So my computer crashed (Blue Screened) twice in the last 24 hours and I just checked the crash dump. Is there anyone that could tell me what the cause of it is? I have Windows 8.1.
Loading Dump File [C:\Windows\MEMORY.DMP]
Kernel Bitmap Dump File: Only kernel address space is available
************* Symbol Path validation summary **************
Response Time (ms) Location
Deferred SRV*C:\Windows\symbol_cache*http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*C:\Windows\symbol_cache*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 8 Kernel Version 9600 MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 9600.17085.amd64fre.winblue_gdr.140330-1035
Machine Name:
Kernel base = 0xfffff802`5ba80000 PsLoadedModuleList = 0xfffff802`5bd4a2d0
Debug session time: Sat Aug 30 09:08:35.713 2014 (UTC - 4:00)
System Uptime: 0 days 2:41:45.335
Loading Kernel Symbols
...............................................................
................................................................
......................................
Loading User Symbols
PEB is paged out (Peb.Ldr = 00000000`7f3af018). Type ".hh dbgerr001" for details
Loading unloaded module list
..........
*******************************************************************************
* *
* Bugcheck brown townysis *
* *
*******************************************************************************
Use !brown townyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fffff8025bd15313, ffffd000342f1cc0, 0}
*** ERROR: Module load completed but symbols could not be loaded for MBAMSwissArmy.sys
Probably caused by : MBAMSwissArmy.sys ( MBAMSwissArmy+7c80 )
Followup: MachineOwner
---------
2: kd> !brown townyze -v
*******************************************************************************
* *
* Bugcheck brown townysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff8025bd15313, Address of the instruction which caused the bugcheck
Arg3: ffffd000342f1cc0, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
OVERLAPPED_MODULE: Address regions for 'WdNisDrv' and 'WUDFRd.sys' overlap
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
FAULTING_IP:
nt!ExFreePoolWithTag+33
fffff802`5bd15313 410fb675f3 movzx esi,byte ptr [r13-0Dh]
CONTEXT: ffffd000342f1cc0 -- (.cxr 0xffffd000342f1cc0;r)
rax=0000000000000001 rbx=fffff8017bdb9cd0 rcx=0000000000003a72
rdx=0000000000000000 rsi=ffffe0004c377980 rdi=ffffd000342f2b80
rip=fffff8025bd15313 rsp=ffffd000342f26f0 rbp=0000000000000001
r8=ffffc001ae4631d0 r9=00000000000007ff r10=ffffd001359923e0
r11=ffffc001b56279f0 r12=0000000000000000 r13=0000000000003a72
r14=0000000000000000 r15=fffff8017bdb9b40
iopl=0 nv up ei pl nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010206
nt!ExFreePoolWithTag+0x33:
fffff802`5bd15313 410fb675f3 movzx esi,byte ptr [r13-0Dh] ds:002b:00000000`00003a65=??
Last set context:
rax=0000000000000001 rbx=fffff8017bdb9cd0 rcx=0000000000003a72
rdx=0000000000000000 rsi=ffffe0004c377980 rdi=ffffd000342f2b80
rip=fffff8025bd15313 rsp=ffffd000342f26f0 rbp=0000000000000001
r8=ffffc001ae4631d0 r9=00000000000007ff r10=ffffd001359923e0
r11=ffffc001b56279f0 r12=0000000000000000 r13=0000000000003a72
r14=0000000000000000 r15=fffff8017bdb9b40
iopl=0 nv up ei pl nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010206
nt!ExFreePoolWithTag+0x33:
fffff802`5bd15313 410fb675f3 movzx esi,byte ptr [r13-0Dh] ds:002b:00000000`00003a65=??
Resetting default scope
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: 0x3B
PROCESS_NAME: mbam.exe
CURRENT_IRQL: 0
brown townYSIS_VERSION: 6.3.9600.17237 (debuggers(dbg).140716-0327) x86fre
LAST_CONTROL_TRANSFER: from fffff8017bda6c80 to fffff8025bd15313
STACK_TEXT:
ffffd000`342f26f0 fffff801`7bda6c80 : 00000000`00000001 ffffd000`342f2b80 ffffe000`4c377980 00000000`00000043 : nt!ExFreePoolWithTag+0x33
ffffd000`342f27c0 fffff801`7bda0507 : 00000000`00000000 00000000`00000001 ffffe000`4c377980 ffffd000`41724765 : MBAMSwissArmy+0x7c80
ffffd000`342f27f0 fffff801`7bdbc4c8 : fffff801`7bdb9cd0 fffff802`00000000 ffffe000`4fe28200 ffffd000`00000000 : MBAMSwissArmy+0x1507
ffffd000`342f2820 fffff802`5be7c8f2 : 00000000`00000000 ffffd000`342f2b80 ffffd000`342f2b80 ffffe000`4c377980 : MBAMSwissArmy+0x1d4c8
ffffd000`342f2880 fffff802`5be7d1c6 : 00000000`00000000 fffff960`00000000 00000000`00000001 00000000`00000000 : nt!IopXxxControlFile+0x8d2
ffffd000`342f2a20 fffff802`5bbdf7b3 : 00000000`00000001 fffff960`00229483 00000000`00000000 00000000`00000000 : nt!NtDeviceIoControlFile+0x56
ffffd000`342f2a90 00000000`77a02772 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0b01ea28 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77a02772
FOLLOWUP_IP:
MBAMSwissArmy+7c80
fffff801`7bda6c80 488b0519400100 mov rax,qword ptr [MBAMSwissArmy+0x1bca0 (fffff801`7bdbaca0)]
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: MBAMSwissArmy+7c80
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: MBAMSwissArmy
IMAGE_NAME: MBAMSwissArmy.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 532b67d3
STACK_COMMAND: .cxr 0xffffd000342f1cc0 ; kb
FAILURE_BUCKET_ID: 0x3B_MBAMSwissArmy+7c80
BUCKET_ID: 0x3B_MBAMSwissArmy+7c80
brown townYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0x3b_mbamswissarmy+7c80
FAILURE_ID_HASH: {3a308b2a-0052-8ae7-6960-c6b6f15d2aba}
Followup: MachineOwner
---------