Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ========================== AUTO DUMP ANALYZER ==========================
- Auto Dump Analyzer
- Version: 0.91
- Time to analyze file(s): 00 hours and 03 minutes and 34 seconds
- ================================= BIOS =================================
- VENDOR: American Megatrends Inc.
- VERSION: 2401
- DATE: 07/15/2019
- ============================= MOTHERBOARD ==============================
- MANUFACTURER: ASUSTeK COMPUTER INC.
- PRODUCT: PRIME Z370-P
- VERSION: Rev X.0x
- ================================= RAM ==================================
- Size Speed Manufacturer Part No.
- -------------- -------------- ------------------- ----------------------
- 0MHz
- 8192MB 2400MHz Corsair CMK16GX4M2A2400C16
- 0MHz
- 8192MB 2400MHz Corsair CMK16GX4M2A2400C16
- ================================= CPU ==================================
- Processor Version: Intel(R) Core(TM) i5-8600K CPU @ 3.60GHz
- COUNT: 6
- MHZ: 3600
- VENDOR: GenuineIntel
- FAMILY: 6
- MODEL: 9e
- STEPPING: a
- MICROCODE: 6,9e,a,0 (F,M,S,R) SIG: B4'00000000 (cache) B4'00000000 (init)
- ================================== OS ==================================
- Product: WinNt, suite: TerminalServer SingleUserTS
- BUILD_VERSION: 10.0.18362.778 (WinBuild.160101.0800)
- BUILD: 18362
- SERVICEPACK: 778
- PLATFORM_TYPE: x64
- NAME: Windows 10
- EDITION: Windows 10 WinNt TerminalServer SingleUserTS
- BUILD_TIMESTAMP: 2015-10-23 02:39:54
- BUILDDATESTAMP: 160101.0800
- BUILDLAB: WinBuild
- BUILDOSVER: 10.0.18362.778
- Built by: 18362.1.amd64fre.19h1_release.190318-1202
- BUILD_VERSION: 10.0.18362.720 (WinBuild.160101.0800)
- SERVICEPACK: 720
- BUILD_TIMESTAMP: unknown_date
- BUILDOSVER: 10.0.18362.720
- =============================== DEBUGGER ===============================
- Microsoft (R) Windows Debugger Version 10.0.14321.1024 AMD64
- Copyright (c) Microsoft Corporation. All rights reserved.
- =============================== COMMENTS ===============================
- * Information gathered from different dump files may be different. If
- Windows updates between two dump files, two or more OS versions may
- be shown above.
- * If the user updates the BIOS between dump files, two or more versions
- and dates may be shown above.
- * More RAM information can be found below in a full BIOS section.
- ========================================================================
- ======================= Dump #1: ANALYZE VERBOSE =======================
- ======================= File: 042320-5000-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 18362 MP (6 procs) Free x64
- Kernel base = 0xfffff800`1ce00000 PsLoadedModuleList = 0xfffff800`1d248150
- Debug session time: Thu Apr 23 15:25:23.845 2020 (UTC - 4:00)
- System Uptime: 0 days 3:08:57.524
- BugCheck A, {1, 2, 0, fffff8001ce6177e}
- Probably caused by : memory_corruption
- Followup: memory_corruption
- IRQL_NOT_LESS_OR_EQUAL (a)
- An attempt was made to access a pageable (or completely invalid) address at an
- interrupt request level (IRQL) that is too high. This is usually
- caused by drivers using improper addresses.
- If a kernel debugger is available get the stack backtrace.
- Arguments:
- Arg1: 0000000000000001, memory referenced
- Arg2: 0000000000000002, IRQL
- Arg3: 0000000000000000, bitfield :
- bit 0 : value 0 = read operation, 1 = write operation
- bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
- Arg4: fffff8001ce6177e, address which referenced memory
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- DUMP_FILE_ATTRIBUTES: 0x8
- Kernel Generated Triage Dump
- READ_ADDRESS: fffff8001d3733b8: Unable to get MiVisibleState
- 0000000000000001
- CURRENT_IRQL: 2
- FAULTING_IP:
- nt!KiAttemptFastRemoveQueue+32
- fffff800`1ce6177e 493913 cmp qword ptr [r11],rdx
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- BUGCHECK_STR: AV
- PROCESS_NAME: firefox.exe
- TRAP_FRAME: fffff98828c4f530 -- (.trap 0xfffff98828c4f530)
- NOTE: The trap frame does not contain all registers.
- Some register values may be zeroed or incorrect.
- rax=0000000000000000 rbx=0000000000000000 rcx=ffff950de730dbd8
- rdx=ffff950de5053498 rsi=0000000000000000 rdi=0000000000000000
- rip=fffff8001ce6177e rsp=fffff98828c4f6c0 rbp=0000000000000000
- r8=ffff950de730dbc0 r9=ffff950de730dbd8 r10=ffff950de730dbd8
- r11=0000000000000001 r12=0000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=0000000000000000
- iopl=0 nv up ei pl zr na po nc
- nt!KiAttemptFastRemoveQueue+0x32:
- fffff800`1ce6177e 493913 cmp qword ptr [r11],rdx ds:00000000`00000001=????????????????
- Resetting default scope
- LAST_CONTROL_TRANSFER: from fffff8001cfd41e9 to fffff8001cfc2390
- STACK_TEXT:
- fffff988`28c4f3e8 fffff800`1cfd41e9 : 00000000`0000000a 00000000`00000001 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
- fffff988`28c4f3f0 fffff800`1cfd0529 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
- fffff988`28c4f530 fffff800`1ce6177e : 00000000`00000001 00000000`00000001 00000000`00000000 ffff950d`e730dbc0 : nt!KiPageFault+0x469
- fffff988`28c4f6c0 fffff800`1cf18162 : ffff950d`e50533f0 fffff800`00000000 ffff950d`e0985c00 ffff950d`e69c01c0 : nt!KiAttemptFastRemoveQueue+0x32
- fffff988`28c4f700 fffff800`1cf178b9 : fffff988`00000000 ffff950d`ec998401 ffff950d`e8af8b00 ffff950d`00000000 : nt!KeRemoveQueueEx+0x622
- fffff988`28c4f7b0 fffff800`1d3f38f0 : fffff988`28c4f920 0000004f`1adff7c8 00000000`0000c101 00000000`00000000 : nt!IoRemoveIoCompletion+0x99
- fffff988`28c4f8d0 fffff800`1cfd3c15 : ffff950d`e69c0080 0000004f`1adff7a8 fffff988`28c4f9a8 000001da`bbd6a038 : nt!NtRemoveIoCompletion+0x140
- fffff988`28c4f990 00007ffb`ed55c194 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
- 0000004f`1adff788 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffb`ed55c194
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
- fffff8001ce61659 - nt!MiMakeProtoLeafValid+55
- [ f6:b6 ]
- fffff8001ce61780 - nt!KiAttemptFastRemoveQueue+34 (+0x127)
- [ 11:13 ]
- fffff8001ce61e0d-fffff8001ce61e0e 2 bytes - nt!MiRaisedIrqlFault+5d (+0x68d)
- [ fb f6:db b6 ]
- fffff8001ce61e1a-fffff8001ce61e1b 2 bytes - nt!MiRaisedIrqlFault+6a (+0x0d)
- [ fb f6:db b6 ]
- 6 errors : !nt (fffff8001ce61659-fffff8001ce61e1b)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: ONE_BIT_LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_ONE_BIT_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_ONE_BIT_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_ONE_BIT_LARGE
- TARGET_TIME: 2020-04-23T19:25:23.000Z
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_one_bit_large
- FAILURE_ID_HASH: {31545515-196b-fab5-2300-9ce714226f43}
- Followup: memory_corruption
- ====================== Dump #1: 3RD PARTY DRIVERS ======================
- Jun 03 2016 - RTKVHD64.sys - Realtek Audio System driver https://www.realtek.com/en/
- Nov 09 2017 - vbdenum.sys - Citrix ICA Host (Citrix Systems, Inc.)
- Jul 12 2018 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Aug 08 2018 - ctxusbm.sys - Citrix USB Filter Driver https://www.citrix.com
- Oct 22 2018 - rt640x64.sys - Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Mar 14 2019 - nvvad64v.sys - Nvidia Virtual Audio driver http://www.nvidia.com/
- Jan 10 2020 - nvvhci.sys - Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Feb 19 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- Mar 17 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- ================== Dump #1: 3RD PARTY DRIVERS (FULL) ===================
- Image name: RTKVHD64.sys
- Search : https://www.google.com/search?q=RTKVHD64.sys
- ADA Info : Realtek Audio System driver https://www.realtek.com/en/
- Timestamp : Fri Jun 3 2016
- Image name: vbdenum.sys
- Search : https://www.google.com/search?q=vbdenum.sys
- ADA Info : Citrix ICA Host (Citrix Systems, Inc.)
- Timestamp : Thu Nov 9 2017
- Image name: TeeDriverW8x64.sys
- Search : https://www.google.com/search?q=TeeDriverW8x64.sys
- ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Timestamp : Thu Jul 12 2018
- Image name: ctxusbm.sys
- Search : https://www.google.com/search?q=ctxusbm.sys
- ADA Info : Citrix USB Filter Driver https://www.citrix.com
- Timestamp : Wed Aug 8 2018
- Mapped memory image file: C:\ProgramData\dbg\sym\rt640x64.sys\5BCDE005a6000\rt640x64.sys
- Image name: rt640x64.sys
- Search : https://www.google.com/search?q=rt640x64.sys
- ADA Info : Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Timestamp : Mon Oct 22 2018
- File version: 9.1.409.2015
- Product version: 9.1.409.2015
- File flags: 8 (Mask 3F) Private
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- CompanyName: Realtek
- ProductName: Realtek 8125/8136/8168/8169 PCI/PCIe Adapters
- InternalName: rt640x64.sys
- OriginalFilename: rt640x64.sys
- ProductVersion: 9.001.0409.2015
- FileVersion: 9.001.0409.2015
- FileDescription: Realtek 8125/8136/8168/8169 NDIS 6.40 64-bit Driver
- LegalCopyright: Copyright (C) 2018 Realtek Semiconductor Corporation. All Right Reserved.
- Image name: nvvad64v.sys
- Search : https://www.google.com/search?q=nvvad64v.sys
- ADA Info : Nvidia Virtual Audio driver http://www.nvidia.com/
- Timestamp : Thu Mar 14 2019
- Image name: nvvhci.sys
- Search : https://www.google.com/search?q=nvvhci.sys
- ADA Info : Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Timestamp : Fri Jan 10 2020
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Wed Feb 19 2020
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Tue Mar 17 2020
- ====================== Dump #1: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- acpipagr.sys ACPI Processor Aggregator Device driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdfs.sys CD-ROM File System Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- csc.sys Windows Client Side Caching driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storport.sys Provides disk access during crash dump file generation (Microsoft)
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- FsDepends.sys File System Dependency Manager Mini Filter driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- IndirectKmd.sys Indirect displays kernel-mode filter driver
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- intelppm.sys Processor Device Driver (Microsoft)
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kdcom.dll Kernel Debugger HW Extension DLL (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate.dll Media Center Update (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- serenum.sys Serial Port Enumerator (Microsoft)
- serial.sys Serial Device Driver
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- ucx01000.sys USB Controller Extension (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- vhdmp.sys VHD Miniport driver (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- winquic.sys QUIC Transport Protocol driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- WUDFRd.sys Windows Driver Foundation - User-mode Driver Framework Reflector driver (Microsoft)
- ====================== Dump #1: UNLOADED MODULES =======================
- fffff800`6bbc0000 fffff800`6bbd4000 WdNisDrv.sys
- fffff800`6ba40000 fffff800`6ba54000 WdNisDrv.sys
- fffff800`27d40000 fffff800`27d4f000 dump_storpor
- fffff800`27d80000 fffff800`27daf000 dump_storahc
- fffff800`27dd0000 fffff800`27dee000 dump_dumpfve
- fffff800`29970000 fffff800`299c1000 WUDFRd.sys
- fffff800`27a70000 fffff800`27a8e000 dam.sys
- fffff800`201b0000 fffff800`201c1000 WdBoot.sys
- fffff800`211b0000 fffff800`211c1000 hwpolicy.sys
- ====================== Dump #1: BIOS INFORMATION =======================
- [SMBIOS Data Tables v3.0]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 4215 bytes]
- [BIOS Information (Type 0) - Length 24 - Handle 0000h]
- Vendor American Megatrends Inc.
- BIOS Version 2401
- BIOS Starting Address Segment f000
- BIOS Release Date 07/15/2019
- BIOS ROM Size 1000000
- BIOS Characteristics
- 07: - PCI Supported
- 10: - APM Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 27: - Keyboard Services Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 32: - BIOS Vendor Reserved
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 5
- BIOS Minor Revision 12
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- Manufacturer System manufacturer
- Product Name System Product Name
- Version System Version
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- SKUNumber SKU
- [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
- Manufacturer ASUSTeK COMPUTER INC.
- Product PRIME Z370-P
- Version Rev X.0x
- Feature Flags 09h
- -527780128: - -527780080: - ÷7£ý
- Location Default string
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 22 - Handle 0003h]
- Manufacturer Default string
- Chassis Type Desktop
- Version Default string
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 3
- [Onboard Devices Information (Type 10) - Length 6 - Handle 0021h]
- Number of Devices 1
- 01: Type Video [enabled]
- [OEM Strings (Type 11) - Length 5 - Handle 0022h]
- Number of Strings 8
- 1 Default string
- 2 Default string
- 3 COD
- 4 Default string
- 5 FFFFFFFFFFFFF
- 6 FFFFFFFFFFFFF
- 7 FFFFFFFFFFFFF
- 8 Default string
- [System Configuration Options (Type 12) - Length 5 - Handle 0023h]
- [Physical Memory Array (Type 16) - Length 23 - Handle 003eh]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 67108864KB
- Number of Memory Devices 4
- [Memory Device (Type 17) - Length 40 - Handle 003fh]
- Physical Memory Array Handle 003eh
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 02h - Unknown
- Device Locator ChannelA-DIMM1
- Bank Locator BANK 0
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Device (Type 17) - Length 40 - Handle 0040h]
- Physical Memory Array Handle 003eh
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM2
- Bank Locator BANK 1
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 2400MHz
- Manufacturer Corsair
- Part Number CMK16GX4M2A2400C16
- [Memory Device (Type 17) - Length 40 - Handle 0041h]
- Physical Memory Array Handle 003eh
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 02h - Unknown
- Device Locator ChannelB-DIMM1
- Bank Locator BANK 2
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Device (Type 17) - Length 40 - Handle 0042h]
- Physical Memory Array Handle 003eh
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM2
- Bank Locator BANK 3
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 2400MHz
- Manufacturer Corsair
- Part Number CMK16GX4M2A2400C16
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0043h]
- Starting Address 00000000h
- Ending Address 00ffffffh
- Memory Array Handle 003eh
- Partition Width 02
- [Cache Information (Type 7) - Length 19 - Handle 0044h]
- Socket Designation L1 Cache
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0180h - 384K
- Installed Size 0180h - 384K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type ParitySingle-Bit ECC
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0045h]
- Socket Designation L2 Cache
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 0600h - 1536K
- Installed Size 0600h - 1536K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Unified
- Associativity 4-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0046h]
- Socket Designation L3 Cache
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 2400h - 9216K
- Installed Size 2400h - 9216K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity Specification Reserved
- [Processor Information (Type 4) - Length 48 - Handle 0047h]
- Socket Designation LGA1151
- Processor Type Central Processor
- Processor Family cdh - Specification Reserved
- Processor Manufacturer Intel(R) Corporation
- Processor ID ea060900fffbebbf
- Processor Version Intel(R) Core(TM) i5-8600K CPU @ 3.60GHz
- Processor Voltage 8ah - 1.0V
- External Clock 100MHz
- Max Speed 8300MHz
- Current Speed 3600MHz
- Status Enabled Populated
- Processor Upgrade Specification Reserved
- L1 Cache Handle 0044h
- L2 Cache Handle 0045h
- L3 Cache Handle 0046h
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0048h]
- Starting Address 00000000h
- Ending Address 007fffffh
- Memory Device Handle 0040h
- Mem Array Mapped Adr Handle 0043h
- Interleave Position 01
- Interleave Data Depth 02
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0049h]
- Starting Address 00800000h
- Ending Address 00ffffffh
- Memory Device Handle 0042h
- Mem Array Mapped Adr Handle 0043h
- Interleave Position 02
- Interleave Data Depth 02
- ========================== Dump #1: Extra #1 ===========================
- 4: kd> !verifier
- fffff8001d248580: Unable to get verifier list.
- ========================== Dump #1: Extra #2 ===========================
- 4: kd> !thread
- THREAD ffff950de69c0080 Cid 2290.22a8 Teb: 0000004f18c08000 Win32Thread: ffff950de63a3710 WAIT: (WrQueue) UserMode Non-Alertable
- ffff950de730dbc0 QueueObject
- Not impersonating
- GetUlongFromAddress: unable to read from fffff8001d22ca14
- Owning Process ffff950de6fec080 Image: firefox.exe
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 725601
- Context Switch Count 3082802 IdealProcessor: 5
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address 0x00007ffbac3edd30
- Stack Init fffff98828c4fb90 Current fffff98828c4f440
- Base fffff98828c50000 Limit fffff98828c49000 Call 0000000000000000
- Priority 12 BasePriority 8 PriorityDecrement 2 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- fffff988`28c4f480 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x0
- ========================================================================
- ======================= Dump #2: ANALYZE VERBOSE =======================
- ======================= File: 042220-4984-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 18362 MP (6 procs) Free x64
- Kernel base = 0xfffff806`61000000 PsLoadedModuleList = 0xfffff806`61448150
- Debug session time: Wed Apr 22 03:45:16.838 2020 (UTC - 4:00)
- System Uptime: 0 days 0:00:58.517
- BugCheck 1E, {ffffffffc0000005, fffff80665e2e605, 1, 9f2fb71}
- Probably caused by : memory_corruption
- Followup: memory_corruption
- KMODE_EXCEPTION_NOT_HANDLED (1e)
- This is a very common bugcheck. Usually the exception address pinpoints
- the driver/function that caused the problem. Always note this address
- as well as the link date of the driver/image that contains this address.
- Arguments:
- Arg1: ffffffffc0000005, The exception code that was not handled
- Arg2: fffff80665e2e605, The address that the exception occurred at
- Arg3: 0000000000000001, Parameter 0 of the exception
- Arg4: 0000000009f2fb71, Parameter 1 of the exception
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- DUMP_FILE_ATTRIBUTES: 0x8
- Kernel Generated Triage Dump
- WRITE_ADDRESS: fffff806615733b8: Unable to get MiVisibleState
- 0000000009f2fb71
- EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.
- FAULTING_IP:
- fileinfo!FIPfInterfaceClose+145
- fffff806`65e2e605 00488d add byte ptr [rax-73h],cl
- EXCEPTION_PARAMETER1: 0000000000000001
- EXCEPTION_PARAMETER2: 0000000009f2fb71
- BUGCHECK_STR: 0x1E_c0000005_W
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- PROCESS_NAME: svchost.exe
- CURRENT_IRQL: 0
- EXCEPTION_RECORD: ffffed76bb5da000 -- (.exr 0xffffed76bb5da000)
- Cannot read Exception record @ ffffed76bb5da000
- TRAP_FRAME: ffff800000000000 -- (.trap 0xffff800000000000)
- Unable to read trap frame at ffff8000`00000000
- LAST_CONTROL_TRANSFER: from fffff8066125ad71 to fffff806611c2390
- STACK_TEXT:
- fffff280`3e9c6688 fffff806`6125ad71 : 00000000`0000001e ffffffff`c0000005 fffff806`65e2e605 00000000`00000001 : nt!KeBugCheckEx
- fffff280`3e9c6690 fffff806`611d431d : ffffed76`bb5da000 fffff280`3e9c6f20 ffff8000`00000000 00000000`09f2fb71 : nt!KiDispatchException+0x15c681
- fffff280`3e9c6d40 fffff806`611d0503 : 33333333`33333333 00000000`00002bed 00000000`0000e36a ffffd905`a2000280 : nt!KiExceptionDispatch+0x11d
- fffff280`3e9c6f20 fffff806`65e2e605 : fffff280`3e9c7110 ffffd905`a9a4e080 ffffd905`ac7f42c0 ffffd905`acadd608 : nt!KiPageFault+0x443
- fffff280`3e9c70b0 fffff806`61635e3d : fffff280`3e9c7301 fffff280`3e9c72b0 ffffd905`acadd608 fffff806`6136f019 : fileinfo!FIPfInterfaceClose+0x145
- fffff280`3e9c70f0 fffff806`615e1655 : 00000000`00000000 00000000`000031e2 fffff280`3e9c7301 ffffd905`acadc000 : nt!PfpOpenHandleClose+0x55
- fffff280`3e9c7140 fffff806`615e1b72 : 00000000`00000000 00000000`00000000 00000000`00000000 ffff860b`10945190 : nt!PfpReadSupportCleanup+0x49
- fffff280`3e9c7170 fffff806`6160a48a : ffffd905`00000000 fffff280`00000658 ffffd905`00000000 ffffd905`00000006 : nt!PfpPrefetchFilesTrickle+0x28e
- fffff280`3e9c7260 fffff806`6160a109 : ffffd905`acadc000 ffffd905`acadc000 fffff280`3e9c7480 00000000`00000000 : nt!PfpPrefetchRequestPerform+0x2b6
- fffff280`3e9c73d0 fffff806`615e99e2 : 00000000`00000001 00000000`00000001 ffffd905`acadc000 ffff860b`11747be0 : nt!PfpPrefetchRequest+0x129
- fffff280`3e9c7450 fffff806`615e7a54 : 00000000`00000000 00000000`00000000 ffff860b`0f50b730 fffff280`3e9c7601 : nt!PfSetSuperfetchInformation+0x16e
- fffff280`3e9c7550 fffff806`611d3c15 : ffff860b`10bd8080 0000002a`a1b05000 0000002a`a247f6e0 ffff860b`0f613d60 : nt!NtSetSystemInformation+0x294
- fffff280`3e9c7a00 00007ffd`1671f4e4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
- 0000002a`a247f528 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffd`1671f4e4
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !fileinfo
- fffff80665e2e01e-fffff80665e2e01f 2 bytes - fileinfo!FIPostCreateCallback+37e
- [ 48 ff:4c 8b ]
- fffff80665e2e025-fffff80665e2e029 5 bytes - fileinfo!FIPostCreateCallback+385 (+0x07)
- [ 0f 1f 44 00 00:e8 86 7f 2d fb ]
- fffff80665e2e0f2-fffff80665e2e0f3 2 bytes - fileinfo!FIPostCreateCallback+452 (+0xcd)
- [ 48 ff:4c 8b ]
- fffff80665e2e0f9-fffff80665e2e0fd 5 bytes - fileinfo!FIPostCreateCallback+459 (+0x07)
- [ 0f 1f 44 00 00:e8 22 b3 6e ff ]
- fffff80665e2e23c-fffff80665e2e23d 2 bytes - fileinfo!FIPfFileFSOpPostCreate+11c (+0x143)
- [ 48 ff:4c 8b ]
- fffff80665e2e243-fffff80665e2e247 5 bytes - fileinfo!FIPfFileFSOpPostCreate+123 (+0x07)
- [ 0f 1f 44 00 00:e8 28 f5 6e ff ]
- fffff80665e2e29c-fffff80665e2e29d 2 bytes - fileinfo!FIPfFileFSOpPostCreate+17c (+0x59)
- [ 48 ff:4c 8b ]
- fffff80665e2e2a3-fffff80665e2e2a7 5 bytes - fileinfo!FIPfFileFSOpPostCreate+183 (+0x07)
- [ 0f 1f 44 00 00:e8 28 58 22 fb ]
- fffff80665e2e2bf-fffff80665e2e2c0 2 bytes - fileinfo!FIPfFileFSOpPostCreate+19f (+0x1c)
- [ 48 ff:4c 8b ]
- fffff80665e2e2c6-fffff80665e2e2ca 5 bytes - fileinfo!FIPfFileFSOpPostCreate+1a6 (+0x07)
- [ 0f 1f 44 00 00:e8 45 ee 71 ff ]
- fffff80665e2e2ef-fffff80665e2e2f0 2 bytes - fileinfo!FIPfFileFSOpPostCreate+1cf (+0x29)
- [ 48 ff:4c 8b ]
- fffff80665e2e2f6-fffff80665e2e2fa 5 bytes - fileinfo!FIPfFileFSOpPostCreate+1d6 (+0x07)
- [ 0f 1f 44 00 00:e8 f5 4e 72 ff ]
- fffff80665e2e36a-fffff80665e2e36b 2 bytes - fileinfo!FIPfFileFSOpPostCreate+24a (+0x74)
- [ 48 ff:4c 8b ]
- fffff80665e2e371-fffff80665e2e375 5 bytes - fileinfo!FIPfFileFSOpPostCreate+251 (+0x07)
- [ 0f 1f 44 00 00:e8 7a d5 30 fb ]
- fffff80665e2e419-fffff80665e2e41a 2 bytes - fileinfo!FIPfFileFSOpPostCreate+2f9 (+0xa8)
- [ 48 ff:4c 8b ]
- fffff80665e2e420-fffff80665e2e424 5 bytes - fileinfo!FIPfFileFSOpPostCreate+300 (+0x07)
- [ 0f 1f 44 00 00:e8 cb 79 71 ff ]
- fffff80665e2e42d-fffff80665e2e42e 2 bytes - fileinfo!FIPfFileFSOpPostCreate+30d (+0x0d)
- [ 48 ff:4c 8b ]
- fffff80665e2e434-fffff80665e2e438 5 bytes - fileinfo!FIPfFileFSOpPostCreate+314 (+0x07)
- [ 0f 1f 44 00 00:e8 e7 af 6e ff ]
- fffff80665e2e451-fffff80665e2e452 2 bytes - fileinfo!FIPfFileFSOpPostCreate+331 (+0x1d)
- [ 48 ff:4c 8b ]
- fffff80665e2e458-fffff80665e2e45c 5 bytes - fileinfo!FIPfFileFSOpPostCreate+338 (+0x07)
- [ 0f 1f 44 00 00:e8 f3 34 2e fb ]
- fffff80665e2e462-fffff80665e2e463 2 bytes - fileinfo!FIPfFileFSOpPostCreate+342 (+0x0a)
- [ 48 ff:4c 8b ]
- fffff80665e2e469-fffff80665e2e46d 5 bytes - fileinfo!FIPfFileFSOpPostCreate+349 (+0x07)
- [ 0f 1f 44 00 00:e8 b2 af 6e ff ]
- fffff80665e2e4f5-fffff80665e2e4f6 2 bytes - fileinfo!FIPfInterfaceClose+35 (+0x8c)
- [ 48 ff:4c 8b ]
- fffff80665e2e4fc-fffff80665e2e500 5 bytes - fileinfo!FIPfInterfaceClose+3c (+0x07)
- [ 0f 1f 44 00 00:e8 4f 34 2e fb ]
- fffff80665e2e505-fffff80665e2e506 2 bytes - fileinfo!FIPfInterfaceClose+45 (+0x09)
- [ 48 ff:4c 8b ]
- fffff80665e2e50c-fffff80665e2e510 5 bytes - fileinfo!FIPfInterfaceClose+4c (+0x07)
- [ 0f 1f 44 00 00:e8 cf 52 72 ff ]
- fffff80665e2e600 - fileinfo!FIPfInterfaceClose+140 (+0xf4)
- [ 0f:0d ]
- fffff80665e2e622-fffff80665e2e623 2 bytes - fileinfo!FIPfInterfaceClose+162 (+0x22)
- [ 48 ff:4c 8b ]
- fffff80665e2e629-fffff80665e2e62d 5 bytes - fileinfo!FIPfInterfaceClose+169 (+0x07)
- [ 0f 1f 44 00 00:e8 f2 ad 6e ff ]
- fffff80665e2e633-fffff80665e2e634 2 bytes - fileinfo!FIPfInterfaceClose+173 (+0x0a)
- [ 48 ff:4c 8b ]
- fffff80665e2e63a-fffff80665e2e63e 5 bytes - fileinfo!FIPfInterfaceClose+17a (+0x07)
- [ 0f 1f 44 00 00:e8 d1 09 54 fb ]
- fffff80665e2e64f-fffff80665e2e650 2 bytes - fileinfo!FIPfInterfaceClose+18f (+0x15)
- [ 48 ff:4c 8b ]
- fffff80665e2e656-fffff80665e2e65a 5 bytes - fileinfo!FIPfInterfaceClose+196 (+0x07)
- [ 0f 1f 44 00 00:e8 c5 ad 6e ff ]
- fffff80665e2e7d1-fffff80665e2e7d2 2 bytes - fileinfo!FIPfFileOpenAdd+f1 (+0x17b)
- [ 48 ff:4c 8b ]
- fffff80665e2e7d8-fffff80665e2e7dc 5 bytes - fileinfo!FIPfFileOpenAdd+f8 (+0x07)
- [ 0f 1f 44 00 00:e8 43 c1 6e ff ]
- fffff80665e2e882-fffff80665e2e883 2 bytes - fileinfo!FIPfFileOpenAdd+1a2 (+0xaa)
- [ 48 ff:4c 8b ]
- fffff80665e2e889-fffff80665e2e88d 5 bytes - fileinfo!FIPfFileOpenAdd+1a9 (+0x07)
- [ 0f 1f 44 00 00:e8 82 07 54 fb ]
- fffff80665e2e94a-fffff80665e2e94b 2 bytes - fileinfo!FIPfInterfaceOpen+aa (+0xc1)
- [ 48 ff:4c 8b ]
- fffff80665e2e951-fffff80665e2e955 5 bytes - fileinfo!FIPfInterfaceOpen+b1 (+0x07)
- [ 0f 1f 44 00 00:e8 ea 82 25 fb ]
- fffff80665e2e9cb-fffff80665e2e9cc 2 bytes - fileinfo!FIPfInterfaceOpen+12b (+0x7a)
- [ 48 ff:4c 8b ]
- fffff80665e2e9d2-fffff80665e2e9d6 5 bytes - fileinfo!FIPfInterfaceOpen+132 (+0x07)
- [ 0f 1f 44 00 00:e8 59 06 54 fb ]
- fffff80665e2eaad-fffff80665e2eaae 2 bytes - fileinfo!FIPfInterfaceOpen+20d (+0xdb)
- [ 48 ff:4c 8b ]
- fffff80665e2eab4-fffff80665e2eab8 5 bytes - fileinfo!FIPfInterfaceOpen+214 (+0x07)
- [ 0f 1f 44 00 00:e8 47 fb 89 fb ]
- fffff80665e2eabf-fffff80665e2eac0 2 bytes - fileinfo!FIPfInterfaceOpen+21f (+0x0b)
- [ 48 ff:4c 8b ]
- fffff80665e2eac6-fffff80665e2eaca 5 bytes - fileinfo!FIPfInterfaceOpen+226 (+0x07)
- [ 0f 1f 44 00 00:e8 35 fb 89 fb ]
- fffff80665e2ec7d-fffff80665e2ec7e 2 bytes - fileinfo!FIPfInterfaceOpen+3dd (+0x1b7)
- [ 48 ff:4c 8b ]
- fffff80665e2ec84-fffff80665e2ec88 5 bytes - fileinfo!FIPfInterfaceOpen+3e4 (+0x07)
- [ 0f 1f 44 00 00:e8 b7 b5 71 ff ]
- fffff80665e2ecbf-fffff80665e2ecc0 2 bytes - fileinfo!FIPfInterfaceOpen+41f (+0x3b)
- [ 48 ff:4c 8b ]
- fffff80665e2ecc6-fffff80665e2ecca 5 bytes - fileinfo!FIPfInterfaceOpen+426 (+0x07)
- [ 0f 1f 44 00 00:e8 75 bb 2d fb ]
- fffff80665e2ecd2-fffff80665e2ecd3 2 bytes - fileinfo!FIPfInterfaceOpen+432 (+0x0c)
- [ 48 ff:4c 8b ]
- WARNING: !chkimg output was truncated to 50 lines. Invoke !chkimg without '-lo [num_lines]' to view entire output.
- 218 errors : !fileinfo (fffff80665e2e01e-fffff80665e2eecf)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-04-22T07:45:16.000Z
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #2: 3RD PARTY DRIVERS ======================
- Jun 03 2016 - RTKVHD64.sys - Realtek Audio System driver https://www.realtek.com/en/
- Nov 09 2017 - vbdenum.sys - Citrix ICA Host (Citrix Systems, Inc.)
- Jul 12 2018 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Aug 08 2018 - ctxusbm.sys - Citrix USB Filter Driver https://www.citrix.com
- Aug 28 2018 - rt640x64.sys - Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Mar 14 2019 - nvvad64v.sys - Nvidia Virtual Audio driver http://www.nvidia.com/
- Jan 10 2020 - nvvhci.sys - Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Feb 19 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- Mar 17 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- ================== Dump #2: 3RD PARTY DRIVERS (FULL) ===================
- Image name: RTKVHD64.sys
- Search : https://www.google.com/search?q=RTKVHD64.sys
- ADA Info : Realtek Audio System driver https://www.realtek.com/en/
- Timestamp : Fri Jun 3 2016
- Image name: vbdenum.sys
- Search : https://www.google.com/search?q=vbdenum.sys
- ADA Info : Citrix ICA Host (Citrix Systems, Inc.)
- Timestamp : Thu Nov 9 2017
- Image name: TeeDriverW8x64.sys
- Search : https://www.google.com/search?q=TeeDriverW8x64.sys
- ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Timestamp : Thu Jul 12 2018
- Image name: ctxusbm.sys
- Search : https://www.google.com/search?q=ctxusbm.sys
- ADA Info : Citrix USB Filter Driver https://www.citrix.com
- Timestamp : Wed Aug 8 2018
- Image name: rt640x64.sys
- Search : https://www.google.com/search?q=rt640x64.sys
- ADA Info : Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Timestamp : Tue Aug 28 2018
- Image name: nvvad64v.sys
- Search : https://www.google.com/search?q=nvvad64v.sys
- ADA Info : Nvidia Virtual Audio driver http://www.nvidia.com/
- Timestamp : Thu Mar 14 2019
- Image name: nvvhci.sys
- Search : https://www.google.com/search?q=nvvhci.sys
- ADA Info : Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Timestamp : Fri Jan 10 2020
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Wed Feb 19 2020
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Tue Mar 17 2020
- ====================== Dump #2: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- acpipagr.sys ACPI Processor Aggregator Device driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- csc.sys Windows Client Side Caching driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storport.sys Provides disk access during crash dump file generation (Microsoft)
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- IndirectKmd.sys Indirect displays kernel-mode filter driver
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- intelppm.sys Processor Device Driver (Microsoft)
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kdcom.dll Kernel Debugger HW Extension DLL (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate.dll Media Center Update (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- serenum.sys Serial Port Enumerator (Microsoft)
- serial.sys Serial Device Driver
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- ucx01000.sys USB Controller Extension (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- winquic.sys QUIC Transport Protocol driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- WUDFRd.sys Windows Driver Foundation - User-mode Driver Framework Reflector driver (Microsoft)
- ====================== Dump #2: UNLOADED MODULES =======================
- fffff806`6cc80000 fffff806`6cc8f000 dump_storpor
- fffff806`6ccc0000 fffff806`6ccef000 dump_storahc
- fffff806`6cd10000 fffff806`6cd2e000 dump_dumpfve
- fffff806`701e0000 fffff806`70231000 WUDFRd.sys
- fffff806`6d570000 fffff806`6d58e000 dam.sys
- fffff806`659b0000 fffff806`659c1000 WdBoot.sys
- fffff806`669b0000 fffff806`669c1000 hwpolicy.sys
- ====================== Dump #2: BIOS INFORMATION =======================
- sysinfo: could not find necessary interfaces.
- sysinfo: note that mssmbios.sys must be loaded (XPSP2+).
- ========================== Dump #2: Extra #1 ===========================
- 3: kd> !verifier
- fffff80661448580: Unable to get verifier list.
- ========================== Dump #2: Extra #2 ===========================
- 3: kd> !thread
- THREAD ffff860b10bd8080 Cid 06c8.12a4 Teb: 0000002aa1b1c000 Win32Thread: 0000000000000000 RUNNING on processor 3
- Impersonation token: ffffd905abc43670 (Level Impersonation)
- GetUlongFromAddress: unable to read from fffff8066142ca14
- Owning Process ffff860b0f6ab0c0 Image: svchost.exe
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 3745
- Context Switch Count 812 IdealProcessor: 0
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address 0x00007ffd0e49ebd0
- Stack Init fffff2803e9c7b90 Current fffff2803e9c6b30
- Base fffff2803e9c8000 Limit fffff2803e9c1000 Call 0000000000000000
- Priority 7 BasePriority 6 PriorityDecrement 0 IoPriority 0 PagePriority 1
- Child-SP RetAddr : Args to Child : Call Site
- fffff280`3e9c6688 fffff806`6125ad71 : 00000000`0000001e ffffffff`c0000005 fffff806`65e2e605 00000000`00000001 : nt!KeBugCheckEx
- fffff280`3e9c6690 fffff806`611d431d : ffffed76`bb5da000 fffff280`3e9c6f20 ffff8000`00000000 00000000`09f2fb71 : nt!KiDispatchException+0x15c681
- fffff280`3e9c6d40 fffff806`611d0503 : 33333333`33333333 00000000`00002bed 00000000`0000e36a ffffd905`a2000280 : nt!KiExceptionDispatch+0x11d
- fffff280`3e9c6f20 fffff806`65e2e605 : fffff280`3e9c7110 ffffd905`a9a4e080 ffffd905`ac7f42c0 ffffd905`acadd608 : nt!KiPageFault+0x443 (TrapFrame @ fffff280`3e9c6f20)
- fffff280`3e9c70b0 fffff806`61635e3d : fffff280`3e9c7301 fffff280`3e9c72b0 ffffd905`acadd608 fffff806`6136f019 : fileinfo!FIPfInterfaceClose+0x145
- fffff280`3e9c70f0 fffff806`615e1655 : 00000000`00000000 00000000`000031e2 fffff280`3e9c7301 ffffd905`acadc000 : nt!PfpOpenHandleClose+0x55
- fffff280`3e9c7140 fffff806`615e1b72 : 00000000`00000000 00000000`00000000 00000000`00000000 ffff860b`10945190 : nt!PfpReadSupportCleanup+0x49
- fffff280`3e9c7170 fffff806`6160a48a : ffffd905`00000000 fffff280`00000658 ffffd905`00000000 ffffd905`00000006 : nt!PfpPrefetchFilesTrickle+0x28e
- fffff280`3e9c7260 fffff806`6160a109 : ffffd905`acadc000 ffffd905`acadc000 fffff280`3e9c7480 00000000`00000000 : nt!PfpPrefetchRequestPerform+0x2b6
- fffff280`3e9c73d0 fffff806`615e99e2 : 00000000`00000001 00000000`00000001 ffffd905`acadc000 ffff860b`11747be0 : nt!PfpPrefetchRequest+0x129
- fffff280`3e9c7450 fffff806`615e7a54 : 00000000`00000000 00000000`00000000 ffff860b`0f50b730 fffff280`3e9c7601 : nt!PfSetSuperfetchInformation+0x16e
- fffff280`3e9c7550 fffff806`611d3c15 : ffff860b`10bd8080 0000002a`a1b05000 0000002a`a247f6e0 ffff860b`0f613d60 : nt!NtSetSystemInformation+0x294
- fffff280`3e9c7a00 00007ffd`1671f4e4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25 (TrapFrame @ fffff280`3e9c7a00)
- 0000002a`a247f528 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffd`1671f4e4
- ========================================================================
- ======================= Dump #3: ANALYZE VERBOSE =======================
- ======================= File: 041920-4531-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 18362 MP (6 procs) Free x64
- Kernel base = 0xfffff805`45200000 PsLoadedModuleList = 0xfffff805`45648150
- Debug session time: Sun Apr 19 15:50:49.924 2020 (UTC - 4:00)
- System Uptime: 0 days 0:00:11.603
- BugCheck EF, {ffffc78db1bfa4c0, 0, 0, 0}
- Probably caused by : ntkrnlmp.exe ( nt!PspCatchCriticalBreak+115 )
- Followup: MachineOwner
- CRITICAL_PROCESS_DIED (ef)
- A critical system process died
- Arguments:
- Arg1: ffffc78db1bfa4c0, Process object or thread object
- Arg2: 0000000000000000, If this is 0, a process died. If this is 1, a thread died.
- Arg3: 0000000000000000
- Arg4: 0000000000000000
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- DUMP_FILE_ATTRIBUTES: 0x8
- Kernel Generated Triage Dump
- PROCESS_NAME: svchost.exe
- CRITICAL_PROCESS: svchost.exe
- EXCEPTION_CODE: (HRESULT) 0xab75e080 (2876629120) - <Unable to get error code text>
- ERROR_CODE: (NTSTATUS) 0xab75e080 - <Unable to get error code text>
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
- BUGCHECK_STR: 0xEF
- CURRENT_IRQL: 0
- LAST_CONTROL_TRANSFER: from fffff80545acb8a9 to fffff805453c2390
- STACK_TEXT:
- ffff8405`187a7838 fffff805`45acb8a9 : 00000000`000000ef ffffc78d`b1bfa4c0 00000000`00000000 00000000`00000000 : nt!KeBugCheckEx
- ffff8405`187a7840 fffff805`459ecbdf : ffffc78d`b1bfa4c0 fffff805`45288065 ffffc78d`b1bfa4c0 fffff805`452880e0 : nt!PspCatchCriticalBreak+0x115
- ffff8405`187a78e0 fffff805`458700c0 : ffffc78d`00000000 00000000`00000000 ffffc78d`b1bfa4c0 ffffc78d`b1bfa4c0 : nt!PspTerminateAllThreads+0x17b193
- ffff8405`187a7950 fffff805`4586fce9 : ffffffff`ffffffff ffff8405`187a7a80 ffffc78d`b1bfa4c0 fffff805`45879401 : nt!PspTerminateProcess+0xe0
- ffff8405`187a7990 fffff805`453d3c15 : ffffc78d`0000021c ffffc78d`ab75e080 ffffc78d`b1bfa4c0 00000072`d297f7dc : nt!NtTerminateProcess+0xa9
- ffff8405`187a7a00 00007ffe`e0f1c5f4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
- 00000072`d297c4e8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffe`e0f1c5f4
- STACK_COMMAND: kb
- THREAD_SHA1_HASH_MOD_FUNC: 042a2b51772309c39e12d732cc93cacf0af3064e
- THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 34572be19e12d6120744c21456db4e874020aa32
- THREAD_SHA1_HASH_MOD: ee8fcf1fb60cb6e3e2f60ddbed2ec02b5748a693
- FOLLOWUP_IP:
- nt!PspCatchCriticalBreak+115
- fffff805`45acb8a9 cc int 3
- FAULT_INSTR_CODE: ed8440cc
- SYMBOL_STACK_INDEX: 1
- SYMBOL_NAME: nt!PspCatchCriticalBreak+115
- FOLLOWUP_NAME: MachineOwner
- MODULE_NAME: nt
- IMAGE_NAME: ntkrnlmp.exe
- DEBUG_FLR_IMAGE_TIMESTAMP: 5629d63a
- IMAGE_VERSION: 10.0.18362.778
- BUCKET_ID_FUNC_OFFSET: 115
- FAILURE_BUCKET_ID: 0xEF_svchost.exe_BUGCHECK_CRITICAL_PROCESS_ab75e080_nt!PspCatchCriticalBreak
- BUCKET_ID: 0xEF_svchost.exe_BUGCHECK_CRITICAL_PROCESS_ab75e080_nt!PspCatchCriticalBreak
- PRIMARY_PROBLEM_CLASS: 0xEF_svchost.exe_BUGCHECK_CRITICAL_PROCESS_ab75e080_nt!PspCatchCriticalBreak
- TARGET_TIME: 2020-04-19T19:50:49.000Z
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:0xef_svchost.exe_bugcheck_critical_process_ab75e080_nt!pspcatchcriticalbreak
- FAILURE_ID_HASH: {cd9b01d0-cd93-b821-3d16-f5bdb93b4cd3}
- Followup: MachineOwner
- ====================== Dump #3: 3RD PARTY DRIVERS ======================
- Jun 03 2016 - RTKVHD64.sys - Realtek Audio System driver https://www.realtek.com/en/
- Nov 09 2017 - vbdenum.sys - Citrix ICA Host (Citrix Systems, Inc.)
- Jul 12 2018 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Aug 08 2018 - ctxusbm.sys - Citrix USB Filter Driver https://www.citrix.com
- Aug 28 2018 - rt640x64.sys - Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Mar 14 2019 - nvvad64v.sys - Nvidia Virtual Audio driver http://www.nvidia.com/
- Jan 10 2020 - nvvhci.sys - Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Feb 19 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- Mar 17 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- ================== Dump #3: 3RD PARTY DRIVERS (FULL) ===================
- Image name: RTKVHD64.sys
- Search : https://www.google.com/search?q=RTKVHD64.sys
- ADA Info : Realtek Audio System driver https://www.realtek.com/en/
- Timestamp : Fri Jun 3 2016
- Image name: vbdenum.sys
- Search : https://www.google.com/search?q=vbdenum.sys
- ADA Info : Citrix ICA Host (Citrix Systems, Inc.)
- Timestamp : Thu Nov 9 2017
- Image name: TeeDriverW8x64.sys
- Search : https://www.google.com/search?q=TeeDriverW8x64.sys
- ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Timestamp : Thu Jul 12 2018
- Image name: ctxusbm.sys
- Search : https://www.google.com/search?q=ctxusbm.sys
- ADA Info : Citrix USB Filter Driver https://www.citrix.com
- Timestamp : Wed Aug 8 2018
- Image name: rt640x64.sys
- Search : https://www.google.com/search?q=rt640x64.sys
- ADA Info : Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Timestamp : Tue Aug 28 2018
- Image name: nvvad64v.sys
- Search : https://www.google.com/search?q=nvvad64v.sys
- ADA Info : Nvidia Virtual Audio driver http://www.nvidia.com/
- Timestamp : Thu Mar 14 2019
- Image name: nvvhci.sys
- Search : https://www.google.com/search?q=nvvhci.sys
- ADA Info : Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Timestamp : Fri Jan 10 2020
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Wed Feb 19 2020
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Tue Mar 17 2020
- ====================== Dump #3: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- acpipagr.sys ACPI Processor Aggregator Device driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- csc.sys Windows Client Side Caching driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storport.sys Provides disk access during crash dump file generation (Microsoft)
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- IndirectKmd.sys Indirect displays kernel-mode filter driver
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- intelppm.sys Processor Device Driver (Microsoft)
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kdcom.dll Kernel Debugger HW Extension DLL (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate.dll Media Center Update (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- serenum.sys Serial Port Enumerator (Microsoft)
- serial.sys Serial Device Driver
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- ucx01000.sys USB Controller Extension (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- winquic.sys QUIC Transport Protocol driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- WUDFRd.sys Windows Driver Foundation - User-mode Driver Framework Reflector driver (Microsoft)
- ====================== Dump #3: UNLOADED MODULES =======================
- fffff805`4f570000 fffff805`4f5c1000 WUDFRd.sys
- fffff805`4f1e0000 fffff805`4f1fe000 dam.sys
- fffff805`479b0000 fffff805`479c1000 WdBoot.sys
- fffff805`489b0000 fffff805`489c1000 hwpolicy.sys
- ====================== Dump #3: BIOS INFORMATION =======================
- [SMBIOS Data Tables v3.0]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 4215 bytes]
- [BIOS Information (Type 0) - Length 24 - Handle 0000h]
- Vendor American Megatrends Inc.
- BIOS Version 2401
- BIOS Starting Address Segment f000
- BIOS Release Date 07/15/2019
- BIOS ROM Size 1000000
- BIOS Characteristics
- 07: - PCI Supported
- 10: - APM Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 27: - Keyboard Services Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 32: - BIOS Vendor Reserved
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 5
- BIOS Minor Revision 12
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- Manufacturer System manufacturer
- Product Name System Product Name
- Version System Version
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- SKUNumber SKU
- [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
- Manufacturer ASUSTeK COMPUTER INC.
- Product PRIME Z370-P
- Version Rev X.0x
- Feature Flags 09h
- -362039584: - -362039536: - ÷7£ý
- Location Default string
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 22 - Handle 0003h]
- Manufacturer Default string
- Chassis Type Desktop
- Version Default string
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 3
- [Onboard Devices Information (Type 10) - Length 6 - Handle 0021h]
- Number of Devices 1
- 01: Type Video [enabled]
- [OEM Strings (Type 11) - Length 5 - Handle 0022h]
- Number of Strings 8
- 1 Default string
- 2 Default string
- 3 COD
- 4 Default string
- 5 FFFFFFFFFFFFF
- 6 FFFFFFFFFFFFF
- 7 FFFFFFFFFFFFF
- 8 Default string
- [System Configuration Options (Type 12) - Length 5 - Handle 0023h]
- [Physical Memory Array (Type 16) - Length 23 - Handle 003eh]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 67108864KB
- Number of Memory Devices 4
- [Memory Device (Type 17) - Length 40 - Handle 003fh]
- Physical Memory Array Handle 003eh
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 02h - Unknown
- Device Locator ChannelA-DIMM1
- Bank Locator BANK 0
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Device (Type 17) - Length 40 - Handle 0040h]
- Physical Memory Array Handle 003eh
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM2
- Bank Locator BANK 1
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 2400MHz
- Manufacturer Corsair
- Part Number CMK16GX4M2A2400C16
- [Memory Device (Type 17) - Length 40 - Handle 0041h]
- Physical Memory Array Handle 003eh
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 02h - Unknown
- Device Locator ChannelB-DIMM1
- Bank Locator BANK 2
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Device (Type 17) - Length 40 - Handle 0042h]
- Physical Memory Array Handle 003eh
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM2
- Bank Locator BANK 3
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 2400MHz
- Manufacturer Corsair
- Part Number CMK16GX4M2A2400C16
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0043h]
- Starting Address 00000000h
- Ending Address 00ffffffh
- Memory Array Handle 003eh
- Partition Width 02
- [Cache Information (Type 7) - Length 19 - Handle 0044h]
- Socket Designation L1 Cache
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0180h - 384K
- Installed Size 0180h - 384K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type ParitySingle-Bit ECC
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0045h]
- Socket Designation L2 Cache
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 0600h - 1536K
- Installed Size 0600h - 1536K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Unified
- Associativity 4-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0046h]
- Socket Designation L3 Cache
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 2400h - 9216K
- Installed Size 2400h - 9216K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity Specification Reserved
- [Processor Information (Type 4) - Length 48 - Handle 0047h]
- Socket Designation LGA1151
- Processor Type Central Processor
- Processor Family cdh - Specification Reserved
- Processor Manufacturer Intel(R) Corporation
- Processor ID ea060900fffbebbf
- Processor Version Intel(R) Core(TM) i5-8600K CPU @ 3.60GHz
- Processor Voltage 8ah - 1.0V
- External Clock 100MHz
- Max Speed 8300MHz
- Current Speed 3600MHz
- Status Enabled Populated
- Processor Upgrade Specification Reserved
- L1 Cache Handle 0044h
- L2 Cache Handle 0045h
- L3 Cache Handle 0046h
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0048h]
- Starting Address 00000000h
- Ending Address 007fffffh
- Memory Device Handle 0040h
- Mem Array Mapped Adr Handle 0043h
- Interleave Position 01
- Interleave Data Depth 02
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0049h]
- Starting Address 00800000h
- Ending Address 00ffffffh
- Memory Device Handle 0042h
- Mem Array Mapped Adr Handle 0043h
- Interleave Position 02
- Interleave Data Depth 02
- ========================== Dump #3: Extra #1 ===========================
- 2: kd> !verifier
- fffff80545648580: Unable to get verifier list.
- ========================== Dump #3: Extra #2 ===========================
- 2: kd> !thread
- THREAD ffffc78dab75e080 Cid 021c.0584 Teb: 00000072d20a2000 Win32Thread: 0000000000000000 RUNNING on processor 2
- Not impersonating
- GetUlongFromAddress: unable to read from fffff8054562ca14
- Owning Process ffffc78db1bfa4c0 Image: svchost.exe
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 741
- Context Switch Count 724 IdealProcessor: 0
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address 0x00007ffee0eb3ce0
- Stack Init ffff8405187a7b90 Current ffff8405187a6e30
- Base ffff8405187a8000 Limit ffff8405187a1000 Call 0000000000000000
- Priority 10 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- ffff8405`187a7838 fffff805`45acb8a9 : 00000000`000000ef ffffc78d`b1bfa4c0 00000000`00000000 00000000`00000000 : nt!KeBugCheckEx
- ffff8405`187a7840 fffff805`459ecbdf : ffffc78d`b1bfa4c0 fffff805`45288065 ffffc78d`b1bfa4c0 fffff805`452880e0 : nt!PspCatchCriticalBreak+0x115
- ffff8405`187a78e0 fffff805`458700c0 : ffffc78d`00000000 00000000`00000000 ffffc78d`b1bfa4c0 ffffc78d`b1bfa4c0 : nt!PspTerminateAllThreads+0x17b193
- ffff8405`187a7950 fffff805`4586fce9 : ffffffff`ffffffff ffff8405`187a7a80 ffffc78d`b1bfa4c0 fffff805`45879401 : nt!PspTerminateProcess+0xe0
- ffff8405`187a7990 fffff805`453d3c15 : ffffc78d`0000021c ffffc78d`ab75e080 ffffc78d`b1bfa4c0 00000072`d297f7dc : nt!NtTerminateProcess+0xa9
- ffff8405`187a7a00 00007ffe`e0f1c5f4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25 (TrapFrame @ ffff8405`187a7a00)
- 00000072`d297c4e8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffe`e0f1c5f4
- ========================================================================
- ======================= Dump #4: ANALYZE VERBOSE =======================
- ======================= File: 041820-5250-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 18362 MP (6 procs) Free x64
- Kernel base = 0xfffff803`62c00000 PsLoadedModuleList = 0xfffff803`63048150
- Debug session time: Sat Apr 18 14:39:13.535 2020 (UTC - 4:00)
- System Uptime: 0 days 9:09:38.215
- BugCheck 1000007F, {8, fffff80366880e50, ffffb182b06b0fc0, fffff80362cc8e9a}
- Probably caused by : memory_corruption
- Followup: memory_corruption
- UNEXPECTED_KERNEL_MODE_TRAP_M (1000007f)
- This means a trap occurred in kernel mode, and it's a trap of a kind
- that the kernel isn't allowed to have/catch (bound trap) or that
- is always instant death (double fault). The first number in the
- bugcheck params is the number of the trap (8 = double fault, etc)
- Consult an Intel x86 family manual to learn more about what these
- traps are. Here is a *portion* of those codes:
- If kv shows a taskGate
- use .tss on the part before the colon, then kv.
- Else if kv shows a trapframe
- use .trap on that value
- Else
- .trap on the appropriate frame will show where the trap was taken
- (on x86, this will be the ebp that goes with the procedure KiTrap)
- Endif
- kb will then show the corrected stack.
- Arguments:
- Arg1: 0000000000000008, EXCEPTION_DOUBLE_FAULT
- Arg2: fffff80366880e50
- Arg3: ffffb182b06b0fc0
- Arg4: fffff80362cc8e9a
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- DUMP_FILE_ATTRIBUTES: 0x8
- Kernel Generated Triage Dump
- BUGCHECK_STR: 0x7f_8
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- PROCESS_NAME: ACOrigins.exe
- CURRENT_IRQL: 0
- TRAP_FRAME: ffffb182b06b1b80 -- (.trap 0xffffb182b06b1b80)
- NOTE: The trap frame does not contain all registers.
- Some register values may be zeroed or incorrect.
- rax=ffffc686c9748080 rbx=0000000000000000 rcx=00000000c0000005
- rdx=0000000000001000 rsi=0000000000000000 rdi=0000000000000000
- rip=fffff80362cdcf7d rsp=ffffb182b06b1d10 rbp=ffffb182b06b1e40
- r8=cfffffffffffffff r9=0000000000000000 r10=ffffc686c57f2580
- r11=ffff8241209047f8 r12=0000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=0000000000000000
- iopl=0 ov up ei pl nz na po cy
- nt!MiIsRetryIoStatus+0x11:
- fffff803`62cdcf7d c0742181f9 sal byte ptr [rcx-7Fh],0F9h ds:00000000`bfffff86=??
- Resetting default scope
- MISALIGNED_IP:
- nt!MiIsRetryIoStatus+11
- fffff803`62cdcf7d c0742181f9 sal byte ptr [rcx-7Fh],0F9h
- LAST_CONTROL_TRANSFER: from fffff80362dd041e to fffff80362cc8e9a
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
- fffff80362cc8174-fffff80362cc8175 2 bytes - nt!MiZeroFault+e4
- [ 80 f6:00 82 ]
- fffff80362cc8184-fffff80362cc8185 2 bytes - nt!MiZeroFault+f4 (+0x10)
- [ ff f6:7f 82 ]
- fffff80362cc8ee3-fffff80362cc8ee4 2 bytes - nt!MmAccessFault+83 (+0xd5f)
- [ 80 f6:00 82 ]
- fffff80362cc8f8f-fffff80362cc8f93 5 bytes - nt!MmAccessFault+12f (+0xac)
- [ d0 be 7d fb f6:40 90 20 41 82 ]
- 11 errors : !nt (fffff80362cc8174-fffff80362cc8f93)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-04-18T18:39:13.000Z
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #4: 3RD PARTY DRIVERS ======================
- Jun 03 2016 - RTKVHD64.sys - Realtek Audio System driver https://www.realtek.com/en/
- Nov 09 2017 - vbdenum.sys - Citrix ICA Host (Citrix Systems, Inc.)
- Jul 12 2018 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Aug 08 2018 - ctxusbm.sys - Citrix USB Filter Driver https://www.citrix.com
- Aug 28 2018 - rt640x64.sys - Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Mar 14 2019 - nvvad64v.sys - Nvidia Virtual Audio driver http://www.nvidia.com/
- Jan 10 2020 - nvvhci.sys - Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Feb 19 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- Mar 17 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- ================== Dump #4: 3RD PARTY DRIVERS (FULL) ===================
- Image name: RTKVHD64.sys
- Search : https://www.google.com/search?q=RTKVHD64.sys
- ADA Info : Realtek Audio System driver https://www.realtek.com/en/
- Timestamp : Fri Jun 3 2016
- Image name: vbdenum.sys
- Search : https://www.google.com/search?q=vbdenum.sys
- ADA Info : Citrix ICA Host (Citrix Systems, Inc.)
- Timestamp : Thu Nov 9 2017
- Image name: TeeDriverW8x64.sys
- Search : https://www.google.com/search?q=TeeDriverW8x64.sys
- ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Timestamp : Thu Jul 12 2018
- Image name: ctxusbm.sys
- Search : https://www.google.com/search?q=ctxusbm.sys
- ADA Info : Citrix USB Filter Driver https://www.citrix.com
- Timestamp : Wed Aug 8 2018
- Image name: rt640x64.sys
- Search : https://www.google.com/search?q=rt640x64.sys
- ADA Info : Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Timestamp : Tue Aug 28 2018
- Image name: nvvad64v.sys
- Search : https://www.google.com/search?q=nvvad64v.sys
- ADA Info : Nvidia Virtual Audio driver http://www.nvidia.com/
- Timestamp : Thu Mar 14 2019
- Image name: nvvhci.sys
- Search : https://www.google.com/search?q=nvvhci.sys
- ADA Info : Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Timestamp : Fri Jan 10 2020
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Wed Feb 19 2020
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Tue Mar 17 2020
- ====================== Dump #4: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- acpipagr.sys ACPI Processor Aggregator Device driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- csc.sys Windows Client Side Caching driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storport.sys Provides disk access during crash dump file generation (Microsoft)
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- IndirectKmd.sys Indirect displays kernel-mode filter driver
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- intelppm.sys Processor Device Driver (Microsoft)
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kdcom.dll Kernel Debugger HW Extension DLL (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate.dll Media Center Update (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- ndisuio.sys NDIS User mode I/O driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- serenum.sys Serial Port Enumerator (Microsoft)
- serial.sys Serial Device Driver
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- ucx01000.sys USB Controller Extension (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- winquic.sys QUIC Transport Protocol driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- WUDFRd.sys Windows Driver Foundation - User-mode Driver Framework Reflector driver (Microsoft)
- ====================== Dump #4: UNLOADED MODULES =======================
- fffff803`6e360000 fffff803`6e374000 WdNisDrv.sys
- fffff803`6e340000 fffff803`6e354000 WdNisDrv.sys
- fffff803`6e320000 fffff803`6e334000 WdNisDrv.sys
- fffff803`6e300000 fffff803`6e314000 WdNisDrv.sys
- fffff803`6e2e0000 fffff803`6e2f4000 WdNisDrv.sys
- fffff803`6e2a0000 fffff803`6e2b4000 WdNisDrv.sys
- fffff803`6e230000 fffff803`6e244000 WdNisDrv.sys
- fffff803`6d2b0000 fffff803`6d2bf000 dump_storpor
- fffff803`6d2f0000 fffff803`6d31f000 dump_storahc
- fffff803`6d340000 fffff803`6d35e000 dump_dumpfve
- fffff803`707e0000 fffff803`70831000 WUDFRd.sys
- fffff803`6cbe0000 fffff803`6cbfe000 dam.sys
- fffff803`653b0000 fffff803`653c1000 WdBoot.sys
- fffff803`663b0000 fffff803`663c1000 hwpolicy.sys
- ====================== Dump #4: BIOS INFORMATION =======================
- [SMBIOS Data Tables v3.0]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 4215 bytes]
- [BIOS Information (Type 0) - Length 24 - Handle 0000h]
- Vendor American Megatrends Inc.
- BIOS Version 2401
- BIOS Starting Address Segment f000
- BIOS Release Date 07/15/2019
- BIOS ROM Size 1000000
- BIOS Characteristics
- 07: - PCI Supported
- 10: - APM Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 27: - Keyboard Services Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 32: - BIOS Vendor Reserved
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 5
- BIOS Minor Revision 12
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- Manufacturer System manufacturer
- Product Name System Product Name
- Version System Version
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- SKUNumber SKU
- [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
- Manufacturer ASUSTeK COMPUTER INC.
- Product PRIME Z370-P
- Version Rev X.0x
- Feature Flags 09h
- -362039584: - -362039536: - ÷7£ý
- Location Default string
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 22 - Handle 0003h]
- Manufacturer Default string
- Chassis Type Desktop
- Version Default string
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 3
- [Onboard Devices Information (Type 10) - Length 6 - Handle 0021h]
- Number of Devices 1
- 01: Type Video [enabled]
- [OEM Strings (Type 11) - Length 5 - Handle 0022h]
- Number of Strings 8
- 1 Default string
- 2 Default string
- 3 COD
- 4 Default string
- 5 FFFFFFFFFFFFF
- 6 FFFFFFFFFFFFF
- 7 FFFFFFFFFFFFF
- 8 Default string
- [System Configuration Options (Type 12) - Length 5 - Handle 0023h]
- [Physical Memory Array (Type 16) - Length 23 - Handle 003eh]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 67108864KB
- Number of Memory Devices 4
- [Memory Device (Type 17) - Length 40 - Handle 003fh]
- Physical Memory Array Handle 003eh
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 02h - Unknown
- Device Locator ChannelA-DIMM1
- Bank Locator BANK 0
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Device (Type 17) - Length 40 - Handle 0040h]
- Physical Memory Array Handle 003eh
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM2
- Bank Locator BANK 1
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 2400MHz
- Manufacturer Corsair
- Part Number CMK16GX4M2A2400C16
- [Memory Device (Type 17) - Length 40 - Handle 0041h]
- Physical Memory Array Handle 003eh
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 02h - Unknown
- Device Locator ChannelB-DIMM1
- Bank Locator BANK 2
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Device (Type 17) - Length 40 - Handle 0042h]
- Physical Memory Array Handle 003eh
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM2
- Bank Locator BANK 3
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 2400MHz
- Manufacturer Corsair
- Part Number CMK16GX4M2A2400C16
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0043h]
- Starting Address 00000000h
- Ending Address 00ffffffh
- Memory Array Handle 003eh
- Partition Width 02
- [Cache Information (Type 7) - Length 19 - Handle 0044h]
- Socket Designation L1 Cache
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0180h - 384K
- Installed Size 0180h - 384K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type ParitySingle-Bit ECC
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0045h]
- Socket Designation L2 Cache
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 0600h - 1536K
- Installed Size 0600h - 1536K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Unified
- Associativity 4-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0046h]
- Socket Designation L3 Cache
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 2400h - 9216K
- Installed Size 2400h - 9216K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity Specification Reserved
- [Processor Information (Type 4) - Length 48 - Handle 0047h]
- Socket Designation LGA1151
- Processor Type Central Processor
- Processor Family cdh - Specification Reserved
- Processor Manufacturer Intel(R) Corporation
- Processor ID ea060900fffbebbf
- Processor Version Intel(R) Core(TM) i5-8600K CPU @ 3.60GHz
- Processor Voltage 8ah - 1.0V
- External Clock 100MHz
- Max Speed 8300MHz
- Current Speed 3600MHz
- Status Enabled Populated
- Processor Upgrade Specification Reserved
- L1 Cache Handle 0044h
- L2 Cache Handle 0045h
- L3 Cache Handle 0046h
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0048h]
- Starting Address 00000000h
- Ending Address 007fffffh
- Memory Device Handle 0040h
- Mem Array Mapped Adr Handle 0043h
- Interleave Position 01
- Interleave Data Depth 02
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0049h]
- Starting Address 00800000h
- Ending Address 00ffffffh
- Memory Device Handle 0042h
- Mem Array Mapped Adr Handle 0043h
- Interleave Position 02
- Interleave Data Depth 02
- ========================== Dump #4: Extra #1 ===========================
- 0: kd> !verifier
- fffff80363048580: Unable to get verifier list.
- ========================== Dump #4: Extra #2 ===========================
- 0: kd> !thread
- ffffc686c9748080 is not a thread object, interpreting as stack value...
- Unable to read @ fffff80363038b40
- TYPE mismatch for thread object at ffffc686c9748080
- ========================================================================
- ======================= Dump #5: ANALYZE VERBOSE =======================
- ======================= File: 041520-4843-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 18362 MP (6 procs) Free x64
- Kernel base = 0xfffff800`71200000 PsLoadedModuleList = 0xfffff800`71648150
- Debug session time: Wed Apr 15 11:29:45.110 2020 (UTC - 4:00)
- System Uptime: 0 days 0:05:23.788
- BugCheck 7F, {8, ffffb68010ddb010, ffffb38438e08f90, fffff800713d00d0}
- Probably caused by : memory_corruption
- Followup: memory_corruption
- UNEXPECTED_KERNEL_MODE_TRAP (7f)
- This means a trap occurred in kernel mode, and it's a trap of a kind
- that the kernel isn't allowed to have/catch (bound trap) or that
- is always instant death (double fault). The first number in the
- bugcheck params is the number of the trap (8 = double fault, etc)
- Consult an Intel x86 family manual to learn more about what these
- traps are. Here is a *portion* of those codes:
- If kv shows a taskGate
- use .tss on the part before the colon, then kv.
- Else if kv shows a trapframe
- use .trap on that value
- Else
- .trap on the appropriate frame will show where the trap was taken
- (on x86, this will be the ebp that goes with the procedure KiTrap)
- Endif
- kb will then show the corrected stack.
- Arguments:
- Arg1: 0000000000000008, EXCEPTION_DOUBLE_FAULT
- Arg2: ffffb68010ddb010
- Arg3: ffffb38438e08f90
- Arg4: fffff800713d00d0
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- BUGCHECK_STR: 0x7f_8
- TRAP_FRAME: ffffb68010ddb010 -- (.trap 0xffffb68010ddb010)
- NOTE: The trap frame does not contain all registers.
- Some register values may be zeroed or incorrect.
- rax=000000000000008b rbx=0000000000000000 rcx=0000000000000000
- rdx=ffffb38438e09101 rsi=0000000000000000 rdi=0000000000000000
- rip=fffff800713d00d0 rsp=ffffb38438e08f90 rbp=ffffb38438e09010
- r8=0000000000000001 r9=ffffb38438e09140 r10=000000000010001f
- r11=ffffb38438e091d0 r12=0000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=0000000000000000
- iopl=0 nv up di ng nz na po nc
- nt!KiPageFault+0x10:
- fffff800`713d00d0 c645ab01 mov byte ptr [rbp-55h],1 ss:ffffb384`38e08fbb=??
- Resetting default scope
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- PROCESS_NAME: firefox.exe
- CURRENT_IRQL: 0
- LAST_CONTROL_TRANSFER: from fffff800713d41e9 to fffff800713c2380
- STACK_OVERFLOW: Stack Limit: ffffb38438e09000. Use (kF) and (!stackusage) to investigate stack usage.
- STACKUSAGE_FUNCTION: The function at address 0xFFFFF800712FE804 was blamed for the stack overflow. It is using 15408 bytes of stack total in 9 instances (likely recursion).
- FOLLOWUP_IP:
- nt!KiDispatchException+104
- fffff800`712fe804 4c8bc6 mov r8,rsi
- STACK_TEXT:
- ffffb384`38e08f90 fffff800`712fe279 : d8a7c9c5`d40059b4 cb11a46a`07524221 0039e3dc`d27ddfb3 d1869f77`140059c4 : nt!KiPageFault+0x10
- ffffb384`38e09120 fffff800`712fe0c0 : d9708f81`47558a01 ffffb384`38e096d0 ffffb384`38e091d0 f9a7c321`d85f70cc : nt!RtlInitializeExtendedContext2+0x6d
- ffffb384`38e09170 fffff800`712fe804 : b226c4ec`f5093ba2 000a8ce5`9406e2b4 38e6f350`35005a14 8fad9403`00000001 : nt!RtlInitializeExtendedContext+0x38
- ffffb384`38e091a0 fffff800`713d431d : ffff9249`24924000 ffffb384`38e09a30 ffff8000`00000000 00000000`00000008 : nt!KiDispatchException+0x104
- ffffb384`38e09850 fffff800`713d0505 : 00035948`8730ff8f b4578cb6`17005fc4 00000000`0010001f 006eaede`9861243e : nt!KiExceptionDispatch+0x11d
- ffffb384`38e09a30 fffff800`712fe279 : 86b3a0fa`7b70422e 008fcd82`5e03c3ff a6d6173a`b10060d4 63dd5e88`a6da16d8 : nt!KiPageFault+0x445
- ffffb384`38e09bc0 fffff800`712fe0c0 : 00a4ded8`e6b7d3ff ffffb384`38e0a170 ffffb384`38e09c70 00ef7627`ab68258b : nt!RtlInitializeExtendedContext2+0x6d
- ffffb384`38e09c10 fffff800`712fe804 : 003c5ec1`ebb08c37 e5b0351b`da006124 93259244`23318711 00482207`00000001 : nt!RtlInitializeExtendedContext+0x38
- ffffb384`38e09c40 fffff800`713d431d : ffff9249`24924000 ffffb384`38e0a4d0 ffff8000`00000000 00000000`00000008 : nt!KiDispatchException+0x104
- ffffb384`38e0a2f0 fffff800`713d0505 : 001f9a82`3b0e60dc dc9b2376`35005184 00000000`0010001f 00802fb8`bff55c6c : nt!KiExceptionDispatch+0x11d
- ffffb384`38e0a4d0 fffff800`712fe279 : f9efbca5`9178e540 0077f524`16184122 b5c63b8f`39005294 b304f321`5927065a : nt!KiPageFault+0x445
- ffffb384`38e0a660 fffff800`712fe0c0 : 004b1938`2eee02ea ffffb384`38e0ac10 ffffb384`38e0a710 00453e12`a73cce32 : nt!RtlInitializeExtendedContext2+0x6d
- ffffb384`38e0a6b0 fffff800`712fe804 : 004b5dc3`97a4e9f7 b87d1ab6`460052e4 6be0d936`ad3d0ac1 002ecac1`00000001 : nt!RtlInitializeExtendedContext+0x38
- ffffb384`38e0a6e0 fffff800`713d431d : ffff9249`24924000 ffffb384`38e0af70 ffff8000`00000000 00000000`00000008 : nt!KiDispatchException+0x104
- ffffb384`38e0ad90 fffff800`713d0505 : 88267535`15005894 3127e033`6a965deb 00000000`0010001f 221c7d15`330058a4 : nt!KiExceptionDispatch+0x11d
- ffffb384`38e0af70 fffff800`712fe279 : b4c62d81`a1d3c810 00cae36f`50e0536f 0ee8fce2`a0004454 653f7da4`a3c79180 : nt!KiPageFault+0x445
- ffffb384`38e0b100 fffff800`712fe0c0 : 0045704b`1dbc9aa5 ffffb384`38e0b6b0 ffffb384`38e0b1b0 0075894e`5064419f : nt!RtlInitializeExtendedContext2+0x6d
- ffffb384`38e0b150 fffff800`712fe804 : 005dd30a`6147664e f2552233`210044a4 5329da00`14b461a8 00ee874f`00000001 : nt!RtlInitializeExtendedContext+0x38
- ffffb384`38e0b180 fffff800`713d431d : ffff9249`24924000 ffffb384`38e0ba10 ffff8000`00000000 00000000`00000008 : nt!KiDispatchException+0x104
- ffffb384`38e0b830 fffff800`713d0505 : fa9b3f07`12004a54 289926e6`aeab8775 00000000`0010001f 6c5c0d22`da004a64 : nt!KiExceptionDispatch+0x11d
- ffffb384`38e0ba10 fffff800`712fe279 : 00045fa9`072aaf45 b9473bb0`32004b64 2370e3f4`a34ecf0d 00c0bb68`00deb511 : nt!KiPageFault+0x445
- ffffb384`38e0bba0 fffff800`712fe0c0 : 23af658a`45004b94 ffffb384`38e0c150 ffffb384`38e0bc50 fd569131`51004ba4 : nt!RtlInitializeExtendedContext2+0x6d
- ffffb384`38e0bbf0 fffff800`712fe804 : a2fff96a`d7004bb4 63af520e`6f8428b7 002b2cf3`a83b965d 730f6895`00000001 : nt!RtlInitializeExtendedContext+0x38
- ffffb384`38e0bc20 fffff800`713d431d : ffff9249`24924000 ffffb384`38e0c4b0 ffff8000`00000000 00000000`00000008 : nt!KiDispatchException+0x104
- ffffb384`38e0c2d0 fffff800`713d0505 : 1451bd42`e0003c14 27e6698d`e542127f 00000000`0010001f e4407939`65003c24 : nt!KiExceptionDispatch+0x11d
- ffffb384`38e0c4b0 fffff800`712fe279 : 00b689fc`3c66d765 57123972`25003d24 dd22e474`ccc1e7a7 0036ee7a`6750ab9e : nt!KiPageFault+0x445
- ffffb384`38e0c640 fffff800`712fe0c0 : 8f4287bc`d6003d54 ffffb384`38e0cbf0 ffffb384`38e0c6f0 6799a0ba`df003d64 : nt!RtlInitializeExtendedContext2+0x6d
- ffffb384`38e0c690 fffff800`712fe804 : 41777186`62003d74 7d5b0025`57c9a412 006aecee`67466779 f992a991`00000001 : nt!RtlInitializeExtendedContext+0x38
- ffffb384`38e0c6c0 fffff800`713d431d : ffff9249`24924000 ffffb384`38e0cf50 ffff8000`00000000 00000000`00000008 : nt!KiDispatchException+0x104
- ffffb384`38e0cd70 fffff800`713d0505 : c308f23b`62dff93c 00c7e369`7fdf81c6 00000000`0010001f d79d2676`04a006e6 : nt!KiExceptionDispatch+0x11d
- ffffb384`38e0cf50 fffff800`712fe279 : e5e5e5e5`e5e5e5e5 e5e5e5e5`e5e5e5e5 e5e5e5e5`e5e5e5e5 e5e5e5e5`e5e5e5e5 : nt!KiPageFault+0x445
- ffffb384`38e0d0e0 fffff800`712fe0c0 : e5e5e5e5`e5e5e5e5 ffffb384`38e0d690 ffffb384`38e0d190 e5e5e5e5`e5e5e5e5 : nt!RtlInitializeExtendedContext2+0x6d
- ffffb384`38e0d130 fffff800`712fe804 : e5e5e5e5`e5e5e5e5 e5e5e5e5`e5e5e5e5 e5e5e5e5`e5e5e5e5 e5e5e5e5`00000001 : nt!RtlInitializeExtendedContext+0x38
- ffffb384`38e0d160 fffff800`713d431d : ffff9249`24924000 ffffb384`38e0d9f0 ffff8000`00000000 00000000`00000008 : nt!KiDispatchException+0x104
- ffffb384`38e0d810 fffff800`713d0505 : 00000000`00000000 ffff970c`3d3a7a00 00000000`0010001f 000000a0`41946350 : nt!KiExceptionDispatch+0x11d
- ffffb384`38e0d9f0 fffff800`712fe279 : ffff970c`38bc1000 ffff970c`38bc1000 00000000`00000000 ffff970c`38bc1000 : nt!KiPageFault+0x445
- ffffb384`38e0db80 fffff800`712fe0c0 : ffff970c`35ef7060 ffffb384`38e0e130 ffffb384`38e0dc30 ffff970c`35ef7060 : nt!RtlInitializeExtendedContext2+0x6d
- ffffb384`38e0dbd0 fffff800`712fe804 : ffff970c`35ef7060 fffff800`7d50ac8e ffff970c`38bc1000 00000000`00000001 : nt!RtlInitializeExtendedContext+0x38
- ffffb384`38e0dc00 fffff800`713d431d : ffff9249`24924000 ffffb384`38e0e490 ffff8000`00000000 00000000`00000008 : nt!KiDispatchException+0x104
- ffffb384`38e0e2b0 fffff800`713d0505 : ffffb680`10dd0180 fffff800`7128d367 00000000`0010001f 00000000`00000000 : nt!KiExceptionDispatch+0x11d
- ffffb384`38e0e490 fffff800`712fe279 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x445
- ffffb384`38e0e620 fffff800`712fe0c0 : 00000000`00000000 ffffb384`38e0ebd0 ffffb384`38e0e6d0 00000000`00000000 : nt!RtlInitializeExtendedContext2+0x6d
- ffffb384`38e0e670 fffff800`712fe804 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000001 : nt!RtlInitializeExtendedContext+0x38
- ffffb384`38e0e6a0 fffff800`713d431d : ffff9249`24924000 ffffb384`38e0ef30 ffff8000`00000000 00000000`000000b9 : nt!KiDispatchException+0x104
- ffffb384`38e0ed50 fffff800`713d0505 : 00000000`00000000 00000000`00000000 fffff800`73406072 00000000`00000000 : nt!KiExceptionDispatch+0x11d
- ffffb384`38e0ef30 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x445
- STACK_COMMAND: .trap 0xffffb68010ddb010 ; kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
- fffff8007125a346-fffff8007125a347 2 bytes - nt!EtwpGetPerfCounter+6
- [ 48 ff:4c 8b ]
- fffff8007125a34d-fffff8007125a34e 2 bytes - nt!EtwpGetPerfCounter+d (+0x07)
- [ 0f 1f:e8 6e ]
- fffff8007125a350-fffff8007125a351 2 bytes - nt!EtwpGetPerfCounter+10 (+0x03)
- [ 00 00:f0 ff ]
- fffff800712c91eb-fffff800712c91ef 5 bytes - nt!MmAccessFault+37b (+0x6ee9b)
- [ df be 7d fb f6:4f 92 24 49 92 ]
- fffff800712c9218-fffff800712c921c 5 bytes - nt!MmAccessFault+3a8 (+0x2d)
- [ d7 be 7d fb f6:47 92 24 49 92 ]
- fffff800712c9edd-fffff800712c9edf 3 bytes - nt!MiFastLockLeafPageTable+ad (+0xcc5)
- [ 40 fb f6:00 49 92 ]
- fffff800712c9f11-fffff800712c9f12 2 bytes - nt!MiFastLockLeafPageTable+e1 (+0x34)
- [ 80 f6:00 92 ]
- fffff800712c9f39-fffff800712c9f3d 5 bytes - nt!MiFastLockLeafPageTable+109 (+0x28)
- [ d0 be 7d fb f6:40 92 24 49 92 ]
- fffff800712c9f46-fffff800712c9f4a 5 bytes - nt!MiFastLockLeafPageTable+116 (+0x0d)
- [ d7 be 7d fb f6:47 92 24 49 92 ]
- 31 errors : !nt (fffff8007125a346-fffff800712c9f4a)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-04-15T15:29:45.000Z
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #5: 3RD PARTY DRIVERS ======================
- Jun 03 2016 - RTKVHD64.sys - Realtek Audio System driver https://www.realtek.com/en/
- Nov 09 2017 - vbdenum.sys - Citrix ICA Host (Citrix Systems, Inc.)
- Jul 12 2018 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Aug 08 2018 - ctxusbm.sys - Citrix USB Filter Driver https://www.citrix.com
- Aug 28 2018 - rt640x64.sys - Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Mar 14 2019 - nvvad64v.sys - Nvidia Virtual Audio driver http://www.nvidia.com/
- Jan 10 2020 - nvvhci.sys - Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Feb 19 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- Mar 17 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- ================== Dump #5: 3RD PARTY DRIVERS (FULL) ===================
- Image path: \SystemRoot\system32\drivers\RTKVHD64.sys
- Image name: RTKVHD64.sys
- Search : https://www.google.com/search?q=RTKVHD64.sys
- ADA Info : Realtek Audio System driver https://www.realtek.com/en/
- Timestamp : Fri Jun 3 2016
- Image path: \SystemRoot\System32\drivers\vbdenum.sys
- Image name: vbdenum.sys
- Search : https://www.google.com/search?q=vbdenum.sys
- ADA Info : Citrix ICA Host (Citrix Systems, Inc.)
- Timestamp : Thu Nov 9 2017
- Image path: \SystemRoot\System32\drivers\TeeDriverW8x64.sys
- Image name: TeeDriverW8x64.sys
- Search : https://www.google.com/search?q=TeeDriverW8x64.sys
- ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Timestamp : Thu Jul 12 2018
- Image path: \SystemRoot\system32\DRIVERS\ctxusbm.sys
- Image name: ctxusbm.sys
- Search : https://www.google.com/search?q=ctxusbm.sys
- ADA Info : Citrix USB Filter Driver https://www.citrix.com
- Timestamp : Wed Aug 8 2018
- Image path: \SystemRoot\System32\drivers\rt640x64.sys
- Image name: rt640x64.sys
- Search : https://www.google.com/search?q=rt640x64.sys
- ADA Info : Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Timestamp : Tue Aug 28 2018
- Image path: \SystemRoot\system32\drivers\nvvad64v.sys
- Image name: nvvad64v.sys
- Search : https://www.google.com/search?q=nvvad64v.sys
- ADA Info : Nvidia Virtual Audio driver http://www.nvidia.com/
- Timestamp : Thu Mar 14 2019
- Image path: \SystemRoot\System32\drivers\nvvhci.sys
- Image name: nvvhci.sys
- Search : https://www.google.com/search?q=nvvhci.sys
- ADA Info : Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Timestamp : Fri Jan 10 2020
- Image path: \SystemRoot\system32\drivers\nvhda64v.sys
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Wed Feb 19 2020
- Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_e0a5a1b06de180e3\nvlddmkm.sys
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Tue Mar 17 2020
- ====================== Dump #5: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- acpipagr.sys ACPI Processor Aggregator Device driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- csc.sys Windows Client Side Caching driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- IndirectKmd.sys Indirect displays kernel-mode filter driver
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- intelppm.sys Processor Device Driver (Microsoft)
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kd.dll Local Kernal Debugger (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate_GenuineIntel.dll Intel Microcode Update Library (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- MpKslDrv.sys Microsoft Anti-malware Protection driver
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- serenum.sys Serial Port Enumerator (Microsoft)
- serial.sys Serial Device Driver
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- ucx01000.sys USB Controller Extension (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- winquic.sys QUIC Transport Protocol driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- WUDFRd.sys Windows Driver Foundation - User-mode Driver Framework Reflector driver (Microsoft)
- ====================== Dump #5: UNLOADED MODULES =======================
- fffff800`7f6b0000 fffff800`7f6c4000 WdNisDrv.sys
- fffff800`7af00000 fffff800`7af0f000 dump_storpor
- fffff800`7af40000 fffff800`7af6f000 dump_storahc
- fffff800`7af90000 fffff800`7afae000 dump_dumpfve
- fffff800`7b2e0000 fffff800`7b331000 WUDFRd.sys
- fffff800`7ae50000 fffff800`7ae6e000 dam.sys
- fffff800`735b0000 fffff800`735c1000 WdBoot.sys
- fffff800`73bf0000 fffff800`73c00000 hwpolicy.sys
- ====================== Dump #5: BIOS INFORMATION =======================
- [SMBIOS Data Tables v3.0]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 4215 bytes]
- [BIOS Information (Type 0) - Length 24 - Handle 0000h]
- Vendor American Megatrends Inc.
- BIOS Version 2401
- BIOS Starting Address Segment f000
- BIOS Release Date 07/15/2019
- BIOS ROM Size 1000000
- BIOS Characteristics
- 07: - PCI Supported
- 10: - APM Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 27: - Keyboard Services Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 32: - BIOS Vendor Reserved
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 5
- BIOS Minor Revision 12
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- Manufacturer System manufacturer
- Product Name System Product Name
- Version System Version
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- SKUNumber SKU
- [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
- Manufacturer ASUSTeK COMPUTER INC.
- Product PRIME Z370-P
- Version Rev X.0x
- Feature Flags 09h
- -362039584: - -362039536: - ÷7£ý
- Location Default string
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 22 - Handle 0003h]
- Manufacturer Default string
- Chassis Type Desktop
- Version Default string
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 3
- [Onboard Devices Information (Type 10) - Length 6 - Handle 0021h]
- Number of Devices 1
- 01: Type Video [enabled]
- [OEM Strings (Type 11) - Length 5 - Handle 0022h]
- Number of Strings 8
- 1 Default string
- 2 Default string
- 3 COD
- 4 Default string
- 5 FFFFFFFFFFFFF
- 6 FFFFFFFFFFFFF
- 7 FFFFFFFFFFFFF
- 8 Default string
- [System Configuration Options (Type 12) - Length 5 - Handle 0023h]
- [Physical Memory Array (Type 16) - Length 23 - Handle 003eh]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 67108864KB
- Number of Memory Devices 4
- [Memory Device (Type 17) - Length 40 - Handle 003fh]
- Physical Memory Array Handle 003eh
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 02h - Unknown
- Device Locator ChannelA-DIMM1
- Bank Locator BANK 0
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Device (Type 17) - Length 40 - Handle 0040h]
- Physical Memory Array Handle 003eh
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM2
- Bank Locator BANK 1
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 2400MHz
- Manufacturer Corsair
- Part Number CMK16GX4M2A2400C16
- [Memory Device (Type 17) - Length 40 - Handle 0041h]
- Physical Memory Array Handle 003eh
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 02h - Unknown
- Device Locator ChannelB-DIMM1
- Bank Locator BANK 2
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Device (Type 17) - Length 40 - Handle 0042h]
- Physical Memory Array Handle 003eh
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM2
- Bank Locator BANK 3
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 2400MHz
- Manufacturer Corsair
- Part Number CMK16GX4M2A2400C16
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0043h]
- Starting Address 00000000h
- Ending Address 00ffffffh
- Memory Array Handle 003eh
- Partition Width 02
- [Cache Information (Type 7) - Length 19 - Handle 0044h]
- Socket Designation L1 Cache
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0180h - 384K
- Installed Size 0180h - 384K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type ParitySingle-Bit ECC
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0045h]
- Socket Designation L2 Cache
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 0600h - 1536K
- Installed Size 0600h - 1536K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Unified
- Associativity 4-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0046h]
- Socket Designation L3 Cache
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 2400h - 9216K
- Installed Size 2400h - 9216K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity Specification Reserved
- [Processor Information (Type 4) - Length 48 - Handle 0047h]
- Socket Designation LGA1151
- Processor Type Central Processor
- Processor Family cdh - Specification Reserved
- Processor Manufacturer Intel(R) Corporation
- Processor ID ea060900fffbebbf
- Processor Version Intel(R) Core(TM) i5-8600K CPU @ 3.60GHz
- Processor Voltage 8ah - 1.0V
- External Clock 100MHz
- Max Speed 8300MHz
- Current Speed 3600MHz
- Status Enabled Populated
- Processor Upgrade Specification Reserved
- L1 Cache Handle 0044h
- L2 Cache Handle 0045h
- L3 Cache Handle 0046h
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0048h]
- Starting Address 00000000h
- Ending Address 007fffffh
- Memory Device Handle 0040h
- Mem Array Mapped Adr Handle 0043h
- Interleave Position 01
- Interleave Data Depth 02
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0049h]
- Starting Address 00800000h
- Ending Address 00ffffffh
- Memory Device Handle 0042h
- Mem Array Mapped Adr Handle 0043h
- Interleave Position 02
- Interleave Data Depth 02
- ========================== Dump #5: Extra #1 ===========================
- 4: kd> !verifier
- Verify Flags Level 0x00000000
- STANDARD FLAGS:
- [X] (0x00000000) Automatic Checks
- [ ] (0x00000001) Special pool
- [ ] (0x00000002) Force IRQL checking
- [ ] (0x00000008) Pool tracking
- [ ] (0x00000010) I/O verification
- [ ] (0x00000020) Deadlock detection
- [ ] (0x00000080) DMA checking
- [ ] (0x00000100) Security checks
- [ ] (0x00000800) Miscellaneous checks
- [ ] (0x00020000) DDI compliance checking
- ADDITIONAL FLAGS:
- [ ] (0x00000004) Randomized low resources simulation
- [ ] (0x00000200) Force pending I/O requests
- [ ] (0x00000400) IRP logging
- [ ] (0x00002000) Invariant MDL checking for stack
- [ ] (0x00004000) Invariant MDL checking for driver
- [ ] (0x00008000) Power framework delay fuzzing
- [ ] (0x00010000) Port/miniport interface checking
- [ ] (0x00040000) Systematic low resources simulation
- [ ] (0x00080000) DDI compliance checking (additional)
- [ ] (0x00200000) NDIS/WIFI verification
- [ ] (0x00800000) Kernel synchronization delay fuzzing
- [ ] (0x01000000) VM switch verification
- [ ] (0x02000000) Code integrity checks
- [X] Indicates flag is enabled
- Summary of All Verifier Statistics
- RaiseIrqls 0x0
- AcquireSpinLocks 0x0
- Synch Executions 0x0
- Trims 0x0
- Pool Allocations Attempted 0x0
- Pool Allocations Succeeded 0x0
- Pool Allocations Succeeded SpecialPool 0x0
- Pool Allocations With NO TAG 0x0
- Pool Allocations Failed 0x0
- Current paged pool allocations 0x0 for 00000000 bytes
- Peak paged pool allocations 0x0 for 00000000 bytes
- Current nonpaged pool allocations 0x0 for 00000000 bytes
- Peak nonpaged pool allocations 0x0 for 00000000 bytes
- ========================== Dump #5: Extra #2 ===========================
- 4: kd> !thread
- THREAD ffff970c3edca080 Cid 1c08.17e4 Teb: 000000b24ce4e000 Win32Thread: ffff970c3de41750 RUNNING on processor 4
- Not impersonating
- GetUlongFromAddress: unable to read from fffff8007162ca14
- Owning Process ffff970c3f5cb480 Image: firefox.exe
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 20721
- Context Switch Count 5427 IdealProcessor: 4
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address 0x00007ff9bd83dd30
- Stack Init ffffb38438e0fb90 Current ffffb38438e0f5e0
- Base ffffb38438e10000 Limit ffffb38438e09000 Call 0000000000000000
- Priority 9 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- ffffb680`10ddaec8 fffff800`713d41e9 : 00000000`0000007f 00000000`00000008 ffffb680`10ddb010 ffffb384`38e08f90 : nt!KeBugCheckEx
- ffffb680`10ddaed0 fffff800`713cf045 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
- ffffb680`10ddb010 fffff800`713d00d0 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDoubleFaultAbort+0x2c5 (TrapFrame @ ffffb680`10ddb010)
- ffffb384`38e08f90 fffff800`712fe279 : d8a7c9c5`d40059b4 cb11a46a`07524221 0039e3dc`d27ddfb3 d1869f77`140059c4 : nt!KiPageFault+0x10 (TrapFrame @ ffffb384`38e08f90)
- ffffb384`38e09120 fffff800`712fe0c0 : d9708f81`47558a01 ffffb384`38e096d0 ffffb384`38e091d0 f9a7c321`d85f70cc : nt!RtlInitializeExtendedContext2+0x6d
- ffffb384`38e09170 fffff800`712fe804 : b226c4ec`f5093ba2 000a8ce5`9406e2b4 38e6f350`35005a14 8fad9403`00000001 : nt!RtlInitializeExtendedContext+0x38
- ffffb384`38e091a0 fffff800`713d431d : ffff9249`24924000 ffffb384`38e09a30 ffff8000`00000000 00000000`00000008 : nt!KiDispatchException+0x104
- ffffb384`38e09850 fffff800`713d0505 : 00035948`8730ff8f b4578cb6`17005fc4 00000000`0010001f 006eaede`9861243e : nt!KiExceptionDispatch+0x11d
- ffffb384`38e09a30 fffff800`712fe279 : 86b3a0fa`7b70422e 008fcd82`5e03c3ff a6d6173a`b10060d4 63dd5e88`a6da16d8 : nt!KiPageFault+0x445 (TrapFrame @ ffffb384`38e09a30)
- ffffb384`38e09bc0 fffff800`712fe0c0 : 00a4ded8`e6b7d3ff ffffb384`38e0a170 ffffb384`38e09c70 00ef7627`ab68258b : nt!RtlInitializeExtendedContext2+0x6d
- ffffb384`38e09c10 fffff800`712fe804 : 003c5ec1`ebb08c37 e5b0351b`da006124 93259244`23318711 00482207`00000001 : nt!RtlInitializeExtendedContext+0x38
- ffffb384`38e09c40 fffff800`713d431d : ffff9249`24924000 ffffb384`38e0a4d0 ffff8000`00000000 00000000`00000008 : nt!KiDispatchException+0x104
- ffffb384`38e0a2f0 fffff800`713d0505 : 001f9a82`3b0e60dc dc9b2376`35005184 00000000`0010001f 00802fb8`bff55c6c : nt!KiExceptionDispatch+0x11d
- ffffb384`38e0a4d0 fffff800`712fe279 : f9efbca5`9178e540 0077f524`16184122 b5c63b8f`39005294 b304f321`5927065a : nt!KiPageFault+0x445 (TrapFrame @ ffffb384`38e0a4d0)
- ffffb384`38e0a660 fffff800`712fe0c0 : 004b1938`2eee02ea ffffb384`38e0ac10 ffffb384`38e0a710 00453e12`a73cce32 : nt!RtlInitializeExtendedContext2+0x6d
- ffffb384`38e0a6b0 fffff800`712fe804 : 004b5dc3`97a4e9f7 b87d1ab6`460052e4 6be0d936`ad3d0ac1 002ecac1`00000001 : nt!RtlInitializeExtendedContext+0x38
- ffffb384`38e0a6e0 fffff800`713d431d : ffff9249`24924000 ffffb384`38e0af70 ffff8000`00000000 00000000`00000008 : nt!KiDispatchException+0x104
- ffffb384`38e0ad90 fffff800`713d0505 : 88267535`15005894 3127e033`6a965deb 00000000`0010001f 221c7d15`330058a4 : nt!KiExceptionDispatch+0x11d
- ffffb384`38e0af70 fffff800`712fe279 : b4c62d81`a1d3c810 00cae36f`50e0536f 0ee8fce2`a0004454 653f7da4`a3c79180 : nt!KiPageFault+0x445 (TrapFrame @ ffffb384`38e0af70)
- ffffb384`38e0b100 fffff800`712fe0c0 : 0045704b`1dbc9aa5 ffffb384`38e0b6b0 ffffb384`38e0b1b0 0075894e`5064419f : nt!RtlInitializeExtendedContext2+0x6d
- ffffb384`38e0b150 fffff800`712fe804 : 005dd30a`6147664e f2552233`210044a4 5329da00`14b461a8 00ee874f`00000001 : nt!RtlInitializeExtendedContext+0x38
- ffffb384`38e0b180 fffff800`713d431d : ffff9249`24924000 ffffb384`38e0ba10 ffff8000`00000000 00000000`00000008 : nt!KiDispatchException+0x104
- ffffb384`38e0b830 fffff800`713d0505 : fa9b3f07`12004a54 289926e6`aeab8775 00000000`0010001f 6c5c0d22`da004a64 : nt!KiExceptionDispatch+0x11d
- ffffb384`38e0ba10 fffff800`712fe279 : 00045fa9`072aaf45 b9473bb0`32004b64 2370e3f4`a34ecf0d 00c0bb68`00deb511 : nt!KiPageFault+0x445 (TrapFrame @ ffffb384`38e0ba10)
- ffffb384`38e0bba0 fffff800`712fe0c0 : 23af658a`45004b94 ffffb384`38e0c150 ffffb384`38e0bc50 fd569131`51004ba4 : nt!RtlInitializeExtendedContext2+0x6d
- ffffb384`38e0bbf0 fffff800`712fe804 : a2fff96a`d7004bb4 63af520e`6f8428b7 002b2cf3`a83b965d 730f6895`00000001 : nt!RtlInitializeExtendedContext+0x38
- ffffb384`38e0bc20 fffff800`713d431d : ffff9249`24924000 ffffb384`38e0c4b0 ffff8000`00000000 00000000`00000008 : nt!KiDispatchException+0x104
- ffffb384`38e0c2d0 fffff800`713d0505 : 1451bd42`e0003c14 27e6698d`e542127f 00000000`0010001f e4407939`65003c24 : nt!KiExceptionDispatch+0x11d
- ffffb384`38e0c4b0 fffff800`712fe279 : 00b689fc`3c66d765 57123972`25003d24 dd22e474`ccc1e7a7 0036ee7a`6750ab9e : nt!KiPageFault+0x445 (TrapFrame @ ffffb384`38e0c4b0)
- ffffb384`38e0c640 fffff800`712fe0c0 : 8f4287bc`d6003d54 ffffb384`38e0cbf0 ffffb384`38e0c6f0 6799a0ba`df003d64 : nt!RtlInitializeExtendedContext2+0x6d
- ffffb384`38e0c690 fffff800`712fe804 : 41777186`62003d74 7d5b0025`57c9a412 006aecee`67466779 f992a991`00000001 : nt!RtlInitializeExtendedContext+0x38
- ffffb384`38e0c6c0 fffff800`713d431d : ffff9249`24924000 ffffb384`38e0cf50 ffff8000`00000000 00000000`00000008 : nt!KiDispatchException+0x104
- ffffb384`38e0cd70 fffff800`713d0505 : c308f23b`62dff93c 00c7e369`7fdf81c6 00000000`0010001f d79d2676`04a006e6 : nt!KiExceptionDispatch+0x11d
- ffffb384`38e0cf50 fffff800`712fe279 : e5e5e5e5`e5e5e5e5 e5e5e5e5`e5e5e5e5 e5e5e5e5`e5e5e5e5 e5e5e5e5`e5e5e5e5 : nt!KiPageFault+0x445 (TrapFrame @ ffffb384`38e0cf50)
- ffffb384`38e0d0e0 fffff800`712fe0c0 : e5e5e5e5`e5e5e5e5 ffffb384`38e0d690 ffffb384`38e0d190 e5e5e5e5`e5e5e5e5 : nt!RtlInitializeExtendedContext2+0x6d
- ffffb384`38e0d130 fffff800`712fe804 : e5e5e5e5`e5e5e5e5 e5e5e5e5`e5e5e5e5 e5e5e5e5`e5e5e5e5 e5e5e5e5`00000001 : nt!RtlInitializeExtendedContext+0x38
- ffffb384`38e0d160 fffff800`713d431d : ffff9249`24924000 ffffb384`38e0d9f0 ffff8000`00000000 00000000`00000008 : nt!KiDispatchException+0x104
- ffffb384`38e0d810 fffff800`713d0505 : 00000000`00000000 ffff970c`3d3a7a00 00000000`0010001f 000000a0`41946350 : nt!KiExceptionDispatch+0x11d
- ffffb384`38e0d9f0 fffff800`712fe279 : ffff970c`38bc1000 ffff970c`38bc1000 00000000`00000000 ffff970c`38bc1000 : nt!KiPageFault+0x445 (TrapFrame @ ffffb384`38e0d9f0)
- ffffb384`38e0db80 fffff800`712fe0c0 : ffff970c`35ef7060 ffffb384`38e0e130 ffffb384`38e0dc30 ffff970c`35ef7060 : nt!RtlInitializeExtendedContext2+0x6d
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement