No, i wasn't doing anything heavy at the time. Its usually when i'm not really doing anything. Just browsing the net or something. It went down again this morning. Here is the dump file.
I'm sorry, i don't know what you mean when you tell me to turn off the index. Thanks
not much info in this one. svchost.exe and ntkrpamp.exe were the likely cause. Have you run a system file check? to run start, search, type cmd,
type sfc /scannow.
that should verify and repair system files. when it is finished you will have a report that tells you if there were nay it couldn't fix
ken
Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\K\Desktop\Mini092409-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*d:\symbols*
Symbol information
Executable search path is:
Windows Server 2008/Windows Vista Kernel Version 6002 (Service Pack 2) MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 6002.18005.x86fre.lh_sp2rtm.090410-1830
Machine Name:
Kernel base = 0x81e1b000 PsLoadedModuleList = 0x81f32c70
Debug session time: Thu Sep 24 09:05:21.241 2009 (GMT-4)
System Uptime: 0 days 0:03:30.912
Loading Kernel Symbols
...............................................................
................................................................
.........................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 19, {20, abd2db20, abd2db20, a000014}
GetPointerFromAddress: unable to read from 81f52868
Unable to read MiSystemVaType memory at 81f32420
Probably caused by : ntkrpamp.exe ( nt!ExFreePoolWithTag+17f )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
BAD_POOL_HEADER (19)
The pool is already corrupt at the time of the current request.
This may or may not be due to the caller.
The internal pool links must be walked to figure out a possible cause of
the problem, and then special pool applied to the suspect tags or the driver
verifier to a suspect driver.
Arguments:
Arg1: 00000020, a pool block header size is corrupt.
Arg2: abd2db20, The pool entry we were looking for within the page.
Arg3: abd2db20, The next pool entry.
Arg4: 0a000014, (reserved)
Debugging Details:
------------------
GetPointerFromAddress: unable to read from 81f52868
Unable to read MiSystemVaType memory at 81f32420
BUGCHECK_STR: 0x19_20
POOL_ADDRESS: GetPointerFromAddress: unable to read from 81f52868
Unable to read MiSystemVaType memory at 81f32420
abd2db20
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 81f08184 to 81ee8b0d
STACK_TEXT:
8c611a74 81f08184 00000019 00000020 abd2db20 nt!KeBugCheckEx+0x1e
8c611ae8 8203150f abd2db28 00000000 84664a10 nt!ExFreePoolWithTag+0x17f
8c611b04 82031206 abd2db28 8c611bec 8c611b50 nt!ObAssignObjectSecurityDescriptor+0x34
8c611b14 8203159b ac262960 00000003 00000000 nt!SeDefaultObjectMethod+0x32
8c611b50 8204b4ba 8c611b00 00000001 ac262960 nt!ObAssignSecurity+0x77
8c611c84 82033ea8 ac262960 00000000 00020008 nt!ObInsertObject+0x542
8c611d30 82036e60 fffffffe 00020008 00000000 nt!NtOpenThreadTokenEx+0x157
8c611d4c 81e65c7a fffffffe 00020008 00000001 nt!NtOpenThreadToken+0x18
8c611d4c 77685e74 fffffffe 00020008 00000001 nt!KiFastCallEntry+0x12a
WARNING: Frame IP not in any known module. Following frames may be wrong.
0320f588 00000000 00000000 00000000 00000000 0x77685e74
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!ExFreePoolWithTag+17f
81f08184 cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!ExFreePoolWithTag+17f
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrpamp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 49e0199e
FAILURE_BUCKET_ID: 0x19_20_nt!ExFreePoolWithTag+17f
BUCKET_ID: 0x19_20_nt!ExFreePoolWithTag+17f
Followup: MachineOwner
---------