Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\Yusra\Downloads\Olban_Minidump_091112\091112-51776-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 7601.17835.amd64fre.win7sp1_gdr.120503-2030
Machine Name:
Kernel base = 0xfffff800`0344d000 PsLoadedModuleList = 0xfffff800`03691670
Debug session time: Tue Sep 11 19:09:06.538 2012 (UTC + 6:00)
System Uptime: 0 days 0:01:05.537
Loading Kernel Symbols
...............................................................
................................................................
...............................................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
[COLOR="Red"]BugCheck C4[/COLOR], {f6, 180, fffffa8009f02b30, fffff88005bde234}
Unable to load image \SystemRoot\system32\DRIVERS\SaiH8000.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for SaiH8000.sys
*** ERROR: Module load completed but symbols could not be loaded for SaiH8000.sys
Probably caused by :[COLOR="red"] SaiH8000.sys ( SaiH8000+26234 )[/COLOR]
Followup: MachineOwner
---------
4: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
[COLOR="red"]DRIVER_VERIFIER_DETECTED_VIOLATION (c4)[/COLOR]
A device driver attempting to corrupt the system has been caught. This is
because the driver was specified in the registry as being suspect (by the
administrator) and the kernel has enabled substantial checking of this driver.
If the driver attempts to corrupt the system, bugchecks 0xC4, 0xC1 and 0xA will
be among the most commonly seen crashes.
Arguments:
Arg1: 00000000000000f6, Referencing user handle as KernelMode.
Arg2: 0000000000000180, Handle value being referenced.
Arg3: fffffa8009f02b30, Address of the current process.
Arg4: fffff88005bde234, Address inside the driver that is performing the incorrect reference.
Debugging Details:
------------------
BUGCHECK_STR: 0xc4_f6
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VERIFIER_ENABLED_VISTA_MINIDUMP
PROCESS_NAME: BTTray.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff800039523dc to fffff800034cc1c0
STACK_TEXT:
fffff880`09b99e18 fffff800`039523dc : 00000000`000000c4 00000000`000000f6 00000000`00000180 fffffa80`09f02b30 : nt!KeBugCheckEx
fffff880`09b99e20 fffff800`03967ae4 : 00000000`00000180 fffffa80`09f02b30 00000000`00000004 00000000`00000000 : nt!VerifierBugCheckIfAppropriate+0x3c
fffff880`09b99e60 fffff800`0371eff0 : fffff6fc`00000000 fffff880`09b9a0b0 fffff880`09b9a200 fffff880`09b9a438 : nt!VfCheckUserHandle+0x1b4
fffff880`09b99f40 fffff800`03798c15 : 00000000`00000000 fffff800`00000001 fffffa80`06d5fa40 fffff6fc`4002de00 : nt! ?? ::NNGAKEGL::`string'+0x212ce
fffff880`09b9a010 fffff800`034cb453 : fffffa80`09f06a50 fffff880`09b9a3c8 00000000`00000002 fffff880`09b9a450 : nt!NtQueryValueKey+0x115
fffff880`09b9a1a0 fffff800`034c7a10 : fffff800`03956c86 fffff880`05bde234 fffff880`09b9a438 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
fffff880`09b9a3a8 fffff800`03956c86 : fffff880`05bde234 fffff880`09b9a438 00000000`00000000 00000000`00000000 : nt!KiServiceLinkage
fffff880`09b9a3b0 fffff880`05bde234 : fffff880`09b9a500 fffff880`09b9a568 fffff880`09b9a500 fffffa80`12a496c0 : nt!VfZwQueryValueKey+0x76
fffff880`09b9a400 fffff880`09b9a500 : fffff880`09b9a568 fffff880`09b9a500 fffffa80`12a496c0 00000000`0000000c : SaiH8000+0x26234
fffff880`09b9a408 fffff880`09b9a568 : fffff880`09b9a500 fffffa80`12a496c0 00000000`0000000c fffff880`09b9a430 : 0xfffff880`09b9a500
fffff880`09b9a410 fffff880`09b9a500 : fffffa80`12a496c0 00000000`0000000c fffff880`09b9a430 fffffa80`12a497a0 : 0xfffff880`09b9a568
fffff880`09b9a418 fffffa80`12a496c0 : 00000000`0000000c fffff880`09b9a430 fffffa80`12a497a0 fffffa80`00080006 : 0xfffff880`09b9a500
fffff880`09b9a420 00000000`0000000c : fffff880`09b9a430 fffffa80`12a497a0 fffffa80`00080006 fffff880`05bd7f98 : 0xfffffa80`12a496c0
fffff880`09b9a428 fffff880`09b9a430 : fffffa80`12a497a0 fffffa80`00080006 fffff880`05bd7f98 fffffa80`10d6ac00 : 0xc
fffff880`09b9a430 fffffa80`12a497a0 : fffffa80`00080006 fffff880`05bd7f98 fffffa80`10d6ac00 00000000`00000000 : 0xfffff880`09b9a430
fffff880`09b9a438 fffffa80`00080006 : fffff880`05bd7f98 fffffa80`10d6ac00 00000000`00000000 fffff800`0395dbb0 : 0xfffffa80`12a497a0
fffff880`09b9a440 fffff880`05bd7f98 : fffffa80`10d6ac00 00000000`00000000 fffff800`0395dbb0 ffff0000`0c0400e6 : 0xfffffa80`00080006
fffff880`09b9a448 fffffa80`10d6ac00 : 00000000`00000000 fffff800`0395dbb0 ffff0000`0c0400e6 fffff800`0395dd1b : SaiH8000+0x1ff98
fffff880`09b9a450 00000000`00000000 : fffff800`0395dbb0 ffff0000`0c0400e6 fffff800`0395dd1b fffff880`09b9a560 : 0xfffffa80`10d6ac00
STACK_COMMAND: kb
FOLLOWUP_IP:
SaiH8000+26234
fffff880`05bde234 488b4c2440 mov rcx,qword ptr [rsp+40h]
SYMBOL_STACK_INDEX: 8
SYMBOL_NAME: SaiH8000+26234
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: SaiH8000
IMAGE_NAME: SaiH8000.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 47f6106a
FAILURE_BUCKET_ID: X64_0xc4_f6_VRF_SaiH8000+26234
BUCKET_ID: X64_0xc4_f6_VRF_SaiH8000+26234
Followup: MachineOwner
---------
4: kd> lmvm SaiH8000
start end module name
fffff880`05bb8000 fffff880`05be2480 SaiH8000 T (no symbols)
Loaded symbol image file: SaiH8000.sys
Image path: \SystemRoot\system32\DRIVERS\SaiH8000.sys
Image name: SaiH8000.sys
Timestamp: [COLOR="red"] Fri Apr 04 17:26:34 2008 (47F6106A)[/COLOR]
CheckSum: 00035E44
ImageSize: 0002A480
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4