Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ========================== AUTO DUMP ANALYZER ==========================
- Auto Dump Analyzer
- Version: 0.91
- Time to analyze file(s): 00 hours and 05 minutes and 19 seconds
- ================================ SYSTEM ================================
- MANUFACTURER: Gigabyte Technology Co., Ltd.
- PRODUCT_NAME: H310M H
- ================================= BIOS =================================
- VENDOR: American Megatrends Inc.
- VERSION: F2
- DATE: 04/19/2018
- ============================= MOTHERBOARD ==============================
- MANUFACTURER: Gigabyte Technology Co., Ltd.
- PRODUCT: H310M H
- VERSION: x.x
- ================================= RAM ==================================
- Size Speed Manufacturer Part No.
- -------------- -------------- ------------------- ----------------------
- 8192MB 2133MHz 029E CMK16GX4M2B3200C16
- 0MHz
- 8192MB 2133MHz 029E CMK16GX4M2B3200C16
- 0MHz
- ================================= CPU ==================================
- Processor Version: Intel(R) Core(TM) i7-8700 CPU @ 3.20GHz
- COUNT: c
- MHZ: 3192
- VENDOR: GenuineIntel
- FAMILY: 6
- MODEL: 9e
- STEPPING: a
- MICROCODE: 6,9e,a,0 (F,M,S,R) SIG: B4'00000000 (cache) B4'00000000 (init)
- ================================== OS ==================================
- Product: WinNt, suite: TerminalServer SingleUserTS
- Built by: 19041.1.amd64fre.vb_release.191206-1406
- BUILD_VERSION: 10.0.19041.423 (WinBuild.160101.0800)
- BUILD: 19041
- SERVICEPACK: 423
- PLATFORM_TYPE: x64
- NAME: Windows 10
- EDITION: Windows 10 WinNt TerminalServer SingleUserTS
- BUILD_TIMESTAMP: unknown_date
- BUILDDATESTAMP: 160101.0800
- BUILDLAB: WinBuild
- BUILDOSVER: 10.0.19041.423
- BUILD_VERSION: 10.0.19041.388 (WinBuild.160101.0800)
- SERVICEPACK: 388
- BUILDOSVER: 10.0.19041.388
- =============================== DEBUGGER ===============================
- Microsoft (R) Windows Debugger Version 10.0.14321.1024 AMD64
- Copyright (c) Microsoft Corporation. All rights reserved.
- =============================== COMMENTS ===============================
- * Information gathered from different dump files may be different. If
- Windows updates between two dump files, two or more OS versions may
- be shown above.
- * If the user updates the BIOS between dump files, two or more versions
- and dates may be shown above.
- * More RAM information can be found below in a full BIOS section.
- ========================================================================
- ======================= Dump #1: ANALYZE VERBOSE =======================
- ======================= File: 080320-9546-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 19041 MP (12 procs) Free x64
- Kernel base = 0xfffff804`73000000 PsLoadedModuleList = 0xfffff804`73c2a330
- Debug session time: Mon Aug 3 03:38:47.458 2020 (UTC - 4:00)
- System Uptime: 0 days 1:46:54.110
- BugCheck 101, {10, 0, ffffd7809f140180, a}
- Probably caused by : memory_corruption
- Followup: memory_corruption
- CLOCK_WATCHDOG_TIMEOUT (101)
- An expected clock interrupt was not received on a secondary processor in an
- MP system within the allocated interval. This indicates that the specified
- processor is hung and not processing interrupts.
- Arguments:
- Arg1: 0000000000000010, Clock interrupt time out interval in nominal clock ticks.
- Arg2: 0000000000000000, 0.
- Arg3: ffffd7809f140180, The PRCB address of the hung processor.
- Arg4: 000000000000000a, The index of the hung processor.
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- BUGCHECK_STR: CLOCK_WATCHDOG_TIMEOUT_c_PROC
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- PROCESS_NAME: RustClient.exe
- CURRENT_IRQL: d
- STACK_TEXT:
- ffffd780`9eda8c88 fffff804`7345952e : 00000000`00000101 00000000`00000010 00000000`00000000 ffffd780`9f140180 : nt!KeBugCheckEx
- ffffd780`9eda8c90 fffff804`732ce52d : 00000000`00000000 ffffd780`9ed8f180 00000000`00000246 00000000`00064387 : nt!KeAccumulateTicks+0x18cade
- ffffd780`9eda8cf0 fffff804`732c7c21 : 00000000`00064100 00000000`0003bbc6 ffffd780`9ed8f180 00000000`00000001 : nt!KiUpdateRunTime+0x5d
- ffffd780`9eda8d40 fffff804`732c9abb : 00000000`00000000 ffff9585`5a4ef200 fffff804`73c31998 00000000`00000000 : nt!KiUpdateTime+0x4a1
- ffffd780`9eda8e80 fffff804`732c6cf2 : ffff9585`5a4ef270 ffff9585`5a4ef2f0 ffff9585`5a4ef2f0 00000000`00000000 : nt!KeClockInterruptNotify+0x2bb
- ffffd780`9eda8f30 fffff804`73208725 : 0000000e`ef326711 ffffc78e`c2cd3720 ffffc78e`c2cd37d0 00000000`00000000 : nt!HalpTimerClockInterrupt+0xe2
- ffffd780`9eda8f60 fffff804`733df9ea : ffff9585`5a4ef2f0 ffffc78e`c2cd3720 00000000`00000001 10c08349`08583349 : nt!KiCallInterruptServiceRoutine+0xa5
- ffffd780`9eda8fb0 fffff804`733dff57 : 00000000`0fafec11 00000000`00000002 00000000`00000000 00000000`00000010 : nt!KiInterruptSubDispatchNoLockNoEtw+0xfa
- ffff9585`5a4ef270 fffff804`732c4700 : 00000000`00000000 ffffffff`ffffffff 00000000`00000002 ffffee00`0c6079e0 : nt!KiInterruptDispatchNoLockNoEtw+0x37
- ffff9585`5a4ef400 fffff804`732c0a52 : ffffc78e`00000001 00000000`00000000 00000000`00000000 ffffac01`48785018 : nt!KeFlushMultipleRangeTb+0x2a0
- ffff9585`5a4ef490 fffff804`732b410f : ffff9585`5a4ef5c0 85000004`2028a867 ffffac01`48785018 00000000`00000009 : nt!MiFlushTbList+0x82
- ffff9585`5a4ef4c0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MiCopyOnWrite+0x6df
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
- fffff8047323c4aa-fffff8047323c4ab 2 bytes - nt!MiInsertCachedPte+20a
- [ ff f6:7f ac ]
- fffff8047338516e-fffff80473385171 4 bytes - nt!MiFreeUltraMapping+32 (+0x148cc4)
- [ a0 7d fb f6:00 2b 56 ac ]
- 6 errors : !nt (fffff8047323c4aa-fffff80473385171)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-08-03T07:38:47.000Z
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #1: 3RD PARTY DRIVERS ======================
- Oct 15 2015 - rzendpt.sys - Razer RzEndPt driver https://www.razer.com/
- Oct 15 2015 - rzudd.sys - Razer Rzudd Engine Driver https://www.razer.com/
- May 04 2017 - ICCWDT.sys - Intel(R) Watchdog Timer driver
- Apr 11 2018 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Jan 11 2019 - iaLPSS2_GPIO2.sys - Intel(R) Serial IO GPIO driver
- Mar 14 2019 - nvvad64v.sys - Nvidia Virtual Audio driver http://www.nvidia.com/
- Apr 25 2019 - mbae64.sys - Malwarebytes driver https://www.malwarebytes.com/
- May 14 2019 - RTKVHD64.sys - Realtek Audio System driver https://www.realtek.com/en/
- Jul 01 2019 - rt640x64.sys - Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Jul 18 2019 - semav6msr64.sys - Intel Driver Update Utility http://www.intel.com/ OR (SEMA Software) http://www.sema-soft.de/en/home/
- Sep 19 2019 - RTCore64.sys - !!! Overclocking Software - RivaTuner - MSI Afterburner http://www.msi.com/ or EVGA Precision X http://www.evga.com/
- Nov 20 2019 - mbamswissarmy.sys - MalwareBytes Anti-Malware system driver https://www.malwarebytes.com/
- Nov 29 2019 - NvModuleTracker.sys - NVIDIA Module Tracker driver
- Jan 10 2020 - nvvhci.sys - Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Jan 26 2020 - UcmCxUcsiNvppc.sys - NVIDIA USB Type-C Port Policy Controller driver
- Jun 04 2020 - MbamChameleon.sys - Malwarebytes Anti-Malware Chameleon driver https://www.malwarebytes.com/
- Jun 09 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- Jun 22 2020 - mwac.sys - Malwarebytes Web Access Control http://www.malwarebytes.org/
- Jun 29 2020 - vgk.sys - Vanguard Anti-Cheat driver
- Jul 05 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- Jul 07 2020 - mbam.sys - Malwarebytes Anti-Malware https://www.malwarebytes.com/
- Jul 17 2020 - farflt.sys - Malwarebytes Anti-RansomWare SDK http://www.malwarebytes.org/
- Jul 23 2020 - EasyAntiCheat.sys - EasyAntiCheat is a anti-cheat driver (EasyAntiCheat Oy.) https://support.easyanticheat.net/
- ================== Dump #1: 3RD PARTY DRIVERS (FULL) ===================
- Image path: \SystemRoot\System32\drivers\rzendpt.sys
- Image name: rzendpt.sys
- Search : https://www.google.com/search?q=rzendpt.sys
- ADA Info : Razer RzEndPt driver https://www.razer.com/
- Timestamp : Thu Oct 15 2015
- Image path: \SystemRoot\System32\drivers\rzudd.sys
- Image name: rzudd.sys
- Search : https://www.google.com/search?q=rzudd.sys
- ADA Info : Razer Rzudd Engine Driver https://www.razer.com/
- Timestamp : Thu Oct 15 2015
- Image path: \SystemRoot\System32\drivers\ICCWDT.sys
- Image name: ICCWDT.sys
- Search : https://www.google.com/search?q=ICCWDT.sys
- ADA Info : Intel(R) Watchdog Timer driver
- Timestamp : Thu May 4 2017
- Image path: \SystemRoot\System32\drivers\TeeDriverW8x64.sys
- Image name: TeeDriverW8x64.sys
- Search : https://www.google.com/search?q=TeeDriverW8x64.sys
- ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Timestamp : Wed Apr 11 2018
- Image path: \SystemRoot\System32\drivers\iaLPSS2_GPIO2.sys
- Image name: iaLPSS2_GPIO2.sys
- Search : https://www.google.com/search?q=iaLPSS2_GPIO2.sys
- ADA Info : Intel(R) Serial IO GPIO driver
- Timestamp : Fri Jan 11 2019
- Image path: \SystemRoot\system32\drivers\nvvad64v.sys
- Image name: nvvad64v.sys
- Search : https://www.google.com/search?q=nvvad64v.sys
- ADA Info : Nvidia Virtual Audio driver http://www.nvidia.com/
- Timestamp : Thu Mar 14 2019
- Image path: \??\C:\WINDOWS\system32\drivers\mbae64.sys
- Image name: mbae64.sys
- Search : https://www.google.com/search?q=mbae64.sys
- ADA Info : Malwarebytes driver https://www.malwarebytes.com/
- Timestamp : Thu Apr 25 2019
- Image path: \SystemRoot\system32\drivers\RTKVHD64.sys
- Image name: RTKVHD64.sys
- Search : https://www.google.com/search?q=RTKVHD64.sys
- ADA Info : Realtek Audio System driver https://www.realtek.com/en/
- Timestamp : Tue May 14 2019
- Image path: \SystemRoot\System32\drivers\rt640x64.sys
- Image name: rt640x64.sys
- Search : https://www.google.com/search?q=rt640x64.sys
- ADA Info : Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Timestamp : Mon Jul 1 2019
- Image path: \??\C:\WINDOWS\system32\drivers\semav6msr64.sys
- Image name: semav6msr64.sys
- Search : https://www.google.com/search?q=semav6msr64.sys
- ADA Info : Intel Driver Update Utility http://www.intel.com/ OR (SEMA Software) http://www.sema-soft.de/en/home/
- Timestamp : Thu Jul 18 2019
- Image path: \??\C:\Program Files (x86)\MSI Afterburner\RTCore64.sys
- Image name: RTCore64.sys
- Search : https://www.google.com/search?q=RTCore64.sys
- ADA Info : !!! Overclocking Software - RivaTuner - MSI Afterburner http://www.msi.com/ or EVGA Precision X http://www.evga.com/
- Timestamp : Thu Sep 19 2019
- Image path: \SystemRoot\System32\Drivers\mbamswissarmy.sys
- Image name: mbamswissarmy.sys
- Search : https://www.google.com/search?q=mbamswissarmy.sys
- ADA Info : MalwareBytes Anti-Malware system driver https://www.malwarebytes.com/
- Timestamp : Wed Nov 20 2019
- Image path: \SystemRoot\System32\drivers\NvModuleTracker.sys
- Image name: NvModuleTracker.sys
- Search : https://www.google.com/search?q=NvModuleTracker.sys
- ADA Info : NVIDIA Module Tracker driver
- Timestamp : Fri Nov 29 2019
- Image path: \SystemRoot\System32\drivers\nvvhci.sys
- Image name: nvvhci.sys
- Search : https://www.google.com/search?q=nvvhci.sys
- ADA Info : Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Timestamp : Fri Jan 10 2020
- Image path: \SystemRoot\System32\DriverStore\FileRepository\nvppc.inf_amd64_0f22333f160a8f42\UcmCxUcsiNvppc.sys
- Image name: UcmCxUcsiNvppc.sys
- Search : https://www.google.com/search?q=UcmCxUcsiNvppc.sys
- ADA Info : NVIDIA USB Type-C Port Policy Controller driver
- Timestamp : Sun Jan 26 2020
- Image path: \SystemRoot\System32\Drivers\MbamChameleon.sys
- Image name: MbamChameleon.sys
- Search : https://www.google.com/search?q=MbamChameleon.sys
- ADA Info : Malwarebytes Anti-Malware Chameleon driver https://www.malwarebytes.com/
- Timestamp : Thu Jun 4 2020
- Image path: \SystemRoot\system32\drivers\nvhda64v.sys
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Tue Jun 9 2020
- Image path: \SystemRoot\system32\DRIVERS\mwac.sys
- Image name: mwac.sys
- Search : https://www.google.com/search?q=mwac.sys
- ADA Info : Malwarebytes Web Access Control http://www.malwarebytes.org/
- Timestamp : Mon Jun 22 2020
- Image path: \??\C:\Program Files\Riot Vanguard\vgk.sys
- Image name: vgk.sys
- Search : https://www.google.com/search?q=vgk.sys
- ADA Info : Vanguard Anti-Cheat driver
- Timestamp : Mon Jun 29 2020
- Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_edab19158bdd0d0a\nvlddmkm.sys
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Sun Jul 5 2020
- Image path: \??\C:\WINDOWS\system32\DRIVERS\mbam.sys
- Image name: mbam.sys
- Search : https://www.google.com/search?q=mbam.sys
- ADA Info : Malwarebytes Anti-Malware https://www.malwarebytes.com/
- Timestamp : Tue Jul 7 2020
- Image path: \SystemRoot\system32\DRIVERS\farflt.sys
- Image name: farflt.sys
- Search : https://www.google.com/search?q=farflt.sys
- ADA Info : Malwarebytes Anti-RansomWare SDK http://www.malwarebytes.org/
- Timestamp : Fri Jul 17 2020
- Image path: \??\C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.sys
- Image name: EasyAntiCheat.sys
- Search : https://www.google.com/search?q=EasyAntiCheat.sys
- ADA Info : EasyAntiCheat is a anti-cheat driver (EasyAntiCheat Oy.) https://support.easyanticheat.net/
- Timestamp : Thu Jul 23 2020
- ====================== Dump #1: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- acpipagr.sys ACPI Processor Aggregator Device driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CimFS.SYS Consumer IR Class Driver for eHome (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- csc.sys Windows Client Side Caching driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- intelppm.sys Processor Device Driver (Microsoft)
- IntelTA.sys Intel Telemetry Driver
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kd.dll Local Kernal Debugger (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate_GenuineIntel.dll Intel Microcode Update Library (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msgpioclx.sys GPIO Class Extension Driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msquic.sys Windows QUIC Driver
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndiscap.sys Microsoft NDIS Packet Capture Filter Driver
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- ndisuio.sys NDIS User mode I/O driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- nwifi.sys NativeWiFi Miniport Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- qwavedrv.sys Quality Windows Audio Video Experience (qWave) Support driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- UcmCx.sys USB Connector Manager KMDF Class Extension
- ucx01000.sys USB Controller Extension (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- ====================== Dump #1: UNLOADED MODULES =======================
- fffff804`8eea0000 fffff804`8eeac000 bertreader.s
- fffff804`8b4f0000 fffff804`8b4ff000 dump_storpor
- fffff804`8b540000 fffff804`8b573000 dump_storahc
- fffff804`8b5a0000 fffff804`8b5be000 dump_dumpfve
- fffff804`8c510000 fffff804`8c52c000 dam.sys
- fffff804`78050000 fffff804`78059000 MbamElam.sys
- fffff804`79050000 fffff804`79061000 hwpolicy.sys
- ====================== Dump #1: BIOS INFORMATION =======================
- sysinfo: could not find necessary interfaces.
- sysinfo: note that mssmbios.sys must be loaded (XPSP2+).
- ========================== Dump #1: Extra #1 ===========================
- 5: kd> !verifier
- Verify Flags Level 0x00000000
- STANDARD FLAGS:
- [X] (0x00000000) Automatic Checks
- [ ] (0x00000001) Special pool
- [ ] (0x00000002) Force IRQL checking
- [ ] (0x00000008) Pool tracking
- [ ] (0x00000010) I/O verification
- [ ] (0x00000020) Deadlock detection
- [ ] (0x00000080) DMA checking
- [ ] (0x00000100) Security checks
- [ ] (0x00000800) Miscellaneous checks
- [ ] (0x00020000) DDI compliance checking
- ADDITIONAL FLAGS:
- [ ] (0x00000004) Randomized low resources simulation
- [ ] (0x00000200) Force pending I/O requests
- [ ] (0x00000400) IRP logging
- [ ] (0x00002000) Invariant MDL checking for stack
- [ ] (0x00004000) Invariant MDL checking for driver
- [ ] (0x00008000) Power framework delay fuzzing
- [ ] (0x00010000) Port/miniport interface checking
- [ ] (0x00040000) Systematic low resources simulation
- [ ] (0x00080000) DDI compliance checking (additional)
- [ ] (0x00200000) NDIS/WIFI verification
- [ ] (0x00800000) Kernel synchronization delay fuzzing
- [ ] (0x01000000) VM switch verification
- [ ] (0x02000000) Code integrity checks
- [X] Indicates flag is enabled
- Summary of All Verifier Statistics
- RaiseIrqls 0x0
- AcquireSpinLocks 0x0
- Synch Executions 0x0
- Trims 0x0
- Pool Allocations Attempted 0x0
- Pool Allocations Succeeded 0x0
- Pool Allocations Succeeded SpecialPool 0x0
- Pool Allocations With NO TAG 0x0
- Pool Allocations Failed 0x0
- Current paged pool allocations 0x0 for 00000000 bytes
- Peak paged pool allocations 0x0 for 00000000 bytes
- Current nonpaged pool allocations 0x0 for 00000000 bytes
- Peak nonpaged pool allocations 0x0 for 00000000 bytes
- ========================== Dump #1: Extra #2 ===========================
- 5: kd> !thread
- THREAD ffffc78ece91a080 Cid 3a2c.0f10 Teb: 000000d11c858000 Win32Thread: 0000000000000000 RUNNING on processor 5
- Not impersonating
- GetUlongFromAddress: unable to read from fffff80473c1146c
- Owning Process ffffc78ecfc18340 Image: RustClient.exe
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 409885
- Context Switch Count 12707 IdealProcessor: 1
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address 0x00007ffce285d500
- Stack Init ffff95855a4efb90 Current ffff95855a4ef670
- Base ffff95855a4f0000 Limit ffff95855a4e9000 Call 0000000000000000
- Priority 12 BasePriority 8 PriorityDecrement 2 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- ffffd780`9eda8c88 fffff804`7345952e : 00000000`00000101 00000000`00000010 00000000`00000000 ffffd780`9f140180 : nt!KeBugCheckEx
- ffffd780`9eda8c90 fffff804`732ce52d : 00000000`00000000 ffffd780`9ed8f180 00000000`00000246 00000000`00064387 : nt!KeAccumulateTicks+0x18cade
- ffffd780`9eda8cf0 fffff804`732c7c21 : 00000000`00064100 00000000`0003bbc6 ffffd780`9ed8f180 00000000`00000001 : nt!KiUpdateRunTime+0x5d
- ffffd780`9eda8d40 fffff804`732c9abb : 00000000`00000000 ffff9585`5a4ef200 fffff804`73c31998 00000000`00000000 : nt!KiUpdateTime+0x4a1
- ffffd780`9eda8e80 fffff804`732c6cf2 : ffff9585`5a4ef270 ffff9585`5a4ef2f0 ffff9585`5a4ef2f0 00000000`00000000 : nt!KeClockInterruptNotify+0x2bb
- ffffd780`9eda8f30 fffff804`73208725 : 0000000e`ef326711 ffffc78e`c2cd3720 ffffc78e`c2cd37d0 00000000`00000000 : nt!HalpTimerClockInterrupt+0xe2
- ffffd780`9eda8f60 fffff804`733df9ea : ffff9585`5a4ef2f0 ffffc78e`c2cd3720 00000000`00000001 10c08349`08583349 : nt!KiCallInterruptServiceRoutine+0xa5
- ffffd780`9eda8fb0 fffff804`733dff57 : 00000000`0fafec11 00000000`00000002 00000000`00000000 00000000`00000010 : nt!KiInterruptSubDispatchNoLockNoEtw+0xfa (TrapFrame @ ffffd780`9eda8e70)
- ffff9585`5a4ef270 fffff804`732c4700 : 00000000`00000000 ffffffff`ffffffff 00000000`00000002 ffffee00`0c6079e0 : nt!KiInterruptDispatchNoLockNoEtw+0x37 (TrapFrame @ ffff9585`5a4ef270)
- ffff9585`5a4ef400 fffff804`732c0a52 : ffffc78e`00000001 00000000`00000000 00000000`00000000 ffffac01`48785018 : nt!KeFlushMultipleRangeTb+0x2a0
- ffff9585`5a4ef490 fffff804`732b410f : ffff9585`5a4ef5c0 85000004`2028a867 ffffac01`48785018 00000000`00000009 : nt!MiFlushTbList+0x82
- ffff9585`5a4ef4c0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MiCopyOnWrite+0x6df
- ========================================================================
- ======================= Dump #2: ANALYZE VERBOSE =======================
- ====================== File: 072920-15640-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 19041 MP (12 procs) Free x64
- Kernel base = 0xfffff807`39e00000 PsLoadedModuleList = 0xfffff807`3aa2a310
- Debug session time: Wed Jul 29 03:14:13.014 2020 (UTC - 4:00)
- System Uptime: 0 days 18:30:15.701
- BugCheck D1, {0, 2, 8, 0}
- *** WARNING: Unable to verify timestamp for win32k.sys
- *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
- Probably caused by : memory_corruption
- Followup: memory_corruption
- DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
- An attempt was made to access a pageable (or completely invalid) address at an
- interrupt request level (IRQL) that is too high. This is usually
- caused by drivers using improper addresses.
- If kernel debugger is available get stack backtrace.
- Arguments:
- Arg1: 0000000000000000, memory referenced
- Arg2: 0000000000000002, IRQL
- Arg3: 0000000000000008, value 0 = read operation, 1 = write operation
- Arg4: 0000000000000000, address which referenced memory
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- READ_ADDRESS: fffff8073aafa388: Unable to get MiVisibleState
- 0000000000000000
- CURRENT_IRQL: 2
- FAULTING_IP:
- +0
- 00000000`00000000 ?? ???
- PROCESS_NAME: EpicGamesLauncher.exe
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- BUGCHECK_STR: AV
- TRAP_FRAME: ffff850b6bc3f460 -- (.trap 0xffff850b6bc3f460)
- NOTE: The trap frame does not contain all registers.
- Some register values may be zeroed or incorrect.
- rax=0000000000000000 rbx=0000000000000000 rcx=ffff850b6bc3f5d0
- rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
- rip=0000000000000000 rsp=ffff850b6bc3f5f0 rbp=000fa4efbd9bbfff
- r8=ffffa107c3c4cde0 r9=00000000000000c7 r10=fffff80737a10000
- r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=0000000000000000
- iopl=0 nv up ei ng nz na pe nc
- 00000000`00000000 ?? ???
- Resetting default scope
- IP_IN_FREE_BLOCK: 0
- LAST_CONTROL_TRANSFER: from fffff8073a1efa29 to fffff8073a1ddb60
- FAILED_INSTRUCTION_ADDRESS:
- +0
- 00000000`00000000 ?? ???
- STACK_TEXT:
- ffff850b`6bc3f318 fffff807`3a1efa29 : 00000000`0000000a 00000000`00000000 00000000`00000002 00000000`00000008 : nt!KeBugCheckEx
- ffff850b`6bc3f320 fffff807`3a1ebd29 : 00000000`00000300 00000000`00000000 00000048`041212f6 00000000`00000004 : nt!KiBugCheckDispatch+0x69
- ffff850b`6bc3f460 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000fff ffffa107`d64b1180 : nt!KiPageFault+0x469
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
- fffff8073a01734a - nt!MiAddWorkingSetEntries+47a
- [ f6:9e ]
- fffff8073a184f3f-fffff8073a184f41 3 bytes - nt!MiFreeUltraMapping+33 (+0x16dbf5)
- [ 7d fb f6:67 cf 9e ]
- 4 errors : !nt (fffff8073a01734a-fffff8073a184f41)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-07-29T07:14:13.000Z
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #2: 3RD PARTY DRIVERS ======================
- Oct 15 2015 - rzendpt.sys - Razer RzEndPt driver https://www.razer.com/
- Oct 15 2015 - rzudd.sys - Razer Rzudd Engine Driver https://www.razer.com/
- May 04 2017 - ICCWDT.sys - Intel(R) Watchdog Timer driver
- Apr 11 2018 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Jan 11 2019 - iaLPSS2_GPIO2.sys - Intel(R) Serial IO GPIO driver
- Mar 14 2019 - nvvad64v.sys - Nvidia Virtual Audio driver http://www.nvidia.com/
- May 14 2019 - RTKVHD64.sys - Realtek Audio System driver https://www.realtek.com/en/
- Jul 01 2019 - rt640x64.sys - Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Jul 18 2019 - semav6msr64.sys - Intel Driver Update Utility http://www.intel.com/ OR (SEMA Software) http://www.sema-soft.de/en/home/
- Sep 19 2019 - RTCore64.sys - !!! Overclocking Software - RivaTuner - MSI Afterburner http://www.msi.com/ or EVGA Precision X http://www.evga.com/
- Nov 29 2019 - NvModuleTracker.sys - NVIDIA Module Tracker driver
- Jan 10 2020 - nvvhci.sys - Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Jan 26 2020 - UcmCxUcsiNvppc.sys - NVIDIA USB Type-C Port Policy Controller driver
- Jun 09 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- Jul 05 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- ================== Dump #2: 3RD PARTY DRIVERS (FULL) ===================
- Image path: \SystemRoot\System32\drivers\rzendpt.sys
- Image name: rzendpt.sys
- Search : https://www.google.com/search?q=rzendpt.sys
- ADA Info : Razer RzEndPt driver https://www.razer.com/
- Timestamp : Thu Oct 15 2015
- Image path: \SystemRoot\System32\drivers\rzudd.sys
- Image name: rzudd.sys
- Search : https://www.google.com/search?q=rzudd.sys
- ADA Info : Razer Rzudd Engine Driver https://www.razer.com/
- Timestamp : Thu Oct 15 2015
- Image path: \SystemRoot\System32\drivers\ICCWDT.sys
- Image name: ICCWDT.sys
- Search : https://www.google.com/search?q=ICCWDT.sys
- ADA Info : Intel(R) Watchdog Timer driver
- Timestamp : Thu May 4 2017
- Image path: \SystemRoot\System32\drivers\TeeDriverW8x64.sys
- Image name: TeeDriverW8x64.sys
- Search : https://www.google.com/search?q=TeeDriverW8x64.sys
- ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Timestamp : Wed Apr 11 2018
- Image path: \SystemRoot\System32\drivers\iaLPSS2_GPIO2.sys
- Image name: iaLPSS2_GPIO2.sys
- Search : https://www.google.com/search?q=iaLPSS2_GPIO2.sys
- ADA Info : Intel(R) Serial IO GPIO driver
- Timestamp : Fri Jan 11 2019
- Image path: \SystemRoot\system32\drivers\nvvad64v.sys
- Image name: nvvad64v.sys
- Search : https://www.google.com/search?q=nvvad64v.sys
- ADA Info : Nvidia Virtual Audio driver http://www.nvidia.com/
- Timestamp : Thu Mar 14 2019
- Image path: \SystemRoot\system32\drivers\RTKVHD64.sys
- Image name: RTKVHD64.sys
- Search : https://www.google.com/search?q=RTKVHD64.sys
- ADA Info : Realtek Audio System driver https://www.realtek.com/en/
- Timestamp : Tue May 14 2019
- Image path: \SystemRoot\System32\drivers\rt640x64.sys
- Image name: rt640x64.sys
- Search : https://www.google.com/search?q=rt640x64.sys
- ADA Info : Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Timestamp : Mon Jul 1 2019
- Image path: \??\C:\WINDOWS\system32\drivers\semav6msr64.sys
- Image name: semav6msr64.sys
- Search : https://www.google.com/search?q=semav6msr64.sys
- ADA Info : Intel Driver Update Utility http://www.intel.com/ OR (SEMA Software) http://www.sema-soft.de/en/home/
- Timestamp : Thu Jul 18 2019
- Image path: \??\C:\Program Files (x86)\MSI Afterburner\RTCore64.sys
- Image name: RTCore64.sys
- Search : https://www.google.com/search?q=RTCore64.sys
- ADA Info : !!! Overclocking Software - RivaTuner - MSI Afterburner http://www.msi.com/ or EVGA Precision X http://www.evga.com/
- Timestamp : Thu Sep 19 2019
- Image path: \SystemRoot\System32\drivers\NvModuleTracker.sys
- Image name: NvModuleTracker.sys
- Search : https://www.google.com/search?q=NvModuleTracker.sys
- ADA Info : NVIDIA Module Tracker driver
- Timestamp : Fri Nov 29 2019
- Image path: \SystemRoot\System32\drivers\nvvhci.sys
- Image name: nvvhci.sys
- Search : https://www.google.com/search?q=nvvhci.sys
- ADA Info : Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Timestamp : Fri Jan 10 2020
- Image path: \SystemRoot\System32\DriverStore\FileRepository\nvppc.inf_amd64_0f22333f160a8f42\UcmCxUcsiNvppc.sys
- Image name: UcmCxUcsiNvppc.sys
- Search : https://www.google.com/search?q=UcmCxUcsiNvppc.sys
- ADA Info : NVIDIA USB Type-C Port Policy Controller driver
- Timestamp : Sun Jan 26 2020
- Image path: \SystemRoot\system32\drivers\nvhda64v.sys
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Tue Jun 9 2020
- Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_edab19158bdd0d0a\nvlddmkm.sys
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Sun Jul 5 2020
- ====================== Dump #2: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- acpipagr.sys ACPI Processor Aggregator Device driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CimFS.SYS Consumer IR Class Driver for eHome (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- csc.sys Windows Client Side Caching driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- intelppm.sys Processor Device Driver (Microsoft)
- IntelTA.sys Intel Telemetry Driver
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kd.dll Local Kernal Debugger (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate_GenuineIntel.dll Intel Microcode Update Library (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- MpKslDrv.sys Microsoft Anti-malware Protection driver
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msgpioclx.sys GPIO Class Extension Driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msquic.sys Windows QUIC Driver
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndiscap.sys Microsoft NDIS Packet Capture Filter Driver
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- ndisuio.sys NDIS User mode I/O driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- nwifi.sys NativeWiFi Miniport Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- qwavedrv.sys Quality Windows Audio Video Experience (qWave) Support driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- UcmCx.sys USB Connector Manager KMDF Class Extension
- ucx01000.sys USB Controller Extension (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- usbvideo.sys USB Video Class Driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- ====================== Dump #2: UNLOADED MODULES =======================
- fffff807`3c330000 fffff807`3c33f000 hiber_storpo
- fffff807`3c340000 fffff807`3c373000 hiber_storah
- fffff807`3c380000 fffff807`3c39e000 hiber_dumpfv
- fffff807`3c320000 fffff807`3c32d000 MSPCLOCK.sys
- fffff807`3c310000 fffff807`3c31d000 MSPQM.sys
- fffff807`3c300000 fffff807`3c30d000 MSPCLOCK.sys
- fffff807`3c2f0000 fffff807`3c2fd000 MSPQM.sys
- fffff807`3c2d0000 fffff807`3c2e1000 MSKSSRV.sys
- fffff807`3c2b0000 fffff807`3c2c1000 MSKSSRV.sys
- fffff807`3c290000 fffff807`3c2a1000 MSKSSRV.sys
- fffff807`3c270000 fffff807`3c281000 MSKSSRV.sys
- fffff807`3c090000 fffff807`3c22b000 EasyAntiChea
- fffff807`3c250000 fffff807`3c261000 MSKSSRV.sys
- fffff807`3be00000 fffff807`3bf9b000 EasyAntiChea
- fffff807`3c070000 fffff807`3c081000 MpKslDrv.sys
- fffff807`3bfb0000 fffff807`3bfc1000 MSKSSRV.sys
- fffff807`537e0000 fffff807`53820000 mbamswissarm
- fffff807`55190000 fffff807`551c9000 MbamChameleo
- fffff807`551d0000 fffff807`551f3000 mwac.sys
- fffff807`53820000 fffff807`53834000 mbam.sys
- fffff807`51060000 fffff807`51094000 farflt.sys
- fffff807`51030000 fffff807`51057000 mbae64.sys
- fffff807`3bfa0000 fffff807`3bfac000 bertreader.s
- fffff807`55bb0000 fffff807`55bc1000 MSKSSRV.sys
- fffff807`3df80000 fffff807`3dfe8000 WdFilter.sys
- fffff807`537c0000 fffff807`537d6000 WdNisDrv.sys
- fffff807`55bb0000 fffff807`55bc1000 MSKSSRV.sys
- fffff807`51040000 fffff807`5104f000 dump_storpor
- fffff807`51090000 fffff807`510c3000 dump_storahc
- fffff807`510f0000 fffff807`5110e000 dump_dumpfve
- fffff807`520d0000 fffff807`520dc000 WdmCompanion
- fffff807`51670000 fffff807`5168c000 dam.sys
- fffff807`52520000 fffff807`52a39000 vgk.sys
- fffff807`3da60000 fffff807`3da71000 WdBoot.sys
- fffff807`3da50000 fffff807`3da59000 MbamElam.sys
- fffff807`3eae0000 fffff807`3eaf0000 hwpolicy.sys
- ====================== Dump #2: BIOS INFORMATION =======================
- [SMBIOS Data Tables v3.1]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 4459 bytes]
- [BIOS Information (Type 0) - Length 26 - Handle 0000h]
- Vendor American Megatrends Inc.
- BIOS Version F2
- BIOS Starting Address Segment f000
- BIOS Release Date 04/19/2018
- BIOS ROM Size 1000000
- BIOS Characteristics
- 07: - PCI Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 32: - BIOS Vendor Reserved
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 5
- BIOS Minor Revision 13
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- Manufacturer Gigabyte Technology Co., Ltd.
- Product Name H310M H
- Version Default string
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- SKUNumber Default string
- Family Default string
- [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
- Manufacturer Gigabyte Technology Co., Ltd.
- Product H310M H
- Version x.x
- Feature Flags 09h
- -1364281632: - -1364281584: - «áêù
- Location Default string
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 22 - Handle 0003h]
- Manufacturer Default string
- Chassis Type Desktop
- Version Default string
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 3
- [Onboard Devices Information (Type 10) - Length 6 - Handle 0021h]
- Number of Devices 1
- 01: Type Video [enabled]
- [OEM Strings (Type 11) - Length 5 - Handle 0022h]
- Number of Strings 1
- 1 Default string
- [System Configuration Options (Type 12) - Length 5 - Handle 0023h]
- [Physical Memory Array (Type 16) - Length 23 - Handle 003ah]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 33554432KB
- Number of Memory Devices 4
- [Memory Device (Type 17) - Length 40 - Handle 003bh]
- Physical Memory Array Handle 003ah
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM0
- Bank Locator BANK 0
- Memory Type 1ah - Specification Reserved
- Type Detail 0080h - Synchronous
- Speed 2133MHz
- Manufacturer 029E
- Part Number CMK16GX4M2B3200C16
- [Memory Device (Type 17) - Length 40 - Handle 003ch]
- Physical Memory Array Handle 003ah
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 02h - Unknown
- Device Locator ChannelA-DIMM1
- Bank Locator BANK 1
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Device (Type 17) - Length 40 - Handle 003dh]
- Physical Memory Array Handle 003ah
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM0
- Bank Locator BANK 2
- Memory Type 1ah - Specification Reserved
- Type Detail 0080h - Synchronous
- Speed 2133MHz
- Manufacturer 029E
- Part Number CMK16GX4M2B3200C16
- [Memory Device (Type 17) - Length 40 - Handle 003eh]
- Physical Memory Array Handle 003ah
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 02h - Unknown
- Device Locator ChannelB-DIMM1
- Bank Locator BANK 3
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 003fh]
- Starting Address 00000000h
- Ending Address 00ffffffh
- Memory Array Handle 003ah
- Partition Width 02
- [Cache Information (Type 7) - Length 19 - Handle 0044h]
- Socket Designation L1 Cache
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0180h - 384K
- Installed Size 0180h - 384K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type ParitySingle-Bit ECC
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0045h]
- Socket Designation L2 Cache
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 0600h - 1536K
- Installed Size 0600h - 1536K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Unified
- Associativity 4-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0046h]
- Socket Designation L3 Cache
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 3000h - 12288K
- Installed Size 3000h - 12288K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 16-way Set-Associative
- [Processor Information (Type 4) - Length 48 - Handle 0047h]
- Socket Designation U3E1
- Processor Type Central Processor
- Processor Family c6h - Specification Reserved
- Processor Manufacturer Intel(R) Corporation
- Processor ID ea060900fffbebbf
- Processor Version Intel(R) Core(TM) i7-8700 CPU @ 3.20GHz
- Processor Voltage 89h - 0.9V
- External Clock 100MHz
- Max Speed 8300MHz
- Current Speed 3200MHz
- Status Enabled Populated
- Processor Upgrade Other
- L1 Cache Handle 0044h
- L2 Cache Handle 0045h
- L3 Cache Handle 0046h
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0048h]
- Starting Address 00000000h
- Ending Address 007fffffh
- Memory Device Handle 003bh
- Mem Array Mapped Adr Handle 003fh
- Interleave Position 01
- Interleave Data Depth 02
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0049h]
- Starting Address 00800000h
- Ending Address 00ffffffh
- Memory Device Handle 003dh
- Mem Array Mapped Adr Handle 003fh
- Interleave Position 02
- Interleave Data Depth 02
- ========================== Dump #2: Extra #1 ===========================
- 10: kd> !verifier
- Verify Flags Level 0x00000000
- STANDARD FLAGS:
- [X] (0x00000000) Automatic Checks
- [ ] (0x00000001) Special pool
- [ ] (0x00000002) Force IRQL checking
- [ ] (0x00000008) Pool tracking
- [ ] (0x00000010) I/O verification
- [ ] (0x00000020) Deadlock detection
- [ ] (0x00000080) DMA checking
- [ ] (0x00000100) Security checks
- [ ] (0x00000800) Miscellaneous checks
- [ ] (0x00020000) DDI compliance checking
- ADDITIONAL FLAGS:
- [ ] (0x00000004) Randomized low resources simulation
- [ ] (0x00000200) Force pending I/O requests
- [ ] (0x00000400) IRP logging
- [ ] (0x00002000) Invariant MDL checking for stack
- [ ] (0x00004000) Invariant MDL checking for driver
- [ ] (0x00008000) Power framework delay fuzzing
- [ ] (0x00010000) Port/miniport interface checking
- [ ] (0x00040000) Systematic low resources simulation
- [ ] (0x00080000) DDI compliance checking (additional)
- [ ] (0x00200000) NDIS/WIFI verification
- [ ] (0x00800000) Kernel synchronization delay fuzzing
- [ ] (0x01000000) VM switch verification
- [ ] (0x02000000) Code integrity checks
- [X] Indicates flag is enabled
- Summary of All Verifier Statistics
- RaiseIrqls 0x0
- AcquireSpinLocks 0x0
- Synch Executions 0x0
- Trims 0x0
- Pool Allocations Attempted 0x0
- Pool Allocations Succeeded 0x0
- Pool Allocations Succeeded SpecialPool 0x0
- Pool Allocations With NO TAG 0x0
- Pool Allocations Failed 0x0
- Current paged pool allocations 0x0 for 00000000 bytes
- Peak paged pool allocations 0x0 for 00000000 bytes
- Current nonpaged pool allocations 0x0 for 00000000 bytes
- Peak nonpaged pool allocations 0x0 for 00000000 bytes
- ========================== Dump #2: Extra #2 ===========================
- 10: kd> !thread
- THREAD ffffa107d64b1080 Cid 3320.36c4 Teb: 000000c7fa21a000 Win32Thread: 0000000000000000 RUNNING on processor a
- Not impersonating
- GetUlongFromAddress: unable to read from fffff8073aa1143c
- Owning Process ffffa107dab0c080 Image: EpicGamesLauncher.exe
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 4263404
- Context Switch Count 840369 IdealProcessor: 6
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address 0x00007ff7eeb047a0
- Stack Init ffff850b6bc3fb90 Current ffff850b6bc3f5a0
- Base ffff850b6bc40000 Limit ffff850b6bc39000 Call 0000000000000000
- Priority 6 BasePriority 6 PriorityDecrement 0 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- ffff850b`6bc3f318 fffff807`3a1efa29 : 00000000`0000000a 00000000`00000000 00000000`00000002 00000000`00000008 : nt!KeBugCheckEx
- ffff850b`6bc3f320 fffff807`3a1ebd29 : 00000000`00000300 00000000`00000000 00000048`041212f6 00000000`00000004 : nt!KiBugCheckDispatch+0x69
- ffff850b`6bc3f460 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000fff ffffa107`d64b1180 : nt!KiPageFault+0x469 (TrapFrame @ ffff850b`6bc3f460)
- ========================================================================
- ======================= Dump #3: ANALYZE VERBOSE =======================
- ====================== File: 072720-15703-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 19041 MP (12 procs) Free x64
- Kernel base = 0xfffff803`6b600000 PsLoadedModuleList = 0xfffff803`6c22a310
- Debug session time: Mon Jul 27 10:32:37.611 2020 (UTC - 4:00)
- System Uptime: 0 days 2:53:15.297
- BugCheck 1E, {ffffffffc000001d, fffff8036b902db4, ffffe0803afcb340, 17}
- *** WARNING: Unable to verify timestamp for win32k.sys
- *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
- Probably caused by : memory_corruption
- Followup: memory_corruption
- KMODE_EXCEPTION_NOT_HANDLED (1e)
- This is a very common bugcheck. Usually the exception address pinpoints
- the driver/function that caused the problem. Always note this address
- as well as the link date of the driver/image that contains this address.
- Arguments:
- Arg1: ffffffffc000001d, The exception code that was not handled
- Arg2: fffff8036b902db4, The address that the exception occurred at
- Arg3: ffffe0803afcb340, Parameter 0 of the exception
- Arg4: 0000000000000017, Parameter 1 of the exception
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- EXCEPTION_CODE: (NTSTATUS) 0xc000001d - {EXCEPTION} Illegal Instruction An attempt was made to execute an illegal instruction.
- FAULTING_IP:
- nt!MiUnlockPageTableInternal+194
- fffff803`6b902db4 c7feffff4c8d xbegin fffff802`f8dd2db9
- EXCEPTION_PARAMETER1: ffffe0803afcb340
- EXCEPTION_PARAMETER2: 0000000000000017
- BUGCHECK_STR: 0x1E_c000001d
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- PROCESS_NAME: System
- CURRENT_IRQL: 2
- BAD_STACK_POINTER: ffffe0803afd98e8
- LAST_CONTROL_TRANSFER: from fffff8036ba2eef1 to fffff8036b9ddb60
- FAILED_INSTRUCTION_ADDRESS:
- nt!MiUnlockPageTableInternal+194
- fffff803`6b902db4 c7feffff4c8d xbegin fffff802`f8dd2db9
- STACK_TEXT:
- ffffe080`3afd98e8 fffff803`6ba2eef1 : 00000000`0000001e ffffffff`c000001d fffff803`6b902db4 ffffe080`3afcb340 : nt!KeBugCheckEx
- ffffe080`3afd98f0 fffff803`6b9de9f2 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDispatchException+0x1b3e31
- ffffe080`3afd9fb0 fffff803`6b9de9c0 : fffff803`6b9efb65 00000000`00000000 00000000`00000000 ffffab87`29c5a040 : nt!KxExceptionDispatchOnExceptionStack+0x12
- ffff8402`3a8bf738 fffff803`6b9efb65 : 00000000`00000000 00000000`00000000 ffffab87`29c5a040 fffff803`6b83a810 : nt!KiExceptionDispatchOnExceptionStackContinue
- ffff8402`3a8bf740 fffff803`6b9ea0a9 : 00000000`00000000 00000018`34148f00 ffffe080`3afc0180 00000008`00000001 : nt!KiExceptionDispatch+0x125
- ffff8402`3a8bf920 fffff803`6b902db4 : 00000000`00000000 00000000`00000001 ffffe080`3afc0180 ffffe080`3afc0180 : nt!KiInvalidOpcodeFault+0x329
- ffff8402`3a8bfab0 00000000`00000000 : 00000000`00000000 00000000`000006e5 ffffab87`2cd93080 ffffe080`3afcb340 : nt!MiUnlockPageTableInternal+0x194
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
- fffff8036b902a34-fffff8036b902a35 2 bytes - nt!MiRebuildPageTableLeafAges+34
- [ fb f6:c8 90 ]
- fffff8036b902a84-fffff8036b902a85 2 bytes - nt!MiRebuildPageTableLeafAges+84 (+0x50)
- [ 80 fa:00 f9 ]
- fffff8036b902b47 - nt!MiCountWslesInPageTable+27 (+0xc3)
- [ f6:90 ]
- fffff8036b902b56-fffff8036b902b5a 5 bytes - nt!MiCountWslesInPageTable+36 (+0x0f)
- [ d0 be 7d fb f6:10 32 64 c8 90 ]
- fffff8036b902b63-fffff8036b902b67 5 bytes - nt!MiCountWslesInPageTable+43 (+0x0d)
- [ d7 be 7d fb f6:17 32 64 c8 90 ]
- fffff8036b902c3e-fffff8036b902c43 6 bytes - nt!MiUnlockPageTableInternal+1e (+0xdb)
- [ 68 df be 7d fb f6:08 19 32 64 c8 90 ]
- fffff8036b902c52-fffff8036b902c56 5 bytes - nt!MiUnlockPageTableInternal+32 (+0x14)
- [ d0 be 7d fb f6:10 32 64 c8 90 ]
- fffff8036b902c5c-fffff8036b902c60 5 bytes - nt!MiUnlockPageTableInternal+3c (+0x0a)
- [ df be 7d fb f6:1f 32 64 c8 90 ]
- fffff8036b902cb1-fffff8036b902cb5 5 bytes - nt!MiUnlockPageTableInternal+91 (+0x55)
- [ d7 be 7d fb f6:17 32 64 c8 90 ]
- fffff8036b902e4b-fffff8036b902e4f 5 bytes - nt!MiGetPageTableLockBuffer+3 (+0x19a)
- [ d0 be 7d fb f6:10 32 64 c8 90 ]
- fffff8036b984f3e-fffff8036b984f41 4 bytes - nt!MiFreeUltraMapping+32 (+0x820f3)
- [ a0 7d fb f6:20 64 c8 90 ]
- 45 errors : !nt (fffff8036b902a34-fffff8036b984f41)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-07-27T14:32:37.000Z
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #3: 3RD PARTY DRIVERS ======================
- Oct 15 2015 - rzendpt.sys - Razer RzEndPt driver https://www.razer.com/
- Oct 15 2015 - rzudd.sys - Razer Rzudd Engine Driver https://www.razer.com/
- May 04 2017 - ICCWDT.sys - Intel(R) Watchdog Timer driver
- Apr 11 2018 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Jan 11 2019 - iaLPSS2_GPIO2.sys - Intel(R) Serial IO GPIO driver
- Mar 14 2019 - nvvad64v.sys - Nvidia Virtual Audio driver http://www.nvidia.com/
- May 14 2019 - RTKVHD64.sys - Realtek Audio System driver https://www.realtek.com/en/
- Jul 01 2019 - rt640x64.sys - Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Jul 18 2019 - semav6msr64.sys - Intel Driver Update Utility http://www.intel.com/ OR (SEMA Software) http://www.sema-soft.de/en/home/
- Nov 29 2019 - NvModuleTracker.sys - NVIDIA Module Tracker driver
- Jan 10 2020 - nvvhci.sys - Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Jan 26 2020 - UcmCxUcsiNvppc.sys - NVIDIA USB Type-C Port Policy Controller driver
- Jun 09 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- Jul 05 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- ================== Dump #3: 3RD PARTY DRIVERS (FULL) ===================
- Image path: \SystemRoot\System32\drivers\rzendpt.sys
- Image name: rzendpt.sys
- Search : https://www.google.com/search?q=rzendpt.sys
- ADA Info : Razer RzEndPt driver https://www.razer.com/
- Timestamp : Thu Oct 15 2015
- Image path: \SystemRoot\System32\drivers\rzudd.sys
- Image name: rzudd.sys
- Search : https://www.google.com/search?q=rzudd.sys
- ADA Info : Razer Rzudd Engine Driver https://www.razer.com/
- Timestamp : Thu Oct 15 2015
- Image path: \SystemRoot\System32\drivers\ICCWDT.sys
- Image name: ICCWDT.sys
- Search : https://www.google.com/search?q=ICCWDT.sys
- ADA Info : Intel(R) Watchdog Timer driver
- Timestamp : Thu May 4 2017
- Image path: \SystemRoot\System32\drivers\TeeDriverW8x64.sys
- Image name: TeeDriverW8x64.sys
- Search : https://www.google.com/search?q=TeeDriverW8x64.sys
- ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Timestamp : Wed Apr 11 2018
- Image path: \SystemRoot\System32\drivers\iaLPSS2_GPIO2.sys
- Image name: iaLPSS2_GPIO2.sys
- Search : https://www.google.com/search?q=iaLPSS2_GPIO2.sys
- ADA Info : Intel(R) Serial IO GPIO driver
- Timestamp : Fri Jan 11 2019
- Image path: \SystemRoot\system32\drivers\nvvad64v.sys
- Image name: nvvad64v.sys
- Search : https://www.google.com/search?q=nvvad64v.sys
- ADA Info : Nvidia Virtual Audio driver http://www.nvidia.com/
- Timestamp : Thu Mar 14 2019
- Image path: \SystemRoot\system32\drivers\RTKVHD64.sys
- Image name: RTKVHD64.sys
- Search : https://www.google.com/search?q=RTKVHD64.sys
- ADA Info : Realtek Audio System driver https://www.realtek.com/en/
- Timestamp : Tue May 14 2019
- Image path: \SystemRoot\System32\drivers\rt640x64.sys
- Image name: rt640x64.sys
- Search : https://www.google.com/search?q=rt640x64.sys
- ADA Info : Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Timestamp : Mon Jul 1 2019
- Image path: \??\C:\WINDOWS\system32\drivers\semav6msr64.sys
- Image name: semav6msr64.sys
- Search : https://www.google.com/search?q=semav6msr64.sys
- ADA Info : Intel Driver Update Utility http://www.intel.com/ OR (SEMA Software) http://www.sema-soft.de/en/home/
- Timestamp : Thu Jul 18 2019
- Image path: \SystemRoot\System32\drivers\NvModuleTracker.sys
- Image name: NvModuleTracker.sys
- Search : https://www.google.com/search?q=NvModuleTracker.sys
- ADA Info : NVIDIA Module Tracker driver
- Timestamp : Fri Nov 29 2019
- Image path: \SystemRoot\System32\drivers\nvvhci.sys
- Image name: nvvhci.sys
- Search : https://www.google.com/search?q=nvvhci.sys
- ADA Info : Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Timestamp : Fri Jan 10 2020
- Image path: \SystemRoot\System32\DriverStore\FileRepository\nvppc.inf_amd64_0f22333f160a8f42\UcmCxUcsiNvppc.sys
- Image name: UcmCxUcsiNvppc.sys
- Search : https://www.google.com/search?q=UcmCxUcsiNvppc.sys
- ADA Info : NVIDIA USB Type-C Port Policy Controller driver
- Timestamp : Sun Jan 26 2020
- Image path: \SystemRoot\system32\drivers\nvhda64v.sys
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Tue Jun 9 2020
- Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_edab19158bdd0d0a\nvlddmkm.sys
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Sun Jul 5 2020
- ====================== Dump #3: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- acpipagr.sys ACPI Processor Aggregator Device driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CimFS.SYS Consumer IR Class Driver for eHome (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- csc.sys Windows Client Side Caching driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- intelppm.sys Processor Device Driver (Microsoft)
- IntelTA.sys Intel Telemetry Driver
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kd.dll Local Kernal Debugger (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate_GenuineIntel.dll Intel Microcode Update Library (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msgpioclx.sys GPIO Class Extension Driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msquic.sys Windows QUIC Driver
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndiscap.sys Microsoft NDIS Packet Capture Filter Driver
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- ndisuio.sys NDIS User mode I/O driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- nwifi.sys NativeWiFi Miniport Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- qwavedrv.sys Quality Windows Audio Video Experience (qWave) Support driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- UcmCx.sys USB Connector Manager KMDF Class Extension
- ucx01000.sys USB Controller Extension (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- usbvideo.sys USB Video Class Driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- ====================== Dump #3: UNLOADED MODULES =======================
- fffff803`84b60000 fffff803`84b71000 MSKSSRV.sys
- fffff803`841a0000 fffff803`841b1000 MSKSSRV.sys
- fffff803`84be0000 fffff803`84bef000 hiber_storpo
- fffff803`6f5d0000 fffff803`6f603000 hiber_storah
- fffff803`6f610000 fffff803`6f62e000 hiber_dumpfv
- fffff803`84bb0000 fffff803`84bbc000 bertreader.s
- fffff803`84b60000 fffff803`84b71000 MSKSSRV.sys
- fffff803`841a0000 fffff803`841b1000 MSKSSRV.sys
- fffff803`83ea0000 fffff803`83eaf000 dump_storpor
- fffff803`83ef0000 fffff803`83f23000 dump_storahc
- fffff803`83f50000 fffff803`83f6e000 dump_dumpfve
- fffff803`86630000 fffff803`8663c000 WdmCompanion
- fffff803`837f0000 fffff803`8380c000 dam.sys
- fffff803`83400000 fffff803`83919000 vgk.sys
- fffff803`70250000 fffff803`70261000 WdBoot.sys
- fffff803`712d0000 fffff803`712e0000 hwpolicy.sys
- ====================== Dump #3: BIOS INFORMATION =======================
- [SMBIOS Data Tables v3.1]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 4459 bytes]
- [BIOS Information (Type 0) - Length 26 - Handle 0000h]
- Vendor American Megatrends Inc.
- BIOS Version F2
- BIOS Starting Address Segment f000
- BIOS Release Date 04/19/2018
- BIOS ROM Size 1000000
- BIOS Characteristics
- 07: - PCI Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 32: - BIOS Vendor Reserved
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 5
- BIOS Minor Revision 13
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- Manufacturer Gigabyte Technology Co., Ltd.
- Product Name H310M H
- Version Default string
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- SKUNumber Default string
- Family Default string
- [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
- Manufacturer Gigabyte Technology Co., Ltd.
- Product H310M H
- Version x.x
- Feature Flags 09h
- -1364281632: - -1364281584: - «áêù
- Location Default string
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 22 - Handle 0003h]
- Manufacturer Default string
- Chassis Type Desktop
- Version Default string
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 3
- [Onboard Devices Information (Type 10) - Length 6 - Handle 0021h]
- Number of Devices 1
- 01: Type Video [enabled]
- [OEM Strings (Type 11) - Length 5 - Handle 0022h]
- Number of Strings 1
- 1 Default string
- [System Configuration Options (Type 12) - Length 5 - Handle 0023h]
- [Physical Memory Array (Type 16) - Length 23 - Handle 003ah]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 33554432KB
- Number of Memory Devices 4
- [Memory Device (Type 17) - Length 40 - Handle 003bh]
- Physical Memory Array Handle 003ah
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM0
- Bank Locator BANK 0
- Memory Type 1ah - Specification Reserved
- Type Detail 0080h - Synchronous
- Speed 2133MHz
- Manufacturer 029E
- Part Number CMK16GX4M2B3200C16
- [Memory Device (Type 17) - Length 40 - Handle 003ch]
- Physical Memory Array Handle 003ah
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 02h - Unknown
- Device Locator ChannelA-DIMM1
- Bank Locator BANK 1
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Device (Type 17) - Length 40 - Handle 003dh]
- Physical Memory Array Handle 003ah
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM0
- Bank Locator BANK 2
- Memory Type 1ah - Specification Reserved
- Type Detail 0080h - Synchronous
- Speed 2133MHz
- Manufacturer 029E
- Part Number CMK16GX4M2B3200C16
- [Memory Device (Type 17) - Length 40 - Handle 003eh]
- Physical Memory Array Handle 003ah
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 02h - Unknown
- Device Locator ChannelB-DIMM1
- Bank Locator BANK 3
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 003fh]
- Starting Address 00000000h
- Ending Address 00ffffffh
- Memory Array Handle 003ah
- Partition Width 02
- [Cache Information (Type 7) - Length 19 - Handle 0044h]
- Socket Designation L1 Cache
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0180h - 384K
- Installed Size 0180h - 384K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type ParitySingle-Bit ECC
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0045h]
- Socket Designation L2 Cache
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 0600h - 1536K
- Installed Size 0600h - 1536K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Unified
- Associativity 4-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0046h]
- Socket Designation L3 Cache
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 3000h - 12288K
- Installed Size 3000h - 12288K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 16-way Set-Associative
- [Processor Information (Type 4) - Length 48 - Handle 0047h]
- Socket Designation U3E1
- Processor Type Central Processor
- Processor Family c6h - Specification Reserved
- Processor Manufacturer Intel(R) Corporation
- Processor ID ea060900fffbebbf
- Processor Version Intel(R) Core(TM) i7-8700 CPU @ 3.20GHz
- Processor Voltage 89h - 0.9V
- External Clock 100MHz
- Max Speed 8300MHz
- Current Speed 3200MHz
- Status Enabled Populated
- Processor Upgrade Other
- L1 Cache Handle 0044h
- L2 Cache Handle 0045h
- L3 Cache Handle 0046h
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0048h]
- Starting Address 00000000h
- Ending Address 007fffffh
- Memory Device Handle 003bh
- Mem Array Mapped Adr Handle 003fh
- Interleave Position 01
- Interleave Data Depth 02
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0049h]
- Starting Address 00800000h
- Ending Address 00ffffffh
- Memory Device Handle 003dh
- Mem Array Mapped Adr Handle 003fh
- Interleave Position 02
- Interleave Data Depth 02
- ========================== Dump #3: Extra #1 ===========================
- 10: kd> !verifier
- Verify Flags Level 0x00000000
- STANDARD FLAGS:
- [X] (0x00000000) Automatic Checks
- [ ] (0x00000001) Special pool
- [ ] (0x00000002) Force IRQL checking
- [ ] (0x00000008) Pool tracking
- [ ] (0x00000010) I/O verification
- [ ] (0x00000020) Deadlock detection
- [ ] (0x00000080) DMA checking
- [ ] (0x00000100) Security checks
- [ ] (0x00000800) Miscellaneous checks
- [ ] (0x00020000) DDI compliance checking
- ADDITIONAL FLAGS:
- [ ] (0x00000004) Randomized low resources simulation
- [ ] (0x00000200) Force pending I/O requests
- [ ] (0x00000400) IRP logging
- [ ] (0x00002000) Invariant MDL checking for stack
- [ ] (0x00004000) Invariant MDL checking for driver
- [ ] (0x00008000) Power framework delay fuzzing
- [ ] (0x00010000) Port/miniport interface checking
- [ ] (0x00040000) Systematic low resources simulation
- [ ] (0x00080000) DDI compliance checking (additional)
- [ ] (0x00200000) NDIS/WIFI verification
- [ ] (0x00800000) Kernel synchronization delay fuzzing
- [ ] (0x01000000) VM switch verification
- [ ] (0x02000000) Code integrity checks
- [X] Indicates flag is enabled
- Summary of All Verifier Statistics
- RaiseIrqls 0x0
- AcquireSpinLocks 0x0
- Synch Executions 0x0
- Trims 0x0
- Pool Allocations Attempted 0x0
- Pool Allocations Succeeded 0x0
- Pool Allocations Succeeded SpecialPool 0x0
- Pool Allocations With NO TAG 0x0
- Pool Allocations Failed 0x0
- Current paged pool allocations 0x0 for 00000000 bytes
- Peak paged pool allocations 0x0 for 00000000 bytes
- Current nonpaged pool allocations 0x0 for 00000000 bytes
- Peak nonpaged pool allocations 0x0 for 00000000 bytes
- ========================== Dump #3: Extra #2 ===========================
- 10: kd> !thread
- THREAD ffffe0803afcb340 Cid 0000.0000 Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor a
- Not impersonating
- GetUlongFromAddress: unable to read from fffff8036c21143c
- Owning Process fffff8036c323a00 Image: System Process
- Attached Process ffffab87204b6040 Image: System
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 665298
- Context Switch Count 14867719 IdealProcessor: 10
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address nt!KiIdleLoop (0xfffff8036b9e1630)
- Stack Init ffff84023a8bfb90 Current ffff84023a8bfb20
- Base ffff84023a8c0000 Limit ffff84023a8b9000 Call 0000000000000000
- Priority 0 BasePriority 0 PriorityDecrement 0 IoPriority 0 PagePriority 0
- Child-SP RetAddr : Args to Child : Call Site
- ffffe080`3afd98e8 fffff803`6ba2eef1 : 00000000`0000001e ffffffff`c000001d fffff803`6b902db4 ffffe080`3afcb340 : nt!KeBugCheckEx
- ffffe080`3afd98f0 fffff803`6b9de9f2 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDispatchException+0x1b3e31
- ffffe080`3afd9fb0 fffff803`6b9de9c0 : fffff803`6b9efb65 00000000`00000000 00000000`00000000 ffffab87`29c5a040 : nt!KxExceptionDispatchOnExceptionStack+0x12 (TrapFrame @ ffffe080`3afd9e70)
- ffff8402`3a8bf738 fffff803`6b9efb65 : 00000000`00000000 00000000`00000000 ffffab87`29c5a040 fffff803`6b83a810 : nt!KiExceptionDispatchOnExceptionStackContinue
- ffff8402`3a8bf740 fffff803`6b9ea0a9 : 00000000`00000000 00000018`34148f00 ffffe080`3afc0180 00000008`00000001 : nt!KiExceptionDispatch+0x125
- ffff8402`3a8bf920 fffff803`6b902db4 : 00000000`00000000 00000000`00000001 ffffe080`3afc0180 ffffe080`3afc0180 : nt!KiInvalidOpcodeFault+0x329 (TrapFrame @ ffff8402`3a8bf920)
- ffff8402`3a8bfab0 00000000`00000000 : 00000000`00000000 00000000`000006e5 ffffab87`2cd93080 ffffe080`3afcb340 : nt!MiUnlockPageTableInternal+0x194
- ========================================================================
- ======================= Dump #4: ANALYZE VERBOSE =======================
- ====================== File: 072720-13453-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 19041 MP (12 procs) Free x64
- Kernel base = 0xfffff804`2a20a000 PsLoadedModuleList = 0xfffff804`2ae34310
- Debug session time: Mon Jul 27 07:36:43.422 2020 (UTC - 4:00)
- System Uptime: 0 days 0:00:14.156
- BugCheck C4, {62, ffffd8087653cf98, ffffd8087d8fa690, 1}
- *** ERROR: Module load completed but symbols could not be loaded for vgk.sys
- Probably caused by : memory_corruption
- Followup: memory_corruption
- DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
- A device driver attempting to corrupt the system has been caught. This is
- because the driver was specified in the registry as being suspect (by the
- administrator) and the kernel has enabled substantial checking of this driver.
- If the driver attempts to corrupt the system, bugchecks 0xC4, 0xC1 and 0xA will
- be among the most commonly seen crashes.
- Arguments:
- Arg1: 0000000000000062, A driver has forgotten to free its pool allocations prior to unloading.
- Arg2: ffffd8087653cf98, name of the driver having the issue.
- Arg3: ffffd8087d8fa690, verifier internal structure with driver information.
- Arg4: 0000000000000001, total # of (paged+nonpaged) allocations that weren't freed.
- Type !verifier 3 drivername.sys for info on the allocations
- that were leaked that caused the bugcheck.
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- BUGCHECK_STR: 0xc4_62
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- FAULTING_MODULE: fffff80b1fd70000 vgk
- VERIFIER_DRIVER_ENTRY: dt nt!_MI_VERIFIER_DRIVER_ENTRY ffffd8087d8fa690
- Symbol nt!_MI_VERIFIER_DRIVER_ENTRY not found.
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- PROCESS_NAME: System
- CURRENT_IRQL: 2
- LAST_CONTROL_TRANSFER: from fffff8042abe8e34 to fffff8042a5e7b60
- STACK_TEXT:
- ffffba06`37807418 fffff804`2abe8e34 : 00000000`000000c4 00000000`00000062 ffffd808`7653cf98 ffffd808`7d8fa690 : nt!KeBugCheckEx
- ffffba06`37807420 fffff804`2abf8119 : ffffd808`7d8fa690 ffffba06`37807510 ffffd808`7653cdb0 ffffd808`7d8dfbe0 : nt!VerifierBugCheckIfAppropriate+0xe0
- ffffba06`37807460 fffff804`2a69df0e : ffffd808`7d8fa690 ffffd808`7653ce50 00000000`00000001 ffffd808`7d8dfbc0 : nt!VfPoolCheckForLeaks+0x49
- ffffba06`378074a0 fffff804`2abda502 : 00000000`00518000 ffffd808`7653cdb0 fffff804`2ae26d50 fffff804`2ae26d50 : nt!VfTargetDriversRemove+0x136222
- ffffba06`37807520 fffff804`2a8e11f3 : ffffd808`7653cdb0 ffffba06`37807650 00000000`00000001 00000000`ffffffff : nt!VfDriverUnloadImage+0x3e
- ffffba06`37807550 fffff804`2a96b6f1 : 00000000`00000000 00000000`ffffffff ffff99d7`00000001 ffffa989`efafd1c0 : nt!MiUnloadSystemImage+0x2eb
- ffffba06`378076f0 fffff804`2a96b61e : ffffd808`765e17e0 ffffba06`37807940 00000000`00000000 00000000`00000000 : nt!MmUnloadSystemImage+0x41
- ffffba06`37807720 fffff804`2a8164f0 : ffffd808`765e17e0 ffffba06`37807940 ffffd808`765e17e0 fffff804`2a7ea27f : nt!IopDeleteDriver+0x4e
- ffffba06`37807770 fffff804`2a42eeb7 : 00000000`00000000 00000000`00000000 ffffba06`37807940 ffffd808`765e1810 : nt!ObpRemoveObjectRoutine+0x80
- ffffba06`378077d0 fffff804`2a40b98e : 00000000`00000008 00000000`00000000 ffffd808`765e17e0 00000000`c0000365 : nt!ObfDereferenceObjectWithTag+0xc7
- ffffba06`37807810 fffff804`2a934f5e : 00000000`00000008 00000000`00000008 00000000`c0000365 00000000`00001000 : nt!HalPutDmaAdapter+0xe
- ffffba06`37807840 fffff804`2ac6eb8f : ffffd808`7d9ff370 ffffd808`7d9ff370 ffffba06`37807a80 00000000`00000000 : nt!IopLoadDriver+0x76a
- ffffba06`37807a10 fffff804`2ac7dac2 : ffffffff`c0000365 ffffa989`efe30fc0 00000000`00000000 fffff804`28ac33e0 : nt!IopInitializeSystemDrivers+0x157
- ffffba06`37807ab0 fffff804`2a9ad05b : fffff804`28ac33e0 fffff804`2ae50fe8 fffff804`2a9ad020 fffff804`28ac33e0 : nt!IoInitSystem+0x2e
- ffffba06`37807ae0 fffff804`2a550735 : ffffd808`764d5040 fffff804`2a9ad020 fffff804`28ac33e0 00000000`00000000 : nt!Phase1Initialization+0x3b
- ffffba06`37807b10 fffff804`2a5ef1b8 : fffff804`28e7e180 ffffd808`764d5040 fffff804`2a5506e0 00000000`00000000 : nt!PspSystemThreadStartup+0x55
- ffffba06`37807b60 00000000`00000000 : ffffba06`37808000 ffffba06`37801000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
- fffff8042a5507b5-fffff8042a5507b6 2 bytes - nt!MiDeleteNonPagedPoolTail+45
- [ 80 fa:00 bb ]
- 2 errors : !nt (fffff8042a5507b5-fffff8042a5507b6)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-07-27T11:36:43.000Z
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #4: 3RD PARTY DRIVERS ======================
- Jun 29 2020 - vgk.sys - Vanguard Anti-Cheat driver
- ================== Dump #4: 3RD PARTY DRIVERS (FULL) ===================
- Image path: \??\C:\Program Files\Riot Vanguard\vgk.sys
- Image name: vgk.sys
- Search : https://www.google.com/search?q=vgk.sys
- ADA Info : Vanguard Anti-Cheat driver
- Timestamp : Mon Jun 29 2020
- ====================== Dump #4: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- IntelTA.sys Intel Telemetry Driver
- iorate.sys I/O rate control Filter (Microsoft)
- kd.dll Local Kernal Debugger (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- mcupdate_GenuineIntel.dll Intel Microcode Update Library (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- VerifierExt.sys Driver Verifier Extension
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- ====================== Dump #4: UNLOADED MODULES =======================
- fffff804`2bb00000 fffff804`2bb11000 WdBoot.sys
- fffff804`2cb80000 fffff804`2cb90000 hwpolicy.sys
- ====================== Dump #4: BIOS INFORMATION =======================
- sysinfo: could not find necessary interfaces.
- sysinfo: note that mssmbios.sys must be loaded (XPSP2+).
- ========================== Dump #4: Extra #1 ===========================
- 11: kd> !verifier
- Verify Flags Level 0x001209bb
- STANDARD FLAGS:
- [X] (0x00000000) Automatic Checks
- [X] (0x00000001) Special pool
- [X] (0x00000002) Force IRQL checking
- [X] (0x00000008) Pool tracking
- [X] (0x00000010) I/O verification
- [X] (0x00000020) Deadlock detection
- [X] (0x00000080) DMA checking
- [X] (0x00000100) Security checks
- [X] (0x00000800) Miscellaneous checks
- [X] (0x00020000) DDI compliance checking
- ADDITIONAL FLAGS:
- [ ] (0x00000004) Randomized low resources simulation
- [ ] (0x00000200) Force pending I/O requests
- [ ] (0x00000400) IRP logging
- [ ] (0x00002000) Invariant MDL checking for stack
- [ ] (0x00004000) Invariant MDL checking for driver
- [ ] (0x00008000) Power framework delay fuzzing
- [ ] (0x00010000) Port/miniport interface checking
- [ ] (0x00040000) Systematic low resources simulation
- [ ] (0x00080000) DDI compliance checking (additional)
- [ ] (0x00200000) NDIS/WIFI verification
- [ ] (0x00800000) Kernel synchronization delay fuzzing
- [ ] (0x01000000) VM switch verification
- [ ] (0x02000000) Code integrity checks
- RESERVED FLAGS (use of these flags is unsupported):
- [X] (0x00100000) Unused or reserved flag
- [X] Indicates flag is enabled
- Summary of All Verifier Statistics
- RaiseIrqls 0x1565
- AcquireSpinLocks 0x94d4
- Synch Executions 0x0
- Trims 0x966
- Pool Allocations Attempted 0x119bb
- Pool Allocations Succeeded 0x119bb
- Pool Allocations Succeeded SpecialPool 0x119bb
- Pool Allocations With NO TAG 0xa
- Pool Allocations Failed 0x0
- Current paged pool allocations 0x5bf for 0014315B bytes
- Peak paged pool allocations 0x66a for 00164AA3 bytes
- Current nonpaged pool allocations 0x1b3e for 00811696 bytes
- Peak nonpaged pool allocations 0x1b4a for 00CEDD56 bytes
- ========================== Dump #4: Extra #2 ===========================
- 11: kd> !thread
- THREAD ffffd808764d5040 Cid 0004.0008 Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor b
- Not impersonating
- GetUlongFromAddress: unable to read from fffff8042ae1b43c
- Owning Process ffffd808764cf040 Image: System
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 905
- Context Switch Count 2170 IdealProcessor: 0
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address nt!Phase1Initialization (0xfffff8042a9ad020)
- Stack Init ffffba0637807b90 Current ffffba06378071c0
- Base ffffba0637808000 Limit ffffba0637801000 Call 0000000000000000
- Priority 31 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- ffffba06`37807418 fffff804`2abe8e34 : 00000000`000000c4 00000000`00000062 ffffd808`7653cf98 ffffd808`7d8fa690 : nt!KeBugCheckEx
- ffffba06`37807420 fffff804`2abf8119 : ffffd808`7d8fa690 ffffba06`37807510 ffffd808`7653cdb0 ffffd808`7d8dfbe0 : nt!VerifierBugCheckIfAppropriate+0xe0
- ffffba06`37807460 fffff804`2a69df0e : ffffd808`7d8fa690 ffffd808`7653ce50 00000000`00000001 ffffd808`7d8dfbc0 : nt!VfPoolCheckForLeaks+0x49
- ffffba06`378074a0 fffff804`2abda502 : 00000000`00518000 ffffd808`7653cdb0 fffff804`2ae26d50 fffff804`2ae26d50 : nt!VfTargetDriversRemove+0x136222
- ffffba06`37807520 fffff804`2a8e11f3 : ffffd808`7653cdb0 ffffba06`37807650 00000000`00000001 00000000`ffffffff : nt!VfDriverUnloadImage+0x3e
- ffffba06`37807550 fffff804`2a96b6f1 : 00000000`00000000 00000000`ffffffff ffff99d7`00000001 ffffa989`efafd1c0 : nt!MiUnloadSystemImage+0x2eb
- ffffba06`378076f0 fffff804`2a96b61e : ffffd808`765e17e0 ffffba06`37807940 00000000`00000000 00000000`00000000 : nt!MmUnloadSystemImage+0x41
- ffffba06`37807720 fffff804`2a8164f0 : ffffd808`765e17e0 ffffba06`37807940 ffffd808`765e17e0 fffff804`2a7ea27f : nt!IopDeleteDriver+0x4e
- ffffba06`37807770 fffff804`2a42eeb7 : 00000000`00000000 00000000`00000000 ffffba06`37807940 ffffd808`765e1810 : nt!ObpRemoveObjectRoutine+0x80
- ffffba06`378077d0 fffff804`2a40b98e : 00000000`00000008 00000000`00000000 ffffd808`765e17e0 00000000`c0000365 : nt!ObfDereferenceObjectWithTag+0xc7
- ffffba06`37807810 fffff804`2a934f5e : 00000000`00000008 00000000`00000008 00000000`c0000365 00000000`00001000 : nt!HalPutDmaAdapter+0xe
- ffffba06`37807840 fffff804`2ac6eb8f : ffffd808`7d9ff370 ffffd808`7d9ff370 ffffba06`37807a80 00000000`00000000 : nt!IopLoadDriver+0x76a
- ffffba06`37807a10 fffff804`2ac7dac2 : ffffffff`c0000365 ffffa989`efe30fc0 00000000`00000000 fffff804`28ac33e0 : nt!IopInitializeSystemDrivers+0x157
- ffffba06`37807ab0 fffff804`2a9ad05b : fffff804`28ac33e0 fffff804`2ae50fe8 fffff804`2a9ad020 fffff804`28ac33e0 : nt!IoInitSystem+0x2e
- ffffba06`37807ae0 fffff804`2a550735 : ffffd808`764d5040 fffff804`2a9ad020 fffff804`28ac33e0 00000000`00000000 : nt!Phase1Initialization+0x3b
- ffffba06`37807b10 fffff804`2a5ef1b8 : fffff804`28e7e180 ffffd808`764d5040 fffff804`2a5506e0 00000000`00000000 : nt!PspSystemThreadStartup+0x55
- ffffba06`37807b60 00000000`00000000 : ffffba06`37808000 ffffba06`37801000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
Advertisement
Add Comment
Please, Sign In to add comment