BSOD BAD_POOL_HEADER 0x00000019

1

Edit 1: Super busy couple of days, friend had to go to emergency room and I helped them get there (vehicle issues). I'll get to this very soon!

Edit 2: Updated additional steps taken, new BSOD info, and "!analyze -v" with Windows Debug. I am using Windows Storage spaces, so I think it's interesting that I'm getting errors after starting that recently since the debug mentioned "spaceport.sys" after I did the analysis. I also noticed that "SavService.exe" was mentioned, and I'm wondering if I should uninstall and reinstall Sophos Endpoint Security. Thoughts?

Edit 3: Added list of recent changes.

Starts below

So, I always tend to feel at a loss for BSODs which don't seem to point to a direct driver and something Microsoft related instead. Believe it or not, I'd done a lot of research over the years to try and narrow down possibilities on what could be causing the issue.

So I'm really looking for two things on this post. Possible sources for this problem and other ways I can better diagnose these things myself (even if it's just a really handy guide that you know of, I'm willing to read if I can find something decent and that -works- well!)

Anyway, this is the information

BSOD Information from Blue Screen Viewer

==================================================
Dump File         : 060616-40703-01.dmp
Crash Time        : 6/6/2016 9:12:56 PM
Bug Check String  : BAD_POOL_HEADER
Bug Check Code    : 0x00000019
Parameter 1       : 00000000`00000020
Parameter 2       : ffffe000`a3020000
Parameter 3       : ffffe000`a30202c0
Parameter 4       : 00000000`0c2c0000
Caused By Driver  : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+142780
File Description  : 
Product Name      : 
Company           : 
File Version      : 
Processor         : x64
Crash Address     : ntoskrnl.exe+142780
Stack Address 1   : 
Stack Address 2   : 
Stack Address 3   : 
Computer Name     : 
Full Path         : C:\Windows\Minidump\060616-40703-01.dmp
Processors Count  : 6
Major Version     : 15
Minor Version     : 10586
Dump File Size    : 280,556
Dump File Time    : 6/6/2016 9:45:37 PM
==================================================

==================================================
Dump File         : 060516-21531-01.dmp
Crash Time        : 6/5/2016 9:15:06 PM
Bug Check String  : BAD_POOL_HEADER
Bug Check Code    : 0x00000019
Parameter 1       : 00000000`00000020
Parameter 2       : ffffe001`3cba1000
Parameter 3       : ffffe001`3cba12c0
Parameter 4       : 00000000`0c2c0000
Caused By Driver  : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+142780
File Description  : 
Product Name      : 
Company           : 
File Version      : 
Processor         : x64
Crash Address     : ntoskrnl.exe+142780
Stack Address 1   : 
Stack Address 2   : 
Stack Address 3   : 
Computer Name     : 
Full Path         : C:\Windows\Minidump\060516-21531-01.dmp
Processors Count  : 6
Major Version     : 15
Minor Version     : 10586
Dump File Size    : 280,500
Dump File Time    : 6/5/2016 9:21:26 PM
==================================================

==================================================
Dump File         : 060316-22125-01.dmp
Crash Time        : 6/3/2016 9:17:31 PM
Bug Check String  : BAD_POOL_HEADER
Bug Check Code    : 0x00000019
Parameter 1       : 00000000`00000020
Parameter 2       : ffffe000`f96e9170
Parameter 3       : ffffe000`f96e9430
Parameter 4       : 00000000`0c2c0017
Caused By Driver  : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+142780
File Description  : 
Product Name      : 
Company           : 
File Version      : 
Processor         : x64
Crash Address     : ntoskrnl.exe+142780
Stack Address 1   : 
Stack Address 2   : 
Stack Address 3   : 
Computer Name     : 
Full Path         : C:\Windows\Minidump\060316-22125-01.dmp
Processors Count  : 6
Major Version     : 15
Minor Version     : 10586
Dump File Size    : 280,516
Dump File Time    : 6/3/2016 9:39:07 PM
==================================================

==================================================
Dump File         : 060216-41609-01.dmp
Crash Time        : 6/2/2016 9:17:58 PM
Bug Check String  : BAD_POOL_HEADER
Bug Check Code    : 0x00000019
Parameter 1       : 00000000`00000020
Parameter 2       : ffffe000`7c726000
Parameter 3       : ffffe000`7c7262c0
Parameter 4       : 00000000`0c2c0000
Caused By Driver  : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+142780
File Description  : 
Product Name      : 
Company           : 
File Version      : 
Processor         : x64
Crash Address     : ntoskrnl.exe+142780
Stack Address 1   : 
Stack Address 2   : 
Stack Address 3   : 
Computer Name     : 
Full Path         : C:\Windows\Minidump\060216-41609-01.dmp
Processors Count  : 6
Major Version     : 15
Minor Version     : 10586
Dump File Size    : 280,636
Dump File Time    : 6/2/2016 10:34:50 PM
==================================================

==================================================
Dump File         : 053116-22062-01.dmp
Crash Time        : 5/31/2016 9:17:09 PM
Bug Check String  : BAD_POOL_HEADER
Bug Check Code    : 0x00000019
Parameter 1       : 00000000`00000020
Parameter 2       : ffffe002`0f7e7000
Parameter 3       : ffffe002`0f7e72c0
Parameter 4       : 00000000`0c2c0000
Caused By Driver  : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+142780
File Description  : 
Product Name      : 
Company           : 
File Version      : 
Processor         : x64
Crash Address     : ntoskrnl.exe+142780
Stack Address 1   : 
Stack Address 2   : 
Stack Address 3   : 
Computer Name     : 
Full Path         : C:\Windows\Minidump\053116-22062-01.dmp
Processors Count  : 6
Major Version     : 15
Minor Version     : 10586
Dump File Size    : 280,588
Dump File Time    : 5/31/2016 9:18:56 PM
==================================================

==================================================
Dump File         : 052716-40593-01.dmp
Crash Time        : 5/27/2016 9:12:58 PM
Bug Check String  : BAD_POOL_HEADER
Bug Check Code    : 0x00000019
Parameter 1       : 00000000`00000020
Parameter 2       : ffffe000`d630f000
Parameter 3       : ffffe000`d630f2c0
Parameter 4       : 00000000`0c2c0000
Caused By Driver  : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+142780
File Description  : 
Product Name      : 
Company           : 
File Version      : 
Processor         : x64
Crash Address     : ntoskrnl.exe+142780
Stack Address 1   : 
Stack Address 2   : 
Stack Address 3   : 
Computer Name     : 
Full Path         : C:\Windows\Minidump\052716-40593-01.dmp
Processors Count  : 6
Major Version     : 15
Minor Version     : 10586
Dump File Size    : 280,468
Dump File Time    : 5/27/2016 9:49:21 PM
==================================================

==================================================
Dump File         : 052616-22187-01.dmp
Crash Time        : 5/26/2016 9:17:26 PM
Bug Check String  : BAD_POOL_HEADER
Bug Check Code    : 0x00000019
Parameter 1       : 00000000`00000020
Parameter 2       : ffffe000`ec94c140
Parameter 3       : ffffe000`ec94c400
Parameter 4       : 00000000`0c2c0005
Caused By Driver  : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+142780
File Description  : 
Product Name      : 
Company           : 
File Version      : 
Processor         : x64
Crash Address     : ntoskrnl.exe+142780
Stack Address 1   : 
Stack Address 2   : 
Stack Address 3   : 
Computer Name     : 
Full Path         : C:\Windows\Minidump\052616-22187-01.dmp
Processors Count  : 6
Major Version     : 15
Minor Version     : 10586
Dump File Size    : 280,564
Dump File Time    : 5/26/2016 9:20:00 PM
==================================================

==================================================
Dump File         : 052516-22093-01.dmp
Crash Time        : 5/25/2016 9:30:58 PM
Bug Check String  : BAD_POOL_HEADER
Bug Check Code    : 0x00000019
Parameter 1       : 00000000`00000020
Parameter 2       : ffffe000`94bff000
Parameter 3       : ffffe000`94bff2c0
Parameter 4       : 00000000`0c2c0000
Caused By Driver  : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+142780
File Description  : 
Product Name      : 
Company           : 
File Version      : 
Processor         : x64
Crash Address     : ntoskrnl.exe+142780
Stack Address 1   : 
Stack Address 2   : 
Stack Address 3   : 
Computer Name     : 
Full Path         : C:\Windows\Minidump\052516-22093-01.dmp
Processors Count  : 6
Major Version     : 15
Minor Version     : 10586
Dump File Size    : 280,500
Dump File Time    : 5/25/2016 9:36:24 PM
==================================================

==================================================
Dump File         : 051816-54859-01.dmp
Crash Time        : 5/18/2016 11:41:50 PM
Bug Check String  : CRITICAL_PROCESS_DIED
Bug Check Code    : 0x000000ef
Parameter 1       : ffffe000`b6fdb840
Parameter 2       : 00000000`00000000
Parameter 3       : 00000000`00000000
Parameter 4       : 00000000`00000000
Caused By Driver  : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+142780
File Description  : 
Product Name      : 
Company           : 
File Version      : 
Processor         : x64
Crash Address     : ntoskrnl.exe+142780
Stack Address 1   : 
Stack Address 2   : 
Stack Address 3   : 
Computer Name     : 
Full Path         : C:\Windows\Minidump\051816-54859-01.dmp
Processors Count  : 6
Major Version     : 15
Minor Version     : 10586
Dump File Size    : 280,476
Dump File Time    : 5/18/2016 11:44:24 PM
==================================================

==================================================
Dump File         : 051816-52671-01.dmp
Crash Time        : 5/18/2016 11:11:33 PM
Bug Check String  : KERNEL_DATA_INPAGE_ERROR
Bug Check Code    : 0x0000007a
Parameter 1       : ffffc001`93929e90
Parameter 2       : ffffffff`c000000e
Parameter 3       : 00000000`1b5d5860
Parameter 4       : fffff801`21cea250
Caused By Driver  : portcls.sys
Caused By Address : portcls.sys+2a250
File Description  : 
Product Name      : 
Company           : 
File Version      : 
Processor         : x64
Crash Address     : ntoskrnl.exe+142780
Stack Address 1   : 
Stack Address 2   : 
Stack Address 3   : 
Computer Name     : 
Full Path         : C:\Windows\Minidump\051816-52671-01.dmp
Processors Count  : 6
Major Version     : 15
Minor Version     : 10586
Dump File Size    : 280,436
Dump File Time    : 5/18/2016 11:30:29 PM
==================================================

==================================================
Dump File         : 050916-53156-01.dmp
Crash Time        : 5/9/2016 9:21:22 AM
Bug Check String  : CRITICAL_PROCESS_DIED
Bug Check Code    : 0x000000ef
Parameter 1       : ffffe001`ff3e6840
Parameter 2       : 00000000`00000000
Parameter 3       : 00000000`00000000
Parameter 4       : 00000000`00000000
Caused By Driver  : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+142760
File Description  : 
Product Name      : 
Company           : 
File Version      : 
Processor         : x64
Crash Address     : ntoskrnl.exe+142760
Stack Address 1   : 
Stack Address 2   : 
Stack Address 3   : 
Computer Name     : 
Full Path         : C:\Windows\Minidump\050916-53156-01.dmp
Processors Count  : 6
Major Version     : 15
Minor Version     : 10586
Dump File Size    : 280,524
Dump File Time    : 5/9/2016 9:23:41 AM
==================================================

==================================================
Dump File         : 042916-71359-01.dmp
Crash Time        : 4/29/2016 8:37:49 AM
Bug Check String  : CRITICAL_PROCESS_DIED
Bug Check Code    : 0x000000ef
Parameter 1       : ffffe001`397ef840
Parameter 2       : 00000000`00000000
Parameter 3       : 00000000`00000000
Parameter 4       : 00000000`00000000
Caused By Driver  : ntoskrnl.exe
Caused By Address : ntoskrnl.exe+142760
File Description  : 
Product Name      : 
Company           : 
File Version      : 
Processor         : x64
Crash Address     : ntoskrnl.exe+142760
Stack Address 1   : 
Stack Address 2   : 
Stack Address 3   : 
Computer Name     : 
Full Path         : C:\Windows\Minidump\042916-71359-01.dmp
Processors Count  : 6
Major Version     : 15
Minor Version     : 10586
Dump File Size    : 280,604
Dump File Time    : 4/29/2016 8:45:25 AM
==================================================

Things Tried thus far

  • Updated Audio Drivers
  • Ran "Windows Memory Diagnostic
  • Ran "sfc /scannow"
  • Ran "DISM /Online /Cleanup-Image /RestoreHealth"
  • Tried to run the Driver Verifier, but was unable to boot into Windows after a restart. Disabled it, did not try to run in Safe Mode long term.

List of recent changes

  • Imaged Partition OS from RAID 1 to SSD, deleted RAID OS and resized partitions
  • Converted OS from using drive in RAID mode (on motherboard) to AHCI, registry edit. Turned off RAID setting on motherboard. Backed up data beforehand.
  • Set up Windows Storage spaces and copied data back over, using Storage spaces to handle the "RAID 1" in order to be able to use the on board SATA controller. My research indicated that on board SATA controllers outperformed 3rd party add on controllers that were on the motherboard or PCIe SATA controllers. Thus RAID can stay off and still maintain data in RAID 1.

I've looked at this microsoft developer network article, but I don't really understand what I need to do (referring to "The internal pool links must be walked using the kernel debugger to figure out a possible cause of the problem."). Or I'd do it. What is that asking me to do? analyze it or something else?

I really appreciate any help you can offer with this. :)

System Hardware

AMD Phenom II X6 1090T Black Edition Processor at 3.2 GHz

ASUS Motherboard Sabertooth 990FX R2.0

Asus ProArt 24" LED LCD Monitor - 16:10 - 6 ms PA248Q

HP S2031 20-Inch Diagonal LCD Monitor - Black

AHCI mode - Samsung 850 EVO 250GB 2.5-Inch SATA III Internal SSD (MZ-75E250B/AM)

AHCI mode, 2 drives using Windows Storage Spaces, RAID 1 with ReFS - WD Red 2 TB NAS Hard Drive: 3.5 Inch, SATA III, 64 MB Cache - WD20EFRX

16 GB of RAM total, all sticks are Kingston, same model, and bought in pairs
1333 MHz, 4 sticks, 4 GB each, KVR1333D3N9K2/8G (bought a set of two 4 GB sticks)

Sapphire AMD Radeon HD 6770 1G GDDR5 PCI-E HDMI/DVI-I/DP
    ver 8.890.0.0, Catalyst 12.6, 2D Driver Version 8.01.01.1253, Direct3D Version 9.14.10.0920
    OpenGL Version 6.14.10.11733, AMD Vision Control Center Version 2012.0611.1251.21046
    0.12.020.000.058

ORICO USB 3.0 SuperSpeed Multi-Card Reader for SD/SDHC/SDXC/MS/CF/TF Cards
    http://www.newegg.com/Product/Product.aspx?Item=0DS-000P-00010

ATAPI iHAS424 SATA

Seasonic M12-11-750bronze
    SeaSonic M12II 750 SS-750AM2 750W ATX12V / EPS12V SLI Ready 80 PLUS BRONZE 
    Certified Modular Active PFC Full-modular Power Supply New 4th Gen CPU Certified Haswell Ready
    http://www.newegg.com/Product/Product.aspx?Item=N82E16817151107

Microsoft LifeCam VX-2000

Anker 7-Port USB 3.0 Hub H7928-U3 - 68UNHUB-B7U 

Saicoo USB3.0 4 Slots 11 in 1 Card Reader, with dual SD and Micro SD slots

    3 External HDDs
        - WD MyBook Essential 4 TB
            - P/N WDBACW0030HBK-01 511D
        -Iomega 640 GB External HDD
            - P\N 31810100
            - Model MMHDU
        -Rosewill RX35-AT-SU BLK Aluminum 3.5" Black SATA USB 2.0 External Enclosure
            -Barcode number 17182155041300542

---------------------------------------------------------------------------
Networked Devices
---------------------------------------------------------------------------
Canon PRO-100 networked wired
HP Photosmart 6510 Series Networked wireless

Additional Information through "!analyze -v"

Microsoft (R) Windows Debugger Version 6.3.9600.17336 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Windows\MEMORY.DMP]
Kernel Bitmap Dump File: Only kernel address space is available


************* Symbol Path validation summary **************
Response                         Time (ms)     Location
Deferred                                       SRV*C:\Windows\symbol_cache*http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*C:\Windows\symbol_cache*http://msdl.microsoft.com/download/symbols
Executable search path is: 
Windows 8 Kernel Version 10586 MP (6 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 10586.306.amd64fre.th2_release_sec.160422-1850
Machine Name:
Kernel base = 0xfffff802`d1c77000 PsLoadedModuleList = 0xfffff802`d1f55cd0
Debug session time: Mon Jun  6 21:12:56.104 2016 (UTC - 7:00)
System Uptime: 0 days 23:51:55.902
Loading Kernel Symbols
...............................................................
................................................................
..............................................................
Loading User Symbols
PEB is paged out (Peb.Ldr = 00000000`005ac018).  Type ".hh dbgerr001" for details
Loading unloaded module list
.............................................
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 19, {20, ffffe000a3020000, ffffe000a30202c0, c2c0000}

*** ERROR: Module load completed but symbols could not be loaded for SamsungRapidDiskFltr.sys
*** ERROR: Module load completed but symbols could not be loaded for fltsrv.sys
*** ERROR: Module load completed but symbols could not be loaded for snapman.sys
Page 4d00 not present in the dump file. Type ".hh dbgerr004" for details
Page 4d00 not present in the dump file. Type ".hh dbgerr004" for details
Page 4d00 not present in the dump file. Type ".hh dbgerr004" for details
Page 4d00 not present in the dump file. Type ".hh dbgerr004" for details
Page 4d00 not present in the dump file. Type ".hh dbgerr004" for details
Page 4d00 not present in the dump file. Type ".hh dbgerr004" for details
Probably caused by : spaceport.sys ( spaceport!SpSpaceDeviceControl+80 )

Followup: MachineOwner
---------

2: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

BAD_POOL_HEADER (19)
The pool is already corrupt at the time of the current request.
This may or may not be due to the caller.
The internal pool links must be walked to figure out a possible cause of
the problem, and then special pool applied to the suspect tags or the driver
verifier to a suspect driver.
Arguments:
Arg1: 0000000000000020, a pool block header size is corrupt.
Arg2: ffffe000a3020000, The pool entry we were looking for within the page.
Arg3: ffffe000a30202c0, The next pool entry.
Arg4: 000000000c2c0000, (reserved)

Debugging Details:
------------------

Page 4d00 not present in the dump file. Type ".hh dbgerr004" for details
Page 4d00 not present in the dump file. Type ".hh dbgerr004" for details
Page 4d00 not present in the dump file. Type ".hh dbgerr004" for details
Page 4d00 not present in the dump file. Type ".hh dbgerr004" for details
Page 4d00 not present in the dump file. Type ".hh dbgerr004" for details
Page 4d00 not present in the dump file. Type ".hh dbgerr004" for details

BUGCHECK_STR:  0x19_20

POOL_ADDRESS: unable to get nt!MmSpecialPoolStart
unable to get nt!MmSpecialPoolEnd
unable to get nt!MmPagedPoolEnd
unable to get nt!MmNonPagedPoolStart
unable to get nt!MmSizeOfNonPagedPoolInBytes
 ffffe000a3020000 

DEFAULT_BUCKET_ID:  WIN8_DRIVER_FAULT

PROCESS_NAME:  SavService.exe

CURRENT_IRQL:  1

ANALYSIS_VERSION: 6.3.9600.17336 (debuggers(dbg).150226-1500) amd64fre

IRP_ADDRESS: ffffe000f2240378

LAST_CONTROL_TRANSFER:  from fffff802d1ea8deb to fffff802d1db9780

STACK_TEXT:  
ffffd000`2294be88 fffff802`d1ea8deb : 00000000`00000019 00000000`00000020 ffffe000`a3020000 ffffe000`a30202c0 : nt!KeBugCheckEx
ffffd000`2294be90 fffff802`d1cf9e99 : ffffe000`a0f95080 fffff802`d1cf4b19 ffffe000`9f439520 00000000`20206f49 : nt!ExDeferredFreePool+0x63b
ffffd000`2294bf70 fffff802`d1cf914c : ffffe000`f22403f0 00000000`00000050 00000028`00000001 00000001`00000000 : nt!IopCompleteRequest+0x79
ffffd000`2294c060 fffff801`7c104050 : fffff801`7d0e8f40 fffff802`d1cefd01 00000000`00000000 00000000`8000001a : nt!IopfCompleteRequest+0x40c
ffffd000`2294c180 fffff801`7caf14a3 : ffffe000`a19d0de0 ffffe000`f22403f0 00000000`00000000 fffff801`7cf142dc : spaceport!SpSpaceDeviceControl+0x80
ffffd000`2294c1c0 fffff801`7cf13a6d : 00000000`00000000 ffffd000`2294c310 ffffe000`f22403f0 00000000`0004d004 : SamsungRapidDiskFltr+0x14a3
ffffd000`2294c210 fffff801`7cef16cf : 00000000`00000000 ffffe000`9ef57750 00000000`0004d004 ffffe000`9ef57828 : CLASSPNP!ClassDeviceControl+0x52d
ffffd000`2294c380 fffff801`7cf18a73 : ffffe000`a2b6e060 00000000`00000001 ffffe000`a2a591b0 ffffe000`a2a59c60 : disk!DiskDeviceControl+0x8f
ffffd000`2294c410 fffff801`7c0e4925 : ffffe000`f22403f0 ffffe000`a2a59c60 ffffd000`2294c590 00000000`00000000 : CLASSPNP!ClassDeviceControlDispatch+0x53
ffffd000`2294c440 fffff801`7c0d2935 : ffffe000`f2240300 00000000`00000000 00000000`00000000 ffffe000`f22403f0 : partmgr!PmIoctlRedirect+0x4d
ffffd000`2294c4b0 fffff801`7ced548f : ffffe000`a2a59b10 ffffe000`f22403f0 ffffe000`f2240748 ffffe000`f2240748 : partmgr!PmFilterDeviceControl+0x2a5
ffffd000`2294c500 fffff801`7ced3eb8 : ffffe000`f22403f0 fffff801`7c0d1960 00000000`00000020 00000000`00000000 : fltsrv+0x548f
ffffd000`2294c550 fffff801`7cdde1ac : ffffe000`9ea6ab80 00000000`00000030 ffffe000`a48e3010 ffffe000`f22403f0 : fltsrv+0x3eb8
ffffd000`2294c580 fffff801`7cde7848 : ffffe000`9ea6ab80 00000000`60000001 ffffe000`f6c2cbf0 fffff801`7cdcdaef : snapman+0x1e1ac
ffffd000`2294c600 fffff801`7cdde694 : ffffe000`a1836560 fffff801`7cdecfe4 ffffe000`a1836560 fffff801`7cde6d39 : snapman+0x27848
ffffd000`2294c630 fffff801`7cde6f71 : 00000000`00005740 ffffe000`a2a59b10 ffffe000`a1836560 ffffe000`9ea6ab80 : snapman+0x1e694
ffffd000`2294c6b0 fffff801`7cded02a : ffffd000`2294d000 ffffe000`f22403f0 ffffd000`22947000 fffff801`7cdecfe4 : snapman+0x26f71
ffffd000`2294c740 fffff801`7ced4d20 : ffffe000`f2240748 fffff801`7cdecfe4 ffffe000`9ea6ab80 ffffd000`2294c7f0 : snapman+0x2d02a
ffffd000`2294c7e0 fffff801`7ced3d24 : ffffe000`9fa07f30 ffffe000`f22403f0 ffffe000`f22403f0 ffffe000`f2240790 : fltsrv+0x4d20
ffffd000`2294c880 fffff802`d21481b2 : 00000000`00000000 ffffc001`3ec173c0 00000000`00000000 fffff802`d2079bf6 : fltsrv+0x3d24
ffffd000`2294c8b0 fffff802`d2147f8c : ffffe000`f22403f0 ffffd000`2294ccc0 ffffe000`a1415e40 fffff802`d1ceacc1 : nt!RawReadWriteDeviceControl+0x9e
ffffd000`2294c8e0 fffff801`7bbf5842 : ffffe000`9df2c060 ffffe000`a36e9400 ffffe000`f22403f0 00000000`00000200 : nt!RawDispatch+0x78
ffffd000`2294c930 fffff802`d2079842 : ffffe000`a36e9400 ffffd000`2294ccc0 00000000`00000001 00000000`00000001 : FLTMGR!FltpDispatch+0xe2
ffffd000`2294c990 fffff802`d20786d6 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!IopXxxControlFile+0x1162
ffffd000`2294cb60 fffff802`d1dc3fa3 : ffffc001`4fed9540 fffff802`d2035ced 00000000`06d1e848 ffffd000`2294ccc0 : nt!NtDeviceIoControlFile+0x56
ffffd000`2294cbd0 00000000`62f521bc : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`06d1f0f8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x62f521bc


STACK_COMMAND:  kb

FOLLOWUP_IP: 
spaceport!SpSpaceDeviceControl+80
fffff801`7c104050 85db            test    ebx,ebx

SYMBOL_STACK_INDEX:  4

SYMBOL_NAME:  spaceport!SpSpaceDeviceControl+80

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: spaceport

IMAGE_NAME:  spaceport.sys

DEBUG_FLR_IMAGE_TIMESTAMP:  5632d745

BUCKET_ID_FUNC_OFFSET:  80

FAILURE_BUCKET_ID:  0x19_20_spaceport!SpSpaceDeviceControl

BUCKET_ID:  0x19_20_spaceport!SpSpaceDeviceControl

ANALYSIS_SOURCE:  KM

FAILURE_ID_HASH_STRING:  km:0x19_20_spaceport!spspacedevicecontrol

FAILURE_ID_HASH:  {856d5b8f-6bfc-cd5c-1543-fe1594ace9a5}

Followup: MachineOwner
---------

2: kd> lmvm spaceport
start             end                 module name
fffff801`7c100000 fffff801`7c186000   spaceport   (pdb symbols)          C:\ProgramData\dbg\sym\spaceport.pdb\2E1806EFBFDD44F793C355B32D6E0EFE1\spaceport.pdb
    Loaded symbol image file: spaceport.sys
    Image path: \SystemRoot\System32\drivers\spaceport.sys
    Image name: spaceport.sys
    Timestamp:        Thu Oct 29 19:34:45 2015 (5632D745)
    CheckSum:         00083816
    ImageSize:        00086000
    Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
windows-10
bsod
asked on Super User Jun 3, 2016 by Wade S • edited Jun 8, 2016 by Wade S

0 Answers

Nobody has answered this question yet.


User contributions licensed under CC BY-SA 3.0