KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common BugCheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff8001a0e6bde, The address that the exception occurred at
Arg3: 0000000000000001, Parameter 0 of the exception
Arg4: 0000000001b00874, Parameter 1 of the exception
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for gameflt.sys
*************************************************************************
*** ***
*** ***
*** Either you specified an unqualified symbol, or your debugger ***
*** doesn't have full symbol information. Unqualified symbol ***
*** resolution is turned off by default. Please either specify a ***
*** fully qualified symbol module!symbolname, or enable resolution ***
*** of unqualified symbols by typing ".symopt- 100". Note that ***
*** enabling unqualified symbol resolution with network symbol ***
*** server shares in the symbol path may cause the debugger to ***
*** appear to hang for long periods of time when an incorrect ***
*** symbol name is typed or the network symbol server is down. ***
*** ***
*** For some commands to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: ExceptionRecord ***
*** ***
*************************************************************************
*************************************************************************
*** ***
*** ***
*** Either you specified an unqualified symbol, or your debugger ***
*** doesn't have full symbol information. Unqualified symbol ***
*** resolution is turned off by default. Please either specify a ***
*** fully qualified symbol module!symbolname, or enable resolution ***
*** of unqualified symbols by typing ".symopt- 100". Note that ***
*** enabling unqualified symbol resolution with network symbol ***
*** server shares in the symbol path may cause the debugger to ***
*** appear to hang for long periods of time when an incorrect ***
*** symbol name is typed or the network symbol server is down. ***
*** ***
*** For some commands to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: ContextRecord ***
*** ***
*************************************************************************
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 1437
Key : Analysis.Elapsed.mSec
Value: 40943
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 1
Key : Analysis.IO.Write.Mb
Value: 21
Key : Analysis.Init.CPU.mSec
Value: 359
Key : Analysis.Init.Elapsed.mSec
Value: 39581
Key : Analysis.Memory.CommitPeak.Mb
Value: 86
Key : Analysis.Version.DbgEng
Value: 10.0.27871.1001
Key : Analysis.Version.Description
Value: 10.2505.01.02 amd64fre
Key : Analysis.Version.Ext
Value: 1.2505.1.2
Key : Bugcheck.Code.LegacyAPI
Value: 0x1e
Key : Bugcheck.Code.TargetModel
Value: 0x1e
Key : Failure.Bucket
Value: AV_W_luafv!LuafvGenerateFileName
Key : Failure.Exception.IP.Address
Value: 0xfffff8001a0e6bde
Key : Failure.Exception.IP.Module
Value: nt
Key : Failure.Exception.IP.Offset
Value: 0x2e6bde
Key : Failure.Hash
Value: {44fbb93c-33d5-d277-f5f4-25d404fd224d}
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Version
Value: 10.0.19041.1
BUGCHECK_CODE: 1e
BUGCHECK_P1: ffffffffc0000005
BUGCHECK_P2: fffff8001a0e6bde
BUGCHECK_P3: 1
BUGCHECK_P4: 1b00874
FILE_IN_CAB: 081525-9703-01.dmp
FAULTING_THREAD: ffffc40f17f4a080
EXCEPTION_PARAMETER1: 0000000000000001
EXCEPTION_PARAMETER2: 0000000001b00874
WRITE_ADDRESS: fffff8001aafb390: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
unable to get nt!MmSpecialPagesInUse
0000000001b00874
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: svchost.exe
TRAP_FRAME: ffff800000000000 -- (.trap 0xffff800000000000)
Unable to read trap frame at ffff8000`00000000
Resetting default scope
STACK_TEXT:
ffffef84`d91801a8 fffff800`1a27f1f3 : 00000000`0000001e ffffffff`c0000005 fffff800`1a0e6bde 00000000`00000001 : nt!KeBugCheckEx
ffffef84`d91801b0 fffff800`1a211eec : 00000000`00001000 ffffef84`d9180a50 ffff8000`00000000 00000000`00000000 : nt!KiDispatchException+0x142ec3
ffffef84`d9180870 fffff800`1a20d752 : 00000000`00000000 00000000`00000000 ffffc40f`0b2e4420 fffff800`1a0c43e5 : nt!KiExceptionDispatch+0x12c
ffffef84`d9180a50 fffff800`1a0e6bde : 00000000`31526d73 fffff800`1a0bc86f ffffc40f`1767cf20 00000000`00000000 : nt!KiPageFault+0x452
ffffef84`d9180be0 fffff800`1a05a4fc : 00000000`00000000 ffffef84`d9180c20 00000000`00000001 ffffc40f`192b3648 : nt!SepIsSModeEnabled+0x3e
ffffef84`d9180c20 fffff800`15fe41fb : 00000000`00000012 ffffef84`d9180d18 ffffc40f`19127850 00000000`00000101 : nt!KeAreAllApcsDisabled+0x1c
ffffef84`d9180c50 fffff800`5ef3f8d0 : ffffc40f`17ae5980 ffffc40f`1453f320 00000000`00000000 ffffc40f`191c1501 : FLTMGR!FltGetFileNameInformation+0xeb
ffffef84`d9180ce0 fffff800`160186ab : ffffc40f`191c15a0 00000000`00000000 ffffc40f`1453f320 fffff800`1a0d0c08 : luafv!LuafvGenerateFileName+0x60
ffffef84`d9180d10 fffff800`16018deb : ffffc40f`17ae8700 ffffc40f`17ae8730 ffffc40f`17ae8730 fffff800`1a0cbbf3 : FLTMGR!FltpGetNormalizedFileNameWorker+0x18b
ffffef84`d9180d90 fffff800`15fe366f : ffffc40f`191c15e0 ffffef84`d9181000 ffffef84`d917b000 fffff800`16008060 : FLTMGR!FltpCreateFileNameInformation+0x2eb
ffffef84`d9180e10 fffff800`15fe4211 : 00000000`00008000 ffffef84`ffff7fff ffffc40f`191c15a0 ffffc40f`15e1b010 : FLTMGR!FltpGetFileNameInformation+0x6ef
ffffef84`d9180ec0 fffff800`ad331efa : ffffc40f`17ae8730 ffffef84`d9699580 ffffef84`d9699400 ffffc40f`17f4a080 : FLTMGR!FltGetFileNameInformation+0x101
ffffef84`d9180f50 ffffc40f`17ae8730 : ffffef84`d9699580 ffffef84`d9699400 ffffc40f`17f4a080 ffffef84`d9180fd0 : gameflt+0x1efa
ffffef84`d9180f58 ffffef84`d9699580 : ffffef84`d9699400 ffffc40f`17f4a080 ffffef84`d9180fd0 fffff800`1a201d7e : 0xffffc40f`17ae8730
ffffef84`d9180f60 ffffef84`d9699400 : ffffc40f`17f4a080 ffffef84`d9180fd0 fffff800`1a201d7e ffffef84`d5fa2b90 : 0xffffef84`d9699580
ffffef84`d9180f68 ffffc40f`17f4a080 : ffffef84`d9180fd0 fffff800`1a201d7e ffffef84`d5fa2b90 00000000`00000000 : 0xffffef84`d9699400
ffffef84`d9180f70 ffffef84`d9180fd0 : fffff800`1a201d7e ffffef84`d5fa2b90 00000000`00000000 00000000`00000000 : 0xffffc40f`17f4a080
ffffef84`d9180f78 fffff800`1a201d7e : ffffef84`d5fa2b90 00000000`00000000 00000000`00000000 00000038`dd98d300 : 0xffffef84`d9180fd0
ffffef84`d9180f80 fffff800`1a201d3c : ffffef84`d9180fd0 ffffc40f`17f4a080 ffffef84`d9181000 fffff800`1a0aaa5d : nt!KxSwitchKernelStackCallout+0x2e
ffffef84`d9699370 fffff800`1a0aaa5d : ffffef84`d9180fd0 ffffc40f`17f4a080 ffffef84`d9699400 00000000`00000000 : nt!KiSwitchKernelStackContinue
ffffef84`d9699390 fffff800`1a0aa852 : fffff800`ad331ee0 ffffef84`d9699580 ffffd785`00000002 00000000`00000000 : nt!KiExpandKernelStackAndCalloutOnStackSegment+0x19d
ffffef84`d9699430 fffff800`1a0aa6b3 : ffffef84`d9699600 00000000`00000001 ffffd785`00000000 ffffc40f`192b35e0 : nt!KiExpandKernelStackAndCalloutSwitchStack+0xf2
ffffef84`d96994a0 fffff800`1a0aa66d : fffff800`ad331ee0 ffffef84`d9699580 ffffc40f`192b3648 ffffc40f`0b457180 : nt!KeExpandKernelStackAndCalloutInternal+0x33
ffffef84`d9699510 fffff800`ad331ed4 : ffffc40f`17f4a080 ffffc40f`1453f3a0 00000000`00000003 00000000`00000003 : nt!KeExpandKernelStackAndCalloutEx+0x1d
ffffef84`d9699550 ffffc40f`17f4a080 : ffffc40f`1453f3a0 00000000`00000003 00000000`00000003 00000000`00000000 : gameflt+0x1ed4
ffffef84`d9699558 ffffc40f`1453f3a0 : 00000000`00000003 00000000`00000003 00000000`00000000 ffffc40f`1453f320 : 0xffffc40f`17f4a080
ffffef84`d9699560 00000000`00000003 : 00000000`00000003 00000000`00000000 ffffc40f`1453f320 00000000`c0000001 : 0xffffc40f`1453f3a0
ffffef84`d9699568 00000000`00000003 : 00000000`00000000 ffffc40f`1453f320 00000000`c0000001 ffffc40f`192b3648 : 0x3
ffffef84`d9699570 00000000`00000000 : ffffc40f`1453f320 00000000`c0000001 ffffc40f`192b3648 00000000`00000101 : 0x3
SYMBOL_NAME: luafv!LuafvGenerateFileName+60
MODULE_NAME: luafv
IMAGE_NAME: luafv.sys
IMAGE_VERSION: 10.0.19041.6157
STACK_COMMAND: .process /r /p 0xffffc40f169a0300; .thread 0xffffc40f17f4a080 ; kb
BUCKET_ID_FUNC_OFFSET: 60
FAILURE_BUCKET_ID: AV_W_luafv!LuafvGenerateFileName
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {44fbb93c-33d5-d277-f5f4-25d404fd224d}
DRIVER_OVERRAN_STACK_BUFFER (f7)
A driver has overrun a stack-based buffer. This overrun could potentially
allow a malicious user to gain control of this machine.
DESCRIPTION
A driver overran a stack-based buffer (or local variable) in a way that would
have overwritten the function's return address and jumped back to an arbitrary
address when the function returned. This is the classic "buffer overrun"
hacking attack and the system has been brought down to prevent a malicious user
from gaining complete control of it.
Do a kb to get a stack backtrace -- the last routine on the stack before the
buffer overrun handlers and BugCheck call is the one that overran its local
variable(s).
Arguments:
Arg1: ffff820f964ca6b0, Actual security check cookie from the stack
Arg2: 0000ac202ec75943, Expected security check cookie
Arg3: ffff53dfd138a6bc, Complement of the expected security check cookie
Arg4: 0000000000000000, zero
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 1031
Key : Analysis.Elapsed.mSec
Value: 26940
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 1
Key : Analysis.IO.Write.Mb
Value: 1
Key : Analysis.Init.CPU.mSec
Value: 390
Key : Analysis.Init.Elapsed.mSec
Value: 1099
Key : Analysis.Memory.CommitPeak.Mb
Value: 76
Key : Analysis.Version.DbgEng
Value: 10.0.27871.1001
Key : Analysis.Version.Description
Value: 10.2505.01.02 amd64fre
Key : Analysis.Version.Ext
Value: 1.2505.1.2
Key : Bugcheck.Code.LegacyAPI
Value: 0xf7
Key : Bugcheck.Code.TargetModel
Value: 0xf7
Key : Failure.Bucket
Value: 0xF7_MISSING_GSFRAME_nt!_report_gsfailure
Key : Failure.Hash
Value: {82d2c1b5-b0cb-60a5-9a5d-78c8c4284f84}
Key : Stack.Pointer
Value: PRCBException
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Version
Value: 10.0.19041.1
BUGCHECK_CODE: f7
BUGCHECK_P1: ffff820f964ca6b0
BUGCHECK_P2: ac202ec75943
BUGCHECK_P3: ffff53dfd138a6bc
BUGCHECK_P4: 0
FILE_IN_CAB: 081225-9453-01.dmp
FAULTING_THREAD: ffffa9085f87f080
SECURITY_COOKIE: Expected 0000ac202ec75943 found ffff820f964ca6b0
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: MsMpEng.exe
STACK_TEXT:
ffff9780`79fbd0f8 fffff807`062b6245 : 00000000`000000f7 ffff820f`964ca6b0 0000ac20`2ec75943 ffff53df`d138a6bc : nt!KeBugCheckEx
ffff9780`79fbd100 fffff807`061d564e : ffff9780`79fbd710 fffff807`0613ea6f fffff807`05f00108 ffff9780`00000000 : nt!_report_gsfailure+0x25
ffff9780`79fbd140 fffff807`061d55e3 : ffff9780`79fbd210 00000000`00000000 ffff9780`79fbd748 ffff9780`79fbd720 : nt!_GSHandlerCheckCommon+0x5a
ffff9780`79fbd170 fffff807`06207f02 : fffff807`061d55d0 00000000`00000000 00000000`00000000 00000000`00000000 : nt!_GSHandlerCheck+0x13
ffff9780`79fbd1a0 fffff807`0613e857 : ffff9780`79fbd710 00000000`00000000 ffff9780`79fbd920 fffff807`06444245 : nt!RtlpExecuteHandlerForException+0x12
ffff9780`79fbd1d0 fffff807`0613c4f6 : ffff820f`964ca478 ffff9780`79fbde20 ffff820f`964ca478 ffffa908`5ce289f0 : nt!RtlDispatchException+0x297
ffff9780`79fbd8f0 fffff807`061fe522 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDispatchException+0x186
ffff9780`79fbdfb0 fffff807`061fe4f0 : fffff807`06211ce5 00000000`00000000 fffff807`060cff08 ffff8380`b2226df4 : nt!KxExceptionDispatchOnExceptionStack+0x12
ffff820f`964ca338 fffff807`06211ce5 : 00000000`00000000 fffff807`060cff08 ffff8380`b2226df4 ffff8380`b9f9b4f0 : nt!KiExceptionDispatchOnExceptionStackContinue
ffff820f`964ca340 fffff807`0620b778 : ffff820f`964ca7e0 00000000`00000000 ffff820f`964ca601 ffff820f`964ca638 : nt!KiExceptionDispatch+0x125
ffff820f`964ca520 fffff807`06444245 : 00000000`00000000 00000000`00000000 ffff820f`00000001 00000000`00000001 : nt!KiInvalidOpcodeFault+0x338
ffff820f`964ca6b0 00000000`00000000 : ffff2e2f`b88bfe53 000000dd`11bf9e78 00000000`00000000 00000000`00000001 : nt!ObpCreateHandle+0x815
SYMBOL_NAME: nt!_report_gsfailure+25
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
IMAGE_VERSION: 10.0.19041.6093
STACK_COMMAND: .process /r /p 0xffffa9085d31d080; .thread 0xffffa9085f87f080 ; kb
BUCKET_ID_FUNC_OFFSET: 25
FAILURE_BUCKET_ID: 0xF7_MISSING_GSFRAME_nt!_report_gsfailure
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {82d2c1b5-b0cb-60a5-9a5d-78c8c4284f84}
DRIVER_OVERRAN_STACK_BUFFER (f7)
A driver has overrun a stack-based buffer. This overrun could potentially
allow a malicious user to gain control of this machine.
DESCRIPTION
A driver overran a stack-based buffer (or local variable) in a way that would
have overwritten the function's return address and jumped back to an arbitrary
address when the function returned. This is the classic "buffer overrun"
hacking attack and the system has been brought down to prevent a malicious user
from gaining complete control of it.
Do a kb to get a stack backtrace -- the last routine on the stack before the
buffer overrun handlers and BugCheck call is the one that overran its local
variable(s).
Arguments:
Arg1: ffffde0a17fe8cb8, Actual security check cookie from the stack
Arg2: 000062f0d893ddb8, Expected security check cookie
Arg3: ffff9d0f276c2247, Complement of the expected security check cookie
Arg4: 0000000000000000, zero
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 1015
Key : Analysis.Elapsed.mSec
Value: 21835
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 1
Key : Analysis.IO.Write.Mb
Value: 21
Key : Analysis.Init.CPU.mSec
Value: 468
Key : Analysis.Init.Elapsed.mSec
Value: 59015
Key : Analysis.Memory.CommitPeak.Mb
Value: 76
Key : Analysis.Version.DbgEng
Value: 10.0.27871.1001
Key : Analysis.Version.Description
Value: 10.2505.01.02 amd64fre
Key : Analysis.Version.Ext
Value: 1.2505.1.2
Key : Bugcheck.Code.LegacyAPI
Value: 0xf7
Key : Bugcheck.Code.TargetModel
Value: 0xf7
Key : Failure.Bucket
Value: 0xF7_MISSING_GSFRAME_nt!_report_gsfailure
Key : Failure.Hash
Value: {82d2c1b5-b0cb-60a5-9a5d-78c8c4284f84}
Key : Stack.Pointer
Value: PRCBException
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Version
Value: 10.0.19041.1
BUGCHECK_CODE: f7
BUGCHECK_P1: ffffde0a17fe8cb8
BUGCHECK_P2: 62f0d893ddb8
BUGCHECK_P3: ffff9d0f276c2247
BUGCHECK_P4: 0
FILE_IN_CAB: 081525-9218-01.dmp
FAULTING_THREAD: ffff9886aedbd080
SECURITY_COOKIE: Expected 000062f0d893ddb8 found ffffde0a17fe8cb8
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: MsMpEng.exe
STACK_TEXT:
ffffb881`93dfc0f8 fffff800`742b63b5 : 00000000`000000f7 ffffde0a`17fe8cb8 000062f0`d893ddb8 ffff9d0f`276c2247 : nt!KeBugCheckEx
ffffb881`93dfc100 fffff800`741d56fe : ffffb881`93dfc710 fffff800`7413ea2f fffff800`73ed035c ffffb881`00000000 : nt!_report_gsfailure+0x25
ffffb881`93dfc140 fffff800`741d5693 : ffffb881`93dfc210 00000000`00000000 ffffb881`93dfc748 ffffb881`93dfc720 : nt!_GSHandlerCheckCommon+0x5a
ffffb881`93dfc170 fffff800`74208052 : fffff800`741d5680 00000000`00000000 00000000`00000000 00000000`00000000 : nt!_GSHandlerCheck+0x13
ffffb881`93dfc1a0 fffff800`7413e817 : ffffb881`93dfc710 00000000`00000000 ffffb881`93dfc920 fffff800`740b57b8 : nt!RtlpExecuteHandlerForException+0x12
ffffb881`93dfc1d0 fffff800`7413c4b6 : ffffde0a`17fe8a78 ffffb881`93dfce20 ffffde0a`17fe8a78 00000000`00000000 : nt!RtlDispatchException+0x297
ffffb881`93dfc8f0 fffff800`741fe672 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDispatchException+0x186
ffffb881`93dfcfb0 fffff800`741fe640 : fffff800`74211ee5 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KxExceptionDispatchOnExceptionStack+0x12
ffffde0a`17fe8938 fffff800`74211ee5 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiExceptionDispatchOnExceptionStackContinue
ffffde0a`17fe8940 fffff800`7420d2ef : ffffde0a`17fe9068 ffffffff`ffffffff fffff800`74a50d40 00000000`00000000 : nt!KiExceptionDispatch+0x125
ffffde0a`17fe8b20 fffff800`740b57b8 : fffff800`740b636c ffff9886`9d17d000 ffff97cb`c0814380 00000000`00000000 : nt!KiGeneralProtectionFault+0x32f
ffffde0a`17fe8cb8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MiDecommitPages+0x908
SYMBOL_NAME: nt!_report_gsfailure+25
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
IMAGE_VERSION: 10.0.19041.6216
STACK_COMMAND: .process /r /p 0xffff9886ae3750c0; .thread 0xffff9886aedbd080 ; kb
BUCKET_ID_FUNC_OFFSET: 25
FAILURE_BUCKET_ID: 0xF7_MISSING_GSFRAME_nt!_report_gsfailure
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {82d2c1b5-b0cb-60a5-9a5d-78c8c4284f84}
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 0000000000000001, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000001, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff8041b6a724e, address which referenced memory
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 1187
Key : Analysis.Elapsed.mSec
Value: 42526
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 1
Key : Analysis.IO.Write.Mb
Value: 23
Key : Analysis.Init.CPU.mSec
Value: 406
Key : Analysis.Init.Elapsed.mSec
Value: 38064
Key : Analysis.Memory.CommitPeak.Mb
Value: 91
Key : Analysis.Version.DbgEng
Value: 10.0.27871.1001
Key : Analysis.Version.Description
Value: 10.2505.01.02 amd64fre
Key : Analysis.Version.Ext
Value: 1.2505.1.2
Key : Bugcheck.Code.LegacyAPI
Value: 0xa
Key : Bugcheck.Code.TargetModel
Value: 0xa
Key : Failure.Bucket
Value: AV_nt!KiPageFault
Key : Failure.Hash
Value: {ec3e2762-48ae-ffe9-5b16-fbcb853e8320}
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Version
Value: 10.0.19041.1
BUGCHECK_CODE: a
BUGCHECK_P1: 1
BUGCHECK_P2: 2
BUGCHECK_P3: 1
BUGCHECK_P4: fffff8041b6a724e
FILE_IN_CAB: 081625-8000-01.dmp
FAULTING_THREAD: ffff8a0b1746e080
WORKER_ROUTINE:
+0
00000000`00000001 ?? ???
WORK_ITEM: fffff8041b6a724e
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: AsusS
STACK_TEXT:
ffffd28d`9b636c08 fffff804`1b811da9 : 00000000`0000000a 00000000`00000001 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
ffffd28d`9b636c10 fffff804`1b80d778 : 00000000`00000000 00000000`00000001 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
ffffd28d`9b636d50 fffff804`1b6a724e : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x478
ffffd28d`9b636ee0 fffff804`1b6a6e72 : 80000000`00000003 80000000`00000008 8a000000`00000000 00000000`00000000 : nt!MiInsertPageInList+0x3be
ffffd28d`9b636f80 fffff804`1b6a5c65 : 00000000`833cc8c0 80000000`00000000 00000000`00000006 00000000`00000000 : nt!MiPfnShareCountIsZero+0x652
ffffd28d`9b636fe0 fffff804`1b6b1e1f : ffff8a0b`02930b00 00000000`00003000 ffff8a0b`0f3a4bb0 00000000`00000001 : nt!MiMakePageAvoidRead+0x1565
ffffd28d`9b637160 fffff804`1b6b271c : ffff9f05`4ca03000 00000174`7f1692c0 ffffd28d`00000000 00000000`00001000 : nt!MmCopyToCachedPage+0x28f
ffffd28d`9b637230 fffff804`1b62ba0a : ffff8a0b`0f3a4bb0 00000174`7f1692c0 ffffd28d`9b637428 00000000`00000000 : nt!CcMapAndCopyInToCache+0x41c
ffffd28d`9b6373d0 fffff804`1f6ecb3c : ffffd28d`9b637540 00000000`00001000 00000000`00004000 00000000`00001000 : nt!CcCopyWriteEx+0xea
ffffd28d`9b637450 fffff804`193c783b : 00000000`00000000 ffffd28d`9b637868 ffffd28d`9b637828 00000174`7f1692c0 : Ntfs!NtfsCopyWriteA+0x5fc
ffffd28d`9b637780 fffff804`193c464a : ffffd28d`9b637890 ffffd28d`9b637828 ffff8a0b`168cfae0 ffff8a0b`168cf9e0 : FLTMGR!FltpPerformFastIoCall+0x16b
ffffd28d`9b6377e0 fffff804`193f9525 : ffffd28d`9b638000 ffffd28d`9b632000 00000000`00000001 ffffd28d`9b637978 : FLTMGR!FltpPassThroughFastIo+0x10a
ffffd28d`9b637860 fffff804`1b9cecaf : ffffd28d`9b637901 ffff8a0b`1746e080 00000000`00000000 00000000`00000000 : FLTMGR!FltpFastIoWrite+0x165
ffffd28d`9b637910 fffff804`1bac92b0 : ffff8a0b`198dac00 00000000`00000000 00000000`00000000 00000000`00000000 : nt!IopWriteFile+0x137
ffffd28d`9b637a10 fffff804`1b811508 : ffffd28d`9b637b80 00000009`531be568 00000009`531be638 00000009`531be308 : nt!NtWriteFile+0xd0
ffffd28d`9b637a90 00007ff8`4620d5f4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
00000009`531be548 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff8`4620d5f4
SYMBOL_NAME: nt!KiPageFault+478
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
IMAGE_VERSION: 10.0.19041.6216
STACK_COMMAND: .process /r /p 0xffff8a0b144670c0; .thread 0xffff8a0b1746e080 ; kb
BUCKET_ID_FUNC_OFFSET: 478
FAILURE_BUCKET_ID: AV_nt!KiPageFault
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {ec3e2762-48ae-ffe9-5b16-fbcb853e8320}
Followup: MachineOwner
---------
[SMBIOS Data Tables v3.2]
[DMI Version - 0]
[2.0 Calling Convention - No]
[Table Size - 1847 bytes]
[BIOS Information (Type 0) - Length 26 - Handle 0000h]
Vendor American Megatrends International, LLC.
BIOS Version G513IH.329
BIOS Starting Address Segment f000
BIOS Release Date 03/01/2023
BIOS ROM Size 1000000
BIOS Characteristics
07: - PCI Supported
11: - Upgradeable FLASH BIOS
12: - BIOS Shadowing Supported
15: - CD-Boot Supported
16: - Selectable Boot Supported
17: - BIOS ROM Socketed
19: - EDD Supported
23: - 1.2MB Floppy Supported
24: - 720KB Floppy Supported
25: - 2.88MB Floppy Supported
26: - Print Screen Device Supported
28: - Serial Services Supported
29: - Printer Services Supported
32: - BIOS Vendor Reserved
BIOS Characteristic Extensions
00: - ACPI Supported
01: - USB Legacy Supported
08: - BIOS Boot Specification Supported
10: - Enable Targeted Content Distribution
11: - UEFI Specification Supported
BIOS Major Revision 5
BIOS Minor Revision 16
EC Firmware Major Revision 0
EC Firmware Minor Revision 80
Extended BIOS ROM Size 16 MB
[System Information (Type 1) - Length 27 - Handle 0001h]
Manufacturer ASUSTeK COMPUTER INC.
Product Name ROG Strix G513IH_G513IH
Version 1.0
Serial Number MBNRKD01857645G
UUID 00000000-0000-0000-0000-000000000000
Wakeup Type Power Switch
SKUNumber
Family ROG Strix
[BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
Manufacturer ASUSTeK COMPUTER INC.
Product G513IH
Version 1.0
Serial Number D81YMC004Y
Asset Tag
Feature Flags 09h
00: - Motherboard
03: - Replaceable
Location Default string
Chassis Handle 0003h
Board Type 0ah - Processor/Memory Module
Number of Child Handles 0
[System Enclosure (Type 3) - Length 22 - Handle 0003h]
Manufacturer ASUSTeK COMPUTER INC.
Chassis Type Notebook
Version 1.0
Serial Number
Asset Tag Number
Bootup State Safe
Power Supply State Safe
Thermal State Safe
Security Status None
OEM Defined 0
Height 0U
Number of Power Cords 1
Number of Contained Elements 0
Contained Element Size 3
[Onboard Devices Information (Type 10) - Length 6 - Handle 0004h]
Note: The On Board Device Information (Type 10) struct is obsolete as of SMBIOs spec v2.6 Number of Devices 1
01: Type Video [enabled]
01: Description To Be Filled By O.E.M.
[OEM Strings (Type 11) - Length 5 - Handle 0005h]
Number of Strings 5
1
2
3
4
5 90NR07P1-M00450
[System Configuration Options (Type 12) - Length 5 - Handle 0006h]
[ (Type 256) - Length 31 - Handle 0008h]
[32Bit Memory Error Information (Type 18) - Length 23 - Handle 0009h]
[Physical Memory Array (Type 16) - Length 23 - Handle 000ah]
Location 03h - SystemBoard/Motherboard
Use 03h - System Memory
Memory Error Correction 03h - None
Maximum Capacity 33554432KB
Memory Error Inf Handle 0009h
Number of Memory Devices 2
[Memory Array Mapped Address (Type 19) - Length 31 - Handle 000bh]
Starting Address 00000000h
Ending Address 007fffffh
Memory Array Handle 000ah
Partition Width 01
Extended Starting Address 0000000000000000h
Extended Ending Address 0000000000000000h
[Cache Information (Type 7) - Length 27 - Handle 000ch]
Socket Designation L1 - Cache
Cache Configuration 0180h - WBEnabled Int NonSocketed L1
Maximum Cache Size 0200h - 512K
Installed Size 0200h - 512K
Supported SRAM Type 0010h - Pipeline-Burst
Current SRAM Type 0010h - Pipeline-Burst
Cache Speed 1ns
Error Correction Type Specification Reserved
System Cache Type Unified
Associativity 8-way Set-Associative
Maximum Cache Size 2 200 - 00000512l Kb
Installed Cache Size 2 200 - 00000512l Kb
[Cache Information (Type 7) - Length 27 - Handle 000dh]
Socket Designation L2 - Cache
Cache Configuration 0181h - WBEnabled Int NonSocketed L2
Maximum Cache Size 1000h - 4096K
Installed Size 1000h - 4096K
Supported SRAM Type 0010h - Pipeline-Burst
Current SRAM Type 0010h - Pipeline-Burst
Cache Speed 1ns
Error Correction Type Specification Reserved
System Cache Type Unified
Associativity 8-way Set-Associative
Maximum Cache Size 2 1000 - 00004096l Kb
Installed Cache Size 2 1000 - 00004096l Kb
[Cache Information (Type 7) - Length 27 - Handle 000eh]
Socket Designation L3 - Cache
Cache Configuration 0182h - WBEnabled Int NonSocketed L3
Maximum Cache Size 2000h - 8192K
Installed Size 2000h - 8192K
Supported SRAM Type 0010h - Pipeline-Burst
Current SRAM Type 0010h - Pipeline-Burst
Cache Speed 1ns
Error Correction Type Specification Reserved
System Cache Type Unified
Associativity 16-way Set-Associative
Maximum Cache Size 2 2000 - 00008192l Kb
Installed Cache Size 2 2000 - 00008192l Kb
[Processor Information (Type 4) - Length 48 - Handle 000fh]
Socket Designation FP6
Processor Type Central Processor
Processor Family 6bh - AMD Zen Processor Family
Processor Manufacturer Advanced Micro Devices, Inc.
Processor ID 10f8600fffb8b17
Processor Version AMD Ryzen 7 4800H with Radeon Graphics
Processor Voltage 8ch - 1.2V
External Clock 100MHz
Max Speed 4300MHz
Current Speed 2900MHz
Status Enabled Populated
Processor Upgrade None
L1 Cache Handle 000ch
L2 Cache Handle 000dh
L3 Cache Handle 000eh
Serial Number
Asset Tag Number
Part Number Unknown
Core Count 8
Core Enabled 8
Thread Count 16
Processor Characteristics fc
Enabled Characteristics:
0x 2: 64-bit Capable
0x 3: Multi-Core
0x 4: Hardware Thread
0x 5: Execute Protection
0x 6: Enhanced Virtualization
0x 7: Power/Performance Control
Processor Family 2 006bh - AMD Zen Processor Family
Core Count 2 8
Core Enabled 2 8
Thread Count 2 16
[32Bit Memory Error Information (Type 18) - Length 23 - Handle 0010h]
[Memory Device (Type 17) - Length 84 - Handle 0011h]
Memory Error Info Handle 0010h
Total Width 64 bits
Data Width 64 bits
Size 8192MB
Form Factor 0dh - SODIMM
Device Set [None]
Device Locator DIMM 0
Bank Locator P0 CHANNEL A
Memory Type 1ah - DDR4
Type Detail 4080h - Synchronous Unbuffered (Unregistered)
Speed 3200MHz
Manufacturer Micron Technology
Serial Number
Asset Tag Number [String Not Specified]
Part Number 4ATF1G64HZ-3G2E2
Attributes 1
Extended Size 0
Configured Memory Speed 3200
Minimum Voltage 1200
Maximum Voltage 1200
Configured Voltage 1200
Memory Technology 3
Memory Operating Mode Capability 8
Firmware Version 6
Module Manufacturer Id 11392
Module Product Id 0
Memory Subsystem Controller Manufacturer Id 0
Memory Subsystem Controller Product Id 0
Non-Volatile Size 0
Volatile Size 0
Cache Size 0
Logical Size 0
[Memory Device Mapped Address (Type 20) - Length 35 - Handle 0012h]
Starting Address 00000000h
Ending Address 007fffffh
Memory Device Handle 0011h
Mem Array Mapped Adr Handle 000bh
Partition Row Position [Unknown]
Interleave Position [None]
Interleave Data Depth [None]
Extended Starting Address 0000000000000000h
Extended Ending Address 0000000000000000h
[32Bit Memory Error Information (Type 18) - Length 23 - Handle 0013h]
[Memory Device (Type 17) - Length 84 - Handle 0014h]
Memory Error Info Handle 0013h
Total Width [Unknown]
Data Width [Unknown]
Size [Not Populated]
Form Factor 02h - Unknown
Device Set [None]
Device Locator DIMM 0
Bank Locator P0 CHANNEL B
Memory Type 02h - Unknown
Type Detail 0004h - Unknown
Speed 0MHz
Manufacturer Unknown
Serial Number
Asset Tag Number [String Not Specified]
Part Number Unknown
Attributes 0
Extended Size 0
Configured Memory Speed 0
Minimum Voltage 0
Maximum Voltage 0
Configured Voltage 0
Memory Technology 2
Memory Operating Mode Capability 4
Firmware Version 6
Module Manufacturer Id 0
Module Product Id 0
Memory Subsystem Controller Manufacturer Id 0
Memory Subsystem Controller Product Id 0
Non-Volatile Size 0
Volatile Size 0
Cache Size 0
Logical Size 0
[ (Type 256) - Length 11 - Handle 0030h]
[ (Type 256) - Length 11 - Handle 0031h]
[ (Type 256) - Length 4 - Handle 0033h]
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except.
Typically the address is just plain bad or it is pointing at freed memory.
Arguments:
Arg1: ffff950d56505c10, memory referenced.
Arg2: 0000000000000011, X64: bit 0 set if the fault was due to a not-present PTE.
bit 1 is set if the fault was due to a write, clear if a read.
bit 3 is set if the processor decided the fault was due to a corrupted PTE.
bit 4 is set if the fault was due to attempted execute of a no-execute PTE.
- ARM64: bit 1 is set if the fault was due to a write, clear if a read.
bit 3 is set if the fault was due to attempted execute of a no-execute PTE.
Arg3: ffff950d56505c10, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000002, (reserved)
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for WdFilter.sys
*** WARNING: Unable to verify timestamp for amdfendr.sys
KEY_VALUES_STRING: 1
Key : AV.PTE
Value: Valid
Key : AV.Type
Value: Execute
Key : Analysis.CPU.mSec
Value: 1343
Key : Analysis.Elapsed.mSec
Value: 35613
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 1
Key : Analysis.IO.Write.Mb
Value: 21
Key : Analysis.Init.CPU.mSec
Value: 531
Key : Analysis.Init.Elapsed.mSec
Value: 58913
Key : Analysis.Memory.CommitPeak.Mb
Value: 86
Key : Analysis.Version.DbgEng
Value: 10.0.27871.1001
Key : Analysis.Version.Description
Value: 10.2505.01.02 amd64fre
Key : Analysis.Version.Ext
Value: 1.2505.1.2
Key : Bugcheck.Code.LegacyAPI
Value: 0x50
Key : Bugcheck.Code.TargetModel
Value: 0x50
Key : Failure.Bucket
Value: AV_X_(null)_WdFilter!unknown_function
Key : Failure.Exception.IP.Address
Value: 0xffff950d56505c10
Key : Failure.Hash
Value: {2466b939-761d-7888-7d7b-3981f617c641}
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Version
Value: 10.0.19041.1
BUGCHECK_CODE: 50
BUGCHECK_P1: ffff950d56505c10
BUGCHECK_P2: 11
BUGCHECK_P3: ffff950d56505c10
BUGCHECK_P4: 2
FILE_IN_CAB: 081425-22218-01.dmp
FAULTING_THREAD: ffff950d4bdd7040
WRITE_ADDRESS: fffff8011dcfb390: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
unable to get nt!MmSpecialPagesInUse
ffff950d56505c10
MM_INTERNAL_CODE: 2
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System
LOCK_ADDRESS: fffff8011dc44be0 -- (!locks fffff8011dc44be0)
Cannot get _ERESOURCE Flag field
Unexpected resource format: 0
1 total locks
PNP_TRIAGE_DATA:
Lock address : 0xfffff8011dc44be0
Thread Count : 0
Thread address: 0x0000000000000000
Thread wait : 0x0
STACK_TEXT:
ffffcf8a`edba0808 fffff801`1d448b23 : 00000000`00000050 ffff950d`56505c10 00000000`00000011 ffffcf8a`edba0ab0 : nt!KeBugCheckEx
ffffcf8a`edba0810 fffff801`1d20d450 : 00000000`00000000 00000000`00000011 ffffcf8a`edba0b30 00000000`00000000 : nt!MiSystemFault+0x1b70a3
ffffcf8a`edba0910 fffff801`1d40d66d : ffff950d`00000000 00000000`00000000 ffff950d`561caa20 ffffcf8a`edba0e40 : nt!MmAccessFault+0x400
ffffcf8a`edba0ab0 ffff950d`56505c10 : fffff801`1d2cbc09 00000000`00040293 fffff801`1d2d0cbb 00000000`ffffffff : nt!KiPageFault+0x36d
ffffcf8a`edba0c48 fffff801`1d2cbc09 : 00000000`00040293 fffff801`1d2d0cbb 00000000`ffffffff ffffad01`00000000 : 0xffff950d`56505c10
ffffcf8a`edba0c50 fffff801`1bf9a478 : ffffcf8a`edba0e68 ffff950d`4b8145e0 ffffcf8a`edba0d58 00000000`00000000 : nt!ExReleaseResourceLite+0x109
ffffcf8a`edba0cb0 fffff801`1bf9a3fd : ffff950d`566d30f8 ffffcf8a`edba0d88 ffff950d`4b2a0a20 00000000`00000009 : FLTMGR!FltSetEcpListIntoCallbackData+0x58
ffffcf8a`edba0ce0 fffff801`21f5a7ea : 00000000`0000004f ffffad01`5871c188 ffffad01`58764690 ffffad01`58733530 : FLTMGR!FltRequestFileInfoOnCreateCompletion+0x11d
ffffcf8a`edba0d20 00000000`0000004f : ffffad01`5871c188 ffffad01`58764690 ffffad01`58733530 00000000`00000170 : WdFilter+0x2a7ea
ffffcf8a`edba0d28 ffffad01`5871c188 : ffffad01`58764690 ffffad01`58733530 00000000`00000170 00000000`00000090 : 0x4f
ffffcf8a`edba0d30 ffffad01`58764690 : ffffad01`58733530 00000000`00000170 00000000`00000090 ffff950d`566d3198 : 0xffffad01`5871c188
ffffcf8a`edba0d38 ffffad01`58733530 : 00000000`00000170 00000000`00000090 ffff950d`566d3198 fffff801`1bf66e12 : 0xffffad01`58764690
ffffcf8a`edba0d40 00000000`00000170 : 00000000`00000090 ffff950d`566d3198 fffff801`1bf66e12 00000000`1000000c : 0xffffad01`58733530
ffffcf8a`edba0d48 00000000`00000090 : ffff950d`566d3198 fffff801`1bf66e12 00000000`1000000c ffff950d`561cacb0 : 0x170
ffffcf8a`edba0d50 ffff950d`566d3198 : fffff801`1bf66e12 00000000`1000000c ffff950d`561cacb0 ffffcf8a`edba0f80 : 0x90
ffffcf8a`edba0d58 fffff801`1bf66e12 : 00000000`1000000c ffff950d`561cacb0 ffffcf8a`edba0f80 ffff950d`566d3090 : 0xffff950d`566d3198
ffffcf8a`edba0d60 fffff801`1bf664cb : 00000000`00000000 ffff950d`00000000 ffff950d`00000000 ffff950d`561cacb0 : FLTMGR!FltpLinkCompletionNodeToInstance+0x112
ffffcf8a`edba0dd0 fffff801`1bf65f7a : ffffcf8a`edba0f00 fffff801`1bf67c00 00000000`00000000 00000000`00000000 : FLTMGR!FltpPerformPreCallbacksWorker+0x36b
ffffcf8a`edba0ef0 fffff801`1bf99ed0 : ffffcf8a`edba2000 ffffcf8a`edb9c000 ffff950d`4b3b2d60 00000000`00000000 : FLTMGR!FltpPassThroughInternal+0xca
ffffcf8a`edba0f40 fffff801`1d2d21c5 : ffff950d`00000000 ffff950d`4b4cd930 00000000`00000000 00000000`00000000 : FLTMGR!FltpCreate+0x310
ffffcf8a`edba0ff0 fffff801`1d2d4084 : ffff950d`5676ca20 fffff801`1d9b418e ffff950d`4b4cd930 fffff801`1d2d3cb3 : nt!IofCallDriver+0x55
ffffcf8a`edba1030 fffff801`1d64f829 : ffffcf8a`edba12e0 ffff950d`4b4cd930 ffff950d`5676cab8 00000000`56700001 : nt!IoCallDriverWithTracing+0x34
ffffcf8a`edba1080 fffff801`1d642757 : ffff950d`4b4cd930 ffff950d`4b4cd900 ffff950d`5670fa20 ffffad01`584bda00 : nt!IopParseDevice+0x11a9
ffffcf8a`edba11e0 fffff801`1d6cec8a : ffff950d`5670fa01 ffffcf8a`edba1448 00000000`00000240 ffff950d`455c3400 : nt!ObpLookupObjectName+0x1117
ffffcf8a`edba13b0 fffff801`1d60c431 : ffff950d`00000000 ffffcf8a`edba1880 ffffcf8a`edba1870 00000000`00000000 : nt!ObOpenObjectByNameEx+0x1fa
ffffcf8a`edba14e0 fffff801`1d60b878 : ffffcf8a`edba18d0 ffff950d`00100001 ffffcf8a`edba1880 ffffcf8a`edba1870 : nt!IopCreateFile+0xb11
ffffcf8a`edba1590 fffff801`1d411508 : ffff950d`00000000 ffff950d`5676c140 00000000`0000009e 00000000`00000000 : nt!NtOpenFile+0x58
ffffcf8a`edba1620 fffff801`1d402300 : fffff801`1d89f4bb ffff950d`456cae30 fffff801`1d5ee514 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
ffffcf8a`edba1828 fffff801`1d89f4bb : ffff950d`456cae30 fffff801`1d5ee514 00000000`00000000 00000000`00000000 : nt!KiServiceLinkage
ffffcf8a`edba1830 fffff801`1d89ecbe : ffffcf8a`edba1970 00000000`00000000 00000000`00000000 ffffcf8a`edba1920 : nt!PiGetDriverImageDirectory+0xf7
ffffcf8a`edba18c0 fffff801`87877fd4 : 00000000`00000000 ffffcf8a`edba1970 00000000`00000000 fffff801`878970f0 : nt!IoGetDriverDirectory+0x6e
ffffcf8a`edba18f0 00000000`00000000 : ffffcf8a`edba1970 00000000`00000000 fffff801`878970f0 ffff950d`557c8edb : amdfendr+0x17fd4
SYMBOL_NAME: WdFilter+2a7ea
MODULE_NAME: WdFilter
IMAGE_NAME: WdFilter.sys
STACK_COMMAND: .process /r /p 0xffff950d454fb240; .thread 0xffff950d4bdd7040 ; kb
BUCKET_ID_FUNC_OFFSET: 2a7ea
FAILURE_BUCKET_ID: AV_X_(null)_WdFilter!unknown_function
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {2466b939-761d-7888-7d7b-3981f617c641}