Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ========================== AUTO DUMP ANALYZER ==========================
- Auto Dump Analyzer
- Version: 0.91
- Time to analyze file(s): 00 hours and 10 minutes and 01 seconds
- ================================= BIOS =================================
- VENDOR: American Megatrends Inc.
- VERSION: P4.20
- DATE: 10/31/2019
- ============================= MOTHERBOARD ==============================
- MANUFACTURER: ASRock
- PRODUCT: Z370 Extreme4
- ================================= RAM ==================================
- Size Speed Manufacturer Part No.
- -------------- -------------- ------------------- ----------------------
- 0MHz
- 8192MB 3200MHz 029E CMK16GX4M2B3200C16
- 0MHz
- 8192MB 3200MHz 029E CMK16GX4M2B3200C16
- ================================= CPU ==================================
- Processor Version: Intel(R) Core(TM) i7-8700K CPU @ 3.70GHz
- COUNT: c
- MHZ: 3696
- VENDOR: GenuineIntel
- FAMILY: 6
- MODEL: 9e
- STEPPING: a
- MICROCODE: 6,9e,a,0 (F,M,S,R) SIG: C6'00000000 (cache) C6'00000000 (init)
- ================================== OS ==================================
- Product: WinNt, suite: TerminalServer SingleUserTS Personal
- BUILD_VERSION: 10.0.19041.330 (WinBuild.160101.0800)
- BUILD: 19041
- SERVICEPACK: 330
- PLATFORM_TYPE: x64
- NAME: Windows 10
- EDITION: Windows 10 WinNt TerminalServer SingleUserTS Personal
- BUILD_TIMESTAMP: unknown_date
- BUILDDATESTAMP: 160101.0800
- BUILDLAB: WinBuild
- BUILDOSVER: 10.0.19041.330
- =============================== DEBUGGER ===============================
- Microsoft (R) Windows Debugger Version 10.0.14321.1024 AMD64
- Copyright (c) Microsoft Corporation. All rights reserved.
- =============================== COMMENTS ===============================
- * Information gathered from different dump files may be different. If
- Windows updates between two dump files, two or more OS versions may
- be shown above.
- * If the user updates the BIOS between dump files, two or more versions
- and dates may be shown above.
- * More RAM information can be found below in a full BIOS section.
- ========================================================================
- ======================= Dump #1: ANALYZE VERBOSE =======================
- ======================= File: 071120-4421-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 19041 MP (12 procs) Free x64
- Kernel base = 0xfffff801`30e00000 PsLoadedModuleList = 0xfffff801`31a2a2b0
- Debug session time: Sat Jul 11 00:24:48.274 2020 (UTC - 4:00)
- System Uptime: 1 days 0:08:23.941
- BugCheck 139, {3, ffff8a830dda6a90, ffff8a830dda69e8, 0}
- Probably caused by : dxgmms2.sys ( dxgmms2!VIDMM_SEGMENT::MarkResourcesForEviction+117 )
- Followup: MachineOwner
- KERNEL_SECURITY_CHECK_FAILURE (139)
- A kernel component has corrupted a critical data structure. The corruption
- could potentially allow a malicious user to gain control of this machine.
- Arguments:
- Arg1: 0000000000000003, A LIST_ENTRY has been corrupted (i.e. double remove).
- Arg2: ffff8a830dda6a90, Address of the trap frame for the exception that caused the bugcheck
- Arg3: ffff8a830dda69e8, Address of the exception record for the exception that caused the bugcheck
- Arg4: 0000000000000000, Reserved
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- DUMP_FILE_ATTRIBUTES: 0x8
- Kernel Generated Triage Dump
- TRAP_FRAME: ffff8a830dda6a90 -- (.trap 0xffff8a830dda6a90)
- NOTE: The trap frame does not contain all registers.
- Some register values may be zeroed or incorrect.
- rax=ffffbe0fc8412ca8 rbx=0000000000000000 rcx=0000000000000003
- rdx=ffffbe0fca219ec8 rsi=0000000000000000 rdi=0000000000000000
- rip=fffff801478633d3 rsp=ffff8a830dda6c20 rbp=0000000000000000
- r8=ffffad8239fd38a8 r9=ffffbe0fc407af50 r10=0000000000000000
- r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=0000000000000000
- iopl=0 nv up ei ng nz na po cy
- dxgmms2!VIDMM_SEGMENT::MarkResourcesForEviction+0x117:
- fffff801`478633d3 cd29 int 29h
- Resetting default scope
- EXCEPTION_RECORD: ffff8a830dda69e8 -- (.exr 0xffff8a830dda69e8)
- ExceptionAddress: fffff801478633d3 (dxgmms2!VIDMM_SEGMENT::MarkResourcesForEviction+0x0000000000000117)
- ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
- ExceptionFlags: 00000001
- NumberParameters: 1
- Parameter[0]: 0000000000000003
- Subcode: 0x3 FAST_FAIL_CORRUPT_LIST_ENTRY
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: LIST_ENTRY_CORRUPT
- BUGCHECK_STR: 0x139
- PROCESS_NAME: System
- CURRENT_IRQL: 0
- ERROR_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.
- EXCEPTION_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.
- EXCEPTION_CODE_STR: c0000409
- EXCEPTION_PARAMETER1: 0000000000000003
- LAST_CONTROL_TRANSFER: from fffff801311ef929 to fffff801311dda20
- STACK_TEXT:
- ffff8a83`0dda6768 fffff801`311ef929 : 00000000`00000139 00000000`00000003 ffff8a83`0dda6a90 ffff8a83`0dda69e8 : nt!KeBugCheckEx
- ffff8a83`0dda6770 fffff801`311efd50 : ffff8160`e9ce728f 00000000`00000004 ffff8a83`0dda69c8 00000000`00000000 : nt!KiBugCheckDispatch+0x69
- ffff8a83`0dda68b0 fffff801`311ee0e3 : ffffad82`392264f0 00000000`00000002 ffff8a83`00000007 ffff8a83`0dda6af0 : nt!KiFastFailDispatch+0xd0
- ffff8a83`0dda6a90 fffff801`478633d3 : ffffbe0f`c8412b30 00000000`00000000 ffffbe0f`c8412b30 00000000`00000000 : nt!KiRaiseSecurityCheckFailure+0x323
- ffff8a83`0dda6c20 fffff801`478643c0 : ffffbe0f`c8412b30 ffffad82`3b1c9000 ffffad82`3d39f010 00000000`dcf6e000 : dxgmms2!VIDMM_SEGMENT::MarkResourcesForEviction+0x117
- ffff8a83`0dda6c50 fffff801`47860c29 : ffffad82`3d39f010 ffffad82`3b1c9000 ffffbe0f`cac8a500 ffffbe0f`c8412b30 : dxgmms2!VIDMM_GLOBAL::NotifyAllocationEviction+0x98
- ffff8a83`0dda6c80 fffff801`47860681 : ffffbe0f`eb20cf60 00000000`00000000 ffffbe0f`cac8a5b0 00000000`0000000d : dxgmms2!VIDMM_GLOBAL::EvictOneAllocation+0x59
- ffff8a83`0dda6cd0 fffff801`4785ff50 : ffffbe0f`eb20cf60 00000000`dcf9a000 00000000`00000002 00000000`0025bcd0 : dxgmms2!VIDMM_PAGE_TABLE::EvictPageTable+0x81
- ffff8a83`0dda6d10 fffff801`47865b02 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`0025bc00 : dxgmms2!VIDMM_PAGE_TABLE::DestroyPageTable+0x30
- ffff8a83`0dda6d90 fffff801`478967c2 : 00000000`00000000 ffffbe0f`cac8a5b0 00000000`00000001 00000000`00000000 : dxgmms2!VIDMM_PAGE_DIRECTORY::CommitVirtualAddressRange+0xb42
- ffff8a83`0dda6f00 fffff801`47864f40 : ffffad82`39fd38a8 ffffbe0f`cac8a5b0 ffffad82`33c45e00 00000000`00000000 : dxgmms2!VIDMM_PAGE_DIRECTORY::CommitVirtualAddressRange+0x31802
- ffff8a83`0dda7070 fffff801`47868369 : ffffad82`336d7000 ffffad82`3b0f3280 00000000`00000000 00000000`00000000 : dxgmms2!CVirtualAddressAllocator::UncommitVirtualAddressRange+0xf4
- ffff8a83`0dda7180 fffff801`47871008 : 00000000`01001002 fffff801`47801ee7 ffffbe0f`c97ed848 fffff801`00000003 : dxgmms2!VIDMM_GLOBAL::MakeOneVirtualAddressRangeNotResident+0x165
- ffff8a83`0dda7610 fffff801`4787209b : ffffbe0f`c969fd50 ffff8a83`0dda7700 ffffbe0f`c969fe70 ffffad82`39b62dd0 : dxgmms2!VIDMM_GLOBAL::MakeVirtualAddressRangeNotResident+0xc0
- ffff8a83`0dda7670 fffff801`4786e388 : ffffbe0f`c97ed810 ffff8a83`0dda77c0 ffffad82`3b1c9000 00000000`00000000 : dxgmms2!VIDMM_MEMORY_SEGMENT::EvictResource+0x23b
- ffff8a83`0dda76c0 fffff801`478879e8 : ffffad82`3b1c9000 ffffad82`3b1d2c10 ffffad82`3b1c9000 ffffad82`3b1c9000 : dxgmms2!VIDMM_GLOBAL::ProcessDeferredCommand+0x8f8
- ffff8a83`0dda7900 fffff801`47891b89 : ffffbe0f`bffbf490 ffffad82`3b0f3200 00000000`00000000 00000000`02821d00 : dxgmms2!VIDMM_WORKER_THREAD::Run+0xb78
- ffff8a83`0dda7ae0 fffff801`31146715 : ffffad82`3b0f3280 fffff801`47891b80 ffffbe0f`bffbf490 000fa4ef`bd9bbfff : dxgmms2!VidMmWorkerThreadProc+0x9
- ffff8a83`0dda7b10 fffff801`311e5078 : ffffd401`100f6180 ffffad82`3b0f3280 fffff801`311466c0 004d005c`00730070 : nt!PspSystemThreadStartup+0x55
- ffff8a83`0dda7b60 00000000`00000000 : ffff8a83`0dda8000 ffff8a83`0dda1000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
- STACK_COMMAND: kb
- THREAD_SHA1_HASH_MOD_FUNC: c2717c3ba2b4d45c1594bee98f05014860a4b53b
- THREAD_SHA1_HASH_MOD_FUNC_OFFSET: bb24661e86bf9ff690401ebb13207b9e8819099e
- THREAD_SHA1_HASH_MOD: a2d08543f6bac7a0719ac5a57897ce755fbdd2ef
- FOLLOWUP_IP:
- dxgmms2!VIDMM_SEGMENT::MarkResourcesForEviction+117
- fffff801`478633d3 cd29 int 29h
- FAULT_INSTR_CODE: cccc29cd
- SYMBOL_STACK_INDEX: 4
- SYMBOL_NAME: dxgmms2!VIDMM_SEGMENT::MarkResourcesForEviction+117
- FOLLOWUP_NAME: MachineOwner
- MODULE_NAME: dxgmms2
- IMAGE_NAME: dxgmms2.sys
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- IMAGE_VERSION: 10.0.19041.207
- BUCKET_ID_FUNC_OFFSET: 117
- FAILURE_BUCKET_ID: 0x139_3_dxgmms2!VIDMM_SEGMENT::MarkResourcesForEviction
- BUCKET_ID: 0x139_3_dxgmms2!VIDMM_SEGMENT::MarkResourcesForEviction
- PRIMARY_PROBLEM_CLASS: 0x139_3_dxgmms2!VIDMM_SEGMENT::MarkResourcesForEviction
- TARGET_TIME: 2020-07-11T04:24:48.000Z
- SUITE_MASK: 784
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:0x139_3_dxgmms2!vidmm_segment::markresourcesforeviction
- FAILURE_ID_HASH: {6d4aa933-0df0-13cc-0e2a-045a4d7f377d}
- Followup: MachineOwner
- ====================== Dump #1: 3RD PARTY DRIVERS ======================
- Oct 09 2015 - wdcsam64.sys - Western Digital SCSI Arcitecture Model (SAM) WDM driver https://support.wdc.com/
- Jan 21 2019 - imaucxhpal.sys - MA-USB (UCX) HPAL driver
- Jan 21 2019 - iwigig.sys - WiGig MAC driver (Intel)
- Apr 04 2019 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
- May 07 2019 - e1d68x64.sys - Intel(R) Gigabit Adapter driver
- Jun 09 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- Jun 21 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- ================== Dump #1: 3RD PARTY DRIVERS (FULL) ===================
- Image name: wdcsam64.sys
- Search : https://www.google.com/search?q=wdcsam64.sys
- ADA Info : Western Digital SCSI Arcitecture Model (SAM) WDM driver https://support.wdc.com/
- Timestamp : Fri Oct 9 2015
- Image name: imaucxhpal.sys
- Search : https://www.google.com/search?q=imaucxhpal.sys
- ADA Info : MA-USB (UCX) HPAL driver
- Timestamp : Mon Jan 21 2019
- Image name: iwigig.sys
- Search : https://www.google.com/search?q=iwigig.sys
- ADA Info : WiGig MAC driver (Intel)
- Timestamp : Mon Jan 21 2019
- Image name: TeeDriverW8x64.sys
- Search : https://www.google.com/search?q=TeeDriverW8x64.sys
- ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Timestamp : Thu Apr 4 2019
- Image name: e1d68x64.sys
- Search : https://www.google.com/search?q=e1d68x64.sys
- ADA Info : Intel(R) Gigabit Adapter driver
- Timestamp : Tue May 7 2019
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Tue Jun 9 2020
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Sun Jun 21 2020
- ====================== Dump #1: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- acpipagr.sys ACPI Processor Aggregator Device driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CimFS.SYS Consumer IR Class Driver for eHome (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storport.sys Provides disk access during crash dump file generation (Microsoft)
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HdAudio.sys High Definition Audio Function driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- intelppm.sys Processor Device Driver (Microsoft)
- IntelTA.sys Intel Telemetry Driver
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kdcom.dll Kernel Debugger HW Extension DLL (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate.dll Media Center Update (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb10.sys Longhorn SMB Downlevel SubRdr (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msquic.sys Windows QUIC Driver
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndiscap.sys Microsoft NDIS Packet Capture Filter Driver
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdpvideominiport.sys RDP Video Miniport driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- serenum.sys Serial Port Enumerator (Microsoft)
- serial.sys Serial Device Driver
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- stornvme.sys NVM Express Storport Miniport driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- ucx01000.sys USB Controller Extension (Microsoft)
- udfs.sys UDF File System driver (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- USBSTOR.SYS USB Mass Storage Class driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WpdUpFltr.sys Portable Device Upper Class Filter driver (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- WUDFRd.sys Windows Driver Foundation - User-mode Driver Framework Reflector driver (Microsoft)
- ====================== Dump #1: UNLOADED MODULES =======================
- fffff801`483b0000 fffff801`483bf000 hiber_storpo
- fffff801`483c0000 fffff801`483f3000 hiber_storah
- fffff801`48400000 fffff801`4841e000 hiber_dumpfv
- fffff801`48340000 fffff801`4834f000 hiber_storpo
- fffff801`48350000 fffff801`48383000 hiber_storah
- fffff801`48390000 fffff801`483ae000 hiber_dumpfv
- fffff801`47380000 fffff801`4738f000 dump_storpor
- fffff801`46c00000 fffff801`46c33000 dump_storahc
- fffff801`46c60000 fffff801`46c7e000 dump_dumpfve
- fffff801`49530000 fffff801`49585000 WUDFRd.sys
- fffff801`475f0000 fffff801`4760c000 dam.sys
- fffff801`33600000 fffff801`33611000 WdBoot.sys
- fffff801`346b0000 fffff801`346c0000 hwpolicy.sys
- ====================== Dump #1: BIOS INFORMATION =======================
- [SMBIOS Data Tables v3.1]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 2808 bytes]
- [BIOS Information (Type 0) - Length 26 - Handle 0000h]
- Vendor American Megatrends Inc.
- BIOS Version P4.20
- BIOS Starting Address Segment f000
- BIOS Release Date 10/31/2019
- BIOS ROM Size 1000000
- BIOS Characteristics
- 07: - PCI Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 27: - Keyboard Services Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 32: - BIOS Vendor Reserved
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 5
- BIOS Minor Revision 12
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
- Manufacturer ASRock
- Product Z370 Extreme4
- Version
- Feature Flags 09h
- -1660307744: - -1660307696: - ÷7?Öý
- Location
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 22 - Handle 0003h]
- Chassis Type Desktop
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 3
- [OEM Strings (Type 11) - Length 5 - Handle 000dh]
- Number of Strings 1
- [Physical Memory Array (Type 16) - Length 23 - Handle 0010h]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 67108864KB
- Number of Memory Devices 4
- [Memory Device (Type 17) - Length 40 - Handle 0011h]
- Physical Memory Array Handle 0010h
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM0
- Bank Locator BANK 0
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Device (Type 17) - Length 40 - Handle 0012h]
- Physical Memory Array Handle 0010h
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM1
- Bank Locator BANK 1
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 3200MHz
- Manufacturer 029E
- Part Number CMK16GX4M2B3200C16
- [Memory Device (Type 17) - Length 40 - Handle 0013h]
- Physical Memory Array Handle 0010h
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM0
- Bank Locator BANK 2
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Device (Type 17) - Length 40 - Handle 0014h]
- Physical Memory Array Handle 0010h
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM1
- Bank Locator BANK 3
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 3200MHz
- Manufacturer 029E
- Part Number CMK16GX4M2B3200C16
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0015h]
- Starting Address 00000000h
- Ending Address 00ffffffh
- Memory Array Handle 0010h
- Partition Width 02
- [Cache Information (Type 7) - Length 27 - Handle 0016h]
- Socket Designation L1 Cache
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0180h - 384K
- Installed Size 0180h - 384K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type ParitySingle-Bit ECC
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 27 - Handle 0017h]
- Socket Designation L2 Cache
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 0600h - 1536K
- Installed Size 0600h - 1536K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Unified
- Associativity 4-way Set-Associative
- [Cache Information (Type 7) - Length 27 - Handle 0018h]
- Socket Designation L3 Cache
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 3000h - 12288K
- Installed Size 3000h - 12288K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 16-way Set-Associative
- [Processor Information (Type 4) - Length 48 - Handle 0019h]
- Socket Designation CPUSocket
- Processor Type Central Processor
- Processor Family c6h - Specification Reserved
- Processor Manufacturer Intel(R) Corporation
- Processor ID ea060900fffbebbf
- Processor Version Intel(R) Core(TM) i7-8700K CPU @ 3.70GHz
- Processor Voltage 8ah - 1.0V
- External Clock 100MHz
- Max Speed 8300MHz
- Current Speed 3700MHz
- Status Enabled Populated
- Processor Upgrade Specification Reserved
- L1 Cache Handle 0016h
- L2 Cache Handle 0017h
- L3 Cache Handle 0018h
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 001ah]
- Starting Address 00000000h
- Ending Address 007fffffh
- Memory Device Handle 0012h
- Mem Array Mapped Adr Handle 0015h
- Partition Row Position 01
- Interleave Position 01
- Interleave Data Depth 02
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 001bh]
- Starting Address 00800000h
- Ending Address 00ffffffh
- Memory Device Handle 0014h
- Mem Array Mapped Adr Handle 0015h
- Partition Row Position 01
- Interleave Position 02
- Interleave Data Depth 02
- ========================== Dump #1: Extra #1 ===========================
- 0: kd> !verifier
- fffff80131a2a6c0: Unable to get verifier list.
- ========================== Dump #1: Extra #2 ===========================
- 0: kd> !thread
- THREAD ffffad823b0f3280 Cid 0004.02e8 Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor 0
- Not impersonating
- GetUlongFromAddress: unable to read from fffff80131a1143c
- Owning Process ffffad823349c040 Image: System
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 5561852
- Context Switch Count 2501996 IdealProcessor: 8
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address dxgmms2!VidMmWorkerThreadProc (0xfffff80147891b80)
- Stack Init ffff8a830dda7b90 Current ffff8a830dda7520
- Base ffff8a830dda8000 Limit ffff8a830dda1000 Call 0000000000000000
- Priority 15 BasePriority 15 PriorityDecrement 0 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- ffff8a83`0dda6768 fffff801`311ef929 : 00000000`00000139 00000000`00000003 ffff8a83`0dda6a90 ffff8a83`0dda69e8 : nt!KeBugCheckEx
- ffff8a83`0dda6770 fffff801`311efd50 : ffff8160`e9ce728f 00000000`00000004 ffff8a83`0dda69c8 00000000`00000000 : nt!KiBugCheckDispatch+0x69
- ffff8a83`0dda68b0 fffff801`311ee0e3 : ffffad82`392264f0 00000000`00000002 ffff8a83`00000007 ffff8a83`0dda6af0 : nt!KiFastFailDispatch+0xd0
- ffff8a83`0dda6a90 fffff801`478633d3 : ffffbe0f`c8412b30 00000000`00000000 ffffbe0f`c8412b30 00000000`00000000 : nt!KiRaiseSecurityCheckFailure+0x323 (TrapFrame @ ffff8a83`0dda6a90)
- ffff8a83`0dda6c20 fffff801`478643c0 : ffffbe0f`c8412b30 ffffad82`3b1c9000 ffffad82`3d39f010 00000000`dcf6e000 : dxgmms2!VIDMM_SEGMENT::MarkResourcesForEviction+0x117
- ffff8a83`0dda6c50 fffff801`47860c29 : ffffad82`3d39f010 ffffad82`3b1c9000 ffffbe0f`cac8a500 ffffbe0f`c8412b30 : dxgmms2!VIDMM_GLOBAL::NotifyAllocationEviction+0x98
- ffff8a83`0dda6c80 fffff801`47860681 : ffffbe0f`eb20cf60 00000000`00000000 ffffbe0f`cac8a5b0 00000000`0000000d : dxgmms2!VIDMM_GLOBAL::EvictOneAllocation+0x59
- ffff8a83`0dda6cd0 fffff801`4785ff50 : ffffbe0f`eb20cf60 00000000`dcf9a000 00000000`00000002 00000000`0025bcd0 : dxgmms2!VIDMM_PAGE_TABLE::EvictPageTable+0x81
- ffff8a83`0dda6d10 fffff801`47865b02 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`0025bc00 : dxgmms2!VIDMM_PAGE_TABLE::DestroyPageTable+0x30
- ffff8a83`0dda6d90 fffff801`478967c2 : 00000000`00000000 ffffbe0f`cac8a5b0 00000000`00000001 00000000`00000000 : dxgmms2!VIDMM_PAGE_DIRECTORY::CommitVirtualAddressRange+0xb42
- ffff8a83`0dda6f00 fffff801`47864f40 : ffffad82`39fd38a8 ffffbe0f`cac8a5b0 ffffad82`33c45e00 00000000`00000000 : dxgmms2!VIDMM_PAGE_DIRECTORY::CommitVirtualAddressRange+0x31802
- ffff8a83`0dda7070 fffff801`47868369 : ffffad82`336d7000 ffffad82`3b0f3280 00000000`00000000 00000000`00000000 : dxgmms2!CVirtualAddressAllocator::UncommitVirtualAddressRange+0xf4
- ffff8a83`0dda7180 fffff801`47871008 : 00000000`01001002 fffff801`47801ee7 ffffbe0f`c97ed848 fffff801`00000003 : dxgmms2!VIDMM_GLOBAL::MakeOneVirtualAddressRangeNotResident+0x165
- ffff8a83`0dda7610 fffff801`4787209b : ffffbe0f`c969fd50 ffff8a83`0dda7700 ffffbe0f`c969fe70 ffffad82`39b62dd0 : dxgmms2!VIDMM_GLOBAL::MakeVirtualAddressRangeNotResident+0xc0
- ffff8a83`0dda7670 fffff801`4786e388 : ffffbe0f`c97ed810 ffff8a83`0dda77c0 ffffad82`3b1c9000 00000000`00000000 : dxgmms2!VIDMM_MEMORY_SEGMENT::EvictResource+0x23b
- ffff8a83`0dda76c0 fffff801`478879e8 : ffffad82`3b1c9000 ffffad82`3b1d2c10 ffffad82`3b1c9000 ffffad82`3b1c9000 : dxgmms2!VIDMM_GLOBAL::ProcessDeferredCommand+0x8f8
- ffff8a83`0dda7900 fffff801`47891b89 : ffffbe0f`bffbf490 ffffad82`3b0f3200 00000000`00000000 00000000`02821d00 : dxgmms2!VIDMM_WORKER_THREAD::Run+0xb78
- ffff8a83`0dda7ae0 fffff801`31146715 : ffffad82`3b0f3280 fffff801`47891b80 ffffbe0f`bffbf490 000fa4ef`bd9bbfff : dxgmms2!VidMmWorkerThreadProc+0x9
- ffff8a83`0dda7b10 fffff801`311e5078 : ffffd401`100f6180 ffffad82`3b0f3280 fffff801`311466c0 004d005c`00730070 : nt!PspSystemThreadStartup+0x55
- ffff8a83`0dda7b60 00000000`00000000 : ffff8a83`0dda8000 ffff8a83`0dda1000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
- ========================================================================
- ======================= Dump #2: ANALYZE VERBOSE =======================
- ======================= File: 071020-4828-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 19041 MP (12 procs) Free x64
- Kernel base = 0xfffff801`27c00000 PsLoadedModuleList = 0xfffff801`2882a2b0
- Debug session time: Fri Jul 10 00:14:37.025 2020 (UTC - 4:00)
- System Uptime: 0 days 12:19:45.692
- BugCheck 1A, {9696, ffffa68009da7bd0, 0, 0}
- Probably caused by : memory_corruption ( nt!MiGetTopLevelPfn+1c664b )
- Followup: MachineOwner
- MEMORY_MANAGEMENT (1a)
- # Any other values for parameter 1 must be individually examined.
- Arguments:
- Arg1: 0000000000009696, The subtype of the bugcheck.
- Arg2: ffffa68009da7bd0
- Arg3: 0000000000000000
- Arg4: 0000000000000000
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- DUMP_FILE_ATTRIBUTES: 0x8
- Kernel Generated Triage Dump
- BUGCHECK_STR: 0x1a_9696
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
- PROCESS_NAME: System
- CURRENT_IRQL: 2
- LAST_CONTROL_TRANSFER: from fffff801280250eb to fffff80127fdda20
- STACK_TEXT:
- ffff8288`1c11f7e8 fffff801`280250eb : 00000000`0000001a 00000000`00009696 ffffa680`09da7bd0 00000000`00000000 : nt!KeBugCheckEx
- ffff8288`1c11f7f0 fffff801`2803d6b6 : ffffa680`09da7bd0 7fffffff`ffffffff 00080000`00359bac ffffa680`00000001 : nt!MiGetTopLevelPfn+0x1c664b
- ffff8288`1c11f880 fffff801`27f6fa0e : fffff801`28851508 ffffa680`09da7bd0 00000000`00000000 00000000`00000001 : nt!MiRestoreTransitionPte+0x1a4d36
- ffff8288`1c11f8f0 fffff801`28158191 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MiRemoveLowestPriorityStandbyPage+0x1ce
- ffff8288`1c11f990 fffff801`281583e3 : fffff801`28850ac0 00000000`00000000 fffff801`00000000 00000000`0000027d : nt!MiPruneStandbyPages+0x265
- ffff8288`1c11fa20 fffff801`27e33f25 : ffffc00a`93d42040 fffff801`28158350 ffffc00a`8ae93a20 fffff801`28852360 : nt!MiRebalanceZeroFreeLists+0x93
- ffff8288`1c11fa70 fffff801`27f46715 : ffffc00a`93d42040 00000000`00000080 ffffc00a`8ae9d040 00700020`00000001 : nt!ExpWorkerThread+0x105
- ffff8288`1c11fb10 fffff801`27fe5078 : ffffe281`fbc80180 ffffc00a`93d42040 fffff801`27f466c0 0065006c`00500020 : nt!PspSystemThreadStartup+0x55
- ffff8288`1c11fb60 00000000`00000000 : ffff8288`1c120000 ffff8288`1c119000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
- STACK_COMMAND: kb
- THREAD_SHA1_HASH_MOD_FUNC: 89698d946d4044f2adeb0f1b0c8506e740b95753
- THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 9424b9466b92d84c3132398bdb83b6b8856a14f8
- THREAD_SHA1_HASH_MOD: 9f457f347057f10e1df248e166a3e95e6570ecfe
- FOLLOWUP_IP:
- nt!MiGetTopLevelPfn+1c664b
- fffff801`280250eb cc int 3
- FAULT_INSTR_CODE: e92ccdcc
- SYMBOL_STACK_INDEX: 1
- SYMBOL_NAME: nt!MiGetTopLevelPfn+1c664b
- FOLLOWUP_NAME: MachineOwner
- MODULE_NAME: nt
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- IMAGE_VERSION: 10.0.19041.330
- IMAGE_NAME: memory_corruption
- BUCKET_ID_FUNC_OFFSET: 1c664b
- FAILURE_BUCKET_ID: 0x1a_9696_nt!MiGetTopLevelPfn
- BUCKET_ID: 0x1a_9696_nt!MiGetTopLevelPfn
- PRIMARY_PROBLEM_CLASS: 0x1a_9696_nt!MiGetTopLevelPfn
- TARGET_TIME: 2020-07-10T04:14:37.000Z
- SUITE_MASK: 784
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:0x1a_9696_nt!migettoplevelpfn
- FAILURE_ID_HASH: {d4280011-e8e7-b961-d005-2ab957e4b051}
- Followup: MachineOwner
- ====================== Dump #2: 3RD PARTY DRIVERS ======================
- Oct 09 2015 - wdcsam64.sys - Western Digital SCSI Arcitecture Model (SAM) WDM driver https://support.wdc.com/
- Jan 21 2019 - imaucxhpal.sys - MA-USB (UCX) HPAL driver
- Jan 21 2019 - iwigig.sys - WiGig MAC driver (Intel)
- Apr 04 2019 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
- May 07 2019 - e1d68x64.sys - Intel(R) Gigabit Adapter driver
- Jun 09 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- Jun 21 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- ================== Dump #2: 3RD PARTY DRIVERS (FULL) ===================
- Image name: wdcsam64.sys
- Search : https://www.google.com/search?q=wdcsam64.sys
- ADA Info : Western Digital SCSI Arcitecture Model (SAM) WDM driver https://support.wdc.com/
- Timestamp : Fri Oct 9 2015
- Image name: imaucxhpal.sys
- Search : https://www.google.com/search?q=imaucxhpal.sys
- ADA Info : MA-USB (UCX) HPAL driver
- Timestamp : Mon Jan 21 2019
- Image name: iwigig.sys
- Search : https://www.google.com/search?q=iwigig.sys
- ADA Info : WiGig MAC driver (Intel)
- Timestamp : Mon Jan 21 2019
- Image name: TeeDriverW8x64.sys
- Search : https://www.google.com/search?q=TeeDriverW8x64.sys
- ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Timestamp : Thu Apr 4 2019
- Image name: e1d68x64.sys
- Search : https://www.google.com/search?q=e1d68x64.sys
- ADA Info : Intel(R) Gigabit Adapter driver
- Timestamp : Tue May 7 2019
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Tue Jun 9 2020
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Sun Jun 21 2020
- ====================== Dump #2: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- acpipagr.sys ACPI Processor Aggregator Device driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CimFS.SYS Consumer IR Class Driver for eHome (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storport.sys Provides disk access during crash dump file generation (Microsoft)
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HdAudio.sys High Definition Audio Function driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- intelppm.sys Processor Device Driver (Microsoft)
- IntelTA.sys Intel Telemetry Driver
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kdcom.dll Kernel Debugger HW Extension DLL (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate.dll Media Center Update (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb10.sys Longhorn SMB Downlevel SubRdr (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msquic.sys Windows QUIC Driver
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndiscap.sys Microsoft NDIS Packet Capture Filter Driver
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdpvideominiport.sys RDP Video Miniport driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- serenum.sys Serial Port Enumerator (Microsoft)
- serial.sys Serial Device Driver
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- stornvme.sys NVM Express Storport Miniport driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- ucx01000.sys USB Controller Extension (Microsoft)
- udfs.sys UDF File System driver (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- USBSTOR.SYS USB Mass Storage Class driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WpdUpFltr.sys Portable Device Upper Class Filter driver (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- WUDFRd.sys Windows Driver Foundation - User-mode Driver Framework Reflector driver (Microsoft)
- ====================== Dump #2: UNLOADED MODULES =======================
- fffff801`3f490000 fffff801`3f49f000 hiber_storpo
- fffff801`29b30000 fffff801`29b63000 hiber_storah
- fffff801`29b70000 fffff801`29b8e000 hiber_dumpfv
- fffff801`3f470000 fffff801`3f481000 MpKslDrv.sys
- fffff801`3f470000 fffff801`3f47f000 hiber_storpo
- fffff801`3f480000 fffff801`3f4b3000 hiber_storah
- fffff801`3fbd0000 fffff801`3fbee000 hiber_dumpfv
- fffff801`3fbe0000 fffff801`3fbef000 dump_storpor
- fffff801`3f440000 fffff801`3f473000 dump_storahc
- fffff801`3f4a0000 fffff801`3f4be000 dump_dumpfve
- fffff801`427b0000 fffff801`42805000 WUDFRd.sys
- fffff801`3fdf0000 fffff801`3fe0c000 dam.sys
- fffff801`2be00000 fffff801`2be11000 WdBoot.sys
- fffff801`2ceb0000 fffff801`2cec0000 hwpolicy.sys
- ====================== Dump #2: BIOS INFORMATION =======================
- [SMBIOS Data Tables v3.1]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 2808 bytes]
- [BIOS Information (Type 0) - Length 26 - Handle 0000h]
- Vendor American Megatrends Inc.
- BIOS Version P4.20
- BIOS Starting Address Segment f000
- BIOS Release Date 10/31/2019
- BIOS ROM Size 1000000
- BIOS Characteristics
- 07: - PCI Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 27: - Keyboard Services Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 32: - BIOS Vendor Reserved
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 5
- BIOS Minor Revision 12
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
- Manufacturer ASRock
- Product Z370 Extreme4
- Version
- Feature Flags 09h
- -1625966880: - -1625966832: - ÷7?Öý
- Location
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 22 - Handle 0003h]
- Chassis Type Desktop
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 3
- [OEM Strings (Type 11) - Length 5 - Handle 000dh]
- Number of Strings 1
- [Physical Memory Array (Type 16) - Length 23 - Handle 0010h]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 67108864KB
- Number of Memory Devices 4
- [Memory Device (Type 17) - Length 40 - Handle 0011h]
- Physical Memory Array Handle 0010h
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM0
- Bank Locator BANK 0
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Device (Type 17) - Length 40 - Handle 0012h]
- Physical Memory Array Handle 0010h
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM1
- Bank Locator BANK 1
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 3200MHz
- Manufacturer 029E
- Part Number CMK16GX4M2B3200C16
- [Memory Device (Type 17) - Length 40 - Handle 0013h]
- Physical Memory Array Handle 0010h
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM0
- Bank Locator BANK 2
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Device (Type 17) - Length 40 - Handle 0014h]
- Physical Memory Array Handle 0010h
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM1
- Bank Locator BANK 3
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 3200MHz
- Manufacturer 029E
- Part Number CMK16GX4M2B3200C16
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0015h]
- Starting Address 00000000h
- Ending Address 00ffffffh
- Memory Array Handle 0010h
- Partition Width 02
- [Cache Information (Type 7) - Length 27 - Handle 0016h]
- Socket Designation L1 Cache
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0180h - 384K
- Installed Size 0180h - 384K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type ParitySingle-Bit ECC
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 27 - Handle 0017h]
- Socket Designation L2 Cache
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 0600h - 1536K
- Installed Size 0600h - 1536K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Unified
- Associativity 4-way Set-Associative
- [Cache Information (Type 7) - Length 27 - Handle 0018h]
- Socket Designation L3 Cache
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 3000h - 12288K
- Installed Size 3000h - 12288K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 16-way Set-Associative
- [Processor Information (Type 4) - Length 48 - Handle 0019h]
- Socket Designation CPUSocket
- Processor Type Central Processor
- Processor Family c6h - Specification Reserved
- Processor Manufacturer Intel(R) Corporation
- Processor ID ea060900fffbebbf
- Processor Version Intel(R) Core(TM) i7-8700K CPU @ 3.70GHz
- Processor Voltage 8ah - 1.0V
- External Clock 100MHz
- Max Speed 8300MHz
- Current Speed 3700MHz
- Status Enabled Populated
- Processor Upgrade Specification Reserved
- L1 Cache Handle 0016h
- L2 Cache Handle 0017h
- L3 Cache Handle 0018h
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 001ah]
- Starting Address 00000000h
- Ending Address 007fffffh
- Memory Device Handle 0012h
- Mem Array Mapped Adr Handle 0015h
- Partition Row Position 01
- Interleave Position 01
- Interleave Data Depth 02
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 001bh]
- Starting Address 00800000h
- Ending Address 00ffffffh
- Memory Device Handle 0014h
- Mem Array Mapped Adr Handle 0015h
- Partition Row Position 01
- Interleave Position 02
- Interleave Data Depth 02
- ========================== Dump #2: Extra #1 ===========================
- 3: kd> !verifier
- fffff8012882a6c0: Unable to get verifier list.
- ========================== Dump #2: Extra #2 ===========================
- 3: kd> !thread
- THREAD ffffc00a93d42040 Cid 0004.2378 Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor 3
- Not impersonating
- GetUlongFromAddress: unable to read from fffff8012881143c
- Owning Process ffffc00a8ae9d040 Image: System
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 2840684
- Context Switch Count 50712 IdealProcessor: 3 NoStackSwap
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address nt!ExpWorkerThread (0xfffff80127e33e20)
- Stack Init ffff82881c11fb90 Current ffff82881c11f720
- Base ffff82881c120000 Limit ffff82881c119000 Call 0000000000000000
- Priority 12 BasePriority 12 PriorityDecrement 0 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- ffff8288`1c11f7e8 fffff801`280250eb : 00000000`0000001a 00000000`00009696 ffffa680`09da7bd0 00000000`00000000 : nt!KeBugCheckEx
- ffff8288`1c11f7f0 fffff801`2803d6b6 : ffffa680`09da7bd0 7fffffff`ffffffff 00080000`00359bac ffffa680`00000001 : nt!MiGetTopLevelPfn+0x1c664b
- ffff8288`1c11f880 fffff801`27f6fa0e : fffff801`28851508 ffffa680`09da7bd0 00000000`00000000 00000000`00000001 : nt!MiRestoreTransitionPte+0x1a4d36
- ffff8288`1c11f8f0 fffff801`28158191 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MiRemoveLowestPriorityStandbyPage+0x1ce
- ffff8288`1c11f990 fffff801`281583e3 : fffff801`28850ac0 00000000`00000000 fffff801`00000000 00000000`0000027d : nt!MiPruneStandbyPages+0x265
- ffff8288`1c11fa20 fffff801`27e33f25 : ffffc00a`93d42040 fffff801`28158350 ffffc00a`8ae93a20 fffff801`28852360 : nt!MiRebalanceZeroFreeLists+0x93
- ffff8288`1c11fa70 fffff801`27f46715 : ffffc00a`93d42040 00000000`00000080 ffffc00a`8ae9d040 00700020`00000001 : nt!ExpWorkerThread+0x105
- ffff8288`1c11fb10 fffff801`27fe5078 : ffffe281`fbc80180 ffffc00a`93d42040 fffff801`27f466c0 0065006c`00500020 : nt!PspSystemThreadStartup+0x55
- ffff8288`1c11fb60 00000000`00000000 : ffff8288`1c120000 ffff8288`1c119000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
- ========================================================================
- ======================= Dump #3: ANALYZE VERBOSE =======================
- ======================= File: 071020-4437-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 19041 MP (12 procs) Free x64
- Kernel base = 0xfffff805`18200000 PsLoadedModuleList = 0xfffff805`18e2a2b0
- Debug session time: Fri Jul 10 00:15:55.925 2020 (UTC - 4:00)
- System Uptime: 0 days 0:00:45.592
- BugCheck 3B, {c0000005, fffff8051842c1c0, fffff8051b0a5920, 0}
- Probably caused by : memory_corruption
- Followup: memory_corruption
- SYSTEM_SERVICE_EXCEPTION (3b)
- An exception happened while executing a system service routine.
- Arguments:
- Arg1: 00000000c0000005, Exception code that caused the bugcheck
- Arg2: fffff8051842c1c0, Address of the instruction which caused the bugcheck
- Arg3: fffff8051b0a5920, Address of the context record for the exception that caused the bugcheck
- Arg4: 0000000000000000, zero.
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- DUMP_FILE_ATTRIBUTES: 0x8
- Kernel Generated Triage Dump
- EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.
- FAULTING_IP:
- nt!MiIdentifyPfn+240
- fffff805`1842c1c0 488b4018 mov rax,qword ptr [rax+18h]
- CONTEXT: fffff8051b0a5920 -- (.cxr 0xfffff8051b0a5920)
- rax=feff8d0f2e26f370 rbx=ffff8d0f3060b888 rcx=0000000000000000
- rdx=0000000080000000 rsi=ffff8d0f2e33a8f0 rdi=ffffec80049d1540
- rip=fffff8051842c1c0 rsp=ffffe983947df050 rbp=ffffffffffffffff
- r8=0000000000189b1c r9=0000000000000000 r10=000000002b5f0542
- r11=0a00000000000020 r12=8000000000000000 r13=fffff80512f72180
- r14=ffff8d0f2e33a870 r15=0000000000000000
- iopl=0 nv up ei ng nz na pe nc
- cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050282
- nt!MiIdentifyPfn+0x240:
- fffff805`1842c1c0 488b4018 mov rax,qword ptr [rax+18h] ds:002b:feff8d0f`2e26f388=????????????????
- Resetting default scope
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- BUGCHECK_STR: 0x3B
- PROCESS_NAME: svchost.exe
- CURRENT_IRQL: 2
- BAD_STACK_POINTER: fffff8051b0a5018
- LAST_CONTROL_TRANSFER: from fffff8051842bf15 to fffff8051842c1c0
- STACK_TEXT:
- ffffe983`947df050 fffff805`1842bf15 : 00000000`00000100 fffff805`00000000 ffff8d0f`3060b888 00000000`00000001 : nt!MiIdentifyPfn+0x240
- ffffe983`947df110 fffff805`187fde94 : 00000000`00000000 ffff8d0f`3060b888 ffffe983`947dfa80 ffff8d0f`3060c8c0 : nt!MiIdentifyPfnWrapper+0x55
- ffffe983`947df140 fffff805`187fd91c : 00000000`00000000 ffff9d07`00000000 ffffe983`947df334 ffff8d0f`3060b000 : nt!PfpPfnPrioRequest+0xe4
- ffffe983`947df1c0 fffff805`187fb9bb : 00000049`1d279e30 00000000`00000000 00000000`0000004f 00000000`00000000 : nt!PfQuerySuperfetchInformation+0x2ec
- ffffe983`947df300 fffff805`187fb6a7 : 00000049`1d279ea0 00000000`00000000 00000000`00000008 00000000`00000000 : nt!ExpQuerySystemInformation+0x1cb
- ffffe983`947df9c0 fffff805`185ef375 : 00000000`00000000 00000000`00000001 00000000`00000000 ffffe983`947dfa80 : nt!NtQuerySystemInformation+0x37
- ffffe983`947dfa00 00007ff9`99f0b454 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
- 00000049`1d279d38 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff9`99f0b454
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
- fffff8051842c321 - nt!MiIdentifyPfn+3a1
- [ f6:82 ]
- fffff8051842c3e0 - nt!MiIdentifyPfn+460 (+0xbf)
- [ fa:ec ]
- fffff8051842c49d - nt!MiIdentifyPfn+51d (+0xbd)
- [ f6:82 ]
- fffff8051842c5a9 - nt!MiIdentifyPfn+629 (+0x10c)
- [ f6:82 ]
- fffff8051842c5b3 - nt!MiIdentifyPfn+633 (+0x0a)
- [ f6:82 ]
- fffff8051842c6a8 - nt!MiIdentifyPfn+728 (+0xf5)
- [ f6:82 ]
- fffff8051842c85f - nt!MiIdentifyPfn+8df (+0x1b7)
- [ f6:82 ]
- 7 errors : !nt (fffff8051842c321-fffff8051842c85f)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- STACK_COMMAND: .cxr 0xfffff8051b0a5920 ; kb
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-07-10T04:15:55.000Z
- SUITE_MASK: 784
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #3: 3RD PARTY DRIVERS ======================
- Oct 09 2015 - wdcsam64.sys - Western Digital SCSI Arcitecture Model (SAM) WDM driver https://support.wdc.com/
- Jan 21 2019 - imaucxhpal.sys - MA-USB (UCX) HPAL driver
- Jan 21 2019 - iwigig.sys - WiGig MAC driver (Intel)
- Apr 04 2019 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
- May 07 2019 - e1d68x64.sys - Intel(R) Gigabit Adapter driver
- Jun 09 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- Jun 21 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- ================== Dump #3: 3RD PARTY DRIVERS (FULL) ===================
- Image name: wdcsam64.sys
- Search : https://www.google.com/search?q=wdcsam64.sys
- ADA Info : Western Digital SCSI Arcitecture Model (SAM) WDM driver https://support.wdc.com/
- Timestamp : Fri Oct 9 2015
- Image name: imaucxhpal.sys
- Search : https://www.google.com/search?q=imaucxhpal.sys
- ADA Info : MA-USB (UCX) HPAL driver
- Timestamp : Mon Jan 21 2019
- Image name: iwigig.sys
- Search : https://www.google.com/search?q=iwigig.sys
- ADA Info : WiGig MAC driver (Intel)
- Timestamp : Mon Jan 21 2019
- Image name: TeeDriverW8x64.sys
- Search : https://www.google.com/search?q=TeeDriverW8x64.sys
- ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Timestamp : Thu Apr 4 2019
- Image name: e1d68x64.sys
- Search : https://www.google.com/search?q=e1d68x64.sys
- ADA Info : Intel(R) Gigabit Adapter driver
- Timestamp : Tue May 7 2019
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Tue Jun 9 2020
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Sun Jun 21 2020
- ====================== Dump #3: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- acpipagr.sys ACPI Processor Aggregator Device driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CimFS.SYS Consumer IR Class Driver for eHome (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storport.sys Provides disk access during crash dump file generation (Microsoft)
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HdAudio.sys High Definition Audio Function driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- intelppm.sys Processor Device Driver (Microsoft)
- IntelTA.sys Intel Telemetry Driver
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kdcom.dll Kernel Debugger HW Extension DLL (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate.dll Media Center Update (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb10.sys Longhorn SMB Downlevel SubRdr (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msquic.sys Windows QUIC Driver
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndiscap.sys Microsoft NDIS Packet Capture Filter Driver
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- serenum.sys Serial Port Enumerator (Microsoft)
- serial.sys Serial Device Driver
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- stornvme.sys NVM Express Storport Miniport driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- ucx01000.sys USB Controller Extension (Microsoft)
- udfs.sys UDF File System driver (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- USBSTOR.SYS USB Mass Storage Class driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WpdUpFltr.sys Portable Device Upper Class Filter driver (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- WUDFRd.sys Windows Driver Foundation - User-mode Driver Framework Reflector driver (Microsoft)
- ====================== Dump #3: UNLOADED MODULES =======================
- fffff805`2e1c0000 fffff805`2e1cf000 dump_storpor
- fffff805`2d240000 fffff805`2d273000 dump_storahc
- fffff805`2d2a0000 fffff805`2d2be000 dump_dumpfve
- fffff805`30050000 fffff805`300a5000 WUDFRd.sys
- fffff805`2dbc0000 fffff805`2dbdc000 dam.sys
- fffff805`19c00000 fffff805`19c11000 WdBoot.sys
- fffff805`1acb0000 fffff805`1acc0000 hwpolicy.sys
- ====================== Dump #3: BIOS INFORMATION =======================
- [SMBIOS Data Tables v3.1]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 2808 bytes]
- [BIOS Information (Type 0) - Length 26 - Handle 0000h]
- Vendor American Megatrends Inc.
- BIOS Version P4.20
- BIOS Starting Address Segment f000
- BIOS Release Date 10/31/2019
- BIOS ROM Size 1000000
- BIOS Characteristics
- 07: - PCI Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 27: - Keyboard Services Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 32: - BIOS Vendor Reserved
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 5
- BIOS Minor Revision 12
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
- Manufacturer ASRock
- Product Z370 Extreme4
- Version
- Feature Flags 09h
- -1660307744: - -1660307696: - ÷7?Öý
- Location
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 22 - Handle 0003h]
- Chassis Type Desktop
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 3
- [OEM Strings (Type 11) - Length 5 - Handle 000dh]
- Number of Strings 1
- [Physical Memory Array (Type 16) - Length 23 - Handle 0010h]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 67108864KB
- Number of Memory Devices 4
- [Memory Device (Type 17) - Length 40 - Handle 0011h]
- Physical Memory Array Handle 0010h
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM0
- Bank Locator BANK 0
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Device (Type 17) - Length 40 - Handle 0012h]
- Physical Memory Array Handle 0010h
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM1
- Bank Locator BANK 1
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 3200MHz
- Manufacturer 029E
- Part Number CMK16GX4M2B3200C16
- [Memory Device (Type 17) - Length 40 - Handle 0013h]
- Physical Memory Array Handle 0010h
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM0
- Bank Locator BANK 2
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Device (Type 17) - Length 40 - Handle 0014h]
- Physical Memory Array Handle 0010h
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM1
- Bank Locator BANK 3
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 3200MHz
- Manufacturer 029E
- Part Number CMK16GX4M2B3200C16
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0015h]
- Starting Address 00000000h
- Ending Address 00ffffffh
- Memory Array Handle 0010h
- Partition Width 02
- [Cache Information (Type 7) - Length 27 - Handle 0016h]
- Socket Designation L1 Cache
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0180h - 384K
- Installed Size 0180h - 384K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type ParitySingle-Bit ECC
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 27 - Handle 0017h]
- Socket Designation L2 Cache
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 0600h - 1536K
- Installed Size 0600h - 1536K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Unified
- Associativity 4-way Set-Associative
- [Cache Information (Type 7) - Length 27 - Handle 0018h]
- Socket Designation L3 Cache
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 3000h - 12288K
- Installed Size 3000h - 12288K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 16-way Set-Associative
- [Processor Information (Type 4) - Length 48 - Handle 0019h]
- Socket Designation CPUSocket
- Processor Type Central Processor
- Processor Family c6h - Specification Reserved
- Processor Manufacturer Intel(R) Corporation
- Processor ID ea060900fffbebbf
- Processor Version Intel(R) Core(TM) i7-8700K CPU @ 3.70GHz
- Processor Voltage 8ah - 1.0V
- External Clock 100MHz
- Max Speed 8300MHz
- Current Speed 3700MHz
- Status Enabled Populated
- Processor Upgrade Specification Reserved
- L1 Cache Handle 0016h
- L2 Cache Handle 0017h
- L3 Cache Handle 0018h
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 001ah]
- Starting Address 00000000h
- Ending Address 007fffffh
- Memory Device Handle 0012h
- Mem Array Mapped Adr Handle 0015h
- Partition Row Position 01
- Interleave Position 01
- Interleave Data Depth 02
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 001bh]
- Starting Address 00800000h
- Ending Address 00ffffffh
- Memory Device Handle 0014h
- Mem Array Mapped Adr Handle 0015h
- Partition Row Position 01
- Interleave Position 02
- Interleave Data Depth 02
- ========================== Dump #3: Extra #1 ===========================
- 0: kd> !verifier
- fffff80518e2a6c0: Unable to get verifier list.
- ========================== Dump #3: Extra #2 ===========================
- 0: kd> !thread
- THREAD ffff8d0f2d39e080 Cid 0808.086c Teb: 000000491cf9a000 Win32Thread: 0000000000000000 RUNNING on processor 0
- Impersonation token: ffff9d0744b51060 (Level Impersonation)
- GetUlongFromAddress: unable to read from fffff80518e1143c
- Owning Process ffff8d0f2d33d340 Image: svchost.exe
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 2902
- Context Switch Count 431 IdealProcessor: 10
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address 0x00007ff9984bd650
- Stack Init ffffe983947dfb90 Current ffffe983947df0a0
- Base ffffe983947e0000 Limit ffffe983947d9000 Call 0000000000000000
- Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- fffff805`1b0a5018 fffff805`185ef929 : 00000000`0000003b 00000000`c0000005 fffff805`1842c1c0 fffff805`1b0a5920 : nt!KeBugCheckEx
- fffff805`1b0a5020 fffff805`185eed7c : fffff805`1b0a5760 fffff805`182e68e0 fffff805`1b0a5210 00000000`00000000 : nt!KiBugCheckDispatch+0x69
- fffff805`1b0a5160 fffff805`185e68df : fffff805`185eed00 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceHandler+0x7c
- fffff805`1b0a51a0 fffff805`18432fb7 : fffff805`1b0a5710 00000000`00000000 ffffe983`947dfa00 fffff805`185ef375 : nt!RtlpExecuteHandlerForException+0xf
- fffff805`1b0a51d0 fffff805`1847b226 : ffffe983`947dee18 fffff805`1b0a5e20 ffffe983`947dee18 ffffec80`049d1540 : nt!RtlDispatchException+0x297
- fffff805`1b0a58f0 fffff805`185de8b2 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDispatchException+0x186
- fffff805`1b0a5fb0 fffff805`185de880 : fffff805`185efa65 00000000`00000000 00000000`07ac1000 00000000`00000001 : nt!KxExceptionDispatchOnExceptionStack+0x12 (TrapFrame @ fffff805`1b0a5e70)
- ffffe983`947decd8 fffff805`185efa65 : 00000000`00000000 00000000`07ac1000 00000000`00000001 00000000`00000003 : nt!KiExceptionDispatchOnExceptionStackContinue
- ffffe983`947dece0 fffff805`185eb7a0 : 00000000`00000000 ffff8d0f`3060afe0 ffffe983`947defb0 ffff8d0f`3060afe8 : nt!KiExceptionDispatch+0x125
- ffffe983`947deec0 fffff805`1842c1c0 : 00000000`00000001 00000000`42506650 ffffe983`947df1d8 00000000`00000000 : nt!KiGeneralProtectionFault+0x320 (TrapFrame @ ffffe983`947deec0)
- ffffe983`947df050 fffff805`1842bf15 : 00000000`00000100 fffff805`00000000 ffff8d0f`3060b888 00000000`00000001 : nt!MiIdentifyPfn+0x240
- ffffe983`947df110 fffff805`187fde94 : 00000000`00000000 ffff8d0f`3060b888 ffffe983`947dfa80 ffff8d0f`3060c8c0 : nt!MiIdentifyPfnWrapper+0x55
- ffffe983`947df140 fffff805`187fd91c : 00000000`00000000 ffff9d07`00000000 ffffe983`947df334 ffff8d0f`3060b000 : nt!PfpPfnPrioRequest+0xe4
- ffffe983`947df1c0 fffff805`187fb9bb : 00000049`1d279e30 00000000`00000000 00000000`0000004f 00000000`00000000 : nt!PfQuerySuperfetchInformation+0x2ec
- ffffe983`947df300 fffff805`187fb6a7 : 00000049`1d279ea0 00000000`00000000 00000000`00000008 00000000`00000000 : nt!ExpQuerySystemInformation+0x1cb
- ffffe983`947df9c0 fffff805`185ef375 : 00000000`00000000 00000000`00000001 00000000`00000000 ffffe983`947dfa80 : nt!NtQuerySystemInformation+0x37
- ffffe983`947dfa00 00007ff9`99f0b454 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25 (TrapFrame @ ffffe983`947dfa00)
- 00000049`1d279d38 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff9`99f0b454
- ========================================================================
- ======================= Dump #4: ANALYZE VERBOSE =======================
- ======================= File: 070920-5437-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 19041 MP (12 procs) Free x64
- Kernel base = 0xfffff804`5cc00000 PsLoadedModuleList = 0xfffff804`5d82a2b0
- Debug session time: Thu Jul 9 11:54:21.522 2020 (UTC - 4:00)
- System Uptime: 1 days 11:11:44.989
- BugCheck 3B, {c0000005, fffff8045ce40619, ffff8b08e4616cf0, 0}
- Probably caused by : ntkrnlmp.exe ( nt!PspReturnQuota+49 )
- Followup: MachineOwner
- SYSTEM_SERVICE_EXCEPTION (3b)
- An exception happened while executing a system service routine.
- Arguments:
- Arg1: 00000000c0000005, Exception code that caused the bugcheck
- Arg2: fffff8045ce40619, Address of the instruction which caused the bugcheck
- Arg3: ffff8b08e4616cf0, Address of the context record for the exception that caused the bugcheck
- Arg4: 0000000000000000, zero.
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- DUMP_FILE_ATTRIBUTES: 0x8
- Kernel Generated Triage Dump
- EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.
- FAULTING_IP:
- nt!PspReturnQuota+49
- fffff804`5ce40619 488b1f mov rbx,qword ptr [rdi]
- CONTEXT: ffff8b08e4616cf0 -- (.cxr 0xffff8b08e4616cf0)
- rax=000000000000d939 rbx=ffff928e81836080 rcx=fffff8045cc00000
- rdx=0000000000000000 rsi=00000000000000d8 rdi=fbff928e7c1f2d80
- rip=fffff8045ce40619 rsp=ffff8b08e46176f0 rbp=0000000000000000
- r8=0000000000000000 r9=00000000000000d8 r10=0000000000000000
- r11=ffff8b08e4617790 r12=fbff928e7c1f2d80 r13=0000000000000005
- r14=0000000000000000 r15=0000000000000000
- iopl=0 nv up ei pl zr na po nc
- cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050246
- nt!PspReturnQuota+0x49:
- fffff804`5ce40619 488b1f mov rbx,qword ptr [rdi] ds:002b:fbff928e`7c1f2d80=????????????????
- Resetting default scope
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
- BUGCHECK_STR: 0x3B
- PROCESS_NAME: naturallocomot
- CURRENT_IRQL: 0
- LAST_CONTROL_TRANSFER: from fffff8045d20c67b to fffff8045ce40619
- STACK_TEXT:
- ffff8b08`e46176f0 fffff804`5d20c67b : ffff928e`81836080 ffff928e`81836080 ffff928e`745f3820 fbff928e`7c1f2d80 : nt!PspReturnQuota+0x49
- ffff8b08`e4617750 fffff804`5d20c4f8 : ffff928e`81836070 00000000`00000000 00000000`00000000 00000000`00000000 : nt!ObpFreeObject+0x12b
- ffff8b08`e46177b0 fffff804`5ce24e97 : 00000000`00000000 00000000`00000000 ffff8b08`e4617939 ffff928e`818360b0 : nt!ObpRemoveObjectRoutine+0x88
- ffff8b08`e4617810 fffff804`5d1f4bbe : ffff928e`745f3820 00000000`00000000 ffffffff`00000000 ffffffff`ffffffff : nt!ObfDereferenceObjectWithTag+0xc7
- ffff8b08`e4617850 fffff804`5d1fb11c : 00000000`000001c8 00000000`00000000 00000000`00000000 000000de`21dff0d8 : nt!ObCloseHandleTableEntry+0x29e
- ffff8b08`e4617990 fffff804`5cfef375 : ffff928e`838c8000 0000025d`00000001 ffff8b08`e4617a80 ffff928e`00000000 : nt!NtClose+0xec
- ffff8b08`e4617a00 00007ffd`1cd6af74 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
- 000000de`21dff3e8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffd`1cd6af74
- THREAD_SHA1_HASH_MOD_FUNC: e8cf64670cd1aff1addd324a6202eec3e6bc9662
- THREAD_SHA1_HASH_MOD_FUNC_OFFSET: aa61a60f3df886b4a7f63e3132106f42132cd778
- THREAD_SHA1_HASH_MOD: 30a3e915496deaace47137d5b90c3ecc03746bf6
- FOLLOWUP_IP:
- nt!PspReturnQuota+49
- fffff804`5ce40619 488b1f mov rbx,qword ptr [rdi]
- FAULT_INSTR_CODE: 481f8b48
- SYMBOL_STACK_INDEX: 0
- SYMBOL_NAME: nt!PspReturnQuota+49
- FOLLOWUP_NAME: MachineOwner
- MODULE_NAME: nt
- IMAGE_NAME: ntkrnlmp.exe
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- IMAGE_VERSION: 10.0.19041.330
- STACK_COMMAND: .cxr 0xffff8b08e4616cf0 ; kb
- BUCKET_ID_FUNC_OFFSET: 49
- FAILURE_BUCKET_ID: 0x3B_nt!PspReturnQuota
- BUCKET_ID: 0x3B_nt!PspReturnQuota
- PRIMARY_PROBLEM_CLASS: 0x3B_nt!PspReturnQuota
- TARGET_TIME: 2020-07-09T15:54:21.000Z
- SUITE_MASK: 784
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:0x3b_nt!pspreturnquota
- FAILURE_ID_HASH: {b08ecb23-fca0-5e47-3efd-af2f42c1a228}
- Followup: MachineOwner
- ====================== Dump #4: 3RD PARTY DRIVERS ======================
- Oct 09 2015 - wdcsam64.sys - Western Digital SCSI Arcitecture Model (SAM) WDM driver https://support.wdc.com/
- Oct 04 2016 - DisplayLinkXRUsbIo_x64_2.1.6.8682.sys - DisplayLink XR USB driver
- Jan 21 2019 - imaucxhpal.sys - MA-USB (UCX) HPAL driver
- Jan 21 2019 - iwigig.sys - WiGig MAC driver (Intel)
- Apr 04 2019 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
- May 07 2019 - e1d68x64.sys - Intel(R) Gigabit Adapter driver
- Jun 09 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- Jun 21 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- ================== Dump #4: 3RD PARTY DRIVERS (FULL) ===================
- Image name: wdcsam64.sys
- Search : https://www.google.com/search?q=wdcsam64.sys
- ADA Info : Western Digital SCSI Arcitecture Model (SAM) WDM driver https://support.wdc.com/
- Timestamp : Fri Oct 9 2015
- Image name: DisplayLinkXRUsbIo_x64_2.1.6.8682.sys
- Search : https://www.google.com/search?q=DisplayLinkXRUsbIo_x64_2.1.6.8682.sys
- ADA Info : DisplayLink XR USB driver
- Timestamp : Tue Oct 4 2016
- Image name: imaucxhpal.sys
- Search : https://www.google.com/search?q=imaucxhpal.sys
- ADA Info : MA-USB (UCX) HPAL driver
- Timestamp : Mon Jan 21 2019
- Image name: iwigig.sys
- Search : https://www.google.com/search?q=iwigig.sys
- ADA Info : WiGig MAC driver (Intel)
- Timestamp : Mon Jan 21 2019
- Image name: TeeDriverW8x64.sys
- Search : https://www.google.com/search?q=TeeDriverW8x64.sys
- ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Timestamp : Thu Apr 4 2019
- Image name: e1d68x64.sys
- Search : https://www.google.com/search?q=e1d68x64.sys
- ADA Info : Intel(R) Gigabit Adapter driver
- Timestamp : Tue May 7 2019
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Tue Jun 9 2020
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Sun Jun 21 2020
- ====================== Dump #4: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- acpipagr.sys ACPI Processor Aggregator Device driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CimFS.SYS Consumer IR Class Driver for eHome (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storport.sys Provides disk access during crash dump file generation (Microsoft)
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HdAudio.sys High Definition Audio Function driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- intelppm.sys Processor Device Driver (Microsoft)
- IntelTA.sys Intel Telemetry Driver
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kdcom.dll Kernel Debugger HW Extension DLL (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate.dll Media Center Update (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb10.sys Longhorn SMB Downlevel SubRdr (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- MSKSSRV.sys MS KS Server driver
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msquic.sys Windows QUIC Driver
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndiscap.sys Microsoft NDIS Packet Capture Filter Driver
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdpvideominiport.sys RDP Video Miniport driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- serenum.sys Serial Port Enumerator (Microsoft)
- serial.sys Serial Device Driver
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- stornvme.sys NVM Express Storport Miniport driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- ucx01000.sys USB Controller Extension (Microsoft)
- udfs.sys UDF File System driver (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbaudio2.sys Microsoft USB Audio Class 2.0 Driver
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- USBSTOR.SYS USB Mass Storage Class driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WpdUpFltr.sys Portable Device Upper Class Filter driver (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- WUDFRd.sys Windows Driver Foundation - User-mode Driver Framework Reflector driver (Microsoft)
- ====================== Dump #4: UNLOADED MODULES =======================
- fffff804`77120000 fffff804`77171000 usbvideo.sys
- fffff804`771a0000 fffff804`771b1000 MSKSSRV.sys
- fffff804`77180000 fffff804`77191000 MSKSSRV.sys
- fffff804`77110000 fffff804`7711c000 WdmCompanion
- fffff804`76fb0000 fffff804`76fc1000 MpKslDrv.sys
- fffff804`77040000 fffff804`7704f000 hiber_storpo
- fffff804`77050000 fffff804`77083000 hiber_storah
- fffff804`77090000 fffff804`770ae000 hiber_dumpfv
- fffff804`76fd0000 fffff804`76fdf000 hiber_storpo
- fffff804`76fe0000 fffff804`77013000 hiber_storah
- fffff804`77020000 fffff804`7703e000 hiber_dumpfv
- fffff804`76f40000 fffff804`76f4f000 hiber_storpo
- fffff804`76f50000 fffff804`76f83000 hiber_storah
- fffff804`76f90000 fffff804`76fae000 hiber_dumpfv
- fffff804`75210000 fffff804`7521f000 dump_storpor
- fffff804`75260000 fffff804`75293000 dump_storahc
- fffff804`752c0000 fffff804`752de000 dump_dumpfve
- fffff804`76100000 fffff804`76155000 WUDFRd.sys
- fffff804`75b30000 fffff804`75b4c000 dam.sys
- fffff804`61c00000 fffff804`61c11000 WdBoot.sys
- fffff804`62cb0000 fffff804`62cc0000 hwpolicy.sys
- ====================== Dump #4: BIOS INFORMATION =======================
- [SMBIOS Data Tables v3.1]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 2808 bytes]
- [BIOS Information (Type 0) - Length 26 - Handle 0000h]
- Vendor American Megatrends Inc.
- BIOS Version P4.20
- BIOS Starting Address Segment f000
- BIOS Release Date 10/31/2019
- BIOS ROM Size 1000000
- BIOS Characteristics
- 07: - PCI Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 27: - Keyboard Services Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 32: - BIOS Vendor Reserved
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 5
- BIOS Minor Revision 12
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
- Manufacturer ASRock
- Product Z370 Extreme4
- Version
- Feature Flags 09h
- -1660307744: - -1660307696: - ÷7?Öý
- Location
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 22 - Handle 0003h]
- Chassis Type Desktop
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 3
- [OEM Strings (Type 11) - Length 5 - Handle 000dh]
- Number of Strings 1
- [Physical Memory Array (Type 16) - Length 23 - Handle 0010h]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 67108864KB
- Number of Memory Devices 4
- [Memory Device (Type 17) - Length 40 - Handle 0011h]
- Physical Memory Array Handle 0010h
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM0
- Bank Locator BANK 0
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Device (Type 17) - Length 40 - Handle 0012h]
- Physical Memory Array Handle 0010h
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM1
- Bank Locator BANK 1
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 3200MHz
- Manufacturer 029E
- Part Number CMK16GX4M2B3200C16
- [Memory Device (Type 17) - Length 40 - Handle 0013h]
- Physical Memory Array Handle 0010h
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM0
- Bank Locator BANK 2
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Device (Type 17) - Length 40 - Handle 0014h]
- Physical Memory Array Handle 0010h
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM1
- Bank Locator BANK 3
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 3200MHz
- Manufacturer 029E
- Part Number CMK16GX4M2B3200C16
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0015h]
- Starting Address 00000000h
- Ending Address 00ffffffh
- Memory Array Handle 0010h
- Partition Width 02
- [Cache Information (Type 7) - Length 27 - Handle 0016h]
- Socket Designation L1 Cache
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0180h - 384K
- Installed Size 0180h - 384K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type ParitySingle-Bit ECC
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 27 - Handle 0017h]
- Socket Designation L2 Cache
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 0600h - 1536K
- Installed Size 0600h - 1536K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Unified
- Associativity 4-way Set-Associative
- [Cache Information (Type 7) - Length 27 - Handle 0018h]
- Socket Designation L3 Cache
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 3000h - 12288K
- Installed Size 3000h - 12288K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 16-way Set-Associative
- [Processor Information (Type 4) - Length 48 - Handle 0019h]
- Socket Designation CPUSocket
- Processor Type Central Processor
- Processor Family c6h - Specification Reserved
- Processor Manufacturer Intel(R) Corporation
- Processor ID ea060900fffbebbf
- Processor Version Intel(R) Core(TM) i7-8700K CPU @ 3.70GHz
- Processor Voltage 8ah - 1.0V
- External Clock 100MHz
- Max Speed 8300MHz
- Current Speed 3700MHz
- Status Enabled Populated
- Processor Upgrade Specification Reserved
- L1 Cache Handle 0016h
- L2 Cache Handle 0017h
- L3 Cache Handle 0018h
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 001ah]
- Starting Address 00000000h
- Ending Address 007fffffh
- Memory Device Handle 0012h
- Mem Array Mapped Adr Handle 0015h
- Partition Row Position 01
- Interleave Position 01
- Interleave Data Depth 02
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 001bh]
- Starting Address 00800000h
- Ending Address 00ffffffh
- Memory Device Handle 0014h
- Mem Array Mapped Adr Handle 0015h
- Partition Row Position 01
- Interleave Position 02
- Interleave Data Depth 02
- ========================== Dump #4: Extra #1 ===========================
- 4: kd> !verifier
- fffff8045d82a6c0: Unable to get verifier list.
- ========================== Dump #4: Extra #2 ===========================
- 4: kd> !thread
- THREAD ffff928e838c8080 Cid 1d24.0d18 Teb: 000000de21a84000 Win32Thread: ffff928e856c26f0 RUNNING on processor 4
- Not impersonating
- GetUlongFromAddress: unable to read from fffff8045d81143c
- Owning Process ffff928e81728080 Image: naturallocomot
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 8109119
- Context Switch Count 1652949 IdealProcessor: 2
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address 0x00007ff6d2f3d3ec
- Stack Init ffff8b08e4617b90 Current ffff8b08e4616c00
- Base ffff8b08e4618000 Limit ffff8b08e4611000 Call 0000000000000000
- Priority 9 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- ffff8b08`e46163e8 fffff804`5cfef929 : 00000000`0000003b 00000000`c0000005 fffff804`5ce40619 ffff8b08`e4616cf0 : nt!KeBugCheckEx
- ffff8b08`e46163f0 fffff804`5cfeed7c : ffff8b08`e4616790 fffff804`5cce68e0 ffff8b08`e46165e0 00000000`00000000 : nt!KiBugCheckDispatch+0x69
- ffff8b08`e4616530 fffff804`5cfe68df : fffff804`5cfeed00 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceHandler+0x7c
- ffff8b08`e4616570 fffff804`5ce32fb7 : ffff8b08`e4616ae0 00000000`00000000 ffff8b08`e4617a00 fffff804`5cfef375 : nt!RtlpExecuteHandlerForException+0xf
- ffff8b08`e46165a0 fffff804`5ce7b226 : ffff8b08`e46174b8 ffff8b08`e46171f0 ffff8b08`e46174b8 fbff928e`7c1f2d80 : nt!RtlDispatchException+0x297
- ffff8b08`e4616cc0 fffff804`5cfefa6c : 00007ffd`1c46a000 00000000`00000000 00000000`00000000 00000000`00000001 : nt!KiDispatchException+0x186
- ffff8b08`e4617380 fffff804`5cfeb7a0 : ffff8b08`e4617780 0a000001`177fb121 00000000`00000000 fffff804`00000000 : nt!KiExceptionDispatch+0x12c
- ffff8b08`e4617560 fffff804`5ce40619 : ffff8b08`e46176f0 ffff8b08`e46176f0 ffff928e`818360b0 fffff804`5d20b72c : nt!KiGeneralProtectionFault+0x320 (TrapFrame @ ffff8b08`e4617560)
- ffff8b08`e46176f0 fffff804`5d20c67b : ffff928e`81836080 ffff928e`81836080 ffff928e`745f3820 fbff928e`7c1f2d80 : nt!PspReturnQuota+0x49
- ffff8b08`e4617750 fffff804`5d20c4f8 : ffff928e`81836070 00000000`00000000 00000000`00000000 00000000`00000000 : nt!ObpFreeObject+0x12b
- ffff8b08`e46177b0 fffff804`5ce24e97 : 00000000`00000000 00000000`00000000 ffff8b08`e4617939 ffff928e`818360b0 : nt!ObpRemoveObjectRoutine+0x88
- ffff8b08`e4617810 fffff804`5d1f4bbe : ffff928e`745f3820 00000000`00000000 ffffffff`00000000 ffffffff`ffffffff : nt!ObfDereferenceObjectWithTag+0xc7
- ffff8b08`e4617850 fffff804`5d1fb11c : 00000000`000001c8 00000000`00000000 00000000`00000000 000000de`21dff0d8 : nt!ObCloseHandleTableEntry+0x29e
- ffff8b08`e4617990 fffff804`5cfef375 : ffff928e`838c8000 0000025d`00000001 ffff8b08`e4617a80 ffff928e`00000000 : nt!NtClose+0xec
- ffff8b08`e4617a00 00007ffd`1cd6af74 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25 (TrapFrame @ ffff8b08`e4617a00)
- 000000de`21dff3e8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffd`1cd6af74
- ========================================================================
- ======================= Dump #5: ANALYZE VERBOSE =======================
- ======================= File: 070820-4750-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 19041 MP (12 procs) Free x64
- Kernel base = 0xfffff806`71800000 PsLoadedModuleList = 0xfffff806`7242a2b0
- Debug session time: Wed Jul 8 00:42:02.440 2020 (UTC - 4:00)
- System Uptime: 0 days 4:30:04.107
- BugCheck A, {ffffc48aea284850, 2, 0, fffff80671a98aff}
- Probably caused by : memory_corruption
- Followup: memory_corruption
- IRQL_NOT_LESS_OR_EQUAL (a)
- An attempt was made to access a pageable (or completely invalid) address at an
- interrupt request level (IRQL) that is too high. This is usually
- caused by drivers using improper addresses.
- If a kernel debugger is available get the stack backtrace.
- Arguments:
- Arg1: ffffc48aea284850, memory referenced
- Arg2: 0000000000000002, IRQL
- Arg3: 0000000000000000, bitfield :
- bit 0 : value 0 = read operation, 1 = write operation
- bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
- Arg4: fffff80671a98aff, address which referenced memory
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- DUMP_FILE_ATTRIBUTES: 0x8
- Kernel Generated Triage Dump
- READ_ADDRESS: fffff806724fa388: Unable to get MiVisibleState
- ffffc48aea284850 Paged pool
- CURRENT_IRQL: 2
- FAULTING_IP:
- nt!MiRestoreTransitionPte+17f
- fffff806`71a98aff 488b09 mov rcx,qword ptr [rcx]
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- BUGCHECK_STR: AV
- PROCESS_NAME: System
- TRAP_FRAME: ffffac8587f876f0 -- (.trap 0xffffac8587f876f0)
- NOTE: The trap frame does not contain all registers.
- Some register values may be zeroed or incorrect.
- rax=0000200000000000 rbx=0000000000000000 rcx=ffffc48aea284850
- rdx=ffffc48aea284850 rsi=0000000000000000 rdi=0000000000000000
- rip=fffff80671a98aff rsp=ffffac8587f87880 rbp=fffff80672450ac0
- r8=0000000080000000 r9=0000000000000003 r10=fffff28000000000
- r11=ffffac8587f87810 r12=0000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=0000000000000000
- iopl=0 nv up ei ng nz na po nc
- nt!MiRestoreTransitionPte+0x17f:
- fffff806`71a98aff 488b09 mov rcx,qword ptr [rcx] ds:ffffc48a`ea284850=????????????????
- Resetting default scope
- LAST_CONTROL_TRANSFER: from fffff80671bef929 to fffff80671bdda20
- STACK_TEXT:
- ffffac85`87f875a8 fffff806`71bef929 : 00000000`0000000a ffffc48a`ea284850 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
- ffffac85`87f875b0 fffff806`71bebc29 : 00000000`00000000 00000000`0000011e ffffcde3`2d8b8f7e ffffc68a`e902c040 : nt!KiBugCheckDispatch+0x69
- ffffac85`87f876f0 fffff806`71a98aff : c48aea28`485004d0 fffff280`0bdcd080 fffff280`0a028520 00000000`00000000 : nt!KiPageFault+0x469
- ffffac85`87f87880 fffff806`71b6fa0e : c48aea28`485004d0 fffff280`0a028520 00000000`00000000 00000000`00000001 : nt!MiRestoreTransitionPte+0x17f
- ffffac85`87f878f0 fffff806`71d58191 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MiRemoveLowestPriorityStandbyPage+0x1ce
- ffffac85`87f87990 fffff806`71d583e3 : fffff806`72450ac0 00000000`00000000 fffff806`00000000 00000000`00000240 : nt!MiPruneStandbyPages+0x265
- ffffac85`87f87a20 fffff806`71a33f25 : ffffc68a`e902c040 fffff806`71d58350 ffffc68a`dd715010 fffff806`72452360 : nt!MiRebalanceZeroFreeLists+0x93
- ffffac85`87f87a70 fffff806`71b46715 : ffffc68a`e902c040 00000000`00000080 ffffc68a`dd69c040 0b6abca9`00000001 : nt!ExpWorkerThread+0x105
- ffffac85`87f87b10 fffff806`71be5078 : fffff806`6e938180 ffffc68a`e902c040 fffff806`71b466c0 4949c94a`5f393fff : nt!PspSystemThreadStartup+0x55
- ffffac85`87f87b60 00000000`00000000 : ffffac85`87f88000 ffffac85`87f81000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
- fffff80671a987e7-fffff80671a987e8 2 bytes - nt!MiHyperPage+23
- [ 80 f6:00 9b ]
- fffff80671a9882a-fffff80671a9882b 2 bytes - nt!MiHyperPage+66 (+0x43)
- [ ff f6:7f 9b ]
- fffff80671a989ee - nt!MiRestoreTransitionPte+6e (+0x1c4)
- [ fa:f2 ]
- fffff80671a98bb6 - nt!MiRestoreTransitionPte+236 (+0x1c8)
- [ fa:f2 ]
- fffff80671a98c97 - nt!MiRestoreTransitionPte+317 (+0xe1)
- [ fa:f2 ]
- fffff80671a98e48 - nt!MiChangePageAttributeBatch+118 (+0x1b1)
- [ fa:f2 ]
- 8 errors : !nt (fffff80671a987e7-fffff80671a98e48)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-07-08T04:42:02.000Z
- SUITE_MASK: 784
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #5: 3RD PARTY DRIVERS ======================
- Oct 09 2015 - wdcsam64.sys - Western Digital SCSI Arcitecture Model (SAM) WDM driver https://support.wdc.com/
- Jan 21 2019 - imaucxhpal.sys - MA-USB (UCX) HPAL driver
- Jan 21 2019 - iwigig.sys - WiGig MAC driver (Intel)
- Apr 04 2019 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
- May 07 2019 - e1d68x64.sys - Intel(R) Gigabit Adapter driver
- Jun 09 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- Jun 21 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- ================== Dump #5: 3RD PARTY DRIVERS (FULL) ===================
- Image name: wdcsam64.sys
- Search : https://www.google.com/search?q=wdcsam64.sys
- ADA Info : Western Digital SCSI Arcitecture Model (SAM) WDM driver https://support.wdc.com/
- Timestamp : Fri Oct 9 2015
- Image name: imaucxhpal.sys
- Search : https://www.google.com/search?q=imaucxhpal.sys
- ADA Info : MA-USB (UCX) HPAL driver
- Timestamp : Mon Jan 21 2019
- Image name: iwigig.sys
- Search : https://www.google.com/search?q=iwigig.sys
- ADA Info : WiGig MAC driver (Intel)
- Timestamp : Mon Jan 21 2019
- Image name: TeeDriverW8x64.sys
- Search : https://www.google.com/search?q=TeeDriverW8x64.sys
- ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Timestamp : Thu Apr 4 2019
- Image name: e1d68x64.sys
- Search : https://www.google.com/search?q=e1d68x64.sys
- ADA Info : Intel(R) Gigabit Adapter driver
- Timestamp : Tue May 7 2019
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Tue Jun 9 2020
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Sun Jun 21 2020
- ====================== Dump #5: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- acpipagr.sys ACPI Processor Aggregator Device driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CimFS.SYS Consumer IR Class Driver for eHome (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storport.sys Provides disk access during crash dump file generation (Microsoft)
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HdAudio.sys High Definition Audio Function driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- intelppm.sys Processor Device Driver (Microsoft)
- IntelTA.sys Intel Telemetry Driver
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kdcom.dll Kernel Debugger HW Extension DLL (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate.dll Media Center Update (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb10.sys Longhorn SMB Downlevel SubRdr (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msquic.sys Windows QUIC Driver
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndiscap.sys Microsoft NDIS Packet Capture Filter Driver
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- serenum.sys Serial Port Enumerator (Microsoft)
- serial.sys Serial Device Driver
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- stornvme.sys NVM Express Storport Miniport driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- ucx01000.sys USB Controller Extension (Microsoft)
- udfs.sys UDF File System driver (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- USBSTOR.SYS USB Mass Storage Class driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WpdUpFltr.sys Portable Device Upper Class Filter driver (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- WUDFRd.sys Windows Driver Foundation - User-mode Driver Framework Reflector driver (Microsoft)
- ====================== Dump #5: UNLOADED MODULES =======================
- fffff806`ccf10000 fffff806`ccf1f000 hiber_storpo
- fffff806`ccf20000 fffff806`ccf53000 hiber_storah
- fffff806`ccf60000 fffff806`ccf7e000 hiber_dumpfv
- fffff806`ccea0000 fffff806`cceaf000 hiber_storpo
- fffff806`cceb0000 fffff806`ccee3000 hiber_storah
- fffff806`ccef0000 fffff806`ccf0e000 hiber_dumpfv
- fffff806`895d0000 fffff806`895df000 dump_storpor
- fffff806`88a40000 fffff806`88a73000 dump_storahc
- fffff806`88aa0000 fffff806`88abe000 dump_dumpfve
- fffff806`89790000 fffff806`897e5000 WUDFRd.sys
- fffff806`893c0000 fffff806`893dc000 dam.sys
- fffff806`75600000 fffff806`75611000 WdBoot.sys
- fffff806`766b0000 fffff806`766c0000 hwpolicy.sys
- ====================== Dump #5: BIOS INFORMATION =======================
- [SMBIOS Data Tables v3.1]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 2808 bytes]
- [BIOS Information (Type 0) - Length 26 - Handle 0000h]
- Vendor American Megatrends Inc.
- BIOS Version P4.20
- BIOS Starting Address Segment f000
- BIOS Release Date 10/31/2019
- BIOS ROM Size 1000000
- BIOS Characteristics
- 07: - PCI Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 27: - Keyboard Services Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 32: - BIOS Vendor Reserved
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 5
- BIOS Minor Revision 12
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
- Manufacturer ASRock
- Product Z370 Extreme4
- Version
- Feature Flags 09h
- -1387415840: - -1387415792: - ÷7?Öý
- Location
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 22 - Handle 0003h]
- Chassis Type Desktop
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 3
- [OEM Strings (Type 11) - Length 5 - Handle 000dh]
- Number of Strings 1
- [Physical Memory Array (Type 16) - Length 23 - Handle 0010h]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 67108864KB
- Number of Memory Devices 4
- [Memory Device (Type 17) - Length 40 - Handle 0011h]
- Physical Memory Array Handle 0010h
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM0
- Bank Locator BANK 0
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Device (Type 17) - Length 40 - Handle 0012h]
- Physical Memory Array Handle 0010h
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM1
- Bank Locator BANK 1
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 3200MHz
- Manufacturer 029E
- Part Number CMK16GX4M2B3200C16
- [Memory Device (Type 17) - Length 40 - Handle 0013h]
- Physical Memory Array Handle 0010h
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM0
- Bank Locator BANK 2
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Device (Type 17) - Length 40 - Handle 0014h]
- Physical Memory Array Handle 0010h
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM1
- Bank Locator BANK 3
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 3200MHz
- Manufacturer 029E
- Part Number CMK16GX4M2B3200C16
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0015h]
- Starting Address 00000000h
- Ending Address 00ffffffh
- Memory Array Handle 0010h
- Partition Width 02
- [Cache Information (Type 7) - Length 27 - Handle 0016h]
- Socket Designation L1 Cache
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0180h - 384K
- Installed Size 0180h - 384K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type ParitySingle-Bit ECC
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 27 - Handle 0017h]
- Socket Designation L2 Cache
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 0600h - 1536K
- Installed Size 0600h - 1536K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Unified
- Associativity 4-way Set-Associative
- [Cache Information (Type 7) - Length 27 - Handle 0018h]
- Socket Designation L3 Cache
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 3000h - 12288K
- Installed Size 3000h - 12288K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 16-way Set-Associative
- [Processor Information (Type 4) - Length 48 - Handle 0019h]
- Socket Designation CPUSocket
- Processor Type Central Processor
- Processor Family c6h - Specification Reserved
- Processor Manufacturer Intel(R) Corporation
- Processor ID ea060900fffbebbf
- Processor Version Intel(R) Core(TM) i7-8700K CPU @ 3.70GHz
- Processor Voltage 8ah - 1.0V
- External Clock 100MHz
- Max Speed 8300MHz
- Current Speed 3700MHz
- Status Enabled Populated
- Processor Upgrade Specification Reserved
- L1 Cache Handle 0016h
- L2 Cache Handle 0017h
- L3 Cache Handle 0018h
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 001ah]
- Starting Address 00000000h
- Ending Address 007fffffh
- Memory Device Handle 0012h
- Mem Array Mapped Adr Handle 0015h
- Partition Row Position 01
- Interleave Position 01
- Interleave Data Depth 02
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 001bh]
- Starting Address 00800000h
- Ending Address 00ffffffh
- Memory Device Handle 0014h
- Mem Array Mapped Adr Handle 0015h
- Partition Row Position 01
- Interleave Position 02
- Interleave Data Depth 02
- ========================== Dump #5: Extra #1 ===========================
- 7: kd> !verifier
- fffff8067242a6c0: Unable to get verifier list.
- ========================== Dump #5: Extra #2 ===========================
- 7: kd> !thread
- THREAD ffffc68ae902c040 Cid 0004.11a0 Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor 7
- Not impersonating
- GetUlongFromAddress: unable to read from fffff8067241143c
- Owning Process ffffc68add69c040 Image: System
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 1037062
- Context Switch Count 92568 IdealProcessor: 7
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address nt!ExpWorkerThread (0xfffff80671a33e20)
- Stack Init ffffac8587f87b90 Current ffffac8587f87720
- Base ffffac8587f88000 Limit ffffac8587f81000 Call 0000000000000000
- Priority 12 BasePriority 12 PriorityDecrement 0 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- ffffac85`87f875a8 fffff806`71bef929 : 00000000`0000000a ffffc48a`ea284850 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
- ffffac85`87f875b0 fffff806`71bebc29 : 00000000`00000000 00000000`0000011e ffffcde3`2d8b8f7e ffffc68a`e902c040 : nt!KiBugCheckDispatch+0x69
- ffffac85`87f876f0 fffff806`71a98aff : c48aea28`485004d0 fffff280`0bdcd080 fffff280`0a028520 00000000`00000000 : nt!KiPageFault+0x469 (TrapFrame @ ffffac85`87f876f0)
- ffffac85`87f87880 fffff806`71b6fa0e : c48aea28`485004d0 fffff280`0a028520 00000000`00000000 00000000`00000001 : nt!MiRestoreTransitionPte+0x17f
- ffffac85`87f878f0 fffff806`71d58191 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MiRemoveLowestPriorityStandbyPage+0x1ce
- ffffac85`87f87990 fffff806`71d583e3 : fffff806`72450ac0 00000000`00000000 fffff806`00000000 00000000`00000240 : nt!MiPruneStandbyPages+0x265
- ffffac85`87f87a20 fffff806`71a33f25 : ffffc68a`e902c040 fffff806`71d58350 ffffc68a`dd715010 fffff806`72452360 : nt!MiRebalanceZeroFreeLists+0x93
- ffffac85`87f87a70 fffff806`71b46715 : ffffc68a`e902c040 00000000`00000080 ffffc68a`dd69c040 0b6abca9`00000001 : nt!ExpWorkerThread+0x105
- ffffac85`87f87b10 fffff806`71be5078 : fffff806`6e938180 ffffc68a`e902c040 fffff806`71b466c0 4949c94a`5f393fff : nt!PspSystemThreadStartup+0x55
- ffffac85`87f87b60 00000000`00000000 : ffffac85`87f88000 ffffac85`87f81000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
- ========================================================================
- ======================= Dump #6: ANALYZE VERBOSE =======================
- ======================= File: 070720-5125-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 19041 MP (12 procs) Free x64
- Kernel base = 0xfffff807`5dc00000 PsLoadedModuleList = 0xfffff807`5e82a2b0
- Debug session time: Tue Jul 7 15:48:02.264 2020 (UTC - 4:00)
- System Uptime: 0 days 1:38:34.931
- BugCheck 3B, {c0000005, fffff8075de42acc, ffff82002c74f920, 0}
- Probably caused by : Pool_Corruption ( nt!ExFreePool+9 )
- Followup: Pool_corruption
- SYSTEM_SERVICE_EXCEPTION (3b)
- An exception happened while executing a system service routine.
- Arguments:
- Arg1: 00000000c0000005, Exception code that caused the bugcheck
- Arg2: fffff8075de42acc, Address of the instruction which caused the bugcheck
- Arg3: ffff82002c74f920, Address of the context record for the exception that caused the bugcheck
- Arg4: 0000000000000000, zero.
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- DUMP_FILE_ATTRIBUTES: 0x8
- Kernel Generated Triage Dump
- EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.
- FAULTING_IP:
- nt!RtlRbRemoveNode+7c
- fffff807`5de42acc 498b4308 mov rax,qword ptr [r11+8]
- CONTEXT: ffff82002c74f920 -- (.cxr 0xffff82002c74f920)
- rax=0000000000000000 rbx=ffffb904cfe02290 rcx=0000000000000000
- rdx=ffffb904dda50b08 rsi=ffffb904dda4ffe0 rdi=ffffb904dda50b08
- rip=fffff8075de42acc rsp=ffffce857d1d9a48 rbp=00000000000000b2
- r8=0000000000000000 r9=0000000000000000 r10=0000000000000000
- r11=fbffb904df664de8 r12=ffffb904dda46030 r13=ffffb904dda46000
- r14=0000000000000000 r15=ffffb904dda50b00
- iopl=0 nv up ei ng nz na po nc
- cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050286
- nt!RtlRbRemoveNode+0x7c:
- fffff807`5de42acc 498b4308 mov rax,qword ptr [r11+8] ds:002b:fbffb904`df664df0=????????????????
- Resetting default scope
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
- BUGCHECK_STR: 0x3B
- PROCESS_NAME: steamtours.exe
- CURRENT_IRQL: 2
- IRP_ADDRESS: ffffffffffffff89
- BAD_STACK_POINTER: ffff82002c74f018
- LAST_CONTROL_TRANSFER: from fffff8075de428e3 to fffff8075de42acc
- STACK_TEXT:
- ffffce85`7d1d9a48 fffff807`5de428e3 : 00000000`000000b2 ffffb904`dda4ffe0 00000000`00000000 ffffb904`dda50b00 : nt!RtlRbRemoveNode+0x7c
- ffffce85`7d1d9a60 fffff807`5de42258 : ffffb904`cfe02280 ffffb904`dda46000 ffffb904`cfe02280 ffffce85`7d1d9b68 : nt!RtlpHpVsChunkCoalesce+0x183
- ffffce85`7d1d9ac0 fffff807`5de40be4 : ffffb904`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!RtlpHpVsContextFree+0x188
- ffffce85`7d1d9b60 fffff807`5e5c2019 : ffffb904`00000500 ffffb904`dcce1220 00000000`00000000 01000000`00100000 : nt!ExFreeHeapPool+0x4d4
- ffffce85`7d1d9c40 fffff807`5de3dfd2 : ffffb904`00000001 ffffce85`7d1d9db9 00000000`00400201 ffffb904`d5b46b40 : nt!ExFreePool+0x9
- ffffce85`7d1d9c70 fffff807`5de3cd88 : 00000000`00000001 00000000`00000001 00000000`00000000 ffffb904`df2b95e0 : nt!IopCompleteRequest+0x8a2
- ffffce85`7d1d9d30 fffff807`5de3c697 : 00000000`00000000 00000000`00000001 ffffcf8c`fe7af970 ffffb904`df2b95e0 : nt!IopfCompleteRequest+0x6d8
- ffffce85`7d1d9e20 fffff807`619de788 : 00000000`00000000 ffffcf8c`00000001 ffffce85`7d1da100 fffff807`619de392 : nt!IofCompleteRequest+0x17
- ffffce85`7d1d9e50 fffff807`61acddae : 00000000`00000000 ffffcf8c`fe7af970 ffffcf8c`fe7af5a0 00000000`00000000 : Ntfs!NtfsExtendedCompleteRequestInternal+0x178
- ffffce85`7d1d9eb0 fffff807`61acc8d6 : ffffce85`7d1da100 ffffb904`df2b95e0 00000000`0000011a fffff807`00000002 : Ntfs!NtfsCommonQueryInformation+0xfbe
- ffffce85`7d1d9fb0 fffff807`61acc760 : ffffce85`7d1da100 ffffb904`df2b95e0 ffffb904`df2b95e0 fffff807`5de24fad : Ntfs!NtfsFsdDispatchSwitch+0x156
- ffffce85`7d1da0e0 fffff807`5de46d25 : ffffce85`7d1da450 fffff807`5b8a4b46 ffffce85`7d1db000 ffffce85`7d1d4000 : Ntfs!NtfsFsdDispatchWait+0x40
- ffffce85`7d1da380 fffff807`5b8a6ccf : 00000000`00000200 00000000`00000000 00000000`000004c0 fffff807`5e5c2094 : nt!IofCallDriver+0x55
- ffffce85`7d1da3c0 fffff807`5b8a48d3 : ffffce85`7d1da450 00000000`00000009 00000000`0000000e fffff807`00000000 : FLTMGR!FltpLegacyProcessingAfterPreCallbacksCompleted+0x28f
- ffffce85`7d1da430 fffff807`5de46d25 : ffffb904`dcce1220 fffff807`5de46d67 00000000`0000000e 00000000`00000000 : FLTMGR!FltpDispatch+0xa3
- ffffce85`7d1da490 fffff807`5e2a1148 : ffffce85`7d1da530 ffffb904`dcce1220 ffffb904`d5b46b40 ffffcf8c`00000000 : nt!IofCallDriver+0x55
- ffffce85`7d1da4d0 fffff807`5e29ee9d : ffffb904`d53ae800 00000000`00000000 00000000`000001dc ffffce85`7d1da5b0 : nt!IopQueryXxxInformation+0x120
- ffffce85`7d1da570 fffff807`5e29e9f6 : ffffb904`dcce1220 00000000`00000000 00000000`00000000 000000dd`c76af0e0 : nt!IopQueryNameInternal+0x3e9
- ffffce85`7d1da620 fffff807`5e29fa73 : ffffb904`df903840 ffffce85`7d1da810 ffffb904`dc3dd700 00000000`00000000 : nt!IopQueryName+0x26
- ffffce85`7d1da670 fffff807`5e26a984 : ffffb904`dcce1220 000000dd`c76af0e0 ffffb904`00000218 ffffce85`7d1da7d8 : nt!ObQueryNameStringMode+0xd3
- ffffce85`7d1da790 fffff807`5e269d85 : ffffa050`00b4a020 ffffa050`28005a50 ffffa050`28140028 ffffb904`dc3dd700 : nt!MmQueryVirtualMemory+0xbe4
- ffffce85`7d1da940 fffff807`5dfef375 : 00000000`00000000 00000000`00000000 00000000`00000000 ffffce85`7d1daa80 : nt!NtQueryVirtualMemory+0x25
- ffffce85`7d1da990 00007ff9`56d8b1f4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
- 000000dd`c76af098 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff9`56d8b1f4
- THREAD_SHA1_HASH_MOD_FUNC: 6b993cda0b4d9e70f3ea70cfb527fd1e7538b9fb
- THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 9905228c9d6a7f487c62707b140a11790be798c8
- THREAD_SHA1_HASH_MOD: 05145e774d5b0968782d0d6d929dc7589214a7cd
- FOLLOWUP_IP:
- nt!ExFreePool+9
- fffff807`5e5c2019 4883c428 add rsp,28h
- FAULT_INSTR_CODE: 28c48348
- SYMBOL_STACK_INDEX: 4
- SYMBOL_NAME: nt!ExFreePool+9
- FOLLOWUP_NAME: Pool_corruption
- IMAGE_NAME: Pool_Corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- IMAGE_VERSION: 10.0.19041.330
- MODULE_NAME: Pool_Corruption
- STACK_COMMAND: .cxr 0xffff82002c74f920 ; kb
- BUCKET_ID_FUNC_OFFSET: 9
- FAILURE_BUCKET_ID: 0x3B_STACKPTR_ERROR_nt!ExFreePool
- BUCKET_ID: 0x3B_STACKPTR_ERROR_nt!ExFreePool
- PRIMARY_PROBLEM_CLASS: 0x3B_STACKPTR_ERROR_nt!ExFreePool
- TARGET_TIME: 2020-07-07T19:48:02.000Z
- SUITE_MASK: 784
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:0x3b_stackptr_error_nt!exfreepool
- FAILURE_ID_HASH: {74c0fd9b-610b-14e7-0dc5-63896bb10036}
- Followup: Pool_corruption
- ====================== Dump #6: 3RD PARTY DRIVERS ======================
- Oct 09 2015 - wdcsam64.sys - Western Digital SCSI Arcitecture Model (SAM) WDM driver https://support.wdc.com/
- Oct 04 2016 - DisplayLinkXRUsbIo_x64_2.1.6.8682.sys - DisplayLink XR USB driver
- Jan 21 2019 - imaucxhpal.sys - MA-USB (UCX) HPAL driver
- Jan 21 2019 - iwigig.sys - WiGig MAC driver (Intel)
- Mar 19 2019 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- Apr 04 2019 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
- May 07 2019 - e1d68x64.sys - Intel(R) Gigabit Adapter driver
- Oct 02 2019 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- ================== Dump #6: 3RD PARTY DRIVERS (FULL) ===================
- Image name: wdcsam64.sys
- Search : https://www.google.com/search?q=wdcsam64.sys
- ADA Info : Western Digital SCSI Arcitecture Model (SAM) WDM driver https://support.wdc.com/
- Timestamp : Fri Oct 9 2015
- Image name: DisplayLinkXRUsbIo_x64_2.1.6.8682.sys
- Search : https://www.google.com/search?q=DisplayLinkXRUsbIo_x64_2.1.6.8682.sys
- ADA Info : DisplayLink XR USB driver
- Timestamp : Tue Oct 4 2016
- Image name: imaucxhpal.sys
- Search : https://www.google.com/search?q=imaucxhpal.sys
- ADA Info : MA-USB (UCX) HPAL driver
- Timestamp : Mon Jan 21 2019
- Image name: iwigig.sys
- Search : https://www.google.com/search?q=iwigig.sys
- ADA Info : WiGig MAC driver (Intel)
- Timestamp : Mon Jan 21 2019
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Tue Mar 19 2019
- Image name: TeeDriverW8x64.sys
- Search : https://www.google.com/search?q=TeeDriverW8x64.sys
- ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Timestamp : Thu Apr 4 2019
- Image name: e1d68x64.sys
- Search : https://www.google.com/search?q=e1d68x64.sys
- ADA Info : Intel(R) Gigabit Adapter driver
- Timestamp : Tue May 7 2019
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Wed Oct 2 2019
- ====================== Dump #6: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- acpipagr.sys ACPI Processor Aggregator Device driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CimFS.SYS Consumer IR Class Driver for eHome (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storport.sys Provides disk access during crash dump file generation (Microsoft)
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HdAudio.sys High Definition Audio Function driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- intelppm.sys Processor Device Driver (Microsoft)
- IntelTA.sys Intel Telemetry Driver
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kdcom.dll Kernel Debugger HW Extension DLL (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate.dll Media Center Update (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb10.sys Longhorn SMB Downlevel SubRdr (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msquic.sys Windows QUIC Driver
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndiscap.sys Microsoft NDIS Packet Capture Filter Driver
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- serenum.sys Serial Port Enumerator (Microsoft)
- serial.sys Serial Device Driver
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- stornvme.sys NVM Express Storport Miniport driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- ucx01000.sys USB Controller Extension (Microsoft)
- udfs.sys UDF File System driver (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbaudio2.sys Microsoft USB Audio Class 2.0 Driver
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- USBSTOR.SYS USB Mass Storage Class driver (Microsoft)
- usbvideo.sys USB Video Class Driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WpdUpFltr.sys Portable Device Upper Class Filter driver (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- WUDFRd.sys Windows Driver Foundation - User-mode Driver Framework Reflector driver (Microsoft)
- ====================== Dump #6: UNLOADED MODULES =======================
- fffff807`75a70000 fffff807`75a81000 MSKSSRV.sys
- fffff807`75a00000 fffff807`75a0c000 WdmCompanion
- fffff807`74b30000 fffff807`74b3f000 dump_storpor
- fffff807`74b80000 fffff807`74bb3000 dump_storahc
- fffff807`74be0000 fffff807`74bfe000 dump_dumpfve
- fffff807`77b30000 fffff807`77b85000 WUDFRd.sys
- fffff807`753d0000 fffff807`753ec000 dam.sys
- fffff807`61400000 fffff807`61411000 WdBoot.sys
- fffff807`624b0000 fffff807`624c0000 hwpolicy.sys
- ====================== Dump #6: BIOS INFORMATION =======================
- sysinfo: could not find necessary interfaces.
- sysinfo: note that mssmbios.sys must be loaded (XPSP2+).
- ========================== Dump #6: Extra #1 ===========================
- 8: kd> !verifier
- fffff8075e82a6c0: Unable to get verifier list.
- ========================== Dump #6: Extra #2 ===========================
- 8: kd> !thread
- THREAD ffffb904ddbea080 Cid 15d8.2dc4 Teb: 000000ddc787a000 Win32Thread: ffffb904df9ca380 RUNNING on processor 8
- Not impersonating
- GetUlongFromAddress: unable to read from fffff8075e81143c
- Owning Process ffffb904dc3dd080 Image: steamtours.exe
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 378555
- Context Switch Count 222 IdealProcessor: 2
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address 0x00007ff7bd6ba5d0
- Stack Init ffffce857d1dab90 Current ffffce857d1da2f0
- Base ffffce857d1db000 Limit ffffce857d1d4000 Call 0000000000000000
- Priority 9 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- ffff8200`2c74f018 fffff807`5dfef929 : 00000000`0000003b 00000000`c0000005 fffff807`5de42acc ffff8200`2c74f920 : nt!KeBugCheckEx
- ffff8200`2c74f020 fffff807`5dfeed7c : ffff8200`2c74f760 fffff807`5dce68e0 ffff8200`2c74f210 00000000`00000000 : nt!KiBugCheckDispatch+0x69
- ffff8200`2c74f160 fffff807`5dfe68df : fffff807`5dfeed00 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceHandler+0x7c
- ffff8200`2c74f1a0 fffff807`5de32fb7 : ffff8200`2c74f710 00000000`00000000 ffffce85`7d1da990 fffff807`5dfef375 : nt!RtlpExecuteHandlerForException+0xf
- ffff8200`2c74f1d0 fffff807`5de7b226 : ffffce85`7d1d9808 ffff8200`2c74fe20 ffffce85`7d1d9808 ffffb904`dda50b08 : nt!RtlDispatchException+0x297
- ffff8200`2c74f8f0 fffff807`5dfde8b2 : 448b1875`c0000023 f08b0b76`c63b6024 eb87a6e9`9f76c33b c085c000`00e5b8ff : nt!KiDispatchException+0x186
- ffff8200`2c74ffb0 fffff807`5dfde880 : fffff807`5dfefa65 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KxExceptionDispatchOnExceptionStack+0x12 (TrapFrame @ ffff8200`2c74fe70)
- ffffce85`7d1d96c8 fffff807`5dfefa65 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiExceptionDispatchOnExceptionStackContinue
- ffffce85`7d1d96d0 fffff807`5dfeb7a0 : 00000000`00000000 00220000`00000000 ffffce85`7d1d99e0 ffffce85`7d1d9a50 : nt!KiExceptionDispatch+0x125
- ffffce85`7d1d98b0 fffff807`5de42acc : 00000038`00200000 0001007a`00380000 fffff807`5de428e3 00000000`000000b2 : nt!KiGeneralProtectionFault+0x320 (TrapFrame @ ffffce85`7d1d98b0)
- ffffce85`7d1d9a48 fffff807`5de428e3 : 00000000`000000b2 ffffb904`dda4ffe0 00000000`00000000 ffffb904`dda50b00 : nt!RtlRbRemoveNode+0x7c
- ffffce85`7d1d9a60 fffff807`5de42258 : ffffb904`cfe02280 ffffb904`dda46000 ffffb904`cfe02280 ffffce85`7d1d9b68 : nt!RtlpHpVsChunkCoalesce+0x183
- ffffce85`7d1d9ac0 fffff807`5de40be4 : ffffb904`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!RtlpHpVsContextFree+0x188
- ffffce85`7d1d9b60 fffff807`5e5c2019 : ffffb904`00000500 ffffb904`dcce1220 00000000`00000000 01000000`00100000 : nt!ExFreeHeapPool+0x4d4
- ffffce85`7d1d9c40 fffff807`5de3dfd2 : ffffb904`00000001 ffffce85`7d1d9db9 00000000`00400201 ffffb904`d5b46b40 : nt!ExFreePool+0x9
- ffffce85`7d1d9c70 fffff807`5de3cd88 : 00000000`00000001 00000000`00000001 00000000`00000000 ffffb904`df2b95e0 : nt!IopCompleteRequest+0x8a2
- ffffce85`7d1d9d30 fffff807`5de3c697 : 00000000`00000000 00000000`00000001 ffffcf8c`fe7af970 ffffb904`df2b95e0 : nt!IopfCompleteRequest+0x6d8
- ffffce85`7d1d9e20 fffff807`619de788 : 00000000`00000000 ffffcf8c`00000001 ffffce85`7d1da100 fffff807`619de392 : nt!IofCompleteRequest+0x17
- ffffce85`7d1d9e50 fffff807`61acddae : 00000000`00000000 ffffcf8c`fe7af970 ffffcf8c`fe7af5a0 00000000`00000000 : Ntfs!NtfsExtendedCompleteRequestInternal+0x178
- ffffce85`7d1d9eb0 fffff807`61acc8d6 : ffffce85`7d1da100 ffffb904`df2b95e0 00000000`0000011a fffff807`00000002 : Ntfs!NtfsCommonQueryInformation+0xfbe
- ffffce85`7d1d9fb0 fffff807`61acc760 : ffffce85`7d1da100 ffffb904`df2b95e0 ffffb904`df2b95e0 fffff807`5de24fad : Ntfs!NtfsFsdDispatchSwitch+0x156
- ffffce85`7d1da0e0 fffff807`5de46d25 : ffffce85`7d1da450 fffff807`5b8a4b46 ffffce85`7d1db000 ffffce85`7d1d4000 : Ntfs!NtfsFsdDispatchWait+0x40
- ffffce85`7d1da380 fffff807`5b8a6ccf : 00000000`00000200 00000000`00000000 00000000`000004c0 fffff807`5e5c2094 : nt!IofCallDriver+0x55
- ffffce85`7d1da3c0 fffff807`5b8a48d3 : ffffce85`7d1da450 00000000`00000009 00000000`0000000e fffff807`00000000 : FLTMGR!FltpLegacyProcessingAfterPreCallbacksCompleted+0x28f
- ffffce85`7d1da430 fffff807`5de46d25 : ffffb904`dcce1220 fffff807`5de46d67 00000000`0000000e 00000000`00000000 : FLTMGR!FltpDispatch+0xa3
- ffffce85`7d1da490 fffff807`5e2a1148 : ffffce85`7d1da530 ffffb904`dcce1220 ffffb904`d5b46b40 ffffcf8c`00000000 : nt!IofCallDriver+0x55
- ffffce85`7d1da4d0 fffff807`5e29ee9d : ffffb904`d53ae800 00000000`00000000 00000000`000001dc ffffce85`7d1da5b0 : nt!IopQueryXxxInformation+0x120
- ffffce85`7d1da570 fffff807`5e29e9f6 : ffffb904`dcce1220 00000000`00000000 00000000`00000000 000000dd`c76af0e0 : nt!IopQueryNameInternal+0x3e9
- ffffce85`7d1da620 fffff807`5e29fa73 : ffffb904`df903840 ffffce85`7d1da810 ffffb904`dc3dd700 00000000`00000000 : nt!IopQueryName+0x26
- ffffce85`7d1da670 fffff807`5e26a984 : ffffb904`dcce1220 000000dd`c76af0e0 ffffb904`00000218 ffffce85`7d1da7d8 : nt!ObQueryNameStringMode+0xd3
- ffffce85`7d1da790 fffff807`5e269d85 : ffffa050`00b4a020 ffffa050`28005a50 ffffa050`28140028 ffffb904`dc3dd700 : nt!MmQueryVirtualMemory+0xbe4
- ffffce85`7d1da940 fffff807`5dfef375 : 00000000`00000000 00000000`00000000 00000000`00000000 ffffce85`7d1daa80 : nt!NtQueryVirtualMemory+0x25
- ffffce85`7d1da990 00007ff9`56d8b1f4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25 (TrapFrame @ ffffce85`7d1daa00)
- 000000dd`c76af098 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff9`56d8b1f4
- ========================================================================
- ======================= Dump #7: ANALYZE VERBOSE =======================
- ======================= File: 070620-5718-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 19041 MP (12 procs) Free x64
- Kernel base = 0xfffff801`1c600000 PsLoadedModuleList = 0xfffff801`1d22a2b0
- Debug session time: Mon Jul 6 14:09:44.963 2020 (UTC - 4:00)
- System Uptime: 0 days 0:25:07.630
- BugCheck 1A, {41792, ffffd73fff7635f8, 800000000000000, 0}
- Probably caused by : memory_corruption
- Followup: memory_corruption
- MEMORY_MANAGEMENT (1a)
- # Any other values for parameter 1 must be individually examined.
- Arguments:
- Arg1: 0000000000041792, A corrupt PTE has been detected. Parameter 2 contains the address of
- the PTE. Parameters 3/4 contain the low/high parts of the PTE.
- Arg2: ffffd73fff7635f8
- Arg3: 0800000000000000
- Arg4: 0000000000000000
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- DUMP_FILE_ATTRIBUTES: 0x8
- Kernel Generated Triage Dump
- MEMORY_CORRUPTOR: LARGE
- BUGCHECK_STR: 0x1a_41792
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- PROCESS_NAME: chrome.exe
- CURRENT_IRQL: 2
- STACK_TEXT:
- ffff8502`26d76b88 fffff801`1ca5418e : 00000000`0000001a 00000000`00041792 ffffd73f`ff7635f8 08000000`00000000 : nt!KeBugCheckEx
- ffff8502`26d76b90 fffff801`1c8119d1 : 00000000`00000003 ffffd73f`ff763000 ffff8502`26d77060 00000000`00000003 : nt!MiDeleteVa+0x191e6e
- ffff8502`26d76c80 fffff801`1c811cf0 : 00000000`00000000 ffffd809`4f644700 00000000`00000000 00000000`00000000 : nt!MiWalkPageTablesRecursively+0x301
- ffff8502`26d76d10 fffff801`1c811cf0 : 00000000`00000000 ffffd809`4f644700 ffffd76b`00000000 00000000`00000010 : nt!MiWalkPageTablesRecursively+0x620
- ffff8502`26d76da0 fffff801`1c811cf0 : ffff8502`26d77060 ffffd809`4f644700 ffffd76b`00000000 00000000`00000020 : nt!MiWalkPageTablesRecursively+0x620
- ffff8502`26d76e30 fffff801`1c80e5fb : 00000000`00000000 ffffd809`4f644700 00000000`00000000 00000000`00000030 : nt!MiWalkPageTablesRecursively+0x620
- ffff8502`26d76ec0 fffff801`1c8c22d1 : ffff8502`26d77060 ffffd809`00000000 ffffd73e`00000002 ffff8502`00000000 : nt!MiWalkPageTables+0x36b
- ffff8502`26d76fc0 fffff801`1c8a787f : 00000000`00000000 00000000`00000060 ffffd809`4f6447c0 00000000`00000000 : nt!MiDeletePagablePteRange+0x491
- ffff8502`26d77440 fffff801`1cbeab99 : ffffd809`4f644080 00000000`00000000 ffffd809`00000000 ffffd809`00000001 : nt!MiDeleteVad+0x41f
- ffff8502`26d77570 fffff801`1cc66dc0 : ffffd809`4f6d1da0 ffffd809`4f644d20 ffffd809`4f74f080 00000000`00000000 : nt!MiUnmapVad+0x49
- ffff8502`26d775a0 fffff801`1cc67c73 : ffffd809`4f6ccb20 ffffd809`4f6ccb20 ffffd809`4f6d1da0 ffffd809`4f644080 : nt!MiCleanVad+0x30
- ffff8502`26d775d0 fffff801`1ccba247 : ffffffff`00000000 ffffffff`ffffffff 00000000`00000001 ffffd809`4f644080 : nt!MmCleanProcessAddressSpace+0x137
- ffff8502`26d77650 fffff801`1cbe8e32 : ffffd809`4f644080 ffffc685`a0e55060 ffff8502`26d77890 00000000`00000000 : nt!PspRundownSingleProcess+0x13b
- ffff8502`26d776d0 fffff801`1ccf51e8 : 00000001`00000000 00000000`00000001 ffff8502`26d778e0 00000066`17280000 : nt!PspExitThread+0x5f6
- ffff8502`26d777d0 fffff801`1c82a4e7 : 00000000`40ad0088 00000000`00000000 00000000`00000000 fffff801`1c814bb6 : nt!KiSchedulerApcTerminate+0x38
- ffff8502`26d77810 fffff801`1c9e1fc0 : 00000066`183ff858 ffff8502`26d778c0 ffff8502`26d77a80 7fffffff`00000000 : nt!KiDeliverApc+0x487
- ffff8502`26d778c0 fffff801`1c9ef41f : ffffd809`4f74f080 00000000`00000001 ffff8502`26d77a18 fffffff7`c1fede00 : nt!KiInitiateUserApc+0x70
- ffff8502`26d77a00 00007fff`2f14ae14 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExit+0x9f
- 00000066`183ff828 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007fff`2f14ae14
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
- fffff8011c8c20e1-fffff8011c8c20e2 2 bytes - nt!MiDeletePagablePteRange+2a1
- [ 80 f6:00 d7 ]
- fffff8011c8c2348-fffff8011c8c234c 5 bytes - nt!MiDeleteVa+28 (+0x267)
- [ d0 be 7d fb f6:e0 da b5 6b d7 ]
- fffff8011c8c235b-fffff8011c8c235f 5 bytes - nt!MiDeleteVa+3b (+0x13)
- [ d7 be 7d fb f6:e7 da b5 6b d7 ]
- fffff8011c8c23c3-fffff8011c8c23c4 2 bytes - nt!MiDeleteVa+a3 (+0x68)
- [ 80 f6:00 d7 ]
- fffff8011c8c2462-fffff8011c8c2463 2 bytes - nt!MiDeleteVa+142 (+0x9f)
- [ 80 f6:00 d7 ]
- fffff8011c8c248f-fffff8011c8c2493 5 bytes - nt!MiDeleteVa+16f (+0x2d)
- [ d0 be 7d fb f6:e0 da b5 6b d7 ]
- fffff8011c8c24ef-fffff8011c8c24f0 2 bytes - nt!MiDeleteVa+1cf (+0x60)
- [ 80 fa:00 e9 ]
- fffff8011c8c2546-fffff8011c8c2547 2 bytes - nt!MiDeleteVa+226 (+0x57)
- [ 80 f6:00 d7 ]
- fffff8011c8c2566-fffff8011c8c256a 5 bytes - nt!MiDeleteVa+246 (+0x20)
- [ d0 be 7d fb f6:e0 da b5 6b d7 ]
- fffff8011c8c2576-fffff8011c8c257a 5 bytes - nt!MiDeleteVa+256 (+0x10)
- [ d7 be 7d fb f6:e7 da b5 6b d7 ]
- fffff8011c8c2620-fffff8011c8c2621 2 bytes - nt!MiDeleteVa+300 (+0xaa)
- [ 80 fa:00 e9 ]
- fffff8011c8c2889-fffff8011c8c288a 2 bytes - nt!MiDeleteVa+569 (+0x269)
- [ 80 f6:00 d7 ]
- fffff8011c8c28e3-fffff8011c8c28e4 2 bytes - nt!MiDeleteVa+5c3 (+0x5a)
- [ 80 fa:00 e9 ]
- fffff8011c8c28fb-fffff8011c8c28fc 2 bytes - nt!MiDeleteVa+5db (+0x18)
- [ 80 f6:00 d7 ]
- fffff8011c8c2916-fffff8011c8c291a 5 bytes - nt!MiDeleteVa+5f6 (+0x1b)
- [ d0 be 7d fb f6:e0 da b5 6b d7 ]
- fffff8011c8c296d-fffff8011c8c2971 5 bytes - nt!MiDeleteVa+64d (+0x57)
- [ d0 be 7d fb f6:e0 da b5 6b d7 ]
- fffff8011c8c29e7-fffff8011c8c29e9 3 bytes - nt!MiDeleteVa+6c7 (+0x7a)
- [ 40 fb f6:80 6b d7 ]
- fffff8011c8c29ff-fffff8011c8c2a03 5 bytes - nt!MiDeleteVa+6df (+0x18)
- [ d0 be 7d fb f6:e0 da b5 6b d7 ]
- fffff8011c8c2a43-fffff8011c8c2a44 2 bytes - nt!MiDeleteVa+723 (+0x44)
- [ 80 fa:00 e9 ]
- fffff8011c8c2c2b-fffff8011c8c2c2f 5 bytes - nt!MiDeleteVa+90b (+0x1e8)
- [ d0 be 7d fb f6:e0 da b5 6b d7 ]
- fffff8011c8c2c4e-fffff8011c8c2c50 3 bytes - nt!MiDeleteVa+92e (+0x23)
- [ 40 fb f6:80 6b d7 ]
- fffff8011c8c2c96-fffff8011c8c2c97 2 bytes - nt!MiDeleteVa+976 (+0x48)
- [ 80 fa:00 e9 ]
- fffff8011c8c2fbc-fffff8011c8c2fbd 2 bytes - nt!MiDeleteVa+c9c (+0x326)
- [ ff f6:7f d7 ]
- 75 errors : !nt (fffff8011c8c20e1-fffff8011c8c2fbd)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-07-06T18:09:44.000Z
- SUITE_MASK: 784
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #7: 3RD PARTY DRIVERS ======================
- Oct 09 2015 - wdcsam64.sys - Western Digital SCSI Arcitecture Model (SAM) WDM driver https://support.wdc.com/
- Jul 20 2017 - SteamStreamingSpeakers.sys - Steam Streaming Speakers driver (Valve Corporation)
- Jul 28 2017 - SteamStreamingMicrophone.sys - Steam Streaming Microphone driver (Valve Corporation)
- Jan 21 2019 - imaucxhpal.sys - MA-USB (UCX) HPAL driver
- Jan 21 2019 - iwigig.sys - WiGig MAC driver (Intel)
- Apr 04 2019 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
- May 07 2019 - e1d68x64.sys - Intel(R) Gigabit Adapter driver
- Jun 09 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- Jun 21 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- ================== Dump #7: 3RD PARTY DRIVERS (FULL) ===================
- Image name: wdcsam64.sys
- Search : https://www.google.com/search?q=wdcsam64.sys
- ADA Info : Western Digital SCSI Arcitecture Model (SAM) WDM driver https://support.wdc.com/
- Timestamp : Fri Oct 9 2015
- Image name: SteamStreamingSpeakers.sys
- Search : https://www.google.com/search?q=SteamStreamingSpeakers.sys
- ADA Info : Steam Streaming Speakers driver (Valve Corporation)
- Timestamp : Thu Jul 20 2017
- Image name: SteamStreamingMicrophone.sys
- Search : https://www.google.com/search?q=SteamStreamingMicrophone.sys
- ADA Info : Steam Streaming Microphone driver (Valve Corporation)
- Timestamp : Fri Jul 28 2017
- Image name: imaucxhpal.sys
- Search : https://www.google.com/search?q=imaucxhpal.sys
- ADA Info : MA-USB (UCX) HPAL driver
- Timestamp : Mon Jan 21 2019
- Image name: iwigig.sys
- Search : https://www.google.com/search?q=iwigig.sys
- ADA Info : WiGig MAC driver (Intel)
- Timestamp : Mon Jan 21 2019
- Image name: TeeDriverW8x64.sys
- Search : https://www.google.com/search?q=TeeDriverW8x64.sys
- ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Timestamp : Thu Apr 4 2019
- Image name: e1d68x64.sys
- Search : https://www.google.com/search?q=e1d68x64.sys
- ADA Info : Intel(R) Gigabit Adapter driver
- Timestamp : Tue May 7 2019
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Tue Jun 9 2020
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Sun Jun 21 2020
- ====================== Dump #7: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- acpipagr.sys ACPI Processor Aggregator Device driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CimFS.SYS Consumer IR Class Driver for eHome (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storport.sys Provides disk access during crash dump file generation (Microsoft)
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HdAudio.sys High Definition Audio Function driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- intelppm.sys Processor Device Driver (Microsoft)
- IntelTA.sys Intel Telemetry Driver
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kdcom.dll Kernel Debugger HW Extension DLL (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate.dll Media Center Update (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb10.sys Longhorn SMB Downlevel SubRdr (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msquic.sys Windows QUIC Driver
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndiscap.sys Microsoft NDIS Packet Capture Filter Driver
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- serenum.sys Serial Port Enumerator (Microsoft)
- serial.sys Serial Device Driver
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- stornvme.sys NVM Express Storport Miniport driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- ucx01000.sys USB Controller Extension (Microsoft)
- udfs.sys UDF File System driver (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- USBSTOR.SYS USB Mass Storage Class driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WpdUpFltr.sys Portable Device Upper Class Filter driver (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- WUDFRd.sys Windows Driver Foundation - User-mode Driver Framework Reflector driver (Microsoft)
- ====================== Dump #7: UNLOADED MODULES =======================
- fffff801`34470000 fffff801`3447f000 dump_storpor
- fffff801`344c0000 fffff801`344f3000 dump_storahc
- fffff801`34520000 fffff801`3453e000 dump_dumpfve
- fffff801`36600000 fffff801`36655000 WUDFRd.sys
- fffff801`33e70000 fffff801`33e8c000 dam.sys
- fffff801`20200000 fffff801`20211000 WdBoot.sys
- fffff801`212b0000 fffff801`212c0000 hwpolicy.sys
- ====================== Dump #7: BIOS INFORMATION =======================
- [SMBIOS Data Tables v3.1]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 2808 bytes]
- [BIOS Information (Type 0) - Length 26 - Handle 0000h]
- Vendor American Megatrends Inc.
- BIOS Version P4.20
- BIOS Starting Address Segment f000
- BIOS Release Date 10/31/2019
- BIOS ROM Size 1000000
- BIOS Characteristics
- 07: - PCI Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 27: - Keyboard Services Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 32: - BIOS Vendor Reserved
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 5
- BIOS Minor Revision 12
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
- Manufacturer ASRock
- Product Z370 Extreme4
- Version
- Feature Flags 09h
- -1387415840: - -1387415792: - ÷7?Öý
- Location
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 22 - Handle 0003h]
- Chassis Type Desktop
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 3
- [OEM Strings (Type 11) - Length 5 - Handle 000dh]
- Number of Strings 1
- [Physical Memory Array (Type 16) - Length 23 - Handle 0010h]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 67108864KB
- Number of Memory Devices 4
- [Memory Device (Type 17) - Length 40 - Handle 0011h]
- Physical Memory Array Handle 0010h
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM0
- Bank Locator BANK 0
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Device (Type 17) - Length 40 - Handle 0012h]
- Physical Memory Array Handle 0010h
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM1
- Bank Locator BANK 1
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 3200MHz
- Manufacturer 029E
- Part Number CMK16GX4M2B3200C16
- [Memory Device (Type 17) - Length 40 - Handle 0013h]
- Physical Memory Array Handle 0010h
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM0
- Bank Locator BANK 2
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Device (Type 17) - Length 40 - Handle 0014h]
- Physical Memory Array Handle 0010h
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM1
- Bank Locator BANK 3
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 3200MHz
- Manufacturer 029E
- Part Number CMK16GX4M2B3200C16
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0015h]
- Starting Address 00000000h
- Ending Address 00ffffffh
- Memory Array Handle 0010h
- Partition Width 02
- [Cache Information (Type 7) - Length 27 - Handle 0016h]
- Socket Designation L1 Cache
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0180h - 384K
- Installed Size 0180h - 384K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type ParitySingle-Bit ECC
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 27 - Handle 0017h]
- Socket Designation L2 Cache
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 0600h - 1536K
- Installed Size 0600h - 1536K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Unified
- Associativity 4-way Set-Associative
- [Cache Information (Type 7) - Length 27 - Handle 0018h]
- Socket Designation L3 Cache
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 3000h - 12288K
- Installed Size 3000h - 12288K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 16-way Set-Associative
- [Processor Information (Type 4) - Length 48 - Handle 0019h]
- Socket Designation CPUSocket
- Processor Type Central Processor
- Processor Family c6h - Specification Reserved
- Processor Manufacturer Intel(R) Corporation
- Processor ID ea060900fffbebbf
- Processor Version Intel(R) Core(TM) i7-8700K CPU @ 3.70GHz
- Processor Voltage 8ah - 1.0V
- External Clock 100MHz
- Max Speed 8300MHz
- Current Speed 3700MHz
- Status Enabled Populated
- Processor Upgrade Specification Reserved
- L1 Cache Handle 0016h
- L2 Cache Handle 0017h
- L3 Cache Handle 0018h
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 001ah]
- Starting Address 00000000h
- Ending Address 007fffffh
- Memory Device Handle 0012h
- Mem Array Mapped Adr Handle 0015h
- Partition Row Position 01
- Interleave Position 01
- Interleave Data Depth 02
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 001bh]
- Starting Address 00800000h
- Ending Address 00ffffffh
- Memory Device Handle 0014h
- Mem Array Mapped Adr Handle 0015h
- Partition Row Position 01
- Interleave Position 02
- Interleave Data Depth 02
- ========================== Dump #7: Extra #1 ===========================
- 7: kd> !verifier
- fffff8011d22a6c0: Unable to get verifier list.
- ========================== Dump #7: Extra #2 ===========================
- 7: kd> !thread
- THREAD ffffd8094f74f080 Cid 1ccc.2030 Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor 7
- Not impersonating
- GetUlongFromAddress: unable to read from fffff8011d21143c
- Owning Process ffffd8094f644080 Image: chrome.exe
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 96488
- Context Switch Count 29 IdealProcessor: 4
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address 0x00007ffeea648cf0
- Stack Init ffff850226d77b90 Current ffff850226d76910
- Base ffff850226d78000 Limit ffff850226d71000 Call 0000000000000000
- Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- ffff8502`26d76b88 fffff801`1ca5418e : 00000000`0000001a 00000000`00041792 ffffd73f`ff7635f8 08000000`00000000 : nt!KeBugCheckEx
- ffff8502`26d76b90 fffff801`1c8119d1 : 00000000`00000003 ffffd73f`ff763000 ffff8502`26d77060 00000000`00000003 : nt!MiDeleteVa+0x191e6e
- ffff8502`26d76c80 fffff801`1c811cf0 : 00000000`00000000 ffffd809`4f644700 00000000`00000000 00000000`00000000 : nt!MiWalkPageTablesRecursively+0x301
- ffff8502`26d76d10 fffff801`1c811cf0 : 00000000`00000000 ffffd809`4f644700 ffffd76b`00000000 00000000`00000010 : nt!MiWalkPageTablesRecursively+0x620
- ffff8502`26d76da0 fffff801`1c811cf0 : ffff8502`26d77060 ffffd809`4f644700 ffffd76b`00000000 00000000`00000020 : nt!MiWalkPageTablesRecursively+0x620
- ffff8502`26d76e30 fffff801`1c80e5fb : 00000000`00000000 ffffd809`4f644700 00000000`00000000 00000000`00000030 : nt!MiWalkPageTablesRecursively+0x620
- ffff8502`26d76ec0 fffff801`1c8c22d1 : ffff8502`26d77060 ffffd809`00000000 ffffd73e`00000002 ffff8502`00000000 : nt!MiWalkPageTables+0x36b
- ffff8502`26d76fc0 fffff801`1c8a787f : 00000000`00000000 00000000`00000060 ffffd809`4f6447c0 00000000`00000000 : nt!MiDeletePagablePteRange+0x491
- ffff8502`26d77440 fffff801`1cbeab99 : ffffd809`4f644080 00000000`00000000 ffffd809`00000000 ffffd809`00000001 : nt!MiDeleteVad+0x41f
- ffff8502`26d77570 fffff801`1cc66dc0 : ffffd809`4f6d1da0 ffffd809`4f644d20 ffffd809`4f74f080 00000000`00000000 : nt!MiUnmapVad+0x49
- ffff8502`26d775a0 fffff801`1cc67c73 : ffffd809`4f6ccb20 ffffd809`4f6ccb20 ffffd809`4f6d1da0 ffffd809`4f644080 : nt!MiCleanVad+0x30
- ffff8502`26d775d0 fffff801`1ccba247 : ffffffff`00000000 ffffffff`ffffffff 00000000`00000001 ffffd809`4f644080 : nt!MmCleanProcessAddressSpace+0x137
- ffff8502`26d77650 fffff801`1cbe8e32 : ffffd809`4f644080 ffffc685`a0e55060 ffff8502`26d77890 00000000`00000000 : nt!PspRundownSingleProcess+0x13b
- ffff8502`26d776d0 fffff801`1ccf51e8 : 00000001`00000000 00000000`00000001 ffff8502`26d778e0 00000066`17280000 : nt!PspExitThread+0x5f6
- ffff8502`26d777d0 fffff801`1c82a4e7 : 00000000`40ad0088 00000000`00000000 00000000`00000000 fffff801`1c814bb6 : nt!KiSchedulerApcTerminate+0x38
- ffff8502`26d77810 fffff801`1c9e1fc0 : 00000066`183ff858 ffff8502`26d778c0 ffff8502`26d77a80 7fffffff`00000000 : nt!KiDeliverApc+0x487
- ffff8502`26d778c0 fffff801`1c9ef41f : ffffd809`4f74f080 00000000`00000001 ffff8502`26d77a18 fffffff7`c1fede00 : nt!KiInitiateUserApc+0x70
- ffff8502`26d77a00 00007fff`2f14ae14 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExit+0x9f (TrapFrame @ ffff8502`26d77a00)
- 00000066`183ff828 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007fff`2f14ae14
- ========================================================================
- ======================= Dump #8: ANALYZE VERBOSE =======================
- ======================= File: 070620-5062-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 19041 MP (12 procs) Free x64
- Kernel base = 0xfffff802`3f000000 PsLoadedModuleList = 0xfffff802`3fc2a2b0
- Debug session time: Mon Jul 6 14:35:12.589 2020 (UTC - 4:00)
- System Uptime: 0 days 0:12:27.256
- BugCheck 1A, {41201, ffffa780ab4716e8, 81000002762dd867, ffff96893ce65a30}
- Probably caused by : memory_corruption ( nt!MiGetPageProtection+19544e )
- Followup: MachineOwner
- MEMORY_MANAGEMENT (1a)
- # Any other values for parameter 1 must be individually examined.
- Arguments:
- Arg1: 0000000000041201, The subtype of the bugcheck.
- Arg2: ffffa780ab4716e8
- Arg3: 81000002762dd867
- Arg4: ffff96893ce65a30
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- DUMP_FILE_ATTRIBUTES: 0x8
- Kernel Generated Triage Dump
- BUGCHECK_STR: 0x1a_41201
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
- PROCESS_NAME: Overwatch.exe
- CURRENT_IRQL: 2
- LAST_CONTROL_TRANSFER: from fffff8023f44be8e to fffff8023f3dda20
- STACK_TEXT:
- ffffc309`28fa7448 fffff802`3f44be8e : 00000000`0000001a 00000000`00041201 ffffa780`ab4716e8 81000002`762dd867 : nt!KeBugCheckEx
- ffffc309`28fa7450 fffff802`3f2b5d14 : 00000000`00001000 00000000`00000000 00000000`00000000 ffff9689`3ce65a30 : nt!MiGetPageProtection+0x19544e
- ffffc309`28fa74b0 fffff802`3f2a3bff : 00000000`00000000 00000156`8e2a0000 00000000`00000000 00000000`00000000 : nt!MiQueryAddressState+0x2f4
- ffffc309`28fa76d0 fffff802`3f66a5dc : 00000000`00000000 00000000`00000000 ffff9689`00000000 00000000`00000000 : nt!MiQueryAddressSpan+0xcf
- ffffc309`28fa7790 fffff802`3f669d85 : 00000000`00000059 00000000`00000000 ffff9689`00000001 0000004e`466fe2b8 : nt!MmQueryVirtualMemory+0x83c
- ffffc309`28fa7940 fffff802`3f3ef375 : 00000000`00000001 0000004e`466fe2b8 00000000`000ed107 00000000`00000000 : nt!NtQueryVirtualMemory+0x25
- ffffc309`28fa7990 00000156`1ea50b68 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
- 0000004e`466fe338 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00000156`1ea50b68
- STACK_COMMAND: kb
- THREAD_SHA1_HASH_MOD_FUNC: daeab5d68ba3ecb3234b5b8938d47aee75235996
- THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 3aeafd959efe4759b4a5f4ef3cd11db1a0a65eeb
- THREAD_SHA1_HASH_MOD: 30a3e915496deaace47137d5b90c3ecc03746bf6
- FOLLOWUP_IP:
- nt!MiGetPageProtection+19544e
- fffff802`3f44be8e cc int 3
- FAULT_INSTR_CODE: d8b48cc
- SYMBOL_STACK_INDEX: 1
- SYMBOL_NAME: nt!MiGetPageProtection+19544e
- FOLLOWUP_NAME: MachineOwner
- MODULE_NAME: nt
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- IMAGE_VERSION: 10.0.19041.330
- IMAGE_NAME: memory_corruption
- BUCKET_ID_FUNC_OFFSET: 19544e
- FAILURE_BUCKET_ID: 0x1a_41201_nt!MiGetPageProtection
- BUCKET_ID: 0x1a_41201_nt!MiGetPageProtection
- PRIMARY_PROBLEM_CLASS: 0x1a_41201_nt!MiGetPageProtection
- TARGET_TIME: 2020-07-06T18:35:12.000Z
- SUITE_MASK: 784
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:0x1a_41201_nt!migetpageprotection
- FAILURE_ID_HASH: {c1fe3b27-3ba8-d99e-656f-85f3d58dc669}
- Followup: MachineOwner
- ====================== Dump #8: 3RD PARTY DRIVERS ======================
- Oct 09 2015 - wdcsam64.sys - Western Digital SCSI Arcitecture Model (SAM) WDM driver https://support.wdc.com/
- Jul 20 2017 - SteamStreamingSpeakers.sys - Steam Streaming Speakers driver (Valve Corporation)
- Jul 28 2017 - SteamStreamingMicrophone.sys - Steam Streaming Microphone driver (Valve Corporation)
- Jan 21 2019 - imaucxhpal.sys - MA-USB (UCX) HPAL driver
- Jan 21 2019 - iwigig.sys - WiGig MAC driver (Intel)
- Apr 04 2019 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
- May 07 2019 - e1d68x64.sys - Intel(R) Gigabit Adapter driver
- Jun 09 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- Jun 21 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- ================== Dump #8: 3RD PARTY DRIVERS (FULL) ===================
- Image name: wdcsam64.sys
- Search : https://www.google.com/search?q=wdcsam64.sys
- ADA Info : Western Digital SCSI Arcitecture Model (SAM) WDM driver https://support.wdc.com/
- Timestamp : Fri Oct 9 2015
- Image name: SteamStreamingSpeakers.sys
- Search : https://www.google.com/search?q=SteamStreamingSpeakers.sys
- ADA Info : Steam Streaming Speakers driver (Valve Corporation)
- Timestamp : Thu Jul 20 2017
- Image name: SteamStreamingMicrophone.sys
- Search : https://www.google.com/search?q=SteamStreamingMicrophone.sys
- ADA Info : Steam Streaming Microphone driver (Valve Corporation)
- Timestamp : Fri Jul 28 2017
- Image name: imaucxhpal.sys
- Search : https://www.google.com/search?q=imaucxhpal.sys
- ADA Info : MA-USB (UCX) HPAL driver
- Timestamp : Mon Jan 21 2019
- Image name: iwigig.sys
- Search : https://www.google.com/search?q=iwigig.sys
- ADA Info : WiGig MAC driver (Intel)
- Timestamp : Mon Jan 21 2019
- Image name: TeeDriverW8x64.sys
- Search : https://www.google.com/search?q=TeeDriverW8x64.sys
- ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Timestamp : Thu Apr 4 2019
- Image name: e1d68x64.sys
- Search : https://www.google.com/search?q=e1d68x64.sys
- ADA Info : Intel(R) Gigabit Adapter driver
- Timestamp : Tue May 7 2019
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Tue Jun 9 2020
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Sun Jun 21 2020
- ====================== Dump #8: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- acpipagr.sys ACPI Processor Aggregator Device driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CimFS.SYS Consumer IR Class Driver for eHome (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storport.sys Provides disk access during crash dump file generation (Microsoft)
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HdAudio.sys High Definition Audio Function driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- intelppm.sys Processor Device Driver (Microsoft)
- IntelTA.sys Intel Telemetry Driver
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kdcom.dll Kernel Debugger HW Extension DLL (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate.dll Media Center Update (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb10.sys Longhorn SMB Downlevel SubRdr (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msquic.sys Windows QUIC Driver
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndiscap.sys Microsoft NDIS Packet Capture Filter Driver
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- serenum.sys Serial Port Enumerator (Microsoft)
- serial.sys Serial Device Driver
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- stornvme.sys NVM Express Storport Miniport driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- ucx01000.sys USB Controller Extension (Microsoft)
- udfs.sys UDF File System driver (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- USBSTOR.SYS USB Mass Storage Class driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WpdUpFltr.sys Portable Device Upper Class Filter driver (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- WUDFRd.sys Windows Driver Foundation - User-mode Driver Framework Reflector driver (Microsoft)
- ====================== Dump #8: UNLOADED MODULES =======================
- fffff802`57370000 fffff802`5737f000 dump_storpor
- fffff802`573c0000 fffff802`573f3000 dump_storahc
- fffff802`57220000 fffff802`5723e000 dump_dumpfve
- fffff802`57f40000 fffff802`57f95000 WUDFRd.sys
- fffff802`57b50000 fffff802`57b6c000 dam.sys
- fffff802`43e00000 fffff802`43e11000 WdBoot.sys
- fffff802`44eb0000 fffff802`44ec0000 hwpolicy.sys
- ====================== Dump #8: BIOS INFORMATION =======================
- [SMBIOS Data Tables v3.1]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 2808 bytes]
- [BIOS Information (Type 0) - Length 26 - Handle 0000h]
- Vendor American Megatrends Inc.
- BIOS Version P4.20
- BIOS Starting Address Segment f000
- BIOS Release Date 10/31/2019
- BIOS ROM Size 1000000
- BIOS Characteristics
- 07: - PCI Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 27: - Keyboard Services Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 32: - BIOS Vendor Reserved
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 5
- BIOS Minor Revision 12
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
- Manufacturer ASRock
- Product Z370 Extreme4
- Version
- Feature Flags 09h
- -1387415840: - -1387415792: - ÷7?Öý
- Location
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 22 - Handle 0003h]
- Chassis Type Desktop
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 3
- [OEM Strings (Type 11) - Length 5 - Handle 000dh]
- Number of Strings 1
- [Physical Memory Array (Type 16) - Length 23 - Handle 0010h]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 67108864KB
- Number of Memory Devices 4
- [Memory Device (Type 17) - Length 40 - Handle 0011h]
- Physical Memory Array Handle 0010h
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM0
- Bank Locator BANK 0
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Device (Type 17) - Length 40 - Handle 0012h]
- Physical Memory Array Handle 0010h
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM1
- Bank Locator BANK 1
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 3200MHz
- Manufacturer 029E
- Part Number CMK16GX4M2B3200C16
- [Memory Device (Type 17) - Length 40 - Handle 0013h]
- Physical Memory Array Handle 0010h
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM0
- Bank Locator BANK 2
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Device (Type 17) - Length 40 - Handle 0014h]
- Physical Memory Array Handle 0010h
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM1
- Bank Locator BANK 3
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 3200MHz
- Manufacturer 029E
- Part Number CMK16GX4M2B3200C16
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0015h]
- Starting Address 00000000h
- Ending Address 00ffffffh
- Memory Array Handle 0010h
- Partition Width 02
- [Cache Information (Type 7) - Length 27 - Handle 0016h]
- Socket Designation L1 Cache
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0180h - 384K
- Installed Size 0180h - 384K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type ParitySingle-Bit ECC
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 27 - Handle 0017h]
- Socket Designation L2 Cache
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 0600h - 1536K
- Installed Size 0600h - 1536K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Unified
- Associativity 4-way Set-Associative
- [Cache Information (Type 7) - Length 27 - Handle 0018h]
- Socket Designation L3 Cache
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 3000h - 12288K
- Installed Size 3000h - 12288K
- Supported SRAM Type 0020h - Synchronous
- Current SRAM Type 0020h - Synchronous
- Cache Speed 0ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 16-way Set-Associative
- [Processor Information (Type 4) - Length 48 - Handle 0019h]
- Socket Designation CPUSocket
- Processor Type Central Processor
- Processor Family c6h - Specification Reserved
- Processor Manufacturer Intel(R) Corporation
- Processor ID ea060900fffbebbf
- Processor Version Intel(R) Core(TM) i7-8700K CPU @ 3.70GHz
- Processor Voltage 8ah - 1.0V
- External Clock 100MHz
- Max Speed 8300MHz
- Current Speed 3700MHz
- Status Enabled Populated
- Processor Upgrade Specification Reserved
- L1 Cache Handle 0016h
- L2 Cache Handle 0017h
- L3 Cache Handle 0018h
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 001ah]
- Starting Address 00000000h
- Ending Address 007fffffh
- Memory Device Handle 0012h
- Mem Array Mapped Adr Handle 0015h
- Partition Row Position 01
- Interleave Position 01
- Interleave Data Depth 02
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 001bh]
- Starting Address 00800000h
- Ending Address 00ffffffh
- Memory Device Handle 0014h
- Mem Array Mapped Adr Handle 0015h
- Partition Row Position 01
- Interleave Position 02
- Interleave Data Depth 02
- ========================== Dump #8: Extra #1 ===========================
- 3: kd> !verifier
- fffff8023fc2a6c0: Unable to get verifier list.
- ========================== Dump #8: Extra #2 ===========================
- 3: kd> !thread
- THREAD ffff96893ab47080 Cid 2490.2868 Teb: 0000004e42860000 Win32Thread: ffff96893f4118c0 RUNNING on processor 3
- Not impersonating
- GetUlongFromAddress: unable to read from fffff8023fc1143c
- Owning Process ffff968938f8d300 Image: Overwatch.exe
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 47824
- Context Switch Count 83142 IdealProcessor: 2
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address 0x00007ff6a16c0ab8
- Stack Init ffffc30928fa7b90 Current ffffc30928fa7670
- Base ffffc30928fa8000 Limit ffffc30928fa1000 Call 0000000000000000
- Priority 10 BasePriority 8 PriorityDecrement 2 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- ffffc309`28fa7448 fffff802`3f44be8e : 00000000`0000001a 00000000`00041201 ffffa780`ab4716e8 81000002`762dd867 : nt!KeBugCheckEx
- ffffc309`28fa7450 fffff802`3f2b5d14 : 00000000`00001000 00000000`00000000 00000000`00000000 ffff9689`3ce65a30 : nt!MiGetPageProtection+0x19544e
- ffffc309`28fa74b0 fffff802`3f2a3bff : 00000000`00000000 00000156`8e2a0000 00000000`00000000 00000000`00000000 : nt!MiQueryAddressState+0x2f4
- ffffc309`28fa76d0 fffff802`3f66a5dc : 00000000`00000000 00000000`00000000 ffff9689`00000000 00000000`00000000 : nt!MiQueryAddressSpan+0xcf
- ffffc309`28fa7790 fffff802`3f669d85 : 00000000`00000059 00000000`00000000 ffff9689`00000001 0000004e`466fe2b8 : nt!MmQueryVirtualMemory+0x83c
- ffffc309`28fa7940 fffff802`3f3ef375 : 00000000`00000001 0000004e`466fe2b8 00000000`000ed107 00000000`00000000 : nt!NtQueryVirtualMemory+0x25
- ffffc309`28fa7990 00000156`1ea50b68 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25 (TrapFrame @ ffffc309`28fa7a00)
- 0000004e`466fe338 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00000156`1ea50b68
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement