melihXD

Çalışkan
Katılım
26 Temmuz 2025
Mesajlar
7
Beğeniler
1
Son düzenleme:
Windows Defender (MsMpEng.exe) → bir sürücü (muhtemelen üçüncü parti ya da eski AMD/ASUS bileşeni) ile çalışırken stack buffer overflow yaratmış.

Call stack içinde amdfendr.sys de geçiyor. Bu dosya AMD’nin Endpoint Security Driver’ı (AMD chipset veya güvenlik yazılımı ile ilgili) olabilir. Windows Defender ile bu sürücü arasında çakışma yaşanıyor olabilir.

Windows 11'e geçince sorunlar çözüldü mü?

Kod:
KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common BugCheck.  Usually the exception address pinpoints
the driver/function that caused the problem.  Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff8001a0e6bde, The address that the exception occurred at
Arg3: 0000000000000001, Parameter 0 of the exception
Arg4: 0000000001b00874, Parameter 1 of the exception

Debugging Details:
------------------

*** WARNING: Unable to verify timestamp for gameflt.sys
*************************************************************************
***                                                                   ***
***                                                                   ***
***    Either you specified an unqualified symbol, or your debugger   ***
***    doesn't have full symbol information.  Unqualified symbol      ***
***    resolution is turned off by default. Please either specify a   ***
***    fully qualified symbol module!symbolname, or enable resolution ***
***    of unqualified symbols by typing ".symopt- 100". Note that     ***
***    enabling unqualified symbol resolution with network symbol     ***
***    server shares in the symbol path may cause the debugger to     ***
***    appear to hang for long periods of time when an incorrect      ***
***    symbol name is typed or the network symbol server is down.     ***
***                                                                   ***
***    For some commands to work properly, your symbol path           ***
***    must point to .pdb files that have full type information.      ***
***                                                                   ***
***    Certain .pdb files (such as the public OS symbols) do not      ***
***    contain the required information.  Contact the group that      ***
***    provided you with these symbols if you need this command to    ***
***    work.                                                          ***
***                                                                   ***
***    Type referenced: ExceptionRecord                               ***
***                                                                   ***
*************************************************************************
*************************************************************************
***                                                                   ***
***                                                                   ***
***    Either you specified an unqualified symbol, or your debugger   ***
***    doesn't have full symbol information.  Unqualified symbol      ***
***    resolution is turned off by default. Please either specify a   ***
***    fully qualified symbol module!symbolname, or enable resolution ***
***    of unqualified symbols by typing ".symopt- 100". Note that     ***
***    enabling unqualified symbol resolution with network symbol     ***
***    server shares in the symbol path may cause the debugger to     ***
***    appear to hang for long periods of time when an incorrect      ***
***    symbol name is typed or the network symbol server is down.     ***
***                                                                   ***
***    For some commands to work properly, your symbol path           ***
***    must point to .pdb files that have full type information.      ***
***                                                                   ***
***    Certain .pdb files (such as the public OS symbols) do not      ***
***    contain the required information.  Contact the group that      ***
***    provided you with these symbols if you need this command to    ***
***    work.                                                          ***
***                                                                   ***
***    Type referenced: ContextRecord                                 ***
***                                                                   ***
*************************************************************************

KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.mSec
    Value: 1437

    Key  : Analysis.Elapsed.mSec
    Value: 40943

    Key  : Analysis.IO.Other.Mb
    Value: 0

    Key  : Analysis.IO.Read.Mb
    Value: 1

    Key  : Analysis.IO.Write.Mb
    Value: 21

    Key  : Analysis.Init.CPU.mSec
    Value: 359

    Key  : Analysis.Init.Elapsed.mSec
    Value: 39581

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 86

    Key  : Analysis.Version.DbgEng
    Value: 10.0.27871.1001

    Key  : Analysis.Version.Description
    Value: 10.2505.01.02 amd64fre

    Key  : Analysis.Version.Ext
    Value: 1.2505.1.2

    Key  : Bugcheck.Code.LegacyAPI
    Value: 0x1e

    Key  : Bugcheck.Code.TargetModel
    Value: 0x1e

    Key  : Failure.Bucket
    Value: AV_W_luafv!LuafvGenerateFileName

    Key  : Failure.Exception.IP.Address
    Value: 0xfffff8001a0e6bde

    Key  : Failure.Exception.IP.Module
    Value: nt

    Key  : Failure.Exception.IP.Offset
    Value: 0x2e6bde

    Key  : Failure.Hash
    Value: {44fbb93c-33d5-d277-f5f4-25d404fd224d}

    Key  : WER.OS.Branch
    Value: vb_release

    Key  : WER.OS.Version
    Value: 10.0.19041.1


BUGCHECK_CODE:  1e

BUGCHECK_P1: ffffffffc0000005

BUGCHECK_P2: fffff8001a0e6bde

BUGCHECK_P3: 1

BUGCHECK_P4: 1b00874

FILE_IN_CAB:  081525-9703-01.dmp

FAULTING_THREAD:  ffffc40f17f4a080

EXCEPTION_PARAMETER1:  0000000000000001

EXCEPTION_PARAMETER2:  0000000001b00874

WRITE_ADDRESS: fffff8001aafb390: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
unable to get nt!MmSpecialPagesInUse
 0000000001b00874 

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  svchost.exe

TRAP_FRAME:  ffff800000000000 -- (.trap 0xffff800000000000)
Unable to read trap frame at ffff8000`00000000
Resetting default scope

STACK_TEXT:  
ffffef84`d91801a8 fffff800`1a27f1f3     : 00000000`0000001e ffffffff`c0000005 fffff800`1a0e6bde 00000000`00000001 : nt!KeBugCheckEx
ffffef84`d91801b0 fffff800`1a211eec     : 00000000`00001000 ffffef84`d9180a50 ffff8000`00000000 00000000`00000000 : nt!KiDispatchException+0x142ec3
ffffef84`d9180870 fffff800`1a20d752     : 00000000`00000000 00000000`00000000 ffffc40f`0b2e4420 fffff800`1a0c43e5 : nt!KiExceptionDispatch+0x12c
ffffef84`d9180a50 fffff800`1a0e6bde     : 00000000`31526d73 fffff800`1a0bc86f ffffc40f`1767cf20 00000000`00000000 : nt!KiPageFault+0x452
ffffef84`d9180be0 fffff800`1a05a4fc     : 00000000`00000000 ffffef84`d9180c20 00000000`00000001 ffffc40f`192b3648 : nt!SepIsSModeEnabled+0x3e
ffffef84`d9180c20 fffff800`15fe41fb     : 00000000`00000012 ffffef84`d9180d18 ffffc40f`19127850 00000000`00000101 : nt!KeAreAllApcsDisabled+0x1c
ffffef84`d9180c50 fffff800`5ef3f8d0     : ffffc40f`17ae5980 ffffc40f`1453f320 00000000`00000000 ffffc40f`191c1501 : FLTMGR!FltGetFileNameInformation+0xeb
ffffef84`d9180ce0 fffff800`160186ab     : ffffc40f`191c15a0 00000000`00000000 ffffc40f`1453f320 fffff800`1a0d0c08 : luafv!LuafvGenerateFileName+0x60
ffffef84`d9180d10 fffff800`16018deb     : ffffc40f`17ae8700 ffffc40f`17ae8730 ffffc40f`17ae8730 fffff800`1a0cbbf3 : FLTMGR!FltpGetNormalizedFileNameWorker+0x18b
ffffef84`d9180d90 fffff800`15fe366f     : ffffc40f`191c15e0 ffffef84`d9181000 ffffef84`d917b000 fffff800`16008060 : FLTMGR!FltpCreateFileNameInformation+0x2eb
ffffef84`d9180e10 fffff800`15fe4211     : 00000000`00008000 ffffef84`ffff7fff ffffc40f`191c15a0 ffffc40f`15e1b010 : FLTMGR!FltpGetFileNameInformation+0x6ef
ffffef84`d9180ec0 fffff800`ad331efa     : ffffc40f`17ae8730 ffffef84`d9699580 ffffef84`d9699400 ffffc40f`17f4a080 : FLTMGR!FltGetFileNameInformation+0x101
ffffef84`d9180f50 ffffc40f`17ae8730     : ffffef84`d9699580 ffffef84`d9699400 ffffc40f`17f4a080 ffffef84`d9180fd0 : gameflt+0x1efa
ffffef84`d9180f58 ffffef84`d9699580     : ffffef84`d9699400 ffffc40f`17f4a080 ffffef84`d9180fd0 fffff800`1a201d7e : 0xffffc40f`17ae8730
ffffef84`d9180f60 ffffef84`d9699400     : ffffc40f`17f4a080 ffffef84`d9180fd0 fffff800`1a201d7e ffffef84`d5fa2b90 : 0xffffef84`d9699580
ffffef84`d9180f68 ffffc40f`17f4a080     : ffffef84`d9180fd0 fffff800`1a201d7e ffffef84`d5fa2b90 00000000`00000000 : 0xffffef84`d9699400
ffffef84`d9180f70 ffffef84`d9180fd0     : fffff800`1a201d7e ffffef84`d5fa2b90 00000000`00000000 00000000`00000000 : 0xffffc40f`17f4a080
ffffef84`d9180f78 fffff800`1a201d7e     : ffffef84`d5fa2b90 00000000`00000000 00000000`00000000 00000038`dd98d300 : 0xffffef84`d9180fd0
ffffef84`d9180f80 fffff800`1a201d3c     : ffffef84`d9180fd0 ffffc40f`17f4a080 ffffef84`d9181000 fffff800`1a0aaa5d : nt!KxSwitchKernelStackCallout+0x2e
ffffef84`d9699370 fffff800`1a0aaa5d     : ffffef84`d9180fd0 ffffc40f`17f4a080 ffffef84`d9699400 00000000`00000000 : nt!KiSwitchKernelStackContinue
ffffef84`d9699390 fffff800`1a0aa852     : fffff800`ad331ee0 ffffef84`d9699580 ffffd785`00000002 00000000`00000000 : nt!KiExpandKernelStackAndCalloutOnStackSegment+0x19d
ffffef84`d9699430 fffff800`1a0aa6b3     : ffffef84`d9699600 00000000`00000001 ffffd785`00000000 ffffc40f`192b35e0 : nt!KiExpandKernelStackAndCalloutSwitchStack+0xf2
ffffef84`d96994a0 fffff800`1a0aa66d     : fffff800`ad331ee0 ffffef84`d9699580 ffffc40f`192b3648 ffffc40f`0b457180 : nt!KeExpandKernelStackAndCalloutInternal+0x33
ffffef84`d9699510 fffff800`ad331ed4     : ffffc40f`17f4a080 ffffc40f`1453f3a0 00000000`00000003 00000000`00000003 : nt!KeExpandKernelStackAndCalloutEx+0x1d
ffffef84`d9699550 ffffc40f`17f4a080     : ffffc40f`1453f3a0 00000000`00000003 00000000`00000003 00000000`00000000 : gameflt+0x1ed4
ffffef84`d9699558 ffffc40f`1453f3a0     : 00000000`00000003 00000000`00000003 00000000`00000000 ffffc40f`1453f320 : 0xffffc40f`17f4a080
ffffef84`d9699560 00000000`00000003     : 00000000`00000003 00000000`00000000 ffffc40f`1453f320 00000000`c0000001 : 0xffffc40f`1453f3a0
ffffef84`d9699568 00000000`00000003     : 00000000`00000000 ffffc40f`1453f320 00000000`c0000001 ffffc40f`192b3648 : 0x3
ffffef84`d9699570 00000000`00000000     : ffffc40f`1453f320 00000000`c0000001 ffffc40f`192b3648 00000000`00000101 : 0x3


SYMBOL_NAME:  luafv!LuafvGenerateFileName+60

MODULE_NAME: luafv

IMAGE_NAME:  luafv.sys

IMAGE_VERSION:  10.0.19041.6157

STACK_COMMAND: .process /r /p 0xffffc40f169a0300; .thread 0xffffc40f17f4a080 ; kb

BUCKET_ID_FUNC_OFFSET:  60

FAILURE_BUCKET_ID:  AV_W_luafv!LuafvGenerateFileName

OS_VERSION:  10.0.19041.1

BUILDLAB_STR:  vb_release

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

FAILURE_ID_HASH:  {44fbb93c-33d5-d277-f5f4-25d404fd224d}

DRIVER_OVERRAN_STACK_BUFFER (f7)
A driver has overrun a stack-based buffer.  This overrun could potentially
allow a malicious user to gain control of this machine.
DESCRIPTION
A driver overran a stack-based buffer (or local variable) in a way that would
have overwritten the function's return address and jumped back to an arbitrary
address when the function returned.  This is the classic "buffer overrun"
hacking attack and the system has been brought down to prevent a malicious user
from gaining complete control of it.
Do a kb to get a stack backtrace -- the last routine on the stack before the
buffer overrun handlers and BugCheck call is the one that overran its local
variable(s).
Arguments:
Arg1: ffff820f964ca6b0, Actual security check cookie from the stack
Arg2: 0000ac202ec75943, Expected security check cookie
Arg3: ffff53dfd138a6bc, Complement of the expected security check cookie
Arg4: 0000000000000000, zero

Debugging Details:
------------------


KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.mSec
    Value: 1031

    Key  : Analysis.Elapsed.mSec
    Value: 26940

    Key  : Analysis.IO.Other.Mb
    Value: 0

    Key  : Analysis.IO.Read.Mb
    Value: 1

    Key  : Analysis.IO.Write.Mb
    Value: 1

    Key  : Analysis.Init.CPU.mSec
    Value: 390

    Key  : Analysis.Init.Elapsed.mSec
    Value: 1099

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 76

    Key  : Analysis.Version.DbgEng
    Value: 10.0.27871.1001

    Key  : Analysis.Version.Description
    Value: 10.2505.01.02 amd64fre

    Key  : Analysis.Version.Ext
    Value: 1.2505.1.2

    Key  : Bugcheck.Code.LegacyAPI
    Value: 0xf7

    Key  : Bugcheck.Code.TargetModel
    Value: 0xf7

    Key  : Failure.Bucket
    Value: 0xF7_MISSING_GSFRAME_nt!_report_gsfailure

    Key  : Failure.Hash
    Value: {82d2c1b5-b0cb-60a5-9a5d-78c8c4284f84}

    Key  : Stack.Pointer
    Value: PRCBException

    Key  : WER.OS.Branch
    Value: vb_release

    Key  : WER.OS.Version
    Value: 10.0.19041.1


BUGCHECK_CODE:  f7

BUGCHECK_P1: ffff820f964ca6b0

BUGCHECK_P2: ac202ec75943

BUGCHECK_P3: ffff53dfd138a6bc

BUGCHECK_P4: 0

FILE_IN_CAB:  081225-9453-01.dmp

FAULTING_THREAD:  ffffa9085f87f080

SECURITY_COOKIE:  Expected 0000ac202ec75943 found ffff820f964ca6b0

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  MsMpEng.exe

STACK_TEXT:  
ffff9780`79fbd0f8 fffff807`062b6245     : 00000000`000000f7 ffff820f`964ca6b0 0000ac20`2ec75943 ffff53df`d138a6bc : nt!KeBugCheckEx
ffff9780`79fbd100 fffff807`061d564e     : ffff9780`79fbd710 fffff807`0613ea6f fffff807`05f00108 ffff9780`00000000 : nt!_report_gsfailure+0x25
ffff9780`79fbd140 fffff807`061d55e3     : ffff9780`79fbd210 00000000`00000000 ffff9780`79fbd748 ffff9780`79fbd720 : nt!_GSHandlerCheckCommon+0x5a
ffff9780`79fbd170 fffff807`06207f02     : fffff807`061d55d0 00000000`00000000 00000000`00000000 00000000`00000000 : nt!_GSHandlerCheck+0x13
ffff9780`79fbd1a0 fffff807`0613e857     : ffff9780`79fbd710 00000000`00000000 ffff9780`79fbd920 fffff807`06444245 : nt!RtlpExecuteHandlerForException+0x12
ffff9780`79fbd1d0 fffff807`0613c4f6     : ffff820f`964ca478 ffff9780`79fbde20 ffff820f`964ca478 ffffa908`5ce289f0 : nt!RtlDispatchException+0x297
ffff9780`79fbd8f0 fffff807`061fe522     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDispatchException+0x186
ffff9780`79fbdfb0 fffff807`061fe4f0     : fffff807`06211ce5 00000000`00000000 fffff807`060cff08 ffff8380`b2226df4 : nt!KxExceptionDispatchOnExceptionStack+0x12
ffff820f`964ca338 fffff807`06211ce5     : 00000000`00000000 fffff807`060cff08 ffff8380`b2226df4 ffff8380`b9f9b4f0 : nt!KiExceptionDispatchOnExceptionStackContinue
ffff820f`964ca340 fffff807`0620b778     : ffff820f`964ca7e0 00000000`00000000 ffff820f`964ca601 ffff820f`964ca638 : nt!KiExceptionDispatch+0x125
ffff820f`964ca520 fffff807`06444245     : 00000000`00000000 00000000`00000000 ffff820f`00000001 00000000`00000001 : nt!KiInvalidOpcodeFault+0x338
ffff820f`964ca6b0 00000000`00000000     : ffff2e2f`b88bfe53 000000dd`11bf9e78 00000000`00000000 00000000`00000001 : nt!ObpCreateHandle+0x815


SYMBOL_NAME:  nt!_report_gsfailure+25

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

IMAGE_VERSION:  10.0.19041.6093

STACK_COMMAND: .process /r /p 0xffffa9085d31d080; .thread 0xffffa9085f87f080 ; kb

BUCKET_ID_FUNC_OFFSET:  25

FAILURE_BUCKET_ID:  0xF7_MISSING_GSFRAME_nt!_report_gsfailure

OS_VERSION:  10.0.19041.1

BUILDLAB_STR:  vb_release

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

FAILURE_ID_HASH:  {82d2c1b5-b0cb-60a5-9a5d-78c8c4284f84}
DRIVER_OVERRAN_STACK_BUFFER (f7)
A driver has overrun a stack-based buffer.  This overrun could potentially
allow a malicious user to gain control of this machine.
DESCRIPTION
A driver overran a stack-based buffer (or local variable) in a way that would
have overwritten the function's return address and jumped back to an arbitrary
address when the function returned.  This is the classic "buffer overrun"
hacking attack and the system has been brought down to prevent a malicious user
from gaining complete control of it.
Do a kb to get a stack backtrace -- the last routine on the stack before the
buffer overrun handlers and BugCheck call is the one that overran its local
variable(s).
Arguments:
Arg1: ffffde0a17fe8cb8, Actual security check cookie from the stack
Arg2: 000062f0d893ddb8, Expected security check cookie
Arg3: ffff9d0f276c2247, Complement of the expected security check cookie
Arg4: 0000000000000000, zero

Debugging Details:
------------------


KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.mSec
    Value: 1015

    Key  : Analysis.Elapsed.mSec
    Value: 21835

    Key  : Analysis.IO.Other.Mb
    Value: 0

    Key  : Analysis.IO.Read.Mb
    Value: 1

    Key  : Analysis.IO.Write.Mb
    Value: 21

    Key  : Analysis.Init.CPU.mSec
    Value: 468

    Key  : Analysis.Init.Elapsed.mSec
    Value: 59015

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 76

    Key  : Analysis.Version.DbgEng
    Value: 10.0.27871.1001

    Key  : Analysis.Version.Description
    Value: 10.2505.01.02 amd64fre

    Key  : Analysis.Version.Ext
    Value: 1.2505.1.2

    Key  : Bugcheck.Code.LegacyAPI
    Value: 0xf7

    Key  : Bugcheck.Code.TargetModel
    Value: 0xf7

    Key  : Failure.Bucket
    Value: 0xF7_MISSING_GSFRAME_nt!_report_gsfailure

    Key  : Failure.Hash
    Value: {82d2c1b5-b0cb-60a5-9a5d-78c8c4284f84}

    Key  : Stack.Pointer
    Value: PRCBException

    Key  : WER.OS.Branch
    Value: vb_release

    Key  : WER.OS.Version
    Value: 10.0.19041.1


BUGCHECK_CODE:  f7

BUGCHECK_P1: ffffde0a17fe8cb8

BUGCHECK_P2: 62f0d893ddb8

BUGCHECK_P3: ffff9d0f276c2247

BUGCHECK_P4: 0

FILE_IN_CAB:  081525-9218-01.dmp

FAULTING_THREAD:  ffff9886aedbd080

SECURITY_COOKIE:  Expected 000062f0d893ddb8 found ffffde0a17fe8cb8

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  MsMpEng.exe

STACK_TEXT:  
ffffb881`93dfc0f8 fffff800`742b63b5     : 00000000`000000f7 ffffde0a`17fe8cb8 000062f0`d893ddb8 ffff9d0f`276c2247 : nt!KeBugCheckEx
ffffb881`93dfc100 fffff800`741d56fe     : ffffb881`93dfc710 fffff800`7413ea2f fffff800`73ed035c ffffb881`00000000 : nt!_report_gsfailure+0x25
ffffb881`93dfc140 fffff800`741d5693     : ffffb881`93dfc210 00000000`00000000 ffffb881`93dfc748 ffffb881`93dfc720 : nt!_GSHandlerCheckCommon+0x5a
ffffb881`93dfc170 fffff800`74208052     : fffff800`741d5680 00000000`00000000 00000000`00000000 00000000`00000000 : nt!_GSHandlerCheck+0x13
ffffb881`93dfc1a0 fffff800`7413e817     : ffffb881`93dfc710 00000000`00000000 ffffb881`93dfc920 fffff800`740b57b8 : nt!RtlpExecuteHandlerForException+0x12
ffffb881`93dfc1d0 fffff800`7413c4b6     : ffffde0a`17fe8a78 ffffb881`93dfce20 ffffde0a`17fe8a78 00000000`00000000 : nt!RtlDispatchException+0x297
ffffb881`93dfc8f0 fffff800`741fe672     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDispatchException+0x186
ffffb881`93dfcfb0 fffff800`741fe640     : fffff800`74211ee5 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KxExceptionDispatchOnExceptionStack+0x12
ffffde0a`17fe8938 fffff800`74211ee5     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiExceptionDispatchOnExceptionStackContinue
ffffde0a`17fe8940 fffff800`7420d2ef     : ffffde0a`17fe9068 ffffffff`ffffffff fffff800`74a50d40 00000000`00000000 : nt!KiExceptionDispatch+0x125
ffffde0a`17fe8b20 fffff800`740b57b8     : fffff800`740b636c ffff9886`9d17d000 ffff97cb`c0814380 00000000`00000000 : nt!KiGeneralProtectionFault+0x32f
ffffde0a`17fe8cb8 00000000`00000000     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MiDecommitPages+0x908


SYMBOL_NAME:  nt!_report_gsfailure+25

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

IMAGE_VERSION:  10.0.19041.6216

STACK_COMMAND: .process /r /p 0xffff9886ae3750c0; .thread 0xffff9886aedbd080 ; kb

BUCKET_ID_FUNC_OFFSET:  25

FAILURE_BUCKET_ID:  0xF7_MISSING_GSFRAME_nt!_report_gsfailure

OS_VERSION:  10.0.19041.1

BUILDLAB_STR:  vb_release

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

FAILURE_ID_HASH:  {82d2c1b5-b0cb-60a5-9a5d-78c8c4284f84}
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high.  This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 0000000000000001, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000001, bitfield :
    bit 0 : value 0 = read operation, 1 = write operation
    bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff8041b6a724e, address which referenced memory

Debugging Details:
------------------


KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.mSec
    Value: 1187

    Key  : Analysis.Elapsed.mSec
    Value: 42526

    Key  : Analysis.IO.Other.Mb
    Value: 0

    Key  : Analysis.IO.Read.Mb
    Value: 1

    Key  : Analysis.IO.Write.Mb
    Value: 23

    Key  : Analysis.Init.CPU.mSec
    Value: 406

    Key  : Analysis.Init.Elapsed.mSec
    Value: 38064

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 91

    Key  : Analysis.Version.DbgEng
    Value: 10.0.27871.1001

    Key  : Analysis.Version.Description
    Value: 10.2505.01.02 amd64fre

    Key  : Analysis.Version.Ext
    Value: 1.2505.1.2

    Key  : Bugcheck.Code.LegacyAPI
    Value: 0xa

    Key  : Bugcheck.Code.TargetModel
    Value: 0xa

    Key  : Failure.Bucket
    Value: AV_nt!KiPageFault

    Key  : Failure.Hash
    Value: {ec3e2762-48ae-ffe9-5b16-fbcb853e8320}

    Key  : WER.OS.Branch
    Value: vb_release

    Key  : WER.OS.Version
    Value: 10.0.19041.1


BUGCHECK_CODE:  a

BUGCHECK_P1: 1

BUGCHECK_P2: 2

BUGCHECK_P3: 1

BUGCHECK_P4: fffff8041b6a724e

FILE_IN_CAB:  081625-8000-01.dmp

FAULTING_THREAD:  ffff8a0b1746e080

WORKER_ROUTINE:
+0
00000000`00000001 ??              ???

WORK_ITEM:  fffff8041b6a724e

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  AsusS

STACK_TEXT: 
ffffd28d`9b636c08 fffff804`1b811da9     : 00000000`0000000a 00000000`00000001 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
ffffd28d`9b636c10 fffff804`1b80d778     : 00000000`00000000 00000000`00000001 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
ffffd28d`9b636d50 fffff804`1b6a724e     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x478
ffffd28d`9b636ee0 fffff804`1b6a6e72     : 80000000`00000003 80000000`00000008 8a000000`00000000 00000000`00000000 : nt!MiInsertPageInList+0x3be
ffffd28d`9b636f80 fffff804`1b6a5c65     : 00000000`833cc8c0 80000000`00000000 00000000`00000006 00000000`00000000 : nt!MiPfnShareCountIsZero+0x652
ffffd28d`9b636fe0 fffff804`1b6b1e1f     : ffff8a0b`02930b00 00000000`00003000 ffff8a0b`0f3a4bb0 00000000`00000001 : nt!MiMakePageAvoidRead+0x1565
ffffd28d`9b637160 fffff804`1b6b271c     : ffff9f05`4ca03000 00000174`7f1692c0 ffffd28d`00000000 00000000`00001000 : nt!MmCopyToCachedPage+0x28f
ffffd28d`9b637230 fffff804`1b62ba0a     : ffff8a0b`0f3a4bb0 00000174`7f1692c0 ffffd28d`9b637428 00000000`00000000 : nt!CcMapAndCopyInToCache+0x41c
ffffd28d`9b6373d0 fffff804`1f6ecb3c     : ffffd28d`9b637540 00000000`00001000 00000000`00004000 00000000`00001000 : nt!CcCopyWriteEx+0xea
ffffd28d`9b637450 fffff804`193c783b     : 00000000`00000000 ffffd28d`9b637868 ffffd28d`9b637828 00000174`7f1692c0 : Ntfs!NtfsCopyWriteA+0x5fc
ffffd28d`9b637780 fffff804`193c464a     : ffffd28d`9b637890 ffffd28d`9b637828 ffff8a0b`168cfae0 ffff8a0b`168cf9e0 : FLTMGR!FltpPerformFastIoCall+0x16b
ffffd28d`9b6377e0 fffff804`193f9525     : ffffd28d`9b638000 ffffd28d`9b632000 00000000`00000001 ffffd28d`9b637978 : FLTMGR!FltpPassThroughFastIo+0x10a
ffffd28d`9b637860 fffff804`1b9cecaf     : ffffd28d`9b637901 ffff8a0b`1746e080 00000000`00000000 00000000`00000000 : FLTMGR!FltpFastIoWrite+0x165
ffffd28d`9b637910 fffff804`1bac92b0     : ffff8a0b`198dac00 00000000`00000000 00000000`00000000 00000000`00000000 : nt!IopWriteFile+0x137
ffffd28d`9b637a10 fffff804`1b811508     : ffffd28d`9b637b80 00000009`531be568 00000009`531be638 00000009`531be308 : nt!NtWriteFile+0xd0
ffffd28d`9b637a90 00007ff8`4620d5f4     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
00000009`531be548 00000000`00000000     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff8`4620d5f4


SYMBOL_NAME:  nt!KiPageFault+478

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

IMAGE_VERSION:  10.0.19041.6216

STACK_COMMAND: .process /r /p 0xffff8a0b144670c0; .thread 0xffff8a0b1746e080 ; kb

BUCKET_ID_FUNC_OFFSET:  478

FAILURE_BUCKET_ID:  AV_nt!KiPageFault

OS_VERSION:  10.0.19041.1

BUILDLAB_STR:  vb_release

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

FAILURE_ID_HASH:  {ec3e2762-48ae-ffe9-5b16-fbcb853e8320}

Followup:     MachineOwner
---------

[SMBIOS Data Tables v3.2]
[DMI Version - 0]
[2.0 Calling Convention - No]
[Table Size - 1847 bytes]

[BIOS Information (Type 0) - Length 26 - Handle 0000h]
  Vendor                        American Megatrends International, LLC.
  BIOS Version                  G513IH.329
  BIOS Starting Address Segment f000
  BIOS Release Date             03/01/2023
  BIOS ROM Size                 1000000
  BIOS Characteristics
       07: - PCI Supported
       11: - Upgradeable FLASH BIOS
       12: - BIOS Shadowing Supported
       15: - CD-Boot Supported
       16: - Selectable Boot Supported
       17: - BIOS ROM Socketed
       19: - EDD Supported
       23: - 1.2MB Floppy Supported
       24: - 720KB Floppy Supported
       25: - 2.88MB Floppy Supported
       26: - Print Screen Device Supported
       28: - Serial Services Supported
       29: - Printer Services Supported
       32: - BIOS Vendor Reserved
  BIOS Characteristic Extensions
       00: - ACPI Supported
       01: - USB Legacy Supported
       08: - BIOS Boot Specification Supported
       10: - Enable Targeted Content Distribution
       11: - UEFI Specification Supported
  BIOS Major Revision           5
  BIOS Minor Revision           16
  EC Firmware Major Revision    0
  EC Firmware Minor Revision    80
  Extended BIOS ROM Size        16 MB
[System Information (Type 1) - Length 27 - Handle 0001h]
  Manufacturer                  ASUSTeK COMPUTER INC.
  Product Name                  ROG Strix G513IH_G513IH
  Version                       1.0
  Serial Number                 MBNRKD01857645G
  UUID                          00000000-0000-0000-0000-000000000000
  Wakeup Type                   Power Switch
  SKUNumber                     
  Family                        ROG Strix
[BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
  Manufacturer                  ASUSTeK COMPUTER INC.
  Product                       G513IH
  Version                       1.0
  Serial Number                 D81YMC004Y     
  Asset Tag                                         
  Feature Flags                 09h
       00: - Motherboard
       03: - Replaceable
  Location                      Default string
  Chassis Handle                0003h
  Board Type                    0ah - Processor/Memory Module
  Number of Child Handles       0
[System Enclosure (Type 3) - Length 22 - Handle 0003h]
  Manufacturer                  ASUSTeK COMPUTER INC.
  Chassis Type                  Notebook
  Version                       1.0
  Serial Number                               
  Asset Tag Number                             
  Bootup State                  Safe
  Power Supply State            Safe
  Thermal State                 Safe
  Security Status               None
  OEM Defined                   0
  Height                        0U
  Number of Power Cords         1
  Number of Contained Elements  0
  Contained Element Size        3
[Onboard Devices Information (Type 10) - Length 6 - Handle 0004h]
Note: The On Board Device Information (Type 10) struct is obsolete as of SMBIOs spec v2.6  Number of Devices             1
  01: Type                      Video [enabled]
  01: Description                  To Be Filled By O.E.M.
[OEM Strings (Type 11) - Length 5 - Handle 0005h]
  Number of Strings             5
   1                             
   2                             
   3                             
   4                             
   5                            90NR07P1-M00450
[System Configuration Options (Type 12) - Length 5 - Handle 0006h]
[ (Type 256) - Length 31 - Handle 0008h]
[32Bit Memory Error Information (Type 18) - Length 23 - Handle 0009h]
[Physical Memory Array (Type 16) - Length 23 - Handle 000ah]
  Location                      03h - SystemBoard/Motherboard
  Use                           03h - System Memory
  Memory Error Correction       03h - None
  Maximum Capacity              33554432KB
  Memory Error Inf Handle       0009h
  Number of Memory Devices      2
[Memory Array Mapped Address (Type 19) - Length 31 - Handle 000bh]
  Starting Address              00000000h
  Ending Address                007fffffh
  Memory Array Handle           000ah
  Partition Width               01
  Extended Starting Address     0000000000000000h
  Extended Ending Address       0000000000000000h
[Cache Information (Type 7) - Length 27 - Handle 000ch]
  Socket Designation            L1 - Cache
  Cache Configuration           0180h - WBEnabled Int NonSocketed L1
  Maximum Cache Size            0200h - 512K
  Installed Size                0200h - 512K
  Supported SRAM Type           0010h - Pipeline-Burst
  Current SRAM Type             0010h - Pipeline-Burst
  Cache Speed                   1ns
  Error Correction Type         Specification Reserved
  System Cache Type             Unified
  Associativity                 8-way Set-Associative
  Maximum Cache Size 2          200 - 00000512l Kb
  Installed Cache Size 2        200 - 00000512l Kb
[Cache Information (Type 7) - Length 27 - Handle 000dh]
  Socket Designation            L2 - Cache
  Cache Configuration           0181h - WBEnabled Int NonSocketed L2
  Maximum Cache Size            1000h - 4096K
  Installed Size                1000h - 4096K
  Supported SRAM Type           0010h - Pipeline-Burst
  Current SRAM Type             0010h - Pipeline-Burst
  Cache Speed                   1ns
  Error Correction Type         Specification Reserved
  System Cache Type             Unified
  Associativity                 8-way Set-Associative
  Maximum Cache Size 2          1000 - 00004096l Kb
  Installed Cache Size 2        1000 - 00004096l Kb
[Cache Information (Type 7) - Length 27 - Handle 000eh]
  Socket Designation            L3 - Cache
  Cache Configuration           0182h - WBEnabled Int NonSocketed L3
  Maximum Cache Size            2000h - 8192K
  Installed Size                2000h - 8192K
  Supported SRAM Type           0010h - Pipeline-Burst
  Current SRAM Type             0010h - Pipeline-Burst
  Cache Speed                   1ns
  Error Correction Type         Specification Reserved
  System Cache Type             Unified
  Associativity                 16-way Set-Associative
  Maximum Cache Size 2          2000 - 00008192l Kb
  Installed Cache Size 2        2000 - 00008192l Kb
[Processor Information (Type 4) - Length 48 - Handle 000fh]
  Socket Designation            FP6
  Processor Type                Central Processor
  Processor Family              6bh - AMD Zen Processor Family
  Processor Manufacturer        Advanced Micro Devices, Inc.
  Processor ID                   10f8600fffb8b17
  Processor Version             AMD Ryzen 7 4800H with Radeon Graphics         
  Processor Voltage             8ch - 1.2V
  External Clock                100MHz
  Max Speed                     4300MHz
  Current Speed                 2900MHz
  Status                        Enabled Populated
  Processor Upgrade             None
  L1 Cache Handle               000ch
  L2 Cache Handle               000dh
  L3 Cache Handle               000eh
  Serial Number                       
  Asset Tag Number                     
  Part Number                   Unknown
  Core Count                    8
  Core Enabled                  8
  Thread Count                  16
  Processor Characteristics     fc
  Enabled Characteristics:
       0x 2: 64-bit Capable
       0x 3: Multi-Core
       0x 4: Hardware Thread
       0x 5: Execute Protection
       0x 6: Enhanced Virtualization
       0x 7: Power/Performance Control
  Processor Family 2            006bh - AMD Zen Processor Family
  Core Count 2                  8
  Core Enabled 2                8
  Thread Count 2                16
[32Bit Memory Error Information (Type 18) - Length 23 - Handle 0010h]
[Memory Device (Type 17) - Length 84 - Handle 0011h]
  Memory Error Info Handle      0010h
  Total Width                   64 bits
  Data Width                    64 bits
  Size                          8192MB
  Form Factor                   0dh - SODIMM
  Device Set                    [None]
  Device Locator                DIMM 0
  Bank Locator                  P0 CHANNEL A
  Memory Type                   1ah - DDR4
  Type Detail                   4080h - Synchronous Unbuffered (Unregistered)
  Speed                         3200MHz
  Manufacturer                  Micron Technology
  Serial Number                         
  Asset Tag Number              [String Not Specified]
  Part Number                   4ATF1G64HZ-3G2E2   
  Attributes                    1
  Extended Size                 0
  Configured Memory Speed       3200
  Minimum Voltage               1200
  Maximum Voltage               1200
  Configured Voltage            1200
  Memory Technology             3
  Memory Operating Mode Capability     8
  Firmware Version              6
  Module Manufacturer Id        11392
  Module Product Id             0
  Memory Subsystem Controller Manufacturer Id  0
  Memory Subsystem Controller Product Id       0
  Non-Volatile Size             0
  Volatile Size                 0
  Cache Size                    0
  Logical Size                  0
[Memory Device Mapped Address (Type 20) - Length 35 - Handle 0012h]
  Starting Address              00000000h
  Ending Address                007fffffh
  Memory Device Handle          0011h
  Mem Array Mapped Adr Handle   000bh
  Partition Row Position        [Unknown]
  Interleave Position           [None]
  Interleave Data Depth         [None]
  Extended Starting Address     0000000000000000h
  Extended Ending Address       0000000000000000h
[32Bit Memory Error Information (Type 18) - Length 23 - Handle 0013h]
[Memory Device (Type 17) - Length 84 - Handle 0014h]
  Memory Error Info Handle      0013h
  Total Width                   [Unknown]
  Data Width                    [Unknown]
  Size                          [Not Populated]
  Form Factor                   02h - Unknown
  Device Set                    [None]
  Device Locator                DIMM 0
  Bank Locator                  P0 CHANNEL B
  Memory Type                   02h - Unknown
  Type Detail                   0004h - Unknown
  Speed                         0MHz
  Manufacturer                  Unknown
  Serial Number                       
  Asset Tag Number              [String Not Specified]
  Part Number                   Unknown
  Attributes                    0
  Extended Size                 0
  Configured Memory Speed       0
  Minimum Voltage               0
  Maximum Voltage               0
  Configured Voltage            0
  Memory Technology             2
  Memory Operating Mode Capability     4
  Firmware Version              6
  Module Manufacturer Id        0
  Module Product Id             0
  Memory Subsystem Controller Manufacturer Id  0
  Memory Subsystem Controller Product Id       0
  Non-Volatile Size             0
  Volatile Size                 0
  Cache Size                    0
  Logical Size                  0
[ (Type 256) - Length 11 - Handle 0030h]
[ (Type 256) - Length 11 - Handle 0031h]
[ (Type 256) - Length 4 - Handle 0033h]
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced.  This cannot be protected by try-except.
Typically the address is just plain bad or it is pointing at freed memory.
Arguments:
Arg1: ffff950d56505c10, memory referenced.
Arg2: 0000000000000011, X64: bit 0 set if the fault was due to a not-present PTE.
    bit 1 is set if the fault was due to a write, clear if a read.
    bit 3 is set if the processor decided the fault was due to a corrupted PTE.
    bit 4 is set if the fault was due to attempted execute of a no-execute PTE.
    - ARM64: bit 1 is set if the fault was due to a write, clear if a read.
    bit 3 is set if the fault was due to attempted execute of a no-execute PTE.
Arg3: ffff950d56505c10, If non-zero, the instruction address which referenced the bad memory
    address.
Arg4: 0000000000000002, (reserved)

Debugging Details:
------------------

*** WARNING: Unable to verify timestamp for WdFilter.sys
*** WARNING: Unable to verify timestamp for amdfendr.sys

KEY_VALUES_STRING: 1

    Key  : AV.PTE
    Value: Valid

    Key  : AV.Type
    Value: Execute

    Key  : Analysis.CPU.mSec
    Value: 1343

    Key  : Analysis.Elapsed.mSec
    Value: 35613

    Key  : Analysis.IO.Other.Mb
    Value: 0

    Key  : Analysis.IO.Read.Mb
    Value: 1

    Key  : Analysis.IO.Write.Mb
    Value: 21

    Key  : Analysis.Init.CPU.mSec
    Value: 531

    Key  : Analysis.Init.Elapsed.mSec
    Value: 58913

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 86

    Key  : Analysis.Version.DbgEng
    Value: 10.0.27871.1001

    Key  : Analysis.Version.Description
    Value: 10.2505.01.02 amd64fre

    Key  : Analysis.Version.Ext
    Value: 1.2505.1.2

    Key  : Bugcheck.Code.LegacyAPI
    Value: 0x50

    Key  : Bugcheck.Code.TargetModel
    Value: 0x50

    Key  : Failure.Bucket
    Value: AV_X_(null)_WdFilter!unknown_function

    Key  : Failure.Exception.IP.Address
    Value: 0xffff950d56505c10

    Key  : Failure.Hash
    Value: {2466b939-761d-7888-7d7b-3981f617c641}

    Key  : WER.OS.Branch
    Value: vb_release

    Key  : WER.OS.Version
    Value: 10.0.19041.1


BUGCHECK_CODE:  50

BUGCHECK_P1: ffff950d56505c10

BUGCHECK_P2: 11

BUGCHECK_P3: ffff950d56505c10

BUGCHECK_P4: 2

FILE_IN_CAB:  081425-22218-01.dmp

FAULTING_THREAD:  ffff950d4bdd7040

WRITE_ADDRESS: fffff8011dcfb390: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
unable to get nt!MmSpecialPagesInUse
 ffff950d56505c10

MM_INTERNAL_CODE:  2

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  System

LOCK_ADDRESS:  fffff8011dc44be0 -- (!locks fffff8011dc44be0)
Cannot get _ERESOURCE Flag field
Unexpected resource format: 0
1 total locks

PNP_TRIAGE_DATA:
    Lock address  : 0xfffff8011dc44be0
    Thread Count  : 0
    Thread address: 0x0000000000000000
    Thread wait   : 0x0

STACK_TEXT: 
ffffcf8a`edba0808 fffff801`1d448b23     : 00000000`00000050 ffff950d`56505c10 00000000`00000011 ffffcf8a`edba0ab0 : nt!KeBugCheckEx
ffffcf8a`edba0810 fffff801`1d20d450     : 00000000`00000000 00000000`00000011 ffffcf8a`edba0b30 00000000`00000000 : nt!MiSystemFault+0x1b70a3
ffffcf8a`edba0910 fffff801`1d40d66d     : ffff950d`00000000 00000000`00000000 ffff950d`561caa20 ffffcf8a`edba0e40 : nt!MmAccessFault+0x400
ffffcf8a`edba0ab0 ffff950d`56505c10     : fffff801`1d2cbc09 00000000`00040293 fffff801`1d2d0cbb 00000000`ffffffff : nt!KiPageFault+0x36d
ffffcf8a`edba0c48 fffff801`1d2cbc09     : 00000000`00040293 fffff801`1d2d0cbb 00000000`ffffffff ffffad01`00000000 : 0xffff950d`56505c10
ffffcf8a`edba0c50 fffff801`1bf9a478     : ffffcf8a`edba0e68 ffff950d`4b8145e0 ffffcf8a`edba0d58 00000000`00000000 : nt!ExReleaseResourceLite+0x109
ffffcf8a`edba0cb0 fffff801`1bf9a3fd     : ffff950d`566d30f8 ffffcf8a`edba0d88 ffff950d`4b2a0a20 00000000`00000009 : FLTMGR!FltSetEcpListIntoCallbackData+0x58
ffffcf8a`edba0ce0 fffff801`21f5a7ea     : 00000000`0000004f ffffad01`5871c188 ffffad01`58764690 ffffad01`58733530 : FLTMGR!FltRequestFileInfoOnCreateCompletion+0x11d
ffffcf8a`edba0d20 00000000`0000004f     : ffffad01`5871c188 ffffad01`58764690 ffffad01`58733530 00000000`00000170 : WdFilter+0x2a7ea
ffffcf8a`edba0d28 ffffad01`5871c188     : ffffad01`58764690 ffffad01`58733530 00000000`00000170 00000000`00000090 : 0x4f
ffffcf8a`edba0d30 ffffad01`58764690     : ffffad01`58733530 00000000`00000170 00000000`00000090 ffff950d`566d3198 : 0xffffad01`5871c188
ffffcf8a`edba0d38 ffffad01`58733530     : 00000000`00000170 00000000`00000090 ffff950d`566d3198 fffff801`1bf66e12 : 0xffffad01`58764690
ffffcf8a`edba0d40 00000000`00000170     : 00000000`00000090 ffff950d`566d3198 fffff801`1bf66e12 00000000`1000000c : 0xffffad01`58733530
ffffcf8a`edba0d48 00000000`00000090     : ffff950d`566d3198 fffff801`1bf66e12 00000000`1000000c ffff950d`561cacb0 : 0x170
ffffcf8a`edba0d50 ffff950d`566d3198     : fffff801`1bf66e12 00000000`1000000c ffff950d`561cacb0 ffffcf8a`edba0f80 : 0x90
ffffcf8a`edba0d58 fffff801`1bf66e12     : 00000000`1000000c ffff950d`561cacb0 ffffcf8a`edba0f80 ffff950d`566d3090 : 0xffff950d`566d3198
ffffcf8a`edba0d60 fffff801`1bf664cb     : 00000000`00000000 ffff950d`00000000 ffff950d`00000000 ffff950d`561cacb0 : FLTMGR!FltpLinkCompletionNodeToInstance+0x112
ffffcf8a`edba0dd0 fffff801`1bf65f7a     : ffffcf8a`edba0f00 fffff801`1bf67c00 00000000`00000000 00000000`00000000 : FLTMGR!FltpPerformPreCallbacksWorker+0x36b
ffffcf8a`edba0ef0 fffff801`1bf99ed0     : ffffcf8a`edba2000 ffffcf8a`edb9c000 ffff950d`4b3b2d60 00000000`00000000 : FLTMGR!FltpPassThroughInternal+0xca
ffffcf8a`edba0f40 fffff801`1d2d21c5     : ffff950d`00000000 ffff950d`4b4cd930 00000000`00000000 00000000`00000000 : FLTMGR!FltpCreate+0x310
ffffcf8a`edba0ff0 fffff801`1d2d4084     : ffff950d`5676ca20 fffff801`1d9b418e ffff950d`4b4cd930 fffff801`1d2d3cb3 : nt!IofCallDriver+0x55
ffffcf8a`edba1030 fffff801`1d64f829     : ffffcf8a`edba12e0 ffff950d`4b4cd930 ffff950d`5676cab8 00000000`56700001 : nt!IoCallDriverWithTracing+0x34
ffffcf8a`edba1080 fffff801`1d642757     : ffff950d`4b4cd930 ffff950d`4b4cd900 ffff950d`5670fa20 ffffad01`584bda00 : nt!IopParseDevice+0x11a9
ffffcf8a`edba11e0 fffff801`1d6cec8a     : ffff950d`5670fa01 ffffcf8a`edba1448 00000000`00000240 ffff950d`455c3400 : nt!ObpLookupObjectName+0x1117
ffffcf8a`edba13b0 fffff801`1d60c431     : ffff950d`00000000 ffffcf8a`edba1880 ffffcf8a`edba1870 00000000`00000000 : nt!ObOpenObjectByNameEx+0x1fa
ffffcf8a`edba14e0 fffff801`1d60b878     : ffffcf8a`edba18d0 ffff950d`00100001 ffffcf8a`edba1880 ffffcf8a`edba1870 : nt!IopCreateFile+0xb11
ffffcf8a`edba1590 fffff801`1d411508     : ffff950d`00000000 ffff950d`5676c140 00000000`0000009e 00000000`00000000 : nt!NtOpenFile+0x58
ffffcf8a`edba1620 fffff801`1d402300     : fffff801`1d89f4bb ffff950d`456cae30 fffff801`1d5ee514 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
ffffcf8a`edba1828 fffff801`1d89f4bb     : ffff950d`456cae30 fffff801`1d5ee514 00000000`00000000 00000000`00000000 : nt!KiServiceLinkage
ffffcf8a`edba1830 fffff801`1d89ecbe     : ffffcf8a`edba1970 00000000`00000000 00000000`00000000 ffffcf8a`edba1920 : nt!PiGetDriverImageDirectory+0xf7
ffffcf8a`edba18c0 fffff801`87877fd4     : 00000000`00000000 ffffcf8a`edba1970 00000000`00000000 fffff801`878970f0 : nt!IoGetDriverDirectory+0x6e
ffffcf8a`edba18f0 00000000`00000000     : ffffcf8a`edba1970 00000000`00000000 fffff801`878970f0 ffff950d`557c8edb : amdfendr+0x17fd4


SYMBOL_NAME:  WdFilter+2a7ea

MODULE_NAME: WdFilter

IMAGE_NAME:  WdFilter.sys

STACK_COMMAND: .process /r /p 0xffff950d454fb240; .thread 0xffff950d4bdd7040 ; kb

BUCKET_ID_FUNC_OFFSET:  2a7ea

FAILURE_BUCKET_ID:  AV_X_(null)_WdFilter!unknown_function

OS_VERSION:  10.0.19041.1

BUILDLAB_STR:  vb_release

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

FAILURE_ID_HASH:  {2466b939-761d-7888-7d7b-3981f617c641}
 
Windows Defender (MsMpEng.exe) → bir sürücü (muhtemelen üçüncü parti ya da eski AMD/ASUS bileşeni) ile çalışırken stack buffer overflow yaratmış.

Call stack içinde amdfendr.sys de geçiyor. Bu dosya AMD’nin Endpoint Security Driver’ı (AMD chipset veya güvenlik yazılımı ile ilgili) olabilir. Windows Defender ile bu sürücü arasında çakışma yaşanıyor olabilir.

Windows 11'e geçince sorunlar çözüldü mü?

Kod:
KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common BugCheck.  Usually the exception address pinpoints
the driver/function that caused the problem.  Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff8001a0e6bde, The address that the exception occurred at
Arg3: 0000000000000001, Parameter 0 of the exception
Arg4: 0000000001b00874, Parameter 1 of the exception

Debugging Details:
------------------

*** WARNING: Unable to verify timestamp for gameflt.sys
*************************************************************************
***                                                                   ***
***                                                                   ***
***    Either you specified an unqualified symbol, or your debugger   ***
***    doesn't have full symbol information.  Unqualified symbol      ***
***    resolution is turned off by default. Please either specify a   ***
***    fully qualified symbol module!symbolname, or enable resolution ***
***    of unqualified symbols by typing ".symopt- 100". Note that     ***
***    enabling unqualified symbol resolution with network symbol     ***
***    server shares in the symbol path may cause the debugger to     ***
***    appear to hang for long periods of time when an incorrect      ***
***    symbol name is typed or the network symbol server is down.     ***
***                                                                   ***
***    For some commands to work properly, your symbol path           ***
***    must point to .pdb files that have full type information.      ***
***                                                                   ***
***    Certain .pdb files (such as the public OS symbols) do not      ***
***    contain the required information.  Contact the group that      ***
***    provided you with these symbols if you need this command to    ***
***    work.                                                          ***
***                                                                   ***
***    Type referenced: ExceptionRecord                               ***
***                                                                   ***
*************************************************************************
*************************************************************************
***                                                                   ***
***                                                                   ***
***    Either you specified an unqualified symbol, or your debugger   ***
***    doesn't have full symbol information.  Unqualified symbol      ***
***    resolution is turned off by default. Please either specify a   ***
***    fully qualified symbol module!symbolname, or enable resolution ***
***    of unqualified symbols by typing ".symopt- 100". Note that     ***
***    enabling unqualified symbol resolution with network symbol     ***
***    server shares in the symbol path may cause the debugger to     ***
***    appear to hang for long periods of time when an incorrect      ***
***    symbol name is typed or the network symbol server is down.     ***
***                                                                   ***
***    For some commands to work properly, your symbol path           ***
***    must point to .pdb files that have full type information.      ***
***                                                                   ***
***    Certain .pdb files (such as the public OS symbols) do not      ***
***    contain the required information.  Contact the group that      ***
***    provided you with these symbols if you need this command to    ***
***    work.                                                          ***
***                                                                   ***
***    Type referenced: ContextRecord                                 ***
***                                                                   ***
*************************************************************************

KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.mSec
    Value: 1437

    Key  : Analysis.Elapsed.mSec
    Value: 40943

    Key  : Analysis.IO.Other.Mb
    Value: 0

    Key  : Analysis.IO.Read.Mb
    Value: 1

    Key  : Analysis.IO.Write.Mb
    Value: 21

    Key  : Analysis.Init.CPU.mSec
    Value: 359

    Key  : Analysis.Init.Elapsed.mSec
    Value: 39581

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 86

    Key  : Analysis.Version.DbgEng
    Value: 10.0.27871.1001

    Key  : Analysis.Version.Description
    Value: 10.2505.01.02 amd64fre

    Key  : Analysis.Version.Ext
    Value: 1.2505.1.2

    Key  : Bugcheck.Code.LegacyAPI
    Value: 0x1e

    Key  : Bugcheck.Code.TargetModel
    Value: 0x1e

    Key  : Failure.Bucket
    Value: AV_W_luafv!LuafvGenerateFileName

    Key  : Failure.Exception.IP.Address
    Value: 0xfffff8001a0e6bde

    Key  : Failure.Exception.IP.Module
    Value: nt

    Key  : Failure.Exception.IP.Offset
    Value: 0x2e6bde

    Key  : Failure.Hash
    Value: {44fbb93c-33d5-d277-f5f4-25d404fd224d}

    Key  : WER.OS.Branch
    Value: vb_release

    Key  : WER.OS.Version
    Value: 10.0.19041.1


BUGCHECK_CODE:  1e

BUGCHECK_P1: ffffffffc0000005

BUGCHECK_P2: fffff8001a0e6bde

BUGCHECK_P3: 1

BUGCHECK_P4: 1b00874

FILE_IN_CAB:  081525-9703-01.dmp

FAULTING_THREAD:  ffffc40f17f4a080

EXCEPTION_PARAMETER1:  0000000000000001

EXCEPTION_PARAMETER2:  0000000001b00874

WRITE_ADDRESS: fffff8001aafb390: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
unable to get nt!MmSpecialPagesInUse
 0000000001b00874

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  svchost.exe

TRAP_FRAME:  ffff800000000000 -- (.trap 0xffff800000000000)
Unable to read trap frame at ffff8000`00000000
Resetting default scope

STACK_TEXT: 
ffffef84`d91801a8 fffff800`1a27f1f3     : 00000000`0000001e ffffffff`c0000005 fffff800`1a0e6bde 00000000`00000001 : nt!KeBugCheckEx
ffffef84`d91801b0 fffff800`1a211eec     : 00000000`00001000 ffffef84`d9180a50 ffff8000`00000000 00000000`00000000 : nt!KiDispatchException+0x142ec3
ffffef84`d9180870 fffff800`1a20d752     : 00000000`00000000 00000000`00000000 ffffc40f`0b2e4420 fffff800`1a0c43e5 : nt!KiExceptionDispatch+0x12c
ffffef84`d9180a50 fffff800`1a0e6bde     : 00000000`31526d73 fffff800`1a0bc86f ffffc40f`1767cf20 00000000`00000000 : nt!KiPageFault+0x452
ffffef84`d9180be0 fffff800`1a05a4fc     : 00000000`00000000 ffffef84`d9180c20 00000000`00000001 ffffc40f`192b3648 : nt!SepIsSModeEnabled+0x3e
ffffef84`d9180c20 fffff800`15fe41fb     : 00000000`00000012 ffffef84`d9180d18 ffffc40f`19127850 00000000`00000101 : nt!KeAreAllApcsDisabled+0x1c
ffffef84`d9180c50 fffff800`5ef3f8d0     : ffffc40f`17ae5980 ffffc40f`1453f320 00000000`00000000 ffffc40f`191c1501 : FLTMGR!FltGetFileNameInformation+0xeb
ffffef84`d9180ce0 fffff800`160186ab     : ffffc40f`191c15a0 00000000`00000000 ffffc40f`1453f320 fffff800`1a0d0c08 : luafv!LuafvGenerateFileName+0x60
ffffef84`d9180d10 fffff800`16018deb     : ffffc40f`17ae8700 ffffc40f`17ae8730 ffffc40f`17ae8730 fffff800`1a0cbbf3 : FLTMGR!FltpGetNormalizedFileNameWorker+0x18b
ffffef84`d9180d90 fffff800`15fe366f     : ffffc40f`191c15e0 ffffef84`d9181000 ffffef84`d917b000 fffff800`16008060 : FLTMGR!FltpCreateFileNameInformation+0x2eb
ffffef84`d9180e10 fffff800`15fe4211     : 00000000`00008000 ffffef84`ffff7fff ffffc40f`191c15a0 ffffc40f`15e1b010 : FLTMGR!FltpGetFileNameInformation+0x6ef
ffffef84`d9180ec0 fffff800`ad331efa     : ffffc40f`17ae8730 ffffef84`d9699580 ffffef84`d9699400 ffffc40f`17f4a080 : FLTMGR!FltGetFileNameInformation+0x101
ffffef84`d9180f50 ffffc40f`17ae8730     : ffffef84`d9699580 ffffef84`d9699400 ffffc40f`17f4a080 ffffef84`d9180fd0 : gameflt+0x1efa
ffffef84`d9180f58 ffffef84`d9699580     : ffffef84`d9699400 ffffc40f`17f4a080 ffffef84`d9180fd0 fffff800`1a201d7e : 0xffffc40f`17ae8730
ffffef84`d9180f60 ffffef84`d9699400     : ffffc40f`17f4a080 ffffef84`d9180fd0 fffff800`1a201d7e ffffef84`d5fa2b90 : 0xffffef84`d9699580
ffffef84`d9180f68 ffffc40f`17f4a080     : ffffef84`d9180fd0 fffff800`1a201d7e ffffef84`d5fa2b90 00000000`00000000 : 0xffffef84`d9699400
ffffef84`d9180f70 ffffef84`d9180fd0     : fffff800`1a201d7e ffffef84`d5fa2b90 00000000`00000000 00000000`00000000 : 0xffffc40f`17f4a080
ffffef84`d9180f78 fffff800`1a201d7e     : ffffef84`d5fa2b90 00000000`00000000 00000000`00000000 00000038`dd98d300 : 0xffffef84`d9180fd0
ffffef84`d9180f80 fffff800`1a201d3c     : ffffef84`d9180fd0 ffffc40f`17f4a080 ffffef84`d9181000 fffff800`1a0aaa5d : nt!KxSwitchKernelStackCallout+0x2e
ffffef84`d9699370 fffff800`1a0aaa5d     : ffffef84`d9180fd0 ffffc40f`17f4a080 ffffef84`d9699400 00000000`00000000 : nt!KiSwitchKernelStackContinue
ffffef84`d9699390 fffff800`1a0aa852     : fffff800`ad331ee0 ffffef84`d9699580 ffffd785`00000002 00000000`00000000 : nt!KiExpandKernelStackAndCalloutOnStackSegment+0x19d
ffffef84`d9699430 fffff800`1a0aa6b3     : ffffef84`d9699600 00000000`00000001 ffffd785`00000000 ffffc40f`192b35e0 : nt!KiExpandKernelStackAndCalloutSwitchStack+0xf2
ffffef84`d96994a0 fffff800`1a0aa66d     : fffff800`ad331ee0 ffffef84`d9699580 ffffc40f`192b3648 ffffc40f`0b457180 : nt!KeExpandKernelStackAndCalloutInternal+0x33
ffffef84`d9699510 fffff800`ad331ed4     : ffffc40f`17f4a080 ffffc40f`1453f3a0 00000000`00000003 00000000`00000003 : nt!KeExpandKernelStackAndCalloutEx+0x1d
ffffef84`d9699550 ffffc40f`17f4a080     : ffffc40f`1453f3a0 00000000`00000003 00000000`00000003 00000000`00000000 : gameflt+0x1ed4
ffffef84`d9699558 ffffc40f`1453f3a0     : 00000000`00000003 00000000`00000003 00000000`00000000 ffffc40f`1453f320 : 0xffffc40f`17f4a080
ffffef84`d9699560 00000000`00000003     : 00000000`00000003 00000000`00000000 ffffc40f`1453f320 00000000`c0000001 : 0xffffc40f`1453f3a0
ffffef84`d9699568 00000000`00000003     : 00000000`00000000 ffffc40f`1453f320 00000000`c0000001 ffffc40f`192b3648 : 0x3
ffffef84`d9699570 00000000`00000000     : ffffc40f`1453f320 00000000`c0000001 ffffc40f`192b3648 00000000`00000101 : 0x3


SYMBOL_NAME:  luafv!LuafvGenerateFileName+60

MODULE_NAME: luafv

IMAGE_NAME:  luafv.sys

IMAGE_VERSION:  10.0.19041.6157

STACK_COMMAND: .process /r /p 0xffffc40f169a0300; .thread 0xffffc40f17f4a080 ; kb

BUCKET_ID_FUNC_OFFSET:  60

FAILURE_BUCKET_ID:  AV_W_luafv!LuafvGenerateFileName

OS_VERSION:  10.0.19041.1

BUILDLAB_STR:  vb_release

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

FAILURE_ID_HASH:  {44fbb93c-33d5-d277-f5f4-25d404fd224d}

DRIVER_OVERRAN_STACK_BUFFER (f7)
A driver has overrun a stack-based buffer.  This overrun could potentially
allow a malicious user to gain control of this machine.
DESCRIPTION
A driver overran a stack-based buffer (or local variable) in a way that would
have overwritten the function's return address and jumped back to an arbitrary
address when the function returned.  This is the classic "buffer overrun"
hacking attack and the system has been brought down to prevent a malicious user
from gaining complete control of it.
Do a kb to get a stack backtrace -- the last routine on the stack before the
buffer overrun handlers and BugCheck call is the one that overran its local
variable(s).
Arguments:
Arg1: ffff820f964ca6b0, Actual security check cookie from the stack
Arg2: 0000ac202ec75943, Expected security check cookie
Arg3: ffff53dfd138a6bc, Complement of the expected security check cookie
Arg4: 0000000000000000, zero

Debugging Details:
------------------


KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.mSec
    Value: 1031

    Key  : Analysis.Elapsed.mSec
    Value: 26940

    Key  : Analysis.IO.Other.Mb
    Value: 0

    Key  : Analysis.IO.Read.Mb
    Value: 1

    Key  : Analysis.IO.Write.Mb
    Value: 1

    Key  : Analysis.Init.CPU.mSec
    Value: 390

    Key  : Analysis.Init.Elapsed.mSec
    Value: 1099

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 76

    Key  : Analysis.Version.DbgEng
    Value: 10.0.27871.1001

    Key  : Analysis.Version.Description
    Value: 10.2505.01.02 amd64fre

    Key  : Analysis.Version.Ext
    Value: 1.2505.1.2

    Key  : Bugcheck.Code.LegacyAPI
    Value: 0xf7

    Key  : Bugcheck.Code.TargetModel
    Value: 0xf7

    Key  : Failure.Bucket
    Value: 0xF7_MISSING_GSFRAME_nt!_report_gsfailure

    Key  : Failure.Hash
    Value: {82d2c1b5-b0cb-60a5-9a5d-78c8c4284f84}

    Key  : Stack.Pointer
    Value: PRCBException

    Key  : WER.OS.Branch
    Value: vb_release

    Key  : WER.OS.Version
    Value: 10.0.19041.1


BUGCHECK_CODE:  f7

BUGCHECK_P1: ffff820f964ca6b0

BUGCHECK_P2: ac202ec75943

BUGCHECK_P3: ffff53dfd138a6bc

BUGCHECK_P4: 0

FILE_IN_CAB:  081225-9453-01.dmp

FAULTING_THREAD:  ffffa9085f87f080

SECURITY_COOKIE:  Expected 0000ac202ec75943 found ffff820f964ca6b0

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  MsMpEng.exe

STACK_TEXT: 
ffff9780`79fbd0f8 fffff807`062b6245     : 00000000`000000f7 ffff820f`964ca6b0 0000ac20`2ec75943 ffff53df`d138a6bc : nt!KeBugCheckEx
ffff9780`79fbd100 fffff807`061d564e     : ffff9780`79fbd710 fffff807`0613ea6f fffff807`05f00108 ffff9780`00000000 : nt!_report_gsfailure+0x25
ffff9780`79fbd140 fffff807`061d55e3     : ffff9780`79fbd210 00000000`00000000 ffff9780`79fbd748 ffff9780`79fbd720 : nt!_GSHandlerCheckCommon+0x5a
ffff9780`79fbd170 fffff807`06207f02     : fffff807`061d55d0 00000000`00000000 00000000`00000000 00000000`00000000 : nt!_GSHandlerCheck+0x13
ffff9780`79fbd1a0 fffff807`0613e857     : ffff9780`79fbd710 00000000`00000000 ffff9780`79fbd920 fffff807`06444245 : nt!RtlpExecuteHandlerForException+0x12
ffff9780`79fbd1d0 fffff807`0613c4f6     : ffff820f`964ca478 ffff9780`79fbde20 ffff820f`964ca478 ffffa908`5ce289f0 : nt!RtlDispatchException+0x297
ffff9780`79fbd8f0 fffff807`061fe522     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDispatchException+0x186
ffff9780`79fbdfb0 fffff807`061fe4f0     : fffff807`06211ce5 00000000`00000000 fffff807`060cff08 ffff8380`b2226df4 : nt!KxExceptionDispatchOnExceptionStack+0x12
ffff820f`964ca338 fffff807`06211ce5     : 00000000`00000000 fffff807`060cff08 ffff8380`b2226df4 ffff8380`b9f9b4f0 : nt!KiExceptionDispatchOnExceptionStackContinue
ffff820f`964ca340 fffff807`0620b778     : ffff820f`964ca7e0 00000000`00000000 ffff820f`964ca601 ffff820f`964ca638 : nt!KiExceptionDispatch+0x125
ffff820f`964ca520 fffff807`06444245     : 00000000`00000000 00000000`00000000 ffff820f`00000001 00000000`00000001 : nt!KiInvalidOpcodeFault+0x338
ffff820f`964ca6b0 00000000`00000000     : ffff2e2f`b88bfe53 000000dd`11bf9e78 00000000`00000000 00000000`00000001 : nt!ObpCreateHandle+0x815


SYMBOL_NAME:  nt!_report_gsfailure+25

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

IMAGE_VERSION:  10.0.19041.6093

STACK_COMMAND: .process /r /p 0xffffa9085d31d080; .thread 0xffffa9085f87f080 ; kb

BUCKET_ID_FUNC_OFFSET:  25

FAILURE_BUCKET_ID:  0xF7_MISSING_GSFRAME_nt!_report_gsfailure

OS_VERSION:  10.0.19041.1

BUILDLAB_STR:  vb_release

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

FAILURE_ID_HASH:  {82d2c1b5-b0cb-60a5-9a5d-78c8c4284f84}
DRIVER_OVERRAN_STACK_BUFFER (f7)
A driver has overrun a stack-based buffer.  This overrun could potentially
allow a malicious user to gain control of this machine.
DESCRIPTION
A driver overran a stack-based buffer (or local variable) in a way that would
have overwritten the function's return address and jumped back to an arbitrary
address when the function returned.  This is the classic "buffer overrun"
hacking attack and the system has been brought down to prevent a malicious user
from gaining complete control of it.
Do a kb to get a stack backtrace -- the last routine on the stack before the
buffer overrun handlers and BugCheck call is the one that overran its local
variable(s).
Arguments:
Arg1: ffffde0a17fe8cb8, Actual security check cookie from the stack
Arg2: 000062f0d893ddb8, Expected security check cookie
Arg3: ffff9d0f276c2247, Complement of the expected security check cookie
Arg4: 0000000000000000, zero

Debugging Details:
------------------


KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.mSec
    Value: 1015

    Key  : Analysis.Elapsed.mSec
    Value: 21835

    Key  : Analysis.IO.Other.Mb
    Value: 0

    Key  : Analysis.IO.Read.Mb
    Value: 1

    Key  : Analysis.IO.Write.Mb
    Value: 21

    Key  : Analysis.Init.CPU.mSec
    Value: 468

    Key  : Analysis.Init.Elapsed.mSec
    Value: 59015

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 76

    Key  : Analysis.Version.DbgEng
    Value: 10.0.27871.1001

    Key  : Analysis.Version.Description
    Value: 10.2505.01.02 amd64fre

    Key  : Analysis.Version.Ext
    Value: 1.2505.1.2

    Key  : Bugcheck.Code.LegacyAPI
    Value: 0xf7

    Key  : Bugcheck.Code.TargetModel
    Value: 0xf7

    Key  : Failure.Bucket
    Value: 0xF7_MISSING_GSFRAME_nt!_report_gsfailure

    Key  : Failure.Hash
    Value: {82d2c1b5-b0cb-60a5-9a5d-78c8c4284f84}

    Key  : Stack.Pointer
    Value: PRCBException

    Key  : WER.OS.Branch
    Value: vb_release

    Key  : WER.OS.Version
    Value: 10.0.19041.1


BUGCHECK_CODE:  f7

BUGCHECK_P1: ffffde0a17fe8cb8

BUGCHECK_P2: 62f0d893ddb8

BUGCHECK_P3: ffff9d0f276c2247

BUGCHECK_P4: 0

FILE_IN_CAB:  081525-9218-01.dmp

FAULTING_THREAD:  ffff9886aedbd080

SECURITY_COOKIE:  Expected 000062f0d893ddb8 found ffffde0a17fe8cb8

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  MsMpEng.exe

STACK_TEXT: 
ffffb881`93dfc0f8 fffff800`742b63b5     : 00000000`000000f7 ffffde0a`17fe8cb8 000062f0`d893ddb8 ffff9d0f`276c2247 : nt!KeBugCheckEx
ffffb881`93dfc100 fffff800`741d56fe     : ffffb881`93dfc710 fffff800`7413ea2f fffff800`73ed035c ffffb881`00000000 : nt!_report_gsfailure+0x25
ffffb881`93dfc140 fffff800`741d5693     : ffffb881`93dfc210 00000000`00000000 ffffb881`93dfc748 ffffb881`93dfc720 : nt!_GSHandlerCheckCommon+0x5a
ffffb881`93dfc170 fffff800`74208052     : fffff800`741d5680 00000000`00000000 00000000`00000000 00000000`00000000 : nt!_GSHandlerCheck+0x13
ffffb881`93dfc1a0 fffff800`7413e817     : ffffb881`93dfc710 00000000`00000000 ffffb881`93dfc920 fffff800`740b57b8 : nt!RtlpExecuteHandlerForException+0x12
ffffb881`93dfc1d0 fffff800`7413c4b6     : ffffde0a`17fe8a78 ffffb881`93dfce20 ffffde0a`17fe8a78 00000000`00000000 : nt!RtlDispatchException+0x297
ffffb881`93dfc8f0 fffff800`741fe672     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDispatchException+0x186
ffffb881`93dfcfb0 fffff800`741fe640     : fffff800`74211ee5 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KxExceptionDispatchOnExceptionStack+0x12
ffffde0a`17fe8938 fffff800`74211ee5     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiExceptionDispatchOnExceptionStackContinue
ffffde0a`17fe8940 fffff800`7420d2ef     : ffffde0a`17fe9068 ffffffff`ffffffff fffff800`74a50d40 00000000`00000000 : nt!KiExceptionDispatch+0x125
ffffde0a`17fe8b20 fffff800`740b57b8     : fffff800`740b636c ffff9886`9d17d000 ffff97cb`c0814380 00000000`00000000 : nt!KiGeneralProtectionFault+0x32f
ffffde0a`17fe8cb8 00000000`00000000     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!MiDecommitPages+0x908


SYMBOL_NAME:  nt!_report_gsfailure+25

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

IMAGE_VERSION:  10.0.19041.6216

STACK_COMMAND: .process /r /p 0xffff9886ae3750c0; .thread 0xffff9886aedbd080 ; kb

BUCKET_ID_FUNC_OFFSET:  25

FAILURE_BUCKET_ID:  0xF7_MISSING_GSFRAME_nt!_report_gsfailure

OS_VERSION:  10.0.19041.1

BUILDLAB_STR:  vb_release

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

FAILURE_ID_HASH:  {82d2c1b5-b0cb-60a5-9a5d-78c8c4284f84}
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high.  This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 0000000000000001, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000001, bitfield :
    bit 0 : value 0 = read operation, 1 = write operation
    bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff8041b6a724e, address which referenced memory

Debugging Details:
------------------


KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.mSec
    Value: 1187

    Key  : Analysis.Elapsed.mSec
    Value: 42526

    Key  : Analysis.IO.Other.Mb
    Value: 0

    Key  : Analysis.IO.Read.Mb
    Value: 1

    Key  : Analysis.IO.Write.Mb
    Value: 23

    Key  : Analysis.Init.CPU.mSec
    Value: 406

    Key  : Analysis.Init.Elapsed.mSec
    Value: 38064

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 91

    Key  : Analysis.Version.DbgEng
    Value: 10.0.27871.1001

    Key  : Analysis.Version.Description
    Value: 10.2505.01.02 amd64fre

    Key  : Analysis.Version.Ext
    Value: 1.2505.1.2

    Key  : Bugcheck.Code.LegacyAPI
    Value: 0xa

    Key  : Bugcheck.Code.TargetModel
    Value: 0xa

    Key  : Failure.Bucket
    Value: AV_nt!KiPageFault

    Key  : Failure.Hash
    Value: {ec3e2762-48ae-ffe9-5b16-fbcb853e8320}

    Key  : WER.OS.Branch
    Value: vb_release

    Key  : WER.OS.Version
    Value: 10.0.19041.1


BUGCHECK_CODE:  a

BUGCHECK_P1: 1

BUGCHECK_P2: 2

BUGCHECK_P3: 1

BUGCHECK_P4: fffff8041b6a724e

FILE_IN_CAB:  081625-8000-01.dmp

FAULTING_THREAD:  ffff8a0b1746e080

WORKER_ROUTINE:
+0
00000000`00000001 ??              ???

WORK_ITEM:  fffff8041b6a724e

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  AsusS

STACK_TEXT:
ffffd28d`9b636c08 fffff804`1b811da9     : 00000000`0000000a 00000000`00000001 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
ffffd28d`9b636c10 fffff804`1b80d778     : 00000000`00000000 00000000`00000001 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
ffffd28d`9b636d50 fffff804`1b6a724e     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x478
ffffd28d`9b636ee0 fffff804`1b6a6e72     : 80000000`00000003 80000000`00000008 8a000000`00000000 00000000`00000000 : nt!MiInsertPageInList+0x3be
ffffd28d`9b636f80 fffff804`1b6a5c65     : 00000000`833cc8c0 80000000`00000000 00000000`00000006 00000000`00000000 : nt!MiPfnShareCountIsZero+0x652
ffffd28d`9b636fe0 fffff804`1b6b1e1f     : ffff8a0b`02930b00 00000000`00003000 ffff8a0b`0f3a4bb0 00000000`00000001 : nt!MiMakePageAvoidRead+0x1565
ffffd28d`9b637160 fffff804`1b6b271c     : ffff9f05`4ca03000 00000174`7f1692c0 ffffd28d`00000000 00000000`00001000 : nt!MmCopyToCachedPage+0x28f
ffffd28d`9b637230 fffff804`1b62ba0a     : ffff8a0b`0f3a4bb0 00000174`7f1692c0 ffffd28d`9b637428 00000000`00000000 : nt!CcMapAndCopyInToCache+0x41c
ffffd28d`9b6373d0 fffff804`1f6ecb3c     : ffffd28d`9b637540 00000000`00001000 00000000`00004000 00000000`00001000 : nt!CcCopyWriteEx+0xea
ffffd28d`9b637450 fffff804`193c783b     : 00000000`00000000 ffffd28d`9b637868 ffffd28d`9b637828 00000174`7f1692c0 : Ntfs!NtfsCopyWriteA+0x5fc
ffffd28d`9b637780 fffff804`193c464a     : ffffd28d`9b637890 ffffd28d`9b637828 ffff8a0b`168cfae0 ffff8a0b`168cf9e0 : FLTMGR!FltpPerformFastIoCall+0x16b
ffffd28d`9b6377e0 fffff804`193f9525     : ffffd28d`9b638000 ffffd28d`9b632000 00000000`00000001 ffffd28d`9b637978 : FLTMGR!FltpPassThroughFastIo+0x10a
ffffd28d`9b637860 fffff804`1b9cecaf     : ffffd28d`9b637901 ffff8a0b`1746e080 00000000`00000000 00000000`00000000 : FLTMGR!FltpFastIoWrite+0x165
ffffd28d`9b637910 fffff804`1bac92b0     : ffff8a0b`198dac00 00000000`00000000 00000000`00000000 00000000`00000000 : nt!IopWriteFile+0x137
ffffd28d`9b637a10 fffff804`1b811508     : ffffd28d`9b637b80 00000009`531be568 00000009`531be638 00000009`531be308 : nt!NtWriteFile+0xd0
ffffd28d`9b637a90 00007ff8`4620d5f4     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
00000009`531be548 00000000`00000000     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff8`4620d5f4


SYMBOL_NAME:  nt!KiPageFault+478

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

IMAGE_VERSION:  10.0.19041.6216

STACK_COMMAND: .process /r /p 0xffff8a0b144670c0; .thread 0xffff8a0b1746e080 ; kb

BUCKET_ID_FUNC_OFFSET:  478

FAILURE_BUCKET_ID:  AV_nt!KiPageFault

OS_VERSION:  10.0.19041.1

BUILDLAB_STR:  vb_release

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

FAILURE_ID_HASH:  {ec3e2762-48ae-ffe9-5b16-fbcb853e8320}

Followup:     MachineOwner
---------

[SMBIOS Data Tables v3.2]
[DMI Version - 0]
[2.0 Calling Convention - No]
[Table Size - 1847 bytes]

[BIOS Information (Type 0) - Length 26 - Handle 0000h]
  Vendor                        American Megatrends International, LLC.
  BIOS Version                  G513IH.329
  BIOS Starting Address Segment f000
  BIOS Release Date             03/01/2023
  BIOS ROM Size                 1000000
  BIOS Characteristics
       07: - PCI Supported
       11: - Upgradeable FLASH BIOS
       12: - BIOS Shadowing Supported
       15: - CD-Boot Supported
       16: - Selectable Boot Supported
       17: - BIOS ROM Socketed
       19: - EDD Supported
       23: - 1.2MB Floppy Supported
       24: - 720KB Floppy Supported
       25: - 2.88MB Floppy Supported
       26: - Print Screen Device Supported
       28: - Serial Services Supported
       29: - Printer Services Supported
       32: - BIOS Vendor Reserved
  BIOS Characteristic Extensions
       00: - ACPI Supported
       01: - USB Legacy Supported
       08: - BIOS Boot Specification Supported
       10: - Enable Targeted Content Distribution
       11: - UEFI Specification Supported
  BIOS Major Revision           5
  BIOS Minor Revision           16
  EC Firmware Major Revision    0
  EC Firmware Minor Revision    80
  Extended BIOS ROM Size        16 MB
[System Information (Type 1) - Length 27 - Handle 0001h]
  Manufacturer                  ASUSTeK COMPUTER INC.
  Product Name                  ROG Strix G513IH_G513IH
  Version                       1.0
  Serial Number                 MBNRKD01857645G
  UUID                          00000000-0000-0000-0000-000000000000
  Wakeup Type                   Power Switch
  SKUNumber                    
  Family                        ROG Strix
[BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
  Manufacturer                  ASUSTeK COMPUTER INC.
  Product                       G513IH
  Version                       1.0
  Serial Number                 D81YMC004Y    
  Asset Tag                                        
  Feature Flags                 09h
       00: - Motherboard
       03: - Replaceable
  Location                      Default string
  Chassis Handle                0003h
  Board Type                    0ah - Processor/Memory Module
  Number of Child Handles       0
[System Enclosure (Type 3) - Length 22 - Handle 0003h]
  Manufacturer                  ASUSTeK COMPUTER INC.
  Chassis Type                  Notebook
  Version                       1.0
  Serial Number                              
  Asset Tag Number                            
  Bootup State                  Safe
  Power Supply State            Safe
  Thermal State                 Safe
  Security Status               None
  OEM Defined                   0
  Height                        0U
  Number of Power Cords         1
  Number of Contained Elements  0
  Contained Element Size        3
[Onboard Devices Information (Type 10) - Length 6 - Handle 0004h]
Note: The On Board Device Information (Type 10) struct is obsolete as of SMBIOs spec v2.6  Number of Devices             1
  01: Type                      Video [enabled]
  01: Description                  To Be Filled By O.E.M.
[OEM Strings (Type 11) - Length 5 - Handle 0005h]
  Number of Strings             5
   1                            
   2                            
   3                            
   4                            
   5                            90NR07P1-M00450
[System Configuration Options (Type 12) - Length 5 - Handle 0006h]
[ (Type 256) - Length 31 - Handle 0008h]
[32Bit Memory Error Information (Type 18) - Length 23 - Handle 0009h]
[Physical Memory Array (Type 16) - Length 23 - Handle 000ah]
  Location                      03h - SystemBoard/Motherboard
  Use                           03h - System Memory
  Memory Error Correction       03h - None
  Maximum Capacity              33554432KB
  Memory Error Inf Handle       0009h
  Number of Memory Devices      2
[Memory Array Mapped Address (Type 19) - Length 31 - Handle 000bh]
  Starting Address              00000000h
  Ending Address                007fffffh
  Memory Array Handle           000ah
  Partition Width               01
  Extended Starting Address     0000000000000000h
  Extended Ending Address       0000000000000000h
[Cache Information (Type 7) - Length 27 - Handle 000ch]
  Socket Designation            L1 - Cache
  Cache Configuration           0180h - WBEnabled Int NonSocketed L1
  Maximum Cache Size            0200h - 512K
  Installed Size                0200h - 512K
  Supported SRAM Type           0010h - Pipeline-Burst
  Current SRAM Type             0010h - Pipeline-Burst
  Cache Speed                   1ns
  Error Correction Type         Specification Reserved
  System Cache Type             Unified
  Associativity                 8-way Set-Associative
  Maximum Cache Size 2          200 - 00000512l Kb
  Installed Cache Size 2        200 - 00000512l Kb
[Cache Information (Type 7) - Length 27 - Handle 000dh]
  Socket Designation            L2 - Cache
  Cache Configuration           0181h - WBEnabled Int NonSocketed L2
  Maximum Cache Size            1000h - 4096K
  Installed Size                1000h - 4096K
  Supported SRAM Type           0010h - Pipeline-Burst
  Current SRAM Type             0010h - Pipeline-Burst
  Cache Speed                   1ns
  Error Correction Type         Specification Reserved
  System Cache Type             Unified
  Associativity                 8-way Set-Associative
  Maximum Cache Size 2          1000 - 00004096l Kb
  Installed Cache Size 2        1000 - 00004096l Kb
[Cache Information (Type 7) - Length 27 - Handle 000eh]
  Socket Designation            L3 - Cache
  Cache Configuration           0182h - WBEnabled Int NonSocketed L3
  Maximum Cache Size            2000h - 8192K
  Installed Size                2000h - 8192K
  Supported SRAM Type           0010h - Pipeline-Burst
  Current SRAM Type             0010h - Pipeline-Burst
  Cache Speed                   1ns
  Error Correction Type         Specification Reserved
  System Cache Type             Unified
  Associativity                 16-way Set-Associative
  Maximum Cache Size 2          2000 - 00008192l Kb
  Installed Cache Size 2        2000 - 00008192l Kb
[Processor Information (Type 4) - Length 48 - Handle 000fh]
  Socket Designation            FP6
  Processor Type                Central Processor
  Processor Family              6bh - AMD Zen Processor Family
  Processor Manufacturer        Advanced Micro Devices, Inc.
  Processor ID                   10f8600fffb8b17
  Processor Version             AMD Ryzen 7 4800H with Radeon Graphics        
  Processor Voltage             8ch - 1.2V
  External Clock                100MHz
  Max Speed                     4300MHz
  Current Speed                 2900MHz
  Status                        Enabled Populated
  Processor Upgrade             None
  L1 Cache Handle               000ch
  L2 Cache Handle               000dh
  L3 Cache Handle               000eh
  Serial Number                      
  Asset Tag Number                    
  Part Number                   Unknown
  Core Count                    8
  Core Enabled                  8
  Thread Count                  16
  Processor Characteristics     fc
  Enabled Characteristics:
       0x 2: 64-bit Capable
       0x 3: Multi-Core
       0x 4: Hardware Thread
       0x 5: Execute Protection
       0x 6: Enhanced Virtualization
       0x 7: Power/Performance Control
  Processor Family 2            006bh - AMD Zen Processor Family
  Core Count 2                  8
  Core Enabled 2                8
  Thread Count 2                16
[32Bit Memory Error Information (Type 18) - Length 23 - Handle 0010h]
[Memory Device (Type 17) - Length 84 - Handle 0011h]
  Memory Error Info Handle      0010h
  Total Width                   64 bits
  Data Width                    64 bits
  Size                          8192MB
  Form Factor                   0dh - SODIMM
  Device Set                    [None]
  Device Locator                DIMM 0
  Bank Locator                  P0 CHANNEL A
  Memory Type                   1ah - DDR4
  Type Detail                   4080h - Synchronous Unbuffered (Unregistered)
  Speed                         3200MHz
  Manufacturer                  Micron Technology
  Serial Number                        
  Asset Tag Number              [String Not Specified]
  Part Number                   4ATF1G64HZ-3G2E2  
  Attributes                    1
  Extended Size                 0
  Configured Memory Speed       3200
  Minimum Voltage               1200
  Maximum Voltage               1200
  Configured Voltage            1200
  Memory Technology             3
  Memory Operating Mode Capability     8
  Firmware Version              6
  Module Manufacturer Id        11392
  Module Product Id             0
  Memory Subsystem Controller Manufacturer Id  0
  Memory Subsystem Controller Product Id       0
  Non-Volatile Size             0
  Volatile Size                 0
  Cache Size                    0
  Logical Size                  0
[Memory Device Mapped Address (Type 20) - Length 35 - Handle 0012h]
  Starting Address              00000000h
  Ending Address                007fffffh
  Memory Device Handle          0011h
  Mem Array Mapped Adr Handle   000bh
  Partition Row Position        [Unknown]
  Interleave Position           [None]
  Interleave Data Depth         [None]
  Extended Starting Address     0000000000000000h
  Extended Ending Address       0000000000000000h
[32Bit Memory Error Information (Type 18) - Length 23 - Handle 0013h]
[Memory Device (Type 17) - Length 84 - Handle 0014h]
  Memory Error Info Handle      0013h
  Total Width                   [Unknown]
  Data Width                    [Unknown]
  Size                          [Not Populated]
  Form Factor                   02h - Unknown
  Device Set                    [None]
  Device Locator                DIMM 0
  Bank Locator                  P0 CHANNEL B
  Memory Type                   02h - Unknown
  Type Detail                   0004h - Unknown
  Speed                         0MHz
  Manufacturer                  Unknown
  Serial Number                      
  Asset Tag Number              [String Not Specified]
  Part Number                   Unknown
  Attributes                    0
  Extended Size                 0
  Configured Memory Speed       0
  Minimum Voltage               0
  Maximum Voltage               0
  Configured Voltage            0
  Memory Technology             2
  Memory Operating Mode Capability     4
  Firmware Version              6
  Module Manufacturer Id        0
  Module Product Id             0
  Memory Subsystem Controller Manufacturer Id  0
  Memory Subsystem Controller Product Id       0
  Non-Volatile Size             0
  Volatile Size                 0
  Cache Size                    0
  Logical Size                  0
[ (Type 256) - Length 11 - Handle 0030h]
[ (Type 256) - Length 11 - Handle 0031h]
[ (Type 256) - Length 4 - Handle 0033h]
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced.  This cannot be protected by try-except.
Typically the address is just plain bad or it is pointing at freed memory.
Arguments:
Arg1: ffff950d56505c10, memory referenced.
Arg2: 0000000000000011, X64: bit 0 set if the fault was due to a not-present PTE.
    bit 1 is set if the fault was due to a write, clear if a read.
    bit 3 is set if the processor decided the fault was due to a corrupted PTE.
    bit 4 is set if the fault was due to attempted execute of a no-execute PTE.
    - ARM64: bit 1 is set if the fault was due to a write, clear if a read.
    bit 3 is set if the fault was due to attempted execute of a no-execute PTE.
Arg3: ffff950d56505c10, If non-zero, the instruction address which referenced the bad memory
    address.
Arg4: 0000000000000002, (reserved)

Debugging Details:
------------------

*** WARNING: Unable to verify timestamp for WdFilter.sys
*** WARNING: Unable to verify timestamp for amdfendr.sys

KEY_VALUES_STRING: 1

    Key  : AV.PTE
    Value: Valid

    Key  : AV.Type
    Value: Execute

    Key  : Analysis.CPU.mSec
    Value: 1343

    Key  : Analysis.Elapsed.mSec
    Value: 35613

    Key  : Analysis.IO.Other.Mb
    Value: 0

    Key  : Analysis.IO.Read.Mb
    Value: 1

    Key  : Analysis.IO.Write.Mb
    Value: 21

    Key  : Analysis.Init.CPU.mSec
    Value: 531

    Key  : Analysis.Init.Elapsed.mSec
    Value: 58913

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 86

    Key  : Analysis.Version.DbgEng
    Value: 10.0.27871.1001

    Key  : Analysis.Version.Description
    Value: 10.2505.01.02 amd64fre

    Key  : Analysis.Version.Ext
    Value: 1.2505.1.2

    Key  : Bugcheck.Code.LegacyAPI
    Value: 0x50

    Key  : Bugcheck.Code.TargetModel
    Value: 0x50

    Key  : Failure.Bucket
    Value: AV_X_(null)_WdFilter!unknown_function

    Key  : Failure.Exception.IP.Address
    Value: 0xffff950d56505c10

    Key  : Failure.Hash
    Value: {2466b939-761d-7888-7d7b-3981f617c641}

    Key  : WER.OS.Branch
    Value: vb_release

    Key  : WER.OS.Version
    Value: 10.0.19041.1


BUGCHECK_CODE:  50

BUGCHECK_P1: ffff950d56505c10

BUGCHECK_P2: 11

BUGCHECK_P3: ffff950d56505c10

BUGCHECK_P4: 2

FILE_IN_CAB:  081425-22218-01.dmp

FAULTING_THREAD:  ffff950d4bdd7040

WRITE_ADDRESS: fffff8011dcfb390: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
unable to get nt!MmSpecialPagesInUse
 ffff950d56505c10

MM_INTERNAL_CODE:  2

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  System

LOCK_ADDRESS:  fffff8011dc44be0 -- (!locks fffff8011dc44be0)
Cannot get _ERESOURCE Flag field
Unexpected resource format: 0
1 total locks

PNP_TRIAGE_DATA:
    Lock address  : 0xfffff8011dc44be0
    Thread Count  : 0
    Thread address: 0x0000000000000000
    Thread wait   : 0x0

STACK_TEXT:
ffffcf8a`edba0808 fffff801`1d448b23     : 00000000`00000050 ffff950d`56505c10 00000000`00000011 ffffcf8a`edba0ab0 : nt!KeBugCheckEx
ffffcf8a`edba0810 fffff801`1d20d450     : 00000000`00000000 00000000`00000011 ffffcf8a`edba0b30 00000000`00000000 : nt!MiSystemFault+0x1b70a3
ffffcf8a`edba0910 fffff801`1d40d66d     : ffff950d`00000000 00000000`00000000 ffff950d`561caa20 ffffcf8a`edba0e40 : nt!MmAccessFault+0x400
ffffcf8a`edba0ab0 ffff950d`56505c10     : fffff801`1d2cbc09 00000000`00040293 fffff801`1d2d0cbb 00000000`ffffffff : nt!KiPageFault+0x36d
ffffcf8a`edba0c48 fffff801`1d2cbc09     : 00000000`00040293 fffff801`1d2d0cbb 00000000`ffffffff ffffad01`00000000 : 0xffff950d`56505c10
ffffcf8a`edba0c50 fffff801`1bf9a478     : ffffcf8a`edba0e68 ffff950d`4b8145e0 ffffcf8a`edba0d58 00000000`00000000 : nt!ExReleaseResourceLite+0x109
ffffcf8a`edba0cb0 fffff801`1bf9a3fd     : ffff950d`566d30f8 ffffcf8a`edba0d88 ffff950d`4b2a0a20 00000000`00000009 : FLTMGR!FltSetEcpListIntoCallbackData+0x58
ffffcf8a`edba0ce0 fffff801`21f5a7ea     : 00000000`0000004f ffffad01`5871c188 ffffad01`58764690 ffffad01`58733530 : FLTMGR!FltRequestFileInfoOnCreateCompletion+0x11d
ffffcf8a`edba0d20 00000000`0000004f     : ffffad01`5871c188 ffffad01`58764690 ffffad01`58733530 00000000`00000170 : WdFilter+0x2a7ea
ffffcf8a`edba0d28 ffffad01`5871c188     : ffffad01`58764690 ffffad01`58733530 00000000`00000170 00000000`00000090 : 0x4f
ffffcf8a`edba0d30 ffffad01`58764690     : ffffad01`58733530 00000000`00000170 00000000`00000090 ffff950d`566d3198 : 0xffffad01`5871c188
ffffcf8a`edba0d38 ffffad01`58733530     : 00000000`00000170 00000000`00000090 ffff950d`566d3198 fffff801`1bf66e12 : 0xffffad01`58764690
ffffcf8a`edba0d40 00000000`00000170     : 00000000`00000090 ffff950d`566d3198 fffff801`1bf66e12 00000000`1000000c : 0xffffad01`58733530
ffffcf8a`edba0d48 00000000`00000090     : ffff950d`566d3198 fffff801`1bf66e12 00000000`1000000c ffff950d`561cacb0 : 0x170
ffffcf8a`edba0d50 ffff950d`566d3198     : fffff801`1bf66e12 00000000`1000000c ffff950d`561cacb0 ffffcf8a`edba0f80 : 0x90
ffffcf8a`edba0d58 fffff801`1bf66e12     : 00000000`1000000c ffff950d`561cacb0 ffffcf8a`edba0f80 ffff950d`566d3090 : 0xffff950d`566d3198
ffffcf8a`edba0d60 fffff801`1bf664cb     : 00000000`00000000 ffff950d`00000000 ffff950d`00000000 ffff950d`561cacb0 : FLTMGR!FltpLinkCompletionNodeToInstance+0x112
ffffcf8a`edba0dd0 fffff801`1bf65f7a     : ffffcf8a`edba0f00 fffff801`1bf67c00 00000000`00000000 00000000`00000000 : FLTMGR!FltpPerformPreCallbacksWorker+0x36b
ffffcf8a`edba0ef0 fffff801`1bf99ed0     : ffffcf8a`edba2000 ffffcf8a`edb9c000 ffff950d`4b3b2d60 00000000`00000000 : FLTMGR!FltpPassThroughInternal+0xca
ffffcf8a`edba0f40 fffff801`1d2d21c5     : ffff950d`00000000 ffff950d`4b4cd930 00000000`00000000 00000000`00000000 : FLTMGR!FltpCreate+0x310
ffffcf8a`edba0ff0 fffff801`1d2d4084     : ffff950d`5676ca20 fffff801`1d9b418e ffff950d`4b4cd930 fffff801`1d2d3cb3 : nt!IofCallDriver+0x55
ffffcf8a`edba1030 fffff801`1d64f829     : ffffcf8a`edba12e0 ffff950d`4b4cd930 ffff950d`5676cab8 00000000`56700001 : nt!IoCallDriverWithTracing+0x34
ffffcf8a`edba1080 fffff801`1d642757     : ffff950d`4b4cd930 ffff950d`4b4cd900 ffff950d`5670fa20 ffffad01`584bda00 : nt!IopParseDevice+0x11a9
ffffcf8a`edba11e0 fffff801`1d6cec8a     : ffff950d`5670fa01 ffffcf8a`edba1448 00000000`00000240 ffff950d`455c3400 : nt!ObpLookupObjectName+0x1117
ffffcf8a`edba13b0 fffff801`1d60c431     : ffff950d`00000000 ffffcf8a`edba1880 ffffcf8a`edba1870 00000000`00000000 : nt!ObOpenObjectByNameEx+0x1fa
ffffcf8a`edba14e0 fffff801`1d60b878     : ffffcf8a`edba18d0 ffff950d`00100001 ffffcf8a`edba1880 ffffcf8a`edba1870 : nt!IopCreateFile+0xb11
ffffcf8a`edba1590 fffff801`1d411508     : ffff950d`00000000 ffff950d`5676c140 00000000`0000009e 00000000`00000000 : nt!NtOpenFile+0x58
ffffcf8a`edba1620 fffff801`1d402300     : fffff801`1d89f4bb ffff950d`456cae30 fffff801`1d5ee514 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
ffffcf8a`edba1828 fffff801`1d89f4bb     : ffff950d`456cae30 fffff801`1d5ee514 00000000`00000000 00000000`00000000 : nt!KiServiceLinkage
ffffcf8a`edba1830 fffff801`1d89ecbe     : ffffcf8a`edba1970 00000000`00000000 00000000`00000000 ffffcf8a`edba1920 : nt!PiGetDriverImageDirectory+0xf7
ffffcf8a`edba18c0 fffff801`87877fd4     : 00000000`00000000 ffffcf8a`edba1970 00000000`00000000 fffff801`878970f0 : nt!IoGetDriverDirectory+0x6e
ffffcf8a`edba18f0 00000000`00000000     : ffffcf8a`edba1970 00000000`00000000 fffff801`878970f0 ffff950d`557c8edb : amdfendr+0x17fd4


SYMBOL_NAME:  WdFilter+2a7ea

MODULE_NAME: WdFilter

IMAGE_NAME:  WdFilter.sys

STACK_COMMAND: .process /r /p 0xffff950d454fb240; .thread 0xffff950d4bdd7040 ; kb

BUCKET_ID_FUNC_OFFSET:  2a7ea

FAILURE_BUCKET_ID:  AV_X_(null)_WdFilter!unknown_function

OS_VERSION:  10.0.19041.1

BUILDLAB_STR:  vb_release

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

FAILURE_ID_HASH:  {2466b939-761d-7888-7d7b-3981f617c641}
Merhabalar hocam geç yazıyorum kusura bakmayın dönüt beklemiyordum. Windows 11'e geçince sorun maalesef düzelmedi hala çok kötü durumda. 1 saat içinde 5 mavi ekran hatası alıyorum. Başka birine dosyalarımı ve disk testimi attığımda sorunun diskte olduğunu söyledi ki bana mantıklı geldi çünkü sürücü problemi olması imkansız gibi.


Kullandığım laptop ROG G513IH modeli. İçindeki diski değiştirmek istiyorum ama bilgi sahibi olamadığım için nasıl bir SSD almalıyım, direk servise verip onların değişmesini mi beklemeliyim bilgim yok (garantisi yok). Ne yapmamı önerirsiniz? Bir SSD alıp o SSD'yi birine laptopuma takması için emanet etmeyi uygun görüyorum aslında ama nasıl bir SSD almam gerektiğini bilmiyorum yardımcı olur musunuz hangi modeli almalıyım?

512 GB bir SSD yeterli olur. Piyasasına hakim olmadığım için fiyat karşılaştırması yapamıyorum ve gereğinden iyi veya kötü bir SSD almak istemiyorum tavsiyede bulunursanız sevinirim.
 
Merhabalar hocam geç yazıyorum kusura bakmayın dönüt beklemiyordum. Windows 11'e geçince sorun maalesef düzelmedi hala çok kötü durumda. 1 saat içinde 5 mavi ekran hatası alıyorum. Başka birine dosyalarımı ve disk testimi attığımda sorunun diskte olduğunu söyledi ki bana mantıklı geldi çünkü sürücü problemi olması imkansız gibi.


Kullandığım laptop ROG G513IH modeli. İçindeki diski değiştirmek istiyorum ama bilgi sahibi olamadığım için nasıl bir SSD almalıyım, direk servise verip onların değişmesini mi beklemeliyim bilgim yok (garantisi yok). Ne yapmamı önerirsiniz? Bir SSD alıp o SSD'yi birine laptopuma takması için emanet etmeyi uygun görüyorum aslında ama nasıl bir SSD almam gerektiğini bilmiyorum yardımcı olur musunuz hangi modeli almalıyım?

512 GB bir SSD yeterli olur. Piyasasına hakim olmadığım için fiyat karşılaştırması yapamıyorum ve gereğinden iyi veya kötü bir SSD almak istemiyorum tavsiyede bulunursanız sevinirim.

Selamlar, @melihXD

Ben 870 EVO Samsung tavsiye ediyorum, herhangi bir fiyat belirlemediğimiz için şu an alabileceğiniz en üst seviye SSD modeli bu. Kalite olarak en iyisi, isterseniz değerlendirebilirsiniz.

* Özellikler:
- Interface: SATA/AHCI​
- Form Factor: 2.5​
- Capacities: 500GB​
- Controller: Samsung MKX​
- Configuration: Tri-core, 8-ch, 8-CE/ch​
- DRAM: Yes​
- NAND Brand: Samsung​
- NAND Type: TLC​
- Layers: 128​
- R/W MB/s: 560/530​
* TECHPOWERUP
- Kaynak
1756745703701.webp
- Fiyat: 2000 TL​
İyi Sosyaller.
 
Son düzenleme:
Selam, @melihXD

Ben 870 EVO Samsung tavsiye ediyorum, herhangi bir fiyat belirlemediğimiz için şu an alabileceğiniz en üst seviye SSD modeli bu. Kalite olarak en iyisi, isterseniz değerlendirebilirsiniz.

* özellikler:
- ınterface: SATA/AHCI​
- form factor: 2.5​
- capacities: 500GB​
- Controller: Samsung mkx​
- Configuration: tri-Core, 8-ch, 8-CE/ch​
- DRAM: yes​
- NAND Brand: Samsung​
- NAND type: TLC​
- layers: 128​
- r/w MB/s: 560/530​
* TechPowerUp
- Kaynak
- fiyat: 2.000 TL​
iyi sosyaller.

Çok sağ olun hocam. Dediğim laptop modeliyle uyumluluk bakımından sıkıntı yaşar mıyım acaba?
 
Çok sağ olun hocam. Dediğim laptop modeliyle uyumluluk bakımından sıkıntı yaşar mıyım acaba?

Şimdi daha detaylı baktım, model olarak size M.2 SSD lazım. Pek dikkatli bakmamışım, SATA önerdim. Kusura bakmayın.

2 tane önerdim: "Samsung 970 EVO Plus" biraz daha iyi, "Kioxia" da kaliteli bir SSD’dir. Her iki modelde de DRAM bulunuyor, sisteminizle uyumludurlar.