Microsoft (R) Windows Debugger Version 10.0.20153.1000 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\CsHay\AppData\Local\Temp\Rar$DIa872.43209\092120-11062-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
************* Path validation summary **************
Response Time (ms) Location
Deferred srv*
Symbol search path is: srv*
Executable search path is:
Windows 10 Kernel Version 19041 MP (6 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Edition build lab: 19041.1.amd64fre.vb_release.191206-1406
Machine Name:
Kernel base = 0xfffff801`0e400000 PsLoadedModuleList = 0xfffff801`0f02a310
Debug session time: Mon Sep 21 21:22:41.612 2020 (UTC + 3:00)
System Uptime: 0 days 7:23:42.194
Loading Kernel Symbols
...............................................................
................................................................
................................................................
.................
Loading User Symbols
Loading unloaded module list
...................
For analysis of this file, run !analyze -v
nt!KeBugCheckEx:
fffff801`0e7f3ea0 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:fffffe8f`4f253500=000000000000000a
4: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 0000000000000040, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000001, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff8010e6cb380, address which referenced memory
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for win32k.sys
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 3983
Key : Analysis.DebugAnalysisProvider.CPP
Value: Create: 8007007e on DESKTOP-IPC9T25
Key : Analysis.DebugData
Value: CreateObject
Key : Analysis.DebugModel
Value: CreateObject
Key : Analysis.Elapsed.mSec
Value: 15235
Key : Analysis.Memory.CommitPeak.Mb
Value: 76
Key : Analysis.System
Value: CreateObject
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Timestamp
Value: 2019-12-06T14:06:00Z
Key : WER.OS.Version
Value: 10.0.19041.1
ADDITIONAL_XML: 1
OS_BUILD_LAYERS: 1
BUGCHECK_CODE: a
BUGCHECK_P1: 40
BUGCHECK_P2: 2
BUGCHECK_P3: 1
BUGCHECK_P4: fffff8010e6cb380
WRITE_ADDRESS: fffff8010f0fa390: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
fffff8010f00f2e0: Unable to get Flags value from nt!KdVersionBlock
fffff8010f00f2e0: Unable to get Flags value from nt!KdVersionBlock
unable to get nt!MmSpecialPagesInUse
0000000000000040
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System
TRAP_FRAME: fffffe8f4f253640 -- (.trap 0xfffffe8f4f253640)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=00000000000000c8 rbx=0000000000000000 rcx=ffff88810b8cf180
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8010e6cb380 rsp=fffffe8f4f2537d0 rbp=ffff88810b8cf180
r8=0000000000000100 r9=0000000000000000 r10=fffff8010c44bac0
r11=0000003dfc107325 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
nt!KiTryUnwaitThread+0x50:
fffff801`0e6cb380 f0480fba6b4000 lock bts qword ptr [rbx+40h],0 ds:00000000`00000040=????????????????
Resetting default scope
STACK_TEXT:
fffffe8f`4f2534f8 fffff801`0e805e69 : 00000000`0000000a 00000000`00000040 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
fffffe8f`4f253500 fffff801`0e802169 : 00000000`00000000 00000000`00000000 00000000`00000001 ffff990d`06c03ca8 : nt!KiBugCheckDispatch+0x69
fffffe8f`4f253640 fffff801`0e6cb380 : 00000000`00000000 ffff990c`fe874290 00000000`00000001 00000000`00989680 : nt!KiPageFault+0x469
fffffe8f`4f2537d0 fffff801`0e6c42a6 : ffff990d`0acfc188 00000000`00000000 ffff8881`0b7671c0 00000000`00000000 : nt!KiTryUnwaitThread+0x50
fffffe8f`4f253830 fffff801`0e6c3e4c : ffff990d`0acfc180 00000000`00000000 fffffe8f`4f253b18 00000000`00000000 : nt!KiTimerWaitTest+0x1e6
fffffe8f`4f2538e0 fffff801`0e6e9509 : 00000000`00000000 00000000`00000000 00000000`00140001 00000000`000f7f1c : nt!KiProcessExpiredTimerList+0xdc
fffffe8f`4f2539d0 fffff801`0e7f7a0e : ffffffff`00000000 ffff8881`0b8cf180 ffff8881`0b8da1c0 ffff990d`09be7080 : nt!KiRetireDpcList+0x9d9
fffffe8f`4f253c60 00000000`00000000 : fffffe8f`4f254000 fffffe8f`4f24e000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x9e
SYMBOL_NAME: nt!KiTryUnwaitThread+50
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
IMAGE_VERSION: 10.0.19041.508
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: 50
FAILURE_BUCKET_ID: AV_nt!KiTryUnwaitThread
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {ba6f35c9-2379-7d7d-3c94-4dc6394d2e20}
Followup: MachineOwner
---------