*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 50, {fffffa800c6bc00c, 0, fffff880027f198a, 0}
Unable to load image OAfilt.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for OAfilt.sys
*** ERROR: Module load completed but symbols could not be loaded for OAfilt.sys
Could not read faulting driver name
[B][COLOR=#ff0000]Probably caused by : OAfilt.sys[/COLOR][/B] ( OAfilt+198a )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: fffffa800c6bc00c, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff880027f198a, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000000, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800032af100
fffffa800c6bc00c
FAULTING_IP:
OAfilt+198a
fffff880`027f198a 448b5114 mov r10d,dword ptr [rcx+14h]
MM_INTERNAL_CODE: 0
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: System
CURRENT_IRQL: 0
TRAP_FRAME: fffff88003508580 -- (.trap 0xfffff88003508580)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000005 rbx=0000000000000000 rcx=fffffa800c6bbff8
rdx=00000000ffffffff rsi=0000000000000000 rdi=0000000000000000
rip=fffff880027f198a rsp=fffff88003508710 rbp=0000000000000000
r8=0000000000000001 r9=0000000000000038 r10=00810084007f0089
r11=fffff88003508708 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na pe cy
OAfilt+0x198a:
fffff880`027f198a 448b5114 mov r10d,dword ptr [rcx+14h] ds:fffffa80`0c6bc00c=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff800030289fc to fffff8000307cc40
STACK_TEXT:
fffff880`03508418 fffff800`030289fc : 00000000`00000050 fffffa80`0c6bc00c 00000000`00000000 fffff880`03508580 : nt!KeBugCheckEx
fffff880`03508420 fffff800`0307ad6e : 00000000`00000000 fffffa80`0c6bc00c 00000000`00000000 fffffa80`0b5e74a0 : nt! ?? ::FNODOBFM::`string'+0x4611f
fffff880`03508580 fffff880`027f198a : 00000000`00000000 fffffa80`0a1ba680 fffffa80`0a1ba680 00000000`00000001 : nt!KiPageFault+0x16e
fffff880`03508710 00000000`00000000 : fffffa80`0a1ba680 fffffa80`0a1ba680 00000000`00000001 fffff800`0322cf40 : OAfilt+0x198a
STACK_COMMAND: kb
FOLLOWUP_IP:
OAfilt+198a
fffff880`027f198a 448b5114 mov r10d,dword ptr [rcx+14h]
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: OAfilt+198a
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: OAfilt
IMAGE_NAME: OAfilt.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4b95aa30
FAILURE_BUCKET_ID: X64_0x50_OAfilt+198a
BUCKET_ID: X64_0x50_OAfilt+198a