*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {fffffac00cfe1f88, 0, fffff80002aabc11, 5}
Could not read faulting driver name
Probably caused by : memory_corruption ( nt!MiGetNextNode+25 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: fffffac00cfe1f88, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff80002aabc11, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000005, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002cb3100
GetUlongFromAddress: unable to read from fffff80002cb31c0
fffffac00cfe1f88 Nonpaged pool
FAULTING_IP:
nt!MiGetNextNode+25
fffff800`02aabc11 488b4808 mov rcx,qword ptr [rax+8]
MM_INTERNAL_CODE: 5
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: explorer.exe
CURRENT_IRQL: 0
ANALYSIS_VERSION: 6.3.9600.16384 (debuggers(dbg).130821-1623) amd64fre
TRAP_FRAME: fffff88007e8b3a0 -- (.trap 0xfffff88007e8b3a0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffffac00cfe1f80 rbx=0000000000000000 rcx=fffffa800d009840
rdx=000000000000040e rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002aabc11 rsp=fffff88007e8b538 rbp=0000000000000001
r8=000000000000040e r9=00000000000007ff r10=0000000000000801
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na pe nc
nt!MiGetNextNode+0x25:
fffff800`02aabc11 488b4808 mov rcx,qword ptr [rax+8] ds:fffffac0`0cfe1f88=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002af60a2 to fffff80002a79540
STACK_TEXT:
fffff880`07e8b238 fffff800`02af60a2 : 00000000`00000050 fffffac0`0cfe1f88 00000000`00000000 fffff880`07e8b3a0 : nt!KeBugCheckEx
fffff880`07e8b240 fffff800`02a7766e : 00000000`00000000 fffffac0`0cfe1f88 00000000`00000000 fffffa80`0d31bb50 : nt! ?? ::FNODOBFM::`string'+0x43311
fffff880`07e8b3a0 fffff800`02aabc11 : fffff800`02e16850 00000000`00000000 fffffa80`0d31bb50 00000000`00000080 : nt!KiPageFault+0x16e
fffff880`07e8b538 fffff800`02e16850 : 00000000`00000000 fffffa80`0d31bb50 00000000`00000080 00000000`00000001 : nt!MiGetNextNode+0x25
fffff880`07e8b540 fffff800`02cd6248 : fffffa80`0d000b30 fffff880`07e8b640 00000000`00000000 00000000`000000d0 : nt!MmEnumerateAndReferenceImages+0x160
fffff880`07e8b5c0 fffff800`02d33c2a : fffffa80`0d000b30 00000000`00000000 fffffa80`0d31bb50 00000000`00000001 : nt! ?? ::NNGAKEGL::`string'+0x1fc89
fffff880`07e8b760 fffff800`02d50c48 : 000007ff`fffa6000 fffff880`07e8bae0 00000000`00000000 fffffa80`0bd92090 : nt!PspExitProcess+0x52
fffff880`07e8b7c0 fffff800`02d3618d : 00000000`c000041d 00000000`00000001 000007ff`fffa6000 00000000`00000000 : nt!PspExitThread+0x848
fffff880`07e8b880 fffff800`02a6c07a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000b1c : nt!PsExitSpecialApc+0x1d
fffff880`07e8b8b0 fffff800`02a6c3c0 : 00000000`00000000 fffff880`07e8b930 fffff800`02d36100 00000000`00000001 : nt!KiDeliverApc+0x2ca
fffff880`07e8b930 fffff800`02a78877 : fffffa80`0d31bb50 00000000`040ee4f8 00000000`00000002 00000000`040ee570 : nt!KiInitiateUserApc+0x70
fffff880`07e8ba70 00000000`771a108a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExit+0x9c
00000000`040ed938 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x771a108a
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!MiGetNextNode+25
fffff800`02aabc11 488b4808 mov rcx,qword ptr [rax+8]
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: nt!MiGetNextNode+25
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 521ea08b
IMAGE_VERSION: 6.1.7601.22436
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: X64_0x50_nt!MiGetNextNode+25
BUCKET_ID: X64_0x50_nt!MiGetNextNode+25
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:x64_0x50_nt!migetnextnode+25
FAILURE_ID_HASH: {1aa95eee-b9de-4282-d3e5-42458123670a}
Followup: MachineOwner
---------