*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff80002b64668, The address that the exception occurred at
Arg3: 0000000000000000, Parameter 0 of the exception
Arg4: ffffffffffffffff, Parameter 1 of the exception
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) [COLOR=Red][B]0xc0000005[/B][/COLOR] - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s".
FAULTING_IP:
nt!MiRelocateImageAgain+48
fffff800`02b64668 f0480fba2e00 lock bts qword ptr [rsi],0
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: ffffffffffffffff
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002ab50e0
ffffffffffffffff
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x1E
PROCESS_NAME: [COLOR=Red][B]svchost.exe[/B][/COLOR]
CURRENT_IRQL: 0
EXCEPTION_RECORD: fffff8800892b108 -- (.exr 0xfffff8800892b108)
ExceptionAddress: fffff80002b64668 (nt!MiRelocateImageAgain+0x0000000000000048)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
TRAP_FRAME: fffff8800892b1b0 -- (.trap 0xfffff8800892b1b0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffffa800459cbb0 rbx=0000000000000000 rcx=fffffa8003cc6d30
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002b64668 rsp=fffff8800892b340 rbp=0000000001000000
r8=fffffa800459cbb0 r9=fffff8800892b178 r10=fffffa800462ef40
r11=fffff8800892b360 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na po nc
nt!MiRelocateImageAgain+0x48:
fffff800`02b64668 f0480fba2e00 lock bts qword ptr [rsi],0 ds:00000000`00000000=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff800028b7a39 to fffff8000287d740
STACK_TEXT:
fffff880`0892a938 fffff800`028b7a39 : 00000000`0000001e ffffffff`c0000005 fffff800`02b64668 00000000`00000000 : nt!KeBugCheckEx
fffff880`0892a940 fffff800`0287cd82 : fffff880`0892b108 ffffffff`ffffffff fffff880`0892b1b0 18dfc24d`dabebd85 : nt!KiDispatchException+0x1b9
fffff880`0892afd0 fffff800`0287b68a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiExceptionDispatch+0xc2
fffff880`0892b1b0 fffff800`02b64668 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiGeneralProtectionFault+0x10a
fffff880`0892b340 fffff800`02b787ce : 00000000`00000004 00000000`01000000 00000000`00000000 00000000`00000000 : nt!MiRelocateImageAgain+0x48
fffff880`0892b390 fffff800`02b6e013 : fffff880`0892b5f0 00000000`00000000 fffff880`0892b698 fffff880`0892b5e8 : nt!MmCreateSection+0x302
fffff880`0892b5a0 fffff800`02cdaa23 : 00000000`00000000 fffff8a0`0c345690 00000000`00000000 00000000`00000001 : nt!NtCreateSection+0x162
fffff880`0892b620 fffff800`02cdafb1 : 00000000`00000000 fffff8a0`0c345690 fffffa80`0505e920 fffff880`00000060 : nt!PfpFileBuildReadSupport+0x163
fffff880`0892b710 fffff800`02ce30ce : fffff8a0`00000000 fffff8a0`00000038 fffff8a0`000001ca fffff8a0`00000000 : nt!PfpPrefetchFilesTrickle+0x121
fffff880`0892b810 fffff800`02ce3c67 : 00000000`00000000 fffff880`0892bca0 fffff880`0892ba08 fffff8a0`01eea060 : nt!PfpPrefetchRequestPerform+0x30e
fffff880`0892b960 fffff800`02cf023e : fffff880`0892ba08 fffff880`0892ba01 fffffa80`06ec11a0 00000000`00000000 : nt!PfpPrefetchRequest+0x176
fffff880`0892b9d0 fffff800`02cf496e : 00000000`00000000 00000000`02c3f8a0 00000000`0000004f 00000000`08ab5001 : nt!PfSetSuperfetchInformation+0x1ad
fffff880`0892bab0 fffff800`0287c993 : fffffa80`04170060 00000000`00000000 00000000`00000001 00000000`00000001 : nt!NtSetSystemInformation+0xb91
fffff880`0892bc20 00000000`7748144a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`02c3f878 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7748144a
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!MiRelocateImageAgain+48
fffff800`02b64668 f0480fba2e00 lock bts qword ptr [rsi],0
SYMBOL_STACK_INDEX: 4
SYMBOL_NAME: nt!MiRelocateImageAgain+48
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: X64_0x1E_nt!MiRelocateImageAgain+48
BUCKET_ID: X64_0x1E_nt!MiRelocateImageAgain+48