Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\K\Desktop\013011-24890-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\Symbols*http://msdl.microsoft.com/download/symbols;srv*e:\symbols
*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`02c5b000 PsLoadedModuleList = 0xfffff800`02e98e50
Debug session time: Sun Jan 30 12:27:31.658 2011 (GMT-5)
System Uptime: 0 days 0:00:42.783
Loading Kernel Symbols
...............................................................
................................................................
.......................
Loading User Symbols
Loading unloaded module list
...
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck C4, {3c, f8, 0, 0}
Unable to load image AVGIDSDriver.Sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for AVGIDSDriver.Sys
*** ERROR: Module load completed but symbols could not be loaded for AVGIDSDriver.Sys
Probably caused by : AVGIDSDriver.Sys ( AVGIDSDriver+184c8 )
Followup: MachineOwner
---------
4: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
A device driver attempting to corrupt the system has been caught. This is
because the driver was specified in the registry as being suspect (by the
administrator) and the kernel has enabled substantial checking of this driver.
If the driver attempts to corrupt the system, bugchecks 0xC4, 0xC1 and 0xA will
be among the most commonly seen crashes.
Arguments:
Arg1: 000000000000003c, ObReferenceObjectByHandle is being called with a bad handle.
Arg2: 00000000000000f8, bad handle passed in,
Arg3: 0000000000000000, object type,
Arg4: 0000000000000000, 0.
Debugging Details:
------------------
BUGCHECK_STR: 0xc4_3c
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: LogonUI.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff800031553dc to fffff80002ccb740
STACK_TEXT:
fffff880`035383c8 fffff800`031553dc : 00000000`000000c4 00000000`0000003c 00000000`000000f8 00000000`00000000 : nt!KeBugCheckEx
fffff880`035383d0 fffff800`0316a90f : fffff880`07145604 fffff800`0316f8ef fffff880`03538940 fffff880`07145604 : nt!VerifierBugCheckIfAppropriate+0x3c
fffff880`03538410 fffff880`071504c8 : fffff880`03538500 fffff800`02e705a0 ffffffff`800013b8 fffffa80`12c30060 : nt!VerifierObReferenceObjectByHandle+0xdf
fffff880`03538460 fffff880`03538500 : fffff800`02e705a0 ffffffff`800013b8 fffffa80`12c30060 fffff880`035384a8 : AVGIDSDriver+0x184c8
fffff880`03538468 fffff800`02e705a0 : ffffffff`800013b8 fffffa80`12c30060 fffff880`035384a8 00000000`00000000 : 0xfffff880`03538500
fffff880`03538470 ffffffff`800013b8 : fffffa80`12c30060 fffff880`035384a8 00000000`00000000 00000000`00363200 : nt!ExWorkerQueue
fffff880`03538478 fffffa80`12c30060 : fffff880`035384a8 00000000`00000000 00000000`00363200 fffff880`0714fa51 : 0xffffffff`800013b8
fffff880`03538480 fffff880`035384a8 : 00000000`00000000 00000000`00363200 fffff880`0714fa51 fffff800`00000001 : 0xfffffa80`12c30060
fffff880`03538488 00000000`00000000 : 00000000`00363200 fffff880`0714fa51 fffff800`00000001 00000000`00000000 : 0xfffff880`035384a8
STACK_COMMAND: kb
FOLLOWUP_IP:
AVGIDSDriver+184c8
fffff880`071504c8 ?? ???
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: AVGIDSDriver+184c8
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: AVGIDSDriver
IMAGE_NAME: AVGIDSDriver.Sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4c58972d
FAILURE_BUCKET_ID: X64_0xc4_3c_AVGIDSDriver+184c8
BUCKET_ID: X64_0xc4_3c_AVGIDSDriver+184c8
Followup: MachineOwner
---------