************ Path validation summary **************
Response Time (ms) Location.
Deferred srv*
Symbol search path is: srv*
Executable search path is:
Windows 10 Kernel Version 19041 MP (4 procs) Free x64.
Product: WinNt, suite: TerminalServer SingleUserTS.
Edition build lab: 19041.1.amd64fre.vb_release.191206-1406
Machine Name:
Kernel base = 0xfffff800`11c00000 PsLoadedModuleList = 0xfffff800`1282a2b0
Debug session time: Tue Jun 8 11:29:23.535 2021 (UTC + 3:00)
System Uptime: 0 days 1:09:57.187
Loading Kernel Symbols.
...............................................................
................................................................
..............................................................
Loading User Symbols.
Loading unloaded module list.
.........
For analysis of this file, run !analyze -v
nt!KeBugCheckEx:
fffff800`11ff6c90 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:fffffa08`56883ee0=000000000000007e
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
This is a very common BugCheck. Usually the exception address pinpoints.
the driver/function that caused the problem. Always note this address.
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard.
coded breakpoint or assertion was hit, but this system was booted.
/NODEBUG. This is not supposed to happen as developers should never have.
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the.
system is booted /DEBUG. This will let us see why this breakpoint is.
happening.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled.
Arg2: fffff8001ca25b0c, The address that the exception occurred at.
Arg3: fffffa0856884ed8, Exception Record Address.
Arg4: fffffa0856884710, Context Record Address.
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for nvlddmkm.sys
*** WARNING: Unable to verify checksum for win32k.sys
KEY_VALUES_STRING: 1
Key : AV.Fault
Value: Read.
Key : Analysis.CPU.mSec
Value: 5687.
Key : Analysis.DebugAnalysisManager
Value: Create.
Key : Analysis.Elapsed.mSec
Value: 23714.
Key : Analysis.Init.CPU.mSec
Value: 436.
Key : Analysis.Init.Elapsed.mSec
Value: 3426.
Key : Analysis.Memory.CommitPeak.Mb
Value: 86.
Key : WER.OS.Branch
Value: vb_release.
Key : WER.OS.Timestamp
Value: 2019-12-06T14:06:00Z
Key : WER.OS.Version
Value: 10.0.19041.1
BUGCHECK_CODE: 7e.
BUGCHECK_P1: ffffffffc0000005.
BUGCHECK_P2: fffff8001ca25b0c.
BUGCHECK_P3: fffffa0856884ed8.
BUGCHECK_P4: fffffa0856884710.
EXCEPTION_RECORD: fffffa0856884ed8 -- (.exr 0xfffffa0856884ed8)
ExceptionAddress: fffff8001ca25b0c (nvlddmkm+0x0000000000125b0c)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000.
NumberParameters: 2
Parameter[0]: 0000000000000000.
Parameter[1]: 00000000bb0526b3.
Attempt to read from address 00000000bb0526b3.
CONTEXT: fffffa0856884710 -- (.cxr 0xfffffa0856884710)
rax=ffffb50f87166000 rbx=fffffa0856885220 rcx=00000000bb0523a3
rdx=00000000005d5d00 rsi=fffff8001d2af060 rdi=ffffb50f87a587c8
rip=fffff8001ca25b0c rsp=fffffa0856885110 rbp=0000000000000000
r8=00000000bb0523a3 r9=0000000000000003 r10=fffff8001d1665b0
r11=0000000000000008 r12=ffffb50f87b028f8 r13=000000000e53d848
r14=ffffb50f87a587c8 r15=fffff8001d2af060
iopl=0 nv up ei pl zr na po nc.
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050246
nvlddmkm+0x125b0c:
fffff800`1ca25b0c 41ff9010030000 call qword ptr [r8+310h] ds:002b:00000000`bb0526b3=????????????????
Resetting default scope.
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System.
READ_ADDRESS: fffff800128fb390: Unable to get MiVisibleState.
Unable to get NonPagedPoolStart.
Unable to get NonPagedPoolEnd.
Unable to get PagedPoolStart.
Unable to get PagedPoolEnd.
unable to get nt!MmSpecialPagesInUse
00000000bb0526b3.
ERROR_CODE: (NTSTATUS) 0xc0000005 - 0x%p adresindeki y nerge 0x%p adresindeki belle e ba vurdu. Bellek u olamaz %s.
EXCEPTION_CODE_STR: c0000005.
EXCEPTION_PARAMETER1: 0000000000000000.
EXCEPTION_PARAMETER2: 00000000bb0526b3.
EXCEPTION_STR: 0xc0000005.
STACK_TEXT:
fffffa08`56885110 fffffa08`56885220 : fffffa08`56885220 fffffa08`56885249 fffff800`1ca269a5 fffffa08`56885220 : nvlddmkm+0x125b0c
fffffa08`56885118 fffffa08`56885220 : fffffa08`56885249 fffff800`1ca269a5 fffffa08`56885220 fffff800`1ca102e8 : 0xfffffa08`56885220
fffffa08`56885120 fffffa08`56885249 : fffff800`1ca269a5 fffffa08`56885220 fffff800`1ca102e8 00000000`00000000 : 0xfffffa08`56885220
fffffa08`56885128 fffff800`1ca269a5 : fffffa08`56885220 fffff800`1ca102e8 00000000`00000000 ffffb50f`87166000 : 0xfffffa08`56885249
fffffa08`56885130 fffffa08`56885220 : fffff800`1ca102e8 00000000`00000000 ffffb50f`87166000 ffffb50f`87b028f0 : nvlddmkm+0x1269a5
fffffa08`56885138 fffff800`1ca102e8 : 00000000`00000000 ffffb50f`87166000 ffffb50f`87b028f0 ffffb50f`87a58ce8 : 0xfffffa08`56885220
fffffa08`56885140 00000000`00000000 : ffffb50f`87166000 ffffb50f`87b028f0 ffffb50f`87a58ce8 fffffa08`56885220 : nvlddmkm+0x1102e8
SYMBOL_NAME: nvlddmkm+125b0c
MODULE_NAME: nvlddmkm.
IMAGE_NAME: nvlddmkm.sys
STACK_COMMAND: .cxr 0xfffffa0856884710 ; kb.
BUCKET_ID_FUNC_OFFSET: 125b0c.
FAILURE_BUCKET_ID: AV_nvlddmkm!unknown_function
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release.
OSPLATFORM_TYPE: x64.
OSNAME: Windows 10.
FAILURE_ID_HASH: {7eea5677-f68d-2154-717e-887e07e55cd3}
Followup: MachineOwner.
---------