Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [D:\Kingston\BSODDmpFiles\IdiotOnComputer\TwoDMPS\033112-17877-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.17640.amd64fre.win7sp1_gdr.110622-1506
Machine Name:
Kernel base = 0xfffff800`02e09000 PsLoadedModuleList = 0xfffff800`0304e670
Debug session time: Sat Mar 31 17:37:03.430 2012 (UTC - 6:00)
System Uptime: 0 days 4:49:01.600
Loading Kernel Symbols
...............................................................
................................................................
.......................
Loading User Symbols
Loading unloaded module list
.............
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck C4, {e3, fffffa80059ba531, 5cdf384, 0}
Probably caused by : ntkrnlmp.exe ( nt!VerifierBugCheckIfAppropriate+3c )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
A device driver attempting to corrupt the system has been caught. This is
because the driver was specified in the registry as being suspect (by the
administrator) and the kernel has enabled substantial checking of this driver.
If the driver attempts to corrupt the system, bugchecks 0xC4, 0xC1 and 0xA will
be among the most commonly seen crashes.
Arguments:
Arg1: 00000000000000e3, Kernel Zw API called with user-mode address as parameter.
Arg2: fffffa80059ba531, Address inside the driver making the incorrect API call.
Arg3: 0000000005cdf384, User-mode address used as API parameter.
Arg4: 0000000000000000
Debugging Details:
------------------
BUGCHECK_STR: 0xc4_e3
FAULTING_IP:
+3035313636653265
fffffa80`059ba531 85c0 test eax,eax
FOLLOWUP_IP:
nt!VerifierBugCheckIfAppropriate+3c
fffff800`0330f3dc cc int 3
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VERIFIER_ENABLED_VISTA_MINIDUMP
PROCESS_NAME: ekrn.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff8000330f3dc to fffff80002e85c40
STACK_TEXT:
fffff880`077f8568 fffff800`0330f3dc : 00000000`000000c4 00000000`000000e3 fffffa80`059ba531 00000000`05cdf384 : nt!KeBugCheckEx
fffff880`077f8570 fffff800`0330fec5 : fffffa80`03e25b00 fffff800`0331e09a fffff880`077f3000 fffff880`077f9000 : nt!VerifierBugCheckIfAppropriate+0x3c
fffff880`077f85b0 fffff800`0331139e : 00000000`00000000 00000000`00000028 fffffa80`059ba3b9 ffffe61c`0000051e : nt!ViZwCheckAddress+0x35
fffff880`077f85f0 fffff800`03311426 : fffff880`077f8738 fffff880`077f8738 00000000`00000000 00000000`00000000 : nt!ViZwCheckUnicodeString+0x2e
fffff880`077f8630 fffff800`03314d99 : fffffa80`059ba531 00000000`00000000 00000000`70616745 00000000`00000000 : nt!ViZwCheckObjectAttributes+0x26
fffff880`077f8660 fffffa80`059ba531 : 00000000`05cdf384 00000000`00000000 00000000`05cdf3b4 00000000`05cdf3fa : nt!VfZwOpenFile+0x49
fffff880`077f86a0 00000000`05cdf384 : 00000000`00000000 00000000`05cdf3b4 00000000`05cdf3fa 00000000`00000007 : 0xfffffa80`059ba531
fffff880`077f86a8 00000000`00000000 : 00000000`05cdf3b4 00000000`05cdf3fa 00000000`00000007 fffffa80`00000021 : 0x5cdf384
STACK_COMMAND: kb
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!VerifierBugCheckIfAppropriate+3c
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4e02aaa3
FAILURE_BUCKET_ID: X64_0xc4_e3_VRF_nt!VerifierBugCheckIfAppropriate+3c
BUCKET_ID: X64_0xc4_e3_VRF_nt!VerifierBugCheckIfAppropriate+3c
Followup: MachineOwner
---------