Guest User

Untitled

a guest
Jul 22nd, 2017
396
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 93.54 KB | None | 0 0
  1. Microsoft (R) Windows Debugger Version 10.0.14321.1024 X86
  2. Copyright (c) Microsoft Corporation. All rights reserved.
  3.  
  4. ========================================================================
  5. =================== Dump File: 071817-14000-01.dmp ===================
  6. ========================================================================
  7. Mini Kernel Dump File: Only registers and stack trace are available
  8. Windows 10 Kernel Version 15063 MP (8 procs) Free x64
  9. Product: WinNt, suite: TerminalServer SingleUserTS
  10. Built by: 15063.0.amd64fre.rs2_release.170317-1834
  11. Kernel base = 0xfffff800`4ca11000 PsLoadedModuleList = 0xfffff800`4cd5d5e0
  12. Debug session time: Tue Jul 18 15:11:51.986 2017 (UTC - 4:00)
  13. System Uptime: 0 days 0:36:43.745
  14.  
  15. BugCheck 19, {d, ffffb08ca0fd3e20, 9abcecfa570b79e7, 9abcecfa560b79e7}
  16. Probably caused by : Pool_Corruption ( nt!ExDeferredFreePool+22f6 )
  17. Followup: Pool_corruption
  18.  
  19. BAD_POOL_HEADER (19)
  20. The pool is already corrupt at the time of the current request.
  21. This may or may not be due to the caller.
  22. The internal pool links must be walked to figure out a possible cause of
  23. the problem, and then special pool applied to the suspect tags or the driver
  24. verifier to a suspect driver.
  25.  
  26. Arguments:
  27. Arg1: 000000000000000d,
  28. Arg2: ffffb08ca0fd3e20
  29. Arg3: 9abcecfa570b79e7
  30. Arg4: 9abcecfa560b79e7
  31.  
  32. Debugging Details:
  33. DUMP_CLASS: 1
  34. DUMP_QUALIFIER: 400
  35. BUILD_VERSION_STRING: 10.0.15063.483 (WinBuild.160101.0800)
  36. SYSTEM_MANUFACTURER: ASUS
  37. SYSTEM_PRODUCT_NAME: All Series
  38. SYSTEM_SKU: All
  39. BIOS_VENDOR: American Megatrends Inc.
  40. BIOS_VERSION: 2603
  41. BIOS_DATE: 02/22/2016
  42. BASEBOARD_MANUFACTURER: ASUSTeK COMPUTER INC.
  43. BASEBOARD_PRODUCT: H97M-PLUS
  44. BASEBOARD_VERSION: Rev X.0x
  45. DUMP_TYPE: 2
  46. BUGCHECK_STR: 0x19_d
  47. CPU_COUNT: 8
  48. CPU_MHZ: c15
  49. CPU_VENDOR: GenuineIntel
  50. CPU_FAMILY: 6
  51. CPU_MODEL: 3c
  52. CPU_STEPPING: 3
  53. CPU_MICROCODE: 6,3c,3,0 (F,M,S,R) SIG: 1E'00000000 (cache) 1E'00000000 (init)
  54. CUSTOMER_CRASH_COUNT: 1
  55. DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
  56.  
  57. PROCESS_NAME: System
  58.  
  59. CURRENT_IRQL: 2
  60. LAST_CONTROL_TRANSFER: from fffff8004cc92316 to fffff8004cb7d4c0
  61. STACK_TEXT:
  62. fffff800`4edc6698 fffff800`4cc92316 : 00000000`00000019 00000000`0000000d ffffb08c`a0fd3e20 9abcecfa`570b79e7 : nt!KeBugCheckEx
  63. fffff800`4edc66a0 fffff800`4cc91801 : ffffb08c`a1030ca0 fffff800`4cd90bc0 fffff800`4edc67b9 ffffb08c`a1030e10 : nt!ExDeferredFreePool+0x22f6
  64. fffff800`4edc6720 fffff800`abd32fc3 : fffff800`abd3b200 ffffb08c`9d525000 00000000`00000000 ffff6758`00000000 : nt!ExFreePoolWithTag+0x7e1
  65. fffff800`4edc6820 fffff800`abd32df0 : ffffb08c`9d525000 ffffb08c`9d52bc38 00000000`00000000 fffff800`4edc68b9 : HDAudBus!HdaController::ProcessCodecResponses+0x193
  66. fffff800`4edc6870 fffff800`4ca83b6c : fffff800`4a083f80 00000000`00000001 fffff800`4a081180 00000000`00010001 : HDAudBus!HdaController::CodecDpc+0x70
  67. fffff800`4edc6920 fffff800`4ca83477 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiExecuteAllDpcs+0x1dc
  68. fffff800`4edc6a60 fffff800`4cb8056a : 00000000`00000000 fffff800`4a081180 00000000`001a6fe0 fffff800`4ce0aa40 : nt!KiRetireDpcList+0xd7
  69. fffff800`4edc6c60 00000000`00000000 : fffff800`4edc7000 fffff800`4edc1000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x5a
  70. STACK_COMMAND: kb
  71. THREAD_SHA1_HASH_MOD_FUNC: 555de23645b4003f21f317e43f30b63cd2b94d17
  72. THREAD_SHA1_HASH_MOD_FUNC_OFFSET: bb57f068f5a2fc0e8568a4573334bcdd60b9561e
  73. THREAD_SHA1_HASH_MOD: c45ee725c8d5fb0d0409d0de11f98f0bac8ce545
  74. FOLLOWUP_IP:
  75. nt!ExDeferredFreePool+22f6
  76. fffff800`4cc92316 cc int 3
  77. FAULT_INSTR_CODE: cc
  78. SYMBOL_STACK_INDEX: 1
  79. SYMBOL_NAME: nt!ExDeferredFreePool+22f6
  80. FOLLOWUP_NAME: Pool_corruption
  81.  
  82. IMAGE_NAME: Pool_Corruption
  83.  
  84. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  85. IMAGE_VERSION: 10.0.15063.483
  86. MODULE_NAME: Pool_Corruption
  87. BUCKET_ID_FUNC_OFFSET: 22f6
  88. FAILURE_BUCKET_ID: 0x19_d_nt!ExDeferredFreePool
  89. BUCKET_ID: 0x19_d_nt!ExDeferredFreePool
  90. PRIMARY_PROBLEM_CLASS: 0x19_d_nt!ExDeferredFreePool
  91. TARGET_TIME: 2017-07-18T19:11:51.000Z
  92. OSBUILD: 15063
  93. OSSERVICEPACK: 483
  94. SERVICEPACK_NUMBER: 0
  95. OS_REVISION: 0
  96. SUITE_MASK: 272
  97. PRODUCT_TYPE: 1
  98. OSPLATFORM_TYPE: x64
  99. OSNAME: Windows 10
  100. OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
  101. USER_LCID: 0
  102. OSBUILD_TIMESTAMP: 2017-07-07 02:06:35
  103. BUILDDATESTAMP_STR: 160101.0800
  104. BUILDLAB_STR: WinBuild
  105. BUILDOSVER_STR: 10.0.15063.483
  106. ANALYSIS_SESSION_ELAPSED_TIME: 1b6b
  107. ANALYSIS_SOURCE: KM
  108. FAILURE_ID_HASH_STRING: km:0x19_d_nt!exdeferredfreepool
  109. FAILURE_ID_HASH: {c66288ca-3a17-2be7-a2de-d6492b261dd2}
  110. Followup: Pool_corruption
  111.  
  112. =============================== Drivers ================================
  113. ffff98e2`00200000 ffff98e2`00593000 win32kfull (deferred)
  114. Image path: \SystemRoot\System32\win32kfull.sys
  115. Image name: win32kfull.sys
  116. Timestamp: unavailable (00000000)
  117. ffff98e2`005a0000 ffff98e2`007a6000 win32kbase (deferred)
  118. Image path: \SystemRoot\System32\win32kbase.sys
  119. Image name: win32kbase.sys
  120. Timestamp: unavailable (00000000)
  121. ffff98e2`007c0000 ffff98e2`007ca000 TSDDD (deferred)
  122. Image path: \SystemRoot\System32\TSDDD.dll
  123. Image name: TSDDD.dll
  124. Timestamp: unavailable (00000000)
  125. ffff98e2`007d0000 ffff98e2`00811000 cdd (deferred)
  126. Image path: \SystemRoot\System32\cdd.dll
  127. Image name: cdd.dll
  128. Timestamp: unavailable (00000000)
  129. ffff98e2`01010000 ffff98e2`01084000 win32k (deferred)
  130. Image path: \SystemRoot\System32\win32k.sys
  131. Image name: win32k.sys
  132. Timestamp: unavailable (00000000)
  133. fffff800`a5b70000 fffff800`a60e2000 iaStorA (deferred)
  134. Image path: \SystemRoot\System32\drivers\iaStorA.sys
  135. Image name: iaStorA.sys
  136. Timestamp: Wed Jun 3 05:38:57 2015 (556ECB31)
  137. fffff800`a7600000 fffff800`a76c6000 peauth (deferred)
  138. Image path: \SystemRoot\system32\drivers\peauth.sys
  139. Image name: peauth.sys
  140. Timestamp: Sat Dec 9 21:03:08 1989 (2581B95C)
  141. fffff800`a7c80000 fffff800`a81f2000 dump_iaStorA (deferred)
  142. Image path: \SystemRoot\System32\Drivers\dump_iaStorA.sys
  143. Image name: dump_iaStorA.sys
  144. Timestamp: Wed Jun 3 05:38:57 2015 (556ECB31)
  145. fffff800`a84a0000 fffff800`a84cf000 VBoxNetAdp6 (deferred)
  146. Image path: \SystemRoot\system32\DRIVERS\VBoxNetAdp6.sys
  147. Image name: VBoxNetAdp6.sys
  148. Timestamp: Fri Apr 28 11:36:57 2017 (59036199)
  149. fffff800`a8690000 fffff800`a869e000 MpKsld67884e7 (deferred)
  150. Image path: \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{6E96F768-7739-4142-B328-C678276DB02B}\MpKsld67884e7.sys
  151. Image name: MpKsld67884e7.sys
  152. Timestamp: Tue May 19 21:50:37 2015 (555BE86D)
  153. fffff800`a8700000 fffff800`a8706000 AsIO (deferred)
  154. Image path: \SystemRoot\SysWow64\drivers\AsIO.sys
  155. Image name: AsIO.sys
  156. Timestamp: Wed Aug 22 05:54:47 2012 (5034AC67)
  157. fffff800`a87b0000 fffff800`a8c2b000 RTKVHD64 (deferred)
  158. Image path: \SystemRoot\system32\drivers\RTKVHD64.sys
  159. Image name: RTKVHD64.sys
  160. Timestamp: Tue May 5 07:18:22 2015 (5548A6FE)
  161. fffff800`aa720000 fffff800`aa750000 TeeDriverW8x64 (deferred)
  162. Image path: \SystemRoot\System32\drivers\TeeDriverW8x64.sys
  163. Image name: TeeDriverW8x64.sys
  164. Timestamp: Tue Jul 7 13:43:32 2015 (559C0FC4)
  165. fffff800`aa750000 fffff800`aa7d4000 e1d62x64 (deferred)
  166. Image path: \SystemRoot\system32\DRIVERS\e1d62x64.sys
  167. Image name: e1d62x64.sys
  168. Timestamp: Sun Mar 19 10:37:16 2017 (58CE979C)
  169. fffff800`aa910000 fffff800`aa91e000 MpKsl026a38c9 (deferred)
  170. Image path: \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{AD3AF98A-5DD0-4D57-BBB9-DFD2C4126F2C}\MpKsl026a38c9.sys
  171. Image name: MpKsl026a38c9.sys
  172. Timestamp: Tue May 19 21:50:37 2015 (555BE86D)
  173. fffff800`aaa40000 fffff800`aaa75000 nvhda64v (deferred)
  174. Image path: \SystemRoot\system32\drivers\nvhda64v.sys
  175. Image name: nvhda64v.sys
  176. Timestamp: Wed Mar 15 08:48:41 2017 (58C93829)
  177. fffff800`aaf10000 fffff800`abd2d000 nvlddmkm (deferred)
  178. Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_ref_pubwu.inf_amd64_f9309145156afb40\nvlddmkm.sys
  179. Image name: nvlddmkm.sys
  180. Timestamp: Mon May 1 15:55:53 2017 (590792C9)
  181. fffff800`abdc0000 fffff800`abde1000 drmk (deferred)
  182. Image path: \SystemRoot\System32\drivers\drmk.sys
  183. Image name: drmk.sys
  184. Timestamp: ***** Invalid (A01C1986)
  185. fffff800`abdf0000 fffff800`abdf7000 semav6msr64 (deferred)
  186. Image path: \??\C:\Windows\system32\drivers\semav6msr64.sys
  187. Image name: semav6msr64.sys
  188. Timestamp: Fri Jan 24 14:22:40 2014 (52E2BD80)
  189. Unloaded modules:
  190. fffff800`aae30000 fffff800`aae3b000 cldflt.sys
  191. Timestamp: unavailable (00000000)
  192. Checksum: 00000000
  193. ImageSize: 0000B000
  194. fffff800`a6de0000 fffff800`a6def000 dump_storpor
  195. Timestamp: unavailable (00000000)
  196. Checksum: 00000000
  197. ImageSize: 0000F000
  198. fffff800`a7600000 fffff800`a7b72000 dump_iaStorA
  199. Timestamp: unavailable (00000000)
  200. Checksum: 00000000
  201. ImageSize: 00572000
  202. fffff800`a7ba0000 fffff800`a7bbd000 dump_dumpfve
  203. Timestamp: unavailable (00000000)
  204. Checksum: 00000000
  205. ImageSize: 0001D000
  206. fffff800`aa8e0000 fffff800`aa91d000 WUDFRd.sys
  207. Timestamp: unavailable (00000000)
  208. Checksum: 00000000
  209. ImageSize: 0003D000
  210. fffff800`a86e0000 fffff800`a8700000 dam.sys
  211. Timestamp: unavailable (00000000)
  212. Checksum: 00000000
  213. ImageSize: 00020000
  214. fffff800`a5870000 fffff800`a587f000 WdBoot.sys
  215. Timestamp: unavailable (00000000)
  216. Checksum: 00000000
  217. ImageSize: 0000F000
  218. fffff800`a6b80000 fffff800`a6b8f000 hwpolicy.sys
  219. Timestamp: unavailable (00000000)
  220. Checksum: 00000000
  221. ImageSize: 0000F000
  222.  
  223. ============================= BIOS INFO ================================
  224. [SMBIOS Data Tables v2.8]
  225. [DMI Version - 0]
  226. [2.0 Calling Convention - No]
  227. [Table Size - 3817 bytes]
  228. [BIOS Information (Type 0) - Length 24 - Handle 0000h]
  229. Vendor American Megatrends Inc.
  230. BIOS Version 2603
  231. BIOS Starting Address Segment f000
  232. BIOS Release Date 02/22/2016
  233. BIOS ROM Size 800000
  234. BIOS Characteristics
  235. 07: - PCI Supported
  236. 10: - APM Supported
  237. 11: - Upgradeable FLASH BIOS
  238. 12: - BIOS Shadowing Supported
  239. 15: - CD-Boot Supported
  240. 16: - Selectable Boot Supported
  241. 17: - BIOS ROM Socketed
  242. 19: - EDD Supported
  243. 23: - 1.2MB Floppy Supported
  244. 24: - 720KB Floppy Supported
  245. 25: - 2.88MB Floppy Supported
  246. 26: - Print Screen Device Supported
  247. 27: - Keyboard Services Supported
  248. 28: - Serial Services Supported
  249. 29: - Printer Services Supported
  250. 32: - BIOS Vendor Reserved
  251. BIOS Characteristic Extensions
  252. 00: - ACPI Supported
  253. 01: - USB Legacy Supported
  254. 08: - BIOS Boot Specification Supported
  255. 10: - Specification Reserved
  256. 11: - Specification Reserved
  257. BIOS Major Revision 4
  258. BIOS Minor Revision 6
  259. EC Firmware Major Revision 255
  260. EC Firmware Minor Revision 255
  261. [System Information (Type 1) - Length 27 - Handle 0001h]
  262. Manufacturer ASUS
  263. Product Name All Series
  264. Version System Version
  265. UUID 00000000-0000-0000-0000-000000000000
  266. Wakeup Type Power Switch
  267. SKUNumber All
  268. Family ASUS MB
  269. [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
  270. Manufacturer ASUSTeK COMPUTER INC.
  271. Product H97M-PLUS
  272. Version Rev X.0x
  273. Feature Flags 09h
  274. 1739792904: - ?ÿU?ì?ì¡H.Æg3Å?Eü3ÀW?}?Eô?Eø?ÿu
  275. ¸@
  276. 1739792944: - ?ÿU?ì?ì¡H.Æg3Å?Eü3ÀW?}?Eô?Eø?ÿu
  277. ¸@
  278. Chassis Handle 0003h
  279. Board Type 0ah - Processor/Memory Module
  280. Number of Child Handles 0
  281. [System Enclosure (Type 3) - Length 25 - Handle 0003h]
  282. Chassis Type Desktop
  283. Bootup State Safe
  284. Power Supply State Safe
  285. Thermal State Safe
  286. Security Status None
  287. OEM Defined 0
  288. Height 0U
  289. Number of Power Cords 1
  290. Number of Contained Elements 1
  291. Contained Element Size 3
  292. [Onboard Devices Information (Type 10) - Length 8 - Handle 0024h]
  293. Number of Devices 2
  294. 01: Type Video [enabled]
  295. 02: Type Ethernet [enabled]
  296. [OEM Strings (Type 11) - Length 5 - Handle 0025h]
  297. Number of Strings 4
  298. 3 Pink
  299. [System Configuration Options (Type 12) - Length 5 - Handle 0026h]
  300. [Physical Memory Array (Type 16) - Length 23 - Handle 0042h]
  301. Location 03h - SystemBoard/Motherboard
  302. Use 03h - System Memory
  303. Memory Error Correction 03h - None
  304. Maximum Capacity 33554432KB
  305. Number of Memory Devices 4
  306. [Memory Device (Type 17) - Length 40 - Handle 0043h]
  307. Physical Memory Array Handle 0042h
  308. Total Width 64 bits
  309. Data Width 64 bits
  310. Size 4096MB
  311. Form Factor 09h - DIMM
  312. Device Locator DIMM_A1
  313. Bank Locator BANK 0
  314. Memory Type 18h - Specification Reserved
  315. Type Detail 0080h - Synchronous
  316. Speed 1600MHz
  317. Manufacturer 1315
  318. [Memory Device (Type 17) - Length 40 - Handle 0044h]
  319. Physical Memory Array Handle 0042h
  320. Total Width 0 bits
  321. Data Width 0 bits
  322. Form Factor 09h - DIMM
  323. Device Locator DIMM_A2
  324. Bank Locator BANK 1
  325. Memory Type 02h - Unknown
  326. Type Detail 0000h -
  327. Speed 0MHz
  328. [Memory Device (Type 17) - Length 40 - Handle 0045h]
  329. Physical Memory Array Handle 0042h
  330. Total Width 64 bits
  331. Data Width 64 bits
  332. Size 4096MB
  333. Form Factor 09h - DIMM
  334. Device Locator DIMM_B1
  335. Bank Locator BANK 2
  336. Memory Type 18h - Specification Reserved
  337. Type Detail 0080h - Synchronous
  338. Speed 1600MHz
  339. Manufacturer 1315
  340. [Memory Device (Type 17) - Length 40 - Handle 0046h]
  341. Physical Memory Array Handle 0042h
  342. Total Width 0 bits
  343. Data Width 0 bits
  344. Form Factor 09h - DIMM
  345. Device Locator DIMM_B2
  346. Bank Locator BANK 3
  347. Memory Type 02h - Unknown
  348. Type Detail 0000h -
  349. Speed 0MHz
  350. [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0047h]
  351. Starting Address 00000000h
  352. Ending Address 007fffffh
  353. Memory Array Handle 0042h
  354. Partition Width 04
  355. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0048h]
  356. Starting Address 00000000h
  357. Ending Address 003fffffh
  358. Memory Device Handle 0046h
  359. Mem Array Mapped Adr Handle 0047h
  360. Interleave Position 01
  361. Interleave Data Depth 02
  362. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0049h]
  363. Starting Address 00400000h
  364. Ending Address 007fffffh
  365. Memory Device Handle 0046h
  366. Mem Array Mapped Adr Handle 0047h
  367. Interleave Position 02
  368. Interleave Data Depth 02
  369. [Processor Information (Type 4) - Length 42 - Handle 004fh]
  370. Socket Designation SOCKET 1150
  371. Processor Type Central Processor
  372. Processor Family 01h - Other
  373. Processor Manufacturer Intel
  374. Processor ID c3060300fffbebbf
  375. Processor Version Intel(R) Core(TM) i7-4770S CPU @ 3.10GHz
  376. Processor Voltage 8ch - 1.2V
  377. External Clock 100MHz
  378. Max Speed 3900MHz
  379. Current Speed 3100MHz
  380. Status Enabled Populated
  381. Processor Upgrade Specification Reserved
  382. L1 Cache Handle 0050h
  383. L2 Cache Handle 0051h
  384. L3 Cache Handle 0052h
  385. [Cache Information (Type 7) - Length 19 - Handle 0050h]
  386. Socket Designation CPU Internal L1
  387. Cache Configuration 0180h - WB Enabled Int NonSocketed L1
  388. Maximum Cache Size 0100h - 256K
  389. Installed Size 0100h - 256K
  390. Supported SRAM Type 0020h - Synchronous
  391. Current SRAM Type 0020h - Synchronous
  392. Cache Speed 0ns
  393. Error Correction Type ParitySingle-Bit ECC
  394. System Cache Type Other
  395. Associativity 8-way Set-Associative
  396. [Cache Information (Type 7) - Length 19 - Handle 0051h]
  397. Socket Designation CPU Internal L2
  398. Cache Configuration 0181h - WB Enabled Int NonSocketed L2
  399. Maximum Cache Size 0400h - 1024K
  400. Installed Size 0400h - 1024K
  401. Supported SRAM Type 0020h - Synchronous
  402. Current SRAM Type 0020h - Synchronous
  403. Cache Speed 0ns
  404. Error Correction Type Multi-Bit ECC
  405. System Cache Type Unified
  406. Associativity 8-way Set-Associative
  407. [Cache Information (Type 7) - Length 19 - Handle 0052h]
  408. Socket Designation CPU Internal L3
  409. Cache Configuration 0182h - WB Enabled Int NonSocketed L3
  410. Maximum Cache Size 2000h - 8192K
  411. Installed Size 2000h - 8192K
  412. Supported SRAM Type 0020h - Synchronous
  413. Current SRAM Type 0020h - Synchronous
  414. Cache Speed 0ns
  415. Error Correction Type Specification Reserved
  416. System Cache Type Unified
  417. Associativity 16-way Set-Associative
  418.  
  419. ========================================================================
  420. =================== Dump File: 071817-15953-01.dmp ===================
  421. ========================================================================
  422. Mini Kernel Dump File: Only registers and stack trace are available
  423. Windows 10 Kernel Version 15063 MP (8 procs) Free x64
  424. Product: WinNt, suite: TerminalServer SingleUserTS
  425. Built by: 15063.0.amd64fre.rs2_release.170317-1834
  426. Kernel base = 0xfffff802`fa887000 PsLoadedModuleList = 0xfffff802`fabd35e0
  427. Debug session time: Tue Jul 18 14:14:05.704 2017 (UTC - 4:00)
  428. System Uptime: 0 days 0:10:29.337
  429.  
  430. BugCheck 4E, {99, 11117e, 2, 600011000111179}
  431. Probably caused by : memory_corruption
  432. Followup: memory_corruption
  433.  
  434. PFN_LIST_CORRUPT (4e)
  435. Typically caused by drivers passing bad memory descriptor lists (ie: calling
  436. MmUnlockPages twice with the same list, etc). If a kernel debugger is
  437. available get the stack trace.
  438.  
  439. Arguments:
  440. Arg1: 0000000000000099, A PTE or PFN is corrupt
  441. Arg2: 000000000011117e, page frame number
  442. Arg3: 0000000000000002, current page state
  443. Arg4: 0600011000111179, 0
  444.  
  445. Debugging Details:
  446. DUMP_CLASS: 1
  447. DUMP_QUALIFIER: 400
  448. BUILD_VERSION_STRING: 10.0.15063.483 (WinBuild.160101.0800)
  449. SYSTEM_MANUFACTURER: ASUS
  450. SYSTEM_PRODUCT_NAME: All Series
  451. SYSTEM_SKU: All
  452. BIOS_VENDOR: American Megatrends Inc.
  453. BIOS_VERSION: 2603
  454. BIOS_DATE: 02/22/2016
  455. BASEBOARD_MANUFACTURER: ASUSTeK COMPUTER INC.
  456. BASEBOARD_PRODUCT: H97M-PLUS
  457. BASEBOARD_VERSION: Rev X.0x
  458. DUMP_TYPE: 2
  459. BUGCHECK_STR: 0x4E_99
  460. CPU_COUNT: 8
  461. CPU_MHZ: c15
  462. CPU_VENDOR: GenuineIntel
  463. CPU_FAMILY: 6
  464. CPU_MODEL: 3c
  465. CPU_STEPPING: 3
  466. CPU_MICROCODE: 6,3c,3,0 (F,M,S,R) SIG: 1E'00000000 (cache) 1E'00000000 (init)
  467. CUSTOMER_CRASH_COUNT: 1
  468. DEFAULT_BUCKET_ID: CODE_CORRUPTION
  469.  
  470. PROCESS_NAME: MpCmdRun.exe
  471.  
  472. CURRENT_IRQL: 2
  473. LAST_CONTROL_TRANSFER: from fffff802faa2ba2a to fffff802fa9f34c0
  474. STACK_TEXT:
  475. ffff8701`947e7fd8 fffff802`faa2ba2a : 00000000`0000004e 00000000`00000099 00000000`0011117e 00000000`00000002 : nt!KeBugCheckEx
  476. ffff8701`947e7fe0 fffff802`fa90bcc2 : ffffbe3f`fc71ffb8 ffffbe3f`fc71fb80 00000000`0000005b ffffbe3f`fc71eff8 : nt!MiDeletePteRun+0x10fcea
  477. ffff8701`947e8150 fffff802`fa9065bd : ffffbe8d`4383ed88 ffffbe8d`43c6e080 ffffbe8d`4383ed88 ffffbe8d`4383e7c0 : nt!MiDeleteVirtualAddresses+0x972
  478. ffff8701`947e8400 fffff802`fad13217 : ffffbe8d`43c6e080 ffffbe8d`424e2b70 ffffbe8d`424e2b70 ffffbe8d`43c6e080 : nt!MiDeleteVad+0x3ad
  479. ffff8701`947e8580 fffff802`fad136fe : 00000000`00000000 ffffbe8d`43cc6a40 ffffbe8d`424e2b70 ffffbe8d`4383e7c0 : nt!MiCleanVad+0x27
  480. ffff8701`947e85b0 fffff802`fad5154f : 00000000`00040000 00000000`00000000 ffffbe8d`4383e7c0 ffffbe8d`00000000 : nt!MmCleanProcessAddressSpace+0x13e
  481. ffff8701`947e8630 fffff802`facc18b1 : ffffbe8d`4383e7c0 ffffd606`4558ea20 ffff8701`947e8840 00000000`00000000 : nt!PspRundownSingleProcess+0x11f
  482. ffff8701`947e86b0 fffff802`fadc1313 : 00000000`000000ff ffffbe8d`43c6e001 00000055`7b09a000 ffff8701`947e8601 : nt!PspExitThread+0x57d
  483. ffff8701`947e87b0 fffff802`fa8bc5d3 : 00000055`00005590 ffffbe8d`42495000 00000000`00000000 ffff8701`947e8130 : nt!KiSchedulerApcTerminate+0x33
  484. ffff8701`947e87f0 fffff802`fa9f6b60 : 00000055`7af3dd80 ffffbe8d`00000010 ffffbe8d`4383e7c0 fffff802`00000000 : nt!KiDeliverApc+0x313
  485. ffff8701`947e8880 fffff802`fa9f3ee3 : 00000000`00000000 00000000`00000000 ffffbe8d`43c6e080 00000000`00000000 : nt!KiInitiateUserApc+0x70
  486. ffff8701`947e89c0 fffff802`fa9fe413 : ffffbe8d`43c6e080 00000000`ffffffff 00000000`00000000 ffffbe8d`c0000034 : nt!NtRaiseException+0x133
  487. ffff8701`947e8b00 00007ff8`e3fd5430 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
  488. 00000055`7af3dc08 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff8`e3fd5430
  489. STACK_COMMAND: kb
  490. CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
  491. fffff802fa90bcef-fffff802fa90bcf0 2 bytes - nt!MiDeleteVirtualAddresses+99f
  492. [ 80 f6:00 be ]
  493. fffff802fa90f0ee-fffff802fa90f0ef 2 bytes - nt!MiGetNextPageTable+19e (+0x33ff)
  494. [ 80 f6:00 be ]
  495. fffff802fa90f121-fffff802fa90f122 2 bytes - nt!MiGetNextPageTable+1d1 (+0x33)
  496. [ 80 f6:00 be ]
  497. fffff802fa974874-fffff802fa974875 2 bytes - nt!MiIsLowestPageTablePage+30 (+0x65753)
  498. [ 80 f6:00 be ]
  499. fffff802fa974886-fffff802fa974887 2 bytes - nt!MiIsLowestPageTablePage+42 (+0x12)
  500. [ ff f6:7f be ]
  501. fffff802fa974902-fffff802fa974903 2 bytes - nt!MiComputePageCommitment+32 (+0x7c)
  502. [ 80 f6:00 be ]
  503. fffff802faa2ba67 - nt!MiDeletePteRun+10fd27 (+0xb7165)
  504. [ fa:e9 ]
  505. fffff802fab07383-fffff802fab07385 3 bytes - nt!ExFreePoolWithTag+363
  506. [ 40 fb f6:00 5f be ]
  507. 16 errors : !nt (fffff802fa90bcef-fffff802fab07385)
  508. MODULE_NAME: memory_corruption
  509.  
  510. IMAGE_NAME: memory_corruption
  511.  
  512. FOLLOWUP_NAME: memory_corruption
  513. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  514. MEMORY_CORRUPTOR: LARGE
  515. FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
  516. BUCKET_ID: MEMORY_CORRUPTION_LARGE
  517. PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
  518. TARGET_TIME: 2017-07-18T18:14:05.000Z
  519. OSBUILD: 15063
  520. OSSERVICEPACK: 483
  521. SERVICEPACK_NUMBER: 0
  522. OS_REVISION: 0
  523. SUITE_MASK: 272
  524. PRODUCT_TYPE: 1
  525. OSPLATFORM_TYPE: x64
  526. OSNAME: Windows 10
  527. OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
  528. USER_LCID: 0
  529. OSBUILD_TIMESTAMP: 2017-07-07 02:06:35
  530. BUILDDATESTAMP_STR: 160101.0800
  531. BUILDLAB_STR: WinBuild
  532. BUILDOSVER_STR: 10.0.15063.483
  533. ANALYSIS_SESSION_ELAPSED_TIME: 38a7
  534. ANALYSIS_SOURCE: KM
  535. FAILURE_ID_HASH_STRING: km:memory_corruption_large
  536. FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
  537. Followup: memory_corruption
  538.  
  539. ========================================================================
  540. =================== Dump File: 071817-15500-01.dmp ===================
  541. ========================================================================
  542. Mini Kernel Dump File: Only registers and stack trace are available
  543. Windows 10 Kernel Version 15063 MP (8 procs) Free x64
  544. Product: WinNt, suite: TerminalServer SingleUserTS
  545. Built by: 15063.0.amd64fre.rs2_release.170317-1834
  546. Kernel base = 0xfffff803`2ec16000 PsLoadedModuleList = 0xfffff803`2ef625e0
  547. Debug session time: Tue Jul 18 14:02:41.988 2017 (UTC - 4:00)
  548. System Uptime: 0 days 4:22:26.747
  549.  
  550. BugCheck 1A, {41792, fffff48000002ea8, 1000000, 0}
  551. Probably caused by : memory_corruption
  552. Followup: memory_corruption
  553.  
  554. MEMORY_MANAGEMENT (1a)
  555. # Any other values for parameter 1 must be individually examined.
  556.  
  557. Arguments:
  558. Arg1: 0000000000041792, A corrupt PTE has been detected. Parameter 2 contains the address of
  559. the PTE. Parameters 3/4 contain the low/high parts of the PTE.
  560. Arg2: fffff48000002ea8
  561. Arg3: 0000000001000000
  562. Arg4: 0000000000000000
  563.  
  564. Debugging Details:
  565. DUMP_CLASS: 1
  566. DUMP_QUALIFIER: 400
  567. BUILD_VERSION_STRING: 10.0.15063.483 (WinBuild.160101.0800)
  568. SYSTEM_MANUFACTURER: ASUS
  569. SYSTEM_PRODUCT_NAME: All Series
  570. SYSTEM_SKU: All
  571. BIOS_VENDOR: American Megatrends Inc.
  572. BIOS_VERSION: 2603
  573. BIOS_DATE: 02/22/2016
  574. BASEBOARD_MANUFACTURER: ASUSTeK COMPUTER INC.
  575. BASEBOARD_PRODUCT: H97M-PLUS
  576. BASEBOARD_VERSION: Rev X.0x
  577. DUMP_TYPE: 2
  578. BUGCHECK_STR: 0x1a_41792
  579. CPU_COUNT: 8
  580. CPU_MHZ: c15
  581. CPU_VENDOR: GenuineIntel
  582. CPU_FAMILY: 6
  583. CPU_MODEL: 3c
  584. CPU_STEPPING: 3
  585. CPU_MICROCODE: 6,3c,3,0 (F,M,S,R) SIG: 1E'00000000 (cache) 1E'00000000 (init)
  586. CUSTOMER_CRASH_COUNT: 1
  587. DEFAULT_BUCKET_ID: CODE_CORRUPTION
  588.  
  589. PROCESS_NAME: esrv.exe
  590.  
  591. CURRENT_IRQL: 2
  592. STACK_TEXT:
  593. ffffb800`d1b54428 fffff803`2edb5cb0 : 00000000`0000001a 00000000`00041792 fffff480`00002ea8 00000000`01000000 : nt!KeBugCheckEx
  594. ffffb800`d1b54430 fffff803`2ec955bd : ffffc886`a2100648 ffffc886`a0bf4500 ffffc886`a2100648 ffffc886`a2100080 : nt!MiDeleteVirtualAddresses+0x11b960
  595. ffffb800`d1b546e0 fffff803`2f0a2217 : ffffc886`a0bf4500 ffffc886`a1fbfd60 ffffc886`a1fbfd60 ffffc886`a0bf4500 : nt!MiDeleteVad+0x3ad
  596. ffffb800`d1b54860 fffff803`2f0a26fe : 00000000`00000000 ffffc886`a272b930 ffffc886`a1fbfd60 ffffc886`a2100080 : nt!MiCleanVad+0x27
  597. ffffb800`d1b54890 fffff803`2f0e054f : 00000000`00040000 00000000`00000000 ffffc886`a2100080 ffffc886`00000000 : nt!MmCleanProcessAddressSpace+0x13e
  598. ffffb800`d1b54910 fffff803`2f0508b1 : ffffc886`a2100080 ffffda08`aaec1060 ffffc886`a2100080 00000000`00000000 : nt!PspRundownSingleProcess+0x11f
  599. ffffb800`d1b54990 fffff803`2f110f89 : 00000000`00000001 ffffc886`a2100001 00000000`0025c000 ffffc886`a0bf4500 : nt!PspExitThread+0x57d
  600. ffffb800`d1b54a90 fffff803`2ed8d413 : ffffc886`a2100080 ffffc886`a0bf4500 ffffb800`d1b54b80 00000000`02341620 : nt!NtTerminateProcess+0xe9
  601. ffffb800`d1b54b00 00007ffe`b8e95924 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
  602. 00000000`04611898 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffe`b8e95924
  603. STACK_COMMAND: kb
  604. CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
  605. fffff8032ec9e0ef - nt!MiGetNextPageTable+19f
  606. [ f6:f4 ]
  607. fffff8032ec9e122 - nt!MiGetNextPageTable+1d2 (+0x33)
  608. [ f6:f4 ]
  609. 2 errors : !nt (fffff8032ec9e0ef-fffff8032ec9e122)
  610. MODULE_NAME: memory_corruption
  611.  
  612. IMAGE_NAME: memory_corruption
  613.  
  614. FOLLOWUP_NAME: memory_corruption
  615. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  616. MEMORY_CORRUPTOR: ONE_BIT_LARGE
  617. FAILURE_BUCKET_ID: MEMORY_CORRUPTION_ONE_BIT_LARGE
  618. BUCKET_ID: MEMORY_CORRUPTION_ONE_BIT_LARGE
  619. PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_ONE_BIT_LARGE
  620. TARGET_TIME: 2017-07-18T18:02:41.000Z
  621. OSBUILD: 15063
  622. OSSERVICEPACK: 483
  623. SERVICEPACK_NUMBER: 0
  624. OS_REVISION: 0
  625. SUITE_MASK: 272
  626. PRODUCT_TYPE: 1
  627. OSPLATFORM_TYPE: x64
  628. OSNAME: Windows 10
  629. OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
  630. USER_LCID: 0
  631. OSBUILD_TIMESTAMP: 2017-07-07 02:06:35
  632. BUILDDATESTAMP_STR: 160101.0800
  633. BUILDLAB_STR: WinBuild
  634. BUILDOSVER_STR: 10.0.15063.483
  635. ANALYSIS_SESSION_ELAPSED_TIME: 2a82
  636. ANALYSIS_SOURCE: KM
  637. FAILURE_ID_HASH_STRING: km:memory_corruption_one_bit_large
  638. FAILURE_ID_HASH: {31545515-196b-fab5-2300-9ce714226f43}
  639. Followup: memory_corruption
  640.  
  641. ========================================================================
  642. =================== Dump File: 071817-14421-01.dmp ===================
  643. ========================================================================
  644. Mini Kernel Dump File: Only registers and stack trace are available
  645. Windows 10 Kernel Version 15063 MP (8 procs) Free x64
  646. Product: WinNt, suite: TerminalServer SingleUserTS
  647. Built by: 15063.0.amd64fre.rs2_release.170317-1834
  648. Kernel base = 0xfffff801`d7697000 PsLoadedModuleList = 0xfffff801`d79e35e0
  649. Debug session time: Tue Jul 18 09:27:22.585 2017 (UTC - 4:00)
  650. System Uptime: 0 days 8:06:22.217
  651.  
  652. BugCheck 12B, {ffffffffc00002c4, c5d, 179a220, ffffad80ba255000}
  653. *** WARNING: Unable to verify timestamp for win32k.sys
  654. *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
  655. Probably caused by : memory_corruption
  656. Followup: memory_corruption
  657.  
  658. FAULTY_HARDWARE_CORRUPTED_PAGE (12b)
  659. This bugcheck indicates that a single bit error was found in this page. This is a hardware memory error.
  660.  
  661. Arguments:
  662. Arg1: ffffffffc00002c4, virtual address mapping the corrupted page
  663. Arg2: 0000000000000c5d, physical page number
  664. Arg3: 000000000179a220, zero
  665. Arg4: ffffad80ba255000, zero
  666.  
  667. Debugging Details:
  668. DUMP_CLASS: 1
  669. DUMP_QUALIFIER: 400
  670. BUILD_VERSION_STRING: 10.0.15063.483 (WinBuild.160101.0800)
  671. SYSTEM_MANUFACTURER: ASUS
  672. SYSTEM_PRODUCT_NAME: All Series
  673. SYSTEM_SKU: All
  674. BIOS_VENDOR: American Megatrends Inc.
  675. BIOS_VERSION: 2603
  676. BIOS_DATE: 02/22/2016
  677. BASEBOARD_MANUFACTURER: ASUSTeK COMPUTER INC.
  678. BASEBOARD_PRODUCT: H97M-PLUS
  679. BASEBOARD_VERSION: Rev X.0x
  680. DUMP_TYPE: 2
  681. BUGCHECK_STR: 0x12B_c00002c4_StCtDecompressFailed
  682. CPU_COUNT: 8
  683. CPU_MHZ: c15
  684. CPU_VENDOR: GenuineIntel
  685. CPU_FAMILY: 6
  686. CPU_MODEL: 3c
  687. CPU_STEPPING: 3
  688. CPU_MICROCODE: 6,3c,3,0 (F,M,S,R) SIG: 1E'00000000 (cache) 1E'00000000 (init)
  689. CUSTOMER_CRASH_COUNT: 1
  690. DEFAULT_BUCKET_ID: CODE_CORRUPTION
  691.  
  692. PROCESS_NAME: MemCompression
  693.  
  694. CURRENT_IRQL: 0
  695. LAST_CONTROL_TRANSFER: from fffff801d78dfb87 to fffff801d78034c0
  696. STACK_TEXT:
  697. ffffad80`b784d208 fffff801`d78dfb87 : 00000000`0000012b ffffffff`c00002c4 00000000`00000c5d 00000000`0179a220 : nt!KeBugCheckEx
  698. ffffad80`b784d210 fffff801`d784e79d : 00000000`00000200 00000000`00000003 00000000`0179a220 ffffad80`ba255000 : nt!ST_STORE<SM_TRAITS>::StDmPageError+0x117
  699. ffffad80`b784d260 fffff801`d777084f : 00000000`00000000 ffffad80`b784d478 00000000`00000000 00000000`00000086 : nt!ST_STORE<SM_TRAITS>::StDmSinglePageCopy+0xddf19
  700. ffffad80`b784d340 fffff801`d777023b : 00000000`00000001 00000000`0000a220 ffffad80`0000a220 00000000`00001000 : nt!ST_STORE<SM_TRAITS>::StDmSinglePageTransfer+0x7b
  701. ffffad80`b784d390 fffff801`d777000c : ffffad80`ffffffff ffff878a`0d935000 ffffad80`b784d478 ffff8789`ff733c10 : nt!ST_STORE<SM_TRAITS>::StDmpSinglePageRetrieve+0x183
  702. ffffad80`b784d430 fffff801`d7771c7f : ffff8789`ff733c10 fffff801`00000000 00000000`00000001 ffff8789`ff733c10 : nt!ST_STORE<SM_TRAITS>::StDmPageRetrieve+0x98
  703. ffffad80`b784d4f0 fffff801`d77c0f81 : ffff878a`0b792000 ffffad80`b784d600 fffff801`d77c0f60 ffffad80`b784d600 : nt!SMKM_STORE<SM_TRAITS>::SmStDirectReadIssue+0x6f
  704. ffffad80`b784d540 fffff801`d76ad20b : ffff878a`0a623080 ffffad80`b784d600 00000000`00000002 fffff801`d77686d0 : nt!SMKM_STORE<SM_TRAITS>::SmStDirectReadCallout+0x21
  705. ffffad80`b784d570 fffff801`d7768625 : 00000000`00000003 ffff878a`0d935000 ffff878a`0b792000 ffff8789`ff733c10 : nt!KeExpandKernelStackAndCalloutInternal+0x8b
  706. ffffad80`b784d5c0 fffff801`d775ecc2 : ffffad80`b784d6c0 fffff801`d7a8da00 00000000`00000000 fffff801`d7772dc0 : nt!SMKM_STORE<SM_TRAITS>::SmStDirectRead+0xad
  707. ffffad80`b784d690 fffff801`d775e522 : 00000000`00000000 00000000`00000000 ffffad80`b784d740 ffff8789`ff733c10 : nt!SMKM_STORE<SM_TRAITS>::SmStWorkItemQueue+0x1ae
  708. ffffad80`b784d6e0 fffff801`d7772afa : 00000000`0000000c 00000000`00000001 ffff8789`ff733c10 ffff878a`09e84060 : nt!SMKM_STORE_MGR<SM_TRAITS>::SmIoCtxQueueWork+0xce
  709. ffffad80`b784d760 fffff801`d77af6ea : ffff878a`00000001 ffff878a`09e84110 ffff878a`00000000 ffff878a`0b792000 : nt!SMKM_STORE_MGR<SM_TRAITS>::SmPageRead+0x16a
  710. ffffad80`b784d7d0 fffff801`d7738fa9 : ffff878a`0a623080 ffff878a`09e84010 00000000`00000000 00000000`00000002 : nt!SmPageRead+0x2e
  711. ffffad80`b784d820 fffff801`d7738970 : 00000000`00000002 ffffad80`b784d8b0 00000000`00000000 ffff878a`09e84010 : nt!MiIssueHardFaultIo+0x11d
  712. ffffad80`b784d870 fffff801`d7724486 : 00000000`c0033333 ffffad80`b784db00 00000000`00000000 ffffad80`00000000 : nt!MiIssueHardFault+0x190
  713. ffffad80`b784d910 fffff801`d780cd72 : ffff878a`0a623080 00000060`00000000 00000000`00000000 00000060`a31fc9c0 : nt!MmAccessFault+0xc96
  714. ffffad80`b784db00 00007ffb`21802246 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x132
  715. 00000060`a31fc280 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffb`21802246
  716. STACK_COMMAND: kb
  717. CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
  718. fffff801d76d5698 - nt!MiGetWsleProtection+18
  719. [ f6:bf ]
  720. fffff801d76d56e8 - nt!MiGetWsleContents+18 (+0x50)
  721. [ f6:bf ]
  722. fffff801d772454d - nt!MmAccessFault+d5d (+0x4ee65)
  723. [ f6:bf ]
  724. fffff801d7738a13 - nt!MiIssueHardFault+233 (+0x144c6)
  725. [ f6:bf ]
  726. 4 errors : !nt (fffff801d76d5698-fffff801d7738a13)
  727. MODULE_NAME: memory_corruption
  728.  
  729. IMAGE_NAME: memory_corruption
  730.  
  731. FOLLOWUP_NAME: memory_corruption
  732. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  733. MEMORY_CORRUPTOR: LARGE
  734. FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
  735. BUCKET_ID: MEMORY_CORRUPTION_LARGE
  736. PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
  737. TARGET_TIME: 2017-07-18T13:27:22.000Z
  738. OSBUILD: 15063
  739. OSSERVICEPACK: 483
  740. SERVICEPACK_NUMBER: 0
  741. OS_REVISION: 0
  742. SUITE_MASK: 272
  743. PRODUCT_TYPE: 1
  744. OSPLATFORM_TYPE: x64
  745. OSNAME: Windows 10
  746. OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
  747. USER_LCID: 0
  748. OSBUILD_TIMESTAMP: 2017-07-07 02:06:35
  749. BUILDDATESTAMP_STR: 160101.0800
  750. BUILDLAB_STR: WinBuild
  751. BUILDOSVER_STR: 10.0.15063.483
  752. ANALYSIS_SESSION_ELAPSED_TIME: 2a82
  753. ANALYSIS_SOURCE: KM
  754. FAILURE_ID_HASH_STRING: km:memory_corruption_large
  755. FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
  756. Followup: memory_corruption
  757.  
  758. ========================================================================
  759. =================== Dump File: 072017-15578-01.dmp ===================
  760. ========================================================================
  761. Mini Kernel Dump File: Only registers and stack trace are available
  762. Windows 10 Kernel Version 15063 MP (8 procs) Free x64
  763. Product: WinNt, suite: TerminalServer SingleUserTS
  764. Built by: 15063.0.amd64fre.rs2_release.170317-1834
  765. Kernel base = 0xfffff800`b5c15000 PsLoadedModuleList = 0xfffff800`b5f615e0
  766. Debug session time: Thu Jul 20 02:16:30.185 2017 (UTC - 4:00)
  767. System Uptime: 0 days 0:11:18.817
  768.  
  769. BugCheck 1A, {41793, ffffe400db965e28, 9, 8}
  770. Probably caused by : memory_corruption
  771. Followup: memory_corruption
  772.  
  773. MEMORY_MANAGEMENT (1a)
  774. # Any other values for parameter 1 must be individually examined.
  775.  
  776. Arguments:
  777. Arg1: 0000000000041793, The subtype of the bugcheck.
  778. Arg2: ffffe400db965e28
  779. Arg3: 0000000000000009
  780. Arg4: 0000000000000008
  781.  
  782. Debugging Details:
  783. DUMP_CLASS: 1
  784. DUMP_QUALIFIER: 400
  785. BUILD_VERSION_STRING: 10.0.15063.483 (WinBuild.160101.0800)
  786. SYSTEM_MANUFACTURER: ASUS
  787. SYSTEM_PRODUCT_NAME: All Series
  788. SYSTEM_SKU: All
  789. BIOS_VENDOR: American Megatrends Inc.
  790. BIOS_VERSION: 2603
  791. BIOS_DATE: 02/22/2016
  792. BASEBOARD_MANUFACTURER: ASUSTeK COMPUTER INC.
  793. BASEBOARD_PRODUCT: H97M-PLUS
  794. BASEBOARD_VERSION: Rev X.0x
  795. DUMP_TYPE: 2
  796. BUGCHECK_STR: 0x1a_41793
  797. CPU_COUNT: 8
  798. CPU_MHZ: c15
  799. CPU_VENDOR: GenuineIntel
  800. CPU_FAMILY: 6
  801. CPU_MODEL: 3c
  802. CPU_STEPPING: 3
  803. CPU_MICROCODE: 6,3c,3,0 (F,M,S,R) SIG: 1E'00000000 (cache) 1E'00000000 (init)
  804. CUSTOMER_CRASH_COUNT: 1
  805. DEFAULT_BUCKET_ID: CODE_CORRUPTION
  806.  
  807. PROCESS_NAME: MsMpEng.exe
  808.  
  809. CURRENT_IRQL: 2
  810. LAST_CONTROL_TRANSFER: from fffff800b5db4cd0 to fffff800b5d814c0
  811. STACK_TEXT:
  812. ffffe680`99a845a8 fffff800`b5db4cd0 : 00000000`0000001a 00000000`00041793 ffffe400`db965e28 00000000`00000009 : nt!KeBugCheckEx
  813. ffffe680`99a845b0 fffff800`b5c945bd : ffff8e00`890cdb48 ffff8e00`7c98f080 ffff8e00`890cdb48 ffff8e00`890cd580 : nt!MiDeleteVirtualAddresses+0x11b980
  814. ffffe680`99a84860 fffff800`b60c989c : 000001b7`2c8d0000 ffff8e00`883d6240 ffffffff`ffffffff 00000000`00000000 : nt!MiDeleteVad+0x3ad
  815. ffffe680`99a849e0 fffff800`b613f9c6 : ffff8e00`890cd580 ffffe680`00000008 ffff8e00`7c423d40 000001b7`2c8d0000 : nt!MiUnmapViewOfSection+0xec
  816. ffffe680`99a84ab0 fffff800`b5d8c413 : ffff8e00`7c98f080 00000000`ffffffff 00000000`00000000 ffff8e00`890cd580 : nt!NtUnmapViewOfSectionEx+0x86
  817. ffffe680`99a84b00 00007ffb`6c0d8b54 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
  818. 0000006e`bfaff1f8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffb`6c0d8b54
  819. STACK_COMMAND: kb
  820. CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
  821. fffff800b5c55051-fffff800b5c55052 2 bytes - nt!MiIsAddressValid+c1
  822. [ ff f6:7f e4 ]
  823. fffff800b5c550e3-fffff800b5c550e4 2 bytes - nt!MmUnmapLockedPages+73 (+0x92)
  824. [ 80 f6:00 e4 ]
  825. fffff800b5c5f0f6-fffff800b5c5f0f7 2 bytes - nt!MiCreateDecayPfn+56 (+0xa013)
  826. [ 80 fa:00 b6 ]
  827. fffff800b5caa816-fffff800b5caa817 2 bytes - nt!MiPfnShareCountIsZero+186 (+0x4b720)
  828. [ 80 f6:00 e4 ]
  829. fffff800b5cacfd2-fffff800b5cacfd3 2 bytes - nt!MiDeletePteList+592 (+0x27bc)
  830. [ 80 fa:00 b6 ]
  831. 10 errors : !nt (fffff800b5c55051-fffff800b5cacfd3)
  832. MODULE_NAME: memory_corruption
  833.  
  834. IMAGE_NAME: memory_corruption
  835.  
  836. FOLLOWUP_NAME: memory_corruption
  837. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  838. MEMORY_CORRUPTOR: LARGE
  839. FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
  840. BUCKET_ID: MEMORY_CORRUPTION_LARGE
  841. PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
  842. TARGET_TIME: 2017-07-20T06:16:30.000Z
  843. OSBUILD: 15063
  844. OSSERVICEPACK: 483
  845. SERVICEPACK_NUMBER: 0
  846. OS_REVISION: 0
  847. SUITE_MASK: 272
  848. PRODUCT_TYPE: 1
  849. OSPLATFORM_TYPE: x64
  850. OSNAME: Windows 10
  851. OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
  852. USER_LCID: 0
  853. OSBUILD_TIMESTAMP: 2017-07-07 02:06:35
  854. BUILDDATESTAMP_STR: 160101.0800
  855. BUILDLAB_STR: WinBuild
  856. BUILDOSVER_STR: 10.0.15063.483
  857. ANALYSIS_SESSION_ELAPSED_TIME: 2a9d
  858. ANALYSIS_SOURCE: KM
  859. FAILURE_ID_HASH_STRING: km:memory_corruption_large
  860. FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
  861. Followup: memory_corruption
  862.  
  863. ========================================================================
  864. =================== Dump File: 072017-14953-01.dmp ===================
  865. ========================================================================
  866. Mini Kernel Dump File: Only registers and stack trace are available
  867. Windows 10 Kernel Version 15063 MP (8 procs) Free x64
  868. Product: WinNt, suite: TerminalServer SingleUserTS
  869. Built by: 15063.0.amd64fre.rs2_release.170317-1834
  870. Kernel base = 0xfffff800`8fa16000 PsLoadedModuleList = 0xfffff800`8fd625e0
  871. Debug session time: Thu Jul 20 16:17:06.990 2017 (UTC - 4:00)
  872. System Uptime: 0 days 0:47:01.622
  873.  
  874. BugCheck 1A, {41792, fffff6805d1fee28, 1000000, 0}
  875. Probably caused by : memory_corruption
  876. Followup: memory_corruption
  877.  
  878. MEMORY_MANAGEMENT (1a)
  879. # Any other values for parameter 1 must be individually examined.
  880.  
  881. Arguments:
  882. Arg1: 0000000000041792, A corrupt PTE has been detected. Parameter 2 contains the address of
  883. the PTE. Parameters 3/4 contain the low/high parts of the PTE.
  884. Arg2: fffff6805d1fee28
  885. Arg3: 0000000001000000
  886. Arg4: 0000000000000000
  887.  
  888. Debugging Details:
  889. DUMP_CLASS: 1
  890. DUMP_QUALIFIER: 400
  891. BUILD_VERSION_STRING: 10.0.15063.483 (WinBuild.160101.0800)
  892. SYSTEM_MANUFACTURER: ASUS
  893. SYSTEM_PRODUCT_NAME: All Series
  894. SYSTEM_SKU: All
  895. BIOS_VENDOR: American Megatrends Inc.
  896. BIOS_VERSION: 2603
  897. BIOS_DATE: 02/22/2016
  898. BASEBOARD_MANUFACTURER: ASUSTeK COMPUTER INC.
  899. BASEBOARD_PRODUCT: H97M-PLUS
  900. BASEBOARD_VERSION: Rev X.0x
  901. DUMP_TYPE: 2
  902. MEMORY_CORRUPTOR: LARGE
  903. BUGCHECK_STR: 0x1a_41792
  904. CPU_COUNT: 8
  905. CPU_MHZ: c15
  906. CPU_VENDOR: GenuineIntel
  907. CPU_FAMILY: 6
  908. CPU_MODEL: 3c
  909. CPU_STEPPING: 3
  910. CPU_MICROCODE: 6,3c,3,0 (F,M,S,R) SIG: 1E'00000000 (cache) 1E'00000000 (init)
  911. CUSTOMER_CRASH_COUNT: 1
  912. DEFAULT_BUCKET_ID: CODE_CORRUPTION
  913.  
  914. PROCESS_NAME: browser_broker.exe
  915.  
  916. CURRENT_IRQL: 2
  917. STACK_TEXT:
  918. ffffb301`6eb7f248 fffff800`8fbb5cb0 : 00000000`0000001a 00000000`00041792 fffff680`5d1fee28 00000000`01000000 : nt!KeBugCheckEx
  919. ffffb301`6eb7f250 fffff800`8fa955bd : ffff9b01`01727d88 ffff9b01`017287c0 ffff9b01`01727d88 ffff9b01`017277c0 : nt!MiDeleteVirtualAddresses+0x11b960
  920. ffffb301`6eb7f500 fffff800`8fea26fe : 00000000`00000000 ffff9b01`005fe2e0 ffff9b01`017d68b0 ffff9b01`017287c0 : nt!MiDeleteVad+0x3ad
  921. ffffb301`6eb7f680 fffff800`8fee054f : 00000000`00040000 00000000`00000000 ffff9b01`017277c0 ffff9b01`00000000 : nt!MmCleanProcessAddressSpace+0x13e
  922. ffffb301`6eb7f700 fffff800`8fe508b1 : ffff9b01`017277c0 ffff8509`e4ca38a0 ffffb301`6eb7f910 00000000`00000000 : nt!PspRundownSingleProcess+0x11f
  923. ffffb301`6eb7f780 fffff800`8ff50313 : 00000000`80004005 ffff9b01`01732001 000000ba`3f85e000 ffffb301`00000010 : nt!PspExitThread+0x57d
  924. ffffb301`6eb7f880 fffff800`8fa4b5d3 : 000000ba`3f7af4d8 000002a8`31c557c0 00000000`e0ffff00 00000001`6eb7f970 : nt!KiSchedulerApcTerminate+0x33
  925. ffffb301`6eb7f8c0 fffff800`8fb85b60 : 000002a8`31c55b40 000002a8`31c557c0 00000000`00000650 ffff9b01`00000000 : nt!KiDeliverApc+0x313
  926. ffffb301`6eb7f950 fffff800`8fb8d4ba : 00000000`00000000 ffffb301`6eb7fb80 00000000`00000000 fffff800`8fec622f : nt!KiInitiateUserApc+0x70
  927. ffffb301`6eb7fa90 00007ff9`c3878c34 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExit+0x9f
  928. 000000ba`3f7af478 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff9`c3878c34
  929. STACK_COMMAND: kb
  930. CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
  931. fffff8008faa70d8-fffff8008faa70d9 2 bytes - nt!MiResolvePrivateZeroFault+2d8
  932. [ 80 fa:00 95 ]
  933. 2 errors : !nt (fffff8008faa70d8-fffff8008faa70d9)
  934. MODULE_NAME: memory_corruption
  935.  
  936. IMAGE_NAME: memory_corruption
  937.  
  938. FOLLOWUP_NAME: memory_corruption
  939. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  940. FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
  941. BUCKET_ID: MEMORY_CORRUPTION_LARGE
  942. PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
  943. TARGET_TIME: 2017-07-20T20:17:06.000Z
  944. OSBUILD: 15063
  945. OSSERVICEPACK: 483
  946. SERVICEPACK_NUMBER: 0
  947. OS_REVISION: 0
  948. SUITE_MASK: 272
  949. PRODUCT_TYPE: 1
  950. OSPLATFORM_TYPE: x64
  951. OSNAME: Windows 10
  952. OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
  953. USER_LCID: 0
  954. OSBUILD_TIMESTAMP: 2017-07-07 02:06:35
  955. BUILDDATESTAMP_STR: 160101.0800
  956. BUILDLAB_STR: WinBuild
  957. BUILDOSVER_STR: 10.0.15063.483
  958. ANALYSIS_SESSION_ELAPSED_TIME: 2ad7
  959. ANALYSIS_SOURCE: KM
  960. FAILURE_ID_HASH_STRING: km:memory_corruption_large
  961. FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
  962. Followup: memory_corruption
  963.  
  964. ========================================================================
  965. =================== Dump File: 072017-14750-01.dmp ===================
  966. ========================================================================
  967. Mini Kernel Dump File: Only registers and stack trace are available
  968. Windows 10 Kernel Version 15063 MP (8 procs) Free x64
  969. Product: WinNt, suite: TerminalServer SingleUserTS
  970. Built by: 15063.0.amd64fre.rs2_release.170317-1834
  971. Kernel base = 0xfffff802`ca212000 PsLoadedModuleList = 0xfffff802`ca55e5e0
  972. Debug session time: Thu Jul 20 15:29:11.125 2017 (UTC - 4:00)
  973. System Uptime: 0 days 13:11:43.883
  974.  
  975. BugCheck F7, {1c8187c5a030, 2fb6679bbf70, ffffd0499864408f, 0}
  976. Probably caused by : memory_corruption
  977. Followup: memory_corruption
  978.  
  979. DRIVER_OVERRAN_STACK_BUFFER (f7)
  980. A driver has overrun a stack-based buffer. This overrun could potentially
  981. allow a malicious user to gain control of this machine.
  982. DESCRIPTION
  983. A driver overran a stack-based buffer (or local variable) in a way that would
  984. have overwritten the function's return address and jumped back to an arbitrary
  985. address when the function returned. This is the classic "buffer overrun"
  986. hacking attack and the system has been brought down to prevent a malicious user
  987. from gaining complete control of it.
  988. Do a kb to get a stack backtrace -- the last routine on the stack before the
  989. buffer overrun handlers and bugcheck call is the one that overran its local
  990. variable(s).
  991.  
  992. Arguments:
  993. Arg1: 00001c8187c5a030, Actual security check cookie from the stack
  994. Arg2: 00002fb6679bbf70, Expected security check cookie
  995. Arg3: ffffd0499864408f, Complement of the expected security check cookie
  996. Arg4: 0000000000000000, zero
  997.  
  998. Debugging Details:
  999. DUMP_CLASS: 1
  1000. DUMP_QUALIFIER: 400
  1001. BUILD_VERSION_STRING: 10.0.15063.483 (WinBuild.160101.0800)
  1002. SYSTEM_MANUFACTURER: ASUS
  1003. SYSTEM_PRODUCT_NAME: All Series
  1004. SYSTEM_SKU: All
  1005. BIOS_VENDOR: American Megatrends Inc.
  1006. BIOS_VERSION: 2603
  1007. BIOS_DATE: 02/22/2016
  1008. BASEBOARD_MANUFACTURER: ASUSTeK COMPUTER INC.
  1009. BASEBOARD_PRODUCT: H97M-PLUS
  1010. BASEBOARD_VERSION: Rev X.0x
  1011. DUMP_TYPE: 2
  1012. SECURITY_COOKIE: Expected 00002fb6679bbf70 found 00001c8187c5a030
  1013. CPU_COUNT: 8
  1014. CPU_MHZ: c15
  1015. CPU_VENDOR: GenuineIntel
  1016. CPU_FAMILY: 6
  1017. CPU_MODEL: 3c
  1018. CPU_STEPPING: 3
  1019. CPU_MICROCODE: 6,3c,3,0 (F,M,S,R) SIG: 1E'00000000 (cache) 1E'00000000 (init)
  1020. CUSTOMER_CRASH_COUNT: 1
  1021. DEFAULT_BUCKET_ID: CODE_CORRUPTION
  1022. BUGCHECK_STR: 0xF7
  1023.  
  1024. PROCESS_NAME: svchost.exe
  1025.  
  1026. CURRENT_IRQL: 2
  1027. LAST_CONTROL_TRANSFER: from fffff802ca3ec905 to fffff802ca37e4c0
  1028. STACK_TEXT:
  1029. ffff9181`87c5ef88 fffff802`ca3ec905 : 00000000`000000f7 00001c81`87c5a030 00002fb6`679bbf70 ffffd049`9864408f : nt!KeBugCheckEx
  1030. ffff9181`87c5ef90 fffff802`ca27b180 : ffffdc0b`2d50b000 ffff9181`87c5f010 00000000`00000000 fffff6fc`00000000 : nt!_report_gsfailure+0x25
  1031. ffff9181`87c5efd0 fffff802`ca27b02e : 00000000`00000100 ffffdc0b`2d50c8c0 00000000`00000000 ffff9181`87c5f198 : nt!MiIdentifyPfn+0x100
  1032. ffff9181`87c5f0a0 fffff802`ca6bfdda : 00000000`00000000 ffffdc0b`2d50b0f0 ffffdc0b`2d50b000 00000000`00000000 : nt!MiIdentifyPfnWrapper+0x3e
  1033. ffff9181`87c5f0d0 fffff802`ca6bf8ef : ffffa30c`ecda0060 00000000`00000001 ffff9181`87c5f2b4 ffffdc0b`2d50b000 : nt!PfpPfnPrioRequest+0xca
  1034. ffff9181`87c5f150 fffff802`ca6bdb4e : 00000000`0000004f 00000000`42506650 0000005e`7ad7a008 00000000`00000200 : nt!PfQuerySuperfetchInformation+0x2bf
  1035. ffff9181`87c5f280 fffff802`ca6bd7fb : 00000000`00000000 00000000`00000000 00000000`00000008 0000005e`7ad7d260 : nt!ExpQuerySystemInformation+0x22e
  1036. ffff9181`87c5fac0 fffff802`ca389413 : ffffdc0b`2998e7c0 00000000`00000000 00000000`00000000 00007ffe`744c4d50 : nt!NtQuerySystemInformation+0x2b
  1037. ffff9181`87c5fb00 00007ffe`87765a64 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
  1038. 0000005e`7ad79f08 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffe`87765a64
  1039. STACK_COMMAND: kb
  1040. CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
  1041. fffff802ca27b0b9-fffff802ca27b0ba 2 bytes - nt!MiIdentifyPfn+39
  1042. [ 80 fa:00 8d ]
  1043. fffff802ca2b7f4a-fffff802ca2b7f4b 2 bytes - nt!MmSetPfnListPriorities+13a (+0x3ce91)
  1044. [ 80 fa:00 8d ]
  1045. fffff802ca6bfde7-fffff802ca6bfde8 2 bytes - nt!PfpPfnPrioRequest+d7
  1046. [ 80 fa:00 8d ]
  1047. 6 errors : !nt (fffff802ca27b0b9-fffff802ca6bfde8)
  1048. MODULE_NAME: memory_corruption
  1049.  
  1050. IMAGE_NAME: memory_corruption
  1051.  
  1052. FOLLOWUP_NAME: memory_corruption
  1053. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  1054. MEMORY_CORRUPTOR: LARGE
  1055. FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
  1056. BUCKET_ID: MEMORY_CORRUPTION_LARGE
  1057. PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
  1058. TARGET_TIME: 2017-07-20T19:29:11.000Z
  1059. OSBUILD: 15063
  1060. OSSERVICEPACK: 483
  1061. SERVICEPACK_NUMBER: 0
  1062. OS_REVISION: 0
  1063. SUITE_MASK: 272
  1064. PRODUCT_TYPE: 1
  1065. OSPLATFORM_TYPE: x64
  1066. OSNAME: Windows 10
  1067. OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
  1068. USER_LCID: 0
  1069. OSBUILD_TIMESTAMP: 2017-07-07 02:06:35
  1070. BUILDDATESTAMP_STR: 160101.0800
  1071. BUILDLAB_STR: WinBuild
  1072. BUILDOSVER_STR: 10.0.15063.483
  1073. ANALYSIS_SESSION_ELAPSED_TIME: 3cd1
  1074. ANALYSIS_SOURCE: KM
  1075. FAILURE_ID_HASH_STRING: km:memory_corruption_large
  1076. FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
  1077. Followup: memory_corruption
  1078.  
  1079. ========================================================================
  1080. =================== Dump File: 072017-14453-01.dmp ===================
  1081. ========================================================================
  1082. Mini Kernel Dump File: Only registers and stack trace are available
  1083. Windows 10 Kernel Version 15063 MP (8 procs) Free x64
  1084. Product: WinNt, suite: TerminalServer SingleUserTS
  1085. Built by: 15063.0.amd64fre.rs2_release.170317-1834
  1086. Kernel base = 0xfffff800`1e601000 PsLoadedModuleList = 0xfffff800`1e94d5e0
  1087. Debug session time: Thu Jul 20 16:28:26.554 2017 (UTC - 4:00)
  1088. System Uptime: 0 days 0:10:25.312
  1089.  
  1090. BugCheck 139, {3, ffffb68180c955d0, ffffb68180c95528, 0}
  1091. *** WARNING: Unable to verify timestamp for win32k.sys
  1092. *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
  1093. Probably caused by : memory_corruption
  1094. Followup: memory_corruption
  1095.  
  1096. KERNEL_SECURITY_CHECK_FAILURE (139)
  1097. A kernel component has corrupted a critical data structure. The corruption
  1098. could potentially allow a malicious user to gain control of this machine.
  1099.  
  1100. Arguments:
  1101. Arg1: 0000000000000003, A LIST_ENTRY has been corrupted (i.e. double remove).
  1102. Arg2: ffffb68180c955d0, Address of the trap frame for the exception that caused the bugcheck
  1103. Arg3: ffffb68180c95528, Address of the exception record for the exception that caused the bugcheck
  1104. Arg4: 0000000000000000, Reserved
  1105.  
  1106. Debugging Details:
  1107. DUMP_CLASS: 1
  1108. DUMP_QUALIFIER: 400
  1109. BUILD_VERSION_STRING: 10.0.15063.483 (WinBuild.160101.0800)
  1110. SYSTEM_MANUFACTURER: ASUS
  1111. SYSTEM_PRODUCT_NAME: All Series
  1112. SYSTEM_SKU: All
  1113. BIOS_VENDOR: American Megatrends Inc.
  1114. BIOS_VERSION: 2603
  1115. BIOS_DATE: 02/22/2016
  1116. BASEBOARD_MANUFACTURER: ASUSTeK COMPUTER INC.
  1117. BASEBOARD_PRODUCT: H97M-PLUS
  1118. BASEBOARD_VERSION: Rev X.0x
  1119. DUMP_TYPE: 2
  1120. TRAP_FRAME: ffffb68180c955d0 -- (.trap 0xffffb68180c955d0)
  1121. NOTE: The trap frame does not contain all registers.
  1122. Some register values may be zeroed or incorrect.
  1123. rax=ffffdd031c9d0ea0 rbx=0000000000000000 rcx=0000000000000003
  1124. rdx=ffffdd031f87eac0 rsi=0000000000000000 rdi=0000000000000000
  1125. rip=fffff8001e8822ed rsp=ffffb68180c95760 rbp=0000000000000000
  1126. r8=ffffdd031c9d0d30 r9=ffffdd031d9d0bd0 r10=0000000000000001
  1127. r11=ffffdd031c8fb950 r12=0000000000000000 r13=0000000000000000
  1128. r14=0000000000000000 r15=0000000000000000
  1129. iopl=0 nv up ei ng nz na pe cy
  1130. nt!ExDeferredFreePool+0x22cd:
  1131. fffff800`1e8822ed cd29 int 29h
  1132. Resetting default scope
  1133. EXCEPTION_RECORD: ffffb68180c95528 -- (.exr 0xffffb68180c95528)
  1134. ExceptionAddress: fffff8001e8822ed (nt!ExDeferredFreePool+0x00000000000022cd)
  1135. ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
  1136. ExceptionFlags: 00000001
  1137. NumberParameters: 1
  1138. Parameter[0]: 0000000000000003
  1139. Subcode: 0x3 FAST_FAIL_CORRUPT_LIST_ENTRY
  1140. CPU_COUNT: 8
  1141. CPU_MHZ: c15
  1142. CPU_VENDOR: GenuineIntel
  1143. CPU_FAMILY: 6
  1144. CPU_MODEL: 3c
  1145. CPU_STEPPING: 3
  1146. CPU_MICROCODE: 6,3c,3,0 (F,M,S,R) SIG: 1E'00000000 (cache) 1E'00000000 (init)
  1147. CUSTOMER_CRASH_COUNT: 1
  1148. DEFAULT_BUCKET_ID: CODE_CORRUPTION
  1149. BUGCHECK_STR: 0x139
  1150.  
  1151. PROCESS_NAME: System
  1152.  
  1153. CURRENT_IRQL: 1
  1154. ERROR_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.
  1155. EXCEPTION_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.
  1156. EXCEPTION_CODE_STR: c0000409
  1157. EXCEPTION_PARAMETER1: 0000000000000003
  1158. LAST_CONTROL_TRANSFER: from fffff8001e7788a9 to fffff8001e76d4c0
  1159. STACK_TEXT:
  1160. ffffb681`80c952a8 fffff800`1e7788a9 : 00000000`00000139 00000000`00000003 ffffb681`80c955d0 ffffb681`80c95528 : nt!KeBugCheckEx
  1161. ffffb681`80c952b0 fffff800`1e778c10 : 00000000`c0000225 fffff809`db237b09 00000000`00000001 ffffb681`80c95808 : nt!KiBugCheckDispatch+0x69
  1162. ffffb681`80c953f0 fffff800`1e777bf7 : 00000000`00000000 fffff809`dc22dd7b ffffcc07`5f9bd940 ffffcc07`5f9bd940 : nt!KiFastFailDispatch+0xd0
  1163. ffffb681`80c955d0 fffff800`1e8822ed : ffffcc07`51a413c0 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiRaiseSecurityCheckFailure+0xf7
  1164. ffffb681`80c95760 fffff800`1e881801 : ffffdd03`201345d0 ffffcc07`51a413c0 ffffb681`80c95879 ffffdd03`1fdc33a0 : nt!ExDeferredFreePool+0x22cd
  1165. ffffb681`80c957e0 fffff800`1eada99c : 00000000`00000000 ffffcc07`5f8b3a70 ffffcc07`5f8b3a70 ffffcc07`00000001 : nt!ExFreePoolWithTag+0x7e1
  1166. ffffb681`80c958e0 fffff800`1e72ab80 : ffffcc07`5f8b3a70 ffffb681`80c959b0 fffff800`1e97e640 ffffb681`7fe00180 : nt!MiSegmentDelete+0x10c
  1167. ffffb681`80c95930 fffff800`1e74ef8c : 00000000`00000002 fffff800`1e97e658 fffff800`1e97e100 fffff800`1e97e100 : nt!MiProcessDereferenceList+0xb0
  1168. ffffb681`80c959e0 fffff800`1e6ddac7 : ffffb681`7fe00180 ffffcc07`5f88e7c0 00000000`00000080 fffff800`1e74ee70 : nt!MiDereferenceSegmentThread+0x11c
  1169. ffffb681`80c95c10 fffff800`1e772946 : ffffb681`7fe00180 ffffcc07`5f88e7c0 fffff800`1e6dda80 fffff800`1e6c7f14 : nt!PspSystemThreadStartup+0x47
  1170. ffffb681`80c95c60 00000000`00000000 : ffffb681`80c96000 ffffb681`80c90000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x16
  1171. STACK_COMMAND: kb
  1172. CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
  1173. fffff8001e719b19-fffff8001e719b1a 2 bytes - nt!MiUnlockPagedAddress+21
  1174. [ 80 f6:00 97 ]
  1175. fffff8001e719b41 - nt!MiUnlockPagedAddress+49 (+0x28)
  1176. [ fa:91 ]
  1177. 3 errors : !nt (fffff8001e719b19-fffff8001e719b41)
  1178. MODULE_NAME: memory_corruption
  1179.  
  1180. IMAGE_NAME: memory_corruption
  1181.  
  1182. FOLLOWUP_NAME: memory_corruption
  1183. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  1184. MEMORY_CORRUPTOR: LARGE
  1185. FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
  1186. BUCKET_ID: MEMORY_CORRUPTION_LARGE
  1187. PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
  1188. TARGET_TIME: 2017-07-20T20:28:26.000Z
  1189. OSBUILD: 15063
  1190. OSSERVICEPACK: 483
  1191. SERVICEPACK_NUMBER: 0
  1192. OS_REVISION: 0
  1193. SUITE_MASK: 272
  1194. PRODUCT_TYPE: 1
  1195. OSPLATFORM_TYPE: x64
  1196. OSNAME: Windows 10
  1197. OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
  1198. USER_LCID: 0
  1199. OSBUILD_TIMESTAMP: 2017-07-07 02:06:35
  1200. BUILDDATESTAMP_STR: 160101.0800
  1201. BUILDLAB_STR: WinBuild
  1202. BUILDOSVER_STR: 10.0.15063.483
  1203. ANALYSIS_SESSION_ELAPSED_TIME: 2aae
  1204. ANALYSIS_SOURCE: KM
  1205. FAILURE_ID_HASH_STRING: km:memory_corruption_large
  1206. FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
  1207. Followup: memory_corruption
  1208.  
  1209. ========================================================================
  1210. =================== Dump File: 071917-16546-01.dmp ===================
  1211. ========================================================================
  1212. Mini Kernel Dump File: Only registers and stack trace are available
  1213. Windows 10 Kernel Version 15063 MP (8 procs) Free x64
  1214. Product: WinNt, suite: TerminalServer SingleUserTS
  1215. Built by: 15063.0.amd64fre.rs2_release.170317-1834
  1216. Kernel base = 0xfffff801`87a7e000 PsLoadedModuleList = 0xfffff801`87dca5e0
  1217. Debug session time: Wed Jul 19 17:40:46.556 2017 (UTC - 4:00)
  1218. System Uptime: 0 days 0:20:19.189
  1219.  
  1220. BugCheck 50, {fffff4fa40000040, 0, 0, 6}
  1221. Could not read faulting driver name
  1222. *** WARNING: Unable to verify timestamp for win32k.sys
  1223. *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
  1224. Probably caused by : memory_corruption
  1225. Followup: memory_corruption
  1226.  
  1227. PAGE_FAULT_IN_NONPAGED_AREA (50)
  1228. Invalid system memory was referenced. This cannot be protected by try-except.
  1229. Typically the address is just plain bad or it is pointing at freed memory.
  1230.  
  1231. Arguments:
  1232. Arg1: fffff4fa40000040, memory referenced.
  1233. Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
  1234. Arg3: 0000000000000000, If non-zero, the instruction address which referenced the bad memory
  1235. address.
  1236. Arg4: 0000000000000006, (reserved)
  1237.  
  1238. Debugging Details:
  1239. Could not read faulting driver name
  1240. DUMP_CLASS: 1
  1241. DUMP_QUALIFIER: 400
  1242. BUILD_VERSION_STRING: 10.0.15063.483 (WinBuild.160101.0800)
  1243. SYSTEM_MANUFACTURER: ASUS
  1244. SYSTEM_PRODUCT_NAME: All Series
  1245. SYSTEM_SKU: All
  1246. BIOS_VENDOR: American Megatrends Inc.
  1247. BIOS_VERSION: 2603
  1248. BIOS_DATE: 02/22/2016
  1249. BASEBOARD_MANUFACTURER: ASUSTeK COMPUTER INC.
  1250. BASEBOARD_PRODUCT: H97M-PLUS
  1251. BASEBOARD_VERSION: Rev X.0x
  1252. DUMP_TYPE: 2
  1253. READ_ADDRESS: fffff80187e5f358: Unable to get MiVisibleState
  1254. fffff4fa40000040
  1255. MM_INTERNAL_CODE: 6
  1256. CPU_COUNT: 8
  1257. CPU_MHZ: c15
  1258. CPU_VENDOR: GenuineIntel
  1259. CPU_FAMILY: 6
  1260. CPU_MODEL: 3c
  1261. CPU_STEPPING: 3
  1262. CPU_MICROCODE: 6,3c,3,0 (F,M,S,R) SIG: 1E'00000000 (cache) 1E'00000000 (init)
  1263. CUSTOMER_CRASH_COUNT: 1
  1264. DEFAULT_BUCKET_ID: CODE_CORRUPTION
  1265. BUGCHECK_STR: AV
  1266.  
  1267. PROCESS_NAME: System
  1268.  
  1269. CURRENT_IRQL: 2
  1270. TRAP_FRAME: ffff9b8009fe4700 -- (.trap 0xffff9b8009fe4700)
  1271. NOTE: The trap frame does not contain all registers.
  1272. Some register values may be zeroed or incorrect.
  1273. rax=0000000000000040 rbx=0000000000000000 rcx=fffff4fa40000000
  1274. rdx=ffff9b8009fe4980 rsi=0000000000000000 rdi=0000000000000000
  1275. rip=fffff80187ae7d08 rsp=ffff9b8009fe4890 rbp=ffff9b8009fe49d9
  1276. r8=0000000000000000 r9=0000000000000000 r10=7ffffffffffffffc
  1277. r11=ffffd8805f976ad0 r12=0000000000000000 r13=0000000000000000
  1278. r14=0000000000000000 r15=0000000000000000
  1279. iopl=0 nv up ei pl nz na pe nc
  1280. nt!ExFreeLargePool+0x68:
  1281. fffff801`87ae7d08 488b0408 mov rax,qword ptr [rax+rcx] ds:fffff4fa`40000040=????????????????
  1282. Resetting default scope
  1283. LAST_CONTROL_TRANSFER: from fffff80187c203f2 to fffff80187bea4c0
  1284. STACK_TEXT:
  1285. ffff9b80`09fe4508 fffff801`87c203f2 : 00000000`00000050 fffff4fa`40000040 00000000`00000000 fffff4fa`7d200000 : nt!KeBugCheckEx
  1286. ffff9b80`09fe4510 fffff801`87bf3d72 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MmAccessFault+0x115c02
  1287. ffff9b80`09fe4700 fffff801`87ae7d08 : ffff9b80`09fe4990 fffff801`87a04ef5 00000000`00000000 ffffae89`998c9001 : nt!KiPageFault+0x132
  1288. ffff9b80`09fe4890 fffff801`87cfe4ef : 00000000`01000000 ffff9b80`09fe4980 00000000`00000000 fffff801`00000000 : nt!ExFreeLargePool+0x68
  1289. ffff9b80`09fe4940 fffff801`8805d37f : 00000000`00000003 00000000`00000000 00000000`00000000 00000000`00080000 : nt!ExFreePoolWithTag+0x4cf
  1290. ffff9b80`09fe4a40 fffff801`87ec077b : ffff9b80`09fe4b28 00000000`00000000 ffffd880`56d72de8 ffff9b80`09fe4b28 : nt!CmpFreeKeyControlBlock+0x19e4ef
  1291. ffff9b80`09fe4a80 fffff801`87edec7d : ffff9b80`09fe4b30 ffff9b80`09fe4b3c 00000000`00000003 00000000`00000000 : nt!CmpUnlockKcb+0x6b
  1292. ffff9b80`09fe4ab0 fffff801`87abbca8 : ffffae89`8ec0a7c0 fffff801`87edea70 fffff801`87de6000 ffffae89`8f4a7750 : nt!CmpDelayCloseWorker+0x20d
  1293. ffff9b80`09fe4b80 fffff801`87b5aac7 : 0030005f`0043004e 00000000`00000080 ffffae89`8e8b9680 ffffae89`8ec0a7c0 : nt!ExpWorkerThread+0xd8
  1294. ffff9b80`09fe4c10 fffff801`87bef946 : ffff9b80`093e0180 ffffae89`8ec0a7c0 fffff801`87b5aa80 00660061`00660036 : nt!PspSystemThreadStartup+0x47
  1295. ffff9b80`09fe4c60 00000000`00000000 : ffff9b80`09fe5000 ffff9b80`09fdf000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x16
  1296. STACK_COMMAND: kb
  1297. CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
  1298. fffff80187cfe384-fffff80187cfe385 2 bytes - nt!ExFreePoolWithTag+364
  1299. [ fb f6:fa f4 ]
  1300. 2 errors : !nt (fffff80187cfe384-fffff80187cfe385)
  1301. MODULE_NAME: memory_corruption
  1302.  
  1303. IMAGE_NAME: memory_corruption
  1304.  
  1305. FOLLOWUP_NAME: memory_corruption
  1306. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  1307. MEMORY_CORRUPTOR: ONE_BIT_LARGE
  1308. FAILURE_BUCKET_ID: MEMORY_CORRUPTION_ONE_BIT_LARGE
  1309. BUCKET_ID: MEMORY_CORRUPTION_ONE_BIT_LARGE
  1310. PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_ONE_BIT_LARGE
  1311. TARGET_TIME: 2017-07-19T21:40:46.000Z
  1312. OSBUILD: 15063
  1313. OSSERVICEPACK: 483
  1314. SERVICEPACK_NUMBER: 0
  1315. OS_REVISION: 0
  1316. SUITE_MASK: 272
  1317. PRODUCT_TYPE: 1
  1318. OSPLATFORM_TYPE: x64
  1319. OSNAME: Windows 10
  1320. OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
  1321. USER_LCID: 0
  1322. OSBUILD_TIMESTAMP: 2017-07-07 02:06:35
  1323. BUILDDATESTAMP_STR: 160101.0800
  1324. BUILDLAB_STR: WinBuild
  1325. BUILDOSVER_STR: 10.0.15063.483
  1326. ANALYSIS_SESSION_ELAPSED_TIME: 398c
  1327. ANALYSIS_SOURCE: KM
  1328. FAILURE_ID_HASH_STRING: km:memory_corruption_one_bit_large
  1329. FAILURE_ID_HASH: {31545515-196b-fab5-2300-9ce714226f43}
  1330. Followup: memory_corruption
  1331.  
  1332. ========================================================================
  1333. =================== Dump File: 071817-17531-01.dmp ===================
  1334. ========================================================================
  1335. Mini Kernel Dump File: Only registers and stack trace are available
  1336. Windows 10 Kernel Version 15063 MP (8 procs) Free x64
  1337. Product: WinNt, suite: TerminalServer SingleUserTS
  1338. Built by: 15063.0.amd64fre.rs2_release.170317-1834
  1339. Kernel base = 0xfffff802`23685000 PsLoadedModuleList = 0xfffff802`239d15e0
  1340. Debug session time: Tue Jul 18 09:39:23.117 2017 (UTC - 4:00)
  1341. System Uptime: 0 days 0:11:07.881
  1342.  
  1343. BugCheck 19, {22, ffff80017121a000, 1, 0}
  1344. Probably caused by : CI.dll ( CI!MincryptFreePolicyInfo+26 )
  1345. Followup: MachineOwner
  1346.  
  1347. BAD_POOL_HEADER (19)
  1348. The pool is already corrupt at the time of the current request.
  1349. This may or may not be due to the caller.
  1350. The internal pool links must be walked to figure out a possible cause of
  1351. the problem, and then special pool applied to the suspect tags or the driver
  1352. verifier to a suspect driver.
  1353.  
  1354. Arguments:
  1355. Arg1: 0000000000000022,
  1356. Arg2: ffff80017121a000
  1357. Arg3: 0000000000000001
  1358. Arg4: 0000000000000000
  1359.  
  1360. Debugging Details:
  1361. DUMP_CLASS: 1
  1362. DUMP_QUALIFIER: 400
  1363. BUILD_VERSION_STRING: 10.0.15063.483 (WinBuild.160101.0800)
  1364. SYSTEM_MANUFACTURER: ASUS
  1365. SYSTEM_PRODUCT_NAME: All Series
  1366. SYSTEM_SKU: All
  1367. BIOS_VENDOR: American Megatrends Inc.
  1368. BIOS_VERSION: 2603
  1369. BIOS_DATE: 02/22/2016
  1370. BASEBOARD_MANUFACTURER: ASUSTeK COMPUTER INC.
  1371. BASEBOARD_PRODUCT: H97M-PLUS
  1372. BASEBOARD_VERSION: Rev X.0x
  1373. DUMP_TYPE: 2
  1374. BUGCHECK_STR: 0x19_22
  1375. POOL_ADDRESS: fffff80223a66358: Unable to get MiVisibleState
  1376. ffff80017121a000
  1377. CPU_COUNT: 8
  1378. CPU_MHZ: c15
  1379. CPU_VENDOR: GenuineIntel
  1380. CPU_FAMILY: 6
  1381. CPU_MODEL: 3c
  1382. CPU_STEPPING: 3
  1383. CPU_MICROCODE: 6,3c,3,0 (F,M,S,R) SIG: 1E'00000000 (cache) 1E'00000000 (init)
  1384. CUSTOMER_CRASH_COUNT: 1
  1385. DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
  1386.  
  1387. PROCESS_NAME: System
  1388.  
  1389. CURRENT_IRQL: 2
  1390. LAST_CONTROL_TRANSFER: from fffff8022381d75c to fffff802237f14c0
  1391. STACK_TEXT:
  1392. ffffc381`9e9658e8 fffff802`2381d75c : 00000000`00000019 00000000`00000022 ffff8001`7121a000 00000000`00000001 : nt!KeBugCheckEx
  1393. ffffc381`9e9658f0 fffff802`239054ef : ffff8001`7121a000 ffffc381`9e9659e0 00000000`00000000 00000000`00000001 : nt!ExFreeLargePool+0x12eabc
  1394. ffffc381`9e9659a0 fffff80d`efa7fa4e : ffff8001`702aad58 fffff802`237064ed 00000000`00000003 ffff8001`6e569898 : nt!ExFreePoolWithTag+0x4cf
  1395. ffffc381`9e965aa0 fffff80d`efa69b56 : ffffa28a`169d1e20 ffffa28a`12332b48 fffff802`23a7d201 ffffa28a`12332b48 : CI!MincryptFreePolicyInfo+0x26
  1396. ffffc381`9e965ad0 fffff80d`efa6cd77 : ffffa28a`12332b48 ffffa28a`169d1e20 ffff8001`6e4eedc0 00000000`00000001 : CI!I_FreeCatalogData+0x62
  1397. ffffc381`9e965b00 fffff80d`efa655d8 : 00000000`00000000 fffff80d`efa65580 ffffa28a`169d1ea0 00000000`00000300 : CI!CiTrimCatalogs+0x17f
  1398. ffffc381`9e965b50 fffff802`236c2ca8 : ffffa28a`1e8eb040 00000000`783a5a00 fffff802`23758ea0 fffff802`239ce300 : CI!CipPostBootWorker+0x58
  1399. ffffc381`9e965b80 fffff802`23761ac7 : 7250620a`61736153 00000000`00000080 ffffa28a`1221e040 ffffa28a`1e8eb040 : nt!ExpWorkerThread+0xd8
  1400. ffffc381`9e965c10 fffff802`237f6946 : ffffc381`9b400180 ffffa28a`1e8eb040 fffff802`23761a80 00010b15`00005331 : nt!PspSystemThreadStartup+0x47
  1401. ffffc381`9e965c60 00000000`00000000 : ffffc381`9e966000 ffffc381`9e960000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x16
  1402. STACK_COMMAND: kb
  1403. THREAD_SHA1_HASH_MOD_FUNC: 4b949bc2c12ae01c3edf98d640e4b12bd61a4327
  1404. THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 273a738ee258368ea7dfb0fb6053096f0f548662
  1405. THREAD_SHA1_HASH_MOD: 6aad5f1d05ac89741af71803f6a8100f925d6eb6
  1406. FOLLOWUP_IP:
  1407. CI!MincryptFreePolicyInfo+26
  1408. fffff80d`efa7fa4e 33d2 xor edx,edx
  1409. FAULT_INSTR_CODE: 8b48d233
  1410. SYMBOL_STACK_INDEX: 3
  1411. SYMBOL_NAME: CI!MincryptFreePolicyInfo+26
  1412. FOLLOWUP_NAME: MachineOwner
  1413. MODULE_NAME: CI
  1414.  
  1415. IMAGE_NAME: CI.dll
  1416.  
  1417. DEBUG_FLR_IMAGE_TIMESTAMP: 57c1e861
  1418. IMAGE_VERSION: 10.0.15063.251
  1419. BUCKET_ID_FUNC_OFFSET: 26
  1420. FAILURE_BUCKET_ID: 0x19_22_CI!MincryptFreePolicyInfo
  1421. BUCKET_ID: 0x19_22_CI!MincryptFreePolicyInfo
  1422. PRIMARY_PROBLEM_CLASS: 0x19_22_CI!MincryptFreePolicyInfo
  1423. TARGET_TIME: 2017-07-18T13:39:23.000Z
  1424. OSBUILD: 15063
  1425. OSSERVICEPACK: 483
  1426. SERVICEPACK_NUMBER: 0
  1427. OS_REVISION: 0
  1428. SUITE_MASK: 272
  1429. PRODUCT_TYPE: 1
  1430. OSPLATFORM_TYPE: x64
  1431. OSNAME: Windows 10
  1432. OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
  1433. USER_LCID: 0
  1434. OSBUILD_TIMESTAMP: 2017-07-07 02:06:35
  1435. BUILDDATESTAMP_STR: 160101.0800
  1436. BUILDLAB_STR: WinBuild
  1437. BUILDOSVER_STR: 10.0.15063.483
  1438. ANALYSIS_SESSION_ELAPSED_TIME: 99b
  1439. ANALYSIS_SOURCE: KM
  1440. FAILURE_ID_HASH_STRING: km:0x19_22_ci!mincryptfreepolicyinfo
  1441. FAILURE_ID_HASH: {28844b18-239c-4dbb-0fee-731ea86689d2}
  1442. Followup: MachineOwner
  1443.  
  1444. ========================================================================
  1445. =================== Dump File: 071817-16312-01.dmp ===================
  1446. ========================================================================
  1447. Mini Kernel Dump File: Only registers and stack trace are available
  1448. Windows 10 Kernel Version 15063 MP (8 procs) Free x64
  1449. Product: WinNt, suite: TerminalServer SingleUserTS
  1450. Built by: 15063.0.amd64fre.rs2_release.170317-1834
  1451. Kernel base = 0xfffff802`36a90000 PsLoadedModuleList = 0xfffff802`36ddc5e0
  1452. Debug session time: Tue Jul 18 01:20:04.815 2017 (UTC - 4:00)
  1453. System Uptime: 0 days 1:48:43.574
  1454.  
  1455. BugCheck 3B, {c0000005, fffff80236c01fc7, ffffe48172648890, 0}
  1456. Probably caused by : ntkrnlmp.exe ( nt!CmpCreateKeyBody+8f )
  1457. Followup: MachineOwner
  1458.  
  1459. SYSTEM_SERVICE_EXCEPTION (3b)
  1460. An exception happened while executing a system service routine.
  1461.  
  1462. Arguments:
  1463. Arg1: 00000000c0000005, Exception code that caused the bugcheck
  1464. Arg2: fffff80236c01fc7, Address of the instruction which caused the bugcheck
  1465. Arg3: ffffe48172648890, Address of the context record for the exception that caused the bugcheck
  1466. Arg4: 0000000000000000, zero.
  1467.  
  1468. Debugging Details:
  1469. DUMP_CLASS: 1
  1470. DUMP_QUALIFIER: 400
  1471. BUILD_VERSION_STRING: 10.0.15063.483 (WinBuild.160101.0800)
  1472. SYSTEM_MANUFACTURER: ASUS
  1473. SYSTEM_PRODUCT_NAME: All Series
  1474. SYSTEM_SKU: All
  1475. BIOS_VENDOR: American Megatrends Inc.
  1476. BIOS_VERSION: 2603
  1477. BIOS_DATE: 02/22/2016
  1478. BASEBOARD_MANUFACTURER: ASUSTeK COMPUTER INC.
  1479. BASEBOARD_PRODUCT: H97M-PLUS
  1480. BASEBOARD_VERSION: Rev X.0x
  1481. DUMP_TYPE: 2
  1482. EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.
  1483. FAULTING_IP:
  1484. nt!ExpInterlockedPopEntrySListFault+0
  1485. fffff802`36c01fc7 498b08 mov rcx,qword ptr [r8]
  1486. CONTEXT: ffffe48172648890 -- (.cxr 0xffffe48172648890)
  1487. rax=00000007649a0002 rbx=0000000000000000 rcx=ffffab00bfeb0b10
  1488. rdx=5364615602050000 rsi=0000000000000000 rdi=0000000000000000
  1489. rip=fffff80236c01fc7 rsp=ffffe48172649280 rbp=ffffab00bfeb0b10
  1490. r8=5364615602050000 r9=0000000000000000 r10=ffffab00bfeb0b10
  1491. r11=ffffe48172649310 r12=ffffe4816dd80180 r13=ffffab00bff47d90
  1492. r14=ffff9186959b9a70 r15=0000000000000001
  1493. iopl=0 nv up ei pl nz na po nc
  1494. cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010206
  1495. nt!ExpInterlockedPopEntrySListFault:
  1496. fffff802`36c01fc7 498b08 mov rcx,qword ptr [r8] ds:002b:53646156`02050000=????????????????
  1497. Resetting default scope
  1498. CPU_COUNT: 8
  1499. CPU_MHZ: c15
  1500. CPU_VENDOR: GenuineIntel
  1501. CPU_FAMILY: 6
  1502. CPU_MODEL: 3c
  1503. CPU_STEPPING: 3
  1504. CPU_MICROCODE: 6,3c,3,0 (F,M,S,R) SIG: 1E'00000000 (cache) 1E'00000000 (init)
  1505. CUSTOMER_CRASH_COUNT: 1
  1506. DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
  1507. BUGCHECK_STR: 0x3B
  1508.  
  1509. PROCESS_NAME: explorer.exe
  1510.  
  1511. CURRENT_IRQL: 0
  1512. LAST_CONTROL_TRANSFER: from fffff80236f28d0f to fffff80236c01fc7
  1513. STACK_TEXT:
  1514. ffffe481`72649280 fffff802`36f28d0f : 00000006`00060001 fffff802`00000006 00000000`00000000 ffff9186`8eb2c000 : nt!ExpInterlockedPopEntrySListFault
  1515. ffffe481`72649290 fffff802`36f2d058 : 00000000`00000000 00000000`00000001 ffffe481`72649cd0 00000000`00000000 : nt!CmpCreateKeyBody+0x8f
  1516. ffffe481`72649340 fffff802`36f38306 : ffffe481`0000001c ffffe481`72649810 ffffe481`72649790 ffff9186`949316b0 : nt!CmpDoParseKey+0xa48
  1517. ffffe481`72649720 fffff802`36f3261b : ffffab00`c0b24b10 fffff491`00000000 ffffab00`c0b24b10 ffffe481`72649b01 : nt!CmpParseKey+0x266
  1518. ffffe481`726498f0 fffff802`36f36150 : ffffab00`c0b24b00 ffffe481`72649b58 ffff9186`00000040 ffffab00`bff47d90 : nt!ObpLookupObjectName+0x46b
  1519. ffffe481`72649ac0 fffff802`36f36e54 : 00000000`00000001 ffffab00`bff47d90 00000000`00000000 00000000`00000000 : nt!ObOpenObjectByNameEx+0x1e0
  1520. ffffe481`72649c00 fffff802`36f39b7f : 00000000`0000a91c fffff491`e0ecdd29 00000000`00000000 00000000`00090402 : nt!CmOpenKey+0x274
  1521. ffffe481`72649e00 fffff802`36c07413 : ffffab00`ce4c67c0 00000000`0c6c9220 00000000`00000005 00000000`00000100 : nt!NtOpenKeyEx+0xf
  1522. ffffe481`72649e40 00007ffb`9d107634 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
  1523. 00000000`10fce0f8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffb`9d107634
  1524. THREAD_SHA1_HASH_MOD_FUNC: d994e0c1e6e8349776dc8ce6a9e19057de601648
  1525. THREAD_SHA1_HASH_MOD_FUNC_OFFSET: a111c5851d3b0f25f8dc319ad34f118ec6262adb
  1526. THREAD_SHA1_HASH_MOD: 9f457f347057f10e1df248e166a3e95e6570ecfe
  1527. FOLLOWUP_IP:
  1528. nt!CmpCreateKeyBody+8f
  1529. fffff802`36f28d0f 488bf0 mov rsi,rax
  1530. FAULT_INSTR_CODE: 48f08b48
  1531. SYMBOL_STACK_INDEX: 1
  1532. SYMBOL_NAME: nt!CmpCreateKeyBody+8f
  1533. FOLLOWUP_NAME: MachineOwner
  1534. MODULE_NAME: nt
  1535.  
  1536. IMAGE_NAME: ntkrnlmp.exe
  1537.  
  1538. DEBUG_FLR_IMAGE_TIMESTAMP: 595f24eb
  1539. IMAGE_VERSION: 10.0.15063.483
  1540. STACK_COMMAND: .cxr 0xffffe48172648890 ; kb
  1541. BUCKET_ID_FUNC_OFFSET: 8f
  1542. FAILURE_BUCKET_ID: 0x3B_nt!CmpCreateKeyBody
  1543. BUCKET_ID: 0x3B_nt!CmpCreateKeyBody
  1544. PRIMARY_PROBLEM_CLASS: 0x3B_nt!CmpCreateKeyBody
  1545. TARGET_TIME: 2017-07-18T05:20:04.000Z
  1546. OSBUILD: 15063
  1547. OSSERVICEPACK: 483
  1548. SERVICEPACK_NUMBER: 0
  1549. OS_REVISION: 0
  1550. SUITE_MASK: 272
  1551. PRODUCT_TYPE: 1
  1552. OSPLATFORM_TYPE: x64
  1553. OSNAME: Windows 10
  1554. OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
  1555. USER_LCID: 0
  1556. OSBUILD_TIMESTAMP: 2017-07-07 02:06:35
  1557. BUILDDATESTAMP_STR: 160101.0800
  1558. BUILDLAB_STR: WinBuild
  1559. BUILDOSVER_STR: 10.0.15063.483
  1560. ANALYSIS_SESSION_ELAPSED_TIME: 782a
  1561. ANALYSIS_SOURCE: KM
  1562. FAILURE_ID_HASH_STRING: km:0x3b_nt!cmpcreatekeybody
  1563. FAILURE_ID_HASH: {9082b3ad-154f-c3b5-53fd-dcb083d044d2}
  1564. Followup: MachineOwner
  1565.  
  1566. ========================================================================
  1567. =================== Dump File: 072117-15484-01.dmp ===================
  1568. ========================================================================
  1569. Mini Kernel Dump File: Only registers and stack trace are available
  1570. Windows 10 Kernel Version 15063 MP (8 procs) Free x64
  1571. Product: WinNt, suite: TerminalServer SingleUserTS
  1572. Built by: 15063.0.amd64fre.rs2_release.170317-1834
  1573. Kernel base = 0xfffff800`21489000 PsLoadedModuleList = 0xfffff800`217d55e0
  1574. Debug session time: Thu Jul 20 21:41:10.463 2017 (UTC - 4:00)
  1575. System Uptime: 0 days 5:11:49.224
  1576.  
  1577. BugCheck 1A, {41793, ffffb98115870e28, 9, 8}
  1578. Probably caused by : memory_corruption
  1579. Followup: memory_corruption
  1580.  
  1581. MEMORY_MANAGEMENT (1a)
  1582. # Any other values for parameter 1 must be individually examined.
  1583.  
  1584. Arguments:
  1585. Arg1: 0000000000041793, The subtype of the bugcheck.
  1586. Arg2: ffffb98115870e28
  1587. Arg3: 0000000000000009
  1588. Arg4: 0000000000000008
  1589.  
  1590. Debugging Details:
  1591. DUMP_CLASS: 1
  1592. DUMP_QUALIFIER: 400
  1593. BUILD_VERSION_STRING: 10.0.15063.483 (WinBuild.160101.0800)
  1594. SYSTEM_MANUFACTURER: ASUS
  1595. SYSTEM_PRODUCT_NAME: All Series
  1596. SYSTEM_SKU: All
  1597. BIOS_VENDOR: American Megatrends Inc.
  1598. BIOS_VERSION: 2603
  1599. BIOS_DATE: 02/22/2016
  1600. BASEBOARD_MANUFACTURER: ASUSTeK COMPUTER INC.
  1601. BASEBOARD_PRODUCT: H97M-PLUS
  1602. BASEBOARD_VERSION: Rev X.0x
  1603. DUMP_TYPE: 2
  1604. BUGCHECK_STR: 0x1a_41793
  1605. CPU_COUNT: 8
  1606. CPU_MHZ: c15
  1607. CPU_VENDOR: GenuineIntel
  1608. CPU_FAMILY: 6
  1609. CPU_MODEL: 3c
  1610. CPU_STEPPING: 3
  1611. CPU_MICROCODE: 6,3c,3,0 (F,M,S,R) SIG: 1E'00000000 (cache) 1E'00000000 (init)
  1612. CUSTOMER_CRASH_COUNT: 1
  1613. DEFAULT_BUCKET_ID: CODE_CORRUPTION
  1614.  
  1615. PROCESS_NAME: MsMpEng.exe
  1616.  
  1617. CURRENT_IRQL: 2
  1618. LAST_CONTROL_TRANSFER: from fffff80021628cd0 to fffff800215f54c0
  1619. STACK_TEXT:
  1620. ffffd581`b2b1d5a8 fffff800`21628cd0 : 00000000`0000001a 00000000`00041793 ffffb981`15870e28 00000000`00000009 : nt!KeBugCheckEx
  1621. ffffd581`b2b1d5b0 fffff800`215085bd : ffff8803`05db9d88 ffff8803`06807080 ffff8803`05db9d88 ffff8803`05db97c0 : nt!MiDeleteVirtualAddresses+0x11b980
  1622. ffffd581`b2b1d860 fffff800`2193d89c : 0000022b`0de00000 ffff8803`01a91d40 ffffffff`ffffffff 00000000`00000000 : nt!MiDeleteVad+0x3ad
  1623. ffffd581`b2b1d9e0 fffff800`219b39c6 : ffff8803`05db97c0 ffffd581`00000008 ffff8802`f96c2f20 0000022b`0de00000 : nt!MiUnmapViewOfSection+0xec
  1624. ffffd581`b2b1dab0 fffff800`21600413 : ffff8803`06807080 00000000`ffffffff 00000000`00000000 ffff8803`05db97c0 : nt!NtUnmapViewOfSectionEx+0x86
  1625. ffffd581`b2b1db00 00007ff8`39228b54 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
  1626. 000000a7`562ff138 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff8`39228b54
  1627. STACK_COMMAND: kb
  1628. CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
  1629. fffff800214d30f6 - nt!MiCreateDecayPfn+56
  1630. [ 80:00 ]
  1631. 1 error : !nt (fffff800214d30f6)
  1632. MODULE_NAME: memory_corruption
  1633.  
  1634. IMAGE_NAME: memory_corruption
  1635.  
  1636. FOLLOWUP_NAME: memory_corruption
  1637. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  1638. MEMORY_CORRUPTOR: ONE_BIT
  1639. FAILURE_BUCKET_ID: MEMORY_CORRUPTION_ONE_BIT
  1640. BUCKET_ID: MEMORY_CORRUPTION_ONE_BIT
  1641. PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_ONE_BIT
  1642. TARGET_TIME: 2017-07-21T01:41:10.000Z
  1643. OSBUILD: 15063
  1644. OSSERVICEPACK: 483
  1645. SERVICEPACK_NUMBER: 0
  1646. OS_REVISION: 0
  1647. SUITE_MASK: 272
  1648. PRODUCT_TYPE: 1
  1649. OSPLATFORM_TYPE: x64
  1650. OSNAME: Windows 10
  1651. OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
  1652. USER_LCID: 0
  1653. OSBUILD_TIMESTAMP: 2017-07-07 02:06:35
  1654. BUILDDATESTAMP_STR: 160101.0800
  1655. BUILDLAB_STR: WinBuild
  1656. BUILDOSVER_STR: 10.0.15063.483
  1657. ANALYSIS_SESSION_ELAPSED_TIME: 3963
  1658. ANALYSIS_SOURCE: KM
  1659. FAILURE_ID_HASH_STRING: km:memory_corruption_one_bit
  1660. FAILURE_ID_HASH: {e3faf315-c3d0-81db-819a-6c43d23c63a7}
  1661. Followup: memory_corruption
  1662.  
  1663. ========================================================================
  1664. =================== Dump File: 072117-14671-01.dmp ===================
  1665. ========================================================================
  1666. Mini Kernel Dump File: Only registers and stack trace are available
  1667. Windows 10 Kernel Version 15063 MP (8 procs) Free x64
  1668. Product: WinNt, suite: TerminalServer SingleUserTS
  1669. Built by: 15063.0.amd64fre.rs2_release.170317-1834
  1670. Kernel base = 0xfffff800`d9c0e000 PsLoadedModuleList = 0xfffff800`d9f5a5e0
  1671. Debug session time: Thu Jul 20 22:04:22.263 2017 (UTC - 4:00)
  1672. System Uptime: 0 days 0:22:18.021
  1673.  
  1674. BugCheck 133, {1, 1e00, fffff800d9fef348, 0}
  1675. *************************************************************************
  1676. *** Either you specified an unqualified symbol, or your debugger ***
  1677. *** doesn't have full symbol information. Unqualified symbol ***
  1678. *** resolution is turned off by default. Please either specify a ***
  1679. *** fully qualified symbol module!symbolname, or enable resolution ***
  1680. *** of unqualified symbols by typing ".symopt- 100". Note that ***
  1681. *** enabling unqualified symbol resolution with network symbol ***
  1682. *** server shares in the symbol path may cause the debugger to ***
  1683. *** appear to hang for long periods of time when an incorrect ***
  1684. *** symbol name is typed or the network symbol server is down. ***
  1685. *** For some commands to work properly, your symbol path ***
  1686. *** must point to .pdb files that have full type information. ***
  1687. *** Certain .pdb files (such as the public OS symbols) do not ***
  1688. *** contain the required information. Contact the group that ***
  1689. *** provided you with these symbols if you need this command to ***
  1690. *** work. ***
  1691. *** Type referenced: TickPeriods ***
  1692. *************************************************************************
  1693. Probably caused by : memory_corruption
  1694. Followup: memory_corruption
  1695.  
  1696. DPC_WATCHDOG_VIOLATION (133)
  1697. The DPC watchdog detected a prolonged run time at an IRQL of DISPATCH_LEVEL
  1698. or above.
  1699.  
  1700. Arguments:
  1701. Arg1: 0000000000000001, The system cumulatively spent an extended period of time at
  1702. DISPATCH_LEVEL or above. The offending component can usually be
  1703. identified with a stack trace.
  1704. Arg2: 0000000000001e00, The watchdog period.
  1705. Arg3: fffff800d9fef348
  1706. Arg4: 0000000000000000
  1707.  
  1708. Debugging Details:
  1709. *************************************************************************
  1710. *** Either you specified an unqualified symbol, or your debugger ***
  1711. *** doesn't have full symbol information. Unqualified symbol ***
  1712. *** resolution is turned off by default. Please either specify a ***
  1713. *** fully qualified symbol module!symbolname, or enable resolution ***
  1714. *** of unqualified symbols by typing ".symopt- 100". Note that ***
  1715. *** enabling unqualified symbol resolution with network symbol ***
  1716. *** server shares in the symbol path may cause the debugger to ***
  1717. *** appear to hang for long periods of time when an incorrect ***
  1718. *** symbol name is typed or the network symbol server is down. ***
  1719. *** For some commands to work properly, your symbol path ***
  1720. *** must point to .pdb files that have full type information. ***
  1721. *** Certain .pdb files (such as the public OS symbols) do not ***
  1722. *** contain the required information. Contact the group that ***
  1723. *** provided you with these symbols if you need this command to ***
  1724. *** work. ***
  1725. *** Type referenced: TickPeriods ***
  1726. *************************************************************************
  1727. DUMP_CLASS: 1
  1728. DUMP_QUALIFIER: 400
  1729. BUILD_VERSION_STRING: 10.0.15063.483 (WinBuild.160101.0800)
  1730. SYSTEM_MANUFACTURER: ASUS
  1731. SYSTEM_PRODUCT_NAME: All Series
  1732. SYSTEM_SKU: All
  1733. BIOS_VENDOR: American Megatrends Inc.
  1734. BIOS_VERSION: 2603
  1735. BIOS_DATE: 02/22/2016
  1736. BASEBOARD_MANUFACTURER: ASUSTeK COMPUTER INC.
  1737. BASEBOARD_PRODUCT: H97M-PLUS
  1738. BASEBOARD_VERSION: Rev X.0x
  1739. DUMP_TYPE: 2
  1740. DPC_TIMEOUT_TYPE: DPC_QUEUE_EXECUTION_TIMEOUT_EXCEEDED
  1741. CPU_COUNT: 8
  1742. CPU_MHZ: c15
  1743. CPU_VENDOR: GenuineIntel
  1744. CPU_FAMILY: 6
  1745. CPU_MODEL: 3c
  1746. CPU_STEPPING: 3
  1747. CPU_MICROCODE: 6,3c,3,0 (F,M,S,R) SIG: 1E'00000000 (cache) 1E'00000000 (init)
  1748. CUSTOMER_CRASH_COUNT: 1
  1749. DEFAULT_BUCKET_ID: CODE_CORRUPTION
  1750. BUGCHECK_STR: 0x133
  1751.  
  1752. PROCESS_NAME: WmiPrvSE.exe
  1753.  
  1754. CURRENT_IRQL: d
  1755. LAST_CONTROL_TRANSFER: from fffff800d9daa45d to fffff800d9d7a4c0
  1756. STACK_TEXT:
  1757. ffffd180`e4ab4bc8 fffff800`d9daa45d : 00000000`00000133 00000000`00000001 00000000`00001e00 fffff800`d9fef348 : nt!KeBugCheckEx
  1758. ffffd180`e4ab4bd0 fffff800`d9c83899 : 000003db`caebda60 ffffd180`e4a80180 00000000`00014e81 00000000`00000002 : nt!KeAccumulateTicks+0x124f2d
  1759. ffffd180`e4ab4c30 fffff800`da49a676 : 000003db`caebca73 00000000`00000001 ffffd180`e86fa360 ffffa90d`70ec65b0 : nt!KeClockInterruptNotify+0x599
  1760. ffffd180`e4ab4f40 fffff800`d9c1d675 : ffffa90d`70ec6500 00000000`00000000 00000000`00000000 00000000`00000000 : hal!HalpTimerClockInterrupt+0x56
  1761. ffffd180`e4ab4f70 fffff800`d9d7bb5a : ffffd180`e86fa3e0 ffffa90d`70ec6500 ffff8b87`e79f76f8 ffff9e80`01ddec10 : nt!KiCallInterruptServiceRoutine+0xa5
  1762. ffffd180`e4ab4fb0 fffff800`d9d7bfa7 : 00000000`000e505f 000e6cc0`0000902e 80000001`00000000 00001f80`00f802c0 : nt!KiInterruptSubDispatchNoLockNoEtw+0xea
  1763. ffffd180`e86fa360 fffff800`d9ca95a1 : 00000000`00000000 00000000`00000004 00000000`00000000 00000000`00000000 : nt!KiInterruptDispatchNoLockNoEtw+0x37
  1764. ffffd180`e86fa4f0 fffff800`da0e360c : ffffa90d`8392fa70 fffffb68`c07282d8 00000000`00000002 fffffb68`00000000 : nt!MiWalkEntireImage+0x251
  1765. ffffd180`e86fa670 fffff800`da0e4943 : ffffa90d`8392fa70 00007fff`cbda0000 fffffb68`c07282d8 00000000`00000000 : nt!MiSwitchBaseAddress+0x5c
  1766. ffffd180`e86fa6a0 fffff800`da0e4607 : 00007fff`cbda0000 ffffd180`e86fa910 00007fff`cca60000 ffffa90d`83b2e7c0 : nt!MiRelocateImageAgain+0x197
  1767. ffffd180`e86fa720 fffff800`da0c7f21 : ffffd180`e86fa910 ffffd180`e86fa910 ffff8b87`d31ed680 00000000`01000000 : nt!MiValidateExistingImage+0x57
  1768. ffffd180`e86fa780 fffff800`da0c73e3 : 00000000`00000002 ffffd180`e86fa910 ffffa90d`8392fa70 ffffa90d`7e10ab60 : nt!MiShareExistingControlArea+0xb9
  1769. ffffd180`e86fa7c0 fffff800`da0c6c82 : ffffa90d`8392fa70 00000000`00000000 ffffa90d`7e10ab60 00000000`00f80060 : nt!MiCreateImageOrDataSection+0x163
  1770. ffffd180`e86fa8a0 fffff800`da0c7802 : 00000000`11000000 00000000`00000000 ffff8b87`c94cd060 fffff800`da0b9159 : nt!MiCreateSection+0xd2
  1771. ffffd180`e86fa9e0 fffff800`d9d85413 : ffffa90d`83b2e7c0 00000000`00000005 00000000`00000000 000000b0`675fbc78 : nt!NtCreateSection+0x1e2
  1772. ffffd180`e86faa90 00007fff`e60c5ce4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
  1773. 000000b0`675fbc58 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007fff`e60c5ce4
  1774. STACK_COMMAND: kb
  1775. CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
  1776. fffff800d9c960ee-fffff800d9c960ef 2 bytes - nt!MiGetNextPageTable+19e
  1777. [ 80 f6:00 fb ]
  1778. fffff800d9c96121-fffff800d9c96122 2 bytes - nt!MiGetNextPageTable+1d1 (+0x33)
  1779. [ 80 f6:00 fb ]
  1780. fffff800d9ca3816-fffff800d9ca3817 2 bytes - nt!MiPfnShareCountIsZero+186 (+0xd6f5)
  1781. [ 80 f6:00 fb ]
  1782. fffff800d9ca95bc - nt!MiWalkEntireImage+26c (+0x5da6)
  1783. [ fa:9e ]
  1784. fffff800d9ca9604-fffff800d9ca9605 2 bytes - nt!MiWalkEntireImage+2b4 (+0x48)
  1785. [ 80 f6:00 fb ]
  1786. fffff800d9ca9666 - nt!MiWalkEntireImage+316 (+0x62)
  1787. [ fa:9e ]
  1788. fffff800d9e8e383-fffff800d9e8e385 3 bytes - nt!ExFreePoolWithTag+363
  1789. [ 40 fb f6:80 7d fb ]
  1790. 13 errors : !nt (fffff800d9c960ee-fffff800d9e8e385)
  1791. MODULE_NAME: memory_corruption
  1792.  
  1793. IMAGE_NAME: memory_corruption
  1794.  
  1795. FOLLOWUP_NAME: memory_corruption
  1796. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  1797. MEMORY_CORRUPTOR: LARGE
  1798. FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
  1799. BUCKET_ID: MEMORY_CORRUPTION_LARGE
  1800. PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
  1801. TARGET_TIME: 2017-07-21T02:04:22.000Z
  1802. OSBUILD: 15063
  1803. OSSERVICEPACK: 483
  1804. SERVICEPACK_NUMBER: 0
  1805. OS_REVISION: 0
  1806. SUITE_MASK: 272
  1807. PRODUCT_TYPE: 1
  1808. OSPLATFORM_TYPE: x64
  1809. OSNAME: Windows 10
  1810. OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
  1811. USER_LCID: 0
  1812. OSBUILD_TIMESTAMP: 2017-07-07 02:06:35
  1813. BUILDDATESTAMP_STR: 160101.0800
  1814. BUILDLAB_STR: WinBuild
  1815. BUILDOSVER_STR: 10.0.15063.483
  1816. ANALYSIS_SESSION_ELAPSED_TIME: 2cbb
  1817. ANALYSIS_SOURCE: KM
  1818. FAILURE_ID_HASH_STRING: km:memory_corruption_large
  1819. FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
  1820. Followup: memory_corruption
  1821.  
  1822. ========================================================================
  1823. =================== Dump File: 072117-16578-01.dmp ===================
  1824. ========================================================================
  1825. Mini Kernel Dump File: Only registers and stack trace are available
  1826. Windows 10 Kernel Version 15063 MP (8 procs) Free x64
  1827. Product: WinNt, suite: TerminalServer SingleUserTS
  1828. Built by: 15063.0.amd64fre.rs2_release.170317-1834
  1829. Kernel base = 0xfffff801`cb084000 PsLoadedModuleList = 0xfffff801`cb3d05e0
  1830. Debug session time: Thu Jul 20 22:26:28.784 2017 (UTC - 4:00)
  1831. System Uptime: 0 days 0:21:13.561
  1832.  
  1833. BugCheck 1A, {41793, ffff810107a19ea8, 5, 4}
  1834. Probably caused by : memory_corruption
  1835. Followup: memory_corruption
  1836.  
  1837. MEMORY_MANAGEMENT (1a)
  1838. # Any other values for parameter 1 must be individually examined.
  1839.  
  1840. Arguments:
  1841. Arg1: 0000000000041793, The subtype of the bugcheck.
  1842. Arg2: ffff810107a19ea8
  1843. Arg3: 0000000000000005
  1844. Arg4: 0000000000000004
  1845.  
  1846. Debugging Details:
  1847. DUMP_CLASS: 1
  1848. DUMP_QUALIFIER: 400
  1849. BUILD_VERSION_STRING: 10.0.15063.483 (WinBuild.160101.0800)
  1850. SYSTEM_MANUFACTURER: ASUS
  1851. SYSTEM_PRODUCT_NAME: All Series
  1852. SYSTEM_SKU: All
  1853. BIOS_VENDOR: American Megatrends Inc.
  1854. BIOS_VERSION: 2603
  1855. BIOS_DATE: 02/22/2016
  1856. BASEBOARD_MANUFACTURER: ASUSTeK COMPUTER INC.
  1857. BASEBOARD_PRODUCT: H97M-PLUS
  1858. BASEBOARD_VERSION: Rev X.0x
  1859. DUMP_TYPE: 2
  1860. BUGCHECK_STR: 0x1a_41793
  1861. CPU_COUNT: 8
  1862. CPU_MHZ: c15
  1863. CPU_VENDOR: GenuineIntel
  1864. CPU_FAMILY: 6
  1865. CPU_MODEL: 3c
  1866. CPU_STEPPING: 3
  1867. CPU_MICROCODE: 6,3c,3,0 (F,M,S,R) SIG: 1E'00000000 (cache) 1E'00000000 (init)
  1868. CUSTOMER_CRASH_COUNT: 1
  1869. DEFAULT_BUCKET_ID: CODE_CORRUPTION
  1870.  
  1871. PROCESS_NAME: MsMpEng.exe
  1872.  
  1873. CURRENT_IRQL: 2
  1874. LAST_CONTROL_TRANSFER: from fffff801cb223cd0 to fffff801cb1f04c0
  1875. STACK_TEXT:
  1876. ffffdf80`31ba75a8 fffff801`cb223cd0 : 00000000`0000001a 00000000`00041793 ffff8101`07a19ea8 00000000`00000005 : nt!KeBugCheckEx
  1877. ffffdf80`31ba75b0 fffff801`cb1035bd : ffffc907`9bc05d88 ffffc907`9c45c080 ffffc907`9bc05d88 ffffc907`9bc057c0 : nt!MiDeleteVirtualAddresses+0x11b980
  1878. ffffdf80`31ba7860 fffff801`cb53889c : 0000020f`433d0000 ffffc907`a01e2b50 ffffffff`ffffffff 00000000`00000000 : nt!MiDeleteVad+0x3ad
  1879. ffffdf80`31ba79e0 fffff801`cb5ae9c6 : ffffc907`9bc057c0 000000f3`00000008 ffffc907`8f026f20 0000020f`433d0000 : nt!MiUnmapViewOfSection+0xec
  1880. ffffdf80`31ba7ab0 fffff801`cb1fb413 : ffffc907`9c45c080 000000f3`00000000 00000000`00000000 ffffc907`9bc057c0 : nt!NtUnmapViewOfSectionEx+0x86
  1881. ffffdf80`31ba7b00 00007fff`95788b54 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
  1882. 000000f3`647fa588 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007fff`95788b54
  1883. STACK_COMMAND: kb
  1884. CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
  1885. fffff801cb0c4287 - nt!MiMapArbitraryPage+37
  1886. [ fa:af ]
  1887. 1 error : !nt (fffff801cb0c4287)
  1888. MODULE_NAME: memory_corruption
  1889.  
  1890. IMAGE_NAME: memory_corruption
  1891.  
  1892. FOLLOWUP_NAME: memory_corruption
  1893. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  1894. MEMORY_CORRUPTOR: ONE_BYTE
  1895. FAILURE_BUCKET_ID: MEMORY_CORRUPTION_ONE_BYTE
  1896. BUCKET_ID: MEMORY_CORRUPTION_ONE_BYTE
  1897. PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_ONE_BYTE
  1898. TARGET_TIME: 2017-07-21T02:26:28.000Z
  1899. OSBUILD: 15063
  1900. OSSERVICEPACK: 483
  1901. SERVICEPACK_NUMBER: 0
  1902. OS_REVISION: 0
  1903. SUITE_MASK: 272
  1904. PRODUCT_TYPE: 1
  1905. OSPLATFORM_TYPE: x64
  1906. OSNAME: Windows 10
  1907. OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
  1908. USER_LCID: 0
  1909. OSBUILD_TIMESTAMP: 2017-07-07 02:06:35
  1910. BUILDDATESTAMP_STR: 160101.0800
  1911. BUILDLAB_STR: WinBuild
  1912. BUILDOSVER_STR: 10.0.15063.483
  1913. ANALYSIS_SESSION_ELAPSED_TIME: 3b57
  1914. ANALYSIS_SOURCE: KM
  1915. FAILURE_ID_HASH_STRING: km:memory_corruption_one_byte
  1916. FAILURE_ID_HASH: {ad110d6a-3b33-2c0a-c931-570eae1ba92d}
  1917. Followup: memory_corruption
  1918.  
  1919. ========================================================================
  1920. =================== Dump File: 072217-20640-01.dmp ===================
  1921. ========================================================================
  1922. Mini Kernel Dump File: Only registers and stack trace are available
  1923. Windows 10 Kernel Version 15063 MP (8 procs) Free x64
  1924. Product: WinNt, suite: TerminalServer SingleUserTS
  1925. Built by: 15063.0.amd64fre.rs2_release.170317-1834
  1926. Kernel base = 0xfffff802`88093000 PsLoadedModuleList = 0xfffff802`883df5e0
  1927. Debug session time: Sat Jul 22 10:37:09.389 2017 (UTC - 4:00)
  1928. System Uptime: 1 days 12:09:42.147
  1929.  
  1930. BugCheck 3B, {c0000005, fffff80288124c95, ffffc38037d6b630, 0}
  1931. Probably caused by : memory_corruption
  1932. Followup: memory_corruption
  1933.  
  1934. SYSTEM_SERVICE_EXCEPTION (3b)
  1935. An exception happened while executing a system service routine.
  1936.  
  1937. Arguments:
  1938. Arg1: 00000000c0000005, Exception code that caused the bugcheck
  1939. Arg2: fffff80288124c95, Address of the instruction which caused the bugcheck
  1940. Arg3: ffffc38037d6b630, Address of the context record for the exception that caused the bugcheck
  1941. Arg4: 0000000000000000, zero.
  1942.  
  1943. Debugging Details:
  1944. DUMP_CLASS: 1
  1945. DUMP_QUALIFIER: 400
  1946. BUILD_VERSION_STRING: 10.0.15063.483 (WinBuild.160101.0800)
  1947. SYSTEM_MANUFACTURER: ASUS
  1948. SYSTEM_PRODUCT_NAME: All Series
  1949. SYSTEM_SKU: All
  1950. BIOS_VENDOR: American Megatrends Inc.
  1951. BIOS_VERSION: 2603
  1952. BIOS_DATE: 02/22/2016
  1953. BASEBOARD_MANUFACTURER: ASUSTeK COMPUTER INC.
  1954. BASEBOARD_PRODUCT: H97M-PLUS
  1955. BASEBOARD_VERSION: Rev X.0x
  1956. DUMP_TYPE: 2
  1957. EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.
  1958. FAULTING_IP:
  1959. nt!MiGetFreeOrZeroPage+45
  1960. fffff802`88124c95 488b8cea680f0000 mov rcx,qword ptr [rdx+rbp*8+0F68h]
  1961. CONTEXT: ffffc38037d6b630 -- (.cxr 0xffffc38037d6b630)
  1962. rax=0000000000000001 rbx=0000000000029a70 rcx=0000000000000000
  1963. rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000001
  1964. rip=fffff80288124c95 rsp=ffffc38037d6c020 rbp=0000000000000001
  1965. r8=0000000000000000 r9=0000000000000029 r10=fffff80288411800
  1966. r11=0000000000000000 r12=00000000000029a7 r13=0000000000000000
  1967. r14=0000000000000000 r15=0000000000000001
  1968. iopl=0 nv up ei pl nz na pe nc
  1969. cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010202
  1970. nt!MiGetFreeOrZeroPage+0x45:
  1971. fffff802`88124c95 488b8cea680f0000 mov rcx,qword ptr [rdx+rbp*8+0F68h] ds:002b:00000000`00000f70=????????????????
  1972. Resetting default scope
  1973. CPU_COUNT: 8
  1974. CPU_MHZ: c15
  1975. CPU_VENDOR: GenuineIntel
  1976. CPU_FAMILY: 6
  1977. CPU_MODEL: 3c
  1978. CPU_STEPPING: 3
  1979. CPU_MICROCODE: 6,3c,3,0 (F,M,S,R) SIG: 1E'00000000 (cache) 1E'00000000 (init)
  1980. CUSTOMER_CRASH_COUNT: 1
  1981. DEFAULT_BUCKET_ID: CODE_CORRUPTION
  1982. BUGCHECK_STR: 0x3B
  1983.  
  1984. PROCESS_NAME: svchost.exe
  1985.  
  1986. CURRENT_IRQL: 0
  1987. LAST_CONTROL_TRANSFER: from fffff80288124b3c to fffff80288124c95
  1988. STACK_TEXT:
  1989. ffffc380`37d6c020 fffff802`88124b3c : 00000000`00000000 00000000`000029a7 ffff93ff`00000000 00000000`00000001 : nt!MiGetFreeOrZeroPage+0x45
  1990. ffffc380`37d6c0d0 fffff802`880d51f9 : 00000000`00000000 ffffd484`00000029 00000000`00000000 00000000`00000001 : nt!MiGetPage+0x8c
  1991. ffffc380`37d6c140 fffff802`880d4a86 : 00000000`00005000 00000000`00005000 00000000`00000000 00000000`001c5000 : nt!MiMakePageAvoidRead+0x139
  1992. ffffc380`37d6c2c0 fffff802`880d41bf : 62617461`00000000 000001b6`3bdc5a50 ffffc380`00000000 ffffc380`37d6c311 : nt!MmCopyToCachedPage+0x186
  1993. ffffc380`37d6c390 fffff802`880d3541 : ffffd484`6ed5db10 000001b6`3bdc5a50 ffffc380`37d6c550 ffffd484`00000000 : nt!CcMapAndCopyInToCache+0x31f
  1994. ffffc380`37d6c4f0 fffff80e`079e3015 : 00000000`001c6000 ffffd484`00000001 ffffc380`37d6c5a8 ffffd484`676b9d60 : nt!CcCopyWriteEx+0x111
  1995. ffffc380`37d6c570 fffff80e`06a05e3e : 00000000`000001a0 ffffd484`69785780 ffffd484`678b2080 000001b6`3bdc5a50 : NTFS!NtfsCopyWriteA+0x3c5
  1996. ffffc380`37d6c820 fffff80e`06a0331d : ffffc380`37d6c910 ffffd484`678b2000 ffffd484`676b9cf8 ffffd484`676b9c00 : FLTMGR!FltpPerformFastIoCall+0x13e
  1997. ffffc380`37d6c880 fffff80e`06a357dc : 00000000`00001000 fffff802`88552ce4 00000000`00000001 ffffc380`37d6c9f8 : FLTMGR!FltpPassThroughFastIo+0xbd
  1998. ffffc380`37d6c8e0 fffff802`885527c7 : 00000000`00000000 fffff802`88528201 ffffc380`37d6cb80 00000000`00000000 : FLTMGR!FltpFastIoWrite+0x15c
  1999. ffffc380`37d6c980 fffff802`8820a413 : 000001b6`3a440000 00000000`00000000 00000000`00000000 000000ac`18f7ebe0 : nt!NtWriteFile+0x457
  2000. ffffc380`37d6ca90 00007ff9`ae6754a4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
  2001. 000000ac`18f7eb38 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff9`ae6754a4
  2002. CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
  2003. fffff802880d522f-fffff802880d5230 2 bytes - nt!MiMakePageAvoidRead+16f
  2004. [ 80 fa:00 91 ]
  2005. fffff802880e2fbb-fffff802880e2fbc 2 bytes - nt!MiReleaseSystemCacheView+43 (+0xdd8c)
  2006. [ 80 f6:00 c2 ]
  2007. fffff802880e3011-fffff802880e3013 3 bytes - nt!MiReleaseSystemCacheView+99 (+0x56)
  2008. [ 40 fb f6:00 61 c2 ]
  2009. fffff80288120d27-fffff80288120d28 2 bytes - nt!MiResolvePageTablePage+3b7 (+0x3dd16)
  2010. [ ff f6:7f c2 ]
  2011. fffff80288120d48-fffff80288120d4c 5 bytes - nt!MiResolvePageTablePage+3d8 (+0x21)
  2012. [ df be 7d fb f6:4f 98 30 61 c2 ]
  2013. fffff8028812407a-fffff8028812407b 2 bytes - nt!MiResolvePrivateZeroFault+27a (+0x3332)
  2014. [ 80 f6:00 c2 ]
  2015. fffff802881240b0-fffff802881240b2 3 bytes - nt!MiResolvePrivateZeroFault+2b0 (+0x36)
  2016. [ 40 fb f6:00 61 c2 ]
  2017. fffff802881240d8-fffff802881240d9 2 bytes - nt!MiResolvePrivateZeroFault+2d8 (+0x28)
  2018. [ 80 fa:00 91 ]
  2019. fffff80288124267-fffff80288124268 2 bytes - nt!MiResolvePrivateZeroFault+467 (+0x18f)
  2020. [ 80 f6:00 c2 ]
  2021. fffff80288124563-fffff80288124564 2 bytes - nt!MiResolvePrivateZeroFault+763 (+0x2fc)
  2022. [ 80 f6:00 c2 ]
  2023. fffff8028812471a-fffff8028812471b 2 bytes - nt!MiGetPageChain+17a (+0x1b7)
  2024. [ 80 fa:00 91 ]
  2025. fffff80288124b53-fffff80288124b54 2 bytes - nt!MiGetPage+a3 (+0x439)
  2026. [ 80 fa:00 91 ]
  2027. fffff80288124cc2-fffff80288124cc3 2 bytes - nt!MiGetFreeOrZeroPage+72 (+0x16f)
  2028. [ 80 fa:00 91 ]
  2029. fffff8028813279c-fffff8028813279d 2 bytes - nt!MiRemoveLockedPageChargeAndDecRef+1ac (+0xdada)
  2030. [ 80 fa:00 91 ]
  2031. fffff8028818b559-fffff8028818b55a 2 bytes - nt!MiDeleteParentDecayNode+25 (+0x58dbd)
  2032. [ 80 fa:00 91 ]
  2033. fffff8028818b614-fffff8028818b615 2 bytes - nt!MiRemoveDecayClusterTimer+38 (+0xbb)
  2034. [ 80 fa:00 91 ]
  2035. fffff80288313383-fffff80288313385 3 bytes - nt!ExFreePoolWithTag+363
  2036. [ 40 fb f6:00 61 c2 ]
  2037. 40 errors : !nt (fffff802880d522f-fffff80288313385)
  2038. MODULE_NAME: memory_corruption
  2039.  
  2040. IMAGE_NAME: memory_corruption
  2041.  
  2042. FOLLOWUP_NAME: memory_corruption
  2043. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  2044. MEMORY_CORRUPTOR: LARGE
  2045. STACK_COMMAND: .cxr 0xffffc38037d6b630 ; kb
  2046. FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
  2047. BUCKET_ID: MEMORY_CORRUPTION_LARGE
  2048. PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
  2049. TARGET_TIME: 2017-07-22T14:37:09.000Z
  2050. OSBUILD: 15063
  2051. OSSERVICEPACK: 483
  2052. SERVICEPACK_NUMBER: 0
  2053. OS_REVISION: 0
  2054. SUITE_MASK: 272
  2055. PRODUCT_TYPE: 1
  2056. OSPLATFORM_TYPE: x64
  2057. OSNAME: Windows 10
  2058. OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
  2059. USER_LCID: 0
  2060. OSBUILD_TIMESTAMP: 2017-07-07 02:06:35
  2061. BUILDDATESTAMP_STR: 160101.0800
  2062. BUILDLAB_STR: WinBuild
  2063. BUILDOSVER_STR: 10.0.15063.483
  2064. ANALYSIS_SESSION_ELAPSED_TIME: 387b
  2065. ANALYSIS_SOURCE: KM
  2066. FAILURE_ID_HASH_STRING: km:memory_corruption_large
  2067. FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
  2068. Followup: memory_corruption
Advertisement
Add Comment
Please, Sign In to add comment