*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
A device driver attempting to corrupt the system has been caught. This is
because the driver was specified in the registry as being suspect (by the
administrator) and the kernel has enabled substantial checking of this driver.
If the driver attempts to corrupt the system, bugchecks 0xC4, 0xC1 and 0xA will
be among the most commonly seen crashes.
Arguments:
Arg1: 000000e3, Kernel Zw API called with user-mode address as parameter.
Arg2: 8c597230, Address inside the driver making the incorrect API call.
Arg3: 0575f3b4, User-mode address used as API parameter.
Arg4: 00000000
Debugging Details:
------------------
BUGCHECK_STR: 0xc4_e3
FAULTING_IP:
+5e882faf0313dc24
8c597230 3d05000080 cmp eax,80000005h
FOLLOWUP_IP:
nt!VerifierBugCheckIfAppropriate+30
82b4ff03 cc int 3
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VERIFIER_ENABLED_VISTA_MINIDUMP
PROCESS_NAME: ekrn.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 82b4ff03 to 828f7f20
STACK_TEXT:
aea7f9ec 82b4ff03 000000c4 000000e3 8c597230 nt!KeBugCheckEx+0x1e
aea7fa0c 82b5da73 8c597230 0575f3b4 aea7faa8 nt!VerifierBugCheckIfAppropriate+0x30
aea7fa20 82b5dadd 8c597230 8c597230 0575f3be nt!ViZwCheckAddress+0x30
aea7fa34 82b5e8ee 8c597230 8c4280f0 b4dd502e nt!ViZwCheckUnicodeString+0x22
aea7fa44 8c597230 80000850 00000000 00000000 nt!VfZwQueryDirectoryFile+0x3f
WARNING: Frame IP not in any known module. Following frames may be wrong.
aea7fa48 80000850 00000000 00000000 00000000 0x8c597230
aea7fa4c 00000000 00000000 00000000 aea7fab0 0x80000850
STACK_COMMAND: kb
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!VerifierBugCheckIfAppropriate+30
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrpamp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4ce78a09
FAILURE_BUCKET_ID: 0xc4_e3_VRF_nt!VerifierBugCheckIfAppropriate+30
BUCKET_ID: 0xc4_e3_VRF_nt!VerifierBugCheckIfAppropriate+30
Followup: MachineOwner
---------
1: kd> lmtsmn
start end module name
850b2000 850fa000 ACPI ACPI.sys Sat Nov 20 21:37:52 2010 (4CE788E0)
8e89a000 8e8f4000 afd afd.sys Sat Nov 20 21:40:00 2010 (4CE78960)
8efd1000 8efe3000 AgileVpn AgileVpn.sys Tue Jul 14 11:55:00 2009 (4A5BC954)
851f2000 851fb000 amdxata amdxata.sys Sat Mar 20 05:19:01 2010 (4BA3A3F5)
851e9000 851f2000 atapi atapi.sys Tue Jul 14 11:11:15 2009 (4A5BBF13)
82fb5000 82fd8000 ataport ataport.SYS Sat Nov 20 21:38:00 2010 (4CE788E8)
8502a000 85031000 Beep Beep.SYS Tue Jul 14 11:45:00 2009 (4A5BC6FC)
8ee8e000 8ee9c000 blbdrive blbdrive.sys Tue Jul 14 11:23:04 2009 (4A5BC1D8)
82ec0000 82ec8000 BOOTVID BOOTVID.dll Tue Jul 14 13:04:34 2009 (4A5BD9A2)
aa159000 aa172000 bowser bowser.sys Tue Jul 14 11:14:21 2009 (4A5BBFCD)
98570000 9858e000 cdd cdd.dll unavailable (00000000)
82fd8000 82ff7000 cdrom cdrom.sys Sat Nov 20 21:38:09 2010 (4CE788F1)
82f0a000 82fb5000 CI CI.dll Sun Nov 21 01:05:17 2010 (4CE7B97D)
85200000 85225000 CLASSPNP CLASSPNP.SYS Tue Jul 14 11:11:20 2009 (4A5BBF18)
82ec8000 82f0a000 CLFS CLFS.SYS Tue Jul 14 11:11:10 2009 (4A5BBF0E)
8543d000 8549a000 cng cng.sys Tue Jul 14 11:32:55 2009 (4A5BC427)
8f619000 8f626000 CompositeBus CompositeBus.sys Sat Nov 20 22:50:21 2010 (4CE799DD)
946ed000 946fa000 crashdmp crashdmp.sys Tue Jul 14 11:45:50 2009 (4A5BC72E)
8ee12000 8ee76000 csc csc.sys Sat Nov 20 21:44:32 2010 (4CE78A70)
8ee76000 8ee8e000 dfsc dfsc.sys Sat Nov 20 21:42:32 2010 (4CE789F8)
8e9ed000 8e9f9000 discache discache.sys Tue Jul 14 11:24:04 2009 (4A5BC214)
855e3000 855f4000 disk disk.sys Tue Jul 14 11:11:28 2009 (4A5BBF20)
946d4000 946ed000 drmk drmk.sys Tue Jul 14 12:36:05 2009 (4A5BD2F5)
94705000 9470e000 dump_atapi dump_atapi.sys Tue Jul 14 11:11:15 2009 (4A5BBF13)
946fa000 94705000 dump_dumpata dump_dumpata.sys Tue Jul 14 11:11:16 2009 (4A5BBF14)
9470e000 9471f000 dump_dumpfve dump_dumpfve.sys Tue Jul 14 11:12:47 2009 (4A5BBF6F)
9471f000 94729000 Dxapi Dxapi.sys Tue Jul 14 11:25:25 2009 (4A5BC265)
8eecf000 8ef86000 dxgkrnl dxgkrnl.sys Sat Nov 20 22:08:14 2010 (4CE78FFE)
8ff51000 8ff8a000 dxgmms1 dxgmms1.sys Sat Nov 20 22:07:03 2010 (4CE78FB7)
aa00b000 aa0b1000 eamonm eamonm.sys Thu Dec 09 18:29:13 2010 (4D006929)
82e00000 82e1f000 ehdrv ehdrv.sys Thu Dec 09 18:29:52 2010 (4D006950)
947a5000 947be000 epfwwfpr epfwwfpr.sys Thu Dec 09 18:25:16 2010 (4D00683C)
8526a000 8527b000 fileinfo fileinfo.sys Tue Jul 14 11:21:51 2009 (4A5BC18F)
85236000 8526a000 fltmgr fltmgr.sys Tue Jul 14 11:11:13 2009 (4A5BBF11)
854a8000 854b1000 Fs_Rec Fs_Rec.sys Tue Jul 14 11:11:14 2009 (4A5BBF12)
85400000 85432000 fvevol fvevol.sys Sat Nov 20 21:40:22 2010 (4CE78976)
85779000 857aa000 fwpkclnt fwpkclnt.sys Sat Nov 20 21:39:08 2010 (4CE7892C)
82c2b000 82c62000 hal halmacpi.dll Sat Nov 20 21:37:38 2010 (4CE788D2)
8ff8a000 8ffa9000 HDAudBus HDAudBus.sys Sat Nov 20 22:59:28 2010 (4CE79C00)
9473f000 94752000 HIDCLASS HIDCLASS.SYS Sat Nov 20 22:59:37 2010 (4CE79C09)
94752000 94758480 HIDPARSE HIDPARSE.SYS Tue Jul 14 11:50:59 2009 (4A5BC863)
94734000 9473f000 hidusb hidusb.sys Sat Nov 20 22:59:38 2010 (4CE79C0A)
aa0d4000 aa159000 HTTP HTTP.sys Sat Nov 20 21:40:17 2010 (4CE78971)
855db000 855e3000 hwpolicy hwpolicy.sys Sat Nov 20 21:37:35 2010 (4CE788CF)
8f634000 8ff51000 igdkmd32 igdkmd32.sys Thu Aug 26 07:31:24 2010 (4C756F8C)
851ac000 851b3000 intelide intelide.sys Tue Jul 14 11:11:19 2009 (4A5BBF17)
8eebd000 8eecf000 intelppm intelppm.sys Tue Jul 14 11:11:03 2009 (4A5BBF07)
8ffa9000 8ffee000 k57nd60x k57nd60x.sys Thu Aug 06 23:44:50 2009 (4A7AC232)
924ae000 924bb000 kbdclass kbdclass.sys Tue Jul 14 11:11:15 2009 (4A5BBF13)
94766000 94772000 kbdhid kbdhid.sys Sat Nov 20 22:50:10 2010 (4CE799D2)
80bac000 80bb4000 kdcom kdcom.dll Tue Jul 14 13:08:58 2009 (4A5BDAAA)
924ca000 924fe000 ks ks.sys Sat Nov 20 22:50:17 2010 (4CE799D9)
853d5000 853e8000 ksecdd ksecdd.sys Sat Nov 20 21:38:54 2010 (4CE7891E)
855a6000 855cb000 ksecpkg ksecpkg.sys Tue Jul 14 11:34:00 2009 (4A5BC468)
aa0b1000 aa0c1000 lltdio lltdio.sys Tue Jul 14 11:53:18 2009 (4A5BC8EE)
94772000 9478d000 luafv luafv.sys Tue Jul 14 11:15:44 2009 (4A5BC020)
82e2a000 82eaf000 mcupdate_GenuineIntel mcupdate_GenuineIntel.dll Sun Nov 21 01:00:54 2010 (4CE7B876)
94729000 94734000 monitor monitor.sys Tue Jul 14 11:25:58 2009 (4A5BC286)
924bb000 924c8000 mouclass mouclass.sys Tue Jul 14 11:11:15 2009 (4A5BBF13)
9475b000 94766000 mouhid mouhid.sys Tue Jul 14 11:45:08 2009 (4A5BC704)
851c1000 851d7000 mountmgr mountmgr.sys Sat Nov 20 21:38:09 2010 (4CE788F1)
aa172000 aa184000 mpsdrv mpsdrv.sys Tue Jul 14 11:52:52 2009 (4A5BC8D4)
aa184000 aa1a7000 mrxsmb mrxsmb.sys Sat Nov 20 21:42:40 2010 (4CE78A00)
aa1a7000 aa1e2000 mrxsmb10 mrxsmb10.sys Sat Nov 20 21:44:15 2010 (4CE78A5F)
aa1e2000 aa1fd000 mrxsmb20 mrxsmb20.sys Sat Nov 20 21:42:47 2010 (4CE78A07)
8e85e000 8e869000 Msfs Msfs.SYS Tue Jul 14 11:11:26 2009 (4A5BBF1E)
85103000 8510b000 msisadrv msisadrv.sys Tue Jul 14 11:11:09 2009 (4A5BBF0D)
853aa000 853d5000 msrpc msrpc.sys Tue Jul 14 11:11:59 2009 (4A5BBF3F)
8e9e3000 8e9ed000 mssmbios mssmbios.sys Tue Jul 14 11:19:25 2009 (4A5BC0FD)
855cb000 855db000 mup mup.sys Tue Jul 14 11:14:14 2009 (4A5BBFC6)
854b1000 85568000 ndis ndis.sys Sat Nov 20 21:39:19 2010 (4CE78937)
8f626000 8f631000 ndistapi ndistapi.sys Tue Jul 14 11:54:24 2009 (4A5BC930)
9243c000 9245e000 ndiswan ndiswan.sys Sat Nov 20 23:07:48 2010 (4CE79DF4)
92550000 92561000 NDProxy NDProxy.SYS Sat Nov 20 23:07:39 2010 (4CE79DEB)
8e94c000 8e95a000 netbios netbios.sys Tue Jul 14 11:53:54 2009 (4A5BC912)
8e8f4000 8e926000 netbt netbt.sys Sat Nov 20 21:39:22 2010 (4CE7893A)
85568000 855a6000 NETIO NETIO.SYS Sat Nov 20 21:40:03 2010 (4CE78963)
8e869000 8e877000 Npfs Npfs.SYS Tue Jul 14 11:11:31 2009 (4A5BBF23)
8e9d9000 8e9e3000 nsiproxy nsiproxy.sys Tue Jul 14 11:12:08 2009 (4A5BBF48)
82819000 82c2b000 nt ntkrpamp.exe Sat Nov 20 21:42:49 2010 (4CE78A09)
8527b000 853aa000 Ntfs Ntfs.sys Sat Nov 20 21:39:08 2010 (4CE7892C)
853f9000 85400000 Null Null.SYS Tue Jul 14 11:11:12 2009 (4A5BBF10)
8e92d000 8e94c000 pacer pacer.sys Tue Jul 14 11:53:58 2009 (4A5BC916)
85140000 85151000 partmgr partmgr.sys Sat Nov 20 21:38:14 2010 (4CE788F6)
8510b000 85135000 pci pci.sys Sat Nov 20 21:37:57 2010 (4CE788E5)
851b3000 851c1000 PCIIDEX PCIIDEX.SYS Tue Jul 14 11:11:15 2009 (4A5BBF13)
8549a000 854a8000 pcw pcw.sys Tue Jul 14 11:11:10 2009 (4A5BBF0E)
92561000 925f8000 peauth peauth.sys Tue Jul 14 12:35:44 2009 (4A5BD2E0)
946a5000 946d4000 portcls portcls.sys Tue Jul 14 11:51:00 2009 (4A5BC864)
82eaf000 82ec0000 PSHED PSHED.dll Tue Jul 14 13:09:36 2009 (4A5BDAD0)
8efe3000 8effb000 rasl2tp rasl2tp.sys Tue Jul 14 11:54:33 2009 (4A5BC939)
9245e000 92476000 raspppoe raspppoe.sys Tue Jul 14 11:54:53 2009 (4A5BC94D)
92476000 9248d000 raspptp raspptp.sys Tue Jul 14 11:54:47 2009 (4A5BC947)
9248d000 924a4000 rassstp rassstp.sys Tue Jul 14 11:54:57 2009 (4A5BC951)
8e998000 8e9d9000 rdbss rdbss.sys Sat Nov 20 21:42:44 2010 (4CE78A04)
924a4000 924ae000 rdpbus rdpbus.sys Tue Jul 14 12:02:40 2009 (4A5BCB20)
8e846000 8e84e000 RDPCDD RDPCDD.sys Sat Nov 20 23:22:19 2010 (4CE7A15B)
ae2df000 ae304000 rdpdr rdpdr.sys Sat Nov 20 23:24:44 2010 (4CE7A1EC)
8e84e000 8e856000 rdpencdd rdpencdd.sys Tue Jul 14 12:01:39 2009 (4A5BCAE3)
8e856000 8e85e000 rdprefmp rdprefmp.sys Tue Jul 14 12:01:41 2009 (4A5BCAE5)
ae31c000 ae34e000 RDPWD RDPWD.SYS Sat Nov 20 23:22:23 2010 (4CE7A15F)
85600000 8562d000 rdyboost rdyboost.sys Sat Nov 20 22:00:07 2010 (4CE78E17)
aa0c1000 aa0d4000 rspndr rspndr.sys Tue Jul 14 11:53:20 2009 (4A5BC8F0)
94402000 946a46c0 RTKVHDA RTKVHDA.sys Sat Sep 12 01:44:25 2009 (4AAA5439)
aa000000 aa00a000 secdrv secdrv.SYS Thu Sep 14 01:18:32 2006 (45080528)
8f60f000 8f619000 serenum serenum.sys Tue Jul 14 11:45:27 2009 (4A5BC717)
8e95a000 8e974000 serial serial.sys Tue Jul 14 11:45:33 2009 (4A5BC71D)
857f2000 857fa000 spldr spldr.sys Tue May 12 04:13:47 2009 (4A084EBB)
ae28e000 ae2df000 srv srv.sys Sat Nov 20 21:45:29 2010 (4CE78AA9)
ae23f000 ae28e000 srv2 srv2.sys Sat Nov 20 21:44:35 2010 (4CE78A73)
947be000 947df000 srvnet srvnet.sys Sat Nov 20 21:44:27 2010 (4CE78A6B)
924c8000 924c9380 swenum swenum.sys Tue Jul 14 11:45:08 2009 (4A5BC704)
8562f000 85779000 tcpip tcpip.sys Sat Nov 20 21:41:36 2010 (4CE789C0)
947df000 947ec000 tcpipreg tcpipreg.sys Sat Nov 20 23:07:13 2010 (4CE79DD1)
8e88e000 8e89a000 TDI TDI.SYS Sat Nov 20 21:39:18 2010 (4CE78936)
ae304000 ae30f000 tdtcp tdtcp.sys Sat Nov 20 23:21:10 2010 (4CE7A116)
8e877000 8e88e000 tdx tdx.sys Sat Nov 20 21:39:17 2010 (4CE78935)
8e987000 8e998000 termdd termdd.sys Sat Nov 20 23:21:10 2010 (4CE7A116)
98540000 98549000 TSDDD TSDDD.dll Tue Jul 14 12:01:40 2009 (4A5BCAE4)
ae30f000 ae31c000 tssecsrv tssecsrv.sys Sat Nov 20 23:22:20 2010 (4CE7A15C)
8ee9c000 8eebd000 tunnel tunnel.sys Sat Nov 20 23:06:40 2010 (4CE79DB0)
924fe000 9250c000 umbus umbus.sys Sat Nov 20 23:00:23 2010 (4CE79C37)
94759000 9475a700 USBD USBD.SYS Tue Jul 14 11:51:05 2009 (4A5BC869)
8f600000 8f60f000 usbehci usbehci.sys Sat Nov 20 22:59:43 2010 (4CE79C0F)
9250c000 92550000 usbhub usbhub.sys Sat Nov 20 23:00:34 2010 (4CE79C42)
8ef86000 8efd1000 USBPORT USBPORT.SYS Sat Nov 20 22:59:49 2010 (4CE79C15)
8ffee000 8fff9000 usbuhci usbuhci.sys Tue Jul 14 11:51:10 2009 (4A5BC86E)
85135000 85140000 vdrvroot vdrvroot.sys Tue Jul 14 11:46:19 2009 (4A5BC74B)
8e80c000 8e818000 vga vga.sys Tue Jul 14 11:25:50 2009 (4A5BC27E)
8e818000 8e839000 VIDEOPRT VIDEOPRT.SYS Tue Jul 14 11:25:49 2009 (4A5BC27D)
85000000 85029180 vmbus vmbus.sys Sat Nov 20 22:14:58 2010 (4CE79192)
857aa000 857b2380 vmstorfl vmstorfl.sys Sat Nov 20 22:14:37 2010 (4CE7917D)
85151000 85161000 volmgr volmgr.sys Sat Nov 20 21:38:06 2010 (4CE788EE)
85161000 851ac000 volmgrx volmgrx.sys Tue Jul 14 11:11:41 2009 (4A5BBF2D)
857b3000 857f2000 volsnap volsnap.sys Sat Nov 20 21:38:13 2010 (4CE788F5)
8e974000 8e987000 wanarp wanarp.sys Sat Nov 20 23:07:45 2010 (4CE79DF1)
8e839000 8e846000 watchdog watchdog.sys Tue Jul 14 11:24:10 2009 (4A5BC21A)
85033000 850a4000 Wdf01000 Wdf01000.sys Tue Jul 14 11:11:36 2009 (4A5BBF28)
850a4000 850b2000 WDFLDR WDFLDR.SYS Tue Jul 14 11:11:25 2009 (4A5BBF1D)
8e926000 8e92d000 wfplwf wfplwf.sys Tue Jul 14 11:53:51 2009 (4A5BC90F)
982e0000 9852d000 win32k win32k.sys Wed Jan 05 16:50:40 2011 (4D23EA90)
851d7000 851e9000 winhv winhv.sys Sat Nov 20 21:38:15 2010 (4CE788F7)
850fa000 85103000 WMILIB WMILIB.SYS Tue Jul 14 11:11:22 2009 (4A5BBF1A)
Unloaded modules:
ae34e000 ae3b8000 spsys.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0006A000
9478d000 947a5000 parport.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 00018000
85225000 85232000 crashdmp.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0000D000
855f4000 855ff000 dump_ataport
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0000B000
85432000 8543b000 dump_atapi.s
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 00009000
853e8000 853f9000 dump_dumpfve
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 00011000