*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck C4, {d5, fffffa800f5fe470, fffff980017a0de0, 0}
*** WARNING: Unable to verify timestamp for gpt_loader.sys
*** ERROR: Module load completed but symbols could not be loaded for gpt_loader.sys
[COLOR=Red]Probably caused by : gpt_loader.sys[/COLOR] ( gpt_loader+97a5 )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
[COLOR=Red]DRIVER_VERIFIER_DETECTED_VIOLATION (c4)[/COLOR]
A device driver attempting to corrupt the system has been caught. This is
because the driver was specified in the registry as being suspect (by the
administrator) and the kernel has enabled substantial checking of this driver.
If the driver attempts to corrupt the system, bugchecks 0xC4, 0xC1 and 0xA will
be among the most commonly seen crashes.
Arguments:
Arg1: 00000000000000d5, IoReleaseRemoveLock tag doesn't match previous IoAcquireRemoveLock tag.
Arg2: fffffa800f5fe470, Address of the chk build Remove Lock structure.
Arg3: fffff980017a0de0, Tag that doesn't match previous IoAcquireRemoveLock tag.
If the driver calling IoReleaseRemoveLock is not built chk,
Parameter 2 is the chk build Remove Lock used by the Driver Verifier
on behalf of the driver. In this case, the address of the RemoveLock
used by the driver is not used at all, because the Driver Verifier is
replacing the lock address for all the Remove Lock APIs.
Arg4: 0000000000000000
Debugging Details:
------------------
BUGCHECK_STR: 0xc4_d5
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: [COLOR=Red]VERIFIER_ENABLED_VISTA_MINIDUMP[/COLOR]
PROCESS_NAME: System
CURRENT_IRQL: 0
ANALYSIS_VERSION: 6.3.9600.16384 (debuggers(dbg).130821-1623) amd64fre
LAST_CONTROL_TRANSFER: from fffff8000370c4ec to fffff8000327fbc0
STACK_TEXT:
fffff880`03099aa8 fffff800`0370c4ec : 00000000`000000c4 00000000`000000d5 fffffa80`0f5fe470 fffff980`017a0de0 : nt!KeBugCheckEx
fffff880`03099ab0 fffff800`0370defd : fffff980`017a0000 fffff980`017a0de0 00000000`00000001 0000000a`00002000 : nt!VerifierBugCheckIfAppropriate+0x3c
fffff880`03099af0 fffff800`03301cdf : fffffa80`0f5fe460 fffff800`0371bf33 fffff980`017a0de0 00000000`00000080 : nt!VfRemLockReportBadReleaseTag+0x1d
fffff880`03099b30 fffff880`014677a5 : 00000000`00000000 fffff980`017a0da0 fffff980`017a0da0 00000000`00000080 : nt! ?? ::FNODOBFM::`string'+0x4db8d
fffff880`03099ba0 00000000`00000000 : fffff980`017a0da0 fffff980`017a0da0 00000000`00000080 fffff880`01467750 : [COLOR=Red]gpt_loader[/COLOR]+0x97a5
STACK_COMMAND: kb
FOLLOWUP_IP:
gpt_loader+97a5
fffff880`014677a5 ?? ???
SYMBOL_STACK_INDEX: 4
[COLOR=Red]SYMBOL_NAME: gpt_loader+97a5[/COLOR]
FOLLOWUP_NAME: MachineOwner
[COLOR=Red]MODULE_NAME: gpt_loader
IMAGE_NAME: gpt_loader.sys[/COLOR]
DEBUG_FLR_IMAGE_TIMESTAMP: 4cf8f313
FAILURE_BUCKET_ID: X64_0xc4_d5_VRF_gpt_loader+97a5
BUCKET_ID: X64_0xc4_d5_VRF_gpt_loader+97a5
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:x64_0xc4_d5_vrf_gpt_loader+97a5
FAILURE_ID_HASH: {d16b33da-5646-7ca9-171b-36735b85d990}
Followup: MachineOwner
---------
2: kd> lmvm gpt_loader
start end module name
fffff880`0145e000 fffff880`01471000 gpt_loader T (no symbols)
Loaded symbol image file: gpt_loader.sys
Image path: \SystemRoot\system32\DRIVERS\gpt_loader.sys
[COLOR=Red] Image name: gpt_loader.sys
Timestamp: Fri Dec 03 19:09:31 2010[/COLOR] (4CF8F313)
CheckSum: 0001CABD
ImageSize: 00013000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4