************* Preparing the environment for Debugger Extensions Gallery repositories **************
ExtensionRepository : Implicit
UseExperimentalFeatureForNugetShare : true
AllowNugetExeUpdate : true
AllowNugetMSCredentialProviderInstall : true
AllowParallelInitializationOfLocalRepositories : true
-- Configuring repositories
----> Repository : LocalInstalled, Enabled: true
----> Repository : UserExtensions, Enabled: true
>>>>>>>>>>>>> Preparing the environment for Debugger Extensions Gallery repositories completed, duration 0.000 seconds
************* Waiting for Debugger Extensions Gallery to Initialize **************
>>>>>>>>>>>>> Waiting for Debugger Extensions Gallery to Initialize completed, duration 0.125 seconds
----> Repository : UserExtensions, Enabled: true, Packages count: 0
----> Repository : LocalInstalled, Enabled: true, Packages count: 36
Microsoft (R) Windows Debugger Version 10.0.25921.1001 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\Çağatay\Desktop\091423-5437-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: srv*
Executable search path is:
Windows 10 Kernel Version 22621 MP (12 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Edition build lab: 22621.1928.amd64fre.ni_release_svc_prod3.230622-0951
Kernel base = 0xfffff801`29000000 PsLoadedModuleList = 0xfffff801`29c130e0
Debug session time: Thu Sep 14 20:30:48.112 2023 (UTC + 3:00)
System Uptime: 0 days 0:26:26.715
Loading Kernel Symbols
...............................................................
................................................................
............................................................
Loading User Symbols
PEB is paged out (Peb.Ldr = 00000000`00839018). Type ".hh dbgerr001" for details
Loading unloaded module list
.......
For analysis of this file, run !analyze -v
nt!KeBugCheckEx:
fffff801`29432140 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:ffffaf81`5f4f7390=000000000000000a
5: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 0000000000000005, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000001, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff801292431e8, address which referenced memory
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 1671
Key : Analysis.Elapsed.mSec
Value: 5182
Key : Analysis.IO.Other.Mb
Value: 15
Key : Analysis.IO.Read.Mb
Value: 14
Key : Analysis.IO.Write.Mb
Value: 39
Key : Analysis.Init.CPU.mSec
Value: 171
Key : Analysis.Init.Elapsed.mSec
Value: 20741
Key : Analysis.Memory.CommitPeak.Mb
Value: 90
Key : Bugcheck.Code.LegacyAPI
Value: 0xa
Key : Failure.Bucket
Value: IP_MISALIGNED_AuthenticAMD.sys
Key : Failure.Hash
Value: {716d112a-8330-4bbb-160c-ec98297019d2}
Key : WER.OS.Branch
Value: ni_release_svc_prod3
Key : WER.OS.Version
Value: 10.0.22621.1928
BUGCHECK_CODE: a
BUGCHECK_P1: 5
BUGCHECK_P2: 2
BUGCHECK_P3: 1
BUGCHECK_P4: fffff801292431e8
FILE_IN_CAB: 091423-5437-01.dmp
WRITE_ADDRESS: fffff80129d1c468: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
unable to get nt!MmSpecialPagesInUse
0000000000000005
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: Cities.exe
TRAP_FRAME: ffffaf815f4f74d0 -- (.trap 0xffffaf815f4f74d0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=0000000000000005
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff801292431e8 rsp=ffffaf815f4f7660 rbp=ffffaf815f4f7760
r8=0000000000000001 r9=0000000000000000 r10=0000000000000000
r11=ffff9307d786d1c0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na po nc
nt!KeWaitForSingleObject+0x208:
fffff801`292431e8 004989 add byte ptr [rcx-77h],cl ds:ffffffff`ffffff8e=??
Resetting default scope
MISALIGNED_IP:
nt!KeWaitForSingleObject+208
fffff801`292431e8 004989 add byte ptr [rcx-77h],cl
STACK_TEXT:
ffffaf81`5f4f7388 fffff801`294477a9 : 00000000`0000000a 00000000`00000005 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
ffffaf81`5f4f7390 fffff801`29442e34 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiBugCheckDispatch+0x69
ffffaf81`5f4f74d0 fffff801`292431e8 : ffff9307`00000000 ffff9307`00000001 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x474
ffffaf81`5f4f7660 fffff801`2977a1ac : ffff9307`dd2760c0 ffff9307`dadbe760 00000000`00000000 00000000`00000001 : nt!KeWaitForSingleObject+0x208
ffffaf81`5f4f7a00 fffff801`2977a09e : ffff9307`d786d080 00000000`00000000 00000000`00000000 ffff9307`dadbe760 : nt!ObWaitForSingleObject+0xcc
ffffaf81`5f4f7a60 fffff801`29446ee8 : ffff9307`d786d080 00000000`03e4b450 00000000`00000000 00000000`00000000 : nt!NtWaitForSingleObject+0x3e
ffffaf81`5f4f7aa0 00007ff9`0792edd4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
00000000`212afb98 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff9`0792edd4
SYMBOL_NAME: nt!KeWaitForSingleObject+208
IMAGE_VERSION: 10.0.22621.2283
STACK_COMMAND: .cxr; .ecxr ; kb
MODULE_NAME: AuthenticAMD
IMAGE_NAME: AuthenticAMD.sys
FAILURE_BUCKET_ID: IP_MISALIGNED_AuthenticAMD.sys
OS_VERSION: 10.0.22621.1928
BUILDLAB_STR: ni_release_svc_prod3
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {716d112a-8330-4bbb-160c-ec98297019d2}
Followup: MachineOwner
---------
5: kd> lmvm AuthenticAMD
Browse full module list
start end module name