*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {ffffffffffffffe9, 0, fffff800031aa465, 0}
Unable to load image \SystemRoot\system32\DRIVERS\tdrpm251.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for tdrpm251.sys
*** ERROR: Module load completed but symbols could not be loaded for tdrpm251.sys
Could not read faulting driver name
[B]Probably caused by : tdrpm251.sys [/B]( tdrpm251+4c0c8 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: ffffffffffffffe9, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff800031aa465, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000000, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800030fc0e0
ffffffffffffffe9
FAULTING_IP:
nt!ObpQueryNameString+51
fffff800`031aa465 410fb64718 movzx eax,byte ptr [r15+18h]
MM_INTERNAL_CODE: 0
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 0
TRAP_FRAME: fffff88007037fb0 -- (.trap 0xfffff88007037fb0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffff88007038238 rbx=0000000000000000 rcx=0000000000000001
rdx=fffffa8003c242b0 rsi=0000000000000000 rdi=0000000000000000
rip=fffff800031aa465 rsp=fffff88007038140 rbp=0000000000000001
r8=0000000000000080 r9=fffff880070382a0 r10=fffff8000303fa00
r11=fffff88001c313c0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
nt!ObpQueryNameString+0x51:
fffff800`031aa465 410fb64718 movzx eax,byte ptr [r15+18h] ds:0bf0:00000000`00000018=??
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002f44f14 to fffff80002ec4740
STACK_TEXT:
fffff880`07037e48 fffff800`02f44f14 : 00000000`00000050 ffffffff`ffffffe9 00000000`00000000 fffff880`07037fb0 : nt!KeBugCheckEx
fffff880`07037e50 fffff800`02ec282e : 00000000`00000000 00000000`00000000 fffffa80`039cf900 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x42837
fffff880`07037fb0 fffff800`031aa465 : fffffa80`06969c90 fffff800`02ff92dd 00000000`00000000 fffff800`02ff84d3 : nt!KiPageFault+0x16e
fffff880`07038140 fffff800`031ab56a : 00000000`00000001 fffffa80`03c242b0 fffffa80`00000080 fffff880`070382a0 : nt!ObpQueryNameString+0x51
fffff880`07038240 fffff880`01c760c8 : fffff880`00000009 00000000`00000001 00000000`00000001 00000000`00000000 : nt!ObQueryNameString+0xe
fffff880`07038280 fffff880`00000009 : 00000000`00000001 00000000`00000001 00000000`00000000 00000000`00000080 : tdrpm251+0x4c0c8
fffff880`07038288 00000000`00000001 : 00000000`00000001 00000000`00000000 00000000`00000080 fffff880`070383a0 : 0xfffff880`00000009
fffff880`07038290 00000000`00000001 : 00000000`00000000 00000000`00000080 fffff880`070383a0 fffffa80`06969c10 : 0x1
fffff880`07038298 00000000`00000000 : 00000000`00000080 fffff880`070383a0 fffffa80`06969c10 fffff880`01c7da0b : 0x1
STACK_COMMAND: kb
FOLLOWUP_IP:
tdrpm251+4c0c8
fffff880`01c760c8 ?? ???
SYMBOL_STACK_INDEX: 5
SYMBOL_NAME: tdrpm251+4c0c8
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: tdrpm251
IMAGE_NAME: tdrpm251.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4a72f8d9
FAILURE_BUCKET_ID: X64_0x50_tdrpm251+4c0c8
BUCKET_ID: X64_0x50_tdrpm251+4c0c8
Followup: MachineOwner
---------
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fffff80002f5d48c, fffff88007b08770, 0}
Probably caused by : ntkrnlmp.exe ( nt!ObpQueryNameString+78 )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff80002f5d48c, Address of the exception record for the exception that caused the bugcheck
Arg3: fffff88007b08770, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!ObpQueryNameString+78
fffff800`02f5d48c 4d8b92a0000000 mov r10,qword ptr [r10+0A0h]
CONTEXT: fffff88007b08770 -- (.cxr 0xfffff88007b08770)
rax=0000000000000001 rbx=0000000000000000 rcx=fffffa80067d0130
rdx=fffffa8006ab2ce0 rsi=0000000000000001 rdi=0000000000000000
rip=fffff80002f5d48c rsp=fffff88007b09140 rbp=fffffa80067d0130
r8=0000000000000080 r9=fffff88007b092a0 r10=00000000bad0b0b0
r11=fffff88001c9e3c0 r12=0000000000000000 r13=fffff80002c07000
r14=fffffa8006ab2ce0 r15=fffffa80067d0100
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010246
nt!ObpQueryNameString+0x78:
fffff800`02f5d48c 4d8b92a0000000 mov r10,qword ptr [r10+0A0h] ds:002b:00000000`bad0b150=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff80002f5d48c
STACK_TEXT:
fffff880`07b09140 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!ObpQueryNameString+0x78
FOLLOWUP_IP:
nt!ObpQueryNameString+78
fffff800`02f5d48c 4d8b92a0000000 mov r10,qword ptr [r10+0A0h]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!ObpQueryNameString+78
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
STACK_COMMAND: .cxr 0xfffff88007b08770 ; kb
FAILURE_BUCKET_ID: X64_0x3B_nt!ObpQueryNameString+78
BUCKET_ID: X64_0x3B_nt!ObpQueryNameString+78
Followup: MachineOwner
---------
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fffff80002fbe48c, fffff880078aa770, 0}
Probably caused by : ntkrnlmp.exe ( nt!ObpQueryNameString+78 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff80002fbe48c, Address of the exception record for the exception that caused the bugcheck
Arg3: fffff880078aa770, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!ObpQueryNameString+78
fffff800`02fbe48c 4d8b92a0000000 mov r10,qword ptr [r10+0A0h]
CONTEXT: fffff880078aa770 -- (.cxr 0xfffff880078aa770)
rax=0000000000000001 rbx=0000000000000000 rcx=fffffa8006698e50
rdx=fffffa800678d260 rsi=0000000000000001 rdi=0000000000000000
rip=fffff80002fbe48c rsp=fffff880078ab140 rbp=fffffa8006698e50
r8=0000000000000080 r9=fffff880078ab2a0 r10=00000000bad0b0b0
r11=fffff88001c553c0 r12=0000000000000000 r13=fffff80002c68000
r14=fffffa800678d260 r15=fffffa8006698e20
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010246
nt!ObpQueryNameString+0x78:
fffff800`02fbe48c 4d8b92a0000000 mov r10,qword ptr [r10+0A0h] ds:002b:00000000`bad0b150=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: svchost.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff80002fbe48c
STACK_TEXT:
fffff880`078ab140 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!ObpQueryNameString+0x78
FOLLOWUP_IP:
nt!ObpQueryNameString+78
fffff800`02fbe48c 4d8b92a0000000 mov r10,qword ptr [r10+0A0h]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!ObpQueryNameString+78
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c44a9
STACK_COMMAND: .cxr 0xfffff880078aa770 ; kb
FAILURE_BUCKET_ID: X64_0x3B_nt!ObpQueryNameString+78
BUCKET_ID: X64_0x3B_nt!ObpQueryNameString+78
Followup: MachineOwner
---------