Loading Dump File [C:\WINDOWS\MEMORY-vbox-200811.DMP] Kernel Summary Dump File: Only kernel address space is available Summary page-count cache: 0xf7dc entries, 0x8 stride, 0xbf3f present, 0x7bee0 total pages Symbol search path is: SRV*c:\local cache*http://msdl.microsoft.com/download/symbols Executable search path is: Loading symbols for 804d7000 ntkrpamp.exe -> ntkrpamp.exe ModLoad: 804d7000 806e2000 ntkrpamp.exe Windows XP Kernel Version 2600 (Service Pack 2) MP (2 procs) Free x86 compatible Product: WinNt, suite: TerminalServer SingleUserTS Built by: 2600.xpsp_sp2_gdr.070227-2254 Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055c700 Debug session time: Sun May 11 17:21:52.546 2008 (GMT-7) System Uptime: 0 days 21:24:20.260 Loading symbols for 804d7000 ntkrpamp.exe -> ntkrpamp.exe ModLoad: 804d7000 806e2000 ntkrpamp.exe Loading Kernel Symbols .ModLoad: 806e2000 80702d00 halmacpi.dll .ModLoad: bada8000 bada9b80 kdcom.dll .ModLoad: bacb8000 bacbb000 \WINDOWS\system32\BOOTVID.dll .ModLoad: ba6a9000 ba7a7000 sptd.sys .ModLoad: badaa000 badab100 \WINDOWS\System32\Drivers\WMILIB.SYS .ModLoad: ba691000 ba6a8800 \WINDOWS\System32\Drivers\SCSIPORT.SYS .ModLoad: ba663000 ba690d80 ACPI.sys .ModLoad: ba652000 ba662a80 pci.sys .ModLoad: ba8a8000 ba8b0c00 isapnp.sys .ModLoad: badac000 badad600 avgarkt.sys .ModLoad: bae70000 bae70d00 pciide.sys .ModLoad: bab28000 bab2e200 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS .ModLoad: ba8b8000 ba8c2500 MountMgr.sys .ModLoad: ba633000 ba651880 ftdisk.sys Unable to read image header at badae000 .ModLoad: badae000 badb0000 dmload.sys .ModLoad: ba60d000 ba632700 dmio.sys .ModLoad: bab30000 bab34900 PartMgr.sys .ModLoad: ba8c8000 ba8d4c80 VolSnap.sys .ModLoad: ba5f5000 ba60c480 atapi.sys .ModLoad: ba8d8000 ba8e0e00 disk.sys .ModLoad: ba8e8000 ba8f4200 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS .ModLoad: ba5d5000 ba5f4780 fltMgr.sys .ModLoad: ba5c3000 ba5d4f00 sr.sys .ModLoad: ba8f8000 ba900b80 PxHelp20.sys .ModLoad: ba5ac000 ba5c2780 KSecDD.sys .ModLoad: ba599000 ba5abf00 WudfPf.sys .ModLoad: ba50c000 ba598400 Ntfs.sys .ModLoad: ba4df000 ba50ba80 NDIS.sys .ModLoad: ba4cb000 ba4df000 srescan.sys .ModLoad: ba908000 ba916e80 ohci1394.sys .ModLoad: ba918000 ba925000 \WINDOWS\system32\DRIVERS\1394BUS.SYS .ModLoad: ba4b0000 ba4ca580 Mup.sys .ModLoad: baa88000 baa97180 \SystemRoot\system32\DRIVERS\nic1394.sys .ModLoad: b9f2a000 b9f38000 \SystemRoot\system32\DRIVERS\AmdK8.sys .ModLoad: b9b23000 b9ee9ba0 \SystemRoot\system32\DRIVERS\nv4_mini.sys .ModLoad: b9b0f000 b9b22780 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS .ModLoad: bac10000 bac14280 \SystemRoot\system32\DRIVERS\usbohci.sys .ModLoad: b9aec000 b9b0ee80 \SystemRoot\system32\DRIVERS\USBPORT.SYS .ModLoad: bac18000 bac1e800 \SystemRoot\system32\DRIVERS\usbehci.sys .ModLoad: b9f1a000 b9f24380 \SystemRoot\system32\DRIVERS\imapi.sys .ModLoad: bad8c000 bad8e880 \SystemRoot\system32\drivers\pfc.sys .ModLoad: b9f0a000 b9f16180 \SystemRoot\system32\DRIVERS\cdrom.sys .ModLoad: b9efa000 b9f08080 \SystemRoot\system32\DRIVERS\redbook.sys .ModLoad: b9ac9000 b9aeb680 \SystemRoot\system32\DRIVERS\ks.sys .ModLoad: bac20000 bac27000 \SystemRoot\System32\Drivers\GEARAspiWDM.sys .ModLoad: b9eea000 b9efa000 \SystemRoot\system32\DRIVERS\bcm4sbxp.sys .ModLoad: b9a4f000 b9ac8f80 \SystemRoot\system32\drivers\ctaud2k.sys .ModLoad: b9a2d000 b9a4e700 \SystemRoot\system32\drivers\portcls.sys .ModLoad: ba968000 ba976b80 \SystemRoot\system32\drivers\drmk.sys .ModLoad: b99fa000 b9a2d000 \SystemRoot\system32\drivers\ctoss2k.sys .ModLoad: bac28000 bac30000 \SystemRoot\system32\drivers\ctprxy2k.sys .ModLoad: bad9c000 bad9ef80 \SystemRoot\system32\DRIVERS\ctgame.sys .ModLoad: b99d4000 b99fa000 \SystemRoot\system32\DRIVERS\HDAudBus.sys .ModLoad: b996f000 b99d4000 \SystemRoot\System32\Drivers\ajtuqigq.SYS .ModLoad: bade6000 bade7280 \SystemRoot\system32\DRIVERS\vncdrv.sys .ModLoad: baf5c000 baf5cc00 \SystemRoot\system32\DRIVERS\audstub.sys .ModLoad: b995d000 b996e780 \SystemRoot\system32\DRIVERS\bridge.sys .ModLoad: bac80000 bac84880 \SystemRoot\system32\DRIVERS\TDI.SYS .ModLoad: baa28000 baa34880 \SystemRoot\system32\DRIVERS\rasl2tp.sys .ModLoad: ba0ee000 ba0f0580 \SystemRoot\system32\DRIVERS\ndistapi.sys .ModLoad: b9946000 b995c680 \SystemRoot\system32\DRIVERS\ndiswan.sys .ModLoad: baa38000 baa42200 \SystemRoot\system32\DRIVERS\raspppoe.sys .ModLoad: baa48000 baa53d00 \SystemRoot\system32\DRIVERS\raspptp.sys .ModLoad: b9935000 b9945e00 \SystemRoot\system32\DRIVERS\psched.sys .ModLoad: baa58000 baa60900 \SystemRoot\system32\DRIVERS\msgpc.sys .ModLoad: bac88000 bac8c580 \SystemRoot\system32\DRIVERS\ptilink.sys .ModLoad: bac90000 bac94080 \SystemRoot\system32\DRIVERS\raspti.sys .ModLoad: baa68000 baa71da0 \SystemRoot\system32\DRIVERS\VBoxTAP.sys .ModLoad: b9904000 b9934100 \SystemRoot\system32\DRIVERS\rdpdr.sys .ModLoad: baa78000 baa81f00 \SystemRoot\system32\DRIVERS\termdd.sys .ModLoad: bac98000 bac9e000 \SystemRoot\system32\DRIVERS\kbdclass.sys .ModLoad: baca0000 baca5a00 \SystemRoot\system32\DRIVERS\mouclass.sys .ModLoad: bae00000 bae01100 \SystemRoot\system32\DRIVERS\swenum.sys .ModLoad: b98a8000 b98db200 \SystemRoot\system32\DRIVERS\update.sys .ModLoad: bad5c000 bad5fc80 \SystemRoot\system32\DRIVERS\mssmbios.sys .ModLoad: b96e3000 b98a8000 \SystemRoot\system32\DRIVERS\TM_CFW.sys .ModLoad: baa98000 baaa1480 \SystemRoot\System32\Drivers\NDProxy.SYS .ModLoad: baab8000 baac6100 \SystemRoot\system32\DRIVERS\usbhub.sys .ModLoad: bae12000 bae13280 \SystemRoot\system32\DRIVERS\USBD.SYS .ModLoad: b7028000 b713a100 \SystemRoot\system32\drivers\sthda.sys .ModLoad: b6fd1000 b6ffb000 \SystemRoot\system32\drivers\hap16v2k.sys .ModLoad: b6ecd000 b6fd1000 \SystemRoot\system32\drivers\ha10kx2k.sys .ModLoad: b6ea0000 b6ecd000 \SystemRoot\system32\drivers\emupia2k.sys .ModLoad: b6e79000 b6ea0000 \SystemRoot\system32\drivers\ctsfm2k.sys .ModLoad: b6ddd000 b6e79000 \SystemRoot\system32\drivers\ctac32k.sys .ModLoad: b6c7b000 b6c9e000 \SystemRoot\system32\DRIVERS\klif.sys .ModLoad: bae30000 bae31f00 \SystemRoot\System32\Drivers\Fs_Rec.SYS Unable to read image header at baf21000 .ModLoad: baf21000 baf22000 \SystemRoot\System32\Drivers\Null.SYS .ModLoad: bae32000 bae33080 \SystemRoot\System32\Drivers\Beep.SYS .ModLoad: baf25000 baf25f80 \SystemRoot\System32\DRIVERS\AvgArCln.sys .ModLoad: bab80000 bab86180 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS .ModLoad: bab88000 bab8d200 \SystemRoot\System32\drivers\vga.sys .ModLoad: bae36000 bae37080 \SystemRoot\System32\Drivers\mnmdd.SYS .ModLoad: bae38000 bae39080 \SystemRoot\System32\DRIVERS\RDPCDD.sys .ModLoad: bab90000 bab94a80 \SystemRoot\System32\Drivers\Msfs.SYS .ModLoad: bab98000 bab9f880 \SystemRoot\System32\Drivers\Npfs.SYS .ModLoad: ba470000 ba472280 \SystemRoot\system32\DRIVERS\rasacd.sys .ModLoad: b6c48000 b6c5a400 \SystemRoot\system32\DRIVERS\ipsec.sys .ModLoad: b6bf0000 b6c47e80 \SystemRoot\system32\DRIVERS\tcpip.sys .ModLoad: b6bc8000 b6befc00 \SystemRoot\system32\DRIVERS\netbt.sys .ModLoad: b9f3a000 b9f42700 \SystemRoot\system32\DRIVERS\wanarp.sys .ModLoad: b6ba7000 b6bc7f00 \SystemRoot\system32\DRIVERS\ipnat.sys .ModLoad: b6b1f000 b6b7e0e0 \SystemRoot\System32\vsdatant.sys .ModLoad: ba958000 ba966d80 \SystemRoot\system32\DRIVERS\arp1394.sys .ModLoad: b6afd000 b6b1ed00 \SystemRoot\System32\drivers\afd.sys .ModLoad: ba978000 ba980700 \SystemRoot\system32\DRIVERS\netbios.sys .ModLoad: baba0000 baba4860 \SystemRoot\system32\drivers\pstrip.sys .ModLoad: ba9a8000 ba9b0880 \SystemRoot\system32\DRIVERS\VBoxUSBMon.sys .ModLoad: ba9b8000 ba9c3cc0 \SystemRoot\system32\DRIVERS\VBoxDrv.sys .ModLoad: b6aeb000 b6afca00 \SystemRoot\system32\DRIVERS\tmtdi.sys .ModLoad: b6ac0000 b6aeaa00 \SystemRoot\system32\DRIVERS\rdbss.sys .ModLoad: b6a51000 b6abfa00 \SystemRoot\system32\DRIVERS\mrxsmb.sys .ModLoad: ba998000 ba9a0880 \SystemRoot\System32\Drivers\Fips.SYS .ModLoad: ba9e8000 ba9f7900 \SystemRoot\System32\Drivers\Cdfs.SYS .ModLoad: b96df000 b96e1580 \SystemRoot\system32\DRIVERS\hidusb.sys .ModLoad: ba9f8000 baa00d80 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS .ModLoad: babb8000 babbfb80 \SystemRoot\system32\DRIVERS\usbccgp.sys .ModLoad: babc0000 babc6780 \SystemRoot\system32\DRIVERS\USBSTOR.SYS .ModLoad: b96d7000 b96d9f80 \SystemRoot\system32\DRIVERS\mouhid.sys .ModLoad: b96d3000 b96d6a00 \SystemRoot\system32\DRIVERS\kbdhid.sys .ModLoad: bae58000 bae59100 \SystemRoot\System32\Drivers\dump_WMILIB.SYS .ModLoad: bf800000 bf9c2800 \SystemRoot\System32\win32k.sys .ModLoad: bada0000 bada2900 \SystemRoot\System32\drivers\Dxapi.sys .ModLoad: babd8000 babdc500 \SystemRoot\System32\watchdog.sys .ModLoad: bf9c3000 bf9d4580 \SystemRoot\System32\drivers\dxg.sys .ModLoad: baeeb000 baeebd00 \SystemRoot\System32\drivers\dxgthk.sys .ModLoad: bf9d5000 bfe1eb00 \SystemRoot\System32\nv4_disp.dll .ModLoad: b56ae000 b56d1000 \SystemRoot\System32\Drivers\Fastfat.SYS .ModLoad: bffa0000 bffe5c00 \SystemRoot\System32\ATMFD.DLL .ModLoad: b6999000 b69a6000 \??\C:\Program Files\Trend Micro\OfficeScan Client\TmPreFlt.sys .ModLoad: b547a000 b5595d00 \??\C:\Program Files\Trend Micro\OfficeScan Client\VSApiNt.sys .ModLoad: b5437000 b547a000 \??\C:\Program Files\Trend Micro\OfficeScan Client\TmXPFlt.sys .ModLoad: b4bf7000 b4bfa900 \SystemRoot\system32\DRIVERS\ndisuio.sys .ModLoad: b3f72000 b3f86400 \SystemRoot\system32\drivers\wdmaud.sys .ModLoad: b412f000 b413dd80 \SystemRoot\system32\drivers\sysaudio.sys .ModLoad: b3bd0000 b3bfbd80 \SystemRoot\system32\DRIVERS\mrxdav.sys .ModLoad: b3b2e000 b3b7f480 \SystemRoot\system32\DRIVERS\srv.sys .ModLoad: b397d000 b399d280 \??\C:\WINDOWS\system32\drivers\tmcomm.sys .ModLoad: bade0000 bade1780 \SystemRoot\System32\Drivers\vnccom.SYS .ModLoad: bac58000 bac5ca00 \SystemRoot\system32\DRIVERS\LVPr2Mon.sys .ModLoad: b352c000 b356c280 \SystemRoot\System32\Drivers\HTTP.sys .ModLoad: b1961000 b1978480 \SystemRoot\System32\Drivers\dump_atapi.sys .ModLoad: b1936000 b1960180 \SystemRoot\system32\drivers\kmixer.sys Loading User Symbols Loading unloaded module list ............................................. Loaded dbghelp extension DLL Loaded ext extension DLL Loaded exts extension DLL Loaded kext extension DLL Loaded kdexts extension DLL ERROR: FindPlugIns 8007007b ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck A, {805a0174, 2, 8, 805a0174} Loading symbols for ba9b8000 VBoxDrv.sys -> VBoxDrv.sys *** ERROR: Symbol file could not be found. Defaulted to export symbols for VBoxDrv.sys - Probably caused by : VBoxDrv.sys ( VBoxDrv+52a ) Followup: MachineOwner --------- 0: kd> !analyze -v ERROR: FindPlugIns 8007007b ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* IRQL_NOT_LESS_OR_EQUAL (a) An attempt was made to access a pageable (or completely invalid) address at an interrupt request level (IRQL) that is too high. This is usually caused by drivers using improper addresses. If a kernel debugger is available get the stack backtrace. Arguments: Arg1: 805a0174, memory referenced Arg2: 00000002, IRQL Arg3: 00000008, value 0 = read operation, 1 = write operation Arg4: 805a0174, address which referenced memory Debugging Details: ------------------ WRITE_ADDRESS: 805a0174 CURRENT_IRQL: 2 FAULTING_IP: nt!KeQueryActiveProcessors+0 805a0174 a1504a5580 mov eax,dword ptr [nt!KeActiveProcessors (80554a50)] DEFAULT_BUCKET_ID: DRIVER_FAULT BUGCHECK_STR: 0xA PROCESS_NAME: System TRAP_FRAME: bacc7df8 -- (.trap 0xffffffffbacc7df8) ErrCode = 00000010 eax=00000000 ebx=00000000 ecx=00000041 edx=00000000 esi=893c8000 edi=8a0d38a0 eip=805a0174 esp=bacc7e6c ebp=bacc7e84 iopl=0 nv up ei pl zr na pe nc cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010246 nt!KeQueryActiveProcessors: 805a0174 a1504a5580 mov eax,dword ptr [nt!KeActiveProcessors (80554a50)] ds:0023:80554a50=00000003 Resetting default scope LAST_CONTROL_TRANSFER: from 805a0174 to 80543930 STACK_TEXT: bacc7df8 805a0174 badb0d00 00000000 b6bf03dd nt!KiTrap0E+0x238 bacc7e68 ba9b852a 00000000 ba9b84e0 bacc7eac nt!KeQueryActiveProcessors WARNING: Stack unwind information not available. Following frames may be wrong. bacc7e84 805016f7 8a0d3918 8a0d38a0 2d54824e VBoxDrv+0x52a bacc7fa0 80501813 806e4ae4 ffdff9c0 ffdff000 nt!KiTimerListExpire+0x14b bacc7fcc 805450bf 8055b4a0 00000000 004b4110 nt!KiTimerExpiration+0xb1 bacc7ff4 80544c2b bad1bbac 00000000 00000000 nt!KiRetireDpcList+0x61 bacc7ff8 bad1bbac 00000000 00000000 00000000 nt!KiDispatchInterrupt+0x2b 80544c2b 00000000 00000009 0081850f bb830000 0xbad1bbac STACK_COMMAND: kb FOLLOWUP_IP: VBoxDrv+52a ba9b852a b102 mov cl,2 SYMBOL_STACK_INDEX: 2 FOLLOWUP_NAME: MachineOwner MODULE_NAME: VBoxDrv IMAGE_NAME: VBoxDrv.sys DEBUG_FLR_IMAGE_TIMESTAMP: 4818d171 SYMBOL_NAME: VBoxDrv+52a FAILURE_BUCKET_ID: 0xA_W_VBoxDrv+52a BUCKET_ID: 0xA_W_VBoxDrv+52a Followup: MachineOwner --------- 0: kd> lmvm VBoxDrv start end module name ba9b8000 ba9c3cc0 VBoxDrv (export symbols) VBoxDrv.sys Loaded symbol image file: VBoxDrv.sys Image path: \SystemRoot\system32\DRIVERS\VBoxDrv.sys Image name: VBoxDrv.sys Timestamp: Wed Apr 30 13:07:13 2008 (4818D171) CheckSum: 0001730A ImageSize: 0000BCC0 Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0