Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\K\Desktop\102810-35521-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\Symbols*http://msdl.microsoft.com/download/symbols;srv*e:\symbols
*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`0281a000 PsLoadedModuleList = 0xfffff800`02a57e50
Debug session time: Thu Oct 28 17:34:48.772 2010 (GMT-4)
System Uptime: 0 days 0:28:46.411
Loading Kernel Symbols
...............................................................
................................................................
.......................
Loading User Symbols
Loading unloaded module list
.......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck C4, {f6, 4, fffffa8003615b30, fffff8800747d273}
Unable to load image \??\C:\Program Files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for KernExplorer64.sys
*** ERROR: Module load completed but symbols could not be loaded for KernExplorer64.sys
Probably caused by : KernExplorer64.sys ( KernExplorer64+1273 )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
A device driver attempting to corrupt the system has been caught. This is
because the driver was specified in the registry as being suspect (by the
administrator) and the kernel has enabled substantial checking of this driver.
If the driver attempts to corrupt the system, bugchecks 0xC4, 0xC1 and 0xA will
be among the most commonly seen crashes.
Arguments:
Arg1: 00000000000000f6, Referencing user handle as KernelMode.
Arg2: 0000000000000004, Handle value being referenced.
Arg3: fffffa8003615b30, Address of the current process.
Arg4: fffff8800747d273, Address inside the driver that is performing the incorrect reference.
Debugging Details:
------------------
BUGCHECK_STR: 0xc4_f6
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VERIFIER_ENABLED_VISTA_MINIDUMP
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff80002d143dc to fffff8000288a740
STACK_TEXT:
fffff880`09bbd658 fffff800`02d143dc : 00000000`000000c4 00000000`000000f6 00000000`00000004 fffffa80`03615b30 : nt!KeBugCheckEx
fffff880`09bbd660 fffff800`02d29ae4 : 00000000`00000004 fffffa80`03615b30 00000000`00000002 fffffa80`04a82060 : nt!VerifierBugCheckIfAppropriate+0x3c
fffff880`09bbd6a0 fffff800`02ae5b40 : fffff800`02a19880 fffff880`09bbd8d0 00000000`00000000 fffffa80`03493e00 : nt!VfCheckUserHandle+0x1b4
fffff880`09bbd780 fffff800`02b615f5 : 00000000`00000300 fffff800`00000000 00000000`00000000 fffffa80`03fdb000 : nt! ?? ::NNGAKEGL::`string'+0x20e2e
fffff880`09bbd850 fffff800`02d29878 : 00000000`00000348 fffffa80`03493e40 fffff880`09bbd930 fffff880`0747db52 : nt!ObReferenceObjectByHandle+0x25
fffff880`09bbd8a0 fffff880`0747d273 : 00000000`00000000 fffffa80`02909000 fffffa80`03493e40 00000000`00000000 : nt!VerifierObReferenceObjectByHandle+0x48
fffff880`09bbd8f0 00000000`00000000 : fffffa80`02909000 fffffa80`03493e40 00000000`00000000 fffff880`09bbd9b0 : KernExplorer64+0x1273
STACK_COMMAND: kb
FOLLOWUP_IP:
KernExplorer64+1273
fffff880`0747d273 807c244001 cmp byte ptr [rsp+40h],1
SYMBOL_STACK_INDEX: 6
SYMBOL_NAME: KernExplorer64+1273
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: KernExplorer64
IMAGE_NAME: KernExplorer64.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4be3e1d3
FAILURE_BUCKET_ID: X64_0xc4_f6_VRF_KernExplorer64+1273
BUCKET_ID: X64_0xc4_f6_VRF_KernExplorer64+1273
Followup: MachineOwner
---------