debugging PAGE_FAULT_IN_NONPAGED_AREA

Grretings everybody.

We are experiencing a bugcheck on one machine with Norton Antivirus
installed (the machine is on another continent …). I have developed a
legacy driver and have used verifier religiously and AFAIK we have no known
issue. Our driver runs on several thousands machines, yet, on this machine,
when NAV is turned on and our driver starts (usually auto start) the system
bugcheks. I was told that a defrag also caused a crash but I was not told
whether our driver was running or not at the time. ( BTW< I am not even sure
that it is related to NAV).

I have looked at the kernel dump for a good while but can’t see anything
that will help me figure out what’s the interop issue we are having. I see
that cisvc.exe was running and that it crashes in the middle of an NTFS
operation but besides that … I am a bit lost. I have asked for a defrag and
I was told that the system crashed, which is not a good symptom either
(unfortunately I was not given that dump file).

Any help is much appreciated!

thanks,

Marco

kd> !analyze -v
*******************************************************************************
*
*
* Bugcheck Analysis
*
*
*
*******************************************************************************

(50)
Invalid system memory was referenced. This cannot be protected by
try-except,
it must be protected by a Probe. Typically the address is just plain bad or
it
is pointing at freed memory.
Arguments:
Arg1: 9b9a0000, memory referenced.
Arg2: 00000000, value 0 = read operation, 1 = write operation.
Arg3: 804f8716, If non-zero, the instruction address which referenced the
bad memory
address.
Arg4: 00000000, (reserved)

Debugging Details:

READ_ADDRESS: 9b9a0000

FAULTING_IP:
nt!RtlIsValidHandler+3c
804f8716 8b1c88 mov ebx,[eax+ecx*4]

MM_INTERNAL_CODE: 0

DEFAULT_BUCKET_ID: DRIVER_FAULT

BUGCHECK_STR: 0x50

EXCEPTION_RECORD: f4fdc72c – (.exr fffffffff4fdc72c)
ExceptionAddress: f733ac6f (Ntfs!NtfsNonCachedIo+0x0000068f)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 00000000
Parameter[1]: 00300000
Attempt to read from address 00300000

LAST_CONTROL_TRANSFER: from 805246fb to 805339ae

STACK_TEXT:
f4fdc1f0 805246fb 00000050 9b9a0000 00000000 nt!KeBugCheckEx+0x1b
f4fdc23c 804e1ff1 00000000 9b9a0000 00000000 nt!MmAccessFault+0x6f5
f4fdc23c 804f8716 00000000 9b9a0000 00000000 nt!KiTrap0E+0xcc
f4fdc2d8 804f865f 33de0000 00000000 f4fdc72c nt!RtlIsValidHandler+0x3c
f4fdc354 8050c72e f4fdc72c f4fdc428 00300000 nt!RtlDispatchException+0x59
f4fdc710 804dfada f4fdc72c 00000000 f4fdc780 nt!KiDispatchException+0x13e
f4fdc778 804dfa86 f4fdc9b4 f733ac6f badb0d00 nt!CommonDispatchException+0x4d
f4fdc794 804e4fcb f4fdc9f0 f4fdc7cc 804dc862 nt!Kei386EoiHelper+0x18a
f4fdc9b4 f73326fe f4fdcaa8 86a3d390 e10660d0 nt!KiAdjustQuantumThread+0x48
f4fdca94 f7331fbf f4fdcaa8 86a3d390 00000001 Ntfs!NtfsCommonRead+0xbdd
f4fdcc44 804e3d77 86f53020 86a3d390 00001000 Ntfs!NtfsFsdRead+0x22d
f4fdcc54 804fb168 86dbada8 86f7dce8 86f7dcf8 nt!IopfCallDriver+0x31
f4fdcc68 804fb18f 86f53020 86f7dd07 86f7dd00 nt!IopPageReadInternal+0xf4
f4fdcc88 804fadf4 86e459e0 86f7dd20 86f7dd00 nt!IoPageRead+0x1b
f4fdccfc 804e97de 2b6b28c0 00b61000 c0002d84 nt!MiDispatchFault+0x274
f4fdcd4c 804e1ff1 00000000 00b61000 01000001 nt!MmAccessFault+0xc09
f4fdcd4c 7da3b8a5 00000000 00b61000 01000001 nt!KiTrap0E+0xcc
WARNING: Frame IP not in any known module. Following frames may be wrong.
0091e080 00000000 00000000 00000000 00000000 0x7da3b8a5

STACK_COMMAND: .bugcheck ; kb

FOLLOWUP_IP:
nt!RtlIsValidHandler+3c
804f8716 8b1c88 mov ebx,[eax+ecx*4]

FAULTING_SOURCE_CODE:

SYMBOL_STACK_INDEX: 3

FOLLOWUP_NAME: MachineOwner

SYMBOL_NAME: nt!RtlIsValidHandler+3c

MODULE_NAME: nt

IMAGE_NAME: ntoskrnl.exe

DEBUG_FLR_IMAGE_TIMESTAMP: 41108004

FAILURE_BUCKET_ID: 0x50_nt!RtlIsValidHandler+3c

BUCKET_ID: 0x50_nt!RtlIsValidHandler+3c

Followup: MachineOwner

kd> !stacks
Proc.Thread .Thread Ticks ThreadState Blocker
[86fc6a00 System]
4.000008 86fc6788 00000e3 READY nt!KiDispatchInterrupt+0x7f
4.000120 86d29da8 0005d5b Blocked emu10k1m!EfxThread+0x197
4.0000a4 86da1318 0006a98 Blocked hcmon+0xb3b
4.0003ec 86be57a0 0001f79 Blocked
pmsecdrv210141!Sections::CleanThread+0x36
4.0003f0 86be5528 0000036 Blocked
pmsecdrv210141!dllhook::CleanThread+0x2b
4.000468 86a06da8 0000492 Blocked HTTP!UlpScavengerThread+0x5d

[86da3a78 smss.exe]

[86f9cda0 csrss.exe]
280.000290 86baeda8 000001a Blocked nt!KiFastCallEntry+0xf8
280.0002a0 86ec77c0 000001a Blocked nt!KiFastCallEntry+0xf8
280.0002a8 86e6f4e8 0000004 Blocked
win32k!xxxMsgWaitForMultipleObjects+0xb0
280.0006a4 86ea75d8 000001a Blocked nt!KiFastCallEntry+0xf8

[86ec5950 winlogon.exe]
298.0002b0 86f84398 00002f1 Blocked nt!KiFastCallEntry+0xf8
298.0002b4 86e171c8 0000733 Blocked nt!KiFastCallEntry+0xf8
298.0002c0 86d79da8 00002f1 Blocked nt!KiFastCallEntry+0xf8
298.00039c 86b1ecb0 00002bb Blocked nt!KiFastCallEntry+0xf8
298.000284 86d60da8 0000068 Blocked nt!KiFastCallEntry+0xf8
298.0007d4 86d791c8 0000039 READY nt!KiFastCallEntry+0xf8
298.0004f0 86e61020 0000068 Blocked nt!KiFastCallEntry+0xf8
298.000698 86b13920 0000733 Blocked nt!KiFastCallEntry+0xf8
298.000c00 86a2d598 00002bb Blocked nt!KiFastCallEntry+0xf8

[86d8b9a8 services.exe]
2c4.00030c 86dccc18 00006c3 Blocked nt!KiFastCallEntry+0xf8
2c4.00063c 86b29da8 00002b1 Blocked nt!KiFastCallEntry+0xf8
2c4.000654 86b362c8 00002b1 Blocked nt!KiFastCallEntry+0xf8
2c4.00021c 86b69240 00002b1 Blocked nt!KiFastCallEntry+0xf8

[86ec25d0 lsass.exe]
2d0.0002e0 86b5a020 000051f Blocked nt!KiFastCallEntry+0xf8
2d0.0002e4 86b45020 000051f Blocked nt!KiFastCallEntry+0xf8
2d0.0002fc 86ec9658 0000095 Blocked nt!KiFastCallEntry+0xf8
2d0.00031c 86ec8998 00002bb Blocked nt!KiFastCallEntry+0xf8
2d0.000320 86f54910 00006c7 Blocked nt!KiFastCallEntry+0xf8
2d0.000334 86d58888 0000066 Blocked nt!KiFastCallEntry+0xf8
2d0.00036c 86b7c808 00002bb Blocked nt!KiFastCallEntry+0xf8
2d0.0006a8 86d7cda8 0000065 Blocked nt!KiFastCallEntry+0xf8
2d0.00053c 86bb0da8 000001d Blocked nt!KiFastCallEntry+0xf8

[86b49da0 svchost.exe]
374.000390 86b45cb0 000033c Blocked nt!KiFastCallEntry+0xf8
374.0005a0 86b55980 0000039 Blocked nt!KiFastCallEntry+0xf8

[86c7f128 svchost.exe]
3ac.0003bc 86c6da88 0000564 Blocked nt!KiFastCallEntry+0xf8
3ac.0003c8 86b59578 0000024 Blocked nt!KiFastCallEntry+0xf8
3ac.0002d4 86dac370 0000031 Blocked nt!KiFastCallEntry+0xf8
3ac.00037c 86d9f5f8 0000031 Blocked nt!KiFastCallEntry+0xf8
3ac.000f0c 86a09640 0000031 Blocked nt!KiFastCallEntry+0xf8

[86d58da0 svchost.exe]
598.0005ac 86b67da8 0000540 Blocked nt!KiFastCallEntry+0xf8
598.000750 86b1d020 0000038 Blocked nt!KiFastCallEntry+0xf8
598.0007b8 86da04a0 00006e9 Blocked nt!KiFastCallEntry+0xf8
598.0007d8 86d825b0 00005e8 Blocked nt!KiFastCallEntry+0xf8
598.0007dc 86d94730 000004a Blocked nt!KiFastCallEntry+0xf8
598.0007fc 86e4eb20 00007c0 Blocked nt!KiFastCallEntry+0xf8
598.0001f0 86ba95f0 0000190 Blocked nt!KiFastCallEntry+0xf8
598.000418 86d7e618 000016b Blocked nt!KiFastCallEntry+0xf8
598.000440 86d91020 00002ef Blocked nt!KiFastCallEntry+0xf8
598.000454 86d6f160 0000168 Blocked nt!KiFastCallEntry+0xf8
598.000350 86e4b020 00002ec Blocked nt!KiFastCallEntry+0xf8
598.000474 86b753d8 0000043 Blocked nt!KiFastCallEntry+0xf8
598.0006fc 86b1f148 00002ec Blocked nt!KiFastCallEntry+0xf8
598.00014c 86b5c3d8 0000190 Blocked nt!KiFastCallEntry+0xf8
598.00066c 86d97800 000016b Blocked nt!KiFastCallEntry+0xf8
598.000188 86eed300 0000168 Blocked nt!KiFastCallEntry+0xf8
598.000b60 86a34da8 0000040 Blocked nt!KiFastCallEntry+0xf8

[86b3d978 svchost.exe]
5e0.000194 86daa610 00006fe Blocked nt!KiFastCallEntry+0xf8

[86d62688 svchost.exe]
618.0002f8 86a06328 0000038 Blocked nt!KiFastCallEntry+0xf8
618.000610 86d68da8 00003d0 Blocked nt!KiFastCallEntry+0xf8
618.000bf4 86b1e2d0 0000310 Blocked nt!KiFastCallEntry+0xf8

[86b39550 lexbces.exE]

[86b22a90 spoolsv.exe]
78c.00079c 86b41c10 0000031 Blocked nt!KiFastCallEntry+0xf8
78c.000b30 86a3e598 0000039 Blocked nt!KiFastCallEntry+0xf8
78c.000b34 86a38598 0000031 Blocked nt!KiFastCallEntry+0xf8
78c.000c30 86a35b68 0000070 Blocked nt!KiFastCallEntry+0xf8

[86b662c0 aspnet_admin.ex]
dc.000110 86d81418 000001e Blocked nt!KiFastCallEntry+0xf8

[86d933a0 cisvc.exe]
1d0.0001dc 86dbada8 0000000 RUNNING nt!KeBugCheckEx+0x1b
1d0.000fd4 86a55798 0000013 Blocked nt!KiFastCallEntry+0xf8
1d0.000fd8 86b68020 0000013 Blocked nt!KiFastCallEntry+0xf8
1d0.000fdc 86b76cb8 0000013 Blocked nt!KiFastCallEntry+0xf8

[86da5b88 defwatch.exe]

[86b4f3d0 inetinfo.exe]
210.00022c 86b42020 0000038 Blocked nt!KiFastCallEntry+0xf8
210.00012c 86b26800 000014f Blocked nt!KiFastCallEntry+0xf8
210.000548 86b3a858 000015c Blocked nt!KiFastCallEntry+0xf8
210.00056c 86d67460 000001e Blocked nt!KiFastCallEntry+0xf8
210.0005f8 86dad920 0000636 Blocked nt!KiFastCallEntry+0xf8
210.000600 86b47598 0000135 Blocked nt!KiFastCallEntry+0xf8
210.0006bc 869b9228 0000113 Blocked nt!KiFastCallEntry+0xf8
210.0000f8 86dba3a8 0000031 Blocked nt!KiFastCallEntry+0xf8
210.0001a0 86a37850 000015c Blocked nt!KiFastCallEntry+0xf8
210.00043c 86a433b8 0000135 Blocked nt!KiFastCallEntry+0xf8

[86b53a88 mdm.exe]

[86ba9da0 wdfmgr.exe]

[86da18b0 vmware-authd.ex]
528.0006dc 86e3c020 00000d4 Blocked nt!KiFastCallEntry+0xf8
528.0006e0 86ecc160 0000107 Blocked nt!KiFastCallEntry+0xf8
528.000170 86a8bda8 00000c7 Blocked nt!KiFastCallEntry+0xf8

[86b34558 vmnat.exe]

[86db0da0 vmnetdhcp.exe]

[86ec33c0 alg.exe]
3f4.000400 86ed0160 0000038 Blocked nt!KiFastCallEntry+0xf8
3f4.000414 86c713c8 00007c1 Blocked nt!KiFastCallEntry+0xf8
3f4.000424 86e74270 000057d Blocked nt!KiFastCallEntry+0xf8

[86e331c8 explorer.exe]
150.0004d8 8699dda8 0000594 Blocked nt!KiFastCallEntry+0xf8
150.0006b0 86b0e5e0 00002fd Blocked nt!KiFastCallEntry+0xf8
150.000664 86b798d8 00000da Blocked nt!KiFastCallEntry+0xf8

[86a8b360 ctfmon.exe]

[86a46838 communicator.ex]
3e4.000508 869b6928 0000039 Blocked nt!KiFastCallEntry+0xf8
3e4.0007bc 86d841d0 0000594 Blocked nt!KiFastCallEntry+0xf8
3e4.0008a8 86a6e200 0000594 Blocked nt!KiFastCallEntry+0xf8
3e4.0009bc 86a816e8 00002b1 Blocked nt!KiFastCallEntry+0xf8
3e4.0009c0 86a82da8 0000231 Blocked nt!KiFastCallEntry+0xf8
3e4.000d08 86a1a640 0000231 Blocked nt!KiFastCallEntry+0xf8

[86a785d0 devldr32.exe]

[86a2d240 cmd.exe]

[86a673f0 ssmypics.scr]
f4c.000f50 86a3c238 0000000 READY nt!KiDispatchInterrupt+0x7f

Threads Processed: 386
kd> !process
PROCESS 86d933a0 SessionId: 0 Cid: 01d0 Peb: 7ffd9000 ParentCid: 02c4
DirBase: 15975000 ObjectTable: e2b87008 HandleCount: 132.
Image: cisvc.exe
VadRoot 86e1c848 Vads 76 Clone 0 Private 332. Modified 182. Locked 0.
DeviceMap e1000068
Token e2b209b0
ElapsedTime 00:07:06.395
UserTime 00:00:00.062
KernelTime 00:00:00.140
QuotaPoolUsage[PagedPool] 36140
QuotaPoolUsage[NonPagedPool] 3872
Working Set Sizes (now,min,max) (711, 50, 345) (2844KB, 200KB, 1380KB)
PeakWorkingSetSize 711
VirtualSize 33 Mb
PeakVirtualSize 35 Mb
PageFaultCount 2002
MemoryPriority BACKGROUND
BasePriority 8
CommitCharge 488

THREAD 86d93128 Cid 01d0.01d4 Teb: 7ffdf000 Win32Thread: e2bbceb0
WAIT: (Executive) UserMode Non-Alertable
86b2a8ac NotificationEvent

THREAD 86dbada8 Cid 01d0.01dc Teb: 7ffde000 Win32Thread: e2300a58
RUNNING on processor 0
THREAD 86a55798 Cid 01d0.0fd4 Teb: 7ffdd000 Win32Thread: 00000000
WAIT: (UserRequest) UserMode Non-Alertable
86f85980 NotificationEvent
86a55888 NotificationTimer

THREAD 86b68020 Cid 01d0.0fd8 Teb: 7ffdc000 Win32Thread: 00000000
WAIT: (UserRequest) UserMode Non-Alertable
86b768a0 NotificationEvent
86b68110 NotificationTimer

THREAD 86b76cb8 Cid 01d0.0fdc Teb: 7ffdb000 Win32Thread: 00000000
WAIT: (UserRequest) UserMode Alertable
86b6f738 NotificationEvent

kd> !pool 9b9a0000
Pool page 9b9a0000 region is Unknown
9b9a0000 is not a valid small pool allocation, checking large pool…
unable to get pool big page table - either wrong symbols or pool tagging is
disabled
9b9a0000 is freed (or corrupt) pool
Bad allocation size @9b9a0000, too large

***
*** An error (or corruption) in the pool was detected;
*** Pool Region unknown (0xFFFFFFFF9B9A0000)
***
*** Use !poolval 9b9a0000 for more details.
***

kd> !poolval 9b9a0000
Pool page 9b9a0000 region is Unknown

Validating Pool headers for pool page: 9b9a0000

Pool page [9b9a0000] is __inVALID.

Analyzing linked list…

Scanning for single bit errors…

None found

kd> !pte 9b9a0000
VA 9b9a0000
PDE at C03009B8 PTE at C026E680
contains 06C68163 contains 00000000
pfn 6c68 -G-DA–KWEV

kd> lm
start end module name
804d7000 806eb780 nt (pdb symbols)
c:\websymbols\ntoskrnl.pdb\8592B6763F34476B9BB560395A383F962\ntoskrnl.pdb
806ec000 8070c380 hal (pdb symbols)
c:\websymbols\halaacpi.pdb\861E03E9E71D469BB4E544F22FD14C821\halaacpi.pdb
bf000000 bf011580 dxg (pdb symbols)
c:\websymbols\dxg.pdb\6443AD3CC36F49BD8A4D7F5259E15F591\dxg.pdb
bf012000 bf425a80 nv4_disp (pdb symbols)
c:\websymbols\nv4_disp.pdb\337C81EA47F04668A368C2AE12BF6E031\nv4_disp.pdb
bf800000 bf9c0380 win32k (pdb symbols)
c:\websymbols\win32k.pdb\D48935A134F249CDA985C45051FBF0462\win32k.pdb
f2491000 f24d1380 HTTP (pdb symbols)
c:\websymbols\http.pdb\98F1C36330524B0EA4D1FC9ED5BBEFEA1\http.pdb
f259a000 f25bc000 RDPWD (pdb symbols)
c:\websymbols\RDPWD.pdb\2371F6731A0B48839290F22CF2F6081B1\RDPWD.pdb
f26f9000 f270d400 wdmaud (pdb symbols)
c:\websymbols\wdmaud.pdb\69752CA941714E8B8AFCD29F503CE9AC2\wdmaud.pdb
f291e000 f292cd80 sysaudio (pdb symbols)
c:\websymbols\sysaudio.pdb\0680FF5C8E3A4B7CBDED87903282A5A32\sysaudio.pdb
f2a06000 f2a3d900 *mydriver* (private pdb symbols) xxxxx.pdb
f2b3e000 f2b90180 srv (pdb symbols)
c:\websymbols\srv.pdb\8A30C8312B30482F8819CA767AC92F792\srv.pdb
f2c31000 f2c335e0 vmnetuserif (no symbols)
f2c81000 f2cad400 mrxdav (pdb symbols)
c:\websymbols\mrxdav.pdb\39E18188AC3942C7B4CA8F4ABC3B15BF1\mrxdav.pdb
f2cce000 f2cd0080 NAVAPEL (no symbols)
f2de2000 f2de5280 ndisuio (pdb symbols)
c:\websymbols\ndisuio.pdb\CCBB88AAABB841A3A8FC18083379A4BA1\ndisuio.pdb
f4a4a000 f4a61480 dump_atapi (pdb symbols)
c:\websymbols\atapi.pdb\25228DED4EEC41F29756FC1568E4B63F1\atapi.pdb
f4a6b000 f4a6bd00 dxgthk (pdb symbols)
\VEGAS\SYMBOLS\sys\dxgthk.pdb
f4ccc000 f4cdb900 Cdfs (pdb symbols)
c:\websymbols\cdfs.pdb\E4641046039940509C2A785DBB90414D2\cdfs.pdb
f4db6000 f4dba500 watchdog (pdb symbols)
c:\websymbols\watchdog.pdb\E34D85BE76CF4B729B27F2CBD2559B881\watchdog.pdb
f53aa000 f53caf00 ipnat (pdb symbols)
c:\websymbols\ipnat.pdb\D0D6DF4996314C2EA051992A5A523E1D1\ipnat.pdb
f53cb000 f5439380 mrxsmb (pdb symbols)
c:\websymbols\mrxsmb.pdb\3D89944B671143FC844564D63F7B6E472\mrxsmb.pdb
f545a000 f545c900 Dxapi (pdb symbols)
\VEGAS\SYMBOLS\sys\dxapi.pdb
f5462000 f548d180 rdbss (pdb symbols)
c:\websymbols\rdbss.pdb\6BFF7598D30C4A76A045FF4DD18DABE32\rdbss.pdb
f548e000 f54afd00 afd (pdb symbols)
c:\websymbols\afd.pdb\F999EE0290D54451AEBCA30AD24CAAB22\afd.pdb
f54b0000 f54d7c00 netbt (pdb symbols)
c:\websymbols\netbt.pdb\68363A5520E247C5830D7E67ABA19D072\netbt.pdb
f54d8000 f552fa80 tcpip (pdb symbols)
c:\websymbols\tcpip.pdb\9546A8399BAC4717BC41758594EF0D9C2\tcpip.pdb
f5530000 f5542400 ipsec (pdb symbols)
c:\websymbols\ipsec.pdb\3A13FAB12CEF49028B6AA15B4CDF05CD2\ipsec.pdb
f67eb000 f681e200 update (pdb symbols)
c:\websymbols\update.pdb\C0E5C10D07AF4A139C0D21FC3510983C1\update.pdb
f6847000 f6877100 rdpdr (pdb symbols)
c:\websymbols\rdpdr.pdb\A81F0F623C3940169DC2E1C410338A031\rdpdr.pdb
f6878000 f6888e00 psched (pdb symbols)
c:\websymbols\psched.pdb\72F13E8E57F04ADA961EFC51F1587E9B1\psched.pdb
f6889000 f689f680 ndiswan (pdb symbols)
c:\websymbols\ndiswan.pdb\4C16F7937E5B43DCA456976A6860A80C2\ndiswan.pdb
f68d1000 f68f3e80 USBPORT (pdb symbols)
c:\websymbols\usbport.pdb\6577C031727943E7BE2D4A8742B28F141\usbport.pdb
f68f4000 f6907900 parport (pdb symbols)
c:\websymbols\parport.pdb\108A07CF6CCD442D9CC62CB94D8ADE1C1\parport.pdb
f6908000 f692a680 ks (pdb symbols)
c:\websymbols\ks.pdb\229E1E4007D54B0899543A3F3B247F882\ks.pdb
f692b000 f694e980 portcls (pdb symbols)
c:\websymbols\portcls.pdb\9380C119FB254169B3415C54DEF742F52\portcls.pdb
f694f000 f6994500 emu10k1m (pdb symbols)
\VEGAS\SYMBOLS\sys\EMU10K1M.pdb
f6995000 f69a5400 el90xbc5 (pdb symbols)
\VEGAS\SYMBOLS\sys\EL90XBC5.pdb
f69a6000 f69b9780 VIDEOPRT (pdb symbols)
c:\websymbols\videoprt.pdb\4F7109A70A214E10A9EB16F46D99D5681\videoprt.pdb
f69ba000 f6b893c0 nv4_mini (pdb symbols)
c:\websymbols\nv4_mini.pdb\334682060D21485394550043012EC7E61\nv4_mini.pdb
f72a6000 f72a8da0 VMNET (export symbols) VMNET.SYS
f72aa000 f72adc80 mssmbios (pdb symbols)
c:\websymbols\mssmbios.pdb\CEAE494998B24A458588AE7866D1B9421\mssmbios.pdb
f72e7000 f7301580 Mup (pdb symbols)
c:\websymbols\mup.pdb\B31678EDA6824BB19A2A0B8081DBF7D72\mup.pdb
f7302000 f732ea80 NDIS (pdb symbols)
c:\websymbols\ndis.pdb\42ED3DC0817A4246B157736BBAF668742\ndis.pdb
f732f000 f73bb480 Ntfs (pdb symbols)
c:\websymbols\ntfs.pdb\CF3F539EE3B2408887756DD42D7E53442\ntfs.pdb
f73bc000 f73d2780 KSecDD (pdb symbols)
c:\websymbols\ksecdd.pdb\E9FEAB740C29470CB973CD9D584FE5A51\ksecdd.pdb
f73d3000 f73f1780 fltmgr (pdb symbols)
c:\websymbols\fltMgr.pdb\A3669C0E41994AC2AD2BD6F85D4B1A041\fltMgr.pdb
f73f2000 f7409480 atapi (pdb symbols)
c:\websymbols\atapi.pdb\25228DED4EEC41F29756FC1568E4B63F1\atapi.pdb
f740a000 f742f700 dmio (pdb symbols)
c:\websymbols\dmio.pdb\A2AA03114EB84B26A6B8E29367484C881\dmio.pdb
f7430000 f744e880 ftdisk (pdb symbols)
\VEGAS\SYMBOLS\sys\ftdisk.pdb
f744f000 f745fa80 pci (pdb symbols)
c:\websymbols\pci.pdb\206656EB8AAA4BFCAE215D6EE55305881\pci.pdb
f7460000 f748dd80 ACPI (pdb symbols)
c:\websymbols\acpi.pdb\F2E034F2911844B491BDAB612C220EAB1\acpi.pdb
f74af000 f74b7c00 isapnp (pdb symbols)
\VEGAS\SYMBOLS\sys\isapnp.pdb
f74bf000 f74c9500 MountMgr (pdb symbols)
c:\websymbols\mountmgr.pdb\E76D919C975C47B1AB592D6BF9A53C1B1\mountmgr.pdb
f74cf000 f74dbc80 VolSnap (pdb symbols)
c:\websymbols\volsnap.pdb\37AD1DAAA6A04AF8B6FC8478DAFCBDE61\volsnap.pdb
f74df000 f74e7e00 disk (pdb symbols)
c:\websymbols\disk.pdb\D9F2945AC6DF4EEDB1E66ED610B7A04A1\disk.pdb
f74ef000 f74fb200 CLASSPNP (pdb symbols)
c:\websymbols\classpnp.pdb\12E3EB58301B4AC3A5B2D3921F91313A2\classpnp.pdb
f74ff000 f7509580 agp440 (pdb symbols)
c:\websymbols\agp440.pdb\F40E49B26D714B678E507055C5B9EBDA1\agp440.pdb
f753f000 f7549680 vmx86 (no symbols)
f756f000 f7577d00 intelppm (pdb symbols)
c:\websymbols\intelppm.pdb\E2C0A60010DB4AB7B45C8F3EF13DEF571\intelppm.pdb
f757f000 f758db80 drmk (export symbols) drmk.sys
f758f000 f7597e80 sfmanm (pdb symbols)
\VEGAS\SYMBOLS\sys\sfmanm.pdb
f759f000 f75abe00 i8042prt (pdb symbols)
c:\websymbols\i8042prt.pdb\F869B9CF49F740EA8295BD75997B338D2\i8042prt.pdb
f75af000 f75bed80 serial (pdb symbols)
c:\websymbols\serial.pdb\1EFB2CDF244D432A927A480E4C740FFB2\serial.pdb
f75bf000 f75cb180 cdrom (pdb symbols)
c:\websymbols\cdrom.pdb\849D224C3F8F411DB1F0591C655A3F651\cdrom.pdb
f75cf000 f75dd080 redbook (pdb symbols)
c:\websymbols\redbook.pdb\1E1D4F22947E487A8472B5E01CF664D51\redbook.pdb
f75df000 f75eb880 rasl2tp (pdb symbols)
c:\websymbols\rasl2tp.pdb\814E65B178D34814B403A26E2DC870422\rasl2tp.pdb
f75ef000 f75f9200 raspppoe (pdb symbols)
c:\websymbols\raspppoe.pdb\0F527A0AA94E4116AB3BDC8605A441431\raspppoe.pdb
f75ff000 f760ad00 raspptp (pdb symbols)
c:\websymbols\raspptp.pdb\E1B38928B9CF41AA829FF8252DA9BE582\raspptp.pdb
f760f000 f7617900 msgpc (pdb symbols)
c:\websymbols\msgpc.pdb\E8FB7A9C282647C1B5AE021FDB52C34A1\msgpc.pdb
f761f000 f7628f00 termdd (pdb symbols)
c:\websymbols\termdd.pdb\9D17EEE8E3684F9CB51249CEE7D2AC961\termdd.pdb
f762f000 f763d100 usbhub (pdb symbols)
c:\websymbols\usbhub.pdb\A3CE86B8CE4941CC890AD17D38D0EF4D1\usbhub.pdb
f763f000 f7648480 NDProxy (pdb symbols)
\VEGAS\SYMBOLS\SYS\ndproxy.pdb
f765f000 f7667700 netbios (pdb symbols)
c:\websymbols\netbios.pdb\EC7846CAA4AC4B6B9D995E397AAE8AA91\netbios.pdb
f768f000 f7697880 Fips (pdb symbols)
\VEGAS\SYMBOLS\SYS\fips.pdb
f769f000 f76a7d80 HIDCLASS (pdb symbols)
c:\websymbols\hidclass.pdb\216F6902ECF84F0A9A75DB2AB532241F1\hidclass.pdb
f76af000 f76b7700 wanarp (pdb symbols)
c:\websymbols\wanarp.pdb\FDB397B5509448699BDFDF4E2214A5D61\wanarp.pdb
f772f000 f7735200 PCIIDEX (pdb symbols)
c:\websymbols\pciidex.pdb\671C7864E7F74A9D8D84385D1A6347411\pciidex.pdb
f7737000 f773b900 PartMgr (pdb symbols)
\VEGAS\SYMBOLS\sys\partmgr.pdb
f774f000 f7754500 TDTCP (pdb symbols)
c:\websymbols\tdtcp.pdb\4763EF6A55424832BBFAC9A2EFA20FCE1\tdtcp.pdb
f776f000 f7773580 hcmon (no symbols)
f7827000 f782db00 fdc (pdb symbols)
c:\websymbols\fdc.pdb\1CF3D63A7C51425AB85A1382FA965FF01\fdc.pdb
f782f000 f7835000 kbdclass (pdb symbols)
c:\websymbols\kbdclass.pdb\8207E908221F480B8DF0B101EF62AFB41\kbdclass.pdb
f7837000 f783e000 GEARAspiWDM (no symbols)
f783f000 f7844000 usbuhci (pdb symbols)
c:\websymbols\usbuhci.pdb\401251DB5CEF4774B90FF7054880FCBC1\usbuhci.pdb
f7847000 f784b880 TDI (pdb symbols)
c:\websymbols\tdi.pdb\5C695BF68B924AE9BA5283BD91AA12511\tdi.pdb
f784f000 f7853580 ptilink (pdb symbols)
\VEGAS\SYMBOLS\sys\ptilink.pdb
f7857000 f785b080 raspti (pdb symbols)
\VEGAS\SYMBOLS\sys\raspti.pdb
f785f000 f7864a00 mouclass (pdb symbols)
c:\websymbols\mouclass.pdb\5AD51F05354A4C5FA0358FC0B60E0B371\mouclass.pdb
f7877000 f787c0c0 vmnetbridge (no symbols)
f787f000 f7884000 flpydisk (pdb symbols)
c:\websymbols\flpydisk.pdb\E1FDA85E9A4B409C84485F51EA17A3421\flpydisk.pdb
f788f000 f7894200 vga (pdb symbols)
c:\websymbols\vga.pdb\64C796A95260466CA898ED2D0540BB1A1\vga.pdb
f7897000 f789ba80 Msfs (pdb symbols)
c:\websymbols\msfs.pdb\5FE94FBDD41B47EE90F09157273AF7A31\msfs.pdb
f789f000 f78a6880 Npfs (pdb symbols)
c:\websymbols\npfs.pdb\BC1F3D9A55D04CD087AA5C5E30A75D8D1\npfs.pdb
f78a7000 f78adb00 StyleXPHelper (no symbols)
f78b7000 f78bd180 HIDPARSE (pdb symbols)
c:\websymbols\hidparse.pdb\A7AED9BB82EF4AACBEDD15DAA32D69781\hidparse.pdb
f78bf000 f78c2000 BOOTVID (pdb symbols)
\VEGAS\SYMBOLS\dll\bootvid.pdb
f795b000 f795d280 rasacd (pdb symbols)
\VEGAS\SYMBOLS\sys\rasacd.pdb
f797b000 f797d580 hidusb (pdb symbols)
\VEGAS\SYMBOLS\sys\hidusb.pdb
f797f000 f7981f80 mouhid (pdb symbols)
\VEGAS\SYMBOLS\sys\mouhid.pdb
f7993000 f7995980 gameenum (pdb symbols)
c:\websymbols\GameEnum.pdb\3F9CE8C99C29484494A0E64BF88B6E2D1\GameEnum.pdb
f7997000 f799ac80 serenum (pdb symbols)
c:\websymbols\SerEnum.pdb\65C854188D1C4126B9DEA70BBAC9C42D1\SerEnum.pdb
f799f000 f79a1580 ndistapi (pdb symbols)
\VEGAS\SYMBOLS\sys\ndistapi.pdb
f79af000 f79b0b80 kdcom (pdb symbols)
\VEGAS\SYMBOLS\dll\kdcom.pdb
f79b1000 f79b2100 WMILIB (pdb symbols)
\VEGAS\SYMBOLS\SYS\wmilib.pdb
f79b3000 f79b4580 intelide (pdb symbols)
c:\websymbols\intelide.pdb\E9E510BE387D4D5A8A3CD81376DE50071\intelide.pdb
f79b5000 f79b6700 dmload (pdb symbols)
\VEGAS\SYMBOLS\sys\dmload.pdb
f79cf000 f79d0a80 ParVdm (pdb symbols)
\VEGAS\SYMBOLS\SYS\parvdm.pdb
f79d1000 f79d2b20 VMparport (no symbols)
f79ed000 f79eeb00 ctlfacem (pdb symbols)
\VEGAS\SYMBOLS\sys\CTLFACEM.pdb
f79ef000 f79f0100 swenum (pdb symbols)
c:\websymbols\swenum.pdb\D98CEE57A7E6460ABFEADB94BEDB11561\swenum.pdb
f79f1000 f79f2f80 vmnetadapter (no symbols)
f79f3000 f79f4280 USBD (pdb symbols)
\VEGAS\SYMBOLS\SYS\usbd.pdb
f79fb000 f79fcf00 Fs_Rec (pdb symbols)
\VEGAS\SYMBOLS\SYS\fs_rec.pdb
f79fd000 f79fe080 Beep (pdb symbols)
\VEGAS\SYMBOLS\SYS\beep.pdb
f79ff000 f7a00080 mnmdd (pdb symbols)
\VEGAS\SYMBOLS\SYS\mnmdd.pdb
f7a01000 f7a02080 RDPCDD (pdb symbols)
\VEGAS\SYMBOLS\sys\RDPCDD.pdb
f7a2f000 f7a30100 dump_WMILIB (pdb symbols)
\VEGAS\SYMBOLS\SYS\wmilib.pdb
f7a8e000 f7a8eb80 Null (pdb symbols)
\VEGAS\SYMBOLS\SYS\null.pdb
f7b9b000 f7b9be80 ctljystk (pdb symbols)
\VEGAS\SYMBOLS\sys\ctljystk.pdb
f7b9c000 f7b9cc00 audstub (pdb symbols)
\VEGAS\SYMBOLS\sys\audstub.pdb

Unloaded modules:
f7b13000 f7b14000 drmkaud.sys
f25e4000 f260e000 kmixer.sys
f26d6000 f26f9000 aec.sys
f28fe000 f290b000 DMusic.sys
f2bb1000 f2bbf000 swmidi.sys
f79eb000 f79ed000 splitter.sys
f2b06000 f2b3e000 xxxxxxx
f767f000 f768a000 imapi.sys
f766f000 f7678000 processr.sys
f7887000 f788c000 Cdaudio.SYS
f7957000 f795a000 Sfloppy.SYS


Marco [www.neovalens.com]