Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\Owner\Downloads\081510-65953-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\symbols*[URL="http://msdl.microsoft.com/download/symbols"]Symbol information[/URL]
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16385.x86fre.win7_rtm.090713-1255
Machine Name:
Kernel base = 0x82c07000 PsLoadedModuleList = 0x82d4f810
Debug session time: Sun Aug 15 11:57:13.270 2010 (GMT-4)
System Uptime: 0 days 0:04:32.411
Loading Kernel Symbols
...............................................................
................................................................
...............................
Loading User Symbols
Loading unloaded module list
......
1: kd> !Analyze
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck C4, {f6, 644, 873edd40, a0266e76}
*** WARNING: Unable to verify timestamp for 3xHybrid.sys
*** ERROR: Module load completed but symbols could not be loaded for 3xHybrid.sys
Probably caused by : 3xHybrid.sys ( 3xHybrid+183d9 )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
A device driver attempting to corrupt the system has been caught. This is
because the driver was specified in the registry as being suspect (by the
administrator) and the kernel has enabled substantial checking of this driver.
If the driver attempts to corrupt the system, bugchecks 0xC4, 0xC1 and 0xA will
be among the most commonly seen crashes.
Arguments:
Arg1: 000000f6, Referencing user handle as KernelMode.
Arg2: 00000644, Handle value being referenced.
Arg3: 873edd40, Address of the current process.
Arg4: a0266e76, Address inside the driver that is performing the incorrect reference.
Debugging Details:
------------------
BUGCHECK_STR: 0xc4_f6
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VERIFIER_ENABLED_VISTA_MINIDUMP
PROCESS_NAME: ADTV.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 82f3bf03 to 82ce3d10
STACK_TEXT:
b8781504 82f3bf03 000000c4 000000f6 00000644 nt!KeBugCheckEx+0x1e
b8781524 82f40766 00000644 873edd40 873eda58 nt!VerifierBugCheckIfAppropriate+0x30
b87815b8 82e2b26c 00000000 00000002 00000000 nt!VfCheckUserHandle+0x14f
b87815ec 82e2b126 00000644 00000001 847d9bd8 nt!ObReferenceObjectByHandleWithTag+0x13b
b8781610 82e82cb0 00000644 00000001 847d9bd8 nt!ObReferenceObjectByHandle+0x21
b8781634 82e8282c 00000644 00000001 b8781600 nt!CmObReferenceObjectByHandle+0x21
b87816e0 82c4a42a 00000644 b878179c 00000002 nt!NtQueryValueKey+0x11e
b87816e0 82c48e6d 00000644 b878179c 00000002 nt!KiFastCallEntry+0x12a
b8781770 a023a3d9 00000644 b878179c 00000002 nt!ZwQueryValueKey+0x11
WARNING: Stack unwind information not available. Following frames may be wrong.
b87817c8 a0266e76 a0266b5c b8781800 a0266b54 3xHybrid+0x183d9
b8781804 a02673c0 9ff0d6e0 89a52008 863dd460 3xHybrid+0x44e76
b8781850 a0224e69 89aa2388 8623dc48 89aa2348 3xHybrid+0x453c0
b878186c a02e752f 89aa2388 8623dc48 00000000 3xHybrid+0x2e69
b878188c a02e90e9 8623dc48 00000003 a02e1f20 ks!KspCreate+0xe0
b8781904 a02e950a 8623dc48 89a7203c 873c0010 ks!CKsPin::Init+0x472
b878193c a02e8c42 8623dc48 89a7203c 873c0010 ks!KspCreatePin+0x98
b8781980 a02e6a9a 86f9e9e8 8623dc48 00000000 ks!CKsFilter::DispatchCreatePin+0xb9
b87819a4 a02e65e7 86f9e9e8 00000000 89a1fba0 ks!DispatchCreate+0xe0
b87819c0 82f366c3 86f9e9e8 8623dc48 8623dd1c ks!CKsDevice::DispatchCreate+0x115
b87819e4 82c43473 00000000 8623dd40 86f9e9e8 nt!IovCallDriver+0x258
b87819f8 82f483d0 873e3890 8623dc48 86f9e420 nt!IofCallDriver+0x1b
b8781a10 82f366c3 86f9e4d8 8623dc48 aabf8f80 nt!ViFilterDispatchGeneric+0x5e
b8781a34 82c43473 00000000 aabf8fdc 86f9e420 nt!IovCallDriver+0x258
b8781a48 82e4762d 91ef8583 873e4860 89a0f008 nt!IofCallDriver+0x1b
b8781b20 82e91031 86f9e420 847e7eb0 89aa3410 nt!IopParseDevice+0xed7
b8781b60 82e281d7 873e4860 847e7eb0 89aa3410 nt!IopParseFile+0x51
b8781bdc 82e4e24d 000004e4 b8781c30 00000040 nt!ObpLookupObjectName+0x4fa
b8781c38 82e465ab 00aeced4 847e7eb0 873c6c01 nt!ObOpenObjectByName+0x159
b8781cb4 82e51eb6 01dabcd4 80000000 00aeced4 nt!IopCreateFile+0x673
b8781d00 82c4a42a 01dabcd4 80000000 00aeced4 nt!NtCreateFile+0x34
b8781d00 76fe64f4 01dabcd4 80000000 00aeced4 nt!KiFastCallEntry+0x12a
00aecf00 00000000 00000000 00000000 00000000 0x76fe64f4
STACK_COMMAND: kb
FOLLOWUP_IP:
3xHybrid+183d9
a023a3d9 ?? ???
SYMBOL_STACK_INDEX: 9
SYMBOL_NAME: 3xHybrid+183d9
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: 3xHybrid
IMAGE_NAME: 3xHybrid.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 45b69ec0
FAILURE_BUCKET_ID: 0xc4_f6_VRF_3xHybrid+183d9
BUCKET_ID: 0xc4_f6_VRF_3xHybrid+183d9
Followup: MachineOwner
---------