SYSTEM_THREAD_EXCEPTION_NOT_HANDLED (7e)
This is a very common BugCheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff807bdf0660c, The address that the exception occurred at
Arg3: ffff948a80de28f8, Exception Record Address
Arg4: ffff948a80de2130, Context Record Address
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for xvdd.sys
KEY_VALUES_STRING: 1
Key : AV.Dereference
Value: NullPtr
Key : AV.Fault
Value: Unknown
Key : Analysis.CPU.mSec
Value: 1249
Key : Analysis.Elapsed.mSec
Value: 14436
Key : Analysis.IO.Other.Mb
Value: 1
Key : Analysis.IO.Read.Mb
Value: 0
Key : Analysis.IO.Write.Mb
Value: 11
Key : Analysis.Init.CPU.mSec
Value: 280
Key : Analysis.Init.Elapsed.mSec
Value: 1689
Key : Analysis.Memory.CommitPeak.Mb
Value: 91
Key : Bugcheck.Code.LegacyAPI
Value: 0x1000007e
Key : Bugcheck.Code.TargetModel
Value: 0x1000007e
Key : Failure.Bucket
Value: AV_xvdd!unknown_function
Key : Failure.Hash
Value: {d4f0644e-8138-0a75-0ccb-35df5ac13ead}
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Version
Value: 10.0.19041.1
BUGCHECK_CODE: 7e
BUGCHECK_P1: ffffffffc0000005
BUGCHECK_P2: fffff807bdf0660c
BUGCHECK_P3: ffff948a80de28f8
BUGCHECK_P4: ffff948a80de2130
FILE_IN_CAB: 073024-13250-01 (2).dmp
EXCEPTION_RECORD: ffff948a80de28f8 -- (.exr 0xffff948a80de28f8)
ExceptionAddress: fffff807bdf0660c (xvdd+0x000000000006660c)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: ffffffffffffffff
Parameter[1]: 0000000000000000
Attempt to unknown address 0000000000000000
CONTEXT: ffff948a80de2130 -- (.cxr 0xffff948a80de2130)
rax=0000000000000081 rbx=ffff9f099427f2b0 rcx=ffff9f099427f2b0
rdx=0000000000000000 rsi=ffff9f0992220000 rdi=00000000000aa000
rip=fffff807bdf0660c rsp=ffff948a80de2b38 rbp=ffffe301f947f000
r8=0000000000000071 r9=0000000000000000 r10=0000000000000001
r11=ffffd2fd18400000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000002
iopl=0 nv up ei ng nz na pe nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050282
xvdd+0x6660c:
fffff807`bdf0660c 48895c2408 mov qword ptr [rsp+8],rbx ss:0018:ffff948a`80de2b40=fffff807bdf7ceb0
Resetting default scope
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXWINLOGON: 1
PROCESS_NAME: System
ERROR_CODE: (NTSTATUS) 0xc0000005 - 0x%p adresindeki y nerge 0x%p adresindeki belle e ba vurdu. Bellek u olamaz %s.
EXCEPTION_CODE_STR: c0000005
EXCEPTION_PARAMETER1: ffffffffffffffff
EXCEPTION_PARAMETER2: 0000000000000000
EXCEPTION_STR: 0xc0000005
STACK_TEXT:
ffff948a`80de2b38 fffff807`bdf0975f : fffff807`bdf7ceb0 ffff9f09`91616c00 00000000`00000000 00000000`00000000 : xvdd+0x6660c
ffff948a`80de2b40 fffff807`bdf7ceb0 : ffff9f09`91616c00 00000000`00000000 00000000`00000000 00000005`3145d563 : xvdd+0x6975f
ffff948a`80de2b48 ffff9f09`91616c00 : 00000000`00000000 00000000`00000000 00000005`3145d563 fffff807`bdf7ce40 : xvdd+0xdceb0
ffff948a`80de2b50 00000000`00000000 : 00000000`00000000 00000005`3145d563 fffff807`bdf7ce40 fffff807`bdf7ceb0 : 0xffff9f09`91616c00
SYMBOL_NAME: xvdd+6660c
MODULE_NAME: xvdd
IMAGE_NAME: xvdd.sys
STACK_COMMAND: .cxr 0xffff948a80de2130 ; kb
BUCKET_ID_FUNC_OFFSET: 6660c
FAILURE_BUCKET_ID: AV_xvdd!unknown_function
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {d4f0644e-8138-0a75-0ccb-35df5ac13ead}
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 0000000000000010, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff8041a79c223, address which referenced memory
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 1280
Key : Analysis.Elapsed.mSec
Value: 3201
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 0
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 343
Key : Analysis.Init.Elapsed.mSec
Value: 754
Key : Analysis.Memory.CommitPeak.Mb
Value: 81
Key : Bugcheck.Code.LegacyAPI
Value: 0xa
Key : Bugcheck.Code.TargetModel
Value: 0xa
Key : Failure.Bucket
Value: AV_nt!MiUnlinkNumaStandbyPage
Key : Failure.Hash
Value: {eda81f1f-73f6-2968-25f9-b9d26d43eeb5}
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Version
Value: 10.0.19041.1
BUGCHECK_CODE: a
BUGCHECK_P1: 10
BUGCHECK_P2: 2
BUGCHECK_P3: 0
BUGCHECK_P4: fffff8041a79c223
FILE_IN_CAB: 073124-13468-01.dmp
READ_ADDRESS: fffff8041b0fb390: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
unable to get nt!MmSpecialPagesInUse
0000000000000010
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System
TRAP_FRAME: ffff9b899cf25820 -- (.trap 0xffff9b899cf25820)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=ffff940003f4c650
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8041a79c223 rsp=ffff9b899cf259b0 rbp=0000000000000000
r8=0000000000000000 r9=0000000fffffffff r10=ffff94000b8d5680
r11=fffffff000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe nc
nt!MiUnlinkNumaStandbyPage+0xaf:
fffff804`1a79c223 48036a10 add rbp,qword ptr [rdx+10h] ds:00000000`00000010=????????????????
Resetting default scope
STACK_TEXT:
ffff9b89`9cf256d8 fffff804`1a80fd29 : 00000000`0000000a 00000000`00000010 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
ffff9b89`9cf256e0 fffff804`1a80b8e3 : 000f8067`b4bbbdff fffff804`1a6f5f00 ffffb280`00000000 00000000`00000001 : nt!KiBugCheckDispatch+0x69
ffff9b89`9cf25820 fffff804`1a79c223 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000076 : nt!KiPageFault+0x463
ffff9b89`9cf259b0 fffff804`1a784936 : ffff9400`03f4c650 00000000`00000000 00000000`00000000 00000000`000001f7 : nt!MiUnlinkNumaStandbyPage+0xaf
ffff9b89`9cf259f0 fffff804`1a94f569 : fffff804`1b050c00 00000000`00000000 00000000`00000000 fffff804`1b0516c0 : nt!MiRemoveLowestPriorityStandbyPage+0x5f6
ffff9b89`9cf25a90 fffff804`1a94f7c3 : fffff804`1b050c00 00000000`00000000 fffff804`00000000 00000000`00000207 : nt!MiPruneStandbyPages+0x265
ffff9b89`9cf25b20 fffff804`1a68e5c5 : ffff9d0f`7766f040 fffff804`1a94f730 ffff9d0f`6b476a20 fffff804`1b0524a0 : nt!MiRebalanceZeroFreeLists+0x93
ffff9b89`9cf25b70 fffff804`1a7265f5 : ffff9d0f`7766f040 00000000`00000080 ffff9d0f`6b4d8200 5a518c4f`57a59400 : nt!ExpWorkerThread+0x105
ffff9b89`9cf25c10 fffff804`1a8048d8 : ffff8381`29292180 ffff9d0f`7766f040 fffff804`1a7265a0 e8a46472`af4c0378 : nt!PspSystemThreadStartup+0x55
ffff9b89`9cf25c60 00000000`00000000 : ffff9b89`9cf26000 ffff9b89`9cf20000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
SYMBOL_NAME: nt!MiUnlinkNumaStandbyPage+af
MODULE_NAME: nt
IMAGE_VERSION: 10.0.19041.2965
STACK_COMMAND: .cxr; .ecxr ; kb
IMAGE_NAME: ntkrnlmp.exe
BUCKET_ID_FUNC_OFFSET: af
FAILURE_BUCKET_ID: AV_nt!MiUnlinkNumaStandbyPage
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {eda81f1f-73f6-2968-25f9-b9d26d43eeb5}
KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure. The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 0000000000000004, The thread's stack pointer was outside the legal stack
extents for the thread.
Arg2: fffff80444eac010, Address of the trap frame for the exception that caused the BugCheck
Arg3: fffff80444eabf68, Address of the exception record for the exception that caused the BugCheck
Arg4: 0000000000000000, Reserved
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 1280
Key : Analysis.Elapsed.mSec
Value: 2888
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 0
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 280
Key : Analysis.Init.Elapsed.mSec
Value: 770
Key : Analysis.Memory.CommitPeak.Mb
Value: 81
Key : Bugcheck.Code.LegacyAPI
Value: 0x139
Key : Bugcheck.Code.TargetModel
Value: 0x139
Key : FailFast.Name
Value: INCORRECT_STACK
Key : FailFast.Type
Value: 4
Key : Failure.Bucket
Value: 0x139_MISSING_GSFRAME_nt!KiFastFailDispatch
Key : Failure.Hash
Value: {1971a9b0-b7ec-89bf-0a51-10ac52818da5}
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Version
Value: 10.0.19041.1
BUGCHECK_CODE: 139
BUGCHECK_P1: 4
BUGCHECK_P2: fffff80444eac010
BUGCHECK_P3: fffff80444eabf68
BUGCHECK_P4: 0
FILE_IN_CAB: 073024-12156-01 (3).dmp
TRAP_FRAME: fffff80444eac010 -- (.trap 0xfffff80444eac010)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffffac0ac5040000 rbx=0000000000000000 rcx=0000000000000004
rdx=ffffac0ac5046000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80441a6097d rsp=fffff80444eac1a0 rbp=fffff80444eac710
r8=ffffac0ac5046000 r9=fffff80444eac728 r10=ffffac0ac5045b00
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
nt!RtlpGetStackLimitsEx+0x17963d:
fffff804`41a6097d cd29 int 29h
Resetting default scope
EXCEPTION_RECORD: fffff80444eabf68 -- (.exr 0xfffff80444eabf68)
ExceptionAddress: fffff80441a6097d (nt!RtlpGetStackLimitsEx+0x000000000017963d)
ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
ExceptionFlags: 00000001
NumberParameters: 1
Parameter[0]: 0000000000000004
Subcode: 0x4 FAST_FAIL_INCORRECT_STACK
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
PROCESS_NAME: amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.4707_none_7de912607ca9
ERROR_CODE: (NTSTATUS) 0xc0000409 - Sistem, bu uygulamada y n tabanl bir arabelle in ta t n alg lad . Bu ta ma, k t niyetli bir kullan c n n bu uygulaman n denetimini ele ge irmesine olanak verebilir.
EXCEPTION_CODE_STR: c0000409
EXCEPTION_PARAMETER1: 0000000000000004
EXCEPTION_STR: 0xc0000409
STACK_TEXT:
fffff804`44eabce8 fffff804`41a0fd29 : 00000000`00000139 00000000`00000004 fffff804`44eac010 fffff804`44eabf68 : nt!KeBugCheckEx
fffff804`44eabcf0 fffff804`41a10290 : 00000000`00000000 00000000`00000003 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
fffff804`44eabe30 fffff804`41a0e25d : fffff804`44eac7c0 00000000`00000000 fffff804`44eaba60 00000000`00000000 : nt!KiFastFailDispatch+0xd0
fffff804`44eac010 fffff804`41a6097d : 000000a0`cbf77f48 00007ffa`474b8e39 fffff804`44eac710 00000000`00000000 : nt!KiRaiseSecurityCheckFailure+0x31d
fffff804`44eac1a0 fffff804`41a602e5 : fffff804`44eac710 00000000`00000000 ffffac0a`c5045b00 fffff804`00000003 : nt!RtlpGetStackLimitsEx+0x17963d
fffff804`44eac1d0 fffff804`418e7896 : ffffac0a`c5045058 fffff804`44eace20 ffffac0a`c5045058 00000000`00000001 : nt!RtlDispatchException+0x17acb5
fffff804`44eac8f0 fffff804`419fcdb2 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDispatchException+0x186
fffff804`44eacfb0 fffff804`419fcd80 : fffff804`41a0fe65 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KxExceptionDispatchOnExceptionStack+0x12
ffffac0a`c5044f18 fffff804`41a0fe65 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiExceptionDispatchOnExceptionStackContinue
ffffac0a`c5044f20 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiExceptionDispatch+0x125
SYMBOL_NAME: nt!KiFastFailDispatch+d0
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
IMAGE_VERSION: 10.0.19041.2965
STACK_COMMAND: .cxr; .ecxr ; kb
BUCKET_ID_FUNC_OFFSET: d0
FAILURE_BUCKET_ID: 0x139_MISSING_GSFRAME_nt!KiFastFailDispatch
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {1971a9b0-b7ec-89bf-0a51-10ac52818da5}
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: fffff01048c61400, memory referenced
Arg2: 00000000000000ff, IRQL
Arg3: 0000000000000080, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff8057fc0b403, address which referenced memory
Debugging Details:
------------------
*** WARNING: Check Image - Checksum mismatch - Dump: 0x3aff59, File: 0x3ab4c9 - C:\ProgramData\Dbg\sym\dxgkrnl.sys\0F2DDF593aa000\dxgkrnl.sys
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 1327
Key : Analysis.Elapsed.mSec
Value: 5405
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 0
Key : Analysis.IO.Write.Mb
Value: 3
Key : Analysis.Init.CPU.mSec
Value: 327
Key : Analysis.Init.Elapsed.mSec
Value: 654
Key : Analysis.Memory.CommitPeak.Mb
Value: 81
Key : Bugcheck.Code.LegacyAPI
Value: 0xa
Key : Bugcheck.Code.TargetModel
Value: 0xa
Key : Failure.Bucket
Value: AV_nt!KiGeneralProtectionFault
Key : Failure.Hash
Value: {dd04af12-f86f-9688-c9a3-e403f84a6db3}
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Version
Value: 10.0.19041.1
BUGCHECK_CODE: a
BUGCHECK_P1: fffff01048c61400
BUGCHECK_P2: ff
BUGCHECK_P3: 80
BUGCHECK_P4: fffff8057fc0b403
FILE_IN_CAB: 073024-13234-01 (2).dmp
READ_ADDRESS: fffff805804fb390: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
unable to get nt!MmSpecialPagesInUse
fffff01048c61400
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXWINLOGON: 1
PROCESS_NAME: svchost.exe
TRAP_FRAME: fffff00fdb9cd2c0 -- (.trap 0xfffff00fdb9cd2c0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=0000000000000011
rdx=ffffd60177bf8bc8 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8057fc0b403 rsp=fffff00fdb9cd450 rbp=fffff00fdb9cd4d0
r8=fffff00fdb9cd5f0 r9=fffff00fdb9cd640 r10=7ffffffffffffffc
r11=fffff00fdb9cd6f8 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up di pl zr na po nc
nt!KiGeneralProtectionFault+0x2c3:
fffff805`7fc0b403 0f296530 movaps xmmword ptr [rbp+30h],xmm4 ss:0018:fffff00f`db9cd500=fffff80500000000c00000015cee9867
Resetting default scope
STACK_TEXT:
fffff00f`db9cd178 fffff805`7fc0fd29 : 00000000`0000000a fffff010`48c61400 00000000`000000ff 00000000`00000080 : nt!KeBugCheckEx
fffff00f`db9cd180 fffff805`7fc0b8e3 : 0007a7c4`ffffffff 00000000`00000000 00000000`00000001 ffffb38c`00000002 : nt!KiBugCheckDispatch+0x69
fffff00f`db9cd2c0 fffff805`7fc0b403 : 00000001`00000000 00000246`ddfe9000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x463
fffff00f`db9cd450 fffff805`7fe4ac26 : ffffd601`74abe730 fffff805`00000002 ffffd601`00000000 ffffb38c`85b4c950 : nt!KiGeneralProtectionFault+0x2c3
fffff00f`db9cd5e0 fffff805`7fe4ab79 : ffffd601`77bf8be0 ffffd601`77bf8a80 ffffb38c`00000000 ffffb38c`89b37a50 : nt!AlpcpEnumerateResourcesPort+0x3e
fffff00f`db9cd620 fffff805`7fe4a9dc : ffffb38c`89b37a50 fffff00f`db9cd6d0 ffffd601`77bf8a80 00000246`ddf40000 : nt!AlpcpLocateSectionView+0x4d
fffff00f`db9cd670 fffff805`7fe4a8fe : 00000246`de91aaa8 00000000`00000000 00000246`dd27b160 00000000`00000019 : nt!AlpcpCaptureViewAttributeInternal+0xd0
fffff00f`db9cd6b0 fffff805`7fdedca2 : 00000000`00000020 fffff00f`db9cdb00 fffff00f`db9cd920 fffff805`00000000 : nt!AlpcpCaptureViewAttribute+0x42
fffff00f`db9cd700 fffff805`7fdec514 : ffffd601`77bf8a80 00000000`00000000 ffff9a00`00000000 00000000`00000000 : nt!AlpcpCaptureAttributes+0x472
fffff00f`db9cd770 fffff805`7fdee7fc : fffff00f`db9cd930 00000246`dd27b160 00000246`de91aaa8 fffff279`0091b701 : nt!AlpcpSendMessage+0x774
fffff00f`db9cd8b0 fffff805`7fdef206 : ffffd601`77bf8a80 ffffd601`00020000 00000246`dd27b160 00000246`de91aaa8 : nt!AlpcpProcessSynchronousRequest+0x31c
fffff00f`db9cd9d0 fffff805`7fc0f4f8 : ffffd601`74abe080 fffff00f`db9cdb80 0000007a`7d0fe0a8 fffff00f`db9cdaa8 : nt!NtAlpcSendWaitReceivePort+0x1d6
fffff00f`db9cda90 00007ff8`d3a8e1d4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
0000007a`7d0fe088 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff8`d3a8e1d4
SYMBOL_NAME: nt!KiGeneralProtectionFault+2c3
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
IMAGE_VERSION: 10.0.19041.2965
STACK_COMMAND: .cxr; .ecxr ; kb
BUCKET_ID_FUNC_OFFSET: 2c3
FAILURE_BUCKET_ID: AV_nt!KiGeneralProtectionFault
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {dd04af12-f86f-9688-c9a3-e403f84a6db3}
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the BugCheck
Arg2: fffff8006144ac26, Address of the instruction which caused the BugCheck
Arg3: ffffea0220786be0, Address of the context record for the exception that caused the BugCheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 1390
Key : Analysis.Elapsed.mSec
Value: 2662
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 0
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 327
Key : Analysis.Init.Elapsed.mSec
Value: 630
Key : Analysis.Memory.CommitPeak.Mb
Value: 81
Key : Bugcheck.Code.LegacyAPI
Value: 0x3b
Key : Bugcheck.Code.TargetModel
Value: 0x3b
Key : Failure.Bucket
Value: AV_nt!AlpcpEnumerateResourcesPort
Key : Failure.Hash
Value: {609bccdb-8db0-06b6-4108-1b19e87eb22b}
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Version
Value: 10.0.19041.1
BUGCHECK_CODE: 3b
BUGCHECK_P1: c0000005
BUGCHECK_P2: fffff8006144ac26
BUGCHECK_P3: ffffea0220786be0
BUGCHECK_P4: 0
FILE_IN_CAB: 073024-15781-01 (2).dmp
CONTEXT: ffffea0220786be0 -- (.cxr 0xffffea0220786be0)
rax=0000000000000000 rbx=ffff2608830792e0 rcx=0000000000000011
rdx=ffff9a87737acbc8 rsi=0000000000000000 rdi=ffff9a87737acbc8
rip=fffff8006144ac26 rsp=ffffea02207875e0 rbp=ffffea0220787640
r8=ffffea02207875f0 r9=ffffea0220787640 r10=7ffffffffffffffc
r11=ffffea02207876f8 r12=0000000000020000 r13=ffff8608a0025c10
r14=ffff9a87737acbd0 r15=0000000000000000
iopl=0 nv up ei ng nz na pe cy
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050283
nt!AlpcpEnumerateResourcesPort+0x3e:
fffff800`6144ac26 807b1106 cmp byte ptr [rbx+11h],6 ds:002b:ffff2608`830792f1=??
Resetting default scope
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
PROCESS_NAME: svchost.exe
STACK_TEXT:
ffffea02`207875e0 fffff800`6144ab79 : ffff9a87`737acbe0 ffff9a87`737aca80 ffff8608`00000000 ffff8608`8d94d580 : nt!AlpcpEnumerateResourcesPort+0x3e
ffffea02`20787620 fffff800`6144a9dc : ffff8608`8d94d580 ffffea02`207876d0 ffff9a87`737aca80 00000180`04110000 : nt!AlpcpLocateSectionView+0x4d
ffffea02`20787670 fffff800`6144a8fe : 00000180`04e1ebb8 00000000`00000000 00000180`0572fc70 00000000`0000002e : nt!AlpcpCaptureViewAttributeInternal+0xd0
ffffea02`207876b0 fffff800`613edca2 : 00000000`00000020 ffffea02`20787b00 ffffea02`20787920 fffff800`00000000 : nt!AlpcpCaptureViewAttribute+0x42
ffffea02`20787700 fffff800`613ec514 : ffff9a87`737aca80 00000000`00000000 ffffe600`00000000 00000000`00000000 : nt!AlpcpCaptureAttributes+0x472
ffffea02`20787770 fffff800`613ee7fc : ffffea02`20787930 00000180`0572fc70 00000180`04e1ebb8 fffff57a`80600101 : nt!AlpcpSendMessage+0x774
ffffea02`207878b0 fffff800`613ef206 : ffff9a87`737aca80 ffff9a87`00020000 00000180`0572fc70 00000180`04e1ebb8 : nt!AlpcpProcessSynchronousRequest+0x31c
ffffea02`207879d0 fffff800`6120f4f8 : ffff9a87`780f2080 ffffea02`20787b80 0000004c`ec57e618 ffffea02`20787aa8 : nt!NtAlpcSendWaitReceivePort+0x1d6
ffffea02`20787a90 00007ffc`c5eae1d4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
0000004c`ec57e5f8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffc`c5eae1d4
SYMBOL_NAME: nt!AlpcpEnumerateResourcesPort+3e
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
IMAGE_VERSION: 10.0.19041.2965
STACK_COMMAND: .cxr 0xffffea0220786be0 ; kb
BUCKET_ID_FUNC_OFFSET: 3e
FAILURE_BUCKET_ID: AV_nt!AlpcpEnumerateResourcesPort
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {609bccdb-8db0-06b6-4108-1b19e87eb22b}
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the BugCheck
Arg2: fffff8014264ac26, Address of the instruction which caused the BugCheck
Arg3: ffff85855e883be0, Address of the context record for the exception that caused the BugCheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
*** WARNING: Check Image - Checksum mismatch - Dump: 0x1fc84, File: 0x24657 - C:\ProgramData\Dbg\sym\crashdmp.sys\985DE65D1e000\crashdmp.sys
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 1218
Key : Analysis.Elapsed.mSec
Value: 3733
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 0
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 280
Key : Analysis.Init.Elapsed.mSec
Value: 755
Key : Analysis.Memory.CommitPeak.Mb
Value: 81
Key : Bugcheck.Code.LegacyAPI
Value: 0x3b
Key : Bugcheck.Code.TargetModel
Value: 0x3b
Key : Failure.Bucket
Value: AV_nt!AlpcpEnumerateResourcesPort
Key : Failure.Hash
Value: {609bccdb-8db0-06b6-4108-1b19e87eb22b}
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Version
Value: 10.0.19041.1
BUGCHECK_CODE: 3b
BUGCHECK_P1: c0000005
BUGCHECK_P2: fffff8014264ac26
BUGCHECK_P3: ffff85855e883be0
BUGCHECK_P4: 0
FILE_IN_CAB: 073024-15812-01 (2).dmp
CONTEXT: ffff85855e883be0 -- (.cxr 0xffff85855e883be0)
rax=0000000000000000 rbx=f4ffdf001fc9c310 rcx=0000000000000011
rdx=ffff8c063c97ea88 rsi=0000000000000000 rdi=ffff8c063c97ea88
rip=fffff8014264ac26 rsp=ffff85855e8845e0 rbp=ffff85855e884640
r8=ffff85855e8845f0 r9=ffff85855e884640 r10=7ffffffffffffffc
r11=ffff85855e8846f8 r12=0000000000020000 r13=ffffdf003145b880
r14=ffff8c063c97ea90 r15=0000000000000000
iopl=0 nv up ei ng nz na pe cy
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050283
nt!AlpcpEnumerateResourcesPort+0x3e:
fffff801`4264ac26 807b1106 cmp byte ptr [rbx+11h],6 ds:002b:f4ffdf00`1fc9c321=??
Resetting default scope
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXWINLOGON: 1
PROCESS_NAME: svchost.exe
STACK_TEXT:
ffff8585`5e8845e0 fffff801`4264ab79 : ffff8c06`3c97eaa0 ffff8c06`3c97e940 ffffdf00`00000000 ffffdf00`12b6a0f0 : nt!AlpcpEnumerateResourcesPort+0x3e
ffff8585`5e884620 fffff801`4264a9dc : ffffdf00`12b6a0f0 ffff8585`5e8846d0 ffff8c06`3c97e940 000001f5`8d400000 : nt!AlpcpLocateSectionView+0x4d
ffff8585`5e884670 fffff801`4264a8fe : 000001f5`8d0fd298 00000000`00000000 000001f5`8a982770 00000000`0000002a : nt!AlpcpCaptureViewAttributeInternal+0xd0
ffff8585`5e8846b0 fffff801`425edca2 : 00000000`00000020 ffff8585`5e884b00 ffff8585`5e884920 fffff801`00000000 : nt!AlpcpCaptureViewAttribute+0x42
ffff8585`5e884700 fffff801`425ec514 : ffff8c06`3c97e940 00000000`00000000 fffff400`00000000 00000000`00000000 : nt!AlpcpCaptureAttributes+0x472
ffff8585`5e884770 fffff801`425ee7fc : ffff8585`5e884930 000001f5`8a982770 000001f5`8d0fd298 ffff8b45`807d6301 : nt!AlpcpSendMessage+0x774
ffff8585`5e8848b0 fffff801`425ef206 : ffff8c06`3c97e940 ffff8c06`00020000 000001f5`8a982770 000001f5`8d0fd298 : nt!AlpcpProcessSynchronousRequest+0x31c
ffff8585`5e8849d0 fffff801`4240f4f8 : ffff8c06`3ede6080 ffff8585`5e884b80 00000022`de67e3c8 ffff8585`5e884aa8 : nt!NtAlpcSendWaitReceivePort+0x1d6
ffff8585`5e884a90 00007ffc`36e2e1d4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
00000022`de67e3a8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffc`36e2e1d4
SYMBOL_NAME: nt!AlpcpEnumerateResourcesPort+3e
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
IMAGE_VERSION: 10.0.19041.2965
STACK_COMMAND: .cxr 0xffff85855e883be0 ; kb
BUCKET_ID_FUNC_OFFSET: 3e
FAILURE_BUCKET_ID: AV_nt!AlpcpEnumerateResourcesPort
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {609bccdb-8db0-06b6-4108-1b19e87eb22b}
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 0000770780a08990, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff80081c1f801, address which referenced memory
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 1405
Key : Analysis.Elapsed.mSec
Value: 2184
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 0
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 343
Key : Analysis.Init.Elapsed.mSec
Value: 642
Key : Analysis.Memory.CommitPeak.Mb
Value: 81
Key : Bugcheck.Code.LegacyAPI
Value: 0xa
Key : Bugcheck.Code.TargetModel
Value: 0xa
Key : Failure.Bucket
Value: AV_nt!MiIdentifyPfn
Key : Failure.Hash
Value: {4f0b8d4b-7219-bc8c-33a3-7bfc14bc92e1}
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Version
Value: 10.0.19041.1
BUGCHECK_CODE: a
BUGCHECK_P1: 770780a08990
BUGCHECK_P2: 2
BUGCHECK_P3: 0
BUGCHECK_P4: fffff80081c1f801
FILE_IN_CAB: 073124-15921-01 (1).dmp
READ_ADDRESS: fffff800826fb390: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
unable to get nt!MmSpecialPagesInUse
0000770780a08990
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXWINLOGON: 1
PROCESS_NAME: svchost.exe
TRAP_FRAME: ffff8b0bb8925310 -- (.trap 0xffff8b0bb8925310)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=770780a089900420 rbx=0000000000000000 rcx=0000000000000000
rdx=fffff80081a00000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80081c1f801 rsp=ffff8b0bb89254a0 rbp=ffff8b0bb8925529
r8=0000000000000000 r9=ff000000000001ff r10=0000000000000000
r11=ffff8b0bb8925480 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
nt!MiIdentifyPfn+0x501:
fffff800`81c1f801 4c8b26 mov r12,qword ptr [rsi] ds:00000000`00000000=????????????????
Resetting default scope
STACK_TEXT:
ffff8b0b`b89251c8 fffff800`81e0fd29 : 00000000`0000000a 00007707`80a08990 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
ffff8b0b`b89251d0 fffff800`81e0b8e3 : 00000000`00000000 00000000`00000000 00000000`00000000 ffffe507`77010290 : nt!KiBugCheckDispatch+0x69
ffff8b0b`b8925310 fffff800`81c1f801 : ffff8b0b`b8925b80 00000000`00000060 ffff8b0b`b8925529 ffffaa00`0b3fffd0 : nt!KiPageFault+0x463
ffff8b0b`b89254a0 fffff800`81c1f295 : 00000000`00000100 00000000`00000000 00000000`00000001 ffff8b0b`b8925688 : nt!MiIdentifyPfn+0x501
ffff8b0b`b8925590 fffff800`82013994 : 00000000`00000000 ffffe507`8238c890 ffff8b0b`b8925b80 ffffe507`8238c8c0 : nt!MiIdentifyPfnWrapper+0x55
ffff8b0b`b89255c0 fffff800`8200baec : 00000000`00000000 ffffbe8e`00000000 ffff8b0b`b89257b0 ffffe507`8238b000 : nt!PfpPfnPrioRequest+0xe4
ffff8b0b`b8925640 fffff800`82009f6b : 00000054`93ef9ff0 00000000`00000001 00000000`00000001 00000000`00000000 : nt!PfQuerySuperfetchInformation+0x2ec
ffff8b0b`b8925780 fffff800`82007f17 : fffff800`81df7d01 fffff800`81cf5f5a 00000000`00000008 00000000`00000000 : nt!ExpQuerySystemInformation+0x1f0b
ffff8b0b`b8925ac0 fffff800`81e0f4f8 : 00000000`00000000 00000000`00000000 ffff8b0b`b8925b80 00000000`00000890 : nt!NtQuerySystemInformation+0x37
ffff8b0b`b8925b00 00007ffa`892ad724 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
00000054`93ef9f08 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffa`892ad724
SYMBOL_NAME: nt!MiIdentifyPfn+501
MODULE_NAME: nt
IMAGE_VERSION: 10.0.19041.2965
STACK_COMMAND: .cxr; .ecxr ; kb
IMAGE_NAME: ntkrnlmp.exe
BUCKET_ID_FUNC_OFFSET: 501
FAILURE_BUCKET_ID: AV_nt!MiIdentifyPfn
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {4f0b8d4b-7219-bc8c-33a3-7bfc14bc92e1}
ATTEMPTED_WRITE_TO_READONLY_MEMORY (be)
An attempt was made to write to readonly memory. The guilty driver is on the
stack trace (and is typically the current instruction pointer).
When possible, the guilty driver's name (Unicode string) is printed on
the BugCheck screen and saved in KiBugCheckDriver.
Arguments:
Arg1: ffff932105ef78a4, Virtual address for the attempted write.
Arg2: 8a00000000200121, PTE contents.
Arg3: fffff08ce1453820, (reserved)
Arg4: 000000000000000a, (reserved)
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 1312
Key : Analysis.Elapsed.mSec
Value: 3774
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 0
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 311
Key : Analysis.Init.Elapsed.mSec
Value: 671
Key : Analysis.Memory.CommitPeak.Mb
Value: 81
Key : Bugcheck.Code.LegacyAPI
Value: 0xbe
Key : Bugcheck.Code.TargetModel
Value: 0xbe
Key : Failure.Bucket
Value: AV_nt!MiRaisedIrqlFault
Key : Failure.Hash
Value: {3b24175f-7f5b-9c9f-8aaf-822c248bf0f5}
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Version
Value: 10.0.19041.1
BUGCHECK_CODE: be
BUGCHECK_P1: ffff932105ef78a4
BUGCHECK_P2: 8a00000000200121
BUGCHECK_P3: fffff08ce1453820
BUGCHECK_P4: a
FILE_IN_CAB: 073124-13578-01 (1).dmp
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXWINLOGON: 1
PROCESS_NAME: System
TRAP_FRAME: fffff08ce1453820 -- (.trap 0xfffff08ce1453820)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffff930000000000 rbx=0000000000000000 rcx=ffff932105ef7880
rdx=00000000000fffff rsi=0000000000000000 rdi=0000000000000000
rip=fffff8030b79c25d rsp=fffff08ce14539b0 rbp=ffff960000007000
r8=0000000000000000 r9=0000000fffffffff r10=ffff930005ef7970
r11=fffffff000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
nt!MiUnlinkNumaStandbyPage+0xe9:
fffff803`0b79c25d 6644897124 mov word ptr [rcx+24h],r14w ds:ffff9321`05ef78a4=????
Resetting default scope
STACK_TEXT:
fffff08c`e1453628 fffff803`0b869fe4 : 00000000`000000be ffff9321`05ef78a4 8a000000`00200121 fffff08c`e1453820 : nt!KeBugCheckEx
fffff08c`e1453630 fffff803`0b66e89f : 8a000000`00200121 00000000`00000003 fffff08c`e14538a0 00000000`00000000 : nt!MiRaisedIrqlFault+0x163d6c
fffff08c`e1453680 fffff803`0b80b7d8 : 000f8067`b4bbbdff fffff803`0b7fdc00 00000000`00000000 3fffffff`00000001 : nt!MmAccessFault+0x4ef
fffff08c`e1453820 fffff803`0b79c25d : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`000000db : nt!KiPageFault+0x358
fffff08c`e14539b0 fffff803`0b784936 : ffff9300`05d6f900 00000000`00000000 00000000`00000000 00000000`00000041 : nt!MiUnlinkNumaStandbyPage+0xe9
fffff08c`e14539f0 fffff803`0b94f569 : fffff803`0c050c00 00000000`00000000 00000000`00000000 fffff803`0c0516c0 : nt!MiRemoveLowestPriorityStandbyPage+0x5f6
fffff08c`e1453a90 fffff803`0b94f7c3 : fffff803`0c050c00 00000000`00000000 fffff803`00000000 00000000`000003c1 : nt!MiPruneStandbyPages+0x265
fffff08c`e1453b20 fffff803`0b68e5c5 : ffffb301`dfbc8040 fffff803`0b94f730 ffffb301`da093cf0 fffff803`0c0524a0 : nt!MiRebalanceZeroFreeLists+0x93
fffff08c`e1453b70 fffff803`0b7265f5 : ffffb301`dfbc8040 00000000`00000080 ffffb301`da0ae200 000f8067`b4bbbdff : nt!ExpWorkerThread+0x105
fffff08c`e1453c10 fffff803`0b8048d8 : ffffde01`f355e180 ffffb301`dfbc8040 fffff803`0b7265a0 6941a469`14e9f7da : nt!PspSystemThreadStartup+0x55
fffff08c`e1453c60 00000000`00000000 : fffff08c`e1454000 fffff08c`e144e000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
SYMBOL_NAME: nt!MiRaisedIrqlFault+163d6c
MODULE_NAME: nt
IMAGE_VERSION: 10.0.19041.2965
STACK_COMMAND: .cxr; .ecxr ; kb
IMAGE_NAME: ntkrnlmp.exe
BUCKET_ID_FUNC_OFFSET: 163d6c
FAILURE_BUCKET_ID: AV_nt!MiRaisedIrqlFault
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {3b24175f-7f5b-9c9f-8aaf-822c248bf0f5}
DPC_WATCHDOG_VIOLATION (133)
The DPC watchdog detected a prolonged run time at an IRQL of DISPATCH_LEVEL
or above.
Arguments:
Arg1: 0000000000000001, The system cumulatively spent an extended period of time at
DISPATCH_LEVEL or above.
Arg2: 0000000000001e00, The watchdog period (in ticks).
Arg3: fffff80104cfb320, cast to nt!DPC_WATCHDOG_GLOBAL_TRIAGE_BLOCK, which contains
additional information regarding the cumulative timeout
Arg4: 0000000000000000
Debugging Details:
------------------
*************************************************************************
*** ***
*** ***
*** Either you specified an unqualified symbol, or your debugger ***
*** doesn't have full symbol information. Unqualified symbol ***
*** resolution is turned off by default. Please either specify a ***
*** fully qualified symbol module!symbolname, or enable resolution ***
*** of unqualified symbols by typing ".symopt- 100". Note that ***
*** enabling unqualified symbol resolution with network symbol ***
*** server shares in the symbol path may cause the debugger to ***
*** appear to hang for long periods of time when an incorrect ***
*** symbol name is typed or the network symbol server is down. ***
*** ***
*** For some commands to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: TickPeriods ***
*** ***
*************************************************************************
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 1327
Key : Analysis.Elapsed.mSec
Value: 5782
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 0
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 374
Key : Analysis.Init.Elapsed.mSec
Value: 676
Key : Analysis.Memory.CommitPeak.Mb
Value: 82
Key : Bugcheck.Code.LegacyAPI
Value: 0x133
Key : Bugcheck.Code.TargetModel
Value: 0x133
Key : Failure.Bucket
Value: 0x133_ISR_nt!KeAccumulateTicks
Key : Failure.Hash
Value: {65350307-c3b9-f4b5-8829-4d27e9ff9b06}
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Version
Value: 10.0.19041.1
BUGCHECK_CODE: 133
BUGCHECK_P1: 1
BUGCHECK_P2: 1e00
BUGCHECK_P3: fffff80104cfb320
BUGCHECK_P4: 0
FILE_IN_CAB: 073124-11218-01 (1).dmp
DPC_TIMEOUT_TYPE: DPC_QUEUE_EXECUTION_TIMEOUT_EXCEEDED
TRAP_FRAME: ffffa78a78df7830 -- (.trap 0xffffa78a78df7830)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=000000001f34c647 rbx=0000000000000000 rcx=ffffa78a78df7a98
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff801042de395 rsp=ffffa78a78df79c0 rbp=fffff80104c51668
r8=0000000000000000 r9=ffffa70000007c90 r10=ffffa70000006180
r11=ffffa40000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na po nc
nt!KeYieldProcessorEx+0x15:
fffff801`042de395 f390 pause
Resetting default scope
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXWINLOGON: 1
PROCESS_NAME: System
STACK_TEXT:
ffff9000`2dbf1e18 fffff801`04443814 : 00000000`00000133 00000000`00000001 00000000`00001e00 fffff801`04cfb320 : nt!KeBugCheckEx
ffff9000`2dbf1e20 fffff801`042813c3 : 000004ed`7d19abe2 ffff9000`2dbd8180 00000000`00000000 ffff9000`2dbd8180 : nt!KeAccumulateTicks+0x1bfbf4
ffff9000`2dbf1e80 fffff801`04280eaa : ffffa987`a2103d40 ffffa78a`78df78b0 00000000`00000000 0000000f`ffffffff : nt!KeClockInterruptNotify+0x453
ffff9000`2dbf1f30 fffff801`0433e965 : ffffa987`a2103d40 fffff801`04322fb7 00000000`00000000 00000000`00000000 : nt!HalpTimerClockIpiRoutine+0x1a
ffff9000`2dbf1f60 fffff801`043fdc3a : ffffa78a`78df78b0 ffffa987`a2103d40 ffffffff`ffffffff 00000000`00000000 : nt!KiCallInterruptServiceRoutine+0xa5
ffff9000`2dbf1fb0 fffff801`043fe407 : ffffa400`07e034b0 00000000`002a0119 ffffa987`a2103d40 ffffa400`07e034b0 : nt!KiInterruptSubDispatchNoLockNoEtw+0xfa
ffffa78a`78df7830 fffff801`042de395 : ffffffff`ffffffd2 fffff801`043845e3 00000000`00000010 00000000`00040282 : nt!KiInterruptDispatchNoLockNoEtw+0x37
ffffa78a`78df79c0 fffff801`043845df : ffffa400`07e034b0 00000000`00000180 00000000`00000010 00000000`00000063 : nt!KeYieldProcessorEx+0x15
ffffa78a`78df79f0 fffff801`0454f569 : fffff801`04c50c00 00000000`1f34c647 00000000`00000000 fffff801`04c516c0 : nt!MiRemoveLowestPriorityStandbyPage+0x29f
ffffa78a`78df7a90 fffff801`0454f7c3 : fffff801`04c50c00 00000000`00000000 fffff801`00000000 00000000`0000039d : nt!MiPruneStandbyPages+0x265
ffffa78a`78df7b20 fffff801`0428e5c5 : ffffa987`adc4e040 fffff801`0454f730 ffffa987`a208ac10 fffff801`04c524a0 : nt!MiRebalanceZeroFreeLists+0x93
ffffa78a`78df7b70 fffff801`043265f5 : ffffa987`adc4e040 00000000`00000080 ffffa987`a20c0080 000f8067`b4bbbdff : nt!ExpWorkerThread+0x105
ffffa78a`78df7c10 fffff801`044048d8 : ffff9000`2db5e180 ffffa987`adc4e040 fffff801`043265a0 00000000`00000000 : nt!PspSystemThreadStartup+0x55
ffffa78a`78df7c60 00000000`00000000 : ffffa78a`78df8000 ffffa78a`78df2000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
SYMBOL_NAME: nt!KeAccumulateTicks+1bfbf4
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
IMAGE_VERSION: 10.0.19041.2965
STACK_COMMAND: .cxr; .ecxr ; kb
BUCKET_ID_FUNC_OFFSET: 1bfbf4
FAILURE_BUCKET_ID: 0x133_ISR_nt!KeAccumulateTicks
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {65350307-c3b9-f4b5-8829-4d27e9ff9b06}
ATTEMPTED_WRITE_TO_READONLY_MEMORY (be)
An attempt was made to write to readonly memory. The guilty driver is on the
stack trace (and is typically the current instruction pointer).
When possible, the guilty driver's name (Unicode string) is printed on
the BugCheck screen and saved in KiBugCheckDriver.
Arguments:
Arg1: ffffe60f0b2b3594, Virtual address for the attempted write.
Arg2: 8a00000000200121, PTE contents.
Arg3: ffffca01feb41820, (reserved)
Arg4: 000000000000000a, (reserved)
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 1218
Key : Analysis.Elapsed.mSec
Value: 2385
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 0
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 405
Key : Analysis.Init.Elapsed.mSec
Value: 2316
Key : Analysis.Memory.CommitPeak.Mb
Value: 81
Key : Bugcheck.Code.LegacyAPI
Value: 0xbe
Key : Bugcheck.Code.TargetModel
Value: 0xbe
Key : Failure.Bucket
Value: AV_nt!MiRaisedIrqlFault
Key : Failure.Hash
Value: {3b24175f-7f5b-9c9f-8aaf-822c248bf0f5}
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Version
Value: 10.0.19041.1
BUGCHECK_CODE: be
BUGCHECK_P1: ffffe60f0b2b3594
BUGCHECK_P2: 8a00000000200121
BUGCHECK_P3: ffffca01feb41820
BUGCHECK_P4: a
FILE_IN_CAB: 073124-13187-01 (1).dmp
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXWINLOGON: 1
PROCESS_NAME: System
TRAP_FRAME: ffffca01feb41820 -- (.trap 0xffffca01feb41820)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffffe60000000000 rbx=0000000000000000 rcx=ffffe60f0b2b3570
rdx=00000000000fffff rsi=0000000000000000 rdi=0000000000000000
rip=fffff80314b9c25d rsp=ffffca01feb419b0 rbp=ffffe90000007000
r8=0000000000000000 r9=0000000fffffffff r10=ffffe6000b2b3420
r11=fffffff000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
nt!MiUnlinkNumaStandbyPage+0xe9:
fffff803`14b9c25d 6644897124 mov word ptr [rcx+24h],r14w ds:ffffe60f`0b2b3594=????
Resetting default scope
STACK_TEXT:
ffffca01`feb41628 fffff803`14c69fe4 : 00000000`000000be ffffe60f`0b2b3594 8a000000`00200121 ffffca01`feb41820 : nt!KeBugCheckEx
ffffca01`feb41630 fffff803`14a6e89f : 8a000000`00200121 00000000`00000003 ffffca01`feb418a0 00000000`00000000 : nt!MiRaisedIrqlFault+0x163d6c
ffffca01`feb41680 fffff803`14c0b7d8 : ffffe600`0b2b17d0 00000000`00000000 fffff803`15450cc0 fffff803`14b146e9 : nt!MmAccessFault+0x4ef
ffffca01`feb41820 fffff803`14b9c25d : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000018 : nt!KiPageFault+0x358
ffffca01`feb419b0 fffff803`14b84936 : ffffe600`0b2b3450 00000000`00000000 00000000`00000000 00000000`00000021 : nt!MiUnlinkNumaStandbyPage+0xe9
ffffca01`feb419f0 fffff803`14d4f569 : fffff803`15450c00 00000000`00000000 00000000`00000000 fffff803`154516c0 : nt!MiRemoveLowestPriorityStandbyPage+0x5f6
ffffca01`feb41a90 fffff803`14d4f7c3 : fffff803`15450c00 00000000`00000000 fffff803`00000000 00000000`000003e3 : nt!MiPruneStandbyPages+0x265
ffffca01`feb41b20 fffff803`14a8e5c5 : ffffa189`7b68e040 fffff803`14d4f730 ffffa189`6f69fc10 fffff803`154524a0 : nt!MiRebalanceZeroFreeLists+0x93
ffffca01`feb41b70 fffff803`14b265f5 : ffffa189`7b68e040 00000000`00000080 ffffa189`6f6c2080 00000000`00000000 : nt!ExpWorkerThread+0x105
ffffca01`feb41c10 fffff803`14c048d8 : ffff8000`926a4180 ffffa189`7b68e040 fffff803`14b265a0 00000000`00000246 : nt!PspSystemThreadStartup+0x55
ffffca01`feb41c60 00000000`00000000 : ffffca01`feb42000 ffffca01`feb3c000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
SYMBOL_NAME: nt!MiRaisedIrqlFault+163d6c
MODULE_NAME: nt
IMAGE_VERSION: 10.0.19041.2965
STACK_COMMAND: .cxr; .ecxr ; kb
IMAGE_NAME: ntkrnlmp.exe
BUCKET_ID_FUNC_OFFSET: 163d6c
FAILURE_BUCKET_ID: AV_nt!MiRaisedIrqlFault
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {3b24175f-7f5b-9c9f-8aaf-822c248bf0f5}