Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\K\Desktop\Windows_NT6_BSOD_jcgriff2\122510-15787-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols;srv*e:\symbols
*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16617.x86fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0x82a07000 PsLoadedModuleList = 0x82b4f810
Debug session time: Sat Dec 25 23:42:01.039 2010 (GMT-5)
System Uptime: 0 days 5:03:50.771
Loading Kernel Symbols
.
Press ctrl-c (cdb, kd, ntsd) or ctrl-break (windbg) to abort symbol loads that take too long.
Run !sym noisy before .reload to track down problems loading symbols.
..............................................................
................................................................
...........................
Loading User Symbols
Loading unloaded module list
......
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: ba05c000, memory referenced.
Arg2: 00000000, value 0 = read operation, 1 = write operation.
Arg3: 82a218c7, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 00000000, (reserved)
Debugging Details:
------------------
Unable to load image \??\C:\Program Files\Garena\safedrv.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for safedrv.sys
*** ERROR: Module load completed but symbols could not be loaded for safedrv.sys
READ_ADDRESS: GetPointerFromAddress: unable to read from 82b6f718
Unable to read MiSystemVaType memory at 82b4f160
ba05c000
FAULTING_IP:
nt!wcsrchr+a
82a218c7 668b08 mov cx,word ptr [eax]
MM_INTERNAL_CODE: 0
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: Garena.exe
CURRENT_IRQL: 0
TRAP_FRAME: a10cda50 -- (.trap 0xffffffffa10cda50)
ErrCode = 00000000
eax=ba05c000 ebx=00000001 ecx=00008671 edx=ba05bf58 esi=00000050 edi=ba05bf58
eip=82a218c7 esp=a10cdac4 ebp=a10cdac4 iopl=0 nv up ei ng nz na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010286
nt!wcsrchr+0xa:
82a218c7 668b08 mov cx,word ptr [eax] ds:0023:ba05c000=????
Resetting default scope
LAST_CONTROL_TRANSFER: from 82a4d638 to 82a8c903
STACK_TEXT:
a10cda38 82a4d638 00000000 ba05c000 00000000 nt!MmAccessFault+0x106
a10cda38 82a218c7 00000000 ba05c000 00000000 nt!KiTrap0E+0xdc
a10cdac4 9f1b22e6 ba05bf58 0000005c 000016a0 nt!wcsrchr+0xa
WARNING: Stack unwind information not available. Following frames may be wrong.
a10cdb00 9f1b21a4 873cb938 a10cdb64 a9a23bd8 safedrv+0x12e6
a10cdb14 82c87187 873cb938 000016a0 a10cdb64 safedrv+0x11a4
a10cdb3c 82c5cbc6 873cb938 000016a0 82b47b08 nt!PsCallImageNotifyRoutines+0x62
a10cdbe8 82c75979 8748a008 871b5d40 a10cdce4 nt!MiMapViewOfImageSection+0x7fd
a10cdc58 82c86241 871b5d40 a10cdce4 00000000 nt!MiMapViewOfSection+0x22e
a10cdc88 82c8616c 99064a70 871b5d40 a10cdce4 nt!MmMapViewOfSection+0x2a
a10cdd04 82a4a44a 00000184 ffffffff 0012f15c nt!NtMapViewOfSection+0x204
a10cdd04 778a64f4 00000184 ffffffff 0012f15c nt!KiFastCallEntry+0x12a
0012f0c8 00000000 00000000 00000000 00000000 0x778a64f4
STACK_COMMAND: kb
FOLLOWUP_IP:
safedrv+12e6
9f1b22e6 ?? ???
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: safedrv+12e6
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: safedrv
IMAGE_NAME: safedrv.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4cc511dc
FAILURE_BUCKET_ID: 0x50_safedrv+12e6
BUCKET_ID: 0x50_safedrv+12e6
Followup: MachineOwner
---------