*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000000403, The subtype of the bugcheck.
Arg2: fffff580f44f96c8
Arg3: 81000001e0399c66
Arg4: bffff580f44f96c8
Debugging Details:
------------------
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
SYSTEM_MANUFACTURER: Gigabyte Technology Co., Ltd.
SYSTEM_PRODUCT_NAME: AB350M-D3V
SYSTEM_SKU: Default string
SYSTEM_VERSION: Default string
BIOS_VENDOR: American Megatrends Inc.
BIOS_VERSION: F10
BIOS_DATE: 12/01/2017
BASEBOARD_MANUFACTURER: Gigabyte Technology Co., Ltd.
BASEBOARD_PRODUCT: AB350M-D3V-CF
BASEBOARD_VERSION: x.x
DUMP_TYPE: 2
BUGCHECK_P1: 403
BUGCHECK_P2: fffff580f44f96c8
BUGCHECK_P3: 81000001e0399c66
BUGCHECK_P4: bffff580f44f96c8
BUGCHECK_STR: 0x1a_403
CPU_COUNT: 6
CPU_MHZ: ed1
CPU_VENDOR: AuthenticAMD
CPU_FAMILY: 17
CPU_MODEL: 1
CPU_STEPPING: 1
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
PROCESS_NAME: EpicGamesLauncher.exe
CURRENT_IRQL: 2
ANALYSIS_SESSION_HOST: DESKTOP-18V31A3
ANALYSIS_SESSION_TIME: 11-12-2019 21:56:46.0884
ANALYSIS_VERSION: 10.0.18362.1 x86fre
LAST_CONTROL_TRANSFER: from fffff8060da37bc3 to fffff8060d9c1220
STACK_TEXT:
ffffa80f`cef63ca8 fffff806`0da37bc3 : 00000000`0000001a 00000000`00000403 fffff580`f44f96c8 81000001`e0399c66 : nt!KeBugCheckEx
ffffa80f`cef63cb0 fffff806`0d816ca2 : 00000000`00000000 00000000`00b41560 ffffa80f`cef64850 00000000`00000000 : nt!MiDeleteClusterPage+0x159c73
ffffa80f`cef63d50 fffff806`0d8b15c7 : 00000000`00000003 ffffa80f`cef644a0 ffffa80f`cef644a0 ffffa80f`cef643f0 : nt!MiDeletePteRun+0xa42
ffffa80f`cef63f70 fffff806`0d8ad0e2 : ffff978e`62031580 fffff580`f44f9a00 00000000`00000000 00000000`00000000 : nt!MiDeleteVaTail+0x77
ffffa80f`cef63fa0 fffff806`0d8ad271 : ffffa80f`cef643f0 fffff5fa`c07a27c8 00000000`00000000 0a000001`dcf81867 : nt!MiWalkPageTablesRecursively+0x512
ffffa80f`cef64060 fffff806`0d8ad271 : ffffa80f`cef643f0 fffff5fa`fd603d10 00000000`00000000 0a000001`b1817867 : nt!MiWalkPageTablesRecursively+0x6a1
ffffa80f`cef64120 fffff806`0d8ad271 : ffffa80f`cef643f0 fffff5fa`fd7eb018 fffff5fa`00000000 0a000001`b1716867 : nt!MiWalkPageTablesRecursively+0x6a1
ffffa80f`cef641e0 fffff806`0d8ac9fc : ffffa80f`cef643f0 00000000`00000000 ffff978e`00000000 00000000`00000001 : nt!MiWalkPageTablesRecursively+0x6a1
ffffa80f`cef642a0 fffff806`0d8aae68 : ffffa80f`cef643f0 ffffa80f`00000002 00000000`00000001 fffff806`00000000 : nt!MiWalkPageTables+0x36c
ffffa80f`cef643a0 fffff806`0d8b8fc0 : ffffffff`ffffffff ffff978e`620313f8 ffff978e`00000001 00000000`00000000 : nt!MiDeletePagablePteRange+0x268
ffffa80f`cef64740 fffff806`0d85919a : 00000000`1e89f33f ffff978e`6202d080 00000000`00000000 fffff806`0d8b3f9a : nt!MiDeleteVad+0x860
ffffa80f`cef64900 fffff806`0de5b310 : 00000000`00000000 00000000`00000000 ffffa80f`cef64a60 ffffffff`ffffffff : nt!MiFreeVadRange+0x9e
ffffa80f`cef64960 fffff806`0de5af4b : 00000000`00000000 ffff850b`eabf3d40 ffff4b21`a1ca6478 fffff806`0deb275f : nt!MmFreeVirtualMemory+0x390
ffffa80f`cef64aa0 fffff806`0d9d2b15 : ffff978e`6202d080 ffff978e`6209a5e0 00007ff6`f14c28d8 00000000`00000000 : nt!NtFreeVirtualMemory+0x8b
ffffa80f`cef64b00 00007ffc`60f3c484 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
000000a9`dbacf128 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffc`60f3c484
THREAD_SHA1_HASH_MOD_FUNC: e3ee830b3ae3c5d26cdd05cb3808fb689f454486
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: c284d6cf0350191fdf75fcc3f89cc701600209eb
THREAD_SHA1_HASH_MOD: 38bc5fec3f0409c265cf5c87da6f8f8859d0711c
FOLLOWUP_IP:
nt!MiDeleteClusterPage+159c73
fffff806`0da37bc3 cc int 3
FAULT_INSTR_CODE: f01a8cc
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!MiDeleteClusterPage+159c73
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 0
IMAGE_VERSION: 10.0.18362.418
STACK_COMMAND: .thread ; .cxr ; kb
IMAGE_NAME: memory_corruption
BUCKET_ID_FUNC_OFFSET: 159c73
FAILURE_BUCKET_ID: 0x1a_403_nt!MiDeleteClusterPage
BUCKET_ID: 0x1a_403_nt!MiDeleteClusterPage
PRIMARY_PROBLEM_CLASS: 0x1a_403_nt!MiDeleteClusterPage
TARGET_TIME: 2019-11-11T19:24:50.000Z
OSBUILD: 18362
OSSERVICEPACK: 418
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: unknown_date
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: 160b
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0x1a_403_nt!mideleteclusterpage
FAILURE_ID_HASH: {f401e11c-900d-f6cd-c291-93cf0151a773}
Followup: MachineOwner
---------
0: kd> lmvm nt
Browse full module list
start end module name
fffff806`0d800000 fffff806`0e2b6000 nt (pdb symbols) C:\ProgramData\dbg\sym\ntkrnlmp.pdb\E0093F3AEF15D58168B753C9488A40431\ntkrnlmp.pdb
Loaded symbol image file: ntkrnlmp.exe
Mapped memory image file: C:\ProgramData\dbg\sym\ntoskrnl.exe\FC9570F2ab6000\ntoskrnl.exe
Image path: ntkrnlmp.exe
Image name: ntkrnlmp.exe
Browse all global symbols functions data
Image was built with /Brepro flag.
Timestamp: FC9570F2 (This is a reproducible build file hash, not a timestamp)
CheckSum: 0097CABE
ImageSize: 00AB6000
File version: 10.0.18362.418
Product version: 10.0.18362.418
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 1.0 App
File date: 00000000.00000000
Translations: 0409.04b0
Information from resource tables:
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: ntkrnlmp.exe
OriginalFilename: ntkrnlmp.exe
ProductVersion: 10.0.18362.418
FileVersion: 10.0.18362.418 (WinBuild.160101.0800)
FileDescription: NT Kernel & System
LegalCopyright: © Microsoft Corporation. All rights reserved.
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: fffff801764c42d0, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, value 0 = read operation, 1 = write operation
Arg4: fffff80175eed1ba, address which referenced memory
Debugging Details:
------------------
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
SYSTEM_MANUFACTURER: Gigabyte Technology Co., Ltd.
SYSTEM_PRODUCT_NAME: AB350M-D3V
SYSTEM_SKU: Default string
SYSTEM_VERSION: Default string
BIOS_VENDOR: American Megatrends Inc.
BIOS_VERSION: F10
BIOS_DATE: 12/01/2017
BASEBOARD_MANUFACTURER: Gigabyte Technology Co., Ltd.
BASEBOARD_PRODUCT: AB350M-D3V-CF
BASEBOARD_VERSION: x.x
DUMP_TYPE: 2
BUGCHECK_P1: fffff801764c42d0
BUGCHECK_P2: 2
BUGCHECK_P3: 0
BUGCHECK_P4: fffff80175eed1ba
READ_ADDRESS: fffff801733733b8: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
fffff801764c42d0
CURRENT_IRQL: 2
FAULTING_IP:
tcpip!IppProtocolGetNextExpirationTick+b6
fffff801`75eed1ba 48ff150f711d00 call qword ptr [tcpip!_imp_RtlIsTimerWheelSuspended (fffff801`760c42d0)]
CPU_COUNT: 6
CPU_MHZ: ed1
CPU_VENDOR: AuthenticAMD
CPU_FAMILY: 17
CPU_MODEL: 1
CPU_STEPPING: 1
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: AV
PROCESS_NAME: System
ANALYSIS_SESSION_HOST: DESKTOP-18V31A3
ANALYSIS_SESSION_TIME: 11-12-2019 21:56:42.0940
ANALYSIS_VERSION: 10.0.18362.1 x86fre
TRAP_FRAME: ffff9f889ca37590 -- (.trap 0xffff9f889ca37590)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=ffff83880ca7f360
rdx=000000000000003f rsi=0000000000000000 rdi=0000000000000000
rip=fffff80175eed1ba rsp=ffff9f889ca37720 rbp=ffff9f889ca37740
r8=0000000000000000 r9=0000000000005463 r10=ffff83880ca7f360
r11=ffff9f889ca37718 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
tcpip!IppProtocolGetNextExpirationTick+0xb6:
fffff801`75eed1ba 48ff150f711d00 call qword ptr [tcpip!_imp_RtlIsTimerWheelSuspended (fffff801`760c42d0)] ds:fffff801`760c42d0=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80172fd30e9 to fffff80172fc1220
STACK_TEXT:
ffff9f88`9ca37448 fffff801`72fd30e9 : 00000000`0000000a fffff801`764c42d0 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
ffff9f88`9ca37450 fffff801`72fcf42b : ffff8388`0e287010 fffff801`75f079c1 ffff8388`0e287190 00000000`000000c0 : nt!KiBugCheckDispatch+0x69
ffff9f88`9ca37590 fffff801`75eed1ba : 00000000`00000020 fffff801`00000020 ffff9f88`9ca37730 ffff8388`0ca24980 : nt!KiPageFault+0x46b
ffff9f88`9ca37720 fffff801`75eec824 : ffff8388`0000003f fffff801`00000020 ffff8388`0ca54b50 fffff801`7609f2e0 : tcpip!IppProtocolGetNextExpirationTick+0xb6
ffff9f88`9ca37780 fffff801`72e6ba79 : 00000000`00000001 fffff801`760a9120 ffffc480`47cdc180 ffff8388`0e204010 : tcpip!IppTimeout+0x914
ffff9f88`9ca37940 fffff801`72e6a7d9 : 00000000`00000018 00000000`00989680 00000000`00000262 00000000`0000007a : nt!KiProcessExpiredTimerList+0x169
ffff9f88`9ca37a30 fffff801`72fc4d64 : ffffffff`00000000 ffffc480`47cdc180 ffffc480`47ced1c0 ffff8388`10b75080 : nt!KiRetireDpcList+0x4e9
ffff9f88`9ca37c60 00000000`00000000 : ffff9f88`9ca38000 ffff9f88`9ca32000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x84
THREAD_SHA1_HASH_MOD_FUNC: f66ab1163e8ed32b51e4a44f038ecb8025d76c4d
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: e9cc81c387fdfc8f8e9a1940124988c8a592fd14
THREAD_SHA1_HASH_MOD: a29dc2cce02a8546a1ac208145ad853692c385b3
FOLLOWUP_IP:
tcpip!IppProtocolGetNextExpirationTick+b6
fffff801`75eed1ba 48ff150f711d00 call qword ptr [tcpip!_imp_RtlIsTimerWheelSuspended (fffff801`760c42d0)]
FAULT_INSTR_CODE: f15ff48
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: tcpip!IppProtocolGetNextExpirationTick+b6
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: tcpip
IMAGE_NAME: tcpip.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 61ae2576
IMAGE_VERSION: 10.0.18362.295
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: b6
FAILURE_BUCKET_ID: AV_tcpip!IppProtocolGetNextExpirationTick
BUCKET_ID: AV_tcpip!IppProtocolGetNextExpirationTick
PRIMARY_PROBLEM_CLASS: AV_tcpip!IppProtocolGetNextExpirationTick
TARGET_TIME: 2019-11-10T14:16:16.000Z
OSBUILD: 18362
OSSERVICEPACK: 418
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: unknown_date
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: a2b
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:av_tcpip!ippprotocolgetnextexpirationtick
FAILURE_ID_HASH: {7e28b96c-bb88-5146-2504-6eddd59d4363}
Followup: MachineOwner
---------
2: kd> lmvm tcpip
Browse full module list
start end module name
fffff801`75ea0000 fffff801`7618a000 tcpip (pdb symbols) C:\ProgramData\dbg\sym\tcpip.pdb\D4924BA536B401A0DC772BC5617367AB1\tcpip.pdb
Loaded symbol image file: tcpip.sys
Mapped memory image file: C:\ProgramData\dbg\sym\tcpip.sys\61AE25762ea000\tcpip.sys
Image path: \SystemRoot\System32\drivers\tcpip.sys
Image name: tcpip.sys
Browse all global symbols functions data
Image was built with /Brepro flag.
Timestamp: 61AE2576 (This is a reproducible build file hash, not a timestamp)
CheckSum: 002E66D9
ImageSize: 002EA000
File version: 10.0.18362.295
Product version: 10.0.18362.295
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.6 Driver
File date: 00000000.00000000
Translations: 0409.04b0
Information from resource tables:
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: tcpip.sys
OriginalFilename: tcpip.sys
ProductVersion: 10.0.18362.295
FileVersion: 10.0.18362.295 (WinBuild.160101.0800)
FileDescription: TCP/IP Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff80e3a8ba0b8, The address that the exception occurred at
Arg3: ffffbe0008406658, Exception Record Address
Arg4: ffffbe0008405ea0, Context Record Address
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : AV.Dereference
Value: NullPtr
Key : AV.Fault
Value: Write
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
DUMP_TYPE: 2
BUGCHECK_P1: ffffffffc0000005
BUGCHECK_P2: fffff80e3a8ba0b8
BUGCHECK_P3: ffffbe0008406658
BUGCHECK_P4: ffffbe0008405ea0
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text>
FAULTING_IP:
ahcache!DriverEntry+40
fffff80e`3a8ba0b8 0000 add byte ptr [rax],al
EXCEPTION_RECORD: ffffbe0008406658 -- (.exr 0xffffbe0008406658)
ExceptionAddress: fffff80e3a8ba0b8 (ahcache!DriverEntry+0x0000000000000040)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000001
Parameter[1]: 0000000000000000
Attempt to write to address 0000000000000000
CONTEXT: ffffbe0008405ea0 -- (.cxr 0xffffbe0008405ea0)
rax=0000000000000000 rbx=ffffbf8c291f6000 rcx=ffffbe00084068d0
rdx=fffff80e3a877150 rsi=ffffbf8c24802e10 rdi=441f0ffffd209b15
rip=fffff80e3a8ba0b8 rsp=ffffbe0008406890 rbp=ffffbe00084068f0
r8=0000000000000000 r9=0000000000000000 r10=fffff80e3a8ba010
r11=0000000000000000 r12=ffffffff80000178 r13=0000000000000002
r14=ffff8609b3aee470 r15=ffffbf8c291f6000
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050246
ahcache!DriverEntry+0x40:
fffff80e`3a8ba0b8 0000 add byte ptr [rax],al ds:002b:00000000`00000000=??
Resetting default scope
CPU_COUNT: c
CPU_MHZ: ed1
CPU_VENDOR: AuthenticAMD
CPU_FAMILY: 17
CPU_MODEL: 1
CPU_STEPPING: 1
BLACKBOXNTFS: 1 (!blackboxntfs)
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: NULL_DEREFERENCE
PROCESS_NAME: System
CURRENT_IRQL: 0
FOLLOWUP_IP:
ahcache!DriverEntry+40
fffff80e`3a8ba0b8 0000 add byte ptr [rax],al
BUGCHECK_STR: AV
WRITE_ADDRESS: fffff801257733b8: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
0000000000000000
ERROR_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text>
EXCEPTION_CODE_STR: c0000005
EXCEPTION_PARAMETER1: 0000000000000001
EXCEPTION_PARAMETER2: 0000000000000000
ANALYSIS_SESSION_HOST: DESKTOP-18V31A3
ANALYSIS_SESSION_TIME: 11-12-2019 21:56:38.0885
ANALYSIS_VERSION: 10.0.18362.1 x86fre
LAST_CONTROL_TRANSFER: from fffff80e3a8ba030 to fffff80e3a8ba0b8
STACK_TEXT:
ffffbe00`08406890 fffff80e`3a8ba030 : ffffbf8c`291f6000 ffffbf8c`24802e10 00000000`00000000 ffff94fc`1828780a : ahcache!DriverEntry+0x40
ffffbe00`08406900 fffff801`2590f1f6 : 00000000`00000000 00000000`00000000 ffffbf8c`24802e10 ffffffff`80000178 : ahcache!GsDriverEntry+0x20
ffffbe00`08406930 fffff801`25c11561 : ffffbf8c`26fc7998 ffffbf8c`26fc7998 ffffbe00`08406b80 00000000`00000000 : nt!IopLoadDriver+0x4c2
ffffbe00`08406b10 fffff801`25c10752 : fffff801`00000000 ffff8609`b5019c50 00000000`00000000 fffff801`20a92dd0 : nt!IopInitializeSystemDrivers+0x151
ffffbe00`08406bb0 fffff801`25961422 : fffff801`20a92dd0 fffff801`20a92dd0 fffff801`259613e0 fffff801`20a92dd0 : nt!IoInitSystem+0x12
ffffbe00`08406be0 fffff801`2532a725 : ffffbf8c`2467d180 fffff801`259613e0 fffff801`20a92dd0 00000000`00000000 : nt!Phase1Initialization+0x42
ffffbe00`08406c10 fffff801`253c886a : fffff801`20e02180 ffffbf8c`2467d180 fffff801`2532a6d0 00000000`00000000 : nt!PspSystemThreadStartup+0x55
ffffbe00`08406c60 00000000`00000000 : ffffbe00`08407000 ffffbe00`08401000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x2a
THREAD_SHA1_HASH_MOD_FUNC: 6cdee51db84f8036131c91b91c86295cc15cc8e1
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 1328a52c2f3c430f868941289c58f19d2df517a5
THREAD_SHA1_HASH_MOD: 8a27bc4b75963fa409f2e038a5f1ec4bbd3674bb
FAULT_INSTR_CODE: d88b0000
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: ahcache!DriverEntry+40
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: ahcache
IMAGE_NAME: ahcache.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 0
IMAGE_VERSION: 10.0.18362.1216
STACK_COMMAND: .cxr 0xffffbe0008405ea0 ; kb
BUCKET_ID_FUNC_OFFSET: 40
FAILURE_BUCKET_ID: AV_ahcache!DriverEntry
BUCKET_ID: AV_ahcache!DriverEntry
PRIMARY_PROBLEM_CLASS: AV_ahcache!DriverEntry
TARGET_TIME: 2019-11-08T18:33:29.000Z
OSBUILD: 18362
OSSERVICEPACK: 418
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: unknown_date
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: 3a4c
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:av_ahcache!driverentry
FAILURE_ID_HASH: {74b70fc8-87a4-dbe7-e6b1-1484701ff95f}
Followup: MachineOwner
---------
11: kd> lmvm ahcache
Browse full module list
start end module name
fffff80e`3a870000 fffff80e`3a8bf000 ahcache # (pdb symbols) C:\ProgramData\dbg\sym\ahcache.pdb\8D0BE32731068C8D79BCD4D1AED3CBE01\ahcache.pdb
Loaded symbol image file: ahcache.sys
Mapped memory image file: C:\ProgramData\dbg\sym\ahcache.sys\A8473BE24f000\ahcache.sys
Image path: \SystemRoot\system32\DRIVERS\ahcache.sys
Image name: ahcache.sys
Browse all global symbols functions data
Image was built with /Brepro flag.
Timestamp: A8473BE2 (This is a reproducible build file hash, not a timestamp)
CheckSum: 00056682
ImageSize: 0004F000
File version: 10.0.18362.1216
Product version: 10.0.18362.1216
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
Information from resource tables:
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: ahcache.sys
OriginalFilename: ahcache.sys
ProductVersion: 10.0.18362.1216
FileVersion: 10.0.18362.1216 (WinBuild.160101.0800)
FileDescription: Application Compatibility Cache
LegalCopyright: © Microsoft Corporation. All rights reserved.
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except.
Typically the address is just plain bad or it is pointing at freed memory.
Arguments:
Arg1: ffffb18ae6205201, memory referenced.
Arg2: 0000000000000011, value 0 = read operation, 1 = write operation.
Arg3: ffffb18ae6205201, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000002, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
DUMP_TYPE: 2
BUGCHECK_P1: ffffb18ae6205201
BUGCHECK_P2: 11
BUGCHECK_P3: ffffb18ae6205201
BUGCHECK_P4: 2
WRITE_ADDRESS: fffff806573733b8: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
ffffb18ae6205201
FAULTING_IP:
+0
ffffb18a`e6205201 0000 add byte ptr [rax],al
MM_INTERNAL_CODE: 2
CPU_COUNT: c
CPU_MHZ: e09
CPU_VENDOR: AuthenticAMD
CPU_FAMILY: 17
CPU_MODEL: 1
CPU_STEPPING: 1
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: AV
PROCESS_NAME: System
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-18V31A3
ANALYSIS_SESSION_TIME: 11-12-2019 21:56:33.0686
ANALYSIS_VERSION: 10.0.18362.1 x86fre
TRAP_FRAME: ffffb18ae6204f00 -- (.trap 0xffffb18ae6204f00)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffffb18ae6205290 rbx=0000000000000000 rcx=0000000000008000
rdx=ffffb30ae5daab80 rsi=0000000000000000 rdi=0000000000000000
rip=ffffb18ae6205201 rsp=ffffb18ae6205098 rbp=ffffb18ae6205280
r8=ffffb30ae5da6180 r9=0000000000000000 r10=ffff9e09948a9a10
r11=ffffb18ae62050e0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe nc
ffffb18a`e6205201 0000 add byte ptr [rax],al ds:ffffb18a`e6205290=01
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80656fe33d6 to fffff80656fc1220
STACK_TEXT:
ffffb18a`e6204c58 fffff806`56fe33d6 : 00000000`00000050 ffffb18a`e6205201 00000000`00000011 ffffb18a`e6204f00 : nt!KeBugCheckEx
ffffb18a`e6204c60 fffff806`56e72edf : 00000000`00000000 00000000`00000011 00000000`00000000 ffffb18a`e6205201 : nt!MiSystemFault+0x1d66a6
ffffb18a`e6204d60 fffff806`56fcf320 : 00000000`00000030 fffff806`00000000 00000000`00000000 fffff8fc`7e33c130 : nt!MmAccessFault+0x34f
ffffb18a`e6204f00 ffffb18a`e6205201 : 00000000`00989680 00000000`00000002 00000000`00000001 ffffb18a`e62050e0 : nt!KiPageFault+0x360
ffffb18a`e6205098 00000000`00989680 : 00000000`00000002 00000000`00000001 ffffb18a`e62050e0 ffffb18a`e6205120 : 0xffffb18a`e6205201
ffffb18a`e62050a0 00000000`00000002 : 00000000`00000001 ffffb18a`e62050e0 ffffb18a`e6205120 00000000`00000001 : 0x989680
ffffb18a`e62050a8 00000000`00000001 : ffffb18a`e62050e0 ffffb18a`e6205120 00000000`00000001 ffffb18a`e6205278 : 0x2
ffffb18a`e62050b0 ffffb18a`e62050e0 : ffffb18a`e6205120 00000000`00000001 ffffb18a`e6205278 00000000`00000001 : 0x1
ffffb18a`e62050b8 ffffb18a`e6205120 : 00000000`00000001 ffffb18a`e6205278 00000000`00000001 00000000`00000101 : 0xffffb18a`e62050e0
ffffb18a`e62050c0 00000000`00000001 : ffffb18a`e6205278 00000000`00000001 00000000`00000101 ffff9e09`948a9a10 : 0xffffb18a`e6205120
ffffb18a`e62050c8 ffffb18a`e6205278 : 00000000`00000001 00000000`00000101 ffff9e09`948a9a10 ffffb30a`e5bc8c98 : 0x1
ffffb18a`e62050d0 00000000`00000001 : 00000000`00000101 ffff9e09`948a9a10 ffffb30a`e5bc8c98 ffffb30a`00008000 : 0xffffb18a`e6205278
ffffb18a`e62050d8 00000000`00000101 : ffff9e09`948a9a10 ffffb30a`e5bc8c98 ffffb30a`00008000 fffff806`00000002 : 0x1
ffffb18a`e62050e0 ffff9e09`948a9a10 : ffffb30a`e5bc8c98 ffffb30a`00008000 fffff806`00000002 00000000`00365000 : 0x101
ffffb18a`e62050e8 ffffb30a`e5bc8c98 : ffffb30a`00008000 fffff806`00000002 00000000`00365000 ffffb30a`e5d2a940 : 0xffff9e09`948a9a10
ffffb18a`e62050f0 ffffb30a`00008000 : fffff806`00000002 00000000`00365000 ffffb30a`e5d2a940 00008000`00008000 : 0xffffb30a`e5bc8c98
ffffb18a`e62050f8 fffff806`00000002 : 00000000`00365000 ffffb30a`e5d2a940 00008000`00008000 ffffb30a`e5d2a940 : 0xffffb30a`00008000
ffffb18a`e6205100 00000000`00365000 : ffffb30a`e5d2a940 00008000`00008000 ffffb30a`e5d2a940 ffff9e09`948a9c70 : 0xfffff806`00000002
ffffb18a`e6205108 ffffb30a`e5d2a940 : 00008000`00008000 ffffb30a`e5d2a940 ffff9e09`948a9c70 ffffb18a`00000000 : 0x365000
ffffb18a`e6205110 00008000`00008000 : ffffb30a`e5d2a940 ffff9e09`948a9c70 ffffb18a`00000000 00000000`00008000 : 0xffffb30a`e5d2a940
ffffb18a`e6205118 ffffb30a`e5d2a940 : ffff9e09`948a9c70 ffffb18a`00000000 00000000`00008000 00000000`00000000 : 0x00008000`00008000
ffffb18a`e6205120 ffff9e09`948a9c70 : ffffb18a`00000000 00000000`00008000 00000000`00000000 ffffb30a`e5bc8ca0 : 0xffffb30a`e5d2a940
ffffb18a`e6205128 ffffb18a`00000000 : 00000000`00008000 00000000`00000000 ffffb30a`e5bc8ca0 ffffb30a`e5da6180 : 0xffff9e09`948a9c70
ffffb18a`e6205130 00000000`00008000 : 00000000`00000000 ffffb30a`e5bc8ca0 ffffb30a`e5da6180 ffffb30a`e5d97090 : 0xffffb18a`00000000
ffffb18a`e6205138 00000000`00000000 : ffffb30a`e5bc8ca0 ffffb30a`e5da6180 ffffb30a`e5d97090 00000000`0036d000 : 0x8000
THREAD_SHA1_HASH_MOD_FUNC: 35852f70c1fb96d682b5bd0e931cc10c7b9fe1fe
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 0557a0823cb15180d0326192f359dade515cb1e4
THREAD_SHA1_HASH_MOD: d084f7dfa548ce4e51810e4fd5914176ebc66791
FOLLOWUP_IP:
nt!MiSystemFault+1d66a6
fffff806`56fe33d6 cc int 3
FAULT_INSTR_CODE: 4d8d48cc
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!MiSystemFault+1d66a6
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 0
IMAGE_VERSION: 10.0.18362.418
STACK_COMMAND: .thread ; .cxr ; kb
IMAGE_NAME: memory_corruption
BUCKET_ID_FUNC_OFFSET: 1d66a6
FAILURE_BUCKET_ID: AV_INVALID_nt!MiSystemFault
BUCKET_ID: AV_INVALID_nt!MiSystemFault
PRIMARY_PROBLEM_CLASS: AV_INVALID_nt!MiSystemFault
TARGET_TIME: 2019-11-06T17:46:19.000Z
OSBUILD: 18362
OSSERVICEPACK: 418
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: unknown_date
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: 4d50
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:av_invalid_nt!misystemfault
FAILURE_ID_HASH: {8a33c6b1-a9f1-4efe-025b-a861cc33d6e2}
Followup: MachineOwner
---------
11: kd> lmvm nt
Browse full module list
start end module name
fffff806`56e00000 fffff806`578b6000 nt (pdb symbols) C:\ProgramData\dbg\sym\ntkrnlmp.pdb\E0093F3AEF15D58168B753C9488A40431\ntkrnlmp.pdb
Loaded symbol image file: ntkrnlmp.exe
Mapped memory image file: C:\ProgramData\dbg\sym\ntoskrnl.exe\FC9570F2ab6000\ntoskrnl.exe
Image path: ntkrnlmp.exe
Image name: ntkrnlmp.exe
Browse all global symbols functions data
Image was built with /Brepro flag.
Timestamp: FC9570F2 (This is a reproducible build file hash, not a timestamp)
CheckSum: 0097CABE
ImageSize: 00AB6000
File version: 10.0.18362.418
Product version: 10.0.18362.418
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 1.0 App
File date: 00000000.00000000
Translations: 0409.04b0
Information from resource tables:
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: ntkrnlmp.exe
OriginalFilename: ntkrnlmp.exe
ProductVersion: 10.0.18362.418
FileVersion: 10.0.18362.418 (WinBuild.160101.0800)
FileDescription: NT Kernel & System
LegalCopyright: © Microsoft Corporation. All rights reserved.