Windows 7 Kernel Version 7601 (Service Pack 1) MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0xfffff800`02a04000 PsLoadedModuleList = 0xfffff800`02c49e90
Debug session time: Mon Feb 21 03:14:58.390 2011 (UTC + 0:00)
System Uptime: 0 days 0:03:05.671
Loading Kernel Symbols
...............................................................
................................................................
................................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck C4, {f6, 264, fffffa8005d835b0, fffff88004030109}
Unable to load image \??\C:\Program Files (x86)\Emsisoft Anti-Malware\a2util64.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for a2util64.sys
*** ERROR: Module load completed but symbols could not be loaded for a2util64.sys
Probably caused by : a2util64.sys ( a2util64+1109 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
A device driver attempting to corrupt the system has been caught. This is
because the driver was specified in the registry as being suspect (by the
administrator) and the kernel has enabled substantial checking of this driver.
If the driver attempts to corrupt the system, bugchecks 0xC4, 0xC1 and 0xA will
be among the most commonly seen crashes.
Arguments:
Arg1: 00000000000000f6, Referencing user handle as KernelMode.
Arg2: 0000000000000264, Handle value being referenced.
Arg3: fffffa8005d835b0, Address of the current process.
Arg4: fffff88004030109, Address inside the driver that is performing the incorrect reference.
Debugging Details:
------------------
BUGCHECK_STR: 0xc4_f6
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VERIFIER_ENABLED_VISTA_MINIDUMP
PROCESS_NAME: taskhost.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff80002f0b3dc to fffff80002a84640
STACK_TEXT:
fffff880`0714e618 fffff800`02f0b3dc : 00000000`000000c4 00000000`000000f6 00000000`00000264 fffffa80`05d835b0 : nt!KeBugCheckEx
fffff880`0714e620 fffff800`02f20ae4 : 00000000`00000264 fffffa80`05d835b0 00000000`00000002 00000000`00000000 : nt!VerifierBugCheckIfAppropriate+0x3c
fffff880`0714e660 fffff800`02cda0c0 : 00000000`00000000 fffff880`0714e890 00000000`00000000 fffff880`0714e900 : nt!VfCheckUserHandle+0x1b4
fffff880`0714e740 fffff800`02d5e905 : fffff800`02d9ef00 00000000`00000000 00000000`00000000 fffff800`02d5e800 : nt! ?? ::NNGAKEGL::`string'+0x2173e
fffff880`0714e810 fffff800`02f20878 : fffffa80`00000001 fffffa80`066740d8 fffff800`02d9ef97 fffff800`02d9ef97 : nt!ObReferenceObjectByHandle+0x25
fffff880`0714e860 fffff880`04030109 : 00000000`00000010 00000000`00000000 fffff880`0714e9b0 fffff800`02d9ef97 : nt!VerifierObReferenceObjectByHandle+0x48
fffff880`0714e8b0 00000000`00000010 : 00000000`00000000 fffff880`0714e9b0 fffff800`02d9ef97 fffff880`0714e8e8 : a2util64+0x1109
fffff880`0714e8b8 00000000`00000000 : fffff880`0714e9b0 fffff800`02d9ef97 fffff880`0714e8e8 00000000`00000000 : 0x10
STACK_COMMAND: kb
FOLLOWUP_IP:
a2util64+1109
fffff880`04030109 413bc7 cmp eax,r15d
SYMBOL_STACK_INDEX: 6
SYMBOL_NAME: a2util64+1109
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: a2util64
IMAGE_NAME: a2util64.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4ad84a4d
FAILURE_BUCKET_ID: X64_0xc4_f6_VRF_a2util64+1109
BUCKET_ID: X64_0xc4_f6