I have the recent memory dump de-bugged as below if that could help you..
Microsoft ® Windows Debugger Version 6.11.0001.404 X86
Copyright © Microsoft Corporation. All rights reserved.
Loading Dump File [C:\WINDOWS\MEMORY.DMP]
Kernel Complete Dump File: Full address space is available
Symbol search path is: SRV*c:\windows\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows XP Kernel Version 2600 (Service Pack 3) UP Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 2600.xpsp_sp3_gdr.091208-2036
Machine Name:
Kernel base = 0x804d7000 PsLoadedModuleList = 0x80554040
Debug session time: Wed Feb 17 03:51:11.343 2010 (GMT+5)
System Uptime: 0 days 8:20:29.927
Loading Kernel Symbols
.......................................
........................
.......................................
.........................
.......................
Loading User Symbols
Loading unloaded module list
.....................
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 7E, {c0000005, b13e8d2f, b84efc4c, b84ef948}
Probably caused by : afd.sys ( afd!AfdFreeNPConnectionResources+48 )
Followup: MachineOwner
---------
kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_THREAD_EXCEPTION_NOT_HANDLED (7e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: c0000005, The exception code that was not handled
Arg2: b13e8d2f, The address that the exception occurred at
Arg3: b84efc4c, Exception Record Address
Arg4: b84ef948, Context Record Address
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s".
FAULTING_IP:
afd!AfdFreeNPConnectionResources+48
b13e8d2f 897904 mov dword ptr [ecx+4],edi
EXCEPTION_RECORD: b84efc4c -- (.exr 0xffffffffb84efc4c)
ExceptionAddress: b13e8d2f (afd!AfdFreeNPConnectionResources+0x00000048)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 00000001
Parameter[1]: 00000004
Attempt to write to address 00000004
CONTEXT: b84ef948 -- (.cxr 0xffffffffb84ef948)
eax=88ec3008 ebx=00000000 ecx=00000000 edx=4a320033 esi=88d72820 edi=88d72850
eip=b13e8d2f esp=b84efd14 ebp=b84efd1c iopl=0 nv up ei pl nz na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010206
afd!AfdFreeNPConnectionResources+0x48:
b13e8d2f 897904 mov dword ptr [ecx+4],edi ds:0023:00000004=?
?
Resetting default scope
PROCESS_NAME: System
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s".
EXCEPTION_PARAMETER1: 00000001
EXCEPTION_PARAMETER2: 00000004
WRITE_ADDRESS: 00000004
FOLLOWUP_IP:
afd!AfdFreeNPConnectionResources+48
b13e8d2f 897904 mov dword ptr [ecx+4],edi
BUGCHECK_STR: 0x7E
DEFAULT_BUCKET_ID: NULL_CLASS_PTR_DEREFERENCE
LAST_CONTROL_TRANSFER: from b13dbc18 to b13e8d2f
STACK_TEXT:
b84efd1c b13dbc18 88d72820 88d72898 88d72820 afd!AfdFreeNPConnectionResources+0x48
b84efd34 b13dbbbc 88d72820 b13da7a8 b84efd60 afd!AfdFreeConnectionResources+0x41
b84efd44 b13d886a 88d72898 8a2e9850 89ce8848 afd!AfdFreeConnection+0x5c
b84efd60 8056bd45 89ce8848 00000000 8055b17c afd!AfdDoWork+0x51
b84efd74 80534c1a 8a2e9850 00000000 8a4c4b30 nt!IopProcessWorkItem+0x13
b84efdac 805c61ee 8a2e9850 00000000 00000000 nt!ExpWorkerThread+0x100
b84efddc 80541e02 80534b1a 00000001 00000000 nt!PspSystemThreadStartup+0x34
00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x16
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: afd!AfdFreeNPConnectionResources+48
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: afd
IMAGE_NAME: afd.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 48a40333
STACK_COMMAND: .cxr 0xffffffffb84ef948 ; kb
FAILURE_BUCKET_ID: 0x7E_afd!AfdFreeNPConnectionResources+48
BUCKET_ID: 0x7E_afd!AfdFreeNPConnectionResources+48
Followup: MachineOwner