Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Microsoft (R) Windows Debugger Version 10.0.17134.1 AMD64
- Copyright (c) Microsoft Corporation. All rights reserved.
- Loading Dump File [C:\Windows\MEMORY.DMP]
- Kernel Bitmap Dump File: Kernel address space is available, User address space may not be available.
- Symbol search path is: srv*
- Executable search path is:
- Windows 10 Kernel Version 17134 MP (4 procs) Free x64
- Product: WinNt, suite: TerminalServer SingleUserTS
- Built by: 17134.1.amd64fre.rs4_release.180410-1804
- Machine Name:
- Kernel base = 0xfffff803`e849b000 PsLoadedModuleList = 0xfffff803`e88551f0
- Debug session time: Wed Aug 1 16:25:29.362 2018 (UTC + 2:00)
- System Uptime: 0 days 0:28:53.276
- Loading Kernel Symbols
- ...............................................................
- ................................................................
- ................................................................
- .....................
- Loading User Symbols
- PEB is paged out (Peb.Ldr = 00000058`358a5018). Type ".hh dbgerr001" for details
- Loading unloaded module list
- ..............
- *******************************************************************************
- * *
- * Bugcheck Analysis *
- * *
- *******************************************************************************
- Use !analyze -v to get detailed debugging information.
- BugCheck 3B, {c0000096, fffff803fce00795, ffffc587d79a6cf0, 0}
- *** ERROR: Module load completed but symbols could not be loaded for GAGCQKOKLFAH.sys
- Probably caused by : GAGCQKOKLFAH.sys ( GAGCQKOKLFAH+795 )
- Followup: MachineOwner
- ---------
- 2: kd> !analyze -v
- *******************************************************************************
- * *
- * Bugcheck Analysis *
- * *
- *******************************************************************************
- SYSTEM_SERVICE_EXCEPTION (3b)
- An exception happened while executing a system service routine.
- Arguments:
- Arg1: 00000000c0000096, Exception code that caused the bugcheck
- Arg2: fffff803fce00795, Address of the instruction which caused the bugcheck
- Arg3: ffffc587d79a6cf0, Address of the context record for the exception that caused the bugcheck
- Arg4: 0000000000000000, zero.
- Debugging Details:
- ------------------
- KEY_VALUES_STRING: 1
- TIMELINE_ANALYSIS: 1
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 401
- BUILD_VERSION_STRING: 17134.1.amd64fre.rs4_release.180410-1804
- SYSTEM_MANUFACTURER: Microsoft Corporation
- SYSTEM_PRODUCT_NAME: Surface Pro 4
- SYSTEM_SKU: Surface_Pro_4
- SYSTEM_VERSION: D:0B:08F:1C:03P:38
- BIOS_VENDOR: Microsoft Corporation
- BIOS_VERSION: 108.1926.769
- BIOS_DATE: 12/06/2017
- BASEBOARD_MANUFACTURER: Microsoft Corporation
- BASEBOARD_PRODUCT: Surface Pro 4
- DUMP_TYPE: 1
- BUGCHECK_P1: c0000096
- BUGCHECK_P2: fffff803fce00795
- BUGCHECK_P3: ffffc587d79a6cf0
- BUGCHECK_P4: 0
- EXCEPTION_CODE: (NTSTATUS) 0xc0000096 - {AUSNAHME} Privilegierte Anweisung
- FAULTING_IP:
- GAGCQKOKLFAH+795
- fffff803`fce00795 0f22e0 mov cr4,rax
- CONTEXT: ffffc587d79a6cf0 -- (.cxr 0xffffc587d79a6cf0)
- rax=0000000000070678 rbx=ffffc80eba1440b0 rcx=ffffc587d79a7710
- rdx=00000000aa013044 rsi=0000000000000004 rdi=ffffc80eb96f2500
- rip=fffff803fce00795 rsp=ffffc587d79a76e8 rbp=ffffc80eb9fbf080
- r8=0000000000000004 r9=0000000000000008 r10=00000000aa013044
- r11=00000000aa012044 r12=ffffc80eb9fbf080 r13=ffffc80eb42bcc60
- r14=0000000000000002 r15=0000000000000000
- iopl=0 nv up di pl nz na po nc
- cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00000006
- GAGCQKOKLFAH+0x795:
- fffff803`fce00795 0f22e0 mov cr4,rax
- Resetting default scope
- CPU_COUNT: 4
- CPU_MHZ: 9c0
- CPU_VENDOR: GenuineIntel
- CPU_FAMILY: 6
- CPU_MODEL: 4e
- CPU_STEPPING: 3
- CPU_MICROCODE: 6,4e,3,0 (F,M,S,R) SIG: C2'00000000 (cache) C2'00000000 (init)
- BLACKBOXBSD: 1 (!blackboxbsd)
- BLACKBOXPNP: 1 (!blackboxpnp)
- DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
- BUGCHECK_STR: 0x3B
- PROCESS_NAME: PerfectInjector.exe
- CURRENT_IRQL: 0
- ANALYSIS_SESSION_HOST: DESKTOP-K3NKTIF
- ANALYSIS_SESSION_TIME: 08-01-2018 16:27:00.0678
- ANALYSIS_VERSION: 10.0.17134.1 amd64fre
- LAST_CONTROL_TRANSFER: from fffff803fce0056e to fffff803fce00795
- STACK_TEXT:
- ffffc587`d79a76e8 fffff803`fce0056e : ffffc587`d79a7940 00000001`5fb7f820 ffffc587`d79a7978 00000000`00001001 : GAGCQKOKLFAH+0x795
- ffffc587`d79a76f0 fffff803`fce00613 : 00000195`99500008 00000000`00000000 00007ff7`d691036f 00000000`0358ed20 : GAGCQKOKLFAH+0x56e
- ffffc587`d79a7740 fffff803`e851f1a9 : ffffc80e`b85d5580 fffff803`e851cc75 ffffc80e`ba1440b0 00000000`20206f49 : GAGCQKOKLFAH+0x613
- ffffc587`d79a7780 fffff803`e89922eb : ffffc80e`ba1440b0 ffffc587`d79a7b00 00000000`00000001 00000000`00000000 : nt!IofCallDriver+0x59
- ffffc587`d79a77c0 fffff803`e899e22f : ffffc80e`00000000 ffffc80e`b9fbf0d0 00000000`00000000 ffffc587`d79a7b00 : nt!IopSynchronousServiceTail+0x1ab
- ffffc587`d79a7870 fffff803`e899e9d6 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!IopXxxControlFile+0x66f
- ffffc587`d79a79a0 fffff803`e8643a43 : 00000000`00000001 00000000`00000000 00000000`00000000 00000000`00000000 : nt!NtDeviceIoControlFile+0x56
- ffffc587`d79a7a10 00007fff`56b69f94 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
- 00000058`35aff648 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007fff`56b69f94
- THREAD_SHA1_HASH_MOD_FUNC: 1669e19263841d1c39148faa3487b006d89509c3
- THREAD_SHA1_HASH_MOD_FUNC_OFFSET: e175c5c28cc3a96e2e55c9c54c4eeb9a701b4b56
- THREAD_SHA1_HASH_MOD: ff7cfd54b792af039a639cbf768a3584e617f180
- FOLLOWUP_IP:
- GAGCQKOKLFAH+795
- fffff803`fce00795 0f22e0 mov cr4,rax
- FAULT_INSTR_CODE: c3e0220f
- SYMBOL_STACK_INDEX: 0
- SYMBOL_NAME: GAGCQKOKLFAH+795
- FOLLOWUP_NAME: MachineOwner
- MODULE_NAME: GAGCQKOKLFAH
- IMAGE_NAME: GAGCQKOKLFAH.sys
- DEBUG_FLR_IMAGE_TIMESTAMP: 57cd1415
- STACK_COMMAND: .cxr 0xffffc587d79a6cf0 ; kb
- BUCKET_ID_FUNC_OFFSET: 795
- FAILURE_BUCKET_ID: 0x3B_GAGCQKOKLFAH!unknown_function
- BUCKET_ID: 0x3B_GAGCQKOKLFAH!unknown_function
- PRIMARY_PROBLEM_CLASS: 0x3B_GAGCQKOKLFAH!unknown_function
- TARGET_TIME: 2018-08-01T14:25:29.000Z
- OSBUILD: 17134
- OSSERVICEPACK: 0
- SERVICEPACK_NUMBER: 0
- OS_REVISION: 0
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- OSPLATFORM_TYPE: x64
- OSNAME: Windows 10
- OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
- OS_LOCALE:
- USER_LCID: 0
- OSBUILD_TIMESTAMP: 2018-07-13 06:03:11
- BUILDDATESTAMP_STR: 180410-1804
- BUILDLAB_STR: rs4_release
- BUILDOSVER_STR: 10.0.17134.1.amd64fre.rs4_release.180410-1804
- ANALYSIS_SESSION_ELAPSED_TIME: fe6
- ANALYSIS_SOURCE: KM
- FAILURE_ID_HASH_STRING: km:0x3b_gagcqkoklfah!unknown_function
- FAILURE_ID_HASH: {c17f572d-033a-b643-835e-72ee026d2c8e}
- Followup: MachineOwner
- ---------
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement