced. This cannot be protected by try-except, it must be protected by a Probe. Typically the address is just plain bad or it is pointing at freed memory. Arguments: Arg1: aeaf6b3c, memory referenced. Arg2: 00000000, value 0 = read operation, 1 = write operation. Arg3: 8426ba0a, If non-zero, the instruction address which referenced the bad memory address. Arg4: 00000002, (reserved) Debugging Details: ------------------ *** WARNING: Unable to verify timestamp for Hookport.sys *** ERROR: Module load completed but symbols could not be loaded for Hookport.sys READ_ADDRESS: GetPointerFromAddress: unable to read from 841b2718 Unable to read MiSystemVaType memory at 84192160 aeaf6b3c FAULTING_IP: nt!ObpParseSymbolicLink+115 8426ba0a 8b4704 mov eax,dword ptr [edi+4] MM_INTERNAL_CODE: 2 CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0x50 PROCESS_NAME: Opera_1111_int CURRENT_IRQL: 0 TRAP_FRAME: 8eaf69dc -- (.trap 0xffffffff8eaf69dc) ErrCode = 00000000 eax=00000048 ebx=00000090 ecx=00000000 edx=00000002 esi=ab1e7998 edi=aeaf6b38 eip=8426ba0a esp=8eaf6a50 ebp=8eaf6a68 iopl=0 nv up ei pl zr na pe nc cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010246 nt!ObpParseSymbolicLink+0x115: 8426ba0a 8b4704 mov eax,dword ptr [edi+4] ds:0023:aeaf6b3c=???????? Resetting default scope LAST_CONTROL_TRANSFER: from 84090628 to 840cf9eb STACK_TEXT: 8eaf69c4 84090628 00000000 aeaf6b3c 00000000 nt!MmAccessFault+0x106 8eaf69c4 8426ba0a 00000000 aeaf6b3c 00000000 nt!KiTrap0E+0xdc 8eaf6a68 8426b57b 8a7bc128 0000002e 86846a30 nt!ObpParseSymbolicLink+0x115 8eaf6ae4 84291729 00000000 8eaf6b38 00000040 nt!ObpLookupObjectName+0x4fa 8eaf6b40 84289a7b 0199faa4 86535040 840ba601 nt!ObOpenObjectByName+0x165 8eaf6bbc 84295392 0199fadc 00100001 0199faa4 nt!IopCreateFile+0x673 8eaf6c08 84da6a42 0199fadc 00100001 0199faa4 nt!NtCreateFile+0x34 WARNING: Stack unwind information not available. Following frames may be wrong. 8eaf6d00 8408d43a 0199fadc 00100001 0199faa4 Hookport+0x1a42 8eaf6d00 77b86344 0199fadc 00100001 0199faa4 nt!KiFastCallEntry+0x12a 0199fae0 00000000 00000000 00000000 00000000 0x77b86344 STACK_COMMAND: kb FOLLOWUP_IP: Hookport+1a42 84da6a42 ?? ??? SYMBOL_STACK_INDEX: 7 SYMBOL_NAME: Hookport+1a42 FOLLOWUP_NAME: MachineOwner MODULE_NAME: Hookport IMAGE_NAME: Hookport.sys DEBUG_FLR_IMAGE_TIMESTAMP: 4dcd5b11 FAILURE_BUCKET_ID: 0x50_Hookport+1a42 BUCKET_ID: 0x50_Hookport+1a42 Followup: MachineOwner ---------