Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Microsoft (R) Windows Debugger Version 10.0.17074.1002 AMD64
- Copyright (c) Microsoft Corporation. All rights reserved.
- Loading Dump File [C:\Windows\MEMORY.DMP]
- Kernel Bitmap Dump File: Kernel address space is available, User address space may not be available.
- Symbol search path is: srv*
- Executable search path is:
- Windows 10 Kernel Version 16299 MP (16 procs) Free x64
- Product: WinNt, suite: TerminalServer SingleUserTS Personal
- Built by: 16299.15.amd64fre.rs3_release.170928-1534
- Machine Name:
- Kernel base = 0xfffff802`fa00c000 PsLoadedModuleList = 0xfffff802`fa373110
- Debug session time: Wed Mar 7 21:46:15.007 2018 (UTC + 0:00)
- System Uptime: 4 days 20:40:18.472
- Loading Kernel Symbols
- ...............................................................
- ................................................................
- ..........................................................
- Loading User Symbols
- PEB is paged out (Peb.Ldr = 000000d4`e9f06018). Type ".hh dbgerr001" for details
- Loading unloaded module list
- .................................
- *******************************************************************************
- * *
- * Bugcheck Analysis *
- * *
- *******************************************************************************
- Use !analyze -v to get detailed debugging information.
- BugCheck A, {ffffcf089df669a8, 2, 0, fffff802fa00fe0f}
- Probably caused by : memory_corruption ( nt!MiEmptyPageAccessLog+23f )
- Followup: MachineOwner
- ---------
- nt!KeBugCheckEx:
- fffff802`fa181430 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:ffff9c83`bb192a90=000000000000000a
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.1801.31001.0_x86__8wekyb3d8bbwe\amd64\Visualizers\atlmfc.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.1801.31001.0_x86__8wekyb3d8bbwe\amd64\Visualizers\concurrency.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.1801.31001.0_x86__8wekyb3d8bbwe\amd64\Visualizers\cpp_rest.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.1801.31001.0_x86__8wekyb3d8bbwe\amd64\Visualizers\stl.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.1801.31001.0_x86__8wekyb3d8bbwe\amd64\Visualizers\Windows.Data.Json.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.1801.31001.0_x86__8wekyb3d8bbwe\amd64\Visualizers\Windows.Devices.Geolocation.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.1801.31001.0_x86__8wekyb3d8bbwe\amd64\Visualizers\Windows.Devices.Sensors.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.1801.31001.0_x86__8wekyb3d8bbwe\amd64\Visualizers\Windows.Media.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.1801.31001.0_x86__8wekyb3d8bbwe\amd64\Visualizers\windows.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.1801.31001.0_x86__8wekyb3d8bbwe\amd64\Visualizers\winrt.natvis'
- NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.1801.31001.0_x86__8wekyb3d8bbwe\amd64\Visualizers\Kernel.natvis'
- Microsoft (R) Windows Debugger Version 10.0.17074.1002 AMD64
- Copyright (c) Microsoft Corporation. All rights reserved.
- Loading Dump File [C:\Windows\Minidump\030718-25328-01.dmp]
- Mini Kernel Dump File: Only registers and stack trace are available
- Symbol search path is: srv*
- Executable search path is:
- Windows 10 Kernel Version 16299 MP (16 procs) Free x64
- Product: WinNt, suite: TerminalServer SingleUserTS Personal
- Built by: 16299.15.amd64fre.rs3_release.170928-1534
- Machine Name:
- Kernel base = 0xfffff802`fa00c000 PsLoadedModuleList = 0xfffff802`fa373110
- Debug session time: Wed Mar 7 21:46:15.007 2018 (UTC + 0:00)
- System Uptime: 4 days 20:40:18.472
- Loading Kernel Symbols
- ...............................................................
- ................................................................
- ..........................................................
- Loading User Symbols
- Loading unloaded module list
- .................................
- *******************************************************************************
- * *
- * Bugcheck Analysis *
- * *
- *******************************************************************************
- Use !analyze -v to get detailed debugging information.
- BugCheck A, {ffffcf089df669a8, 2, 0, fffff802fa00fe0f}
- Probably caused by : memory_corruption ( nt!MiEmptyPageAccessLog+23f )
- Followup: MachineOwner
- ---------
- nt!KeBugCheckEx:
- fffff802`fa181430 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:ffff9c83`bb192a90=000000000000000a
- ************* Path validation summary **************
- Response Time (ms) Location
- Deferred srv*
- 12: kd> !analyze -v
- *******************************************************************************
- * *
- * Bugcheck Analysis *
- * *
- *******************************************************************************
- IRQL_NOT_LESS_OR_EQUAL (a)
- An attempt was made to access a pageable (or completely invalid) address at an
- interrupt request level (IRQL) that is too high. This is usually
- caused by drivers using improper addresses.
- If a kernel debugger is available get the stack backtrace.
- Arguments:
- Arg1: ffffcf089df669a8, memory referenced
- Arg2: 0000000000000002, IRQL
- Arg3: 0000000000000000, bitfield :
- bit 0 : value 0 = read operation, 1 = write operation
- bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
- Arg4: fffff802fa00fe0f, address which referenced memory
- Debugging Details:
- ------------------
- KEY_VALUES_STRING: 1
- TIMELINE_ANALYSIS: 1
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- BUILD_VERSION_STRING: 10.0.16299.248 (WinBuild.160101.0800)
- SYSTEM_MANUFACTURER: Micro-Star International Co., Ltd.
- SYSTEM_PRODUCT_NAME: MS-7A32
- SYSTEM_SKU: To be filled by O.E.M.
- SYSTEM_VERSION: 1.0
- BIOS_VENDOR: American Megatrends Inc.
- BIOS_VERSION: 1.90
- BIOS_DATE: 09/20/2017
- BASEBOARD_MANUFACTURER: Micro-Star International Co., Ltd.
- BASEBOARD_PRODUCT: X370 GAMING PRO CARBON (MS-7A32)
- BASEBOARD_VERSION: 1.0
- DUMP_TYPE: 2
- BUGCHECK_P1: ffffcf089df669a8
- BUGCHECK_P2: 2
- BUGCHECK_P3: 0
- BUGCHECK_P4: fffff802fa00fe0f
- READ_ADDRESS: fffff802fa409380: Unable to get MiVisibleState
- Unable to get NonPagedPoolStart
- Unable to get NonPagedPoolEnd
- Unable to get PagedPoolStart
- Unable to get PagedPoolEnd
- ffffcf089df669a8
- CURRENT_IRQL: 2
- FAULTING_IP:
- nt!MiEmptyPageAccessLog+23f
- fffff802`fa00fe0f 488b01 mov rax,qword ptr [rcx]
- CPU_COUNT: 10
- CPU_MHZ: bb8
- CPU_VENDOR: AuthenticAMD
- CPU_FAMILY: 17
- CPU_MODEL: 1
- CPU_STEPPING: 1
- BLACKBOXBSD: 1 (!blackboxbsd)
- BLACKBOXPNP: 1 (!blackboxpnp)
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
- BUGCHECK_STR: AV
- PROCESS_NAME: MsMpEng.exe
- ANALYSIS_SESSION_HOST: DESKTOP-69RG4KQ
- ANALYSIS_SESSION_TIME: 03-09-2018 15:25:32.0482
- ANALYSIS_VERSION: 10.0.17074.1002 amd64fre
- TRAP_FRAME: ffff9c83bb192bd0 -- (.trap 0xffff9c83bb192bd0)
- NOTE: The trap frame does not contain all registers.
- Some register values may be zeroed or incorrect.
- rax=ffffcf088cf9efe8 rbx=0000000000000000 rcx=ffffcf089df669a8
- rdx=ffffa78b2d706840 rsi=0000000000000000 rdi=0000000000000000
- rip=fffff802fa00fe0f rsp=ffff9c83bb192d60 rbp=0057c596b8341400
- r8=0000000000000000 r9=0000000000000000 r10=00000000000001ff
- r11=ffff838000000000 r12=0000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=0000000000000000
- iopl=0 nv up ei ng nz na po nc
- nt!MiEmptyPageAccessLog+0x23f:
- fffff802`fa00fe0f 488b01 mov rax,qword ptr [rcx] ds:ffffcf08`9df669a8=????????????????
- Resetting default scope
- LAST_CONTROL_TRANSFER: from fffff802fa194529 to fffff802fa181430
- STACK_TEXT:
- ffff9c83`bb192a88 fffff802`fa194529 : 00000000`0000000a ffffcf08`9df669a8 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
- ffff9c83`bb192a90 fffff802`fa190659 : 00000000`00000000 00000000`63416d4d 00000000`00000200 00000000`00001000 : nt!KiBugCheckDispatch+0x69
- ffff9c83`bb192bd0 fffff802`fa00fe0f : 00000000`04455403 fffff802`00000002 00000000`00000000 fffff802`fa232b0c : nt!KiPageFault+0x519
- ffff9c83`bb192d60 fffff802`fa00faf4 : ffffcf08`8cf9e000 ffffcf08`00000000 00000003`00000000 00000000`043e2401 : nt!MiEmptyPageAccessLog+0x23f
- ffff9c83`bb192df0 fffff802`fa00f7d2 : ffff8380`edc297b0 ffff83ff`ffffffff ffffcf08`8bde1000 00000000`00000000 : nt!MiAllocateAccessLog+0xf4
- ffff9c83`bb192e20 fffff802`fa0700b1 : 00000003`00000000 ffff83ff`ffffffff 80000001`349d2847 ffff8380`00000000 : nt!MiLogPageAccess+0x52
- ffff9c83`bb192e90 fffff802`fa06f76e : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MiAgePte+0x771
- ffff9c83`bb192f50 fffff802`fa06f670 : 00000000`00000000 00000000`00000000 00000000`00000001 00000000`00000000 : nt!MiWalkPageTablesRecursively+0x75e
- ffff9c83`bb193010 fffff802`fa06f670 : 00000000`00000000 ffff9c83`bb193110 ffffba80`e6079180 00000000`00000000 : nt!MiWalkPageTablesRecursively+0x660
- ffff9c83`bb1930d0 fffff802`fa06f670 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MiWalkPageTablesRecursively+0x660
- ffff9c83`bb193190 fffff802`fa06ef4f : ffff9c83`bb193480 00000000`00000c60 ffff9c83`bb193270 ffff9c83`bb193270 : nt!MiWalkPageTablesRecursively+0x660
- ffff9c83`bb193250 fffff802`fa06eb91 : 00000000`00000000 fffff802`fa070bd0 ffffcf08`8aa62010 fffff802`73576d4d : nt!MiWalkPageTables+0x20f
- ffff9c83`bb1932f0 fffff802`fa06e5b5 : ffffcf08`937a2a80 00000000`00000002 00000000`00000000 ffffcf08`92c0f580 : nt!MiAgeWorkingSet+0x2b1
- ffff9c83`bb1937f0 fffff802`fa06dd29 : ffffcf08`00000000 ffff9c83`bb193a80 ffff9c83`bb1939b0 00000000`00000000 : nt!MiTrimOrAgeWorkingSet+0x175
- ffff9c83`bb1938b0 fffff802`fa0a80c2 : fffff802`fa3930c0 fffff802`fa3930c0 00000000`00000078 00000000`00000078 : nt!MiProcessWorkingSets+0x219
- ffff9c83`bb193a60 fffff802`fa14d260 : 00000000`ffffffff 00000000`00000002 00000000`ffffffff 00000000`00000001 : nt!MiWorkingSetManager+0xa2
- ffff9c83`bb193b20 fffff802`fa122b87 : ffffcf08`8ab65040 00000000`00000080 fffff802`fa14d110 00000000`00000000 : nt!KeBalanceSetManager+0x150
- ffff9c83`bb193c10 fffff802`fa188be6 : ffffba80`e5f0f180 ffffcf08`8ab65040 fffff802`fa122b40 00000000`00000000 : nt!PspSystemThreadStartup+0x47
- ffff9c83`bb193c60 00000000`00000000 : ffff9c83`bb194000 ffff9c83`bb18e000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x16
- THREAD_SHA1_HASH_MOD_FUNC: 34b8500d32060e7bf947feb8c8ed53f6feb183c1
- THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 7a33da1f2b06944e493cbee53e359cac83eb2da5
- THREAD_SHA1_HASH_MOD: a9ca63faa9e43cc61ef524ad38163e6a9ae5c358
- FOLLOWUP_IP:
- nt!MiEmptyPageAccessLog+23f
- fffff802`fa00fe0f 488b01 mov rax,qword ptr [rcx]
- FAULT_INSTR_CODE: 8b018b48
- SYMBOL_STACK_INDEX: 3
- SYMBOL_NAME: nt!MiEmptyPageAccessLog+23f
- FOLLOWUP_NAME: MachineOwner
- MODULE_NAME: nt
- DEBUG_FLR_IMAGE_TIMESTAMP: 5a7e7659
- IMAGE_VERSION: 10.0.16299.248
- STACK_COMMAND: .thread ; .cxr ; kb
- IMAGE_NAME: memory_corruption
- BUCKET_ID_FUNC_OFFSET: 23f
- FAILURE_BUCKET_ID: AV_nt!MiEmptyPageAccessLog
- BUCKET_ID: AV_nt!MiEmptyPageAccessLog
- PRIMARY_PROBLEM_CLASS: AV_nt!MiEmptyPageAccessLog
- TARGET_TIME: 2018-03-07T21:46:15.000Z
- OSBUILD: 16299
- OSSERVICEPACK: 248
- SERVICEPACK_NUMBER: 0
- OS_REVISION: 0
- SUITE_MASK: 784
- PRODUCT_TYPE: 1
- OSPLATFORM_TYPE: x64
- OSNAME: Windows 10
- OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS Personal
- OS_LOCALE:
- USER_LCID: 0
- OSBUILD_TIMESTAMP: 2018-02-10 04:34:33
- BUILDDATESTAMP_STR: 160101.0800
- BUILDLAB_STR: WinBuild
- BUILDOSVER_STR: 10.0.16299.248
- ANALYSIS_SESSION_ELAPSED_TIME: cf7
- ANALYSIS_SOURCE: KM
- FAILURE_ID_HASH_STRING: km:av_nt!miemptypageaccesslog
- FAILURE_ID_HASH: {18874cb9-02c8-297c-e41f-9e712e158c7d}
- Followup: MachineOwner
- ---------
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement