*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1E, {ffffffffc0000005, fffff80002f68808, 0, ffffffffffffffff}
Probably caused by : memory_corruption ( nt!MiUnlinkPageFromBadList+38 )
KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff80002f68808, The address that the exception occurred at
Arg3: 0000000000000000, Parameter 0 of the exception
Arg4: ffffffffffffffff, Parameter 1 of the exception
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!MiUnlinkPageFromBadList+38
fffff800`02f68808 488914c1 mov qword ptr [rcx+rax*8],rdx
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: ffffffffffffffff
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800030f20e0
ffffffffffffffff
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x1E
PROCESS_NAME: WerFault.exe
CURRENT_IRQL: 2
EXCEPTION_RECORD: fffff88006d53658 -- (.exr 0xfffff88006d53658)
ExceptionAddress: fffff80002f68808 (nt!MiUnlinkPageFromBadList+0x0000000000000038)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
TRAP_FRAME: fffff88006d53700 -- (.trap 0xfffff88006d53700)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffffdf0000b5bb40 rbx=0000000000000000 rcx=fffffa8000000008
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002f68808 rsp=fffff88006d53890 rbp=fffffa80001e61e0
r8=fffff88006d538b0 r9=fffff800030f25b0 r10=0000000fffffffff
r11=fffffa80001e49e0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na pe cy
nt!MiUnlinkPageFromBadList+0x38:
fffff800`02f68808 488914c1 mov qword ptr [rcx+rax*8],rdx ds:f1c0:fffef280`05adda08=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002ef4ab9 to fffff80002eba700
STACK_TEXT:
fffff880`06d52e88 fffff800`02ef4ab9 : 00000000`0000001e ffffffff`c0000005 fffff800`02f68808 00000000`00000000 : nt!KeBugCheckEx
fffff880`06d52e90 fffff800`02eb9d42 : fffff880`06d53658 fffffa80`001e61e0 fffff880`06d53700 fffffa80`00279d50 : nt!KiDispatchException+0x1b9
fffff880`06d53520 fffff800`02eb864a : fffff880`06d53878 fffff880`01258c74 fffffa80`082cae40 fffffa80`00000001 : nt!KiExceptionDispatch+0xc2
fffff880`06d53700 fffff800`02f68808 : fffff8a0`00d4a010 fffffa80`00279d50 fffff800`03032c80 fffff880`06d538b8 : nt!KiGeneralProtectionFault+0x10a
fffff880`06d53890 fffff800`02edb6ed : fffff880`06d539d0 00000000`00000000 fffffa80`079a7de0 fffffa80`075fd010 : nt!MiUnlinkPageFromBadList+0x38
fffff880`06d538e0 fffff800`02ed6b8c : fffffa80`079a7de0 fffffa80`00000000 fffff8a0`079a7de0 fffffa80`001909b0 : nt!MiUnlinkPageFromLockedList+0xbd
fffff880`06d53970 fffff800`02ed4743 : ffffffff`ffffff00 00000000`007e0000 00000000`00000000 fffff800`00000000 : nt!MiDispatchFault+0x7ac
fffff880`06d53a80 fffff800`02eb87ee : 00000000`00000000 00000000`00000000 00000000`00000101 00000000`00000001 : nt!MmAccessFault+0x343
fffff880`06d53be0 000007fe`f06f859f : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x16e
00000000`000cb330 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7fe`f06f859f
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!MiUnlinkPageFromBadList+38
fffff800`02f68808 488914c1 mov qword ptr [rcx+rax*8],rdx
SYMBOL_STACK_INDEX: 4
SYMBOL_NAME: nt!MiUnlinkPageFromBadList+38
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 4d9fdd34
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: X64_0x1E_nt!MiUnlinkPageFromBadList+38
BUCKET_ID: X64_0x1E_nt!MiUnlinkPageFromBadList+38
Followup: MachineOwner
---------