P
Pablo Rampone
Guest
After installing Windows6.0-KB938194-x64, and Windows6.0-KB938979-x64 Kaspersky, jetico firewall, and kerio firewall crash system.
After installing both the updates from the Microsoft site (first from
connect then from Microsoft.com), I started to receive BSODS things that I
had installed were Kaspersky and Jetico Firewall both the versions that are
compatibile with x64 vista, mind you that before the updates everything was
running solid, and very stable no issues what so ever. After doing the
updates I came across these crashes, so I was stumpped I could'nt think of
what was making it BSOD so I deciced to investigate further I installed the
x64 debugging toolkit and started to look at the memory dumps and the
minidumps and come to find out it was klif.sys which is from Kaspersky and
bc_ngn.sys which is from Jetico. Seems Microsoft is either eliminating the
competition or there just eliminating poorly written drivers. Now funny
thing is that I run NOD32 as of now no issues what so ever and NOD32 is an
older antivirus toolkit than the earlier tools I had installed. If anyone
else is experiencing issues like this please repost ASAP so these issues are
stated back to Microsoft. I do want to say that working on Vista is a
pleasure out of all the releases of Windows I think that Vista is at its
prime and is suiting its name. I will post the dumps and my system specs.
Concerned Microsoft Evangalist.
Pablo R.
Pacoxfl@hotmail.com
System Specs:
OS Name Microsoft® Windows VistaT Ultimate
Version 6.0.6000 Build 6000
Other OS Description Not Available
OS Manufacturer Microsoft Corporation
System Name HBX-PC
System Manufacturer Gateway
System Model GT5058
System Type x64-based PC
Processor AMD Athlon(tm) 64 X2 Dual Core Processor 3800+, 2000 Mhz, 2
Core(s), 2 Logical Processor(s)
BIOS Version/Date Phoenix Technologies, LTD 6.00 PG, 2/10/2006
SMBIOS Version 2.2
Windows Directory C:\Windows
System Directory C:\Windows\system32
Boot Device \Device\HarddiskVolume2
Locale United States
Hardware Abstraction Layer Version = "6.0.6000.16386"
User Name HBX-PC\HBX
Time Zone Eastern Daylight Time
Total Physical Memory 2,045.94 MB
Available Physical Memory 575.52 MB
Total Virtual Memory 4.22 GB
Available Virtual Memory 2.04 GB
Page File Space 2.29 GB
Page File C:\pagefile.sys
----------------------------------------------------------------------------------------------------------------
Jetico Crash dump: -->
Microsoft (R) Windows Debugger Version 6.7.0005.1
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File
[C:\Users\HBX\AppData\Local\Temp\WER921C.tmp\Mini080507-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: *** Invalid ***
****************************************************************************
* Symbol loading may be unreliable without a symbol search path. *
* Use .symfix to have the debugger choose a symbol path. *
* After setting your symbol path, use .reload to refresh symbol locations. *
****************************************************************************
Executable search path is:
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for
ntoskrnl.exe
Windows Vista Kernel Version 6000 MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Kernel base = 0xfffff800`02800000 PsLoadedModuleList = 0xfffff800`0299af50
Debug session time: Sun Aug 5 21:05:20.893 2007 (GMT-4)
System Uptime: 0 days 0:08:00.409
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for
ntoskrnl.exe
Loading Kernel Symbols
............................................................................................................................................................
Loading User Symbols
Loading unloaded module list
........
*******************************************************************************
*
*
* Bugcheck Analysis
*
*
*
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck C4, {81, fffffa80037d0dd0, a, 0}
Unable to load image \SystemRoot\System32\Drivers\bc_ngn.sys, Win32 error
0n2
*** WARNING: Unable to verify timestamp for bc_ngn.sys
*** ERROR: Module load completed but symbols could not be loaded for
bc_ngn.sys
***** Kernel symbols are WRONG. Please fix symbols to do analysis.
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
Probably caused by : bc_ngn.sys ( bc_ngn+2a4d )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
*
*
* Bugcheck Analysis
*
*
*
*******************************************************************************
DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
A device driver attempting to corrupt the system has been caught. This is
because the driver was specified in the registry as being suspect (by the
administrator) and the kernel has enabled substantial checking of this
driver.
If the driver attempts to corrupt the system, bugchecks 0xC4, 0xC1 and 0xA
will
be among the most commonly seen crashes.
Parameter 1 = 0x1000 .. 0x1020 - deadlock verifier error codes.
Typically the code is 0x1001 (deadlock detected) and you can
issue a '!deadlock' KD command to get more information.
Arguments:
Arg1: 0000000000000081, MmMapLockedPages called without MDL_MAPPING_CAN_FAIL
Arg2: fffffa80037d0dd0, MDL address.
Arg3: 000000000000000a, MDL flags.
Arg4: 0000000000000000, 0.
Debugging Details:
------------------
***** Kernel symbols are WRONG. Please fix symbols to do analysis.
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
MODULE_NAME: bc_ngn
FAULTING_MODULE: fffff80002800000 nt
DEBUG_FLR_IMAGE_TIMESTAMP: 46568106
BUGCHECK_STR: 0xc4_81
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WRONG_SYMBOLS
LAST_CONTROL_TRANSFER: from fffff80002c0937d to fffff8000284dbd0
STACK_TEXT:
fffff980`26f158d8 fffff800`02c0937d : 00000000`000000c4 00000000`00000081
fffffa80`037d0dd0 00000000`0000000a : nt+0x4dbd0
fffff980`26f158e0 00000000`000000c4 : 00000000`00000081 fffffa80`037d0dd0
00000000`0000000a 00000000`00000000 : nt+0x40937d
fffff980`26f158e8 00000000`00000081 : fffffa80`037d0dd0 00000000`0000000a
00000000`00000000 fffff800`02a8f017 : 0xc4
fffff980`26f158f0 fffffa80`037d0dd0 : 00000000`0000000a 00000000`00000000
fffff800`02a8f017 fffffa80`037d0dd0 : 0x81
fffff980`26f158f8 00000000`0000000a : 00000000`00000000 fffff800`02a8f017
fffffa80`037d0dd0 fffff800`02c195bd : 0xfffffa80`037d0dd0
fffff980`26f15900 00000000`00000000 : fffff800`02a8f017 fffffa80`037d0dd0
fffff800`02c195bd fffffa80`037d0dd0 : 0xa
fffff980`26f15908 fffff800`02a8f017 : fffffa80`037d0dd0 fffff800`02c195bd
fffffa80`037d0dd0 00000000`000000c4 : 0x0
fffff980`26f15910 fffffa80`037d0dd0 : fffff800`02c195bd fffffa80`037d0dd0
00000000`000000c4 00000000`0000000d : nt+0x28f017
fffff980`26f15918 fffff800`02c195bd : fffffa80`037d0dd0 00000000`000000c4
00000000`0000000d 00000000`00000002 : 0xfffffa80`037d0dd0
fffff980`26f15920 fffffa80`037d0dd0 : 00000000`000000c4 00000000`0000000d
00000000`00000002 00000000`00000000 : nt+0x4195bd
fffff980`26f15928 00000000`000000c4 : 00000000`0000000d 00000000`00000002
00000000`00000000 00000000`00000001 : 0xfffffa80`037d0dd0
fffff980`26f15930 00000000`0000000d : 00000000`00000002 00000000`00000000
00000000`00000001 fffff980`2d296ee0 : 0xc4
fffff980`26f15938 00000000`00000002 : 00000000`00000000 00000000`00000001
fffff980`2d296ee0 fffff980`00477a4d : 0xd
fffff980`26f15940 00000000`00000000 : 00000000`00000001 fffff980`2d296ee0
fffff980`00477a4d fffffa80`037f9000 : 0x2
fffff980`26f15948 00000000`00000001 : fffff980`2d296ee0 fffff980`00477a4d
fffffa80`037f9000 00000000`00000002 : 0x0
fffff980`26f15950 fffff980`2d296ee0 : fffff980`00477a4d fffffa80`037f9000
00000000`00000002 00000000`00000000 : 0x1
fffff980`26f15958 fffff980`00477a4d : fffffa80`037f9000 00000000`00000002
00000000`00000000 fffff6fb`40000010 : 0xfffff980`2d296ee0
fffff980`26f15960 fffffa80`037f9000 : 00000000`00000002 00000000`00000000
fffff6fb`40000010 fffff980`004783d0 : bc_ngn+0x2a4d
fffff980`26f15968 00000000`00000002 : 00000000`00000000 fffff6fb`40000010
fffff980`004783d0 fffff980`0047857d : 0xfffffa80`037f9000
fffff980`26f15970 00000000`00000000 : fffff6fb`40000010 fffff980`004783d0
fffff980`0047857d fffff980`2d296ee0 : 0x2
fffff980`26f15978 fffff6fb`40000010 : fffff980`004783d0 fffff980`0047857d
fffff980`2d296ee0 fffff980`2d296ee0 : 0x0
fffff980`26f15980 fffff980`004783d0 : fffff980`0047857d fffff980`2d296ee0
fffff980`2d296ee0 00000000`00000000 : 0xfffff6fb`40000010
fffff980`26f15988 fffff980`0047857d : fffff980`2d296ee0 fffff980`2d296ee0
00000000`00000000 fffffa80`03596f40 : bc_ngn+0x33d0
fffff980`26f15990 fffff980`2d296ee0 : fffff980`2d296ee0 00000000`00000000
fffffa80`03596f40 fffffa80`03596f40 : bc_ngn+0x357d
fffff980`26f15998 fffff980`2d296ee0 : 00000000`00000000 fffffa80`03596f40
fffffa80`03596f40 fffff800`02c254e6 : 0xfffff980`2d296ee0
fffff980`26f159a0 00000000`00000000 : fffffa80`03596f40 fffffa80`03596f40
fffff800`02c254e6 fffff980`2d296ee0 : 0xfffff980`2d296ee0
fffff980`26f159a8 fffffa80`03596f40 : fffffa80`03596f40 fffff800`02c254e6
fffff980`2d296ee0 fffffa80`030cb060 : 0x0
fffff980`26f159b0 fffffa80`03596f40 : fffff800`02c254e6 fffff980`2d296ee0
fffffa80`030cb060 fffff980`2d296ee0 : 0xfffffa80`03596f40
fffff980`26f159b8 fffff800`02c254e6 : fffff980`2d296ee0 fffffa80`030cb060
fffff980`2d296ee0 fffffa80`030cb060 : 0xfffffa80`03596f40
fffff980`26f159c0 fffff980`2d296ee0 : fffffa80`030cb060 fffff980`2d296ee0
fffffa80`030cb060 00000000`00000001 : nt+0x4254e6
fffff980`26f159c8 fffffa80`030cb060 : fffff980`2d296ee0 fffffa80`030cb060
00000000`00000001 fffff980`2d296ee0 : 0xfffff980`2d296ee0
fffff980`26f159d0 fffff980`2d296ee0 : fffffa80`030cb060 00000000`00000001
fffff980`2d296ee0 fffffa80`05b079f0 : 0xfffffa80`030cb060
fffff980`26f159d8 fffffa80`030cb060 : 00000000`00000001 fffff980`2d296ee0
fffffa80`05b079f0 fffff800`02a8f017 : 0xfffff980`2d296ee0
fffff980`26f159e0 00000000`00000001 : fffff980`2d296ee0 fffffa80`05b079f0
fffff800`02a8f017 fffff980`2d296f00 : 0xfffffa80`030cb060
fffff980`26f159e8 fffff980`2d296ee0 : fffffa80`05b079f0 fffff800`02a8f017
fffff980`2d296f00 fffff980`26f15ca0 : 0x1
fffff980`26f159f0 fffffa80`05b079f0 : fffff800`02a8f017 fffff980`2d296f00
fffff980`26f15ca0 fffff980`00000000 : 0xfffff980`2d296ee0
fffff980`26f159f8 fffff800`02a8f017 : fffff980`2d296f00 fffff980`26f15ca0
fffff980`00000000 fffffa80`03596f40 : 0xfffffa80`05b079f0
fffff980`26f15a00 fffff980`2d296f00 : fffff980`26f15ca0 fffff980`00000000
fffffa80`03596f40 fffff980`2d296ee0 : nt+0x28f017
fffff980`26f15a08 fffff980`26f15ca0 : fffff980`00000000 fffffa80`03596f40
fffff980`2d296ee0 fffff980`26f15aa0 : 0xfffff980`2d296f00
fffff980`26f15a10 fffff980`00000000 : fffffa80`03596f40 fffff980`2d296ee0
fffff980`26f15aa0 00000000`00000000 : 0xfffff980`26f15ca0
fffff980`26f15a18 fffffa80`03596f40 : fffff980`2d296ee0 fffff980`26f15aa0
00000000`00000000 00000000`00000000 : 0xfffff980`00000000
fffff980`26f15a20 fffff980`2d296ee0 : fffff980`26f15aa0 00000000`00000000
00000000`00000000 00000000`00000000 : 0xfffffa80`03596f40
fffff980`26f15a28 fffff980`26f15aa0 : 00000000`00000000 00000000`00000000
00000000`00000000 00000000`00000000 : 0xfffff980`2d296ee0
fffff980`26f15a30 00000000`00000000 : 00000000`00000000 00000000`00000000
00000000`00000000 0000101e`0000101e : 0xfffff980`26f15aa0
fffff980`26f15a38 00000000`00000000 : 00000000`00000000 00000000`00000000
0000101e`0000101e fffffa80`05b079f0 : 0x0
fffff980`26f15a40 00000000`00000000 : 00000000`00000000 0000101e`0000101e
fffffa80`05b079f0 00000000`00000000 : 0x0
fffff980`26f15a48 00000000`00000000 : 0000101e`0000101e fffffa80`05b079f0
00000000`00000000 00000000`00000000 : 0x0
fffff980`26f15a50 0000101e`0000101e : fffffa80`05b079f0 00000000`00000000
00000000`00000000 00000000`0000101e : 0x0
fffff980`26f15a58 fffffa80`05b079f0 : 00000000`00000000 00000000`00000000
00000000`0000101e fffff980`2d296ee0 : 0x101e`0000101e
fffff980`26f15a60 00000000`00000000 : 00000000`00000000 00000000`0000101e
fffff980`2d296ee0 fffffa80`05b079f0 : 0xfffffa80`05b079f0
fffff980`26f15a68 00000000`00000000 : 00000000`0000101e fffff980`2d296ee0
fffffa80`05b079f0 00000000`00000000 : 0x0
fffff980`26f15a70 00000000`0000101e : fffff980`2d296ee0 fffffa80`05b079f0
00000000`00000000 00000000`00000000 : 0x0
fffff980`26f15a78 fffff980`2d296ee0 : fffffa80`05b079f0 00000000`00000000
00000000`00000000 00000000`00000000 : 0x101e
fffff980`26f15a80 fffffa80`05b079f0 : 00000000`00000000 00000000`00000000
00000000`00000000 0012019f`00000000 : 0xfffff980`2d296ee0
fffff980`26f15a88 00000000`00000000 : 00000000`00000000 00000000`00000000
0012019f`00000000 fffffa80`05775060 : 0xfffffa80`05b079f0
fffff980`26f15a90 00000000`00000000 : 00000000`00000000 0012019f`00000000
fffffa80`05775060 00000000`00000000 : 0x0
fffff980`26f15a98 00000000`00000000 : 0012019f`00000000 fffffa80`05775060
00000000`00000000 fffffa80`037f9000 : 0x0
fffff980`26f15aa0 0012019f`00000000 : fffffa80`05775060 00000000`00000000
fffffa80`037f9000 fffffa80`05b07a88 : 0x0
fffff980`26f15aa8 fffffa80`05775060 : 00000000`00000000 fffffa80`037f9000
fffffa80`05b07a88 00000000`00000001 : 0x12019f`00000000
fffff980`26f15ab0 00000000`00000000 : fffffa80`037f9000 fffffa80`05b07a88
00000000`00000001 fffffa80`05b079f0 : 0xfffffa80`05775060
fffff980`26f15ab8 fffffa80`037f9000 : fffffa80`05b07a88 00000000`00000001
fffffa80`05b079f0 fffffa80`05775060 : 0x0
fffff980`26f15ac0 fffffa80`05b07a88 : 00000000`00000001 fffffa80`05b079f0
fffffa80`05775060 00000000`00000000 : 0xfffffa80`037f9000
fffff980`26f15ac8 00000000`00000001 : fffffa80`05b079f0 fffffa80`05775060
00000000`00000000 00000000`7efa7000 : 0xfffffa80`05b07a88
fffff980`26f15ad0 fffffa80`05b079f0 : fffffa80`05775060 00000000`00000000
00000000`7efa7000 00000000`00000000 : 0x1
fffff980`26f15ad8 fffffa80`05775060 : 00000000`00000000 00000000`7efa7000
00000000`00000000 fffff800`02ac89ff : 0xfffffa80`05b079f0
fffff980`26f15ae0 00000000`00000000 : 00000000`7efa7000 00000000`00000000
fffff800`02ac89ff 00000000`75db3370 : 0xfffffa80`05775060
fffff980`26f15ae8 00000000`7efa7000 : 00000000`00000000 fffff800`02ac89ff
00000000`75db3370 00000000`0177f130 : 0x0
fffff980`26f15af0 00000000`00000000 : fffff800`02ac89ff 00000000`75db3370
00000000`0177f130 00000000`0177fd20 : 0x7efa7000
fffff980`26f15af8 fffff800`02ac89ff : 00000000`75db3370 00000000`0177f130
00000000`0177fd20 00000000`7efa7000 : 0x0
fffff980`26f15b00 00000000`75db3370 : 00000000`0177f130 00000000`0177fd20
00000000`7efa7000 fffff980`26f15bc8 : nt+0x2c89ff
fffff980`26f15b08 00000000`0177f130 : 00000000`0177fd20 00000000`7efa7000
fffff980`26f15bc8 00000000`0177f0d8 : 0x75db3370
fffff980`26f15b10 00000000`0177fd20 : 00000000`7efa7000 fffff980`26f15bc8
00000000`0177f0d8 fffffa80`05775060 : 0x177f130
fffff980`26f15b18 00000000`7efa7000 : fffff980`26f15bc8 00000000`0177f0d8
fffffa80`05775060 fffff800`02a95266 : 0x177fd20
fffff980`26f15b20 fffff980`26f15bc8 : 00000000`0177f0d8 fffffa80`05775060
fffff800`02a95266 00000000`00000001 : 0x7efa7000
fffff980`26f15b28 00000000`0177f0d8 : fffffa80`05775060 fffff800`02a95266
00000000`00000001 00000000`00000000 : 0xfffff980`26f15bc8
STACK_COMMAND: kb
FOLLOWUP_IP:
bc_ngn+2a4d
fffff980`00477a4d ?? ???
SYMBOL_STACK_INDEX: 11
FOLLOWUP_NAME: MachineOwner
IMAGE_NAME: bc_ngn.sys
SYMBOL_NAME: bc_ngn+2a4d
BUCKET_ID: WRONG_SYMBOLS
Followup: MachineOwner
---------
------------------------------------------------------------------------------------------------------------------
Kaspersky Crashdump:
Microsoft (R) Windows Debugger Version 6.7.0005.1
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File
[C:\Users\HBX\AppData\Local\Temp\WER4F97.tmp\Mini080607-03.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: *** Invalid ***
****************************************************************************
* Symbol loading may be unreliable without a symbol search path. *
* Use .symfix to have the debugger choose a symbol path. *
* After setting your symbol path, use .reload to refresh symbol locations. *
****************************************************************************
Executable search path is:
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for
ntoskrnl.exe
Windows Vista Kernel Version 6000 MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Kernel base = 0xfffff800`02800000 PsLoadedModuleList = 0xfffff800`0299af50
Debug session time: Mon Aug 6 17:18:29.628 2007 (GMT-4)
System Uptime: 0 days 0:06:47.145
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for
ntoskrnl.exe
Loading Kernel Symbols
.....................................................................................................................................................
Loading User Symbols
Loading unloaded module list
.......
*******************************************************************************
*
*
* Bugcheck Analysis
*
*
*
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck C4, {3d, 0, 0, fffff98020a35c14}
Unable to load image \SystemRoot\system32\DRIVERS\klif.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for klif.sys
*** ERROR: Module load completed but symbols could not be loaded for
klif.sys
***** Kernel symbols are WRONG. Please fix symbols to do analysis.
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
Probably caused by : klif.sys ( klif+23c14 )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
*
*
* Bugcheck Analysis
*
*
*
*******************************************************************************
DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
A device driver attempting to corrupt the system has been caught. This is
because the driver was specified in the registry as being suspect (by the
administrator) and the kernel has enabled substantial checking of this
driver.
If the driver attempts to corrupt the system, bugchecks 0xC4, 0xC1 and 0xA
will
be among the most commonly seen crashes.
Parameter 1 = 0x1000 .. 0x1020 - deadlock verifier error codes.
Typically the code is 0x1001 (deadlock detected) and you can
issue a '!deadlock' KD command to get more information.
Arguments:
Arg1: 000000000000003d, ERESOURCE address is unaligned.
Arg2: 0000000000000000, 0
Arg3: 0000000000000000, 0
Arg4: fffff98020a35c14, bad resource address passed in.
Debugging Details:
------------------
***** Kernel symbols are WRONG. Please fix symbols to do analysis.
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
MODULE_NAME: klif
FAULTING_MODULE: fffff80002800000 nt
DEBUG_FLR_IMAGE_TIMESTAMP: 4649721f
BUGCHECK_STR: 0xc4_3d
CUSTOMER_CRASH_COUNT: 3
DEFAULT_BUCKET_ID: WRONG_SYMBOLS
LAST_CONTROL_TRANSFER: from fffff80002c0937d to fffff8000284dbd0
STACK_TEXT:
fffff980`1f090578 fffff800`02c0937d : 00000000`000000c4 00000000`0000003d
00000000`00000000 00000000`00000000 : nt+0x4dbd0
fffff980`1f090580 00000000`000000c4 : 00000000`0000003d 00000000`00000000
00000000`00000000 fffff980`20a35c14 : nt+0x40937d
fffff980`1f090588 00000000`0000003d : 00000000`00000000 00000000`00000000
fffff980`20a35c14 00000000`00000000 : 0xc4
fffff980`1f090590 00000000`00000000 : 00000000`00000000 fffff980`20a35c14
00000000`00000000 fffff980`20a35c14 : 0x3d
fffff980`1f090598 00000000`00000000 : fffff980`20a35c14 00000000`00000000
fffff980`20a35c14 fffff800`02c0a22e : 0x0
fffff980`1f0905a0 fffff980`20a35c14 : 00000000`00000000 fffff980`20a35c14
fffff800`02c0a22e 00000000`00000000 : 0x0
fffff980`1f0905a8 00000000`00000000 : fffff980`20a35c14 fffff800`02c0a22e
00000000`00000000 00000000`00000000 : klif+0x23c14
fffff980`1f0905b0 fffff980`20a35c14 : fffff800`02c0a22e 00000000`00000000
00000000`00000000 00000000`00000000 : 0x0
fffff980`1f0905b8 fffff800`02c0a22e : 00000000`00000000 00000000`00000000
00000000`00000000 00000000`00000000 : klif+0x23c14
fffff980`1f0905c0 00000000`00000000 : 00000000`00000000 00000000`00000000
00000000`00000000 fffff980`20a35c14 : nt+0x40a22e
fffff980`1f0905c8 00000000`00000000 : 00000000`00000000 00000000`00000000
fffff980`20a35c14 00000000`00000000 : 0x0
fffff980`1f0905d0 00000000`00000000 : 00000000`00000000 fffff980`20a35c14
00000000`00000000 fffff980`20a35c14 : 0x0
fffff980`1f0905d8 00000000`00000000 : fffff980`20a35c14 00000000`00000000
fffff980`20a35c14 fffff800`02c188b4 : 0x0
fffff980`1f0905e0 fffff980`20a35c14 : 00000000`00000000 fffff980`20a35c14
fffff800`02c188b4 fffff980`58bdef01 : 0x0
fffff980`1f0905e8 00000000`00000000 : fffff980`20a35c14 fffff800`02c188b4
fffff980`58bdef01 00000000`00000000 : klif+0x23c14
fffff980`1f0905f0 fffff980`20a35c14 : fffff800`02c188b4 fffff980`58bdef01
00000000`00000000 00000000`00000000 : 0x0
fffff980`1f0905f8 fffff800`02c188b4 : fffff980`58bdef01 00000000`00000000
00000000`00000000 00000000`00000000 : klif+0x23c14
fffff980`1f090600 fffff980`58bdef01 : 00000000`00000000 00000000`00000000
00000000`00000000 fffff980`1f090780 : nt+0x4188b4
fffff980`1f090608 00000000`00000000 : 00000000`00000000 00000000`00000000
fffff980`1f090780 fffff980`20a1a0c7 : 0xfffff980`58bdef01
fffff980`1f090610 00000000`00000000 : 00000000`00000000 fffff980`1f090780
fffff980`20a1a0c7 fffff980`58bdef01 : 0x0
fffff980`1f090618 00000000`00000000 : fffff980`1f090780 fffff980`20a1a0c7
fffff980`58bdef01 00000000`00000000 : 0x0
fffff980`1f090620 fffff980`1f090780 : fffff980`20a1a0c7 fffff980`58bdef01
00000000`00000000 00000000`00000000 : 0x0
fffff980`1f090628 fffff980`20a1a0c7 : fffff980`58bdef01 00000000`00000000
00000000`00000000 00000000`00000000 : 0xfffff980`1f090780
fffff980`1f090630 fffff980`58bdef01 : 00000000`00000000 00000000`00000000
00000000`00000000 00000000`00000000 : klif+0x80c7
fffff980`1f090638 00000000`00000000 : 00000000`00000000 00000000`00000000
00000000`00000000 fffff980`20a148f9 : 0xfffff980`58bdef01
fffff980`1f090640 00000000`00000000 : 00000000`00000000 00000000`00000000
fffff980`20a148f9 00000000`00000000 : 0x0
fffff980`1f090648 00000000`00000000 : 00000000`00000000 fffff980`20a148f9
00000000`00000000 00000000`00000000 : 0x0
fffff980`1f090650 00000000`00000000 : fffff980`20a148f9 00000000`00000000
00000000`00000000 fffff980`58bdef60 : 0x0
fffff980`1f090658 fffff980`20a148f9 : 00000000`00000000 00000000`00000000
fffff980`58bdef60 00000000`00000000 : 0x0
fffff980`1f090660 00000000`00000000 : 00000000`00000000 fffff980`58bdef60
00000000`00000000 00000000`00000000 : klif+0x28f9
fffff980`1f090668 00000000`00000000 : fffff980`58bdef60 00000000`00000000
00000000`00000000 00000000`00000000 : 0x0
fffff980`1f090670 fffff980`58bdef60 : 00000000`00000000 00000000`00000000
00000000`00000000 00000000`00000000 : 0x0
fffff980`1f090678 00000000`00000000 : 00000000`00000000 00000000`00000000
00000000`00000000 00000000`00000000 : 0xfffff980`58bdef60
fffff980`1f090680 00000000`00000000 : 00000000`00000000 00000000`00000000
00000000`00000000 fffff980`20a35000 : 0x0
fffff980`1f090688 00000000`00000000 : 00000000`00000000 00000000`00000000
fffff980`20a35000 00000000`0088f880 : 0x0
fffff980`1f090690 00000000`00000000 : 00000000`00000000 fffff980`20a35000
00000000`0088f880 00000000`0088f870 : 0x0
fffff980`1f090698 00000000`00000000 : fffff980`20a35000 00000000`0088f880
00000000`0088f870 00000000`c00000bb : 0x0
fffff980`1f0906a0 fffff980`20a35000 : 00000000`0088f880 00000000`0088f870
00000000`c00000bb fffff980`55fb8ee0 : 0x0
fffff980`1f0906a8 00000000`0088f880 : 00000000`0088f870 00000000`c00000bb
fffff980`55fb8ee0 fffff800`02a91ac0 : klif+0x23000
fffff980`1f0906b0 00000000`0088f870 : 00000000`c00000bb fffff980`55fb8ee0
fffff800`02a91ac0 fffff980`55fb8ee0 : 0x88f880
fffff980`1f0906b8 00000000`c00000bb : fffff980`55fb8ee0 fffff800`02a91ac0
fffff980`55fb8ee0 fffff980`20a16e71 : 0x88f870
fffff980`1f0906c0 fffff980`55fb8ee0 : fffff800`02a91ac0 fffff980`55fb8ee0
fffff980`20a16e71 fffff980`55fb8ee0 : 0xc00000bb
fffff980`1f0906c8 fffff800`02a91ac0 : fffff980`55fb8ee0 fffff980`20a16e71
fffff980`55fb8ee0 00000000`00000030 : 0xfffff980`55fb8ee0
fffff980`1f0906d0 fffff980`55fb8ee0 : fffff980`20a16e71 fffff980`55fb8ee0
00000000`00000030 00000000`00000000 : nt+0x291ac0
fffff980`1f0906d8 fffff980`20a16e71 : fffff980`55fb8ee0 00000000`00000030
00000000`00000000 00000000`c000000d : 0xfffff980`55fb8ee0
fffff980`1f0906e0 fffff980`55fb8ee0 : 00000000`00000030 00000000`00000000
00000000`c000000d fffff980`58bdef60 : klif+0x4e71
fffff980`1f0906e8 00000000`00000030 : 00000000`00000000 00000000`c000000d
fffff980`58bdef60 fffff800`028934db : 0xfffff980`55fb8ee0
fffff980`1f0906f0 00000000`00000000 : 00000000`c000000d fffff980`58bdef60
fffff800`028934db 00000000`00000000 : 0x30
fffff980`1f0906f8 00000000`c000000d : fffff980`58bdef60 fffff800`028934db
00000000`00000000 fffff800`02a924a4 : 0x0
fffff980`1f090700 fffff980`58bdef60 : fffff800`028934db 00000000`00000000
fffff800`02a924a4 00000000`00000002 : 0xc000000d
fffff980`1f090708 fffff800`028934db : 00000000`00000000 fffff800`02a924a4
00000000`00000002 fffff980`00000000 : 0xfffff980`58bdef60
fffff980`1f090710 00000000`00000000 : fffff800`02a924a4 00000000`00000002
fffff980`00000000 fffff980`1f0907e8 : nt+0x934db
fffff980`1f090718 fffff800`02a924a4 : 00000000`00000002 fffff980`00000000
fffff980`1f0907e8 fffff800`028934db : 0x0
fffff980`1f090720 00000000`00000002 : fffff980`00000000 fffff980`1f0907e8
fffff800`028934db fffff980`1f0907f0 : nt+0x2924a4
fffff980`1f090728 fffff980`00000000 : fffff980`1f0907e8 fffff800`028934db
fffff980`1f0907f0 fffff800`028934db : 0x2
fffff980`1f090730 fffff980`1f0907e8 : fffff800`028934db fffff980`1f0907f0
fffff800`028934db 00000000`00000000 : 0xfffff980`00000000
fffff980`1f090738 fffff800`028934db : fffff980`1f0907f0 fffff800`028934db
00000000`00000000 fffff880`00100003 : 0xfffff980`1f0907e8
fffff980`1f090740 fffff980`1f0907f0 : fffff800`028934db 00000000`00000000
fffff880`00100003 fffff980`00000001 : nt+0x934db
fffff980`1f090748 fffff800`028934db : 00000000`00000000 fffff880`00100003
fffff980`00000001 fffff800`02894104 : 0xfffff980`1f0907f0
fffff980`1f090750 00000000`00000000 : fffff880`00100003 fffff980`00000001
fffff800`02894104 fffff980`1f090828 : nt+0x934db
fffff980`1f090758 fffff880`00100003 : fffff980`00000001 fffff800`02894104
fffff980`1f090828 fffff800`028934db : 0x0
fffff980`1f090760 fffff980`00000001 : fffff800`02894104 fffff980`1f090828
fffff800`028934db 000003b6`0000038d : 0xfffff880`00100003
fffff980`1f090768 fffff800`02894104 : fffff980`1f090828 fffff800`028934db
000003b6`0000038d 00000000`00004200 : 0xfffff980`00000001
fffff980`1f090770 fffff980`1f090828 : fffff800`028934db 000003b6`0000038d
00000000`00004200 00000000`00000003 : nt+0x94104
fffff980`1f090778 fffff800`028934db : 000003b6`0000038d 00000000`00004200
00000000`00000003 00000000`00000000 : 0xfffff980`1f090828
fffff980`1f090780 000003b6`0000038d : 00000000`00004200 00000000`00000003
00000000`00000000 fffff980`1f090858 : nt+0x934db
fffff980`1f090788 00000000`00004200 : 00000000`00000003 00000000`00000000
fffff980`1f090858 fffff800`02894104 : 0x3b6`0000038d
fffff980`1f090790 00000000`00000003 : 00000000`00000000 fffff980`1f090858
fffff800`02894104 fffff980`1f090860 : 0x4200
fffff980`1f090798 00000000`00000000 : fffff980`1f090858 fffff800`02894104
fffff980`1f090860 00000000`00000000 : 0x3
fffff980`1f0907a0 fffff980`1f090858 : fffff800`02894104 fffff980`1f090860
00000000`00000000 00000000`00000000 : 0x0
fffff980`1f0907a8 fffff800`02894104 : fffff980`1f090860 00000000`00000000
00000000`00000000 fffff800`0280d194 : 0xfffff980`1f090858
fffff980`1f0907b0 fffff980`1f090860 : 00000000`00000000 00000000`00000000
fffff800`0280d194 00000000`00000003 : nt+0x94104
fffff980`1f0907b8 00000000`00000000 : 00000000`00000000 fffff800`0280d194
00000000`00000003 fffff800`0280d194 : 0xfffff980`1f090860
fffff980`1f0907c0 00000000`00000000 : fffff800`0280d194 00000000`00000003
fffff800`0280d194 00000000`00000000 : 0x0
fffff980`1f0907c8 fffff800`0280d194 : 00000000`00000003 fffff800`0280d194
00000000`00000000 fffff800`0288422f : 0x0
STACK_COMMAND: kb
FOLLOWUP_IP:
klif+23c14
fffff980`20a35c14 98 cwde
SYMBOL_STACK_INDEX: 6
FOLLOWUP_NAME: MachineOwner
IMAGE_NAME: klif.sys
SYMBOL_NAME: klif+23c14
BUCKET_ID: WRONG_SYMBOLS
Followup: MachineOwner
---------
----------------------------------------------------------------------------------------------------------------
Kerio firewall Crashdump : (happened after installation - Reboot-)
Microsoft (R) Windows Debugger Version 6.7.0005.1
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File
[C:\Users\HBX\AppData\Local\Temp\WER120.tmp\Mini080807-02.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: *** Invalid ***
****************************************************************************
* Symbol loading may be unreliable without a symbol search path. *
* Use .symfix to have the debugger choose a symbol path. *
* After setting your symbol path, use .reload to refresh symbol locations. *
****************************************************************************
Executable search path is:
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for
ntoskrnl.exe
Windows Vista Kernel Version 6000 MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Kernel base = 0xfffff800`02800000 PsLoadedModuleList = 0xfffff800`0299af50
Debug session time: Wed Aug 8 22:30:50.096 2007 (GMT-4)
System Uptime: 0 days 2:24:44.160
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for
ntoskrnl.exe
Loading Kernel Symbols
..........................................................................................................................................................
Loading User Symbols
Loading unloaded module list
........
*******************************************************************************
*
*
* Bugcheck Analysis
*
*
*
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck C4, {3b, 2, fffff9800d954fc8, 0}
Unable to load image \SystemRoot\System32\drivers\tcpip.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for tcpip.sys
*** ERROR: Module load completed but symbols could not be loaded for
tcpip.sys
Unable to load image \SystemRoot\system32\drivers\NETIO.SYS, Win32 error 0n2
*** WARNING: Unable to verify timestamp for NETIO.SYS
*** ERROR: Module load completed but symbols could not be loaded for
NETIO.SYS
Unable to load image \SystemRoot\system32\DRIVERS\kvpndrv.sys, Win32 error
0n2
*** WARNING: Unable to verify timestamp for kvpndrv.sys
*** ERROR: Module load completed but symbols could not be loaded for
kvpndrv.sys
***** Kernel symbols are WRONG. Please fix symbols to do analysis.
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
Probably caused by : NETIO.SYS ( NETIO+bdd5 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
*
*
* Bugcheck Analysis
*
*
*
*******************************************************************************
DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
A device driver attempting to corrupt the system has been caught. This is
because the driver was specified in the registry as being suspect (by the
administrator) and the kernel has enabled substantial checking of this
driver.
If the driver attempts to corrupt the system, bugchecks 0xC4, 0xC1 and 0xA
will
be among the most commonly seen crashes.
Parameter 1 = 0x1000 .. 0x1020 - deadlock verifier error codes.
Typically the code is 0x1001 (deadlock detected) and you can
issue a '!deadlock' KD command to get more information.
Arguments:
Arg1: 000000000000003b, KeWaitXxx routine is being called at DISPATCH_LEVEL
or higher.
Arg2: 0000000000000002, current irql,
Arg3: fffff9800d954fc8, object to wait on,
Arg4: 0000000000000000, time out parameter.
Debugging Details:
------------------
***** Kernel symbols are WRONG. Please fix symbols to do analysis.
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
MODULE_NAME: NETIO
FAULTING_MODULE: fffff80002800000 nt
DEBUG_FLR_IMAGE_TIMESTAMP: 4549beb1
BUGCHECK_STR: 0xc4_3b
CURRENT_IRQL: 2
CUSTOMER_CRASH_COUNT: 2
DEFAULT_BUCKET_ID: WRONG_SYMBOLS
LAST_CONTROL_TRANSFER: from fffff80002c0937d to fffff8000284dbd0
STACK_TEXT:
fffff980`00eacab8 fffff800`02c0937d : 00000000`000000c4 00000000`0000003b
00000000`00000002 fffff980`0d954fc8 : nt+0x4dbd0
fffff980`00eacac0 00000000`000000c4 : 00000000`0000003b 00000000`00000002
fffff980`0d954fc8 00000000`00000000 : nt+0x40937d
fffff980`00eacac8 00000000`0000003b : 00000000`00000002 fffff980`0d954fc8
00000000`00000000 fffff800`0289bf5d : 0xc4
fffff980`00eacad0 00000000`00000002 : fffff980`0d954fc8 00000000`00000000
fffff800`0289bf5d 00000000`00000002 : 0x3b
fffff980`00eacad8 fffff980`0d954fc8 : 00000000`00000000 fffff800`0289bf5d
00000000`00000002 fffff800`02c229d3 : 0x2
fffff980`00eacae0 00000000`00000000 : fffff800`0289bf5d 00000000`00000002
fffff800`02c229d3 00000000`00000000 : 0xfffff980`0d954fc8
fffff980`00eacae8 fffff800`0289bf5d : 00000000`00000002 fffff800`02c229d3
00000000`00000000 00000000`00000000 : 0x0
fffff980`00eacaf0 00000000`00000002 : fffff800`02c229d3 00000000`00000000
00000000`00000000 00000000`00000003 : nt+0x9bf5d
fffff980`00eacaf8 fffff800`02c229d3 : 00000000`00000000 00000000`00000000
00000000`00000003 fffff800`02c0a79a : 0x2
fffff980`00eacb00 00000000`00000000 : 00000000`00000000 00000000`00000003
fffff800`02c0a79a 00000000`00000000 : nt+0x4229d3
fffff980`00eacb08 00000000`00000000 : 00000000`00000003 fffff800`02c0a79a
00000000`00000000 00000000`00000001 : 0x0
fffff980`00eacb10 00000000`00000003 : fffff800`02c0a79a 00000000`00000000
00000000`00000001 00000000`00000010 : 0x0
fffff980`00eacb18 fffff800`02c0a79a : 00000000`00000000 00000000`00000001
00000000`00000010 fffff980`0d954f40 : 0x3
fffff980`00eacb20 00000000`00000000 : 00000000`00000001 00000000`00000010
fffff980`0d954f40 fffff980`0d3b80f0 : nt+0x40a79a
fffff980`00eacb28 00000000`00000001 : 00000000`00000010 fffff980`0d954f40
fffff980`0d3b80f0 fffff980`00674dd5 : 0x0
fffff980`00eacb30 00000000`00000010 : fffff980`0d954f40 fffff980`0d3b80f0
fffff980`00674dd5 fffff980`0d954fc8 : 0x1
fffff980`00eacb38 fffff980`0d954f40 : fffff980`0d3b80f0 fffff980`00674dd5
fffff980`0d954fc8 fffff980`00eacbe0 : 0x10
fffff980`00eacb40 fffff980`0d3b80f0 : fffff980`00674dd5 fffff980`0d954fc8
fffff980`00eacbe0 00000000`00000580 : 0xfffff980`0d954f40
fffff980`00eacb48 fffff980`00674dd5 : fffff980`0d954fc8 fffff980`00eacbe0
00000000`00000580 fffff800`02968998 : tcpip+0xf00f0
fffff980`00eacb50 fffff980`0d954fc8 : fffff980`00eacbe0 00000000`00000580
fffff800`02968998 00000000`00000000 : NETIO+0xbdd5
fffff980`00eacb58 fffff980`00eacbe0 : 00000000`00000580 fffff800`02968998
00000000`00000000 00000000`00000000 : 0xfffff980`0d954fc8
fffff980`00eacb60 00000000`00000580 : fffff800`02968998 00000000`00000000
00000000`00000000 00000000`0d269902 : 0xfffff980`00eacbe0
fffff980`00eacb68 fffff800`02968998 : 00000000`00000000 00000000`00000000
00000000`0d269902 00000000`00000000 : 0x580
fffff980`00eacb70 00000000`00000000 : 00000000`00000000 00000000`0d269902
00000000`00000000 fffffa80`04e3a920 : nt+0x168998
fffff980`00eacb78 00000000`00000000 : 00000000`0d269902 00000000`00000000
fffffa80`04e3a920 00000000`00000000 : 0x0
fffff980`00eacb80 00000000`0d269902 : 00000000`00000000 fffffa80`04e3a920
00000000`00000000 00000000`00000001 : 0x0
fffff980`00eacb88 00000000`00000000 : fffffa80`04e3a920 00000000`00000000
00000000`00000001 fffffa80`02130720 : 0xd269902
fffff980`00eacb90 fffffa80`04e3a920 : 00000000`00000000 00000000`00000001
fffffa80`02130720 fffff980`31922ec0 : 0x0
fffff980`00eacb98 00000000`00000000 : 00000000`00000001 fffffa80`02130720
fffff980`31922ec0 fffff980`006912af : 0xfffffa80`04e3a920
fffff980`00eacba0 00000000`00000001 : fffffa80`02130720 fffff980`31922ec0
fffff980`006912af fffff800`02968998 : 0x0
fffff980`00eacba8 fffffa80`02130720 : fffff980`31922ec0 fffff980`006912af
fffff800`02968998 00000000`00000000 : 0x1
fffff980`00eacbb0 fffff980`31922ec0 : fffff980`006912af fffff800`02968998
00000000`00000000 fffff980`1e518fe0 : 0xfffffa80`02130720
fffff980`00eacbb8 fffff980`006912af : fffff800`02968998 00000000`00000000
fffff980`1e518fe0 00000000`00000000 : 0xfffff980`31922ec0
fffff980`00eacbc0 fffff800`02968998 : 00000000`00000000 fffff980`1e518fe0
00000000`00000000 00000000`00000000 : NETIO+0x282af
fffff980`00eacbc8 00000000`00000000 : fffff980`1e518fe0 00000000`00000000
00000000`00000000 fffff980`006a35b0 : nt+0x168998
fffff980`00eacbd0 fffff980`1e518fe0 : 00000000`00000000 00000000`00000000
fffff980`006a35b0 00000000`00000010 : 0x0
fffff980`00eacbd8 00000000`00000000 : 00000000`00000000 fffff980`006a35b0
00000000`00000010 fffff980`3191cfb0 : 0xfffff980`1e518fe0
fffff980`00eacbe0 00000000`00000000 : fffff980`006a35b0 00000000`00000010
fffff980`3191cfb0 fffff980`0a12ce80 : 0x0
fffff980`00eacbe8 fffff980`006a35b0 : 00000000`00000010 fffff980`3191cfb0
fffff980`0a12ce80 fffff980`006914b1 : 0x0
fffff980`00eacbf0 00000000`00000010 : fffff980`3191cfb0 fffff980`0a12ce80
fffff980`006914b1 fffffa80`02130720 : NETIO+0x3a5b0
fffff980`00eacbf8 fffff980`3191cfb0 : fffff980`0a12ce80 fffff980`006914b1
fffffa80`02130720 00000000`00000000 : 0x10
fffff980`00eacc00 fffff980`0a12ce80 : fffff980`006914b1 fffffa80`02130720
00000000`00000000 fffff980`0521ca04 : 0xfffff980`3191cfb0
fffff980`00eacc08 fffff980`006914b1 : fffffa80`02130720 00000000`00000000
fffff980`0521ca04 00000000`00000001 : 0xfffff980`0a12ce80
fffff980`00eacc10 fffffa80`02130720 : 00000000`00000000 fffff980`0521ca04
00000000`00000001 fffff980`0521fc3c : NETIO+0x284b1
fffff980`00eacc18 00000000`00000000 : fffff980`0521ca04 00000000`00000001
fffff980`0521fc3c fffff980`0521ca40 : 0xfffffa80`02130720
fffff980`00eacc20 fffff980`0521ca04 : 00000000`00000001 fffff980`0521fc3c
fffff980`0521ca40 fffff980`0a12ce50 : 0x0
fffff980`00eacc28 00000000`00000001 : fffff980`0521fc3c fffff980`0521ca40
fffff980`0a12ce50 fffff800`028685e0 : kvpndrv+0x7a04
fffff980`00eacc30 fffff980`0521fc3c : fffff980`0521ca40 fffff980`0a12ce50
fffff800`028685e0 00000000`00000000 : 0x1
fffff980`00eacc38 fffff980`0521ca40 : fffff980`0a12ce50 fffff800`028685e0
00000000`00000000 fffff980`7cf82f70 : kvpndrv+0xac3c
fffff980`00eacc40 fffff980`0a12ce50 : fffff800`028685e0 00000000`00000000
fffff980`7cf82f70 fffff980`0000000a : kvpndrv+0x7a40
fffff980`00eacc48 fffff800`028685e0 : 00000000`00000000 fffff980`7cf82f70
fffff980`0000000a fffff800`0294a980 : 0xfffff980`0a12ce50
fffff980`00eacc50 00000000`00000000 : fffff980`7cf82f70 fffff980`0000000a
fffff800`0294a980 fffff880`04538008 : nt+0x685e0
fffff980`00eacc58 fffff980`7cf82f70 : fffff980`0000000a fffff800`0294a980
fffff880`04538008 fffff800`02acb398 : 0x0
fffff980`00eacc60 fffff980`0000000a : fffff800`0294a980 fffff880`04538008
fffff800`02acb398 fffff980`1e518fe0 : 0xfffff980`7cf82f70
fffff980`00eacc68 fffff800`0294a980 : fffff880`04538008 fffff800`02acb398
fffff980`1e518fe0 fffff980`0521fc3c : 0xfffff980`0000000a
fffff980`00eacc70 fffff880`04538008 : fffff800`02acb398 fffff980`1e518fe0
fffff980`0521fc3c fffffa80`02130720 : nt+0x14a980
fffff980`00eacc78 fffff800`02acb398 : fffff980`1e518fe0 fffff980`0521fc3c
fffffa80`02130720 fffff800`02968998 : 0xfffff880`04538008
fffff980`00eacc80 fffff980`1e518fe0 : fffff980`0521fc3c fffffa80`02130720
fffff800`02968998 fffff980`1e518fe0 : nt+0x2cb398
fffff980`00eacc88 fffff980`0521fc3c : fffffa80`02130720 fffff800`02968998
fffff980`1e518fe0 fffff980`0521fc4c : 0xfffff980`1e518fe0
fffff980`00eacc90 fffffa80`02130720 : fffff800`02968998 fffff980`1e518fe0
fffff980`0521fc4c 00000000`00000001 : kvpndrv+0xac3c
fffff980`00eacc98 fffff800`02968998 : fffff980`1e518fe0 fffff980`0521fc4c
00000000`00000001 00000000`00000000 : 0xfffffa80`02130720
fffff980`00eacca0 fffff980`1e518fe0 : fffff980`0521fc4c 00000000`00000001
00000000`00000000 fffff800`02aa6490 : nt+0x168998
fffff980`00eacca8 fffff980`0521fc4c : 00000000`00000001 00000000`00000000
fffff800`02aa6490 fffffa80`02130720 : 0xfffff980`1e518fe0
fffff980`00eaccb0 00000000`00000001 : 00000000`00000000 fffff800`02aa6490
fffffa80`02130720 fffff980`2ef44fe0 : kvpndrv+0xac4c
fffff980`00eaccb8 00000000`00000000 : fffff800`02aa6490 fffffa80`02130720
fffff980`2ef44fe0 fffff800`02859ca3 : 0x1
fffff980`00eaccc0 fffff800`02aa6490 : fffffa80`02130720 fffff980`2ef44fe0
fffff800`02859ca3 fffff800`029d20c0 : 0x0
fffff980`00eaccc8 fffffa80`02130720 : fffff980`2ef44fe0 fffff800`02859ca3
fffff800`029d20c0 fffff800`02968901 : nt+0x2a6490
fffff980`00eaccd0 fffff980`2ef44fe0 : fffff800`02859ca3 fffff800`029d20c0
fffff800`02968901 fffffa80`02130700 : 0xfffffa80`02130720
fffff980`00eaccd8 fffff800`02859ca3 : fffff800`029d20c0 fffff800`02968901
fffffa80`02130700 00000000`00000000 : 0xfffff980`2ef44fe0
fffff980`00eacce0 fffff800`029d20c0 : fffff800`02968901 fffffa80`02130700
00000000`00000000 fffff980`00eacd50 : nt+0x59ca3
fffff980`00eacce8 fffff800`02968901 : fffffa80`02130700 00000000`00000000
fffff980`00eacd50 00000000`00000001 : nt+0x1d20c0
fffff980`00eaccf0 fffffa80`02130700 : 00000000`00000000 fffff980`00eacd50
00000000`00000001 fffff980`00c66bc0 : nt+0x168901
fffff980`00eaccf8 00000000`00000000 : fffff980`00eacd50 00000000`00000001
fffff980`00c66bc0 fffffa80`020fc430 : 0xfffffa80`02130700
fffff980`00eacd00 fffff980`00eacd50 : 00000000`00000001 fffff980`00c66bc0
fffffa80`020fc430 00000000`00000000 : 0x0
fffff980`00eacd08 00000000`00000001 : fffff980`00c66bc0 fffffa80`020fc430
00000000`00000000 fffff800`02859b80 : 0xfffff980`00eacd50
STACK_COMMAND: kb
FOLLOWUP_IP:
NETIO+bdd5
fffff980`00674dd5 ?? ???
SYMBOL_STACK_INDEX: 13
FOLLOWUP_NAME: MachineOwner
IMAGE_NAME: NETIO.SYS
SYMBOL_NAME: NETIO+bdd5
BUCKET_ID: WRONG_SYMBOLS
Followup: MachineOwner
---------
After installing both the updates from the Microsoft site (first from
connect then from Microsoft.com), I started to receive BSODS things that I
had installed were Kaspersky and Jetico Firewall both the versions that are
compatibile with x64 vista, mind you that before the updates everything was
running solid, and very stable no issues what so ever. After doing the
updates I came across these crashes, so I was stumpped I could'nt think of
what was making it BSOD so I deciced to investigate further I installed the
x64 debugging toolkit and started to look at the memory dumps and the
minidumps and come to find out it was klif.sys which is from Kaspersky and
bc_ngn.sys which is from Jetico. Seems Microsoft is either eliminating the
competition or there just eliminating poorly written drivers. Now funny
thing is that I run NOD32 as of now no issues what so ever and NOD32 is an
older antivirus toolkit than the earlier tools I had installed. If anyone
else is experiencing issues like this please repost ASAP so these issues are
stated back to Microsoft. I do want to say that working on Vista is a
pleasure out of all the releases of Windows I think that Vista is at its
prime and is suiting its name. I will post the dumps and my system specs.
Concerned Microsoft Evangalist.
Pablo R.
Pacoxfl@hotmail.com
System Specs:
OS Name Microsoft® Windows VistaT Ultimate
Version 6.0.6000 Build 6000
Other OS Description Not Available
OS Manufacturer Microsoft Corporation
System Name HBX-PC
System Manufacturer Gateway
System Model GT5058
System Type x64-based PC
Processor AMD Athlon(tm) 64 X2 Dual Core Processor 3800+, 2000 Mhz, 2
Core(s), 2 Logical Processor(s)
BIOS Version/Date Phoenix Technologies, LTD 6.00 PG, 2/10/2006
SMBIOS Version 2.2
Windows Directory C:\Windows
System Directory C:\Windows\system32
Boot Device \Device\HarddiskVolume2
Locale United States
Hardware Abstraction Layer Version = "6.0.6000.16386"
User Name HBX-PC\HBX
Time Zone Eastern Daylight Time
Total Physical Memory 2,045.94 MB
Available Physical Memory 575.52 MB
Total Virtual Memory 4.22 GB
Available Virtual Memory 2.04 GB
Page File Space 2.29 GB
Page File C:\pagefile.sys
----------------------------------------------------------------------------------------------------------------
Jetico Crash dump: -->
Microsoft (R) Windows Debugger Version 6.7.0005.1
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File
[C:\Users\HBX\AppData\Local\Temp\WER921C.tmp\Mini080507-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: *** Invalid ***
****************************************************************************
* Symbol loading may be unreliable without a symbol search path. *
* Use .symfix to have the debugger choose a symbol path. *
* After setting your symbol path, use .reload to refresh symbol locations. *
****************************************************************************
Executable search path is:
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for
ntoskrnl.exe
Windows Vista Kernel Version 6000 MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Kernel base = 0xfffff800`02800000 PsLoadedModuleList = 0xfffff800`0299af50
Debug session time: Sun Aug 5 21:05:20.893 2007 (GMT-4)
System Uptime: 0 days 0:08:00.409
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for
ntoskrnl.exe
Loading Kernel Symbols
............................................................................................................................................................
Loading User Symbols
Loading unloaded module list
........
*******************************************************************************
*
*
* Bugcheck Analysis
*
*
*
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck C4, {81, fffffa80037d0dd0, a, 0}
Unable to load image \SystemRoot\System32\Drivers\bc_ngn.sys, Win32 error
0n2
*** WARNING: Unable to verify timestamp for bc_ngn.sys
*** ERROR: Module load completed but symbols could not be loaded for
bc_ngn.sys
***** Kernel symbols are WRONG. Please fix symbols to do analysis.
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
Probably caused by : bc_ngn.sys ( bc_ngn+2a4d )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
*
*
* Bugcheck Analysis
*
*
*
*******************************************************************************
DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
A device driver attempting to corrupt the system has been caught. This is
because the driver was specified in the registry as being suspect (by the
administrator) and the kernel has enabled substantial checking of this
driver.
If the driver attempts to corrupt the system, bugchecks 0xC4, 0xC1 and 0xA
will
be among the most commonly seen crashes.
Parameter 1 = 0x1000 .. 0x1020 - deadlock verifier error codes.
Typically the code is 0x1001 (deadlock detected) and you can
issue a '!deadlock' KD command to get more information.
Arguments:
Arg1: 0000000000000081, MmMapLockedPages called without MDL_MAPPING_CAN_FAIL
Arg2: fffffa80037d0dd0, MDL address.
Arg3: 000000000000000a, MDL flags.
Arg4: 0000000000000000, 0.
Debugging Details:
------------------
***** Kernel symbols are WRONG. Please fix symbols to do analysis.
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
MODULE_NAME: bc_ngn
FAULTING_MODULE: fffff80002800000 nt
DEBUG_FLR_IMAGE_TIMESTAMP: 46568106
BUGCHECK_STR: 0xc4_81
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WRONG_SYMBOLS
LAST_CONTROL_TRANSFER: from fffff80002c0937d to fffff8000284dbd0
STACK_TEXT:
fffff980`26f158d8 fffff800`02c0937d : 00000000`000000c4 00000000`00000081
fffffa80`037d0dd0 00000000`0000000a : nt+0x4dbd0
fffff980`26f158e0 00000000`000000c4 : 00000000`00000081 fffffa80`037d0dd0
00000000`0000000a 00000000`00000000 : nt+0x40937d
fffff980`26f158e8 00000000`00000081 : fffffa80`037d0dd0 00000000`0000000a
00000000`00000000 fffff800`02a8f017 : 0xc4
fffff980`26f158f0 fffffa80`037d0dd0 : 00000000`0000000a 00000000`00000000
fffff800`02a8f017 fffffa80`037d0dd0 : 0x81
fffff980`26f158f8 00000000`0000000a : 00000000`00000000 fffff800`02a8f017
fffffa80`037d0dd0 fffff800`02c195bd : 0xfffffa80`037d0dd0
fffff980`26f15900 00000000`00000000 : fffff800`02a8f017 fffffa80`037d0dd0
fffff800`02c195bd fffffa80`037d0dd0 : 0xa
fffff980`26f15908 fffff800`02a8f017 : fffffa80`037d0dd0 fffff800`02c195bd
fffffa80`037d0dd0 00000000`000000c4 : 0x0
fffff980`26f15910 fffffa80`037d0dd0 : fffff800`02c195bd fffffa80`037d0dd0
00000000`000000c4 00000000`0000000d : nt+0x28f017
fffff980`26f15918 fffff800`02c195bd : fffffa80`037d0dd0 00000000`000000c4
00000000`0000000d 00000000`00000002 : 0xfffffa80`037d0dd0
fffff980`26f15920 fffffa80`037d0dd0 : 00000000`000000c4 00000000`0000000d
00000000`00000002 00000000`00000000 : nt+0x4195bd
fffff980`26f15928 00000000`000000c4 : 00000000`0000000d 00000000`00000002
00000000`00000000 00000000`00000001 : 0xfffffa80`037d0dd0
fffff980`26f15930 00000000`0000000d : 00000000`00000002 00000000`00000000
00000000`00000001 fffff980`2d296ee0 : 0xc4
fffff980`26f15938 00000000`00000002 : 00000000`00000000 00000000`00000001
fffff980`2d296ee0 fffff980`00477a4d : 0xd
fffff980`26f15940 00000000`00000000 : 00000000`00000001 fffff980`2d296ee0
fffff980`00477a4d fffffa80`037f9000 : 0x2
fffff980`26f15948 00000000`00000001 : fffff980`2d296ee0 fffff980`00477a4d
fffffa80`037f9000 00000000`00000002 : 0x0
fffff980`26f15950 fffff980`2d296ee0 : fffff980`00477a4d fffffa80`037f9000
00000000`00000002 00000000`00000000 : 0x1
fffff980`26f15958 fffff980`00477a4d : fffffa80`037f9000 00000000`00000002
00000000`00000000 fffff6fb`40000010 : 0xfffff980`2d296ee0
fffff980`26f15960 fffffa80`037f9000 : 00000000`00000002 00000000`00000000
fffff6fb`40000010 fffff980`004783d0 : bc_ngn+0x2a4d
fffff980`26f15968 00000000`00000002 : 00000000`00000000 fffff6fb`40000010
fffff980`004783d0 fffff980`0047857d : 0xfffffa80`037f9000
fffff980`26f15970 00000000`00000000 : fffff6fb`40000010 fffff980`004783d0
fffff980`0047857d fffff980`2d296ee0 : 0x2
fffff980`26f15978 fffff6fb`40000010 : fffff980`004783d0 fffff980`0047857d
fffff980`2d296ee0 fffff980`2d296ee0 : 0x0
fffff980`26f15980 fffff980`004783d0 : fffff980`0047857d fffff980`2d296ee0
fffff980`2d296ee0 00000000`00000000 : 0xfffff6fb`40000010
fffff980`26f15988 fffff980`0047857d : fffff980`2d296ee0 fffff980`2d296ee0
00000000`00000000 fffffa80`03596f40 : bc_ngn+0x33d0
fffff980`26f15990 fffff980`2d296ee0 : fffff980`2d296ee0 00000000`00000000
fffffa80`03596f40 fffffa80`03596f40 : bc_ngn+0x357d
fffff980`26f15998 fffff980`2d296ee0 : 00000000`00000000 fffffa80`03596f40
fffffa80`03596f40 fffff800`02c254e6 : 0xfffff980`2d296ee0
fffff980`26f159a0 00000000`00000000 : fffffa80`03596f40 fffffa80`03596f40
fffff800`02c254e6 fffff980`2d296ee0 : 0xfffff980`2d296ee0
fffff980`26f159a8 fffffa80`03596f40 : fffffa80`03596f40 fffff800`02c254e6
fffff980`2d296ee0 fffffa80`030cb060 : 0x0
fffff980`26f159b0 fffffa80`03596f40 : fffff800`02c254e6 fffff980`2d296ee0
fffffa80`030cb060 fffff980`2d296ee0 : 0xfffffa80`03596f40
fffff980`26f159b8 fffff800`02c254e6 : fffff980`2d296ee0 fffffa80`030cb060
fffff980`2d296ee0 fffffa80`030cb060 : 0xfffffa80`03596f40
fffff980`26f159c0 fffff980`2d296ee0 : fffffa80`030cb060 fffff980`2d296ee0
fffffa80`030cb060 00000000`00000001 : nt+0x4254e6
fffff980`26f159c8 fffffa80`030cb060 : fffff980`2d296ee0 fffffa80`030cb060
00000000`00000001 fffff980`2d296ee0 : 0xfffff980`2d296ee0
fffff980`26f159d0 fffff980`2d296ee0 : fffffa80`030cb060 00000000`00000001
fffff980`2d296ee0 fffffa80`05b079f0 : 0xfffffa80`030cb060
fffff980`26f159d8 fffffa80`030cb060 : 00000000`00000001 fffff980`2d296ee0
fffffa80`05b079f0 fffff800`02a8f017 : 0xfffff980`2d296ee0
fffff980`26f159e0 00000000`00000001 : fffff980`2d296ee0 fffffa80`05b079f0
fffff800`02a8f017 fffff980`2d296f00 : 0xfffffa80`030cb060
fffff980`26f159e8 fffff980`2d296ee0 : fffffa80`05b079f0 fffff800`02a8f017
fffff980`2d296f00 fffff980`26f15ca0 : 0x1
fffff980`26f159f0 fffffa80`05b079f0 : fffff800`02a8f017 fffff980`2d296f00
fffff980`26f15ca0 fffff980`00000000 : 0xfffff980`2d296ee0
fffff980`26f159f8 fffff800`02a8f017 : fffff980`2d296f00 fffff980`26f15ca0
fffff980`00000000 fffffa80`03596f40 : 0xfffffa80`05b079f0
fffff980`26f15a00 fffff980`2d296f00 : fffff980`26f15ca0 fffff980`00000000
fffffa80`03596f40 fffff980`2d296ee0 : nt+0x28f017
fffff980`26f15a08 fffff980`26f15ca0 : fffff980`00000000 fffffa80`03596f40
fffff980`2d296ee0 fffff980`26f15aa0 : 0xfffff980`2d296f00
fffff980`26f15a10 fffff980`00000000 : fffffa80`03596f40 fffff980`2d296ee0
fffff980`26f15aa0 00000000`00000000 : 0xfffff980`26f15ca0
fffff980`26f15a18 fffffa80`03596f40 : fffff980`2d296ee0 fffff980`26f15aa0
00000000`00000000 00000000`00000000 : 0xfffff980`00000000
fffff980`26f15a20 fffff980`2d296ee0 : fffff980`26f15aa0 00000000`00000000
00000000`00000000 00000000`00000000 : 0xfffffa80`03596f40
fffff980`26f15a28 fffff980`26f15aa0 : 00000000`00000000 00000000`00000000
00000000`00000000 00000000`00000000 : 0xfffff980`2d296ee0
fffff980`26f15a30 00000000`00000000 : 00000000`00000000 00000000`00000000
00000000`00000000 0000101e`0000101e : 0xfffff980`26f15aa0
fffff980`26f15a38 00000000`00000000 : 00000000`00000000 00000000`00000000
0000101e`0000101e fffffa80`05b079f0 : 0x0
fffff980`26f15a40 00000000`00000000 : 00000000`00000000 0000101e`0000101e
fffffa80`05b079f0 00000000`00000000 : 0x0
fffff980`26f15a48 00000000`00000000 : 0000101e`0000101e fffffa80`05b079f0
00000000`00000000 00000000`00000000 : 0x0
fffff980`26f15a50 0000101e`0000101e : fffffa80`05b079f0 00000000`00000000
00000000`00000000 00000000`0000101e : 0x0
fffff980`26f15a58 fffffa80`05b079f0 : 00000000`00000000 00000000`00000000
00000000`0000101e fffff980`2d296ee0 : 0x101e`0000101e
fffff980`26f15a60 00000000`00000000 : 00000000`00000000 00000000`0000101e
fffff980`2d296ee0 fffffa80`05b079f0 : 0xfffffa80`05b079f0
fffff980`26f15a68 00000000`00000000 : 00000000`0000101e fffff980`2d296ee0
fffffa80`05b079f0 00000000`00000000 : 0x0
fffff980`26f15a70 00000000`0000101e : fffff980`2d296ee0 fffffa80`05b079f0
00000000`00000000 00000000`00000000 : 0x0
fffff980`26f15a78 fffff980`2d296ee0 : fffffa80`05b079f0 00000000`00000000
00000000`00000000 00000000`00000000 : 0x101e
fffff980`26f15a80 fffffa80`05b079f0 : 00000000`00000000 00000000`00000000
00000000`00000000 0012019f`00000000 : 0xfffff980`2d296ee0
fffff980`26f15a88 00000000`00000000 : 00000000`00000000 00000000`00000000
0012019f`00000000 fffffa80`05775060 : 0xfffffa80`05b079f0
fffff980`26f15a90 00000000`00000000 : 00000000`00000000 0012019f`00000000
fffffa80`05775060 00000000`00000000 : 0x0
fffff980`26f15a98 00000000`00000000 : 0012019f`00000000 fffffa80`05775060
00000000`00000000 fffffa80`037f9000 : 0x0
fffff980`26f15aa0 0012019f`00000000 : fffffa80`05775060 00000000`00000000
fffffa80`037f9000 fffffa80`05b07a88 : 0x0
fffff980`26f15aa8 fffffa80`05775060 : 00000000`00000000 fffffa80`037f9000
fffffa80`05b07a88 00000000`00000001 : 0x12019f`00000000
fffff980`26f15ab0 00000000`00000000 : fffffa80`037f9000 fffffa80`05b07a88
00000000`00000001 fffffa80`05b079f0 : 0xfffffa80`05775060
fffff980`26f15ab8 fffffa80`037f9000 : fffffa80`05b07a88 00000000`00000001
fffffa80`05b079f0 fffffa80`05775060 : 0x0
fffff980`26f15ac0 fffffa80`05b07a88 : 00000000`00000001 fffffa80`05b079f0
fffffa80`05775060 00000000`00000000 : 0xfffffa80`037f9000
fffff980`26f15ac8 00000000`00000001 : fffffa80`05b079f0 fffffa80`05775060
00000000`00000000 00000000`7efa7000 : 0xfffffa80`05b07a88
fffff980`26f15ad0 fffffa80`05b079f0 : fffffa80`05775060 00000000`00000000
00000000`7efa7000 00000000`00000000 : 0x1
fffff980`26f15ad8 fffffa80`05775060 : 00000000`00000000 00000000`7efa7000
00000000`00000000 fffff800`02ac89ff : 0xfffffa80`05b079f0
fffff980`26f15ae0 00000000`00000000 : 00000000`7efa7000 00000000`00000000
fffff800`02ac89ff 00000000`75db3370 : 0xfffffa80`05775060
fffff980`26f15ae8 00000000`7efa7000 : 00000000`00000000 fffff800`02ac89ff
00000000`75db3370 00000000`0177f130 : 0x0
fffff980`26f15af0 00000000`00000000 : fffff800`02ac89ff 00000000`75db3370
00000000`0177f130 00000000`0177fd20 : 0x7efa7000
fffff980`26f15af8 fffff800`02ac89ff : 00000000`75db3370 00000000`0177f130
00000000`0177fd20 00000000`7efa7000 : 0x0
fffff980`26f15b00 00000000`75db3370 : 00000000`0177f130 00000000`0177fd20
00000000`7efa7000 fffff980`26f15bc8 : nt+0x2c89ff
fffff980`26f15b08 00000000`0177f130 : 00000000`0177fd20 00000000`7efa7000
fffff980`26f15bc8 00000000`0177f0d8 : 0x75db3370
fffff980`26f15b10 00000000`0177fd20 : 00000000`7efa7000 fffff980`26f15bc8
00000000`0177f0d8 fffffa80`05775060 : 0x177f130
fffff980`26f15b18 00000000`7efa7000 : fffff980`26f15bc8 00000000`0177f0d8
fffffa80`05775060 fffff800`02a95266 : 0x177fd20
fffff980`26f15b20 fffff980`26f15bc8 : 00000000`0177f0d8 fffffa80`05775060
fffff800`02a95266 00000000`00000001 : 0x7efa7000
fffff980`26f15b28 00000000`0177f0d8 : fffffa80`05775060 fffff800`02a95266
00000000`00000001 00000000`00000000 : 0xfffff980`26f15bc8
STACK_COMMAND: kb
FOLLOWUP_IP:
bc_ngn+2a4d
fffff980`00477a4d ?? ???
SYMBOL_STACK_INDEX: 11
FOLLOWUP_NAME: MachineOwner
IMAGE_NAME: bc_ngn.sys
SYMBOL_NAME: bc_ngn+2a4d
BUCKET_ID: WRONG_SYMBOLS
Followup: MachineOwner
---------
------------------------------------------------------------------------------------------------------------------
Kaspersky Crashdump:
Microsoft (R) Windows Debugger Version 6.7.0005.1
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File
[C:\Users\HBX\AppData\Local\Temp\WER4F97.tmp\Mini080607-03.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: *** Invalid ***
****************************************************************************
* Symbol loading may be unreliable without a symbol search path. *
* Use .symfix to have the debugger choose a symbol path. *
* After setting your symbol path, use .reload to refresh symbol locations. *
****************************************************************************
Executable search path is:
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for
ntoskrnl.exe
Windows Vista Kernel Version 6000 MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Kernel base = 0xfffff800`02800000 PsLoadedModuleList = 0xfffff800`0299af50
Debug session time: Mon Aug 6 17:18:29.628 2007 (GMT-4)
System Uptime: 0 days 0:06:47.145
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for
ntoskrnl.exe
Loading Kernel Symbols
.....................................................................................................................................................
Loading User Symbols
Loading unloaded module list
.......
*******************************************************************************
*
*
* Bugcheck Analysis
*
*
*
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck C4, {3d, 0, 0, fffff98020a35c14}
Unable to load image \SystemRoot\system32\DRIVERS\klif.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for klif.sys
*** ERROR: Module load completed but symbols could not be loaded for
klif.sys
***** Kernel symbols are WRONG. Please fix symbols to do analysis.
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
Probably caused by : klif.sys ( klif+23c14 )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
*
*
* Bugcheck Analysis
*
*
*
*******************************************************************************
DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
A device driver attempting to corrupt the system has been caught. This is
because the driver was specified in the registry as being suspect (by the
administrator) and the kernel has enabled substantial checking of this
driver.
If the driver attempts to corrupt the system, bugchecks 0xC4, 0xC1 and 0xA
will
be among the most commonly seen crashes.
Parameter 1 = 0x1000 .. 0x1020 - deadlock verifier error codes.
Typically the code is 0x1001 (deadlock detected) and you can
issue a '!deadlock' KD command to get more information.
Arguments:
Arg1: 000000000000003d, ERESOURCE address is unaligned.
Arg2: 0000000000000000, 0
Arg3: 0000000000000000, 0
Arg4: fffff98020a35c14, bad resource address passed in.
Debugging Details:
------------------
***** Kernel symbols are WRONG. Please fix symbols to do analysis.
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
MODULE_NAME: klif
FAULTING_MODULE: fffff80002800000 nt
DEBUG_FLR_IMAGE_TIMESTAMP: 4649721f
BUGCHECK_STR: 0xc4_3d
CUSTOMER_CRASH_COUNT: 3
DEFAULT_BUCKET_ID: WRONG_SYMBOLS
LAST_CONTROL_TRANSFER: from fffff80002c0937d to fffff8000284dbd0
STACK_TEXT:
fffff980`1f090578 fffff800`02c0937d : 00000000`000000c4 00000000`0000003d
00000000`00000000 00000000`00000000 : nt+0x4dbd0
fffff980`1f090580 00000000`000000c4 : 00000000`0000003d 00000000`00000000
00000000`00000000 fffff980`20a35c14 : nt+0x40937d
fffff980`1f090588 00000000`0000003d : 00000000`00000000 00000000`00000000
fffff980`20a35c14 00000000`00000000 : 0xc4
fffff980`1f090590 00000000`00000000 : 00000000`00000000 fffff980`20a35c14
00000000`00000000 fffff980`20a35c14 : 0x3d
fffff980`1f090598 00000000`00000000 : fffff980`20a35c14 00000000`00000000
fffff980`20a35c14 fffff800`02c0a22e : 0x0
fffff980`1f0905a0 fffff980`20a35c14 : 00000000`00000000 fffff980`20a35c14
fffff800`02c0a22e 00000000`00000000 : 0x0
fffff980`1f0905a8 00000000`00000000 : fffff980`20a35c14 fffff800`02c0a22e
00000000`00000000 00000000`00000000 : klif+0x23c14
fffff980`1f0905b0 fffff980`20a35c14 : fffff800`02c0a22e 00000000`00000000
00000000`00000000 00000000`00000000 : 0x0
fffff980`1f0905b8 fffff800`02c0a22e : 00000000`00000000 00000000`00000000
00000000`00000000 00000000`00000000 : klif+0x23c14
fffff980`1f0905c0 00000000`00000000 : 00000000`00000000 00000000`00000000
00000000`00000000 fffff980`20a35c14 : nt+0x40a22e
fffff980`1f0905c8 00000000`00000000 : 00000000`00000000 00000000`00000000
fffff980`20a35c14 00000000`00000000 : 0x0
fffff980`1f0905d0 00000000`00000000 : 00000000`00000000 fffff980`20a35c14
00000000`00000000 fffff980`20a35c14 : 0x0
fffff980`1f0905d8 00000000`00000000 : fffff980`20a35c14 00000000`00000000
fffff980`20a35c14 fffff800`02c188b4 : 0x0
fffff980`1f0905e0 fffff980`20a35c14 : 00000000`00000000 fffff980`20a35c14
fffff800`02c188b4 fffff980`58bdef01 : 0x0
fffff980`1f0905e8 00000000`00000000 : fffff980`20a35c14 fffff800`02c188b4
fffff980`58bdef01 00000000`00000000 : klif+0x23c14
fffff980`1f0905f0 fffff980`20a35c14 : fffff800`02c188b4 fffff980`58bdef01
00000000`00000000 00000000`00000000 : 0x0
fffff980`1f0905f8 fffff800`02c188b4 : fffff980`58bdef01 00000000`00000000
00000000`00000000 00000000`00000000 : klif+0x23c14
fffff980`1f090600 fffff980`58bdef01 : 00000000`00000000 00000000`00000000
00000000`00000000 fffff980`1f090780 : nt+0x4188b4
fffff980`1f090608 00000000`00000000 : 00000000`00000000 00000000`00000000
fffff980`1f090780 fffff980`20a1a0c7 : 0xfffff980`58bdef01
fffff980`1f090610 00000000`00000000 : 00000000`00000000 fffff980`1f090780
fffff980`20a1a0c7 fffff980`58bdef01 : 0x0
fffff980`1f090618 00000000`00000000 : fffff980`1f090780 fffff980`20a1a0c7
fffff980`58bdef01 00000000`00000000 : 0x0
fffff980`1f090620 fffff980`1f090780 : fffff980`20a1a0c7 fffff980`58bdef01
00000000`00000000 00000000`00000000 : 0x0
fffff980`1f090628 fffff980`20a1a0c7 : fffff980`58bdef01 00000000`00000000
00000000`00000000 00000000`00000000 : 0xfffff980`1f090780
fffff980`1f090630 fffff980`58bdef01 : 00000000`00000000 00000000`00000000
00000000`00000000 00000000`00000000 : klif+0x80c7
fffff980`1f090638 00000000`00000000 : 00000000`00000000 00000000`00000000
00000000`00000000 fffff980`20a148f9 : 0xfffff980`58bdef01
fffff980`1f090640 00000000`00000000 : 00000000`00000000 00000000`00000000
fffff980`20a148f9 00000000`00000000 : 0x0
fffff980`1f090648 00000000`00000000 : 00000000`00000000 fffff980`20a148f9
00000000`00000000 00000000`00000000 : 0x0
fffff980`1f090650 00000000`00000000 : fffff980`20a148f9 00000000`00000000
00000000`00000000 fffff980`58bdef60 : 0x0
fffff980`1f090658 fffff980`20a148f9 : 00000000`00000000 00000000`00000000
fffff980`58bdef60 00000000`00000000 : 0x0
fffff980`1f090660 00000000`00000000 : 00000000`00000000 fffff980`58bdef60
00000000`00000000 00000000`00000000 : klif+0x28f9
fffff980`1f090668 00000000`00000000 : fffff980`58bdef60 00000000`00000000
00000000`00000000 00000000`00000000 : 0x0
fffff980`1f090670 fffff980`58bdef60 : 00000000`00000000 00000000`00000000
00000000`00000000 00000000`00000000 : 0x0
fffff980`1f090678 00000000`00000000 : 00000000`00000000 00000000`00000000
00000000`00000000 00000000`00000000 : 0xfffff980`58bdef60
fffff980`1f090680 00000000`00000000 : 00000000`00000000 00000000`00000000
00000000`00000000 fffff980`20a35000 : 0x0
fffff980`1f090688 00000000`00000000 : 00000000`00000000 00000000`00000000
fffff980`20a35000 00000000`0088f880 : 0x0
fffff980`1f090690 00000000`00000000 : 00000000`00000000 fffff980`20a35000
00000000`0088f880 00000000`0088f870 : 0x0
fffff980`1f090698 00000000`00000000 : fffff980`20a35000 00000000`0088f880
00000000`0088f870 00000000`c00000bb : 0x0
fffff980`1f0906a0 fffff980`20a35000 : 00000000`0088f880 00000000`0088f870
00000000`c00000bb fffff980`55fb8ee0 : 0x0
fffff980`1f0906a8 00000000`0088f880 : 00000000`0088f870 00000000`c00000bb
fffff980`55fb8ee0 fffff800`02a91ac0 : klif+0x23000
fffff980`1f0906b0 00000000`0088f870 : 00000000`c00000bb fffff980`55fb8ee0
fffff800`02a91ac0 fffff980`55fb8ee0 : 0x88f880
fffff980`1f0906b8 00000000`c00000bb : fffff980`55fb8ee0 fffff800`02a91ac0
fffff980`55fb8ee0 fffff980`20a16e71 : 0x88f870
fffff980`1f0906c0 fffff980`55fb8ee0 : fffff800`02a91ac0 fffff980`55fb8ee0
fffff980`20a16e71 fffff980`55fb8ee0 : 0xc00000bb
fffff980`1f0906c8 fffff800`02a91ac0 : fffff980`55fb8ee0 fffff980`20a16e71
fffff980`55fb8ee0 00000000`00000030 : 0xfffff980`55fb8ee0
fffff980`1f0906d0 fffff980`55fb8ee0 : fffff980`20a16e71 fffff980`55fb8ee0
00000000`00000030 00000000`00000000 : nt+0x291ac0
fffff980`1f0906d8 fffff980`20a16e71 : fffff980`55fb8ee0 00000000`00000030
00000000`00000000 00000000`c000000d : 0xfffff980`55fb8ee0
fffff980`1f0906e0 fffff980`55fb8ee0 : 00000000`00000030 00000000`00000000
00000000`c000000d fffff980`58bdef60 : klif+0x4e71
fffff980`1f0906e8 00000000`00000030 : 00000000`00000000 00000000`c000000d
fffff980`58bdef60 fffff800`028934db : 0xfffff980`55fb8ee0
fffff980`1f0906f0 00000000`00000000 : 00000000`c000000d fffff980`58bdef60
fffff800`028934db 00000000`00000000 : 0x30
fffff980`1f0906f8 00000000`c000000d : fffff980`58bdef60 fffff800`028934db
00000000`00000000 fffff800`02a924a4 : 0x0
fffff980`1f090700 fffff980`58bdef60 : fffff800`028934db 00000000`00000000
fffff800`02a924a4 00000000`00000002 : 0xc000000d
fffff980`1f090708 fffff800`028934db : 00000000`00000000 fffff800`02a924a4
00000000`00000002 fffff980`00000000 : 0xfffff980`58bdef60
fffff980`1f090710 00000000`00000000 : fffff800`02a924a4 00000000`00000002
fffff980`00000000 fffff980`1f0907e8 : nt+0x934db
fffff980`1f090718 fffff800`02a924a4 : 00000000`00000002 fffff980`00000000
fffff980`1f0907e8 fffff800`028934db : 0x0
fffff980`1f090720 00000000`00000002 : fffff980`00000000 fffff980`1f0907e8
fffff800`028934db fffff980`1f0907f0 : nt+0x2924a4
fffff980`1f090728 fffff980`00000000 : fffff980`1f0907e8 fffff800`028934db
fffff980`1f0907f0 fffff800`028934db : 0x2
fffff980`1f090730 fffff980`1f0907e8 : fffff800`028934db fffff980`1f0907f0
fffff800`028934db 00000000`00000000 : 0xfffff980`00000000
fffff980`1f090738 fffff800`028934db : fffff980`1f0907f0 fffff800`028934db
00000000`00000000 fffff880`00100003 : 0xfffff980`1f0907e8
fffff980`1f090740 fffff980`1f0907f0 : fffff800`028934db 00000000`00000000
fffff880`00100003 fffff980`00000001 : nt+0x934db
fffff980`1f090748 fffff800`028934db : 00000000`00000000 fffff880`00100003
fffff980`00000001 fffff800`02894104 : 0xfffff980`1f0907f0
fffff980`1f090750 00000000`00000000 : fffff880`00100003 fffff980`00000001
fffff800`02894104 fffff980`1f090828 : nt+0x934db
fffff980`1f090758 fffff880`00100003 : fffff980`00000001 fffff800`02894104
fffff980`1f090828 fffff800`028934db : 0x0
fffff980`1f090760 fffff980`00000001 : fffff800`02894104 fffff980`1f090828
fffff800`028934db 000003b6`0000038d : 0xfffff880`00100003
fffff980`1f090768 fffff800`02894104 : fffff980`1f090828 fffff800`028934db
000003b6`0000038d 00000000`00004200 : 0xfffff980`00000001
fffff980`1f090770 fffff980`1f090828 : fffff800`028934db 000003b6`0000038d
00000000`00004200 00000000`00000003 : nt+0x94104
fffff980`1f090778 fffff800`028934db : 000003b6`0000038d 00000000`00004200
00000000`00000003 00000000`00000000 : 0xfffff980`1f090828
fffff980`1f090780 000003b6`0000038d : 00000000`00004200 00000000`00000003
00000000`00000000 fffff980`1f090858 : nt+0x934db
fffff980`1f090788 00000000`00004200 : 00000000`00000003 00000000`00000000
fffff980`1f090858 fffff800`02894104 : 0x3b6`0000038d
fffff980`1f090790 00000000`00000003 : 00000000`00000000 fffff980`1f090858
fffff800`02894104 fffff980`1f090860 : 0x4200
fffff980`1f090798 00000000`00000000 : fffff980`1f090858 fffff800`02894104
fffff980`1f090860 00000000`00000000 : 0x3
fffff980`1f0907a0 fffff980`1f090858 : fffff800`02894104 fffff980`1f090860
00000000`00000000 00000000`00000000 : 0x0
fffff980`1f0907a8 fffff800`02894104 : fffff980`1f090860 00000000`00000000
00000000`00000000 fffff800`0280d194 : 0xfffff980`1f090858
fffff980`1f0907b0 fffff980`1f090860 : 00000000`00000000 00000000`00000000
fffff800`0280d194 00000000`00000003 : nt+0x94104
fffff980`1f0907b8 00000000`00000000 : 00000000`00000000 fffff800`0280d194
00000000`00000003 fffff800`0280d194 : 0xfffff980`1f090860
fffff980`1f0907c0 00000000`00000000 : fffff800`0280d194 00000000`00000003
fffff800`0280d194 00000000`00000000 : 0x0
fffff980`1f0907c8 fffff800`0280d194 : 00000000`00000003 fffff800`0280d194
00000000`00000000 fffff800`0288422f : 0x0
STACK_COMMAND: kb
FOLLOWUP_IP:
klif+23c14
fffff980`20a35c14 98 cwde
SYMBOL_STACK_INDEX: 6
FOLLOWUP_NAME: MachineOwner
IMAGE_NAME: klif.sys
SYMBOL_NAME: klif+23c14
BUCKET_ID: WRONG_SYMBOLS
Followup: MachineOwner
---------
----------------------------------------------------------------------------------------------------------------
Kerio firewall Crashdump : (happened after installation - Reboot-)
Microsoft (R) Windows Debugger Version 6.7.0005.1
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File
[C:\Users\HBX\AppData\Local\Temp\WER120.tmp\Mini080807-02.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: *** Invalid ***
****************************************************************************
* Symbol loading may be unreliable without a symbol search path. *
* Use .symfix to have the debugger choose a symbol path. *
* After setting your symbol path, use .reload to refresh symbol locations. *
****************************************************************************
Executable search path is:
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for
ntoskrnl.exe
Windows Vista Kernel Version 6000 MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Kernel base = 0xfffff800`02800000 PsLoadedModuleList = 0xfffff800`0299af50
Debug session time: Wed Aug 8 22:30:50.096 2007 (GMT-4)
System Uptime: 0 days 2:24:44.160
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for
ntoskrnl.exe
Loading Kernel Symbols
..........................................................................................................................................................
Loading User Symbols
Loading unloaded module list
........
*******************************************************************************
*
*
* Bugcheck Analysis
*
*
*
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck C4, {3b, 2, fffff9800d954fc8, 0}
Unable to load image \SystemRoot\System32\drivers\tcpip.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for tcpip.sys
*** ERROR: Module load completed but symbols could not be loaded for
tcpip.sys
Unable to load image \SystemRoot\system32\drivers\NETIO.SYS, Win32 error 0n2
*** WARNING: Unable to verify timestamp for NETIO.SYS
*** ERROR: Module load completed but symbols could not be loaded for
NETIO.SYS
Unable to load image \SystemRoot\system32\DRIVERS\kvpndrv.sys, Win32 error
0n2
*** WARNING: Unable to verify timestamp for kvpndrv.sys
*** ERROR: Module load completed but symbols could not be loaded for
kvpndrv.sys
***** Kernel symbols are WRONG. Please fix symbols to do analysis.
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
Probably caused by : NETIO.SYS ( NETIO+bdd5 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
*
*
* Bugcheck Analysis
*
*
*
*******************************************************************************
DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
A device driver attempting to corrupt the system has been caught. This is
because the driver was specified in the registry as being suspect (by the
administrator) and the kernel has enabled substantial checking of this
driver.
If the driver attempts to corrupt the system, bugchecks 0xC4, 0xC1 and 0xA
will
be among the most commonly seen crashes.
Parameter 1 = 0x1000 .. 0x1020 - deadlock verifier error codes.
Typically the code is 0x1001 (deadlock detected) and you can
issue a '!deadlock' KD command to get more information.
Arguments:
Arg1: 000000000000003b, KeWaitXxx routine is being called at DISPATCH_LEVEL
or higher.
Arg2: 0000000000000002, current irql,
Arg3: fffff9800d954fc8, object to wait on,
Arg4: 0000000000000000, time out parameter.
Debugging Details:
------------------
***** Kernel symbols are WRONG. Please fix symbols to do analysis.
*************************************************************************
*** ***
*** ***
*** Your debugger is not using the correct symbols ***
*** ***
*** In order for this command to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: nt!_KPRCB ***
*** ***
*************************************************************************
MODULE_NAME: NETIO
FAULTING_MODULE: fffff80002800000 nt
DEBUG_FLR_IMAGE_TIMESTAMP: 4549beb1
BUGCHECK_STR: 0xc4_3b
CURRENT_IRQL: 2
CUSTOMER_CRASH_COUNT: 2
DEFAULT_BUCKET_ID: WRONG_SYMBOLS
LAST_CONTROL_TRANSFER: from fffff80002c0937d to fffff8000284dbd0
STACK_TEXT:
fffff980`00eacab8 fffff800`02c0937d : 00000000`000000c4 00000000`0000003b
00000000`00000002 fffff980`0d954fc8 : nt+0x4dbd0
fffff980`00eacac0 00000000`000000c4 : 00000000`0000003b 00000000`00000002
fffff980`0d954fc8 00000000`00000000 : nt+0x40937d
fffff980`00eacac8 00000000`0000003b : 00000000`00000002 fffff980`0d954fc8
00000000`00000000 fffff800`0289bf5d : 0xc4
fffff980`00eacad0 00000000`00000002 : fffff980`0d954fc8 00000000`00000000
fffff800`0289bf5d 00000000`00000002 : 0x3b
fffff980`00eacad8 fffff980`0d954fc8 : 00000000`00000000 fffff800`0289bf5d
00000000`00000002 fffff800`02c229d3 : 0x2
fffff980`00eacae0 00000000`00000000 : fffff800`0289bf5d 00000000`00000002
fffff800`02c229d3 00000000`00000000 : 0xfffff980`0d954fc8
fffff980`00eacae8 fffff800`0289bf5d : 00000000`00000002 fffff800`02c229d3
00000000`00000000 00000000`00000000 : 0x0
fffff980`00eacaf0 00000000`00000002 : fffff800`02c229d3 00000000`00000000
00000000`00000000 00000000`00000003 : nt+0x9bf5d
fffff980`00eacaf8 fffff800`02c229d3 : 00000000`00000000 00000000`00000000
00000000`00000003 fffff800`02c0a79a : 0x2
fffff980`00eacb00 00000000`00000000 : 00000000`00000000 00000000`00000003
fffff800`02c0a79a 00000000`00000000 : nt+0x4229d3
fffff980`00eacb08 00000000`00000000 : 00000000`00000003 fffff800`02c0a79a
00000000`00000000 00000000`00000001 : 0x0
fffff980`00eacb10 00000000`00000003 : fffff800`02c0a79a 00000000`00000000
00000000`00000001 00000000`00000010 : 0x0
fffff980`00eacb18 fffff800`02c0a79a : 00000000`00000000 00000000`00000001
00000000`00000010 fffff980`0d954f40 : 0x3
fffff980`00eacb20 00000000`00000000 : 00000000`00000001 00000000`00000010
fffff980`0d954f40 fffff980`0d3b80f0 : nt+0x40a79a
fffff980`00eacb28 00000000`00000001 : 00000000`00000010 fffff980`0d954f40
fffff980`0d3b80f0 fffff980`00674dd5 : 0x0
fffff980`00eacb30 00000000`00000010 : fffff980`0d954f40 fffff980`0d3b80f0
fffff980`00674dd5 fffff980`0d954fc8 : 0x1
fffff980`00eacb38 fffff980`0d954f40 : fffff980`0d3b80f0 fffff980`00674dd5
fffff980`0d954fc8 fffff980`00eacbe0 : 0x10
fffff980`00eacb40 fffff980`0d3b80f0 : fffff980`00674dd5 fffff980`0d954fc8
fffff980`00eacbe0 00000000`00000580 : 0xfffff980`0d954f40
fffff980`00eacb48 fffff980`00674dd5 : fffff980`0d954fc8 fffff980`00eacbe0
00000000`00000580 fffff800`02968998 : tcpip+0xf00f0
fffff980`00eacb50 fffff980`0d954fc8 : fffff980`00eacbe0 00000000`00000580
fffff800`02968998 00000000`00000000 : NETIO+0xbdd5
fffff980`00eacb58 fffff980`00eacbe0 : 00000000`00000580 fffff800`02968998
00000000`00000000 00000000`00000000 : 0xfffff980`0d954fc8
fffff980`00eacb60 00000000`00000580 : fffff800`02968998 00000000`00000000
00000000`00000000 00000000`0d269902 : 0xfffff980`00eacbe0
fffff980`00eacb68 fffff800`02968998 : 00000000`00000000 00000000`00000000
00000000`0d269902 00000000`00000000 : 0x580
fffff980`00eacb70 00000000`00000000 : 00000000`00000000 00000000`0d269902
00000000`00000000 fffffa80`04e3a920 : nt+0x168998
fffff980`00eacb78 00000000`00000000 : 00000000`0d269902 00000000`00000000
fffffa80`04e3a920 00000000`00000000 : 0x0
fffff980`00eacb80 00000000`0d269902 : 00000000`00000000 fffffa80`04e3a920
00000000`00000000 00000000`00000001 : 0x0
fffff980`00eacb88 00000000`00000000 : fffffa80`04e3a920 00000000`00000000
00000000`00000001 fffffa80`02130720 : 0xd269902
fffff980`00eacb90 fffffa80`04e3a920 : 00000000`00000000 00000000`00000001
fffffa80`02130720 fffff980`31922ec0 : 0x0
fffff980`00eacb98 00000000`00000000 : 00000000`00000001 fffffa80`02130720
fffff980`31922ec0 fffff980`006912af : 0xfffffa80`04e3a920
fffff980`00eacba0 00000000`00000001 : fffffa80`02130720 fffff980`31922ec0
fffff980`006912af fffff800`02968998 : 0x0
fffff980`00eacba8 fffffa80`02130720 : fffff980`31922ec0 fffff980`006912af
fffff800`02968998 00000000`00000000 : 0x1
fffff980`00eacbb0 fffff980`31922ec0 : fffff980`006912af fffff800`02968998
00000000`00000000 fffff980`1e518fe0 : 0xfffffa80`02130720
fffff980`00eacbb8 fffff980`006912af : fffff800`02968998 00000000`00000000
fffff980`1e518fe0 00000000`00000000 : 0xfffff980`31922ec0
fffff980`00eacbc0 fffff800`02968998 : 00000000`00000000 fffff980`1e518fe0
00000000`00000000 00000000`00000000 : NETIO+0x282af
fffff980`00eacbc8 00000000`00000000 : fffff980`1e518fe0 00000000`00000000
00000000`00000000 fffff980`006a35b0 : nt+0x168998
fffff980`00eacbd0 fffff980`1e518fe0 : 00000000`00000000 00000000`00000000
fffff980`006a35b0 00000000`00000010 : 0x0
fffff980`00eacbd8 00000000`00000000 : 00000000`00000000 fffff980`006a35b0
00000000`00000010 fffff980`3191cfb0 : 0xfffff980`1e518fe0
fffff980`00eacbe0 00000000`00000000 : fffff980`006a35b0 00000000`00000010
fffff980`3191cfb0 fffff980`0a12ce80 : 0x0
fffff980`00eacbe8 fffff980`006a35b0 : 00000000`00000010 fffff980`3191cfb0
fffff980`0a12ce80 fffff980`006914b1 : 0x0
fffff980`00eacbf0 00000000`00000010 : fffff980`3191cfb0 fffff980`0a12ce80
fffff980`006914b1 fffffa80`02130720 : NETIO+0x3a5b0
fffff980`00eacbf8 fffff980`3191cfb0 : fffff980`0a12ce80 fffff980`006914b1
fffffa80`02130720 00000000`00000000 : 0x10
fffff980`00eacc00 fffff980`0a12ce80 : fffff980`006914b1 fffffa80`02130720
00000000`00000000 fffff980`0521ca04 : 0xfffff980`3191cfb0
fffff980`00eacc08 fffff980`006914b1 : fffffa80`02130720 00000000`00000000
fffff980`0521ca04 00000000`00000001 : 0xfffff980`0a12ce80
fffff980`00eacc10 fffffa80`02130720 : 00000000`00000000 fffff980`0521ca04
00000000`00000001 fffff980`0521fc3c : NETIO+0x284b1
fffff980`00eacc18 00000000`00000000 : fffff980`0521ca04 00000000`00000001
fffff980`0521fc3c fffff980`0521ca40 : 0xfffffa80`02130720
fffff980`00eacc20 fffff980`0521ca04 : 00000000`00000001 fffff980`0521fc3c
fffff980`0521ca40 fffff980`0a12ce50 : 0x0
fffff980`00eacc28 00000000`00000001 : fffff980`0521fc3c fffff980`0521ca40
fffff980`0a12ce50 fffff800`028685e0 : kvpndrv+0x7a04
fffff980`00eacc30 fffff980`0521fc3c : fffff980`0521ca40 fffff980`0a12ce50
fffff800`028685e0 00000000`00000000 : 0x1
fffff980`00eacc38 fffff980`0521ca40 : fffff980`0a12ce50 fffff800`028685e0
00000000`00000000 fffff980`7cf82f70 : kvpndrv+0xac3c
fffff980`00eacc40 fffff980`0a12ce50 : fffff800`028685e0 00000000`00000000
fffff980`7cf82f70 fffff980`0000000a : kvpndrv+0x7a40
fffff980`00eacc48 fffff800`028685e0 : 00000000`00000000 fffff980`7cf82f70
fffff980`0000000a fffff800`0294a980 : 0xfffff980`0a12ce50
fffff980`00eacc50 00000000`00000000 : fffff980`7cf82f70 fffff980`0000000a
fffff800`0294a980 fffff880`04538008 : nt+0x685e0
fffff980`00eacc58 fffff980`7cf82f70 : fffff980`0000000a fffff800`0294a980
fffff880`04538008 fffff800`02acb398 : 0x0
fffff980`00eacc60 fffff980`0000000a : fffff800`0294a980 fffff880`04538008
fffff800`02acb398 fffff980`1e518fe0 : 0xfffff980`7cf82f70
fffff980`00eacc68 fffff800`0294a980 : fffff880`04538008 fffff800`02acb398
fffff980`1e518fe0 fffff980`0521fc3c : 0xfffff980`0000000a
fffff980`00eacc70 fffff880`04538008 : fffff800`02acb398 fffff980`1e518fe0
fffff980`0521fc3c fffffa80`02130720 : nt+0x14a980
fffff980`00eacc78 fffff800`02acb398 : fffff980`1e518fe0 fffff980`0521fc3c
fffffa80`02130720 fffff800`02968998 : 0xfffff880`04538008
fffff980`00eacc80 fffff980`1e518fe0 : fffff980`0521fc3c fffffa80`02130720
fffff800`02968998 fffff980`1e518fe0 : nt+0x2cb398
fffff980`00eacc88 fffff980`0521fc3c : fffffa80`02130720 fffff800`02968998
fffff980`1e518fe0 fffff980`0521fc4c : 0xfffff980`1e518fe0
fffff980`00eacc90 fffffa80`02130720 : fffff800`02968998 fffff980`1e518fe0
fffff980`0521fc4c 00000000`00000001 : kvpndrv+0xac3c
fffff980`00eacc98 fffff800`02968998 : fffff980`1e518fe0 fffff980`0521fc4c
00000000`00000001 00000000`00000000 : 0xfffffa80`02130720
fffff980`00eacca0 fffff980`1e518fe0 : fffff980`0521fc4c 00000000`00000001
00000000`00000000 fffff800`02aa6490 : nt+0x168998
fffff980`00eacca8 fffff980`0521fc4c : 00000000`00000001 00000000`00000000
fffff800`02aa6490 fffffa80`02130720 : 0xfffff980`1e518fe0
fffff980`00eaccb0 00000000`00000001 : 00000000`00000000 fffff800`02aa6490
fffffa80`02130720 fffff980`2ef44fe0 : kvpndrv+0xac4c
fffff980`00eaccb8 00000000`00000000 : fffff800`02aa6490 fffffa80`02130720
fffff980`2ef44fe0 fffff800`02859ca3 : 0x1
fffff980`00eaccc0 fffff800`02aa6490 : fffffa80`02130720 fffff980`2ef44fe0
fffff800`02859ca3 fffff800`029d20c0 : 0x0
fffff980`00eaccc8 fffffa80`02130720 : fffff980`2ef44fe0 fffff800`02859ca3
fffff800`029d20c0 fffff800`02968901 : nt+0x2a6490
fffff980`00eaccd0 fffff980`2ef44fe0 : fffff800`02859ca3 fffff800`029d20c0
fffff800`02968901 fffffa80`02130700 : 0xfffffa80`02130720
fffff980`00eaccd8 fffff800`02859ca3 : fffff800`029d20c0 fffff800`02968901
fffffa80`02130700 00000000`00000000 : 0xfffff980`2ef44fe0
fffff980`00eacce0 fffff800`029d20c0 : fffff800`02968901 fffffa80`02130700
00000000`00000000 fffff980`00eacd50 : nt+0x59ca3
fffff980`00eacce8 fffff800`02968901 : fffffa80`02130700 00000000`00000000
fffff980`00eacd50 00000000`00000001 : nt+0x1d20c0
fffff980`00eaccf0 fffffa80`02130700 : 00000000`00000000 fffff980`00eacd50
00000000`00000001 fffff980`00c66bc0 : nt+0x168901
fffff980`00eaccf8 00000000`00000000 : fffff980`00eacd50 00000000`00000001
fffff980`00c66bc0 fffffa80`020fc430 : 0xfffffa80`02130700
fffff980`00eacd00 fffff980`00eacd50 : 00000000`00000001 fffff980`00c66bc0
fffffa80`020fc430 00000000`00000000 : 0x0
fffff980`00eacd08 00000000`00000001 : fffff980`00c66bc0 fffffa80`020fc430
00000000`00000000 fffff800`02859b80 : 0xfffff980`00eacd50
STACK_COMMAND: kb
FOLLOWUP_IP:
NETIO+bdd5
fffff980`00674dd5 ?? ???
SYMBOL_STACK_INDEX: 13
FOLLOWUP_NAME: MachineOwner
IMAGE_NAME: NETIO.SYS
SYMBOL_NAME: NETIO+bdd5
BUCKET_ID: WRONG_SYMBOLS
Followup: MachineOwner
---------