Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ========================== AUTO DUMP ANALYZER ==========================
- Auto Dump Analyzer
- Version: 0.9
- Time to analyze file(s): 00 hours and 03 minutes and 17 seconds
- ================================ SYSTEM ================================
- MANUFACTURER: Micro-Star International Co., Ltd.
- PRODUCT_NAME: MS-7B79
- VERSION: 2.0
- ================================= BIOS =================================
- VENDOR: American Megatrends Inc.
- VERSION: A.90
- DATE: 03/07/2019
- ============================= MOTHERBOARD ==============================
- MANUFACTURER: Micro-Star International Co., Ltd.
- PRODUCT: X470 GAMING PLUS (MS-7B79)
- VERSION: 2.0
- ================================= RAM ==================================
- Size Speed Manufacturer Part No.
- -------------- -------------- ------------------- ----------------------
- 2400MHz Unknown Unknown
- 8192MB 2400MHz Unknown F4-2400C15-8GFX
- 2400MHz Unknown Unknown
- 8192MB 2400MHz Unknown F4-2400C15-8GFX
- ================================= CPU ==================================
- Processor Version: AMD Ryzen 7 2700X Eight-Core Processor
- COUNT: 10
- MHZ: 3700
- VENDOR: AuthenticAMD
- FAMILY: 17
- MODEL: 8
- STEPPING: 2
- ================================== OS ==================================
- Product: WinNt, suite: TerminalServer SingleUserTS
- Built by: 18362.1.amd64fre.19h1_release.190318-1202
- BUILD_VERSION: 18362.1.amd64fre.19h1_release.190318-1202
- BUILD: 18362
- SERVICEPACK: 0
- PLATFORM_TYPE: x64
- NAME: Windows 10
- EDITION: Windows 10 WinNt TerminalServer SingleUserTS
- BUILD_TIMESTAMP: unknown_date
- BUILDDATESTAMP: 190318-1202
- BUILDLAB: 19h1_release
- BUILDOSVER: 10.0.18362.1.amd64fre.19h1_release.190318-1202
- =============================== DEBUGGER ===============================
- Microsoft (R) Windows Debugger Version 10.0.14321.1024 AMD64
- Copyright (c) Microsoft Corporation. All rights reserved.
- =============================== COMMENTS ===============================
- * Information gathered from different dump files may be different. If
- Windows updates between two dump files, two or more OS versions may
- be shown above.
- * If the user updates the BIOS between dump files, two or more versions
- and dates may be shown above.
- * More RAM information can be found below in the full BIOS section.
- ========================================================================
- ==================== Dump File: 063019-9468-01.dmp =====================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
- *** WARNING: Unable to verify timestamp for ntoskrnl.exe
- *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
- Windows 10 Kernel Version 18362 MP (16 procs) Free x64
- Kernel base = 0xfffff804`0c200000 PsLoadedModuleList = 0xfffff804`0c643370
- Debug session time: Mon Jul 1 00:33:56.913 2019 (UTC - 4:00)
- System Uptime: 0 days 0:13:36.608
- Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
- *** WARNING: Unable to verify timestamp for ntoskrnl.exe
- *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
- ************* Symbol Loading Error Summary **************
- Module name Error
- ntoskrnl The system cannot find the file specified
- You can troubleshoot most symbol related issues by turning on symbol loading diagnostics (!sym noisy) and repeating the command that caused symbols to be loaded.
- You should also verify that your symbol search path (.sympath) is correct.
- BugCheck A, {10, 2, 0, fffff8040c21994f}
- ***** Kernel symbols are WRONG. Please fix symbols to do analysis.
- *** WARNING: Unable to verify timestamp for win32k.sys
- *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
- Probably caused by : memory_corruption
- Followup: memory_corruption
- IRQL_NOT_LESS_OR_EQUAL (a)
- An attempt was made to access a pageable (or completely invalid) address at an
- interrupt request level (IRQL) that is too high. This is usually
- caused by drivers using improper addresses.
- If a kernel debugger is available get the stack backtrace.
- Arguments:
- Arg1: 0000000000000010, memory referenced
- Arg2: 0000000000000002, IRQL
- Arg3: 0000000000000000, bitfield :
- bit 0 : value 0 = read operation, 1 = write operation
- bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
- Arg4: fffff8040c21994f, address which referenced memory
- Debugging Details:
- ***** Kernel symbols are WRONG. Please fix symbols to do analysis.
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- ADDITIONAL_DEBUG_TEXT:
- You can run '.symfix; .reload' to try to fix the symbol path and load symbols.
- WRONG_SYMBOLS_TIMESTAMP: eadcd02b
- WRONG_SYMBOLS_SIZE: ab2000
- FAULTING_MODULE: fffff8040c200000 nt
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- DUMP_TYPE: 2
- READ_ADDRESS: *************************************************************************
- Unable to get size of nt!_MMPTE - probably bad symbols
- 0000000000000010
- CURRENT_IRQL: 0
- FAULTING_IP:
- nt+1994f
- fffff804`0c21994f 49034710 add rax,qword ptr [r15+10h]
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- BUGCHECK_STR: AV
- LAST_CONTROL_TRANSFER: from fffff8040c3ce569 to fffff8040c3bc8a0
- STACK_TEXT:
- fffffd09`9b7cc748 fffff804`0c3ce569 : 00000000`0000000a 00000000`00000010 00000000`00000002 00000000`00000000 : nt+0x1bc8a0
- fffffd09`9b7cc750 00000000`0000000a : 00000000`00000010 00000000`00000002 00000000`00000000 fffff804`0c21994f : nt+0x1ce569
- fffffd09`9b7cc758 00000000`00000010 : 00000000`00000002 00000000`00000000 fffff804`0c21994f 00000000`00000000 : 0xa
- fffffd09`9b7cc760 00000000`00000002 : 00000000`00000000 fffff804`0c21994f 00000000`00000000 00000000`00000000 : 0x10
- fffffd09`9b7cc768 00000000`00000000 : fffff804`0c21994f 00000000`00000000 00000000`00000000 00000000`00000000 : 0x2
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !hal
- fffff8040ccb3c53 - hal!HalpApicRequestInterrupt+a3
- [ 00:90 ]
- fffff8040ccb3cc1-fffff8040ccb3cc6 6 bytes - hal!HalpApicRequestInterrupt+111 (+0x6e)
- [ ff 15 41 6c 07 00:e8 da c5 89 ff 90 ]
- fffff8040ccb52ca - hal!HalPerformEndOfInterrupt+1a (+0x1609)
- [ 00:90 ]
- fffff8040ccb53a7-fffff8040ccb53a8 2 bytes - hal!HalPutScatterGatherList+67 (+0xdd)
- [ 48 ff:4c 8b ]
- fffff8040ccb53ae-fffff8040ccb53b2 5 bytes - hal!HalPutScatterGatherList+6e (+0x07)
- [ 0f 1f 44 00 00:e8 ed 4c 8b ff ]
- 15 errors : !hal (fffff8040ccb3c53-fffff8040ccb53b2)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2019-07-01T04:33:56.000Z
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ========================================================================
- ===================== 3RD PARTY DRIVER QUICK LIST ======================
- ========================================================================
- Mar 19 2015 - amd_sata.sys - AMD SATA Controller AHCI Device driver http://support.amd.com/
- Mar 19 2015 - amd_xata.sys - AMD Stor Filter driver http://support.amd.com/
- Mar 14 2016 - amdgpio3.sys - AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Aug 16 2018 - nvvhci.sys - Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Sep 10 2018 - amdpsp.sys - Advanced Micro Devices, Inc http://support.amd.com/
- Oct 11 2018 - AMDPCIDev.sys - Advanced Micro Devices PCI Device driver
- Nov 12 2018 - amdgpio2.sys - AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Mar 05 2019 - RTKVHD64.sys - Realtek Audio Driver system driver https://www.realtek.com/en/
- Mar 07 2019 - rt640x64.sys - Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Mar 14 2019 - nvvad64v.sys - Nvidia Virtual Audio Driver http://www.nvidia.com/
- Mar 19 2019 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- Mar 25 2019 - asmthub3.sys - ASMedia USB 3.0 Hub driver http://www.asmedia.com.tw/
- Mar 25 2019 - asmtxhci.sys - ASMedia USB 3.0 driver http://www.asmedia.com.tw/
- ========================================================================
- ========================== 3RD PARTY DRIVERS ===========================
- ========================================================================
- Image path: \SystemRoot\System32\drivers\amd_sata.sys
- Image name: amd_sata.sys
- Search : https://www.google.com/search?q=amd_sata.sys
- ADA Info : AMD SATA Controller AHCI Device driver http://support.amd.com/
- Timestamp : Thu Mar 19 2015
- Image path: \SystemRoot\System32\drivers\amd_xata.sys
- Image name: amd_xata.sys
- Search : https://www.google.com/search?q=amd_xata.sys
- ADA Info : AMD Stor Filter driver http://support.amd.com/
- Timestamp : Thu Mar 19 2015
- Image path: \SystemRoot\System32\drivers\amdgpio3.sys
- Image name: amdgpio3.sys
- Search : https://www.google.com/search?q=amdgpio3.sys
- ADA Info : AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Timestamp : Mon Mar 14 2016
- Image path: \SystemRoot\System32\drivers\nvvhci.sys
- Image name: nvvhci.sys
- Search : https://www.google.com/search?q=nvvhci.sys
- ADA Info : Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Timestamp : Thu Aug 16 2018
- Image path: \SystemRoot\System32\drivers\amdpsp.sys
- Image name: amdpsp.sys
- Search : https://www.google.com/search?q=amdpsp.sys
- ADA Info : Advanced Micro Devices, Inc http://support.amd.com/
- Timestamp : Mon Sep 10 2018
- Image path: \SystemRoot\System32\drivers\AMDPCIDev.sys
- Image name: AMDPCIDev.sys
- Search : https://www.google.com/search?q=AMDPCIDev.sys
- ADA Info : Advanced Micro Devices PCI Device driver
- Timestamp : Thu Oct 11 2018
- Image path: \SystemRoot\System32\drivers\amdgpio2.sys
- Image name: amdgpio2.sys
- Search : https://www.google.com/search?q=amdgpio2.sys
- ADA Info : AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Timestamp : Mon Nov 12 2018
- Image path: \SystemRoot\system32\drivers\RTKVHD64.sys
- Image name: RTKVHD64.sys
- Search : https://www.google.com/search?q=RTKVHD64.sys
- ADA Info : Realtek Audio Driver system driver https://www.realtek.com/en/
- Timestamp : Tue Mar 5 2019
- Image path: \SystemRoot\System32\drivers\rt640x64.sys
- Image name: rt640x64.sys
- Search : https://www.google.com/search?q=rt640x64.sys
- ADA Info : Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Timestamp : Thu Mar 7 2019
- Image path: \SystemRoot\system32\drivers\nvvad64v.sys
- Image name: nvvad64v.sys
- Search : https://www.google.com/search?q=nvvad64v.sys
- ADA Info : Nvidia Virtual Audio Driver http://www.nvidia.com/
- Timestamp : Thu Mar 14 2019
- Image path: \SystemRoot\system32\drivers\nvhda64v.sys
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Tue Mar 19 2019
- Image path: \SystemRoot\System32\drivers\asmthub3.sys
- Image name: asmthub3.sys
- Search : https://www.google.com/search?q=asmthub3.sys
- ADA Info : ASMedia USB 3.0 Hub driver http://www.asmedia.com.tw/
- Timestamp : Mon Mar 25 2019
- Image path: \SystemRoot\System32\drivers\asmtxhci.sys
- Image name: asmtxhci.sys
- Search : https://www.google.com/search?q=asmtxhci.sys
- ADA Info : ASMedia USB 3.0 driver http://www.asmedia.com.tw/
- Timestamp : Mon Mar 25 2019
- If any of the above drivers are from Microsoft then please let me know.
- I will have them moved to the Microsoft list on the next update.
- ========================================================================
- ========================== MICROSOFT DRIVERS ===========================
- ========================================================================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- amdppm.sys Processor Device Driver
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- csc.sys Windows Client Side Caching driver (Microsoft)
- dc1-controller.sys KMDF driver for DC1 Controller
- DevAuthE.sys Xbox Device Authentication Driver
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kd.dll Local Kernal Debugger (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate_AuthenticAMD.dll AMD Microcode Update Library (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msgpioclx.sys GPIO Class Extension Driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- ntoskrnl.exe NT Operating System Kernal (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- parport.sys Parallel Port Driver (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdpdr.sys RDP Device redirector (Microsoft)
- rdpvideominiport.sys RDP Video Miniport driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- serenum.sys Serial Port Enumerator (Microsoft)
- serial.sys Serial Device Driver
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- tsusbhub.sys USB-Hub driver (Microsoft)
- ucx01000.sys USB Controller Extension (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- USBSTOR.SYS USB Mass Storage Class driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface Driver
- winquic.sys QUIC Transport Protocol driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WpdUpFltr.sys Portable Device Upper Class Filter driver (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- WUDFRd.sys Windows Driver Foundation - User-mode Driver Framework Reflector driver (Microsoft)
- xboxgip.sys Game Input Protocol Driver
- xinputhid.sys XINPUT filter driver for HID
- Unloaded modules:
- fffff804`08d20000 fffff804`08d28000 NTIOLib_X64.
- fffff804`18fc0000 fffff804`18fcf000 dump_storpor
- fffff804`18c00000 fffff804`18c2f000 dump_storahc
- fffff804`18c50000 fffff804`18c6e000 dump_dumpfve
- fffff804`1aef0000 fffff804`1af41000 WUDFRd.sys
- fffff804`0f7a0000 fffff804`0f7bc000 EhStorClass.
- fffff804`199e0000 fffff804`19a31000 WUDFRd.sys
- fffff804`19800000 fffff804`1981e000 dam.sys
- fffff804`0f3f0000 fffff804`0f3f9000 MbamElam.sys
- fffff804`0f3d0000 fffff804`0f3e1000 WdBoot.sys
- fffff804`10410000 fffff804`10420000 hwpolicy.sys
- ========================================================================
- ============================== BIOS INFO ===============================
- ========================================================================
- [SMBIOS Data Tables v2.8]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 2475 bytes]
- [BIOS Information (Type 0) - Length 26 - Handle 0000h]
- Vendor American Megatrends Inc.
- BIOS Version A.90
- BIOS Starting Address Segment f000
- BIOS Release Date 03/07/2019
- BIOS ROM Size 1000000
- BIOS Characteristics
- 07: - PCI Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 27: - Keyboard Services Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 32: - BIOS Vendor Reserved
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 5
- BIOS Minor Revision 14
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- Manufacturer Micro-Star International Co., Ltd.
- Product Name MS-7B79
- Version 2.0
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
- Manufacturer Micro-Star International Co., Ltd.
- Product X470 GAMING PLUS (MS-7B79)
- Version 2.0
- Feature Flags 09h
- 1994569440: - 1994569488: - 8½?ÿ
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 22 - Handle 0003h]
- Manufacturer Micro-Star International Co., Ltd.
- Chassis Type Desktop
- Version 2.0
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 3
- [OEM Strings (Type 11) - Length 5 - Handle 000bh]
- Number of Strings 1
- [System Configuration Options (Type 12) - Length 5 - Handle 000ch]
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 000eh]
- [Physical Memory Array (Type 16) - Length 23 - Handle 000fh]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 268435456KB
- Memory Error Inf Handle 000eh
- Number of Memory Devices 4
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0010h]
- Starting Address 00000000h
- Ending Address 00ffffffh
- Memory Array Handle 000fh
- Partition Width 02
- [Cache Information (Type 7) - Length 19 - Handle 0011h]
- Socket Designation L1 - Cache
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0300h - 768K
- Installed Size 0300h - 768K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0012h]
- Socket Designation L2 - Cache
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 1000h - 4096K
- Installed Size 1000h - 4096K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0013h]
- Socket Designation L3 - Cache
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 4000h - 16384K
- Installed Size 4000h - 16384K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 16-way Set-Associative
- [Processor Information (Type 4) - Length 48 - Handle 0014h]
- Socket Designation AM4
- Processor Type Central Processor
- Processor Family 6bh - Specification Reserved
- Processor Manufacturer Advanced Micro Devices, Inc.
- Processor ID 820f8000fffb8b17
- Processor Version AMD Ryzen 7 2700X Eight-Core Processor
- Processor Voltage 8ch - 1.2V
- External Clock 100MHz
- Max Speed 4350MHz
- Current Speed 3700MHz
- Status Enabled Populated
- Processor Upgrade Specification Reserved
- L1 Cache Handle 0011h
- L2 Cache Handle 0012h
- L3 Cache Handle 0013h
- Part Number Unknown
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 0015h]
- [Memory Device (Type 17) - Length 40 - Handle 0016h]
- Physical Memory Array Handle 000fh
- Memory Error Info Handle 0015h
- Form Factor 02h - Unknown
- Device Locator DIMM 0
- Bank Locator P0 CHANNEL A
- Memory Type 02h - Unknown
- Type Detail 0004h - Unknown
- Speed 2400MHz
- Manufacturer Unknown
- Part Number Unknown
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 0017h]
- [Memory Device (Type 17) - Length 40 - Handle 0018h]
- Physical Memory Array Handle 000fh
- Memory Error Info Handle 0017h
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator DIMM 1
- Bank Locator P0 CHANNEL A
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 2400MHz
- Manufacturer Unknown
- Part Number F4-2400C15-8GFX
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0019h]
- Starting Address 00000000h
- Ending Address 00ffffffh
- Memory Device Handle 0018h
- Mem Array Mapped Adr Handle 0010h
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 001ah]
- [Memory Device (Type 17) - Length 40 - Handle 001bh]
- Physical Memory Array Handle 000fh
- Memory Error Info Handle 001ah
- Form Factor 02h - Unknown
- Device Locator DIMM 0
- Bank Locator P0 CHANNEL B
- Memory Type 02h - Unknown
- Type Detail 0004h - Unknown
- Speed 2400MHz
- Manufacturer Unknown
- Part Number Unknown
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 001ch]
- [Memory Device (Type 17) - Length 40 - Handle 001dh]
- Physical Memory Array Handle 000fh
- Memory Error Info Handle 001ch
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator DIMM 1
- Bank Locator P0 CHANNEL B
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 2400MHz
- Manufacturer Unknown
- Part Number F4-2400C15-8GFX
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 001eh]
- Starting Address 00000000h
- Ending Address 00ffffffh
- Memory Device Handle 001dh
- Mem Array Mapped Adr Handle 0010h
- ========================================================================
- ============================== IMAGE SCAN ==============================
- ========================================================================
- MZ at ffff80df`531b0000, prot 00000040, type 01000000 - size 2a8000
- Name: win32kbase.sys
- MZ at ffff80df`53460000, prot 00000040, type 01000000 - size 48000
- Name: cdd.dll
- MZ at fffff804`08ae0000, prot 00000040, type 01000000 - size c4000
- Name: srv2.exe
- MZ at fffff804`08bb0000, prot 00000040, type 01000000 - size 1d000
- Name: rassstp.exe
- MZ at fffff804`08bd0000, prot 00000040, type 01000000 - size 40000
- Name: ndproxy.exe
- MZ at fffff804`08c20000, prot 00000040, type 01000000 - size 27000
- Name: AgileVpn.exe
- MZ at fffff804`08c50000, prot 00000040, type 01000000 - size 22000
- Name: rasl2tp.exe
- MZ at fffff804`08c80000, prot 00000040, type 01000000 - size 20000
- Name: raspptp.exe
- MZ at fffff804`08cb0000, prot 00000040, type 01000000 - size 1c000
- Name: raspppoe.exe
- MZ at fffff804`08cd0000, prot 00000040, type 01000000 - size f000
- Name: NDISTAPI.SYS
- MZ at fffff804`08ce0000, prot 00000040, type 01000000 - size 3a000
- Name: ndiswan.exe
- MZ at fffff804`08d50000, prot 00000040, type 01000000 - size 13000
- Name: condrv.exe
- MZ at fffff804`09190000, prot 00000040, type 01000000 - size 144000
- Name: http.exe
- MZ at fffff804`092e0000, prot 00000040, type 01000000 - size 1a000
- Name: mpsdrv.exe
- MZ at fffff804`09300000, prot 00000040, type 01000000 - size 52000
- Name: srvnet.sys
- MZ at fffff804`09360000, prot 00000040, type 01000000 - size 27000
- Name: ndu.exe
- MZ at fffff804`09390000, prot 00000040, type 01000000 - size 14000
- Name: mmcss.exe
- MZ at fffff804`093b0000, prot 00000040, type 01000000 - size 14000
- Name: tcpipreg.exe
- MZ at fffff804`0ccb2000, prot 00000040, type 01000000 - size a3000
- Name: HAL.dll
- MZ at fffff804`0ec00000, prot 00000040, type 01000000 - size b000
- Name: KD.dll
- MZ at fffff804`0ec40000, prot 00000040, type 01000000 - size 11000
- Name: WerLiveKernelApi.dll
- MZ at fffff804`0ec60000, prot 00000040, type 01000000 - size 2a000
- Name: ksecdd.sys
- MZ at fffff804`0ec90000, prot 00000040, type 01000000 - size 60000
- Name: msrpc.sys
- MZ at fffff804`0ed00000, prot 00000040, type 01000000 - size 27000
- Name: ntostmhost.dll
- MZ at fffff804`0ed30000, prot 00000040, type 01000000 - size 68000
- Name: CLFS.SYS
- MZ at fffff804`0eda0000, prot 00000040, type 01000000 - size 1a000
- Name: PSHED.dll
- MZ at fffff804`0edc0000, prot 00000040, type 01000000 - size b000
- Name: BOOTVID.dll
- MZ at fffff804`0edd0000, prot 00000040, type 01000000 - size 105000
- Name: clipsp.sys
- MZ at fffff804`0eee0000, prot 00000040, type 01000000 - size 71000
- Name: FLTMGR.SYS
- MZ at fffff804`0ef60000, prot 00000040, type 01000000 - size e000
- Name: cmimcext.dll
- MZ at fffff804`0ef70000, prot 00000040, type 01000000 - size c000
- Name: ntosext.dll
- MZ at fffff804`0ef80000, prot 00000040, type 01000000 - size dc000
- Name: CI.dll
- MZ at fffff804`0f060000, prot 00000040, type 01000000 - size bc000
- Name: cng.sys
- MZ at fffff804`0f120000, prot 00000040, type 01000000 - size d5000
- Name: Wdf01000.exe
- MZ at fffff804`0f200000, prot 00000040, type 01000000 - size 13000
- Name: WDFLDR.SYS
- MZ at fffff804`0f220000, prot 00000040, type 01000000 - size f000
- Name: SleepStudyHelper.sys
- MZ at fffff804`0f230000, prot 00000040, type 01000000 - size 10000
- Name: WppRecorder.sys
- MZ at fffff804`0f250000, prot 00000040, type 01000000 - size 25000
- Name: acpiex.exe
- MZ at fffff804`0f280000, prot 00000040, type 01000000 - size 49000
- Name: mssecflt.exe
- MZ at fffff804`0f2d0000, prot 00000040, type 01000000 - size 1a000
- Name: SgrmAgent.exe
- MZ at fffff804`0f2f0000, prot 00000040, type 01000000 - size cc000
- Name: ACPI.SYS
- MZ at fffff804`0f3c0000, prot 00000040, type 01000000 - size c000
- Name: WMILIB.SYS
- MZ at fffff804`0f400000, prot 00000040, type 01000000 - size 49000
- Name: intelpep.exe
- MZ at fffff804`0f450000, prot 00000040, type 01000000 - size 17000
- Name: WindowsTrustedRT.exe
- MZ at fffff804`0f470000, prot 00000040, type 01000000 - size b000
- Name: WindowsTrustedRTProxy.exe
- MZ at fffff804`0f480000, prot 00000040, type 01000000 - size 15000
- Name: pcw.exe
- MZ at fffff804`0f4a0000, prot 00000040, type 01000000 - size b000
- Name: msisadrv.exe
- MZ at fffff804`0f4b0000, prot 00000040, type 01000000 - size 6f000
- Name: pci.exe
- MZ at fffff804`0f520000, prot 00000040, type 01000000 - size 13000
- Name: vdrvroot.exe
- MZ at fffff804`0f540000, prot 00000040, type 01000000 - size 33000
- Name: PDC.exe
- MZ at fffff804`0f580000, prot 00000040, type 01000000 - size 19000
- Name: CEA.sys
- MZ at fffff804`0f5a0000, prot 00000040, type 01000000 - size 30000
- Name: partmgr.exe
- MZ at fffff804`0f5e0000, prot 00000040, type 01000000 - size a5000
- Name: spaceport.exe
- MZ at fffff804`0f690000, prot 00000040, type 01000000 - size 1a000
- Name: volmgr.exe
- MZ at fffff804`0f6b0000, prot 00000040, type 01000000 - size 63000
- Name: volmgrx.exe
- MZ at fffff804`0f720000, prot 00000040, type 01000000 - size 1f000
- Name: mountmgr.exe
- MZ at fffff804`0f740000, prot 00000040, type 01000000 - size 2e000
- Name: storahci.exe
- MZ at fffff804`0f7c0000, prot 00000040, type 01000000 - size 1a000
- Name: fileinfo.exe
- MZ at fffff804`0f7e0000, prot 00000040, type 01000000 - size d000
- Name: fs_rec.exe
- MZ at fffff804`0f7f0000, prot 00000040, type 01000000 - size b000
- Name: volume.exe
- MZ at fffff804`0f800000, prot 00000040, type 01000000 - size a2000
- Name: storport.sys
- MZ at fffff804`0f8b0000, prot 00000040, type 01000000 - size 3d000
- Name: wof.exe
- MZ at fffff804`0f950000, prot 00000040, type 01000000 - size 29e000
- Name: ntfs.exe
- MZ at fffff804`0fbf0000, prot 00000040, type 01000000 - size 172000
- Name: NDIS.SYS
- MZ at fffff804`0fd70000, prot 00000040, type 01000000 - size 94000
- Name: NETIO.SYS
- MZ at fffff804`0fe10000, prot 00000040, type 01000000 - size 32000
- Name: ksecpkg.exe
- MZ at fffff804`0fe80000, prot 00000040, type 01000000 - size 2ea000
- Name: TCPIP.SYS
- MZ at fffff804`10170000, prot 00000040, type 01000000 - size 7a000
- Name: fwpkclnt.sys
- MZ at fffff804`101f0000, prot 00000040, type 01000000 - size 30000
- Name: wfplwfs.exe
- MZ at fffff804`10230000, prot 00000040, type 01000000 - size c9000
- Name: fvevol.exe
- MZ at fffff804`10300000, prot 00000040, type 01000000 - size 6d000
- Name: volsnap.exe
- MZ at fffff804`10370000, prot 00000040, type 01000000 - size 4e000
- Name: rdyboost.exe
- MZ at fffff804`103c0000, prot 00000040, type 01000000 - size 25000
- Name: MUP.SYS
- MZ at fffff804`103f0000, prot 00000040, type 01000000 - size 12000
- Name: iorate.exe
- MZ at fffff804`10420000, prot 00000040, type 01000000 - size 1c000
- Name: disk.exe
- MZ at fffff804`10440000, prot 00000040, type 01000000 - size 6b000
- Name: CLASSPNP.SYS
- MZ at fffff804`18c70000, prot 00000040, type 01000000 - size 30000
- Name: cdrom.exe
- MZ at fffff804`18cb0000, prot 00000040, type 01000000 - size 15000
- Name: filecrypt.exe
- MZ at fffff804`18cd0000, prot 00000040, type 01000000 - size e000
- Name: tbs.sys
- MZ at fffff804`18ce0000, prot 00000040, type 01000000 - size a000
- Name: null.exe
- MZ at fffff804`18cf0000, prot 00000040, type 01000000 - size a000
- Name: beep.exe
- MZ at fffff804`18d00000, prot 00000040, type 01000000 - size 9c000
- Name: usbhub3.sys
- MZ at fffff804`18da0000, prot 00000040, type 01000000 - size 8f000
- Name: mrxsmb.sys
- MZ at fffff804`18e30000, prot 00000040, type 01000000 - size 45000
- Name: mrxsmb20.exe
- MZ at fffff804`18e80000, prot 00000040, type 01000000 - size 27000
- Name: TsUsbHub.exe
- MZ at fffff804`18f90000, prot 00000040, type 01000000 - size 1d000
- Name: CRASHDMP.SYS
- MZ at fffff804`19400000, prot 00000040, type 01000000 - size 11000
- Name: BasicRender.exe
- MZ at fffff804`19420000, prot 00000040, type 01000000 - size 1c000
- Name: npfs.exe
- MZ at fffff804`19440000, prot 00000040, type 01000000 - size 11000
- Name: msfs.exe
- MZ at fffff804`19460000, prot 00000040, type 01000000 - size 26000
- Name: tdx.exe
- MZ at fffff804`19490000, prot 00000040, type 01000000 - size 10000
- Name: TDI.SYS
- MZ at fffff804`194b0000, prot 00000040, type 01000000 - size 59000
- Name: netbt.exe
- MZ at fffff804`19510000, prot 00000040, type 01000000 - size 13000
- Name: afunix.dll
- MZ at fffff804`19530000, prot 00000040, type 01000000 - size a7000
- Name: afd.exe
- MZ at fffff804`195e0000, prot 00000040, type 01000000 - size 1a000
- Name: vwififlt.SYS
- MZ at fffff804`19600000, prot 00000040, type 01000000 - size 2b000
- Name: pacer.exe
- MZ at fffff804`19630000, prot 00000040, type 01000000 - size 14000
- Name: netbios.exe
- MZ at fffff804`19650000, prot 00000040, type 01000000 - size 7b000
- Name: rdbss.sys
- MZ at fffff804`196d0000, prot 00000040, type 01000000 - size 94000
- Name: csc.exe
- MZ at fffff804`19770000, prot 00000040, type 01000000 - size 12000
- Name: nsiproxy.exe
- MZ at fffff804`19790000, prot 00000040, type 01000000 - size d000
- Name: NpSvcTrig.exe
- MZ at fffff804`197a0000, prot 00000040, type 01000000 - size 10000
- Name: mssmbios.exe
- MZ at fffff804`197c0000, prot 00000040, type 01000000 - size a000
- Name: gpuenergydrv.exe
- MZ at fffff804`197d0000, prot 00000040, type 01000000 - size 2c000
- Name: dfsc.exe
- MZ at fffff804`19800000, prot 00000040, type 01000000 - size 1d000
- Name: wanarp.exe
- MZ at fffff804`19820000, prot 00000040, type 01000000 - size 6b000
- Name: fastfat.exe
- MZ at fffff804`19890000, prot 00000040, type 01000000 - size 16000
- Name: bam.exe
- MZ at fffff804`198b0000, prot 00000040, type 01000000 - size 4f000
- Name: ahcache.exe
- MZ at fffff804`19900000, prot 00000040, type 01000000 - size 8c000
- Name: Vid.exe
- MZ at fffff804`19990000, prot 00000040, type 01000000 - size 1f000
- Name: winhvr.sys
- MZ at fffff804`199b0000, prot 00000040, type 01000000 - size 11000
- Name: CompositeBus.exe
- MZ at fffff804`199d0000, prot 00000040, type 01000000 - size d000
- Name: kdnic.sys
- MZ at fffff804`199e0000, prot 00000040, type 01000000 - size 38000
- Name: winquic.sys
- MZ at fffff804`19a20000, prot 00000040, type 01000000 - size 18000
- Name: lltdio.exe
- MZ at fffff804`19a40000, prot 00000040, type 01000000 - size 15000
- Name: UmBus.exe
- MZ at fffff804`19a60000, prot 00000040, type 01000000 - size 88000
- Name: usbxhci.exe
- MZ at fffff804`19af0000, prot 00000040, type 01000000 - size 41000
- Name: ucx01000.exe
- MZ at fffff804`19ce0000, prot 00000040, type 01000000 - size 22000
- Name: hdaudbus.exe
- MZ at fffff804`19d10000, prot 00000040, type 01000000 - size 67000
- Name: portcls.sys
- MZ at fffff804`19db0000, prot 00000040, type 01000000 - size 78000
- Name: ks.sys
- MZ at fffff804`19e40000, prot 00000040, type 01000000 - size 1f000
- Name: parport.exe
- MZ at fffff804`19e60000, prot 00000040, type 01000000 - size 1c000
- Name: serial.exe
- MZ at fffff804`19e80000, prot 00000040, type 01000000 - size f000
- Name: SerEnum.exe
- MZ at fffff804`19ea0000, prot 00000040, type 01000000 - size 30000
- Name: msgpioclx.exe
- MZ at fffff804`19ee0000, prot 00000040, type 01000000 - size c000
- Name: wmiacpi.exe
- MZ at fffff804`19ef0000, prot 00000040, type 01000000 - size 3a000
- Name: amdppm.exe
- MZ at fffff804`19f40000, prot 00000040, type 01000000 - size e000
- Name: UEFI.SYS
- MZ at fffff804`19f70000, prot 00000040, type 01000000 - size f000
- Name: ksthunk.exe
- MZ at fffff804`19fa0000, prot 00000040, type 01000000 - size d000
- Name: NdisVirtualBus.exe
- MZ at fffff804`19fb0000, prot 00000040, type 01000000 - size c000
- Name: swenum.exe
- MZ at fffff804`19fc0000, prot 00000040, type 01000000 - size e000
- Name: rdpbus.exe
- MZ at fffff804`19fd0000, prot 00000040, type 01000000 - size e000
- Name: USBD.SYS
- MZ at fffff804`1a020000, prot 00000040, type 01000000 - size 1b000
- Name: rspndr.exe
- MZ at fffff804`1a040000, prot 00000040, type 01000000 - size 373000
- Name: dxgkrnl.sys
- MZ at fffff804`1a3c0000, prot 00000040, type 01000000 - size 16000
- Name: watchdog.sys
- MZ at fffff804`1a3e0000, prot 00000040, type 01000000 - size 16000
- Name: BasicDisplay.exe
- MZ at fffff804`1ac00000, prot 00000040, type 01000000 - size 33000
- Name: usbccgp.exe
- MZ at fffff804`1ac40000, prot 00000040, type 01000000 - size 12000
- Name: hidusb.exe
- MZ at fffff804`1ac60000, prot 00000040, type 01000000 - size 3b000
- Name: HIDCLASS.SYS
- MZ at fffff804`1aca0000, prot 00000040, type 01000000 - size 13000
- Name: HIDPARSE.SYS
- MZ at fffff804`1acc0000, prot 00000040, type 01000000 - size 10000
- Name: mouhid.exe
- MZ at fffff804`1ace0000, prot 00000040, type 01000000 - size 13000
- Name: mouclass.exe
- MZ at fffff804`1ad00000, prot 00000040, type 01000000 - size 11000
- Name: kbdhid.exe
- MZ at fffff804`1ad20000, prot 00000040, type 01000000 - size 14000
- Name: kbdclass.exe
- MZ at fffff804`1ad40000, prot 00000040, type 01000000 - size 16000
- Name: dc1-controller.exe
- MZ at fffff804`1ad60000, prot 00000040, type 01000000 - size 12e000
- Name: XBOXGIP.exe
- MZ at fffff804`1ae90000, prot 00000040, type 01000000 - size 14000
- Name: DevAuthE.sys
- MZ at fffff804`1aeb0000, prot 00000040, type 01000000 - size 37000
- Name: USBAudio.exe
- MZ at fffff804`1af20000, prot 00000040, type 01000000 - size 2e000
- Name: storahci.exe
- MZ at fffff804`1af70000, prot 00000040, type 01000000 - size 1d000
- Name: DUMPFVE.SYS
- MZ at fffff804`1af90000, prot 00000040, type 01000000 - size 50000
- Name: WUDFRd.exe
- MZ at fffff804`1aff0000, prot 00000040, type 01000000 - size 13000
- Name: XINPUTHID.exe
- MZ at fffff804`1b010000, prot 00000040, type 01000000 - size d000
- Name: rdpvideominiport.exe
- MZ at fffff804`1b020000, prot 00000040, type 01000000 - size 2a000
- Name: luafv.exe
- MZ at fffff804`1b050000, prot 00000040, type 01000000 - size 36000
- Name: wcifs.exe
- MZ at fffff804`1b090000, prot 00000040, type 01000000 - size 2f000
- Name: rdpdr.exe
- MZ at fffff804`1b0c0000, prot 00000040, type 01000000 - size e000
- Name: WpdUpFltr.exe
- MZ at fffff804`1b0d0000, prot 00000040, type 01000000 - size 77000
- Name: cldflt.exe
- MZ at fffff804`1b150000, prot 00000040, type 01000000 - size 1a000
- Name: storqosflt.exe
- MZ at fffff804`1b170000, prot 00000040, type 01000000 - size 25000
- Name: bowser.exe
- MZ at fffff804`1b1a0000, prot 00000040, type 01000000 - size db000
- Name: dxgmms2.sys
- MZ at fffff804`1b280000, prot 00000040, type 01000000 - size 16000
- Name: monitor.exe
- MZ at fffff804`1b2b0000, prot 00000040, type 01000000 - size e000
- Name: SYS.exe
- MZ at fffff804`1b980000, prot 00000040, type 01000000 - size 25000
- Name: usbstor.exe
- MZ at fffff804`1b9e0000, prot 00000040, type 01000000 - size 19000
- Name: mslldp.exe
- ========================================================================
- ==================== Dump File: 070119-9812-01.dmp =====================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Mini Kernel Dump does not have process information
- Unable to load image Unknown_Module_00000000`00000000, Win32 error 0n2
- *** WARNING: Unable to verify timestamp for Unknown_Module_00000000`00000000
- Unable to add module at 00000000`00000000
- WARNING: .reload failed, module list may be incomplete
- Debugger can not determine kernel base address
- Windows 10 Kernel Version 18362 MP (16 procs) Free x64
- Kernel base = 0xfffff803`3dc00000 PsLoadedModuleList = 0xfffff803`3e043370
- Debug session time: Mon Jul 1 19:04:17.877 2019 (UTC - 4:00)
- System Uptime: 0 days 0:01:20.572
- Unable to load image Unknown_Module_00000000`00000000, Win32 error 0n2
- *** WARNING: Unable to verify timestamp for Unknown_Module_00000000`00000000
- Unable to add module at 00000000`00000000
- WARNING: .reload failed, module list may be incomplete
- Debugger can not determine kernel base address
- .Unable to load image Unknown_Module_00000000`00000000, Win32 error 0n2
- *** WARNING: Unable to verify timestamp for Unknown_Module_00000000`00000000
- Unable to add module at 00000000`00000000
- BugCheck 19, {22, ffff9d8271c70000, 1, 0}
- ***** Debugger could not find nt in module list, module list might be corrupt, error 0x80070057.
- Unable to get size of nt!_MMPTE - probably bad symbols
- Probably caused by : Unknown_Image ( ANALYSIS_INCONCLUSIVE )
- Followup: MachineOwner
- BAD_POOL_HEADER (19)
- The pool is already corrupt at the time of the current request.
- This may or may not be due to the caller.
- The internal pool links must be walked to figure out a possible cause of
- the problem, and then special pool applied to the suspect tags or the driver
- verifier to a suspect driver.
- Arguments:
- Arg1: 0000000000000022,
- Arg2: ffff9d8271c70000
- Arg3: 0000000000000001
- Arg4: 0000000000000000
- Debugging Details:
- ***** Debugger could not find nt in module list, module list might be corrupt, error 0x80070057.
- Unable to get size of nt!_MMPTE - probably bad symbols
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- BUGCHECK_STR: 0x19_22
- POOL_ADDRESS: Unable to get size of nt!_MMPTE - probably bad symbols
- ffff9d8271c70000
- CUSTOMER_CRASH_COUNT: 1
- CURRENT_IRQL: 0
- LAST_CONTROL_TRANSFER: from fffff8033ddf8a6a to fffff8033ddbc8a0
- STACK_TEXT:
- ffff8708`2b524bc8 fffff803`3ddf8a6a : 00000000`00000019 00000000`00000022 ffff9d82`71c70000 00000000`00000001 : 0xfffff803`3ddbc8a0
- ffff8708`2b524bd0 00000000`00000019 : 00000000`00000022 ffff9d82`71c70000 00000000`00000001 00000000`00000000 : 0xfffff803`3ddf8a6a
- ffff8708`2b524bd8 00000000`00000022 : ffff9d82`71c70000 00000000`00000001 00000000`00000000 00000000`00001001 : 0x19
- ffff8708`2b524be0 ffff9d82`71c70000 : 00000000`00000001 00000000`00000000 00000000`00001001 00000000`00000000 : 0x22
- ffff8708`2b524be8 00000000`00000001 : 00000000`00000000 00000000`00001001 00000000`00000000 00000000`00000000 : 0xffff9d82`71c70000
- ffff8708`2b524bf0 00000000`00000000 : 00000000`00001001 00000000`00000000 00000000`00000000 00000000`00000103 : 0x1
- STACK_COMMAND: kb
- SYMBOL_NAME: ANALYSIS_INCONCLUSIVE
- FOLLOWUP_NAME: MachineOwner
- MODULE_NAME: Unknown_Module
- IMAGE_NAME: Unknown_Image
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- BUCKET_ID: CORRUPT_MODULELIST_0x19_22
- DEFAULT_BUCKET_ID: CORRUPT_MODULELIST_0x19_22
- PRIMARY_PROBLEM_CLASS: CORRUPT_MODULELIST
- FAILURE_BUCKET_ID: CORRUPT_MODULELIST_0x19_22
- TARGET_TIME: 2019-07-01T23:04:17.000Z
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:corrupt_modulelist_0x19_22
- FAILURE_ID_HASH: {1ea13dde-9f77-c377-4e27-a6958973d90b}
- Followup: MachineOwner
- ========================================================================
- ==================== Dump File: 062919-9593-01.dmp =====================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
- *** WARNING: Unable to verify timestamp for ntoskrnl.exe
- *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
- Windows 10 Kernel Version 18362 MP (16 procs) Free x64
- Kernel base = 0xfffff801`77800000 PsLoadedModuleList = 0xfffff801`77c43370
- Debug session time: Sat Jun 29 19:25:23.116 2019 (UTC - 4:00)
- System Uptime: 0 days 0:05:44.812
- Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
- *** WARNING: Unable to verify timestamp for ntoskrnl.exe
- *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
- ************* Symbol Loading Error Summary **************
- Module name Error
- ntoskrnl The system cannot find the file specified
- You can troubleshoot most symbol related issues by turning on symbol loading diagnostics (!sym noisy) and repeating the command that caused symbols to be loaded.
- You should also verify that your symbol search path (.sympath) is correct.
- BugCheck A, {fffff8017234da90, 2, 1, fffff80177849c23}
- ***** Kernel symbols are WRONG. Please fix symbols to do analysis.
- *** WARNING: Unable to verify timestamp for win32k.sys
- *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
- Probably caused by : memory_corruption
- Followup: memory_corruption
- IRQL_NOT_LESS_OR_EQUAL (a)
- An attempt was made to access a pageable (or completely invalid) address at an
- interrupt request level (IRQL) that is too high. This is usually
- caused by drivers using improper addresses.
- If a kernel debugger is available get the stack backtrace.
- Arguments:
- Arg1: fffff8017234da90, memory referenced
- Arg2: 0000000000000002, IRQL
- Arg3: 0000000000000001, bitfield :
- bit 0 : value 0 = read operation, 1 = write operation
- bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
- Arg4: fffff80177849c23, address which referenced memory
- Debugging Details:
- ***** Kernel symbols are WRONG. Please fix symbols to do analysis.
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- ADDITIONAL_DEBUG_TEXT:
- You can run '.symfix; .reload' to try to fix the symbol path and load symbols.
- WRONG_SYMBOLS_TIMESTAMP: eadcd02b
- WRONG_SYMBOLS_SIZE: ab2000
- FAULTING_MODULE: fffff80177800000 nt
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- DUMP_TYPE: 2
- WRITE_ADDRESS: *************************************************************************
- Unable to get size of nt!_MMPTE - probably bad symbols
- fffff8017234da90
- CURRENT_IRQL: 0
- FAULTING_IP:
- nt+49c23
- fffff801`77849c23 f0480fbaaf1059000000 lock bts qword ptr [rdi+5910h],0
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- BUGCHECK_STR: AV
- LAST_CONTROL_TRANSFER: from fffff801779ce569 to fffff801779bc8a0
- STACK_TEXT:
- fffff801`7aa67558 fffff801`779ce569 : 00000000`0000000a fffff801`7234da90 00000000`00000002 00000000`00000001 : nt+0x1bc8a0
- fffff801`7aa67560 00000000`0000000a : fffff801`7234da90 00000000`00000002 00000000`00000001 fffff801`77849c23 : nt+0x1ce569
- fffff801`7aa67568 fffff801`7234da90 : 00000000`00000002 00000000`00000001 fffff801`77849c23 ffff8006`ca0a9678 : 0xa
- fffff801`7aa67570 00000000`00000002 : 00000000`00000001 fffff801`77849c23 ffff8006`ca0a9678 00000000`00000000 : 0xfffff801`7234da90
- fffff801`7aa67578 00000000`00000001 : fffff801`77849c23 ffff8006`ca0a9678 00000000`00000000 00000000`00000000 : 0x2
- fffff801`7aa67580 fffff801`77849c23 : ffff8006`ca0a9678 00000000`00000000 00000000`00000000 00000000`00000000 : 0x1
- fffff801`7aa67588 ffff8006`ca0a9678 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt+0x49c23
- fffff801`7aa67590 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0xffff8006`ca0a9678
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !hal
- fffff801782b38a6-fffff801782b38ab 6 bytes - hal!KeQueryPerformanceCounter+e6
- [ ff 15 5c 70 07 00:e8 f5 c9 89 ff 90 ]
- fffff801782b3c53 - hal!HalpApicRequestInterrupt+a3 (+0x3ad)
- [ 00:90 ]
- fffff801782b3cc1-fffff801782b3cc6 6 bytes - hal!HalpApicRequestInterrupt+111 (+0x6e)
- [ ff 15 41 6c 07 00:e8 da c5 89 ff 90 ]
- fffff801782b51d5-fffff801782b51d6 2 bytes - hal!HalpTimerClockIpiRoutine+15 (+0x1514)
- [ 48 ff:4c 8b ]
- fffff801782b51dc-fffff801782b51e0 5 bytes - hal!HalpTimerClockIpiRoutine+1c (+0x07)
- [ 0f 1f 44 00 00:e8 bf 9e 56 ff ]
- fffff801782b5237-fffff801782b523c 6 bytes - hal!HalpTimerClockIpiRoutine+77 (+0x5b)
- [ ff 15 cb 56 07 00:e8 64 b0 89 ff 90 ]
- 26 errors : !hal (fffff801782b38a6-fffff801782b523c)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2019-06-29T23:25:23.000Z
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ========================================================================
- ==================== Dump File: 062919-9562-01.dmp =====================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
- *** WARNING: Unable to verify timestamp for ntoskrnl.exe
- *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
- Windows 10 Kernel Version 18362 MP (16 procs) Free x64
- Kernel base = 0xfffff801`5e600000 PsLoadedModuleList = 0xfffff801`5ea43370
- Debug session time: Sat Jun 29 19:27:45.370 2019 (UTC - 4:00)
- System Uptime: 0 days 0:01:33.066
- Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
- *** WARNING: Unable to verify timestamp for ntoskrnl.exe
- *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
- ************* Symbol Loading Error Summary **************
- Module name Error
- ntoskrnl The system cannot find the file specified
- You can troubleshoot most symbol related issues by turning on symbol loading diagnostics (!sym noisy) and repeating the command that caused symbols to be loaded.
- You should also verify that your symbol search path (.sympath) is correct.
- BugCheck 50, {ffffeb832920ff42, 0, fffff80162d5b7ae, 2}
- ***** Kernel symbols are WRONG. Please fix symbols to do analysis.
- Probably caused by : memory_corruption
- Followup: memory_corruption
- PAGE_FAULT_IN_NONPAGED_AREA (50)
- Invalid system memory was referenced. This cannot be protected by try-except.
- Typically the address is just plain bad or it is pointing at freed memory.
- Arguments:
- Arg1: ffffeb832920ff42, memory referenced.
- Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
- Arg3: fffff80162d5b7ae, If non-zero, the instruction address which referenced the bad memory
- address.
- Arg4: 0000000000000002, (reserved)
- Debugging Details:
- ***** Kernel symbols are WRONG. Please fix symbols to do analysis.
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- ADDITIONAL_DEBUG_TEXT:
- You can run '.symfix; .reload' to try to fix the symbol path and load symbols.
- WRONG_SYMBOLS_TIMESTAMP: eadcd02b
- WRONG_SYMBOLS_SIZE: ab2000
- FAULTING_MODULE: fffff8015e600000 nt
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- DUMP_TYPE: 2
- READ_ADDRESS: *************************************************************************
- Unable to get size of nt!_MMPTE - probably bad symbols
- ffffeb832920ff42
- FAULTING_IP:
- Ntfs!NtfsCommonWrite+12be
- fffff801`62d5b7ae 498d5218 lea rdx,[r10+18h]
- MM_INTERNAL_CODE: 2
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- BUGCHECK_STR: AV
- CURRENT_IRQL: 0
- LAST_CONTROL_TRANSFER: from fffff8015e7dfd54 to fffff8015e7bc8a0
- STACK_TEXT:
- ffffeb83`9dd8e058 fffff801`5e7dfd54 : 00000000`00000050 ffffeb83`2920ff42 00000000`00000000 ffffeb83`9dd8e300 : nt+0x1bc8a0
- ffffeb83`9dd8e060 00000000`00000050 : ffffeb83`2920ff42 00000000`00000000 ffffeb83`9dd8e300 00000000`00000002 : nt+0x1dfd54
- ffffeb83`9dd8e068 ffffeb83`2920ff42 : 00000000`00000000 ffffeb83`9dd8e300 00000000`00000002 ffffca88`86949d1c : 0x50
- ffffeb83`9dd8e070 00000000`00000000 : ffffeb83`9dd8e300 00000000`00000002 ffffca88`86949d1c 00000000`00000000 : 0xffffeb83`2920ff42
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !win32kbase
- ffff83a09ae9613b-ffff83a09ae9613c 2 bytes - win32kbase!EngFreeUserMem+1b
- [ 48 ff:4c 8b ]
- ffff83a09ae96142-ffff83a09ae96145 4 bytes - win32kbase!EngFreeUserMem+22 (+0x07)
- [ 0f 1f 44 00:e8 d9 22 21 ]
- ffff83a09ae96178-ffff83a09ae96179 2 bytes - win32kbase!EngFreeUserMem+58 (+0x36)
- [ 48 ff:4c 8b ]
- ffff83a09ae9617f-ffff83a09ae96182 4 bytes - win32kbase!EngFreeUserMem+5f (+0x07)
- [ 0f 1f 44 00:e8 9c 22 21 ]
- ffff83a09ae96195-ffff83a09ae96196 2 bytes - win32kbase!EngFreeUserMem+75 (+0x16)
- [ 48 ff:4c 8b ]
- ffff83a09ae9619c-ffff83a09ae9619f 4 bytes - win32kbase!EngFreeUserMem+7c (+0x07)
- [ 0f 1f 44 00:e8 7f 22 21 ]
- ffff83a09ae961b3-ffff83a09ae961b4 2 bytes - win32kbase!EngFreeUserMem+93 (+0x17)
- [ 48 ff:4c 8b ]
- ffff83a09ae961ba-ffff83a09ae961bd 4 bytes - win32kbase!EngFreeUserMem+9a (+0x07)
- [ 0f 1f 44 00:e8 61 22 21 ]
- ffff83a09ae961cf - win32kbase!EngFreeUserMem+af (+0x15)
- [ 48:4c ]
- ffff83a09ae9cfb9-ffff83a09ae9cfbe 6 bytes - win32kbase!DirectComposition::CAnimationMarshaler::SetReferenceProperty+49 (+0x6dea)
- [ ff 15 e9 b7 19 00:e8 e2 b2 20 00 90 ]
- ffff83a09ae9d029-ffff83a09ae9d02a 2 bytes - win32kbase!SfmSignalTokenEvent+19 (+0x70)
- [ 48 ff:4c 8b ]
- ffff83a09ae9d030-ffff83a09ae9d033 4 bytes - win32kbase!SfmSignalTokenEvent+20 (+0x07)
- [ 0f 1f 44 00:e8 eb b3 20 ]
- ffff83a09ae9de15-ffff83a09ae9de16 2 bytes - win32kbase!GreSfmDwmShutdown+35 (+0xde5)
- [ 48 ff:4c 8b ]
- ffff83a09ae9de1c-ffff83a09ae9de1f 4 bytes - win32kbase!GreSfmDwmShutdown+3c (+0x07)
- [ 0f 1f 44 00:e8 ff a5 20 ]
- ffff83a09ae9de25-ffff83a09ae9de26 2 bytes - win32kbase!GreSfmDwmShutdown+45 (+0x09)
- [ 48 ff:4c 8b ]
- ffff83a09ae9de2c-ffff83a09ae9de2f 4 bytes - win32kbase!GreSfmDwmShutdown+4c (+0x07)
- [ 0f 1f 44 00:e8 ef a5 20 ]
- ffff83a09ae9de50-ffff83a09ae9de51 2 bytes - win32kbase!GreSfmDwmShutdown+70 (+0x24)
- [ 48 ff:4c 8b ]
- ffff83a09ae9de57-ffff83a09ae9de5a 4 bytes - win32kbase!GreSfmDwmShutdown+77 (+0x07)
- [ 0f 1f 44 00:e8 c4 a5 20 ]
- ffff83a09ae9de5c-ffff83a09ae9de5d 2 bytes - win32kbase!GreSfmDwmShutdown+7c (+0x05)
- [ 48 ff:4c 8b ]
- ffff83a09ae9de63-ffff83a09ae9de66 4 bytes - win32kbase!GreSfmDwmShutdown+83 (+0x07)
- [ 0f 1f 44 00:e8 b8 a5 20 ]
- 61 errors : !win32kbase (ffff83a09ae9613b-ffff83a09ae9de66)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2019-06-29T23:27:45.000Z
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ========================================================================
- ==================== Dump File: 062519-9046-01.dmp =====================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Invalid directory table base value 0x0
- Unable to load image Unknown_Module_00000000`00000000, Win32 error 0n2
- *** WARNING: Unable to verify timestamp for Unknown_Module_00000000`00000000
- Unable to add module at 00000000`00000000
- WARNING: .reload failed, module list may be incomplete
- Debugger can not determine kernel base address
- Windows 10 Kernel Version 18362 MP (16 procs) Free x64
- Kernel base = 0xfffff805`72600000 PsLoadedModuleList = 0xfffff805`72a43370
- Debug session time: Wed Jun 26 01:12:43.430 2019 (UTC - 4:00)
- System Uptime: 0 days 0:29:42.125
- Unable to load image Unknown_Module_00000000`00000000, Win32 error 0n2
- *** WARNING: Unable to verify timestamp for Unknown_Module_00000000`00000000
- Unable to add module at 00000000`00000000
- WARNING: .reload failed, module list may be incomplete
- Debugger can not determine kernel base address
- .Unable to load image Unknown_Module_00000000`00000000, Win32 error 0n2
- *** WARNING: Unable to verify timestamp for Unknown_Module_00000000`00000000
- Unable to add module at 00000000`00000000
- BugCheck D1, {500, e, 0, fffff80584799d70}
- ***** Debugger could not find nt in module list, module list might be corrupt, error 0x80070057.
- Probably caused by : Unknown_Image ( ANALYSIS_INCONCLUSIVE )
- Followup: MachineOwner
- DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
- An attempt was made to access a pageable (or completely invalid) address at an
- interrupt request level (IRQL) that is too high. This is usually
- caused by drivers using improper addresses.
- If kernel debugger is available get stack backtrace.
- Arguments:
- Arg1: 0000000000000500, memory referenced
- Arg2: 000000000000000e, IRQL
- Arg3: 0000000000000000, value 0 = read operation, 1 = write operation
- Arg4: fffff80584799d70, address which referenced memory
- Debugging Details:
- ***** Debugger could not find nt in module list, module list might be corrupt, error 0x80070057.
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- READ_ADDRESS: Unable to get size of nt!_MMPTE - probably bad symbols
- 0000000000000500
- CURRENT_IRQL: 0
- FAULTING_IP:
- +0
- fffff805`84799d70 ?? ???
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CORRUPT_MODULELIST_AV
- BUGCHECK_STR: AV
- LAST_CONTROL_TRANSFER: from fffff805727ce569 to fffff805727bc8a0
- STACK_TEXT:
- ffffd700`7a9b1348 fffff805`727ce569 : 00000000`0000000a 00000000`00000500 00000000`0000000e 00000000`00000000 : 0xfffff805`727bc8a0
- ffffd700`7a9b1350 00000000`0000000a : 00000000`00000500 00000000`0000000e 00000000`00000000 fffff805`84799d70 : 0xfffff805`727ce569
- ffffd700`7a9b1358 00000000`00000500 : 00000000`0000000e 00000000`00000000 fffff805`84799d70 ffffd700`7a9b1449 : 0xa
- ffffd700`7a9b1360 00000000`0000000e : 00000000`00000000 fffff805`84799d70 ffffd700`7a9b1449 00000000`00000000 : 0x500
- ffffd700`7a9b1368 00000000`00000000 : fffff805`84799d70 ffffd700`7a9b1449 00000000`00000000 00000000`00000000 : 0xe
- STACK_COMMAND: kb
- SYMBOL_NAME: ANALYSIS_INCONCLUSIVE
- FOLLOWUP_NAME: MachineOwner
- MODULE_NAME: Unknown_Module
- IMAGE_NAME: Unknown_Image
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- BUCKET_ID: CORRUPT_MODULELIST_AV
- PRIMARY_PROBLEM_CLASS: CORRUPT_MODULELIST
- FAILURE_BUCKET_ID: CORRUPT_MODULELIST_AV
- TARGET_TIME: 2019-06-26T05:12:43.000Z
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:corrupt_modulelist_av
- FAILURE_ID_HASH: {fc259191-ef0c-6215-476f-d32e5dcaf1b7}
- Followup: MachineOwner
Advertisement
Add Comment
Please, Sign In to add comment