Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ========================== AUTO DUMP ANALYZER ==========================
- Auto Dump Analyzer
- Version: 0.91
- Time to analyze file(s): 00 hours and 00 minutes and 29 seconds
- ================================= CPU ==================================
- COUNT: c
- MHZ: 3696
- VENDOR: GenuineIntel
- FAMILY: 6
- MODEL: 9e
- STEPPING: a
- ================================== OS ==================================
- Product: WinNt, suite: TerminalServer SingleUserTS Personal
- BUILD_VERSION: 10.0.19041.330 (WinBuild.160101.0800)
- BUILD: 19041
- SERVICEPACK: 330
- PLATFORM_TYPE: x64
- NAME: Windows 10
- EDITION: Windows 10 WinNt TerminalServer SingleUserTS Personal
- BUILD_TIMESTAMP: unknown_date
- BUILDDATESTAMP: 160101.0800
- BUILDLAB: WinBuild
- BUILDOSVER: 10.0.19041.330
- =============================== DEBUGGER ===============================
- Microsoft (R) Windows Debugger Version 10.0.14321.1024 AMD64
- Copyright (c) Microsoft Corporation. All rights reserved.
- =============================== COMMENTS ===============================
- * Information gathered from different dump files may be different. If
- Windows updates between two dump files, two or more OS versions may
- be shown above.
- * Additional BIOS information was not included in the dump file(s). This
- can be caused by an outdated BIOS.
- ========================================================================
- ======================= Dump #1: ANALYZE VERBOSE =======================
- ======================= File: 062620-4906-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 19041 MP (12 procs) Free x64
- Kernel base = 0xfffff802`5ac00000 PsLoadedModuleList = 0xfffff802`5b82a2b0
- Debug session time: Fri Jun 26 12:31:19.743 2020 (UTC - 4:00)
- System Uptime: 0 days 2:54:33.157
- BugCheck 1000007E, {ffffffffc0000005, fffff8025afe5957, ffffae87963c9e48, ffffae87963c9680}
- Probably caused by : memory_corruption ( nt!MiGetPage+fc )
- Followup: MachineOwner
- SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
- This is a very common bugcheck. Usually the exception address pinpoints
- the driver/function that caused the problem. Always note this address
- as well as the link date of the driver/image that contains this address.
- Some common problems are exception code 0x80000003. This means a hard
- coded breakpoint or assertion was hit, but this system was booted
- /NODEBUG. This is not supposed to happen as developers should never have
- hardcoded breakpoints in retail code, but ...
- If this happens, make sure a debugger gets connected, and the
- system is booted /DEBUG. This will let us see why this breakpoint is
- happening.
- Arguments:
- Arg1: ffffffffc0000005, The exception code that was not handled
- Arg2: fffff8025afe5957, The address that the exception occurred at
- Arg3: ffffae87963c9e48, Exception Record Address
- Arg4: ffffae87963c9680, Context Record Address
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- DUMP_FILE_ATTRIBUTES: 0x8
- Kernel Generated Triage Dump
- EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.
- FAULTING_IP:
- nt!ExpInterlockedPopEntrySListFault+0
- fffff802`5afe5957 498b08 mov rcx,qword ptr [r8]
- EXCEPTION_RECORD: ffffae87963c9e48 -- (.exr 0xffffae87963c9e48)
- ExceptionAddress: fffff8025afe5957 (nt!ExpInterlockedPopEntrySListFault)
- ExceptionCode: c0000005 (Access violation)
- ExceptionFlags: 00000000
- NumberParameters: 2
- Parameter[0]: 0000000000000000
- Parameter[1]: ffffffffffffffff
- Attempt to read from address ffffffffffffffff
- CONTEXT: ffffae87963c9680 -- (.cxr 0xffffae87963c9680)
- rax=00000000fa48000e rbx=0000000000000000 rcx=ffffd70000006330
- rdx=0003b3e006ff0990 rsi=0000000000000000 rdi=0000000000000000
- rip=fffff8025afe5957 rsp=ffffae87963ca080 rbp=0000000000000000
- r8=0003b3e006ff0990 r9=0000000000000000 r10=ffffd70000006330
- r11=fffff8025ac09f18 r12=fffff8025ac09f18 r13=0000000000000001
- r14=fffff8025b850ac0 r15=0000000000000001
- iopl=0 nv up ei pl nz na po nc
- cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050206
- nt!ExpInterlockedPopEntrySListFault:
- fffff802`5afe5957 498b08 mov rcx,qword ptr [r8] ds:002b:0003b3e0`06ff0990=????????????????
- Resetting default scope
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
- PROCESS_NAME: System
- CURRENT_IRQL: 0
- ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.
- EXCEPTION_CODE_STR: c0000005
- EXCEPTION_PARAMETER1: 0000000000000000
- EXCEPTION_PARAMETER2: ffffffffffffffff
- FOLLOWUP_IP:
- nt!MiGetPage+fc
- fffff802`5ae1836c 4c8bf0 mov r14,rax
- READ_ADDRESS: fffff8025b8fa388: Unable to get MiVisibleState
- ffffffffffffffff
- BUGCHECK_STR: AV
- LAST_CONTROL_TRANSFER: from fffff8025ae1836c to fffff8025afe5957
- STACK_TEXT:
- ffffae87`963ca080 fffff802`5ae1836c : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!ExpInterlockedPopEntrySListFault
- ffffae87`963ca090 fffff802`5ae17972 : fffff802`5b850ac0 00000000`00000033 00000000`00000033 00000000`00000000 : nt!MiGetPage+0xfc
- ffffae87`963ca170 fffff802`5b266738 : e18bb608`0bc004c0 00000000`00000010 ffff9e87`cef7f698 0a000001`f460f821 : nt!MiGetPageChain+0x172
- ffffae87`963ca3d0 fffff802`5b245245 : 00000000`00000000 ffffe18b`9275a510 ffffe18b`85142040 00000000`00000000 : nt!MiPfPrepareSequentialReadList+0x598
- ffffae87`963ca4e0 fffff802`5aef9bdf : ffffe18b`8efb3a20 ffffae87`963ca6f0 00000000`00000000 ffffe18b`92165800 : nt!MmPrefetchForCacheManager+0x75
- ffffae87`963ca540 fffff802`5afa0b30 : ffffe18b`00010000 00000000`00000000 00000000`57ec3cc1 ffffe18b`85142040 : nt!CcAsyncReadPrefetch+0x13f
- ffffae87`963ca5f0 fffff802`5af46715 : ffffe18b`85142040 ffffe18b`85142040 fffff802`5afa09a0 ffffe18b`851faf60 : nt!CcAsyncReadWorker+0x190
- ffffae87`963cab10 fffff802`5afe5078 : ffffb001`ead5f180 ffffe18b`85142040 fffff802`5af466c0 00000000`00000000 : nt!PspSystemThreadStartup+0x55
- ffffae87`963cab60 00000000`00000000 : ffffae87`963cb000 ffffae87`963c4000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
- THREAD_SHA1_HASH_MOD_FUNC: b2dc7b3c8b3b222476f04821cf66e3a07b8ce974
- THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 531f8e52d989e92424937027323880edb675d177
- THREAD_SHA1_HASH_MOD: 9f457f347057f10e1df248e166a3e95e6570ecfe
- FAULT_INSTR_CODE: 48f08b4c
- SYMBOL_STACK_INDEX: 1
- SYMBOL_NAME: nt!MiGetPage+fc
- FOLLOWUP_NAME: MachineOwner
- MODULE_NAME: nt
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- IMAGE_VERSION: 10.0.19041.330
- STACK_COMMAND: .cxr 0xffffae87963c9680 ; kb
- IMAGE_NAME: memory_corruption
- BUCKET_ID_FUNC_OFFSET: fc
- FAILURE_BUCKET_ID: AV_nt!MiGetPage
- BUCKET_ID: AV_nt!MiGetPage
- PRIMARY_PROBLEM_CLASS: AV_nt!MiGetPage
- TARGET_TIME: 2020-06-26T16:31:19.000Z
- SUITE_MASK: 784
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:av_nt!migetpage
- FAILURE_ID_HASH: {f2081220-629b-308b-003b-b589256b0abf}
- Followup: MachineOwner
- ====================== Dump #1: 3RD PARTY DRIVERS ======================
- Oct 09 2015 - wdcsam64.sys - Western Digital SCSI Arcitecture Model (SAM) WDM driver https://support.wdc.com/
- Oct 04 2016 - DisplayLinkXRUsbIo_x64_2.1.6.8682.sys - DisplayLink XR USB driver
- Jan 21 2019 - imaucxhpal.sys - MA-USB (UCX) HPAL driver
- Jan 21 2019 - iwigig.sys - WiGig MAC driver (Intel)
- Mar 19 2019 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- Apr 04 2019 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
- May 07 2019 - e1d68x64.sys - Intel(R) Gigabit Adapter driver
- Oct 02 2019 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- ================== Dump #1: 3RD PARTY DRIVERS (FULL) ===================
- Image name: wdcsam64.sys
- Search : https://www.google.com/search?q=wdcsam64.sys
- ADA Info : Western Digital SCSI Arcitecture Model (SAM) WDM driver https://support.wdc.com/
- Timestamp : Fri Oct 9 2015
- Image name: DisplayLinkXRUsbIo_x64_2.1.6.8682.sys
- Search : https://www.google.com/search?q=DisplayLinkXRUsbIo_x64_2.1.6.8682.sys
- ADA Info : DisplayLink XR USB driver
- Timestamp : Tue Oct 4 2016
- Image name: imaucxhpal.sys
- Search : https://www.google.com/search?q=imaucxhpal.sys
- ADA Info : MA-USB (UCX) HPAL driver
- Timestamp : Mon Jan 21 2019
- Image name: iwigig.sys
- Search : https://www.google.com/search?q=iwigig.sys
- ADA Info : WiGig MAC driver (Intel)
- Timestamp : Mon Jan 21 2019
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Tue Mar 19 2019
- Image name: TeeDriverW8x64.sys
- Search : https://www.google.com/search?q=TeeDriverW8x64.sys
- ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Timestamp : Thu Apr 4 2019
- Image name: e1d68x64.sys
- Search : https://www.google.com/search?q=e1d68x64.sys
- ADA Info : Intel(R) Gigabit Adapter driver
- Timestamp : Tue May 7 2019
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Wed Oct 2 2019
- ====================== Dump #1: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- acpipagr.sys ACPI Processor Aggregator Device driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CimFS.SYS Consumer IR Class Driver for eHome (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storport.sys Provides disk access during crash dump file generation (Microsoft)
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HdAudio.sys High Definition Audio Function driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- intelppm.sys Processor Device Driver (Microsoft)
- IntelTA.sys Intel Telemetry Driver
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kdcom.dll Kernel Debugger HW Extension DLL (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate.dll Media Center Update (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- MpKslDrv.sys Microsoft Anti-malware Protection driver
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb10.sys Longhorn SMB Downlevel SubRdr (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- MSKSSRV.sys MS KS Server driver
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msquic.sys Windows QUIC Driver
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndiscap.sys Microsoft NDIS Packet Capture Filter Driver
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdpvideominiport.sys RDP Video Miniport driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- serenum.sys Serial Port Enumerator (Microsoft)
- serial.sys Serial Device Driver
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- stornvme.sys NVM Express Storport Miniport driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- ucx01000.sys USB Controller Extension (Microsoft)
- udfs.sys UDF File System driver (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbaudio2.sys Microsoft USB Audio Class 2.0 Driver
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- USBSTOR.SYS USB Mass Storage Class driver (Microsoft)
- usbvideo.sys USB Video Class Driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WpdUpFltr.sys Portable Device Upper Class Filter driver (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- WUDFRd.sys Windows Driver Foundation - User-mode Driver Framework Reflector driver (Microsoft)
- ====================== Dump #1: UNLOADED MODULES =======================
- fffff802`58340000 fffff802`5834c000 WdmCompanion
- fffff802`58290000 fffff802`582d6000 usbaudio2.sy
- fffff802`58280000 fffff802`58290000 DisplayLinkX
- fffff802`5a170000 fffff802`5a1b6000 usbaudio2.sy
- fffff802`5a160000 fffff802`5a170000 DisplayLinkX
- fffff802`58260000 fffff802`58271000 MSKSSRV.sys
- fffff802`5a1c0000 fffff802`5a1cc000 WdmCompanion
- fffff802`5a0d0000 fffff802`5a0df000 hiber_storpo
- fffff802`5a0e0000 fffff802`5a113000 hiber_storah
- fffff802`5a120000 fffff802`5a13e000 hiber_dumpfv
- fffff802`73320000 fffff802`7333c000 monitor.sys
- fffff802`746c0000 fffff802`75c36000 nvlddmkm.sys
- fffff802`75c40000 fffff802`75c5c000 monitor.sys
- fffff802`73300000 fffff802`7331c000 monitor.sys
- fffff802`72950000 fffff802`7296c000 monitor.sys
- fffff802`712e0000 fffff802`712ef000 dump_storpor
- fffff802`71330000 fffff802`71363000 dump_storahc
- fffff802`71390000 fffff802`713ae000 dump_dumpfve
- fffff802`72570000 fffff802`725c5000 WUDFRd.sys
- fffff802`710d0000 fffff802`710ec000 dam.sys
- fffff802`5dc00000 fffff802`5dc11000 WdBoot.sys
- fffff802`5ecb0000 fffff802`5ecc0000 hwpolicy.sys
- ====================== Dump #1: BIOS INFORMATION =======================
- sysinfo: could not find necessary interfaces.
- sysinfo: note that mssmbios.sys must be loaded (XPSP2+).
- ========================== Dump #1: Extra #1 ===========================
- 3: kd> !verifier
- fffff8025b82a6c0: Unable to get verifier list.
- ========================== Dump #1: Extra #2 ===========================
- 3: kd> !thread
- THREAD ffffe18b85142040 Cid 0004.0088 Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor 3
- IRP List:
- Unable to read nt!_IRP @ ffffe18b953f6940
- Not impersonating
- GetUlongFromAddress: unable to read from fffff8025b81143c
- Owning Process ffffe18b8509c040 Image: System
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 670282
- Context Switch Count 33106 IdealProcessor: 3
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address nt!CcAsyncReadWorker (0xfffff8025afa09a0)
- Stack Init ffffae87963cab90 Current ffffae87963ca0b0
- Base ffffae87963cb000 Limit ffffae87963c4000 Call 0000000000000000
- Priority 9 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- ffffae87`963ca080 fffff802`5ae1836c : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!ExpInterlockedPopEntrySListFault
- ffffae87`963ca090 fffff802`5ae17972 : fffff802`5b850ac0 00000000`00000033 00000000`00000033 00000000`00000000 : nt!MiGetPage+0xfc
- ffffae87`963ca170 fffff802`5b266738 : e18bb608`0bc004c0 00000000`00000010 ffff9e87`cef7f698 0a000001`f460f821 : nt!MiGetPageChain+0x172
- ffffae87`963ca3d0 fffff802`5b245245 : 00000000`00000000 ffffe18b`9275a510 ffffe18b`85142040 00000000`00000000 : nt!MiPfPrepareSequentialReadList+0x598
- ffffae87`963ca4e0 fffff802`5aef9bdf : ffffe18b`8efb3a20 ffffae87`963ca6f0 00000000`00000000 ffffe18b`92165800 : nt!MmPrefetchForCacheManager+0x75
- ffffae87`963ca540 fffff802`5afa0b30 : ffffe18b`00010000 00000000`00000000 00000000`57ec3cc1 ffffe18b`85142040 : nt!CcAsyncReadPrefetch+0x13f
- ffffae87`963ca5f0 fffff802`5af46715 : ffffe18b`85142040 ffffe18b`85142040 fffff802`5afa09a0 ffffe18b`851faf60 : nt!CcAsyncReadWorker+0x190
- ffffae87`963cab10 fffff802`5afe5078 : ffffb001`ead5f180 ffffe18b`85142040 fffff802`5af466c0 00000000`00000000 : nt!PspSystemThreadStartup+0x55
- ffffae87`963cab60 00000000`00000000 : ffffae87`963cb000 ffffae87`963c4000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement