Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Microsoft (R) Windows Debugger Version 10.0.14321.1024 X86
- Copyright (c) Microsoft Corporation. All rights reserved.
- ========================================================================
- =================== Dump File: 072417-48312-01.dmp ===================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 15063 MP (6 procs) Free x64
- Product: WinNt, suite: TerminalServer SingleUserTS
- Built by: 15063.0.amd64fre.rs2_release.170317-1834
- Kernel base = 0xfffff802`5e41a000 PsLoadedModuleList = 0xfffff802`5e7665a0
- Debug session time: Mon Jul 24 19:11:27.865 2017 (UTC - 4:00)
- System Uptime: 2 days 2:27:39.554
- BugCheck 7A, {ffffe48724036a18, ffffffffc0000185, bcbcc860, fffff80ed8419ee4}
- *** WARNING: Unable to verify timestamp for win32k.sys
- *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
- Probably caused by : memory_corruption
- Followup: memory_corruption
- KERNEL_DATA_INPAGE_ERROR (7a)
- The requested page of kernel data could not be read in. Typically caused by
- a bad block in the paging file or disk controller error. Also see
- KERNEL_STACK_INPAGE_ERROR.
- If the error status is 0xC000000E, 0xC000009C, 0xC000009D or 0xC0000185,
- it means the disk subsystem has experienced a failure.
- If the error status is 0xC000009A, then it means the request failed because
- a filesystem failed to make forward progress.
- Arguments:
- Arg1: ffffe48724036a18, lock type that was held (value 1,2,3, or PTE address)
- Arg2: ffffffffc0000185, error status (normally i/o status code)
- Arg3: 00000000bcbcc860, current process (virtual address for lock type 3, or PTE)
- Arg4: fffff80ed8419ee4, virtual address that could not be in-paged (or PTE contents if arg1 is a PTE address)
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- BUILD_VERSION_STRING: 10.0.15063.413 (WinBuild.160101.0800)
- SYSTEM_MANUFACTURER: Gigabyte Technology Co., Ltd.
- SYSTEM_PRODUCT_NAME: GA-78LMT-USB3
- BIOS_VENDOR: Award Software International, Inc.
- BIOS_VERSION: FA
- BIOS_DATE: 04/23/2013
- BASEBOARD_MANUFACTURER: Gigabyte Technology Co., Ltd.
- BASEBOARD_PRODUCT: GA-78LMT-USB3
- BASEBOARD_VERSION: SEx
- DUMP_TYPE: 2
- ERROR_CODE: (NTSTATUS) 0xc0000185 - The I/O device reported an I/O error.
- DISK_HARDWARE_ERROR: There was error with disk hardware
- BUGCHECK_STR: 0x7a_c0000185
- CPU_COUNT: 6
- CPU_MHZ: c8e
- CPU_VENDOR: AuthenticAMD
- CPU_FAMILY: 10
- CPU_MODEL: a
- CPU_STEPPING: 0
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- PROCESS_NAME: System
- CURRENT_IRQL: 0
- TRAP_FRAME: ffffb001267bc0d0 -- (.trap 0xffffb001267bc0d0)
- NOTE: The trap frame does not contain all registers.
- Some register values may be zeroed or incorrect.
- rax=0000000000000002 rbx=0000000000000000 rcx=ffffd4899ccd9698
- rdx=ffffd4899b5ce848 rsi=0000000000000000 rdi=0000000000000000
- rip=fffff80ed8419ee4 rsp=ffffb001267bc268 rbp=ffffd4899ccdc488
- r8=0000000000000002 r9=fffff80ed83f0000 r10=0000000000000038
- r11=ffffb001267bc2f0 r12=0000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=0000000000000000
- iopl=0 nv up ei pl zr na po nc
- usbccgp!PdoRemoveDevice:
- fffff80e`d8419ee4 48895c2408 mov qword ptr [rsp+8],rbx ss:0018:ffffb001`267bc270=0000000000000000
- Resetting default scope
- LOCK_ADDRESS: fffff8025e77ef20 -- (!locks fffff8025e77ef20)
- Resource @ nt!PiEngineLock (0xfffff8025e77ef20) Exclusively owned
- Contention Count = 73
- Threads: ffffd4899b626700-01<*>
- 1 total locks, 1 locks currently held
- PNP_TRIAGE:
- Lock address : 0xfffff8025e77ef20
- Thread Count : 1
- Thread address: 0xffffd4899b626700
- Thread wait : 0xb166e1
- LAST_CONTROL_TRANSFER: from fffff8025e5c268a to fffff8025e5863f0
- STACK_TEXT:
- ffffb001`267bbcf8 fffff802`5e5c268a : 00000000`0000007a ffffe487`24036a18 ffffffff`c0000185 00000000`bcbcc860 : nt!KeBugCheckEx
- ffffb001`267bbd00 fffff802`5e4bb928 : 00000000`00000003 ffffb001`267bbe98 00000000`00000000 ffffd489`00000000 : nt!MiWaitForInPageComplete+0x108a0a
- ffffb001`267bbe00 fffff802`5e4a73f6 : 00000000`c0033333 ffffb001`267bc0d0 00000000`00000000 ffffd489`99ec2680 : nt!MiIssueHardFault+0x1d8
- ffffb001`267bbee0 fffff802`5e58fc72 : ffffd489`9ccdc488 00000000`00000000 ffffd489`9f523860 fffff802`5e47a6c4 : nt!MmAccessFault+0xc96
- ffffb001`267bc0d0 fffff80e`d8419ee4 : fffff80e`d841151d 00000000`00000000 fffff80e`d8437101 00000000`0000000f : nt!KiPageFault+0x132
- ffffb001`267bc268 fffff80e`d841151d : 00000000`00000000 fffff80e`d8437101 00000000`0000000f fffff80e`d83f11c1 : usbccgp!PdoRemoveDevice
- ffffb001`267bc270 fffff80e`d83f116e : ffffd489`9ccd9698 00000000`0000001b ffffd489`9ccd9698 ffffd489`00000000 : usbccgp!DispatchPdoPnp+0x2dd
- ffffb001`267bc360 fffff80e`d843d0bf : ffffd489`9ccd9540 ffffd489`00000000 00000000`00000002 ffffd489`9cccb918 : usbccgp!USBC_Dispatch+0x15e
- ffffb001`267bc420 fffff80e`d843c361 : 00000000`00000000 ffffb001`267bc4f9 ffffd489`9cccb918 00000000`00000070 : hidusb!HumRemoveDevice+0x7f
- ffffb001`267bc460 fffff80e`d845666a : ffffd489`9cb15000 00000000`746c6644 ffffd489`9b5ce580 ffffd489`00000000 : hidusb!HumPnP+0x151
- ffffb001`267bc560 fffff80e`d847c706 : ffffd489`9cccb400 ffffd489`9b5ce580 ffffd489`9cccb878 ffffd489`9cccb1d0 : HIDCLASS!HidpCallDriver+0x7a
- ffffb001`267bc5c0 fffff80e`d847973f : 00000000`00000002 ffffd489`9b5ce848 ffffd489`9b5ce580 ffffd489`9cccb1b0 : HIDCLASS!HidpRemoveDevice+0x12a
- ffffb001`267bc610 fffff80e`d847611a : ffffd489`9cccb1b0 00000000`00000000 fffff80e`d846a488 00000000`00000000 : HIDCLASS!HidpFdoPnp+0x3a1f
- ffffb001`267bc680 fffff80e`d8452013 : 00000000`0000001b ffffd489`9b5ce580 00000000`00000002 fffff802`5e47ab42 : HIDCLASS!HidpIrpMajorPnp+0x6a
- ffffb001`267bc6c0 fffff802`5e88bfc9 : ffffd489`9cccb060 00000000`00000000 ffffb001`267bc800 fffff802`5e981009 : HIDCLASS!HidpMajorHandler+0xe3
- ffffb001`267bc750 fffff802`5e980e53 : 00000000`00000002 ffffb001`267bc819 ffffd489`9cb1c170 ffffd489`9ccd9540 : nt!IopSynchronousCall+0xe5
- ffffb001`267bc7c0 fffff802`5e53d44b : ffffe487`31475e40 ffffd489`9cb1c170 00000000`0000000a fffff802`00000000 : nt!IopRemoveDevice+0xdf
- ffffb001`267bc880 fffff802`5e9807da : ffffd489`9cb1c170 00000000`00000000 00000000`00000000 00000000`00000000 : nt!PnpRemoveLockedDeviceNode+0x1a7
- ffffb001`267bc8e0 fffff802`5e98051a : 00000000`00000000 ffffb001`267bc960 ffffe487`2a237f00 00000000`00000000 : nt!PnpDeleteLockedDeviceNode+0x4e
- ffffb001`267bc920 fffff802`5e97c0dd : ffffd489`9ccd5060 00000000`00000002 ffffd489`9ee26350 00000000`00000000 : nt!PnpDeleteLockedDeviceNodes+0xbe
- ffffb001`267bc990 fffff802`5e97bfdf : ffffd489`9ee26350 ffffb001`267bca10 ffffd489`9ccd5060 fffff802`5e77ef00 : nt!PipRemoveDevicesInRelationList+0x8d
- ffffb001`267bc9e0 fffff802`5e97bebd : 00000000`00000001 ffffe487`3638f502 ffffd489`9ee26350 fffff802`5e47de98 : nt!PnpDelayedRemoveWorker+0xef
- ffffb001`267bca20 fffff802`5e53d821 : 00000000`0000000a 00000000`00000001 00000000`00000000 ffffe487`2a237f02 : nt!PnpChainDereferenceComplete+0x101
- ffffb001`267bca50 fffff802`5e97f741 : 00000000`0000000b 0000000b`00000000 ffffb001`267bcb99 ffffe487`00000001 : nt!PnpIsChainDereferenced+0x111
- ffffb001`267bcad0 fffff802`5e8888b6 : ffffb001`267bcc60 ffffe487`2e4d6d00 ffffb001`267bcc00 00000000`00000001 : nt!PnpProcessQueryRemoveAndEject+0x4ed
- ffffb001`267bcc00 fffff802`5e892e94 : ffffe487`31475e40 00000000`00000000 ffffd489`9b80d400 ffffe487`2e4d6d20 : nt!PnpProcessTargetDeviceEvent+0xf2
- ffffb001`267bcc30 fffff802`5e457ca8 : 00000000`00000800 ffffd489`9b626700 ffffd489`9b80d410 fffff802`5e812380 : nt!PnpDeviceEventWorker+0x254
- ffffb001`267bccc0 fffff802`5e4f6a37 : 00000000`00000000 00000000`00000080 ffffd489`99ec2680 ffffd489`9b626700 : nt!ExpWorkerThread+0xd8
- ffffb001`267bcd50 fffff802`5e58b876 : ffffb001`2015c180 ffffd489`9b626700 fffff802`5e4f69f0 00000000`00000000 : nt!PspSystemThreadStartup+0x47
- ffffb001`267bcda0 00000000`00000000 : ffffb001`267bd000 ffffb001`267b7000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x16
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
- fffff8025e4a74bc-fffff8025e4a74bd 2 bytes - nt!MmAccessFault+d5c
- [ ff f6:7f 92 ]
- fffff8025e4bb982-fffff8025e4bb983 2 bytes - nt!MiIssueHardFault+232 (+0x144c6)
- [ 80 f6:00 92 ]
- fffff8025e4bbaaa-fffff8025e4bbaab 2 bytes - nt!MiIssueHardFault+35a (+0x128)
- [ 80 fa:00 82 ]
- fffff8025e5c26a0-fffff8025e5c26a1 2 bytes - nt!MiWaitForInPageComplete+108a20 (+0x106bf6)
- [ 80 fa:00 82 ]
- fffff8025e69a383-fffff8025e69a385 3 bytes - nt!ExFreePoolWithTag+363
- [ 40 fb f6:00 49 92 ]
- 11 errors : !nt (fffff8025e4a74bc-fffff8025e69a385)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2017-07-24T23:11:27.000Z
- OSBUILD: 15063
- OSSERVICEPACK: 413
- SERVICEPACK_NUMBER: 0
- OS_REVISION: 0
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- OSPLATFORM_TYPE: x64
- OSNAME: Windows 10
- OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
- USER_LCID: 0
- OSBUILD_TIMESTAMP: 2017-06-03 04:53:36
- BUILDDATESTAMP_STR: 160101.0800
- BUILDLAB_STR: WinBuild
- BUILDOSVER_STR: 10.0.15063.413
- ANALYSIS_SESSION_ELAPSED_TIME: 2d42
- ANALYSIS_SOURCE: KM
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- =============================== Drivers ================================
- fffff802`5ee00000 fffff802`5ee0b000 kdcom (deferred)
- Image path: kdcom.dll
- Image name: kdcom.dll
- Timestamp: ***** Invalid (91688416)
- fffff80e`d3340000 fffff80e`d339e000 volmgrx (deferred)
- Image path: \SystemRoot\System32\drivers\volmgrx.sys
- Image name: volmgrx.sys
- Timestamp: unavailable (00000000)
- fffff80e`d3820000 fffff80e`d382d000 Fs_Rec (deferred)
- Image path: Fs_Rec.sys
- Image name: Fs_Rec.sys
- Timestamp: unavailable (00000000)
- fffff80e`d3a30000 fffff80e`d3a4c000 mcupdate (deferred)
- Image path: mcupdate.dll
- Image name: mcupdate.dll
- Timestamp: Tue Jan 31 06:16:29 1978 (0F346A8D)
- fffff80e`d3a50000 fffff80e`d3aaf000 msrpc (deferred)
- Image path: msrpc.sys
- Image name: msrpc.sys
- Timestamp: unavailable (00000000)
- fffff80e`d3ea0000 fffff80e`d3eaa000 Null (deferred)
- Image path: Null.SYS
- Image name: Null.SYS
- Timestamp: unavailable (00000000)
- fffff80e`d4910000 fffff80e`d4936000 VBoxUSBMon (deferred)
- Image path: \SystemRoot\system32\DRIVERS\VBoxUSBMon.sys
- Image name: VBoxUSBMon.sys
- Timestamp: Tue Sep 15 23:25:39 2015 (55F8E133)
- fffff80e`d4980000 fffff80e`d498e000 MpKsle410f036 (deferred)
- Image path: MpKsle410f036.sys
- Image name: MpKsle410f036.sys
- Timestamp: Tue May 19 21:50:37 2015 (555BE86D)
- fffff80e`d4ae0000 fffff80e`d4b63000 atikmpag (deferred)
- Image path: atikmpag.sys
- Image name: atikmpag.sys
- Timestamp: Tue Jul 4 17:48:49 2017 (595C0D41)
- fffff80e`d4bf0000 fffff80e`d4cb6000 peauth (deferred)
- Image path: peauth.sys
- Image name: peauth.sys
- Timestamp: Sat Dec 9 21:03:08 1989 (2581B95C)
- fffff80e`d5810000 fffff80e`d5820000 Msfs (deferred)
- Image path: Msfs.SYS
- Image name: Msfs.SYS
- Timestamp: unavailable (00000000)
- fffff80e`d7e70000 fffff80e`d7e91000 drmk (deferred)
- Image path: drmk.sys
- Image name: drmk.sys
- Timestamp: ***** Invalid (A01C1986)
- fffff80e`d7fc0000 fffff80e`d8058000 rt640x64 (deferred)
- Image path: rt640x64.sys
- Image name: rt640x64.sys
- Timestamp: Wed Oct 5 09:32:55 2016 (57F50107)
- fffff80e`d8110000 fffff80e`d811a000 ALSysIO64 (deferred)
- Image path: ALSysIO64.sys
- Image name: ALSysIO64.sys
- Timestamp: Wed Jul 6 12:47:33 2016 (577D3625)
- fffff80e`d8170000 fffff80e`d817f000 dtliteusbbus (deferred)
- Image path: dtliteusbbus.sys
- Image name: dtliteusbbus.sys
- Timestamp: Mon Dec 28 08:05:52 2015 (568133B0)
- fffff80e`d81a0000 fffff80e`d81ae000 ssdevfactory (deferred)
- Image path: ssdevfactory.sys
- Image name: ssdevfactory.sys
- Timestamp: Wed Oct 19 17:04:31 2016 (5807DFDF)
- fffff80e`d81b0000 fffff80e`d81bb000 dtlitescsibus (deferred)
- Image path: dtlitescsibus.sys
- Image name: dtlitescsibus.sys
- Timestamp: Thu Sep 24 16:17:21 2015 (56045A51)
- fffff80e`d8270000 fffff80e`d828e000 AtihdWT6 (deferred)
- Image path: AtihdWT6.sys
- Image name: AtihdWT6.sys
- Timestamp: Sat Mar 25 17:04:05 2017 (58D6DB45)
- fffff80e`d8330000 fffff80e`d83e3000 viahduaa (deferred)
- Image path: viahduaa.sys
- Image name: viahduaa.sys
- Timestamp: Tue Jun 16 04:06:10 2015 (557FD8F2)
- fffff80e`d84b0000 fffff80e`d84bf000 sshid (deferred)
- Image path: \SystemRoot\System32\drivers\sshid.sys
- Image name: sshid.sys
- Timestamp: Mon Dec 19 12:43:41 2016 (58581C4D)
- fffff80e`d8540000 fffff80e`d854f000 dump_storport (deferred)
- Image path: dump_storport.sys
- Image name: dump_storport.sys
- Timestamp: Wed Aug 28 09:02:36 2013 (521DF4EC)
- fffff80e`d87e0000 fffff80e`d8800000 ssudbus (deferred)
- Image path: ssudbus.sys
- Image name: ssudbus.sys
- Timestamp: Wed Aug 24 04:00:41 2016 (57BD5429)
- fffff80e`d8a70000 fffff80e`dada7000 atikmdag (deferred)
- Image path: atikmdag.sys
- Image name: atikmdag.sys
- Timestamp: Tue Jul 4 18:11:43 2017 (595C129F)
- fffff80e`dadb0000 fffff80e`dadbe000 MpKsle8082030 (deferred)
- Image path: \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5FE2EF65-34E9-4DE5-81B7-0626A935C4C8}\MpKsle8082030.sys
- Image name: MpKsle8082030.sys
- Timestamp: Tue May 19 21:50:37 2015 (555BE86D)
- fffffcde`1bc00000 fffffcde`1bf93000 win32kfull (deferred)
- Image path: \SystemRoot\System32\win32kfull.sys
- Image name: win32kfull.sys
- Timestamp: unavailable (00000000)
- fffffcde`1c020000 fffffcde`1c094000 win32k T (no symbols)
- Loaded symbol image file: win32k.sys
- Image path: win32k.sys
- Image name: win32k.sys
- Timestamp: unavailable (00000000)
- fffffcde`1c3c0000 fffffcde`1c401000 cdd (deferred)
- Image path: cdd.dll
- Image name: cdd.dll
- Timestamp: unavailable (00000000)
- fffffcde`1cdc0000 fffffcde`1cfc6000 win32kbase (deferred)
- Image path: win32kbase.sys
- Image name: win32kbase.sys
- Timestamp: unavailable (00000000)
- fffffcde`1cfe0000 fffffcde`1cfea000 TSDDD (deferred)
- Image path: TSDDD.dll
- Image name: TSDDD.dll
- Timestamp: unavailable (00000000)
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- Unloaded modules:
- fffff80e`d87e0000 fffff80e`d8800000 ssudbus.sys
- fffff80e`d5350000 fffff80e`d5361000 modem.sys
- fffff80e`d5310000 fffff80e`d5341000 ssudmdm.sys
- fffff80e`d8940000 fffff80e`d894d000 WpdUpFltr.sy
- fffff80e`d52d0000 fffff80e`d530d000 WUDFRd.sys
- fffff80e`d52b0000 fffff80e`d52cd000 WinUSB.SYS
- fffff80e`d87f0000 fffff80e`d87ff000 hiber_storpo
- fffff80e`d5260000 fffff80e`d5287000 hiber_storah
- fffff80e`d5290000 fffff80e`d52ad000 hiber_dumpfv
- fffff80e`d87e0000 fffff80e`d87ef000 hiber_storpo
- fffff80e`d5210000 fffff80e`d5237000 hiber_storah
- fffff80e`d5240000 fffff80e`d525d000 hiber_dumpfv
- fffff80e`d87e0000 fffff80e`d8800000 ssudbus.sys
- fffff80e`d51f0000 fffff80e`d5201000 modem.sys
- fffff80e`d51b0000 fffff80e`d51e1000 ssudmdm.sys
- fffff80e`d8940000 fffff80e`d894d000 WpdUpFltr.sy
- fffff80e`d5170000 fffff80e`d51ad000 WUDFRd.sys
- fffff80e`d5150000 fffff80e`d516d000 WinUSB.SYS
- fffff80e`d87e0000 fffff80e`d8800000 ssudbus.sys
- fffff80e`d5130000 fffff80e`d5141000 RNDISMP6.SYS
- fffff80e`d5120000 fffff80e`d512d000 usb80236.sys
- fffff80e`d8940000 fffff80e`d8946000 RTCore64.sys
- fffff80e`d8940000 fffff80e`d8946000 RTCore64.sys
- fffff80e`d87e0000 fffff80e`d8800000 ssudbus.sys
- fffff80e`d5100000 fffff80e`d5111000 modem.sys
- fffff80e`d50c0000 fffff80e`d50f1000 ssudmdm.sys
- fffff80e`d50b0000 fffff80e`d50bd000 WpdUpFltr.sy
- fffff80e`d5070000 fffff80e`d50ad000 WUDFRd.sys
- fffff80e`d4fe0000 fffff80e`d4ffd000 WinUSB.SYS
- fffff80e`d87f0000 fffff80e`d87ff000 hiber_storpo
- fffff80e`d4f90000 fffff80e`d4fb7000 hiber_storah
- fffff80e`d4fc0000 fffff80e`d4fdd000 hiber_dumpfv
- fffff80e`d87e0000 fffff80e`d87ef000 hiber_storpo
- fffff80e`d4f40000 fffff80e`d4f67000 hiber_storah
- fffff80e`d4f70000 fffff80e`d4f8d000 hiber_dumpfv
- fffff80e`d87e0000 fffff80e`d8800000 ssudbus.sys
- fffff80e`d4f00000 fffff80e`d4f11000 modem.sys
- fffff80e`d4ec0000 fffff80e`d4ef1000 ssudmdm.sys
- fffff80e`d8940000 fffff80e`d894d000 WpdUpFltr.sy
- fffff80e`d57b0000 fffff80e`d57ed000 WUDFRd.sys
- fffff80e`d5790000 fffff80e`d57ad000 WinUSB.SYS
- fffff80e`d87e0000 fffff80e`d8800000 ssudbus.sys
- fffff80e`d5770000 fffff80e`d5781000 RNDISMP6.SYS
- fffff80e`d8940000 fffff80e`d894d000 usb80236.sys
- fffff80e`d87e0000 fffff80e`d8800000 ssudbus.sys
- fffff80e`d5750000 fffff80e`d5761000 modem.sys
- fffff80e`d5710000 fffff80e`d5741000 ssudmdm.sys
- fffff80e`d8940000 fffff80e`d894d000 WpdUpFltr.sy
- fffff80e`d56d0000 fffff80e`d570d000 WUDFRd.sys
- fffff80e`d56b0000 fffff80e`d56cd000 WinUSB.SYS
- ============================= BIOS INFO ================================
- [SMBIOS Data Tables v2.4]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 2829 bytes]
- [BIOS Information (Type 0) - Length 24 - Handle 0000h]
- Vendor Award Software International, Inc.
- BIOS Version FA
- BIOS Starting Address Segment e000
- BIOS Release Date 04/23/2013
- BIOS ROM Size 400000
- BIOS Characteristics
- 04: - ISA Supported
- 07: - PCI Supported
- 09: - Plug and Play Supported
- 10: - APM Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 22: - 360KB Floppy Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 27: - Keyboard Services Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 30: - CGA/Mono Services Supported
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 02: - AGP Supported
- 04: - LS120-Boot Supported
- 05: - ATAPI ZIP-Boot Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- BIOS Major Revision 255
- BIOS Minor Revision 255
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- Manufacturer Gigabyte Technology Co., Ltd.
- Product Name GA-78LMT-USB3
- Version
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- SKUNumber
- Family
- [BaseBoard Information (Type 2) - Length 8 - Handle 0002h]
- Manufacturer Gigabyte Technology Co., Ltd.
- Product GA-78LMT-USB3
- Version SEx
- [System Enclosure (Type 3) - Length 17 - Handle 0003h]
- Manufacturer Gigabyte Technology Co., Ltd.
- Chassis Type Desktop
- Version
- Bootup State Unknown
- Power Supply State Unknown
- Thermal State Unknown
- Security Status Unknown
- OEM Defined 0
- [Processor Information (Type 4) - Length 35 - Handle 0004h]
- Socket Designation Socket M2
- Processor Type Central Processor
- Processor Family 1dh - AMD Athlon Family
- Processor Manufacturer AMD
- Processor ID a00f1000fffb8b17
- Processor Version AMD Phenom(tm) II X6 1090T Processor
- Processor Voltage 90h - 1.6V
- External Clock 200MHz
- Max Speed 3000MHz
- Current Speed 3200MHz
- Status Enabled Populated
- Processor Upgrade Socket 754
- L1 Cache Handle 000ah
- L2 Cache Handle 000ch
- L3 Cache Handle [Not Present]
- Part Number
- [Memory Controller Information (Type 5) - Length 24 - Handle 0005h]
- Error Detecting Method 06h - 64-bit ECC
- Error Correcting Capability 04h - None
- Supported Interleave 03h - One Way Interleave
- Current Interleave 03h - One Way Interleave
- Maximum Memory Module Size 0ch - 4096MB
- Supported Speeds 001ch - 70ns 60ns 50ns
- Supported Memory Types 0104h - Standard DIMM
- Memory Module Voltage 2.9V
- Number of Memory Slots 4
- Memory Slot Handle 0006h
- Memory Slot Handle 0007h
- Memory Slot Handle 0008h
- Memory Slot Handle 0009h
- Enabled Err Correcting Caps 04h - None
- [Memory Module Information (Type 6) - Length 12 - Handle 0006h]
- Socket Designation A0
- Bank Connections 1fh - 1
- Current Speed 31ns
- Current Memory Type 0013h - Other Unknown EDO
- Installed Size 0bh - 2048 [single bank]
- Enabled Size 0bh - 2048 [single bank]
- Error Status 00h - [No Errors]
- [Memory Module Information (Type 6) - Length 12 - Handle 0007h]
- Socket Designation A1
- Bank Connections 2fh - 2
- Current Speed 47ns
- Current Memory Type 0013h - Other Unknown EDO
- Installed Size 0bh - 2048 [single bank]
- Enabled Size 0bh - 2048 [single bank]
- Error Status 00h - [No Errors]
- [Memory Module Information (Type 6) - Length 12 - Handle 0008h]
- Socket Designation A2
- Bank Connections 3fh - 3
- Current Speed 63ns
- Current Memory Type 0013h - Other Unknown EDO
- Installed Size 8ch - 4096 [double bank]
- Enabled Size 8ch - 4096 [double bank]
- Error Status 00h - [No Errors]
- [Memory Module Information (Type 6) - Length 12 - Handle 0009h]
- Socket Designation A3
- Bank Connections 4fh - 4
- Current Speed 79ns
- Current Memory Type 0013h - Other Unknown EDO
- Installed Size 0bh - 2048 [single bank]
- Enabled Size 0bh - 2048 [single bank]
- Error Status 00h - [No Errors]
- [Cache Information (Type 7) - Length 19 - Handle 000ah]
- Socket Designation Internal Cache
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0080h - 128K
- Installed Size 0080h - 128K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Unknown
- System Cache Type Unknown
- Associativity Unknown
- [Cache Information (Type 7) - Length 19 - Handle 000bh]
- Socket Designation Internal Cache
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0080h - 128K
- Installed Size 0080h - 128K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Unknown
- System Cache Type Unknown
- Associativity Unknown
- [Cache Information (Type 7) - Length 19 - Handle 000ch]
- Socket Designation External Cache
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 0200h - 512K
- Installed Size 0200h - 512K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Unknown
- System Cache Type Unknown
- Associativity Unknown
- [Cache Information (Type 7) - Length 19 - Handle 000dh]
- Socket Designation External Cache
- Cache Configuration 0001h - WT Disabled Int NonSocketed L2
- Maximum Cache Size 0400h - 1024K
- Installed Size 0000h - 0K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Unknown
- System Cache Type Unknown
- Associativity Unknown
- [Physical Memory Array (Type 16) - Length 15 - Handle 0023h]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 16777216KB
- Number of Memory Devices 4
- [Memory Device (Type 17) - Length 27 - Handle 0024h]
- Physical Memory Array Handle 0023h
- Total Width 64 bits
- Data Width 64 bits
- Size 2048MB
- Form Factor 09h - DIMM
- Device Locator A0
- Bank Locator Bank0/1
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 1600MHz
- Manufacturer None
- Part Number None
- [Memory Device (Type 17) - Length 27 - Handle 0025h]
- Physical Memory Array Handle 0023h
- Total Width 64 bits
- Data Width 64 bits
- Size 2048MB
- Form Factor 09h - DIMM
- Device Locator A1
- Bank Locator Bank2/3
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 1600MHz
- Manufacturer None
- Part Number None
- [Memory Device (Type 17) - Length 27 - Handle 0026h]
- Physical Memory Array Handle 0023h
- Total Width 64 bits
- Data Width 64 bits
- Size 4096MB
- Form Factor 09h - DIMM
- Device Locator A2
- Bank Locator Bank4/5
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 1600MHz
- Manufacturer None
- Part Number None
- [Memory Device (Type 17) - Length 27 - Handle 0027h]
- Physical Memory Array Handle 0023h
- Total Width 64 bits
- Data Width 64 bits
- Size 2048MB
- Form Factor 09h - DIMM
- Device Locator A3
- Bank Locator Bank6/7
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 1600MHz
- Manufacturer None
- Part Number None
- [Memory Array Mapped Address (Type 19) - Length 15 - Handle 0028h]
- Starting Address 00000000h
- Ending Address 009fffffh
- Memory Array Handle 0023h
- Partition Width 01
- [Memory Device Mapped Address (Type 20) - Length 19 - Handle 0029h]
- Starting Address 00000000h
- Ending Address 001fffffh
- Memory Device Handle 0024h
- Mem Array Mapped Adr Handle 0028h
- Partition Row Position 01
- Interleave Position [None]
- Interleave Data Depth [None]
- [Memory Device Mapped Address (Type 20) - Length 19 - Handle 002ah]
- Starting Address 00200000h
- Ending Address 003fffffh
- Memory Device Handle 0025h
- Mem Array Mapped Adr Handle 0028h
- Partition Row Position 01
- Interleave Position [None]
- Interleave Data Depth [None]
- [Memory Device Mapped Address (Type 20) - Length 19 - Handle 002bh]
- Starting Address 00400000h
- Ending Address 007fffffh
- Memory Device Handle 0026h
- Mem Array Mapped Adr Handle 0028h
- Partition Row Position 01
- Interleave Position [None]
- Interleave Data Depth [None]
- [Memory Device Mapped Address (Type 20) - Length 19 - Handle 002ch]
- Starting Address 00800000h
- Ending Address 009fffffh
- Memory Device Handle 0027h
- Mem Array Mapped Adr Handle 0028h
- Partition Row Position 01
- Interleave Position [None]
- Interleave Data Depth [None]
- ========================================================================
- =================== Dump File: 072617-64937-01.dmp ===================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 15063 MP (6 procs) Free x64
- Product: WinNt, suite: TerminalServer SingleUserTS
- Built by: 15063.0.amd64fre.rs2_release.170317-1834
- Kernel base = 0xfffff800`f320c000 PsLoadedModuleList = 0xfffff800`f35585a0
- Debug session time: Wed Jul 26 23:01:31.321 2017 (UTC - 4:00)
- System Uptime: 0 days 0:51:35.242
- BugCheck EF, {ffff90898fa6c7c0, 0, 0, 0}
- errfg" bg="errbg">ETW minidump data unavailable
- Probably caused by : ntkrnlmp.exe ( nt!PspCatchCriticalBreak+c9 )
- Followup: MachineOwner
- CRITICAL_PROCESS_DIED (ef)
- A critical system process died
- Arguments:
- Arg1: ffff90898fa6c7c0, Process object or thread object
- Arg2: 0000000000000000, If this is 0, a process died. If this is 1, a thread died.
- Arg3: 0000000000000000
- Arg4: 0000000000000000
- Debugging Details:
- ETW minidump data unavailable
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- BUILD_VERSION_STRING: 10.0.15063.413 (WinBuild.160101.0800)
- SYSTEM_MANUFACTURER: Gigabyte Technology Co., Ltd.
- SYSTEM_PRODUCT_NAME: GA-78LMT-USB3
- BIOS_VENDOR: Award Software International, Inc.
- BIOS_VERSION: FA
- BIOS_DATE: 04/23/2013
- BASEBOARD_MANUFACTURER: Gigabyte Technology Co., Ltd.
- BASEBOARD_PRODUCT: GA-78LMT-USB3
- BASEBOARD_VERSION: SEx
- DUMP_TYPE: 2
- PROCESS_NAME: svchost.exe
- CRITICAL_PROCESS: svchost.exe
- EXCEPTION_RECORD: ffffc8010c61ebb0 -- (.exr 0xffffc8010c61ebb0)
- ExceptionAddress: 000000c1dc280ff8
- ExceptionCode: 00000002
- ExceptionFlags: 00000000
- NumberParameters: 0
- EXCEPTION_CODE: (Win32) 0x2 (2) - The system cannot find the file specified.
- ERROR_CODE: (NTSTATUS) 0x2 - STATUS_WAIT_2
- CPU_COUNT: 6
- CPU_MHZ: c8e
- CPU_VENDOR: AuthenticAMD
- CPU_FAMILY: 10
- CPU_MODEL: a
- CPU_STEPPING: 0
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
- BUGCHECK_STR: 0xEF
- CURRENT_IRQL: 0
- EXCEPTION_CODE_STR: 2
- LAST_CONTROL_TRANSFER: from fffff800f38ebf51 to fffff800f33783f0
- STACK_TEXT:
- ffffc801`0c61e098 fffff800`f38ebf51 : 00000000`000000ef ffff9089`8fa6c7c0 00000000`00000000 00000000`00000000 : nt!KeBugCheckEx
- ffffc801`0c61e0a0 fffff800`f3827a6d : ffff9089`8fa6c7c0 00000000`00000001 ffff9089`8fa6c7c0 fffff800`f326f059 : nt!PspCatchCriticalBreak+0xc9
- ffffc801`0c61e0f0 fffff800`f37070f6 : ffff9089`00000000 ffff9089`8fa6c7c0 00000000`00000001 ffff9089`8fa6c7c0 : nt!PspTerminateAllThreads+0x120871
- ffffc801`0c61e160 fffff800`f3706eb7 : ffffffff`ffffffff ffff9089`8fa6c7c0 ffff9089`8fa6c7c0 fffff800`f326f200 : nt!PspTerminateProcess+0xde
- ffffc801`0c61e1a0 fffff800`f3383313 : ffff9089`8fa6c7c0 ffff9089`8fb00080 ffffc801`0c61e290 ffffc801`0c61e3e0 : nt!NtTerminateProcess+0xa7
- ffffc801`0c61e210 fffff800`f337b5d0 : fffff800`f3236f2f ffffc801`0c61eb98 ffffc801`0c61eb98 ffffc801`0c61e3e0 : nt!KiSystemServiceCopyEnd+0x13
- ffffc801`0c61e3a8 fffff800`f3236f2f : ffffc801`0c61eb98 ffffc801`0c61eb98 ffffc801`0c61e3e0 ffffc801`0c61eb98 : nt!KiServiceLinkage
- ffffc801`0c61e3b0 fffff800`f338388e : ffffc801`0c61ebb0 000000c1`00000000 ffffc801`0c61ec00 00000000`00000001 : nt!KiDispatchException+0x5ef
- ffffc801`0c61ea60 fffff800`f3381d57 : ffff9089`8fb00080 000001d8`94c945e0 00000000`00000000 00000000`00000000 : nt!KiExceptionDispatch+0xce
- ffffc801`0c61ec40 00007ffe`6bcb9935 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x217
- 000000c1`dc280f60 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffe`6bcb9935
- STACK_COMMAND: kb
- THREAD_SHA1_HASH_MOD_FUNC: f6b0f7fafbd5253fc3d42ad0a11af14fddabdcf0
- THREAD_SHA1_HASH_MOD_FUNC_OFFSET: efe92f4eb616323a9b7827c3a48553119101f25d
- THREAD_SHA1_HASH_MOD: bc100a5647b828107ac4e18055e00abcbe1ec406
- FOLLOWUP_IP:
- nt!PspCatchCriticalBreak+c9
- fffff800`f38ebf51 cc int 3
- FAULT_INSTR_CODE: ff8440cc
- SYMBOL_STACK_INDEX: 1
- SYMBOL_NAME: nt!PspCatchCriticalBreak+c9
- FOLLOWUP_NAME: MachineOwner
- MODULE_NAME: nt
- IMAGE_NAME: ntkrnlmp.exe
- DEBUG_FLR_IMAGE_TIMESTAMP: 59327910
- IMAGE_VERSION: 10.0.15063.413
- BUCKET_ID_FUNC_OFFSET: c9
- FAILURE_BUCKET_ID: 0xEF_svchost.exe_BUGCHECK_CRITICAL_PROCESS_8fb00080_nt!PspCatchCriticalBreak
- BUCKET_ID: 0xEF_svchost.exe_BUGCHECK_CRITICAL_PROCESS_8fb00080_nt!PspCatchCriticalBreak
- PRIMARY_PROBLEM_CLASS: 0xEF_svchost.exe_BUGCHECK_CRITICAL_PROCESS_8fb00080_nt!PspCatchCriticalBreak
- TARGET_TIME: 2017-07-27T03:01:31.000Z
- OSBUILD: 15063
- OSSERVICEPACK: 413
- SERVICEPACK_NUMBER: 0
- OS_REVISION: 0
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- OSPLATFORM_TYPE: x64
- OSNAME: Windows 10
- OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
- USER_LCID: 0
- OSBUILD_TIMESTAMP: 2017-06-03 04:53:36
- BUILDDATESTAMP_STR: 160101.0800
- BUILDLAB_STR: WinBuild
- BUILDOSVER_STR: 10.0.15063.413
- ANALYSIS_SESSION_ELAPSED_TIME: d25
- ANALYSIS_SOURCE: KM
- FAILURE_ID_HASH_STRING: km:0xef_svchost.exe_bugcheck_critical_process_8fb00080_nt!pspcatchcriticalbreak
- FAILURE_ID_HASH: {23a99615-bc05-a082-c262-194be341870e}
- Followup: MachineOwner
- ========================================================================
- =================== Dump File: 070917-55406-01.dmp ===================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 15063 MP (6 procs) Free x64
- Product: WinNt, suite: TerminalServer SingleUserTS
- Built by: 15063.0.amd64fre.rs2_release.170317-1834
- Kernel base = 0xfffff802`3ae7c000 PsLoadedModuleList = 0xfffff802`3b1c85a0
- Debug session time: Sun Jul 9 22:18:50.161 2017 (UTC - 4:00)
- System Uptime: 0 days 0:09:00.839
- BugCheck D1, {fffff8023cf013e0, 2, 8, fffff8023cf013e0}
- Probably caused by : ntkrnlmp.exe ( nt!KiPageFault+23d )
- Followup: MachineOwner
- DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
- An attempt was made to access a pageable (or completely invalid) address at an
- interrupt request level (IRQL) that is too high. This is usually
- caused by drivers using improper addresses.
- If kernel debugger is available get stack backtrace.
- Arguments:
- Arg1: fffff8023cf013e0, memory referenced
- Arg2: 0000000000000002, IRQL
- Arg3: 0000000000000008, value 0 = read operation, 1 = write operation
- Arg4: fffff8023cf013e0, address which referenced memory
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- BUILD_VERSION_STRING: 10.0.15063.413 (WinBuild.160101.0800)
- SYSTEM_MANUFACTURER: Gigabyte Technology Co., Ltd.
- SYSTEM_PRODUCT_NAME: GA-78LMT-USB3
- BIOS_VENDOR: Award Software International, Inc.
- BIOS_VERSION: FA
- BIOS_DATE: 04/23/2013
- BASEBOARD_MANUFACTURER: Gigabyte Technology Co., Ltd.
- BASEBOARD_PRODUCT: GA-78LMT-USB3
- BASEBOARD_VERSION: SEx
- DUMP_TYPE: 2
- READ_ADDRESS: fffff8023b25d358: Unable to get MiVisibleState
- fffff8023cf013e0
- CURRENT_IRQL: 2
- FAULTING_IP:
- +0
- fffff802`3cf013e0 ?? ???
- CPU_COUNT: 6
- CPU_MHZ: c8e
- CPU_VENDOR: AuthenticAMD
- CPU_FAMILY: 10
- CPU_MODEL: a
- CPU_STEPPING: 0
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
- BUGCHECK_STR: AV
- PROCESS_NAME: witcher3.exe
- TRAP_FRAME: ffff9e81a8106550 -- (.trap 0xffff9e81a8106550)
- NOTE: The trap frame does not contain all registers.
- Some register values may be zeroed or incorrect.
- rax=ffffaf0c811d4cc0 rbx=0000000000000000 rcx=ffffaf0c811d4cc0
- rdx=000001fbe8452000 rsi=0000000000000000 rdi=0000000000000000
- rip=fffff8023cf013e0 rsp=ffff9e81a81066e8 rbp=ffff9e81a81067f0
- r8=0000000000000041 r9=000000000000000a r10=ffff970000000000
- r11=0000000000000001 r12=0000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=0000000000000000
- iopl=0 nv up ei pl nz na pe nc
- fffff802`3cf013e0 ?? ???
- Resetting default scope
- LAST_CONTROL_TRANSFER: from fffff8023aff37a9 to fffff8023afe83f0
- FAILED_INSTRUCTION_ADDRESS:
- +0
- fffff802`3cf013e0 ?? ???
- STACK_TEXT:
- ffff9e81`a8106408 fffff802`3aff37a9 : 00000000`0000000a fffff802`3cf013e0 00000000`00000002 00000000`00000008 : nt!KeBugCheckEx
- ffff9e81`a8106410 fffff802`3aff1d7d : 00000000`00001000 00000000`00000000 ffff9e81`a81065f9 fffff802`3b0fb770 : nt!KiBugCheckDispatch+0x69
- ffff9e81`a8106550 fffff802`3cf013e0 : fffff802`3af006c1 00000003`00000000 00000000`00000001 00000000`00000020 : nt!KiPageFault+0x23d
- ffff9e81`a81066e8 fffff802`3af006c1 : 00000003`00000000 00000000`00000001 00000000`00000020 00000000`00000000 : 0xfffff802`3cf013e0
- ffff9e81`a81066f0 fffff802`3aefb52d : ffffaf0c`811d4d88 ffffaf0c`8122c7c0 ffffaf0c`811d4d88 ffffaf0c`811d47c0 : nt!MiDeleteVirtualAddresses+0x401
- ffff9e81`a81069a0 fffff802`3b33080c : 000001fb`e8450000 ffffaf0c`811a3500 00000000`00000a88 00000000`00000000 : nt!MiDeleteVad+0x3ad
- ffff9e81`a8106b20 fffff802`3b3a67d6 : ffffaf0c`811d47c0 00000096`00000008 ffffaf0c`7e8bdf20 000001fb`e8450000 : nt!MiUnmapViewOfSection+0xec
- ffff9e81`a8106bf0 fffff802`3aff3313 : ffffaf0c`8122c7c0 ffffaf0c`8127b680 ffff9e81`a8106cc0 ffffaf0c`811d47c0 : nt!NtUnmapViewOfSectionEx+0x86
- ffff9e81`a8106c40 00007ffa`1eef58f4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
- 00000096`89993bc8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffa`1eef58f4
- STACK_COMMAND: kb
- THREAD_SHA1_HASH_MOD_FUNC: 44368a842df743395f386b744319f95a840da82e
- THREAD_SHA1_HASH_MOD_FUNC_OFFSET: b55476803df26cfc3d002b44cd8b94ba26de0c83
- THREAD_SHA1_HASH_MOD: cb5f414824c2521bcc505eaa03e92fa10922dad8
- FOLLOWUP_IP:
- nt!KiPageFault+23d
- fffff802`3aff1d7d 33c0 xor eax,eax
- FAULT_INSTR_CODE: ffb0c033
- SYMBOL_STACK_INDEX: 2
- SYMBOL_NAME: nt!KiPageFault+23d
- FOLLOWUP_NAME: MachineOwner
- MODULE_NAME: nt
- IMAGE_NAME: ntkrnlmp.exe
- DEBUG_FLR_IMAGE_TIMESTAMP: 59327910
- IMAGE_VERSION: 10.0.15063.413
- BUCKET_ID_FUNC_OFFSET: 23d
- FAILURE_BUCKET_ID: AV_CODE_AV_BAD_IP_nt!KiPageFault
- BUCKET_ID: AV_CODE_AV_BAD_IP_nt!KiPageFault
- PRIMARY_PROBLEM_CLASS: AV_CODE_AV_BAD_IP_nt!KiPageFault
- TARGET_TIME: 2017-07-10T02:18:50.000Z
- OSBUILD: 15063
- OSSERVICEPACK: 413
- SERVICEPACK_NUMBER: 0
- OS_REVISION: 0
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- OSPLATFORM_TYPE: x64
- OSNAME: Windows 10
- OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
- USER_LCID: 0
- OSBUILD_TIMESTAMP: 2017-06-03 04:53:36
- BUILDDATESTAMP_STR: 160101.0800
- BUILDLAB_STR: WinBuild
- BUILDOSVER_STR: 10.0.15063.413
- ANALYSIS_SESSION_ELAPSED_TIME: 926
- ANALYSIS_SOURCE: KM
- FAILURE_ID_HASH_STRING: km:av_code_av_bad_ip_nt!kipagefault
- FAILURE_ID_HASH: {73cd60cc-83fa-6b76-df08-1961c31d7403}
- Followup: MachineOwner
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement