Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\K\Desktop\121909-22921-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*d:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
[B]Built by: 7600.16385.amd64fre.win7_rtm.090713-1255[/B]
Machine Name:
Kernel base = 0xfffff800`02c4d000 PsLoadedModuleList = 0xfffff800`02e8ae50
Debug session time: Sat Dec 19 09:29:18.642 2009 (GMT-5)
System Uptime: 0 days 0:51:22.236
Loading Kernel Symbols
...............................................................
................................................................
..................
Loading User Symbols
Loading unloaded module list
.......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
[U][I][B]BugCheck 50, {fffff8a0120099cc, 1, fffff88000d07046, 2}
Could not read faulting driver name
Probably caused by : memory_corruption
Followup: memory_corruption[/B][/I][/U]
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
[B]PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: fffff8a0120099cc, memory referenced.
Arg2: 0000000000000001, value 0 = read operation, 1 = write operation.
Arg3: fffff88000d07046, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000002, (reserved)
[/B]
Debugging Details:
------------------
Could not read faulting driver name
WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff80002ef50e0
fffff8a0120099cc
FAULTING_IP:
CI!MFKeyIsTrustedRootKey+da8a
fffff880`00d07046 46890409 mov dword ptr [rcx+r9],r8d
MM_INTERNAL_CODE: 2
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: CODE_CORRUPTION
BUGCHECK_STR: 0x50
[B]
PROCESS_NAME: audiodg.exe
[/B]
CURRENT_IRQL: 0
TRAP_FRAME: fffff880085ea3f0 -- (.trap 0xfffff880085ea3f0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=000000003c4c64af rbx=0000000000000000 rcx=000000001200000c
rdx=0000000073e30179 rsi=0000000000000000 rdi=0000000000000000
rip=fffff88000d07046 rsp=fffff880085ea580 rbp=fffff880085ea790
r8=00000000363b5779 r9=fffff8a0000099c0 r10=00000000ab799e43
r11=fffff880085ea648 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na po nc
CI!MFKeyIsTrustedRootKey+0xda8a:
fffff880`00d07046 46890409 mov dword ptr [rcx+r9],r8d ds:0020:fffff8a0`120099cc=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002d3cbc2 to fffff80002cbef00
STACK_TEXT:
fffff880`085ea288 fffff800`02d3cbc2 : 00000000`00000050 fffff8a0`120099cc 00000000`00000001 fffff880`085ea3f0 : nt!KeBugCheckEx
fffff880`085ea290 fffff800`02cbcfee : 00000000`00000001 00000000`781f802a fffff880`01a00000 fffff880`01dffff8 : nt! ?? ::FNODOBFM::`string'+0x40f90
fffff880`085ea3f0 fffff880`00d07046 : 3c4c64af`781f802a fffff880`ab799e43 fffff880`085ea648 00000000`73e30179 : nt!KiPageFault+0x16e
fffff880`085ea580 fffff880`00d37418 : fffff880`085ea790 fffff880`085ea780 00000000`ca5697b4 f89a35d5`0ed57f24 : CI!MFKeyIsTrustedRootKey+0xda8a
fffff880`085ea620 fffff880`00d375a3 : 00000000`0003028f 00000000`00000005 00000000`00000000 00000000`00000002 : CI!MFKeyIsTrustedRootKey+0x3de5c
fffff880`085ea980 fffff880`00ce4526 : c11b999c`187b4d0e 00000000`0003028f 00000000`00000001 00000000`00000000 : CI!peauthvbn_StoreParameter+0x3f
fffff880`085ea9d0 fffff880`00cf883f : fffff880`00d4b998 00000000`00000000 fffff880`00d49970 fffff8a0`000a8630 : CI!PEAuthStoreParameter+0x5a
fffff880`085eaa00 fffff880`00cf8bbc : 00000000`00000c30 00000000`00000001 fffff8a0`00281d10 fffffa80`0464d720 : CI!I_PEUpdatePEHashBucket+0x1f7
fffff880`085eaa40 fffff800`02f7aaca : fffff8a0`00294930 fffffa80`061ec160 fffffa80`061ec160 fffffa80`05b7db80 : CI!I_PEProcessNotify+0x28
fffff880`085eaa70 fffff800`02fa16eb : 000007ff`fffde000 00000000`00000001 00000000`00000000 fffffa80`05928540 : nt!PspExitProcess+0x156
fffff880`085eaad0 fffff800`02f7acb8 : 00000000`c000004b 00000000`00000001 000007ff`fffde000 00000000`00000000 : nt!PspExitThread+0x3bb
fffff880`085eaba0 fffff800`02cbe153 : fffffa80`061ec160 fffff880`c000004b fffffa80`0464d720 00000000`00000000 : nt!NtTerminateProcess+0x138
fffff880`085eac20 00000000`771d017a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0023f1e8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x771d017a
STACK_COMMAND: kb
CHKIMG_EXTENSION: !chkimg -lo 50 -d !CI
fffff88000d07045 - CI!MFKeyIsTrustedRootKey+da89
[ 00:12 ]
1 error : !CI (fffff88000d07045)
MODULE_NAME: memory_corruption
IMAGE_NAME: memory_corruption
FOLLOWUP_NAME: memory_corruption
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MEMORY_CORRUPTOR: ONE_BYTE
FAILURE_BUCKET_ID: X64_MEMORY_CORRUPTION_ONE_BYTE
BUCKET_ID: X64_MEMORY_CORRUPTION_ONE_BYTE
Followup: memory_corruption
---------