Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ========================== AUTO DUMP ANALYZER ==========================
- Auto Dump Analyzer
- Version: 0.91
- Time to analyze file(s): 00 hours and 01 minutes and 51 seconds
- ================================ SYSTEM ================================
- MANUFACTURER: Micro-Star International Co., Ltd.
- PRODUCT_NAME: MS-7B93
- VERSION: 1.0
- ================================= BIOS =================================
- VENDOR: American Megatrends Inc.
- VERSION: 1.72
- DATE: 04/22/2020
- ============================= MOTHERBOARD ==============================
- MANUFACTURER: Micro-Star International Co., Ltd.
- PRODUCT: MPG X570 GAMING PRO CARBON WIFI (MS-7B93)
- VERSION: 1.0
- ================================= RAM ==================================
- Size Speed Manufacturer Part No.
- -------------- -------------- ------------------- ----------------------
- 3000MHz Unknown Unknown
- 8192MB 3000MHz Unknown CMK16GX4M2B3000C15
- 3000MHz Unknown Unknown
- 8192MB 3000MHz Unknown CMK16GX4M2B3000C15
- ================================= CPU ==================================
- Processor Version: AMD Ryzen 5 3600 6-Core Processor
- COUNT: c
- MHZ: 3600
- VENDOR: AuthenticAMD
- FAMILY: 17
- MODEL: 71
- STEPPING: 0
- ================================== OS ==================================
- Product: WinNt, suite: TerminalServer SingleUserTS Personal
- Built by: 19041.1.amd64fre.vb_release.191206-1406
- BUILD_VERSION: 10.0.19041.329 (WinBuild.160101.0800)
- BUILD: 19041
- SERVICEPACK: 329
- PLATFORM_TYPE: x64
- NAME: Windows 10
- EDITION: Windows 10 WinNt TerminalServer SingleUserTS Personal
- BUILD_TIMESTAMP: unknown_date
- BUILDDATESTAMP: 160101.0800
- BUILDLAB: WinBuild
- BUILDOSVER: 10.0.19041.329
- =============================== DEBUGGER ===============================
- Microsoft (R) Windows Debugger Version 10.0.14321.1024 AMD64
- Copyright (c) Microsoft Corporation. All rights reserved.
- =============================== COMMENTS ===============================
- * Information gathered from different dump files may be different. If
- Windows updates between two dump files, two or more OS versions may
- be shown above.
- * If the user updates the BIOS between dump files, two or more versions
- and dates may be shown above.
- * More RAM information can be found below in a full BIOS section.
- ========================================================================
- ======================= Dump #1: ANALYZE VERBOSE =======================
- ======================= File: 063020-7406-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 19041 MP (12 procs) Free x64
- Kernel base = 0xfffff800`49000000 PsLoadedModuleList = 0xfffff800`49c2a2b0
- Debug session time: Tue Jun 30 10:58:03.391 2020 (UTC - 4:00)
- System Uptime: 1 days 20:02:38.026
- BugCheck 162, {ffffb481d5a88080, ffffd68511313000, ffffffff, 0}
- Probably caused by : memory_corruption
- Followup: memory_corruption
- KERNEL_AUTO_BOOST_INVALID_LOCK_RELEASE (162)
- A lock tracked by AutoBoost was released by a thread that did not own the lock.
- This is typically caused when some thread releases a lock on behalf of another
- thread (which is not legal with AutoBoost tracking enabled) or when some thread
- tries to release a lock it no longer owns.
- Arguments:
- Arg1: ffffb481d5a88080, The address of the thread
- Arg2: ffffd68511313000, The lock address
- Arg3: 00000000ffffffff, The session ID of the thread
- Arg4: 0000000000000000, Reserved
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- BUGCHECK_STR: 0x162
- PROCESS_NAME: DCv2.e
- CURRENT_IRQL: 0
- LAST_CONTROL_TRANSFER: from fffff800493fabaa to fffff800493dda20
- STACK_TEXT:
- ffff8386`d904af48 fffff800`493fabaa : 00000000`00000162 ffffb481`d5a88080 ffffd685`11313000 00000000`ffffffff : nt!KeBugCheckEx
- ffff8386`d904af50 fffff800`495f6916 : ffffd684`e23e28b5 00000000`00000000 00000000`00000000 00000000`00000000 : nt!ExReleasePushLockEx+0x1d4d9a
- ffff8386`d904afb0 fffff800`49621557 : ffffd684`ee087bf0 ffffd684`ee087bf0 ffff8386`d904b1d0 fffff800`00000006 : nt!CmpPerformSingleKcbCacheLookup+0x306
- ffff8386`d904b040 fffff800`495f9a2a : ffff8386`d9040000 ffff8386`d904b100 ffff8386`00000006 00000000`00000000 : nt!CmpPerformCompleteKcbCacheLookup+0x77
- ffff8386`d904b0d0 fffff800`495f1e63 : ffffb481`0000001c ffff8386`d904b420 ffff8386`d904b3d8 ffffb481`d4717a20 : nt!CmpDoParseKey+0x2da
- ffff8386`d904b370 fffff800`495f554e : fffff800`495f1b01 00000000`00000000 ffffb481`d4717a20 00000000`6d4e6201 : nt!CmpParseKey+0x2c3
- ffff8386`d904b510 fffff800`495f0faa : ffffb481`d4717a00 ffff8386`d904b778 00000000`00000040 ffffb481`c08bc820 : nt!ObpLookupObjectName+0x3fe
- ffff8386`d904b6e0 fffff800`495f0d8c : 00000000`00000000 00000000`00000000 00000000`00000000 ffffb481`c08bc820 : nt!ObOpenObjectByNameEx+0x1fa
- ffff8386`d904b810 fffff800`495f08b1 : 000000a0`7a6be5c8 ffff8386`d904bb80 00000000`00000001 fffff800`4920198e : nt!ObOpenObjectByName+0x5c
- ffff8386`d904b860 fffff800`495efe9f : ffffb481`d5a88080 fffff800`4960b8af 00000000`00000000 000000a0`7a6be600 : nt!CmOpenKey+0x2c1
- ffff8386`d904bac0 fffff800`493ef378 : ffffb481`d5a88000 ffffb481`cfacc9e0 ffffffff`ffffd8f0 ffffb481`00000000 : nt!NtOpenKeyEx+0xf
- ffff8386`d904bb00 00007ff8`a008d184 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
- 000000a0`7a6be4e8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff8`a008d184
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !FLTMGR
- fffff8004597cd05-fffff8004597cd06 2 bytes - FLTMGR!DeleteStreamListCtrlCallback+35
- [ 48 ff:4c 8b ]
- fffff8004597cd0c-fffff8004597cd10 5 bytes - FLTMGR!DeleteStreamListCtrlCallback+3c (+0x07)
- [ 0f 1f 44 00 00:e8 ff 5a 99 03 ]
- fffff8004597cd1a-fffff8004597cd1b 2 bytes - FLTMGR!DeleteStreamListCtrlCallback+4a (+0x0e)
- [ 48 ff:4c 8b ]
- fffff8004597cd21-fffff8004597cd25 5 bytes - FLTMGR!DeleteStreamListCtrlCallback+51 (+0x07)
- [ 0f 1f 44 00 00:e8 da 63 8a 03 ]
- fffff8004597cd6a-fffff8004597cd6b 2 bytes - FLTMGR!DeleteStreamListCtrlCallback+9a (+0x49)
- [ 48 ff:4c 8b ]
- fffff8004597cd71-fffff8004597cd77 7 bytes - FLTMGR!DeleteStreamListCtrlCallback+a1 (+0x07)
- [ 0f 1f 44 00 00 48 ff:e8 da 5b 8a 03 4c 8b ]
- fffff8004597cd7d-fffff8004597cd81 5 bytes - FLTMGR!DeleteStreamListCtrlCallback+ad (+0x0c)
- [ 0f 1f 44 00 00:e8 3e eb 97 03 ]
- 28 errors : !FLTMGR (fffff8004597cd05-fffff8004597cd81)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-06-30T14:58:03.000Z
- SUITE_MASK: 784
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #1: 3RD PARTY DRIVERS ======================
- Jul 09 2017 - NTIOLib_X64.sys - !!! Overclocking Software - NTIO Library http://www.msi.com/ This file may be installed with other software such as MSI Live Update and that is OK.
- Jul 09 2017 - NTIOLib_X64.sys - !!! Overclocking Software - NTIO Library http://www.msi.com/ This file may be installed with other software such as MSI Live Update and that is OK.
- Jul 09 2017 - NTIOLib_X64.sys - !!! Overclocking Software - NTIO Library http://www.msi.com/ This file may be installed with other software such as MSI Live Update and that is OK.
- May 28 2018 - I2cHkBurn.sys - MSI Gaming App driver or FINTEK FitGpBus Device driver (Feature Integration Technology)
- May 13 2019 - Netwtw08.sys - Intel(R) Wireless Networking driver
- Jul 24 2019 - AMDPCIDev.sys - Advanced Micro Devices PCI Device driver
- Sep 29 2019 - amdgpio2.sys - AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Oct 16 2019 - msio64.sys - MSI Gaming App driver
- Jan 17 2020 - Nahimic_Mirroring.sys - Nahimic driver https://www.nahimic.com/
- Jan 26 2020 - UcmCxUcsiNvppc.sys - NVIDIA USB Type-C Port Policy Controller driver
- Feb 12 2020 - e1r68x64.sys - Intel(R) Gigabit Adapter driver https://downloadcenter.intel.com/
- Apr 02 2020 - ibtusb.sys - Intel(R) Wireless Bluetooth(R) Filter driver (Intel Corporation)
- Apr 08 2020 - iqvsw64e.sys - Intel driver
- May 08 2020 - ene.sys - (Ptolemy Tech Co.) or ASUS RGB driver or Gigabyte RGB driver
- May 28 2020 - cfosspeed6.sys - cFosSpeed driver (cFos Software)
- Jun 09 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- Jun 21 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- ================== Dump #1: 3RD PARTY DRIVERS (FULL) ===================
- Image path: \??\C:\Program Files (x86)\MSI\One Dragon Center\Lib\NTIOLib_X64.sys
- Image name: NTIOLib_X64.sys
- Search : https://www.google.com/search?q=NTIOLib_X64.sys
- ADA Info : !!! Overclocking Software - NTIO Library http://www.msi.com/ This file may be installed with other software such as MSI Live Update and that is OK.
- Timestamp : Sun Jul 9 2017
- Image path: \??\C:\Program Files (x86)\MSI\One Dragon Center\Lib\SYS\NTIOLib_X64.sys
- Image name: NTIOLib_X64.sys
- Search : https://www.google.com/search?q=NTIOLib_X64.sys
- ADA Info : !!! Overclocking Software - NTIO Library http://www.msi.com/ This file may be installed with other software such as MSI Live Update and that is OK.
- Timestamp : Sun Jul 9 2017
- Image path: \??\C:\Program Files (x86)\MSI\One Dragon Center\Mystic_Light\Lib\NTIOLib_X64.sys
- Image name: NTIOLib_X64.sys
- Search : https://www.google.com/search?q=NTIOLib_X64.sys
- ADA Info : !!! Overclocking Software - NTIO Library http://www.msi.com/ This file may be installed with other software such as MSI Live Update and that is OK.
- Timestamp : Sun Jul 9 2017
- Image path: \SystemRoot\system32\drivers\I2cHkBurn.sys
- Image name: I2cHkBurn.sys
- Search : https://www.google.com/search?q=I2cHkBurn.sys
- ADA Info : MSI Gaming App driver or FINTEK FitGpBus Device driver (Feature Integration Technology)
- Timestamp : Mon May 28 2018
- Mapped memory image file: C:\ProgramData\dbg\sym\Netwtw08.sys\5CD9DF95910000\Netwtw08.sys
- Image path: \SystemRoot\System32\drivers\Netwtw08.sys
- Image name: Netwtw08.sys
- Search : https://www.google.com/search?q=Netwtw08.sys
- ADA Info : Intel(R) Wireless Networking driver
- Timestamp : Mon May 13 2019
- File version: 21.10.2.2
- Product version: 1.0.1.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- CompanyName: Intel Corporation
- ProductName: Intel® Wireless WiFi Link Adapter
- InternalName: .sys
- OriginalFilename: .sys
- FileVersion: 21.10.2.2
- FileDescription: Intel® Wireless WiFi Link Driver
- LegalCopyright: Copyright © Intel Corporation 2011
- Comments: NDIS650_MINIPORT
- Image path: \SystemRoot\System32\drivers\AMDPCIDev.sys
- Image name: AMDPCIDev.sys
- Search : https://www.google.com/search?q=AMDPCIDev.sys
- ADA Info : Advanced Micro Devices PCI Device driver
- Timestamp : Wed Jul 24 2019
- Image path: \SystemRoot\System32\drivers\amdgpio2.sys
- Image name: amdgpio2.sys
- Search : https://www.google.com/search?q=amdgpio2.sys
- ADA Info : AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Timestamp : Sun Sep 29 2019
- Image path: \??\C:\Program Files (x86)\MSI\One Dragon Center\Mystic_Light\msio64.sys
- Image name: msio64.sys
- Search : https://www.google.com/search?q=msio64.sys
- ADA Info : MSI Gaming App driver
- Timestamp : Wed Oct 16 2019
- Image path: \SystemRoot\System32\drivers\Nahimic_Mirroring.sys
- Image name: Nahimic_Mirroring.sys
- Search : https://www.google.com/search?q=Nahimic_Mirroring.sys
- ADA Info : Nahimic driver https://www.nahimic.com/
- Timestamp : Fri Jan 17 2020
- Image path: \SystemRoot\System32\DriverStore\FileRepository\nvppc.inf_amd64_0f22333f160a8f42\UcmCxUcsiNvppc.sys
- Image name: UcmCxUcsiNvppc.sys
- Search : https://www.google.com/search?q=UcmCxUcsiNvppc.sys
- ADA Info : NVIDIA USB Type-C Port Policy Controller driver
- Timestamp : Sun Jan 26 2020
- Image path: \SystemRoot\System32\drivers\e1r68x64.sys
- Image name: e1r68x64.sys
- Search : https://www.google.com/search?q=e1r68x64.sys
- ADA Info : Intel(R) Gigabit Adapter driver https://downloadcenter.intel.com/
- Timestamp : Wed Feb 12 2020
- Image path: \SystemRoot\System32\DriverStore\FileRepository\ibtusb.inf_amd64_94347ae3d824b51e\ibtusb.sys
- Image name: ibtusb.sys
- Search : https://www.google.com/search?q=ibtusb.sys
- ADA Info : Intel(R) Wireless Bluetooth(R) Filter driver (Intel Corporation)
- Timestamp : Thu Apr 2 2020
- Image path: \??\C:\Windows\system32\Drivers\iqvsw64e.sys
- Image name: iqvsw64e.sys
- Search : https://www.google.com/search?q=iqvsw64e.sys
- ADA Info : Intel driver
- Timestamp : Wed Apr 8 2020
- Image path: \??\C:\Windows\system32\drivers\ene.sys
- Image name: ene.sys
- Search : https://www.google.com/search?q=ene.sys
- ADA Info : (Ptolemy Tech Co.) or ASUS RGB driver or Gigabyte RGB driver
- Timestamp : Fri May 8 2020
- Image path: \SystemRoot\system32\DRIVERS\cfosspeed6.sys
- Image name: cfosspeed6.sys
- Search : https://www.google.com/search?q=cfosspeed6.sys
- ADA Info : cFosSpeed driver (cFos Software)
- Timestamp : Thu May 28 2020
- Image path: \SystemRoot\system32\drivers\nvhda64v.sys
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Tue Jun 9 2020
- Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_ccad5caddc3a3d35\nvlddmkm.sys
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Sun Jun 21 2020
- ====================== Dump #1: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- amdppm.sys Processor Device Driver
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- BthEnum.sys Bluetooth Bus Extender
- bthpan.sys Bluetooth Personal Area Networking
- BTHport.sys Bluetooth Bus driver (Microsoft)
- BTHUSB.sys Bluetooth Miniport driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CimFS.SYS Consumer IR Class Driver for eHome (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- dc1-controller.sys KMDF driver for DC1 Controller
- DevAuthE.sys Xbox Device Authentication Driver
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_dumpstorport.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_stornvme.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HdAudio.sys High Definition Audio Function driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- IntelTA.sys Intel Telemetry Driver
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kd.dll Local Kernal Debugger (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate_AuthenticAMD.dll AMD Microcode Update Library (Microsoft)
- Microsoft.Bluetooth.Legacy.LEEnumerator.sys Microsoft Bluetooth Legacy LE Enumerator driver (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- MpKslDrv.sys Microsoft Anti-malware Protection driver
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb10.sys Longhorn SMB Downlevel SubRdr (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msgpioclx.sys GPIO Class Extension Driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msquic.sys Windows QUIC Driver
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndiscap.sys Microsoft NDIS Packet Capture Filter Driver
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- ndisuio.sys NDIS User mode I/O driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- nwifi.sys NativeWiFi Miniport Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- qwavedrv.sys Quality Windows Audio Video Experience (qWave) Support driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdpvideominiport.sys RDP Video Miniport driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rfcomm.sys Bluetooth RFCOMM driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- stornvme.sys NVM Express Storport Miniport driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- UcmCx.sys USB Connector Manager KMDF Class Extension
- ucx01000.sys USB Controller Extension (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- umpass.sys Generic pass-through driver (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwifibus.sys Virtual Wireless Bus driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- vwifimp.sys Virtual WiFi Miniport Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- wdiwifi.sys WDI Driver Framework driver (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- xboxgip.sys Game Input Protocol Driver
- xinputhid.sys XINPUT filter driver for HID
- ====================== Dump #1: UNLOADED MODULES =======================
- fffff800`9e910000 fffff800`9e918000 amifldrv64.s
- fffff800`5c130000 fffff800`5c1c6000 e1r68x64.sys
- fffff800`5c090000 fffff800`5c126000 e1r68x64.sys
- fffff800`5b300000 fffff800`5b30c000 umpass.sys
- fffff800`55720000 fffff800`557b5000 e1r68x64.sys
- fffff800`5c1a0000 fffff800`5c1b4000 xinputhid.sy
- fffff800`5c1f0000 fffff800`5c1ff000 hiber_storpo
- fffff800`5b290000 fffff800`5b2bc000 hiber_stornv
- fffff800`5b2c0000 fffff800`5b2de000 hiber_dumpfv
- fffff800`5c1c0000 fffff800`5c1cc000 umpass.sys
- fffff800`55c00000 fffff800`55ee7000 BEDaisy.sys
- fffff800`5c110000 fffff800`5c11c000 umpass.sys
- fffff800`5c0f0000 fffff800`5c104000 xinputhid.sy
- fffff800`5c140000 fffff800`5c14f000 hiber_storpo
- fffff800`5c150000 fffff800`5c17c000 hiber_stornv
- fffff800`5c180000 fffff800`5c19e000 hiber_dumpfv
- fffff800`5c120000 fffff800`5c131000 MpKslDrv.sys
- fffff800`55c00000 fffff800`55eed000 BEDaisy.sys
- fffff800`5b330000 fffff800`5b341000 MpKsld845e74
- fffff800`5c090000 fffff800`5c09f000 hiber_storpo
- fffff800`5c0a0000 fffff800`5c0cc000 hiber_stornv
- fffff800`5c0d0000 fffff800`5c0ee000 hiber_dumpfv
- fffff800`5b300000 fffff800`5b314000 xinputhid.sy
- fffff800`55570000 fffff800`55581000 MpKslDrv.sys
- fffff800`5b320000 fffff800`5b32c000 umpass.sys
- fffff800`5a710000 fffff800`5a724000 xinputhid.sy
- fffff800`5b2a0000 fffff800`5b2af000 hiber_storpo
- fffff800`5b2b0000 fffff800`5b2dc000 hiber_stornv
- fffff800`5b2e0000 fffff800`5b2fe000 hiber_dumpfv
- fffff800`5b290000 fffff800`5b29c000 umpass.sys
- fffff800`551c0000 fffff800`551cf000 dump_storpor
- fffff800`54c00000 fffff800`54c2c000 dump_stornvm
- fffff800`54c50000 fffff800`54c6e000 dump_dumpfve
- fffff800`555d0000 fffff800`555ec000 dam.sys
- fffff800`4b3a0000 fffff800`4b3b1000 WdBoot.sys
- fffff800`4c450000 fffff800`4c460000 hwpolicy.sys
- ====================== Dump #1: BIOS INFORMATION =======================
- [SMBIOS Data Tables v2.8]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 2465 bytes]
- [BIOS Information (Type 0) - Length 26 - Handle 0000h]
- Vendor American Megatrends Inc.
- BIOS Version 1.72
- BIOS Starting Address Segment f000
- BIOS Release Date 04/22/2020
- BIOS ROM Size 1000000
- BIOS Characteristics
- 07: - PCI Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 27: - Keyboard Services Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 32: - BIOS Vendor Reserved
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 5
- BIOS Minor Revision 14
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- Manufacturer Micro-Star International Co., Ltd.
- Product Name MS-7B93
- Version 1.0
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
- Manufacturer Micro-Star International Co., Ltd.
- Product MPG X570 GAMING PRO CARBON WIFI (MS-7B93)
- Version 1.0
- Feature Flags 09h
- -469322016: - -469321968: - ÷7!ü
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 22 - Handle 0003h]
- Manufacturer Micro-Star International Co., Ltd.
- Chassis Type Desktop
- Version 1.0
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 3
- [OEM Strings (Type 11) - Length 5 - Handle 000bh]
- Number of Strings 1
- [System Configuration Options (Type 12) - Length 5 - Handle 000ch]
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 000eh]
- [Physical Memory Array (Type 16) - Length 23 - Handle 000fh]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 134217728KB
- Memory Error Inf Handle 000eh
- Number of Memory Devices 4
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0010h]
- Starting Address 00000000h
- Ending Address 0037ffffh
- Memory Array Handle 000fh
- Partition Width 02
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0011h]
- Starting Address 00400000h
- Ending Address 0107ffffh
- Memory Array Handle 000fh
- Partition Width 02
- [Cache Information (Type 7) - Length 19 - Handle 0012h]
- Socket Designation L1 - Cache
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0180h - 384K
- Installed Size 0180h - 384K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0013h]
- Socket Designation L2 - Cache
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 0c00h - 3072K
- Installed Size 0c00h - 3072K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0014h]
- Socket Designation L3 - Cache
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 8200h - 32768K
- Installed Size 8200h - 32768K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 16-way Set-Associative
- [Processor Information (Type 4) - Length 48 - Handle 0015h]
- Socket Designation AM4
- Processor Type Central Processor
- Processor Family 6bh - Specification Reserved
- Processor Manufacturer Advanced Micro Devices, Inc.
- Processor ID 100f8700fffb8b17
- Processor Version AMD Ryzen 5 3600 6-Core Processor
- Processor Voltage 8bh - 1.1V
- External Clock 100MHz
- Max Speed 4200MHz
- Current Speed 3600MHz
- Status Enabled Populated
- Processor Upgrade Specification Reserved
- L1 Cache Handle 0012h
- L2 Cache Handle 0013h
- L3 Cache Handle 0014h
- Part Number Unknown
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 0016h]
- [Memory Device (Type 17) - Length 40 - Handle 0017h]
- Physical Memory Array Handle 000fh
- Memory Error Info Handle 0016h
- Form Factor 02h - Unknown
- Device Locator DIMM 0
- Bank Locator P0 CHANNEL A
- Memory Type 02h - Unknown
- Type Detail 0004h - Unknown
- Speed 3000MHz
- Manufacturer Unknown
- Part Number Unknown
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 0018h]
- [Memory Device (Type 17) - Length 40 - Handle 0019h]
- Physical Memory Array Handle 000fh
- Memory Error Info Handle 0018h
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator DIMM 1
- Bank Locator P0 CHANNEL A
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 3000MHz
- Manufacturer Unknown
- Part Number CMK16GX4M2B3000C15
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 001ah]
- Starting Address 00000000h
- Ending Address 00ffffffh
- Memory Device Handle 0019h
- Mem Array Mapped Adr Handle 0011h
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 001bh]
- [Memory Device (Type 17) - Length 40 - Handle 001ch]
- Physical Memory Array Handle 000fh
- Memory Error Info Handle 001bh
- Form Factor 02h - Unknown
- Device Locator DIMM 0
- Bank Locator P0 CHANNEL B
- Memory Type 02h - Unknown
- Type Detail 0004h - Unknown
- Speed 3000MHz
- Manufacturer Unknown
- Part Number Unknown
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 001dh]
- [Memory Device (Type 17) - Length 40 - Handle 001eh]
- Physical Memory Array Handle 000fh
- Memory Error Info Handle 001dh
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator DIMM 1
- Bank Locator P0 CHANNEL B
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 3000MHz
- Manufacturer Unknown
- Part Number CMK16GX4M2B3000C15
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 001fh]
- Starting Address 00000000h
- Ending Address 00ffffffh
- Memory Device Handle 001eh
- Mem Array Mapped Adr Handle 0011h
- ========================== Dump #1: Extra #1 ===========================
- 3: kd> !verifier
- Verify Flags Level 0x00000000
- STANDARD FLAGS:
- [X] (0x00000000) Automatic Checks
- [ ] (0x00000001) Special pool
- [ ] (0x00000002) Force IRQL checking
- [ ] (0x00000008) Pool tracking
- [ ] (0x00000010) I/O verification
- [ ] (0x00000020) Deadlock detection
- [ ] (0x00000080) DMA checking
- [ ] (0x00000100) Security checks
- [ ] (0x00000800) Miscellaneous checks
- [ ] (0x00020000) DDI compliance checking
- ADDITIONAL FLAGS:
- [ ] (0x00000004) Randomized low resources simulation
- [ ] (0x00000200) Force pending I/O requests
- [ ] (0x00000400) IRP logging
- [ ] (0x00002000) Invariant MDL checking for stack
- [ ] (0x00004000) Invariant MDL checking for driver
- [ ] (0x00008000) Power framework delay fuzzing
- [ ] (0x00010000) Port/miniport interface checking
- [ ] (0x00040000) Systematic low resources simulation
- [ ] (0x00080000) DDI compliance checking (additional)
- [ ] (0x00200000) NDIS/WIFI verification
- [ ] (0x00800000) Kernel synchronization delay fuzzing
- [ ] (0x01000000) VM switch verification
- [ ] (0x02000000) Code integrity checks
- [X] Indicates flag is enabled
- Summary of All Verifier Statistics
- RaiseIrqls 0x0
- AcquireSpinLocks 0x0
- Synch Executions 0x0
- Trims 0x0
- Pool Allocations Attempted 0x0
- Pool Allocations Succeeded 0x0
- Pool Allocations Succeeded SpecialPool 0x0
- Pool Allocations With NO TAG 0x0
- Pool Allocations Failed 0x0
- Current paged pool allocations 0x0 for 00000000 bytes
- Peak paged pool allocations 0x0 for 00000000 bytes
- Current nonpaged pool allocations 0x0 for 00000000 bytes
- Peak nonpaged pool allocations 0x0 for 00000000 bytes
- ========================== Dump #1: Extra #2 ===========================
- 3: kd> !thread
- THREAD ffffb481d5a88080 Cid 093c.2dc0 Teb: 000000a07387a000 Win32Thread: 0000000000000000 RUNNING on processor 3
- Not impersonating
- GetUlongFromAddress: unable to read from fffff80049c1143c
- Owning Process ffffb481cef47080 Image: DCv2.e
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 10147713
- Context Switch Count 42535 IdealProcessor: 7
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address 0x00007ff8727bb530
- Stack Init ffff8386d904bc90 Current ffff8386d904b490
- Base ffff8386d904c000 Limit ffff8386d9046000 Call 0000000000000000
- Priority 8 BasePriority 6 PriorityDecrement 2 IoPriority 1 PagePriority 2
- Child-SP RetAddr : Args to Child : Call Site
- ffff8386`d904af48 fffff800`493fabaa : 00000000`00000162 ffffb481`d5a88080 ffffd685`11313000 00000000`ffffffff : nt!KeBugCheckEx
- ffff8386`d904af50 fffff800`495f6916 : ffffd684`e23e28b5 00000000`00000000 00000000`00000000 00000000`00000000 : nt!ExReleasePushLockEx+0x1d4d9a
- ffff8386`d904afb0 fffff800`49621557 : ffffd684`ee087bf0 ffffd684`ee087bf0 ffff8386`d904b1d0 fffff800`00000006 : nt!CmpPerformSingleKcbCacheLookup+0x306
- ffff8386`d904b040 fffff800`495f9a2a : ffff8386`d9040000 ffff8386`d904b100 ffff8386`00000006 00000000`00000000 : nt!CmpPerformCompleteKcbCacheLookup+0x77
- ffff8386`d904b0d0 fffff800`495f1e63 : ffffb481`0000001c ffff8386`d904b420 ffff8386`d904b3d8 ffffb481`d4717a20 : nt!CmpDoParseKey+0x2da
- ffff8386`d904b370 fffff800`495f554e : fffff800`495f1b01 00000000`00000000 ffffb481`d4717a20 00000000`6d4e6201 : nt!CmpParseKey+0x2c3
- ffff8386`d904b510 fffff800`495f0faa : ffffb481`d4717a00 ffff8386`d904b778 00000000`00000040 ffffb481`c08bc820 : nt!ObpLookupObjectName+0x3fe
- ffff8386`d904b6e0 fffff800`495f0d8c : 00000000`00000000 00000000`00000000 00000000`00000000 ffffb481`c08bc820 : nt!ObOpenObjectByNameEx+0x1fa
- ffff8386`d904b810 fffff800`495f08b1 : 000000a0`7a6be5c8 ffff8386`d904bb80 00000000`00000001 fffff800`4920198e : nt!ObOpenObjectByName+0x5c
- ffff8386`d904b860 fffff800`495efe9f : ffffb481`d5a88080 fffff800`4960b8af 00000000`00000000 000000a0`7a6be600 : nt!CmOpenKey+0x2c1
- ffff8386`d904bac0 fffff800`493ef378 : ffffb481`d5a88000 ffffb481`cfacc9e0 ffffffff`ffffd8f0 ffffb481`00000000 : nt!NtOpenKeyEx+0xf
- ffff8386`d904bb00 00007ff8`a008d184 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28 (TrapFrame @ ffff8386`d904bb00)
- 000000a0`7a6be4e8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff8`a008d184
- ========================================================================
- ======================= Dump #2: ANALYZE VERBOSE =======================
- ======================= File: 063020-7406-02.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 19041 MP (12 procs) Free x64
- Kernel base = 0xfffff806`80400000 PsLoadedModuleList = 0xfffff806`8102a2b0
- Debug session time: Tue Jun 30 11:56:03.468 2020 (UTC - 4:00)
- System Uptime: 0 days 0:57:30.102
- BugCheck 139, {1e, ffffec04f97eca90, ffffec04f97ec9e8, 0}
- Probably caused by : memory_corruption
- Followup: memory_corruption
- KERNEL_SECURITY_CHECK_FAILURE (139)
- A kernel component has corrupted a critical data structure. The corruption
- could potentially allow a malicious user to gain control of this machine.
- Arguments:
- Arg1: 000000000000001e, Type of memory safety violation
- Arg2: ffffec04f97eca90, Address of the trap frame for the exception that caused the bugcheck
- Arg3: ffffec04f97ec9e8, Address of the exception record for the exception that caused the bugcheck
- Arg4: 0000000000000000, Reserved
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- TRAP_FRAME: ffffec04f97eca90 -- (.trap 0xffffec04f97eca90)
- NOTE: The trap frame does not contain all registers.
- Some register values may be zeroed or incorrect.
- rax=0000000000000005 rbx=0000000000000000 rcx=000000000000001e
- rdx=fffff806810fcc80 rsi=0000000000000000 rdi=0000000000000000
- rip=fffff806808628db rsp=ffffec04f97ecc20 rbp=ffffdb812fcd5180
- r8=0000000000000000 r9=ffffec04f97ecfb0 r10=0000000000000000
- r11=000000000000000e r12=0000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=0000000000000000
- iopl=0 nv up ei pl zr na po nc
- nt!KeQueryValuesThread+0x17e62b:
- fffff806`808628db cd29 int 29h
- Resetting default scope
- EXCEPTION_RECORD: ffffec04f97ec9e8 -- (.exr 0xffffec04f97ec9e8)
- ExceptionAddress: fffff806808628db (nt!KeQueryValuesThread+0x000000000017e62b)
- ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
- ExceptionFlags: 00000001
- NumberParameters: 1
- Parameter[0]: 000000000000001e
- Subcode: 0x1e FAST_FAIL_INVALID_NEXT_THREAD
- CUSTOMER_CRASH_COUNT: 2
- BUGCHECK_STR: 0x139
- PROCESS_NAME: steam.exe
- CURRENT_IRQL: 2
- ERROR_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.
- EXCEPTION_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.
- EXCEPTION_CODE_STR: c0000409
- EXCEPTION_PARAMETER1: 000000000000001e
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- LAST_CONTROL_TRANSFER: from fffff806807ef929 to fffff806807dda20
- STACK_TEXT:
- ffffec04`f97ec768 fffff806`807ef929 : 00000000`00000139 00000000`0000001e ffffec04`f97eca90 ffffec04`f97ec9e8 : nt!KeBugCheckEx
- ffffec04`f97ec770 fffff806`807efd50 : fffff806`80751800 fffff806`80712284 ffff9507`96f96c98 fffff806`806ec455 : nt!KiBugCheckDispatch+0x69
- ffffec04`f97ec8b0 fffff806`807ee0e3 : 00000000`00000000 00000000`00000000 ffffcb0d`2cc69060 00000000`000001f0 : nt!KiFastFailDispatch+0xd0
- ffffec04`f97eca90 fffff806`808628db : ffff9507`8d012880 01f000d0`000000d0 0064006e`00000000 005c0073`0077006f : nt!KiRaiseSecurityCheckFailure+0x323
- ffffec04`f97ecc20 fffff806`80a95a31 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KeQueryValuesThread+0x17e62b
- ffffec04`f97ecca0 fffff806`80a956c2 : ffff9507`9bf4d660 ffff9507`9bf4d8e0 ffff9507`9d76d080 00000000`00000002 : nt!PsQueryStatisticsProcess+0x111
- ffffec04`f97ecd20 fffff806`809f8071 : 00000000`00000002 ffff9507`9bf4d080 00000000`ffffffff 00000000`00000000 : nt!ExpCopyProcessInfo+0x42
- ffffec04`f97ecda0 fffff806`809fbfc3 : 00000000`00f10000 00000000`00041e30 ffffec04`f97ed8e8 00000000`00000000 : nt!ExpGetProcessInformation+0x9f1
- ffffec04`f97ed400 fffff806`809fb6a7 : ffff9507`9d76d080 00000000`00000000 00000000`00000000 00000000`09bff860 : nt!ExpQuerySystemInformation+0x7d3
- ffffec04`f97edac0 fffff806`807ef378 : ffff9507`9d760000 ffff9507`9aa25080 ffffec04`f97edb18 ffffffff`ff676980 : nt!NtQuerySystemInformation+0x37
- ffffec04`f97edb00 00007ffc`c954b454 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
- 00000000`09afe5e8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffc`c954b454
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !win32kbase
- fffff7471da2aecc-fffff7471da2aecd 2 bytes - win32kbase!GreSetDCOwnerEx+6c
- [ 48 ff:4c 8b ]
- fffff7471da2aed3-fffff7471da2aed6 4 bytes - win32kbase!GreSetDCOwnerEx+73 (+0x07)
- [ 0f 1f 44 00:e8 48 a5 2b ]
- fffff7471da2aedb-fffff7471da2aedc 2 bytes - win32kbase!GreSetDCOwnerEx+7b (+0x08)
- [ 48 ff:4c 8b ]
- fffff7471da2aee2-fffff7471da2aee5 4 bytes - win32kbase!GreSetDCOwnerEx+82 (+0x07)
- [ 0f 1f 44 00:e8 39 a5 2b ]
- fffff7471da2af02-fffff7471da2af03 2 bytes - win32kbase!GreSetDCOwnerEx+a2 (+0x20)
- [ 48 ff:4c 8b ]
- fffff7471da2af09-fffff7471da2af0c 4 bytes - win32kbase!GreSetDCOwnerEx+a9 (+0x07)
- [ 0f 1f 44 00:e8 12 a5 2b ]
- fffff7471da2af0e-fffff7471da2af0f 2 bytes - win32kbase!GreSetDCOwnerEx+ae (+0x05)
- [ 48 ff:4c 8b ]
- fffff7471da2af15-fffff7471da2af18 4 bytes - win32kbase!GreSetDCOwnerEx+b5 (+0x07)
- [ 0f 1f 44 00:e8 06 a5 2b ]
- fffff7471dc8b167-fffff7471dc8b168 2 bytes - win32kbase!TraceLoggingRegisterEx_EtwRegister_EtwSetInformation+6b
- [ 48 ff:4c 8b ]
- fffff7471dc8b16e-fffff7471dc8b171 4 bytes - win32kbase!TraceLoggingRegisterEx_EtwRegister_EtwSetInformation+72 (+0x07)
- [ 0f 1f 44 00:e8 ad a2 05 ]
- fffff7471dc8b1dc-fffff7471dc8b1dd 2 bytes - win32kbase!CreateTlgAggregateSession+40 (+0x6e)
- [ 48 ff:4c 8b ]
- fffff7471dc8b1e3-fffff7471dc8b1e6 4 bytes - win32kbase!CreateTlgAggregateSession+47 (+0x07)
- [ 0f 1f 44 00:e8 38 a2 05 ]
- fffff7471dc8b545-fffff7471dc8b54a 6 bytes - win32kbase!tlgEnableCallback+45 (+0x362)
- [ ff 15 6d 8a ff ff:e8 56 9d 05 00 90 ]
- fffff7471dc8b5c8-fffff7471dc8b5c9 2 bytes - win32kbase!WmsgpPostMessage+4c (+0x83)
- [ 48 ff:4c 8b ]
- fffff7471dc8b5cf-fffff7471dc8b5d2 4 bytes - win32kbase!WmsgpPostMessage+53 (+0x07)
- [ 0f 1f 44 00:e8 4c 9e 05 ]
- fffff7471dc8b5e6-fffff7471dc8b5e7 2 bytes - win32kbase!WmsgpPostMessage+6a (+0x17)
- [ 48 ff:4c 8b ]
- fffff7471dc8b5ed-fffff7471dc8b5f0 4 bytes - win32kbase!WmsgpPostMessage+71 (+0x07)
- [ 0f 1f 44 00:e8 2e 9e 05 ]
- 54 errors : !win32kbase (fffff7471da2aecc-fffff7471dc8b5f0)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-06-30T15:56:03.000Z
- SUITE_MASK: 784
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #2: 3RD PARTY DRIVERS ======================
- May 13 2019 - Netwtw08.sys - Intel(R) Wireless Networking driver
- Jul 24 2019 - AMDPCIDev.sys - Advanced Micro Devices PCI Device driver
- Sep 29 2019 - amdgpio2.sys - AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Jan 17 2020 - Nahimic_Mirroring.sys - Nahimic driver https://www.nahimic.com/
- Jan 26 2020 - UcmCxUcsiNvppc.sys - NVIDIA USB Type-C Port Policy Controller driver
- Feb 12 2020 - e1r68x64.sys - Intel(R) Gigabit Adapter driver https://downloadcenter.intel.com/
- Apr 02 2020 - ibtusb.sys - Intel(R) Wireless Bluetooth(R) Filter driver (Intel Corporation)
- Apr 08 2020 - iqvsw64e.sys - Intel driver
- Jun 09 2020 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- Jun 21 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- ================== Dump #2: 3RD PARTY DRIVERS (FULL) ===================
- Mapped memory image file: C:\ProgramData\dbg\sym\Netwtw08.sys\5CD9DF95910000\Netwtw08.sys
- Image path: \SystemRoot\System32\drivers\Netwtw08.sys
- Image name: Netwtw08.sys
- Search : https://www.google.com/search?q=Netwtw08.sys
- ADA Info : Intel(R) Wireless Networking driver
- Timestamp : Mon May 13 2019
- File version: 21.10.2.2
- Product version: 1.0.1.0
- File flags: 0 (Mask 3F)
- File OS: 40004 NT Win32
- File type: 3.6 Driver
- File date: 00000000.00000000
- CompanyName: Intel Corporation
- ProductName: Intel® Wireless WiFi Link Adapter
- InternalName: .sys
- OriginalFilename: .sys
- FileVersion: 21.10.2.2
- FileDescription: Intel® Wireless WiFi Link Driver
- LegalCopyright: Copyright © Intel Corporation 2011
- Comments: NDIS650_MINIPORT
- Image path: \SystemRoot\System32\drivers\AMDPCIDev.sys
- Image name: AMDPCIDev.sys
- Search : https://www.google.com/search?q=AMDPCIDev.sys
- ADA Info : Advanced Micro Devices PCI Device driver
- Timestamp : Wed Jul 24 2019
- Image path: \SystemRoot\System32\drivers\amdgpio2.sys
- Image name: amdgpio2.sys
- Search : https://www.google.com/search?q=amdgpio2.sys
- ADA Info : AMD GPIO Controller Driver from Advanced Micro Devices http://support.amd.com/
- Timestamp : Sun Sep 29 2019
- Image path: \SystemRoot\System32\drivers\Nahimic_Mirroring.sys
- Image name: Nahimic_Mirroring.sys
- Search : https://www.google.com/search?q=Nahimic_Mirroring.sys
- ADA Info : Nahimic driver https://www.nahimic.com/
- Timestamp : Fri Jan 17 2020
- Image path: \SystemRoot\System32\DriverStore\FileRepository\nvppc.inf_amd64_0f22333f160a8f42\UcmCxUcsiNvppc.sys
- Image name: UcmCxUcsiNvppc.sys
- Search : https://www.google.com/search?q=UcmCxUcsiNvppc.sys
- ADA Info : NVIDIA USB Type-C Port Policy Controller driver
- Timestamp : Sun Jan 26 2020
- Image path: \SystemRoot\System32\drivers\e1r68x64.sys
- Image name: e1r68x64.sys
- Search : https://www.google.com/search?q=e1r68x64.sys
- ADA Info : Intel(R) Gigabit Adapter driver https://downloadcenter.intel.com/
- Timestamp : Wed Feb 12 2020
- Image path: \SystemRoot\System32\DriverStore\FileRepository\ibtusb.inf_amd64_94347ae3d824b51e\ibtusb.sys
- Image name: ibtusb.sys
- Search : https://www.google.com/search?q=ibtusb.sys
- ADA Info : Intel(R) Wireless Bluetooth(R) Filter driver (Intel Corporation)
- Timestamp : Thu Apr 2 2020
- Image path: \??\C:\Windows\system32\Drivers\iqvsw64e.sys
- Image name: iqvsw64e.sys
- Search : https://www.google.com/search?q=iqvsw64e.sys
- ADA Info : Intel driver
- Timestamp : Wed Apr 8 2020
- Image path: \SystemRoot\system32\drivers\nvhda64v.sys
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Tue Jun 9 2020
- Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_ccad5caddc3a3d35\nvlddmkm.sys
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Sun Jun 21 2020
- ====================== Dump #2: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- amdppm.sys Processor Device Driver
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- BthEnum.sys Bluetooth Bus Extender
- bthpan.sys Bluetooth Personal Area Networking
- BTHport.sys Bluetooth Bus driver (Microsoft)
- BTHUSB.sys Bluetooth Miniport driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CimFS.SYS Consumer IR Class Driver for eHome (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- dc1-controller.sys KMDF driver for DC1 Controller
- DevAuthE.sys Xbox Device Authentication Driver
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_dumpstorport.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_stornvme.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HdAudio.sys High Definition Audio Function driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- IntelTA.sys Intel Telemetry Driver
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kd.dll Local Kernal Debugger (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate_AuthenticAMD.dll AMD Microcode Update Library (Microsoft)
- Microsoft.Bluetooth.Legacy.LEEnumerator.sys Microsoft Bluetooth Legacy LE Enumerator driver (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- MpKslDrv.sys Microsoft Anti-malware Protection driver
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb10.sys Longhorn SMB Downlevel SubRdr (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msgpioclx.sys GPIO Class Extension Driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msquic.sys Windows QUIC Driver
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndiscap.sys Microsoft NDIS Packet Capture Filter Driver
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- ndisuio.sys NDIS User mode I/O driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- nwifi.sys NativeWiFi Miniport Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdpvideominiport.sys RDP Video Miniport driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rfcomm.sys Bluetooth RFCOMM driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- stornvme.sys NVM Express Storport Miniport driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- UcmCx.sys USB Connector Manager KMDF Class Extension
- ucx01000.sys USB Controller Extension (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- umpass.sys Generic pass-through driver (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwifibus.sys Virtual Wireless Bus driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- vwifimp.sys Virtual WiFi Miniport Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- wdiwifi.sys WDI Driver Framework driver (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- xboxgip.sys Game Input Protocol Driver
- xinputhid.sys XINPUT filter driver for HID
- ====================== Dump #2: UNLOADED MODULES =======================
- fffff806`7d600000 fffff806`7d8e7000 BEDaisy.sys
- fffff806`7eb60000 fffff806`7eb6c000 umpass.sys
- fffff806`923f0000 fffff806`92404000 xinputhid.sy
- fffff806`7eae0000 fffff806`7eaef000 hiber_storpo
- fffff806`7eaf0000 fffff806`7eb1c000 hiber_stornv
- fffff806`7eb20000 fffff806`7eb3e000 hiber_dumpfv
- fffff806`7ea30000 fffff806`7ea3c000 umpass.sys
- fffff806`7eac0000 fffff806`7eac8000 NTIOLib_X64.
- fffff806`8d060000 fffff806`8d069000 ene.sys
- fffff806`7eab0000 fffff806`7eab8000 NTIOLib_X64.
- fffff806`7eaa0000 fffff806`7eaa8000 NTIOLib_X64.
- fffff806`7ea50000 fffff806`7ea59000 msio64.sys
- fffff806`7ea60000 fffff806`7ea68000 NTIOLib_X64.
- fffff806`7ea40000 fffff806`7ea48000 NTIOLib_X64.
- fffff806`8cbf0000 fffff806`8cded000 cfosspeed6.s
- fffff806`7ea80000 fffff806`7ea91000 MpKslc3969c2
- fffff806`7ea70000 fffff806`7ea78000 amifldrv64.s
- fffff806`8d2b0000 fffff806`8d2bf000 dump_storpor
- fffff806`8d2f0000 fffff806`8d31c000 dump_stornvm
- fffff806`8d340000 fffff806`8d35e000 dump_dumpfve
- fffff806`8d0a0000 fffff806`8d0bc000 dam.sys
- fffff806`82da0000 fffff806`82db1000 WdBoot.sys
- fffff806`83e50000 fffff806`83e60000 hwpolicy.sys
- ====================== Dump #2: BIOS INFORMATION =======================
- [SMBIOS Data Tables v2.8]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 2465 bytes]
- [BIOS Information (Type 0) - Length 26 - Handle 0000h]
- Vendor American Megatrends Inc.
- BIOS Version 1.72
- BIOS Starting Address Segment f000
- BIOS Release Date 04/22/2020
- BIOS ROM Size 1000000
- BIOS Characteristics
- 07: - PCI Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 27: - Keyboard Services Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 32: - BIOS Vendor Reserved
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 5
- BIOS Minor Revision 14
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- Manufacturer Micro-Star International Co., Ltd.
- Product Name MS-7B93
- Version 1.0
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
- Manufacturer Micro-Star International Co., Ltd.
- Product MPG X570 GAMING PRO CARBON WIFI (MS-7B93)
- Version 1.0
- Feature Flags 09h
- -409880864: - -409880816: - ÷7!ü
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 22 - Handle 0003h]
- Manufacturer Micro-Star International Co., Ltd.
- Chassis Type Desktop
- Version 1.0
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 3
- [OEM Strings (Type 11) - Length 5 - Handle 000bh]
- Number of Strings 1
- [System Configuration Options (Type 12) - Length 5 - Handle 000ch]
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 000eh]
- [Physical Memory Array (Type 16) - Length 23 - Handle 000fh]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 134217728KB
- Memory Error Inf Handle 000eh
- Number of Memory Devices 4
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0010h]
- Starting Address 00000000h
- Ending Address 0037ffffh
- Memory Array Handle 000fh
- Partition Width 02
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0011h]
- Starting Address 00400000h
- Ending Address 0107ffffh
- Memory Array Handle 000fh
- Partition Width 02
- [Cache Information (Type 7) - Length 19 - Handle 0012h]
- Socket Designation L1 - Cache
- Cache Configuration 0180h - WB Enabled Int NonSocketed L1
- Maximum Cache Size 0180h - 384K
- Installed Size 0180h - 384K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0013h]
- Socket Designation L2 - Cache
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 0c00h - 3072K
- Installed Size 0c00h - 3072K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 8-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0014h]
- Socket Designation L3 - Cache
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 8200h - 32768K
- Installed Size 8200h - 32768K
- Supported SRAM Type 0010h - Pipeline-Burst
- Current SRAM Type 0010h - Pipeline-Burst
- Cache Speed 1ns
- Error Correction Type Specification Reserved
- System Cache Type Unified
- Associativity 16-way Set-Associative
- [Processor Information (Type 4) - Length 48 - Handle 0015h]
- Socket Designation AM4
- Processor Type Central Processor
- Processor Family 6bh - Specification Reserved
- Processor Manufacturer Advanced Micro Devices, Inc.
- Processor ID 100f8700fffb8b17
- Processor Version AMD Ryzen 5 3600 6-Core Processor
- Processor Voltage 8bh - 1.1V
- External Clock 100MHz
- Max Speed 4200MHz
- Current Speed 3600MHz
- Status Enabled Populated
- Processor Upgrade Specification Reserved
- L1 Cache Handle 0012h
- L2 Cache Handle 0013h
- L3 Cache Handle 0014h
- Part Number Unknown
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 0016h]
- [Memory Device (Type 17) - Length 40 - Handle 0017h]
- Physical Memory Array Handle 000fh
- Memory Error Info Handle 0016h
- Form Factor 02h - Unknown
- Device Locator DIMM 0
- Bank Locator P0 CHANNEL A
- Memory Type 02h - Unknown
- Type Detail 0004h - Unknown
- Speed 3000MHz
- Manufacturer Unknown
- Part Number Unknown
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 0018h]
- [Memory Device (Type 17) - Length 40 - Handle 0019h]
- Physical Memory Array Handle 000fh
- Memory Error Info Handle 0018h
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator DIMM 1
- Bank Locator P0 CHANNEL A
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 3000MHz
- Manufacturer Unknown
- Part Number CMK16GX4M2B3000C15
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 001ah]
- Starting Address 00000000h
- Ending Address 00ffffffh
- Memory Device Handle 0019h
- Mem Array Mapped Adr Handle 0011h
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 001bh]
- [Memory Device (Type 17) - Length 40 - Handle 001ch]
- Physical Memory Array Handle 000fh
- Memory Error Info Handle 001bh
- Form Factor 02h - Unknown
- Device Locator DIMM 0
- Bank Locator P0 CHANNEL B
- Memory Type 02h - Unknown
- Type Detail 0004h - Unknown
- Speed 3000MHz
- Manufacturer Unknown
- Part Number Unknown
- [32Bit Memory Error Information (Type 18) - Length 23 - Handle 001dh]
- [Memory Device (Type 17) - Length 40 - Handle 001eh]
- Physical Memory Array Handle 000fh
- Memory Error Info Handle 001dh
- Total Width 64 bits
- Data Width 64 bits
- Size 8192MB
- Form Factor 09h - DIMM
- Device Locator DIMM 1
- Bank Locator P0 CHANNEL B
- Memory Type 1ah - Specification Reserved
- Type Detail 4080h - Synchronous
- Speed 3000MHz
- Manufacturer Unknown
- Part Number CMK16GX4M2B3000C15
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 001fh]
- Starting Address 00000000h
- Ending Address 00ffffffh
- Memory Device Handle 001eh
- Mem Array Mapped Adr Handle 0011h
- ========================== Dump #2: Extra #1 ===========================
- 11: kd> !verifier
- Verify Flags Level 0x00000000
- STANDARD FLAGS:
- [X] (0x00000000) Automatic Checks
- [ ] (0x00000001) Special pool
- [ ] (0x00000002) Force IRQL checking
- [ ] (0x00000008) Pool tracking
- [ ] (0x00000010) I/O verification
- [ ] (0x00000020) Deadlock detection
- [ ] (0x00000080) DMA checking
- [ ] (0x00000100) Security checks
- [ ] (0x00000800) Miscellaneous checks
- [ ] (0x00020000) DDI compliance checking
- ADDITIONAL FLAGS:
- [ ] (0x00000004) Randomized low resources simulation
- [ ] (0x00000200) Force pending I/O requests
- [ ] (0x00000400) IRP logging
- [ ] (0x00002000) Invariant MDL checking for stack
- [ ] (0x00004000) Invariant MDL checking for driver
- [ ] (0x00008000) Power framework delay fuzzing
- [ ] (0x00010000) Port/miniport interface checking
- [ ] (0x00040000) Systematic low resources simulation
- [ ] (0x00080000) DDI compliance checking (additional)
- [ ] (0x00200000) NDIS/WIFI verification
- [ ] (0x00800000) Kernel synchronization delay fuzzing
- [ ] (0x01000000) VM switch verification
- [ ] (0x02000000) Code integrity checks
- [X] Indicates flag is enabled
- Summary of All Verifier Statistics
- RaiseIrqls 0x0
- AcquireSpinLocks 0x0
- Synch Executions 0x0
- Trims 0x0
- Pool Allocations Attempted 0x0
- Pool Allocations Succeeded 0x0
- Pool Allocations Succeeded SpecialPool 0x0
- Pool Allocations With NO TAG 0x0
- Pool Allocations Failed 0x0
- Current paged pool allocations 0x0 for 00000000 bytes
- Peak paged pool allocations 0x0 for 00000000 bytes
- Current nonpaged pool allocations 0x0 for 00000000 bytes
- Peak nonpaged pool allocations 0x0 for 00000000 bytes
- ========================== Dump #2: Extra #2 ===========================
- 11: kd> !thread
- THREAD ffff95079d76d080 Cid 1cfc.36dc Teb: 0000000000d86000 Win32Thread: ffff950792a44310 RUNNING on processor b
- Not impersonating
- GetUlongFromAddress: unable to read from fffff8068101143c
- Owning Process ffff950798d51080 Image: steam.exe
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 220742
- Context Switch Count 4357 IdealProcessor: 5
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address 0x000000005da8b380
- Stack Init ffffec04f97edc90 Current ffffec04f97ed6a0
- Base ffffec04f97ee000 Limit ffffec04f97e8000 Call 0000000000000000
- Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- ffffec04`f97ec768 fffff806`807ef929 : 00000000`00000139 00000000`0000001e ffffec04`f97eca90 ffffec04`f97ec9e8 : nt!KeBugCheckEx
- ffffec04`f97ec770 fffff806`807efd50 : fffff806`80751800 fffff806`80712284 ffff9507`96f96c98 fffff806`806ec455 : nt!KiBugCheckDispatch+0x69
- ffffec04`f97ec8b0 fffff806`807ee0e3 : 00000000`00000000 00000000`00000000 ffffcb0d`2cc69060 00000000`000001f0 : nt!KiFastFailDispatch+0xd0
- ffffec04`f97eca90 fffff806`808628db : ffff9507`8d012880 01f000d0`000000d0 0064006e`00000000 005c0073`0077006f : nt!KiRaiseSecurityCheckFailure+0x323 (TrapFrame @ ffffec04`f97eca90)
- ffffec04`f97ecc20 fffff806`80a95a31 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KeQueryValuesThread+0x17e62b
- ffffec04`f97ecca0 fffff806`80a956c2 : ffff9507`9bf4d660 ffff9507`9bf4d8e0 ffff9507`9d76d080 00000000`00000002 : nt!PsQueryStatisticsProcess+0x111
- ffffec04`f97ecd20 fffff806`809f8071 : 00000000`00000002 ffff9507`9bf4d080 00000000`ffffffff 00000000`00000000 : nt!ExpCopyProcessInfo+0x42
- ffffec04`f97ecda0 fffff806`809fbfc3 : 00000000`00f10000 00000000`00041e30 ffffec04`f97ed8e8 00000000`00000000 : nt!ExpGetProcessInformation+0x9f1
- ffffec04`f97ed400 fffff806`809fb6a7 : ffff9507`9d76d080 00000000`00000000 00000000`00000000 00000000`09bff860 : nt!ExpQuerySystemInformation+0x7d3
- ffffec04`f97edac0 fffff806`807ef378 : ffff9507`9d760000 ffff9507`9aa25080 ffffec04`f97edb18 ffffffff`ff676980 : nt!NtQuerySystemInformation+0x37
- ffffec04`f97edb00 00007ffc`c954b454 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28 (TrapFrame @ ffffec04`f97edb00)
- 00000000`09afe5e8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffc`c954b454
Add Comment
Please, Sign In to add comment