Sysmon 13.30 BSOD with Excel 365
We have been having sporadic reports with our Windows 10 computers BSOD related to the sysmon driver and excel. This is behavior that was not there with Office 2016. The error shows chrome, but the user was copening an excel file downloaded internally.
- *
- Bugcheck Analysis *
- *
BAD_POOL_CALLER (c2)
The current thread is making a bad pool request. Typically this is at a bad IRQL level or double freeing the same allocation, etc.
Arguments:
Arg1: 000000000000000d, Attempt to release quota on a corrupted pool allocation.
Arg2: ffffb70284657620, Address of pool
Arg3: 00000000fffff804, Pool allocation's tag
Arg4: d043bb0a529e74d8, Quota process pointer (bad).
Debugging Details:
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 4046
Key : Analysis.DebugAnalysisManager
Value: Create
Key : Analysis.Elapsed.mSec
Value: 32538
Key : Analysis.Init.CPU.mSec
Value: 655
Key : Analysis.Init.Elapsed.mSec
Value: 3279
Key : Analysis.Memory.CommitPeak.Mb
Value: 78
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Timestamp
Value: 2019-12-06T14:06:00Z
Key : WER.OS.Version
Value: 10.0.19041.1
FILE_IN_CAB: 121021-24484-01.dmp
BUGCHECK_CODE: c2
BUGCHECK_P1: d
BUGCHECK_P2: ffffb70284657620
BUGCHECK_P3: fffff804
BUGCHECK_P4: d043bb0a529e74d8
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: chrome.exe
STACK_TEXT:
ffffed867f796358 fffff804
7783d460 : 00000000000000c2 00000000
0000000d ffffb70284657620 00000000
fffff804 : nt!KeBugCheckEx
ffffed867f796360 fffff804
77db2149 : 0000000000000010 00000000
00040082 ffffed867f796468 01000000
00100000 : nt!ExFreeHeapPool+0x1b43b0
ffffed867f796440 fffff804
7d3a82bc : ffffed867f796570 00000000
00000000 000000000000056a fffff804
00000000 : nt!ExFreePool+0x9
ffffed867f796470 ffffed86
7f796570 : 0000000000000000 00000000
0000056a fffff80400000000 ffffed86
7f7964c4 : SysmonDrv+0x82bc
ffffed867f796478 00000000
00000000 : 000000000000056a fffff804
00000000 ffffed867f7964c4 ffffed86
7f796550 : 0xffffed86`7f796570
SYMBOL_NAME: SysmonDrv+82bc
MODULE_NAME: SysmonDrv
IMAGE_NAME: SysmonDrv.sys
STACK_COMMAND: .cxr; .ecxr ; kb
BUCKET_ID_FUNC_OFFSET: 82bc
FAILURE_BUCKET_ID: 0xc2_d_SysmonDrv!unknown_function
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {7fed9f86-89f9-24bf-7bdf-bc0a6eb2fdea}