UNEXPECTED_KERNEL_MODE_TRAP (7f)
This means a trap occurred in kernel mode, and it's a trap of a kind
that the kernel isn't allowed to have/catch (bound trap) or that
is always instant death (double fault). The first number in the
BugCheck params is the number of the trap (8 = double fault, etc)
Consult an Intel x86 family manual to learn more about what these
traps are. Here is a *portion* of those codes:
If kv shows a taskGate
use .tss on the part before the colon, then kv.
Else if kv shows a trapframe
use .trap on that value
Else
.trap on the appropriate frame will show where the trap was taken
(on x86, this will be the ebp that goes with the procedure KiTrap)
Endif
kb will then show the corrected stack.
Arguments:
Arg1: 0000000000000008, EXCEPTION_DOUBLE_FAULT
Arg2: ffffc981dbc5ae70
Arg3: 0000000010000000
Arg4: fffff8003365c0f9
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 2500
Key : Analysis.Elapsed.mSec
Value: 7455
Key : Analysis.IO.Other.Mb
Value: 17
Key : Analysis.IO.Read.Mb
Value: 0
Key : Analysis.IO.Write.Mb
Value: 18
Key : Analysis.Init.CPU.mSec
Value: 1000
Key : Analysis.Init.Elapsed.mSec
Value: 55214
Key : Analysis.Memory.CommitPeak.Mb
Value: 82
Key : Bugcheck.Code.LegacyAPI
Value: 0x7f
Key : Bugcheck.Code.TargetModel
Value: 0x7f
Key : Failure.Bucket
Value: IP_MISALIGNED_GenuineIntel.sys
Key : Failure.Hash
Value: {e930d917-b247-3f7f-23cb-88a0c9f1b274}
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Version
Value: 10.0.19041.1
BUGCHECK_CODE: 7f
BUGCHECK_P1: 8
BUGCHECK_P2: ffffc981dbc5ae70
BUGCHECK_P3: 10000000
BUGCHECK_P4: fffff8003365c0f9
FILE_IN_CAB: 041524-7984-01.dmp
TRAP_FRAME: ffffc981dbc5ae70 -- (.trap 0xffffc981dbc5ae70)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=000000006b1aed00 rbx=0000000000000000 rcx=ffff84f28739fa08
rdx=ffff84c2613097f8 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8003365c0f9 rsp=0000000010000000 rbp=00000000000003e0
r8=0000000000000000 r9=0000000000000000 r10=ffffb20ef2b758a0
r11=0000000000000002 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
nt!RemoveListHeadPte+0x55:
fffff800`3365c0f9 c2a801 ret 1A8h
Resetting default scope
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: RustClient.exe
MISALIGNED_IP:
nt!RemoveListHeadPte+55
fffff800`3365c0f9 c2a801 ret 1A8h
STACK_TEXT:
ffffc981`dbc5ad28 fffff800`33812269 : 00000000`0000007f 00000000`00000008 ffffc981`dbc5ae70 00000000`10000000 : nt!KeBugCheckEx
ffffc981`dbc5ad30 fffff800`3380c74e : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
ffffc981`dbc5ae70 fffff800`3365c0f9 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDoubleFaultAbort+0x2ce
00000000`10000000 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!RemoveListHeadPte+0x55
SYMBOL_NAME: nt!KiDoubleFaultAbort+2ce
IMAGE_VERSION: 10.0.19041.4291
STACK_COMMAND: .cxr; .ecxr ; kb
MODULE_NAME: GenuineIntel
IMAGE_NAME: GenuineIntel.sys
FAILURE_BUCKET_ID: IP_MISALIGNED_GenuineIntel.sys
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {e930d917-b247-3f7f-23cb-88a0c9f1b274}
DRIVER_UNLOADED_WITHOUT_CANCELLING_PENDING_OPERATIONS (ce)
A driver unloaded without cancelling timers, DPCs, worker threads, etc.
The broken driver's name is displayed on the screen and saved in
KiBugCheckDriver.
Arguments:
Arg1: fffff803309f1a6c, memory referenced
Arg2: 0000000000000010, value 0 = read operation, 1 = write operation
Arg3: fffff803309f1a6c, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000000, Mm internal code.
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 2671
Key : Analysis.Elapsed.mSec
Value: 9401
Key : Analysis.IO.Other.Mb
Value: 9
Key : Analysis.IO.Read.Mb
Value: 0
Key : Analysis.IO.Write.Mb
Value: 11
Key : Analysis.Init.CPU.mSec
Value: 577
Key : Analysis.Init.Elapsed.mSec
Value: 48226
Key : Analysis.Memory.CommitPeak.Mb
Value: 83
Key : Bugcheck.Code.LegacyAPI
Value: 0xce
Key : Bugcheck.Code.TargetModel
Value: 0xce
Key : Failure.Bucket
Value: 0xCE_EasyAntiChea!unknown_function
Key : Failure.Hash
Value: {7ef9ddcc-afc0-3e06-b418-78b47b58c1e5}
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Version
Value: 10.0.19041.1
BUGCHECK_CODE: ce
BUGCHECK_P1: fffff803309f1a6c
BUGCHECK_P2: 10
BUGCHECK_P3: fffff803309f1a6c
BUGCHECK_P4: 0
FILE_IN_CAB: 041424-6812-01.dmp
WRITE_ADDRESS: fffff8005ccfb390: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
unable to get nt!MmSpecialPagesInUse
fffff803309f1a6c
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: CalculatorApp.exe
TRAP_FRAME: ffff810008bdf4a0 -- (.trap 0xffff810008bdf4a0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffff8005c20c99f rbx=0000000000000000 rcx=fffff8032f975be1
rdx=fffff8032f9756f0 rsi=0000000000000000 rdi=0000000000000000
rip=fffff803309f1a6c rsp=ffff810008bdf638 rbp=ffff810008bdf6a0
r8=0000000000000003 r9=0000000000000003 r10=fffff7efc0001158
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na po nc
<Unloaded_EasyAntiChea>+0x1201a6c:
fffff803`309f1a6c ?? ???
Resetting default scope
IP_MODULE_UNLOADED:
EasyAntiChea+1201a6c
fffff803`309f1a6c ?? ???
STACK_TEXT:
ffff8100`08bdf1f8 fffff800`5c43938b : 00000000`00000050 fffff803`309f1a6c 00000000`00000010 ffff8100`08bdf4a0 : nt!KeBugCheckEx
ffff8100`08bdf200 fffff800`5c21c2a0 : 00000000`00000000 00000000`00000010 ffff8100`08bdf520 00000000`00000000 : nt!MiSystemFault+0x1de2db
ffff8100`08bdf300 fffff800`5c40db29 : 00000000`00000000 00000000`00000000 ffff8100`08bdf4a0 00000000`00000000 : nt!MmAccessFault+0x400
ffff8100`08bdf4a0 fffff803`309f1a6c : ffff8100`08bdf700 0a000010`21385121 7fffffff`ffffffff 00000000`00000005 : nt!KiPageFault+0x369
ffff8100`08bdf638 ffff8100`08bdf700 : 0a000010`21385121 7fffffff`ffffffff 00000000`00000005 fffff800`5c52036e : <Unloaded_EasyAntiChea>+0x1201a6c
ffff8100`08bdf640 0a000010`21385121 : 7fffffff`ffffffff 00000000`00000005 fffff800`5c52036e ffffd70c`00000003 : 0xffff8100`08bdf700
ffff8100`08bdf648 7fffffff`ffffffff : 00000000`00000005 fffff800`5c52036e ffffd70c`00000003 ffff8100`08bdf6f9 : 0x0a000010`21385121
ffff8100`08bdf650 00000000`00000005 : fffff800`5c52036e ffffd70c`00000003 ffff8100`08bdf6f9 00000000`00000009 : 0x7fffffff`ffffffff
ffff8100`08bdf658 fffff800`5c52036e : ffffd70c`00000003 ffff8100`08bdf6f9 00000000`00000009 fffff800`5c20c99f : 0x5
ffff8100`08bdf660 00000000`00000003 : 00000000`00000000 00000000`0eac417c ffff8100`08bdf9a0 00000000`00090157 : nt!KiConvertDynamicHeteroPolicy+0x1e
ffff8100`08bdf690 00000000`00000000 : 00000000`0eac417c ffff8100`08bdf9a0 00000000`00090157 00000000`00000000 : 0x3
SYMBOL_NAME: EasyAntiChea+1201a6c
MODULE_NAME: EasyAntiChea
IMAGE_NAME: EasyAntiChea
STACK_COMMAND: .cxr; .ecxr ; kb
BUCKET_ID_FUNC_OFFSET: 1201a6c
FAILURE_BUCKET_ID: 0xCE_EasyAntiChea!unknown_function
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {7ef9ddcc-afc0-3e06-b418-78b47b58c1e5}
Followup: MachineOwner
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the BugCheck
Arg2: fffff80183e1ae18, Address of the instruction which caused the BugCheck
Arg3: ffffec8e08016910, Address of the context record for the exception that caused the BugCheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 2233
Key : Analysis.Elapsed.mSec
Value: 5346
Key : Analysis.IO.Other.Mb
Value: 20
Key : Analysis.IO.Read.Mb
Value: 0
Key : Analysis.IO.Write.Mb
Value: 25
Key : Analysis.Init.CPU.mSec
Value: 1031
Key : Analysis.Init.Elapsed.mSec
Value: 59959
Key : Analysis.Memory.CommitPeak.Mb
Value: 92
Key : Bugcheck.Code.LegacyAPI
Value: 0x3b
Key : Bugcheck.Code.TargetModel
Value: 0x3b
Key : Failure.Bucket
Value: AV_win32kbase!toupper
Key : Failure.Hash
Value: {125ff3a9-2925-1f5e-344d-aa284eafd1c4}
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Version
Value: 10.0.19041.1
BUGCHECK_CODE: 3b
BUGCHECK_P1: c0000005
BUGCHECK_P2: fffff80183e1ae18
BUGCHECK_P3: ffffec8e08016910
BUGCHECK_P4: 0
FILE_IN_CAB: 041424-10718-01.dmp
CONTEXT: ffffec8e08016910 -- (.cxr 0xffffec8e08016910)
rax=ffffd48e24702000 rbx=0000000000000000 rcx=0000000000000000
rdx=000000c68c986000 rsi=0000000000000000 rdi=ffffab2c0074a400
rip=fffff80183e1ae18 rsp=ffffec8e08017310 rbp=ffffec8e08017410
r8=ffffec8e08017438 r9=000000000000004f r10=0000000000000002
r11=0000000000000001 r12=0000000000000000 r13=ffffab2c007859f0
r14=ffffab2c007c4240 r15=0000000000000000
iopl=0 nv up ei ng nz na pe nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050282
nt!RtlAnsiCharToUnicodeChar+0x28:
fffff801`83e1ae18 488b3e mov rdi,qword ptr [rsi] ds:002b:00000000`00000000=????????????????
Resetting default scope
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: NVDisp
STACK_TEXT:
ffffec8e`08017310 fffff801`83e1a8f2 : 00000000`00000020 ffffec8e`08017438 00000000`00000000 ffffab2c`007c4240 : nt!RtlAnsiCharToUnicodeChar+0x28
ffffec8e`08017380 ffffab5d`392c8f55 : 00000000`00000020 ffffec8e`08017410 00000000`00000000 ffffab2c`0074a400 : nt!RtlUpcaseUnicodeToMultiByteN+0x72
ffffec8e`080173d0 ffffab5d`392916cc : 00000000`0000006c 00000000`0000004f ffffec8e`0801006f ffffab2c`00000000 : win32kbase!toupper+0x21
ffffec8e`08017420 ffffab5d`392730af : 00000000`0020001e 00000000`00000000 00000000`000c000a ffffab5d`39406230 : win32kbase!DrvGetRegistryHandleFromDeviceMap+0x244
ffffec8e`080176b0 ffffab5d`39271a74 : 00000000`00000000 00000000`00000000 ffffab2c`0074a400 ffffab2c`00785680 : win32kbase!DrvGetPruneFlag+0x5f
ffffec8e`08017750 ffffab5d`39271776 : ffffd48e`14097040 00000000`00000000 00000000`00000000 ffffd48e`09e87088 : win32kbase!DrvEnumDisplayDevices+0x284
ffffec8e`08017940 ffffab5d`39a5e616 : 00000000`00000020 fffff801`a031270b ffffd48e`14097040 00000251`e4b61520 : win32kbase!NtUserEnumDisplayDevices+0x86
ffffec8e`08017a00 fffff801`83c119c5 : ffffd48e`14097040 ffffd48e`14097040 00000000`00000000 00000000`00000000 : win32k!NtUserEnumDisplayDevices+0x16
ffffec8e`08017a40 00007ffc`a73c2d84 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
000000c6`8defa268 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffc`a73c2d84
SYMBOL_NAME: win32kbase!toupper+21
MODULE_NAME: win32kbase
IMAGE_NAME: win32kbase.sys
IMAGE_VERSION: 10.0.19041.4291
STACK_COMMAND: .cxr 0xffffec8e08016910 ; kb
BUCKET_ID_FUNC_OFFSET: 21
FAILURE_BUCKET_ID: AV_win32kbase!toupper
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {125ff3a9-2925-1f5e-344d-aa284eafd1c4}
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the BugCheck
Arg2: fffff80560b94cf4, Address of the instruction which caused the BugCheck
Arg3: ffffc9800ec9a920, Address of the context record for the exception that caused the BugCheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 2280
Key : Analysis.Elapsed.mSec
Value: 16811
Key : Analysis.IO.Other.Mb
Value: 17
Key : Analysis.IO.Read.Mb
Value: 0
Key : Analysis.IO.Write.Mb
Value: 19
Key : Analysis.Init.CPU.mSec
Value: 890
Key : Analysis.Init.Elapsed.mSec
Value: 45999
Key : Analysis.Memory.CommitPeak.Mb
Value: 82
Key : Bugcheck.Code.LegacyAPI
Value: 0x3b
Key : Bugcheck.Code.TargetModel
Value: 0x3b
Key : Failure.Bucket
Value: IP_MISALIGNED_vgk.sys
Key : Failure.Hash
Value: {c38582a8-fb68-6d00-6996-ec0ba0c44355}
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Version
Value: 10.0.19041.1
BUGCHECK_CODE: 3b
BUGCHECK_P1: c0000005
BUGCHECK_P2: fffff80560b94cf4
BUGCHECK_P3: ffffc9800ec9a920
BUGCHECK_P4: 0
FILE_IN_CAB: 041424-6062-01.dmp
CONTEXT: ffffc9800ec9a920 -- (.cxr 0xffffc9800ec9a920)
rax=0000000000000000 rbx=ffffb88daea19080 rcx=ffffb88daea19080
rdx=0000000000000000 rsi=ffffeb0fabbe01a8 rdi=0000000000000000
rip=fffff80560b94cf4 rsp=ffffeb0fabbdfff0 rbp=ffffeb0fabbe0089
r8=0000000000000001 r9=fffff809e28c2ced r10=fffff80560b40c78
r11=fffff80560ac0000 r12=0000000000000001 r13=ffffb88daea19080
r14=0000000000000008 r15=fffff80560ac0000
iopl=0 nv up di ng nz na pe nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050082
vgk+0xd4cf4:
fffff805`60b94cf4 c00f85 ror byte ptr [rdi],85h ds:002b:00000000`00000000=??
Resetting default scope
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: svchost.exe
MISALIGNED_IP:
vgk+d4cf4
fffff805`60b94cf4 c00f85 ror byte ptr [rdi],85h
STACK_TEXT:
ffffeb0f`abbdfff0 ffffb88d`aea19080 : fffff805`4295e730 00000000`00000000 00000000`00000000 ffffeb0f`abbe01a8 : vgk+0xd4cf4
ffffeb0f`abbdfff8 fffff805`4295e72f : 00000000`00000000 00000000`00000000 ffffeb0f`abbe01a8 fffff805`60b95d26 : 0xffffb88d`aea19080
ffffeb0f`abbe0000 00000000`00000000 : 00000000`00000000 ffffeb0f`abbe01a8 fffff805`60b95d26 00001000`a6e30000 : nt!KeSetDisableQuantumProcess+0xdb
SYMBOL_NAME: vgk+d4cf4
STACK_COMMAND: .cxr 0xffffc9800ec9a920 ; kb
MODULE_NAME: hardware
IMAGE_NAME: hardware
FAILURE_BUCKET_ID: IP_MISALIGNED_vgk.sys
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {c38582a8-fb68-6d00-6996-ec0ba0c44355}
Followup: MachineOwner
---------
PnpActivityId : {00000000-0000-0000-0000-000000000000}
PnpActivityTime : 133575795290365112
PnpEventInformation: 5
PnpEventInProgress : 0
PnpProblemCode : 43
PnpVetoType : 0
DeviceId : USB\VID_8087&PID_0038\5&cc3f949&0&14
VetoString :