*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {fffffa804b7ce6b8, 0, fffff80003f0ff0a, 5}
[B][COLOR=darkred]Could not read faulting driver name[/COLOR][/B]
[B][COLOR=darkred]Probably caused by : memory_corruption ( nt!MiGetNextNode+2e )[/COLOR][/B]
[B][COLOR=darkred]Followup: MachineOwner[/COLOR][/B]
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: fffffa804b7ce6b8, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff80003f0ff0a, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000005, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80004115100
fffffa804b7ce6b8
FAULTING_IP:
nt!MiGetNextNode+2e
fffff800`03f0ff0a 488b4908 mov rcx,qword ptr [rcx+8]
MM_INTERNAL_CODE: 5
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
[B][COLOR=red]PROCESS_NAME: TobuActivation[/COLOR][/B]
CURRENT_IRQL: 0
TRAP_FRAME: fffff8800a2ce680 -- (.trap 0xfffff8800a2ce680)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffffa804b7ce6b0 rbx=0000000000000000 rcx=fffffa804b7ce6b0
rdx=fffffa800a222b2a rsi=0000000000000000 rdi=0000000000000000
rip=fffff80003f0ff0a rsp=fffff8800a2ce818 rbp=fffffa800b5e9660
r8=000000000000000b r9=0000000000006f8c r10=0000000000000000
r11=fffff8800a2ce700 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na pe nc
nt!MiGetNextNode+0x2e:
fffff800`03f0ff0a 488b4908 mov rcx,qword ptr [rcx+8] ds:fffffa80`4b7ce6b8=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80003f5a5b3 to fffff80003eddbc0
STACK_TEXT:
fffff880`0a2ce518 fffff800`03f5a5b3 : 00000000`00000050 fffffa80`4b7ce6b8 00000000`00000000 fffff880`0a2ce680 : nt!KeBugCheckEx
fffff880`0a2ce520 fffff800`03edbcee : 00000000`00000000 fffffa80`4b7ce6b8 00000000`00000000 fffffa80`0beb4a00 : nt! ?? ::FNODOBFM::`string'+0x43801
fffff880`0a2ce680 fffff800`03f0ff0a : fffff800`04278490 00000000`00000001 fffffa80`0beb4a00 00000000`00000080 : nt!KiPageFault+0x16e
fffff880`0a2ce818 fffff800`04278490 : 00000000`00000001 fffffa80`0beb4a00 00000000`00000080 00000000`000007ff : nt!MiGetNextNode+0x2e
fffff880`0a2ce820 fffff800`04137ac8 : fffffa80`0befd990 fffff880`0a2ce900 00000000`00000000 00000000`000000d0 : nt!MmEnumerateAndReferenceImages+0x160
fffff880`0a2ce8a0 fffff800`041960fe : fffffa80`0befd990 00000000`00000000 fffffa80`0beb4a00 fffffa80`0befdaf0 : nt! ?? ::NNGAKEGL::`string'+0x204c9
fffff880`0a2cea40 fffff800`041b20d9 : 00000000`7efdb000 00000000`00000001 00000000`00000000 00000000`00000000 : nt!PspExitProcess+0x4e
fffff880`0a2ceaa0 fffff800`041966b8 : 00000000`00000000 00000000`00000001 00000000`7efdb000 00000000`00000000 : nt!PspExitThread+0x4e9
fffff880`0a2ceba0 fffff800`03edce53 : fffffa80`0befd990 00000000`00000000 fffffa80`0beb4a00 00000000`005e2dd8 : nt!NtTerminateProcess+0x138
fffff880`0a2cec20 00000000`7700157a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0008dcb8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7700157a
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!MiGetNextNode+2e
fffff800`03f0ff0a 488b4908 mov rcx,qword ptr [rcx+8]
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: nt!MiGetNextNode+2e
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 521ea035
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: X64_0x50_nt!MiGetNextNode+2e
BUCKET_ID: X64_0x50_nt!MiGetNextNode+2e
Followup: MachineOwner