Advertisement
Guest User

Untitled

a guest
Aug 11th, 2020
89
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 185.22 KB | None | 0 0
  1. ========================== AUTO DUMP ANALYZER ==========================
  2. Auto Dump Analyzer
  3. Version: 0.91
  4. Time to analyze file(s): 00 hours and 04 minutes and 42 seconds
  5.  
  6. ================================ SYSTEM ================================
  7. MANUFACTURER: Gigabyte Tecohnology Co., Ltd.
  8. PRODUCT_NAME: H61M-DS2
  9.  
  10. ================================= BIOS =================================
  11. VENDOR: American Megatrends Inc.
  12. VERSION: F6
  13. DATE: 02/16/2012
  14.  
  15. ============================= MOTHERBOARD ==============================
  16. MANUFACTURER: Gigabyte Tecohnology Co., Ltd.
  17. PRODUCT: H61M-DS2
  18. VERSION: x.x
  19.  
  20. ================================= RAM ==================================
  21. Size Speed Manufacturer Part No.
  22. -------------- -------------- ------------------- ----------------------
  23. 4096MB 1333MHz Hynix/Hyundai HMT351U6CFR8C-H9
  24. 0MHz
  25. 4096MB 1333MHz 8325 FLFF65F-C8KL9
  26. 0MHz
  27.  
  28. ================================= CPU ==================================
  29. Processor Version: Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
  30. COUNT: 4
  31. MHZ: 3293
  32. VENDOR: GenuineIntel
  33. FAMILY: 6
  34. MODEL: 2a
  35. STEPPING: 7
  36. MICROCODE: 6,2a,7,0 (F,M,S,R) SIG: 2F'00000000 (cache) 2F'00000000 (init)
  37.  
  38. ================================== OS ==================================
  39. Product: WinNt, suite: TerminalServer SingleUserTS
  40. Built by: 19041.1.amd64fre.vb_release.191206-1406
  41. BUILD_VERSION: 10.0.19041.388 (WinBuild.160101.0800)
  42. BUILD: 19041
  43. SERVICEPACK: 388
  44. PLATFORM_TYPE: x64
  45. NAME: Windows 10
  46. EDITION: Windows 10 WinNt TerminalServer SingleUserTS
  47. BUILD_TIMESTAMP: unknown_date
  48. BUILDDATESTAMP: 160101.0800
  49. BUILDLAB: WinBuild
  50. BUILDOSVER: 10.0.19041.388
  51.  
  52. =============================== DEBUGGER ===============================
  53. Microsoft (R) Windows Debugger Version 10.0.14321.1024 AMD64
  54. Copyright (c) Microsoft Corporation. All rights reserved.
  55.  
  56. =============================== COMMENTS ===============================
  57. * Information gathered from different dump files may be different. If
  58. Windows updates between two dump files, two or more OS versions may
  59. be shown above.
  60. * If the user updates the BIOS between dump files, two or more versions
  61. and dates may be shown above.
  62. * More RAM information can be found below in a full BIOS section.
  63.  
  64. ========================================================================
  65. ======================= Dump #1: ANALYZE VERBOSE =======================
  66. ====================== File: 081120-35937-01.dmp =======================
  67. ========================================================================
  68.  
  69. Mini Kernel Dump File: Only registers and stack trace are available
  70. Windows 10 Kernel Version 19041 MP (4 procs) Free x64
  71. Kernel base = 0xfffff807`4d000000 PsLoadedModuleList = 0xfffff807`4dc2a310
  72. Debug session time: Mon Aug 10 19:39:19.376 2020 (UTC - 4:00)
  73. System Uptime: 0 days 1:46:29.092
  74.  
  75. BugCheck 1A, {403, fffff880e25e7e68, 80000000152cf867, ffff9480e25e7e68}
  76. *** WARNING: Unable to verify timestamp for win32k.sys
  77. *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
  78. Probably caused by : memory_corruption
  79. Followup: memory_corruption
  80.  
  81. MEMORY_MANAGEMENT (1a)
  82. # Any other values for parameter 1 must be individually examined.
  83.  
  84. Arguments:
  85. Arg1: 0000000000000403, The subtype of the bugcheck.
  86. Arg2: fffff880e25e7e68
  87. Arg3: 80000000152cf867
  88. Arg4: ffff9480e25e7e68
  89.  
  90. Debugging Details:
  91. DUMP_CLASS: 1
  92. DUMP_QUALIFIER: 400
  93. DUMP_TYPE: 2
  94. BUGCHECK_STR: 0x1a_403
  95. CUSTOMER_CRASH_COUNT: 1
  96. DEFAULT_BUCKET_ID: CODE_CORRUPTION
  97.  
  98. PROCESS_NAME: CefSharp.BrowserSubprocess.exe
  99.  
  100. CURRENT_IRQL: 2
  101. LAST_CONTROL_TRANSFER: from fffff8074d4464a4 to fffff8074d3ddb60
  102. STACK_TEXT:
  103. fffffb04`4b8530e8 fffff807`4d4464a4 : 00000000`0000001a 00000000`00000403 fffff880`e25e7e68 80000000`152cf867 : nt!KeBugCheckEx
  104. fffffb04`4b8530f0 fffff807`4d2c1588 : 00000000`00000000 fffffb04`4b8534a0 fffffb04`4b8534a0 fffff880`e25e7e78 : nt!MiDeletePteRun+0x19b6a4
  105. fffffb04`4b853320 fffff807`4d2c219b : fffffb04`4b853450 ffffd688`080e1700 fffff880`e25e7e78 fffffb04`4b853450 : nt!MiDeleteVaTail+0x78
  106. fffffb04`4b853350 fffff807`4d2a789f : 00000000`00000000 00000000`00000060 ffffd688`080e17c0 000001c4`bcfcffff : nt!MiDeletePagablePteRange+0x33b
  107. fffffb04`4b8537d0 fffff807`4d29d9bb : ffffd688`080e1080 00000000`00000000 ffffd688`00000000 fffff807`00000001 : nt!MiDeleteVad+0x41f
  108. fffffb04`4b853900 fffff807`4d665fdc : fffffb04`00000000 00000000`00000000 fffffb04`4b853a60 00000000`00008000 : nt!MiFreeVadRange+0xa3
  109. fffffb04`4b853960 fffff807`4d665c05 : 00000000`00000000 00000042`7cbfab18 ffff9852`0734b8bb 00007ffa`00000004 : nt!MmFreeVirtualMemory+0x39c
  110. fffffb04`4b853aa0 fffff807`4d3ef478 : ffffd688`04a27080 000001c4`00000001 00007ffb`22534600 fffffb04`4b853b80 : nt!NtFreeVirtualMemory+0x95
  111. fffffb04`4b853b00 00007ffb`2f90b154 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
  112. 00000042`7cbfb118 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffb`2f90b154
  113. STACK_COMMAND: kb
  114. CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
  115. fffff8074d2c166a-fffff8074d2c166e 5 bytes - nt!MiDeleteVaTail+15a
  116. [ d0 be 7d fb f6:10 3f 7e fc f8 ]
  117. fffff8074d2c167d-fffff8074d2c1681 5 bytes - nt!MiDeleteVaTail+16d (+0x13)
  118. [ df be 7d fb f6:1f 3f 7e fc f8 ]
  119. fffff8074d2c2368-fffff8074d2c236c 5 bytes - nt!MiDeleteVa+28 (+0xceb)
  120. [ d0 be 7d fb f6:10 3f 7e fc f8 ]
  121. fffff8074d2c237b-fffff8074d2c237f 5 bytes - nt!MiDeleteVa+3b (+0x13)
  122. [ d7 be 7d fb f6:17 3f 7e fc f8 ]
  123. fffff8074d2c23e4 - nt!MiDeleteVa+a4 (+0x69)
  124. [ f6:f8 ]
  125. fffff8074d384f3e-fffff8074d384f41 4 bytes - nt!MiFreeUltraMapping+32 (+0xc2b5a)
  126. [ a0 7d fb f6:20 7e fc f8 ]
  127. 25 errors : !nt (fffff8074d2c166a-fffff8074d384f41)
  128. MODULE_NAME: memory_corruption
  129.  
  130. IMAGE_NAME: memory_corruption
  131.  
  132. FOLLOWUP_NAME: memory_corruption
  133. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  134. MEMORY_CORRUPTOR: LARGE
  135. FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
  136. BUCKET_ID: MEMORY_CORRUPTION_LARGE
  137. PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
  138. TARGET_TIME: 2020-08-10T23:39:19.000Z
  139. SUITE_MASK: 272
  140. PRODUCT_TYPE: 1
  141. USER_LCID: 0
  142. FAILURE_ID_HASH_STRING: km:memory_corruption_large
  143. FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
  144. Followup: memory_corruption
  145.  
  146. ====================== Dump #1: 3RD PARTY DRIVERS ======================
  147.  
  148. Jul 21 2014 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
  149. Sep 04 2014 - nvvad64v.sys - Nvidia Virtual Audio driver http://www.nvidia.com/
  150. Sep 06 2014 - NvStreamKms.sys - Nvidia Streaming Kernel Service http://www.nvidia.com/
  151. Mar 31 2015 - HWiNFO64A.SYS - HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
  152. Jul 07 2015 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
  153. May 26 2020 - rt640x64.sys - Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
  154. Jul 05 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
  155.  
  156. ================== Dump #1: 3RD PARTY DRIVERS (FULL) ===================
  157.  
  158. Image path: \SystemRoot\system32\drivers\nvhda64v.sys
  159. Image name: nvhda64v.sys
  160. Search : https://www.google.com/search?q=nvhda64v.sys
  161. ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
  162. Timestamp : Mon Jul 21 2014
  163.  
  164. Image path: \SystemRoot\system32\drivers\nvvad64v.sys
  165. Image name: nvvad64v.sys
  166. Search : https://www.google.com/search?q=nvvad64v.sys
  167. ADA Info : Nvidia Virtual Audio driver http://www.nvidia.com/
  168. Timestamp : Thu Sep 4 2014
  169.  
  170. Image path: \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
  171. Image name: NvStreamKms.sys
  172. Search : https://www.google.com/search?q=NvStreamKms.sys
  173. ADA Info : Nvidia Streaming Kernel Service http://www.nvidia.com/
  174. Timestamp : Sat Sep 6 2014
  175.  
  176. Image path: \??\C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS
  177. Image name: HWiNFO64A.SYS
  178. Search : https://www.google.com/search?q=HWiNFO64A.SYS
  179. ADA Info : HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
  180. Timestamp : Tue Mar 31 2015
  181.  
  182. Image path: \SystemRoot\System32\drivers\TeeDriverW8x64.sys
  183. Image name: TeeDriverW8x64.sys
  184. Search : https://www.google.com/search?q=TeeDriverW8x64.sys
  185. ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
  186. Timestamp : Tue Jul 7 2015
  187.  
  188. Image path: \SystemRoot\System32\drivers\rt640x64.sys
  189. Image name: rt640x64.sys
  190. Search : https://www.google.com/search?q=rt640x64.sys
  191. ADA Info : Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
  192. Timestamp : Tue May 26 2020
  193.  
  194. Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_e92a0ac2e05fb2ca\nvlddmkm.sys
  195. Image name: nvlddmkm.sys
  196. Search : https://www.google.com/search?q=nvlddmkm.sys
  197. ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
  198. Timestamp : Sun Jul 5 2020
  199.  
  200. ====================== Dump #1: MICROSOFT DRIVERS ======================
  201.  
  202. ACPI.sys ACPI Driver for NT (Microsoft)
  203. acpiex.sys ACPIEx Driver (Microsoft)
  204. afd.sys Ancillary Function Driver for WinSock (Microsoft)
  205. afunix.sys AF_UNIX Socket Provider driver (Microsoft)
  206. AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
  207. ahcache.sys Application Compatibility Cache (Microsoft)
  208. atapi.sys ATAPI IDE MiniPort driver (Microsoft)
  209. ataport.SYS ATAPI Driver Extension (Microsoft)
  210. bam.sys BAM Kernal driver (Microsoft)
  211. BasicDisplay.sys Basic Display driver (Microsoft)
  212. BasicRender.sys Basic Render driver (Microsoft)
  213. Beep.SYS BEEP driver (Microsoft)
  214. bindflt.sys Windows Bind Filter driver (Microsoft)
  215. BOOTVID.dll VGA Boot Driver (Microsoft)
  216. bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
  217. cdd.dll Canonical Display Driver (Microsoft)
  218. cdfs.sys CD-ROM File System Driver (Microsoft)
  219. cdrom.sys SCSI CD-ROM Driver (Microsoft)
  220. CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
  221. CI.dll Code Integrity Module (Microsoft)
  222. CimFS.SYS Consumer IR Class Driver for eHome (Microsoft)
  223. CLASSPNP.SYS SCSI Class System Dll (Microsoft)
  224. cldflt.sys Cloud Files Mini Filter driver (Microsoft)
  225. CLFS.SYS Common Log File System Driver (Microsoft)
  226. clipsp.sys CLIP Service (Microsoft)
  227. cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
  228. cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
  229. CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
  230. condrv.sys Console Driver (Microsoft)
  231. crashdmp.sys Crash Dump driver (Microsoft)
  232. csc.sys Windows Client Side Caching driver (Microsoft)
  233. dfsc.sys DFS Namespace Client Driver (Microsoft)
  234. disk.sys PnP Disk Driver (Microsoft)
  235. drmk.sys Digital Rights Management (DRM) driver (Microsoft)
  236. dump_atapi.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  237. dump_dumpata.sys ATAPI Dump Driver
  238. dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  239. dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
  240. dxgmms2.sys DirectX Graphics MMS
  241. EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
  242. fastfat.SYS Fast FAT File System Driver (Microsoft)
  243. filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
  244. fileinfo.sys FileInfo Filter Driver (Microsoft)
  245. FLTMGR.SYS Filesystem Filter Manager (Microsoft)
  246. Fs_Rec.sys File System Recognizer Driver (Microsoft)
  247. fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
  248. fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
  249. gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
  250. hal.dll Hardware Abstraction Layer DLL (Microsoft)
  251. HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
  252. HdAudio.sys High Definition Audio Function driver (Microsoft)
  253. HIDCLASS.SYS Hid Class Library (Microsoft)
  254. HIDPARSE.SYS Hid Parsing Library (Microsoft)
  255. hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
  256. HTTP.sys HTTP Protocol Stack (Microsoft)
  257. intelpep.sys Intel Power Engine Plugin (Microsoft)
  258. intelppm.sys Processor Device Driver (Microsoft)
  259. IntelTA.sys Intel Telemetry Driver
  260. iorate.sys I/O rate control Filter (Microsoft)
  261. kbdclass.sys Keyboard Class Driver (Microsoft)
  262. kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
  263. kd.dll Local Kernal Debugger (Microsoft)
  264. kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
  265. ks.sys Kernal CSA Library (Microsoft)
  266. ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
  267. ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
  268. ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
  269. lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
  270. luafv.sys LUA File Virtualization Filter Driver (Microsoft)
  271. mcupdate_GenuineIntel.dll Intel Microcode Update Library (Microsoft)
  272. mmcss.sys MMCSS Driver (Microsoft)
  273. monitor.sys Monitor Driver (Microsoft)
  274. mouclass.sys Mouse Class Driver (Microsoft)
  275. mouhid.sys HID Mouse Filter Driver (Microsoft)
  276. mountmgr.sys Mount Point Manager (Microsoft)
  277. MpKslDrv.sys Microsoft Anti-malware Protection driver
  278. mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
  279. mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
  280. mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
  281. Msfs.SYS Mailslot driver (Microsoft)
  282. msisadrv.sys ISA Driver (Microsoft)
  283. mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
  284. msquic.sys Windows QUIC Driver
  285. msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
  286. mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
  287. mssmbios.sys System Management BIOS driver (Microsoft)
  288. mup.sys Multiple UNC Provider driver (Microsoft)
  289. ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
  290. ndiscap.sys Microsoft NDIS Packet Capture Filter Driver
  291. ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
  292. NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
  293. ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
  294. NDProxy.sys NDIS Proxy driver (Microsoft)
  295. Ndu.sys Network Data Usage Monitoring driver (Microsoft)
  296. netbios.sys NetBIOS Interface driver (Microsoft)
  297. netbt.sys MBT Transport driver (Microsoft)
  298. NETIO.SYS Network I/O Subsystem (Microsoft)
  299. Npfs.SYS NPFS driver (Microsoft)
  300. npsvctrig.sys Named pipe service triggers (Microsoft)
  301. nsiproxy.sys NSI Proxy driver (Microsoft)
  302. Ntfs.sys NT File System Driver (Microsoft)
  303. ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
  304. ntosext.sys NTOS Extension Host driver (Microsoft)
  305. Null.SYS NULL Driver (Microsoft)
  306. pacer.sys QoS Packet Scheduler (Microsoft)
  307. parport.sys Parallel Port Driver (Microsoft)
  308. partmgr.sys Partition driver (Microsoft)
  309. pci.sys NT Plug and Play PCI Enumerator (Microsoft)
  310. pciide.sys Generic PCI IDE Bus Driver (Microsoft)
  311. PCIIDEX.SYS PCI IDE Bus driver file (Microsoft)
  312. pcw.sys Performance Counter Driver (Microsoft)
  313. pdc.sys Power Dependency Coordinator Driver (Microsoft)
  314. peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
  315. portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
  316. PSHED.dll Platform Specific Hardware Error driver (Microsoft)
  317. rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
  318. raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
  319. raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
  320. rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
  321. rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
  322. rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
  323. rdyboost.sys ReadyBoost Driver (Microsoft)
  324. rspndr.sys Link-Layer Topology Responder driver (Microsoft)
  325. serenum.sys Serial Port Enumerator (Microsoft)
  326. serial.sys Serial Device Driver
  327. SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
  328. SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
  329. spaceport.sys Storage Spaces driver (Microsoft)
  330. srv2.sys Smb 2.0 Server driver (Microsoft)
  331. srvnet.sys Server Network driver (Microsoft)
  332. storqosflt.sys Storage QoS Filter driver (Microsoft)
  333. swenum.sys Plug and Play Software Device Enumerator (Microsoft)
  334. tbs.sys Export driver for kernel mode TPM API (Microsoft)
  335. tcpip.sys TCP/IP Protocol driver (Microsoft)
  336. tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
  337. TDI.SYS TDI Wrapper driver (Microsoft)
  338. tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
  339. tm.sys Kernel Transaction Manager driver (Microsoft)
  340. umbus.sys User-Mode Bus Enumerator (Microsoft)
  341. usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
  342. USBD.SYS Universal Serial Bus Driver (Microsoft)
  343. usbehci.sys EHCI eUSB Miniport Driver (Microsoft)
  344. usbhub.sys Default Hub Driver for USB (Microsoft)
  345. USBPORT.SYS USB 1.1 & 2.0 Port Driver (Microsoft)
  346. vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
  347. Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
  348. volmgr.sys Volume Manager Driver (Microsoft)
  349. volmgrx.sys Volume Manager Extension Driver (Microsoft)
  350. volsnap.sys Volume Shadow Copy driver (Microsoft)
  351. volume.sys Volume driver (Microsoft)
  352. vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
  353. wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
  354. watchdog.sys Watchdog driver (Microsoft)
  355. wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
  356. Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
  357. WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
  358. WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
  359. WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
  360. werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
  361. wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
  362. win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
  363. win32kbase.sys Base Win32k Kernel Driver (Microsoft)
  364. win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
  365. WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
  366. WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
  367. winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
  368. WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
  369. Wof.sys Windows Overlay Filter (Microsoft)
  370. WppRecorder.sys WPP Trace Recorder (Microsoft)
  371.  
  372. ====================== Dump #1: UNLOADED MODULES =======================
  373.  
  374. fffff807`57ab0000 fffff807`57ac0000 dump_ataport
  375. fffff807`57ad0000 fffff807`57ade000 dump_atapi.s
  376. fffff807`57b00000 fffff807`57b1e000 dump_dumpfve
  377. fffff807`57c30000 fffff807`57c4c000 dam.sys
  378. fffff807`50650000 fffff807`50662000 WdBoot.sys
  379. fffff807`51650000 fffff807`51660000 hwpolicy.sys
  380.  
  381. ====================== Dump #1: BIOS INFORMATION =======================
  382.  
  383. [SMBIOS Data Tables v2.7]
  384. [DMI Version - 0]
  385. [2.0 Calling Convention - No]
  386. [Table Size - 3016 bytes]
  387. [BIOS Information (Type 0) - Length 24 - Handle 0000h]
  388. Vendor American Megatrends Inc.
  389. BIOS Version F6
  390. BIOS Starting Address Segment f000
  391. BIOS Release Date 02/16/2012
  392. BIOS ROM Size 280000
  393. BIOS Characteristics
  394. 07: - PCI Supported
  395. 11: - Upgradeable FLASH BIOS
  396. 12: - BIOS Shadowing Supported
  397. 15: - CD-Boot Supported
  398. 16: - Selectable Boot Supported
  399. 17: - BIOS ROM Socketed
  400. 19: - EDD Supported
  401. 23: - 1.2MB Floppy Supported
  402. 24: - 720KB Floppy Supported
  403. 25: - 2.88MB Floppy Supported
  404. 26: - Print Screen Device Supported
  405. 27: - Keyboard Services Supported
  406. 28: - Serial Services Supported
  407. 29: - Printer Services Supported
  408. 32: - BIOS Vendor Reserved
  409. BIOS Characteristic Extensions
  410. 00: - ACPI Supported
  411. 01: - USB Legacy Supported
  412. 08: - BIOS Boot Specification Supported
  413. 10: - Specification Reserved
  414. 11: - Specification Reserved
  415. BIOS Major Revision 4
  416. BIOS Minor Revision 6
  417. EC Firmware Major Revision 255
  418. EC Firmware Minor Revision 255
  419. [System Information (Type 1) - Length 27 - Handle 0001h]
  420. Manufacturer Gigabyte Tecohnology Co., Ltd.
  421. Product Name H61M-DS2
  422. UUID 00000000-0000-0000-0000-000000000000
  423. Wakeup Type Power Switch
  424. [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
  425. Manufacturer Gigabyte Tecohnology Co., Ltd.
  426. Product H61M-DS2
  427. Version x.x
  428. Feature Flags 09h
  429. -971589920: - -971589872: - «¯þø
  430. Chassis Handle 0003h
  431. Board Type 0ah - Processor/Memory Module
  432. Number of Child Handles 0
  433. [System Enclosure (Type 3) - Length 22 - Handle 0003h]
  434. Manufacturer Gigabyte Tecohnology Co., Ltd.
  435. Chassis Type Desktop
  436. Bootup State Safe
  437. Power Supply State Safe
  438. Thermal State Safe
  439. Security Status None
  440. OEM Defined 0
  441. Height 0U
  442. Number of Power Cords 1
  443. Number of Contained Elements 0
  444. Contained Element Size 0
  445. [Cache Information (Type 7) - Length 19 - Handle 0004h]
  446. Cache Configuration 0181h - WB Enabled Int NonSocketed L2
  447. Maximum Cache Size 0020h - 32K
  448. Installed Size 0020h - 32K
  449. Supported SRAM Type 0040h - Asynchronous
  450. Current SRAM Type 0040h - Asynchronous
  451. Cache Speed 0ns
  452. Error Correction Type Multi-Bit ECC
  453. System Cache Type Other
  454. Associativity 16-way Set-Associative
  455. [Cache Information (Type 7) - Length 19 - Handle 0005h]
  456. Cache Configuration 0182h - WB Enabled Int NonSocketed L3
  457. Maximum Cache Size 0100h - 256K
  458. Installed Size 0100h - 256K
  459. Supported SRAM Type 0040h - Asynchronous
  460. Current SRAM Type 0040h - Asynchronous
  461. Cache Speed 0ns
  462. Error Correction Type Multi-Bit ECC
  463. System Cache Type Instruction
  464. Associativity 16-way Set-Associative
  465. [Cache Information (Type 7) - Length 19 - Handle 0006h]
  466. Cache Configuration 0183h - WB Enabled Int NonSocketed L4
  467. Maximum Cache Size 0c00h - 3072K
  468. Installed Size 0c00h - 3072K
  469. Supported SRAM Type 0040h - Asynchronous
  470. Current SRAM Type 0040h - Asynchronous
  471. Cache Speed 0ns
  472. Error Correction Type Multi-Bit ECC
  473. System Cache Type Instruction
  474. Associativity Specification Reserved
  475. [Physical Memory Array (Type 16) - Length 23 - Handle 0007h]
  476. Location 03h - SystemBoard/Motherboard
  477. Use 03h - System Memory
  478. Memory Error Correction 03h - None
  479. Maximum Capacity 33554432KB
  480. Number of Memory Devices 4
  481. [Onboard Devices Information (Type 10) - Length 6 - Handle 0026h]
  482. Number of Devices 1
  483. 01: Type Video [enabled]
  484. [OEM Strings (Type 11) - Length 5 - Handle 0027h]
  485. Number of Strings 1
  486. [System Configuration Options (Type 12) - Length 5 - Handle 0028h]
  487. [Memory Device (Type 17) - Length 34 - Handle 0040h]
  488. Physical Memory Array Handle 0007h
  489. Total Width 64 bits
  490. Data Width 64 bits
  491. Size 4096MB
  492. Form Factor 09h - DIMM
  493. Device Locator ChannelA-DIMM0
  494. Bank Locator BANK 0
  495. Memory Type 18h - Specification Reserved
  496. Type Detail 0080h - Synchronous
  497. Speed 1333MHz
  498. Manufacturer Hynix/Hyundai
  499. Part Number HMT351U6CFR8C-H9
  500. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0041h]
  501. Starting Address 00000000h
  502. Ending Address 003fffffh
  503. Memory Device Handle 0040h
  504. Mem Array Mapped Adr Handle 0047h
  505. Interleave Position 01
  506. Interleave Data Depth 02
  507. [Memory Device (Type 17) - Length 34 - Handle 0042h]
  508. Physical Memory Array Handle 0007h
  509. Total Width 0 bits
  510. Data Width 0 bits
  511. Form Factor 09h - DIMM
  512. Device Locator ChannelA-DIMM1
  513. Bank Locator BANK 1
  514. Memory Type 02h - Unknown
  515. Type Detail 0000h -
  516. Speed 0MHz
  517. [Processor Information (Type 4) - Length 42 - Handle 0043h]
  518. Socket Designation Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
  519. Processor Type Central Processor
  520. Processor Family c6h - Specification Reserved
  521. Processor Manufacturer Intel
  522. Processor ID a7060200fffbebbf
  523. Processor Version Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
  524. Processor Voltage 8bh - 1.1V
  525. External Clock 100MHz
  526. Max Speed 7000MHz
  527. Current Speed 3300MHz
  528. Status Enabled Populated
  529. Processor Upgrade Other
  530. L1 Cache Handle 0004h
  531. L2 Cache Handle 0005h
  532. L3 Cache Handle 0006h
  533. [Memory Device (Type 17) - Length 34 - Handle 0044h]
  534. Physical Memory Array Handle 0007h
  535. Total Width 64 bits
  536. Data Width 64 bits
  537. Size 4096MB
  538. Form Factor 09h - DIMM
  539. Device Locator ChannelB-DIMM0
  540. Bank Locator BANK 2
  541. Memory Type 18h - Specification Reserved
  542. Type Detail 0080h - Synchronous
  543. Speed 1333MHz
  544. Manufacturer 8325
  545. Part Number FLFF65F-C8KL9
  546. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0045h]
  547. Starting Address 00400000h
  548. Ending Address 007fffffh
  549. Memory Device Handle 0044h
  550. Mem Array Mapped Adr Handle 0047h
  551. Interleave Position 02
  552. Interleave Data Depth 02
  553. [Memory Device (Type 17) - Length 34 - Handle 0046h]
  554. Physical Memory Array Handle 0007h
  555. Total Width 0 bits
  556. Data Width 0 bits
  557. Form Factor 09h - DIMM
  558. Device Locator ChannelB-DIMM1
  559. Bank Locator BANK 3
  560. Memory Type 02h - Unknown
  561. Type Detail 0000h -
  562. Speed 0MHz
  563. [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0047h]
  564. Starting Address 00000000h
  565. Ending Address 007fffffh
  566. Memory Array Handle 0007h
  567. Partition Width 04
  568.  
  569. ========================== Dump #1: Extra #1 ===========================
  570.  
  571. 0: kd> !verifier
  572. Verify Flags Level 0x00000000
  573. STANDARD FLAGS:
  574. [X] (0x00000000) Automatic Checks
  575. [ ] (0x00000001) Special pool
  576. [ ] (0x00000002) Force IRQL checking
  577. [ ] (0x00000008) Pool tracking
  578. [ ] (0x00000010) I/O verification
  579. [ ] (0x00000020) Deadlock detection
  580. [ ] (0x00000080) DMA checking
  581. [ ] (0x00000100) Security checks
  582. [ ] (0x00000800) Miscellaneous checks
  583. [ ] (0x00020000) DDI compliance checking
  584. ADDITIONAL FLAGS:
  585. [ ] (0x00000004) Randomized low resources simulation
  586. [ ] (0x00000200) Force pending I/O requests
  587. [ ] (0x00000400) IRP logging
  588. [ ] (0x00002000) Invariant MDL checking for stack
  589. [ ] (0x00004000) Invariant MDL checking for driver
  590. [ ] (0x00008000) Power framework delay fuzzing
  591. [ ] (0x00010000) Port/miniport interface checking
  592. [ ] (0x00040000) Systematic low resources simulation
  593. [ ] (0x00080000) DDI compliance checking (additional)
  594. [ ] (0x00200000) NDIS/WIFI verification
  595. [ ] (0x00800000) Kernel synchronization delay fuzzing
  596. [ ] (0x01000000) VM switch verification
  597. [ ] (0x02000000) Code integrity checks
  598. [X] Indicates flag is enabled
  599. Summary of All Verifier Statistics
  600. RaiseIrqls 0x0
  601. AcquireSpinLocks 0x0
  602. Synch Executions 0x0
  603. Trims 0x0
  604. Pool Allocations Attempted 0x0
  605. Pool Allocations Succeeded 0x0
  606. Pool Allocations Succeeded SpecialPool 0x0
  607. Pool Allocations With NO TAG 0x0
  608. Pool Allocations Failed 0x0
  609. Current paged pool allocations 0x0 for 00000000 bytes
  610. Peak paged pool allocations 0x0 for 00000000 bytes
  611. Current nonpaged pool allocations 0x0 for 00000000 bytes
  612. Peak nonpaged pool allocations 0x0 for 00000000 bytes
  613.  
  614. ========================== Dump #1: Extra #2 ===========================
  615.  
  616. 0: kd> !thread
  617. THREAD ffffd68804a27080 Cid 12d0.2888 Teb: 000000427c783000 Win32Thread: ffffd688077df060 RUNNING on processor 0
  618. Not impersonating
  619. GetUlongFromAddress: unable to read from fffff8074dc1143c
  620. Owning Process ffffd688080e1080 Image: CefSharp.BrowserSubprocess.exe
  621. Attached Process N/A Image: N/A
  622. fffff78000000000: Unable to get shared data
  623. Wait Start TickCount 408901
  624. Context Switch Count 3519 IdealProcessor: 2
  625. ReadMemory error: Cannot get nt!KeMaximumIncrement value.
  626. UserTime 00:00:00.000
  627. KernelTime 00:00:00.000
  628. Win32 Start Address 0x000001c49bea0000
  629. Stack Init fffffb044b853c90 Current fffffb044b853980
  630. Base fffffb044b854000 Limit fffffb044b84e000 Call 0000000000000000
  631. Priority 9 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5
  632. Child-SP RetAddr : Args to Child : Call Site
  633. fffffb04`4b8530e8 fffff807`4d4464a4 : 00000000`0000001a 00000000`00000403 fffff880`e25e7e68 80000000`152cf867 : nt!KeBugCheckEx
  634. fffffb04`4b8530f0 fffff807`4d2c1588 : 00000000`00000000 fffffb04`4b8534a0 fffffb04`4b8534a0 fffff880`e25e7e78 : nt!MiDeletePteRun+0x19b6a4
  635. fffffb04`4b853320 fffff807`4d2c219b : fffffb04`4b853450 ffffd688`080e1700 fffff880`e25e7e78 fffffb04`4b853450 : nt!MiDeleteVaTail+0x78
  636. fffffb04`4b853350 fffff807`4d2a789f : 00000000`00000000 00000000`00000060 ffffd688`080e17c0 000001c4`bcfcffff : nt!MiDeletePagablePteRange+0x33b
  637. fffffb04`4b8537d0 fffff807`4d29d9bb : ffffd688`080e1080 00000000`00000000 ffffd688`00000000 fffff807`00000001 : nt!MiDeleteVad+0x41f
  638. fffffb04`4b853900 fffff807`4d665fdc : fffffb04`00000000 00000000`00000000 fffffb04`4b853a60 00000000`00008000 : nt!MiFreeVadRange+0xa3
  639. fffffb04`4b853960 fffff807`4d665c05 : 00000000`00000000 00000042`7cbfab18 ffff9852`0734b8bb 00007ffa`00000004 : nt!MmFreeVirtualMemory+0x39c
  640. fffffb04`4b853aa0 fffff807`4d3ef478 : ffffd688`04a27080 000001c4`00000001 00007ffb`22534600 fffffb04`4b853b80 : nt!NtFreeVirtualMemory+0x95
  641. fffffb04`4b853b00 00007ffb`2f90b154 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28 (TrapFrame @ fffffb04`4b853b00)
  642. 00000042`7cbfb118 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffb`2f90b154
  643.  
  644.  
  645. ========================================================================
  646. ======================= Dump #2: ANALYZE VERBOSE =======================
  647. ====================== File: 081120-30171-01.dmp =======================
  648. ========================================================================
  649.  
  650. Mini Kernel Dump File: Only registers and stack trace are available
  651. Windows 10 Kernel Version 19041 MP (4 procs) Free x64
  652. Kernel base = 0xfffff800`30a00000 PsLoadedModuleList = 0xfffff800`3162a310
  653. Debug session time: Tue Aug 11 07:21:23.229 2020 (UTC - 4:00)
  654. System Uptime: 0 days 0:40:49.945
  655.  
  656. BugCheck 4A, {7ffc8bd85024, 2, 0, ffff8888ccdb1b80}
  657. Probably caused by : memory_corruption
  658. Followup: memory_corruption
  659.  
  660. IRQL_GT_ZERO_AT_SYSTEM_SERVICE (4a)
  661. Returning to usermode from a system call at an IRQL > PASSIVE_LEVEL.
  662.  
  663. Arguments:
  664. Arg1: 00007ffc8bd85024, Address of system function (system call routine)
  665. Arg2: 0000000000000002, Current IRQL
  666. Arg3: 0000000000000000, 0
  667. Arg4: ffff8888ccdb1b80, 0
  668.  
  669. Debugging Details:
  670. DUMP_CLASS: 1
  671. DUMP_QUALIFIER: 400
  672. DUMP_TYPE: 2
  673.  
  674. PROCESS_NAME: opera.exe
  675.  
  676. BUGCHECK_STR: RAISED_IRQL_FAULT
  677. FAULTING_IP:
  678. +0
  679. 00007ffc`8bd85024 ?? ???
  680. CUSTOMER_CRASH_COUNT: 1
  681. DEFAULT_BUCKET_ID: CODE_CORRUPTION
  682. CURRENT_IRQL: 2
  683. LAST_CONTROL_TRANSFER: from fffff80030defa29 to fffff80030dddb60
  684. STACK_TEXT:
  685. ffff8888`ccdb19b8 fffff800`30defa29 : 00000000`0000004a 00007ffc`8bd85024 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
  686. ffff8888`ccdb19c0 fffff800`30def8f3 : 000001a2`95e42420 ffffb687`af276080 000001a2`f8262210 ffff8888`ccdb1b80 : nt!KiBugCheckDispatch+0x69
  687. ffff8888`ccdb1b00 00007ffc`8bd85024 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExitPico+0x1fe
  688. 0000009a`65dfca28 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffc`8bd85024
  689. STACK_COMMAND: kb
  690. CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
  691. fffff80030d84f3f-fffff80030d84f41 3 bytes - nt!MiFreeUltraMapping+33
  692. [ 7d fb f6:78 f1 e2 ]
  693. fffff80030def951-fffff80030def954 4 bytes - nt!KiSystemServiceExitPico+25c (+0x6aa12)
  694. [ ff d0 0f 1f:e8 8a 59 63 ]
  695. fffff80030def9ac-fffff80030def9af 4 bytes - nt!KiSystemServiceExitPico+2b7 (+0x5b)
  696. [ ff d0 0f 1f:e8 2f 59 63 ]
  697. 11 errors : !nt (fffff80030d84f3f-fffff80030def9af)
  698. MODULE_NAME: memory_corruption
  699.  
  700. IMAGE_NAME: memory_corruption
  701.  
  702. FOLLOWUP_NAME: memory_corruption
  703. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  704. MEMORY_CORRUPTOR: LARGE
  705. FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
  706. BUCKET_ID: MEMORY_CORRUPTION_LARGE
  707. PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
  708. TARGET_TIME: 2020-08-11T11:21:23.000Z
  709. SUITE_MASK: 272
  710. PRODUCT_TYPE: 1
  711. USER_LCID: 0
  712. FAILURE_ID_HASH_STRING: km:memory_corruption_large
  713. FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
  714. Followup: memory_corruption
  715.  
  716. ====================== Dump #2: 3RD PARTY DRIVERS ======================
  717.  
  718. Jul 21 2014 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
  719. Sep 04 2014 - nvvad64v.sys - Nvidia Virtual Audio driver http://www.nvidia.com/
  720. Sep 06 2014 - NvStreamKms.sys - Nvidia Streaming Kernel Service http://www.nvidia.com/
  721. Mar 31 2015 - HWiNFO64A.SYS - HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
  722. Jul 07 2015 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
  723. Dec 05 2019 - cpuz149_x64.sys - CPUID driver
  724. May 26 2020 - rt640x64.sys - Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
  725. Jul 05 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
  726.  
  727. ================== Dump #2: 3RD PARTY DRIVERS (FULL) ===================
  728.  
  729. Image path: \SystemRoot\system32\drivers\nvhda64v.sys
  730. Image name: nvhda64v.sys
  731. Search : https://www.google.com/search?q=nvhda64v.sys
  732. ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
  733. Timestamp : Mon Jul 21 2014
  734.  
  735. Image path: \SystemRoot\system32\drivers\nvvad64v.sys
  736. Image name: nvvad64v.sys
  737. Search : https://www.google.com/search?q=nvvad64v.sys
  738. ADA Info : Nvidia Virtual Audio driver http://www.nvidia.com/
  739. Timestamp : Thu Sep 4 2014
  740.  
  741. Image path: \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
  742. Image name: NvStreamKms.sys
  743. Search : https://www.google.com/search?q=NvStreamKms.sys
  744. ADA Info : Nvidia Streaming Kernel Service http://www.nvidia.com/
  745. Timestamp : Sat Sep 6 2014
  746.  
  747. Image path: \??\C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS
  748. Image name: HWiNFO64A.SYS
  749. Search : https://www.google.com/search?q=HWiNFO64A.SYS
  750. ADA Info : HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
  751. Timestamp : Tue Mar 31 2015
  752.  
  753. Image path: \SystemRoot\System32\drivers\TeeDriverW8x64.sys
  754. Image name: TeeDriverW8x64.sys
  755. Search : https://www.google.com/search?q=TeeDriverW8x64.sys
  756. ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
  757. Timestamp : Tue Jul 7 2015
  758.  
  759. Image path: \??\C:\WINDOWS\temp\cpuz149\cpuz149_x64.sys
  760. Image name: cpuz149_x64.sys
  761. Search : https://www.google.com/search?q=cpuz149_x64.sys
  762. ADA Info : CPUID driver
  763. Timestamp : Thu Dec 5 2019
  764.  
  765. Image path: \SystemRoot\System32\drivers\rt640x64.sys
  766. Image name: rt640x64.sys
  767. Search : https://www.google.com/search?q=rt640x64.sys
  768. ADA Info : Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
  769. Timestamp : Tue May 26 2020
  770.  
  771. Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_e92a0ac2e05fb2ca\nvlddmkm.sys
  772. Image name: nvlddmkm.sys
  773. Search : https://www.google.com/search?q=nvlddmkm.sys
  774. ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
  775. Timestamp : Sun Jul 5 2020
  776.  
  777. ====================== Dump #2: MICROSOFT DRIVERS ======================
  778.  
  779. ACPI.sys ACPI Driver for NT (Microsoft)
  780. acpiex.sys ACPIEx Driver (Microsoft)
  781. afd.sys Ancillary Function Driver for WinSock (Microsoft)
  782. afunix.sys AF_UNIX Socket Provider driver (Microsoft)
  783. AgileVpn.sys RAS Agil VPN Miniport Call Manager driver (Microsoft)
  784. ahcache.sys Application Compatibility Cache (Microsoft)
  785. atapi.sys ATAPI IDE MiniPort driver (Microsoft)
  786. ataport.SYS ATAPI Driver Extension (Microsoft)
  787. bam.sys BAM Kernal driver (Microsoft)
  788. BasicDisplay.sys Basic Display driver (Microsoft)
  789. BasicRender.sys Basic Render driver (Microsoft)
  790. Beep.SYS BEEP driver (Microsoft)
  791. bindflt.sys Windows Bind Filter driver (Microsoft)
  792. BOOTVID.dll VGA Boot Driver (Microsoft)
  793. bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
  794. cdd.dll Canonical Display Driver (Microsoft)
  795. cdfs.sys CD-ROM File System Driver (Microsoft)
  796. cdrom.sys SCSI CD-ROM Driver (Microsoft)
  797. CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
  798. CI.dll Code Integrity Module (Microsoft)
  799. CimFS.SYS Consumer IR Class Driver for eHome (Microsoft)
  800. CLASSPNP.SYS SCSI Class System Dll (Microsoft)
  801. cldflt.sys Cloud Files Mini Filter driver (Microsoft)
  802. CLFS.SYS Common Log File System Driver (Microsoft)
  803. clipsp.sys CLIP Service (Microsoft)
  804. cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
  805. cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
  806. CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
  807. condrv.sys Console Driver (Microsoft)
  808. crashdmp.sys Crash Dump driver (Microsoft)
  809. csc.sys Windows Client Side Caching driver (Microsoft)
  810. dfsc.sys DFS Namespace Client Driver (Microsoft)
  811. disk.sys PnP Disk Driver (Microsoft)
  812. drmk.sys Digital Rights Management (DRM) driver (Microsoft)
  813. dump_atapi.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  814. dump_dumpata.sys ATAPI Dump Driver
  815. dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  816. dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
  817. dxgmms2.sys DirectX Graphics MMS
  818. EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
  819. fastfat.SYS Fast FAT File System Driver (Microsoft)
  820. filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
  821. fileinfo.sys FileInfo Filter Driver (Microsoft)
  822. FLTMGR.SYS Filesystem Filter Manager (Microsoft)
  823. Fs_Rec.sys File System Recognizer Driver (Microsoft)
  824. fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
  825. fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
  826. gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
  827. hal.dll Hardware Abstraction Layer DLL (Microsoft)
  828. HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
  829. HdAudio.sys High Definition Audio Function driver (Microsoft)
  830. HIDCLASS.SYS Hid Class Library (Microsoft)
  831. HIDPARSE.SYS Hid Parsing Library (Microsoft)
  832. hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
  833. HTTP.sys HTTP Protocol Stack (Microsoft)
  834. intelpep.sys Intel Power Engine Plugin (Microsoft)
  835. intelppm.sys Processor Device Driver (Microsoft)
  836. IntelTA.sys Intel Telemetry Driver
  837. iorate.sys I/O rate control Filter (Microsoft)
  838. kbdclass.sys Keyboard Class Driver (Microsoft)
  839. kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
  840. kd.dll Local Kernal Debugger (Microsoft)
  841. kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
  842. ks.sys Kernal CSA Library (Microsoft)
  843. ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
  844. ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
  845. ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
  846. lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
  847. luafv.sys LUA File Virtualization Filter Driver (Microsoft)
  848. mcupdate_GenuineIntel.dll Intel Microcode Update Library (Microsoft)
  849. mmcss.sys MMCSS Driver (Microsoft)
  850. monitor.sys Monitor Driver (Microsoft)
  851. mouclass.sys Mouse Class Driver (Microsoft)
  852. mouhid.sys HID Mouse Filter Driver (Microsoft)
  853. mountmgr.sys Mount Point Manager (Microsoft)
  854. MpKslDrv.sys Microsoft Anti-malware Protection driver
  855. mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
  856. mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
  857. mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
  858. Msfs.SYS Mailslot driver (Microsoft)
  859. msisadrv.sys ISA Driver (Microsoft)
  860. mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
  861. msquic.sys Windows QUIC Driver
  862. msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
  863. mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
  864. mssmbios.sys System Management BIOS driver (Microsoft)
  865. mup.sys Multiple UNC Provider driver (Microsoft)
  866. ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
  867. ndiscap.sys Microsoft NDIS Packet Capture Filter Driver
  868. ndistapi.sys NDIS 3.0 Connection Wrapper driver (Microsoft)
  869. NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
  870. ndiswan.sys MS PPP Framing Driver (Strong Encryption) Microsoft)
  871. NDProxy.sys NDIS Proxy driver (Microsoft)
  872. Ndu.sys Network Data Usage Monitoring driver (Microsoft)
  873. netbios.sys NetBIOS Interface driver (Microsoft)
  874. netbt.sys MBT Transport driver (Microsoft)
  875. NETIO.SYS Network I/O Subsystem (Microsoft)
  876. Npfs.SYS NPFS driver (Microsoft)
  877. npsvctrig.sys Named pipe service triggers (Microsoft)
  878. nsiproxy.sys NSI Proxy driver (Microsoft)
  879. Ntfs.sys NT File System Driver (Microsoft)
  880. ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
  881. ntosext.sys NTOS Extension Host driver (Microsoft)
  882. Null.SYS NULL Driver (Microsoft)
  883. pacer.sys QoS Packet Scheduler (Microsoft)
  884. parport.sys Parallel Port Driver (Microsoft)
  885. partmgr.sys Partition driver (Microsoft)
  886. pci.sys NT Plug and Play PCI Enumerator (Microsoft)
  887. pciide.sys Generic PCI IDE Bus Driver (Microsoft)
  888. PCIIDEX.SYS PCI IDE Bus driver file (Microsoft)
  889. pcw.sys Performance Counter Driver (Microsoft)
  890. pdc.sys Power Dependency Coordinator Driver (Microsoft)
  891. peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
  892. portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
  893. PSHED.dll Platform Specific Hardware Error driver (Microsoft)
  894. rasl2tp.sys RAS L2TP Mini-port/Call-manager driver (Microsoft)
  895. raspppoe.sys RAS PPPoE Mini-port/Call manager driver (Microsoft)
  896. raspptp.sys Peer-to-Peer Tunneling Protocol (Microsoft)
  897. rassstp.sys RAS SSTP Miniport Call Manager driver (Microsoft)
  898. rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
  899. rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
  900. rdyboost.sys ReadyBoost Driver (Microsoft)
  901. rspndr.sys Link-Layer Topology Responder driver (Microsoft)
  902. serenum.sys Serial Port Enumerator (Microsoft)
  903. serial.sys Serial Device Driver
  904. SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
  905. SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
  906. spaceport.sys Storage Spaces driver (Microsoft)
  907. srv2.sys Smb 2.0 Server driver (Microsoft)
  908. srvnet.sys Server Network driver (Microsoft)
  909. storqosflt.sys Storage QoS Filter driver (Microsoft)
  910. swenum.sys Plug and Play Software Device Enumerator (Microsoft)
  911. tbs.sys Export driver for kernel mode TPM API (Microsoft)
  912. tcpip.sys TCP/IP Protocol driver (Microsoft)
  913. tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
  914. TDI.SYS TDI Wrapper driver (Microsoft)
  915. tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
  916. tm.sys Kernel Transaction Manager driver (Microsoft)
  917. umbus.sys User-Mode Bus Enumerator (Microsoft)
  918. usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
  919. USBD.SYS Universal Serial Bus Driver (Microsoft)
  920. usbehci.sys EHCI eUSB Miniport Driver (Microsoft)
  921. usbhub.sys Default Hub Driver for USB (Microsoft)
  922. USBPORT.SYS USB 1.1 & 2.0 Port Driver (Microsoft)
  923. vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
  924. Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
  925. volmgr.sys Volume Manager Driver (Microsoft)
  926. volmgrx.sys Volume Manager Extension Driver (Microsoft)
  927. volsnap.sys Volume Shadow Copy driver (Microsoft)
  928. volume.sys Volume driver (Microsoft)
  929. vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
  930. wanarp.sys MS Remote Access and Routing ARP driver (Microsoft)
  931. watchdog.sys Watchdog driver (Microsoft)
  932. wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
  933. Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
  934. WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
  935. WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
  936. WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
  937. werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
  938. wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
  939. win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
  940. win32kbase.sys Base Win32k Kernel Driver (Microsoft)
  941. win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
  942. WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
  943. WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
  944. winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
  945. WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
  946. Wof.sys Windows Overlay Filter (Microsoft)
  947. WppRecorder.sys WPP Trace Recorder (Microsoft)
  948.  
  949. ====================== Dump #2: UNLOADED MODULES =======================
  950.  
  951. fffff800`3dcf0000 fffff800`3dd00000 dump_ataport
  952. fffff800`3dd10000 fffff800`3dd1e000 dump_atapi.s
  953. fffff800`3dd40000 fffff800`3dd5e000 dump_dumpfve
  954. fffff800`3d720000 fffff800`3d73c000 dam.sys
  955. fffff800`36250000 fffff800`36262000 WdBoot.sys
  956. fffff800`37250000 fffff800`37260000 hwpolicy.sys
  957.  
  958. ====================== Dump #2: BIOS INFORMATION =======================
  959.  
  960. [SMBIOS Data Tables v2.7]
  961. [DMI Version - 0]
  962. [2.0 Calling Convention - No]
  963. [Table Size - 3016 bytes]
  964. [BIOS Information (Type 0) - Length 24 - Handle 0000h]
  965. Vendor American Megatrends Inc.
  966. BIOS Version F6
  967. BIOS Starting Address Segment f000
  968. BIOS Release Date 02/16/2012
  969. BIOS ROM Size 280000
  970. BIOS Characteristics
  971. 07: - PCI Supported
  972. 11: - Upgradeable FLASH BIOS
  973. 12: - BIOS Shadowing Supported
  974. 15: - CD-Boot Supported
  975. 16: - Selectable Boot Supported
  976. 17: - BIOS ROM Socketed
  977. 19: - EDD Supported
  978. 23: - 1.2MB Floppy Supported
  979. 24: - 720KB Floppy Supported
  980. 25: - 2.88MB Floppy Supported
  981. 26: - Print Screen Device Supported
  982. 27: - Keyboard Services Supported
  983. 28: - Serial Services Supported
  984. 29: - Printer Services Supported
  985. 32: - BIOS Vendor Reserved
  986. BIOS Characteristic Extensions
  987. 00: - ACPI Supported
  988. 01: - USB Legacy Supported
  989. 08: - BIOS Boot Specification Supported
  990. 10: - Specification Reserved
  991. 11: - Specification Reserved
  992. BIOS Major Revision 4
  993. BIOS Minor Revision 6
  994. EC Firmware Major Revision 255
  995. EC Firmware Minor Revision 255
  996. [System Information (Type 1) - Length 27 - Handle 0001h]
  997. Manufacturer Gigabyte Tecohnology Co., Ltd.
  998. Product Name H61M-DS2
  999. UUID 00000000-0000-0000-0000-000000000000
  1000. Wakeup Type Power Switch
  1001. [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
  1002. Manufacturer Gigabyte Tecohnology Co., Ltd.
  1003. Product H61M-DS2
  1004. Version x.x
  1005. Feature Flags 09h
  1006. -926632224: - -926632176: - «¯þø
  1007. Chassis Handle 0003h
  1008. Board Type 0ah - Processor/Memory Module
  1009. Number of Child Handles 0
  1010. [System Enclosure (Type 3) - Length 22 - Handle 0003h]
  1011. Manufacturer Gigabyte Tecohnology Co., Ltd.
  1012. Chassis Type Desktop
  1013. Bootup State Safe
  1014. Power Supply State Safe
  1015. Thermal State Safe
  1016. Security Status None
  1017. OEM Defined 0
  1018. Height 0U
  1019. Number of Power Cords 1
  1020. Number of Contained Elements 0
  1021. Contained Element Size 0
  1022. [Cache Information (Type 7) - Length 19 - Handle 0004h]
  1023. Cache Configuration 0181h - WB Enabled Int NonSocketed L2
  1024. Maximum Cache Size 0020h - 32K
  1025. Installed Size 0020h - 32K
  1026. Supported SRAM Type 0040h - Asynchronous
  1027. Current SRAM Type 0040h - Asynchronous
  1028. Cache Speed 0ns
  1029. Error Correction Type Multi-Bit ECC
  1030. System Cache Type Other
  1031. Associativity 16-way Set-Associative
  1032. [Cache Information (Type 7) - Length 19 - Handle 0005h]
  1033. Cache Configuration 0182h - WB Enabled Int NonSocketed L3
  1034. Maximum Cache Size 0100h - 256K
  1035. Installed Size 0100h - 256K
  1036. Supported SRAM Type 0040h - Asynchronous
  1037. Current SRAM Type 0040h - Asynchronous
  1038. Cache Speed 0ns
  1039. Error Correction Type Multi-Bit ECC
  1040. System Cache Type Instruction
  1041. Associativity 16-way Set-Associative
  1042. [Cache Information (Type 7) - Length 19 - Handle 0006h]
  1043. Cache Configuration 0183h - WB Enabled Int NonSocketed L4
  1044. Maximum Cache Size 0c00h - 3072K
  1045. Installed Size 0c00h - 3072K
  1046. Supported SRAM Type 0040h - Asynchronous
  1047. Current SRAM Type 0040h - Asynchronous
  1048. Cache Speed 0ns
  1049. Error Correction Type Multi-Bit ECC
  1050. System Cache Type Instruction
  1051. Associativity Specification Reserved
  1052. [Physical Memory Array (Type 16) - Length 23 - Handle 0007h]
  1053. Location 03h - SystemBoard/Motherboard
  1054. Use 03h - System Memory
  1055. Memory Error Correction 03h - None
  1056. Maximum Capacity 33554432KB
  1057. Number of Memory Devices 4
  1058. [Onboard Devices Information (Type 10) - Length 6 - Handle 0026h]
  1059. Number of Devices 1
  1060. 01: Type Video [enabled]
  1061. [OEM Strings (Type 11) - Length 5 - Handle 0027h]
  1062. Number of Strings 1
  1063. [System Configuration Options (Type 12) - Length 5 - Handle 0028h]
  1064. [Memory Device (Type 17) - Length 34 - Handle 0040h]
  1065. Physical Memory Array Handle 0007h
  1066. Total Width 64 bits
  1067. Data Width 64 bits
  1068. Size 4096MB
  1069. Form Factor 09h - DIMM
  1070. Device Locator ChannelA-DIMM0
  1071. Bank Locator BANK 0
  1072. Memory Type 18h - Specification Reserved
  1073. Type Detail 0080h - Synchronous
  1074. Speed 1333MHz
  1075. Manufacturer Hynix/Hyundai
  1076. Part Number HMT351U6CFR8C-H9
  1077. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0041h]
  1078. Starting Address 00000000h
  1079. Ending Address 003fffffh
  1080. Memory Device Handle 0040h
  1081. Mem Array Mapped Adr Handle 0047h
  1082. Interleave Position 01
  1083. Interleave Data Depth 02
  1084. [Memory Device (Type 17) - Length 34 - Handle 0042h]
  1085. Physical Memory Array Handle 0007h
  1086. Total Width 0 bits
  1087. Data Width 0 bits
  1088. Form Factor 09h - DIMM
  1089. Device Locator ChannelA-DIMM1
  1090. Bank Locator BANK 1
  1091. Memory Type 02h - Unknown
  1092. Type Detail 0000h -
  1093. Speed 0MHz
  1094. [Processor Information (Type 4) - Length 42 - Handle 0043h]
  1095. Socket Designation Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
  1096. Processor Type Central Processor
  1097. Processor Family c6h - Specification Reserved
  1098. Processor Manufacturer Intel
  1099. Processor ID a7060200fffbebbf
  1100. Processor Version Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
  1101. Processor Voltage 8bh - 1.1V
  1102. External Clock 100MHz
  1103. Max Speed 7000MHz
  1104. Current Speed 3300MHz
  1105. Status Enabled Populated
  1106. Processor Upgrade Other
  1107. L1 Cache Handle 0004h
  1108. L2 Cache Handle 0005h
  1109. L3 Cache Handle 0006h
  1110. [Memory Device (Type 17) - Length 34 - Handle 0044h]
  1111. Physical Memory Array Handle 0007h
  1112. Total Width 64 bits
  1113. Data Width 64 bits
  1114. Size 4096MB
  1115. Form Factor 09h - DIMM
  1116. Device Locator ChannelB-DIMM0
  1117. Bank Locator BANK 2
  1118. Memory Type 18h - Specification Reserved
  1119. Type Detail 0080h - Synchronous
  1120. Speed 1333MHz
  1121. Manufacturer 8325
  1122. Part Number FLFF65F-C8KL9
  1123. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0045h]
  1124. Starting Address 00400000h
  1125. Ending Address 007fffffh
  1126. Memory Device Handle 0044h
  1127. Mem Array Mapped Adr Handle 0047h
  1128. Interleave Position 02
  1129. Interleave Data Depth 02
  1130. [Memory Device (Type 17) - Length 34 - Handle 0046h]
  1131. Physical Memory Array Handle 0007h
  1132. Total Width 0 bits
  1133. Data Width 0 bits
  1134. Form Factor 09h - DIMM
  1135. Device Locator ChannelB-DIMM1
  1136. Bank Locator BANK 3
  1137. Memory Type 02h - Unknown
  1138. Type Detail 0000h -
  1139. Speed 0MHz
  1140. [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0047h]
  1141. Starting Address 00000000h
  1142. Ending Address 007fffffh
  1143. Memory Array Handle 0007h
  1144. Partition Width 04
  1145.  
  1146. ========================== Dump #2: Extra #1 ===========================
  1147.  
  1148. 1: kd> !verifier
  1149. Verify Flags Level 0x00000000
  1150. STANDARD FLAGS:
  1151. [X] (0x00000000) Automatic Checks
  1152. [ ] (0x00000001) Special pool
  1153. [ ] (0x00000002) Force IRQL checking
  1154. [ ] (0x00000008) Pool tracking
  1155. [ ] (0x00000010) I/O verification
  1156. [ ] (0x00000020) Deadlock detection
  1157. [ ] (0x00000080) DMA checking
  1158. [ ] (0x00000100) Security checks
  1159. [ ] (0x00000800) Miscellaneous checks
  1160. [ ] (0x00020000) DDI compliance checking
  1161. ADDITIONAL FLAGS:
  1162. [ ] (0x00000004) Randomized low resources simulation
  1163. [ ] (0x00000200) Force pending I/O requests
  1164. [ ] (0x00000400) IRP logging
  1165. [ ] (0x00002000) Invariant MDL checking for stack
  1166. [ ] (0x00004000) Invariant MDL checking for driver
  1167. [ ] (0x00008000) Power framework delay fuzzing
  1168. [ ] (0x00010000) Port/miniport interface checking
  1169. [ ] (0x00040000) Systematic low resources simulation
  1170. [ ] (0x00080000) DDI compliance checking (additional)
  1171. [ ] (0x00200000) NDIS/WIFI verification
  1172. [ ] (0x00800000) Kernel synchronization delay fuzzing
  1173. [ ] (0x01000000) VM switch verification
  1174. [ ] (0x02000000) Code integrity checks
  1175. [X] Indicates flag is enabled
  1176. Summary of All Verifier Statistics
  1177. RaiseIrqls 0x0
  1178. AcquireSpinLocks 0x0
  1179. Synch Executions 0x0
  1180. Trims 0x0
  1181. Pool Allocations Attempted 0x0
  1182. Pool Allocations Succeeded 0x0
  1183. Pool Allocations Succeeded SpecialPool 0x0
  1184. Pool Allocations With NO TAG 0x0
  1185. Pool Allocations Failed 0x0
  1186. Current paged pool allocations 0x0 for 00000000 bytes
  1187. Peak paged pool allocations 0x0 for 00000000 bytes
  1188. Current nonpaged pool allocations 0x0 for 00000000 bytes
  1189. Peak nonpaged pool allocations 0x0 for 00000000 bytes
  1190.  
  1191. ========================== Dump #2: Extra #2 ===========================
  1192.  
  1193. 1: kd> !thread
  1194. THREAD ffffb687af276080 Cid 09d4.1464 Teb: 0000009a65bb2000 Win32Thread: ffffb687af1ad680 RUNNING on processor 1
  1195. Not impersonating
  1196. GetUlongFromAddress: unable to read from fffff8003161143c
  1197. Owning Process ffffb687af1570c0 Image: opera.exe
  1198. Attached Process N/A Image: N/A
  1199. fffff78000000000: Unable to get shared data
  1200. Wait Start TickCount 156796
  1201. Context Switch Count 167172 IdealProcessor: 3
  1202. ReadMemory error: Cannot get nt!KeMaximumIncrement value.
  1203. UserTime 00:00:00.000
  1204. KernelTime 00:00:00.000
  1205. Win32 Start Address 0x00007ff7bc5c9860
  1206. Stack Init ffff8888ccdb1c90 Current ffff8888ccdb16a0
  1207. Base ffff8888ccdb2000 Limit ffff8888ccdac000 Call 0000000000000000
  1208. Priority 12 BasePriority 11 PriorityDecrement 0 IoPriority 2 PagePriority 5
  1209. Child-SP RetAddr : Args to Child : Call Site
  1210. ffff8888`ccdb19b8 fffff800`30defa29 : 00000000`0000004a 00007ffc`8bd85024 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
  1211. ffff8888`ccdb19c0 fffff800`30def8f3 : 000001a2`95e42420 ffffb687`af276080 000001a2`f8262210 ffff8888`ccdb1b80 : nt!KiBugCheckDispatch+0x69
  1212. ffff8888`ccdb1b00 00007ffc`8bd85024 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExitPico+0x1fe (TrapFrame @ ffff8888`ccdb1b00)
  1213. 0000009a`65dfca28 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffc`8bd85024
  1214.  
  1215.  
  1216. ========================================================================
  1217. ======================= Dump #3: ANALYZE VERBOSE =======================
  1218. ====================== File: 081020-37390-01.dmp =======================
  1219. ========================================================================
  1220.  
  1221. Mini Kernel Dump File: Only registers and stack trace are available
  1222. Windows 10 Kernel Version 19041 MP (4 procs) Free x64
  1223. Kernel base = 0xfffff804`31800000 PsLoadedModuleList = 0xfffff804`3242a310
  1224. Debug session time: Mon Aug 10 08:23:27.582 2020 (UTC - 4:00)
  1225. System Uptime: 0 days 0:32:57.298
  1226.  
  1227. BugCheck A, {10, 2, 0, fffff80431aacc45}
  1228. Probably caused by : memory_corruption
  1229. Followup: memory_corruption
  1230.  
  1231. IRQL_NOT_LESS_OR_EQUAL (a)
  1232. An attempt was made to access a pageable (or completely invalid) address at an
  1233. interrupt request level (IRQL) that is too high. This is usually
  1234. caused by drivers using improper addresses.
  1235. If a kernel debugger is available get the stack backtrace.
  1236.  
  1237. Arguments:
  1238. Arg1: 0000000000000010, memory referenced
  1239. Arg2: 0000000000000002, IRQL
  1240. Arg3: 0000000000000000, bitfield :
  1241. bit 0 : value 0 = read operation, 1 = write operation
  1242. bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
  1243. Arg4: fffff80431aacc45, address which referenced memory
  1244.  
  1245. Debugging Details:
  1246. DUMP_CLASS: 1
  1247. DUMP_QUALIFIER: 400
  1248. DUMP_TYPE: 2
  1249. READ_ADDRESS: fffff804324fa388: Unable to get MiVisibleState
  1250. 0000000000000010
  1251. CURRENT_IRQL: 2
  1252. FAULTING_IP:
  1253. nt!MiInsertPageInFreeOrZeroedList+1d5
  1254. fffff804`31aacc45 49037d10 add rdi,qword ptr [r13+10h]
  1255. CUSTOMER_CRASH_COUNT: 1
  1256. DEFAULT_BUCKET_ID: CODE_CORRUPTION
  1257. BUGCHECK_STR: AV
  1258.  
  1259. PROCESS_NAME: GTA5.exe
  1260.  
  1261. TRAP_FRAME: ffff9489be3efeb0 -- (.trap 0xffff9489be3efeb0)
  1262. NOTE: The trap frame does not contain all registers.
  1263. Some register values may be zeroed or incorrect.
  1264. rax=0000000000000041 rbx=0000000000000000 rcx=0000000000000008
  1265. rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
  1266. rip=fffff80431aacc45 rsp=ffff9489be3f0040 rbp=ffff9489be3f00d9
  1267. r8=00000000000008c0 r9=00000000000000a1 r10=0000000000000000
  1268. r11=ffff9489be3f0138 r12=0000000000000000 r13=0000000000000000
  1269. r14=0000000000000000 r15=0000000000000000
  1270. iopl=0 nv up ei pl nz na po nc
  1271. nt!MiInsertPageInFreeOrZeroedList+0x1d5:
  1272. fffff804`31aacc45 49037d10 add rdi,qword ptr [r13+10h] ds:00000000`00000010=????????????????
  1273. Resetting default scope
  1274. LAST_CONTROL_TRANSFER: from fffff80431befa29 to fffff80431bddb60
  1275. STACK_TEXT:
  1276. ffff9489`be3efd68 fffff804`31befa29 : 00000000`0000000a 00000000`00000010 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
  1277. ffff9489`be3efd70 fffff804`31bebd29 : fffff804`2ec628a0 ffffd08f`0c728210 00000000`0000000d fffff804`31ac6199 : nt!KiBugCheckDispatch+0x69
  1278. ffff9489`be3efeb0 fffff804`31aacc45 : 00000000`0000000e fffff804`31ac90ff 00000050`00000000 ffff9489`be3f0110 : nt!KiPageFault+0x469
  1279. ffff9489`be3f0040 fffff804`31aaac7a : 00000000`000153a1 ffffe680`003fae48 00000000`000000a2 00000000`00000000 : nt!MiInsertPageInFreeOrZeroedList+0x1d5
  1280. ffff9489`be3f0140 fffff804`31b1ae16 : fffff804`32450b40 00000000`00000050 00000000`00000000 00000000`00000001 : nt!MiDemoteLocalLargePage+0x2ca
  1281. ffff9489`be3f02a0 fffff804`31a1865c : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000001 : nt!MiGetFreeOrZeroPageAnyColor+0x42
  1282. ffff9489`be3f02d0 fffff804`31a17992 : fffff804`32450b40 ffff8a14`00000050 00000000`00000050 00000000`00000001 : nt!MiGetPage+0x3cc
  1283. ffff9489`be3f03b0 fffff804`31a15676 : ffff9489`be3f0790 00000000`00000000 00000000`00000001 ffffd08f`11c33011 : nt!MiGetPageChain+0x172
  1284. ffff9489`be3f0610 fffff804`31a15138 : 00000000`00000004 ffff9489`00000000 ffffd08f`11b137a0 fffff804`32450b40 : nt!MiResolvePrivateZeroFault+0x176
  1285. ffff9489`be3f0730 fffff804`31a1450d : 00000000`c0000016 00000000`00000002 00000000`00000000 00000000`00000002 : nt!MiResolveDemandZeroFault+0x208
  1286. ffff9489`be3f0820 fffff804`31a12a89 : 00000000`00000111 00000000`00000003 00000000`c0000016 00000000`00000000 : nt!MiDispatchFault+0x22d
  1287. ffff9489`be3f0960 fffff804`31bebc1e : ffffd08f`0fae6080 ffffd08f`00000000 00000000`00000000 00000000`00000000 : nt!MmAccessFault+0x189
  1288. ffff9489`be3f0b00 00007ff9`81f7c5ef : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x35e
  1289. 0000009a`13afd850 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff9`81f7c5ef
  1290. STACK_COMMAND: kb
  1291. CHKIMG_EXTENSION: !chkimg -lo 50 -d !dxgmms2
  1292. fffff8042ecf61d9-fffff8042ecf61da 2 bytes - dxgmms2!TlgAggregateInternalProviderCallback+19
  1293. [ 48 ff:4c 8b ]
  1294. fffff8042ecf61e0-fffff8042ecf61e4 5 bytes - dxgmms2!TlgAggregateInternalProviderCallback+20 (+0x07)
  1295. [ 0f 1f 44 00 00:e8 2b 9f e0 02 ]
  1296. fffff8042ecf620f-fffff8042ecf6210 2 bytes - dxgmms2!TlgAggregateInternalProviderCallback+4f (+0x2f)
  1297. [ 48 ff:4c 8b ]
  1298. fffff8042ecf6216-fffff8042ecf621a 5 bytes - dxgmms2!TlgAggregateInternalProviderCallback+56 (+0x07)
  1299. [ 0f 1f 44 00 00:e8 a5 f4 d2 02 ]
  1300. fffff8042ecf629c-fffff8042ecf629d 2 bytes - dxgmms2!TlgUnregisterAggregateProvider+2c (+0x86)
  1301. [ 48 ff:4c 8b ]
  1302. fffff8042ecf62a3-fffff8042ecf62a7 5 bytes - dxgmms2!TlgUnregisterAggregateProvider+33 (+0x07)
  1303. [ 0f 1f 44 00 00:e8 a8 83 25 03 ]
  1304. fffff8042ecf62b8-fffff8042ecf62b9 2 bytes - dxgmms2!TlgUnregisterAggregateProvider+48 (+0x15)
  1305. [ 48 ff:4c 8b ]
  1306. fffff8042ecf62bf - dxgmms2!TlgUnregisterAggregateProvider+4f (+0x07)
  1307. [ 0f:e8 ]
  1308. 24 errors : !dxgmms2 (fffff8042ecf61d9-fffff8042ecf62bf)
  1309. MODULE_NAME: memory_corruption
  1310.  
  1311. IMAGE_NAME: memory_corruption
  1312.  
  1313. FOLLOWUP_NAME: memory_corruption
  1314. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  1315. MEMORY_CORRUPTOR: LARGE
  1316. FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
  1317. BUCKET_ID: MEMORY_CORRUPTION_LARGE
  1318. PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
  1319. TARGET_TIME: 2020-08-10T12:23:27.000Z
  1320. SUITE_MASK: 272
  1321. PRODUCT_TYPE: 1
  1322. USER_LCID: 0
  1323. FAILURE_ID_HASH_STRING: km:memory_corruption_large
  1324. FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
  1325. Followup: memory_corruption
  1326.  
  1327. ====================== Dump #3: 3RD PARTY DRIVERS ======================
  1328.  
  1329. Jul 21 2014 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
  1330. Sep 04 2014 - nvvad64v.sys - Nvidia Virtual Audio driver http://www.nvidia.com/
  1331. Sep 06 2014 - NvStreamKms.sys - Nvidia Streaming Kernel Service http://www.nvidia.com/
  1332. Mar 31 2015 - HWiNFO64A.SYS - HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
  1333. Jul 07 2015 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
  1334. May 26 2020 - rt640x64.sys - Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
  1335. Jul 05 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
  1336.  
  1337. ================== Dump #3: 3RD PARTY DRIVERS (FULL) ===================
  1338.  
  1339. Image path: \SystemRoot\system32\drivers\nvhda64v.sys
  1340. Image name: nvhda64v.sys
  1341. Search : https://www.google.com/search?q=nvhda64v.sys
  1342. ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
  1343. Timestamp : Mon Jul 21 2014
  1344.  
  1345. Image path: \SystemRoot\system32\drivers\nvvad64v.sys
  1346. Image name: nvvad64v.sys
  1347. Search : https://www.google.com/search?q=nvvad64v.sys
  1348. ADA Info : Nvidia Virtual Audio driver http://www.nvidia.com/
  1349. Timestamp : Thu Sep 4 2014
  1350.  
  1351. Image path: \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
  1352. Image name: NvStreamKms.sys
  1353. Search : https://www.google.com/search?q=NvStreamKms.sys
  1354. ADA Info : Nvidia Streaming Kernel Service http://www.nvidia.com/
  1355. Timestamp : Sat Sep 6 2014
  1356.  
  1357. Image path: \??\C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS
  1358. Image name: HWiNFO64A.SYS
  1359. Search : https://www.google.com/search?q=HWiNFO64A.SYS
  1360. ADA Info : HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
  1361. Timestamp : Tue Mar 31 2015
  1362.  
  1363. Image path: \SystemRoot\System32\drivers\TeeDriverW8x64.sys
  1364. Image name: TeeDriverW8x64.sys
  1365. Search : https://www.google.com/search?q=TeeDriverW8x64.sys
  1366. ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
  1367. Timestamp : Tue Jul 7 2015
  1368.  
  1369. Image path: \SystemRoot\System32\drivers\rt640x64.sys
  1370. Image name: rt640x64.sys
  1371. Search : https://www.google.com/search?q=rt640x64.sys
  1372. ADA Info : Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
  1373. Timestamp : Tue May 26 2020
  1374.  
  1375. Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_e92a0ac2e05fb2ca\nvlddmkm.sys
  1376. Image name: nvlddmkm.sys
  1377. Search : https://www.google.com/search?q=nvlddmkm.sys
  1378. ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
  1379. Timestamp : Sun Jul 5 2020
  1380.  
  1381. ====================== Dump #3: MICROSOFT DRIVERS ======================
  1382.  
  1383. ACPI.sys ACPI Driver for NT (Microsoft)
  1384. acpiex.sys ACPIEx Driver (Microsoft)
  1385. afd.sys Ancillary Function Driver for WinSock (Microsoft)
  1386. afunix.sys AF_UNIX Socket Provider driver (Microsoft)
  1387. ahcache.sys Application Compatibility Cache (Microsoft)
  1388. atapi.sys ATAPI IDE MiniPort driver (Microsoft)
  1389. ataport.SYS ATAPI Driver Extension (Microsoft)
  1390. bam.sys BAM Kernal driver (Microsoft)
  1391. BasicDisplay.sys Basic Display driver (Microsoft)
  1392. BasicRender.sys Basic Render driver (Microsoft)
  1393. Beep.SYS BEEP driver (Microsoft)
  1394. bindflt.sys Windows Bind Filter driver (Microsoft)
  1395. BOOTVID.dll VGA Boot Driver (Microsoft)
  1396. bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
  1397. cdd.dll Canonical Display Driver (Microsoft)
  1398. cdfs.sys CD-ROM File System Driver (Microsoft)
  1399. cdrom.sys SCSI CD-ROM Driver (Microsoft)
  1400. CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
  1401. CI.dll Code Integrity Module (Microsoft)
  1402. CimFS.SYS Consumer IR Class Driver for eHome (Microsoft)
  1403. CLASSPNP.SYS SCSI Class System Dll (Microsoft)
  1404. cldflt.sys Cloud Files Mini Filter driver (Microsoft)
  1405. CLFS.SYS Common Log File System Driver (Microsoft)
  1406. clipsp.sys CLIP Service (Microsoft)
  1407. cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
  1408. cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
  1409. CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
  1410. condrv.sys Console Driver (Microsoft)
  1411. crashdmp.sys Crash Dump driver (Microsoft)
  1412. csc.sys Windows Client Side Caching driver (Microsoft)
  1413. dfsc.sys DFS Namespace Client Driver (Microsoft)
  1414. disk.sys PnP Disk Driver (Microsoft)
  1415. drmk.sys Digital Rights Management (DRM) driver (Microsoft)
  1416. dump_atapi.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  1417. dump_dumpata.sys ATAPI Dump Driver
  1418. dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  1419. dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
  1420. dxgmms2.sys DirectX Graphics MMS
  1421. EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
  1422. fastfat.SYS Fast FAT File System Driver (Microsoft)
  1423. filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
  1424. fileinfo.sys FileInfo Filter Driver (Microsoft)
  1425. FLTMGR.SYS Filesystem Filter Manager (Microsoft)
  1426. Fs_Rec.sys File System Recognizer Driver (Microsoft)
  1427. fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
  1428. fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
  1429. gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
  1430. hal.dll Hardware Abstraction Layer DLL (Microsoft)
  1431. HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
  1432. HdAudio.sys High Definition Audio Function driver (Microsoft)
  1433. HIDCLASS.SYS Hid Class Library (Microsoft)
  1434. HIDPARSE.SYS Hid Parsing Library (Microsoft)
  1435. hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
  1436. HTTP.sys HTTP Protocol Stack (Microsoft)
  1437. intelpep.sys Intel Power Engine Plugin (Microsoft)
  1438. intelppm.sys Processor Device Driver (Microsoft)
  1439. IntelTA.sys Intel Telemetry Driver
  1440. iorate.sys I/O rate control Filter (Microsoft)
  1441. kbdclass.sys Keyboard Class Driver (Microsoft)
  1442. kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
  1443. kd.dll Local Kernal Debugger (Microsoft)
  1444. kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
  1445. ks.sys Kernal CSA Library (Microsoft)
  1446. ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
  1447. ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
  1448. ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
  1449. lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
  1450. luafv.sys LUA File Virtualization Filter Driver (Microsoft)
  1451. mcupdate_GenuineIntel.dll Intel Microcode Update Library (Microsoft)
  1452. mmcss.sys MMCSS Driver (Microsoft)
  1453. monitor.sys Monitor Driver (Microsoft)
  1454. mouclass.sys Mouse Class Driver (Microsoft)
  1455. mouhid.sys HID Mouse Filter Driver (Microsoft)
  1456. mountmgr.sys Mount Point Manager (Microsoft)
  1457. mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
  1458. mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
  1459. mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
  1460. Msfs.SYS Mailslot driver (Microsoft)
  1461. msisadrv.sys ISA Driver (Microsoft)
  1462. mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
  1463. msquic.sys Windows QUIC Driver
  1464. msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
  1465. mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
  1466. mssmbios.sys System Management BIOS driver (Microsoft)
  1467. mup.sys Multiple UNC Provider driver (Microsoft)
  1468. ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
  1469. ndiscap.sys Microsoft NDIS Packet Capture Filter Driver
  1470. NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
  1471. Ndu.sys Network Data Usage Monitoring driver (Microsoft)
  1472. netbios.sys NetBIOS Interface driver (Microsoft)
  1473. netbt.sys MBT Transport driver (Microsoft)
  1474. NETIO.SYS Network I/O Subsystem (Microsoft)
  1475. Npfs.SYS NPFS driver (Microsoft)
  1476. npsvctrig.sys Named pipe service triggers (Microsoft)
  1477. nsiproxy.sys NSI Proxy driver (Microsoft)
  1478. Ntfs.sys NT File System Driver (Microsoft)
  1479. ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
  1480. ntosext.sys NTOS Extension Host driver (Microsoft)
  1481. Null.SYS NULL Driver (Microsoft)
  1482. pacer.sys QoS Packet Scheduler (Microsoft)
  1483. parport.sys Parallel Port Driver (Microsoft)
  1484. partmgr.sys Partition driver (Microsoft)
  1485. pci.sys NT Plug and Play PCI Enumerator (Microsoft)
  1486. pciide.sys Generic PCI IDE Bus Driver (Microsoft)
  1487. PCIIDEX.SYS PCI IDE Bus driver file (Microsoft)
  1488. pcw.sys Performance Counter Driver (Microsoft)
  1489. pdc.sys Power Dependency Coordinator Driver (Microsoft)
  1490. peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
  1491. portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
  1492. PSHED.dll Platform Specific Hardware Error driver (Microsoft)
  1493. rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
  1494. rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
  1495. rdyboost.sys ReadyBoost Driver (Microsoft)
  1496. rspndr.sys Link-Layer Topology Responder driver (Microsoft)
  1497. serenum.sys Serial Port Enumerator (Microsoft)
  1498. serial.sys Serial Device Driver
  1499. SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
  1500. SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
  1501. spaceport.sys Storage Spaces driver (Microsoft)
  1502. srv2.sys Smb 2.0 Server driver (Microsoft)
  1503. srvnet.sys Server Network driver (Microsoft)
  1504. storqosflt.sys Storage QoS Filter driver (Microsoft)
  1505. swenum.sys Plug and Play Software Device Enumerator (Microsoft)
  1506. tbs.sys Export driver for kernel mode TPM API (Microsoft)
  1507. tcpip.sys TCP/IP Protocol driver (Microsoft)
  1508. tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
  1509. TDI.SYS TDI Wrapper driver (Microsoft)
  1510. tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
  1511. tm.sys Kernel Transaction Manager driver (Microsoft)
  1512. umbus.sys User-Mode Bus Enumerator (Microsoft)
  1513. usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
  1514. USBD.SYS Universal Serial Bus Driver (Microsoft)
  1515. usbehci.sys EHCI eUSB Miniport Driver (Microsoft)
  1516. usbhub.sys Default Hub Driver for USB (Microsoft)
  1517. USBPORT.SYS USB 1.1 & 2.0 Port Driver (Microsoft)
  1518. vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
  1519. Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
  1520. volmgr.sys Volume Manager Driver (Microsoft)
  1521. volmgrx.sys Volume Manager Extension Driver (Microsoft)
  1522. volsnap.sys Volume Shadow Copy driver (Microsoft)
  1523. volume.sys Volume driver (Microsoft)
  1524. vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
  1525. watchdog.sys Watchdog driver (Microsoft)
  1526. wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
  1527. Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
  1528. WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
  1529. WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
  1530. WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
  1531. werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
  1532. wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
  1533. win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
  1534. win32kbase.sys Base Win32k Kernel Driver (Microsoft)
  1535. win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
  1536. WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
  1537. WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
  1538. winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
  1539. WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
  1540. Wof.sys Windows Overlay Filter (Microsoft)
  1541. WppRecorder.sys WPP Trace Recorder (Microsoft)
  1542.  
  1543. ====================== Dump #3: UNLOADED MODULES =======================
  1544.  
  1545. fffff804`3b2c0000 fffff804`3b2d0000 dump_ataport
  1546. fffff804`3b2e0000 fffff804`3b2ee000 dump_atapi.s
  1547. fffff804`3b310000 fffff804`3b32e000 dump_dumpfve
  1548. fffff804`3af20000 fffff804`3af3c000 dam.sys
  1549. fffff804`33a50000 fffff804`33a62000 WdBoot.sys
  1550. fffff804`34a50000 fffff804`34a60000 hwpolicy.sys
  1551.  
  1552. ====================== Dump #3: BIOS INFORMATION =======================
  1553.  
  1554. [SMBIOS Data Tables v2.7]
  1555. [DMI Version - 0]
  1556. [2.0 Calling Convention - No]
  1557. [Table Size - 3016 bytes]
  1558. [BIOS Information (Type 0) - Length 24 - Handle 0000h]
  1559. Vendor American Megatrends Inc.
  1560. BIOS Version F6
  1561. BIOS Starting Address Segment f000
  1562. BIOS Release Date 02/16/2012
  1563. BIOS ROM Size 280000
  1564. BIOS Characteristics
  1565. 07: - PCI Supported
  1566. 11: - Upgradeable FLASH BIOS
  1567. 12: - BIOS Shadowing Supported
  1568. 15: - CD-Boot Supported
  1569. 16: - Selectable Boot Supported
  1570. 17: - BIOS ROM Socketed
  1571. 19: - EDD Supported
  1572. 23: - 1.2MB Floppy Supported
  1573. 24: - 720KB Floppy Supported
  1574. 25: - 2.88MB Floppy Supported
  1575. 26: - Print Screen Device Supported
  1576. 27: - Keyboard Services Supported
  1577. 28: - Serial Services Supported
  1578. 29: - Printer Services Supported
  1579. 32: - BIOS Vendor Reserved
  1580. BIOS Characteristic Extensions
  1581. 00: - ACPI Supported
  1582. 01: - USB Legacy Supported
  1583. 08: - BIOS Boot Specification Supported
  1584. 10: - Specification Reserved
  1585. 11: - Specification Reserved
  1586. BIOS Major Revision 4
  1587. BIOS Minor Revision 6
  1588. EC Firmware Major Revision 255
  1589. EC Firmware Minor Revision 255
  1590. [System Information (Type 1) - Length 27 - Handle 0001h]
  1591. Manufacturer Gigabyte Tecohnology Co., Ltd.
  1592. Product Name H61M-DS2
  1593. UUID 00000000-0000-0000-0000-000000000000
  1594. Wakeup Type Power Switch
  1595. [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
  1596. Manufacturer Gigabyte Tecohnology Co., Ltd.
  1597. Product H61M-DS2
  1598. Version x.x
  1599. Feature Flags 09h
  1600. -926632224: - -926632176: - «¯þø
  1601. Chassis Handle 0003h
  1602. Board Type 0ah - Processor/Memory Module
  1603. Number of Child Handles 0
  1604. [System Enclosure (Type 3) - Length 22 - Handle 0003h]
  1605. Manufacturer Gigabyte Tecohnology Co., Ltd.
  1606. Chassis Type Desktop
  1607. Bootup State Safe
  1608. Power Supply State Safe
  1609. Thermal State Safe
  1610. Security Status None
  1611. OEM Defined 0
  1612. Height 0U
  1613. Number of Power Cords 1
  1614. Number of Contained Elements 0
  1615. Contained Element Size 0
  1616. [Cache Information (Type 7) - Length 19 - Handle 0004h]
  1617. Cache Configuration 0181h - WB Enabled Int NonSocketed L2
  1618. Maximum Cache Size 0020h - 32K
  1619. Installed Size 0020h - 32K
  1620. Supported SRAM Type 0040h - Asynchronous
  1621. Current SRAM Type 0040h - Asynchronous
  1622. Cache Speed 0ns
  1623. Error Correction Type Multi-Bit ECC
  1624. System Cache Type Other
  1625. Associativity 16-way Set-Associative
  1626. [Cache Information (Type 7) - Length 19 - Handle 0005h]
  1627. Cache Configuration 0182h - WB Enabled Int NonSocketed L3
  1628. Maximum Cache Size 0100h - 256K
  1629. Installed Size 0100h - 256K
  1630. Supported SRAM Type 0040h - Asynchronous
  1631. Current SRAM Type 0040h - Asynchronous
  1632. Cache Speed 0ns
  1633. Error Correction Type Multi-Bit ECC
  1634. System Cache Type Instruction
  1635. Associativity 16-way Set-Associative
  1636. [Cache Information (Type 7) - Length 19 - Handle 0006h]
  1637. Cache Configuration 0183h - WB Enabled Int NonSocketed L4
  1638. Maximum Cache Size 0c00h - 3072K
  1639. Installed Size 0c00h - 3072K
  1640. Supported SRAM Type 0040h - Asynchronous
  1641. Current SRAM Type 0040h - Asynchronous
  1642. Cache Speed 0ns
  1643. Error Correction Type Multi-Bit ECC
  1644. System Cache Type Instruction
  1645. Associativity Specification Reserved
  1646. [Physical Memory Array (Type 16) - Length 23 - Handle 0007h]
  1647. Location 03h - SystemBoard/Motherboard
  1648. Use 03h - System Memory
  1649. Memory Error Correction 03h - None
  1650. Maximum Capacity 33554432KB
  1651. Number of Memory Devices 4
  1652. [Onboard Devices Information (Type 10) - Length 6 - Handle 0026h]
  1653. Number of Devices 1
  1654. 01: Type Video [enabled]
  1655. [OEM Strings (Type 11) - Length 5 - Handle 0027h]
  1656. Number of Strings 1
  1657. [System Configuration Options (Type 12) - Length 5 - Handle 0028h]
  1658. [Memory Device (Type 17) - Length 34 - Handle 0040h]
  1659. Physical Memory Array Handle 0007h
  1660. Total Width 64 bits
  1661. Data Width 64 bits
  1662. Size 4096MB
  1663. Form Factor 09h - DIMM
  1664. Device Locator ChannelA-DIMM0
  1665. Bank Locator BANK 0
  1666. Memory Type 18h - Specification Reserved
  1667. Type Detail 0080h - Synchronous
  1668. Speed 1333MHz
  1669. Manufacturer Hynix/Hyundai
  1670. Part Number HMT351U6CFR8C-H9
  1671. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0041h]
  1672. Starting Address 00000000h
  1673. Ending Address 003fffffh
  1674. Memory Device Handle 0040h
  1675. Mem Array Mapped Adr Handle 0047h
  1676. Interleave Position 01
  1677. Interleave Data Depth 02
  1678. [Memory Device (Type 17) - Length 34 - Handle 0042h]
  1679. Physical Memory Array Handle 0007h
  1680. Total Width 0 bits
  1681. Data Width 0 bits
  1682. Form Factor 09h - DIMM
  1683. Device Locator ChannelA-DIMM1
  1684. Bank Locator BANK 1
  1685. Memory Type 02h - Unknown
  1686. Type Detail 0000h -
  1687. Speed 0MHz
  1688. [Processor Information (Type 4) - Length 42 - Handle 0043h]
  1689. Socket Designation Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
  1690. Processor Type Central Processor
  1691. Processor Family c6h - Specification Reserved
  1692. Processor Manufacturer Intel
  1693. Processor ID a7060200fffbebbf
  1694. Processor Version Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
  1695. Processor Voltage 8bh - 1.1V
  1696. External Clock 100MHz
  1697. Max Speed 7000MHz
  1698. Current Speed 3300MHz
  1699. Status Enabled Populated
  1700. Processor Upgrade Other
  1701. L1 Cache Handle 0004h
  1702. L2 Cache Handle 0005h
  1703. L3 Cache Handle 0006h
  1704. [Memory Device (Type 17) - Length 34 - Handle 0044h]
  1705. Physical Memory Array Handle 0007h
  1706. Total Width 64 bits
  1707. Data Width 64 bits
  1708. Size 4096MB
  1709. Form Factor 09h - DIMM
  1710. Device Locator ChannelB-DIMM0
  1711. Bank Locator BANK 2
  1712. Memory Type 18h - Specification Reserved
  1713. Type Detail 0080h - Synchronous
  1714. Speed 1333MHz
  1715. Manufacturer 8325
  1716. Part Number FLFF65F-C8KL9
  1717. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0045h]
  1718. Starting Address 00400000h
  1719. Ending Address 007fffffh
  1720. Memory Device Handle 0044h
  1721. Mem Array Mapped Adr Handle 0047h
  1722. Interleave Position 02
  1723. Interleave Data Depth 02
  1724. [Memory Device (Type 17) - Length 34 - Handle 0046h]
  1725. Physical Memory Array Handle 0007h
  1726. Total Width 0 bits
  1727. Data Width 0 bits
  1728. Form Factor 09h - DIMM
  1729. Device Locator ChannelB-DIMM1
  1730. Bank Locator BANK 3
  1731. Memory Type 02h - Unknown
  1732. Type Detail 0000h -
  1733. Speed 0MHz
  1734. [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0047h]
  1735. Starting Address 00000000h
  1736. Ending Address 007fffffh
  1737. Memory Array Handle 0007h
  1738. Partition Width 04
  1739.  
  1740. ========================== Dump #3: Extra #1 ===========================
  1741.  
  1742. 0: kd> !verifier
  1743. Verify Flags Level 0x00000000
  1744. STANDARD FLAGS:
  1745. [X] (0x00000000) Automatic Checks
  1746. [ ] (0x00000001) Special pool
  1747. [ ] (0x00000002) Force IRQL checking
  1748. [ ] (0x00000008) Pool tracking
  1749. [ ] (0x00000010) I/O verification
  1750. [ ] (0x00000020) Deadlock detection
  1751. [ ] (0x00000080) DMA checking
  1752. [ ] (0x00000100) Security checks
  1753. [ ] (0x00000800) Miscellaneous checks
  1754. [ ] (0x00020000) DDI compliance checking
  1755. ADDITIONAL FLAGS:
  1756. [ ] (0x00000004) Randomized low resources simulation
  1757. [ ] (0x00000200) Force pending I/O requests
  1758. [ ] (0x00000400) IRP logging
  1759. [ ] (0x00002000) Invariant MDL checking for stack
  1760. [ ] (0x00004000) Invariant MDL checking for driver
  1761. [ ] (0x00008000) Power framework delay fuzzing
  1762. [ ] (0x00010000) Port/miniport interface checking
  1763. [ ] (0x00040000) Systematic low resources simulation
  1764. [ ] (0x00080000) DDI compliance checking (additional)
  1765. [ ] (0x00200000) NDIS/WIFI verification
  1766. [ ] (0x00800000) Kernel synchronization delay fuzzing
  1767. [ ] (0x01000000) VM switch verification
  1768. [ ] (0x02000000) Code integrity checks
  1769. [X] Indicates flag is enabled
  1770. Summary of All Verifier Statistics
  1771. RaiseIrqls 0x0
  1772. AcquireSpinLocks 0x0
  1773. Synch Executions 0x0
  1774. Trims 0x0
  1775. Pool Allocations Attempted 0x0
  1776. Pool Allocations Succeeded 0x0
  1777. Pool Allocations Succeeded SpecialPool 0x0
  1778. Pool Allocations With NO TAG 0x0
  1779. Pool Allocations Failed 0x0
  1780. Current paged pool allocations 0x0 for 00000000 bytes
  1781. Peak paged pool allocations 0x0 for 00000000 bytes
  1782. Current nonpaged pool allocations 0x0 for 00000000 bytes
  1783. Peak nonpaged pool allocations 0x0 for 00000000 bytes
  1784.  
  1785. ========================== Dump #3: Extra #2 ===========================
  1786.  
  1787. 0: kd> !thread
  1788. THREAD ffffd08f0fae6080 Cid 21c0.0b28 Teb: 0000009a13907000 Win32Thread: ffffd08f11b1ff00 RUNNING on processor 0
  1789. IRP List:
  1790. Unable to read nt!_IRP @ ffffd08f11c85880
  1791. Not impersonating
  1792. GetUlongFromAddress: unable to read from fffff8043241143c
  1793. Owning Process ffffd08f11c33080 Image: GTA5.exe
  1794. Attached Process N/A Image: N/A
  1795. fffff78000000000: Unable to get shared data
  1796. Wait Start TickCount 126547
  1797. Context Switch Count 16990 IdealProcessor: 2
  1798. ReadMemory error: Cannot get nt!KeMaximumIncrement value.
  1799. UserTime 00:00:00.000
  1800. KernelTime 00:00:00.000
  1801. Win32 Start Address 0x00007ff722641144
  1802. Stack Init ffff9489be3f0c90 Current ffff9489be3ef0c0
  1803. Base ffff9489be3f1000 Limit ffff9489be3eb000 Call 0000000000000000
  1804. Priority 15 BasePriority 15 PriorityDecrement 0 IoPriority 2 PagePriority 5
  1805. Child-SP RetAddr : Args to Child : Call Site
  1806. ffff9489`be3efd68 fffff804`31befa29 : 00000000`0000000a 00000000`00000010 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
  1807. ffff9489`be3efd70 fffff804`31bebd29 : fffff804`2ec628a0 ffffd08f`0c728210 00000000`0000000d fffff804`31ac6199 : nt!KiBugCheckDispatch+0x69
  1808. ffff9489`be3efeb0 fffff804`31aacc45 : 00000000`0000000e fffff804`31ac90ff 00000050`00000000 ffff9489`be3f0110 : nt!KiPageFault+0x469 (TrapFrame @ ffff9489`be3efeb0)
  1809. ffff9489`be3f0040 fffff804`31aaac7a : 00000000`000153a1 ffffe680`003fae48 00000000`000000a2 00000000`00000000 : nt!MiInsertPageInFreeOrZeroedList+0x1d5
  1810. ffff9489`be3f0140 fffff804`31b1ae16 : fffff804`32450b40 00000000`00000050 00000000`00000000 00000000`00000001 : nt!MiDemoteLocalLargePage+0x2ca
  1811. ffff9489`be3f02a0 fffff804`31a1865c : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000001 : nt!MiGetFreeOrZeroPageAnyColor+0x42
  1812. ffff9489`be3f02d0 fffff804`31a17992 : fffff804`32450b40 ffff8a14`00000050 00000000`00000050 00000000`00000001 : nt!MiGetPage+0x3cc
  1813. ffff9489`be3f03b0 fffff804`31a15676 : ffff9489`be3f0790 00000000`00000000 00000000`00000001 ffffd08f`11c33011 : nt!MiGetPageChain+0x172
  1814. ffff9489`be3f0610 fffff804`31a15138 : 00000000`00000004 ffff9489`00000000 ffffd08f`11b137a0 fffff804`32450b40 : nt!MiResolvePrivateZeroFault+0x176
  1815. ffff9489`be3f0730 fffff804`31a1450d : 00000000`c0000016 00000000`00000002 00000000`00000000 00000000`00000002 : nt!MiResolveDemandZeroFault+0x208
  1816. ffff9489`be3f0820 fffff804`31a12a89 : 00000000`00000111 00000000`00000003 00000000`c0000016 00000000`00000000 : nt!MiDispatchFault+0x22d
  1817. ffff9489`be3f0960 fffff804`31bebc1e : ffffd08f`0fae6080 ffffd08f`00000000 00000000`00000000 00000000`00000000 : nt!MmAccessFault+0x189
  1818. ffff9489`be3f0b00 00007ff9`81f7c5ef : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x35e (TrapFrame @ ffff9489`be3f0b00)
  1819. 0000009a`13afd850 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff9`81f7c5ef
  1820.  
  1821.  
  1822. ========================================================================
  1823. ======================= Dump #4: ANALYZE VERBOSE =======================
  1824. ====================== File: 081020-31234-01.dmp =======================
  1825. ========================================================================
  1826.  
  1827. Mini Kernel Dump File: Only registers and stack trace are available
  1828. Windows 10 Kernel Version 19041 MP (4 procs) Free x64
  1829. Kernel base = 0xfffff806`2aa00000 PsLoadedModuleList = 0xfffff806`2b62a310
  1830. Debug session time: Mon Aug 10 10:22:59.388 2020 (UTC - 4:00)
  1831. System Uptime: 0 days 0:34:06.105
  1832.  
  1833. BugCheck A, {ffffbf07556b1042, 2, 0, fffff8062acc4d3b}
  1834. Probably caused by : memory_corruption
  1835. Followup: memory_corruption
  1836.  
  1837. IRQL_NOT_LESS_OR_EQUAL (a)
  1838. An attempt was made to access a pageable (or completely invalid) address at an
  1839. interrupt request level (IRQL) that is too high. This is usually
  1840. caused by drivers using improper addresses.
  1841. If a kernel debugger is available get the stack backtrace.
  1842.  
  1843. Arguments:
  1844. Arg1: ffffbf07556b1042, memory referenced
  1845. Arg2: 0000000000000002, IRQL
  1846. Arg3: 0000000000000000, bitfield :
  1847. bit 0 : value 0 = read operation, 1 = write operation
  1848. bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
  1849. Arg4: fffff8062acc4d3b, address which referenced memory
  1850.  
  1851. Debugging Details:
  1852. DUMP_CLASS: 1
  1853. DUMP_QUALIFIER: 400
  1854. DUMP_TYPE: 2
  1855. READ_ADDRESS: fffff8062b6fa388: Unable to get MiVisibleState
  1856. ffffbf07556b1042
  1857. CURRENT_IRQL: 2
  1858. FAULTING_IP:
  1859. nt!MiLogPageAccess+30b
  1860. fffff806`2acc4d3b f6462202 test byte ptr [rsi+22h],2
  1861. CUSTOMER_CRASH_COUNT: 1
  1862. DEFAULT_BUCKET_ID: CODE_CORRUPTION
  1863. BUGCHECK_STR: AV
  1864.  
  1865. PROCESS_NAME: 347.09-notebook-win8-win7-64bit-internationa
  1866.  
  1867. TRAP_FRAME: ffffb901b2c52f50 -- (.trap 0xffffb901b2c52f50)
  1868. NOTE: The trap frame does not contain all registers.
  1869. Some register values may be zeroed or incorrect.
  1870. rax=8000000000000000 rbx=0000000000000000 rcx=a781707af1f80000
  1871. rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
  1872. rip=fffff8062acc4d3b rsp=ffffb901b2c530e0 rbp=ffffb901b2c53128
  1873. r8=ffff88f1c7a7ebf8 r9=0000000000000000 r10=00000000ffffffff
  1874. r11=0000000000000001 r12=0000000000000000 r13=0000000000000000
  1875. r14=0000000000000000 r15=0000000000000000
  1876. iopl=0 nv up ei ng nz ac po cy
  1877. nt!MiLogPageAccess+0x30b:
  1878. fffff806`2acc4d3b f6462202 test byte ptr [rsi+22h],2 ds:00000000`00000022=??
  1879. Resetting default scope
  1880. LAST_CONTROL_TRANSFER: from fffff8062adefa29 to fffff8062adddb60
  1881. STACK_TEXT:
  1882. ffffb901`b2c52e08 fffff806`2adefa29 : 00000000`0000000a ffffbf07`556b1042 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
  1883. ffffb901`b2c52e10 fffff806`2adebd29 : 00000000`00000000 fffff806`2ac956b9 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
  1884. ffffb901`b2c52f50 fffff806`2acc4d3b : fffff980`013faa30 ffffb901`b2c53128 fffff806`2b652780 fffff806`2b64f600 : nt!KiPageFault+0x469
  1885. ffffb901`b2c530e0 fffff806`2acc07e8 : 00000000`00b3e000 80000000`6a8e1821 00000003`00000000 fffff806`2ad16b2a : nt!MiLogPageAccess+0x30b
  1886. ffffb901`b2c53170 fffff806`2b063c5f : ffffe38f`4fd7f000 ffffa781`6d349280 00000000`00000000 00000000`00000000 : nt!MmUnmapViewInSystemCache+0x988
  1887. ffffb901`b2c53290 fffff806`2ac86ae6 : 00000000`00b00000 ffffbf07`46356a20 ffffbf07`3b9103b8 00000000`00000001 : nt!CcUnmapVacb+0x63
  1888. ffffb901`b2c532d0 fffff806`2ac8bb7a : 00000000`00c00001 ffffbf07`3b6898a0 00000000`00400000 00000000`00000001 : nt!CcUnmapVacbArray+0x206
  1889. ffffb901`b2c53340 fffff806`2b064180 : 00000000`00c00000 00000000`00000000 ffffb901`b2c53480 ffffb901`b2c53490 : nt!CcGetVirtualAddress+0x40a
  1890. ffffb901`b2c533e0 fffff806`2ac8b0b9 : 00000000`00000000 00000000`00c00000 00000000`00000000 00000000`00000001 : nt!CcMapAndCopyFromCache+0x80
  1891. ffffb901`b2c53480 fffff806`3045a1ad : ffffb901`b2c535e0 00000000`00000000 ffffa781`00100000 00000000`00100000 : nt!CcCopyReadEx+0x139
  1892. ffffb901`b2c53530 fffff806`2a2373fb : 00000000`00000000 ffffb901`b2c53908 ffffb901`b2c538c8 00000000`032b0020 : Ntfs!NtfsCopyReadA+0x2ed
  1893. ffffb901`b2c53820 fffff806`2a2344d7 : ffffb901`b2c53930 ffffb901`b2c538c8 ffffbf07`449f1110 ffffbf07`449f1010 : FLTMGR!FltpPerformFastIoCall+0x16b
  1894. ffffb901`b2c53880 fffff806`2a26b405 : ffffb901`b2c54000 ffffb901`b2c4e000 ffffbf07`4622b080 fffff806`2aff8fce : FLTMGR!FltpPassThroughFastIo+0x107
  1895. ffffb901`b2c53900 fffff806`2b011b5f : ffffbf07`4657a100 00000000`00000000 00000000`00000000 ffffbf07`00000000 : FLTMGR!FltpFastIoRead+0x165
  1896. ffffb901`b2c539b0 fffff806`2adef478 : 00000000`0000026c 00000000`00000000 00000000`00000000 00000000`00000000 : nt!NtReadFile+0x37f
  1897. ffffb901`b2c53a90 00000000`76f11cfc : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
  1898. 00000000`031af308 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x76f11cfc
  1899. STACK_COMMAND: kb
  1900. CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
  1901. fffff8062acc41bd - nt!MiAgePteWorker+36d
  1902. [ f6:88 ]
  1903. fffff8062acc41f7 - nt!MiAgePteWorker+3a7 (+0x3a)
  1904. [ fa:f9 ]
  1905. fffff8062acc421a-fffff8062acc421e 5 bytes - nt!MiAgePteWorker+3ca (+0x23)
  1906. [ d7 be 7d fb f6:17 31 62 c4 88 ]
  1907. fffff8062acc43d6 - nt!MiClearPteAccessed+46 (+0x1bc)
  1908. [ f6:88 ]
  1909. fffff8062acc43fd - nt!MiClearPteAccessed+6d (+0x27)
  1910. [ f6:88 ]
  1911. fffff8062acc4445-fffff8062acc4449 5 bytes - nt!MiClearPteAccessed+b5 (+0x48)
  1912. [ d0 be 7d fb f6:10 31 62 c4 88 ]
  1913. fffff8062acc444f-fffff8062acc4453 5 bytes - nt!MiClearPteAccessed+bf (+0x0a)
  1914. [ d7 be 7d fb f6:17 31 62 c4 88 ]
  1915. fffff8062acc4572-fffff8062acc4576 5 bytes - nt!MiClearPteAccessed+1e2 (+0x123)
  1916. [ d7 be 7d fb f6:17 31 62 c4 88 ]
  1917. fffff8062acc457c-fffff8062acc4580 5 bytes - nt!MiClearPteAccessed+1ec (+0x0a)
  1918. [ d0 be 7d fb f6:10 31 62 c4 88 ]
  1919. fffff8062acc4598 - nt!MiClearPteAccessed+208 (+0x1c)
  1920. [ f6:88 ]
  1921. fffff8062acc47b8 - nt!MiClearPteAccessed+428 (+0x220)
  1922. [ f6:88 ]
  1923. fffff8062acc47ce - nt!MiClearPteAccessed+43e (+0x16)
  1924. [ f6:88 ]
  1925. fffff8062acc4830 - nt!MiClearPteAccessed+4a0 (+0x62)
  1926. [ f6:88 ]
  1927. fffff8062acc488b - nt!MiClearPteAccessed+4fb (+0x5b)
  1928. [ fa:f9 ]
  1929. fffff8062acc4936-fffff8062acc493a 5 bytes - nt!MiClearPteAccessed+5a6 (+0xab)
  1930. [ d0 be 7d fb f6:10 31 62 c4 88 ]
  1931. fffff8062acc4940-fffff8062acc4944 5 bytes - nt!MiClearPteAccessed+5b0 (+0x0a)
  1932. [ d7 be 7d fb f6:17 31 62 c4 88 ]
  1933. fffff8062acc4a8b-fffff8062acc4a8f 5 bytes - nt!MiLogPageAccess+5b (+0x14b)
  1934. [ d0 be 7d fb f6:10 31 62 c4 88 ]
  1935. fffff8062acc4ad0 - nt!MiLogPageAccess+a0 (+0x45)
  1936. [ fa:f9 ]
  1937. fffff8062acc4d26-fffff8062acc4d2a 5 bytes - nt!MiLogPageAccess+2f6 (+0x256)
  1938. [ d7 be 7d fb f6:17 31 62 c4 88 ]
  1939. fffff8062ad84f3e-fffff8062ad84f41 4 bytes - nt!MiFreeUltraMapping+32 (+0xc0218)
  1940. [ a0 7d fb f6:20 62 c4 88 ]
  1941. 59 errors : !nt (fffff8062acc41bd-fffff8062ad84f41)
  1942. MODULE_NAME: memory_corruption
  1943.  
  1944. IMAGE_NAME: memory_corruption
  1945.  
  1946. FOLLOWUP_NAME: memory_corruption
  1947. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  1948. MEMORY_CORRUPTOR: LARGE
  1949. FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
  1950. BUCKET_ID: MEMORY_CORRUPTION_LARGE
  1951. PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
  1952. TARGET_TIME: 2020-08-10T14:22:59.000Z
  1953. SUITE_MASK: 272
  1954. PRODUCT_TYPE: 1
  1955. USER_LCID: 0
  1956. FAILURE_ID_HASH_STRING: km:memory_corruption_large
  1957. FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
  1958. Followup: memory_corruption
  1959.  
  1960. ====================== Dump #4: 3RD PARTY DRIVERS ======================
  1961.  
  1962. Jul 21 2014 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
  1963. Sep 04 2014 - nvvad64v.sys - Nvidia Virtual Audio driver http://www.nvidia.com/
  1964. Sep 06 2014 - NvStreamKms.sys - Nvidia Streaming Kernel Service http://www.nvidia.com/
  1965. Mar 31 2015 - HWiNFO64A.SYS - HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
  1966. Jul 07 2015 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
  1967. May 26 2020 - rt640x64.sys - Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
  1968. Jul 05 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
  1969.  
  1970. ================== Dump #4: 3RD PARTY DRIVERS (FULL) ===================
  1971.  
  1972. Image path: \SystemRoot\system32\drivers\nvhda64v.sys
  1973. Image name: nvhda64v.sys
  1974. Search : https://www.google.com/search?q=nvhda64v.sys
  1975. ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
  1976. Timestamp : Mon Jul 21 2014
  1977.  
  1978. Image path: \SystemRoot\system32\drivers\nvvad64v.sys
  1979. Image name: nvvad64v.sys
  1980. Search : https://www.google.com/search?q=nvvad64v.sys
  1981. ADA Info : Nvidia Virtual Audio driver http://www.nvidia.com/
  1982. Timestamp : Thu Sep 4 2014
  1983.  
  1984. Image path: \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
  1985. Image name: NvStreamKms.sys
  1986. Search : https://www.google.com/search?q=NvStreamKms.sys
  1987. ADA Info : Nvidia Streaming Kernel Service http://www.nvidia.com/
  1988. Timestamp : Sat Sep 6 2014
  1989.  
  1990. Image path: \??\C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS
  1991. Image name: HWiNFO64A.SYS
  1992. Search : https://www.google.com/search?q=HWiNFO64A.SYS
  1993. ADA Info : HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
  1994. Timestamp : Tue Mar 31 2015
  1995.  
  1996. Image path: \SystemRoot\System32\drivers\TeeDriverW8x64.sys
  1997. Image name: TeeDriverW8x64.sys
  1998. Search : https://www.google.com/search?q=TeeDriverW8x64.sys
  1999. ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
  2000. Timestamp : Tue Jul 7 2015
  2001.  
  2002. Image path: \SystemRoot\System32\drivers\rt640x64.sys
  2003. Image name: rt640x64.sys
  2004. Search : https://www.google.com/search?q=rt640x64.sys
  2005. ADA Info : Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
  2006. Timestamp : Tue May 26 2020
  2007.  
  2008. Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_e92a0ac2e05fb2ca\nvlddmkm.sys
  2009. Image name: nvlddmkm.sys
  2010. Search : https://www.google.com/search?q=nvlddmkm.sys
  2011. ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
  2012. Timestamp : Sun Jul 5 2020
  2013.  
  2014. ====================== Dump #4: MICROSOFT DRIVERS ======================
  2015.  
  2016. ACPI.sys ACPI Driver for NT (Microsoft)
  2017. acpiex.sys ACPIEx Driver (Microsoft)
  2018. afd.sys Ancillary Function Driver for WinSock (Microsoft)
  2019. afunix.sys AF_UNIX Socket Provider driver (Microsoft)
  2020. ahcache.sys Application Compatibility Cache (Microsoft)
  2021. atapi.sys ATAPI IDE MiniPort driver (Microsoft)
  2022. ataport.SYS ATAPI Driver Extension (Microsoft)
  2023. bam.sys BAM Kernal driver (Microsoft)
  2024. BasicDisplay.sys Basic Display driver (Microsoft)
  2025. BasicRender.sys Basic Render driver (Microsoft)
  2026. Beep.SYS BEEP driver (Microsoft)
  2027. bindflt.sys Windows Bind Filter driver (Microsoft)
  2028. BOOTVID.dll VGA Boot Driver (Microsoft)
  2029. bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
  2030. cdd.dll Canonical Display Driver (Microsoft)
  2031. cdfs.sys CD-ROM File System Driver (Microsoft)
  2032. cdrom.sys SCSI CD-ROM Driver (Microsoft)
  2033. CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
  2034. CI.dll Code Integrity Module (Microsoft)
  2035. CimFS.SYS Consumer IR Class Driver for eHome (Microsoft)
  2036. CLASSPNP.SYS SCSI Class System Dll (Microsoft)
  2037. cldflt.sys Cloud Files Mini Filter driver (Microsoft)
  2038. CLFS.SYS Common Log File System Driver (Microsoft)
  2039. clipsp.sys CLIP Service (Microsoft)
  2040. cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
  2041. cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
  2042. CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
  2043. condrv.sys Console Driver (Microsoft)
  2044. crashdmp.sys Crash Dump driver (Microsoft)
  2045. csc.sys Windows Client Side Caching driver (Microsoft)
  2046. dfsc.sys DFS Namespace Client Driver (Microsoft)
  2047. disk.sys PnP Disk Driver (Microsoft)
  2048. drmk.sys Digital Rights Management (DRM) driver (Microsoft)
  2049. dump_atapi.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  2050. dump_dumpata.sys ATAPI Dump Driver
  2051. dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  2052. dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
  2053. dxgmms2.sys DirectX Graphics MMS
  2054. EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
  2055. fastfat.SYS Fast FAT File System Driver (Microsoft)
  2056. filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
  2057. fileinfo.sys FileInfo Filter Driver (Microsoft)
  2058. FLTMGR.SYS Filesystem Filter Manager (Microsoft)
  2059. Fs_Rec.sys File System Recognizer Driver (Microsoft)
  2060. fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
  2061. fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
  2062. gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
  2063. hal.dll Hardware Abstraction Layer DLL (Microsoft)
  2064. HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
  2065. HdAudio.sys High Definition Audio Function driver (Microsoft)
  2066. HIDCLASS.SYS Hid Class Library (Microsoft)
  2067. HIDPARSE.SYS Hid Parsing Library (Microsoft)
  2068. hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
  2069. HTTP.sys HTTP Protocol Stack (Microsoft)
  2070. intelpep.sys Intel Power Engine Plugin (Microsoft)
  2071. intelppm.sys Processor Device Driver (Microsoft)
  2072. IntelTA.sys Intel Telemetry Driver
  2073. iorate.sys I/O rate control Filter (Microsoft)
  2074. kbdclass.sys Keyboard Class Driver (Microsoft)
  2075. kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
  2076. kd.dll Local Kernal Debugger (Microsoft)
  2077. kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
  2078. ks.sys Kernal CSA Library (Microsoft)
  2079. ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
  2080. ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
  2081. ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
  2082. lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
  2083. luafv.sys LUA File Virtualization Filter Driver (Microsoft)
  2084. mcupdate_GenuineIntel.dll Intel Microcode Update Library (Microsoft)
  2085. mmcss.sys MMCSS Driver (Microsoft)
  2086. monitor.sys Monitor Driver (Microsoft)
  2087. mouclass.sys Mouse Class Driver (Microsoft)
  2088. mouhid.sys HID Mouse Filter Driver (Microsoft)
  2089. mountmgr.sys Mount Point Manager (Microsoft)
  2090. MpKslDrv.sys Microsoft Anti-malware Protection driver
  2091. mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
  2092. mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
  2093. mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
  2094. Msfs.SYS Mailslot driver (Microsoft)
  2095. msisadrv.sys ISA Driver (Microsoft)
  2096. mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
  2097. msquic.sys Windows QUIC Driver
  2098. msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
  2099. mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
  2100. mssmbios.sys System Management BIOS driver (Microsoft)
  2101. mup.sys Multiple UNC Provider driver (Microsoft)
  2102. ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
  2103. ndiscap.sys Microsoft NDIS Packet Capture Filter Driver
  2104. NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
  2105. Ndu.sys Network Data Usage Monitoring driver (Microsoft)
  2106. netbios.sys NetBIOS Interface driver (Microsoft)
  2107. netbt.sys MBT Transport driver (Microsoft)
  2108. NETIO.SYS Network I/O Subsystem (Microsoft)
  2109. Npfs.SYS NPFS driver (Microsoft)
  2110. npsvctrig.sys Named pipe service triggers (Microsoft)
  2111. nsiproxy.sys NSI Proxy driver (Microsoft)
  2112. Ntfs.sys NT File System Driver (Microsoft)
  2113. ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
  2114. ntosext.sys NTOS Extension Host driver (Microsoft)
  2115. Null.SYS NULL Driver (Microsoft)
  2116. pacer.sys QoS Packet Scheduler (Microsoft)
  2117. parport.sys Parallel Port Driver (Microsoft)
  2118. partmgr.sys Partition driver (Microsoft)
  2119. pci.sys NT Plug and Play PCI Enumerator (Microsoft)
  2120. pciide.sys Generic PCI IDE Bus Driver (Microsoft)
  2121. PCIIDEX.SYS PCI IDE Bus driver file (Microsoft)
  2122. pcw.sys Performance Counter Driver (Microsoft)
  2123. pdc.sys Power Dependency Coordinator Driver (Microsoft)
  2124. peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
  2125. portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
  2126. PSHED.dll Platform Specific Hardware Error driver (Microsoft)
  2127. rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
  2128. rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
  2129. rdyboost.sys ReadyBoost Driver (Microsoft)
  2130. rspndr.sys Link-Layer Topology Responder driver (Microsoft)
  2131. serenum.sys Serial Port Enumerator (Microsoft)
  2132. serial.sys Serial Device Driver
  2133. SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
  2134. SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
  2135. spaceport.sys Storage Spaces driver (Microsoft)
  2136. srv2.sys Smb 2.0 Server driver (Microsoft)
  2137. srvnet.sys Server Network driver (Microsoft)
  2138. storqosflt.sys Storage QoS Filter driver (Microsoft)
  2139. swenum.sys Plug and Play Software Device Enumerator (Microsoft)
  2140. tbs.sys Export driver for kernel mode TPM API (Microsoft)
  2141. tcpip.sys TCP/IP Protocol driver (Microsoft)
  2142. tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
  2143. TDI.SYS TDI Wrapper driver (Microsoft)
  2144. tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
  2145. tm.sys Kernel Transaction Manager driver (Microsoft)
  2146. umbus.sys User-Mode Bus Enumerator (Microsoft)
  2147. usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
  2148. USBD.SYS Universal Serial Bus Driver (Microsoft)
  2149. usbehci.sys EHCI eUSB Miniport Driver (Microsoft)
  2150. usbhub.sys Default Hub Driver for USB (Microsoft)
  2151. USBPORT.SYS USB 1.1 & 2.0 Port Driver (Microsoft)
  2152. vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
  2153. Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
  2154. volmgr.sys Volume Manager Driver (Microsoft)
  2155. volmgrx.sys Volume Manager Extension Driver (Microsoft)
  2156. volsnap.sys Volume Shadow Copy driver (Microsoft)
  2157. volume.sys Volume driver (Microsoft)
  2158. vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
  2159. watchdog.sys Watchdog driver (Microsoft)
  2160. wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
  2161. Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
  2162. WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
  2163. WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
  2164. WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
  2165. werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
  2166. wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
  2167. win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
  2168. win32kbase.sys Base Win32k Kernel Driver (Microsoft)
  2169. win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
  2170. WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
  2171. WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
  2172. winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
  2173. WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
  2174. Wof.sys Windows Overlay Filter (Microsoft)
  2175. WppRecorder.sys WPP Trace Recorder (Microsoft)
  2176.  
  2177. ====================== Dump #4: UNLOADED MODULES =======================
  2178.  
  2179. fffff806`36bb0000 fffff806`36bc0000 dump_ataport
  2180. fffff806`36bd0000 fffff806`36bde000 dump_atapi.s
  2181. fffff806`36a00000 fffff806`36a1e000 dump_dumpfve
  2182. fffff806`381b0000 fffff806`381cc000 dam.sys
  2183. fffff806`2fe50000 fffff806`2fe62000 WdBoot.sys
  2184. fffff806`30e50000 fffff806`30e60000 hwpolicy.sys
  2185.  
  2186. ====================== Dump #4: BIOS INFORMATION =======================
  2187.  
  2188. [SMBIOS Data Tables v2.7]
  2189. [DMI Version - 0]
  2190. [2.0 Calling Convention - No]
  2191. [Table Size - 3016 bytes]
  2192. [BIOS Information (Type 0) - Length 24 - Handle 0000h]
  2193. Vendor American Megatrends Inc.
  2194. BIOS Version F6
  2195. BIOS Starting Address Segment f000
  2196. BIOS Release Date 02/16/2012
  2197. BIOS ROM Size 280000
  2198. BIOS Characteristics
  2199. 07: - PCI Supported
  2200. 11: - Upgradeable FLASH BIOS
  2201. 12: - BIOS Shadowing Supported
  2202. 15: - CD-Boot Supported
  2203. 16: - Selectable Boot Supported
  2204. 17: - BIOS ROM Socketed
  2205. 19: - EDD Supported
  2206. 23: - 1.2MB Floppy Supported
  2207. 24: - 720KB Floppy Supported
  2208. 25: - 2.88MB Floppy Supported
  2209. 26: - Print Screen Device Supported
  2210. 27: - Keyboard Services Supported
  2211. 28: - Serial Services Supported
  2212. 29: - Printer Services Supported
  2213. 32: - BIOS Vendor Reserved
  2214. BIOS Characteristic Extensions
  2215. 00: - ACPI Supported
  2216. 01: - USB Legacy Supported
  2217. 08: - BIOS Boot Specification Supported
  2218. 10: - Specification Reserved
  2219. 11: - Specification Reserved
  2220. BIOS Major Revision 4
  2221. BIOS Minor Revision 6
  2222. EC Firmware Major Revision 255
  2223. EC Firmware Minor Revision 255
  2224. [System Information (Type 1) - Length 27 - Handle 0001h]
  2225. Manufacturer Gigabyte Tecohnology Co., Ltd.
  2226. Product Name H61M-DS2
  2227. UUID 00000000-0000-0000-0000-000000000000
  2228. Wakeup Type Power Switch
  2229. [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
  2230. Manufacturer Gigabyte Tecohnology Co., Ltd.
  2231. Product H61M-DS2
  2232. Version x.x
  2233. Feature Flags 09h
  2234. -926632224: - -926632176: - «¯þø
  2235. Chassis Handle 0003h
  2236. Board Type 0ah - Processor/Memory Module
  2237. Number of Child Handles 0
  2238. [System Enclosure (Type 3) - Length 22 - Handle 0003h]
  2239. Manufacturer Gigabyte Tecohnology Co., Ltd.
  2240. Chassis Type Desktop
  2241. Bootup State Safe
  2242. Power Supply State Safe
  2243. Thermal State Safe
  2244. Security Status None
  2245. OEM Defined 0
  2246. Height 0U
  2247. Number of Power Cords 1
  2248. Number of Contained Elements 0
  2249. Contained Element Size 0
  2250. [Cache Information (Type 7) - Length 19 - Handle 0004h]
  2251. Cache Configuration 0181h - WB Enabled Int NonSocketed L2
  2252. Maximum Cache Size 0020h - 32K
  2253. Installed Size 0020h - 32K
  2254. Supported SRAM Type 0040h - Asynchronous
  2255. Current SRAM Type 0040h - Asynchronous
  2256. Cache Speed 0ns
  2257. Error Correction Type Multi-Bit ECC
  2258. System Cache Type Other
  2259. Associativity 16-way Set-Associative
  2260. [Cache Information (Type 7) - Length 19 - Handle 0005h]
  2261. Cache Configuration 0182h - WB Enabled Int NonSocketed L3
  2262. Maximum Cache Size 0100h - 256K
  2263. Installed Size 0100h - 256K
  2264. Supported SRAM Type 0040h - Asynchronous
  2265. Current SRAM Type 0040h - Asynchronous
  2266. Cache Speed 0ns
  2267. Error Correction Type Multi-Bit ECC
  2268. System Cache Type Instruction
  2269. Associativity 16-way Set-Associative
  2270. [Cache Information (Type 7) - Length 19 - Handle 0006h]
  2271. Cache Configuration 0183h - WB Enabled Int NonSocketed L4
  2272. Maximum Cache Size 0c00h - 3072K
  2273. Installed Size 0c00h - 3072K
  2274. Supported SRAM Type 0040h - Asynchronous
  2275. Current SRAM Type 0040h - Asynchronous
  2276. Cache Speed 0ns
  2277. Error Correction Type Multi-Bit ECC
  2278. System Cache Type Instruction
  2279. Associativity Specification Reserved
  2280. [Physical Memory Array (Type 16) - Length 23 - Handle 0007h]
  2281. Location 03h - SystemBoard/Motherboard
  2282. Use 03h - System Memory
  2283. Memory Error Correction 03h - None
  2284. Maximum Capacity 33554432KB
  2285. Number of Memory Devices 4
  2286. [Onboard Devices Information (Type 10) - Length 6 - Handle 0026h]
  2287. Number of Devices 1
  2288. 01: Type Video [enabled]
  2289. [OEM Strings (Type 11) - Length 5 - Handle 0027h]
  2290. Number of Strings 1
  2291. [System Configuration Options (Type 12) - Length 5 - Handle 0028h]
  2292. [Memory Device (Type 17) - Length 34 - Handle 0040h]
  2293. Physical Memory Array Handle 0007h
  2294. Total Width 64 bits
  2295. Data Width 64 bits
  2296. Size 4096MB
  2297. Form Factor 09h - DIMM
  2298. Device Locator ChannelA-DIMM0
  2299. Bank Locator BANK 0
  2300. Memory Type 18h - Specification Reserved
  2301. Type Detail 0080h - Synchronous
  2302. Speed 1333MHz
  2303. Manufacturer Hynix/Hyundai
  2304. Part Number HMT351U6CFR8C-H9
  2305. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0041h]
  2306. Starting Address 00000000h
  2307. Ending Address 003fffffh
  2308. Memory Device Handle 0040h
  2309. Mem Array Mapped Adr Handle 0047h
  2310. Interleave Position 01
  2311. Interleave Data Depth 02
  2312. [Memory Device (Type 17) - Length 34 - Handle 0042h]
  2313. Physical Memory Array Handle 0007h
  2314. Total Width 0 bits
  2315. Data Width 0 bits
  2316. Form Factor 09h - DIMM
  2317. Device Locator ChannelA-DIMM1
  2318. Bank Locator BANK 1
  2319. Memory Type 02h - Unknown
  2320. Type Detail 0000h -
  2321. Speed 0MHz
  2322. [Processor Information (Type 4) - Length 42 - Handle 0043h]
  2323. Socket Designation Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
  2324. Processor Type Central Processor
  2325. Processor Family c6h - Specification Reserved
  2326. Processor Manufacturer Intel
  2327. Processor ID a7060200fffbebbf
  2328. Processor Version Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
  2329. Processor Voltage 8bh - 1.1V
  2330. External Clock 100MHz
  2331. Max Speed 7000MHz
  2332. Current Speed 3300MHz
  2333. Status Enabled Populated
  2334. Processor Upgrade Other
  2335. L1 Cache Handle 0004h
  2336. L2 Cache Handle 0005h
  2337. L3 Cache Handle 0006h
  2338. [Memory Device (Type 17) - Length 34 - Handle 0044h]
  2339. Physical Memory Array Handle 0007h
  2340. Total Width 64 bits
  2341. Data Width 64 bits
  2342. Size 4096MB
  2343. Form Factor 09h - DIMM
  2344. Device Locator ChannelB-DIMM0
  2345. Bank Locator BANK 2
  2346. Memory Type 18h - Specification Reserved
  2347. Type Detail 0080h - Synchronous
  2348. Speed 1333MHz
  2349. Manufacturer 8325
  2350. Part Number FLFF65F-C8KL9
  2351. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0045h]
  2352. Starting Address 00400000h
  2353. Ending Address 007fffffh
  2354. Memory Device Handle 0044h
  2355. Mem Array Mapped Adr Handle 0047h
  2356. Interleave Position 02
  2357. Interleave Data Depth 02
  2358. [Memory Device (Type 17) - Length 34 - Handle 0046h]
  2359. Physical Memory Array Handle 0007h
  2360. Total Width 0 bits
  2361. Data Width 0 bits
  2362. Form Factor 09h - DIMM
  2363. Device Locator ChannelB-DIMM1
  2364. Bank Locator BANK 3
  2365. Memory Type 02h - Unknown
  2366. Type Detail 0000h -
  2367. Speed 0MHz
  2368. [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0047h]
  2369. Starting Address 00000000h
  2370. Ending Address 007fffffh
  2371. Memory Array Handle 0007h
  2372. Partition Width 04
  2373.  
  2374. ========================== Dump #4: Extra #1 ===========================
  2375.  
  2376. 0: kd> !verifier
  2377. Verify Flags Level 0x00000000
  2378. STANDARD FLAGS:
  2379. [X] (0x00000000) Automatic Checks
  2380. [ ] (0x00000001) Special pool
  2381. [ ] (0x00000002) Force IRQL checking
  2382. [ ] (0x00000008) Pool tracking
  2383. [ ] (0x00000010) I/O verification
  2384. [ ] (0x00000020) Deadlock detection
  2385. [ ] (0x00000080) DMA checking
  2386. [ ] (0x00000100) Security checks
  2387. [ ] (0x00000800) Miscellaneous checks
  2388. [ ] (0x00020000) DDI compliance checking
  2389. ADDITIONAL FLAGS:
  2390. [ ] (0x00000004) Randomized low resources simulation
  2391. [ ] (0x00000200) Force pending I/O requests
  2392. [ ] (0x00000400) IRP logging
  2393. [ ] (0x00002000) Invariant MDL checking for stack
  2394. [ ] (0x00004000) Invariant MDL checking for driver
  2395. [ ] (0x00008000) Power framework delay fuzzing
  2396. [ ] (0x00010000) Port/miniport interface checking
  2397. [ ] (0x00040000) Systematic low resources simulation
  2398. [ ] (0x00080000) DDI compliance checking (additional)
  2399. [ ] (0x00200000) NDIS/WIFI verification
  2400. [ ] (0x00800000) Kernel synchronization delay fuzzing
  2401. [ ] (0x01000000) VM switch verification
  2402. [ ] (0x02000000) Code integrity checks
  2403. [X] Indicates flag is enabled
  2404. Summary of All Verifier Statistics
  2405. RaiseIrqls 0x0
  2406. AcquireSpinLocks 0x0
  2407. Synch Executions 0x0
  2408. Trims 0x0
  2409. Pool Allocations Attempted 0x0
  2410. Pool Allocations Succeeded 0x0
  2411. Pool Allocations Succeeded SpecialPool 0x0
  2412. Pool Allocations With NO TAG 0x0
  2413. Pool Allocations Failed 0x0
  2414. Current paged pool allocations 0x0 for 00000000 bytes
  2415. Peak paged pool allocations 0x0 for 00000000 bytes
  2416. Current nonpaged pool allocations 0x0 for 00000000 bytes
  2417. Peak nonpaged pool allocations 0x0 for 00000000 bytes
  2418.  
  2419. ========================== Dump #4: Extra #2 ===========================
  2420.  
  2421. 0: kd> !thread
  2422. THREAD ffffbf074622b080 Cid 0a14.0590 Teb: 0000000000386000 Win32Thread: ffffbf07462c5040 RUNNING on processor 0
  2423. Not impersonating
  2424. GetUlongFromAddress: unable to read from fffff8062b61143c
  2425. Owning Process ffffbf0740de3080 Image: 347.09-notebook-win8-win7-64bit-internationa
  2426. Attached Process N/A Image: N/A
  2427. fffff78000000000: Unable to get shared data
  2428. Wait Start TickCount 130950
  2429. Context Switch Count 67 IdealProcessor: 0
  2430. ReadMemory error: Cannot get nt!KeMaximumIncrement value.
  2431. UserTime 00:00:00.000
  2432. KernelTime 00:00:00.000
  2433. Win32 Start Address 0x0000000000401230
  2434. Stack Init ffffb901b2c53c90 Current ffffb901b2c530b0
  2435. Base ffffb901b2c54000 Limit ffffb901b2c4e000 Call 0000000000000000
  2436. Priority 12 BasePriority 8 PriorityDecrement 2 IoPriority 2 PagePriority 5
  2437. Child-SP RetAddr : Args to Child : Call Site
  2438. ffffb901`b2c52e08 fffff806`2adefa29 : 00000000`0000000a ffffbf07`556b1042 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
  2439. ffffb901`b2c52e10 fffff806`2adebd29 : 00000000`00000000 fffff806`2ac956b9 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
  2440. ffffb901`b2c52f50 fffff806`2acc4d3b : fffff980`013faa30 ffffb901`b2c53128 fffff806`2b652780 fffff806`2b64f600 : nt!KiPageFault+0x469 (TrapFrame @ ffffb901`b2c52f50)
  2441. ffffb901`b2c530e0 fffff806`2acc07e8 : 00000000`00b3e000 80000000`6a8e1821 00000003`00000000 fffff806`2ad16b2a : nt!MiLogPageAccess+0x30b
  2442. ffffb901`b2c53170 fffff806`2b063c5f : ffffe38f`4fd7f000 ffffa781`6d349280 00000000`00000000 00000000`00000000 : nt!MmUnmapViewInSystemCache+0x988
  2443. ffffb901`b2c53290 fffff806`2ac86ae6 : 00000000`00b00000 ffffbf07`46356a20 ffffbf07`3b9103b8 00000000`00000001 : nt!CcUnmapVacb+0x63
  2444. ffffb901`b2c532d0 fffff806`2ac8bb7a : 00000000`00c00001 ffffbf07`3b6898a0 00000000`00400000 00000000`00000001 : nt!CcUnmapVacbArray+0x206
  2445. ffffb901`b2c53340 fffff806`2b064180 : 00000000`00c00000 00000000`00000000 ffffb901`b2c53480 ffffb901`b2c53490 : nt!CcGetVirtualAddress+0x40a
  2446. ffffb901`b2c533e0 fffff806`2ac8b0b9 : 00000000`00000000 00000000`00c00000 00000000`00000000 00000000`00000001 : nt!CcMapAndCopyFromCache+0x80
  2447. ffffb901`b2c53480 fffff806`3045a1ad : ffffb901`b2c535e0 00000000`00000000 ffffa781`00100000 00000000`00100000 : nt!CcCopyReadEx+0x139
  2448. ffffb901`b2c53530 fffff806`2a2373fb : 00000000`00000000 ffffb901`b2c53908 ffffb901`b2c538c8 00000000`032b0020 : Ntfs!NtfsCopyReadA+0x2ed
  2449. ffffb901`b2c53820 fffff806`2a2344d7 : ffffb901`b2c53930 ffffb901`b2c538c8 ffffbf07`449f1110 ffffbf07`449f1010 : FLTMGR!FltpPerformFastIoCall+0x16b
  2450. ffffb901`b2c53880 fffff806`2a26b405 : ffffb901`b2c54000 ffffb901`b2c4e000 ffffbf07`4622b080 fffff806`2aff8fce : FLTMGR!FltpPassThroughFastIo+0x107
  2451. ffffb901`b2c53900 fffff806`2b011b5f : ffffbf07`4657a100 00000000`00000000 00000000`00000000 ffffbf07`00000000 : FLTMGR!FltpFastIoRead+0x165
  2452. ffffb901`b2c539b0 fffff806`2adef478 : 00000000`0000026c 00000000`00000000 00000000`00000000 00000000`00000000 : nt!NtReadFile+0x37f
  2453. ffffb901`b2c53a90 00000000`76f11cfc : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28 (TrapFrame @ ffffb901`b2c53b00)
  2454. 00000000`031af308 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x76f11cfc
  2455.  
  2456.  
  2457. ========================================================================
  2458. ======================= Dump #5: ANALYZE VERBOSE =======================
  2459. ====================== File: 081020-26375-01.dmp =======================
  2460. ========================================================================
  2461.  
  2462. Mini Kernel Dump File: Only registers and stack trace are available
  2463. Windows 10 Kernel Version 19041 MP (4 procs) Free x64
  2464. Kernel base = 0xfffff806`7b000000 PsLoadedModuleList = 0xfffff806`7bc2a310
  2465. Debug session time: Mon Aug 10 17:49:54.155 2020 (UTC - 4:00)
  2466. System Uptime: 0 days 0:29:33.871
  2467.  
  2468. BugCheck 1A, {61941, 23ba113fa58, d, fffff28e61731b00}
  2469. *** WARNING: Unable to verify timestamp for win32k.sys
  2470. *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
  2471. Probably caused by : memory_corruption
  2472. Followup: memory_corruption
  2473.  
  2474. MEMORY_MANAGEMENT (1a)
  2475. # Any other values for parameter 1 must be individually examined.
  2476.  
  2477. Arguments:
  2478. Arg1: 0000000000061941, The subtype of the bugcheck.
  2479. Arg2: 0000023ba113fa58
  2480. Arg3: 000000000000000d
  2481. Arg4: fffff28e61731b00
  2482.  
  2483. Debugging Details:
  2484. DUMP_CLASS: 1
  2485. DUMP_QUALIFIER: 400
  2486. DUMP_TYPE: 2
  2487. BUGCHECK_STR: 0x1a_61941
  2488. CUSTOMER_CRASH_COUNT: 1
  2489. DEFAULT_BUCKET_ID: CODE_CORRUPTION
  2490.  
  2491. PROCESS_NAME: GTA5.exe
  2492.  
  2493. CURRENT_IRQL: 0
  2494. LAST_CONTROL_TRANSFER: from fffff8067b4020a6 to fffff8067b3ddb60
  2495. STACK_TEXT:
  2496. fffff28e`61731958 fffff806`7b4020a6 : 00000000`0000001a 00000000`00061941 0000023b`a113fa58 00000000`0000000d : nt!KeBugCheckEx
  2497. fffff28e`61731960 fffff806`7b3ebc1e : 0000023b`00000000 00000000`00000001 00000000`00000001 fffff28e`61731b80 : nt!MmAccessFault+0x1ef7a6
  2498. fffff28e`61731b00 00007ff7`4061b435 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x35e
  2499. 00000057`285ff5b8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff7`4061b435
  2500. STACK_COMMAND: kb
  2501. CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
  2502. fffff8067b384f3e-fffff8067b384f41 4 bytes - nt!MiFreeUltraMapping+32
  2503. [ a0 7d fb f6:40 be 7c f9 ]
  2504. fffff8067b3e4c13-fffff8067b3e4c14 2 bytes - nt!SwapContext+53 (+0x5fcd5)
  2505. [ 48 ff:4c 8b ]
  2506. fffff8067b3e4c1a-fffff8067b3e4c1d 4 bytes - nt!SwapContext+5a (+0x07)
  2507. [ 0f 1f 44 00:e8 01 08 64 ]
  2508. 10 errors : !nt (fffff8067b384f3e-fffff8067b3e4c1d)
  2509. MODULE_NAME: memory_corruption
  2510.  
  2511. IMAGE_NAME: memory_corruption
  2512.  
  2513. FOLLOWUP_NAME: memory_corruption
  2514. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  2515. MEMORY_CORRUPTOR: LARGE
  2516. FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
  2517. BUCKET_ID: MEMORY_CORRUPTION_LARGE
  2518. PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
  2519. TARGET_TIME: 2020-08-10T21:49:54.000Z
  2520. SUITE_MASK: 272
  2521. PRODUCT_TYPE: 1
  2522. USER_LCID: 0
  2523. FAILURE_ID_HASH_STRING: km:memory_corruption_large
  2524. FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
  2525. Followup: memory_corruption
  2526.  
  2527. ====================== Dump #5: 3RD PARTY DRIVERS ======================
  2528.  
  2529. Jul 21 2014 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
  2530. Sep 04 2014 - nvvad64v.sys - Nvidia Virtual Audio driver http://www.nvidia.com/
  2531. Sep 06 2014 - NvStreamKms.sys - Nvidia Streaming Kernel Service http://www.nvidia.com/
  2532. Mar 31 2015 - HWiNFO64A.SYS - HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
  2533. Jul 07 2015 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
  2534. May 26 2020 - rt640x64.sys - Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
  2535. Jul 05 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
  2536.  
  2537. ================== Dump #5: 3RD PARTY DRIVERS (FULL) ===================
  2538.  
  2539. Image path: \SystemRoot\system32\drivers\nvhda64v.sys
  2540. Image name: nvhda64v.sys
  2541. Search : https://www.google.com/search?q=nvhda64v.sys
  2542. ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
  2543. Timestamp : Mon Jul 21 2014
  2544.  
  2545. Image path: \SystemRoot\system32\drivers\nvvad64v.sys
  2546. Image name: nvvad64v.sys
  2547. Search : https://www.google.com/search?q=nvvad64v.sys
  2548. ADA Info : Nvidia Virtual Audio driver http://www.nvidia.com/
  2549. Timestamp : Thu Sep 4 2014
  2550.  
  2551. Image path: \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
  2552. Image name: NvStreamKms.sys
  2553. Search : https://www.google.com/search?q=NvStreamKms.sys
  2554. ADA Info : Nvidia Streaming Kernel Service http://www.nvidia.com/
  2555. Timestamp : Sat Sep 6 2014
  2556.  
  2557. Image path: \??\C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS
  2558. Image name: HWiNFO64A.SYS
  2559. Search : https://www.google.com/search?q=HWiNFO64A.SYS
  2560. ADA Info : HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
  2561. Timestamp : Tue Mar 31 2015
  2562.  
  2563. Image path: \SystemRoot\System32\drivers\TeeDriverW8x64.sys
  2564. Image name: TeeDriverW8x64.sys
  2565. Search : https://www.google.com/search?q=TeeDriverW8x64.sys
  2566. ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
  2567. Timestamp : Tue Jul 7 2015
  2568.  
  2569. Image path: \SystemRoot\System32\drivers\rt640x64.sys
  2570. Image name: rt640x64.sys
  2571. Search : https://www.google.com/search?q=rt640x64.sys
  2572. ADA Info : Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
  2573. Timestamp : Tue May 26 2020
  2574.  
  2575. Image name: nvlddmkm.sys
  2576. Search : https://www.google.com/search?q=nvlddmkm.sys
  2577. ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
  2578. Timestamp : Sun Jul 5 2020
  2579.  
  2580. ====================== Dump #5: MICROSOFT DRIVERS ======================
  2581.  
  2582. ACPI.sys ACPI Driver for NT (Microsoft)
  2583. acpiex.sys ACPIEx Driver (Microsoft)
  2584. afd.sys Ancillary Function Driver for WinSock (Microsoft)
  2585. afunix.sys AF_UNIX Socket Provider driver (Microsoft)
  2586. ahcache.sys Application Compatibility Cache (Microsoft)
  2587. atapi.sys ATAPI IDE MiniPort driver (Microsoft)
  2588. ataport.SYS ATAPI Driver Extension (Microsoft)
  2589. bam.sys BAM Kernal driver (Microsoft)
  2590. BasicDisplay.sys Basic Display driver (Microsoft)
  2591. BasicRender.sys Basic Render driver (Microsoft)
  2592. Beep.SYS BEEP driver (Microsoft)
  2593. bindflt.sys Windows Bind Filter driver (Microsoft)
  2594. BOOTVID.dll VGA Boot Driver (Microsoft)
  2595. bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
  2596. cdd.dll Canonical Display Driver (Microsoft)
  2597. cdfs.sys CD-ROM File System Driver (Microsoft)
  2598. cdrom.sys SCSI CD-ROM Driver (Microsoft)
  2599. CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
  2600. CI.dll Code Integrity Module (Microsoft)
  2601. CimFS.SYS Consumer IR Class Driver for eHome (Microsoft)
  2602. CLASSPNP.SYS SCSI Class System Dll (Microsoft)
  2603. cldflt.sys Cloud Files Mini Filter driver (Microsoft)
  2604. CLFS.SYS Common Log File System Driver (Microsoft)
  2605. clipsp.sys CLIP Service (Microsoft)
  2606. cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
  2607. cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
  2608. CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
  2609. condrv.sys Console Driver (Microsoft)
  2610. crashdmp.sys Crash Dump driver (Microsoft)
  2611. csc.sys Windows Client Side Caching driver (Microsoft)
  2612. dfsc.sys DFS Namespace Client Driver (Microsoft)
  2613. disk.sys PnP Disk Driver (Microsoft)
  2614. drmk.sys Digital Rights Management (DRM) driver (Microsoft)
  2615. dump_atapi.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  2616. dump_dumpata.sys ATAPI Dump Driver
  2617. dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  2618. dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
  2619. dxgmms2.sys DirectX Graphics MMS
  2620. EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
  2621. fastfat.SYS Fast FAT File System Driver (Microsoft)
  2622. filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
  2623. fileinfo.sys FileInfo Filter Driver (Microsoft)
  2624. FLTMGR.SYS Filesystem Filter Manager (Microsoft)
  2625. Fs_Rec.sys File System Recognizer Driver (Microsoft)
  2626. fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
  2627. fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
  2628. gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
  2629. hal.dll Hardware Abstraction Layer DLL (Microsoft)
  2630. HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
  2631. HdAudio.sys High Definition Audio Function driver (Microsoft)
  2632. HIDCLASS.SYS Hid Class Library (Microsoft)
  2633. HIDPARSE.SYS Hid Parsing Library (Microsoft)
  2634. hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
  2635. HTTP.sys HTTP Protocol Stack (Microsoft)
  2636. intelpep.sys Intel Power Engine Plugin (Microsoft)
  2637. intelppm.sys Processor Device Driver (Microsoft)
  2638. IntelTA.sys Intel Telemetry Driver
  2639. iorate.sys I/O rate control Filter (Microsoft)
  2640. kbdclass.sys Keyboard Class Driver (Microsoft)
  2641. kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
  2642. kd.dll Local Kernal Debugger (Microsoft)
  2643. kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
  2644. ks.sys Kernal CSA Library (Microsoft)
  2645. ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
  2646. ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
  2647. ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
  2648. lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
  2649. luafv.sys LUA File Virtualization Filter Driver (Microsoft)
  2650. mcupdate_GenuineIntel.dll Intel Microcode Update Library (Microsoft)
  2651. mmcss.sys MMCSS Driver (Microsoft)
  2652. monitor.sys Monitor Driver (Microsoft)
  2653. mouclass.sys Mouse Class Driver (Microsoft)
  2654. mouhid.sys HID Mouse Filter Driver (Microsoft)
  2655. mountmgr.sys Mount Point Manager (Microsoft)
  2656. MpKslDrv.sys Microsoft Anti-malware Protection driver
  2657. mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
  2658. mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
  2659. mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
  2660. Msfs.SYS Mailslot driver (Microsoft)
  2661. msisadrv.sys ISA Driver (Microsoft)
  2662. mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
  2663. msquic.sys Windows QUIC Driver
  2664. msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
  2665. mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
  2666. mssmbios.sys System Management BIOS driver (Microsoft)
  2667. mup.sys Multiple UNC Provider driver (Microsoft)
  2668. ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
  2669. ndiscap.sys Microsoft NDIS Packet Capture Filter Driver
  2670. NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
  2671. Ndu.sys Network Data Usage Monitoring driver (Microsoft)
  2672. netbios.sys NetBIOS Interface driver (Microsoft)
  2673. netbt.sys MBT Transport driver (Microsoft)
  2674. NETIO.SYS Network I/O Subsystem (Microsoft)
  2675. Npfs.SYS NPFS driver (Microsoft)
  2676. npsvctrig.sys Named pipe service triggers (Microsoft)
  2677. nsiproxy.sys NSI Proxy driver (Microsoft)
  2678. Ntfs.sys NT File System Driver (Microsoft)
  2679. ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
  2680. ntosext.sys NTOS Extension Host driver (Microsoft)
  2681. Null.SYS NULL Driver (Microsoft)
  2682. pacer.sys QoS Packet Scheduler (Microsoft)
  2683. parport.sys Parallel Port Driver (Microsoft)
  2684. partmgr.sys Partition driver (Microsoft)
  2685. pci.sys NT Plug and Play PCI Enumerator (Microsoft)
  2686. pciide.sys Generic PCI IDE Bus Driver (Microsoft)
  2687. PCIIDEX.SYS PCI IDE Bus driver file (Microsoft)
  2688. pcw.sys Performance Counter Driver (Microsoft)
  2689. pdc.sys Power Dependency Coordinator Driver (Microsoft)
  2690. peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
  2691. portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
  2692. PSHED.dll Platform Specific Hardware Error driver (Microsoft)
  2693. rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
  2694. rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
  2695. rdyboost.sys ReadyBoost Driver (Microsoft)
  2696. rspndr.sys Link-Layer Topology Responder driver (Microsoft)
  2697. serenum.sys Serial Port Enumerator (Microsoft)
  2698. serial.sys Serial Device Driver
  2699. SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
  2700. SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
  2701. spaceport.sys Storage Spaces driver (Microsoft)
  2702. srv2.sys Smb 2.0 Server driver (Microsoft)
  2703. srvnet.sys Server Network driver (Microsoft)
  2704. storqosflt.sys Storage QoS Filter driver (Microsoft)
  2705. swenum.sys Plug and Play Software Device Enumerator (Microsoft)
  2706. tbs.sys Export driver for kernel mode TPM API (Microsoft)
  2707. tcpip.sys TCP/IP Protocol driver (Microsoft)
  2708. tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
  2709. TDI.SYS TDI Wrapper driver (Microsoft)
  2710. tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
  2711. tm.sys Kernel Transaction Manager driver (Microsoft)
  2712. umbus.sys User-Mode Bus Enumerator (Microsoft)
  2713. usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
  2714. USBD.SYS Universal Serial Bus Driver (Microsoft)
  2715. usbehci.sys EHCI eUSB Miniport Driver (Microsoft)
  2716. usbhub.sys Default Hub Driver for USB (Microsoft)
  2717. USBPORT.SYS USB 1.1 & 2.0 Port Driver (Microsoft)
  2718. vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
  2719. Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
  2720. volmgr.sys Volume Manager Driver (Microsoft)
  2721. volmgrx.sys Volume Manager Extension Driver (Microsoft)
  2722. volsnap.sys Volume Shadow Copy driver (Microsoft)
  2723. volume.sys Volume driver (Microsoft)
  2724. vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
  2725. watchdog.sys Watchdog driver (Microsoft)
  2726. wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
  2727. Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
  2728. WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
  2729. WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
  2730. WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
  2731. werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
  2732. wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
  2733. win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
  2734. win32kbase.sys Base Win32k Kernel Driver (Microsoft)
  2735. win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
  2736. WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
  2737. WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
  2738. winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
  2739. WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
  2740. Wof.sys Windows Overlay Filter (Microsoft)
  2741. WppRecorder.sys WPP Trace Recorder (Microsoft)
  2742.  
  2743. ====================== Dump #5: UNLOADED MODULES =======================
  2744.  
  2745. fffff806`85100000 fffff806`85110000 dump_ataport
  2746. fffff806`85120000 fffff806`8512e000 dump_atapi.s
  2747. fffff806`85150000 fffff806`8516e000 dump_dumpfve
  2748. fffff806`84b40000 fffff806`84b5c000 dam.sys
  2749. fffff806`7d650000 fffff806`7d662000 WdBoot.sys
  2750. fffff806`7e650000 fffff806`7e660000 hwpolicy.sys
  2751.  
  2752. ====================== Dump #5: BIOS INFORMATION =======================
  2753.  
  2754. [SMBIOS Data Tables v2.7]
  2755. [DMI Version - 0]
  2756. [2.0 Calling Convention - No]
  2757. [Table Size - 3016 bytes]
  2758. [BIOS Information (Type 0) - Length 24 - Handle 0000h]
  2759. Vendor American Megatrends Inc.
  2760. BIOS Version F6
  2761. BIOS Starting Address Segment f000
  2762. BIOS Release Date 02/16/2012
  2763. BIOS ROM Size 280000
  2764. BIOS Characteristics
  2765. 07: - PCI Supported
  2766. 11: - Upgradeable FLASH BIOS
  2767. 12: - BIOS Shadowing Supported
  2768. 15: - CD-Boot Supported
  2769. 16: - Selectable Boot Supported
  2770. 17: - BIOS ROM Socketed
  2771. 19: - EDD Supported
  2772. 23: - 1.2MB Floppy Supported
  2773. 24: - 720KB Floppy Supported
  2774. 25: - 2.88MB Floppy Supported
  2775. 26: - Print Screen Device Supported
  2776. 27: - Keyboard Services Supported
  2777. 28: - Serial Services Supported
  2778. 29: - Printer Services Supported
  2779. 32: - BIOS Vendor Reserved
  2780. BIOS Characteristic Extensions
  2781. 00: - ACPI Supported
  2782. 01: - USB Legacy Supported
  2783. 08: - BIOS Boot Specification Supported
  2784. 10: - Specification Reserved
  2785. 11: - Specification Reserved
  2786. BIOS Major Revision 4
  2787. BIOS Minor Revision 6
  2788. EC Firmware Major Revision 255
  2789. EC Firmware Minor Revision 255
  2790. [System Information (Type 1) - Length 27 - Handle 0001h]
  2791. Manufacturer Gigabyte Tecohnology Co., Ltd.
  2792. Product Name H61M-DS2
  2793. UUID 00000000-0000-0000-0000-000000000000
  2794. Wakeup Type Power Switch
  2795. [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
  2796. Manufacturer Gigabyte Tecohnology Co., Ltd.
  2797. Product H61M-DS2
  2798. Version x.x
  2799. Feature Flags 09h
  2800. -926632224: - -926632176: - «¯þø
  2801. Chassis Handle 0003h
  2802. Board Type 0ah - Processor/Memory Module
  2803. Number of Child Handles 0
  2804. [System Enclosure (Type 3) - Length 22 - Handle 0003h]
  2805. Manufacturer Gigabyte Tecohnology Co., Ltd.
  2806. Chassis Type Desktop
  2807. Bootup State Safe
  2808. Power Supply State Safe
  2809. Thermal State Safe
  2810. Security Status None
  2811. OEM Defined 0
  2812. Height 0U
  2813. Number of Power Cords 1
  2814. Number of Contained Elements 0
  2815. Contained Element Size 0
  2816. [Cache Information (Type 7) - Length 19 - Handle 0004h]
  2817. Cache Configuration 0181h - WB Enabled Int NonSocketed L2
  2818. Maximum Cache Size 0020h - 32K
  2819. Installed Size 0020h - 32K
  2820. Supported SRAM Type 0040h - Asynchronous
  2821. Current SRAM Type 0040h - Asynchronous
  2822. Cache Speed 0ns
  2823. Error Correction Type Multi-Bit ECC
  2824. System Cache Type Other
  2825. Associativity 16-way Set-Associative
  2826. [Cache Information (Type 7) - Length 19 - Handle 0005h]
  2827. Cache Configuration 0182h - WB Enabled Int NonSocketed L3
  2828. Maximum Cache Size 0100h - 256K
  2829. Installed Size 0100h - 256K
  2830. Supported SRAM Type 0040h - Asynchronous
  2831. Current SRAM Type 0040h - Asynchronous
  2832. Cache Speed 0ns
  2833. Error Correction Type Multi-Bit ECC
  2834. System Cache Type Instruction
  2835. Associativity 16-way Set-Associative
  2836. [Cache Information (Type 7) - Length 19 - Handle 0006h]
  2837. Cache Configuration 0183h - WB Enabled Int NonSocketed L4
  2838. Maximum Cache Size 0c00h - 3072K
  2839. Installed Size 0c00h - 3072K
  2840. Supported SRAM Type 0040h - Asynchronous
  2841. Current SRAM Type 0040h - Asynchronous
  2842. Cache Speed 0ns
  2843. Error Correction Type Multi-Bit ECC
  2844. System Cache Type Instruction
  2845. Associativity Specification Reserved
  2846. [Physical Memory Array (Type 16) - Length 23 - Handle 0007h]
  2847. Location 03h - SystemBoard/Motherboard
  2848. Use 03h - System Memory
  2849. Memory Error Correction 03h - None
  2850. Maximum Capacity 33554432KB
  2851. Number of Memory Devices 4
  2852. [Onboard Devices Information (Type 10) - Length 6 - Handle 0026h]
  2853. Number of Devices 1
  2854. 01: Type Video [enabled]
  2855. [OEM Strings (Type 11) - Length 5 - Handle 0027h]
  2856. Number of Strings 1
  2857. [System Configuration Options (Type 12) - Length 5 - Handle 0028h]
  2858. [Memory Device (Type 17) - Length 34 - Handle 0040h]
  2859. Physical Memory Array Handle 0007h
  2860. Total Width 64 bits
  2861. Data Width 64 bits
  2862. Size 4096MB
  2863. Form Factor 09h - DIMM
  2864. Device Locator ChannelA-DIMM0
  2865. Bank Locator BANK 0
  2866. Memory Type 18h - Specification Reserved
  2867. Type Detail 0080h - Synchronous
  2868. Speed 1333MHz
  2869. Manufacturer Hynix/Hyundai
  2870. Part Number HMT351U6CFR8C-H9
  2871. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0041h]
  2872. Starting Address 00000000h
  2873. Ending Address 003fffffh
  2874. Memory Device Handle 0040h
  2875. Mem Array Mapped Adr Handle 0047h
  2876. Interleave Position 01
  2877. Interleave Data Depth 02
  2878. [Memory Device (Type 17) - Length 34 - Handle 0042h]
  2879. Physical Memory Array Handle 0007h
  2880. Total Width 0 bits
  2881. Data Width 0 bits
  2882. Form Factor 09h - DIMM
  2883. Device Locator ChannelA-DIMM1
  2884. Bank Locator BANK 1
  2885. Memory Type 02h - Unknown
  2886. Type Detail 0000h -
  2887. Speed 0MHz
  2888. [Processor Information (Type 4) - Length 42 - Handle 0043h]
  2889. Socket Designation Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
  2890. Processor Type Central Processor
  2891. Processor Family c6h - Specification Reserved
  2892. Processor Manufacturer Intel
  2893. Processor ID a7060200fffbebbf
  2894. Processor Version Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
  2895. Processor Voltage 8bh - 1.1V
  2896. External Clock 100MHz
  2897. Max Speed 7000MHz
  2898. Current Speed 3300MHz
  2899. Status Enabled Populated
  2900. Processor Upgrade Other
  2901. L1 Cache Handle 0004h
  2902. L2 Cache Handle 0005h
  2903. L3 Cache Handle 0006h
  2904. [Memory Device (Type 17) - Length 34 - Handle 0044h]
  2905. Physical Memory Array Handle 0007h
  2906. Total Width 64 bits
  2907. Data Width 64 bits
  2908. Size 4096MB
  2909. Form Factor 09h - DIMM
  2910. Device Locator ChannelB-DIMM0
  2911. Bank Locator BANK 2
  2912. Memory Type 18h - Specification Reserved
  2913. Type Detail 0080h - Synchronous
  2914. Speed 1333MHz
  2915. Manufacturer 8325
  2916. Part Number FLFF65F-C8KL9
  2917. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0045h]
  2918. Starting Address 00400000h
  2919. Ending Address 007fffffh
  2920. Memory Device Handle 0044h
  2921. Mem Array Mapped Adr Handle 0047h
  2922. Interleave Position 02
  2923. Interleave Data Depth 02
  2924. [Memory Device (Type 17) - Length 34 - Handle 0046h]
  2925. Physical Memory Array Handle 0007h
  2926. Total Width 0 bits
  2927. Data Width 0 bits
  2928. Form Factor 09h - DIMM
  2929. Device Locator ChannelB-DIMM1
  2930. Bank Locator BANK 3
  2931. Memory Type 02h - Unknown
  2932. Type Detail 0000h -
  2933. Speed 0MHz
  2934. [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0047h]
  2935. Starting Address 00000000h
  2936. Ending Address 007fffffh
  2937. Memory Array Handle 0007h
  2938. Partition Width 04
  2939.  
  2940. ========================== Dump #5: Extra #1 ===========================
  2941.  
  2942. 3: kd> !verifier
  2943. Verify Flags Level 0x00000000
  2944. STANDARD FLAGS:
  2945. [X] (0x00000000) Automatic Checks
  2946. [ ] (0x00000001) Special pool
  2947. [ ] (0x00000002) Force IRQL checking
  2948. [ ] (0x00000008) Pool tracking
  2949. [ ] (0x00000010) I/O verification
  2950. [ ] (0x00000020) Deadlock detection
  2951. [ ] (0x00000080) DMA checking
  2952. [ ] (0x00000100) Security checks
  2953. [ ] (0x00000800) Miscellaneous checks
  2954. [ ] (0x00020000) DDI compliance checking
  2955. ADDITIONAL FLAGS:
  2956. [ ] (0x00000004) Randomized low resources simulation
  2957. [ ] (0x00000200) Force pending I/O requests
  2958. [ ] (0x00000400) IRP logging
  2959. [ ] (0x00002000) Invariant MDL checking for stack
  2960. [ ] (0x00004000) Invariant MDL checking for driver
  2961. [ ] (0x00008000) Power framework delay fuzzing
  2962. [ ] (0x00010000) Port/miniport interface checking
  2963. [ ] (0x00040000) Systematic low resources simulation
  2964. [ ] (0x00080000) DDI compliance checking (additional)
  2965. [ ] (0x00200000) NDIS/WIFI verification
  2966. [ ] (0x00800000) Kernel synchronization delay fuzzing
  2967. [ ] (0x01000000) VM switch verification
  2968. [ ] (0x02000000) Code integrity checks
  2969. [X] Indicates flag is enabled
  2970. Summary of All Verifier Statistics
  2971. RaiseIrqls 0x0
  2972. AcquireSpinLocks 0x0
  2973. Synch Executions 0x0
  2974. Trims 0x0
  2975. Pool Allocations Attempted 0x0
  2976. Pool Allocations Succeeded 0x0
  2977. Pool Allocations Succeeded SpecialPool 0x0
  2978. Pool Allocations With NO TAG 0x0
  2979. Pool Allocations Failed 0x0
  2980. Current paged pool allocations 0x0 for 00000000 bytes
  2981. Peak paged pool allocations 0x0 for 00000000 bytes
  2982. Current nonpaged pool allocations 0x0 for 00000000 bytes
  2983. Peak nonpaged pool allocations 0x0 for 00000000 bytes
  2984.  
  2985. ========================== Dump #5: Extra #2 ===========================
  2986.  
  2987. 3: kd> !thread
  2988. THREAD ffff980396139080 Cid 1c5c.1674 Teb: 0000005727395000 Win32Thread: ffff980397645c20 RUNNING on processor 3
  2989. Not impersonating
  2990. GetUlongFromAddress: unable to read from fffff8067bc1143c
  2991. Owning Process ffff98039535e080 Image: GTA5.exe
  2992. Attached Process N/A Image: N/A
  2993. fffff78000000000: Unable to get shared data
  2994. Wait Start TickCount 113527
  2995. Context Switch Count 4889304 IdealProcessor: 0
  2996. ReadMemory error: Cannot get nt!KeMaximumIncrement value.
  2997. UserTime 00:00:00.000
  2998. KernelTime 00:00:00.000
  2999. Win32 Start Address 0x00007ff74058c6e0
  3000. Stack Init fffff28e61731c90 Current fffff28e61731980
  3001. Base fffff28e61732000 Limit fffff28e6172c000 Call 0000000000000000
  3002. Priority 9 BasePriority 9 PriorityDecrement 0 IoPriority 2 PagePriority 5
  3003. Child-SP RetAddr : Args to Child : Call Site
  3004. fffff28e`61731958 fffff806`7b4020a6 : 00000000`0000001a 00000000`00061941 0000023b`a113fa58 00000000`0000000d : nt!KeBugCheckEx
  3005. fffff28e`61731960 fffff806`7b3ebc1e : 0000023b`00000000 00000000`00000001 00000000`00000001 fffff28e`61731b80 : nt!MmAccessFault+0x1ef7a6
  3006. fffff28e`61731b00 00007ff7`4061b435 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x35e (TrapFrame @ fffff28e`61731b00)
  3007. 00000057`285ff5b8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff7`4061b435
  3008.  
  3009.  
  3010. ========================================================================
  3011. ======================= Dump #6: ANALYZE VERBOSE =======================
  3012. ====================== File: 081020-25140-01.dmp =======================
  3013. ========================================================================
  3014.  
  3015. Mini Kernel Dump File: Only registers and stack trace are available
  3016. Windows 10 Kernel Version 19041 MP (4 procs) Free x64
  3017. Kernel base = 0xfffff802`27200000 PsLoadedModuleList = 0xfffff802`27e2a310
  3018. Debug session time: Sun Aug 9 19:52:15.882 2020 (UTC - 4:00)
  3019. System Uptime: 0 days 10:01:45.386
  3020.  
  3021. BugCheck A, {1ddbb5, 2, 0, fffff802274acd4d}
  3022. *** WARNING: Unable to verify timestamp for win32k.sys
  3023. *** ERROR: Module load completed but symbols could not be loaded for win32k.sys
  3024. Probably caused by : memory_corruption
  3025. Followup: memory_corruption
  3026.  
  3027. IRQL_NOT_LESS_OR_EQUAL (a)
  3028. An attempt was made to access a pageable (or completely invalid) address at an
  3029. interrupt request level (IRQL) that is too high. This is usually
  3030. caused by drivers using improper addresses.
  3031. If a kernel debugger is available get the stack backtrace.
  3032.  
  3033. Arguments:
  3034. Arg1: 00000000001ddbb5, memory referenced
  3035. Arg2: 0000000000000002, IRQL
  3036. Arg3: 0000000000000000, bitfield :
  3037. bit 0 : value 0 = read operation, 1 = write operation
  3038. bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
  3039. Arg4: fffff802274acd4d, address which referenced memory
  3040.  
  3041. Debugging Details:
  3042. DUMP_CLASS: 1
  3043. DUMP_QUALIFIER: 400
  3044. DUMP_TYPE: 2
  3045. READ_ADDRESS: fffff80227efa388: Unable to get MiVisibleState
  3046. 00000000001ddbb5
  3047. CURRENT_IRQL: 2
  3048. FAULTING_IP:
  3049. nt!MiInsertPageInFreeOrZeroedList+2dd
  3050. fffff802`274acd4d 0fb70c11 movzx ecx,word ptr [rcx+rdx]
  3051. CUSTOMER_CRASH_COUNT: 1
  3052. DEFAULT_BUCKET_ID: CODE_CORRUPTION
  3053. BUGCHECK_STR: AV
  3054.  
  3055. PROCESS_NAME: System
  3056.  
  3057. TRAP_FRAME: ffffda8a37616800 -- (.trap 0xffffda8a37616800)
  3058. NOTE: The trap frame does not contain all registers.
  3059. Some register values may be zeroed or incorrect.
  3060. rax=0000000000000001 rbx=0000000000000000 rcx=00000000000001e0
  3061. rdx=00000000001dd9d5 rsi=0000000000000000 rdi=0000000000000000
  3062. rip=fffff802274acd4d rsp=ffffda8a37616990 rbp=ffffda8a37616a29
  3063. r8=ffffdc039c446510 r9=0000000000001000 r10=000000000000001e
  3064. r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
  3065. r14=0000000000000000 r15=0000000000000000
  3066. iopl=0 nv up ei pl nz na pe nc
  3067. nt!MiInsertPageInFreeOrZeroedList+0x2dd:
  3068. fffff802`274acd4d 0fb70c11 movzx ecx,word ptr [rcx+rdx] ds:00000000`001ddbb5=????
  3069. Resetting default scope
  3070. LAST_CONTROL_TRANSFER: from fffff802275efa29 to fffff802275ddb60
  3071. STACK_TEXT:
  3072. ffffda8a`376166b8 fffff802`275efa29 : 00000000`0000000a 00000000`001ddbb5 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
  3073. ffffda8a`376166c0 fffff802`275ebd29 : ffff9d01`ae1b0140 ffffdc03`a7df5040 ffff9d01`ae1a5180 fffff802`275e4d72 : nt!KiBugCheckDispatch+0x69
  3074. ffffda8a`37616800 fffff802`274acd4d : 00000000`00000000 ffff9780`00000001 00000000`00000000 fffff802`27e4e680 : nt!KiPageFault+0x469
  3075. ffffda8a`37616990 fffff802`2775877c : 00000000`00064e1e 00000000`00000000 00000000`0000001e 00000000`00000001 : nt!MiInsertPageInFreeOrZeroedList+0x2dd
  3076. ffffda8a`37616a90 fffff802`277588b3 : fffff802`27e50b40 00000000`00000000 fffff802`00000000 00000000`00000229 : nt!MiPruneStandbyPages+0x380
  3077. ffffda8a`37616b20 fffff802`27433f45 : ffffdc03`a7df5040 fffff802`27758820 ffffdc03`9c557a60 fffff802`27e523e0 : nt!MiRebalanceZeroFreeLists+0x93
  3078. ffffda8a`37616b70 fffff802`27546735 : ffffdc03`a7df5040 00000000`00000080 ffffdc03`9c496040 00000000`00000001 : nt!ExpWorkerThread+0x105
  3079. ffffda8a`37616c10 fffff802`275e51b8 : ffff9d01`ae2f6180 ffffdc03`a7df5040 fffff802`275466e0 00000000`00000000 : nt!PspSystemThreadStartup+0x55
  3080. ffffda8a`37616c60 00000000`00000000 : ffffda8a`37617000 ffffda8a`37611000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
  3081. STACK_COMMAND: kb
  3082. CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
  3083. fffff80227458de2 - nt!MiTradeTransitionPage+9a
  3084. [ fa:97 ]
  3085. fffff802274ac017 - nt!MiDeleteBatch+f7 (+0x53235)
  3086. [ fa:97 ]
  3087. fffff802274ac021 - nt!MiDeleteBatch+101 (+0x0a)
  3088. [ fa:97 ]
  3089. fffff802274ac02b - nt!MiDeleteBatch+10b (+0x0a)
  3090. [ fa:97 ]
  3091. fffff802274ac0c9 - nt!MiDeleteBatch+1a9 (+0x9e)
  3092. [ fa:97 ]
  3093. fffff802274ac0dd - nt!MiDeleteBatch+1bd (+0x14)
  3094. [ fa:97 ]
  3095. fffff802274ac0e7 - nt!MiDeleteBatch+1c7 (+0x0a)
  3096. [ fa:97 ]
  3097. fffff802274ac1d7 - nt!MiDeleteBatch+2b7 (+0xf0)
  3098. [ fa:97 ]
  3099. fffff802274ac24a - nt!MiDeleteBatch+32a (+0x73)
  3100. [ fa:97 ]
  3101. fffff802274ac47b - nt!MiZeroLargePages+20b (+0x231)
  3102. [ fa:97 ]
  3103. fffff802274ac4f8 - nt!MiZeroLargePages+288 (+0x7d)
  3104. [ fa:97 ]
  3105. fffff802274aca9c - nt!MiInsertPageInFreeOrZeroedList+2c (+0x5a4)
  3106. [ fa:97 ]
  3107. fffff802275467b6 - nt!MiDeleteNonPagedPoolTail+46 (+0x99d1a)
  3108. [ fa:97 ]
  3109. fffff80227584f3e-fffff80227584f41 4 bytes - nt!MiFreeUltraMapping+32 (+0x3e788)
  3110. [ a0 7d fb f6:60 fb f6 ed ]
  3111. fffff802277587f3 - nt!MiPruneStandbyPages+3f7 (+0x1d38b5)
  3112. [ fa:97 ]
  3113. 18 errors : !nt (fffff80227458de2-fffff802277587f3)
  3114. MODULE_NAME: memory_corruption
  3115.  
  3116. IMAGE_NAME: memory_corruption
  3117.  
  3118. FOLLOWUP_NAME: memory_corruption
  3119. DEBUG_FLR_IMAGE_TIMESTAMP: 0
  3120. MEMORY_CORRUPTOR: LARGE
  3121. FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE
  3122. BUCKET_ID: MEMORY_CORRUPTION_LARGE
  3123. PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_LARGE
  3124. TARGET_TIME: 2020-08-09T23:52:15.000Z
  3125. SUITE_MASK: 272
  3126. PRODUCT_TYPE: 1
  3127. USER_LCID: 0
  3128. FAILURE_ID_HASH_STRING: km:memory_corruption_large
  3129. FAILURE_ID_HASH: {e29154ac-69a4-0eb8-172a-a860f73c0a3c}
  3130. Followup: memory_corruption
  3131.  
  3132. ====================== Dump #6: 3RD PARTY DRIVERS ======================
  3133.  
  3134. Jul 21 2014 - nvhda64v.sys - Nvidia HDMI Audio Device http://www.nvidia.com/
  3135. Sep 04 2014 - nvvad64v.sys - Nvidia Virtual Audio driver http://www.nvidia.com/
  3136. Sep 06 2014 - NvStreamKms.sys - Nvidia Streaming Kernel Service http://www.nvidia.com/
  3137. Mar 31 2015 - HWiNFO64A.SYS - HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
  3138. Jul 07 2015 - TeeDriverW8x64.sys - Intel Management Engine Interface driver https://downloadcenter.intel.com/
  3139. May 26 2020 - rt640x64.sys - Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
  3140. Jul 05 2020 - nvlddmkm.sys - Nvidia Graphics Card driver http://www.nvidia.com/
  3141.  
  3142. ================== Dump #6: 3RD PARTY DRIVERS (FULL) ===================
  3143.  
  3144. Image path: \SystemRoot\system32\drivers\nvhda64v.sys
  3145. Image name: nvhda64v.sys
  3146. Search : https://www.google.com/search?q=nvhda64v.sys
  3147. ADA Info : Nvidia HDMI Audio Device http://www.nvidia.com/
  3148. Timestamp : Mon Jul 21 2014
  3149.  
  3150. Image path: \SystemRoot\system32\drivers\nvvad64v.sys
  3151. Image name: nvvad64v.sys
  3152. Search : https://www.google.com/search?q=nvvad64v.sys
  3153. ADA Info : Nvidia Virtual Audio driver http://www.nvidia.com/
  3154. Timestamp : Thu Sep 4 2014
  3155.  
  3156. Image path: \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
  3157. Image name: NvStreamKms.sys
  3158. Search : https://www.google.com/search?q=NvStreamKms.sys
  3159. ADA Info : Nvidia Streaming Kernel Service http://www.nvidia.com/
  3160. Timestamp : Sat Sep 6 2014
  3161.  
  3162. Image path: \??\C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS
  3163. Image name: HWiNFO64A.SYS
  3164. Search : https://www.google.com/search?q=HWiNFO64A.SYS
  3165. ADA Info : HWiNFO AMD64 Kernel driver https://www.hwinfo.com/
  3166. Timestamp : Tue Mar 31 2015
  3167.  
  3168. Image path: \SystemRoot\System32\drivers\TeeDriverW8x64.sys
  3169. Image name: TeeDriverW8x64.sys
  3170. Search : https://www.google.com/search?q=TeeDriverW8x64.sys
  3171. ADA Info : Intel Management Engine Interface driver https://downloadcenter.intel.com/
  3172. Timestamp : Tue Jul 7 2015
  3173.  
  3174. Image path: \SystemRoot\System32\drivers\rt640x64.sys
  3175. Image name: rt640x64.sys
  3176. Search : https://www.google.com/search?q=rt640x64.sys
  3177. ADA Info : Realtek NICDRV 8169 PCIe GBE Family Controller driver https://www.realtek.com/en/
  3178. Timestamp : Tue May 26 2020
  3179.  
  3180. Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_e92a0ac2e05fb2ca\nvlddmkm.sys
  3181. Image name: nvlddmkm.sys
  3182. Search : https://www.google.com/search?q=nvlddmkm.sys
  3183. ADA Info : Nvidia Graphics Card driver http://www.nvidia.com/
  3184. Timestamp : Sun Jul 5 2020
  3185.  
  3186. ====================== Dump #6: MICROSOFT DRIVERS ======================
  3187.  
  3188. ACPI.sys ACPI Driver for NT (Microsoft)
  3189. acpiex.sys ACPIEx Driver (Microsoft)
  3190. afd.sys Ancillary Function Driver for WinSock (Microsoft)
  3191. afunix.sys AF_UNIX Socket Provider driver (Microsoft)
  3192. ahcache.sys Application Compatibility Cache (Microsoft)
  3193. atapi.sys ATAPI IDE MiniPort driver (Microsoft)
  3194. ataport.SYS ATAPI Driver Extension (Microsoft)
  3195. bam.sys BAM Kernal driver (Microsoft)
  3196. BasicDisplay.sys Basic Display driver (Microsoft)
  3197. BasicRender.sys Basic Render driver (Microsoft)
  3198. Beep.SYS BEEP driver (Microsoft)
  3199. bindflt.sys Windows Bind Filter driver (Microsoft)
  3200. BOOTVID.dll VGA Boot Driver (Microsoft)
  3201. bowser.sys NT Lan Manager Datagram Receiver Driver (Microsoft)
  3202. cdd.dll Canonical Display Driver (Microsoft)
  3203. cdfs.sys CD-ROM File System Driver (Microsoft)
  3204. cdrom.sys SCSI CD-ROM Driver (Microsoft)
  3205. CEA.sys Event Aggregation Kernal Mode Library (Microsoft)
  3206. CI.dll Code Integrity Module (Microsoft)
  3207. CimFS.SYS Consumer IR Class Driver for eHome (Microsoft)
  3208. CLASSPNP.SYS SCSI Class System Dll (Microsoft)
  3209. cldflt.sys Cloud Files Mini Filter driver (Microsoft)
  3210. CLFS.SYS Common Log File System Driver (Microsoft)
  3211. clipsp.sys CLIP Service (Microsoft)
  3212. cmimcext.sys Kernal Configuration Manager Initial Con. Driver (Microsoft)
  3213. cng.sys Kernal Cryptography, Next Generation Driver (Microsoft)
  3214. CompositeBus.sys Multi-Transport Composite Bus Enumerator (Microsoft)
  3215. condrv.sys Console Driver (Microsoft)
  3216. crashdmp.sys Crash Dump driver (Microsoft)
  3217. csc.sys Windows Client Side Caching driver (Microsoft)
  3218. dfsc.sys DFS Namespace Client Driver (Microsoft)
  3219. disk.sys PnP Disk Driver (Microsoft)
  3220. drmk.sys Digital Rights Management (DRM) driver (Microsoft)
  3221. dump_atapi.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  3222. dump_dumpata.sys ATAPI Dump Driver
  3223. dump_dumpfve.sys (Generic Description) dump_*.sys drivers usually provide disk access during a crash to write dump files.
  3224. dxgkrnl.sys DirectX Graphics Kernal (Microsoft)
  3225. dxgmms2.sys DirectX Graphics MMS
  3226. EhStorClass.sys Enhanced Storage Class driver for IEEE... (Microsoft)
  3227. fastfat.SYS Fast FAT File System Driver (Microsoft)
  3228. filecrypt.sys Windows sandboxing and encryption filter (Microsoft)
  3229. fileinfo.sys FileInfo Filter Driver (Microsoft)
  3230. FLTMGR.SYS Filesystem Filter Manager (Microsoft)
  3231. Fs_Rec.sys File System Recognizer Driver (Microsoft)
  3232. fvevol.sys BitLocker Driver Encryption Driver (Microsoft)
  3233. fwpkclnt.sys FWP/IPsec Kernal-Mode API (Microsoft)
  3234. gpuenergydrv.sys GPU Energy Kernal Driver (Microsoft)
  3235. hal.dll Hardware Abstraction Layer DLL (Microsoft)
  3236. HDAudBus.sys High Definition Audio Bus Driver (Microsoft)
  3237. HdAudio.sys High Definition Audio Function driver (Microsoft)
  3238. HIDCLASS.SYS Hid Class Library (Microsoft)
  3239. HIDPARSE.SYS Hid Parsing Library (Microsoft)
  3240. hidusb.sys USB Miniport Driver for Input Devices (Microsoft)
  3241. HTTP.sys HTTP Protocol Stack (Microsoft)
  3242. intelpep.sys Intel Power Engine Plugin (Microsoft)
  3243. intelppm.sys Processor Device Driver (Microsoft)
  3244. IntelTA.sys Intel Telemetry Driver
  3245. iorate.sys I/O rate control Filter (Microsoft)
  3246. kbdclass.sys Keyboard Class Driver (Microsoft)
  3247. kbdhid.sys HID Mouse Filter Driver or HID Keyboard Filter Driver (Microsoft)
  3248. kd.dll Local Kernal Debugger (Microsoft)
  3249. kdnic.sys Microsoft Kernel Debugger Network Miniport (Microsoft)
  3250. ks.sys Kernal CSA Library (Microsoft)
  3251. ksecdd.sys Kernel Security Support Provider Interface (Microsoft)
  3252. ksecpkg.sys Kernel Security Support Provider Interface Packages (Microsoft)
  3253. ksthunk.sys Kernal Streaming WOW Thunk Service (Microsoft)
  3254. lltdio.sys Link-Layer Topology Mapper I/O Driver (Microsoft)
  3255. luafv.sys LUA File Virtualization Filter Driver (Microsoft)
  3256. mcupdate_GenuineIntel.dll Intel Microcode Update Library (Microsoft)
  3257. mmcss.sys MMCSS Driver (Microsoft)
  3258. monitor.sys Monitor Driver (Microsoft)
  3259. mouclass.sys Mouse Class Driver (Microsoft)
  3260. mouhid.sys HID Mouse Filter Driver (Microsoft)
  3261. mountmgr.sys Mount Point Manager (Microsoft)
  3262. MpKslDrv.sys Microsoft Anti-malware Protection driver
  3263. mpsdrv.sys Microsoft Protection Service Driver (Microsoft)
  3264. mrxsmb.sys SMB MiniRedirector Wrapper and Engine (Microsoft)
  3265. mrxsmb20.sys Longhorn SMB 2.0 Redirector (Microsoft)
  3266. Msfs.SYS Mailslot driver (Microsoft)
  3267. msisadrv.sys ISA Driver (Microsoft)
  3268. mslldp.sys Microsoft Link-Layer Discovery Protocol... (Microsoft)
  3269. msquic.sys Windows QUIC Driver
  3270. msrpc.sys Kernel Remote Procedure Call Provider (Microsoft)
  3271. mssecflt.sys Microsoft Security Events Component file system filter driver (Microsoft)
  3272. mssmbios.sys System Management BIOS driver (Microsoft)
  3273. mup.sys Multiple UNC Provider driver (Microsoft)
  3274. ndis.sys Network Driver Interface Specification (NDIS) driver (Microsoft)
  3275. ndiscap.sys Microsoft NDIS Packet Capture Filter Driver
  3276. NdisVirtualBus.sys Virtual Network Adapter Enumerator (Microsoft)
  3277. Ndu.sys Network Data Usage Monitoring driver (Microsoft)
  3278. netbios.sys NetBIOS Interface driver (Microsoft)
  3279. netbt.sys MBT Transport driver (Microsoft)
  3280. NETIO.SYS Network I/O Subsystem (Microsoft)
  3281. Npfs.SYS NPFS driver (Microsoft)
  3282. npsvctrig.sys Named pipe service triggers (Microsoft)
  3283. nsiproxy.sys NSI Proxy driver (Microsoft)
  3284. Ntfs.sys NT File System Driver (Microsoft)
  3285. ntkrnlmp.exe Windows NT operating system kernel (Microsoft)
  3286. ntosext.sys NTOS Extension Host driver (Microsoft)
  3287. Null.SYS NULL Driver (Microsoft)
  3288. pacer.sys QoS Packet Scheduler (Microsoft)
  3289. parport.sys Parallel Port Driver (Microsoft)
  3290. partmgr.sys Partition driver (Microsoft)
  3291. pci.sys NT Plug and Play PCI Enumerator (Microsoft)
  3292. pciide.sys Generic PCI IDE Bus Driver (Microsoft)
  3293. PCIIDEX.SYS PCI IDE Bus driver file (Microsoft)
  3294. pcw.sys Performance Counter Driver (Microsoft)
  3295. pdc.sys Power Dependency Coordinator Driver (Microsoft)
  3296. peauth.sys Protected Environment Authentication and Authorization Export Driver (Microsoft)
  3297. portcls.sys Class Driver for Port/Miniport Devices system driver (Microsoft)
  3298. PSHED.dll Platform Specific Hardware Error driver (Microsoft)
  3299. qwavedrv.sys Quality Windows Audio Video Experience (qWave) Support driver (Microsoft)
  3300. rdbss.sys Redirected Drive Buffering SubSystem driver (Microsoft)
  3301. rdpbus.sys Microsoft RDP Bus Device driver (Microsoft)
  3302. rdyboost.sys ReadyBoost Driver (Microsoft)
  3303. rspndr.sys Link-Layer Topology Responder driver (Microsoft)
  3304. serenum.sys Serial Port Enumerator (Microsoft)
  3305. serial.sys Serial Device Driver
  3306. SgrmAgent.sys System Guard Runtime Monitor Agent driver (Microsoft)
  3307. SleepStudyHelper.sys Sleep Study Helper driver (Microsoft)
  3308. spaceport.sys Storage Spaces driver (Microsoft)
  3309. srv2.sys Smb 2.0 Server driver (Microsoft)
  3310. srvnet.sys Server Network driver (Microsoft)
  3311. storqosflt.sys Storage QoS Filter driver (Microsoft)
  3312. swenum.sys Plug and Play Software Device Enumerator (Microsoft)
  3313. tbs.sys Export driver for kernel mode TPM API (Microsoft)
  3314. tcpip.sys TCP/IP Protocol driver (Microsoft)
  3315. tcpipreg.sys Microsoft Windows TCP/IP Registry Compatibility driver (Microsoft)
  3316. TDI.SYS TDI Wrapper driver (Microsoft)
  3317. tdx.sys NetIO Legacy TDI x-bit Support Driver (Microsoft)
  3318. tm.sys Kernel Transaction Manager driver (Microsoft)
  3319. umbus.sys User-Mode Bus Enumerator (Microsoft)
  3320. usbccgp.sys USB Common Class Generic Parent Driver (Microsoft)
  3321. USBD.SYS Universal Serial Bus Driver (Microsoft)
  3322. usbehci.sys EHCI eUSB Miniport Driver (Microsoft)
  3323. usbhub.sys Default Hub Driver for USB (Microsoft)
  3324. USBPORT.SYS USB 1.1 & 2.0 Port Driver (Microsoft)
  3325. vdrvroot.sys Virtual Drive Root Enumerator (Microsoft)
  3326. Vid.sys Microsoft Hyper-V Virtualization Infrastructure Driver
  3327. volmgr.sys Volume Manager Driver (Microsoft)
  3328. volmgrx.sys Volume Manager Extension Driver (Microsoft)
  3329. volsnap.sys Volume Shadow Copy driver (Microsoft)
  3330. volume.sys Volume driver (Microsoft)
  3331. vwififlt.sys Virtual WiFi Filter Driver (Microsoft)
  3332. watchdog.sys Watchdog driver (Microsoft)
  3333. wcifs.sys Windows Container Isolation FS Filter driver (Microsoft)
  3334. Wdf01000.sys Kernel Mode Driver Framework Runtime (Microsoft)
  3335. WdFilter.sys Microsoft Anti-malware file system filter driver (Microsoft)
  3336. WDFLDR.SYS Kernel Mode Driver Framework Loader (Microsoft)
  3337. WdNisDrv.sys Microsoft Network Realtime Inspection driver (Microsoft)
  3338. werkernel.sys Windows Error Reporting Kernel driver (Microsoft)
  3339. wfplwfs.sys WPF NDIS Lightweight Filter driver (Microsoft)
  3340. win32k.sys Full/Desktop Multi-User Win32 driver (Microsoft)
  3341. win32kbase.sys Base Win32k Kernel Driver (Microsoft)
  3342. win32kfull.sys Full/Desktop Win32k Kernel Driver (Microsoft)
  3343. WindowsTrustedRT.sys Windows Trusted Runtime Interface driver (Microsoft)
  3344. WindowsTrustedRTProxy.sys Windows Trusted Runtime Service Proxy driver (Microsoft)
  3345. winhvr.sys Windows Hypervisor Root Interface driver (Microsoft)
  3346. WMILIB.SYS WMILIB WMI support library DLL (Microsoft)
  3347. Wof.sys Windows Overlay Filter (Microsoft)
  3348. WppRecorder.sys WPP Trace Recorder (Microsoft)
  3349.  
  3350. ====================== Dump #6: UNLOADED MODULES =======================
  3351.  
  3352. fffff802`32fb0000 fffff802`32fc0000 dump_ataport
  3353. fffff802`32fd0000 fffff802`32fde000 dump_atapi.s
  3354. fffff802`32400000 fffff802`3241e000 dump_dumpfve
  3355. fffff802`32dd0000 fffff802`32dec000 dam.sys
  3356. fffff802`2b850000 fffff802`2b862000 WdBoot.sys
  3357. fffff802`2c850000 fffff802`2c860000 hwpolicy.sys
  3358.  
  3359. ====================== Dump #6: BIOS INFORMATION =======================
  3360.  
  3361. [SMBIOS Data Tables v2.7]
  3362. [DMI Version - 0]
  3363. [2.0 Calling Convention - No]
  3364. [Table Size - 3016 bytes]
  3365. [BIOS Information (Type 0) - Length 24 - Handle 0000h]
  3366. Vendor American Megatrends Inc.
  3367. BIOS Version F6
  3368. BIOS Starting Address Segment f000
  3369. BIOS Release Date 02/16/2012
  3370. BIOS ROM Size 280000
  3371. BIOS Characteristics
  3372. 07: - PCI Supported
  3373. 11: - Upgradeable FLASH BIOS
  3374. 12: - BIOS Shadowing Supported
  3375. 15: - CD-Boot Supported
  3376. 16: - Selectable Boot Supported
  3377. 17: - BIOS ROM Socketed
  3378. 19: - EDD Supported
  3379. 23: - 1.2MB Floppy Supported
  3380. 24: - 720KB Floppy Supported
  3381. 25: - 2.88MB Floppy Supported
  3382. 26: - Print Screen Device Supported
  3383. 27: - Keyboard Services Supported
  3384. 28: - Serial Services Supported
  3385. 29: - Printer Services Supported
  3386. 32: - BIOS Vendor Reserved
  3387. BIOS Characteristic Extensions
  3388. 00: - ACPI Supported
  3389. 01: - USB Legacy Supported
  3390. 08: - BIOS Boot Specification Supported
  3391. 10: - Specification Reserved
  3392. 11: - Specification Reserved
  3393. BIOS Major Revision 4
  3394. BIOS Minor Revision 6
  3395. EC Firmware Major Revision 255
  3396. EC Firmware Minor Revision 255
  3397. [System Information (Type 1) - Length 27 - Handle 0001h]
  3398. Manufacturer Gigabyte Tecohnology Co., Ltd.
  3399. Product Name H61M-DS2
  3400. UUID 00000000-0000-0000-0000-000000000000
  3401. Wakeup Type Power Switch
  3402. [BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
  3403. Manufacturer Gigabyte Tecohnology Co., Ltd.
  3404. Product H61M-DS2
  3405. Version x.x
  3406. Feature Flags 09h
  3407. -926632224: - -926632176: - «¯þø
  3408. Chassis Handle 0003h
  3409. Board Type 0ah - Processor/Memory Module
  3410. Number of Child Handles 0
  3411. [System Enclosure (Type 3) - Length 22 - Handle 0003h]
  3412. Manufacturer Gigabyte Tecohnology Co., Ltd.
  3413. Chassis Type Desktop
  3414. Bootup State Safe
  3415. Power Supply State Safe
  3416. Thermal State Safe
  3417. Security Status None
  3418. OEM Defined 0
  3419. Height 0U
  3420. Number of Power Cords 1
  3421. Number of Contained Elements 0
  3422. Contained Element Size 0
  3423. [Cache Information (Type 7) - Length 19 - Handle 0004h]
  3424. Cache Configuration 0181h - WB Enabled Int NonSocketed L2
  3425. Maximum Cache Size 0020h - 32K
  3426. Installed Size 0020h - 32K
  3427. Supported SRAM Type 0040h - Asynchronous
  3428. Current SRAM Type 0040h - Asynchronous
  3429. Cache Speed 0ns
  3430. Error Correction Type Multi-Bit ECC
  3431. System Cache Type Other
  3432. Associativity 16-way Set-Associative
  3433. [Cache Information (Type 7) - Length 19 - Handle 0005h]
  3434. Cache Configuration 0182h - WB Enabled Int NonSocketed L3
  3435. Maximum Cache Size 0100h - 256K
  3436. Installed Size 0100h - 256K
  3437. Supported SRAM Type 0040h - Asynchronous
  3438. Current SRAM Type 0040h - Asynchronous
  3439. Cache Speed 0ns
  3440. Error Correction Type Multi-Bit ECC
  3441. System Cache Type Instruction
  3442. Associativity 16-way Set-Associative
  3443. [Cache Information (Type 7) - Length 19 - Handle 0006h]
  3444. Cache Configuration 0183h - WB Enabled Int NonSocketed L4
  3445. Maximum Cache Size 0c00h - 3072K
  3446. Installed Size 0c00h - 3072K
  3447. Supported SRAM Type 0040h - Asynchronous
  3448. Current SRAM Type 0040h - Asynchronous
  3449. Cache Speed 0ns
  3450. Error Correction Type Multi-Bit ECC
  3451. System Cache Type Instruction
  3452. Associativity Specification Reserved
  3453. [Physical Memory Array (Type 16) - Length 23 - Handle 0007h]
  3454. Location 03h - SystemBoard/Motherboard
  3455. Use 03h - System Memory
  3456. Memory Error Correction 03h - None
  3457. Maximum Capacity 33554432KB
  3458. Number of Memory Devices 4
  3459. [Onboard Devices Information (Type 10) - Length 6 - Handle 0026h]
  3460. Number of Devices 1
  3461. 01: Type Video [enabled]
  3462. [OEM Strings (Type 11) - Length 5 - Handle 0027h]
  3463. Number of Strings 1
  3464. [System Configuration Options (Type 12) - Length 5 - Handle 0028h]
  3465. [Memory Device (Type 17) - Length 34 - Handle 0040h]
  3466. Physical Memory Array Handle 0007h
  3467. Total Width 64 bits
  3468. Data Width 64 bits
  3469. Size 4096MB
  3470. Form Factor 09h - DIMM
  3471. Device Locator ChannelA-DIMM0
  3472. Bank Locator BANK 0
  3473. Memory Type 18h - Specification Reserved
  3474. Type Detail 0080h - Synchronous
  3475. Speed 1333MHz
  3476. Manufacturer Hynix/Hyundai
  3477. Part Number HMT351U6CFR8C-H9
  3478. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0041h]
  3479. Starting Address 00000000h
  3480. Ending Address 003fffffh
  3481. Memory Device Handle 0040h
  3482. Mem Array Mapped Adr Handle 0047h
  3483. Interleave Position 01
  3484. Interleave Data Depth 02
  3485. [Memory Device (Type 17) - Length 34 - Handle 0042h]
  3486. Physical Memory Array Handle 0007h
  3487. Total Width 0 bits
  3488. Data Width 0 bits
  3489. Form Factor 09h - DIMM
  3490. Device Locator ChannelA-DIMM1
  3491. Bank Locator BANK 1
  3492. Memory Type 02h - Unknown
  3493. Type Detail 0000h -
  3494. Speed 0MHz
  3495. [Processor Information (Type 4) - Length 42 - Handle 0043h]
  3496. Socket Designation Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
  3497. Processor Type Central Processor
  3498. Processor Family c6h - Specification Reserved
  3499. Processor Manufacturer Intel
  3500. Processor ID a7060200fffbebbf
  3501. Processor Version Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz
  3502. Processor Voltage 8bh - 1.1V
  3503. External Clock 100MHz
  3504. Max Speed 7000MHz
  3505. Current Speed 3300MHz
  3506. Status Enabled Populated
  3507. Processor Upgrade Other
  3508. L1 Cache Handle 0004h
  3509. L2 Cache Handle 0005h
  3510. L3 Cache Handle 0006h
  3511. [Memory Device (Type 17) - Length 34 - Handle 0044h]
  3512. Physical Memory Array Handle 0007h
  3513. Total Width 64 bits
  3514. Data Width 64 bits
  3515. Size 4096MB
  3516. Form Factor 09h - DIMM
  3517. Device Locator ChannelB-DIMM0
  3518. Bank Locator BANK 2
  3519. Memory Type 18h - Specification Reserved
  3520. Type Detail 0080h - Synchronous
  3521. Speed 1333MHz
  3522. Manufacturer 8325
  3523. Part Number FLFF65F-C8KL9
  3524. [Memory Device Mapped Address (Type 20) - Length 35 - Handle 0045h]
  3525. Starting Address 00400000h
  3526. Ending Address 007fffffh
  3527. Memory Device Handle 0044h
  3528. Mem Array Mapped Adr Handle 0047h
  3529. Interleave Position 02
  3530. Interleave Data Depth 02
  3531. [Memory Device (Type 17) - Length 34 - Handle 0046h]
  3532. Physical Memory Array Handle 0007h
  3533. Total Width 0 bits
  3534. Data Width 0 bits
  3535. Form Factor 09h - DIMM
  3536. Device Locator ChannelB-DIMM1
  3537. Bank Locator BANK 3
  3538. Memory Type 02h - Unknown
  3539. Type Detail 0000h -
  3540. Speed 0MHz
  3541. [Memory Array Mapped Address (Type 19) - Length 31 - Handle 0047h]
  3542. Starting Address 00000000h
  3543. Ending Address 007fffffh
  3544. Memory Array Handle 0007h
  3545. Partition Width 04
  3546.  
  3547. ========================== Dump #6: Extra #1 ===========================
  3548.  
  3549. 1: kd> !verifier
  3550. Verify Flags Level 0x00000000
  3551. STANDARD FLAGS:
  3552. [X] (0x00000000) Automatic Checks
  3553. [ ] (0x00000001) Special pool
  3554. [ ] (0x00000002) Force IRQL checking
  3555. [ ] (0x00000008) Pool tracking
  3556. [ ] (0x00000010) I/O verification
  3557. [ ] (0x00000020) Deadlock detection
  3558. [ ] (0x00000080) DMA checking
  3559. [ ] (0x00000100) Security checks
  3560. [ ] (0x00000800) Miscellaneous checks
  3561. [ ] (0x00020000) DDI compliance checking
  3562. ADDITIONAL FLAGS:
  3563. [ ] (0x00000004) Randomized low resources simulation
  3564. [ ] (0x00000200) Force pending I/O requests
  3565. [ ] (0x00000400) IRP logging
  3566. [ ] (0x00002000) Invariant MDL checking for stack
  3567. [ ] (0x00004000) Invariant MDL checking for driver
  3568. [ ] (0x00008000) Power framework delay fuzzing
  3569. [ ] (0x00010000) Port/miniport interface checking
  3570. [ ] (0x00040000) Systematic low resources simulation
  3571. [ ] (0x00080000) DDI compliance checking (additional)
  3572. [ ] (0x00200000) NDIS/WIFI verification
  3573. [ ] (0x00800000) Kernel synchronization delay fuzzing
  3574. [ ] (0x01000000) VM switch verification
  3575. [ ] (0x02000000) Code integrity checks
  3576. [X] Indicates flag is enabled
  3577. Summary of All Verifier Statistics
  3578. RaiseIrqls 0x0
  3579. AcquireSpinLocks 0x0
  3580. Synch Executions 0x0
  3581. Trims 0x0
  3582. Pool Allocations Attempted 0x0
  3583. Pool Allocations Succeeded 0x0
  3584. Pool Allocations Succeeded SpecialPool 0x0
  3585. Pool Allocations With NO TAG 0x0
  3586. Pool Allocations Failed 0x0
  3587. Current paged pool allocations 0x0 for 00000000 bytes
  3588. Peak paged pool allocations 0x0 for 00000000 bytes
  3589. Current nonpaged pool allocations 0x0 for 00000000 bytes
  3590. Peak nonpaged pool allocations 0x0 for 00000000 bytes
  3591.  
  3592. ========================== Dump #6: Extra #2 ===========================
  3593.  
  3594. 1: kd> !thread
  3595. THREAD ffffdc03a7df5040 Cid 0004.1850 Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor 1
  3596. Not impersonating
  3597. GetUlongFromAddress: unable to read from fffff80227e1143c
  3598. Owning Process ffffdc039c496040 Image: System
  3599. Attached Process N/A Image: N/A
  3600. fffff78000000000: Unable to get shared data
  3601. Wait Start TickCount 2310744
  3602. Context Switch Count 14114 IdealProcessor: 1
  3603. ReadMemory error: Cannot get nt!KeMaximumIncrement value.
  3604. UserTime 00:00:00.000
  3605. KernelTime 00:00:00.000
  3606. Win32 Start Address nt!ExpWorkerThread (0xfffff80227433e40)
  3607. Stack Init ffffda8a37616c90 Current ffffda8a37616820
  3608. Base ffffda8a37617000 Limit ffffda8a37611000 Call 0000000000000000
  3609. Priority 12 BasePriority 12 PriorityDecrement 0 IoPriority 2 PagePriority 5
  3610. Child-SP RetAddr : Args to Child : Call Site
  3611. ffffda8a`376166b8 fffff802`275efa29 : 00000000`0000000a 00000000`001ddbb5 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
  3612. ffffda8a`376166c0 fffff802`275ebd29 : ffff9d01`ae1b0140 ffffdc03`a7df5040 ffff9d01`ae1a5180 fffff802`275e4d72 : nt!KiBugCheckDispatch+0x69
  3613. ffffda8a`37616800 fffff802`274acd4d : 00000000`00000000 ffff9780`00000001 00000000`00000000 fffff802`27e4e680 : nt!KiPageFault+0x469 (TrapFrame @ ffffda8a`37616800)
  3614. ffffda8a`37616990 fffff802`2775877c : 00000000`00064e1e 00000000`00000000 00000000`0000001e 00000000`00000001 : nt!MiInsertPageInFreeOrZeroedList+0x2dd
  3615. ffffda8a`37616a90 fffff802`277588b3 : fffff802`27e50b40 00000000`00000000 fffff802`00000000 00000000`00000229 : nt!MiPruneStandbyPages+0x380
  3616. ffffda8a`37616b20 fffff802`27433f45 : ffffdc03`a7df5040 fffff802`27758820 ffffdc03`9c557a60 fffff802`27e523e0 : nt!MiRebalanceZeroFreeLists+0x93
  3617. ffffda8a`37616b70 fffff802`27546735 : ffffdc03`a7df5040 00000000`00000080 ffffdc03`9c496040 00000000`00000001 : nt!ExpWorkerThread+0x105
  3618. ffffda8a`37616c10 fffff802`275e51b8 : ffff9d01`ae2f6180 ffffdc03`a7df5040 fffff802`275466e0 00000000`00000000 : nt!PspSystemThreadStartup+0x55
  3619. ffffda8a`37616c60 00000000`00000000 : ffffda8a`37617000 ffffda8a`37611000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement