Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ========================== AUTO DUMP ANALYZER ==========================
- Auto Dump Analyzer
- Version: 0.91
- Time to analyze file(s): 00 hours and 01 minutes and 14 seconds
- ================================= CPU ==================================
- COUNT: c
- MHZ: 3696
- VENDOR: GenuineIntel
- FAMILY: 6
- MODEL: 9e
- STEPPING: a
- ================================== OS ==================================
- Product: WinNt, suite: TerminalServer SingleUserTS Personal
- BUILD_VERSION: 10.0.19041.330 (WinBuild.160101.0800)
- BUILD: 19041
- SERVICEPACK: 330
- PLATFORM_TYPE: x64
- NAME: Windows 10
- EDITION: Windows 10 WinNt TerminalServer SingleUserTS Personal
- BUILD_TIMESTAMP: unknown_date
- BUILDDATESTAMP: 160101.0800
- BUILDLAB: WinBuild
- BUILDOSVER: 10.0.19041.330
- =============================== DEBUGGER ===============================
- Microsoft (R) Windows Debugger Version 10.0.14321.1024 AMD64
- Copyright (c) Microsoft Corporation. All rights reserved.
- =============================== COMMENTS ===============================
- * Information gathered from different dump files may be different. If
- Windows updates between two dump files, two or more OS versions may
- be shown above.
- * Additional BIOS information was not included in the dump file(s). This
- can be caused by an outdated BIOS.
- ========================================================================
- ======================= Dump #1: ANALYZE VERBOSE =======================
- ======================= File: 062620-4140-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 19041 MP (12 procs) Free x64
- Kernel base = 0xfffff800`83c00000 PsLoadedModuleList = 0xfffff800`8482a2b0
- Debug session time: Fri Jun 26 13:09:08.380 2020 (UTC - 4:00)
- System Uptime: 0 days 0:37:17.047
- BugCheck 34, {944, ffffffffc0000420, 0, 0}
- Probably caused by : ntkrnlmp.exe ( nt!CcUninitializeCacheMap+1afd99 )
- Followup: MachineOwner
- CACHE_MANAGER (34)
- See the comment for FAT_FILE_SYSTEM (0x23)
- Arguments:
- Arg1: 0000000000000944
- Arg2: ffffffffc0000420
- Arg3: 0000000000000000
- Arg4: 0000000000000000
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- DUMP_FILE_ATTRIBUTES: 0x8
- Kernel Generated Triage Dump
- EXCEPTION_RECORD: ffffffffc0000420 -- (.exr 0xffffffffc0000420)
- Cannot read Exception record @ ffffffffc0000420
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
- BUGCHECK_STR: 0x34
- PROCESS_NAME: System
- CURRENT_IRQL: 2
- LAST_CONTROL_TRANSFER: from fffff800840313b9 to fffff80083fdda20
- STACK_TEXT:
- ffffb285`e79e9a98 fffff800`840313b9 : 00000000`00000034 00000000`00000944 ffffffff`c0000420 00000000`00000000 : nt!KeBugCheckEx
- ffffb285`e79e9aa0 fffff800`86b0fed0 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!CcUninitializeCacheMap+0x1afd99
- ffffb285`e79e9b60 fffff800`86b00bd0 : ffffa281`2ba52800 ffffa281`2ba528a0 00000000`00000000 ffffa281`2ba52a00 : Ntfs!NtfsDeleteInternalAttributeStream+0x10c
- ffffb285`e79e9ba0 fffff800`869eace5 : ffffa281`2ba528a0 ffffa281`2ba52a00 00000000`00000000 ffffa281`2ba52a00 : Ntfs!NtfsRemoveScb+0x130
- ffffb285`e79e9c00 fffff800`869ea9b9 : ffffa281`2ddc05e0 00000000`00000000 ffffdb0d`fd51e180 ffffa281`2ba528a0 : Ntfs!NtfsPrepareFcbForRemoval+0x75
- ffffb285`e79e9c40 fffff800`86b008ea : ffffdb0e`04d4a018 ffffdb0d`fd51e180 ffffa281`2ddc05a0 ffffa281`2ddc09f8 : Ntfs!NtfsTeardownFromLcb+0x2c9
- ffffb285`e79e9ce0 fffff800`869dd560 : ffffdb0e`04d4a018 ffffb285`e79e9de2 ffffa281`2ddc09f8 ffffa281`2ddc05a0 : Ntfs!NtfsTeardownStructures+0xea
- ffffb285`e79e9d60 fffff800`86acb6a7 : ffffb285`e79e9f00 ffffa281`00000001 00000000`00000000 ffffa281`2ddc0500 : Ntfs!NtfsDecrementCloseCounts+0xb0
- ffffb285`e79e9da0 fffff800`86ac81c1 : ffffdb0e`04d4a018 ffffa281`2ddc0700 ffffa281`2ddc05a0 ffffdb0d`fd51e180 : Ntfs!NtfsCommonClose+0x467
- ffffb285`e79e9e80 fffff800`86b2f014 : ffffb285`e79ea2f0 fffff800`83e46d25 ffffdb0e`042c6100 fffff800`84211fbb : Ntfs!NtfsFspCloseInternal+0x241
- ffffb285`e79e9fe0 fffff800`86aeb91c : 00000000`00000000 00000000`00000000 ffffdb0d`fd51e180 ffffa281`2391e460 : Ntfs!NtfsFlushVolume+0x10c
- ffffb285`e79ea0f0 fffff800`86aeaaf9 : ffffdb0e`02131a98 ffffdb0e`01d9fa20 ffffdb0e`02131a01 ffffb285`e79ea320 : Ntfs!NtfsCommonFlushBuffers+0x8d0
- ffffb285`e79ea210 fffff800`83e371f8 : ffffb285`e79ea320 ffffdb0e`02131a98 ffffdb0d`00000000 ffffdb0e`01d9fa20 : Ntfs!NtfsCommonFlushBuffersCallout+0x19
- ffffb285`e79ea240 fffff800`83e3716d : fffff800`86aeaae0 ffffb285`e79ea320 00000000`00000000 fffff800`00000000 : nt!KeExpandKernelStackAndCalloutInternal+0x78
- ffffb285`e79ea2b0 fffff800`86aaa5fb : 00000000`00000000 00000000`00000310 ffffb285`e79eb000 00000000`00000030 : nt!KeExpandKernelStackAndCalloutEx+0x1d
- ffffb285`e79ea2f0 fffff800`86aaa525 : 00000000`00000000 ffffdb0d`f9add1c0 ffffb285`e79ea388 00000000`00000000 : Ntfs!NtfsCommonFlushBuffersOnNewStack+0x67
- ffffb285`e79ea360 fffff800`83e46d25 : ffffdb0e`038e84a0 ffffdb0e`01d9fa20 ffffdb0e`02131a98 ffffb285`e79ea388 : Ntfs!NtfsFsdFlushBuffers+0xe5
- ffffb285`e79ea3d0 fffff800`808b6ccf : ffffb285`e79ea448 ffffb285`e79ea4f0 ffffb285`e79ea430 00000000`00000000 : nt!IofCallDriver+0x55
- ffffb285`e79ea410 fffff800`808b48d3 : ffffb285`e79ea4a0 00000000`00000000 00000000`00000000 ffffdb0d`f9aaeb80 : FLTMGR!FltpLegacyProcessingAfterPreCallbacksCompleted+0x28f
- ffffb285`e79ea480 fffff800`83e46d25 : ffffdb0e`01d9fa20 ffffdb0d`f849c000 ffffb285`e79ea710 00000000`00000000 : FLTMGR!FltpDispatch+0xa3
- ffffb285`e79ea4e0 fffff800`8420eb18 : ffffb285`e79ea710 ffffdb0e`01d9fa20 00000000`00000001 00000000`00000000 : nt!IofCallDriver+0x55
- ffffb285`e79ea520 fffff800`842ec0f9 : ffffdb0e`00000000 ffffb285`e79ea710 00000000`00000000 ffffb285`e79ea710 : nt!IopSynchronousServiceTail+0x1a8
- ffffb285`e79ea5c0 fffff800`842ebee6 : ffffdb0e`01791040 00000000`00000000 ffffdb0d`fd38cd60 00000000`00000000 : nt!NtFlushBuffersFileEx+0x1f9
- ffffb285`e79ea650 fffff800`83fef375 : fffff800`83c00000 fffff800`83e0198e ffffb285`e79ea8e0 00000000`00000000 : nt!NtFlushBuffersFile+0x16
- ffffb285`e79ea690 fffff800`83fe1880 : fffff800`845a45ca ffffb285`e6bef470 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
- ffffb285`e79ea828 fffff800`845a45ca : ffffb285`e6bef470 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiServiceLinkage
- ffffb285`e79ea830 fffff800`83f46715 : ffffdb0e`01791040 ffffdb0e`01791040 fffff800`845a4440 00000000`00000001 : nt!PopFlushVolumeWorker+0x18a
- ffffb285`e79eab10 fffff800`83fe5078 : ffffcb01`6a55a180 ffffdb0e`01791040 fffff800`83f466c0 00000000`00000000 : nt!PspSystemThreadStartup+0x55
- ffffb285`e79eab60 00000000`00000000 : ffffb285`e79eb000 ffffb285`e79e4000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
- STACK_COMMAND: kb
- THREAD_SHA1_HASH_MOD_FUNC: 43f7b136cf5cc46624075a6455a6b6b346a966f9
- THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 7d9c051ff9e9b85b738d9e76b3291308b3af3d8c
- THREAD_SHA1_HASH_MOD: 8e49d1ed9c175267305950cab8dabd3bd45d3494
- FOLLOWUP_IP:
- nt!CcUninitializeCacheMap+1afd99
- fffff800`840313b9 cc int 3
- FAULT_INSTR_CODE: 838d48cc
- SYMBOL_STACK_INDEX: 1
- SYMBOL_NAME: nt!CcUninitializeCacheMap+1afd99
- FOLLOWUP_NAME: MachineOwner
- MODULE_NAME: nt
- IMAGE_NAME: ntkrnlmp.exe
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- IMAGE_VERSION: 10.0.19041.330
- BUCKET_ID_FUNC_OFFSET: 1afd99
- FAILURE_BUCKET_ID: 0x34_nt!CcUninitializeCacheMap
- BUCKET_ID: 0x34_nt!CcUninitializeCacheMap
- PRIMARY_PROBLEM_CLASS: 0x34_nt!CcUninitializeCacheMap
- TARGET_TIME: 2020-06-26T17:09:08.000Z
- SUITE_MASK: 784
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:0x34_nt!ccuninitializecachemap
- FAILURE_ID_HASH: {8e05a99b-1bec-5629-33ce-0f8c05cbbfc6}
- Followup: MachineOwner
- ====================== Dump #1: 3RD PARTY DRIVERS ======================
- Oct 09 2015 - wdcsam64.sys - Western Digital SCSI Arcitecture Model (SAM) WDM driver https://support.wdc.com/
- Jan 21 2019 - imaucxhpal.sys - MA-USB (UCX) HPAL driver
- Jan 21 2019 - iwigig.sys - WiGig MAC driver (Intel)
- Mar 19 2019 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- Apr 04 2019 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
- May 07 2019 - e1d68x64.sys - Intel(R) Gigabit Adapter driver
- Oct 02 2019 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- ================== Dump #1: 3RD PARTY DRIVERS (FULL) ===================
- Image name: wdcsam64.sys
- Search : https://www.google.com/search?q=wdcsam64.sys
- ADA Info : Western Digital SCSI Arcitecture Model (SAM) WDM driver https://support.wdc.com/
- Timestamp : Fri Oct 9 2015
- Image name: imaucxhpal.sys
- Search : https://www.google.com/search?q=imaucxhpal.sys
- ADA Info : MA-USB (UCX) HPAL driver
- Timestamp : Mon Jan 21 2019
- Image name: iwigig.sys
- Search : https://www.google.com/search?q=iwigig.sys
- ADA Info : WiGig MAC driver (Intel)
- Timestamp : Mon Jan 21 2019
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Tue Mar 19 2019
- Image name: TeeDriverW8x64.sys
- Search : https://www.google.com/search?q=TeeDriverW8x64.sys
- ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Timestamp : Thu Apr 4 2019
- Image name: e1d68x64.sys
- Search : https://www.google.com/search?q=e1d68x64.sys
- ADA Info : Intel(R) Gigabit Adapter driver
- Timestamp : Tue May 7 2019
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Wed Oct 2 2019
- ====================== Dump #1: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- acpipagr.sys ACPI Processor Aggregator Device driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CimFS.SYS Consumer IR Class Driver for eHome (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storport.sys Provides disk access during crash dump file generation (Microsoft)
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HdAudio.sys High Definition Audio Function driver (Microsoft)
- hiber_dumpfve.sys (Generic Description) hiber_*.sys drivers provide disk access to store the system state while hibernating
- hiber_storahci.sys (Generic Description) hiber_*.sys drivers provide disk access to store the system state while hibernating
- hiber_storport.sys (Generic Description) hiber_*.sys drivers provide disk access to store the system state while hibernating
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- intelppm.sys Processor Device Driver (Microsoft)
- IntelTA.sys Intel Telemetry Driver
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kdcom.dll Kernel Debugger HW Extension DLL (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate.dll Media Center Update (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- MpKslDrv.sys Microsoft Anti-malware Protection driver
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb10.sys Longhorn SMB Downlevel SubRdr (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msquic.sys Windows QUIC Driver
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndiscap.sys Microsoft NDIS Packet Capture Filter Driver
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdpvideominiport.sys RDP Video Miniport driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- serenum.sys Serial Port Enumerator (Microsoft)
- serial.sys Serial Device Driver
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- stornvme.sys NVM Express Storport Miniport driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- ucx01000.sys USB Controller Extension (Microsoft)
- udfs.sys UDF File System driver (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- USBSTOR.SYS USB Mass Storage Class driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WpdUpFltr.sys Portable Device Upper Class Filter driver (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- WUDFRd.sys Windows Driver Foundation - User-mode Driver Framework Reflector driver (Microsoft)
- ====================== Dump #1: UNLOADED MODULES =======================
- fffff800`9a5e0000 fffff800`9a5ef000 dump_storpor
- fffff800`99a40000 fffff800`99a73000 dump_storahc
- fffff800`99aa0000 fffff800`99abe000 dump_dumpfve
- fffff800`9b110000 fffff800`9b165000 WUDFRd.sys
- fffff800`9a3e0000 fffff800`9a3fc000 dam.sys
- fffff800`86400000 fffff800`86411000 WdBoot.sys
- fffff800`874b0000 fffff800`874c0000 hwpolicy.sys
- ====================== Dump #1: BIOS INFORMATION =======================
- sysinfo: could not find necessary interfaces.
- sysinfo: note that mssmbios.sys must be loaded (XPSP2+).
- ========================== Dump #1: Extra #1 ===========================
- 0: kd> !verifier
- fffff8008482a6c0: Unable to get verifier list.
- ========================== Dump #1: Extra #2 ===========================
- 0: kd> !thread
- THREAD ffffdb0e01791040 Cid 0004.2810 Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor 0
- IRP List:
- Unable to read nt!_IRP @ ffffdb0e01d9fa20
- Not impersonating
- GetUlongFromAddress: unable to read from fffff8008481143c
- Owning Process ffffdb0df849c040 Image: System
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 143171
- Context Switch Count 287 IdealProcessor: 0
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address nt!PopFlushVolumeWorker (0xfffff800845a4440)
- Stack Init ffffb285e79eab90 Current ffffb285e79e8760
- Base ffffb285e79eb000 Limit ffffb285e79e4000 Call 0000000000000000
- Priority 9 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- ffffb285`e79e9a98 fffff800`840313b9 : 00000000`00000034 00000000`00000944 ffffffff`c0000420 00000000`00000000 : nt!KeBugCheckEx
- ffffb285`e79e9aa0 fffff800`86b0fed0 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!CcUninitializeCacheMap+0x1afd99
- ffffb285`e79e9b60 fffff800`86b00bd0 : ffffa281`2ba52800 ffffa281`2ba528a0 00000000`00000000 ffffa281`2ba52a00 : Ntfs!NtfsDeleteInternalAttributeStream+0x10c
- ffffb285`e79e9ba0 fffff800`869eace5 : ffffa281`2ba528a0 ffffa281`2ba52a00 00000000`00000000 ffffa281`2ba52a00 : Ntfs!NtfsRemoveScb+0x130
- ffffb285`e79e9c00 fffff800`869ea9b9 : ffffa281`2ddc05e0 00000000`00000000 ffffdb0d`fd51e180 ffffa281`2ba528a0 : Ntfs!NtfsPrepareFcbForRemoval+0x75
- ffffb285`e79e9c40 fffff800`86b008ea : ffffdb0e`04d4a018 ffffdb0d`fd51e180 ffffa281`2ddc05a0 ffffa281`2ddc09f8 : Ntfs!NtfsTeardownFromLcb+0x2c9
- ffffb285`e79e9ce0 fffff800`869dd560 : ffffdb0e`04d4a018 ffffb285`e79e9de2 ffffa281`2ddc09f8 ffffa281`2ddc05a0 : Ntfs!NtfsTeardownStructures+0xea
- ffffb285`e79e9d60 fffff800`86acb6a7 : ffffb285`e79e9f00 ffffa281`00000001 00000000`00000000 ffffa281`2ddc0500 : Ntfs!NtfsDecrementCloseCounts+0xb0
- ffffb285`e79e9da0 fffff800`86ac81c1 : ffffdb0e`04d4a018 ffffa281`2ddc0700 ffffa281`2ddc05a0 ffffdb0d`fd51e180 : Ntfs!NtfsCommonClose+0x467
- ffffb285`e79e9e80 fffff800`86b2f014 : ffffb285`e79ea2f0 fffff800`83e46d25 ffffdb0e`042c6100 fffff800`84211fbb : Ntfs!NtfsFspCloseInternal+0x241
- ffffb285`e79e9fe0 fffff800`86aeb91c : 00000000`00000000 00000000`00000000 ffffdb0d`fd51e180 ffffa281`2391e460 : Ntfs!NtfsFlushVolume+0x10c
- ffffb285`e79ea0f0 fffff800`86aeaaf9 : ffffdb0e`02131a98 ffffdb0e`01d9fa20 ffffdb0e`02131a01 ffffb285`e79ea320 : Ntfs!NtfsCommonFlushBuffers+0x8d0
- ffffb285`e79ea210 fffff800`83e371f8 : ffffb285`e79ea320 ffffdb0e`02131a98 ffffdb0d`00000000 ffffdb0e`01d9fa20 : Ntfs!NtfsCommonFlushBuffersCallout+0x19
- ffffb285`e79ea240 fffff800`83e3716d : fffff800`86aeaae0 ffffb285`e79ea320 00000000`00000000 fffff800`00000000 : nt!KeExpandKernelStackAndCalloutInternal+0x78
- ffffb285`e79ea2b0 fffff800`86aaa5fb : 00000000`00000000 00000000`00000310 ffffb285`e79eb000 00000000`00000030 : nt!KeExpandKernelStackAndCalloutEx+0x1d
- ffffb285`e79ea2f0 fffff800`86aaa525 : 00000000`00000000 ffffdb0d`f9add1c0 ffffb285`e79ea388 00000000`00000000 : Ntfs!NtfsCommonFlushBuffersOnNewStack+0x67
- ffffb285`e79ea360 fffff800`83e46d25 : ffffdb0e`038e84a0 ffffdb0e`01d9fa20 ffffdb0e`02131a98 ffffb285`e79ea388 : Ntfs!NtfsFsdFlushBuffers+0xe5
- ffffb285`e79ea3d0 fffff800`808b6ccf : ffffb285`e79ea448 ffffb285`e79ea4f0 ffffb285`e79ea430 00000000`00000000 : nt!IofCallDriver+0x55
- ffffb285`e79ea410 fffff800`808b48d3 : ffffb285`e79ea4a0 00000000`00000000 00000000`00000000 ffffdb0d`f9aaeb80 : FLTMGR!FltpLegacyProcessingAfterPreCallbacksCompleted+0x28f
- ffffb285`e79ea480 fffff800`83e46d25 : ffffdb0e`01d9fa20 ffffdb0d`f849c000 ffffb285`e79ea710 00000000`00000000 : FLTMGR!FltpDispatch+0xa3
- ffffb285`e79ea4e0 fffff800`8420eb18 : ffffb285`e79ea710 ffffdb0e`01d9fa20 00000000`00000001 00000000`00000000 : nt!IofCallDriver+0x55
- ffffb285`e79ea520 fffff800`842ec0f9 : ffffdb0e`00000000 ffffb285`e79ea710 00000000`00000000 ffffb285`e79ea710 : nt!IopSynchronousServiceTail+0x1a8
- ffffb285`e79ea5c0 fffff800`842ebee6 : ffffdb0e`01791040 00000000`00000000 ffffdb0d`fd38cd60 00000000`00000000 : nt!NtFlushBuffersFileEx+0x1f9
- ffffb285`e79ea650 fffff800`83fef375 : fffff800`83c00000 fffff800`83e0198e ffffb285`e79ea8e0 00000000`00000000 : nt!NtFlushBuffersFile+0x16
- ffffb285`e79ea690 fffff800`83fe1880 : fffff800`845a45ca ffffb285`e6bef470 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25 (TrapFrame @ ffffb285`e79ea690)
- ffffb285`e79ea828 fffff800`845a45ca : ffffb285`e6bef470 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiServiceLinkage
- ffffb285`e79ea830 fffff800`83f46715 : ffffdb0e`01791040 ffffdb0e`01791040 fffff800`845a4440 00000000`00000001 : nt!PopFlushVolumeWorker+0x18a
- ffffb285`e79eab10 fffff800`83fe5078 : ffffcb01`6a55a180 ffffdb0e`01791040 fffff800`83f466c0 00000000`00000000 : nt!PspSystemThreadStartup+0x55
- ffffb285`e79eab60 00000000`00000000 : ffffb285`e79eb000 ffffb285`e79e4000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
- ========================================================================
- ======================= Dump #2: ANALYZE VERBOSE =======================
- ======================= File: 062620-4109-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 19041 MP (12 procs) Free x64
- Kernel base = 0xfffff802`0ee00000 PsLoadedModuleList = 0xfffff802`0fa2a2b0
- Debug session time: Fri Jun 26 18:45:27.123 2020 (UTC - 4:00)
- System Uptime: 0 days 0:20:07.790
- BugCheck 1A, {41792, ffff903ffe4da3f8, 100000000000000, 0}
- Probably caused by : memory_corruption ( ONE_BIT )
- Followup: MachineOwner
- MEMORY_MANAGEMENT (1a)
- # Any other values for parameter 1 must be individually examined.
- Arguments:
- Arg1: 0000000000041792, A corrupt PTE has been detected. Parameter 2 contains the address of
- the PTE. Parameters 3/4 contain the low/high parts of the PTE.
- Arg2: ffff903ffe4da3f8
- Arg3: 0100000000000000
- Arg4: 0000000000000000
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- DUMP_FILE_ATTRIBUTES: 0x8
- Kernel Generated Triage Dump
- MEMORY_CORRUPTOR: ONE_BIT
- BUGCHECK_STR: 0x1a_41792
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
- PROCESS_NAME: svchost.exe
- CURRENT_IRQL: 2
- STACK_TEXT:
- ffff8684`bf36f1c8 fffff802`0f25418e : 00000000`0000001a 00000000`00041792 ffff903f`fe4da3f8 01000000`00000000 : nt!KeBugCheckEx
- ffff8684`bf36f1d0 fffff802`0f0c215f : ffffa501`524a5700 00007ffc`9b460000 00000000`00000002 ffff8684`bf36f3c0 : nt!MiDeleteVa+0x191e6e
- ffff8684`bf36f2c0 fffff802`0f0a787f : 00000000`00000000 00000000`00000060 ffffa501`524a57c0 00000000`00000000 : nt!MiDeletePagablePteRange+0x31f
- ffff8684`bf36f740 fffff802`0f3eab99 : ffffa501`524a5080 00000000`00000000 00000000`00000000 ffffa501`00000001 : nt!MiDeleteVad+0x41f
- ffff8684`bf36f870 fffff802`0f3ea972 : ffffa501`55e98220 00007ffc`9b460000 ffffa501`524a5080 00000000`00000000 : nt!MiUnmapVad+0x49
- ffff8684`bf36f8a0 fffff802`0f3ea7e9 : ffffa501`526ab080 fffff802`0f1ef375 00000000`00000000 00000000`00000000 : nt!MiUnmapViewOfSection+0x152
- ffff8684`bf36f980 fffff802`0f3ea3ec : ffffa501`526ab080 00000180`04a2c130 00000000`00000001 ffffa501`524a5080 : nt!NtUnmapViewOfSectionEx+0x99
- ffff8684`bf36f9d0 fffff802`0f1ef375 : ffffa501`526ab000 00000000`00000010 ffff8684`bf36fa80 ffffa501`00000000 : nt!NtUnmapViewOfSection+0xc
- ffff8684`bf36fa00 00007ffc`9ebeb2d4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
- 00000060`3fa7cd08 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffc`9ebeb2d4
- STACK_COMMAND: kb
- THREAD_SHA1_HASH_MOD_FUNC: 960b7cb4384a69a432e1bb91134d79d8580a5250
- THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 65b113d111711ecf7a86f1e57421062255defe4e
- THREAD_SHA1_HASH_MOD: 9f457f347057f10e1df248e166a3e95e6570ecfe
- SYMBOL_NAME: ONE_BIT
- FOLLOWUP_NAME: MachineOwner
- MODULE_NAME: hardware
- IMAGE_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_ONE_BIT
- BUCKET_ID: MEMORY_CORRUPTION_ONE_BIT
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_ONE_BIT
- TARGET_TIME: 2020-06-26T22:45:27.000Z
- SUITE_MASK: 784
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_one_bit
- FAILURE_ID_HASH: {e3faf315-c3d0-81db-819a-6c43d23c63a7}
- Followup: MachineOwner
- ====================== Dump #2: 3RD PARTY DRIVERS ======================
- Oct 09 2015 - wdcsam64.sys - Western Digital SCSI Arcitecture Model (SAM) WDM driver https://support.wdc.com/
- Jan 21 2019 - imaucxhpal.sys - MA-USB (UCX) HPAL driver
- Jan 21 2019 - iwigig.sys - WiGig MAC driver (Intel)
- Mar 19 2019 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- Apr 04 2019 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
- May 07 2019 - e1d68x64.sys - Intel(R) Gigabit Adapter driver
- Oct 02 2019 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- ================== Dump #2: 3RD PARTY DRIVERS (FULL) ===================
- Image name: wdcsam64.sys
- Search : https://www.google.com/search?q=wdcsam64.sys
- ADA Info : Western Digital SCSI Arcitecture Model (SAM) WDM driver https://support.wdc.com/
- Timestamp : Fri Oct 9 2015
- Image name: imaucxhpal.sys
- Search : https://www.google.com/search?q=imaucxhpal.sys
- ADA Info : MA-USB (UCX) HPAL driver
- Timestamp : Mon Jan 21 2019
- Image name: iwigig.sys
- Search : https://www.google.com/search?q=iwigig.sys
- ADA Info : WiGig MAC driver (Intel)
- Timestamp : Mon Jan 21 2019
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Tue Mar 19 2019
- Image name: TeeDriverW8x64.sys
- Search : https://www.google.com/search?q=TeeDriverW8x64.sys
- ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Timestamp : Thu Apr 4 2019
- Image name: e1d68x64.sys
- Search : https://www.google.com/search?q=e1d68x64.sys
- ADA Info : Intel(R) Gigabit Adapter driver
- Timestamp : Tue May 7 2019
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Wed Oct 2 2019
- ====================== Dump #2: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- acpipagr.sys ACPI Processor Aggregator Device driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CimFS.SYS Consumer IR Class Driver for eHome (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storport.sys Provides disk access during crash dump file generation (Microsoft)
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HdAudio.sys High Definition Audio Function driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- intelppm.sys Processor Device Driver (Microsoft)
- IntelTA.sys Intel Telemetry Driver
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kdcom.dll Kernel Debugger HW Extension DLL (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate.dll Media Center Update (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- MpKslDrv.sys Microsoft Anti-malware Protection driver
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb10.sys Longhorn SMB Downlevel SubRdr (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msquic.sys Windows QUIC Driver
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndiscap.sys Microsoft NDIS Packet Capture Filter Driver
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- serenum.sys Serial Port Enumerator (Microsoft)
- serial.sys Serial Device Driver
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- stornvme.sys NVM Express Storport Miniport driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- ucx01000.sys USB Controller Extension (Microsoft)
- udfs.sys UDF File System driver (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- USBSTOR.SYS USB Mass Storage Class driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WpdUpFltr.sys Portable Device Upper Class Filter driver (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- WUDFRd.sys Windows Driver Foundation - User-mode Driver Framework Reflector driver (Microsoft)
- ====================== Dump #2: UNLOADED MODULES =======================
- fffff802`68fc0000 fffff802`68fc8000 magdrvamd64.
- fffff802`68fb0000 fffff802`68fb8000 magdrvamd64.
- fffff802`25030000 fffff802`2503f000 dump_storpor
- fffff802`25080000 fffff802`250b3000 dump_storahc
- fffff802`250e0000 fffff802`250fe000 dump_dumpfve
- fffff802`27f30000 fffff802`27f85000 WUDFRd.sys
- fffff802`25ac0000 fffff802`25adc000 dam.sys
- fffff802`11c00000 fffff802`11c11000 WdBoot.sys
- fffff802`12cb0000 fffff802`12cc0000 hwpolicy.sys
- ====================== Dump #2: BIOS INFORMATION =======================
- sysinfo: could not find necessary interfaces.
- sysinfo: note that mssmbios.sys must be loaded (XPSP2+).
- ========================== Dump #2: Extra #1 ===========================
- 5: kd> !verifier
- fffff8020fa2a6c0: Unable to get verifier list.
- ========================== Dump #2: Extra #2 ===========================
- 5: kd> !thread
- THREAD ffffa501526ab080 Cid 10d8.1ad4 Teb: 000000603f417000 Win32Thread: 0000000000000000 RUNNING on processor 5
- Not impersonating
- GetUlongFromAddress: unable to read from fffff8020fa1143c
- Owning Process ffffa501524a5080 Image: svchost.exe
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 77298
- Context Switch Count 3 IdealProcessor: 5
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address 0x00007ffc9eb620e0
- Stack Init ffff8684bf36fb90 Current ffff8684bf36f2c0
- Base ffff8684bf370000 Limit ffff8684bf369000 Call 0000000000000000
- Priority 9 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- ffff8684`bf36f1c8 fffff802`0f25418e : 00000000`0000001a 00000000`00041792 ffff903f`fe4da3f8 01000000`00000000 : nt!KeBugCheckEx
- ffff8684`bf36f1d0 fffff802`0f0c215f : ffffa501`524a5700 00007ffc`9b460000 00000000`00000002 ffff8684`bf36f3c0 : nt!MiDeleteVa+0x191e6e
- ffff8684`bf36f2c0 fffff802`0f0a787f : 00000000`00000000 00000000`00000060 ffffa501`524a57c0 00000000`00000000 : nt!MiDeletePagablePteRange+0x31f
- ffff8684`bf36f740 fffff802`0f3eab99 : ffffa501`524a5080 00000000`00000000 00000000`00000000 ffffa501`00000001 : nt!MiDeleteVad+0x41f
- ffff8684`bf36f870 fffff802`0f3ea972 : ffffa501`55e98220 00007ffc`9b460000 ffffa501`524a5080 00000000`00000000 : nt!MiUnmapVad+0x49
- ffff8684`bf36f8a0 fffff802`0f3ea7e9 : ffffa501`526ab080 fffff802`0f1ef375 00000000`00000000 00000000`00000000 : nt!MiUnmapViewOfSection+0x152
- ffff8684`bf36f980 fffff802`0f3ea3ec : ffffa501`526ab080 00000180`04a2c130 00000000`00000001 ffffa501`524a5080 : nt!NtUnmapViewOfSectionEx+0x99
- ffff8684`bf36f9d0 fffff802`0f1ef375 : ffffa501`526ab000 00000000`00000010 ffff8684`bf36fa80 ffffa501`00000000 : nt!NtUnmapViewOfSection+0xc
- ffff8684`bf36fa00 00007ffc`9ebeb2d4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25 (TrapFrame @ ffff8684`bf36fa00)
- 00000060`3fa7cd08 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffc`9ebeb2d4
- ========================================================================
- ======================= Dump #3: ANALYZE VERBOSE =======================
- ======================= File: 062620-3953-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 19041 MP (12 procs) Free x64
- Kernel base = 0xfffff802`7e000000 PsLoadedModuleList = 0xfffff802`7ec2a2b0
- Debug session time: Fri Jun 26 19:45:21.339 2020 (UTC - 4:00)
- System Uptime: 0 days 0:59:27.006
- BugCheck 1E, {ffffffffc0000005, fffff8027e225101, 0, ffffffffffffffff}
- Probably caused by : Unknown_Image ( nt!ExAcquireFastMutex+101 )
- Followup: MachineOwner
- KMODE_EXCEPTION_NOT_HANDLED (1e)
- This is a very common bugcheck. Usually the exception address pinpoints
- the driver/function that caused the problem. Always note this address
- as well as the link date of the driver/image that contains this address.
- Arguments:
- Arg1: ffffffffc0000005, The exception code that was not handled
- Arg2: fffff8027e225101, The address that the exception occurred at
- Arg3: 0000000000000000, Parameter 0 of the exception
- Arg4: ffffffffffffffff, Parameter 1 of the exception
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- DUMP_FILE_ATTRIBUTES: 0x8
- Kernel Generated Triage Dump
- READ_ADDRESS: fffff8027ecfa388: Unable to get MiVisibleState
- ffffffffffffffff
- EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.
- FAULTING_IP:
- nt!ExAcquireFastMutex+101
- fffff802`7e225101 f00fba3600 lock btr dword ptr [rsi],0
- EXCEPTION_PARAMETER2: ffffffffffffffff
- BUGCHECK_STR: 0x1E_c0000005_R
- CUSTOMER_CRASH_COUNT: 1
- PROCESS_NAME: steamwebhelper
- CURRENT_IRQL: 1
- EXCEPTION_RECORD: 0000000000000001 -- (.exr 0x1)
- Cannot read Exception record @ 0000000000000001
- TRAP_FRAME: ffffe189a901f508 -- (.trap 0xffffe189a901f508)
- NOTE: The trap frame does not contain all registers.
- Some register values may be zeroed or incorrect.
- rax=0000000000000000 rbx=0000000000000000 rcx=0000000000000000
- rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
- rip=ffff9381b0cd5180 rsp=0000000000000000 rbp=ffffbc82e9ca3060
- r8=ffff0c717a96adef r9=ffffe508ed4060c0 r10=ffffe189a901f680
- r11=0000000000000001 r12=0000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=0000000000000000
- iopl=0 nv up di pl nz ac pe nc
- ffff9381`b0cd5180 ?? ???
- Resetting default scope
- LAST_CONTROL_TRANSFER: from fffff8027e42edf9 to fffff8027e3dda20
- STACK_TEXT:
- ffffe189`a901e918 fffff802`7e42edf9 : 00000000`0000001e ffffffff`c0000005 fffff802`7e225101 00000000`00000000 : nt!KeBugCheckEx
- ffffe189`a901e920 fffff802`7e3efa6c : 00000000`00000001 ffffe189`a901f508 ffffe189`a901f508 00000000`00000000 : nt!KiDispatchException+0x1b3d59
- ffffe189`a901efe0 fffff802`7e3eb7a0 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiExceptionDispatch+0x12c
- ffffe189`a901f1c0 fffff802`7e225101 : ffffe508`ef509118 02000000`00000018 ffffe508`e2893040 00000000`00000000 : nt!KiGeneralProtectionFault+0x320
- ffffe189`a901f350 fffff802`7e891c01 : 00000000`00000000 00000000`00000001 00000000`00000000 fffff802`7ec31de8 : nt!ExAcquireFastMutex+0x101
- ffffe189`a901f3a0 fffff802`7e893728 : 00000000`00000002 ffffe508`ef509080 ffffe508`ef509378 00000000`00000000 : nt!DbgkpQueueMessage+0x1b9
- ffffe189`a901f5a0 fffff802`7e80f345 : 00000000`00000000 ffffe189`a901fa80 ffffe508`ef509080 fffff802`7ed22640 : nt!DbgkpSendApiMessage+0xa4
- ffffe189`a901f5f0 fffff802`7e65edfb : ffff9381`b1136180 ffff9381`b1136180 ffffe508`ef509080 00000000`00000000 : nt!DbgkCreateThread+0x1b0421
- ffffe189`a901f7d0 fffff802`7e3e53e8 : ffff9381`b1136180 ffffe508`ef509080 ffff9381`b1141340 00000000`00000000 : nt!PspUserThreadStartup+0xbb
- ffffe189`a901f8c0 fffff802`7e3e5350 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiStartUserThread+0x28
- ffffe189`a901fa00 00007ff9`3d2fcea0 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiStartUserThreadReturn
- 000000f0`751ffb28 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff9`3d2fcea0
- STACK_COMMAND: kb
- THREAD_SHA1_HASH_MOD_FUNC: 3e0ad8521d541f1ec6916b3f425b6bb7261d7291
- THREAD_SHA1_HASH_MOD_FUNC_OFFSET: a1c506f700c692767b246ec025495a5714399513
- THREAD_SHA1_HASH_MOD: b28610981796779b4ac02f58898fde25728a775c
- FOLLOWUP_IP:
- nt!ExAcquireFastMutex+101
- fffff802`7e225101 f00fba3600 lock btr dword ptr [rsi],0
- FAULT_INSTR_CODE: 36ba0ff0
- SYMBOL_STACK_INDEX: 4
- SYMBOL_NAME: nt!ExAcquireFastMutex+101
- FOLLOWUP_NAME: MachineOwner
- IMAGE_NAME: Unknown_Image
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- IMAGE_VERSION: 10.0.19041.330
- MODULE_NAME: Unknown_Module
- BUCKET_ID: RAISED_IRQL_USER_FAULT_0x1E_c0000005_R
- DEFAULT_BUCKET_ID: RAISED_IRQL_USER_FAULT_0x1E_c0000005_R
- PRIMARY_PROBLEM_CLASS: RAISED_IRQL_USER_FAULT
- FAILURE_BUCKET_ID: RAISED_IRQL_USER_FAULT_0x1E_c0000005_R
- TARGET_TIME: 2020-06-26T23:45:21.000Z
- SUITE_MASK: 784
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:raised_irql_user_fault_0x1e_c0000005_r
- FAILURE_ID_HASH: {d1e1826c-605d-7a79-a04d-b8220695ad88}
- Followup: MachineOwner
- ====================== Dump #3: 3RD PARTY DRIVERS ======================
- Oct 09 2015 - wdcsam64.sys - Western Digital SCSI Arcitecture Model (SAM) WDM driver https://support.wdc.com/
- Jan 21 2019 - imaucxhpal.sys - MA-USB (UCX) HPAL driver
- Jan 21 2019 - iwigig.sys - WiGig MAC driver (Intel)
- Mar 19 2019 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- Apr 04 2019 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
- May 07 2019 - e1d68x64.sys - Intel(R) Gigabit Adapter driver
- Oct 02 2019 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- ================== Dump #3: 3RD PARTY DRIVERS (FULL) ===================
- Image name: wdcsam64.sys
- Search : https://www.google.com/search?q=wdcsam64.sys
- ADA Info : Western Digital SCSI Arcitecture Model (SAM) WDM driver https://support.wdc.com/
- Timestamp : Fri Oct 9 2015
- Image name: imaucxhpal.sys
- Search : https://www.google.com/search?q=imaucxhpal.sys
- ADA Info : MA-USB (UCX) HPAL driver
- Timestamp : Mon Jan 21 2019
- Image name: iwigig.sys
- Search : https://www.google.com/search?q=iwigig.sys
- ADA Info : WiGig MAC driver (Intel)
- Timestamp : Mon Jan 21 2019
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Tue Mar 19 2019
- Image name: TeeDriverW8x64.sys
- Search : https://www.google.com/search?q=TeeDriverW8x64.sys
- ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Timestamp : Thu Apr 4 2019
- Image name: e1d68x64.sys
- Search : https://www.google.com/search?q=e1d68x64.sys
- ADA Info : Intel(R) Gigabit Adapter driver
- Timestamp : Tue May 7 2019
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Wed Oct 2 2019
- ====================== Dump #3: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- acpipagr.sys ACPI Processor Aggregator Device driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CimFS.SYS Consumer IR Class Driver for eHome (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storahci.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_storport.sys Provides disk access during crash dump file generation (Microsoft)
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HdAudio.sys High Definition Audio Function driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- intelppm.sys Processor Device Driver (Microsoft)
- IntelTA.sys Intel Telemetry Driver
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kdcom.dll Kernel Debugger HW Extension DLL (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate.dll Media Center Update (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- MpKslDrv.sys Microsoft Anti-malware Protection driver
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb10.sys Longhorn SMB Downlevel SubRdr (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msquic.sys Windows QUIC Driver
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndiscap.sys Microsoft NDIS Packet Capture Filter Driver
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- serenum.sys Serial Port Enumerator (Microsoft)
- serial.sys Serial Device Driver
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storahci.sys MS AHCI Storport Miniport Driver (Microsoft)
- stornvme.sys NVM Express Storport Miniport driver (Microsoft)
- storport.sys Storage port driver for use with high-performance buses such as fibre channel buses and RAID adapters. (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- ucx01000.sys USB Controller Extension (Microsoft)
- udfs.sys UDF File System driver (Microsoft)
- UEFI.sys UEFI NT driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbaudio.sys USB Audio Class Driver (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- UsbHub3.sys USB3 HUB driver (Microsoft)
- USBSTOR.SYS USB Mass Storage Class driver (Microsoft)
- USBXHCI.SYS USB XHCI driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- wmiacpi.sys Windows Management Interface for ACPI (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WpdUpFltr.sys Portable Device Upper Class Filter driver (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- WUDFRd.sys Windows Driver Foundation - User-mode Driver Framework Reflector driver (Microsoft)
- ====================== Dump #3: UNLOADED MODULES =======================
- fffff802`d7f70000 fffff802`d7f78000 magdrvamd64.
- fffff802`d7f60000 fffff802`d7f68000 magdrvamd64.
- fffff802`94190000 fffff802`9419f000 dump_storpor
- fffff802`93e00000 fffff802`93e33000 dump_storahc
- fffff802`93e60000 fffff802`93e7e000 dump_dumpfve
- fffff802`95130000 fffff802`95185000 WUDFRd.sys
- fffff802`95bd0000 fffff802`95bec000 dam.sys
- fffff802`80800000 fffff802`80811000 WdBoot.sys
- fffff802`818b0000 fffff802`818c0000 hwpolicy.sys
- ====================== Dump #3: BIOS INFORMATION =======================
- sysinfo: could not find necessary interfaces.
- sysinfo: note that mssmbios.sys must be loaded (XPSP2+).
- ========================== Dump #3: Extra #1 ===========================
- 11: kd> !verifier
- fffff8027ec2a6c0: Unable to get verifier list.
- ========================== Dump #3: Extra #2 ===========================
- 11: kd> !thread
- THREAD ffffe508ef509080 Cid 2350.197c Teb: 000000f074e6d000 Win32Thread: 0000000000000000 RUNNING on processor b
- Not impersonating
- GetUlongFromAddress: unable to read from fffff8027ec1143c
- Owning Process ffffe508ed4060c0 Image: steamwebhelper
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 0
- Context Switch Count 1 IdealProcessor: 11
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address 0x00007ff9065b48c0
- Stack Init ffffe189a901fb90 Current ffffe189a901f880
- Base ffffe189a9020000 Limit ffffe189a9019000 Call 0000000000000000
- Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- ffffe189`a901e918 fffff802`7e42edf9 : 00000000`0000001e ffffffff`c0000005 fffff802`7e225101 00000000`00000000 : nt!KeBugCheckEx
- ffffe189`a901e920 fffff802`7e3efa6c : 00000000`00000001 ffffe189`a901f508 ffffe189`a901f508 00000000`00000000 : nt!KiDispatchException+0x1b3d59
- ffffe189`a901efe0 fffff802`7e3eb7a0 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiExceptionDispatch+0x12c
- ffffe189`a901f1c0 fffff802`7e225101 : ffffe508`ef509118 02000000`00000018 ffffe508`e2893040 00000000`00000000 : nt!KiGeneralProtectionFault+0x320 (TrapFrame @ ffffe189`a901f1c0)
- ffffe189`a901f350 fffff802`7e891c01 : 00000000`00000000 00000000`00000001 00000000`00000000 fffff802`7ec31de8 : nt!ExAcquireFastMutex+0x101
- ffffe189`a901f3a0 fffff802`7e893728 : 00000000`00000002 ffffe508`ef509080 ffffe508`ef509378 00000000`00000000 : nt!DbgkpQueueMessage+0x1b9
- ffffe189`a901f5a0 fffff802`7e80f345 : 00000000`00000000 ffffe189`a901fa80 ffffe508`ef509080 fffff802`7ed22640 : nt!DbgkpSendApiMessage+0xa4
- ffffe189`a901f5f0 fffff802`7e65edfb : ffff9381`b1136180 ffff9381`b1136180 ffffe508`ef509080 00000000`00000000 : nt!DbgkCreateThread+0x1b0421
- ffffe189`a901f7d0 fffff802`7e3e53e8 : ffff9381`b1136180 ffffe508`ef509080 ffff9381`b1141340 00000000`00000000 : nt!PspUserThreadStartup+0xbb
- ffffe189`a901f8c0 fffff802`7e3e5350 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiStartUserThread+0x28
- ffffe189`a901fa00 00007ff9`3d2fcea0 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiStartUserThreadReturn (TrapFrame @ ffffe189`a901fa00)
- 000000f0`751ffb28 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff9`3d2fcea0
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement