[list=1]
[*]
Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [D:\Kingston\BSODDmpFiles\soulnotsoldier4\Windows_NT6_BSOD_jcgriff2\030612-25116-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (6 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`03265000 PsLoadedModuleList = 0xfffff800`034aa670
Debug session time: Tue Mar 6 11:10:44.576 2012 (UTC - 7:00)
System Uptime: 0 days 18:54:57.418
Loading Kernel Symbols
...............................................................
................................................................
.............................
Loading User Symbols
Loading unloaded module list
........
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck C1, {fffff980267e6ff0, fffff980267e6ffc, 87000c, 24}
Unable to load image \??\C:\Windows\gdrv.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for gdrv.sys
*** ERROR: Module load completed but symbols could not be loaded for gdrv.sys
Probably caused by : gdrv.sys ( gdrv+30c7 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SPECIAL_POOL_DETECTED_MEMORY_CORRUPTION (c1)
Special pool has detected memory corruption. Typically the current thread's
stack backtrace will reveal the guilty party.
Arguments:
Arg1: fffff980267e6ff0, address trying to free
Arg2: fffff980267e6ffc, address where bits are corrupted
Arg3: 000000000087000c, (reserved)
Arg4: 0000000000000024, caller is freeing an address where bytes after the end of the allocation have been overwritten
Debugging Details:
------------------
BUGCHECK_STR: 0xC1_24
SPECIAL_POOL_CORRUPTION_TYPE: 24
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VERIFIER_ENABLED_VISTA_MINIDUMP
PROCESS_NAME: essvr.exe
CURRENT_IRQL: 1
IRP_ADDRESS: fffff98028e6ef3b
LAST_CONTROL_TRANSFER: from fffff800033e3b54 to fffff800032e1c40
STACK_TEXT:
fffff880`07eb2398 fffff800`033e3b54 : 00000000`000000c1 fffff980`267e6ff0 fffff980`267e6ffc 00000000`0087000c : nt!KeBugCheckEx
fffff880`07eb23a0 fffff800`0340f93b : fffff800`03265000 00000000`20206f49 00000000`015d6bdc fffffa80`106badb0 : nt!MmFreeSpecialPool+0x374
fffff880`07eb24e0 fffff800`032f709e : 00000000`00000000 fffff980`28e6efb0 fffff980`0356ece0 fffffa80`0f56e740 : nt!ExDeferredFreePool+0xf33
fffff880`07eb2590 fffff800`032e534a : fffff980`28e6efb3 00000000`00000001 00000000`00000001 fffff800`0339e803 : nt!IopCompleteRequest+0x5ce
fffff880`07eb2660 fffff800`0378119f : fffff980`28e6eee0 fffffa80`109bda00 fffff980`28e6ef00 00000000`00000000 : nt!IopfCompleteRequest+0x66a
fffff880`07eb2750 fffff880`081f80c7 : fffff880`081f8a50 00000000`00000008 00000000`00000000 fffff980`28e6efb0 : nt!IovCompleteRequest+0x19f
fffff880`07eb2820 fffff880`081f8a50 : 00000000`00000008 00000000`00000000 fffff980`28e6efb0 00000000`00000001 : gdrv+0x30c7
fffff880`07eb2828 00000000`00000008 : 00000000`00000000 fffff980`28e6efb0 00000000`00000001 00000000`00000000 : gdrv+0x3a50
fffff880`07eb2830 00000000`00000000 : fffff980`28e6efb0 00000000`00000001 00000000`00000000 00000000`00000001 : 0x8
STACK_COMMAND: kb
FOLLOWUP_IP:
gdrv+30c7
fffff880`081f80c7 ?? ???
SYMBOL_STACK_INDEX: 6
SYMBOL_NAME: gdrv+30c7
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: gdrv
IMAGE_NAME: gdrv.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 49b9d175
FAILURE_BUCKET_ID: X64_0xC1_24_VRF_gdrv+30c7
BUCKET_ID: X64_0xC1_24_VRF_gdrv+30c7
Followup: MachineOwner
---------
[*]
Loading Dump File [D:\Kingston\BSODDmpFiles\soulnotsoldier4\Windows_NT6_BSOD_jcgriff2\030512-21808-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (6 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`0324c000 PsLoadedModuleList = 0xfffff800`03491670
Debug session time: Mon Mar 5 16:14:48.655 2012 (UTC - 7:00)
System Uptime: 0 days 1:39:31.842
Loading Kernel Symbols
...............................................................
................................................................
..............................
Loading User Symbols
Loading unloaded module list
........
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck C9, {7, fffff88008402a10, fffff9801e162ee0, 0}
Unable to load image \??\C:\Program Files\PeerBlock\pbfilter.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for pbfilter.sys
*** ERROR: Module load completed but symbols could not be loaded for pbfilter.sys
Probably caused by : pbfilter.sys ( pbfilter+2a10 )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_VERIFIER_IOMANAGER_VIOLATION (c9)
The IO manager has caught a misbehaving driver.
Arguments:
Arg1: 0000000000000007, IRP passed to IoCompleteRequest still has cancel routine set
Arg2: fffff88008402a10, the cancel routine pointer
Arg3: fffff9801e162ee0, the IRP
Arg4: 0000000000000000
Debugging Details:
------------------
BUGCHECK_STR: 0xc9_7
DRIVER_VERIFIER_IO_VIOLATION_TYPE: 7
IRP_CANCEL_ROUTINE:
pbfilter+2a10
fffff880`08402a10 48895c2408 mov qword ptr [rsp+8],rbx
FAULTING_IP:
pbfilter+2a10
fffff880`08402a10 48895c2408 mov qword ptr [rsp+8],rbx
FOLLOWUP_IP:
pbfilter+2a10
fffff880`08402a10 48895c2408 mov qword ptr [rsp+8],rbx
IRP_ADDRESS: fffff9801e162ee0
DEVICE_OBJECT: fffffa800f663b60
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VERIFIER_ENABLED_VISTA_MINIDUMP
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 2
LAST_CONTROL_TRANSFER: from fffff80003768072 to fffff800032c8c40
STACK_TEXT:
fffff880`088d60e8 fffff800`03768072 : 00000000`000000c9 00000000`00000007 fffff880`08402a10 fffff980`1e162ee0 : nt!KeBugCheckEx
fffff880`088d60f0 fffff880`084029ea : 00000000`0000cde1 00000000`00000000 fffffa80`0f663cb0 fffff980`1e162ee0 : nt!IovCompleteRequest+0x72
fffff880`088d61c0 00000000`0000cde1 : 00000000`00000000 fffffa80`0f663cb0 fffff980`1e162ee0 00000000`00000011 : pbfilter+0x29ea
fffff880`088d61c8 00000000`00000000 : fffffa80`0f663cb0 fffff980`1e162ee0 00000000`00000011 00000000`faffffef : 0xcde1
STACK_COMMAND: .bugcheck ; kb
SYMBOL_NAME: pbfilter+2a10
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: pbfilter
IMAGE_NAME: pbfilter.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4cd60dba
FAILURE_BUCKET_ID: X64_0xc9_7_VRF_pbfilter+2a10
BUCKET_ID: X64_0xc9_7_VRF_pbfilter+2a10
Followup: MachineOwner
---------
[/list]