KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common BugCheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff805a5f98bae, The address that the exception occurred at
Arg3: 0000000000000001, Parameter 0 of the exception
Arg4: 000000006a3b8920, Parameter 1 of the exception
Debugging Details:
------------------
*************************************************************************
*** ***
*** ***
*** Either you specified an unqualified symbol, or your debugger ***
*** doesn't have full symbol information. Unqualified symbol ***
*** resolution is turned off by default. Please either specify a ***
*** fully qualified symbol module!symbolname, or enable resolution ***
*** of unqualified symbols by typing ".symopt- 100". Note that ***
*** enabling unqualified symbol resolution with network symbol ***
*** server shares in the symbol path may cause the debugger to ***
*** appear to hang for long periods of time when an incorrect ***
*** symbol name is typed or the network symbol server is down. ***
*** ***
*** For some commands to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: ExceptionRecord ***
*** ***
*************************************************************************
*************************************************************************
*** ***
*** ***
*** Either you specified an unqualified symbol, or your debugger ***
*** doesn't have full symbol information. Unqualified symbol ***
*** resolution is turned off by default. Please either specify a ***
*** fully qualified symbol module!symbolname, or enable resolution ***
*** of unqualified symbols by typing ".symopt- 100". Note that ***
*** enabling unqualified symbol resolution with network symbol ***
*** server shares in the symbol path may cause the debugger to ***
*** appear to hang for long periods of time when an incorrect ***
*** symbol name is typed or the network symbol server is down. ***
*** ***
*** For some commands to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: ContextRecord ***
*** ***
*************************************************************************
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 1031
Key : Analysis.Elapsed.mSec
Value: 6311
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 1
Key : Analysis.IO.Write.Mb
Value: 1
Key : Analysis.Init.CPU.mSec
Value: 328
Key : Analysis.Init.Elapsed.mSec
Value: 1228
Key : Analysis.Memory.CommitPeak.Mb
Value: 89
Key : Analysis.Version.DbgEng
Value: 10.0.27793.1000
Key : Analysis.Version.Description
Value: 10.2410.02.02 amd64fre
Key : Analysis.Version.Ext
Value: 1.2410.2.2
Key : Bugcheck.Code.LegacyAPI
Value: 0x1e
Key : Bugcheck.Code.TargetModel
Value: 0x1e
Key : Dump.Attributes.AsUlong
Value: 0x21008
Key : Dump.Attributes.DiagDataWrittenToHeader
Value: 1
Key : Dump.Attributes.ErrorCode
Value: 0x0
Key : Dump.Attributes.KernelGeneratedTriageDump
Value: 1
Key : Dump.Attributes.LastLine
Value: Dump completed successfully.
Key : Dump.Attributes.ProgressPercentage
Value: 0
Key : Failure.Bucket
Value: AV_W_nt!MiUserFault
Key : Failure.Exception.IP.Address
Value: 0xfffff805a5f98bae
Key : Failure.Exception.IP.Module
Value: nt
Key : Failure.Exception.IP.Offset
Value: 0x398bae
Key : Failure.Hash
Value: {dcf4eef0-91be-dd26-5b9a-dd64525e8eca}
BUGCHECK_CODE: 1e
BUGCHECK_P1: ffffffffc0000005
BUGCHECK_P2: fffff805a5f98bae
BUGCHECK_P3: 1
BUGCHECK_P4: 6a3b8920
FILE_IN_CAB: 040825-14109-01.dmp
DUMP_FILE_ATTRIBUTES: 0x21008
Kernel Generated Triage Dump
FAULTING_THREAD: ffffe68e2c6e00c0
EXCEPTION_PARAMETER1: 0000000000000001
EXCEPTION_PARAMETER2: 000000006a3b8920
WRITE_ADDRESS: fffff805a6bc34b0: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
unable to get nt!MmSpecialPagesInUse
000000006a3b8920
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: qgis-ltr-bin.e
STACK_TEXT:
ffffd601`6a3b7d18 fffff805`a5f9ee26 : 00000000`0000001e ffffffff`c0000005 fffff805`a5f98bae 00000000`00000001 : nt!KeBugCheckEx
ffffd601`6a3b7d20 fffff805`a6287145 : 00000000`c0000005 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDispatchException+0xb16
ffffd601`6a3b8430 fffff805`a6282282 : 00000000`00640062 000001ae`b5d58120 00000000`006a0068 000001ae`b5d58184 : nt!KiExceptionDispatch+0x145
ffffd601`6a3b8610 fffff805`a5f98bae : 00000000`00000000 00000000`00000000 00000000`00000000 ffffb40b`e0000000 : nt!KiPageFault+0x442
ffffd601`6a3b87a0 00000000`00000000 : ffffb40b`fe772650 fffff805`a67310d1 00000000`00000090 00000000`00000090 : nt!MiUserFault+0x2a
SYMBOL_NAME: nt!MiUserFault+2a
MODULE_NAME: nt
IMAGE_VERSION: 10.0.26100.1742
STACK_COMMAND: .process /r /p 0xffffe68e319020c0; .thread 0xffffe68e2c6e00c0 ; kb
IMAGE_NAME: ntkrnlmp.exe
BUCKET_ID_FUNC_OFFSET: 2a
FAILURE_BUCKET_ID: AV_W_nt!MiUserFault
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {dcf4eef0-91be-dd26-5b9a-dd64525e8eca}
Followup: MachineOwner
---------
PnpActivityId : {00000000-0000-0000-0000-000000000000}
PnpActivityTime : 133885896803822456
PnpEventInformation: 0
PnpEventInProgress : 0
PnpProblemCode : 22
PnpVetoType : 0
DeviceId : ROOT\PANGPD\0000
VetoString :
[SMBIOS Data Tables v3.2]
[DMI Version - 0]
[2.0 Calling Convention - No]
[Table Size - 2540 bytes]
[BIOS Information (Type 0) - Length 26 - Handle 0000h]
Vendor LENOVO
BIOS Version FCCN21WW
BIOS Starting Address Segment e000
BIOS Release Date 09/20/2023
BIOS ROM Size f20000
BIOS Characteristics
07: - PCI Supported
11: - Upgradeable FLASH BIOS
12: - BIOS Shadowing Supported
15: - CD-Boot Supported
16: - Selectable Boot Supported
19: - EDD Supported
20: - NEC 9800 J-Floppy Supported
21: - Toshiba J-Floppy Supported
22: - 360KB Floppy Supported
23: - 1.2MB Floppy Supported
24: - 720KB Floppy Supported
25: - 2.88MB Floppy Supported
27: - Keyboard Services Supported
30: - CGA/Mono Services Supported
49: - System Vendor Reserved
51: - System Vendor Reserved
52: - System Vendor Reserved
BIOS Characteristic Extensions
00: - ACPI Supported
01: - USB Legacy Supported
08: - BIOS Boot Specification Supported
10: - Enable Targeted Content Distribution
11: - UEFI Specification Supported
BIOS Major Revision 1
BIOS Minor Revision 21
EC Firmware Major Revision 1
EC Firmware Minor Revision 21
Extended BIOS ROM Size 0 MB
[System Information (Type 1) - Length 27 - Handle 0001h]
Manufacturer LENOVO
Product Name 82EY
Version IdeaPad Gaming 3 15ARH05
Serial Number PF2MV8SM
UUID 00000000-0000-0000-0000-000000000000
Wakeup Type Power Switch
SKUNumber LENOVO_MT_82EY_BU_idea_FM_IdeaPad Gaming 3 15ARH05
Family IdeaPad Gaming 3 15ARH05
[BaseBoard Information (Type 2) - Length 16 - Handle 0002h]
Manufacturer LENOVO
Product LNVNB161216
Version NO DPK
Serial Number PF2MV8SM
Asset Tag
Feature Flags 09h
00: - Motherboard
03: - Replaceable
Location Base Board Chassis Location
Chassis Handle 0003h
Board Type 0ah - Processor/Memory Module
Number of Child Handles 0
[System Enclosure (Type 3) - Length 23 - Handle 0003h]
Manufacturer LENOVO
Chassis Type Notebook
Version IdeaPad Gaming 3 15ARH05
Serial Number
Asset Tag Number
Bootup State Safe
Power Supply State Safe
Thermal State Safe
Security Status None
OEM Defined 0
Height 0U
Number of Power Cords 1
Number of Contained Elements 0
Contained Element Size 0
SKU Number Chassis SKU
[Processor Information (Type 4) - Length 48 - Handle 0004h]
Socket Designation FP6
Processor Type Central Processor
Processor Family 6bh - AMD Zen Processor Family
Processor Manufacturer Advanced Micro Devices, Inc.
Processor ID 10f8600fffb8b17
Processor Version AMD Ryzen 7 4800H with Radeon Graphics
Processor Voltage 8ch - 1.2V
External Clock 100MHz
Max Speed 4300MHz
Current Speed 2900MHz
Status Enabled Populated
Processor Upgrade None
L1 Cache Handle 0005h
L2 Cache Handle 0006h
L3 Cache Handle 0007h
Serial Number
Asset Tag Number
Part Number Unknown
Core Count 8
Core Enabled 8
Thread Count 16
Processor Characteristics fc
Enabled Characteristics:
0x 2: 64-bit Capable
0x 3: Multi-Core
0x 4: Hardware Thread
0x 5: Execute Protection
0x 6: Enhanced Virtualization
0x 7: Power/Performance Control
Processor Family 2 006bh - AMD Zen Processor Family
Core Count 2 8
Core Enabled 2 8
Thread Count 2 16
[Cache Information (Type 7) - Length 27 - Handle 0005h]
Socket Designation L1 - Cache
Cache Configuration 0180h - WBEnabled Int NonSocketed L1
Maximum Cache Size 0200h - 512K
Installed Size 0200h - 512K
Supported SRAM Type 0010h - Pipeline-Burst
Current SRAM Type 0010h - Pipeline-Burst
Cache Speed 1ns
Error Correction Type Specification Reserved
System Cache Type Unified
Associativity 8-way Set-Associative
Maximum Cache Size 2 200 - 00000512l Kb
Installed Cache Size 2 200 - 00000512l Kb
[Cache Information (Type 7) - Length 27 - Handle 0006h]
Socket Designation L2 - Cache
Cache Configuration 0181h - WBEnabled Int NonSocketed L2
Maximum Cache Size 1000h - 4096K
Installed Size 1000h - 4096K
Supported SRAM Type 0010h - Pipeline-Burst
Current SRAM Type 0010h - Pipeline-Burst
Cache Speed 1ns
Error Correction Type Specification Reserved
System Cache Type Unified
Associativity 8-way Set-Associative
Maximum Cache Size 2 1000 - 00004096l Kb
Installed Cache Size 2 1000 - 00004096l Kb
[Cache Information (Type 7) - Length 27 - Handle 0007h]
Socket Designation L3 - Cache
Cache Configuration 0182h - WBEnabled Int NonSocketed L3
Maximum Cache Size 2000h - 8192K
Installed Size 2000h - 8192K
Supported SRAM Type 0010h - Pipeline-Burst
Current SRAM Type 0010h - Pipeline-Burst
Cache Speed 1ns
Error Correction Type Specification Reserved
System Cache Type Unified
Associativity 16-way Set-Associative
Maximum Cache Size 2 2000 - 00008192l Kb
Installed Cache Size 2 2000 - 00008192l Kb
[OEM Strings (Type 11) - Length 5 - Handle 001fh]
Number of Strings 1
1 Modern Preload
[System Configuration Options (Type 12) - Length 5 - Handle 0020h]
[Physical Memory Array (Type 16) - Length 23 - Handle 0022h]
Location 03h - SystemBoard/Motherboard
Use 03h - System Memory
Memory Error Correction 03h - None
Maximum Capacity 33554432KB
Memory Error Inf Handle 0025h
Number of Memory Devices 2
[Memory Device (Type 17) - Length 84 - Handle 0023h]
Memory Error Info Handle 0026h
Total Width 64 bits
Data Width 64 bits
Size 8192MB
Form Factor 0dh - SODIMM
Device Set [None]
Device Locator DIMM 0
Bank Locator P0 CHANNEL A
Memory Type 1ah - DDR4
Type Detail 4080h - Synchronous Unbuffered (Unregistered)
Speed 3200MHz
Manufacturer Hynix
Serial Number
Asset Tag Number [String Not Specified]
Part Number HMA81GS6DJR8N-XN
Attributes 1
Extended Size 0
Configured Memory Speed 3200
Minimum Voltage 1200
Maximum Voltage 1200
Configured Voltage 1200
Memory Technology 3
Memory Operating Mode Capability 8
Firmware Version 6
Module Manufacturer Id 44416
Module Product Id 0
Memory Subsystem Controller Manufacturer Id 0
Memory Subsystem Controller Product Id 0
Non-Volatile Size 0
Volatile Size 0
Cache Size 0
Logical Size 0
[Memory Device (Type 17) - Length 84 - Handle 0024h]
Memory Error Info Handle 0027h
Total Width 64 bits
Data Width 64 bits
Size 8192MB
Form Factor 0dh - SODIMM
Device Set [None]
Device Locator DIMM 0
Bank Locator P0 CHANNEL B
Memory Type 1ah - DDR4
Type Detail 4080h - Synchronous Unbuffered (Unregistered)
Speed 3200MHz
Manufacturer Hynix
Serial Number
Asset Tag Number [String Not Specified]
Part Number HMA81GS6DJR8N-XN
Attributes 1
Extended Size 0
Configured Memory Speed 3200
Minimum Voltage 1200
Maximum Voltage 1200
Configured Voltage 1200
Memory Technology 3
Memory Operating Mode Capability 8
Firmware Version 6
Module Manufacturer Id 44416
Module Product Id 0
Memory Subsystem Controller Manufacturer Id 0
Memory Subsystem Controller Product Id 0
Non-Volatile Size 0
Volatile Size 0
Cache Size 0
Logical Size 0
[32Bit Memory Error Information (Type 18) - Length 23 - Handle 0025h]
[32Bit Memory Error Information (Type 18) - Length 23 - Handle 0026h]
[32Bit Memory Error Information (Type 18) - Length 23 - Handle 0027h]
[Memory Array Mapped Address (Type 19) - Length 31 - Handle 0028h]
Starting Address 00000000h
Ending Address 00ffffffh
Memory Array Handle 0022h
Partition Width 02
Extended Starting Address 0000000000000000h
Extended Ending Address 0000000000000000h
[Memory Device Mapped Address (Type 20) - Length 35 - Handle 0029h]
Starting Address 00000000h
Ending Address 00ffffffh
Memory Device Handle 0023h
Mem Array Mapped Adr Handle 0028h
Partition Row Position [Unknown]
Interleave Position [Unknown]
Interleave Data Depth [Unknown]
Extended Starting Address 0000000000000000h
Extended Ending Address 0000000000000000h
[Memory Device Mapped Address (Type 20) - Length 35 - Handle 002ah]
Starting Address 00000000h
Ending Address 00ffffffh
Memory Device Handle 0024h
Mem Array Mapped Adr Handle 0028h
Partition Row Position [Unknown]
Interleave Position [Unknown]
Interleave Data Depth [Unknown]
Extended Starting Address 0000000000000000h
Extended Ending Address 0000000000000000h
[ (Type 256) - Length 18 - Handle 0031h]
[ (Type 256) - Length 11 - Handle 0032h]
[ (Type 256) - Length 11 - Handle 0033h]
[ (Type 256) - Length 5 - Handle 0034h]
[ (Type 256) - Length 18 - Handle 0036h]
[ (Type 256) - Length 4 - Handle feffh]
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 0000000089f3007f, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000001, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff804d588d61c, address which referenced memory
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 828
Key : Analysis.Elapsed.mSec
Value: 4421
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 1
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 328
Key : Analysis.Init.Elapsed.mSec
Value: 1201
Key : Analysis.Memory.CommitPeak.Mb
Value: 88
Key : Analysis.Version.DbgEng
Value: 10.0.27793.1000
Key : Analysis.Version.Description
Value: 10.2410.02.02 amd64fre
Key : Analysis.Version.Ext
Value: 1.2410.2.2
Key : Bugcheck.Code.LegacyAPI
Value: 0xa
Key : Bugcheck.Code.TargetModel
Value: 0xa
Key : Dump.Attributes.AsUlong
Value: 0x21008
Key : Dump.Attributes.DiagDataWrittenToHeader
Value: 1
Key : Dump.Attributes.ErrorCode
Value: 0x0
Key : Dump.Attributes.KernelGeneratedTriageDump
Value: 1
Key : Dump.Attributes.LastLine
Value: Dump completed successfully.
Key : Dump.Attributes.ProgressPercentage
Value: 0
Key : Failure.Bucket
Value: AV_nt!KiCommitThreadWait
Key : Failure.Exception.IP.Address
Value: 0xfffff804d588d61c
Key : Failure.Exception.IP.Module
Value: nt
Key : Failure.Exception.IP.Offset
Value: 0x28d61c
Key : Failure.Hash
Value: {3128e59f-7ae1-250b-f845-2e4be0c2c23a}
BUGCHECK_CODE: a
BUGCHECK_P1: 89f3007f
BUGCHECK_P2: 2
BUGCHECK_P3: 1
BUGCHECK_P4: fffff804d588d61c
FILE_IN_CAB: 040825-14031-02.dmp
DUMP_FILE_ATTRIBUTES: 0x21008
Kernel Generated Triage Dump
FAULTING_THREAD: ffffe78764c35080
WRITE_ADDRESS: fffff804d65c34b0: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
unable to get nt!MmSpecialPagesInUse
0000000089f3007f
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 2
PROCESS_NAME: MBAMService.ex
STACK_TEXT:
ffff8107`e2710530 fffff804`d588e8ef : 00000000`00000000 ffffae80`ebbb7180 00000000`00000000 00000000`00000000 : nt!KiSwapContext+0x76
ffff8107`e2710670 00000000`00000018 : 00000000`00000000 00000000`00000000 ffff8107`e2710818 00001f80`000000f3 : nt!KiSwapThread+0x96f
ffff8107`e2710700 00000000`00000000 : 00000000`00000000 ffff8107`e2710818 00001f80`000000f3 00000000`00000000 : 0x18
SYMBOL_NAME: nt!KiCommitThreadWait+39c
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
IMAGE_VERSION: 10.0.26100.1742
STACK_COMMAND: .process /r /p 0xffffe7876336c080; .thread 0xffffe78764c35080 ; kb
BUCKET_ID_FUNC_OFFSET: 39c
FAILURE_BUCKET_ID: AV_nt!KiCommitThreadWait
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {3128e59f-7ae1-250b-f845-2e4be0c2c23a}
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the BugCheck
Arg2: fffff804dfe96476, Address of the instruction which caused the BugCheck
Arg3: fffff68836f40e30, Address of the context record for the exception that caused the BugCheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 828
Key : Analysis.Elapsed.mSec
Value: 5503
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 1
Key : Analysis.IO.Write.Mb
Value: 1
Key : Analysis.Init.CPU.mSec
Value: 406
Key : Analysis.Init.Elapsed.mSec
Value: 1253
Key : Analysis.Memory.CommitPeak.Mb
Value: 89
Key : Analysis.Version.DbgEng
Value: 10.0.27793.1000
Key : Analysis.Version.Description
Value: 10.2410.02.02 amd64fre
Key : Analysis.Version.Ext
Value: 1.2410.2.2
Key : Bugcheck.Code.LegacyAPI
Value: 0x3b
Key : Bugcheck.Code.TargetModel
Value: 0x3b
Key : Dump.Attributes.AsUlong
Value: 0x21008
Key : Dump.Attributes.DiagDataWrittenToHeader
Value: 1
Key : Dump.Attributes.ErrorCode
Value: 0x0
Key : Dump.Attributes.KernelGeneratedTriageDump
Value: 1
Key : Dump.Attributes.LastLine
Value: Dump completed successfully.
Key : Dump.Attributes.ProgressPercentage
Value: 0
Key : Failure.Bucket
Value: AV_nt!IopCloseFile
Key : Failure.Exception.IP.Address
Value: 0xfffff804dfe96476
Key : Failure.Exception.IP.Module
Value: nt
Key : Failure.Exception.IP.Offset
Value: 0x296476
Key : Failure.Hash
Value: {ce25db90-c697-4b29-8f4d-08e80373a560}
BUGCHECK_CODE: 3b
BUGCHECK_P1: c0000005
BUGCHECK_P2: fffff804dfe96476
BUGCHECK_P3: fffff68836f40e30
BUGCHECK_P4: 0
FILE_IN_CAB: 040825-14265-01.dmp
DUMP_FILE_ATTRIBUTES: 0x21008
Kernel Generated Triage Dump
FAULTING_THREAD: ffffd68686cd3080
CONTEXT: fffff68836f40e30 -- (.cxr 0xfffff68836f40e30)
rax=0000000000000000 rbx=ffffd68688a053a0 rcx=fffff68836f418d8
rdx=0000000000000001 rsi=ffffd686848430c0 rdi=0000000000000000
rip=fffff804dfe96476 rsp=fffff68836f41888 rbp=0000000000000000
r8=0000000000000000 r9=0000000000000001 r10=ffffd686848430c0
r11=ffffd68686cd3080 r12=0000000000000000 r13=0000000000000000
r14=0000000000000001 r15=ffffd6867a62cd60
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050246
nt!IoGetRelatedDeviceObject+0x16:
fffff804`dfe96476 488b4038 mov rax,qword ptr [rax+38h] ds:002b:00000000`00000038=????????????????
Resetting default scope
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: LenovoVantage-
STACK_TEXT:
fffff688`36f41888 fffff804`e0429ce6 : ffffd686`848430c0 ffffd686`00000000 00000000`00000002 00000000`00000000 : nt!IoGetRelatedDeviceObject+0x16
fffff688`36f41890 fffff804`e045c8d2 : fffff688`36f41a20 ffffd686`88a05370 00000000`00000000 00000000`00000000 : nt!IopCloseFile+0x236
fffff688`36f41920 fffff804`e045aef9 : 00000000`00000000 000001d8`597c4aa0 00000000`00000000 fffff804`e04a4d30 : nt!ObCloseHandleTableEntry+0x512
fffff688`36f41a70 fffff804`e0286658 : 00000000`00000000 00000000`0000000c ffffd686`86cd3080 000001d8`597c4aa0 : nt!NtClose+0xe9
fffff688`36f41ae0 00007ffc`119defe4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
00000036`9e7fcf58 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffc`119defe4
SYMBOL_NAME: nt!IopCloseFile+236
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
IMAGE_VERSION: 10.0.26100.1742
STACK_COMMAND: .cxr 0xfffff68836f40e30 ; kb
BUCKET_ID_FUNC_OFFSET: 236
FAILURE_BUCKET_ID: AV_nt!IopCloseFile
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {ce25db90-c697-4b29-8f4d-08e80373a560}
Followup: MachineOwner
---------
PnpActivityId : {00000000-0000-0000-0000-000000000000}
PnpActivityTime : 133885896381476614
PnpEventInformation: 0
PnpEventInProgress : 0
PnpProblemCode : 22
PnpVetoType : 0
DeviceId : ROOT\PANGPD\0000
VetoString :
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 0000000000000188, memory referenced
Arg2: 00000000000000ff, IRQL
Arg3: 000000000000000b, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff8007fa86799, address which referenced memory
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 859
Key : Analysis.Elapsed.mSec
Value: 6496
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 1
Key : Analysis.IO.Write.Mb
Value: 1
Key : Analysis.Init.CPU.mSec
Value: 390
Key : Analysis.Init.Elapsed.mSec
Value: 1268
Key : Analysis.Memory.CommitPeak.Mb
Value: 89
Key : Analysis.Version.DbgEng
Value: 10.0.27793.1000
Key : Analysis.Version.Description
Value: 10.2410.02.02 amd64fre
Key : Analysis.Version.Ext
Value: 1.2410.2.2
Key : Bugcheck.Code.LegacyAPI
Value: 0xa
Key : Bugcheck.Code.TargetModel
Value: 0xa
Key : Dump.Attributes.AsUlong
Value: 0x21008
Key : Dump.Attributes.DiagDataWrittenToHeader
Value: 1
Key : Dump.Attributes.ErrorCode
Value: 0x0
Key : Dump.Attributes.KernelGeneratedTriageDump
Value: 1
Key : Dump.Attributes.LastLine
Value: Dump completed successfully.
Key : Dump.Attributes.ProgressPercentage
Value: 0
Key : Failure.Bucket
Value: IP_MISALIGNED_AuthenticAMD.sys
Key : Failure.Exception.IP.Address
Value: 0xfffff8007fa86799
Key : Failure.Exception.IP.Module
Value: nt
Key : Failure.Exception.IP.Offset
Value: 0x686799
Key : Failure.Hash
Value: {716d112a-8330-4bbb-160c-ec98297019d2}
BUGCHECK_CODE: a
BUGCHECK_P1: 188
BUGCHECK_P2: ff
BUGCHECK_P3: b
BUGCHECK_P4: fffff8007fa86799
FILE_IN_CAB: 040825-14250-01.dmp
DUMP_FILE_ATTRIBUTES: 0x21008
Kernel Generated Triage Dump
FAULTING_THREAD: ffffb90a3bb94080
WRITE_ADDRESS: fffff800803c34b0: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
unable to get nt!MmSpecialPagesInUse
0000000000000188
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: warp-svc.exe
TRAP_FRAME: ffffc98717e90950 -- (.trap 0xffffc98717e90950)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000040000024 rbx=0000000000000000 rcx=ffffb90a3bb94080
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8007fa86799 rsp=ffffc98717e90ae0 rbp=ffffc98717e90b60
r8=ffffc98717e90af0 r9=0000000000000000 r10=0000fffff8007fc1
r11=ffffb90a3bb94080 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up di pl zr na po nc
nt!KiSystemServiceExit+0x139:
fffff800`7fa86799 488b0c2588010000 mov rcx,qword ptr [188h] ds:00000000`00000188=????????????????
Resetting default scope
MISALIGNED_IP:
nt!KiSystemServiceExit+139
fffff800`7fa86799 488b0c2588010000 mov rcx,qword ptr [188h]
STACK_TEXT:
ffffc987`17e90808 fffff800`7fa86fe9 : 00000000`0000000a 00000000`00000188 00000000`000000ff 00000000`0000000b : nt!KeBugCheckEx
ffffc987`17e90810 fffff800`7fa822a8 : fffff800`0ed48280 ffffa901`692e9180 00000000`00000001 ffffb90a`3bb94180 : nt!KiBugCheckDispatch+0x69
ffffc987`17e90950 fffff800`7fa86799 : 00000007`685dbfee 000000a5`479fefa0 ffffc987`17e90b60 000000a5`3e8f3000 : nt!KiPageFault+0x468
ffffc987`17e90ae0 00007ffd`fc3ff484 : 00007ffd`fc376d04 000001ee`fda00b40 000001ee`fab15040 ffffffff`fffffffe : nt!KiSystemServiceExit+0x139
000000a5`479fef38 00007ffd`fc376d04 : 000001ee`fda00b40 000001ee`fab15040 ffffffff`fffffffe 00000000`000000ff : 0x00007ffd`fc3ff484
000000a5`479fef40 000001ee`fda00b40 : 000001ee`fab15040 ffffffff`fffffffe 00000000`000000ff 000000a5`479ff040 : 0x00007ffd`fc376d04
000000a5`479fef48 000001ee`fab15040 : ffffffff`fffffffe 00000000`000000ff 000000a5`479ff040 00007ffd`f9c9ca1b : 0x000001ee`fda00b40
000000a5`479fef50 ffffffff`fffffffe : 00000000`000000ff 000000a5`479ff040 00007ffd`f9c9ca1b 00000000`00000000 : 0x000001ee`fab15040
000000a5`479fef58 00000000`000000ff : 000000a5`479ff040 00007ffd`f9c9ca1b 00000000`00000000 00000000`00000000 : 0xffffffff`fffffffe
000000a5`479fef60 000000a5`479ff040 : 00007ffd`f9c9ca1b 00000000`00000000 00000000`00000000 000000a5`479ff020 : 0xff
000000a5`479fef68 00007ffd`f9c9ca1b : 00000000`00000000 00000000`00000000 000000a5`479ff020 000001ee`fda00a00 : 0x000000a5`479ff040
000000a5`479fef70 00000000`00000000 : 00000000`00000000 000000a5`479ff020 000001ee`fda00a00 00000000`000000ff : 0x00007ffd`f9c9ca1b
SYMBOL_NAME: nt!KiSystemServiceExit+139
IMAGE_VERSION: 10.0.26100.1742
STACK_COMMAND: .process /r /p 0xffffb90a395ad080; .thread 0xffffb90a3bb94080 ; kb
MODULE_NAME: AuthenticAMD
IMAGE_NAME: AuthenticAMD.sys
FAILURE_BUCKET_ID: IP_MISALIGNED_AuthenticAMD.sys
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {716d112a-8330-4bbb-160c-ec98297019d2}
Followup: MachineOwner
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 00007fffffff0000, memory referenced
Arg2: 00000000000000ff, IRQL
Arg3: 0000000000000064, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff801ec643bdb, address which referenced memory
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 968
Key : Analysis.Elapsed.mSec
Value: 5979
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 1
Key : Analysis.IO.Write.Mb
Value: 1
Key : Analysis.Init.CPU.mSec
Value: 406
Key : Analysis.Init.Elapsed.mSec
Value: 1406
Key : Analysis.Memory.CommitPeak.Mb
Value: 88
Key : Analysis.Version.DbgEng
Value: 10.0.27793.1000
Key : Analysis.Version.Description
Value: 10.2410.02.02 amd64fre
Key : Analysis.Version.Ext
Value: 1.2410.2.2
Key : Bugcheck.Code.LegacyAPI
Value: 0xa
Key : Bugcheck.Code.TargetModel
Value: 0xa
Key : Dump.Attributes.AsUlong
Value: 0x21008
Key : Dump.Attributes.DiagDataWrittenToHeader
Value: 1
Key : Dump.Attributes.ErrorCode
Value: 0x0
Key : Dump.Attributes.KernelGeneratedTriageDump
Value: 1
Key : Dump.Attributes.LastLine
Value: Dump completed successfully.
Key : Dump.Attributes.ProgressPercentage
Value: 0
Key : Failure.Bucket
Value: AV_nt!RtlpxVirtualUnwind
Key : Failure.Exception.IP.Address
Value: 0xfffff801ec643bdb
Key : Failure.Exception.IP.Module
Value: nt
Key : Failure.Exception.IP.Offset
Value: 0x243bdb
Key : Failure.Hash
Value: {90caf8d4-a034-a257-3599-d8f696fd9681}
Key : Stack.Pointer
Value: PRCBException
BUGCHECK_CODE: a
BUGCHECK_P1: 7fffffff0000
BUGCHECK_P2: ff
BUGCHECK_P3: 64
BUGCHECK_P4: fffff801ec643bdb
FILE_IN_CAB: 041025-8484-02.dmp
DUMP_FILE_ATTRIBUTES: 0x21008
Kernel Generated Triage Dump
FAULTING_THREAD: ffff9f8e02773280
READ_ADDRESS: fffff801ed3c34c0: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
unable to get nt!MmSpecialPagesInUse
00007fffffff0000
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 2
PROCESS_NAME: System
TRAP_FRAME: ffffd5804ecf2ef0 -- (.trap 0xffffd5804ecf2ef0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=00007fffffff0000 rbx=0000000000000000 rcx=00007fffffff0000
rdx=00007ffffffeffff rsi=0000000000000000 rdi=0000000000000000
rip=fffff801ec643bdb rsp=ffffd5804ecf3080 rbp=ffffd5804ecf36a0
r8=ffffd5804ecf3238 r9=0000000000000000 r10=fffff801ec400000
r11=ffffd5804ecf30c0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up di ng nz na po nc
nt!RtlpxVirtualUnwind+0x50b:
fffff801`ec643bdb 0fb600 movzx eax,byte ptr [rax] ds:00007fff`ffff0000=??
Resetting default scope
STACK_TEXT:
ffffd580`4ecf2da8 fffff801`eca8f8e9 : 00000000`0000000a 00007fff`ffff0000 00000000`000000ff 00000000`00000064 : nt!KeBugCheckEx
ffffd580`4ecf2db0 fffff801`eca8aba8 : ffffd580`4ecf31a0 fffff801`ec400000 00000000`00000000 fffff801`ec4baba8 : nt!KiBugCheckDispatch+0x69
ffffd580`4ecf2ef0 fffff801`ec643bdb : fffff801`ec400000 fffff801`ec72f060 ffff9508`674998e0 fffff801`ec4e4744 : nt!KiPageFault+0x468
ffffd580`4ecf3080 fffff801`ec779d6b : ffffd580`4ecf31a0 fffff801`ec400000 00000002`f0ebbb10 00000000`00000000 : nt!RtlpxVirtualUnwind+0x50b
ffffd580`4ecf3140 fffff801`ec77afa9 : ffff9508`67499750 ffffd580`4ecf3dd0 ffff9508`67499750 ffffd580`4ecf38d0 : nt!RtlDispatchException+0x1fb
ffffd580`4ecf38a0 fffff801`eca7bb92 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDispatchException+0xac9
ffffd580`4ecf3fb0 fffff801`eca7bb60 : fffff801`eca8fa3e fffff801`ec7f0360 fffff801`ec688bda 00000000`00000000 : nt!KxExceptionDispatchOnExceptionStack+0x12
ffff9508`67499568 fffff801`eca8fa3e : fffff801`ec7f0360 fffff801`ec688bda 00000000`00000000 00000000`00002700 : nt!KiExceptionDispatchOnExceptionStackContinue
ffff9508`67499570 fffff801`eca8a725 : ffff9508`67499810 fffff801`ec72810f 00000000`00000000 ffff9508`674999b0 : nt!KiExceptionDispatch+0x13e
ffff9508`67499750 fffff801`ec72f060 : 00000002`f0ebbb10 00000000`00000000 00000002`00000003 ffff9508`67499a01 : nt!KiGeneralProtectionFault+0x365
ffff9508`674998e0 00000002`f0ebbb10 : 00000000`00000000 00000002`00000003 ffff9508`67499a01 00000000`00000000 : nt!KiCheckForTimerExpiration
ffff9508`674998e8 00000000`00000000 : 00000002`00000003 ffff9508`67499a01 00000000`00000000 00000000`00000000 : 0x00000002`f0ebbb10
SYMBOL_NAME: nt!RtlpxVirtualUnwind+50b
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
IMAGE_VERSION: 10.0.26100.3775
STACK_COMMAND: .process /r /p 0xfffff801ed3cdf80; .thread 0xffff9f8e02773280 ; kb
BUCKET_ID_FUNC_OFFSET: 50b
FAILURE_BUCKET_ID: AV_nt!RtlpxVirtualUnwind
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {90caf8d4-a034-a257-3599-d8f696fd9681}
KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common BugCheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff800a8bd9aca, The address that the exception occurred at
Arg3: 0000000000000001, Parameter 0 of the exception
Arg4: 0000000000000000, Parameter 1 of the exception
Debugging Details:
------------------
*************************************************************************
*** ***
*** ***
*** Either you specified an unqualified symbol, or your debugger ***
*** doesn't have full symbol information. Unqualified symbol ***
*** resolution is turned off by default. Please either specify a ***
*** fully qualified symbol module!symbolname, or enable resolution ***
*** of unqualified symbols by typing ".symopt- 100". Note that ***
*** enabling unqualified symbol resolution with network symbol ***
*** server shares in the symbol path may cause the debugger to ***
*** appear to hang for long periods of time when an incorrect ***
*** symbol name is typed or the network symbol server is down. ***
*** ***
*** For some commands to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: ExceptionRecord ***
*** ***
*************************************************************************
*************************************************************************
*** ***
*** ***
*** Either you specified an unqualified symbol, or your debugger ***
*** doesn't have full symbol information. Unqualified symbol ***
*** resolution is turned off by default. Please either specify a ***
*** fully qualified symbol module!symbolname, or enable resolution ***
*** of unqualified symbols by typing ".symopt- 100". Note that ***
*** enabling unqualified symbol resolution with network symbol ***
*** server shares in the symbol path may cause the debugger to ***
*** appear to hang for long periods of time when an incorrect ***
*** symbol name is typed or the network symbol server is down. ***
*** ***
*** For some commands to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: ContextRecord ***
*** ***
*************************************************************************
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 937
Key : Analysis.Elapsed.mSec
Value: 971
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 1
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 437
Key : Analysis.Init.Elapsed.mSec
Value: 1418
Key : Analysis.Memory.CommitPeak.Mb
Value: 88
Key : Analysis.Version.DbgEng
Value: 10.0.27793.1000
Key : Analysis.Version.Description
Value: 10.2410.02.02 amd64fre
Key : Analysis.Version.Ext
Value: 1.2410.2.2
Key : Bugcheck.Code.LegacyAPI
Value: 0x1e
Key : Bugcheck.Code.TargetModel
Value: 0x1e
Key : Dump.Attributes.AsUlong
Value: 0x21008
Key : Dump.Attributes.DiagDataWrittenToHeader
Value: 1
Key : Dump.Attributes.ErrorCode
Value: 0x0
Key : Dump.Attributes.KernelGeneratedTriageDump
Value: 1
Key : Dump.Attributes.LastLine
Value: Dump completed successfully.
Key : Dump.Attributes.ProgressPercentage
Value: 0
Key : Failure.Bucket
Value: AV_W_nt!KeYieldExecution
Key : Failure.Exception.IP.Address
Value: 0xfffff800a8bd9aca
Key : Failure.Exception.IP.Module
Value: nt
Key : Failure.Exception.IP.Offset
Value: 0x3d9aca
Key : Failure.Hash
Value: {af7f7542-d988-2608-d909-8136f1817fcc}
BUGCHECK_CODE: 1e
BUGCHECK_P1: ffffffffc0000005
BUGCHECK_P2: fffff800a8bd9aca
BUGCHECK_P3: 1
BUGCHECK_P4: 0
FILE_IN_CAB: 041025-8671-01.dmp
DUMP_FILE_ATTRIBUTES: 0x21008
Kernel Generated Triage Dump
FAULTING_THREAD: ffffe60f4fb59080
EXCEPTION_PARAMETER1: 0000000000000001
EXCEPTION_PARAMETER2: 0000000000000000
WRITE_ADDRESS: fffff800a97c34c0: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
unable to get nt!MmSpecialPagesInUse
0000000000000000
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: TiWorker.exe
STACK_TEXT:
ffffd501`1cc59348 fffff800`a8b7aff6 : 00000000`0000001e ffffffff`c0000005 fffff800`a8bd9aca 00000000`00000001 : nt!KeBugCheckEx
ffffd501`1cc59350 fffff800`a8e8fa45 : 00000000`c0000005 00000000`00000000 00000000`00000000 000000e0`a8bc964f : nt!KiDispatchException+0xb16
ffffd501`1cc59a60 fffff800`a8e8ab82 : 00000000`00000100 ffffd501`1cc5a0b0 00000000`00000000 fffff800`3a35a13c : nt!KiExceptionDispatch+0x145
ffffd501`1cc59c40 fffff800`a8bd9aca : ffffd501`00000000 00000000`00000000 ffffe60f`4475e850 00000000`00000000 : nt!KiPageFault+0x442
ffffd501`1cc59dd0 00000000`c01c0005 : 00000000`00000102 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KeYieldExecution+0x3a
ffffd501`1cc59e60 00000000`00000102 : 00000000`00000000 00000000`00000000 00000000`00000000 ffff898a`00000000 : 0xc01c0005
ffffd501`1cc59e68 00000000`00000000 : 00000000`00000000 00000000`00000000 ffff898a`00000000 ffff898a`e7f1fd00 : 0x102
SYMBOL_NAME: nt!KeYieldExecution+3a
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
IMAGE_VERSION: 10.0.26100.3775
STACK_COMMAND: .process /r /p 0xffffe60f4f23e080; .thread 0xffffe60f4fb59080 ; kb
BUCKET_ID_FUNC_OFFSET: 3a
FAILURE_BUCKET_ID: AV_W_nt!KeYieldExecution
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {af7f7542-d988-2608-d909-8136f1817fcc}
Followup: MachineOwner
---------
PnpActivityId : {00000000-0000-0000-0000-000000000000}
PnpActivityTime : 133887806643304620
PnpEventInformation: 0
PnpEventInProgress : 0
PnpProblemCode : 21
PnpVetoType : 0
DeviceId : SWD\DRIVERENUM\{86f65302-34a5-441c-8e16-c05c2d9e6151}#FMAPO&6&3b178bf3&0
VetoString :
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 0000000004c2754b, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff803bd68eeb6, address which referenced memory
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 1203
Key : Analysis.Elapsed.mSec
Value: 1244
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 1
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 328
Key : Analysis.Init.Elapsed.mSec
Value: 969
Key : Analysis.Memory.CommitPeak.Mb
Value: 86
Key : Analysis.Version.DbgEng
Value: 10.0.27793.1000
Key : Analysis.Version.Description
Value: 10.2410.02.02 amd64fre
Key : Analysis.Version.Ext
Value: 1.2410.2.2
Key : Bugcheck.Code.LegacyAPI
Value: 0xa
Key : Bugcheck.Code.TargetModel
Value: 0xa
Key : Failure.Bucket
Value: IP_MISALIGNED_AuthenticAMD.sys
Key : Failure.Exception.IP.Address
Value: 0xfffff803bd68eeb6
Key : Failure.Exception.IP.Module
Value: nt
Key : Failure.Exception.IP.Offset
Value: 0x28eeb6
Key : Failure.Hash
Value: {716d112a-8330-4bbb-160c-ec98297019d2}
Key : WER.OS.Branch
Value: ge_release
Key : WER.OS.Version
Value: 10.0.26100.1
BUGCHECK_CODE: a
BUGCHECK_P1: 4c2754b
BUGCHECK_P2: 2
BUGCHECK_P3: 0
BUGCHECK_P4: fffff803bd68eeb6
FILE_IN_CAB: 041025-8484-01.dmp
FAULTING_THREAD: ffffba019c39c040
READ_ADDRESS: fffff803be3c34b0: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
unable to get nt!MmSpecialPagesInUse
0000000004c2754b
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: svchost.exe
TRAP_FRAME: ffffdd845bf08df0 -- (.trap 0xffffdd845bf08df0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000001a5c rbx=0000000000000000 rcx=ffffca002a2d1180
rdx=ffffba018f9f46a8 rsi=0000000000000000 rdi=0000000000000000
rip=fffff803bd68eeb6 rsp=ffffdd845bf08f80 rbp=b8809ad90ef42aac
r8=ffffba018f9f3ee8 r9=000000000000005c r10=0000000000000000
r11=ffffdd845bf09078 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz ac po nc
nt!KeSetCoalescableTimer+0x146:
fffff803`bd68eeb6 0384c00f88c104 add eax,dword ptr [rax+rax*8+4C1880Fh] ds:00000000`04c2754b=????????
Resetting default scope
LOCK_ADDRESS: fffff803be38a640 -- (!locks fffff803be38a640)
Unable to get value of PsActiveProcessHead.Flink
Cannot get _ERESOURCE Flag field
Unexpected resource format: 0
1 total locks
PNP_TRIAGE_DATA:
Lock address : 0xfffff803be38a640
Thread Count : 0
Thread address: 0x0000000000000000
Thread wait : 0x0
MISALIGNED_IP:
nt!KeSetCoalescableTimer+146
fffff803`bd68eeb6 0384c00f88c104 add eax,dword ptr [rax+rax*8+4C1880Fh]
STACK_TEXT:
ffffdd84`5bf08ca8 fffff803`bda86fe9 : 00000000`0000000a 00000000`04c2754b 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
ffffdd84`5bf08cb0 fffff803`bda822a8 : 00000000`00000000 00000000`00000000 00000000`00000001 ffffffff`fffffffd : nt!KiBugCheckDispatch+0x69
ffffdd84`5bf08df0 fffff803`bd68eeb6 : ffffdd84`5bf09010 fffff803`bda86658 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x468
ffffdd84`5bf08f80 fffff803`bddbec29 : ffffdd84`5bf09098 ffff950d`080a91a0 00000000`00000000 ffff950c`ff2fc8d0 : nt!KeSetCoalescableTimer+0x146
ffffdd84`5bf09080 fffff803`bdd29e4c : 00000000`00000000 ffff950d`080a91a0 ffff950c`ff3fea20 ffff950c`ff3fea20 : nt!PiDrvDbNodeActionCallback+0xa9
ffffdd84`5bf090c0 fffff803`bdd293fa : 00000000`00000000 ffff950c`ff3fea80 ffffdd84`5bf091b1 ffff950c`ff2fc8d0 : nt!DrvDbUnloadDatabaseNode+0x58
ffffdd84`5bf09130 fffff803`bdd2902e : ffff950c`ff2fc8d0 00000000`00000000 ffffffff`00000002 ffff950c`ff3fea20 : nt!DrvDbOpenObjectRegKey+0x3ba
ffffdd84`5bf091f0 fffff803`bdd28b9c : 00000000`00000008 ffff950d`080a60f8 00000000`00000002 fffff803`bdd08adf : nt!DrvDbOpenDriverPackageRegKey+0x3a
ffffdd84`5bf09250 fffff803`bdd27ede : ffff950c`ff2fc8d0 ffff950d`080a91a0 ffffdd84`5bf09480 ffffdd84`00000e00 : nt!DrvDbGetDriverPackageMappedProperty+0xb4c
ffffdd84`5bf09340 fffff803`bdd0a166 : ffff950c`ff000000 00000000`00000000 ffff1e42`47f1d2d9 00000004`00000040 : nt!DrvDbDispatchDriverPackage+0xae
ffffdd84`5bf093a0 fffff803`bdc8af2b : ffff950d`08de7e01 00000000`00000001 ffffdd84`5bf09858 00000000`00000001 : nt!PnpGetObjectPropertyWorker+0x466
ffffdd84`5bf095c0 fffff803`bdc8a383 : 00000000`0000037c ffff950d`00000000 ffffba01`8f835e30 00000000`00000001 : nt!PiCMHandleIoctl+0x47b
ffffdd84`5bf09740 fffff803`bdc89167 : 00000000`00000001 00000000`00000001 00000000`00000103 00000000`00000000 : nt!PiCMFastIoDeviceDispatch+0x53
ffffdd84`5bf09790 fffff803`bdc88aae : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!IopXxxControlFile+0x6a7
ffffdd84`5bf09a00 fffff803`bda86658 : ffffba01`9e150cb0 00000000`00000000 ffffdd84`5bf09b60 00000052`eb1fcd30 : nt!NtDeviceIoControlFile+0x5e
ffffdd84`5bf09a70 00007ffb`4bbfeee4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
00000052`eb1fca78 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffb`4bbfeee4
SYMBOL_NAME: nt!KeSetCoalescableTimer+146
IMAGE_VERSION: 10.0.26100.1742
STACK_COMMAND: .process /r /p 0xffffba019c59f0c0; .thread 0xffffba019c39c040 ; kb
MODULE_NAME: AuthenticAMD
IMAGE_NAME: AuthenticAMD.sys
FAILURE_BUCKET_ID: IP_MISALIGNED_AuthenticAMD.sys
OS_VERSION: 10.0.26100.1
BUILDLAB_STR: ge_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {716d112a-8330-4bbb-160c-ec98297019d2}
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the BugCheck
Arg2: fffff8045dad7eb4, Address of the instruction which caused the BugCheck
Arg3: fffffe074c03d660, Address of the context record for the exception that caused the BugCheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 781
Key : Analysis.Elapsed.mSec
Value: 3201
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 1
Key : Analysis.IO.Write.Mb
Value: 2
Key : Analysis.Init.CPU.mSec
Value: 453
Key : Analysis.Init.Elapsed.mSec
Value: 6257
Key : Analysis.Memory.CommitPeak.Mb
Value: 93
Key : Analysis.Version.DbgEng
Value: 10.0.27793.1000
Key : Analysis.Version.Description
Value: 10.2410.02.02 amd64fre
Key : Analysis.Version.Ext
Value: 1.2410.2.2
Key : Bugcheck.Code.LegacyAPI
Value: 0x3b
Key : Bugcheck.Code.TargetModel
Value: 0x3b
Key : Dump.Attributes.AsUlong
Value: 0x21008
Key : Dump.Attributes.DiagDataWrittenToHeader
Value: 1
Key : Dump.Attributes.ErrorCode
Value: 0x0
Key : Dump.Attributes.KernelGeneratedTriageDump
Value: 1
Key : Dump.Attributes.LastLine
Value: Dump completed successfully.
Key : Dump.Attributes.ProgressPercentage
Value: 0
Key : Failure.Bucket
Value: AV_FLTMGR!FltpPerformPreCallbacksWorker
Key : Failure.Exception.IP.Address
Value: 0xfffff8045dad7eb4
Key : Failure.Exception.IP.Module
Value: FLTMGR
Key : Failure.Exception.IP.Offset
Value: 0x7eb4
Key : Failure.Hash
Value: {a374902e-70dc-42ac-3104-3d5a9649eb03}
BUGCHECK_CODE: 3b
BUGCHECK_P1: c0000005
BUGCHECK_P2: fffff8045dad7eb4
BUGCHECK_P3: fffffe074c03d660
BUGCHECK_P4: 0
FILE_IN_CAB: 040825-14031-01.dmp
DUMP_FILE_ATTRIBUTES: 0x21008
Kernel Generated Triage Dump
FAULTING_THREAD: ffff9a8646c95080
CONTEXT: fffffe074c03d660 -- (.cxr 0xfffffe074c03d660)
rax=000000004c03e3a0 rbx=ffff9a864de11010 rcx=ffff9a863b79b4b0
rdx=0000000000000100 rsi=ffff9a863b622c60 rdi=ffff9a864de110f8
rip=fffff8045dad7eb4 rsp=fffffe074c03e0b8 rbp=fffffe074c03e1c0
r8=ffff9a863b5b49c0 r9=0000000000000002 r10=fffff804cc1ea9c0
r11=ffff9a8644676810 r12=0000000000000000 r13=ffff9a863b7c02d0
r14=ffff9a863b6228a0 r15=ffff9a86372f6200
iopl=0 nv up ei ng nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050286
FLTMGR!FltpPerformPreCallbacksWorker+0x214:
fffff804`5dad7eb4 8b4028 mov eax,dword ptr [rax+28h] ds:002b:00000000`4c03e3c8=????????
Resetting default scope
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: svchost.exe
STACK_TEXT:
fffffe07`4c03e0b8 fffffe07`4c03e3e0 : fffff804`5dad7961 fffffe07`4c03e3a0 00000000`00000f00 00000000`00000000 : FLTMGR!FltpPerformPreCallbacksWorker+0x214
fffffe07`4c03e2a8 fffff804`5dad7961 : fffffe07`4c03e3a0 00000000`00000f00 00000000`00000000 00000000`00000000 : 0xfffffe07`4c03e3e0
fffffe07`4c03e2b0 fffff804`5db36847 : fffffe07`4c039000 fffffe07`4c03e3e0 ffff9a86`455b4900 00000000`00000000 : FLTMGR!FltpPassThroughInternal+0xf1
fffffe07`4c03e360 fffff804`cc09697e : ffff9a86`4df46b00 00000000`00000000 00000000`00000000 00000000`00000000 : FLTMGR!FltpCreate+0x687
fffffe07`4c03e410 fffff804`cc7c7a7a : ffff8283`692bca05 fffffe07`4c03e6f0 00000000`00000000 fffff804`6e898718 : nt!IofCallDriver+0xbe
fffffe07`4c03e450 fffff804`cc621680 : ffffba07`32bdf5c3 ffff8283`692bca90 00000000`00000040 fffffe07`4c03e838 : nt!IopParseDevice+0x126a
fffffe07`4c03e5f0 fffff804`cc61f671 : ffff9a86`4ccd0a01 fffffe07`4c03e838 ffff9a86`00000840 ffff9a86`357d3b50 : nt!ObpLookupObjectName+0xcf0
fffffe07`4c03e7b0 fffff804`cc740db2 : 00000000`00000000 ffff9a86`357d3b50 00000000`00000001 fffff804`cc65c7b3 : nt!ObOpenObjectByNameEx+0x201
fffffe07`4c03e900 fffff804`cc740998 : 00000018`1b27a928 00000000`00100000 00000018`1b27a968 00000018`1b27a9c8 : nt!IopCreateFile+0x37a
fffffe07`4c03e9e0 fffff804`cc486658 : 00000000`00000000 00000000`00000002 fffffe07`4c03eb60 00000018`1b27af90 : nt!NtOpenFile+0x58
fffffe07`4c03ea70 00007ffa`ca35f464 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
00000018`1b27a8d8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffa`ca35f464
SYMBOL_NAME: FLTMGR!FltpPerformPreCallbacksWorker+214
MODULE_NAME: FLTMGR
IMAGE_NAME: FLTMGR.SYS
IMAGE_VERSION: 10.0.26100.1150
STACK_COMMAND: .cxr 0xfffffe074c03d660 ; kb
BUCKET_ID_FUNC_OFFSET: 214
FAILURE_BUCKET_ID: AV_FLTMGR!FltpPerformPreCallbacksWorker
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {a374902e-70dc-42ac-3104-3d5a9649eb03}
DRIVER_OVERRAN_STACK_BUFFER (f7)
A driver has overrun a stack-based buffer. This overrun could potentially
allow a malicious user to gain control of this machine.
DESCRIPTION
A driver overran a stack-based buffer (or local variable) in a way that would
have overwritten the function's return address and jumped back to an arbitrary
address when the function returned. This is the classic "buffer overrun"
hacking attack and the system has been brought down to prevent a malicious user
from gaining complete control of it.
Do a kb to get a stack backtrace -- the last routine on the stack before the
buffer overrun handlers and BugCheck call is the one that overran its local
variable(s).
Arguments:
Arg1: ffffb2879618d5d8, Actual security check cookie from the stack
Arg2: 00008be06b0181e2, Expected security check cookie
Arg3: ffff741f94fe7e1d, Complement of the expected security check cookie
Arg4: 0000000000000000, zero
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 765
Key : Analysis.Elapsed.mSec
Value: 777
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 1
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 359
Key : Analysis.Init.Elapsed.mSec
Value: 1630
Key : Analysis.Memory.CommitPeak.Mb
Value: 87
Key : Analysis.Version.DbgEng
Value: 10.0.27793.1000
Key : Analysis.Version.Description
Value: 10.2410.02.02 amd64fre
Key : Analysis.Version.Ext
Value: 1.2410.2.2
Key : Bugcheck.Code.LegacyAPI
Value: 0xf7
Key : Bugcheck.Code.TargetModel
Value: 0xf7
Key : Dump.Attributes.AsUlong
Value: 0x21008
Key : Dump.Attributes.DiagDataWrittenToHeader
Value: 1
Key : Dump.Attributes.ErrorCode
Value: 0x0
Key : Dump.Attributes.KernelGeneratedTriageDump
Value: 1
Key : Dump.Attributes.LastLine
Value: Dump completed successfully.
Key : Dump.Attributes.ProgressPercentage
Value: 0
Key : Failure.Bucket
Value: 0xF7_MISSING_GSFRAME_nt!_report_gsfailure
Key : Failure.Hash
Value: {82d2c1b5-b0cb-60a5-9a5d-78c8c4284f84}
BUGCHECK_CODE: f7
BUGCHECK_P1: ffffb2879618d5d8
BUGCHECK_P2: 8be06b0181e2
BUGCHECK_P3: ffff741f94fe7e1d
BUGCHECK_P4: 0
FILE_IN_CAB: 041025-8125-01.dmp
DUMP_FILE_ATTRIBUTES: 0x21008
Kernel Generated Triage Dump
FAULTING_THREAD: ffffc382c39d5040
SECURITY_COOKIE: Expected 00008be06b0181e2 found ffffb2879618d5d8
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: Registry
STACK_TEXT:
ffffb287`9618c2d8 fffff807`7d6f3685 : 00000000`000000f7 ffffb287`9618d5d8 00008be0`6b0181e2 ffff741f`94fe7e1d : nt!KeBugCheckEx
ffffb287`9618c2e0 fffff807`7d6bbcd2 : ffffb287`9618c3c8 ffffb287`9618c9c0 00000000`00000110 ffffd780`bed27d10 : nt!_report_gsfailure+0x25
ffffb287`9618c320 fffff807`7d6bbc67 : 7fffffff`fffffffc fffff807`7d6bbc54 ffffd780`bed10000 ffffb287`9618c410 : nt!_GSHandlerCheckCommon+0x5a
ffffb287`9618c350 fffff807`7d884f72 : ffffb287`9618cb40 00000000`00000000 ffffb287`9618c410 00000000`00000000 : nt!_GSHandlerCheck+0x13
ffffb287`9618c380 fffff807`7d579e42 : ffffb287`9618c410 fffff807`7d200000 fffff807`7da601f8 fffff807`7d321ec0 : nt!RtlpExecuteHandlerForException+0x12
ffffb287`9618c3b0 fffff807`7d57afa9 : ffffb287`9618d400 ffffb287`9618d040 ffffb287`9618d400 ffffb287`9618cb40 : nt!RtlDispatchException+0x2d2
ffffb287`9618cb10 fffff807`7d88fa45 : 00000000`c0000005 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDispatchException+0xac9
ffffb287`9618d220 fffff807`7d88ab82 : ffff9587`cec45930 ffffb287`9618d551 7fffffff`fffffffc 00000000`00000000 : nt!KiExceptionDispatch+0x145
ffffb287`9618d400 fffff807`7da601f8 : fffff807`7da60202 ffff9587`cec45900 ffffb287`9618d700 ffffb287`9618d6a0 : nt!KiPageFault+0x442
ffffb287`9618d598 ffffb287`9618d940 : fffff807`7da5f7ef 00000000`0000001a ffffb287`9618d930 ffffb287`9618d8c0 : nt!CmpDoParseKey+0x480
ffffb287`9618d838 fffff807`7da5f7ef : 00000000`0000001a ffffb287`9618d930 ffffb287`9618d8c0 ffffb287`9618dc78 : 0xffffb287`9618d940
ffffb287`9618d840 fffff807`7da5db71 : 00000000`00000f01 00000000`00000000 ffffc382`c6dd2660 00000000`00000000 : nt!CmpParseKey+0x34f
ffffb287`9618da30 fffff807`7da5c461 : ffffc382`c6dd2601 ffffb287`9618dc78 ffffc382`000002c0 ffffc382`b2857390 : nt!ObpLookupObjectName+0x3f1
ffffb287`9618dbf0 fffff807`7dad75de : ffffb287`00000000 ffffc382`b2857390 ffffc382`b2857390 ffffb287`c0000034 : nt!ObOpenObjectByNameEx+0x201
ffffb287`9618dd40 fffff807`7dad7185 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!CmCreateKey+0x42e
ffffb287`9618dfc0 fffff807`7d88ef58 : 00000000`00000000 ffff9587`d7dfe050 ffff3967`fd195fd2 fffff807`7da33dc9 : nt!NtCreateKey+0x55
ffffb287`9618e020 fffff807`7d87d420 : fffff807`7dabf16b 00000000`00000000 00000000`00000000 ffffb287`9618e2c0 : nt!KiSystemServiceCopyEnd+0x28
ffffb287`9618e228 fffff807`7dabf16b : 00000000`00000000 00000000`00000000 ffffb287`9618e2c0 00000000`00000000 : nt!KiServiceLinkage
ffffb287`9618e230 fffff807`7dabeb43 : 00000000`00000002 ffff9587`d8b7f5a0 ffff9587`c73fd0e0 00000000`02000000 : nt!RegRtlCreateTreeTransacted+0xf7
ffffb287`9618e300 fffff807`7dabd711 : ffff9587`c723e6f0 00000000`00000002 ffff3967`00000002 fffff807`7dd39476 : nt!DrvDbOpenObjectRegKey+0x313
ffffb287`9618e3c0 fffff807`7db1673f : 00000000`00000060 ffffffff`ffffffff 00000000`00000001 00000000`000005a0 : nt!DrvDbDispatchDriverPackage+0xf1
ffffb287`9618e420 fffff807`7da8cdcb : 00000000`00000008 ffffb287`9618e858 00000000`00000000 00000065`4de7c610 : nt!PnpOpenObjectRegKey+0x18b
ffffb287`9618e510 fffff807`7da83940 : 00000065`4de7c5e0 00000000`00000010 00000000`00000030 00000000`00000000 : nt!PiCMOpenObjectKey+0xeb
ffffb287`9618e5c0 fffff807`7da82c53 : 00000000`00000380 ffff9587`00000000 ffffc382`b27a3cc0 00000000`00000001 : nt!PiCMHandleIoctl+0x5c0
ffffb287`9618e740 fffff807`7da81a37 : 00000000`00000001 00000000`00000001 00000000`00000103 00000000`00000000 : nt!PiCMFastIoDeviceDispatch+0x53
ffffb287`9618e790 fffff807`7da8137e : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!IopXxxControlFile+0x6a7
ffffb287`9618ea00 fffff807`7d88ef58 : ffffc382`c7725150 00000000`00000000 ffffb287`9618eb60 00000065`4de79fc0 : nt!NtDeviceIoControlFile+0x5e
ffffb287`9618ea70 00007ffb`68adc0a4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
00000065`4de7c458 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffb`68adc0a4
SYMBOL_NAME: nt!_report_gsfailure+25
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
IMAGE_VERSION: 10.0.26100.3775
STACK_COMMAND: .process /r /p 0xffffc382c28f2080; .thread 0xffffc382c39d5040 ; kb
BUCKET_ID_FUNC_OFFSET: 25
FAILURE_BUCKET_ID: 0xF7_MISSING_GSFRAME_nt!_report_gsfailure
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {82d2c1b5-b0cb-60a5-9a5d-78c8c4284f84}
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 0000000000000002, memory referenced
Arg2: 00000000000000ff, IRQL
Arg3: 00000000000000ce, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff801a548ecde, address which referenced memory
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 812
Key : Analysis.Elapsed.mSec
Value: 837
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 1
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 359
Key : Analysis.Init.Elapsed.mSec
Value: 1578
Key : Analysis.Memory.CommitPeak.Mb
Value: 87
Key : Analysis.Version.DbgEng
Value: 10.0.27793.1000
Key : Analysis.Version.Description
Value: 10.2410.02.02 amd64fre
Key : Analysis.Version.Ext
Value: 1.2410.2.2
Key : Bugcheck.Code.LegacyAPI
Value: 0xa
Key : Bugcheck.Code.TargetModel
Value: 0xa
Key : Dump.Attributes.AsUlong
Value: 0x21008
Key : Dump.Attributes.DiagDataWrittenToHeader
Value: 1
Key : Dump.Attributes.ErrorCode
Value: 0x0
Key : Dump.Attributes.KernelGeneratedTriageDump
Value: 1
Key : Dump.Attributes.LastLine
Value: Dump completed successfully.
Key : Dump.Attributes.ProgressPercentage
Value: 0
Key : Failure.Bucket
Value: IP_MISALIGNED_AuthenticAMD.sys
Key : Failure.Exception.IP.Address
Value: 0xfffff801a548ecde
Key : Failure.Exception.IP.Module
Value: nt
Key : Failure.Exception.IP.Offset
Value: 0x68ecde
Key : Failure.Hash
Value: {716d112a-8330-4bbb-160c-ec98297019d2}
BUGCHECK_CODE: a
BUGCHECK_P1: 2
BUGCHECK_P2: ff
BUGCHECK_P3: ce
BUGCHECK_P4: fffff801a548ecde
FILE_IN_CAB: 041025-8343-01.dmp
DUMP_FILE_ATTRIBUTES: 0x21008
Kernel Generated Triage Dump
FAULTING_THREAD: ffffc80e5a904080
READ_ADDRESS: fffff801a5dc34c0: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
unable to get nt!MmSpecialPagesInUse
0000000000000002
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: chrome.exe
TRAP_FRAME: ffffea820ee52950 -- (.trap 0xffffea820ee52950)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000002 rbx=0000000000000000 rcx=0000000100000000
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff801a548ecde rsp=ffffea820ee52ae0 rbp=ffffea820ee52b60
r8=000000d2e8bfe188 r9=00007ff81821e1a0 r10=0000000000002710
r11=0000000000000246 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up di pl zr na po nc
nt!KiSystemCall64+0x29e:
fffff801`a548ecde 0000 add byte ptr [rax],al ds:00000000`00000002=??
Resetting default scope
MISALIGNED_IP:
nt!KiSystemCall64+29e
fffff801`a548ecde 0000 add byte ptr [rax],al
STACK_TEXT:
ffffea82`0ee52808 fffff801`a548f8e9 : 00000000`0000000a 00000000`00000002 00000000`000000ff 00000000`000000ce : nt!KeBugCheckEx
ffffea82`0ee52810 fffff801`a548aba8 : 00000000`00000000 fffff801`a508a884 ffffda81`35db7180 ffffc80e`5a904080 : nt!KiBugCheckDispatch+0x69
ffffea82`0ee52950 fffff801`a548ecde : ffffc80e`5a904080 00000000`00000138 ffffea82`0ee52b60 00000000`00000008 : nt!KiPageFault+0x468
ffffea82`0ee52ae0 00007ff8`1963f7f4 : 00007ff8`1818349c 00000000`4fca60a2 00ffffff`ffffffff 40000000`00000000 : nt!KiSystemCall64+0x29e
000000d2`e8bfe148 00007ff8`1818349c : 00000000`4fca60a2 00ffffff`ffffffff 40000000`00000000 0000236c`000a00f0 : 0x00007ff8`1963f7f4
000000d2`e8bfe150 00000000`4fca60a2 : 00ffffff`ffffffff 40000000`00000000 0000236c`000a00f0 00000000`00000000 : 0x00007ff8`1818349c
000000d2`e8bfe158 00ffffff`ffffffff : 40000000`00000000 0000236c`000a00f0 00000000`00000000 00007fff`878ce090 : 0x4fca60a2
000000d2`e8bfe160 40000000`00000000 : 0000236c`000a00f0 00000000`00000000 00007fff`878ce090 00000000`00000000 : 0x00ffffff`ffffffff
000000d2`e8bfe168 0000236c`000a00f0 : 00000000`00000000 00007fff`878ce090 00000000`00000000 00000000`00000000 : 0x40000000`00000000
000000d2`e8bfe170 00000000`00000000 : 00007fff`878ce090 00000000`00000000 00000000`00000000 00000000`00000000 : 0x0000236c`000a00f0
SYMBOL_NAME: nt!KiSystemCall64+29e
IMAGE_VERSION: 10.0.26100.3775
STACK_COMMAND: .process /r /p 0xffffc80e58f2f080; .thread 0xffffc80e5a904080 ; kb
MODULE_NAME: AuthenticAMD
IMAGE_NAME: AuthenticAMD.sys
FAILURE_BUCKET_ID: IP_MISALIGNED_AuthenticAMD.sys
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {716d112a-8330-4bbb-160c-ec98297019d2}