*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck D5, {fffff980023eaf10, 0, fffff88003ba1d8e, 0}
Unable to load image \SystemRoot\system32\drivers\ATKDispLowFilter.sys, Win32 error 0n2
*** ERROR: Module load completed but symbols could not be loaded for ATKDispLowFilter.sys
Could not read faulting driver name
Probably caused by : ATKDispLowFilter.sys ( ATKDispLowFilter+d8e )
DRIVER_PAGE_FAULT_IN_FREED_SPECIAL_POOL (d5)
Memory was referenced after it was freed.
This cannot be protected by try-except.
When possible, the guilty driver's name (Unicode string) is printed on
the bugcheck screen and saved in KiBugCheckDriver.
Arguments:
Arg1: fffff980023eaf10, memory referenced
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation
Arg3: fffff88003ba1d8e, if non-zero, the address which referenced memory.
Arg4: 0000000000000000, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002d060e0
fffff980023eaf10
FAULTING_IP:
ATKDispLowFilter+d8e
fffff880`03ba1d8e 4c8b4f70 mov r9,qword ptr [rdi+70h]
MM_INTERNAL_CODE: 0
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VERIFIER_ENABLED_VISTA_MINIDUMP
BUGCHECK_STR: 0xD5
PROCESS_NAME: System
CURRENT_IRQL: 0
TRAP_FRAME: fffff88002f83a70 -- (.trap 0xfffff88002f83a70)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=fffffa8009999071
rdx=fffffa800999bf41 rsi=0000000000000000 rdi=0000000000000000
rip=fffff88003ba1d8e rsp=fffff88002f83c00 rbp=0000000000000000
r8=fffffa800999bf40 r9=0000000000000100 r10=fffff80002f83640
r11=fffffa8009999070 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz ac pe cy
ATKDispLowFilter+0xd8e:
fffff880`03ba1d8e 4c8b4f70 mov r9,qword ptr [rdi+70h] ds:aea0:00000000`00000070=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002b4ef14 to fffff80002ace740
STACK_TEXT:
fffff880`02f83908 fffff800`02b4ef14 : 00000000`00000050 fffff980`023eaf10 00000000`00000000 fffff880`02f83a70 : nt!KeBugCheckEx
fffff880`02f83910 fffff800`02acc82e : 00000000`00000000 00000000`00000001 00000000`00000000 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x42837
fffff880`02f83a70 fffff880`03ba1d8e : 00000000`00000001 00000000`00000002 fffffa80`099a81b0 fffffa80`09999070 : nt!KiPageFault+0x16e
fffff880`02f83c00 00000000`00000001 : 00000000`00000002 fffffa80`099a81b0 fffffa80`09999070 00000000`00000020 : ATKDispLowFilter+0xd8e
fffff880`02f83c08 00000000`00000002 : fffffa80`099a81b0 fffffa80`09999070 00000000`00000020 fffffa80`099b6010 : 0x1
fffff880`02f83c10 fffffa80`099a81b0 : fffffa80`09999070 00000000`00000020 fffffa80`099b6010 fffff980`0221cfd0 : 0x2
fffff880`02f83c18 fffffa80`09999070 : 00000000`00000020 fffffa80`099b6010 fffff980`0221cfd0 00000000`00000000 : 0xfffffa80`099a81b0
fffff880`02f83c20 00000000`00000020 : fffffa80`099b6010 fffff980`0221cfd0 00000000`00000000 fffffa80`099b6010 : 0xfffffa80`09999070
fffff880`02f83c28 fffffa80`099b6010 : fffff980`0221cfd0 00000000`00000000 fffffa80`099b6010 fffff880`03ba169b : 0x20
fffff880`02f83c30 fffff980`0221cfd0 : 00000000`00000000 fffffa80`099b6010 fffff880`03ba169b fffff980`023eaea0 : 0xfffffa80`099b6010
fffff880`02f83c38 00000000`00000000 : fffffa80`099b6010 fffff880`03ba169b fffff980`023eaea0 00000000`00000002 : 0xfffff980`0221cfd0
STACK_COMMAND: kb
FOLLOWUP_IP:
ATKDispLowFilter+d8e
fffff880`03ba1d8e 4c8b4f70 mov r9,qword ptr [rdi+70h]
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: ATKDispLowFilter+d8e
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: ATKDispLowFilter
IMAGE_NAME: ATKDispLowFilter.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 482a5671
FAILURE_BUCKET_ID: X64_0xD5_VRF_ATKDispLowFilter+d8e
BUCKET_ID: X64_0xD5_VRF_ATKDispLowFilter+d8e
Followup: MachineOwner
---------