Loading Dump File [C:\DUMPS\PivertMe\021011-30154-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16695.amd64fre.win7_gdr.101026-1503
Machine Name:
Kernel base = 0xfffff800`03066000 PsLoadedModuleList = 0xfffff800`032a3e50
Debug session time: Thu Feb 10 19:55:11.862 2011 (UTC + 0:00)
System Uptime: 0 days 0:30:02.173
Loading Kernel Symbols
...............................................................
................................................................
..........................................................
Loading User Symbols
Loading unloaded module list
......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck C4, {91, 2, fffff8000325ec40, 0}
Unable to load image \SystemRoot\system32\DRIVERS\vsdatant.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for vsdatant.sys
*** ERROR: Module load completed but symbols could not be loaded for vsdatant.sys
Probably caused by : vsdatant.sys ( vsdatant+11264 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
A device driver attempting to corrupt the system has been caught. This is
because the driver was specified in the registry as being suspect (by the
administrator) and the kernel has enabled substantial checking of this driver.
If the driver attempts to corrupt the system, bugchecks 0xC4, 0xC1 and 0xA will
be among the most commonly seen crashes.
Arguments:
Arg1: 0000000000000091, A driver switched stacks using a method that is not supported by
the operating system. The only supported way to extend a kernel
mode stack is by using KeExpandKernelStackAndCallout.
Arg2: 0000000000000002
Arg3: fffff8000325ec40
Arg4: 0000000000000000
Debugging Details:
------------------
BUGCHECK_STR: 0xc4_91
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
PROCESS_NAME: System
CURRENT_IRQL: 2
LAST_CONTROL_TRANSFER: from fffff8000312b24a to fffff800030d6740
STACK_TEXT:
fffff800`05114d68 fffff800`0312b24a : 00000000`000000c4 00000000`00000091 00000000`00000002 fffff800`0325ec40 : nt!KeBugCheckEx
fffff800`05114d70 fffff800`03076569 : 00000000`00000000 00000000`00000000 00000000`00000002 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x4904
fffff800`05114db0 fffff800`0307694d : fffff800`05115000 fffff800`0511b000 00000000`00000000 00000000`00000000 : nt!RtlEnoughStackSpaceForStackCapture+0x15
fffff800`05114de0 fffff800`03199c3b : 00000000`00000001 fffffa80`08fa2b90 fffff800`05114f10 00000000`00000000 : nt!RtlWalkFrameChain+0x59
fffff800`05114e10 fffff880`04f5c264 : fffffa80`08fa2b80 fffff880`04faf110 00000000`00000002 00000000`00000000 : nt!RtlCaptureStackBackTrace+0x4b
fffff800`05114e40 fffffa80`08fa2b80 : fffff880`04faf110 00000000`00000002 00000000`00000000 00000000`00000000 : vsdatant+0x11264
fffff800`05114e48 fffff880`04faf110 : 00000000`00000002 00000000`00000000 00000000`00000000 00000000`00000000 : 0xfffffa80`08fa2b80
fffff800`05114e50 00000000`00000002 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : vsdatant+0x64110
fffff800`05114e58 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x2
STACK_COMMAND: kb
FOLLOWUP_IP:
vsdatant+11264
fffff880`04f5c264 ?? ???
SYMBOL_STACK_INDEX: 5
SYMBOL_NAME: vsdatant+11264
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: vsdatant
IMAGE_NAME: vsdatant.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4bdf0b8a
FAILURE_BUCKET_ID: X64_0xc4_91_vsdatant+11264
BUCKET_ID: X64_0xc4_91_vsdatant+11264
Followup: MachineOwner
---------