Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Break instruction exception - code 80000003 (first chance)
- *******************************************************************************
- * *
- * You are seeing this message because you pressed either *
- * CTRL+C (if you run console kernel debugger) or, *
- * CTRL+BREAK (if you run GUI kernel debugger), *
- * on your debugger machine's keyboard. *
- * *
- * THIS IS NOT A BUG OR A SYSTEM CRASH *
- * *
- * If you did not intend to break into the debugger, press the "g" key, then *
- * press the "Enter" key now. This message might immediately reappear. If it *
- * does, press "g" and "Enter" again. *
- * *
- *******************************************************************************
- nt!DbgBreakPointWithStatus:
- fffff800`02700200 cc int 3
- kd> g
- Will breakin at next boot.
- *** Fatal System Error: 0x000000c4
- (0x0000000000000081,0xFFFFFA80082B7BE0,0xFFFFFFFFFFFF8042,0x0000000000000000)
- Break instruction exception - code 80000003 (first chance)
- A fatal system error has occurred.
- Debugger entered on first try; Bugcheck callbacks have not been invoked.
- A fatal system error has occurred.
- Connected to Windows 7 7601 x64 target at (Wed Nov 21 13:39:54.897 2018 (UTC - 5:00)), ptr64 TRUE
- Loading Kernel Symbols
- ...............................................................
- .............................................
- Press ctrl-c (cdb, kd, ntsd) or ctrl-break (windbg) to abort symbol loads that take too long.
- Run !sym noisy before .reload to track down problems loading symbols.
- ...................
- .......
- Loading User Symbols
- Loading unloaded module list
- ......Unable to enumerate user-mode unloaded modules, Win32 error 0n30
- ERROR: FindPlugIns 8007007b
- ERROR: Some plugins may not be available [8007007b]
- *******************************************************************************
- * *
- * Bugcheck Analysis *
- * *
- *******************************************************************************
- Use !analyze -v to get detailed debugging information.
- BugCheck C4, {81, fffffa80082b7be0, ffffffffffff8042, 0}
- Probably caused by : eram.sys ( eram!EramReadWrite+144 )
- Followup: MachineOwner
- ---------
- nt!DbgBreakPointWithStatus:
- fffff800`02700200 cc int 3
- kd> !analyze -v
- ERROR: FindPlugIns 8007007b
- ERROR: Some plugins may not be available [8007007b]
- *******************************************************************************
- * *
- * Bugcheck Analysis *
- * *
- *******************************************************************************
- DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
- A device driver attempting to corrupt the system has been caught. This is
- because the driver was specified in the registry as being suspect (by the
- administrator) and the kernel has enabled substantial checking of this driver.
- If the driver attempts to corrupt the system, bugchecks 0xC4, 0xC1 and 0xA will
- be among the most commonly seen crashes.
- Arguments:
- Arg1: 0000000000000081, MmMapLockedPages called without MDL_MAPPING_CAN_FAIL
- Arg2: fffffa80082b7be0, MDL address.
- Arg3: ffffffffffff8042, MDL flags.
- Arg4: 0000000000000000, 0.
- Debugging Details:
- ------------------
- KEY_VALUES_STRING: 1
- STACKHASH_ANALYSIS: 1
- TIMELINE_ANALYSIS: 1
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 0
- BUILD_VERSION_STRING: 7601.24291.amd64fre.win7sp1_ldr_escrow.181110-1429
- DUMP_TYPE: 0
- BUGCHECK_P1: 81
- BUGCHECK_P2: fffffa80082b7be0
- BUGCHECK_P3: ffffffffffff8042
- BUGCHECK_P4: 0
- BUGCHECK_STR: 0xc4_81
- CPU_COUNT: 1
- CPU_MHZ: a98
- CPU_VENDOR: GenuineIntel
- CPU_FAMILY: 6
- CPU_MODEL: 5e
- CPU_STEPPING: 3
- CPU_MICROCODE: 6,5e,3,0 (F,M,S,R) SIG: 0'00000000 (cache) 0'00000000 (init)
- DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
- PROCESS_NAME: System
- CURRENT_IRQL: 2
- ANALYSIS_SESSION_HOST: BRYAN-PC
- ANALYSIS_SESSION_TIME: 11-21-2018 13:40:23.0511
- ANALYSIS_VERSION: 10.0.17763.132 amd64fre
- LAST_CONTROL_TRANSFER: from fffff800027b45d2 to fffff80002700200
- STACK_TEXT:
- fffff880`02f99568 fffff800`027b45d2 : 00000000`00000081 fffffa80`067b1660 00000000`00000065 fffff800`026d12c8 : nt!DbgBreakPointWithStatus
- fffff880`02f99570 fffff800`027b53c2 : ffffffff`00000003 00000000`00000000 fffff800`02709050 00000000`000000c4 : nt!KiBugCheckDebugBreak+0x12
- fffff880`02f995d0 fffff800`026f9aa4 : fffff880`04aab2c5 00000000`00000000 fffffa80`08227f40 fffff880`04aab2c5 : nt!KeBugCheck2+0x722
- fffff880`02f99ca0 fffff800`02b5f4fc : 00000000`000000c4 00000000`00000081 fffffa80`082b7be0 ffffffff`ffff8042 : nt!KeBugCheckEx+0x104
- fffff880`02f99ce0 fffff800`02b727ba : fffffa80`082b7be0 00000000`00000002 fffffa80`07690700 00000000`00000000 : nt!VerifierBugCheckIfAppropriate+0x3c
- fffff880`02f99d20 fffff880`01877784 : fffff980`2a9bae50 00000000`00000002 fffffa80`08227f40 fffff800`02b77ec6 : nt!VerifierMmMapLockedPages+0x4a
- fffff880`02f99d60 fffff800`02b7bd56 : fffffa80`07690700 fffff980`2a9bae50 fffff880`02f95001 00000000`00000002 : eram!EramReadWrite+0x144 [c:\eram\eram.c @ 490]
- fffff880`02f99de0 fffff880`04aab2c5 : fffffa80`07a958b0 00000000`00000002 00000000`00000000 fffffa80`08227f40 : nt!IovCallDriver+0x566
- fffff880`02f99e40 fffff880`04a86abc : fffff980`22c46f80 fffff980`2a9bae50 fffffa80`07a95700 fffffa80`00000001 : fastfat!FatCommonRead+0xb75
- fffff880`02f99f60 fffff800`02b7bd56 : fffff980`2a9bae50 fffff980`2a9bae50 fffff880`02f9b000 fffff880`02f95000 : fastfat!FatFsdRead+0x1a0
- fffff880`02f99ff0 fffff880`0109583f : fffff980`2a9bafb0 fffff880`02f9a0a0 fffff980`2a4c2e10 fffffa80`0839ae20 : nt!IovCallDriver+0x566
- fffff880`02f9a050 fffff880`010946df : fffffa80`074f0530 fffffa80`074f0530 fffff980`2a9bae00 fffff980`2a9bae50 : fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x24f
- fffff880`02f9a0e0 fffff800`02b7bd56 : fffff980`2a9bae50 00000000`00000002 fffffa80`082b7b70 fffffa80`06845b18 : fltmgr!FltpDispatch+0xcf
- fffff880`02f9a140 fffff800`0272dae1 : fffff980`2a9bae50 fffffa80`074f0530 fffffa80`082b7be0 fffffa80`0892e290 : nt!IovCallDriver+0x566
- fffff880`02f9a1a0 fffff800`027ce853 : 00000000`00000000 00000000`00000000 fffffa80`082b7b70 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x21761
- fffff880`02f9a230 fffff800`027d5860 : ffffffff`ffffffff 00000000`00000000 00000000`c0033333 ffffffff`ffffffff : nt!MiIssueHardFault+0x363
- fffff880`02f9a2d0 fffff800`027d8883 : 00000000`00000000 fffff980`23200000 00000000`00000000 fffffa80`067b1660 : nt!MmAccessFault+0x4820
- fffff880`02f9a420 fffff800`026af6d4 : fffff980`23200000 fffff880`02f9a611 00000000`00000000 fffff800`026bf601 : nt!MmCheckCachedPageStates+0x693
- fffff880`02f9a590 fffff800`026a9310 : 00000000`00000002 fffffa80`00000000 00000000`00000001 fffff880`02f9a720 : nt!CcMapAndRead+0xc4
- fffff880`02f9a5f0 fffff800`0296d3ea : fffffa80`00040000 fffff880`02f9a768 00000000`00000400 00000000`00000000 : nt!CcPinFileData+0x570
- fffff880`02f9a6b0 fffff880`04a86f99 : 00000000`00000000 00000000`00000000 00000000`00000400 fffffa80`07a958b0 : nt!CcPinRead+0xde
- fffff880`02f9a760 fffff880`04aaba31 : fffff980`2a556f80 fffffa80`07a95801 00000000`00000002 fffff880`04a8b400 : fastfat!FatMarkVolume+0x19d
- fffff880`02f9a830 fffff880`04aab8e6 : fffff980`2a556f80 fffff980`2a490ea0 fffff980`2a490e01 fffff980`2a490ea0 : fastfat!FatCommonShutdown+0x101
- fffff880`02f9a8d0 fffff800`02b7bd56 : fffff980`2a490ea0 fffff980`2a490ea0 fffffa80`067fbe01 00000000`00000002 : fastfat!FatFsdShutdown+0x46
- fffff880`02f9a910 fffff880`010946af : fffffa80`07a34cb0 00000000`00000002 fffffa80`07a34cb0 fffffa80`07b17800 : nt!IovCallDriver+0x566
- fffff880`02f9a970 fffff800`02b7bd56 : fffff980`2a490ea0 00000000`00000002 fffff980`2a490ea0 fffff800`0299459c : fltmgr!FltpDispatch+0x9f
- fffff880`02f9a9d0 fffff800`0291be1c : fffffa80`067fbe40 fffff800`028767a0 fffff800`028d7050 fffffa80`08bd90e0 : nt!IovCallDriver+0x566
- fffff880`02f9aa30 fffff800`0291bfb2 : 00000000`00000001 00000000`00000001 fffff800`028767a0 00000000`00000000 : nt!IopShutdownBaseFileSystems+0xac
- fffff880`02f9aab0 fffff800`0291cd36 : fffff800`0291cb50 fffff800`028767a0 00000000`00000001 00000000`00000001 : nt!IoShutdownSystem+0x122
- fffff880`02f9ab30 fffff800`02694b39 : fffff800`0291cb50 fffff800`0293f601 fffff800`028d8f00 fffffa80`00000000 : nt!PopGracefulShutdown+0x1e6
- fffff880`02f9ab70 fffff800`029a7d10 : 00000000`00000000 fffff800`0284a180 00000000`00000080 00000000`00000001 : nt!ExpWorkerThread+0x111
- fffff880`02f9ac00 fffff800`026ff9a6 : fffff800`0284a180 fffffa80`067b1660 fffffa80`067b1b50 00000000`00000000 : nt!PspSystemThreadStartup+0x194
- fffff880`02f9ac40 00000000`00000000 : fffff880`02f9b000 fffff880`02f95000 fffff880`06c8f5a0 00000000`00000000 : nt!KiStartSystemThread+0x16
- THREAD_SHA1_HASH_MOD_FUNC: 07d10f8729e4a10d7e1cd59b8b0a833eec9384bf
- THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 6e5ccf8ad4b20d22b22b828d1e7886ce8a6f3c84
- THREAD_SHA1_HASH_MOD: e512cdf6de5c59baf1f1c62cdee7073972af92c8
- FOLLOWUP_IP:
- eram!EramReadWrite+144 [c:\eram\eram.c @ 490]
- fffff880`01877784 4889442460 mov qword ptr [rsp+60h],rax
- FAULT_INSTR_CODE: 24448948
- FAULTING_SOURCE_LINE: c:\eram\eram.c
- FAULTING_SOURCE_FILE: c:\eram\eram.c
- FAULTING_SOURCE_LINE_NUMBER: 490
- FAULTING_SOURCE_CODE:
- 486: pTransAddr = NULL;
- 487: if (pIrp->MdlAddress != NULL) /* with address */
- 488: {
- 489: /* address translation */
- > 490: pTransAddr = MmGetSystemAddressForMdl(pIrp->MdlAddress);
- 491: }
- 492: /* Set success */
- 493: ntStat = STATUS_SUCCESS;
- 494: /* Set the data length */
- 495: pIrp->IoStatus.Information = 0;
- SYMBOL_STACK_INDEX: 6
- SYMBOL_NAME: eram!EramReadWrite+144
- FOLLOWUP_NAME: MachineOwner
- MODULE_NAME: eram
- IMAGE_NAME: eram.sys
- DEBUG_FLR_IMAGE_TIMESTAMP: 5bf574b7
- STACK_COMMAND: .thread ; .cxr ; kb
- FAILURE_BUCKET_ID: X64_0xc4_81_VRF_eram!EramReadWrite+144
- BUCKET_ID: X64_0xc4_81_VRF_eram!EramReadWrite+144
- PRIMARY_PROBLEM_CLASS: X64_0xc4_81_VRF_eram!EramReadWrite+144
- TARGET_TIME: 2018-11-21T18:39:49.000Z
- OSBUILD: 7601
- OSSERVICEPACK: 1000
- SERVICEPACK_NUMBER: 0
- OS_REVISION: 0
- SUITE_MASK: 784
- PRODUCT_TYPE: 1
- OSPLATFORM_TYPE: x64
- OSNAME: Windows 7
- OSEDITION: Windows 7 WinNt (Service Pack 1) TerminalServer SingleUserTS Personal
- OS_LOCALE:
- USER_LCID: 0
- OSBUILD_TIMESTAMP: 2018-11-10 19:44:59
- BUILDDATESTAMP_STR: 181110-1429
- BUILDLAB_STR: win7sp1_ldr_escrow
- BUILDOSVER_STR: 6.1.7601.24291.amd64fre.win7sp1_ldr_escrow.181110-1429
- ANALYSIS_SESSION_ELAPSED_TIME: 61c
- ANALYSIS_SOURCE: KM
- FAILURE_ID_HASH_STRING: km:x64_0xc4_81_vrf_eram!eramreadwrite+144
- FAILURE_ID_HASH: {33edf415-9b76-1d64-5320-59d2189dbf11}
- Followup: MachineOwner
- ---------
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement