Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Microsoft (R) Windows Debugger Version 10.0.15063.468 AMD64
- Copyright (c) Microsoft Corporation. All rights reserved.
- Loading Dump File [B:\d\092217-14734-01.dmp]
- Mini Kernel Dump File: Only registers and stack trace are available
- ************* Symbol Path validation summary **************
- Response Time (ms) Location
- Deferred srv*c:\symbols*http://msdl.microsoft.com/download/symbols
- Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols
- Executable search path is:
- Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
- *** WARNING: Unable to verify timestamp for ntoskrnl.exe
- *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
- Windows 10 Kernel Version 16294 MP (16 procs) Free x64
- Product: WinNt, suite: TerminalServer SingleUserTS
- Built by: 16294.1.amd64fre.rs3_release.170916-2023
- Machine Name:
- Kernel base = 0xfffff800`2c087000 PsLoadedModuleList = 0xfffff800`2c3e8fb0
- Debug session time: Fri Sep 22 20:37:01.519 2017 (UTC + 1:00)
- System Uptime: 0 days 20:22:07.225
- Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
- *** WARNING: Unable to verify timestamp for ntoskrnl.exe
- *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
- Loading Kernel Symbols
- ...............................................................
- ................................................................
- ................................................................
- ...............................
- Loading User Symbols
- Loading unloaded module list
- ............................................
- ************* Symbol Loading Error Summary **************
- Module name Error
- ntoskrnl The system cannot find the file specified
- You can troubleshoot most symbol related issues by turning on symbol loading diagnostics (!sym noisy) and repeating the command that caused symbols to be loaded.
- You should also verify that your symbol search path (.sympath) is correct.
- *******************************************************************************
- * *
- * Bugcheck Analysis *
- * *
- *******************************************************************************
- Use !analyze -v to get detailed debugging information.
- BugCheck 9F, {3, ffff850ca8da5060, ffff8308022378f0, ffff850ca82b2640}
- ***** Kernel symbols are WRONG. Please fix symbols to do analysis.
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: NT!_DEVICE_OBJECT ***
- *** ***
- *************************************************************************
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: nt!_IRP ***
- *** ***
- *************************************************************************
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: nt!_IRP ***
- *** ***
- *************************************************************************
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: nt!_TRIAGE_9F_POWER ***
- *** ***
- *************************************************************************
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: nt!_IRP ***
- *** ***
- *************************************************************************
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: nt!_IO_STACK_LOCATION ***
- *** ***
- *************************************************************************
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: nt!_IRP ***
- *** ***
- *************************************************************************
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: nt!_DEVICE_OBJECT ***
- *** ***
- *************************************************************************
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: nt!_EPROCESS ***
- *** ***
- *************************************************************************
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: nt!_KPRCB ***
- *** ***
- *************************************************************************
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: nt!_IRP ***
- *** ***
- *************************************************************************
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: nt!_KPRCB ***
- *** ***
- *************************************************************************
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: nt!_KPRCB ***
- *** ***
- *************************************************************************
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: nt!_KPRCB ***
- *** ***
- *************************************************************************
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: nt!_KTHREAD ***
- *** ***
- *************************************************************************
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: nt!_KPRCB ***
- *** ***
- *************************************************************************
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: nt!_KPRCB ***
- *** ***
- *************************************************************************
- Probably caused by : ntoskrnl.wrong.symbols.exe ( nt_wrong_symbols!59BE13EC8D2000 )
- Followup: MachineOwner
- ---------
- 2: kd> .logclose
- Closing open log file C:\Users\Raymond\AppData\Local\msdart_crashanalyzer_kd_ansi.log
- Opened log file 'C:\Users\Raymond\AppData\Local\msdart_crashanalyzer_kd_unicode.log'
- 2: kd> !analyze -v
- *******************************************************************************
- * *
- * Bugcheck Analysis *
- * *
- *******************************************************************************
- DRIVER_POWER_STATE_FAILURE (9f)
- A driver has failed to complete a power IRP within a specific time.
- Arguments:
- Arg1: 0000000000000003, A device object has been blocking an Irp for too long a time
- Arg2: ffff850ca8da5060, Physical Device Object of the stack
- Arg3: ffff8308022378f0, nt!TRIAGE_9F_POWER on Win7 and higher, otherwise the Functional Device Object of the stack
- Arg4: ffff850ca82b2640, The blocked IRP
- Debugging Details:
- ------------------
- ***** Kernel symbols are WRONG. Please fix symbols to do analysis.
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: NT!_DEVICE_OBJECT ***
- *** ***
- *************************************************************************
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: nt!_IRP ***
- *** ***
- *************************************************************************
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: nt!_IRP ***
- *** ***
- *************************************************************************
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: nt!_TRIAGE_9F_POWER ***
- *** ***
- *************************************************************************
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: nt!_IRP ***
- *** ***
- *************************************************************************
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: nt!_IO_STACK_LOCATION ***
- *** ***
- *************************************************************************
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: nt!_IRP ***
- *** ***
- *************************************************************************
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: nt!_DEVICE_OBJECT ***
- *** ***
- *************************************************************************
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: nt!_EPROCESS ***
- *** ***
- *************************************************************************
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: nt!_KPRCB ***
- *** ***
- *************************************************************************
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: nt!_IRP ***
- *** ***
- *************************************************************************
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: nt!_KPRCB ***
- *** ***
- *************************************************************************
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: nt!_KPRCB ***
- *** ***
- *************************************************************************
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: nt!_KPRCB ***
- *** ***
- *************************************************************************
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: nt!_KTHREAD ***
- *** ***
- *************************************************************************
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: nt!_KPRCB ***
- *** ***
- *************************************************************************
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: nt!_KPRCB ***
- *** ***
- *************************************************************************
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- BUILD_VERSION_STRING: 16294.1.amd64fre.rs3_release.170916-2023
- SYSTEM_PRODUCT_NAME: To Be Filled By O.E.M.
- SYSTEM_SKU: To Be Filled By O.E.M.
- SYSTEM_VERSION: To Be Filled By O.E.M.
- BIOS_VENDOR: American Megatrends Inc.
- BIOS_VERSION: P3.10
- BIOS_DATE: 08/25/2017
- BASEBOARD_MANUFACTURER: ASRock
- BASEBOARD_PRODUCT: X370 Taichi
- BASEBOARD_VERSION:
- ADDITIONAL_DEBUG_TEXT:
- You can run '.symfix; .reload' to try to fix the symbol path and load symbols.
- WRONG_SYMBOLS_TIMESTAMP: 59be13ec
- WRONG_SYMBOLS_SIZE: 8d2000
- FAULTING_MODULE: fffff8002c087000 nt
- DEBUG_FLR_IMAGE_TIMESTAMP: 59be13ec
- DUMP_TYPE: 2
- BUGCHECK_P1: 3
- BUGCHECK_P2: ffff850ca8da5060
- BUGCHECK_P3: ffff8308022378f0
- BUGCHECK_P4: ffff850ca82b2640
- DRVPOWERSTATE_SUBCODE: 3
- IRP_ADDRESS: ffff850ca82b2640
- DEVICE_OBJECT: ffff850ca8da5060
- CPU_COUNT: 10
- CPU_MHZ: d48
- CPU_VENDOR: AuthenticAMD
- CPU_FAMILY: 17
- CPU_MODEL: 1
- CPU_STEPPING: 1
- CUSTOMER_CRASH_COUNT: 1
- CURRENT_IRQL: 0
- ANALYSIS_SESSION_HOST: MAINCLIENT
- ANALYSIS_SESSION_TIME: 09-23-2017 14:33:40.0754
- ANALYSIS_VERSION: 10.0.15063.468 amd64fre
- LAST_CONTROL_TRANSFER: from fffff8002c2b8b27 to fffff8002c1ea7c0
- STACK_TEXT:
- ffff8308`022378b8 fffff800`2c2b8b27 : 00000000`0000009f 00000000`00000003 ffff850c`a8da5060 ffff8308`022378f0 : nt+0x1637c0
- ffff8308`022378c0 00000000`0000009f : 00000000`00000003 ffff850c`a8da5060 ffff8308`022378f0 ffff850c`a82b2640 : nt+0x231b27
- ffff8308`022378c8 00000000`00000003 : ffff850c`a8da5060 ffff8308`022378f0 ffff850c`a82b2640 ffff850c`aacdf580 : 0x9f
- ffff8308`022378d0 ffff850c`a8da5060 : ffff8308`022378f0 ffff850c`a82b2640 ffff850c`aacdf580 00000000`00018000 : 0x3
- ffff8308`022378d8 ffff8308`022378f0 : ffff850c`a82b2640 ffff850c`aacdf580 00000000`00018000 fffff800`2c3e4c00 : 0xffff850c`a8da5060
- ffff8308`022378e0 ffff850c`a82b2640 : ffff850c`aacdf580 00000000`00018000 fffff800`2c3e4c00 fffff800`2c3e38d0 : 0xffff8308`022378f0
- ffff8308`022378e8 ffff850c`aacdf580 : 00000000`00018000 fffff800`2c3e4c00 fffff800`2c3e38d0 ffff850c`a4af3b30 : 0xffff850c`a82b2640
- ffff8308`022378f0 00000000`00018000 : fffff800`2c3e4c00 fffff800`2c3e38d0 ffff850c`a4af3b30 00000000`00000003 : 0xffff850c`aacdf580
- ffff8308`022378f8 fffff800`2c3e4c00 : fffff800`2c3e38d0 ffff850c`a4af3b30 00000000`00000003 fffff800`2c2b8a32 : 0x18000
- ffff8308`02237900 fffff800`2c3e38d0 : ffff850c`a4af3b30 00000000`00000003 fffff800`2c2b8a32 ffff850c`e0ac6f00 : nt+0x35dc00
- ffff8308`02237908 ffff850c`a4af3b30 : 00000000`00000003 fffff800`2c2b8a32 ffff850c`e0ac6f00 ffff9c80`46079180 : nt+0x35c8d0
- ffff8308`02237910 00000000`00000003 : fffff800`2c2b8a32 ffff850c`e0ac6f00 ffff9c80`46079180 ffff850c`e0ac6f78 : 0xffff850c`a4af3b30
- ffff8308`02237918 fffff800`2c2b8a32 : ffff850c`e0ac6f00 ffff9c80`46079180 ffff850c`e0ac6f78 00000000`00000080 : 0x3
- ffff8308`02237920 ffff850c`e0ac6f00 : ffff9c80`46079180 ffff850c`e0ac6f78 00000000`00000080 00000000`00000000 : nt+0x231a32
- ffff8308`02237928 ffff9c80`46079180 : ffff850c`e0ac6f78 00000000`00000080 00000000`00000000 fffff800`2c3e4c20 : 0xffff850c`e0ac6f00
- ffff8308`02237930 ffff850c`e0ac6f78 : 00000000`00000080 00000000`00000000 fffff800`2c3e4c20 00000000`00000002 : 0xffff9c80`46079180
- ffff8308`02237938 00000000`00000080 : 00000000`00000000 fffff800`2c3e4c20 00000000`00000002 ffff9c80`46079180 : 0xffff850c`e0ac6f78
- ffff8308`02237940 00000000`00000000 : fffff800`2c3e4c20 00000000`00000002 ffff9c80`46079180 00000000`00000002 : 0x80
- STACK_COMMAND: kb
- THREAD_SHA1_HASH_MOD_FUNC: f08ac56120cad14894587db086f77ce277bfae84
- THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 96f1ac404d993a8805f8770c7c31121bc2791039
- THREAD_SHA1_HASH_MOD: f08ac56120cad14894587db086f77ce277bfae84
- FOLLOWUP_IP:
- nt+1637c0
- fffff800`2c1ea7c0 48894c2408 mov qword ptr [rsp+8],rcx
- FAULT_INSTR_CODE: 244c8948
- SYMBOL_STACK_INDEX: 0
- FOLLOWUP_NAME: MachineOwner
- BUGCHECK_STR: 59BE13EC
- EXCEPTION_CODE: (NTSTATUS) 0x59be13ec - <Unable to get error code text>
- EXCEPTION_CODE_STR: 59BE13EC
- EXCEPTION_STR: WRONG_SYMBOLS
- PROCESS_NAME: ntoskrnl.wrong.symbols.exe
- IMAGE_NAME: ntoskrnl.wrong.symbols.exe
- MODULE_NAME: nt_wrong_symbols
- SYMBOL_NAME: nt_wrong_symbols!59BE13EC8D2000
- BUCKET_ID: WRONG_SYMBOLS_X64_16294.1.amd64fre.rs3_release.170916-2023_TIMESTAMP_170917-061924
- DEFAULT_BUCKET_ID: WRONG_SYMBOLS_X64_16294.1.amd64fre.rs3_release.170916-2023_TIMESTAMP_170917-061924
- PRIMARY_PROBLEM_CLASS: WRONG_SYMBOLS
- FAILURE_BUCKET_ID: WRONG_SYMBOLS_X64_16294.1.amd64fre.rs3_release.170916-2023_TIMESTAMP_170917-061924_59BE13EC_nt_wrong_symbols!59BE13EC8D2000
- TARGET_TIME: 2017-09-22T19:37:01.000Z
- OSBUILD: 16294
- OSSERVICEPACK: 0
- SERVICEPACK_NUMBER: 0
- OS_REVISION: 0
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- OSPLATFORM_TYPE: x64
- OSNAME: Windows 10
- OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
- OS_LOCALE:
- USER_LCID: 0
- OSBUILD_TIMESTAMP: 2017-09-17 07:19:24
- BUILDDATESTAMP_STR: 170916-2023
- BUILDLAB_STR: rs3_release
- BUILDOSVER_STR: 10.0.16294.1.amd64fre.rs3_release.170916-2023
- ANALYSIS_SESSION_ELAPSED_TIME: 20e2
- ANALYSIS_SOURCE: KM
- FAILURE_ID_HASH_STRING: km:wrong_symbols_x64_16294.1.amd64fre.rs3_release.170916-2023_timestamp_170917-061924_59be13ec_nt_wrong_symbols!59be13ec8d2000
- FAILURE_ID_HASH: {5adaf15a-7e97-8e23-5afd-5b7678c493df}
- Followup: MachineOwner
- ---------
- 2: kd> !thread
- GetPointerFromAddress: unable to read from fffff8002c348200
- *************************************************************************
- *** ***
- *** ***
- *** Either you specified an unqualified symbol, or your debugger ***
- *** doesn't have full symbol information. Unqualified symbol ***
- *** resolution is turned off by default. Please either specify a ***
- *** fully qualified symbol module!symbolname, or enable resolution ***
- *** of unqualified symbols by typing ".symopt- 100". Note that ***
- *** enabling unqualified symbol resolution with network symbol ***
- *** server shares in the symbol path may cause the debugger to ***
- *** appear to hang for long periods of time when an incorrect ***
- *** symbol name is typed or the network symbol server is down. ***
- *** ***
- *** For some commands to work properly, your symbol path ***
- *** must point to .pdb files that have full type information. ***
- *** ***
- *** Certain .pdb files (such as the public OS symbols) do not ***
- *** contain the required information. Contact the group that ***
- *** provided you with these symbols if you need this command to ***
- *** work. ***
- *** ***
- *** Type referenced: nt!_ETHREAD ***
- *** ***
- *************************************************************************
- ffff9c8046085ec0: Unable to get thread contents
- 2: kd> lm kv
- start end module name
- fffff800`2ae00000 fffff800`2ae2b000 klupd_klif_mark (deferred)
- Image path: \SystemRoot\System32\Drivers\klupd_klif_mark.sys
- Image name: klupd_klif_mark.sys
- Timestamp: Thu Mar 30 15:46:51 2017 (58DD1A5B)
- CheckSum: 00039585
- ImageSize: 0002B000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff800`2ae40000 fffff800`2ae6d000 klids (deferred)
- Image path: \??\C:\ProgramData\Kaspersky Lab\AVP18.0.0\Bases\klids.sys
- Image name: klids.sys
- Timestamp: Fri Jul 28 10:32:39 2017 (597B04B7)
- CheckSum: 00032801
- ImageSize: 0002D000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff800`2ae70000 fffff800`2ae79000 CorsairVHidDriver (deferred)
- Image path: \SystemRoot\System32\drivers\CorsairVHidDriver.sys
- Image name: CorsairVHidDriver.sys
- Timestamp: Thu May 25 14:04:02 2017 (5926D642)
- CheckSum: 00008B73
- ImageSize: 00009000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff800`2aeb0000 fffff800`2aebd000 rdpvideominiport (deferred)
- Mapped memory image file: c:\symbols\rdpvideominiport.sys\834709A4d000\rdpvideominiport.sys
- Image path: \SystemRoot\System32\drivers\rdpvideominiport.sys
- Image name: rdpvideominiport.sys
- Timestamp: ***** Invalid (834709A4)
- CheckSum: 0000D296
- ImageSize: 0000D000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.0 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: rdpvideominiport.sys
- OriginalFilename: rdpvideominiport.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Microsoft RDP Video Miniport driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff800`2aee0000 fffff800`2af1e000 klupd_klif_klark (deferred)
- Image path: \SystemRoot\System32\Drivers\klupd_klif_klark.sys
- Image name: klupd_klif_klark.sys
- Timestamp: Thu Mar 30 15:51:16 2017 (58DD1B64)
- CheckSum: 0003E432
- ImageSize: 0003E000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff800`2af80000 fffff800`2af8b000 umpass (deferred)
- Mapped memory image file: c:\symbols\umpass.sys\FA98656Fb000\umpass.sys
- Image path: \SystemRoot\System32\drivers\umpass.sys
- Image name: umpass.sys
- Timestamp: ***** Invalid (FA98656F)
- CheckSum: 00003C8A
- ImageSize: 0000B000
- File version: 10.0.16262.1001
- Product version: 10.0.16262.1001
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: umpass.sys
- OriginalFilename: fumpass.sys
- ProductVersion: 10.0.16262.1001
- FileVersion: 10.0.16262.1001 (WinBuild.160101.0800)
- FileDescription: Generic pass-through driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff800`2afc0000 fffff800`2b598000 iqvw64e (deferred)
- Image path: \??\C:\Windows\system32\Drivers\iqvw64e.sys
- Image name: iqvw64e.sys
- Timestamp: Mon Apr 3 16:14:26 2017 (58E266D2)
- CheckSum: 00013DE1
- ImageSize: 005D8000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff800`2b5a0000 fffff800`2b5b0000 vwifimp (deferred)
- Mapped memory image file: c:\symbols\vwifimp.sys\5BA3CDB810000\vwifimp.sys
- Image path: \SystemRoot\System32\drivers\vwifimp.sys
- Image name: vwifimp.sys
- Timestamp: Thu Sep 20 17:41:28 2018 (5BA3CDB8)
- CheckSum: 000110B8
- ImageSize: 00010000
- File version: 10.0.16262.1001
- Product version: 10.0.16262.1001
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: vwifimp.sys
- OriginalFilename: vwifimp.sys
- ProductVersion: 10.0.16262.1001
- FileVersion: 10.0.16262.1001 (WinBuild.160101.0800)
- FileDescription: Virtual WiFi Miniport Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff800`2b5b0000 fffff800`2b5d4000 tunnel (deferred)
- Mapped memory image file: c:\symbols\tunnel.sys\9206C4C024000\tunnel.sys
- Image path: \SystemRoot\System32\drivers\tunnel.sys
- Image name: tunnel.sys
- Timestamp: ***** Invalid (9206C4C0)
- CheckSum: 0001D5B9
- ImageSize: 00024000
- File version: 10.0.16288.1
- Product version: 10.0.16288.1
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: tunnel.sys
- OriginalFilename: tunnel.sys
- ProductVersion: 10.0.16288.1
- FileVersion: 10.0.16288.1 (WinBuild.160101.0800)
- FileDescription: Microsoft Tunnel Interface Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff800`2b5e0000 fffff800`2b5f7000 klupd_klif_kimul (deferred)
- Image path: \SystemRoot\System32\Drivers\klupd_klif_kimul.sys
- Image name: klupd_klif_kimul.sys
- Timestamp: Mon Feb 6 11:09:33 2017 (5898596D)
- CheckSum: 0001F6D8
- ImageSize: 00017000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff800`2c008000 fffff800`2c087000 hal (deferred)
- Mapped memory image file: c:\symbols\hal.dll\869C055B7f000\hal.dll
- Image path: hal.dll
- Image name: hal.dll
- Timestamp: ***** Invalid (869C055B)
- CheckSum: 000831A8
- ImageSize: 0007F000
- File version: 10.0.16288.1
- Product version: 10.0.16288.1
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: hal.dll
- OriginalFilename: hal.dll
- ProductVersion: 10.0.16288.1
- FileVersion: 10.0.16288.1 (WinBuild.160101.0800)
- FileDescription: Hardware Abstraction Layer DLL
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff800`2c087000 fffff800`2c959000 nt T (no symbols)
- Loaded symbol image file: ntoskrnl.exe
- Image path: \SystemRoot\system32\ntoskrnl.exe
- Image name: ntoskrnl.exe
- Timestamp: Sun Sep 17 07:19:24 2017 (59BE13EC)
- CheckSum: 0083CA59
- ImageSize: 008D2000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff800`2ca00000 fffff800`2ca0b000 kd (deferred)
- Mapped memory image file: c:\symbols\kd.dll\FA8983CBb000\kd.dll
- Image path: \SystemRoot\system32\kd.dll
- Image name: kd.dll
- Timestamp: ***** Invalid (FA8983CB)
- CheckSum: 0000864E
- ImageSize: 0000B000
- File version: 10.0.16262.1001
- Product version: 10.0.16262.1001
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.A Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: kd.dll
- OriginalFilename: kd.dll
- ProductVersion: 10.0.16262.1001
- FileVersion: 10.0.16262.1001 (WinBuild.160101.0800)
- FileDescription: Local Kernel Debugger
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`13e00000 fffff805`13e68000 FLTMGR (deferred)
- Mapped memory image file: c:\symbols\FLTMGR.SYS\7AD26C5168000\FLTMGR.SYS
- Image path: \SystemRoot\System32\drivers\FLTMGR.SYS
- Image name: FLTMGR.SYS
- Timestamp: Thu Apr 19 16:50:41 2035 (7AD26C51)
- CheckSum: 0006F9D8
- ImageSize: 00068000
- File version: 10.0.16288.1
- Product version: 10.0.16288.1
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: fltMgr.sys
- OriginalFilename: fltMgr.sys
- ProductVersion: 10.0.16288.1
- FileVersion: 10.0.16288.1 (WinBuild.160101.0800)
- FileDescription: Microsoft Filesystem Filter Manager
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`13e70000 fffff805`13f71000 clipsp (deferred)
- Image path: \SystemRoot\System32\drivers\clipsp.sys
- Image name: clipsp.sys
- Timestamp: Sun Sep 17 07:29:18 2017 (59BE163E)
- CheckSum: 000F9DF5
- ImageSize: 00101000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`13f80000 fffff805`13f8e000 cmimcext (deferred)
- Mapped memory image file: c:\symbols\cmimcext.sys\D4EADF74e000\cmimcext.sys
- Image path: \SystemRoot\System32\drivers\cmimcext.sys
- Image name: cmimcext.sys
- Timestamp: ***** Invalid (D4EADF74)
- CheckSum: 00012094
- ImageSize: 0000E000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: cmimcext.sys
- OriginalFilename: cmimcext.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Kernel Configuration Manager Initial Configuration Extension Host Export Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`13f90000 fffff805`13f9c000 ntosext (deferred)
- Mapped memory image file: c:\symbols\ntosext.sys\1B6DA4C4c000\ntosext.sys
- Image path: \SystemRoot\System32\drivers\ntosext.sys
- Image name: ntosext.sys
- Timestamp: Wed Aug 1 02:07:16 1984 (1B6DA4C4)
- CheckSum: 000130C8
- ImageSize: 0000C000
- File version: 10.0.16262.1001
- Product version: 10.0.16262.1001
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: ntosext.sys
- OriginalFilename: ntosext.sys
- ProductVersion: 10.0.16262.1001
- FileVersion: 10.0.16262.1001 (WinBuild.160101.0800)
- FileDescription: NTOS extension host driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`13fa0000 fffff805`14052000 CI (deferred)
- Image path: \SystemRoot\system32\CI.dll
- Image name: CI.dll
- Timestamp: Sun May 1 17:48:30 1977 (0DCA2BDE)
- CheckSum: 000B4C28
- ImageSize: 000B2000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`14060000 fffff805`1410a000 cng (deferred)
- Mapped memory image file: c:\symbols\cng.sys\76DB7D7Daa000\cng.sys
- Image path: \SystemRoot\System32\drivers\cng.sys
- Image name: cng.sys
- Timestamp: Thu Mar 10 19:33:17 2033 (76DB7D7D)
- CheckSum: 000AB7FB
- ImageSize: 000AA000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: cng.sys
- OriginalFilename: cng.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Kernel Cryptography, Next Generation
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`14110000 fffff805`141f3000 Wdf01000 (deferred)
- Mapped memory image file: c:\symbols\Wdf01000.sys\30874750e3000\Wdf01000.sys
- Image path: \SystemRoot\system32\drivers\Wdf01000.sys
- Image name: Wdf01000.sys
- Timestamp: Fri Oct 20 07:53:04 1995 (30874750)
- CheckSum: 000E7061
- ImageSize: 000E3000
- File version: 1.23.16288.1
- Product version: 1.23.16288.1
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: wdf01000.sys
- OriginalFilename: wdf01000.sys
- ProductVersion: 1.23.16288.1
- FileVersion: 1.23.16288.1 (WinBuild.160101.0800)
- FileDescription: Kernel Mode Driver Framework Runtime
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`14200000 fffff805`14213000 WDFLDR (deferred)
- Mapped memory image file: c:\symbols\WDFLDR.SYS\B573265013000\WDFLDR.SYS
- Image path: \SystemRoot\system32\drivers\WDFLDR.SYS
- Image name: WDFLDR.SYS
- Timestamp: ***** Invalid (B5732650)
- CheckSum: 00018693
- ImageSize: 00013000
- File version: 1.23.16278.1000
- Product version: 1.23.16278.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: wdfldr.sys
- OriginalFilename: wdfldr.sys
- ProductVersion: 1.23.16278.1000
- FileVersion: 1.23.16278.1000 (WinBuild.160101.0800)
- FileDescription: Kernel Mode Driver Framework Loader
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`14220000 fffff805`1422e000 WppRecorder (deferred)
- Mapped memory image file: c:\symbols\WppRecorder.sys\A67A2B71e000\WppRecorder.sys
- Image path: \SystemRoot\system32\drivers\WppRecorder.sys
- Image name: WppRecorder.sys
- Timestamp: ***** Invalid (A67A2B71)
- CheckSum: 0000F3E4
- ImageSize: 0000E000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: WppRecorder.sys
- OriginalFilename: WppRecorder.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: WPP Trace Recorder
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`14230000 fffff805`1423f000 SleepStudyHelper (deferred)
- Mapped memory image file: c:\symbols\SleepStudyHelper.sys\A0E1B647f000\SleepStudyHelper.sys
- Image path: \SystemRoot\system32\drivers\SleepStudyHelper.sys
- Image name: SleepStudyHelper.sys
- Timestamp: ***** Invalid (A0E1B647)
- CheckSum: 000120B6
- ImageSize: 0000F000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: SleepStudyHelper.sys
- OriginalFilename: SleepStudyHelper.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Sleep Study Helper
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`14240000 fffff805`14260000 mcupdate_AuthenticAMD (deferred)
- Image path: \SystemRoot\system32\mcupdate_AuthenticAMD.dll
- Image name: mcupdate_AuthenticAMD.dll
- Timestamp: Fri Jun 25 20:46:20 2010 (4C25078C)
- CheckSum: 00022633
- ImageSize: 00020000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`14260000 fffff805`142c1000 msrpc (deferred)
- Mapped memory image file: c:\symbols\msrpc.sys\687CE03761000\msrpc.sys
- Image path: \SystemRoot\System32\drivers\msrpc.sys
- Image name: msrpc.sys
- Timestamp: Sun Jul 20 13:25:27 2025 (687CE037)
- CheckSum: 0005CD09
- ImageSize: 00061000
- File version: 10.0.16281.1000
- Product version: 10.0.16281.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: krpcdd.sys
- OriginalFilename: krpcdd.sys
- ProductVersion: 10.0.16281.1000
- FileVersion: 10.0.16281.1000 (WinBuild.160101.0800)
- FileDescription: Kernel Remote Procedure Call Provider
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`142d0000 fffff805`142f9000 ksecdd (deferred)
- Image path: \SystemRoot\System32\drivers\ksecdd.sys
- Image name: ksecdd.sys
- Timestamp: ***** Invalid (9A56383F)
- CheckSum: 0002B5CC
- ImageSize: 00029000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`14300000 fffff805`14311000 werkernel (deferred)
- Mapped memory image file: c:\symbols\werkernel.sys\623CE79811000\werkernel.sys
- Image path: \SystemRoot\System32\drivers\werkernel.sys
- Image name: werkernel.sys
- Timestamp: Thu Mar 24 21:50:16 2022 (623CE798)
- CheckSum: 00010EA2
- ImageSize: 00011000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: werkernel
- OriginalFilename: werkernel.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Windows Error Reporting Kernel Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`14320000 fffff805`14382000 CLFS (deferred)
- Image path: \SystemRoot\System32\drivers\CLFS.SYS
- Image name: CLFS.SYS
- Timestamp: Sun Dec 8 05:07:42 2030 (729DB01E)
- CheckSum: 00062255
- ImageSize: 00062000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`14390000 fffff805`143b4000 tm (deferred)
- Mapped memory image file: c:\symbols\tm.sys\50FBCEC024000\tm.sys
- Image path: \SystemRoot\System32\drivers\tm.sys
- Image name: tm.sys
- Timestamp: Sun Jan 20 11:02:24 2013 (50FBCEC0)
- CheckSum: 0002BC46
- ImageSize: 00024000
- File version: 10.0.16281.1000
- Product version: 10.0.16281.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: tm.sys
- OriginalFilename: tm.sys
- ProductVersion: 10.0.16281.1000
- FileVersion: 10.0.16281.1000 (WinBuild.160101.0800)
- FileDescription: Kernel Transaction Manager Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`143c0000 fffff805`143d7000 PSHED (deferred)
- Mapped memory image file: c:\symbols\PSHED.dll\FE1A7C4017000\PSHED.dll
- Image path: \SystemRoot\system32\PSHED.dll
- Image name: PSHED.dll
- Timestamp: ***** Invalid (FE1A7C40)
- CheckSum: 000115CB
- ImageSize: 00017000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: pshed.dll
- OriginalFilename: pshed.dll
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Platform Specific Hardware Error Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`143e0000 fffff805`143eb000 BOOTVID (deferred)
- Mapped memory image file: c:\symbols\BOOTVID.dll\2FB571EAb000\BOOTVID.dll
- Image path: \SystemRoot\system32\BOOTVID.dll
- Image name: BOOTVID.dll
- Timestamp: Sun May 14 03:58:50 1995 (2FB571EA)
- CheckSum: 0000836F
- ImageSize: 0000B000
- File version: 10.0.16262.1001
- Product version: 10.0.16262.1001
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.4 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: bootvid.dll
- OriginalFilename: bootvid.dll
- ProductVersion: 10.0.16262.1001
- FileVersion: 10.0.16262.1001 (WinBuild.160101.0800)
- FileDescription: VGA Boot Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`14400000 fffff805`144b9000 ACPI (deferred)
- Image path: \SystemRoot\System32\drivers\ACPI.sys
- Image name: ACPI.sys
- Timestamp: ***** Invalid (F288DB9E)
- CheckSum: 000BE79C
- ImageSize: 000B9000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`144c0000 fffff805`144cc000 WMILIB (deferred)
- Mapped memory image file: c:\symbols\WMILIB.SYS\FD702A37c000\WMILIB.SYS
- Image path: \SystemRoot\System32\drivers\WMILIB.SYS
- Image name: WMILIB.SYS
- Timestamp: ***** Invalid (FD702A37)
- CheckSum: 000076EC
- ImageSize: 0000C000
- File version: 10.0.16262.1001
- Product version: 10.0.16262.1001
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: WmiLib.sys
- OriginalFilename: WmiLib.sys
- ProductVersion: 10.0.16262.1001
- FileVersion: 10.0.16262.1001 (WinBuild.160101.0800)
- FileDescription: WMILIB WMI support library Dll
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`144e0000 fffff805`14505000 intelpep (deferred)
- Mapped memory image file: c:\symbols\intelpep.sys\EB730B5B25000\intelpep.sys
- Image path: \SystemRoot\System32\drivers\intelpep.sys
- Image name: intelpep.sys
- Timestamp: ***** Invalid (EB730B5B)
- CheckSum: 0002ACBD
- ImageSize: 00025000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.A Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: intelpep.sys
- OriginalFilename: intelpep.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Intel Power Engine Plugin
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`14510000 fffff805`14526000 WindowsTrustedRT (deferred)
- Mapped memory image file: c:\symbols\WindowsTrustedRT.sys\6174852016000\WindowsTrustedRT.sys
- Image path: \SystemRoot\system32\drivers\WindowsTrustedRT.sys
- Image name: WindowsTrustedRT.sys
- Timestamp: Sat Oct 23 22:56:48 2021 (61748520)
- CheckSum: 0001DF2A
- ImageSize: 00016000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: WindowsTrustedRT.sys
- OriginalFilename: WindowsTrustedRT.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Windows Trusted Runtime Interface Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`14530000 fffff805`1453b000 WindowsTrustedRTProxy (deferred)
- Mapped memory image file: c:\symbols\WindowsTrustedRTProxy.sys\C6109CE2b000\WindowsTrustedRTProxy.sys
- Image path: \SystemRoot\System32\drivers\WindowsTrustedRTProxy.sys
- Image name: WindowsTrustedRTProxy.sys
- Timestamp: ***** Invalid (C6109CE2)
- CheckSum: 0000F309
- ImageSize: 0000B000
- File version: 10.0.16262.1001
- Product version: 10.0.16262.1001
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: WindowsTrustedRTProxy.sys
- OriginalFilename: WindowsTrustedRTProxy.sys
- ProductVersion: 10.0.16262.1001
- FileVersion: 10.0.16262.1001 (WinBuild.160101.0800)
- FileDescription: Windows Trusted Runtime Service Proxy Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`14540000 fffff805`14554000 pcw (deferred)
- Mapped memory image file: c:\symbols\pcw.sys\B45241A014000\pcw.sys
- Image path: \SystemRoot\System32\drivers\pcw.sys
- Image name: pcw.sys
- Timestamp: ***** Invalid (B45241A0)
- CheckSum: 00017BEF
- ImageSize: 00014000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.8 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: pcw.sys
- OriginalFilename: pcw.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Performance Counters for Windows Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`14560000 fffff805`14599000 klupd_klif_arkmon (deferred)
- Image path: \SystemRoot\System32\Drivers\klupd_klif_arkmon.sys
- Image name: klupd_klif_arkmon.sys
- Timestamp: Thu Mar 30 15:41:32 2017 (58DD191C)
- CheckSum: 00038D0D
- ImageSize: 00039000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`145a0000 fffff805`145ab000 msisadrv (deferred)
- Mapped memory image file: c:\symbols\msisadrv.sys\2B3273BCb000\msisadrv.sys
- Image path: \SystemRoot\System32\drivers\msisadrv.sys
- Image name: msisadrv.sys
- Timestamp: Sat Dec 19 00:58:36 1992 (2B3273BC)
- CheckSum: 00012467
- ImageSize: 0000B000
- File version: 10.0.16262.1001
- Product version: 10.0.16262.1001
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: msisadrv.sys
- OriginalFilename: msisadrv.sys
- ProductVersion: 10.0.16262.1001
- FileVersion: 10.0.16262.1001 (WinBuild.160101.0800)
- FileDescription: ISA Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`145b0000 fffff805`1460d000 pci (deferred)
- Mapped memory image file: c:\symbols\pci.sys\F05D50D85d000\pci.sys
- Image path: \SystemRoot\System32\drivers\pci.sys
- Image name: pci.sys
- Timestamp: ***** Invalid (F05D50D8)
- CheckSum: 0005AC5B
- ImageSize: 0005D000
- File version: 10.0.16288.1
- Product version: 10.0.16288.1
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: pci.sys
- OriginalFilename: pci.sys
- ProductVersion: 10.0.16288.1
- FileVersion: 10.0.16288.1 (WinBuild.160101.0800)
- FileDescription: NT Plug and Play PCI Enumerator
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`14610000 fffff805`14622000 vdrvroot (deferred)
- Mapped memory image file: c:\symbols\vdrvroot.sys\53ABAAC212000\vdrvroot.sys
- Image path: \SystemRoot\System32\drivers\vdrvroot.sys
- Image name: vdrvroot.sys
- Timestamp: Thu Jun 26 06:08:18 2014 (53ABAAC2)
- CheckSum: 0000F797
- ImageSize: 00012000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: vdrvroot.sys
- OriginalFilename: vdrvroot.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Virtual Drive Root Enumerator
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`14630000 fffff805`14655000 pdc (deferred)
- Mapped memory image file: c:\symbols\pdc.sys\4003A61925000\pdc.sys
- Image path: \SystemRoot\system32\drivers\pdc.sys
- Image name: pdc.sys
- Timestamp: Tue Jan 13 08:02:33 2004 (4003A619)
- CheckSum: 00023068
- ImageSize: 00025000
- File version: 10.0.16281.1000
- Product version: 10.0.16281.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: pdc.sys
- OriginalFilename: pdc.sys
- ProductVersion: 10.0.16281.1000
- FileVersion: 10.0.16281.1000 (WinBuild.160101.0800)
- FileDescription: Power Dependency Coordinator Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`14660000 fffff805`14679000 CEA (deferred)
- Mapped memory image file: c:\symbols\CEA.sys\CE9B9DFB19000\CEA.sys
- Image path: \SystemRoot\system32\drivers\CEA.sys
- Image name: CEA.sys
- Timestamp: ***** Invalid (CE9B9DFB)
- CheckSum: 00014C22
- ImageSize: 00019000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: EventAggregation.sys
- OriginalFilename: EventAggregation.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Event Aggregation Kernel Mode Library
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`14680000 fffff805`146ad000 partmgr (deferred)
- Mapped memory image file: c:\symbols\partmgr.sys\0902AE712d000\partmgr.sys
- Image path: \SystemRoot\System32\drivers\partmgr.sys
- Image name: partmgr.sys
- Timestamp: Wed Oct 16 16:51:13 1974 (0902AE71)
- CheckSum: 0002AF94
- ImageSize: 0002D000
- File version: 10.0.16288.1
- Product version: 10.0.16288.1
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: partmgr.sys
- OriginalFilename: partmgr.sys
- ProductVersion: 10.0.16288.1
- FileVersion: 10.0.16288.1 (WinBuild.160101.0800)
- FileDescription: Partition driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`146b0000 fffff805`146e9000 cm_km (deferred)
- Image path: \SystemRoot\system32\DRIVERS\cm_km.sys
- Image name: cm_km.sys
- Timestamp: Thu Dec 15 07:43:48 2016 (585249B4)
- CheckSum: 0003DF46
- ImageSize: 00039000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`146f0000 fffff805`14780000 spaceport (deferred)
- Image path: \SystemRoot\System32\drivers\spaceport.sys
- Image name: spaceport.sys
- Timestamp: Thu Jul 23 20:29:16 2020 (5F19E50C)
- CheckSum: 0008D5EC
- ImageSize: 00090000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`14780000 fffff805`14799000 volmgr (deferred)
- Mapped memory image file: c:\symbols\volmgr.sys\B0634E7119000\volmgr.sys
- Image path: \SystemRoot\System32\drivers\volmgr.sys
- Image name: volmgr.sys
- Timestamp: ***** Invalid (B0634E71)
- CheckSum: 000205D7
- ImageSize: 00019000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: volmgr.sys
- OriginalFilename: volmgr.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Volume Manager Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`147a0000 fffff805`147fe000 volmgrx (deferred)
- Mapped memory image file: c:\symbols\volmgrx.sys\BD8710A65e000\volmgrx.sys
- Image path: \SystemRoot\System32\drivers\volmgrx.sys
- Image name: volmgrx.sys
- Timestamp: ***** Invalid (BD8710A6)
- CheckSum: 0005CD83
- ImageSize: 0005E000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: volmgrx.sys
- OriginalFilename: volmgrx.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Volume Manager Extension Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`14800000 fffff805`1481e000 mountmgr (deferred)
- Image path: \SystemRoot\System32\drivers\mountmgr.sys
- Image name: mountmgr.sys
- Timestamp: ***** Invalid (ADA090FE)
- CheckSum: 00021E13
- ImageSize: 0001E000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`14820000 fffff805`1482f000 klbackupdisk (deferred)
- Image path: \SystemRoot\system32\DRIVERS\klbackupdisk.sys
- Image name: klbackupdisk.sys
- Timestamp: Wed Dec 7 09:11:58 2016 (5847D25E)
- CheckSum: 0001925B
- ImageSize: 0000F000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`14830000 fffff805`14853000 secnvme (deferred)
- Image path: \SystemRoot\System32\drivers\secnvme.sys
- Image name: secnvme.sys
- Timestamp: Fri Mar 17 06:03:34 2017 (58CB7C36)
- CheckSum: 00030180
- ImageSize: 00023000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`14860000 fffff805`148ee000 storport (deferred)
- Image path: \SystemRoot\System32\drivers\storport.sys
- Image name: storport.sys
- Timestamp: ***** Invalid (E9CDBFC5)
- CheckSum: 0008D5D6
- ImageSize: 0008E000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`148f0000 fffff805`1490c000 EhStorClass (deferred)
- Mapped memory image file: c:\symbols\EhStorClass.sys\6D0AE02C1c000\EhStorClass.sys
- Image path: \SystemRoot\System32\drivers\EhStorClass.sys
- Image name: EhStorClass.sys
- Timestamp: Tue Dec 21 22:48:12 2027 (6D0AE02C)
- CheckSum: 00018DBA
- ImageSize: 0001C000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: EhStorClass.sys
- OriginalFilename: EhStorClass.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Enhanced Storage Class driver for IEEE 1667 devices
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`14910000 fffff805`1492a000 fileinfo (deferred)
- Mapped memory image file: c:\symbols\fileinfo.sys\19C047731a000\fileinfo.sys
- Image path: \SystemRoot\System32\drivers\fileinfo.sys
- Image name: fileinfo.sys
- Timestamp: Sat Sep 10 09:46:43 1983 (19C04773)
- CheckSum: 0001BEBA
- ImageSize: 0001A000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: FileInfo.sys
- OriginalFilename: FileInfo.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: FileInfo Filter Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`14930000 fffff805`1496b000 Wof (deferred)
- Mapped memory image file: c:\symbols\Wof.sys\F9D43CDF3b000\Wof.sys
- Image path: \SystemRoot\System32\Drivers\Wof.sys
- Image name: Wof.sys
- Timestamp: ***** Invalid (F9D43CDF)
- CheckSum: 00034094
- ImageSize: 0003B000
- File version: 10.0.16288.1
- Product version: 10.0.16288.1
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: wof.sys
- OriginalFilename: wof.sys
- ProductVersion: 10.0.16288.1
- FileVersion: 10.0.16288.1 (WinBuild.160101.0800)
- FileDescription: Windows Overlay Filter
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`14970000 fffff805`14bc6000 NTFS (deferred)
- Image path: \SystemRoot\System32\Drivers\NTFS.sys
- Image name: NTFS.sys
- Timestamp: Tue Nov 17 21:12:44 2037 (7FADEE4C)
- CheckSum: 00259123
- ImageSize: 00256000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`14bd0000 fffff805`14be3000 rcbottom (deferred)
- Image path: \SystemRoot\System32\drivers\rcbottom.sys
- Image name: rcbottom.sys
- Timestamp: Tue Mar 28 14:34:05 2017 (58DA664D)
- CheckSum: 0001EFCB
- ImageSize: 00013000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`14bf0000 fffff805`14df5000 rcraid (deferred)
- Image path: \SystemRoot\System32\drivers\rcraid.sys
- Image name: rcraid.sys
- Timestamp: Tue Mar 28 14:37:02 2017 (58DA66FE)
- CheckSum: 00081861
- ImageSize: 00205000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`14e00000 fffff805`14e0d000 Fs_Rec (deferred)
- Mapped memory image file: c:\symbols\Fs_Rec.sys\1F94F6F0d000\Fs_Rec.sys
- Image path: \SystemRoot\System32\Drivers\Fs_Rec.sys
- Image name: Fs_Rec.sys
- Timestamp: Thu Oct 16 15:17:20 1986 (1F94F6F0)
- CheckSum: 0001071A
- ImageSize: 0000D000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: fs_rec.sys
- OriginalFilename: fs_rec.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: File System Recognizer Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`14e10000 fffff805`14f4f000 ndis (deferred)
- Mapped memory image file: c:\symbols\ndis.sys\AF6C505313f000\ndis.sys
- Image path: \SystemRoot\system32\drivers\ndis.sys
- Image name: ndis.sys
- Timestamp: ***** Invalid (AF6C5053)
- CheckSum: 00144092
- ImageSize: 0013F000
- File version: 10.0.16288.1
- Product version: 10.0.16288.1
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: NDIS.SYS
- OriginalFilename: NDIS.SYS
- ProductVersion: 10.0.16288.1
- FileVersion: 10.0.16288.1 (WinBuild.160101.0800)
- FileDescription: Network Driver Interface Specification (NDIS)
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`14f50000 fffff805`14fd8000 NETIO (deferred)
- Mapped memory image file: c:\symbols\NETIO.SYS\302C3E5D88000\NETIO.SYS
- Image path: \SystemRoot\system32\drivers\NETIO.SYS
- Image name: NETIO.SYS
- Timestamp: Sat Aug 12 06:38:37 1995 (302C3E5D)
- CheckSum: 0008F95B
- ImageSize: 00088000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: netio.sys
- OriginalFilename: netio.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Network I/O Subsystem
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`14fe0000 fffff805`15010000 ksecpkg (deferred)
- Mapped memory image file: c:\symbols\ksecpkg.sys\A2D0764A30000\ksecpkg.sys
- Image path: \SystemRoot\System32\Drivers\ksecpkg.sys
- Image name: ksecpkg.sys
- Timestamp: ***** Invalid (A2D0764A)
- CheckSum: 00033C2E
- ImageSize: 00030000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: ksecpkg.sys
- OriginalFilename: ksecpkg.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Kernel Security Support Provider Interface Packages
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`15010000 fffff805`150c8000 fvevol (deferred)
- Mapped memory image file: c:\symbols\fvevol.sys\2493BBE7b8000\fvevol.sys
- Image path: \SystemRoot\System32\DRIVERS\fvevol.sys
- Image name: fvevol.sys
- Timestamp: Mon Jun 12 14:34:31 1989 (2493BBE7)
- CheckSum: 000BEB94
- ImageSize: 000B8000
- File version: 10.0.16288.1
- Product version: 10.0.16288.1
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: FVEVOL.SYS
- OriginalFilename: FVEVOL.SYS
- ProductVersion: 10.0.16288.1
- FileVersion: 10.0.16288.1 (WinBuild.160101.0800)
- FileDescription: BitLocker Drive Encryption Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`150d0000 fffff805`15136000 volsnap (deferred)
- Image path: \SystemRoot\System32\drivers\volsnap.sys
- Image name: volsnap.sys
- Timestamp: ***** Invalid (C10D9CA3)
- CheckSum: 00068218
- ImageSize: 00066000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`15160000 fffff805`15183000 acpiex (deferred)
- Mapped memory image file: c:\symbols\acpiex.sys\8F81B54323000\acpiex.sys
- Image path: \SystemRoot\System32\Drivers\acpiex.sys
- Image name: acpiex.sys
- Timestamp: ***** Invalid (8F81B543)
- CheckSum: 00021434
- ImageSize: 00023000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: acpiex.sys
- OriginalFilename: acpiex.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: ACPIEx Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`15190000 fffff805`151db000 mssecflt (deferred)
- Image path: \SystemRoot\system32\drivers\mssecflt.sys
- Image name: mssecflt.sys
- Timestamp: Sat Mar 10 11:02:06 2035 (7A9D6CAE)
- CheckSum: 0004A917
- ImageSize: 0004B000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`15200000 fffff805`1524c000 rdyboost (deferred)
- Mapped memory image file: c:\symbols\rdyboost.sys\32E813EE4c000\rdyboost.sys
- Image path: \SystemRoot\System32\drivers\rdyboost.sys
- Image name: rdyboost.sys
- Timestamp: Fri Jan 24 01:44:14 1997 (32E813EE)
- CheckSum: 0004C494
- ImageSize: 0004C000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: rdyboost.sys
- OriginalFilename: rdyboost.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: ReadyBoost Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`15250000 fffff805`15502000 tcpip (deferred)
- Mapped memory image file: c:\symbols\tcpip.sys\C818C3B32b2000\tcpip.sys
- Image path: \SystemRoot\System32\drivers\tcpip.sys
- Image name: tcpip.sys
- Timestamp: ***** Invalid (C818C3B3)
- CheckSum: 002A594E
- ImageSize: 002B2000
- File version: 10.0.16288.1
- Product version: 10.0.16288.1
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: tcpip.sys
- OriginalFilename: tcpip.sys
- ProductVersion: 10.0.16288.1
- FileVersion: 10.0.16288.1 (WinBuild.160101.0800)
- FileDescription: TCP/IP Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`15510000 fffff805`15581000 fwpkclnt (deferred)
- Mapped memory image file: c:\symbols\fwpkclnt.sys\CAEC7F6271000\fwpkclnt.sys
- Image path: \SystemRoot\System32\drivers\fwpkclnt.sys
- Image name: fwpkclnt.sys
- Timestamp: ***** Invalid (CAEC7F62)
- CheckSum: 00074586
- ImageSize: 00071000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: fwpkclnt.sys
- OriginalFilename: fwpkclnt.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: FWP/IPsec Kernel-Mode API
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`15590000 fffff805`155bc000 wfplwfs (deferred)
- Mapped memory image file: c:\symbols\wfplwfs.sys\E5844F932c000\wfplwfs.sys
- Image path: \SystemRoot\System32\drivers\wfplwfs.sys
- Image name: wfplwfs.sys
- Timestamp: ***** Invalid (E5844F93)
- CheckSum: 0002CCF4
- ImageSize: 0002C000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: WFPLWFS.SYS
- OriginalFilename: WFPLWFS.SYS
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: WFP NDIS 6.30 Lightweight Filter Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`155c0000 fffff805`155d9000 asstahci64 (deferred)
- Image path: \SystemRoot\System32\drivers\asstahci64.sys
- Image name: asstahci64.sys
- Timestamp: Tue May 17 10:38:26 2016 (573AE692)
- CheckSum: 000210CE
- ImageSize: 00019000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`155e0000 fffff805`155eb000 volume (deferred)
- Mapped memory image file: c:\symbols\volume.sys\1C3359ECb000\volume.sys
- Image path: \SystemRoot\System32\drivers\volume.sys
- Image name: volume.sys
- Timestamp: Sat Dec 29 00:16:44 1984 (1C3359EC)
- CheckSum: 0000EC6C
- ImageSize: 0000B000
- File version: 10.0.16246.1000
- Product version: 10.0.16246.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: volume.sys
- OriginalFilename: volume.sys
- ProductVersion: 10.0.16246.1000
- FileVersion: 10.0.16246.1000 (WinBuild.160101.0800)
- FileDescription: Volume driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`155f0000 fffff805`155f8000 pwdrvio (deferred)
- Image path: \SystemRoot\system32\pwdrvio.sys
- Image name: pwdrvio.sys
- Timestamp: Tue Jun 16 02:43:45 2009 (4A36F8D1)
- CheckSum: 000123CB
- ImageSize: 00008000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`15600000 fffff805`15d09000 kl1 (deferred)
- Image path: \SystemRoot\system32\DRIVERS\kl1.sys
- Image name: kl1.sys
- Timestamp: Fri Apr 1 15:20:28 2016 (56FE83AC)
- CheckSum: 0009550A
- ImageSize: 00709000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`15d10000 fffff805`15d21000 iorate (deferred)
- Mapped memory image file: c:\symbols\iorate.sys\6F697C3C11000\iorate.sys
- Image path: \SystemRoot\system32\drivers\iorate.sys
- Image name: iorate.sys
- Timestamp: Mon Mar 26 02:47:40 2029 (6F697C3C)
- CheckSum: 0000E990
- ImageSize: 00011000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: iorate.sys
- OriginalFilename: iorate.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: I/O rate control Filter
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`15d40000 fffff805`15d5c000 disk (deferred)
- Mapped memory image file: c:\symbols\disk.sys\C979741E1c000\disk.sys
- Image path: \SystemRoot\System32\drivers\disk.sys
- Image name: disk.sys
- Timestamp: ***** Invalid (C979741E)
- CheckSum: 00019C7D
- ImageSize: 0001C000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: disk.sys
- OriginalFilename: disk.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: PnP Disk Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`15d60000 fffff805`15dc8000 CLASSPNP (deferred)
- Mapped memory image file: c:\symbols\CLASSPNP.SYS\BF85BFAE68000\CLASSPNP.SYS
- Image path: \SystemRoot\System32\drivers\CLASSPNP.SYS
- Image name: CLASSPNP.SYS
- Timestamp: ***** Invalid (BF85BFAE)
- CheckSum: 00064E8F
- ImageSize: 00068000
- File version: 10.0.16288.1
- Product version: 10.0.16288.1
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: Classpnp.sys
- OriginalFilename: Classpnp.sys
- ProductVersion: 10.0.16288.1
- FileVersion: 10.0.16288.1 (WinBuild.160101.0800)
- FileDescription: SCSI Class System Dll
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`15df0000 fffff805`15e0b000 crashdmp (deferred)
- Mapped memory image file: c:\symbols\crashdmp.sys\8DC80A7C1b000\crashdmp.sys
- Image path: \SystemRoot\System32\Drivers\crashdmp.sys
- Image name: crashdmp.sys
- Timestamp: ***** Invalid (8DC80A7C)
- CheckSum: 0002044C
- ImageSize: 0001B000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: crashdmp.sys
- OriginalFilename: crashdmp.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Crash Dump Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`15ed0000 fffff805`15f7e000 klhk (deferred)
- Image path: \SystemRoot\System32\drivers\klhk.sys
- Image name: klhk.sys
- Timestamp: Tue Mar 28 13:43:13 2017 (58DA5A61)
- CheckSum: 00081BB4
- ImageSize: 000AE000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`15f80000 fffff805`15fae000 cdrom (deferred)
- Mapped memory image file: c:\symbols\cdrom.sys\1424F0702e000\cdrom.sys
- Image path: \SystemRoot\System32\drivers\cdrom.sys
- Image name: cdrom.sys
- Timestamp: Tue Sep 16 16:12:48 1980 (1424F070)
- CheckSum: 0002D825
- ImageSize: 0002E000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: cdrom.sys
- OriginalFilename: cdrom.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: SCSI CD-ROM Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`15fb0000 fffff805`15fc3000 klbackupflt (deferred)
- Image path: \SystemRoot\system32\DRIVERS\klbackupflt.sys
- Image name: klbackupflt.sys
- Timestamp: Fri Dec 23 11:35:00 2016 (585D0BE4)
- CheckSum: 00024F84
- ImageSize: 00013000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`15fd0000 fffff805`16010000 klflt (deferred)
- Image path: \SystemRoot\system32\DRIVERS\klflt.sys
- Image name: klflt.sys
- Timestamp: Wed Jul 19 13:00:58 2017 (596F49FA)
- CheckSum: 000422FC
- ImageSize: 00040000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`16010000 fffff805`16024000 filecrypt (deferred)
- Mapped memory image file: c:\symbols\filecrypt.sys\518A49BF14000\filecrypt.sys
- Image path: \SystemRoot\system32\drivers\filecrypt.sys
- Image name: filecrypt.sys
- Timestamp: Wed May 8 13:49:03 2013 (518A49BF)
- CheckSum: 00017691
- ImageSize: 00014000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: filecrypt.sys
- OriginalFilename: filecrypt.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Windows sandboxing and encryption filter
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`16030000 fffff805`1603d000 tbs (deferred)
- Mapped memory image file: c:\symbols\tbs.sys\237A7C1Dd000\tbs.sys
- Image path: \SystemRoot\system32\drivers\tbs.sys
- Image name: tbs.sys
- Timestamp: Fri Nov 11 05:35:25 1988 (237A7C1D)
- CheckSum: 0000A0B0
- ImageSize: 0000D000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: TBS.SYS
- OriginalFilename: TBS.SYS
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Export driver for kernel mode TPM API
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`16040000 fffff805`1604b000 klpd (deferred)
- Image path: \SystemRoot\system32\DRIVERS\klpd.sys
- Image name: klpd.sys
- Timestamp: Fri Mar 24 13:44:30 2017 (58D522BE)
- CheckSum: 00014A77
- ImageSize: 0000B000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`16050000 fffff805`16074000 mup (deferred)
- Mapped memory image file: c:\symbols\mup.sys\454D52CC24000\mup.sys
- Image path: \SystemRoot\System32\Drivers\mup.sys
- Image name: mup.sys
- Timestamp: Sun Nov 5 02:56:12 2006 (454D52CC)
- CheckSum: 0002706F
- ImageSize: 00024000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: MUP.SYS
- OriginalFilename: MUP.SYS
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Multiple UNC Provider Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`16080000 fffff805`1609c000 klupd_klif_klbg (deferred)
- Image path: \SystemRoot\System32\Drivers\klupd_klif_klbg.sys
- Image name: klupd_klif_klbg.sys
- Timestamp: Thu Mar 30 15:51:17 2017 (58DD1B65)
- CheckSum: 000234F1
- ImageSize: 0001C000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`160a0000 fffff805`161a7000 klif (deferred)
- Image path: \SystemRoot\system32\DRIVERS\klif.sys
- Image name: klif.sys
- Timestamp: Fri Aug 11 17:04:35 2017 (598DD593)
- CheckSum: 00102372
- ImageSize: 00107000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`161b0000 fffff805`161d3000 tdx (deferred)
- Mapped memory image file: c:\symbols\tdx.sys\0CBC8CF323000\tdx.sys
- Image path: \SystemRoot\system32\DRIVERS\tdx.sys
- Image name: tdx.sys
- Timestamp: Sat Oct 9 05:30:43 1976 (0CBC8CF3)
- CheckSum: 000245BA
- ImageSize: 00023000
- File version: 10.0.16353.1000
- Product version: 10.0.16353.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: tdx.sys
- OriginalFilename: tdx.sys
- ProductVersion: 10.0.16353.1000
- FileVersion: 10.0.16353.1000 (WinBuild.160101.0800)
- FileDescription: TDI Translation Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`16400000 fffff805`16679000 dxgkrnl (deferred)
- Image path: \SystemRoot\System32\drivers\dxgkrnl.sys
- Image name: dxgkrnl.sys
- Timestamp: Fri Feb 27 12:18:23 2015 (54F0608F)
- CheckSum: 002806CF
- ImageSize: 00279000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`16680000 fffff805`16690000 TDI (deferred)
- Mapped memory image file: c:\symbols\TDI.SYS\1BBDCA2C10000\TDI.SYS
- Image path: \SystemRoot\system32\DRIVERS\TDI.SYS
- Image name: TDI.SYS
- Timestamp: Sun Sep 30 21:08:12 1984 (1BBDCA2C)
- CheckSum: 00018A08
- ImageSize: 00010000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: tdi.sys
- OriginalFilename: tdi.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: TDI Wrapper
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`16690000 fffff805`166f8000 ks (deferred)
- Mapped memory image file: c:\symbols\ks.sys\C5B6B46568000\ks.sys
- Image path: \SystemRoot\system32\DRIVERS\ks.sys
- Image name: ks.sys
- Timestamp: ***** Invalid (C5B6B465)
- CheckSum: 00067ECB
- ImageSize: 00068000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.0 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: ks.sys
- OriginalFilename: ks.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Kernel CSA Library
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`16700000 fffff805`1670a000 Null (deferred)
- Mapped memory image file: c:\symbols\Null.SYS\E2BC2636a000\Null.SYS
- Image path: \SystemRoot\System32\Drivers\Null.SYS
- Image name: Null.SYS
- Timestamp: ***** Invalid (E2BC2636)
- CheckSum: 00005081
- ImageSize: 0000A000
- File version: 10.0.16262.1001
- Product version: 10.0.16262.1001
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: null.sys
- OriginalFilename: null.sys
- ProductVersion: 10.0.16262.1001
- FileVersion: 10.0.16262.1001 (WinBuild.160101.0800)
- FileDescription: NULL Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`16710000 fffff805`1671a000 Beep (deferred)
- Mapped memory image file: c:\symbols\Beep.SYS\85F9535Ba000\Beep.SYS
- Image path: \SystemRoot\System32\Drivers\Beep.SYS
- Image name: Beep.SYS
- Timestamp: ***** Invalid (85F9535B)
- CheckSum: 00004277
- ImageSize: 0000A000
- File version: 10.0.16262.1001
- Product version: 10.0.16262.1001
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: beep.sys
- OriginalFilename: beep.sys
- ProductVersion: 10.0.16262.1001
- FileVersion: 10.0.16262.1001 (WinBuild.160101.0800)
- FileDescription: BEEP Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`16720000 fffff805`16735000 BasicDisplay (deferred)
- Mapped memory image file: c:\symbols\BasicDisplay.sys\D192C74415000\BasicDisplay.sys
- Image path: \SystemRoot\System32\drivers\BasicDisplay.sys
- Image name: BasicDisplay.sys
- Timestamp: ***** Invalid (D192C744)
- CheckSum: 00019DDD
- ImageSize: 00015000
- File version: 10.0.16281.1000
- Product version: 10.0.16281.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.4 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: BasicDisplay.sys
- OriginalFilename: BasicDisplay.sys
- ProductVersion: 10.0.16281.1000
- FileVersion: 10.0.16281.1000 (WinBuild.160101.0800)
- FileDescription: Microsoft Basic Display Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`16740000 fffff805`16754000 watchdog (deferred)
- Mapped memory image file: c:\symbols\watchdog.sys\EE73D2B814000\watchdog.sys
- Image path: \SystemRoot\System32\drivers\watchdog.sys
- Image name: watchdog.sys
- Timestamp: ***** Invalid (EE73D2B8)
- CheckSum: 00011EB8
- ImageSize: 00014000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: watchdog.sys
- OriginalFilename: watchdog.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Watchdog Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`16760000 fffff805`1677a000 vmbkmclr (deferred)
- Mapped memory image file: c:\symbols\vmbkmclr.sys\3FDEFDB51a000\vmbkmclr.sys
- Image path: \SystemRoot\System32\drivers\vmbkmclr.sys
- Image name: vmbkmclr.sys
- Timestamp: Tue Dec 16 12:42:29 2003 (3FDEFDB5)
- CheckSum: 000142E8
- ImageSize: 0001A000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: vmbkmclr.sys
- OriginalFilename: vmbkmclr.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Hyper-V VMBus Root KMCL
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`16780000 fffff805`16790000 BasicRender (deferred)
- Mapped memory image file: c:\symbols\BasicRender.sys\6849FB6910000\BasicRender.sys
- Image path: \SystemRoot\System32\drivers\BasicRender.sys
- Image name: BasicRender.sys
- Timestamp: Wed Jun 11 22:55:53 2025 (6849FB69)
- CheckSum: 00011E03
- ImageSize: 00010000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.4 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: BasicRender.sys
- OriginalFilename: BasicRender.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Microsoft Basic Render Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`16790000 fffff805`167ab000 Npfs (deferred)
- Mapped memory image file: c:\symbols\Npfs.SYS\1A9900EF1b000\Npfs.SYS
- Image path: \SystemRoot\System32\Drivers\Npfs.SYS
- Image name: Npfs.SYS
- Timestamp: Tue Feb 21 18:07:43 1984 (1A9900EF)
- CheckSum: 000205EE
- ImageSize: 0001B000
- File version: 10.0.16278.1000
- Product version: 10.0.16278.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: npfs.sys
- OriginalFilename: npfs.sys
- ProductVersion: 10.0.16278.1000
- FileVersion: 10.0.16278.1000 (WinBuild.160101.0800)
- FileDescription: NPFS Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`167b0000 fffff805`167c0000 Msfs (deferred)
- Mapped memory image file: c:\symbols\Msfs.SYS\B74D7D9A10000\Msfs.SYS
- Image path: \SystemRoot\System32\Drivers\Msfs.SYS
- Image name: Msfs.SYS
- Timestamp: ***** Invalid (B74D7D9A)
- CheckSum: 000103E6
- ImageSize: 00010000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: MSFS.SYS
- OriginalFilename: MSFS.SYS
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Mailslot driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`167c0000 fffff805`167fd000 amdpsp (deferred)
- Image path: \SystemRoot\system32\DRIVERS\amdpsp.sys
- Image name: amdpsp.sys
- Timestamp: Mon Jun 5 22:23:56 2017 (5935CBEC)
- CheckSum: 000428AD
- ImageSize: 0003D000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`16800000 fffff805`16812000 netbios (deferred)
- Mapped memory image file: c:\symbols\netbios.sys\1AF6149412000\netbios.sys
- Image path: \SystemRoot\system32\drivers\netbios.sys
- Image name: netbios.sys
- Timestamp: Wed May 2 09:32:20 1984 (1AF61494)
- CheckSum: 0001A463
- ImageSize: 00012000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: NETBIOS.SYS
- OriginalFilename: NETBIOS.SYS
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: NetBIOS interface driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`16820000 fffff805`16893000 rdbss (deferred)
- Mapped memory image file: c:\symbols\rdbss.sys\E1D1CEAA73000\rdbss.sys
- Image path: \SystemRoot\system32\DRIVERS\rdbss.sys
- Image name: rdbss.sys
- Timestamp: ***** Invalid (E1D1CEAA)
- CheckSum: 00077CB6
- ImageSize: 00073000
- File version: 10.0.16288.1
- Product version: 10.0.16288.1
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: rdbss.sys
- OriginalFilename: RDBSS.Sys
- ProductVersion: 10.0.16288.1
- FileVersion: 10.0.16288.1 (WinBuild.160101.0800)
- FileDescription: Redirected Drive Buffering SubSystem Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`168a0000 fffff805`1692f000 csc (deferred)
- Mapped memory image file: c:\symbols\csc.sys\9EFA102F8f000\csc.sys
- Image path: \SystemRoot\system32\drivers\csc.sys
- Image name: csc.sys
- Timestamp: ***** Invalid (9EFA102F)
- CheckSum: 000932EF
- ImageSize: 0008F000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: csc.sys
- OriginalFilename: CSC.Sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Windows Client Side Caching Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`16930000 fffff805`16960000 VBoxUSBMon (deferred)
- Image path: \SystemRoot\system32\DRIVERS\VBoxUSBMon.sys
- Image name: VBoxUSBMon.sys
- Timestamp: Wed Sep 13 10:04:22 2017 (59B8F496)
- CheckSum: 0002D60A
- ImageSize: 00030000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`16960000 fffff805`16a59000 VBoxDrv (deferred)
- Image path: \SystemRoot\system32\DRIVERS\VBoxDrv.sys
- Image name: VBoxDrv.sys
- Timestamp: Wed Sep 13 10:04:22 2017 (59B8F496)
- CheckSum: 000F10CB
- ImageSize: 000F9000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`16a60000 fffff805`16a72000 nsiproxy (deferred)
- Image path: \SystemRoot\system32\drivers\nsiproxy.sys
- Image name: nsiproxy.sys
- Timestamp: ***** Invalid (955A981E)
- CheckSum: 00019605
- ImageSize: 00012000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`16a80000 fffff805`16a8d000 npsvctrig (deferred)
- Mapped memory image file: c:\symbols\npsvctrig.sys\BCBD5B64d000\npsvctrig.sys
- Image path: \SystemRoot\System32\drivers\npsvctrig.sys
- Image name: npsvctrig.sys
- Timestamp: ***** Invalid (BCBD5B64)
- CheckSum: 0000CF41
- ImageSize: 0000D000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: npsvctrig.sys
- OriginalFilename: npsvctrig.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Named pipe service triggers
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`16a90000 fffff805`16a9f000 mssmbios (deferred)
- Mapped memory image file: c:\symbols\mssmbios.sys\34839A22f000\mssmbios.sys
- Image path: \SystemRoot\System32\drivers\mssmbios.sys
- Image name: mssmbios.sys
- Timestamp: Tue Dec 2 05:18:26 1997 (34839A22)
- CheckSum: 000147F2
- ImageSize: 0000F000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: smbios.sys
- OriginalFilename: smbios.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: System Management BIOS Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`16aa0000 fffff805`16acd000 kneps (deferred)
- Image path: \SystemRoot\system32\DRIVERS\kneps.sys
- Image name: kneps.sys
- Timestamp: Wed Jun 7 10:54:05 2017 (5937CD3D)
- CheckSum: 0003FEA6
- ImageSize: 0002D000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`16b00000 fffff805`16b0a000 gpuenergydrv (deferred)
- Mapped memory image file: c:\symbols\gpuenergydrv.sys\4E8D39D4a000\gpuenergydrv.sys
- Image path: \SystemRoot\System32\drivers\gpuenergydrv.sys
- Image name: gpuenergydrv.sys
- Timestamp: Thu Oct 6 06:17:08 2011 (4E8D39D4)
- CheckSum: 0000C3FE
- ImageSize: 0000A000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: gpuenergydrv.sys
- OriginalFilename: gpuenergydrv.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: GPU Energy Kernel Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`16b10000 fffff805`16b3a000 dfsc (deferred)
- Mapped memory image file: c:\symbols\dfsc.sys\94C5D3E22a000\dfsc.sys
- Image path: \SystemRoot\System32\Drivers\dfsc.sys
- Image name: dfsc.sys
- Timestamp: ***** Invalid (94C5D3E2)
- CheckSum: 0002D468
- ImageSize: 0002A000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: dfsclient.sys
- OriginalFilename: dfsclient.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: DFS Namespace Client Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`16b60000 fffff805`16b74000 bam (deferred)
- Mapped memory image file: c:\symbols\bam.sys\0CD64A3A14000\bam.sys
- Image path: \SystemRoot\system32\drivers\bam.sys
- Image name: bam.sys
- Timestamp: Thu Oct 28 18:04:58 1976 (0CD64A3A)
- CheckSum: 0001B21F
- ImageSize: 00014000
- File version: 10.0.16288.1
- Product version: 10.0.16288.1
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: bam.sys
- OriginalFilename: bam.sys
- ProductVersion: 10.0.16288.1
- FileVersion: 10.0.16288.1 (WinBuild.160101.0800)
- FileDescription: BAM Kernel Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`16b80000 fffff805`16bc2000 ahcache (deferred)
- Mapped memory image file: c:\symbols\ahcache.sys\D84C012D42000\ahcache.sys
- Image path: \SystemRoot\system32\DRIVERS\ahcache.sys
- Image name: ahcache.sys
- Timestamp: ***** Invalid (D84C012D)
- CheckSum: 0003BC67
- ImageSize: 00042000
- File version: 10.0.16278.1000
- Product version: 10.0.16278.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: ahcache.sys
- OriginalFilename: ahcache.sys
- ProductVersion: 10.0.16278.1000
- FileVersion: 10.0.16278.1000 (WinBuild.160101.0800)
- FileDescription: Application Compatibility Cache
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`16bd0000 fffff805`16c0e000 VBoxNetAdp6 (deferred)
- Image path: \SystemRoot\System32\drivers\VBoxNetAdp6.sys
- Image name: VBoxNetAdp6.sys
- Timestamp: Wed Sep 13 10:04:22 2017 (59B8F496)
- CheckSum: 0003E509
- ImageSize: 0003E000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`16c10000 fffff805`16c1c000 kltap (deferred)
- Image path: \SystemRoot\System32\drivers\kltap.sys
- Image name: kltap.sys
- Timestamp: Mon May 16 22:04:28 2016 (573A35DC)
- CheckSum: 0000FCAA
- ImageSize: 0000C000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`16c20000 fffff805`16c31000 CompositeBus (deferred)
- Mapped memory image file: c:\symbols\CompositeBus.sys\3D0FA01A11000\CompositeBus.sys
- Image path: \SystemRoot\System32\DriverStore\FileRepository\compositebus.inf_amd64_164ab490b1c4a422\CompositeBus.sys
- Image name: CompositeBus.sys
- Timestamp: Tue Jun 18 22:03:22 2002 (3D0FA01A)
- CheckSum: 000128FE
- ImageSize: 00011000
- File version: 10.0.16262.1001
- Product version: 10.0.16262.1001
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: compositebus.sys
- OriginalFilename: compositebus.sys
- ProductVersion: 10.0.16262.1001
- FileVersion: 10.0.16262.1001 (WinBuild.160101.0800)
- FileDescription: Multi-Transport Composite Bus Enumerator
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`16c40000 fffff805`16c4b000 serscan (deferred)
- Mapped memory image file: c:\symbols\serscan.sys\D5242713b000\serscan.sys
- Image path: \SystemRoot\system32\DRIVERS\serscan.sys
- Image name: serscan.sys
- Timestamp: ***** Invalid (D5242713)
- CheckSum: 00012978
- ImageSize: 0000B000
- File version: 10.0.16262.1001
- Product version: 10.0.16262.1001
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: serscan.sys
- OriginalFilename: serscan.sys
- ProductVersion: 10.0.16262.1001
- FileVersion: 10.0.16262.1001 (WinBuild.160101.0800)
- FileDescription: Serial Imaging Device Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`16c50000 fffff805`16c5f000 ksthunk (deferred)
- Mapped memory image file: c:\symbols\ksthunk.sys\3E950951f000\ksthunk.sys
- Image path: \SystemRoot\system32\drivers\ksthunk.sys
- Image name: ksthunk.sys
- Timestamp: Thu Apr 10 07:04:01 2003 (3E950951)
- CheckSum: 0000D4C7
- ImageSize: 0000F000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.0 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: ksthunk.sys
- OriginalFilename: ksthunk.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Kernel Streaming WOW Thunk Service
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`16c60000 fffff805`16c6d000 kdnic (deferred)
- Mapped memory image file: c:\symbols\kdnic.sys\E91C9C29d000\kdnic.sys
- Image path: \SystemRoot\System32\drivers\kdnic.sys
- Image name: kdnic.sys
- Timestamp: ***** Invalid (E91C9C29)
- CheckSum: 0000A619
- ImageSize: 0000D000
- File version: 6.1.0.0
- Product version: 6.1.0.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft Kernel Debugger Network Adapter (NDIS 6.20 Miniport)
- InternalName: kdnic.sys
- OriginalFilename: kdnic.sys
- ProductVersion: 6.01.00.0000
- FileVersion: 6.01.00.0000 (WinBuild.160101.0800)
- FileDescription: Microsoft Kernel Debugger Network Miniport
- LegalCopyright: Copyright (C) Microsoft Corporation. All rights reserved.
- fffff805`16c70000 fffff805`16c85000 umbus (deferred)
- Mapped memory image file: c:\symbols\umbus.sys\6E2974CF15000\umbus.sys
- Image path: \SystemRoot\System32\drivers\umbus.sys
- Image name: umbus.sys
- Timestamp: Wed Jul 26 08:50:39 2028 (6E2974CF)
- CheckSum: 0001CDDF
- ImageSize: 00015000
- File version: 10.0.16262.1001
- Product version: 10.0.16262.1001
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: umbus.sys
- OriginalFilename: umbus.sys
- ProductVersion: 10.0.16262.1001
- FileVersion: 10.0.16262.1001 (WinBuild.160101.0800)
- FileDescription: User-Mode Bus Enumerator
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`16c90000 fffff805`16d00000 USBXHCI (deferred)
- Mapped memory image file: c:\symbols\USBXHCI.SYS\EF002EB670000\USBXHCI.SYS
- Image path: \SystemRoot\System32\drivers\USBXHCI.SYS
- Image name: USBXHCI.SYS
- Timestamp: ***** Invalid (EF002EB6)
- CheckSum: 00079368
- ImageSize: 00070000
- File version: 10.0.16281.1000
- Product version: 10.0.16281.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: usbxhci.sys
- OriginalFilename: usbxhci.sys
- ProductVersion: 10.0.16281.1000
- FileVersion: 10.0.16281.1000 (WinBuild.160101.0800)
- FileDescription: USB XHCI Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`16d00000 fffff805`16d3c000 ucx01000 (deferred)
- Mapped memory image file: c:\symbols\ucx01000.sys\A2A8C6AD3c000\ucx01000.sys
- Image path: \SystemRoot\system32\drivers\ucx01000.sys
- Image name: ucx01000.sys
- Timestamp: ***** Invalid (A2A8C6AD)
- CheckSum: 0003B0B9
- ImageSize: 0003C000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: ucx01000.sys
- OriginalFilename: ucx01000.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: USB Controller Extension
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`16d40000 fffff805`16d4a000 rccfg (deferred)
- Image path: \SystemRoot\System32\drivers\rccfg.sys
- Image name: rccfg.sys
- Timestamp: Tue Mar 28 14:34:19 2017 (58DA665B)
- CheckSum: 0000E708
- ImageSize: 0000A000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`17210000 fffff805`17266000 netbt (deferred)
- Mapped memory image file: c:\symbols\netbt.sys\39FA0BBD56000\netbt.sys
- Image path: \SystemRoot\System32\DRIVERS\netbt.sys
- Image name: netbt.sys
- Timestamp: Sat Oct 28 00:11:57 2000 (39FA0BBD)
- CheckSum: 000552E5
- ImageSize: 00056000
- File version: 10.0.16288.1
- Product version: 10.0.16288.1
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: netbt.sys
- OriginalFilename: netbt.sys
- ProductVersion: 10.0.16288.1
- FileVersion: 10.0.16288.1 (WinBuild.160101.0800)
- FileDescription: MBT Transport driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`17270000 fffff805`17286000 klwfp (deferred)
- Image path: \SystemRoot\system32\DRIVERS\klwfp.sys
- Image name: klwfp.sys
- Timestamp: Tue Nov 29 10:32:02 2016 (583D5922)
- CheckSum: 0001703E
- ImageSize: 00016000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`17290000 fffff805`1732b000 afd (deferred)
- Mapped memory image file: c:\symbols\afd.sys\AE5DA66C9b000\afd.sys
- Image path: \SystemRoot\system32\drivers\afd.sys
- Image name: afd.sys
- Timestamp: ***** Invalid (AE5DA66C)
- CheckSum: 0009FAC5
- ImageSize: 0009B000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: afd.sys
- OriginalFilename: afd.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Ancillary Function Driver for WinSock
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`17330000 fffff805`1733c000 klim6 (deferred)
- Image path: \SystemRoot\system32\DRIVERS\klim6.sys
- Image name: klim6.sys
- Timestamp: Fri Sep 30 14:35:20 2016 (57EE6A18)
- CheckSum: 0001BB70
- ImageSize: 0000C000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`17340000 fffff805`17381000 VBoxNetLwf (deferred)
- Image path: \SystemRoot\system32\DRIVERS\VBoxNetLwf.sys
- Image name: VBoxNetLwf.sys
- Timestamp: Wed Sep 13 10:04:22 2017 (59B8F496)
- CheckSum: 0003AE93
- ImageSize: 00041000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`17390000 fffff805`173aa000 vwififlt (deferred)
- Mapped memory image file: c:\symbols\vwififlt.sys\F55574E71a000\vwififlt.sys
- Image path: \SystemRoot\System32\drivers\vwififlt.sys
- Image name: vwififlt.sys
- Timestamp: ***** Invalid (F55574E7)
- CheckSum: 00016A95
- ImageSize: 0001A000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: vwififlt.sys
- OriginalFilename: vwififlt.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Virtual WiFi Filter Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`173b0000 fffff805`173d9000 pacer (deferred)
- Mapped memory image file: c:\symbols\pacer.sys\5053745729000\pacer.sys
- Image path: \SystemRoot\System32\drivers\pacer.sys
- Image name: pacer.sys
- Timestamp: Fri Sep 14 19:15:51 2012 (50537457)
- CheckSum: 00025DF7
- ImageSize: 00029000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: pacer.sys
- OriginalFilename: pacer.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: QoS Packet Scheduler
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`173e0000 fffff805`17400000 klwtp (deferred)
- Image path: \SystemRoot\system32\DRIVERS\klwtp.sys
- Image name: klwtp.sys
- Timestamp: Fri Mar 24 13:45:50 2017 (58D5230E)
- CheckSum: 0002607B
- ImageSize: 00020000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`17c00000 fffff805`17c87000 e1r65x64 (deferred)
- Image path: \SystemRoot\system32\DRIVERS\e1r65x64.sys
- Image name: e1r65x64.sys
- Timestamp: Sat Jul 30 08:56:48 2016 (579C5DC0)
- CheckSum: 00088915
- ImageSize: 00087000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`17c90000 fffff805`17d15000 atikmpag (deferred)
- Image path: \SystemRoot\System32\DriverStore\FileRepository\c0318192.inf_amd64_d0f929f3a19ab987\atikmpag.sys
- Image name: atikmpag.sys
- Timestamp: Tue Sep 19 00:02:19 2017 (59C0507B)
- CheckSum: 0008D373
- ImageSize: 00085000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`17d20000 fffff805`17d67000 srvnet (deferred)
- Mapped memory image file: c:\symbols\srvnet.sys\0AF3550547000\srvnet.sys
- Image path: \SystemRoot\System32\DRIVERS\srvnet.sys
- Image name: srvnet.sys
- Timestamp: Tue Oct 28 09:06:13 1975 (0AF35505)
- CheckSum: 00043080
- ImageSize: 00047000
- File version: 10.0.16288.1
- Product version: 10.0.16288.1
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: SRVNET.SYS
- OriginalFilename: SRVNET.SYS
- ProductVersion: 10.0.16288.1
- FileVersion: 10.0.16288.1 (WinBuild.160101.0800)
- FileDescription: Server Network driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`17d70000 fffff805`17dbe000 mrxsmb10 (deferred)
- Mapped memory image file: c:\symbols\mrxsmb10.sys\4BEADCED4e000\mrxsmb10.sys
- Image path: \SystemRoot\system32\DRIVERS\mrxsmb10.sys
- Image name: mrxsmb10.sys
- Timestamp: Wed May 12 17:53:01 2010 (4BEADCED)
- CheckSum: 00048977
- ImageSize: 0004E000
- File version: 10.0.16288.1
- Product version: 10.0.16288.1
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: MRxSmb0.sys
- OriginalFilename: MRXSMB0.Sys
- ProductVersion: 10.0.16288.1
- FileVersion: 10.0.16288.1 (WinBuild.160101.0800)
- FileDescription: Longhorn SMB Downlevel SubRdr
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`17dc0000 fffff805`17e81000 peauth (deferred)
- Image path: \SystemRoot\system32\drivers\peauth.sys
- Image name: peauth.sys
- Timestamp: Tue Oct 28 05:03:18 2014 (544F2396)
- CheckSum: 000B8888
- ImageSize: 000C1000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`17e90000 fffff805`17f49000 srv2 (deferred)
- Mapped memory image file: c:\symbols\srv2.sys\F3EF8D9Db9000\srv2.sys
- Image path: \SystemRoot\System32\DRIVERS\srv2.sys
- Image name: srv2.sys
- Timestamp: ***** Invalid (F3EF8D9D)
- CheckSum: 000C0CE9
- ImageSize: 000B9000
- File version: 10.0.16288.1
- Product version: 10.0.16288.1
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: SRV2.SYS
- OriginalFilename: SRV2.SYS
- ProductVersion: 10.0.16288.1
- FileVersion: 10.0.16288.1 (WinBuild.160101.0800)
- FileDescription: Smb 2.0 Server driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`17f50000 fffff805`17f63000 tcpipreg (deferred)
- Mapped memory image file: c:\symbols\tcpipreg.sys\5B8D9A4813000\tcpipreg.sys
- Image path: \SystemRoot\System32\drivers\tcpipreg.sys
- Image name: tcpipreg.sys
- Timestamp: Mon Sep 3 21:32:08 2018 (5B8D9A48)
- CheckSum: 0000DBDA
- ImageSize: 00013000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 1.0 App
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: tcpipreg.sys
- OriginalFilename: tcpipreg.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: TCP/IP Registry Compatibility Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`17f70000 fffff805`18000000 srv (deferred)
- Mapped memory image file: c:\symbols\srv.sys\2C44A55390000\srv.sys
- Image path: \SystemRoot\System32\DRIVERS\srv.sys
- Image name: srv.sys
- Timestamp: Thu Jul 15 01:31:15 1993 (2C44A553)
- CheckSum: 00075884
- ImageSize: 00090000
- File version: 10.0.16288.1
- Product version: 10.0.16288.1
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: SRV.SYS
- OriginalFilename: SRV.SYS
- ProductVersion: 10.0.16288.1
- FileVersion: 10.0.16288.1 (WinBuild.160101.0800)
- FileDescription: Server driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`18000000 fffff805`1801b000 rassstp (deferred)
- Mapped memory image file: c:\symbols\rassstp.sys\D487583C1b000\rassstp.sys
- Image path: \SystemRoot\System32\drivers\rassstp.sys
- Image name: rassstp.sys
- Timestamp: ***** Invalid (D487583C)
- CheckSum: 0001E748
- ImageSize: 0001B000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: rassstp.sys
- OriginalFilename: rassstp.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: RAS SSTP Miniport Call Manager
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`18020000 fffff805`18036000 NDProxy (deferred)
- Mapped memory image file: c:\symbols\NDProxy.sys\B13FCE4516000\NDProxy.sys
- Image path: \SystemRoot\System32\DRIVERS\NDProxy.sys
- Image name: NDProxy.sys
- Timestamp: ***** Invalid (B13FCE45)
- CheckSum: 00011FA8
- ImageSize: 00016000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: ndproxy.sys
- OriginalFilename: ndproxy.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: NDIS Proxy
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`18040000 fffff805`18067000 AgileVpn (deferred)
- Mapped memory image file: c:\symbols\AgileVpn.sys\BDD34C6E27000\AgileVpn.sys
- Image path: \SystemRoot\System32\drivers\AgileVpn.sys
- Image name: AgileVpn.sys
- Timestamp: ***** Invalid (BDD34C6E)
- CheckSum: 0002991F
- ImageSize: 00027000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: agilevpn.sys
- OriginalFilename: agilevpn.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: RAS Agile Vpn Miniport Call Manager
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`18070000 fffff805`18090000 rasl2tp (deferred)
- Mapped memory image file: c:\symbols\rasl2tp.sys\EDECEF5F20000\rasl2tp.sys
- Image path: \SystemRoot\System32\drivers\rasl2tp.sys
- Image name: rasl2tp.sys
- Timestamp: ***** Invalid (EDECEF5F)
- CheckSum: 0001F99D
- ImageSize: 00020000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: rasl2tp.sys
- OriginalFilename: rasl2tp.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: RAS L2TP mini-port/call-manager driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`18090000 fffff805`180af000 raspptp (deferred)
- Mapped memory image file: c:\symbols\raspptp.sys\30102AA91f000\raspptp.sys
- Image path: \SystemRoot\System32\drivers\raspptp.sys
- Image name: raspptp.sys
- Timestamp: Fri Jul 21 23:31:05 1995 (30102AA9)
- CheckSum: 00022328
- ImageSize: 0001F000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: RASPPTP.SYS
- OriginalFilename: RASPPTP.SYS
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Peer-to-Peer Tunneling Protocol
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`180b0000 fffff805`180cb000 raspppoe (deferred)
- Mapped memory image file: c:\symbols\raspppoe.sys\A080D0BE1b000\raspppoe.sys
- Image path: \SystemRoot\System32\DRIVERS\raspppoe.sys
- Image name: raspppoe.sys
- Timestamp: ***** Invalid (A080D0BE)
- CheckSum: 0001E766
- ImageSize: 0001B000
- File version: 10.0.16262.1001
- Product version: 10.0.16262.1001
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: raspppoe.sys
- OriginalFilename: raspppoe.sys
- ProductVersion: 10.0.16262.1001
- FileVersion: 10.0.16262.1001 (WinBuild.160101.0800)
- FileDescription: RAS PPPoE mini-port/call-manager driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`180d0000 fffff805`18107000 ndiswan (deferred)
- Mapped memory image file: c:\symbols\ndiswan.sys\F58EC2FA37000\ndiswan.sys
- Image path: \SystemRoot\System32\drivers\ndiswan.sys
- Image name: ndiswan.sys
- Timestamp: ***** Invalid (F58EC2FA)
- CheckSum: 00034D9C
- ImageSize: 00037000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: NDISWAN.SYS
- OriginalFilename: NDISWAN.SYS
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: MS PPP Framing Driver (Strong Encryption)
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`18110000 fffff805`1813b000 ibtusb (deferred)
- Image path: \SystemRoot\system32\DRIVERS\ibtusb.sys
- Image name: ibtusb.sys
- Timestamp: Wed Jun 21 21:09:28 2017 (594AD278)
- CheckSum: 00035259
- ImageSize: 0002B000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`18140000 fffff805`1815c000 BTHUSB (deferred)
- Mapped memory image file: c:\symbols\BTHUSB.sys\84C1E1731c000\BTHUSB.sys
- Image path: \SystemRoot\system32\DRIVERS\BTHUSB.sys
- Image name: BTHUSB.sys
- Timestamp: ***** Invalid (84C1E173)
- CheckSum: 000170CA
- ImageSize: 0001C000
- File version: 10.0.16288.1
- Product version: 10.0.16288.1
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: bthusb.sys
- OriginalFilename: bthusb.sys
- ProductVersion: 10.0.16288.1
- FileVersion: 10.0.16288.1 (WinBuild.160101.0800)
- FileDescription: Bluetooth Miniport Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`18160000 fffff805`1825f000 bthport (deferred)
- Mapped memory image file: c:\symbols\bthport.sys\7ACA307Aff000\bthport.sys
- Image path: \SystemRoot\system32\DRIVERS\bthport.sys
- Image name: bthport.sys
- Timestamp: Fri Apr 13 10:57:14 2035 (7ACA307A)
- CheckSum: 000FCD8B
- ImageSize: 000FF000
- File version: 10.0.16288.1
- Product version: 10.0.16288.1
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: bthport.sys
- OriginalFilename: bthport.sys
- ProductVersion: 10.0.16288.1
- FileVersion: 10.0.16288.1 (WinBuild.160101.0800)
- FileDescription: Bluetooth Bus Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`18760000 fffff805`18eeb000 Netwtw04 (deferred)
- Image path: \SystemRoot\System32\drivers\Netwtw04.sys
- Image name: Netwtw04.sys
- Timestamp: Sun Jul 2 19:25:56 2017 (59593AB4)
- CheckSum: 00749699
- ImageSize: 0078B000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`18ef0000 fffff805`18fb3000 wdiwifi (deferred)
- Mapped memory image file: c:\symbols\wdiwifi.sys\3BBEA85Dc3000\wdiwifi.sys
- Image path: \SystemRoot\system32\DRIVERS\wdiwifi.sys
- Image name: wdiwifi.sys
- Timestamp: Sat Oct 6 07:44:45 2001 (3BBEA85D)
- CheckSum: 000CB2BB
- ImageSize: 000C3000
- File version: 10.0.16288.1
- Product version: 10.0.16288.1
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: wdiwifi.sys
- OriginalFilename: wdiwifi.sys
- ProductVersion: 10.0.16288.1
- FileVersion: 10.0.16288.1 (WinBuild.160101.0800)
- FileDescription: WDI Driver Framework Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`18fc0000 fffff805`18fce000 vwifibus (deferred)
- Mapped memory image file: c:\symbols\vwifibus.sys\2AD49D54e000\vwifibus.sys
- Image path: \SystemRoot\System32\drivers\vwifibus.sys
- Image name: vwifibus.sys
- Timestamp: Thu Oct 8 21:43:00 1992 (2AD49D54)
- CheckSum: 0000C4A8
- ImageSize: 0000E000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: VWiFiBus.sys
- OriginalFilename: VWiFiBus.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Virtual Wireless Bus Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1b600000 fffff805`1bbaa000 RTKVHD64 (deferred)
- Image path: \SystemRoot\system32\drivers\RTKVHD64.sys
- Image name: RTKVHD64.sys
- Timestamp: Tue Apr 18 13:08:20 2017 (58F601B4)
- CheckSum: 00579AD6
- ImageSize: 005AA000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`1bbb0000 fffff805`1bc6c000 dxgmms2 (deferred)
- Image path: \SystemRoot\System32\drivers\dxgmms2.sys
- Image name: dxgmms2.sys
- Timestamp: Sat Oct 18 04:03:01 1997 (344826E5)
- CheckSum: 000BA097
- ImageSize: 000BC000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`1bc70000 fffff805`1bc96000 luafv (deferred)
- Mapped memory image file: c:\symbols\luafv.sys\229F7AA626000\luafv.sys
- Image path: \SystemRoot\system32\drivers\luafv.sys
- Image name: luafv.sys
- Timestamp: Sun May 29 03:42:46 1988 (229F7AA6)
- CheckSum: 00023E56
- ImageSize: 00026000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: luafv.sys
- OriginalFilename: luafv.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: LUA File Virtualization Filter Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1bca0000 fffff805`1bcc7000 wcifs (deferred)
- Mapped memory image file: c:\symbols\wcifs.sys\549B61FA27000\wcifs.sys
- Image path: \SystemRoot\system32\drivers\wcifs.sys
- Image name: wcifs.sys
- Timestamp: Thu Dec 25 01:01:46 2014 (549B61FA)
- CheckSum: 0002A375
- ImageSize: 00027000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: wcifs.sys
- OriginalFilename: wcifs.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Windows Container Isolation FS Filter Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1bcd0000 fffff805`1bd16000 WUDFRd (deferred)
- Mapped memory image file: c:\symbols\WUDFRd.sys\9195B73B46000\WUDFRd.sys
- Image path: \SystemRoot\system32\DRIVERS\WUDFRd.sys
- Image name: WUDFRd.sys
- Timestamp: ***** Invalid (9195B73B)
- CheckSum: 0004D0BB
- ImageSize: 00046000
- File version: 10.0.16288.1
- Product version: 10.0.16288.1
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: WUDFRd.sys
- OriginalFilename: WUDFRd.sys
- ProductVersion: 10.0.16288.1
- FileVersion: 10.0.16288.1 (WinBuild.160101.0800)
- FileDescription: Windows Driver Foundation - User-mode Driver Framework Reflector
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1bd20000 fffff805`1bd86000 cldflt (deferred)
- Image path: \SystemRoot\system32\drivers\cldflt.sys
- Image name: cldflt.sys
- Timestamp: Thu Jun 29 10:42:13 1989 (24A9EEF5)
- CheckSum: 00061F3D
- ImageSize: 00066000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`1bd90000 fffff805`1bda9000 storqosflt (deferred)
- Mapped memory image file: c:\symbols\storqosflt.sys\426B6C8119000\storqosflt.sys
- Image path: \SystemRoot\system32\drivers\storqosflt.sys
- Image name: storqosflt.sys
- Timestamp: Sun Apr 24 10:53:05 2005 (426B6C81)
- CheckSum: 00019668
- ImageSize: 00019000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: storqosflt.sys
- OriginalFilename: storqosflt.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Storage QoS Filter
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1bdb0000 fffff805`1bdca000 mslldp (deferred)
- Mapped memory image file: c:\symbols\mslldp.sys\0A8826211a000\mslldp.sys
- Image path: \SystemRoot\system32\drivers\mslldp.sys
- Image name: mslldp.sys
- Timestamp: Fri Aug 8 02:53:37 1975 (0A882621)
- CheckSum: 00021544
- ImageSize: 0001A000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: MSLLDP.SYS
- OriginalFilename: MSLLDP.SYS
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Microsoft Link-Layer Discovery Protocol Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1bdd0000 fffff805`1bde2000 condrv (deferred)
- Mapped memory image file: c:\symbols\condrv.sys\A6EA12B512000\condrv.sys
- Image path: \SystemRoot\System32\drivers\condrv.sys
- Image name: condrv.sys
- Timestamp: ***** Invalid (A6EA12B5)
- CheckSum: 0001264A
- ImageSize: 00012000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: condrv.sys
- OriginalFilename: condrv.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Console Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1bdf0000 fffff805`1be06000 lltdio (deferred)
- Mapped memory image file: c:\symbols\lltdio.sys\562D485116000\lltdio.sys
- Image path: \SystemRoot\system32\drivers\lltdio.sys
- Image name: lltdio.sys
- Timestamp: Sun Oct 25 21:23:29 2015 (562D4851)
- CheckSum: 0001D32C
- ImageSize: 00016000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: LLTDIO.SYS
- OriginalFilename: LLTDIO.SYS
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Link-Layer Topology Mapper I/O Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1be10000 fffff805`1be2a000 rspndr (deferred)
- Mapped memory image file: c:\symbols\rspndr.sys\808AAECD1a000\rspndr.sys
- Image path: \SystemRoot\system32\drivers\rspndr.sys
- Image name: rspndr.sys
- Timestamp: ***** Invalid (808AAECD)
- CheckSum: 0001DF2E
- ImageSize: 0001A000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: RSPNDR.SYS
- OriginalFilename: RSPNDR.SYS
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Link-Layer Topology Responder Driver for NDIS 6
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1be30000 fffff805`1be4b000 wanarp (deferred)
- Mapped memory image file: c:\symbols\wanarp.sys\F90588841b000\wanarp.sys
- Image path: \SystemRoot\System32\DRIVERS\wanarp.sys
- Image name: wanarp.sys
- Timestamp: ***** Invalid (F9058884)
- CheckSum: 00014F65
- ImageSize: 0001B000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: WANARP.SYS
- OriginalFilename: WANARP.SYS
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: MS Remote Access and Routing ARP Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1be50000 fffff805`1bed7000 nwifi (deferred)
- Mapped memory image file: c:\symbols\nwifi.sys\2D5908D487000\nwifi.sys
- Image path: \SystemRoot\system32\DRIVERS\nwifi.sys
- Image name: nwifi.sys
- Timestamp: Wed Feb 9 16:01:24 1994 (2D5908D4)
- CheckSum: 0008784A
- ImageSize: 00087000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: NWiFi.SYS
- OriginalFilename: NWiFi.SYS
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: NativeWiFi Miniport Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1bee0000 fffff805`1bef6000 ndisuio (deferred)
- Mapped memory image file: c:\symbols\ndisuio.sys\9ABF995E16000\ndisuio.sys
- Image path: \SystemRoot\system32\drivers\ndisuio.sys
- Image name: ndisuio.sys
- Timestamp: ***** Invalid (9ABF995E)
- CheckSum: 00010091
- ImageSize: 00016000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: NDISUIO.SYS
- OriginalFilename: NDISUIO.SYS
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: NDIS User mode I/O driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1bf00000 fffff805`1c013000 HTTP (deferred)
- Mapped memory image file: c:\symbols\HTTP.sys\8E07C76C113000\HTTP.sys
- Image path: \SystemRoot\system32\drivers\HTTP.sys
- Image name: HTTP.sys
- Timestamp: ***** Invalid (8E07C76C)
- CheckSum: 00111897
- ImageSize: 00113000
- File version: 10.0.16288.1
- Product version: 10.0.16288.1
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: http.sys
- OriginalFilename: http.sys
- ProductVersion: 10.0.16288.1
- FileVersion: 10.0.16288.1 (WinBuild.160101.0800)
- FileDescription: HTTP Protocol Stack
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1c020000 fffff805`1c041000 bowser (deferred)
- Mapped memory image file: c:\symbols\bowser.sys\A73B9D4121000\bowser.sys
- Image path: \SystemRoot\system32\DRIVERS\bowser.sys
- Image name: bowser.sys
- Timestamp: ***** Invalid (A73B9D41)
- CheckSum: 0001AC75
- ImageSize: 00021000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: browser.sys
- OriginalFilename: browser.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: NT Lan Manager Datagram Receiver Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1c050000 fffff805`1c069000 mpsdrv (deferred)
- Mapped memory image file: c:\symbols\mpsdrv.sys\DFB7E61319000\mpsdrv.sys
- Image path: \SystemRoot\System32\drivers\mpsdrv.sys
- Image name: mpsdrv.sys
- Timestamp: ***** Invalid (DFB7E613)
- CheckSum: 0001BC83
- ImageSize: 00019000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: mpsdrv.sys
- OriginalFilename: mpsdrv.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Microsoft Protection Service Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1c070000 fffff805`1c0f1000 mrxsmb (deferred)
- Image path: \SystemRoot\system32\DRIVERS\mrxsmb.sys
- Image name: mrxsmb.sys
- Timestamp: Fri Dec 18 12:18:57 1970 (01CF6BB1)
- CheckSum: 00083D5C
- ImageSize: 00081000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`1c100000 fffff805`1c13d000 mrxsmb20 (deferred)
- Mapped memory image file: c:\symbols\mrxsmb20.sys\BCF390873d000\mrxsmb20.sys
- Image path: \SystemRoot\system32\DRIVERS\mrxsmb20.sys
- Image name: mrxsmb20.sys
- Timestamp: ***** Invalid (BCF39087)
- CheckSum: 0003E809
- ImageSize: 0003D000
- File version: 10.0.16288.1
- Product version: 10.0.16288.1
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: MRxSmb20.sys
- OriginalFilename: MRXSMB20.Sys
- ProductVersion: 10.0.16288.1
- FileVersion: 10.0.16288.1 (WinBuild.160101.0800)
- FileDescription: Longhorn SMB 2.0 Redirector
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1c140000 fffff805`1c174000 AMDRyzenMasterDriver (deferred)
- Image path: \??\C:\Program Files\AMD\RyzenMaster\bin\AMDRyzenMasterDriver.sys
- Image name: AMDRyzenMasterDriver.sys
- Timestamp: Tue Mar 28 04:29:24 2017 (58D9D894)
- CheckSum: 0001BACB
- ImageSize: 00034000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`1c180000 fffff805`1c192000 kldisk (deferred)
- Image path: \SystemRoot\system32\DRIVERS\kldisk.sys
- Image name: kldisk.sys
- Timestamp: Fri Dec 25 07:47:51 2015 (567CF4A7)
- CheckSum: 0001E276
- ImageSize: 00012000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`1c1a0000 fffff805`1e6f3000 atikmdag (deferred)
- Image path: \SystemRoot\System32\DriverStore\FileRepository\c0318192.inf_amd64_d0f929f3a19ab987\atikmdag.sys
- Image name: atikmdag.sys
- Timestamp: Tue Sep 19 01:13:58 2017 (59C06146)
- CheckSum: 02505205
- ImageSize: 02553000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`1e700000 fffff805`1e70f000 ndistapi (deferred)
- Mapped memory image file: c:\symbols\ndistapi.sys\66B12A51f000\ndistapi.sys
- Image path: \SystemRoot\System32\DRIVERS\ndistapi.sys
- Image name: ndistapi.sys
- Timestamp: Mon Aug 5 20:38:57 2024 (66B12A51)
- CheckSum: 00009961
- ImageSize: 0000F000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: NDISTAPI.SYS
- OriginalFilename: NDISTAPI.SYS
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: NDIS 3.0 connection wrapper driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1e710000 fffff805`1e72d000 HDAudBus (deferred)
- Mapped memory image file: c:\symbols\HDAudBus.sys\186192D81d000\HDAudBus.sys
- Image path: \SystemRoot\System32\drivers\HDAudBus.sys
- Image name: HDAudBus.sys
- Timestamp: Sat Dec 18 08:22:48 1982 (186192D8)
- CheckSum: 0002097A
- ImageSize: 0001D000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.9 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: hdaudbus.sys
- OriginalFilename: hdaudbus.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: High Definition Audio Bus Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1e730000 fffff805`1e793000 portcls (deferred)
- Mapped memory image file: c:\symbols\portcls.sys\A7AAD0F563000\portcls.sys
- Image path: \SystemRoot\System32\drivers\portcls.sys
- Image name: portcls.sys
- Timestamp: ***** Invalid (A7AAD0F5)
- CheckSum: 0005E584
- ImageSize: 00063000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.9 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: portcls.sys
- OriginalFilename: portcls.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Port Class (Class Driver for Port/Miniport Devices)
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1e7a0000 fffff805`1e7c1000 drmk (deferred)
- Image path: \SystemRoot\System32\drivers\drmk.sys
- Image name: drmk.sys
- Timestamp: Fri Mar 28 09:18:28 2014 (53353E64)
- CheckSum: 00021F69
- ImageSize: 00021000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`1e7d0000 fffff805`1e7f5000 Ndu (deferred)
- Mapped memory image file: c:\symbols\Ndu.sys\59CB3F2125000\Ndu.sys
- Image path: \SystemRoot\system32\drivers\Ndu.sys
- Image name: Ndu.sys
- Timestamp: Wed Sep 27 07:03:13 2017 (59CB3F21)
- CheckSum: 000297EE
- ImageSize: 00025000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: ndu.sys
- OriginalFilename: ndu.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Windows Network Data Usage Monitoring Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1e800000 fffff805`1e80a000 digitalpower (deferred)
- Image path: \SystemRoot\system32\drivers\digitalpower.sys
- Image name: digitalpower.sys
- Timestamp: Thu Sep 10 19:27:32 2015 (55F1CB94)
- CheckSum: 00013314
- ImageSize: 0000A000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`1e830000 fffff805`1e865000 HIDCLASS (deferred)
- Image path: \SystemRoot\System32\drivers\HIDCLASS.SYS
- Image name: HIDCLASS.SYS
- Timestamp: ***** Invalid (A4B57241)
- CheckSum: 0003875B
- ImageSize: 00035000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`1e870000 fffff805`1e883000 HIDPARSE (deferred)
- Mapped memory image file: c:\symbols\HIDPARSE.SYS\3B5CA86C13000\HIDPARSE.SYS
- Image path: \SystemRoot\System32\drivers\HIDPARSE.SYS
- Image name: HIDPARSE.SYS
- Timestamp: Mon Jul 23 23:42:52 2001 (3B5CA86C)
- CheckSum: 00018797
- ImageSize: 00013000
- File version: 10.0.16246.1000
- Product version: 10.0.16246.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: hidparse.sys
- OriginalFilename: hidparse.sys
- ProductVersion: 10.0.16246.1000
- FileVersion: 10.0.16246.1000 (WinBuild.160101.0800)
- FileDescription: Hid Parsing Library
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1e890000 fffff805`1e91c000 UsbHub3 (deferred)
- Mapped memory image file: c:\symbols\UsbHub3.sys\FC3D204E8c000\UsbHub3.sys
- Image path: \SystemRoot\System32\drivers\UsbHub3.sys
- Image name: UsbHub3.sys
- Timestamp: ***** Invalid (FC3D204E)
- CheckSum: 0008FCB7
- ImageSize: 0008C000
- File version: 10.0.16281.1000
- Product version: 10.0.16281.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: usbhub3.sys
- OriginalFilename: usbhub3.sys
- ProductVersion: 10.0.16281.1000
- FileVersion: 10.0.16281.1000 (WinBuild.160101.0800)
- FileDescription: USB3 HUB Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1e920000 fffff805`1e92e000 USBD (deferred)
- Mapped memory image file: c:\symbols\USBD.SYS\638FCB99e000\USBD.SYS
- Image path: \SystemRoot\System32\drivers\USBD.SYS
- Image name: USBD.SYS
- Timestamp: Tue Dec 6 23:09:13 2022 (638FCB99)
- CheckSum: 0000C234
- ImageSize: 0000E000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: usbd.sys
- OriginalFilename: usbd.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Universal Serial Bus Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1e930000 fffff805`1e940000 kbdhid (deferred)
- Mapped memory image file: c:\symbols\kbdhid.sys\30E4F78A10000\kbdhid.sys
- Image path: \SystemRoot\System32\drivers\kbdhid.sys
- Image name: kbdhid.sys
- Timestamp: Sat Dec 30 08:25:46 1995 (30E4F78A)
- CheckSum: 0000EB64
- ImageSize: 00010000
- File version: 10.0.16288.1
- Product version: 10.0.16288.1
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: kbdhid.sys
- OriginalFilename: kbdhid.sys
- ProductVersion: 10.0.16288.1
- FileVersion: 10.0.16288.1 (WinBuild.160101.0800)
- FileDescription: HID Keyboard Filter Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1e940000 fffff805`1e94e000 klkbdflt (deferred)
- Image path: \SystemRoot\system32\DRIVERS\klkbdflt.sys
- Image name: klkbdflt.sys
- Timestamp: Tue Dec 20 22:06:18 2016 (5859AB5A)
- CheckSum: 0001266F
- ImageSize: 0000E000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`1e950000 fffff805`1e963000 kbdclass (deferred)
- Mapped memory image file: c:\symbols\kbdclass.sys\E1050CA813000\kbdclass.sys
- Image path: \SystemRoot\System32\drivers\kbdclass.sys
- Image name: kbdclass.sys
- Timestamp: ***** Invalid (E1050CA8)
- CheckSum: 00018EC4
- ImageSize: 00013000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: kbdclass.sys
- OriginalFilename: kbdclass.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Keyboard Class Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1e970000 fffff805`1e98e000 AtihdWT6 (deferred)
- Image path: \SystemRoot\system32\drivers\AtihdWT6.sys
- Image name: AtihdWT6.sys
- Timestamp: Sat Mar 25 21:04:05 2017 (58D6DB45)
- CheckSum: 00027D44
- ImageSize: 0001E000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`1e9a0000 fffff805`1e9d5000 nvhda64v (deferred)
- Image path: \SystemRoot\system32\drivers\nvhda64v.sys
- Image name: nvhda64v.sys
- Timestamp: Tue May 16 14:02:27 2017 (591AF863)
- CheckSum: 0003F6DE
- ImageSize: 00035000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`1e9e0000 fffff805`1e9f3000 mmcss (deferred)
- Mapped memory image file: c:\symbols\mmcss.sys\6634461413000\mmcss.sys
- Image path: \SystemRoot\system32\drivers\mmcss.sys
- Image name: mmcss.sys
- Timestamp: Fri May 3 03:04:04 2024 (66344614)
- CheckSum: 0000F544
- ImageSize: 00013000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: mmcss.sys
- OriginalFilename: mmcss.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: MMCSS Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1ea00000 fffff805`1ea2f000 usbccgp (deferred)
- Mapped memory image file: c:\symbols\usbccgp.sys\D5E154C62f000\usbccgp.sys
- Image path: \SystemRoot\System32\drivers\usbccgp.sys
- Image name: usbccgp.sys
- Timestamp: ***** Invalid (D5E154C6)
- CheckSum: 00034C1F
- ImageSize: 0002F000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: USBCCGP.SYS
- OriginalFilename: USBCCGP.SYS
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: USB Common Class Generic Parent Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1ea30000 fffff805`1ea7b000 usbvideo (deferred)
- Mapped memory image file: c:\symbols\usbvideo.sys\D45DD7944b000\usbvideo.sys
- Image path: \SystemRoot\System32\Drivers\usbvideo.sys
- Image name: usbvideo.sys
- Timestamp: ***** Invalid (D45DD794)
- CheckSum: 000505C2
- ImageSize: 0004B000
- File version: 10.0.16262.1001
- Product version: 10.0.16262.1001
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.0 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: usbvideo.sys
- OriginalFilename: usbvideo.sys
- ProductVersion: 10.0.16262.1001
- FileVersion: 10.0.16262.1001 (WinBuild.160101.0800)
- FileDescription: USB Video Class Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1ea80000 fffff805`1eaa7000 usbaudio (deferred)
- Mapped memory image file: c:\symbols\usbaudio.sys\21F26F6027000\usbaudio.sys
- Image path: \SystemRoot\system32\drivers\usbaudio.sys
- Image name: usbaudio.sys
- Timestamp: Mon Jan 18 20:32:32 1988 (21F26F60)
- CheckSum: 00025FF6
- ImageSize: 00027000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: USBAudio.sys
- OriginalFilename: USBAudio.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: USB Audio Class Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1eab0000 fffff805`1eabd000 WpdUpFltr (deferred)
- Mapped memory image file: c:\symbols\WpdUpFltr.sys\B911FEB2d000\WpdUpFltr.sys
- Image path: \SystemRoot\System32\drivers\WpdUpFltr.sys
- Image name: WpdUpFltr.sys
- Timestamp: ***** Invalid (B911FEB2)
- CheckSum: 0000E2E6
- ImageSize: 0000D000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.0 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: WpdUpFltr.sys
- OriginalFilename: WpdUpFltr.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Windows Portable Device Upper Class Filter Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1eac0000 fffff805`1ead2000 hidusb (deferred)
- Mapped memory image file: c:\symbols\hidusb.sys\2E8A200F12000\hidusb.sys
- Image path: \SystemRoot\System32\drivers\hidusb.sys
- Image name: hidusb.sys
- Timestamp: Thu Sep 29 03:01:51 1994 (2E8A200F)
- CheckSum: 0001082D
- ImageSize: 00012000
- File version: 10.0.16262.1001
- Product version: 10.0.16262.1001
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: HIDUSB.SYS
- OriginalFilename: HIDUSB.SYS
- ProductVersion: 10.0.16262.1001
- FileVersion: 10.0.16262.1001 (WinBuild.160101.0800)
- FileDescription: USB Miniport Driver for Input Devices
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1eae0000 fffff805`1eaf9000 CorsairGamingAudioamd64 (deferred)
- Image path: \SystemRoot\system32\DRIVERS\CorsairGamingAudioamd64.sys
- Image name: CorsairGamingAudioamd64.sys
- Timestamp: Thu Aug 3 14:51:06 2017 (59832A4A)
- CheckSum: 000197AD
- ImageSize: 00019000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`1eb00000 fffff805`1eb0a000 speedfan (deferred)
- Image path: \??\C:\Windows\SysWOW64\speedfan.sys
- Image name: speedfan.sys
- Timestamp: Sat Dec 29 20:59:35 2012 (50DF59B7)
- CheckSum: 0000CE4F
- ImageSize: 0000A000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`1eb10000 fffff805`1eb1f000 mouhid (deferred)
- Mapped memory image file: c:\symbols\mouhid.sys\25B918D8f000\mouhid.sys
- Image path: \SystemRoot\System32\drivers\mouhid.sys
- Image name: mouhid.sys
- Timestamp: Sun Jan 21 02:05:12 1990 (25B918D8)
- CheckSum: 00009DAF
- ImageSize: 0000F000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: mouhid.sys
- OriginalFilename: mouhid.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: HID Mouse Filter Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1eb20000 fffff805`1eb2f000 klmouflt (deferred)
- Image path: \SystemRoot\system32\DRIVERS\klmouflt.sys
- Image name: klmouflt.sys
- Timestamp: Wed Nov 30 07:58:40 2016 (583E86B0)
- CheckSum: 0000F557
- ImageSize: 0000F000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`1eb30000 fffff805`1eb42000 mouclass (deferred)
- Mapped memory image file: c:\symbols\mouclass.sys\92A73CAB12000\mouclass.sys
- Image path: \SystemRoot\System32\drivers\mouclass.sys
- Image name: mouclass.sys
- Timestamp: ***** Invalid (92A73CAB)
- CheckSum: 00014AD3
- ImageSize: 00012000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: mouclass.sys
- OriginalFilename: mouclass.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Mouse Class Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1eb50000 fffff805`1ebaf000 fastfat (deferred)
- Mapped memory image file: c:\symbols\fastfat.SYS\67829B1C5f000\fastfat.SYS
- Image path: \SystemRoot\System32\Drivers\fastfat.SYS
- Image name: fastfat.SYS
- Timestamp: Sat Jan 11 16:23:56 2025 (67829B1C)
- CheckSum: 0005CBE3
- ImageSize: 0005F000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: fastfat.sys
- OriginalFilename: FastFAT.Sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Fast FAT File System Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1ebc0000 fffff805`1ebcf000 dump_diskdump (deferred)
- Mapped memory image file: c:\symbols\diskdump.sys\988D6CDEf000\diskdump.sys
- Image path: \SystemRoot\System32\Drivers\dump_diskdump.sys
- Image name: dump_diskdump.sys
- Timestamp: ***** Invalid (988D6CDE)
- CheckSum: 00016738
- ImageSize: 0000F000
- File version: 10.0.16262.1001
- Product version: 10.0.16262.1001
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: diskdump.sys
- OriginalFilename: diskdump.sys
- ProductVersion: 10.0.16262.1001
- FileVersion: 10.0.16262.1001 (WinBuild.160101.0800)
- FileDescription: Crash Dump Disk Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1ec00000 fffff805`1ec23000 dump_secnvme (deferred)
- Image path: \SystemRoot\System32\Drivers\dump_secnvme.sys
- Image name: dump_secnvme.sys
- Timestamp: Fri Mar 17 06:03:34 2017 (58CB7C36)
- CheckSum: 00030180
- ImageSize: 00023000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`1ec50000 fffff805`1ec6d000 dump_dumpfve (deferred)
- Mapped memory image file: c:\symbols\dumpfve.sys\C2B56CB91d000\dumpfve.sys
- Image path: \SystemRoot\System32\Drivers\dump_dumpfve.sys
- Image name: dump_dumpfve.sys
- Timestamp: ***** Invalid (C2B56CB9)
- CheckSum: 0001E684
- ImageSize: 0001D000
- File version: 10.0.16262.1001
- Product version: 10.0.16262.1001
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: dumpfve.sys
- OriginalFilename: dumpfve.sys
- ProductVersion: 10.0.16262.1001
- FileVersion: 10.0.16262.1001 (WinBuild.160101.0800)
- FileDescription: Bitlocker Drive Encryption Crashdump Filter
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1ec70000 fffff805`1ec81000 monitor (deferred)
- Mapped memory image file: c:\symbols\monitor.sys\CBD8B93811000\monitor.sys
- Image path: \SystemRoot\System32\drivers\monitor.sys
- Image name: monitor.sys
- Timestamp: ***** Invalid (CBD8B938)
- CheckSum: 0000D8CC
- ImageSize: 00011000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: monitor.sys
- OriginalFilename: monitor.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Monitor Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1ec90000 fffff805`1ec9d000 000 (deferred)
- Image path: \??\C:\Program Files (x86)\CyberLink\PowerDVD17\Common\NavFilter\000.fcl
- Image name: 000.fcl
- Timestamp: Tue Sep 1 07:15:20 2015 (55E54278)
- CheckSum: 0000C388
- ImageSize: 0000D000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`1eca0000 fffff805`1fd07000 nvlddmkm (deferred)
- Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_ref_pubwu.inf_amd64_17a7729c4a220588\nvlddmkm.sys
- Image name: nvlddmkm.sys
- Timestamp: Sun Sep 3 22:34:19 2017 (59AC755B)
- CheckSum: 01012A10
- ImageSize: 01067000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`1fd10000 fffff805`1fd1c000 wmiacpi (deferred)
- Mapped memory image file: c:\symbols\wmiacpi.sys\DE409228c000\wmiacpi.sys
- Image path: \SystemRoot\System32\drivers\wmiacpi.sys
- Image name: wmiacpi.sys
- Timestamp: ***** Invalid (DE409228)
- CheckSum: 0000D824
- ImageSize: 0000C000
- File version: 10.0.16262.1001
- Product version: 10.0.16262.1001
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: wmiacpi.sys
- OriginalFilename: wmiacpi.sys
- ProductVersion: 10.0.16262.1001
- FileVersion: 10.0.16262.1001 (WinBuild.160101.0800)
- FileDescription: Windows Management Interface for ACPI
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1fd20000 fffff805`1fd58000 amdppm (deferred)
- Mapped memory image file: c:\symbols\amdppm.sys\E154DCE338000\amdppm.sys
- Image path: \SystemRoot\System32\drivers\amdppm.sys
- Image name: amdppm.sys
- Timestamp: ***** Invalid (E154DCE3)
- CheckSum: 00031F90
- ImageSize: 00038000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: amdppm.sys
- OriginalFilename: amdppm.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Processor Device Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1fd60000 fffff805`1fd6c000 amdgpio2 (deferred)
- Image path: \SystemRoot\System32\drivers\amdgpio2.sys
- Image name: amdgpio2.sys
- Timestamp: Tue Aug 9 11:05:07 2016 (57A9AAD3)
- CheckSum: 00008F89
- ImageSize: 0000C000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`1fd70000 fffff805`1fd9d000 msgpioclx (deferred)
- Mapped memory image file: c:\symbols\msgpioclx.sys\984DCFE72d000\msgpioclx.sys
- Image path: \SystemRoot\System32\Drivers\msgpioclx.sys
- Image name: msgpioclx.sys
- Timestamp: ***** Invalid (984DCFE7)
- CheckSum: 0002C16F
- ImageSize: 0002D000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: msgpioclx.sys
- OriginalFilename: msgpioclx.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: GPIO Class Extension Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1fda0000 fffff805`1fdaa000 amdgpio3 (deferred)
- Image path: \SystemRoot\System32\drivers\amdgpio3.sys
- Image name: amdgpio3.sys
- Timestamp: Mon Mar 14 10:19:36 2016 (56E69038)
- CheckSum: 00016CD4
- ImageSize: 0000A000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`1fdb0000 fffff805`1fdbd000 UEFI (deferred)
- Mapped memory image file: c:\symbols\UEFI.sys\A89859B3d000\UEFI.sys
- Image path: \SystemRoot\System32\drivers\UEFI.sys
- Image name: UEFI.sys
- Timestamp: ***** Invalid (A89859B3)
- CheckSum: 0000D4DD
- ImageSize: 0000D000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: UEFI.sys
- OriginalFilename: UEFI.sys
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: UEFI Driver for NT
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1fdc0000 fffff805`1fdcd000 NdisVirtualBus (deferred)
- Mapped memory image file: c:\symbols\NdisVirtualBus.sys\74D36D6Ed000\NdisVirtualBus.sys
- Image path: \SystemRoot\System32\drivers\NdisVirtualBus.sys
- Image name: NdisVirtualBus.sys
- Timestamp: Tue Feb 10 08:06:06 2032 (74D36D6E)
- CheckSum: 00009F7A
- ImageSize: 0000D000
- File version: 10.0.16262.1001
- Product version: 10.0.16262.1001
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: NdisVirtualBus.sys
- OriginalFilename: NdisVirtualBus.sys
- ProductVersion: 10.0.16262.1001
- FileVersion: 10.0.16262.1001 (WinBuild.160101.0800)
- FileDescription: Microsoft Virtual Network Adapter Enumerator
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1fdd0000 fffff805`1fddc000 swenum (deferred)
- Mapped memory image file: c:\symbols\swenum.sys\3C18D717c000\swenum.sys
- Image path: \SystemRoot\System32\drivers\swenum.sys
- Image name: swenum.sys
- Timestamp: Thu Dec 13 16:28:07 2001 (3C18D717)
- CheckSum: 00005F7D
- ImageSize: 0000C000
- File version: 10.0.16246.1000
- Product version: 10.0.16246.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.0 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: swenum.sys
- OriginalFilename: swenum.sys
- ProductVersion: 10.0.16246.1000
- FileVersion: 10.0.16246.1000 (WinBuild.160101.0800)
- FileDescription: Plug and Play Software Device Enumerator
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff805`1fde0000 fffff805`1fdee000 CorsairVBusDriver (deferred)
- Image path: \SystemRoot\System32\drivers\CorsairVBusDriver.sys
- Image name: CorsairVBusDriver.sys
- Timestamp: Thu May 25 14:04:01 2017 (5926D641)
- CheckSum: 00019E2A
- ImageSize: 0000E000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff805`1fdf0000 fffff805`1fdfe000 rdpbus (deferred)
- Mapped memory image file: c:\symbols\rdpbus.sys\BF7D986Ce000\rdpbus.sys
- Image path: \SystemRoot\System32\drivers\rdpbus.sys
- Image name: rdpbus.sys
- Timestamp: ***** Invalid (BF7D986C)
- CheckSum: 0000C9F3
- ImageSize: 0000E000
- File version: 10.0.16273.1000
- Product version: 10.0.16273.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.0 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: RDPBUS.SYS
- OriginalFilename: RDPBUS.SYS
- ProductVersion: 10.0.16273.1000
- FileVersion: 10.0.16273.1000 (WinBuild.160101.0800)
- FileDescription: Microsoft RDP Bus Device driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffffb67`f8000000 fffffb67`f8394000 win32kfull (deferred)
- Image path: \SystemRoot\System32\win32kfull.sys
- Image name: win32kfull.sys
- Timestamp: unavailable (00000000)
- CheckSum: 00000000
- ImageSize: 00394000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffffb67`f83a0000 fffffb67`f85b2000 win32kbase (deferred)
- Image path: \SystemRoot\System32\win32kbase.sys
- Image name: win32kbase.sys
- Timestamp: unavailable (00000000)
- CheckSum: 00000000
- ImageSize: 00212000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffffb67`f85d0000 fffffb67`f85da000 TSDDD (deferred)
- Image path: \SystemRoot\System32\TSDDD.dll
- Image name: TSDDD.dll
- Timestamp: unavailable (00000000)
- CheckSum: 00000000
- ImageSize: 0000A000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffffb67`f8730000 fffffb67`f8771000 cdd (deferred)
- Image path: \SystemRoot\System32\cdd.dll
- Image name: cdd.dll
- Timestamp: unavailable (00000000)
- CheckSum: 00000000
- ImageSize: 00041000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffffb67`f88f0000 fffffb67`f8967000 win32k (deferred)
- Image path: \SystemRoot\System32\win32k.sys
- Image name: win32k.sys
- Timestamp: unavailable (00000000)
- CheckSum: 00000000
- ImageSize: 00077000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- Unloaded modules:
- fffff800`2af20000 fffff800`2af2f000 hiber_storpo
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 0000F000
- fffff800`2af30000 fffff800`2af53000 hiber_secnvm
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 00023000
- fffff800`2af60000 fffff800`2af7d000 hiber_dumpfv
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 0001D000
- fffff800`2aed0000 fffff800`2aed9000 optovcm.sys
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 00009000
- fffff800`2aec0000 fffff800`2aec7000 optousb.sys
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 00007000
- fffff800`2ae30000 fffff800`2ae3b000 umpass.sys
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 0000B000
- fffff805`1e990000 fffff805`1e999000 optovcm.sys
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 00009000
- fffff805`1e810000 fffff805`1e817000 optousb.sys
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 00007000
- fffff800`2aea0000 fffff800`2aea7000 magdrvamd64.
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 00007000
- fffff800`2ae90000 fffff800`2ae97000 magdrvamd64.
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 00007000
- fffff800`2ae80000 fffff800`2ae87000 magdrvamd64.
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 00007000
- fffff800`2af60000 fffff800`2af6f000 hiber_storpo
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 0000F000
- fffff800`2af70000 fffff800`2af93000 hiber_secnvm
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 00023000
- fffff800`2afa0000 fffff800`2afbd000 hiber_dumpfv
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 0001D000
- fffff800`2af20000 fffff800`2af2b000 umpass.sys
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 0000B000
- fffff800`2af50000 fffff800`2af57000 magdrvamd64.
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 00007000
- fffff800`2af40000 fffff800`2af47000 magdrvamd64.
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 00007000
- fffff800`2af30000 fffff800`2af37000 magdrvamd64.
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 00007000
- fffff800`2aec0000 fffff800`2aecf000 hiber_storpo
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 0000F000
- fffff800`2aed0000 fffff800`2aef3000 hiber_secnvm
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 00023000
- fffff800`2af00000 fffff800`2af1d000 hiber_dumpfv
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 0001D000
- fffff800`2ae30000 fffff800`2ae3b000 umpass.sys
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 0000B000
- fffff800`2b5b0000 fffff800`2b5d4000 tunnel.sys
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 00024000
- fffff800`2aea0000 fffff800`2aea7000 magdrvamd64.
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 00007000
- fffff800`2ae90000 fffff800`2ae97000 magdrvamd64.
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 00007000
- fffff800`2ae80000 fffff800`2ae87000 magdrvamd64.
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 00007000
- fffff805`1e820000 fffff805`1e829000 CorsairVHidD
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 00009000
- fffff805`16ad0000 fffff805`16afd000 klids.sys
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 0002D000
- fffff805`15e20000 fffff805`15e2f000 dump_storpor
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 0000F000
- fffff805`15e60000 fffff805`15e83000 dump_secnvme
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 00023000
- fffff805`15eb0000 fffff805`15ecd000 dump_dumpfve
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 0001D000
- fffff805`1eb80000 fffff805`1eb9c000 BTHUSB.sys
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 0001C000
- fffff805`1eba0000 fffff805`1ec9f000 bthport.sys
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 000FF000
- fffff805`1eb50000 fffff805`1eb7b000 ibtusb.sys
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 0002B000
- fffff805`1eb00000 fffff805`1eb0b000 klpnpflt.sys
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 0000B000
- fffff805`1eab0000 fffff805`1eabb000 klpnpflt.sys
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 0000B000
- fffff805`1e9f0000 fffff805`1e9fb000 klpnpflt.sys
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 0000B000
- fffff805`1e9e0000 fffff805`1e9eb000 klpnpflt.sys
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 0000B000
- fffff805`1e990000 fffff805`1e99b000 klpnpflt.sys
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 0000B000
- fffff805`1e810000 fffff805`1e81b000 klpnpflt.sys
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 0000B000
- fffff805`1e700000 fffff805`1e70a000 amdkmafd.sys
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 0000A000
- fffff805`16b40000 fffff805`16b59000 dam.sys
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 00019000
- fffff805`144d0000 fffff805`144dc000 klelam.sys
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 0000C000
- fffff805`15d30000 fffff805`15d3f000 hwpolicy.sys
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 0000F000
- 2: kd> q
- quit:
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement