- 0: kd> .reboot
- Shutdown occurred at (Thu Mar 18 14:36:07.022 2010 (UTC + 2:00))...unloading all symbol tables.
- Waiting to reconnect...
- Connected to Windows XP 2600 x86 compatible target at (Thu Mar 18 14:36:45.082 2010 (UTC + 2:00)), ptr64 FALSE
- Kernel Debugger connection established.
- Symbol search path is: symsrv*symsrv.dll*C:\Symbols*http://msdl.microsoft.com/download/symbols
- Executable search path is:
- Windows XP Kernel Version 2600 MP (1 procs) Checked x86 compatible
- Built by: 2600.xpsp.080413-2133
- Machine Name:
- Kernel base = 0x80a02000 PsLoadedModuleList = 0x80b019e8
- System Uptime: not available
- MM: Loader/HAL memory block indicates large pages cannot be used for 80100000->8012777F
- Intel Storage Driver Ver: 8.2.2.1001
- driver \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20100317.021\navex15.sys has lower case sections (init or pagexxx)
- driver \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20100317.021\navex15.sys has lower case sections (init or pagexxx)
- AFD: Read DefaultSendWindow from the registry, value: 0xfc00 (default: 0x2000))
- *** Assertion failed: KeGetCurrentIrql() == PASSIVE_LEVEL
- *** Source File: d:\xpsp\base\ntos\mm\sysload.c, line 7480
- Break repeatedly, break Once, Ignore, terminate Process, or terminate Thread (boipt)? i
- i
- *** Assertion failed: KeGetCurrentIrql() == PASSIVE_LEVEL
- *** Source File: d:\xpsp\base\ntos\mm\sysload.c, line 7480
- Break repeatedly, break Once, Ignore, terminate Process, or terminate Thread (boipt)? i
- i
- *** Assertion failed: KeGetCurrentIrql() == PASSIVE_LEVEL
- *** Source File: d:\xpsp\base\ntos\mm\sysload.c, line 7480
- Break repeatedly, break Once, Ignore, terminate Process, or terminate Thread (boipt)? i
- i
- *** Assertion failed: KeGetCurrentIrql() == PASSIVE_LEVEL
- *** Source File: d:\xpsp\base\ntos\mm\sysload.c, line 7480
- Break repeatedly, break Once, Ignore, terminate Process, or terminate Thread (boipt)? i
- i
- *** Assertion failed: KeGetCurrentIrql() == PASSIVE_LEVEL
- *** Source File: d:\xpsp\base\ntos\mm\sysload.c, line 7480
- Break repeatedly, break Once, Ignore, terminate Process, or terminate Thread (boipt)? i
- i
- *** Assertion failed: KeGetCurrentIrql() == PASSIVE_LEVEL
- *** Source File: d:\xpsp\base\ntos\mm\sysload.c, line 7480
- Break repeatedly, break Once, Ignore, terminate Process, or terminate Thread (boipt)? i
- i
- MiSessionWideReserveImageAddress: NO Code Sharing on \SystemRoot\System32\drivers\dxg.sys, Address 0xbf000000
- MiSessionWideReserveImageAddress: NO Code Sharing on \SystemRoot\System32\igxprd32.dll, Address 0xbf012000
- MiSessionWideReserveImageAddress: NO Code Sharing on \SystemRoot\System32\igxpgd32.dll, Address 0xbf024000
- MiSessionWideReserveImageAddress: NO Code Sharing on \SystemRoot\System32\igxprd32.dll, Address 0xbf012000
- MiSessionWideReserveImageAddress: NO Code Sharing on \SystemRoot\System32\igxpdv32.DLL, Address 0xbf04f000
- MiSessionWideReserveImageAddress: NO Code Sharing on \SystemRoot\System32\igxpdx32.DLL, Address 0xbf25b000
- MiSessionWideReserveImageAddress: NO Code Sharing on \SystemRoot\System32\idisw2km.dll, Address 0xbf562000
- MiSessionWideReserveImageAddress: NO Code Sharing on \SystemRoot\System32\idisw2km.dll, Address 0xbf562000
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
- ERROR: DavReadRegistryValues/RegQueryValueExW(4). WStatus = 127
- ERROR: DavReadRegistryValues/RegQueryValueExW(5). WStatus = 127
- ERROR: DavReadRegistryValues/RegQueryValueExW(6). WStatus = 127
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
- 0 - KeepSCMHappyOnStart
- 17 - KeepSCMHappyOnStart
- 35 - TellSCMGoodToGo
- SavRoam: initializing communications
- SavRoam: initializing COM
- SavRoam: starting Transman
- *** Assertion failed: (MemoryDescriptorList->MdlFlags & ( MDL_MAPPED_TO_SYSTEM_VA | MDL_SOURCE_IS_NONPAGED_POOL | MDL_PARTIAL_HAS_BEEN_MAPPED)) == 0
- *** Source File: d:\xpsp\base\ntos\mm\iosup.c, line 3542
- Break repeatedly, break Once, Ignore, terminate Process, or terminate Thread (boipt)? b
- b
- Execute '.cxr BA4FF87C' to dump context
- Break instruction exception - code 80000003 (first chance)
- nt!DbgBreakPoint:
- 80ac37e0 cc int 3
- 0: kd> kn
- # ChildEBP RetAddr
- 00 ba4ff85c 80ac54a2 nt!DbgBreakPoint
- 01 ba4ffb4c 80ac54e4 nt!RtlAssert2+0x104
- 02 ba4ffb68 80a50d12 nt!RtlAssert+0x18
- 03 ba4ffbc4 80a5136e nt!MmMapLockedPagesSpecifyCache+0x72
- 04 ba4ffbe4 9cafe882 nt!MmMapLockedPages+0x18
- 05 ba4ffbf4 9caff443 uphcleanhlp!RegmonMapServiceTable+0x72
- 06 ba4ffc50 9caff812 uphcleanhlp!RealRegFlushKey <PERF> (uphcleanhlp+0x1443)
- 07 ba4ffc7c 80b3f5d9 uphcleanhlp!DriverEntry+0x13e
- 08 ba4ffd58 80b3f806 nt!IopLoadDriver+0x6b7
- 09 ba4ffd80 80ad51a9 nt!IopLoadUnloadDriver+0x78
- 0a ba4ffdac 80bd81ac nt!ExpWorkerThread+0x10f
- 0b ba4ffddc 80ae4212 nt!PspSystemThreadStartup+0x34
- 0c 00000000 00000000 nt!KiThreadStartup+0x16
- 0: kd> g
- *** Assertion failed: (MemoryDescriptorList->MdlFlags & ( MDL_MAPPED_TO_SYSTEM_VA | MDL_SOURCE_IS_NONPAGED_POOL | MDL_PARTIAL_HAS_BEEN_MAPPED)) == 0
- *** Source File: d:\xpsp\base\ntos\mm\iosup.c, line 3542
- Break repeatedly, break Once, Ignore, terminate Process, or terminate Thread (boipt)? i
- i
- *** Assertion failed: (MemoryDescriptorList->MdlFlags & ( MDL_PAGES_LOCKED | MDL_PARTIAL)) != 0
- *** Source File: d:\xpsp\base\ntos\mm\iosup.c, line 3546
- Break repeatedly, break Once, Ignore, terminate Process, or terminate Thread (boipt)? i
- i
- couldn't read disable reg flush key value 0xc0000034
- SavRoam: loading certs from: C:\Program Files\Symantec AntiVirus\
- SavRoam: loading ScsComms
- SavRoam: communication initialization SUCCEEDED!
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
- driver \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20100317.021\navex15.sys has lower case sections (init or pagexxx)
- driver \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20100317.021\navex15.sys has lower case sections (init or pagexxx)
- SE: Obsolete call: SeImpersonateClient
- CmpLinkHiveToMaster: ObOpenObjectByName for CmHive = E2E23B60 , LinkName = S-1-5-18 failed with status c0000022
- SE: Obsolete call: SeImpersonateClient
- LPC[ 3c4.3f4 ]: Refusing connection from 3c4.b68
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
- LPC[ a0.3d4 ]: Refusing connection from a0.3a4
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
- LPC[ 410.ec0 ]: svchost.exe Attempted ReplyWaitReceive to Thread 891e3768 (explorer.exe)
- LPC[ 410.ec0 ]: failed. MessageId == 19322 Client Id: c30.cb8
- LPC[ 410.ec0 ]: Thread MessageId == 0 Client Id: c30.cb8
- Subkeys open inside the hive (E120E578) (\Microsoft\Windows\UsrClass.dat) :
- Process 897A4D50 (PID = 410 ImageFileName = svchost.exe) (KCB = E2FB8100) :: Key \REGISTRY\USER\S-1-5-21-189481810-146959734-1386271435-77180_CLASSES
- Process 897A4D50 (PID = 410 ImageFileName = svchost.exe) (KCB = E2FB8100) :: Key \REGISTRY\USER\S-1-5-21-189481810-146959734-1386271435-77180_CLASSES
- Process 897D4768 (PID = 2e4 ImageFileName = winlogon.exe) (KCB = E2FB8100) :: Key \REGISTRY\USER\S-1-5-21-189481810-146959734-1386271435-77180_CLASSES
- <CSync:BeginUnload
- <CSync:BeginUnload
- MM: Session 1 image \SystemRoot\System32\drivers\dxg.sys is linked at a nonsharable address (00010000)
- MM: Image \SystemRoot\System32\drivers\dxg.sys has been moved to address (BF000000) by the system so it can run,
- but this needs to be fixed in the image for sharing to occur.
- MM: Session 2 image \SystemRoot\System32\drivers\dxg.sys is linked at a nonsharable address (00010000)
- MM: Image \SystemRoot\System32\drivers\dxg.sys has been moved to address (BF000000) by the system so it can run,
- but this needs to be fixed in the image for sharing to occur.
- MiSessionWideReserveImageAddress: NO Code Sharing on \SystemRoot\System32\igxprd32.dll, Address 0xbf012000
- MM: Session 2 image \SystemRoot\System32\igxprd32.dll is linked at a nonsharable address (00010000)
- MM: Image \SystemRoot\System32\igxprd32.dll has been moved to address (BF012000) by the system so it can run,
- but this needs to be fixed in the image for sharing to occur.
- MM: Session 2 image \SystemRoot\System32\igxpgd32.dll is linked at a nonsharable address (00010000)
- MM: Image \SystemRoot\System32\igxpgd32.dll has been moved to address (BF024000) by the system so it can run,
- but this needs to be fixed in the image for sharing to occur.
- MiSessionWideReserveImageAddress: NO Code Sharing on \SystemRoot\System32\igxprd32.dll, Address 0xbf012000
- MM: Session 2 image \SystemRoot\System32\igxprd32.dll is linked at a nonsharable address (00010000)
- MM: Image \SystemRoot\System32\igxprd32.dll has been moved to address (BF012000) by the system so it can run,
- but this needs to be fixed in the image for sharing to occur.
- MM: Session 2 image \SystemRoot\System32\igxpdv32.DLL is linked at a nonsharable address (00010000)
- MM: Image \SystemRoot\System32\igxpdv32.DLL has been moved to address (BF04F000) by the system so it can run,
- but this needs to be fixed in the image for sharing to occur.
- MiSessionWideReserveImageAddress: NO Code Sharing on \SystemRoot\System32\igxpdx32.DLL, Address 0xbf25b000
- MM: Session 2 image \SystemRoot\System32\igxpdx32.DLL is linked at a nonsharable address (00010000)
- MM: Image \SystemRoot\System32\igxpdx32.DLL has been moved to address (BF25B000) by the system so it can run,
- but this needs to be fixed in the image for sharing to occur.
- MiSessionWideReserveImageAddress: NO Code Sharing on \SystemRoot\System32\idisw2km.dll, Address 0xbf562000
- MM: Session 2 image \SystemRoot\System32\idisw2km.dll is linked at a nonsharable address (00010000)
- MM: Image \SystemRoot\System32\idisw2km.dll has been moved to address (BF562000) by the system so it can run,
- but this needs to be fixed in the image for sharing to occur.
- MiSessionWideReserveImageAddress: NO Code Sharing on \SystemRoot\System32\idisw2km.dll, Address 0xbf562000
- MM: Session 2 image \SystemRoot\System32\idisw2km.dll is linked at a nonsharable address (00010000)
- MM: Image \SystemRoot\System32\idisw2km.dll has been moved to address (BF562000) by the system so it can run,
- but this needs to be fixed in the image for sharing to occur.
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
- SE: Obsolete call: SeImpersonateClient
