*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck C4, {91, 2, fffff80003c0ccc0, 0}
Unable to load image \SystemRoot\system32\DRIVERS\nvlddmkm.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for nvlddmkm.sys
*** ERROR: Module load completed but symbols could not be loaded for nvlddmkm.sys
Probably caused by : nvlddmkm.sys ( nvlddmkm+18b286 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
A device driver attempting to corrupt the system has been caught. This is
because the driver was specified in the registry as being suspect (by the
administrator) and the kernel has enabled substantial checking of this driver.
If the driver attempts to corrupt the system, bugchecks 0xC4, 0xC1 and 0xA will
be among the most commonly seen crashes.
Arguments:
Arg1: 0000000000000091, A driver switched stacks using a method that is not supported by
the operating system. The only supported way to extend a kernel
mode stack is by using KeExpandKernelStackAndCallout.
Arg2: 0000000000000002
Arg3: fffff80003c0ccc0
Arg4: 0000000000000000
Debugging Details:
------------------
BUGCHECK_STR: 0xc4_91
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 2
EXCEPTION_RECORD: fffff80005336398 -- (.exr 0xfffff80005336398)
ExceptionAddress: fffff88009250286 (nvlddmkm+0x000000000018b286)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff
TRAP_FRAME: fffff80005336440 -- (.trap 0xfffff80005336440)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=0000000000100042
rdx=fffffa800bf2c000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff88009250286 rsp=fffff800053365d0 rbp=fffff800053365d0
r8=fffffa800bf2c368 r9=0000000000400108 r10=fffffa800bf2c000
r11=0000000000400108 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na po nc
nvlddmkm+0x18b286:
fffff880`09250286 ?? ???
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80003ada4fa to fffff80003a83bc0
STACK_TEXT:
fffff800`05335498 fffff800`03ada4fa : 00000000`000000c4 00000000`00000091 00000000`00000002 fffff800`03c0ccc0 : nt!KeBugCheckEx
fffff800`053354a0 fffff800`03aad153 : 5422203d`20444945 00202020`36372d50 5f37372d`00000003 20444945`4c424154 : nt! ?? ::FNODOBFM::`string'+0x4884
fffff800`053354e0 fffff800`03abe4c1 : fffff800`05336398 fffff800`053360f0 fffff800`05336440 fffffa80`0bf2c000 : nt!RtlDispatchException+0x33
fffff800`05335bc0 fffff800`03a83242 : fffff800`05336398 fffffa80`0a2d52d0 fffff800`05336440 fffffa80`0bf7d1a0 : nt!KiDispatchException+0x135
fffff800`05336260 fffff800`03a81b4a : 03bb8e00`001093c0 00000000`fffff800 03bb8e00`001093d0 00000000`fffff800 : nt!KiExceptionDispatch+0xc2
fffff800`05336440 fffff880`09250286 : fffff800`05336610 fffff880`0945f6a6 fffffa80`0a2d52d0 fffffa80`0bf7d1a0 : nt!KiGeneralProtectionFault+0x10a
fffff800`053365d0 fffff800`05336610 : fffff880`0945f6a6 fffffa80`0a2d52d0 fffffa80`0bf7d1a0 fffffa80`0bf2c000 : nvlddmkm+0x18b286
fffff800`053365d8 fffff880`0945f6a6 : fffffa80`0a2d52d0 fffffa80`0bf7d1a0 fffffa80`0bf2c000 fffff880`00000000 : 0xfffff800`05336610
fffff800`053365e0 fffffa80`0a2d52d0 : fffffa80`0bf7d1a0 fffffa80`0bf2c000 fffff880`00000000 fffffa80`0bf2c000 : nvlddmkm+0x39a6a6
fffff800`053365e8 fffffa80`0bf7d1a0 : fffffa80`0bf2c000 fffff880`00000000 fffffa80`0bf2c000 00000000`00400108 : 0xfffffa80`0a2d52d0
fffff800`053365f0 fffffa80`0bf2c000 : fffff880`00000000 fffffa80`0bf2c000 00000000`00400108 fffff800`05336670 : 0xfffffa80`0bf7d1a0
fffff800`053365f8 fffff880`00000000 : fffffa80`0bf2c000 00000000`00400108 fffff800`05336670 fffff880`092d35fe : 0xfffffa80`0bf2c000
fffff800`05336600 fffffa80`0bf2c000 : 00000000`00400108 fffff800`05336670 fffff880`092d35fe fffffa80`0c25f9e0 : 0xfffff880`00000000
fffff800`05336608 00000000`00400108 : fffff800`05336670 fffff880`092d35fe fffffa80`0c25f9e0 00000000`00000000 : 0xfffffa80`0bf2c000
fffff800`05336610 fffff800`05336670 : fffff880`092d35fe fffffa80`0c25f9e0 00000000`00000000 fffff800`053366f8 : 0x400108
fffff800`05336618 fffff880`092d35fe : fffffa80`0c25f9e0 00000000`00000000 fffff800`053366f8 00000000`00000020 : 0xfffff800`05336670
fffff800`05336620 fffffa80`0c25f9e0 : 00000000`00000000 fffff800`053366f8 00000000`00000020 fffff800`00000000 : nvlddmkm+0x20e5fe
fffff800`05336628 00000000`00000000 : fffff800`053366f8 00000000`00000020 fffff800`00000000 fffff880`0927e26b : 0xfffffa80`0c25f9e0
STACK_COMMAND: kb
FOLLOWUP_IP:
nvlddmkm+18b286
fffff880`09250286 ?? ???
SYMBOL_STACK_INDEX: 6
SYMBOL_NAME: nvlddmkm+18b286
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nvlddmkm
IMAGE_NAME: nvlddmkm.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 51427b3c
FAILURE_BUCKET_ID: X64_0xc4_91_nvlddmkm+18b286
BUCKET_ID: X64_0xc4_91_nvlddmkm+18b286
Followup: MachineOwner
---------
0: kd> lmvm nvlddmkm
start end module name
fffff880`090c5000 fffff880`09b70000 nvlddmkm T (no symbols)
Loaded symbol image file: nvlddmkm.sys
Image path: \SystemRoot\system32\DRIVERS\nvlddmkm.sys
Image name: nvlddmkm.sys
Timestamp: Fri Mar 15 07:07:00 2013 (51427B3C)
CheckSum: 00A8D47C
ImageSize: 00AAB000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4