*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {fffff8802b2fd590, 0, fffff800030bb7f7, 2}
Could not read faulting driver name
Probably caused by : memory_corruption
Followup: memory_corruption
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: fffff8802b2fd590, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff800030bb7f7, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000002, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800032cd100
fffff8802b2fd590
FAULTING_IP:
nt!ExpAllocateBigPool+147
fffff800`030bb7f7 8b8c2400010020 mov ecx,dword ptr [rsp+20000100h]
MM_INTERNAL_CODE: 2
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: CODE_CORRUPTION
BUGCHECK_STR: 0x50
PROCESS_NAME: iw5sp.exe
CURRENT_IRQL: 0
TRAP_FRAME: fffff8800b2fd300 -- (.trap 0xfffff8800b2fd300)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=00000000034735e0 rbx=0000000000000000 rcx=0000000000000000
rdx=fffff800032d0180 rsi=0000000000000000 rdi=0000000000000000
rip=fffff800030bb7f7 rsp=fffff8800b2fd490 rbp=fffffa800397a000
r8=0000000000020000 r9=fffffa8006c00000 r10=0000000000000000
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
nt!ExpAllocateBigPool+0x147:
fffff800`030bb7f7 8b8c2400010020 mov ecx,dword ptr [rsp+20000100h] ss:0018:fffff880`2b2fd590=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff800030453f0 to fffff8000309ac40
STACK_TEXT:
fffff880`0b2fd198 fffff800`030453f0 : 00000000`00000050 fffff880`2b2fd590 00000000`00000000 fffff880`0b2fd300 : nt!KeBugCheckEx
fffff880`0b2fd1a0 fffff800`03098d6e : 00000000`00000000 fffff880`2b2fd590 fffff880`0b2fd500 00000000`00001000 : nt! ?? ::FNODOBFM::`string'+0x447c6
fffff880`0b2fd300 fffff800`030bb7f7 : fffffa80`0397a000 fffff800`63416d4d 00000000`00001000 00000000`00000000 : nt!KiPageFault+0x16e
fffff880`0b2fd490 fffff800`031c990e : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00001000 : nt!ExpAllocateBigPool+0x147
fffff880`0b2fd580 fffff800`0319bdc4 : fffff700`01080000 00000000`00001000 00000000`00000040 00000000`00000000 : nt!ExAllocatePoolWithTag+0x82e
fffff880`0b2fd670 fffff800`0319bf96 : 00000000`00000000 c6600000`66b92867 fffff680`00108580 00000000`00000004 : nt!MiAllocateAccessLog+0xb4
fffff880`0b2fd6a0 fffff800`03109ea7 : 00000003`00000000 fffffa80`01342b60 00000000`210b0000 c6600000`66b92867 : nt!MiLogPageAccess+0x46
fffff880`0b2fd6f0 fffff800`030ce569 : 00000000`00000000 00000000`210bafff fffff880`00000000 fffff880`00961000 : nt! ?? ::FNODOBFM::`string'+0x35d67
fffff880`0b2fd8b0 fffff800`033b2221 : fffffa80`09466850 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MiRemoveMappedView+0xd9
fffff880`0b2fd9d0 fffff800`033b2623 : 0000007f`00000000 00000000`210b0000 fffffa80`00000001 00000000`1827f101 : nt!MiUnmapViewOfSection+0x1b1
fffff880`0b2fda90 fffff800`03099ed3 : 00000000`00000001 00000000`210ba0e8 fffffa80`0641b650 00000000`210b0000 : nt!NtUnmapViewOfSection+0x5f
fffff880`0b2fdae0 00000000`773f15ba : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`1827e808 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x773f15ba
STACK_COMMAND: kb
CHKIMG_EXTENSION: !chkimg -lo 50 -db !nt
3 errors : !nt (fffff800030bb7d5-fffff800030bb7fd)
fffff800030bb7d0 c1 46 50 f0 83 *4e 40 01 41 0f ba f7 1f *4c 3b 3d [email protected];=
...
fffff800030bb7f0 41 0f 85 05 71 f7 ff 8b 8c 24 00 01 00 *20 85 c9 A...q....$... ..
MODULE_NAME: memory_corruption
IMAGE_NAME: memory_corruption
FOLLOWUP_NAME: memory_corruption
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MEMORY_CORRUPTOR: STRIDE
FAILURE_BUCKET_ID: X64_MEMORY_CORRUPTION_STRIDE
BUCKET_ID: X64_MEMORY_CORRUPTION_STRIDE