Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ========================== AUTO DUMP ANALYZER ==========================
- Auto Dump Analyzer
- Version: 0.91
- Time to analyze file(s): 00 hours and 04 minutes and 40 seconds
- ================================= BIOS =================================
- VENDOR: American Megatrends Inc.
- VERSION: 5406
- DATE: 11/13/2019
- ============================= MOTHERBOARD ==============================
- MANUFACTURER: ASUSTeK COMPUTER INC.
- PRODUCT: ROG STRIX B350-F GAMING
- VERSION: Rev X.0x
- ================================= RAM ==================================
- Size Speed Manufacturer Part No.
- -------------- -------------- ------------------- ----------------------
- 8192MB 3200MHz Corsair CMW16GX4M2C3200C16
- 0MHz Unknown Unknown
- 8192MB 3200MHz Corsair CMW16GX4M2C3200C16
- 0MHz Unknown Unknown
- ================================= CPU ==================================
- Processor Version: AMD Ryzen 5 3600 6-Core Processor
- COUNT: c
- MHZ: 3593
- VENDOR: AuthenticAMD
- FAMILY: 17
- MODEL: 71
- STEPPING: 0
- ================================== OS ==================================
- Product: WinNt, suite: TerminalServer SingleUserTS Personal
- Built by: 18362.1.amd64fre.19h1_release.190318-1202
- BUILD_VERSION: 10.0.18362.959 (WinBuild.160101.0800)
- BUILD: 18362
- SERVICEPACK: 959
- PLATFORM_TYPE: x64
- NAME: Windows 10
- EDITION: Windows 10 WinNt TerminalServer SingleUserTS Personal
- BUILD_TIMESTAMP: unknown_date
- BUILDDATESTAMP: 160101.0800
- BUILDLAB: WinBuild
- BUILDOSVER: 10.0.18362.959
- =============================== DEBUGGER ===============================
- Microsoft (R) Windows Debugger Version 10.0.14321.1024 AMD64
- Copyright (c) Microsoft Corporation. All rights reserved.
- =============================== COMMENTS ===============================
- * Information gathered from different dump files may be different. If
- Windows updates between two dump files, two or more OS versions may
- be shown above.
- * If the user updates the BIOS between dump files, two or more versions
- and dates may be shown above.
- * More RAM information can be found below in a full BIOS section.
- ========================================================================
- ======================= Dump #1: ANALYZE VERBOSE =======================
- ====================== File: 072420-10109-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 18362 MP (12 procs) Free x64
- Kernel base = 0xfffff802`2d600000 PsLoadedModuleList = 0xfffff802`2da48190
- Debug session time: Fri Jul 24 12:08:20.867 2020 (UTC - 4:00)
- System Uptime: 0 days 4:32:05.525
- BugCheck 50, {fffffe55d4b62ab2, 10, fffffe55d4b62ab2, 2}
- *** WARNING: Unable to verify timestamp for win32kfull.sys
- *** ERROR: Module load completed but symbols could not be loaded for win32kfull.sys
- Could not read faulting driver name
- *** WARNING: Unable to verify timestamp for win32k.sys
- *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
- Probably caused by : memory_corruption
- Followup: memory_corruption
- PAGE_FAULT_IN_NONPAGED_AREA (50)
- Invalid system memory was referenced. This cannot be protected by try-except.
- Typically the address is just plain bad or it is pointing at freed memory.
- Arguments:
- Arg1: fffffe55d4b62ab2, memory referenced.
- Arg2: 0000000000000010, value 0 = read operation, 1 = write operation.
- Arg3: fffffe55d4b62ab2, If non-zero, the instruction address which referenced the bad memory
- address.
- Arg4: 0000000000000002, (reserved)
- Debugging Details:
- Could not read faulting driver name
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- READ_ADDRESS: fffff8022db733b8: Unable to get MiVisibleState
- fffffe55d4b62ab2
- FAULTING_IP:
- win32kfull+162ab2
- fffffe55`d4b62ab2 ?? ???
- MM_INTERNAL_CODE: 2
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- BUGCHECK_STR: AV
- PROCESS_NAME: Medal.exe
- CURRENT_IRQL: 0
- TRAP_FRAME: ffffa681cfd24f20 -- (.trap 0xffffa681cfd24f20)
- NOTE: The trap frame does not contain all registers.
- Some register values may be zeroed or incorrect.
- rax=0000000000000102 rbx=0000000000000000 rcx=418e234b086e0000
- rdx=000000007457624f rsi=0000000000000000 rdi=0000000000000000
- rip=fffffe55d4b62ab2 rsp=ffffa681cfd250b0 rbp=0000000000000001
- r8=0000000000000000 r9=fffff8022d600000 r10=0000fffff8022d73
- r11=ffffa681cfd24878 r12=0000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=0000000000000000
- iopl=0 nv up ei pl zr na po nc
- win32kfull+0x162ab2:
- fffffe55`d4b62ab2 ?? ???
- Resetting default scope
- LAST_CONTROL_TRANSFER: from fffff8022d7ecf0a to fffff8022d7c23c0
- FAILED_INSTRUCTION_ADDRESS:
- win32kfull+162ab2
- fffffe55`d4b62ab2 ?? ???
- STACK_TEXT:
- ffffa681`cfd24c78 fffff802`2d7ecf0a : 00000000`00000050 fffffe55`d4b62ab2 00000000`00000010 ffffa681`cfd24f20 : nt!KeBugCheckEx
- ffffa681`cfd24c80 fffff802`2d65875f : 00000000`00000000 00000000`00000010 00000000`00000000 fffffe55`d4b62ab2 : nt!MiSystemFault+0x1c5aaa
- ffffa681`cfd24d80 fffff802`2d7d041e : 00000000`00000001 00000000`00000003 00000000`00000001 00000000`00000000 : nt!MmAccessFault+0x34f
- ffffa681`cfd24f20 fffffe55`d4b62ab2 : 00000000`00000000 ffffe389`0bfab3f0 fffffe2e`02f0e920 ffffa681`cfd250d0 : nt!KiPageFault+0x35e
- ffffa681`cfd250b0 00000000`00000000 : ffffe389`0bfab3f0 fffffe2e`02f0e920 ffffa681`cfd250d0 ffffe389`130ea001 : win32kfull+0x162ab2
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
- fffff8022d65878b-fffff8022d65878f 5 bytes - nt!MmAccessFault+37b
- [ df be 7d fb f6:bf 71 e3 c6 8d ]
- fffff8022d6587b8-fffff8022d6587bc 5 bytes - nt!MmAccessFault+3a8 (+0x2d)
- [ d7 be 7d fb f6:b7 71 e3 c6 8d ]
- fffff8022d7ecfbf - nt!MiSystemFault+1c5b5f (+0x194807)
- [ f6:8d ]
- fffff8022d7ecfd5 - nt!MiSystemFault+1c5b75 (+0x16)
- [ f6:8d ]
- 12 errors : !nt (fffff8022d65878b-fffff8022d7ecfd5)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-07-24T16:08:20.000Z
- SUITE_MASK: 784
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #1: 3RD PARTY DRIVERS ======================
- Aug 22 2012 - AsIO.sys - ASUS Input Output driver http://www.asus.com/
- Mar 19 2015 - amd_sata.sys - AMD SATA Controller AHCI Device driver http://support.amd.com/
- Mar 19 2015 - amd_xata.sys - AMD Stor Filter driver http://support.amd.com/
- Mar 31 2015 - HWiNFO64A.SYS - HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
- Mar 14 2016 - amdgpio3.sys - AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Aug 02 2017 - Oculus_ViGEmBus.sys - Oculus Virtual Gamepad Emulation Bus driver
- Feb 12 2018 - msio64.sys - MSI Gaming App driver
- Mar 26 2019 - RTKVHD64.sys - Realtek Audio System driver https://www.realtek.com/en/
- Apr 09 2019 - AsIO2.sys - Asus Input Output driver
- Apr 22 2019 - GLCKIO2.sys - ASUS RGB driver
- Apr 22 2019 - OCULUSUD.sys - Oculus VR Headset driver
- Apr 25 2019 - mbae64.sys - Malwarebytes driver https://www.malwarebytes.com/
- Jun 06 2019 - IUProcessFilter.sys - IObit Uninstaller driver (IObit Information Technology)
- Sep 05 2019 - e1r65x64.sys - Intel(R) Gigabit Adapter NDIS 6.x driver https://downloadcenter.intel.com/
- Oct 14 2019 - ene.sys - (Ptolemy Tech Co.) or ASUS RGB driver or Gigabyte RGB driver
- Nov 06 2019 - IUFileFilter.sys - IObit Uninstaller driver (IObit)
- Nov 06 2019 - IURegistryFilter.sys - IObit Uninstaller driver (IObit Information Technology)
- Nov 15 2019 - AtihdWT6.sys - AMD High Definition Audio Function driver http://support.amd.com/
- Nov 20 2019 - mbamswissarmy.sys - MalwareBytes Anti-Malware system driver https://www.malwarebytes.com/
- Nov 27 2019 - teVirtualMIDI64.sys - teVirtualMIDI - Virtual MIDI driver (Tobias Erichsen)
- Dec 05 2019 - cpuz149_x64.sys - CPUID driver
- Jan 14 2020 - amdgpio2.sys - AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Jan 16 2020 - amdkmpfd.sys - AMD Kernel Miniport Filter driver
- Feb 10 2020 - bcmwl63a.sys - Broadcom 802 11 Network Adapter Wireless driver http://www.broadcom.com/support/
- Feb 12 2020 - HWiNFO64A_150.SYS - HWiNFO driver https://www.hwinfo.com/
- Feb 14 2020 - CorsairLLAccess64.sys - CORSAIR iCUE Software driver
- Mar 06 2020 - amdpsp.sys - Advanced Micro Devices, Inc http://support.amd.com/
- Mar 26 2020 - amdxe.sys - AMD Link Xinput Emulation driver
- Apr 10 2020 - AMDPCIDev.sys - Advanced Micro Devices PCI Device driver
- May 07 2020 - CorsairGamingAudio64.sys - Corsair Gaming Audio 64-bit driver
- May 25 2020 - amdkmdag.sys - AMD Graphics driver
- May 28 2020 - oculusvad.sys - Oculus VAD driver
- Jun 04 2020 - MbamChameleon.sys - Malwarebytes Anti-Malware Chameleon driver https://www.malwarebytes.com/
- Jun 09 2020 - amdlog.sys - AMD LOG driver
- Jun 22 2020 - mwac.sys - Malwarebytes Web Access Control http://www.malwarebytes.org/
- Jun 30 2020 - CorsairVBusDriver.sys - Corsair Virtual Device driver (Corsair Utility Engine) http://www.corsair.com/
- Jun 30 2020 - CorsairVHidDriver.sys - Corsair Virtual Device driver (Corsair Utility Engine) http://www.corsair.com/
- Jul 07 2020 - mbam.sys - Malwarebytes Anti-Malware https://www.malwarebytes.com/
- Jul 17 2020 - farflt.sys - Malwarebytes Anti-RansomWare SDK http://www.malwarebytes.org/
- ================== Dump #1: 3RD PARTY DRIVERS (FULL) ===================
- Image path: \SystemRoot\SysWow64\drivers\AsIO.sys
- Image name: AsIO.sys
- Search : https://www.google.com/search?q=AsIO.sys
- ADA Info : ASUS Input Output driver http://www.asus.com/
- Timestamp : Wed Aug 22 2012
- Image path: \SystemRoot\System32\drivers\amd_sata.sys
- Image name: amd_sata.sys
- Search : https://www.google.com/search?q=amd_sata.sys
- ADA Info : AMD SATA Controller AHCI Device driver http://support.amd.com/
- Timestamp : Thu Mar 19 2015
- Image path: \SystemRoot\System32\drivers\amd_xata.sys
- Image name: amd_xata.sys
- Search : https://www.google.com/search?q=amd_xata.sys
- ADA Info : AMD Stor Filter driver http://support.amd.com/
- Timestamp : Thu Mar 19 2015
- Image path: \??\C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS
- Image name: HWiNFO64A.SYS
- Search : https://www.google.com/search?q=HWiNFO64A.SYS
- ADA Info : HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
- Timestamp : Tue Mar 31 2015
- Image path: \SystemRoot\System32\drivers\amdgpio3.sys
- Image name: amdgpio3.sys
- Search : https://www.google.com/search?q=amdgpio3.sys
- ADA Info : AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Timestamp : Mon Mar 14 2016
- Image path: \SystemRoot\System32\drivers\Oculus_ViGEmBus.sys
- Image name: Oculus_ViGEmBus.sys
- Search : https://www.google.com/search?q=Oculus_ViGEmBus.sys
- ADA Info : Oculus Virtual Gamepad Emulation Bus driver
- Timestamp : Wed Aug 2 2017
- Image path: \??\C:\Program Files\Patriot\Aac_Patriot Viper RGB\msio64.sys
- Image name: msio64.sys
- Search : https://www.google.com/search?q=msio64.sys
- ADA Info : MSI Gaming App driver
- Timestamp : Mon Feb 12 2018
- Image path: \SystemRoot\system32\drivers\RTKVHD64.sys
- Image name: RTKVHD64.sys
- Search : https://www.google.com/search?q=RTKVHD64.sys
- ADA Info : Realtek Audio System driver https://www.realtek.com/en/
- Timestamp : Tue Mar 26 2019
- Image path: \??\C:\WINDOWS\system32\drivers\AsIO2.sys
- Image name: AsIO2.sys
- Search : https://www.google.com/search?q=AsIO2.sys
- ADA Info : Asus Input Output driver
- Timestamp : Tue Apr 9 2019
- Image path: \??\C:\WINDOWS\system32\drivers\GLCKIO2.sys
- Image name: GLCKIO2.sys
- Search : https://www.google.com/search?q=GLCKIO2.sys
- ADA Info : ASUS RGB driver
- Timestamp : Mon Apr 22 2019
- Image path: \SystemRoot\System32\drivers\OCULUSUD.sys
- Image name: OCULUSUD.sys
- Search : https://www.google.com/search?q=OCULUSUD.sys
- ADA Info : Oculus VR Headset driver
- Timestamp : Mon Apr 22 2019
- Image path: \??\C:\WINDOWS\system32\drivers\mbae64.sys
- Image name: mbae64.sys
- Search : https://www.google.com/search?q=mbae64.sys
- ADA Info : Malwarebytes driver https://www.malwarebytes.com/
- Timestamp : Thu Apr 25 2019
- Image path: \??\D:\Programs I want\IObit Uninstaller\drivers\win10_amd64\IUProcessFilter.sys
- Image name: IUProcessFilter.sys
- Search : https://www.google.com/search?q=IUProcessFilter.sys
- ADA Info : IObit Uninstaller driver (IObit Information Technology)
- Timestamp : Thu Jun 6 2019
- Image path: \SystemRoot\system32\DRIVERS\e1r65x64.sys
- Image name: e1r65x64.sys
- Search : https://www.google.com/search?q=e1r65x64.sys
- ADA Info : Intel(R) Gigabit Adapter NDIS 6.x driver https://downloadcenter.intel.com/
- Timestamp : Thu Sep 5 2019
- Image path: \??\C:\WINDOWS\system32\drivers\ene.sys
- Image name: ene.sys
- Search : https://www.google.com/search?q=ene.sys
- ADA Info : (Ptolemy Tech Co.) or ASUS RGB driver or Gigabyte RGB driver
- Timestamp : Mon Oct 14 2019
- Image path: \??\D:\Programs I want\IObit Uninstaller\drivers\win10_amd64\IUFileFilter.sys
- Image name: IUFileFilter.sys
- Search : https://www.google.com/search?q=IUFileFilter.sys
- ADA Info : IObit Uninstaller driver (IObit)
- Timestamp : Wed Nov 6 2019
- Image path: \??\D:\Programs I want\IObit Uninstaller\drivers\win10_amd64\IURegistryFilter.sys
- Image name: IURegistryFilter.sys
- Search : https://www.google.com/search?q=IURegistryFilter.sys
- ADA Info : IObit Uninstaller driver (IObit Information Technology)
- Timestamp : Wed Nov 6 2019
- Image path: \SystemRoot\system32\drivers\AtihdWT6.sys
- Image name: AtihdWT6.sys
- Search : https://www.google.com/search?q=AtihdWT6.sys
- ADA Info : AMD High Definition Audio Function driver http://support.amd.com/
- Timestamp : Fri Nov 15 2019
- Image path: \SystemRoot\System32\Drivers\mbamswissarmy.sys
- Image name: mbamswissarmy.sys
- Search : https://www.google.com/search?q=mbamswissarmy.sys
- ADA Info : MalwareBytes Anti-Malware system driver https://www.malwarebytes.com/
- Timestamp : Wed Nov 20 2019
- Image path: \SystemRoot\System32\drivers\teVirtualMIDI64.sys
- Image name: teVirtualMIDI64.sys
- Search : https://www.google.com/search?q=teVirtualMIDI64.sys
- ADA Info : teVirtualMIDI - Virtual MIDI driver (Tobias Erichsen)
- Timestamp : Wed Nov 27 2019
- Image path: \??\C:\WINDOWS\temp\cpuz149\cpuz149_x64.sys
- Image name: cpuz149_x64.sys
- Search : https://www.google.com/search?q=cpuz149_x64.sys
- ADA Info : CPUID driver
- Timestamp : Thu Dec 5 2019
- Image path: \SystemRoot\System32\drivers\amdgpio2.sys
- Image name: amdgpio2.sys
- Search : https://www.google.com/search?q=amdgpio2.sys
- ADA Info : AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Timestamp : Tue Jan 14 2020
- Image path: \SystemRoot\System32\drivers\amdkmpfd.sys
- Image name: amdkmpfd.sys
- Search : https://www.google.com/search?q=amdkmpfd.sys
- ADA Info : AMD Kernel Miniport Filter driver
- Timestamp : Thu Jan 16 2020
- Image path: \SystemRoot\system32\DRIVERS\bcmwl63a.sys
- Image name: bcmwl63a.sys
- Search : https://www.google.com/search?q=bcmwl63a.sys
- ADA Info : Broadcom 802 11 Network Adapter Wireless driver http://www.broadcom.com/support/
- Timestamp : Mon Feb 10 2020
- Image path: \??\C:\Users\andre\AppData\Local\Temp\HWiNFO64A_150.SYS
- Image name: HWiNFO64A_150.SYS
- Search : https://www.google.com/search?q=HWiNFO64A_150.SYS
- ADA Info : HWiNFO driver https://www.hwinfo.com/
- Timestamp : Wed Feb 12 2020
- Image path: \??\C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\CorsairLLAccess64.sys
- Image name: CorsairLLAccess64.sys
- Search : https://www.google.com/search?q=CorsairLLAccess64.sys
- ADA Info : CORSAIR iCUE Software driver
- Timestamp : Fri Feb 14 2020
- Image path: \SystemRoot\System32\drivers\amdpsp.sys
- Image name: amdpsp.sys
- Search : https://www.google.com/search?q=amdpsp.sys
- ADA Info : Advanced Micro Devices, Inc http://support.amd.com/
- Timestamp : Fri Mar 6 2020
- Image path: \SystemRoot\System32\drivers\amdxe.sys
- Image name: amdxe.sys
- Search : https://www.google.com/search?q=amdxe.sys
- ADA Info : AMD Link Xinput Emulation driver
- Timestamp : Thu Mar 26 2020
- Image path: \SystemRoot\System32\drivers\AMDPCIDev.sys
- Image name: AMDPCIDev.sys
- Search : https://www.google.com/search?q=AMDPCIDev.sys
- ADA Info : Advanced Micro Devices PCI Device driver
- Timestamp : Fri Apr 10 2020
- Image path: \SystemRoot\system32\DRIVERS\CorsairGamingAudio64.sys
- Image name: CorsairGamingAudio64.sys
- Search : https://www.google.com/search?q=CorsairGamingAudio64.sys
- ADA Info : Corsair Gaming Audio 64-bit driver
- Timestamp : Thu May 7 2020
- Image path: \SystemRoot\System32\DriverStore\FileRepository\u0356013.inf_amd64_61ba7b1fb4cf4aec\B355483\amdkmdag.sys
- Image name: amdkmdag.sys
- Search : https://www.google.com/search?q=amdkmdag.sys
- ADA Info : AMD Graphics driver
- Timestamp : Mon May 25 2020
- Image path: \SystemRoot\System32\drivers\oculusvad.sys
- Image name: oculusvad.sys
- Search : https://www.google.com/search?q=oculusvad.sys
- ADA Info : Oculus VAD driver
- Timestamp : Thu May 28 2020
- Image path: \SystemRoot\System32\Drivers\MbamChameleon.sys
- Image name: MbamChameleon.sys
- Search : https://www.google.com/search?q=MbamChameleon.sys
- ADA Info : Malwarebytes Anti-Malware Chameleon driver https://www.malwarebytes.com/
- Timestamp : Thu Jun 4 2020
- Image path: \SystemRoot\System32\drivers\amdlog.sys
- Image name: amdlog.sys
- Search : https://www.google.com/search?q=amdlog.sys
- ADA Info : AMD LOG driver
- Timestamp : Tue Jun 9 2020
- Image path: \SystemRoot\system32\DRIVERS\mwac.sys
- Image name: mwac.sys
- Search : https://www.google.com/search?q=mwac.sys
- ADA Info : Malwarebytes Web Access Control http://www.malwarebytes.org/
- Timestamp : Mon Jun 22 2020
- Image path: \SystemRoot\System32\drivers\CorsairVBusDriver.sys
- Image name: CorsairVBusDriver.sys
- Search : https://www.google.com/search?q=CorsairVBusDriver.sys
- ADA Info : Corsair Virtual Device driver (Corsair Utility Engine) http://www.corsair.com/
- Timestamp : Tue Jun 30 2020
- Image path: \SystemRoot\System32\drivers\CorsairVHidDriver.sys
- Image name: CorsairVHidDriver.sys
- Search : https://www.google.com/search?q=CorsairVHidDriver.sys
- ADA Info : Corsair Virtual Device driver (Corsair Utility Engine) http://www.corsair.com/
- Timestamp : Tue Jun 30 2020
- Image path: \??\C:\WINDOWS\system32\DRIVERS\mbam.sys
- Image name: mbam.sys
- Search : https://www.google.com/search?q=mbam.sys
- ADA Info : Malwarebytes Anti-Malware https://www.malwarebytes.com/
- Timestamp : Tue Jul 7 2020
- Image path: \SystemRoot\system32\DRIVERS\farflt.sys
- Image name: farflt.sys
- Search : https://www.google.com/search?q=farflt.sys
- ADA Info : Malwarebytes Anti-RansomWare SDK http://www.malwarebytes.org/
- Timestamp : Fri Jul 17 2020
- ====================== Dump #1: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- amdppm.sys Processor Device Driver
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_amd_sata.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kd.dll Local Kernal Debugger (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate_AuthenticAMD.dll AMD Microcode Update Library (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msgpioclx.sys GPIO Class Extension Driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- ndisuio.sys NDIS User mode I/O driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- nwifi.sys NativeWiFi Miniport Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- qwavedrv.sys Quality Windows Audio Video Experience (qWave) Support driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- serenum.sys Serial Port Enumerator (Microsoft)
- serial.sys Serial Device Driver
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- ucx01000.sys USB Controller Extension (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- usbser.sys USB Serial driver (Microsoft)
- usbvideo.sys USB Video Class Driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwifibus.sys Virtual Wireless Bus driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- vwifimp.sys Virtual WiFi Miniport Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- winquic.sys QUIC Transport Protocol driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- WSDPrint.sys Web Services Print Device driver (Microsoft)
- WSDScan.sys Web Service Based Scan Device driver (Microsoft)
- ====================== Dump #1: UNLOADED MODULES =======================
- fffff802`2acc0000 fffff802`2acce000 WSDScan.sys
- fffff802`2acb0000 fffff802`2acbe000 WSDPrint.sys
- fffff802`2aca0000 fffff802`2acae000 WSDScan.sys
- fffff802`2ac90000 fffff802`2ac9e000 WSDPrint.sys
- fffff802`2ac80000 fffff802`2ac8e000 WSDScan.sys
- fffff802`2ac70000 fffff802`2ac7e000 WSDPrint.sys
- fffff802`2ac60000 fffff802`2ac6e000 WSDScan.sys
- fffff802`2ac50000 fffff802`2ac5e000 WSDPrint.sys
- fffff802`2ac40000 fffff802`2ac4e000 WSDScan.sys
- fffff802`2ac30000 fffff802`2ac3e000 WSDPrint.sys
- fffff802`2ac20000 fffff802`2ac2e000 WSDScan.sys
- fffff802`2ac10000 fffff802`2ac1e000 WSDPrint.sys
- fffff802`2ac00000 fffff802`2ac0e000 WSDScan.sys
- fffff802`2abf0000 fffff802`2abfe000 WSDPrint.sys
- fffff802`2abe0000 fffff802`2abee000 WSDScan.sys
- fffff802`2abd0000 fffff802`2abde000 WSDPrint.sys
- fffff802`2abc0000 fffff802`2abce000 WSDScan.sys
- fffff802`2abb0000 fffff802`2abbe000 WSDPrint.sys
- fffff802`2aba0000 fffff802`2abae000 WSDScan.sys
- fffff802`2ab90000 fffff802`2ab9e000 WSDPrint.sys
- fffff802`2ab80000 fffff802`2ab8e000 WSDScan.sys
- fffff802`2ab70000 fffff802`2ab7e000 WSDPrint.sys
- fffff802`2ab60000 fffff802`2ab6e000 WSDScan.sys
- fffff802`2ab50000 fffff802`2ab5e000 WSDPrint.sys
- fffff802`2ab40000 fffff802`2ab4e000 WSDScan.sys
- fffff802`2ab30000 fffff802`2ab3e000 WSDPrint.sys
- fffff802`2ab20000 fffff802`2ab2e000 WSDScan.sys
- fffff802`2ab10000 fffff802`2ab1e000 WSDPrint.sys
- fffff802`2ab00000 fffff802`2ab0e000 WSDScan.sys
- fffff802`2aaf0000 fffff802`2aafe000 WSDPrint.sys
- fffff802`2aae0000 fffff802`2aaee000 WSDScan.sys
- fffff802`2aad0000 fffff802`2aade000 WSDPrint.sys
- fffff802`2aac0000 fffff802`2aace000 WSDScan.sys
- fffff802`2aab0000 fffff802`2aabe000 WSDPrint.sys
- fffff802`2aaa0000 fffff802`2aaae000 WSDScan.sys
- fffff802`2aa90000 fffff802`2aa9e000 WSDPrint.sys
- fffff802`2aa80000 fffff802`2aa8e000 WSDScan.sys
- fffff802`2aa70000 fffff802`2aa7e000 WSDPrint.sys
- fffff802`2aa60000 fffff802`2aa6e000 WSDScan.sys
- fffff802`2aa50000 fffff802`2aa5e000 WSDPrint.sys
- fffff802`2aa40000 fffff802`2aa4e000 WSDScan.sys
- fffff802`2aa30000 fffff802`2aa3e000 WSDPrint.sys
- fffff802`2aa20000 fffff802`2aa2e000 WSDScan.sys
- fffff802`2aa10000 fffff802`2aa1e000 WSDPrint.sys
- fffff802`2aa00000 fffff802`2aa0e000 WSDScan.sys
- fffff802`2a9f0000 fffff802`2a9fe000 WSDPrint.sys
- fffff802`2a9e0000 fffff802`2a9ee000 WSDScan.sys
- fffff802`2a9d0000 fffff802`2a9de000 WSDPrint.sys
- fffff802`2a9c0000 fffff802`2a9ce000 WSDScan.sys
- fffff802`2a9b0000 fffff802`2a9be000 WSDPrint.sys
- ====================== Dump #1: BIOS INFORMATION =======================
- [SMBIOS Data Tables v3.1]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 2505 bytes]
- [BIOS Information (Type 0) - Length 26 - Handle 0000h]
- Vendor American Megatrends Inc.
- BIOS Version 5406
- BIOS Starting Address Segment f000
- BIOS Release Date 11/13/2019
- BIOS ROM Size 1000000
- BIOS Characteristics
- 07: - PCI Supported
- 10: - APM Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 27: - Keyboard Services Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 32: - BIOS Vendor Reserved
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 5
- BIOS Minor Revision 13
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- Manufacturer System manufacturer
- Product Name System Product Name
- Version System Version
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- SKUNumber SKU
- [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
- Manufacturer ASUSTeK COMPUTER INC.
- Product ROG STRIX B350-F GAMING
- Version Rev X.0x
- Feature Flags 09h
- -863389984: - -863389936: - «
- ø
- Location Default string
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 22 - Handle 0003h]
- Manufacturer Default string
- Chassis Type Desktop
- Version Default string
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 3
- [Onboard Devices Information (Type 10) - Length 6 - Handle 0020h]
- Number of Devices 1
- 01: Type Video [enabled]
- [OEM Strings (Type 11) - Length 5 - Handle 0021h]
- Number of Strings 8
- 1 Default string
- 2 Default string
- 3 CHOPIN
- 4 Default string
- 5 FFFFFFFFFFFFF
- 6 FFFFFFFFFFFFF
- 7 FFFFFFFFFFFFF
- 8 Default string
- [System Configuration Options (Type 12) - Length 5 - Handle 0022h]
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 0026h]
- [Physical Memory Array (Type 16) - Length 23 - Handle 0027h]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 134217728KB
- Memory Error Inf Handle 0026h
- Number of Memory Devices 4
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0028h]
- Starting Address 00000000h
- Ending Address 0037ffffh
- Memory Array Handle 0027h
- Partition Width 02
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0029h]
- Starting Address 00400000h
- Ending Address 0107ffffh
- Memory Array Handle 0027h
- Partition Width 02
- [Cache Information (Type 7) - Length 19 - Handle 002ah]
- Socket Designation L1 - Cache
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0180h - 384K
- Installed Size 0180h - 384K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 002bh]
- Socket Designation L2 - Cache
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 0c00h - 3072K
- Installed Size 0c00h - 3072K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 002ch]
- Socket Designation L3 - Cache
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 8200h - 32768K
- Installed Size 8200h - 32768K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 16-way Set-Associative
- [Processor Information (Type 4) - Length 48 - Handle 002dh]
- Socket Designation AM4
- Processor Type Central Processor
- Processor Family 6bh - Specification Reserved
- Processor Manufacturer Advanced Micro Devices, Inc.
- Processor ID 100f8700fffb8b17
- Processor Version AMD Ryzen 5 3600 6-Core Processor
- Processor Voltage 8bh - 1.1V
- External Clock 100MHz
- Max Speed 4200MHz
- Current Speed 3600MHz
- Status Enabled Populated
- Processor Upgrade Specification Reserved
- L1 Cache Handle 002ah
- L2 Cache Handle 002bh
- L3 Cache Handle 002ch
- Part Number Unknown
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 002eh]
- [Memory Device (Type 17) - Length 40 - Handle 002fh]
- Physical Memory Array Handle 0027h
- Memory Error Info Handle 002eh
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator DIMM_A1
- Bank Locator BANK 0
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 3200MHz
- Manufacturer Corsair
- Part Number CMW16GX4M2C3200C16
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0030h]
- Starting Address 00000000h
- Ending Address 00ffffffh
- Memory Device Handle 002fh
- Mem Array Mapped Adr Handle 0029h
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 0031h]
- [Memory Device (Type 17) - Length 40 - Handle 0032h]
- Physical Memory Array Handle 0027h
- Memory Error Info Handle 0031h
- Form Factor 02h - Unknown
- Device Locator DIMM_A2
- Bank Locator BANK 1
- Memory Type 02h - Unknown
- Type Detail 0004h - Unknown
- Speed 0MHz
- Manufacturer Unknown
- Part Number Unknown
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 0033h]
- [Memory Device (Type 17) - Length 40 - Handle 0034h]
- Physical Memory Array Handle 0027h
- Memory Error Info Handle 0033h
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator DIMM_B1
- Bank Locator BANK 2
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 3200MHz
- Manufacturer Corsair
- Part Number CMW16GX4M2C3200C16
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0035h]
- Starting Address 00000000h
- Ending Address 00ffffffh
- Memory Device Handle 0034h
- Mem Array Mapped Adr Handle 0029h
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 0036h]
- [Memory Device (Type 17) - Length 40 - Handle 0037h]
- Physical Memory Array Handle 0027h
- Memory Error Info Handle 0036h
- Form Factor 02h - Unknown
- Device Locator DIMM_B2
- Bank Locator BANK 3
- Memory Type 02h - Unknown
- Type Detail 0004h - Unknown
- Speed 0MHz
- Manufacturer Unknown
- Part Number Unknown
- ========================== Dump #1: Extra #1 ===========================
- 9: kd> !verifier
- Verify Flags Level 0x00000000
- STANDARD FLAGS:
- [X] (0x00000000) Automatic Checks
- [ ] (0x00000001) Special pool
- [ ] (0x00000002) Force IRQL checking
- [ ] (0x00000008) Pool tracking
- [ ] (0x00000010) I/O verification
- [ ] (0x00000020) Deadlock detection
- [ ] (0x00000080) DMA checking
- [ ] (0x00000100) Security checks
- [ ] (0x00000800) Miscellaneous checks
- [ ] (0x00020000) DDI compliance checking
- ADDITIONAL FLAGS:
- [ ] (0x00000004) Randomized low resources simulation
- [ ] (0x00000200) Force pending I/O requests
- [ ] (0x00000400) IRP logging
- [ ] (0x00002000) Invariant MDL checking for stack
- [ ] (0x00004000) Invariant MDL checking for driver
- [ ] (0x00008000) Power framework delay fuzzing
- [ ] (0x00010000) Port/miniport interface checking
- [ ] (0x00040000) Systematic low resources simulation
- [ ] (0x00080000) DDI compliance checking (additional)
- [ ] (0x00200000) NDIS/WIFI verification
- [ ] (0x00800000) Kernel synchronization delay fuzzing
- [ ] (0x01000000) VM switch verification
- [ ] (0x02000000) Code integrity checks
- [X] Indicates flag is enabled
- Summary of All Verifier Statistics
- RaiseIrqls 0x0
- AcquireSpinLocks 0x0
- Synch Executions 0x0
- Trims 0x0
- Pool Allocations Attempted 0x0
- Pool Allocations Succeeded 0x0
- Pool Allocations Succeeded SpecialPool 0x0
- Pool Allocations With NO TAG 0x0
- Pool Allocations Failed 0x0
- Current paged pool allocations 0x0 for 00000000 bytes
- Peak paged pool allocations 0x0 for 00000000 bytes
- Current nonpaged pool allocations 0x0 for 00000000 bytes
- Peak nonpaged pool allocations 0x0 for 00000000 bytes
- ========================== Dump #1: Extra #2 ===========================
- 9: kd> !thread
- THREAD ffffe389130ea080 Cid 3278.3810 Teb: 0000008b8ff7e000 Win32Thread: ffffe3891318d1b0 RUNNING on processor 9
- Not impersonating
- GetUlongFromAddress: unable to read from fffff8022da2ca14
- Owning Process ffffe38911c650c0 Image: Medal.exe
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 1044833
- Context Switch Count 8468919 IdealProcessor: 8
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address 0x00007ff611ecf4d0
- Stack Init ffffa681cfd25c90 Current ffffa681cfd24700
- Base ffffa681cfd26000 Limit ffffa681cfd20000 Call 0000000000000000
- Priority 10 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- ffffa681`cfd24c78 fffff802`2d7ecf0a : 00000000`00000050 fffffe55`d4b62ab2 00000000`00000010 ffffa681`cfd24f20 : nt!KeBugCheckEx
- ffffa681`cfd24c80 fffff802`2d65875f : 00000000`00000000 00000000`00000010 00000000`00000000 fffffe55`d4b62ab2 : nt!MiSystemFault+0x1c5aaa
- ffffa681`cfd24d80 fffff802`2d7d041e : 00000000`00000001 00000000`00000003 00000000`00000001 00000000`00000000 : nt!MmAccessFault+0x34f
- ffffa681`cfd24f20 fffffe55`d4b62ab2 : 00000000`00000000 ffffe389`0bfab3f0 fffffe2e`02f0e920 ffffa681`cfd250d0 : nt!KiPageFault+0x35e (TrapFrame @ ffffa681`cfd24f20)
- ffffa681`cfd250b0 00000000`00000000 : ffffe389`0bfab3f0 fffffe2e`02f0e920 ffffa681`cfd250d0 ffffe389`130ea001 : win32kfull+0x162ab2
- ========================================================================
- ======================= Dump #2: ANALYZE VERBOSE =======================
- ======================= File: 072320-8546-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 18362 MP (12 procs) Free x64
- Kernel base = 0xfffff806`6960a000 PsLoadedModuleList = 0xfffff806`69a52190
- Debug session time: Thu Jul 23 08:11:42.974 2020 (UTC - 4:00)
- System Uptime: 0 days 0:00:06.705
- BugCheck C4, {62, ffffba08d72a4ab8, ffffba08d398c3e0, 1}
- *** ERROR: Module load completed but symbols could not be loaded for vgk.sys
- Probably caused by : memory_corruption
- Followup: memory_corruption
- DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
- A device driver attempting to corrupt the system has been caught. This is
- because the driver was specified in the registry as being suspect (by the
- administrator) and the kernel has enabled substantial checking of this driver.
- If the driver attempts to corrupt the system, bugchecks 0xC4, 0xC1 and 0xA will
- be among the most commonly seen crashes.
- Arguments:
- Arg1: 0000000000000062, A driver has forgotten to free its pool allocations prior to unloading.
- Arg2: ffffba08d72a4ab8, name of the driver having the issue.
- Arg3: ffffba08d398c3e0, verifier internal structure with driver information.
- Arg4: 0000000000000001, total # of (paged+nonpaged) allocations that weren't freed.
- Type !verifier 3 drivername.sys for info on the allocations
- that were leaked that caused the bugcheck.
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- BUGCHECK_STR: 0xc4_62
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- FAULTING_MODULE: fffff804ec3f0000 vgk
- VERIFIER_DRIVER_ENTRY: dt nt!_MI_VERIFIER_DRIVER_ENTRY ffffba08d398c3e0
- Symbol nt!_MI_VERIFIER_DRIVER_ENTRY not found.
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- PROCESS_NAME: System
- CURRENT_IRQL: 2
- LAST_CONTROL_TRANSFER: from fffff80669f7a6e3 to fffff806697cc3c0
- STACK_TEXT:
- ffff8689`8f806548 fffff806`69f7a6e3 : 00000000`000000c4 00000000`00000062 ffffba08`d72a4ab8 ffffba08`d398c3e0 : nt!KeBugCheckEx
- ffff8689`8f806550 fffff806`69f89492 : ffffba08`d398c3e0 ffff8689`8f806640 ffffba08`d72a48e0 ffffba08`d3984da0 : nt!VerifierBugCheckIfAppropriate+0xdf
- ffff8689`8f806590 fffff806`69879b66 : ffffba08`d398c3e0 00000000`ffffffff 00000000`00000001 fffff804`ec3f1000 : nt!VfPoolCheckForLeaks+0x46
- ffff8689`8f8065d0 fffff806`69f6c4be : 00000000`00518000 ffffba08`d72a48e0 fffff806`69a41c10 fffff806`69a41c10 : nt!VfTargetDriversRemove+0xf2516
- ffff8689`8f806650 fffff806`69c70ad3 : ffffba08`d72a48e0 ffff8689`8f806780 ffffa40a`994edcc0 ffffba08`d72a48e0 : nt!VfDriverUnloadImage+0x3e
- ffff8689`8f806680 fffff806`69d50930 : 00000000`00000518 00000000`ffffffff ffffa40a`994edcc0 fffff77c`02761f80 : nt!MiUnloadSystemImage+0x38b
- ffff8689`8f806810 fffff806`69d8d450 : ffffba08`d726ad80 fffff806`69722d6e ffffba08`d726ad80 ffffba08`d726adb0 : nt!MmUnloadSystemImage+0x20
- ffff8689`8f806840 fffff806`69c22910 : ffffba08`d726ad80 00000000`00000000 00000000`00000000 ffff8689`8f8068b0 : nt!IopDeleteDriver+0x40
- ffff8689`8f806890 fffff806`696ab024 : 00000000`00000000 00000000`00000000 ffff8689`8f806a30 ffffba08`d726adb0 : nt!ObpRemoveObjectRoutine+0x80
- ffff8689`8f8068f0 fffff806`69d035bc : 00000000`00000000 ffffba08`d726adb0 ffffba08`c0000365 ffffffff`800001d8 : nt!ObfDereferenceObject+0xa4
- ffff8689`8f806930 fffff806`6a01bf91 : ffffba08`d398f150 ffffba08`d398f150 ffff8689`8f806b80 00000000`00000000 : nt!IopLoadDriver+0x710
- ffff8689`8f806b10 fffff806`6a01b182 : fffff806`c0000365 ffffa40a`99c28fc0 00000000`00000000 fffff806`67fb9330 : nt!IopInitializeSystemDrivers+0x151
- ffff8689`8f806bb0 fffff806`69d62b62 : fffff806`67fb9330 fffff806`67fb9330 fffff806`69d62b20 fffff806`67fb9330 : nt!IoInitSystem+0x12
- ffff8689`8f806be0 fffff806`69728155 : ffffba08`cfabe040 fffff806`69d62b20 fffff806`67fb9330 00000000`00000000 : nt!Phase1Initialization+0x42
- ffff8689`8f806c10 fffff806`697d39c8 : fffff806`6836a180 ffffba08`cfabe040 fffff806`69728100 00000000`00000000 : nt!PspSystemThreadStartup+0x55
- ffff8689`8f806c60 00000000`00000000 : ffff8689`8f807000 ffff8689`8f801000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
- fffff80669d62b2f-fffff80669d62b30 2 bytes - nt!Phase1Initialization+f
- [ 48 ff:4c 8b ]
- fffff80669d62b36-fffff80669d62b3a 5 bytes - nt!Phase1Initialization+16 (+0x07)
- [ 0f 1f 44 00 00:e8 e5 b8 bf ff ]
- 7 errors : !nt (fffff80669d62b2f-fffff80669d62b3a)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-07-23T12:11:42.000Z
- SUITE_MASK: 784
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #2: 3RD PARTY DRIVERS ======================
- Mar 19 2015 - amd_sata.sys - AMD SATA Controller AHCI Device driver http://support.amd.com/
- Mar 19 2015 - amd_xata.sys - AMD Stor Filter driver http://support.amd.com/
- Nov 20 2019 - mbamswissarmy.sys - MalwareBytes Anti-Malware system driver https://www.malwarebytes.com/
- Jan 16 2020 - amdkmpfd.sys - AMD Kernel Miniport Filter driver
- Mar 06 2020 - amdpsp.sys - Advanced Micro Devices, Inc http://support.amd.com/
- Jun 29 2020 - vgk.sys - Vanguard Anti-Cheat driver
- ================== Dump #2: 3RD PARTY DRIVERS (FULL) ===================
- Image path: \SystemRoot\System32\drivers\amd_sata.sys
- Image name: amd_sata.sys
- Search : https://www.google.com/search?q=amd_sata.sys
- ADA Info : AMD SATA Controller AHCI Device driver http://support.amd.com/
- Timestamp : Thu Mar 19 2015
- Image path: \SystemRoot\System32\drivers\amd_xata.sys
- Image name: amd_xata.sys
- Search : https://www.google.com/search?q=amd_xata.sys
- ADA Info : AMD Stor Filter driver http://support.amd.com/
- Timestamp : Thu Mar 19 2015
- Image path: \SystemRoot\System32\Drivers\mbamswissarmy.sys
- Image name: mbamswissarmy.sys
- Search : https://www.google.com/search?q=mbamswissarmy.sys
- ADA Info : MalwareBytes Anti-Malware system driver https://www.malwarebytes.com/
- Timestamp : Wed Nov 20 2019
- Image path: \SystemRoot\System32\drivers\amdkmpfd.sys
- Image name: amdkmpfd.sys
- Search : https://www.google.com/search?q=amdkmpfd.sys
- ADA Info : AMD Kernel Miniport Filter driver
- Timestamp : Thu Jan 16 2020
- Image path: \SystemRoot\System32\drivers\amdpsp.sys
- Image name: amdpsp.sys
- Search : https://www.google.com/search?q=amdpsp.sys
- ADA Info : Advanced Micro Devices, Inc http://support.amd.com/
- Timestamp : Fri Mar 6 2020
- Image path: \??\C:\Program Files\Riot Vanguard\vgk.sys
- Image name: vgk.sys
- Search : https://www.google.com/search?q=vgk.sys
- ADA Info : Vanguard Anti-Cheat driver
- Timestamp : Mon Jun 29 2020
- ====================== Dump #2: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- dump_amd_sata.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- iorate.sys I/O rate control Filter (Microsoft)
- kd.dll Local Kernal Debugger (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- mcupdate_AuthenticAMD.dll AMD Microcode Update Library (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- VerifierExt.sys Driver Verifier Extension
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- ====================== Dump #2: UNLOADED MODULES =======================
- fffff806`6aa30000 fffff806`6aa41000 WdBoot.sys
- fffff806`6aa20000 fffff806`6aa29000 MbamElam.sys
- fffff806`6bb50000 fffff806`6bb61000 hwpolicy.sys
- ====================== Dump #2: BIOS INFORMATION =======================
- sysinfo: could not find necessary interfaces.
- sysinfo: note that mssmbios.sys must be loaded (XPSP2+).
- ========================== Dump #2: Extra #1 ===========================
- 11: kd> !verifier
- Verify Flags Level 0x001209bb
- STANDARD FLAGS:
- [X] (0x00000000) Automatic Checks
- [X] (0x00000001) Special pool
- [X] (0x00000002) Force IRQL checking
- [X] (0x00000008) Pool tracking
- [X] (0x00000010) I/O verification
- [X] (0x00000020) Deadlock detection
- [X] (0x00000080) DMA checking
- [X] (0x00000100) Security checks
- [X] (0x00000800) Miscellaneous checks
- [X] (0x00020000) DDI compliance checking
- ADDITIONAL FLAGS:
- [ ] (0x00000004) Randomized low resources simulation
- [ ] (0x00000200) Force pending I/O requests
- [ ] (0x00000400) IRP logging
- [ ] (0x00002000) Invariant MDL checking for stack
- [ ] (0x00004000) Invariant MDL checking for driver
- [ ] (0x00008000) Power framework delay fuzzing
- [ ] (0x00010000) Port/miniport interface checking
- [ ] (0x00040000) Systematic low resources simulation
- [ ] (0x00080000) DDI compliance checking (additional)
- [ ] (0x00200000) NDIS/WIFI verification
- [ ] (0x00800000) Kernel synchronization delay fuzzing
- [ ] (0x01000000) VM switch verification
- [ ] (0x02000000) Code integrity checks
- RESERVED FLAGS (use of these flags is unsupported):
- [X] (0x00100000) Unused or reserved flag
- [X] Indicates flag is enabled
- Summary of All Verifier Statistics
- RaiseIrqls 0xace6
- AcquireSpinLocks 0x2d111
- Synch Executions 0x4
- Trims 0xf3a
- Pool Allocations Attempted 0x1c846
- Pool Allocations Succeeded 0x1c846
- Pool Allocations Succeeded SpecialPool 0x1c846
- Pool Allocations With NO TAG 0x9
- Pool Allocations Failed 0x0
- Current paged pool allocations 0x651 for 0019FBAB bytes
- Peak paged pool allocations 0x722 for 001E2357 bytes
- Current nonpaged pool allocations 0x1889 for 00D454AC bytes
- Peak nonpaged pool allocations 0x1895 for 023709CC bytes
- ========================== Dump #2: Extra #2 ===========================
- 11: kd> !thread
- THREAD ffffba08cfabe040 Cid 0004.0008 Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor b
- Not impersonating
- GetUlongFromAddress: unable to read from fffff80669a36a14
- Owning Process ffffba08cfa91040 Image: System
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 429
- Context Switch Count 814 IdealProcessor: 11
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address nt!Phase1Initialization (0xfffff80669d62b20)
- Stack Init ffff86898f806c90 Current ffff86898f806310
- Base ffff86898f807000 Limit ffff86898f801000 Call 0000000000000000
- Priority 31 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- ffff8689`8f806548 fffff806`69f7a6e3 : 00000000`000000c4 00000000`00000062 ffffba08`d72a4ab8 ffffba08`d398c3e0 : nt!KeBugCheckEx
- ffff8689`8f806550 fffff806`69f89492 : ffffba08`d398c3e0 ffff8689`8f806640 ffffba08`d72a48e0 ffffba08`d3984da0 : nt!VerifierBugCheckIfAppropriate+0xdf
- ffff8689`8f806590 fffff806`69879b66 : ffffba08`d398c3e0 00000000`ffffffff 00000000`00000001 fffff804`ec3f1000 : nt!VfPoolCheckForLeaks+0x46
- ffff8689`8f8065d0 fffff806`69f6c4be : 00000000`00518000 ffffba08`d72a48e0 fffff806`69a41c10 fffff806`69a41c10 : nt!VfTargetDriversRemove+0xf2516
- ffff8689`8f806650 fffff806`69c70ad3 : ffffba08`d72a48e0 ffff8689`8f806780 ffffa40a`994edcc0 ffffba08`d72a48e0 : nt!VfDriverUnloadImage+0x3e
- ffff8689`8f806680 fffff806`69d50930 : 00000000`00000518 00000000`ffffffff ffffa40a`994edcc0 fffff77c`02761f80 : nt!MiUnloadSystemImage+0x38b
- ffff8689`8f806810 fffff806`69d8d450 : ffffba08`d726ad80 fffff806`69722d6e ffffba08`d726ad80 ffffba08`d726adb0 : nt!MmUnloadSystemImage+0x20
- ffff8689`8f806840 fffff806`69c22910 : ffffba08`d726ad80 00000000`00000000 00000000`00000000 ffff8689`8f8068b0 : nt!IopDeleteDriver+0x40
- ffff8689`8f806890 fffff806`696ab024 : 00000000`00000000 00000000`00000000 ffff8689`8f806a30 ffffba08`d726adb0 : nt!ObpRemoveObjectRoutine+0x80
- ffff8689`8f8068f0 fffff806`69d035bc : 00000000`00000000 ffffba08`d726adb0 ffffba08`c0000365 ffffffff`800001d8 : nt!ObfDereferenceObject+0xa4
- ffff8689`8f806930 fffff806`6a01bf91 : ffffba08`d398f150 ffffba08`d398f150 ffff8689`8f806b80 00000000`00000000 : nt!IopLoadDriver+0x710
- ffff8689`8f806b10 fffff806`6a01b182 : fffff806`c0000365 ffffa40a`99c28fc0 00000000`00000000 fffff806`67fb9330 : nt!IopInitializeSystemDrivers+0x151
- ffff8689`8f806bb0 fffff806`69d62b62 : fffff806`67fb9330 fffff806`67fb9330 fffff806`69d62b20 fffff806`67fb9330 : nt!IoInitSystem+0x12
- ffff8689`8f806be0 fffff806`69728155 : ffffba08`cfabe040 fffff806`69d62b20 fffff806`67fb9330 00000000`00000000 : nt!Phase1Initialization+0x42
- ffff8689`8f806c10 fffff806`697d39c8 : fffff806`6836a180 ffffba08`cfabe040 fffff806`69728100 00000000`00000000 : nt!PspSystemThreadStartup+0x55
- ffff8689`8f806c60 00000000`00000000 : ffff8689`8f807000 ffff8689`8f801000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
- ========================================================================
- ======================= Dump #3: ANALYZE VERBOSE =======================
- ====================== File: 072320-10656-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 18362 MP (12 procs) Free x64
- Kernel base = 0xfffff800`406a5000 PsLoadedModuleList = 0xfffff800`40aed190
- Debug session time: Thu Jul 23 09:19:29.302 2020 (UTC - 4:00)
- System Uptime: 0 days 0:00:06.033
- BugCheck C4, {62, ffff9a8ad3676d98, ffff9a8acecfe640, 1}
- *** ERROR: Module load completed but symbols could not be loaded for vgk.sys
- Probably caused by : memory_corruption
- Followup: memory_corruption
- DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
- A device driver attempting to corrupt the system has been caught. This is
- because the driver was specified in the registry as being suspect (by the
- administrator) and the kernel has enabled substantial checking of this driver.
- If the driver attempts to corrupt the system, bugchecks 0xC4, 0xC1 and 0xA will
- be among the most commonly seen crashes.
- Arguments:
- Arg1: 0000000000000062, A driver has forgotten to free its pool allocations prior to unloading.
- Arg2: ffff9a8ad3676d98, name of the driver having the issue.
- Arg3: ffff9a8acecfe640, verifier internal structure with driver information.
- Arg4: 0000000000000001, total # of (paged+nonpaged) allocations that weren't freed.
- Type !verifier 3 drivername.sys for info on the allocations
- that were leaked that caused the bugcheck.
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- BUGCHECK_STR: 0xc4_62
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- FAULTING_MODULE: fffff80d8ce00000 vgk
- VERIFIER_DRIVER_ENTRY: dt nt!_MI_VERIFIER_DRIVER_ENTRY ffff9a8acecfe640
- Symbol nt!_MI_VERIFIER_DRIVER_ENTRY not found.
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- PROCESS_NAME: System
- CURRENT_IRQL: 2
- LAST_CONTROL_TRANSFER: from fffff800410156e3 to fffff800408673c0
- STACK_TEXT:
- ffffd18b`d6806548 fffff800`410156e3 : 00000000`000000c4 00000000`00000062 ffff9a8a`d3676d98 ffff9a8a`cecfe640 : nt!KeBugCheckEx
- ffffd18b`d6806550 fffff800`41024492 : ffff9a8a`cecfe640 ffffd18b`d6806640 ffff9a8a`d3676bc0 ffff9a8a`cf36b320 : nt!VerifierBugCheckIfAppropriate+0xdf
- ffffd18b`d6806590 fffff800`40914b66 : ffff9a8a`cecfe640 00000000`ffffffff 00000000`00000001 fffff80d`8ce01000 : nt!VfPoolCheckForLeaks+0x46
- ffffd18b`d68065d0 fffff800`410074be : 00000000`00518000 ffff9a8a`d3676bc0 fffff800`40adcc10 fffff800`40adcc10 : nt!VfTargetDriversRemove+0xf2516
- ffffd18b`d6806650 fffff800`40d0bad3 : ffff9a8a`d3676bc0 ffffd18b`d6806780 ffffc189`a56edf40 ffff9a8a`d3676bc0 : nt!VfDriverUnloadImage+0x3e
- ffffd18b`d6806680 fffff800`40deb930 : 00000000`00000518 00000000`ffffffff ffffc189`a56edf40 fffff9fc`06c67000 : nt!MiUnloadSystemImage+0x38b
- ffffd18b`d6806810 fffff800`40e28450 : ffff9a8a`d36ebc40 fffff800`407bdd6e ffff9a8a`d36ebc40 ffff9a8a`d36ebc70 : nt!MmUnloadSystemImage+0x20
- ffffd18b`d6806840 fffff800`40cbd910 : ffff9a8a`d36ebc40 00000000`00000000 00000000`00000000 ffffd18b`d68068b0 : nt!IopDeleteDriver+0x40
- ffffd18b`d6806890 fffff800`40746024 : 00000000`00000000 00000000`00000000 ffffd18b`d6806a30 ffff9a8a`d36ebc70 : nt!ObpRemoveObjectRoutine+0x80
- ffffd18b`d68068f0 fffff800`40d9e5bc : 00000000`00000000 ffff9a8a`d36ebc70 ffff9a8a`c0000365 ffffffff`800001d4 : nt!ObfDereferenceObject+0xa4
- ffffd18b`d6806930 fffff800`410b6f91 : ffff9a8a`d37c55a0 ffff9a8a`d37c55a0 ffffd18b`d6806b80 00000000`00000000 : nt!IopLoadDriver+0x710
- ffffd18b`d6806b10 fffff800`410b6182 : fffff800`c0000365 ffffc189`a5e24fc0 00000000`00000000 fffff800`3f03f330 : nt!IopInitializeSystemDrivers+0x151
- ffffd18b`d6806bb0 fffff800`40dfdb62 : fffff800`3f03f330 fffff800`3f03f330 fffff800`40dfdb20 fffff800`3f03f330 : nt!IoInitSystem+0x12
- ffffd18b`d6806be0 fffff800`407c3155 : ffff9a8a`cc48a300 fffff800`40dfdb20 fffff800`3f03f330 eec624b2`e28624b6 : nt!Phase1Initialization+0x42
- ffffd18b`d6806c10 fffff800`4086e9c8 : fffff800`3f3f0180 ffff9a8a`cc48a300 fffff800`407c3100 cefe0170`c2be0174 : nt!PspSystemThreadStartup+0x55
- ffffd18b`d6806c60 00000000`00000000 : ffffd18b`d6807000 ffffd18b`d6801000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !hal
- fffff80040621465-fffff8004062146a 6 bytes - hal!HalpIommuAllocateDmaDomain+10189
- [ ff 15 a5 94 05 00:e8 36 7e 3d 00 90 ]
- fffff800406214e9-fffff800406214ee 6 bytes - hal!HalpIommuEnableInterrupts+10169 (+0x84)
- [ ff 15 21 94 05 00:e8 b2 7d 3d 00 90 ]
- fffff8004063cf7e-fffff8004063cf7f 2 bytes - hal!HalpIommuGetHardwareDomain+14e (+0x1ba95)
- [ 48 ff:4c 8b ]
- fffff8004063cf85-fffff8004063cf88 4 bytes - hal!HalpIommuGetHardwareDomain+155 (+0x07)
- [ 0f 1f 44 00:e8 96 c4 3b ]
- fffff8004063d88b-fffff8004063d88c 2 bytes - hal!HalpIommuAcquireNewDomain+57 (+0x906)
- [ 48 ff:4c 8b ]
- fffff8004063d892-fffff8004063d895 4 bytes - hal!HalpIommuAcquireNewDomain+5e (+0x07)
- [ 0f 1f 44 00:e8 89 bb 3b ]
- fffff8004063d8bc-fffff8004063d8c1 6 bytes - hal!HalpIommuAcquireNewDomain+88 (+0x2a)
- [ ff 15 4e d0 03 00:e8 df b9 3b 00 90 ]
- fffff8004063d8ca-fffff8004063d8cb 2 bytes - hal!HalpIommuAcquireNewDomain+96 (+0x0e)
- [ 48 ff:4c 8b ]
- fffff8004063d8d1-fffff8004063d8d4 4 bytes - hal!HalpIommuAcquireNewDomain+9d (+0x07)
- [ 0f 1f 44 00:e8 4a bb 3b ]
- fffff8004063d91b-fffff8004063d920 6 bytes - hal!HalpIommuAttachDeviceDomain+1f (+0x4a)
- [ ff 15 ef cf 03 00:e8 80 b9 3b 00 90 ]
- 42 errors : !hal (fffff80040621465-fffff8004063d920)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-07-23T13:19:29.000Z
- SUITE_MASK: 784
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #3: 3RD PARTY DRIVERS ======================
- Mar 19 2015 - amd_sata.sys - AMD SATA Controller AHCI Device driver http://support.amd.com/
- Mar 19 2015 - amd_xata.sys - AMD Stor Filter driver http://support.amd.com/
- Nov 20 2019 - mbamswissarmy.sys - MalwareBytes Anti-Malware system driver https://www.malwarebytes.com/
- Jan 16 2020 - amdkmpfd.sys - AMD Kernel Miniport Filter driver
- Mar 06 2020 - amdpsp.sys - Advanced Micro Devices, Inc http://support.amd.com/
- Jun 29 2020 - vgk.sys - Vanguard Anti-Cheat driver
- ================== Dump #3: 3RD PARTY DRIVERS (FULL) ===================
- Image path: \SystemRoot\System32\drivers\amd_sata.sys
- Image name: amd_sata.sys
- Search : https://www.google.com/search?q=amd_sata.sys
- ADA Info : AMD SATA Controller AHCI Device driver http://support.amd.com/
- Timestamp : Thu Mar 19 2015
- Image path: \SystemRoot\System32\drivers\amd_xata.sys
- Image name: amd_xata.sys
- Search : https://www.google.com/search?q=amd_xata.sys
- ADA Info : AMD Stor Filter driver http://support.amd.com/
- Timestamp : Thu Mar 19 2015
- Image path: \SystemRoot\System32\Drivers\mbamswissarmy.sys
- Image name: mbamswissarmy.sys
- Search : https://www.google.com/search?q=mbamswissarmy.sys
- ADA Info : MalwareBytes Anti-Malware system driver https://www.malwarebytes.com/
- Timestamp : Wed Nov 20 2019
- Image path: \SystemRoot\System32\drivers\amdkmpfd.sys
- Image name: amdkmpfd.sys
- Search : https://www.google.com/search?q=amdkmpfd.sys
- ADA Info : AMD Kernel Miniport Filter driver
- Timestamp : Thu Jan 16 2020
- Image path: \SystemRoot\System32\drivers\amdpsp.sys
- Image name: amdpsp.sys
- Search : https://www.google.com/search?q=amdpsp.sys
- ADA Info : Advanced Micro Devices, Inc http://support.amd.com/
- Timestamp : Fri Mar 6 2020
- Image path: \??\C:\Program Files\Riot Vanguard\vgk.sys
- Image name: vgk.sys
- Search : https://www.google.com/search?q=vgk.sys
- ADA Info : Vanguard Anti-Cheat driver
- Timestamp : Mon Jun 29 2020
- ====================== Dump #3: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- dump_amd_sata.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- iorate.sys I/O rate control Filter (Microsoft)
- kd.dll Local Kernal Debugger (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- mcupdate_AuthenticAMD.dll AMD Microcode Update Library (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- VerifierExt.sys Driver Verifier Extension
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- ====================== Dump #3: UNLOADED MODULES =======================
- fffff800`41960000 fffff800`41971000 WdBoot.sys
- fffff800`41950000 fffff800`41959000 MbamElam.sys
- fffff800`42b50000 fffff800`42b61000 hwpolicy.sys
- ====================== Dump #3: BIOS INFORMATION =======================
- sysinfo: could not find necessary interfaces.
- sysinfo: note that mssmbios.sys must be loaded (XPSP2+).
- ========================== Dump #3: Extra #1 ===========================
- 11: kd> !verifier
- Verify Flags Level 0x001209bb
- STANDARD FLAGS:
- [X] (0x00000000) Automatic Checks
- [X] (0x00000001) Special pool
- [X] (0x00000002) Force IRQL checking
- [X] (0x00000008) Pool tracking
- [X] (0x00000010) I/O verification
- [X] (0x00000020) Deadlock detection
- [X] (0x00000080) DMA checking
- [X] (0x00000100) Security checks
- [X] (0x00000800) Miscellaneous checks
- [X] (0x00020000) DDI compliance checking
- ADDITIONAL FLAGS:
- [ ] (0x00000004) Randomized low resources simulation
- [ ] (0x00000200) Force pending I/O requests
- [ ] (0x00000400) IRP logging
- [ ] (0x00002000) Invariant MDL checking for stack
- [ ] (0x00004000) Invariant MDL checking for driver
- [ ] (0x00008000) Power framework delay fuzzing
- [ ] (0x00010000) Port/miniport interface checking
- [ ] (0x00040000) Systematic low resources simulation
- [ ] (0x00080000) DDI compliance checking (additional)
- [ ] (0x00200000) NDIS/WIFI verification
- [ ] (0x00800000) Kernel synchronization delay fuzzing
- [ ] (0x01000000) VM switch verification
- [ ] (0x02000000) Code integrity checks
- RESERVED FLAGS (use of these flags is unsupported):
- [X] (0x00100000) Unused or reserved flag
- [X] Indicates flag is enabled
- Summary of All Verifier Statistics
- RaiseIrqls 0xabf7
- AcquireSpinLocks 0x2d14e
- Synch Executions 0x2
- Trims 0xf2a
- Pool Allocations Attempted 0xead9
- Pool Allocations Succeeded 0xead9
- Pool Allocations Succeeded SpecialPool 0xead9
- Pool Allocations With NO TAG 0x9
- Pool Allocations Failed 0x0
- Current paged pool allocations 0x64f for 0019FB2B bytes
- Peak paged pool allocations 0x721 for 001E2357 bytes
- Current nonpaged pool allocations 0x1882 for 00D43CC4 bytes
- Peak nonpaged pool allocations 0x188d for 0236FDA4 bytes
- ========================== Dump #3: Extra #2 ===========================
- 11: kd> !thread
- THREAD ffff9a8acc48a300 Cid 0004.0008 Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor b
- Not impersonating
- GetUlongFromAddress: unable to read from fffff80040ad1a14
- Owning Process ffff9a8acc4c2040 Image: System
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 386
- Context Switch Count 967 IdealProcessor: 11
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address nt!Phase1Initialization (0xfffff80040dfdb20)
- Stack Init ffffd18bd6806c90 Current ffffd18bd6806310
- Base ffffd18bd6807000 Limit ffffd18bd6801000 Call 0000000000000000
- Priority 31 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- ffffd18b`d6806548 fffff800`410156e3 : 00000000`000000c4 00000000`00000062 ffff9a8a`d3676d98 ffff9a8a`cecfe640 : nt!KeBugCheckEx
- ffffd18b`d6806550 fffff800`41024492 : ffff9a8a`cecfe640 ffffd18b`d6806640 ffff9a8a`d3676bc0 ffff9a8a`cf36b320 : nt!VerifierBugCheckIfAppropriate+0xdf
- ffffd18b`d6806590 fffff800`40914b66 : ffff9a8a`cecfe640 00000000`ffffffff 00000000`00000001 fffff80d`8ce01000 : nt!VfPoolCheckForLeaks+0x46
- ffffd18b`d68065d0 fffff800`410074be : 00000000`00518000 ffff9a8a`d3676bc0 fffff800`40adcc10 fffff800`40adcc10 : nt!VfTargetDriversRemove+0xf2516
- ffffd18b`d6806650 fffff800`40d0bad3 : ffff9a8a`d3676bc0 ffffd18b`d6806780 ffffc189`a56edf40 ffff9a8a`d3676bc0 : nt!VfDriverUnloadImage+0x3e
- ffffd18b`d6806680 fffff800`40deb930 : 00000000`00000518 00000000`ffffffff ffffc189`a56edf40 fffff9fc`06c67000 : nt!MiUnloadSystemImage+0x38b
- ffffd18b`d6806810 fffff800`40e28450 : ffff9a8a`d36ebc40 fffff800`407bdd6e ffff9a8a`d36ebc40 ffff9a8a`d36ebc70 : nt!MmUnloadSystemImage+0x20
- ffffd18b`d6806840 fffff800`40cbd910 : ffff9a8a`d36ebc40 00000000`00000000 00000000`00000000 ffffd18b`d68068b0 : nt!IopDeleteDriver+0x40
- ffffd18b`d6806890 fffff800`40746024 : 00000000`00000000 00000000`00000000 ffffd18b`d6806a30 ffff9a8a`d36ebc70 : nt!ObpRemoveObjectRoutine+0x80
- ffffd18b`d68068f0 fffff800`40d9e5bc : 00000000`00000000 ffff9a8a`d36ebc70 ffff9a8a`c0000365 ffffffff`800001d4 : nt!ObfDereferenceObject+0xa4
- ffffd18b`d6806930 fffff800`410b6f91 : ffff9a8a`d37c55a0 ffff9a8a`d37c55a0 ffffd18b`d6806b80 00000000`00000000 : nt!IopLoadDriver+0x710
- ffffd18b`d6806b10 fffff800`410b6182 : fffff800`c0000365 ffffc189`a5e24fc0 00000000`00000000 fffff800`3f03f330 : nt!IopInitializeSystemDrivers+0x151
- ffffd18b`d6806bb0 fffff800`40dfdb62 : fffff800`3f03f330 fffff800`3f03f330 fffff800`40dfdb20 fffff800`3f03f330 : nt!IoInitSystem+0x12
- ffffd18b`d6806be0 fffff800`407c3155 : ffff9a8a`cc48a300 fffff800`40dfdb20 fffff800`3f03f330 eec624b2`e28624b6 : nt!Phase1Initialization+0x42
- ffffd18b`d6806c10 fffff800`4086e9c8 : fffff800`3f3f0180 ffff9a8a`cc48a300 fffff800`407c3100 cefe0170`c2be0174 : nt!PspSystemThreadStartup+0x55
- ffffd18b`d6806c60 00000000`00000000 : ffffd18b`d6807000 ffffd18b`d6801000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
- ========================================================================
- ======================= Dump #4: ANALYZE VERBOSE =======================
- ====================== File: 072220-10671-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 18362 MP (12 procs) Free x64
- Kernel base = 0xfffff801`05000000 PsLoadedModuleList = 0xfffff801`05448190
- Debug session time: Wed Jul 22 07:31:42.672 2020 (UTC - 4:00)
- System Uptime: 1 days 0:16:15.504
- BugCheck A, {0, 2, 1, fffff8010502acff}
- *** WARNING: Unable to verify timestamp for win32k.sys
- *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
- Probably caused by : memory_corruption
- Followup: memory_corruption
- IRQL_NOT_LESS_OR_EQUAL (a)
- An attempt was made to access a pageable (or completely invalid) address at an
- interrupt request level (IRQL) that is too high. This is usually
- caused by drivers using improper addresses.
- If a kernel debugger is available get the stack backtrace.
- Arguments:
- Arg1: 0000000000000000, memory referenced
- Arg2: 0000000000000002, IRQL
- Arg3: 0000000000000001, bitfield :
- bit 0 : value 0 = read operation, 1 = write operation
- bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
- Arg4: fffff8010502acff, address which referenced memory
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- WRITE_ADDRESS: fffff801055733b8: Unable to get MiVisibleState
- 0000000000000000
- CURRENT_IRQL: 2
- FAULTING_IP:
- nt!KiAcquireKobjectLockSafe+f
- fffff801`0502acff f00fba2907 lock bts dword ptr [rcx],7
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- BUGCHECK_STR: AV
- PROCESS_NAME: System
- TRAP_FRAME: fffff40e54099780 -- (.trap 0xfffff40e54099780)
- NOTE: The trap frame does not contain all registers.
- Some register values may be zeroed or incorrect.
- rax=0000000000000000 rbx=0000000000000000 rcx=0000000000000000
- rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
- rip=fffff8010502acff rsp=fffff40e54099910 rbp=ffff9e07e48bc7b0
- r8=0000000000000f0c r9=0000000000000000 r10=0000000000000fff
- r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=0000000000000000
- iopl=0 nv up ei pl zr na po nc
- nt!KiAcquireKobjectLockSafe+0xf:
- fffff801`0502acff f00fba2907 lock bts dword ptr [rcx],7 ds:00000000`00000000=????????
- Resetting default scope
- LAST_CONTROL_TRANSFER: from fffff801051d41e9 to fffff801051c23c0
- STACK_TEXT:
- fffff40e`54099638 fffff801`051d41e9 : 00000000`0000000a 00000000`00000000 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
- fffff40e`54099640 fffff801`051d0529 : 00000000`00000000 00000000`00000000 00000000`00000fff fffff801`052b0245 : nt!KiBugCheckDispatch+0x69
- fffff40e`54099780 fffff801`0502acff : ffffc180`2b139180 00000000`0000000e fffff801`01992800 00000000`00000000 : nt!KiPageFault+0x469
- fffff40e`54099910 fffff801`050513b0 : ffff9e07`e48bc720 ffff9e07`dac881f0 00000001`00000002 ffff9e07`d41de010 : nt!KiAcquireKobjectLockSafe+0xf
- fffff40e`54099940 fffff801`05050059 : 00000000`00000006 00000000`00989680 00000000`0032dbf6 00000000`0000000e : nt!KiProcessExpiredTimerList+0x220
- fffff40e`54099a30 fffff801`051c5eee : ffffffff`00000000 ffffc180`2b139180 ffffc180`2b14a340 ffff9e07`dabe6080 : nt!KiRetireDpcList+0x4e9
- fffff40e`54099c60 00000000`00000000 : fffff40e`5409a000 fffff40e`54094000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x7e
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
- fffff8010503fb50-fffff8010503fb51 2 bytes - nt!MiDeletePteRun+af0
- [ fb f6:f2 e4 ]
- fffff8010503fb79-fffff8010503fb7d 5 bytes - nt!MiDeletePteRun+b19 (+0x29)
- [ d0 be 7d fb f6:90 3c 79 f2 e4 ]
- fffff8010503fbb8 - nt!MiDeletePteRun+b58 (+0x3f)
- [ fa:81 ]
- fffff8010503fbd1-fffff8010503fbd5 5 bytes - nt!MiDeletePteRun+b71 (+0x19)
- [ d7 be 7d fb f6:97 3c 79 f2 e4 ]
- fffff8010503fc13 - nt!MiDeletePteRun+bb3 (+0x42)
- [ f6:e4 ]
- fffff80105077ce8 - nt!MiTerminateWsleCluster+b8 (+0x380d5)
- [ f6:e4 ]
- fffff80105077d4f-fffff80105077d53 5 bytes - nt!MiTerminateWsleCluster+11f (+0x67)
- [ d7 be 7d fb f6:97 3c 79 f2 e4 ]
- fffff80105077d5d - nt!MiTerminateWsleCluster+12d (+0x0e)
- [ fa:81 ]
- fffff80105077d7c - nt!MiTerminateWsleCluster+14c (+0x1f)
- [ f6:e4 ]
- fffff80105077d82-fffff80105077d86 5 bytes - nt!MiTerminateWsleCluster+152 (+0x06)
- [ d0 be 7d fb f6:90 3c 79 f2 e4 ]
- 27 errors : !nt (fffff8010503fb50-fffff80105077d86)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-07-22T11:31:42.000Z
- SUITE_MASK: 784
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #4: 3RD PARTY DRIVERS ======================
- Aug 22 2012 - AsIO.sys - ASUS Input Output driver http://www.asus.com/
- Mar 19 2015 - amd_sata.sys - AMD SATA Controller AHCI Device driver http://support.amd.com/
- Mar 19 2015 - amd_xata.sys - AMD Stor Filter driver http://support.amd.com/
- Mar 30 2015 - Hamdrv.sys - LogMeIn Hamachi Virtual Miniport driver http://www.logmein.com/
- Mar 31 2015 - HWiNFO64A.SYS - HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
- Mar 14 2016 - amdgpio3.sys - AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Aug 02 2017 - Oculus_ViGEmBus.sys - Oculus Virtual Gamepad Emulation Bus driver
- Feb 12 2018 - msio64.sys - MSI Gaming App driver
- Mar 26 2019 - RTKVHD64.sys - Realtek Audio System driver https://www.realtek.com/en/
- Apr 09 2019 - AsIO2.sys - Asus Input Output driver
- Apr 22 2019 - GLCKIO2.sys - ASUS RGB driver
- Apr 22 2019 - OCULUSUD.sys - Oculus VR Headset driver
- Jun 06 2019 - IUProcessFilter.sys - IObit Uninstaller driver (IObit Information Technology)
- Sep 05 2019 - e1r65x64.sys - Intel(R) Gigabit Adapter NDIS 6.x driver https://downloadcenter.intel.com/
- Oct 14 2019 - ene.sys - (Ptolemy Tech Co.) or ASUS RGB driver or Gigabyte RGB driver
- Nov 06 2019 - IUFileFilter.sys - IObit Uninstaller driver (IObit)
- Nov 06 2019 - IURegistryFilter.sys - IObit Uninstaller driver (IObit Information Technology)
- Nov 15 2019 - AtihdWT6.sys - AMD High Definition Audio Function driver http://support.amd.com/
- Nov 20 2019 - mbamswissarmy.sys - MalwareBytes Anti-Malware system driver https://www.malwarebytes.com/
- Nov 27 2019 - teVirtualMIDI64.sys - teVirtualMIDI - Virtual MIDI driver (Tobias Erichsen)
- Dec 05 2019 - cpuz149_x64.sys - CPUID driver
- Jan 14 2020 - amdgpio2.sys - AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Jan 16 2020 - amdkmpfd.sys - AMD Kernel Miniport Filter driver
- Feb 10 2020 - bcmwl63a.sys - Broadcom 802 11 Network Adapter Wireless driver http://www.broadcom.com/support/
- Feb 12 2020 - HWiNFO64A_150.SYS - HWiNFO driver https://www.hwinfo.com/
- Feb 14 2020 - CorsairLLAccess64.sys - CORSAIR iCUE Software driver
- Feb 25 2020 - oculusvad.sys - Oculus VAD driver
- Mar 06 2020 - amdpsp.sys - Advanced Micro Devices, Inc http://support.amd.com/
- Mar 26 2020 - amdxe.sys - AMD Link Xinput Emulation driver
- Apr 10 2020 - AMDPCIDev.sys - Advanced Micro Devices PCI Device driver
- May 07 2020 - CorsairGamingAudio64.sys - Corsair Gaming Audio 64-bit driver
- May 25 2020 - amdkmdag.sys - AMD Graphics driver
- Jun 04 2020 - MbamChameleon.sys - Malwarebytes Anti-Malware Chameleon driver https://www.malwarebytes.com/
- Jun 09 2020 - amdlog.sys - AMD LOG driver
- Jun 30 2020 - CorsairVBusDriver.sys - Corsair Virtual Device driver (Corsair Utility Engine) http://www.corsair.com/
- Jun 30 2020 - CorsairVHidDriver.sys - Corsair Virtual Device driver (Corsair Utility Engine) http://www.corsair.com/
- ================== Dump #4: 3RD PARTY DRIVERS (FULL) ===================
- Image path: \SystemRoot\SysWow64\drivers\AsIO.sys
- Image name: AsIO.sys
- Search : https://www.google.com/search?q=AsIO.sys
- ADA Info : ASUS Input Output driver http://www.asus.com/
- Timestamp : Wed Aug 22 2012
- Image path: \SystemRoot\System32\drivers\amd_sata.sys
- Image name: amd_sata.sys
- Search : https://www.google.com/search?q=amd_sata.sys
- ADA Info : AMD SATA Controller AHCI Device driver http://support.amd.com/
- Timestamp : Thu Mar 19 2015
- Image path: \SystemRoot\System32\drivers\amd_xata.sys
- Image name: amd_xata.sys
- Search : https://www.google.com/search?q=amd_xata.sys
- ADA Info : AMD Stor Filter driver http://support.amd.com/
- Timestamp : Thu Mar 19 2015
- Image path: \SystemRoot\system32\DRIVERS\Hamdrv.sys
- Image name: Hamdrv.sys
- Search : https://www.google.com/search?q=Hamdrv.sys
- ADA Info : LogMeIn Hamachi Virtual Miniport driver http://www.logmein.com/
- Timestamp : Mon Mar 30 2015
- Image path: \??\C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS
- Image name: HWiNFO64A.SYS
- Search : https://www.google.com/search?q=HWiNFO64A.SYS
- ADA Info : HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
- Timestamp : Tue Mar 31 2015
- Image path: \SystemRoot\System32\drivers\amdgpio3.sys
- Image name: amdgpio3.sys
- Search : https://www.google.com/search?q=amdgpio3.sys
- ADA Info : AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Timestamp : Mon Mar 14 2016
- Image path: \SystemRoot\System32\drivers\Oculus_ViGEmBus.sys
- Image name: Oculus_ViGEmBus.sys
- Search : https://www.google.com/search?q=Oculus_ViGEmBus.sys
- ADA Info : Oculus Virtual Gamepad Emulation Bus driver
- Timestamp : Wed Aug 2 2017
- Image path: \??\C:\Program Files\Patriot\Aac_Patriot Viper RGB\msio64.sys
- Image name: msio64.sys
- Search : https://www.google.com/search?q=msio64.sys
- ADA Info : MSI Gaming App driver
- Timestamp : Mon Feb 12 2018
- Image path: \SystemRoot\system32\drivers\RTKVHD64.sys
- Image name: RTKVHD64.sys
- Search : https://www.google.com/search?q=RTKVHD64.sys
- ADA Info : Realtek Audio System driver https://www.realtek.com/en/
- Timestamp : Tue Mar 26 2019
- Image path: \??\C:\WINDOWS\system32\drivers\AsIO2.sys
- Image name: AsIO2.sys
- Search : https://www.google.com/search?q=AsIO2.sys
- ADA Info : Asus Input Output driver
- Timestamp : Tue Apr 9 2019
- Image path: \??\C:\WINDOWS\system32\drivers\GLCKIO2.sys
- Image name: GLCKIO2.sys
- Search : https://www.google.com/search?q=GLCKIO2.sys
- ADA Info : ASUS RGB driver
- Timestamp : Mon Apr 22 2019
- Image path: \SystemRoot\System32\drivers\OCULUSUD.sys
- Image name: OCULUSUD.sys
- Search : https://www.google.com/search?q=OCULUSUD.sys
- ADA Info : Oculus VR Headset driver
- Timestamp : Mon Apr 22 2019
- Image path: \??\D:\Programs I want\IObit Uninstaller\drivers\win10_amd64\IUProcessFilter.sys
- Image name: IUProcessFilter.sys
- Search : https://www.google.com/search?q=IUProcessFilter.sys
- ADA Info : IObit Uninstaller driver (IObit Information Technology)
- Timestamp : Thu Jun 6 2019
- Image path: \SystemRoot\system32\DRIVERS\e1r65x64.sys
- Image name: e1r65x64.sys
- Search : https://www.google.com/search?q=e1r65x64.sys
- ADA Info : Intel(R) Gigabit Adapter NDIS 6.x driver https://downloadcenter.intel.com/
- Timestamp : Thu Sep 5 2019
- Image path: \??\C:\WINDOWS\system32\drivers\ene.sys
- Image name: ene.sys
- Search : https://www.google.com/search?q=ene.sys
- ADA Info : (Ptolemy Tech Co.) or ASUS RGB driver or Gigabyte RGB driver
- Timestamp : Mon Oct 14 2019
- Image path: \??\D:\Programs I want\IObit Uninstaller\drivers\win10_amd64\IUFileFilter.sys
- Image name: IUFileFilter.sys
- Search : https://www.google.com/search?q=IUFileFilter.sys
- ADA Info : IObit Uninstaller driver (IObit)
- Timestamp : Wed Nov 6 2019
- Image path: \??\D:\Programs I want\IObit Uninstaller\drivers\win10_amd64\IURegistryFilter.sys
- Image name: IURegistryFilter.sys
- Search : https://www.google.com/search?q=IURegistryFilter.sys
- ADA Info : IObit Uninstaller driver (IObit Information Technology)
- Timestamp : Wed Nov 6 2019
- Image path: \SystemRoot\system32\drivers\AtihdWT6.sys
- Image name: AtihdWT6.sys
- Search : https://www.google.com/search?q=AtihdWT6.sys
- ADA Info : AMD High Definition Audio Function driver http://support.amd.com/
- Timestamp : Fri Nov 15 2019
- Image path: \SystemRoot\System32\Drivers\mbamswissarmy.sys
- Image name: mbamswissarmy.sys
- Search : https://www.google.com/search?q=mbamswissarmy.sys
- ADA Info : MalwareBytes Anti-Malware system driver https://www.malwarebytes.com/
- Timestamp : Wed Nov 20 2019
- Image path: \SystemRoot\System32\drivers\teVirtualMIDI64.sys
- Image name: teVirtualMIDI64.sys
- Search : https://www.google.com/search?q=teVirtualMIDI64.sys
- ADA Info : teVirtualMIDI - Virtual MIDI driver (Tobias Erichsen)
- Timestamp : Wed Nov 27 2019
- Image path: \??\C:\WINDOWS\temp\cpuz149\cpuz149_x64.sys
- Image name: cpuz149_x64.sys
- Search : https://www.google.com/search?q=cpuz149_x64.sys
- ADA Info : CPUID driver
- Timestamp : Thu Dec 5 2019
- Image path: \SystemRoot\System32\drivers\amdgpio2.sys
- Image name: amdgpio2.sys
- Search : https://www.google.com/search?q=amdgpio2.sys
- ADA Info : AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Timestamp : Tue Jan 14 2020
- Image path: \SystemRoot\System32\drivers\amdkmpfd.sys
- Image name: amdkmpfd.sys
- Search : https://www.google.com/search?q=amdkmpfd.sys
- ADA Info : AMD Kernel Miniport Filter driver
- Timestamp : Thu Jan 16 2020
- Image path: \SystemRoot\system32\DRIVERS\bcmwl63a.sys
- Image name: bcmwl63a.sys
- Search : https://www.google.com/search?q=bcmwl63a.sys
- ADA Info : Broadcom 802 11 Network Adapter Wireless driver http://www.broadcom.com/support/
- Timestamp : Mon Feb 10 2020
- Image path: \??\C:\Users\andre\AppData\Local\Temp\HWiNFO64A_150.SYS
- Image name: HWiNFO64A_150.SYS
- Search : https://www.google.com/search?q=HWiNFO64A_150.SYS
- ADA Info : HWiNFO driver https://www.hwinfo.com/
- Timestamp : Wed Feb 12 2020
- Image path: \??\C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\CorsairLLAccess64.sys
- Image name: CorsairLLAccess64.sys
- Search : https://www.google.com/search?q=CorsairLLAccess64.sys
- ADA Info : CORSAIR iCUE Software driver
- Timestamp : Fri Feb 14 2020
- Image path: \SystemRoot\System32\drivers\oculusvad.sys
- Image name: oculusvad.sys
- Search : https://www.google.com/search?q=oculusvad.sys
- ADA Info : Oculus VAD driver
- Timestamp : Tue Feb 25 2020
- Image path: \SystemRoot\System32\drivers\amdpsp.sys
- Image name: amdpsp.sys
- Search : https://www.google.com/search?q=amdpsp.sys
- ADA Info : Advanced Micro Devices, Inc http://support.amd.com/
- Timestamp : Fri Mar 6 2020
- Image path: \SystemRoot\System32\drivers\amdxe.sys
- Image name: amdxe.sys
- Search : https://www.google.com/search?q=amdxe.sys
- ADA Info : AMD Link Xinput Emulation driver
- Timestamp : Thu Mar 26 2020
- Image path: \SystemRoot\System32\drivers\AMDPCIDev.sys
- Image name: AMDPCIDev.sys
- Search : https://www.google.com/search?q=AMDPCIDev.sys
- ADA Info : Advanced Micro Devices PCI Device driver
- Timestamp : Fri Apr 10 2020
- Image path: \SystemRoot\system32\DRIVERS\CorsairGamingAudio64.sys
- Image name: CorsairGamingAudio64.sys
- Search : https://www.google.com/search?q=CorsairGamingAudio64.sys
- ADA Info : Corsair Gaming Audio 64-bit driver
- Timestamp : Thu May 7 2020
- Image path: \SystemRoot\System32\DriverStore\FileRepository\u0356013.inf_amd64_61ba7b1fb4cf4aec\B355483\amdkmdag.sys
- Image name: amdkmdag.sys
- Search : https://www.google.com/search?q=amdkmdag.sys
- ADA Info : AMD Graphics driver
- Timestamp : Mon May 25 2020
- Image path: \SystemRoot\System32\Drivers\MbamChameleon.sys
- Image name: MbamChameleon.sys
- Search : https://www.google.com/search?q=MbamChameleon.sys
- ADA Info : Malwarebytes Anti-Malware Chameleon driver https://www.malwarebytes.com/
- Timestamp : Thu Jun 4 2020
- Image path: \SystemRoot\System32\drivers\amdlog.sys
- Image name: amdlog.sys
- Search : https://www.google.com/search?q=amdlog.sys
- ADA Info : AMD LOG driver
- Timestamp : Tue Jun 9 2020
- Image path: \SystemRoot\System32\drivers\CorsairVBusDriver.sys
- Image name: CorsairVBusDriver.sys
- Search : https://www.google.com/search?q=CorsairVBusDriver.sys
- ADA Info : Corsair Virtual Device driver (Corsair Utility Engine) http://www.corsair.com/
- Timestamp : Tue Jun 30 2020
- Image path: \SystemRoot\System32\drivers\CorsairVHidDriver.sys
- Image name: CorsairVHidDriver.sys
- Search : https://www.google.com/search?q=CorsairVHidDriver.sys
- ADA Info : Corsair Virtual Device driver (Corsair Utility Engine) http://www.corsair.com/
- Timestamp : Tue Jun 30 2020
- ====================== Dump #4: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- amdppm.sys Processor Device Driver
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_amd_sata.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kd.dll Local Kernal Debugger (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate_AuthenticAMD.dll AMD Microcode Update Library (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- MpKsld4eaee01.sys Microsoft Anti-malware Protection driver
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msgpioclx.sys GPIO Class Extension Driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- ndisuio.sys NDIS User mode I/O driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- nwifi.sys NativeWiFi Miniport Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- qwavedrv.sys Quality Windows Audio Video Experience (qWave) Support driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdpvideominiport.sys RDP Video Miniport driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- serenum.sys Serial Port Enumerator (Microsoft)
- serial.sys Serial Device Driver
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- ucx01000.sys USB Controller Extension (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- usbser.sys USB Serial driver (Microsoft)
- USBSTOR.SYS USB Mass Storage Class driver (Microsoft)
- usbvideo.sys USB Video Class Driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwifibus.sys Virtual Wireless Bus driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- vwifimp.sys Virtual WiFi Miniport Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- winquic.sys QUIC Transport Protocol driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WpdUpFltr.sys Portable Device Upper Class Filter driver (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- WUDFRd.sys Windows Driver Foundation - User-mode Driver Framework Reflector driver (Microsoft)
- ====================== Dump #4: UNLOADED MODULES =======================
- fffff801`04820000 fffff801`04831000 MSKSSRV.sys
- fffff801`0fe70000 fffff801`0fe7f000 Hamdrv.sys
- fffff801`04750000 fffff801`0475f000 hiber_storpo
- fffff801`04760000 fffff801`0477e000 hiber_amd_sa
- fffff801`04780000 fffff801`0479e000 hiber_dumpfv
- fffff801`17a70000 fffff801`17a8e000 AtihdWT6.sys
- fffff801`046d0000 fffff801`04720000 usbvideo.sys
- fffff801`04720000 fffff801`04731000 MSKSSRV.sys
- fffff801`043a0000 fffff801`043f0000 usbvideo.sys
- fffff801`046b0000 fffff801`046c1000 MSKSSRV.sys
- fffff801`04690000 fffff801`046a1000 MSKSSRV.sys
- fffff801`04500000 fffff801`0466a000 EasyAntiChea
- fffff801`17ba0000 fffff801`17bb2000 CorsairGamin
- fffff801`0fc90000 fffff801`0fca1000 MpKslDrv.sys
- fffff801`04460000 fffff801`04471000 MpKsle9e11df
- fffff801`043f0000 fffff801`04401000 MSKSSRV.sys
- fffff801`17940000 fffff801`1794a000 CorsairVHidD
- fffff801`04330000 fffff801`0433e000 WSDScan.sys
- fffff801`04320000 fffff801`0432e000 WSDPrint.sys
- fffff801`0fa10000 fffff801`0fa1f000 dump_storpor
- fffff801`0fa40000 fffff801`0fa5e000 dump_amd_sat
- fffff801`0fa80000 fffff801`0fa9e000 dump_dumpfve
- fffff801`08630000 fffff801`0864c000 EhStorClass.
- fffff801`0fd20000 fffff801`0fd3e000 dam.sys
- fffff801`0faa0000 fffff801`0ffb9000 vgk.sys
- fffff801`08190000 fffff801`081a1000 WdBoot.sys
- fffff801`08180000 fffff801`08189000 MbamElam.sys
- fffff801`092b0000 fffff801`092c1000 hwpolicy.sys
- ====================== Dump #4: BIOS INFORMATION =======================
- [SMBIOS Data Tables v3.1]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 2505 bytes]
- [BIOS Information (Type 0) - Length 26 - Handle 0000h]
- Vendor American Megatrends Inc.
- BIOS Version 5406
- BIOS Starting Address Segment f000
- BIOS Release Date 11/13/2019
- BIOS ROM Size 1000000
- BIOS Characteristics
- 07: - PCI Supported
- 10: - APM Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 27: - Keyboard Services Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 32: - BIOS Vendor Reserved
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 5
- BIOS Minor Revision 13
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- Manufacturer System manufacturer
- Product Name System Product Name
- Version System Version
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- SKUNumber SKU
- [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
- Manufacturer ASUSTeK COMPUTER INC.
- Product ROG STRIX B350-F GAMING
- Version Rev X.0x
- Feature Flags 09h
- -815483168: - -815483120: - «
- ø
- Location Default string
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 22 - Handle 0003h]
- Manufacturer Default string
- Chassis Type Desktop
- Version Default string
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 3
- [Onboard Devices Information (Type 10) - Length 6 - Handle 0020h]
- Number of Devices 1
- 01: Type Video [enabled]
- [OEM Strings (Type 11) - Length 5 - Handle 0021h]
- Number of Strings 8
- 1 Default string
- 2 Default string
- 3 CHOPIN
- 4 Default string
- 5 FFFFFFFFFFFFF
- 6 FFFFFFFFFFFFF
- 7 FFFFFFFFFFFFF
- 8 Default string
- [System Configuration Options (Type 12) - Length 5 - Handle 0022h]
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 0026h]
- [Physical Memory Array (Type 16) - Length 23 - Handle 0027h]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 134217728KB
- Memory Error Inf Handle 0026h
- Number of Memory Devices 4
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0028h]
- Starting Address 00000000h
- Ending Address 0037ffffh
- Memory Array Handle 0027h
- Partition Width 02
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0029h]
- Starting Address 00400000h
- Ending Address 0107ffffh
- Memory Array Handle 0027h
- Partition Width 02
- [Cache Information (Type 7) - Length 19 - Handle 002ah]
- Socket Designation L1 - Cache
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0180h - 384K
- Installed Size 0180h - 384K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 002bh]
- Socket Designation L2 - Cache
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 0c00h - 3072K
- Installed Size 0c00h - 3072K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 002ch]
- Socket Designation L3 - Cache
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 8200h - 32768K
- Installed Size 8200h - 32768K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 16-way Set-Associative
- [Processor Information (Type 4) - Length 48 - Handle 002dh]
- Socket Designation AM4
- Processor Type Central Processor
- Processor Family 6bh - Specification Reserved
- Processor Manufacturer Advanced Micro Devices, Inc.
- Processor ID 100f8700fffb8b17
- Processor Version AMD Ryzen 5 3600 6-Core Processor
- Processor Voltage 8bh - 1.1V
- External Clock 100MHz
- Max Speed 4200MHz
- Current Speed 3600MHz
- Status Enabled Populated
- Processor Upgrade Specification Reserved
- L1 Cache Handle 002ah
- L2 Cache Handle 002bh
- L3 Cache Handle 002ch
- Part Number Unknown
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 002eh]
- [Memory Device (Type 17) - Length 40 - Handle 002fh]
- Physical Memory Array Handle 0027h
- Memory Error Info Handle 002eh
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator DIMM_A1
- Bank Locator BANK 0
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 3200MHz
- Manufacturer Corsair
- Part Number CMW16GX4M2C3200C16
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0030h]
- Starting Address 00000000h
- Ending Address 00ffffffh
- Memory Device Handle 002fh
- Mem Array Mapped Adr Handle 0029h
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 0031h]
- [Memory Device (Type 17) - Length 40 - Handle 0032h]
- Physical Memory Array Handle 0027h
- Memory Error Info Handle 0031h
- Form Factor 02h - Unknown
- Device Locator DIMM_A2
- Bank Locator BANK 1
- Memory Type 02h - Unknown
- Type Detail 0004h - Unknown
- Speed 0MHz
- Manufacturer Unknown
- Part Number Unknown
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 0033h]
- [Memory Device (Type 17) - Length 40 - Handle 0034h]
- Physical Memory Array Handle 0027h
- Memory Error Info Handle 0033h
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator DIMM_B1
- Bank Locator BANK 2
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 3200MHz
- Manufacturer Corsair
- Part Number CMW16GX4M2C3200C16
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0035h]
- Starting Address 00000000h
- Ending Address 00ffffffh
- Memory Device Handle 0034h
- Mem Array Mapped Adr Handle 0029h
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 0036h]
- [Memory Device (Type 17) - Length 40 - Handle 0037h]
- Physical Memory Array Handle 0027h
- Memory Error Info Handle 0036h
- Form Factor 02h - Unknown
- Device Locator DIMM_B2
- Bank Locator BANK 3
- Memory Type 02h - Unknown
- Type Detail 0004h - Unknown
- Speed 0MHz
- Manufacturer Unknown
- Part Number Unknown
- ========================== Dump #4: Extra #1 ===========================
- 9: kd> !verifier
- Verify Flags Level 0x00000000
- STANDARD FLAGS:
- [X] (0x00000000) Automatic Checks
- [ ] (0x00000001) Special pool
- [ ] (0x00000002) Force IRQL checking
- [ ] (0x00000008) Pool tracking
- [ ] (0x00000010) I/O verification
- [ ] (0x00000020) Deadlock detection
- [ ] (0x00000080) DMA checking
- [ ] (0x00000100) Security checks
- [ ] (0x00000800) Miscellaneous checks
- [ ] (0x00020000) DDI compliance checking
- ADDITIONAL FLAGS:
- [ ] (0x00000004) Randomized low resources simulation
- [ ] (0x00000200) Force pending I/O requests
- [ ] (0x00000400) IRP logging
- [ ] (0x00002000) Invariant MDL checking for stack
- [ ] (0x00004000) Invariant MDL checking for driver
- [ ] (0x00008000) Power framework delay fuzzing
- [ ] (0x00010000) Port/miniport interface checking
- [ ] (0x00040000) Systematic low resources simulation
- [ ] (0x00080000) DDI compliance checking (additional)
- [ ] (0x00200000) NDIS/WIFI verification
- [ ] (0x00800000) Kernel synchronization delay fuzzing
- [ ] (0x01000000) VM switch verification
- [ ] (0x02000000) Code integrity checks
- [X] Indicates flag is enabled
- Summary of All Verifier Statistics
- RaiseIrqls 0x0
- AcquireSpinLocks 0x0
- Synch Executions 0x0
- Trims 0x0
- Pool Allocations Attempted 0x0
- Pool Allocations Succeeded 0x0
- Pool Allocations Succeeded SpecialPool 0x0
- Pool Allocations With NO TAG 0x0
- Pool Allocations Failed 0x0
- Current paged pool allocations 0x0 for 00000000 bytes
- Peak paged pool allocations 0x0 for 00000000 bytes
- Current nonpaged pool allocations 0x0 for 00000000 bytes
- Peak nonpaged pool allocations 0x0 for 00000000 bytes
- ========================== Dump #4: Extra #2 ===========================
- 9: kd> !thread
- THREAD ffffc1802b14a340 Cid 0000.0000 Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor 9
- Not impersonating
- GetUlongFromAddress: unable to read from fffff8010542ca14
- Owning Process fffff8010558e9c0 Image: System Process
- Attached Process ffff9e07ce0b0080 Image: System
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 5592032
- Context Switch Count 126114234 IdealProcessor: 9
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address nt!KiIdleLoop (0xfffff801051c5e70)
- Stack Init fffff40e54099c90 Current fffff40e54099c20
- Base fffff40e5409a000 Limit fffff40e54094000 Call 0000000000000000
- Priority 0 BasePriority 0 PriorityDecrement 0 IoPriority 0 PagePriority 0
- Child-SP RetAddr : Args to Child : Call Site
- fffff40e`54099638 fffff801`051d41e9 : 00000000`0000000a 00000000`00000000 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
- fffff40e`54099640 fffff801`051d0529 : 00000000`00000000 00000000`00000000 00000000`00000fff fffff801`052b0245 : nt!KiBugCheckDispatch+0x69
- fffff40e`54099780 fffff801`0502acff : ffffc180`2b139180 00000000`0000000e fffff801`01992800 00000000`00000000 : nt!KiPageFault+0x469 (TrapFrame @ fffff40e`54099780)
- fffff40e`54099910 fffff801`050513b0 : ffff9e07`e48bc720 ffff9e07`dac881f0 00000001`00000002 ffff9e07`d41de010 : nt!KiAcquireKobjectLockSafe+0xf
- fffff40e`54099940 fffff801`05050059 : 00000000`00000006 00000000`00989680 00000000`0032dbf6 00000000`0000000e : nt!KiProcessExpiredTimerList+0x220
- fffff40e`54099a30 fffff801`051c5eee : ffffffff`00000000 ffffc180`2b139180 ffffc180`2b14a340 ffff9e07`dabe6080 : nt!KiRetireDpcList+0x4e9
- fffff40e`54099c60 00000000`00000000 : fffff40e`5409a000 fffff40e`54094000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x7e
- ========================================================================
- ======================= Dump #5: ANALYZE VERBOSE =======================
- ====================== File: 072120-11187-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 18362 MP (12 procs) Free x64
- Kernel base = 0xfffff805`26800000 PsLoadedModuleList = 0xfffff805`26c48190
- Debug session time: Tue Jul 21 07:13:32.268 2020 (UTC - 4:00)
- System Uptime: 0 days 21:27:08.926
- BugCheck A, {ffff9b93ba88a9d8, ff, 6e, fffff80526af064d}
- *** WARNING: Unable to verify timestamp for win32k.sys
- *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
- Probably caused by : memory_corruption
- Followup: memory_corruption
- IRQL_NOT_LESS_OR_EQUAL (a)
- An attempt was made to access a pageable (or completely invalid) address at an
- interrupt request level (IRQL) that is too high. This is usually
- caused by drivers using improper addresses.
- If a kernel debugger is available get the stack backtrace.
- Arguments:
- Arg1: ffff9b93ba88a9d8, memory referenced
- Arg2: 00000000000000ff, IRQL
- Arg3: 000000000000006e, bitfield :
- bit 0 : value 0 = read operation, 1 = write operation
- bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
- Arg4: fffff80526af064d, address which referenced memory
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- READ_ADDRESS: fffff80526d733b8: Unable to get MiVisibleState
- ffff9b93ba88a9d8
- CURRENT_IRQL: 0
- FAULTING_IP:
- nt!PpmIdleUpdateConcurrency+55
- fffff805`26af064d 4a014ccb20 add qword ptr [rbx+r9*8+20h],rcx
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- BUGCHECK_STR: AV
- PROCESS_NAME: System
- TRAP_FRAME: fffff8052b46b610 -- (.trap 0xfffff8052b46b610)
- NOTE: The trap frame does not contain all registers.
- Some register values may be zeroed or incorrect.
- rax=000000b3d3cc5504 rbx=0000000000000000 rcx=0000000000000006
- rdx=000000b3d3cc550a rsi=0000000000000000 rdi=0000000000000000
- rip=fffff80526af064d rsp=fffff8052b46b7a0 rbp=ffff9b8bbf139001
- r8=0000000000000000 r9=00000000ffffffff r10=fffff805268f0170
- r11=ffff76fcefa00000 r12=0000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=0000000000000000
- iopl=0 nv up di pl nz na pe nc
- nt!PpmIdleUpdateConcurrency+0x55:
- fffff805`26af064d 4a014ccb20 add qword ptr [rbx+r9*8+20h],rcx ds:00000008`00000018=????????????????
- Resetting default scope
- LAST_CONTROL_TRANSFER: from fffff805269d41e9 to fffff805269c23c0
- STACK_TEXT:
- fffff805`2b46b4c8 fffff805`269d41e9 : 00000000`0000000a ffff9b93`ba88a9d8 00000000`000000ff 00000000`0000006e : nt!KeBugCheckEx
- fffff805`2b46b4d0 fffff805`269d0529 : 00000000`00000002 fffff805`2b46b7f8 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
- fffff805`2b46b610 fffff805`26af064d : 00000000`00000200 fffff805`2675d8f8 fffff805`235f9180 00000000`00000000 : nt!KiPageFault+0x469
- fffff805`2b46b7a0 fffff805`269fc0b8 : 000092fe`cb6a86c6 ffff9b8b`bf139080 00000000`00000000 00000000`00000000 : nt!PpmIdleUpdateConcurrency+0x55
- fffff805`2b46b7e0 fffff805`2684a38e : 00000000`00000003 00000000`00000002 00000000`00000000 01d65f4f`f80d40f2 : nt!PpmIdleExecuteTransition+0x1b1b88
- fffff805`2b46bb00 fffff805`269c5eb4 : 00000000`00000000 fffff805`235f9180 ffff9b8b`ce5860c0 00000000`00000438 : nt!PoIdle+0x36e
- fffff805`2b46bc60 00000000`00000000 : fffff805`2b46c000 fffff805`2b466000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x44
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !hal
- fffff8052675d956-fffff8052675d95b 6 bytes - hal!KeQueryPerformanceCounter+e6
- [ ff 15 b4 7f 07 00:e8 45 69 3f 00 90 ]
- 6 errors : !hal (fffff8052675d956-fffff8052675d95b)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-07-21T11:13:32.000Z
- SUITE_MASK: 784
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #5: 3RD PARTY DRIVERS ======================
- Aug 22 2012 - AsIO.sys - ASUS Input Output driver http://www.asus.com/
- Mar 19 2015 - amd_sata.sys - AMD SATA Controller AHCI Device driver http://support.amd.com/
- Mar 19 2015 - amd_xata.sys - AMD Stor Filter driver http://support.amd.com/
- Mar 30 2015 - Hamdrv.sys - LogMeIn Hamachi Virtual Miniport driver http://www.logmein.com/
- Mar 31 2015 - HWiNFO64A.SYS - HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
- Mar 14 2016 - amdgpio3.sys - AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Aug 02 2017 - Oculus_ViGEmBus.sys - Oculus Virtual Gamepad Emulation Bus driver
- Feb 12 2018 - msio64.sys - MSI Gaming App driver
- Mar 26 2019 - RTKVHD64.sys - Realtek Audio System driver https://www.realtek.com/en/
- Apr 09 2019 - AsIO2.sys - Asus Input Output driver
- Apr 22 2019 - GLCKIO2.sys - ASUS RGB driver
- Apr 22 2019 - OCULUSUD.sys - Oculus VR Headset driver
- Jun 06 2019 - IUProcessFilter.sys - IObit Uninstaller driver (IObit Information Technology)
- Sep 05 2019 - e1r65x64.sys - Intel(R) Gigabit Adapter NDIS 6.x driver https://downloadcenter.intel.com/
- Oct 14 2019 - ene.sys - (Ptolemy Tech Co.) or ASUS RGB driver or Gigabyte RGB driver
- Nov 06 2019 - IUFileFilter.sys - IObit Uninstaller driver (IObit)
- Nov 06 2019 - IURegistryFilter.sys - IObit Uninstaller driver (IObit Information Technology)
- Nov 15 2019 - AtihdWT6.sys - AMD High Definition Audio Function driver http://support.amd.com/
- Nov 20 2019 - mbamswissarmy.sys - MalwareBytes Anti-Malware system driver https://www.malwarebytes.com/
- Nov 27 2019 - teVirtualMIDI64.sys - teVirtualMIDI - Virtual MIDI driver (Tobias Erichsen)
- Dec 05 2019 - cpuz149_x64.sys - CPUID driver
- Jan 14 2020 - amdgpio2.sys - AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Jan 16 2020 - amdkmpfd.sys - AMD Kernel Miniport Filter driver
- Feb 10 2020 - bcmwl63a.sys - Broadcom 802 11 Network Adapter Wireless driver http://www.broadcom.com/support/
- Feb 12 2020 - HWiNFO64A_150.SYS - HWiNFO driver https://www.hwinfo.com/
- Feb 14 2020 - CorsairLLAccess64.sys - CORSAIR iCUE Software driver
- Feb 25 2020 - oculusvad.sys - Oculus VAD driver
- Mar 06 2020 - amdpsp.sys - Advanced Micro Devices, Inc http://support.amd.com/
- Mar 26 2020 - amdxe.sys - AMD Link Xinput Emulation driver
- Apr 10 2020 - AMDPCIDev.sys - Advanced Micro Devices PCI Device driver
- May 07 2020 - CorsairGamingAudio64.sys - Corsair Gaming Audio 64-bit driver
- May 25 2020 - amdkmdag.sys - AMD Graphics driver
- Jun 04 2020 - MbamChameleon.sys - Malwarebytes Anti-Malware Chameleon driver https://www.malwarebytes.com/
- Jun 09 2020 - amdlog.sys - AMD LOG driver
- Jun 30 2020 - CorsairVBusDriver.sys - Corsair Virtual Device driver (Corsair Utility Engine) http://www.corsair.com/
- Jun 30 2020 - CorsairVHidDriver.sys - Corsair Virtual Device driver (Corsair Utility Engine) http://www.corsair.com/
- ================== Dump #5: 3RD PARTY DRIVERS (FULL) ===================
- Image path: \SystemRoot\SysWow64\drivers\AsIO.sys
- Image name: AsIO.sys
- Search : https://www.google.com/search?q=AsIO.sys
- ADA Info : ASUS Input Output driver http://www.asus.com/
- Timestamp : Wed Aug 22 2012
- Image path: \SystemRoot\System32\drivers\amd_sata.sys
- Image name: amd_sata.sys
- Search : https://www.google.com/search?q=amd_sata.sys
- ADA Info : AMD SATA Controller AHCI Device driver http://support.amd.com/
- Timestamp : Thu Mar 19 2015
- Image path: \SystemRoot\System32\drivers\amd_xata.sys
- Image name: amd_xata.sys
- Search : https://www.google.com/search?q=amd_xata.sys
- ADA Info : AMD Stor Filter driver http://support.amd.com/
- Timestamp : Thu Mar 19 2015
- Image path: \SystemRoot\system32\DRIVERS\Hamdrv.sys
- Image name: Hamdrv.sys
- Search : https://www.google.com/search?q=Hamdrv.sys
- ADA Info : LogMeIn Hamachi Virtual Miniport driver http://www.logmein.com/
- Timestamp : Mon Mar 30 2015
- Image path: \??\C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS
- Image name: HWiNFO64A.SYS
- Search : https://www.google.com/search?q=HWiNFO64A.SYS
- ADA Info : HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
- Timestamp : Tue Mar 31 2015
- Image path: \SystemRoot\System32\drivers\amdgpio3.sys
- Image name: amdgpio3.sys
- Search : https://www.google.com/search?q=amdgpio3.sys
- ADA Info : AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Timestamp : Mon Mar 14 2016
- Image path: \SystemRoot\System32\drivers\Oculus_ViGEmBus.sys
- Image name: Oculus_ViGEmBus.sys
- Search : https://www.google.com/search?q=Oculus_ViGEmBus.sys
- ADA Info : Oculus Virtual Gamepad Emulation Bus driver
- Timestamp : Wed Aug 2 2017
- Image path: \??\C:\Program Files\Patriot\Aac_Patriot Viper RGB\msio64.sys
- Image name: msio64.sys
- Search : https://www.google.com/search?q=msio64.sys
- ADA Info : MSI Gaming App driver
- Timestamp : Mon Feb 12 2018
- Image path: \SystemRoot\system32\drivers\RTKVHD64.sys
- Image name: RTKVHD64.sys
- Search : https://www.google.com/search?q=RTKVHD64.sys
- ADA Info : Realtek Audio System driver https://www.realtek.com/en/
- Timestamp : Tue Mar 26 2019
- Image path: \??\C:\WINDOWS\system32\drivers\AsIO2.sys
- Image name: AsIO2.sys
- Search : https://www.google.com/search?q=AsIO2.sys
- ADA Info : Asus Input Output driver
- Timestamp : Tue Apr 9 2019
- Image path: \??\C:\WINDOWS\system32\drivers\GLCKIO2.sys
- Image name: GLCKIO2.sys
- Search : https://www.google.com/search?q=GLCKIO2.sys
- ADA Info : ASUS RGB driver
- Timestamp : Mon Apr 22 2019
- Image path: \SystemRoot\System32\drivers\OCULUSUD.sys
- Image name: OCULUSUD.sys
- Search : https://www.google.com/search?q=OCULUSUD.sys
- ADA Info : Oculus VR Headset driver
- Timestamp : Mon Apr 22 2019
- Image path: \??\D:\Programs I want\IObit Uninstaller\drivers\win10_amd64\IUProcessFilter.sys
- Image name: IUProcessFilter.sys
- Search : https://www.google.com/search?q=IUProcessFilter.sys
- ADA Info : IObit Uninstaller driver (IObit Information Technology)
- Timestamp : Thu Jun 6 2019
- Image path: \SystemRoot\system32\DRIVERS\e1r65x64.sys
- Image name: e1r65x64.sys
- Search : https://www.google.com/search?q=e1r65x64.sys
- ADA Info : Intel(R) Gigabit Adapter NDIS 6.x driver https://downloadcenter.intel.com/
- Timestamp : Thu Sep 5 2019
- Image path: \??\C:\WINDOWS\system32\drivers\ene.sys
- Image name: ene.sys
- Search : https://www.google.com/search?q=ene.sys
- ADA Info : (Ptolemy Tech Co.) or ASUS RGB driver or Gigabyte RGB driver
- Timestamp : Mon Oct 14 2019
- Image path: \??\D:\Programs I want\IObit Uninstaller\drivers\win10_amd64\IUFileFilter.sys
- Image name: IUFileFilter.sys
- Search : https://www.google.com/search?q=IUFileFilter.sys
- ADA Info : IObit Uninstaller driver (IObit)
- Timestamp : Wed Nov 6 2019
- Image path: \??\D:\Programs I want\IObit Uninstaller\drivers\win10_amd64\IURegistryFilter.sys
- Image name: IURegistryFilter.sys
- Search : https://www.google.com/search?q=IURegistryFilter.sys
- ADA Info : IObit Uninstaller driver (IObit Information Technology)
- Timestamp : Wed Nov 6 2019
- Image path: \SystemRoot\system32\drivers\AtihdWT6.sys
- Image name: AtihdWT6.sys
- Search : https://www.google.com/search?q=AtihdWT6.sys
- ADA Info : AMD High Definition Audio Function driver http://support.amd.com/
- Timestamp : Fri Nov 15 2019
- Image path: \SystemRoot\System32\Drivers\mbamswissarmy.sys
- Image name: mbamswissarmy.sys
- Search : https://www.google.com/search?q=mbamswissarmy.sys
- ADA Info : MalwareBytes Anti-Malware system driver https://www.malwarebytes.com/
- Timestamp : Wed Nov 20 2019
- Image path: \SystemRoot\System32\drivers\teVirtualMIDI64.sys
- Image name: teVirtualMIDI64.sys
- Search : https://www.google.com/search?q=teVirtualMIDI64.sys
- ADA Info : teVirtualMIDI - Virtual MIDI driver (Tobias Erichsen)
- Timestamp : Wed Nov 27 2019
- Image path: \??\C:\WINDOWS\temp\cpuz149\cpuz149_x64.sys
- Image name: cpuz149_x64.sys
- Search : https://www.google.com/search?q=cpuz149_x64.sys
- ADA Info : CPUID driver
- Timestamp : Thu Dec 5 2019
- Image path: \SystemRoot\System32\drivers\amdgpio2.sys
- Image name: amdgpio2.sys
- Search : https://www.google.com/search?q=amdgpio2.sys
- ADA Info : AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Timestamp : Tue Jan 14 2020
- Image path: \SystemRoot\System32\drivers\amdkmpfd.sys
- Image name: amdkmpfd.sys
- Search : https://www.google.com/search?q=amdkmpfd.sys
- ADA Info : AMD Kernel Miniport Filter driver
- Timestamp : Thu Jan 16 2020
- Image path: \SystemRoot\system32\DRIVERS\bcmwl63a.sys
- Image name: bcmwl63a.sys
- Search : https://www.google.com/search?q=bcmwl63a.sys
- ADA Info : Broadcom 802 11 Network Adapter Wireless driver http://www.broadcom.com/support/
- Timestamp : Mon Feb 10 2020
- Image path: \??\C:\Users\andre\AppData\Local\Temp\HWiNFO64A_150.SYS
- Image name: HWiNFO64A_150.SYS
- Search : https://www.google.com/search?q=HWiNFO64A_150.SYS
- ADA Info : HWiNFO driver https://www.hwinfo.com/
- Timestamp : Wed Feb 12 2020
- Image path: \??\C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\CorsairLLAccess64.sys
- Image name: CorsairLLAccess64.sys
- Search : https://www.google.com/search?q=CorsairLLAccess64.sys
- ADA Info : CORSAIR iCUE Software driver
- Timestamp : Fri Feb 14 2020
- Image path: \SystemRoot\System32\drivers\oculusvad.sys
- Image name: oculusvad.sys
- Search : https://www.google.com/search?q=oculusvad.sys
- ADA Info : Oculus VAD driver
- Timestamp : Tue Feb 25 2020
- Image path: \SystemRoot\System32\drivers\amdpsp.sys
- Image name: amdpsp.sys
- Search : https://www.google.com/search?q=amdpsp.sys
- ADA Info : Advanced Micro Devices, Inc http://support.amd.com/
- Timestamp : Fri Mar 6 2020
- Image path: \SystemRoot\System32\drivers\amdxe.sys
- Image name: amdxe.sys
- Search : https://www.google.com/search?q=amdxe.sys
- ADA Info : AMD Link Xinput Emulation driver
- Timestamp : Thu Mar 26 2020
- Image path: \SystemRoot\System32\drivers\AMDPCIDev.sys
- Image name: AMDPCIDev.sys
- Search : https://www.google.com/search?q=AMDPCIDev.sys
- ADA Info : Advanced Micro Devices PCI Device driver
- Timestamp : Fri Apr 10 2020
- Image path: \SystemRoot\system32\DRIVERS\CorsairGamingAudio64.sys
- Image name: CorsairGamingAudio64.sys
- Search : https://www.google.com/search?q=CorsairGamingAudio64.sys
- ADA Info : Corsair Gaming Audio 64-bit driver
- Timestamp : Thu May 7 2020
- Image path: \SystemRoot\System32\DriverStore\FileRepository\u0356013.inf_amd64_61ba7b1fb4cf4aec\B355483\amdkmdag.sys
- Image name: amdkmdag.sys
- Search : https://www.google.com/search?q=amdkmdag.sys
- ADA Info : AMD Graphics driver
- Timestamp : Mon May 25 2020
- Image path: \SystemRoot\System32\Drivers\MbamChameleon.sys
- Image name: MbamChameleon.sys
- Search : https://www.google.com/search?q=MbamChameleon.sys
- ADA Info : Malwarebytes Anti-Malware Chameleon driver https://www.malwarebytes.com/
- Timestamp : Thu Jun 4 2020
- Image path: \SystemRoot\System32\drivers\amdlog.sys
- Image name: amdlog.sys
- Search : https://www.google.com/search?q=amdlog.sys
- ADA Info : AMD LOG driver
- Timestamp : Tue Jun 9 2020
- Image path: \SystemRoot\System32\drivers\CorsairVBusDriver.sys
- Image name: CorsairVBusDriver.sys
- Search : https://www.google.com/search?q=CorsairVBusDriver.sys
- ADA Info : Corsair Virtual Device driver (Corsair Utility Engine) http://www.corsair.com/
- Timestamp : Tue Jun 30 2020
- Image path: \SystemRoot\System32\drivers\CorsairVHidDriver.sys
- Image name: CorsairVHidDriver.sys
- Search : https://www.google.com/search?q=CorsairVHidDriver.sys
- ADA Info : Corsair Virtual Device driver (Corsair Utility Engine) http://www.corsair.com/
- Timestamp : Tue Jun 30 2020
- ====================== Dump #5: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- amdppm.sys Processor Device Driver
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_amd_sata.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kd.dll Local Kernal Debugger (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate_AuthenticAMD.dll AMD Microcode Update Library (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- MpKslDrv.sys Microsoft Anti-malware Protection driver
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msgpioclx.sys GPIO Class Extension Driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- ndisuio.sys NDIS User mode I/O driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- nwifi.sys NativeWiFi Miniport Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- qwavedrv.sys Quality Windows Audio Video Experience (qWave) Support driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- serenum.sys Serial Port Enumerator (Microsoft)
- serial.sys Serial Device Driver
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- ucx01000.sys USB Controller Extension (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- usbser.sys USB Serial driver (Microsoft)
- USBSTOR.SYS USB Mass Storage Class driver (Microsoft)
- usbvideo.sys USB Video Class Driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwifibus.sys Virtual Wireless Bus driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- vwifimp.sys Virtual WiFi Miniport Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- winquic.sys QUIC Transport Protocol driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WpdUpFltr.sys Portable Device Upper Class Filter driver (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- WUDFRd.sys Windows Driver Foundation - User-mode Driver Framework Reflector driver (Microsoft)
- ====================== Dump #5: UNLOADED MODULES =======================
- fffff805`7b310000 fffff805`7b321000 MSKSSRV.sys
- fffff805`31ad0000 fffff805`31b20000 usbvideo.sys
- fffff805`31a60000 fffff805`31a6f000 Hamdrv.sys
- fffff805`7b260000 fffff805`7b26f000 hiber_storpo
- fffff805`7b270000 fffff805`7b28e000 hiber_amd_sa
- fffff805`7b290000 fffff805`7b2ae000 hiber_dumpfv
- fffff805`39740000 fffff805`3975e000 AtihdWT6.sys
- fffff805`7b220000 fffff805`7b231000 MSKSSRV.sys
- fffff805`7b290000 fffff805`7b3fa000 EasyAntiChea
- fffff805`31b20000 fffff805`31b31000 MSKSSRV.sys
- fffff805`31a10000 fffff805`31a1e000 WSDScan.sys
- fffff805`31a00000 fffff805`31a0e000 WSDPrint.sys
- fffff805`39610000 fffff805`3961a000 CorsairVHidD
- fffff805`325c0000 fffff805`325cf000 dump_storpor
- fffff805`31600000 fffff805`3161e000 dump_amd_sat
- fffff805`31640000 fffff805`3165e000 dump_dumpfve
- fffff805`2a2e0000 fffff805`2a2fc000 EhStorClass.
- fffff805`32360000 fffff805`3237e000 dam.sys
- fffff805`31660000 fffff805`31b79000 vgk.sys
- fffff805`29d90000 fffff805`29da1000 WdBoot.sys
- fffff805`29d80000 fffff805`29d89000 MbamElam.sys
- fffff805`2aeb0000 fffff805`2aec1000 hwpolicy.sys
- ====================== Dump #5: BIOS INFORMATION =======================
- [SMBIOS Data Tables v3.1]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 2505 bytes]
- [BIOS Information (Type 0) - Length 26 - Handle 0000h]
- Vendor American Megatrends Inc.
- BIOS Version 5406
- BIOS Starting Address Segment f000
- BIOS Release Date 11/13/2019
- BIOS ROM Size 1000000
- BIOS Characteristics
- 07: - PCI Supported
- 10: - APM Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 27: - Keyboard Services Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 32: - BIOS Vendor Reserved
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 5
- BIOS Minor Revision 13
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- Manufacturer System manufacturer
- Product Name System Product Name
- Version System Version
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- SKUNumber SKU
- [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
- Manufacturer ASUSTeK COMPUTER INC.
- Product ROG STRIX B350-F GAMING
- Version Rev X.0x
- Feature Flags 09h
- -815483168: - -815483120: - «
- ø
- Location Default string
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 22 - Handle 0003h]
- Manufacturer Default string
- Chassis Type Desktop
- Version Default string
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 3
- [Onboard Devices Information (Type 10) - Length 6 - Handle 0020h]
- Number of Devices 1
- 01: Type Video [enabled]
- [OEM Strings (Type 11) - Length 5 - Handle 0021h]
- Number of Strings 8
- 1 Default string
- 2 Default string
- 3 CHOPIN
- 4 Default string
- 5 FFFFFFFFFFFFF
- 6 FFFFFFFFFFFFF
- 7 FFFFFFFFFFFFF
- 8 Default string
- [System Configuration Options (Type 12) - Length 5 - Handle 0022h]
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 0026h]
- [Physical Memory Array (Type 16) - Length 23 - Handle 0027h]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 134217728KB
- Memory Error Inf Handle 0026h
- Number of Memory Devices 4
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0028h]
- Starting Address 00000000h
- Ending Address 0037ffffh
- Memory Array Handle 0027h
- Partition Width 02
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0029h]
- Starting Address 00400000h
- Ending Address 0107ffffh
- Memory Array Handle 0027h
- Partition Width 02
- [Cache Information (Type 7) - Length 19 - Handle 002ah]
- Socket Designation L1 - Cache
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0180h - 384K
- Installed Size 0180h - 384K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 002bh]
- Socket Designation L2 - Cache
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 0c00h - 3072K
- Installed Size 0c00h - 3072K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 002ch]
- Socket Designation L3 - Cache
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 8200h - 32768K
- Installed Size 8200h - 32768K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 16-way Set-Associative
- [Processor Information (Type 4) - Length 48 - Handle 002dh]
- Socket Designation AM4
- Processor Type Central Processor
- Processor Family 6bh - Specification Reserved
- Processor Manufacturer Advanced Micro Devices, Inc.
- Processor ID 100f8700fffb8b17
- Processor Version AMD Ryzen 5 3600 6-Core Processor
- Processor Voltage 8bh - 1.1V
- External Clock 100MHz
- Max Speed 4200MHz
- Current Speed 3600MHz
- Status Enabled Populated
- Processor Upgrade Specification Reserved
- L1 Cache Handle 002ah
- L2 Cache Handle 002bh
- L3 Cache Handle 002ch
- Part Number Unknown
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 002eh]
- [Memory Device (Type 17) - Length 40 - Handle 002fh]
- Physical Memory Array Handle 0027h
- Memory Error Info Handle 002eh
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator DIMM_A1
- Bank Locator BANK 0
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 3200MHz
- Manufacturer Corsair
- Part Number CMW16GX4M2C3200C16
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0030h]
- Starting Address 00000000h
- Ending Address 00ffffffh
- Memory Device Handle 002fh
- Mem Array Mapped Adr Handle 0029h
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 0031h]
- [Memory Device (Type 17) - Length 40 - Handle 0032h]
- Physical Memory Array Handle 0027h
- Memory Error Info Handle 0031h
- Form Factor 02h - Unknown
- Device Locator DIMM_A2
- Bank Locator BANK 1
- Memory Type 02h - Unknown
- Type Detail 0004h - Unknown
- Speed 0MHz
- Manufacturer Unknown
- Part Number Unknown
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 0033h]
- [Memory Device (Type 17) - Length 40 - Handle 0034h]
- Physical Memory Array Handle 0027h
- Memory Error Info Handle 0033h
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator DIMM_B1
- Bank Locator BANK 2
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 3200MHz
- Manufacturer Corsair
- Part Number CMW16GX4M2C3200C16
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0035h]
- Starting Address 00000000h
- Ending Address 00ffffffh
- Memory Device Handle 0034h
- Mem Array Mapped Adr Handle 0029h
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 0036h]
- [Memory Device (Type 17) - Length 40 - Handle 0037h]
- Physical Memory Array Handle 0027h
- Memory Error Info Handle 0036h
- Form Factor 02h - Unknown
- Device Locator DIMM_B2
- Bank Locator BANK 3
- Memory Type 02h - Unknown
- Type Detail 0004h - Unknown
- Speed 0MHz
- Manufacturer Unknown
- Part Number Unknown
- ========================== Dump #5: Extra #1 ===========================
- 0: kd> !verifier
- Verify Flags Level 0x00000000
- STANDARD FLAGS:
- [X] (0x00000000) Automatic Checks
- [ ] (0x00000001) Special pool
- [ ] (0x00000002) Force IRQL checking
- [ ] (0x00000008) Pool tracking
- [ ] (0x00000010) I/O verification
- [ ] (0x00000020) Deadlock detection
- [ ] (0x00000080) DMA checking
- [ ] (0x00000100) Security checks
- [ ] (0x00000800) Miscellaneous checks
- [ ] (0x00020000) DDI compliance checking
- ADDITIONAL FLAGS:
- [ ] (0x00000004) Randomized low resources simulation
- [ ] (0x00000200) Force pending I/O requests
- [ ] (0x00000400) IRP logging
- [ ] (0x00002000) Invariant MDL checking for stack
- [ ] (0x00004000) Invariant MDL checking for driver
- [ ] (0x00008000) Power framework delay fuzzing
- [ ] (0x00010000) Port/miniport interface checking
- [ ] (0x00040000) Systematic low resources simulation
- [ ] (0x00080000) DDI compliance checking (additional)
- [ ] (0x00200000) NDIS/WIFI verification
- [ ] (0x00800000) Kernel synchronization delay fuzzing
- [ ] (0x01000000) VM switch verification
- [ ] (0x02000000) Code integrity checks
- [X] Indicates flag is enabled
- Summary of All Verifier Statistics
- RaiseIrqls 0x0
- AcquireSpinLocks 0x0
- Synch Executions 0x0
- Trims 0x0
- Pool Allocations Attempted 0x0
- Pool Allocations Succeeded 0x0
- Pool Allocations Succeeded SpecialPool 0x0
- Pool Allocations With NO TAG 0x0
- Pool Allocations Failed 0x0
- Current paged pool allocations 0x0 for 00000000 bytes
- Peak paged pool allocations 0x0 for 00000000 bytes
- Current nonpaged pool allocations 0x0 for 00000000 bytes
- Peak nonpaged pool allocations 0x0 for 00000000 bytes
- ========================== Dump #5: Extra #2 ===========================
- 0: kd> !thread
- THREAD fffff80526d91400 Cid 0000.0000 Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor 0
- Not impersonating
- GetUlongFromAddress: unable to read from fffff80526c2ca14
- Owning Process fffff80526d8e9c0 Image: System Process
- Attached Process ffff9b8bb92b0080 Image: System
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 4942651
- Context Switch Count 162822339 IdealProcessor: 0
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address nt!KiIdleLoop (0xfffff805269c5e70)
- Stack Init fffff8052b46bc90 Current fffff8052b46bc20
- Base fffff8052b46c000 Limit fffff8052b466000 Call 0000000000000000
- Priority 0 BasePriority 0 PriorityDecrement 0 IoPriority 0 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- fffff805`2b46b4c8 fffff805`269d41e9 : 00000000`0000000a ffff9b93`ba88a9d8 00000000`000000ff 00000000`0000006e : nt!KeBugCheckEx
- fffff805`2b46b4d0 fffff805`269d0529 : 00000000`00000002 fffff805`2b46b7f8 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
- fffff805`2b46b610 fffff805`26af064d : 00000000`00000200 fffff805`2675d8f8 fffff805`235f9180 00000000`00000000 : nt!KiPageFault+0x469 (TrapFrame @ fffff805`2b46b610)
- fffff805`2b46b7a0 fffff805`269fc0b8 : 000092fe`cb6a86c6 ffff9b8b`bf139080 00000000`00000000 00000000`00000000 : nt!PpmIdleUpdateConcurrency+0x55
- fffff805`2b46b7e0 fffff805`2684a38e : 00000000`00000003 00000000`00000002 00000000`00000000 01d65f4f`f80d40f2 : nt!PpmIdleExecuteTransition+0x1b1b88
- fffff805`2b46bb00 fffff805`269c5eb4 : 00000000`00000000 fffff805`235f9180 ffff9b8b`ce5860c0 00000000`00000438 : nt!PoIdle+0x36e
- fffff805`2b46bc60 00000000`00000000 : fffff805`2b46c000 fffff805`2b466000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x44
- ========================================================================
- ======================= Dump #6: ANALYZE VERBOSE =======================
- ================ File: The BSOD that just happened.dmp =================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 18362 MP (12 procs) Free x64
- Kernel base = 0xfffff805`77600000 PsLoadedModuleList = 0xfffff805`77a48190
- Debug session time: Sat Jul 25 13:29:08.954 2020 (UTC - 4:00)
- System Uptime: 0 days 20:44:40.613
- BugCheck 3B, {c0000096, fffff805776a4784, ffff9081c96df930, 0}
- Probably caused by : memory_corruption
- Followup: memory_corruption
- SYSTEM_SERVICE_EXCEPTION (3b)
- An exception happened while executing a system service routine.
- Arguments:
- Arg1: 00000000c0000096, Exception code that caused the bugcheck
- Arg2: fffff805776a4784, Address of the instruction which caused the bugcheck
- Arg3: ffff9081c96df930, Address of the context record for the exception that caused the bugcheck
- Arg4: 0000000000000000, zero.
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- EXCEPTION_CODE: (NTSTATUS) 0xc0000096 - {EXCEPTION} Privileged instruction.
- FAULTING_IP:
- nt!KiSwapThread+cd4
- fffff805`776a4784 440f22c1 mov cr8,rcx
- CONTEXT: ffff9081c96df930 -- (.cxr 0xffff9081c96df930)
- rax=0000000000000000 rbx=0000000000000000 rcx=0000000000000080
- rdx=0000000000000000 rsi=ffffd18e96e17080 rdi=0000000000000000
- rip=fffff805776a4784 rsp=fffff8843c964860 rbp=ffff9081c9721180
- r8=0000000000000fa0 r9=fffff80577600000 r10=ffff9081c9680180
- r11=fffff8843c964858 r12=0000000000000000 r13=ffff9081c9721180
- r14=0000000000000001 r15=ffffd18e96e17180
- iopl=0 nv up ei pl zr na po nc
- cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050246
- nt!KiSwapThread+0xcd4:
- fffff805`776a4784 440f22c1 mov cr8,rcx
- Resetting default scope
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- BUGCHECK_STR: 0x3B
- PROCESS_NAME: MedalEncoder.exe
- CURRENT_IRQL: 2
- BAD_STACK_POINTER: ffff9081c96deff8
- LAST_CONTROL_TRANSFER: from fffff805776a3534 to fffff805776a4784
- STACK_TEXT:
- fffff884`3c964860 fffff805`776a3534 : ffffd18e`96e17080 ffffffff`00000000 bf48d332`00000000 00000000`00000000 : nt!KiSwapThread+0xcd4
- fffff884`3c964900 fffff805`776a2cd5 : 00000000`0000006d 00000000`00000000 00000000`00000001 00000000`00000000 : nt!KiCommitThreadWait+0x144
- fffff884`3c9649a0 fffff805`77c1248b : ffffd18e`9bbcc740 00000000`00000006 00000000`00000001 ffffd18e`9bbcc700 : nt!KeWaitForSingleObject+0x255
- fffff884`3c964a80 fffff805`777d3c18 : ffffd18e`96e17080 000000be`ccb3b6f8 fffff884`3c964b18 ffffffff`ff671b60 : nt!NtWaitForSingleObject+0x10b
- fffff884`3c964b00 00007ffb`5cedc0f4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
- 000000be`ccb3b6c8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffb`5cedc0f4
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !win32kbase
- ffffa7ed43e97809-ffffa7ed43e9780e 6 bytes - win32kbase!DirectComposition::CAnimationMarshaler::SetReferenceProperty+49
- [ ff 15 a1 ef 19 00:e8 92 ea 20 00 90 ]
- ffffa7ed43e97879-ffffa7ed43e9787a 2 bytes - win32kbase!SfmSignalTokenEvent+19 (+0x70)
- [ 48 ff:4c 8b ]
- ffffa7ed43e97880-ffffa7ed43e97883 4 bytes - win32kbase!SfmSignalTokenEvent+20 (+0x07)
- [ 0f 1f 44 00:e8 9b eb 20 ]
- ffffa7ed43e98985-ffffa7ed43e98986 2 bytes - win32kbase!GreSfmDwmShutdown+35 (+0x1105)
- [ 48 ff:4c 8b ]
- ffffa7ed43e9898c-ffffa7ed43e9898f 4 bytes - win32kbase!GreSfmDwmShutdown+3c (+0x07)
- [ 0f 1f 44 00:e8 8f da 20 ]
- ffffa7ed43e98995-ffffa7ed43e98996 2 bytes - win32kbase!GreSfmDwmShutdown+45 (+0x09)
- [ 48 ff:4c 8b ]
- ffffa7ed43e9899c-ffffa7ed43e9899f 4 bytes - win32kbase!GreSfmDwmShutdown+4c (+0x07)
- [ 0f 1f 44 00:e8 7f da 20 ]
- 24 errors : !win32kbase (ffffa7ed43e97809-ffffa7ed43e9899f)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- STACK_COMMAND: .cxr 0xffff9081c96df930 ; kb
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-07-25T17:29:08.000Z
- SUITE_MASK: 784
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #6: 3RD PARTY DRIVERS ======================
- Aug 22 2012 - AsIO.sys - ASUS Input Output driver http://www.asus.com/
- Mar 19 2015 - amd_sata.sys - AMD SATA Controller AHCI Device driver http://support.amd.com/
- Mar 19 2015 - amd_xata.sys - AMD Stor Filter driver http://support.amd.com/
- Mar 31 2015 - HWiNFO64A.SYS - HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
- Mar 14 2016 - amdgpio3.sys - AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Aug 02 2017 - Oculus_ViGEmBus.sys - Oculus Virtual Gamepad Emulation Bus driver
- Feb 12 2018 - msio64.sys - MSI Gaming App driver
- Mar 26 2019 - RTKVHD64.sys - Realtek Audio System driver https://www.realtek.com/en/
- Apr 09 2019 - AsIO2.sys - Asus Input Output driver
- Apr 22 2019 - GLCKIO2.sys - ASUS RGB driver
- Apr 22 2019 - OCULUSUD.sys - Oculus VR Headset driver
- Apr 25 2019 - mbae64.sys - Malwarebytes driver https://www.malwarebytes.com/
- Jun 06 2019 - IUProcessFilter.sys - IObit Uninstaller driver (IObit Information Technology)
- Sep 05 2019 - e1r65x64.sys - Intel(R) Gigabit Adapter NDIS 6.x driver https://downloadcenter.intel.com/
- Oct 14 2019 - ene.sys - (Ptolemy Tech Co.) or ASUS RGB driver or Gigabyte RGB driver
- Nov 06 2019 - IUFileFilter.sys - IObit Uninstaller driver (IObit)
- Nov 06 2019 - IURegistryFilter.sys - IObit Uninstaller driver (IObit Information Technology)
- Nov 15 2019 - AtihdWT6.sys - AMD High Definition Audio Function driver http://support.amd.com/
- Nov 20 2019 - mbamswissarmy.sys - MalwareBytes Anti-Malware system driver https://www.malwarebytes.com/
- Nov 27 2019 - teVirtualMIDI64.sys - teVirtualMIDI - Virtual MIDI driver (Tobias Erichsen)
- Dec 05 2019 - cpuz149_x64.sys - CPUID driver
- Jan 14 2020 - amdgpio2.sys - AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Jan 16 2020 - amdkmpfd.sys - AMD Kernel Miniport Filter driver
- Feb 10 2020 - bcmwl63a.sys - Broadcom 802 11 Network Adapter Wireless driver http://www.broadcom.com/support/
- Feb 12 2020 - HWiNFO64A_150.SYS - HWiNFO driver https://www.hwinfo.com/
- Feb 14 2020 - CorsairLLAccess64.sys - CORSAIR iCUE Software driver
- Mar 06 2020 - amdpsp.sys - Advanced Micro Devices, Inc http://support.amd.com/
- Mar 26 2020 - amdxe.sys - AMD Link Xinput Emulation driver
- Apr 10 2020 - AMDPCIDev.sys - Advanced Micro Devices PCI Device driver
- May 07 2020 - CorsairGamingAudio64.sys - Corsair Gaming Audio 64-bit driver
- May 28 2020 - oculusvad.sys - Oculus VAD driver
- Jun 04 2020 - MbamChameleon.sys - Malwarebytes Anti-Malware Chameleon driver https://www.malwarebytes.com/
- Jun 09 2020 - amdlog.sys - AMD LOG driver
- Jun 10 2020 - amdkmdag.sys - AMD Graphics driver
- Jun 22 2020 - mwac.sys - Malwarebytes Web Access Control http://www.malwarebytes.org/
- Jun 30 2020 - CorsairVBusDriver.sys - Corsair Virtual Device driver (Corsair Utility Engine) http://www.corsair.com/
- Jun 30 2020 - CorsairVHidDriver.sys - Corsair Virtual Device driver (Corsair Utility Engine) http://www.corsair.com/
- Jul 07 2020 - mbam.sys - Malwarebytes Anti-Malware https://www.malwarebytes.com/
- Jul 17 2020 - farflt.sys - Malwarebytes Anti-RansomWare SDK http://www.malwarebytes.org/
- ================== Dump #6: 3RD PARTY DRIVERS (FULL) ===================
- Image path: \SystemRoot\SysWow64\drivers\AsIO.sys
- Image name: AsIO.sys
- Search : https://www.google.com/search?q=AsIO.sys
- ADA Info : ASUS Input Output driver http://www.asus.com/
- Timestamp : Wed Aug 22 2012
- Image path: \SystemRoot\System32\drivers\amd_sata.sys
- Image name: amd_sata.sys
- Search : https://www.google.com/search?q=amd_sata.sys
- ADA Info : AMD SATA Controller AHCI Device driver http://support.amd.com/
- Timestamp : Thu Mar 19 2015
- Image path: \SystemRoot\System32\drivers\amd_xata.sys
- Image name: amd_xata.sys
- Search : https://www.google.com/search?q=amd_xata.sys
- ADA Info : AMD Stor Filter driver http://support.amd.com/
- Timestamp : Thu Mar 19 2015
- Image path: \??\C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS
- Image name: HWiNFO64A.SYS
- Search : https://www.google.com/search?q=HWiNFO64A.SYS
- ADA Info : HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
- Timestamp : Tue Mar 31 2015
- Image path: \SystemRoot\System32\drivers\amdgpio3.sys
- Image name: amdgpio3.sys
- Search : https://www.google.com/search?q=amdgpio3.sys
- ADA Info : AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Timestamp : Mon Mar 14 2016
- Image path: \SystemRoot\System32\drivers\Oculus_ViGEmBus.sys
- Image name: Oculus_ViGEmBus.sys
- Search : https://www.google.com/search?q=Oculus_ViGEmBus.sys
- ADA Info : Oculus Virtual Gamepad Emulation Bus driver
- Timestamp : Wed Aug 2 2017
- Image path: \??\C:\Program Files\Patriot\Aac_Patriot Viper RGB\msio64.sys
- Image name: msio64.sys
- Search : https://www.google.com/search?q=msio64.sys
- ADA Info : MSI Gaming App driver
- Timestamp : Mon Feb 12 2018
- Image path: \SystemRoot\system32\drivers\RTKVHD64.sys
- Image name: RTKVHD64.sys
- Search : https://www.google.com/search?q=RTKVHD64.sys
- ADA Info : Realtek Audio System driver https://www.realtek.com/en/
- Timestamp : Tue Mar 26 2019
- Image path: \??\C:\WINDOWS\system32\drivers\AsIO2.sys
- Image name: AsIO2.sys
- Search : https://www.google.com/search?q=AsIO2.sys
- ADA Info : Asus Input Output driver
- Timestamp : Tue Apr 9 2019
- Image path: \??\C:\WINDOWS\system32\drivers\GLCKIO2.sys
- Image name: GLCKIO2.sys
- Search : https://www.google.com/search?q=GLCKIO2.sys
- ADA Info : ASUS RGB driver
- Timestamp : Mon Apr 22 2019
- Image path: \SystemRoot\System32\drivers\OCULUSUD.sys
- Image name: OCULUSUD.sys
- Search : https://www.google.com/search?q=OCULUSUD.sys
- ADA Info : Oculus VR Headset driver
- Timestamp : Mon Apr 22 2019
- Image path: \??\C:\WINDOWS\system32\drivers\mbae64.sys
- Image name: mbae64.sys
- Search : https://www.google.com/search?q=mbae64.sys
- ADA Info : Malwarebytes driver https://www.malwarebytes.com/
- Timestamp : Thu Apr 25 2019
- Image path: \??\D:\Programs I want\IObit Uninstaller\drivers\win10_amd64\IUProcessFilter.sys
- Image name: IUProcessFilter.sys
- Search : https://www.google.com/search?q=IUProcessFilter.sys
- ADA Info : IObit Uninstaller driver (IObit Information Technology)
- Timestamp : Thu Jun 6 2019
- Image path: \SystemRoot\system32\DRIVERS\e1r65x64.sys
- Image name: e1r65x64.sys
- Search : https://www.google.com/search?q=e1r65x64.sys
- ADA Info : Intel(R) Gigabit Adapter NDIS 6.x driver https://downloadcenter.intel.com/
- Timestamp : Thu Sep 5 2019
- Image path: \??\C:\WINDOWS\system32\drivers\ene.sys
- Image name: ene.sys
- Search : https://www.google.com/search?q=ene.sys
- ADA Info : (Ptolemy Tech Co.) or ASUS RGB driver or Gigabyte RGB driver
- Timestamp : Mon Oct 14 2019
- Image path: \??\D:\Programs I want\IObit Uninstaller\drivers\win10_amd64\IUFileFilter.sys
- Image name: IUFileFilter.sys
- Search : https://www.google.com/search?q=IUFileFilter.sys
- ADA Info : IObit Uninstaller driver (IObit)
- Timestamp : Wed Nov 6 2019
- Image path: \??\D:\Programs I want\IObit Uninstaller\drivers\win10_amd64\IURegistryFilter.sys
- Image name: IURegistryFilter.sys
- Search : https://www.google.com/search?q=IURegistryFilter.sys
- ADA Info : IObit Uninstaller driver (IObit Information Technology)
- Timestamp : Wed Nov 6 2019
- Image path: \SystemRoot\system32\drivers\AtihdWT6.sys
- Image name: AtihdWT6.sys
- Search : https://www.google.com/search?q=AtihdWT6.sys
- ADA Info : AMD High Definition Audio Function driver http://support.amd.com/
- Timestamp : Fri Nov 15 2019
- Image path: \SystemRoot\System32\Drivers\mbamswissarmy.sys
- Image name: mbamswissarmy.sys
- Search : https://www.google.com/search?q=mbamswissarmy.sys
- ADA Info : MalwareBytes Anti-Malware system driver https://www.malwarebytes.com/
- Timestamp : Wed Nov 20 2019
- Image path: \SystemRoot\System32\drivers\teVirtualMIDI64.sys
- Image name: teVirtualMIDI64.sys
- Search : https://www.google.com/search?q=teVirtualMIDI64.sys
- ADA Info : teVirtualMIDI - Virtual MIDI driver (Tobias Erichsen)
- Timestamp : Wed Nov 27 2019
- Image path: \??\C:\WINDOWS\temp\cpuz149\cpuz149_x64.sys
- Image name: cpuz149_x64.sys
- Search : https://www.google.com/search?q=cpuz149_x64.sys
- ADA Info : CPUID driver
- Timestamp : Thu Dec 5 2019
- Image path: \SystemRoot\System32\drivers\amdgpio2.sys
- Image name: amdgpio2.sys
- Search : https://www.google.com/search?q=amdgpio2.sys
- ADA Info : AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Timestamp : Tue Jan 14 2020
- Image path: \SystemRoot\System32\drivers\amdkmpfd.sys
- Image name: amdkmpfd.sys
- Search : https://www.google.com/search?q=amdkmpfd.sys
- ADA Info : AMD Kernel Miniport Filter driver
- Timestamp : Thu Jan 16 2020
- Image path: \SystemRoot\system32\DRIVERS\bcmwl63a.sys
- Image name: bcmwl63a.sys
- Search : https://www.google.com/search?q=bcmwl63a.sys
- ADA Info : Broadcom 802 11 Network Adapter Wireless driver http://www.broadcom.com/support/
- Timestamp : Mon Feb 10 2020
- Image path: \??\C:\Users\andre\AppData\Local\Temp\HWiNFO64A_150.SYS
- Image name: HWiNFO64A_150.SYS
- Search : https://www.google.com/search?q=HWiNFO64A_150.SYS
- ADA Info : HWiNFO driver https://www.hwinfo.com/
- Timestamp : Wed Feb 12 2020
- Image path: \??\C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\CorsairLLAccess64.sys
- Image name: CorsairLLAccess64.sys
- Search : https://www.google.com/search?q=CorsairLLAccess64.sys
- ADA Info : CORSAIR iCUE Software driver
- Timestamp : Fri Feb 14 2020
- Image path: \SystemRoot\System32\drivers\amdpsp.sys
- Image name: amdpsp.sys
- Search : https://www.google.com/search?q=amdpsp.sys
- ADA Info : Advanced Micro Devices, Inc http://support.amd.com/
- Timestamp : Fri Mar 6 2020
- Image path: \SystemRoot\System32\drivers\amdxe.sys
- Image name: amdxe.sys
- Search : https://www.google.com/search?q=amdxe.sys
- ADA Info : AMD Link Xinput Emulation driver
- Timestamp : Thu Mar 26 2020
- Image path: \SystemRoot\System32\drivers\AMDPCIDev.sys
- Image name: AMDPCIDev.sys
- Search : https://www.google.com/search?q=AMDPCIDev.sys
- ADA Info : Advanced Micro Devices PCI Device driver
- Timestamp : Fri Apr 10 2020
- Image path: \SystemRoot\system32\DRIVERS\CorsairGamingAudio64.sys
- Image name: CorsairGamingAudio64.sys
- Search : https://www.google.com/search?q=CorsairGamingAudio64.sys
- ADA Info : Corsair Gaming Audio 64-bit driver
- Timestamp : Thu May 7 2020
- Image path: \SystemRoot\System32\drivers\oculusvad.sys
- Image name: oculusvad.sys
- Search : https://www.google.com/search?q=oculusvad.sys
- ADA Info : Oculus VAD driver
- Timestamp : Thu May 28 2020
- Image path: \SystemRoot\System32\Drivers\MbamChameleon.sys
- Image name: MbamChameleon.sys
- Search : https://www.google.com/search?q=MbamChameleon.sys
- ADA Info : Malwarebytes Anti-Malware Chameleon driver https://www.malwarebytes.com/
- Timestamp : Thu Jun 4 2020
- Image path: \SystemRoot\System32\drivers\amdlog.sys
- Image name: amdlog.sys
- Search : https://www.google.com/search?q=amdlog.sys
- ADA Info : AMD LOG driver
- Timestamp : Tue Jun 9 2020
- Image path: \SystemRoot\System32\DriverStore\FileRepository\c0356490.inf_amd64_d882b4516d9b62a0\B356520\amdkmdag.sys
- Image name: amdkmdag.sys
- Search : https://www.google.com/search?q=amdkmdag.sys
- ADA Info : AMD Graphics driver
- Timestamp : Wed Jun 10 2020
- Image path: \SystemRoot\system32\DRIVERS\mwac.sys
- Image name: mwac.sys
- Search : https://www.google.com/search?q=mwac.sys
- ADA Info : Malwarebytes Web Access Control http://www.malwarebytes.org/
- Timestamp : Mon Jun 22 2020
- Image path: \SystemRoot\System32\drivers\CorsairVBusDriver.sys
- Image name: CorsairVBusDriver.sys
- Search : https://www.google.com/search?q=CorsairVBusDriver.sys
- ADA Info : Corsair Virtual Device driver (Corsair Utility Engine) http://www.corsair.com/
- Timestamp : Tue Jun 30 2020
- Image path: \SystemRoot\System32\drivers\CorsairVHidDriver.sys
- Image name: CorsairVHidDriver.sys
- Search : https://www.google.com/search?q=CorsairVHidDriver.sys
- ADA Info : Corsair Virtual Device driver (Corsair Utility Engine) http://www.corsair.com/
- Timestamp : Tue Jun 30 2020
- Image path: \??\C:\WINDOWS\system32\DRIVERS\mbam.sys
- Image name: mbam.sys
- Search : https://www.google.com/search?q=mbam.sys
- ADA Info : Malwarebytes Anti-Malware https://www.malwarebytes.com/
- Timestamp : Tue Jul 7 2020
- Image path: \SystemRoot\system32\DRIVERS\farflt.sys
- Image name: farflt.sys
- Search : https://www.google.com/search?q=farflt.sys
- ADA Info : Malwarebytes Anti-RansomWare SDK http://www.malwarebytes.org/
- Timestamp : Fri Jul 17 2020
- ====================== Dump #6: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- amdppm.sys Processor Device Driver
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_amd_sata.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kd.dll Local Kernal Debugger (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate_AuthenticAMD.dll AMD Microcode Update Library (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msgpioclx.sys GPIO Class Extension Driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- ndisuio.sys NDIS User mode I/O driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- nwifi.sys NativeWiFi Miniport Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- serenum.sys Serial Port Enumerator (Microsoft)
- serial.sys Serial Device Driver
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- ucx01000.sys USB Controller Extension (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- usbser.sys USB Serial driver (Microsoft)
- usbvideo.sys USB Video Class Driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwifibus.sys Virtual Wireless Bus driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- vwifimp.sys Virtual WiFi Miniport Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- winquic.sys QUIC Transport Protocol driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- WSDPrint.sys Web Services Print Device driver (Microsoft)
- WSDScan.sys Web Service Based Scan Device driver (Microsoft)
- ====================== Dump #6: UNLOADED MODULES =======================
- fffff805`c9d60000 fffff805`c9d71000 MSKSSRV.sys
- fffff805`c9d10000 fffff805`c9d60000 usbvideo.sys
- fffff805`c9e70000 fffff805`c9e7f000 hiber_storpo
- fffff805`c9ea0000 fffff805`c9ebe000 hiber_amd_sa
- fffff805`c9ec0000 fffff805`c9ede000 hiber_dumpfv
- fffff805`8be00000 fffff805`8be1e000 AtihdWT6.sys
- fffff805`c9e30000 fffff805`c9e41000 MSKSSRV.sys
- fffff805`c9e10000 fffff805`c9e21000 MSKSSRV.sys
- fffff805`c9d60000 fffff805`c9d71000 MSKSSRV.sys
- fffff805`85850000 fffff805`85c04000 OCULUSUD.sys
- fffff805`c9ea0000 fffff805`c9ebc000 usbser.sys
- fffff805`c9d10000 fffff805`c9d60000 usbvideo.sys
- fffff805`c9d60000 fffff805`c9d71000 MSKSSRV.sys
- fffff805`c9e70000 fffff805`c9e7c000 cpuz143_x64.
- fffff805`c9e30000 fffff805`c9e49000 monitor.sys
- fffff805`8be90000 fffff805`90296000 amdkmdag.sys
- fffff805`85cf0000 fffff805`85d09000 monitor.sys
- fffff805`85850000 fffff805`85c04000 OCULUSUD.sys
- fffff805`86850000 fffff805`8686c000 usbser.sys
- fffff805`c9d10000 fffff805`c9d60000 usbvideo.sys
- fffff805`c9e10000 fffff805`c9e21000 MSKSSRV.sys
- fffff805`7cf60000 fffff805`7cfc8000 WdFilter.sys
- fffff805`c9dd0000 fffff805`c9de1000 MpKslDrv.sys
- fffff805`c9bb0000 fffff805`c9bc6000 WdNisDrv.sys
- fffff805`c9d60000 fffff805`c9d71000 MSKSSRV.sys
- fffff805`8bd80000 fffff805`8bd8a000 CorsairVHidD
- fffff805`c9b80000 fffff805`c9b8e000 WSDScan.sys
- fffff805`c9b70000 fffff805`c9b7e000 WSDPrint.sys
- fffff805`846f0000 fffff805`846ff000 dump_storpor
- fffff805`84720000 fffff805`8473e000 dump_amd_sat
- fffff805`84760000 fffff805`8477e000 dump_dumpfve
- fffff805`849b0000 fffff805`849ce000 dam.sys
- fffff805`7c990000 fffff805`7c9a1000 WdBoot.sys
- fffff805`7c980000 fffff805`7c989000 MbamElam.sys
- fffff805`7dab0000 fffff805`7dac1000 hwpolicy.sys
- ====================== Dump #6: BIOS INFORMATION =======================
- [SMBIOS Data Tables v3.1]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 2505 bytes]
- [BIOS Information (Type 0) - Length 26 - Handle 0000h]
- Vendor American Megatrends Inc.
- BIOS Version 5406
- BIOS Starting Address Segment f000
- BIOS Release Date 11/13/2019
- BIOS ROM Size 1000000
- BIOS Characteristics
- 07: - PCI Supported
- 10: - APM Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 27: - Keyboard Services Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 32: - BIOS Vendor Reserved
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 5
- BIOS Minor Revision 13
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- Manufacturer System manufacturer
- Product Name System Product Name
- Version System Version
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- SKUNumber SKU
- [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
- Manufacturer ASUSTeK COMPUTER INC.
- Product ROG STRIX B350-F GAMING
- Version Rev X.0x
- Feature Flags 09h
- -814696736: - -814696688: - «
- ø
- Location Default string
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 22 - Handle 0003h]
- Manufacturer Default string
- Chassis Type Desktop
- Version Default string
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 3
- [Onboard Devices Information (Type 10) - Length 6 - Handle 0020h]
- Number of Devices 1
- 01: Type Video [enabled]
- [OEM Strings (Type 11) - Length 5 - Handle 0021h]
- Number of Strings 8
- 1 Default string
- 2 Default string
- 3 CHOPIN
- 4 Default string
- 5 FFFFFFFFFFFFF
- 6 FFFFFFFFFFFFF
- 7 FFFFFFFFFFFFF
- 8 Default string
- [System Configuration Options (Type 12) - Length 5 - Handle 0022h]
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 0026h]
- [Physical Memory Array (Type 16) - Length 23 - Handle 0027h]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 134217728KB
- Memory Error Inf Handle 0026h
- Number of Memory Devices 4
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0028h]
- Starting Address 00000000h
- Ending Address 0037ffffh
- Memory Array Handle 0027h
- Partition Width 02
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0029h]
- Starting Address 00400000h
- Ending Address 0107ffffh
- Memory Array Handle 0027h
- Partition Width 02
- [Cache Information (Type 7) - Length 19 - Handle 002ah]
- Socket Designation L1 - Cache
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0180h - 384K
- Installed Size 0180h - 384K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 002bh]
- Socket Designation L2 - Cache
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 0c00h - 3072K
- Installed Size 0c00h - 3072K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 002ch]
- Socket Designation L3 - Cache
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 8200h - 32768K
- Installed Size 8200h - 32768K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 16-way Set-Associative
- [Processor Information (Type 4) - Length 48 - Handle 002dh]
- Socket Designation AM4
- Processor Type Central Processor
- Processor Family 6bh - Specification Reserved
- Processor Manufacturer Advanced Micro Devices, Inc.
- Processor ID 100f8700fffb8b17
- Processor Version AMD Ryzen 5 3600 6-Core Processor
- Processor Voltage 8bh - 1.1V
- External Clock 100MHz
- Max Speed 4200MHz
- Current Speed 3600MHz
- Status Enabled Populated
- Processor Upgrade Specification Reserved
- L1 Cache Handle 002ah
- L2 Cache Handle 002bh
- L3 Cache Handle 002ch
- Part Number Unknown
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 002eh]
- [Memory Device (Type 17) - Length 40 - Handle 002fh]
- Physical Memory Array Handle 0027h
- Memory Error Info Handle 002eh
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator DIMM_A1
- Bank Locator BANK 0
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 3200MHz
- Manufacturer Corsair
- Part Number CMW16GX4M2C3200C16
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0030h]
- Starting Address 00000000h
- Ending Address 00ffffffh
- Memory Device Handle 002fh
- Mem Array Mapped Adr Handle 0029h
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 0031h]
- [Memory Device (Type 17) - Length 40 - Handle 0032h]
- Physical Memory Array Handle 0027h
- Memory Error Info Handle 0031h
- Form Factor 02h - Unknown
- Device Locator DIMM_A2
- Bank Locator BANK 1
- Memory Type 02h - Unknown
- Type Detail 0004h - Unknown
- Speed 0MHz
- Manufacturer Unknown
- Part Number Unknown
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 0033h]
- [Memory Device (Type 17) - Length 40 - Handle 0034h]
- Physical Memory Array Handle 0027h
- Memory Error Info Handle 0033h
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator DIMM_B1
- Bank Locator BANK 2
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 3200MHz
- Manufacturer Corsair
- Part Number CMW16GX4M2C3200C16
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0035h]
- Starting Address 00000000h
- Ending Address 00ffffffh
- Memory Device Handle 0034h
- Mem Array Mapped Adr Handle 0029h
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 0036h]
- [Memory Device (Type 17) - Length 40 - Handle 0037h]
- Physical Memory Array Handle 0027h
- Memory Error Info Handle 0036h
- Form Factor 02h - Unknown
- Device Locator DIMM_B2
- Bank Locator BANK 3
- Memory Type 02h - Unknown
- Type Detail 0004h - Unknown
- Speed 0MHz
- Manufacturer Unknown
- Part Number Unknown
- ========================== Dump #6: Extra #1 ===========================
- 9: kd> !verifier
- Verify Flags Level 0x00000000
- STANDARD FLAGS:
- [X] (0x00000000) Automatic Checks
- [ ] (0x00000001) Special pool
- [ ] (0x00000002) Force IRQL checking
- [ ] (0x00000008) Pool tracking
- [ ] (0x00000010) I/O verification
- [ ] (0x00000020) Deadlock detection
- [ ] (0x00000080) DMA checking
- [ ] (0x00000100) Security checks
- [ ] (0x00000800) Miscellaneous checks
- [ ] (0x00020000) DDI compliance checking
- ADDITIONAL FLAGS:
- [ ] (0x00000004) Randomized low resources simulation
- [ ] (0x00000200) Force pending I/O requests
- [ ] (0x00000400) IRP logging
- [ ] (0x00002000) Invariant MDL checking for stack
- [ ] (0x00004000) Invariant MDL checking for driver
- [ ] (0x00008000) Power framework delay fuzzing
- [ ] (0x00010000) Port/miniport interface checking
- [ ] (0x00040000) Systematic low resources simulation
- [ ] (0x00080000) DDI compliance checking (additional)
- [ ] (0x00200000) NDIS/WIFI verification
- [ ] (0x00800000) Kernel synchronization delay fuzzing
- [ ] (0x01000000) VM switch verification
- [ ] (0x02000000) Code integrity checks
- [X] Indicates flag is enabled
- Summary of All Verifier Statistics
- RaiseIrqls 0x0
- AcquireSpinLocks 0x0
- Synch Executions 0x0
- Trims 0x0
- Pool Allocations Attempted 0x0
- Pool Allocations Succeeded 0x0
- Pool Allocations Succeeded SpecialPool 0x0
- Pool Allocations With NO TAG 0x0
- Pool Allocations Failed 0x0
- Current paged pool allocations 0x0 for 00000000 bytes
- Peak paged pool allocations 0x0 for 00000000 bytes
- Current nonpaged pool allocations 0x0 for 00000000 bytes
- Peak nonpaged pool allocations 0x0 for 00000000 bytes
- ========================== Dump #6: Extra #2 ===========================
- 9: kd> !thread
- THREAD ffffd18e96e17080 Cid 4758.4634 Teb: 000000bec9933000 Win32Thread: ffffd18ea04dd140 RUNNING on processor 9
- Not impersonating
- GetUlongFromAddress: unable to read from fffff80577a2ca14
- Owning Process ffffd18e9e4e9080 Image: MedalEncoder.exe
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 4779559
- Context Switch Count 785504 IdealProcessor: 0
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address 0x00007ffaf3d96a88
- Stack Init fffff8843c964c90 Current fffff8843c9646e0
- Base fffff8843c965000 Limit fffff8843c95f000 Call 0000000000000000
- Priority 15 BasePriority 15 PriorityDecrement 0 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- ffff9081`c96deff8 fffff805`777d41e9 : 00000000`0000003b 00000000`c0000096 fffff805`776a4784 ffff9081`c96df930 : nt!KeBugCheckEx
- ffff9081`c96df000 fffff805`777d363c : fffff884`3c964628 ffff9081`c96df930 fffff805`77b414ec fffff884`3c964a00 : nt!KiBugCheckDispatch+0x69
- ffff9081`c96df140 fffff805`777cb1b2 : fffff805`77b11000 fffff805`77600000 0005e320`00ab7000 00000000`0010001f : nt!KiSystemServiceHandler+0x7c
- ffff9081`c96df180 fffff805`77689875 : 00000000`00000000 00000000`00000000 ffff9081`c96df6f0 00007fff`ffff0000 : nt!RtlpExecuteHandlerForException+0x12
- ffff9081`c96df1b0 fffff805`7768de0e : fffff884`3c964628 ffff9081`c96dfe30 fffff884`3c964628 00000000`00000000 : nt!RtlDispatchException+0x4a5
- ffff9081`c96df900 fffff805`777c3232 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDispatchException+0x16e
- ffff9081`c96dffb0 fffff805`777c3200 : fffff805`777d4316 00000000`00000006 00000008`00000001 00000000`00000000 : nt!KxExceptionDispatchOnExceptionStack+0x12 (TrapFrame @ ffff9081`c96dfe70)
- fffff884`3c9644e8 fffff805`777d4316 : 00000000`00000006 00000008`00000001 00000000`00000000 00000000`00000000 : nt!KiExceptionDispatchOnExceptionStackContinue
- fffff884`3c9644f0 fffff805`777d00a0 : ffff9081`c9680180 fffff805`777c958f 00000067`b4bbbdff 00000000`00000001 : nt!KiExceptionDispatch+0x116
- fffff884`3c9646d0 fffff805`776a4784 : ffff9081`00000000 00000000`00000000 00000000`00000000 ffffd18e`96e17180 : nt!KiGeneralProtectionFault+0x320 (TrapFrame @ fffff884`3c9646d0)
- fffff884`3c964860 fffff805`776a3534 : ffffd18e`96e17080 ffffffff`00000000 bf48d332`00000000 00000000`00000000 : nt!KiSwapThread+0xcd4
- fffff884`3c964900 fffff805`776a2cd5 : 00000000`0000006d 00000000`00000000 00000000`00000001 00000000`00000000 : nt!KiCommitThreadWait+0x144
- fffff884`3c9649a0 fffff805`77c1248b : ffffd18e`9bbcc740 00000000`00000006 00000000`00000001 ffffd18e`9bbcc700 : nt!KeWaitForSingleObject+0x255
- fffff884`3c964a80 fffff805`777d3c18 : ffffd18e`96e17080 000000be`ccb3b6f8 fffff884`3c964b18 ffffffff`ff671b60 : nt!NtWaitForSingleObject+0x10b
- fffff884`3c964b00 00007ffb`5cedc0f4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28 (TrapFrame @ fffff884`3c964b00)
- 000000be`ccb3b6c8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffb`5cedc0f4
Advertisement
Add Comment
Please, Sign In to add comment