Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Microsoft (R) Windows Debugger Version 10.0.14321.1024 X86
- Copyright (c) Microsoft Corporation. All rights reserved.
- Auto Dump Analyzer by gardenman
- Time to debug file(s): 00 hours and 04 minutes and 59 seconds
- ========================================================================
- =================== Dump File: 080117-16187-01.dmp ===================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 15063 MP (4 procs) Free x64
- Product: WinNt, suite: TerminalServer SingleUserTS
- Built by: 15063.0.amd64fre.rs2_release.170317-1834
- Kernel base = 0xfffff803`32c7e000 PsLoadedModuleList = 0xfffff803`32fca5a0
- Debug session time: Tue Aug 1 01:23:40.858 2017 (UTC - 4:00)
- System Uptime: 0 days 0:11:29.476
- BugCheck 50, {fffff803323ce400, 2, fffff80332cdd3ff, 0}
- Could not read faulting driver name
- Probably caused by : ntkrnlmp.exe ( nt!RtlSetBits+3f )
- Followup: MachineOwner
- PAGE_FAULT_IN_NONPAGED_AREA (50)
- Invalid system memory was referenced. This cannot be protected by try-except.
- Typically the address is just plain bad or it is pointing at freed memory.
- Arguments:
- Arg1: fffff803323ce400, memory referenced.
- Arg2: 0000000000000002, value 0 = read operation, 1 = write operation.
- Arg3: fffff80332cdd3ff, If non-zero, the instruction address which referenced the bad memory
- address.
- Arg4: 0000000000000000, (reserved)
- Debugging Details:
- Could not read faulting driver name
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- BUILD_VERSION_STRING: 10.0.15063.0 (WinBuild.160101.0800)
- SYSTEM_MANUFACTURER: Gigabyte Technology Co., Ltd.
- SYSTEM_PRODUCT_NAME: B250M-D3H
- SYSTEM_SKU: Default string
- SYSTEM_VERSION: Default string
- BIOS_VENDOR: American Megatrends Inc.
- BIOS_VERSION: F7
- BIOS_DATE: 07/06/2017
- BASEBOARD_MANUFACTURER: Gigabyte Technology Co., Ltd.
- BASEBOARD_PRODUCT: B250M-D3H-CF
- BASEBOARD_VERSION: x.x
- DUMP_TYPE: 2
- DUMP_FILE_ATTRIBUTES: 0x8
- Kernel Generated Triage Dump
- READ_ADDRESS: fffff8033305f358: Unable to get MiVisibleState
- fffff803323ce400
- FAULTING_IP:
- nt!RtlSetBits+3f
- fffff803`32cdd3ff 0803 or byte ptr [rbx],al
- MM_INTERNAL_CODE: 0
- CPU_COUNT: 4
- CPU_MHZ: bb8
- CPU_VENDOR: GenuineIntel
- CPU_FAMILY: 6
- CPU_MODEL: 9e
- CPU_STEPPING: 9
- CPU_MICROCODE: 6,9e,9,0 (F,M,S,R) SIG: 5E'00000000 (cache) 5E'00000000 (init)
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
- BUGCHECK_STR: AV
- PROCESS_NAME: CompatTelRunne
- CURRENT_IRQL: 2
- TRAP_FRAME: ffffb9003d3a21d0 -- (.trap 0xffffb9003d3a21d0)
- NOTE: The trap frame does not contain all registers.
- Some register values may be zeroed or incorrect.
- rax=0000000000000003 rbx=0000000000000000 rcx=0000000000000000
- rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
- rip=fffff80332cdd3ff rsp=ffffb9003d3a2360 rbp=fffff80332c7e000
- r8=0000000000000002 r9=0000000000028000 r10=0000000000000001
- r11=ffffa88f88348a00 r12=0000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=0000000000000000
- iopl=0 nv up ei ng nz ac po cy
- nt!RtlSetBits+0x3f:
- fffff803`32cdd3ff 0803 or byte ptr [rbx],al ds:00000000`00000000=??
- Resetting default scope
- LAST_CONTROL_TRANSFER: from fffff80332e18d5c to fffff80332de9fd0
- STACK_TEXT:
- ffffb900`3d3a1f38 fffff803`32e18d5c : 00000000`00000050 fffff803`323ce400 00000000`00000002 ffffb900`3d3a21d0 : nt!KeBugCheckEx
- ffffb900`3d3a1f40 fffff803`32cec766 : 00000000`00000002 fffff803`323ce400 ffffb900`3d3a21d0 ffffa88f`8dd537c0 : nt!MiSystemFault+0x12e79c
- ffffb900`3d3a1fe0 fffff803`32df3872 : 00000000`00006280 00000000`00000000 ffffb900`3d3a2270 fffff803`32df39a0 : nt!MmAccessFault+0xae6
- ffffb900`3d3a21d0 fffff803`32cdd3ff : ffffb900`3d3a23f8 ffffb900`3d3a23d0 ffffb900`3d3a2388 00000000`00000018 : nt!KiPageFault+0x132
- ffffb900`3d3a2360 fffff803`33195a25 : ffffce0a`04f23920 ffffb900`3d3a2401 00000000`00000007 ffffa88f`88348a00 : nt!RtlSetBits+0x3f
- ffffb900`3d3a2390 fffff803`33194617 : ffffce0a`0707f058 00000000`0000012d ffffce0a`0707f010 00000000`0000018a : nt!MiUpdateCfgSystemWideBitmapWorker+0x2e5
- ffffb900`3d3a2460 fffff803`3319a1bc : 00000000`00000023 ffffb900`3d3a26d9 00000000`5cf00000 00000000`00000000 : nt!MiUpdateCfgSystemWideBitmap+0x83
- ffffb900`3d3a24a0 fffff803`33197a99 : ffffb900`3d3a2890 ffffb900`3d3a2890 ffffb900`3d3a26d9 ffffb900`3d3a2890 : nt!MiRelocateImage+0x30c
- ffffb900`3d3a2600 fffff803`330fdf29 : ffffb900`00000000 ffffb900`3d3a2890 ffffb900`3d3a2890 ffffa88f`8ad7b370 : nt!MiCreateNewSection+0x3ad
- ffffb900`3d3a2740 fffff803`330fd6a2 : ffffb900`3d3a2770 ffffce0a`0704b7b0 ffffa88f`8ad7b370 00000000`00f80090 : nt!MiCreateImageOrDataSection+0x289
- ffffb900`3d3a2820 fffff803`330fe222 : 00000000`11000000 00000000`00000000 ffffce09`ffd0b060 fffff803`331687f8 : nt!MiCreateSection+0xd2
- ffffb900`3d3a2960 fffff803`32df4f13 : ffffa88f`8ef282c0 fffff803`00000004 00000000`00000000 00000007`a3ef8de8 : nt!NtCreateSection+0x1e2
- ffffb900`3d3a2a10 00007ffb`aee95cf4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
- 00000007`a3ef8dc8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffb`aee95cf4
- STACK_COMMAND: kb
- THREAD_SHA1_HASH_MOD_FUNC: d885ed60512863ae72cc84f501b87df966e8411c
- THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 2f5a57a1cf28d25012b23515739c92edb122d100
- THREAD_SHA1_HASH_MOD: fe34192f63d13620a8987d294372ee74d699cfee
- FOLLOWUP_IP:
- nt!RtlSetBits+3f
- fffff803`32cdd3ff 0803 or byte ptr [rbx],al
- FAULT_INSTR_CODE: 8b480308
- SYMBOL_STACK_INDEX: 4
- SYMBOL_NAME: nt!RtlSetBits+3f
- FOLLOWUP_NAME: MachineOwner
- MODULE_NAME: nt
- IMAGE_NAME: ntkrnlmp.exe
- DEBUG_FLR_IMAGE_TIMESTAMP: 58ccba4c
- IMAGE_VERSION: 10.0.15063.0
- BUCKET_ID_FUNC_OFFSET: 3f
- FAILURE_BUCKET_ID: AV_INVALID_nt!RtlSetBits
- BUCKET_ID: AV_INVALID_nt!RtlSetBits
- PRIMARY_PROBLEM_CLASS: AV_INVALID_nt!RtlSetBits
- TARGET_TIME: 2017-08-01T05:23:40.000Z
- OSBUILD: 15063
- OSSERVICEPACK: 0
- SERVICEPACK_NUMBER: 0
- OS_REVISION: 0
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- OSPLATFORM_TYPE: x64
- OSNAME: Windows 10
- OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
- USER_LCID: 0
- OSBUILD_TIMESTAMP: 2017-03-18 00:40:44
- BUILDDATESTAMP_STR: 160101.0800
- BUILDLAB_STR: WinBuild
- BUILDOSVER_STR: 10.0.15063.0
- ANALYSIS_SESSION_ELAPSED_TIME: a3c
- ANALYSIS_SOURCE: KM
- FAILURE_ID_HASH_STRING: km:av_invalid_nt!rtlsetbits
- FAILURE_ID_HASH: {d8bc1995-ce19-2f06-c15b-0181e3fe55f4}
- Followup: MachineOwner
- =============================== Drivers ================================
- Image path: kdcom.dll
- Image name: kdcom.dll
- Possible Info Link: http://www.carrona.org/drivers/driver.php?id=kdcom.dll
- Timestamp: ***** Invalid (91688416)
- Image path: mcupdate.dll
- Image name: mcupdate.dll
- Possible Info Link: http://www.carrona.org/drivers/driver.php?id=mcupdate.dll
- Timestamp: Tue Jul 17 1979
- Image path: peauth.sys
- Image name: peauth.sys
- Possible Info Link: http://www.carrona.org/drivers/driver.php?id=peauth.sys
- Possible Driver Info: Protected Environment Authentication and Authorization Export Driver (Microsoft)
- Timestamp: Sat Dec 9 1989
- Image path: amdkmpfd.sys
- Image name: amdkmpfd.sys
- Possible Info Link: http://www.carrona.org/drivers/driver.php?id=amdkmpfd.sys
- Timestamp: Mon May 25 2015
- Image path: iaStorA.sys
- Image name: iaStorA.sys
- Possible Info Link: http://www.carrona.org/drivers/driver.php?id=iaStorA.sys
- Possible Driver Info: Intel SATA Storage Device RAID Controller
- Timestamp: Tue Jun 6 2017
- Image path: TeeDriverW8x64.sys
- Image name: TeeDriverW8x64.sys
- Possible Info Link: http://www.carrona.org/drivers/driver.php?id=TeeDriverW8x64.sys
- Timestamp: Tue Apr 4 2017
- Image path: dump_iaStorA.sys
- Image name: dump_iaStorA.sys
- Possible Info Link: http://www.carrona.org/drivers/driver.php?id=dump_iaStorA.sys
- Possible Driver Info: IASTOR.SYS is a Intel SATA driver for hard drives.
- Timestamp: Tue Jun 6 2017
- Image path: ISODrv64.sys
- Image name: ISODrv64.sys
- Possible Info Link: http://www.carrona.org/drivers/driver.php?id=ISODrv64.sys
- Timestamp: Thu Jan 28 2010
- Image path: ElcMouUFlt.sys
- Image name: ElcMouUFlt.sys
- Possible Info Link: http://www.carrona.org/drivers/driver.php?id=ElcMouUFlt.sys
- Timestamp: Tue Nov 30 2010
- Image path: dump_storport.sys
- Image name: dump_storport.sys
- Possible Info Link: http://www.carrona.org/drivers/driver.php?id=dump_storport.sys
- Timestamp: Wed Aug 28 2013
- Image path: RTKVHD64.sys
- Image name: RTKVHD64.sys
- Possible Info Link: http://www.carrona.org/drivers/driver.php?id=RTKVHD64.sys
- Timestamp: Thu Jan 5 2017
- Image path: t_mouse.sys
- Image name: t_mouse.sys
- Possible Info Link: http://www.carrona.org/drivers/driver.php?id=t_mouse.sys
- Timestamp: Mon Dec 3 2012
- Image path: ElcMouLFlt.sys
- Image name: ElcMouLFlt.sys
- Possible Info Link: http://www.carrona.org/drivers/driver.php?id=ElcMouLFlt.sys
- Timestamp: Mon Oct 4 2010
- Image path: drmk.sys
- Image name: drmk.sys
- Possible Info Link: http://www.carrona.org/drivers/driver.php?id=drmk.sys
- Timestamp: ***** Invalid (A01C1986)
- Image path: e1d65x64.sys
- Image name: e1d65x64.sys
- Possible Info Link: http://www.carrona.org/drivers/driver.php?id=e1d65x64.sys
- Timestamp: Sun Mar 19 2017
- Image path: nvvad64v.sys
- Image name: nvvad64v.sys
- Possible Info Link: http://www.carrona.org/drivers/driver.php?id=nvvad64v.sys
- Timestamp: Sun May 28 2017
- Image path: nvvhci.sys
- Image name: nvvhci.sys
- Possible Info Link: http://www.carrona.org/drivers/driver.php?id=nvvhci.sys
- Timestamp: Tue Dec 27 2016
- Image path: womic.sys
- Image name: womic.sys
- Possible Info Link: http://www.carrona.org/drivers/driver.php?id=womic.sys
- Timestamp: Sun May 21 2017
- Image path: nvhda64v.sys
- Image name: nvhda64v.sys
- Possible Info Link: http://www.carrona.org/drivers/driver.php?id=nvhda64v.sys
- Timestamp: Tue May 16 2017
- Image path: nvlddmkm.sys
- Image name: nvlddmkm.sys
- Possible Info Link: http://www.carrona.org/drivers/driver.php?id=nvlddmkm.sys
- Timestamp: Tue Jul 18 2017
- Unloaded modules:
- fffff803`bd110000 fffff803`bd11b000 cldflt.sys
- fffff803`b9490000 fffff803`b949f000 dump_storpor
- fffff803`bc470000 fffff803`bcfbd000 dump_iaStorA
- fffff803`bcfe0000 fffff803`bcffd000 dump_dumpfve
- fffff803`bbd70000 fffff803`bbd90000 dam.sys
- fffff803`b8100000 fffff803`b810f000 WdBoot.sys
- fffff803`b9490000 fffff803`b949f000 hwpolicy.sys
- ============================= BIOS INFO ================================
- [SMBIOS Data Tables v3.0]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 4226 bytes]
- [BIOS Information (Type 0) - Length 24 - Handle 0000h]
- Vendor American Megatrends Inc.
- BIOS Version F7
- BIOS Starting Address Segment f000
- BIOS Release Date 07/06/2017
- BIOS ROM Size 800000
- BIOS Characteristics
- 07: - PCI Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 32: - BIOS Vendor Reserved
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 5
- BIOS Minor Revision 12
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- Manufacturer Gigabyte Technology Co., Ltd.
- Product Name B250M-D3H
- Version Default string
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- SKUNumber Default string
- Family Default string
- [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
- Manufacturer Gigabyte Technology Co., Ltd.
- Product B250M-D3H-CF
- Version x.x
- Feature Flags 09h
- 1634083336: - ?ÿU?ì?ì¡H.ya3Å?Eü3ÀW?}?Eô?Eø?ÿu
- ¸@
- 1634083376: - ?ÿU?ì?ì¡H.ya3Å?Eü3ÀW?}?Eô?Eø?ÿu
- ¸@
- Location Default string
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 22 - Handle 0003h]
- Manufacturer Default string
- Chassis Type Desktop
- Version Default string
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 3
- [Onboard Devices Information (Type 10) - Length 6 - Handle 0021h]
- Number of Devices 1
- 01: Type Video [enabled]
- [OEM Strings (Type 11) - Length 5 - Handle 0022h]
- Number of Strings 1
- 1 Default string
- [System Configuration Options (Type 12) - Length 5 - Handle 0023h]
- [Physical Memory Array (Type 16) - Length 23 - Handle 003dh]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 67108864KB
- Number of Memory Devices 4
- [Memory Device (Type 17) - Length 40 - Handle 003eh]
- Physical Memory Array Handle 003dh
- Total Width 64 bits
- Data Width 64 bits
- Size 4096MB
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM0
- Bank Locator BANK 0
- Memory Type 1ah - Specification Reserved
- Type Detail 0080h - Synchronous
- Speed 2133MHz
- Manufacturer 0616
- Part Number DDR4-2400 CL16 4GB
- [Memory Device (Type 17) - Length 40 - Handle 003fh]
- Physical Memory Array Handle 003dh
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 02h - Unknown
- Device Locator ChannelA-DIMM1
- Bank Locator BANK 1
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Device (Type 17) - Length 40 - Handle 0040h]
- Physical Memory Array Handle 003dh
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 02h - Unknown
- Device Locator ChannelB-DIMM0
- Bank Locator BANK 2
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Device (Type 17) - Length 40 - Handle 0041h]
- Physical Memory Array Handle 003dh
- Total Width 64 bits
- Data Width 64 bits
- Size 4096MB
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM1
- Bank Locator BANK 3
- Memory Type 1ah - Specification Reserved
- Type Detail 0080h - Synchronous
- Speed 2133MHz
- Manufacturer 0616
- Part Number DDR4-2400 CL16 4GB
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0042h]
- Starting Address 00000000h
- Ending Address 007fffffh
- Memory Array Handle 003dh
- Partition Width 02
- [Cache Information (Type 7) - Length 19 - Handle 0043h]
- Socket Designation L1 Cache
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0100h - 256K
- Installed Size 0100h - 256K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type ParitySingle-Bit ECC
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0044h]
- Socket Designation L2 Cache
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 0400h - 1024K
- Installed Size 0400h - 1024K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Unified
- Associativity 4-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0045h]
- Socket Designation L3 Cache
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 1800h - 6144K
- Installed Size 1800h - 6144K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity Specification Reserved
- [Processor Information (Type 4) - Length 48 - Handle 0046h]
- Socket Designation U3E1
- Processor Type Central Processor
- Processor Family cdh - Specification Reserved
- Processor Manufacturer Intel(R) Corporation
- Processor ID e9060900fffbebbf
- Processor Version Intel(R) Core(TM) i5-7400 CPU @ 3.00GHz
- Processor Voltage 8ah - 1.0V
- External Clock 100MHz
- Max Speed 8300MHz
- Current Speed 3300MHz
- Status Enabled Populated
- Processor Upgrade Other
- L1 Cache Handle 0043h
- L2 Cache Handle 0044h
- L3 Cache Handle 0045h
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0047h]
- Starting Address 00000000h
- Ending Address 003fffffh
- Memory Device Handle 003eh
- Mem Array Mapped Adr Handle 0042h
- Interleave Position [None]
- Interleave Data Depth [None]
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0048h]
- Starting Address 00400000h
- Ending Address 007fffffh
- Memory Device Handle 0041h
- Mem Array Mapped Adr Handle 0042h
- Interleave Position [None]
- Interleave Data Depth [None]
- ========================================================================
- =================== Dump File: 080117-16390-01.dmp ===================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 15063 MP (4 procs) Free x64
- Product: WinNt, suite: TerminalServer SingleUserTS
- Built by: 15063.0.amd64fre.rs2_release.170317-1834
- Kernel base = 0xfffff803`f061a000 PsLoadedModuleList = 0xfffff803`f09665a0
- Debug session time: Tue Aug 1 00:35:29.128 2017 (UTC - 4:00)
- System Uptime: 0 days 0:00:39.747
- BugCheck 50, {ffff948e22e95103, 0, fffff803f089910e, 0}
- Could not read faulting driver name
- Probably caused by : Pool_Corruption ( nt!ExDeferredFreePool+fe )
- Followup: Pool_corruption
- PAGE_FAULT_IN_NONPAGED_AREA (50)
- Invalid system memory was referenced. This cannot be protected by try-except.
- Typically the address is just plain bad or it is pointing at freed memory.
- Arguments:
- Arg1: ffff948e22e95103, memory referenced.
- Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
- Arg3: fffff803f089910e, If non-zero, the instruction address which referenced the bad memory
- address.
- Arg4: 0000000000000000, (reserved)
- Debugging Details:
- Could not read faulting driver name
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- BUILD_VERSION_STRING: 10.0.15063.0 (WinBuild.160101.0800)
- SYSTEM_MANUFACTURER: Gigabyte Technology Co., Ltd.
- SYSTEM_PRODUCT_NAME: B250M-D3H
- SYSTEM_SKU: Default string
- SYSTEM_VERSION: Default string
- BIOS_VENDOR: American Megatrends Inc.
- BIOS_VERSION: F7
- BIOS_DATE: 07/06/2017
- BASEBOARD_MANUFACTURER: Gigabyte Technology Co., Ltd.
- BASEBOARD_PRODUCT: B250M-D3H-CF
- BASEBOARD_VERSION: x.x
- DUMP_TYPE: 2
- DUMP_FILE_ATTRIBUTES: 0x8
- Kernel Generated Triage Dump
- READ_ADDRESS: fffff803f09fb358: Unable to get MiVisibleState
- ffff948e22e95103
- FAULTING_IP:
- nt!ExDeferredFreePool+fe
- fffff803`f089910e 44385103 cmp byte ptr [rcx+3],r10b
- MM_INTERNAL_CODE: 0
- CPU_COUNT: 4
- CPU_MHZ: bb8
- CPU_VENDOR: GenuineIntel
- CPU_FAMILY: 6
- CPU_MODEL: 9e
- CPU_STEPPING: 9
- CPU_MICROCODE: 6,9e,9,0 (F,M,S,R) SIG: 5E'00000000 (cache) 5E'00000000 (init)
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
- BUGCHECK_STR: AV
- PROCESS_NAME: WerFault.exe
- CURRENT_IRQL: 2
- TRAP_FRAME: ffffaf00179b9ea0 -- (.trap 0xffffaf00179b9ea0)
- NOTE: The trap frame does not contain all registers.
- Some register values may be zeroed or incorrect.
- rax=0000000000000577 rbx=0000000000000000 rcx=ffff948e22e95100
- rdx=ffff948e22e66010 rsi=0000000000000000 rdi=0000000000000000
- rip=fffff803f089910e rsp=ffffaf00179ba030 rbp=0000000000000000
- r8=ffff948e22e94990 r9=ffff948e22c4de00 r10=0000000000000000
- r11=ffff948e22e3e560 r12=0000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=0000000000000000
- iopl=0 nv up ei pl nz na po nc
- nt!ExDeferredFreePool+0xfe:
- fffff803`f089910e 44385103 cmp byte ptr [rcx+3],r10b ds:ffff948e`22e95103=??
- Resetting default scope
- LOCK_ADDRESS: fffff803f097ef20 -- (!locks fffff803f097ef20)
- Resource @ nt!PiEngineLock (0xfffff803f097ef20) Available
- WARNING: SystemResourcesList->Flink chain invalid. Resource may be corrupted, or already deleted.
- WARNING: SystemResourcesList->Blink chain invalid. Resource may be corrupted, or already deleted.
- 1 total locks
- PNP_TRIAGE:
- Lock address : 0xfffff803f097ef20
- Thread Count : 0
- Thread address: 0x0000000000000000
- Thread wait : 0x0
- LAST_CONTROL_TRANSFER: from fffff803f07b4d5c to fffff803f0785fd0
- STACK_TEXT:
- ffffaf00`179b9c08 fffff803`f07b4d5c : 00000000`00000050 ffff948e`22e95103 00000000`00000000 ffffaf00`179b9ea0 : nt!KeBugCheckEx
- ffffaf00`179b9c10 fffff803`f0688766 : 00000000`00000000 ffff948e`22e95103 ffffaf00`179b9ea0 ffffbf04`f80af080 : nt!MiSystemFault+0x12e79c
- ffffaf00`179b9cb0 fffff803`f078f872 : ffff948e`22685e00 ffffaf00`179b9db0 00000000`00000002 ffff948e`221d5600 : nt!MmAccessFault+0xae6
- ffffaf00`179b9ea0 fffff803`f089910e : ffffbf04`f3240280 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x132
- ffffaf00`179ba030 fffff803`f089a7f1 : ffff948e`221d5820 ffffbf04`f3240280 ffffaf00`179ba149 ffff948e`221d55f0 : nt!ExDeferredFreePool+0xfe
- ffffaf00`179ba0b0 fffff803`f0ac5acf : ffff948e`22e31010 ffff948e`22e31010 00000000`006e006c ffffaf00`00000001 : nt!ExFreePoolWithTag+0x7e1
- ffffaf00`179ba1b0 fffff803`f0ac6702 : 00640064`00350036 00330065`0032002d 00300034`002d0064 0061002d`00340039 : nt!_RegRtlQueryValue+0x12b
- ffffaf00`179ba2e0 fffff803`f0a38a8d : ffff948e`1aabb2b0 ffffffff`8000160c ffffaf00`179ba4a0 ffff948e`1aabb2b0 : nt!_PnpRegQueryValueIndirect+0x72
- ffffaf00`179ba340 fffff803`f0ac34f7 : 00000000`02000001 ffff948e`1aabb200 00000000`00000000 ffffaf00`179ba430 : nt!PnpCtxRegQueryValueIndirect+0x4d
- ffffaf00`179ba390 fffff803`f0ac7852 : 00000000`c0000016 00000000`00000200 ffff948e`22e31010 ffff948e`22e31010 : nt!PnpGetGenericStoreProperty+0x1cf
- ffffaf00`179ba520 fffff803`f0ac69f9 : 00000000`00000000 ffff948e`22dc2050 ffffaf00`179ba661 ffff948e`1aabb2b0 : nt!_PnpGetObjectPropertyWorker+0x126
- ffffaf00`179ba5c0 fffff803`f0ac4a26 : 00000000`00000000 ffff948e`22e31010 00000000`00000001 ffffaf00`00000000 : nt!_PnpGetObjectProperty+0x119
- ffffaf00`179ba690 fffff803`f0ac4243 : bf04f965`5050fe6d ffffbf04`f3327b00 00000000`00000000 00000000`00000214 : nt!PiCMGetObjectProperty+0x14e
- ffffaf00`179ba7b0 fffff803`f0ac41da : ffffbf04`f9655080 00000000`00470813 ffffbf04`f80af080 ffffbf04`00000000 : nt!PiCMFastIoDeviceDispatch+0x53
- ffffaf00`179ba800 fffff803`f0a76b22 : ffffbf04`f9655080 00000000`00000000 00000000`00000000 00000000`00000001 : nt!PiDaFastIoDispatch+0x6a
- ffffaf00`179ba860 fffff803`f0a76756 : ffffbf04`f80af080 00000000`00000000 00000000`00000000 00000000`00000000 : nt!IopXxxControlFile+0x3b2
- ffffaf00`179ba9a0 fffff803`f0790f13 : ffffaf00`179baa90 00000000`00000000 ffffbf04`f80a6080 00000099`295dcc68 : nt!NtDeviceIoControlFile+0x56
- ffffaf00`179baa10 00007ffe`131a5494 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
- 00000099`295dcb78 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffe`131a5494
- STACK_COMMAND: kb
- THREAD_SHA1_HASH_MOD_FUNC: 076212619202c5b1a39c96a8f16a6c474bd3a47a
- THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 2889022a15a286090331a06401cd904298c82b1d
- THREAD_SHA1_HASH_MOD: 82d14546c43bd06881f781d6d197c4c7f7ceb9cb
- FOLLOWUP_IP:
- nt!ExDeferredFreePool+fe
- fffff803`f089910e 44385103 cmp byte ptr [rcx+3],r10b
- FAULT_INSTR_CODE: 3513844
- SYMBOL_STACK_INDEX: 4
- SYMBOL_NAME: nt!ExDeferredFreePool+fe
- FOLLOWUP_NAME: Pool_corruption
- IMAGE_NAME: Pool_Corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- IMAGE_VERSION: 10.0.15063.0
- MODULE_NAME: Pool_Corruption
- BUCKET_ID_FUNC_OFFSET: fe
- FAILURE_BUCKET_ID: AV_R_INVALID_nt!ExDeferredFreePool
- BUCKET_ID: AV_R_INVALID_nt!ExDeferredFreePool
- PRIMARY_PROBLEM_CLASS: AV_R_INVALID_nt!ExDeferredFreePool
- TARGET_TIME: 2017-08-01T04:35:29.000Z
- OSBUILD: 15063
- OSSERVICEPACK: 0
- SERVICEPACK_NUMBER: 0
- OS_REVISION: 0
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- OSPLATFORM_TYPE: x64
- OSNAME: Windows 10
- OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
- USER_LCID: 0
- OSBUILD_TIMESTAMP: 2017-03-18 00:40:44
- BUILDDATESTAMP_STR: 160101.0800
- BUILDLAB_STR: WinBuild
- BUILDOSVER_STR: 10.0.15063.0
- ANALYSIS_SESSION_ELAPSED_TIME: 1325
- ANALYSIS_SOURCE: KM
- FAILURE_ID_HASH_STRING: km:av_r_invalid_nt!exdeferredfreepool
- FAILURE_ID_HASH: {028c647e-835a-75c4-058d-04f80fc3ba93}
- Followup: Pool_corruption
- ========================================================================
- =================== Dump File: 080117-16984-01.dmp ===================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 15063 MP (4 procs) Free x64
- Product: WinNt, suite: TerminalServer SingleUserTS
- Kernel base = 0xfffff803`ac412000 PsLoadedModuleList = 0xfffff803`ac75e5a0
- Debug session time: Tue Aug 1 07:29:29.874 2017 (UTC - 4:00)
- System Uptime: 0 days 6:05:18.492
- BugCheck 50, {fffff8021bc7e4c2, 2, fffff803ac4713ff, 2}
- Could not read faulting driver name
- Probably caused by : ntkrnlmp.exe ( nt!RtlSetBits+3f )
- Followup: MachineOwner
- PAGE_FAULT_IN_NONPAGED_AREA (50)
- Invalid system memory was referenced. This cannot be protected by try-except.
- Typically the address is just plain bad or it is pointing at freed memory.
- Arguments:
- Arg1: fffff8021bc7e4c2, memory referenced.
- Arg2: 0000000000000002, value 0 = read operation, 1 = write operation.
- Arg3: fffff803ac4713ff, If non-zero, the instruction address which referenced the bad memory
- address.
- Arg4: 0000000000000002, (reserved)
- Debugging Details:
- Could not read faulting driver name
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- BUILD_VERSION_STRING: 10.0.15063.0 (WinBuild.160101.0800)
- SYSTEM_MANUFACTURER: Gigabyte Technology Co., Ltd.
- SYSTEM_PRODUCT_NAME: B250M-D3H
- SYSTEM_SKU: Default string
- SYSTEM_VERSION: Default string
- BIOS_VENDOR: American Megatrends Inc.
- BIOS_VERSION: F7
- BIOS_DATE: 07/06/2017
- BASEBOARD_MANUFACTURER: Gigabyte Technology Co., Ltd.
- BASEBOARD_PRODUCT: B250M-D3H-CF
- BASEBOARD_VERSION: x.x
- DUMP_TYPE: 2
- DUMP_FILE_ATTRIBUTES: 0x8
- Kernel Generated Triage Dump
- READ_ADDRESS: fffff803ac7f3358: Unable to get MiVisibleState
- fffff8021bc7e4c2
- FAULTING_IP:
- nt!RtlSetBits+3f
- fffff803`ac4713ff 0803 or byte ptr [rbx],al
- MM_INTERNAL_CODE: 2
- CPU_COUNT: 4
- CPU_MHZ: bb8
- CPU_VENDOR: GenuineIntel
- CPU_FAMILY: 6
- CPU_MODEL: 9e
- CPU_STEPPING: 9
- CPU_MICROCODE: 6,9e,9,0 (F,M,S,R) SIG: 5E'00000000 (cache) 5E'00000000 (init)
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
- BUGCHECK_STR: AV
- PROCESS_NAME: CompatTelRunne
- CURRENT_IRQL: 0
- TRAP_FRAME: ffff9100f488d1d0 -- (.trap 0xffff9100f488d1d0)
- NOTE: The trap frame does not contain all registers.
- Some register values may be zeroed or incorrect.
- rax=00000000000000c0 rbx=0000000000000000 rcx=0000000000000006
- rdx=0000000000000006 rsi=0000000000000000 rdi=0000000000000000
- rip=fffff803ac4713ff rsp=ffff9100f488d360 rbp=fffff803ac412000
- r8=0000000000000002 r9=000000000026630b r10=0000000000000001
- r11=ffffc50931348a00 r12=0000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=0000000000000000
- iopl=0 nv up ei ng nz na po nc
- nt!RtlSetBits+0x3f:
- fffff803`ac4713ff 0803 or byte ptr [rbx],al ds:00000000`00000000=??
- Resetting default scope
- LAST_CONTROL_TRANSFER: from fffff803ac5acf86 to fffff803ac57dfd0
- STACK_TEXT:
- ffff9100`f488cf38 fffff803`ac5acf86 : 00000000`00000050 fffff802`1bc7e4c2 00000000`00000002 ffff9100`f488d1d0 : nt!KeBugCheckEx
- ffff9100`f488cf40 fffff803`ac480766 : 00000000`00000002 fffff802`1bc7e4c2 ffff9100`f488d1d0 ffffc509`31899080 : nt!MiSystemFault+0x12e9c6
- ffff9100`f488cfe0 fffff803`ac587872 : 00000000`00006280 00000000`00000000 ffff9100`f488d270 fffff803`ac5879a0 : nt!MmAccessFault+0xae6
- ffff9100`f488d1d0 fffff803`ac4713ff : ffff9100`f488d3f8 ffff9100`f488d3d0 ffff9100`f488d388 00000000`00000018 : nt!KiPageFault+0x132
- ffff9100`f488d360 fffff803`ac929a25 : ffff8003`0e879d50 ffff9100`f488d401 00000000`00000007 ffffc509`31348a00 : nt!RtlSetBits+0x3f
- ffff9100`f488d390 fffff803`ac928617 : ffff8003`0effe058 00000000`0000012d ffff8003`0effe010 00000000`0000018a : nt!MiUpdateCfgSystemWideBitmapWorker+0x2e5
- ffff9100`f488d460 fffff803`ac92e1bc : 00000000`00000023 ffff9100`f488d6d9 00000000`5cf00000 00000000`00000000 : nt!MiUpdateCfgSystemWideBitmap+0x83
- ffff9100`f488d4a0 fffff803`ac92ba99 : ffff9100`f488d890 ffff9100`f488d890 ffff9100`f488d6d9 ffff9100`f488d890 : nt!MiRelocateImage+0x30c
- ffff9100`f488d600 fffff803`ac891f29 : ffff9100`00000000 ffff9100`f488d890 ffff9100`f488d890 ffffc509`385107f0 : nt!MiCreateNewSection+0x3ad
- ffff9100`f488d740 fffff803`ac8916a2 : ffff9100`f488d770 ffff8003`0edb2670 ffffc509`385107f0 00000000`00f80090 : nt!MiCreateImageOrDataSection+0x289
- ffff9100`f488d820 fffff803`ac892222 : 00000000`11000000 00000000`00000000 ffff8003`0e5f97c0 fffff803`ac8fc7f8 : nt!MiCreateSection+0xd2
- ffff9100`f488d960 fffff803`ac588f13 : ffffc509`39022080 fffff803`00000004 00000000`00000000 000000ad`695b8b68 : nt!NtCreateSection+0x1e2
- ffff9100`f488da10 00007ffa`ce3e5cf4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
- 000000ad`695b8b48 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffa`ce3e5cf4
- STACK_COMMAND: kb
- THREAD_SHA1_HASH_MOD_FUNC: d885ed60512863ae72cc84f501b87df966e8411c
- THREAD_SHA1_HASH_MOD_FUNC_OFFSET: b4101bd84c0450b4374d12f4a111885d3bf99a75
- THREAD_SHA1_HASH_MOD: fe34192f63d13620a8987d294372ee74d699cfee
- FOLLOWUP_IP:
- nt!RtlSetBits+3f
- fffff803`ac4713ff 0803 or byte ptr [rbx],al
- FAULT_INSTR_CODE: 8b480308
- SYMBOL_STACK_INDEX: 4
- SYMBOL_NAME: nt!RtlSetBits+3f
- FOLLOWUP_NAME: MachineOwner
- MODULE_NAME: nt
- IMAGE_NAME: ntkrnlmp.exe
- DEBUG_FLR_IMAGE_TIMESTAMP: 58ccba4c
- IMAGE_VERSION: 10.0.15063.0
- BUCKET_ID_FUNC_OFFSET: 3f
- FAILURE_BUCKET_ID: AV_INVALID_nt!RtlSetBits
- BUCKET_ID: AV_INVALID_nt!RtlSetBits
- PRIMARY_PROBLEM_CLASS: AV_INVALID_nt!RtlSetBits
- TARGET_TIME: 2017-08-01T11:29:29.000Z
- OSBUILD: 15063
- OSSERVICEPACK: 0
- SERVICEPACK_NUMBER: 0
- OS_REVISION: 0
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- OSPLATFORM_TYPE: x64
- OSNAME: Windows 10
- OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
- USER_LCID: 0
- OSBUILD_TIMESTAMP: 2017-03-18 00:40:44
- BUILDDATESTAMP_STR: 160101.0800
- BUILDLAB_STR: WinBuild
- BUILDOSVER_STR: 10.0.15063.0
- ANALYSIS_SESSION_ELAPSED_TIME: a4b
- ANALYSIS_SOURCE: KM
- FAILURE_ID_HASH_STRING: km:av_invalid_nt!rtlsetbits
- FAILURE_ID_HASH: {d8bc1995-ce19-2f06-c15b-0181e3fe55f4}
- Followup: MachineOwner
- ========================================================================
- =================== Dump File: 080117-22375-01.dmp ===================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 15063 MP (4 procs) Free x64
- Product: WinNt, suite: TerminalServer SingleUserTS
- Kernel base = 0xfffff801`c4e19000 PsLoadedModuleList = 0xfffff801`c51655a0
- Debug session time: Tue Aug 1 01:11:42.537 2017 (UTC - 4:00)
- System Uptime: 0 days 0:14:12.154
- BugCheck 50, {fffff80476e25bda, 2, fffff801c4e783ff, 2}
- Could not read faulting driver name
- Probably caused by : ntkrnlmp.exe ( nt!RtlSetBits+3f )
- Followup: MachineOwner
- PAGE_FAULT_IN_NONPAGED_AREA (50)
- Invalid system memory was referenced. This cannot be protected by try-except.
- Typically the address is just plain bad or it is pointing at freed memory.
- Arguments:
- Arg1: fffff80476e25bda, memory referenced.
- Arg2: 0000000000000002, value 0 = read operation, 1 = write operation.
- Arg3: fffff801c4e783ff, If non-zero, the instruction address which referenced the bad memory
- address.
- Arg4: 0000000000000002, (reserved)
- Debugging Details:
- Could not read faulting driver name
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- BUILD_VERSION_STRING: 10.0.15063.0 (WinBuild.160101.0800)
- SYSTEM_MANUFACTURER: Gigabyte Technology Co., Ltd.
- SYSTEM_PRODUCT_NAME: B250M-D3H
- SYSTEM_SKU: Default string
- SYSTEM_VERSION: Default string
- BIOS_VENDOR: American Megatrends Inc.
- BIOS_VERSION: F7
- BIOS_DATE: 07/06/2017
- BASEBOARD_MANUFACTURER: Gigabyte Technology Co., Ltd.
- BASEBOARD_PRODUCT: B250M-D3H-CF
- BASEBOARD_VERSION: x.x
- DUMP_TYPE: 2
- DUMP_FILE_ATTRIBUTES: 0x8
- Kernel Generated Triage Dump
- READ_ADDRESS: fffff801c51fa358: Unable to get MiVisibleState
- fffff80476e25bda
- FAULTING_IP:
- nt!RtlSetBits+3f
- fffff801`c4e783ff 0803 or byte ptr [rbx],al
- MM_INTERNAL_CODE: 2
- CPU_COUNT: 4
- CPU_MHZ: bb8
- CPU_VENDOR: GenuineIntel
- CPU_FAMILY: 6
- CPU_MODEL: 9e
- CPU_STEPPING: 9
- CPU_MICROCODE: 6,9e,9,0 (F,M,S,R) SIG: 5E'00000000 (cache) 5E'00000000 (init)
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
- BUGCHECK_STR: AV
- PROCESS_NAME: CompatTelRunne
- CURRENT_IRQL: 0
- TRAP_FRAME: ffffac81f5a331d0 -- (.trap 0xffffac81f5a331d0)
- NOTE: The trap frame does not contain all registers.
- Some register values may be zeroed or incorrect.
- rax=00000000000000c0 rbx=0000000000000000 rcx=0000000000000006
- rdx=0000000000000006 rsi=0000000000000000 rdi=0000000000000000
- rip=fffff801c4e783ff rsp=ffffac81f5a33360 rbp=fffff801c4e19000
- r8=0000000000000002 r9=0000000000deaf6b r10=0000000000000001
- r11=ffffd90fe234db70 r12=0000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=0000000000000000
- iopl=0 nv up ei ng nz na po nc
- nt!RtlSetBits+0x3f:
- fffff801`c4e783ff 0803 or byte ptr [rbx],al ds:00000000`00000000=??
- Resetting default scope
- LAST_CONTROL_TRANSFER: from fffff801c4fb3f86 to fffff801c4f84fd0
- STACK_TEXT:
- ffffac81`f5a32f38 fffff801`c4fb3f86 : 00000000`00000050 fffff804`76e25bda 00000000`00000002 ffffac81`f5a331d0 : nt!KeBugCheckEx
- ffffac81`f5a32f40 fffff801`c4e87766 : 00000000`00000002 fffff804`76e25bda ffffac81`f5a331d0 ffffd90f`e86437c0 : nt!MiSystemFault+0x12e9c6
- ffffac81`f5a32fe0 fffff801`c4f8e872 : 00000000`00006280 00000000`00000000 ffffac81`f5a33270 fffff801`c4f8e9a0 : nt!MmAccessFault+0xae6
- ffffac81`f5a331d0 fffff801`c4e783ff : ffffac81`f5a333f8 ffffac81`f5a333d0 ffffac81`f5a33388 00000000`00000018 : nt!KiPageFault+0x132
- ffffac81`f5a33360 fffff801`c5330a25 : ffff950c`2fd38810 ffffac81`f5a33401 00000000`00000007 ffffd90f`e234db70 : nt!RtlSetBits+0x3f
- ffffac81`f5a33390 fffff801`c532f617 : ffff950c`268ad058 00000000`0000012d ffff950c`268ad010 00000000`0000018a : nt!MiUpdateCfgSystemWideBitmapWorker+0x2e5
- ffffac81`f5a33460 fffff801`c53351bc : 00000000`00000023 ffffac81`f5a336d9 00000000`5cf00000 00000000`00000000 : nt!MiUpdateCfgSystemWideBitmap+0x83
- ffffac81`f5a334a0 fffff801`c5332a99 : ffffac81`f5a33890 ffffac81`f5a33890 ffffac81`f5a336d9 ffffac81`f5a33890 : nt!MiRelocateImage+0x30c
- ffffac81`f5a33600 fffff801`c5298f29 : ffffac81`00000000 ffffac81`f5a33890 ffffac81`f5a33890 ffffd90f`e3807730 : nt!MiCreateNewSection+0x3ad
- ffffac81`f5a33740 fffff801`c52986a2 : ffffac81`f5a33770 ffff950c`2e382640 ffffd90f`e3807730 00000000`00f80090 : nt!MiCreateImageOrDataSection+0x289
- ffffac81`f5a33820 fffff801`c5299222 : 00000000`11000000 00000000`00000000 ffff950c`26af9060 fffff801`c53037f8 : nt!MiCreateSection+0xd2
- ffffac81`f5a33960 fffff801`c4f8ff13 : ffffd90f`e86d76c0 fffff801`00000004 00000000`00000000 00000008`ae4f8cd8 : nt!NtCreateSection+0x1e2
- ffffac81`f5a33a10 00007ffa`797e5cf4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
- 00000008`ae4f8cb8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffa`797e5cf4
- STACK_COMMAND: kb
- THREAD_SHA1_HASH_MOD_FUNC: d885ed60512863ae72cc84f501b87df966e8411c
- THREAD_SHA1_HASH_MOD_FUNC_OFFSET: b4101bd84c0450b4374d12f4a111885d3bf99a75
- THREAD_SHA1_HASH_MOD: fe34192f63d13620a8987d294372ee74d699cfee
- FOLLOWUP_IP:
- nt!RtlSetBits+3f
- fffff801`c4e783ff 0803 or byte ptr [rbx],al
- FAULT_INSTR_CODE: 8b480308
- SYMBOL_STACK_INDEX: 4
- SYMBOL_NAME: nt!RtlSetBits+3f
- FOLLOWUP_NAME: MachineOwner
- MODULE_NAME: nt
- IMAGE_NAME: ntkrnlmp.exe
- DEBUG_FLR_IMAGE_TIMESTAMP: 58ccba4c
- IMAGE_VERSION: 10.0.15063.0
- BUCKET_ID_FUNC_OFFSET: 3f
- FAILURE_BUCKET_ID: AV_INVALID_nt!RtlSetBits
- BUCKET_ID: AV_INVALID_nt!RtlSetBits
- PRIMARY_PROBLEM_CLASS: AV_INVALID_nt!RtlSetBits
- TARGET_TIME: 2017-08-01T05:11:42.000Z
- OSBUILD: 15063
- OSSERVICEPACK: 0
- SERVICEPACK_NUMBER: 0
- OS_REVISION: 0
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- OSPLATFORM_TYPE: x64
- OSNAME: Windows 10
- OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
- USER_LCID: 0
- OSBUILD_TIMESTAMP: 2017-03-18 00:40:44
- BUILDDATESTAMP_STR: 160101.0800
- BUILDLAB_STR: WinBuild
- BUILDOSVER_STR: 10.0.15063.0
- ANALYSIS_SESSION_ELAPSED_TIME: ae2
- ANALYSIS_SOURCE: KM
- FAILURE_ID_HASH_STRING: km:av_invalid_nt!rtlsetbits
- FAILURE_ID_HASH: {d8bc1995-ce19-2f06-c15b-0181e3fe55f4}
- Followup: MachineOwner
- ========================================================================
- =================== Dump File: 080117-14984-01.dmp ===================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 15063 MP (4 procs) Free x64
- Product: WinNt, suite: TerminalServer SingleUserTS
- Kernel base = 0xfffff800`a0888000 PsLoadedModuleList = 0xfffff800`a0bd45a0
- Debug session time: Tue Aug 1 00:40:51.836 2017 (UTC - 4:00)
- System Uptime: 0 days 0:00:41.453
- BugCheck 139, {3, ffff8d0040e98ae0, ffff8d0040e98a38, 0}
- Probably caused by : Pool_Corruption ( nt!ExDeferredFreePool+22e3 )
- Followup: Pool_corruption
- KERNEL_SECURITY_CHECK_FAILURE (139)
- A kernel component has corrupted a critical data structure. The corruption
- could potentially allow a malicious user to gain control of this machine.
- Arguments:
- Arg1: 0000000000000003, A LIST_ENTRY has been corrupted (i.e. double remove).
- Arg2: ffff8d0040e98ae0, Address of the trap frame for the exception that caused the bugcheck
- Arg3: ffff8d0040e98a38, Address of the exception record for the exception that caused the bugcheck
- Arg4: 0000000000000000, Reserved
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- BUILD_VERSION_STRING: 10.0.15063.0 (WinBuild.160101.0800)
- SYSTEM_MANUFACTURER: Gigabyte Technology Co., Ltd.
- SYSTEM_PRODUCT_NAME: B250M-D3H
- SYSTEM_SKU: Default string
- SYSTEM_VERSION: Default string
- BIOS_VENDOR: American Megatrends Inc.
- BIOS_VERSION: F7
- BIOS_DATE: 07/06/2017
- BASEBOARD_MANUFACTURER: Gigabyte Technology Co., Ltd.
- BASEBOARD_PRODUCT: B250M-D3H-CF
- BASEBOARD_VERSION: x.x
- DUMP_TYPE: 2
- DUMP_FILE_ATTRIBUTES: 0x8
- Kernel Generated Triage Dump
- TRAP_FRAME: ffff8d0040e98ae0 -- (.trap 0xffff8d0040e98ae0)
- NOTE: The trap frame does not contain all registers.
- Some register values may be zeroed or incorrect.
- rax=ffffc688ff740110 rbx=0000000000000000 rcx=0000000000000003
- rdx=ffffc688ff7403f0 rsi=0000000000000000 rdi=0000000000000000
- rip=fffff800a0b092f3 rsp=ffff8d0040e98c70 rbp=0000000000000000
- r8=ffffc688ff73fee0 r9=ffffc688ff55875c r10=0000000000000001
- r11=ffffc688ff558750 r12=0000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=0000000000000000
- iopl=0 nv up ei pl nz na po cy
- nt!ExDeferredFreePool+0x22e3:
- fffff800`a0b092f3 cd29 int 29h
- Resetting default scope
- EXCEPTION_RECORD: ffff8d0040e98a38 -- (.exr 0xffff8d0040e98a38)
- ExceptionAddress: fffff800a0b092f3 (nt!ExDeferredFreePool+0x00000000000022e3)
- ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
- ExceptionFlags: 00000001
- NumberParameters: 1
- Parameter[0]: 0000000000000003
- Subcode: 0x3 FAST_FAIL_CORRUPT_LIST_ENTRY
- CPU_COUNT: 4
- CPU_MHZ: bb8
- CPU_VENDOR: GenuineIntel
- CPU_FAMILY: 6
- CPU_MODEL: 9e
- CPU_STEPPING: 9
- CPU_MICROCODE: 6,9e,9,0 (F,M,S,R) SIG: 5E'00000000 (cache) 5E'00000000 (init)
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: LIST_ENTRY_CORRUPT
- BUGCHECK_STR: 0x139
- PROCESS_NAME: WerFault.exe
- CURRENT_IRQL: 1
- ERROR_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.
- EXCEPTION_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.
- EXCEPTION_CODE_STR: c0000409
- EXCEPTION_PARAMETER1: 0000000000000003
- LAST_CONTROL_TRANSFER: from fffff800a09ff3a9 to fffff800a09f3fd0
- STACK_TEXT:
- ffff8d00`40e987b8 fffff800`a09ff3a9 : 00000000`00000139 00000000`00000003 ffff8d00`40e98ae0 ffff8d00`40e98a38 : nt!KeBugCheckEx
- ffff8d00`40e987c0 fffff800`a09ff710 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
- ffff8d00`40e98900 fffff800`a09fe6f7 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiFastFailDispatch+0xd0
- ffff8d00`40e98ae0 fffff800`a0b092f3 : ffffd906`1123f140 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiRaiseSecurityCheckFailure+0xf7
- ffff8d00`40e98c70 fffff800`a0b087f1 : ffffc688`ff75a320 ffffd906`1123f140 ffff8d00`40e98d89 ffffc688`ff76cc70 : nt!ExDeferredFreePool+0x22e3
- ffff8d00`40e98cf0 fffff800`15556d8f : ffffd906`12ff8680 ffffc688`ff7294a0 ffffd906`16e76dc0 ffffd906`00000001 : nt!ExFreePoolWithTag+0x7e1
- ffff8d00`40e98df0 fffff800`15526eb0 : ffffd906`16e76e00 ffffd906`1129bd60 ffffd906`179f1b00 00000000`00000000 : FLTMGR!FltpCreateFileNameInformation+0x33f
- ffff8d00`40e98e40 fffff800`1552270a : 00000000`00008000 ffffd906`16e76dc0 00000000`00000000 ffffd906`16e76e28 : FLTMGR!FltpGetFileNameInformation+0x390
- ffff8d00`40e98ef0 fffff800`1790d07f : 00000000`00000000 fffff780`00000320 ffff8d00`40e98f90 ffffd906`12f2d8b0 : FLTMGR!FltGetFileNameInformation+0x1ba
- ffff8d00`40e98f70 fffff800`1790da28 : ffff8d11`feba97a6 ffffd906`12f2db40 ffff8d00`40e99100 00000000`00000001 : fileinfo!FIStreamQueryInfo+0xcf
- ffff8d00`40e99000 fffff800`1552413c : 00000000`00000000 00000000`00000001 00000000`0000005c 00000000`00000000 : fileinfo!FIPostCreateCallback+0x208
- ffff8d00`40e990b0 fffff800`15523af3 : ffffd906`16e6a500 ffffd906`16e6a500 ffffd906`179ad670 00000000`00000000 : FLTMGR!FltpPerformPostCallbacks+0x2ac
- ffff8d00`40e99180 fffff800`155256ce : ffffd906`179ad240 ffffd906`16e6a580 00000000`00000008 ffffd906`16e6a598 : FLTMGR!FltpPassThroughCompletionWorker+0x73
- ffff8d00`40e991c0 fffff800`1555612b : ffff8d00`40e99270 ffffd906`179ad670 ffff8d00`40e992f8 fffff800`00000000 : FLTMGR!FltpLegacyProcessingAfterPreCallbacksCompleted+0x21e
- ffff8d00`40e99230 fffff800`a0ce60c5 : 00000000`00000000 00000000`000000c5 ffffd906`12e82b10 ffff8d00`00000001 : FLTMGR!FltpCreate+0x2eb
- ffff8d00`40e992e0 fffff800`a0cf147b : fffff800`a0ce58b0 fffff800`a0ce58b0 ffff8d00`00000000 ffffd906`12e63c50 : nt!IopParseDevice+0x815
- ffff8d00`40e994c0 fffff800`a0cf4df0 : ffffd906`17e7e100 ffff8d00`40e99728 00000000`00000040 ffffd906`112ef9a0 : nt!ObpLookupObjectName+0x46b
- ffff8d00`40e99690 fffff800`a0d40afb : ffffd906`00000001 00000094`21cab8a0 000001f8`a42d58a0 00000094`21cab870 : nt!ObOpenObjectByNameEx+0x1e0
- ffff8d00`40e997d0 fffff800`a09fef13 : ffffd906`173f77c0 00000000`00000000 ffffd906`173f77c0 00000000`00000000 : nt!NtQueryFullAttributesFile+0x18b
- ffff8d00`40e99a80 00007ffc`b51f7ac4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
- 00000094`21cab818 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffc`b51f7ac4
- STACK_COMMAND: kb
- THREAD_SHA1_HASH_MOD_FUNC: c235256bd39ce4cb2c5cc79f6cfc2b1445807368
- THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 60931d29dd8f38d73e73303a11a21a2883bd7b91
- THREAD_SHA1_HASH_MOD: 24c3bc276fad152f6c8bb44a001f20c83a39b813
- FOLLOWUP_IP:
- nt!ExDeferredFreePool+22e3
- fffff800`a0b092f3 cd29 int 29h
- FAULT_INSTR_CODE: 3b929cd
- SYMBOL_STACK_INDEX: 4
- SYMBOL_NAME: nt!ExDeferredFreePool+22e3
- FOLLOWUP_NAME: Pool_corruption
- IMAGE_NAME: Pool_Corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- IMAGE_VERSION: 10.0.15063.0
- MODULE_NAME: Pool_Corruption
- BUCKET_ID_FUNC_OFFSET: 22e3
- FAILURE_BUCKET_ID: 0x139_3_nt!ExDeferredFreePool
- BUCKET_ID: 0x139_3_nt!ExDeferredFreePool
- PRIMARY_PROBLEM_CLASS: 0x139_3_nt!ExDeferredFreePool
- TARGET_TIME: 2017-08-01T04:40:51.000Z
- OSBUILD: 15063
- OSSERVICEPACK: 0
- SERVICEPACK_NUMBER: 0
- OS_REVISION: 0
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- OSPLATFORM_TYPE: x64
- OSNAME: Windows 10
- OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
- USER_LCID: 0
- OSBUILD_TIMESTAMP: 2017-03-18 00:40:44
- BUILDDATESTAMP_STR: 160101.0800
- BUILDLAB_STR: WinBuild
- BUILDOSVER_STR: 10.0.15063.0
- ANALYSIS_SESSION_ELAPSED_TIME: 968
- ANALYSIS_SOURCE: KM
- FAILURE_ID_HASH_STRING: km:0x139_3_nt!exdeferredfreepool
- FAILURE_ID_HASH: {14bfade4-e1ed-98c0-40bb-116f20a8dfc3}
- Followup: Pool_corruption
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement