Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Microsoft (R) Windows Debugger Version 10.0.14321.1024 AMD64
- Copyright (c) Microsoft Corporation. All rights reserved.
- ========================================================================
- =================== Dump File: 071717-27828-01.dmp ===================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 15063 MP (4 procs) Free x64
- Product: WinNt, suite: TerminalServer SingleUserTS
- Built by: 15063.0.amd64fre.rs2_release.170317-1834
- Kernel base = 0xfffff803`2ce0d000 PsLoadedModuleList = 0xfffff803`2d1595e0
- Debug session time: Mon Jul 17 04:50:33.602 2017 (UTC - 4:00)
- System Uptime: 0 days 3:28:10.237
- BugCheck 1A, {61948, 1fac62, 1, 1fac62}
- *** WARNING: Unable to verify timestamp for aswStm.sys
- *** ERROR: Module load completed but symbols could not be loaded for aswStm.sys
- Probably caused by : memory_corruption
- Followup: memory_corruption
- 1: kd> !analyze -v
- MEMORY_MANAGEMENT (1a)
- # Any other values for parameter 1 must be individually examined.
- Arguments:
- Arg1: 0000000000061948, The subtype of the bugcheck.
- Arg2: 00000000001fac62
- Arg3: 0000000000000001
- Arg4: 00000000001fac62
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- BUILD_VERSION_STRING: 10.0.15063.483 (WinBuild.160101.0800)
- SYSTEM_MANUFACTURER: ASUS
- SYSTEM_PRODUCT_NAME: All Series
- SYSTEM_SKU: All
- SYSTEM_VERSION: System Version
- BIOS_VENDOR: American Megatrends Inc.
- BIOS_VERSION: 2201
- BIOS_DATE: 06/25/2015
- BASEBOARD_MANUFACTURER: ASUSTeK COMPUTER INC.
- BASEBOARD_PRODUCT: B85M-G R2.0
- BASEBOARD_VERSION: Rev X.0x
- DUMP_TYPE: 2
- BUGCHECK_STR: 0x1a_61948
- CPU_COUNT: 4
- CPU_MHZ: c80
- CPU_VENDOR: GenuineIntel
- CPU_FAMILY: 6
- CPU_MODEL: 3c
- CPU_STEPPING: 3
- CPU_MICROCODE: 6,3c,3,0 (F,M,S,R) SIG: 1E'00000000 (cache) 1E'00000000 (init)
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- PROCESS_NAME: AvastSvc.exe
- CURRENT_IRQL: 2
- ANALYSIS_SESSION_HOST: USERNAME-PC
- ANALYSIS_SESSION_TIME: 07-17-2017 17:10:11.0064
- ANALYSIS_VERSION: 10.0.14321.1024 amd64fre
- LAST_CONTROL_TRANSFER: from fffff8032cfc66de to fffff8032cf794c0
- STACK_TEXT:
- ffff8401`592afec8 fffff803`2cfc66de : 00000000`0000001a 00000000`00061948 00000000`001fac62 00000000`00000001 : nt!KeBugCheckEx
- ffff8401`592afed0 fffff803`2cf9c57b : 00000000`00000000 00000000`00000000 00000000`00000001 00000000`00000001 : nt!MiDereferenceIoPages+0xd578a
- ffff8401`592aff80 fffff803`2ce797b8 : 00000000`00000001 ffffc30d`661dd680 ffff8401`592b0160 00000000`00400201 : nt!MmUnlockPages+0x14c5fb
- ffff8401`592b0060 fffff801`219fa0c2 : 00000000`00000000 ffffc30d`661dd602 00000000`00000000 ffffc30d`641d4020 : nt!IopfCompleteRequest+0x7c8
- ffff8401`592b0190 fffff801`219f695b : 00000000`00000001 00000000`00000000 00000000`00000f4b fffff801`23106f68 : Wdf01000!FxRequest::CompleteInternal+0x242
- ffff8401`592b0250 fffff801`2310c6d4 : ffffc30d`65ac7890 ffffc30d`65ee7390 ffff8401`592b03f0 ffffc30d`63ad0d80 : Wdf01000!imp_WdfRequestCompleteWithInformation+0x9b
- ffff8401`592b02c0 ffffc30d`65ac7890 : ffffc30d`65ee7390 ffff8401`592b03f0 ffffc30d`63ad0d80 00000000`00000000 : aswStm+0x1c6d4
- ffff8401`592b02c8 ffffc30d`65ee7390 : ffff8401`592b03f0 ffffc30d`63ad0d80 00000000`00000000 fffff801`231071f0 : 0xffffc30d`65ac7890
- ffff8401`592b02d0 ffff8401`592b03f0 : ffffc30d`63ad0d80 00000000`00000000 fffff801`231071f0 ffffc30d`65ac7890 : 0xffffc30d`65ee7390
- ffff8401`592b02d8 ffffc30d`63ad0d80 : 00000000`00000000 fffff801`231071f0 ffffc30d`65ac7890 ffffc30d`00000000 : 0xffff8401`592b03f0
- ffff8401`592b02e0 00000000`00000000 : fffff801`231071f0 ffffc30d`65ac7890 ffffc30d`00000000 ffffc30d`6448d780 : 0xffffc30d`63ad0d80
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
- fffff8032ce49cb2 - nt!MmIsSpecialPoolAddress+e
- [ f6:b0 ]
- fffff8032ce49cc4 - nt!MmIsSpecialPoolAddress+20 (+0x12)
- [ f6:b0 ]
- fffff8032cf0c7c8 - nt!MiPteNeedsCommitCharge+48 (+0xc2b04)
- [ f6:b0 ]
- fffff8032cf13389-fffff8032cf1338a 2 bytes - nt!MiModifiedWriterNoReservationSort+9 (+0x6bc1)
- [ 80 fa:00 e6 ]
- fffff8032cf9c646 - nt!MiReleasePtes+14bc46 (+0x892bd)
- [ f6:b0 ]
- 6 errors : !nt (fffff8032ce49cb2-fffff8032cf9c646)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2017-07-17T08:50:33.000Z
- OSBUILD: 15063
- OSSERVICEPACK: 483
- SERVICEPACK_NUMBER: 0
- OS_REVISION: 0
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- OSPLATFORM_TYPE: x64
- OSNAME: Windows 10
- OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
- USER_LCID: 0
- OSBUILD_TIMESTAMP: 2017-07-07 02:06:35
- BUILDDATESTAMP_STR: 160101.0800
- BUILDLAB_STR: WinBuild
- BUILDOSVER_STR: 10.0.15063.483
- ANALYSIS_SESSION_ELAPSED_TIME: bedc
- ANALYSIS_SOURCE: KM
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- 1: kd> q
- quit:
- ========================================================================
- =================== Dump File: 071717-31687-01.dmp ===================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 15063 MP (4 procs) Free x64
- Product: WinNt, suite: TerminalServer SingleUserTS
- Built by: 15063.0.amd64fre.rs2_release.170317-1834
- Kernel base = 0xfffff801`a0a9b000 PsLoadedModuleList = 0xfffff801`a0de75e0
- Debug session time: Sun Jul 16 23:17:51.467 2017 (UTC - 4:00)
- System Uptime: 0 days 0:24:59.103
- BugCheck A, {ffffd605a5f027a0, ff, 0, fffff801a0afca26}
- *** WARNING: Unable to verify timestamp for aswbidsdrivera.sys
- *** ERROR: Module load completed but symbols could not be loaded for aswbidsdrivera.sys
- Probably caused by : aswbidsdrivera.sys ( aswbidsdrivera+14145 )
- Followup: MachineOwner
- 1: kd> !analyze -v
- IRQL_NOT_LESS_OR_EQUAL (a)
- An attempt was made to access a pageable (or completely invalid) address at an
- interrupt request level (IRQL) that is too high. This is usually
- caused by drivers using improper addresses.
- If a kernel debugger is available get the stack backtrace.
- Arguments:
- Arg1: ffffd605a5f027a0, memory referenced
- Arg2: 00000000000000ff, IRQL
- Arg3: 0000000000000000, bitfield :
- bit 0 : value 0 = read operation, 1 = write operation
- bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
- Arg4: fffff801a0afca26, address which referenced memory
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- BUILD_VERSION_STRING: 10.0.15063.483 (WinBuild.160101.0800)
- SYSTEM_MANUFACTURER: ASUS
- SYSTEM_PRODUCT_NAME: All Series
- SYSTEM_SKU: All
- SYSTEM_VERSION: System Version
- BIOS_VENDOR: American Megatrends Inc.
- BIOS_VERSION: 2201
- BIOS_DATE: 06/25/2015
- BASEBOARD_MANUFACTURER: ASUSTeK COMPUTER INC.
- BASEBOARD_PRODUCT: B85M-G R2.0
- BASEBOARD_VERSION: Rev X.0x
- DUMP_TYPE: 2
- READ_ADDRESS: fffff801a0e7c358: Unable to get MiVisibleState
- ffffd605a5f027a0
- CURRENT_IRQL: 0
- FAULTING_IP:
- nt!ExpAcquireResourceSharedLite+c6
- fffff801`a0afca26 894338 mov dword ptr [rbx+38h],eax
- CPU_COUNT: 4
- CPU_MHZ: c80
- CPU_VENDOR: GenuineIntel
- CPU_FAMILY: 6
- CPU_MODEL: 3c
- CPU_STEPPING: 3
- CPU_MICROCODE: 6,3c,3,0 (F,M,S,R) SIG: 1E'00000000 (cache) 1E'00000000 (init)
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
- BUGCHECK_STR: AV
- PROCESS_NAME: AvastSvc.exe
- ANALYSIS_SESSION_HOST: USERNAME-PC
- ANALYSIS_SESSION_TIME: 07-17-2017 17:17:05.0384
- ANALYSIS_VERSION: 10.0.14321.1024 amd64fre
- TRAP_FRAME: ffff9e01c2deabf0 -- (.trap 0xffff9e01c2deabf0)
- NOTE: The trap frame does not contain all registers.
- Some register values may be zeroed or incorrect.
- rax=0000000000000008 rbx=0000000000000000 rcx=0000000000000000
- rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
- rip=fffff801a0afca26 rsp=ffff9e01c2dead80 rbp=ffff9e01c2deadf0
- r8=0000000000000002 r9=000000007f4401fe r10=fffff8016ae00000
- r11=0000000000000001 r12=0000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=0000000000000000
- iopl=0 nv up di pl nz na pe nc
- nt!ExpAcquireResourceSharedLite+0xc6:
- fffff801`a0afca26 894338 mov dword ptr [rbx+38h],eax ds:00000000`00000038=????????
- Resetting default scope
- LAST_CONTROL_TRANSFER: from fffff801a0c128a9 to fffff801a0c074c0
- STACK_TEXT:
- ffff9e01`c2deaaa8 fffff801`a0c128a9 : 00000000`0000000a ffffd605`a5f027a0 00000000`000000ff 00000000`00000000 : nt!KeBugCheckEx
- ffff9e01`c2deaab0 fffff801`a0c10e7d : fffff801`00000000 fffff801`00000001 ffffd605`a6124040 00000000`00000000 : nt!KiBugCheckDispatch+0x69
- ffff9e01`c2deabf0 fffff801`a0afca26 : ffffd605`b4f2cb18 fffff801`a0b07fe9 ffffd605`b4f2cb18 ffffd605`b275b1b0 : nt!KiPageFault+0x23d
- ffff9e01`c2dead80 fffff801`6bbc4145 : 00000001`00000002 ffffd605`a5f02768 00000000`000008d8 00000000`00000000 : nt!ExpAcquireResourceSharedLite+0xc6
- ffff9e01`c2deae20 00000001`00000002 : ffffd605`a5f02768 00000000`000008d8 00000000`00000000 00000000`00000000 : aswbidsdrivera+0x14145
- ffff9e01`c2deae28 ffffd605`a5f02768 : 00000000`000008d8 00000000`00000000 00000000`00000000 fffff801`a0b07107 : 0x00000001`00000002
- ffff9e01`c2deae30 00000000`000008d8 : 00000000`00000000 00000000`00000000 fffff801`a0b07107 00000000`00001001 : 0xffffd605`a5f02768
- ffff9e01`c2deae38 00000000`00000000 : 00000000`00000000 fffff801`a0b07107 00000000`00001001 00000000`00000006 : 0x8d8
- STACK_COMMAND: kb
- THREAD_SHA1_HASH_MOD_FUNC: 6d8f6bb7949b2fc75392bdf042183d1b7890f6f8
- THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 23eaa1a738c949cbf2b3971d2934492e80cfef3d
- THREAD_SHA1_HASH_MOD: 52ed1883575d1d4850f196f6a85e3eaca7e0a68e
- FOLLOWUP_IP:
- aswbidsdrivera+14145
- fffff801`6bbc4145 0fb6d8 movzx ebx,al
- FAULT_INSTR_CODE: 84d8b60f
- SYMBOL_STACK_INDEX: 4
- SYMBOL_NAME: aswbidsdrivera+14145
- FOLLOWUP_NAME: MachineOwner
- MODULE_NAME: aswbidsdrivera
- IMAGE_NAME: aswbidsdrivera.sys
- DEBUG_FLR_IMAGE_TIMESTAMP: 5936d4e0
- BUCKET_ID_FUNC_OFFSET: 14145
- FAILURE_BUCKET_ID: AV_aswbidsdrivera!unknown_function
- BUCKET_ID: AV_aswbidsdrivera!unknown_function
- PRIMARY_PROBLEM_CLASS: AV_aswbidsdrivera!unknown_function
- TARGET_TIME: 2017-07-17T03:17:51.000Z
- OSBUILD: 15063
- OSSERVICEPACK: 483
- SERVICEPACK_NUMBER: 0
- OS_REVISION: 0
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- OSPLATFORM_TYPE: x64
- OSNAME: Windows 10
- OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
- USER_LCID: 0
- OSBUILD_TIMESTAMP: 2017-07-07 02:06:35
- BUILDDATESTAMP_STR: 160101.0800
- BUILDLAB_STR: WinBuild
- BUILDOSVER_STR: 10.0.15063.483
- ANALYSIS_SESSION_ELAPSED_TIME: 72e9
- ANALYSIS_SOURCE: KM
- FAILURE_ID_HASH_STRING: km:av_aswbidsdrivera!unknown_function
- FAILURE_ID_HASH: {de6ddb71-c05a-3939-35d5-62ca51e18f25}
- Followup: MachineOwner
- 1: kd> q
- quit:
- ========================================================================
- =================== Dump File: 071717-30171-01.dmp ===================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 15063 MP (4 procs) Free x64
- Product: WinNt, suite: TerminalServer SingleUserTS
- Built by: 15063.0.amd64fre.rs2_release.170317-1834
- Kernel base = 0xfffff801`3320e000 PsLoadedModuleList = 0xfffff801`3355a5e0
- Debug session time: Mon Jul 17 01:21:42.007 2017 (UTC - 4:00)
- System Uptime: 0 days 2:03:10.642
- BugCheck 3B, {c0000005, fffff80133218e58, ffffbc006c0dea20, 0}
- Probably caused by : memory_corruption
- Followup: memory_corruption
- 1: kd> !analyze -v
- SYSTEM_SERVICE_EXCEPTION (3b)
- An exception happened while executing a system service routine.
- Arguments:
- Arg1: 00000000c0000005, Exception code that caused the bugcheck
- Arg2: fffff80133218e58, Address of the instruction which caused the bugcheck
- Arg3: ffffbc006c0dea20, Address of the context record for the exception that caused the bugcheck
- Arg4: 0000000000000000, zero.
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- BUILD_VERSION_STRING: 10.0.15063.483 (WinBuild.160101.0800)
- SYSTEM_MANUFACTURER: ASUS
- SYSTEM_PRODUCT_NAME: All Series
- SYSTEM_SKU: All
- SYSTEM_VERSION: System Version
- BIOS_VENDOR: American Megatrends Inc.
- BIOS_VERSION: 2201
- BIOS_DATE: 06/25/2015
- BASEBOARD_MANUFACTURER: ASUSTeK COMPUTER INC.
- BASEBOARD_PRODUCT: B85M-G R2.0
- BASEBOARD_VERSION: Rev X.0x
- DUMP_TYPE: 2
- EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.
- FAULTING_IP:
- nt!MiDecrementCombinedPte+20
- fffff801`33218e58 488b4810 mov rcx,qword ptr [rax+10h]
- CONTEXT: ffffbc006c0dea20 -- (.cxr 0xffffbc006c0dea20)
- rax=7ffffffffffff000 rbx=0000000000000004 rcx=8000000000000000
- rdx=ffffffffffffffff rsi=8000000000000000 rdi=0000000000000000
- rip=fffff80133218e58 rsp=ffffbc006c0df410 rbp=ffffbc006c0df540
- r8=3fffffffffffffff r9=0000000000000003 r10=00000000001fdb2b
- r11=0000007ffffffff8 r12=8000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=fffffc000252b940
- iopl=0 nv up ei ng nz na po nc
- cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010286
- nt!MiDecrementCombinedPte+0x20:
- fffff801`33218e58 488b4810 mov rcx,qword ptr [rax+10h] ds:002b:7fffffff`fffff010=????????????????
- Resetting default scope
- CPU_COUNT: 4
- CPU_MHZ: c80
- CPU_VENDOR: GenuineIntel
- CPU_FAMILY: 6
- CPU_MODEL: 3c
- CPU_STEPPING: 3
- CPU_MICROCODE: 6,3c,3,0 (F,M,S,R) SIG: 1E'00000000 (cache) 1E'00000000 (init)
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- BUGCHECK_STR: 0x3B
- PROCESS_NAME: Battle.net.exe
- CURRENT_IRQL: 2
- ANALYSIS_SESSION_HOST: USERNAME-PC
- ANALYSIS_SESSION_TIME: 07-17-2017 17:15:09.0963
- ANALYSIS_VERSION: 10.0.14321.1024 amd64fre
- LAST_CONTROL_TRANSFER: from fffff801332a3319 to fffff80133218e58
- STACK_TEXT:
- ffffbc00`6c0df410 fffff801`332a3319 : ffffaa8c`00000000 00000000`00000004 ffffcd00`0005c2b0 ffffcd00`0005c2b0 : nt!MiDecrementCombinedPte+0x20
- ffffbc00`6c0df440 fffff801`33292cc2 : ffffcd00`0005c3f0 ffffcd00`0005c280 00000000`0000009f 00000000`0000000f : nt!MiDeletePteRun+0x5d9
- ffffbc00`6c0df5b0 fffff801`3328d5bd : ffffaa8c`73d8fd88 ffffaa8c`731977c0 ffffaa8c`73d8fd88 ffffaa8c`73d8f7c0 : nt!MiDeleteVirtualAddresses+0x972
- ffffbc00`6c0df860 fffff801`336c289c : 00000000`0b850000 ffffaa8c`7fbe4010 00000000`6ff04230 00000000`00000000 : nt!MiDeleteVad+0x3ad
- ffffbc00`6c0df9e0 fffff801`337389c6 : ffffaa8c`73d8f7c0 00000000`00000008 ffffaa8c`7281ec40 00000000`0b850000 : nt!MiUnmapViewOfSection+0xec
- ffffbc00`6c0dfab0 fffff801`33385413 : ffffaa8c`731977c0 00000000`00000000 00000000`00000000 ffffaa8c`73d8f7c0 : nt!NtUnmapViewOfSectionEx+0x86
- ffffbc00`6c0dfb00 00007ff9`87ee8b54 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
- 00000000`08ade5b8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff9`87ee8b54
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
- fffff801332180f6-fffff801332180f7 2 bytes - nt!MiGetWorkingSetInfoList+4a6
- [ 80 f6:00 cd ]
- fffff80133218157-fffff80133218158 2 bytes - nt!MiGetWorkingSetInfoList+507 (+0x61)
- [ 80 f6:00 cd ]
- fffff801332182f9-fffff801332182fb 3 bytes - nt!MiGetWorkingSetInfoList+6a9 (+0x1a2)
- [ 40 fb f6:80 66 cd ]
- fffff801332183f4-fffff801332183f5 2 bytes - nt!MiGetWorkingSetInfoList+7a4 (+0xfb)
- [ 80 fa:00 fc ]
- fffff801332184be-fffff801332184bf 2 bytes - nt!MiGetWorkingSetInfoList+86e (+0xca)
- [ 80 fa:00 fc ]
- fffff80133218817-fffff80133218818 2 bytes - nt!MiRevokeExecutePte+27 (+0x359)
- [ 80 f6:00 cd ]
- fffff80133218869-fffff8013321886a 2 bytes - nt!MiRevokeExecutePte+79 (+0x52)
- [ 80 fa:00 fc ]
- fffff801332188be-fffff801332188bf 2 bytes - nt!MiQueryLeafPte+1e (+0x55)
- [ 80 f6:00 cd ]
- fffff8013321890e-fffff8013321890f 2 bytes - nt!MiQueryLeafPte+6e (+0x50)
- [ 80 fa:00 fc ]
- fffff80133218a1d-fffff80133218a1e 2 bytes - nt!MiQueryLeafPte+17d (+0x10f)
- [ ff f6:7f cd ]
- fffff80133218b0b-fffff80133218b0c 2 bytes - nt!MiLockProtoPage+4f (+0xee)
- [ 80 f6:00 cd ]
- fffff80133218b32-fffff80133218b33 2 bytes - nt!MiLockProtoPage+76 (+0x27)
- [ 80 fa:00 fc ]
- fffff80133218bd1-fffff80133218bd2 2 bytes - nt!MiQueryPfn+15 (+0x9f)
- [ 80 fa:00 fc ]
- fffff80133218c6e-fffff80133218c6f 2 bytes - nt!MiMakeProtoAddressValid+3a (+0x9d)
- [ 80 f6:00 cd ]
- fffff80133218cc4-fffff80133218cc5 2 bytes - nt!MiMakeProtoAddressValid+90 (+0x56)
- [ 80 fa:00 fc ]
- fffff80133292cef-fffff80133292cf0 2 bytes - nt!MiDeleteVirtualAddresses+99f (+0x7a02b)
- [ 80 f6:00 cd ]
- fffff8013329f07a-fffff8013329f07b 2 bytes - nt!MiResolvePrivateZeroFault+27a (+0xc38b)
- [ 80 f6:00 cd ]
- fffff8013329f0b0-fffff8013329f0b2 3 bytes - nt!MiResolvePrivateZeroFault+2b0 (+0x36)
- [ 40 fb f6:80 66 cd ]
- fffff8013329f0d8-fffff8013329f0d9 2 bytes - nt!MiResolvePrivateZeroFault+2d8 (+0x28)
- [ 80 fa:00 fc ]
- fffff8013329fb53-fffff8013329fb54 2 bytes - nt!MiGetPage+a3 (+0xa7b)
- [ 80 fa:00 fc ]
- fffff8013329fcc2-fffff8013329fcc3 2 bytes - nt!MiGetFreeOrZeroPage+72 (+0x16f)
- [ 80 fa:00 fc ]
- fffff801332a3410-fffff801332a3411 2 bytes - nt!MiDeletePteRun+6d0 (+0x374e)
- [ 80 f6:00 cd ]
- fffff801332a3a80-fffff801332a3a81 2 bytes - nt!MiInsertPageInFreeOrZeroedList+20 (+0x670)
- [ 80 fa:00 fc ]
- 48 errors : !nt (fffff801332180f6-fffff801332a3a81)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- STACK_COMMAND: .cxr 0xffffbc006c0dea20 ; kb
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2017-07-17T05:21:42.000Z
- OSBUILD: 15063
- OSSERVICEPACK: 483
- SERVICEPACK_NUMBER: 0
- OS_REVISION: 0
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- OSPLATFORM_TYPE: x64
- OSNAME: Windows 10
- OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
- USER_LCID: 0
- OSBUILD_TIMESTAMP: 2017-07-07 02:06:35
- BUILDDATESTAMP_STR: 160101.0800
- BUILDLAB_STR: WinBuild
- BUILDOSVER_STR: 10.0.15063.483
- ANALYSIS_SESSION_ELAPSED_TIME: 1ab3
- ANALYSIS_SOURCE: KM
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- 1: kd> q
- quit:
- ========================================================================
- =================== Dump File: 071717-29500-01.dmp ===================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 15063 MP (4 procs) Free x64
- Product: WinNt, suite: TerminalServer SingleUserTS
- Built by: 15063.0.amd64fre.rs2_release.170317-1834
- Kernel base = 0xfffff803`5e60a000 PsLoadedModuleList = 0xfffff803`5e9565e0
- Debug session time: Mon Jul 17 15:18:02.922 2017 (UTC - 4:00)
- System Uptime: 0 days 1:47:15.558
- BugCheck 1A, {41201, ffff8d3ffbf86398, 1fc454025, ffff908e7176fd90}
- Probably caused by : memory_corruption ( nt!MiGetPageProtection+1183bf )
- Followup: MachineOwner
- 1: kd> !analyze -v
- MEMORY_MANAGEMENT (1a)
- # Any other values for parameter 1 must be individually examined.
- Arguments:
- Arg1: 0000000000041201, The subtype of the bugcheck.
- Arg2: ffff8d3ffbf86398
- Arg3: 00000001fc454025
- Arg4: ffff908e7176fd90
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- BUILD_VERSION_STRING: 10.0.15063.483 (WinBuild.160101.0800)
- SYSTEM_MANUFACTURER: ASUS
- SYSTEM_PRODUCT_NAME: All Series
- SYSTEM_SKU: All
- SYSTEM_VERSION: System Version
- BIOS_VENDOR: American Megatrends Inc.
- BIOS_VERSION: 2201
- BIOS_DATE: 06/25/2015
- BASEBOARD_MANUFACTURER: ASUSTeK COMPUTER INC.
- BASEBOARD_PRODUCT: B85M-G R2.0
- BASEBOARD_VERSION: Rev X.0x
- DUMP_TYPE: 2
- BUGCHECK_STR: 0x1a_41201
- CPU_COUNT: 4
- CPU_MHZ: c80
- CPU_VENDOR: GenuineIntel
- CPU_FAMILY: 6
- CPU_MODEL: 3c
- CPU_STEPPING: 3
- CPU_MICROCODE: 6,3c,3,0 (F,M,S,R) SIG: 1E'00000000 (cache) 1E'00000000 (init)
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
- PROCESS_NAME: sppsvc.exe
- CURRENT_IRQL: 2
- ANALYSIS_SESSION_HOST: USERNAME-PC
- ANALYSIS_SESSION_TIME: 07-17-2017 17:13:43.0877
- ANALYSIS_VERSION: 10.0.14321.1024 amd64fre
- LAST_CONTROL_TRANSFER: from fffff8035e7aa64f to fffff8035e7764c0
- STACK_TEXT:
- ffffbc80`c3bf4b58 fffff803`5e7aa64f : 00000000`0000001a 00000000`00041201 ffff8d3f`fbf86398 00000001`fc454025 : nt!KeBugCheckEx
- ffffbc80`c3bf4b60 fffff803`5e691ae3 : ffff8d3f`fbf86398 00000000`00001000 00000001`fc454025 00000000`00000000 : nt!MiGetPageProtection+0x1183bf
- ffffbc80`c3bf4bb0 fffff803`5e69163e : 00007ff7`00000000 ffffa707`fa519900 ffffbc80`00000000 ffff908e`652efcc0 : nt!MiQueryAddressState+0x2b3
- ffffbc80`c3bf4c40 fffff803`5ea9701f : 00000000`00000003 00000000`00000001 00000000`00000003 00007ff7`f0c73000 : nt!MiQueryAddressSpan+0x12e
- ffffbc80`c3bf4cf0 fffff803`5ea968c1 : 00000000`00000000 00000000`00000201 00000000`00000000 00000000`00000000 : nt!MmQueryVirtualMemory+0x74f
- ffffbc80`c3bf4e50 fffff803`5e781413 : 00000000`00000000 00000000`00000008 ffffbc80`c5abe820 00000000`00000001 : nt!NtQueryVirtualMemory+0x25
- ffffbc80`c3bf4ea0 fffff803`5e7796a0 : fffff803`5ead1ecb ffff085c`a2af8e91 000000aa`0000000a ffffbc80`c5abe820 : nt!KiSystemServiceCopyEnd+0x13
- ffffbc80`c3bf50a8 fffff803`5ead1ecb : ffff085c`a2af8e91 000000aa`0000000a ffffbc80`c5abe820 00007ff7`f0c33820 : nt!KiServiceLinkage
- ffffbc80`c3bf50b0 fffff803`5ead41a5 : ffffa707`fa3847f0 ffffa707`fa3847f0 ffffa707`fb37d0f4 00007ff7`f0c33820 : nt!WbCreateHeapExecutedBlock+0x37b
- ffffbc80`c3bf5120 fffff803`5ead4343 : ffffa707`fa3847f0 00000000`00000000 ffffbc80`c3bf5b80 00000000`00000000 : nt!WbMakeUserDataPagesKernelWritable+0x209
- ffffbc80`c3bf51b0 fffff803`5eb44606 : ffffffff`ffffffff ffff908e`64658ae0 00000000`00000000 ffffa707`00000000 : nt!WbMakeUserDataPagesKernelWritable+0x3a7
- ffffbc80`c3bf51e0 fffff803`5ead20e9 : 00000000`00000001 00000025`3d37d7d0 00000000`00000000 ffffa707`fa3847f0 : nt!WbDecryptEncryptionSegment+0x7a
- ffffbc80`c3bf5210 fffff803`5eab5b9f : ffffa707`f3446790 ffffbc80`c3bf54e0 ffffa707`f5ae3a80 00000000`00000000 : nt!WbDispatchOperation+0x1d9
- ffffbc80`c3bf5280 fffff803`5eab57fb : 00000025`3d37f701 ffff908e`65324100 00007ff9`dfc39c20 00000025`3d37e260 : nt!ExpQuerySystemInformation+0x27f
- ffffbc80`c3bf5ac0 fffff803`5e781413 : ffff908e`646587c0 00000000`00000000 00000000`00000000 00007ff9`dfc34c20 : nt!NtQuerySystemInformation+0x2b
- ffffbc80`c3bf5b00 00007ff9`f0545a64 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
- 00000025`3d37d7a8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff9`f0545a64
- STACK_COMMAND: kb
- THREAD_SHA1_HASH_MOD_FUNC: 95cf5ae0ca1e8a6c94eeccc5f29c74d552895889
- THREAD_SHA1_HASH_MOD_FUNC_OFFSET: d382c80ea6fa0a1e714435cd189513fc9d00bded
- THREAD_SHA1_HASH_MOD: 9eef8c7ca0ce66f8b8b34848179f303828cff762
- FOLLOWUP_IP:
- nt!MiGetPageProtection+1183bf
- fffff803`5e7aa64f cc int 3
- FAULT_INSTR_CODE: a88d49cc
- SYMBOL_STACK_INDEX: 1
- SYMBOL_NAME: nt!MiGetPageProtection+1183bf
- FOLLOWUP_NAME: MachineOwner
- MODULE_NAME: nt
- DEBUG_FLR_IMAGE_TIMESTAMP: 595f24eb
- IMAGE_VERSION: 10.0.15063.483
- IMAGE_NAME: memory_corruption
- BUCKET_ID_FUNC_OFFSET: 1183bf
- FAILURE_BUCKET_ID: 0x1a_41201_nt!MiGetPageProtection
- BUCKET_ID: 0x1a_41201_nt!MiGetPageProtection
- PRIMARY_PROBLEM_CLASS: 0x1a_41201_nt!MiGetPageProtection
- TARGET_TIME: 2017-07-17T19:18:02.000Z
- OSBUILD: 15063
- OSSERVICEPACK: 483
- SERVICEPACK_NUMBER: 0
- OS_REVISION: 0
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- OSPLATFORM_TYPE: x64
- OSNAME: Windows 10
- OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
- USER_LCID: 0
- OSBUILD_TIMESTAMP: 2017-07-07 02:06:35
- BUILDDATESTAMP_STR: 160101.0800
- BUILDLAB_STR: WinBuild
- BUILDOSVER_STR: 10.0.15063.483
- ANALYSIS_SESSION_ELAPSED_TIME: 1f8e
- ANALYSIS_SOURCE: KM
- FAILURE_ID_HASH_STRING: km:0x1a_41201_nt!migetpageprotection
- FAILURE_ID_HASH: {c1fe3b27-3ba8-d99e-656f-85f3d58dc669}
- Followup: MachineOwner
- 1: kd> q
- quit:
- ========================================================================
- =================== Dump File: 071717-28296-01.dmp ===================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 15063 MP (4 procs) Free x64
- Product: WinNt, suite: TerminalServer SingleUserTS
- Built by: 15063.0.amd64fre.rs2_release.170317-1834
- Kernel base = 0xfffff801`87a12000 PsLoadedModuleList = 0xfffff801`87d5e5e0
- Debug session time: Mon Jul 17 13:29:48.569 2017 (UTC - 4:00)
- System Uptime: 0 days 8:34:30.204
- BugCheck 4E, {99, 1fbb51, 0, 0}
- *** WARNING: Unable to verify timestamp for win32k.sys
- *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
- Probably caused by : memory_corruption
- Followup: memory_corruption
- 1: kd> !analyze -v
- PFN_LIST_CORRUPT (4e)
- Typically caused by drivers passing bad memory descriptor lists (ie: calling
- MmUnlockPages twice with the same list, etc). If a kernel debugger is
- available get the stack trace.
- Arguments:
- Arg1: 0000000000000099, A PTE or PFN is corrupt
- Arg2: 00000000001fbb51, page frame number
- Arg3: 0000000000000000, current page state
- Arg4: 0000000000000000, 0
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- BUILD_VERSION_STRING: 10.0.15063.483 (WinBuild.160101.0800)
- SYSTEM_MANUFACTURER: ASUS
- SYSTEM_PRODUCT_NAME: All Series
- SYSTEM_SKU: All
- SYSTEM_VERSION: System Version
- BIOS_VENDOR: American Megatrends Inc.
- BIOS_VERSION: 2201
- BIOS_DATE: 06/25/2015
- BASEBOARD_MANUFACTURER: ASUSTeK COMPUTER INC.
- BASEBOARD_PRODUCT: B85M-G R2.0
- BASEBOARD_VERSION: Rev X.0x
- DUMP_TYPE: 2
- BUGCHECK_STR: 0x4E_99
- CPU_COUNT: 4
- CPU_MHZ: c80
- CPU_VENDOR: GenuineIntel
- CPU_FAMILY: 6
- CPU_MODEL: 3c
- CPU_STEPPING: 3
- CPU_MICROCODE: 6,3c,3,0 (F,M,S,R) SIG: 1E'00000000 (cache) 1E'00000000 (init)
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- PROCESS_NAME: chrome.exe
- CURRENT_IRQL: 2
- ANALYSIS_SESSION_HOST: USERNAME-PC
- ANALYSIS_SESSION_TIME: 07-17-2017 17:12:28.0860
- ANALYSIS_VERSION: 10.0.14321.1024 amd64fre
- LAST_CONTROL_TRANSFER: from fffff80187ba2960 to fffff80187b7e4c0
- STACK_TEXT:
- ffffce80`91e91fe8 fffff801`87ba2960 : 00000000`0000004e 00000000`00000099 00000000`001fbb51 00000000`00000000 : nt!KeBugCheckEx
- ffffce80`91e91ff0 fffff801`87a61dae : 00000000`00000000 ffffce80`91e920d0 ffffccd3`0000001f ffffb70a`ded10811 : nt!MiDecrementShareCount+0x145090
- ffffce80`91e92030 fffff801`87e9c1b1 : ffffb70a`da055080 ffffb70a`ddb3dc18 00000000`00b00000 00000000`00000000 : nt!MmUnmapViewInSystemCache+0x6ee
- ffffce80`91e92320 fffff801`87a63026 : 00000000`00b00000 ffffb70a`ca1f1f10 00000000`01280000 00000000`00000001 : nt!CcUnmapVacb+0x9d
- ffffce80`91e92360 fffff801`87a56ce0 : 00000000`00000001 00000000`00400000 00000000`00000001 00000000`00040000 : nt!CcUnmapVacbArray+0x156
- ffffce80`91e923d0 fffff801`87e9b3b9 : 00000000`00000000 00000000`00000000 ffffce80`91e92500 ffffce80`91e92510 : nt!CcGetVirtualAddress+0x2f0
- ffffce80`91e92460 fffff801`87a563cb : 00000000`00000000 00000000`00c00000 00000000`00000e00 fffff804`0c88ad01 : nt!CcMapAndCopyFromCache+0x79
- ffffce80`91e92500 fffff804`0c94d135 : ffffce80`91e92610 ffffce80`00000000 ffffb70a`00001000 ffffe202`e5d0d150 : nt!CcCopyReadEx+0x12b
- ffffce80`91e92590 fffff804`0bf85e3e : 00000000`00000190 00000000`00000000 ffffb70a`cb936950 0000021d`388f2d10 : NTFS!NtfsCopyReadA+0x235
- ffffce80`91e92830 fffff804`0bf8331d : ffffce80`91e92920 ffffb70a`cb936900 ffffb70a`ca99cb78 ffffb70a`ca99ca80 : FLTMGR!FltpPerformFastIoCall+0x13e
- ffffce80`91e92890 fffff804`0bfb5da9 : 00000000`00000001 00000000`00000001 00000000`00000000 00000000`00000006 : FLTMGR!FltpPassThroughFastIo+0xbd
- ffffce80`91e928f0 fffff801`87ea71fd : ffffb70a`cb936950 00000000`00000001 00000000`00000000 ffffb70a`cb936950 : FLTMGR!FltpFastIoRead+0x159
- ffffce80`91e92990 fffff801`87b89413 : ffffcce6`40874ec8 00000000`00000000 00000000`00000000 00000000`00000000 : nt!NtReadFile+0x43d
- ffffce80`91e92a90 00007ffa`f2055464 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
- 000000ab`877fe578 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffa`f2055464
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -db !nt
- 2 errors : !nt (fffff80187ba2979-fffff80187ba29b1)
- fffff80187ba2970 24 70 49 b9 00 00 00 00 80 *cc ff ff e9 c3 b0 eb $pI.............
- fffff80187ba29b0 80 *cc ff ff e9 ab b0 eb ff cc 4c 8b c3 48 89 44 ..........L..H.D
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: STRIDE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_STRIDE
- BUCKET_ID: MEMORY_CORRUPTION_STRIDE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_STRIDE
- TARGET_TIME: 2017-07-17T17:29:48.000Z
- OSBUILD: 15063
- OSSERVICEPACK: 483
- SERVICEPACK_NUMBER: 0
- OS_REVISION: 0
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- OSPLATFORM_TYPE: x64
- OSNAME: Windows 10
- OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
- USER_LCID: 0
- OSBUILD_TIMESTAMP: 2017-07-07 02:06:35
- BUILDDATESTAMP_STR: 160101.0800
- BUILDLAB_STR: WinBuild
- BUILDOSVER_STR: 10.0.15063.483
- ANALYSIS_SESSION_ELAPSED_TIME: 1a86
- ANALYSIS_SOURCE: KM
- FAILURE_ID_HASH_STRING: km:memory_corruption_stride
- FAILURE_ID_HASH: {574dbc1b-92cb-fb09-cb7a-cacc1bb2c511}
- Followup: memory_corruption
- 1: kd> q
- quit:
- ========================================================================
- =================== Dump File: 071617-33296-01.dmp ===================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 15063 MP (4 procs) Free x64
- Product: WinNt, suite: TerminalServer SingleUserTS
- Built by: 15063.0.amd64fre.rs2_release.170317-1834
- Kernel base = 0xfffff803`3cc1b000 PsLoadedModuleList = 0xfffff803`3cf675e0
- Debug session time: Sun Jul 16 22:52:06.408 2017 (UTC - 4:00)
- System Uptime: 0 days 3:47:19.054
- BugCheck 1A, {41201, ffff83bffb6c7b68, 1fc90d025, ffffad0a53e7b540}
- Probably caused by : memory_corruption
- Followup: memory_corruption
- 1: kd> !analyze -v
- MEMORY_MANAGEMENT (1a)
- # Any other values for parameter 1 must be individually examined.
- Arguments:
- Arg1: 0000000000041201, The subtype of the bugcheck.
- Arg2: ffff83bffb6c7b68
- Arg3: 00000001fc90d025
- Arg4: ffffad0a53e7b540
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- BUILD_VERSION_STRING: 10.0.15063.483 (WinBuild.160101.0800)
- SYSTEM_MANUFACTURER: ASUS
- SYSTEM_PRODUCT_NAME: All Series
- SYSTEM_SKU: All
- SYSTEM_VERSION: System Version
- BIOS_VENDOR: American Megatrends Inc.
- BIOS_VERSION: 2201
- BIOS_DATE: 06/25/2015
- BASEBOARD_MANUFACTURER: ASUSTeK COMPUTER INC.
- BASEBOARD_PRODUCT: B85M-G R2.0
- BASEBOARD_VERSION: Rev X.0x
- DUMP_TYPE: 2
- BUGCHECK_STR: 0x1a_41201
- CPU_COUNT: 4
- CPU_MHZ: c80
- CPU_VENDOR: GenuineIntel
- CPU_FAMILY: 6
- CPU_MODEL: 3c
- CPU_STEPPING: 3
- CPU_MICROCODE: 6,3c,3,0 (F,M,S,R) SIG: 1E'00000000 (cache) 1E'00000000 (init)
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- PROCESS_NAME: SppExtComObj.Exe
- CURRENT_IRQL: 2
- ANALYSIS_SESSION_HOST: USERNAME-PC
- ANALYSIS_SESSION_TIME: 07-17-2017 17:08:05.0455
- ANALYSIS_VERSION: 10.0.14321.1024 amd64fre
- LAST_CONTROL_TRANSFER: from fffff8033cdbb64f to fffff8033cd874c0
- STACK_TEXT:
- ffffdb00`29a64b68 fffff803`3cdbb64f : 00000000`0000001a 00000000`00041201 ffff83bf`fb6c7b68 00000001`fc90d025 : nt!KeBugCheckEx
- ffffdb00`29a64b70 fffff803`3cca2ae3 : ffff83bf`fb6c7b68 00000000`00001000 00000001`fc90d025 fffff803`3ccdad73 : nt!MiGetPageProtection+0x1183bf
- ffffdb00`29a64bc0 fffff803`3cca263e : 00000000`00000000 ffffdb00`29a65000 00000000`00000000 ffffad0a`55738a00 : nt!MiQueryAddressState+0x2b3
- ffffdb00`29a64c50 fffff803`3d0a801f : 00000000`00000003 00000000`00000001 00000000`00000003 00007ff6`d8f6d000 : nt!MiQueryAddressSpan+0x12e
- ffffdb00`29a64d00 fffff803`3d0a78c1 : 0000007f`0000000d 00000027`0000003f 00000053`0000000a 00000094`00000063 : nt!MmQueryVirtualMemory+0x74f
- ffffdb00`29a64e60 fffff803`3cd92413 : 00000000`00000000 00000000`00000008 00000000`0fffffff 00000000`00000001 : nt!NtQueryVirtualMemory+0x25
- ffffdb00`29a64eb0 fffff803`3cd8a6a0 : fffff803`3d0e2ecb ffff5883`831d5986 00000030`00000005 00000000`0fffffff : nt!KiSystemServiceCopyEnd+0x13
- ffffdb00`29a650b8 fffff803`3d0e2ecb : ffff5883`831d5986 00000030`00000005 00000000`0fffffff 00000000`00000030 : nt!KiServiceLinkage
- ffffdb00`29a650c0 fffff803`3d0e4e84 : ffff9780`91720954 00007ff6`d8f467d0 00000000`00000000 00000000`00000030 : nt!WbCreateHeapExecutedBlock+0x37b
- ffffdb00`29a65130 fffff803`3d0e5125 : 00000000`000000c3 00000000`00000000 00000000`00000000 0000002f`22f9d7a0 : nt!PspApplyJobLimitsToProcess+0x158
- ffffdb00`29a651b0 fffff803`3d1556ce : ffffffff`ffffffff ffffdb00`29a65b80 00000000`00000000 ffff9780`00000000 : nt!WbMakeUserDataPagesKernelWritable+0x189
- ffffdb00`29a651e0 fffff803`3d0e30cf : 00000000`00000001 0000002f`22f9d7a0 00000000`00000000 ffff9780`81f89230 : nt!WbReEncryptEncryptionSegment+0x7a
- ffffdb00`29a65210 fffff803`3d0c6b9f : ffff9780`92f21c50 00000000`00000000 ffff9780`864f4a40 00000000`00000000 : nt!WbDispatchOperation+0x1bf
- ffffdb00`29a65280 fffff803`3d0c67fb : 00000000`5d46b711 00007ff6`d8f78a80 00000000`00000000 fedbc51e`e5bf6b35 : nt!ExpQuerySystemInformation+0x27f
- ffffdb00`29a65ac0 fffff803`3cd92413 : ffffad0a`53f72040 00000000`00000000 00000000`00000000 00007ebf`97807864 : nt!NtQuerySystemInformation+0x2b
- ffffdb00`29a65b00 00007ffc`363b5a64 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
- 0000002f`22f9d778 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffc`363b5a64
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
- fffff8033ce9b383-fffff8033ce9b385 3 bytes - nt!ExFreePoolWithTag+363
- [ 40 fb f6:c0 c1 83 ]
- 3 errors : !nt (fffff8033ce9b383-fffff8033ce9b385)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2017-07-17T02:52:06.000Z
- OSBUILD: 15063
- OSSERVICEPACK: 483
- SERVICEPACK_NUMBER: 0
- OS_REVISION: 0
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- OSPLATFORM_TYPE: x64
- OSNAME: Windows 10
- OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
- USER_LCID: 0
- OSBUILD_TIMESTAMP: 2017-07-07 02:06:35
- BUILDDATESTAMP_STR: 160101.0800
- BUILDLAB_STR: WinBuild
- BUILDOSVER_STR: 10.0.15063.483
- ANALYSIS_SESSION_ELAPSED_TIME: 1b29
- ANALYSIS_SOURCE: KM
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- 1: kd> lmv
- start end module name
- fffff2a5`29800000 fffff2a5`29b93000 win32kfull (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\win32kfull.sys\41105314393000\win32kfull.sys
- Image path: \SystemRoot\System32\win32kfull.sys
- Image name: win32kfull.sys
- Timestamp: Tue Aug 3 23:08:04 2004 (41105314)
- CheckSum: 003844BB
- ImageSize: 00393000
- File version: 10.0.15063.478
- Product version: 10.0.15063.478
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: win32kfull.sys
- OriginalFilename: win32kfull.sys
- ProductVersion: 10.0.15063.478
- FileVersion: 10.0.15063.478 (WinBuild.160101.0800)
- FileDescription: Full/Desktop Win32k Kernel Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff2a5`29ba0000 fffff2a5`29da6000 win32kbase (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\win32kbase.sys\2CDDD6B0206000\win32kbase.sys
- Image path: \SystemRoot\System32\win32kbase.sys
- Image name: win32kbase.sys
- Timestamp: Mon Nov 8 00:18:40 1993 (2CDDD6B0)
- CheckSum: 001F783B
- ImageSize: 00206000
- File version: 10.0.15063.477
- Product version: 10.0.15063.477
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: win32kbase.sys
- OriginalFilename: win32kbase.sys
- ProductVersion: 10.0.15063.477
- FileVersion: 10.0.15063.477 (WinBuild.160101.0800)
- FileDescription: Base Win32k Kernel Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff2a5`29dc0000 fffff2a5`29dca000 TSDDD (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\TSDDD.dll\F622DB7Ea000\TSDDD.dll
- Image path: \SystemRoot\System32\TSDDD.dll
- Image name: TSDDD.dll
- Timestamp: ***** Invalid (F622DB7E)
- CheckSum: 000074F8
- ImageSize: 0000A000
- File version: 10.0.15004.1000
- Product version: 10.0.15004.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.4 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: framebuf.dll
- OriginalFilename: framebuf.dll
- ProductVersion: 10.0.15004.1000
- FileVersion: 10.0.15004.1000 (WinBuild.160101.0800)
- FileDescription: Framebuffer Display Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff2a5`29dd0000 fffff2a5`29e11000 cdd (deferred)
- Image path: \SystemRoot\System32\cdd.dll
- Image name: cdd.dll
- Timestamp: unavailable (00000000)
- CheckSum: 00000000
- ImageSize: 00041000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff2a5`2a330000 fffff2a5`2a3a4000 win32k # (pdb symbols) C:\ProgramData\dbg\sym\win32k.pdb\99C346F25FA5B47CA32FBFB1F94AE5911\win32k.pdb
- Loaded symbol image file: win32k.sys
- Mapped memory image file: C:\ProgramData\dbg\sym\win32k.sys\46FD924F74000\win32k.sys
- Image path: \SystemRoot\System32\win32k.sys
- Image name: win32k.sys
- Timestamp: Fri Sep 28 19:46:23 2007 (46FD924F)
- CheckSum: 0007C4FE
- ImageSize: 00074000
- File version: 10.0.15052.0
- Product version: 10.0.15052.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: win32k.sys
- OriginalFilename: win32k.sys
- ProductVersion: 10.0.15052.0
- FileVersion: 10.0.15052.0 (WinBuild.160101.0800)
- FileDescription: Full/Desktop Multi-User Win32 Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`3ba00000 fffff803`3ba0f000 serenum (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\serenum.sys\EB7AAB2Ef000\serenum.sys
- Image path: \SystemRoot\System32\drivers\serenum.sys
- Image name: serenum.sys
- Timestamp: ***** Invalid (EB7AAB2E)
- CheckSum: 000129C5
- ImageSize: 0000F000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: serenum.sys
- OriginalFilename: serenum.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Serial Port Enumerator
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`3ba10000 fffff803`3ba21000 monitor (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\monitor.sys\546AA4AB11000\monitor.sys
- Image path: \SystemRoot\System32\drivers\monitor.sys
- Image name: monitor.sys
- Timestamp: Mon Nov 17 20:45:15 2014 (546AA4AB)
- CheckSum: 0000E236
- ImageSize: 00011000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: monitor.sys
- OriginalFilename: monitor.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: Monitor Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`3ba30000 fffff803`3ba4e000 WudfPf (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\WudfPf.sys\1EF783571e000\WudfPf.sys
- Image path: \SystemRoot\system32\drivers\WudfPf.sys
- Image name: WudfPf.sys
- Timestamp: Wed Jun 18 23:58:15 1986 (1EF78357)
- CheckSum: 0001EDC7
- ImageSize: 0001E000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: WUDFPf.sys
- OriginalFilename: WUDFPf.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Windows Driver Foundation - User-mode Driver Framework Platform Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`3ba50000 fffff803`3ba88000 intelppm (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\intelppm.sys\CDD5C2DE38000\intelppm.sys
- Image path: \SystemRoot\System32\drivers\intelppm.sys
- Image name: intelppm.sys
- Timestamp: ***** Invalid (CDD5C2DE)
- CheckSum: 0003AB14
- ImageSize: 00038000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: intelppm.sys
- OriginalFilename: intelppm.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: Processor Device Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`3ba90000 fffff803`3ba9c000 wmiacpi (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\wmiacpi.sys\15BDC190c000\wmiacpi.sys
- Image path: \SystemRoot\System32\drivers\wmiacpi.sys
- Image name: wmiacpi.sys
- Timestamp: Thu Jul 23 13:29:52 1981 (15BDC190)
- CheckSum: 00012E7A
- ImageSize: 0000C000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: wmiacpi.sys
- OriginalFilename: wmiacpi.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Windows Management Interface for ACPI
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`3baa0000 fffff803`3baad000 NdisVirtualBus (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\NdisVirtualBus.sys\B2B82E4Cd000\NdisVirtualBus.sys
- Image path: \SystemRoot\System32\drivers\NdisVirtualBus.sys
- Image name: NdisVirtualBus.sys
- Timestamp: ***** Invalid (B2B82E4C)
- CheckSum: 0000767E
- ImageSize: 0000D000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: NdisVirtualBus.sys
- OriginalFilename: NdisVirtualBus.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Microsoft Virtual Network Adapter Enumerator
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`3bab0000 fffff803`3babc000 swenum (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\swenum.sys\B9D78944c000\swenum.sys
- Image path: \SystemRoot\System32\drivers\swenum.sys
- Image name: swenum.sys
- Timestamp: ***** Invalid (B9D78944)
- CheckSum: 00010256
- ImageSize: 0000C000
- File version: 10.0.15004.1000
- Product version: 10.0.15004.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.0 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: swenum.sys
- OriginalFilename: swenum.sys
- ProductVersion: 10.0.15004.1000
- FileVersion: 10.0.15004.1000 (WinBuild.160101.0800)
- FileDescription: Plug and Play Software Device Enumerator
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`3bac0000 fffff803`3bacd000 rdpbus (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\rdpbus.sys\401D6CEAd000\rdpbus.sys
- Image path: \SystemRoot\System32\drivers\rdpbus.sys
- Image name: rdpbus.sys
- Timestamp: Sun Feb 1 16:17:30 2004 (401D6CEA)
- CheckSum: 0000F0A9
- ImageSize: 0000D000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.0 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: RDPBUS.SYS
- OriginalFilename: RDPBUS.SYS
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Microsoft RDP Bus Device driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`3bad0000 fffff803`3bb52000 usbhub (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\usbhub.sys\12EAB7AA82000\usbhub.sys
- Image path: \SystemRoot\System32\drivers\usbhub.sys
- Image name: usbhub.sys
- Timestamp: Tue Jan 22 01:58:50 1980 (12EAB7AA)
- CheckSum: 0007D922
- ImageSize: 00082000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: usbhub.sys
- OriginalFilename: usbhub.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: Default Hub Driver for USB
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`3bb60000 fffff803`3bb6e000 USBD (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\USBD.SYS\02B9A964e000\USBD.SYS
- Image path: \SystemRoot\System32\drivers\USBD.SYS
- Image name: USBD.SYS
- Timestamp: Mon Jun 14 00:32:36 1971 (02B9A964)
- CheckSum: 00013619
- ImageSize: 0000E000
- File version: 10.0.15052.0
- Product version: 10.0.15052.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: usbd.sys
- OriginalFilename: usbd.sys
- ProductVersion: 10.0.15052.0
- FileVersion: 10.0.15052.0 (WinBuild.160101.0800)
- FileDescription: Universal Serial Bus Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`3bb70000 fffff803`3bb8e000 AtihdWT6 (deferred)
- Image path: \SystemRoot\system32\drivers\AtihdWT6.sys
- Image name: AtihdWT6.sys
- Timestamp: Sat Mar 25 17:04:05 2017 (58D6DB45)
- CheckSum: 00027D44
- ImageSize: 0001E000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff803`3bb90000 fffff803`3bb9e000 ksthunk (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\ksthunk.sys\A98424C7e000\ksthunk.sys
- Image path: \SystemRoot\system32\drivers\ksthunk.sys
- Image name: ksthunk.sys
- Timestamp: ***** Invalid (A98424C7)
- CheckSum: 0000EC18
- ImageSize: 0000E000
- File version: 10.0.15063.312
- Product version: 10.0.15063.312
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.0 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: ksthunk.sys
- OriginalFilename: ksthunk.sys
- ProductVersion: 10.0.15063.312
- FileVersion: 10.0.15063.312 (WinBuild.160101.0800)
- FileDescription: Kernel Streaming WOW Thunk Service
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`3bba0000 fffff803`3bc2c000 UsbHub3 (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\UsbHub3.sys\20EB40398c000\UsbHub3.sys
- Image path: \SystemRoot\System32\drivers\UsbHub3.sys
- Image name: UsbHub3.sys
- Timestamp: Fri Jul 3 01:25:13 1987 (20EB4039)
- CheckSum: 00089ACF
- ImageSize: 0008C000
- File version: 10.0.15063.470
- Product version: 10.0.15063.470
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: usbhub3.sys
- OriginalFilename: usbhub3.sys
- ProductVersion: 10.0.15063.470
- FileVersion: 10.0.15063.470 (WinBuild.160101.0800)
- FileDescription: USB3 HUB Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`3bc30000 fffff803`3c1fb000 RTKVHD64 (deferred)
- Image path: \SystemRoot\system32\drivers\RTKVHD64.sys
- Image name: RTKVHD64.sys
- Timestamp: Tue Jul 4 08:21:17 2017 (595B883D)
- CheckSum: 005A1D00
- ImageSize: 005CB000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff803`3c200000 fffff803`3c212000 HIDPARSE (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\HIDPARSE.SYS\CCA5718512000\HIDPARSE.SYS
- Image path: \SystemRoot\System32\drivers\HIDPARSE.SYS
- Image name: HIDPARSE.SYS
- Timestamp: ***** Invalid (CCA57185)
- CheckSum: 0001506A
- ImageSize: 00012000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: hidparse.sys
- OriginalFilename: hidparse.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Hid Parsing Library
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`3c370000 fffff803`3c38d000 dump_dumpfve (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\dumpfve.sys\B65817D61d000\dumpfve.sys
- Image path: \SystemRoot\System32\Drivers\dump_dumpfve.sys
- Image name: dump_dumpfve.sys
- Timestamp: ***** Invalid (B65817D6)
- CheckSum: 0001EA4A
- ImageSize: 0001D000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: dumpfve.sys
- OriginalFilename: dumpfve.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Bitlocker Drive Encryption Crashdump Filter
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`3c390000 fffff803`3c3c1000 usbccgp (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\usbccgp.sys\5B5307EA31000\usbccgp.sys
- Image path: \SystemRoot\System32\drivers\usbccgp.sys
- Image name: usbccgp.sys
- Timestamp: Sat Jul 21 06:16:10 2018 (5B5307EA)
- CheckSum: 0002DC32
- ImageSize: 00031000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: USBCCGP.SYS
- OriginalFilename: USBCCGP.SYS
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: USB Common Class Generic Parent Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`3c3d0000 fffff803`3c3e2000 hidusb (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\hidusb.sys\572851EF12000\hidusb.sys
- Image path: \SystemRoot\System32\drivers\hidusb.sys
- Image name: hidusb.sys
- Timestamp: Tue May 3 03:23:27 2016 (572851EF)
- CheckSum: 00016E3E
- ImageSize: 00012000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: HIDUSB.SYS
- OriginalFilename: HIDUSB.SYS
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: USB Miniport Driver for Input Devices
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`3c3f0000 fffff803`3c423000 HIDCLASS (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\HIDCLASS.SYS\28A8EF3D33000\HIDCLASS.SYS
- Image path: \SystemRoot\System32\drivers\HIDCLASS.SYS
- Image name: HIDCLASS.SYS
- Timestamp: Wed Aug 14 04:52:13 1991 (28A8EF3D)
- CheckSum: 000367E8
- ImageSize: 00033000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: hidclass.sys
- OriginalFilename: hidclass.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: Hid Class Library
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`3c440000 fffff803`3c44f000 dump_diskdump (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\diskdump.sys\521DF4ECf000\diskdump.sys
- Image path: \SystemRoot\System32\Drivers\dump_diskdump.sys
- Image name: dump_diskdump.sys
- Timestamp: Wed Aug 28 09:02:36 2013 (521DF4EC)
- CheckSum: 00015D88
- ImageSize: 0000F000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: diskdump.sys
- OriginalFilename: diskdump.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Crash Dump Disk Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`3c450000 fffff803`3c460000 kbdhid (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\kbdhid.sys\6264CDC410000\kbdhid.sys
- Image path: \SystemRoot\System32\drivers\kbdhid.sys
- Image name: kbdhid.sys
- Timestamp: Sun Apr 24 00:10:44 2022 (6264CDC4)
- CheckSum: 00010564
- ImageSize: 00010000
- File version: 10.0.15052.0
- Product version: 10.0.15052.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: kbdhid.sys
- OriginalFilename: kbdhid.sys
- ProductVersion: 10.0.15052.0
- FileVersion: 10.0.15052.0 (WinBuild.160101.0800)
- FileDescription: HID Keyboard Filter Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`3c460000 fffff803`3c473000 kbdclass (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\kbdclass.sys\D67B605D13000\kbdclass.sys
- Image path: \SystemRoot\System32\drivers\kbdclass.sys
- Image name: kbdclass.sys
- Timestamp: ***** Invalid (D67B605D)
- CheckSum: 00019BCB
- ImageSize: 00013000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: kbdclass.sys
- OriginalFilename: kbdclass.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Keyboard Class Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`3c480000 fffff803`3c48f000 mouhid (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\mouhid.sys\E277736Ff000\mouhid.sys
- Image path: \SystemRoot\System32\drivers\mouhid.sys
- Image name: mouhid.sys
- Timestamp: ***** Invalid (E277736F)
- CheckSum: 000145D4
- ImageSize: 0000F000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: mouhid.sys
- OriginalFilename: mouhid.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: HID Mouse Filter Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`3c490000 fffff803`3c4a3000 mouclass (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\mouclass.sys\7BC8E3F513000\mouclass.sys
- Image path: \SystemRoot\System32\drivers\mouclass.sys
- Image name: mouclass.sys
- Timestamp: Tue Oct 23 10:38:45 2035 (7BC8E3F5)
- CheckSum: 000154AD
- ImageSize: 00013000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: mouclass.sys
- OriginalFilename: mouclass.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: Mouse Class Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`3c4b0000 fffff803`3c5a2000 rt640x64 (deferred)
- Image path: \SystemRoot\System32\drivers\rt640x64.sys
- Image name: rt640x64.sys
- Timestamp: Fri May 26 03:02:29 2017 (5927D305)
- CheckSum: 000F7B4F
- ImageSize: 000F2000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff803`3c5b0000 fffff803`3c5bb000 ICCWDT (deferred)
- Image path: \SystemRoot\System32\drivers\ICCWDT.sys
- Image name: ICCWDT.sys
- Timestamp: Sun Sep 20 03:59:19 2015 (55FE6757)
- CheckSum: 000149FA
- ImageSize: 0000B000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff803`3c5c0000 fffff803`3c5de000 parport (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\parport.sys\A81208301e000\parport.sys
- Image path: \SystemRoot\System32\drivers\parport.sys
- Image name: parport.sys
- Timestamp: ***** Invalid (A8120830)
- CheckSum: 000217F8
- ImageSize: 0001E000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: parport.sys
- OriginalFilename: parport.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Parallel Port Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`3c5e0000 fffff803`3c5fc000 serial (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\serial.sys\64C1C1E01c000\serial.sys
- Image path: \SystemRoot\System32\drivers\serial.sys
- Image name: serial.sys
- Timestamp: Wed Jul 26 21:01:20 2023 (64C1C1E0)
- CheckSum: 0001C398
- ImageSize: 0001C000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: serial.sys
- OriginalFilename: serial.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Serial Device Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`3cc1b000 fffff803`3d4a4000 nt (pdb symbols) C:\ProgramData\dbg\sym\ntkrnlmp.pdb\DDA812F4AC284269AB8073D8423801A41\ntkrnlmp.pdb
- Loaded symbol image file: ntkrnlmp.exe
- Mapped memory image file: C:\ProgramData\dbg\sym\ntoskrnl.exe\595F24EB889000\ntoskrnl.exe
- Image path: ntkrnlmp.exe
- Image name: ntkrnlmp.exe
- Timestamp: Fri Jul 7 02:06:35 2017 (595F24EB)
- CheckSum: 007FA636
- ImageSize: 00889000
- File version: 10.0.15063.483
- Product version: 10.0.15063.483
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 1.0 App
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: ntkrnlmp.exe
- OriginalFilename: ntkrnlmp.exe
- ProductVersion: 10.0.15063.483
- FileVersion: 10.0.15063.483 (WinBuild.160101.0800)
- FileDescription: NT Kernel & System
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`3d4a4000 fffff803`3d520000 hal (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\hal.dll\CEA0A6467c000\hal.dll
- Image path: hal.dll
- Image name: hal.dll
- Timestamp: ***** Invalid (CEA0A646)
- CheckSum: 000795FE
- ImageSize: 0007C000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: hal.dll
- OriginalFilename: hal.dll
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: Hardware Abstraction Layer DLL
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`3d600000 fffff803`3d60b000 kd (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\kd.dll\91688416b000\kd.dll
- Image path: \SystemRoot\system32\kd.dll
- Image name: kd.dll
- Timestamp: ***** Invalid (91688416)
- CheckSum: 0000C219
- ImageSize: 0000B000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.A Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: kd.dll
- OriginalFilename: kd.dll
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Local Kernel Debugger
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`3fe00000 fffff803`3fe7b000 mrxsmb (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\mrxsmb.sys\41707DB67b000\mrxsmb.sys
- Image path: \SystemRoot\system32\DRIVERS\mrxsmb.sys
- Image name: mrxsmb.sys
- Timestamp: Fri Oct 15 21:47:34 2004 (41707DB6)
- CheckSum: 000761DC
- ImageSize: 0007B000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: MRxSmb.sys
- OriginalFilename: MRXSMB.Sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: Windows NT SMB Minirdr
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`3fe80000 fffff803`3febd000 mrxsmb20 (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\mrxsmb20.sys\4FC9BDCC3d000\mrxsmb20.sys
- Image path: \SystemRoot\system32\DRIVERS\mrxsmb20.sys
- Image name: mrxsmb20.sys
- Timestamp: Sat Jun 2 03:16:28 2012 (4FC9BDCC)
- CheckSum: 00041784
- ImageSize: 0003D000
- File version: 10.0.15063.468
- Product version: 10.0.15063.468
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: MRxSmb20.sys
- OriginalFilename: MRXSMB20.Sys
- ProductVersion: 10.0.15063.468
- FileVersion: 10.0.15063.468 (WinBuild.160101.0800)
- FileDescription: Longhorn SMB 2.0 Redirector
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`3fec0000 fffff803`3ff06000 srvnet (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\srvnet.sys\525EB0E046000\srvnet.sys
- Image path: \SystemRoot\System32\DRIVERS\srvnet.sys
- Image name: srvnet.sys
- Timestamp: Wed Oct 16 11:29:36 2013 (525EB0E0)
- CheckSum: 0004A0FD
- ImageSize: 00046000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: SRVNET.SYS
- OriginalFilename: SRVNET.SYS
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: Server Network driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`3ff10000 fffff803`3ff24000 mmcss (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\mmcss.sys\95EC281D14000\mmcss.sys
- Image path: \SystemRoot\system32\drivers\mmcss.sys
- Image name: mmcss.sys
- Timestamp: ***** Invalid (95EC281D)
- CheckSum: 000165DE
- ImageSize: 00014000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: mmcss.sys
- OriginalFilename: mmcss.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: MMCSS Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`3ff30000 fffff803`3ff7e000 mrxsmb10 (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\mrxsmb10.sys\D3F9A54C4e000\mrxsmb10.sys
- Image path: \SystemRoot\system32\DRIVERS\mrxsmb10.sys
- Image name: mrxsmb10.sys
- Timestamp: ***** Invalid (D3F9A54C)
- CheckSum: 0004CF74
- ImageSize: 0004E000
- File version: 10.0.15063.468
- Product version: 10.0.15063.468
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: MRxSmb0.sys
- OriginalFilename: MRXSMB0.Sys
- ProductVersion: 10.0.15063.468
- FileVersion: 10.0.15063.468 (WinBuild.160101.0800)
- FileDescription: Longhorn SMB Downlevel SubRdr
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`3ff80000 fffff803`3ffa6000 Ndu (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\Ndu.sys\84A4289326000\Ndu.sys
- Image path: \SystemRoot\system32\drivers\Ndu.sys
- Image name: Ndu.sys
- Timestamp: ***** Invalid (84A42893)
- CheckSum: 000290F8
- ImageSize: 00026000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: ndu.sys
- OriginalFilename: ndu.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: Windows Network Data Usage Monitoring Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`3ffb0000 fffff803`40076000 peauth (deferred)
- Image path: \SystemRoot\system32\drivers\peauth.sys
- Image name: peauth.sys
- Timestamp: Sat Dec 9 21:03:08 1989 (2581B95C)
- CheckSum: 000C12D5
- ImageSize: 000C6000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff803`40080000 fffff803`40093000 tcpipreg (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\tcpipreg.sys\F09C8E9F13000\tcpipreg.sys
- Image path: \SystemRoot\System32\drivers\tcpipreg.sys
- Image name: tcpipreg.sys
- Timestamp: ***** Invalid (F09C8E9F)
- CheckSum: 0001B5C9
- ImageSize: 00013000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 1.0 App
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: tcpipreg.sys
- OriginalFilename: tcpipreg.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: TCP/IP Registry Compatibility Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`400a0000 fffff803`40158000 srv2 (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\srv2.sys\61B5FB64b8000\srv2.sys
- Image path: \SystemRoot\System32\DRIVERS\srv2.sys
- Image name: srv2.sys
- Timestamp: Sun Dec 12 08:38:44 2021 (61B5FB64)
- CheckSum: 000BB8B8
- ImageSize: 000B8000
- File version: 10.0.15063.246
- Product version: 10.0.15063.246
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: SRV2.SYS
- OriginalFilename: SRV2.SYS
- ProductVersion: 10.0.15063.246
- FileVersion: 10.0.15063.246 (WinBuild.160101.0800)
- FileDescription: Smb 2.0 Server driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`40180000 fffff803`4020b000 nwifi (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\nwifi.sys\3E4B5B018b000\nwifi.sys
- Image path: \SystemRoot\system32\DRIVERS\nwifi.sys
- Image name: nwifi.sys
- Timestamp: Thu Feb 13 03:44:49 2003 (3E4B5B01)
- CheckSum: 0008658E
- ImageSize: 0008B000
- File version: 10.0.15052.0
- Product version: 10.0.15052.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: NWiFi.SYS
- OriginalFilename: NWiFi.SYS
- ProductVersion: 10.0.15052.0
- FileVersion: 10.0.15052.0 (WinBuild.160101.0800)
- FileDescription: NativeWiFi Miniport Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`40210000 fffff803`40226000 ndisuio (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\ndisuio.sys\FC45647916000\ndisuio.sys
- Image path: \SystemRoot\system32\drivers\ndisuio.sys
- Image name: ndisuio.sys
- Timestamp: ***** Invalid (FC456479)
- CheckSum: 00015844
- ImageSize: 00016000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: NDISUIO.SYS
- OriginalFilename: NDISUIO.SYS
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: NDIS User mode I/O driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`40230000 fffff803`40344000 HTTP (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\HTTP.sys\CC93E16B114000\HTTP.sys
- Image path: \SystemRoot\system32\drivers\HTTP.sys
- Image name: HTTP.sys
- Timestamp: ***** Invalid (CC93E16B)
- CheckSum: 00117882
- ImageSize: 00114000
- File version: 10.0.15063.470
- Product version: 10.0.15063.470
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: http.sys
- OriginalFilename: http.sys
- ProductVersion: 10.0.15063.470
- FileVersion: 10.0.15063.470 (WinBuild.160101.0800)
- FileDescription: HTTP Protocol Stack
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`40350000 fffff803`40371000 bowser (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\bowser.sys\B091348621000\bowser.sys
- Image path: \SystemRoot\system32\DRIVERS\bowser.sys
- Image name: bowser.sys
- Timestamp: ***** Invalid (B0913486)
- CheckSum: 00021EC6
- ImageSize: 00021000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: browser.sys
- OriginalFilename: browser.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: NT Lan Manager Datagram Receiver Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`40380000 fffff803`4039a000 mpsdrv (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\mpsdrv.sys\148326721a000\mpsdrv.sys
- Image path: \SystemRoot\System32\drivers\mpsdrv.sys
- Image name: mpsdrv.sys
- Timestamp: Wed Nov 26 21:16:18 1980 (14832672)
- CheckSum: 0001A5AB
- ImageSize: 0001A000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: mpsdrv.sys
- OriginalFilename: mpsdrv.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: Microsoft Protection Service Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`404b0000 fffff803`4055f000 BEDaisy (deferred)
- Image path: \??\C:\Program Files (x86)\Common Files\BattlEye\BEDaisy.sys
- Image name: BEDaisy.sys
- Timestamp: Tue Jan 10 22:01:10 2017 (58759FF6)
- CheckSum: 00071812
- ImageSize: 000AF000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff803`40a10000 fffff803`40a9d000 srv (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\srv.sys\6EE066FD8d000\srv.sys
- Image path: \SystemRoot\System32\DRIVERS\srv.sys
- Image name: srv.sys
- Timestamp: Mon Dec 11 21:16:29 2028 (6EE066FD)
- CheckSum: 0006AB08
- ImageSize: 0008D000
- File version: 10.0.15063.246
- Product version: 10.0.15063.246
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: SRV.SYS
- OriginalFilename: SRV.SYS
- ProductVersion: 10.0.15063.246
- FileVersion: 10.0.15063.246 (WinBuild.160101.0800)
- FileDescription: Server driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`40aa0000 fffff803`40ab1000 vwifimp (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\vwifimp.sys\FDE8912E11000\vwifimp.sys
- Image path: \SystemRoot\System32\drivers\vwifimp.sys
- Image name: vwifimp.sys
- Timestamp: ***** Invalid (FDE8912E)
- CheckSum: 0000E1E3
- ImageSize: 00011000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: vwifimp.sys
- OriginalFilename: vwifimp.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Virtual WiFi Miniport Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`40ac0000 fffff803`40af0000 tunnel (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\tunnel.sys\157D715030000\tunnel.sys
- Image path: \SystemRoot\System32\drivers\tunnel.sys
- Image name: tunnel.sys
- Timestamp: Thu Jun 4 18:42:24 1981 (157D7150)
- CheckSum: 000309F8
- ImageSize: 00030000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: tunnel.sys
- OriginalFilename: tunnel.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Microsoft Tunnel Interface Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`40af0000 fffff803`40b02000 condrv (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\condrv.sys\73A5288F12000\condrv.sys
- Image path: \SystemRoot\System32\drivers\condrv.sys
- Image name: condrv.sys
- Timestamp: Wed Jun 25 21:27:43 2031 (73A5288F)
- CheckSum: 00014797
- ImageSize: 00012000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: condrv.sys
- OriginalFilename: condrv.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Console Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`41400000 fffff803`41421000 drmk (deferred)
- Image path: \SystemRoot\System32\drivers\drmk.sys
- Image name: drmk.sys
- Timestamp: ***** Invalid (A01C1986)
- CheckSum: 000244D4
- ImageSize: 00021000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff803`41430000 fffff803`41494000 USBXHCI (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\USBXHCI.SYS\42DB248264000\USBXHCI.SYS
- Image path: \SystemRoot\System32\drivers\USBXHCI.SYS
- Image name: USBXHCI.SYS
- Timestamp: Sun Jul 17 23:39:46 2005 (42DB2482)
- CheckSum: 00063B8A
- ImageSize: 00064000
- File version: 10.0.15063.137
- Product version: 10.0.15063.137
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: usbxhci.sys
- OriginalFilename: usbxhci.sys
- ProductVersion: 10.0.15063.137
- FileVersion: 10.0.15063.137 (WinBuild.160101.0800)
- FileDescription: USB XHCI Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`414a0000 fffff803`414d9000 ucx01000 (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\ucx01000.sys\2D6A1C0439000\ucx01000.sys
- Image path: \SystemRoot\system32\drivers\ucx01000.sys
- Image name: ucx01000.sys
- Timestamp: Tue Feb 22 09:51:48 1994 (2D6A1C04)
- CheckSum: 0003CD1A
- ImageSize: 00039000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: ucx01000.sys
- OriginalFilename: ucx01000.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: USB Controller Extension
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`414e0000 fffff803`41514000 TeeDriverW8x64 (deferred)
- Image path: \SystemRoot\System32\drivers\TeeDriverW8x64.sys
- Image name: TeeDriverW8x64.sys
- Timestamp: Tue Apr 4 03:02:36 2017 (58E3450C)
- CheckSum: 0003DC8C
- ImageSize: 00034000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff803`41520000 fffff803`4153c000 usbehci (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\usbehci.sys\B53499C21c000\usbehci.sys
- Image path: \SystemRoot\System32\drivers\usbehci.sys
- Image name: usbehci.sys
- Timestamp: ***** Invalid (B53499C2)
- CheckSum: 0001A61F
- ImageSize: 0001C000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: USBEHCI.sys
- OriginalFilename: USBEHCI.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: EHCI eUSB Miniport Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`41540000 fffff803`415b7000 USBPORT (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\USBPORT.SYS\CE98320377000\USBPORT.SYS
- Image path: \SystemRoot\System32\drivers\USBPORT.SYS
- Image name: USBPORT.SYS
- Timestamp: ***** Invalid (CE983203)
- CheckSum: 0007E3BD
- ImageSize: 00077000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: usbport.sys
- OriginalFilename: usbport.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: USB 1.1 & 2.0 Port Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`415c0000 fffff803`415ce000 vwifibus (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\vwifibus.sys\B333B2DAe000\vwifibus.sys
- Image path: \SystemRoot\System32\drivers\vwifibus.sys
- Image name: vwifibus.sys
- Timestamp: ***** Invalid (B333B2DA)
- CheckSum: 00009366
- ImageSize: 0000E000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: VWiFiBus.sys
- OriginalFilename: VWiFiBus.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Virtual Wireless Bus Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`415d0000 fffff803`4160d000 WUDFRd (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\WUDFRd.sys\8D7459263d000\WUDFRd.sys
- Image path: \SystemRoot\System32\drivers\WUDFRd.sys
- Image name: WUDFRd.sys
- Timestamp: ***** Invalid (8D745926)
- CheckSum: 000411B6
- ImageSize: 0003D000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: WUDFRd.sys
- OriginalFilename: WUDFRd.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Windows Driver Foundation - User-mode Driver Framework Reflector
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`41610000 fffff803`43947000 atikmdag (deferred)
- Image path: \SystemRoot\System32\DriverStore\FileRepository\c0315940.inf_amd64_2b462f080682210e\atikmdag.sys
- Image name: atikmdag.sys
- Timestamp: Tue Jul 4 18:11:43 2017 (595C129F)
- CheckSum: 022EB89D
- ImageSize: 02337000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff803`43960000 fffff803`4397d000 HDAudBus (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\HDAudBus.sys\21FD85791d000\HDAudBus.sys
- Image path: \SystemRoot\System32\drivers\HDAudBus.sys
- Image name: HDAudBus.sys
- Timestamp: Wed Jan 27 01:21:45 1988 (21FD8579)
- CheckSum: 0001E51D
- ImageSize: 0001D000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.9 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: hdaudbus.sys
- OriginalFilename: hdaudbus.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: High Definition Audio Bus Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`43980000 fffff803`439e3000 portcls (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\portcls.sys\ABE570C263000\portcls.sys
- Image path: \SystemRoot\System32\drivers\portcls.sys
- Image name: portcls.sys
- Timestamp: ***** Invalid (ABE570C2)
- CheckSum: 0005DD44
- ImageSize: 00063000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.9 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: portcls.sys
- OriginalFilename: portcls.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Port Class (Class Driver for Port/Miniport Devices)
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff803`439f0000 fffff803`439fb000 registry (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\registry.sys\A10D8E26b000\registry.sys
- Image path: \SystemRoot\System32\drivers\registry.sys
- Image name: registry.sys
- Timestamp: ***** Invalid (A10D8E26)
- CheckSum: 000113F7
- ImageSize: 0000B000
- File version: 10.0.15004.1000
- Product version: 10.0.15004.1000
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: registry.sys
- OriginalFilename: registry.sys
- ProductVersion: 10.0.15004.1000
- FileVersion: 10.0.15004.1000 (WinBuild.160101.0800)
- FileDescription: Registry Containment Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e6000000 fffff80a`e6065000 CLFS (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\CLFS.SYS\A746E82D65000\CLFS.SYS
- Image path: \SystemRoot\System32\drivers\CLFS.SYS
- Image name: CLFS.SYS
- Timestamp: ***** Invalid (A746E82D)
- CheckSum: 0006C6FD
- ImageSize: 00065000
- File version: 10.0.15063.468
- Product version: 10.0.15063.468
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: clfs.sys
- OriginalFilename: Clfs.Sys
- ProductVersion: 10.0.15063.468
- FileVersion: 10.0.15063.468 (WinBuild.160101.0800)
- FileDescription: Common Log File System Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e6070000 fffff80a`e6095000 tm (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\tm.sys\69649A1925000\tm.sys
- Image path: \SystemRoot\System32\drivers\tm.sys
- Image name: tm.sys
- Timestamp: Mon Jan 12 01:52:09 2026 (69649A19)
- CheckSum: 0002374B
- ImageSize: 00025000
- File version: 10.0.15063.400
- Product version: 10.0.15063.400
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: tm.sys
- OriginalFilename: tm.sys
- ProductVersion: 10.0.15063.400
- FileVersion: 10.0.15063.400 (WinBuild.160101.0800)
- FileDescription: Kernel Transaction Manager Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e60a0000 fffff80a`e60b7000 PSHED (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\PSHED.dll\6AEC44D517000\PSHED.dll
- Image path: \SystemRoot\system32\PSHED.dll
- Image name: PSHED.dll
- Timestamp: Thu Nov 5 03:56:53 2026 (6AEC44D5)
- CheckSum: 00016449
- ImageSize: 00017000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: pshed.dll
- OriginalFilename: pshed.dll
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Platform Specific Hardware Error Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e60c0000 fffff80a`e60cb000 BOOTVID (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\BOOTVID.dll\9EAF733Cb000\BOOTVID.dll
- Image path: \SystemRoot\system32\BOOTVID.dll
- Image name: BOOTVID.dll
- Timestamp: ***** Invalid (9EAF733C)
- CheckSum: 00016298
- ImageSize: 0000B000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.4 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: bootvid.dll
- OriginalFilename: bootvid.dll
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: VGA Boot Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e60d0000 fffff80a`e6135000 FLTMGR (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\FLTMGR.SYS\90D626DF65000\FLTMGR.SYS
- Image path: \SystemRoot\System32\drivers\FLTMGR.SYS
- Image name: FLTMGR.SYS
- Timestamp: ***** Invalid (90D626DF)
- CheckSum: 000656FA
- ImageSize: 00065000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: fltMgr.sys
- OriginalFilename: fltMgr.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: Microsoft Filesystem Filter Manager
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e6140000 fffff80a`e6220000 clipsp (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\clipsp.sys\58CCBD75e0000\clipsp.sys
- Image path: \SystemRoot\System32\drivers\clipsp.sys
- Image name: clipsp.sys
- Timestamp: Sat Mar 18 00:54:13 2017 (58CCBD75)
- CheckSum: 000DC888
- ImageSize: 000E0000
- File version: 10.0.15063.0
- Product version: 10.0.15063.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: clipsp.dll
- OriginalFilename: clipsp.dll
- ProductVersion: 10.0.15063.0
- FileVersion: 10.0.15063.0 (WinBuild.160101.0800)
- FileDescription: CLIP Service
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e6220000 fffff80a`e622e000 cmimcext (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\cmimcext.sys\FF4D5961e000\cmimcext.sys
- Image path: \SystemRoot\System32\drivers\cmimcext.sys
- Image name: cmimcext.sys
- Timestamp: ***** Invalid (FF4D5961)
- CheckSum: 00008775
- ImageSize: 0000E000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: cmimcext.sys
- OriginalFilename: cmimcext.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Kernel Configuration Manager Initial Configuration Extension Host Export Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e6230000 fffff80a`e623c000 ntosext (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\ntosext.sys\CC2A33ADc000\ntosext.sys
- Image path: \SystemRoot\System32\drivers\ntosext.sys
- Image name: ntosext.sys
- Timestamp: ***** Invalid (CC2A33AD)
- CheckSum: 00012746
- ImageSize: 0000C000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: ntosext.sys
- OriginalFilename: ntosext.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: NTOS extension host driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e6240000 fffff80a`e62e8000 CI (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\CI.dll\57C1E861a8000\CI.dll
- Image path: \SystemRoot\system32\CI.dll
- Image name: CI.dll
- Timestamp: Sat Aug 27 15:22:09 2016 (57C1E861)
- CheckSum: 000A5ED0
- ImageSize: 000A8000
- File version: 10.0.15063.251
- Product version: 10.0.15063.251
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: ci.dll
- OriginalFilename: ci.dll
- ProductVersion: 10.0.15063.251
- FileVersion: 10.0.15063.251 (WinBuild.160101.0800)
- FileDescription: Code Integrity Module
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e62f0000 fffff80a`e6392000 cng (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\cng.sys\F2E91F26a2000\cng.sys
- Image path: \SystemRoot\System32\drivers\cng.sys
- Image name: cng.sys
- Timestamp: ***** Invalid (F2E91F26)
- CheckSum: 000A8550
- ImageSize: 000A2000
- File version: 10.0.15063.0
- Product version: 10.0.15063.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: cng.sys
- OriginalFilename: cng.sys
- ProductVersion: 10.0.15063.0
- FileVersion: 10.0.15063.0 (WinBuild.160101.0800)
- FileDescription: Kernel Cryptography, Next Generation
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e63a0000 fffff80a`e647e000 Wdf01000 (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\Wdf01000.sys\26EEE197de000\Wdf01000.sys
- Image path: \SystemRoot\system32\drivers\Wdf01000.sys
- Image name: Wdf01000.sys
- Timestamp: Wed Sep 12 21:32:07 1990 (26EEE197)
- CheckSum: 000E46B7
- ImageSize: 000DE000
- File version: 1.21.15063.0
- Product version: 1.21.15063.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: wdf01000.sys
- OriginalFilename: wdf01000.sys
- ProductVersion: 1.21.15063.0
- FileVersion: 1.21.15063.0 (WinBuild.160101.0800)
- FileDescription: Kernel Mode Driver Framework Runtime
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e6480000 fffff80a`e6493000 WDFLDR (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\WDFLDR.SYS\0E910A3D13000\WDFLDR.SYS
- Image path: \SystemRoot\system32\drivers\WDFLDR.SYS
- Image name: WDFLDR.SYS
- Timestamp: Thu Sep 29 09:06:05 1977 (0E910A3D)
- CheckSum: 00018953
- ImageSize: 00013000
- File version: 1.21.15058.0
- Product version: 1.21.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: wdfldr.sys
- OriginalFilename: wdfldr.sys
- ProductVersion: 1.21.15058.0
- FileVersion: 1.21.15058.0 (WinBuild.160101.0800)
- FileDescription: Kernel Mode Driver Framework Loader
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e64a0000 fffff80a`e64ae000 SleepStudyHelper (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\SleepStudyHelper.sys\EFF776F3e000\SleepStudyHelper.sys
- Image path: \SystemRoot\system32\drivers\SleepStudyHelper.sys
- Image name: SleepStudyHelper.sys
- Timestamp: ***** Invalid (EFF776F3)
- CheckSum: 00010075
- ImageSize: 0000E000
- File version: 10.0.15052.0
- Product version: 10.0.15052.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: SleepStudyHelper.sys
- OriginalFilename: SleepStudyHelper.sys
- ProductVersion: 10.0.15052.0
- FileVersion: 10.0.15052.0 (WinBuild.160101.0800)
- FileDescription: Sleep Study Helper
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e64b0000 fffff80a`e64d3000 acpiex (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\acpiex.sys\DC6150EE23000\acpiex.sys
- Image path: \SystemRoot\System32\Drivers\acpiex.sys
- Image name: acpiex.sys
- Timestamp: ***** Invalid (DC6150EE)
- CheckSum: 00028B4D
- ImageSize: 00023000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: acpiex.sys
- OriginalFilename: acpiex.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: ACPIEx Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e64e0000 fffff80a`e64ee000 WppRecorder (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\WppRecorder.sys\1E4DAB2Fe000\WppRecorder.sys
- Image path: \SystemRoot\System32\Drivers\WppRecorder.sys
- Image name: WppRecorder.sys
- Timestamp: Mon Feb 10 03:02:55 1986 (1E4DAB2F)
- CheckSum: 0000C53D
- ImageSize: 0000E000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: WppRecorder.sys
- OriginalFilename: WppRecorder.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: WPP Trace Recorder
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e64f0000 fffff80a`e65a7000 ACPI (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\ACPI.sys\0B2AD2B4b7000\ACPI.sys
- Image path: \SystemRoot\System32\drivers\ACPI.sys
- Image name: ACPI.sys
- Timestamp: Tue Dec 9 06:17:08 1975 (0B2AD2B4)
- CheckSum: 000B1260
- ImageSize: 000B7000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: ACPI.sys
- OriginalFilename: ACPI.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: ACPI Driver for NT
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e65b0000 fffff80a`e65bc000 WMILIB (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\WMILIB.SYS\5BAE5A54c000\WMILIB.SYS
- Image path: \SystemRoot\System32\drivers\WMILIB.SYS
- Image name: WMILIB.SYS
- Timestamp: Fri Sep 28 12:44:04 2018 (5BAE5A54)
- CheckSum: 0000E2FE
- ImageSize: 0000C000
- File version: 10.0.15052.0
- Product version: 10.0.15052.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: WmiLib.sys
- OriginalFilename: WmiLib.sys
- ProductVersion: 10.0.15052.0
- FileVersion: 10.0.15052.0 (WinBuild.160101.0800)
- FileDescription: WMILIB WMI support library Dll
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e65c0000 fffff80a`e65d7000 intelpep (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\intelpep.sys\46272DF617000\intelpep.sys
- Image path: \SystemRoot\System32\drivers\intelpep.sys
- Image name: intelpep.sys
- Timestamp: Thu Apr 19 04:53:10 2007 (46272DF6)
- CheckSum: 00022020
- ImageSize: 00017000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.A Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: intelpep.sys
- OriginalFilename: intelpep.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Intel Power Engine Plugin
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e65e0000 fffff80a`e65f6000 WindowsTrustedRT (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\WindowsTrustedRT.sys\E3FF4AF616000\WindowsTrustedRT.sys
- Image path: \SystemRoot\system32\drivers\WindowsTrustedRT.sys
- Image name: WindowsTrustedRT.sys
- Timestamp: ***** Invalid (E3FF4AF6)
- CheckSum: 0001FED5
- ImageSize: 00016000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: WindowsTrustedRT.sys
- OriginalFilename: WindowsTrustedRT.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Windows Trusted Runtime Interface Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e6600000 fffff80a`e660b000 WindowsTrustedRTProxy (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\WindowsTrustedRTProxy.sys\44CA11F8b000\WindowsTrustedRTProxy.sys
- Image path: \SystemRoot\System32\drivers\WindowsTrustedRTProxy.sys
- Image name: WindowsTrustedRTProxy.sys
- Timestamp: Fri Jul 28 09:32:40 2006 (44CA11F8)
- CheckSum: 0000A552
- ImageSize: 0000B000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: WindowsTrustedRTProxy.sys
- OriginalFilename: WindowsTrustedRTProxy.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Windows Trusted Runtime Service Proxy Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e6610000 fffff80a`e6623000 pcw (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\pcw.sys\000CEFA513000\pcw.sys
- Image path: \SystemRoot\System32\drivers\pcw.sys
- Image name: pcw.sys
- Timestamp: Sat Jan 10 14:29:41 1970 (000CEFA5)
- CheckSum: 000188B9
- ImageSize: 00013000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.8 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: pcw.sys
- OriginalFilename: pcw.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Performance Counters for Windows Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e6630000 fffff80a`e663b000 msisadrv (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\msisadrv.sys\BAF553EFb000\msisadrv.sys
- Image path: \SystemRoot\System32\drivers\msisadrv.sys
- Image name: msisadrv.sys
- Timestamp: ***** Invalid (BAF553EF)
- CheckSum: 0000CAA1
- ImageSize: 0000B000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: msisadrv.sys
- OriginalFilename: msisadrv.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: ISA Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e6640000 fffff80a`e669b000 pci (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\pci.sys\688DD7395b000\pci.sys
- Image path: \SystemRoot\System32\drivers\pci.sys
- Image name: pci.sys
- Timestamp: Sat Aug 2 05:15:37 2025 (688DD739)
- CheckSum: 00063A5B
- ImageSize: 0005B000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: pci.sys
- OriginalFilename: pci.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: NT Plug and Play PCI Enumerator
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e66a0000 fffff80a`e66b2000 vdrvroot (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\vdrvroot.sys\C0C6BED012000\vdrvroot.sys
- Image path: \SystemRoot\System32\drivers\vdrvroot.sys
- Image name: vdrvroot.sys
- Timestamp: ***** Invalid (C0C6BED0)
- CheckSum: 0001558D
- ImageSize: 00012000
- File version: 10.0.15052.0
- Product version: 10.0.15052.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: vdrvroot.sys
- OriginalFilename: vdrvroot.sys
- ProductVersion: 10.0.15052.0
- FileVersion: 10.0.15052.0 (WinBuild.160101.0800)
- FileDescription: Virtual Drive Root Enumerator
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e66c0000 fffff80a`e66e3000 pdc (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\pdc.sys\26921BAC23000\pdc.sys
- Image path: \SystemRoot\system32\drivers\pdc.sys
- Image name: pdc.sys
- Timestamp: Wed Jul 4 12:39:08 1990 (26921BAC)
- CheckSum: 0002C547
- ImageSize: 00023000
- File version: 10.0.15063.468
- Product version: 10.0.15063.468
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: pdc.sys
- OriginalFilename: pdc.sys
- ProductVersion: 10.0.15063.468
- FileVersion: 10.0.15063.468 (WinBuild.160101.0800)
- FileDescription: Power Dependency Coordinator Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e66f0000 fffff80a`e6708000 CEA (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\CEA.sys\01CDB10218000\CEA.sys
- Image path: \SystemRoot\system32\drivers\CEA.sys
- Image name: CEA.sys
- Timestamp: Wed Dec 16 23:50:10 1970 (01CDB102)
- CheckSum: 0001DBD0
- ImageSize: 00018000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: EventAggregation.sys
- OriginalFilename: EventAggregation.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Event Aggregation Kernel Mode Library
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e6710000 fffff80a`e673b000 partmgr (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\partmgr.sys\694A94AD2b000\partmgr.sys
- Image path: \SystemRoot\System32\drivers\partmgr.sys
- Image name: partmgr.sys
- Timestamp: Tue Dec 23 08:10:05 2025 (694A94AD)
- CheckSum: 0003332D
- ImageSize: 0002B000
- File version: 10.0.15063.0
- Product version: 10.0.15063.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: partmgr.sys
- OriginalFilename: partmgr.sys
- ProductVersion: 10.0.15063.0
- FileVersion: 10.0.15063.0 (WinBuild.160101.0800)
- FileDescription: Partition driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e6740000 fffff80a`e67d4000 spaceport (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\spaceport.sys\7AD9C5C094000\spaceport.sys
- Image path: \SystemRoot\System32\drivers\spaceport.sys
- Image name: spaceport.sys
- Timestamp: Wed Apr 25 01:38:08 2035 (7AD9C5C0)
- CheckSum: 000914F1
- ImageSize: 00094000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: spaceport.sys
- OriginalFilename: spaceport.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: Storage Spaces Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e67e0000 fffff80a`e67f9000 volmgr (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\volmgr.sys\D713384719000\volmgr.sys
- Image path: \SystemRoot\System32\drivers\volmgr.sys
- Image name: volmgr.sys
- Timestamp: ***** Invalid (D7133847)
- CheckSum: 00020990
- ImageSize: 00019000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: volmgr.sys
- OriginalFilename: volmgr.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: Volume Manager Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e6800000 fffff80a`e685e000 volmgrx (deferred)
- Image path: \SystemRoot\System32\drivers\volmgrx.sys
- Image name: volmgrx.sys
- Timestamp: unavailable (00000000)
- CheckSum: 00000000
- ImageSize: 0005E000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff80a`e6860000 fffff80a`e687e000 mountmgr (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\mountmgr.sys\EA4F8C7B1e000\mountmgr.sys
- Image path: \SystemRoot\System32\drivers\mountmgr.sys
- Image name: mountmgr.sys
- Timestamp: ***** Invalid (EA4F8C7B)
- CheckSum: 00022641
- ImageSize: 0001E000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: mountmgr.sys
- OriginalFilename: mountmgr.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: Mount Point Manager
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e6880000 fffff80a`e69ac000 iaStorE (deferred)
- Image path: \SystemRoot\System32\drivers\iaStorE.sys
- Image name: iaStorE.sys
- Timestamp: Thu Apr 20 12:13:57 2017 (58F8DE45)
- CheckSum: 000FF41C
- ImageSize: 0012C000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff80a`e69b0000 fffff80a`e6a3a000 storport (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\storport.sys\005E8DE48a000\storport.sys
- Image path: \SystemRoot\System32\drivers\storport.sys
- Image name: storport.sys
- Timestamp: Fri Mar 13 13:18:28 1970 (005E8DE4)
- CheckSum: 0008C162
- ImageSize: 0008A000
- File version: 10.0.15063.312
- Product version: 10.0.15063.312
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: storport.sys
- OriginalFilename: storport.sys
- ProductVersion: 10.0.15063.312
- FileVersion: 10.0.15063.312 (WinBuild.160101.0800)
- FileDescription: Microsoft Storage Port Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e6a40000 fffff80a`e6a5c000 EhStorClass (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\EhStorClass.sys\DDF6ADD31c000\EhStorClass.sys
- Image path: \SystemRoot\System32\drivers\EhStorClass.sys
- Image name: EhStorClass.sys
- Timestamp: ***** Invalid (DDF6ADD3)
- CheckSum: 0001B589
- ImageSize: 0001C000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: EhStorClass.sys
- OriginalFilename: EhStorClass.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Enhanced Storage Class driver for IEEE 1667 devices
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e6a60000 fffff80a`e6a7a000 fileinfo (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\fileinfo.sys\885C54141a000\fileinfo.sys
- Image path: \SystemRoot\System32\drivers\fileinfo.sys
- Image name: fileinfo.sys
- Timestamp: ***** Invalid (885C5414)
- CheckSum: 000235B2
- ImageSize: 0001A000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: FileInfo.sys
- OriginalFilename: FileInfo.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: FileInfo Filter Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e6a80000 fffff80a`e6abb000 Wof (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\Wof.sys\07E257913b000\Wof.sys
- Image path: \SystemRoot\System32\Drivers\Wof.sys
- Image name: Wof.sys
- Timestamp: Mon Mar 11 18:47:45 1974 (07E25791)
- CheckSum: 00038B80
- ImageSize: 0003B000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: wof.sys
- OriginalFilename: wof.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Windows Overlay Filter
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e6ac0000 fffff80a`e6d03000 NTFS (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\NTFS.sys\26C2A6E9243000\NTFS.sys
- Image path: \SystemRoot\System32\Drivers\NTFS.sys
- Image name: NTFS.sys
- Timestamp: Fri Aug 10 08:22:01 1990 (26C2A6E9)
- CheckSum: 00244449
- ImageSize: 00243000
- File version: 10.0.15063.442
- Product version: 10.0.15063.442
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: ntfs.sys
- OriginalFilename: ntfs.sys
- ProductVersion: 10.0.15063.442
- FileVersion: 10.0.15063.442 (WinBuild.160101.0800)
- FileDescription: NT File System Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e6d10000 fffff80a`e6d1d000 Fs_Rec (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\Fs_Rec.sys\9836443Cd000\Fs_Rec.sys
- Image path: \SystemRoot\System32\Drivers\Fs_Rec.sys
- Image name: Fs_Rec.sys
- Timestamp: ***** Invalid (9836443C)
- CheckSum: 00012F34
- ImageSize: 0000D000
- File version: 10.0.15052.0
- Product version: 10.0.15052.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: fs_rec.sys
- OriginalFilename: fs_rec.sys
- ProductVersion: 10.0.15052.0
- FileVersion: 10.0.15052.0 (WinBuild.160101.0800)
- FileDescription: File System Recognizer Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e6d20000 fffff80a`e6e56000 ndis (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\ndis.sys\45396ECD136000\ndis.sys
- Image path: \SystemRoot\system32\drivers\ndis.sys
- Image name: ndis.sys
- Timestamp: Fri Oct 20 20:50:21 2006 (45396ECD)
- CheckSum: 00138177
- ImageSize: 00136000
- File version: 10.0.15063.442
- Product version: 10.0.15063.442
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: NDIS.SYS
- OriginalFilename: NDIS.SYS
- ProductVersion: 10.0.15063.442
- FileVersion: 10.0.15063.442 (WinBuild.160101.0800)
- FileDescription: Network Driver Interface Specification (NDIS)
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e6e60000 fffff80a`e6e72000 netbios (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\netbios.sys\93C21EE712000\netbios.sys
- Image path: \SystemRoot\system32\drivers\netbios.sys
- Image name: netbios.sys
- Timestamp: ***** Invalid (93C21EE7)
- CheckSum: 0001A8FF
- ImageSize: 00012000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: NETBIOS.SYS
- OriginalFilename: NETBIOS.SYS
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: NetBIOS interface driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e6e80000 fffff80a`e6e9a000 rspndr (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\rspndr.sys\283736811a000\rspndr.sys
- Image path: \SystemRoot\system32\drivers\rspndr.sys
- Image name: rspndr.sys
- Timestamp: Sun May 19 22:37:53 1991 (28373681)
- CheckSum: 00017DD9
- ImageSize: 0001A000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: RSPNDR.SYS
- OriginalFilename: RSPNDR.SYS
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: Link-Layer Topology Responder Driver for NDIS 6
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e6ea0000 fffff80a`e6f2e000 mcupdate_GenuineIntel (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\mcupdate_GenuineIntel.dll\11F2820A8e000\mcupdate_GenuineIntel.dll
- Image path: \SystemRoot\system32\mcupdate_GenuineIntel.dll
- Image name: mcupdate_GenuineIntel.dll
- Timestamp: Tue Jul 17 20:27:54 1979 (11F2820A)
- CheckSum: 00092CCF
- ImageSize: 0008E000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.A Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: mcupdate.dll
- OriginalFilename: mcupdate_GenuineIntel.dll
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Intel Microcode Update Library
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e6f30000 fffff80a`e6f8f000 msrpc (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\msrpc.sys\16A8209D5f000\msrpc.sys
- Image path: \SystemRoot\System32\drivers\msrpc.sys
- Image name: msrpc.sys
- Timestamp: Sun Jan 17 07:05:49 1982 (16A8209D)
- CheckSum: 0006343C
- ImageSize: 0005F000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: krpcdd.sys
- OriginalFilename: krpcdd.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: Kernel Remote Procedure Call Provider
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e6f90000 fffff80a`e6fb9000 ksecdd (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\ksecdd.sys\85DBC70829000\ksecdd.sys
- Image path: \SystemRoot\System32\drivers\ksecdd.sys
- Image name: ksecdd.sys
- Timestamp: ***** Invalid (85DBC708)
- CheckSum: 000289CA
- ImageSize: 00029000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: ksecdd.sys
- OriginalFilename: ksecdd.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: Kernel Security Support Provider Interface
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e6fc0000 fffff80a`e6fd1000 werkernel (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\werkernel.sys\C3403C4211000\werkernel.sys
- Image path: \SystemRoot\System32\drivers\werkernel.sys
- Image name: werkernel.sys
- Timestamp: ***** Invalid (C3403C42)
- CheckSum: 000160E2
- ImageSize: 00011000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: werkernel
- OriginalFilename: werkernel.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Windows Error Reporting Kernel Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e7000000 fffff80a`e709b000 afd (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\afd.sys\ED6FDF1B9b000\afd.sys
- Image path: \SystemRoot\system32\drivers\afd.sys
- Image name: afd.sys
- Timestamp: ***** Invalid (ED6FDF1B)
- CheckSum: 0009BF2E
- ImageSize: 0009B000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: afd.sys
- OriginalFilename: afd.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: Ancillary Function Driver for WinSock
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e70a0000 fffff80a`e70c9000 pacer (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\pacer.sys\C07DAF1029000\pacer.sys
- Image path: \SystemRoot\System32\drivers\pacer.sys
- Image name: pacer.sys
- Timestamp: ***** Invalid (C07DAF10)
- CheckSum: 0002B1A2
- ImageSize: 00029000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: pacer.sys
- OriginalFilename: pacer.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: QoS Packet Scheduler
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e70d0000 fffff80a`e7155000 NETIO (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\NETIO.SYS\2F813BEF85000\NETIO.SYS
- Image path: \SystemRoot\system32\drivers\NETIO.SYS
- Image name: NETIO.SYS
- Timestamp: Tue Apr 4 08:30:39 1995 (2F813BEF)
- CheckSum: 0008E61A
- ImageSize: 00085000
- File version: 10.0.15063.468
- Product version: 10.0.15063.468
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: netio.sys
- OriginalFilename: netio.sys
- ProductVersion: 10.0.15063.468
- FileVersion: 10.0.15063.468 (WinBuild.160101.0800)
- FileDescription: Network I/O Subsystem
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e7160000 fffff80a`e7190000 ksecpkg (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\ksecpkg.sys\AC6D7E9B30000\ksecpkg.sys
- Image path: \SystemRoot\System32\Drivers\ksecpkg.sys
- Image name: ksecpkg.sys
- Timestamp: ***** Invalid (AC6D7E9B)
- CheckSum: 0002A48F
- ImageSize: 00030000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: ksecpkg.sys
- OriginalFilename: ksecpkg.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: Kernel Security Support Provider Interface Packages
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e7190000 fffff80a`e71e2000 netbt (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\netbt.sys\B2AD25BE52000\netbt.sys
- Image path: \SystemRoot\System32\DRIVERS\netbt.sys
- Image name: netbt.sys
- Timestamp: ***** Invalid (B2AD25BE)
- CheckSum: 00055B39
- ImageSize: 00052000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: netbt.sys
- OriginalFilename: netbt.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: MBT Transport driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e7200000 fffff80a`e72b6000 fvevol (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\fvevol.sys\36B7F511b6000\fvevol.sys
- Image path: \SystemRoot\System32\DRIVERS\fvevol.sys
- Image name: fvevol.sys
- Timestamp: Wed Feb 3 02:04:49 1999 (36B7F511)
- CheckSum: 000B8351
- ImageSize: 000B6000
- File version: 10.0.15061.0
- Product version: 10.0.15061.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: FVEVOL.SYS
- OriginalFilename: FVEVOL.SYS
- ProductVersion: 10.0.15061.0
- FileVersion: 10.0.15061.0 (WinBuild.160101.0800)
- FileDescription: BitLocker Drive Encryption Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e72c0000 fffff80a`e72cb000 volume (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\volume.sys\9CBEE8B7b000\volume.sys
- Image path: \SystemRoot\System32\drivers\volume.sys
- Image name: volume.sys
- Timestamp: ***** Invalid (9CBEE8B7)
- CheckSum: 00012BB5
- ImageSize: 0000B000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: volume.sys
- OriginalFilename: volume.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Volume driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e72d0000 fffff80a`e7334000 volsnap (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\volsnap.sys\DC1CFF9164000\volsnap.sys
- Image path: \SystemRoot\System32\drivers\volsnap.sys
- Image name: volsnap.sys
- Timestamp: ***** Invalid (DC1CFF91)
- CheckSum: 0006B682
- ImageSize: 00064000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: volsnap.sys
- OriginalFilename: volsnap.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: Volume Shadow Copy driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e7340000 fffff80a`e738c000 rdyboost (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\rdyboost.sys\CA830C4C4c000\rdyboost.sys
- Image path: \SystemRoot\System32\drivers\rdyboost.sys
- Image name: rdyboost.sys
- Timestamp: ***** Invalid (CA830C4C)
- CheckSum: 0004E490
- ImageSize: 0004C000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: rdyboost.sys
- OriginalFilename: rdyboost.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: ReadyBoost Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e7390000 fffff80a`e73b4000 mup (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\mup.sys\98323F4C24000\mup.sys
- Image path: \SystemRoot\System32\Drivers\mup.sys
- Image name: mup.sys
- Timestamp: ***** Invalid (98323F4C)
- CheckSum: 0002CA2F
- ImageSize: 00024000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: MUP.SYS
- OriginalFilename: MUP.SYS
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: Multiple UNC Provider Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e73c0000 fffff80a`e73d1000 iorate (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\iorate.sys\510C4C9F11000\iorate.sys
- Image path: \SystemRoot\system32\drivers\iorate.sys
- Image name: iorate.sys
- Timestamp: Fri Feb 1 18:15:43 2013 (510C4C9F)
- CheckSum: 00019E81
- ImageSize: 00011000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: iorate.sys
- OriginalFilename: iorate.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: I/O rate control Filter
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e73f0000 fffff80a`e740e000 disk (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\disk.sys\49CE6E681e000\disk.sys
- Image path: \SystemRoot\System32\drivers\disk.sys
- Image name: disk.sys
- Timestamp: Sat Mar 28 14:37:28 2009 (49CE6E68)
- CheckSum: 0001E637
- ImageSize: 0001E000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: disk.sys
- OriginalFilename: disk.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: PnP Disk Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e7410000 fffff80a`e7475000 CLASSPNP (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\CLASSPNP.SYS\2A05694965000\CLASSPNP.SYS
- Image path: \SystemRoot\System32\drivers\CLASSPNP.SYS
- Image name: CLASSPNP.SYS
- Timestamp: Mon May 4 12:41:45 1992 (2A056949)
- CheckSum: 0006CAEA
- ImageSize: 00065000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: Classpnp.sys
- OriginalFilename: Classpnp.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: SCSI Class System Dll
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e7480000 fffff80a`e748e000 aswbuniva (deferred)
- Image path: \SystemRoot\system32\drivers\aswbuniva.sys
- Image name: aswbuniva.sys
- Timestamp: Tue Jun 6 12:14:23 2017 (5936D4DF)
- CheckSum: 0001C94C
- ImageSize: 0000E000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff80a`e7490000 fffff80a`e74e0000 aswbloga (deferred)
- Image path: \SystemRoot\system32\drivers\aswbloga.sys
- Image name: aswbloga.sys
- Timestamp: Tue Jun 6 12:14:26 2017 (5936D4E2)
- CheckSum: 00058A07
- ImageSize: 00050000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff80a`e74e0000 fffff80a`e750f000 aswbidsha (deferred)
- Image path: \SystemRoot\system32\drivers\aswbidsha.sys
- Image name: aswbidsha.sys
- Timestamp: Tue Jun 6 12:14:33 2017 (5936D4E9)
- CheckSum: 00036223
- ImageSize: 0002F000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff80a`e7530000 fffff80a`e754b000 crashdmp (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\crashdmp.sys\2C13F6811b000\crashdmp.sys
- Image path: \SystemRoot\System32\Drivers\crashdmp.sys
- Image name: crashdmp.sys
- Timestamp: Mon Jun 7 22:16:33 1993 (2C13F681)
- CheckSum: 0001EF18
- ImageSize: 0001B000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: crashdmp.sys
- OriginalFilename: crashdmp.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: Crash Dump Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e7550000 fffff80a`e767c000 dump_iaStorE (deferred)
- Image path: \SystemRoot\System32\Drivers\dump_iaStorE.sys
- Image name: dump_iaStorE.sys
- Timestamp: Thu Apr 20 12:13:57 2017 (58F8DE45)
- CheckSum: 000FF41C
- ImageSize: 0012C000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff80a`e7680000 fffff80a`e7733000 dxgmms2 (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\dxgmms2.sys\ABB616E9b3000\dxgmms2.sys
- Image path: \SystemRoot\System32\drivers\dxgmms2.sys
- Image name: dxgmms2.sys
- Timestamp: ***** Invalid (ABB616E9)
- CheckSum: 000AE8C9
- ImageSize: 000B3000
- File version: 10.0.15063.312
- Product version: 10.0.15063.312
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: dxgmms2.sys
- OriginalFilename: dxgmms2.sys
- ProductVersion: 10.0.15063.312
- FileVersion: 10.0.15063.312 (WinBuild.160101.0800)
- FileDescription: DirectX Graphics MMS
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e7740000 fffff80a`e7767000 aswMonFlt (deferred)
- Image path: \SystemRoot\system32\drivers\aswMonFlt.sys
- Image name: aswMonFlt.sys
- Timestamp: Thu Jun 22 18:45:03 2017 (594C486F)
- CheckSum: 0002ED17
- ImageSize: 00027000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff80a`e7770000 fffff80a`e77a1000 aswStm (deferred)
- Image path: \SystemRoot\system32\drivers\aswStm.sys
- Image name: aswStm.sys
- Timestamp: Mon Jun 19 18:56:07 2017 (59485687)
- CheckSum: 00030C56
- ImageSize: 00031000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff80a`e77b0000 fffff80a`e77c6000 lltdio (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\lltdio.sys\DD62481516000\lltdio.sys
- Image path: \SystemRoot\system32\drivers\lltdio.sys
- Image name: lltdio.sys
- Timestamp: ***** Invalid (DD624815)
- CheckSum: 000188CA
- ImageSize: 00016000
- File version: 10.0.15052.0
- Product version: 10.0.15052.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: LLTDIO.SYS
- OriginalFilename: LLTDIO.SYS
- ProductVersion: 10.0.15052.0
- FileVersion: 10.0.15052.0 (WinBuild.160101.0800)
- FileDescription: Link-Layer Topology Mapper I/O Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e77d0000 fffff80a`e77ea000 mslldp (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\mslldp.sys\C33AB00E1a000\mslldp.sys
- Image path: \SystemRoot\system32\drivers\mslldp.sys
- Image name: mslldp.sys
- Timestamp: ***** Invalid (C33AB00E)
- CheckSum: 00016E1F
- ImageSize: 0001A000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: MSLLDP.SYS
- OriginalFilename: MSLLDP.SYS
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: Microsoft Link-Layer Discovery Protocol Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e77f0000 fffff80a`e780b000 wanarp (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\wanarp.sys\1754996C1b000\wanarp.sys
- Image path: \SystemRoot\System32\DRIVERS\wanarp.sys
- Image name: wanarp.sys
- Timestamp: Fri May 28 03:51:08 1982 (1754996C)
- CheckSum: 00019288
- ImageSize: 0001B000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: WANARP.SYS
- OriginalFilename: WANARP.SYS
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: MS Remote Access and Routing ARP Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e7810000 fffff80a`e783e000 cdrom (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\cdrom.sys\04CCA32D2e000\cdrom.sys
- Image path: \SystemRoot\System32\drivers\cdrom.sys
- Image name: cdrom.sys
- Timestamp: Thu Jul 20 18:39:41 1972 (04CCA32D)
- CheckSum: 00036ABC
- ImageSize: 0002E000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: cdrom.sys
- OriginalFilename: cdrom.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: SCSI CD-ROM Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e7840000 fffff80a`e78f1000 aswSP (deferred)
- Image path: \SystemRoot\system32\drivers\aswSP.sys
- Image name: aswSP.sys
- Timestamp: Thu Jun 22 18:45:26 2017 (594C4886)
- CheckSum: 00099882
- ImageSize: 000B1000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff80a`e7900000 fffff80a`e79f6000 aswSnx (deferred)
- Image path: \SystemRoot\system32\drivers\aswSnx.sys
- Image name: aswSnx.sys
- Timestamp: Mon Jun 19 18:37:45 2017 (59485239)
- CheckSum: 000F9C99
- ImageSize: 000F6000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff80a`e7a00000 fffff80a`e7a67000 ks (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\ks.sys\12A4A31867000\ks.sys
- Image path: \SystemRoot\system32\drivers\ks.sys
- Image name: ks.sys
- Timestamp: Thu Nov 29 22:12:24 1979 (12A4A318)
- CheckSum: 00068D97
- ImageSize: 00067000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.0 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: ks.sys
- OriginalFilename: ks.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: Kernel CSA Library
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e7a70000 fffff80a`e7a84000 filecrypt (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\filecrypt.sys\719E181314000\filecrypt.sys
- Image path: \SystemRoot\system32\drivers\filecrypt.sys
- Image name: filecrypt.sys
- Timestamp: Tue May 28 04:10:59 2030 (719E1813)
- CheckSum: 0001B03D
- ImageSize: 00014000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: filecrypt.sys
- OriginalFilename: filecrypt.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Windows sandboxing and encryption filter
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e7a90000 fffff80a`e7a9d000 tbs (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\tbs.sys\6C444C9Bd000\tbs.sys
- Image path: \SystemRoot\system32\drivers\tbs.sys
- Image name: tbs.sys
- Timestamp: Sat Jul 24 03:49:47 2027 (6C444C9B)
- CheckSum: 00007016
- ImageSize: 0000D000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: TBS.SYS
- OriginalFilename: TBS.SYS
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Export driver for kernel mode TPM API
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e7aa0000 fffff80a`e7aaa000 Null (deferred)
- Image path: \SystemRoot\System32\Drivers\Null.SYS
- Image name: Null.SYS
- Timestamp: unavailable (00000000)
- CheckSum: 00000000
- ImageSize: 0000A000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff80a`e7ab0000 fffff80a`e7aba000 Beep (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\Beep.SYS\A94A035Ea000\Beep.SYS
- Image path: \SystemRoot\System32\Drivers\Beep.SYS
- Image name: Beep.SYS
- Timestamp: ***** Invalid (A94A035E)
- CheckSum: 0000B8DE
- ImageSize: 0000A000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: beep.sys
- OriginalFilename: beep.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: BEEP Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e7ac0000 fffff80a`e7ad5000 BasicDisplay (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\BasicDisplay.sys\E7A205B415000\BasicDisplay.sys
- Image path: \SystemRoot\System32\drivers\BasicDisplay.sys
- Image name: BasicDisplay.sys
- Timestamp: ***** Invalid (E7A205B4)
- CheckSum: 000178AD
- ImageSize: 00015000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.4 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: BasicDisplay.sys
- OriginalFilename: BasicDisplay.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Microsoft Basic Display Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e7ae0000 fffff80a`e7af4000 watchdog (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\watchdog.sys\DFC4C1CD14000\watchdog.sys
- Image path: \SystemRoot\System32\drivers\watchdog.sys
- Image name: watchdog.sys
- Timestamp: ***** Invalid (DFC4C1CD)
- CheckSum: 0001BE1C
- ImageSize: 00014000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: watchdog.sys
- OriginalFilename: watchdog.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: Watchdog Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e7b00000 fffff80a`e7d5a000 dxgkrnl (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\dxgkrnl.sys\DE0AC79A25a000\dxgkrnl.sys
- Image path: \SystemRoot\System32\drivers\dxgkrnl.sys
- Image name: dxgkrnl.sys
- Timestamp: ***** Invalid (DE0AC79A)
- CheckSum: 00260856
- ImageSize: 0025A000
- File version: 10.0.15063.481
- Product version: 10.0.15063.481
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: dxgkrnl.sys
- OriginalFilename: dxgkrnl.sys
- ProductVersion: 10.0.15063.481
- FileVersion: 10.0.15063.481 (WinBuild.160101.0800)
- FileDescription: DirectX Graphics Kernel
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e7d60000 fffff80a`e7d7a000 vmbkmclr (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\vmbkmclr.sys\2CD1D7AA1a000\vmbkmclr.sys
- Image path: \SystemRoot\System32\drivers\vmbkmclr.sys
- Image name: vmbkmclr.sys
- Timestamp: Fri Oct 29 22:55:38 1993 (2CD1D7AA)
- CheckSum: 0001B34D
- ImageSize: 0001A000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: vmbkmclr.sys
- OriginalFilename: vmbkmclr.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Hyper-V VMBus Root KMCL
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e7d80000 fffff80a`e7d90000 BasicRender (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\BasicRender.sys\4692B90410000\BasicRender.sys
- Image path: \SystemRoot\System32\drivers\BasicRender.sys
- Image name: BasicRender.sys
- Timestamp: Mon Jul 9 18:39:00 2007 (4692B904)
- CheckSum: 000185B7
- ImageSize: 00010000
- File version: 10.0.15063.409
- Product version: 10.0.15063.409
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.4 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: BasicRender.sys
- OriginalFilename: BasicRender.sys
- ProductVersion: 10.0.15063.409
- FileVersion: 10.0.15063.409 (WinBuild.160101.0800)
- FileDescription: Microsoft Basic Render Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e7d90000 fffff80a`e7da9000 Npfs (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\Npfs.SYS\71DCD8D919000\Npfs.SYS
- Image path: \SystemRoot\System32\Drivers\Npfs.SYS
- Image name: Npfs.SYS
- Timestamp: Sun Jul 14 18:34:01 2030 (71DCD8D9)
- CheckSum: 00012322
- ImageSize: 00019000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: npfs.sys
- OriginalFilename: npfs.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: NPFS Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e7db0000 fffff80a`e7dc0000 Msfs (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\Msfs.SYS\39F56D6310000\Msfs.SYS
- Image path: \SystemRoot\System32\Drivers\Msfs.SYS
- Image name: Msfs.SYS
- Timestamp: Tue Oct 24 07:07:15 2000 (39F56D63)
- CheckSum: 0000C5C3
- ImageSize: 00010000
- File version: 10.0.15052.0
- Product version: 10.0.15052.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: MSFS.SYS
- OriginalFilename: MSFS.SYS
- ProductVersion: 10.0.15052.0
- FileVersion: 10.0.15052.0 (WinBuild.160101.0800)
- FileDescription: Mailslot driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e7dc0000 fffff80a`e7de2000 tdx (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\tdx.sys\92AD75A722000\tdx.sys
- Image path: \SystemRoot\system32\DRIVERS\tdx.sys
- Image name: tdx.sys
- Timestamp: ***** Invalid (92AD75A7)
- CheckSum: 00026155
- ImageSize: 00022000
- File version: 10.0.15063.409
- Product version: 10.0.15063.409
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: tdx.sys
- OriginalFilename: tdx.sys
- ProductVersion: 10.0.15063.409
- FileVersion: 10.0.15063.409 (WinBuild.160101.0800)
- FileDescription: TDI Translation Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e7df0000 fffff80a`e808c000 tcpip (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\tcpip.sys\35A110E029c000\tcpip.sys
- Image path: \SystemRoot\System32\drivers\tcpip.sys
- Image name: tcpip.sys
- Timestamp: Mon Jul 6 14:01:04 1998 (35A110E0)
- CheckSum: 00295C38
- ImageSize: 0029C000
- File version: 10.0.15063.442
- Product version: 10.0.15063.442
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: tcpip.sys
- OriginalFilename: tcpip.sys
- ProductVersion: 10.0.15063.442
- FileVersion: 10.0.15063.442 (WinBuild.160101.0800)
- FileDescription: TCP/IP Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e8090000 fffff80a`e80fa000 fwpkclnt (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\fwpkclnt.sys\36B0062A6a000\fwpkclnt.sys
- Image path: \SystemRoot\System32\drivers\fwpkclnt.sys
- Image name: fwpkclnt.sys
- Timestamp: Thu Jan 28 01:39:38 1999 (36B0062A)
- CheckSum: 0006ABB4
- ImageSize: 0006A000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: fwpkclnt.sys
- OriginalFilename: fwpkclnt.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: FWP/IPsec Kernel-Mode API
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e8100000 fffff80a`e812c000 wfplwfs (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\wfplwfs.sys\4BBA3B962c000\wfplwfs.sys
- Image path: \SystemRoot\System32\drivers\wfplwfs.sys
- Image name: wfplwfs.sys
- Timestamp: Mon Apr 5 15:35:50 2010 (4BBA3B96)
- CheckSum: 00033C97
- ImageSize: 0002C000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: WFPLWFS.SYS
- OriginalFilename: WFPLWFS.SYS
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: WFP NDIS 6.30 Lightweight Filter Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e8130000 fffff80a`e8186000 aswVmm (deferred)
- Image path: \SystemRoot\system32\drivers\aswVmm.sys
- Image name: aswVmm.sys
- Timestamp: Thu Jun 29 10:44:20 2017 (59551244)
- CheckSum: 0005CA69
- ImageSize: 00056000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff80a`e8190000 fffff80a`e81a3000 aswRvrt (deferred)
- Image path: \SystemRoot\system32\drivers\aswRvrt.sys
- Image name: aswRvrt.sys
- Timestamp: Mon Jun 19 18:37:16 2017 (5948521C)
- CheckSum: 00023CE1
- ImageSize: 00013000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff80a`e81b0000 fffff80a`e81c0000 TDI (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\TDI.SYS\D2C3B05910000\TDI.SYS
- Image path: \SystemRoot\system32\DRIVERS\TDI.SYS
- Image name: TDI.SYS
- Timestamp: ***** Invalid (D2C3B059)
- CheckSum: 0000FA4A
- ImageSize: 00010000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: tdi.sys
- OriginalFilename: tdi.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: TDI Wrapper
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e81c0000 fffff80a`e81da000 aswRdr2 (deferred)
- Image path: \SystemRoot\system32\drivers\aswRdr2.sys
- Image name: aswRdr2.sys
- Timestamp: Mon Jun 19 18:37:38 2017 (59485232)
- CheckSum: 000221F7
- ImageSize: 0001A000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff80a`e81e0000 fffff80a`e81fa000 vwififlt (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\vwififlt.sys\7575D0541a000\vwififlt.sys
- Image path: \SystemRoot\System32\drivers\vwififlt.sys
- Image name: vwififlt.sys
- Timestamp: Sat Jun 12 08:15:16 2032 (7575D054)
- CheckSum: 000177F5
- ImageSize: 0001A000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: vwififlt.sys
- OriginalFilename: vwififlt.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Virtual WiFi Filter Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e8400000 fffff80a`e8419000 storqosflt (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\storqosflt.sys\56737F3B19000\storqosflt.sys
- Image path: \SystemRoot\system32\drivers\storqosflt.sys
- Image name: storqosflt.sys
- Timestamp: Thu Dec 17 22:36:27 2015 (56737F3B)
- CheckSum: 00016F44
- ImageSize: 00019000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: storqosflt.sys
- OriginalFilename: storqosflt.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Storage QoS Filter
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e8420000 fffff80a`e8470000 aswbidsdrivera (deferred)
- Image path: \SystemRoot\system32\drivers\aswbidsdrivera.sys
- Image name: aswbidsdrivera.sys
- Timestamp: Tue Jun 6 12:14:24 2017 (5936D4E0)
- CheckSum: 0005E1C4
- ImageSize: 00050000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff80a`e8470000 fffff80a`e8476000 AsIO (deferred)
- Image path: \SystemRoot\SysWow64\drivers\AsIO.sys
- Image name: AsIO.sys
- Timestamp: Wed Aug 22 05:54:47 2012 (5034AC67)
- CheckSum: 0000EA4F
- ImageSize: 00006000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff80a`e8480000 fffff80a`e84c1000 ahcache (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\ahcache.sys\410882A241000\ahcache.sys
- Image path: \SystemRoot\system32\DRIVERS\ahcache.sys
- Image name: ahcache.sys
- Timestamp: Thu Jul 29 00:52:50 2004 (410882A2)
- CheckSum: 00045EB6
- ImageSize: 00041000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: ahcache.sys
- OriginalFilename: ahcache.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: Application Compatibility Cache
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e84d0000 fffff80a`e84e1000 CompositeBus (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\CompositeBus.sys\A29FEBD911000\CompositeBus.sys
- Image path: \SystemRoot\System32\DriverStore\FileRepository\compositebus.inf_amd64_de4c68ea4fb1be53\CompositeBus.sys
- Image name: CompositeBus.sys
- Timestamp: ***** Invalid (A29FEBD9)
- CheckSum: 0000BFAF
- ImageSize: 00011000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: compositebus.sys
- OriginalFilename: compositebus.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Multi-Transport Composite Bus Enumerator
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e84f0000 fffff80a`e84fd000 kdnic (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\kdnic.sys\E88EF29Ad000\kdnic.sys
- Image path: \SystemRoot\System32\drivers\kdnic.sys
- Image name: kdnic.sys
- Timestamp: ***** Invalid (E88EF29A)
- CheckSum: 00012EF1
- ImageSize: 0000D000
- File version: 6.1.0.0
- Product version: 6.1.0.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0000.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft Kernel Debugger Network Adapter (NDIS 6.20 Miniport)
- InternalName: kdnic.sys
- OriginalFilename: kdnic.sys
- ProductVersion: 6.01.00.0000
- FileVersion: 6.01.00.0000 (WinBuild.160101.0800)
- FileDescription: Microsoft Kernel Debugger Network Miniport
- LegalCopyright: Copyright (C) Microsoft Corporation. All rights reserved.
- fffff80a`e8500000 fffff80a`e8515000 umbus (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\umbus.sys\6863F00915000\umbus.sys
- Image path: \SystemRoot\System32\drivers\umbus.sys
- Image name: umbus.sys
- Timestamp: Tue Jul 1 10:26:17 2025 (6863F009)
- CheckSum: 0001604F
- ImageSize: 00015000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 2.0 Dll
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: umbus.sys
- OriginalFilename: umbus.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: User-Mode Bus Enumerator
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e8520000 fffff80a`e85a3000 atikmpag (deferred)
- Image path: \SystemRoot\System32\DriverStore\FileRepository\c0315940.inf_amd64_2b462f080682210e\atikmpag.sys
- Image name: atikmpag.sys
- Timestamp: Tue Jul 4 17:48:49 2017 (595C0D41)
- CheckSum: 0008F67A
- ImageSize: 00083000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff80a`e85b0000 fffff80a`e89ea000 athw10x (deferred)
- Image path: \SystemRoot\System32\drivers\athw10x.sys
- Image name: athw10x.sys
- Timestamp: Mon Apr 17 01:38:20 2017 (58F454CC)
- CheckSum: 00427F79
- ImageSize: 0043A000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff80a`e89f0000 fffff80a`e8a16000 luafv (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\luafv.sys\7ED7BCAF26000\luafv.sys
- Image path: \SystemRoot\system32\drivers\luafv.sys
- Image name: luafv.sys
- Timestamp: Mon Jun 8 05:55:59 2037 (7ED7BCAF)
- CheckSum: 00027EE2
- ImageSize: 00026000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: luafv.sys
- OriginalFilename: luafv.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: LUA File Virtualization Filter Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e8a20000 fffff80a`e8a46000 wcifs (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\wcifs.sys\CE08A39126000\wcifs.sys
- Image path: \SystemRoot\system32\drivers\wcifs.sys
- Image name: wcifs.sys
- Timestamp: ***** Invalid (CE08A391)
- CheckSum: 0003046A
- ImageSize: 00026000
- File version: 10.0.15063.442
- Product version: 10.0.15063.442
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: wcifs.sys
- OriginalFilename: wcifs.sys
- ProductVersion: 10.0.15063.442
- FileVersion: 10.0.15063.442 (WinBuild.160101.0800)
- FileDescription: Windows Container Isolation FS Filter Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e8a60000 fffff80a`e8ad5000 rdbss (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\rdbss.sys\E291A5CA75000\rdbss.sys
- Image path: \SystemRoot\system32\DRIVERS\rdbss.sys
- Image name: rdbss.sys
- Timestamp: ***** Invalid (E291A5CA)
- CheckSum: 000792B0
- ImageSize: 00075000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: rdbss.sys
- OriginalFilename: RDBSS.Sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: Redirected Drive Buffering SubSystem Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e8ae0000 fffff80a`e8b6f000 csc (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\csc.sys\7EFA9C6D8f000\csc.sys
- Image path: \SystemRoot\system32\drivers\csc.sys
- Image name: csc.sys
- Timestamp: Sat Jul 4 16:47:41 2037 (7EFA9C6D)
- CheckSum: 0008D9D8
- ImageSize: 0008F000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: csc.sys
- OriginalFilename: CSC.Sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: Windows Client Side Caching Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e8b70000 fffff80a`e8b81000 nsiproxy (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\nsiproxy.sys\E796A4DD11000\nsiproxy.sys
- Image path: \SystemRoot\system32\drivers\nsiproxy.sys
- Image name: nsiproxy.sys
- Timestamp: ***** Invalid (E796A4DD)
- CheckSum: 0001247A
- ImageSize: 00011000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: nsiproxy.sys
- OriginalFilename: nsiproxy.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: NSI Proxy
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e8b90000 fffff80a`e8b9f000 npsvctrig (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\npsvctrig.sys\EFF190DDf000\npsvctrig.sys
- Image path: \SystemRoot\System32\drivers\npsvctrig.sys
- Image name: npsvctrig.sys
- Timestamp: ***** Invalid (EFF190DD)
- CheckSum: 00009E31
- ImageSize: 0000F000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: npsvctrig.sys
- OriginalFilename: npsvctrig.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: Named pipe service triggers
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e8ba0000 fffff80a`e8bb0000 mssmbios (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\mssmbios.sys\BC4E1F4C10000\mssmbios.sys
- Image path: \SystemRoot\System32\drivers\mssmbios.sys
- Image name: mssmbios.sys
- Timestamp: ***** Invalid (BC4E1F4C)
- CheckSum: 0000F528
- ImageSize: 00010000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: smbios.sys
- OriginalFilename: smbios.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: System Management BIOS Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e8bb0000 fffff80a`e8bba000 HWiNFO64A (deferred)
- Image path: \??\C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS
- Image name: HWiNFO64A.SYS
- Timestamp: Tue Mar 31 05:51:32 2015 (551A6E24)
- CheckSum: 0000DE1E
- ImageSize: 0000A000
- Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
- fffff80a`e8bc0000 fffff80a`e8bca000 gpuenergydrv (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\gpuenergydrv.sys\05622075a000\gpuenergydrv.sys
- Image path: \SystemRoot\System32\drivers\gpuenergydrv.sys
- Image name: gpuenergydrv.sys
- Timestamp: Sat Nov 11 03:01:57 1972 (05622075)
- CheckSum: 0000429A
- ImageSize: 0000A000
- File version: 10.0.15046.0
- Product version: 10.0.15046.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: gpuenergydrv.sys
- OriginalFilename: gpuenergydrv.sys
- ProductVersion: 10.0.15046.0
- FileVersion: 10.0.15046.0 (WinBuild.160101.0800)
- FileDescription: GPU Energy Kernel Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- fffff80a`e8bd0000 fffff80a`e8bfb000 dfsc (deferred)
- Mapped memory image file: C:\ProgramData\dbg\sym\dfsc.sys\640317972b000\dfsc.sys
- Image path: \SystemRoot\System32\Drivers\dfsc.sys
- Image name: dfsc.sys
- Timestamp: Sat Mar 4 05:04:07 2023 (64031797)
- CheckSum: 00032C04
- ImageSize: 0002B000
- File version: 10.0.15058.0
- Product version: 10.0.15058.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- Translations: 0409.04b0
- CompanyName: Microsoft Corporation
- ProductName: Microsoft® Windows® Operating System
- InternalName: dfsclient.sys
- OriginalFilename: dfsclient.sys
- ProductVersion: 10.0.15058.0
- FileVersion: 10.0.15058.0 (WinBuild.160101.0800)
- FileDescription: DFS Namespace Client Driver
- LegalCopyright: © Microsoft Corporation. All rights reserved.
- Unloaded modules:
- fffff803`40400000 fffff803`404af000 BEDaisy.sys
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 000AF000
- fffff803`40b10000 fffff803`40bbf000 BEDaisy.sys
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 000AF000
- fffff803`43950000 fffff803`4395b000 cldflt.sys
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 0000B000
- fffff80a`e7560000 fffff80a`e756f000 dump_storpor
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 0000F000
- fffff80a`e76a0000 fffff80a`e77cc000 dump_iaStorE
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 0012C000
- fffff80a`e77f0000 fffff80a`e780d000 dump_dumpfve
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 0001D000
- fffff803`3ba10000 fffff803`3ba4d000 WUDFRd.sys
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 0003D000
- fffff803`43950000 fffff803`4395a000 amdkmafd.sys
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 0000A000
- fffff80a`e8400000 fffff80a`e8420000 dam.sys
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 00020000
- fffff80a`e73e0000 fffff80a`e73ef000 hwpolicy.sys
- Timestamp: unavailable (00000000)
- Checksum: 00000000
- ImageSize: 0000F000
- ------------------------------ BIOS INFO -------------------------------
- [SMBIOS Data Tables v2.7]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 3070 bytes]
- [BIOS Information (Type 0) - Length 24 - Handle 0000h]
- Vendor American Megatrends Inc.
- BIOS Version 2201
- BIOS Starting Address Segment f000
- BIOS Release Date 06/25/2015
- BIOS ROM Size 1000000
- BIOS Characteristics
- 07: - PCI Supported
- 10: - APM Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 27: - Keyboard Services Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 32: - BIOS Vendor Reserved
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 4
- BIOS Minor Revision 6
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- Manufacturer ASUS
- Product Name All Series
- Version System Version
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- SKUNumber All
- Family ASUS MB
- [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
- Manufacturer ASUSTeK COMPUTER INC.
- Product B85M-G R2.0
- Version Rev X.0x
- Feature Flags 09h
- 98285280: - 98285328: - ?¿Ï#
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 22 - Handle 0003h]
- Manufacturer Chassis Manufacture
- Chassis Type Desktop
- Version Chassis Version
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 0
- [Onboard Devices Information (Type 10) - Length 8 - Handle 0021h]
- Number of Devices 2
- 01: Type Ethernet [enabled]
- 01: Description Onboard Ethernet
- 02: Type Sound [enabled]
- 02: Description Onboard Audio
- [OEM Strings (Type 11) - Length 5 - Handle 0022h]
- Number of Strings 4
- 3 AB85
- [System Configuration Options (Type 12) - Length 5 - Handle 0023h]
- [Memory Device (Type 17) - Length 34 - Handle 003fh]
- Physical Memory Array Handle 0040h
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM0
- Bank Locator BANK 0
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- Manufacturer [Empty]
- Part Number [Empty]
- [Physical Memory Array (Type 16) - Length 23 - Handle 0040h]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 33554432KB
- Number of Memory Devices 4
- [Memory Device (Type 17) - Length 34 - Handle 0041h]
- Physical Memory Array Handle 0040h
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM1
- Bank Locator BANK 1
- Memory Type 18h - Specification Reserved
- Type Detail 0080h - Synchronous
- Speed 1600MHz
- Manufacturer Kingston
- Part Number KHX1600C10D3/8G
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0042h]
- Starting Address 00000000h
- Ending Address 007fffffh
- Memory Device Handle 0041h
- Mem Array Mapped Adr Handle 0046h
- [Memory Device (Type 17) - Length 34 - Handle 0043h]
- Physical Memory Array Handle 0040h
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM0
- Bank Locator BANK 2
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- Manufacturer [Empty]
- Part Number [Empty]
- [Memory Device (Type 17) - Length 34 - Handle 0044h]
- Physical Memory Array Handle 0040h
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM1
- Bank Locator BANK 3
- Memory Type 18h - Specification Reserved
- Type Detail 0080h - Synchronous
- Speed 1600MHz
- Manufacturer Kingston
- Part Number KHX1600C10D3/8G
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0045h]
- Starting Address 00800000h
- Ending Address 00ffffffh
- Memory Device Handle 0044h
- Mem Array Mapped Adr Handle 0046h
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0046h]
- Starting Address 00000000h
- Ending Address 00ffffffh
- Memory Array Handle 0040h
- Partition Width 04
- [Cache Information (Type 7) - Length 19 - Handle 0047h]
- Socket Designation CPU Internal L1
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0100h - 256K
- Installed Size 0100h - 256K
- Supported SRAM Type 0002h - Unknown
- Current SRAM Type 0002h - Unknown
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Other
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0048h]
- Socket Designation CPU Internal L2
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 0400h - 1024K
- Installed Size 0400h - 1024K
- Supported SRAM Type 0002h - Unknown
- Current SRAM Type 0002h - Unknown
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0049h]
- Socket Designation CPU Internal L3
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 1800h - 6144K
- Installed Size 1800h - 6144K
- Supported SRAM Type 0002h - Unknown
- Current SRAM Type 0002h - Unknown
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Unified
- Associativity Specification Reserved
- [Processor Information (Type 4) - Length 42 - Handle 004dh]
- Socket Designation SOCKET 1150
- Processor Type Central Processor
- Processor Family 01h - Other
- Processor Manufacturer Intel
- Processor ID c3060300fffbebbf
- Processor Version Intel(R) Core(TM) i5-4460 CPU @ 3.20GHz
- Processor Voltage 8ch - 1.2V
- External Clock 100MHz
- Max Speed 3900MHz
- Current Speed 3208MHz
- Status Enabled Populated
- Processor Upgrade Specification Reserved
- L1 Cache Handle 0047h
- L2 Cache Handle 0048h
- L3 Cache Handle 0049h
- Part Number Fill By OEM
- 1: kd> q
- quit:
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement