Windows 7 Kernel Version 7600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16617.amd64fre.win7_gdr.100618-1621
Machine Name:
Kernel base = 0xfffff800`02a4a000 PsLoadedModuleList = 0xfffff800`02c87e50
Debug session time: Tue Feb 8 23:37:23.477 2011 (GMT-8)
System Uptime: 0 days 0:00:15.991
Loading Kernel Symbols
...............................................................
......................
Loading User Symbols
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck C5, {fffff8a0007a99b8, 2, 1, fffff80002beda68}
Probably caused by : Pool_Corruption ( nt!ExDeferredFreePool+16b5 )
Followup: Pool_corruption
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_CORRUPTED_EXPOOL (c5)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is
caused by drivers that have corrupted the system pool. Run the driver
verifier against any new (or suspect) drivers, and if that doesn't turn up
the culprit, then use gflags to enable special pool.
Arguments:
Arg1: fffff8a0007a99b8, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000001, value 0 = read operation, 1 = write operation
Arg4: fffff80002beda68, address which referenced memory
Debugging Details:
------------------
BUGCHECK_STR: 0xC5_2
CURRENT_IRQL: 2
FAULTING_IP:
nt!ExDeferredFreePool+16b5
fffff800`02beda68 48895008 mov qword ptr [rax+8],rdx
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VERIFIER_ENABLED_VISTA_MINIDUMP
PROCESS_NAME: System
TRAP_FRAME: fffff880031a00d0 -- (.trap 0xfffff880031a00d0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffff8a0007a99b0 rbx=0000000000000000 rcx=fffffa80039772e0
rdx=fffff8a00079a670 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002beda68 rsp=fffff880031a0260 rbp=0000000000000000
r8=0000000000000001 r9=0000000000000060 r10=fffff80002a4a000
r11=000000000000045c r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na pe nc
nt!ExDeferredFreePool+0x16b5:
fffff800`02beda68 48895008 mov qword ptr [rax+8],rdx ds:a670:fffff8a0`007a99b8=fffffa80039772e0
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002ab9ca9 to fffff80002aba740
STACK_TEXT:
fffff880`0319ff88 fffff800`02ab9ca9 : 00000000`0000000a fffff8a0`007a99b8 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
fffff880`0319ff90 fffff800`02ab8920 : 00000000`00000000 fffff8a0`0079a660 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
fffff880`031a00d0 fffff800`02beda68 : fffff8a0`0079a670 00000000`00000060 00000000`00000003 00000000`00000001 : nt!KiPageFault+0x260
fffff880`031a0260 fffff880`00ce6c53 : fffff980`03a000f0 00000000`00000000 00000000`63734943 0000000a`0000045b : nt!ExDeferredFreePool+0x16b5
fffff880`031a0310 fffff880`00ce6281 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : CI!CipImageGetImageHash+0x42b
fffff880`031a04f0 fffff880`00ce4fbb : 00000000`00000001 fffff880`031a07b0 fffff880`031a07b0 80000000`00000020 : CI!CipValidateFileHash+0x211
fffff880`031a0660 fffff800`02d2568e : 00000000`00000056 00000000`000fffff fffffa80`064d0f20 00000000`00000000 : CI!CiValidateImageHeader+0x213
fffff880`031a0740 fffff800`02d2557c : 00000000`00000001 00000000`01000000 fffffa80`064d0920 00000000`00000000 : nt!SeValidateImageHeader+0x2e
fffff880`031a0780 fffff800`02db5d95 : fffffa80`064d0f20 fffffa80`064d0920 00000000`00000001 00000000`00000056 : nt!MiValidateImageHeader+0xa4
fffff880`031a0840 fffff800`02dab013 : fffff880`031a0aa0 00000000`00000000 fffff880`031a0d58 00000000`00000001 : nt!MmCreateSection+0x8c9
fffff880`031a0a50 fffff800`02ab9993 : fffffa80`04605040 fffff880`031a0cf8 fffff880`031a0ae8 00000000`00000000 : nt!NtCreateSection+0x162
fffff880`031a0ad0 fffff800`02ab5f30 : fffff800`02e938b6 fffffa80`04605040 00000000`00000000 00000000`00000004 : nt!KiSystemServiceCopyEnd+0x13
fffff880`031a0cd8 fffff800`02e938b6 : fffffa80`04605040 00000000`00000000 00000000`00000004 00000000`0000002c : nt!KiServiceLinkage
fffff880`031a0ce0 fffff800`02e93c7c : ffffffff`8000022c 00000000`00100000 00000000`00000001 fffff800`02ab893d : nt!MmCheckSystemImage+0x96
fffff880`031a0e10 fffff800`02e93e97 : ffffffff`8000022c 00001f80`00000001 fffff8a0`006afc40 00000000`00000000 : nt!MiCreateSectionForDriver+0xcc
fffff880`031a0ec0 fffff800`02e9f73a : 00000000`00000000 fffff880`031a1080 fffffa80`04605040 00000000`00000000 : nt!MiObtainSectionForDriver+0xd7
fffff880`031a0f20 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MmLoadSystemImage+0x23a
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!ExDeferredFreePool+16b5
fffff800`02beda68 48895008 mov qword ptr [rax+8],rdx
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: nt!ExDeferredFreePool+16b5
FOLLOWUP_NAME: Pool_corruption
IMAGE_NAME: Pool_Corruption
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MODULE_NAME: Pool_Corruption
FAILURE_BUCKET_ID: X64_0xC5_2_VRF_nt!ExDeferredFreePool+16b5
BUCKET_ID: X64_0xC5_2_VRF_nt!ExDeferredFreePool+16b5
Followup: Pool_corruption
---------
2: kd> lmvm CI
start end module name
fffff880`00cda000 fffff880`00d9a000 CI (pdb symbols) c:\windows\symbols\ci.pdb\5F1BDC2205AC402CB0F09FC7CF17A3701\ci.pdb
Loaded symbol image file: CI.dll
Mapped memory image file: C:\Windows\Symbols\CI.dll\4A5BE01Dc0000\CI.dll
Image path: \SystemRoot\system32\CI.dll
Image name: CI.dll
Timestamp: Mon Jul 13 18:32:13 2009 (4A5BE01D)
CheckSum: 000C6E0E
ImageSize: 000C0000
File version: 6.1.7600.16385
Product version: 6.1.7600.16385
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: ci.dll
OriginalFilename: ci.dll
ProductVersion: 6.1.7600.16385
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
FileDescription: Code Integrity Module
LegalCopyright: © Microsoft Corporation. All rights reserved.