Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ========================== AUTO DUMP ANALYZER ==========================
- Auto Dump Analyzer
- Version: 0.91
- Time to analyze file(s): 00 hours and 10 minutes and 22 seconds
- ================================= CPU ==================================
- COUNT: 10
- MHZ: 3593
- VENDOR: AuthenticAMD
- FAMILY: 17
- MODEL: 71
- STEPPING: 0
- ================================== OS ==================================
- Product: WinNt, suite: TerminalServer SingleUserTS
- Built by: 18362.1.amd64fre.19h1_release.190318-1202
- BUILD_VERSION: 10.0.18362.1256 (WinBuild.160101.0800)
- BUILD: 18362
- SERVICEPACK: 1256
- PLATFORM_TYPE: x64
- NAME: Windows 10
- EDITION: Windows 10 WinNt TerminalServer SingleUserTS
- BUILD_TIMESTAMP: unknown_date
- BUILDDATESTAMP: 160101.0800
- BUILDLAB: WinBuild
- BUILDOSVER: 10.0.18362.1256
- BUILD_VERSION: 10.0.18362.1198 (WinBuild.160101.0800)
- SERVICEPACK: 1198
- BUILD_TIMESTAMP: 1981-09-10 19:55:31
- BUILDOSVER: 10.0.18362.1198
- BUILD_VERSION: 10.0.18362.1 (WinBuild.160101.0800)
- SERVICEPACK: 1
- BUILD_TIMESTAMP: 1970-06-25 11:20:15
- BUILDOSVER: 10.0.18362.1
- =============================== DEBUGGER ===============================
- Microsoft (R) Windows Debugger Version 10.0.14321.1024 AMD64
- Copyright (c) Microsoft Corporation. All rights reserved.
- =============================== COMMENTS ===============================
- * Information gathered from different dump files may be different. If
- Windows updates between two dump files, two or more OS versions may
- be shown above.
- * Additional BIOS information was not included in the dump file(s). This
- can be caused by an outdated BIOS.
- ========================================================================
- ======================= Dump #1: ANALYZE VERBOSE =======================
- ====================== File: 121620-10437-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 18362 MP (16 procs) Free x64
- Kernel base = 0xfffff800`2dc00000 PsLoadedModuleList = 0xfffff800`2e0461b0
- Debug session time: Wed Dec 16 08:00:51.791 2020 (UTC - 5:00)
- System Uptime: 0 days 0:05:30.445
- BugCheck D1, {fffff80000400a02, ff, 0, fffff80000400a02}
- *** WARNING: Unable to verify timestamp for win32k.sys
- *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
- Probably caused by : memory_corruption
- Followup: memory_corruption
- DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
- An attempt was made to access a pageable (or completely invalid) address at an
- interrupt request level (IRQL) that is too high. This is usually
- caused by drivers using improper addresses.
- If kernel debugger is available get stack backtrace.
- Arguments:
- Arg1: fffff80000400a02, memory referenced
- Arg2: 00000000000000ff, IRQL
- Arg3: 0000000000000000, value 0 = read operation, 1 = write operation
- Arg4: fffff80000400a02, address which referenced memory
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- READ_ADDRESS: fffff8002e1713b8: Unable to get MiVisibleState
- fffff80000400a02
- CURRENT_IRQL: 0
- FAULTING_IP:
- +0
- fffff800`00400a02 ?? ???
- ADDITIONAL_DEBUG_TEXT: The trap occurred when interrupts are disabled on the target.
- BUGCHECK_STR: DISABLED_INTERRUPT_FAULT
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- PROCESS_NAME: System
- TRAP_FRAME: ffff838dc1237520 -- (.trap 0xffff838dc1237520)
- NOTE: The trap frame does not contain all registers.
- Some register values may be zeroed or incorrect.
- rax=fffff80000400a02 rbx=0000000000000000 rcx=ffffbf045fe3fa10
- rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
- rip=fffff80000400a02 rsp=ffff838dc12376b8 rbp=0000000000000200
- r8=ffff838dc1237720 r9=ffff838dc1237710 r10=0000fffff8000040
- r11=ffffd77cbec00000 r12=0000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=0000000000000000
- iopl=0 nv up di pl nz na pe nc
- fffff800`00400a02 ?? ???
- Resetting default scope
- LAST_CONTROL_TRANSFER: from fffff8002ddd5929 to fffff8002ddc3b20
- FAILED_INSTRUCTION_ADDRESS:
- +0
- fffff800`00400a02 ?? ???
- STACK_TEXT:
- ffff838d`c12373d8 fffff800`2ddd5929 : 00000000`0000000a fffff800`00400a02 00000000`000000ff 00000000`00000000 : nt!KeBugCheckEx
- ffff838d`c12373e0 fffff800`2ddd1c69 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
- ffff838d`c1237520 fffff800`00400a02 : fffff800`3c789841 ffffbf04`5fd90770 00000000`00000004 ffff838d`c123762c : nt!KiPageFault+0x469
- ffff838d`c12376b8 fffff800`3c789841 : ffffbf04`5fd90770 00000000`00000004 ffff838d`c123762c 00000000`00000004 : 0xfffff800`00400a02
- ffff838d`c12376c0 fffff800`2dc33e6f : 00000000`00000000 ffffe780`7ad9eec8 ffffe780`7ad99180 ffffe780`00000001 : amdppm!PerfReadWrappingCounter+0x31
- ffff838d`c1237710 fffff800`2dc31fd2 : 00000000`00000000 00000000`c51add6c 00000000`c51add6c 00000000`00000012 : nt!PpmUpdatePerformanceFeedback+0x14f
- ffff838d`c12377c0 fffff800`2dc3138e : 00000000`00000003 00000000`00000002 00000000`00000001 00000000`00000000 : nt!PpmIdleExecuteTransition+0xaa2
- ffff838d`c1237b00 fffff800`2ddc7614 : ffffffff`00000000 ffffe780`7ad99180 ffffbf04`6530e080 00000000`00000264 : nt!PoIdle+0x36e
- ffff838d`c1237c60 00000000`00000000 : ffff838d`c1238000 ffff838d`c1232000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x44
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
- fffff8002dc3146f-fffff8002dc31470 2 bytes - nt!PoIdle+44f
- [ 48 ff:4c 8b ]
- fffff8002dc31476-fffff8002dc31479 4 bytes - nt!PoIdle+456 (+0x07)
- [ 0f 1f 44 00:e8 a5 5d a8 ]
- fffff8002dc31489-fffff8002dc3148a 2 bytes - nt!PoIdle+469 (+0x13)
- [ 48 ff:4c 8b ]
- 8 errors : !nt (fffff8002dc3146f-fffff8002dc3148a)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-12-16T13:00:51.000Z
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #1: 3RD PARTY DRIVERS ======================
- Jun 11 2018 - e1i65x64.sys - Intel(R) Gigabit Adapter driver
- Dec 09 2018 - UcmCxUcsiNvppc.sys - NVIDIA USB Type-C Port Policy Controller driver
- Feb 07 2019 - amdgpio2.sys - AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Mar 14 2019 - nvvad64v.sys - Nvidia Virtual Audio driver http://www.nvidia.com/
- May 14 2019 - RTKVHD64.sys - Realtek Audio System driver https://www.realtek.com/en/
- Jun 19 2019 - amdpsp.sys - Advanced Micro Devices, Inc http://support.amd.com/
- Sep 11 2019 - AMDPCIDev.sys - Advanced Micro Devices PCI Device driver
- Oct 02 2019 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- Nov 29 2019 - NvModuleTracker.sys - NVIDIA Module Tracker driver
- Jan 10 2020 - nvvhci.sys - Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Oct 16 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- ================== Dump #1: 3RD PARTY DRIVERS (FULL) ===================
- Mapped memory image file: C:\ProgramData\dbg\sym\e1i65x64.sys\5B1EB8E28e000\e1i65x64.sys
- Image path: \SystemRoot\System32\drivers\e1i65x64.sys
- Image name: e1i65x64.sys
- Search : https://www.google.com/search?q=e1i65x64.sys
- ADA Info : Intel(R) Gigabit Adapter driver
- Timestamp : Mon Jun 11 2018
- File version: 12.17.10.8
- Product version: 10.0.10011.16384
- File flags: 8 (Mask 3F) Private
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- CompanyName: Intel Corporation
- ProductName: Intel(R) Gigabit Adapter
- InternalName: e1i65x64.sys
- OriginalFilename: e1i65x64.sys
- ProductVersion: 12.17.10.8
- FileVersion: 12.17.10.8
- FileDescription: Intel(R) Gigabit Adapter NDIS 6.x driver
- LegalCopyright: Copyright(C) 2013, Intel Corporation. All rights reserved.
- Image path: \SystemRoot\System32\drivers\UcmCxUcsiNvppc.sys
- Image name: UcmCxUcsiNvppc.sys
- Search : https://www.google.com/search?q=UcmCxUcsiNvppc.sys
- ADA Info : NVIDIA USB Type-C Port Policy Controller driver
- Timestamp : Sun Dec 9 2018
- Mapped memory image file: C:\ProgramData\dbg\sym\amdgpio2.sys\5C5BFB24c000\amdgpio2.sys
- Image path: \SystemRoot\System32\drivers\amdgpio2.sys
- Image name: amdgpio2.sys
- Search : https://www.google.com/search?q=amdgpio2.sys
- ADA Info : AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Timestamp : Thu Feb 7 2019
- File version: 2.2.0.71
- Product version: 2.2.0.71
- File flags: 8 (Mask 3F) Private
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- CompanyName: Advanced Micro Devices, Inc
- ProductName: AMD GPIO Controller Driver
- InternalName: amdgpio2.sys
- OriginalFilename: amdgpio2.sys
- ProductVersion: 2.2.0.71
- FileVersion: 2.2.0.71
- FileDescription: AMD GPIO Controller Driver
- LegalCopyright: Copyright © 2012-2019 Advanced Micro Devices, Inc
- Image path: \SystemRoot\system32\drivers\nvvad64v.sys
- Image name: nvvad64v.sys
- Search : https://www.google.com/search?q=nvvad64v.sys
- ADA Info : Nvidia Virtual Audio driver http://www.nvidia.com/
- Timestamp : Thu Mar 14 2019
- Image path: \SystemRoot\system32\drivers\RTKVHD64.sys
- Image name: RTKVHD64.sys
- Search : https://www.google.com/search?q=RTKVHD64.sys
- ADA Info : Realtek Audio System driver https://www.realtek.com/en/
- Timestamp : Tue May 14 2019
- Image path: \SystemRoot\System32\drivers\amdpsp.sys
- Image name: amdpsp.sys
- Search : https://www.google.com/search?q=amdpsp.sys
- ADA Info : Advanced Micro Devices, Inc http://support.amd.com/
- Timestamp : Wed Jun 19 2019
- Image path: \SystemRoot\System32\drivers\AMDPCIDev.sys
- Image name: AMDPCIDev.sys
- Search : https://www.google.com/search?q=AMDPCIDev.sys
- ADA Info : Advanced Micro Devices PCI Device driver
- Timestamp : Wed Sep 11 2019
- Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_90685a092bcf58c7\nvlddmkm.sys
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Wed Oct 2 2019
- Image path: \SystemRoot\System32\drivers\NvModuleTracker.sys
- Image name: NvModuleTracker.sys
- Search : https://www.google.com/search?q=NvModuleTracker.sys
- ADA Info : NVIDIA Module Tracker driver
- Timestamp : Fri Nov 29 2019
- Image path: \SystemRoot\System32\drivers\nvvhci.sys
- Image name: nvvhci.sys
- Search : https://www.google.com/search?q=nvvhci.sys
- ADA Info : Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Timestamp : Fri Jan 10 2020
- Image path: \SystemRoot\system32\drivers\nvhda64v.sys
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Fri Oct 16 2020
- ====================== Dump #1: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- amdppm.sys Processor Device Driver
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- csc.sys Windows Client Side Caching driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kd.dll Local Kernal Debugger (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate_AuthenticAMD.dll AMD Microcode Update Library (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msgpioclx.sys GPIO Class Extension Driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- UcmCx.sys USB Connector Manager KMDF Class Extension
- ucx01000.sys USB Controller Extension (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- winquic.sys QUIC Transport Protocol driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- ====================== Dump #1: UNLOADED MODULES =======================
- fffff800`316c0000 fffff800`316cf000 dump_storpor
- fffff800`31700000 fffff800`3172f000 dump_storahc
- fffff800`31750000 fffff800`3176e000 dump_dumpfve
- fffff800`39fa0000 fffff800`39fbe000 dam.sys
- fffff800`2ffd0000 fffff800`2ffe1000 WdBoot.sys
- fffff800`30ff0000 fffff800`31001000 hwpolicy.sys
- ====================== Dump #1: BIOS INFORMATION =======================
- sysinfo: could not find necessary interfaces.
- sysinfo: note that mssmbios.sys must be loaded (XPSP2+).
- ========================== Dump #1: Extra #1 ===========================
- 2: kd> !verifier
- Verify Flags Level 0x00000000
- STANDARD FLAGS:
- [X] (0x00000000) Automatic Checks
- [ ] (0x00000001) Special pool
- [ ] (0x00000002) Force IRQL checking
- [ ] (0x00000008) Pool tracking
- [ ] (0x00000010) I/O verification
- [ ] (0x00000020) Deadlock detection
- [ ] (0x00000080) DMA checking
- [ ] (0x00000100) Security checks
- [ ] (0x00000800) Miscellaneous checks
- [ ] (0x00020000) DDI compliance checking
- ADDITIONAL FLAGS:
- [ ] (0x00000004) Randomized low resources simulation
- [ ] (0x00000200) Force pending I/O requests
- [ ] (0x00000400) IRP logging
- [ ] (0x00002000) Invariant MDL checking for stack
- [ ] (0x00004000) Invariant MDL checking for driver
- [ ] (0x00008000) Power framework delay fuzzing
- [ ] (0x00010000) Port/miniport interface checking
- [ ] (0x00040000) Systematic low resources simulation
- [ ] (0x00080000) DDI compliance checking (additional)
- [ ] (0x00200000) NDIS/WIFI verification
- [ ] (0x00800000) Kernel synchronization delay fuzzing
- [ ] (0x01000000) VM switch verification
- [ ] (0x02000000) Code integrity checks
- [X] Indicates flag is enabled
- Summary of All Verifier Statistics
- RaiseIrqls 0x0
- AcquireSpinLocks 0x0
- Synch Executions 0x0
- Trims 0x0
- Pool Allocations Attempted 0x0
- Pool Allocations Succeeded 0x0
- Pool Allocations Succeeded SpecialPool 0x0
- Pool Allocations With NO TAG 0x0
- Pool Allocations Failed 0x0
- Current paged pool allocations 0x0 for 00000000 bytes
- Peak paged pool allocations 0x0 for 00000000 bytes
- Current nonpaged pool allocations 0x0 for 00000000 bytes
- Peak nonpaged pool allocations 0x0 for 00000000 bytes
- ========================== Dump #1: Extra #2 ===========================
- 2: kd> !thread
- THREAD ffffe7807adaa440 Cid 0000.0000 Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor 2
- Not impersonating
- GetUlongFromAddress: unable to read from fffff8002e02aa04
- Owning Process fffff8002e18c9c0 Image: System Process
- Attached Process ffffbf045d4b0080 Image: System
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 21143
- Context Switch Count 196047 IdealProcessor: 2
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address nt!KiIdleLoop (0xfffff8002ddc75d0)
- Stack Init ffff838dc1237c90 Current ffff838dc1237c20
- Base ffff838dc1238000 Limit ffff838dc1232000 Call 0000000000000000
- Priority 0 BasePriority 0 PriorityDecrement 0 IoPriority 0 PagePriority 0
- Child-SP RetAddr : Args to Child : Call Site
- ffff838d`c12373d8 fffff800`2ddd5929 : 00000000`0000000a fffff800`00400a02 00000000`000000ff 00000000`00000000 : nt!KeBugCheckEx
- ffff838d`c12373e0 fffff800`2ddd1c69 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
- ffff838d`c1237520 fffff800`00400a02 : fffff800`3c789841 ffffbf04`5fd90770 00000000`00000004 ffff838d`c123762c : nt!KiPageFault+0x469 (TrapFrame @ ffff838d`c1237520)
- ffff838d`c12376b8 fffff800`3c789841 : ffffbf04`5fd90770 00000000`00000004 ffff838d`c123762c 00000000`00000004 : 0xfffff800`00400a02
- ffff838d`c12376c0 fffff800`2dc33e6f : 00000000`00000000 ffffe780`7ad9eec8 ffffe780`7ad99180 ffffe780`00000001 : amdppm!PerfReadWrappingCounter+0x31
- ffff838d`c1237710 fffff800`2dc31fd2 : 00000000`00000000 00000000`c51add6c 00000000`c51add6c 00000000`00000012 : nt!PpmUpdatePerformanceFeedback+0x14f
- ffff838d`c12377c0 fffff800`2dc3138e : 00000000`00000003 00000000`00000002 00000000`00000001 00000000`00000000 : nt!PpmIdleExecuteTransition+0xaa2
- ffff838d`c1237b00 fffff800`2ddc7614 : ffffffff`00000000 ffffe780`7ad99180 ffffbf04`6530e080 00000000`00000264 : nt!PoIdle+0x36e
- ffff838d`c1237c60 00000000`00000000 : ffff838d`c1238000 ffff838d`c1232000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x44
- ========================================================================
- ======================= Dump #2: ANALYZE VERBOSE =======================
- ====================== File: 121520-11843-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 18362 MP (16 procs) Free x64
- Kernel base = 0xfffff807`73800000 PsLoadedModuleList = 0xfffff807`73c461b0
- Debug session time: Tue Dec 15 00:32:48.052 2020 (UTC - 5:00)
- System Uptime: 0 days 20:43:42.706
- BugCheck 139, {2, ffffbd0e717f4720, ffffbd0e717f4678, 0}
- *** WARNING: Unable to verify timestamp for win32kfull.sys
- *** ERROR: Module load completed but symbols could not be loaded for win32kfull.sys
- Probably caused by : memory_corruption
- Followup: memory_corruption
- KERNEL_SECURITY_CHECK_FAILURE (139)
- A kernel component has corrupted a critical data structure. The corruption
- could potentially allow a malicious user to gain control of this machine.
- Arguments:
- Arg1: 0000000000000002, Stack cookie instrumentation code detected a stack-based
- buffer overrun.
- Arg2: ffffbd0e717f4720, Address of the trap frame for the exception that caused the bugcheck
- Arg3: ffffbd0e717f4678, Address of the exception record for the exception that caused the bugcheck
- Arg4: 0000000000000000, Reserved
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- TRAP_FRAME: ffffbd0e717f4720 -- (.trap 0xffffbd0e717f4720)
- NOTE: The trap frame does not contain all registers.
- Some register values may be zeroed or incorrect.
- rax=00000000000113a4 rbx=0000000000000000 rcx=0000000000000002
- rdx=ffff8f0c4139e330 rsi=0000000000000000 rdi=0000000000000000
- rip=ffff8f6150142ab5 rsp=ffffbd0e717f48b8 rbp=ffff8f614fcbcc9a
- r8=ffffbd0e717f4440 r9=0000000000000001 r10=fffff80773909aa0
- r11=ffffbd0e717f4570 r12=0000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=0000000000000000
- iopl=0 nv up ei ng nz ac pe nc
- win32kfull+0x162ab5:
- ffff8f61`50142ab5 cd29 int 29h
- Resetting default scope
- EXCEPTION_RECORD: ffffbd0e717f4678 -- (.exr 0xffffbd0e717f4678)
- ExceptionAddress: ffff8f6150142ab5 (win32kfull+0x0000000000162ab5)
- ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
- ExceptionFlags: 00000001
- NumberParameters: 1
- Parameter[0]: 0000000000000002
- Subcode: 0x2 FAST_FAIL_STACK_COOKIE_CHECK_FAILURE
- CUSTOMER_CRASH_COUNT: 1
- BUGCHECK_STR: 0x139
- PROCESS_NAME: explorer.exe
- CURRENT_IRQL: 0
- ERROR_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.
- EXCEPTION_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.
- EXCEPTION_CODE_STR: c0000409
- EXCEPTION_PARAMETER1: 0000000000000002
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- WATSON_BKT_EVENT: BEX
- LAST_CONTROL_TRANSFER: from fffff807739d5929 to fffff807739c3b20
- FAULTING_THREAD: 0000000000000000
- STACK_TEXT:
- ffffbd0e`717f43f8 fffff807`739d5929 : 00000000`00000139 00000000`00000002 ffffbd0e`717f4720 ffffbd0e`717f4678 : nt!KeBugCheckEx
- ffffbd0e`717f4400 fffff807`739d5d50 : ffff8f0c`44739010 ffffbd0e`717f4570 ffff8f0c`44739010 ffff8f61`4fc26e52 : nt!KiBugCheckDispatch+0x69
- ffffbd0e`717f4540 fffff807`739d40e3 : 00000000`00000001 00000000`00000001 00000000`00000000 00000000`01eb0422 : nt!KiFastFailDispatch+0xd0
- ffffbd0e`717f4720 ffff8f61`50142ab5 : ffff8f61`500a8812 ffff8f0c`00000000 000001eb`00000422 00000000`00000000 : nt!KiRaiseSecurityCheckFailure+0x323
- ffffbd0e`717f48b8 ffff8f61`500a8812 : ffff8f0c`00000000 000001eb`00000422 00000000`00000000 00000000`01eb0422 : win32kfull+0x162ab5
- ffffbd0e`717f48c0 ffff8f0c`00000000 : 000001eb`00000422 00000000`00000000 00000000`01eb0422 00000000`00000000 : win32kfull+0xc8812
- ffffbd0e`717f48c8 000001eb`00000422 : 00000000`00000000 00000000`01eb0422 00000000`00000000 fffff807`00000000 : 0xffff8f0c`00000000
- ffffbd0e`717f48d0 00000000`00000000 : 00000000`01eb0422 00000000`00000000 fffff807`00000000 00000000`00000001 : 0x000001eb`00000422
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !win32k
- ffff8f614fa422ca-ffff8f614fa422cc 3 bytes - win32k!NtUserPeekMessage
- [ 48 ff 25:4c 8b 15 ]
- ffff8f614fa422d1-ffff8f614fa422d5 5 bytes - win32k!NtUserPeekMessage+7 (+0x07)
- [ cc cc cc cc cc:e9 4a a1 08 00 ]
- ffff8f614fa422dc-ffff8f614fa422de 3 bytes - win32k!NtUserCallOneParam (+0x0b)
- [ 48 ff 25:4c 8b 15 ]
- ffff8f614fa422e3-ffff8f614fa422e7 5 bytes - win32k!NtUserCallOneParam+7 (+0x07)
- [ cc cc cc cc cc:e9 38 a1 08 00 ]
- ffff8f614fa422ee-ffff8f614fa422f0 3 bytes - win32k!NtUserGetKeyState (+0x0b)
- [ 48 ff 25:4c 8b 15 ]
- ffff8f614fa422f5-ffff8f614fa422f9 5 bytes - win32k!NtUserGetKeyState+7 (+0x07)
- [ cc cc cc cc cc:e9 26 a1 08 00 ]
- ffff8f614fa42300-ffff8f614fa42302 3 bytes - win32k!NtUserInvalidateRect (+0x0b)
- [ 48 ff 25:4c 8b 15 ]
- ffff8f614fa42307-ffff8f614fa4230b 5 bytes - win32k!NtUserInvalidateRect+7 (+0x07)
- [ cc cc cc cc cc:e9 14 a1 08 00 ]
- ffff8f614fa42312-ffff8f614fa42314 3 bytes - win32k!NtUserCallNoParam (+0x0b)
- [ 48 ff 25:4c 8b 15 ]
- ffff8f614fa42319-ffff8f614fa4231d 5 bytes - win32k!NtUserCallNoParam+7 (+0x07)
- [ cc cc cc cc cc:e9 02 a1 08 00 ]
- ffff8f614fa42324-ffff8f614fa42326 3 bytes - win32k!NtUserGetMessage (+0x0b)
- [ 48 ff 25:4c 8b 15 ]
- ffff8f614fa4232b-ffff8f614fa4232f 5 bytes - win32k!NtUserGetMessage+7 (+0x07)
- [ cc cc cc cc cc:e9 f0 a0 08 00 ]
- ffff8f614fa42336-ffff8f614fa42338 3 bytes - win32k!NtUserMessageCall (+0x0b)
- [ 48 ff 25:4c 8b 15 ]
- ffff8f614fa4233d-ffff8f614fa42341 5 bytes - win32k!NtUserMessageCall+7 (+0x07)
- [ cc cc cc cc cc:e9 de a0 08 00 ]
- ffff8f614fa42348-ffff8f614fa4234a 3 bytes - win32k!NtGdiBitBlt (+0x0b)
- [ 48 ff 25:4c 8b 15 ]
- ffff8f614fa4234f - win32k!NtGdiBitBlt+7 (+0x07)
- [ cc:e9 ]
- ffff8f614fa42351-ffff8f614fa42353 3 bytes - win32k!NtGdiBitBlt+9 (+0x02)
- [ cc cc cc:a0 08 00 ]
- ffff8f614fa4235a-ffff8f614fa4235c 3 bytes - win32k!NtGdiGetCharSet (+0x09)
- [ 48 ff 25:4c 8b 15 ]
- ffff8f614fa42361-ffff8f614fa42365 5 bytes - win32k!NtGdiGetCharSet+7 (+0x07)
- [ cc cc cc cc cc:e9 ba a0 08 00 ]
- ffff8f614fa4236c-ffff8f614fa4236e 3 bytes - win32k!NtUserGetDC (+0x0b)
- [ 48 ff 25:4c 8b 15 ]
- ffff8f614fa42373-ffff8f614fa42377 5 bytes - win32k!NtUserGetDC+7 (+0x07)
- [ cc cc cc cc cc:e9 a8 a0 08 00 ]
- ffff8f614fa4237e-ffff8f614fa42380 3 bytes - win32k!NtGdiSelectBitmap (+0x0b)
- [ 48 ff 25:4c 8b 15 ]
- ffff8f614fa42385-ffff8f614fa42389 5 bytes - win32k!NtGdiSelectBitmap+7 (+0x07)
- [ cc cc cc cc cc:e9 96 a0 08 00 ]
- ffff8f614fa42390-ffff8f614fa42392 3 bytes - win32k!NtUserWaitMessage (+0x0b)
- [ 48 ff 25:4c 8b 15 ]
- ffff8f614fa42397-ffff8f614fa4239b 5 bytes - win32k!NtUserWaitMessage+7 (+0x07)
- [ cc cc cc cc cc:e9 84 a0 08 00 ]
- ffff8f614fa423a2-ffff8f614fa423a4 3 bytes - win32k!NtUserTranslateMessage (+0x0b)
- [ 48 ff 25:4c 8b 15 ]
- ffff8f614fa423a9-ffff8f614fa423ad 5 bytes - win32k!NtUserTranslateMessage+7 (+0x07)
- [ cc cc cc cc cc:e9 72 a0 08 00 ]
- ffff8f614fa423b4-ffff8f614fa423b6 3 bytes - win32k!NtUserGetProp (+0x0b)
- [ 48 ff 25:4c 8b 15 ]
- ffff8f614fa423bb-ffff8f614fa423bf 5 bytes - win32k!NtUserGetProp+7 (+0x07)
- [ cc cc cc cc cc:e9 60 a0 08 00 ]
- ffff8f614fa423c6-ffff8f614fa423c8 3 bytes - win32k!NtUserPostMessage (+0x0b)
- [ 48 ff 25:4c 8b 15 ]
- ffff8f614fa423cd-ffff8f614fa423d1 5 bytes - win32k!NtUserPostMessage+7 (+0x07)
- [ cc cc cc cc cc:e9 4e a0 08 00 ]
- ffff8f614fa423d8-ffff8f614fa423da 3 bytes - win32k!NtUserQueryWindow (+0x0b)
- [ 48 ff 25:4c 8b 15 ]
- ffff8f614fa423df-ffff8f614fa423e3 5 bytes - win32k!NtUserQueryWindow+7 (+0x07)
- [ cc cc cc cc cc:e9 3c a0 08 00 ]
- ffff8f614fa423ea-ffff8f614fa423ec 3 bytes - win32k!NtUserTranslateAccelerator (+0x0b)
- [ 48 ff 25:4c 8b 15 ]
- ffff8f614fa423f1-ffff8f614fa423f5 5 bytes - win32k!NtUserTranslateAccelerator+7 (+0x07)
- [ cc cc cc cc cc:e9 2a a0 08 00 ]
- ffff8f614fa423fc-ffff8f614fa423fe 3 bytes - win32k!NtGdiFlush (+0x0b)
- [ 48 ff 25:4c 8b 15 ]
- ffff8f614fa42403-ffff8f614fa42407 5 bytes - win32k!NtGdiFlush+7 (+0x07)
- [ cc cc cc cc cc:e9 18 a0 08 00 ]
- ffff8f614fa4240e-ffff8f614fa42410 3 bytes - win32k!NtUserRedrawWindow (+0x0b)
- [ 48 ff 25:4c 8b 15 ]
- ffff8f614fa42415-ffff8f614fa42419 5 bytes - win32k!NtUserRedrawWindow+7 (+0x07)
- [ cc cc cc cc cc:e9 06 a0 08 00 ]
- ffff8f614fa42420-ffff8f614fa42422 3 bytes - win32k!NtUserWindowFromPoint (+0x0b)
- [ 48 ff 25:4c 8b 15 ]
- ffff8f614fa42427-ffff8f614fa4242b 5 bytes - win32k!NtUserWindowFromPoint+7 (+0x07)
- [ cc cc cc cc cc:e9 f4 9f 08 00 ]
- ffff8f614fa42432-ffff8f614fa42434 3 bytes - win32k!NtUserCallMsgFilter (+0x0b)
- [ 48 ff 25:4c 8b 15 ]
- ffff8f614fa42439-ffff8f614fa4243d 5 bytes - win32k!NtUserCallMsgFilter+7 (+0x07)
- [ cc cc cc cc cc:e9 e2 9f 08 00 ]
- ffff8f614fa42444-ffff8f614fa42446 3 bytes - win32k!NtUserValidateTimerCallback (+0x0b)
- [ 48 ff 25:4c 8b 15 ]
- ffff8f614fa4244b-ffff8f614fa4244f 5 bytes - win32k!NtUserValidateTimerCallback+7 (+0x07)
- [ cc cc cc cc cc:e9 d0 9f 08 00 ]
- ffff8f614fa42456-ffff8f614fa42458 3 bytes - win32k!NtUserBeginPaint (+0x0b)
- [ 48 ff 25:4c 8b 15 ]
- ffff8f614fa4245d-ffff8f614fa42461 5 bytes - win32k!NtUserBeginPaint+7 (+0x07)
- [ cc cc cc cc cc:e9 be 9f 08 00 ]
- ffff8f614fa42468-ffff8f614fa4246a 3 bytes - win32k!NtUserSetTimer (+0x0b)
- [ 48 ff 25:4c 8b 15 ]
- ffff8f614fa4246f-ffff8f614fa42473 5 bytes - win32k!NtUserSetTimer+7 (+0x07)
- [ cc cc cc cc cc:e9 ac 9f 08 00 ]
- ffff8f614fa4247a-ffff8f614fa4247c 3 bytes - win32k!NtUserEndPaint (+0x0b)
- [ 48 ff 25:4c 8b 15 ]
- WARNING: !chkimg output was truncated to 50 lines. Invoke !chkimg without '-lo [num_lines]' to view entire output.
- 923 errors : !win32k (ffff8f614fa422ca-ffff8f614fa47338)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- STACK_COMMAND: ~0s ; kb
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-12-15T05:32:48.000Z
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #2: 3RD PARTY DRIVERS ======================
- Jun 11 2018 - e1i65x64.sys - Intel(R) Gigabit Adapter driver
- Dec 09 2018 - UcmCxUcsiNvppc.sys - NVIDIA USB Type-C Port Policy Controller driver
- Feb 07 2019 - amdgpio2.sys - AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Mar 14 2019 - nvvad64v.sys - Nvidia Virtual Audio driver http://www.nvidia.com/
- May 14 2019 - RTKVHD64.sys - Realtek Audio System driver https://www.realtek.com/en/
- Jun 19 2019 - amdpsp.sys - Advanced Micro Devices, Inc http://support.amd.com/
- Sep 11 2019 - AMDPCIDev.sys - Advanced Micro Devices PCI Device driver
- Oct 02 2019 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- Nov 29 2019 - NvModuleTracker.sys - NVIDIA Module Tracker driver
- Jan 10 2020 - nvvhci.sys - Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Oct 16 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- ================== Dump #2: 3RD PARTY DRIVERS (FULL) ===================
- Mapped memory image file: C:\ProgramData\dbg\sym\e1i65x64.sys\5B1EB8E28e000\e1i65x64.sys
- Image path: \SystemRoot\System32\drivers\e1i65x64.sys
- Image name: e1i65x64.sys
- Search : https://www.google.com/search?q=e1i65x64.sys
- ADA Info : Intel(R) Gigabit Adapter driver
- Timestamp : Mon Jun 11 2018
- File version: 12.17.10.8
- Product version: 10.0.10011.16384
- File flags: 8 (Mask 3F) Private
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- CompanyName: Intel Corporation
- ProductName: Intel(R) Gigabit Adapter
- InternalName: e1i65x64.sys
- OriginalFilename: e1i65x64.sys
- ProductVersion: 12.17.10.8
- FileVersion: 12.17.10.8
- FileDescription: Intel(R) Gigabit Adapter NDIS 6.x driver
- LegalCopyright: Copyright(C) 2013, Intel Corporation. All rights reserved.
- Image path: \SystemRoot\System32\drivers\UcmCxUcsiNvppc.sys
- Image name: UcmCxUcsiNvppc.sys
- Search : https://www.google.com/search?q=UcmCxUcsiNvppc.sys
- ADA Info : NVIDIA USB Type-C Port Policy Controller driver
- Timestamp : Sun Dec 9 2018
- Mapped memory image file: C:\ProgramData\dbg\sym\amdgpio2.sys\5C5BFB24c000\amdgpio2.sys
- Image path: \SystemRoot\System32\drivers\amdgpio2.sys
- Image name: amdgpio2.sys
- Search : https://www.google.com/search?q=amdgpio2.sys
- ADA Info : AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Timestamp : Thu Feb 7 2019
- File version: 2.2.0.71
- Product version: 2.2.0.71
- File flags: 8 (Mask 3F) Private
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- CompanyName: Advanced Micro Devices, Inc
- ProductName: AMD GPIO Controller Driver
- InternalName: amdgpio2.sys
- OriginalFilename: amdgpio2.sys
- ProductVersion: 2.2.0.71
- FileVersion: 2.2.0.71
- FileDescription: AMD GPIO Controller Driver
- LegalCopyright: Copyright © 2012-2019 Advanced Micro Devices, Inc
- Image path: \SystemRoot\system32\drivers\nvvad64v.sys
- Image name: nvvad64v.sys
- Search : https://www.google.com/search?q=nvvad64v.sys
- ADA Info : Nvidia Virtual Audio driver http://www.nvidia.com/
- Timestamp : Thu Mar 14 2019
- Image path: \SystemRoot\system32\drivers\RTKVHD64.sys
- Image name: RTKVHD64.sys
- Search : https://www.google.com/search?q=RTKVHD64.sys
- ADA Info : Realtek Audio System driver https://www.realtek.com/en/
- Timestamp : Tue May 14 2019
- Image path: \SystemRoot\System32\drivers\amdpsp.sys
- Image name: amdpsp.sys
- Search : https://www.google.com/search?q=amdpsp.sys
- ADA Info : Advanced Micro Devices, Inc http://support.amd.com/
- Timestamp : Wed Jun 19 2019
- Image path: \SystemRoot\System32\drivers\AMDPCIDev.sys
- Image name: AMDPCIDev.sys
- Search : https://www.google.com/search?q=AMDPCIDev.sys
- ADA Info : Advanced Micro Devices PCI Device driver
- Timestamp : Wed Sep 11 2019
- Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_90685a092bcf58c7\nvlddmkm.sys
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Wed Oct 2 2019
- Image path: \SystemRoot\System32\drivers\NvModuleTracker.sys
- Image name: NvModuleTracker.sys
- Search : https://www.google.com/search?q=NvModuleTracker.sys
- ADA Info : NVIDIA Module Tracker driver
- Timestamp : Fri Nov 29 2019
- Image path: \SystemRoot\System32\drivers\nvvhci.sys
- Image name: nvvhci.sys
- Search : https://www.google.com/search?q=nvvhci.sys
- ADA Info : Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Timestamp : Fri Jan 10 2020
- Image path: \SystemRoot\system32\drivers\nvhda64v.sys
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Fri Oct 16 2020
- ====================== Dump #2: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- amdppm.sys Processor Device Driver
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- csc.sys Windows Client Side Caching driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kd.dll Local Kernal Debugger (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate_AuthenticAMD.dll AMD Microcode Update Library (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msgpioclx.sys GPIO Class Extension Driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- qwavedrv.sys Quality Windows Audio Video Experience (qWave) Support driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdpvideominiport.sys RDP Video Miniport driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- UcmCx.sys USB Connector Manager KMDF Class Extension
- ucx01000.sys USB Controller Extension (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- winquic.sys QUIC Transport Protocol driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- ====================== Dump #2: UNLOADED MODULES =======================
- fffff807`700a0000 fffff807`703c3000 BEDaisy.sys
- fffff807`703e0000 fffff807`703ef000 hiber_storpo
- fffff807`703f0000 fffff807`7041f000 hiber_storah
- fffff807`70420000 fffff807`7043e000 hiber_dumpfv
- fffff807`700a0000 fffff807`703c3000 BEDaisy.sys
- fffff807`703e0000 fffff807`703ef000 hiber_storpo
- fffff807`703f0000 fffff807`7041f000 hiber_storah
- fffff807`70420000 fffff807`7043e000 hiber_dumpfv
- fffff807`700a0000 fffff807`703c3000 BEDaisy.sys
- fffff807`703e0000 fffff807`703ef000 hiber_storpo
- fffff807`703f0000 fffff807`7041f000 hiber_storah
- fffff807`70420000 fffff807`7043e000 hiber_dumpfv
- fffff807`700a0000 fffff807`703c3000 BEDaisy.sys
- fffff807`80770000 fffff807`8077f000 dump_storpor
- fffff807`807b0000 fffff807`807df000 dump_storahc
- fffff807`7f800000 fffff807`7f81e000 dump_dumpfve
- fffff807`80070000 fffff807`8008e000 dam.sys
- fffff807`75fd0000 fffff807`75fe1000 WdBoot.sys
- fffff807`76ff0000 fffff807`77001000 hwpolicy.sys
- ====================== Dump #2: BIOS INFORMATION =======================
- sysinfo: could not find necessary interfaces.
- sysinfo: note that mssmbios.sys must be loaded (XPSP2+).
- ========================== Dump #2: Extra #1 ===========================
- 3: kd> !verifier
- Verify Flags Level 0x00000000
- STANDARD FLAGS:
- [X] (0x00000000) Automatic Checks
- [ ] (0x00000001) Special pool
- [ ] (0x00000002) Force IRQL checking
- [ ] (0x00000008) Pool tracking
- [ ] (0x00000010) I/O verification
- [ ] (0x00000020) Deadlock detection
- [ ] (0x00000080) DMA checking
- [ ] (0x00000100) Security checks
- [ ] (0x00000800) Miscellaneous checks
- [ ] (0x00020000) DDI compliance checking
- ADDITIONAL FLAGS:
- [ ] (0x00000004) Randomized low resources simulation
- [ ] (0x00000200) Force pending I/O requests
- [ ] (0x00000400) IRP logging
- [ ] (0x00002000) Invariant MDL checking for stack
- [ ] (0x00004000) Invariant MDL checking for driver
- [ ] (0x00008000) Power framework delay fuzzing
- [ ] (0x00010000) Port/miniport interface checking
- [ ] (0x00040000) Systematic low resources simulation
- [ ] (0x00080000) DDI compliance checking (additional)
- [ ] (0x00200000) NDIS/WIFI verification
- [ ] (0x00800000) Kernel synchronization delay fuzzing
- [ ] (0x01000000) VM switch verification
- [ ] (0x02000000) Code integrity checks
- [X] Indicates flag is enabled
- Summary of All Verifier Statistics
- RaiseIrqls 0x0
- AcquireSpinLocks 0x0
- Synch Executions 0x0
- Trims 0x0
- Pool Allocations Attempted 0x0
- Pool Allocations Succeeded 0x0
- Pool Allocations Succeeded SpecialPool 0x0
- Pool Allocations With NO TAG 0x0
- Pool Allocations Failed 0x0
- Current paged pool allocations 0x0 for 00000000 bytes
- Peak paged pool allocations 0x0 for 00000000 bytes
- Current nonpaged pool allocations 0x0 for 00000000 bytes
- Peak nonpaged pool allocations 0x0 for 00000000 bytes
- ========================== Dump #2: Extra #2 ===========================
- 3: kd> !thread
- THREAD ffffd20e92d0f080 Cid 1b68.1770 Teb: 000000000116c000 Win32Thread: ffffd20e8f29cfc0 RUNNING on processor 3
- Not impersonating
- GetUlongFromAddress: unable to read from fffff80773c2aa04
- Owning Process ffffd20e903e60c0 Image: explorer.exe
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 4775852
- Context Switch Count 4918 IdealProcessor: 3
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address 0x00007ff99034c140
- Stack Init ffffbd0e717f5fd0 Current ffffbd0e717f4b20
- Base ffffbd0e717f6000 Limit ffffbd0e717f0000 Call 0000000000000000
- Priority 12 BasePriority 8 PriorityDecrement 2 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- ffffbd0e`717f43f8 fffff807`739d5929 : 00000000`00000139 00000000`00000002 ffffbd0e`717f4720 ffffbd0e`717f4678 : nt!KeBugCheckEx
- ffffbd0e`717f4400 fffff807`739d5d50 : ffff8f0c`44739010 ffffbd0e`717f4570 ffff8f0c`44739010 ffff8f61`4fc26e52 : nt!KiBugCheckDispatch+0x69
- ffffbd0e`717f4540 fffff807`739d40e3 : 00000000`00000001 00000000`00000001 00000000`00000000 00000000`01eb0422 : nt!KiFastFailDispatch+0xd0
- ffffbd0e`717f4720 ffff8f61`50142ab5 : ffff8f61`500a8812 ffff8f0c`00000000 000001eb`00000422 00000000`00000000 : nt!KiRaiseSecurityCheckFailure+0x323 (TrapFrame @ ffffbd0e`717f4720)
- ffffbd0e`717f48b8 ffff8f61`500a8812 : ffff8f0c`00000000 000001eb`00000422 00000000`00000000 00000000`01eb0422 : win32kfull+0x162ab5
- ffffbd0e`717f48c0 ffff8f0c`00000000 : 000001eb`00000422 00000000`00000000 00000000`01eb0422 00000000`00000000 : win32kfull+0xc8812
- ffffbd0e`717f48c8 000001eb`00000422 : 00000000`00000000 00000000`01eb0422 00000000`00000000 fffff807`00000000 : 0xffff8f0c`00000000
- ffffbd0e`717f48d0 00000000`00000000 : 00000000`01eb0422 00000000`00000000 fffff807`00000000 00000000`00000001 : 0x000001eb`00000422
- ========================================================================
- ======================= Dump #3: ANALYZE VERBOSE =======================
- ======================= File: 121420-9765-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 18362 MP (16 procs) Free x64
- Kernel base = 0xfffff804`5a800000 PsLoadedModuleList = 0xfffff804`5ac461b0
- Debug session time: Mon Dec 14 03:47:45.622 2020 (UTC - 5:00)
- System Uptime: 0 days 2:29:48.276
- BugCheck A, {118, 2, 1, fffff8045a9cae18}
- *** WARNING: Unable to verify timestamp for win32k.sys
- *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
- Probably caused by : memory_corruption
- Followup: memory_corruption
- IRQL_NOT_LESS_OR_EQUAL (a)
- An attempt was made to access a pageable (or completely invalid) address at an
- interrupt request level (IRQL) that is too high. This is usually
- caused by drivers using improper addresses.
- If a kernel debugger is available get the stack backtrace.
- Arguments:
- Arg1: 0000000000000118, memory referenced
- Arg2: 0000000000000002, IRQL
- Arg3: 0000000000000001, bitfield :
- bit 0 : value 0 = read operation, 1 = write operation
- bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
- Arg4: fffff8045a9cae18, address which referenced memory
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- WRITE_ADDRESS: fffff8045ad713b8: Unable to get MiVisibleState
- 0000000000000118
- CURRENT_IRQL: 2
- FAULTING_IP:
- nt!SwapContext+2d8
- fffff804`5a9cae18 f0480fb38cc218010000 lock btr qword ptr [rdx+rax*8+118h],rcx
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- BUGCHECK_STR: AV
- PROCESS_NAME: Discord.exe
- TRAP_FRAME: fffff40bdb46ddb0 -- (.trap 0xfffff40bdb46ddb0)
- NOTE: The trap frame does not contain all registers.
- Some register values may be zeroed or incorrect.
- rax=0000000000000000 rbx=0000000000000000 rcx=0000000000000002
- rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
- rip=fffff8045a9cae18 rsp=fffff40bdb46df40 rbp=00000067b4bbbdff
- r8=ffff890157558180 r9=0000000000000000 r10=ffff990192a020c0
- r11=000000010000004b r12=0000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=0000000000000000
- iopl=0 nv up ei pl zr na po nc
- nt!SwapContext+0x2d8:
- fffff804`5a9cae18 f0480fb38cc218010000 lock btr qword ptr [rdx+rax*8+118h],rcx ds:00000000`00000118=????????????????
- Resetting default scope
- LAST_CONTROL_TRANSFER: from fffff8045a9d5929 to fffff8045a9c3b20
- STACK_TEXT:
- fffff40b`db46dc68 fffff804`5a9d5929 : 00000000`0000000a 00000000`00000118 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
- fffff40b`db46dc70 fffff804`5a9d1c69 : ffff8901`57558180 fffff40b`db46de30 ffff9901`830c2000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
- fffff40b`db46ddb0 fffff804`5a9cae18 : 00000067`b4bbbdff 00000000`00000001 ffff8901`00000000 00001f80`00ce00ac : nt!KiPageFault+0x469
- fffff40b`db46df40 fffff804`5a9ca866 : fffff804`5a800000 ffff9901`92a020c0 fffff40b`db46e0b8 00000000`0000ffff : nt!SwapContext+0x2d8
- fffff40b`db46df80 fffff804`5a8419fd : ffff8901`57500180 00000000`fffffffe ffff8901`ffffffff 00000000`00000001 : nt!KiSwapContext+0x76
- fffff40b`db46e0c0 fffff804`5a840884 : ffff9901`8fdda080 00001f80`00000000 00000000`00000000 ffff9901`00000000 : nt!KiSwapThread+0xbfd
- fffff40b`db46e160 fffff804`5a87c7b7 : 00000000`0000006e 00000000`00000000 43300000`00000001 00000000`00000000 : nt!KiCommitThreadWait+0x144
- fffff40b`db46e200 fffff804`5ae0b1e9 : fffff40b`db46e5c0 00000000`00000001 ffff9901`8f1a38b0 fffff804`5a8cff31 : nt!KeWaitForMultipleObjects+0x287
- fffff40b`db46e310 fffff804`5aec839c : 00000000`00000000 ffff8901`57558100 ffff9901`8fdda000 ffff9901`8c0c3080 : nt!ObWaitForMultipleObjects+0x2a9
- fffff40b`db46e810 fffff804`5a9d5891 : ffff9901`8fdda080 fffff40b`db46eb80 00000000`14bfe7c8 ffff8901`57558180 : nt!NtWaitForMultipleObjects32+0xfc
- fffff40b`db46ea90 00000000`77731cbc : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExitPico+0x2bc
- 00000000`14bff0a8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77731cbc
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !win32kbase
- ffffa94ab4096b89-ffffa94ab4096b8e 6 bytes - win32kbase!DirectComposition::CAnimationMarshaler::SetReferenceProperty+49
- [ ff 15 39 dc 19 00:e8 12 d7 20 00 90 ]
- ffffa94ab4096c09-ffffa94ab4096c0a 2 bytes - win32kbase!SfmSignalTokenEvent+19 (+0x80)
- [ 48 ff:4c 8b ]
- ffffa94ab4096c10-ffffa94ab4096c13 4 bytes - win32kbase!SfmSignalTokenEvent+20 (+0x07)
- [ 0f 1f 44 00:e8 0b d8 20 ]
- 12 errors : !win32kbase (ffffa94ab4096b89-ffffa94ab4096c13)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-12-14T08:47:45.000Z
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #3: 3RD PARTY DRIVERS ======================
- Jun 11 2018 - e1i65x64.sys - Intel(R) Gigabit Adapter driver
- Dec 09 2018 - UcmCxUcsiNvppc.sys - NVIDIA USB Type-C Port Policy Controller driver
- Feb 07 2019 - amdgpio2.sys - AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Mar 14 2019 - nvvad64v.sys - Nvidia Virtual Audio driver http://www.nvidia.com/
- May 14 2019 - RTKVHD64.sys - Realtek Audio System driver https://www.realtek.com/en/
- Jun 19 2019 - amdpsp.sys - Advanced Micro Devices, Inc http://support.amd.com/
- Sep 11 2019 - AMDPCIDev.sys - Advanced Micro Devices PCI Device driver
- Oct 02 2019 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- Nov 29 2019 - NvModuleTracker.sys - NVIDIA Module Tracker driver
- Jan 10 2020 - nvvhci.sys - Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Oct 16 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- ================== Dump #3: 3RD PARTY DRIVERS (FULL) ===================
- Mapped memory image file: C:\ProgramData\dbg\sym\e1i65x64.sys\5B1EB8E28e000\e1i65x64.sys
- Image path: \SystemRoot\System32\drivers\e1i65x64.sys
- Image name: e1i65x64.sys
- Search : https://www.google.com/search?q=e1i65x64.sys
- ADA Info : Intel(R) Gigabit Adapter driver
- Timestamp : Mon Jun 11 2018
- File version: 12.17.10.8
- Product version: 10.0.10011.16384
- File flags: 8 (Mask 3F) Private
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- CompanyName: Intel Corporation
- ProductName: Intel(R) Gigabit Adapter
- InternalName: e1i65x64.sys
- OriginalFilename: e1i65x64.sys
- ProductVersion: 12.17.10.8
- FileVersion: 12.17.10.8
- FileDescription: Intel(R) Gigabit Adapter NDIS 6.x driver
- LegalCopyright: Copyright(C) 2013, Intel Corporation. All rights reserved.
- Image path: \SystemRoot\System32\drivers\UcmCxUcsiNvppc.sys
- Image name: UcmCxUcsiNvppc.sys
- Search : https://www.google.com/search?q=UcmCxUcsiNvppc.sys
- ADA Info : NVIDIA USB Type-C Port Policy Controller driver
- Timestamp : Sun Dec 9 2018
- Mapped memory image file: C:\ProgramData\dbg\sym\amdgpio2.sys\5C5BFB24c000\amdgpio2.sys
- Image path: \SystemRoot\System32\drivers\amdgpio2.sys
- Image name: amdgpio2.sys
- Search : https://www.google.com/search?q=amdgpio2.sys
- ADA Info : AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Timestamp : Thu Feb 7 2019
- File version: 2.2.0.71
- Product version: 2.2.0.71
- File flags: 8 (Mask 3F) Private
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- CompanyName: Advanced Micro Devices, Inc
- ProductName: AMD GPIO Controller Driver
- InternalName: amdgpio2.sys
- OriginalFilename: amdgpio2.sys
- ProductVersion: 2.2.0.71
- FileVersion: 2.2.0.71
- FileDescription: AMD GPIO Controller Driver
- LegalCopyright: Copyright © 2012-2019 Advanced Micro Devices, Inc
- Image path: \SystemRoot\system32\drivers\nvvad64v.sys
- Image name: nvvad64v.sys
- Search : https://www.google.com/search?q=nvvad64v.sys
- ADA Info : Nvidia Virtual Audio driver http://www.nvidia.com/
- Timestamp : Thu Mar 14 2019
- Image path: \SystemRoot\system32\drivers\RTKVHD64.sys
- Image name: RTKVHD64.sys
- Search : https://www.google.com/search?q=RTKVHD64.sys
- ADA Info : Realtek Audio System driver https://www.realtek.com/en/
- Timestamp : Tue May 14 2019
- Image path: \SystemRoot\System32\drivers\amdpsp.sys
- Image name: amdpsp.sys
- Search : https://www.google.com/search?q=amdpsp.sys
- ADA Info : Advanced Micro Devices, Inc http://support.amd.com/
- Timestamp : Wed Jun 19 2019
- Image path: \SystemRoot\System32\drivers\AMDPCIDev.sys
- Image name: AMDPCIDev.sys
- Search : https://www.google.com/search?q=AMDPCIDev.sys
- ADA Info : Advanced Micro Devices PCI Device driver
- Timestamp : Wed Sep 11 2019
- Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_90685a092bcf58c7\nvlddmkm.sys
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Wed Oct 2 2019
- Image path: \SystemRoot\System32\drivers\NvModuleTracker.sys
- Image name: NvModuleTracker.sys
- Search : https://www.google.com/search?q=NvModuleTracker.sys
- ADA Info : NVIDIA Module Tracker driver
- Timestamp : Fri Nov 29 2019
- Image path: \SystemRoot\System32\drivers\nvvhci.sys
- Image name: nvvhci.sys
- Search : https://www.google.com/search?q=nvvhci.sys
- ADA Info : Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Timestamp : Fri Jan 10 2020
- Image path: \SystemRoot\system32\drivers\nvhda64v.sys
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Fri Oct 16 2020
- ====================== Dump #3: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- amdppm.sys Processor Device Driver
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- csc.sys Windows Client Side Caching driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kd.dll Local Kernal Debugger (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate_AuthenticAMD.dll AMD Microcode Update Library (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msgpioclx.sys GPIO Class Extension Driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- ndisuio.sys NDIS User mode I/O driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- qwavedrv.sys Quality Windows Audio Video Experience (qWave) Support driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdpvideominiport.sys RDP Video Miniport driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- UcmCx.sys USB Connector Manager KMDF Class Extension
- ucx01000.sys USB Controller Extension (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- winquic.sys QUIC Transport Protocol driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- ====================== Dump #3: UNLOADED MODULES =======================
- fffff804`597e0000 fffff804`597ef000 hiber_storpo
- fffff804`597f0000 fffff804`5981f000 hiber_storah
- fffff804`59820000 fffff804`5983e000 hiber_dumpfv
- fffff804`59480000 fffff804`597a3000 BEDaisy.sys
- fffff804`695d0000 fffff804`695df000 dump_storpor
- fffff804`68c30000 fffff804`68c5f000 dump_storahc
- fffff804`68c80000 fffff804`68c9e000 dump_dumpfve
- fffff804`694f0000 fffff804`6950e000 dam.sys
- fffff804`5f3d0000 fffff804`5f3e1000 WdBoot.sys
- fffff804`603f0000 fffff804`60401000 hwpolicy.sys
- ====================== Dump #3: BIOS INFORMATION =======================
- sysinfo: could not find necessary interfaces.
- sysinfo: note that mssmbios.sys must be loaded (XPSP2+).
- ========================== Dump #3: Extra #1 ===========================
- 2: kd> !verifier
- Verify Flags Level 0x00000000
- STANDARD FLAGS:
- [X] (0x00000000) Automatic Checks
- [ ] (0x00000001) Special pool
- [ ] (0x00000002) Force IRQL checking
- [ ] (0x00000008) Pool tracking
- [ ] (0x00000010) I/O verification
- [ ] (0x00000020) Deadlock detection
- [ ] (0x00000080) DMA checking
- [ ] (0x00000100) Security checks
- [ ] (0x00000800) Miscellaneous checks
- [ ] (0x00020000) DDI compliance checking
- ADDITIONAL FLAGS:
- [ ] (0x00000004) Randomized low resources simulation
- [ ] (0x00000200) Force pending I/O requests
- [ ] (0x00000400) IRP logging
- [ ] (0x00002000) Invariant MDL checking for stack
- [ ] (0x00004000) Invariant MDL checking for driver
- [ ] (0x00008000) Power framework delay fuzzing
- [ ] (0x00010000) Port/miniport interface checking
- [ ] (0x00040000) Systematic low resources simulation
- [ ] (0x00080000) DDI compliance checking (additional)
- [ ] (0x00200000) NDIS/WIFI verification
- [ ] (0x00800000) Kernel synchronization delay fuzzing
- [ ] (0x01000000) VM switch verification
- [ ] (0x02000000) Code integrity checks
- [X] Indicates flag is enabled
- Summary of All Verifier Statistics
- RaiseIrqls 0x0
- AcquireSpinLocks 0x0
- Synch Executions 0x0
- Trims 0x0
- Pool Allocations Attempted 0x0
- Pool Allocations Succeeded 0x0
- Pool Allocations Succeeded SpecialPool 0x0
- Pool Allocations With NO TAG 0x0
- Pool Allocations Failed 0x0
- Current paged pool allocations 0x0 for 00000000 bytes
- Peak paged pool allocations 0x0 for 00000000 bytes
- Current nonpaged pool allocations 0x0 for 00000000 bytes
- Peak nonpaged pool allocations 0x0 for 00000000 bytes
- ========================== Dump #3: Extra #2 ===========================
- 2: kd> !thread
- THREAD ffff99018fdda080 Cid 1aa8.31c4 Teb: 000000000a03c000 Win32Thread: ffff99018dac1de0 RUNNING on processor 2
- Not impersonating
- GetUlongFromAddress: unable to read from fffff8045ac2aa04
- Owning Process ffff990192a020c0 Image: Discord.exe
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 575249
- Context Switch Count 25219 IdealProcessor: 1
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address 0x0000000064c81d22
- Stack Init fffff40bdb46ec90 Current fffff40bdb46df40
- Base fffff40bdb46f000 Limit fffff40bdb469000 Call 0000000000000000
- Priority 26 BasePriority 26 PriorityDecrement 0 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- fffff40b`db46dc68 fffff804`5a9d5929 : 00000000`0000000a 00000000`00000118 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
- fffff40b`db46dc70 fffff804`5a9d1c69 : ffff8901`57558180 fffff40b`db46de30 ffff9901`830c2000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
- fffff40b`db46ddb0 fffff804`5a9cae18 : 00000067`b4bbbdff 00000000`00000001 ffff8901`00000000 00001f80`00ce00ac : nt!KiPageFault+0x469 (TrapFrame @ fffff40b`db46ddb0)
- fffff40b`db46df40 fffff804`5a9ca866 : fffff804`5a800000 ffff9901`92a020c0 fffff40b`db46e0b8 00000000`0000ffff : nt!SwapContext+0x2d8
- fffff40b`db46df80 fffff804`5a8419fd : ffff8901`57500180 00000000`fffffffe ffff8901`ffffffff 00000000`00000001 : nt!KiSwapContext+0x76
- fffff40b`db46e0c0 fffff804`5a840884 : ffff9901`8fdda080 00001f80`00000000 00000000`00000000 ffff9901`00000000 : nt!KiSwapThread+0xbfd
- fffff40b`db46e160 fffff804`5a87c7b7 : 00000000`0000006e 00000000`00000000 43300000`00000001 00000000`00000000 : nt!KiCommitThreadWait+0x144
- fffff40b`db46e200 fffff804`5ae0b1e9 : fffff40b`db46e5c0 00000000`00000001 ffff9901`8f1a38b0 fffff804`5a8cff31 : nt!KeWaitForMultipleObjects+0x287
- fffff40b`db46e310 fffff804`5aec839c : 00000000`00000000 ffff8901`57558100 ffff9901`8fdda000 ffff9901`8c0c3080 : nt!ObWaitForMultipleObjects+0x2a9
- fffff40b`db46e810 fffff804`5a9d5891 : ffff9901`8fdda080 fffff40b`db46eb80 00000000`14bfe7c8 ffff8901`57558180 : nt!NtWaitForMultipleObjects32+0xfc
- fffff40b`db46ea90 00000000`77731cbc : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExitPico+0x2bc (TrapFrame @ fffff40b`db46eb00)
- 00000000`14bff0a8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77731cbc
- ========================================================================
- ======================= Dump #4: ANALYZE VERBOSE =======================
- ======================= File: 121420-9687-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 18362 MP (16 procs) Free x64
- Kernel base = 0xfffff806`38000000 PsLoadedModuleList = 0xfffff806`38443290
- Debug session time: Mon Dec 14 01:12:30.432 2020 (UTC - 5:00)
- System Uptime: 0 days 18:06:18.085
- BugCheck 3B, {c0000005, fffff8063802edfa, ffff8209c7f8df60, 0}
- Probably caused by : memory_corruption
- Followup: memory_corruption
- SYSTEM_SERVICE_EXCEPTION (3b)
- An exception happened while executing a system service routine.
- Arguments:
- Arg1: 00000000c0000005, Exception code that caused the bugcheck
- Arg2: fffff8063802edfa, Address of the instruction which caused the bugcheck
- Arg3: ffff8209c7f8df60, Address of the context record for the exception that caused the bugcheck
- Arg4: 0000000000000000, zero.
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.
- FAULTING_IP:
- nt!KeAbPreAcquire+11a
- fffff806`3802edfa 0fb64220 movzx eax,byte ptr [rdx+20h]
- CONTEXT: ffff8209c7f8df60 -- (.cxr 0xffff8209c7f8df60)
- rax=0000000000000102 rbx=ffffc202bd91a080 rcx=ffffc202c3369060
- rdx=0000000000000e10 rsi=ffffc202c3369060 rdi=0000000000000e10
- rip=fffff8063802edfa rsp=ffff8209c7f8e950 rbp=0000000000000000
- r8=0000000000000000 r9=fffff80638000000 r10=ffffd2811c556180
- r11=ffff8209c7f8e858 r12=ffffc202bd91a1c0 r13=0000000000000000
- r14=0000000000000e10 r15=ffffd2811c364180
- iopl=0 nv up ei pl nz na pe nc
- cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050202
- nt!KeAbPreAcquire+0x11a:
- fffff806`3802edfa 0fb64220 movzx eax,byte ptr [rdx+20h] ds:002b:00000000`00000e30=??
- Resetting default scope
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- BUGCHECK_STR: 0x3B
- PROCESS_NAME: steam.exe
- CURRENT_IRQL: 0
- LAST_CONTROL_TRANSFER: from fffff806381e8d33 to fffff8063802edfa
- STACK_TEXT:
- ffff8209`c7f8e950 fffff806`381e8d33 : ffffc202`bd91a080 ffff8209`c7f8ea21 00000000`00000102 00000000`00000000 : nt!KeAbPreAcquire+0x11a
- ffff8209`c7f8e9a0 fffff806`3861fa1b : ffffc202`c3369060 ffff8209`00000006 00000000`00000001 ffffa1a7`d1b7a100 : nt!KeWaitForSingleObject+0x1b8893
- ffff8209`c7f8ea80 fffff806`381ce3d1 : ffffc202`bd91a080 00000000`00000000 ffff8209`c7f8eb18 ffffffff`ffd9da60 : nt!NtWaitForSingleObject+0x10b
- ffff8209`c7f8eb00 00000000`77051cbc : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExitPico+0x2bc
- 00000000`0a45f088 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77051cbc
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !hal
- fffff80637f5ec4e-fffff80637f5ec53 6 bytes - hal!HalpApicRequestInterrupt+9e
- [ ff 15 b4 6c 07 00:e8 4d 16 3f 00 90 ]
- fffff80637f5ecc1-fffff80637f5ecc6 6 bytes - hal!HalpApicRequestInterrupt+111 (+0x73)
- [ ff 15 41 6c 07 00:e8 da 15 3f 00 90 ]
- fffff80637f601d5-fffff80637f601d6 2 bytes - hal!HalpTimerClockIpiRoutine+15 (+0x1514)
- [ 48 ff:4c 8b ]
- fffff80637f601dc-fffff80637f601df 4 bytes - hal!HalpTimerClockIpiRoutine+1c (+0x07)
- [ 0f 1f 44 00:e8 4f 2e 12 ]
- fffff80637f60237-fffff80637f6023c 6 bytes - hal!HalpTimerClockIpiRoutine+77 (+0x5b)
- [ ff 15 cb 56 07 00:e8 64 00 3f 00 90 ]
- 24 errors : !hal (fffff80637f5ec4e-fffff80637f6023c)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- STACK_COMMAND: .cxr 0xffff8209c7f8df60 ; kb
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-12-14T06:12:30.000Z
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #4: 3RD PARTY DRIVERS ======================
- Jun 11 2018 - e1i65x64.sys - Intel(R) Gigabit Adapter driver
- Dec 09 2018 - UcmCxUcsiNvppc.sys - NVIDIA USB Type-C Port Policy Controller driver
- Feb 07 2019 - amdgpio2.sys - AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Mar 14 2019 - nvvad64v.sys - Nvidia Virtual Audio driver http://www.nvidia.com/
- May 14 2019 - RTKVHD64.sys - Realtek Audio System driver https://www.realtek.com/en/
- Jun 19 2019 - amdpsp.sys - Advanced Micro Devices, Inc http://support.amd.com/
- Sep 11 2019 - AMDPCIDev.sys - Advanced Micro Devices PCI Device driver
- Oct 02 2019 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- Nov 29 2019 - NvModuleTracker.sys - NVIDIA Module Tracker driver
- Jan 10 2020 - nvvhci.sys - Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Oct 16 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- ================== Dump #4: 3RD PARTY DRIVERS (FULL) ===================
- Mapped memory image file: C:\ProgramData\dbg\sym\e1i65x64.sys\5B1EB8E28e000\e1i65x64.sys
- Image path: \SystemRoot\System32\drivers\e1i65x64.sys
- Image name: e1i65x64.sys
- Search : https://www.google.com/search?q=e1i65x64.sys
- ADA Info : Intel(R) Gigabit Adapter driver
- Timestamp : Mon Jun 11 2018
- File version: 12.17.10.8
- Product version: 10.0.10011.16384
- File flags: 8 (Mask 3F) Private
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- CompanyName: Intel Corporation
- ProductName: Intel(R) Gigabit Adapter
- InternalName: e1i65x64.sys
- OriginalFilename: e1i65x64.sys
- ProductVersion: 12.17.10.8
- FileVersion: 12.17.10.8
- FileDescription: Intel(R) Gigabit Adapter NDIS 6.x driver
- LegalCopyright: Copyright(C) 2013, Intel Corporation. All rights reserved.
- Image path: \SystemRoot\System32\drivers\UcmCxUcsiNvppc.sys
- Image name: UcmCxUcsiNvppc.sys
- Search : https://www.google.com/search?q=UcmCxUcsiNvppc.sys
- ADA Info : NVIDIA USB Type-C Port Policy Controller driver
- Timestamp : Sun Dec 9 2018
- Mapped memory image file: C:\ProgramData\dbg\sym\amdgpio2.sys\5C5BFB24c000\amdgpio2.sys
- Image path: \SystemRoot\System32\drivers\amdgpio2.sys
- Image name: amdgpio2.sys
- Search : https://www.google.com/search?q=amdgpio2.sys
- ADA Info : AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Timestamp : Thu Feb 7 2019
- File version: 2.2.0.71
- Product version: 2.2.0.71
- File flags: 8 (Mask 3F) Private
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- CompanyName: Advanced Micro Devices, Inc
- ProductName: AMD GPIO Controller Driver
- InternalName: amdgpio2.sys
- OriginalFilename: amdgpio2.sys
- ProductVersion: 2.2.0.71
- FileVersion: 2.2.0.71
- FileDescription: AMD GPIO Controller Driver
- LegalCopyright: Copyright © 2012-2019 Advanced Micro Devices, Inc
- Image path: \SystemRoot\system32\drivers\nvvad64v.sys
- Image name: nvvad64v.sys
- Search : https://www.google.com/search?q=nvvad64v.sys
- ADA Info : Nvidia Virtual Audio driver http://www.nvidia.com/
- Timestamp : Thu Mar 14 2019
- Image path: \SystemRoot\system32\drivers\RTKVHD64.sys
- Image name: RTKVHD64.sys
- Search : https://www.google.com/search?q=RTKVHD64.sys
- ADA Info : Realtek Audio System driver https://www.realtek.com/en/
- Timestamp : Tue May 14 2019
- Image path: \SystemRoot\System32\drivers\amdpsp.sys
- Image name: amdpsp.sys
- Search : https://www.google.com/search?q=amdpsp.sys
- ADA Info : Advanced Micro Devices, Inc http://support.amd.com/
- Timestamp : Wed Jun 19 2019
- Image path: \SystemRoot\System32\drivers\AMDPCIDev.sys
- Image name: AMDPCIDev.sys
- Search : https://www.google.com/search?q=AMDPCIDev.sys
- ADA Info : Advanced Micro Devices PCI Device driver
- Timestamp : Wed Sep 11 2019
- Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_90685a092bcf58c7\nvlddmkm.sys
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Wed Oct 2 2019
- Image path: \SystemRoot\System32\drivers\NvModuleTracker.sys
- Image name: NvModuleTracker.sys
- Search : https://www.google.com/search?q=NvModuleTracker.sys
- ADA Info : NVIDIA Module Tracker driver
- Timestamp : Fri Nov 29 2019
- Image path: \SystemRoot\System32\drivers\nvvhci.sys
- Image name: nvvhci.sys
- Search : https://www.google.com/search?q=nvvhci.sys
- ADA Info : Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Timestamp : Fri Jan 10 2020
- Image path: \SystemRoot\system32\drivers\nvhda64v.sys
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Fri Oct 16 2020
- ====================== Dump #4: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- amdppm.sys Processor Device Driver
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- csc.sys Windows Client Side Caching driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kd.dll Local Kernal Debugger (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate_AuthenticAMD.dll AMD Microcode Update Library (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- MpKsl58d732fe.sys Microsoft Anti-malware Protection driver
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msgpioclx.sys GPIO Class Extension Driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- ndisuio.sys NDIS User mode I/O driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- qwavedrv.sys Quality Windows Audio Video Experience (qWave) Support driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdpvideominiport.sys RDP Video Miniport driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- UcmCx.sys USB Connector Manager KMDF Class Extension
- ucx01000.sys USB Controller Extension (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- winquic.sys QUIC Transport Protocol driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- ====================== Dump #4: UNLOADED MODULES =======================
- fffff806`46740000 fffff806`46a63000 BEDaisy.sys
- fffff806`48800000 fffff806`4880f000 hiber_storpo
- fffff806`48810000 fffff806`4883f000 hiber_storah
- fffff806`48840000 fffff806`4885e000 hiber_dumpfv
- fffff806`46740000 fffff806`46a63000 BEDaisy.sys
- fffff806`487a0000 fffff806`487af000 hiber_storpo
- fffff806`487b0000 fffff806`487df000 hiber_storah
- fffff806`487e0000 fffff806`487fe000 hiber_dumpfv
- fffff806`46740000 fffff806`46a63000 BEDaisy.sys
- fffff806`482a0000 fffff806`482d8000 usbaudio.sys
- fffff806`48700000 fffff806`4870f000 hiber_storpo
- fffff806`48710000 fffff806`4873f000 hiber_storah
- fffff806`48740000 fffff806`4875e000 hiber_dumpfv
- fffff806`46740000 fffff806`46a63000 BEDaisy.sys
- fffff806`3ac90000 fffff806`3ace5000 WdFilter.sys
- fffff806`48600000 fffff806`48613000 WdNisDrv.sys
- fffff806`44d40000 fffff806`44d4f000 dump_storpor
- fffff806`44d80000 fffff806`44daf000 dump_storahc
- fffff806`44dd0000 fffff806`44dee000 dump_dumpfve
- fffff806`44860000 fffff806`4487e000 dam.sys
- fffff806`3a7d0000 fffff806`3a7e1000 WdBoot.sys
- fffff806`3b7d0000 fffff806`3b7e0000 hwpolicy.sys
- ====================== Dump #4: BIOS INFORMATION =======================
- sysinfo: could not find necessary interfaces.
- sysinfo: note that mssmbios.sys must be loaded (XPSP2+).
- ========================== Dump #4: Extra #1 ===========================
- 6: kd> !verifier
- Verify Flags Level 0x00000000
- STANDARD FLAGS:
- [X] (0x00000000) Automatic Checks
- [ ] (0x00000001) Special pool
- [ ] (0x00000002) Force IRQL checking
- [ ] (0x00000008) Pool tracking
- [ ] (0x00000010) I/O verification
- [ ] (0x00000020) Deadlock detection
- [ ] (0x00000080) DMA checking
- [ ] (0x00000100) Security checks
- [ ] (0x00000800) Miscellaneous checks
- [ ] (0x00020000) DDI compliance checking
- ADDITIONAL FLAGS:
- [ ] (0x00000004) Randomized low resources simulation
- [ ] (0x00000200) Force pending I/O requests
- [ ] (0x00000400) IRP logging
- [ ] (0x00002000) Invariant MDL checking for stack
- [ ] (0x00004000) Invariant MDL checking for driver
- [ ] (0x00008000) Power framework delay fuzzing
- [ ] (0x00010000) Port/miniport interface checking
- [ ] (0x00040000) Systematic low resources simulation
- [ ] (0x00080000) DDI compliance checking (additional)
- [ ] (0x00200000) NDIS/WIFI verification
- [ ] (0x00800000) Kernel synchronization delay fuzzing
- [ ] (0x01000000) VM switch verification
- [ ] (0x02000000) Code integrity checks
- [X] Indicates flag is enabled
- Summary of All Verifier Statistics
- RaiseIrqls 0x0
- AcquireSpinLocks 0x0
- Synch Executions 0x0
- Trims 0x0
- Pool Allocations Attempted 0x0
- Pool Allocations Succeeded 0x0
- Pool Allocations Succeeded SpecialPool 0x0
- Pool Allocations With NO TAG 0x0
- Pool Allocations Failed 0x0
- Current paged pool allocations 0x0 for 00000000 bytes
- Peak paged pool allocations 0x0 for 00000000 bytes
- Current nonpaged pool allocations 0x0 for 00000000 bytes
- Peak nonpaged pool allocations 0x0 for 00000000 bytes
- ========================== Dump #4: Extra #2 ===========================
- 6: kd> !thread
- THREAD ffffc202bd91a080 Cid 28bc.2520 Teb: 0000000000db2000 Win32Thread: 0000000000000000 RUNNING on processor 6
- Not impersonating
- GetUlongFromAddress: unable to read from fffff80638427604
- Owning Process ffffc202bf7172c0 Image: steam.exe
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 4171380
- Context Switch Count 33169 IdealProcessor: 10
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address 0x0000000063145950
- Stack Init ffff8209c7f8ec90 Current ffff8209c7f8e6e0
- Base ffff8209c7f8f000 Limit ffff8209c7f89000 Call 0000000000000000
- Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- ffff8209`c7f8d628 fffff806`381ce469 : 00000000`0000003b 00000000`c0000005 fffff806`3802edfa ffff8209`c7f8df60 : nt!KeBugCheckEx
- ffff8209`c7f8d630 fffff806`381cd8bc : ffff8209`c7f8e718 ffff8209`c7f8df60 fffff806`3853d5b4 ffff8209`c7f8ea00 : nt!KiBugCheckDispatch+0x69
- ffff8209`c7f8d770 fffff806`381c5512 : fffff806`3850c000 fffff806`38000000 0005e5cc`00ab2000 00000000`0010001f : nt!KiSystemServiceHandler+0x7c
- ffff8209`c7f8d7b0 fffff806`380b4745 : 00000000`00000000 00000000`00000000 ffff8209`c7f8dd20 00007fff`ffff0000 : nt!RtlpExecuteHandlerForException+0x12
- ffff8209`c7f8d7e0 fffff806`380b865e : ffff8209`c7f8e718 ffff8209`c7f8e460 ffff8209`c7f8e718 00000000`00000e10 : nt!RtlDispatchException+0x4a5
- ffff8209`c7f8df30 fffff806`381ce59d : fffff8fc`7e3f1000 ffff8209`c7f8e7c0 ffff8000`00000000 00000000`00000e30 : nt!KiDispatchException+0x16e
- ffff8209`c7f8e5e0 fffff806`381ca77f : 00000000`00000000 fffff806`38033445 ffffc202`bd91a1c0 00000000`00000000 : nt!KiExceptionDispatch+0x11d
- ffff8209`c7f8e7c0 fffff806`3802edfa : 00000000`00000000 00000000`00000001 ffffd281`1c364180 00000000`00000000 : nt!KiPageFault+0x43f (TrapFrame @ ffff8209`c7f8e7c0)
- ffff8209`c7f8e950 fffff806`381e8d33 : ffffc202`bd91a080 ffff8209`c7f8ea21 00000000`00000102 00000000`00000000 : nt!KeAbPreAcquire+0x11a
- ffff8209`c7f8e9a0 fffff806`3861fa1b : ffffc202`c3369060 ffff8209`00000006 00000000`00000001 ffffa1a7`d1b7a100 : nt!KeWaitForSingleObject+0x1b8893
- ffff8209`c7f8ea80 fffff806`381ce3d1 : ffffc202`bd91a080 00000000`00000000 ffff8209`c7f8eb18 ffffffff`ffd9da60 : nt!NtWaitForSingleObject+0x10b
- ffff8209`c7f8eb00 00000000`77051cbc : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExitPico+0x2bc (TrapFrame @ ffff8209`c7f8eb00)
- 00000000`0a45f088 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77051cbc
- ========================================================================
- ======================= Dump #5: ANALYZE VERBOSE =======================
- ======================= File: 121320-9812-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 18362 MP (16 procs) Free x64
- Kernel base = 0xfffff800`16400000 PsLoadedModuleList = 0xfffff800`16843290
- Debug session time: Sun Dec 13 07:05:32.987 2020 (UTC - 5:00)
- System Uptime: 0 days 0:02:12.640
- BugCheck 1, {fffff80016a492f0, 0, ffff, 1}
- *** WARNING: Unable to verify timestamp for win32k.sys
- *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
- Probably caused by : memory_corruption
- Followup: memory_corruption
- APC_INDEX_MISMATCH (1)
- This is a kernel internal error. The most common reason to see this
- bugcheck is when a filesystem or a driver has a mismatched number of
- calls to disable and re-enable APCs. The key data item is the
- Thread->CombinedApcDisable field. This consists of two separate 16-bit
- fields, the SpecialApcDisable and the KernelApcDisable. A negative value
- of either indicates that a driver has disabled special or normal APCs
- (respectively) without re-enabling them; a positive value indicates that
- a driver has enabled special or normal APCs (respectively) too many times.
- Arguments:
- Arg1: fffff80016a492f0, Address of system call function or worker routine
- Arg2: 0000000000000000, Thread->ApcStateIndex
- Arg3: 000000000000ffff, (Thread->SpecialApcDisable << 16) | Thread->KernelApcDisable
- Arg4: 0000000000000001, Call type (0 - system call, 1 - worker routine)
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- FAULTING_IP:
- nt!PfSnPopulateReadList+0
- fffff800`16a492f0 4c8bdc mov r11,rsp
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- BUGCHECK_STR: 0x1
- PROCESS_NAME: System
- CURRENT_IRQL: 0
- LAST_CONTROL_TRANSFER: from fffff8001661dda3 to fffff800165bc810
- STACK_TEXT:
- fffff18b`aa302b68 fffff800`1661dda3 : 00000000`00000001 fffff800`16a492f0 00000000`00000000 00000000`0000ffff : nt!KeBugCheckEx
- fffff18b`aa302b70 fffff800`16530925 : ffff9f85`10a0e140 00000000`00000080 ffff9f85`10876080 00000000`00000000 : nt!ExpWorkerThread+0x16f673
- fffff18b`aa302c10 fffff800`165c3d5a : fffff800`119c5180 ffff9f85`10a0e140 fffff800`165308d0 0000020b`8a65bb00 : nt!PspSystemThreadStartup+0x55
- fffff18b`aa302c60 00000000`00000000 : fffff18b`aa303000 fffff18b`aa2fd000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x2a
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
- fffff800166ab9bf-fffff800166ab9c0 2 bytes - nt!KeSwitchFrozenProcessor+8f
- [ 48 ff:4c 8b ]
- fffff800166ab9c6-fffff800166ab9ca 5 bytes - nt!KeSwitchFrozenProcessor+96 (+0x07)
- [ 0f 1f 44 00 00:e8 f5 2d cb ff ]
- 7 errors : !nt (fffff800166ab9bf-fffff800166ab9ca)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-12-13T12:05:32.000Z
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #5: 3RD PARTY DRIVERS ======================
- Jun 11 2018 - e1i65x64.sys - Intel(R) Gigabit Adapter driver
- Dec 09 2018 - UcmCxUcsiNvppc.sys - NVIDIA USB Type-C Port Policy Controller driver
- Feb 07 2019 - amdgpio2.sys - AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Mar 14 2019 - nvvad64v.sys - Nvidia Virtual Audio driver http://www.nvidia.com/
- May 14 2019 - RTKVHD64.sys - Realtek Audio System driver https://www.realtek.com/en/
- Jun 19 2019 - amdpsp.sys - Advanced Micro Devices, Inc http://support.amd.com/
- Sep 11 2019 - AMDPCIDev.sys - Advanced Micro Devices PCI Device driver
- Oct 02 2019 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- Nov 29 2019 - NvModuleTracker.sys - NVIDIA Module Tracker driver
- Jan 10 2020 - nvvhci.sys - Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Oct 16 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- ================== Dump #5: 3RD PARTY DRIVERS (FULL) ===================
- Mapped memory image file: C:\ProgramData\dbg\sym\e1i65x64.sys\5B1EB8E28e000\e1i65x64.sys
- Image path: \SystemRoot\System32\drivers\e1i65x64.sys
- Image name: e1i65x64.sys
- Search : https://www.google.com/search?q=e1i65x64.sys
- ADA Info : Intel(R) Gigabit Adapter driver
- Timestamp : Mon Jun 11 2018
- File version: 12.17.10.8
- Product version: 10.0.10011.16384
- File flags: 8 (Mask 3F) Private
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- CompanyName: Intel Corporation
- ProductName: Intel(R) Gigabit Adapter
- InternalName: e1i65x64.sys
- OriginalFilename: e1i65x64.sys
- ProductVersion: 12.17.10.8
- FileVersion: 12.17.10.8
- FileDescription: Intel(R) Gigabit Adapter NDIS 6.x driver
- LegalCopyright: Copyright(C) 2013, Intel Corporation. All rights reserved.
- Image path: \SystemRoot\System32\drivers\UcmCxUcsiNvppc.sys
- Image name: UcmCxUcsiNvppc.sys
- Search : https://www.google.com/search?q=UcmCxUcsiNvppc.sys
- ADA Info : NVIDIA USB Type-C Port Policy Controller driver
- Timestamp : Sun Dec 9 2018
- Mapped memory image file: C:\ProgramData\dbg\sym\amdgpio2.sys\5C5BFB24c000\amdgpio2.sys
- Image path: \SystemRoot\System32\drivers\amdgpio2.sys
- Image name: amdgpio2.sys
- Search : https://www.google.com/search?q=amdgpio2.sys
- ADA Info : AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Timestamp : Thu Feb 7 2019
- File version: 2.2.0.71
- Product version: 2.2.0.71
- File flags: 8 (Mask 3F) Private
- File OS: 40004 NT Win32
- File type: 3.7 Driver
- File date: 00000000.00000000
- CompanyName: Advanced Micro Devices, Inc
- ProductName: AMD GPIO Controller Driver
- InternalName: amdgpio2.sys
- OriginalFilename: amdgpio2.sys
- ProductVersion: 2.2.0.71
- FileVersion: 2.2.0.71
- FileDescription: AMD GPIO Controller Driver
- LegalCopyright: Copyright © 2012-2019 Advanced Micro Devices, Inc
- Image path: \SystemRoot\system32\drivers\nvvad64v.sys
- Image name: nvvad64v.sys
- Search : https://www.google.com/search?q=nvvad64v.sys
- ADA Info : Nvidia Virtual Audio driver http://www.nvidia.com/
- Timestamp : Thu Mar 14 2019
- Image path: \SystemRoot\system32\drivers\RTKVHD64.sys
- Image name: RTKVHD64.sys
- Search : https://www.google.com/search?q=RTKVHD64.sys
- ADA Info : Realtek Audio System driver https://www.realtek.com/en/
- Timestamp : Tue May 14 2019
- Image path: \SystemRoot\System32\drivers\amdpsp.sys
- Image name: amdpsp.sys
- Search : https://www.google.com/search?q=amdpsp.sys
- ADA Info : Advanced Micro Devices, Inc http://support.amd.com/
- Timestamp : Wed Jun 19 2019
- Image path: \SystemRoot\System32\drivers\AMDPCIDev.sys
- Image name: AMDPCIDev.sys
- Search : https://www.google.com/search?q=AMDPCIDev.sys
- ADA Info : Advanced Micro Devices PCI Device driver
- Timestamp : Wed Sep 11 2019
- Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_90685a092bcf58c7\nvlddmkm.sys
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Wed Oct 2 2019
- Image path: \SystemRoot\System32\drivers\NvModuleTracker.sys
- Image name: NvModuleTracker.sys
- Search : https://www.google.com/search?q=NvModuleTracker.sys
- ADA Info : NVIDIA Module Tracker driver
- Timestamp : Fri Nov 29 2019
- Image path: \SystemRoot\System32\drivers\nvvhci.sys
- Image name: nvvhci.sys
- Search : https://www.google.com/search?q=nvvhci.sys
- ADA Info : Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Timestamp : Fri Jan 10 2020
- Image path: \SystemRoot\system32\drivers\nvhda64v.sys
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Fri Oct 16 2020
- ====================== Dump #5: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- amdppm.sys Processor Device Driver
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- csc.sys Windows Client Side Caching driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kd.dll Local Kernal Debugger (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate_AuthenticAMD.dll AMD Microcode Update Library (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- MpKsl58d732fe.sys Microsoft Anti-malware Protection driver
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msgpioclx.sys GPIO Class Extension Driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- UcmCx.sys USB Connector Manager KMDF Class Extension
- ucx01000.sys USB Controller Extension (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- winquic.sys QUIC Transport Protocol driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- ====================== Dump #5: UNLOADED MODULES =======================
- fffff800`21b70000 fffff800`21b7f000 dump_storpor
- fffff800`21bb0000 fffff800`21bdf000 dump_storahc
- fffff800`21600000 fffff800`2161e000 dump_dumpfve
- fffff800`21e30000 fffff800`21e4e000 dam.sys
- fffff800`17dd0000 fffff800`17de1000 WdBoot.sys
- fffff800`18dd0000 fffff800`18de0000 hwpolicy.sys
- ====================== Dump #5: BIOS INFORMATION =======================
- sysinfo: could not find necessary interfaces.
- sysinfo: note that mssmbios.sys must be loaded (XPSP2+).
- ========================== Dump #5: Extra #1 ===========================
- 4: kd> !verifier
- Verify Flags Level 0x00000000
- STANDARD FLAGS:
- [X] (0x00000000) Automatic Checks
- [ ] (0x00000001) Special pool
- [ ] (0x00000002) Force IRQL checking
- [ ] (0x00000008) Pool tracking
- [ ] (0x00000010) I/O verification
- [ ] (0x00000020) Deadlock detection
- [ ] (0x00000080) DMA checking
- [ ] (0x00000100) Security checks
- [ ] (0x00000800) Miscellaneous checks
- [ ] (0x00020000) DDI compliance checking
- ADDITIONAL FLAGS:
- [ ] (0x00000004) Randomized low resources simulation
- [ ] (0x00000200) Force pending I/O requests
- [ ] (0x00000400) IRP logging
- [ ] (0x00002000) Invariant MDL checking for stack
- [ ] (0x00004000) Invariant MDL checking for driver
- [ ] (0x00008000) Power framework delay fuzzing
- [ ] (0x00010000) Port/miniport interface checking
- [ ] (0x00040000) Systematic low resources simulation
- [ ] (0x00080000) DDI compliance checking (additional)
- [ ] (0x00200000) NDIS/WIFI verification
- [ ] (0x00800000) Kernel synchronization delay fuzzing
- [ ] (0x01000000) VM switch verification
- [ ] (0x02000000) Code integrity checks
- [X] Indicates flag is enabled
- Summary of All Verifier Statistics
- RaiseIrqls 0x0
- AcquireSpinLocks 0x0
- Synch Executions 0x0
- Trims 0x0
- Pool Allocations Attempted 0x0
- Pool Allocations Succeeded 0x0
- Pool Allocations Succeeded SpecialPool 0x0
- Pool Allocations With NO TAG 0x0
- Pool Allocations Failed 0x0
- Current paged pool allocations 0x0 for 00000000 bytes
- Peak paged pool allocations 0x0 for 00000000 bytes
- Current nonpaged pool allocations 0x0 for 00000000 bytes
- Peak nonpaged pool allocations 0x0 for 00000000 bytes
- ========================== Dump #5: Extra #2 ===========================
- 4: kd> !thread
- THREAD ffff9f8510a0e140 Cid 0004.0020 Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor 4
- Not impersonating
- GetUlongFromAddress: unable to read from fffff80016827604
- Owning Process ffff9f8510876080 Image: System
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 8488
- Context Switch Count 374 IdealProcessor: 4
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address nt!ExpWorkerThread (0xfffff800164ae730)
- Stack Init fffff18baa302c90 Current fffff18baa301220
- Base fffff18baa303000 Limit fffff18baa2fd000 Call 0000000000000000
- Priority 10 BasePriority 9 PriorityDecrement 0 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- fffff18b`aa302b68 fffff800`1661dda3 : 00000000`00000001 fffff800`16a492f0 00000000`00000000 00000000`0000ffff : nt!KeBugCheckEx
- fffff18b`aa302b70 fffff800`16530925 : ffff9f85`10a0e140 00000000`00000080 ffff9f85`10876080 00000000`00000000 : nt!ExpWorkerThread+0x16f673
- fffff18b`aa302c10 fffff800`165c3d5a : fffff800`119c5180 ffff9f85`10a0e140 fffff800`165308d0 0000020b`8a65bb00 : nt!PspSystemThreadStartup+0x55
- fffff18b`aa302c60 00000000`00000000 : fffff18b`aa303000 fffff18b`aa2fd000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x2a
Advertisement
Add Comment
Please, Sign In to add comment