Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ========================== AUTO DUMP ANALYZER ==========================
- Auto Dump Analyzer
- Version: 0.91
- Time to analyze file(s): 00 hours and 03 minutes and 18 seconds
- ================================ SYSTEM ================================
- MANUFACTURER: Micro-Star International Co., Ltd.
- PRODUCT_NAME: MS-7C37
- VERSION: 2.0
- ================================= BIOS =================================
- VENDOR: American Megatrends Inc.
- VERSION: 1407
- DATE: 04/02/2020
- VERSION: A.70
- DATE: 01/09/2020
- ============================= MOTHERBOARD ==============================
- MANUFACTURER: ASUSTeK COMPUTER INC.
- PRODUCT: PRIME X570-PRO
- VERSION: Rev X.0x
- MANUFACTURER: Micro-Star International Co., Ltd.
- PRODUCT: MPG X570 GAMING PLUS (MS-7C37)
- VERSION: 2.0
- ================================= RAM ==================================
- Size Speed Manufacturer Part No.
- -------------- -------------- ------------------- ----------------------
- 0MHz Unknown Unknown
- 16384MB 3600MHz G-Skill F4-3600C16-16GTZNC
- 0MHz Unknown Unknown
- 16384MB 3600MHz G-Skill F4-3600C16-16GTZNC
- ================================= CPU ==================================
- Processor Version: AMD Ryzen 7 3700X 8-Core Processor
- COUNT: 10
- MHZ: 3593
- VENDOR: AuthenticAMD
- FAMILY: 17
- MODEL: 71
- STEPPING: 0
- MHZ: 3600
- ================================== OS ==================================
- Product: WinNt, suite: TerminalServer SingleUserTS
- Built by: 18362.1.amd64fre.19h1_release.190318-1202
- BUILD_VERSION: 10.0.18362.778 (WinBuild.160101.0800)
- BUILD: 18362
- SERVICEPACK: 778
- PLATFORM_TYPE: x64
- NAME: Windows 10
- EDITION: Windows 10 WinNt TerminalServer SingleUserTS
- BUILD_TIMESTAMP: 2015-10-23 02:39:54
- BUILDDATESTAMP: 160101.0800
- BUILDLAB: WinBuild
- BUILDOSVER: 10.0.18362.778
- =============================== DEBUGGER ===============================
- Microsoft (R) Windows Debugger Version 10.0.14321.1024 AMD64
- Copyright (c) Microsoft Corporation. All rights reserved.
- =============================== COMMENTS ===============================
- * Information gathered from different dump files may be different. If
- Windows updates between two dump files, two or more OS versions may
- be shown above.
- * If the user updates the BIOS between dump files, two or more versions
- and dates may be shown above.
- * More RAM information can be found below in a full BIOS section.
- ========================================================================
- ======================= Dump #1: ANALYZE VERBOSE =======================
- ====================== File: 042420-10968-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 18362 MP (16 procs) Free x64
- Kernel base = 0xfffff802`5ec00000 PsLoadedModuleList = 0xfffff802`5f048150
- Debug session time: Fri Apr 24 13:36:53.844 2020 (UTC - 4:00)
- System Uptime: 0 days 0:04:12.502
- BugCheck 34, {51359, fffff009b870dac8, fffff009b870d310, fffff8026211a72d}
- *** WARNING: Unable to verify timestamp for win32k.sys
- *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
- Probably caused by : memory_corruption
- Followup: memory_corruption
- CACHE_MANAGER (34)
- See the comment for FAT_FILE_SYSTEM (0x23)
- Arguments:
- Arg1: 0000000000051359
- Arg2: fffff009b870dac8
- Arg3: fffff009b870d310
- Arg4: fffff8026211a72d
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- EXCEPTION_RECORD: fffff009b870dac8 -- (.exr 0xfffff009b870dac8)
- ExceptionAddress: fffff8026211a72d (Ntfs!TxfProcessCancelList+0x0000000000000085)
- ExceptionCode: c0000005 (Access violation)
- ExceptionFlags: 00000000
- NumberParameters: 2
- Parameter[0]: 0000000000000000
- Parameter[1]: 000000001bc400d0
- Attempt to read from address 000000001bc400d0
- CONTEXT: fffff009b870d310 -- (.cxr 0xfffff009b870d310)
- rax=000000001bc40000 rbx=ffffb60e970cba18 rcx=ffffb60e970cba18
- rdx=0000000000000000 rsi=fffff009b870dd50 rdi=ffffb60e8955dd30
- rip=fffff8026211a72d rsp=fffff009b870dd00 rbp=fffff009b870ddb9
- r8=0000000000000010 r9=0000000000017a00 r10=000000000000000e
- r11=0000000000000000 r12=0000000000000000 r13=00000000fffffbff
- r14=ffffb60e970cba00 r15=ffffb60e937bd368
- iopl=0 nv up ei ng nz na po nc
- cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050286
- Ntfs!TxfProcessCancelList+0x85:
- fffff802`6211a72d 4c8bb8d0000000 mov r15,qword ptr [rax+0D0h] ds:002b:00000000`1bc400d0=????????????????
- Resetting default scope
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- PROCESS_NAME: System
- CURRENT_IRQL: 0
- ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.
- EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.
- EXCEPTION_CODE_STR: c0000005
- EXCEPTION_PARAMETER1: 0000000000000000
- EXCEPTION_PARAMETER2: 000000001bc400d0
- FOLLOWUP_IP:
- Ntfs!TxfProcessCancelList+85
- fffff802`6211a72d 4c8bb8d0000000 mov r15,qword ptr [rax+0D0h]
- FAULTING_IP:
- Ntfs!TxfProcessCancelList+85
- fffff802`6211a72d 4c8bb8d0000000 mov r15,qword ptr [rax+0D0h]
- READ_ADDRESS: fffff8025f1733b8: Unable to get MiVisibleState
- 000000001bc400d0
- BUGCHECK_STR: 0x34
- LAST_CONTROL_TRANSFER: from fffff80262149426 to fffff8026211a72d
- STACK_TEXT:
- fffff009`b870dd00 fffff802`62149426 : ffffb60e`970cba18 ffffb60e`970cba18 ffffb60e`937bd010 00000000`00000001 : Ntfs!TxfProcessCancelList+0x85
- fffff009`b870de20 fffff802`6211f69c : 00000000`00000000 00000000`00004000 7fffffff`ffffffff 00000000`00004000 : Ntfs!NtfsExtendedCompleteRequestInternal+0x1fe96
- fffff009`b870de90 fffff802`6211c438 : ffffb60e`970cba18 00000000`00000000 fffff009`b870e118 00000000`00000000 : Ntfs!NtfsCommonWrite+0x2fbc
- fffff009`b870e0c0 fffff802`5ed0a929 : ffffb60e`961855a0 ffffb60e`937bd010 ffffb60e`937bd3b0 ffffb60e`89685da0 : Ntfs!NtfsFsdWrite+0x1e8
- fffff009`b870e190 fffff802`616e55de : 00000000`00000000 fffff009`b870e270 ffffb60e`937bd010 fffff009`b870e280 : nt!IofCallDriver+0x59
- fffff009`b870e1d0 fffff802`616e3f16 : fffff009`b870e270 00000000`0000000f 00000000`00000001 00000000`00000000 : FLTMGR!FltpLegacyProcessingAfterPreCallbacksCompleted+0x15e
- fffff009`b870e250 fffff802`5ed0a929 : ffffb60e`937bd010 fffff802`5ed0a967 00000000`0000000c 00000000`00000004 : FLTMGR!FltpDispatch+0xb6
- fffff009`b870e2b0 fffff802`5ec21ac3 : fffff009`b870e4e0 ffffb60e`937bd010 ffffb60e`9a29a7b0 ffffb60e`89685da0 : nt!IofCallDriver+0x59
- fffff009`b870e2f0 fffff802`5ec57e64 : 00000000`00000000 fffff009`b870e390 ffffb60e`9a29a7b0 ffffb60e`9a29a7b0 : nt!IoSynchronousPageWriteEx+0x137
- fffff009`b870e330 fffff802`5ecec418 : 00000000`00000011 ffffd60b`b829c010 00000000`00000000 ffffcb00`0b16bdf0 : nt!MiIssueSynchronousFlush+0x70
- fffff009`b870e3b0 fffff802`5ec8fb97 : fffff009`b870ea90 ffffb60e`9a2758a8 00000000`00000000 00000000`00000000 : nt!MiFlushSectionInternal+0x868
- fffff009`b870e680 fffff802`5ec8dfdb : 00000000`00000000 ffffb60e`91d4e040 00000000`00001000 00000000`00000000 : nt!MmFlushSection+0xcf
- fffff009`b870e730 fffff802`5ec24309 : ffffb60e`9a2758a8 00000000`00000000 ffffb60e`00000001 00000000`00000000 : nt!CcFlushCachePriv+0x45b
- fffff009`b870e880 fffff802`5ec24cc1 : ffffb60e`86691900 00000000`00000000 ffffb60e`86691ab0 fffff009`b870ea90 : nt!CcWriteBehindInternal+0x209
- fffff009`b870e960 fffff802`5ec25014 : 00000000`00000000 ffffb60e`866919b0 ffffb60e`9203f980 fffff802`6204185c : nt!CcWriteBehind+0x8d
- fffff009`b870ea50 fffff802`5ecf43b5 : ffffb60e`86685a20 ffffb60e`91d4e040 ffffb60e`86685a20 ffffb60e`86685a20 : nt!CcWorkerThread+0x244
- fffff009`b870eb70 fffff802`5ec6bcd5 : ffffb60e`91d4e040 00000000`00000080 ffffb60e`86679300 00000067`b4bbbdff : nt!ExpWorkerThread+0x105
- fffff009`b870ec10 fffff802`5edc9998 : ffffa580`18364180 ffffb60e`91d4e040 fffff802`5ec6bc80 00000000`00000000 : nt!PspSystemThreadStartup+0x55
- fffff009`b870ec60 00000000`00000000 : fffff009`b870f000 fffff009`b8709000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !hal
- fffff8025eb5d956-fffff8025eb5d95b 6 bytes - hal!KeQueryPerformanceCounter+e6
- [ ff 15 b4 7f 07 00:e8 45 69 3f 00 90 ]
- fffff8025eb5dd03 - hal!HalpApicRequestInterrupt+a3 (+0x3ad)
- [ 00:90 ]
- fffff8025eb5dd71-fffff8025eb5dd76 6 bytes - hal!HalpApicRequestInterrupt+111 (+0x6e)
- [ ff 15 99 7b 07 00:e8 2a 65 3f 00 90 ]
- fffff8025eb5e53b-fffff8025eb5e53c 2 bytes - hal!HalRequestIpi+31b (+0x7ca)
- [ 48 ff:4c 8b ]
- fffff8025eb5e542-fffff8025eb5e545 4 bytes - hal!HalRequestIpi+322 (+0x07)
- [ 0f 1f 44 00:e8 39 db 0c ]
- fffff8025eb5e58e-fffff8025eb5e58f 2 bytes - hal!HalRequestIpi+36e (+0x4c)
- [ 48 ff:4c 8b ]
- fffff8025eb5e595-fffff8025eb5e598 4 bytes - hal!HalRequestIpi+375 (+0x07)
- [ 0f 1f 44 00:e8 16 e6 0c ]
- fffff8025eb5e5a7-fffff8025eb5e5a8 2 bytes - hal!HalRequestIpi+387 (+0x12)
- [ 48 ff:4c 8b ]
- fffff8025eb5e5ae-fffff8025eb5e5b1 4 bytes - hal!HalRequestIpi+38e (+0x07)
- [ 0f 1f 44 00:e8 0d 08 14 ]
- fffff8025eb5e5e1-fffff8025eb5e5e2 2 bytes - hal!HalRequestIpi+3c1 (+0x33)
- [ 48 ff:4c 8b ]
- fffff8025eb5e5e8-fffff8025eb5e5eb 4 bytes - hal!HalRequestIpi+3c8 (+0x07)
- [ 0f 1f 44 00:e8 d3 07 14 ]
- fffff8025eb5f285-fffff8025eb5f286 2 bytes - hal!HalpTimerClockIpiRoutine+15 (+0xc9d)
- [ 48 ff:4c 8b ]
- fffff8025eb5f28c-fffff8025eb5f28f 4 bytes - hal!HalpTimerClockIpiRoutine+1c (+0x07)
- [ 0f 1f 44 00:e8 0f 92 15 ]
- fffff8025eb5f2e7-fffff8025eb5f2ec 6 bytes - hal!HalpTimerClockIpiRoutine+77 (+0x5b)
- [ ff 15 23 66 07 00:e8 b4 4f 3f 00 90 ]
- 49 errors : !hal (fffff8025eb5d956-fffff8025eb5f2ec)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- STACK_COMMAND: .cxr 0xfffff009b870d310 ; kb
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-04-24T17:36:53.000Z
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #1: 3RD PARTY DRIVERS ======================
- May 01 2013 - WinRing0x64.sys - Intel Processor Diagnostic Tool or BatteryCare by OpenLibSys.org or Throttlestop (Properties say: OpenLibSys.org) or EVGA Precision X https://www.evga.com/
- Jun 11 2018 - e1i65x64.sys - Intel(R) Gigabit Adapter driver
- Mar 14 2019 - nvvad64v.sys - Nvidia Virtual Audio driver http://www.nvidia.com/
- Apr 09 2019 - AsIO2.sys - Asus Input Output driver
- Apr 11 2019 - CorsairVBusDriver.sys - Corsair Virtual Device driver (Corsair Utility Engine) http://www.corsair.com/
- Apr 11 2019 - CorsairVHidDriver.sys - Corsair Virtual Device driver (Corsair Utility Engine) http://www.corsair.com/
- Apr 22 2019 - GLCKIO2.sys - ASUS RGB driver
- May 14 2019 - sshid.sys - SteelSeries Engine HID driver https://steelseries.com/
- Jul 24 2019 - AMDPCIDev.sys - Advanced Micro Devices PCI Device driver
- Sep 29 2019 - amdgpio2.sys - AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Dec 05 2019 - cpuz149_x64.sys - CPUID driver
- Dec 16 2019 - AMDRyzenMasterDriver.sys - AMD Ryzen Master driver
- Jan 10 2020 - nvvhci.sys - Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Feb 14 2020 - CorsairLLAccess64.sys - CORSAIR iCUE Software driver
- Feb 19 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- Mar 12 2020 - nvrtxvad64v.sys -
- Apr 03 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- ================== Dump #1: 3RD PARTY DRIVERS (FULL) ===================
- Image path: \??\C:\Program Files (x86)\EVGA\LED Sync\WinRing0\WinRing0x64.sys
- Image name: WinRing0x64.sys
- Search : https://www.google.com/search?q=WinRing0x64.sys
- ADA Info : Intel Processor Diagnostic Tool or BatteryCare by OpenLibSys.org or Throttlestop (Properties say: OpenLibSys.org) or EVGA Precision X https://www.evga.com/
- Timestamp : Wed May 1 2013
- Mapped memory image file: C:\ProgramData\dbg\sym\e1i65x64.sys\5B1EB8E28e000\e1i65x64.sys
- Image path: \SystemRoot\System32\drivers\e1i65x64.sys
- Image name: e1i65x64.sys
- Search : https://www.google.com/search?q=e1i65x64.sys
- ADA Info : Intel(R) Gigabit Adapter driver
- Timestamp : Mon Jun 11 2018
- File version: 12.17.10.8
- Product version: 10.0.10011.16384
- File flags: 8 (Mask 3F) Private
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- CompanyName: Intel Corporation
- ProductName: Intel(R) Gigabit Adapter
- InternalName: e1i65x64.sys
- OriginalFilename: e1i65x64.sys
- ProductVersion: 12.17.10.8
- FileVersion: 12.17.10.8
- FileDescription: Intel(R) Gigabit Adapter NDIS 6.x driver
- LegalCopyright: Copyright(C) 2013, Intel Corporation. All rights reserved.
- Image path: \SystemRoot\system32\drivers\nvvad64v.sys
- Image name: nvvad64v.sys
- Search : https://www.google.com/search?q=nvvad64v.sys
- ADA Info : Nvidia Virtual Audio driver http://www.nvidia.com/
- Timestamp : Thu Mar 14 2019
- Image path: \??\C:\WINDOWS\system32\drivers\AsIO2.sys
- Image name: AsIO2.sys
- Search : https://www.google.com/search?q=AsIO2.sys
- ADA Info : Asus Input Output driver
- Timestamp : Tue Apr 9 2019
- Image path: \SystemRoot\System32\drivers\CorsairVBusDriver.sys
- Image name: CorsairVBusDriver.sys
- Search : https://www.google.com/search?q=CorsairVBusDriver.sys
- ADA Info : Corsair Virtual Device driver (Corsair Utility Engine) http://www.corsair.com/
- Timestamp : Thu Apr 11 2019
- Image path: \SystemRoot\System32\drivers\CorsairVHidDriver.sys
- Image name: CorsairVHidDriver.sys
- Search : https://www.google.com/search?q=CorsairVHidDriver.sys
- ADA Info : Corsair Virtual Device driver (Corsair Utility Engine) http://www.corsair.com/
- Timestamp : Thu Apr 11 2019
- Image path: \??\C:\WINDOWS\system32\drivers\GLCKIO2.sys
- Image name: GLCKIO2.sys
- Search : https://www.google.com/search?q=GLCKIO2.sys
- ADA Info : ASUS RGB driver
- Timestamp : Mon Apr 22 2019
- Image path: \SystemRoot\System32\drivers\sshid.sys
- Image name: sshid.sys
- Search : https://www.google.com/search?q=sshid.sys
- ADA Info : SteelSeries Engine HID driver https://steelseries.com/
- Timestamp : Tue May 14 2019
- Image path: \SystemRoot\System32\drivers\AMDPCIDev.sys
- Image name: AMDPCIDev.sys
- Search : https://www.google.com/search?q=AMDPCIDev.sys
- ADA Info : Advanced Micro Devices PCI Device driver
- Timestamp : Wed Jul 24 2019
- Image path: \SystemRoot\System32\drivers\amdgpio2.sys
- Image name: amdgpio2.sys
- Search : https://www.google.com/search?q=amdgpio2.sys
- ADA Info : AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Timestamp : Sun Sep 29 2019
- Image path: \??\C:\WINDOWS\temp\cpuz149\cpuz149_x64.sys
- Image name: cpuz149_x64.sys
- Search : https://www.google.com/search?q=cpuz149_x64.sys
- ADA Info : CPUID driver
- Timestamp : Thu Dec 5 2019
- Image path: \??\C:\Program Files\AMD\RyzenMaster\bin\AMDRyzenMasterDriver.sys
- Image name: AMDRyzenMasterDriver.sys
- Search : https://www.google.com/search?q=AMDRyzenMasterDriver.sys
- ADA Info : AMD Ryzen Master driver
- Timestamp : Mon Dec 16 2019
- Image path: \SystemRoot\System32\drivers\nvvhci.sys
- Image name: nvvhci.sys
- Search : https://www.google.com/search?q=nvvhci.sys
- ADA Info : Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Timestamp : Fri Jan 10 2020
- Image path: \??\C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\CorsairLLAccess64.sys
- Image name: CorsairLLAccess64.sys
- Search : https://www.google.com/search?q=CorsairLLAccess64.sys
- ADA Info : CORSAIR iCUE Software driver
- Timestamp : Fri Feb 14 2020
- Image path: \SystemRoot\system32\drivers\nvhda64v.sys
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Wed Feb 19 2020
- Image path: \SystemRoot\system32\drivers\nvrtxvad64v.sys
- Image name: nvrtxvad64v.sys
- Search : https://www.google.com/search?q=nvrtxvad64v.sys
- Timestamp : Thu Mar 12 2020
- Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_95bdb3a23d6478de\nvlddmkm.sys
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Fri Apr 3 2020
- ====================== Dump #1: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- amdppm.sys Processor Device Driver
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- csc.sys Windows Client Side Caching driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HdAudio.sys High Definition Audio Function driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kd.dll Local Kernal Debugger (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate_AuthenticAMD.dll AMD Microcode Update Library (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msgpioclx.sys GPIO Class Extension Driver (Microsoft)
- mshidkmdf.sys Pass-through HID to KMDF Filter driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- qwavedrv.sys Quality Windows Audio Video Experience (qWave) Support driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- serenum.sys Serial Port Enumerator (Microsoft)
- serial.sys Serial Device Driver
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- ucx01000.sys USB Controller Extension (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- winquic.sys QUIC Transport Protocol driver (Microsoft)
- WinUSB.SYS Windows WinUSB Class driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- ====================== Dump #1: UNLOADED MODULES =======================
- fffff802`6b320000 fffff802`6b32f000 dump_storpor
- fffff802`6b360000 fffff802`6b38f000 dump_storahc
- fffff802`6b3b0000 fffff802`6b3ce000 dump_dumpfve
- fffff802`6bd40000 fffff802`6bd5e000 dam.sys
- fffff802`61bd0000 fffff802`61be1000 WdBoot.sys
- fffff802`62bc0000 fffff802`62bd1000 hwpolicy.sys
- ====================== Dump #1: BIOS INFORMATION =======================
- [SMBIOS Data Tables v3.2]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 3181 bytes]
- [BIOS Information (Type 0) - Length 26 - Handle 0000h]
- Vendor American Megatrends Inc.
- BIOS Version 1407
- BIOS Starting Address Segment f000
- BIOS Release Date 04/02/2020
- BIOS ROM Size 1000000
- BIOS Characteristics
- 07: - PCI Supported
- 10: - APM Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 27: - Keyboard Services Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 32: - BIOS Vendor Reserved
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 5
- BIOS Minor Revision 14
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- Manufacturer System manufacturer
- Product Name System Product Name
- Version System Version
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- SKUNumber SKU
- [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
- Manufacturer ASUSTeK COMPUTER INC.
- Product PRIME X570-PRO
- Version Rev X.0x
- Feature Flags 09h
- -376588576: - -376588528: - ÷7£ý
- Location Default string
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 22 - Handle 0003h]
- Manufacturer Default string
- Chassis Type Desktop
- Version Default string
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 3
- [Onboard Devices Information (Type 10) - Length 6 - Handle 002dh]
- Number of Devices 1
- 01: Type Video [enabled]
- [OEM Strings (Type 11) - Length 5 - Handle 002eh]
- Number of Strings 8
- 1 Default string
- 2 Default string
- 3 MIAMI
- 4 Default string
- 5 FFFFFFFFFFFFF
- 6 FFFFFFFFFFFFF
- 7 FFFFFFFFFFFFF
- 8 Default string
- [System Configuration Options (Type 12) - Length 5 - Handle 002fh]
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 0034h]
- [Physical Memory Array (Type 16) - Length 23 - Handle 0035h]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 134217728KB
- Memory Error Inf Handle 0034h
- Number of Memory Devices 4
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0036h]
- Starting Address 00000000h
- Ending Address 0037ffffh
- Memory Array Handle 0035h
- Partition Width 02
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0037h]
- Starting Address 00400000h
- Ending Address 0207ffffh
- Memory Array Handle 0035h
- Partition Width 02
- [Cache Information (Type 7) - Length 27 - Handle 0038h]
- Socket Designation L1 - Cache
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0200h - 512K
- Installed Size 0200h - 512K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 27 - Handle 0039h]
- Socket Designation L2 - Cache
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 1000h - 4096K
- Installed Size 1000h - 4096K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 27 - Handle 003ah]
- Socket Designation L3 - Cache
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 8200h - 32768K
- Installed Size 8200h - 32768K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 16-way Set-Associative
- [Processor Information (Type 4) - Length 48 - Handle 003bh]
- Socket Designation AM4
- Processor Type Central Processor
- Processor Family 6bh - Specification Reserved
- Processor Manufacturer Advanced Micro Devices, Inc.
- Processor ID 100f8700fffb8b17
- Processor Version AMD Ryzen 7 3700X 8-Core Processor
- Processor Voltage 8bh - 1.1V
- External Clock 100MHz
- Max Speed 4400MHz
- Current Speed 3600MHz
- Status Enabled Populated
- Processor Upgrade Specification Reserved
- L1 Cache Handle 0038h
- L2 Cache Handle 0039h
- L3 Cache Handle 003ah
- Part Number Unknown
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 003ch]
- [Memory Device (Type 17) - Length 84 - Handle 003dh]
- Physical Memory Array Handle 0035h
- Memory Error Info Handle 003ch
- Form Factor 02h - Unknown
- Device Locator DIMM_A1
- Bank Locator BANK 0
- Memory Type 02h - Unknown
- Type Detail 0004h - Unknown
- Speed 0MHz
- Manufacturer Unknown
- Part Number Unknown
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 003eh]
- [Memory Device (Type 17) - Length 84 - Handle 003fh]
- Physical Memory Array Handle 0035h
- Memory Error Info Handle 003eh
- Total Width 64 bits
- Data Width 64 bits
- Size 16384MB
- Form Factor 09h - DIMM
- Device Locator DIMM_A2
- Bank Locator BANK 1
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 3600MHz
- Manufacturer G-Skill
- Part Number F4-3600C16-16GTZNC
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0040h]
- Starting Address 00000000h
- Ending Address 01ffffffh
- Memory Device Handle 003fh
- Mem Array Mapped Adr Handle 0037h
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 0041h]
- [Memory Device (Type 17) - Length 84 - Handle 0042h]
- Physical Memory Array Handle 0035h
- Memory Error Info Handle 0041h
- Form Factor 02h - Unknown
- Device Locator DIMM_B1
- Bank Locator BANK 2
- Memory Type 02h - Unknown
- Type Detail 0004h - Unknown
- Speed 0MHz
- Manufacturer Unknown
- Part Number Unknown
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 0043h]
- [Memory Device (Type 17) - Length 84 - Handle 0044h]
- Physical Memory Array Handle 0035h
- Memory Error Info Handle 0043h
- Total Width 64 bits
- Data Width 64 bits
- Size 16384MB
- Form Factor 09h - DIMM
- Device Locator DIMM_B2
- Bank Locator BANK 3
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 3600MHz
- Manufacturer G-Skill
- Part Number F4-3600C16-16GTZNC
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0045h]
- Starting Address 00000000h
- Ending Address 01ffffffh
- Memory Device Handle 0044h
- Mem Array Mapped Adr Handle 0037h
- ========================== Dump #1: Extra #1 ===========================
- 14: kd> !verifier
- Verify Flags Level 0x00000000
- STANDARD FLAGS:
- [X] (0x00000000) Automatic Checks
- [ ] (0x00000001) Special pool
- [ ] (0x00000002) Force IRQL checking
- [ ] (0x00000008) Pool tracking
- [ ] (0x00000010) I/O verification
- [ ] (0x00000020) Deadlock detection
- [ ] (0x00000080) DMA checking
- [ ] (0x00000100) Security checks
- [ ] (0x00000800) Miscellaneous checks
- [ ] (0x00020000) DDI compliance checking
- ADDITIONAL FLAGS:
- [ ] (0x00000004) Randomized low resources simulation
- [ ] (0x00000200) Force pending I/O requests
- [ ] (0x00000400) IRP logging
- [ ] (0x00002000) Invariant MDL checking for stack
- [ ] (0x00004000) Invariant MDL checking for driver
- [ ] (0x00008000) Power framework delay fuzzing
- [ ] (0x00010000) Port/miniport interface checking
- [ ] (0x00040000) Systematic low resources simulation
- [ ] (0x00080000) DDI compliance checking (additional)
- [ ] (0x00200000) NDIS/WIFI verification
- [ ] (0x00800000) Kernel synchronization delay fuzzing
- [ ] (0x01000000) VM switch verification
- [ ] (0x02000000) Code integrity checks
- [X] Indicates flag is enabled
- Summary of All Verifier Statistics
- RaiseIrqls 0x0
- AcquireSpinLocks 0x0
- Synch Executions 0x0
- Trims 0x0
- Pool Allocations Attempted 0x0
- Pool Allocations Succeeded 0x0
- Pool Allocations Succeeded SpecialPool 0x0
- Pool Allocations With NO TAG 0x0
- Pool Allocations Failed 0x0
- Current paged pool allocations 0x0 for 00000000 bytes
- Peak paged pool allocations 0x0 for 00000000 bytes
- Current nonpaged pool allocations 0x0 for 00000000 bytes
- Peak nonpaged pool allocations 0x0 for 00000000 bytes
- ========================== Dump #1: Extra #2 ===========================
- 14: kd> !thread
- THREAD ffffb60e91d4e040 Cid 0004.1d8c Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor e
- IRP List:
- ffffb60e937bd010: (0006,0430) Flags: 00060043 Mdl: fffff009b870e4e0
- Not impersonating
- GetUlongFromAddress: unable to read from fffff8025f02ca14
- Owning Process ffffb60e86679300 Image: System
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 16160
- Context Switch Count 13055 IdealProcessor: 8
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address nt!ExpWorkerThread (0xfffff8025ecf42b0)
- Stack Init fffff009b870ec90 Current fffff009b870d860
- Base fffff009b870f000 Limit fffff009b8709000 Call 0000000000000000
- Priority 14 BasePriority 13 PriorityDecrement 0 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- fffff009`b870ca78 fffff802`5edda042 : 00000000`00000034 00000000`00051359 fffff009`b870dac8 fffff009`b870d310 : nt!KeBugCheckEx
- fffff009`b870ca80 fffff802`5ed9d37c : 00000000`00000003 fffff802`5efb04d8 fffff009`b8709000 fffff009`b870f000 : nt!CcWorkerThread$filt$0+0x42
- fffff009`b870cac0 fffff802`5edbe5e2 : fffff802`5efb04d8 fffff009`b870dac8 fffff009`b870ea50 00000000`00000000 : nt!_C_specific_handler+0xac
- fffff009`b870cb30 fffff802`5edcb182 : fffff009`b870ea50 fffff009`b870d0d0 00000000`00000000 00000000`00000000 : nt!_GSHandlerCheck_SEH+0x6a
- fffff009`b870cb60 fffff802`5ecfa2c5 : 00000000`0000008d 00000000`00000000 fffff009`b870d0d0 00007fff`ffff0000 : nt!RtlpExecuteHandlerForException+0x12
- fffff009`b870cb90 fffff802`5ecfe85e : fffff009`b870dac8 fffff009`b870d810 fffff009`b870dac8 ffffb60e`8955dd30 : nt!RtlDispatchException+0x4a5
- fffff009`b870d2e0 fffff802`5edd431d : fffff009`b870d9a0 00000000`00000018 ffff8000`00000000 00000000`1bc400d0 : nt!KiDispatchException+0x16e
- fffff009`b870d990 fffff802`5edd0503 : 00000000`00000000 ffffb60e`91d4e040 00000000`00000000 fffff802`5ed0f42a : nt!KiExceptionDispatch+0x11d
- fffff009`b870db70 fffff802`6211a72d : 00000000`00000000 ffffb60e`86691a30 00000000`00000001 00000000`00000000 : nt!KiPageFault+0x443 (TrapFrame @ fffff009`b870db70)
- fffff009`b870dd00 fffff802`62149426 : ffffb60e`970cba18 ffffb60e`970cba18 ffffb60e`937bd010 00000000`00000001 : Ntfs!TxfProcessCancelList+0x85
- fffff009`b870de20 fffff802`6211f69c : 00000000`00000000 00000000`00004000 7fffffff`ffffffff 00000000`00004000 : Ntfs!NtfsExtendedCompleteRequestInternal+0x1fe96
- fffff009`b870de90 fffff802`6211c438 : ffffb60e`970cba18 00000000`00000000 fffff009`b870e118 00000000`00000000 : Ntfs!NtfsCommonWrite+0x2fbc
- fffff009`b870e0c0 fffff802`5ed0a929 : ffffb60e`961855a0 ffffb60e`937bd010 ffffb60e`937bd3b0 ffffb60e`89685da0 : Ntfs!NtfsFsdWrite+0x1e8
- fffff009`b870e190 fffff802`616e55de : 00000000`00000000 fffff009`b870e270 ffffb60e`937bd010 fffff009`b870e280 : nt!IofCallDriver+0x59
- fffff009`b870e1d0 fffff802`616e3f16 : fffff009`b870e270 00000000`0000000f 00000000`00000001 00000000`00000000 : FLTMGR!FltpLegacyProcessingAfterPreCallbacksCompleted+0x15e
- fffff009`b870e250 fffff802`5ed0a929 : ffffb60e`937bd010 fffff802`5ed0a967 00000000`0000000c 00000000`00000004 : FLTMGR!FltpDispatch+0xb6
- fffff009`b870e2b0 fffff802`5ec21ac3 : fffff009`b870e4e0 ffffb60e`937bd010 ffffb60e`9a29a7b0 ffffb60e`89685da0 : nt!IofCallDriver+0x59
- fffff009`b870e2f0 fffff802`5ec57e64 : 00000000`00000000 fffff009`b870e390 ffffb60e`9a29a7b0 ffffb60e`9a29a7b0 : nt!IoSynchronousPageWriteEx+0x137
- fffff009`b870e330 fffff802`5ecec418 : 00000000`00000011 ffffd60b`b829c010 00000000`00000000 ffffcb00`0b16bdf0 : nt!MiIssueSynchronousFlush+0x70
- fffff009`b870e3b0 fffff802`5ec8fb97 : fffff009`b870ea90 ffffb60e`9a2758a8 00000000`00000000 00000000`00000000 : nt!MiFlushSectionInternal+0x868
- fffff009`b870e680 fffff802`5ec8dfdb : 00000000`00000000 ffffb60e`91d4e040 00000000`00001000 00000000`00000000 : nt!MmFlushSection+0xcf
- fffff009`b870e730 fffff802`5ec24309 : ffffb60e`9a2758a8 00000000`00000000 ffffb60e`00000001 00000000`00000000 : nt!CcFlushCachePriv+0x45b
- fffff009`b870e880 fffff802`5ec24cc1 : ffffb60e`86691900 00000000`00000000 ffffb60e`86691ab0 fffff009`b870ea90 : nt!CcWriteBehindInternal+0x209
- fffff009`b870e960 fffff802`5ec25014 : 00000000`00000000 ffffb60e`866919b0 ffffb60e`9203f980 fffff802`6204185c : nt!CcWriteBehind+0x8d
- fffff009`b870ea50 fffff802`5ecf43b5 : ffffb60e`86685a20 ffffb60e`91d4e040 ffffb60e`86685a20 ffffb60e`86685a20 : nt!CcWorkerThread+0x244
- fffff009`b870eb70 fffff802`5ec6bcd5 : ffffb60e`91d4e040 00000000`00000080 ffffb60e`86679300 00000067`b4bbbdff : nt!ExpWorkerThread+0x105
- fffff009`b870ec10 fffff802`5edc9998 : ffffa580`18364180 ffffb60e`91d4e040 fffff802`5ec6bc80 00000000`00000000 : nt!PspSystemThreadStartup+0x55
- fffff009`b870ec60 00000000`00000000 : fffff009`b870f000 fffff009`b8709000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
- ========================================================================
- ======================= Dump #2: ANALYZE VERBOSE =======================
- ====================== File: 042420-10906-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 18362 MP (16 procs) Free x64
- Kernel base = 0xfffff807`33e00000 PsLoadedModuleList = 0xfffff807`34248150
- Debug session time: Fri Apr 24 13:31:47.411 2020 (UTC - 4:00)
- System Uptime: 0 days 10:27:26.069
- BugCheck A, {ffff854ee2d410c8, 2, 0, fffff80733ecfd34}
- Probably caused by : memory_corruption
- Followup: memory_corruption
- IRQL_NOT_LESS_OR_EQUAL (a)
- An attempt was made to access a pageable (or completely invalid) address at an
- interrupt request level (IRQL) that is too high. This is usually
- caused by drivers using improper addresses.
- If a kernel debugger is available get the stack backtrace.
- Arguments:
- Arg1: ffff854ee2d410c8, memory referenced
- Arg2: 0000000000000002, IRQL
- Arg3: 0000000000000000, bitfield :
- bit 0 : value 0 = read operation, 1 = write operation
- bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
- Arg4: fffff80733ecfd34, address which referenced memory
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- READ_ADDRESS: fffff807343733b8: Unable to get MiVisibleState
- ffff854ee2d410c8
- CURRENT_IRQL: 2
- FAULTING_IP:
- nt!MiResolveProtoPteFault+c4
- fffff807`33ecfd34 4c8b0b mov r9,qword ptr [rbx]
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- BUGCHECK_STR: AV
- PROCESS_NAME: ModernWarfare.exe
- TRAP_FRAME: ffffcc0ff9348580 -- (.trap 0xffffcc0ff9348580)
- NOTE: The trap frame does not contain all registers.
- Some register values may be zeroed or incorrect.
- rax=ffff850000000000 rbx=0000000000000000 rcx=ffffcc0ff9348880
- rdx=ffffcc0ff9348b00 rsi=0000000000000000 rdi=0000000000000000
- rip=fffff80733ecfd34 rsp=ffffcc0ff9348710 rbp=ffffcc0ff9348910
- r8=ffff9dc5a821992e r9=0000007ffffffff8 r10=ffff850000000000
- r11=ffffcc0ff9348b00 r12=0000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=0000000000000000
- iopl=0 nv up ei ng nz na pe nc
- nt!MiResolveProtoPteFault+0xc4:
- fffff807`33ecfd34 4c8b0b mov r9,qword ptr [rbx] ds:00000000`00000000=????????????????
- Resetting default scope
- LAST_CONTROL_TRANSFER: from fffff80733fd41e9 to fffff80733fc2390
- STACK_TEXT:
- ffffcc0f`f9348438 fffff807`33fd41e9 : 00000000`0000000a ffff854e`e2d410c8 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
- ffffcc0f`f9348440 fffff807`33fd0529 : 00000000`00000000 00000000`00000002 00000000`00000000 ffffcc0f`f9348730 : nt!KiBugCheckDispatch+0x69
- ffffcc0f`f9348580 fffff807`33ecfd34 : 00000000`00000000 fffff807`33ecb738 ffffe100`5a5c7180 fffff807`00000000 : nt!KiPageFault+0x469
- ffffcc0f`f9348710 fffff807`33ecae8c : ffffcc0f`f9348880 00000000`00000000 ffffcc0f`f9348858 fffff807`33ec9f84 : nt!MiResolveProtoPteFault+0xc4
- ffffcc0f`f9348810 fffff807`33ec8fc9 : ffffe100`5a521180 00000000`00000100 00000000`c0000016 ffffcc0f`00000000 : nt!MiDispatchFault+0x80c
- ffffcc0f`f9348960 fffff807`33fd041e : 000001ea`58a108b8 ffffcc0f`f9348b80 000001e8`0dfce744 ffff940a`1587ca60 : nt!MmAccessFault+0x169
- ffffcc0f`f9348b00 00007fff`d87bb171 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x35e
- 0000007c`936fe2b0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007fff`d87bb171
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !win32kbase
- ffffb60ae1647839-ffffb60ae164783e 6 bytes - win32kbase!DirectComposition::CAnimationMarshaler::SetReferenceProperty+49
- [ ff 15 71 ef 19 00:e8 62 ea 20 00 90 ]
- ffffb60ae16478a9-ffffb60ae16478aa 2 bytes - win32kbase!SfmSignalTokenEvent+19 (+0x70)
- [ 48 ff:4c 8b ]
- ffffb60ae16478b0-ffffb60ae16478b3 4 bytes - win32kbase!SfmSignalTokenEvent+20 (+0x07)
- [ 0f 1f 44 00:e8 6b eb 20 ]
- ffffb60ae16489b5-ffffb60ae16489b6 2 bytes - win32kbase!GreSfmDwmShutdown+35 (+0x1105)
- [ 48 ff:4c 8b ]
- ffffb60ae16489bc-ffffb60ae16489bf 4 bytes - win32kbase!GreSfmDwmShutdown+3c (+0x07)
- [ 0f 1f 44 00:e8 5f da 20 ]
- ffffb60ae16489c5-ffffb60ae16489c6 2 bytes - win32kbase!GreSfmDwmShutdown+45 (+0x09)
- [ 48 ff:4c 8b ]
- ffffb60ae16489cc-ffffb60ae16489cf 4 bytes - win32kbase!GreSfmDwmShutdown+4c (+0x07)
- [ 0f 1f 44 00:e8 4f da 20 ]
- 24 errors : !win32kbase (ffffb60ae1647839-ffffb60ae16489cf)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-04-24T17:31:47.000Z
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #2: 3RD PARTY DRIVERS ======================
- May 01 2013 - WinRing0x64.sys - Intel Processor Diagnostic Tool or BatteryCare by OpenLibSys.org or Throttlestop (Properties say: OpenLibSys.org) or EVGA Precision X https://www.evga.com/
- Jun 11 2018 - e1i65x64.sys - Intel(R) Gigabit Adapter driver
- Mar 14 2019 - nvvad64v.sys - Nvidia Virtual Audio driver http://www.nvidia.com/
- Apr 09 2019 - AsIO2.sys - Asus Input Output driver
- Apr 11 2019 - CorsairVBusDriver.sys - Corsair Virtual Device driver (Corsair Utility Engine) http://www.corsair.com/
- Apr 11 2019 - CorsairVHidDriver.sys - Corsair Virtual Device driver (Corsair Utility Engine) http://www.corsair.com/
- Apr 22 2019 - GLCKIO2.sys - ASUS RGB driver
- May 14 2019 - sshid.sys - SteelSeries Engine HID driver https://steelseries.com/
- Jul 24 2019 - AMDPCIDev.sys - Advanced Micro Devices PCI Device driver
- Sep 29 2019 - amdgpio2.sys - AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Dec 05 2019 - cpuz149_x64.sys - CPUID driver
- Dec 16 2019 - AMDRyzenMasterDriver.sys - AMD Ryzen Master driver
- Jan 10 2020 - nvvhci.sys - Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Feb 14 2020 - CorsairLLAccess64.sys - CORSAIR iCUE Software driver
- Feb 19 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- Mar 12 2020 - nvrtxvad64v.sys -
- Apr 03 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- ================== Dump #2: 3RD PARTY DRIVERS (FULL) ===================
- Image path: \??\C:\Program Files (x86)\EVGA\LED Sync\WinRing0\WinRing0x64.sys
- Image name: WinRing0x64.sys
- Search : https://www.google.com/search?q=WinRing0x64.sys
- ADA Info : Intel Processor Diagnostic Tool or BatteryCare by OpenLibSys.org or Throttlestop (Properties say: OpenLibSys.org) or EVGA Precision X https://www.evga.com/
- Timestamp : Wed May 1 2013
- Mapped memory image file: C:\ProgramData\dbg\sym\e1i65x64.sys\5B1EB8E28e000\e1i65x64.sys
- Image path: \SystemRoot\System32\drivers\e1i65x64.sys
- Image name: e1i65x64.sys
- Search : https://www.google.com/search?q=e1i65x64.sys
- ADA Info : Intel(R) Gigabit Adapter driver
- Timestamp : Mon Jun 11 2018
- File version: 12.17.10.8
- Product version: 10.0.10011.16384
- File flags: 8 (Mask 3F) Private
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- CompanyName: Intel Corporation
- ProductName: Intel(R) Gigabit Adapter
- InternalName: e1i65x64.sys
- OriginalFilename: e1i65x64.sys
- ProductVersion: 12.17.10.8
- FileVersion: 12.17.10.8
- FileDescription: Intel(R) Gigabit Adapter NDIS 6.x driver
- LegalCopyright: Copyright(C) 2013, Intel Corporation. All rights reserved.
- Image path: \SystemRoot\system32\drivers\nvvad64v.sys
- Image name: nvvad64v.sys
- Search : https://www.google.com/search?q=nvvad64v.sys
- ADA Info : Nvidia Virtual Audio driver http://www.nvidia.com/
- Timestamp : Thu Mar 14 2019
- Image path: \??\C:\WINDOWS\system32\drivers\AsIO2.sys
- Image name: AsIO2.sys
- Search : https://www.google.com/search?q=AsIO2.sys
- ADA Info : Asus Input Output driver
- Timestamp : Tue Apr 9 2019
- Image path: \SystemRoot\System32\drivers\CorsairVBusDriver.sys
- Image name: CorsairVBusDriver.sys
- Search : https://www.google.com/search?q=CorsairVBusDriver.sys
- ADA Info : Corsair Virtual Device driver (Corsair Utility Engine) http://www.corsair.com/
- Timestamp : Thu Apr 11 2019
- Image path: \SystemRoot\System32\drivers\CorsairVHidDriver.sys
- Image name: CorsairVHidDriver.sys
- Search : https://www.google.com/search?q=CorsairVHidDriver.sys
- ADA Info : Corsair Virtual Device driver (Corsair Utility Engine) http://www.corsair.com/
- Timestamp : Thu Apr 11 2019
- Image path: \??\C:\WINDOWS\system32\drivers\GLCKIO2.sys
- Image name: GLCKIO2.sys
- Search : https://www.google.com/search?q=GLCKIO2.sys
- ADA Info : ASUS RGB driver
- Timestamp : Mon Apr 22 2019
- Image path: \SystemRoot\System32\drivers\sshid.sys
- Image name: sshid.sys
- Search : https://www.google.com/search?q=sshid.sys
- ADA Info : SteelSeries Engine HID driver https://steelseries.com/
- Timestamp : Tue May 14 2019
- Image path: \SystemRoot\System32\drivers\AMDPCIDev.sys
- Image name: AMDPCIDev.sys
- Search : https://www.google.com/search?q=AMDPCIDev.sys
- ADA Info : Advanced Micro Devices PCI Device driver
- Timestamp : Wed Jul 24 2019
- Image path: \SystemRoot\System32\drivers\amdgpio2.sys
- Image name: amdgpio2.sys
- Search : https://www.google.com/search?q=amdgpio2.sys
- ADA Info : AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Timestamp : Sun Sep 29 2019
- Image path: \??\C:\WINDOWS\temp\cpuz149\cpuz149_x64.sys
- Image name: cpuz149_x64.sys
- Search : https://www.google.com/search?q=cpuz149_x64.sys
- ADA Info : CPUID driver
- Timestamp : Thu Dec 5 2019
- Image path: \??\C:\Program Files\AMD\RyzenMaster\bin\AMDRyzenMasterDriver.sys
- Image name: AMDRyzenMasterDriver.sys
- Search : https://www.google.com/search?q=AMDRyzenMasterDriver.sys
- ADA Info : AMD Ryzen Master driver
- Timestamp : Mon Dec 16 2019
- Image path: \SystemRoot\System32\drivers\nvvhci.sys
- Image name: nvvhci.sys
- Search : https://www.google.com/search?q=nvvhci.sys
- ADA Info : Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Timestamp : Fri Jan 10 2020
- Image path: \??\C:\Program Files (x86)\Corsair\CORSAIR iCUE Software\CorsairLLAccess64.sys
- Image name: CorsairLLAccess64.sys
- Search : https://www.google.com/search?q=CorsairLLAccess64.sys
- ADA Info : CORSAIR iCUE Software driver
- Timestamp : Fri Feb 14 2020
- Image path: \SystemRoot\system32\drivers\nvhda64v.sys
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Wed Feb 19 2020
- Image path: \SystemRoot\system32\drivers\nvrtxvad64v.sys
- Image name: nvrtxvad64v.sys
- Search : https://www.google.com/search?q=nvrtxvad64v.sys
- Timestamp : Thu Mar 12 2020
- Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_95bdb3a23d6478de\nvlddmkm.sys
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Fri Apr 3 2020
- ====================== Dump #2: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- amdppm.sys Processor Device Driver
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- csc.sys Windows Client Side Caching driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HdAudio.sys High Definition Audio Function driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kd.dll Local Kernal Debugger (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate_AuthenticAMD.dll AMD Microcode Update Library (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msgpioclx.sys GPIO Class Extension Driver (Microsoft)
- mshidkmdf.sys Pass-through HID to KMDF Filter driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- ndisuio.sys NDIS User mode I/O driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- qwavedrv.sys Quality Windows Audio Video Experience (qWave) Support driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- serenum.sys Serial Port Enumerator (Microsoft)
- serial.sys Serial Device Driver
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- ucx01000.sys USB Controller Extension (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- winquic.sys QUIC Transport Protocol driver (Microsoft)
- WinUSB.SYS Windows WinUSB Class driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- ====================== Dump #2: UNLOADED MODULES =======================
- fffff807`83130000 fffff807`83141000 HWiNFO64A_15
- fffff807`83110000 fffff807`83121000 HWiNFO64A_15
- fffff807`830b0000 fffff807`830c1000 MSKSSRV.sys
- fffff807`42680000 fffff807`4268a000 CorsairVHidD
- fffff807`3fd30000 fffff807`3fd3f000 dump_storpor
- fffff807`3fd70000 fffff807`3fd9f000 dump_storahc
- fffff807`3fdc0000 fffff807`3fdde000 dump_dumpfve
- fffff807`3fc60000 fffff807`3fc7e000 dam.sys
- fffff807`35dd0000 fffff807`35de1000 WdBoot.sys
- fffff807`36dc0000 fffff807`36dd1000 hwpolicy.sys
- ====================== Dump #2: BIOS INFORMATION =======================
- [SMBIOS Data Tables v3.2]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 3181 bytes]
- [BIOS Information (Type 0) - Length 26 - Handle 0000h]
- Vendor American Megatrends Inc.
- BIOS Version 1407
- BIOS Starting Address Segment f000
- BIOS Release Date 04/02/2020
- BIOS ROM Size 1000000
- BIOS Characteristics
- 07: - PCI Supported
- 10: - APM Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 27: - Keyboard Services Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 32: - BIOS Vendor Reserved
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 5
- BIOS Minor Revision 14
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- Manufacturer System manufacturer
- Product Name System Product Name
- Version System Version
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- SKUNumber SKU
- [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
- Manufacturer ASUSTeK COMPUTER INC.
- Product PRIME X570-PRO
- Version Rev X.0x
- Feature Flags 09h
- -258820384: - -258820336: - ÷7£ý
- Location Default string
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 22 - Handle 0003h]
- Manufacturer Default string
- Chassis Type Desktop
- Version Default string
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 3
- [Onboard Devices Information (Type 10) - Length 6 - Handle 002dh]
- Number of Devices 1
- 01: Type Video [enabled]
- [OEM Strings (Type 11) - Length 5 - Handle 002eh]
- Number of Strings 8
- 1 Default string
- 2 Default string
- 3 MIAMI
- 4 Default string
- 5 FFFFFFFFFFFFF
- 6 FFFFFFFFFFFFF
- 7 FFFFFFFFFFFFF
- 8 Default string
- [System Configuration Options (Type 12) - Length 5 - Handle 002fh]
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 0034h]
- [Physical Memory Array (Type 16) - Length 23 - Handle 0035h]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 134217728KB
- Memory Error Inf Handle 0034h
- Number of Memory Devices 4
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0036h]
- Starting Address 00000000h
- Ending Address 0037ffffh
- Memory Array Handle 0035h
- Partition Width 02
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0037h]
- Starting Address 00400000h
- Ending Address 0207ffffh
- Memory Array Handle 0035h
- Partition Width 02
- [Cache Information (Type 7) - Length 27 - Handle 0038h]
- Socket Designation L1 - Cache
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0200h - 512K
- Installed Size 0200h - 512K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 27 - Handle 0039h]
- Socket Designation L2 - Cache
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 1000h - 4096K
- Installed Size 1000h - 4096K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 27 - Handle 003ah]
- Socket Designation L3 - Cache
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 8200h - 32768K
- Installed Size 8200h - 32768K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 16-way Set-Associative
- [Processor Information (Type 4) - Length 48 - Handle 003bh]
- Socket Designation AM4
- Processor Type Central Processor
- Processor Family 6bh - Specification Reserved
- Processor Manufacturer Advanced Micro Devices, Inc.
- Processor ID 100f8700fffb8b17
- Processor Version AMD Ryzen 7 3700X 8-Core Processor
- Processor Voltage 8bh - 1.1V
- External Clock 100MHz
- Max Speed 4400MHz
- Current Speed 3600MHz
- Status Enabled Populated
- Processor Upgrade Specification Reserved
- L1 Cache Handle 0038h
- L2 Cache Handle 0039h
- L3 Cache Handle 003ah
- Part Number Unknown
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 003ch]
- [Memory Device (Type 17) - Length 84 - Handle 003dh]
- Physical Memory Array Handle 0035h
- Memory Error Info Handle 003ch
- Form Factor 02h - Unknown
- Device Locator DIMM_A1
- Bank Locator BANK 0
- Memory Type 02h - Unknown
- Type Detail 0004h - Unknown
- Speed 0MHz
- Manufacturer Unknown
- Part Number Unknown
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 003eh]
- [Memory Device (Type 17) - Length 84 - Handle 003fh]
- Physical Memory Array Handle 0035h
- Memory Error Info Handle 003eh
- Total Width 64 bits
- Data Width 64 bits
- Size 16384MB
- Form Factor 09h - DIMM
- Device Locator DIMM_A2
- Bank Locator BANK 1
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 3600MHz
- Manufacturer G-Skill
- Part Number F4-3600C16-16GTZNC
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0040h]
- Starting Address 00000000h
- Ending Address 01ffffffh
- Memory Device Handle 003fh
- Mem Array Mapped Adr Handle 0037h
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 0041h]
- [Memory Device (Type 17) - Length 84 - Handle 0042h]
- Physical Memory Array Handle 0035h
- Memory Error Info Handle 0041h
- Form Factor 02h - Unknown
- Device Locator DIMM_B1
- Bank Locator BANK 2
- Memory Type 02h - Unknown
- Type Detail 0004h - Unknown
- Speed 0MHz
- Manufacturer Unknown
- Part Number Unknown
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 0043h]
- [Memory Device (Type 17) - Length 84 - Handle 0044h]
- Physical Memory Array Handle 0035h
- Memory Error Info Handle 0043h
- Total Width 64 bits
- Data Width 64 bits
- Size 16384MB
- Form Factor 09h - DIMM
- Device Locator DIMM_B2
- Bank Locator BANK 3
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 3600MHz
- Manufacturer G-Skill
- Part Number F4-3600C16-16GTZNC
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0045h]
- Starting Address 00000000h
- Ending Address 01ffffffh
- Memory Device Handle 0044h
- Mem Array Mapped Adr Handle 0037h
- ========================== Dump #2: Extra #1 ===========================
- 14: kd> !verifier
- Verify Flags Level 0x00000000
- STANDARD FLAGS:
- [X] (0x00000000) Automatic Checks
- [ ] (0x00000001) Special pool
- [ ] (0x00000002) Force IRQL checking
- [ ] (0x00000008) Pool tracking
- [ ] (0x00000010) I/O verification
- [ ] (0x00000020) Deadlock detection
- [ ] (0x00000080) DMA checking
- [ ] (0x00000100) Security checks
- [ ] (0x00000800) Miscellaneous checks
- [ ] (0x00020000) DDI compliance checking
- ADDITIONAL FLAGS:
- [ ] (0x00000004) Randomized low resources simulation
- [ ] (0x00000200) Force pending I/O requests
- [ ] (0x00000400) IRP logging
- [ ] (0x00002000) Invariant MDL checking for stack
- [ ] (0x00004000) Invariant MDL checking for driver
- [ ] (0x00008000) Power framework delay fuzzing
- [ ] (0x00010000) Port/miniport interface checking
- [ ] (0x00040000) Systematic low resources simulation
- [ ] (0x00080000) DDI compliance checking (additional)
- [ ] (0x00200000) NDIS/WIFI verification
- [ ] (0x00800000) Kernel synchronization delay fuzzing
- [ ] (0x01000000) VM switch verification
- [ ] (0x02000000) Code integrity checks
- [X] Indicates flag is enabled
- Summary of All Verifier Statistics
- RaiseIrqls 0x0
- AcquireSpinLocks 0x0
- Synch Executions 0x0
- Trims 0x0
- Pool Allocations Attempted 0x0
- Pool Allocations Succeeded 0x0
- Pool Allocations Succeeded SpecialPool 0x0
- Pool Allocations With NO TAG 0x0
- Pool Allocations Failed 0x0
- Current paged pool allocations 0x0 for 00000000 bytes
- Peak paged pool allocations 0x0 for 00000000 bytes
- Current nonpaged pool allocations 0x0 for 00000000 bytes
- Peak nonpaged pool allocations 0x0 for 00000000 bytes
- ========================== Dump #2: Extra #2 ===========================
- 14: kd> !thread
- THREAD ffff940a13ab4080 Cid 3278.3094 Teb: 0000007c923f4000 Win32Thread: ffff940a1292bc20 RUNNING on processor e
- Not impersonating
- GetUlongFromAddress: unable to read from fffff8073422ca14
- Owning Process ffff940a0e9da0c0 Image: ModernWarfare.exe
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 2409348 Ticks: 0
- Context Switch Count 263448 IdealProcessor: 14
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address 0x00007ff741314b60
- Stack Init ffffcc0ff9348c90 Current ffffcc0ff9348850
- Base ffffcc0ff9349000 Limit ffffcc0ff9343000 Call 0000000000000000
- Priority 9 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- ffffcc0f`f9348438 fffff807`33fd41e9 : 00000000`0000000a ffff854e`e2d410c8 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
- ffffcc0f`f9348440 fffff807`33fd0529 : 00000000`00000000 00000000`00000002 00000000`00000000 ffffcc0f`f9348730 : nt!KiBugCheckDispatch+0x69
- ffffcc0f`f9348580 fffff807`33ecfd34 : 00000000`00000000 fffff807`33ecb738 ffffe100`5a5c7180 fffff807`00000000 : nt!KiPageFault+0x469 (TrapFrame @ ffffcc0f`f9348580)
- ffffcc0f`f9348710 fffff807`33ecae8c : ffffcc0f`f9348880 00000000`00000000 ffffcc0f`f9348858 fffff807`33ec9f84 : nt!MiResolveProtoPteFault+0xc4
- ffffcc0f`f9348810 fffff807`33ec8fc9 : ffffe100`5a521180 00000000`00000100 00000000`c0000016 ffffcc0f`00000000 : nt!MiDispatchFault+0x80c
- ffffcc0f`f9348960 fffff807`33fd041e : 000001ea`58a108b8 ffffcc0f`f9348b80 000001e8`0dfce744 ffff940a`1587ca60 : nt!MmAccessFault+0x169
- ffffcc0f`f9348b00 00007fff`d87bb171 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x35e (TrapFrame @ ffffcc0f`f9348b00)
- 0000007c`936fe2b0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007fff`d87bb171
- ========================================================================
- ======================= Dump #3: ANALYZE VERBOSE =======================
- ======================= File: 042320-5562-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 18362 MP (16 procs) Free x64
- Kernel base = 0xfffff802`63c00000 PsLoadedModuleList = 0xfffff802`64048150
- Debug session time: Thu Apr 23 03:31:02.255 2020 (UTC - 4:00)
- System Uptime: 0 days 0:04:01.912
- BugCheck 162, {ffffe00eb6439040, ffff9f87619e2748, ffffffff, 0}
- Probably caused by : memory_corruption
- Followup: memory_corruption
- KERNEL_AUTO_BOOST_INVALID_LOCK_RELEASE (162)
- A lock tracked by AutoBoost was released by a thread that did not own the lock.
- This is typically caused when some thread releases a lock on behalf of another
- thread (which is not legal with AutoBoost tracking enabled) or when some thread
- tries to release a lock it no longer owns.
- Arguments:
- Arg1: ffffe00eb6439040, The address of the thread
- Arg2: ffff9f87619e2748, The lock address
- Arg3: 00000000ffffffff, The session ID of the thread
- Arg4: 0000000000000000, Reserved
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- BUGCHECK_STR: 0x162
- PROCESS_NAME: GameBar.exe
- CURRENT_IRQL: 0
- LAST_CONTROL_TRANSFER: from fffff80263dde43e to fffff80263dc2390
- STACK_TEXT:
- fffffe84`adb8daf8 fffff802`63dde43e : 00000000`00000162 ffffe00e`b6439040 ffff9f87`619e2748 00000000`ffffffff : nt!KeBugCheckEx
- fffffe84`adb8db00 fffff802`63d11afd : ffffe00e`ad953190 ffffe00e`00000000 ffffe00e`00000000 ffffe00e`ad953190 : nt!ExReleasePushLockEx+0xcbb0e
- fffffe84`adb8db60 fffff802`652e7c9c : ffffe00e`b88afde0 ffffe00e`b89b3a98 ffffe00e`ad953190 fffff802`652e35c9 : nt!FsRtlLookupPerStreamContextInternal+0x8d
- fffffe84`adb8db90 fffff802`652e7b09 : ffffe00e`ad953190 ffffffff`ffffff01 ffffe00e`ad953190 00000000`00000103 : FLTMGR!FltpGetStreamListCtrl+0x6c
- fffffe84`adb8dc00 fffff802`7078e142 : 00000000`00000000 ffff9f87`619e2700 fffffe84`adb8dd08 fffff802`65309060 : FLTMGR!FltGetStreamHandleContext+0x29
- fffffe84`adb8dc40 fffff802`652e4a5c : ffffe00e`b89b39b0 ffffe00e`b89b3b38 fffffe84`adb8dd29 00000000`00000000 : luafv!LuafvPreQueryInformation+0x62
- fffffe84`adb8dc80 fffff802`652e45a0 : fffffe84`adb8dde0 ffffe00e`ad953200 ffffe00e`b89b3905 ffffe00e`b3ed6900 : FLTMGR!FltpPerformPreCallbacks+0x2fc
- fffffe84`adb8dd90 fffff802`652e2bd8 : ffffe00e`b89b3a98 ffffe00e`b3ed69a8 00000000`00000000 ffffe00e`b89b3a98 : FLTMGR!FltpPassThroughInternal+0x90
- fffffe84`adb8ddc0 fffff802`6531c422 : ffffe00e`b89b39b0 ffffe00e`b89b3a98 00000000`00000028 00000000`00000004 : FLTMGR!FltPerformSynchronousIo+0x2d8
- fffffe84`adb8de60 fffff802`6fe63ae6 : ffffe00e`b88afde0 fffffe84`adb8df59 ffffe00e`b7dc4d10 00000000`00000000 : FLTMGR!FltQueryInformationFile+0x72
- fffffe84`adb8dea0 fffff802`6fe65f2c : 00000000`00000004 ffffe00e`b89aca98 00000000`00000000 fffffe84`adb8e078 : cldflt!HsmFltPreSetBasicInformation+0xbe
- fffffe84`adb8dfb0 fffff802`652e4a5c : ffffe00e`b89ac901 ffffe00e`b89acbb8 fffffe84`adb8e0b9 ffffe00e`b89ac9b0 : cldflt!HsmFltPreSET_INFORMATION+0x16c
- fffffe84`adb8e010 fffff802`652e45a0 : fffffe84`adb8e1f0 ffffe00e`b88afe00 00000000`00000006 00000000`00060800 : FLTMGR!FltpPerformPreCallbacks+0x2fc
- fffffe84`adb8e120 fffff802`652e4112 : 00000000`00000000 fffffe84`adb8e1f0 ffffe00e`b6ac9010 fffffe84`adb8e200 : FLTMGR!FltpPassThroughInternal+0x90
- fffffe84`adb8e150 fffff802`652e3efe : 00000000`20206f49 ffffe00e`b8828f68 fffffe84`0000000a 00000000`00000000 : FLTMGR!FltpPassThrough+0x162
- fffffe84`adb8e1d0 fffff802`63d0a929 : 00000000`00000000 00000000`00000208 00000000`00000000 00000000`00000000 : FLTMGR!FltpDispatch+0x9e
- fffffe84`adb8e230 fffff802`63c9fdf1 : ffffe00e`b88afe30 00000000`00000000 00000000`00000000 00000000`00000004 : nt!IofCallDriver+0x59
- fffffe84`adb8e270 fffff802`63c9cf19 : ffffe00e`b6ac9010 fffffe84`adb8e3e0 ffffe00e`b56aa000 ffffe00e`b341f010 : nt!IopCallDriverReference+0xf1
- fffffe84`adb8e2e0 fffff802`63dd3c18 : ffffffff`800046ec fffffe84`adb8e750 fffffe84`adb8e7a0 ffffe00e`00000028 : nt!NtSetInformationFile+0x6f9
- fffffe84`adb8e430 fffff802`63dc61b0 : fffff802`65c4eec0 00000000`00000000 fffffe84`adb8e740 fffffe84`adb8e820 : nt!KiSystemServiceCopyEnd+0x28
- fffffe84`adb8e638 fffff802`65c4eec0 : 00000000`00000000 fffffe84`adb8e740 fffffe84`adb8e820 ffff9f87`6181de50 : nt!KiServiceLinkage
- fffffe84`adb8e640 fffff802`64235d50 : 00000002`00000000 ffffe00e`b78030c0 ffff9f87`67499a30 fffffe84`adb8e930 : fileinfo!FIPfInterfaceOpen+0x620
- fffffe84`adb8e800 fffff802`6423574e : ffff9f87`7e514b98 ffffffff`fffdb610 fffffe84`adb8eac0 ffffffff`80003704 : nt!PfpOpenHandleCreate+0xdc
- fffffe84`adb8e8d0 fffff802`642353ad : 00000000`0000006c fffffe84`adb8eb00 ffff9f87`7e5a04de ffff9f87`00000000 : nt!PfSnGetSectionObject+0x126
- fffffe84`adb8ea00 fffff802`63cf43b5 : ffffe00e`aa87a9a0 ffffe00e`b6439040 ffffe00e`aa87a9a0 00000000`00000300 : nt!PfSnPopulateReadList+0x2bd
- fffffe84`adb8eb70 fffff802`63c6bcd5 : ffffe00e`b6439040 00000000`00000080 ffffe00e`aa8962c0 00000000`00000080 : nt!ExpWorkerThread+0x105
- fffffe84`adb8ec10 fffff802`63dc9998 : ffffb580`35b15180 ffffe00e`b6439040 fffff802`63c6bc80 00000000`00000007 : nt!PspSystemThreadStartup+0x55
- fffffe84`adb8ec60 00000000`00000000 : fffffe84`adb8f000 fffffe84`adb89000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
- fffff80263dd3b7a-fffff80263dd3b7e 5 bytes - nt!KiSystemServiceGdiTebAccess+93
- [ 41 ff e3 cc cc:e8 81 06 18 00 ]
- 5 errors : !nt (fffff80263dd3b7a-fffff80263dd3b7e)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-04-23T07:31:02.000Z
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #3: 3RD PARTY DRIVERS ======================
- May 01 2013 - WinRing0x64.sys - Intel Processor Diagnostic Tool or BatteryCare by OpenLibSys.org or Throttlestop (Properties say: OpenLibSys.org) or EVGA Precision X https://www.evga.com/
- Oct 22 2018 - rt640x64.sys - Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Mar 14 2019 - nvvad64v.sys - Nvidia Virtual Audio driver http://www.nvidia.com/
- May 14 2019 - sshid.sys - SteelSeries Engine HID driver https://steelseries.com/
- Jul 24 2019 - AMDPCIDev.sys - Advanced Micro Devices PCI Device driver
- Sep 29 2019 - amdgpio2.sys - AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Jan 10 2020 - nvvhci.sys - Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Feb 19 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- Apr 03 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- ================== Dump #3: 3RD PARTY DRIVERS (FULL) ===================
- Image path: \??\C:\Program Files (x86)\EVGA\WinRing0\WinRing0x64.sys
- Image name: WinRing0x64.sys
- Search : https://www.google.com/search?q=WinRing0x64.sys
- ADA Info : Intel Processor Diagnostic Tool or BatteryCare by OpenLibSys.org or Throttlestop (Properties say: OpenLibSys.org) or EVGA Precision X https://www.evga.com/
- Timestamp : Wed May 1 2013
- Mapped memory image file: C:\ProgramData\dbg\sym\rt640x64.sys\5BCDE005a6000\rt640x64.sys
- Image path: \SystemRoot\System32\drivers\rt640x64.sys
- Image name: rt640x64.sys
- Search : https://www.google.com/search?q=rt640x64.sys
- ADA Info : Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Timestamp : Mon Oct 22 2018
- File version: 9.1.409.2015
- Product version: 9.1.409.2015
- File flags: 8 (Mask 3F) Private
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- CompanyName: Realtek
- ProductName: Realtek 8125/8136/8168/8169 PCI/PCIe Adapters
- InternalName: rt640x64.sys
- OriginalFilename: rt640x64.sys
- ProductVersion: 9.001.0409.2015
- FileVersion: 9.001.0409.2015
- FileDescription: Realtek 8125/8136/8168/8169 NDIS 6.40 64-bit Driver
- LegalCopyright: Copyright (C) 2018 Realtek Semiconductor Corporation. All Right Reserved.
- Image path: \SystemRoot\system32\drivers\nvvad64v.sys
- Image name: nvvad64v.sys
- Search : https://www.google.com/search?q=nvvad64v.sys
- ADA Info : Nvidia Virtual Audio driver http://www.nvidia.com/
- Timestamp : Thu Mar 14 2019
- Image path: \SystemRoot\System32\drivers\sshid.sys
- Image name: sshid.sys
- Search : https://www.google.com/search?q=sshid.sys
- ADA Info : SteelSeries Engine HID driver https://steelseries.com/
- Timestamp : Tue May 14 2019
- Image path: \SystemRoot\System32\drivers\AMDPCIDev.sys
- Image name: AMDPCIDev.sys
- Search : https://www.google.com/search?q=AMDPCIDev.sys
- ADA Info : Advanced Micro Devices PCI Device driver
- Timestamp : Wed Jul 24 2019
- Image path: \SystemRoot\System32\drivers\amdgpio2.sys
- Image name: amdgpio2.sys
- Search : https://www.google.com/search?q=amdgpio2.sys
- ADA Info : AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Timestamp : Sun Sep 29 2019
- Image path: \SystemRoot\System32\drivers\nvvhci.sys
- Image name: nvvhci.sys
- Search : https://www.google.com/search?q=nvvhci.sys
- ADA Info : Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Timestamp : Fri Jan 10 2020
- Image path: \SystemRoot\system32\drivers\nvhda64v.sys
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Wed Feb 19 2020
- Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_95bdb3a23d6478de\nvlddmkm.sys
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Fri Apr 3 2020
- ====================== Dump #3: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- amdppm.sys Processor Device Driver
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- csc.sys Windows Client Side Caching driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HdAudio.sys High Definition Audio Function driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kd.dll Local Kernal Debugger (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate_AuthenticAMD.dll AMD Microcode Update Library (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msgpioclx.sys GPIO Class Extension Driver (Microsoft)
- mshidkmdf.sys Pass-through HID to KMDF Filter driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- serenum.sys Serial Port Enumerator (Microsoft)
- serial.sys Serial Device Driver
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- ucx01000.sys USB Controller Extension (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- winquic.sys QUIC Transport Protocol driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- ====================== Dump #3: UNLOADED MODULES =======================
- fffff802`6f2b0000 fffff802`6f2bf000 dump_storpor
- fffff802`6f2f0000 fffff802`6f31f000 dump_storahc
- fffff802`6f340000 fffff802`6f35e000 dump_dumpfve
- fffff802`6f6e0000 fffff802`6f6fe000 dam.sys
- fffff802`657d0000 fffff802`657e1000 WdBoot.sys
- fffff802`667b0000 fffff802`667c1000 hwpolicy.sys
- ====================== Dump #3: BIOS INFORMATION =======================
- [SMBIOS Data Tables v2.8]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 2450 bytes]
- [BIOS Information (Type 0) - Length 26 - Handle 0000h]
- Vendor American Megatrends Inc.
- BIOS Version A.70
- BIOS Starting Address Segment f000
- BIOS Release Date 01/09/2020
- BIOS ROM Size 1000000
- BIOS Characteristics
- 07: - PCI Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 27: - Keyboard Services Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 32: - BIOS Vendor Reserved
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 5
- BIOS Minor Revision 14
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- Manufacturer Micro-Star International Co., Ltd.
- Product Name MS-7C37
- Version 2.0
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
- Manufacturer Micro-Star International Co., Ltd.
- Product MPG X570 GAMING PLUS (MS-7C37)
- Version 2.0
- Feature Flags 09h
- -258820384: - -258820336: - ÷7£ý
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 22 - Handle 0003h]
- Manufacturer Micro-Star International Co., Ltd.
- Chassis Type Desktop
- Version 2.0
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 3
- [OEM Strings (Type 11) - Length 5 - Handle 000bh]
- Number of Strings 1
- [System Configuration Options (Type 12) - Length 5 - Handle 000ch]
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 000eh]
- [Physical Memory Array (Type 16) - Length 23 - Handle 000fh]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 134217728KB
- Memory Error Inf Handle 000eh
- Number of Memory Devices 4
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0010h]
- Starting Address 00000000h
- Ending Address 0037ffffh
- Memory Array Handle 000fh
- Partition Width 02
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0011h]
- Starting Address 00400000h
- Ending Address 0207ffffh
- Memory Array Handle 000fh
- Partition Width 02
- [Cache Information (Type 7) - Length 19 - Handle 0012h]
- Socket Designation L1 - Cache
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0200h - 512K
- Installed Size 0200h - 512K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0013h]
- Socket Designation L2 - Cache
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 1000h - 4096K
- Installed Size 1000h - 4096K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0014h]
- Socket Designation L3 - Cache
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 8200h - 32768K
- Installed Size 8200h - 32768K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 16-way Set-Associative
- [Processor Information (Type 4) - Length 48 - Handle 0015h]
- Socket Designation AM4
- Processor Type Central Processor
- Processor Family 6bh - Specification Reserved
- Processor Manufacturer Advanced Micro Devices, Inc.
- Processor ID 100f8700fffb8b17
- Processor Version AMD Ryzen 7 3700X 8-Core Processor
- Processor Voltage 8bh - 1.1V
- External Clock 100MHz
- Max Speed 4400MHz
- Current Speed 3600MHz
- Status Enabled Populated
- Processor Upgrade Specification Reserved
- L1 Cache Handle 0012h
- L2 Cache Handle 0013h
- L3 Cache Handle 0014h
- Part Number Unknown
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 0016h]
- [Memory Device (Type 17) - Length 40 - Handle 0017h]
- Physical Memory Array Handle 000fh
- Memory Error Info Handle 0016h
- Form Factor 02h - Unknown
- Device Locator DIMM 0
- Bank Locator P0 CHANNEL A
- Memory Type 02h - Unknown
- Type Detail 0004h - Unknown
- Speed 3600MHz
- Manufacturer Unknown
- Part Number Unknown
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 0018h]
- [Memory Device (Type 17) - Length 40 - Handle 0019h]
- Physical Memory Array Handle 000fh
- Memory Error Info Handle 0018h
- Total Width 64 bits
- Data Width 64 bits
- Size 16384MB
- Form Factor 09h - DIMM
- Device Locator DIMM 1
- Bank Locator P0 CHANNEL A
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 3600MHz
- Manufacturer Unknown
- Part Number F4-3600C16-16GTZNC
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 001ah]
- Starting Address 00000000h
- Ending Address 01ffffffh
- Memory Device Handle 0019h
- Mem Array Mapped Adr Handle 0011h
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 001bh]
- [Memory Device (Type 17) - Length 40 - Handle 001ch]
- Physical Memory Array Handle 000fh
- Memory Error Info Handle 001bh
- Form Factor 02h - Unknown
- Device Locator DIMM 0
- Bank Locator P0 CHANNEL B
- Memory Type 02h - Unknown
- Type Detail 0004h - Unknown
- Speed 3600MHz
- Manufacturer Unknown
- Part Number Unknown
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 001dh]
- [Memory Device (Type 17) - Length 40 - Handle 001eh]
- Physical Memory Array Handle 000fh
- Memory Error Info Handle 001dh
- Total Width 64 bits
- Data Width 64 bits
- Size 16384MB
- Form Factor 09h - DIMM
- Device Locator DIMM 1
- Bank Locator P0 CHANNEL B
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 3600MHz
- Manufacturer Unknown
- Part Number F4-3600C16-16GTZNC
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 001fh]
- Starting Address 00000000h
- Ending Address 01ffffffh
- Memory Device Handle 001eh
- Mem Array Mapped Adr Handle 0011h
- ========================== Dump #3: Extra #1 ===========================
- 14: kd> !verifier
- Verify Flags Level 0x00000000
- STANDARD FLAGS:
- [X] (0x00000000) Automatic Checks
- [ ] (0x00000001) Special pool
- [ ] (0x00000002) Force IRQL checking
- [ ] (0x00000008) Pool tracking
- [ ] (0x00000010) I/O verification
- [ ] (0x00000020) Deadlock detection
- [ ] (0x00000080) DMA checking
- [ ] (0x00000100) Security checks
- [ ] (0x00000800) Miscellaneous checks
- [ ] (0x00020000) DDI compliance checking
- ADDITIONAL FLAGS:
- [ ] (0x00000004) Randomized low resources simulation
- [ ] (0x00000200) Force pending I/O requests
- [ ] (0x00000400) IRP logging
- [ ] (0x00002000) Invariant MDL checking for stack
- [ ] (0x00004000) Invariant MDL checking for driver
- [ ] (0x00008000) Power framework delay fuzzing
- [ ] (0x00010000) Port/miniport interface checking
- [ ] (0x00040000) Systematic low resources simulation
- [ ] (0x00080000) DDI compliance checking (additional)
- [ ] (0x00200000) NDIS/WIFI verification
- [ ] (0x00800000) Kernel synchronization delay fuzzing
- [ ] (0x01000000) VM switch verification
- [ ] (0x02000000) Code integrity checks
- [X] Indicates flag is enabled
- Summary of All Verifier Statistics
- RaiseIrqls 0x0
- AcquireSpinLocks 0x0
- Synch Executions 0x0
- Trims 0x0
- Pool Allocations Attempted 0x0
- Pool Allocations Succeeded 0x0
- Pool Allocations Succeeded SpecialPool 0x0
- Pool Allocations With NO TAG 0x0
- Pool Allocations Failed 0x0
- Current paged pool allocations 0x0 for 00000000 bytes
- Peak paged pool allocations 0x0 for 00000000 bytes
- Current nonpaged pool allocations 0x0 for 00000000 bytes
- Peak nonpaged pool allocations 0x0 for 00000000 bytes
- ========================== Dump #3: Extra #2 ===========================
- 14: kd> !thread
- THREAD ffffe00eb6439040 Cid 0004.1748 Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor e
- IRP List:
- ffffe00eb6ac9010: (0006,0430) Flags: 00060834 Mdl: 00000000
- Not impersonating
- GetUlongFromAddress: unable to read from fffff8026402ca14
- Owning Process ffffe00eaa8962c0 Image: System Process
- Attached Process ffffe00eb891a080 Image: GameBar.exe
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 15482
- Context Switch Count 2425 IdealProcessor: 12
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address nt!ExpWorkerThread (0xfffff80263cf42b0)
- Stack Init fffffe84adb8ec90 Current fffffe84adb8d770
- Base fffffe84adb8f000 Limit fffffe84adb89000 Call 0000000000000000
- Priority 12 BasePriority 11 PriorityDecrement 0 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- fffffe84`adb8daf8 fffff802`63dde43e : 00000000`00000162 ffffe00e`b6439040 ffff9f87`619e2748 00000000`ffffffff : nt!KeBugCheckEx
- fffffe84`adb8db00 fffff802`63d11afd : ffffe00e`ad953190 ffffe00e`00000000 ffffe00e`00000000 ffffe00e`ad953190 : nt!ExReleasePushLockEx+0xcbb0e
- fffffe84`adb8db60 fffff802`652e7c9c : ffffe00e`b88afde0 ffffe00e`b89b3a98 ffffe00e`ad953190 fffff802`652e35c9 : nt!FsRtlLookupPerStreamContextInternal+0x8d
- fffffe84`adb8db90 fffff802`652e7b09 : ffffe00e`ad953190 ffffffff`ffffff01 ffffe00e`ad953190 00000000`00000103 : FLTMGR!FltpGetStreamListCtrl+0x6c
- fffffe84`adb8dc00 fffff802`7078e142 : 00000000`00000000 ffff9f87`619e2700 fffffe84`adb8dd08 fffff802`65309060 : FLTMGR!FltGetStreamHandleContext+0x29
- fffffe84`adb8dc40 fffff802`652e4a5c : ffffe00e`b89b39b0 ffffe00e`b89b3b38 fffffe84`adb8dd29 00000000`00000000 : luafv!LuafvPreQueryInformation+0x62
- fffffe84`adb8dc80 fffff802`652e45a0 : fffffe84`adb8dde0 ffffe00e`ad953200 ffffe00e`b89b3905 ffffe00e`b3ed6900 : FLTMGR!FltpPerformPreCallbacks+0x2fc
- fffffe84`adb8dd90 fffff802`652e2bd8 : ffffe00e`b89b3a98 ffffe00e`b3ed69a8 00000000`00000000 ffffe00e`b89b3a98 : FLTMGR!FltpPassThroughInternal+0x90
- fffffe84`adb8ddc0 fffff802`6531c422 : ffffe00e`b89b39b0 ffffe00e`b89b3a98 00000000`00000028 00000000`00000004 : FLTMGR!FltPerformSynchronousIo+0x2d8
- fffffe84`adb8de60 fffff802`6fe63ae6 : ffffe00e`b88afde0 fffffe84`adb8df59 ffffe00e`b7dc4d10 00000000`00000000 : FLTMGR!FltQueryInformationFile+0x72
- fffffe84`adb8dea0 fffff802`6fe65f2c : 00000000`00000004 ffffe00e`b89aca98 00000000`00000000 fffffe84`adb8e078 : cldflt!HsmFltPreSetBasicInformation+0xbe
- fffffe84`adb8dfb0 fffff802`652e4a5c : ffffe00e`b89ac901 ffffe00e`b89acbb8 fffffe84`adb8e0b9 ffffe00e`b89ac9b0 : cldflt!HsmFltPreSET_INFORMATION+0x16c
- fffffe84`adb8e010 fffff802`652e45a0 : fffffe84`adb8e1f0 ffffe00e`b88afe00 00000000`00000006 00000000`00060800 : FLTMGR!FltpPerformPreCallbacks+0x2fc
- fffffe84`adb8e120 fffff802`652e4112 : 00000000`00000000 fffffe84`adb8e1f0 ffffe00e`b6ac9010 fffffe84`adb8e200 : FLTMGR!FltpPassThroughInternal+0x90
- fffffe84`adb8e150 fffff802`652e3efe : 00000000`20206f49 ffffe00e`b8828f68 fffffe84`0000000a 00000000`00000000 : FLTMGR!FltpPassThrough+0x162
- fffffe84`adb8e1d0 fffff802`63d0a929 : 00000000`00000000 00000000`00000208 00000000`00000000 00000000`00000000 : FLTMGR!FltpDispatch+0x9e
- fffffe84`adb8e230 fffff802`63c9fdf1 : ffffe00e`b88afe30 00000000`00000000 00000000`00000000 00000000`00000004 : nt!IofCallDriver+0x59
- fffffe84`adb8e270 fffff802`63c9cf19 : ffffe00e`b6ac9010 fffffe84`adb8e3e0 ffffe00e`b56aa000 ffffe00e`b341f010 : nt!IopCallDriverReference+0xf1
- fffffe84`adb8e2e0 fffff802`63dd3c18 : ffffffff`800046ec fffffe84`adb8e750 fffffe84`adb8e7a0 ffffe00e`00000028 : nt!NtSetInformationFile+0x6f9
- fffffe84`adb8e430 fffff802`63dc61b0 : fffff802`65c4eec0 00000000`00000000 fffffe84`adb8e740 fffffe84`adb8e820 : nt!KiSystemServiceCopyEnd+0x28 (TrapFrame @ fffffe84`adb8e4a0)
- fffffe84`adb8e638 fffff802`65c4eec0 : 00000000`00000000 fffffe84`adb8e740 fffffe84`adb8e820 ffff9f87`6181de50 : nt!KiServiceLinkage
- fffffe84`adb8e640 fffff802`64235d50 : 00000002`00000000 ffffe00e`b78030c0 ffff9f87`67499a30 fffffe84`adb8e930 : fileinfo!FIPfInterfaceOpen+0x620
- fffffe84`adb8e800 fffff802`6423574e : ffff9f87`7e514b98 ffffffff`fffdb610 fffffe84`adb8eac0 ffffffff`80003704 : nt!PfpOpenHandleCreate+0xdc
- fffffe84`adb8e8d0 fffff802`642353ad : 00000000`0000006c fffffe84`adb8eb00 ffff9f87`7e5a04de ffff9f87`00000000 : nt!PfSnGetSectionObject+0x126
- fffffe84`adb8ea00 fffff802`63cf43b5 : ffffe00e`aa87a9a0 ffffe00e`b6439040 ffffe00e`aa87a9a0 00000000`00000300 : nt!PfSnPopulateReadList+0x2bd
- fffffe84`adb8eb70 fffff802`63c6bcd5 : ffffe00e`b6439040 00000000`00000080 ffffe00e`aa8962c0 00000000`00000080 : nt!ExpWorkerThread+0x105
- fffffe84`adb8ec10 fffff802`63dc9998 : ffffb580`35b15180 ffffe00e`b6439040 fffff802`63c6bc80 00000000`00000007 : nt!PspSystemThreadStartup+0x55
- fffffe84`adb8ec60 00000000`00000000 : fffffe84`adb8f000 fffffe84`adb89000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
- ========================================================================
- ======================= Dump #4: ANALYZE VERBOSE =======================
- ======================= File: 042320-5531-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 18362 MP (16 procs) Free x64
- Kernel base = 0xfffff800`81a00000 PsLoadedModuleList = 0xfffff800`81e48150
- Debug session time: Thu Apr 23 03:26:20.871 2020 (UTC - 4:00)
- System Uptime: 0 days 0:06:35.526
- BugCheck 162, {ffffaa0e38a80040, ffff93040b8e0708, ffffffff, 0}
- *** WARNING: Unable to verify timestamp for win32k.sys
- *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
- Probably caused by : memory_corruption
- Followup: memory_corruption
- KERNEL_AUTO_BOOST_INVALID_LOCK_RELEASE (162)
- A lock tracked by AutoBoost was released by a thread that did not own the lock.
- This is typically caused when some thread releases a lock on behalf of another
- thread (which is not legal with AutoBoost tracking enabled) or when some thread
- tries to release a lock it no longer owns.
- Arguments:
- Arg1: ffffaa0e38a80040, The address of the thread
- Arg2: ffff93040b8e0708, The lock address
- Arg3: 00000000ffffffff, The session ID of the thread
- Arg4: 0000000000000000, Reserved
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- BUGCHECK_STR: 0x162
- PROCESS_NAME: System
- CURRENT_IRQL: 0
- LAST_CONTROL_TRANSFER: from fffff80081bde4b5 to fffff80081bc2390
- STACK_TEXT:
- ffffec02`dc787a58 fffff800`81bde4b5 : 00000000`00000162 ffffaa0e`38a80040 ffff9304`0b8e0708 00000000`ffffffff : nt!KeBugCheckEx
- ffffec02`dc787a60 fffff800`82018a4a : ffffffff`00000000 00000000`00000000 ffff9304`0b8e0710 00000000`00000000 : nt!KeAbPostRelease+0xcb5b5
- ffffec02`dc787ab0 fffff800`820187a5 : ffffaa0e`38a80040 fffff800`82018780 ffffaa0e`3806c930 fffff800`82018780 : nt!ExpWnfDispatchKernelSubscription+0x276
- ffffec02`dc787b40 fffff800`81af43b5 : ffffaa0e`3806c930 ffffaa0e`3806c900 ffffaa0e`45079e00 ffffaa0e`3806c930 : nt!ExpWnfWorkItemRoutine+0x25
- ffffec02`dc787b70 fffff800`81a6bcd5 : ffffaa0e`38a80040 00000000`00000080 ffffaa0e`3806f040 00000067`b4bbbdff : nt!ExpWorkerThread+0x105
- ffffec02`dc787c10 fffff800`81bc9998 : ffffbe01`c29c1180 ffffaa0e`38a80040 fffff800`81a6bc80 00000000`00000000 : nt!PspSystemThreadStartup+0x55
- ffffec02`dc787c60 00000000`00000000 : ffffec02`dc788000 ffffec02`dc782000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !bam
- fffff8008dceb301-fffff8008dceb302 2 bytes - bam!BampThrottledProcessWakeNotificationCallback+b1
- [ 48 ff:4c 8b ]
- fffff8008dceb308-fffff8008dceb30c 5 bytes - bam!BampThrottledProcessWakeNotificationCallback+b8 (+0x07)
- [ 0f 1f 44 00 00:e8 53 39 ed f3 ]
- 7 errors : !bam (fffff8008dceb301-fffff8008dceb30c)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-04-23T07:26:20.000Z
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #4: 3RD PARTY DRIVERS ======================
- May 01 2013 - WinRing0x64.sys - Intel Processor Diagnostic Tool or BatteryCare by OpenLibSys.org or Throttlestop (Properties say: OpenLibSys.org) or EVGA Precision X https://www.evga.com/
- Oct 22 2018 - rt640x64.sys - Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Mar 14 2019 - nvvad64v.sys - Nvidia Virtual Audio driver http://www.nvidia.com/
- May 14 2019 - sshid.sys - SteelSeries Engine HID driver https://steelseries.com/
- Jul 24 2019 - AMDPCIDev.sys - Advanced Micro Devices PCI Device driver
- Sep 29 2019 - amdgpio2.sys - AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Jan 10 2020 - nvvhci.sys - Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Feb 19 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- Apr 03 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- ================== Dump #4: 3RD PARTY DRIVERS (FULL) ===================
- Image path: \??\C:\Program Files (x86)\EVGA\WinRing0\WinRing0x64.sys
- Image name: WinRing0x64.sys
- Search : https://www.google.com/search?q=WinRing0x64.sys
- ADA Info : Intel Processor Diagnostic Tool or BatteryCare by OpenLibSys.org or Throttlestop (Properties say: OpenLibSys.org) or EVGA Precision X https://www.evga.com/
- Timestamp : Wed May 1 2013
- Mapped memory image file: C:\ProgramData\dbg\sym\rt640x64.sys\5BCDE005a6000\rt640x64.sys
- Image path: \SystemRoot\System32\drivers\rt640x64.sys
- Image name: rt640x64.sys
- Search : https://www.google.com/search?q=rt640x64.sys
- ADA Info : Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Timestamp : Mon Oct 22 2018
- File version: 9.1.409.2015
- Product version: 9.1.409.2015
- File flags: 8 (Mask 3F) Private
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- CompanyName: Realtek
- ProductName: Realtek 8125/8136/8168/8169 PCI/PCIe Adapters
- InternalName: rt640x64.sys
- OriginalFilename: rt640x64.sys
- ProductVersion: 9.001.0409.2015
- FileVersion: 9.001.0409.2015
- FileDescription: Realtek 8125/8136/8168/8169 NDIS 6.40 64-bit Driver
- LegalCopyright: Copyright (C) 2018 Realtek Semiconductor Corporation. All Right Reserved.
- Image path: \SystemRoot\system32\drivers\nvvad64v.sys
- Image name: nvvad64v.sys
- Search : https://www.google.com/search?q=nvvad64v.sys
- ADA Info : Nvidia Virtual Audio driver http://www.nvidia.com/
- Timestamp : Thu Mar 14 2019
- Image path: \SystemRoot\System32\drivers\sshid.sys
- Image name: sshid.sys
- Search : https://www.google.com/search?q=sshid.sys
- ADA Info : SteelSeries Engine HID driver https://steelseries.com/
- Timestamp : Tue May 14 2019
- Image path: \SystemRoot\System32\drivers\AMDPCIDev.sys
- Image name: AMDPCIDev.sys
- Search : https://www.google.com/search?q=AMDPCIDev.sys
- ADA Info : Advanced Micro Devices PCI Device driver
- Timestamp : Wed Jul 24 2019
- Image path: \SystemRoot\System32\drivers\amdgpio2.sys
- Image name: amdgpio2.sys
- Search : https://www.google.com/search?q=amdgpio2.sys
- ADA Info : AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Timestamp : Sun Sep 29 2019
- Image path: \SystemRoot\System32\drivers\nvvhci.sys
- Image name: nvvhci.sys
- Search : https://www.google.com/search?q=nvvhci.sys
- ADA Info : Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
- Timestamp : Fri Jan 10 2020
- Image path: \SystemRoot\system32\drivers\nvhda64v.sys
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Wed Feb 19 2020
- Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_95bdb3a23d6478de\nvlddmkm.sys
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Fri Apr 3 2020
- ====================== Dump #4: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- amdppm.sys Processor Device Driver
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- csc.sys Windows Client Side Caching driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_diskdump.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HdAudio.sys High Definition Audio Function driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kd.dll Local Kernal Debugger (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate_AuthenticAMD.dll AMD Microcode Update Library (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msgpioclx.sys GPIO Class Extension Driver (Microsoft)
- mshidkmdf.sys Pass-through HID to KMDF Filter driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- serenum.sys Serial Port Enumerator (Microsoft)
- serial.sys Serial Device Driver
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- ucx01000.sys USB Controller Extension (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- winquic.sys QUIC Transport Protocol driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- ====================== Dump #4: UNLOADED MODULES =======================
- fffff800`8d3d0000 fffff800`8d3df000 dump_storpor
- fffff800`8d030000 fffff800`8d05f000 dump_storahc
- fffff800`8d080000 fffff800`8d09e000 dump_dumpfve
- fffff800`8dc50000 fffff800`8dc6e000 dam.sys
- fffff800`839d0000 fffff800`839e1000 WdBoot.sys
- fffff800`849b0000 fffff800`849c1000 hwpolicy.sys
- ====================== Dump #4: BIOS INFORMATION =======================
- [SMBIOS Data Tables v2.8]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 2450 bytes]
- [BIOS Information (Type 0) - Length 26 - Handle 0000h]
- Vendor American Megatrends Inc.
- BIOS Version A.70
- BIOS Starting Address Segment f000
- BIOS Release Date 01/09/2020
- BIOS ROM Size 1000000
- BIOS Characteristics
- 07: - PCI Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 27: - Keyboard Services Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 32: - BIOS Vendor Reserved
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 5
- BIOS Minor Revision 14
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- Manufacturer Micro-Star International Co., Ltd.
- Product Name MS-7C37
- Version 2.0
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
- Manufacturer Micro-Star International Co., Ltd.
- Product MPG X570 GAMING PLUS (MS-7C37)
- Version 2.0
- Feature Flags 09h
- -258820384: - -258820336: - ÷7£ý
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 22 - Handle 0003h]
- Manufacturer Micro-Star International Co., Ltd.
- Chassis Type Desktop
- Version 2.0
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 3
- [OEM Strings (Type 11) - Length 5 - Handle 000bh]
- Number of Strings 1
- [System Configuration Options (Type 12) - Length 5 - Handle 000ch]
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 000eh]
- [Physical Memory Array (Type 16) - Length 23 - Handle 000fh]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 134217728KB
- Memory Error Inf Handle 000eh
- Number of Memory Devices 4
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0010h]
- Starting Address 00000000h
- Ending Address 0037ffffh
- Memory Array Handle 000fh
- Partition Width 02
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0011h]
- Starting Address 00400000h
- Ending Address 0207ffffh
- Memory Array Handle 000fh
- Partition Width 02
- [Cache Information (Type 7) - Length 19 - Handle 0012h]
- Socket Designation L1 - Cache
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0200h - 512K
- Installed Size 0200h - 512K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0013h]
- Socket Designation L2 - Cache
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 1000h - 4096K
- Installed Size 1000h - 4096K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0014h]
- Socket Designation L3 - Cache
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 8200h - 32768K
- Installed Size 8200h - 32768K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 16-way Set-Associative
- [Processor Information (Type 4) - Length 48 - Handle 0015h]
- Socket Designation AM4
- Processor Type Central Processor
- Processor Family 6bh - Specification Reserved
- Processor Manufacturer Advanced Micro Devices, Inc.
- Processor ID 100f8700fffb8b17
- Processor Version AMD Ryzen 7 3700X 8-Core Processor
- Processor Voltage 8bh - 1.1V
- External Clock 100MHz
- Max Speed 4400MHz
- Current Speed 3600MHz
- Status Enabled Populated
- Processor Upgrade Specification Reserved
- L1 Cache Handle 0012h
- L2 Cache Handle 0013h
- L3 Cache Handle 0014h
- Part Number Unknown
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 0016h]
- [Memory Device (Type 17) - Length 40 - Handle 0017h]
- Physical Memory Array Handle 000fh
- Memory Error Info Handle 0016h
- Form Factor 02h - Unknown
- Device Locator DIMM 0
- Bank Locator P0 CHANNEL A
- Memory Type 02h - Unknown
- Type Detail 0004h - Unknown
- Speed 3600MHz
- Manufacturer Unknown
- Part Number Unknown
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 0018h]
- [Memory Device (Type 17) - Length 40 - Handle 0019h]
- Physical Memory Array Handle 000fh
- Memory Error Info Handle 0018h
- Total Width 64 bits
- Data Width 64 bits
- Size 16384MB
- Form Factor 09h - DIMM
- Device Locator DIMM 1
- Bank Locator P0 CHANNEL A
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 3600MHz
- Manufacturer Unknown
- Part Number F4-3600C16-16GTZNC
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 001ah]
- Starting Address 00000000h
- Ending Address 01ffffffh
- Memory Device Handle 0019h
- Mem Array Mapped Adr Handle 0011h
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 001bh]
- [Memory Device (Type 17) - Length 40 - Handle 001ch]
- Physical Memory Array Handle 000fh
- Memory Error Info Handle 001bh
- Form Factor 02h - Unknown
- Device Locator DIMM 0
- Bank Locator P0 CHANNEL B
- Memory Type 02h - Unknown
- Type Detail 0004h - Unknown
- Speed 3600MHz
- Manufacturer Unknown
- Part Number Unknown
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 001dh]
- [Memory Device (Type 17) - Length 40 - Handle 001eh]
- Physical Memory Array Handle 000fh
- Memory Error Info Handle 001dh
- Total Width 64 bits
- Data Width 64 bits
- Size 16384MB
- Form Factor 09h - DIMM
- Device Locator DIMM 1
- Bank Locator P0 CHANNEL B
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 3600MHz
- Manufacturer Unknown
- Part Number F4-3600C16-16GTZNC
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 001fh]
- Starting Address 00000000h
- Ending Address 01ffffffh
- Memory Device Handle 001eh
- Mem Array Mapped Adr Handle 0011h
- ========================== Dump #4: Extra #1 ===========================
- 14: kd> !verifier
- Verify Flags Level 0x00000000
- STANDARD FLAGS:
- [X] (0x00000000) Automatic Checks
- [ ] (0x00000001) Special pool
- [ ] (0x00000002) Force IRQL checking
- [ ] (0x00000008) Pool tracking
- [ ] (0x00000010) I/O verification
- [ ] (0x00000020) Deadlock detection
- [ ] (0x00000080) DMA checking
- [ ] (0x00000100) Security checks
- [ ] (0x00000800) Miscellaneous checks
- [ ] (0x00020000) DDI compliance checking
- ADDITIONAL FLAGS:
- [ ] (0x00000004) Randomized low resources simulation
- [ ] (0x00000200) Force pending I/O requests
- [ ] (0x00000400) IRP logging
- [ ] (0x00002000) Invariant MDL checking for stack
- [ ] (0x00004000) Invariant MDL checking for driver
- [ ] (0x00008000) Power framework delay fuzzing
- [ ] (0x00010000) Port/miniport interface checking
- [ ] (0x00040000) Systematic low resources simulation
- [ ] (0x00080000) DDI compliance checking (additional)
- [ ] (0x00200000) NDIS/WIFI verification
- [ ] (0x00800000) Kernel synchronization delay fuzzing
- [ ] (0x01000000) VM switch verification
- [ ] (0x02000000) Code integrity checks
- [X] Indicates flag is enabled
- Summary of All Verifier Statistics
- RaiseIrqls 0x0
- AcquireSpinLocks 0x0
- Synch Executions 0x0
- Trims 0x0
- Pool Allocations Attempted 0x0
- Pool Allocations Succeeded 0x0
- Pool Allocations Succeeded SpecialPool 0x0
- Pool Allocations With NO TAG 0x0
- Pool Allocations Failed 0x0
- Current paged pool allocations 0x0 for 00000000 bytes
- Peak paged pool allocations 0x0 for 00000000 bytes
- Current nonpaged pool allocations 0x0 for 00000000 bytes
- Peak nonpaged pool allocations 0x0 for 00000000 bytes
- ========================== Dump #4: Extra #2 ===========================
- 14: kd> !thread
- THREAD ffffaa0e38a80040 Cid 0004.1768 Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor e
- Not impersonating
- GetUlongFromAddress: unable to read from fffff80081e2ca14
- Owning Process ffffaa0e3806f040 Image: System
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 25313
- Context Switch Count 9362 IdealProcessor: 3
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address nt!ExpWorkerThread (0xfffff80081af42b0)
- Stack Init ffffec02dc787c90 Current ffffec02dc787820
- Base ffffec02dc788000 Limit ffffec02dc782000 Call 0000000000000000
- Priority 12 BasePriority 12 PriorityDecrement 0 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- ffffec02`dc787a58 fffff800`81bde4b5 : 00000000`00000162 ffffaa0e`38a80040 ffff9304`0b8e0708 00000000`ffffffff : nt!KeBugCheckEx
- ffffec02`dc787a60 fffff800`82018a4a : ffffffff`00000000 00000000`00000000 ffff9304`0b8e0710 00000000`00000000 : nt!KeAbPostRelease+0xcb5b5
- ffffec02`dc787ab0 fffff800`820187a5 : ffffaa0e`38a80040 fffff800`82018780 ffffaa0e`3806c930 fffff800`82018780 : nt!ExpWnfDispatchKernelSubscription+0x276
- ffffec02`dc787b40 fffff800`81af43b5 : ffffaa0e`3806c930 ffffaa0e`3806c900 ffffaa0e`45079e00 ffffaa0e`3806c930 : nt!ExpWnfWorkItemRoutine+0x25
- ffffec02`dc787b70 fffff800`81a6bcd5 : ffffaa0e`38a80040 00000000`00000080 ffffaa0e`3806f040 00000067`b4bbbdff : nt!ExpWorkerThread+0x105
- ffffec02`dc787c10 fffff800`81bc9998 : ffffbe01`c29c1180 ffffaa0e`38a80040 fffff800`81a6bc80 00000000`00000000 : nt!PspSystemThreadStartup+0x55
- ffffec02`dc787c60 00000000`00000000 : ffffec02`dc788000 ffffec02`dc782000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement