Microsoft (R) Windows Debugger Version 6.3.9600.16384 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\YUSRA\Downloads\LIONEL_HUTZ-02_01_2015_193237_73\123014-12620-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
************* Symbol Path validation summary **************
Response Time (ms) Location
Deferred SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (6 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.18409.amd64fre.win7sp1_gdr.140303-2144
Machine Name:
Kernel base = 0xfffff800`02e5a000 PsLoadedModuleList = 0xfffff800`0309d890
Debug session time: Tue Dec 30 23:32:38.362 2014 (UTC + 6:00)
System Uptime: 0 days 4:08:08.517
Loading Kernel Symbols
.
Press ctrl-c (cdb, kd, ntsd) or ctrl-break (windbg) to abort symbol loads that take too long.
Run !sym noisy before .reload to track down problems loading symbols.
..............................................................
................................................................
..........................
Loading User Symbols
Loading unloaded module list
.................................
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck C5, {fffffffffffffff2, 2, 0, fffff80003003123}
Probably caused by : NETIO.SYS ( NETIO!FreeConditions+92 )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_CORRUPTED_EXPOOL (c5)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is
caused by drivers that have corrupted the system pool. Run the driver
verifier against any new (or suspect) drivers, and if that doesn't turn up
the culprit, then use gflags to enable special pool.
Arguments:
Arg1: fffffffffffffff2, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, value 0 = read operation, 1 = write operation
Arg4: fffff80003003123, address which referenced memory
Debugging Details:
------------------
BUGCHECK_STR: 0xC5_2
CURRENT_IRQL: 2
FAULTING_IP:
nt!ExFreePoolWithTag+43
fffff800`03003123 418b45f0 mov eax,dword ptr [r13-10h]
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
PROCESS_NAME: svchost.exe
ANALYSIS_VERSION: 6.3.9600.16384 (debuggers(dbg).130821-1623) x86fre
TRAP_FRAME: fffff88007c4d470 -- (.trap 0xfffff88007c4d470)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=0000000000000002
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80003003123 rsp=fffff88007c4d600 rbp=fffffa8007157cd0
r8=fffffa800bb08c90 r9=0000000000000020 r10=fffff88002f65a60
r11=fffffa80075a0ef0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe nc
nt!ExFreePoolWithTag+0x43:
fffff800`03003123 418b45f0 mov eax,dword ptr [r13-10h] ds:ffffffff`fffffff0=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002ecf169 to fffff80002ecfbc0
STACK_TEXT:
fffff880`07c4d328 fffff800`02ecf169 : 00000000`0000000a ffffffff`fffffff2 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
fffff880`07c4d330 fffff800`02ecdde0 : 00000000`00000000 00000000`00000000 00000000`00000000 fffffa80`071626c0 : nt!KiBugCheckDispatch+0x69
fffff880`07c4d470 fffff800`03003123 : fffffa80`0b2ac2e0 00000000`00000070 00000000`00000000 00000000`000007ff : nt!KiPageFault+0x260
fffff880`07c4d600 fffff880`01588ea1 : badbadfa`badbadfa fffffa80`06c81b98 00000000`48706657 fffffa80`06c81b98 : nt!ExFreePoolWithTag+0x43
fffff880`07c4d6b0 fffff880`015910e5 : fffffa80`09fa06d0 fffffa80`06c81b98 00000000`0000000b fffffa80`06c81b98 : NETIO!FreeConditions+0x92
fffff880`07c4d6e0 fffff880`0158ff9d : fffffa80`09fa06f0 00000000`00000000 fffff880`07c4d7c0 fffff880`07c4d7c0 : NETIO!FreeCacheEntry+0x95
fffff880`07c4d720 fffff880`01591176 : fffff880`07c4d7c0 00000000`00000000 00000000`00000000 fffffa80`06c81b98 : NETIO!FreeSomeCacheBucketEntries+0x6d
fffff880`07c4d770 fffff880`0158362e : fffffa80`06c81b98 00000000`00000000 00000000`00020004 00000000`00000000 : NETIO!FreeSomeCacheEntries+0x36
fffff880`07c4d7a0 fffff880`0158fc19 : 00000000`00000000 fffff880`01000003 00000000`00000009 00000000`00000010 : NETIO!UpdateCacheLruBucket+0x1de
fffff880`07c4d7e0 fffff880`01590a5e : 00000000`00000000 00000000`00000012 fffffa80`07dda660 00000000`00000090 : NETIO!WfpActivateCaches+0x52
fffff880`07c4d820 fffff880`01591274 : fffffa80`080000ff fffffa80`0853d180 fffffa80`07951628 00000000`00000000 : NETIO!KfdCommitTransaction+0x197
fffff880`07c4d860 fffff880`016100bb : fffffa80`079515f0 fffffa80`0853d180 fffffa80`0949f2c0 00000000`00000001 : NETIO!IoctlKfdCommitTransaction+0x54
fffff880`07c4d890 fffff800`031ece67 : fffffa80`0949f2c0 fffff880`07c4db60 fffffa80`0949f2c0 fffffa80`079515f0 : tcpip!KfdDispatchDevCtl+0x6b
fffff880`07c4d8d0 fffff800`031ed6c6 : fffff880`07c4dab8 00000000`00000000 00000000`00000000 00000000`00000000 : nt!IopXxxControlFile+0x607
fffff880`07c4da00 fffff800`02ecee53 : fffff880`07c4db60 fffffa80`08cce120 fffff880`07c4dab8 00000980`00000000 : nt!NtDeviceIoControlFile+0x56
fffff880`07c4da70 00000000`77b7132a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`009ae878 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77b7132a
STACK_COMMAND: kb
FOLLOWUP_IP:
NETIO!FreeConditions+92
fffff880`01588ea1 4c8923 mov qword ptr [rbx],r12
SYMBOL_STACK_INDEX: 4
SYMBOL_NAME: NETIO!FreeConditions+92
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: NETIO
IMAGE_NAME: NETIO.SYS
DEBUG_FLR_IMAGE_TIMESTAMP: 5294760d
IMAGE_VERSION: 6.1.7601.18327
FAILURE_BUCKET_ID: X64_0xC5_2_NETIO!FreeConditions+92
BUCKET_ID: X64_0xC5_2_NETIO!FreeConditions+92
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:x64_0xc5_2_netio!freeconditions+92
FAILURE_ID_HASH: {e8a84e23-940e-5eea-53da-242d14948bbe}
Followup: MachineOwner
---------