Advertisement
Guest User

Untitled

a guest
Aug 17th, 2017
687
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 50.02 KB | None | 0 0
  1. Microsoft (R) Windows Debugger Version 10.0.14321.1024 X86
  2. Copyright (c) Microsoft Corporation. All rights reserved.
  3.  
  4. Auto Dump Analyzer by gardenman
  5. Time to debug file(s): 00 hours and 07 minutes and 16 seconds
  6.  
  7. =========================== BRIEF BIOS INFO ============================
  8. DATE: 03/22/2017
  9. VERSION: 0906
  10. VENDOR: American Megatrends Inc.
  11.  
  12. =========================== MOTHERBOARD INFO ===========================
  13. VERSION: Rev 1.xx
  14. PRODUCT: STRIX Z270F GAMING
  15. MANUFACTURER: ASUSTeK COMPUTER INC.
  16.  
  17. =============================== CPU INFO ===============================
  18. Processor Version: Intel(R) Core(TM) i7-7700K CPU @ 4.20GHz
  19. MICROCODE: 6,9e,9,0 (F,M,S,R) SIG: 42'00000000 (cache) 42'00000000 (init)
  20. STEPPING: 9
  21. MODEL: 9e
  22. FAMILY: 6
  23. VENDOR: GenuineIntel
  24. MHZ: 4200
  25. COUNT: 8
  26.  
  27. =============================== OS INFO ================================
  28. BUILDOSVER: 10.0.15063.502
  29. BUILD_TIMESTAMP: 2017-07-28 00:07:59
  30. SERVICEPACK: 502
  31. BUILD_VERSION: 10.0.15063.502 (WinBuild.160101.0800)
  32. BUILDOSVER: 10.0.15063.483
  33. BUILD_TIMESTAMP: 2017-07-07 02:06:35
  34. SERVICEPACK: 483
  35. BUILD_VERSION: 10.0.15063.483 (WinBuild.160101.0800)
  36. BUILDOSVER: 10.0.15063.540
  37. BUILDLAB: WinBuild
  38. BUILDDATESTAMP: 160101.0800
  39. BUILD_TIMESTAMP: 2017-07-31 21:23:25
  40. EDITION: Windows 10 WinNt TerminalServer SingleUserTS Personal
  41. NAME: Windows 10
  42. PLATFORM_TYPE: x64
  43. SERVICEPACK: 540
  44. BUILD: 15063
  45. BUILD_VERSION: 10.0.15063.540 (WinBuild.160101.0800)
  46. Built by: 15063.0.amd64fre.rs2_release.170317-1834
  47. Product: WinNt, suite: TerminalServer SingleUserTS Personal
  48.  
  49. If you see multiple OS versions listed above it's likely because the
  50. dump files were created at different times and Windows has updated to
  51. a new version. This is normal. The same goes for BIOS Versions/Dates.
  52.  
  53. ========================================================================
  54. ==================== Dump File: 081417-5062-01.dmp =====================
  55. ========================================================================
  56. Mini Kernel Dump File: Only registers and stack trace are available
  57. Windows 10 Kernel Version 15063 MP (8 procs) Free x64
  58. Kernel base = 0xfffff801`6da99000 PsLoadedModuleList = 0xfffff801`6dde55c0
  59. Debug session time: Mon Aug 14 02:11:06.407 2017 (UTC - 4:00)
  60. System Uptime: 4 days 2:58:41.071
  61.  
  62. BugCheck 19, {e, ffffd60d09a6a190, ce33200119d4d, 389086fa5575390}
  63. Probably caused by : Npfs.SYS ( Npfs!NpAddDataQueueEntry+237 )
  64. Followup: MachineOwner
  65.  
  66. BAD_POOL_HEADER (19)
  67. The pool is already corrupt at the time of the current request.
  68. This may or may not be due to the caller.
  69. The internal pool links must be walked to figure out a possible cause of
  70. the problem, and then special pool applied to the suspect tags or the driver
  71. verifier to a suspect driver.
  72.  
  73. Arguments:
  74. Arg1: 000000000000000e,
  75. Arg2: ffffd60d09a6a190
  76. Arg3: 000ce33200119d4d
  77. Arg4: 0389086fa5575390
  78.  
  79. Debugging Details:
  80. DUMP_CLASS: 1
  81. DUMP_QUALIFIER: 400
  82. DUMP_TYPE: 2
  83. BUGCHECK_STR: 0x19_e
  84. CUSTOMER_CRASH_COUNT: 1
  85. DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
  86.  
  87. PROCESS_NAME: DSAService.exe
  88.  
  89. CURRENT_IRQL: 0
  90. LAST_CONTROL_TRANSFER: from fffff8016dd19c49 to fffff8016dc05560
  91. STACK_TEXT:
  92. ffffe600`1e67d4f8 fffff801`6dd19c49 : 00000000`00000019 00000000`0000000e ffffd60d`09a6a190 000ce332`00119d4d : nt!KeBugCheckEx
  93. ffffe600`1e67d500 fffff801`6db3c31b : ffffd60d`0352b9c0 00000000`7246704e 00000000`00000000 00000000`00000000 : nt!ExAllocatePoolWithTag+0x18a9
  94. ffffe600`1e67d5f0 fffff80c`441ea4b7 : 00000000`00000000 00000000`0000010f ffffd60d`7246704e fffff801`00000000 : nt!ExAllocatePoolWithQuotaTag+0x6b
  95. ffffe600`1e67d680 fffff80c`441ea982 : ffffbf0c`3a111700 00000000`0000010f ffffbf0c`3a1117a8 00000000`0000010f : Npfs!NpAddDataQueueEntry+0x237
  96. ffffe600`1e67d6e0 fffff80c`441ea6ef : ffffbf0c`397e2810 00000000`02206198 ffffd60d`01494060 ffffd60d`0cfe0400 : Npfs!NpCommonWrite+0x222
  97. ffffe600`1e67d770 fffff80c`3fd93502 : ffffd60c`ffa82df0 fffff801`6df1da90 00000000`7e000000 00000000`00000000 : Npfs!NpFsdWrite+0x5f
  98. ffffe600`1e67d7e0 fffff801`6df2f6ef : ffffd60d`02f40ef0 ffffe600`1e67db00 00000000`00000000 fffff801`00000000 : FLTMGR!FltpDispatch+0xe2
  99. ffffe600`1e67d840 fffff801`6df58a48 : ffffbf0c`00000000 00000000`00000004 ffffd60c`fbebbb20 ffffe600`1e67db00 : nt!IopSynchronousServiceTail+0x1af
  100. ffffe600`1e67d900 fffff801`6dc10413 : ffffd60d`0cfe0400 00000000`00000a05 00000000`00000001 00000000`00000000 : nt!NtWriteFile+0x6d8
  101. ffffe600`1e67da10 00000000`560a21cc : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
  102. 00000000`0138efd8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x560a21cc
  103. STACK_COMMAND: kb
  104. THREAD_SHA1_HASH_MOD_FUNC: e4790fe0bac6de0fd79539d81c423e2e030ddb09
  105. THREAD_SHA1_HASH_MOD_FUNC_OFFSET: c76527a82a4fa79aaba0de7816e8c1fa7829c317
  106. THREAD_SHA1_HASH_MOD: 6ecd44f80943a3f36be683021b93ae6184283233
  107. FOLLOWUP_IP:
  108. Npfs!NpAddDataQueueEntry+237
  109. fffff80c`441ea4b7 488bf8 mov rdi,rax
  110. FAULT_INSTR_CODE: 48f88b48
  111. SYMBOL_STACK_INDEX: 3
  112. SYMBOL_NAME: Npfs!NpAddDataQueueEntry+237
  113. FOLLOWUP_NAME: MachineOwner
  114. MODULE_NAME: Npfs
  115.  
  116. IMAGE_NAME: Npfs.SYS
  117.  
  118. DEBUG_FLR_IMAGE_TIMESTAMP: 71dcd8d9
  119. IMAGE_VERSION: 10.0.15058.0
  120. BUCKET_ID_FUNC_OFFSET: 237
  121. FAILURE_BUCKET_ID: 0x19_e_Npfs!NpAddDataQueueEntry
  122. BUCKET_ID: 0x19_e_Npfs!NpAddDataQueueEntry
  123. PRIMARY_PROBLEM_CLASS: 0x19_e_Npfs!NpAddDataQueueEntry
  124. TARGET_TIME: 2017-08-14T06:11:06.000Z
  125. SUITE_MASK: 784
  126. PRODUCT_TYPE: 1
  127. USER_LCID: 0
  128. FAILURE_ID_HASH_STRING: km:0x19_e_npfs!npadddataqueueentry
  129. FAILURE_ID_HASH: {25f9d0b9-97e0-491a-4da5-b9bf5576c742}
  130. Followup: MachineOwner
  131.  
  132. ========================================================================
  133. ========================== 3RD PARTY DRIVERS ===========================
  134. ============================ Sorted by Date ============================
  135. ========================================================================
  136. Image path: \SystemRoot\SysWow64\drivers\AsIO.sys
  137. Image name: AsIO.sys
  138. Info Link : http://www.carrona.org/drivers/driver.php?id=AsIO.sys
  139. ADA Info : Asus Input Output driver http://www.asus.com/
  140. Timestamp : Wed Aug 22 2012
  141.  
  142. Image path: \SystemRoot\system32\DRIVERS\Hamdrv.sys
  143. Image name: Hamdrv.sys
  144. Info Link : http://www.carrona.org/drivers/driver.php?id=Hamdrv.sys
  145. Timestamp : Mon Mar 30 2015
  146.  
  147. Image path: \SystemRoot\sysWOW64\drivers\npf_devolo.sys
  148. Image name: npf_devolo.sys
  149. Info Link : http://www.carrona.org/drivers/driver.php?id=npf_devolo.sys
  150. ADA Info : NetGroup Packet Filter driver http://www.cacetech.com/
  151. Timestamp : Thu Aug 13 2015
  152.  
  153. Image path: \SystemRoot\System32\drivers\asmthub3.sys
  154. Image name: asmthub3.sys
  155. Info Link : http://www.carrona.org/drivers/driver.php?id=asmthub3.sys
  156. ADA Info : ASMedia USB 3.0 Hub driver http://www.asmedia.com.tw/
  157. Timestamp : Mon Aug 29 2016
  158.  
  159. Image path: \SystemRoot\system32\DRIVERS\asmtxhci.sys
  160. Image name: asmtxhci.sys
  161. Info Link : http://www.carrona.org/drivers/driver.php?id=asmtxhci.sys
  162. ADA Info : ASMedia USB 3.0 driver http://www.asmedia.com.tw/
  163. Timestamp : Mon Aug 29 2016
  164.  
  165. Image path: \SystemRoot\system32\drivers\netfilter2.sys
  166. Image name: netfilter2.sys
  167. Info Link : http://www.carrona.org/drivers/driver.php?id=netfilter2.sys
  168. Timestamp : Sat Sep 17 2016
  169.  
  170. Image path: \SystemRoot\system32\DRIVERS\e1d65x64.sys
  171. Image name: e1d65x64.sys
  172. Info Link : http://www.carrona.org/drivers/driver.php?id=e1d65x64.sys
  173. ADA Info : Intel(R) Gigabit Adapter NDIS 6.x driver https://downloadcenter.intel.com/
  174. Timestamp : Wed Oct 5 2016
  175.  
  176. Image path: \SystemRoot\System32\drivers\rzendpt.sys
  177. Image name: rzendpt.sys
  178. Info Link : http://www.carrona.org/drivers/driver.php?id=rzendpt.sys
  179. ADA Info : Razer RzEndPt driver https://www.razerzone.com/
  180. Timestamp : Wed Oct 26 2016
  181.  
  182. Image path: \SystemRoot\System32\drivers\rzudd.sys
  183. Image name: rzudd.sys
  184. Info Link : http://www.carrona.org/drivers/driver.php?id=rzudd.sys
  185. ADA Info : Razer Rzudd Engine Driver https://www.razerzone.com/
  186. Timestamp : Wed Oct 26 2016
  187.  
  188. Image path: \SystemRoot\System32\drivers\nvvhci.sys
  189. Image name: nvvhci.sys
  190. Info Link : http://www.carrona.org/drivers/driver.php?id=nvvhci.sys
  191. ADA Info : Nvidia Virtual USB Host Controller driver http://www.nvidia.com/
  192. Timestamp : Tue Dec 27 2016
  193.  
  194. Image path: \SystemRoot\System32\drivers\TeeDriverW8x64.sys
  195. Image name: TeeDriverW8x64.sys
  196. Info Link : http://www.carrona.org/drivers/driver.php?id=TeeDriverW8x64.sys
  197. ADA Info : Intel® Management Engine Interface
  198. Timestamp : Tue Apr 4 2017
  199.  
  200. Image path: \SystemRoot\system32\drivers\nvvad64v.sys
  201. Image name: nvvad64v.sys
  202. Info Link : http://www.carrona.org/drivers/driver.php?id=nvvad64v.sys
  203. ADA Info : Nvidia Virtual Audio Driver http://www.nvidia.com/
  204. Timestamp : Wed Apr 12 2017
  205.  
  206. Image path: \SystemRoot\system32\drivers\nvhda64v.sys
  207. Image name: nvhda64v.sys
  208. Info Link : http://www.carrona.org/drivers/driver.php?id=nvhda64v.sys
  209. ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
  210. Timestamp : Tue May 16 2017
  211.  
  212. Image path: \SystemRoot\System32\Drivers\dump_iaStorA.sys
  213. Image name: dump_iaStorA.sys
  214. Info Link : http://www.carrona.org/drivers/driver.php?id=dump_iaStorA.sys
  215. Timestamp : Mon Jun 12 2017
  216.  
  217. Image path: \SystemRoot\System32\drivers\iaStorA.sys
  218. Image name: iaStorA.sys
  219. Info Link : http://www.carrona.org/drivers/driver.php?id=iaStorA.sys
  220. ADA Info : Intel SATA Storage Device RAID Controller
  221. Timestamp : Mon Jun 12 2017
  222.  
  223. Image path: \??\C:\WINDOWS\system32\drivers\rzpnk.sys
  224. Image name: rzpnk.sys
  225. Info Link : http://www.carrona.org/drivers/driver.php?id=rzpnk.sys
  226. ADA Info : Razer Overlay Support https://www.razerzone.com/
  227. Timestamp : Sun Jul 16 2017
  228.  
  229. Image path: \??\C:\WINDOWS\system32\drivers\rzpmgrk.sys
  230. Image name: rzpmgrk.sys
  231. Info Link : http://www.carrona.org/drivers/driver.php?id=rzpmgrk.sys
  232. ADA Info : Razer Overlay Support https://www.razerzone.com/
  233. Timestamp : Tue Jul 18 2017
  234.  
  235. Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_24ddebfb518b5a55\nvlddmkm.sys
  236. Image name: nvlddmkm.sys
  237. Info Link : http://www.carrona.org/drivers/driver.php?id=nvlddmkm.sys
  238. ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
  239. Timestamp : Tue Jul 18 2017
  240.  
  241. ========================================================================
  242. ========================== MICROSOFT DRIVERS ===========================
  243. ========================================================================
  244. ACPI.sys ACPI Driver for NT (Microsoft)
  245. acpiex.sys ACPIEx Driver (Microsoft)
  246. acpipagr.sys ACPI Processor Aggregator Device Driver
  247. afd.sys Ancillary Function Driver for WinSock (Microsoft)
  248. ahcache.sys Application Compatibility Cache (Microsoft)
  249. BasicDisplay.sys Basic Display driver (Microsoft)
  250. BasicRender.sys Basic Render driver (Microsoft)
  251. Beep.SYS BEEP driver (Microsoft)
  252. BOOTVID.dll VGA Boot Driver (Microsoft)
  253. bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
  254. cdd.dll Canonical Display Driver (Microsoft)
  255. cdrom.sys SCSI CD-ROM Driver (Microsoft)
  256. CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
  257. CI.dll Code Integrity Module (Microsoft)
  258. CLASSPNP.SYS SCSI Class System Dll (Microsoft)
  259. CLFS.SYS Common Log File System Driver (Microsoft)
  260. clipsp.sys CLIP Service (Microsoft)
  261. cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
  262. cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
  263. CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
  264. condrv.sys Console Driver (Microsoft)
  265. crashdmp.sys Crash Dump Driver
  266. dfsc.sys DFS Namespace Client Driver (Microsoft)
  267. disk.sys PnP Disk Driver (Microsoft)
  268. drmk.sys Digital Rights Management (DRM) driver (Microsoft)
  269. dump_diskdump.sys Crash Dump Disk Driver
  270. dump_dumpfve.sys Bitlocker Drive Encryption Crashdump Filter
  271. dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
  272. dxgmms2.sys DirectX Graphics MMS
  273. EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
  274. fastfat.SYS Fast FAT File System Driver (Microsoft)
  275. filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
  276. fileinfo.sys FileInfo Filter Driver (Microsoft)
  277. FLTMGR.SYS Filesystem Filter Manager (Microsoft)
  278. Fs_Rec.sys File System Recognizer Driver (Microsoft)
  279. fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
  280. fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
  281. gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
  282. hal.dll Hardware Abstraction Layer DLL (Microsoft)
  283. HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
  284. HdAudio.sys High Definition Audio Function Driver
  285. HIDCLASS.SYS Hid Class Library
  286. HIDPARSE.SYS Hid Parsing Library (Microsoft)
  287. hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
  288. HTTP.sys HTTP Protocol Stack (Microsoft)
  289. intelpep.sys Intel Power Engine Plugin (Microsoft)
  290. intelppm.sys Processor Device Driver (Microsoft)
  291. iorate.sys I/O rate control Filter (Microsoft)
  292. kbdclass.sys Keyboard Class Driver (Microsoft)
  293. kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
  294. kd.dll Local Kernal Debugger (Microsoft)
  295. kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
  296. ks.sys Kernal CSA Library (Microsoft)
  297. ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
  298. ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
  299. ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
  300. lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
  301. luafv.sys LUA File Virtualization Filter Driver (Microsoft)
  302. mcupdate_GenuineIntel.dll Intel Microcode Update Library (Microsoft)
  303. mmcss.sys MMCSS Driver (Microsoft)
  304. monitor.sys Monitor Driver (Microsoft)
  305. mouclass.sys Mouse Class Driver (Microsoft)
  306. mouhid.sys HID Mouse Filter Driver (Microsoft)
  307. mountmgr.sys Mount Point Manager (Microsoft)
  308. mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
  309. mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
  310. mrxsmb10.sys Longhorn SMB Downlevel SubRdr (Microsoft)
  311. mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
  312. Msfs.SYS Mailslot driver (Microsoft)
  313. msisadrv.sys ISA Driver (Microsoft)
  314. mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
  315. msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
  316. mssmbios.sys System Management BIOS driver (Microsoft)
  317. mup.sys Multiple UNC Provider driver (Microsoft)
  318. ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
  319. ndisuio.sys NDIS User mode I/O driver (Microsoft)
  320. NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
  321. Ndu.sys Network Data Usage Monitoring driver (Microsoft)
  322. netbios.sys NetBIOS Interface driver (Microsoft)
  323. netbt.sys MBT Transport driver (Microsoft)
  324. NETIO.SYS Network I/O Subsystem (Microsoft)
  325. Npfs.SYS NPFS driver (Microsoft)
  326. npsvctrig.sys Named pipe service triggers (Microsoft)
  327. nsiproxy.sys NSI Proxy driver (Microsoft)
  328. NTFS.sys NT File System Driver (Microsoft)
  329. ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
  330. ntosext.sys NTOS Extension Host driver (Microsoft)
  331. Null.SYS NULL Driver (Microsoft)
  332. pacer.sys QoS Packet Scheduler (Microsoft)
  333. partmgr.sys Partition driver (Microsoft)
  334. pci.sys NT Plug and Play PCI Enumerator
  335. pcw.sys Performance Counter Driver (Microsoft)
  336. pdc.sys Power Dependency Coordinator Driver (Microsoft)
  337. peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
  338. portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
  339. PSHED.dll Platform Specific Hardware Error driver (Microsoft)
  340. qwavedrv.sys Microsoft Quality Windows Audio Video Experience (qWave) Support Driver
  341. rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
  342. rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
  343. rdyboost.sys ReadyBoost Driver (Microsoft)
  344. registry.sys Registry Container driver (Microsoft)
  345. rspndr.sys Link-Layer Topology Responder driver (Microsoft)
  346. serenum.sys Serial Port Enumerator
  347. serial.sys Serial Device Driver
  348. SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
  349. spaceport.sys Storage Spaces driver (Microsoft)
  350. srv.sys Server driver (Microsoft)
  351. srv2.sys Smb 2.0 Server driver (Microsoft)
  352. srvnet.sys Server Network driver (Microsoft)
  353. storport.sys A storage port driver that is especially suitable for use with high-performance buses, such as fibre channel buses, and RAID adapters. (Microsoft)
  354. storqosflt.sys Storage QoS Filter driver (Microsoft)
  355. swenum.sys Plug and Play Software Device Enumerator (Microsoft)
  356. tbs.sys Export driver for kernel mode TPM API (Microsoft)
  357. tcpip.sys TCP/IP Protocol driver (Microsoft)
  358. tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
  359. TDI.SYS TDI Wrapper driver (Microsoft)
  360. tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
  361. tm.sys Kernel Transaction Manager driver (Microsoft)
  362. TSDDD.dll Framebuffer Display Driver (Microsoft)
  363. ucx01000.sys USB Controller Extension
  364. UEFI.sys UEFI Driver for NT
  365. umbus.sys User-Mode Bus Enumerator (Microsoft)
  366. usbaudio.sys USB Audio Class Driver (Microsoft)
  367. usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
  368. USBD.SYS Universal Serial Bus Driver (Microsoft)
  369. UsbHub3.sys USB3 HUB Driver
  370. USBXHCI.SYS USB XHCI Driver
  371. vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
  372. vmbkmclr.sys Hyper-V VMBus Root KMCL (Microsoft)
  373. volmgr.sys Volume Manager Driver (Microsoft)
  374. volmgrx.sys Volume Manager Extension Driver (Microsoft)
  375. volsnap.sys Volume Shadow Copy driver (Microsoft)
  376. volume.sys Volume driver (Microsoft)
  377. vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
  378. wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
  379. watchdog.sys Watchdog driver (Microsoft)
  380. wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
  381. Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
  382. WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
  383. WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
  384. WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
  385. werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
  386. wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
  387. win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
  388. win32kbase.sys Base Win32k Kernel Driver (Microsoft)
  389. win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
  390. WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
  391. WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
  392. wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
  393. WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
  394. Wof.sys Windows Overlay Filter (Microsoft)
  395. WppRecorder.sys WPP Trace Recorder (Microsoft)
  396. WudfPf.sys Windows Driver Foundation - User-mode Driver Framework Platform driver (Microsoft)
  397.  
  398. Unloaded modules:
  399. fffff80c`42360000 fffff80c`4236e000 MpKsl43c2c16
  400. fffff80c`42310000 fffff80c`4231e000 MpKsld84a02a
  401. fffff80c`42350000 fffff80c`4235f000 hiber_storpo
  402. fffff801`8a360000 fffff801`8aead000 hiber_iaStor
  403. fffff801`8aeb0000 fffff801`8aecd000 hiber_dumpfv
  404. fffff80c`42340000 fffff80c`4234f000 hiber_storpo
  405. fffff801`8a7b0000 fffff801`8b2fd000 hiber_iaStor
  406. fffff801`8b300000 fffff801`8b31d000 hiber_dumpfv
  407. fffff80c`42330000 fffff80c`4233f000 hiber_storpo
  408. fffff801`8b1e0000 fffff801`8bd2d000 hiber_iaStor
  409. fffff801`8bd30000 fffff801`8bd4d000 hiber_dumpfv
  410. fffff80c`42320000 fffff80c`4232f000 hiber_storpo
  411. fffff801`86e80000 fffff801`879cd000 hiber_iaStor
  412. fffff801`879d0000 fffff801`879ed000 hiber_dumpfv
  413. fffff80c`422e0000 fffff80c`422ee000 MpKsl4959130
  414. fffff80c`42300000 fffff80c`4230f000 hiber_storpo
  415. fffff801`8a7d0000 fffff801`8b31d000 hiber_iaStor
  416. fffff801`8b320000 fffff801`8b33d000 hiber_dumpfv
  417. fffff80c`422f0000 fffff80c`422ff000 hiber_storpo
  418. fffff801`8acd0000 fffff801`8b81d000 hiber_iaStor
  419. fffff801`8b820000 fffff801`8b83d000 hiber_dumpfv
  420. fffff80c`42260000 fffff80c`4226e000 MpKslaa2df84
  421. fffff80c`422d0000 fffff80c`422df000 hiber_storpo
  422. fffff801`8b410000 fffff801`8bf5d000 hiber_iaStor
  423. fffff801`8bf60000 fffff801`8bf7d000 hiber_dumpfv
  424. fffff80c`422a0000 fffff80c`422af000 hiber_storpo
  425. fffff801`88760000 fffff801`892ad000 hiber_iaStor
  426. fffff801`892b0000 fffff801`892cd000 hiber_dumpfv
  427. fffff80c`42290000 fffff80c`42297000 semav6msr64.
  428. fffff80c`42280000 fffff80c`4228b000 cpuz143_x64.
  429. fffff80c`42270000 fffff80c`4227f000 hiber_storpo
  430. fffff801`6cd30000 fffff801`6d87d000 hiber_iaStor
  431. fffff801`6d880000 fffff801`6d89d000 hiber_dumpfv
  432. fffff80c`45d40000 fffff80c`45d4b000 cldflt.sys
  433. fffff80c`41610000 fffff80c`4161f000 dump_storpor
  434. fffff80c`42a00000 fffff80c`4354d000 dump_iaStorA
  435. fffff80c`43570000 fffff80c`4358d000 dump_dumpfve
  436. fffff80c`41e00000 fffff80c`41e20000 dam.sys
  437. fffff80c`3fc80000 fffff80c`3fc8f000 WdBoot.sys
  438. fffff80c`41520000 fffff80c`4152f000 hwpolicy.sys
  439.  
  440. ========================================================================
  441. ============================== BIOS INFO ===============================
  442. ========================================================================
  443. [SMBIOS Data Tables v3.0]
  444. [DMI Version - 0]
  445. [2.0 Calling Convention - No]
  446. [Table Size - 4338 bytes]
  447. [BIOS Information (Type 0) - Length 24 - Handle 0000h]
  448. Vendor American Megatrends Inc.
  449. BIOS Version 0906
  450. BIOS Starting Address Segment f000
  451. BIOS Release Date 03/22/2017
  452. BIOS ROM Size 1000000
  453. BIOS Characteristics
  454. 07: - PCI Supported
  455. 10: - APM Supported
  456. 11: - Upgradeable FLASH BIOS
  457. 12: - BIOS Shadowing Supported
  458. 15: - CD-Boot Supported
  459. 16: - Selectable Boot Supported
  460. 17: - BIOS ROM Socketed
  461. 19: - EDD Supported
  462. 23: - 1.2MB Floppy Supported
  463. 24: - 720KB Floppy Supported
  464. 25: - 2.88MB Floppy Supported
  465. 26: - Print Screen Device Supported
  466. 27: - Keyboard Services Supported
  467. 28: - Serial Services Supported
  468. 29: - Printer Services Supported
  469. 32: - BIOS Vendor Reserved
  470. BIOS Characteristic Extensions
  471. 00: - ACPI Supported
  472. 01: - USB Legacy Supported
  473. 08: - BIOS Boot Specification Supported
  474. 10: - Specification Reserved
  475. 11: - Specification Reserved
  476. BIOS Major Revision 5
  477. BIOS Minor Revision 12
  478. EC Firmware Major Revision 255
  479. EC Firmware Minor Revision 255
  480. [System Information (Type 1) - Length 27 - Handle 0001h]
  481. Manufacturer System manufacturer
  482. Product Name System Product Name
  483. Version System Version
  484. UUID 00000000-0000-0000-0000-000000000000
  485. Wakeup Type Power Switch
  486. SKUNumber SKU
  487. [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
  488. Manufacturer ASUSTeK COMPUTER INC.
  489. Product STRIX Z270F GAMING
  490. Version Rev 1.xx
  491. Feature Flags 09h
  492. Location Default string
  493. Chassis Handle 0003h
  494. Board Type 0ah - Processor/Memory Module
  495. Number of Child Handles 0
  496. [System Enclosure (Type 3) - Length 22 - Handle 0003h]
  497. Manufacturer Default string
  498. Chassis Type Desktop
  499. Version Default string
  500. Bootup State Safe
  501. Power Supply State Safe
  502. Thermal State Safe
  503. Security Status None
  504. OEM Defined 0
  505. Height 0U
  506. Number of Power Cords 1
  507. Number of Contained Elements 0
  508. Contained Element Size 3
  509. [Onboard Devices Information (Type 10) - Length 6 - Handle 0028h]
  510. Number of Devices 1
  511. 01: Type Video [enabled]
  512. [OEM Strings (Type 11) - Length 5 - Handle 0029h]
  513. Number of Strings 4
  514. 1 Default string
  515. 2 Default string
  516. 3 EINSTEIN
  517. 4 Default string
  518. [System Configuration Options (Type 12) - Length 5 - Handle 002ah]
  519. [Physical Memory Array (Type 16) - Length 23 - Handle 0045h]
  520. Location 03h - SystemBoard/Motherboard
  521. Use 03h - System Memory
  522. Memory Error Correction 03h - None
  523. Maximum Capacity 67108864KB
  524. Number of Memory Devices 4
  525. [Memory Device (Type 17) - Length 40 - Handle 0046h]
  526. Physical Memory Array Handle 0045h
  527. Total Width 0 bits
  528. Data Width 0 bits
  529. Form Factor 02h - Unknown
  530. Device Locator ChannelA-DIMM1
  531. Bank Locator BANK 0
  532. Memory Type 02h - Unknown
  533. Type Detail 0000h -
  534. Speed 0MHz
  535. [Memory Device (Type 17) - Length 40 - Handle 0047h]
  536. Physical Memory Array Handle 0045h
  537. Total Width 64 bits
  538. Data Width 64 bits
  539. Size 8192MB
  540. Form Factor 09h - DIMM
  541. Device Locator ChannelA-DIMM2
  542. Bank Locator BANK 1
  543. Memory Type 1ah - Specification Reserved
  544. Type Detail 0080h - Synchronous
  545. Speed 2133MHz
  546. Manufacturer G-Skill
  547. Part Number F4-2400C15-8GTZR
  548. [Memory Device (Type 17) - Length 40 - Handle 0048h]
  549. Physical Memory Array Handle 0045h
  550. Total Width 0 bits
  551. Data Width 0 bits
  552. Form Factor 02h - Unknown
  553. Device Locator ChannelB-DIMM1
  554. Bank Locator BANK 2
  555. Memory Type 02h - Unknown
  556. Type Detail 0000h -
  557. Speed 0MHz
  558. [Memory Device (Type 17) - Length 40 - Handle 0049h]
  559. Physical Memory Array Handle 0045h
  560. Total Width 64 bits
  561. Data Width 64 bits
  562. Size 8192MB
  563. Form Factor 09h - DIMM
  564. Device Locator ChannelB-DIMM2
  565. Bank Locator BANK 3
  566. Memory Type 1ah - Specification Reserved
  567. Type Detail 0080h - Synchronous
  568. Speed 2133MHz
  569. Manufacturer G-Skill
  570. Part Number F4-2400C15-8GTZR
  571. [Memory Array Mapped Address (Type 19) - Length 31 - Handle 004ah]
  572. Starting Address 00000000h
  573. Ending Address 00ffffffh
  574. Memory Array Handle 0045h
  575. Partition Width 02
  576. [Cache Information (Type 7) - Length 19 - Handle 004bh]
  577. Socket Designation L1 Cache
  578. Cache Configuration 0180h - WB Enabled Int NonSocketed L1
  579. Maximum Cache Size 0100h - 256K
  580. Installed Size 0100h - 256K
  581. Supported SRAM Type 0020h - Synchronous
  582. Current SRAM Type 0020h - Synchronous
  583. Cache Speed 0ns
  584. Error Correction Type ParitySingle-Bit ECC
  585. System Cache Type Unified
  586. Associativity 8-way Set-Associative
  587. [Cache Information (Type 7) - Length 19 - Handle 004ch]
  588. Socket Designation L2 Cache
  589. Cache Configuration 0181h - WB Enabled Int NonSocketed L2
  590. Maximum Cache Size 0400h - 1024K
  591. Installed Size 0400h - 1024K
  592. Supported SRAM Type 0020h - Synchronous
  593. Current SRAM Type 0020h - Synchronous
  594. Cache Speed 0ns
  595. Error Correction Type Multi-Bit ECC
  596. System Cache Type Unified
  597. Associativity 4-way Set-Associative
  598. [Cache Information (Type 7) - Length 19 - Handle 004dh]
  599. Socket Designation L3 Cache
  600. Cache Configuration 0182h - WB Enabled Int NonSocketed L3
  601. Maximum Cache Size 2000h - 8192K
  602. Installed Size 2000h - 8192K
  603. Supported SRAM Type 0020h - Synchronous
  604. Current SRAM Type 0020h - Synchronous
  605. Cache Speed 0ns
  606. Error Correction Type Specification Reserved
  607. System Cache Type Unified
  608. Associativity 16-way Set-Associative
  609. [Processor Information (Type 4) - Length 48 - Handle 004eh]
  610. Socket Designation LGA1151
  611. Processor Type Central Processor
  612. Processor Family c6h - Specification Reserved
  613. Processor Manufacturer Intel(R) Corporation
  614. Processor ID e9060900fffbebbf
  615. Processor Version Intel(R) Core(TM) i7-7700K CPU @ 4.20GHz
  616. Processor Voltage 8bh - 1.1V
  617. External Clock 100MHz
  618. Max Speed 8300MHz
  619. Current Speed 4200MHz
  620. Status Enabled Populated
  621. Processor Upgrade Other
  622. L1 Cache Handle 004bh
  623. L2 Cache Handle 004ch
  624. L3 Cache Handle 004dh
  625. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 004fh]
  626. Starting Address 00000000h
  627. Ending Address 007fffffh
  628. Memory Device Handle 0047h
  629. Mem Array Mapped Adr Handle 004ah
  630. Interleave Position 01
  631. Interleave Data Depth 02
  632. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0050h]
  633. Starting Address 00800000h
  634. Ending Address 00ffffffh
  635. Memory Device Handle 0049h
  636. Mem Array Mapped Adr Handle 004ah
  637. Interleave Position 02
  638. Interleave Data Depth 02
  639.  
  640. ========================================================================
  641. ==================== Dump File: 073117-4250-01.dmp =====================
  642. ========================================================================
  643. Mini Kernel Dump File: Only registers and stack trace are available
  644. Windows 10 Kernel Version 15063 MP (8 procs) Free x64
  645. Kernel base = 0xfffff803`a1207000 PsLoadedModuleList = 0xfffff803`a15535e0
  646. Debug session time: Mon Jul 31 17:05:54.827 2017 (UTC - 4:00)
  647. System Uptime: 1 days 0:44:53.481
  648.  
  649. BugCheck 11D, {7, ffffdb0353830000, 10000, 40000}
  650. *** WARNING: Unable to verify timestamp for win32k.sys
  651. *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
  652. Probably caused by : memory_corruption
  653. Followup: memory_corruption
  654.  
  655. EVENT_TRACING_FATAL_ERROR (11d)
  656. Event Tracing subsystem has encountered an unexpected fatal error. First parameter indicates
  657. the type of failure.
  658.  
  659. Arguments:
  660. Arg1: 0000000000000007, Trace buffer corruption.
  661. Arg2: ffffdb0353830000
  662. Arg3: 0000000000010000
  663. Arg4: 0000000000040000
  664.  
  665. Debugging Details:
  666. DUMP_CLASS: 1
  667. DUMP_QUALIFIER: 400
  668. DUMP_TYPE: 2
  669. CUSTOMER_CRASH_COUNT: 1
  670. DEFAULT_BUCKET_ID: CODE_CORRUPTION
  671. BUGCHECK_STR: 0x11D
  672.  
  673. PROCESS_NAME: svchost.exe
  674.  
  675. CURRENT_IRQL: 0
  676. LAST_CONTROL_TRANSFER: from fffff803a138badb to fffff803a13734c0
  677. STACK_TEXT:
  678. ffffad01`85759418 fffff803`a138badb : 00000000`0000011d 00000000`00000007 ffffdb03`53830000 00000000`00010000 : nt!KeBugCheckEx
  679. ffffad01`85759420 fffff803`a1226a29 : ffffdb03`5b1e3000 00000000`00000000 ffff860e`6e1f6b40 00000000`00000000 : nt!EtwpDequeueFreeBuffer+0x164ee3
  680. ffffad01`85759470 fffff803`a1225706 : ffff860e`6e1f6b40 00000000`00000208 ffff860e`6deb6000 00000000`00000000 : nt!EtwpSwitchBuffer+0x29
  681. ffffad01`857594b0 fffff803`a164dbc2 : ffffad01`0000000a ffff860e`6e1f6b40 ffffad01`85759570 ffffad01`85759620 : nt!EtwpReserveTraceBuffer+0x136
  682. ffffad01`85759530 fffff803`a1224f96 : ffff860e`6d010000 ffffad01`85759a80 00000096`06ffecd8 ffffdb03`5b186340 : nt!EtwpWriteUserEvent+0x4c2
  683. ffffad01`857598e0 fffff803`a137e413 : ffff860e`75bbf7c0 00000000`00000000 00000000`00000000 00000292`48b70040 : nt!NtTraceEvent+0x236
  684. ffffad01`85759a80 00007ffd`ce835f54 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
  685. 00000096`06ffec68 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffd`ce835f54
  686. STACK_COMMAND: kb
  687. CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
  688. fffff803a12900cf-fffff803a12900d0 2 bytes - nt!MiSetProtectionOnSection+12f
  689. [ 80 f6:00 80 ]
  690. 2 errors : !nt (fffff803a12900cf-fffff803a12900d0)
  691. MODULE_NAME: memory_corruption
  692.  
  693. IMAGE_NAME: memory_corruption
  694.  
  695. FOLLOWUP_NAME: memory_corruption
  696. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  697. MEMORY_CORRUPTOR: LARGE
  698. FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
  699. BUCKET_ID: MEMORY_CORRUPTION_LARGE
  700. PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
  701. TARGET_TIME: 2017-07-31T21:05:54.000Z
  702. SUITE_MASK: 784
  703. PRODUCT_TYPE: 1
  704. USER_LCID: 0
  705. FAILURE_ID_HASH_STRING: km:memory_corruption_large
  706. FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
  707. Followup: memory_corruption
  708.  
  709. ========================================================================
  710. ==================== Dump File: 080517-5390-01.dmp =====================
  711. ========================================================================
  712. Mini Kernel Dump File: Only registers and stack trace are available
  713. Windows 10 Kernel Version 15063 MP (8 procs) Free x64
  714. Kernel base = 0xfffff800`58c8b000 PsLoadedModuleList = 0xfffff800`58fd75c0
  715. Debug session time: Fri Aug 4 21:21:34.033 2017 (UTC - 4:00)
  716. System Uptime: 2 days 5:46:13.692
  717.  
  718. BugCheck 19, {3, ffffe201c60ab470, ffffe201c608b470, ffffe201c60ab470}
  719. *** WARNING: Unable to verify timestamp for win32k.sys
  720. *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
  721. Probably caused by : ntkrnlmp.exe ( nt!ExAllocatePoolWithTag+197a )
  722. Followup: MachineOwner
  723.  
  724. BAD_POOL_HEADER (19)
  725. The pool is already corrupt at the time of the current request.
  726. This may or may not be due to the caller.
  727. The internal pool links must be walked to figure out a possible cause of
  728. the problem, and then special pool applied to the suspect tags or the driver
  729. verifier to a suspect driver.
  730.  
  731. Arguments:
  732. Arg1: 0000000000000003, the pool freelist is corrupt.
  733. Arg2: ffffe201c60ab470, the pool entry being checked.
  734. Arg3: ffffe201c608b470, the read back flink freelist value (should be the same as 2).
  735. Arg4: ffffe201c60ab470, the read back blink freelist value (should be the same as 2).
  736.  
  737. Debugging Details:
  738. DUMP_CLASS: 1
  739. DUMP_QUALIFIER: 400
  740. DUMP_TYPE: 2
  741. BUGCHECK_STR: 0x19_3
  742. CUSTOMER_CRASH_COUNT: 1
  743. DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
  744.  
  745. PROCESS_NAME: SearchIndexer.exe
  746.  
  747. CURRENT_IRQL: 1
  748. LAST_CONTROL_TRANSFER: from fffff80058f0bd1a to fffff80058df7550
  749. STACK_TEXT:
  750. ffff9001`862a7248 fffff800`58f0bd1a : 00000000`00000019 00000000`00000003 ffffe201`c60ab470 ffffe201`c608b470 : nt!KeBugCheckEx
  751. ffff9001`862a7250 fffff80f`06d67e36 : 00000000`00000004 00000000`000000a8 00000000`000028c5 fffff800`00000000 : nt!ExAllocatePoolWithTag+0x197a
  752. ffff9001`862a7340 fffff80f`06e14f69 : ffffe201`befdf450 ffffd206`aa727602 ffffd206`aa7276c8 ffffd206`aa7276c8 : NTFS!NtfsPerformPrefetch+0xba
  753. ffff9001`862a73b0 fffff80f`06e136ba : ffff9001`862a75f8 fffff80f`06d6ac15 ffffd206`a3b62360 ffffd206`aa96cc00 : NTFS!NtfsReadUsnJournal+0x3c9
  754. ffff9001`862a7540 fffff80f`06e13546 : ffffd206`aa7276c8 00000000`00000000 00000000`00000000 00000000`00000000 : NTFS!NtfsUserFsRequest+0xe6
  755. ffff9001`862a75c0 fffff80f`05f8563d : ffffd206`aa96cc00 ffff9001`862a7770 ffffd206`a3a0d8c0 ffffd206`a88fc650 : NTFS!NtfsFsdFileSystemControl+0x356
  756. ffff9001`862a76d0 fffff80f`05fb5640 : ffff9001`862a7760 00000000`00000001 00000000`00000001 ffffd206`9fa2c140 : FLTMGR!FltpLegacyProcessingAfterPreCallbacksCompleted+0x18d
  757. ffff9001`862a7740 fffff800`591216ef : ffffd206`a57f6630 00000000`00000002 00000000`00000000 ffffd206`a8051240 : FLTMGR!FltpFsControl+0x110
  758. ffff9001`862a77a0 fffff800`591214f4 : ffff9001`00000001 ffffd206`a57f6604 fffff780`000002dc ffff9001`862a7b00 : nt!IopSynchronousServiceTail+0x1af
  759. ffff9001`862a7860 fffff800`591bbef6 : 00000090`0677d268 00000000`000008d0 00000000`00000000 0000023e`3b376548 : nt!IopXxxControlFile+0xdc4
  760. ffff9001`862a79a0 fffff800`58e02413 : 00000000`000008b4 fffff800`59130e6b ffff9001`862a7a28 0000023e`318b7db0 : nt!NtFsControlFile+0x56
  761. ffff9001`862a7a10 00007ffc`03b95ac4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
  762. 00000090`0677d1f8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffc`03b95ac4
  763. STACK_COMMAND: kb
  764. THREAD_SHA1_HASH_MOD_FUNC: d92d1167310f0a3c4c6d67228dde6bc941cf33f9
  765. THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 39a0a0543f3e693aff8d5227a69cf699fb0bdeb6
  766. THREAD_SHA1_HASH_MOD: 9fd74f6e9409a708d8636cf30aeb592ae9bf3855
  767. FOLLOWUP_IP:
  768. nt!ExAllocatePoolWithTag+197a
  769. fffff800`58f0bd1a cc int 3
  770. FAULT_INSTR_CODE: ffdb33cc
  771. SYMBOL_STACK_INDEX: 1
  772. SYMBOL_NAME: nt!ExAllocatePoolWithTag+197a
  773. FOLLOWUP_NAME: MachineOwner
  774. MODULE_NAME: nt
  775.  
  776. IMAGE_NAME: ntkrnlmp.exe
  777.  
  778. DEBUG_FLR_IMAGE_TIMESTAMP: 597ab89f
  779. IMAGE_VERSION: 10.0.15063.502
  780. BUCKET_ID_FUNC_OFFSET: 197a
  781. FAILURE_BUCKET_ID: 0x19_3_nt!ExAllocatePoolWithTag
  782. BUCKET_ID: 0x19_3_nt!ExAllocatePoolWithTag
  783. PRIMARY_PROBLEM_CLASS: 0x19_3_nt!ExAllocatePoolWithTag
  784. TARGET_TIME: 2017-08-05T01:21:34.000Z
  785. SUITE_MASK: 784
  786. PRODUCT_TYPE: 1
  787. USER_LCID: 0
  788. FAILURE_ID_HASH_STRING: km:0x19_3_nt!exallocatepoolwithtag
  789. FAILURE_ID_HASH: {4b68972e-e926-5fd8-7b97-1ce977bc62b9}
  790. Followup: MachineOwner
  791.  
  792. ========================================================================
  793. ==================== Dump File: 080717-4437-01.dmp =====================
  794. ========================================================================
  795. Mini Kernel Dump File: Only registers and stack trace are available
  796. Windows 10 Kernel Version 15063 MP (8 procs) Free x64
  797. Kernel base = 0xfffff800`71889000 PsLoadedModuleList = 0xfffff800`71bd55c0
  798. Debug session time: Mon Aug 7 09:00:04.194 2017 (UTC - 4:00)
  799. System Uptime: 2 days 11:38:00.547
  800.  
  801. BugCheck 3B, {c0000005, fffff80071cc8722, ffffb001e3887df0, 0}
  802. *** WARNING: Unable to verify timestamp for win32k.sys
  803. *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
  804. Probably caused by : memory_corruption
  805. Followup: memory_corruption
  806.  
  807. SYSTEM_SERVICE_EXCEPTION (3b)
  808. An exception happened while executing a system service routine.
  809.  
  810. Arguments:
  811. Arg1: 00000000c0000005, Exception code that caused the bugcheck
  812. Arg2: fffff80071cc8722, Address of the instruction which caused the bugcheck
  813. Arg3: ffffb001e3887df0, Address of the context record for the exception that caused the bugcheck
  814. Arg4: 0000000000000000, zero.
  815.  
  816. Debugging Details:
  817. DUMP_CLASS: 1
  818. DUMP_QUALIFIER: 400
  819. DUMP_TYPE: 2
  820. EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.
  821. FAULTING_IP:
  822. nt!ObQueryNameStringMode+1d2
  823. fffff800`71cc8722 0820 or byte ptr [rax],ah
  824. CONTEXT: ffffb001e3887df0 -- (.cxr 0xffffb001e3887df0)
  825. rax=0000000000000000 rbx=ffff998897f273d0 rcx=ffff998897f273d0
  826. rdx=0000000000000022 rsi=ffff99889a37f150 rdi=0000000000000000
  827. rip=fffff80071cc8722 rsp=ffffb001e38887e0 rbp=ffffb001e3888b00
  828. r8=0000000000000000 r9=7fff99889a37f160 r10=7ffffffffffffffc
  829. r11=ffff9988ade1c040 r12=fffff80071889000 r13=000000002bfde570
  830. r14=fffff80071889000 r15=ffff99889a37f180
  831. iopl=0 nv up ei ng nz na pe nc
  832. cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010282
  833. nt!ObQueryNameStringMode+0x1d2:
  834. fffff800`71cc8722 0820 or byte ptr [rax],ah ds:002b:00000000`00000000=??
  835. Resetting default scope
  836. CUSTOMER_CRASH_COUNT: 1
  837. DEFAULT_BUCKET_ID: CODE_CORRUPTION
  838. BUGCHECK_STR: 0x3B
  839.  
  840. PROCESS_NAME: playstv.exe
  841.  
  842. CURRENT_IRQL: 0
  843. LAST_CONTROL_TRANSFER: from fffff80071cc8183 to fffff80071cc8722
  844. STACK_TEXT:
  845. ffffb001`e38887e0 fffff800`71cc8183 : ffff9988`9a37f180 00000000`2bfde570 00000000`00000210 ffffb001`e3888928 : nt!ObQueryNameStringMode+0x1d2
  846. ffffb001`e38888d0 fffff800`71a00413 : ffffce07`8fb42600 00000000`2bfde518 ffffb001`e3888a28 00000000`00f75000 : nt!NtQueryObject+0x2a3
  847. ffffb001`e3888a10 00007ffa`7ad755a4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
  848. 00000000`2bfde4f8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffa`7ad755a4
  849. CHKIMG_EXTENSION: !chkimg -lo 50 -db !nt
  850. 104 errors : !nt (fffff80071cc8002-fffff80071cc8f7a)
  851. fffff80071cc8000 01 00 *08 41 83 fe 03 0f 84 31 *d9 19 00 48 8d 8c ...A.....1...H..
  852. fffff80071cc8020 00 00 *cb 89 4c 24 20 44 0f b6 c8 45 33 c0 33 d2 ....L$ D...E3.3.
  853. fffff80071cc8030 48 8b *d8 e8 c8 2a 06 00 44 8b *80 48 8b b4 24 e0 H....*..D..H..$.
  854. fffff80071cc8040 00 00 00 48 89 74 24 78 89 44 *04 54 85 c0 0f 88 ...H.t$x.D.T....
  855. fffff80071cc8050 e0 00 00 00 44 8b 84 24 a4 00 *04 00 44 89 44 24 ....D..$....D.D$
  856. fffff80071cc8070 48 c1 *e0 08 0f b6 c8 0f b6 42 *08 48 33 c8 0f b6 H........B.H3...
  857. fffff80071cc8300 00 00 *e8 0d 4c 8b bc 24 60 01 00 00 48 8b 74 24 ....L..$`...H.t$
  858. fffff80071cc8310 78 44 *02 64 24 54 e9 f1 fd ff *d7 41 83 ee 01 0f xD.d$T.....A....
  859. fffff80071cc8320 85 4f *70 19 00 4c 8d 4c 24 58 *40 8b c5 48 8b d7 .Op..L.L$X@..H..
  860. fffff80071cc8330 e8 0b *48 10 00 e9 49 fe ff ff *48 8b bc 24 60 01 ..H...I...H..$`.
  861. fffff80071cc8340 00 00 *80 bc fc ff ff 0f b6 c0 *82 e0 03 48 8d 1d .............H..
  862. fffff80071cc8350 ac 0c *b6 ff 0f b6 84 18 a0 bf 34 00 49 8b ce 48 ..........4.I..H
  863. fffff80071cc8360 2b c8 *08 89 4c 24 60 0f 84 ec *b6 ff ff 48 8b 09 +...L$`......H..
  864. fffff80071cc8370 48 89 *04 24 70 48 85 c9 0f 84 *c3 fe ff ff e8 4d H..$pH.........M
  865. fffff80071cc8400 88 00 00 00 0f b6 41 1a a8 02 *34 22 0f b6 c0 83 ......A...4"....
  866. fffff80071cc8410 e0 03 *0c b6 84 18 a0 bf 34 00 *88 8b d1 48 2b d0 ........4....H+.
  867. fffff80071cc8420 74 0c *8c 8b 02 4d 85 c0 0f 85 *a5 00 00 00 48 8d t....M........H.
  868. fffff80071cc8430 59 10 b8 11 00 00 00 f0 4c 0f *a1 23 0f 85 80 fc Y.......L..#....
  869. fffff80071cc8440 19 00 48 8b cb e8 96 43 c2 ff *05 48 8b 0c 25 88 ..H....C...H..%.
  870. fffff80071cc8450 01 00 *0c e8 68 f7 c2 ff 48 8b *7c 24 70 48 85 c0 ....h...H.|$pH..
  871. fffff80071cc8460 74 08 48 8b c8 e8 96 47 c2 ff *01 c6 12 e9 12 fe t.H....G........
  872. fffff80071cc8470 ff ff *6d 84 24 98 00 00 00 0f 00 00 00 44 89 64 ..m.$........D.d
  873. fffff80071cc8700 0f 84 *e6 00 00 00 48 3b 0d 13 *a6 f0 ff 0f 84 e8 ......H;........
  874. fffff80071cc8710 00 00 *09 48 85 c9 0f 84 df 00 *0a 00 8b 81 50 01 ...H..........P.
  875. fffff80071cc8720 00 00 *08 20 0f 85 d1 00 00 00 48 8d 41 d0 48 89 ... ......H.A.H.
  876. fffff80071cc8730 84 24 80 00 00 00 65 48 8b 0c *01 88 01 00 00 0f .$....eH........
  877. fffff80071cc8740 bf 81 *9c 01 00 00 ff c8 66 89 81 e4 01 00 00 4c ........f......L
  878. fffff80071cc8750 8b b4 *84 80 00 00 00 33 d2 49 *cc 4e 10 e8 ce 39 .......3.I.N...9
  879. fffff80071cc8760 c2 ff *c8 0f b6 46 1a a8 02 0f *9c 2f 01 00 00 0f .....F...../....
  880. fffff80071cc8770 b6 c0 *81 e0 03 42 0f b6 84 20 *80 bf 34 00 49 8b .....B... ..4.I.
  881. fffff80071cc8800 00 0f *00 cc 00 00 00 4c 8d 35 *c2 07 bc ff 44 8b .......L.5....D.
  882. fffff80071cc8810 a4 24 00 01 00 00 48 8d 42 12 *8a 44 24 60 48 8b .$....H.B..D$`H.
  883. fffff80071cc8820 8c 24 *0a 01 00 00 89 01 eb 3e *81 84 24 98 00 00 .$.......>..$...
  884. fffff80071cc8830 00 89 *40 24 44 c6 44 24 40 00 *13 ff 4c 8d 35 bd ..@$D.D$@...L.5.
  885. fffff80071cc8840 07 bc *ec 4c 8b ac 24 f8 00 00 00 4c 8b bc 24 f0 ...L..$....L..$.
  886. fffff80071cc8850 00 00 *ac 48 8b b4 24 90 00 00 *24 44 8b a4 24 00 ...H..$...$D..$.
  887. fffff80071cc8860 01 00 *24 e9 97 00 00 00 44 3b 64 24 60 0f 83 8c ..$.....D;d$`...
  888. fffff80071cc8870 00 00 *20 c7 44 24 44 04 00 00 *61 c6 44 24 40 00 .. .D$D...a.D$@.
  889. fffff80071cc8b00 48 8b *10 08 e8 f7 8a d3 ff b8 *99 00 00 00 f0 49 H..............I
  890. fffff80071cc8b10 0f b1 *10 24 75 64 49 8b cc e8 *40 3c c2 ff e8 6d ...$udI...@<...m
  891. fffff80071cc8b20 42 c2 *14 e9 d1 fe ff ff 48 8b *00 24 50 4d 8d 65 B.......H..$PM.e
  892. fffff80071cc8b30 10 48 *01 e9 02 48 89 4c 24 50 *90 5c 00 00 00 66 .H...H.L$P.\...f
  893. fffff80071cc8b40 89 01 *00 b7 44 24 60 66 2b c1 *00 41 03 c5 0f b7 ....D$`f+..A....
  894. fffff80071cc8b50 c0 89 *00 24 9c 00 00 00 66 41 *88 45 02 8b d8 48 ...$....fA.E...H
  895. fffff80071cc8b60 83 c0 *dc 66 41 89 45 00 4d 89 *fd 08 4c 3b e1 0f ...fA.E.M...L;..
  896. fffff80071cc8b70 85 c5 00 00 00 e9 dc 00 00 00 *09 8b cc e8 ae 8f ................
  897. fffff80071cc8c00 4d 8d *20 10 49 3b cc 49 0f 42 *00 48 89 4c 24 50 M. .I;.I.B.H.L$P
  898. fffff80071cc8c10 8b 05 *22 f8 e6 ff 89 01 0f b7 *00 5d f8 e6 ff 66 .."........]...f
  899. fffff80071cc8c20 89 41 *00 49 3b cc 0f 85 05 ff ff ff 48 83 c1 02 .A.I;.......H...
  900. fffff80071cc8c30 48 89 *40 24 50 e9 f7 fe ff ff *40 8b c3 48 8b d1 H.@$P.....@..H..
  901. WARNING: !chkimg output was truncated to 50 lines. Invoke !chkimg without '-lo [num_lines]' to view entire output.
  902. MODULE_NAME: memory_corruption
  903.  
  904. IMAGE_NAME: memory_corruption
  905.  
  906. FOLLOWUP_NAME: memory_corruption
  907. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  908. MEMORY_CORRUPTOR: STRIDE
  909. STACK_COMMAND: .cxr 0xffffb001e3887df0 ; kb
  910. FAILURE_BUCKET_ID: MEMORY_CORRUPTION_STRIDE
  911. BUCKET_ID: MEMORY_CORRUPTION_STRIDE
  912. PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_STRIDE
  913. TARGET_TIME: 2017-08-07T13:00:04.000Z
  914. SUITE_MASK: 784
  915. PRODUCT_TYPE: 1
  916. USER_LCID: 0
  917. FAILURE_ID_HASH_STRING: km:memory_corruption_stride
  918. FAILURE_ID_HASH: {574dbc1b-92cb-fb09-cb7a-cacc1bb2c511}
  919. Followup: memory_corruption
  920.  
  921. ========================================================================
  922. ==================== Dump File: 081017-4343-01.dmp =====================
  923. ========================================================================
  924. Mini Kernel Dump File: Only registers and stack trace are available
  925. Windows 10 Kernel Version 15063 MP (8 procs) Free x64
  926. Kernel base = 0xfffff803`da60c000 PsLoadedModuleList = 0xfffff803`da9585c0
  927. Debug session time: Wed Aug 9 23:11:49.150 2017 (UTC - 4:00)
  928. System Uptime: 1 days 4:20:15.805
  929.  
  930. BugCheck 1A, {41201, ffffb48122c21010, 8200000251415825, ffffcb0d847e2950}
  931. Probably caused by : memory_corruption ( nt!MiGetPageProtection+1183bf )
  932. Followup: MachineOwner
  933.  
  934. MEMORY_MANAGEMENT (1a)
  935. # Any other values for parameter 1 must be individually examined.
  936.  
  937. Arguments:
  938. Arg1: 0000000000041201, The subtype of the bugcheck.
  939. Arg2: ffffb48122c21010
  940. Arg3: 8200000251415825
  941. Arg4: ffffcb0d847e2950
  942.  
  943. Debugging Details:
  944. DUMP_CLASS: 1
  945. DUMP_QUALIFIER: 400
  946. DUMP_TYPE: 2
  947. BUGCHECK_STR: 0x1a_41201
  948. CUSTOMER_CRASH_COUNT: 1
  949. DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
  950.  
  951. PROCESS_NAME: chrome.exe
  952.  
  953. CURRENT_IRQL: 2
  954. LAST_CONTROL_TRANSFER: from fffff803da7ac64f to fffff803da778560
  955. STACK_TEXT:
  956. ffffa200`137266c8 fffff803`da7ac64f : 00000000`0000001a 00000000`00041201 ffffb481`22c21010 82000002`51415825 : nt!KeBugCheckEx
  957. ffffa200`137266d0 fffff803`da693ae3 : ffffb481`22c21010 00000000`00001000 82000002`51415825 00000000`00000000 : nt!MiGetPageProtection+0x1183bf
  958. ffffa200`13726720 fffff803`da69363e : 00000245`00000000 fffff803`daaadd00 00000000`00000000 ffffcb0d`840a0cc0 : nt!MiQueryAddressState+0x2b3
  959. ffffa200`137267b0 fffff803`daa9901f : ffffcb0d`00000006 00000000`00000001 00000000`00000000 00000245`84202000 : nt!MiQueryAddressSpan+0x12e
  960. ffffa200`13726860 fffff803`daa988c1 : 00000190`1b220b30 fffff803`daa96907 ffffcb0d`00001000 0000002a`00000004 : nt!MmQueryVirtualMemory+0x74f
  961. ffffa200`137269c0 fffff803`da783413 : ffffb4da`40640730 ffffb4da`6d203200 ffffb4da`6d369018 ffffdec2`4e533711 : nt!NtQueryVirtualMemory+0x25
  962. ffffa200`13726a10 00007ffc`66945804 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
  963. 0000002a`81dfea38 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffc`66945804
  964. STACK_COMMAND: kb
  965. THREAD_SHA1_HASH_MOD_FUNC: daeab5d68ba3ecb3234b5b8938d47aee75235996
  966. THREAD_SHA1_HASH_MOD_FUNC_OFFSET: ab74cfc1f0ddbd58ad4e35e049a5c63d44d1b33b
  967. THREAD_SHA1_HASH_MOD: 30a3e915496deaace47137d5b90c3ecc03746bf6
  968. FOLLOWUP_IP:
  969. nt!MiGetPageProtection+1183bf
  970. fffff803`da7ac64f cc int 3
  971. FAULT_INSTR_CODE: a88d49cc
  972. SYMBOL_STACK_INDEX: 1
  973. SYMBOL_NAME: nt!MiGetPageProtection+1183bf
  974. FOLLOWUP_NAME: MachineOwner
  975. MODULE_NAME: nt
  976. DEBUG_FLR_IMAGE_TIMESTAMP: 597fd80d
  977. IMAGE_VERSION: 10.0.15063.540
  978.  
  979. IMAGE_NAME: memory_corruption
  980.  
  981. BUCKET_ID_FUNC_OFFSET: 1183bf
  982. FAILURE_BUCKET_ID: 0x1a_41201_nt!MiGetPageProtection
  983. BUCKET_ID: 0x1a_41201_nt!MiGetPageProtection
  984. PRIMARY_PROBLEM_CLASS: 0x1a_41201_nt!MiGetPageProtection
  985. TARGET_TIME: 2017-08-10T03:11:49.000Z
  986. SUITE_MASK: 784
  987. PRODUCT_TYPE: 1
  988. USER_LCID: 0
  989. FAILURE_ID_HASH_STRING: km:0x1a_41201_nt!migetpageprotection
  990. FAILURE_ID_HASH: {c1fe3b27-3ba8-d99e-656f-85f3d58dc669}
  991. Followup: MachineOwner
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement