Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ========================== AUTO DUMP ANALYZER ==========================
- Auto Dump Analyzer
- Version: 0.4
- Created by: gardenman
- Time to analyze file(s): 00 hours and 02 minutes and 04 seconds
- ================================= BIOS =================================
- VENDOR: American Megatrends Inc.
- VERSION: P2.70
- DATE: 11/04/2015
- ============================= MOTHERBOARD ==============================
- MANUFACTURER: ASRock
- PRODUCT: Z170 Pro4S
- ================================= RAM ==================================
- Size Speed Manufacturer Part No.
- -------------- -------------- ------------------- ----------------------
- 8192MB 2133MHz 0793 GR2133D464L15/8G
- 0MHz
- 0MHz
- 0MHz
- ================================= CPU ==================================
- Processor Version: Intel(R) Core(TM) i5-6402P CPU @ 2.80GHz
- COUNT: 4
- MHZ: 2808
- VENDOR: GenuineIntel
- FAMILY: 6
- MODEL: 5e
- STEPPING: 3
- MICROCODE: 6,5e,3,0 (F,M,S,R) SIG: 49'00000000 (cache) 49'00000000 (init)
- ================================== OS ==================================
- Product: WinNt, suite: TerminalServer SingleUserTS
- Built by: 15063.0.amd64fre.rs2_release.170317-1834
- BUILD_VERSION: 10.0.15063.608 (WinBuild.160101.0800)
- BUILD: 15063
- SERVICEPACK: 608
- PLATFORM_TYPE: x64
- NAME: Windows 10
- EDITION: Windows 10 WinNt TerminalServer SingleUserTS
- BUILD_TIMESTAMP: 2017-09-05 00:09:34
- BUILDDATESTAMP: 160101.0800
- BUILDLAB: WinBuild
- BUILDOSVER: 10.0.15063.608
- =============================== DEBUGGER ===============================
- Microsoft (R) Windows Debugger Version 10.0.14321.1024 X86
- Copyright (c) Microsoft Corporation. All rights reserved.
- =============================== COMMENTS ===============================
- * Information gathered from different dump files may be different. If
- Windows updates between two dump files, two or more OS versions may
- be shown above.
- * If the user updates the BIOS between dump files, two or more versions
- and dates may be shown above.
- * More RAM information can be found below in the full BIOS section.
- ========================================================================
- ==================== Dump File: 092717-25359-01.dmp ====================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 15063 MP (4 procs) Free x64
- Kernel base = 0xfffff803`5b286000 PsLoadedModuleList = 0xfffff803`5b5d25c0
- Debug session time: Wed Sep 27 15:23:53.399 2017 (UTC - 4:00)
- System Uptime: 0 days 1:19:44.101
- BugCheck 3B, {c0000005, fffff8035b37c720, ffff8080b04a4240, 0}
- *** WARNING: Unable to verify timestamp for klbackupdisk.sys
- *** ERROR: Module load completed but symbols could not be loaded for klbackupdisk.sys
- Probably caused by : memory_corruption
- Followup: memory_corruption
- SYSTEM_SERVICE_EXCEPTION (3b)
- An exception happened while executing a system service routine.
- Arguments:
- Arg1: 00000000c0000005, Exception code that caused the bugcheck
- Arg2: fffff8035b37c720, Address of the instruction which caused the bugcheck
- Arg3: ffff8080b04a4240, Address of the context record for the exception that caused the bugcheck
- Arg4: 0000000000000000, zero.
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.
- FAULTING_IP:
- nt!IoGetSiloParameters+0
- fffff803`5b37c720 488b81d0000000 mov rax,qword ptr [rcx+0D0h]
- CONTEXT: ffff8080b04a4240 -- (.cxr 0xffff8080b04a4240)
- rax=0000000000000001 rbx=ffffe10f29cc34a0 rcx=0000000000000000
- rdx=ffff8080b04a4d30 rsi=ffffe10f29cc33c0 rdi=ffff8080b04a4d30
- rip=fffff8035b37c720 rsp=ffff8080b04a4c38 rbp=ffff8080b04a4dd9
- r8=ffffe10f29cc34f8 r9=000000000000003e r10=ffffe10f27b33010
- r11=ffffe10f2bfa57c0 r12=ffffe10f29cc3440 r13=ffffe10f347cf010
- r14=ffffe10f29cc3540 r15=0000000010000004
- iopl=0 nv up ei ng nz na pe nc
- cs=0010 ss=0000 ds=002b es=002b fs=0053 gs=002b efl=00010282
- nt!IoGetSiloParameters:
- fffff803`5b37c720 488b81d0000000 mov rax,qword ptr [rcx+0D0h] ds:002b:00000000`000000d0=????????????????
- Resetting default scope
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- BUGCHECK_STR: 0x3B
- PROCESS_NAME: OriginWebHelperService.exe
- CURRENT_IRQL: 0
- LAST_CONTROL_TRANSFER: from fffff803735d323a to fffff8035b37c720
- STACK_TEXT:
- ffff8080`b04a4c38 fffff803`735d323a : ffff8080`b04a4c50 ffffe10f`27a67610 00000000`00000001 00000000`00000000 : nt!IoGetSiloParameters
- ffff8080`b04a4c40 fffff803`735e2926 : 00000000`00000003 fffff803`5b605bc0 ffffe10f`20206f49 00000000`00000030 : wcnfs!WcnGetSiloFromFileObject+0xa
- ffff8080`b04a4c70 fffff803`735dc52f : ffffe10f`2bfa5ae0 ffff8080`b04a4db0 ffffe10f`29cc33c0 ffffe10f`278bc0f0 : wcnfs!WcnGetFltCallbackSiloDetails+0x22
- ffff8080`b04a4cd0 fffff803`54a04b4c : 00000000`00000000 ffff8080`b04a4dd9 ffffe10f`00000000 ffffe10f`29cc33c0 : wcnfs!WcnFsctlDefaultFilter+0x1f
- ffff8080`b04a4d20 fffff803`54a046ec : ffff8080`b04a4f10 ffffe10f`27bad000 00000000`00000000 ffffe10f`2cc7780d : FLTMGR!FltpPerformPreCallbacks+0x2ec
- ffff8080`b04a4e40 fffff803`54a036d8 : 00000000`00000000 ffff8080`b04a4f10 ffffe10f`2cc77840 ffff8080`b04a4f20 : FLTMGR!FltpPassThroughInternal+0x8c
- ffff8080`b04a4e70 fffff803`54a355fb : ffffe10f`26fa0c80 ffffe10f`26fa0c80 00000000`0000000f 00000000`00000001 : FLTMGR!FltpPassThrough+0x168
- ffff8080`b04a4ef0 fffff803`5515640c : ffffe10f`27b6e801 ffff8080`b04a5229 ffffe10f`27b67101 fffff803`54a0addf : FLTMGR!FltpFsControl+0xcb
- ffff8080`b04a4f50 ffffe10f`27b6e801 : ffff8080`b04a5229 ffffe10f`27b67101 fffff803`54a0addf 00000000`00000010 : klbackupdisk+0x640c
- ffff8080`b04a4f58 ffff8080`b04a5229 : ffffe10f`27b67101 fffff803`54a0addf 00000000`00000010 00000000`00000086 : 0xffffe10f`27b6e801
- ffff8080`b04a4f60 ffffe10f`27b67101 : fffff803`54a0addf 00000000`00000010 00000000`00000086 00000000`b0060000 : 0xffff8080`b04a5229
- ffff8080`b04a4f68 fffff803`54a0addf : 00000000`00000010 00000000`00000086 00000000`b0060000 ffff8080`b04a4f88 : 0xffffe10f`27b67101
- ffff8080`b04a4f70 fffff803`54a0ad4f : ffffe10f`27b6cb00 00000000`00000000 ffffe10f`27b67101 ffff8080`b04a5229 : FLTMGR!FltReleasePushLock+0xf
- ffff8080`b04a4fa0 fffff803`5515185b : ffffe10f`27b6cb00 001fceeb`8320005b ffff8080`b04a5000 ffffe10f`00000010 : FLTMGR!FltAcquirePushLockExclusive+0xf
- ffff8080`b04a4fd0 ffffe10f`27b6cb00 : 001fceeb`8320005b ffff8080`b04a5000 ffffe10f`00000010 00000000`00000000 : klbackupdisk+0x185b
- ffff8080`b04a4fd8 001fceeb`8320005b : ffff8080`b04a5000 ffffe10f`00000010 00000000`00000000 00007fff`00000000 : 0xffffe10f`27b6cb00
- ffff8080`b04a4fe0 ffff8080`b04a5000 : ffffe10f`00000010 00000000`00000000 00007fff`00000000 00000000`00000001 : 0x001fceeb`8320005b
- ffff8080`b04a4fe8 ffffe10f`00000010 : 00000000`00000000 00007fff`00000000 00000000`00000001 00000000`06400000 : 0xffff8080`b04a5000
- ffff8080`b04a4ff0 00000000`00000000 : 00007fff`00000000 00000000`00000001 00000000`06400000 ffff5d36`7a315845 : 0xffffe10f`00000010
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
- fffff8035b2f0dfb-fffff8035b2f0dfc 2 bytes - nt!MiInsertNonPagedPoolOnSlist+40b
- [ 80 fa:00 c2 ]
- fffff8035b2f0e32-fffff8035b2f0e33 2 bytes - nt!MiInsertNonPagedPoolOnSlist+442 (+0x37)
- [ 80 f6:00 f5 ]
- fffff8035b3141d7-fffff8035b3141d8 2 bytes - nt!MiResolvePageTablePage+3b7 (+0x233a5)
- [ ff f6:7f f5 ]
- fffff8035b3141f8-fffff8035b3141fc 5 bytes - nt!MiResolvePageTablePage+3d8 (+0x21)
- [ df be 7d fb f6:af 5e bd 7a f5 ]
- fffff8035b37c018-fffff8035b37c01a 3 bytes - nt!MiGetPhysicalAddress+48 (+0x67e20)
- [ 40 fb f6:80 7a f5 ]
- fffff8035b37c026-fffff8035b37c027 2 bytes - nt!MiGetPhysicalAddress+56 (+0x0e)
- [ 80 f6:00 f5 ]
- fffff8035b37c150-fffff8035b37c151 2 bytes - nt!MiVaToPfn+30 (+0x12a)
- [ 80 f6:00 f5 ]
- fffff8035b37c29b-fffff8035b37c29c 2 bytes - nt!MiInPageSingleKernelStack+53 (+0x14b)
- [ 80 f6:00 f5 ]
- fffff8035b37c392-fffff8035b37c393 2 bytes - nt!MiInPageSingleKernelStack+14a (+0xf7)
- [ 80 f6:00 f5 ]
- fffff8035b37c469-fffff8035b37c46a 2 bytes - nt!MiInPageSingleKernelStack+221 (+0xd7)
- [ 80 fa:00 c2 ]
- fffff8035b37c65f-fffff8035b37c660 2 bytes - nt!MiProcessWsInSwapFault+5f (+0x1f6)
- [ 80 fa:00 c2 ]
- fffff8035b37c7a3-fffff8035b37c7a4 2 bytes - nt!MiClearNonPagedPtes+53 (+0x144)
- [ 80 f6:00 f5 ]
- fffff8035b37c884-fffff8035b37c885 2 bytes - nt!MiClearNonPagedPtes+134 (+0xe1)
- [ 80 f6:00 f5 ]
- fffff8035b37c995-fffff8035b37c996 2 bytes - nt!MiLockNonPagedPoolPte+25 (+0x111)
- [ 80 fa:00 c2 ]
- fffff8035b506383-fffff8035b506385 3 bytes - nt!ExFreePoolWithTag+363
- [ 40 fb f6:80 7a f5 ]
- 35 errors : !nt (fffff8035b2f0dfb-fffff8035b506385)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- STACK_COMMAND: .cxr 0xffff8080b04a4240 ; kb
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2017-09-27T19:23:53.000Z
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ========================================================================
- ===================== 3RD PARTY DRIVER QUICK LIST ======================
- ========================================================================
- Sep 09 2005 - atillk64.sys -
- May 05 2013 - ScpVBus.sys - Scarlet.Crush Productions Scp Dual Shock 3 Virtual Bus driver http://forums.pcsx2.net/
- Dec 25 2015 - kldisk.sys - Kaspersky Virtual Disk driver https://www.kaspersky.com/
- Mar 04 2016 - e1i63x64.sys - Intel(R) Gigabit Adapter NDIS 6.x driver https://downloadcenter.intel.com/
- Apr 01 2016 - kl1.sys - Kaspersky Lab 1 Unified Driver https://www.kaspersky.com/
- May 16 2016 - kltap.sys - TAP-Windows Virtual Network Driver (AnchorFree)
- Aug 31 2016 - TeeDriverW8x64.sys - Intel® Management Engine Interface
- Sep 13 2016 - RTKVHD64.sys - Realtek Audio Driver system driver http://www.realtek.com.tw/
- Sep 30 2016 - RTCore64.sys - !!! Overclocking Software (Remove ALL copies while attempting to fix BSODs) - MSI Afterburner http://www.msi.com/ or EVGA Precision X http://www.evga.com/
- Sep 30 2016 - klim6.sys - Kaspersky Lab Intermediate Network Driver https://www.kaspersky.com/
- Oct 26 2016 - rzendpt.sys - Razer RzEndPt driver https://www.razerzone.com/
- Oct 26 2016 - rzudd.sys - Razer Rzudd Engine Driver https://www.razerzone.com/
- Nov 15 2016 - rtwlanu.sys - Realtek WLAN USB NDIS Driver http://www.realtek.com.tw/
- Nov 30 2016 - klmouflt.sys - Kaspersky Mouse Device Filter https://www.kaspersky.com/
- Dec 07 2016 - klbackupdisk.sys - Kaspersky Backup Disk Filter https://www.kaspersky.com/
- Dec 15 2016 - cm_km.sys - Kaspersky Cryptographic Module Driver
- Dec 20 2016 - klkbdflt.sys - Kaspersky Keyboard Device Filter https://www.kaspersky.com/
- Dec 23 2016 - klbackupflt.sys - Kaspersky Backup File Filter https://www.kaspersky.com/
- Feb 06 2017 - klupd_klif_kimul.sys - Kaspersky Kernel Heuristics Engine https://www.kaspersky.com/
- Mar 24 2017 - klpd.sys - Kaspersky Format Recognizer https://www.kaspersky.com/
- Mar 24 2017 - klwtp.sys - Kaspersky WFP Network Connection Filter Driver https://www.kaspersky.com/
- Mar 25 2017 - AtihdWT6.sys - AMD High Definition Audio Function Driver http://support.amd.com/
- Mar 28 2017 - klhk.sys - Kaspersky Lab service driver https://www.kaspersky.com/
- Mar 30 2017 - klupd_klif_arkmon.sys - Kaspersky Anti-Virus Anti-Rootkit Monitor https://www.kaspersky.com/
- Mar 30 2017 - klupd_klif_klbg.sys - Kaspersky Anti-Virus Lab Boot Guard Driver https://www.kaspersky.com/
- Mar 30 2017 - klupd_klif_mark.sys - Kaspersky Lab Anti-Rootkit Engine https://www.kaspersky.com
- Jun 07 2017 - kneps.sys - Kaspersky KNEPS Power https://www.kaspersky.com/
- Jul 16 2017 - rzpnk.sys - Razer Overlay Support https://www.razerzone.com/
- Jul 18 2017 - rzpmgrk.sys - Razer Overlay Support https://www.razerzone.com/
- Jul 19 2017 - klflt.sys - Kaspersky Filter Core https://www.kaspersky.com/
- Aug 11 2017 - klif.sys - Kaspersky Lab Intruder Filter driver https://www.kaspersky.com/
- Sep 05 2017 - atikmdag.sys - ATI Radeon Kernel Mode Driver Package
- Sep 05 2017 - atikmpag.sys - ATI video card driver
- ========================================================================
- ========================== 3RD PARTY DRIVERS ===========================
- ========================================================================
- Image path: \??\C:\Program Files (x86)\GIGABYTE\XTREME GAMING ENGINE\AtiTool\atillk64.sys
- Image name: atillk64.sys
- Search : https://www.google.com/search?q=atillk64.sys
- Timestamp : Fri Sep 9 2005
- Image path: \SystemRoot\System32\drivers\ScpVBus.sys
- Image name: ScpVBus.sys
- Search : https://www.google.com/search?q=ScpVBus.sys
- ADA Info : Scarlet.Crush Productions Scp Dual Shock 3 Virtual Bus driver http://forums.pcsx2.net/
- Timestamp : Sun May 5 2013
- Image path: \SystemRoot\system32\DRIVERS\kldisk.sys
- Image name: kldisk.sys
- Search : https://www.google.com/search?q=kldisk.sys
- ADA Info : Kaspersky Virtual Disk driver https://www.kaspersky.com/
- Timestamp : Fri Dec 25 2015
- Image path: \SystemRoot\System32\drivers\e1i63x64.sys
- Image name: e1i63x64.sys
- Search : https://www.google.com/search?q=e1i63x64.sys
- ADA Info : Intel(R) Gigabit Adapter NDIS 6.x driver https://downloadcenter.intel.com/
- Timestamp : Fri Mar 4 2016
- Image path: \SystemRoot\system32\DRIVERS\kl1.sys
- Image name: kl1.sys
- Search : https://www.google.com/search?q=kl1.sys
- ADA Info : Kaspersky Lab 1 Unified Driver https://www.kaspersky.com/
- Timestamp : Fri Apr 1 2016
- Image path: \SystemRoot\System32\drivers\kltap.sys
- Image name: kltap.sys
- Search : https://www.google.com/search?q=kltap.sys
- ADA Info : TAP-Windows Virtual Network Driver (AnchorFree)
- Timestamp : Mon May 16 2016
- Image path: \SystemRoot\System32\drivers\TeeDriverW8x64.sys
- Image name: TeeDriverW8x64.sys
- Search : https://www.google.com/search?q=TeeDriverW8x64.sys
- ADA Info : Intel® Management Engine Interface
- Timestamp : Wed Aug 31 2016
- Image path: \SystemRoot\system32\drivers\RTKVHD64.sys
- Image name: RTKVHD64.sys
- Search : https://www.google.com/search?q=RTKVHD64.sys
- ADA Info : Realtek Audio Driver system driver http://www.realtek.com.tw/
- Timestamp : Tue Sep 13 2016
- Image path: \??\C:\Program Files (x86)\MSI Afterburner\RTCore64.sys
- Image name: RTCore64.sys
- Search : https://www.google.com/search?q=RTCore64.sys
- ADA Info : !!! Overclocking Software (Remove ALL copies while attempting to fix BSODs) - MSI Afterburner http://www.msi.com/ or EVGA Precision X http://www.evga.com/
- Timestamp : Fri Sep 30 2016
- Image path: \SystemRoot\system32\DRIVERS\klim6.sys
- Image name: klim6.sys
- Search : https://www.google.com/search?q=klim6.sys
- ADA Info : Kaspersky Lab Intermediate Network Driver https://www.kaspersky.com/
- Timestamp : Fri Sep 30 2016
- Image path: \SystemRoot\System32\drivers\rzendpt.sys
- Image name: rzendpt.sys
- Search : https://www.google.com/search?q=rzendpt.sys
- ADA Info : Razer RzEndPt driver https://www.razerzone.com/
- Timestamp : Wed Oct 26 2016
- Image path: \SystemRoot\System32\drivers\rzudd.sys
- Image name: rzudd.sys
- Search : https://www.google.com/search?q=rzudd.sys
- ADA Info : Razer Rzudd Engine Driver https://www.razerzone.com/
- Timestamp : Wed Oct 26 2016
- Image path: \SystemRoot\System32\drivers\rtwlanu.sys
- Image name: rtwlanu.sys
- Search : https://www.google.com/search?q=rtwlanu.sys
- ADA Info : Realtek WLAN USB NDIS Driver http://www.realtek.com.tw/
- Timestamp : Tue Nov 15 2016
- Image path: \SystemRoot\system32\DRIVERS\klmouflt.sys
- Image name: klmouflt.sys
- Search : https://www.google.com/search?q=klmouflt.sys
- ADA Info : Kaspersky Mouse Device Filter https://www.kaspersky.com/
- Timestamp : Wed Nov 30 2016
- Image path: \SystemRoot\system32\DRIVERS\klbackupdisk.sys
- Image name: klbackupdisk.sys
- Search : https://www.google.com/search?q=klbackupdisk.sys
- ADA Info : Kaspersky Backup Disk Filter https://www.kaspersky.com/
- Timestamp : Wed Dec 7 2016
- Image path: \SystemRoot\system32\DRIVERS\cm_km.sys
- Image name: cm_km.sys
- Search : https://www.google.com/search?q=cm_km.sys
- ADA Info : Kaspersky Cryptographic Module Driver
- Timestamp : Thu Dec 15 2016
- Image path: \SystemRoot\system32\DRIVERS\klkbdflt.sys
- Image name: klkbdflt.sys
- Search : https://www.google.com/search?q=klkbdflt.sys
- ADA Info : Kaspersky Keyboard Device Filter https://www.kaspersky.com/
- Timestamp : Tue Dec 20 2016
- Image path: \SystemRoot\system32\DRIVERS\klbackupflt.sys
- Image name: klbackupflt.sys
- Search : https://www.google.com/search?q=klbackupflt.sys
- ADA Info : Kaspersky Backup File Filter https://www.kaspersky.com/
- Timestamp : Fri Dec 23 2016
- Image path: \SystemRoot\System32\Drivers\klupd_klif_kimul.sys
- Image name: klupd_klif_kimul.sys
- Search : https://www.google.com/search?q=klupd_klif_kimul.sys
- ADA Info : Kaspersky Kernel Heuristics Engine https://www.kaspersky.com/
- Timestamp : Mon Feb 6 2017
- Image path: \SystemRoot\system32\DRIVERS\klpd.sys
- Image name: klpd.sys
- Search : https://www.google.com/search?q=klpd.sys
- ADA Info : Kaspersky Format Recognizer https://www.kaspersky.com/
- Timestamp : Fri Mar 24 2017
- Image path: \SystemRoot\system32\DRIVERS\klwtp.sys
- Image name: klwtp.sys
- Search : https://www.google.com/search?q=klwtp.sys
- ADA Info : Kaspersky WFP Network Connection Filter Driver https://www.kaspersky.com/
- Timestamp : Fri Mar 24 2017
- Image path: \SystemRoot\system32\drivers\AtihdWT6.sys
- Image name: AtihdWT6.sys
- Search : https://www.google.com/search?q=AtihdWT6.sys
- ADA Info : AMD High Definition Audio Function Driver http://support.amd.com/
- Timestamp : Sat Mar 25 2017
- Image path: \SystemRoot\System32\drivers\klhk.sys
- Image name: klhk.sys
- Search : https://www.google.com/search?q=klhk.sys
- ADA Info : Kaspersky Lab service driver https://www.kaspersky.com/
- Timestamp : Tue Mar 28 2017
- Image path: \SystemRoot\System32\Drivers\klupd_klif_arkmon.sys
- Image name: klupd_klif_arkmon.sys
- Search : https://www.google.com/search?q=klupd_klif_arkmon.sys
- ADA Info : Kaspersky Anti-Virus Anti-Rootkit Monitor https://www.kaspersky.com/
- Timestamp : Thu Mar 30 2017
- Image path: \SystemRoot\System32\Drivers\klupd_klif_klbg.sys
- Image name: klupd_klif_klbg.sys
- Search : https://www.google.com/search?q=klupd_klif_klbg.sys
- ADA Info : Kaspersky Anti-Virus Lab Boot Guard Driver https://www.kaspersky.com/
- Timestamp : Thu Mar 30 2017
- Image path: \SystemRoot\System32\Drivers\klupd_klif_mark.sys
- Image name: klupd_klif_mark.sys
- Search : https://www.google.com/search?q=klupd_klif_mark.sys
- ADA Info : Kaspersky Lab Anti-Rootkit Engine https://www.kaspersky.com
- Timestamp : Thu Mar 30 2017
- Image path: \SystemRoot\system32\DRIVERS\kneps.sys
- Image name: kneps.sys
- Search : https://www.google.com/search?q=kneps.sys
- ADA Info : Kaspersky KNEPS Power https://www.kaspersky.com/
- Timestamp : Wed Jun 7 2017
- Image path: \??\C:\Windows\system32\drivers\rzpnk.sys
- Image name: rzpnk.sys
- Search : https://www.google.com/search?q=rzpnk.sys
- ADA Info : Razer Overlay Support https://www.razerzone.com/
- Timestamp : Sun Jul 16 2017
- Image path: \??\C:\Windows\system32\drivers\rzpmgrk.sys
- Image name: rzpmgrk.sys
- Search : https://www.google.com/search?q=rzpmgrk.sys
- ADA Info : Razer Overlay Support https://www.razerzone.com/
- Timestamp : Tue Jul 18 2017
- Image path: \SystemRoot\system32\DRIVERS\klflt.sys
- Image name: klflt.sys
- Search : https://www.google.com/search?q=klflt.sys
- ADA Info : Kaspersky Filter Core https://www.kaspersky.com/
- Timestamp : Wed Jul 19 2017
- Image path: \SystemRoot\system32\DRIVERS\klif.sys
- Image name: klif.sys
- Search : https://www.google.com/search?q=klif.sys
- ADA Info : Kaspersky Lab Intruder Filter driver https://www.kaspersky.com/
- Timestamp : Fri Aug 11 2017
- Image path: \SystemRoot\System32\DriverStore\FileRepository\c0317685.inf_amd64_f4ed8f05a31c5d2d\atikmdag.sys
- Image name: atikmdag.sys
- Search : https://www.google.com/search?q=atikmdag.sys
- ADA Info : ATI Radeon Kernel Mode Driver Package
- Timestamp : Tue Sep 5 2017
- Image path: \SystemRoot\System32\DriverStore\FileRepository\c0317685.inf_amd64_f4ed8f05a31c5d2d\atikmpag.sys
- Image name: atikmpag.sys
- Search : https://www.google.com/search?q=atikmpag.sys
- ADA Info : ATI video card driver
- Timestamp : Tue Sep 5 2017
- If any of the above drivers are from Microsoft then please let me know.
- I will have them moved to the Microsoft list on the next update.
- ========================================================================
- ========================== MICROSOFT DRIVERS ===========================
- ========================================================================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- acpipagr.sys ACPI Processor Aggregator Device driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdfs.sys CD-ROM File System Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- csc.sys Windows Client Side Caching driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_diskdump.sys Crash Dump Disk Driver
- dump_dumpfve.sys Bitlocker Drive Encryption Crashdump Filter
- dump_storahci.sys MS AHCI Storport Miniport Driver
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- intelppm.sys Processor Device Driver (Microsoft)
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kd.dll Local Kernal Debugger (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate_GenuineIntel.dll Intel Microcode Update Library (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb10.sys Longhorn SMB Downlevel SubRdr (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndisuio.sys NDIS User mode I/O driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- NTFS.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- nwifi.sys NativeWiFi Miniport Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- qwavedrv.sys Quality Windows Audio Video Experience (qWave) Support driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- registry.sys Registry Container driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- serenum.sys Serial Port Enumerator (Microsoft)
- serial.sys Serial Device Driver
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv.sys Server driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- TSDDD.dll Framebuffer Display Driver (Microsoft)
- tunnel.sys Microsoft Tunnel Interface driver (Microsoft)
- ucx01000.sys USB Controller Extension (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- USBSTOR.SYS USB Mass Storage Class driver (Microsoft)
- USBXHCI.SYS USB XHCI Driver
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- vmbkmclr.sys Hyper-V VMBus Root KMCL (Microsoft)
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwifibus.sys Virtual Wireless Bus driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- vwifimp.sys Virtual WiFi Miniport Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- wcnfs.sys Windows Container Name Virtualization FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- wdiwifi.sys WDI Driver Framework Driver
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WpdUpFltr.sys Portable Device Upper Class Filter driver (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- WudfPf.sys Windows Driver Foundation - User-mode Driver Framework Platform driver (Microsoft)
- WUDFRd.sys Windows Driver Foundation - User-mode Driver Framework Reflector driver (Microsoft)
- Unloaded modules:
- fffff803`73d10000 fffff803`73d16000 GPCIDrv64.sy
- fffff803`73ca0000 fffff803`73cae000 vwifibus.sys
- fffff803`73640000 fffff803`73bdb000 rtwlanu.sys
- fffff803`73be0000 fffff803`73ca0000 wdiwifi.sys
- fffff803`73cb0000 fffff803`73cc1000 vwifimp.sys
- fffff803`72cc0000 fffff803`72cce000 vwifibus.sys
- fffff803`739e0000 fffff803`73f7b000 rtwlanu.sys
- fffff803`72c00000 fffff803`72cc0000 wdiwifi.sys
- fffff803`735b0000 fffff803`735c1000 vwifimp.sys
- fffff803`72d60000 fffff803`72d9d000 WUDFRd.sys
- fffff803`72d00000 fffff803`72d0b000 klpnpflt.sys
- fffff803`72bf0000 fffff803`72bfb000 cldflt.sys
- fffff803`56420000 fffff803`5642f000 dump_storpor
- fffff803`56460000 fffff803`56487000 dump_storahc
- fffff803`564b0000 fffff803`564cd000 dump_dumpfve
- fffff803`55240000 fffff803`5525c000 EhStorClass.
- fffff803`70520000 fffff803`7052b000 klpnpflt.sys
- fffff803`6ff10000 fffff803`6ff1b000 klpnpflt.sys
- fffff803`72ba0000 fffff803`72baa000 amdkmafd.sys
- fffff803`576f0000 fffff803`57710000 dam.sys
- fffff803`54e20000 fffff803`54e2c000 klelam.sys
- fffff803`56330000 fffff803`5633f000 hwpolicy.sys
- ========================================================================
- ============================== BIOS INFO ===============================
- ========================================================================
- [SMBIOS Data Tables v2.8]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 1655 bytes]
- [BIOS Information (Type 0) - Length 24 - Handle 0000h]
- Vendor American Megatrends Inc.
- BIOS Version P2.70
- BIOS Starting Address Segment f000
- BIOS Release Date 11/04/2015
- BIOS ROM Size e00000
- BIOS Characteristics
- 07: - PCI Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 27: - Keyboard Services Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 32: - BIOS Vendor Reserved
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 5
- BIOS Minor Revision 11
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
- Manufacturer ASRock
- Product Z170 Pro4S
- Version
- Feature Flags 09h
- Location
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 25 - Handle 0003h]
- Chassis Type Desktop
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 1
- Contained Element Size 3
- [OEM Strings (Type 11) - Length 5 - Handle 000ah]
- Number of Strings 1
- [Cache Information (Type 7) - Length 19 - Handle 000dh]
- Socket Designation L1 Cache
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0080h - 128K
- Installed Size 0080h - 128K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type ParitySingle-Bit ECC
- System Cache Type Data
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 000eh]
- Socket Designation L1 Cache
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0080h - 128K
- Installed Size 0080h - 128K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type ParitySingle-Bit ECC
- System Cache Type Instruction
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 000fh]
- Socket Designation L2 Cache
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 0400h - 1024K
- Installed Size 0400h - 1024K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Unified
- Associativity 4-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0010h]
- Socket Designation L3 Cache
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 1800h - 6144K
- Installed Size 1800h - 6144K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity Specification Reserved
- [Processor Information (Type 4) - Length 48 - Handle 0011h]
- Socket Designation CPUSocket
- Processor Type Central Processor
- Processor Family cdh - Specification Reserved
- Processor Manufacturer Intel(R) Corporation
- Processor ID e3060500fffbebbf
- Processor Version Intel(R) Core(TM) i5-6402P CPU @ 2.80GHz
- Processor Voltage 89h - 0.9V
- External Clock 100MHz
- Max Speed 5000MHz
- Current Speed 2800MHz
- Status Enabled Populated
- Processor Upgrade Other
- L1 Cache Handle 000eh
- L2 Cache Handle 000fh
- L3 Cache Handle 0010h
- [Physical Memory Array (Type 16) - Length 23 - Handle 0012h]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 67108864KB
- Number of Memory Devices 4
- [Memory Device (Type 17) - Length 40 - Handle 0013h]
- Physical Memory Array Handle 0012h
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM0
- Bank Locator BANK 0
- Memory Type 1ah - Specification Reserved
- Type Detail 0080h - Synchronous
- Speed 2133MHz
- Manufacturer 0793
- Part Number GR2133D464L15/8G
- [Memory Device (Type 17) - Length 40 - Handle 0014h]
- Physical Memory Array Handle 0012h
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM1
- Bank Locator BANK 1
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Device (Type 17) - Length 40 - Handle 0015h]
- Physical Memory Array Handle 0012h
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM0
- Bank Locator BANK 2
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Device (Type 17) - Length 40 - Handle 0016h]
- Physical Memory Array Handle 0012h
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM1
- Bank Locator BANK 3
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0017h]
- Starting Address 00000000h
- Ending Address 007fffffh
- Memory Array Handle 0012h
- Partition Width 01
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0018h]
- Starting Address 00000000h
- Ending Address 007fffffh
- Memory Device Handle 0013h
- Mem Array Mapped Adr Handle 0017h
- Partition Row Position 01
- Interleave Position 01
- Interleave Data Depth 01
Advertisement
Add Comment
Please, Sign In to add comment