0: kd> .bugcheck
Bugcheck code 000000C4
Arguments 00000000`000000f6 00000000`00000320 ffffe001`08b98900 fffff801`a2d57430
[COLOR=#800080]
//Driver Verifier bugchecked the system because a Kernel mode driver referenced a user mode handle in Kernel mode, we didn't switch back to user mode[/COLOR]
0: kd> kn
# Child-SP RetAddr Call Site
00 ffffd000`2492b5a8 fffff801`2f49c6b0 nt!KeBugCheckEx [COLOR=#800080]//BSOD[/COLOR]
01 ffffd000`2492b5b0 fffff801`2f4a1fa0 nt!VerifierBugCheckIfAppropriate+0x3c [COLOR=#800080]//Bugcheck if required[/COLOR]
02 ffffd000`2492b5f0 fffff801`2f3623cb nt!VfCheckUserHandle+0x1b8 [COLOR=#800080]//Driver Verifier check the user handle[/COLOR]
03 ffffd000`2492b6d0 fffff801`2f1fb575 nt!ObReferenceObjectByHandleWithTag+0x1d18b [COLOR=#800080]//Reference handle with tag[/COLOR]
04 ffffd000`2492b770 fffff801`2f1d6ade nt!ObReferenceObjectByHandle+0x25 [COLOR=#800080]//Reference the object with handle[/COLOR]
05 ffffd000`2492b7c0 fffff801`2ef732b3 nt!NtSetEvent+0x6e [COLOR=#800080]//Set event[/COLOR]
06 ffffd000`2492b810 fffff801`2ef6b700 nt!KiSystemServiceCopyEnd+0x13 [COLOR=#800080]//Transition into Kernel mode[/COLOR]
07 ffffd000`2492b9a8 fffff801`a2d57430 nt!KiServiceLinkage [COLOR=#800080]//System service link[/COLOR]
08 ffffd000`2492b9b0 ffffcf80`04bf0001 rzpmgrk+0x1430 [COLOR=#800080]//Razer Overlay driver[/COLOR]
09 ffffd000`2492b9b8 ffffcf80`04bf0000 0xffffcf80`04bf0001 [COLOR=#800080]//Context not saved[/COLOR]
0a ffffd000`2492b9c0 00000000`00000b00 0xffffcf80`04bf0000 [COLOR=#800080]//Context not saved[/COLOR]
0b ffffd000`2492b9c8 ffffe001`088b8ef0 0xb00
0c ffffd000`2492b9d0 00000000`00000000 0xffffe001`088b8ef0 [COLOR=#800080]//Context not saved[/COLOR]
0: kd> u fffff801a2d57430 [COLOR=#800080]//Razer overlay driver caused the fault[/COLOR]
rzpmgrk+0x1430:
fffff801`a2d57430 488b4c2460 mov rcx,qword ptr [rsp+60h] [COLOR=#800080]//Faulting instruction[/COLOR]
fffff801`a2d57435 ff15451f0000 call qword ptr [rzpmgrk+0x3380 (fffff801`a2d59380)]
fffff801`a2d5743b 488b742468 mov rsi,qword ptr [rsp+68h]
fffff801`a2d57440 0fb6c3 movzx eax,bl
fffff801`a2d57443 488b5c2458 mov rbx,qword ptr [rsp+58h]
fffff801`a2d57448 4883c440 add rsp,40h
fffff801`a2d5744c 5f pop rdi
fffff801`a2d5744d c3 ret
0: kd> !handle 320
GetPointerFromAddress: unable to read from fffff8012f17a000
PROCESS ffffe00108b98900
SessionId: none Cid: 0b00 Peb: 7ff6b3acb000 ParentCid: 0790
DirBase: 131a51000 ObjectTable: ffffc001a8668c00 HandleCount: <Data Not Accessible>
Image: runonce.exe
GetPointerFromAddress: unable to read from fffff8012f0d7a18
ffffc001a8668c00: Unable to read handle table
0: kd> lmvm rzpmgrk
start end module name
fffff801`a2d56000 fffff801`a2d5d280 rzpmgrk T (no symbols)
Loaded symbol image file: rzpmgrk.sys
Image path: \??\C:\Windows\system32\drivers\rzpmgrk.sys
Image name: rzpmgrk.sys
Timestamp: Thu Apr 17 20:36:12 2014 (53502D2C)
CheckSum: 0001707D
ImageSize: 00007280
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4