3: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * *******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50) Invalid system memory was referenced. This cannot be protected by try-except, it must be protected by a Probe. Typically the address is just plain bad or it is pointing at freed memory. Arguments: Arg1: ffffffff80000ad8, memory referenced. Arg2: 0000000000000000, value 0 = read operation, 1 = write operation. Arg3: fffff800041a80f3, If non-zero, the instruction address which referenced the bad memory address. Arg4: 0000000000000005, (reserved)
Debugging Details: ------------------
***** Kernel symbols are WRONG. Please fix symbols to do analysis.
************************************************************************* *** *** *** *** *** Your debugger is not using the correct symbols *** *** *** *** In order for this command to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: nt!_KPRCB *** *** *** ************************************************************************* 。 。 。
ADDITIONAL_DEBUG_TEXT: Use '!findthebuild' command to search for the target build information. If the build information is available, run '!findthebuild -s ; .reload' to set symbol path and load symbols.
MODULE_NAME: myfs
FAULTING_MODULE: fffff80004003000 nt
DEBUG_FLR_IMAGE_TIMESTAMP: 4ffa5638
READ_ADDRESS: ffffffff80000ad8
FAULTING_IP: nt!ExFreePoolWithTag+43 fffff800`041a80f3 418b45f0 mov eax,dword ptr [r13-10h]
MM_INTERNAL_CODE: 5
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from fffff800040f2b91 to fffff80004074f00
STACK_TEXT: fffff880`05cd8f98 fffff800`040f2b91 : 00000000`00000050 ffffffff`80000ad8 00000000`00000000 fffff880`05cd9100 : nt!KeBugCheckEx fffff880`05cd8fa0 fffff800`04072fee : 00000000`00000000 00000000`00000800 00000000`00000000 00000000`00000000 : nt!wcsncat_s+0x2d3a9 fffff880`05cd9100 fffff800`041a80f3 : 00000000`00000020 00000000`00000000 00000000`00000001 fffff880`05cd9300 : nt!KeSynchronizeExecution+0x28de fffff880`05cd9290 fffff880`0513f4c0 : fffffa80`06fdecf0 00000000`00000080 fffffa80`474c444c 00000000`0000042f : nt!ExFreePoolWithTag+0x43 fffff880`05cd9340 fffff880`05171223 : fffff880`05194fa0 00000000`c0000011 00000000`00000000 00000000`00000000 : myfs+0xe4c0 fffff880`05cd94d0 fffff880`0518e859 : fffffa80`0717fa80 fffffa80`07426430 fffffa80`0717fa80 00000000`00000000 : myfs+0x40223 fffff880`05cd9500 fffff880`05179b60 : fffff8a0`035d6710 fffffa80`07426548 fffffa80`07426430 fffff880`00000000 : myfs+0x5d859 fffff880`05cd9560 fffff880`0517a919 : fffffa80`0717fa80 fffffa80`07426430 00000000`00000001 00000000`00000001 : myfs+0x48b60 fffff880`05cd95b0 fffff880`05144f87 : fffffa80`0717fa80 fffffa80`07426430 fffffa80`0940c900 00000000`00000000 : myfs+0x49919 fffff880`05cd96f0 fffff880`05178d54 : fffff880`05154130 00000000`00000800 fffffa80`07c9ed40 fffffa80`0940c920 : myfs+0x13f87 fffff880`05cd97f0 fffff880`05165b7a : fffffa80`0976c248 fffffa80`07c9d8b0 fffffa80`07519f80 fffffa80`07519e01 : myfs+0x47d54 fffff880`05cd9820 fffff880`015f5271 : fffffa80`074f6c70 fffffa80`07426430 fffffa80`07115c30 fffffa80`07c9dd00 : myfs+0x34b7a fffff880`05cd9850 fffff880`015f3138 : fffff8a0`001db400 fffffa80`074f6c70 00000000`00000001 00000000`00000000 : mup!MupSurrogateGetUncProviderDeviceObject+0x1491 fffff880`05cd98c0 fffff880`015f3b0d : fffffa80`07426430 fffff880`015f1110 fffffa80`070d9ed0 00000000`00000000 : mup!MupSurrogatePurgeNegativeCacheEntry+0x33b0 fffff880`05cd9910 fffff880`010b723f : fffffa80`074265d8 fffffa80`074f6c70 fffff880`05cd99a0 fffffa80`07519e30 : mup!MupSurrogatePurgeNegativeCacheEntry+0x3d85 fffff880`05cd9960 fffff880`010b56df : fffffa80`07c9dd40 00000000`00000001 fffffa80`07c9dd00 fffffa80`07426430 : fltmgr!FltIsCallbackDataDirty+0xa2f fffff880`05cd99f0 fffff800`04388929 : 00000000`00000000 fffffa80`070d9ed0 00000000`00000001 fffffa80`07426430 : fltmgr+0x16df fffff880`05cd9a50 fffff800`04390143 : fffffa80`070d9ed0 fffffa80`070d9ed0 fffffa80`070d9ed0 fffff880`045d5180 : nt!IoRemoveShareAccess+0x169 fffff880`05cd9ac0 fffff800`04074153 : 00000000`00002b2c 00000000`00000000 00000000`00000000 00000000`00000000 : nt!NtReadFile+0x633 fffff880`05cd9bb0 00000000`7738ff1a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KeSynchronizeExecution+0x3a43 00000000`4d15f838 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7738ff1a
STACK_COMMAND: kb
FOLLOWUP_IP: myfs+e4c0 fffff880`0513f4c0 8bc7 mov eax,edi
SYMBOL_STACK_INDEX: 4
SYMBOL_NAME: myfs+e4c0
FOLLOWUP_NAME: MachineOwner
IMAGE_NAME: myfs.sys
BUCKET_ID: WRONG_SYMBOLS
Followup: MachineOwner ---------
|