PFN_LIST_CORRUPT (4e)
Typically caused by drivers passing bad memory descriptor lists (ie: calling
MmUnlockPages twice with the same list, etc). If a kernel debugger is
available get the stack trace.
Arguments:
Arg1: 0000000000000099, [COLOR="#FF0000"]A PTE or PFN is corrupt[/COLOR]
Arg2: 0000000000424fac, page frame number
Arg3: 0000000000000000, current page state
Arg4: 02fffff000413e2c, 0
....
[COLOR="#FF0000"]BUGCHECK_STR: 0x4E_99[/COLOR]
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
[COLOR="#FF0000"]PROCESS_NAME: Skype.exe[/COLOR]
....
....
STACK_TEXT:
ffffd000`22b3be58 fffff802`d1c0ddf5 : 00000000`0000004e 00000000`00000099 00000000`00424fac 00000000`00000000 : [COLOR="#FF0000"]nt!KeBugCheckEx[/COLOR]
ffffd000`22b3be60 fffff802`d1b36441 : ffffd000`22b3bff0 ffffe001`0cf75600 00000000`00000200 ffffd000`22b3c8b0 : nt! ?? ::FNODOBFM::`string'+0x33af5
ffffd000`22b3bf30 fffff802`d1f1bf1e : ffffe001`00000010 ffffe001`0cf75600 ffffe001`10c42510 00000000`00000001 : [COLOR="#FF0000"]nt!MiDecommitPages+0x771[/COLOR]
ffffd000`22b3c870 fffff802`d1f49885 : 00000000`00000000 ffffd000`22b3ca80 00000000`1cfca000 00000000`00000000 : [COLOR="#FF0000"]nt!MiDecommitRegion+0x6e[/COLOR]
ffffd000`22b3c8e0 fffff802`d1bd61a3 : ffffe001`10ce3300 00000000`0e174688 ffffe001`10ce3300 ffffd000`22b3ca80 : [COLOR="#FF0000"]nt!NtFreeVirtualMemory+0x235[/COLOR]
ffffd000`22b3ca00 00007ffe`07ca54a4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0009e688 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffe`07ca54a4
[COLOR="#008000"]Auf dem Stack wird erst der virtuelle Memory, dann eine Speicherregion und zuletzt eine Speicherseite frei gegeben (hier Dekommit -> Verbindung lösen)[/COLOR]
....
....
6: kd> !thread
GetPointerFromAddress: unable to read from fffff802d1e07200
THREAD ffffe00110ce3300 Cid 0b5c.18b8 Teb: 00000000002f1000 Win32Thread: ffffe001116289a0 RUNNING on processor 6
Not impersonating
GetUlongFromAddress: unable to read from fffff802d1d56fa8
[COLOR="#FF0000"]Owning Process ffffe0010cf75600 Image: Skype.exe[/COLOR]
[COLOR="#008000"]der aktuelle Thread war von Skype[/COLOR]
Attached Process N/A Image: N/A
fffff78000000000: Unable to get shared data
Wait Start TickCount 7652164
Context Switch Count 5717 IdealProcessor: 3
ReadMemory error: Cannot get nt!KeMaximumIncrement value.
UserTime 00:00:00.000
KernelTime 00:00:00.000
Win32 Start Address 0x0000000002518ca0
Stack Init ffffd00022b3cb90 Current ffffd00022b3c470
Base ffffd00022b3d000 Limit ffffd00022b36000 Call 0
Priority 8 BasePriority 8 UnusualBoost 0 ForegroundBoost 0 IoPriority 2 PagePriority 5
....
....
[COLOR="#008000"]der vom Debugger empfohlene Trap hat keine zusätzlichen Erkenntnisse gebracht.[/COLOR]
6: kd> .trap ffffd000`22b3ca00
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=0000000000000000
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=00007ffe07ca54a4 rsp=000000000009e688 rbp=000000000019f284
r8=0000000000000000 r9=0000000000000000 r10=0000000000000000
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
0033:00007ffe`07ca54a4 ?? ???