Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ========================== AUTO DUMP ANALYZER ==========================
- Auto Dump Analyzer
- Version: 0.91
- Time to analyze file(s): 00 hours and 02 minutes and 18 seconds
- ================================= BIOS =================================
- VENDOR: American Megatrends Inc.
- VERSION: P1.10
- DATE: 12/04/2015
- ============================= MOTHERBOARD ==============================
- MANUFACTURER: ASRock
- PRODUCT: 970A-G/3.1
- ================================= RAM ==================================
- Size Speed Manufacturer Part No.
- -------------- -------------- ------------------- ----------------------
- 8192MB 1600MHz Kingston KHX1600C10D3/8G
- 0MHz A1_Manufacturer1 Array1_PartNumber1
- 8192MB 1600MHz Kingston KHX1600C10D3/8G
- 0MHz A1_Manufacturer3 Array1_PartNumber3
- ================================= CPU ==================================
- Processor Version: AMD FX-8320E Eight-Core Processor
- COUNT: 8
- MHZ: 3193
- VENDOR: AuthenticAMD
- FAMILY: 15
- MODEL: 2
- STEPPING: 0
- ================================== OS ==================================
- Product: WinNt, suite: TerminalServer SingleUserTS
- BUILD_VERSION: 10.0.18362.959 (WinBuild.160101.0800)
- BUILD: 18362
- SERVICEPACK: 959
- PLATFORM_TYPE: x64
- NAME: Windows 10
- EDITION: Windows 10 WinNt TerminalServer SingleUserTS
- BUILD_TIMESTAMP: unknown_date
- BUILDDATESTAMP: 160101.0800
- BUILDLAB: WinBuild
- BUILDOSVER: 10.0.18362.959
- =============================== DEBUGGER ===============================
- Microsoft (R) Windows Debugger Version 10.0.14321.1024 AMD64
- Copyright (c) Microsoft Corporation. All rights reserved.
- =============================== COMMENTS ===============================
- * Information gathered from different dump files may be different. If
- Windows updates between two dump files, two or more OS versions may
- be shown above.
- * If the user updates the BIOS between dump files, two or more versions
- and dates may be shown above.
- * More RAM information can be found below in a full BIOS section.
- ========================================================================
- ======================= Dump #1: ANALYZE VERBOSE =======================
- ====================== File: 071920-63500-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 18362 MP (8 procs) Free x64
- Kernel base = 0xfffff802`7a600000 PsLoadedModuleList = 0xfffff802`7aa48190
- Debug session time: Sun Jul 19 05:31:23.968 2020 (UTC - 4:00)
- System Uptime: 3 days 17:41:00.740
- BugCheck 1000007F, {8, ffffe6008aac40b0, be48049895, fffff8027a7c958a}
- Probably caused by : memory_corruption
- Followup: memory_corruption
- UNEXPECTED_KERNEL_MODE_TRAP_M (1000007f)
- This means a trap occurred in kernel mode, and it's a trap of a kind
- that the kernel isn't allowed to have/catch (bound trap) or that
- is always instant death (double fault). The first number in the
- bugcheck params is the number of the trap (8 = double fault, etc)
- Consult an Intel x86 family manual to learn more about what these
- traps are. Here is a *portion* of those codes:
- If kv shows a taskGate
- use .tss on the part before the colon, then kv.
- Else if kv shows a trapframe
- use .trap on that value
- Else
- .trap on the appropriate frame will show where the trap was taken
- (on x86, this will be the ebp that goes with the procedure KiTrap)
- Endif
- kb will then show the corrected stack.
- Arguments:
- Arg1: 0000000000000008, EXCEPTION_DOUBLE_FAULT
- Arg2: ffffe6008aac40b0
- Arg3: 000000be48049895
- Arg4: fffff8027a7c958a
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- DUMP_FILE_ATTRIBUTES: 0x8
- Kernel Generated Triage Dump
- BUGCHECK_STR: 0x7f_8
- BAD_STACK_POINTER: 000000be48049895
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- PROCESS_NAME: The Universim.
- CURRENT_IRQL: 2
- UNALIGNED_STACK_POINTER: 000000be48049895
- LAST_CONTROL_TRANSFER: from 0000000000000000 to fffff8027a7c958a
- STACK_TEXT:
- 000000be`48049895 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!SwapContext+0x1aa
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
- fffff8027a7c9433-fffff8027a7c9434 2 bytes - nt!SwapContext+53
- [ 48 ff:4c 8b ]
- fffff8027a7c943a-fffff8027a7c943d 4 bytes - nt!SwapContext+5a (+0x07)
- [ 0f 1f 44 00:e8 e1 0c 8f ]
- fffff8027a7c986e-fffff8027a7c986f 2 bytes - nt!SwapContext+48e (+0x434)
- [ 48 ff:4c 8b ]
- fffff8027a7c9875-fffff8027a7c9878 4 bytes - nt!SwapContext+495 (+0x07)
- [ 0f 1f 44 00:e8 a6 08 8f ]
- fffff8027a7c9fe6-fffff8027a7c9fea 5 bytes - nt!tcpxsum+96 (+0x771)
- [ 41 ff e1 cc cc:e8 d5 a1 18 00 ]
- 17 errors : !nt (fffff8027a7c9433-fffff8027a7c9fea)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-07-19T09:31:23.000Z
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #1: 3RD PARTY DRIVERS ======================
- Feb 18 2010 - amdiox64.sys - AMD IO driver
- Dec 04 2012 - amdide64.sys - AMD SATA Controller driver http://support.amd.com/
- Feb 17 2014 - usbfilter.sys - AMD USB Filter driver
- Mar 31 2015 - HWiNFO64A.SYS - HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
- Apr 21 2016 - tap0901.sys - TAP-Win32 Virtual Private Network Driver 0901 (OpenVPN by OpenVPN Technologies) https://openvpn.net/
- Feb 09 2017 - tib.sys - Acronis Backup Archive (TIB) Explorer
- Feb 10 2017 - tib_mounter.sys - Acronis Backup Archive Mounter driver (Acronis International GmbH)
- May 14 2017 - ElbyCDIO.sys - ElbyCD Windows Input/Output driver http://www.elby.ch/
- Jun 28 2017 - volume_tracker.sys - Acronis Volume Tracker driver (Acronis International GmbH)
- Sep 11 2017 - rtwlanu.sys - Realtek WLAN USB NDIS Driver https://www.realtek.com/en/
- Nov 21 2017 - virtual_file.sys - Acronis Virtual File driver (Acronis International GmbH)
- Feb 21 2018 - fltsrv.sys - Acronis Storage Filter Management driver http://www.acronis.com/
- Jul 10 2018 - asmthub3.sys - ASMedia USB 3.0 Hub driver http://www.asmedia.com.tw/
- Jul 10 2018 - asmtxhci.sys - ASMedia USB 3.0 driver http://www.asmedia.com.tw/
- Jul 20 2018 - snapman.sys - Acronis Snapshots Manager from Acronis Snapshots Manager or Seagate DiscWizard
- Aug 03 2018 - file_tracker.sys - File Tracker Minifilter driver (Acronis International GmbH)
- Aug 09 2018 - dokan1.sys - Dokan Project driver (ISLOG)
- Apr 22 2019 - eubakup.sys - EaseUS Todo Backup
- Apr 22 2019 - EUBKMON.sys - EaseUS Todo Backup Kernel Monitor driver
- Apr 22 2019 - eudskacs.sys - EaseUS Todo Backup Disk Access driver
- Apr 22 2019 - EuFdDisk.sys - EaseUS Todo Backup Image Preview driver
- Jul 02 2019 - RTKVHD64.sys - Realtek Audio System driver https://www.realtek.com/en/
- Nov 15 2019 - AtihdWT6.sys - AMD High Definition Audio Function driver http://support.amd.com/
- Feb 12 2020 - rt640x64.sys - Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Feb 22 2020 - VClone.sys - Virtual Clone CD driver http://www.elby.ch/
- Apr 21 2020 - atikmdag.sys - ATI Radeon Kernel Mode driver
- Apr 21 2020 - atikmpag.sys - ATI video card driver
- ================== Dump #1: 3RD PARTY DRIVERS (FULL) ===================
- Image name: amdiox64.sys
- Search : https://www.google.com/search?q=amdiox64.sys
- ADA Info : AMD IO driver
- Timestamp : Thu Feb 18 2010
- Image name: amdide64.sys
- Search : https://www.google.com/search?q=amdide64.sys
- ADA Info : AMD SATA Controller driver http://support.amd.com/
- Timestamp : Tue Dec 4 2012
- Image name: usbfilter.sys
- Search : https://www.google.com/search?q=usbfilter.sys
- ADA Info : AMD USB Filter driver
- Timestamp : Mon Feb 17 2014
- Image name: HWiNFO64A.SYS
- Search : https://www.google.com/search?q=HWiNFO64A.SYS
- ADA Info : HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
- Timestamp : Tue Mar 31 2015
- Image name: tap0901.sys
- Search : https://www.google.com/search?q=tap0901.sys
- ADA Info : TAP-Win32 Virtual Private Network Driver 0901 (OpenVPN by OpenVPN Technologies) https://openvpn.net/
- Timestamp : Thu Apr 21 2016
- Image name: tib.sys
- Search : https://www.google.com/search?q=tib.sys
- ADA Info : Acronis Backup Archive (TIB) Explorer
- Timestamp : Thu Feb 9 2017
- Image name: tib_mounter.sys
- Search : https://www.google.com/search?q=tib_mounter.sys
- ADA Info : Acronis Backup Archive Mounter driver (Acronis International GmbH)
- Timestamp : Fri Feb 10 2017
- Image name: ElbyCDIO.sys
- Search : https://www.google.com/search?q=ElbyCDIO.sys
- ADA Info : ElbyCD Windows Input/Output driver http://www.elby.ch/
- Timestamp : Sun May 14 2017
- Image name: volume_tracker.sys
- Search : https://www.google.com/search?q=volume_tracker.sys
- ADA Info : Acronis Volume Tracker driver (Acronis International GmbH)
- Timestamp : Wed Jun 28 2017
- Image name: rtwlanu.sys
- Search : https://www.google.com/search?q=rtwlanu.sys
- ADA Info : Realtek WLAN USB NDIS Driver https://www.realtek.com/en/
- Timestamp : Mon Sep 11 2017
- Image name: virtual_file.sys
- Search : https://www.google.com/search?q=virtual_file.sys
- ADA Info : Acronis Virtual File driver (Acronis International GmbH)
- Timestamp : Tue Nov 21 2017
- Image name: fltsrv.sys
- Search : https://www.google.com/search?q=fltsrv.sys
- ADA Info : Acronis Storage Filter Management driver http://www.acronis.com/
- Timestamp : Wed Feb 21 2018
- Image name: asmthub3.sys
- Search : https://www.google.com/search?q=asmthub3.sys
- ADA Info : ASMedia USB 3.0 Hub driver http://www.asmedia.com.tw/
- Timestamp : Tue Jul 10 2018
- Image name: asmtxhci.sys
- Search : https://www.google.com/search?q=asmtxhci.sys
- ADA Info : ASMedia USB 3.0 driver http://www.asmedia.com.tw/
- Timestamp : Tue Jul 10 2018
- Image name: snapman.sys
- Search : https://www.google.com/search?q=snapman.sys
- ADA Info : Acronis Snapshots Manager from Acronis Snapshots Manager or Seagate DiscWizard
- Timestamp : Fri Jul 20 2018
- Image name: file_tracker.sys
- Search : https://www.google.com/search?q=file_tracker.sys
- ADA Info : File Tracker Minifilter driver (Acronis International GmbH)
- Timestamp : Fri Aug 3 2018
- Image name: dokan1.sys
- Search : https://www.google.com/search?q=dokan1.sys
- ADA Info : Dokan Project driver (ISLOG)
- Timestamp : Thu Aug 9 2018
- Image name: eubakup.sys
- Search : https://www.google.com/search?q=eubakup.sys
- ADA Info : EaseUS Todo Backup
- Timestamp : Mon Apr 22 2019
- Image name: EUBKMON.sys
- Search : https://www.google.com/search?q=EUBKMON.sys
- ADA Info : EaseUS Todo Backup Kernel Monitor driver
- Timestamp : Mon Apr 22 2019
- Image name: eudskacs.sys
- Search : https://www.google.com/search?q=eudskacs.sys
- ADA Info : EaseUS Todo Backup Disk Access driver
- Timestamp : Mon Apr 22 2019
- Image name: EuFdDisk.sys
- Search : https://www.google.com/search?q=EuFdDisk.sys
- ADA Info : EaseUS Todo Backup Image Preview driver
- Timestamp : Mon Apr 22 2019
- Image name: RTKVHD64.sys
- Search : https://www.google.com/search?q=RTKVHD64.sys
- ADA Info : Realtek Audio System driver https://www.realtek.com/en/
- Timestamp : Tue Jul 2 2019
- Image name: AtihdWT6.sys
- Search : https://www.google.com/search?q=AtihdWT6.sys
- ADA Info : AMD High Definition Audio Function driver http://support.amd.com/
- Timestamp : Fri Nov 15 2019
- Image name: rt640x64.sys
- Search : https://www.google.com/search?q=rt640x64.sys
- ADA Info : Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Timestamp : Wed Feb 12 2020
- Image name: VClone.sys
- Search : https://www.google.com/search?q=VClone.sys
- ADA Info : Virtual Clone CD driver http://www.elby.ch/
- Timestamp : Sat Feb 22 2020
- Image name: atikmdag.sys
- Search : https://www.google.com/search?q=atikmdag.sys
- ADA Info : ATI Radeon Kernel Mode driver
- Timestamp : Tue Apr 21 2020
- Image name: atikmpag.sys
- Search : https://www.google.com/search?q=atikmpag.sys
- ADA Info : ATI video card driver
- Timestamp : Tue Apr 21 2020
- ====================== Dump #1: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- amdppm.sys Processor Device Driver
- atapi.sys ATAPI IDE MiniPort driver (Microsoft)
- ataport.SYS ATAPI Driver Extension (Microsoft)
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- csc.sys Windows Client Side Caching driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_atapi.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_ataport.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kdcom.dll Kernel Debugger HW Extension DLL (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate.dll Media Center Update (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mqac.sys Message Queuing Device driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- ndisuio.sys NDIS User mode I/O driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- nwifi.sys NativeWiFi Miniport Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- PCIIDEX.SYS PCI IDE Bus driver file (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdpdr.sys RDP Device redirector (Microsoft)
- rdpvideominiport.sys RDP Video Miniport driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- serenum.sys Serial Port Enumerator (Microsoft)
- serial.sys Serial Device Driver
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- tsusbhub.sys USB-Hub driver (Microsoft)
- ucx01000.sys USB Controller Extension (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- usbehci.sys EHCI eUSB Miniport Driver (Microsoft)
- usbhub.sys Default Hub Driver for USB (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- usbohci.sys OHCI USB Miniport Driver (Microsoft)
- USBPORT.SYS USB 1.1 & 2.0 Port Driver (Microsoft)
- USBSTOR.SYS USB Mass Storage Class driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwifibus.sys Virtual Wireless Bus driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- vwifimp.sys Virtual WiFi Miniport Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- wdiwifi.sys WDI Driver Framework driver (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- winquic.sys QUIC Transport Protocol driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WpdUpFltr.sys Portable Device Upper Class Filter driver (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- WUDFRd.sys Windows Driver Foundation - User-mode Driver Framework Reflector driver (Microsoft)
- ====================== Dump #1: UNLOADED MODULES =======================
- fffff802`76ef0000 fffff802`76f00000 hiber_atapor
- fffff802`76f00000 fffff802`76f0e000 hiber_atapi.
- fffff802`76f10000 fffff802`76f2e000 hiber_dumpfv
- fffff802`77df0000 fffff802`77e00000 hiber_atapor
- fffff802`76ec0000 fffff802`76ece000 hiber_atapi.
- fffff802`76ed0000 fffff802`76eee000 hiber_dumpfv
- fffff802`76f00000 fffff802`76f11000 MpKslDrv.sys
- fffff802`76f20000 fffff802`76f30000 hiber_atapor
- fffff802`76f30000 fffff802`76f3e000 hiber_atapi.
- fffff802`76f40000 fffff802`76f5e000 hiber_dumpfv
- fffff802`76ec0000 fffff802`76ed0000 hiber_atapor
- fffff802`76ed0000 fffff802`76ede000 hiber_atapi.
- fffff802`76ee0000 fffff802`76efe000 hiber_dumpfv
- fffff802`7ed80000 fffff802`7ed90000 dump_ataport
- fffff802`7eda0000 fffff802`7edae000 dump_atapi.s
- fffff802`7edd0000 fffff802`7edee000 dump_dumpfve
- fffff802`7d7c0000 fffff802`7d7dc000 EhStorClass.
- fffff802`7f650000 fffff802`7f66e000 dam.sys
- fffff802`7d3d0000 fffff802`7d3e1000 WdBoot.sys
- fffff802`7e5d0000 fffff802`7e5e1000 hwpolicy.sys
- ====================== Dump #1: BIOS INFORMATION =======================
- [SMBIOS Data Tables v2.7]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 1611 bytes]
- [BIOS Information (Type 0) - Length 24 - Handle 0000h]
- Vendor American Megatrends Inc.
- BIOS Version P1.10
- BIOS Starting Address Segment f000
- BIOS Release Date 12/04/2015
- BIOS ROM Size 400000
- BIOS Characteristics
- 07: - PCI Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 27: - Keyboard Services Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 32: - BIOS Vendor Reserved
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 4
- BIOS Minor Revision 6
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
- Manufacturer ASRock
- Product 970A-G/3.1
- Version
- Feature Flags 09h
- -1988315424: - -1988315376: - «Eºþ
- Location
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 22 - Handle 0003h]
- Chassis Type Desktop
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 0
- [Processor Information (Type 4) - Length 42 - Handle 0004h]
- Socket Designation CPUSocket
- Processor Type Central Processor
- Processor Family 02h - Unknown
- Processor Manufacturer AMD
- Processor ID 200f6000fffb8b17
- Processor Version AMD FX-8320E Eight-Core Processor
- Processor Voltage 8ch - 1.2V
- External Clock 200MHz
- Max Speed 3200MHz
- Current Speed 3200MHz
- Status Enabled Populated
- Processor Upgrade Specification Reserved
- L1 Cache Handle 0005h
- L2 Cache Handle 0006h
- L3 Cache Handle 0007h
- [Cache Information (Type 7) - Length 19 - Handle 0005h]
- Socket Designation L1-Cache
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0180h - 384K
- Installed Size 0180h - 384K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 2-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0006h]
- Socket Designation L2-Cache
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 2000h - 8192K
- Installed Size 2000h - 8192K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 16-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0007h]
- Socket Designation L3-Cache
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 2000h - 8192K
- Installed Size 2000h - 8192K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity Specification Reserved
- [OEM Strings (Type 11) - Length 5 - Handle 000dh]
- Number of Strings 1
- [Physical Memory Array (Type 16) - Length 23 - Handle 000eh]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 33554432KB
- Number of Memory Devices 4
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 000fh]
- Starting Address 00000000h
- Ending Address 010fc000h
- Memory Array Handle 000eh
- Partition Width 255
- [Memory Device (Type 17) - Length 34 - Handle 0010h]
- Physical Memory Array Handle 000eh
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator A1_DIMM0
- Bank Locator A1_BANK0
- Memory Type 18h - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 1600MHz
- Manufacturer Kingston
- Part Number KHX1600C10D3/8G
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0011h]
- Starting Address 00000000h
- Ending Address 007fffffh
- Memory Device Handle 0010h
- Mem Array Mapped Adr Handle 000fh
- Partition Row Position 01
- Interleave Position [None]
- Interleave Data Depth [None]
- [Memory Device (Type 17) - Length 34 - Handle 0012h]
- Physical Memory Array Handle 000eh
- Total Width 0 bits
- Data Width 64 bits
- Form Factor 09h - DIMM
- Device Locator A1_DIMM1
- Bank Locator A1_BANK1
- Memory Type 02h - Unknown
- Type Detail 0080h - Synchronous
- Speed 0MHz
- Manufacturer A1_Manufacturer1
- Part Number Array1_PartNumber1
- [Memory Device (Type 17) - Length 34 - Handle 0014h]
- Physical Memory Array Handle 000eh
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator A1_DIMM2
- Bank Locator A1_BANK2
- Memory Type 18h - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 1600MHz
- Manufacturer Kingston
- Part Number KHX1600C10D3/8G
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0015h]
- Starting Address 00800000h
- Ending Address 00ffffffh
- Memory Device Handle 0014h
- Mem Array Mapped Adr Handle 000fh
- Partition Row Position 01
- Interleave Position [None]
- Interleave Data Depth [None]
- [Memory Device (Type 17) - Length 34 - Handle 0016h]
- Physical Memory Array Handle 000eh
- Total Width 0 bits
- Data Width 64 bits
- Form Factor 09h - DIMM
- Device Locator A1_DIMM3
- Bank Locator A1_BANK3
- Memory Type 02h - Unknown
- Type Detail 0080h - Synchronous
- Speed 0MHz
- Manufacturer A1_Manufacturer3
- Part Number Array1_PartNumber3
- ========================== Dump #1: Extra #1 ===========================
- 5: kd> !verifier
- fffff8027aa485c0: Unable to get verifier list.
- ========================== Dump #1: Extra #2 ===========================
- 5: kd> !thread
- THREAD ffffb88f3ffde080 Cid 0930.1814 Teb: 0000003b938fc000 Win32Thread: 0000000000000000 RUNNING on processor 5
- Not impersonating
- GetUlongFromAddress: unable to read from fffff8027aa2ca14
- Owning Process ffffb88f3ed130c0 Image: The Universim.
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 20663087
- Context Switch Count 9898917 IdealProcessor: 2
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address 0x00007ff89e109070
- Stack Init ffff8b8e44427c90 Current 000000be48049895
- Base ffff8b8e44428000 Limit ffff8b8e44422000 Call 0000000000000000
- Priority 11 BasePriority 8 PriorityDecrement 2 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- 000000be`48049895 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!SwapContext+0x1aa
Add Comment
Please, Sign In to add comment