Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [D:\Kingston\BSODDmpFiles\kharistos\Windows_NT6_BSOD_jcgriff2\032212-48141-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16917.amd64fre.win7_gdr.111118-2330
Machine Name:
Kernel base = 0xfffff800`02a1a000 PsLoadedModuleList = 0xfffff800`02c56e70
Debug session time: Wed Mar 21 21:29:09.506 2012 (UTC - 6:00)
System Uptime: 0 days 0:00:07.926
Loading Kernel Symbols
...............................................................
.................
Loading User Symbols
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {fffff6fe50002b30, 0, fffff80002a9be88, 5}
Could not read faulting driver name
Probably caused by : CI.dll ( CI!SHATransform+236 )
Followup: MachineOwner
---------
3: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: fffff6fe50002b30, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff80002a9be88, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000005, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002cc10e0
fffff6fe50002b30
FAULTING_IP:
nt!MiLockProtoPoolPage+38
fffff800`02a9be88 4a8b3c36 mov rdi,qword ptr [rsi+r14]
MM_INTERNAL_CODE: 5
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: System
CURRENT_IRQL: 0
TRAP_FRAME: fffff8800319fa00 -- (.trap 0xfffff8800319fa00)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=00000000c51c1a7e rbx=0000000000000000 rcx=0000000081002702
rdx=000000002b375eb2 rsi=0000000000000000 rdi=0000000000000000
rip=fffff88000cdacd6 rsp=fffff8800319fb90 rbp=0000000000418bcd
r8=00000000c221f9e4 r9=000000009140672b r10=00000000f6e8e0d3
r11=000000006fc9d785 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na po cy
CI!SHATransform+0x236:
fffff880`00cdacd6 8b7334 mov esi,dword ptr [rbx+34h] ds:00000000`00000034=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002b08ed1 to fffff80002a8a540
STACK_TEXT:
fffff880`0319f448 fffff800`02b08ed1 : 00000000`00000050 fffff6fe`50002b30 00000000`00000000 fffff880`0319f5b0 : nt!KeBugCheckEx
fffff880`0319f450 fffff800`02a8862e : 00000000`00000000 fffff980`02cfb000 fffffa80`07d8b000 fffff800`02af8eac : nt! ?? ::FNODOBFM::`string'+0x408fb
fffff880`0319f5b0 fffff800`02a9be88 : 00000000`00000000 fffff800`02c15e00 fffff800`02c15e00 fffff6fc`c00167d0 : nt!KiPageFault+0x16e
fffff880`0319f740 fffff800`02aa6927 : 00000000`00000000 fffff980`02cfa000 fffff6fc`c00167d0 fffff800`02c15e00 : nt!MiLockProtoPoolPage+0x38
fffff880`0319f790 fffff800`02aa4941 : 00000000`00000000 00000000`00000000 ffffffff`ffffffff 00000000`00000000 : nt!MiDispatchFault+0x8f7
fffff880`0319f8a0 fffff800`02a8862e : 00000000`00000000 fffff980`02cfafcc 00000000`656e7100 00000000`6a0fba0d : nt!MmAccessFault+0x8f1
fffff880`0319fa00 fffff880`00cdacd6 : e8000000`00003394 0033ca8b`7ea20696 24c40000`00898c24 719086c3`6f979c57 : nt!KiPageFault+0x16e
fffff880`0319fb90 fffff880`00cdbd0c : fffff880`0319fd88 fffffa80`1e279074 fffff980`79ba8fe7 fffff800`b017e31e : CI!SHATransform+0x236
fffff880`0319fc20 fffff880`00c98824 : fffff8a0`001460c0 fffff980`02c00110 00000000`00000000 00000000`00000000 : CI!A_SHAUpdate+0xcc
fffff880`0319fc60 fffff880`00c90b38 : fffff980`02c001b8 00000000`00000000 00000000`00000600 0000000d`00001000 : CI!HashpHashBytes+0x40
fffff880`0319fc90 fffff880`00c90281 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : CI!CipImageGetImageHash+0x310
fffff880`0319fe70 fffff880`00c8efbb : 00000000`00000001 fffff880`031a0130 fffff880`031a0130 00000000`00000000 : CI!CipValidateFileHash+0x211
fffff880`0319ffe0 fffff800`02cf0b78 : 00000000`00000abe 00000000`000fffff fffffa80`07d70700 00000000`00000000 : CI!CiValidateImageHeader+0x213
fffff880`031a00c0 fffff800`02cf097a : 00000000`00000000 00000000`01000000 fffffa80`07d8b010 00000000`00000000 : nt!SeValidateImageHeader+0x58
fffff880`031a0100 fffff800`02d815e5 : fffffa80`07d70700 fffffa80`07d8b010 00000000`00000001 00000000`00000abe : nt!MiValidateImageHeader+0x21a
fffff880`031a01d0 fffff800`02d767e3 : fffff880`031a0430 00000000`00000000 fffff880`031a06e8 00000000`00000001 : nt!MmCreateSection+0x8c9
fffff880`031a03e0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!NtCreateSection+0x162
STACK_COMMAND: kb
FOLLOWUP_IP:
CI!SHATransform+236
fffff880`00cdacd6 8b7334 mov esi,dword ptr [rbx+34h]
SYMBOL_STACK_INDEX: 7
SYMBOL_NAME: CI!SHATransform+236
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: CI
IMAGE_NAME: CI.dll
DEBUG_FLR_IMAGE_TIMESTAMP: 4a5be01d
FAILURE_BUCKET_ID: X64_0x50_CI!SHATransform+236
BUCKET_ID: X64_0x50_CI!SHATransform+236
Followup: MachineOwner
---------