Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ========================== AUTO DUMP ANALYZER ==========================
- Auto Dump Analyzer
- Version: 0.91
- Time to analyze file(s): 00 hours and 04 minutes and 42 seconds
- ================================ SYSTEM ================================
- MANUFACTURER: Gigabyte Tecohnology Co., Ltd.
- PRODUCT_NAME: H61M-DS2
- ================================= BIOS =================================
- VENDOR: American Megatrends Inc.
- VERSION: F6
- DATE: 02/16/2012
- ============================= MOTHERBOARD ==============================
- MANUFACTURER: Gigabyte Tecohnology Co., Ltd.
- PRODUCT: H61M-DS2
- VERSION: x.x
- ================================= RAM ==================================
- Size Speed Manufacturer Part No.
- -------------- -------------- ------------------- ----------------------
- 4096MB 1333MHz Hynix/Hyundai HMT351U6CFR8C-H9
- 0MHz
- 4096MB 1333MHz 8325 FLFF65F-C8KL9
- 0MHz
- ================================= CPU ==================================
- Processor Version: Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
- COUNT: 4
- MHZ: 3293
- VENDOR: GenuineIntel
- FAMILY: 6
- MODEL: 2a
- STEPPING: 7
- MICROCODE: 6,2a,7,0 (F,M,S,R) SIG: 2F'00000000 (cache) 2F'00000000 (init)
- ================================== OS ==================================
- Product: WinNt, suite: TerminalServer SingleUserTS
- Built by: 19041.1.amd64fre.vb_release.191206-1406
- BUILD_VERSION: 10.0.19041.388 (WinBuild.160101.0800)
- BUILD: 19041
- SERVICEPACK: 388
- PLATFORM_TYPE: x64
- NAME: Windows 10
- EDITION: Windows 10 WinNt TerminalServer SingleUserTS
- BUILD_TIMESTAMP: unknown_date
- BUILDDATESTAMP: 160101.0800
- BUILDLAB: WinBuild
- BUILDOSVER: 10.0.19041.388
- =============================== DEBUGGER ===============================
- Microsoft (R) Windows Debugger Version 10.0.14321.1024 AMD64
- Copyright (c) Microsoft Corporation. All rights reserved.
- =============================== COMMENTS ===============================
- * Information gathered from different dump files may be different. If
- Windows updates between two dump files, two or more OS versions may
- be shown above.
- * If the user updates the BIOS between dump files, two or more versions
- and dates may be shown above.
- * More RAM information can be found below in a full BIOS section.
- ========================================================================
- ======================= Dump #1: ANALYZE VERBOSE =======================
- ====================== File: 081120-35937-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 19041 MP (4 procs) Free x64
- Kernel base = 0xfffff807`4d000000 PsLoadedModuleList = 0xfffff807`4dc2a310
- Debug session time: Mon Aug 10 19:39:19.376 2020 (UTC - 4:00)
- System Uptime: 0 days 1:46:29.092
- BugCheck 1A, {403, fffff880e25e7e68, 80000000152cf867, ffff9480e25e7e68}
- *** WARNING: Unable to verify timestamp for win32k.sys
- *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
- Probably caused by : memory_corruption
- Followup: memory_corruption
- MEMORY_MANAGEMENT (1a)
- # Any other values for parameter 1 must be individually examined.
- Arguments:
- Arg1: 0000000000000403, The subtype of the bugcheck.
- Arg2: fffff880e25e7e68
- Arg3: 80000000152cf867
- Arg4: ffff9480e25e7e68
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- BUGCHECK_STR: 0x1a_403
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- PROCESS_NAME: CefSharp.BrowserSubprocess.exe
- CURRENT_IRQL: 2
- LAST_CONTROL_TRANSFER: from fffff8074d4464a4 to fffff8074d3ddb60
- STACK_TEXT:
- fffffb04`4b8530e8 fffff807`4d4464a4 : 00000000`0000001a 00000000`00000403 fffff880`e25e7e68 80000000`152cf867 : nt!KeBugCheckEx
- fffffb04`4b8530f0 fffff807`4d2c1588 : 00000000`00000000 fffffb04`4b8534a0 fffffb04`4b8534a0 fffff880`e25e7e78 : nt!MiDeletePteRun+0x19b6a4
- fffffb04`4b853320 fffff807`4d2c219b : fffffb04`4b853450 ffffd688`080e1700 fffff880`e25e7e78 fffffb04`4b853450 : nt!MiDeleteVaTail+0x78
- fffffb04`4b853350 fffff807`4d2a789f : 00000000`00000000 00000000`00000060 ffffd688`080e17c0 000001c4`bcfcffff : nt!MiDeletePagablePteRange+0x33b
- fffffb04`4b8537d0 fffff807`4d29d9bb : ffffd688`080e1080 00000000`00000000 ffffd688`00000000 fffff807`00000001 : nt!MiDeleteVad+0x41f
- fffffb04`4b853900 fffff807`4d665fdc : fffffb04`00000000 00000000`00000000 fffffb04`4b853a60 00000000`00008000 : nt!MiFreeVadRange+0xa3
- fffffb04`4b853960 fffff807`4d665c05 : 00000000`00000000 00000042`7cbfab18 ffff9852`0734b8bb 00007ffa`00000004 : nt!MmFreeVirtualMemory+0x39c
- fffffb04`4b853aa0 fffff807`4d3ef478 : ffffd688`04a27080 000001c4`00000001 00007ffb`22534600 fffffb04`4b853b80 : nt!NtFreeVirtualMemory+0x95
- fffffb04`4b853b00 00007ffb`2f90b154 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
- 00000042`7cbfb118 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffb`2f90b154
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
- fffff8074d2c166a-fffff8074d2c166e 5 bytes - nt!MiDeleteVaTail+15a
- [ d0 be 7d fb f6:10 3f 7e fc f8 ]
- fffff8074d2c167d-fffff8074d2c1681 5 bytes - nt!MiDeleteVaTail+16d (+0x13)
- [ df be 7d fb f6:1f 3f 7e fc f8 ]
- fffff8074d2c2368-fffff8074d2c236c 5 bytes - nt!MiDeleteVa+28 (+0xceb)
- [ d0 be 7d fb f6:10 3f 7e fc f8 ]
- fffff8074d2c237b-fffff8074d2c237f 5 bytes - nt!MiDeleteVa+3b (+0x13)
- [ d7 be 7d fb f6:17 3f 7e fc f8 ]
- fffff8074d2c23e4 - nt!MiDeleteVa+a4 (+0x69)
- [ f6:f8 ]
- fffff8074d384f3e-fffff8074d384f41 4 bytes - nt!MiFreeUltraMapping+32 (+0xc2b5a)
- [ a0 7d fb f6:20 7e fc f8 ]
- 25 errors : !nt (fffff8074d2c166a-fffff8074d384f41)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-08-10T23:39:19.000Z
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #1: 3RD PARTY DRIVERS ======================
- Jul 21 2014 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- Sep 04 2014 - nvvad64v.sys - Nvidia Virtual Audio driver http://www.nvidia.com/
- Sep 06 2014 - NvStreamKms.sys - Nvidia Streaming Kernel Service http://www.nvidia.com/
- Mar 31 2015 - HWiNFO64A.SYS - HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
- Jul 07 2015 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
- May 26 2020 - rt640x64.sys - Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Jul 05 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- ================== Dump #1: 3RD PARTY DRIVERS (FULL) ===================
- Image path: \SystemRoot\system32\drivers\nvhda64v.sys
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Mon Jul 21 2014
- Image path: \SystemRoot\system32\drivers\nvvad64v.sys
- Image name: nvvad64v.sys
- Search : https://www.google.com/search?q=nvvad64v.sys
- ADA Info : Nvidia Virtual Audio driver http://www.nvidia.com/
- Timestamp : Thu Sep 4 2014
- Image path: \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
- Image name: NvStreamKms.sys
- Search : https://www.google.com/search?q=NvStreamKms.sys
- ADA Info : Nvidia Streaming Kernel Service http://www.nvidia.com/
- Timestamp : Sat Sep 6 2014
- Image path: \??\C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS
- Image name: HWiNFO64A.SYS
- Search : https://www.google.com/search?q=HWiNFO64A.SYS
- ADA Info : HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
- Timestamp : Tue Mar 31 2015
- Image path: \SystemRoot\System32\drivers\TeeDriverW8x64.sys
- Image name: TeeDriverW8x64.sys
- Search : https://www.google.com/search?q=TeeDriverW8x64.sys
- ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Timestamp : Tue Jul 7 2015
- Image path: \SystemRoot\System32\drivers\rt640x64.sys
- Image name: rt640x64.sys
- Search : https://www.google.com/search?q=rt640x64.sys
- ADA Info : Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Timestamp : Tue May 26 2020
- Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_e92a0ac2e05fb2ca\nvlddmkm.sys
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Sun Jul 5 2020
- ====================== Dump #1: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- atapi.sys ATAPI IDE MiniPort driver (Microsoft)
- ataport.SYS ATAPI Driver Extension (Microsoft)
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdfs.sys CD-ROM File System Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CimFS.SYS Consumer IR Class Driver for eHome (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- csc.sys Windows Client Side Caching driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_atapi.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_dumpata.sys ATAPI Dump Driver
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HdAudio.sys High Definition Audio Function driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- intelppm.sys Processor Device Driver (Microsoft)
- IntelTA.sys Intel Telemetry Driver
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kd.dll Local Kernal Debugger (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate_GenuineIntel.dll Intel Microcode Update Library (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- MpKslDrv.sys Microsoft Anti-malware Protection driver
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msquic.sys Windows QUIC Driver
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndiscap.sys Microsoft NDIS Packet Capture Filter Driver
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- parport.sys Parallel Port Driver (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pciide.sys Generic PCI IDE Bus Driver (Microsoft)
- PCIIDEX.SYS PCI IDE Bus driver file (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- serenum.sys Serial Port Enumerator (Microsoft)
- serial.sys Serial Device Driver
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- usbehci.sys EHCI eUSB Miniport Driver (Microsoft)
- usbhub.sys Default Hub Driver for USB (Microsoft)
- USBPORT.SYS USB 1.1 & 2.0 Port Driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- ====================== Dump #1: UNLOADED MODULES =======================
- fffff807`57ab0000 fffff807`57ac0000 dump_ataport
- fffff807`57ad0000 fffff807`57ade000 dump_atapi.s
- fffff807`57b00000 fffff807`57b1e000 dump_dumpfve
- fffff807`57c30000 fffff807`57c4c000 dam.sys
- fffff807`50650000 fffff807`50662000 WdBoot.sys
- fffff807`51650000 fffff807`51660000 hwpolicy.sys
- ====================== Dump #1: BIOS INFORMATION =======================
- [SMBIOS Data Tables v2.7]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 3016 bytes]
- [BIOS Information (Type 0) - Length 24 - Handle 0000h]
- Vendor American Megatrends Inc.
- BIOS Version F6
- BIOS Starting Address Segment f000
- BIOS Release Date 02/16/2012
- BIOS ROM Size 280000
- BIOS Characteristics
- 07: - PCI Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 27: - Keyboard Services Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 32: - BIOS Vendor Reserved
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 4
- BIOS Minor Revision 6
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- Manufacturer Gigabyte Tecohnology Co., Ltd.
- Product Name H61M-DS2
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
- Manufacturer Gigabyte Tecohnology Co., Ltd.
- Product H61M-DS2
- Version x.x
- Feature Flags 09h
- -971589920: - -971589872: - «¯þø
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 22 - Handle 0003h]
- Manufacturer Gigabyte Tecohnology Co., Ltd.
- Chassis Type Desktop
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 0
- [Cache Information (Type 7) - Length 19 - Handle 0004h]
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 0020h - 32K
- Installed Size 0020h - 32K
- Supported SRAM Type 0040h - Asynchronous
- Current SRAM Type 0040h - Asynchronous
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Other
- Associativity 16-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0005h]
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 0100h - 256K
- Installed Size 0100h - 256K
- Supported SRAM Type 0040h - Asynchronous
- Current SRAM Type 0040h - Asynchronous
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Instruction
- Associativity 16-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0006h]
- Cache Configuration 0183h - WB Enabled Int NonSocketed L4
- Maximum Cache Size 0c00h - 3072K
- Installed Size 0c00h - 3072K
- Supported SRAM Type 0040h - Asynchronous
- Current SRAM Type 0040h - Asynchronous
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Instruction
- Associativity Specification Reserved
- [Physical Memory Array (Type 16) - Length 23 - Handle 0007h]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 33554432KB
- Number of Memory Devices 4
- [Onboard Devices Information (Type 10) - Length 6 - Handle 0026h]
- Number of Devices 1
- 01: Type Video [enabled]
- [OEM Strings (Type 11) - Length 5 - Handle 0027h]
- Number of Strings 1
- [System Configuration Options (Type 12) - Length 5 - Handle 0028h]
- [Memory Device (Type 17) - Length 34 - Handle 0040h]
- Physical Memory Array Handle 0007h
- Total Width 64 bits
- Data Width 64 bits
- Size 4096MB
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM0
- Bank Locator BANK 0
- Memory Type 18h - Specification Reserved
- Type Detail 0080h - Synchronous
- Speed 1333MHz
- Manufacturer Hynix/Hyundai
- Part Number HMT351U6CFR8C-H9
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0041h]
- Starting Address 00000000h
- Ending Address 003fffffh
- Memory Device Handle 0040h
- Mem Array Mapped Adr Handle 0047h
- Interleave Position 01
- Interleave Data Depth 02
- [Memory Device (Type 17) - Length 34 - Handle 0042h]
- Physical Memory Array Handle 0007h
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM1
- Bank Locator BANK 1
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Processor Information (Type 4) - Length 42 - Handle 0043h]
- Socket Designation Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
- Processor Type Central Processor
- Processor Family c6h - Specification Reserved
- Processor Manufacturer Intel
- Processor ID a7060200fffbebbf
- Processor Version Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
- Processor Voltage 8bh - 1.1V
- External Clock 100MHz
- Max Speed 7000MHz
- Current Speed 3300MHz
- Status Enabled Populated
- Processor Upgrade Other
- L1 Cache Handle 0004h
- L2 Cache Handle 0005h
- L3 Cache Handle 0006h
- [Memory Device (Type 17) - Length 34 - Handle 0044h]
- Physical Memory Array Handle 0007h
- Total Width 64 bits
- Data Width 64 bits
- Size 4096MB
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM0
- Bank Locator BANK 2
- Memory Type 18h - Specification Reserved
- Type Detail 0080h - Synchronous
- Speed 1333MHz
- Manufacturer 8325
- Part Number FLFF65F-C8KL9
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0045h]
- Starting Address 00400000h
- Ending Address 007fffffh
- Memory Device Handle 0044h
- Mem Array Mapped Adr Handle 0047h
- Interleave Position 02
- Interleave Data Depth 02
- [Memory Device (Type 17) - Length 34 - Handle 0046h]
- Physical Memory Array Handle 0007h
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM1
- Bank Locator BANK 3
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0047h]
- Starting Address 00000000h
- Ending Address 007fffffh
- Memory Array Handle 0007h
- Partition Width 04
- ========================== Dump #1: Extra #1 ===========================
- 0: kd> !verifier
- Verify Flags Level 0x00000000
- STANDARD FLAGS:
- [X] (0x00000000) Automatic Checks
- [ ] (0x00000001) Special pool
- [ ] (0x00000002) Force IRQL checking
- [ ] (0x00000008) Pool tracking
- [ ] (0x00000010) I/O verification
- [ ] (0x00000020) Deadlock detection
- [ ] (0x00000080) DMA checking
- [ ] (0x00000100) Security checks
- [ ] (0x00000800) Miscellaneous checks
- [ ] (0x00020000) DDI compliance checking
- ADDITIONAL FLAGS:
- [ ] (0x00000004) Randomized low resources simulation
- [ ] (0x00000200) Force pending I/O requests
- [ ] (0x00000400) IRP logging
- [ ] (0x00002000) Invariant MDL checking for stack
- [ ] (0x00004000) Invariant MDL checking for driver
- [ ] (0x00008000) Power framework delay fuzzing
- [ ] (0x00010000) Port/miniport interface checking
- [ ] (0x00040000) Systematic low resources simulation
- [ ] (0x00080000) DDI compliance checking (additional)
- [ ] (0x00200000) NDIS/WIFI verification
- [ ] (0x00800000) Kernel synchronization delay fuzzing
- [ ] (0x01000000) VM switch verification
- [ ] (0x02000000) Code integrity checks
- [X] Indicates flag is enabled
- Summary of All Verifier Statistics
- RaiseIrqls 0x0
- AcquireSpinLocks 0x0
- Synch Executions 0x0
- Trims 0x0
- Pool Allocations Attempted 0x0
- Pool Allocations Succeeded 0x0
- Pool Allocations Succeeded SpecialPool 0x0
- Pool Allocations With NO TAG 0x0
- Pool Allocations Failed 0x0
- Current paged pool allocations 0x0 for 00000000 bytes
- Peak paged pool allocations 0x0 for 00000000 bytes
- Current nonpaged pool allocations 0x0 for 00000000 bytes
- Peak nonpaged pool allocations 0x0 for 00000000 bytes
- ========================== Dump #1: Extra #2 ===========================
- 0: kd> !thread
- THREAD ffffd68804a27080 Cid 12d0.2888 Teb: 000000427c783000 Win32Thread: ffffd688077df060 RUNNING on processor 0
- Not impersonating
- GetUlongFromAddress: unable to read from fffff8074dc1143c
- Owning Process ffffd688080e1080 Image: CefSharp.BrowserSubprocess.exe
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 408901
- Context Switch Count 3519 IdealProcessor: 2
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address 0x000001c49bea0000
- Stack Init fffffb044b853c90 Current fffffb044b853980
- Base fffffb044b854000 Limit fffffb044b84e000 Call 0000000000000000
- Priority 9 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- fffffb04`4b8530e8 fffff807`4d4464a4 : 00000000`0000001a 00000000`00000403 fffff880`e25e7e68 80000000`152cf867 : nt!KeBugCheckEx
- fffffb04`4b8530f0 fffff807`4d2c1588 : 00000000`00000000 fffffb04`4b8534a0 fffffb04`4b8534a0 fffff880`e25e7e78 : nt!MiDeletePteRun+0x19b6a4
- fffffb04`4b853320 fffff807`4d2c219b : fffffb04`4b853450 ffffd688`080e1700 fffff880`e25e7e78 fffffb04`4b853450 : nt!MiDeleteVaTail+0x78
- fffffb04`4b853350 fffff807`4d2a789f : 00000000`00000000 00000000`00000060 ffffd688`080e17c0 000001c4`bcfcffff : nt!MiDeletePagablePteRange+0x33b
- fffffb04`4b8537d0 fffff807`4d29d9bb : ffffd688`080e1080 00000000`00000000 ffffd688`00000000 fffff807`00000001 : nt!MiDeleteVad+0x41f
- fffffb04`4b853900 fffff807`4d665fdc : fffffb04`00000000 00000000`00000000 fffffb04`4b853a60 00000000`00008000 : nt!MiFreeVadRange+0xa3
- fffffb04`4b853960 fffff807`4d665c05 : 00000000`00000000 00000042`7cbfab18 ffff9852`0734b8bb 00007ffa`00000004 : nt!MmFreeVirtualMemory+0x39c
- fffffb04`4b853aa0 fffff807`4d3ef478 : ffffd688`04a27080 000001c4`00000001 00007ffb`22534600 fffffb04`4b853b80 : nt!NtFreeVirtualMemory+0x95
- fffffb04`4b853b00 00007ffb`2f90b154 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28 (TrapFrame @ fffffb04`4b853b00)
- 00000042`7cbfb118 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffb`2f90b154
- ========================================================================
- ======================= Dump #2: ANALYZE VERBOSE =======================
- ====================== File: 081120-30171-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 19041 MP (4 procs) Free x64
- Kernel base = 0xfffff800`30a00000 PsLoadedModuleList = 0xfffff800`3162a310
- Debug session time: Tue Aug 11 07:21:23.229 2020 (UTC - 4:00)
- System Uptime: 0 days 0:40:49.945
- BugCheck 4A, {7ffc8bd85024, 2, 0, ffff8888ccdb1b80}
- Probably caused by : memory_corruption
- Followup: memory_corruption
- IRQL_GT_ZERO_AT_SYSTEM_SERVICE (4a)
- Returning to usermode from a system call at an IRQL > PASSIVE_LEVEL.
- Arguments:
- Arg1: 00007ffc8bd85024, Address of system function (system call routine)
- Arg2: 0000000000000002, Current IRQL
- Arg3: 0000000000000000, 0
- Arg4: ffff8888ccdb1b80, 0
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- PROCESS_NAME: opera.exe
- BUGCHECK_STR: RAISED_IRQL_FAULT
- FAULTING_IP:
- +0
- 00007ffc`8bd85024 ?? ???
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- CURRENT_IRQL: 2
- LAST_CONTROL_TRANSFER: from fffff80030defa29 to fffff80030dddb60
- STACK_TEXT:
- ffff8888`ccdb19b8 fffff800`30defa29 : 00000000`0000004a 00007ffc`8bd85024 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
- ffff8888`ccdb19c0 fffff800`30def8f3 : 000001a2`95e42420 ffffb687`af276080 000001a2`f8262210 ffff8888`ccdb1b80 : nt!KiBugCheckDispatch+0x69
- ffff8888`ccdb1b00 00007ffc`8bd85024 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExitPico+0x1fe
- 0000009a`65dfca28 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffc`8bd85024
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
- fffff80030d84f3f-fffff80030d84f41 3 bytes - nt!MiFreeUltraMapping+33
- [ 7d fb f6:78 f1 e2 ]
- fffff80030def951-fffff80030def954 4 bytes - nt!KiSystemServiceExitPico+25c (+0x6aa12)
- [ ff d0 0f 1f:e8 8a 59 63 ]
- fffff80030def9ac-fffff80030def9af 4 bytes - nt!KiSystemServiceExitPico+2b7 (+0x5b)
- [ ff d0 0f 1f:e8 2f 59 63 ]
- 11 errors : !nt (fffff80030d84f3f-fffff80030def9af)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-08-11T11:21:23.000Z
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #2: 3RD PARTY DRIVERS ======================
- Jul 21 2014 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- Sep 04 2014 - nvvad64v.sys - Nvidia Virtual Audio driver http://www.nvidia.com/
- Sep 06 2014 - NvStreamKms.sys - Nvidia Streaming Kernel Service http://www.nvidia.com/
- Mar 31 2015 - HWiNFO64A.SYS - HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
- Jul 07 2015 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Dec 05 2019 - cpuz149_x64.sys - CPUID driver
- May 26 2020 - rt640x64.sys - Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Jul 05 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- ================== Dump #2: 3RD PARTY DRIVERS (FULL) ===================
- Image path: \SystemRoot\system32\drivers\nvhda64v.sys
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Mon Jul 21 2014
- Image path: \SystemRoot\system32\drivers\nvvad64v.sys
- Image name: nvvad64v.sys
- Search : https://www.google.com/search?q=nvvad64v.sys
- ADA Info : Nvidia Virtual Audio driver http://www.nvidia.com/
- Timestamp : Thu Sep 4 2014
- Image path: \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
- Image name: NvStreamKms.sys
- Search : https://www.google.com/search?q=NvStreamKms.sys
- ADA Info : Nvidia Streaming Kernel Service http://www.nvidia.com/
- Timestamp : Sat Sep 6 2014
- Image path: \??\C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS
- Image name: HWiNFO64A.SYS
- Search : https://www.google.com/search?q=HWiNFO64A.SYS
- ADA Info : HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
- Timestamp : Tue Mar 31 2015
- Image path: \SystemRoot\System32\drivers\TeeDriverW8x64.sys
- Image name: TeeDriverW8x64.sys
- Search : https://www.google.com/search?q=TeeDriverW8x64.sys
- ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Timestamp : Tue Jul 7 2015
- Image path: \??\C:\WINDOWS\temp\cpuz149\cpuz149_x64.sys
- Image name: cpuz149_x64.sys
- Search : https://www.google.com/search?q=cpuz149_x64.sys
- ADA Info : CPUID driver
- Timestamp : Thu Dec 5 2019
- Image path: \SystemRoot\System32\drivers\rt640x64.sys
- Image name: rt640x64.sys
- Search : https://www.google.com/search?q=rt640x64.sys
- ADA Info : Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Timestamp : Tue May 26 2020
- Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_e92a0ac2e05fb2ca\nvlddmkm.sys
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Sun Jul 5 2020
- ====================== Dump #2: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- atapi.sys ATAPI IDE MiniPort driver (Microsoft)
- ataport.SYS ATAPI Driver Extension (Microsoft)
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdfs.sys CD-ROM File System Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CimFS.SYS Consumer IR Class Driver for eHome (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- csc.sys Windows Client Side Caching driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_atapi.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_dumpata.sys ATAPI Dump Driver
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HdAudio.sys High Definition Audio Function driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- intelppm.sys Processor Device Driver (Microsoft)
- IntelTA.sys Intel Telemetry Driver
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kd.dll Local Kernal Debugger (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate_GenuineIntel.dll Intel Microcode Update Library (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- MpKslDrv.sys Microsoft Anti-malware Protection driver
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msquic.sys Windows QUIC Driver
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndiscap.sys Microsoft NDIS Packet Capture Filter Driver
- ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
- NDProxy.sys NDIS Proxy driver (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- parport.sys Parallel Port Driver (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pciide.sys Generic PCI IDE Bus Driver (Microsoft)
- PCIIDEX.SYS PCI IDE Bus driver file (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
- raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
- raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
- rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- serenum.sys Serial Port Enumerator (Microsoft)
- serial.sys Serial Device Driver
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- usbehci.sys EHCI eUSB Miniport Driver (Microsoft)
- usbhub.sys Default Hub Driver for USB (Microsoft)
- USBPORT.SYS USB 1.1 & 2.0 Port Driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- ====================== Dump #2: UNLOADED MODULES =======================
- fffff800`3dcf0000 fffff800`3dd00000 dump_ataport
- fffff800`3dd10000 fffff800`3dd1e000 dump_atapi.s
- fffff800`3dd40000 fffff800`3dd5e000 dump_dumpfve
- fffff800`3d720000 fffff800`3d73c000 dam.sys
- fffff800`36250000 fffff800`36262000 WdBoot.sys
- fffff800`37250000 fffff800`37260000 hwpolicy.sys
- ====================== Dump #2: BIOS INFORMATION =======================
- [SMBIOS Data Tables v2.7]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 3016 bytes]
- [BIOS Information (Type 0) - Length 24 - Handle 0000h]
- Vendor American Megatrends Inc.
- BIOS Version F6
- BIOS Starting Address Segment f000
- BIOS Release Date 02/16/2012
- BIOS ROM Size 280000
- BIOS Characteristics
- 07: - PCI Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 27: - Keyboard Services Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 32: - BIOS Vendor Reserved
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 4
- BIOS Minor Revision 6
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- Manufacturer Gigabyte Tecohnology Co., Ltd.
- Product Name H61M-DS2
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
- Manufacturer Gigabyte Tecohnology Co., Ltd.
- Product H61M-DS2
- Version x.x
- Feature Flags 09h
- -926632224: - -926632176: - «¯þø
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 22 - Handle 0003h]
- Manufacturer Gigabyte Tecohnology Co., Ltd.
- Chassis Type Desktop
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 0
- [Cache Information (Type 7) - Length 19 - Handle 0004h]
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 0020h - 32K
- Installed Size 0020h - 32K
- Supported SRAM Type 0040h - Asynchronous
- Current SRAM Type 0040h - Asynchronous
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Other
- Associativity 16-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0005h]
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 0100h - 256K
- Installed Size 0100h - 256K
- Supported SRAM Type 0040h - Asynchronous
- Current SRAM Type 0040h - Asynchronous
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Instruction
- Associativity 16-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0006h]
- Cache Configuration 0183h - WB Enabled Int NonSocketed L4
- Maximum Cache Size 0c00h - 3072K
- Installed Size 0c00h - 3072K
- Supported SRAM Type 0040h - Asynchronous
- Current SRAM Type 0040h - Asynchronous
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Instruction
- Associativity Specification Reserved
- [Physical Memory Array (Type 16) - Length 23 - Handle 0007h]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 33554432KB
- Number of Memory Devices 4
- [Onboard Devices Information (Type 10) - Length 6 - Handle 0026h]
- Number of Devices 1
- 01: Type Video [enabled]
- [OEM Strings (Type 11) - Length 5 - Handle 0027h]
- Number of Strings 1
- [System Configuration Options (Type 12) - Length 5 - Handle 0028h]
- [Memory Device (Type 17) - Length 34 - Handle 0040h]
- Physical Memory Array Handle 0007h
- Total Width 64 bits
- Data Width 64 bits
- Size 4096MB
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM0
- Bank Locator BANK 0
- Memory Type 18h - Specification Reserved
- Type Detail 0080h - Synchronous
- Speed 1333MHz
- Manufacturer Hynix/Hyundai
- Part Number HMT351U6CFR8C-H9
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0041h]
- Starting Address 00000000h
- Ending Address 003fffffh
- Memory Device Handle 0040h
- Mem Array Mapped Adr Handle 0047h
- Interleave Position 01
- Interleave Data Depth 02
- [Memory Device (Type 17) - Length 34 - Handle 0042h]
- Physical Memory Array Handle 0007h
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM1
- Bank Locator BANK 1
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Processor Information (Type 4) - Length 42 - Handle 0043h]
- Socket Designation Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
- Processor Type Central Processor
- Processor Family c6h - Specification Reserved
- Processor Manufacturer Intel
- Processor ID a7060200fffbebbf
- Processor Version Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
- Processor Voltage 8bh - 1.1V
- External Clock 100MHz
- Max Speed 7000MHz
- Current Speed 3300MHz
- Status Enabled Populated
- Processor Upgrade Other
- L1 Cache Handle 0004h
- L2 Cache Handle 0005h
- L3 Cache Handle 0006h
- [Memory Device (Type 17) - Length 34 - Handle 0044h]
- Physical Memory Array Handle 0007h
- Total Width 64 bits
- Data Width 64 bits
- Size 4096MB
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM0
- Bank Locator BANK 2
- Memory Type 18h - Specification Reserved
- Type Detail 0080h - Synchronous
- Speed 1333MHz
- Manufacturer 8325
- Part Number FLFF65F-C8KL9
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0045h]
- Starting Address 00400000h
- Ending Address 007fffffh
- Memory Device Handle 0044h
- Mem Array Mapped Adr Handle 0047h
- Interleave Position 02
- Interleave Data Depth 02
- [Memory Device (Type 17) - Length 34 - Handle 0046h]
- Physical Memory Array Handle 0007h
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM1
- Bank Locator BANK 3
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0047h]
- Starting Address 00000000h
- Ending Address 007fffffh
- Memory Array Handle 0007h
- Partition Width 04
- ========================== Dump #2: Extra #1 ===========================
- 1: kd> !verifier
- Verify Flags Level 0x00000000
- STANDARD FLAGS:
- [X] (0x00000000) Automatic Checks
- [ ] (0x00000001) Special pool
- [ ] (0x00000002) Force IRQL checking
- [ ] (0x00000008) Pool tracking
- [ ] (0x00000010) I/O verification
- [ ] (0x00000020) Deadlock detection
- [ ] (0x00000080) DMA checking
- [ ] (0x00000100) Security checks
- [ ] (0x00000800) Miscellaneous checks
- [ ] (0x00020000) DDI compliance checking
- ADDITIONAL FLAGS:
- [ ] (0x00000004) Randomized low resources simulation
- [ ] (0x00000200) Force pending I/O requests
- [ ] (0x00000400) IRP logging
- [ ] (0x00002000) Invariant MDL checking for stack
- [ ] (0x00004000) Invariant MDL checking for driver
- [ ] (0x00008000) Power framework delay fuzzing
- [ ] (0x00010000) Port/miniport interface checking
- [ ] (0x00040000) Systematic low resources simulation
- [ ] (0x00080000) DDI compliance checking (additional)
- [ ] (0x00200000) NDIS/WIFI verification
- [ ] (0x00800000) Kernel synchronization delay fuzzing
- [ ] (0x01000000) VM switch verification
- [ ] (0x02000000) Code integrity checks
- [X] Indicates flag is enabled
- Summary of All Verifier Statistics
- RaiseIrqls 0x0
- AcquireSpinLocks 0x0
- Synch Executions 0x0
- Trims 0x0
- Pool Allocations Attempted 0x0
- Pool Allocations Succeeded 0x0
- Pool Allocations Succeeded SpecialPool 0x0
- Pool Allocations With NO TAG 0x0
- Pool Allocations Failed 0x0
- Current paged pool allocations 0x0 for 00000000 bytes
- Peak paged pool allocations 0x0 for 00000000 bytes
- Current nonpaged pool allocations 0x0 for 00000000 bytes
- Peak nonpaged pool allocations 0x0 for 00000000 bytes
- ========================== Dump #2: Extra #2 ===========================
- 1: kd> !thread
- THREAD ffffb687af276080 Cid 09d4.1464 Teb: 0000009a65bb2000 Win32Thread: ffffb687af1ad680 RUNNING on processor 1
- Not impersonating
- GetUlongFromAddress: unable to read from fffff8003161143c
- Owning Process ffffb687af1570c0 Image: opera.exe
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 156796
- Context Switch Count 167172 IdealProcessor: 3
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address 0x00007ff7bc5c9860
- Stack Init ffff8888ccdb1c90 Current ffff8888ccdb16a0
- Base ffff8888ccdb2000 Limit ffff8888ccdac000 Call 0000000000000000
- Priority 12 BasePriority 11 PriorityDecrement 0 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- ffff8888`ccdb19b8 fffff800`30defa29 : 00000000`0000004a 00007ffc`8bd85024 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
- ffff8888`ccdb19c0 fffff800`30def8f3 : 000001a2`95e42420 ffffb687`af276080 000001a2`f8262210 ffff8888`ccdb1b80 : nt!KiBugCheckDispatch+0x69
- ffff8888`ccdb1b00 00007ffc`8bd85024 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExitPico+0x1fe (TrapFrame @ ffff8888`ccdb1b00)
- 0000009a`65dfca28 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffc`8bd85024
- ========================================================================
- ======================= Dump #3: ANALYZE VERBOSE =======================
- ====================== File: 081020-37390-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 19041 MP (4 procs) Free x64
- Kernel base = 0xfffff804`31800000 PsLoadedModuleList = 0xfffff804`3242a310
- Debug session time: Mon Aug 10 08:23:27.582 2020 (UTC - 4:00)
- System Uptime: 0 days 0:32:57.298
- BugCheck A, {10, 2, 0, fffff80431aacc45}
- Probably caused by : memory_corruption
- Followup: memory_corruption
- IRQL_NOT_LESS_OR_EQUAL (a)
- An attempt was made to access a pageable (or completely invalid) address at an
- interrupt request level (IRQL) that is too high. This is usually
- caused by drivers using improper addresses.
- If a kernel debugger is available get the stack backtrace.
- Arguments:
- Arg1: 0000000000000010, memory referenced
- Arg2: 0000000000000002, IRQL
- Arg3: 0000000000000000, bitfield :
- bit 0 : value 0 = read operation, 1 = write operation
- bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
- Arg4: fffff80431aacc45, address which referenced memory
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- READ_ADDRESS: fffff804324fa388: Unable to get MiVisibleState
- 0000000000000010
- CURRENT_IRQL: 2
- FAULTING_IP:
- nt!MiInsertPageInFreeOrZeroedList+1d5
- fffff804`31aacc45 49037d10 add rdi,qword ptr [r13+10h]
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- BUGCHECK_STR: AV
- PROCESS_NAME: GTA5.exe
- TRAP_FRAME: ffff9489be3efeb0 -- (.trap 0xffff9489be3efeb0)
- NOTE: The trap frame does not contain all registers.
- Some register values may be zeroed or incorrect.
- rax=0000000000000041 rbx=0000000000000000 rcx=0000000000000008
- rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
- rip=fffff80431aacc45 rsp=ffff9489be3f0040 rbp=ffff9489be3f00d9
- r8=00000000000008c0 r9=00000000000000a1 r10=0000000000000000
- r11=ffff9489be3f0138 r12=0000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=0000000000000000
- iopl=0 nv up ei pl nz na po nc
- nt!MiInsertPageInFreeOrZeroedList+0x1d5:
- fffff804`31aacc45 49037d10 add rdi,qword ptr [r13+10h] ds:00000000`00000010=????????????????
- Resetting default scope
- LAST_CONTROL_TRANSFER: from fffff80431befa29 to fffff80431bddb60
- STACK_TEXT:
- ffff9489`be3efd68 fffff804`31befa29 : 00000000`0000000a 00000000`00000010 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
- ffff9489`be3efd70 fffff804`31bebd29 : fffff804`2ec628a0 ffffd08f`0c728210 00000000`0000000d fffff804`31ac6199 : nt!KiBugCheckDispatch+0x69
- ffff9489`be3efeb0 fffff804`31aacc45 : 00000000`0000000e fffff804`31ac90ff 00000050`00000000 ffff9489`be3f0110 : nt!KiPageFault+0x469
- ffff9489`be3f0040 fffff804`31aaac7a : 00000000`000153a1 ffffe680`003fae48 00000000`000000a2 00000000`00000000 : nt!MiInsertPageInFreeOrZeroedList+0x1d5
- ffff9489`be3f0140 fffff804`31b1ae16 : fffff804`32450b40 00000000`00000050 00000000`00000000 00000000`00000001 : nt!MiDemoteLocalLargePage+0x2ca
- ffff9489`be3f02a0 fffff804`31a1865c : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000001 : nt!MiGetFreeOrZeroPageAnyColor+0x42
- ffff9489`be3f02d0 fffff804`31a17992 : fffff804`32450b40 ffff8a14`00000050 00000000`00000050 00000000`00000001 : nt!MiGetPage+0x3cc
- ffff9489`be3f03b0 fffff804`31a15676 : ffff9489`be3f0790 00000000`00000000 00000000`00000001 ffffd08f`11c33011 : nt!MiGetPageChain+0x172
- ffff9489`be3f0610 fffff804`31a15138 : 00000000`00000004 ffff9489`00000000 ffffd08f`11b137a0 fffff804`32450b40 : nt!MiResolvePrivateZeroFault+0x176
- ffff9489`be3f0730 fffff804`31a1450d : 00000000`c0000016 00000000`00000002 00000000`00000000 00000000`00000002 : nt!MiResolveDemandZeroFault+0x208
- ffff9489`be3f0820 fffff804`31a12a89 : 00000000`00000111 00000000`00000003 00000000`c0000016 00000000`00000000 : nt!MiDispatchFault+0x22d
- ffff9489`be3f0960 fffff804`31bebc1e : ffffd08f`0fae6080 ffffd08f`00000000 00000000`00000000 00000000`00000000 : nt!MmAccessFault+0x189
- ffff9489`be3f0b00 00007ff9`81f7c5ef : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x35e
- 0000009a`13afd850 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff9`81f7c5ef
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !dxgmms2
- fffff8042ecf61d9-fffff8042ecf61da 2 bytes - dxgmms2!TlgAggregateInternalProviderCallback+19
- [ 48 ff:4c 8b ]
- fffff8042ecf61e0-fffff8042ecf61e4 5 bytes - dxgmms2!TlgAggregateInternalProviderCallback+20 (+0x07)
- [ 0f 1f 44 00 00:e8 2b 9f e0 02 ]
- fffff8042ecf620f-fffff8042ecf6210 2 bytes - dxgmms2!TlgAggregateInternalProviderCallback+4f (+0x2f)
- [ 48 ff:4c 8b ]
- fffff8042ecf6216-fffff8042ecf621a 5 bytes - dxgmms2!TlgAggregateInternalProviderCallback+56 (+0x07)
- [ 0f 1f 44 00 00:e8 a5 f4 d2 02 ]
- fffff8042ecf629c-fffff8042ecf629d 2 bytes - dxgmms2!TlgUnregisterAggregateProvider+2c (+0x86)
- [ 48 ff:4c 8b ]
- fffff8042ecf62a3-fffff8042ecf62a7 5 bytes - dxgmms2!TlgUnregisterAggregateProvider+33 (+0x07)
- [ 0f 1f 44 00 00:e8 a8 83 25 03 ]
- fffff8042ecf62b8-fffff8042ecf62b9 2 bytes - dxgmms2!TlgUnregisterAggregateProvider+48 (+0x15)
- [ 48 ff:4c 8b ]
- fffff8042ecf62bf - dxgmms2!TlgUnregisterAggregateProvider+4f (+0x07)
- [ 0f:e8 ]
- 24 errors : !dxgmms2 (fffff8042ecf61d9-fffff8042ecf62bf)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-08-10T12:23:27.000Z
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #3: 3RD PARTY DRIVERS ======================
- Jul 21 2014 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- Sep 04 2014 - nvvad64v.sys - Nvidia Virtual Audio driver http://www.nvidia.com/
- Sep 06 2014 - NvStreamKms.sys - Nvidia Streaming Kernel Service http://www.nvidia.com/
- Mar 31 2015 - HWiNFO64A.SYS - HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
- Jul 07 2015 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
- May 26 2020 - rt640x64.sys - Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Jul 05 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- ================== Dump #3: 3RD PARTY DRIVERS (FULL) ===================
- Image path: \SystemRoot\system32\drivers\nvhda64v.sys
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Mon Jul 21 2014
- Image path: \SystemRoot\system32\drivers\nvvad64v.sys
- Image name: nvvad64v.sys
- Search : https://www.google.com/search?q=nvvad64v.sys
- ADA Info : Nvidia Virtual Audio driver http://www.nvidia.com/
- Timestamp : Thu Sep 4 2014
- Image path: \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
- Image name: NvStreamKms.sys
- Search : https://www.google.com/search?q=NvStreamKms.sys
- ADA Info : Nvidia Streaming Kernel Service http://www.nvidia.com/
- Timestamp : Sat Sep 6 2014
- Image path: \??\C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS
- Image name: HWiNFO64A.SYS
- Search : https://www.google.com/search?q=HWiNFO64A.SYS
- ADA Info : HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
- Timestamp : Tue Mar 31 2015
- Image path: \SystemRoot\System32\drivers\TeeDriverW8x64.sys
- Image name: TeeDriverW8x64.sys
- Search : https://www.google.com/search?q=TeeDriverW8x64.sys
- ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Timestamp : Tue Jul 7 2015
- Image path: \SystemRoot\System32\drivers\rt640x64.sys
- Image name: rt640x64.sys
- Search : https://www.google.com/search?q=rt640x64.sys
- ADA Info : Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Timestamp : Tue May 26 2020
- Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_e92a0ac2e05fb2ca\nvlddmkm.sys
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Sun Jul 5 2020
- ====================== Dump #3: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- atapi.sys ATAPI IDE MiniPort driver (Microsoft)
- ataport.SYS ATAPI Driver Extension (Microsoft)
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdfs.sys CD-ROM File System Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CimFS.SYS Consumer IR Class Driver for eHome (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- csc.sys Windows Client Side Caching driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_atapi.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_dumpata.sys ATAPI Dump Driver
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HdAudio.sys High Definition Audio Function driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- intelppm.sys Processor Device Driver (Microsoft)
- IntelTA.sys Intel Telemetry Driver
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kd.dll Local Kernal Debugger (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate_GenuineIntel.dll Intel Microcode Update Library (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msquic.sys Windows QUIC Driver
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndiscap.sys Microsoft NDIS Packet Capture Filter Driver
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- parport.sys Parallel Port Driver (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pciide.sys Generic PCI IDE Bus Driver (Microsoft)
- PCIIDEX.SYS PCI IDE Bus driver file (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- serenum.sys Serial Port Enumerator (Microsoft)
- serial.sys Serial Device Driver
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- usbehci.sys EHCI eUSB Miniport Driver (Microsoft)
- usbhub.sys Default Hub Driver for USB (Microsoft)
- USBPORT.SYS USB 1.1 & 2.0 Port Driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- ====================== Dump #3: UNLOADED MODULES =======================
- fffff804`3b2c0000 fffff804`3b2d0000 dump_ataport
- fffff804`3b2e0000 fffff804`3b2ee000 dump_atapi.s
- fffff804`3b310000 fffff804`3b32e000 dump_dumpfve
- fffff804`3af20000 fffff804`3af3c000 dam.sys
- fffff804`33a50000 fffff804`33a62000 WdBoot.sys
- fffff804`34a50000 fffff804`34a60000 hwpolicy.sys
- ====================== Dump #3: BIOS INFORMATION =======================
- [SMBIOS Data Tables v2.7]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 3016 bytes]
- [BIOS Information (Type 0) - Length 24 - Handle 0000h]
- Vendor American Megatrends Inc.
- BIOS Version F6
- BIOS Starting Address Segment f000
- BIOS Release Date 02/16/2012
- BIOS ROM Size 280000
- BIOS Characteristics
- 07: - PCI Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 27: - Keyboard Services Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 32: - BIOS Vendor Reserved
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 4
- BIOS Minor Revision 6
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- Manufacturer Gigabyte Tecohnology Co., Ltd.
- Product Name H61M-DS2
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
- Manufacturer Gigabyte Tecohnology Co., Ltd.
- Product H61M-DS2
- Version x.x
- Feature Flags 09h
- -926632224: - -926632176: - «¯þø
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 22 - Handle 0003h]
- Manufacturer Gigabyte Tecohnology Co., Ltd.
- Chassis Type Desktop
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 0
- [Cache Information (Type 7) - Length 19 - Handle 0004h]
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 0020h - 32K
- Installed Size 0020h - 32K
- Supported SRAM Type 0040h - Asynchronous
- Current SRAM Type 0040h - Asynchronous
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Other
- Associativity 16-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0005h]
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 0100h - 256K
- Installed Size 0100h - 256K
- Supported SRAM Type 0040h - Asynchronous
- Current SRAM Type 0040h - Asynchronous
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Instruction
- Associativity 16-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0006h]
- Cache Configuration 0183h - WB Enabled Int NonSocketed L4
- Maximum Cache Size 0c00h - 3072K
- Installed Size 0c00h - 3072K
- Supported SRAM Type 0040h - Asynchronous
- Current SRAM Type 0040h - Asynchronous
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Instruction
- Associativity Specification Reserved
- [Physical Memory Array (Type 16) - Length 23 - Handle 0007h]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 33554432KB
- Number of Memory Devices 4
- [Onboard Devices Information (Type 10) - Length 6 - Handle 0026h]
- Number of Devices 1
- 01: Type Video [enabled]
- [OEM Strings (Type 11) - Length 5 - Handle 0027h]
- Number of Strings 1
- [System Configuration Options (Type 12) - Length 5 - Handle 0028h]
- [Memory Device (Type 17) - Length 34 - Handle 0040h]
- Physical Memory Array Handle 0007h
- Total Width 64 bits
- Data Width 64 bits
- Size 4096MB
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM0
- Bank Locator BANK 0
- Memory Type 18h - Specification Reserved
- Type Detail 0080h - Synchronous
- Speed 1333MHz
- Manufacturer Hynix/Hyundai
- Part Number HMT351U6CFR8C-H9
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0041h]
- Starting Address 00000000h
- Ending Address 003fffffh
- Memory Device Handle 0040h
- Mem Array Mapped Adr Handle 0047h
- Interleave Position 01
- Interleave Data Depth 02
- [Memory Device (Type 17) - Length 34 - Handle 0042h]
- Physical Memory Array Handle 0007h
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM1
- Bank Locator BANK 1
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Processor Information (Type 4) - Length 42 - Handle 0043h]
- Socket Designation Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
- Processor Type Central Processor
- Processor Family c6h - Specification Reserved
- Processor Manufacturer Intel
- Processor ID a7060200fffbebbf
- Processor Version Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
- Processor Voltage 8bh - 1.1V
- External Clock 100MHz
- Max Speed 7000MHz
- Current Speed 3300MHz
- Status Enabled Populated
- Processor Upgrade Other
- L1 Cache Handle 0004h
- L2 Cache Handle 0005h
- L3 Cache Handle 0006h
- [Memory Device (Type 17) - Length 34 - Handle 0044h]
- Physical Memory Array Handle 0007h
- Total Width 64 bits
- Data Width 64 bits
- Size 4096MB
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM0
- Bank Locator BANK 2
- Memory Type 18h - Specification Reserved
- Type Detail 0080h - Synchronous
- Speed 1333MHz
- Manufacturer 8325
- Part Number FLFF65F-C8KL9
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0045h]
- Starting Address 00400000h
- Ending Address 007fffffh
- Memory Device Handle 0044h
- Mem Array Mapped Adr Handle 0047h
- Interleave Position 02
- Interleave Data Depth 02
- [Memory Device (Type 17) - Length 34 - Handle 0046h]
- Physical Memory Array Handle 0007h
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM1
- Bank Locator BANK 3
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0047h]
- Starting Address 00000000h
- Ending Address 007fffffh
- Memory Array Handle 0007h
- Partition Width 04
- ========================== Dump #3: Extra #1 ===========================
- 0: kd> !verifier
- Verify Flags Level 0x00000000
- STANDARD FLAGS:
- [X] (0x00000000) Automatic Checks
- [ ] (0x00000001) Special pool
- [ ] (0x00000002) Force IRQL checking
- [ ] (0x00000008) Pool tracking
- [ ] (0x00000010) I/O verification
- [ ] (0x00000020) Deadlock detection
- [ ] (0x00000080) DMA checking
- [ ] (0x00000100) Security checks
- [ ] (0x00000800) Miscellaneous checks
- [ ] (0x00020000) DDI compliance checking
- ADDITIONAL FLAGS:
- [ ] (0x00000004) Randomized low resources simulation
- [ ] (0x00000200) Force pending I/O requests
- [ ] (0x00000400) IRP logging
- [ ] (0x00002000) Invariant MDL checking for stack
- [ ] (0x00004000) Invariant MDL checking for driver
- [ ] (0x00008000) Power framework delay fuzzing
- [ ] (0x00010000) Port/miniport interface checking
- [ ] (0x00040000) Systematic low resources simulation
- [ ] (0x00080000) DDI compliance checking (additional)
- [ ] (0x00200000) NDIS/WIFI verification
- [ ] (0x00800000) Kernel synchronization delay fuzzing
- [ ] (0x01000000) VM switch verification
- [ ] (0x02000000) Code integrity checks
- [X] Indicates flag is enabled
- Summary of All Verifier Statistics
- RaiseIrqls 0x0
- AcquireSpinLocks 0x0
- Synch Executions 0x0
- Trims 0x0
- Pool Allocations Attempted 0x0
- Pool Allocations Succeeded 0x0
- Pool Allocations Succeeded SpecialPool 0x0
- Pool Allocations With NO TAG 0x0
- Pool Allocations Failed 0x0
- Current paged pool allocations 0x0 for 00000000 bytes
- Peak paged pool allocations 0x0 for 00000000 bytes
- Current nonpaged pool allocations 0x0 for 00000000 bytes
- Peak nonpaged pool allocations 0x0 for 00000000 bytes
- ========================== Dump #3: Extra #2 ===========================
- 0: kd> !thread
- THREAD ffffd08f0fae6080 Cid 21c0.0b28 Teb: 0000009a13907000 Win32Thread: ffffd08f11b1ff00 RUNNING on processor 0
- IRP List:
- Unable to read nt!_IRP @ ffffd08f11c85880
- Not impersonating
- GetUlongFromAddress: unable to read from fffff8043241143c
- Owning Process ffffd08f11c33080 Image: GTA5.exe
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 126547
- Context Switch Count 16990 IdealProcessor: 2
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address 0x00007ff722641144
- Stack Init ffff9489be3f0c90 Current ffff9489be3ef0c0
- Base ffff9489be3f1000 Limit ffff9489be3eb000 Call 0000000000000000
- Priority 15 BasePriority 15 PriorityDecrement 0 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- ffff9489`be3efd68 fffff804`31befa29 : 00000000`0000000a 00000000`00000010 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
- ffff9489`be3efd70 fffff804`31bebd29 : fffff804`2ec628a0 ffffd08f`0c728210 00000000`0000000d fffff804`31ac6199 : nt!KiBugCheckDispatch+0x69
- ffff9489`be3efeb0 fffff804`31aacc45 : 00000000`0000000e fffff804`31ac90ff 00000050`00000000 ffff9489`be3f0110 : nt!KiPageFault+0x469 (TrapFrame @ ffff9489`be3efeb0)
- ffff9489`be3f0040 fffff804`31aaac7a : 00000000`000153a1 ffffe680`003fae48 00000000`000000a2 00000000`00000000 : nt!MiInsertPageInFreeOrZeroedList+0x1d5
- ffff9489`be3f0140 fffff804`31b1ae16 : fffff804`32450b40 00000000`00000050 00000000`00000000 00000000`00000001 : nt!MiDemoteLocalLargePage+0x2ca
- ffff9489`be3f02a0 fffff804`31a1865c : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000001 : nt!MiGetFreeOrZeroPageAnyColor+0x42
- ffff9489`be3f02d0 fffff804`31a17992 : fffff804`32450b40 ffff8a14`00000050 00000000`00000050 00000000`00000001 : nt!MiGetPage+0x3cc
- ffff9489`be3f03b0 fffff804`31a15676 : ffff9489`be3f0790 00000000`00000000 00000000`00000001 ffffd08f`11c33011 : nt!MiGetPageChain+0x172
- ffff9489`be3f0610 fffff804`31a15138 : 00000000`00000004 ffff9489`00000000 ffffd08f`11b137a0 fffff804`32450b40 : nt!MiResolvePrivateZeroFault+0x176
- ffff9489`be3f0730 fffff804`31a1450d : 00000000`c0000016 00000000`00000002 00000000`00000000 00000000`00000002 : nt!MiResolveDemandZeroFault+0x208
- ffff9489`be3f0820 fffff804`31a12a89 : 00000000`00000111 00000000`00000003 00000000`c0000016 00000000`00000000 : nt!MiDispatchFault+0x22d
- ffff9489`be3f0960 fffff804`31bebc1e : ffffd08f`0fae6080 ffffd08f`00000000 00000000`00000000 00000000`00000000 : nt!MmAccessFault+0x189
- ffff9489`be3f0b00 00007ff9`81f7c5ef : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x35e (TrapFrame @ ffff9489`be3f0b00)
- 0000009a`13afd850 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff9`81f7c5ef
- ========================================================================
- ======================= Dump #4: ANALYZE VERBOSE =======================
- ====================== File: 081020-31234-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 19041 MP (4 procs) Free x64
- Kernel base = 0xfffff806`2aa00000 PsLoadedModuleList = 0xfffff806`2b62a310
- Debug session time: Mon Aug 10 10:22:59.388 2020 (UTC - 4:00)
- System Uptime: 0 days 0:34:06.105
- BugCheck A, {ffffbf07556b1042, 2, 0, fffff8062acc4d3b}
- Probably caused by : memory_corruption
- Followup: memory_corruption
- IRQL_NOT_LESS_OR_EQUAL (a)
- An attempt was made to access a pageable (or completely invalid) address at an
- interrupt request level (IRQL) that is too high. This is usually
- caused by drivers using improper addresses.
- If a kernel debugger is available get the stack backtrace.
- Arguments:
- Arg1: ffffbf07556b1042, memory referenced
- Arg2: 0000000000000002, IRQL
- Arg3: 0000000000000000, bitfield :
- bit 0 : value 0 = read operation, 1 = write operation
- bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
- Arg4: fffff8062acc4d3b, address which referenced memory
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- READ_ADDRESS: fffff8062b6fa388: Unable to get MiVisibleState
- ffffbf07556b1042
- CURRENT_IRQL: 2
- FAULTING_IP:
- nt!MiLogPageAccess+30b
- fffff806`2acc4d3b f6462202 test byte ptr [rsi+22h],2
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- BUGCHECK_STR: AV
- PROCESS_NAME: 347.09-notebook-win8-win7-64bit-internationa
- TRAP_FRAME: ffffb901b2c52f50 -- (.trap 0xffffb901b2c52f50)
- NOTE: The trap frame does not contain all registers.
- Some register values may be zeroed or incorrect.
- rax=8000000000000000 rbx=0000000000000000 rcx=a781707af1f80000
- rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
- rip=fffff8062acc4d3b rsp=ffffb901b2c530e0 rbp=ffffb901b2c53128
- r8=ffff88f1c7a7ebf8 r9=0000000000000000 r10=00000000ffffffff
- r11=0000000000000001 r12=0000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=0000000000000000
- iopl=0 nv up ei ng nz ac po cy
- nt!MiLogPageAccess+0x30b:
- fffff806`2acc4d3b f6462202 test byte ptr [rsi+22h],2 ds:00000000`00000022=??
- Resetting default scope
- LAST_CONTROL_TRANSFER: from fffff8062adefa29 to fffff8062adddb60
- STACK_TEXT:
- ffffb901`b2c52e08 fffff806`2adefa29 : 00000000`0000000a ffffbf07`556b1042 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
- ffffb901`b2c52e10 fffff806`2adebd29 : 00000000`00000000 fffff806`2ac956b9 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
- ffffb901`b2c52f50 fffff806`2acc4d3b : fffff980`013faa30 ffffb901`b2c53128 fffff806`2b652780 fffff806`2b64f600 : nt!KiPageFault+0x469
- ffffb901`b2c530e0 fffff806`2acc07e8 : 00000000`00b3e000 80000000`6a8e1821 00000003`00000000 fffff806`2ad16b2a : nt!MiLogPageAccess+0x30b
- ffffb901`b2c53170 fffff806`2b063c5f : ffffe38f`4fd7f000 ffffa781`6d349280 00000000`00000000 00000000`00000000 : nt!MmUnmapViewInSystemCache+0x988
- ffffb901`b2c53290 fffff806`2ac86ae6 : 00000000`00b00000 ffffbf07`46356a20 ffffbf07`3b9103b8 00000000`00000001 : nt!CcUnmapVacb+0x63
- ffffb901`b2c532d0 fffff806`2ac8bb7a : 00000000`00c00001 ffffbf07`3b6898a0 00000000`00400000 00000000`00000001 : nt!CcUnmapVacbArray+0x206
- ffffb901`b2c53340 fffff806`2b064180 : 00000000`00c00000 00000000`00000000 ffffb901`b2c53480 ffffb901`b2c53490 : nt!CcGetVirtualAddress+0x40a
- ffffb901`b2c533e0 fffff806`2ac8b0b9 : 00000000`00000000 00000000`00c00000 00000000`00000000 00000000`00000001 : nt!CcMapAndCopyFromCache+0x80
- ffffb901`b2c53480 fffff806`3045a1ad : ffffb901`b2c535e0 00000000`00000000 ffffa781`00100000 00000000`00100000 : nt!CcCopyReadEx+0x139
- ffffb901`b2c53530 fffff806`2a2373fb : 00000000`00000000 ffffb901`b2c53908 ffffb901`b2c538c8 00000000`032b0020 : Ntfs!NtfsCopyReadA+0x2ed
- ffffb901`b2c53820 fffff806`2a2344d7 : ffffb901`b2c53930 ffffb901`b2c538c8 ffffbf07`449f1110 ffffbf07`449f1010 : FLTMGR!FltpPerformFastIoCall+0x16b
- ffffb901`b2c53880 fffff806`2a26b405 : ffffb901`b2c54000 ffffb901`b2c4e000 ffffbf07`4622b080 fffff806`2aff8fce : FLTMGR!FltpPassThroughFastIo+0x107
- ffffb901`b2c53900 fffff806`2b011b5f : ffffbf07`4657a100 00000000`00000000 00000000`00000000 ffffbf07`00000000 : FLTMGR!FltpFastIoRead+0x165
- ffffb901`b2c539b0 fffff806`2adef478 : 00000000`0000026c 00000000`00000000 00000000`00000000 00000000`00000000 : nt!NtReadFile+0x37f
- ffffb901`b2c53a90 00000000`76f11cfc : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
- 00000000`031af308 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x76f11cfc
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
- fffff8062acc41bd - nt!MiAgePteWorker+36d
- [ f6:88 ]
- fffff8062acc41f7 - nt!MiAgePteWorker+3a7 (+0x3a)
- [ fa:f9 ]
- fffff8062acc421a-fffff8062acc421e 5 bytes - nt!MiAgePteWorker+3ca (+0x23)
- [ d7 be 7d fb f6:17 31 62 c4 88 ]
- fffff8062acc43d6 - nt!MiClearPteAccessed+46 (+0x1bc)
- [ f6:88 ]
- fffff8062acc43fd - nt!MiClearPteAccessed+6d (+0x27)
- [ f6:88 ]
- fffff8062acc4445-fffff8062acc4449 5 bytes - nt!MiClearPteAccessed+b5 (+0x48)
- [ d0 be 7d fb f6:10 31 62 c4 88 ]
- fffff8062acc444f-fffff8062acc4453 5 bytes - nt!MiClearPteAccessed+bf (+0x0a)
- [ d7 be 7d fb f6:17 31 62 c4 88 ]
- fffff8062acc4572-fffff8062acc4576 5 bytes - nt!MiClearPteAccessed+1e2 (+0x123)
- [ d7 be 7d fb f6:17 31 62 c4 88 ]
- fffff8062acc457c-fffff8062acc4580 5 bytes - nt!MiClearPteAccessed+1ec (+0x0a)
- [ d0 be 7d fb f6:10 31 62 c4 88 ]
- fffff8062acc4598 - nt!MiClearPteAccessed+208 (+0x1c)
- [ f6:88 ]
- fffff8062acc47b8 - nt!MiClearPteAccessed+428 (+0x220)
- [ f6:88 ]
- fffff8062acc47ce - nt!MiClearPteAccessed+43e (+0x16)
- [ f6:88 ]
- fffff8062acc4830 - nt!MiClearPteAccessed+4a0 (+0x62)
- [ f6:88 ]
- fffff8062acc488b - nt!MiClearPteAccessed+4fb (+0x5b)
- [ fa:f9 ]
- fffff8062acc4936-fffff8062acc493a 5 bytes - nt!MiClearPteAccessed+5a6 (+0xab)
- [ d0 be 7d fb f6:10 31 62 c4 88 ]
- fffff8062acc4940-fffff8062acc4944 5 bytes - nt!MiClearPteAccessed+5b0 (+0x0a)
- [ d7 be 7d fb f6:17 31 62 c4 88 ]
- fffff8062acc4a8b-fffff8062acc4a8f 5 bytes - nt!MiLogPageAccess+5b (+0x14b)
- [ d0 be 7d fb f6:10 31 62 c4 88 ]
- fffff8062acc4ad0 - nt!MiLogPageAccess+a0 (+0x45)
- [ fa:f9 ]
- fffff8062acc4d26-fffff8062acc4d2a 5 bytes - nt!MiLogPageAccess+2f6 (+0x256)
- [ d7 be 7d fb f6:17 31 62 c4 88 ]
- fffff8062ad84f3e-fffff8062ad84f41 4 bytes - nt!MiFreeUltraMapping+32 (+0xc0218)
- [ a0 7d fb f6:20 62 c4 88 ]
- 59 errors : !nt (fffff8062acc41bd-fffff8062ad84f41)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-08-10T14:22:59.000Z
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #4: 3RD PARTY DRIVERS ======================
- Jul 21 2014 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- Sep 04 2014 - nvvad64v.sys - Nvidia Virtual Audio driver http://www.nvidia.com/
- Sep 06 2014 - NvStreamKms.sys - Nvidia Streaming Kernel Service http://www.nvidia.com/
- Mar 31 2015 - HWiNFO64A.SYS - HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
- Jul 07 2015 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
- May 26 2020 - rt640x64.sys - Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Jul 05 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- ================== Dump #4: 3RD PARTY DRIVERS (FULL) ===================
- Image path: \SystemRoot\system32\drivers\nvhda64v.sys
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Mon Jul 21 2014
- Image path: \SystemRoot\system32\drivers\nvvad64v.sys
- Image name: nvvad64v.sys
- Search : https://www.google.com/search?q=nvvad64v.sys
- ADA Info : Nvidia Virtual Audio driver http://www.nvidia.com/
- Timestamp : Thu Sep 4 2014
- Image path: \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
- Image name: NvStreamKms.sys
- Search : https://www.google.com/search?q=NvStreamKms.sys
- ADA Info : Nvidia Streaming Kernel Service http://www.nvidia.com/
- Timestamp : Sat Sep 6 2014
- Image path: \??\C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS
- Image name: HWiNFO64A.SYS
- Search : https://www.google.com/search?q=HWiNFO64A.SYS
- ADA Info : HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
- Timestamp : Tue Mar 31 2015
- Image path: \SystemRoot\System32\drivers\TeeDriverW8x64.sys
- Image name: TeeDriverW8x64.sys
- Search : https://www.google.com/search?q=TeeDriverW8x64.sys
- ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Timestamp : Tue Jul 7 2015
- Image path: \SystemRoot\System32\drivers\rt640x64.sys
- Image name: rt640x64.sys
- Search : https://www.google.com/search?q=rt640x64.sys
- ADA Info : Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Timestamp : Tue May 26 2020
- Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_e92a0ac2e05fb2ca\nvlddmkm.sys
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Sun Jul 5 2020
- ====================== Dump #4: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- atapi.sys ATAPI IDE MiniPort driver (Microsoft)
- ataport.SYS ATAPI Driver Extension (Microsoft)
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdfs.sys CD-ROM File System Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CimFS.SYS Consumer IR Class Driver for eHome (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- csc.sys Windows Client Side Caching driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_atapi.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_dumpata.sys ATAPI Dump Driver
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HdAudio.sys High Definition Audio Function driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- intelppm.sys Processor Device Driver (Microsoft)
- IntelTA.sys Intel Telemetry Driver
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kd.dll Local Kernal Debugger (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate_GenuineIntel.dll Intel Microcode Update Library (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- MpKslDrv.sys Microsoft Anti-malware Protection driver
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msquic.sys Windows QUIC Driver
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndiscap.sys Microsoft NDIS Packet Capture Filter Driver
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- parport.sys Parallel Port Driver (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pciide.sys Generic PCI IDE Bus Driver (Microsoft)
- PCIIDEX.SYS PCI IDE Bus driver file (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- serenum.sys Serial Port Enumerator (Microsoft)
- serial.sys Serial Device Driver
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- usbehci.sys EHCI eUSB Miniport Driver (Microsoft)
- usbhub.sys Default Hub Driver for USB (Microsoft)
- USBPORT.SYS USB 1.1 & 2.0 Port Driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- ====================== Dump #4: UNLOADED MODULES =======================
- fffff806`36bb0000 fffff806`36bc0000 dump_ataport
- fffff806`36bd0000 fffff806`36bde000 dump_atapi.s
- fffff806`36a00000 fffff806`36a1e000 dump_dumpfve
- fffff806`381b0000 fffff806`381cc000 dam.sys
- fffff806`2fe50000 fffff806`2fe62000 WdBoot.sys
- fffff806`30e50000 fffff806`30e60000 hwpolicy.sys
- ====================== Dump #4: BIOS INFORMATION =======================
- [SMBIOS Data Tables v2.7]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 3016 bytes]
- [BIOS Information (Type 0) - Length 24 - Handle 0000h]
- Vendor American Megatrends Inc.
- BIOS Version F6
- BIOS Starting Address Segment f000
- BIOS Release Date 02/16/2012
- BIOS ROM Size 280000
- BIOS Characteristics
- 07: - PCI Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 27: - Keyboard Services Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 32: - BIOS Vendor Reserved
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 4
- BIOS Minor Revision 6
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- Manufacturer Gigabyte Tecohnology Co., Ltd.
- Product Name H61M-DS2
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
- Manufacturer Gigabyte Tecohnology Co., Ltd.
- Product H61M-DS2
- Version x.x
- Feature Flags 09h
- -926632224: - -926632176: - «¯þø
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 22 - Handle 0003h]
- Manufacturer Gigabyte Tecohnology Co., Ltd.
- Chassis Type Desktop
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 0
- [Cache Information (Type 7) - Length 19 - Handle 0004h]
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 0020h - 32K
- Installed Size 0020h - 32K
- Supported SRAM Type 0040h - Asynchronous
- Current SRAM Type 0040h - Asynchronous
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Other
- Associativity 16-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0005h]
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 0100h - 256K
- Installed Size 0100h - 256K
- Supported SRAM Type 0040h - Asynchronous
- Current SRAM Type 0040h - Asynchronous
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Instruction
- Associativity 16-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0006h]
- Cache Configuration 0183h - WB Enabled Int NonSocketed L4
- Maximum Cache Size 0c00h - 3072K
- Installed Size 0c00h - 3072K
- Supported SRAM Type 0040h - Asynchronous
- Current SRAM Type 0040h - Asynchronous
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Instruction
- Associativity Specification Reserved
- [Physical Memory Array (Type 16) - Length 23 - Handle 0007h]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 33554432KB
- Number of Memory Devices 4
- [Onboard Devices Information (Type 10) - Length 6 - Handle 0026h]
- Number of Devices 1
- 01: Type Video [enabled]
- [OEM Strings (Type 11) - Length 5 - Handle 0027h]
- Number of Strings 1
- [System Configuration Options (Type 12) - Length 5 - Handle 0028h]
- [Memory Device (Type 17) - Length 34 - Handle 0040h]
- Physical Memory Array Handle 0007h
- Total Width 64 bits
- Data Width 64 bits
- Size 4096MB
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM0
- Bank Locator BANK 0
- Memory Type 18h - Specification Reserved
- Type Detail 0080h - Synchronous
- Speed 1333MHz
- Manufacturer Hynix/Hyundai
- Part Number HMT351U6CFR8C-H9
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0041h]
- Starting Address 00000000h
- Ending Address 003fffffh
- Memory Device Handle 0040h
- Mem Array Mapped Adr Handle 0047h
- Interleave Position 01
- Interleave Data Depth 02
- [Memory Device (Type 17) - Length 34 - Handle 0042h]
- Physical Memory Array Handle 0007h
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM1
- Bank Locator BANK 1
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Processor Information (Type 4) - Length 42 - Handle 0043h]
- Socket Designation Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
- Processor Type Central Processor
- Processor Family c6h - Specification Reserved
- Processor Manufacturer Intel
- Processor ID a7060200fffbebbf
- Processor Version Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
- Processor Voltage 8bh - 1.1V
- External Clock 100MHz
- Max Speed 7000MHz
- Current Speed 3300MHz
- Status Enabled Populated
- Processor Upgrade Other
- L1 Cache Handle 0004h
- L2 Cache Handle 0005h
- L3 Cache Handle 0006h
- [Memory Device (Type 17) - Length 34 - Handle 0044h]
- Physical Memory Array Handle 0007h
- Total Width 64 bits
- Data Width 64 bits
- Size 4096MB
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM0
- Bank Locator BANK 2
- Memory Type 18h - Specification Reserved
- Type Detail 0080h - Synchronous
- Speed 1333MHz
- Manufacturer 8325
- Part Number FLFF65F-C8KL9
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0045h]
- Starting Address 00400000h
- Ending Address 007fffffh
- Memory Device Handle 0044h
- Mem Array Mapped Adr Handle 0047h
- Interleave Position 02
- Interleave Data Depth 02
- [Memory Device (Type 17) - Length 34 - Handle 0046h]
- Physical Memory Array Handle 0007h
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM1
- Bank Locator BANK 3
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0047h]
- Starting Address 00000000h
- Ending Address 007fffffh
- Memory Array Handle 0007h
- Partition Width 04
- ========================== Dump #4: Extra #1 ===========================
- 0: kd> !verifier
- Verify Flags Level 0x00000000
- STANDARD FLAGS:
- [X] (0x00000000) Automatic Checks
- [ ] (0x00000001) Special pool
- [ ] (0x00000002) Force IRQL checking
- [ ] (0x00000008) Pool tracking
- [ ] (0x00000010) I/O verification
- [ ] (0x00000020) Deadlock detection
- [ ] (0x00000080) DMA checking
- [ ] (0x00000100) Security checks
- [ ] (0x00000800) Miscellaneous checks
- [ ] (0x00020000) DDI compliance checking
- ADDITIONAL FLAGS:
- [ ] (0x00000004) Randomized low resources simulation
- [ ] (0x00000200) Force pending I/O requests
- [ ] (0x00000400) IRP logging
- [ ] (0x00002000) Invariant MDL checking for stack
- [ ] (0x00004000) Invariant MDL checking for driver
- [ ] (0x00008000) Power framework delay fuzzing
- [ ] (0x00010000) Port/miniport interface checking
- [ ] (0x00040000) Systematic low resources simulation
- [ ] (0x00080000) DDI compliance checking (additional)
- [ ] (0x00200000) NDIS/WIFI verification
- [ ] (0x00800000) Kernel synchronization delay fuzzing
- [ ] (0x01000000) VM switch verification
- [ ] (0x02000000) Code integrity checks
- [X] Indicates flag is enabled
- Summary of All Verifier Statistics
- RaiseIrqls 0x0
- AcquireSpinLocks 0x0
- Synch Executions 0x0
- Trims 0x0
- Pool Allocations Attempted 0x0
- Pool Allocations Succeeded 0x0
- Pool Allocations Succeeded SpecialPool 0x0
- Pool Allocations With NO TAG 0x0
- Pool Allocations Failed 0x0
- Current paged pool allocations 0x0 for 00000000 bytes
- Peak paged pool allocations 0x0 for 00000000 bytes
- Current nonpaged pool allocations 0x0 for 00000000 bytes
- Peak nonpaged pool allocations 0x0 for 00000000 bytes
- ========================== Dump #4: Extra #2 ===========================
- 0: kd> !thread
- THREAD ffffbf074622b080 Cid 0a14.0590 Teb: 0000000000386000 Win32Thread: ffffbf07462c5040 RUNNING on processor 0
- Not impersonating
- GetUlongFromAddress: unable to read from fffff8062b61143c
- Owning Process ffffbf0740de3080 Image: 347.09-notebook-win8-win7-64bit-internationa
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 130950
- Context Switch Count 67 IdealProcessor: 0
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address 0x0000000000401230
- Stack Init ffffb901b2c53c90 Current ffffb901b2c530b0
- Base ffffb901b2c54000 Limit ffffb901b2c4e000 Call 0000000000000000
- Priority 12 BasePriority 8 PriorityDecrement 2 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- ffffb901`b2c52e08 fffff806`2adefa29 : 00000000`0000000a ffffbf07`556b1042 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
- ffffb901`b2c52e10 fffff806`2adebd29 : 00000000`00000000 fffff806`2ac956b9 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
- ffffb901`b2c52f50 fffff806`2acc4d3b : fffff980`013faa30 ffffb901`b2c53128 fffff806`2b652780 fffff806`2b64f600 : nt!KiPageFault+0x469 (TrapFrame @ ffffb901`b2c52f50)
- ffffb901`b2c530e0 fffff806`2acc07e8 : 00000000`00b3e000 80000000`6a8e1821 00000003`00000000 fffff806`2ad16b2a : nt!MiLogPageAccess+0x30b
- ffffb901`b2c53170 fffff806`2b063c5f : ffffe38f`4fd7f000 ffffa781`6d349280 00000000`00000000 00000000`00000000 : nt!MmUnmapViewInSystemCache+0x988
- ffffb901`b2c53290 fffff806`2ac86ae6 : 00000000`00b00000 ffffbf07`46356a20 ffffbf07`3b9103b8 00000000`00000001 : nt!CcUnmapVacb+0x63
- ffffb901`b2c532d0 fffff806`2ac8bb7a : 00000000`00c00001 ffffbf07`3b6898a0 00000000`00400000 00000000`00000001 : nt!CcUnmapVacbArray+0x206
- ffffb901`b2c53340 fffff806`2b064180 : 00000000`00c00000 00000000`00000000 ffffb901`b2c53480 ffffb901`b2c53490 : nt!CcGetVirtualAddress+0x40a
- ffffb901`b2c533e0 fffff806`2ac8b0b9 : 00000000`00000000 00000000`00c00000 00000000`00000000 00000000`00000001 : nt!CcMapAndCopyFromCache+0x80
- ffffb901`b2c53480 fffff806`3045a1ad : ffffb901`b2c535e0 00000000`00000000 ffffa781`00100000 00000000`00100000 : nt!CcCopyReadEx+0x139
- ffffb901`b2c53530 fffff806`2a2373fb : 00000000`00000000 ffffb901`b2c53908 ffffb901`b2c538c8 00000000`032b0020 : Ntfs!NtfsCopyReadA+0x2ed
- ffffb901`b2c53820 fffff806`2a2344d7 : ffffb901`b2c53930 ffffb901`b2c538c8 ffffbf07`449f1110 ffffbf07`449f1010 : FLTMGR!FltpPerformFastIoCall+0x16b
- ffffb901`b2c53880 fffff806`2a26b405 : ffffb901`b2c54000 ffffb901`b2c4e000 ffffbf07`4622b080 fffff806`2aff8fce : FLTMGR!FltpPassThroughFastIo+0x107
- ffffb901`b2c53900 fffff806`2b011b5f : ffffbf07`4657a100 00000000`00000000 00000000`00000000 ffffbf07`00000000 : FLTMGR!FltpFastIoRead+0x165
- ffffb901`b2c539b0 fffff806`2adef478 : 00000000`0000026c 00000000`00000000 00000000`00000000 00000000`00000000 : nt!NtReadFile+0x37f
- ffffb901`b2c53a90 00000000`76f11cfc : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28 (TrapFrame @ ffffb901`b2c53b00)
- 00000000`031af308 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x76f11cfc
- ========================================================================
- ======================= Dump #5: ANALYZE VERBOSE =======================
- ====================== File: 081020-26375-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 19041 MP (4 procs) Free x64
- Kernel base = 0xfffff806`7b000000 PsLoadedModuleList = 0xfffff806`7bc2a310
- Debug session time: Mon Aug 10 17:49:54.155 2020 (UTC - 4:00)
- System Uptime: 0 days 0:29:33.871
- BugCheck 1A, {61941, 23ba113fa58, d, fffff28e61731b00}
- *** WARNING: Unable to verify timestamp for win32k.sys
- *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
- Probably caused by : memory_corruption
- Followup: memory_corruption
- MEMORY_MANAGEMENT (1a)
- # Any other values for parameter 1 must be individually examined.
- Arguments:
- Arg1: 0000000000061941, The subtype of the bugcheck.
- Arg2: 0000023ba113fa58
- Arg3: 000000000000000d
- Arg4: fffff28e61731b00
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- BUGCHECK_STR: 0x1a_61941
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- PROCESS_NAME: GTA5.exe
- CURRENT_IRQL: 0
- LAST_CONTROL_TRANSFER: from fffff8067b4020a6 to fffff8067b3ddb60
- STACK_TEXT:
- fffff28e`61731958 fffff806`7b4020a6 : 00000000`0000001a 00000000`00061941 0000023b`a113fa58 00000000`0000000d : nt!KeBugCheckEx
- fffff28e`61731960 fffff806`7b3ebc1e : 0000023b`00000000 00000000`00000001 00000000`00000001 fffff28e`61731b80 : nt!MmAccessFault+0x1ef7a6
- fffff28e`61731b00 00007ff7`4061b435 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x35e
- 00000057`285ff5b8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff7`4061b435
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
- fffff8067b384f3e-fffff8067b384f41 4 bytes - nt!MiFreeUltraMapping+32
- [ a0 7d fb f6:40 be 7c f9 ]
- fffff8067b3e4c13-fffff8067b3e4c14 2 bytes - nt!SwapContext+53 (+0x5fcd5)
- [ 48 ff:4c 8b ]
- fffff8067b3e4c1a-fffff8067b3e4c1d 4 bytes - nt!SwapContext+5a (+0x07)
- [ 0f 1f 44 00:e8 01 08 64 ]
- 10 errors : !nt (fffff8067b384f3e-fffff8067b3e4c1d)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-08-10T21:49:54.000Z
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #5: 3RD PARTY DRIVERS ======================
- Jul 21 2014 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- Sep 04 2014 - nvvad64v.sys - Nvidia Virtual Audio driver http://www.nvidia.com/
- Sep 06 2014 - NvStreamKms.sys - Nvidia Streaming Kernel Service http://www.nvidia.com/
- Mar 31 2015 - HWiNFO64A.SYS - HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
- Jul 07 2015 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
- May 26 2020 - rt640x64.sys - Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Jul 05 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- ================== Dump #5: 3RD PARTY DRIVERS (FULL) ===================
- Image path: \SystemRoot\system32\drivers\nvhda64v.sys
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Mon Jul 21 2014
- Image path: \SystemRoot\system32\drivers\nvvad64v.sys
- Image name: nvvad64v.sys
- Search : https://www.google.com/search?q=nvvad64v.sys
- ADA Info : Nvidia Virtual Audio driver http://www.nvidia.com/
- Timestamp : Thu Sep 4 2014
- Image path: \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
- Image name: NvStreamKms.sys
- Search : https://www.google.com/search?q=NvStreamKms.sys
- ADA Info : Nvidia Streaming Kernel Service http://www.nvidia.com/
- Timestamp : Sat Sep 6 2014
- Image path: \??\C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS
- Image name: HWiNFO64A.SYS
- Search : https://www.google.com/search?q=HWiNFO64A.SYS
- ADA Info : HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
- Timestamp : Tue Mar 31 2015
- Image path: \SystemRoot\System32\drivers\TeeDriverW8x64.sys
- Image name: TeeDriverW8x64.sys
- Search : https://www.google.com/search?q=TeeDriverW8x64.sys
- ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Timestamp : Tue Jul 7 2015
- Image path: \SystemRoot\System32\drivers\rt640x64.sys
- Image name: rt640x64.sys
- Search : https://www.google.com/search?q=rt640x64.sys
- ADA Info : Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Timestamp : Tue May 26 2020
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Sun Jul 5 2020
- ====================== Dump #5: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- atapi.sys ATAPI IDE MiniPort driver (Microsoft)
- ataport.SYS ATAPI Driver Extension (Microsoft)
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdfs.sys CD-ROM File System Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CimFS.SYS Consumer IR Class Driver for eHome (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- csc.sys Windows Client Side Caching driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_atapi.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_dumpata.sys ATAPI Dump Driver
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HdAudio.sys High Definition Audio Function driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- intelppm.sys Processor Device Driver (Microsoft)
- IntelTA.sys Intel Telemetry Driver
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kd.dll Local Kernal Debugger (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate_GenuineIntel.dll Intel Microcode Update Library (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- MpKslDrv.sys Microsoft Anti-malware Protection driver
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msquic.sys Windows QUIC Driver
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndiscap.sys Microsoft NDIS Packet Capture Filter Driver
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- parport.sys Parallel Port Driver (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pciide.sys Generic PCI IDE Bus Driver (Microsoft)
- PCIIDEX.SYS PCI IDE Bus driver file (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- serenum.sys Serial Port Enumerator (Microsoft)
- serial.sys Serial Device Driver
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- usbehci.sys EHCI eUSB Miniport Driver (Microsoft)
- usbhub.sys Default Hub Driver for USB (Microsoft)
- USBPORT.SYS USB 1.1 & 2.0 Port Driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- ====================== Dump #5: UNLOADED MODULES =======================
- fffff806`85100000 fffff806`85110000 dump_ataport
- fffff806`85120000 fffff806`8512e000 dump_atapi.s
- fffff806`85150000 fffff806`8516e000 dump_dumpfve
- fffff806`84b40000 fffff806`84b5c000 dam.sys
- fffff806`7d650000 fffff806`7d662000 WdBoot.sys
- fffff806`7e650000 fffff806`7e660000 hwpolicy.sys
- ====================== Dump #5: BIOS INFORMATION =======================
- [SMBIOS Data Tables v2.7]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 3016 bytes]
- [BIOS Information (Type 0) - Length 24 - Handle 0000h]
- Vendor American Megatrends Inc.
- BIOS Version F6
- BIOS Starting Address Segment f000
- BIOS Release Date 02/16/2012
- BIOS ROM Size 280000
- BIOS Characteristics
- 07: - PCI Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 27: - Keyboard Services Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 32: - BIOS Vendor Reserved
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 4
- BIOS Minor Revision 6
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- Manufacturer Gigabyte Tecohnology Co., Ltd.
- Product Name H61M-DS2
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
- Manufacturer Gigabyte Tecohnology Co., Ltd.
- Product H61M-DS2
- Version x.x
- Feature Flags 09h
- -926632224: - -926632176: - «¯þø
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 22 - Handle 0003h]
- Manufacturer Gigabyte Tecohnology Co., Ltd.
- Chassis Type Desktop
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 0
- [Cache Information (Type 7) - Length 19 - Handle 0004h]
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 0020h - 32K
- Installed Size 0020h - 32K
- Supported SRAM Type 0040h - Asynchronous
- Current SRAM Type 0040h - Asynchronous
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Other
- Associativity 16-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0005h]
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 0100h - 256K
- Installed Size 0100h - 256K
- Supported SRAM Type 0040h - Asynchronous
- Current SRAM Type 0040h - Asynchronous
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Instruction
- Associativity 16-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0006h]
- Cache Configuration 0183h - WB Enabled Int NonSocketed L4
- Maximum Cache Size 0c00h - 3072K
- Installed Size 0c00h - 3072K
- Supported SRAM Type 0040h - Asynchronous
- Current SRAM Type 0040h - Asynchronous
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Instruction
- Associativity Specification Reserved
- [Physical Memory Array (Type 16) - Length 23 - Handle 0007h]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 33554432KB
- Number of Memory Devices 4
- [Onboard Devices Information (Type 10) - Length 6 - Handle 0026h]
- Number of Devices 1
- 01: Type Video [enabled]
- [OEM Strings (Type 11) - Length 5 - Handle 0027h]
- Number of Strings 1
- [System Configuration Options (Type 12) - Length 5 - Handle 0028h]
- [Memory Device (Type 17) - Length 34 - Handle 0040h]
- Physical Memory Array Handle 0007h
- Total Width 64 bits
- Data Width 64 bits
- Size 4096MB
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM0
- Bank Locator BANK 0
- Memory Type 18h - Specification Reserved
- Type Detail 0080h - Synchronous
- Speed 1333MHz
- Manufacturer Hynix/Hyundai
- Part Number HMT351U6CFR8C-H9
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0041h]
- Starting Address 00000000h
- Ending Address 003fffffh
- Memory Device Handle 0040h
- Mem Array Mapped Adr Handle 0047h
- Interleave Position 01
- Interleave Data Depth 02
- [Memory Device (Type 17) - Length 34 - Handle 0042h]
- Physical Memory Array Handle 0007h
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM1
- Bank Locator BANK 1
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Processor Information (Type 4) - Length 42 - Handle 0043h]
- Socket Designation Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
- Processor Type Central Processor
- Processor Family c6h - Specification Reserved
- Processor Manufacturer Intel
- Processor ID a7060200fffbebbf
- Processor Version Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
- Processor Voltage 8bh - 1.1V
- External Clock 100MHz
- Max Speed 7000MHz
- Current Speed 3300MHz
- Status Enabled Populated
- Processor Upgrade Other
- L1 Cache Handle 0004h
- L2 Cache Handle 0005h
- L3 Cache Handle 0006h
- [Memory Device (Type 17) - Length 34 - Handle 0044h]
- Physical Memory Array Handle 0007h
- Total Width 64 bits
- Data Width 64 bits
- Size 4096MB
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM0
- Bank Locator BANK 2
- Memory Type 18h - Specification Reserved
- Type Detail 0080h - Synchronous
- Speed 1333MHz
- Manufacturer 8325
- Part Number FLFF65F-C8KL9
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0045h]
- Starting Address 00400000h
- Ending Address 007fffffh
- Memory Device Handle 0044h
- Mem Array Mapped Adr Handle 0047h
- Interleave Position 02
- Interleave Data Depth 02
- [Memory Device (Type 17) - Length 34 - Handle 0046h]
- Physical Memory Array Handle 0007h
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM1
- Bank Locator BANK 3
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0047h]
- Starting Address 00000000h
- Ending Address 007fffffh
- Memory Array Handle 0007h
- Partition Width 04
- ========================== Dump #5: Extra #1 ===========================
- 3: kd> !verifier
- Verify Flags Level 0x00000000
- STANDARD FLAGS:
- [X] (0x00000000) Automatic Checks
- [ ] (0x00000001) Special pool
- [ ] (0x00000002) Force IRQL checking
- [ ] (0x00000008) Pool tracking
- [ ] (0x00000010) I/O verification
- [ ] (0x00000020) Deadlock detection
- [ ] (0x00000080) DMA checking
- [ ] (0x00000100) Security checks
- [ ] (0x00000800) Miscellaneous checks
- [ ] (0x00020000) DDI compliance checking
- ADDITIONAL FLAGS:
- [ ] (0x00000004) Randomized low resources simulation
- [ ] (0x00000200) Force pending I/O requests
- [ ] (0x00000400) IRP logging
- [ ] (0x00002000) Invariant MDL checking for stack
- [ ] (0x00004000) Invariant MDL checking for driver
- [ ] (0x00008000) Power framework delay fuzzing
- [ ] (0x00010000) Port/miniport interface checking
- [ ] (0x00040000) Systematic low resources simulation
- [ ] (0x00080000) DDI compliance checking (additional)
- [ ] (0x00200000) NDIS/WIFI verification
- [ ] (0x00800000) Kernel synchronization delay fuzzing
- [ ] (0x01000000) VM switch verification
- [ ] (0x02000000) Code integrity checks
- [X] Indicates flag is enabled
- Summary of All Verifier Statistics
- RaiseIrqls 0x0
- AcquireSpinLocks 0x0
- Synch Executions 0x0
- Trims 0x0
- Pool Allocations Attempted 0x0
- Pool Allocations Succeeded 0x0
- Pool Allocations Succeeded SpecialPool 0x0
- Pool Allocations With NO TAG 0x0
- Pool Allocations Failed 0x0
- Current paged pool allocations 0x0 for 00000000 bytes
- Peak paged pool allocations 0x0 for 00000000 bytes
- Current nonpaged pool allocations 0x0 for 00000000 bytes
- Peak nonpaged pool allocations 0x0 for 00000000 bytes
- ========================== Dump #5: Extra #2 ===========================
- 3: kd> !thread
- THREAD ffff980396139080 Cid 1c5c.1674 Teb: 0000005727395000 Win32Thread: ffff980397645c20 RUNNING on processor 3
- Not impersonating
- GetUlongFromAddress: unable to read from fffff8067bc1143c
- Owning Process ffff98039535e080 Image: GTA5.exe
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 113527
- Context Switch Count 4889304 IdealProcessor: 0
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address 0x00007ff74058c6e0
- Stack Init fffff28e61731c90 Current fffff28e61731980
- Base fffff28e61732000 Limit fffff28e6172c000 Call 0000000000000000
- Priority 9 BasePriority 9 PriorityDecrement 0 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- fffff28e`61731958 fffff806`7b4020a6 : 00000000`0000001a 00000000`00061941 0000023b`a113fa58 00000000`0000000d : nt!KeBugCheckEx
- fffff28e`61731960 fffff806`7b3ebc1e : 0000023b`00000000 00000000`00000001 00000000`00000001 fffff28e`61731b80 : nt!MmAccessFault+0x1ef7a6
- fffff28e`61731b00 00007ff7`4061b435 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x35e (TrapFrame @ fffff28e`61731b00)
- 00000057`285ff5b8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff7`4061b435
- ========================================================================
- ======================= Dump #6: ANALYZE VERBOSE =======================
- ====================== File: 081020-25140-01.dmp =======================
- ========================================================================
- Mini Kernel Dump File: Only registers and stack trace are available
- Windows 10 Kernel Version 19041 MP (4 procs) Free x64
- Kernel base = 0xfffff802`27200000 PsLoadedModuleList = 0xfffff802`27e2a310
- Debug session time: Sun Aug 9 19:52:15.882 2020 (UTC - 4:00)
- System Uptime: 0 days 10:01:45.386
- BugCheck A, {1ddbb5, 2, 0, fffff802274acd4d}
- *** WARNING: Unable to verify timestamp for win32k.sys
- *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
- Probably caused by : memory_corruption
- Followup: memory_corruption
- IRQL_NOT_LESS_OR_EQUAL (a)
- An attempt was made to access a pageable (or completely invalid) address at an
- interrupt request level (IRQL) that is too high. This is usually
- caused by drivers using improper addresses.
- If a kernel debugger is available get the stack backtrace.
- Arguments:
- Arg1: 00000000001ddbb5, memory referenced
- Arg2: 0000000000000002, IRQL
- Arg3: 0000000000000000, bitfield :
- bit 0 : value 0 = read operation, 1 = write operation
- bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
- Arg4: fffff802274acd4d, address which referenced memory
- Debugging Details:
- DUMP_CLASS: 1
- DUMP_QUALIFIER: 400
- DUMP_TYPE: 2
- READ_ADDRESS: fffff80227efa388: Unable to get MiVisibleState
- 00000000001ddbb5
- CURRENT_IRQL: 2
- FAULTING_IP:
- nt!MiInsertPageInFreeOrZeroedList+2dd
- fffff802`274acd4d 0fb70c11 movzx ecx,word ptr [rcx+rdx]
- CUSTOMER_CRASH_COUNT: 1
- DEFAULT_BUCKET_ID: CODE_CORRUPTION
- BUGCHECK_STR: AV
- PROCESS_NAME: System
- TRAP_FRAME: ffffda8a37616800 -- (.trap 0xffffda8a37616800)
- NOTE: The trap frame does not contain all registers.
- Some register values may be zeroed or incorrect.
- rax=0000000000000001 rbx=0000000000000000 rcx=00000000000001e0
- rdx=00000000001dd9d5 rsi=0000000000000000 rdi=0000000000000000
- rip=fffff802274acd4d rsp=ffffda8a37616990 rbp=ffffda8a37616a29
- r8=ffffdc039c446510 r9=0000000000001000 r10=000000000000001e
- r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
- r14=0000000000000000 r15=0000000000000000
- iopl=0 nv up ei pl nz na pe nc
- nt!MiInsertPageInFreeOrZeroedList+0x2dd:
- fffff802`274acd4d 0fb70c11 movzx ecx,word ptr [rcx+rdx] ds:00000000`001ddbb5=????
- Resetting default scope
- LAST_CONTROL_TRANSFER: from fffff802275efa29 to fffff802275ddb60
- STACK_TEXT:
- ffffda8a`376166b8 fffff802`275efa29 : 00000000`0000000a 00000000`001ddbb5 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
- ffffda8a`376166c0 fffff802`275ebd29 : ffff9d01`ae1b0140 ffffdc03`a7df5040 ffff9d01`ae1a5180 fffff802`275e4d72 : nt!KiBugCheckDispatch+0x69
- ffffda8a`37616800 fffff802`274acd4d : 00000000`00000000 ffff9780`00000001 00000000`00000000 fffff802`27e4e680 : nt!KiPageFault+0x469
- ffffda8a`37616990 fffff802`2775877c : 00000000`00064e1e 00000000`00000000 00000000`0000001e 00000000`00000001 : nt!MiInsertPageInFreeOrZeroedList+0x2dd
- ffffda8a`37616a90 fffff802`277588b3 : fffff802`27e50b40 00000000`00000000 fffff802`00000000 00000000`00000229 : nt!MiPruneStandbyPages+0x380
- ffffda8a`37616b20 fffff802`27433f45 : ffffdc03`a7df5040 fffff802`27758820 ffffdc03`9c557a60 fffff802`27e523e0 : nt!MiRebalanceZeroFreeLists+0x93
- ffffda8a`37616b70 fffff802`27546735 : ffffdc03`a7df5040 00000000`00000080 ffffdc03`9c496040 00000000`00000001 : nt!ExpWorkerThread+0x105
- ffffda8a`37616c10 fffff802`275e51b8 : ffff9d01`ae2f6180 ffffdc03`a7df5040 fffff802`275466e0 00000000`00000000 : nt!PspSystemThreadStartup+0x55
- ffffda8a`37616c60 00000000`00000000 : ffffda8a`37617000 ffffda8a`37611000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
- STACK_COMMAND: kb
- CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
- fffff80227458de2 - nt!MiTradeTransitionPage+9a
- [ fa:97 ]
- fffff802274ac017 - nt!MiDeleteBatch+f7 (+0x53235)
- [ fa:97 ]
- fffff802274ac021 - nt!MiDeleteBatch+101 (+0x0a)
- [ fa:97 ]
- fffff802274ac02b - nt!MiDeleteBatch+10b (+0x0a)
- [ fa:97 ]
- fffff802274ac0c9 - nt!MiDeleteBatch+1a9 (+0x9e)
- [ fa:97 ]
- fffff802274ac0dd - nt!MiDeleteBatch+1bd (+0x14)
- [ fa:97 ]
- fffff802274ac0e7 - nt!MiDeleteBatch+1c7 (+0x0a)
- [ fa:97 ]
- fffff802274ac1d7 - nt!MiDeleteBatch+2b7 (+0xf0)
- [ fa:97 ]
- fffff802274ac24a - nt!MiDeleteBatch+32a (+0x73)
- [ fa:97 ]
- fffff802274ac47b - nt!MiZeroLargePages+20b (+0x231)
- [ fa:97 ]
- fffff802274ac4f8 - nt!MiZeroLargePages+288 (+0x7d)
- [ fa:97 ]
- fffff802274aca9c - nt!MiInsertPageInFreeOrZeroedList+2c (+0x5a4)
- [ fa:97 ]
- fffff802275467b6 - nt!MiDeleteNonPagedPoolTail+46 (+0x99d1a)
- [ fa:97 ]
- fffff80227584f3e-fffff80227584f41 4 bytes - nt!MiFreeUltraMapping+32 (+0x3e788)
- [ a0 7d fb f6:60 fb f6 ed ]
- fffff802277587f3 - nt!MiPruneStandbyPages+3f7 (+0x1d38b5)
- [ fa:97 ]
- 18 errors : !nt (fffff80227458de2-fffff802277587f3)
- MODULE_NAME: memory_corruption
- IMAGE_NAME: memory_corruption
- FOLLOWUP_NAME: memory_corruption
- DEBUG_FLR_IMAGE_TIMESTAMP: 0
- MEMORY_CORRUPTOR: LARGE
- FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
- BUCKET_ID: MEMORY_CORRUPTION_LARGE
- PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
- TARGET_TIME: 2020-08-09T23:52:15.000Z
- SUITE_MASK: 272
- PRODUCT_TYPE: 1
- USER_LCID: 0
- FAILURE_ID_HASH_STRING: km:memory_corruption_large
- FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
- Followup: memory_corruption
- ====================== Dump #6: 3RD PARTY DRIVERS ======================
- Jul 21 2014 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
- Sep 04 2014 - nvvad64v.sys - Nvidia Virtual Audio driver http://www.nvidia.com/
- Sep 06 2014 - NvStreamKms.sys - Nvidia Streaming Kernel Service http://www.nvidia.com/
- Mar 31 2015 - HWiNFO64A.SYS - HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
- Jul 07 2015 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
- May 26 2020 - rt640x64.sys - Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Jul 05 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
- ================== Dump #6: 3RD PARTY DRIVERS (FULL) ===================
- Image path: \SystemRoot\system32\drivers\nvhda64v.sys
- Image name: nvhda64v.sys
- Search : https://www.google.com/search?q=nvhda64v.sys
- ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
- Timestamp : Mon Jul 21 2014
- Image path: \SystemRoot\system32\drivers\nvvad64v.sys
- Image name: nvvad64v.sys
- Search : https://www.google.com/search?q=nvvad64v.sys
- ADA Info : Nvidia Virtual Audio driver http://www.nvidia.com/
- Timestamp : Thu Sep 4 2014
- Image path: \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
- Image name: NvStreamKms.sys
- Search : https://www.google.com/search?q=NvStreamKms.sys
- ADA Info : Nvidia Streaming Kernel Service http://www.nvidia.com/
- Timestamp : Sat Sep 6 2014
- Image path: \??\C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS
- Image name: HWiNFO64A.SYS
- Search : https://www.google.com/search?q=HWiNFO64A.SYS
- ADA Info : HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
- Timestamp : Tue Mar 31 2015
- Image path: \SystemRoot\System32\drivers\TeeDriverW8x64.sys
- Image name: TeeDriverW8x64.sys
- Search : https://www.google.com/search?q=TeeDriverW8x64.sys
- ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
- Timestamp : Tue Jul 7 2015
- Image path: \SystemRoot\System32\drivers\rt640x64.sys
- Image name: rt640x64.sys
- Search : https://www.google.com/search?q=rt640x64.sys
- ADA Info : Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
- Timestamp : Tue May 26 2020
- Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_e92a0ac2e05fb2ca\nvlddmkm.sys
- Image name: nvlddmkm.sys
- Search : https://www.google.com/search?q=nvlddmkm.sys
- ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
- Timestamp : Sun Jul 5 2020
- ====================== Dump #6: MICROSOFT DRIVERS ======================
- ACPI.sys ACPI Driver for NT (Microsoft)
- acpiex.sys ACPIEx Driver (Microsoft)
- afd.sys Ancillary Function Driver for WinSock (Microsoft)
- afunix.sys AF_UNIX Socket Provider driver (Microsoft)
- ahcache.sys Application Compatibility Cache (Microsoft)
- atapi.sys ATAPI IDE MiniPort driver (Microsoft)
- ataport.SYS ATAPI Driver Extension (Microsoft)
- bam.sys BAM Kernal driver (Microsoft)
- BasicDisplay.sys Basic Display driver (Microsoft)
- BasicRender.sys Basic Render driver (Microsoft)
- Beep.SYS BEEP driver (Microsoft)
- bindflt.sys Windows Bind Filter driver (Microsoft)
- BOOTVID.dll VGA Boot Driver (Microsoft)
- bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
- cdd.dll Canonical Display Driver (Microsoft)
- cdfs.sys CD-ROM File System Driver (Microsoft)
- cdrom.sys SCSI CD-ROM Driver (Microsoft)
- CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
- CI.dll Code Integrity Module (Microsoft)
- CimFS.SYS Consumer IR Class Driver for eHome (Microsoft)
- CLASSPNP.SYS SCSI Class System Dll (Microsoft)
- cldflt.sys Cloud Files Mini Filter driver (Microsoft)
- CLFS.SYS Common Log File System Driver (Microsoft)
- clipsp.sys CLIP Service (Microsoft)
- cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
- cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
- CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
- condrv.sys Console Driver (Microsoft)
- crashdmp.sys Crash Dump driver (Microsoft)
- csc.sys Windows Client Side Caching driver (Microsoft)
- dfsc.sys DFS Namespace Client Driver (Microsoft)
- disk.sys PnP Disk Driver (Microsoft)
- drmk.sys Digital Rights Management (DRM) driver (Microsoft)
- dump_atapi.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dump_dumpata.sys ATAPI Dump Driver
- dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
- dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
- dxgmms2.sys DirectX Graphics MMS
- EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
- fastfat.SYS Fast FAT File System Driver (Microsoft)
- filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
- fileinfo.sys FileInfo Filter Driver (Microsoft)
- FLTMGR.SYS Filesystem Filter Manager (Microsoft)
- Fs_Rec.sys File System Recognizer Driver (Microsoft)
- fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
- fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
- gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
- hal.dll Hardware Abstraction Layer DLL (Microsoft)
- HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
- HdAudio.sys High Definition Audio Function driver (Microsoft)
- HIDCLASS.SYS Hid Class Library (Microsoft)
- HIDPARSE.SYS Hid Parsing Library (Microsoft)
- hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
- HTTP.sys HTTP Protocol Stack (Microsoft)
- intelpep.sys Intel Power Engine Plugin (Microsoft)
- intelppm.sys Processor Device Driver (Microsoft)
- IntelTA.sys Intel Telemetry Driver
- iorate.sys I/O rate control Filter (Microsoft)
- kbdclass.sys Keyboard Class Driver (Microsoft)
- kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
- kd.dll Local Kernal Debugger (Microsoft)
- kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
- ks.sys Kernal CSA Library (Microsoft)
- ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
- ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
- ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
- lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
- luafv.sys LUA File Virtualization Filter Driver (Microsoft)
- mcupdate_GenuineIntel.dll Intel Microcode Update Library (Microsoft)
- mmcss.sys MMCSS Driver (Microsoft)
- monitor.sys Monitor Driver (Microsoft)
- mouclass.sys Mouse Class Driver (Microsoft)
- mouhid.sys HID Mouse Filter Driver (Microsoft)
- mountmgr.sys Mount Point Manager (Microsoft)
- MpKslDrv.sys Microsoft Anti-malware Protection driver
- mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
- mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
- mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
- Msfs.SYS Mailslot driver (Microsoft)
- msisadrv.sys ISA Driver (Microsoft)
- mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
- msquic.sys Windows QUIC Driver
- msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
- mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
- mssmbios.sys System Management BIOS driver (Microsoft)
- mup.sys Multiple UNC Provider driver (Microsoft)
- ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
- ndiscap.sys Microsoft NDIS Packet Capture Filter Driver
- NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
- Ndu.sys Network Data Usage Monitoring driver (Microsoft)
- netbios.sys NetBIOS Interface driver (Microsoft)
- netbt.sys MBT Transport driver (Microsoft)
- NETIO.SYS Network I/O Subsystem (Microsoft)
- Npfs.SYS NPFS driver (Microsoft)
- npsvctrig.sys Named pipe service triggers (Microsoft)
- nsiproxy.sys NSI Proxy driver (Microsoft)
- Ntfs.sys NT File System Driver (Microsoft)
- ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
- ntosext.sys NTOS Extension Host driver (Microsoft)
- Null.SYS NULL Driver (Microsoft)
- pacer.sys QoS Packet Scheduler (Microsoft)
- parport.sys Parallel Port Driver (Microsoft)
- partmgr.sys Partition driver (Microsoft)
- pci.sys NT Plug and Play PCI Enumerator (Microsoft)
- pciide.sys Generic PCI IDE Bus Driver (Microsoft)
- PCIIDEX.SYS PCI IDE Bus driver file (Microsoft)
- pcw.sys Performance Counter Driver (Microsoft)
- pdc.sys Power Dependency Coordinator Driver (Microsoft)
- peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
- portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
- PSHED.dll Platform Specific Hardware Error driver (Microsoft)
- qwavedrv.sys Quality Windows Audio Video Experience (qWave) Support driver (Microsoft)
- rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
- rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
- rdyboost.sys ReadyBoost Driver (Microsoft)
- rspndr.sys Link-Layer Topology Responder driver (Microsoft)
- serenum.sys Serial Port Enumerator (Microsoft)
- serial.sys Serial Device Driver
- SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
- SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
- spaceport.sys Storage Spaces driver (Microsoft)
- srv2.sys Smb 2.0 Server driver (Microsoft)
- srvnet.sys Server Network driver (Microsoft)
- storqosflt.sys Storage QoS Filter driver (Microsoft)
- swenum.sys Plug and Play Software Device Enumerator (Microsoft)
- tbs.sys Export driver for kernel mode TPM API (Microsoft)
- tcpip.sys TCP/IP Protocol driver (Microsoft)
- tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
- TDI.SYS TDI Wrapper driver (Microsoft)
- tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
- tm.sys Kernel Transaction Manager driver (Microsoft)
- umbus.sys User-Mode Bus Enumerator (Microsoft)
- usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
- USBD.SYS Universal Serial Bus Driver (Microsoft)
- usbehci.sys EHCI eUSB Miniport Driver (Microsoft)
- usbhub.sys Default Hub Driver for USB (Microsoft)
- USBPORT.SYS USB 1.1 & 2.0 Port Driver (Microsoft)
- vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
- Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
- volmgr.sys Volume Manager Driver (Microsoft)
- volmgrx.sys Volume Manager Extension Driver (Microsoft)
- volsnap.sys Volume Shadow Copy driver (Microsoft)
- volume.sys Volume driver (Microsoft)
- vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
- watchdog.sys Watchdog driver (Microsoft)
- wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
- Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
- WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
- WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
- WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
- werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
- wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
- win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
- win32kbase.sys Base Win32k Kernel Driver (Microsoft)
- win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
- WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
- WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
- winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
- WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
- Wof.sys Windows Overlay Filter (Microsoft)
- WppRecorder.sys WPP Trace Recorder (Microsoft)
- ====================== Dump #6: UNLOADED MODULES =======================
- fffff802`32fb0000 fffff802`32fc0000 dump_ataport
- fffff802`32fd0000 fffff802`32fde000 dump_atapi.s
- fffff802`32400000 fffff802`3241e000 dump_dumpfve
- fffff802`32dd0000 fffff802`32dec000 dam.sys
- fffff802`2b850000 fffff802`2b862000 WdBoot.sys
- fffff802`2c850000 fffff802`2c860000 hwpolicy.sys
- ====================== Dump #6: BIOS INFORMATION =======================
- [SMBIOS Data Tables v2.7]
- [DMI Version - 0]
- [2.0 Calling Convention - No]
- [Table Size - 3016 bytes]
- [BIOS Information (Type 0) - Length 24 - Handle 0000h]
- Vendor American Megatrends Inc.
- BIOS Version F6
- BIOS Starting Address Segment f000
- BIOS Release Date 02/16/2012
- BIOS ROM Size 280000
- BIOS Characteristics
- 07: - PCI Supported
- 11: - Upgradeable FLASH BIOS
- 12: - BIOS Shadowing Supported
- 15: - CD-Boot Supported
- 16: - Selectable Boot Supported
- 17: - BIOS ROM Socketed
- 19: - EDD Supported
- 23: - 1.2MB Floppy Supported
- 24: - 720KB Floppy Supported
- 25: - 2.88MB Floppy Supported
- 26: - Print Screen Device Supported
- 27: - Keyboard Services Supported
- 28: - Serial Services Supported
- 29: - Printer Services Supported
- 32: - BIOS Vendor Reserved
- BIOS Characteristic Extensions
- 00: - ACPI Supported
- 01: - USB Legacy Supported
- 08: - BIOS Boot Specification Supported
- 10: - Specification Reserved
- 11: - Specification Reserved
- BIOS Major Revision 4
- BIOS Minor Revision 6
- EC Firmware Major Revision 255
- EC Firmware Minor Revision 255
- [System Information (Type 1) - Length 27 - Handle 0001h]
- Manufacturer Gigabyte Tecohnology Co., Ltd.
- Product Name H61M-DS2
- UUID 00000000-0000-0000-0000-000000000000
- Wakeup Type Power Switch
- [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
- Manufacturer Gigabyte Tecohnology Co., Ltd.
- Product H61M-DS2
- Version x.x
- Feature Flags 09h
- -926632224: - -926632176: - «¯þø
- Chassis Handle 0003h
- Board Type 0ah - Processor/Memory Module
- Number of Child Handles 0
- [System Enclosure (Type 3) - Length 22 - Handle 0003h]
- Manufacturer Gigabyte Tecohnology Co., Ltd.
- Chassis Type Desktop
- Bootup State Safe
- Power Supply State Safe
- Thermal State Safe
- Security Status None
- OEM Defined 0
- Height 0U
- Number of Power Cords 1
- Number of Contained Elements 0
- Contained Element Size 0
- [Cache Information (Type 7) - Length 19 - Handle 0004h]
- Cache Configuration 0181h - WB Enabled Int NonSocketed L2
- Maximum Cache Size 0020h - 32K
- Installed Size 0020h - 32K
- Supported SRAM Type 0040h - Asynchronous
- Current SRAM Type 0040h - Asynchronous
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Other
- Associativity 16-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0005h]
- Cache Configuration 0182h - WB Enabled Int NonSocketed L3
- Maximum Cache Size 0100h - 256K
- Installed Size 0100h - 256K
- Supported SRAM Type 0040h - Asynchronous
- Current SRAM Type 0040h - Asynchronous
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Instruction
- Associativity 16-way Set-Associative
- [Cache Information (Type 7) - Length 19 - Handle 0006h]
- Cache Configuration 0183h - WB Enabled Int NonSocketed L4
- Maximum Cache Size 0c00h - 3072K
- Installed Size 0c00h - 3072K
- Supported SRAM Type 0040h - Asynchronous
- Current SRAM Type 0040h - Asynchronous
- Cache Speed 0ns
- Error Correction Type Multi-Bit ECC
- System Cache Type Instruction
- Associativity Specification Reserved
- [Physical Memory Array (Type 16) - Length 23 - Handle 0007h]
- Location 03h - SystemBoard/Motherboard
- Use 03h - System Memory
- Memory Error Correction 03h - None
- Maximum Capacity 33554432KB
- Number of Memory Devices 4
- [Onboard Devices Information (Type 10) - Length 6 - Handle 0026h]
- Number of Devices 1
- 01: Type Video [enabled]
- [OEM Strings (Type 11) - Length 5 - Handle 0027h]
- Number of Strings 1
- [System Configuration Options (Type 12) - Length 5 - Handle 0028h]
- [Memory Device (Type 17) - Length 34 - Handle 0040h]
- Physical Memory Array Handle 0007h
- Total Width 64 bits
- Data Width 64 bits
- Size 4096MB
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM0
- Bank Locator BANK 0
- Memory Type 18h - Specification Reserved
- Type Detail 0080h - Synchronous
- Speed 1333MHz
- Manufacturer Hynix/Hyundai
- Part Number HMT351U6CFR8C-H9
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0041h]
- Starting Address 00000000h
- Ending Address 003fffffh
- Memory Device Handle 0040h
- Mem Array Mapped Adr Handle 0047h
- Interleave Position 01
- Interleave Data Depth 02
- [Memory Device (Type 17) - Length 34 - Handle 0042h]
- Physical Memory Array Handle 0007h
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 09h - DIMM
- Device Locator ChannelA-DIMM1
- Bank Locator BANK 1
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Processor Information (Type 4) - Length 42 - Handle 0043h]
- Socket Designation Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
- Processor Type Central Processor
- Processor Family c6h - Specification Reserved
- Processor Manufacturer Intel
- Processor ID a7060200fffbebbf
- Processor Version Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
- Processor Voltage 8bh - 1.1V
- External Clock 100MHz
- Max Speed 7000MHz
- Current Speed 3300MHz
- Status Enabled Populated
- Processor Upgrade Other
- L1 Cache Handle 0004h
- L2 Cache Handle 0005h
- L3 Cache Handle 0006h
- [Memory Device (Type 17) - Length 34 - Handle 0044h]
- Physical Memory Array Handle 0007h
- Total Width 64 bits
- Data Width 64 bits
- Size 4096MB
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM0
- Bank Locator BANK 2
- Memory Type 18h - Specification Reserved
- Type Detail 0080h - Synchronous
- Speed 1333MHz
- Manufacturer 8325
- Part Number FLFF65F-C8KL9
- [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0045h]
- Starting Address 00400000h
- Ending Address 007fffffh
- Memory Device Handle 0044h
- Mem Array Mapped Adr Handle 0047h
- Interleave Position 02
- Interleave Data Depth 02
- [Memory Device (Type 17) - Length 34 - Handle 0046h]
- Physical Memory Array Handle 0007h
- Total Width 0 bits
- Data Width 0 bits
- Form Factor 09h - DIMM
- Device Locator ChannelB-DIMM1
- Bank Locator BANK 3
- Memory Type 02h - Unknown
- Type Detail 0000h -
- Speed 0MHz
- [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0047h]
- Starting Address 00000000h
- Ending Address 007fffffh
- Memory Array Handle 0007h
- Partition Width 04
- ========================== Dump #6: Extra #1 ===========================
- 1: kd> !verifier
- Verify Flags Level 0x00000000
- STANDARD FLAGS:
- [X] (0x00000000) Automatic Checks
- [ ] (0x00000001) Special pool
- [ ] (0x00000002) Force IRQL checking
- [ ] (0x00000008) Pool tracking
- [ ] (0x00000010) I/O verification
- [ ] (0x00000020) Deadlock detection
- [ ] (0x00000080) DMA checking
- [ ] (0x00000100) Security checks
- [ ] (0x00000800) Miscellaneous checks
- [ ] (0x00020000) DDI compliance checking
- ADDITIONAL FLAGS:
- [ ] (0x00000004) Randomized low resources simulation
- [ ] (0x00000200) Force pending I/O requests
- [ ] (0x00000400) IRP logging
- [ ] (0x00002000) Invariant MDL checking for stack
- [ ] (0x00004000) Invariant MDL checking for driver
- [ ] (0x00008000) Power framework delay fuzzing
- [ ] (0x00010000) Port/miniport interface checking
- [ ] (0x00040000) Systematic low resources simulation
- [ ] (0x00080000) DDI compliance checking (additional)
- [ ] (0x00200000) NDIS/WIFI verification
- [ ] (0x00800000) Kernel synchronization delay fuzzing
- [ ] (0x01000000) VM switch verification
- [ ] (0x02000000) Code integrity checks
- [X] Indicates flag is enabled
- Summary of All Verifier Statistics
- RaiseIrqls 0x0
- AcquireSpinLocks 0x0
- Synch Executions 0x0
- Trims 0x0
- Pool Allocations Attempted 0x0
- Pool Allocations Succeeded 0x0
- Pool Allocations Succeeded SpecialPool 0x0
- Pool Allocations With NO TAG 0x0
- Pool Allocations Failed 0x0
- Current paged pool allocations 0x0 for 00000000 bytes
- Peak paged pool allocations 0x0 for 00000000 bytes
- Current nonpaged pool allocations 0x0 for 00000000 bytes
- Peak nonpaged pool allocations 0x0 for 00000000 bytes
- ========================== Dump #6: Extra #2 ===========================
- 1: kd> !thread
- THREAD ffffdc03a7df5040 Cid 0004.1850 Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor 1
- Not impersonating
- GetUlongFromAddress: unable to read from fffff80227e1143c
- Owning Process ffffdc039c496040 Image: System
- Attached Process N/A Image: N/A
- fffff78000000000: Unable to get shared data
- Wait Start TickCount 2310744
- Context Switch Count 14114 IdealProcessor: 1
- ReadMemory error: Cannot get nt!KeMaximumIncrement value.
- UserTime 00:00:00.000
- KernelTime 00:00:00.000
- Win32 Start Address nt!ExpWorkerThread (0xfffff80227433e40)
- Stack Init ffffda8a37616c90 Current ffffda8a37616820
- Base ffffda8a37617000 Limit ffffda8a37611000 Call 0000000000000000
- Priority 12 BasePriority 12 PriorityDecrement 0 IoPriority 2 PagePriority 5
- Child-SP RetAddr : Args to Child : Call Site
- ffffda8a`376166b8 fffff802`275efa29 : 00000000`0000000a 00000000`001ddbb5 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
- ffffda8a`376166c0 fffff802`275ebd29 : ffff9d01`ae1b0140 ffffdc03`a7df5040 ffff9d01`ae1a5180 fffff802`275e4d72 : nt!KiBugCheckDispatch+0x69
- ffffda8a`37616800 fffff802`274acd4d : 00000000`00000000 ffff9780`00000001 00000000`00000000 fffff802`27e4e680 : nt!KiPageFault+0x469 (TrapFrame @ ffffda8a`37616800)
- ffffda8a`37616990 fffff802`2775877c : 00000000`00064e1e 00000000`00000000 00000000`0000001e 00000000`00000001 : nt!MiInsertPageInFreeOrZeroedList+0x2dd
- ffffda8a`37616a90 fffff802`277588b3 : fffff802`27e50b40 00000000`00000000 fffff802`00000000 00000000`00000229 : nt!MiPruneStandbyPages+0x380
- ffffda8a`37616b20 fffff802`27433f45 : ffffdc03`a7df5040 fffff802`27758820 ffffdc03`9c557a60 fffff802`27e523e0 : nt!MiRebalanceZeroFreeLists+0x93
- ffffda8a`37616b70 fffff802`27546735 : ffffdc03`a7df5040 00000000`00000080 ffffdc03`9c496040 00000000`00000001 : nt!ExpWorkerThread+0x105
- ffffda8a`37616c10 fffff802`275e51b8 : ffff9d01`ae2f6180 ffffdc03`a7df5040 fffff802`275466e0 00000000`00000000 : nt!PspSystemThreadStartup+0x55
- ffffda8a`37616c60 00000000`00000000 : ffffda8a`37617000 ffffda8a`37611000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement