Guest User

Untitled

a guest
Jun 26th, 2020
29
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. ========================== AUTO DUMP ANALYZER ==========================
  2. Auto Dump Analyzer
  3. Version: 0.91
  4. Time to analyze file(s): 00 hours and 05 minutes and 26 seconds
  5.  
  6. ================================= BIOS =================================
  7. VENDOR: American Megatrends Inc.
  8. VERSION: P7.50
  9. DATE: 01/23/2018
  10.  
  11. ============================= MOTHERBOARD ==============================
  12. MANUFACTURER: ASRock
  13. PRODUCT: Z170 Pro4S
  14.  
  15. ================================= RAM ==================================
  16. Size Speed Manufacturer Part No.
  17. -------------- -------------- ------------------- ----------------------
  18. 0MHz
  19. 8192MB 3000MHz Kingston KHX3000C15D4/8GX
  20. 0MHz
  21. 8192MB 3000MHz Kingston KHX3000C15D4/8GX
  22.  
  23. ================================= CPU ==================================
  24. Processor Version: Intel(R) Core(TM) i5-6600K CPU @ 3.50GHz
  25. COUNT: 4
  26. MHZ: 3504
  27. VENDOR: GenuineIntel
  28. FAMILY: 6
  29. MODEL: 5e
  30. STEPPING: 3
  31. MICROCODE: 6,5e,3,0 (F,M,S,R) SIG: CC'00000000 (cache) CC'00000000 (init)
  32.  
  33. ================================== OS ==================================
  34. Product: WinNt, suite: TerminalServer SingleUserTS Personal
  35. Built by: 18362.1.amd64fre.19h1_release.190318-1202
  36. BUILD_VERSION: 10.0.18362.900 (WinBuild.160101.0800)
  37. BUILD: 18362
  38. SERVICEPACK: 900
  39. PLATFORM_TYPE: x64
  40. NAME: Windows 10
  41. EDITION: Windows 10 WinNt TerminalServer SingleUserTS Personal
  42. BUILD_TIMESTAMP: 2012-07-06 17:22:33
  43. BUILDDATESTAMP: 160101.0800
  44. BUILDLAB: WinBuild
  45. BUILDOSVER: 10.0.18362.900
  46. BUILD_VERSION: 10.0.18362.836 (WinBuild.160101.0800)
  47. SERVICEPACK: 836
  48. BUILD_TIMESTAMP: unknown_date
  49. BUILDOSVER: 10.0.18362.836
  50.  
  51. =============================== DEBUGGER ===============================
  52. Microsoft (R) Windows Debugger Version 10.0.14321.1024 AMD64
  53. Copyright (c) Microsoft Corporation. All rights reserved.
  54.  
  55. =============================== COMMENTS ===============================
  56. * Information gathered from different dump files may be different. If
  57. Windows updates between two dump files, two or more OS versions may
  58. be shown above.
  59. * If the user updates the BIOS between dump files, two or more versions
  60. and dates may be shown above.
  61. * More RAM information can be found below in a full BIOS section.
  62.  
  63. ========================================================================
  64. ======================= Dump #1: ANALYZE VERBOSE =======================
  65. ======================= File: 062120-7921-01.dmp =======================
  66. ========================================================================
  67.  
  68. Mini Kernel Dump File: Only registers and stack trace are available
  69. Windows 10 Kernel Version 18362 MP (4 procs) Free x64
  70. Kernel base = 0xfffff807`2c600000 PsLoadedModuleList = 0xfffff807`2ca48190
  71. Debug session time: Sun Jun 21 11:37:12.152 2020 (UTC - 4:00)
  72. System Uptime: 0 days 0:28:15.824
  73.  
  74. BugCheck A, {fffff80733727f08, b, 1, fffff8072c64f52c}
  75. *** WARNING: Unable to verify timestamp for win32k.sys
  76. *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
  77. Probably caused by : memory_corruption
  78. Followup: memory_corruption
  79.  
  80. IRQL_NOT_LESS_OR_EQUAL (a)
  81. An attempt was made to access a pageable (or completely invalid) address at an
  82. interrupt request level (IRQL) that is too high. This is usually
  83. caused by drivers using improper addresses.
  84. If a kernel debugger is available get the stack backtrace.
  85.  
  86. Arguments:
  87. Arg1: fffff80733727f08, memory referenced
  88. Arg2: 000000000000000b, IRQL
  89. Arg3: 0000000000000001, bitfield :
  90. bit 0 : value 0 = read operation, 1 = write operation
  91. bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
  92. Arg4: fffff8072c64f52c, address which referenced memory
  93.  
  94. Debugging Details:
  95. DUMP_CLASS: 1
  96. DUMP_QUALIFIER: 400
  97. DUMP_TYPE: 2
  98. WRITE_ADDRESS: fffff8072cb733b8: Unable to get MiVisibleState
  99. fffff80733727f08
  100. CURRENT_IRQL: b
  101. FAULTING_IP:
  102. nt!PerfInfoLogInterrupt+fc
  103. fffff807`2c64f52c e87fdd1400 call nt!_security_check_cookie (fffff807`2c79d2b0)
  104. CUSTOMER_CRASH_COUNT: 1
  105. DEFAULT_BUCKET_ID: CODE_CORRUPTION
  106. BUGCHECK_STR: AV
  107.  
  108. PROCESS_NAME: System
  109.  
  110. TRAP_FRAME: fffff80733747d80 -- (.trap 0xfffff80733747d80)
  111. NOTE: The trap frame does not contain all registers.
  112. Some register values may be zeroed or incorrect.
  113. rax=ffffbd8a9849400e rbx=0000000000000000 rcx=00004598453319ce
  114. rdx=0000000000010023 rsi=0000000000000000 rdi=0000000000000000
  115. rip=fffff8072c64f52c rsp=fffff80733747f10 rbp=0000000000000000
  116. r8=0000000000000f43 r9=0000000000000000 r10=fffff8072c73d490
  117. r11=ffffbd8a98494088 r12=0000000000000000 r13=0000000000000000
  118. r14=0000000000000000 r15=0000000000000000
  119. iopl=0 nv up ei pl nz na pe nc
  120. nt!PerfInfoLogInterrupt+0xfc:
  121. fffff807`2c64f52c e87fdd1400 call nt!_security_check_cookie (fffff807`2c79d2b0)
  122. Resetting default scope
  123. LAST_CONTROL_TRANSFER: from fffff8072c7d41e9 to fffff8072c7c23a0
  124. STACK_TEXT:
  125. fffff807`33747c38 fffff807`2c7d41e9 : 00000000`0000000a fffff807`33727f08 00000000`0000000b 00000000`00000001 : nt!KeBugCheckEx
  126. fffff807`33747c40 fffff807`2c7d0529 : 00000000`00000000 00000000`00000000 00000000`00000000 ffff9700`f1420180 : nt!KiBugCheckDispatch+0x69
  127. fffff807`33747d80 fffff807`2c64f52c : 00000000`00000000 ffffbd8a`981c9000 ffffbd9f`7647678e 00000000`00000002 : nt!KiPageFault+0x469
  128. fffff807`33747f10 fffff807`2c7c3bcb : fffff807`2a64a180 fffff807`33738a50 ffff9700`f1bba640 ffff9700`f1bba640 : nt!PerfInfoLogInterrupt+0xfc
  129. fffff807`33747f90 fffff807`2c7c3e77 : 00000000`00000000 fffff807`2a64a180 fffff807`33738b00 00000000`00000001 : nt!KiInterruptSubDispatch+0x13b
  130. fffff807`337389d0 fffff807`2c7c5e9a : 00000000`00000000 fffff807`2a64a180 ffffbd8a`a31d6080 00000000`000002d0 : nt!KiInterruptDispatch+0x37
  131. fffff807`33738b60 00000000`00000000 : fffff807`33739000 fffff807`33732000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x4a
  132. STACK_COMMAND: kb
  133. CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
  134. fffff8072c64ff5d-fffff8072c64ff5e 2 bytes - nt!KiRetireDpcList+40d
  135. [ 48 ff:4c 8b ]
  136. fffff8072c64ff64-fffff8072c64ff67 4 bytes - nt!KiRetireDpcList+414 (+0x07)
  137. [ 0f 1f 44 00:e8 07 89 a6 ]
  138. fffff8072c7c3ef8-fffff8072c7c3ef9 2 bytes - nt!KiInterruptDispatch+b8 (+0x173f94)
  139. [ 48 ff:4c 8b ]
  140. fffff8072c7c3eff-fffff8072c7c3f02 4 bytes - nt!KiInterruptDispatch+bf (+0x07)
  141. [ 0f 1f 44 00:e8 1c 62 8f ]
  142. 12 errors : !nt (fffff8072c64ff5d-fffff8072c7c3f02)
  143. MODULE_NAME: memory_corruption
  144.  
  145. IMAGE_NAME: memory_corruption
  146.  
  147. FOLLOWUP_NAME: memory_corruption
  148. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  149. MEMORY_CORRUPTOR: LARGE
  150. FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
  151. BUCKET_ID: MEMORY_CORRUPTION_LARGE
  152. PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
  153. TARGET_TIME: 2020-06-21T15:37:12.000Z
  154. SUITE_MASK: 784
  155. PRODUCT_TYPE: 1
  156. USER_LCID: 0
  157. FAILURE_ID_HASH_STRING: km:memory_corruption_large
  158. FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
  159. Followup: memory_corruption
  160.  
  161. ====================== Dump #1: 3RD PARTY DRIVERS ======================
  162.  
  163. May 10 2011 - AsrAppCharger.sys - ASRock App Charger driver
  164. Jun 03 2015 - iaStorA.sys - Intel SATA Storage Device RAID Controller
  165. Jun 23 2015 - RTKVHD64.sys - Realtek Audio System driver https://www.realtek.com/en/
  166. Apr 11 2018 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
  167. Jun 11 2018 - e1i65x64.sys - Intel(R) Gigabit Adapter driver
  168. Feb 19 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
  169. May 15 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
  170. May 20 2020 - FACEIT.sys - FACEIT Client https://www.faceit.com/
  171.  
  172. ================== Dump #1: 3RD PARTY DRIVERS (FULL) ===================
  173.  
  174. Image path: \SystemRoot\system32\DRIVERS\AsrAppCharger.sys
  175. Image name: AsrAppCharger.sys
  176. Search : https://www.google.com/search?q=AsrAppCharger.sys
  177. ADA Info : ASRock App Charger driver
  178. Timestamp : Tue May 10 2011
  179.  
  180. Image path: \SystemRoot\System32\drivers\iaStorA.sys
  181. Image name: iaStorA.sys
  182. Search : https://www.google.com/search?q=iaStorA.sys
  183. ADA Info : Intel SATA Storage Device RAID Controller
  184. Timestamp : Wed Jun 3 2015
  185.  
  186. Image path: \SystemRoot\system32\drivers\RTKVHD64.sys
  187. Image name: RTKVHD64.sys
  188. Search : https://www.google.com/search?q=RTKVHD64.sys
  189. ADA Info : Realtek Audio System driver https://www.realtek.com/en/
  190. Timestamp : Tue Jun 23 2015
  191.  
  192. Image path: \SystemRoot\System32\drivers\TeeDriverW8x64.sys
  193. Image name: TeeDriverW8x64.sys
  194. Search : https://www.google.com/search?q=TeeDriverW8x64.sys
  195. ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
  196. Timestamp : Wed Apr 11 2018
  197.  
  198. Mapped memory image file: C:\ProgramData\dbg\sym\e1i65x64.sys\5B1EB8E28e000\e1i65x64.sys
  199. Image path: \SystemRoot\System32\drivers\e1i65x64.sys
  200. Image name: e1i65x64.sys
  201. Search : https://www.google.com/search?q=e1i65x64.sys
  202. ADA Info : Intel(R) Gigabit Adapter driver
  203. Timestamp : Mon Jun 11 2018
  204. File version: 12.17.10.8
  205. Product version: 10.0.10011.16384
  206. File flags: 8 (Mask 3F) Private
  207. File OS: 40004 NT Win32
  208. File type: 3.6 Driver
  209. File date: 00000000.00000000
  210. CompanyName: Intel Corporation
  211. ProductName: Intel(R) Gigabit Adapter
  212. InternalName: e1i65x64.sys
  213. OriginalFilename: e1i65x64.sys
  214. ProductVersion: 12.17.10.8
  215. FileVersion: 12.17.10.8
  216. FileDescription: Intel(R) Gigabit Adapter NDIS 6.x driver
  217. LegalCopyright: Copyright(C) 2013, Intel Corporation. All rights reserved.
  218.  
  219. Image path: \SystemRoot\system32\drivers\nvhda64v.sys
  220. Image name: nvhda64v.sys
  221. Search : https://www.google.com/search?q=nvhda64v.sys
  222. ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
  223. Timestamp : Wed Feb 19 2020
  224.  
  225. Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d5216eae94436d77\nvlddmkm.sys
  226. Image name: nvlddmkm.sys
  227. Search : https://www.google.com/search?q=nvlddmkm.sys
  228. ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
  229. Timestamp : Fri May 15 2020
  230.  
  231. Image path: \SystemRoot\System32\Drivers\FACEIT.sys
  232. Image name: FACEIT.sys
  233. Search : https://www.google.com/search?q=FACEIT.sys
  234. ADA Info : FACEIT Client https://www.faceit.com/
  235. Timestamp : Wed May 20 2020
  236.  
  237. ====================== Dump #1: MICROSOFT DRIVERS ======================
  238.  
  239. ACPI.sys ACPI Driver for NT (Microsoft)
  240. acpiex.sys ACPIEx Driver (Microsoft)
  241. acpipagr.sys ACPI Processor Aggregator Device driver (Microsoft)
  242. afd.sys Ancillary Function Driver for WinSock (Microsoft)
  243. afunix.sys AF_UNIX Socket Provider driver (Microsoft)
  244. AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
  245. ahcache.sys Application Compatibility Cache (Microsoft)
  246. bam.sys BAM Kernal driver (Microsoft)
  247. BasicDisplay.sys Basic Display driver (Microsoft)
  248. BasicRender.sys Basic Render driver (Microsoft)
  249. Beep.SYS BEEP driver (Microsoft)
  250. BOOTVID.dll VGA Boot Driver (Microsoft)
  251. bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
  252. cdd.dll Canonical Display Driver (Microsoft)
  253. cdrom.sys SCSI CD-ROM Driver (Microsoft)
  254. CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
  255. CI.dll Code Integrity Module (Microsoft)
  256. CLASSPNP.SYS SCSI Class System Dll (Microsoft)
  257. cldflt.sys Cloud Files Mini Filter driver (Microsoft)
  258. CLFS.SYS Common Log File System Driver (Microsoft)
  259. clipsp.sys CLIP Service (Microsoft)
  260. cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
  261. cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
  262. CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
  263. condrv.sys Console Driver (Microsoft)
  264. crashdmp.sys Crash Dump driver (Microsoft)
  265. dfsc.sys DFS Namespace Client Driver (Microsoft)
  266. disk.sys PnP Disk Driver (Microsoft)
  267. drmk.sys Digital Rights Management (DRM) driver (Microsoft)
  268. dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  269. dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  270. dump_iaStorA.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  271. dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
  272. dxgmms2.sys DirectX Graphics MMS
  273. EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
  274. filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
  275. fileinfo.sys FileInfo Filter Driver (Microsoft)
  276. FLTMGR.SYS Filesystem Filter Manager (Microsoft)
  277. Fs_Rec.sys File System Recognizer Driver (Microsoft)
  278. fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
  279. fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
  280. gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
  281. hal.dll Hardware Abstraction Layer DLL (Microsoft)
  282. HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
  283. HIDCLASS.SYS Hid Class Library (Microsoft)
  284. HIDPARSE.SYS Hid Parsing Library (Microsoft)
  285. hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
  286. HTTP.sys HTTP Protocol Stack (Microsoft)
  287. hwpolicy.sys Hardware Policy Driver
  288. intelpep.sys Intel Power Engine Plugin (Microsoft)
  289. intelppm.sys Processor Device Driver (Microsoft)
  290. iorate.sys I/O rate control Filter (Microsoft)
  291. kbdclass.sys Keyboard Class Driver (Microsoft)
  292. kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
  293. kd.dll Local Kernal Debugger (Microsoft)
  294. kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
  295. ks.sys Kernal CSA Library (Microsoft)
  296. ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
  297. ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
  298. ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
  299. lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
  300. luafv.sys LUA File Virtualization Filter Driver (Microsoft)
  301. mcupdate_GenuineIntel.dll Intel Microcode Update Library (Microsoft)
  302. mmcss.sys MMCSS Driver (Microsoft)
  303. monitor.sys Monitor Driver (Microsoft)
  304. mouclass.sys Mouse Class Driver (Microsoft)
  305. mouhid.sys HID Mouse Filter Driver (Microsoft)
  306. mountmgr.sys Mount Point Manager (Microsoft)
  307. mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
  308. mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
  309. mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
  310. Msfs.SYS Mailslot driver (Microsoft)
  311. msisadrv.sys ISA Driver (Microsoft)
  312. mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
  313. msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
  314. mssmbios.sys System Management BIOS driver (Microsoft)
  315. mup.sys Multiple UNC Provider driver (Microsoft)
  316. ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
  317. ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
  318. NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
  319. ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
  320. NDProxy.sys NDIS Proxy driver (Microsoft)
  321. Ndu.sys Network Data Usage Monitoring driver (Microsoft)
  322. netbios.sys NetBIOS Interface driver (Microsoft)
  323. netbt.sys MBT Transport driver (Microsoft)
  324. NETIO.SYS Network I/O Subsystem (Microsoft)
  325. Npfs.SYS NPFS driver (Microsoft)
  326. npsvctrig.sys Named pipe service triggers (Microsoft)
  327. nsiproxy.sys NSI Proxy driver (Microsoft)
  328. Ntfs.sys NT File System Driver (Microsoft)
  329. ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
  330. ntosext.sys NTOS Extension Host driver (Microsoft)
  331. Null.SYS NULL Driver (Microsoft)
  332. pacer.sys QoS Packet Scheduler (Microsoft)
  333. partmgr.sys Partition driver (Microsoft)
  334. pci.sys NT Plug and Play PCI Enumerator (Microsoft)
  335. pcw.sys Performance Counter Driver (Microsoft)
  336. pdc.sys Power Dependency Coordinator Driver (Microsoft)
  337. peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
  338. portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
  339. PSHED.dll Platform Specific Hardware Error driver (Microsoft)
  340. rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
  341. raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
  342. raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
  343. rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
  344. rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
  345. rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
  346. rdyboost.sys ReadyBoost Driver (Microsoft)
  347. rspndr.sys Link-Layer Topology Responder driver (Microsoft)
  348. serenum.sys Serial Port Enumerator (Microsoft)
  349. serial.sys Serial Device Driver
  350. SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
  351. SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
  352. spaceport.sys Storage Spaces driver (Microsoft)
  353. srv2.sys Smb 2.0 Server driver (Microsoft)
  354. srvnet.sys Server Network driver (Microsoft)
  355. storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
  356. storqosflt.sys Storage QoS Filter driver (Microsoft)
  357. swenum.sys Plug and Play Software Device Enumerator (Microsoft)
  358. tbs.sys Export driver for kernel mode TPM API (Microsoft)
  359. tcpip.sys TCP/IP Protocol driver (Microsoft)
  360. tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
  361. TDI.SYS TDI Wrapper driver (Microsoft)
  362. tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
  363. tm.sys Kernel Transaction Manager driver (Microsoft)
  364. ucx01000.sys USB Controller Extension (Microsoft)
  365. umbus.sys User-Mode Bus Enumerator (Microsoft)
  366. usbaudio2.sys Microsoft USB Audio Class 2.0 Driver
  367. usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
  368. USBD.SYS Universal Serial Bus Driver (Microsoft)
  369. UsbHub3.sys USB3 HUB driver (Microsoft)
  370. USBXHCI.SYS USB XHCI driver (Microsoft)
  371. vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
  372. Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
  373. volmgr.sys Volume Manager Driver (Microsoft)
  374. volmgrx.sys Volume Manager Extension Driver (Microsoft)
  375. volsnap.sys Volume Shadow Copy driver (Microsoft)
  376. volume.sys Volume driver (Microsoft)
  377. vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
  378. wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
  379. watchdog.sys Watchdog driver (Microsoft)
  380. wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
  381. WdBoot.sys Microsoft Antimalware Boot driver
  382. Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
  383. WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
  384. WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
  385. WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
  386. werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
  387. wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
  388. win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
  389. win32kbase.sys Base Win32k Kernel Driver (Microsoft)
  390. win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
  391. WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
  392. WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
  393. winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
  394. winquic.sys QUIC Transport Protocol driver (Microsoft)
  395. wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
  396. WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
  397. Wof.sys Windows Overlay Filter (Microsoft)
  398. WppRecorder.sys WPP Trace Recorder (Microsoft)
  399. WSDPrint.sys Web Services Print Device driver (Microsoft)
  400.  
  401. ====================== Dump #1: UNLOADED MODULES =======================
  402.  
  403. fffff807`391d0000 fffff807`391de000 WSDPrint.sys
  404. fffff807`33db0000 fffff807`33dbf000 dump_storpor
  405. fffff807`35780000 fffff807`35cf3000 dump_iaStorA
  406. fffff807`35d20000 fffff807`35d3e000 dump_dumpfve
  407. fffff807`35320000 fffff807`3533e000 dam.sys
  408.  
  409. ====================== Dump #1: BIOS INFORMATION =======================
  410.  
  411. [SMBIOS Data Tables v2.8]
  412. [DMI Version - 0]
  413. [2.0 Calling Convention - No]
  414. [Table Size - 1735 bytes]
  415. [BIOS Information (Type 0) - Length 24 - Handle 0000h]
  416. Vendor American Megatrends Inc.
  417. BIOS Version P7.50
  418. BIOS Starting Address Segment f000
  419. BIOS Release Date 01/23/2018
  420. BIOS ROM Size e00000
  421. BIOS Characteristics
  422. 07: - PCI Supported
  423. 11: - Upgradeable FLASH BIOS
  424. 12: - BIOS Shadowing Supported
  425. 15: - CD-Boot Supported
  426. 16: - Selectable Boot Supported
  427. 17: - BIOS ROM Socketed
  428. 19: - EDD Supported
  429. 23: - 1.2MB Floppy Supported
  430. 24: - 720KB Floppy Supported
  431. 25: - 2.88MB Floppy Supported
  432. 26: - Print Screen Device Supported
  433. 27: - Keyboard Services Supported
  434. 28: - Serial Services Supported
  435. 29: - Printer Services Supported
  436. 32: - BIOS Vendor Reserved
  437. BIOS Characteristic Extensions
  438. 00: - ACPI Supported
  439. 01: - USB Legacy Supported
  440. 08: - BIOS Boot Specification Supported
  441. 10: - Specification Reserved
  442. 11: - Specification Reserved
  443. BIOS Major Revision 5
  444. BIOS Minor Revision 11
  445. EC Firmware Major Revision 255
  446. EC Firmware Minor Revision 255
  447. [System Information (Type 1) - Length 27 - Handle 0001h]
  448. UUID 00000000-0000-0000-0000-000000000000
  449. Wakeup Type Power Switch
  450. [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
  451. Manufacturer ASRock
  452. Product Z170 Pro4S
  453. Version
  454. Feature Flags 09h
  455. -453789984: - -453789936: - ÷7!ü
  456. Location
  457. Chassis Handle 0003h
  458. Board Type 0ah - Processor/Memory Module
  459. Number of Child Handles 0
  460. [System Enclosure (Type 3) - Length 25 - Handle 0003h]
  461. Chassis Type Desktop
  462. Bootup State Safe
  463. Power Supply State Safe
  464. Thermal State Safe
  465. Security Status None
  466. OEM Defined 0
  467. Height 0U
  468. Number of Power Cords 1
  469. Number of Contained Elements 1
  470. Contained Element Size 3
  471. [OEM Strings (Type 11) - Length 5 - Handle 000ah]
  472. Number of Strings 1
  473. [Cache Information (Type 7) - Length 19 - Handle 000dh]
  474. Socket Designation L1 Cache
  475. Cache Configuration 0180h - WB Enabled Int NonSocketed L1
  476. Maximum Cache Size 0080h - 128K
  477. Installed Size 0080h - 128K
  478. Supported SRAM Type 0020h - Synchronous
  479. Current SRAM Type 0020h - Synchronous
  480. Cache Speed 0ns
  481. Error Correction Type ParitySingle-Bit ECC
  482. System Cache Type Data
  483. Associativity 8-way Set-Associative
  484. [Cache Information (Type 7) - Length 19 - Handle 000eh]
  485. Socket Designation L1 Cache
  486. Cache Configuration 0180h - WB Enabled Int NonSocketed L1
  487. Maximum Cache Size 0080h - 128K
  488. Installed Size 0080h - 128K
  489. Supported SRAM Type 0020h - Synchronous
  490. Current SRAM Type 0020h - Synchronous
  491. Cache Speed 0ns
  492. Error Correction Type ParitySingle-Bit ECC
  493. System Cache Type Instruction
  494. Associativity 8-way Set-Associative
  495. [Cache Information (Type 7) - Length 19 - Handle 000fh]
  496. Socket Designation L2 Cache
  497. Cache Configuration 0181h - WB Enabled Int NonSocketed L2
  498. Maximum Cache Size 0400h - 1024K
  499. Installed Size 0400h - 1024K
  500. Supported SRAM Type 0020h - Synchronous
  501. Current SRAM Type 0020h - Synchronous
  502. Cache Speed 0ns
  503. Error Correction Type Multi-Bit ECC
  504. System Cache Type Unified
  505. Associativity 4-way Set-Associative
  506. [Cache Information (Type 7) - Length 19 - Handle 0010h]
  507. Socket Designation L3 Cache
  508. Cache Configuration 0182h - WB Enabled Int NonSocketed L3
  509. Maximum Cache Size 1800h - 6144K
  510. Installed Size 1800h - 6144K
  511. Supported SRAM Type 0020h - Synchronous
  512. Current SRAM Type 0020h - Synchronous
  513. Cache Speed 0ns
  514. Error Correction Type Specification Reserved
  515. System Cache Type Unified
  516. Associativity Specification Reserved
  517. [Processor Information (Type 4) - Length 48 - Handle 0011h]
  518. Socket Designation CPUSocket
  519. Processor Type Central Processor
  520. Processor Family cdh - Specification Reserved
  521. Processor Manufacturer Intel(R) Corporation
  522. Processor ID e3060500fffbebbf
  523. Processor Version Intel(R) Core(TM) i5-6600K CPU @ 3.50GHz
  524. Processor Voltage 8bh - 1.1V
  525. External Clock 100MHz
  526. Max Speed 5000MHz
  527. Current Speed 3500MHz
  528. Status Enabled Populated
  529. Processor Upgrade Other
  530. L1 Cache Handle 000eh
  531. L2 Cache Handle 000fh
  532. L3 Cache Handle 0010h
  533. [Physical Memory Array (Type 16) - Length 23 - Handle 0012h]
  534. Location 03h - SystemBoard/Motherboard
  535. Use 03h - System Memory
  536. Memory Error Correction 03h - None
  537. Maximum Capacity 67108864KB
  538. Number of Memory Devices 4
  539. [Memory Device (Type 17) - Length 40 - Handle 0013h]
  540. Physical Memory Array Handle 0012h
  541. Total Width 0 bits
  542. Data Width 0 bits
  543. Form Factor 09h - DIMM
  544. Device Locator ChannelA-DIMM0
  545. Bank Locator BANK 0
  546. Memory Type 02h - Unknown
  547. Type Detail 0000h -
  548. Speed 0MHz
  549. [Memory Device (Type 17) - Length 40 - Handle 0014h]
  550. Physical Memory Array Handle 0012h
  551. Total Width 64 bits
  552. Data Width 64 bits
  553. Size 8192MB
  554. Form Factor 09h - DIMM
  555. Device Locator ChannelA-DIMM1
  556. Bank Locator BANK 1
  557. Memory Type 1ah - Specification Reserved
  558. Type Detail 0080h - Synchronous
  559. Speed 3000MHz
  560. Manufacturer Kingston
  561. Part Number KHX3000C15D4/8GX
  562. [Memory Device (Type 17) - Length 40 - Handle 0015h]
  563. Physical Memory Array Handle 0012h
  564. Total Width 0 bits
  565. Data Width 0 bits
  566. Form Factor 09h - DIMM
  567. Device Locator ChannelB-DIMM0
  568. Bank Locator BANK 2
  569. Memory Type 02h - Unknown
  570. Type Detail 0000h -
  571. Speed 0MHz
  572. [Memory Device (Type 17) - Length 40 - Handle 0016h]
  573. Physical Memory Array Handle 0012h
  574. Total Width 64 bits
  575. Data Width 64 bits
  576. Size 8192MB
  577. Form Factor 09h - DIMM
  578. Device Locator ChannelB-DIMM1
  579. Bank Locator BANK 3
  580. Memory Type 1ah - Specification Reserved
  581. Type Detail 0080h - Synchronous
  582. Speed 3000MHz
  583. Manufacturer Kingston
  584. Part Number KHX3000C15D4/8GX
  585. [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0017h]
  586. Starting Address 00000000h
  587. Ending Address 00ffffffh
  588. Memory Array Handle 0012h
  589. Partition Width 02
  590. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0018h]
  591. Starting Address 00000000h
  592. Ending Address 007fffffh
  593. Memory Device Handle 0014h
  594. Mem Array Mapped Adr Handle 0017h
  595. Partition Row Position 01
  596. Interleave Position 01
  597. Interleave Data Depth 02
  598. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0019h]
  599. Starting Address 00800000h
  600. Ending Address 00ffffffh
  601. Memory Device Handle 0016h
  602. Mem Array Mapped Adr Handle 0017h
  603. Partition Row Position 01
  604. Interleave Position 02
  605. Interleave Data Depth 02
  606.  
  607. ========================== Dump #1: Extra #1 ===========================
  608.  
  609. 0: kd> !verifier
  610. Verify Flags Level 0x00000000
  611. STANDARD FLAGS:
  612. [X] (0x00000000) Automatic Checks
  613. [ ] (0x00000001) Special pool
  614. [ ] (0x00000002) Force IRQL checking
  615. [ ] (0x00000008) Pool tracking
  616. [ ] (0x00000010) I/O verification
  617. [ ] (0x00000020) Deadlock detection
  618. [ ] (0x00000080) DMA checking
  619. [ ] (0x00000100) Security checks
  620. [ ] (0x00000800) Miscellaneous checks
  621. [ ] (0x00020000) DDI compliance checking
  622. ADDITIONAL FLAGS:
  623. [ ] (0x00000004) Randomized low resources simulation
  624. [ ] (0x00000200) Force pending I/O requests
  625. [ ] (0x00000400) IRP logging
  626. [ ] (0x00002000) Invariant MDL checking for stack
  627. [ ] (0x00004000) Invariant MDL checking for driver
  628. [ ] (0x00008000) Power framework delay fuzzing
  629. [ ] (0x00010000) Port/miniport interface checking
  630. [ ] (0x00040000) Systematic low resources simulation
  631. [ ] (0x00080000) DDI compliance checking (additional)
  632. [ ] (0x00200000) NDIS/WIFI verification
  633. [ ] (0x00800000) Kernel synchronization delay fuzzing
  634. [ ] (0x01000000) VM switch verification
  635. [ ] (0x02000000) Code integrity checks
  636. [X] Indicates flag is enabled
  637. Summary of All Verifier Statistics
  638. RaiseIrqls 0x0
  639. AcquireSpinLocks 0x0
  640. Synch Executions 0x0
  641. Trims 0x0
  642. Pool Allocations Attempted 0x0
  643. Pool Allocations Succeeded 0x0
  644. Pool Allocations Succeeded SpecialPool 0x0
  645. Pool Allocations With NO TAG 0x0
  646. Pool Allocations Failed 0x0
  647. Current paged pool allocations 0x0 for 00000000 bytes
  648. Peak paged pool allocations 0x0 for 00000000 bytes
  649. Current nonpaged pool allocations 0x0 for 00000000 bytes
  650. Peak nonpaged pool allocations 0x0 for 00000000 bytes
  651.  
  652. ========================== Dump #1: Extra #2 ===========================
  653.  
  654. 0: kd> !thread
  655. THREAD fffff8072cb91400 Cid 0000.0000 Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor 0
  656. Not impersonating
  657. GetUlongFromAddress: unable to read from fffff8072ca2ca14
  658. Owning Process fffff8072cb8e9c0 Image: System Process
  659. Attached Process ffffbd8a9807e080 Image: System
  660. fffff78000000000: Unable to get shared data
  661. Wait Start TickCount 105133
  662. Context Switch Count 2437175 IdealProcessor: 0
  663. ReadMemory error: Cannot get nt!KeMaximumIncrement value.
  664. UserTime 00:00:00.000
  665. KernelTime 00:00:00.000
  666. Win32 Start Address nt!KiIdleLoop (0xfffff8072c7c5e50)
  667. Stack Init fffff80733738b90 Current fffff80733738b20
  668. Base fffff80733739000 Limit fffff80733732000 Call 0000000000000000
  669. Priority 0 BasePriority 0 PriorityDecrement 0 IoPriority 0 PagePriority 5
  670. Child-SP RetAddr : Args to Child : Call Site
  671. fffff807`33747c38 fffff807`2c7d41e9 : 00000000`0000000a fffff807`33727f08 00000000`0000000b 00000000`00000001 : nt!KeBugCheckEx
  672. fffff807`33747c40 fffff807`2c7d0529 : 00000000`00000000 00000000`00000000 00000000`00000000 ffff9700`f1420180 : nt!KiBugCheckDispatch+0x69
  673. fffff807`33747d80 fffff807`2c64f52c : 00000000`00000000 ffffbd8a`981c9000 ffffbd9f`7647678e 00000000`00000002 : nt!KiPageFault+0x469 (TrapFrame @ fffff807`33747d80)
  674. fffff807`33747f10 fffff807`2c7c3bcb : fffff807`2a64a180 fffff807`33738a50 ffff9700`f1bba640 ffff9700`f1bba640 : nt!PerfInfoLogInterrupt+0xfc
  675. fffff807`33747f90 fffff807`2c7c3e77 : 00000000`00000000 fffff807`2a64a180 fffff807`33738b00 00000000`00000001 : nt!KiInterruptSubDispatch+0x13b (TrapFrame @ fffff807`33747e70)
  676. fffff807`337389d0 fffff807`2c7c5e9a : 00000000`00000000 fffff807`2a64a180 ffffbd8a`a31d6080 00000000`000002d0 : nt!KiInterruptDispatch+0x37 (TrapFrame @ fffff807`337389d0)
  677. fffff807`33738b60 00000000`00000000 : fffff807`33739000 fffff807`33732000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x4a
  678.  
  679.  
  680. ========================================================================
  681. ======================= Dump #2: ANALYZE VERBOSE =======================
  682. ======================= File: 062120-7906-01.dmp =======================
  683. ========================================================================
  684.  
  685. Mini Kernel Dump File: Only registers and stack trace are available
  686. Windows 10 Kernel Version 18362 MP (4 procs) Free x64
  687. Kernel base = 0xfffff803`77c00000 PsLoadedModuleList = 0xfffff803`78048190
  688. Debug session time: Sun Jun 21 11:07:13.699 2020 (UTC - 4:00)
  689. System Uptime: 5 days 4:19:49.371
  690.  
  691. BugCheck A, {fffff8037c727b68, ff, 93, fffff80377c47d80}
  692. *** WARNING: Unable to verify timestamp for win32k.sys
  693. *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
  694. Probably caused by : memory_corruption
  695. Followup: memory_corruption
  696.  
  697. IRQL_NOT_LESS_OR_EQUAL (a)
  698. An attempt was made to access a pageable (or completely invalid) address at an
  699. interrupt request level (IRQL) that is too high. This is usually
  700. caused by drivers using improper addresses.
  701. If a kernel debugger is available get the stack backtrace.
  702.  
  703. Arguments:
  704. Arg1: fffff8037c727b68, memory referenced
  705. Arg2: 00000000000000ff, IRQL
  706. Arg3: 0000000000000093, bitfield :
  707. bit 0 : value 0 = read operation, 1 = write operation
  708. bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
  709. Arg4: fffff80377c47d80, address which referenced memory
  710.  
  711. Debugging Details:
  712. DUMP_CLASS: 1
  713. DUMP_QUALIFIER: 400
  714. DUMP_TYPE: 2
  715. WRITE_ADDRESS: fffff803781733b8: Unable to get MiVisibleState
  716. fffff8037c727b68
  717. CURRENT_IRQL: d
  718. FAULTING_IP:
  719. nt!KeClockInterruptNotify+350
  720. fffff803`77c47d80 e8eb5af1ff call hal!KeQueryPerformanceCounter (fffff803`77b5d870)
  721. CUSTOMER_CRASH_COUNT: 1
  722. DEFAULT_BUCKET_ID: CODE_CORRUPTION
  723. BUGCHECK_STR: AV
  724.  
  725. PROCESS_NAME: System
  726.  
  727. TRAP_FRAME: fffff8037c7479e0 -- (.trap 0xfffff8037c7479e0)
  728. NOTE: The trap frame does not contain all registers.
  729. Some register values may be zeroed or incorrect.
  730. rax=0000000017eddaa6 rbx=0000000000000000 rcx=0000000000000000
  731. rdx=fffff78000000340 rsi=0000000000000000 rdi=0000000000000000
  732. rip=fffff80377c47d80 rsp=fffff8037c747b70 rbp=0000000000000001
  733. r8=0000000000000008 r9=0000000000000000 r10=fffff80377b5d870
  734. r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
  735. r14=0000000000000000 r15=0000000000000000
  736. iopl=0 nv up di pl zr na po nc
  737. nt!KeClockInterruptNotify+0x350:
  738. fffff803`77c47d80 e8eb5af1ff call hal!KeQueryPerformanceCounter (fffff803`77b5d870)
  739. Resetting default scope
  740. LAST_CONTROL_TRANSFER: from fffff80377dd41e9 to fffff80377dc23a0
  741. STACK_TEXT:
  742. fffff803`7c747898 fffff803`77dd41e9 : 00000000`0000000a fffff803`7c727b68 00000000`000000ff 00000000`00000093 : nt!KeBugCheckEx
  743. fffff803`7c7478a0 fffff803`77dd0529 : 00000000`00000000 00000000`00000000 fffff803`7c747c20 fffff803`7ca13514 : nt!KiBugCheckDispatch+0x69
  744. fffff803`7c7479e0 fffff803`77c47d80 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`01c15855 : nt!KiPageFault+0x469
  745. fffff803`7c747b70 fffff803`77b5d567 : fffff803`73592180 fffff803`7c7389d0 fffff803`7c738a50 00000000`00000000 : nt!KeClockInterruptNotify+0x350
  746. fffff803`7c747f30 fffff803`77d37385 : 00000412`27acfa3a fffff803`77bcc100 fffff803`77bcc1b0 ffff28c4`2dabfe92 : hal!HalpTimerClockInterrupt+0xf7
  747. fffff803`7c747f60 fffff803`77dc3e2a : fffff803`7c738a50 fffff803`77bcc100 00000000`00000810 fffff803`77bcc100 : nt!KiCallInterruptServiceRoutine+0xa5
  748. fffff803`7c747fb0 fffff803`77dc4397 : 00000000`00000000 fffff803`73592180 fffff803`7c738b00 00000000`00000001 : nt!KiInterruptSubDispatchNoLockNoEtw+0xfa
  749. fffff803`7c7389d0 fffff803`77dc5e9a : 00000000`00000000 fffff803`73592180 ffff9001`0f546580 00000000`00000810 : nt!KiInterruptDispatchNoLockNoEtw+0x37
  750. fffff803`7c738b60 00000000`00000000 : fffff803`7c739000 fffff803`7c732000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x4a
  751. STACK_COMMAND: kb
  752. CHKIMG_EXTENSION: !chkimg -lo 50 -d !hal
  753. fffff80377b5d4cc-fffff80377b5d4cd 2 bytes - hal!HalpTimerClockInterrupt+5c
  754. [ 48 ff:4c 8b ]
  755. fffff80377b5d4d3-fffff80377b5d4d6 4 bytes - hal!HalpTimerClockInterrupt+63 (+0x07)
  756. [ 0f 1f 44 00:e8 18 13 0d ]
  757. fffff80377b5d51c-fffff80377b5d51d 2 bytes - hal!HalpTimerClockInterrupt+ac (+0x49)
  758. [ 48 ff:4c 8b ]
  759. fffff80377b5d523-fffff80377b5d526 4 bytes - hal!HalpTimerClockInterrupt+b3 (+0x07)
  760. [ 0f 1f 44 00:e8 e8 ea 1a ]
  761. fffff80377b5d55b-fffff80377b5d55c 2 bytes - hal!HalpTimerClockInterrupt+eb (+0x38)
  762. [ 48 ff:4c 8b ]
  763. fffff80377b5d562-fffff80377b5d565 4 bytes - hal!HalpTimerClockInterrupt+f2 (+0x07)
  764. [ 0f 1f 44 00:e8 c9 a4 0e ]
  765. fffff80377b5d8ec-fffff80377b5d8ed 2 bytes - hal!KeQueryPerformanceCounter+7c (+0x38a)
  766. [ 48 ff:4c 8b ]
  767. fffff80377b5d8f3-fffff80377b5d8f6 4 bytes - hal!KeQueryPerformanceCounter+83 (+0x07)
  768. [ 0f 1f 44 00:e8 58 28 19 ]
  769. fffff80377b98d3a-fffff80377b98d3b 2 bytes - hal!IommuHvDevicePowerChange+4a (+0x3b447)
  770. [ 48 ff:4c 8b ]
  771. fffff80377b98d41-fffff80377b98d44 4 bytes - hal!IommuHvDevicePowerChange+51 (+0x07)
  772. [ 0f 1f 44 00:e8 5a 96 22 ]
  773. 30 errors : !hal (fffff80377b5d4cc-fffff80377b98d44)
  774. MODULE_NAME: memory_corruption
  775.  
  776. IMAGE_NAME: memory_corruption
  777.  
  778. FOLLOWUP_NAME: memory_corruption
  779. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  780. MEMORY_CORRUPTOR: LARGE
  781. FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
  782. BUCKET_ID: MEMORY_CORRUPTION_LARGE
  783. PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
  784. TARGET_TIME: 2020-06-21T15:07:13.000Z
  785. SUITE_MASK: 784
  786. PRODUCT_TYPE: 1
  787. USER_LCID: 0
  788. FAILURE_ID_HASH_STRING: km:memory_corruption_large
  789. FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
  790. Followup: memory_corruption
  791.  
  792. ====================== Dump #2: 3RD PARTY DRIVERS ======================
  793.  
  794. May 10 2011 - AsrAppCharger.sys - ASRock App Charger driver
  795. Jun 03 2015 - iaStorA.sys - Intel SATA Storage Device RAID Controller
  796. Jun 23 2015 - RTKVHD64.sys - Realtek Audio System driver https://www.realtek.com/en/
  797. Apr 11 2018 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
  798. Jun 11 2018 - e1i65x64.sys - Intel(R) Gigabit Adapter driver
  799. Feb 19 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
  800. May 15 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
  801. May 20 2020 - FACEIT.sys - FACEIT Client https://www.faceit.com/
  802.  
  803. ================== Dump #2: 3RD PARTY DRIVERS (FULL) ===================
  804.  
  805. Image path: \SystemRoot\system32\DRIVERS\AsrAppCharger.sys
  806. Image name: AsrAppCharger.sys
  807. Search : https://www.google.com/search?q=AsrAppCharger.sys
  808. ADA Info : ASRock App Charger driver
  809. Timestamp : Tue May 10 2011
  810.  
  811. Image path: \SystemRoot\System32\drivers\iaStorA.sys
  812. Image name: iaStorA.sys
  813. Search : https://www.google.com/search?q=iaStorA.sys
  814. ADA Info : Intel SATA Storage Device RAID Controller
  815. Timestamp : Wed Jun 3 2015
  816.  
  817. Image path: \SystemRoot\system32\drivers\RTKVHD64.sys
  818. Image name: RTKVHD64.sys
  819. Search : https://www.google.com/search?q=RTKVHD64.sys
  820. ADA Info : Realtek Audio System driver https://www.realtek.com/en/
  821. Timestamp : Tue Jun 23 2015
  822.  
  823. Image path: \SystemRoot\System32\drivers\TeeDriverW8x64.sys
  824. Image name: TeeDriverW8x64.sys
  825. Search : https://www.google.com/search?q=TeeDriverW8x64.sys
  826. ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
  827. Timestamp : Wed Apr 11 2018
  828.  
  829. Mapped memory image file: C:\ProgramData\dbg\sym\e1i65x64.sys\5B1EB8E28e000\e1i65x64.sys
  830. Image path: \SystemRoot\System32\drivers\e1i65x64.sys
  831. Image name: e1i65x64.sys
  832. Search : https://www.google.com/search?q=e1i65x64.sys
  833. ADA Info : Intel(R) Gigabit Adapter driver
  834. Timestamp : Mon Jun 11 2018
  835. File version: 12.17.10.8
  836. Product version: 10.0.10011.16384
  837. File flags: 8 (Mask 3F) Private
  838. File OS: 40004 NT Win32
  839. File type: 3.6 Driver
  840. File date: 00000000.00000000
  841. CompanyName: Intel Corporation
  842. ProductName: Intel(R) Gigabit Adapter
  843. InternalName: e1i65x64.sys
  844. OriginalFilename: e1i65x64.sys
  845. ProductVersion: 12.17.10.8
  846. FileVersion: 12.17.10.8
  847. FileDescription: Intel(R) Gigabit Adapter NDIS 6.x driver
  848. LegalCopyright: Copyright(C) 2013, Intel Corporation. All rights reserved.
  849.  
  850. Image path: \SystemRoot\system32\drivers\nvhda64v.sys
  851. Image name: nvhda64v.sys
  852. Search : https://www.google.com/search?q=nvhda64v.sys
  853. ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
  854. Timestamp : Wed Feb 19 2020
  855.  
  856. Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d5216eae94436d77\nvlddmkm.sys
  857. Image name: nvlddmkm.sys
  858. Search : https://www.google.com/search?q=nvlddmkm.sys
  859. ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
  860. Timestamp : Fri May 15 2020
  861.  
  862. Image path: \SystemRoot\System32\Drivers\FACEIT.sys
  863. Image name: FACEIT.sys
  864. Search : https://www.google.com/search?q=FACEIT.sys
  865. ADA Info : FACEIT Client https://www.faceit.com/
  866. Timestamp : Wed May 20 2020
  867.  
  868. ====================== Dump #2: MICROSOFT DRIVERS ======================
  869.  
  870. ACPI.sys ACPI Driver for NT (Microsoft)
  871. acpiex.sys ACPIEx Driver (Microsoft)
  872. acpipagr.sys ACPI Processor Aggregator Device driver (Microsoft)
  873. afd.sys Ancillary Function Driver for WinSock (Microsoft)
  874. afunix.sys AF_UNIX Socket Provider driver (Microsoft)
  875. AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
  876. ahcache.sys Application Compatibility Cache (Microsoft)
  877. bam.sys BAM Kernal driver (Microsoft)
  878. BasicDisplay.sys Basic Display driver (Microsoft)
  879. BasicRender.sys Basic Render driver (Microsoft)
  880. Beep.SYS BEEP driver (Microsoft)
  881. bindflt.sys Windows Bind Filter driver (Microsoft)
  882. BOOTVID.dll VGA Boot Driver (Microsoft)
  883. bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
  884. cdd.dll Canonical Display Driver (Microsoft)
  885. cdrom.sys SCSI CD-ROM Driver (Microsoft)
  886. CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
  887. CI.dll Code Integrity Module (Microsoft)
  888. CLASSPNP.SYS SCSI Class System Dll (Microsoft)
  889. cldflt.sys Cloud Files Mini Filter driver (Microsoft)
  890. CLFS.SYS Common Log File System Driver (Microsoft)
  891. clipsp.sys CLIP Service (Microsoft)
  892. cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
  893. cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
  894. CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
  895. condrv.sys Console Driver (Microsoft)
  896. crashdmp.sys Crash Dump driver (Microsoft)
  897. dfsc.sys DFS Namespace Client Driver (Microsoft)
  898. disk.sys PnP Disk Driver (Microsoft)
  899. drmk.sys Digital Rights Management (DRM) driver (Microsoft)
  900. dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  901. dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  902. dump_iaStorA.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  903. dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
  904. dxgmms2.sys DirectX Graphics MMS
  905. EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
  906. filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
  907. fileinfo.sys FileInfo Filter Driver (Microsoft)
  908. FLTMGR.SYS Filesystem Filter Manager (Microsoft)
  909. Fs_Rec.sys File System Recognizer Driver (Microsoft)
  910. fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
  911. fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
  912. gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
  913. hal.dll Hardware Abstraction Layer DLL (Microsoft)
  914. HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
  915. HIDCLASS.SYS Hid Class Library (Microsoft)
  916. HIDPARSE.SYS Hid Parsing Library (Microsoft)
  917. hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
  918. HTTP.sys HTTP Protocol Stack (Microsoft)
  919. hwpolicy.sys Hardware Policy Driver
  920. intelpep.sys Intel Power Engine Plugin (Microsoft)
  921. intelppm.sys Processor Device Driver (Microsoft)
  922. iorate.sys I/O rate control Filter (Microsoft)
  923. kbdclass.sys Keyboard Class Driver (Microsoft)
  924. kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
  925. kd.dll Local Kernal Debugger (Microsoft)
  926. kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
  927. ks.sys Kernal CSA Library (Microsoft)
  928. ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
  929. ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
  930. ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
  931. lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
  932. luafv.sys LUA File Virtualization Filter Driver (Microsoft)
  933. mcupdate_GenuineIntel.dll Intel Microcode Update Library (Microsoft)
  934. mmcss.sys MMCSS Driver (Microsoft)
  935. monitor.sys Monitor Driver (Microsoft)
  936. mouclass.sys Mouse Class Driver (Microsoft)
  937. mouhid.sys HID Mouse Filter Driver (Microsoft)
  938. mountmgr.sys Mount Point Manager (Microsoft)
  939. mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
  940. mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
  941. mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
  942. Msfs.SYS Mailslot driver (Microsoft)
  943. msisadrv.sys ISA Driver (Microsoft)
  944. mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
  945. msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
  946. mssmbios.sys System Management BIOS driver (Microsoft)
  947. mup.sys Multiple UNC Provider driver (Microsoft)
  948. ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
  949. ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
  950. ndisuio.sys NDIS User mode I/O driver (Microsoft)
  951. NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
  952. ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
  953. NDProxy.sys NDIS Proxy driver (Microsoft)
  954. Ndu.sys Network Data Usage Monitoring driver (Microsoft)
  955. netbios.sys NetBIOS Interface driver (Microsoft)
  956. netbt.sys MBT Transport driver (Microsoft)
  957. NETIO.SYS Network I/O Subsystem (Microsoft)
  958. Npfs.SYS NPFS driver (Microsoft)
  959. npsvctrig.sys Named pipe service triggers (Microsoft)
  960. nsiproxy.sys NSI Proxy driver (Microsoft)
  961. Ntfs.sys NT File System Driver (Microsoft)
  962. ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
  963. ntosext.sys NTOS Extension Host driver (Microsoft)
  964. Null.SYS NULL Driver (Microsoft)
  965. pacer.sys QoS Packet Scheduler (Microsoft)
  966. partmgr.sys Partition driver (Microsoft)
  967. pci.sys NT Plug and Play PCI Enumerator (Microsoft)
  968. pcw.sys Performance Counter Driver (Microsoft)
  969. pdc.sys Power Dependency Coordinator Driver (Microsoft)
  970. peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
  971. portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
  972. PSHED.dll Platform Specific Hardware Error driver (Microsoft)
  973. rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
  974. raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
  975. raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
  976. rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
  977. rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
  978. rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
  979. rdpvideominiport.sys RDP Video Miniport driver (Microsoft)
  980. rdyboost.sys ReadyBoost Driver (Microsoft)
  981. rspndr.sys Link-Layer Topology Responder driver (Microsoft)
  982. serenum.sys Serial Port Enumerator (Microsoft)
  983. serial.sys Serial Device Driver
  984. SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
  985. SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
  986. spaceport.sys Storage Spaces driver (Microsoft)
  987. srv2.sys Smb 2.0 Server driver (Microsoft)
  988. srvnet.sys Server Network driver (Microsoft)
  989. storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
  990. storqosflt.sys Storage QoS Filter driver (Microsoft)
  991. swenum.sys Plug and Play Software Device Enumerator (Microsoft)
  992. tbs.sys Export driver for kernel mode TPM API (Microsoft)
  993. tcpip.sys TCP/IP Protocol driver (Microsoft)
  994. tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
  995. TDI.SYS TDI Wrapper driver (Microsoft)
  996. tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
  997. tm.sys Kernel Transaction Manager driver (Microsoft)
  998. ucx01000.sys USB Controller Extension (Microsoft)
  999. umbus.sys User-Mode Bus Enumerator (Microsoft)
  1000. usbaudio2.sys Microsoft USB Audio Class 2.0 Driver
  1001. usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
  1002. USBD.SYS Universal Serial Bus Driver (Microsoft)
  1003. UsbHub3.sys USB3 HUB driver (Microsoft)
  1004. USBXHCI.SYS USB XHCI driver (Microsoft)
  1005. vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
  1006. Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
  1007. volmgr.sys Volume Manager Driver (Microsoft)
  1008. volmgrx.sys Volume Manager Extension Driver (Microsoft)
  1009. volsnap.sys Volume Shadow Copy driver (Microsoft)
  1010. volume.sys Volume driver (Microsoft)
  1011. vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
  1012. wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
  1013. watchdog.sys Watchdog driver (Microsoft)
  1014. wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
  1015. WdBoot.sys Microsoft Antimalware Boot driver
  1016. Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
  1017. WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
  1018. WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
  1019. WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
  1020. werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
  1021. wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
  1022. win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
  1023. win32kbase.sys Base Win32k Kernel Driver (Microsoft)
  1024. win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
  1025. WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
  1026. WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
  1027. winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
  1028. winquic.sys QUIC Transport Protocol driver (Microsoft)
  1029. wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
  1030. WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
  1031. Wof.sys Windows Overlay Filter (Microsoft)
  1032. WppRecorder.sys WPP Trace Recorder (Microsoft)
  1033. WSDPrint.sys Web Services Print Device driver (Microsoft)
  1034.  
  1035. ====================== Dump #2: UNLOADED MODULES =======================
  1036.  
  1037. fffff803`7f8c0000 fffff803`7f906000 usbaudio2.sy
  1038. fffff803`7f910000 fffff803`7f91f000 hiber_storpo
  1039. fffff803`73f50000 fffff803`744c3000 hiber_iaStor
  1040. fffff803`744d0000 fffff803`744ee000 hiber_dumpfv
  1041. fffff803`7f860000 fffff803`7f8a6000 usbaudio2.sy
  1042. fffff803`7f8b0000 fffff803`7f8bf000 hiber_storpo
  1043. fffff803`74330000 fffff803`748a3000 hiber_iaStor
  1044. fffff803`748b0000 fffff803`748ce000 hiber_dumpfv
  1045. fffff803`7f8c0000 fffff803`7f906000 usbaudio2.sy
  1046. fffff803`7f910000 fffff803`7f91f000 hiber_storpo
  1047. fffff803`73e80000 fffff803`743f3000 hiber_iaStor
  1048. fffff803`73600000 fffff803`7361e000 hiber_dumpfv
  1049. fffff803`7f860000 fffff803`7f8a6000 usbaudio2.sy
  1050. fffff803`7f8b0000 fffff803`7f8bf000 hiber_storpo
  1051. fffff803`73f30000 fffff803`744a3000 hiber_iaStor
  1052. fffff803`744b0000 fffff803`744ce000 hiber_dumpfv
  1053. fffff803`7f7c0000 fffff803`7f7ce000 WSDPrint.sys
  1054. fffff803`7f900000 fffff803`7f90e000 WSDPrint.sys
  1055. fffff803`7f790000 fffff803`7f79f000 hiber_storpo
  1056. fffff803`761e0000 fffff803`76753000 hiber_iaStor
  1057. fffff803`76760000 fffff803`7677e000 hiber_dumpfv
  1058. fffff803`7f8a0000 fffff803`7f8e6000 usbaudio2.sy
  1059. fffff803`7f910000 fffff803`7f91f000 hiber_storpo
  1060. fffff803`769e0000 fffff803`76f53000 hiber_iaStor
  1061. fffff803`76f60000 fffff803`76f7e000 hiber_dumpfv
  1062. fffff803`7f8f0000 fffff803`7f8fe000 WSDPrint.sys
  1063. fffff803`7f880000 fffff803`7f88e000 WSDPrint.sys
  1064. fffff803`7f850000 fffff803`7f861000 MpKslDrv.sys
  1065. fffff803`7f890000 fffff803`7f89f000 hiber_storpo
  1066. fffff803`77070000 fffff803`775e3000 hiber_iaStor
  1067. fffff803`76400000 fffff803`7641e000 hiber_dumpfv
  1068. fffff803`7f8c0000 fffff803`7f906000 usbaudio2.sy
  1069. fffff803`7f870000 fffff803`7f87e000 WSDPrint.sys
  1070. fffff803`7f7c0000 fffff803`7f7ce000 WSDPrint.sys
  1071. fffff803`7f860000 fffff803`7f8a6000 usbaudio2.sy
  1072. fffff803`7f8b0000 fffff803`7f8bf000 hiber_storpo
  1073. fffff803`73850000 fffff803`73dc3000 hiber_iaStor
  1074. fffff803`73dd0000 fffff803`73dee000 hiber_dumpfv
  1075. fffff803`80780000 fffff803`807c6000 usbaudio2.sy
  1076. fffff803`7f850000 fffff803`7f85f000 hiber_storpo
  1077. fffff803`745b0000 fffff803`74b23000 hiber_iaStor
  1078. fffff803`74b30000 fffff803`74b4e000 hiber_dumpfv
  1079. fffff803`7f790000 fffff803`7f79e000 WSDPrint.sys
  1080. fffff803`7ce80000 fffff803`7ce8f000 dump_storpor
  1081. fffff803`7d600000 fffff803`7db73000 dump_iaStorA
  1082. fffff803`7dba0000 fffff803`7dbbe000 dump_dumpfve
  1083. fffff803`7cf50000 fffff803`7cf6e000 dam.sys
  1084.  
  1085. ====================== Dump #2: BIOS INFORMATION =======================
  1086.  
  1087. [SMBIOS Data Tables v2.8]
  1088. [DMI Version - 0]
  1089. [2.0 Calling Convention - No]
  1090. [Table Size - 1735 bytes]
  1091. [BIOS Information (Type 0) - Length 24 - Handle 0000h]
  1092. Vendor American Megatrends Inc.
  1093. BIOS Version P7.50
  1094. BIOS Starting Address Segment f000
  1095. BIOS Release Date 01/23/2018
  1096. BIOS ROM Size e00000
  1097. BIOS Characteristics
  1098. 07: - PCI Supported
  1099. 11: - Upgradeable FLASH BIOS
  1100. 12: - BIOS Shadowing Supported
  1101. 15: - CD-Boot Supported
  1102. 16: - Selectable Boot Supported
  1103. 17: - BIOS ROM Socketed
  1104. 19: - EDD Supported
  1105. 23: - 1.2MB Floppy Supported
  1106. 24: - 720KB Floppy Supported
  1107. 25: - 2.88MB Floppy Supported
  1108. 26: - Print Screen Device Supported
  1109. 27: - Keyboard Services Supported
  1110. 28: - Serial Services Supported
  1111. 29: - Printer Services Supported
  1112. 32: - BIOS Vendor Reserved
  1113. BIOS Characteristic Extensions
  1114. 00: - ACPI Supported
  1115. 01: - USB Legacy Supported
  1116. 08: - BIOS Boot Specification Supported
  1117. 10: - Specification Reserved
  1118. 11: - Specification Reserved
  1119. BIOS Major Revision 5
  1120. BIOS Minor Revision 11
  1121. EC Firmware Major Revision 255
  1122. EC Firmware Minor Revision 255
  1123. [System Information (Type 1) - Length 27 - Handle 0001h]
  1124. UUID 00000000-0000-0000-0000-000000000000
  1125. Wakeup Type Power Switch
  1126. [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
  1127. Manufacturer ASRock
  1128. Product Z170 Pro4S
  1129. Version
  1130. Feature Flags 09h
  1131. -449726752: - -449726704: - ÷7!ü
  1132. Location
  1133. Chassis Handle 0003h
  1134. Board Type 0ah - Processor/Memory Module
  1135. Number of Child Handles 0
  1136. [System Enclosure (Type 3) - Length 25 - Handle 0003h]
  1137. Chassis Type Desktop
  1138. Bootup State Safe
  1139. Power Supply State Safe
  1140. Thermal State Safe
  1141. Security Status None
  1142. OEM Defined 0
  1143. Height 0U
  1144. Number of Power Cords 1
  1145. Number of Contained Elements 1
  1146. Contained Element Size 3
  1147. [OEM Strings (Type 11) - Length 5 - Handle 000ah]
  1148. Number of Strings 1
  1149. [Cache Information (Type 7) - Length 19 - Handle 000dh]
  1150. Socket Designation L1 Cache
  1151. Cache Configuration 0180h - WB Enabled Int NonSocketed L1
  1152. Maximum Cache Size 0080h - 128K
  1153. Installed Size 0080h - 128K
  1154. Supported SRAM Type 0020h - Synchronous
  1155. Current SRAM Type 0020h - Synchronous
  1156. Cache Speed 0ns
  1157. Error Correction Type ParitySingle-Bit ECC
  1158. System Cache Type Data
  1159. Associativity 8-way Set-Associative
  1160. [Cache Information (Type 7) - Length 19 - Handle 000eh]
  1161. Socket Designation L1 Cache
  1162. Cache Configuration 0180h - WB Enabled Int NonSocketed L1
  1163. Maximum Cache Size 0080h - 128K
  1164. Installed Size 0080h - 128K
  1165. Supported SRAM Type 0020h - Synchronous
  1166. Current SRAM Type 0020h - Synchronous
  1167. Cache Speed 0ns
  1168. Error Correction Type ParitySingle-Bit ECC
  1169. System Cache Type Instruction
  1170. Associativity 8-way Set-Associative
  1171. [Cache Information (Type 7) - Length 19 - Handle 000fh]
  1172. Socket Designation L2 Cache
  1173. Cache Configuration 0181h - WB Enabled Int NonSocketed L2
  1174. Maximum Cache Size 0400h - 1024K
  1175. Installed Size 0400h - 1024K
  1176. Supported SRAM Type 0020h - Synchronous
  1177. Current SRAM Type 0020h - Synchronous
  1178. Cache Speed 0ns
  1179. Error Correction Type Multi-Bit ECC
  1180. System Cache Type Unified
  1181. Associativity 4-way Set-Associative
  1182. [Cache Information (Type 7) - Length 19 - Handle 0010h]
  1183. Socket Designation L3 Cache
  1184. Cache Configuration 0182h - WB Enabled Int NonSocketed L3
  1185. Maximum Cache Size 1800h - 6144K
  1186. Installed Size 1800h - 6144K
  1187. Supported SRAM Type 0020h - Synchronous
  1188. Current SRAM Type 0020h - Synchronous
  1189. Cache Speed 0ns
  1190. Error Correction Type Specification Reserved
  1191. System Cache Type Unified
  1192. Associativity Specification Reserved
  1193. [Processor Information (Type 4) - Length 48 - Handle 0011h]
  1194. Socket Designation CPUSocket
  1195. Processor Type Central Processor
  1196. Processor Family cdh - Specification Reserved
  1197. Processor Manufacturer Intel(R) Corporation
  1198. Processor ID e3060500fffbebbf
  1199. Processor Version Intel(R) Core(TM) i5-6600K CPU @ 3.50GHz
  1200. Processor Voltage 8bh - 1.1V
  1201. External Clock 100MHz
  1202. Max Speed 5000MHz
  1203. Current Speed 3500MHz
  1204. Status Enabled Populated
  1205. Processor Upgrade Other
  1206. L1 Cache Handle 000eh
  1207. L2 Cache Handle 000fh
  1208. L3 Cache Handle 0010h
  1209. [Physical Memory Array (Type 16) - Length 23 - Handle 0012h]
  1210. Location 03h - SystemBoard/Motherboard
  1211. Use 03h - System Memory
  1212. Memory Error Correction 03h - None
  1213. Maximum Capacity 67108864KB
  1214. Number of Memory Devices 4
  1215. [Memory Device (Type 17) - Length 40 - Handle 0013h]
  1216. Physical Memory Array Handle 0012h
  1217. Total Width 0 bits
  1218. Data Width 0 bits
  1219. Form Factor 09h - DIMM
  1220. Device Locator ChannelA-DIMM0
  1221. Bank Locator BANK 0
  1222. Memory Type 02h - Unknown
  1223. Type Detail 0000h -
  1224. Speed 0MHz
  1225. [Memory Device (Type 17) - Length 40 - Handle 0014h]
  1226. Physical Memory Array Handle 0012h
  1227. Total Width 64 bits
  1228. Data Width 64 bits
  1229. Size 8192MB
  1230. Form Factor 09h - DIMM
  1231. Device Locator ChannelA-DIMM1
  1232. Bank Locator BANK 1
  1233. Memory Type 1ah - Specification Reserved
  1234. Type Detail 0080h - Synchronous
  1235. Speed 3000MHz
  1236. Manufacturer Kingston
  1237. Part Number KHX3000C15D4/8GX
  1238. [Memory Device (Type 17) - Length 40 - Handle 0015h]
  1239. Physical Memory Array Handle 0012h
  1240. Total Width 0 bits
  1241. Data Width 0 bits
  1242. Form Factor 09h - DIMM
  1243. Device Locator ChannelB-DIMM0
  1244. Bank Locator BANK 2
  1245. Memory Type 02h - Unknown
  1246. Type Detail 0000h -
  1247. Speed 0MHz
  1248. [Memory Device (Type 17) - Length 40 - Handle 0016h]
  1249. Physical Memory Array Handle 0012h
  1250. Total Width 64 bits
  1251. Data Width 64 bits
  1252. Size 8192MB
  1253. Form Factor 09h - DIMM
  1254. Device Locator ChannelB-DIMM1
  1255. Bank Locator BANK 3
  1256. Memory Type 1ah - Specification Reserved
  1257. Type Detail 0080h - Synchronous
  1258. Speed 3000MHz
  1259. Manufacturer Kingston
  1260. Part Number KHX3000C15D4/8GX
  1261. [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0017h]
  1262. Starting Address 00000000h
  1263. Ending Address 00ffffffh
  1264. Memory Array Handle 0012h
  1265. Partition Width 02
  1266. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0018h]
  1267. Starting Address 00000000h
  1268. Ending Address 007fffffh
  1269. Memory Device Handle 0014h
  1270. Mem Array Mapped Adr Handle 0017h
  1271. Partition Row Position 01
  1272. Interleave Position 01
  1273. Interleave Data Depth 02
  1274. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0019h]
  1275. Starting Address 00800000h
  1276. Ending Address 00ffffffh
  1277. Memory Device Handle 0016h
  1278. Mem Array Mapped Adr Handle 0017h
  1279. Partition Row Position 01
  1280. Interleave Position 02
  1281. Interleave Data Depth 02
  1282.  
  1283. ========================== Dump #2: Extra #1 ===========================
  1284.  
  1285. 0: kd> !verifier
  1286. Verify Flags Level 0x00000000
  1287. STANDARD FLAGS:
  1288. [X] (0x00000000) Automatic Checks
  1289. [ ] (0x00000001) Special pool
  1290. [ ] (0x00000002) Force IRQL checking
  1291. [ ] (0x00000008) Pool tracking
  1292. [ ] (0x00000010) I/O verification
  1293. [ ] (0x00000020) Deadlock detection
  1294. [ ] (0x00000080) DMA checking
  1295. [ ] (0x00000100) Security checks
  1296. [ ] (0x00000800) Miscellaneous checks
  1297. [ ] (0x00020000) DDI compliance checking
  1298. ADDITIONAL FLAGS:
  1299. [ ] (0x00000004) Randomized low resources simulation
  1300. [ ] (0x00000200) Force pending I/O requests
  1301. [ ] (0x00000400) IRP logging
  1302. [ ] (0x00002000) Invariant MDL checking for stack
  1303. [ ] (0x00004000) Invariant MDL checking for driver
  1304. [ ] (0x00008000) Power framework delay fuzzing
  1305. [ ] (0x00010000) Port/miniport interface checking
  1306. [ ] (0x00040000) Systematic low resources simulation
  1307. [ ] (0x00080000) DDI compliance checking (additional)
  1308. [ ] (0x00200000) NDIS/WIFI verification
  1309. [ ] (0x00800000) Kernel synchronization delay fuzzing
  1310. [ ] (0x01000000) VM switch verification
  1311. [ ] (0x02000000) Code integrity checks
  1312. [X] Indicates flag is enabled
  1313. Summary of All Verifier Statistics
  1314. RaiseIrqls 0x0
  1315. AcquireSpinLocks 0x0
  1316. Synch Executions 0x0
  1317. Trims 0x0
  1318. Pool Allocations Attempted 0x0
  1319. Pool Allocations Succeeded 0x0
  1320. Pool Allocations Succeeded SpecialPool 0x0
  1321. Pool Allocations With NO TAG 0x0
  1322. Pool Allocations Failed 0x0
  1323. Current paged pool allocations 0x0 for 00000000 bytes
  1324. Peak paged pool allocations 0x0 for 00000000 bytes
  1325. Current nonpaged pool allocations 0x0 for 00000000 bytes
  1326. Peak nonpaged pool allocations 0x0 for 00000000 bytes
  1327.  
  1328. ========================== Dump #2: Extra #2 ===========================
  1329.  
  1330. 0: kd> !thread
  1331. THREAD fffff80378191400 Cid 0000.0000 Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor 0
  1332. Not impersonating
  1333. GetUlongFromAddress: unable to read from fffff8037802ca14
  1334. Owning Process fffff8037818e9c0 Image: System Process
  1335. Attached Process ffff90010566e080 Image: System
  1336. Wait Start TickCount 28645714 Ticks: 5 (0:00:00:00.078)
  1337. Context Switch Count 436218423 IdealProcessor: 0
  1338. ReadMemory error: Cannot get nt!KeMaximumIncrement value.
  1339. UserTime 00:00:00.000
  1340. KernelTime 00:00:00.000
  1341. Win32 Start Address nt!KiIdleLoop (0xfffff80377dc5e50)
  1342. Stack Init fffff8037c738b90 Current fffff8037c738b20
  1343. Base fffff8037c739000 Limit fffff8037c732000 Call 0000000000000000
  1344. Priority 0 BasePriority 0 PriorityDecrement 0 IoPriority 0 PagePriority 5
  1345. Child-SP RetAddr : Args to Child : Call Site
  1346. fffff803`7c747898 fffff803`77dd41e9 : 00000000`0000000a fffff803`7c727b68 00000000`000000ff 00000000`00000093 : nt!KeBugCheckEx
  1347. fffff803`7c7478a0 fffff803`77dd0529 : 00000000`00000000 00000000`00000000 fffff803`7c747c20 fffff803`7ca13514 : nt!KiBugCheckDispatch+0x69
  1348. fffff803`7c7479e0 fffff803`77c47d80 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`01c15855 : nt!KiPageFault+0x469 (TrapFrame @ fffff803`7c7479e0)
  1349. fffff803`7c747b70 fffff803`77b5d567 : fffff803`73592180 fffff803`7c7389d0 fffff803`7c738a50 00000000`00000000 : nt!KeClockInterruptNotify+0x350
  1350. fffff803`7c747f30 fffff803`77d37385 : 00000412`27acfa3a fffff803`77bcc100 fffff803`77bcc1b0 ffff28c4`2dabfe92 : hal!HalpTimerClockInterrupt+0xf7
  1351. fffff803`7c747f60 fffff803`77dc3e2a : fffff803`7c738a50 fffff803`77bcc100 00000000`00000810 fffff803`77bcc100 : nt!KiCallInterruptServiceRoutine+0xa5
  1352. fffff803`7c747fb0 fffff803`77dc4397 : 00000000`00000000 fffff803`73592180 fffff803`7c738b00 00000000`00000001 : nt!KiInterruptSubDispatchNoLockNoEtw+0xfa (TrapFrame @ fffff803`7c747e70)
  1353. fffff803`7c7389d0 fffff803`77dc5e9a : 00000000`00000000 fffff803`73592180 ffff9001`0f546580 00000000`00000810 : nt!KiInterruptDispatchNoLockNoEtw+0x37 (TrapFrame @ fffff803`7c7389d0)
  1354. fffff803`7c738b60 00000000`00000000 : fffff803`7c739000 fffff803`7c732000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x4a
  1355.  
  1356.  
  1357. ========================================================================
  1358. ======================= Dump #3: ANALYZE VERBOSE =======================
  1359. ======================= File: 061620-8656-01.dmp =======================
  1360. ========================================================================
  1361.  
  1362. Mini Kernel Dump File: Only registers and stack trace are available
  1363. Windows 10 Kernel Version 18362 MP (4 procs) Free x64
  1364. Kernel base = 0xfffff806`58600000 PsLoadedModuleList = 0xfffff806`58a48190
  1365. Debug session time: Tue Jun 16 06:46:59.768 2020 (UTC - 4:00)
  1366. System Uptime: 0 days 0:00:24.440
  1367.  
  1368. BugCheck A, {fffff8065c318238, ff, 7a, fffff806587c23ca}
  1369. *** WARNING: Unable to verify timestamp for win32k.sys
  1370. *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
  1371. Probably caused by : memory_corruption
  1372. Followup: memory_corruption
  1373.  
  1374. IRQL_NOT_LESS_OR_EQUAL (a)
  1375. An attempt was made to access a pageable (or completely invalid) address at an
  1376. interrupt request level (IRQL) that is too high. This is usually
  1377. caused by drivers using improper addresses.
  1378. If a kernel debugger is available get the stack backtrace.
  1379.  
  1380. Arguments:
  1381. Arg1: fffff8065c318238, memory referenced
  1382. Arg2: 00000000000000ff, IRQL
  1383. Arg3: 000000000000007a, bitfield :
  1384. bit 0 : value 0 = read operation, 1 = write operation
  1385. bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
  1386. Arg4: fffff806587c23ca, address which referenced memory
  1387.  
  1388. Debugging Details:
  1389. DUMP_CLASS: 1
  1390. DUMP_QUALIFIER: 400
  1391. DUMP_TYPE: 2
  1392. READ_ADDRESS: fffff80658b733b8: Unable to get MiVisibleState
  1393. fffff8065c318238
  1394. CURRENT_IRQL: 0
  1395. FAULTING_IP:
  1396. nt!KeBugCheckEx+2a
  1397. fffff806`587c23ca e8c17f0000 call nt!RtlCaptureContext (fffff806`587ca390)
  1398. CUSTOMER_CRASH_COUNT: 1
  1399. DEFAULT_BUCKET_ID: CODE_CORRUPTION
  1400. BUGCHECK_STR: AV
  1401.  
  1402. PROCESS_NAME: System
  1403.  
  1404. TRAP_FRAME: fffff8065c338550 -- (.trap 0xfffff8065c338550)
  1405. NOTE: The trap frame does not contain all registers.
  1406. Some register values may be zeroed or incorrect.
  1407. rax=0000000000000000 rbx=0000000000000000 rcx=0000000000000000
  1408. rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
  1409. rip=fffff8065864acd6 rsp=fffff8065c3386e0 rbp=ffffe20bcffa6000
  1410. r8=ffffe20bcf3bfd10 r9=0000000000000000 r10=fffff8065855d870
  1411. r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
  1412. r14=0000000000000000 r15=0000000000000000
  1413. iopl=0 nv up di pl zr na po nc
  1414. nt!PpmIdleExecuteTransition+0x7c6:
  1415. fffff806`5864acd6 e8952bf1ff call hal!KeQueryPerformanceCounter (fffff806`5855d870)
  1416. Resetting default scope
  1417. LAST_CONTROL_TRANSFER: from fffff806587d41e9 to fffff806587c23a0
  1418. STACK_TEXT:
  1419. fffff806`5c337f68 fffff806`587d41e9 : 00000000`0000000a fffff806`5c318238 00000000`000000ff 00000000`0000007a : nt!KeBugCheckEx
  1420. fffff806`5c337f70 fffff806`587d0529 : ffff1615`bbddf4e4 00000000`00000000 00000000`00000002 00000000`00000000 : nt!KiBugCheckDispatch+0x69
  1421. fffff806`5c3380b0 fffff806`587c23ca : ffffe20b`cfcfde61 fffff806`5badaa51 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x469
  1422. fffff806`5c338240 fffff806`587d41e9 : 00000000`0000000a fffff806`5c0b8548 00000000`000000ff 00000000`000000ae : nt!KeBugCheckEx+0x2a
  1423. fffff806`5c338280 fffff806`587d0529 : 00000000`00000000 ffff9000`a58b7020 ffffe20b`cf5024c8 ffffe20b`d3713220 : nt!KiBugCheckDispatch+0x69
  1424. fffff806`5c3383c0 fffff806`587d0524 : 00000000`00000000 ffff9000`a58b7020 ffffffff`ffffffff ffffe20b`d3609220 : nt!KiPageFault+0x469
  1425. fffff806`5c338550 fffff806`5864acd6 : 00000000`00000000 00000000`0000006f ffffe20b`cffa6000 00000000`000009a9 : nt!KiPageFault+0x464
  1426. fffff806`5c3386e0 fffff806`5864a36e : 00000000`00000003 00000000`00000002 fffff806`5c338b00 00000000`00000000 : nt!PpmIdleExecuteTransition+0x7c6
  1427. fffff806`5c338a00 fffff806`587c5e94 : 00000000`00000000 fffff806`53290180 ffffe20b`cdea6080 00000000`0000041c : nt!PoIdle+0x36e
  1428. fffff806`5c338b60 00000000`00000000 : fffff806`5c339000 fffff806`5c332000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x44
  1429. STACK_COMMAND: kb
  1430. CHKIMG_EXTENSION: !chkimg -lo 50 -d !hal
  1431. fffff8065855d8ec-fffff8065855d8ed 2 bytes - hal!KeQueryPerformanceCounter+7c
  1432. [ 48 ff:4c 8b ]
  1433. fffff8065855d8f3-fffff8065855d8f6 4 bytes - hal!KeQueryPerformanceCounter+83 (+0x07)
  1434. [ 0f 1f 44 00:e8 58 28 19 ]
  1435. fffff8065858e4df-fffff8065858e4e0 2 bytes - hal!HalpInterruptPowerComponentIdleCallback+1f (+0x30bec)
  1436. [ 48 ff:4c 8b ]
  1437. fffff8065858e4e6-fffff8065858e4e9 4 bytes - hal!HalpInterruptPowerComponentIdleCallback+26 (+0x07)
  1438. [ 0f 1f 44 00:e8 45 ea 18 ]
  1439. fffff8065858e5f4-fffff8065858e5f5 2 bytes - hal!HalpInterruptDeferredRecoveryService+4 (+0x10e)
  1440. [ 48 ff:4c 8b ]
  1441. fffff8065858e5fb-fffff8065858e5fe 4 bytes - hal!HalpInterruptDeferredRecoveryService+b (+0x07)
  1442. [ 0f 1f 44 00:e8 c0 3e 3b ]
  1443. 18 errors : !hal (fffff8065855d8ec-fffff8065858e5fe)
  1444. MODULE_NAME: memory_corruption
  1445.  
  1446. IMAGE_NAME: memory_corruption
  1447.  
  1448. FOLLOWUP_NAME: memory_corruption
  1449. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  1450. MEMORY_CORRUPTOR: LARGE
  1451. FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
  1452. BUCKET_ID: MEMORY_CORRUPTION_LARGE
  1453. PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
  1454. TARGET_TIME: 2020-06-16T10:46:59.000Z
  1455. SUITE_MASK: 784
  1456. PRODUCT_TYPE: 1
  1457. USER_LCID: 0
  1458. FAILURE_ID_HASH_STRING: km:memory_corruption_large
  1459. FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
  1460. Followup: memory_corruption
  1461.  
  1462. ====================== Dump #3: 3RD PARTY DRIVERS ======================
  1463.  
  1464. May 10 2011 - AsrAppCharger.sys - ASRock App Charger driver
  1465. Jun 03 2015 - iaStorA.sys - Intel SATA Storage Device RAID Controller
  1466. Jun 23 2015 - RTKVHD64.sys - Realtek Audio System driver https://www.realtek.com/en/
  1467. Apr 11 2018 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
  1468. Jun 11 2018 - e1i65x64.sys - Intel(R) Gigabit Adapter driver
  1469. Feb 19 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
  1470. May 15 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
  1471. May 20 2020 - FACEIT.sys - FACEIT Client https://www.faceit.com/
  1472.  
  1473. ================== Dump #3: 3RD PARTY DRIVERS (FULL) ===================
  1474.  
  1475. Image path: \SystemRoot\system32\DRIVERS\AsrAppCharger.sys
  1476. Image name: AsrAppCharger.sys
  1477. Search : https://www.google.com/search?q=AsrAppCharger.sys
  1478. ADA Info : ASRock App Charger driver
  1479. Timestamp : Tue May 10 2011
  1480.  
  1481. Image path: \SystemRoot\System32\drivers\iaStorA.sys
  1482. Image name: iaStorA.sys
  1483. Search : https://www.google.com/search?q=iaStorA.sys
  1484. ADA Info : Intel SATA Storage Device RAID Controller
  1485. Timestamp : Wed Jun 3 2015
  1486.  
  1487. Image path: \SystemRoot\system32\drivers\RTKVHD64.sys
  1488. Image name: RTKVHD64.sys
  1489. Search : https://www.google.com/search?q=RTKVHD64.sys
  1490. ADA Info : Realtek Audio System driver https://www.realtek.com/en/
  1491. Timestamp : Tue Jun 23 2015
  1492.  
  1493. Image path: \SystemRoot\System32\drivers\TeeDriverW8x64.sys
  1494. Image name: TeeDriverW8x64.sys
  1495. Search : https://www.google.com/search?q=TeeDriverW8x64.sys
  1496. ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
  1497. Timestamp : Wed Apr 11 2018
  1498.  
  1499. Mapped memory image file: C:\ProgramData\dbg\sym\e1i65x64.sys\5B1EB8E28e000\e1i65x64.sys
  1500. Image path: \SystemRoot\System32\drivers\e1i65x64.sys
  1501. Image name: e1i65x64.sys
  1502. Search : https://www.google.com/search?q=e1i65x64.sys
  1503. ADA Info : Intel(R) Gigabit Adapter driver
  1504. Timestamp : Mon Jun 11 2018
  1505. File version: 12.17.10.8
  1506. Product version: 10.0.10011.16384
  1507. File flags: 8 (Mask 3F) Private
  1508. File OS: 40004 NT Win32
  1509. File type: 3.6 Driver
  1510. File date: 00000000.00000000
  1511. CompanyName: Intel Corporation
  1512. ProductName: Intel(R) Gigabit Adapter
  1513. InternalName: e1i65x64.sys
  1514. OriginalFilename: e1i65x64.sys
  1515. ProductVersion: 12.17.10.8
  1516. FileVersion: 12.17.10.8
  1517. FileDescription: Intel(R) Gigabit Adapter NDIS 6.x driver
  1518. LegalCopyright: Copyright(C) 2013, Intel Corporation. All rights reserved.
  1519.  
  1520. Image path: \SystemRoot\system32\drivers\nvhda64v.sys
  1521. Image name: nvhda64v.sys
  1522. Search : https://www.google.com/search?q=nvhda64v.sys
  1523. ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
  1524. Timestamp : Wed Feb 19 2020
  1525.  
  1526. Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d5216eae94436d77\nvlddmkm.sys
  1527. Image name: nvlddmkm.sys
  1528. Search : https://www.google.com/search?q=nvlddmkm.sys
  1529. ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
  1530. Timestamp : Fri May 15 2020
  1531.  
  1532. Image path: \SystemRoot\System32\Drivers\FACEIT.sys
  1533. Image name: FACEIT.sys
  1534. Search : https://www.google.com/search?q=FACEIT.sys
  1535. ADA Info : FACEIT Client https://www.faceit.com/
  1536. Timestamp : Wed May 20 2020
  1537.  
  1538. ====================== Dump #3: MICROSOFT DRIVERS ======================
  1539.  
  1540. ACPI.sys ACPI Driver for NT (Microsoft)
  1541. acpiex.sys ACPIEx Driver (Microsoft)
  1542. acpipagr.sys ACPI Processor Aggregator Device driver (Microsoft)
  1543. afd.sys Ancillary Function Driver for WinSock (Microsoft)
  1544. afunix.sys AF_UNIX Socket Provider driver (Microsoft)
  1545. AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
  1546. ahcache.sys Application Compatibility Cache (Microsoft)
  1547. bam.sys BAM Kernal driver (Microsoft)
  1548. BasicDisplay.sys Basic Display driver (Microsoft)
  1549. BasicRender.sys Basic Render driver (Microsoft)
  1550. Beep.SYS BEEP driver (Microsoft)
  1551. BOOTVID.dll VGA Boot Driver (Microsoft)
  1552. bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
  1553. cdd.dll Canonical Display Driver (Microsoft)
  1554. cdrom.sys SCSI CD-ROM Driver (Microsoft)
  1555. CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
  1556. CI.dll Code Integrity Module (Microsoft)
  1557. CLASSPNP.SYS SCSI Class System Dll (Microsoft)
  1558. cldflt.sys Cloud Files Mini Filter driver (Microsoft)
  1559. CLFS.SYS Common Log File System Driver (Microsoft)
  1560. clipsp.sys CLIP Service (Microsoft)
  1561. cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
  1562. cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
  1563. CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
  1564. crashdmp.sys Crash Dump driver (Microsoft)
  1565. dfsc.sys DFS Namespace Client Driver (Microsoft)
  1566. disk.sys PnP Disk Driver (Microsoft)
  1567. drmk.sys Digital Rights Management (DRM) driver (Microsoft)
  1568. dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  1569. dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  1570. dump_iaStorA.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  1571. dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
  1572. dxgmms2.sys DirectX Graphics MMS
  1573. EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
  1574. filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
  1575. fileinfo.sys FileInfo Filter Driver (Microsoft)
  1576. FLTMGR.SYS Filesystem Filter Manager (Microsoft)
  1577. Fs_Rec.sys File System Recognizer Driver (Microsoft)
  1578. fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
  1579. fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
  1580. gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
  1581. hal.dll Hardware Abstraction Layer DLL (Microsoft)
  1582. HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
  1583. HIDCLASS.SYS Hid Class Library (Microsoft)
  1584. HIDPARSE.SYS Hid Parsing Library (Microsoft)
  1585. hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
  1586. HTTP.sys HTTP Protocol Stack (Microsoft)
  1587. hwpolicy.sys Hardware Policy Driver
  1588. intelpep.sys Intel Power Engine Plugin (Microsoft)
  1589. intelppm.sys Processor Device Driver (Microsoft)
  1590. iorate.sys I/O rate control Filter (Microsoft)
  1591. kbdclass.sys Keyboard Class Driver (Microsoft)
  1592. kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
  1593. kd.dll Local Kernal Debugger (Microsoft)
  1594. kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
  1595. ks.sys Kernal CSA Library (Microsoft)
  1596. ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
  1597. ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
  1598. ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
  1599. lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
  1600. luafv.sys LUA File Virtualization Filter Driver (Microsoft)
  1601. mcupdate_GenuineIntel.dll Intel Microcode Update Library (Microsoft)
  1602. mmcss.sys MMCSS Driver (Microsoft)
  1603. monitor.sys Monitor Driver (Microsoft)
  1604. mouclass.sys Mouse Class Driver (Microsoft)
  1605. mouhid.sys HID Mouse Filter Driver (Microsoft)
  1606. mountmgr.sys Mount Point Manager (Microsoft)
  1607. mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
  1608. mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
  1609. mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
  1610. Msfs.SYS Mailslot driver (Microsoft)
  1611. msisadrv.sys ISA Driver (Microsoft)
  1612. mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
  1613. msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
  1614. mssmbios.sys System Management BIOS driver (Microsoft)
  1615. mup.sys Multiple UNC Provider driver (Microsoft)
  1616. ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
  1617. ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
  1618. NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
  1619. ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
  1620. NDProxy.sys NDIS Proxy driver (Microsoft)
  1621. Ndu.sys Network Data Usage Monitoring driver (Microsoft)
  1622. netbios.sys NetBIOS Interface driver (Microsoft)
  1623. netbt.sys MBT Transport driver (Microsoft)
  1624. NETIO.SYS Network I/O Subsystem (Microsoft)
  1625. Npfs.SYS NPFS driver (Microsoft)
  1626. npsvctrig.sys Named pipe service triggers (Microsoft)
  1627. nsiproxy.sys NSI Proxy driver (Microsoft)
  1628. Ntfs.sys NT File System Driver (Microsoft)
  1629. ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
  1630. ntosext.sys NTOS Extension Host driver (Microsoft)
  1631. Null.SYS NULL Driver (Microsoft)
  1632. pacer.sys QoS Packet Scheduler (Microsoft)
  1633. partmgr.sys Partition driver (Microsoft)
  1634. pci.sys NT Plug and Play PCI Enumerator (Microsoft)
  1635. pcw.sys Performance Counter Driver (Microsoft)
  1636. pdc.sys Power Dependency Coordinator Driver (Microsoft)
  1637. peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
  1638. portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
  1639. PSHED.dll Platform Specific Hardware Error driver (Microsoft)
  1640. rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
  1641. raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
  1642. raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
  1643. rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
  1644. rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
  1645. rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
  1646. rdyboost.sys ReadyBoost Driver (Microsoft)
  1647. rspndr.sys Link-Layer Topology Responder driver (Microsoft)
  1648. serenum.sys Serial Port Enumerator (Microsoft)
  1649. serial.sys Serial Device Driver
  1650. SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
  1651. SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
  1652. spaceport.sys Storage Spaces driver (Microsoft)
  1653. srv2.sys Smb 2.0 Server driver (Microsoft)
  1654. srvnet.sys Server Network driver (Microsoft)
  1655. storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
  1656. storqosflt.sys Storage QoS Filter driver (Microsoft)
  1657. swenum.sys Plug and Play Software Device Enumerator (Microsoft)
  1658. tbs.sys Export driver for kernel mode TPM API (Microsoft)
  1659. tcpip.sys TCP/IP Protocol driver (Microsoft)
  1660. tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
  1661. TDI.SYS TDI Wrapper driver (Microsoft)
  1662. tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
  1663. tm.sys Kernel Transaction Manager driver (Microsoft)
  1664. ucx01000.sys USB Controller Extension (Microsoft)
  1665. umbus.sys User-Mode Bus Enumerator (Microsoft)
  1666. usbaudio2.sys Microsoft USB Audio Class 2.0 Driver
  1667. usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
  1668. USBD.SYS Universal Serial Bus Driver (Microsoft)
  1669. UsbHub3.sys USB3 HUB driver (Microsoft)
  1670. USBXHCI.SYS USB XHCI driver (Microsoft)
  1671. vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
  1672. Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
  1673. volmgr.sys Volume Manager Driver (Microsoft)
  1674. volmgrx.sys Volume Manager Extension Driver (Microsoft)
  1675. volsnap.sys Volume Shadow Copy driver (Microsoft)
  1676. volume.sys Volume driver (Microsoft)
  1677. vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
  1678. wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
  1679. watchdog.sys Watchdog driver (Microsoft)
  1680. wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
  1681. WdBoot.sys Microsoft Antimalware Boot driver
  1682. Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
  1683. WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
  1684. WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
  1685. WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
  1686. werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
  1687. wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
  1688. win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
  1689. win32kbase.sys Base Win32k Kernel Driver (Microsoft)
  1690. win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
  1691. WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
  1692. WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
  1693. winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
  1694. winquic.sys QUIC Transport Protocol driver (Microsoft)
  1695. wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
  1696. WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
  1697. Wof.sys Windows Overlay Filter (Microsoft)
  1698. WppRecorder.sys WPP Trace Recorder (Microsoft)
  1699. WSDPrint.sys Web Services Print Device driver (Microsoft)
  1700.  
  1701. ====================== Dump #3: UNLOADED MODULES =======================
  1702.  
  1703. fffff806`542b0000 fffff806`542be000 WSDPrint.sys
  1704. fffff806`5c870000 fffff806`5c87f000 dump_storpor
  1705. fffff806`5d000000 fffff806`5d573000 dump_iaStorA
  1706. fffff806`5d5a0000 fffff806`5d5be000 dump_dumpfve
  1707. fffff806`5dd70000 fffff806`5dd8e000 dam.sys
  1708.  
  1709. ====================== Dump #3: BIOS INFORMATION =======================
  1710.  
  1711. [SMBIOS Data Tables v2.8]
  1712. [DMI Version - 0]
  1713. [2.0 Calling Convention - No]
  1714. [Table Size - 1735 bytes]
  1715. [BIOS Information (Type 0) - Length 24 - Handle 0000h]
  1716. Vendor American Megatrends Inc.
  1717. BIOS Version P7.50
  1718. BIOS Starting Address Segment f000
  1719. BIOS Release Date 01/23/2018
  1720. BIOS ROM Size e00000
  1721. BIOS Characteristics
  1722. 07: - PCI Supported
  1723. 11: - Upgradeable FLASH BIOS
  1724. 12: - BIOS Shadowing Supported
  1725. 15: - CD-Boot Supported
  1726. 16: - Selectable Boot Supported
  1727. 17: - BIOS ROM Socketed
  1728. 19: - EDD Supported
  1729. 23: - 1.2MB Floppy Supported
  1730. 24: - 720KB Floppy Supported
  1731. 25: - 2.88MB Floppy Supported
  1732. 26: - Print Screen Device Supported
  1733. 27: - Keyboard Services Supported
  1734. 28: - Serial Services Supported
  1735. 29: - Printer Services Supported
  1736. 32: - BIOS Vendor Reserved
  1737. BIOS Characteristic Extensions
  1738. 00: - ACPI Supported
  1739. 01: - USB Legacy Supported
  1740. 08: - BIOS Boot Specification Supported
  1741. 10: - Specification Reserved
  1742. 11: - Specification Reserved
  1743. BIOS Major Revision 5
  1744. BIOS Minor Revision 11
  1745. EC Firmware Major Revision 255
  1746. EC Firmware Minor Revision 255
  1747. [System Information (Type 1) - Length 27 - Handle 0001h]
  1748. UUID 00000000-0000-0000-0000-000000000000
  1749. Wakeup Type Power Switch
  1750. [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
  1751. Manufacturer ASRock
  1752. Product Z170 Pro4S
  1753. Version
  1754. Feature Flags 09h
  1755. -449726752: - -449726704: - ÷7!ü
  1756. Location
  1757. Chassis Handle 0003h
  1758. Board Type 0ah - Processor/Memory Module
  1759. Number of Child Handles 0
  1760. [System Enclosure (Type 3) - Length 25 - Handle 0003h]
  1761. Chassis Type Desktop
  1762. Bootup State Safe
  1763. Power Supply State Safe
  1764. Thermal State Safe
  1765. Security Status None
  1766. OEM Defined 0
  1767. Height 0U
  1768. Number of Power Cords 1
  1769. Number of Contained Elements 1
  1770. Contained Element Size 3
  1771. [OEM Strings (Type 11) - Length 5 - Handle 000ah]
  1772. Number of Strings 1
  1773. [Cache Information (Type 7) - Length 19 - Handle 000dh]
  1774. Socket Designation L1 Cache
  1775. Cache Configuration 0180h - WB Enabled Int NonSocketed L1
  1776. Maximum Cache Size 0080h - 128K
  1777. Installed Size 0080h - 128K
  1778. Supported SRAM Type 0020h - Synchronous
  1779. Current SRAM Type 0020h - Synchronous
  1780. Cache Speed 0ns
  1781. Error Correction Type ParitySingle-Bit ECC
  1782. System Cache Type Data
  1783. Associativity 8-way Set-Associative
  1784. [Cache Information (Type 7) - Length 19 - Handle 000eh]
  1785. Socket Designation L1 Cache
  1786. Cache Configuration 0180h - WB Enabled Int NonSocketed L1
  1787. Maximum Cache Size 0080h - 128K
  1788. Installed Size 0080h - 128K
  1789. Supported SRAM Type 0020h - Synchronous
  1790. Current SRAM Type 0020h - Synchronous
  1791. Cache Speed 0ns
  1792. Error Correction Type ParitySingle-Bit ECC
  1793. System Cache Type Instruction
  1794. Associativity 8-way Set-Associative
  1795. [Cache Information (Type 7) - Length 19 - Handle 000fh]
  1796. Socket Designation L2 Cache
  1797. Cache Configuration 0181h - WB Enabled Int NonSocketed L2
  1798. Maximum Cache Size 0400h - 1024K
  1799. Installed Size 0400h - 1024K
  1800. Supported SRAM Type 0020h - Synchronous
  1801. Current SRAM Type 0020h - Synchronous
  1802. Cache Speed 0ns
  1803. Error Correction Type Multi-Bit ECC
  1804. System Cache Type Unified
  1805. Associativity 4-way Set-Associative
  1806. [Cache Information (Type 7) - Length 19 - Handle 0010h]
  1807. Socket Designation L3 Cache
  1808. Cache Configuration 0182h - WB Enabled Int NonSocketed L3
  1809. Maximum Cache Size 1800h - 6144K
  1810. Installed Size 1800h - 6144K
  1811. Supported SRAM Type 0020h - Synchronous
  1812. Current SRAM Type 0020h - Synchronous
  1813. Cache Speed 0ns
  1814. Error Correction Type Specification Reserved
  1815. System Cache Type Unified
  1816. Associativity Specification Reserved
  1817. [Processor Information (Type 4) - Length 48 - Handle 0011h]
  1818. Socket Designation CPUSocket
  1819. Processor Type Central Processor
  1820. Processor Family cdh - Specification Reserved
  1821. Processor Manufacturer Intel(R) Corporation
  1822. Processor ID e3060500fffbebbf
  1823. Processor Version Intel(R) Core(TM) i5-6600K CPU @ 3.50GHz
  1824. Processor Voltage 8bh - 1.1V
  1825. External Clock 100MHz
  1826. Max Speed 5000MHz
  1827. Current Speed 3500MHz
  1828. Status Enabled Populated
  1829. Processor Upgrade Other
  1830. L1 Cache Handle 000eh
  1831. L2 Cache Handle 000fh
  1832. L3 Cache Handle 0010h
  1833. [Physical Memory Array (Type 16) - Length 23 - Handle 0012h]
  1834. Location 03h - SystemBoard/Motherboard
  1835. Use 03h - System Memory
  1836. Memory Error Correction 03h - None
  1837. Maximum Capacity 67108864KB
  1838. Number of Memory Devices 4
  1839. [Memory Device (Type 17) - Length 40 - Handle 0013h]
  1840. Physical Memory Array Handle 0012h
  1841. Total Width 0 bits
  1842. Data Width 0 bits
  1843. Form Factor 09h - DIMM
  1844. Device Locator ChannelA-DIMM0
  1845. Bank Locator BANK 0
  1846. Memory Type 02h - Unknown
  1847. Type Detail 0000h -
  1848. Speed 0MHz
  1849. [Memory Device (Type 17) - Length 40 - Handle 0014h]
  1850. Physical Memory Array Handle 0012h
  1851. Total Width 64 bits
  1852. Data Width 64 bits
  1853. Size 8192MB
  1854. Form Factor 09h - DIMM
  1855. Device Locator ChannelA-DIMM1
  1856. Bank Locator BANK 1
  1857. Memory Type 1ah - Specification Reserved
  1858. Type Detail 0080h - Synchronous
  1859. Speed 3000MHz
  1860. Manufacturer Kingston
  1861. Part Number KHX3000C15D4/8GX
  1862. [Memory Device (Type 17) - Length 40 - Handle 0015h]
  1863. Physical Memory Array Handle 0012h
  1864. Total Width 0 bits
  1865. Data Width 0 bits
  1866. Form Factor 09h - DIMM
  1867. Device Locator ChannelB-DIMM0
  1868. Bank Locator BANK 2
  1869. Memory Type 02h - Unknown
  1870. Type Detail 0000h -
  1871. Speed 0MHz
  1872. [Memory Device (Type 17) - Length 40 - Handle 0016h]
  1873. Physical Memory Array Handle 0012h
  1874. Total Width 64 bits
  1875. Data Width 64 bits
  1876. Size 8192MB
  1877. Form Factor 09h - DIMM
  1878. Device Locator ChannelB-DIMM1
  1879. Bank Locator BANK 3
  1880. Memory Type 1ah - Specification Reserved
  1881. Type Detail 0080h - Synchronous
  1882. Speed 3000MHz
  1883. Manufacturer Kingston
  1884. Part Number KHX3000C15D4/8GX
  1885. [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0017h]
  1886. Starting Address 00000000h
  1887. Ending Address 00ffffffh
  1888. Memory Array Handle 0012h
  1889. Partition Width 02
  1890. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0018h]
  1891. Starting Address 00000000h
  1892. Ending Address 007fffffh
  1893. Memory Device Handle 0014h
  1894. Mem Array Mapped Adr Handle 0017h
  1895. Partition Row Position 01
  1896. Interleave Position 01
  1897. Interleave Data Depth 02
  1898. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0019h]
  1899. Starting Address 00800000h
  1900. Ending Address 00ffffffh
  1901. Memory Device Handle 0016h
  1902. Mem Array Mapped Adr Handle 0017h
  1903. Partition Row Position 01
  1904. Interleave Position 02
  1905. Interleave Data Depth 02
  1906.  
  1907. ========================== Dump #3: Extra #1 ===========================
  1908.  
  1909. 0: kd> !verifier
  1910. Verify Flags Level 0x00000000
  1911. STANDARD FLAGS:
  1912. [X] (0x00000000) Automatic Checks
  1913. [ ] (0x00000001) Special pool
  1914. [ ] (0x00000002) Force IRQL checking
  1915. [ ] (0x00000008) Pool tracking
  1916. [ ] (0x00000010) I/O verification
  1917. [ ] (0x00000020) Deadlock detection
  1918. [ ] (0x00000080) DMA checking
  1919. [ ] (0x00000100) Security checks
  1920. [ ] (0x00000800) Miscellaneous checks
  1921. [ ] (0x00020000) DDI compliance checking
  1922. ADDITIONAL FLAGS:
  1923. [ ] (0x00000004) Randomized low resources simulation
  1924. [ ] (0x00000200) Force pending I/O requests
  1925. [ ] (0x00000400) IRP logging
  1926. [ ] (0x00002000) Invariant MDL checking for stack
  1927. [ ] (0x00004000) Invariant MDL checking for driver
  1928. [ ] (0x00008000) Power framework delay fuzzing
  1929. [ ] (0x00010000) Port/miniport interface checking
  1930. [ ] (0x00040000) Systematic low resources simulation
  1931. [ ] (0x00080000) DDI compliance checking (additional)
  1932. [ ] (0x00200000) NDIS/WIFI verification
  1933. [ ] (0x00800000) Kernel synchronization delay fuzzing
  1934. [ ] (0x01000000) VM switch verification
  1935. [ ] (0x02000000) Code integrity checks
  1936. [X] Indicates flag is enabled
  1937. Summary of All Verifier Statistics
  1938. RaiseIrqls 0x0
  1939. AcquireSpinLocks 0x0
  1940. Synch Executions 0x0
  1941. Trims 0x0
  1942. Pool Allocations Attempted 0x0
  1943. Pool Allocations Succeeded 0x0
  1944. Pool Allocations Succeeded SpecialPool 0x0
  1945. Pool Allocations With NO TAG 0x0
  1946. Pool Allocations Failed 0x0
  1947. Current paged pool allocations 0x0 for 00000000 bytes
  1948. Peak paged pool allocations 0x0 for 00000000 bytes
  1949. Current nonpaged pool allocations 0x0 for 00000000 bytes
  1950. Peak nonpaged pool allocations 0x0 for 00000000 bytes
  1951.  
  1952. ========================== Dump #3: Extra #2 ===========================
  1953.  
  1954. 0: kd> !thread
  1955. THREAD fffff80658b91400 Cid 0000.0000 Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor 0
  1956. Not impersonating
  1957. GetUlongFromAddress: unable to read from fffff80658a2ca14
  1958. Owning Process fffff80658b8e9c0 Image: System Process
  1959. Attached Process ffffe20bcda9c080 Image: System
  1960. fffff78000000000: Unable to get shared data
  1961. Wait Start TickCount 710
  1962. Context Switch Count 21733 IdealProcessor: 0
  1963. ReadMemory error: Cannot get nt!KeMaximumIncrement value.
  1964. UserTime 00:00:00.000
  1965. KernelTime 00:00:00.000
  1966. Win32 Start Address nt!KiIdleLoop (0xfffff806587c5e50)
  1967. Stack Init fffff8065c338b90 Current fffff8065c338b20
  1968. Base fffff8065c339000 Limit fffff8065c332000 Call 0000000000000000
  1969. Priority 0 BasePriority 0 PriorityDecrement 0 IoPriority 0 PagePriority 5
  1970. Child-SP RetAddr : Args to Child : Call Site
  1971. fffff806`5c337f68 fffff806`587d41e9 : 00000000`0000000a fffff806`5c318238 00000000`000000ff 00000000`0000007a : nt!KeBugCheckEx
  1972. fffff806`5c337f70 fffff806`587d0529 : ffff1615`bbddf4e4 00000000`00000000 00000000`00000002 00000000`00000000 : nt!KiBugCheckDispatch+0x69
  1973. fffff806`5c3380b0 fffff806`587c23ca : ffffe20b`cfcfde61 fffff806`5badaa51 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x469 (TrapFrame @ fffff806`5c3380b0)
  1974. fffff806`5c338240 fffff806`587d41e9 : 00000000`0000000a fffff806`5c0b8548 00000000`000000ff 00000000`000000ae : nt!KeBugCheckEx+0x2a
  1975. fffff806`5c338280 fffff806`587d0529 : 00000000`00000000 ffff9000`a58b7020 ffffe20b`cf5024c8 ffffe20b`d3713220 : nt!KiBugCheckDispatch+0x69
  1976. fffff806`5c3383c0 fffff806`587d0524 : 00000000`00000000 ffff9000`a58b7020 ffffffff`ffffffff ffffe20b`d3609220 : nt!KiPageFault+0x469 (TrapFrame @ fffff806`5c3383c0)
  1977. fffff806`5c338550 fffff806`5864acd6 : 00000000`00000000 00000000`0000006f ffffe20b`cffa6000 00000000`000009a9 : nt!KiPageFault+0x464 (TrapFrame @ fffff806`5c338550)
  1978. fffff806`5c3386e0 fffff806`5864a36e : 00000000`00000003 00000000`00000002 fffff806`5c338b00 00000000`00000000 : nt!PpmIdleExecuteTransition+0x7c6
  1979. fffff806`5c338a00 fffff806`587c5e94 : 00000000`00000000 fffff806`53290180 ffffe20b`cdea6080 00000000`0000041c : nt!PoIdle+0x36e
  1980. fffff806`5c338b60 00000000`00000000 : fffff806`5c339000 fffff806`5c332000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x44
  1981.  
  1982.  
  1983. ========================================================================
  1984. ======================= Dump #4: ANALYZE VERBOSE =======================
  1985. ====================== File: 061620-11218-01.dmp =======================
  1986. ========================================================================
  1987.  
  1988. Mini Kernel Dump File: Only registers and stack trace are available
  1989. Windows 10 Kernel Version 18362 MP (4 procs) Free x64
  1990. Kernel base = 0xfffff800`7e000000 PsLoadedModuleList = 0xfffff800`7e448190
  1991. Debug session time: Tue Jun 16 06:45:59.742 2020 (UTC - 4:00)
  1992. System Uptime: 4 days 10:42:11.752
  1993.  
  1994. BugCheck A, {fffff80085298808, ff, f5, fffff8007e04b27c}
  1995. *** WARNING: Unable to verify timestamp for win32k.sys
  1996. *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
  1997. Probably caused by : memory_corruption
  1998. Followup: memory_corruption
  1999.  
  2000. IRQL_NOT_LESS_OR_EQUAL (a)
  2001. An attempt was made to access a pageable (or completely invalid) address at an
  2002. interrupt request level (IRQL) that is too high. This is usually
  2003. caused by drivers using improper addresses.
  2004. If a kernel debugger is available get the stack backtrace.
  2005.  
  2006. Arguments:
  2007. Arg1: fffff80085298808, memory referenced
  2008. Arg2: 00000000000000ff, IRQL
  2009. Arg3: 00000000000000f5, bitfield :
  2010. bit 0 : value 0 = read operation, 1 = write operation
  2011. bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
  2012. Arg4: fffff8007e04b27c, address which referenced memory
  2013.  
  2014. Debugging Details:
  2015. DUMP_CLASS: 1
  2016. DUMP_QUALIFIER: 400
  2017. DUMP_TYPE: 2
  2018. WRITE_ADDRESS: fffff8007e5733b8: Unable to get MiVisibleState
  2019. fffff80085298808
  2020. CURRENT_IRQL: 0
  2021. FAULTING_IP:
  2022. nt!PpmIdlePrepare+ec
  2023. fffff800`7e04b27c e8ef25f1ff call hal!KeQueryPerformanceCounter (fffff800`7df5d870)
  2024. CUSTOMER_CRASH_COUNT: 1
  2025. DEFAULT_BUCKET_ID: CODE_CORRUPTION
  2026. BUGCHECK_STR: AV
  2027.  
  2028. PROCESS_NAME: System
  2029.  
  2030. TRAP_FRAME: fffff80085338680 -- (.trap 0xfffff80085338680)
  2031. NOTE: The trap frame does not contain all registers.
  2032. Some register values may be zeroed or incorrect.
  2033. rax=fffff78000000340 rbx=0000000000000000 rcx=0000000000000000
  2034. rdx=0000000000000001 rsi=0000000000000000 rdi=0000000000000000
  2035. rip=fffff8007e04b27c rsp=fffff80085338810 rbp=fffff80085338910
  2036. r8=fffff80085338a50 r9=fffff80085338a60 r10=fffff8007df5d870
  2037. r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
  2038. r14=0000000000000000 r15=0000000000000000
  2039. iopl=0 nv up di pl zr na po nc
  2040. nt!PpmIdlePrepare+0xec:
  2041. fffff800`7e04b27c e8ef25f1ff call hal!KeQueryPerformanceCounter (fffff800`7df5d870)
  2042. Resetting default scope
  2043. LAST_CONTROL_TRANSFER: from fffff8007e1d41e9 to fffff8007e1c23a0
  2044. STACK_TEXT:
  2045. fffff800`85338538 fffff800`7e1d41e9 : 00000000`0000000a fffff800`85298808 00000000`000000ff 00000000`000000f5 : nt!KeBugCheckEx
  2046. fffff800`85338540 fffff800`7e1d0529 : 00000000`00000000 00000000`00000000 00000000`017720f0 00000000`00000000 : nt!KiBugCheckDispatch+0x69
  2047. fffff800`85338680 fffff800`7e04b27c : 0000037e`605deadc 00000000`00000000 00000000`00000000 fffff800`7c2d3180 : nt!KiPageFault+0x469
  2048. fffff800`85338810 fffff800`7e04a1e6 : 00000000`00000003 00000000`00000002 ffffdd8c`1df9b0f0 00000000`00000008 : nt!PpmIdlePrepare+0xec
  2049. fffff800`85338a00 fffff800`7e1c5e94 : 00000000`00000000 fffff800`7c2d3180 ffffdd8c`2e26d0c0 00000000`00000378 : nt!PoIdle+0x1e6
  2050. fffff800`85338b60 00000000`00000000 : fffff800`85339000 fffff800`85332000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x44
  2051. STACK_COMMAND: kb
  2052. CHKIMG_EXTENSION: !chkimg -lo 50 -d !hal
  2053. fffff8007df5d8ec-fffff8007df5d8ed 2 bytes - hal!KeQueryPerformanceCounter+7c
  2054. [ 48 ff:4c 8b ]
  2055. fffff8007df5d8f3-fffff8007df5d8f6 4 bytes - hal!KeQueryPerformanceCounter+83 (+0x07)
  2056. [ 0f 1f 44 00:e8 58 28 19 ]
  2057. fffff8007df5f457-fffff8007df5f458 2 bytes - hal!HalPutScatterGatherList+67 (+0x1b64)
  2058. [ 48 ff:4c 8b ]
  2059. fffff8007df5f45e-fffff8007df5f461 4 bytes - hal!HalPutScatterGatherList+6e (+0x07)
  2060. [ 0f 1f 44 00:e8 3d fc 40 ]
  2061. 12 errors : !hal (fffff8007df5d8ec-fffff8007df5f461)
  2062. MODULE_NAME: memory_corruption
  2063.  
  2064. IMAGE_NAME: memory_corruption
  2065.  
  2066. FOLLOWUP_NAME: memory_corruption
  2067. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  2068. MEMORY_CORRUPTOR: LARGE
  2069. FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
  2070. BUCKET_ID: MEMORY_CORRUPTION_LARGE
  2071. PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
  2072. TARGET_TIME: 2020-06-16T10:45:59.000Z
  2073. SUITE_MASK: 784
  2074. PRODUCT_TYPE: 1
  2075. USER_LCID: 0
  2076. FAILURE_ID_HASH_STRING: km:memory_corruption_large
  2077. FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
  2078. Followup: memory_corruption
  2079.  
  2080. ====================== Dump #4: 3RD PARTY DRIVERS ======================
  2081.  
  2082. May 10 2011 - AsrAppCharger.sys - ASRock App Charger driver
  2083. Jun 03 2015 - iaStorA.sys - Intel SATA Storage Device RAID Controller
  2084. Jun 23 2015 - RTKVHD64.sys - Realtek Audio System driver https://www.realtek.com/en/
  2085. Apr 11 2018 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
  2086. Jun 11 2018 - e1i65x64.sys - Intel(R) Gigabit Adapter driver
  2087. Feb 19 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
  2088. May 15 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
  2089. May 20 2020 - FACEIT.sys - FACEIT Client https://www.faceit.com/
  2090.  
  2091. ================== Dump #4: 3RD PARTY DRIVERS (FULL) ===================
  2092.  
  2093. Image path: \SystemRoot\system32\DRIVERS\AsrAppCharger.sys
  2094. Image name: AsrAppCharger.sys
  2095. Search : https://www.google.com/search?q=AsrAppCharger.sys
  2096. ADA Info : ASRock App Charger driver
  2097. Timestamp : Tue May 10 2011
  2098.  
  2099. Image path: \SystemRoot\System32\drivers\iaStorA.sys
  2100. Image name: iaStorA.sys
  2101. Search : https://www.google.com/search?q=iaStorA.sys
  2102. ADA Info : Intel SATA Storage Device RAID Controller
  2103. Timestamp : Wed Jun 3 2015
  2104.  
  2105. Image path: \SystemRoot\system32\drivers\RTKVHD64.sys
  2106. Image name: RTKVHD64.sys
  2107. Search : https://www.google.com/search?q=RTKVHD64.sys
  2108. ADA Info : Realtek Audio System driver https://www.realtek.com/en/
  2109. Timestamp : Tue Jun 23 2015
  2110.  
  2111. Image path: \SystemRoot\System32\drivers\TeeDriverW8x64.sys
  2112. Image name: TeeDriverW8x64.sys
  2113. Search : https://www.google.com/search?q=TeeDriverW8x64.sys
  2114. ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
  2115. Timestamp : Wed Apr 11 2018
  2116.  
  2117. Mapped memory image file: C:\ProgramData\dbg\sym\e1i65x64.sys\5B1EB8E28e000\e1i65x64.sys
  2118. Image path: \SystemRoot\System32\drivers\e1i65x64.sys
  2119. Image name: e1i65x64.sys
  2120. Search : https://www.google.com/search?q=e1i65x64.sys
  2121. ADA Info : Intel(R) Gigabit Adapter driver
  2122. Timestamp : Mon Jun 11 2018
  2123. File version: 12.17.10.8
  2124. Product version: 10.0.10011.16384
  2125. File flags: 8 (Mask 3F) Private
  2126. File OS: 40004 NT Win32
  2127. File type: 3.6 Driver
  2128. File date: 00000000.00000000
  2129. CompanyName: Intel Corporation
  2130. ProductName: Intel(R) Gigabit Adapter
  2131. InternalName: e1i65x64.sys
  2132. OriginalFilename: e1i65x64.sys
  2133. ProductVersion: 12.17.10.8
  2134. FileVersion: 12.17.10.8
  2135. FileDescription: Intel(R) Gigabit Adapter NDIS 6.x driver
  2136. LegalCopyright: Copyright(C) 2013, Intel Corporation. All rights reserved.
  2137.  
  2138. Image path: \SystemRoot\system32\drivers\nvhda64v.sys
  2139. Image name: nvhda64v.sys
  2140. Search : https://www.google.com/search?q=nvhda64v.sys
  2141. ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
  2142. Timestamp : Wed Feb 19 2020
  2143.  
  2144. Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d5216eae94436d77\nvlddmkm.sys
  2145. Image name: nvlddmkm.sys
  2146. Search : https://www.google.com/search?q=nvlddmkm.sys
  2147. ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
  2148. Timestamp : Fri May 15 2020
  2149.  
  2150. Image path: \SystemRoot\System32\Drivers\FACEIT.sys
  2151. Image name: FACEIT.sys
  2152. Search : https://www.google.com/search?q=FACEIT.sys
  2153. ADA Info : FACEIT Client https://www.faceit.com/
  2154. Timestamp : Wed May 20 2020
  2155.  
  2156. ====================== Dump #4: MICROSOFT DRIVERS ======================
  2157.  
  2158. ACPI.sys ACPI Driver for NT (Microsoft)
  2159. acpiex.sys ACPIEx Driver (Microsoft)
  2160. acpipagr.sys ACPI Processor Aggregator Device driver (Microsoft)
  2161. afd.sys Ancillary Function Driver for WinSock (Microsoft)
  2162. afunix.sys AF_UNIX Socket Provider driver (Microsoft)
  2163. AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
  2164. ahcache.sys Application Compatibility Cache (Microsoft)
  2165. bam.sys BAM Kernal driver (Microsoft)
  2166. BasicDisplay.sys Basic Display driver (Microsoft)
  2167. BasicRender.sys Basic Render driver (Microsoft)
  2168. Beep.SYS BEEP driver (Microsoft)
  2169. bindflt.sys Windows Bind Filter driver (Microsoft)
  2170. BOOTVID.dll VGA Boot Driver (Microsoft)
  2171. bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
  2172. cdd.dll Canonical Display Driver (Microsoft)
  2173. cdrom.sys SCSI CD-ROM Driver (Microsoft)
  2174. CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
  2175. CI.dll Code Integrity Module (Microsoft)
  2176. CLASSPNP.SYS SCSI Class System Dll (Microsoft)
  2177. cldflt.sys Cloud Files Mini Filter driver (Microsoft)
  2178. CLFS.SYS Common Log File System Driver (Microsoft)
  2179. clipsp.sys CLIP Service (Microsoft)
  2180. cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
  2181. cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
  2182. CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
  2183. condrv.sys Console Driver (Microsoft)
  2184. crashdmp.sys Crash Dump driver (Microsoft)
  2185. dfsc.sys DFS Namespace Client Driver (Microsoft)
  2186. disk.sys PnP Disk Driver (Microsoft)
  2187. drmk.sys Digital Rights Management (DRM) driver (Microsoft)
  2188. dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  2189. dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  2190. dump_iaStorA.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  2191. dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
  2192. dxgmms2.sys DirectX Graphics MMS
  2193. EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
  2194. filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
  2195. fileinfo.sys FileInfo Filter Driver (Microsoft)
  2196. FLTMGR.SYS Filesystem Filter Manager (Microsoft)
  2197. Fs_Rec.sys File System Recognizer Driver (Microsoft)
  2198. fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
  2199. fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
  2200. gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
  2201. hal.dll Hardware Abstraction Layer DLL (Microsoft)
  2202. HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
  2203. HIDCLASS.SYS Hid Class Library (Microsoft)
  2204. HIDPARSE.SYS Hid Parsing Library (Microsoft)
  2205. hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
  2206. HTTP.sys HTTP Protocol Stack (Microsoft)
  2207. hwpolicy.sys Hardware Policy Driver
  2208. intelpep.sys Intel Power Engine Plugin (Microsoft)
  2209. intelppm.sys Processor Device Driver (Microsoft)
  2210. iorate.sys I/O rate control Filter (Microsoft)
  2211. kbdclass.sys Keyboard Class Driver (Microsoft)
  2212. kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
  2213. kd.dll Local Kernal Debugger (Microsoft)
  2214. kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
  2215. ks.sys Kernal CSA Library (Microsoft)
  2216. ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
  2217. ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
  2218. ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
  2219. lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
  2220. luafv.sys LUA File Virtualization Filter Driver (Microsoft)
  2221. mcupdate_GenuineIntel.dll Intel Microcode Update Library (Microsoft)
  2222. mmcss.sys MMCSS Driver (Microsoft)
  2223. monitor.sys Monitor Driver (Microsoft)
  2224. mouclass.sys Mouse Class Driver (Microsoft)
  2225. mouhid.sys HID Mouse Filter Driver (Microsoft)
  2226. mountmgr.sys Mount Point Manager (Microsoft)
  2227. mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
  2228. mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
  2229. mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
  2230. Msfs.SYS Mailslot driver (Microsoft)
  2231. msisadrv.sys ISA Driver (Microsoft)
  2232. mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
  2233. msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
  2234. mssmbios.sys System Management BIOS driver (Microsoft)
  2235. mup.sys Multiple UNC Provider driver (Microsoft)
  2236. ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
  2237. ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
  2238. ndisuio.sys NDIS User mode I/O driver (Microsoft)
  2239. NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
  2240. ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
  2241. NDProxy.sys NDIS Proxy driver (Microsoft)
  2242. Ndu.sys Network Data Usage Monitoring driver (Microsoft)
  2243. netbios.sys NetBIOS Interface driver (Microsoft)
  2244. netbt.sys MBT Transport driver (Microsoft)
  2245. NETIO.SYS Network I/O Subsystem (Microsoft)
  2246. Npfs.SYS NPFS driver (Microsoft)
  2247. npsvctrig.sys Named pipe service triggers (Microsoft)
  2248. nsiproxy.sys NSI Proxy driver (Microsoft)
  2249. Ntfs.sys NT File System Driver (Microsoft)
  2250. ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
  2251. ntosext.sys NTOS Extension Host driver (Microsoft)
  2252. Null.SYS NULL Driver (Microsoft)
  2253. pacer.sys QoS Packet Scheduler (Microsoft)
  2254. partmgr.sys Partition driver (Microsoft)
  2255. pci.sys NT Plug and Play PCI Enumerator (Microsoft)
  2256. pcw.sys Performance Counter Driver (Microsoft)
  2257. pdc.sys Power Dependency Coordinator Driver (Microsoft)
  2258. peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
  2259. portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
  2260. PSHED.dll Platform Specific Hardware Error driver (Microsoft)
  2261. qwavedrv.sys Quality Windows Audio Video Experience (qWave) Support driver (Microsoft)
  2262. rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
  2263. raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
  2264. raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
  2265. rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
  2266. rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
  2267. rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
  2268. rdpvideominiport.sys RDP Video Miniport driver (Microsoft)
  2269. rdyboost.sys ReadyBoost Driver (Microsoft)
  2270. rspndr.sys Link-Layer Topology Responder driver (Microsoft)
  2271. serenum.sys Serial Port Enumerator (Microsoft)
  2272. serial.sys Serial Device Driver
  2273. SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
  2274. SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
  2275. spaceport.sys Storage Spaces driver (Microsoft)
  2276. srv2.sys Smb 2.0 Server driver (Microsoft)
  2277. srvnet.sys Server Network driver (Microsoft)
  2278. storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
  2279. storqosflt.sys Storage QoS Filter driver (Microsoft)
  2280. swenum.sys Plug and Play Software Device Enumerator (Microsoft)
  2281. tbs.sys Export driver for kernel mode TPM API (Microsoft)
  2282. tcpip.sys TCP/IP Protocol driver (Microsoft)
  2283. tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
  2284. TDI.SYS TDI Wrapper driver (Microsoft)
  2285. tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
  2286. tm.sys Kernel Transaction Manager driver (Microsoft)
  2287. ucx01000.sys USB Controller Extension (Microsoft)
  2288. umbus.sys User-Mode Bus Enumerator (Microsoft)
  2289. usbaudio2.sys Microsoft USB Audio Class 2.0 Driver
  2290. usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
  2291. USBD.SYS Universal Serial Bus Driver (Microsoft)
  2292. UsbHub3.sys USB3 HUB driver (Microsoft)
  2293. USBXHCI.SYS USB XHCI driver (Microsoft)
  2294. vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
  2295. Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
  2296. volmgr.sys Volume Manager Driver (Microsoft)
  2297. volmgrx.sys Volume Manager Extension Driver (Microsoft)
  2298. volsnap.sys Volume Shadow Copy driver (Microsoft)
  2299. volume.sys Volume driver (Microsoft)
  2300. vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
  2301. wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
  2302. watchdog.sys Watchdog driver (Microsoft)
  2303. wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
  2304. WdBoot.sys Microsoft Antimalware Boot driver
  2305. Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
  2306. WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
  2307. WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
  2308. WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
  2309. werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
  2310. wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
  2311. win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
  2312. win32kbase.sys Base Win32k Kernel Driver (Microsoft)
  2313. win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
  2314. WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
  2315. WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
  2316. winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
  2317. winquic.sys QUIC Transport Protocol driver (Microsoft)
  2318. wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
  2319. WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
  2320. Wof.sys Windows Overlay Filter (Microsoft)
  2321. WppRecorder.sys WPP Trace Recorder (Microsoft)
  2322. WSDPrint.sys Web Services Print Device driver (Microsoft)
  2323.  
  2324. ====================== Dump #4: UNLOADED MODULES =======================
  2325.  
  2326. fffff800`88a30000 fffff800`88a3e000 WSDPrint.sys
  2327. fffff800`88a40000 fffff800`88a4e000 WSDPrint.sys
  2328. fffff800`889b0000 fffff800`889f6000 usbaudio2.sy
  2329. fffff800`88a00000 fffff800`88a0f000 hiber_storpo
  2330. fffff800`80ae0000 fffff800`81053000 hiber_iaStor
  2331. fffff800`81060000 fffff800`8107e000 hiber_dumpfv
  2332. fffff800`88a30000 fffff800`88a3e000 WSDPrint.sys
  2333. fffff800`88a60000 fffff800`88a6e000 WSDPrint.sys
  2334. fffff800`889b0000 fffff800`889f6000 usbaudio2.sy
  2335. fffff800`88a00000 fffff800`88a0f000 hiber_storpo
  2336. fffff800`7cf40000 fffff800`7d4b3000 hiber_iaStor
  2337. fffff800`7d4c0000 fffff800`7d4de000 hiber_dumpfv
  2338. fffff800`88a50000 fffff800`88a5e000 WSDPrint.sys
  2339. fffff800`88a30000 fffff800`88a3e000 WSDPrint.sys
  2340. fffff800`889b0000 fffff800`889f6000 usbaudio2.sy
  2341. fffff800`88a40000 fffff800`88a4f000 hiber_storpo
  2342. fffff800`7c6e0000 fffff800`7cc53000 hiber_iaStor
  2343. fffff800`7cc60000 fffff800`7cc7e000 hiber_dumpfv
  2344. fffff800`88a00000 fffff800`88a0e000 WSDPrint.sys
  2345. fffff800`88a70000 fffff800`88a7e000 WSDPrint.sys
  2346. fffff800`889b0000 fffff800`889f6000 usbaudio2.sy
  2347. fffff800`88a00000 fffff800`88a0f000 hiber_storpo
  2348. fffff800`7cc30000 fffff800`7d1a3000 hiber_iaStor
  2349. fffff800`7d1b0000 fffff800`7d1ce000 hiber_dumpfv
  2350. fffff800`88a60000 fffff800`88a6e000 WSDPrint.sys
  2351. fffff800`88a40000 fffff800`88a4e000 WSDPrint.sys
  2352. fffff800`889c0000 fffff800`88a06000 usbaudio2.sy
  2353. fffff800`88a50000 fffff800`88a5f000 hiber_storpo
  2354. fffff800`7ce00000 fffff800`7d373000 hiber_iaStor
  2355. fffff800`7d380000 fffff800`7d39e000 hiber_dumpfv
  2356. fffff800`88a30000 fffff800`88a3e000 WSDPrint.sys
  2357. fffff800`889b0000 fffff800`889be000 WSDPrint.sys
  2358. fffff800`88a40000 fffff800`88a51000 MpKslDrv.sys
  2359. fffff800`88970000 fffff800`8897e000 WSDPrint.sys
  2360. fffff800`88a70000 fffff800`88a7e000 WSDPrint.sys
  2361. fffff800`889c0000 fffff800`88a06000 usbaudio2.sy
  2362. fffff800`88bf0000 fffff800`88bff000 hiber_storpo
  2363. fffff800`7c790000 fffff800`7cd03000 hiber_iaStor
  2364. fffff800`7cd10000 fffff800`7cd2e000 hiber_dumpfv
  2365. fffff800`88a60000 fffff800`88a6e000 WSDPrint.sys
  2366. fffff800`88a30000 fffff800`88a3e000 WSDPrint.sys
  2367. fffff800`88a20000 fffff800`88a2e000 WSDPrint.sys
  2368. fffff800`88a10000 fffff800`88a1e000 WSDPrint.sys
  2369. fffff800`88970000 fffff800`8897e000 WSDPrint.sys
  2370. fffff800`889b0000 fffff800`889bf000 hiber_storpo
  2371. fffff800`7c590000 fffff800`7cb03000 hiber_iaStor
  2372. fffff800`7cb10000 fffff800`7cb2e000 hiber_dumpfv
  2373. fffff800`890e0000 fffff800`89126000 usbaudio2.sy
  2374. fffff800`88bf0000 fffff800`88bfe000 WSDPrint.sys
  2375. fffff800`85ef0000 fffff800`85eff000 dump_storpor
  2376.  
  2377. ====================== Dump #4: BIOS INFORMATION =======================
  2378.  
  2379. [SMBIOS Data Tables v2.8]
  2380. [DMI Version - 0]
  2381. [2.0 Calling Convention - No]
  2382. [Table Size - 1735 bytes]
  2383. [BIOS Information (Type 0) - Length 24 - Handle 0000h]
  2384. Vendor American Megatrends Inc.
  2385. BIOS Version P7.50
  2386. BIOS Starting Address Segment f000
  2387. BIOS Release Date 01/23/2018
  2388. BIOS ROM Size e00000
  2389. BIOS Characteristics
  2390. 07: - PCI Supported
  2391. 11: - Upgradeable FLASH BIOS
  2392. 12: - BIOS Shadowing Supported
  2393. 15: - CD-Boot Supported
  2394. 16: - Selectable Boot Supported
  2395. 17: - BIOS ROM Socketed
  2396. 19: - EDD Supported
  2397. 23: - 1.2MB Floppy Supported
  2398. 24: - 720KB Floppy Supported
  2399. 25: - 2.88MB Floppy Supported
  2400. 26: - Print Screen Device Supported
  2401. 27: - Keyboard Services Supported
  2402. 28: - Serial Services Supported
  2403. 29: - Printer Services Supported
  2404. 32: - BIOS Vendor Reserved
  2405. BIOS Characteristic Extensions
  2406. 00: - ACPI Supported
  2407. 01: - USB Legacy Supported
  2408. 08: - BIOS Boot Specification Supported
  2409. 10: - Specification Reserved
  2410. 11: - Specification Reserved
  2411. BIOS Major Revision 5
  2412. BIOS Minor Revision 11
  2413. EC Firmware Major Revision 255
  2414. EC Firmware Minor Revision 255
  2415. [System Information (Type 1) - Length 27 - Handle 0001h]
  2416. UUID 00000000-0000-0000-0000-000000000000
  2417. Wakeup Type Power Switch
  2418. [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
  2419. Manufacturer ASRock
  2420. Product Z170 Pro4S
  2421. Version
  2422. Feature Flags 09h
  2423. -449726752: - -449726704: - ÷7!ü
  2424. Location
  2425. Chassis Handle 0003h
  2426. Board Type 0ah - Processor/Memory Module
  2427. Number of Child Handles 0
  2428. [System Enclosure (Type 3) - Length 25 - Handle 0003h]
  2429. Chassis Type Desktop
  2430. Bootup State Safe
  2431. Power Supply State Safe
  2432. Thermal State Safe
  2433. Security Status None
  2434. OEM Defined 0
  2435. Height 0U
  2436. Number of Power Cords 1
  2437. Number of Contained Elements 1
  2438. Contained Element Size 3
  2439. [OEM Strings (Type 11) - Length 5 - Handle 000ah]
  2440. Number of Strings 1
  2441. [Cache Information (Type 7) - Length 19 - Handle 000dh]
  2442. Socket Designation L1 Cache
  2443. Cache Configuration 0180h - WB Enabled Int NonSocketed L1
  2444. Maximum Cache Size 0080h - 128K
  2445. Installed Size 0080h - 128K
  2446. Supported SRAM Type 0020h - Synchronous
  2447. Current SRAM Type 0020h - Synchronous
  2448. Cache Speed 0ns
  2449. Error Correction Type ParitySingle-Bit ECC
  2450. System Cache Type Data
  2451. Associativity 8-way Set-Associative
  2452. [Cache Information (Type 7) - Length 19 - Handle 000eh]
  2453. Socket Designation L1 Cache
  2454. Cache Configuration 0180h - WB Enabled Int NonSocketed L1
  2455. Maximum Cache Size 0080h - 128K
  2456. Installed Size 0080h - 128K
  2457. Supported SRAM Type 0020h - Synchronous
  2458. Current SRAM Type 0020h - Synchronous
  2459. Cache Speed 0ns
  2460. Error Correction Type ParitySingle-Bit ECC
  2461. System Cache Type Instruction
  2462. Associativity 8-way Set-Associative
  2463. [Cache Information (Type 7) - Length 19 - Handle 000fh]
  2464. Socket Designation L2 Cache
  2465. Cache Configuration 0181h - WB Enabled Int NonSocketed L2
  2466. Maximum Cache Size 0400h - 1024K
  2467. Installed Size 0400h - 1024K
  2468. Supported SRAM Type 0020h - Synchronous
  2469. Current SRAM Type 0020h - Synchronous
  2470. Cache Speed 0ns
  2471. Error Correction Type Multi-Bit ECC
  2472. System Cache Type Unified
  2473. Associativity 4-way Set-Associative
  2474. [Cache Information (Type 7) - Length 19 - Handle 0010h]
  2475. Socket Designation L3 Cache
  2476. Cache Configuration 0182h - WB Enabled Int NonSocketed L3
  2477. Maximum Cache Size 1800h - 6144K
  2478. Installed Size 1800h - 6144K
  2479. Supported SRAM Type 0020h - Synchronous
  2480. Current SRAM Type 0020h - Synchronous
  2481. Cache Speed 0ns
  2482. Error Correction Type Specification Reserved
  2483. System Cache Type Unified
  2484. Associativity Specification Reserved
  2485. [Processor Information (Type 4) - Length 48 - Handle 0011h]
  2486. Socket Designation CPUSocket
  2487. Processor Type Central Processor
  2488. Processor Family cdh - Specification Reserved
  2489. Processor Manufacturer Intel(R) Corporation
  2490. Processor ID e3060500fffbebbf
  2491. Processor Version Intel(R) Core(TM) i5-6600K CPU @ 3.50GHz
  2492. Processor Voltage 8bh - 1.1V
  2493. External Clock 100MHz
  2494. Max Speed 5000MHz
  2495. Current Speed 3500MHz
  2496. Status Enabled Populated
  2497. Processor Upgrade Other
  2498. L1 Cache Handle 000eh
  2499. L2 Cache Handle 000fh
  2500. L3 Cache Handle 0010h
  2501. [Physical Memory Array (Type 16) - Length 23 - Handle 0012h]
  2502. Location 03h - SystemBoard/Motherboard
  2503. Use 03h - System Memory
  2504. Memory Error Correction 03h - None
  2505. Maximum Capacity 67108864KB
  2506. Number of Memory Devices 4
  2507. [Memory Device (Type 17) - Length 40 - Handle 0013h]
  2508. Physical Memory Array Handle 0012h
  2509. Total Width 0 bits
  2510. Data Width 0 bits
  2511. Form Factor 09h - DIMM
  2512. Device Locator ChannelA-DIMM0
  2513. Bank Locator BANK 0
  2514. Memory Type 02h - Unknown
  2515. Type Detail 0000h -
  2516. Speed 0MHz
  2517. [Memory Device (Type 17) - Length 40 - Handle 0014h]
  2518. Physical Memory Array Handle 0012h
  2519. Total Width 64 bits
  2520. Data Width 64 bits
  2521. Size 8192MB
  2522. Form Factor 09h - DIMM
  2523. Device Locator ChannelA-DIMM1
  2524. Bank Locator BANK 1
  2525. Memory Type 1ah - Specification Reserved
  2526. Type Detail 0080h - Synchronous
  2527. Speed 3000MHz
  2528. Manufacturer Kingston
  2529. Part Number KHX3000C15D4/8GX
  2530. [Memory Device (Type 17) - Length 40 - Handle 0015h]
  2531. Physical Memory Array Handle 0012h
  2532. Total Width 0 bits
  2533. Data Width 0 bits
  2534. Form Factor 09h - DIMM
  2535. Device Locator ChannelB-DIMM0
  2536. Bank Locator BANK 2
  2537. Memory Type 02h - Unknown
  2538. Type Detail 0000h -
  2539. Speed 0MHz
  2540. [Memory Device (Type 17) - Length 40 - Handle 0016h]
  2541. Physical Memory Array Handle 0012h
  2542. Total Width 64 bits
  2543. Data Width 64 bits
  2544. Size 8192MB
  2545. Form Factor 09h - DIMM
  2546. Device Locator ChannelB-DIMM1
  2547. Bank Locator BANK 3
  2548. Memory Type 1ah - Specification Reserved
  2549. Type Detail 0080h - Synchronous
  2550. Speed 3000MHz
  2551. Manufacturer Kingston
  2552. Part Number KHX3000C15D4/8GX
  2553. [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0017h]
  2554. Starting Address 00000000h
  2555. Ending Address 00ffffffh
  2556. Memory Array Handle 0012h
  2557. Partition Width 02
  2558. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0018h]
  2559. Starting Address 00000000h
  2560. Ending Address 007fffffh
  2561. Memory Device Handle 0014h
  2562. Mem Array Mapped Adr Handle 0017h
  2563. Partition Row Position 01
  2564. Interleave Position 01
  2565. Interleave Data Depth 02
  2566. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0019h]
  2567. Starting Address 00800000h
  2568. Ending Address 00ffffffh
  2569. Memory Device Handle 0016h
  2570. Mem Array Mapped Adr Handle 0017h
  2571. Partition Row Position 01
  2572. Interleave Position 02
  2573. Interleave Data Depth 02
  2574.  
  2575. ========================== Dump #4: Extra #1 ===========================
  2576.  
  2577. 0: kd> !verifier
  2578. Verify Flags Level 0x00000000
  2579. STANDARD FLAGS:
  2580. [X] (0x00000000) Automatic Checks
  2581. [ ] (0x00000001) Special pool
  2582. [ ] (0x00000002) Force IRQL checking
  2583. [ ] (0x00000008) Pool tracking
  2584. [ ] (0x00000010) I/O verification
  2585. [ ] (0x00000020) Deadlock detection
  2586. [ ] (0x00000080) DMA checking
  2587. [ ] (0x00000100) Security checks
  2588. [ ] (0x00000800) Miscellaneous checks
  2589. [ ] (0x00020000) DDI compliance checking
  2590. ADDITIONAL FLAGS:
  2591. [ ] (0x00000004) Randomized low resources simulation
  2592. [ ] (0x00000200) Force pending I/O requests
  2593. [ ] (0x00000400) IRP logging
  2594. [ ] (0x00002000) Invariant MDL checking for stack
  2595. [ ] (0x00004000) Invariant MDL checking for driver
  2596. [ ] (0x00008000) Power framework delay fuzzing
  2597. [ ] (0x00010000) Port/miniport interface checking
  2598. [ ] (0x00040000) Systematic low resources simulation
  2599. [ ] (0x00080000) DDI compliance checking (additional)
  2600. [ ] (0x00200000) NDIS/WIFI verification
  2601. [ ] (0x00800000) Kernel synchronization delay fuzzing
  2602. [ ] (0x01000000) VM switch verification
  2603. [ ] (0x02000000) Code integrity checks
  2604. [X] Indicates flag is enabled
  2605. Summary of All Verifier Statistics
  2606. RaiseIrqls 0x0
  2607. AcquireSpinLocks 0x0
  2608. Synch Executions 0x0
  2609. Trims 0x0
  2610. Pool Allocations Attempted 0x0
  2611. Pool Allocations Succeeded 0x0
  2612. Pool Allocations Succeeded SpecialPool 0x0
  2613. Pool Allocations With NO TAG 0x0
  2614. Pool Allocations Failed 0x0
  2615. Current paged pool allocations 0x0 for 00000000 bytes
  2616. Peak paged pool allocations 0x0 for 00000000 bytes
  2617. Current nonpaged pool allocations 0x0 for 00000000 bytes
  2618. Peak nonpaged pool allocations 0x0 for 00000000 bytes
  2619.  
  2620. ========================== Dump #4: Extra #2 ===========================
  2621.  
  2622. 0: kd> !thread
  2623. THREAD fffff8007e591400 Cid 0000.0000 Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor 0
  2624. Not impersonating
  2625. GetUlongFromAddress: unable to read from fffff8007e42ca14
  2626. Owning Process fffff8007e58e9c0 Image: System Process
  2627. Attached Process ffffdd8c1b86e080 Image: System
  2628. Wait Start TickCount 24584431 Ticks: 1 (0:00:00:00.015)
  2629. Context Switch Count 253675088 IdealProcessor: 0
  2630. ReadMemory error: Cannot get nt!KeMaximumIncrement value.
  2631. UserTime 00:00:00.000
  2632. KernelTime 00:00:00.000
  2633. Win32 Start Address nt!KiIdleLoop (0xfffff8007e1c5e50)
  2634. Stack Init fffff80085338b90 Current fffff80085338b20
  2635. Base fffff80085339000 Limit fffff80085332000 Call 0000000000000000
  2636. Priority 0 BasePriority 0 PriorityDecrement 0 IoPriority 0 PagePriority 5
  2637. Child-SP RetAddr : Args to Child : Call Site
  2638. fffff800`85338538 fffff800`7e1d41e9 : 00000000`0000000a fffff800`85298808 00000000`000000ff 00000000`000000f5 : nt!KeBugCheckEx
  2639. fffff800`85338540 fffff800`7e1d0529 : 00000000`00000000 00000000`00000000 00000000`017720f0 00000000`00000000 : nt!KiBugCheckDispatch+0x69
  2640. fffff800`85338680 fffff800`7e04b27c : 0000037e`605deadc 00000000`00000000 00000000`00000000 fffff800`7c2d3180 : nt!KiPageFault+0x469 (TrapFrame @ fffff800`85338680)
  2641. fffff800`85338810 fffff800`7e04a1e6 : 00000000`00000003 00000000`00000002 ffffdd8c`1df9b0f0 00000000`00000008 : nt!PpmIdlePrepare+0xec
  2642. fffff800`85338a00 fffff800`7e1c5e94 : 00000000`00000000 fffff800`7c2d3180 ffffdd8c`2e26d0c0 00000000`00000378 : nt!PoIdle+0x1e6
  2643. fffff800`85338b60 00000000`00000000 : fffff800`85339000 fffff800`85332000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x44
  2644.  
  2645.  
  2646. ========================================================================
  2647. ======================= Dump #5: ANALYZE VERBOSE =======================
  2648. ======================= File: 061220-8281-01.dmp =======================
  2649. ========================================================================
  2650.  
  2651. Mini Kernel Dump File: Only registers and stack trace are available
  2652. Windows 10 Kernel Version 18362 MP (4 procs) Free x64
  2653. Kernel base = 0xfffff804`36400000 PsLoadedModuleList = 0xfffff804`36848190
  2654. Debug session time: Thu Jun 11 20:03:17.374 2020 (UTC - 4:00)
  2655. System Uptime: 1 days 4:21:38.045
  2656.  
  2657. BugCheck A, {fffff8043d3186d8, ff, a2, fffff8043644adf2}
  2658. *** WARNING: Unable to verify timestamp for win32k.sys
  2659. *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
  2660. Probably caused by : memory_corruption
  2661. Followup: memory_corruption
  2662.  
  2663. IRQL_NOT_LESS_OR_EQUAL (a)
  2664. An attempt was made to access a pageable (or completely invalid) address at an
  2665. interrupt request level (IRQL) that is too high. This is usually
  2666. caused by drivers using improper addresses.
  2667. If a kernel debugger is available get the stack backtrace.
  2668.  
  2669. Arguments:
  2670. Arg1: fffff8043d3186d8, memory referenced
  2671. Arg2: 00000000000000ff, IRQL
  2672. Arg3: 00000000000000a2, bitfield :
  2673. bit 0 : value 0 = read operation, 1 = write operation
  2674. bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
  2675. Arg4: fffff8043644adf2, address which referenced memory
  2676.  
  2677. Debugging Details:
  2678. DUMP_CLASS: 1
  2679. DUMP_QUALIFIER: 400
  2680. DUMP_TYPE: 2
  2681. READ_ADDRESS: fffff804369733b8: Unable to get MiVisibleState
  2682. fffff8043d3186d8
  2683. CURRENT_IRQL: 0
  2684. FAULTING_IP:
  2685. nt!PpmIdleExecuteTransition+8e2
  2686. fffff804`3644adf2 e8090a0000 call nt!KeAccumulateTicks (fffff804`3644b800)
  2687. CUSTOMER_CRASH_COUNT: 1
  2688. DEFAULT_BUCKET_ID: CODE_CORRUPTION
  2689. BUGCHECK_STR: AV
  2690.  
  2691. PROCESS_NAME: System
  2692.  
  2693. TRAP_FRAME: fffff8043d338550 -- (.trap 0xfffff8043d338550)
  2694. NOTE: The trap frame does not contain all registers.
  2695. Some register values may be zeroed or incorrect.
  2696. rax=fffff78000000320 rbx=0000000000000000 rcx=fffff8043419c180
  2697. rdx=000000000063b482 rsi=0000000000000000 rdi=0000000000000000
  2698. rip=fffff8043644adf2 rsp=fffff8043d3386e0 rbp=ffffcd024c5d6000
  2699. r8=000000000063b482 r9=0000000000000000 r10=fffff8043635f3d0
  2700. r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
  2701. r14=0000000000000000 r15=0000000000000000
  2702. iopl=0 nv up di pl zr na po nc
  2703. nt!PpmIdleExecuteTransition+0x8e2:
  2704. fffff804`3644adf2 e8090a0000 call nt!KeAccumulateTicks (fffff804`3644b800)
  2705. Resetting default scope
  2706. LAST_CONTROL_TRANSFER: from fffff804365d41e9 to fffff804365c23a0
  2707. STACK_TEXT:
  2708. fffff804`3d338408 fffff804`365d41e9 : 00000000`0000000a fffff804`3d3186d8 00000000`000000ff 00000000`000000a2 : nt!KeBugCheckEx
  2709. fffff804`3d338410 fffff804`365d0529 : 00000000`00000002 fffff804`364f7d8e 00000000`40cb0088 00000000`00000000 : nt!KiBugCheckDispatch+0x69
  2710. fffff804`3d338550 fffff804`3644adf2 : ffffffff`fffffffe 0000ecb6`39857909 fffff804`3419c180 00000000`00000000 : nt!KiPageFault+0x469
  2711. fffff804`3d3386e0 fffff804`3644a36e : 00000000`00000003 00000000`00000002 00000000`00000001 00000000`00000000 : nt!PpmIdleExecuteTransition+0x8e2
  2712. fffff804`3d338a00 fffff804`365c5e94 : 00000000`00000000 fffff804`3419c180 ffffcd02`47a27040 00000000`000005f2 : nt!PoIdle+0x36e
  2713. fffff804`3d338b60 00000000`00000000 : fffff804`3d339000 fffff804`3d332000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x44
  2714. STACK_COMMAND: kb
  2715. CHKIMG_EXTENSION: !chkimg -lo 50 -d !hal
  2716. fffff8043635f457-fffff8043635f458 2 bytes - hal!HalPutScatterGatherList+67
  2717. [ 48 ff:4c 8b ]
  2718. fffff8043635f45e-fffff8043635f461 4 bytes - hal!HalPutScatterGatherList+6e (+0x07)
  2719. [ 0f 1f 44 00:e8 3d fc 40 ]
  2720. 6 errors : !hal (fffff8043635f457-fffff8043635f461)
  2721. MODULE_NAME: memory_corruption
  2722.  
  2723. IMAGE_NAME: memory_corruption
  2724.  
  2725. FOLLOWUP_NAME: memory_corruption
  2726. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  2727. MEMORY_CORRUPTOR: LARGE
  2728. FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
  2729. BUCKET_ID: MEMORY_CORRUPTION_LARGE
  2730. PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
  2731. TARGET_TIME: 2020-06-12T00:03:17.000Z
  2732. SUITE_MASK: 784
  2733. PRODUCT_TYPE: 1
  2734. USER_LCID: 0
  2735. FAILURE_ID_HASH_STRING: km:memory_corruption_large
  2736. FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
  2737. Followup: memory_corruption
  2738.  
  2739. ====================== Dump #5: 3RD PARTY DRIVERS ======================
  2740.  
  2741. May 10 2011 - AsrAppCharger.sys - ASRock App Charger driver
  2742. Jun 03 2015 - iaStorA.sys - Intel SATA Storage Device RAID Controller
  2743. Jun 23 2015 - RTKVHD64.sys - Realtek Audio System driver https://www.realtek.com/en/
  2744. Apr 11 2018 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
  2745. Jun 11 2018 - e1i65x64.sys - Intel(R) Gigabit Adapter driver
  2746. Feb 19 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
  2747. Mar 17 2020 - EasyAntiCheat.sys - EasyAntiCheat is a anti-cheat driver (EasyAntiCheat Oy.) https://support.easyanticheat.net/
  2748. May 15 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
  2749. May 20 2020 - FACEIT.sys - FACEIT Client https://www.faceit.com/
  2750.  
  2751. ================== Dump #5: 3RD PARTY DRIVERS (FULL) ===================
  2752.  
  2753. Image path: \SystemRoot\system32\DRIVERS\AsrAppCharger.sys
  2754. Image name: AsrAppCharger.sys
  2755. Search : https://www.google.com/search?q=AsrAppCharger.sys
  2756. ADA Info : ASRock App Charger driver
  2757. Timestamp : Tue May 10 2011
  2758.  
  2759. Image path: \SystemRoot\System32\drivers\iaStorA.sys
  2760. Image name: iaStorA.sys
  2761. Search : https://www.google.com/search?q=iaStorA.sys
  2762. ADA Info : Intel SATA Storage Device RAID Controller
  2763. Timestamp : Wed Jun 3 2015
  2764.  
  2765. Image path: \SystemRoot\system32\drivers\RTKVHD64.sys
  2766. Image name: RTKVHD64.sys
  2767. Search : https://www.google.com/search?q=RTKVHD64.sys
  2768. ADA Info : Realtek Audio System driver https://www.realtek.com/en/
  2769. Timestamp : Tue Jun 23 2015
  2770.  
  2771. Image path: \SystemRoot\System32\drivers\TeeDriverW8x64.sys
  2772. Image name: TeeDriverW8x64.sys
  2773. Search : https://www.google.com/search?q=TeeDriverW8x64.sys
  2774. ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
  2775. Timestamp : Wed Apr 11 2018
  2776.  
  2777. Mapped memory image file: C:\ProgramData\dbg\sym\e1i65x64.sys\5B1EB8E28e000\e1i65x64.sys
  2778. Image path: \SystemRoot\System32\drivers\e1i65x64.sys
  2779. Image name: e1i65x64.sys
  2780. Search : https://www.google.com/search?q=e1i65x64.sys
  2781. ADA Info : Intel(R) Gigabit Adapter driver
  2782. Timestamp : Mon Jun 11 2018
  2783. File version: 12.17.10.8
  2784. Product version: 10.0.10011.16384
  2785. File flags: 8 (Mask 3F) Private
  2786. File OS: 40004 NT Win32
  2787. File type: 3.6 Driver
  2788. File date: 00000000.00000000
  2789. CompanyName: Intel Corporation
  2790. ProductName: Intel(R) Gigabit Adapter
  2791. InternalName: e1i65x64.sys
  2792. OriginalFilename: e1i65x64.sys
  2793. ProductVersion: 12.17.10.8
  2794. FileVersion: 12.17.10.8
  2795. FileDescription: Intel(R) Gigabit Adapter NDIS 6.x driver
  2796. LegalCopyright: Copyright(C) 2013, Intel Corporation. All rights reserved.
  2797.  
  2798. Image path: \SystemRoot\system32\drivers\nvhda64v.sys
  2799. Image name: nvhda64v.sys
  2800. Search : https://www.google.com/search?q=nvhda64v.sys
  2801. ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
  2802. Timestamp : Wed Feb 19 2020
  2803.  
  2804. Image path: \??\C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys
  2805. Image name: EasyAntiCheat.sys
  2806. Search : https://www.google.com/search?q=EasyAntiCheat.sys
  2807. ADA Info : EasyAntiCheat is a anti-cheat driver (EasyAntiCheat Oy.) https://support.easyanticheat.net/
  2808. Timestamp : Tue Mar 17 2020
  2809.  
  2810. Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d5216eae94436d77\nvlddmkm.sys
  2811. Image name: nvlddmkm.sys
  2812. Search : https://www.google.com/search?q=nvlddmkm.sys
  2813. ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
  2814. Timestamp : Fri May 15 2020
  2815.  
  2816. Image path: \SystemRoot\System32\Drivers\FACEIT.sys
  2817. Image name: FACEIT.sys
  2818. Search : https://www.google.com/search?q=FACEIT.sys
  2819. ADA Info : FACEIT Client https://www.faceit.com/
  2820. Timestamp : Wed May 20 2020
  2821.  
  2822. ====================== Dump #5: MICROSOFT DRIVERS ======================
  2823.  
  2824. ACPI.sys ACPI Driver for NT (Microsoft)
  2825. acpiex.sys ACPIEx Driver (Microsoft)
  2826. acpipagr.sys ACPI Processor Aggregator Device driver (Microsoft)
  2827. afd.sys Ancillary Function Driver for WinSock (Microsoft)
  2828. afunix.sys AF_UNIX Socket Provider driver (Microsoft)
  2829. AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
  2830. ahcache.sys Application Compatibility Cache (Microsoft)
  2831. bam.sys BAM Kernal driver (Microsoft)
  2832. BasicDisplay.sys Basic Display driver (Microsoft)
  2833. BasicRender.sys Basic Render driver (Microsoft)
  2834. Beep.SYS BEEP driver (Microsoft)
  2835. bindflt.sys Windows Bind Filter driver (Microsoft)
  2836. BOOTVID.dll VGA Boot Driver (Microsoft)
  2837. bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
  2838. cdd.dll Canonical Display Driver (Microsoft)
  2839. cdrom.sys SCSI CD-ROM Driver (Microsoft)
  2840. CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
  2841. CI.dll Code Integrity Module (Microsoft)
  2842. CLASSPNP.SYS SCSI Class System Dll (Microsoft)
  2843. cldflt.sys Cloud Files Mini Filter driver (Microsoft)
  2844. CLFS.SYS Common Log File System Driver (Microsoft)
  2845. clipsp.sys CLIP Service (Microsoft)
  2846. cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
  2847. cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
  2848. CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
  2849. condrv.sys Console Driver (Microsoft)
  2850. crashdmp.sys Crash Dump driver (Microsoft)
  2851. dfsc.sys DFS Namespace Client Driver (Microsoft)
  2852. disk.sys PnP Disk Driver (Microsoft)
  2853. drmk.sys Digital Rights Management (DRM) driver (Microsoft)
  2854. dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  2855. dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  2856. dump_iaStorA.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  2857. dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
  2858. dxgmms2.sys DirectX Graphics MMS
  2859. EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
  2860. filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
  2861. fileinfo.sys FileInfo Filter Driver (Microsoft)
  2862. FLTMGR.SYS Filesystem Filter Manager (Microsoft)
  2863. Fs_Rec.sys File System Recognizer Driver (Microsoft)
  2864. fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
  2865. fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
  2866. gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
  2867. hal.dll Hardware Abstraction Layer DLL (Microsoft)
  2868. HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
  2869. HIDCLASS.SYS Hid Class Library (Microsoft)
  2870. HIDPARSE.SYS Hid Parsing Library (Microsoft)
  2871. hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
  2872. HTTP.sys HTTP Protocol Stack (Microsoft)
  2873. hwpolicy.sys Hardware Policy Driver
  2874. intelpep.sys Intel Power Engine Plugin (Microsoft)
  2875. intelppm.sys Processor Device Driver (Microsoft)
  2876. iorate.sys I/O rate control Filter (Microsoft)
  2877. kbdclass.sys Keyboard Class Driver (Microsoft)
  2878. kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
  2879. kd.dll Local Kernal Debugger (Microsoft)
  2880. kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
  2881. ks.sys Kernal CSA Library (Microsoft)
  2882. ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
  2883. ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
  2884. ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
  2885. lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
  2886. luafv.sys LUA File Virtualization Filter Driver (Microsoft)
  2887. mcupdate_GenuineIntel.dll Intel Microcode Update Library (Microsoft)
  2888. mmcss.sys MMCSS Driver (Microsoft)
  2889. monitor.sys Monitor Driver (Microsoft)
  2890. mouclass.sys Mouse Class Driver (Microsoft)
  2891. mouhid.sys HID Mouse Filter Driver (Microsoft)
  2892. mountmgr.sys Mount Point Manager (Microsoft)
  2893. mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
  2894. mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
  2895. mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
  2896. Msfs.SYS Mailslot driver (Microsoft)
  2897. msisadrv.sys ISA Driver (Microsoft)
  2898. mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
  2899. msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
  2900. mssmbios.sys System Management BIOS driver (Microsoft)
  2901. mup.sys Multiple UNC Provider driver (Microsoft)
  2902. ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
  2903. ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
  2904. ndisuio.sys NDIS User mode I/O driver (Microsoft)
  2905. NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
  2906. ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
  2907. NDProxy.sys NDIS Proxy driver (Microsoft)
  2908. Ndu.sys Network Data Usage Monitoring driver (Microsoft)
  2909. netbios.sys NetBIOS Interface driver (Microsoft)
  2910. netbt.sys MBT Transport driver (Microsoft)
  2911. NETIO.SYS Network I/O Subsystem (Microsoft)
  2912. Npfs.SYS NPFS driver (Microsoft)
  2913. npsvctrig.sys Named pipe service triggers (Microsoft)
  2914. nsiproxy.sys NSI Proxy driver (Microsoft)
  2915. Ntfs.sys NT File System Driver (Microsoft)
  2916. ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
  2917. ntosext.sys NTOS Extension Host driver (Microsoft)
  2918. Null.SYS NULL Driver (Microsoft)
  2919. pacer.sys QoS Packet Scheduler (Microsoft)
  2920. partmgr.sys Partition driver (Microsoft)
  2921. pci.sys NT Plug and Play PCI Enumerator (Microsoft)
  2922. pcw.sys Performance Counter Driver (Microsoft)
  2923. pdc.sys Power Dependency Coordinator Driver (Microsoft)
  2924. peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
  2925. portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
  2926. PSHED.dll Platform Specific Hardware Error driver (Microsoft)
  2927. rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
  2928. raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
  2929. raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
  2930. rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
  2931. rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
  2932. rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
  2933. rdpvideominiport.sys RDP Video Miniport driver (Microsoft)
  2934. rdyboost.sys ReadyBoost Driver (Microsoft)
  2935. rspndr.sys Link-Layer Topology Responder driver (Microsoft)
  2936. serenum.sys Serial Port Enumerator (Microsoft)
  2937. serial.sys Serial Device Driver
  2938. SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
  2939. SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
  2940. spaceport.sys Storage Spaces driver (Microsoft)
  2941. srv2.sys Smb 2.0 Server driver (Microsoft)
  2942. srvnet.sys Server Network driver (Microsoft)
  2943. storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
  2944. storqosflt.sys Storage QoS Filter driver (Microsoft)
  2945. swenum.sys Plug and Play Software Device Enumerator (Microsoft)
  2946. tbs.sys Export driver for kernel mode TPM API (Microsoft)
  2947. tcpip.sys TCP/IP Protocol driver (Microsoft)
  2948. tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
  2949. TDI.SYS TDI Wrapper driver (Microsoft)
  2950. tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
  2951. tm.sys Kernel Transaction Manager driver (Microsoft)
  2952. ucx01000.sys USB Controller Extension (Microsoft)
  2953. umbus.sys User-Mode Bus Enumerator (Microsoft)
  2954. usbaudio2.sys Microsoft USB Audio Class 2.0 Driver
  2955. usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
  2956. USBD.SYS Universal Serial Bus Driver (Microsoft)
  2957. UsbHub3.sys USB3 HUB driver (Microsoft)
  2958. USBXHCI.SYS USB XHCI driver (Microsoft)
  2959. vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
  2960. Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
  2961. volmgr.sys Volume Manager Driver (Microsoft)
  2962. volmgrx.sys Volume Manager Extension Driver (Microsoft)
  2963. volsnap.sys Volume Shadow Copy driver (Microsoft)
  2964. volume.sys Volume driver (Microsoft)
  2965. vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
  2966. wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
  2967. watchdog.sys Watchdog driver (Microsoft)
  2968. wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
  2969. WdBoot.sys Microsoft Antimalware Boot driver
  2970. Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
  2971. WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
  2972. WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
  2973. WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
  2974. werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
  2975. wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
  2976. win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
  2977. win32kbase.sys Base Win32k Kernel Driver (Microsoft)
  2978. win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
  2979. WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
  2980. WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
  2981. winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
  2982. winquic.sys QUIC Transport Protocol driver (Microsoft)
  2983. wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
  2984. WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
  2985. Wof.sys Windows Overlay Filter (Microsoft)
  2986. WppRecorder.sys WPP Trace Recorder (Microsoft)
  2987.  
  2988. ====================== Dump #5: UNLOADED MODULES =======================
  2989.  
  2990. fffff804`34880000 fffff804`349f0000 EasyAntiChea
  2991. fffff804`34200000 fffff804`34211000 MpKslDrv.sys
  2992. fffff804`3eb20000 fffff804`3eb2e000 WSDPrint.sys
  2993. fffff804`34220000 fffff804`34266000 usbaudio2.sy
  2994. fffff804`34280000 fffff804`3428f000 hiber_storpo
  2995. fffff804`34290000 fffff804`34803000 hiber_iaStor
  2996. fffff804`34810000 fffff804`3482e000 hiber_dumpfv
  2997. fffff804`34f60000 fffff804`34fa6000 usbaudio2.sy
  2998. fffff804`34940000 fffff804`34f15000 iqvw64e.sys
  2999. fffff804`3d630000 fffff804`3d63f000 dump_storpor
  3000. fffff804`3e570000 fffff804`3eae3000 dump_iaStorA
  3001. fffff804`3eb10000 fffff804`3eb2e000 dump_dumpfve
  3002. fffff804`3dd40000 fffff804`3dd5e000 dam.sys
  3003.  
  3004. ====================== Dump #5: BIOS INFORMATION =======================
  3005.  
  3006. [SMBIOS Data Tables v2.8]
  3007. [DMI Version - 0]
  3008. [2.0 Calling Convention - No]
  3009. [Table Size - 1735 bytes]
  3010. [BIOS Information (Type 0) - Length 24 - Handle 0000h]
  3011. Vendor American Megatrends Inc.
  3012. BIOS Version P7.50
  3013. BIOS Starting Address Segment f000
  3014. BIOS Release Date 01/23/2018
  3015. BIOS ROM Size e00000
  3016. BIOS Characteristics
  3017. 07: - PCI Supported
  3018. 11: - Upgradeable FLASH BIOS
  3019. 12: - BIOS Shadowing Supported
  3020. 15: - CD-Boot Supported
  3021. 16: - Selectable Boot Supported
  3022. 17: - BIOS ROM Socketed
  3023. 19: - EDD Supported
  3024. 23: - 1.2MB Floppy Supported
  3025. 24: - 720KB Floppy Supported
  3026. 25: - 2.88MB Floppy Supported
  3027. 26: - Print Screen Device Supported
  3028. 27: - Keyboard Services Supported
  3029. 28: - Serial Services Supported
  3030. 29: - Printer Services Supported
  3031. 32: - BIOS Vendor Reserved
  3032. BIOS Characteristic Extensions
  3033. 00: - ACPI Supported
  3034. 01: - USB Legacy Supported
  3035. 08: - BIOS Boot Specification Supported
  3036. 10: - Specification Reserved
  3037. 11: - Specification Reserved
  3038. BIOS Major Revision 5
  3039. BIOS Minor Revision 11
  3040. EC Firmware Major Revision 255
  3041. EC Firmware Minor Revision 255
  3042. [System Information (Type 1) - Length 27 - Handle 0001h]
  3043. UUID 00000000-0000-0000-0000-000000000000
  3044. Wakeup Type Power Switch
  3045. [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
  3046. Manufacturer ASRock
  3047. Product Z170 Pro4S
  3048. Version
  3049. Feature Flags 09h
  3050. -449726752: - -449726704: - ÷7!ü
  3051. Location
  3052. Chassis Handle 0003h
  3053. Board Type 0ah - Processor/Memory Module
  3054. Number of Child Handles 0
  3055. [System Enclosure (Type 3) - Length 25 - Handle 0003h]
  3056. Chassis Type Desktop
  3057. Bootup State Safe
  3058. Power Supply State Safe
  3059. Thermal State Safe
  3060. Security Status None
  3061. OEM Defined 0
  3062. Height 0U
  3063. Number of Power Cords 1
  3064. Number of Contained Elements 1
  3065. Contained Element Size 3
  3066. [OEM Strings (Type 11) - Length 5 - Handle 000ah]
  3067. Number of Strings 1
  3068. [Cache Information (Type 7) - Length 19 - Handle 000dh]
  3069. Socket Designation L1 Cache
  3070. Cache Configuration 0180h - WB Enabled Int NonSocketed L1
  3071. Maximum Cache Size 0080h - 128K
  3072. Installed Size 0080h - 128K
  3073. Supported SRAM Type 0020h - Synchronous
  3074. Current SRAM Type 0020h - Synchronous
  3075. Cache Speed 0ns
  3076. Error Correction Type ParitySingle-Bit ECC
  3077. System Cache Type Data
  3078. Associativity 8-way Set-Associative
  3079. [Cache Information (Type 7) - Length 19 - Handle 000eh]
  3080. Socket Designation L1 Cache
  3081. Cache Configuration 0180h - WB Enabled Int NonSocketed L1
  3082. Maximum Cache Size 0080h - 128K
  3083. Installed Size 0080h - 128K
  3084. Supported SRAM Type 0020h - Synchronous
  3085. Current SRAM Type 0020h - Synchronous
  3086. Cache Speed 0ns
  3087. Error Correction Type ParitySingle-Bit ECC
  3088. System Cache Type Instruction
  3089. Associativity 8-way Set-Associative
  3090. [Cache Information (Type 7) - Length 19 - Handle 000fh]
  3091. Socket Designation L2 Cache
  3092. Cache Configuration 0181h - WB Enabled Int NonSocketed L2
  3093. Maximum Cache Size 0400h - 1024K
  3094. Installed Size 0400h - 1024K
  3095. Supported SRAM Type 0020h - Synchronous
  3096. Current SRAM Type 0020h - Synchronous
  3097. Cache Speed 0ns
  3098. Error Correction Type Multi-Bit ECC
  3099. System Cache Type Unified
  3100. Associativity 4-way Set-Associative
  3101. [Cache Information (Type 7) - Length 19 - Handle 0010h]
  3102. Socket Designation L3 Cache
  3103. Cache Configuration 0182h - WB Enabled Int NonSocketed L3
  3104. Maximum Cache Size 1800h - 6144K
  3105. Installed Size 1800h - 6144K
  3106. Supported SRAM Type 0020h - Synchronous
  3107. Current SRAM Type 0020h - Synchronous
  3108. Cache Speed 0ns
  3109. Error Correction Type Specification Reserved
  3110. System Cache Type Unified
  3111. Associativity Specification Reserved
  3112. [Processor Information (Type 4) - Length 48 - Handle 0011h]
  3113. Socket Designation CPUSocket
  3114. Processor Type Central Processor
  3115. Processor Family cdh - Specification Reserved
  3116. Processor Manufacturer Intel(R) Corporation
  3117. Processor ID e3060500fffbebbf
  3118. Processor Version Intel(R) Core(TM) i5-6600K CPU @ 3.50GHz
  3119. Processor Voltage 8bh - 1.1V
  3120. External Clock 100MHz
  3121. Max Speed 5000MHz
  3122. Current Speed 3500MHz
  3123. Status Enabled Populated
  3124. Processor Upgrade Other
  3125. L1 Cache Handle 000eh
  3126. L2 Cache Handle 000fh
  3127. L3 Cache Handle 0010h
  3128. [Physical Memory Array (Type 16) - Length 23 - Handle 0012h]
  3129. Location 03h - SystemBoard/Motherboard
  3130. Use 03h - System Memory
  3131. Memory Error Correction 03h - None
  3132. Maximum Capacity 67108864KB
  3133. Number of Memory Devices 4
  3134. [Memory Device (Type 17) - Length 40 - Handle 0013h]
  3135. Physical Memory Array Handle 0012h
  3136. Total Width 0 bits
  3137. Data Width 0 bits
  3138. Form Factor 09h - DIMM
  3139. Device Locator ChannelA-DIMM0
  3140. Bank Locator BANK 0
  3141. Memory Type 02h - Unknown
  3142. Type Detail 0000h -
  3143. Speed 0MHz
  3144. [Memory Device (Type 17) - Length 40 - Handle 0014h]
  3145. Physical Memory Array Handle 0012h
  3146. Total Width 64 bits
  3147. Data Width 64 bits
  3148. Size 8192MB
  3149. Form Factor 09h - DIMM
  3150. Device Locator ChannelA-DIMM1
  3151. Bank Locator BANK 1
  3152. Memory Type 1ah - Specification Reserved
  3153. Type Detail 0080h - Synchronous
  3154. Speed 3000MHz
  3155. Manufacturer Kingston
  3156. Part Number KHX3000C15D4/8GX
  3157. [Memory Device (Type 17) - Length 40 - Handle 0015h]
  3158. Physical Memory Array Handle 0012h
  3159. Total Width 0 bits
  3160. Data Width 0 bits
  3161. Form Factor 09h - DIMM
  3162. Device Locator ChannelB-DIMM0
  3163. Bank Locator BANK 2
  3164. Memory Type 02h - Unknown
  3165. Type Detail 0000h -
  3166. Speed 0MHz
  3167. [Memory Device (Type 17) - Length 40 - Handle 0016h]
  3168. Physical Memory Array Handle 0012h
  3169. Total Width 64 bits
  3170. Data Width 64 bits
  3171. Size 8192MB
  3172. Form Factor 09h - DIMM
  3173. Device Locator ChannelB-DIMM1
  3174. Bank Locator BANK 3
  3175. Memory Type 1ah - Specification Reserved
  3176. Type Detail 0080h - Synchronous
  3177. Speed 3000MHz
  3178. Manufacturer Kingston
  3179. Part Number KHX3000C15D4/8GX
  3180. [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0017h]
  3181. Starting Address 00000000h
  3182. Ending Address 00ffffffh
  3183. Memory Array Handle 0012h
  3184. Partition Width 02
  3185. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0018h]
  3186. Starting Address 00000000h
  3187. Ending Address 007fffffh
  3188. Memory Device Handle 0014h
  3189. Mem Array Mapped Adr Handle 0017h
  3190. Partition Row Position 01
  3191. Interleave Position 01
  3192. Interleave Data Depth 02
  3193. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0019h]
  3194. Starting Address 00800000h
  3195. Ending Address 00ffffffh
  3196. Memory Device Handle 0016h
  3197. Mem Array Mapped Adr Handle 0017h
  3198. Partition Row Position 01
  3199. Interleave Position 02
  3200. Interleave Data Depth 02
  3201.  
  3202. ========================== Dump #5: Extra #1 ===========================
  3203.  
  3204. 0: kd> !verifier
  3205. Verify Flags Level 0x00000000
  3206. STANDARD FLAGS:
  3207. [X] (0x00000000) Automatic Checks
  3208. [ ] (0x00000001) Special pool
  3209. [ ] (0x00000002) Force IRQL checking
  3210. [ ] (0x00000008) Pool tracking
  3211. [ ] (0x00000010) I/O verification
  3212. [ ] (0x00000020) Deadlock detection
  3213. [ ] (0x00000080) DMA checking
  3214. [ ] (0x00000100) Security checks
  3215. [ ] (0x00000800) Miscellaneous checks
  3216. [ ] (0x00020000) DDI compliance checking
  3217. ADDITIONAL FLAGS:
  3218. [ ] (0x00000004) Randomized low resources simulation
  3219. [ ] (0x00000200) Force pending I/O requests
  3220. [ ] (0x00000400) IRP logging
  3221. [ ] (0x00002000) Invariant MDL checking for stack
  3222. [ ] (0x00004000) Invariant MDL checking for driver
  3223. [ ] (0x00008000) Power framework delay fuzzing
  3224. [ ] (0x00010000) Port/miniport interface checking
  3225. [ ] (0x00040000) Systematic low resources simulation
  3226. [ ] (0x00080000) DDI compliance checking (additional)
  3227. [ ] (0x00200000) NDIS/WIFI verification
  3228. [ ] (0x00800000) Kernel synchronization delay fuzzing
  3229. [ ] (0x01000000) VM switch verification
  3230. [ ] (0x02000000) Code integrity checks
  3231. [X] Indicates flag is enabled
  3232. Summary of All Verifier Statistics
  3233. RaiseIrqls 0x0
  3234. AcquireSpinLocks 0x0
  3235. Synch Executions 0x0
  3236. Trims 0x0
  3237. Pool Allocations Attempted 0x0
  3238. Pool Allocations Succeeded 0x0
  3239. Pool Allocations Succeeded SpecialPool 0x0
  3240. Pool Allocations With NO TAG 0x0
  3241. Pool Allocations Failed 0x0
  3242. Current paged pool allocations 0x0 for 00000000 bytes
  3243. Peak paged pool allocations 0x0 for 00000000 bytes
  3244. Current nonpaged pool allocations 0x0 for 00000000 bytes
  3245. Peak nonpaged pool allocations 0x0 for 00000000 bytes
  3246.  
  3247. ========================== Dump #5: Extra #2 ===========================
  3248.  
  3249. 0: kd> !thread
  3250. THREAD fffff80436991400 Cid 0000.0000 Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor 0
  3251. Not impersonating
  3252. GetUlongFromAddress: unable to read from fffff8043682ca14
  3253. Owning Process fffff8043698e9c0 Image: System Process
  3254. Attached Process ffffcd024707b080 Image: System
  3255. fffff78000000000: Unable to get shared data
  3256. Wait Start TickCount 6524646 Ticks: 9628
  3257. Context Switch Count 98085951 IdealProcessor: 0
  3258. ReadMemory error: Cannot get nt!KeMaximumIncrement value.
  3259. UserTime 00:00:00.000
  3260. KernelTime 00:00:00.000
  3261. Win32 Start Address nt!KiIdleLoop (0xfffff804365c5e50)
  3262. Stack Init fffff8043d338b90 Current fffff8043d338b20
  3263. Base fffff8043d339000 Limit fffff8043d332000 Call 0000000000000000
  3264. Priority 0 BasePriority 0 PriorityDecrement 0 IoPriority 0 PagePriority 5
  3265. Child-SP RetAddr : Args to Child : Call Site
  3266. fffff804`3d338408 fffff804`365d41e9 : 00000000`0000000a fffff804`3d3186d8 00000000`000000ff 00000000`000000a2 : nt!KeBugCheckEx
  3267. fffff804`3d338410 fffff804`365d0529 : 00000000`00000002 fffff804`364f7d8e 00000000`40cb0088 00000000`00000000 : nt!KiBugCheckDispatch+0x69
  3268. fffff804`3d338550 fffff804`3644adf2 : ffffffff`fffffffe 0000ecb6`39857909 fffff804`3419c180 00000000`00000000 : nt!KiPageFault+0x469 (TrapFrame @ fffff804`3d338550)
  3269. fffff804`3d3386e0 fffff804`3644a36e : 00000000`00000003 00000000`00000002 00000000`00000001 00000000`00000000 : nt!PpmIdleExecuteTransition+0x8e2
  3270. fffff804`3d338a00 fffff804`365c5e94 : 00000000`00000000 fffff804`3419c180 ffffcd02`47a27040 00000000`000005f2 : nt!PoIdle+0x36e
  3271. fffff804`3d338b60 00000000`00000000 : fffff804`3d339000 fffff804`3d332000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x44
  3272.  
  3273.  
  3274. ========================================================================
  3275. ======================= Dump #6: ANALYZE VERBOSE =======================
  3276. ====================== File: 060920-10625-01.dmp =======================
  3277. ========================================================================
  3278.  
  3279. Mini Kernel Dump File: Only registers and stack trace are available
  3280. Windows 10 Kernel Version 18362 MP (4 procs) Free x64
  3281. Kernel base = 0xfffff804`12a00000 PsLoadedModuleList = 0xfffff804`12e48170
  3282. Debug session time: Mon Jun 8 21:00:35.312 2020 (UTC - 4:00)
  3283. System Uptime: 0 days 4:35:23.984
  3284.  
  3285. BugCheck A, {fffff80418d185e0, 2, 1, fffff80412a21050}
  3286. *** WARNING: Unable to verify timestamp for win32k.sys
  3287. *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
  3288. Probably caused by : memory_corruption
  3289. Followup: memory_corruption
  3290.  
  3291. IRQL_NOT_LESS_OR_EQUAL (a)
  3292. An attempt was made to access a pageable (or completely invalid) address at an
  3293. interrupt request level (IRQL) that is too high. This is usually
  3294. caused by drivers using improper addresses.
  3295. If a kernel debugger is available get the stack backtrace.
  3296.  
  3297. Arguments:
  3298. Arg1: fffff80418d185e0, memory referenced
  3299. Arg2: 0000000000000002, IRQL
  3300. Arg3: 0000000000000001, bitfield :
  3301. bit 0 : value 0 = read operation, 1 = write operation
  3302. bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
  3303. Arg4: fffff80412a21050, address which referenced memory
  3304.  
  3305. Debugging Details:
  3306. DUMP_CLASS: 1
  3307. DUMP_QUALIFIER: 400
  3308. DUMP_TYPE: 2
  3309. WRITE_ADDRESS: fffff80412f733b8: Unable to get MiVisibleState
  3310. fffff80418d185e0
  3311. CURRENT_IRQL: 2
  3312. FAULTING_IP:
  3313. nt!KeAcquireSpinLockAtDpcLevel+0
  3314. fffff804`12a21050 4053 push rbx
  3315. CUSTOMER_CRASH_COUNT: 1
  3316. DEFAULT_BUCKET_ID: CODE_CORRUPTION
  3317. BUGCHECK_STR: AV
  3318.  
  3319. PROCESS_NAME: System
  3320.  
  3321. TRAP_FRAME: fffff80418d38450 -- (.trap 0xfffff80418d38450)
  3322. NOTE: The trap frame does not contain all registers.
  3323. Some register values may be zeroed or incorrect.
  3324. rax=fffff80418d38618 rbx=0000000000000000 rcx=ffffe60617422d10
  3325. rdx=ffffe60617dc47c8 rsi=0000000000000000 rdi=0000000000000000
  3326. rip=fffff80412a21050 rsp=fffff80418d385e8 rbp=fffff80418d38602
  3327. r8=0000000000000001 r9=0000000000000000 r10=fffff80412a21050
  3328. r11=ffffe60617499dcc r12=0000000000000000 r13=0000000000000000
  3329. r14=0000000000000000 r15=0000000000000000
  3330. iopl=0 nv up ei pl nz na pe nc
  3331. nt!KeAcquireSpinLockAtDpcLevel:
  3332. fffff804`12a21050 4053 push rbx
  3333. Resetting default scope
  3334. LAST_CONTROL_TRANSFER: from fffff80412bd41e9 to fffff80412bc2390
  3335. STACK_TEXT:
  3336. fffff804`18d38308 fffff804`12bd41e9 : 00000000`0000000a fffff804`18d185e0 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
  3337. fffff804`18d38310 fffff804`12bd0529 : 00000000`00000001 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
  3338. fffff804`18d38450 fffff804`12a21050 : fffff804`1854bee5 fffff804`1859c698 ffffe606`17ba91a0 00000000`0000000e : nt!KiPageFault+0x469
  3339. fffff804`18d385e8 fffff804`1854bee5 : fffff804`1859c698 ffffe606`17ba91a0 00000000`0000000e fffff804`534f5248 : nt!KeAcquireSpinLockAtDpcLevel
  3340. fffff804`18d385f0 fffff804`18570a0d : ffffe606`17dc47c8 fffff804`18d38690 ffffe606`17ba91a0 ffffe606`17dc44a0 : ndis!ndisInsertInWorkQueue+0x3d
  3341. fffff804`18d38620 fffff804`18522b7c : ffffe606`17dc4688 ffffe606`17dc44a0 00000000`ffffffff 00000000`00000000 : ndis!ndisQueueDpcWorkItem+0x171
  3342. fffff804`18d386c0 fffff804`12ac115a : fffff804`0fb58180 00000000`00000001 fffff804`18d387a8 fffff804`12abc05c : ndis!ndisInterruptDpc+0x43a4c
  3343. fffff804`18d387f0 fffff804`12ac07af : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiExecuteAllDpcs+0x30a
  3344. fffff804`18d38930 fffff804`12bc5ebe : 00000000`00000000 fffff804`0fb58180 fffff804`12f91400 ffffe606`1740d680 : nt!KiRetireDpcList+0x1ef
  3345. fffff804`18d38b60 00000000`00000000 : fffff804`18d39000 fffff804`18d32000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x7e
  3346. STACK_COMMAND: kb
  3347. CHKIMG_EXTENSION: !chkimg -lo 50 -d !hal
  3348. fffff8041295f457-fffff8041295f458 2 bytes - hal!HalPutScatterGatherList+67
  3349. [ 48 ff:4c 8b ]
  3350. fffff8041295f45e-fffff8041295f461 4 bytes - hal!HalPutScatterGatherList+6e (+0x07)
  3351. [ 0f 1f 44 00:e8 ad fb 40 ]
  3352. 6 errors : !hal (fffff8041295f457-fffff8041295f461)
  3353. MODULE_NAME: memory_corruption
  3354.  
  3355. IMAGE_NAME: memory_corruption
  3356.  
  3357. FOLLOWUP_NAME: memory_corruption
  3358. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  3359. MEMORY_CORRUPTOR: LARGE
  3360. FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
  3361. BUCKET_ID: MEMORY_CORRUPTION_LARGE
  3362. PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
  3363. TARGET_TIME: 2020-06-09T01:00:35.000Z
  3364. SUITE_MASK: 784
  3365. PRODUCT_TYPE: 1
  3366. USER_LCID: 0
  3367. FAILURE_ID_HASH_STRING: km:memory_corruption_large
  3368. FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
  3369. Followup: memory_corruption
  3370.  
  3371. ====================== Dump #6: 3RD PARTY DRIVERS ======================
  3372.  
  3373. May 10 2011 - AsrAppCharger.sys - ASRock App Charger driver
  3374. Jun 03 2015 - iaStorA.sys - Intel SATA Storage Device RAID Controller
  3375. Jun 23 2015 - RTKVHD64.sys - Realtek Audio System driver https://www.realtek.com/en/
  3376. Apr 11 2018 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
  3377. Jun 11 2018 - e1i65x64.sys - Intel(R) Gigabit Adapter driver
  3378. Feb 19 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
  3379. May 15 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
  3380. May 20 2020 - FACEIT.sys - FACEIT Client https://www.faceit.com/
  3381.  
  3382. ================== Dump #6: 3RD PARTY DRIVERS (FULL) ===================
  3383.  
  3384. Image path: \SystemRoot\system32\DRIVERS\AsrAppCharger.sys
  3385. Image name: AsrAppCharger.sys
  3386. Search : https://www.google.com/search?q=AsrAppCharger.sys
  3387. ADA Info : ASRock App Charger driver
  3388. Timestamp : Tue May 10 2011
  3389.  
  3390. Image path: \SystemRoot\System32\drivers\iaStorA.sys
  3391. Image name: iaStorA.sys
  3392. Search : https://www.google.com/search?q=iaStorA.sys
  3393. ADA Info : Intel SATA Storage Device RAID Controller
  3394. Timestamp : Wed Jun 3 2015
  3395.  
  3396. Image path: \SystemRoot\system32\drivers\RTKVHD64.sys
  3397. Image name: RTKVHD64.sys
  3398. Search : https://www.google.com/search?q=RTKVHD64.sys
  3399. ADA Info : Realtek Audio System driver https://www.realtek.com/en/
  3400. Timestamp : Tue Jun 23 2015
  3401.  
  3402. Image path: \SystemRoot\System32\drivers\TeeDriverW8x64.sys
  3403. Image name: TeeDriverW8x64.sys
  3404. Search : https://www.google.com/search?q=TeeDriverW8x64.sys
  3405. ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
  3406. Timestamp : Wed Apr 11 2018
  3407.  
  3408. Mapped memory image file: C:\ProgramData\dbg\sym\e1i65x64.sys\5B1EB8E28e000\e1i65x64.sys
  3409. Image path: \SystemRoot\System32\drivers\e1i65x64.sys
  3410. Image name: e1i65x64.sys
  3411. Search : https://www.google.com/search?q=e1i65x64.sys
  3412. ADA Info : Intel(R) Gigabit Adapter driver
  3413. Timestamp : Mon Jun 11 2018
  3414. File version: 12.17.10.8
  3415. Product version: 10.0.10011.16384
  3416. File flags: 8 (Mask 3F) Private
  3417. File OS: 40004 NT Win32
  3418. File type: 3.6 Driver
  3419. File date: 00000000.00000000
  3420. CompanyName: Intel Corporation
  3421. ProductName: Intel(R) Gigabit Adapter
  3422. InternalName: e1i65x64.sys
  3423. OriginalFilename: e1i65x64.sys
  3424. ProductVersion: 12.17.10.8
  3425. FileVersion: 12.17.10.8
  3426. FileDescription: Intel(R) Gigabit Adapter NDIS 6.x driver
  3427. LegalCopyright: Copyright(C) 2013, Intel Corporation. All rights reserved.
  3428.  
  3429. Image path: \SystemRoot\system32\drivers\nvhda64v.sys
  3430. Image name: nvhda64v.sys
  3431. Search : https://www.google.com/search?q=nvhda64v.sys
  3432. ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
  3433. Timestamp : Wed Feb 19 2020
  3434.  
  3435. Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d5216eae94436d77\nvlddmkm.sys
  3436. Image name: nvlddmkm.sys
  3437. Search : https://www.google.com/search?q=nvlddmkm.sys
  3438. ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
  3439. Timestamp : Fri May 15 2020
  3440.  
  3441. Image path: \SystemRoot\System32\Drivers\FACEIT.sys
  3442. Image name: FACEIT.sys
  3443. Search : https://www.google.com/search?q=FACEIT.sys
  3444. ADA Info : FACEIT Client https://www.faceit.com/
  3445. Timestamp : Wed May 20 2020
  3446.  
  3447. ====================== Dump #6: MICROSOFT DRIVERS ======================
  3448.  
  3449. ACPI.sys ACPI Driver for NT (Microsoft)
  3450. acpiex.sys ACPIEx Driver (Microsoft)
  3451. acpipagr.sys ACPI Processor Aggregator Device driver (Microsoft)
  3452. afd.sys Ancillary Function Driver for WinSock (Microsoft)
  3453. afunix.sys AF_UNIX Socket Provider driver (Microsoft)
  3454. AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
  3455. ahcache.sys Application Compatibility Cache (Microsoft)
  3456. bam.sys BAM Kernal driver (Microsoft)
  3457. BasicDisplay.sys Basic Display driver (Microsoft)
  3458. BasicRender.sys Basic Render driver (Microsoft)
  3459. Beep.SYS BEEP driver (Microsoft)
  3460. bindflt.sys Windows Bind Filter driver (Microsoft)
  3461. BOOTVID.dll VGA Boot Driver (Microsoft)
  3462. bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
  3463. cdd.dll Canonical Display Driver (Microsoft)
  3464. cdrom.sys SCSI CD-ROM Driver (Microsoft)
  3465. CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
  3466. CI.dll Code Integrity Module (Microsoft)
  3467. CLASSPNP.SYS SCSI Class System Dll (Microsoft)
  3468. cldflt.sys Cloud Files Mini Filter driver (Microsoft)
  3469. CLFS.SYS Common Log File System Driver (Microsoft)
  3470. clipsp.sys CLIP Service (Microsoft)
  3471. cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
  3472. cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
  3473. CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
  3474. condrv.sys Console Driver (Microsoft)
  3475. crashdmp.sys Crash Dump driver (Microsoft)
  3476. dfsc.sys DFS Namespace Client Driver (Microsoft)
  3477. disk.sys PnP Disk Driver (Microsoft)
  3478. drmk.sys Digital Rights Management (DRM) driver (Microsoft)
  3479. dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  3480. dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  3481. dump_iaStorA.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  3482. dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
  3483. dxgmms2.sys DirectX Graphics MMS
  3484. EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
  3485. filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
  3486. fileinfo.sys FileInfo Filter Driver (Microsoft)
  3487. FLTMGR.SYS Filesystem Filter Manager (Microsoft)
  3488. Fs_Rec.sys File System Recognizer Driver (Microsoft)
  3489. fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
  3490. fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
  3491. gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
  3492. hal.dll Hardware Abstraction Layer DLL (Microsoft)
  3493. HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
  3494. HIDCLASS.SYS Hid Class Library (Microsoft)
  3495. HIDPARSE.SYS Hid Parsing Library (Microsoft)
  3496. hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
  3497. HTTP.sys HTTP Protocol Stack (Microsoft)
  3498. hwpolicy.sys Hardware Policy Driver
  3499. intelpep.sys Intel Power Engine Plugin (Microsoft)
  3500. intelppm.sys Processor Device Driver (Microsoft)
  3501. iorate.sys I/O rate control Filter (Microsoft)
  3502. kbdclass.sys Keyboard Class Driver (Microsoft)
  3503. kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
  3504. kd.dll Local Kernal Debugger (Microsoft)
  3505. kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
  3506. ks.sys Kernal CSA Library (Microsoft)
  3507. ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
  3508. ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
  3509. ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
  3510. lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
  3511. luafv.sys LUA File Virtualization Filter Driver (Microsoft)
  3512. mcupdate_GenuineIntel.dll Intel Microcode Update Library (Microsoft)
  3513. mmcss.sys MMCSS Driver (Microsoft)
  3514. monitor.sys Monitor Driver (Microsoft)
  3515. mouclass.sys Mouse Class Driver (Microsoft)
  3516. mouhid.sys HID Mouse Filter Driver (Microsoft)
  3517. mountmgr.sys Mount Point Manager (Microsoft)
  3518. mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
  3519. mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
  3520. mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
  3521. Msfs.SYS Mailslot driver (Microsoft)
  3522. msisadrv.sys ISA Driver (Microsoft)
  3523. mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
  3524. msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
  3525. mssmbios.sys System Management BIOS driver (Microsoft)
  3526. mup.sys Multiple UNC Provider driver (Microsoft)
  3527. ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
  3528. ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
  3529. NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
  3530. ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
  3531. NDProxy.sys NDIS Proxy driver (Microsoft)
  3532. Ndu.sys Network Data Usage Monitoring driver (Microsoft)
  3533. netbios.sys NetBIOS Interface driver (Microsoft)
  3534. netbt.sys MBT Transport driver (Microsoft)
  3535. NETIO.SYS Network I/O Subsystem (Microsoft)
  3536. Npfs.SYS NPFS driver (Microsoft)
  3537. npsvctrig.sys Named pipe service triggers (Microsoft)
  3538. nsiproxy.sys NSI Proxy driver (Microsoft)
  3539. Ntfs.sys NT File System Driver (Microsoft)
  3540. ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
  3541. ntosext.sys NTOS Extension Host driver (Microsoft)
  3542. Null.SYS NULL Driver (Microsoft)
  3543. pacer.sys QoS Packet Scheduler (Microsoft)
  3544. partmgr.sys Partition driver (Microsoft)
  3545. pci.sys NT Plug and Play PCI Enumerator (Microsoft)
  3546. pcw.sys Performance Counter Driver (Microsoft)
  3547. pdc.sys Power Dependency Coordinator Driver (Microsoft)
  3548. peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
  3549. portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
  3550. PSHED.dll Platform Specific Hardware Error driver (Microsoft)
  3551. rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
  3552. raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
  3553. raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
  3554. rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
  3555. rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
  3556. rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
  3557. rdyboost.sys ReadyBoost Driver (Microsoft)
  3558. rspndr.sys Link-Layer Topology Responder driver (Microsoft)
  3559. serenum.sys Serial Port Enumerator (Microsoft)
  3560. serial.sys Serial Device Driver
  3561. SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
  3562. SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
  3563. spaceport.sys Storage Spaces driver (Microsoft)
  3564. srv2.sys Smb 2.0 Server driver (Microsoft)
  3565. srvnet.sys Server Network driver (Microsoft)
  3566. storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
  3567. storqosflt.sys Storage QoS Filter driver (Microsoft)
  3568. swenum.sys Plug and Play Software Device Enumerator (Microsoft)
  3569. tbs.sys Export driver for kernel mode TPM API (Microsoft)
  3570. tcpip.sys TCP/IP Protocol driver (Microsoft)
  3571. tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
  3572. TDI.SYS TDI Wrapper driver (Microsoft)
  3573. tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
  3574. tm.sys Kernel Transaction Manager driver (Microsoft)
  3575. ucx01000.sys USB Controller Extension (Microsoft)
  3576. umbus.sys User-Mode Bus Enumerator (Microsoft)
  3577. usbaudio2.sys Microsoft USB Audio Class 2.0 Driver
  3578. usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
  3579. USBD.SYS Universal Serial Bus Driver (Microsoft)
  3580. UsbHub3.sys USB3 HUB driver (Microsoft)
  3581. USBXHCI.SYS USB XHCI driver (Microsoft)
  3582. vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
  3583. Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
  3584. volmgr.sys Volume Manager Driver (Microsoft)
  3585. volmgrx.sys Volume Manager Extension Driver (Microsoft)
  3586. volsnap.sys Volume Shadow Copy driver (Microsoft)
  3587. volume.sys Volume driver (Microsoft)
  3588. vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
  3589. wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
  3590. watchdog.sys Watchdog driver (Microsoft)
  3591. wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
  3592. WdBoot.sys Microsoft Antimalware Boot driver
  3593. Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
  3594. WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
  3595. WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
  3596. WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
  3597. werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
  3598. wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
  3599. win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
  3600. win32kbase.sys Base Win32k Kernel Driver (Microsoft)
  3601. win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
  3602. WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
  3603. WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
  3604. winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
  3605. winquic.sys QUIC Transport Protocol driver (Microsoft)
  3606. wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
  3607. WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
  3608. Wof.sys Windows Overlay Filter (Microsoft)
  3609. WppRecorder.sys WPP Trace Recorder (Microsoft)
  3610. WSDPrint.sys Web Services Print Device driver (Microsoft)
  3611.  
  3612. ====================== Dump #6: UNLOADED MODULES =======================
  3613.  
  3614. fffff804`193d0000 fffff804`193df000 dump_storpor
  3615. fffff804`19a00000 fffff804`19f73000 dump_iaStorA
  3616. fffff804`19fa0000 fffff804`19fbe000 dump_dumpfve
  3617. fffff804`1a770000 fffff804`1a78e000 dam.sys
  3618.  
  3619. ====================== Dump #6: BIOS INFORMATION =======================
  3620.  
  3621. [SMBIOS Data Tables v2.8]
  3622. [DMI Version - 0]
  3623. [2.0 Calling Convention - No]
  3624. [Table Size - 1735 bytes]
  3625. [BIOS Information (Type 0) - Length 24 - Handle 0000h]
  3626. Vendor American Megatrends Inc.
  3627. BIOS Version P7.50
  3628. BIOS Starting Address Segment f000
  3629. BIOS Release Date 01/23/2018
  3630. BIOS ROM Size e00000
  3631. BIOS Characteristics
  3632. 07: - PCI Supported
  3633. 11: - Upgradeable FLASH BIOS
  3634. 12: - BIOS Shadowing Supported
  3635. 15: - CD-Boot Supported
  3636. 16: - Selectable Boot Supported
  3637. 17: - BIOS ROM Socketed
  3638. 19: - EDD Supported
  3639. 23: - 1.2MB Floppy Supported
  3640. 24: - 720KB Floppy Supported
  3641. 25: - 2.88MB Floppy Supported
  3642. 26: - Print Screen Device Supported
  3643. 27: - Keyboard Services Supported
  3644. 28: - Serial Services Supported
  3645. 29: - Printer Services Supported
  3646. 32: - BIOS Vendor Reserved
  3647. BIOS Characteristic Extensions
  3648. 00: - ACPI Supported
  3649. 01: - USB Legacy Supported
  3650. 08: - BIOS Boot Specification Supported
  3651. 10: - Specification Reserved
  3652. 11: - Specification Reserved
  3653. BIOS Major Revision 5
  3654. BIOS Minor Revision 11
  3655. EC Firmware Major Revision 255
  3656. EC Firmware Minor Revision 255
  3657. [System Information (Type 1) - Length 27 - Handle 0001h]
  3658. UUID 00000000-0000-0000-0000-000000000000
  3659. Wakeup Type Power Switch
  3660. [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
  3661. Manufacturer ASRock
  3662. Product Z170 Pro4S
  3663. Version
  3664. Feature Flags 09h
  3665. -449726752: - -449726704: - ÷7!ü
  3666. Location
  3667. Chassis Handle 0003h
  3668. Board Type 0ah - Processor/Memory Module
  3669. Number of Child Handles 0
  3670. [System Enclosure (Type 3) - Length 25 - Handle 0003h]
  3671. Chassis Type Desktop
  3672. Bootup State Safe
  3673. Power Supply State Safe
  3674. Thermal State Safe
  3675. Security Status None
  3676. OEM Defined 0
  3677. Height 0U
  3678. Number of Power Cords 1
  3679. Number of Contained Elements 1
  3680. Contained Element Size 3
  3681. [OEM Strings (Type 11) - Length 5 - Handle 000ah]
  3682. Number of Strings 1
  3683. [Cache Information (Type 7) - Length 19 - Handle 000dh]
  3684. Socket Designation L1 Cache
  3685. Cache Configuration 0180h - WB Enabled Int NonSocketed L1
  3686. Maximum Cache Size 0080h - 128K
  3687. Installed Size 0080h - 128K
  3688. Supported SRAM Type 0020h - Synchronous
  3689. Current SRAM Type 0020h - Synchronous
  3690. Cache Speed 0ns
  3691. Error Correction Type ParitySingle-Bit ECC
  3692. System Cache Type Data
  3693. Associativity 8-way Set-Associative
  3694. [Cache Information (Type 7) - Length 19 - Handle 000eh]
  3695. Socket Designation L1 Cache
  3696. Cache Configuration 0180h - WB Enabled Int NonSocketed L1
  3697. Maximum Cache Size 0080h - 128K
  3698. Installed Size 0080h - 128K
  3699. Supported SRAM Type 0020h - Synchronous
  3700. Current SRAM Type 0020h - Synchronous
  3701. Cache Speed 0ns
  3702. Error Correction Type ParitySingle-Bit ECC
  3703. System Cache Type Instruction
  3704. Associativity 8-way Set-Associative
  3705. [Cache Information (Type 7) - Length 19 - Handle 000fh]
  3706. Socket Designation L2 Cache
  3707. Cache Configuration 0181h - WB Enabled Int NonSocketed L2
  3708. Maximum Cache Size 0400h - 1024K
  3709. Installed Size 0400h - 1024K
  3710. Supported SRAM Type 0020h - Synchronous
  3711. Current SRAM Type 0020h - Synchronous
  3712. Cache Speed 0ns
  3713. Error Correction Type Multi-Bit ECC
  3714. System Cache Type Unified
  3715. Associativity 4-way Set-Associative
  3716. [Cache Information (Type 7) - Length 19 - Handle 0010h]
  3717. Socket Designation L3 Cache
  3718. Cache Configuration 0182h - WB Enabled Int NonSocketed L3
  3719. Maximum Cache Size 1800h - 6144K
  3720. Installed Size 1800h - 6144K
  3721. Supported SRAM Type 0020h - Synchronous
  3722. Current SRAM Type 0020h - Synchronous
  3723. Cache Speed 0ns
  3724. Error Correction Type Specification Reserved
  3725. System Cache Type Unified
  3726. Associativity Specification Reserved
  3727. [Processor Information (Type 4) - Length 48 - Handle 0011h]
  3728. Socket Designation CPUSocket
  3729. Processor Type Central Processor
  3730. Processor Family cdh - Specification Reserved
  3731. Processor Manufacturer Intel(R) Corporation
  3732. Processor ID e3060500fffbebbf
  3733. Processor Version Intel(R) Core(TM) i5-6600K CPU @ 3.50GHz
  3734. Processor Voltage 8bh - 1.1V
  3735. External Clock 100MHz
  3736. Max Speed 5000MHz
  3737. Current Speed 3500MHz
  3738. Status Enabled Populated
  3739. Processor Upgrade Other
  3740. L1 Cache Handle 000eh
  3741. L2 Cache Handle 000fh
  3742. L3 Cache Handle 0010h
  3743. [Physical Memory Array (Type 16) - Length 23 - Handle 0012h]
  3744. Location 03h - SystemBoard/Motherboard
  3745. Use 03h - System Memory
  3746. Memory Error Correction 03h - None
  3747. Maximum Capacity 67108864KB
  3748. Number of Memory Devices 4
  3749. [Memory Device (Type 17) - Length 40 - Handle 0013h]
  3750. Physical Memory Array Handle 0012h
  3751. Total Width 0 bits
  3752. Data Width 0 bits
  3753. Form Factor 09h - DIMM
  3754. Device Locator ChannelA-DIMM0
  3755. Bank Locator BANK 0
  3756. Memory Type 02h - Unknown
  3757. Type Detail 0000h -
  3758. Speed 0MHz
  3759. [Memory Device (Type 17) - Length 40 - Handle 0014h]
  3760. Physical Memory Array Handle 0012h
  3761. Total Width 64 bits
  3762. Data Width 64 bits
  3763. Size 8192MB
  3764. Form Factor 09h - DIMM
  3765. Device Locator ChannelA-DIMM1
  3766. Bank Locator BANK 1
  3767. Memory Type 1ah - Specification Reserved
  3768. Type Detail 0080h - Synchronous
  3769. Speed 3000MHz
  3770. Manufacturer Kingston
  3771. Part Number KHX3000C15D4/8GX
  3772. [Memory Device (Type 17) - Length 40 - Handle 0015h]
  3773. Physical Memory Array Handle 0012h
  3774. Total Width 0 bits
  3775. Data Width 0 bits
  3776. Form Factor 09h - DIMM
  3777. Device Locator ChannelB-DIMM0
  3778. Bank Locator BANK 2
  3779. Memory Type 02h - Unknown
  3780. Type Detail 0000h -
  3781. Speed 0MHz
  3782. [Memory Device (Type 17) - Length 40 - Handle 0016h]
  3783. Physical Memory Array Handle 0012h
  3784. Total Width 64 bits
  3785. Data Width 64 bits
  3786. Size 8192MB
  3787. Form Factor 09h - DIMM
  3788. Device Locator ChannelB-DIMM1
  3789. Bank Locator BANK 3
  3790. Memory Type 1ah - Specification Reserved
  3791. Type Detail 0080h - Synchronous
  3792. Speed 3000MHz
  3793. Manufacturer Kingston
  3794. Part Number KHX3000C15D4/8GX
  3795. [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0017h]
  3796. Starting Address 00000000h
  3797. Ending Address 00ffffffh
  3798. Memory Array Handle 0012h
  3799. Partition Width 02
  3800. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0018h]
  3801. Starting Address 00000000h
  3802. Ending Address 007fffffh
  3803. Memory Device Handle 0014h
  3804. Mem Array Mapped Adr Handle 0017h
  3805. Partition Row Position 01
  3806. Interleave Position 01
  3807. Interleave Data Depth 02
  3808. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0019h]
  3809. Starting Address 00800000h
  3810. Ending Address 00ffffffh
  3811. Memory Device Handle 0016h
  3812. Mem Array Mapped Adr Handle 0017h
  3813. Partition Row Position 01
  3814. Interleave Position 02
  3815. Interleave Data Depth 02
  3816.  
  3817. ========================== Dump #6: Extra #1 ===========================
  3818.  
  3819. 0: kd> !verifier
  3820. Verify Flags Level 0x00000000
  3821. STANDARD FLAGS:
  3822. [X] (0x00000000) Automatic Checks
  3823. [ ] (0x00000001) Special pool
  3824. [ ] (0x00000002) Force IRQL checking
  3825. [ ] (0x00000008) Pool tracking
  3826. [ ] (0x00000010) I/O verification
  3827. [ ] (0x00000020) Deadlock detection
  3828. [ ] (0x00000080) DMA checking
  3829. [ ] (0x00000100) Security checks
  3830. [ ] (0x00000800) Miscellaneous checks
  3831. [ ] (0x00020000) DDI compliance checking
  3832. ADDITIONAL FLAGS:
  3833. [ ] (0x00000004) Randomized low resources simulation
  3834. [ ] (0x00000200) Force pending I/O requests
  3835. [ ] (0x00000400) IRP logging
  3836. [ ] (0x00002000) Invariant MDL checking for stack
  3837. [ ] (0x00004000) Invariant MDL checking for driver
  3838. [ ] (0x00008000) Power framework delay fuzzing
  3839. [ ] (0x00010000) Port/miniport interface checking
  3840. [ ] (0x00040000) Systematic low resources simulation
  3841. [ ] (0x00080000) DDI compliance checking (additional)
  3842. [ ] (0x00200000) NDIS/WIFI verification
  3843. [ ] (0x00800000) Kernel synchronization delay fuzzing
  3844. [ ] (0x01000000) VM switch verification
  3845. [ ] (0x02000000) Code integrity checks
  3846. [X] Indicates flag is enabled
  3847. Summary of All Verifier Statistics
  3848. RaiseIrqls 0x0
  3849. AcquireSpinLocks 0x0
  3850. Synch Executions 0x0
  3851. Trims 0x0
  3852. Pool Allocations Attempted 0x0
  3853. Pool Allocations Succeeded 0x0
  3854. Pool Allocations Succeeded SpecialPool 0x0
  3855. Pool Allocations With NO TAG 0x0
  3856. Pool Allocations Failed 0x0
  3857. Current paged pool allocations 0x0 for 00000000 bytes
  3858. Peak paged pool allocations 0x0 for 00000000 bytes
  3859. Current nonpaged pool allocations 0x0 for 00000000 bytes
  3860. Peak nonpaged pool allocations 0x0 for 00000000 bytes
  3861.  
  3862. ========================== Dump #6: Extra #2 ===========================
  3863.  
  3864. 0: kd> !thread
  3865. THREAD fffff80412f91400 Cid 0000.0000 Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor 0
  3866. Not impersonating
  3867. GetUlongFromAddress: unable to read from fffff80412e2ca24
  3868. Owning Process fffff80412f8e9c0 Image: System Process
  3869. Attached Process ffffe60615a7b080 Image: System
  3870. fffff78000000000: Unable to get shared data
  3871. Wait Start TickCount 1057533 Ticks: 2
  3872. Context Switch Count 59910247 IdealProcessor: 0
  3873. ReadMemory error: Cannot get nt!KeMaximumIncrement value.
  3874. UserTime 00:00:00.000
  3875. KernelTime 00:00:00.000
  3876. Win32 Start Address nt!KiIdleLoop (0xfffff80412bc5e40)
  3877. Stack Init fffff80418d38b90 Current fffff80418d38b20
  3878. Base fffff80418d39000 Limit fffff80418d32000 Call 0000000000000000
  3879. Priority 0 BasePriority 0 PriorityDecrement 0 IoPriority 0 PagePriority 5
  3880. Child-SP RetAddr : Args to Child : Call Site
  3881. fffff804`18d38308 fffff804`12bd41e9 : 00000000`0000000a fffff804`18d185e0 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
  3882. fffff804`18d38310 fffff804`12bd0529 : 00000000`00000001 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
  3883. fffff804`18d38450 fffff804`12a21050 : fffff804`1854bee5 fffff804`1859c698 ffffe606`17ba91a0 00000000`0000000e : nt!KiPageFault+0x469 (TrapFrame @ fffff804`18d38450)
  3884. fffff804`18d385e8 fffff804`1854bee5 : fffff804`1859c698 ffffe606`17ba91a0 00000000`0000000e fffff804`534f5248 : nt!KeAcquireSpinLockAtDpcLevel
  3885. fffff804`18d385f0 fffff804`18570a0d : ffffe606`17dc47c8 fffff804`18d38690 ffffe606`17ba91a0 ffffe606`17dc44a0 : ndis!ndisInsertInWorkQueue+0x3d
  3886. fffff804`18d38620 fffff804`18522b7c : ffffe606`17dc4688 ffffe606`17dc44a0 00000000`ffffffff 00000000`00000000 : ndis!ndisQueueDpcWorkItem+0x171
  3887. fffff804`18d386c0 fffff804`12ac115a : fffff804`0fb58180 00000000`00000001 fffff804`18d387a8 fffff804`12abc05c : ndis!ndisInterruptDpc+0x43a4c
  3888. fffff804`18d387f0 fffff804`12ac07af : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiExecuteAllDpcs+0x30a
  3889. fffff804`18d38930 fffff804`12bc5ebe : 00000000`00000000 fffff804`0fb58180 fffff804`12f91400 ffffe606`1740d680 : nt!KiRetireDpcList+0x1ef
  3890. fffff804`18d38b60 00000000`00000000 : fffff804`18d39000 fffff804`18d32000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x7e
  3891.  
  3892.  
  3893. ========================================================================
  3894. ======================= Dump #7: ANALYZE VERBOSE =======================
  3895. ======================= File: 060520-8250-01.dmp =======================
  3896. ========================================================================
  3897.  
  3898. Mini Kernel Dump File: Only registers and stack trace are available
  3899. Windows 10 Kernel Version 18362 MP (4 procs) Free x64
  3900. Kernel base = 0xfffff802`1ee00000 PsLoadedModuleList = 0xfffff802`1f248170
  3901. Debug session time: Thu Jun 4 18:21:55.916 2020 (UTC - 4:00)
  3902. System Uptime: 3 days 1:07:30.587
  3903.  
  3904. BugCheck A, {fffff802255186d8, ff, 53, fffff8021eebb862}
  3905. *** WARNING: Unable to verify timestamp for win32k.sys
  3906. *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
  3907. Probably caused by : memory_corruption
  3908. Followup: memory_corruption
  3909.  
  3910. IRQL_NOT_LESS_OR_EQUAL (a)
  3911. An attempt was made to access a pageable (or completely invalid) address at an
  3912. interrupt request level (IRQL) that is too high. This is usually
  3913. caused by drivers using improper addresses.
  3914. If a kernel debugger is available get the stack backtrace.
  3915.  
  3916. Arguments:
  3917. Arg1: fffff802255186d8, memory referenced
  3918. Arg2: 00000000000000ff, IRQL
  3919. Arg3: 0000000000000053, bitfield :
  3920. bit 0 : value 0 = read operation, 1 = write operation
  3921. bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
  3922. Arg4: fffff8021eebb862, address which referenced memory
  3923.  
  3924. Debugging Details:
  3925. DUMP_CLASS: 1
  3926. DUMP_QUALIFIER: 400
  3927. DUMP_TYPE: 2
  3928. WRITE_ADDRESS: fffff8021f3733b8: Unable to get MiVisibleState
  3929. fffff802255186d8
  3930. CURRENT_IRQL: 0
  3931. FAULTING_IP:
  3932. nt!PpmIdleExecuteTransition+8e2
  3933. fffff802`1eebb862 e8090a0000 call nt!KeAccumulateTicks (fffff802`1eebc270)
  3934. CUSTOMER_CRASH_COUNT: 1
  3935. DEFAULT_BUCKET_ID: CODE_CORRUPTION
  3936. BUGCHECK_STR: AV
  3937.  
  3938. PROCESS_NAME: System
  3939.  
  3940. TRAP_FRAME: fffff80225538550 -- (.trap 0xfffff80225538550)
  3941. NOTE: The trap frame does not contain all registers.
  3942. Some register values may be zeroed or incorrect.
  3943. rax=fffff78000000320 rbx=0000000000000000 rcx=fffff8021cc3a180
  3944. rdx=00000000010114a5 rsi=0000000000000000 rdi=0000000000000000
  3945. rip=fffff8021eebb862 rsp=fffff802255386e0 rbp=ffffe689845a2000
  3946. r8=00000000010114a5 r9=0000000000000000 r10=fffff8021ed5f3d0
  3947. r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
  3948. r14=0000000000000000 r15=0000000000000000
  3949. iopl=0 nv up di pl zr na po nc
  3950. nt!PpmIdleExecuteTransition+0x8e2:
  3951. fffff802`1eebb862 e8090a0000 call nt!KeAccumulateTicks (fffff802`1eebc270)
  3952. Resetting default scope
  3953. LAST_CONTROL_TRANSFER: from fffff8021efd41e9 to fffff8021efc2390
  3954. STACK_TEXT:
  3955. fffff802`25538408 fffff802`1efd41e9 : 00000000`0000000a fffff802`255186d8 00000000`000000ff 00000000`00000053 : nt!KeBugCheckEx
  3956. fffff802`25538410 fffff802`1efd0529 : 00000000`00000000 ffffe689`8453a010 fffff802`255386b0 fffff802`293fbc07 : nt!KiBugCheckDispatch+0x69
  3957. fffff802`25538550 fffff802`1eebb862 : 00000000`00000001 000245bb`92ea2879 fffff802`1cc3a180 00000000`00000000 : nt!KiPageFault+0x469
  3958. fffff802`255386e0 fffff802`1eebadde : 00000000`00000003 00000000`00000002 ffffe689`845a20f0 00000000`00000008 : nt!PpmIdleExecuteTransition+0x8e2
  3959. fffff802`25538a00 fffff802`1efc5e84 : 00000000`00000000 fffff802`1cc3a180 ffffe689`7ed3e080 00000000`000002be : nt!PoIdle+0x36e
  3960. fffff802`25538b60 00000000`00000000 : fffff802`25539000 fffff802`25532000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x44
  3961. STACK_COMMAND: kb
  3962. CHKIMG_EXTENSION: !chkimg -lo 50 -d !hal
  3963. fffff8021ed5f457-fffff8021ed5f458 2 bytes - hal!HalPutScatterGatherList+67
  3964. [ 48 ff:4c 8b ]
  3965. fffff8021ed5f45e-fffff8021ed5f461 4 bytes - hal!HalPutScatterGatherList+6e (+0x07)
  3966. [ 0f 1f 44 00:e8 ad fb 40 ]
  3967. 6 errors : !hal (fffff8021ed5f457-fffff8021ed5f461)
  3968. MODULE_NAME: memory_corruption
  3969.  
  3970. IMAGE_NAME: memory_corruption
  3971.  
  3972. FOLLOWUP_NAME: memory_corruption
  3973. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  3974. MEMORY_CORRUPTOR: LARGE
  3975. FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
  3976. BUCKET_ID: MEMORY_CORRUPTION_LARGE
  3977. PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
  3978. TARGET_TIME: 2020-06-04T22:21:55.000Z
  3979. SUITE_MASK: 784
  3980. PRODUCT_TYPE: 1
  3981. USER_LCID: 0
  3982. FAILURE_ID_HASH_STRING: km:memory_corruption_large
  3983. FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
  3984. Followup: memory_corruption
  3985.  
  3986. ====================== Dump #7: 3RD PARTY DRIVERS ======================
  3987.  
  3988. May 10 2011 - AsrAppCharger.sys - ASRock App Charger driver
  3989. Jun 03 2015 - iaStorA.sys - Intel SATA Storage Device RAID Controller
  3990. Jun 23 2015 - RTKVHD64.sys - Realtek Audio System driver https://www.realtek.com/en/
  3991. Apr 11 2018 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
  3992. Jun 11 2018 - e1i65x64.sys - Intel(R) Gigabit Adapter driver
  3993. Feb 19 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
  3994. May 15 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
  3995. May 20 2020 - FACEIT.sys - FACEIT Client https://www.faceit.com/
  3996. May 21 2020 - EasyAntiCheat.sys - EasyAntiCheat is a anti-cheat driver (EasyAntiCheat Oy.) https://support.easyanticheat.net/
  3997.  
  3998. ================== Dump #7: 3RD PARTY DRIVERS (FULL) ===================
  3999.  
  4000. Image path: \SystemRoot\system32\DRIVERS\AsrAppCharger.sys
  4001. Image name: AsrAppCharger.sys
  4002. Search : https://www.google.com/search?q=AsrAppCharger.sys
  4003. ADA Info : ASRock App Charger driver
  4004. Timestamp : Tue May 10 2011
  4005.  
  4006. Image path: \SystemRoot\System32\drivers\iaStorA.sys
  4007. Image name: iaStorA.sys
  4008. Search : https://www.google.com/search?q=iaStorA.sys
  4009. ADA Info : Intel SATA Storage Device RAID Controller
  4010. Timestamp : Wed Jun 3 2015
  4011.  
  4012. Image path: \SystemRoot\system32\drivers\RTKVHD64.sys
  4013. Image name: RTKVHD64.sys
  4014. Search : https://www.google.com/search?q=RTKVHD64.sys
  4015. ADA Info : Realtek Audio System driver https://www.realtek.com/en/
  4016. Timestamp : Tue Jun 23 2015
  4017.  
  4018. Image path: \SystemRoot\System32\drivers\TeeDriverW8x64.sys
  4019. Image name: TeeDriverW8x64.sys
  4020. Search : https://www.google.com/search?q=TeeDriverW8x64.sys
  4021. ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
  4022. Timestamp : Wed Apr 11 2018
  4023.  
  4024. Mapped memory image file: C:\ProgramData\dbg\sym\e1i65x64.sys\5B1EB8E28e000\e1i65x64.sys
  4025. Image path: \SystemRoot\System32\drivers\e1i65x64.sys
  4026. Image name: e1i65x64.sys
  4027. Search : https://www.google.com/search?q=e1i65x64.sys
  4028. ADA Info : Intel(R) Gigabit Adapter driver
  4029. Timestamp : Mon Jun 11 2018
  4030. File version: 12.17.10.8
  4031. Product version: 10.0.10011.16384
  4032. File flags: 8 (Mask 3F) Private
  4033. File OS: 40004 NT Win32
  4034. File type: 3.6 Driver
  4035. File date: 00000000.00000000
  4036. CompanyName: Intel Corporation
  4037. ProductName: Intel(R) Gigabit Adapter
  4038. InternalName: e1i65x64.sys
  4039. OriginalFilename: e1i65x64.sys
  4040. ProductVersion: 12.17.10.8
  4041. FileVersion: 12.17.10.8
  4042. FileDescription: Intel(R) Gigabit Adapter NDIS 6.x driver
  4043. LegalCopyright: Copyright(C) 2013, Intel Corporation. All rights reserved.
  4044.  
  4045. Image path: \SystemRoot\system32\drivers\nvhda64v.sys
  4046. Image name: nvhda64v.sys
  4047. Search : https://www.google.com/search?q=nvhda64v.sys
  4048. ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
  4049. Timestamp : Wed Feb 19 2020
  4050.  
  4051. Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d5216eae94436d77\nvlddmkm.sys
  4052. Image name: nvlddmkm.sys
  4053. Search : https://www.google.com/search?q=nvlddmkm.sys
  4054. ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
  4055. Timestamp : Fri May 15 2020
  4056.  
  4057. Image path: \SystemRoot\System32\Drivers\FACEIT.sys
  4058. Image name: FACEIT.sys
  4059. Search : https://www.google.com/search?q=FACEIT.sys
  4060. ADA Info : FACEIT Client https://www.faceit.com/
  4061. Timestamp : Wed May 20 2020
  4062.  
  4063. Image path: \??\C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys
  4064. Image name: EasyAntiCheat.sys
  4065. Search : https://www.google.com/search?q=EasyAntiCheat.sys
  4066. ADA Info : EasyAntiCheat is a anti-cheat driver (EasyAntiCheat Oy.) https://support.easyanticheat.net/
  4067. Timestamp : Thu May 21 2020
  4068.  
  4069. ====================== Dump #7: MICROSOFT DRIVERS ======================
  4070.  
  4071. ACPI.sys ACPI Driver for NT (Microsoft)
  4072. acpiex.sys ACPIEx Driver (Microsoft)
  4073. acpipagr.sys ACPI Processor Aggregator Device driver (Microsoft)
  4074. afd.sys Ancillary Function Driver for WinSock (Microsoft)
  4075. afunix.sys AF_UNIX Socket Provider driver (Microsoft)
  4076. AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
  4077. ahcache.sys Application Compatibility Cache (Microsoft)
  4078. bam.sys BAM Kernal driver (Microsoft)
  4079. BasicDisplay.sys Basic Display driver (Microsoft)
  4080. BasicRender.sys Basic Render driver (Microsoft)
  4081. Beep.SYS BEEP driver (Microsoft)
  4082. bindflt.sys Windows Bind Filter driver (Microsoft)
  4083. BOOTVID.dll VGA Boot Driver (Microsoft)
  4084. bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
  4085. cdd.dll Canonical Display Driver (Microsoft)
  4086. cdrom.sys SCSI CD-ROM Driver (Microsoft)
  4087. CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
  4088. CI.dll Code Integrity Module (Microsoft)
  4089. CLASSPNP.SYS SCSI Class System Dll (Microsoft)
  4090. cldflt.sys Cloud Files Mini Filter driver (Microsoft)
  4091. CLFS.SYS Common Log File System Driver (Microsoft)
  4092. clipsp.sys CLIP Service (Microsoft)
  4093. cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
  4094. cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
  4095. CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
  4096. condrv.sys Console Driver (Microsoft)
  4097. crashdmp.sys Crash Dump driver (Microsoft)
  4098. dfsc.sys DFS Namespace Client Driver (Microsoft)
  4099. disk.sys PnP Disk Driver (Microsoft)
  4100. drmk.sys Digital Rights Management (DRM) driver (Microsoft)
  4101. dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  4102. dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  4103. dump_iaStorA.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  4104. dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
  4105. dxgmms2.sys DirectX Graphics MMS
  4106. EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
  4107. filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
  4108. fileinfo.sys FileInfo Filter Driver (Microsoft)
  4109. FLTMGR.SYS Filesystem Filter Manager (Microsoft)
  4110. Fs_Rec.sys File System Recognizer Driver (Microsoft)
  4111. fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
  4112. fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
  4113. gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
  4114. hal.dll Hardware Abstraction Layer DLL (Microsoft)
  4115. HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
  4116. HIDCLASS.SYS Hid Class Library (Microsoft)
  4117. HIDPARSE.SYS Hid Parsing Library (Microsoft)
  4118. hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
  4119. HTTP.sys HTTP Protocol Stack (Microsoft)
  4120. hwpolicy.sys Hardware Policy Driver
  4121. intelpep.sys Intel Power Engine Plugin (Microsoft)
  4122. intelppm.sys Processor Device Driver (Microsoft)
  4123. iorate.sys I/O rate control Filter (Microsoft)
  4124. kbdclass.sys Keyboard Class Driver (Microsoft)
  4125. kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
  4126. kd.dll Local Kernal Debugger (Microsoft)
  4127. kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
  4128. ks.sys Kernal CSA Library (Microsoft)
  4129. ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
  4130. ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
  4131. ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
  4132. lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
  4133. luafv.sys LUA File Virtualization Filter Driver (Microsoft)
  4134. mcupdate_GenuineIntel.dll Intel Microcode Update Library (Microsoft)
  4135. mmcss.sys MMCSS Driver (Microsoft)
  4136. monitor.sys Monitor Driver (Microsoft)
  4137. mouclass.sys Mouse Class Driver (Microsoft)
  4138. mouhid.sys HID Mouse Filter Driver (Microsoft)
  4139. mountmgr.sys Mount Point Manager (Microsoft)
  4140. mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
  4141. mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
  4142. mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
  4143. Msfs.SYS Mailslot driver (Microsoft)
  4144. msisadrv.sys ISA Driver (Microsoft)
  4145. mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
  4146. msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
  4147. mssmbios.sys System Management BIOS driver (Microsoft)
  4148. mup.sys Multiple UNC Provider driver (Microsoft)
  4149. ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
  4150. ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
  4151. ndisuio.sys NDIS User mode I/O driver (Microsoft)
  4152. NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
  4153. ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
  4154. NDProxy.sys NDIS Proxy driver (Microsoft)
  4155. Ndu.sys Network Data Usage Monitoring driver (Microsoft)
  4156. netbios.sys NetBIOS Interface driver (Microsoft)
  4157. netbt.sys MBT Transport driver (Microsoft)
  4158. NETIO.SYS Network I/O Subsystem (Microsoft)
  4159. Npfs.SYS NPFS driver (Microsoft)
  4160. npsvctrig.sys Named pipe service triggers (Microsoft)
  4161. nsiproxy.sys NSI Proxy driver (Microsoft)
  4162. Ntfs.sys NT File System Driver (Microsoft)
  4163. ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
  4164. ntosext.sys NTOS Extension Host driver (Microsoft)
  4165. Null.SYS NULL Driver (Microsoft)
  4166. pacer.sys QoS Packet Scheduler (Microsoft)
  4167. partmgr.sys Partition driver (Microsoft)
  4168. pci.sys NT Plug and Play PCI Enumerator (Microsoft)
  4169. pcw.sys Performance Counter Driver (Microsoft)
  4170. pdc.sys Power Dependency Coordinator Driver (Microsoft)
  4171. peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
  4172. portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
  4173. PSHED.dll Platform Specific Hardware Error driver (Microsoft)
  4174. rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
  4175. raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
  4176. raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
  4177. rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
  4178. rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
  4179. rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
  4180. rdpvideominiport.sys RDP Video Miniport driver (Microsoft)
  4181. rdyboost.sys ReadyBoost Driver (Microsoft)
  4182. rspndr.sys Link-Layer Topology Responder driver (Microsoft)
  4183. serenum.sys Serial Port Enumerator (Microsoft)
  4184. serial.sys Serial Device Driver
  4185. SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
  4186. SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
  4187. spaceport.sys Storage Spaces driver (Microsoft)
  4188. srv2.sys Smb 2.0 Server driver (Microsoft)
  4189. srvnet.sys Server Network driver (Microsoft)
  4190. storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
  4191. storqosflt.sys Storage QoS Filter driver (Microsoft)
  4192. swenum.sys Plug and Play Software Device Enumerator (Microsoft)
  4193. tbs.sys Export driver for kernel mode TPM API (Microsoft)
  4194. tcpip.sys TCP/IP Protocol driver (Microsoft)
  4195. tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
  4196. TDI.SYS TDI Wrapper driver (Microsoft)
  4197. tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
  4198. tm.sys Kernel Transaction Manager driver (Microsoft)
  4199. ucx01000.sys USB Controller Extension (Microsoft)
  4200. umbus.sys User-Mode Bus Enumerator (Microsoft)
  4201. usbaudio2.sys Microsoft USB Audio Class 2.0 Driver
  4202. usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
  4203. USBD.SYS Universal Serial Bus Driver (Microsoft)
  4204. UsbHub3.sys USB3 HUB driver (Microsoft)
  4205. USBXHCI.SYS USB XHCI driver (Microsoft)
  4206. vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
  4207. Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
  4208. volmgr.sys Volume Manager Driver (Microsoft)
  4209. volmgrx.sys Volume Manager Extension Driver (Microsoft)
  4210. volsnap.sys Volume Shadow Copy driver (Microsoft)
  4211. volume.sys Volume driver (Microsoft)
  4212. vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
  4213. wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
  4214. watchdog.sys Watchdog driver (Microsoft)
  4215. wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
  4216. WdBoot.sys Microsoft Antimalware Boot driver
  4217. Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
  4218. WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
  4219. WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
  4220. werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
  4221. wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
  4222. win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
  4223. win32kbase.sys Base Win32k Kernel Driver (Microsoft)
  4224. win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
  4225. WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
  4226. WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
  4227. winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
  4228. winquic.sys QUIC Transport Protocol driver (Microsoft)
  4229. wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
  4230. WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
  4231. Wof.sys Windows Overlay Filter (Microsoft)
  4232. WppRecorder.sys WPP Trace Recorder (Microsoft)
  4233.  
  4234. ====================== Dump #7: UNLOADED MODULES =======================
  4235.  
  4236. fffff802`1e800000 fffff802`1e991000 EasyAntiChea
  4237. fffff802`1e1e0000 fffff802`1e1f1000 MpKslDrv.sys
  4238. fffff802`1eb70000 fffff802`1eb86000 WdNisDrv.sys
  4239. fffff802`1dff0000 fffff802`1e036000 usbaudio2.sy
  4240. fffff802`1e200000 fffff802`1e20f000 hiber_storpo
  4241. fffff802`1e210000 fffff802`1e783000 hiber_iaStor
  4242. fffff802`1e790000 fffff802`1e7ae000 hiber_dumpfv
  4243. fffff802`1e040000 fffff802`1e1d1000 EasyAntiChea
  4244. fffff802`1e750000 fffff802`1e796000 usbaudio2.sy
  4245. fffff802`1e7a0000 fffff802`1e7af000 hiber_storpo
  4246. fffff802`1da50000 fffff802`1dfc3000 hiber_iaStor
  4247. fffff802`1dfd0000 fffff802`1dfee000 hiber_dumpfv
  4248. fffff802`1d9d0000 fffff802`1d9e1000 MpKslDrv.sys
  4249. fffff802`285c0000 fffff802`28606000 usbaudio2.sy
  4250. fffff802`1e1a0000 fffff802`1e1af000 hiber_storpo
  4251. fffff802`1e1b0000 fffff802`1e723000 hiber_iaStor
  4252. fffff802`1e730000 fffff802`1e74e000 hiber_dumpfv
  4253. fffff802`1e000000 fffff802`1e191000 EasyAntiChea
  4254. fffff802`1da50000 fffff802`1da5f000 hiber_storpo
  4255. fffff802`1da60000 fffff802`1dfd3000 hiber_iaStor
  4256. fffff802`1dfe0000 fffff802`1dffe000 hiber_dumpfv
  4257. fffff802`1d9c0000 fffff802`1d9cc000 cpuz149_x64.
  4258. fffff802`1d800000 fffff802`1d991000 EasyAntiChea
  4259. fffff802`1d9a0000 fffff802`1d9b1000 MpKslc90a352
  4260. fffff802`1e580000 fffff802`1eb55000 iqvw64e.sys
  4261. fffff802`1eb60000 fffff802`1eb6e000 WSDPrint.sys
  4262. fffff802`265e0000 fffff802`265ef000 dump_storpor
  4263. fffff802`25d80000 fffff802`262f3000 dump_iaStorA
  4264. fffff802`26320000 fffff802`2633e000 dump_dumpfve
  4265. fffff802`26c30000 fffff802`26c4e000 dam.sys
  4266.  
  4267. ====================== Dump #7: BIOS INFORMATION =======================
  4268.  
  4269. [SMBIOS Data Tables v2.8]
  4270. [DMI Version - 0]
  4271. [2.0 Calling Convention - No]
  4272. [Table Size - 1735 bytes]
  4273. [BIOS Information (Type 0) - Length 24 - Handle 0000h]
  4274. Vendor American Megatrends Inc.
  4275. BIOS Version P7.50
  4276. BIOS Starting Address Segment f000
  4277. BIOS Release Date 01/23/2018
  4278. BIOS ROM Size e00000
  4279. BIOS Characteristics
  4280. 07: - PCI Supported
  4281. 11: - Upgradeable FLASH BIOS
  4282. 12: - BIOS Shadowing Supported
  4283. 15: - CD-Boot Supported
  4284. 16: - Selectable Boot Supported
  4285. 17: - BIOS ROM Socketed
  4286. 19: - EDD Supported
  4287. 23: - 1.2MB Floppy Supported
  4288. 24: - 720KB Floppy Supported
  4289. 25: - 2.88MB Floppy Supported
  4290. 26: - Print Screen Device Supported
  4291. 27: - Keyboard Services Supported
  4292. 28: - Serial Services Supported
  4293. 29: - Printer Services Supported
  4294. 32: - BIOS Vendor Reserved
  4295. BIOS Characteristic Extensions
  4296. 00: - ACPI Supported
  4297. 01: - USB Legacy Supported
  4298. 08: - BIOS Boot Specification Supported
  4299. 10: - Specification Reserved
  4300. 11: - Specification Reserved
  4301. BIOS Major Revision 5
  4302. BIOS Minor Revision 11
  4303. EC Firmware Major Revision 255
  4304. EC Firmware Minor Revision 255
  4305. [System Information (Type 1) - Length 27 - Handle 0001h]
  4306. UUID 00000000-0000-0000-0000-000000000000
  4307. Wakeup Type Power Switch
  4308. [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
  4309. Manufacturer ASRock
  4310. Product Z170 Pro4S
  4311. Version
  4312. Feature Flags 09h
  4313. -449726752: - -449726704: - ÷7!ü
  4314. Location
  4315. Chassis Handle 0003h
  4316. Board Type 0ah - Processor/Memory Module
  4317. Number of Child Handles 0
  4318. [System Enclosure (Type 3) - Length 25 - Handle 0003h]
  4319. Chassis Type Desktop
  4320. Bootup State Safe
  4321. Power Supply State Safe
  4322. Thermal State Safe
  4323. Security Status None
  4324. OEM Defined 0
  4325. Height 0U
  4326. Number of Power Cords 1
  4327. Number of Contained Elements 1
  4328. Contained Element Size 3
  4329. [OEM Strings (Type 11) - Length 5 - Handle 000ah]
  4330. Number of Strings 1
  4331. [Cache Information (Type 7) - Length 19 - Handle 000dh]
  4332. Socket Designation L1 Cache
  4333. Cache Configuration 0180h - WB Enabled Int NonSocketed L1
  4334. Maximum Cache Size 0080h - 128K
  4335. Installed Size 0080h - 128K
  4336. Supported SRAM Type 0020h - Synchronous
  4337. Current SRAM Type 0020h - Synchronous
  4338. Cache Speed 0ns
  4339. Error Correction Type ParitySingle-Bit ECC
  4340. System Cache Type Data
  4341. Associativity 8-way Set-Associative
  4342. [Cache Information (Type 7) - Length 19 - Handle 000eh]
  4343. Socket Designation L1 Cache
  4344. Cache Configuration 0180h - WB Enabled Int NonSocketed L1
  4345. Maximum Cache Size 0080h - 128K
  4346. Installed Size 0080h - 128K
  4347. Supported SRAM Type 0020h - Synchronous
  4348. Current SRAM Type 0020h - Synchronous
  4349. Cache Speed 0ns
  4350. Error Correction Type ParitySingle-Bit ECC
  4351. System Cache Type Instruction
  4352. Associativity 8-way Set-Associative
  4353. [Cache Information (Type 7) - Length 19 - Handle 000fh]
  4354. Socket Designation L2 Cache
  4355. Cache Configuration 0181h - WB Enabled Int NonSocketed L2
  4356. Maximum Cache Size 0400h - 1024K
  4357. Installed Size 0400h - 1024K
  4358. Supported SRAM Type 0020h - Synchronous
  4359. Current SRAM Type 0020h - Synchronous
  4360. Cache Speed 0ns
  4361. Error Correction Type Multi-Bit ECC
  4362. System Cache Type Unified
  4363. Associativity 4-way Set-Associative
  4364. [Cache Information (Type 7) - Length 19 - Handle 0010h]
  4365. Socket Designation L3 Cache
  4366. Cache Configuration 0182h - WB Enabled Int NonSocketed L3
  4367. Maximum Cache Size 1800h - 6144K
  4368. Installed Size 1800h - 6144K
  4369. Supported SRAM Type 0020h - Synchronous
  4370. Current SRAM Type 0020h - Synchronous
  4371. Cache Speed 0ns
  4372. Error Correction Type Specification Reserved
  4373. System Cache Type Unified
  4374. Associativity Specification Reserved
  4375. [Processor Information (Type 4) - Length 48 - Handle 0011h]
  4376. Socket Designation CPUSocket
  4377. Processor Type Central Processor
  4378. Processor Family cdh - Specification Reserved
  4379. Processor Manufacturer Intel(R) Corporation
  4380. Processor ID e3060500fffbebbf
  4381. Processor Version Intel(R) Core(TM) i5-6600K CPU @ 3.50GHz
  4382. Processor Voltage 8bh - 1.1V
  4383. External Clock 100MHz
  4384. Max Speed 5000MHz
  4385. Current Speed 3500MHz
  4386. Status Enabled Populated
  4387. Processor Upgrade Other
  4388. L1 Cache Handle 000eh
  4389. L2 Cache Handle 000fh
  4390. L3 Cache Handle 0010h
  4391. [Physical Memory Array (Type 16) - Length 23 - Handle 0012h]
  4392. Location 03h - SystemBoard/Motherboard
  4393. Use 03h - System Memory
  4394. Memory Error Correction 03h - None
  4395. Maximum Capacity 67108864KB
  4396. Number of Memory Devices 4
  4397. [Memory Device (Type 17) - Length 40 - Handle 0013h]
  4398. Physical Memory Array Handle 0012h
  4399. Total Width 0 bits
  4400. Data Width 0 bits
  4401. Form Factor 09h - DIMM
  4402. Device Locator ChannelA-DIMM0
  4403. Bank Locator BANK 0
  4404. Memory Type 02h - Unknown
  4405. Type Detail 0000h -
  4406. Speed 0MHz
  4407. [Memory Device (Type 17) - Length 40 - Handle 0014h]
  4408. Physical Memory Array Handle 0012h
  4409. Total Width 64 bits
  4410. Data Width 64 bits
  4411. Size 8192MB
  4412. Form Factor 09h - DIMM
  4413. Device Locator ChannelA-DIMM1
  4414. Bank Locator BANK 1
  4415. Memory Type 1ah - Specification Reserved
  4416. Type Detail 0080h - Synchronous
  4417. Speed 3000MHz
  4418. Manufacturer Kingston
  4419. Part Number KHX3000C15D4/8GX
  4420. [Memory Device (Type 17) - Length 40 - Handle 0015h]
  4421. Physical Memory Array Handle 0012h
  4422. Total Width 0 bits
  4423. Data Width 0 bits
  4424. Form Factor 09h - DIMM
  4425. Device Locator ChannelB-DIMM0
  4426. Bank Locator BANK 2
  4427. Memory Type 02h - Unknown
  4428. Type Detail 0000h -
  4429. Speed 0MHz
  4430. [Memory Device (Type 17) - Length 40 - Handle 0016h]
  4431. Physical Memory Array Handle 0012h
  4432. Total Width 64 bits
  4433. Data Width 64 bits
  4434. Size 8192MB
  4435. Form Factor 09h - DIMM
  4436. Device Locator ChannelB-DIMM1
  4437. Bank Locator BANK 3
  4438. Memory Type 1ah - Specification Reserved
  4439. Type Detail 0080h - Synchronous
  4440. Speed 3000MHz
  4441. Manufacturer Kingston
  4442. Part Number KHX3000C15D4/8GX
  4443. [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0017h]
  4444. Starting Address 00000000h
  4445. Ending Address 00ffffffh
  4446. Memory Array Handle 0012h
  4447. Partition Width 02
  4448. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0018h]
  4449. Starting Address 00000000h
  4450. Ending Address 007fffffh
  4451. Memory Device Handle 0014h
  4452. Mem Array Mapped Adr Handle 0017h
  4453. Partition Row Position 01
  4454. Interleave Position 01
  4455. Interleave Data Depth 02
  4456. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0019h]
  4457. Starting Address 00800000h
  4458. Ending Address 00ffffffh
  4459. Memory Device Handle 0016h
  4460. Mem Array Mapped Adr Handle 0017h
  4461. Partition Row Position 01
  4462. Interleave Position 02
  4463. Interleave Data Depth 02
  4464.  
  4465. ========================== Dump #7: Extra #1 ===========================
  4466.  
  4467. 0: kd> !verifier
  4468. Verify Flags Level 0x00000000
  4469. STANDARD FLAGS:
  4470. [X] (0x00000000) Automatic Checks
  4471. [ ] (0x00000001) Special pool
  4472. [ ] (0x00000002) Force IRQL checking
  4473. [ ] (0x00000008) Pool tracking
  4474. [ ] (0x00000010) I/O verification
  4475. [ ] (0x00000020) Deadlock detection
  4476. [ ] (0x00000080) DMA checking
  4477. [ ] (0x00000100) Security checks
  4478. [ ] (0x00000800) Miscellaneous checks
  4479. [ ] (0x00020000) DDI compliance checking
  4480. ADDITIONAL FLAGS:
  4481. [ ] (0x00000004) Randomized low resources simulation
  4482. [ ] (0x00000200) Force pending I/O requests
  4483. [ ] (0x00000400) IRP logging
  4484. [ ] (0x00002000) Invariant MDL checking for stack
  4485. [ ] (0x00004000) Invariant MDL checking for driver
  4486. [ ] (0x00008000) Power framework delay fuzzing
  4487. [ ] (0x00010000) Port/miniport interface checking
  4488. [ ] (0x00040000) Systematic low resources simulation
  4489. [ ] (0x00080000) DDI compliance checking (additional)
  4490. [ ] (0x00200000) NDIS/WIFI verification
  4491. [ ] (0x00800000) Kernel synchronization delay fuzzing
  4492. [ ] (0x01000000) VM switch verification
  4493. [ ] (0x02000000) Code integrity checks
  4494. [X] Indicates flag is enabled
  4495. Summary of All Verifier Statistics
  4496. RaiseIrqls 0x0
  4497. AcquireSpinLocks 0x0
  4498. Synch Executions 0x0
  4499. Trims 0x0
  4500. Pool Allocations Attempted 0x0
  4501. Pool Allocations Succeeded 0x0
  4502. Pool Allocations Succeeded SpecialPool 0x0
  4503. Pool Allocations With NO TAG 0x0
  4504. Pool Allocations Failed 0x0
  4505. Current paged pool allocations 0x0 for 00000000 bytes
  4506. Peak paged pool allocations 0x0 for 00000000 bytes
  4507. Current nonpaged pool allocations 0x0 for 00000000 bytes
  4508. Peak nonpaged pool allocations 0x0 for 00000000 bytes
  4509.  
  4510. ========================== Dump #7: Extra #2 ===========================
  4511.  
  4512. 0: kd> !thread
  4513. THREAD fffff8021f391400 Cid 0000.0000 Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor 0
  4514. Not impersonating
  4515. GetUlongFromAddress: unable to read from fffff8021f22ca24
  4516. Owning Process fffff8021f38e9c0 Image: System Process
  4517. Attached Process ffffe6897ec7b080 Image: System
  4518. fffff78000000000: Unable to get shared data
  4519. Wait Start TickCount 16748053 Ticks: 99984
  4520. Context Switch Count 189702797 IdealProcessor: 0
  4521. ReadMemory error: Cannot get nt!KeMaximumIncrement value.
  4522. UserTime 00:00:00.000
  4523. KernelTime 00:00:00.000
  4524. Win32 Start Address nt!KiIdleLoop (0xfffff8021efc5e40)
  4525. Stack Init fffff80225538b90 Current fffff80225538b20
  4526. Base fffff80225539000 Limit fffff80225532000 Call 0000000000000000
  4527. Priority 0 BasePriority 0 PriorityDecrement 0 IoPriority 0 PagePriority 5
  4528. Child-SP RetAddr : Args to Child : Call Site
  4529. fffff802`25538408 fffff802`1efd41e9 : 00000000`0000000a fffff802`255186d8 00000000`000000ff 00000000`00000053 : nt!KeBugCheckEx
  4530. fffff802`25538410 fffff802`1efd0529 : 00000000`00000000 ffffe689`8453a010 fffff802`255386b0 fffff802`293fbc07 : nt!KiBugCheckDispatch+0x69
  4531. fffff802`25538550 fffff802`1eebb862 : 00000000`00000001 000245bb`92ea2879 fffff802`1cc3a180 00000000`00000000 : nt!KiPageFault+0x469 (TrapFrame @ fffff802`25538550)
  4532. fffff802`255386e0 fffff802`1eebadde : 00000000`00000003 00000000`00000002 ffffe689`845a20f0 00000000`00000008 : nt!PpmIdleExecuteTransition+0x8e2
  4533. fffff802`25538a00 fffff802`1efc5e84 : 00000000`00000000 fffff802`1cc3a180 ffffe689`7ed3e080 00000000`000002be : nt!PoIdle+0x36e
  4534. fffff802`25538b60 00000000`00000000 : fffff802`25539000 fffff802`25532000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x44
RAW Paste Data