Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- KEY_VALUES_STRING: 1
- Key : AV.Fault
- Value: Read
- Key : Analysis.CPU.mSec
- Value: 546
- Key : Analysis.Elapsed.mSec
- Value: 430
- Key : Analysis.IO.Other.Mb
- Value: 0
- Key : Analysis.IO.Read.Mb
- Value: 0
- Key : Analysis.IO.Write.Mb
- Value: 0
- Key : Analysis.Init.CPU.mSec
- Value: 218
- Key : Analysis.Init.Elapsed.mSec
- Value: 2229
- Key : Analysis.Memory.CommitPeak.Mb
- Value: 254
- Key : Failure.Bucket
- Value: INVALID_POINTER_READ_c0000005_Discovery.exe!______B____TvA___cQ_____8_N_______$___9_PL__HS___v__a__ie}__0_____^_p_xP_!
- Key : Failure.Hash
- Value: {08b9cfb2-6166-74e5-7e6a-fbc6adde7ba6}
- Key : Timeline.OS.Boot.DeltaSec
- Value: 465
- Key : Timeline.Process.Start.DeltaSec
- Value: 371
- Key : WER.OS.Branch
- Value: ni_release
- Key : WER.OS.Version
- Value: 10.0.22621.1
- Key : WER.Process.Version
- Value: 5.0.3.0
- FILE_IN_CAB: UEMinidump.dmp
- CONTEXT: (.ecxr)
- rax=4820ec8348535756 rbx=0000023ff2c6edc0 rcx=00007ff766457220
- rdx=0000023f2d415980 rsi=000000461cd7f380 rdi=0000023eb20f2c50
- rip=00007ff76642c743 rsp=000000461cd7f380 rbp=0000000000000028
- r8=0000000000000008 r9=00007fffcfd2141d r10=00007fffcfd20000
- r11=0000000000000000 r12=0000000000000000 r13=0000023e51736d28
- r14=0000000000000008 r15=000000461cd7f3a0
- iopl=0 nv up ei pl nz na pe nc
- cs=0033 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00010202
- $ ò=Á8ðþ…ß?¾ž«ƒ`œã ñÕÅu–¤Ï©³ï뿟c#®ªâ“ÕÑh,øä°!¨gƒ& ™éšˆŠQt9Ï6[Æè$f)Sº[ÈÚ=žÉ…¦]~¤“°?8x€‹‹Dì–F<W§ÙWFšT%xj]„«™üÑõ
- ÇâPì¹;àc;:çx¥¶(Ê^º¥½â)¡ý’û&ë˜}p¼ËácÆ#¡
- 9É8)<¹È3“?UÕ;kzk}I{ý¯zÍO;7€PÔÅÉcäT-‡¹,-&µ}H¦Ä®xA€Ý‚å=`ÄNR¡à[³<c¹‹húZûplæF;È«ÜÒfŠÄ™Â˜k‹«CÂb\š°£f.ª’³öÑ’ZhÑ{A¡M´*‹s8„̾O3üÂE¹+70í–üX‚–ɤ‚g
- ¬ÞûŒóòð¨é…—ò'ô´û`A÷÷Íl†€ìf`ƒœÖ¹’ØNöïÄÙX«yûɲz°ÂK•®ñш||²òÞˆ€â+VF’A–‹:ënu‡½+0x539c743:
- 00007ff7`6642c743 ff5008 call qword ptr [rax+8] ds:4820ec83`4853575e=????????????????
- Resetting default scope
- EXCEPTION_RECORD: (.exr -1)
- $ ò=Á8ðþ…ß?¾ž«ƒ`œã ñÕÅu–¤Ï©³ï뿟c#®ªâ“ÕÑh,øä°!¨gƒ& ™éšˆŠQt9Ï6[Æè$f)Sº[ÈÚ=žÉ…¦]~¤“°?8x€‹‹Dì–F<W§ÙWFšT%xj]„«™üÑõ
- ÇâPì¹;àc;:çx¥¶(Ê^º¥½â)¡ý’û&ë˜}p¼ËácÆ#¡
- 9É8)<¹È3“?UÕ;kzk}I{ý¯zÍO;7€PÔÅÉcäT-‡¹,-&µ}H¦Ä®xA€Ý‚å=`ÄNR¡à[³<c¹‹húZûplæF;È«ÜÒfŠÄ™Â˜k‹«CÂb\š°£f.ª’³öÑ’ZhÑ{A¡M´*‹s8„̾O3üÂE¹+70í–üX‚–ɤ‚g
- ¬ÞûŒóòð¨é…—ò'ô´û`A÷÷Íl†€ìf`ƒœÖ¹’ØNöïÄÙX«yûɲz°ÂK•®ñш||²òÞˆ€â+VF’A–‹:ënu‡½+0x000000000539c743)
- ExceptionCode: c0000005 (Access violation)
- ExceptionFlags: 00000000
- NumberParameters: 2
- Parameter[0]: 0000000000000000
- Parameter[1]: ffffffffffffffff
- Attempt to read from address ffffffffffffffff
- PROCESS_NAME: Discovery.exe
- READ_ADDRESS: ffffffffffffffff
- ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.
- EXCEPTION_CODE_STR: c0000005
- EXCEPTION_PARAMETER1: 0000000000000000
- EXCEPTION_PARAMETER2: ffffffffffffffff
- IP_ON_HEAP: 0000023e51736d28
- The fault address in not in any loaded module, please check your build's rebase
- log at <releasedir>\bin\build_logs\timebuild\ntrebase.log for module which may
- contain the address if it were loaded.
- FRAME_ONE_INVALID: 1
- STACK_TEXT:
- $ ò=Á8ðþ ß?¾«`ã ñÕÅu¤Ï©³ïë¿c#®ªâÕÑh,øä°!¨g& éQt9Ï6[Æè$f)Sº[ÈÚ=É ¦]~¤°?8xDìF<W§ÙWFT%xj]«üÑõ
- ÇâPì¹;àc;:çx¥¶(Ê^º¥½â)¡ýû&ë}p¼ËácÆ#¡
- 9É8)<¹È3?UÕ;kzk}I{ý¯zÍO;7PÔÅÉcäT-¹,-&µ}H¦Ä®xAÝå=`ÄNR¡à[³<c¹húZûplæF;È«ÜÒfÄÂk«CÂb\°£f.ª³öÑZhÑ{A¡M´*s8̾O3üÂE¹+70íüXɤg
- ¬Þûóòð¨é ò'ô´û`A÷÷Ílìf`Ö¹ØNöïÄÙX«yûòz°ÂK®ñÑ||²òÞâ+VFA:ënu½+0x539c743
- 00000046`1cd7f388 00000046`1cd7f420 : 00007ff7`66457220 00007ff7`66126868 0000023e`b20f2c50 00000002`00000001 : 0x0000023e`51736d28
- 00000046`1cd7f390 00007ff7`66457220 : 00007ff7`66126868 0000023e`b20f2c50 00000002`00000001 00000000`00000001 : 0x00000046`1cd7f420
- $ ò=Á8ðþ ß?¾«`ã ñÕÅu¤Ï©³ïë¿c#®ªâÕÑh,øä°!¨g& éQt9Ï6[Æè$f)Sº[ÈÚ=É ¦]~¤°?8xDìF<W§ÙWFT%xj]«üÑõ
- ÇâPì¹;àc;:çx¥¶(Ê^º¥½â)¡ýû&ë}p¼ËácÆ#¡
- 9É8)<¹È3?UÕ;kzk}I{ý¯zÍO;7PÔÅÉcäT-¹,-&µ}H¦Ä®xAÝå=`ÄNR¡à[³<c¹húZûplæF;È«ÜÒfÄÂk«CÂb\°£f.ª³öÑZhÑ{A¡M´*s8̾O3üÂE¹+70íüXɤg
- ¬Þûóòð¨é ò'ô´û`A÷÷Ílìf`Ö¹ØNöïÄÙX«yûòz°ÂK®ñÑ||²òÞâ+VFA:ënu½+0x53c7220
- $ ò=Á8ðþ ß?¾«`ã ñÕÅu¤Ï©³ïë¿c#®ªâÕÑh,øä°!¨g& éQt9Ï6[Æè$f)Sº[ÈÚ=É ¦]~¤°?8xDìF<W§ÙWFT%xj]«üÑõ
- ÇâPì¹;àc;:çx¥¶(Ê^º¥½â)¡ýû&ë}p¼ËácÆ#¡
- 9É8)<¹È3?UÕ;kzk}I{ý¯zÍO;7PÔÅÉcäT-¹,-&µ}H¦Ä®xAÝå=`ÄNR¡à[³<c¹húZûplæF;È«ÜÒfÄÂk«CÂb\°£f.ª³öÑZhÑ{A¡M´*s8̾O3üÂE¹+70íüXɤg
- ¬Þûóòð¨é ò'ô´û`A÷÷Ílìf`Ö¹ØNöïÄÙX«yûòz°ÂK®ñÑ||²òÞâ+VFA:ënu½+0x5096868
- 00000046`1cd7f3a8 00000002`00000001 : 00000000`00000001 00007ff7`644c026e 0000023e`28602b90 0000023e`28602b80 : 0x0000023e`b20f2c50
- 00000046`1cd7f3b0 00000000`00000001 : 00007ff7`644c026e 0000023e`28602b90 0000023e`28602b80 0000ad8c`e3d55f0f : 0x00000002`00000001
- 00000046`1cd7f3b8 00007ff7`644c026e : 0000023e`28602b90 0000023e`28602b80 0000ad8c`e3d55f0f 00007ff7`63a2ddc0 : 0x1
- $ ò=Á8ðþ ß?¾«`ã ñÕÅu¤Ï©³ïë¿c#®ªâÕÑh,øä°!¨g& éQt9Ï6[Æè$f)Sº[ÈÚ=É ¦]~¤°?8xDìF<W§ÙWFT%xj]«üÑõ
- ÇâPì¹;àc;:çx¥¶(Ê^º¥½â)¡ýû&ë}p¼ËácÆ#¡
- 9É8)<¹È3?UÕ;kzk}I{ý¯zÍO;7PÔÅÉcäT-¹,-&µ}H¦Ä®xAÝå=`ÄNR¡à[³<c¹húZûplæF;È«ÜÒfÄÂk«CÂb\°£f.ª³öÑZhÑ{A¡M´*s8̾O3üÂE¹+70íüXɤg
- ¬Þûóòð¨é ò'ô´û`A÷÷Ílìf`Ö¹ØNöïÄÙX«yûòz°ÂK®ñÑ||²òÞâ+VFA:ënu½+0x343026e
- 00000046`1cd7f3c8 0000023e`28602b80 : 0000ad8c`e3d55f0f 00007ff7`63a2ddc0 0000023e`6d63c3a0 0000023e`28602b80 : 0x0000023e`28602b90
- 00000046`1cd7f3d0 0000ad8c`e3d55f0f : 00007ff7`63a2ddc0 0000023e`6d63c3a0 0000023e`28602b80 0000023e`517360a0 : 0x0000023e`28602b80
- 00000046`1cd7f3d8 00007ff7`63a2ddc0 : 0000023e`6d63c3a0 0000023e`28602b80 0000023e`517360a0 00007ff7`6612c17d : 0x0000ad8c`e3d55f0f
- $ ò=Á8ðþ ß?¾«`ã ñÕÅu¤Ï©³ïë¿c#®ªâÕÑh,øä°!¨g& éQt9Ï6[Æè$f)Sº[ÈÚ=É ¦]~¤°?8xDìF<W§ÙWFT%xj]«üÑõ
- ÇâPì¹;àc;:çx¥¶(Ê^º¥½â)¡ýû&ë}p¼ËácÆ#¡
- 9É8)<¹È3?UÕ;kzk}I{ý¯zÍO;7PÔÅÉcäT-¹,-&µ}H¦Ä®xAÝå=`ÄNR¡à[³<c¹húZûplæF;È«ÜÒfÄÂk«CÂb\°£f.ª³öÑZhÑ{A¡M´*s8̾O3üÂE¹+70íüXɤg
- ¬Þûóòð¨é ò'ô´û`A÷÷Ílìf`Ö¹ØNöïÄÙX«yûòz°ÂK®ñÑ||²òÞâ+VFA:ënu½+0x299ddc0
- 00000046`1cd7f3e8 0000023e`28602b80 : 0000023e`517360a0 00007ff7`6612c17d 00000240`27a3d8f0 00007ff7`64477980 : 0x0000023e`6d63c3a0
- 00000046`1cd7f3f0 0000023e`517360a0 : 00007ff7`6612c17d 00000240`27a3d8f0 00007ff7`64477980 00000000`00000000 : 0x0000023e`28602b80
- 00000046`1cd7f3f8 00007ff7`6612c17d : 00000240`27a3d8f0 00007ff7`64477980 00000000`00000000 00007ff7`644740a8 : 0x0000023e`517360a0
- $ ò=Á8ðþ ß?¾«`ã ñÕÅu¤Ï©³ïë¿c#®ªâÕÑh,øä°!¨g& éQt9Ï6[Æè$f)Sº[ÈÚ=É ¦]~¤°?8xDìF<W§ÙWFT%xj]«üÑõ
- ÇâPì¹;àc;:çx¥¶(Ê^º¥½â)¡ýû&ë}p¼ËácÆ#¡
- 9É8)<¹È3?UÕ;kzk}I{ý¯zÍO;7PÔÅÉcäT-¹,-&µ}H¦Ä®xAÝå=`ÄNR¡à[³<c¹húZûplæF;È«ÜÒfÄÂk«CÂb\°£f.ª³öÑZhÑ{A¡M´*s8̾O3üÂE¹+70íüXɤg
- ¬Þûóòð¨é ò'ô´û`A÷÷Ílìf`Ö¹ØNöïÄÙX«yûòz°ÂK®ñÑ||²òÞâ+VFA:ënu½+0x509c17d
- 00000046`1cd7f408 00007ff7`64477980 : 00000000`00000000 00007ff7`644740a8 0000023e`28602b90 0000023e`28602b80 : 0x00000240`27a3d8f0
- $ ò=Á8ðþ ß?¾«`ã ñÕÅu¤Ï©³ïë¿c#®ªâÕÑh,øä°!¨g& éQt9Ï6[Æè$f)Sº[ÈÚ=É ¦]~¤°?8xDìF<W§ÙWFT%xj]«üÑõ
- ÇâPì¹;àc;:çx¥¶(Ê^º¥½â)¡ýû&ë}p¼ËácÆ#¡
- 9É8)<¹È3?UÕ;kzk}I{ý¯zÍO;7PÔÅÉcäT-¹,-&µ}H¦Ä®xAÝå=`ÄNR¡à[³<c¹húZûplæF;È«ÜÒfÄÂk«CÂb\°£f.ª³öÑZhÑ{A¡M´*s8̾O3üÂE¹+70íüXɤg
- ¬Þûóòð¨é ò'ô´û`A÷÷Ílìf`Ö¹ØNöïÄÙX«yûòz°ÂK®ñÑ||²òÞâ+VFA:ënu½+0x33e7980
- $ ò=Á8ðþ ß?¾«`ã ñÕÅu¤Ï©³ïë¿c#®ªâÕÑh,øä°!¨g& éQt9Ï6[Æè$f)Sº[ÈÚ=É ¦]~¤°?8xDìF<W§ÙWFT%xj]«üÑõ
- ÇâPì¹;àc;:çx¥¶(Ê^º¥½â)¡ýû&ë}p¼ËácÆ#¡
- 9É8)<¹È3?UÕ;kzk}I{ý¯zÍO;7PÔÅÉcäT-¹,-&µ}H¦Ä®xAÝå=`ÄNR¡à[³<c¹húZûplæF;È«ÜÒfÄÂk«CÂb\°£f.ª³öÑZhÑ{A¡M´*s8̾O3üÂE¹+70íüXɤg
- ¬Þûóòð¨é ò'ô´û`A÷÷Ílìf`Ö¹ØNöïÄÙX«yûòz°ÂK®ñÑ||²òÞâ+VF
- MODULE_NAME: Discovery
- IMAGE_NAME: Discovery.exe
- STACK_COMMAND: ~28s; .ecxr ; kb
- FAILURE_BUCKET_ID: INVALID_POINTER_READ_c0000005_Discovery.exe!______B____TvA___cQ_____8_N_______$___9_PL__HS___v__a__ie}__0_____^_p_xP_!_______
- OS_VERSION: 10.0.22621.1
- BUILDLAB_STR: ni_release
- OSPLATFORM_TYPE: x64
- OSNAME: Windows 10
- IMAGE_VERSION: 5.0.3.0
- FAILURE_ID_HASH: {08b9cfb2-6166-74e5-7e6a-fbc6adde7ba6}
- Followup: MachineOwner
- ---------
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement