Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ========================== AUTO DUMP ANALYZER ==========================
- Auto Dump Analyzer
- Version: 0.91
- Time to analyze file(s): 00 hours and 01 minutes and 34 seconds
- ================================ SYSTEM ================================
- MANUFACTURER: Acer
- PRODUCT_NAME: Aspire E5-551G
- SKU: [Removed]
- VERSION: V1.15
- ================================= BIOS =================================
- VENDOR: Insyde Corp.
- VERSION: V1.15
- DATE: 07/06/2015
- ============================= MOTHERBOARD ==============================
- MANUFACTURER: Acer
- PRODUCT: EA50_KV
- VERSION: V1.15
- ================================= RAM ==================================
- Size Speed Manufacturer Part No.
- -------------- -------------- ------------------- ----------------------
- 0MHz Empty Empty
- 8192MB 1600MHz Kingston ACR16D3LS1KNG/8G
- ================================= CPU ==================================
- Processor Version: AMD A10-7300 Radeon R6, 10 Compute Cores 4C+6G
- COUNT: 4
- MHZ: 1896
- VENDOR: AuthenticAMD
- FAMILY: 15
- MODEL: 30
- STEPPING: 1
- ================================== OS ==================================
- Product: WinNt, suite: TerminalServer SingleUserTS
- Built by: 19041.1.amd64fre.vb_release.191206-1406
- BUILD_VERSION: 10.0.19041.388 (WinBuild.160101.0800)
- BUILD: 19041
- SERVICEPACK: 388
- PLATFORM_TYPE: x64
- NAME: Windows 10
- EDITION: Windows 10 WinNt TerminalServer SingleUserTS
- BUILD_TIMESTAMP: unknown_date
- BUILDDATESTAMP: 160101.0800
- BUILDLAB: WinBuild
- BUILDOSVER: 10.0.19041.388
- =============================== DEBUGGER ===============================
- Microsoft (R) Windows Debugger Version 10.0.14321.1024 AMD64
- Copyright (c) Microsoft Corporation. All rights reserved.
- =============================== COMMENTS ===============================
- * Information gathered from different dump files may be different. If
- Windows updates between two dump files, two or more OS versions may
- be shown above.
- * If the user updates the BIOS between dump files, two or more versions
- and dates may be shown above.
- * More RAM information can be found below in a full BIOS section.
- ========================================================================
- ======================= Dump #1: ANALYZE VERBOSE =======================
- ====================== File: 072320-39203-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 19041 MP (4 procs) Free x64
- Kernel base = 0xfffff800`6540e000 PsLoadedModuleList = 0xfffff800`66038310
- Debug session time: Thu Jul 23 03:15:56.392 2020 (UTC - 4:00)
- System Uptime: 0 days 0:25:43.195
- BugCheck C4, {b9, 137347c0000, ffff8288df999210, 0}
- *** WARNING: Unable to verify timestamp for atikmpag.sys
- *** ERROR: Module load completed but symbols could not be loaded for atikmpag.sys
- *** WARNING: Unable to verify timestamp for win32k.sys
- *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
- Probably caused by : memory_corruption
- Followup: memory_corruption
- DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
- A device driver attempting to corrupt the system has been caught. This is
- because the driver was specified in the registry as being suspect (by the
- administrator) and the kernel has enabled substantial checking of this driver.
- If the driver attempts to corrupt the system, bugchecks 0xC4, 0xC1 and 0xA will
- be among the most commonly seen crashes.
- Arguments:
- Arg1: 00000000000000b9, subclass of driver violation.
- Arg2: 00000137347c0000
- Arg3: ffff8288df999210
- Arg4: 0000000000000000
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- BUGCHECK_STR: 0xc4_b9
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- PROCESS_NAME: System
- CURRENT_IRQL: 0
- LAST_CONTROL_TRANSFER: from fffff80065dece34 to fffff800657ebb60
- STACK_TEXT:
- ffffd183`50d6fd48 fffff800`65dece34 : 00000000`000000c4 00000000`000000b9 00000137`347c0000 ffff8288`df999210 : nt!KeBugCheckEx
- ffffd183`50d6fd50 fffff800`65e032e3 : ffff8288`df999210 00000000`00000000 00000000`00001fff 00000137`347c0000 : nt!VerifierBugCheckIfAppropriate+0xe0
- ffffd183`50d6fd90 fffff80d`57a2aac8 : ffff8288`e2472f80 ffff8288`e2472f80 00000000`00100cc0 ffff8288`e2400d40 : nt!VerifierMmUnmapLockedPages+0x173
- ffffd183`50d6fe00 ffff8288`e2472f80 : ffff8288`e2472f80 00000000`00100cc0 ffff8288`e2400d40 ffff8288`e2472f80 : atikmpag+0x2aac8
- ffffd183`50d6fe08 ffff8288`e2472f80 : 00000000`00100cc0 ffff8288`e2400d40 ffff8288`e2472f80 fffff80d`57a14ddd : 0xffff8288`e2472f80
- ffffd183`50d6fe10 00000000`00100cc0 : ffff8288`e2400d40 ffff8288`e2472f80 fffff80d`57a14ddd ffff8288`dd81b000 : 0xffff8288`e2472f80
- ffffd183`50d6fe18 ffff8288`e2400d40 : ffff8288`e2472f80 fffff80d`57a14ddd ffff8288`dd81b000 ffff8288`e2472f80 : 0x100cc0
- ffffd183`50d6fe20 ffff8288`e2472f80 : fffff80d`57a14ddd ffff8288`dd81b000 ffff8288`e2472f80 00000000`00000000 : 0xffff8288`e2400d40
- ffffd183`50d6fe28 fffff80d`57a14ddd : ffff8288`dd81b000 ffff8288`e2472f80 00000000`00000000 00001f80`00000000 : 0xffff8288`e2472f80
- ffffd183`50d6fe30 ffff8288`dd81b000 : ffff8288`e2472f80 00000000`00000000 00001f80`00000000 ffff8288`dfe1b8a0 : atikmpag+0x14ddd
- ffffd183`50d6fe38 ffff8288`e2472f80 : 00000000`00000000 00001f80`00000000 ffff8288`dfe1b8a0 fffff80d`583fc3a6 : 0xffff8288`dd81b000
- ffffd183`50d6fe40 00000000`00000000 : 00001f80`00000000 ffff8288`dfe1b8a0 fffff80d`583fc3a6 ffff8288`e40fadb0 : 0xffff8288`e2472f80
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
- fffff80065792f3e-fffff80065792f41 4 bytes - nt!MiFreeUltraMapping+32
- [ a0 7d fb f6:00 20 40 80 ]
- 4 errors : !nt (fffff80065792f3e-fffff80065792f41)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-07-23T07:15:56.000Z
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #1: 3RD PARTY DRIVERS ======================
- Mar 31 2015 - HWiNFO64A.SYS - HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
- May 25 2015 - amdkmpfd.sys - AMD Kernel Miniport Filter driver
- Jun 29 2015 - btfilter.sys - Qualcomm Atheros BT Filter driver https://www.qualcomm.com/
- Jul 29 2015 - SynRMIHID.sys - Synaptics I2C Driver (Synaptics Incorporated) https://www.symantec.com/
- Mar 13 2018 - athw10x.sys - Qualcomm Atheros Extensible Wireless LAN device driver
- May 09 2018 - RtsPer.sys - Realtek RTS PCIE Reader driver https://www.realtek.com/en/
- Jul 02 2019 - RTKVHD64.sys - Realtek Audio System driver https://www.realtek.com/en/
- Aug 16 2019 - atikmdag.sys - ATI Radeon Kernel Mode driver
- Aug 16 2019 - atikmpag.sys - ATI video card driver
- Nov 20 2019 - mbamswissarmy.sys - MalwareBytes Anti-Malware system driver https://www.malwarebytes.com/
- May 26 2020 - rt640x64.sys - Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Jun 01 2020 - AtihdWT6.sys - AMD High Definition Audio Function driver http://support.amd.com/
- Jun 02 2020 - amdxe.sys - AMD Link Xinput Emulation driver
- Jun 09 2020 - amdfendr.sys - AMD Crash Defender Service driver
- ================== Dump #1: 3RD PARTY DRIVERS (FULL) ===================
- Image path: \??\C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS
- Image name: HWiNFO64A.SYS
- Search : https://www.google.com/search?q=HWiNFO64A.SYS
- ADA Info : HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
- Timestamp : Tue Mar 31 2015
- Image path: \SystemRoot\System32\drivers\amdkmpfd.sys
- Image name: amdkmpfd.sys
- Search : https://www.google.com/search?q=amdkmpfd.sys
- ADA Info : AMD Kernel Miniport Filter driver
- Timestamp : Mon May 25 2015
- Image path: \SystemRoot\system32\DRIVERS\btfilter.sys
- Image name: btfilter.sys
- Search : https://www.google.com/search?q=btfilter.sys
- ADA Info : Qualcomm Atheros BT Filter driver https://www.qualcomm.com/
- Timestamp : Mon Jun 29 2015
- Image path: \SystemRoot\system32\DRIVERS\SynRMIHID.sys
- Image name: SynRMIHID.sys
- Search : https://www.google.com/search?q=SynRMIHID.sys
- ADA Info : Synaptics I2C Driver (Synaptics Incorporated) https://www.symantec.com/
- Timestamp : Wed Jul 29 2015
- Image path: \SystemRoot\System32\drivers\athw10x.sys
- Image name: athw10x.sys
- Search : https://www.google.com/search?q=athw10x.sys
- ADA Info : Qualcomm Atheros Extensible Wireless LAN device driver
- Timestamp : Tue Mar 13 2018
- Image path: \SystemRoot\system32\DRIVERS\RtsPer.sys
- Image name: RtsPer.sys
- Search : https://www.google.com/search?q=RtsPer.sys
- ADA Info : Realtek RTS PCIE Reader driver https://www.realtek.com/en/
- Timestamp : Wed May 9 2018
- Image path: \SystemRoot\system32\drivers\RTKVHD64.sys
- Image name: RTKVHD64.sys
- Search : https://www.google.com/search?q=RTKVHD64.sys
- ADA Info : Realtek Audio System driver https://www.realtek.com/en/
- Timestamp : Tue Jul 2 2019
- Image path: \SystemRoot\System32\DriverStore\FileRepository\u0346830.inf_amd64_35731e557194973d\B345901\atikmdag.sys
- Image name: atikmdag.sys
- Search : https://www.google.com/search?q=atikmdag.sys
- ADA Info : ATI Radeon Kernel Mode driver
- Timestamp : Fri Aug 16 2019
- Image path: \SystemRoot\System32\DriverStore\FileRepository\u0346830.inf_amd64_35731e557194973d\B345901\atikmpag.sys
- Image name: atikmpag.sys
- Search : https://www.google.com/search?q=atikmpag.sys
- ADA Info : ATI video card driver
- Timestamp : Fri Aug 16 2019
- Image path: \SystemRoot\System32\Drivers\mbamswissarmy.sys
- Image name: mbamswissarmy.sys
- Search : https://www.google.com/search?q=mbamswissarmy.sys
- ADA Info : MalwareBytes Anti-Malware system driver https://www.malwarebytes.com/
- Timestamp : Wed Nov 20 2019
- Image path: \SystemRoot\System32\drivers\rt640x64.sys
- Image name: rt640x64.sys
- Search : https://www.google.com/search?q=rt640x64.sys
- ADA Info : Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Timestamp : Tue May 26 2020
- Image path: \SystemRoot\system32\drivers\AtihdWT6.sys
- Image name: AtihdWT6.sys
- Search : https://www.google.com/search?q=AtihdWT6.sys
- ADA Info : AMD High Definition Audio Function driver http://support.amd.com/
- Timestamp : Mon Jun 1 2020
- Image path: \SystemRoot\System32\drivers\amdxe.sys
- Image name: amdxe.sys
- Search : https://www.google.com/search?q=amdxe.sys
- ADA Info : AMD Link Xinput Emulation driver
- Timestamp : Tue Jun 2 2020
- Image path: \SystemRoot\system32\DRIVERS\amdfendr.sys
- Image name: amdfendr.sys
- Search : https://www.google.com/search?q=amdfendr.sys
- ADA Info : AMD Crash Defender Service driver
- Timestamp : Tue Jun 9 2020
- ====================== Dump #1: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- amdppm.sys Processor Device Driver
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- BATTC.SYS Battery Class driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- BTHport.sys Bluetooth Bus driver (Microsoft)
- BTHUSB.sys Bluetooth Miniport driver (Microsoft)
- CAD.sys Charge Arbiration driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CimFS.SYS Consumer IR Class Driver for eHome (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- CmBatt.sys Control Method Battery driver (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- csc.sys Windows Client Side Caching driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- i8042prt.sys i8042 Keyboard / PS/2 Mouse driver (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- IntelTA.sys Intel Telemetry Driver
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kd.dll Local Kernal Debugger (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate_AuthenticAMD.dll AMD Microcode Update Library (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- MpKslDrv.sys Microsoft Anti-malware Protection driver
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msquic.sys Windows QUIC Driver
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- MTConfig.sys Microsoft Multi-Touch HID Driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndiscap.sys Microsoft NDIS Packet Capture Filter Driver
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- ndisuio.sys NDIS User mode I/O driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- nwifi.sys NativeWiFi Miniport Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- ucx01000.sys USB Controller Extension (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- usbehci.sys EHCI eUSB Miniport Driver (Microsoft)
- usbhub.sys Default Hub Driver for USB (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- usbohci.sys OHCI USB Miniport Driver (Microsoft)
- USBPORT.SYS USB 1.1 & 2.0 Port Driver (Microsoft)
- usbvideo.sys USB Video Class Driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- VerifierExt.sys Driver Verifier Extension
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwifibus.sys Virtual Wireless Bus driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- vwifimp.sys Virtual WiFi Miniport Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- ====================== Dump #1: UNLOADED MODULES =======================
- fffff80d`59570000 fffff80d`5958c000 monitor.sys
- fffff80d`57860000 fffff80d`57871000 MSKSSRV.sys
- fffff80d`59700000 fffff80d`59711000 MSKSSRV.sys
- fffff80d`57870000 fffff80d`5787f000 dump_storpor
- fffff80d`578c0000 fffff80d`578f3000 dump_storahc
- fffff80d`57920000 fffff80d`5793e000 dump_dumpfve
- fffff80d`59300000 fffff80d`5930c000 WdmCompanion
- fffff80d`58200000 fffff80d`5821c000 dam.sys
- fffff800`669e0000 fffff800`669f1000 WdBoot.sys
- fffff800`669d0000 fffff800`669d9000 MbamElam.sys
- fffff800`67c00000 fffff800`67c10000 hwpolicy.sys
- ====================== Dump #1: BIOS INFORMATION =======================
- [SMBIOS Data Tables v2.8]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 1471 bytes]
- [BIOS Information (Type 0) - Length 24 - Handle 0000h]
- Vendor Insyde Corp.
- BIOS Version V1.15
- BIOS Starting Address Segment e000
- BIOS Release Date 07/06/2015
- BIOS ROM Size 800000
- BIOS Characteristics
- 07: - PCI Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 19: - EDD Supported
- 20: - NEC 9800 J-Floppy Supported
- 21: - Toshiba J-Floppy Supported
- 22: - 360KB Floppy Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 27: - Keyboard Services Supported
- 30: - CGA/Mono Services Supported
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 1
- BIOS Minor Revision 15
- EC Firmware Major Revision 1
- EC Firmware Minor Revision 15
- [System Information (Type 1) - Length 27 - Handle 0001h]
- Manufacturer Acer
- Product Name Aspire E5-551G
- Version V1.15
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- SKUNumber Aspire E5-551G_086A_V1.15
- Family KV
- [BaseBoard Information (Type 2) - Length 16 - Handle 0002h]
- Manufacturer Acer
- Product EA50_KV
- Version V1.15
- Feature Flags 09h
- -1877821728: - -1877821680: - «?Íû
- Location Base Board Chassis Location
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 23 - Handle 0003h]
- Manufacturer Acer
- Chassis Type Notebook
- Version Chassis Version
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 0
- [Processor Information (Type 4) - Length 42 - Handle 0004h]
- Socket Designation Socket FP3
- Processor Type Central Processor
- Processor Family 48h - Specification Reserved
- Processor Manufacturer AMD processor
- Processor ID 010f6300fffb8b17
- Processor Version AMD A10-7300 Radeon R6, 10 Compute Cores 4C+6G
- Processor Voltage 8ah - 1.0V
- External Clock 100MHz
- Max Speed 1900MHz
- Current Speed 1900MHz
- Status Enabled Populated
- Processor Upgrade None
- L1 Cache Handle 0005h
- L2 Cache Handle 0006h
- L3 Cache Handle [Not Present]
- Part Number FFFF
- [Cache Information (Type 7) - Length 19 - Handle 0005h]
- Socket Designation L1 Cache
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0100h - 256K
- Installed Size 0100h - 256K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 2-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0006h]
- Socket Designation L2 Cache
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 8040h - 4096K
- Installed Size 8040h - 4096K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 16-way Set-Associative
- [Onboard Devices Information (Type 10) - Length 6 - Handle 0007h]
- Number of Devices 1
- 01: Type Video [enabled]
- 01: Description Video Graphics Controller
- [Onboard Devices Information (Type 10) - Length 6 - Handle 0008h]
- Number of Devices 1
- 01: Type Ethernet [enabled]
- 01: Description Realtek Lan Controller
- [OEM Strings (Type 11) - Length 5 - Handle 0009h]
- Number of Strings 5
- 1 Acer System
- 2 String2 for Original Equipment Manufacturer
- 3 String3 for Original Equipment Manufacturer
- 4 String4 for Original Equipment Manufacturer
- 5 String5 for Original Equipment Manufacturer
- [System Configuration Options (Type 12) - Length 5 - Handle 000ah]
- [Physical Memory Array (Type 16) - Length 23 - Handle 000bh]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 33554432KB
- Number of Memory Devices 2
- [Memory Device (Type 17) - Length 40 - Handle 000ch]
- Physical Memory Array Handle 000bh
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 00h - Specification Reserved
- Device Locator DIMM 0
- Bank Locator CHANNEL A
- Memory Type 02h - Unknown
- Type Detail 0004h - Unknown
- Speed 0MHz
- Manufacturer Empty
- Part Number Empty
- [Memory Device (Type 17) - Length 40 - Handle 000dh]
- Physical Memory Array Handle 000bh
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 0dh - SODIMM
- Device Locator DIMM 0
- Bank Locator CHANNEL B
- Memory Type 18h - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 1600MHz
- Manufacturer Kingston
- Part Number ACR16D3LS1KNG/8G
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 000eh]
- Starting Address 00000000h
- Ending Address 007fffffh
- Memory Array Handle 000bh
- Partition Width 255
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 000fh]
- Starting Address 00000000h
- Ending Address 007fffffh
- Memory Device Handle 000dh
- Mem Array Mapped Adr Handle 000eh
- ========================== Dump #1: Extra #1 ===========================
- 0: kd> !verifier
- Verify Flags Level 0x0012892b
- STANDARD FLAGS:
- [X] (0x00000000) Automatic Checks
- [X] (0x00000001) Special pool
- [X] (0x00000002) Force IRQL checking
- [X] (0x00000008) Pool tracking
- [ ] (0x00000010) I/O verification
- [X] (0x00000020) Deadlock detection
- [ ] (0x00000080) DMA checking
- [X] (0x00000100) Security checks
- [X] (0x00000800) Miscellaneous checks
- [X] (0x00020000) DDI compliance checking
- ADDITIONAL FLAGS:
- [ ] (0x00000004) Randomized low resources simulation
- [ ] (0x00000200) Force pending I/O requests
- [ ] (0x00000400) IRP logging
- [ ] (0x00002000) Invariant MDL checking for stack
- [ ] (0x00004000) Invariant MDL checking for driver
- [X] (0x00008000) Power framework delay fuzzing
- [ ] (0x00010000) Port/miniport interface checking
- [ ] (0x00040000) Systematic low resources simulation
- [ ] (0x00080000) DDI compliance checking (additional)
- [ ] (0x00200000) NDIS/WIFI verification
- [ ] (0x00800000) Kernel synchronization delay fuzzing
- [ ] (0x01000000) VM switch verification
- [ ] (0x02000000) Code integrity checks
- RESERVED FLAGS (use of these flags is unsupported):
- [X] (0x00100000) Unused or reserved flag
- [X] Indicates flag is enabled
- Summary of All Verifier Statistics
- RaiseIrqls 0x2
- AcquireSpinLocks 0x3d291
- Synch Executions 0x0
- Trims 0x327
- Pool Allocations Attempted 0x16ea3
- Pool Allocations Succeeded 0x16ea3
- Pool Allocations Succeeded SpecialPool 0x16ea3
- Pool Allocations With NO TAG 0x15
- Pool Allocations Failed 0x0
- Current paged pool allocations 0x2a1c for 0056BE9A bytes
- Peak paged pool allocations 0x3406 for 021E101A bytes
- Current nonpaged pool allocations 0xa2e for 007ADCA0 bytes
- Peak nonpaged pool allocations 0xf9b for 009ED5C0 bytes
- ========================== Dump #1: Extra #2 ===========================
- 0: kd> !thread
- THREAD ffff8288e4a29040 Cid 0004.206c Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor 0
- IRP List:
- ffff8288e45ec8e0: (0006,03a0) Flags: 00000000 Mdl: 00000000
- Not impersonating
- GetUlongFromAddress: unable to read from fffff8006601f43c
- Owning Process ffff8288d9881080 Image: System
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 98764
- Context Switch Count 8970 IdealProcessor: 2
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address nt!ExpWorkerThread (0xfffff80065641e40)
- Stack Init ffffd18350d70c90 Current ffffd18350d6fc00
- Base ffffd18350d71000 Limit ffffd18350d6b000 Call 0000000000000000
- Priority 15 BasePriority 12 PriorityDecrement 0 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- ffffd183`50d6fd48 fffff800`65dece34 : 00000000`000000c4 00000000`000000b9 00000137`347c0000 ffff8288`df999210 : nt!KeBugCheckEx
- ffffd183`50d6fd50 fffff800`65e032e3 : ffff8288`df999210 00000000`00000000 00000000`00001fff 00000137`347c0000 : nt!VerifierBugCheckIfAppropriate+0xe0
- ffffd183`50d6fd90 fffff80d`57a2aac8 : ffff8288`e2472f80 ffff8288`e2472f80 00000000`00100cc0 ffff8288`e2400d40 : nt!VerifierMmUnmapLockedPages+0x173
- ffffd183`50d6fe00 ffff8288`e2472f80 : ffff8288`e2472f80 00000000`00100cc0 ffff8288`e2400d40 ffff8288`e2472f80 : atikmpag+0x2aac8
- ffffd183`50d6fe08 ffff8288`e2472f80 : 00000000`00100cc0 ffff8288`e2400d40 ffff8288`e2472f80 fffff80d`57a14ddd : 0xffff8288`e2472f80
- ffffd183`50d6fe10 00000000`00100cc0 : ffff8288`e2400d40 ffff8288`e2472f80 fffff80d`57a14ddd ffff8288`dd81b000 : 0xffff8288`e2472f80
- ffffd183`50d6fe18 ffff8288`e2400d40 : ffff8288`e2472f80 fffff80d`57a14ddd ffff8288`dd81b000 ffff8288`e2472f80 : 0x100cc0
- ffffd183`50d6fe20 ffff8288`e2472f80 : fffff80d`57a14ddd ffff8288`dd81b000 ffff8288`e2472f80 00000000`00000000 : 0xffff8288`e2400d40
- ffffd183`50d6fe28 fffff80d`57a14ddd : ffff8288`dd81b000 ffff8288`e2472f80 00000000`00000000 00001f80`00000000 : 0xffff8288`e2472f80
- ffffd183`50d6fe30 ffff8288`dd81b000 : ffff8288`e2472f80 00000000`00000000 00001f80`00000000 ffff8288`dfe1b8a0 : atikmpag+0x14ddd
- ffffd183`50d6fe38 ffff8288`e2472f80 : 00000000`00000000 00001f80`00000000 ffff8288`dfe1b8a0 fffff80d`583fc3a6 : 0xffff8288`dd81b000
- ffffd183`50d6fe40 00000000`00000000 : 00001f80`00000000 ffff8288`dfe1b8a0 fffff80d`583fc3a6 ffff8288`e40fadb0 : 0xffff8288`e2472f80
- ========================================================================
- ======================= Dump #2: ANALYZE VERBOSE =======================
- ====================== File: 072320-33953-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 19041 MP (4 procs) Free x64
- Kernel base = 0xfffff804`7640a000 PsLoadedModuleList = 0xfffff804`77034310
- Debug session time: Wed Jul 22 09:37:55.508 2020 (UTC - 4:00)
- System Uptime: 0 days 3:00:15.760
- BugCheck A, {4000002, 2, 0, fffff80476640cc4}
- *** WARNING: Unable to verify timestamp for win32k.sys
- *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
- Probably caused by : memory_corruption
- Followup: memory_corruption
- IRQL_NOT_LESS_OR_EQUAL (a)
- An attempt was made to access a pageable (or completely invalid) address at an
- interrupt request level (IRQL) that is too high. This is usually
- caused by drivers using improper addresses.
- If a kernel debugger is available get the stack backtrace.
- Arguments:
- Arg1: 0000000004000002, memory referenced
- Arg2: 0000000000000002, IRQL
- Arg3: 0000000000000000, bitfield :
- bit 0 : value 0 = read operation, 1 = write operation
- bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
- Arg4: fffff80476640cc4, address which referenced memory
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- READ_ADDRESS: fffff80477104388: Unable to get MiVisibleState
- 0000000004000002
- CURRENT_IRQL: 2
- FAULTING_IP:
- nt!KiTimerWaitTest+1f4
- fffff804`76640cc4 0fb74602 movzx eax,word ptr [rsi+2]
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- BUGCHECK_STR: AV
- PROCESS_NAME: System
- TRAP_FRAME: fffff80478e6b6a0 -- (.trap 0xfffff80478e6b6a0)
- NOTE: The trap frame does not contain all registers.
- Some register values may be zeroed or incorrect.
- rax=0000000000000001 rbx=0000000000000000 rcx=0000000000000005
- rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
- rip=fffff80476640cc4 rsp=fffff80478e6b830 rbp=0000000000000002
- r8=0000000000000000 r9=0000000000000000 r10=0000000000000000
- r11=fffff80478e6b8c0 r12=0000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=0000000000000000
- iopl=0 nv up ei pl nz na pe nc
- nt!KiTimerWaitTest+0x1f4:
- fffff804`76640cc4 0fb74602 movzx eax,word ptr [rsi+2] ds:00000000`00000002=????
- Resetting default scope
- LAST_CONTROL_TRANSFER: from fffff804767f9a29 to fffff804767e7b60
- STACK_TEXT:
- fffff804`78e6b558 fffff804`767f9a29 : 00000000`0000000a 00000000`04000002 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
- fffff804`78e6b560 fffff804`767f5d29 : ffffffff`fff9e580 00000000`00000002 ffffffff`fff9e580 ffffc586`0da20100 : nt!KiBugCheckDispatch+0x69
- fffff804`78e6b6a0 fffff804`76640cc4 : ffff9a87`507c6b88 fffff804`00000000 00000000`00000002 00000000`04000000 : nt!KiPageFault+0x469
- fffff804`78e6b830 fffff804`7664085c : ffff9a87`507c6b80 00000000`00000002 fffff804`78e6bb18 ffffc586`0e0ee180 : nt!KiTimerWaitTest+0x1f4
- fffff804`78e6b8e0 fffff804`76643d8d : 00000000`00000000 00000000`00000000 00000000`00140001 00000000`00064bc4 : nt!KiProcessExpiredTimerList+0xdc
- fffff804`78e6b9d0 fffff804`767eb6ce : 00000000`00000000 fffff804`74f42180 fffff804`77130600 ffffc586`1a61f040 : nt!KiRetireDpcList+0x5dd
- fffff804`78e6bc60 00000000`00000000 : fffff804`78e6c000 fffff804`78e66000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x9e
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
- fffff804767507b5-fffff804767507b6 2 bytes - nt!MiDeleteNonPagedPoolTail+45
- [ 80 fa:00 ef ]
- fffff8047678ef3e-fffff8047678ef41 4 bytes - nt!MiFreeUltraMapping+32 (+0x3e789)
- [ a0 7d fb f6:60 f5 ea d5 ]
- 6 errors : !nt (fffff804767507b5-fffff8047678ef41)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-07-22T13:37:55.000Z
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #2: 3RD PARTY DRIVERS ======================
- Mar 31 2015 - HWiNFO64A.SYS - HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
- May 25 2015 - amdkmpfd.sys - AMD Kernel Miniport Filter driver
- Jun 29 2015 - btfilter.sys - Qualcomm Atheros BT Filter driver https://www.qualcomm.com/
- Jul 29 2015 - SynRMIHID.sys - Synaptics I2C Driver (Synaptics Incorporated) https://www.symantec.com/
- Mar 13 2018 - athw10x.sys - Qualcomm Atheros Extensible Wireless LAN device driver
- May 09 2018 - RtsPer.sys - Realtek RTS PCIE Reader driver https://www.realtek.com/en/
- Jul 02 2019 - RTKVHD64.sys - Realtek Audio System driver https://www.realtek.com/en/
- Aug 16 2019 - atikmdag.sys - ATI Radeon Kernel Mode driver
- Aug 16 2019 - atikmpag.sys - ATI video card driver
- Nov 20 2019 - mbamswissarmy.sys - MalwareBytes Anti-Malware system driver https://www.malwarebytes.com/
- May 26 2020 - rt640x64.sys - Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Jun 01 2020 - AtihdWT6.sys - AMD High Definition Audio Function driver http://support.amd.com/
- ================== Dump #2: 3RD PARTY DRIVERS (FULL) ===================
- Image path: \??\C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS
- Image name: HWiNFO64A.SYS
- Search : https://www.google.com/search?q=HWiNFO64A.SYS
- ADA Info : HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
- Timestamp : Tue Mar 31 2015
- Image path: \SystemRoot\System32\drivers\amdkmpfd.sys
- Image name: amdkmpfd.sys
- Search : https://www.google.com/search?q=amdkmpfd.sys
- ADA Info : AMD Kernel Miniport Filter driver
- Timestamp : Mon May 25 2015
- Image path: \SystemRoot\system32\DRIVERS\btfilter.sys
- Image name: btfilter.sys
- Search : https://www.google.com/search?q=btfilter.sys
- ADA Info : Qualcomm Atheros BT Filter driver https://www.qualcomm.com/
- Timestamp : Mon Jun 29 2015
- Image path: \SystemRoot\system32\DRIVERS\SynRMIHID.sys
- Image name: SynRMIHID.sys
- Search : https://www.google.com/search?q=SynRMIHID.sys
- ADA Info : Synaptics I2C Driver (Synaptics Incorporated) https://www.symantec.com/
- Timestamp : Wed Jul 29 2015
- Image path: \SystemRoot\System32\drivers\athw10x.sys
- Image name: athw10x.sys
- Search : https://www.google.com/search?q=athw10x.sys
- ADA Info : Qualcomm Atheros Extensible Wireless LAN device driver
- Timestamp : Tue Mar 13 2018
- Image path: \SystemRoot\system32\DRIVERS\RtsPer.sys
- Image name: RtsPer.sys
- Search : https://www.google.com/search?q=RtsPer.sys
- ADA Info : Realtek RTS PCIE Reader driver https://www.realtek.com/en/
- Timestamp : Wed May 9 2018
- Image path: \SystemRoot\system32\drivers\RTKVHD64.sys
- Image name: RTKVHD64.sys
- Search : https://www.google.com/search?q=RTKVHD64.sys
- ADA Info : Realtek Audio System driver https://www.realtek.com/en/
- Timestamp : Tue Jul 2 2019
- Image path: \SystemRoot\System32\DriverStore\FileRepository\u0346830.inf_amd64_35731e557194973d\B345901\atikmdag.sys
- Image name: atikmdag.sys
- Search : https://www.google.com/search?q=atikmdag.sys
- ADA Info : ATI Radeon Kernel Mode driver
- Timestamp : Fri Aug 16 2019
- Image path: \SystemRoot\System32\DriverStore\FileRepository\u0346830.inf_amd64_35731e557194973d\B345901\atikmpag.sys
- Image name: atikmpag.sys
- Search : https://www.google.com/search?q=atikmpag.sys
- ADA Info : ATI video card driver
- Timestamp : Fri Aug 16 2019
- Image path: \SystemRoot\System32\Drivers\mbamswissarmy.sys
- Image name: mbamswissarmy.sys
- Search : https://www.google.com/search?q=mbamswissarmy.sys
- ADA Info : MalwareBytes Anti-Malware system driver https://www.malwarebytes.com/
- Timestamp : Wed Nov 20 2019
- Image path: \SystemRoot\System32\drivers\rt640x64.sys
- Image name: rt640x64.sys
- Search : https://www.google.com/search?q=rt640x64.sys
- ADA Info : Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Timestamp : Tue May 26 2020
- Image path: \SystemRoot\system32\drivers\AtihdWT6.sys
- Image name: AtihdWT6.sys
- Search : https://www.google.com/search?q=AtihdWT6.sys
- ADA Info : AMD High Definition Audio Function driver http://support.amd.com/
- Timestamp : Mon Jun 1 2020
- ====================== Dump #2: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- amdppm.sys Processor Device Driver
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- BATTC.SYS Battery Class driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- BTHport.sys Bluetooth Bus driver (Microsoft)
- BTHUSB.sys Bluetooth Miniport driver (Microsoft)
- CAD.sys Charge Arbiration driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CimFS.SYS Consumer IR Class Driver for eHome (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- CmBatt.sys Control Method Battery driver (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- csc.sys Windows Client Side Caching driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- i8042prt.sys i8042 Keyboard / PS/2 Mouse driver (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- IntelTA.sys Intel Telemetry Driver
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kd.dll Local Kernal Debugger (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate_AuthenticAMD.dll AMD Microcode Update Library (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- MpKslDrv.sys Microsoft Anti-malware Protection driver
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msquic.sys Windows QUIC Driver
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- MTConfig.sys Microsoft Multi-Touch HID Driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndiscap.sys Microsoft NDIS Packet Capture Filter Driver
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- ndisuio.sys NDIS User mode I/O driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- nwifi.sys NativeWiFi Miniport Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- ucx01000.sys USB Controller Extension (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- usbehci.sys EHCI eUSB Miniport Driver (Microsoft)
- usbhub.sys Default Hub Driver for USB (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- usbohci.sys OHCI USB Miniport Driver (Microsoft)
- USBPORT.SYS USB 1.1 & 2.0 Port Driver (Microsoft)
- usbvideo.sys USB Video Class Driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- VerifierExt.sys Driver Verifier Extension
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwifibus.sys Virtual Wireless Bus driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- vwifimp.sys Virtual WiFi Miniport Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- ====================== Dump #2: UNLOADED MODULES =======================
- fffff80f`73710000 fffff80f`73721000 MSKSSRV.sys
- fffff80f`72a60000 fffff80f`72a6f000 dump_storpor
- fffff80f`72ab0000 fffff80f`72ae3000 dump_storahc
- fffff80f`72b10000 fffff80f`72b2e000 dump_dumpfve
- fffff80f`77b90000 fffff80f`77b9c000 WdmCompanion
- fffff80f`73710000 fffff80f`7372c000 dam.sys
- fffff804`779e0000 fffff804`779f1000 WdBoot.sys
- fffff804`779d0000 fffff804`779d9000 MbamElam.sys
- fffff804`78c00000 fffff804`78c10000 hwpolicy.sys
- ====================== Dump #2: BIOS INFORMATION =======================
- [SMBIOS Data Tables v2.8]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 1471 bytes]
- [BIOS Information (Type 0) - Length 24 - Handle 0000h]
- Vendor Insyde Corp.
- BIOS Version V1.15
- BIOS Starting Address Segment e000
- BIOS Release Date 07/06/2015
- BIOS ROM Size 800000
- BIOS Characteristics
- 07: - PCI Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 19: - EDD Supported
- 20: - NEC 9800 J-Floppy Supported
- 21: - Toshiba J-Floppy Supported
- 22: - 360KB Floppy Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 27: - Keyboard Services Supported
- 30: - CGA/Mono Services Supported
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 1
- BIOS Minor Revision 15
- EC Firmware Major Revision 1
- EC Firmware Minor Revision 15
- [System Information (Type 1) - Length 27 - Handle 0001h]
- Manufacturer Acer
- Product Name Aspire E5-551G
- Version V1.15
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- SKUNumber Aspire E5-551G_086A_V1.15
- Family KV
- [BaseBoard Information (Type 2) - Length 16 - Handle 0002h]
- Manufacturer Acer
- Product EA50_KV
- Version V1.15
- Feature Flags 09h
- -1856522528: - -1856522480: - «?Íû
- Location Base Board Chassis Location
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 23 - Handle 0003h]
- Manufacturer Acer
- Chassis Type Notebook
- Version Chassis Version
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 0
- [Processor Information (Type 4) - Length 42 - Handle 0004h]
- Socket Designation Socket FP3
- Processor Type Central Processor
- Processor Family 48h - Specification Reserved
- Processor Manufacturer AMD processor
- Processor ID 010f6300fffb8b17
- Processor Version AMD A10-7300 Radeon R6, 10 Compute Cores 4C+6G
- Processor Voltage 8ah - 1.0V
- External Clock 100MHz
- Max Speed 1900MHz
- Current Speed 1900MHz
- Status Enabled Populated
- Processor Upgrade None
- L1 Cache Handle 0005h
- L2 Cache Handle 0006h
- L3 Cache Handle [Not Present]
- Part Number FFFF
- [Cache Information (Type 7) - Length 19 - Handle 0005h]
- Socket Designation L1 Cache
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0100h - 256K
- Installed Size 0100h - 256K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 2-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0006h]
- Socket Designation L2 Cache
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 8040h - 4096K
- Installed Size 8040h - 4096K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 16-way Set-Associative
- [Onboard Devices Information (Type 10) - Length 6 - Handle 0007h]
- Number of Devices 1
- 01: Type Video [enabled]
- 01: Description Video Graphics Controller
- [Onboard Devices Information (Type 10) - Length 6 - Handle 0008h]
- Number of Devices 1
- 01: Type Ethernet [enabled]
- 01: Description Realtek Lan Controller
- [OEM Strings (Type 11) - Length 5 - Handle 0009h]
- Number of Strings 5
- 1 Acer System
- 2 String2 for Original Equipment Manufacturer
- 3 String3 for Original Equipment Manufacturer
- 4 String4 for Original Equipment Manufacturer
- 5 String5 for Original Equipment Manufacturer
- [System Configuration Options (Type 12) - Length 5 - Handle 000ah]
- [Physical Memory Array (Type 16) - Length 23 - Handle 000bh]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 33554432KB
- Number of Memory Devices 2
- [Memory Device (Type 17) - Length 40 - Handle 000ch]
- Physical Memory Array Handle 000bh
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 00h - Specification Reserved
- Device Locator DIMM 0
- Bank Locator CHANNEL A
- Memory Type 02h - Unknown
- Type Detail 0004h - Unknown
- Speed 0MHz
- Manufacturer Empty
- Part Number Empty
- [Memory Device (Type 17) - Length 40 - Handle 000dh]
- Physical Memory Array Handle 000bh
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 0dh - SODIMM
- Device Locator DIMM 0
- Bank Locator CHANNEL B
- Memory Type 18h - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 1600MHz
- Manufacturer Kingston
- Part Number ACR16D3LS1KNG/8G
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 000eh]
- Starting Address 00000000h
- Ending Address 007fffffh
- Memory Array Handle 000bh
- Partition Width 255
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 000fh]
- Starting Address 00000000h
- Ending Address 007fffffh
- Memory Device Handle 000dh
- Mem Array Mapped Adr Handle 000eh
- ========================== Dump #2: Extra #1 ===========================
- 0: kd> !verifier
- Verify Flags Level 0x0012892b
- STANDARD FLAGS:
- [X] (0x00000000) Automatic Checks
- [X] (0x00000001) Special pool
- [X] (0x00000002) Force IRQL checking
- [X] (0x00000008) Pool tracking
- [ ] (0x00000010) I/O verification
- [X] (0x00000020) Deadlock detection
- [ ] (0x00000080) DMA checking
- [X] (0x00000100) Security checks
- [X] (0x00000800) Miscellaneous checks
- [X] (0x00020000) DDI compliance checking
- ADDITIONAL FLAGS:
- [ ] (0x00000004) Randomized low resources simulation
- [ ] (0x00000200) Force pending I/O requests
- [ ] (0x00000400) IRP logging
- [ ] (0x00002000) Invariant MDL checking for stack
- [ ] (0x00004000) Invariant MDL checking for driver
- [X] (0x00008000) Power framework delay fuzzing
- [ ] (0x00010000) Port/miniport interface checking
- [ ] (0x00040000) Systematic low resources simulation
- [ ] (0x00080000) DDI compliance checking (additional)
- [ ] (0x00200000) NDIS/WIFI verification
- [ ] (0x00800000) Kernel synchronization delay fuzzing
- [ ] (0x01000000) VM switch verification
- [ ] (0x02000000) Code integrity checks
- RESERVED FLAGS (use of these flags is unsupported):
- [X] (0x00100000) Unused or reserved flag
- [X] Indicates flag is enabled
- Summary of All Verifier Statistics
- RaiseIrqls 0x2
- AcquireSpinLocks 0xf10aa
- Synch Executions 0x0
- Trims 0x3f92
- Pool Allocations Attempted 0x46360
- Pool Allocations Succeeded 0x46360
- Pool Allocations Succeeded SpecialPool 0x46360
- Pool Allocations With NO TAG 0x15
- Pool Allocations Failed 0x0
- Current paged pool allocations 0x3555 for 00912B20 bytes
- Peak paged pool allocations 0x3af3 for 021E0DAE bytes
- Current nonpaged pool allocations 0x1401 for 00BBC2B8 bytes
- Peak nonpaged pool allocations 0x229c for 00E73E50 bytes
- ========================== Dump #2: Extra #2 ===========================
- 0: kd> !thread
- THREAD fffff80477130600 Cid 0000.0000 Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor 0
- Not impersonating
- GetUlongFromAddress: unable to read from fffff8047701b43c
- Owning Process fffff8047712da00 Image: System Process
- Attached Process ffffc58608a84080 Image: System
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 692206
- Context Switch Count 4686253 IdealProcessor: 0
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address nt!KiIdleLoop (0xfffff804767eb630)
- Stack Init fffff80478e6bc90 Current fffff80478e6bc20
- Base fffff80478e6c000 Limit fffff80478e66000 Call 0000000000000000
- Priority 0 BasePriority 0 PriorityDecrement 0 IoPriority 0 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- fffff804`78e6b558 fffff804`767f9a29 : 00000000`0000000a 00000000`04000002 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
- fffff804`78e6b560 fffff804`767f5d29 : ffffffff`fff9e580 00000000`00000002 ffffffff`fff9e580 ffffc586`0da20100 : nt!KiBugCheckDispatch+0x69
- fffff804`78e6b6a0 fffff804`76640cc4 : ffff9a87`507c6b88 fffff804`00000000 00000000`00000002 00000000`04000000 : nt!KiPageFault+0x469 (TrapFrame @ fffff804`78e6b6a0)
- fffff804`78e6b830 fffff804`7664085c : ffff9a87`507c6b80 00000000`00000002 fffff804`78e6bb18 ffffc586`0e0ee180 : nt!KiTimerWaitTest+0x1f4
- fffff804`78e6b8e0 fffff804`76643d8d : 00000000`00000000 00000000`00000000 00000000`00140001 00000000`00064bc4 : nt!KiProcessExpiredTimerList+0xdc
- fffff804`78e6b9d0 fffff804`767eb6ce : 00000000`00000000 fffff804`74f42180 fffff804`77130600 ffffc586`1a61f040 : nt!KiRetireDpcList+0x5dd
- fffff804`78e6bc60 00000000`00000000 : fffff804`78e6c000 fffff804`78e66000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x9e
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement