*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck A, {fffffb40059d06db, 2, 0, fffff800032933c9}
Probably caused by : memory_corruption ( nt!MiUnlinkPageFromLockedList+169 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: fffffb40059d06db, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff800032933c9, address which referenced memory
Debugging Details:
------------------
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800034ba100
GetUlongFromAddress: unable to read from fffff800034ba1c0
fffffb40059d06db Nonpaged pool
CURRENT_IRQL: 2
FAULTING_IP:
nt!MiUnlinkPageFromLockedList+169
fffff800`032933c9 410fb6511b movzx edx,byte ptr [r9+1Bh]
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
BUGCHECK_STR: 0xA
PROCESS_NAME: AvastSvc.exe
TRAP_FRAME: fffff8800d53b530 -- (.trap 0xfffff8800d53b530)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=00000004001df024 rbx=0000000000000000 rcx=00000000001ed78b
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff800032933c9 rsp=fffff8800d53b6c0 rbp=0000000000000000
r8=fffff8800d53b6f0 r9=fffffb40059d06c0 r10=fffffa8009a774d8
r11=fffff8800d53b710 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na po cy
nt!MiUnlinkPageFromLockedList+0x169:
fffff800`032933c9 410fb6511b movzx edx,byte ptr [r9+1Bh] ds:fffffb40`059d06db=??
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80003282129 to fffff80003282b80
STACK_TEXT:
fffff880`0d53b3e8 fffff800`03282129 : 00000000`0000000a fffffb40`059d06db 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
fffff880`0d53b3f0 fffff800`03280da0 : fffff880`0d53b5e8 00000000`00000000 00000002`00000000 fffffa80`0063c990 : nt!KiBugCheckDispatch+0x69
fffff880`0d53b530 fffff800`032933c9 : fffff980`27cf32f0 00000000`00000002 fffff800`034bdcd0 00000000`00000002 : nt!KiPageFault+0x260
fffff880`0d53b6c0 fffff800`0324fead : 00000000`00021433 fffffa80`0063c990 fffff8a0`0edfb000 fffffa80`09a774d8 : nt!MiUnlinkPageFromLockedList+0x169
fffff880`0d53b740 fffff800`03250832 : 00000000`00000000 fffffa80`0758d000 00000000`00000000 00000000`00000000 : nt!MmPurgeSection+0x4bd
fffff880`0d53b830 fffff880`012a14c3 : fffffa80`09df0b88 00000000`00000000 fffff8a0`00000000 00000000`00000000 : nt!CcPurgeCacheSection+0x172
fffff880`0d53b8a0 fffff880`012c1e31 : fffff880`09395730 fffff8a0`13994b40 fffff8a0`1446a490 fffff880`0d53bba8 : Ntfs!NtfsDeleteFile+0x57b
fffff880`0d53bb20 fffff880`01231699 : fffffa80`06df5010 fffffa80`066ac680 fffff880`09395690 fffffa80`09b66060 : Ntfs!NtfsCommonCleanup+0x1651
fffff880`0d53bf30 fffff800`0327a677 : fffff880`09395690 00000000`00000000 00000000`00000000 00000000`00000000 : Ntfs!NtfsCommonCleanupCallout+0x19
fffff880`0d53bf60 fffff800`0327a638 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KySwitchKernelStackCallout+0x27
fffff880`09395560 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSwitchKernelStackContinue
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!MiUnlinkPageFromLockedList+169
fffff800`032933c9 410fb6511b movzx edx,byte ptr [r9+1Bh]
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: nt!MiUnlinkPageFromLockedList+169
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 51fb06cd
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: X64_0xA_nt!MiUnlinkPageFromLockedList+169
BUCKET_ID: X64_0xA_nt!MiUnlinkPageFromLockedList+169
Followup: MachineOwner
---------