Guest User

Untitled

a guest
Jul 1st, 2019
1,351
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 66.01 KB | None | 0 0
  1. ========================== AUTO DUMP ANALYZER ==========================
  2. Auto Dump Analyzer
  3. Version: 0.9
  4. Time to analyze file(s): 00 hours and 03 minutes and 17 seconds
  5.  
  6. ================================ SYSTEM ================================
  7. MANUFACTURER: Micro-Star International Co., Ltd.
  8. PRODUCT_NAME: MS-7B79
  9. VERSION: 2.0
  10.  
  11. ================================= BIOS =================================
  12. VENDOR: American Megatrends Inc.
  13. VERSION: A.90
  14. DATE: 03/07/2019
  15.  
  16. ============================= MOTHERBOARD ==============================
  17. MANUFACTURER: Micro-Star International Co., Ltd.
  18. PRODUCT: X470 GAMING PLUS (MS-7B79)
  19. VERSION: 2.0
  20.  
  21. ================================= RAM ==================================
  22. Size Speed Manufacturer Part No.
  23. -------------- -------------- ------------------- ----------------------
  24. 2400MHz Unknown Unknown
  25. 8192MB 2400MHz Unknown F4-2400C15-8GFX
  26. 2400MHz Unknown Unknown
  27. 8192MB 2400MHz Unknown F4-2400C15-8GFX
  28.  
  29. ================================= CPU ==================================
  30. Processor Version: AMD Ryzen 7 2700X Eight-Core Processor
  31. COUNT: 10
  32. MHZ: 3700
  33. VENDOR: AuthenticAMD
  34. FAMILY: 17
  35. MODEL: 8
  36. STEPPING: 2
  37.  
  38. ================================== OS ==================================
  39. Product: WinNt, suite: TerminalServer SingleUserTS
  40. Built by: 18362.1.amd64fre.19h1_release.190318-1202
  41. BUILD_VERSION: 18362.1.amd64fre.19h1_release.190318-1202
  42. BUILD: 18362
  43. SERVICEPACK: 0
  44. PLATFORM_TYPE: x64
  45. NAME: Windows 10
  46. EDITION: Windows 10 WinNt TerminalServer SingleUserTS
  47. BUILD_TIMESTAMP: unknown_date
  48. BUILDDATESTAMP: 190318-1202
  49. BUILDLAB: 19h1_release
  50. BUILDOSVER: 10.0.18362.1.amd64fre.19h1_release.190318-1202
  51.  
  52. =============================== DEBUGGER ===============================
  53. Microsoft (R) Windows Debugger Version 10.0.14321.1024 AMD64
  54. Copyright (c) Microsoft Corporation. All rights reserved.
  55.  
  56. =============================== COMMENTS ===============================
  57. * Information gathered from different dump files may be different. If
  58. Windows updates between two dump files, two or more OS versions may
  59. be shown above.
  60. * If the user updates the BIOS between dump files, two or more versions
  61. and dates may be shown above.
  62. * More RAM information can be found below in the full BIOS section.
  63.  
  64.  
  65.  
  66. ========================================================================
  67. ==================== Dump File: 063019-9468-01.dmp =====================
  68. ========================================================================
  69. Mini Kernel Dump File: Only registers and stack trace are available
  70. Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
  71. *** WARNING: Unable to verify timestamp for ntoskrnl.exe
  72. *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
  73. Windows 10 Kernel Version 18362 MP (16 procs) Free x64
  74. Kernel base = 0xfffff804`0c200000 PsLoadedModuleList = 0xfffff804`0c643370
  75. Debug session time: Mon Jul 1 00:33:56.913 2019 (UTC - 4:00)
  76. System Uptime: 0 days 0:13:36.608
  77. Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
  78. *** WARNING: Unable to verify timestamp for ntoskrnl.exe
  79. *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
  80.  
  81. ************* Symbol Loading Error Summary **************
  82. Module name Error
  83. ntoskrnl The system cannot find the file specified
  84. You can troubleshoot most symbol related issues by turning on symbol loading diagnostics (!sym noisy) and repeating the command that caused symbols to be loaded.
  85. You should also verify that your symbol search path (.sympath) is correct.
  86.  
  87. BugCheck A, {10, 2, 0, fffff8040c21994f}
  88. ***** Kernel symbols are WRONG. Please fix symbols to do analysis.
  89. *** WARNING: Unable to verify timestamp for win32k.sys
  90. *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
  91. Probably caused by : memory_corruption
  92. Followup: memory_corruption
  93.  
  94. IRQL_NOT_LESS_OR_EQUAL (a)
  95. An attempt was made to access a pageable (or completely invalid) address at an
  96. interrupt request level (IRQL) that is too high. This is usually
  97. caused by drivers using improper addresses.
  98. If a kernel debugger is available get the stack backtrace.
  99.  
  100. Arguments:
  101. Arg1: 0000000000000010, memory referenced
  102. Arg2: 0000000000000002, IRQL
  103. Arg3: 0000000000000000, bitfield :
  104. bit 0 : value 0 = read operation, 1 = write operation
  105. bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
  106. Arg4: fffff8040c21994f, address which referenced memory
  107.  
  108. Debugging Details:
  109. ***** Kernel symbols are WRONG. Please fix symbols to do analysis.
  110. DUMP_CLASS: 1
  111. DUMP_QUALIFIER: 400
  112. ADDITIONAL_DEBUG_TEXT:
  113. You can run '.symfix; .reload' to try to fix the symbol path and load symbols.
  114. WRONG_SYMBOLS_TIMESTAMP: eadcd02b
  115. WRONG_SYMBOLS_SIZE: ab2000
  116. FAULTING_MODULE: fffff8040c200000 nt
  117. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  118. DUMP_TYPE: 2
  119. READ_ADDRESS: *************************************************************************
  120. Unable to get size of nt!_MMPTE - probably bad symbols
  121. 0000000000000010
  122. CURRENT_IRQL: 0
  123. FAULTING_IP:
  124. nt+1994f
  125. fffff804`0c21994f 49034710 add rax,qword ptr [r15+10h]
  126. CUSTOMER_CRASH_COUNT: 1
  127. DEFAULT_BUCKET_ID: CODE_CORRUPTION
  128. BUGCHECK_STR: AV
  129. LAST_CONTROL_TRANSFER: from fffff8040c3ce569 to fffff8040c3bc8a0
  130. STACK_TEXT:
  131. fffffd09`9b7cc748 fffff804`0c3ce569 : 00000000`0000000a 00000000`00000010 00000000`00000002 00000000`00000000 : nt+0x1bc8a0
  132. fffffd09`9b7cc750 00000000`0000000a : 00000000`00000010 00000000`00000002 00000000`00000000 fffff804`0c21994f : nt+0x1ce569
  133. fffffd09`9b7cc758 00000000`00000010 : 00000000`00000002 00000000`00000000 fffff804`0c21994f 00000000`00000000 : 0xa
  134. fffffd09`9b7cc760 00000000`00000002 : 00000000`00000000 fffff804`0c21994f 00000000`00000000 00000000`00000000 : 0x10
  135. fffffd09`9b7cc768 00000000`00000000 : fffff804`0c21994f 00000000`00000000 00000000`00000000 00000000`00000000 : 0x2
  136. STACK_COMMAND: kb
  137. CHKIMG_EXTENSION: !chkimg -lo 50 -d !hal
  138. fffff8040ccb3c53 - hal!HalpApicRequestInterrupt+a3
  139. [ 00:90 ]
  140. fffff8040ccb3cc1-fffff8040ccb3cc6 6 bytes - hal!HalpApicRequestInterrupt+111 (+0x6e)
  141. [ ff 15 41 6c 07 00:e8 da c5 89 ff 90 ]
  142. fffff8040ccb52ca - hal!HalPerformEndOfInterrupt+1a (+0x1609)
  143. [ 00:90 ]
  144. fffff8040ccb53a7-fffff8040ccb53a8 2 bytes - hal!HalPutScatterGatherList+67 (+0xdd)
  145. [ 48 ff:4c 8b ]
  146. fffff8040ccb53ae-fffff8040ccb53b2 5 bytes - hal!HalPutScatterGatherList+6e (+0x07)
  147. [ 0f 1f 44 00 00:e8 ed 4c 8b ff ]
  148. 15 errors : !hal (fffff8040ccb3c53-fffff8040ccb53b2)
  149. MODULE_NAME: memory_corruption
  150.  
  151. IMAGE_NAME: memory_corruption
  152.  
  153. FOLLOWUP_NAME: memory_corruption
  154. MEMORY_CORRUPTOR: LARGE
  155. FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
  156. BUCKET_ID: MEMORY_CORRUPTION_LARGE
  157. PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
  158. TARGET_TIME: 2019-07-01T04:33:56.000Z
  159. SUITE_MASK: 272
  160. PRODUCT_TYPE: 1
  161. USER_LCID: 0
  162. FAILURE_ID_HASH_STRING: km:memory_corruption_large
  163. FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
  164. Followup: memory_corruption
  165.  
  166. ========================================================================
  167. ===================== 3RD PARTY DRIVER QUICK LIST ======================
  168. ========================================================================
  169. Mar 19 2015 - amd_sata.sys - AMD SATA Controller AHCI Device driver http://support.amd.com/
  170. Mar 19 2015 - amd_xata.sys - AMD Stor Filter driver http://support.amd.com/
  171. Mar 14 2016 - amdgpio3.sys - AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
  172. Aug 16 2018 - nvvhci.sys - Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
  173. Sep 10 2018 - amdpsp.sys - Advanced Micro Devices, Inc http://support.amd.com/
  174. Oct 11 2018 - AMDPCIDev.sys - Advanced Micro Devices PCI Device driver
  175. Nov 12 2018 - amdgpio2.sys - AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
  176. Mar 05 2019 - RTKVHD64.sys - Realtek Audio Driver system driver https://www.realtek.com/en/
  177. Mar 07 2019 - rt640x64.sys - Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
  178. Mar 14 2019 - nvvad64v.sys - Nvidia Virtual Audio Driver http://www.nvidia.com/
  179. Mar 19 2019 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
  180. Mar 25 2019 - asmthub3.sys - ASMedia USB 3.0 Hub driver http://www.asmedia.com.tw/
  181. Mar 25 2019 - asmtxhci.sys - ASMedia USB 3.0 driver http://www.asmedia.com.tw/
  182.  
  183. ========================================================================
  184. ========================== 3RD PARTY DRIVERS ===========================
  185. ========================================================================
  186. Image path: \SystemRoot\System32\drivers\amd_sata.sys
  187. Image name: amd_sata.sys
  188. Search : https://www.google.com/search?q=amd_sata.sys
  189. ADA Info : AMD SATA Controller AHCI Device driver http://support.amd.com/
  190. Timestamp : Thu Mar 19 2015
  191.  
  192. Image path: \SystemRoot\System32\drivers\amd_xata.sys
  193. Image name: amd_xata.sys
  194. Search : https://www.google.com/search?q=amd_xata.sys
  195. ADA Info : AMD Stor Filter driver http://support.amd.com/
  196. Timestamp : Thu Mar 19 2015
  197.  
  198. Image path: \SystemRoot\System32\drivers\amdgpio3.sys
  199. Image name: amdgpio3.sys
  200. Search : https://www.google.com/search?q=amdgpio3.sys
  201. ADA Info : AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
  202. Timestamp : Mon Mar 14 2016
  203.  
  204. Image path: \SystemRoot\System32\drivers\nvvhci.sys
  205. Image name: nvvhci.sys
  206. Search : https://www.google.com/search?q=nvvhci.sys
  207. ADA Info : Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
  208. Timestamp : Thu Aug 16 2018
  209.  
  210. Image path: \SystemRoot\System32\drivers\amdpsp.sys
  211. Image name: amdpsp.sys
  212. Search : https://www.google.com/search?q=amdpsp.sys
  213. ADA Info : Advanced Micro Devices, Inc http://support.amd.com/
  214. Timestamp : Mon Sep 10 2018
  215.  
  216. Image path: \SystemRoot\System32\drivers\AMDPCIDev.sys
  217. Image name: AMDPCIDev.sys
  218. Search : https://www.google.com/search?q=AMDPCIDev.sys
  219. ADA Info : Advanced Micro Devices PCI Device driver
  220. Timestamp : Thu Oct 11 2018
  221.  
  222. Image path: \SystemRoot\System32\drivers\amdgpio2.sys
  223. Image name: amdgpio2.sys
  224. Search : https://www.google.com/search?q=amdgpio2.sys
  225. ADA Info : AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
  226. Timestamp : Mon Nov 12 2018
  227.  
  228. Image path: \SystemRoot\system32\drivers\RTKVHD64.sys
  229. Image name: RTKVHD64.sys
  230. Search : https://www.google.com/search?q=RTKVHD64.sys
  231. ADA Info : Realtek Audio Driver system driver https://www.realtek.com/en/
  232. Timestamp : Tue Mar 5 2019
  233.  
  234. Image path: \SystemRoot\System32\drivers\rt640x64.sys
  235. Image name: rt640x64.sys
  236. Search : https://www.google.com/search?q=rt640x64.sys
  237. ADA Info : Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
  238. Timestamp : Thu Mar 7 2019
  239.  
  240. Image path: \SystemRoot\system32\drivers\nvvad64v.sys
  241. Image name: nvvad64v.sys
  242. Search : https://www.google.com/search?q=nvvad64v.sys
  243. ADA Info : Nvidia Virtual Audio Driver http://www.nvidia.com/
  244. Timestamp : Thu Mar 14 2019
  245.  
  246. Image path: \SystemRoot\system32\drivers\nvhda64v.sys
  247. Image name: nvhda64v.sys
  248. Search : https://www.google.com/search?q=nvhda64v.sys
  249. ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
  250. Timestamp : Tue Mar 19 2019
  251.  
  252. Image path: \SystemRoot\System32\drivers\asmthub3.sys
  253. Image name: asmthub3.sys
  254. Search : https://www.google.com/search?q=asmthub3.sys
  255. ADA Info : ASMedia USB 3.0 Hub driver http://www.asmedia.com.tw/
  256. Timestamp : Mon Mar 25 2019
  257.  
  258. Image path: \SystemRoot\System32\drivers\asmtxhci.sys
  259. Image name: asmtxhci.sys
  260. Search : https://www.google.com/search?q=asmtxhci.sys
  261. ADA Info : ASMedia USB 3.0 driver http://www.asmedia.com.tw/
  262. Timestamp : Mon Mar 25 2019
  263.  
  264. If any of the above drivers are from Microsoft then please let me know.
  265. I will have them moved to the Microsoft list on the next update.
  266.  
  267. ========================================================================
  268. ========================== MICROSOFT DRIVERS ===========================
  269. ========================================================================
  270. ACPI.sys ACPI Driver for NT (Microsoft)
  271. acpiex.sys ACPIEx Driver (Microsoft)
  272. afd.sys Ancillary Function Driver for WinSock (Microsoft)
  273. afunix.sys AF_UNIX Socket Provider driver (Microsoft)
  274. AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
  275. ahcache.sys Application Compatibility Cache (Microsoft)
  276. amdppm.sys Processor Device Driver
  277. bam.sys BAM Kernal driver (Microsoft)
  278. BasicDisplay.sys Basic Display driver (Microsoft)
  279. BasicRender.sys Basic Render driver (Microsoft)
  280. Beep.SYS BEEP driver (Microsoft)
  281. BOOTVID.dll VGA Boot Driver (Microsoft)
  282. bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
  283. cdd.dll Canonical Display Driver (Microsoft)
  284. cdrom.sys SCSI CD-ROM Driver (Microsoft)
  285. CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
  286. CI.dll Code Integrity Module (Microsoft)
  287. CLASSPNP.SYS SCSI Class System Dll (Microsoft)
  288. cldflt.sys Cloud Files Mini Filter driver (Microsoft)
  289. CLFS.SYS Common Log File System Driver (Microsoft)
  290. clipsp.sys CLIP Service (Microsoft)
  291. cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
  292. cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
  293. CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
  294. condrv.sys Console Driver (Microsoft)
  295. crashdmp.sys Crash Dump driver (Microsoft)
  296. csc.sys Windows Client Side Caching driver (Microsoft)
  297. dc1-controller.sys KMDF driver for DC1 Controller
  298. DevAuthE.sys Xbox Device Authentication Driver
  299. dfsc.sys DFS Namespace Client Driver (Microsoft)
  300. disk.sys PnP Disk Driver (Microsoft)
  301. drmk.sys Digital Rights Management (DRM) driver (Microsoft)
  302. dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  303. dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  304. dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  305. dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
  306. dxgmms2.sys DirectX Graphics MMS
  307. fastfat.SYS Fast FAT File System Driver (Microsoft)
  308. filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
  309. fileinfo.sys FileInfo Filter Driver (Microsoft)
  310. FLTMGR.SYS Filesystem Filter Manager (Microsoft)
  311. Fs_Rec.sys File System Recognizer Driver (Microsoft)
  312. fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
  313. fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
  314. gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
  315. hal.dll Hardware Abstraction Layer DLL (Microsoft)
  316. HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
  317. HIDCLASS.SYS Hid Class Library (Microsoft)
  318. HIDPARSE.SYS Hid Parsing Library (Microsoft)
  319. hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
  320. HTTP.sys HTTP Protocol Stack (Microsoft)
  321. intelpep.sys Intel Power Engine Plugin (Microsoft)
  322. iorate.sys I/O rate control Filter (Microsoft)
  323. kbdclass.sys Keyboard Class Driver (Microsoft)
  324. kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
  325. kd.dll Local Kernal Debugger (Microsoft)
  326. kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
  327. ks.sys Kernal CSA Library (Microsoft)
  328. ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
  329. ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
  330. ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
  331. lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
  332. luafv.sys LUA File Virtualization Filter Driver (Microsoft)
  333. mcupdate_AuthenticAMD.dll AMD Microcode Update Library (Microsoft)
  334. mmcss.sys MMCSS Driver (Microsoft)
  335. monitor.sys Monitor Driver (Microsoft)
  336. mouclass.sys Mouse Class Driver (Microsoft)
  337. mouhid.sys HID Mouse Filter Driver (Microsoft)
  338. mountmgr.sys Mount Point Manager (Microsoft)
  339. mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
  340. mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
  341. mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
  342. Msfs.SYS Mailslot driver (Microsoft)
  343. msgpioclx.sys GPIO Class Extension Driver (Microsoft)
  344. msisadrv.sys ISA Driver (Microsoft)
  345. mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
  346. msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
  347. mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
  348. mssmbios.sys System Management BIOS driver (Microsoft)
  349. mup.sys Multiple UNC Provider driver (Microsoft)
  350. ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
  351. ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
  352. NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
  353. ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
  354. NDProxy.sys NDIS Proxy driver (Microsoft)
  355. Ndu.sys Network Data Usage Monitoring driver (Microsoft)
  356. netbios.sys NetBIOS Interface driver (Microsoft)
  357. netbt.sys MBT Transport driver (Microsoft)
  358. NETIO.SYS Network I/O Subsystem (Microsoft)
  359. Npfs.SYS NPFS driver (Microsoft)
  360. npsvctrig.sys Named pipe service triggers (Microsoft)
  361. nsiproxy.sys NSI Proxy driver (Microsoft)
  362. Ntfs.sys NT File System Driver (Microsoft)
  363. ntosext.sys NTOS Extension Host driver (Microsoft)
  364. ntoskrnl.exe NT Operating System Kernal (Microsoft)
  365. Null.SYS NULL Driver (Microsoft)
  366. pacer.sys QoS Packet Scheduler (Microsoft)
  367. parport.sys Parallel Port Driver (Microsoft)
  368. partmgr.sys Partition driver (Microsoft)
  369. pci.sys NT Plug and Play PCI Enumerator (Microsoft)
  370. pcw.sys Performance Counter Driver (Microsoft)
  371. pdc.sys Power Dependency Coordinator Driver (Microsoft)
  372. peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
  373. portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
  374. PSHED.dll Platform Specific Hardware Error driver (Microsoft)
  375. rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
  376. raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
  377. raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
  378. rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
  379. rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
  380. rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
  381. rdpdr.sys RDP Device redirector (Microsoft)
  382. rdpvideominiport.sys RDP Video Miniport driver (Microsoft)
  383. rdyboost.sys ReadyBoost Driver (Microsoft)
  384. rspndr.sys Link-Layer Topology Responder driver (Microsoft)
  385. serenum.sys Serial Port Enumerator (Microsoft)
  386. serial.sys Serial Device Driver
  387. SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
  388. SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
  389. spaceport.sys Storage Spaces driver (Microsoft)
  390. srv2.sys Smb 2.0 Server driver (Microsoft)
  391. srvnet.sys Server Network driver (Microsoft)
  392. storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
  393. storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
  394. storqosflt.sys Storage QoS Filter driver (Microsoft)
  395. swenum.sys Plug and Play Software Device Enumerator (Microsoft)
  396. tbs.sys Export driver for kernel mode TPM API (Microsoft)
  397. tcpip.sys TCP/IP Protocol driver (Microsoft)
  398. tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
  399. TDI.SYS TDI Wrapper driver (Microsoft)
  400. tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
  401. tm.sys Kernel Transaction Manager driver (Microsoft)
  402. tsusbhub.sys USB-Hub driver (Microsoft)
  403. ucx01000.sys USB Controller Extension (Microsoft)
  404. UEFI.sys UEFI NT driver (Microsoft)
  405. umbus.sys User-Mode Bus Enumerator (Microsoft)
  406. usbaudio.sys USB Audio Class Driver (Microsoft)
  407. usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
  408. USBD.SYS Universal Serial Bus Driver (Microsoft)
  409. UsbHub3.sys USB3 HUB driver (Microsoft)
  410. USBSTOR.SYS USB Mass Storage Class driver (Microsoft)
  411. USBXHCI.SYS USB XHCI driver (Microsoft)
  412. vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
  413. Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
  414. volmgr.sys Volume Manager Driver (Microsoft)
  415. volmgrx.sys Volume Manager Extension Driver (Microsoft)
  416. volsnap.sys Volume Shadow Copy driver (Microsoft)
  417. volume.sys Volume driver (Microsoft)
  418. vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
  419. wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
  420. watchdog.sys Watchdog driver (Microsoft)
  421. wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
  422. Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
  423. WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
  424. WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
  425. WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
  426. werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
  427. wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
  428. win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
  429. win32kbase.sys Base Win32k Kernel Driver (Microsoft)
  430. win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
  431. WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
  432. WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
  433. winhvr.sys Windows Hypervisor Root Interface Driver
  434. winquic.sys QUIC Transport Protocol driver (Microsoft)
  435. wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
  436. WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
  437. Wof.sys Windows Overlay Filter (Microsoft)
  438. WpdUpFltr.sys Portable Device Upper Class Filter driver (Microsoft)
  439. WppRecorder.sys WPP Trace Recorder (Microsoft)
  440. WUDFRd.sys Windows Driver Foundation - User-mode Driver Framework Reflector driver (Microsoft)
  441. xboxgip.sys Game Input Protocol Driver
  442. xinputhid.sys XINPUT filter driver for HID
  443.  
  444. Unloaded modules:
  445. fffff804`08d20000 fffff804`08d28000 NTIOLib_X64.
  446. fffff804`18fc0000 fffff804`18fcf000 dump_storpor
  447. fffff804`18c00000 fffff804`18c2f000 dump_storahc
  448. fffff804`18c50000 fffff804`18c6e000 dump_dumpfve
  449. fffff804`1aef0000 fffff804`1af41000 WUDFRd.sys
  450. fffff804`0f7a0000 fffff804`0f7bc000 EhStorClass.
  451. fffff804`199e0000 fffff804`19a31000 WUDFRd.sys
  452. fffff804`19800000 fffff804`1981e000 dam.sys
  453. fffff804`0f3f0000 fffff804`0f3f9000 MbamElam.sys
  454. fffff804`0f3d0000 fffff804`0f3e1000 WdBoot.sys
  455. fffff804`10410000 fffff804`10420000 hwpolicy.sys
  456.  
  457. ========================================================================
  458. ============================== BIOS INFO ===============================
  459. ========================================================================
  460. [SMBIOS Data Tables v2.8]
  461. [DMI Version - 0]
  462. [2.0 Calling Convention - No]
  463. [Table Size - 2475 bytes]
  464. [BIOS Information (Type 0) - Length 26 - Handle 0000h]
  465. Vendor American Megatrends Inc.
  466. BIOS Version A.90
  467. BIOS Starting Address Segment f000
  468. BIOS Release Date 03/07/2019
  469. BIOS ROM Size 1000000
  470. BIOS Characteristics
  471. 07: - PCI Supported
  472. 11: - Upgradeable FLASH BIOS
  473. 12: - BIOS Shadowing Supported
  474. 15: - CD-Boot Supported
  475. 16: - Selectable Boot Supported
  476. 17: - BIOS ROM Socketed
  477. 19: - EDD Supported
  478. 23: - 1.2MB Floppy Supported
  479. 24: - 720KB Floppy Supported
  480. 25: - 2.88MB Floppy Supported
  481. 26: - Print Screen Device Supported
  482. 27: - Keyboard Services Supported
  483. 28: - Serial Services Supported
  484. 29: - Printer Services Supported
  485. 32: - BIOS Vendor Reserved
  486. BIOS Characteristic Extensions
  487. 00: - ACPI Supported
  488. 01: - USB Legacy Supported
  489. 08: - BIOS Boot Specification Supported
  490. 10: - Specification Reserved
  491. 11: - Specification Reserved
  492. BIOS Major Revision 5
  493. BIOS Minor Revision 14
  494. EC Firmware Major Revision 255
  495. EC Firmware Minor Revision 255
  496. [System Information (Type 1) - Length 27 - Handle 0001h]
  497. Manufacturer Micro-Star International Co., Ltd.
  498. Product Name MS-7B79
  499. Version 2.0
  500. UUID 00000000-0000-0000-0000-000000000000
  501. Wakeup Type Power Switch
  502. [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
  503. Manufacturer Micro-Star International Co., Ltd.
  504. Product X470 GAMING PLUS (MS-7B79)
  505. Version 2.0
  506. Feature Flags 09h
  507. 1994569440: - 1994569488: - 8½?ÿ
  508. Chassis Handle 0003h
  509. Board Type 0ah - Processor/Memory Module
  510. Number of Child Handles 0
  511. [System Enclosure (Type 3) - Length 22 - Handle 0003h]
  512. Manufacturer Micro-Star International Co., Ltd.
  513. Chassis Type Desktop
  514. Version 2.0
  515. Bootup State Safe
  516. Power Supply State Safe
  517. Thermal State Safe
  518. Security Status None
  519. OEM Defined 0
  520. Height 0U
  521. Number of Power Cords 1
  522. Number of Contained Elements 0
  523. Contained Element Size 3
  524. [OEM Strings (Type 11) - Length 5 - Handle 000bh]
  525. Number of Strings 1
  526. [System Configuration Options (Type 12) - Length 5 - Handle 000ch]
  527. [32Bit Memory Error Information (Type 18) - Length 23 - Handle 000eh]
  528. [Physical Memory Array (Type 16) - Length 23 - Handle 000fh]
  529. Location 03h - SystemBoard/Motherboard
  530. Use 03h - System Memory
  531. Memory Error Correction 03h - None
  532. Maximum Capacity 268435456KB
  533. Memory Error Inf Handle 000eh
  534. Number of Memory Devices 4
  535. [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0010h]
  536. Starting Address 00000000h
  537. Ending Address 00ffffffh
  538. Memory Array Handle 000fh
  539. Partition Width 02
  540. [Cache Information (Type 7) - Length 19 - Handle 0011h]
  541. Socket Designation L1 - Cache
  542. Cache Configuration 0180h - WB Enabled Int NonSocketed L1
  543. Maximum Cache Size 0300h - 768K
  544. Installed Size 0300h - 768K
  545. Supported SRAM Type 0010h - Pipeline-Burst
  546. Current SRAM Type 0010h - Pipeline-Burst
  547. Cache Speed 1ns
  548. Error Correction Type Specification Reserved
  549. System Cache Type Unified
  550. Associativity 8-way Set-Associative
  551. [Cache Information (Type 7) - Length 19 - Handle 0012h]
  552. Socket Designation L2 - Cache
  553. Cache Configuration 0181h - WB Enabled Int NonSocketed L2
  554. Maximum Cache Size 1000h - 4096K
  555. Installed Size 1000h - 4096K
  556. Supported SRAM Type 0010h - Pipeline-Burst
  557. Current SRAM Type 0010h - Pipeline-Burst
  558. Cache Speed 1ns
  559. Error Correction Type Specification Reserved
  560. System Cache Type Unified
  561. Associativity 8-way Set-Associative
  562. [Cache Information (Type 7) - Length 19 - Handle 0013h]
  563. Socket Designation L3 - Cache
  564. Cache Configuration 0182h - WB Enabled Int NonSocketed L3
  565. Maximum Cache Size 4000h - 16384K
  566. Installed Size 4000h - 16384K
  567. Supported SRAM Type 0010h - Pipeline-Burst
  568. Current SRAM Type 0010h - Pipeline-Burst
  569. Cache Speed 1ns
  570. Error Correction Type Specification Reserved
  571. System Cache Type Unified
  572. Associativity 16-way Set-Associative
  573. [Processor Information (Type 4) - Length 48 - Handle 0014h]
  574. Socket Designation AM4
  575. Processor Type Central Processor
  576. Processor Family 6bh - Specification Reserved
  577. Processor Manufacturer Advanced Micro Devices, Inc.
  578. Processor ID 820f8000fffb8b17
  579. Processor Version AMD Ryzen 7 2700X Eight-Core Processor
  580. Processor Voltage 8ch - 1.2V
  581. External Clock 100MHz
  582. Max Speed 4350MHz
  583. Current Speed 3700MHz
  584. Status Enabled Populated
  585. Processor Upgrade Specification Reserved
  586. L1 Cache Handle 0011h
  587. L2 Cache Handle 0012h
  588. L3 Cache Handle 0013h
  589. Part Number Unknown
  590. [32Bit Memory Error Information (Type 18) - Length 23 - Handle 0015h]
  591. [Memory Device (Type 17) - Length 40 - Handle 0016h]
  592. Physical Memory Array Handle 000fh
  593. Memory Error Info Handle 0015h
  594. Form Factor 02h - Unknown
  595. Device Locator DIMM 0
  596. Bank Locator P0 CHANNEL A
  597. Memory Type 02h - Unknown
  598. Type Detail 0004h - Unknown
  599. Speed 2400MHz
  600. Manufacturer Unknown
  601. Part Number Unknown
  602. [32Bit Memory Error Information (Type 18) - Length 23 - Handle 0017h]
  603. [Memory Device (Type 17) - Length 40 - Handle 0018h]
  604. Physical Memory Array Handle 000fh
  605. Memory Error Info Handle 0017h
  606. Total Width 64 bits
  607. Data Width 64 bits
  608. Size 8192MB
  609. Form Factor 09h - DIMM
  610. Device Locator DIMM 1
  611. Bank Locator P0 CHANNEL A
  612. Memory Type 1ah - Specification Reserved
  613. Type Detail 4080h - Synchronous
  614. Speed 2400MHz
  615. Manufacturer Unknown
  616. Part Number F4-2400C15-8GFX
  617. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0019h]
  618. Starting Address 00000000h
  619. Ending Address 00ffffffh
  620. Memory Device Handle 0018h
  621. Mem Array Mapped Adr Handle 0010h
  622. [32Bit Memory Error Information (Type 18) - Length 23 - Handle 001ah]
  623. [Memory Device (Type 17) - Length 40 - Handle 001bh]
  624. Physical Memory Array Handle 000fh
  625. Memory Error Info Handle 001ah
  626. Form Factor 02h - Unknown
  627. Device Locator DIMM 0
  628. Bank Locator P0 CHANNEL B
  629. Memory Type 02h - Unknown
  630. Type Detail 0004h - Unknown
  631. Speed 2400MHz
  632. Manufacturer Unknown
  633. Part Number Unknown
  634. [32Bit Memory Error Information (Type 18) - Length 23 - Handle 001ch]
  635. [Memory Device (Type 17) - Length 40 - Handle 001dh]
  636. Physical Memory Array Handle 000fh
  637. Memory Error Info Handle 001ch
  638. Total Width 64 bits
  639. Data Width 64 bits
  640. Size 8192MB
  641. Form Factor 09h - DIMM
  642. Device Locator DIMM 1
  643. Bank Locator P0 CHANNEL B
  644. Memory Type 1ah - Specification Reserved
  645. Type Detail 4080h - Synchronous
  646. Speed 2400MHz
  647. Manufacturer Unknown
  648. Part Number F4-2400C15-8GFX
  649. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 001eh]
  650. Starting Address 00000000h
  651. Ending Address 00ffffffh
  652. Memory Device Handle 001dh
  653. Mem Array Mapped Adr Handle 0010h
  654.  
  655. ========================================================================
  656. ============================== IMAGE SCAN ==============================
  657. ========================================================================
  658.  
  659. MZ at ffff80df`531b0000, prot 00000040, type 01000000 - size 2a8000
  660. Name: win32kbase.sys
  661. MZ at ffff80df`53460000, prot 00000040, type 01000000 - size 48000
  662. Name: cdd.dll
  663. MZ at fffff804`08ae0000, prot 00000040, type 01000000 - size c4000
  664. Name: srv2.exe
  665. MZ at fffff804`08bb0000, prot 00000040, type 01000000 - size 1d000
  666. Name: rassstp.exe
  667. MZ at fffff804`08bd0000, prot 00000040, type 01000000 - size 40000
  668. Name: ndproxy.exe
  669. MZ at fffff804`08c20000, prot 00000040, type 01000000 - size 27000
  670. Name: AgileVpn.exe
  671. MZ at fffff804`08c50000, prot 00000040, type 01000000 - size 22000
  672. Name: rasl2tp.exe
  673. MZ at fffff804`08c80000, prot 00000040, type 01000000 - size 20000
  674. Name: raspptp.exe
  675. MZ at fffff804`08cb0000, prot 00000040, type 01000000 - size 1c000
  676. Name: raspppoe.exe
  677. MZ at fffff804`08cd0000, prot 00000040, type 01000000 - size f000
  678. Name: NDISTAPI.SYS
  679. MZ at fffff804`08ce0000, prot 00000040, type 01000000 - size 3a000
  680. Name: ndiswan.exe
  681. MZ at fffff804`08d50000, prot 00000040, type 01000000 - size 13000
  682. Name: condrv.exe
  683. MZ at fffff804`09190000, prot 00000040, type 01000000 - size 144000
  684. Name: http.exe
  685. MZ at fffff804`092e0000, prot 00000040, type 01000000 - size 1a000
  686. Name: mpsdrv.exe
  687. MZ at fffff804`09300000, prot 00000040, type 01000000 - size 52000
  688. Name: srvnet.sys
  689. MZ at fffff804`09360000, prot 00000040, type 01000000 - size 27000
  690. Name: ndu.exe
  691. MZ at fffff804`09390000, prot 00000040, type 01000000 - size 14000
  692. Name: mmcss.exe
  693. MZ at fffff804`093b0000, prot 00000040, type 01000000 - size 14000
  694. Name: tcpipreg.exe
  695. MZ at fffff804`0ccb2000, prot 00000040, type 01000000 - size a3000
  696. Name: HAL.dll
  697. MZ at fffff804`0ec00000, prot 00000040, type 01000000 - size b000
  698. Name: KD.dll
  699. MZ at fffff804`0ec40000, prot 00000040, type 01000000 - size 11000
  700. Name: WerLiveKernelApi.dll
  701. MZ at fffff804`0ec60000, prot 00000040, type 01000000 - size 2a000
  702. Name: ksecdd.sys
  703. MZ at fffff804`0ec90000, prot 00000040, type 01000000 - size 60000
  704. Name: msrpc.sys
  705. MZ at fffff804`0ed00000, prot 00000040, type 01000000 - size 27000
  706. Name: ntostmhost.dll
  707. MZ at fffff804`0ed30000, prot 00000040, type 01000000 - size 68000
  708. Name: CLFS.SYS
  709. MZ at fffff804`0eda0000, prot 00000040, type 01000000 - size 1a000
  710. Name: PSHED.dll
  711. MZ at fffff804`0edc0000, prot 00000040, type 01000000 - size b000
  712. Name: BOOTVID.dll
  713. MZ at fffff804`0edd0000, prot 00000040, type 01000000 - size 105000
  714. Name: clipsp.sys
  715. MZ at fffff804`0eee0000, prot 00000040, type 01000000 - size 71000
  716. Name: FLTMGR.SYS
  717. MZ at fffff804`0ef60000, prot 00000040, type 01000000 - size e000
  718. Name: cmimcext.dll
  719. MZ at fffff804`0ef70000, prot 00000040, type 01000000 - size c000
  720. Name: ntosext.dll
  721. MZ at fffff804`0ef80000, prot 00000040, type 01000000 - size dc000
  722. Name: CI.dll
  723. MZ at fffff804`0f060000, prot 00000040, type 01000000 - size bc000
  724. Name: cng.sys
  725. MZ at fffff804`0f120000, prot 00000040, type 01000000 - size d5000
  726. Name: Wdf01000.exe
  727. MZ at fffff804`0f200000, prot 00000040, type 01000000 - size 13000
  728. Name: WDFLDR.SYS
  729. MZ at fffff804`0f220000, prot 00000040, type 01000000 - size f000
  730. Name: SleepStudyHelper.sys
  731. MZ at fffff804`0f230000, prot 00000040, type 01000000 - size 10000
  732. Name: WppRecorder.sys
  733. MZ at fffff804`0f250000, prot 00000040, type 01000000 - size 25000
  734. Name: acpiex.exe
  735. MZ at fffff804`0f280000, prot 00000040, type 01000000 - size 49000
  736. Name: mssecflt.exe
  737. MZ at fffff804`0f2d0000, prot 00000040, type 01000000 - size 1a000
  738. Name: SgrmAgent.exe
  739. MZ at fffff804`0f2f0000, prot 00000040, type 01000000 - size cc000
  740. Name: ACPI.SYS
  741. MZ at fffff804`0f3c0000, prot 00000040, type 01000000 - size c000
  742. Name: WMILIB.SYS
  743. MZ at fffff804`0f400000, prot 00000040, type 01000000 - size 49000
  744. Name: intelpep.exe
  745. MZ at fffff804`0f450000, prot 00000040, type 01000000 - size 17000
  746. Name: WindowsTrustedRT.exe
  747. MZ at fffff804`0f470000, prot 00000040, type 01000000 - size b000
  748. Name: WindowsTrustedRTProxy.exe
  749. MZ at fffff804`0f480000, prot 00000040, type 01000000 - size 15000
  750. Name: pcw.exe
  751. MZ at fffff804`0f4a0000, prot 00000040, type 01000000 - size b000
  752. Name: msisadrv.exe
  753. MZ at fffff804`0f4b0000, prot 00000040, type 01000000 - size 6f000
  754. Name: pci.exe
  755. MZ at fffff804`0f520000, prot 00000040, type 01000000 - size 13000
  756. Name: vdrvroot.exe
  757. MZ at fffff804`0f540000, prot 00000040, type 01000000 - size 33000
  758. Name: PDC.exe
  759. MZ at fffff804`0f580000, prot 00000040, type 01000000 - size 19000
  760. Name: CEA.sys
  761. MZ at fffff804`0f5a0000, prot 00000040, type 01000000 - size 30000
  762. Name: partmgr.exe
  763. MZ at fffff804`0f5e0000, prot 00000040, type 01000000 - size a5000
  764. Name: spaceport.exe
  765. MZ at fffff804`0f690000, prot 00000040, type 01000000 - size 1a000
  766. Name: volmgr.exe
  767. MZ at fffff804`0f6b0000, prot 00000040, type 01000000 - size 63000
  768. Name: volmgrx.exe
  769. MZ at fffff804`0f720000, prot 00000040, type 01000000 - size 1f000
  770. Name: mountmgr.exe
  771. MZ at fffff804`0f740000, prot 00000040, type 01000000 - size 2e000
  772. Name: storahci.exe
  773. MZ at fffff804`0f7c0000, prot 00000040, type 01000000 - size 1a000
  774. Name: fileinfo.exe
  775. MZ at fffff804`0f7e0000, prot 00000040, type 01000000 - size d000
  776. Name: fs_rec.exe
  777. MZ at fffff804`0f7f0000, prot 00000040, type 01000000 - size b000
  778. Name: volume.exe
  779. MZ at fffff804`0f800000, prot 00000040, type 01000000 - size a2000
  780. Name: storport.sys
  781. MZ at fffff804`0f8b0000, prot 00000040, type 01000000 - size 3d000
  782. Name: wof.exe
  783. MZ at fffff804`0f950000, prot 00000040, type 01000000 - size 29e000
  784. Name: ntfs.exe
  785. MZ at fffff804`0fbf0000, prot 00000040, type 01000000 - size 172000
  786. Name: NDIS.SYS
  787. MZ at fffff804`0fd70000, prot 00000040, type 01000000 - size 94000
  788. Name: NETIO.SYS
  789. MZ at fffff804`0fe10000, prot 00000040, type 01000000 - size 32000
  790. Name: ksecpkg.exe
  791. MZ at fffff804`0fe80000, prot 00000040, type 01000000 - size 2ea000
  792. Name: TCPIP.SYS
  793. MZ at fffff804`10170000, prot 00000040, type 01000000 - size 7a000
  794. Name: fwpkclnt.sys
  795. MZ at fffff804`101f0000, prot 00000040, type 01000000 - size 30000
  796. Name: wfplwfs.exe
  797. MZ at fffff804`10230000, prot 00000040, type 01000000 - size c9000
  798. Name: fvevol.exe
  799. MZ at fffff804`10300000, prot 00000040, type 01000000 - size 6d000
  800. Name: volsnap.exe
  801. MZ at fffff804`10370000, prot 00000040, type 01000000 - size 4e000
  802. Name: rdyboost.exe
  803. MZ at fffff804`103c0000, prot 00000040, type 01000000 - size 25000
  804. Name: MUP.SYS
  805. MZ at fffff804`103f0000, prot 00000040, type 01000000 - size 12000
  806. Name: iorate.exe
  807. MZ at fffff804`10420000, prot 00000040, type 01000000 - size 1c000
  808. Name: disk.exe
  809. MZ at fffff804`10440000, prot 00000040, type 01000000 - size 6b000
  810. Name: CLASSPNP.SYS
  811. MZ at fffff804`18c70000, prot 00000040, type 01000000 - size 30000
  812. Name: cdrom.exe
  813. MZ at fffff804`18cb0000, prot 00000040, type 01000000 - size 15000
  814. Name: filecrypt.exe
  815. MZ at fffff804`18cd0000, prot 00000040, type 01000000 - size e000
  816. Name: tbs.sys
  817. MZ at fffff804`18ce0000, prot 00000040, type 01000000 - size a000
  818. Name: null.exe
  819. MZ at fffff804`18cf0000, prot 00000040, type 01000000 - size a000
  820. Name: beep.exe
  821. MZ at fffff804`18d00000, prot 00000040, type 01000000 - size 9c000
  822. Name: usbhub3.sys
  823. MZ at fffff804`18da0000, prot 00000040, type 01000000 - size 8f000
  824. Name: mrxsmb.sys
  825. MZ at fffff804`18e30000, prot 00000040, type 01000000 - size 45000
  826. Name: mrxsmb20.exe
  827. MZ at fffff804`18e80000, prot 00000040, type 01000000 - size 27000
  828. Name: TsUsbHub.exe
  829. MZ at fffff804`18f90000, prot 00000040, type 01000000 - size 1d000
  830. Name: CRASHDMP.SYS
  831. MZ at fffff804`19400000, prot 00000040, type 01000000 - size 11000
  832. Name: BasicRender.exe
  833. MZ at fffff804`19420000, prot 00000040, type 01000000 - size 1c000
  834. Name: npfs.exe
  835. MZ at fffff804`19440000, prot 00000040, type 01000000 - size 11000
  836. Name: msfs.exe
  837. MZ at fffff804`19460000, prot 00000040, type 01000000 - size 26000
  838. Name: tdx.exe
  839. MZ at fffff804`19490000, prot 00000040, type 01000000 - size 10000
  840. Name: TDI.SYS
  841. MZ at fffff804`194b0000, prot 00000040, type 01000000 - size 59000
  842. Name: netbt.exe
  843. MZ at fffff804`19510000, prot 00000040, type 01000000 - size 13000
  844. Name: afunix.dll
  845. MZ at fffff804`19530000, prot 00000040, type 01000000 - size a7000
  846. Name: afd.exe
  847. MZ at fffff804`195e0000, prot 00000040, type 01000000 - size 1a000
  848. Name: vwififlt.SYS
  849. MZ at fffff804`19600000, prot 00000040, type 01000000 - size 2b000
  850. Name: pacer.exe
  851. MZ at fffff804`19630000, prot 00000040, type 01000000 - size 14000
  852. Name: netbios.exe
  853. MZ at fffff804`19650000, prot 00000040, type 01000000 - size 7b000
  854. Name: rdbss.sys
  855. MZ at fffff804`196d0000, prot 00000040, type 01000000 - size 94000
  856. Name: csc.exe
  857. MZ at fffff804`19770000, prot 00000040, type 01000000 - size 12000
  858. Name: nsiproxy.exe
  859. MZ at fffff804`19790000, prot 00000040, type 01000000 - size d000
  860. Name: NpSvcTrig.exe
  861. MZ at fffff804`197a0000, prot 00000040, type 01000000 - size 10000
  862. Name: mssmbios.exe
  863. MZ at fffff804`197c0000, prot 00000040, type 01000000 - size a000
  864. Name: gpuenergydrv.exe
  865. MZ at fffff804`197d0000, prot 00000040, type 01000000 - size 2c000
  866. Name: dfsc.exe
  867. MZ at fffff804`19800000, prot 00000040, type 01000000 - size 1d000
  868. Name: wanarp.exe
  869. MZ at fffff804`19820000, prot 00000040, type 01000000 - size 6b000
  870. Name: fastfat.exe
  871. MZ at fffff804`19890000, prot 00000040, type 01000000 - size 16000
  872. Name: bam.exe
  873. MZ at fffff804`198b0000, prot 00000040, type 01000000 - size 4f000
  874. Name: ahcache.exe
  875. MZ at fffff804`19900000, prot 00000040, type 01000000 - size 8c000
  876. Name: Vid.exe
  877. MZ at fffff804`19990000, prot 00000040, type 01000000 - size 1f000
  878. Name: winhvr.sys
  879. MZ at fffff804`199b0000, prot 00000040, type 01000000 - size 11000
  880. Name: CompositeBus.exe
  881. MZ at fffff804`199d0000, prot 00000040, type 01000000 - size d000
  882. Name: kdnic.sys
  883. MZ at fffff804`199e0000, prot 00000040, type 01000000 - size 38000
  884. Name: winquic.sys
  885. MZ at fffff804`19a20000, prot 00000040, type 01000000 - size 18000
  886. Name: lltdio.exe
  887. MZ at fffff804`19a40000, prot 00000040, type 01000000 - size 15000
  888. Name: UmBus.exe
  889. MZ at fffff804`19a60000, prot 00000040, type 01000000 - size 88000
  890. Name: usbxhci.exe
  891. MZ at fffff804`19af0000, prot 00000040, type 01000000 - size 41000
  892. Name: ucx01000.exe
  893. MZ at fffff804`19ce0000, prot 00000040, type 01000000 - size 22000
  894. Name: hdaudbus.exe
  895. MZ at fffff804`19d10000, prot 00000040, type 01000000 - size 67000
  896. Name: portcls.sys
  897. MZ at fffff804`19db0000, prot 00000040, type 01000000 - size 78000
  898. Name: ks.sys
  899. MZ at fffff804`19e40000, prot 00000040, type 01000000 - size 1f000
  900. Name: parport.exe
  901. MZ at fffff804`19e60000, prot 00000040, type 01000000 - size 1c000
  902. Name: serial.exe
  903. MZ at fffff804`19e80000, prot 00000040, type 01000000 - size f000
  904. Name: SerEnum.exe
  905. MZ at fffff804`19ea0000, prot 00000040, type 01000000 - size 30000
  906. Name: msgpioclx.exe
  907. MZ at fffff804`19ee0000, prot 00000040, type 01000000 - size c000
  908. Name: wmiacpi.exe
  909. MZ at fffff804`19ef0000, prot 00000040, type 01000000 - size 3a000
  910. Name: amdppm.exe
  911. MZ at fffff804`19f40000, prot 00000040, type 01000000 - size e000
  912. Name: UEFI.SYS
  913. MZ at fffff804`19f70000, prot 00000040, type 01000000 - size f000
  914. Name: ksthunk.exe
  915. MZ at fffff804`19fa0000, prot 00000040, type 01000000 - size d000
  916. Name: NdisVirtualBus.exe
  917. MZ at fffff804`19fb0000, prot 00000040, type 01000000 - size c000
  918. Name: swenum.exe
  919. MZ at fffff804`19fc0000, prot 00000040, type 01000000 - size e000
  920. Name: rdpbus.exe
  921. MZ at fffff804`19fd0000, prot 00000040, type 01000000 - size e000
  922. Name: USBD.SYS
  923. MZ at fffff804`1a020000, prot 00000040, type 01000000 - size 1b000
  924. Name: rspndr.exe
  925. MZ at fffff804`1a040000, prot 00000040, type 01000000 - size 373000
  926. Name: dxgkrnl.sys
  927. MZ at fffff804`1a3c0000, prot 00000040, type 01000000 - size 16000
  928. Name: watchdog.sys
  929. MZ at fffff804`1a3e0000, prot 00000040, type 01000000 - size 16000
  930. Name: BasicDisplay.exe
  931. MZ at fffff804`1ac00000, prot 00000040, type 01000000 - size 33000
  932. Name: usbccgp.exe
  933. MZ at fffff804`1ac40000, prot 00000040, type 01000000 - size 12000
  934. Name: hidusb.exe
  935. MZ at fffff804`1ac60000, prot 00000040, type 01000000 - size 3b000
  936. Name: HIDCLASS.SYS
  937. MZ at fffff804`1aca0000, prot 00000040, type 01000000 - size 13000
  938. Name: HIDPARSE.SYS
  939. MZ at fffff804`1acc0000, prot 00000040, type 01000000 - size 10000
  940. Name: mouhid.exe
  941. MZ at fffff804`1ace0000, prot 00000040, type 01000000 - size 13000
  942. Name: mouclass.exe
  943. MZ at fffff804`1ad00000, prot 00000040, type 01000000 - size 11000
  944. Name: kbdhid.exe
  945. MZ at fffff804`1ad20000, prot 00000040, type 01000000 - size 14000
  946. Name: kbdclass.exe
  947. MZ at fffff804`1ad40000, prot 00000040, type 01000000 - size 16000
  948. Name: dc1-controller.exe
  949. MZ at fffff804`1ad60000, prot 00000040, type 01000000 - size 12e000
  950. Name: XBOXGIP.exe
  951. MZ at fffff804`1ae90000, prot 00000040, type 01000000 - size 14000
  952. Name: DevAuthE.sys
  953. MZ at fffff804`1aeb0000, prot 00000040, type 01000000 - size 37000
  954. Name: USBAudio.exe
  955. MZ at fffff804`1af20000, prot 00000040, type 01000000 - size 2e000
  956. Name: storahci.exe
  957. MZ at fffff804`1af70000, prot 00000040, type 01000000 - size 1d000
  958. Name: DUMPFVE.SYS
  959. MZ at fffff804`1af90000, prot 00000040, type 01000000 - size 50000
  960. Name: WUDFRd.exe
  961. MZ at fffff804`1aff0000, prot 00000040, type 01000000 - size 13000
  962. Name: XINPUTHID.exe
  963. MZ at fffff804`1b010000, prot 00000040, type 01000000 - size d000
  964. Name: rdpvideominiport.exe
  965. MZ at fffff804`1b020000, prot 00000040, type 01000000 - size 2a000
  966. Name: luafv.exe
  967. MZ at fffff804`1b050000, prot 00000040, type 01000000 - size 36000
  968. Name: wcifs.exe
  969. MZ at fffff804`1b090000, prot 00000040, type 01000000 - size 2f000
  970. Name: rdpdr.exe
  971. MZ at fffff804`1b0c0000, prot 00000040, type 01000000 - size e000
  972. Name: WpdUpFltr.exe
  973. MZ at fffff804`1b0d0000, prot 00000040, type 01000000 - size 77000
  974. Name: cldflt.exe
  975. MZ at fffff804`1b150000, prot 00000040, type 01000000 - size 1a000
  976. Name: storqosflt.exe
  977. MZ at fffff804`1b170000, prot 00000040, type 01000000 - size 25000
  978. Name: bowser.exe
  979. MZ at fffff804`1b1a0000, prot 00000040, type 01000000 - size db000
  980. Name: dxgmms2.sys
  981. MZ at fffff804`1b280000, prot 00000040, type 01000000 - size 16000
  982. Name: monitor.exe
  983. MZ at fffff804`1b2b0000, prot 00000040, type 01000000 - size e000
  984. Name: SYS.exe
  985. MZ at fffff804`1b980000, prot 00000040, type 01000000 - size 25000
  986. Name: usbstor.exe
  987. MZ at fffff804`1b9e0000, prot 00000040, type 01000000 - size 19000
  988. Name: mslldp.exe
  989.  
  990. ========================================================================
  991. ==================== Dump File: 070119-9812-01.dmp =====================
  992. ========================================================================
  993. Mini Kernel Dump File: Only registers and stack trace are available
  994. Mini Kernel Dump does not have process information
  995. Unable to load image Unknown_Module_00000000`00000000, Win32 error 0n2
  996. *** WARNING: Unable to verify timestamp for Unknown_Module_00000000`00000000
  997. Unable to add module at 00000000`00000000
  998. WARNING: .reload failed, module list may be incomplete
  999. Debugger can not determine kernel base address
  1000. Windows 10 Kernel Version 18362 MP (16 procs) Free x64
  1001. Kernel base = 0xfffff803`3dc00000 PsLoadedModuleList = 0xfffff803`3e043370
  1002. Debug session time: Mon Jul 1 19:04:17.877 2019 (UTC - 4:00)
  1003. System Uptime: 0 days 0:01:20.572
  1004. Unable to load image Unknown_Module_00000000`00000000, Win32 error 0n2
  1005. *** WARNING: Unable to verify timestamp for Unknown_Module_00000000`00000000
  1006. Unable to add module at 00000000`00000000
  1007. WARNING: .reload failed, module list may be incomplete
  1008. Debugger can not determine kernel base address
  1009. .Unable to load image Unknown_Module_00000000`00000000, Win32 error 0n2
  1010. *** WARNING: Unable to verify timestamp for Unknown_Module_00000000`00000000
  1011. Unable to add module at 00000000`00000000
  1012.  
  1013. BugCheck 19, {22, ffff9d8271c70000, 1, 0}
  1014. ***** Debugger could not find nt in module list, module list might be corrupt, error 0x80070057.
  1015. Unable to get size of nt!_MMPTE - probably bad symbols
  1016. Probably caused by : Unknown_Image ( ANALYSIS_INCONCLUSIVE )
  1017. Followup: MachineOwner
  1018.  
  1019. BAD_POOL_HEADER (19)
  1020. The pool is already corrupt at the time of the current request.
  1021. This may or may not be due to the caller.
  1022. The internal pool links must be walked to figure out a possible cause of
  1023. the problem, and then special pool applied to the suspect tags or the driver
  1024. verifier to a suspect driver.
  1025.  
  1026. Arguments:
  1027. Arg1: 0000000000000022,
  1028. Arg2: ffff9d8271c70000
  1029. Arg3: 0000000000000001
  1030. Arg4: 0000000000000000
  1031.  
  1032. Debugging Details:
  1033. ***** Debugger could not find nt in module list, module list might be corrupt, error 0x80070057.
  1034. Unable to get size of nt!_MMPTE - probably bad symbols
  1035. DUMP_CLASS: 1
  1036. DUMP_QUALIFIER: 400
  1037. DUMP_TYPE: 2
  1038. BUGCHECK_STR: 0x19_22
  1039. POOL_ADDRESS: Unable to get size of nt!_MMPTE - probably bad symbols
  1040. ffff9d8271c70000
  1041. CUSTOMER_CRASH_COUNT: 1
  1042. CURRENT_IRQL: 0
  1043. LAST_CONTROL_TRANSFER: from fffff8033ddf8a6a to fffff8033ddbc8a0
  1044. STACK_TEXT:
  1045. ffff8708`2b524bc8 fffff803`3ddf8a6a : 00000000`00000019 00000000`00000022 ffff9d82`71c70000 00000000`00000001 : 0xfffff803`3ddbc8a0
  1046. ffff8708`2b524bd0 00000000`00000019 : 00000000`00000022 ffff9d82`71c70000 00000000`00000001 00000000`00000000 : 0xfffff803`3ddf8a6a
  1047. ffff8708`2b524bd8 00000000`00000022 : ffff9d82`71c70000 00000000`00000001 00000000`00000000 00000000`00001001 : 0x19
  1048. ffff8708`2b524be0 ffff9d82`71c70000 : 00000000`00000001 00000000`00000000 00000000`00001001 00000000`00000000 : 0x22
  1049. ffff8708`2b524be8 00000000`00000001 : 00000000`00000000 00000000`00001001 00000000`00000000 00000000`00000000 : 0xffff9d82`71c70000
  1050. ffff8708`2b524bf0 00000000`00000000 : 00000000`00001001 00000000`00000000 00000000`00000000 00000000`00000103 : 0x1
  1051. STACK_COMMAND: kb
  1052. SYMBOL_NAME: ANALYSIS_INCONCLUSIVE
  1053. FOLLOWUP_NAME: MachineOwner
  1054. MODULE_NAME: Unknown_Module
  1055.  
  1056. IMAGE_NAME: Unknown_Image
  1057.  
  1058. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  1059. BUCKET_ID: CORRUPT_MODULELIST_0x19_22
  1060. DEFAULT_BUCKET_ID: CORRUPT_MODULELIST_0x19_22
  1061. PRIMARY_PROBLEM_CLASS: CORRUPT_MODULELIST
  1062. FAILURE_BUCKET_ID: CORRUPT_MODULELIST_0x19_22
  1063. TARGET_TIME: 2019-07-01T23:04:17.000Z
  1064. SUITE_MASK: 272
  1065. PRODUCT_TYPE: 1
  1066. USER_LCID: 0
  1067. FAILURE_ID_HASH_STRING: km:corrupt_modulelist_0x19_22
  1068. FAILURE_ID_HASH: {1ea13dde-9f77-c377-4e27-a6958973d90b}
  1069. Followup: MachineOwner
  1070.  
  1071. ========================================================================
  1072. ==================== Dump File: 062919-9593-01.dmp =====================
  1073. ========================================================================
  1074. Mini Kernel Dump File: Only registers and stack trace are available
  1075. Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
  1076. *** WARNING: Unable to verify timestamp for ntoskrnl.exe
  1077. *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
  1078. Windows 10 Kernel Version 18362 MP (16 procs) Free x64
  1079. Kernel base = 0xfffff801`77800000 PsLoadedModuleList = 0xfffff801`77c43370
  1080. Debug session time: Sat Jun 29 19:25:23.116 2019 (UTC - 4:00)
  1081. System Uptime: 0 days 0:05:44.812
  1082. Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
  1083. *** WARNING: Unable to verify timestamp for ntoskrnl.exe
  1084. *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
  1085.  
  1086. ************* Symbol Loading Error Summary **************
  1087. Module name Error
  1088. ntoskrnl The system cannot find the file specified
  1089. You can troubleshoot most symbol related issues by turning on symbol loading diagnostics (!sym noisy) and repeating the command that caused symbols to be loaded.
  1090. You should also verify that your symbol search path (.sympath) is correct.
  1091.  
  1092. BugCheck A, {fffff8017234da90, 2, 1, fffff80177849c23}
  1093. ***** Kernel symbols are WRONG. Please fix symbols to do analysis.
  1094. *** WARNING: Unable to verify timestamp for win32k.sys
  1095. *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
  1096. Probably caused by : memory_corruption
  1097. Followup: memory_corruption
  1098.  
  1099. IRQL_NOT_LESS_OR_EQUAL (a)
  1100. An attempt was made to access a pageable (or completely invalid) address at an
  1101. interrupt request level (IRQL) that is too high. This is usually
  1102. caused by drivers using improper addresses.
  1103. If a kernel debugger is available get the stack backtrace.
  1104.  
  1105. Arguments:
  1106. Arg1: fffff8017234da90, memory referenced
  1107. Arg2: 0000000000000002, IRQL
  1108. Arg3: 0000000000000001, bitfield :
  1109. bit 0 : value 0 = read operation, 1 = write operation
  1110. bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
  1111. Arg4: fffff80177849c23, address which referenced memory
  1112.  
  1113. Debugging Details:
  1114. ***** Kernel symbols are WRONG. Please fix symbols to do analysis.
  1115. DUMP_CLASS: 1
  1116. DUMP_QUALIFIER: 400
  1117. ADDITIONAL_DEBUG_TEXT:
  1118. You can run '.symfix; .reload' to try to fix the symbol path and load symbols.
  1119. WRONG_SYMBOLS_TIMESTAMP: eadcd02b
  1120. WRONG_SYMBOLS_SIZE: ab2000
  1121. FAULTING_MODULE: fffff80177800000 nt
  1122. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  1123. DUMP_TYPE: 2
  1124. WRITE_ADDRESS: *************************************************************************
  1125. Unable to get size of nt!_MMPTE - probably bad symbols
  1126. fffff8017234da90
  1127. CURRENT_IRQL: 0
  1128. FAULTING_IP:
  1129. nt+49c23
  1130. fffff801`77849c23 f0480fbaaf1059000000 lock bts qword ptr [rdi+5910h],0
  1131. CUSTOMER_CRASH_COUNT: 1
  1132. DEFAULT_BUCKET_ID: CODE_CORRUPTION
  1133. BUGCHECK_STR: AV
  1134. LAST_CONTROL_TRANSFER: from fffff801779ce569 to fffff801779bc8a0
  1135. STACK_TEXT:
  1136. fffff801`7aa67558 fffff801`779ce569 : 00000000`0000000a fffff801`7234da90 00000000`00000002 00000000`00000001 : nt+0x1bc8a0
  1137. fffff801`7aa67560 00000000`0000000a : fffff801`7234da90 00000000`00000002 00000000`00000001 fffff801`77849c23 : nt+0x1ce569
  1138. fffff801`7aa67568 fffff801`7234da90 : 00000000`00000002 00000000`00000001 fffff801`77849c23 ffff8006`ca0a9678 : 0xa
  1139. fffff801`7aa67570 00000000`00000002 : 00000000`00000001 fffff801`77849c23 ffff8006`ca0a9678 00000000`00000000 : 0xfffff801`7234da90
  1140. fffff801`7aa67578 00000000`00000001 : fffff801`77849c23 ffff8006`ca0a9678 00000000`00000000 00000000`00000000 : 0x2
  1141. fffff801`7aa67580 fffff801`77849c23 : ffff8006`ca0a9678 00000000`00000000 00000000`00000000 00000000`00000000 : 0x1
  1142. fffff801`7aa67588 ffff8006`ca0a9678 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt+0x49c23
  1143. fffff801`7aa67590 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0xffff8006`ca0a9678
  1144. STACK_COMMAND: kb
  1145. CHKIMG_EXTENSION: !chkimg -lo 50 -d !hal
  1146. fffff801782b38a6-fffff801782b38ab 6 bytes - hal!KeQueryPerformanceCounter+e6
  1147. [ ff 15 5c 70 07 00:e8 f5 c9 89 ff 90 ]
  1148. fffff801782b3c53 - hal!HalpApicRequestInterrupt+a3 (+0x3ad)
  1149. [ 00:90 ]
  1150. fffff801782b3cc1-fffff801782b3cc6 6 bytes - hal!HalpApicRequestInterrupt+111 (+0x6e)
  1151. [ ff 15 41 6c 07 00:e8 da c5 89 ff 90 ]
  1152. fffff801782b51d5-fffff801782b51d6 2 bytes - hal!HalpTimerClockIpiRoutine+15 (+0x1514)
  1153. [ 48 ff:4c 8b ]
  1154. fffff801782b51dc-fffff801782b51e0 5 bytes - hal!HalpTimerClockIpiRoutine+1c (+0x07)
  1155. [ 0f 1f 44 00 00:e8 bf 9e 56 ff ]
  1156. fffff801782b5237-fffff801782b523c 6 bytes - hal!HalpTimerClockIpiRoutine+77 (+0x5b)
  1157. [ ff 15 cb 56 07 00:e8 64 b0 89 ff 90 ]
  1158. 26 errors : !hal (fffff801782b38a6-fffff801782b523c)
  1159. MODULE_NAME: memory_corruption
  1160.  
  1161. IMAGE_NAME: memory_corruption
  1162.  
  1163. FOLLOWUP_NAME: memory_corruption
  1164. MEMORY_CORRUPTOR: LARGE
  1165. FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
  1166. BUCKET_ID: MEMORY_CORRUPTION_LARGE
  1167. PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
  1168. TARGET_TIME: 2019-06-29T23:25:23.000Z
  1169. SUITE_MASK: 272
  1170. PRODUCT_TYPE: 1
  1171. USER_LCID: 0
  1172. FAILURE_ID_HASH_STRING: km:memory_corruption_large
  1173. FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
  1174. Followup: memory_corruption
  1175.  
  1176. ========================================================================
  1177. ==================== Dump File: 062919-9562-01.dmp =====================
  1178. ========================================================================
  1179. Mini Kernel Dump File: Only registers and stack trace are available
  1180. Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
  1181. *** WARNING: Unable to verify timestamp for ntoskrnl.exe
  1182. *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
  1183. Windows 10 Kernel Version 18362 MP (16 procs) Free x64
  1184. Kernel base = 0xfffff801`5e600000 PsLoadedModuleList = 0xfffff801`5ea43370
  1185. Debug session time: Sat Jun 29 19:27:45.370 2019 (UTC - 4:00)
  1186. System Uptime: 0 days 0:01:33.066
  1187. Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
  1188. *** WARNING: Unable to verify timestamp for ntoskrnl.exe
  1189. *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
  1190.  
  1191. ************* Symbol Loading Error Summary **************
  1192. Module name Error
  1193. ntoskrnl The system cannot find the file specified
  1194. You can troubleshoot most symbol related issues by turning on symbol loading diagnostics (!sym noisy) and repeating the command that caused symbols to be loaded.
  1195. You should also verify that your symbol search path (.sympath) is correct.
  1196.  
  1197. BugCheck 50, {ffffeb832920ff42, 0, fffff80162d5b7ae, 2}
  1198. ***** Kernel symbols are WRONG. Please fix symbols to do analysis.
  1199. Probably caused by : memory_corruption
  1200. Followup: memory_corruption
  1201.  
  1202. PAGE_FAULT_IN_NONPAGED_AREA (50)
  1203. Invalid system memory was referenced. This cannot be protected by try-except.
  1204. Typically the address is just plain bad or it is pointing at freed memory.
  1205.  
  1206. Arguments:
  1207. Arg1: ffffeb832920ff42, memory referenced.
  1208. Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
  1209. Arg3: fffff80162d5b7ae, If non-zero, the instruction address which referenced the bad memory
  1210. address.
  1211. Arg4: 0000000000000002, (reserved)
  1212.  
  1213. Debugging Details:
  1214. ***** Kernel symbols are WRONG. Please fix symbols to do analysis.
  1215. DUMP_CLASS: 1
  1216. DUMP_QUALIFIER: 400
  1217. ADDITIONAL_DEBUG_TEXT:
  1218. You can run '.symfix; .reload' to try to fix the symbol path and load symbols.
  1219. WRONG_SYMBOLS_TIMESTAMP: eadcd02b
  1220. WRONG_SYMBOLS_SIZE: ab2000
  1221. FAULTING_MODULE: fffff8015e600000 nt
  1222. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  1223. DUMP_TYPE: 2
  1224. READ_ADDRESS: *************************************************************************
  1225. Unable to get size of nt!_MMPTE - probably bad symbols
  1226. ffffeb832920ff42
  1227. FAULTING_IP:
  1228. Ntfs!NtfsCommonWrite+12be
  1229. fffff801`62d5b7ae 498d5218 lea rdx,[r10+18h]
  1230. MM_INTERNAL_CODE: 2
  1231. CUSTOMER_CRASH_COUNT: 1
  1232. DEFAULT_BUCKET_ID: CODE_CORRUPTION
  1233. BUGCHECK_STR: AV
  1234. CURRENT_IRQL: 0
  1235. LAST_CONTROL_TRANSFER: from fffff8015e7dfd54 to fffff8015e7bc8a0
  1236. STACK_TEXT:
  1237. ffffeb83`9dd8e058 fffff801`5e7dfd54 : 00000000`00000050 ffffeb83`2920ff42 00000000`00000000 ffffeb83`9dd8e300 : nt+0x1bc8a0
  1238. ffffeb83`9dd8e060 00000000`00000050 : ffffeb83`2920ff42 00000000`00000000 ffffeb83`9dd8e300 00000000`00000002 : nt+0x1dfd54
  1239. ffffeb83`9dd8e068 ffffeb83`2920ff42 : 00000000`00000000 ffffeb83`9dd8e300 00000000`00000002 ffffca88`86949d1c : 0x50
  1240. ffffeb83`9dd8e070 00000000`00000000 : ffffeb83`9dd8e300 00000000`00000002 ffffca88`86949d1c 00000000`00000000 : 0xffffeb83`2920ff42
  1241. STACK_COMMAND: kb
  1242. CHKIMG_EXTENSION: !chkimg -lo 50 -d !win32kbase
  1243. ffff83a09ae9613b-ffff83a09ae9613c 2 bytes - win32kbase!EngFreeUserMem+1b
  1244. [ 48 ff:4c 8b ]
  1245. ffff83a09ae96142-ffff83a09ae96145 4 bytes - win32kbase!EngFreeUserMem+22 (+0x07)
  1246. [ 0f 1f 44 00:e8 d9 22 21 ]
  1247. ffff83a09ae96178-ffff83a09ae96179 2 bytes - win32kbase!EngFreeUserMem+58 (+0x36)
  1248. [ 48 ff:4c 8b ]
  1249. ffff83a09ae9617f-ffff83a09ae96182 4 bytes - win32kbase!EngFreeUserMem+5f (+0x07)
  1250. [ 0f 1f 44 00:e8 9c 22 21 ]
  1251. ffff83a09ae96195-ffff83a09ae96196 2 bytes - win32kbase!EngFreeUserMem+75 (+0x16)
  1252. [ 48 ff:4c 8b ]
  1253. ffff83a09ae9619c-ffff83a09ae9619f 4 bytes - win32kbase!EngFreeUserMem+7c (+0x07)
  1254. [ 0f 1f 44 00:e8 7f 22 21 ]
  1255. ffff83a09ae961b3-ffff83a09ae961b4 2 bytes - win32kbase!EngFreeUserMem+93 (+0x17)
  1256. [ 48 ff:4c 8b ]
  1257. ffff83a09ae961ba-ffff83a09ae961bd 4 bytes - win32kbase!EngFreeUserMem+9a (+0x07)
  1258. [ 0f 1f 44 00:e8 61 22 21 ]
  1259. ffff83a09ae961cf - win32kbase!EngFreeUserMem+af (+0x15)
  1260. [ 48:4c ]
  1261. ffff83a09ae9cfb9-ffff83a09ae9cfbe 6 bytes - win32kbase!DirectComposition::CAnimationMarshaler::SetReferenceProperty+49 (+0x6dea)
  1262. [ ff 15 e9 b7 19 00:e8 e2 b2 20 00 90 ]
  1263. ffff83a09ae9d029-ffff83a09ae9d02a 2 bytes - win32kbase!SfmSignalTokenEvent+19 (+0x70)
  1264. [ 48 ff:4c 8b ]
  1265. ffff83a09ae9d030-ffff83a09ae9d033 4 bytes - win32kbase!SfmSignalTokenEvent+20 (+0x07)
  1266. [ 0f 1f 44 00:e8 eb b3 20 ]
  1267. ffff83a09ae9de15-ffff83a09ae9de16 2 bytes - win32kbase!GreSfmDwmShutdown+35 (+0xde5)
  1268. [ 48 ff:4c 8b ]
  1269. ffff83a09ae9de1c-ffff83a09ae9de1f 4 bytes - win32kbase!GreSfmDwmShutdown+3c (+0x07)
  1270. [ 0f 1f 44 00:e8 ff a5 20 ]
  1271. ffff83a09ae9de25-ffff83a09ae9de26 2 bytes - win32kbase!GreSfmDwmShutdown+45 (+0x09)
  1272. [ 48 ff:4c 8b ]
  1273. ffff83a09ae9de2c-ffff83a09ae9de2f 4 bytes - win32kbase!GreSfmDwmShutdown+4c (+0x07)
  1274. [ 0f 1f 44 00:e8 ef a5 20 ]
  1275. ffff83a09ae9de50-ffff83a09ae9de51 2 bytes - win32kbase!GreSfmDwmShutdown+70 (+0x24)
  1276. [ 48 ff:4c 8b ]
  1277. ffff83a09ae9de57-ffff83a09ae9de5a 4 bytes - win32kbase!GreSfmDwmShutdown+77 (+0x07)
  1278. [ 0f 1f 44 00:e8 c4 a5 20 ]
  1279. ffff83a09ae9de5c-ffff83a09ae9de5d 2 bytes - win32kbase!GreSfmDwmShutdown+7c (+0x05)
  1280. [ 48 ff:4c 8b ]
  1281. ffff83a09ae9de63-ffff83a09ae9de66 4 bytes - win32kbase!GreSfmDwmShutdown+83 (+0x07)
  1282. [ 0f 1f 44 00:e8 b8 a5 20 ]
  1283. 61 errors : !win32kbase (ffff83a09ae9613b-ffff83a09ae9de66)
  1284. MODULE_NAME: memory_corruption
  1285.  
  1286. IMAGE_NAME: memory_corruption
  1287.  
  1288. FOLLOWUP_NAME: memory_corruption
  1289. MEMORY_CORRUPTOR: LARGE
  1290. FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
  1291. BUCKET_ID: MEMORY_CORRUPTION_LARGE
  1292. PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
  1293. TARGET_TIME: 2019-06-29T23:27:45.000Z
  1294. SUITE_MASK: 272
  1295. PRODUCT_TYPE: 1
  1296. USER_LCID: 0
  1297. FAILURE_ID_HASH_STRING: km:memory_corruption_large
  1298. FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
  1299. Followup: memory_corruption
  1300.  
  1301. ========================================================================
  1302. ==================== Dump File: 062519-9046-01.dmp =====================
  1303. ========================================================================
  1304. Mini Kernel Dump File: Only registers and stack trace are available
  1305. Invalid directory table base value 0x0
  1306. Unable to load image Unknown_Module_00000000`00000000, Win32 error 0n2
  1307. *** WARNING: Unable to verify timestamp for Unknown_Module_00000000`00000000
  1308. Unable to add module at 00000000`00000000
  1309. WARNING: .reload failed, module list may be incomplete
  1310. Debugger can not determine kernel base address
  1311. Windows 10 Kernel Version 18362 MP (16 procs) Free x64
  1312. Kernel base = 0xfffff805`72600000 PsLoadedModuleList = 0xfffff805`72a43370
  1313. Debug session time: Wed Jun 26 01:12:43.430 2019 (UTC - 4:00)
  1314. System Uptime: 0 days 0:29:42.125
  1315. Unable to load image Unknown_Module_00000000`00000000, Win32 error 0n2
  1316. *** WARNING: Unable to verify timestamp for Unknown_Module_00000000`00000000
  1317. Unable to add module at 00000000`00000000
  1318. WARNING: .reload failed, module list may be incomplete
  1319. Debugger can not determine kernel base address
  1320. .Unable to load image Unknown_Module_00000000`00000000, Win32 error 0n2
  1321. *** WARNING: Unable to verify timestamp for Unknown_Module_00000000`00000000
  1322. Unable to add module at 00000000`00000000
  1323.  
  1324. BugCheck D1, {500, e, 0, fffff80584799d70}
  1325. ***** Debugger could not find nt in module list, module list might be corrupt, error 0x80070057.
  1326. Probably caused by : Unknown_Image ( ANALYSIS_INCONCLUSIVE )
  1327. Followup: MachineOwner
  1328.  
  1329. DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
  1330. An attempt was made to access a pageable (or completely invalid) address at an
  1331. interrupt request level (IRQL) that is too high. This is usually
  1332. caused by drivers using improper addresses.
  1333. If kernel debugger is available get stack backtrace.
  1334.  
  1335. Arguments:
  1336. Arg1: 0000000000000500, memory referenced
  1337. Arg2: 000000000000000e, IRQL
  1338. Arg3: 0000000000000000, value 0 = read operation, 1 = write operation
  1339. Arg4: fffff80584799d70, address which referenced memory
  1340.  
  1341. Debugging Details:
  1342. ***** Debugger could not find nt in module list, module list might be corrupt, error 0x80070057.
  1343. DUMP_CLASS: 1
  1344. DUMP_QUALIFIER: 400
  1345. DUMP_TYPE: 2
  1346. READ_ADDRESS: Unable to get size of nt!_MMPTE - probably bad symbols
  1347. 0000000000000500
  1348. CURRENT_IRQL: 0
  1349. FAULTING_IP:
  1350. +0
  1351. fffff805`84799d70 ?? ???
  1352. CUSTOMER_CRASH_COUNT: 1
  1353. DEFAULT_BUCKET_ID: CORRUPT_MODULELIST_AV
  1354. BUGCHECK_STR: AV
  1355. LAST_CONTROL_TRANSFER: from fffff805727ce569 to fffff805727bc8a0
  1356. STACK_TEXT:
  1357. ffffd700`7a9b1348 fffff805`727ce569 : 00000000`0000000a 00000000`00000500 00000000`0000000e 00000000`00000000 : 0xfffff805`727bc8a0
  1358. ffffd700`7a9b1350 00000000`0000000a : 00000000`00000500 00000000`0000000e 00000000`00000000 fffff805`84799d70 : 0xfffff805`727ce569
  1359. ffffd700`7a9b1358 00000000`00000500 : 00000000`0000000e 00000000`00000000 fffff805`84799d70 ffffd700`7a9b1449 : 0xa
  1360. ffffd700`7a9b1360 00000000`0000000e : 00000000`00000000 fffff805`84799d70 ffffd700`7a9b1449 00000000`00000000 : 0x500
  1361. ffffd700`7a9b1368 00000000`00000000 : fffff805`84799d70 ffffd700`7a9b1449 00000000`00000000 00000000`00000000 : 0xe
  1362. STACK_COMMAND: kb
  1363. SYMBOL_NAME: ANALYSIS_INCONCLUSIVE
  1364. FOLLOWUP_NAME: MachineOwner
  1365. MODULE_NAME: Unknown_Module
  1366.  
  1367. IMAGE_NAME: Unknown_Image
  1368.  
  1369. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  1370. BUCKET_ID: CORRUPT_MODULELIST_AV
  1371. PRIMARY_PROBLEM_CLASS: CORRUPT_MODULELIST
  1372. FAILURE_BUCKET_ID: CORRUPT_MODULELIST_AV
  1373. TARGET_TIME: 2019-06-26T05:12:43.000Z
  1374. SUITE_MASK: 272
  1375. PRODUCT_TYPE: 1
  1376. USER_LCID: 0
  1377. FAILURE_ID_HASH_STRING: km:corrupt_modulelist_av
  1378. FAILURE_ID_HASH: {fc259191-ef0c-6215-476f-d32e5dcaf1b7}
  1379. Followup: MachineOwner
Advertisement
Add Comment
Please, Sign In to add comment