*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
A device driver attempting to corrupt the system has been caught. This is
because the driver was specified in the registry as being suspect (by the
administrator) and the kernel has enabled substantial checking of this driver.
If the driver attempts to corrupt the system, bugchecks 0xC4, 0xC1 and 0xA will
be among the most commonly seen crashes.
Arguments:
Arg1: 000000f6, Referencing user handle as KernelMode.
Arg2: 0000088c, Handle value being referenced.
Arg3: b0452d38, Address of the current process.
Arg4: 8329141a, Address inside the driver that is performing the incorrect reference.
Debugging Details:
------------------
BUGCHECK_STR: 0xc4_f6
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VERIFIER_ENABLED_VISTA_MINIDUMP
PROCESS_NAME: Steam.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 83582f03 to 8332ae3c
STACK_TEXT:
bc177b94 83582f03 000000c4 000000f6 0000088c nt!KeBugCheckEx+0x1e
bc177bb4 83587766 0000088c bc177c68 0000088c nt!VerifierBugCheckIfAppropriate+0x30
bc177c48 834955b1 bc177ce4 00000000 00000000 nt!VfCheckUserHandle+0x14f
bc177c5c 8329141a 0000088c bc177d24 8328ed6d nt!NtClose+0x45
bc177c5c 8328ed6d 0000088c bc177d24 8328ed6d nt!KiFastCallEntry+0x12a
bc177cd8 86d0cbad 0000088c 3ac44d7d 000008a0 nt!ZwClose+0x11
WARNING: Stack unwind information not available. Following frames may be wrong.
bc177d24 8329141a 000008a0 00000001 0012cd24 cmdguard+0xcbad
bc177d24 76e26344 000008a0 00000001 0012cd24 nt!KiFastCallEntry+0x12a
0012cd24 00000000 00000000 00000000 00000000 0x76e26344
STACK_COMMAND: kb
FOLLOWUP_IP:
cmdguard+cbad
86d0cbad ?? ???
SYMBOL_STACK_INDEX: 6
SYMBOL_NAME: cmdguard+cbad
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: cmdguard
IMAGE_NAME: cmdguard.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4d24a4f1
FAILURE_BUCKET_ID: 0xc4_f6_VRFK_cmdguard+cbad
BUCKET_ID: 0xc4_f6_VRFK_cmdguard+cbad
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
A device driver attempting to corrupt the system has been caught. This is
because the driver was specified in the registry as being suspect (by the
administrator) and the kernel has enabled substantial checking of this driver.
If the driver attempts to corrupt the system, bugchecks 0xC4, 0xC1 and 0xA will
be among the most commonly seen crashes.
Arguments:
Arg1: 000000f6, Referencing user handle as KernelMode.
Arg2: 0000088c, Handle value being referenced.
Arg3: b0452d38, Address of the current process.
Arg4: 8329141a, Address inside the driver that is performing the incorrect reference.
Debugging Details:
------------------
BUGCHECK_STR: 0xc4_f6
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VERIFIER_ENABLED_VISTA_MINIDUMP
PROCESS_NAME: Steam.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 83582f03 to 8332ae3c
STACK_TEXT:
bc177b94 83582f03 000000c4 000000f6 0000088c nt!KeBugCheckEx+0x1e
bc177bb4 83587766 0000088c bc177c68 0000088c nt!VerifierBugCheckIfAppropriate+0x30
bc177c48 834955b1 bc177ce4 00000000 00000000 nt!VfCheckUserHandle+0x14f
bc177c5c 8329141a 0000088c bc177d24 8328ed6d nt!NtClose+0x45
bc177c5c 8328ed6d 0000088c bc177d24 8328ed6d nt!KiFastCallEntry+0x12a
bc177cd8 86d0cbad 0000088c 3ac44d7d 000008a0 nt!ZwClose+0x11
WARNING: Stack unwind information not available. Following frames may be wrong.
bc177d24 8329141a 000008a0 00000001 0012cd24 cmdguard+0xcbad
bc177d24 76e26344 000008a0 00000001 0012cd24 nt!KiFastCallEntry+0x12a
0012cd24 00000000 00000000 00000000 00000000 0x76e26344
STACK_COMMAND: kb
FOLLOWUP_IP:
cmdguard+cbad
86d0cbad ?? ???
SYMBOL_STACK_INDEX: 6
SYMBOL_NAME: cmdguard+cbad
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: cmdguard
IMAGE_NAME: cmdguard.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4d24a4f1
FAILURE_BUCKET_ID: 0xc4_f6_VRFK_cmdguard+cbad
BUCKET_ID: 0xc4_f6_VRFK_cmdguard+cbad
Followup: MachineOwner
---------