Sysmon 13.30 BSOD with Excel 365

Chris Maiura 6 Reputation points
2021-12-10T16:15:49.2+00:00

We have been having sporadic reports with our Windows 10 computers BSOD related to the sysmon driver and excel. This is behavior that was not there with Office 2016. The error shows chrome, but the user was copening an excel file downloaded internally.


  • *
  • Bugcheck Analysis *
  • *

BAD_POOL_CALLER (c2)
The current thread is making a bad pool request. Typically this is at a bad IRQL level or double freeing the same allocation, etc.
Arguments:
Arg1: 000000000000000d, Attempt to release quota on a corrupted pool allocation.
Arg2: ffffb70284657620, Address of pool
Arg3: 00000000fffff804, Pool allocation's tag
Arg4: d043bb0a529e74d8, Quota process pointer (bad).

Debugging Details:


KEY_VALUES_STRING: 1

Key  : Analysis.CPU.mSec
Value: 4046

Key  : Analysis.DebugAnalysisManager
Value: Create

Key  : Analysis.Elapsed.mSec
Value: 32538

Key  : Analysis.Init.CPU.mSec
Value: 655

Key  : Analysis.Init.Elapsed.mSec
Value: 3279

Key  : Analysis.Memory.CommitPeak.Mb
Value: 78

Key  : WER.OS.Branch
Value: vb_release

Key  : WER.OS.Timestamp
Value: 2019-12-06T14:06:00Z

Key  : WER.OS.Version
Value: 10.0.19041.1

FILE_IN_CAB: 121021-24484-01.dmp

BUGCHECK_CODE: c2

BUGCHECK_P1: d

BUGCHECK_P2: ffffb70284657620

BUGCHECK_P3: fffff804

BUGCHECK_P4: d043bb0a529e74d8

BLACKBOXBSD: 1 (!blackboxbsd)

BLACKBOXNTFS: 1 (!blackboxntfs)

BLACKBOXPNP: 1 (!blackboxpnp)

BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT: 1

PROCESS_NAME: chrome.exe

STACK_TEXT:
ffffed867f796358 fffff8047783d460 : 00000000000000c2 000000000000000d ffffb70284657620 00000000fffff804 : nt!KeBugCheckEx
ffffed867f796360 fffff80477db2149 : 0000000000000010 0000000000040082 ffffed867f796468 0100000000100000 : nt!ExFreeHeapPool+0x1b43b0
ffffed867f796440 fffff8047d3a82bc : ffffed867f796570 0000000000000000 000000000000056a fffff80400000000 : nt!ExFreePool+0x9
ffffed867f796470 ffffed867f796570 : 0000000000000000 000000000000056a fffff80400000000 ffffed867f7964c4 : SysmonDrv+0x82bc
ffffed867f796478 0000000000000000 : 000000000000056a fffff80400000000 ffffed867f7964c4 ffffed867f796550 : 0xffffed86`7f796570

SYMBOL_NAME: SysmonDrv+82bc

MODULE_NAME: SysmonDrv

IMAGE_NAME: SysmonDrv.sys

STACK_COMMAND: .cxr; .ecxr ; kb

BUCKET_ID_FUNC_OFFSET: 82bc

FAILURE_BUCKET_ID: 0xc2_d_SysmonDrv!unknown_function

OS_VERSION: 10.0.19041.1

BUILDLAB_STR: vb_release

OSPLATFORM_TYPE: x64

OSNAME: Windows 10

FAILURE_ID_HASH: {7fed9f86-89f9-24bf-7bdf-bc0a6eb2fdea}

Followup: MachineOwner

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,091 questions
{count} vote