4: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except.
Typically the address is just plain bad or it is pointing at freed memory.
Arguments:
Arg1: ffffaa089085a000, memory referenced.
Arg2: 0000000000000000, X64: bit 0 set if the fault was due to a not-present PTE.
bit 1 is set if the fault was due to a write, clear if a read.
bit 3 is set if the processor decided the fault was due to a corrupted PTE.
bit 4 is set if the fault was due to attempted execute of a no-execute PTE.
- ARM64: bit 1 is set if the fault was due to a write, clear if a read.
bit 3 is set if the fault was due to attempted execute of a no-execute PTE.
Arg3: fffff80392f33d42, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000000, (reserved)
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for vvftav303.sys
KEY_VALUES_STRING: 1
Key : AV.Type
Value: Read
Key : Analysis.CPU.mSec
Value: 5031
Key : Analysis.DebugAnalysisManager
Value: Create
Key : Analysis.Elapsed.mSec
Value: 32940
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 0
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 343
Key : Analysis.Init.Elapsed.mSec
Value: 2108
Key : Analysis.Memory.CommitPeak.Mb
Value: 91
Key : Bugcheck.Code.DumpHeader
Value: 0x50
Key : Bugcheck.Code.Register
Value: 0x50
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Timestamp
Value: 2019-12-06T14:06:00Z
Key : WER.OS.Version
Value: 10.0.19041.1
FILE_IN_CAB: 052823-18609-01.dmp
BUGCHECK_CODE: 50
BUGCHECK_P1: ffffaa089085a000
BUGCHECK_P2: 0
BUGCHECK_P3: fffff80392f33d42
BUGCHECK_P4: 0
READ_ADDRESS: fffff8033a0fb390: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
unable to get nt!MmSpecialPagesInUse
ffffaa089085a000
MM_INTERNAL_CODE: 0
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: amcap.exe
TRAP_FRAME: ffff920911cfe840 -- (.trap 0xffff920911cfe840)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000a35ca4 rbx=0000000000000000 rcx=00000000009ac1f4
rdx=0000000000a35ca4 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80392f33d42 rsp=ffff920911cfe9d0 rbp=0000000000000001
r8=0000000000000550 r9=0000000000000040 r10=0000000000000004
r11=ffffe505f1420320 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na po nc
vvftav303+0x13d42:
fffff803`92f33d42 f3a4 rep movs byte ptr [rdi],byte ptr [rsi]
Resetting default scope
STACK_TEXT:
ffff9209`11cfe598 fffff803`3984af03 : 00000000`00000050 ffffaa08`9085a000 00000000`00000000 ffff9209`11cfe840 : nt!KeBugCheckEx
ffff9209`11cfe5a0 fffff803`3966e7b0 : 00000000`00000000 00000000`00000000 ffff9209`11cfe8c0 00000000`00000000 : nt!MiSystemFault+0x1b2523
ffff9209`11cfe6a0 fffff803`3980b7d8 : 00000000`00000000 00000000`00000001 00000000`00000000 00000000`00000000 : nt!MmAccessFault+0x400
ffff9209`11cfe840 fffff803`92f33d42 : 00000000`00000000 00000000`00000078 00000000`000000a0 ffff9209`11cfeb98 : nt!KiPageFault+0x358
ffff9209`11cfe9d0 00000000`00000000 : 00000000`00000078 00000000`000000a0 ffff9209`11cfeb98 00000000`00000000 : vvftav303+0x13d42
SYMBOL_NAME: vvftav303+13d42
MODULE_NAME: vvftav303
IMAGE_NAME: vvftav303.sys
STACK_COMMAND: .cxr; .ecxr ; kb
BUCKET_ID_FUNC_OFFSET: 13d42
FAILURE_BUCKET_ID: AV_R_(null)_vvftav303!unknown_function
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {9e80d5ab-7094-3d2e-1554-91029ecf86aa}
Followup: MachineOwner
---------
4: kd> lmvm vvftav303
Browse full module list
start end module name
fffff803`92f20000 fffff803`92f6b380 vvftav303 T (no symbols)
Loaded symbol image file: vvftav303.sys
Image path: \SystemRoot\system32\drivers\vvftav303.sys
Image name: vvftav303.sys
Browse all global symbols functions data
Timestamp: Sat Jun 23 08:46:10 2007 (467CB3A2)
CheckSum: 0004F751
ImageSize: 0004B380
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
Information from resource tables:
4: kd> !sysinfo machineid
Machine ID Information [From Smbios 3.3, DMIVersion 0, Size=2303]
BiosMajorRelease = 5
BiosMinorRelease = 17
BiosVendor = American Megatrends Inc.
BiosVersion = 6062
BiosReleaseDate = 02/24/2023
SystemManufacturer = System manufacturer
SystemProductName = System Product Name
SystemFamily = To be filled by O.E.M.
SystemVersion = System Version
SystemSKU = SKU
BaseBoardManufacturer = ASUSTeK COMPUTER INC.
BaseBoardProduct = PRIME A320M-C R2.0
BaseBoardVersion = Rev X.0x