*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {fffff80004424598, 0, fffff800034097d0, 0}
Could not read faulting driver name
Probably caused by : ntkrnlmp.exe ( nt! ?? ::FNODOBFM::`string'+4518f )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: fffff80004424598, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff800034097d0, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000000, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800030c2100
GetUlongFromAddress: unable to read from fffff800030c21c0
fffff80004424598 Nonpaged pool
FAULTING_IP:
hal!KeQueryPerformanceCounter+dc
fffff800`034097d0 8b0dc2ad0100 mov ecx,dword ptr [hal!HalpQueryPerformanceCounterOriginalSource (fffff800`03424598)]
MM_INTERNAL_CODE: 0
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: System
CURRENT_IRQL: 0
TAG_NOT_DEFINED_c000000f: FFFFF88002F94FB0
TRAP_FRAME: fffff88002f8d9a0 -- (.trap 0xfffff88002f8d9a0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=000000965fd7500f rbx=0000000000000000 rcx=0000010381738f0a
rdx=0002587b00000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff800034097d0 rsp=fffff88002f8db30 rbp=0000000000000000
r8=0000000000000000 r9=00000000003a21c8 r10=000000000002ab34
r11=fffff88002f65100 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz ac po nc
hal!KeQueryPerformanceCounter+0xdc:
fffff800`034097d0 8b0dc2ad0100 mov ecx,dword ptr [hal!HalpQueryPerformanceCounterOriginalSource (fffff800`03424598)] ds:fffff800`03424598=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002f08bf0 to fffff80002e8abc0
STACK_TEXT:
fffff880`02f8d838 fffff800`02f08bf0 : 00000000`00000050 fffff800`04424598 00000000`00000000 fffff880`02f8d9a0 : nt!KeBugCheckEx
fffff880`02f8d840 fffff800`02e88cee : 00000000`00000000 fffff800`04424598 fffff800`02e95f00 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x4518f
fffff880`02f8d9a0 fffff800`034097d0 : 00000000`00000010 00000000`00000246 fffff880`02f8db58 00000000`00000018 : nt!KiPageFault+0x16e
fffff880`02f8db30 fffff800`02e93786 : 00000000`003a21c8 00000000`00000000 fffff880`02f700c0 00000000`00000001 : hal!KeQueryPerformanceCounter+0xdc
fffff880`02f8db60 fffff800`02e8289c : fffff880`02f65180 fffff880`00000000 00000000`00000000 fffff880`04455480 : nt!PoIdle+0x5a7
fffff880`02f8dc40 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x2c
STACK_COMMAND: kb
FOLLOWUP_IP:
nt! ?? ::FNODOBFM::`string'+4518f
fffff800`02f08bf0 cc int 3
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt! ?? ::FNODOBFM::`string'+4518f
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 521ea035
FAILURE_BUCKET_ID: X64_0x50_nt!_??_::FNODOBFM::_string_+4518f
BUCKET_ID: X64_0x50_nt!_??_::FNODOBFM::_string_+4518f
Followup: MachineOwner
---------