Guest User

Untitled

a guest
Aug 3rd, 2020
110
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 114.06 KB | None | 0 0
  1. ========================== AUTO DUMP ANALYZER ==========================
  2. Auto Dump Analyzer
  3. Version: 0.91
  4. Time to analyze file(s): 00 hours and 05 minutes and 19 seconds
  5.  
  6. ================================ SYSTEM ================================
  7. MANUFACTURER: Gigabyte Technology Co., Ltd.
  8. PRODUCT_NAME: H310M H
  9.  
  10. ================================= BIOS =================================
  11. VENDOR: American Megatrends Inc.
  12. VERSION: F2
  13. DATE: 04/19/2018
  14.  
  15. ============================= MOTHERBOARD ==============================
  16. MANUFACTURER: Gigabyte Technology Co., Ltd.
  17. PRODUCT: H310M H
  18. VERSION: x.x
  19.  
  20. ================================= RAM ==================================
  21. Size Speed Manufacturer Part No.
  22. -------------- -------------- ------------------- ----------------------
  23. 8192MB 2133MHz 029E CMK16GX4M2B3200C16
  24. 0MHz
  25. 8192MB 2133MHz 029E CMK16GX4M2B3200C16
  26. 0MHz
  27.  
  28. ================================= CPU ==================================
  29. Processor Version: Intel(R) Core(TM) i7-8700 CPU @ 3.20GHz
  30. COUNT: c
  31. MHZ: 3192
  32. VENDOR: GenuineIntel
  33. FAMILY: 6
  34. MODEL: 9e
  35. STEPPING: a
  36. MICROCODE: 6,9e,a,0 (F,M,S,R) SIG: B4'00000000 (cache) B4'00000000 (init)
  37.  
  38. ================================== OS ==================================
  39. Product: WinNt, suite: TerminalServer SingleUserTS
  40. Built by: 19041.1.amd64fre.vb_release.191206-1406
  41. BUILD_VERSION: 10.0.19041.423 (WinBuild.160101.0800)
  42. BUILD: 19041
  43. SERVICEPACK: 423
  44. PLATFORM_TYPE: x64
  45. NAME: Windows 10
  46. EDITION: Windows 10 WinNt TerminalServer SingleUserTS
  47. BUILD_TIMESTAMP: unknown_date
  48. BUILDDATESTAMP: 160101.0800
  49. BUILDLAB: WinBuild
  50. BUILDOSVER: 10.0.19041.423
  51. BUILD_VERSION: 10.0.19041.388 (WinBuild.160101.0800)
  52. SERVICEPACK: 388
  53. BUILDOSVER: 10.0.19041.388
  54.  
  55. =============================== DEBUGGER ===============================
  56. Microsoft (R) Windows Debugger Version 10.0.14321.1024 AMD64
  57. Copyright (c) Microsoft Corporation. All rights reserved.
  58.  
  59. =============================== COMMENTS ===============================
  60. * Information gathered from different dump files may be different. If
  61. Windows updates between two dump files, two or more OS versions may
  62. be shown above.
  63. * If the user updates the BIOS between dump files, two or more versions
  64. and dates may be shown above.
  65. * More RAM information can be found below in a full BIOS section.
  66.  
  67. ========================================================================
  68. ======================= Dump #1: ANALYZE VERBOSE =======================
  69. ======================= File: 080320-9546-01.dmp =======================
  70. ========================================================================
  71.  
  72. Mini Kernel Dump File: Only registers and stack trace are available
  73. Windows 10 Kernel Version 19041 MP (12 procs) Free x64
  74. Kernel base = 0xfffff804`73000000 PsLoadedModuleList = 0xfffff804`73c2a330
  75. Debug session time: Mon Aug 3 03:38:47.458 2020 (UTC - 4:00)
  76. System Uptime: 0 days 1:46:54.110
  77.  
  78. BugCheck 101, {10, 0, ffffd7809f140180, a}
  79. Probably caused by : memory_corruption
  80. Followup: memory_corruption
  81.  
  82. CLOCK_WATCHDOG_TIMEOUT (101)
  83. An expected clock interrupt was not received on a secondary processor in an
  84. MP system within the allocated interval. This indicates that the specified
  85. processor is hung and not processing interrupts.
  86.  
  87. Arguments:
  88. Arg1: 0000000000000010, Clock interrupt time out interval in nominal clock ticks.
  89. Arg2: 0000000000000000, 0.
  90. Arg3: ffffd7809f140180, The PRCB address of the hung processor.
  91. Arg4: 000000000000000a, The index of the hung processor.
  92.  
  93. Debugging Details:
  94. DUMP_CLASS: 1
  95. DUMP_QUALIFIER: 400
  96. DUMP_TYPE: 2
  97. BUGCHECK_STR: CLOCK_WATCHDOG_TIMEOUT_c_PROC
  98. CUSTOMER_CRASH_COUNT: 1
  99. DEFAULT_BUCKET_ID: CODE_CORRUPTION
  100.  
  101. PROCESS_NAME: RustClient.exe
  102.  
  103. CURRENT_IRQL: d
  104. STACK_TEXT:
  105. ffffd780`9eda8c88 fffff804`7345952e : 00000000`00000101 00000000`00000010 00000000`00000000 ffffd780`9f140180 : nt!KeBugCheckEx
  106. ffffd780`9eda8c90 fffff804`732ce52d : 00000000`00000000 ffffd780`9ed8f180 00000000`00000246 00000000`00064387 : nt!KeAccumulateTicks+0x18cade
  107. ffffd780`9eda8cf0 fffff804`732c7c21 : 00000000`00064100 00000000`0003bbc6 ffffd780`9ed8f180 00000000`00000001 : nt!KiUpdateRunTime+0x5d
  108. ffffd780`9eda8d40 fffff804`732c9abb : 00000000`00000000 ffff9585`5a4ef200 fffff804`73c31998 00000000`00000000 : nt!KiUpdateTime+0x4a1
  109. ffffd780`9eda8e80 fffff804`732c6cf2 : ffff9585`5a4ef270 ffff9585`5a4ef2f0 ffff9585`5a4ef2f0 00000000`00000000 : nt!KeClockInterruptNotify+0x2bb
  110. ffffd780`9eda8f30 fffff804`73208725 : 0000000e`ef326711 ffffc78e`c2cd3720 ffffc78e`c2cd37d0 00000000`00000000 : nt!HalpTimerClockInterrupt+0xe2
  111. ffffd780`9eda8f60 fffff804`733df9ea : ffff9585`5a4ef2f0 ffffc78e`c2cd3720 00000000`00000001 10c08349`08583349 : nt!KiCallInterruptServiceRoutine+0xa5
  112. ffffd780`9eda8fb0 fffff804`733dff57 : 00000000`0fafec11 00000000`00000002 00000000`00000000 00000000`00000010 : nt!KiInterruptSubDispatchNoLockNoEtw+0xfa
  113. ffff9585`5a4ef270 fffff804`732c4700 : 00000000`00000000 ffffffff`ffffffff 00000000`00000002 ffffee00`0c6079e0 : nt!KiInterruptDispatchNoLockNoEtw+0x37
  114. ffff9585`5a4ef400 fffff804`732c0a52 : ffffc78e`00000001 00000000`00000000 00000000`00000000 ffffac01`48785018 : nt!KeFlushMultipleRangeTb+0x2a0
  115. ffff9585`5a4ef490 fffff804`732b410f : ffff9585`5a4ef5c0 85000004`2028a867 ffffac01`48785018 00000000`00000009 : nt!MiFlushTbList+0x82
  116. ffff9585`5a4ef4c0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MiCopyOnWrite+0x6df
  117. STACK_COMMAND: kb
  118. CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
  119. fffff8047323c4aa-fffff8047323c4ab 2 bytes - nt!MiInsertCachedPte+20a
  120. [ ff f6:7f ac ]
  121. fffff8047338516e-fffff80473385171 4 bytes - nt!MiFreeUltraMapping+32 (+0x148cc4)
  122. [ a0 7d fb f6:00 2b 56 ac ]
  123. 6 errors : !nt (fffff8047323c4aa-fffff80473385171)
  124. MODULE_NAME: memory_corruption
  125.  
  126. IMAGE_NAME: memory_corruption
  127.  
  128. FOLLOWUP_NAME: memory_corruption
  129. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  130. MEMORY_CORRUPTOR: LARGE
  131. FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
  132. BUCKET_ID: MEMORY_CORRUPTION_LARGE
  133. PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
  134. TARGET_TIME: 2020-08-03T07:38:47.000Z
  135. SUITE_MASK: 272
  136. PRODUCT_TYPE: 1
  137. USER_LCID: 0
  138. FAILURE_ID_HASH_STRING: km:memory_corruption_large
  139. FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
  140. Followup: memory_corruption
  141.  
  142. ====================== Dump #1: 3RD PARTY DRIVERS ======================
  143.  
  144. Oct 15 2015 - rzendpt.sys - Razer RzEndPt driver https://www.razer.com/
  145. Oct 15 2015 - rzudd.sys - Razer Rzudd Engine Driver https://www.razer.com/
  146. May 04 2017 - ICCWDT.sys - Intel(R) Watchdog Timer driver
  147. Apr 11 2018 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
  148. Jan 11 2019 - iaLPSS2_GPIO2.sys - Intel(R) Serial IO GPIO driver
  149. Mar 14 2019 - nvvad64v.sys - Nvidia Virtual Audio driver http://www.nvidia.com/
  150. Apr 25 2019 - mbae64.sys - Malwarebytes driver https://www.malwarebytes.com/
  151. May 14 2019 - RTKVHD64.sys - Realtek Audio System driver https://www.realtek.com/en/
  152. Jul 01 2019 - rt640x64.sys - Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
  153. Jul 18 2019 - semav6msr64.sys - Intel Driver Update Utility http://www.intel.com/ OR (SEMA Software) http://www.sema-soft.de/en/home/
  154. Sep 19 2019 - RTCore64.sys - !!! Overclocking Software - RivaTuner - MSI Afterburner http://www.msi.com/ or EVGA Precision X http://www.evga.com/
  155. Nov 20 2019 - mbamswissarmy.sys - MalwareBytes Anti-Malware system driver https://www.malwarebytes.com/
  156. Nov 29 2019 - NvModuleTracker.sys - NVIDIA Module Tracker driver
  157. Jan 10 2020 - nvvhci.sys - Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
  158. Jan 26 2020 - UcmCxUcsiNvppc.sys - NVIDIA USB Type-C Port Policy Controller driver
  159. Jun 04 2020 - MbamChameleon.sys - Malwarebytes Anti-Malware Chameleon driver https://www.malwarebytes.com/
  160. Jun 09 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
  161. Jun 22 2020 - mwac.sys - Malwarebytes Web Access Control http://www.malwarebytes.org/
  162. Jun 29 2020 - vgk.sys - Vanguard Anti-Cheat driver
  163. Jul 05 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
  164. Jul 07 2020 - mbam.sys - Malwarebytes Anti-Malware https://www.malwarebytes.com/
  165. Jul 17 2020 - farflt.sys - Malwarebytes Anti-RansomWare SDK http://www.malwarebytes.org/
  166. Jul 23 2020 - EasyAntiCheat.sys - EasyAntiCheat is a anti-cheat driver (EasyAntiCheat Oy.) https://support.easyanticheat.net/
  167.  
  168. ================== Dump #1: 3RD PARTY DRIVERS (FULL) ===================
  169.  
  170. Image path: \SystemRoot\System32\drivers\rzendpt.sys
  171. Image name: rzendpt.sys
  172. Search : https://www.google.com/search?q=rzendpt.sys
  173. ADA Info : Razer RzEndPt driver https://www.razer.com/
  174. Timestamp : Thu Oct 15 2015
  175.  
  176. Image path: \SystemRoot\System32\drivers\rzudd.sys
  177. Image name: rzudd.sys
  178. Search : https://www.google.com/search?q=rzudd.sys
  179. ADA Info : Razer Rzudd Engine Driver https://www.razer.com/
  180. Timestamp : Thu Oct 15 2015
  181.  
  182. Image path: \SystemRoot\System32\drivers\ICCWDT.sys
  183. Image name: ICCWDT.sys
  184. Search : https://www.google.com/search?q=ICCWDT.sys
  185. ADA Info : Intel(R) Watchdog Timer driver
  186. Timestamp : Thu May 4 2017
  187.  
  188. Image path: \SystemRoot\System32\drivers\TeeDriverW8x64.sys
  189. Image name: TeeDriverW8x64.sys
  190. Search : https://www.google.com/search?q=TeeDriverW8x64.sys
  191. ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
  192. Timestamp : Wed Apr 11 2018
  193.  
  194. Image path: \SystemRoot\System32\drivers\iaLPSS2_GPIO2.sys
  195. Image name: iaLPSS2_GPIO2.sys
  196. Search : https://www.google.com/search?q=iaLPSS2_GPIO2.sys
  197. ADA Info : Intel(R) Serial IO GPIO driver
  198. Timestamp : Fri Jan 11 2019
  199.  
  200. Image path: \SystemRoot\system32\drivers\nvvad64v.sys
  201. Image name: nvvad64v.sys
  202. Search : https://www.google.com/search?q=nvvad64v.sys
  203. ADA Info : Nvidia Virtual Audio driver http://www.nvidia.com/
  204. Timestamp : Thu Mar 14 2019
  205.  
  206. Image path: \??\C:\WINDOWS\system32\drivers\mbae64.sys
  207. Image name: mbae64.sys
  208. Search : https://www.google.com/search?q=mbae64.sys
  209. ADA Info : Malwarebytes driver https://www.malwarebytes.com/
  210. Timestamp : Thu Apr 25 2019
  211.  
  212. Image path: \SystemRoot\system32\drivers\RTKVHD64.sys
  213. Image name: RTKVHD64.sys
  214. Search : https://www.google.com/search?q=RTKVHD64.sys
  215. ADA Info : Realtek Audio System driver https://www.realtek.com/en/
  216. Timestamp : Tue May 14 2019
  217.  
  218. Image path: \SystemRoot\System32\drivers\rt640x64.sys
  219. Image name: rt640x64.sys
  220. Search : https://www.google.com/search?q=rt640x64.sys
  221. ADA Info : Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
  222. Timestamp : Mon Jul 1 2019
  223.  
  224. Image path: \??\C:\WINDOWS\system32\drivers\semav6msr64.sys
  225. Image name: semav6msr64.sys
  226. Search : https://www.google.com/search?q=semav6msr64.sys
  227. ADA Info : Intel Driver Update Utility http://www.intel.com/ OR (SEMA Software) http://www.sema-soft.de/en/home/
  228. Timestamp : Thu Jul 18 2019
  229.  
  230. Image path: \??\C:\Program Files (x86)\MSI Afterburner\RTCore64.sys
  231. Image name: RTCore64.sys
  232. Search : https://www.google.com/search?q=RTCore64.sys
  233. ADA Info : !!! Overclocking Software - RivaTuner - MSI Afterburner http://www.msi.com/ or EVGA Precision X http://www.evga.com/
  234. Timestamp : Thu Sep 19 2019
  235.  
  236. Image path: \SystemRoot\System32\Drivers\mbamswissarmy.sys
  237. Image name: mbamswissarmy.sys
  238. Search : https://www.google.com/search?q=mbamswissarmy.sys
  239. ADA Info : MalwareBytes Anti-Malware system driver https://www.malwarebytes.com/
  240. Timestamp : Wed Nov 20 2019
  241.  
  242. Image path: \SystemRoot\System32\drivers\NvModuleTracker.sys
  243. Image name: NvModuleTracker.sys
  244. Search : https://www.google.com/search?q=NvModuleTracker.sys
  245. ADA Info : NVIDIA Module Tracker driver
  246. Timestamp : Fri Nov 29 2019
  247.  
  248. Image path: \SystemRoot\System32\drivers\nvvhci.sys
  249. Image name: nvvhci.sys
  250. Search : https://www.google.com/search?q=nvvhci.sys
  251. ADA Info : Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
  252. Timestamp : Fri Jan 10 2020
  253.  
  254. Image path: \SystemRoot\System32\DriverStore\FileRepository\nvppc.inf_amd64_0f22333f160a8f42\UcmCxUcsiNvppc.sys
  255. Image name: UcmCxUcsiNvppc.sys
  256. Search : https://www.google.com/search?q=UcmCxUcsiNvppc.sys
  257. ADA Info : NVIDIA USB Type-C Port Policy Controller driver
  258. Timestamp : Sun Jan 26 2020
  259.  
  260. Image path: \SystemRoot\System32\Drivers\MbamChameleon.sys
  261. Image name: MbamChameleon.sys
  262. Search : https://www.google.com/search?q=MbamChameleon.sys
  263. ADA Info : Malwarebytes Anti-Malware Chameleon driver https://www.malwarebytes.com/
  264. Timestamp : Thu Jun 4 2020
  265.  
  266. Image path: \SystemRoot\system32\drivers\nvhda64v.sys
  267. Image name: nvhda64v.sys
  268. Search : https://www.google.com/search?q=nvhda64v.sys
  269. ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
  270. Timestamp : Tue Jun 9 2020
  271.  
  272. Image path: \SystemRoot\system32\DRIVERS\mwac.sys
  273. Image name: mwac.sys
  274. Search : https://www.google.com/search?q=mwac.sys
  275. ADA Info : Malwarebytes Web Access Control http://www.malwarebytes.org/
  276. Timestamp : Mon Jun 22 2020
  277.  
  278. Image path: \??\C:\Program Files\Riot Vanguard\vgk.sys
  279. Image name: vgk.sys
  280. Search : https://www.google.com/search?q=vgk.sys
  281. ADA Info : Vanguard Anti-Cheat driver
  282. Timestamp : Mon Jun 29 2020
  283.  
  284. Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_edab19158bdd0d0a\nvlddmkm.sys
  285. Image name: nvlddmkm.sys
  286. Search : https://www.google.com/search?q=nvlddmkm.sys
  287. ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
  288. Timestamp : Sun Jul 5 2020
  289.  
  290. Image path: \??\C:\WINDOWS\system32\DRIVERS\mbam.sys
  291. Image name: mbam.sys
  292. Search : https://www.google.com/search?q=mbam.sys
  293. ADA Info : Malwarebytes Anti-Malware https://www.malwarebytes.com/
  294. Timestamp : Tue Jul 7 2020
  295.  
  296. Image path: \SystemRoot\system32\DRIVERS\farflt.sys
  297. Image name: farflt.sys
  298. Search : https://www.google.com/search?q=farflt.sys
  299. ADA Info : Malwarebytes Anti-RansomWare SDK http://www.malwarebytes.org/
  300. Timestamp : Fri Jul 17 2020
  301.  
  302. Image path: \??\C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys
  303. Image name: EasyAntiCheat.sys
  304. Search : https://www.google.com/search?q=EasyAntiCheat.sys
  305. ADA Info : EasyAntiCheat is a anti-cheat driver (EasyAntiCheat Oy.) https://support.easyanticheat.net/
  306. Timestamp : Thu Jul 23 2020
  307.  
  308. ====================== Dump #1: MICROSOFT DRIVERS ======================
  309.  
  310. ACPI.sys ACPI Driver for NT (Microsoft)
  311. acpiex.sys ACPIEx Driver (Microsoft)
  312. acpipagr.sys ACPI Processor Aggregator Device driver (Microsoft)
  313. afd.sys Ancillary Function Driver for WinSock (Microsoft)
  314. afunix.sys AF_UNIX Socket Provider driver (Microsoft)
  315. AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
  316. ahcache.sys Application Compatibility Cache (Microsoft)
  317. bam.sys BAM Kernal driver (Microsoft)
  318. BasicDisplay.sys Basic Display driver (Microsoft)
  319. BasicRender.sys Basic Render driver (Microsoft)
  320. Beep.SYS BEEP driver (Microsoft)
  321. bindflt.sys Windows Bind Filter driver (Microsoft)
  322. BOOTVID.dll VGA Boot Driver (Microsoft)
  323. bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
  324. cdd.dll Canonical Display Driver (Microsoft)
  325. cdrom.sys SCSI CD-ROM Driver (Microsoft)
  326. CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
  327. CI.dll Code Integrity Module (Microsoft)
  328. CimFS.SYS Consumer IR Class Driver for eHome (Microsoft)
  329. CLASSPNP.SYS SCSI Class System Dll (Microsoft)
  330. cldflt.sys Cloud Files Mini Filter driver (Microsoft)
  331. CLFS.SYS Common Log File System Driver (Microsoft)
  332. clipsp.sys CLIP Service (Microsoft)
  333. cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
  334. cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
  335. CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
  336. condrv.sys Console Driver (Microsoft)
  337. crashdmp.sys Crash Dump driver (Microsoft)
  338. csc.sys Windows Client Side Caching driver (Microsoft)
  339. dfsc.sys DFS Namespace Client Driver (Microsoft)
  340. disk.sys PnP Disk Driver (Microsoft)
  341. drmk.sys Digital Rights Management (DRM) driver (Microsoft)
  342. dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  343. dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  344. dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  345. dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
  346. dxgmms2.sys DirectX Graphics MMS
  347. EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
  348. fastfat.SYS Fast FAT File System Driver (Microsoft)
  349. filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
  350. fileinfo.sys FileInfo Filter Driver (Microsoft)
  351. FLTMGR.SYS Filesystem Filter Manager (Microsoft)
  352. Fs_Rec.sys File System Recognizer Driver (Microsoft)
  353. fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
  354. fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
  355. gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
  356. hal.dll Hardware Abstraction Layer DLL (Microsoft)
  357. HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
  358. HIDCLASS.SYS Hid Class Library (Microsoft)
  359. HIDPARSE.SYS Hid Parsing Library (Microsoft)
  360. hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
  361. HTTP.sys HTTP Protocol Stack (Microsoft)
  362. intelpep.sys Intel Power Engine Plugin (Microsoft)
  363. intelppm.sys Processor Device Driver (Microsoft)
  364. IntelTA.sys Intel Telemetry Driver
  365. iorate.sys I/O rate control Filter (Microsoft)
  366. kbdclass.sys Keyboard Class Driver (Microsoft)
  367. kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
  368. kd.dll Local Kernal Debugger (Microsoft)
  369. kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
  370. ks.sys Kernal CSA Library (Microsoft)
  371. ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
  372. ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
  373. ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
  374. lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
  375. luafv.sys LUA File Virtualization Filter Driver (Microsoft)
  376. mcupdate_GenuineIntel.dll Intel Microcode Update Library (Microsoft)
  377. mmcss.sys MMCSS Driver (Microsoft)
  378. monitor.sys Monitor Driver (Microsoft)
  379. mouclass.sys Mouse Class Driver (Microsoft)
  380. mouhid.sys HID Mouse Filter Driver (Microsoft)
  381. mountmgr.sys Mount Point Manager (Microsoft)
  382. mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
  383. mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
  384. mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
  385. Msfs.SYS Mailslot driver (Microsoft)
  386. msgpioclx.sys GPIO Class Extension Driver (Microsoft)
  387. msisadrv.sys ISA Driver (Microsoft)
  388. mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
  389. msquic.sys Windows QUIC Driver
  390. msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
  391. mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
  392. mssmbios.sys System Management BIOS driver (Microsoft)
  393. mup.sys Multiple UNC Provider driver (Microsoft)
  394. ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
  395. ndiscap.sys Microsoft NDIS Packet Capture Filter Driver
  396. ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
  397. ndisuio.sys NDIS User mode I/O driver (Microsoft)
  398. NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
  399. ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
  400. NDProxy.sys NDIS Proxy driver (Microsoft)
  401. Ndu.sys Network Data Usage Monitoring driver (Microsoft)
  402. netbios.sys NetBIOS Interface driver (Microsoft)
  403. netbt.sys MBT Transport driver (Microsoft)
  404. NETIO.SYS Network I/O Subsystem (Microsoft)
  405. Npfs.SYS NPFS driver (Microsoft)
  406. npsvctrig.sys Named pipe service triggers (Microsoft)
  407. nsiproxy.sys NSI Proxy driver (Microsoft)
  408. Ntfs.sys NT File System Driver (Microsoft)
  409. ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
  410. ntosext.sys NTOS Extension Host driver (Microsoft)
  411. Null.SYS NULL Driver (Microsoft)
  412. nwifi.sys NativeWiFi Miniport Driver (Microsoft)
  413. pacer.sys QoS Packet Scheduler (Microsoft)
  414. partmgr.sys Partition driver (Microsoft)
  415. pci.sys NT Plug and Play PCI Enumerator (Microsoft)
  416. pcw.sys Performance Counter Driver (Microsoft)
  417. pdc.sys Power Dependency Coordinator Driver (Microsoft)
  418. peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
  419. portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
  420. PSHED.dll Platform Specific Hardware Error driver (Microsoft)
  421. qwavedrv.sys Quality Windows Audio Video Experience (qWave) Support driver (Microsoft)
  422. rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
  423. raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
  424. raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
  425. rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
  426. rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
  427. rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
  428. rdyboost.sys ReadyBoost Driver (Microsoft)
  429. rspndr.sys Link-Layer Topology Responder driver (Microsoft)
  430. SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
  431. SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
  432. spaceport.sys Storage Spaces driver (Microsoft)
  433. srv2.sys Smb 2.0 Server driver (Microsoft)
  434. srvnet.sys Server Network driver (Microsoft)
  435. storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
  436. storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
  437. storqosflt.sys Storage QoS Filter driver (Microsoft)
  438. swenum.sys Plug and Play Software Device Enumerator (Microsoft)
  439. tbs.sys Export driver for kernel mode TPM API (Microsoft)
  440. tcpip.sys TCP/IP Protocol driver (Microsoft)
  441. tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
  442. TDI.SYS TDI Wrapper driver (Microsoft)
  443. tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
  444. tm.sys Kernel Transaction Manager driver (Microsoft)
  445. UcmCx.sys USB Connector Manager KMDF Class Extension
  446. ucx01000.sys USB Controller Extension (Microsoft)
  447. UEFI.sys UEFI NT driver (Microsoft)
  448. umbus.sys User-Mode Bus Enumerator (Microsoft)
  449. usbaudio.sys USB Audio Class Driver (Microsoft)
  450. usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
  451. USBD.SYS Universal Serial Bus Driver (Microsoft)
  452. UsbHub3.sys USB3 HUB driver (Microsoft)
  453. USBXHCI.SYS USB XHCI driver (Microsoft)
  454. vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
  455. Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
  456. volmgr.sys Volume Manager Driver (Microsoft)
  457. volmgrx.sys Volume Manager Extension Driver (Microsoft)
  458. volsnap.sys Volume Shadow Copy driver (Microsoft)
  459. volume.sys Volume driver (Microsoft)
  460. vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
  461. wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
  462. watchdog.sys Watchdog driver (Microsoft)
  463. wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
  464. Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
  465. WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
  466. werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
  467. wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
  468. win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
  469. win32kbase.sys Base Win32k Kernel Driver (Microsoft)
  470. win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
  471. WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
  472. WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
  473. winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
  474. wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
  475. WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
  476. Wof.sys Windows Overlay Filter (Microsoft)
  477. WppRecorder.sys WPP Trace Recorder (Microsoft)
  478.  
  479. ====================== Dump #1: UNLOADED MODULES =======================
  480.  
  481. fffff804`8eea0000 fffff804`8eeac000 bertreader.s
  482. fffff804`8b4f0000 fffff804`8b4ff000 dump_storpor
  483. fffff804`8b540000 fffff804`8b573000 dump_storahc
  484. fffff804`8b5a0000 fffff804`8b5be000 dump_dumpfve
  485. fffff804`8c510000 fffff804`8c52c000 dam.sys
  486. fffff804`78050000 fffff804`78059000 MbamElam.sys
  487. fffff804`79050000 fffff804`79061000 hwpolicy.sys
  488.  
  489. ====================== Dump #1: BIOS INFORMATION =======================
  490.  
  491. sysinfo: could not find necessary interfaces.
  492. sysinfo: note that mssmbios.sys must be loaded (XPSP2+).
  493.  
  494. ========================== Dump #1: Extra #1 ===========================
  495.  
  496. 5: kd> !verifier
  497. Verify Flags Level 0x00000000
  498. STANDARD FLAGS:
  499. [X] (0x00000000) Automatic Checks
  500. [ ] (0x00000001) Special pool
  501. [ ] (0x00000002) Force IRQL checking
  502. [ ] (0x00000008) Pool tracking
  503. [ ] (0x00000010) I/O verification
  504. [ ] (0x00000020) Deadlock detection
  505. [ ] (0x00000080) DMA checking
  506. [ ] (0x00000100) Security checks
  507. [ ] (0x00000800) Miscellaneous checks
  508. [ ] (0x00020000) DDI compliance checking
  509. ADDITIONAL FLAGS:
  510. [ ] (0x00000004) Randomized low resources simulation
  511. [ ] (0x00000200) Force pending I/O requests
  512. [ ] (0x00000400) IRP logging
  513. [ ] (0x00002000) Invariant MDL checking for stack
  514. [ ] (0x00004000) Invariant MDL checking for driver
  515. [ ] (0x00008000) Power framework delay fuzzing
  516. [ ] (0x00010000) Port/miniport interface checking
  517. [ ] (0x00040000) Systematic low resources simulation
  518. [ ] (0x00080000) DDI compliance checking (additional)
  519. [ ] (0x00200000) NDIS/WIFI verification
  520. [ ] (0x00800000) Kernel synchronization delay fuzzing
  521. [ ] (0x01000000) VM switch verification
  522. [ ] (0x02000000) Code integrity checks
  523. [X] Indicates flag is enabled
  524. Summary of All Verifier Statistics
  525. RaiseIrqls 0x0
  526. AcquireSpinLocks 0x0
  527. Synch Executions 0x0
  528. Trims 0x0
  529. Pool Allocations Attempted 0x0
  530. Pool Allocations Succeeded 0x0
  531. Pool Allocations Succeeded SpecialPool 0x0
  532. Pool Allocations With NO TAG 0x0
  533. Pool Allocations Failed 0x0
  534. Current paged pool allocations 0x0 for 00000000 bytes
  535. Peak paged pool allocations 0x0 for 00000000 bytes
  536. Current nonpaged pool allocations 0x0 for 00000000 bytes
  537. Peak nonpaged pool allocations 0x0 for 00000000 bytes
  538.  
  539. ========================== Dump #1: Extra #2 ===========================
  540.  
  541. 5: kd> !thread
  542. THREAD ffffc78ece91a080 Cid 3a2c.0f10 Teb: 000000d11c858000 Win32Thread: 0000000000000000 RUNNING on processor 5
  543. Not impersonating
  544. GetUlongFromAddress: unable to read from fffff80473c1146c
  545. Owning Process ffffc78ecfc18340 Image: RustClient.exe
  546. Attached Process N/A Image: N/A
  547. fffff78000000000: Unable to get shared data
  548. Wait Start TickCount 409885
  549. Context Switch Count 12707 IdealProcessor: 1
  550. ReadMemory error: Cannot get nt!KeMaximumIncrement value.
  551. UserTime 00:00:00.000
  552. KernelTime 00:00:00.000
  553. Win32 Start Address 0x00007ffce285d500
  554. Stack Init ffff95855a4efb90 Current ffff95855a4ef670
  555. Base ffff95855a4f0000 Limit ffff95855a4e9000 Call 0000000000000000
  556. Priority 12 BasePriority 8 PriorityDecrement 2 IoPriority 2 PagePriority 5
  557. Child-SP RetAddr : Args to Child : Call Site
  558. ffffd780`9eda8c88 fffff804`7345952e : 00000000`00000101 00000000`00000010 00000000`00000000 ffffd780`9f140180 : nt!KeBugCheckEx
  559. ffffd780`9eda8c90 fffff804`732ce52d : 00000000`00000000 ffffd780`9ed8f180 00000000`00000246 00000000`00064387 : nt!KeAccumulateTicks+0x18cade
  560. ffffd780`9eda8cf0 fffff804`732c7c21 : 00000000`00064100 00000000`0003bbc6 ffffd780`9ed8f180 00000000`00000001 : nt!KiUpdateRunTime+0x5d
  561. ffffd780`9eda8d40 fffff804`732c9abb : 00000000`00000000 ffff9585`5a4ef200 fffff804`73c31998 00000000`00000000 : nt!KiUpdateTime+0x4a1
  562. ffffd780`9eda8e80 fffff804`732c6cf2 : ffff9585`5a4ef270 ffff9585`5a4ef2f0 ffff9585`5a4ef2f0 00000000`00000000 : nt!KeClockInterruptNotify+0x2bb
  563. ffffd780`9eda8f30 fffff804`73208725 : 0000000e`ef326711 ffffc78e`c2cd3720 ffffc78e`c2cd37d0 00000000`00000000 : nt!HalpTimerClockInterrupt+0xe2
  564. ffffd780`9eda8f60 fffff804`733df9ea : ffff9585`5a4ef2f0 ffffc78e`c2cd3720 00000000`00000001 10c08349`08583349 : nt!KiCallInterruptServiceRoutine+0xa5
  565. ffffd780`9eda8fb0 fffff804`733dff57 : 00000000`0fafec11 00000000`00000002 00000000`00000000 00000000`00000010 : nt!KiInterruptSubDispatchNoLockNoEtw+0xfa (TrapFrame @ ffffd780`9eda8e70)
  566. ffff9585`5a4ef270 fffff804`732c4700 : 00000000`00000000 ffffffff`ffffffff 00000000`00000002 ffffee00`0c6079e0 : nt!KiInterruptDispatchNoLockNoEtw+0x37 (TrapFrame @ ffff9585`5a4ef270)
  567. ffff9585`5a4ef400 fffff804`732c0a52 : ffffc78e`00000001 00000000`00000000 00000000`00000000 ffffac01`48785018 : nt!KeFlushMultipleRangeTb+0x2a0
  568. ffff9585`5a4ef490 fffff804`732b410f : ffff9585`5a4ef5c0 85000004`2028a867 ffffac01`48785018 00000000`00000009 : nt!MiFlushTbList+0x82
  569. ffff9585`5a4ef4c0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MiCopyOnWrite+0x6df
  570.  
  571.  
  572. ========================================================================
  573. ======================= Dump #2: ANALYZE VERBOSE =======================
  574. ====================== File: 072920-15640-01.dmp =======================
  575. ========================================================================
  576.  
  577. Mini Kernel Dump File: Only registers and stack trace are available
  578. Windows 10 Kernel Version 19041 MP (12 procs) Free x64
  579. Kernel base = 0xfffff807`39e00000 PsLoadedModuleList = 0xfffff807`3aa2a310
  580. Debug session time: Wed Jul 29 03:14:13.014 2020 (UTC - 4:00)
  581. System Uptime: 0 days 18:30:15.701
  582.  
  583. BugCheck D1, {0, 2, 8, 0}
  584. *** WARNING: Unable to verify timestamp for win32k.sys
  585. *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
  586. Probably caused by : memory_corruption
  587. Followup: memory_corruption
  588.  
  589. DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
  590. An attempt was made to access a pageable (or completely invalid) address at an
  591. interrupt request level (IRQL) that is too high. This is usually
  592. caused by drivers using improper addresses.
  593. If kernel debugger is available get stack backtrace.
  594.  
  595. Arguments:
  596. Arg1: 0000000000000000, memory referenced
  597. Arg2: 0000000000000002, IRQL
  598. Arg3: 0000000000000008, value 0 = read operation, 1 = write operation
  599. Arg4: 0000000000000000, address which referenced memory
  600.  
  601. Debugging Details:
  602. DUMP_CLASS: 1
  603. DUMP_QUALIFIER: 400
  604. DUMP_TYPE: 2
  605. READ_ADDRESS: fffff8073aafa388: Unable to get MiVisibleState
  606. 0000000000000000
  607. CURRENT_IRQL: 2
  608. FAULTING_IP:
  609. +0
  610. 00000000`00000000 ?? ???
  611.  
  612. PROCESS_NAME: EpicGamesLauncher.exe
  613.  
  614. CUSTOMER_CRASH_COUNT: 1
  615. DEFAULT_BUCKET_ID: CODE_CORRUPTION
  616. BUGCHECK_STR: AV
  617. TRAP_FRAME: ffff850b6bc3f460 -- (.trap 0xffff850b6bc3f460)
  618. NOTE: The trap frame does not contain all registers.
  619. Some register values may be zeroed or incorrect.
  620. rax=0000000000000000 rbx=0000000000000000 rcx=ffff850b6bc3f5d0
  621. rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
  622. rip=0000000000000000 rsp=ffff850b6bc3f5f0 rbp=000fa4efbd9bbfff
  623. r8=ffffa107c3c4cde0 r9=00000000000000c7 r10=fffff80737a10000
  624. r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
  625. r14=0000000000000000 r15=0000000000000000
  626. iopl=0 nv up ei ng nz na pe nc
  627. 00000000`00000000 ?? ???
  628. Resetting default scope
  629. IP_IN_FREE_BLOCK: 0
  630. LAST_CONTROL_TRANSFER: from fffff8073a1efa29 to fffff8073a1ddb60
  631. FAILED_INSTRUCTION_ADDRESS:
  632. +0
  633. 00000000`00000000 ?? ???
  634. STACK_TEXT:
  635. ffff850b`6bc3f318 fffff807`3a1efa29 : 00000000`0000000a 00000000`00000000 00000000`00000002 00000000`00000008 : nt!KeBugCheckEx
  636. ffff850b`6bc3f320 fffff807`3a1ebd29 : 00000000`00000300 00000000`00000000 00000048`041212f6 00000000`00000004 : nt!KiBugCheckDispatch+0x69
  637. ffff850b`6bc3f460 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000fff ffffa107`d64b1180 : nt!KiPageFault+0x469
  638. STACK_COMMAND: kb
  639. CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
  640. fffff8073a01734a - nt!MiAddWorkingSetEntries+47a
  641. [ f6:9e ]
  642. fffff8073a184f3f-fffff8073a184f41 3 bytes - nt!MiFreeUltraMapping+33 (+0x16dbf5)
  643. [ 7d fb f6:67 cf 9e ]
  644. 4 errors : !nt (fffff8073a01734a-fffff8073a184f41)
  645. MODULE_NAME: memory_corruption
  646.  
  647. IMAGE_NAME: memory_corruption
  648.  
  649. FOLLOWUP_NAME: memory_corruption
  650. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  651. MEMORY_CORRUPTOR: LARGE
  652. FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
  653. BUCKET_ID: MEMORY_CORRUPTION_LARGE
  654. PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
  655. TARGET_TIME: 2020-07-29T07:14:13.000Z
  656. SUITE_MASK: 272
  657. PRODUCT_TYPE: 1
  658. USER_LCID: 0
  659. FAILURE_ID_HASH_STRING: km:memory_corruption_large
  660. FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
  661. Followup: memory_corruption
  662.  
  663. ====================== Dump #2: 3RD PARTY DRIVERS ======================
  664.  
  665. Oct 15 2015 - rzendpt.sys - Razer RzEndPt driver https://www.razer.com/
  666. Oct 15 2015 - rzudd.sys - Razer Rzudd Engine Driver https://www.razer.com/
  667. May 04 2017 - ICCWDT.sys - Intel(R) Watchdog Timer driver
  668. Apr 11 2018 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
  669. Jan 11 2019 - iaLPSS2_GPIO2.sys - Intel(R) Serial IO GPIO driver
  670. Mar 14 2019 - nvvad64v.sys - Nvidia Virtual Audio driver http://www.nvidia.com/
  671. May 14 2019 - RTKVHD64.sys - Realtek Audio System driver https://www.realtek.com/en/
  672. Jul 01 2019 - rt640x64.sys - Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
  673. Jul 18 2019 - semav6msr64.sys - Intel Driver Update Utility http://www.intel.com/ OR (SEMA Software) http://www.sema-soft.de/en/home/
  674. Sep 19 2019 - RTCore64.sys - !!! Overclocking Software - RivaTuner - MSI Afterburner http://www.msi.com/ or EVGA Precision X http://www.evga.com/
  675. Nov 29 2019 - NvModuleTracker.sys - NVIDIA Module Tracker driver
  676. Jan 10 2020 - nvvhci.sys - Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
  677. Jan 26 2020 - UcmCxUcsiNvppc.sys - NVIDIA USB Type-C Port Policy Controller driver
  678. Jun 09 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
  679. Jul 05 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
  680.  
  681. ================== Dump #2: 3RD PARTY DRIVERS (FULL) ===================
  682.  
  683. Image path: \SystemRoot\System32\drivers\rzendpt.sys
  684. Image name: rzendpt.sys
  685. Search : https://www.google.com/search?q=rzendpt.sys
  686. ADA Info : Razer RzEndPt driver https://www.razer.com/
  687. Timestamp : Thu Oct 15 2015
  688.  
  689. Image path: \SystemRoot\System32\drivers\rzudd.sys
  690. Image name: rzudd.sys
  691. Search : https://www.google.com/search?q=rzudd.sys
  692. ADA Info : Razer Rzudd Engine Driver https://www.razer.com/
  693. Timestamp : Thu Oct 15 2015
  694.  
  695. Image path: \SystemRoot\System32\drivers\ICCWDT.sys
  696. Image name: ICCWDT.sys
  697. Search : https://www.google.com/search?q=ICCWDT.sys
  698. ADA Info : Intel(R) Watchdog Timer driver
  699. Timestamp : Thu May 4 2017
  700.  
  701. Image path: \SystemRoot\System32\drivers\TeeDriverW8x64.sys
  702. Image name: TeeDriverW8x64.sys
  703. Search : https://www.google.com/search?q=TeeDriverW8x64.sys
  704. ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
  705. Timestamp : Wed Apr 11 2018
  706.  
  707. Image path: \SystemRoot\System32\drivers\iaLPSS2_GPIO2.sys
  708. Image name: iaLPSS2_GPIO2.sys
  709. Search : https://www.google.com/search?q=iaLPSS2_GPIO2.sys
  710. ADA Info : Intel(R) Serial IO GPIO driver
  711. Timestamp : Fri Jan 11 2019
  712.  
  713. Image path: \SystemRoot\system32\drivers\nvvad64v.sys
  714. Image name: nvvad64v.sys
  715. Search : https://www.google.com/search?q=nvvad64v.sys
  716. ADA Info : Nvidia Virtual Audio driver http://www.nvidia.com/
  717. Timestamp : Thu Mar 14 2019
  718.  
  719. Image path: \SystemRoot\system32\drivers\RTKVHD64.sys
  720. Image name: RTKVHD64.sys
  721. Search : https://www.google.com/search?q=RTKVHD64.sys
  722. ADA Info : Realtek Audio System driver https://www.realtek.com/en/
  723. Timestamp : Tue May 14 2019
  724.  
  725. Image path: \SystemRoot\System32\drivers\rt640x64.sys
  726. Image name: rt640x64.sys
  727. Search : https://www.google.com/search?q=rt640x64.sys
  728. ADA Info : Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
  729. Timestamp : Mon Jul 1 2019
  730.  
  731. Image path: \??\C:\WINDOWS\system32\drivers\semav6msr64.sys
  732. Image name: semav6msr64.sys
  733. Search : https://www.google.com/search?q=semav6msr64.sys
  734. ADA Info : Intel Driver Update Utility http://www.intel.com/ OR (SEMA Software) http://www.sema-soft.de/en/home/
  735. Timestamp : Thu Jul 18 2019
  736.  
  737. Image path: \??\C:\Program Files (x86)\MSI Afterburner\RTCore64.sys
  738. Image name: RTCore64.sys
  739. Search : https://www.google.com/search?q=RTCore64.sys
  740. ADA Info : !!! Overclocking Software - RivaTuner - MSI Afterburner http://www.msi.com/ or EVGA Precision X http://www.evga.com/
  741. Timestamp : Thu Sep 19 2019
  742.  
  743. Image path: \SystemRoot\System32\drivers\NvModuleTracker.sys
  744. Image name: NvModuleTracker.sys
  745. Search : https://www.google.com/search?q=NvModuleTracker.sys
  746. ADA Info : NVIDIA Module Tracker driver
  747. Timestamp : Fri Nov 29 2019
  748.  
  749. Image path: \SystemRoot\System32\drivers\nvvhci.sys
  750. Image name: nvvhci.sys
  751. Search : https://www.google.com/search?q=nvvhci.sys
  752. ADA Info : Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
  753. Timestamp : Fri Jan 10 2020
  754.  
  755. Image path: \SystemRoot\System32\DriverStore\FileRepository\nvppc.inf_amd64_0f22333f160a8f42\UcmCxUcsiNvppc.sys
  756. Image name: UcmCxUcsiNvppc.sys
  757. Search : https://www.google.com/search?q=UcmCxUcsiNvppc.sys
  758. ADA Info : NVIDIA USB Type-C Port Policy Controller driver
  759. Timestamp : Sun Jan 26 2020
  760.  
  761. Image path: \SystemRoot\system32\drivers\nvhda64v.sys
  762. Image name: nvhda64v.sys
  763. Search : https://www.google.com/search?q=nvhda64v.sys
  764. ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
  765. Timestamp : Tue Jun 9 2020
  766.  
  767. Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_edab19158bdd0d0a\nvlddmkm.sys
  768. Image name: nvlddmkm.sys
  769. Search : https://www.google.com/search?q=nvlddmkm.sys
  770. ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
  771. Timestamp : Sun Jul 5 2020
  772.  
  773. ====================== Dump #2: MICROSOFT DRIVERS ======================
  774.  
  775. ACPI.sys ACPI Driver for NT (Microsoft)
  776. acpiex.sys ACPIEx Driver (Microsoft)
  777. acpipagr.sys ACPI Processor Aggregator Device driver (Microsoft)
  778. afd.sys Ancillary Function Driver for WinSock (Microsoft)
  779. afunix.sys AF_UNIX Socket Provider driver (Microsoft)
  780. AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
  781. ahcache.sys Application Compatibility Cache (Microsoft)
  782. bam.sys BAM Kernal driver (Microsoft)
  783. BasicDisplay.sys Basic Display driver (Microsoft)
  784. BasicRender.sys Basic Render driver (Microsoft)
  785. Beep.SYS BEEP driver (Microsoft)
  786. bindflt.sys Windows Bind Filter driver (Microsoft)
  787. BOOTVID.dll VGA Boot Driver (Microsoft)
  788. bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
  789. cdd.dll Canonical Display Driver (Microsoft)
  790. cdrom.sys SCSI CD-ROM Driver (Microsoft)
  791. CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
  792. CI.dll Code Integrity Module (Microsoft)
  793. CimFS.SYS Consumer IR Class Driver for eHome (Microsoft)
  794. CLASSPNP.SYS SCSI Class System Dll (Microsoft)
  795. cldflt.sys Cloud Files Mini Filter driver (Microsoft)
  796. CLFS.SYS Common Log File System Driver (Microsoft)
  797. clipsp.sys CLIP Service (Microsoft)
  798. cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
  799. cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
  800. CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
  801. condrv.sys Console Driver (Microsoft)
  802. crashdmp.sys Crash Dump driver (Microsoft)
  803. csc.sys Windows Client Side Caching driver (Microsoft)
  804. dfsc.sys DFS Namespace Client Driver (Microsoft)
  805. disk.sys PnP Disk Driver (Microsoft)
  806. drmk.sys Digital Rights Management (DRM) driver (Microsoft)
  807. dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  808. dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  809. dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  810. dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
  811. dxgmms2.sys DirectX Graphics MMS
  812. EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
  813. fastfat.SYS Fast FAT File System Driver (Microsoft)
  814. filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
  815. fileinfo.sys FileInfo Filter Driver (Microsoft)
  816. FLTMGR.SYS Filesystem Filter Manager (Microsoft)
  817. Fs_Rec.sys File System Recognizer Driver (Microsoft)
  818. fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
  819. fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
  820. gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
  821. hal.dll Hardware Abstraction Layer DLL (Microsoft)
  822. HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
  823. HIDCLASS.SYS Hid Class Library (Microsoft)
  824. HIDPARSE.SYS Hid Parsing Library (Microsoft)
  825. hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
  826. HTTP.sys HTTP Protocol Stack (Microsoft)
  827. intelpep.sys Intel Power Engine Plugin (Microsoft)
  828. intelppm.sys Processor Device Driver (Microsoft)
  829. IntelTA.sys Intel Telemetry Driver
  830. iorate.sys I/O rate control Filter (Microsoft)
  831. kbdclass.sys Keyboard Class Driver (Microsoft)
  832. kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
  833. kd.dll Local Kernal Debugger (Microsoft)
  834. kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
  835. ks.sys Kernal CSA Library (Microsoft)
  836. ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
  837. ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
  838. ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
  839. lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
  840. luafv.sys LUA File Virtualization Filter Driver (Microsoft)
  841. mcupdate_GenuineIntel.dll Intel Microcode Update Library (Microsoft)
  842. mmcss.sys MMCSS Driver (Microsoft)
  843. monitor.sys Monitor Driver (Microsoft)
  844. mouclass.sys Mouse Class Driver (Microsoft)
  845. mouhid.sys HID Mouse Filter Driver (Microsoft)
  846. mountmgr.sys Mount Point Manager (Microsoft)
  847. MpKslDrv.sys Microsoft Anti-malware Protection driver
  848. mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
  849. mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
  850. mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
  851. Msfs.SYS Mailslot driver (Microsoft)
  852. msgpioclx.sys GPIO Class Extension Driver (Microsoft)
  853. msisadrv.sys ISA Driver (Microsoft)
  854. mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
  855. msquic.sys Windows QUIC Driver
  856. msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
  857. mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
  858. mssmbios.sys System Management BIOS driver (Microsoft)
  859. mup.sys Multiple UNC Provider driver (Microsoft)
  860. ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
  861. ndiscap.sys Microsoft NDIS Packet Capture Filter Driver
  862. ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
  863. ndisuio.sys NDIS User mode I/O driver (Microsoft)
  864. NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
  865. ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
  866. NDProxy.sys NDIS Proxy driver (Microsoft)
  867. Ndu.sys Network Data Usage Monitoring driver (Microsoft)
  868. netbios.sys NetBIOS Interface driver (Microsoft)
  869. netbt.sys MBT Transport driver (Microsoft)
  870. NETIO.SYS Network I/O Subsystem (Microsoft)
  871. Npfs.SYS NPFS driver (Microsoft)
  872. npsvctrig.sys Named pipe service triggers (Microsoft)
  873. nsiproxy.sys NSI Proxy driver (Microsoft)
  874. Ntfs.sys NT File System Driver (Microsoft)
  875. ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
  876. ntosext.sys NTOS Extension Host driver (Microsoft)
  877. Null.SYS NULL Driver (Microsoft)
  878. nwifi.sys NativeWiFi Miniport Driver (Microsoft)
  879. pacer.sys QoS Packet Scheduler (Microsoft)
  880. partmgr.sys Partition driver (Microsoft)
  881. pci.sys NT Plug and Play PCI Enumerator (Microsoft)
  882. pcw.sys Performance Counter Driver (Microsoft)
  883. pdc.sys Power Dependency Coordinator Driver (Microsoft)
  884. peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
  885. portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
  886. PSHED.dll Platform Specific Hardware Error driver (Microsoft)
  887. qwavedrv.sys Quality Windows Audio Video Experience (qWave) Support driver (Microsoft)
  888. rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
  889. raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
  890. raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
  891. rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
  892. rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
  893. rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
  894. rdyboost.sys ReadyBoost Driver (Microsoft)
  895. rspndr.sys Link-Layer Topology Responder driver (Microsoft)
  896. SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
  897. SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
  898. spaceport.sys Storage Spaces driver (Microsoft)
  899. srv2.sys Smb 2.0 Server driver (Microsoft)
  900. srvnet.sys Server Network driver (Microsoft)
  901. storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
  902. storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
  903. storqosflt.sys Storage QoS Filter driver (Microsoft)
  904. swenum.sys Plug and Play Software Device Enumerator (Microsoft)
  905. tbs.sys Export driver for kernel mode TPM API (Microsoft)
  906. tcpip.sys TCP/IP Protocol driver (Microsoft)
  907. tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
  908. TDI.SYS TDI Wrapper driver (Microsoft)
  909. tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
  910. tm.sys Kernel Transaction Manager driver (Microsoft)
  911. UcmCx.sys USB Connector Manager KMDF Class Extension
  912. ucx01000.sys USB Controller Extension (Microsoft)
  913. UEFI.sys UEFI NT driver (Microsoft)
  914. umbus.sys User-Mode Bus Enumerator (Microsoft)
  915. usbaudio.sys USB Audio Class Driver (Microsoft)
  916. usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
  917. USBD.SYS Universal Serial Bus Driver (Microsoft)
  918. UsbHub3.sys USB3 HUB driver (Microsoft)
  919. usbvideo.sys USB Video Class Driver (Microsoft)
  920. USBXHCI.SYS USB XHCI driver (Microsoft)
  921. vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
  922. Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
  923. volmgr.sys Volume Manager Driver (Microsoft)
  924. volmgrx.sys Volume Manager Extension Driver (Microsoft)
  925. volsnap.sys Volume Shadow Copy driver (Microsoft)
  926. volume.sys Volume driver (Microsoft)
  927. vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
  928. wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
  929. watchdog.sys Watchdog driver (Microsoft)
  930. wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
  931. Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
  932. WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
  933. WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
  934. WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
  935. werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
  936. wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
  937. win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
  938. win32kbase.sys Base Win32k Kernel Driver (Microsoft)
  939. win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
  940. WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
  941. WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
  942. winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
  943. wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
  944. WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
  945. Wof.sys Windows Overlay Filter (Microsoft)
  946. WppRecorder.sys WPP Trace Recorder (Microsoft)
  947.  
  948. ====================== Dump #2: UNLOADED MODULES =======================
  949.  
  950. fffff807`3c330000 fffff807`3c33f000 hiber_storpo
  951. fffff807`3c340000 fffff807`3c373000 hiber_storah
  952. fffff807`3c380000 fffff807`3c39e000 hiber_dumpfv
  953. fffff807`3c320000 fffff807`3c32d000 MSPCLOCK.sys
  954. fffff807`3c310000 fffff807`3c31d000 MSPQM.sys
  955. fffff807`3c300000 fffff807`3c30d000 MSPCLOCK.sys
  956. fffff807`3c2f0000 fffff807`3c2fd000 MSPQM.sys
  957. fffff807`3c2d0000 fffff807`3c2e1000 MSKSSRV.sys
  958. fffff807`3c2b0000 fffff807`3c2c1000 MSKSSRV.sys
  959. fffff807`3c290000 fffff807`3c2a1000 MSKSSRV.sys
  960. fffff807`3c270000 fffff807`3c281000 MSKSSRV.sys
  961. fffff807`3c090000 fffff807`3c22b000 EasyAntiChea
  962. fffff807`3c250000 fffff807`3c261000 MSKSSRV.sys
  963. fffff807`3be00000 fffff807`3bf9b000 EasyAntiChea
  964. fffff807`3c070000 fffff807`3c081000 MpKslDrv.sys
  965. fffff807`3bfb0000 fffff807`3bfc1000 MSKSSRV.sys
  966. fffff807`537e0000 fffff807`53820000 mbamswissarm
  967. fffff807`55190000 fffff807`551c9000 MbamChameleo
  968. fffff807`551d0000 fffff807`551f3000 mwac.sys
  969. fffff807`53820000 fffff807`53834000 mbam.sys
  970. fffff807`51060000 fffff807`51094000 farflt.sys
  971. fffff807`51030000 fffff807`51057000 mbae64.sys
  972. fffff807`3bfa0000 fffff807`3bfac000 bertreader.s
  973. fffff807`55bb0000 fffff807`55bc1000 MSKSSRV.sys
  974. fffff807`3df80000 fffff807`3dfe8000 WdFilter.sys
  975. fffff807`537c0000 fffff807`537d6000 WdNisDrv.sys
  976. fffff807`55bb0000 fffff807`55bc1000 MSKSSRV.sys
  977. fffff807`51040000 fffff807`5104f000 dump_storpor
  978. fffff807`51090000 fffff807`510c3000 dump_storahc
  979. fffff807`510f0000 fffff807`5110e000 dump_dumpfve
  980. fffff807`520d0000 fffff807`520dc000 WdmCompanion
  981. fffff807`51670000 fffff807`5168c000 dam.sys
  982. fffff807`52520000 fffff807`52a39000 vgk.sys
  983. fffff807`3da60000 fffff807`3da71000 WdBoot.sys
  984. fffff807`3da50000 fffff807`3da59000 MbamElam.sys
  985. fffff807`3eae0000 fffff807`3eaf0000 hwpolicy.sys
  986.  
  987. ====================== Dump #2: BIOS INFORMATION =======================
  988.  
  989. [SMBIOS Data Tables v3.1]
  990. [DMI Version - 0]
  991. [2.0 Calling Convention - No]
  992. [Table Size - 4459 bytes]
  993. [BIOS Information (Type 0) - Length 26 - Handle 0000h]
  994. Vendor American Megatrends Inc.
  995. BIOS Version F2
  996. BIOS Starting Address Segment f000
  997. BIOS Release Date 04/19/2018
  998. BIOS ROM Size 1000000
  999. BIOS Characteristics
  1000. 07: - PCI Supported
  1001. 11: - Upgradeable FLASH BIOS
  1002. 12: - BIOS Shadowing Supported
  1003. 15: - CD-Boot Supported
  1004. 16: - Selectable Boot Supported
  1005. 17: - BIOS ROM Socketed
  1006. 19: - EDD Supported
  1007. 23: - 1.2MB Floppy Supported
  1008. 24: - 720KB Floppy Supported
  1009. 25: - 2.88MB Floppy Supported
  1010. 26: - Print Screen Device Supported
  1011. 28: - Serial Services Supported
  1012. 29: - Printer Services Supported
  1013. 32: - BIOS Vendor Reserved
  1014. BIOS Characteristic Extensions
  1015. 00: - ACPI Supported
  1016. 01: - USB Legacy Supported
  1017. 08: - BIOS Boot Specification Supported
  1018. 10: - Specification Reserved
  1019. 11: - Specification Reserved
  1020. BIOS Major Revision 5
  1021. BIOS Minor Revision 13
  1022. EC Firmware Major Revision 255
  1023. EC Firmware Minor Revision 255
  1024. [System Information (Type 1) - Length 27 - Handle 0001h]
  1025. Manufacturer Gigabyte Technology Co., Ltd.
  1026. Product Name H310M H
  1027. Version Default string
  1028. UUID 00000000-0000-0000-0000-000000000000
  1029. Wakeup Type Power Switch
  1030. SKUNumber Default string
  1031. Family Default string
  1032. [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
  1033. Manufacturer Gigabyte Technology Co., Ltd.
  1034. Product H310M H
  1035. Version x.x
  1036. Feature Flags 09h
  1037. -1364281632: - -1364281584: - «áêù
  1038. Location Default string
  1039. Chassis Handle 0003h
  1040. Board Type 0ah - Processor/Memory Module
  1041. Number of Child Handles 0
  1042. [System Enclosure (Type 3) - Length 22 - Handle 0003h]
  1043. Manufacturer Default string
  1044. Chassis Type Desktop
  1045. Version Default string
  1046. Bootup State Safe
  1047. Power Supply State Safe
  1048. Thermal State Safe
  1049. Security Status None
  1050. OEM Defined 0
  1051. Height 0U
  1052. Number of Power Cords 1
  1053. Number of Contained Elements 0
  1054. Contained Element Size 3
  1055. [Onboard Devices Information (Type 10) - Length 6 - Handle 0021h]
  1056. Number of Devices 1
  1057. 01: Type Video [enabled]
  1058. [OEM Strings (Type 11) - Length 5 - Handle 0022h]
  1059. Number of Strings 1
  1060. 1 Default string
  1061. [System Configuration Options (Type 12) - Length 5 - Handle 0023h]
  1062. [Physical Memory Array (Type 16) - Length 23 - Handle 003ah]
  1063. Location 03h - SystemBoard/Motherboard
  1064. Use 03h - System Memory
  1065. Memory Error Correction 03h - None
  1066. Maximum Capacity 33554432KB
  1067. Number of Memory Devices 4
  1068. [Memory Device (Type 17) - Length 40 - Handle 003bh]
  1069. Physical Memory Array Handle 003ah
  1070. Total Width 64 bits
  1071. Data Width 64 bits
  1072. Size 8192MB
  1073. Form Factor 09h - DIMM
  1074. Device Locator ChannelA-DIMM0
  1075. Bank Locator BANK 0
  1076. Memory Type 1ah - Specification Reserved
  1077. Type Detail 0080h - Synchronous
  1078. Speed 2133MHz
  1079. Manufacturer 029E
  1080. Part Number CMK16GX4M2B3200C16
  1081. [Memory Device (Type 17) - Length 40 - Handle 003ch]
  1082. Physical Memory Array Handle 003ah
  1083. Total Width 0 bits
  1084. Data Width 0 bits
  1085. Form Factor 02h - Unknown
  1086. Device Locator ChannelA-DIMM1
  1087. Bank Locator BANK 1
  1088. Memory Type 02h - Unknown
  1089. Type Detail 0000h -
  1090. Speed 0MHz
  1091. [Memory Device (Type 17) - Length 40 - Handle 003dh]
  1092. Physical Memory Array Handle 003ah
  1093. Total Width 64 bits
  1094. Data Width 64 bits
  1095. Size 8192MB
  1096. Form Factor 09h - DIMM
  1097. Device Locator ChannelB-DIMM0
  1098. Bank Locator BANK 2
  1099. Memory Type 1ah - Specification Reserved
  1100. Type Detail 0080h - Synchronous
  1101. Speed 2133MHz
  1102. Manufacturer 029E
  1103. Part Number CMK16GX4M2B3200C16
  1104. [Memory Device (Type 17) - Length 40 - Handle 003eh]
  1105. Physical Memory Array Handle 003ah
  1106. Total Width 0 bits
  1107. Data Width 0 bits
  1108. Form Factor 02h - Unknown
  1109. Device Locator ChannelB-DIMM1
  1110. Bank Locator BANK 3
  1111. Memory Type 02h - Unknown
  1112. Type Detail 0000h -
  1113. Speed 0MHz
  1114. [Memory Array Mapped Address (Type 19) - Length 31 - Handle 003fh]
  1115. Starting Address 00000000h
  1116. Ending Address 00ffffffh
  1117. Memory Array Handle 003ah
  1118. Partition Width 02
  1119. [Cache Information (Type 7) - Length 19 - Handle 0044h]
  1120. Socket Designation L1 Cache
  1121. Cache Configuration 0180h - WB Enabled Int NonSocketed L1
  1122. Maximum Cache Size 0180h - 384K
  1123. Installed Size 0180h - 384K
  1124. Supported SRAM Type 0020h - Synchronous
  1125. Current SRAM Type 0020h - Synchronous
  1126. Cache Speed 0ns
  1127. Error Correction Type ParitySingle-Bit ECC
  1128. System Cache Type Unified
  1129. Associativity 8-way Set-Associative
  1130. [Cache Information (Type 7) - Length 19 - Handle 0045h]
  1131. Socket Designation L2 Cache
  1132. Cache Configuration 0181h - WB Enabled Int NonSocketed L2
  1133. Maximum Cache Size 0600h - 1536K
  1134. Installed Size 0600h - 1536K
  1135. Supported SRAM Type 0020h - Synchronous
  1136. Current SRAM Type 0020h - Synchronous
  1137. Cache Speed 0ns
  1138. Error Correction Type Multi-Bit ECC
  1139. System Cache Type Unified
  1140. Associativity 4-way Set-Associative
  1141. [Cache Information (Type 7) - Length 19 - Handle 0046h]
  1142. Socket Designation L3 Cache
  1143. Cache Configuration 0182h - WB Enabled Int NonSocketed L3
  1144. Maximum Cache Size 3000h - 12288K
  1145. Installed Size 3000h - 12288K
  1146. Supported SRAM Type 0020h - Synchronous
  1147. Current SRAM Type 0020h - Synchronous
  1148. Cache Speed 0ns
  1149. Error Correction Type Specification Reserved
  1150. System Cache Type Unified
  1151. Associativity 16-way Set-Associative
  1152. [Processor Information (Type 4) - Length 48 - Handle 0047h]
  1153. Socket Designation U3E1
  1154. Processor Type Central Processor
  1155. Processor Family c6h - Specification Reserved
  1156. Processor Manufacturer Intel(R) Corporation
  1157. Processor ID ea060900fffbebbf
  1158. Processor Version Intel(R) Core(TM) i7-8700 CPU @ 3.20GHz
  1159. Processor Voltage 89h - 0.9V
  1160. External Clock 100MHz
  1161. Max Speed 8300MHz
  1162. Current Speed 3200MHz
  1163. Status Enabled Populated
  1164. Processor Upgrade Other
  1165. L1 Cache Handle 0044h
  1166. L2 Cache Handle 0045h
  1167. L3 Cache Handle 0046h
  1168. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0048h]
  1169. Starting Address 00000000h
  1170. Ending Address 007fffffh
  1171. Memory Device Handle 003bh
  1172. Mem Array Mapped Adr Handle 003fh
  1173. Interleave Position 01
  1174. Interleave Data Depth 02
  1175. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0049h]
  1176. Starting Address 00800000h
  1177. Ending Address 00ffffffh
  1178. Memory Device Handle 003dh
  1179. Mem Array Mapped Adr Handle 003fh
  1180. Interleave Position 02
  1181. Interleave Data Depth 02
  1182.  
  1183. ========================== Dump #2: Extra #1 ===========================
  1184.  
  1185. 10: kd> !verifier
  1186. Verify Flags Level 0x00000000
  1187. STANDARD FLAGS:
  1188. [X] (0x00000000) Automatic Checks
  1189. [ ] (0x00000001) Special pool
  1190. [ ] (0x00000002) Force IRQL checking
  1191. [ ] (0x00000008) Pool tracking
  1192. [ ] (0x00000010) I/O verification
  1193. [ ] (0x00000020) Deadlock detection
  1194. [ ] (0x00000080) DMA checking
  1195. [ ] (0x00000100) Security checks
  1196. [ ] (0x00000800) Miscellaneous checks
  1197. [ ] (0x00020000) DDI compliance checking
  1198. ADDITIONAL FLAGS:
  1199. [ ] (0x00000004) Randomized low resources simulation
  1200. [ ] (0x00000200) Force pending I/O requests
  1201. [ ] (0x00000400) IRP logging
  1202. [ ] (0x00002000) Invariant MDL checking for stack
  1203. [ ] (0x00004000) Invariant MDL checking for driver
  1204. [ ] (0x00008000) Power framework delay fuzzing
  1205. [ ] (0x00010000) Port/miniport interface checking
  1206. [ ] (0x00040000) Systematic low resources simulation
  1207. [ ] (0x00080000) DDI compliance checking (additional)
  1208. [ ] (0x00200000) NDIS/WIFI verification
  1209. [ ] (0x00800000) Kernel synchronization delay fuzzing
  1210. [ ] (0x01000000) VM switch verification
  1211. [ ] (0x02000000) Code integrity checks
  1212. [X] Indicates flag is enabled
  1213. Summary of All Verifier Statistics
  1214. RaiseIrqls 0x0
  1215. AcquireSpinLocks 0x0
  1216. Synch Executions 0x0
  1217. Trims 0x0
  1218. Pool Allocations Attempted 0x0
  1219. Pool Allocations Succeeded 0x0
  1220. Pool Allocations Succeeded SpecialPool 0x0
  1221. Pool Allocations With NO TAG 0x0
  1222. Pool Allocations Failed 0x0
  1223. Current paged pool allocations 0x0 for 00000000 bytes
  1224. Peak paged pool allocations 0x0 for 00000000 bytes
  1225. Current nonpaged pool allocations 0x0 for 00000000 bytes
  1226. Peak nonpaged pool allocations 0x0 for 00000000 bytes
  1227.  
  1228. ========================== Dump #2: Extra #2 ===========================
  1229.  
  1230. 10: kd> !thread
  1231. THREAD ffffa107d64b1080 Cid 3320.36c4 Teb: 000000c7fa21a000 Win32Thread: 0000000000000000 RUNNING on processor a
  1232. Not impersonating
  1233. GetUlongFromAddress: unable to read from fffff8073aa1143c
  1234. Owning Process ffffa107dab0c080 Image: EpicGamesLauncher.exe
  1235. Attached Process N/A Image: N/A
  1236. fffff78000000000: Unable to get shared data
  1237. Wait Start TickCount 4263404
  1238. Context Switch Count 840369 IdealProcessor: 6
  1239. ReadMemory error: Cannot get nt!KeMaximumIncrement value.
  1240. UserTime 00:00:00.000
  1241. KernelTime 00:00:00.000
  1242. Win32 Start Address 0x00007ff7eeb047a0
  1243. Stack Init ffff850b6bc3fb90 Current ffff850b6bc3f5a0
  1244. Base ffff850b6bc40000 Limit ffff850b6bc39000 Call 0000000000000000
  1245. Priority 6 BasePriority 6 PriorityDecrement 0 IoPriority 2 PagePriority 5
  1246. Child-SP RetAddr : Args to Child : Call Site
  1247. ffff850b`6bc3f318 fffff807`3a1efa29 : 00000000`0000000a 00000000`00000000 00000000`00000002 00000000`00000008 : nt!KeBugCheckEx
  1248. ffff850b`6bc3f320 fffff807`3a1ebd29 : 00000000`00000300 00000000`00000000 00000048`041212f6 00000000`00000004 : nt!KiBugCheckDispatch+0x69
  1249. ffff850b`6bc3f460 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000fff ffffa107`d64b1180 : nt!KiPageFault+0x469 (TrapFrame @ ffff850b`6bc3f460)
  1250.  
  1251.  
  1252. ========================================================================
  1253. ======================= Dump #3: ANALYZE VERBOSE =======================
  1254. ====================== File: 072720-15703-01.dmp =======================
  1255. ========================================================================
  1256.  
  1257. Mini Kernel Dump File: Only registers and stack trace are available
  1258. Windows 10 Kernel Version 19041 MP (12 procs) Free x64
  1259. Kernel base = 0xfffff803`6b600000 PsLoadedModuleList = 0xfffff803`6c22a310
  1260. Debug session time: Mon Jul 27 10:32:37.611 2020 (UTC - 4:00)
  1261. System Uptime: 0 days 2:53:15.297
  1262.  
  1263. BugCheck 1E, {ffffffffc000001d, fffff8036b902db4, ffffe0803afcb340, 17}
  1264. *** WARNING: Unable to verify timestamp for win32k.sys
  1265. *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
  1266. Probably caused by : memory_corruption
  1267. Followup: memory_corruption
  1268.  
  1269. KMODE_EXCEPTION_NOT_HANDLED (1e)
  1270. This is a very common bugcheck. Usually the exception address pinpoints
  1271. the driver/function that caused the problem. Always note this address
  1272. as well as the link date of the driver/image that contains this address.
  1273.  
  1274. Arguments:
  1275. Arg1: ffffffffc000001d, The exception code that was not handled
  1276. Arg2: fffff8036b902db4, The address that the exception occurred at
  1277. Arg3: ffffe0803afcb340, Parameter 0 of the exception
  1278. Arg4: 0000000000000017, Parameter 1 of the exception
  1279.  
  1280. Debugging Details:
  1281. DUMP_CLASS: 1
  1282. DUMP_QUALIFIER: 400
  1283. DUMP_TYPE: 2
  1284. EXCEPTION_CODE: (NTSTATUS) 0xc000001d - {EXCEPTION} Illegal Instruction An attempt was made to execute an illegal instruction.
  1285. FAULTING_IP:
  1286. nt!MiUnlockPageTableInternal+194
  1287. fffff803`6b902db4 c7feffff4c8d xbegin fffff802`f8dd2db9
  1288. EXCEPTION_PARAMETER1: ffffe0803afcb340
  1289. EXCEPTION_PARAMETER2: 0000000000000017
  1290. BUGCHECK_STR: 0x1E_c000001d
  1291. CUSTOMER_CRASH_COUNT: 1
  1292. DEFAULT_BUCKET_ID: CODE_CORRUPTION
  1293.  
  1294. PROCESS_NAME: System
  1295.  
  1296. CURRENT_IRQL: 2
  1297. BAD_STACK_POINTER: ffffe0803afd98e8
  1298. LAST_CONTROL_TRANSFER: from fffff8036ba2eef1 to fffff8036b9ddb60
  1299. FAILED_INSTRUCTION_ADDRESS:
  1300. nt!MiUnlockPageTableInternal+194
  1301. fffff803`6b902db4 c7feffff4c8d xbegin fffff802`f8dd2db9
  1302. STACK_TEXT:
  1303. ffffe080`3afd98e8 fffff803`6ba2eef1 : 00000000`0000001e ffffffff`c000001d fffff803`6b902db4 ffffe080`3afcb340 : nt!KeBugCheckEx
  1304. ffffe080`3afd98f0 fffff803`6b9de9f2 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDispatchException+0x1b3e31
  1305. ffffe080`3afd9fb0 fffff803`6b9de9c0 : fffff803`6b9efb65 00000000`00000000 00000000`00000000 ffffab87`29c5a040 : nt!KxExceptionDispatchOnExceptionStack+0x12
  1306. ffff8402`3a8bf738 fffff803`6b9efb65 : 00000000`00000000 00000000`00000000 ffffab87`29c5a040 fffff803`6b83a810 : nt!KiExceptionDispatchOnExceptionStackContinue
  1307. ffff8402`3a8bf740 fffff803`6b9ea0a9 : 00000000`00000000 00000018`34148f00 ffffe080`3afc0180 00000008`00000001 : nt!KiExceptionDispatch+0x125
  1308. ffff8402`3a8bf920 fffff803`6b902db4 : 00000000`00000000 00000000`00000001 ffffe080`3afc0180 ffffe080`3afc0180 : nt!KiInvalidOpcodeFault+0x329
  1309. ffff8402`3a8bfab0 00000000`00000000 : 00000000`00000000 00000000`000006e5 ffffab87`2cd93080 ffffe080`3afcb340 : nt!MiUnlockPageTableInternal+0x194
  1310. STACK_COMMAND: kb
  1311. CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
  1312. fffff8036b902a34-fffff8036b902a35 2 bytes - nt!MiRebuildPageTableLeafAges+34
  1313. [ fb f6:c8 90 ]
  1314. fffff8036b902a84-fffff8036b902a85 2 bytes - nt!MiRebuildPageTableLeafAges+84 (+0x50)
  1315. [ 80 fa:00 f9 ]
  1316. fffff8036b902b47 - nt!MiCountWslesInPageTable+27 (+0xc3)
  1317. [ f6:90 ]
  1318. fffff8036b902b56-fffff8036b902b5a 5 bytes - nt!MiCountWslesInPageTable+36 (+0x0f)
  1319. [ d0 be 7d fb f6:10 32 64 c8 90 ]
  1320. fffff8036b902b63-fffff8036b902b67 5 bytes - nt!MiCountWslesInPageTable+43 (+0x0d)
  1321. [ d7 be 7d fb f6:17 32 64 c8 90 ]
  1322. fffff8036b902c3e-fffff8036b902c43 6 bytes - nt!MiUnlockPageTableInternal+1e (+0xdb)
  1323. [ 68 df be 7d fb f6:08 19 32 64 c8 90 ]
  1324. fffff8036b902c52-fffff8036b902c56 5 bytes - nt!MiUnlockPageTableInternal+32 (+0x14)
  1325. [ d0 be 7d fb f6:10 32 64 c8 90 ]
  1326. fffff8036b902c5c-fffff8036b902c60 5 bytes - nt!MiUnlockPageTableInternal+3c (+0x0a)
  1327. [ df be 7d fb f6:1f 32 64 c8 90 ]
  1328. fffff8036b902cb1-fffff8036b902cb5 5 bytes - nt!MiUnlockPageTableInternal+91 (+0x55)
  1329. [ d7 be 7d fb f6:17 32 64 c8 90 ]
  1330. fffff8036b902e4b-fffff8036b902e4f 5 bytes - nt!MiGetPageTableLockBuffer+3 (+0x19a)
  1331. [ d0 be 7d fb f6:10 32 64 c8 90 ]
  1332. fffff8036b984f3e-fffff8036b984f41 4 bytes - nt!MiFreeUltraMapping+32 (+0x820f3)
  1333. [ a0 7d fb f6:20 64 c8 90 ]
  1334. 45 errors : !nt (fffff8036b902a34-fffff8036b984f41)
  1335. MODULE_NAME: memory_corruption
  1336.  
  1337. IMAGE_NAME: memory_corruption
  1338.  
  1339. FOLLOWUP_NAME: memory_corruption
  1340. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  1341. MEMORY_CORRUPTOR: LARGE
  1342. FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
  1343. BUCKET_ID: MEMORY_CORRUPTION_LARGE
  1344. PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
  1345. TARGET_TIME: 2020-07-27T14:32:37.000Z
  1346. SUITE_MASK: 272
  1347. PRODUCT_TYPE: 1
  1348. USER_LCID: 0
  1349. FAILURE_ID_HASH_STRING: km:memory_corruption_large
  1350. FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
  1351. Followup: memory_corruption
  1352.  
  1353. ====================== Dump #3: 3RD PARTY DRIVERS ======================
  1354.  
  1355. Oct 15 2015 - rzendpt.sys - Razer RzEndPt driver https://www.razer.com/
  1356. Oct 15 2015 - rzudd.sys - Razer Rzudd Engine Driver https://www.razer.com/
  1357. May 04 2017 - ICCWDT.sys - Intel(R) Watchdog Timer driver
  1358. Apr 11 2018 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
  1359. Jan 11 2019 - iaLPSS2_GPIO2.sys - Intel(R) Serial IO GPIO driver
  1360. Mar 14 2019 - nvvad64v.sys - Nvidia Virtual Audio driver http://www.nvidia.com/
  1361. May 14 2019 - RTKVHD64.sys - Realtek Audio System driver https://www.realtek.com/en/
  1362. Jul 01 2019 - rt640x64.sys - Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
  1363. Jul 18 2019 - semav6msr64.sys - Intel Driver Update Utility http://www.intel.com/ OR (SEMA Software) http://www.sema-soft.de/en/home/
  1364. Nov 29 2019 - NvModuleTracker.sys - NVIDIA Module Tracker driver
  1365. Jan 10 2020 - nvvhci.sys - Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
  1366. Jan 26 2020 - UcmCxUcsiNvppc.sys - NVIDIA USB Type-C Port Policy Controller driver
  1367. Jun 09 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
  1368. Jul 05 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
  1369.  
  1370. ================== Dump #3: 3RD PARTY DRIVERS (FULL) ===================
  1371.  
  1372. Image path: \SystemRoot\System32\drivers\rzendpt.sys
  1373. Image name: rzendpt.sys
  1374. Search : https://www.google.com/search?q=rzendpt.sys
  1375. ADA Info : Razer RzEndPt driver https://www.razer.com/
  1376. Timestamp : Thu Oct 15 2015
  1377.  
  1378. Image path: \SystemRoot\System32\drivers\rzudd.sys
  1379. Image name: rzudd.sys
  1380. Search : https://www.google.com/search?q=rzudd.sys
  1381. ADA Info : Razer Rzudd Engine Driver https://www.razer.com/
  1382. Timestamp : Thu Oct 15 2015
  1383.  
  1384. Image path: \SystemRoot\System32\drivers\ICCWDT.sys
  1385. Image name: ICCWDT.sys
  1386. Search : https://www.google.com/search?q=ICCWDT.sys
  1387. ADA Info : Intel(R) Watchdog Timer driver
  1388. Timestamp : Thu May 4 2017
  1389.  
  1390. Image path: \SystemRoot\System32\drivers\TeeDriverW8x64.sys
  1391. Image name: TeeDriverW8x64.sys
  1392. Search : https://www.google.com/search?q=TeeDriverW8x64.sys
  1393. ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
  1394. Timestamp : Wed Apr 11 2018
  1395.  
  1396. Image path: \SystemRoot\System32\drivers\iaLPSS2_GPIO2.sys
  1397. Image name: iaLPSS2_GPIO2.sys
  1398. Search : https://www.google.com/search?q=iaLPSS2_GPIO2.sys
  1399. ADA Info : Intel(R) Serial IO GPIO driver
  1400. Timestamp : Fri Jan 11 2019
  1401.  
  1402. Image path: \SystemRoot\system32\drivers\nvvad64v.sys
  1403. Image name: nvvad64v.sys
  1404. Search : https://www.google.com/search?q=nvvad64v.sys
  1405. ADA Info : Nvidia Virtual Audio driver http://www.nvidia.com/
  1406. Timestamp : Thu Mar 14 2019
  1407.  
  1408. Image path: \SystemRoot\system32\drivers\RTKVHD64.sys
  1409. Image name: RTKVHD64.sys
  1410. Search : https://www.google.com/search?q=RTKVHD64.sys
  1411. ADA Info : Realtek Audio System driver https://www.realtek.com/en/
  1412. Timestamp : Tue May 14 2019
  1413.  
  1414. Image path: \SystemRoot\System32\drivers\rt640x64.sys
  1415. Image name: rt640x64.sys
  1416. Search : https://www.google.com/search?q=rt640x64.sys
  1417. ADA Info : Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
  1418. Timestamp : Mon Jul 1 2019
  1419.  
  1420. Image path: \??\C:\WINDOWS\system32\drivers\semav6msr64.sys
  1421. Image name: semav6msr64.sys
  1422. Search : https://www.google.com/search?q=semav6msr64.sys
  1423. ADA Info : Intel Driver Update Utility http://www.intel.com/ OR (SEMA Software) http://www.sema-soft.de/en/home/
  1424. Timestamp : Thu Jul 18 2019
  1425.  
  1426. Image path: \SystemRoot\System32\drivers\NvModuleTracker.sys
  1427. Image name: NvModuleTracker.sys
  1428. Search : https://www.google.com/search?q=NvModuleTracker.sys
  1429. ADA Info : NVIDIA Module Tracker driver
  1430. Timestamp : Fri Nov 29 2019
  1431.  
  1432. Image path: \SystemRoot\System32\drivers\nvvhci.sys
  1433. Image name: nvvhci.sys
  1434. Search : https://www.google.com/search?q=nvvhci.sys
  1435. ADA Info : Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
  1436. Timestamp : Fri Jan 10 2020
  1437.  
  1438. Image path: \SystemRoot\System32\DriverStore\FileRepository\nvppc.inf_amd64_0f22333f160a8f42\UcmCxUcsiNvppc.sys
  1439. Image name: UcmCxUcsiNvppc.sys
  1440. Search : https://www.google.com/search?q=UcmCxUcsiNvppc.sys
  1441. ADA Info : NVIDIA USB Type-C Port Policy Controller driver
  1442. Timestamp : Sun Jan 26 2020
  1443.  
  1444. Image path: \SystemRoot\system32\drivers\nvhda64v.sys
  1445. Image name: nvhda64v.sys
  1446. Search : https://www.google.com/search?q=nvhda64v.sys
  1447. ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
  1448. Timestamp : Tue Jun 9 2020
  1449.  
  1450. Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_edab19158bdd0d0a\nvlddmkm.sys
  1451. Image name: nvlddmkm.sys
  1452. Search : https://www.google.com/search?q=nvlddmkm.sys
  1453. ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
  1454. Timestamp : Sun Jul 5 2020
  1455.  
  1456. ====================== Dump #3: MICROSOFT DRIVERS ======================
  1457.  
  1458. ACPI.sys ACPI Driver for NT (Microsoft)
  1459. acpiex.sys ACPIEx Driver (Microsoft)
  1460. acpipagr.sys ACPI Processor Aggregator Device driver (Microsoft)
  1461. afd.sys Ancillary Function Driver for WinSock (Microsoft)
  1462. afunix.sys AF_UNIX Socket Provider driver (Microsoft)
  1463. AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
  1464. ahcache.sys Application Compatibility Cache (Microsoft)
  1465. bam.sys BAM Kernal driver (Microsoft)
  1466. BasicDisplay.sys Basic Display driver (Microsoft)
  1467. BasicRender.sys Basic Render driver (Microsoft)
  1468. Beep.SYS BEEP driver (Microsoft)
  1469. bindflt.sys Windows Bind Filter driver (Microsoft)
  1470. BOOTVID.dll VGA Boot Driver (Microsoft)
  1471. bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
  1472. cdd.dll Canonical Display Driver (Microsoft)
  1473. cdrom.sys SCSI CD-ROM Driver (Microsoft)
  1474. CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
  1475. CI.dll Code Integrity Module (Microsoft)
  1476. CimFS.SYS Consumer IR Class Driver for eHome (Microsoft)
  1477. CLASSPNP.SYS SCSI Class System Dll (Microsoft)
  1478. cldflt.sys Cloud Files Mini Filter driver (Microsoft)
  1479. CLFS.SYS Common Log File System Driver (Microsoft)
  1480. clipsp.sys CLIP Service (Microsoft)
  1481. cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
  1482. cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
  1483. CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
  1484. condrv.sys Console Driver (Microsoft)
  1485. crashdmp.sys Crash Dump driver (Microsoft)
  1486. csc.sys Windows Client Side Caching driver (Microsoft)
  1487. dfsc.sys DFS Namespace Client Driver (Microsoft)
  1488. disk.sys PnP Disk Driver (Microsoft)
  1489. drmk.sys Digital Rights Management (DRM) driver (Microsoft)
  1490. dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  1491. dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  1492. dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  1493. dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
  1494. dxgmms2.sys DirectX Graphics MMS
  1495. EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
  1496. fastfat.SYS Fast FAT File System Driver (Microsoft)
  1497. filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
  1498. fileinfo.sys FileInfo Filter Driver (Microsoft)
  1499. FLTMGR.SYS Filesystem Filter Manager (Microsoft)
  1500. Fs_Rec.sys File System Recognizer Driver (Microsoft)
  1501. fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
  1502. fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
  1503. gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
  1504. hal.dll Hardware Abstraction Layer DLL (Microsoft)
  1505. HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
  1506. HIDCLASS.SYS Hid Class Library (Microsoft)
  1507. HIDPARSE.SYS Hid Parsing Library (Microsoft)
  1508. hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
  1509. HTTP.sys HTTP Protocol Stack (Microsoft)
  1510. intelpep.sys Intel Power Engine Plugin (Microsoft)
  1511. intelppm.sys Processor Device Driver (Microsoft)
  1512. IntelTA.sys Intel Telemetry Driver
  1513. iorate.sys I/O rate control Filter (Microsoft)
  1514. kbdclass.sys Keyboard Class Driver (Microsoft)
  1515. kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
  1516. kd.dll Local Kernal Debugger (Microsoft)
  1517. kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
  1518. ks.sys Kernal CSA Library (Microsoft)
  1519. ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
  1520. ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
  1521. ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
  1522. lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
  1523. luafv.sys LUA File Virtualization Filter Driver (Microsoft)
  1524. mcupdate_GenuineIntel.dll Intel Microcode Update Library (Microsoft)
  1525. mmcss.sys MMCSS Driver (Microsoft)
  1526. monitor.sys Monitor Driver (Microsoft)
  1527. mouclass.sys Mouse Class Driver (Microsoft)
  1528. mouhid.sys HID Mouse Filter Driver (Microsoft)
  1529. mountmgr.sys Mount Point Manager (Microsoft)
  1530. mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
  1531. mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
  1532. mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
  1533. Msfs.SYS Mailslot driver (Microsoft)
  1534. msgpioclx.sys GPIO Class Extension Driver (Microsoft)
  1535. msisadrv.sys ISA Driver (Microsoft)
  1536. mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
  1537. msquic.sys Windows QUIC Driver
  1538. msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
  1539. mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
  1540. mssmbios.sys System Management BIOS driver (Microsoft)
  1541. mup.sys Multiple UNC Provider driver (Microsoft)
  1542. ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
  1543. ndiscap.sys Microsoft NDIS Packet Capture Filter Driver
  1544. ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
  1545. ndisuio.sys NDIS User mode I/O driver (Microsoft)
  1546. NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
  1547. ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
  1548. NDProxy.sys NDIS Proxy driver (Microsoft)
  1549. Ndu.sys Network Data Usage Monitoring driver (Microsoft)
  1550. netbios.sys NetBIOS Interface driver (Microsoft)
  1551. netbt.sys MBT Transport driver (Microsoft)
  1552. NETIO.SYS Network I/O Subsystem (Microsoft)
  1553. Npfs.SYS NPFS driver (Microsoft)
  1554. npsvctrig.sys Named pipe service triggers (Microsoft)
  1555. nsiproxy.sys NSI Proxy driver (Microsoft)
  1556. Ntfs.sys NT File System Driver (Microsoft)
  1557. ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
  1558. ntosext.sys NTOS Extension Host driver (Microsoft)
  1559. Null.SYS NULL Driver (Microsoft)
  1560. nwifi.sys NativeWiFi Miniport Driver (Microsoft)
  1561. pacer.sys QoS Packet Scheduler (Microsoft)
  1562. partmgr.sys Partition driver (Microsoft)
  1563. pci.sys NT Plug and Play PCI Enumerator (Microsoft)
  1564. pcw.sys Performance Counter Driver (Microsoft)
  1565. pdc.sys Power Dependency Coordinator Driver (Microsoft)
  1566. peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
  1567. portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
  1568. PSHED.dll Platform Specific Hardware Error driver (Microsoft)
  1569. qwavedrv.sys Quality Windows Audio Video Experience (qWave) Support driver (Microsoft)
  1570. rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
  1571. raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
  1572. raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
  1573. rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
  1574. rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
  1575. rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
  1576. rdyboost.sys ReadyBoost Driver (Microsoft)
  1577. rspndr.sys Link-Layer Topology Responder driver (Microsoft)
  1578. SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
  1579. SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
  1580. spaceport.sys Storage Spaces driver (Microsoft)
  1581. srv2.sys Smb 2.0 Server driver (Microsoft)
  1582. srvnet.sys Server Network driver (Microsoft)
  1583. storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
  1584. storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
  1585. storqosflt.sys Storage QoS Filter driver (Microsoft)
  1586. swenum.sys Plug and Play Software Device Enumerator (Microsoft)
  1587. tbs.sys Export driver for kernel mode TPM API (Microsoft)
  1588. tcpip.sys TCP/IP Protocol driver (Microsoft)
  1589. tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
  1590. TDI.SYS TDI Wrapper driver (Microsoft)
  1591. tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
  1592. tm.sys Kernel Transaction Manager driver (Microsoft)
  1593. UcmCx.sys USB Connector Manager KMDF Class Extension
  1594. ucx01000.sys USB Controller Extension (Microsoft)
  1595. UEFI.sys UEFI NT driver (Microsoft)
  1596. umbus.sys User-Mode Bus Enumerator (Microsoft)
  1597. usbaudio.sys USB Audio Class Driver (Microsoft)
  1598. usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
  1599. USBD.SYS Universal Serial Bus Driver (Microsoft)
  1600. UsbHub3.sys USB3 HUB driver (Microsoft)
  1601. usbvideo.sys USB Video Class Driver (Microsoft)
  1602. USBXHCI.SYS USB XHCI driver (Microsoft)
  1603. vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
  1604. Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
  1605. volmgr.sys Volume Manager Driver (Microsoft)
  1606. volmgrx.sys Volume Manager Extension Driver (Microsoft)
  1607. volsnap.sys Volume Shadow Copy driver (Microsoft)
  1608. volume.sys Volume driver (Microsoft)
  1609. vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
  1610. wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
  1611. watchdog.sys Watchdog driver (Microsoft)
  1612. wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
  1613. Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
  1614. WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
  1615. WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
  1616. WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
  1617. werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
  1618. wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
  1619. win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
  1620. win32kbase.sys Base Win32k Kernel Driver (Microsoft)
  1621. win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
  1622. WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
  1623. WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
  1624. winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
  1625. wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
  1626. WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
  1627. Wof.sys Windows Overlay Filter (Microsoft)
  1628. WppRecorder.sys WPP Trace Recorder (Microsoft)
  1629.  
  1630. ====================== Dump #3: UNLOADED MODULES =======================
  1631.  
  1632. fffff803`84b60000 fffff803`84b71000 MSKSSRV.sys
  1633. fffff803`841a0000 fffff803`841b1000 MSKSSRV.sys
  1634. fffff803`84be0000 fffff803`84bef000 hiber_storpo
  1635. fffff803`6f5d0000 fffff803`6f603000 hiber_storah
  1636. fffff803`6f610000 fffff803`6f62e000 hiber_dumpfv
  1637. fffff803`84bb0000 fffff803`84bbc000 bertreader.s
  1638. fffff803`84b60000 fffff803`84b71000 MSKSSRV.sys
  1639. fffff803`841a0000 fffff803`841b1000 MSKSSRV.sys
  1640. fffff803`83ea0000 fffff803`83eaf000 dump_storpor
  1641. fffff803`83ef0000 fffff803`83f23000 dump_storahc
  1642. fffff803`83f50000 fffff803`83f6e000 dump_dumpfve
  1643. fffff803`86630000 fffff803`8663c000 WdmCompanion
  1644. fffff803`837f0000 fffff803`8380c000 dam.sys
  1645. fffff803`83400000 fffff803`83919000 vgk.sys
  1646. fffff803`70250000 fffff803`70261000 WdBoot.sys
  1647. fffff803`712d0000 fffff803`712e0000 hwpolicy.sys
  1648.  
  1649. ====================== Dump #3: BIOS INFORMATION =======================
  1650.  
  1651. [SMBIOS Data Tables v3.1]
  1652. [DMI Version - 0]
  1653. [2.0 Calling Convention - No]
  1654. [Table Size - 4459 bytes]
  1655. [BIOS Information (Type 0) - Length 26 - Handle 0000h]
  1656. Vendor American Megatrends Inc.
  1657. BIOS Version F2
  1658. BIOS Starting Address Segment f000
  1659. BIOS Release Date 04/19/2018
  1660. BIOS ROM Size 1000000
  1661. BIOS Characteristics
  1662. 07: - PCI Supported
  1663. 11: - Upgradeable FLASH BIOS
  1664. 12: - BIOS Shadowing Supported
  1665. 15: - CD-Boot Supported
  1666. 16: - Selectable Boot Supported
  1667. 17: - BIOS ROM Socketed
  1668. 19: - EDD Supported
  1669. 23: - 1.2MB Floppy Supported
  1670. 24: - 720KB Floppy Supported
  1671. 25: - 2.88MB Floppy Supported
  1672. 26: - Print Screen Device Supported
  1673. 28: - Serial Services Supported
  1674. 29: - Printer Services Supported
  1675. 32: - BIOS Vendor Reserved
  1676. BIOS Characteristic Extensions
  1677. 00: - ACPI Supported
  1678. 01: - USB Legacy Supported
  1679. 08: - BIOS Boot Specification Supported
  1680. 10: - Specification Reserved
  1681. 11: - Specification Reserved
  1682. BIOS Major Revision 5
  1683. BIOS Minor Revision 13
  1684. EC Firmware Major Revision 255
  1685. EC Firmware Minor Revision 255
  1686. [System Information (Type 1) - Length 27 - Handle 0001h]
  1687. Manufacturer Gigabyte Technology Co., Ltd.
  1688. Product Name H310M H
  1689. Version Default string
  1690. UUID 00000000-0000-0000-0000-000000000000
  1691. Wakeup Type Power Switch
  1692. SKUNumber Default string
  1693. Family Default string
  1694. [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
  1695. Manufacturer Gigabyte Technology Co., Ltd.
  1696. Product H310M H
  1697. Version x.x
  1698. Feature Flags 09h
  1699. -1364281632: - -1364281584: - «áêù
  1700. Location Default string
  1701. Chassis Handle 0003h
  1702. Board Type 0ah - Processor/Memory Module
  1703. Number of Child Handles 0
  1704. [System Enclosure (Type 3) - Length 22 - Handle 0003h]
  1705. Manufacturer Default string
  1706. Chassis Type Desktop
  1707. Version Default string
  1708. Bootup State Safe
  1709. Power Supply State Safe
  1710. Thermal State Safe
  1711. Security Status None
  1712. OEM Defined 0
  1713. Height 0U
  1714. Number of Power Cords 1
  1715. Number of Contained Elements 0
  1716. Contained Element Size 3
  1717. [Onboard Devices Information (Type 10) - Length 6 - Handle 0021h]
  1718. Number of Devices 1
  1719. 01: Type Video [enabled]
  1720. [OEM Strings (Type 11) - Length 5 - Handle 0022h]
  1721. Number of Strings 1
  1722. 1 Default string
  1723. [System Configuration Options (Type 12) - Length 5 - Handle 0023h]
  1724. [Physical Memory Array (Type 16) - Length 23 - Handle 003ah]
  1725. Location 03h - SystemBoard/Motherboard
  1726. Use 03h - System Memory
  1727. Memory Error Correction 03h - None
  1728. Maximum Capacity 33554432KB
  1729. Number of Memory Devices 4
  1730. [Memory Device (Type 17) - Length 40 - Handle 003bh]
  1731. Physical Memory Array Handle 003ah
  1732. Total Width 64 bits
  1733. Data Width 64 bits
  1734. Size 8192MB
  1735. Form Factor 09h - DIMM
  1736. Device Locator ChannelA-DIMM0
  1737. Bank Locator BANK 0
  1738. Memory Type 1ah - Specification Reserved
  1739. Type Detail 0080h - Synchronous
  1740. Speed 2133MHz
  1741. Manufacturer 029E
  1742. Part Number CMK16GX4M2B3200C16
  1743. [Memory Device (Type 17) - Length 40 - Handle 003ch]
  1744. Physical Memory Array Handle 003ah
  1745. Total Width 0 bits
  1746. Data Width 0 bits
  1747. Form Factor 02h - Unknown
  1748. Device Locator ChannelA-DIMM1
  1749. Bank Locator BANK 1
  1750. Memory Type 02h - Unknown
  1751. Type Detail 0000h -
  1752. Speed 0MHz
  1753. [Memory Device (Type 17) - Length 40 - Handle 003dh]
  1754. Physical Memory Array Handle 003ah
  1755. Total Width 64 bits
  1756. Data Width 64 bits
  1757. Size 8192MB
  1758. Form Factor 09h - DIMM
  1759. Device Locator ChannelB-DIMM0
  1760. Bank Locator BANK 2
  1761. Memory Type 1ah - Specification Reserved
  1762. Type Detail 0080h - Synchronous
  1763. Speed 2133MHz
  1764. Manufacturer 029E
  1765. Part Number CMK16GX4M2B3200C16
  1766. [Memory Device (Type 17) - Length 40 - Handle 003eh]
  1767. Physical Memory Array Handle 003ah
  1768. Total Width 0 bits
  1769. Data Width 0 bits
  1770. Form Factor 02h - Unknown
  1771. Device Locator ChannelB-DIMM1
  1772. Bank Locator BANK 3
  1773. Memory Type 02h - Unknown
  1774. Type Detail 0000h -
  1775. Speed 0MHz
  1776. [Memory Array Mapped Address (Type 19) - Length 31 - Handle 003fh]
  1777. Starting Address 00000000h
  1778. Ending Address 00ffffffh
  1779. Memory Array Handle 003ah
  1780. Partition Width 02
  1781. [Cache Information (Type 7) - Length 19 - Handle 0044h]
  1782. Socket Designation L1 Cache
  1783. Cache Configuration 0180h - WB Enabled Int NonSocketed L1
  1784. Maximum Cache Size 0180h - 384K
  1785. Installed Size 0180h - 384K
  1786. Supported SRAM Type 0020h - Synchronous
  1787. Current SRAM Type 0020h - Synchronous
  1788. Cache Speed 0ns
  1789. Error Correction Type ParitySingle-Bit ECC
  1790. System Cache Type Unified
  1791. Associativity 8-way Set-Associative
  1792. [Cache Information (Type 7) - Length 19 - Handle 0045h]
  1793. Socket Designation L2 Cache
  1794. Cache Configuration 0181h - WB Enabled Int NonSocketed L2
  1795. Maximum Cache Size 0600h - 1536K
  1796. Installed Size 0600h - 1536K
  1797. Supported SRAM Type 0020h - Synchronous
  1798. Current SRAM Type 0020h - Synchronous
  1799. Cache Speed 0ns
  1800. Error Correction Type Multi-Bit ECC
  1801. System Cache Type Unified
  1802. Associativity 4-way Set-Associative
  1803. [Cache Information (Type 7) - Length 19 - Handle 0046h]
  1804. Socket Designation L3 Cache
  1805. Cache Configuration 0182h - WB Enabled Int NonSocketed L3
  1806. Maximum Cache Size 3000h - 12288K
  1807. Installed Size 3000h - 12288K
  1808. Supported SRAM Type 0020h - Synchronous
  1809. Current SRAM Type 0020h - Synchronous
  1810. Cache Speed 0ns
  1811. Error Correction Type Specification Reserved
  1812. System Cache Type Unified
  1813. Associativity 16-way Set-Associative
  1814. [Processor Information (Type 4) - Length 48 - Handle 0047h]
  1815. Socket Designation U3E1
  1816. Processor Type Central Processor
  1817. Processor Family c6h - Specification Reserved
  1818. Processor Manufacturer Intel(R) Corporation
  1819. Processor ID ea060900fffbebbf
  1820. Processor Version Intel(R) Core(TM) i7-8700 CPU @ 3.20GHz
  1821. Processor Voltage 89h - 0.9V
  1822. External Clock 100MHz
  1823. Max Speed 8300MHz
  1824. Current Speed 3200MHz
  1825. Status Enabled Populated
  1826. Processor Upgrade Other
  1827. L1 Cache Handle 0044h
  1828. L2 Cache Handle 0045h
  1829. L3 Cache Handle 0046h
  1830. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0048h]
  1831. Starting Address 00000000h
  1832. Ending Address 007fffffh
  1833. Memory Device Handle 003bh
  1834. Mem Array Mapped Adr Handle 003fh
  1835. Interleave Position 01
  1836. Interleave Data Depth 02
  1837. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0049h]
  1838. Starting Address 00800000h
  1839. Ending Address 00ffffffh
  1840. Memory Device Handle 003dh
  1841. Mem Array Mapped Adr Handle 003fh
  1842. Interleave Position 02
  1843. Interleave Data Depth 02
  1844.  
  1845. ========================== Dump #3: Extra #1 ===========================
  1846.  
  1847. 10: kd> !verifier
  1848. Verify Flags Level 0x00000000
  1849. STANDARD FLAGS:
  1850. [X] (0x00000000) Automatic Checks
  1851. [ ] (0x00000001) Special pool
  1852. [ ] (0x00000002) Force IRQL checking
  1853. [ ] (0x00000008) Pool tracking
  1854. [ ] (0x00000010) I/O verification
  1855. [ ] (0x00000020) Deadlock detection
  1856. [ ] (0x00000080) DMA checking
  1857. [ ] (0x00000100) Security checks
  1858. [ ] (0x00000800) Miscellaneous checks
  1859. [ ] (0x00020000) DDI compliance checking
  1860. ADDITIONAL FLAGS:
  1861. [ ] (0x00000004) Randomized low resources simulation
  1862. [ ] (0x00000200) Force pending I/O requests
  1863. [ ] (0x00000400) IRP logging
  1864. [ ] (0x00002000) Invariant MDL checking for stack
  1865. [ ] (0x00004000) Invariant MDL checking for driver
  1866. [ ] (0x00008000) Power framework delay fuzzing
  1867. [ ] (0x00010000) Port/miniport interface checking
  1868. [ ] (0x00040000) Systematic low resources simulation
  1869. [ ] (0x00080000) DDI compliance checking (additional)
  1870. [ ] (0x00200000) NDIS/WIFI verification
  1871. [ ] (0x00800000) Kernel synchronization delay fuzzing
  1872. [ ] (0x01000000) VM switch verification
  1873. [ ] (0x02000000) Code integrity checks
  1874. [X] Indicates flag is enabled
  1875. Summary of All Verifier Statistics
  1876. RaiseIrqls 0x0
  1877. AcquireSpinLocks 0x0
  1878. Synch Executions 0x0
  1879. Trims 0x0
  1880. Pool Allocations Attempted 0x0
  1881. Pool Allocations Succeeded 0x0
  1882. Pool Allocations Succeeded SpecialPool 0x0
  1883. Pool Allocations With NO TAG 0x0
  1884. Pool Allocations Failed 0x0
  1885. Current paged pool allocations 0x0 for 00000000 bytes
  1886. Peak paged pool allocations 0x0 for 00000000 bytes
  1887. Current nonpaged pool allocations 0x0 for 00000000 bytes
  1888. Peak nonpaged pool allocations 0x0 for 00000000 bytes
  1889.  
  1890. ========================== Dump #3: Extra #2 ===========================
  1891.  
  1892. 10: kd> !thread
  1893. THREAD ffffe0803afcb340 Cid 0000.0000 Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor a
  1894. Not impersonating
  1895. GetUlongFromAddress: unable to read from fffff8036c21143c
  1896. Owning Process fffff8036c323a00 Image: System Process
  1897. Attached Process ffffab87204b6040 Image: System
  1898. fffff78000000000: Unable to get shared data
  1899. Wait Start TickCount 665298
  1900. Context Switch Count 14867719 IdealProcessor: 10
  1901. ReadMemory error: Cannot get nt!KeMaximumIncrement value.
  1902. UserTime 00:00:00.000
  1903. KernelTime 00:00:00.000
  1904. Win32 Start Address nt!KiIdleLoop (0xfffff8036b9e1630)
  1905. Stack Init ffff84023a8bfb90 Current ffff84023a8bfb20
  1906. Base ffff84023a8c0000 Limit ffff84023a8b9000 Call 0000000000000000
  1907. Priority 0 BasePriority 0 PriorityDecrement 0 IoPriority 0 PagePriority 0
  1908. Child-SP RetAddr : Args to Child : Call Site
  1909. ffffe080`3afd98e8 fffff803`6ba2eef1 : 00000000`0000001e ffffffff`c000001d fffff803`6b902db4 ffffe080`3afcb340 : nt!KeBugCheckEx
  1910. ffffe080`3afd98f0 fffff803`6b9de9f2 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDispatchException+0x1b3e31
  1911. ffffe080`3afd9fb0 fffff803`6b9de9c0 : fffff803`6b9efb65 00000000`00000000 00000000`00000000 ffffab87`29c5a040 : nt!KxExceptionDispatchOnExceptionStack+0x12 (TrapFrame @ ffffe080`3afd9e70)
  1912. ffff8402`3a8bf738 fffff803`6b9efb65 : 00000000`00000000 00000000`00000000 ffffab87`29c5a040 fffff803`6b83a810 : nt!KiExceptionDispatchOnExceptionStackContinue
  1913. ffff8402`3a8bf740 fffff803`6b9ea0a9 : 00000000`00000000 00000018`34148f00 ffffe080`3afc0180 00000008`00000001 : nt!KiExceptionDispatch+0x125
  1914. ffff8402`3a8bf920 fffff803`6b902db4 : 00000000`00000000 00000000`00000001 ffffe080`3afc0180 ffffe080`3afc0180 : nt!KiInvalidOpcodeFault+0x329 (TrapFrame @ ffff8402`3a8bf920)
  1915. ffff8402`3a8bfab0 00000000`00000000 : 00000000`00000000 00000000`000006e5 ffffab87`2cd93080 ffffe080`3afcb340 : nt!MiUnlockPageTableInternal+0x194
  1916.  
  1917.  
  1918. ========================================================================
  1919. ======================= Dump #4: ANALYZE VERBOSE =======================
  1920. ====================== File: 072720-13453-01.dmp =======================
  1921. ========================================================================
  1922.  
  1923. Mini Kernel Dump File: Only registers and stack trace are available
  1924. Windows 10 Kernel Version 19041 MP (12 procs) Free x64
  1925. Kernel base = 0xfffff804`2a20a000 PsLoadedModuleList = 0xfffff804`2ae34310
  1926. Debug session time: Mon Jul 27 07:36:43.422 2020 (UTC - 4:00)
  1927. System Uptime: 0 days 0:00:14.156
  1928.  
  1929. BugCheck C4, {62, ffffd8087653cf98, ffffd8087d8fa690, 1}
  1930. *** ERROR: Module load completed but symbols could not be loaded for vgk.sys
  1931. Probably caused by : memory_corruption
  1932. Followup: memory_corruption
  1933.  
  1934. DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
  1935. A device driver attempting to corrupt the system has been caught. This is
  1936. because the driver was specified in the registry as being suspect (by the
  1937. administrator) and the kernel has enabled substantial checking of this driver.
  1938. If the driver attempts to corrupt the system, bugchecks 0xC4, 0xC1 and 0xA will
  1939. be among the most commonly seen crashes.
  1940.  
  1941. Arguments:
  1942. Arg1: 0000000000000062, A driver has forgotten to free its pool allocations prior to unloading.
  1943. Arg2: ffffd8087653cf98, name of the driver having the issue.
  1944. Arg3: ffffd8087d8fa690, verifier internal structure with driver information.
  1945. Arg4: 0000000000000001, total # of (paged+nonpaged) allocations that weren't freed.
  1946. Type !verifier 3 drivername.sys for info on the allocations
  1947. that were leaked that caused the bugcheck.
  1948.  
  1949. Debugging Details:
  1950. DUMP_CLASS: 1
  1951. DUMP_QUALIFIER: 400
  1952. DUMP_TYPE: 2
  1953. BUGCHECK_STR: 0xc4_62
  1954. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  1955. FAULTING_MODULE: fffff80b1fd70000 vgk
  1956. VERIFIER_DRIVER_ENTRY: dt nt!_MI_VERIFIER_DRIVER_ENTRY ffffd8087d8fa690
  1957. Symbol nt!_MI_VERIFIER_DRIVER_ENTRY not found.
  1958. CUSTOMER_CRASH_COUNT: 1
  1959. DEFAULT_BUCKET_ID: CODE_CORRUPTION
  1960.  
  1961. PROCESS_NAME: System
  1962.  
  1963. CURRENT_IRQL: 2
  1964. LAST_CONTROL_TRANSFER: from fffff8042abe8e34 to fffff8042a5e7b60
  1965. STACK_TEXT:
  1966. ffffba06`37807418 fffff804`2abe8e34 : 00000000`000000c4 00000000`00000062 ffffd808`7653cf98 ffffd808`7d8fa690 : nt!KeBugCheckEx
  1967. ffffba06`37807420 fffff804`2abf8119 : ffffd808`7d8fa690 ffffba06`37807510 ffffd808`7653cdb0 ffffd808`7d8dfbe0 : nt!VerifierBugCheckIfAppropriate+0xe0
  1968. ffffba06`37807460 fffff804`2a69df0e : ffffd808`7d8fa690 ffffd808`7653ce50 00000000`00000001 ffffd808`7d8dfbc0 : nt!VfPoolCheckForLeaks+0x49
  1969. ffffba06`378074a0 fffff804`2abda502 : 00000000`00518000 ffffd808`7653cdb0 fffff804`2ae26d50 fffff804`2ae26d50 : nt!VfTargetDriversRemove+0x136222
  1970. ffffba06`37807520 fffff804`2a8e11f3 : ffffd808`7653cdb0 ffffba06`37807650 00000000`00000001 00000000`ffffffff : nt!VfDriverUnloadImage+0x3e
  1971. ffffba06`37807550 fffff804`2a96b6f1 : 00000000`00000000 00000000`ffffffff ffff99d7`00000001 ffffa989`efafd1c0 : nt!MiUnloadSystemImage+0x2eb
  1972. ffffba06`378076f0 fffff804`2a96b61e : ffffd808`765e17e0 ffffba06`37807940 00000000`00000000 00000000`00000000 : nt!MmUnloadSystemImage+0x41
  1973. ffffba06`37807720 fffff804`2a8164f0 : ffffd808`765e17e0 ffffba06`37807940 ffffd808`765e17e0 fffff804`2a7ea27f : nt!IopDeleteDriver+0x4e
  1974. ffffba06`37807770 fffff804`2a42eeb7 : 00000000`00000000 00000000`00000000 ffffba06`37807940 ffffd808`765e1810 : nt!ObpRemoveObjectRoutine+0x80
  1975. ffffba06`378077d0 fffff804`2a40b98e : 00000000`00000008 00000000`00000000 ffffd808`765e17e0 00000000`c0000365 : nt!ObfDereferenceObjectWithTag+0xc7
  1976. ffffba06`37807810 fffff804`2a934f5e : 00000000`00000008 00000000`00000008 00000000`c0000365 00000000`00001000 : nt!HalPutDmaAdapter+0xe
  1977. ffffba06`37807840 fffff804`2ac6eb8f : ffffd808`7d9ff370 ffffd808`7d9ff370 ffffba06`37807a80 00000000`00000000 : nt!IopLoadDriver+0x76a
  1978. ffffba06`37807a10 fffff804`2ac7dac2 : ffffffff`c0000365 ffffa989`efe30fc0 00000000`00000000 fffff804`28ac33e0 : nt!IopInitializeSystemDrivers+0x157
  1979. ffffba06`37807ab0 fffff804`2a9ad05b : fffff804`28ac33e0 fffff804`2ae50fe8 fffff804`2a9ad020 fffff804`28ac33e0 : nt!IoInitSystem+0x2e
  1980. ffffba06`37807ae0 fffff804`2a550735 : ffffd808`764d5040 fffff804`2a9ad020 fffff804`28ac33e0 00000000`00000000 : nt!Phase1Initialization+0x3b
  1981. ffffba06`37807b10 fffff804`2a5ef1b8 : fffff804`28e7e180 ffffd808`764d5040 fffff804`2a5506e0 00000000`00000000 : nt!PspSystemThreadStartup+0x55
  1982. ffffba06`37807b60 00000000`00000000 : ffffba06`37808000 ffffba06`37801000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
  1983. STACK_COMMAND: kb
  1984. CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
  1985. fffff8042a5507b5-fffff8042a5507b6 2 bytes - nt!MiDeleteNonPagedPoolTail+45
  1986. [ 80 fa:00 bb ]
  1987. 2 errors : !nt (fffff8042a5507b5-fffff8042a5507b6)
  1988. MODULE_NAME: memory_corruption
  1989.  
  1990. IMAGE_NAME: memory_corruption
  1991.  
  1992. FOLLOWUP_NAME: memory_corruption
  1993. MEMORY_CORRUPTOR: LARGE
  1994. FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
  1995. BUCKET_ID: MEMORY_CORRUPTION_LARGE
  1996. PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
  1997. TARGET_TIME: 2020-07-27T11:36:43.000Z
  1998. SUITE_MASK: 272
  1999. PRODUCT_TYPE: 1
  2000. USER_LCID: 0
  2001. FAILURE_ID_HASH_STRING: km:memory_corruption_large
  2002. FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
  2003. Followup: memory_corruption
  2004.  
  2005. ====================== Dump #4: 3RD PARTY DRIVERS ======================
  2006.  
  2007. Jun 29 2020 - vgk.sys - Vanguard Anti-Cheat driver
  2008.  
  2009. ================== Dump #4: 3RD PARTY DRIVERS (FULL) ===================
  2010.  
  2011. Image path: \??\C:\Program Files\Riot Vanguard\vgk.sys
  2012. Image name: vgk.sys
  2013. Search : https://www.google.com/search?q=vgk.sys
  2014. ADA Info : Vanguard Anti-Cheat driver
  2015. Timestamp : Mon Jun 29 2020
  2016.  
  2017. ====================== Dump #4: MICROSOFT DRIVERS ======================
  2018.  
  2019. ACPI.sys ACPI Driver for NT (Microsoft)
  2020. acpiex.sys ACPIEx Driver (Microsoft)
  2021. BOOTVID.dll VGA Boot Driver (Microsoft)
  2022. CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
  2023. CI.dll Code Integrity Module (Microsoft)
  2024. CLASSPNP.SYS SCSI Class System Dll (Microsoft)
  2025. CLFS.SYS Common Log File System Driver (Microsoft)
  2026. clipsp.sys CLIP Service (Microsoft)
  2027. cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
  2028. cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
  2029. crashdmp.sys Crash Dump driver (Microsoft)
  2030. disk.sys PnP Disk Driver (Microsoft)
  2031. dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  2032. dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  2033. dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  2034. EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
  2035. fileinfo.sys FileInfo Filter Driver (Microsoft)
  2036. FLTMGR.SYS Filesystem Filter Manager (Microsoft)
  2037. Fs_Rec.sys File System Recognizer Driver (Microsoft)
  2038. fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
  2039. fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
  2040. hal.dll Hardware Abstraction Layer DLL (Microsoft)
  2041. intelpep.sys Intel Power Engine Plugin (Microsoft)
  2042. IntelTA.sys Intel Telemetry Driver
  2043. iorate.sys I/O rate control Filter (Microsoft)
  2044. kd.dll Local Kernal Debugger (Microsoft)
  2045. ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
  2046. ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
  2047. mcupdate_GenuineIntel.dll Intel Microcode Update Library (Microsoft)
  2048. mountmgr.sys Mount Point Manager (Microsoft)
  2049. msisadrv.sys ISA Driver (Microsoft)
  2050. msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
  2051. mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
  2052. mup.sys Multiple UNC Provider driver (Microsoft)
  2053. ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
  2054. NETIO.SYS Network I/O Subsystem (Microsoft)
  2055. Ntfs.sys NT File System Driver (Microsoft)
  2056. ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
  2057. ntosext.sys NTOS Extension Host driver (Microsoft)
  2058. partmgr.sys Partition driver (Microsoft)
  2059. pci.sys NT Plug and Play PCI Enumerator (Microsoft)
  2060. pcw.sys Performance Counter Driver (Microsoft)
  2061. pdc.sys Power Dependency Coordinator Driver (Microsoft)
  2062. PSHED.dll Platform Specific Hardware Error driver (Microsoft)
  2063. rdyboost.sys ReadyBoost Driver (Microsoft)
  2064. SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
  2065. SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
  2066. spaceport.sys Storage Spaces driver (Microsoft)
  2067. storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
  2068. storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
  2069. tcpip.sys TCP/IP Protocol driver (Microsoft)
  2070. tm.sys Kernel Transaction Manager driver (Microsoft)
  2071. vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
  2072. VerifierExt.sys Driver Verifier Extension
  2073. volmgr.sys Volume Manager Driver (Microsoft)
  2074. volmgrx.sys Volume Manager Extension Driver (Microsoft)
  2075. volsnap.sys Volume Shadow Copy driver (Microsoft)
  2076. volume.sys Volume driver (Microsoft)
  2077. Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
  2078. WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
  2079. WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
  2080. werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
  2081. wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
  2082. WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
  2083. WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
  2084. WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
  2085. Wof.sys Windows Overlay Filter (Microsoft)
  2086. WppRecorder.sys WPP Trace Recorder (Microsoft)
  2087.  
  2088. ====================== Dump #4: UNLOADED MODULES =======================
  2089.  
  2090. fffff804`2bb00000 fffff804`2bb11000 WdBoot.sys
  2091. fffff804`2cb80000 fffff804`2cb90000 hwpolicy.sys
  2092.  
  2093. ====================== Dump #4: BIOS INFORMATION =======================
  2094.  
  2095. sysinfo: could not find necessary interfaces.
  2096. sysinfo: note that mssmbios.sys must be loaded (XPSP2+).
  2097.  
  2098. ========================== Dump #4: Extra #1 ===========================
  2099.  
  2100. 11: kd> !verifier
  2101. Verify Flags Level 0x001209bb
  2102. STANDARD FLAGS:
  2103. [X] (0x00000000) Automatic Checks
  2104. [X] (0x00000001) Special pool
  2105. [X] (0x00000002) Force IRQL checking
  2106. [X] (0x00000008) Pool tracking
  2107. [X] (0x00000010) I/O verification
  2108. [X] (0x00000020) Deadlock detection
  2109. [X] (0x00000080) DMA checking
  2110. [X] (0x00000100) Security checks
  2111. [X] (0x00000800) Miscellaneous checks
  2112. [X] (0x00020000) DDI compliance checking
  2113. ADDITIONAL FLAGS:
  2114. [ ] (0x00000004) Randomized low resources simulation
  2115. [ ] (0x00000200) Force pending I/O requests
  2116. [ ] (0x00000400) IRP logging
  2117. [ ] (0x00002000) Invariant MDL checking for stack
  2118. [ ] (0x00004000) Invariant MDL checking for driver
  2119. [ ] (0x00008000) Power framework delay fuzzing
  2120. [ ] (0x00010000) Port/miniport interface checking
  2121. [ ] (0x00040000) Systematic low resources simulation
  2122. [ ] (0x00080000) DDI compliance checking (additional)
  2123. [ ] (0x00200000) NDIS/WIFI verification
  2124. [ ] (0x00800000) Kernel synchronization delay fuzzing
  2125. [ ] (0x01000000) VM switch verification
  2126. [ ] (0x02000000) Code integrity checks
  2127. RESERVED FLAGS (use of these flags is unsupported):
  2128. [X] (0x00100000) Unused or reserved flag
  2129. [X] Indicates flag is enabled
  2130. Summary of All Verifier Statistics
  2131. RaiseIrqls 0x1565
  2132. AcquireSpinLocks 0x94d4
  2133. Synch Executions 0x0
  2134. Trims 0x966
  2135. Pool Allocations Attempted 0x119bb
  2136. Pool Allocations Succeeded 0x119bb
  2137. Pool Allocations Succeeded SpecialPool 0x119bb
  2138. Pool Allocations With NO TAG 0xa
  2139. Pool Allocations Failed 0x0
  2140. Current paged pool allocations 0x5bf for 0014315B bytes
  2141. Peak paged pool allocations 0x66a for 00164AA3 bytes
  2142. Current nonpaged pool allocations 0x1b3e for 00811696 bytes
  2143. Peak nonpaged pool allocations 0x1b4a for 00CEDD56 bytes
  2144.  
  2145. ========================== Dump #4: Extra #2 ===========================
  2146.  
  2147. 11: kd> !thread
  2148. THREAD ffffd808764d5040 Cid 0004.0008 Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor b
  2149. Not impersonating
  2150. GetUlongFromAddress: unable to read from fffff8042ae1b43c
  2151. Owning Process ffffd808764cf040 Image: System
  2152. Attached Process N/A Image: N/A
  2153. fffff78000000000: Unable to get shared data
  2154. Wait Start TickCount 905
  2155. Context Switch Count 2170 IdealProcessor: 0
  2156. ReadMemory error: Cannot get nt!KeMaximumIncrement value.
  2157. UserTime 00:00:00.000
  2158. KernelTime 00:00:00.000
  2159. Win32 Start Address nt!Phase1Initialization (0xfffff8042a9ad020)
  2160. Stack Init ffffba0637807b90 Current ffffba06378071c0
  2161. Base ffffba0637808000 Limit ffffba0637801000 Call 0000000000000000
  2162. Priority 31 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5
  2163. Child-SP RetAddr : Args to Child : Call Site
  2164. ffffba06`37807418 fffff804`2abe8e34 : 00000000`000000c4 00000000`00000062 ffffd808`7653cf98 ffffd808`7d8fa690 : nt!KeBugCheckEx
  2165. ffffba06`37807420 fffff804`2abf8119 : ffffd808`7d8fa690 ffffba06`37807510 ffffd808`7653cdb0 ffffd808`7d8dfbe0 : nt!VerifierBugCheckIfAppropriate+0xe0
  2166. ffffba06`37807460 fffff804`2a69df0e : ffffd808`7d8fa690 ffffd808`7653ce50 00000000`00000001 ffffd808`7d8dfbc0 : nt!VfPoolCheckForLeaks+0x49
  2167. ffffba06`378074a0 fffff804`2abda502 : 00000000`00518000 ffffd808`7653cdb0 fffff804`2ae26d50 fffff804`2ae26d50 : nt!VfTargetDriversRemove+0x136222
  2168. ffffba06`37807520 fffff804`2a8e11f3 : ffffd808`7653cdb0 ffffba06`37807650 00000000`00000001 00000000`ffffffff : nt!VfDriverUnloadImage+0x3e
  2169. ffffba06`37807550 fffff804`2a96b6f1 : 00000000`00000000 00000000`ffffffff ffff99d7`00000001 ffffa989`efafd1c0 : nt!MiUnloadSystemImage+0x2eb
  2170. ffffba06`378076f0 fffff804`2a96b61e : ffffd808`765e17e0 ffffba06`37807940 00000000`00000000 00000000`00000000 : nt!MmUnloadSystemImage+0x41
  2171. ffffba06`37807720 fffff804`2a8164f0 : ffffd808`765e17e0 ffffba06`37807940 ffffd808`765e17e0 fffff804`2a7ea27f : nt!IopDeleteDriver+0x4e
  2172. ffffba06`37807770 fffff804`2a42eeb7 : 00000000`00000000 00000000`00000000 ffffba06`37807940 ffffd808`765e1810 : nt!ObpRemoveObjectRoutine+0x80
  2173. ffffba06`378077d0 fffff804`2a40b98e : 00000000`00000008 00000000`00000000 ffffd808`765e17e0 00000000`c0000365 : nt!ObfDereferenceObjectWithTag+0xc7
  2174. ffffba06`37807810 fffff804`2a934f5e : 00000000`00000008 00000000`00000008 00000000`c0000365 00000000`00001000 : nt!HalPutDmaAdapter+0xe
  2175. ffffba06`37807840 fffff804`2ac6eb8f : ffffd808`7d9ff370 ffffd808`7d9ff370 ffffba06`37807a80 00000000`00000000 : nt!IopLoadDriver+0x76a
  2176. ffffba06`37807a10 fffff804`2ac7dac2 : ffffffff`c0000365 ffffa989`efe30fc0 00000000`00000000 fffff804`28ac33e0 : nt!IopInitializeSystemDrivers+0x157
  2177. ffffba06`37807ab0 fffff804`2a9ad05b : fffff804`28ac33e0 fffff804`2ae50fe8 fffff804`2a9ad020 fffff804`28ac33e0 : nt!IoInitSystem+0x2e
  2178. ffffba06`37807ae0 fffff804`2a550735 : ffffd808`764d5040 fffff804`2a9ad020 fffff804`28ac33e0 00000000`00000000 : nt!Phase1Initialization+0x3b
  2179. ffffba06`37807b10 fffff804`2a5ef1b8 : fffff804`28e7e180 ffffd808`764d5040 fffff804`2a5506e0 00000000`00000000 : nt!PspSystemThreadStartup+0x55
  2180. ffffba06`37807b60 00000000`00000000 : ffffba06`37808000 ffffba06`37801000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
Advertisement
Add Comment
Please, Sign In to add comment