*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000000403, The subtype of the bugcheck.
Arg2: fffff580f44f96c8
Arg3: 81000001e0399c66
Arg4: bffff580f44f96c8
Debugging Details:
------------------
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
SYSTEM_MANUFACTURER: Gigabyte Technology Co., Ltd.
SYSTEM_PRODUCT_NAME: AB350M-D3V
SYSTEM_SKU: Default string
SYSTEM_VERSION: Default string
BIOS_VENDOR: American Megatrends Inc.
BIOS_VERSION: F10
BIOS_DATE: 12/01/2017
BASEBOARD_MANUFACTURER: Gigabyte Technology Co., Ltd.
BASEBOARD_PRODUCT: AB350M-D3V-CF
BASEBOARD_VERSION: x.x
DUMP_TYPE: 2
BUGCHECK_P1: 403
BUGCHECK_P2: fffff580f44f96c8
BUGCHECK_P3: 81000001e0399c66
BUGCHECK_P4: bffff580f44f96c8
BUGCHECK_STR: 0x1a_403
CPU_COUNT: 6
CPU_MHZ: ed1
CPU_VENDOR: AuthenticAMD
CPU_FAMILY: 17
CPU_MODEL: 1
CPU_STEPPING: 1
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
PROCESS_NAME: EpicGamesLauncher.exe
CURRENT_IRQL: 2
ANALYSIS_SESSION_HOST: DESKTOP-18V31A3
ANALYSIS_SESSION_TIME: 11-12-2019 21:56:46.0884
ANALYSIS_VERSION: 10.0.18362.1 x86fre
LAST_CONTROL_TRANSFER: from fffff8060da37bc3 to fffff8060d9c1220
STACK_TEXT:
ffffa80f`cef63ca8 fffff806`0da37bc3 : 00000000`0000001a 00000000`00000403 fffff580`f44f96c8 81000001`e0399c66 : nt!KeBugCheckEx
ffffa80f`cef63cb0 fffff806`0d816ca2 : 00000000`00000000 00000000`00b41560 ffffa80f`cef64850 00000000`00000000 : nt!MiDeleteClusterPage+0x159c73
ffffa80f`cef63d50 fffff806`0d8b15c7 : 00000000`00000003 ffffa80f`cef644a0 ffffa80f`cef644a0 ffffa80f`cef643f0 : nt!MiDeletePteRun+0xa42
ffffa80f`cef63f70 fffff806`0d8ad0e2 : ffff978e`62031580 fffff580`f44f9a00 00000000`00000000 00000000`00000000 : nt!MiDeleteVaTail+0x77
ffffa80f`cef63fa0 fffff806`0d8ad271 : ffffa80f`cef643f0 fffff5fa`c07a27c8 00000000`00000000 0a000001`dcf81867 : nt!MiWalkPageTablesRecursively+0x512
ffffa80f`cef64060 fffff806`0d8ad271 : ffffa80f`cef643f0 fffff5fa`fd603d10 00000000`00000000 0a000001`b1817867 : nt!MiWalkPageTablesRecursively+0x6a1
ffffa80f`cef64120 fffff806`0d8ad271 : ffffa80f`cef643f0 fffff5fa`fd7eb018 fffff5fa`00000000 0a000001`b1716867 : nt!MiWalkPageTablesRecursively+0x6a1
ffffa80f`cef641e0 fffff806`0d8ac9fc : ffffa80f`cef643f0 00000000`00000000 ffff978e`00000000 00000000`00000001 : nt!MiWalkPageTablesRecursively+0x6a1
ffffa80f`cef642a0 fffff806`0d8aae68 : ffffa80f`cef643f0 ffffa80f`00000002 00000000`00000001 fffff806`00000000 : nt!MiWalkPageTables+0x36c
ffffa80f`cef643a0 fffff806`0d8b8fc0 : ffffffff`ffffffff ffff978e`620313f8 ffff978e`00000001 00000000`00000000 : nt!MiDeletePagablePteRange+0x268
ffffa80f`cef64740 fffff806`0d85919a : 00000000`1e89f33f ffff978e`6202d080 00000000`00000000 fffff806`0d8b3f9a : nt!MiDeleteVad+0x860
ffffa80f`cef64900 fffff806`0de5b310 : 00000000`00000000 00000000`00000000 ffffa80f`cef64a60 ffffffff`ffffffff : nt!MiFreeVadRange+0x9e
ffffa80f`cef64960 fffff806`0de5af4b : 00000000`00000000 ffff850b`eabf3d40 ffff4b21`a1ca6478 fffff806`0deb275f : nt!MmFreeVirtualMemory+0x390
ffffa80f`cef64aa0 fffff806`0d9d2b15 : ffff978e`6202d080 ffff978e`6209a5e0 00007ff6`f14c28d8 00000000`00000000 : nt!NtFreeVirtualMemory+0x8b
ffffa80f`cef64b00 00007ffc`60f3c484 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
000000a9`dbacf128 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffc`60f3c484
THREAD_SHA1_HASH_MOD_FUNC: e3ee830b3ae3c5d26cdd05cb3808fb689f454486
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: c284d6cf0350191fdf75fcc3f89cc701600209eb
THREAD_SHA1_HASH_MOD: 38bc5fec3f0409c265cf5c87da6f8f8859d0711c
FOLLOWUP_IP:
nt!MiDeleteClusterPage+159c73
fffff806`0da37bc3 cc int 3
FAULT_INSTR_CODE: f01a8cc
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!MiDeleteClusterPage+159c73
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 0
IMAGE_VERSION: 10.0.18362.418
STACK_COMMAND: .thread ; .cxr ; kb
IMAGE_NAME: memory_corruption
BUCKET_ID_FUNC_OFFSET: 159c73
FAILURE_BUCKET_ID: 0x1a_403_nt!MiDeleteClusterPage
BUCKET_ID: 0x1a_403_nt!MiDeleteClusterPage
PRIMARY_PROBLEM_CLASS: 0x1a_403_nt!MiDeleteClusterPage
TARGET_TIME: 2019-11-11T19:24:50.000Z
OSBUILD: 18362
OSSERVICEPACK: 418
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: unknown_date
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: 160b
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0x1a_403_nt!mideleteclusterpage
FAILURE_ID_HASH: {f401e11c-900d-f6cd-c291-93cf0151a773}
Followup: MachineOwner
---------
0: kd> lmvm nt
Browse full module list
start end module name
fffff806`0d800000 fffff806`0e2b6000 nt (pdb symbols) C:\ProgramData\dbg\sym\ntkrnlmp.pdb\E0093F3AEF15D58168B753C9488A40431\ntkrnlmp.pdb
Loaded symbol image file: ntkrnlmp.exe
Mapped memory image file: C:\ProgramData\dbg\sym\ntoskrnl.exe\FC9570F2ab6000\ntoskrnl.exe
Image path: ntkrnlmp.exe
Image name: ntkrnlmp.exe
Browse all global symbols functions data
Image was built with /Brepro flag.
Timestamp: FC9570F2 (This is a reproducible build file hash, not a timestamp)
CheckSum: 0097CABE
ImageSize: 00AB6000
File version: 10.0.18362.418
Product version: 10.0.18362.418
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 1.0 App
File date: 00000000.00000000
Translations: 0409.04b0
Information from resource tables:
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: ntkrnlmp.exe
OriginalFilename: ntkrnlmp.exe
ProductVersion: 10.0.18362.418
FileVersion: 10.0.18362.418 (WinBuild.160101.0800)
FileDescription: NT Kernel & System
LegalCopyright: © Microsoft Corporation. All rights reserved.
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: fffff801764c42d0, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, value 0 = read operation, 1 = write operation
Arg4: fffff80175eed1ba, address which referenced memory
Debugging Details:
------------------
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
SYSTEM_MANUFACTURER: Gigabyte Technology Co., Ltd.
SYSTEM_PRODUCT_NAME: AB350M-D3V
SYSTEM_SKU: Default string
SYSTEM_VERSION: Default string
BIOS_VENDOR: American Megatrends Inc.
BIOS_VERSION: F10
BIOS_DATE: 12/01/2017
BASEBOARD_MANUFACTURER: Gigabyte Technology Co., Ltd.
BASEBOARD_PRODUCT: AB350M-D3V-CF
BASEBOARD_VERSION: x.x
DUMP_TYPE: 2
BUGCHECK_P1: fffff801764c42d0
BUGCHECK_P2: 2
BUGCHECK_P3: 0
BUGCHECK_P4: fffff80175eed1ba
READ_ADDRESS: fffff801733733b8: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
fffff801764c42d0
CURRENT_IRQL: 2
FAULTING_IP:
tcpip!IppProtocolGetNextExpirationTick+b6
fffff801`75eed1ba 48ff150f711d00 call qword ptr [tcpip!_imp_RtlIsTimerWheelSuspended (fffff801`760c42d0)]
CPU_COUNT: 6
CPU_MHZ: ed1
CPU_VENDOR: AuthenticAMD
CPU_FAMILY: 17
CPU_MODEL: 1
CPU_STEPPING: 1
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: AV
PROCESS_NAME: System
ANALYSIS_SESSION_HOST: DESKTOP-18V31A3
ANALYSIS_SESSION_TIME: 11-12-2019 21:56:42.0940
ANALYSIS_VERSION: 10.0.18362.1 x86fre
TRAP_FRAME: ffff9f889ca37590 -- (.trap 0xffff9f889ca37590)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=ffff83880ca7f360
rdx=000000000000003f rsi=0000000000000000 rdi=0000000000000000
rip=fffff80175eed1ba rsp=ffff9f889ca37720 rbp=ffff9f889ca37740
r8=0000000000000000 r9=0000000000005463 r10=ffff83880ca7f360
r11=ffff9f889ca37718 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
tcpip!IppProtocolGetNextExpirationTick+0xb6:
fffff801`75eed1ba 48ff150f711d00 call qword ptr [tcpip!_imp_RtlIsTimerWheelSuspended (fffff801`760c42d0)] ds:fffff801`760c42d0=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80172fd30e9 to fffff80172fc1220
STACK_TEXT:
ffff9f88`9ca37448 fffff801`72fd30e9 : 00000000`0000000a fffff801`764c42d0 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
ffff9f88`9ca37450 fffff801`72fcf42b : ffff8388`0e287010 fffff801`75f079c1 ffff8388`0e287190 00000000`000000c0 : nt!KiBugCheckDispatch+0x69
ffff9f88`9ca37590 fffff801`75eed1ba : 00000000`00000020 fffff801`00000020 ffff9f88`9ca37730 ffff8388`0ca24980 : nt!KiPageFault+0x46b
ffff9f88`9ca37720 fffff801`75eec824 : ffff8388`0000003f fffff801`00000020 ffff8388`0ca54b50 fffff801`7609f2e0 : tcpip!IppProtocolGetNextExpirationTick+0xb6
ffff9f88`9ca37780 fffff801`72e6ba79 : 00000000`00000001 fffff801`760a9120 ffffc480`47cdc180 ffff8388`0e204010 : tcpip!IppTimeout+0x914
ffff9f88`9ca37940 fffff801`72e6a7d9 : 00000000`00000018 00000000`00989680 00000000`00000262 00000000`0000007a : nt!KiProcessExpiredTimerList+0x169
ffff9f88`9ca37a30 fffff801`72fc4d64 : ffffffff`00000000 ffffc480`47cdc180 ffffc480`47ced1c0 ffff8388`10b75080 : nt!KiRetireDpcList+0x4e9
ffff9f88`9ca37c60 00000000`00000000 : ffff9f88`9ca38000 ffff9f88`9ca32000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x84
THREAD_SHA1_HASH_MOD_FUNC: f66ab1163e8ed32b51e4a44f038ecb8025d76c4d
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: e9cc81c387fdfc8f8e9a1940124988c8a592fd14
THREAD_SHA1_HASH_MOD: a29dc2cce02a8546a1ac208145ad853692c385b3
FOLLOWUP_IP:
tcpip!IppProtocolGetNextExpirationTick+b6
fffff801`75eed1ba 48ff150f711d00 call qword ptr [tcpip!_imp_RtlIsTimerWheelSuspended (fffff801`760c42d0)]
FAULT_INSTR_CODE: f15ff48
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: tcpip!IppProtocolGetNextExpirationTick+b6
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: tcpip
IMAGE_NAME: tcpip.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 61ae2576
IMAGE_VERSION: 10.0.18362.295
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: b6
FAILURE_BUCKET_ID: AV_tcpip!IppProtocolGetNextExpirationTick
BUCKET_ID: AV_tcpip!IppProtocolGetNextExpirationTick
PRIMARY_PROBLEM_CLASS: AV_tcpip!IppProtocolGetNextExpirationTick
TARGET_TIME: 2019-11-10T14:16:16.000Z
OSBUILD: 18362
OSSERVICEPACK: 418
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: unknown_date
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: a2b
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:av_tcpip!ippprotocolgetnextexpirationtick
FAILURE_ID_HASH: {7e28b96c-bb88-5146-2504-6eddd59d4363}
Followup: MachineOwner
---------
2: kd> lmvm tcpip
Browse full module list
start end module name
fffff801`75ea0000 fffff801`7618a000 tcpip (pdb symbols) C:\ProgramData\dbg\sym\tcpip.pdb\D4924BA536B401A0DC772BC5617367AB1\tcpip.pdb
Loaded symbol image file: tcpip.sys
Mapped memory image file: C:\ProgramData\dbg\sym\tcpip.sys\61AE25762ea000\tcpip.sys
Image path: \SystemRoot\System32\drivers\tcpip.sys
Image name: tcpip.sys
Browse all global symbols functions data
Image was built with /Brepro flag.
Timestamp: 61AE2576 (This is a reproducible build file hash, not a timestamp)
CheckSum: 002E66D9
ImageSize: 002EA000
File version: 10.0.18362.295
Product version: 10.0.18362.295
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.6 Driver
File date: 00000000.00000000
Translations: 0409.04b0
Information from resource tables:
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: tcpip.sys
OriginalFilename: tcpip.sys
ProductVersion: 10.0.18362.295
FileVersion: 10.0.18362.295 (WinBuild.160101.0800)
FileDescription: TCP/IP Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff80e3a8ba0b8, The address that the exception occurred at
Arg3: ffffbe0008406658, Exception Record Address
Arg4: ffffbe0008405ea0, Context Record Address
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : AV.Dereference
Value: NullPtr
Key : AV.Fault
Value: Write
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
DUMP_TYPE: 2
BUGCHECK_P1: ffffffffc0000005
BUGCHECK_P2: fffff80e3a8ba0b8
BUGCHECK_P3: ffffbe0008406658
BUGCHECK_P4: ffffbe0008405ea0
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text>
FAULTING_IP:
ahcache!DriverEntry+40
fffff80e`3a8ba0b8 0000 add byte ptr [rax],al
EXCEPTION_RECORD: ffffbe0008406658 -- (.exr 0xffffbe0008406658)
ExceptionAddress: fffff80e3a8ba0b8 (ahcache!DriverEntry+0x0000000000000040)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000001
Parameter[1]: 0000000000000000
Attempt to write to address 0000000000000000
CONTEXT: ffffbe0008405ea0 -- (.cxr 0xffffbe0008405ea0)
rax=0000000000000000 rbx=ffffbf8c291f6000 rcx=ffffbe00084068d0
rdx=fffff80e3a877150 rsi=ffffbf8c24802e10 rdi=441f0ffffd209b15
rip=fffff80e3a8ba0b8 rsp=ffffbe0008406890 rbp=ffffbe00084068f0
r8=0000000000000000 r9=0000000000000000 r10=fffff80e3a8ba010
r11=0000000000000000 r12=ffffffff80000178 r13=0000000000000002
r14=ffff8609b3aee470 r15=ffffbf8c291f6000
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050246
ahcache!DriverEntry+0x40:
fffff80e`3a8ba0b8 0000 add byte ptr [rax],al ds:002b:00000000`00000000=??
Resetting default scope
CPU_COUNT: c
CPU_MHZ: ed1
CPU_VENDOR: AuthenticAMD
CPU_FAMILY: 17
CPU_MODEL: 1
CPU_STEPPING: 1
BLACKBOXNTFS: 1 (!blackboxntfs)
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: NULL_DEREFERENCE
PROCESS_NAME: System
CURRENT_IRQL: 0
FOLLOWUP_IP:
ahcache!DriverEntry+40
fffff80e`3a8ba0b8 0000 add byte ptr [rax],al
BUGCHECK_STR: AV
WRITE_ADDRESS: fffff801257733b8: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
0000000000000000
ERROR_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text>
EXCEPTION_CODE_STR: c0000005
EXCEPTION_PARAMETER1: 0000000000000001
EXCEPTION_PARAMETER2: 0000000000000000
ANALYSIS_SESSION_HOST: DESKTOP-18V31A3
ANALYSIS_SESSION_TIME: 11-12-2019 21:56:38.0885
ANALYSIS_VERSION: 10.0.18362.1 x86fre
LAST_CONTROL_TRANSFER: from fffff80e3a8ba030 to fffff80e3a8ba0b8
STACK_TEXT:
ffffbe00`08406890 fffff80e`3a8ba030 : ffffbf8c`291f6000 ffffbf8c`24802e10 00000000`00000000 ffff94fc`1828780a : ahcache!DriverEntry+0x40
ffffbe00`08406900 fffff801`2590f1f6 : 00000000`00000000 00000000`00000000 ffffbf8c`24802e10 ffffffff`80000178 : ahcache!GsDriverEntry+0x20
ffffbe00`08406930 fffff801`25c11561 : ffffbf8c`26fc7998 ffffbf8c`26fc7998 ffffbe00`08406b80 00000000`00000000 : nt!IopLoadDriver+0x4c2
ffffbe00`08406b10 fffff801`25c10752 : fffff801`00000000 ffff8609`b5019c50 00000000`00000000 fffff801`20a92dd0 : nt!IopInitializeSystemDrivers+0x151
ffffbe00`08406bb0 fffff801`25961422 : fffff801`20a92dd0 fffff801`20a92dd0 fffff801`259613e0 fffff801`20a92dd0 : nt!IoInitSystem+0x12
ffffbe00`08406be0 fffff801`2532a725 : ffffbf8c`2467d180 fffff801`259613e0 fffff801`20a92dd0 00000000`00000000 : nt!Phase1Initialization+0x42
ffffbe00`08406c10 fffff801`253c886a : fffff801`20e02180 ffffbf8c`2467d180 fffff801`2532a6d0 00000000`00000000 : nt!PspSystemThreadStartup+0x55
ffffbe00`08406c60 00000000`00000000 : ffffbe00`08407000 ffffbe00`08401000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x2a
THREAD_SHA1_HASH_MOD_FUNC: 6cdee51db84f8036131c91b91c86295cc15cc8e1
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 1328a52c2f3c430f868941289c58f19d2df517a5
THREAD_SHA1_HASH_MOD: 8a27bc4b75963fa409f2e038a5f1ec4bbd3674bb
FAULT_INSTR_CODE: d88b0000
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: ahcache!DriverEntry+40
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: ahcache
IMAGE_NAME: ahcache.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 0
IMAGE_VERSION: 10.0.18362.1216
STACK_COMMAND: .cxr 0xffffbe0008405ea0 ; kb
BUCKET_ID_FUNC_OFFSET: 40
FAILURE_BUCKET_ID: AV_ahcache!DriverEntry
BUCKET_ID: AV_ahcache!DriverEntry
PRIMARY_PROBLEM_CLASS: AV_ahcache!DriverEntry
TARGET_TIME: 2019-11-08T18:33:29.000Z
OSBUILD: 18362
OSSERVICEPACK: 418
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: unknown_date
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: 3a4c
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:av_ahcache!driverentry
FAILURE_ID_HASH: {74b70fc8-87a4-dbe7-e6b1-1484701ff95f}
Followup: MachineOwner
---------
11: kd> lmvm ahcache
Browse full module list
start end module name
fffff80e`3a870000 fffff80e`3a8bf000 ahcache # (pdb symbols) C:\ProgramData\dbg\sym\ahcache.pdb\8D0BE32731068C8D79BCD4D1AED3CBE01\ahcache.pdb
Loaded symbol image file: ahcache.sys
Mapped memory image file: C:\ProgramData\dbg\sym\ahcache.sys\A8473BE24f000\ahcache.sys
Image path: \SystemRoot\system32\DRIVERS\ahcache.sys
Image name: ahcache.sys
Browse all global symbols functions data
Image was built with /Brepro flag.
Timestamp: A8473BE2 (This is a reproducible build file hash, not a timestamp)
CheckSum: 00056682
ImageSize: 0004F000
File version: 10.0.18362.1216
Product version: 10.0.18362.1216
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
Information from resource tables:
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: ahcache.sys
OriginalFilename: ahcache.sys
ProductVersion: 10.0.18362.1216
FileVersion: 10.0.18362.1216 (WinBuild.160101.0800)
FileDescription: Application Compatibility Cache
LegalCopyright: © Microsoft Corporation. All rights reserved.
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except.
Typically the address is just plain bad or it is pointing at freed memory.
Arguments:
Arg1: ffffb18ae6205201, memory referenced.
Arg2: 0000000000000011, value 0 = read operation, 1 = write operation.
Arg3: ffffb18ae6205201, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000002, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
DUMP_TYPE: 2
BUGCHECK_P1: ffffb18ae6205201
BUGCHECK_P2: 11
BUGCHECK_P3: ffffb18ae6205201
BUGCHECK_P4: 2
WRITE_ADDRESS: fffff806573733b8: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
ffffb18ae6205201
FAULTING_IP:
+0
ffffb18a`e6205201 0000 add byte ptr [rax],al
MM_INTERNAL_CODE: 2
CPU_COUNT: c
CPU_MHZ: e09
CPU_VENDOR: AuthenticAMD
CPU_FAMILY: 17
CPU_MODEL: 1
CPU_STEPPING: 1
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: AV
PROCESS_NAME: System
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-18V31A3
ANALYSIS_SESSION_TIME: 11-12-2019 21:56:33.0686
ANALYSIS_VERSION: 10.0.18362.1 x86fre
TRAP_FRAME: ffffb18ae6204f00 -- (.trap 0xffffb18ae6204f00)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffffb18ae6205290 rbx=0000000000000000 rcx=0000000000008000
rdx=ffffb30ae5daab80 rsi=0000000000000000 rdi=0000000000000000
rip=ffffb18ae6205201 rsp=ffffb18ae6205098 rbp=ffffb18ae6205280
r8=ffffb30ae5da6180 r9=0000000000000000 r10=ffff9e09948a9a10
r11=ffffb18ae62050e0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe nc
ffffb18a`e6205201 0000 add byte ptr [rax],al ds:ffffb18a`e6205290=01
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80656fe33d6 to fffff80656fc1220
STACK_TEXT:
ffffb18a`e6204c58 fffff806`56fe33d6 : 00000000`00000050 ffffb18a`e6205201 00000000`00000011 ffffb18a`e6204f00 : nt!KeBugCheckEx
ffffb18a`e6204c60 fffff806`56e72edf : 00000000`00000000 00000000`00000011 00000000`00000000 ffffb18a`e6205201 : nt!MiSystemFault+0x1d66a6
ffffb18a`e6204d60 fffff806`56fcf320 : 00000000`00000030 fffff806`00000000 00000000`00000000 fffff8fc`7e33c130 : nt!MmAccessFault+0x34f
ffffb18a`e6204f00 ffffb18a`e6205201 : 00000000`00989680 00000000`00000002 00000000`00000001 ffffb18a`e62050e0 : nt!KiPageFault+0x360
ffffb18a`e6205098 00000000`00989680 : 00000000`00000002 00000000`00000001 ffffb18a`e62050e0 ffffb18a`e6205120 : 0xffffb18a`e6205201
ffffb18a`e62050a0 00000000`00000002 : 00000000`00000001 ffffb18a`e62050e0 ffffb18a`e6205120 00000000`00000001 : 0x989680
ffffb18a`e62050a8 00000000`00000001 : ffffb18a`e62050e0 ffffb18a`e6205120 00000000`00000001 ffffb18a`e6205278 : 0x2
ffffb18a`e62050b0 ffffb18a`e62050e0 : ffffb18a`e6205120 00000000`00000001 ffffb18a`e6205278 00000000`00000001 : 0x1
ffffb18a`e62050b8 ffffb18a`e6205120 : 00000000`00000001 ffffb18a`e6205278 00000000`00000001 00000000`00000101 : 0xffffb18a`e62050e0
ffffb18a`e62050c0 00000000`00000001 : ffffb18a`e6205278 00000000`00000001 00000000`00000101 ffff9e09`948a9a10 : 0xffffb18a`e6205120
ffffb18a`e62050c8 ffffb18a`e6205278 : 00000000`00000001 00000000`00000101 ffff9e09`948a9a10 ffffb30a`e5bc8c98 : 0x1
ffffb18a`e62050d0 00000000`00000001 : 00000000`00000101 ffff9e09`948a9a10 ffffb30a`e5bc8c98 ffffb30a`00008000 : 0xffffb18a`e6205278
ffffb18a`e62050d8 00000000`00000101 : ffff9e09`948a9a10 ffffb30a`e5bc8c98 ffffb30a`00008000 fffff806`00000002 : 0x1
ffffb18a`e62050e0 ffff9e09`948a9a10 : ffffb30a`e5bc8c98 ffffb30a`00008000 fffff806`00000002 00000000`00365000 : 0x101
ffffb18a`e62050e8 ffffb30a`e5bc8c98 : ffffb30a`00008000 fffff806`00000002 00000000`00365000 ffffb30a`e5d2a940 : 0xffff9e09`948a9a10
ffffb18a`e62050f0 ffffb30a`00008000 : fffff806`00000002 00000000`00365000 ffffb30a`e5d2a940 00008000`00008000 : 0xffffb30a`e5bc8c98
ffffb18a`e62050f8 fffff806`00000002 : 00000000`00365000 ffffb30a`e5d2a940 00008000`00008000 ffffb30a`e5d2a940 : 0xffffb30a`00008000
ffffb18a`e6205100 00000000`00365000 : ffffb30a`e5d2a940 00008000`00008000 ffffb30a`e5d2a940 ffff9e09`948a9c70 : 0xfffff806`00000002
ffffb18a`e6205108 ffffb30a`e5d2a940 : 00008000`00008000 ffffb30a`e5d2a940 ffff9e09`948a9c70 ffffb18a`00000000 : 0x365000
ffffb18a`e6205110 00008000`00008000 : ffffb30a`e5d2a940 ffff9e09`948a9c70 ffffb18a`00000000 00000000`00008000 : 0xffffb30a`e5d2a940
ffffb18a`e6205118 ffffb30a`e5d2a940 : ffff9e09`948a9c70 ffffb18a`00000000 00000000`00008000 00000000`00000000 : 0x00008000`00008000
ffffb18a`e6205120 ffff9e09`948a9c70 : ffffb18a`00000000 00000000`00008000 00000000`00000000 ffffb30a`e5bc8ca0 : 0xffffb30a`e5d2a940
ffffb18a`e6205128 ffffb18a`00000000 : 00000000`00008000 00000000`00000000 ffffb30a`e5bc8ca0 ffffb30a`e5da6180 : 0xffff9e09`948a9c70
ffffb18a`e6205130 00000000`00008000 : 00000000`00000000 ffffb30a`e5bc8ca0 ffffb30a`e5da6180 ffffb30a`e5d97090 : 0xffffb18a`00000000
ffffb18a`e6205138 00000000`00000000 : ffffb30a`e5bc8ca0 ffffb30a`e5da6180 ffffb30a`e5d97090 00000000`0036d000 : 0x8000
THREAD_SHA1_HASH_MOD_FUNC: 35852f70c1fb96d682b5bd0e931cc10c7b9fe1fe
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 0557a0823cb15180d0326192f359dade515cb1e4
THREAD_SHA1_HASH_MOD: d084f7dfa548ce4e51810e4fd5914176ebc66791
FOLLOWUP_IP:
nt!MiSystemFault+1d66a6
fffff806`56fe33d6 cc int 3
FAULT_INSTR_CODE: 4d8d48cc
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!MiSystemFault+1d66a6
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 0
IMAGE_VERSION: 10.0.18362.418
STACK_COMMAND: .thread ; .cxr ; kb
IMAGE_NAME: memory_corruption
BUCKET_ID_FUNC_OFFSET: 1d66a6
FAILURE_BUCKET_ID: AV_INVALID_nt!MiSystemFault
BUCKET_ID: AV_INVALID_nt!MiSystemFault
PRIMARY_PROBLEM_CLASS: AV_INVALID_nt!MiSystemFault
TARGET_TIME: 2019-11-06T17:46:19.000Z
OSBUILD: 18362
OSSERVICEPACK: 418
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: unknown_date
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: 4d50
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:av_invalid_nt!misystemfault
FAILURE_ID_HASH: {8a33c6b1-a9f1-4efe-025b-a861cc33d6e2}
Followup: MachineOwner
---------
11: kd> lmvm nt
Browse full module list
start end module name
fffff806`56e00000 fffff806`578b6000 nt (pdb symbols) C:\ProgramData\dbg\sym\ntkrnlmp.pdb\E0093F3AEF15D58168B753C9488A40431\ntkrnlmp.pdb
Loaded symbol image file: ntkrnlmp.exe
Mapped memory image file: C:\ProgramData\dbg\sym\ntoskrnl.exe\FC9570F2ab6000\ntoskrnl.exe
Image path: ntkrnlmp.exe
Image name: ntkrnlmp.exe
Browse all global symbols functions data
Image was built with /Brepro flag.
Timestamp: FC9570F2 (This is a reproducible build file hash, not a timestamp)
CheckSum: 0097CABE
ImageSize: 00AB6000
File version: 10.0.18362.418
Product version: 10.0.18362.418
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 1.0 App
File date: 00000000.00000000
Translations: 0409.04b0
Information from resource tables:
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: ntkrnlmp.exe
OriginalFilename: ntkrnlmp.exe
ProductVersion: 10.0.18362.418
FileVersion: 10.0.18362.418 (WinBuild.160101.0800)
FileDescription: NT Kernel & System
LegalCopyright: © Microsoft Corporation. All rights reserved.
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except.
Typically the address is just plain bad or it is pointing at freed memory.
Arguments:
Arg1: ffffb18ae6205201, memory referenced.
Arg2: 0000000000000011, value 0 = read operation, 1 = write operation.
Arg3: ffffb18ae6205201, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000002, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
KEY_VALUES_STRING: 1
Key : Analysis.CPU.Sec
Value: 4
Key : Analysis.DebugAnalysisProvider.CPP
Value: Create: 8007007e on DESKTOP-R1MKTM3
Key : Analysis.DebugData
Value: CreateObject
Key : Analysis.DebugModel
Value: CreateObject
Key : Analysis.Elapsed.Sec
Value: 11
Key : Analysis.Memory.CommitPeak.Mb
Value: 64
Key : Analysis.System
Value: CreateObject
BUGCHECK_CODE: 50
BUGCHECK_P1: ffffb18ae6205201
BUGCHECK_P2: 11
BUGCHECK_P3: ffffb18ae6205201
BUGCHECK_P4: 2
WRITE_ADDRESS: fffff806573733b8: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
fffff8065722a3c8: Unable to get Flags value from nt!KdVersionBlock
fffff8065722a3c8: Unable to get Flags value from nt!KdVersionBlock
unable to get nt!MmSpecialPagesInUse
ffffb18ae6205201
MM_INTERNAL_CODE: 2
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System
TRAP_FRAME: ffffb18ae6204f00 -- (.trap 0xffffb18ae6204f00)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffffb18ae6205290 rbx=0000000000000000 rcx=0000000000008000
rdx=ffffb30ae5daab80 rsi=0000000000000000 rdi=0000000000000000
rip=ffffb18ae6205201 rsp=ffffb18ae6205098 rbp=ffffb18ae6205280
r8=ffffb30ae5da6180 r9=0000000000000000 r10=ffff9e09948a9a10
r11=ffffb18ae62050e0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe nc
ffffb18a`e6205201 0000 add byte ptr [rax],al ds:ffffb18a`e6205290=01
Resetting default scope
STACK_TEXT:
ffffb18a`e6204c58 fffff806`56fe33d6 : 00000000`00000050 ffffb18a`e6205201 00000000`00000011 ffffb18a`e6204f00 : nt!KeBugCheckEx
ffffb18a`e6204c60 fffff806`56e72edf : 00000000`00000000 00000000`00000011 00000000`00000000 ffffb18a`e6205201 : nt!MiSystemFault+0x1d66a6
ffffb18a`e6204d60 fffff806`56fcf320 : 00000000`00000030 fffff806`00000000 00000000`00000000 fffff8fc`7e33c130 : nt!MmAccessFault+0x34f
ffffb18a`e6204f00 ffffb18a`e6205201 : 00000000`00989680 00000000`00000002 00000000`00000001 ffffb18a`e62050e0 : nt!KiPageFault+0x360
ffffb18a`e6205098 00000000`00989680 : 00000000`00000002 00000000`00000001 ffffb18a`e62050e0 ffffb18a`e6205120 : 0xffffb18a`e6205201
ffffb18a`e62050a0 00000000`00000002 : 00000000`00000001 ffffb18a`e62050e0 ffffb18a`e6205120 00000000`00000001 : 0x989680
ffffb18a`e62050a8 00000000`00000001 : ffffb18a`e62050e0 ffffb18a`e6205120 00000000`00000001 ffffb18a`e6205278 : 0x2
ffffb18a`e62050b0 ffffb18a`e62050e0 : ffffb18a`e6205120 00000000`00000001 ffffb18a`e6205278 00000000`00000001 : 0x1
ffffb18a`e62050b8 ffffb18a`e6205120 : 00000000`00000001 ffffb18a`e6205278 00000000`00000001 00000000`00000101 : 0xffffb18a`e62050e0
ffffb18a`e62050c0 00000000`00000001 : ffffb18a`e6205278 00000000`00000001 00000000`00000101 ffff9e09`948a9a10 : 0xffffb18a`e6205120
ffffb18a`e62050c8 ffffb18a`e6205278 : 00000000`00000001 00000000`00000101 ffff9e09`948a9a10 ffffb30a`e5bc8c98 : 0x1
ffffb18a`e62050d0 00000000`00000001 : 00000000`00000101 ffff9e09`948a9a10 ffffb30a`e5bc8c98 ffffb30a`00008000 : 0xffffb18a`e6205278
ffffb18a`e62050d8 00000000`00000101 : ffff9e09`948a9a10 ffffb30a`e5bc8c98 ffffb30a`00008000 fffff806`00000002 : 0x1
ffffb18a`e62050e0 ffff9e09`948a9a10 : ffffb30a`e5bc8c98 ffffb30a`00008000 fffff806`00000002 00000000`00365000 : 0x101
ffffb18a`e62050e8 ffffb30a`e5bc8c98 : ffffb30a`00008000 fffff806`00000002 00000000`00365000 ffffb30a`e5d2a940 : 0xffff9e09`948a9a10
ffffb18a`e62050f0 ffffb30a`00008000 : fffff806`00000002 00000000`00365000 ffffb30a`e5d2a940 00008000`00008000 : 0xffffb30a`e5bc8c98
ffffb18a`e62050f8 fffff806`00000002 : 00000000`00365000 ffffb30a`e5d2a940 00008000`00008000 ffffb30a`e5d2a940 : 0xffffb30a`00008000
ffffb18a`e6205100 00000000`00365000 : ffffb30a`e5d2a940 00008000`00008000 ffffb30a`e5d2a940 ffff9e09`948a9c70 : 0xfffff806`00000002
ffffb18a`e6205108 ffffb30a`e5d2a940 : 00008000`00008000 ffffb30a`e5d2a940 ffff9e09`948a9c70 ffffb18a`00000000 : 0x365000
ffffb18a`e6205110 00008000`00008000 : ffffb30a`e5d2a940 ffff9e09`948a9c70 ffffb18a`00000000 00000000`00008000 : 0xffffb30a`e5d2a940
ffffb18a`e6205118 ffffb30a`e5d2a940 : ffff9e09`948a9c70 ffffb18a`00000000 00000000`00008000 00000000`00000000 : 0x00008000`00008000
ffffb18a`e6205120 ffff9e09`948a9c70 : ffffb18a`00000000 00000000`00008000 00000000`00000000 ffffb30a`e5bc8ca0 : 0xffffb30a`e5d2a940
ffffb18a`e6205128 ffffb18a`00000000 : 00000000`00008000 00000000`00000000 ffffb30a`e5bc8ca0 ffffb30a`e5da6180 : 0xffff9e09`948a9c70
ffffb18a`e6205130 00000000`00008000 : 00000000`00000000 ffffb30a`e5bc8ca0 ffffb30a`e5da6180 ffffb30a`e5d97090 : 0xffffb18a`00000000
ffffb18a`e6205138 00000000`00000000 : ffffb30a`e5bc8ca0 ffffb30a`e5da6180 ffffb30a`e5d97090 00000000`0036d000 : 0x8000
SYMBOL_NAME: nt!MiSystemFault+1d66a6
MODULE_NAME: nt
IMAGE_VERSION: 10.0.18362.418
STACK_COMMAND: .thread ; .cxr ; kb
IMAGE_NAME: memory_corruption
BUCKET_ID_FUNC_OFFSET: 1d66a6
FAILURE_BUCKET_ID: AV_INVALID_nt!MiSystemFault
OS_VERSION: 10.0.18362.1
BUILDLAB_STR: 19h1_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {8a33c6b1-a9f1-4efe-025b-a861cc33d6e2}
Followup: MachineOwner
XMP veya Overclock açık mı?
Kod:******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* MEMORY_MANAGEMENT (1a) # Any other values for parameter 1 must be individually examined. Arguments: Arg1: 0000000000000403, The subtype of the bugcheck. Arg2: fffff580f44f96c8 Arg3: 81000001e0399c66 Arg4: bffff580f44f96c8 Debugging Details: ------------------ KEY_VALUES_STRING: 1 PROCESSES_ANALYSIS: 1 SERVICE_ANALYSIS: 1 STACKHASH_ANALYSIS: 1 TIMELINE_ANALYSIS: 1 DUMP_CLASS: 1 DUMP_QUALIFIER: 400 BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202 SYSTEM_MANUFACTURER: Gigabyte Technology Co., Ltd. SYSTEM_PRODUCT_NAME: AB350M-D3V SYSTEM_SKU: Default string SYSTEM_VERSION: Default string BIOS_VENDOR: American Megatrends Inc. BIOS_VERSION: F10 BIOS_DATE: 12/01/2017 BASEBOARD_MANUFACTURER: Gigabyte Technology Co., Ltd. BASEBOARD_PRODUCT: AB350M-D3V-CF BASEBOARD_VERSION: x.x DUMP_TYPE: 2 BUGCHECK_P1: 403 BUGCHECK_P2: fffff580f44f96c8 BUGCHECK_P3: 81000001e0399c66 BUGCHECK_P4: bffff580f44f96c8 BUGCHECK_STR: 0x1a_403 CPU_COUNT: 6 CPU_MHZ: ed1 CPU_VENDOR: AuthenticAMD CPU_FAMILY: 17 CPU_MODEL: 1 CPU_STEPPING: 1 BLACKBOXBSD: 1 (!blackboxbsd) BLACKBOXNTFS: 1 (!blackboxntfs) BLACKBOXWINLOGON: 1 CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT PROCESS_NAME: EpicGamesLauncher.exe CURRENT_IRQL: 2 ANALYSIS_SESSION_HOST: DESKTOP-18V31A3 ANALYSIS_SESSION_TIME: 11-12-2019 21:56:46.0884 ANALYSIS_VERSION: 10.0.18362.1 x86fre LAST_CONTROL_TRANSFER: from fffff8060da37bc3 to fffff8060d9c1220 STACK_TEXT: ffffa80f`cef63ca8 fffff806`0da37bc3 : 00000000`0000001a 00000000`00000403 fffff580`f44f96c8 81000001`e0399c66 : nt!KeBugCheckEx ffffa80f`cef63cb0 fffff806`0d816ca2 : 00000000`00000000 00000000`00b41560 ffffa80f`cef64850 00000000`00000000 : nt!MiDeleteClusterPage+0x159c73 ffffa80f`cef63d50 fffff806`0d8b15c7 : 00000000`00000003 ffffa80f`cef644a0 ffffa80f`cef644a0 ffffa80f`cef643f0 : nt!MiDeletePteRun+0xa42 ffffa80f`cef63f70 fffff806`0d8ad0e2 : ffff978e`62031580 fffff580`f44f9a00 00000000`00000000 00000000`00000000 : nt!MiDeleteVaTail+0x77 ffffa80f`cef63fa0 fffff806`0d8ad271 : ffffa80f`cef643f0 fffff5fa`c07a27c8 00000000`00000000 0a000001`dcf81867 : nt!MiWalkPageTablesRecursively+0x512 ffffa80f`cef64060 fffff806`0d8ad271 : ffffa80f`cef643f0 fffff5fa`fd603d10 00000000`00000000 0a000001`b1817867 : nt!MiWalkPageTablesRecursively+0x6a1 ffffa80f`cef64120 fffff806`0d8ad271 : ffffa80f`cef643f0 fffff5fa`fd7eb018 fffff5fa`00000000 0a000001`b1716867 : nt!MiWalkPageTablesRecursively+0x6a1 ffffa80f`cef641e0 fffff806`0d8ac9fc : ffffa80f`cef643f0 00000000`00000000 ffff978e`00000000 00000000`00000001 : nt!MiWalkPageTablesRecursively+0x6a1 ffffa80f`cef642a0 fffff806`0d8aae68 : ffffa80f`cef643f0 ffffa80f`00000002 00000000`00000001 fffff806`00000000 : nt!MiWalkPageTables+0x36c ffffa80f`cef643a0 fffff806`0d8b8fc0 : ffffffff`ffffffff ffff978e`620313f8 ffff978e`00000001 00000000`00000000 : nt!MiDeletePagablePteRange+0x268 ffffa80f`cef64740 fffff806`0d85919a : 00000000`1e89f33f ffff978e`6202d080 00000000`00000000 fffff806`0d8b3f9a : nt!MiDeleteVad+0x860 ffffa80f`cef64900 fffff806`0de5b310 : 00000000`00000000 00000000`00000000 ffffa80f`cef64a60 ffffffff`ffffffff : nt!MiFreeVadRange+0x9e ffffa80f`cef64960 fffff806`0de5af4b : 00000000`00000000 ffff850b`eabf3d40 ffff4b21`a1ca6478 fffff806`0deb275f : nt!MmFreeVirtualMemory+0x390 ffffa80f`cef64aa0 fffff806`0d9d2b15 : ffff978e`6202d080 ffff978e`6209a5e0 00007ff6`f14c28d8 00000000`00000000 : nt!NtFreeVirtualMemory+0x8b ffffa80f`cef64b00 00007ffc`60f3c484 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25 000000a9`dbacf128 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffc`60f3c484 THREAD_SHA1_HASH_MOD_FUNC: e3ee830b3ae3c5d26cdd05cb3808fb689f454486 THREAD_SHA1_HASH_MOD_FUNC_OFFSET: c284d6cf0350191fdf75fcc3f89cc701600209eb THREAD_SHA1_HASH_MOD: 38bc5fec3f0409c265cf5c87da6f8f8859d0711c FOLLOWUP_IP: nt!MiDeleteClusterPage+159c73 fffff806`0da37bc3 cc int 3 FAULT_INSTR_CODE: f01a8cc SYMBOL_STACK_INDEX: 1 SYMBOL_NAME: nt!MiDeleteClusterPage+159c73 FOLLOWUP_NAME: MachineOwner MODULE_NAME: nt DEBUG_FLR_IMAGE_TIMESTAMP: 0 IMAGE_VERSION: 10.0.18362.418 STACK_COMMAND: .thread ; .cxr ; kb IMAGE_NAME: memory_corruption BUCKET_ID_FUNC_OFFSET: 159c73 FAILURE_BUCKET_ID: 0x1a_403_nt!MiDeleteClusterPage BUCKET_ID: 0x1a_403_nt!MiDeleteClusterPage PRIMARY_PROBLEM_CLASS: 0x1a_403_nt!MiDeleteClusterPage TARGET_TIME: 2019-11-11T19:24:50.000Z OSBUILD: 18362 OSSERVICEPACK: 418 SERVICEPACK_NUMBER: 0 OS_REVISION: 0 SUITE_MASK: 272 PRODUCT_TYPE: 1 OSPLATFORM_TYPE: x64 OSNAME: Windows 10 OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS OS_LOCALE: USER_LCID: 0 OSBUILD_TIMESTAMP: unknown_date BUILDDATESTAMP_STR: 190318-1202 BUILDLAB_STR: 19h1_release BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202 ANALYSIS_SESSION_ELAPSED_TIME: 160b ANALYSIS_SOURCE: KM FAILURE_ID_HASH_STRING: km:0x1a_403_nt!mideleteclusterpage FAILURE_ID_HASH: {f401e11c-900d-f6cd-c291-93cf0151a773} Followup: MachineOwner --------- 0: kd> lmvm nt Browse full module list start end module name fffff806`0d800000 fffff806`0e2b6000 nt (pdb symbols) C:\ProgramData\dbg\sym\ntkrnlmp.pdb\E0093F3AEF15D58168B753C9488A40431\ntkrnlmp.pdb Loaded symbol image file: ntkrnlmp.exe Mapped memory image file: C:\ProgramData\dbg\sym\ntoskrnl.exe\FC9570F2ab6000\ntoskrnl.exe Image path: ntkrnlmp.exe Image name: ntkrnlmp.exe Browse all global symbols functions data Image was built with /Brepro flag. Timestamp: FC9570F2 (This is a reproducible build file hash, not a timestamp) CheckSum: 0097CABE ImageSize: 00AB6000 File version: 10.0.18362.418 Product version: 10.0.18362.418 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 1.0 App File date: 00000000.00000000 Translations: 0409.04b0 Information from resource tables: CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: ntkrnlmp.exe OriginalFilename: ntkrnlmp.exe ProductVersion: 10.0.18362.418 FileVersion: 10.0.18362.418 (WinBuild.160101.0800) FileDescription: NT Kernel & System LegalCopyright: © Microsoft Corporation. All rights reserved. ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1) An attempt was made to access a pageable (or completely invalid) address at an interrupt request level (IRQL) that is too high. This is usually caused by drivers using improper addresses. If kernel debugger is available get stack backtrace. Arguments: Arg1: fffff801764c42d0, memory referenced Arg2: 0000000000000002, IRQL Arg3: 0000000000000000, value 0 = read operation, 1 = write operation Arg4: fffff80175eed1ba, address which referenced memory Debugging Details: ------------------ KEY_VALUES_STRING: 1 PROCESSES_ANALYSIS: 1 SERVICE_ANALYSIS: 1 STACKHASH_ANALYSIS: 1 TIMELINE_ANALYSIS: 1 DUMP_CLASS: 1 DUMP_QUALIFIER: 400 BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202 SYSTEM_MANUFACTURER: Gigabyte Technology Co., Ltd. SYSTEM_PRODUCT_NAME: AB350M-D3V SYSTEM_SKU: Default string SYSTEM_VERSION: Default string BIOS_VENDOR: American Megatrends Inc. BIOS_VERSION: F10 BIOS_DATE: 12/01/2017 BASEBOARD_MANUFACTURER: Gigabyte Technology Co., Ltd. BASEBOARD_PRODUCT: AB350M-D3V-CF BASEBOARD_VERSION: x.x DUMP_TYPE: 2 BUGCHECK_P1: fffff801764c42d0 BUGCHECK_P2: 2 BUGCHECK_P3: 0 BUGCHECK_P4: fffff80175eed1ba READ_ADDRESS: fffff801733733b8: Unable to get MiVisibleState Unable to get NonPagedPoolStart Unable to get NonPagedPoolEnd Unable to get PagedPoolStart Unable to get PagedPoolEnd fffff801764c42d0 CURRENT_IRQL: 2 FAULTING_IP: tcpip!IppProtocolGetNextExpirationTick+b6 fffff801`75eed1ba 48ff150f711d00 call qword ptr [tcpip!_imp_RtlIsTimerWheelSuspended (fffff801`760c42d0)] CPU_COUNT: 6 CPU_MHZ: ed1 CPU_VENDOR: AuthenticAMD CPU_FAMILY: 17 CPU_MODEL: 1 CPU_STEPPING: 1 BLACKBOXBSD: 1 (!blackboxbsd) BLACKBOXNTFS: 1 (!blackboxntfs) BLACKBOXWINLOGON: 1 CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT BUGCHECK_STR: AV PROCESS_NAME: System ANALYSIS_SESSION_HOST: DESKTOP-18V31A3 ANALYSIS_SESSION_TIME: 11-12-2019 21:56:42.0940 ANALYSIS_VERSION: 10.0.18362.1 x86fre TRAP_FRAME: ffff9f889ca37590 -- (.trap 0xffff9f889ca37590) NOTE: The trap frame does not contain all registers. Some register values may be zeroed or incorrect. rax=0000000000000000 rbx=0000000000000000 rcx=ffff83880ca7f360 rdx=000000000000003f rsi=0000000000000000 rdi=0000000000000000 rip=fffff80175eed1ba rsp=ffff9f889ca37720 rbp=ffff9f889ca37740 r8=0000000000000000 r9=0000000000005463 r10=ffff83880ca7f360 r11=ffff9f889ca37718 r12=0000000000000000 r13=0000000000000000 r14=0000000000000000 r15=0000000000000000 iopl=0 nv up ei pl zr na po nc tcpip!IppProtocolGetNextExpirationTick+0xb6: fffff801`75eed1ba 48ff150f711d00 call qword ptr [tcpip!_imp_RtlIsTimerWheelSuspended (fffff801`760c42d0)] ds:fffff801`760c42d0=???????????????? Resetting default scope LAST_CONTROL_TRANSFER: from fffff80172fd30e9 to fffff80172fc1220 STACK_TEXT: ffff9f88`9ca37448 fffff801`72fd30e9 : 00000000`0000000a fffff801`764c42d0 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx ffff9f88`9ca37450 fffff801`72fcf42b : ffff8388`0e287010 fffff801`75f079c1 ffff8388`0e287190 00000000`000000c0 : nt!KiBugCheckDispatch+0x69 ffff9f88`9ca37590 fffff801`75eed1ba : 00000000`00000020 fffff801`00000020 ffff9f88`9ca37730 ffff8388`0ca24980 : nt!KiPageFault+0x46b ffff9f88`9ca37720 fffff801`75eec824 : ffff8388`0000003f fffff801`00000020 ffff8388`0ca54b50 fffff801`7609f2e0 : tcpip!IppProtocolGetNextExpirationTick+0xb6 ffff9f88`9ca37780 fffff801`72e6ba79 : 00000000`00000001 fffff801`760a9120 ffffc480`47cdc180 ffff8388`0e204010 : tcpip!IppTimeout+0x914 ffff9f88`9ca37940 fffff801`72e6a7d9 : 00000000`00000018 00000000`00989680 00000000`00000262 00000000`0000007a : nt!KiProcessExpiredTimerList+0x169 ffff9f88`9ca37a30 fffff801`72fc4d64 : ffffffff`00000000 ffffc480`47cdc180 ffffc480`47ced1c0 ffff8388`10b75080 : nt!KiRetireDpcList+0x4e9 ffff9f88`9ca37c60 00000000`00000000 : ffff9f88`9ca38000 ffff9f88`9ca32000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x84 THREAD_SHA1_HASH_MOD_FUNC: f66ab1163e8ed32b51e4a44f038ecb8025d76c4d THREAD_SHA1_HASH_MOD_FUNC_OFFSET: e9cc81c387fdfc8f8e9a1940124988c8a592fd14 THREAD_SHA1_HASH_MOD: a29dc2cce02a8546a1ac208145ad853692c385b3 FOLLOWUP_IP: tcpip!IppProtocolGetNextExpirationTick+b6 fffff801`75eed1ba 48ff150f711d00 call qword ptr [tcpip!_imp_RtlIsTimerWheelSuspended (fffff801`760c42d0)] FAULT_INSTR_CODE: f15ff48 SYMBOL_STACK_INDEX: 3 SYMBOL_NAME: tcpip!IppProtocolGetNextExpirationTick+b6 FOLLOWUP_NAME: MachineOwner MODULE_NAME: tcpip IMAGE_NAME: tcpip.sys DEBUG_FLR_IMAGE_TIMESTAMP: 61ae2576 IMAGE_VERSION: 10.0.18362.295 STACK_COMMAND: .thread ; .cxr ; kb BUCKET_ID_FUNC_OFFSET: b6 FAILURE_BUCKET_ID: AV_tcpip!IppProtocolGetNextExpirationTick BUCKET_ID: AV_tcpip!IppProtocolGetNextExpirationTick PRIMARY_PROBLEM_CLASS: AV_tcpip!IppProtocolGetNextExpirationTick TARGET_TIME: 2019-11-10T14:16:16.000Z OSBUILD: 18362 OSSERVICEPACK: 418 SERVICEPACK_NUMBER: 0 OS_REVISION: 0 SUITE_MASK: 272 PRODUCT_TYPE: 1 OSPLATFORM_TYPE: x64 OSNAME: Windows 10 OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS OS_LOCALE: USER_LCID: 0 OSBUILD_TIMESTAMP: unknown_date BUILDDATESTAMP_STR: 190318-1202 BUILDLAB_STR: 19h1_release BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202 ANALYSIS_SESSION_ELAPSED_TIME: a2b ANALYSIS_SOURCE: KM FAILURE_ID_HASH_STRING: km:av_tcpip!ippprotocolgetnextexpirationtick FAILURE_ID_HASH: {7e28b96c-bb88-5146-2504-6eddd59d4363} Followup: MachineOwner --------- 2: kd> lmvm tcpip Browse full module list start end module name fffff801`75ea0000 fffff801`7618a000 tcpip (pdb symbols) C:\ProgramData\dbg\sym\tcpip.pdb\D4924BA536B401A0DC772BC5617367AB1\tcpip.pdb Loaded symbol image file: tcpip.sys Mapped memory image file: C:\ProgramData\dbg\sym\tcpip.sys\61AE25762ea000\tcpip.sys Image path: \SystemRoot\System32\drivers\tcpip.sys Image name: tcpip.sys Browse all global symbols functions data Image was built with /Brepro flag. Timestamp: 61AE2576 (This is a reproducible build file hash, not a timestamp) CheckSum: 002E66D9 ImageSize: 002EA000 File version: 10.0.18362.295 Product version: 10.0.18362.295 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 3.6 Driver File date: 00000000.00000000 Translations: 0409.04b0 Information from resource tables: CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: tcpip.sys OriginalFilename: tcpip.sys ProductVersion: 10.0.18362.295 FileVersion: 10.0.18362.295 (WinBuild.160101.0800) FileDescription: TCP/IP Driver LegalCopyright: © Microsoft Corporation. All rights reserved. ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e) This is a very common bugcheck. Usually the exception address pinpoints the driver/function that caused the problem. Always note this address as well as the link date of the driver/image that contains this address. Some common problems are exception code 0x80000003. This means a hard coded breakpoint or assertion was hit, but this system was booted /NODEBUG. This is not supposed to happen as developers should never have hardcoded breakpoints in retail code, but ... If this happens, make sure a debugger gets connected, and the system is booted /DEBUG. This will let us see why this breakpoint is happening. Arguments: Arg1: ffffffffc0000005, The exception code that was not handled Arg2: fffff80e3a8ba0b8, The address that the exception occurred at Arg3: ffffbe0008406658, Exception Record Address Arg4: ffffbe0008405ea0, Context Record Address Debugging Details: ------------------ KEY_VALUES_STRING: 1 Key : AV.Dereference Value: NullPtr Key : AV.Fault Value: Write PROCESSES_ANALYSIS: 1 SERVICE_ANALYSIS: 1 STACKHASH_ANALYSIS: 1 TIMELINE_ANALYSIS: 1 DUMP_CLASS: 1 DUMP_QUALIFIER: 400 BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202 DUMP_TYPE: 2 BUGCHECK_P1: ffffffffc0000005 BUGCHECK_P2: fffff80e3a8ba0b8 BUGCHECK_P3: ffffbe0008406658 BUGCHECK_P4: ffffbe0008405ea0 EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text> FAULTING_IP: ahcache!DriverEntry+40 fffff80e`3a8ba0b8 0000 add byte ptr [rax],al EXCEPTION_RECORD: ffffbe0008406658 -- (.exr 0xffffbe0008406658) ExceptionAddress: fffff80e3a8ba0b8 (ahcache!DriverEntry+0x0000000000000040) ExceptionCode: c0000005 (Access violation) ExceptionFlags: 00000000 NumberParameters: 2 Parameter[0]: 0000000000000001 Parameter[1]: 0000000000000000 Attempt to write to address 0000000000000000 CONTEXT: ffffbe0008405ea0 -- (.cxr 0xffffbe0008405ea0) rax=0000000000000000 rbx=ffffbf8c291f6000 rcx=ffffbe00084068d0 rdx=fffff80e3a877150 rsi=ffffbf8c24802e10 rdi=441f0ffffd209b15 rip=fffff80e3a8ba0b8 rsp=ffffbe0008406890 rbp=ffffbe00084068f0 r8=0000000000000000 r9=0000000000000000 r10=fffff80e3a8ba010 r11=0000000000000000 r12=ffffffff80000178 r13=0000000000000002 r14=ffff8609b3aee470 r15=ffffbf8c291f6000 iopl=0 nv up ei pl zr na po nc cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050246 ahcache!DriverEntry+0x40: fffff80e`3a8ba0b8 0000 add byte ptr [rax],al ds:002b:00000000`00000000=?? Resetting default scope CPU_COUNT: c CPU_MHZ: ed1 CPU_VENDOR: AuthenticAMD CPU_FAMILY: 17 CPU_MODEL: 1 CPU_STEPPING: 1 BLACKBOXNTFS: 1 (!blackboxntfs) CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: NULL_DEREFERENCE PROCESS_NAME: System CURRENT_IRQL: 0 FOLLOWUP_IP: ahcache!DriverEntry+40 fffff80e`3a8ba0b8 0000 add byte ptr [rax],al BUGCHECK_STR: AV WRITE_ADDRESS: fffff801257733b8: Unable to get MiVisibleState Unable to get NonPagedPoolStart Unable to get NonPagedPoolEnd Unable to get PagedPoolStart Unable to get PagedPoolEnd 0000000000000000 ERROR_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text> EXCEPTION_CODE_STR: c0000005 EXCEPTION_PARAMETER1: 0000000000000001 EXCEPTION_PARAMETER2: 0000000000000000 ANALYSIS_SESSION_HOST: DESKTOP-18V31A3 ANALYSIS_SESSION_TIME: 11-12-2019 21:56:38.0885 ANALYSIS_VERSION: 10.0.18362.1 x86fre LAST_CONTROL_TRANSFER: from fffff80e3a8ba030 to fffff80e3a8ba0b8 STACK_TEXT: ffffbe00`08406890 fffff80e`3a8ba030 : ffffbf8c`291f6000 ffffbf8c`24802e10 00000000`00000000 ffff94fc`1828780a : ahcache!DriverEntry+0x40 ffffbe00`08406900 fffff801`2590f1f6 : 00000000`00000000 00000000`00000000 ffffbf8c`24802e10 ffffffff`80000178 : ahcache!GsDriverEntry+0x20 ffffbe00`08406930 fffff801`25c11561 : ffffbf8c`26fc7998 ffffbf8c`26fc7998 ffffbe00`08406b80 00000000`00000000 : nt!IopLoadDriver+0x4c2 ffffbe00`08406b10 fffff801`25c10752 : fffff801`00000000 ffff8609`b5019c50 00000000`00000000 fffff801`20a92dd0 : nt!IopInitializeSystemDrivers+0x151 ffffbe00`08406bb0 fffff801`25961422 : fffff801`20a92dd0 fffff801`20a92dd0 fffff801`259613e0 fffff801`20a92dd0 : nt!IoInitSystem+0x12 ffffbe00`08406be0 fffff801`2532a725 : ffffbf8c`2467d180 fffff801`259613e0 fffff801`20a92dd0 00000000`00000000 : nt!Phase1Initialization+0x42 ffffbe00`08406c10 fffff801`253c886a : fffff801`20e02180 ffffbf8c`2467d180 fffff801`2532a6d0 00000000`00000000 : nt!PspSystemThreadStartup+0x55 ffffbe00`08406c60 00000000`00000000 : ffffbe00`08407000 ffffbe00`08401000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x2a THREAD_SHA1_HASH_MOD_FUNC: 6cdee51db84f8036131c91b91c86295cc15cc8e1 THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 1328a52c2f3c430f868941289c58f19d2df517a5 THREAD_SHA1_HASH_MOD: 8a27bc4b75963fa409f2e038a5f1ec4bbd3674bb FAULT_INSTR_CODE: d88b0000 SYMBOL_STACK_INDEX: 0 SYMBOL_NAME: ahcache!DriverEntry+40 FOLLOWUP_NAME: MachineOwner MODULE_NAME: ahcache IMAGE_NAME: ahcache.sys DEBUG_FLR_IMAGE_TIMESTAMP: 0 IMAGE_VERSION: 10.0.18362.1216 STACK_COMMAND: .cxr 0xffffbe0008405ea0 ; kb BUCKET_ID_FUNC_OFFSET: 40 FAILURE_BUCKET_ID: AV_ahcache!DriverEntry BUCKET_ID: AV_ahcache!DriverEntry PRIMARY_PROBLEM_CLASS: AV_ahcache!DriverEntry TARGET_TIME: 2019-11-08T18:33:29.000Z OSBUILD: 18362 OSSERVICEPACK: 418 SERVICEPACK_NUMBER: 0 OS_REVISION: 0 SUITE_MASK: 272 PRODUCT_TYPE: 1 OSPLATFORM_TYPE: x64 OSNAME: Windows 10 OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS OS_LOCALE: USER_LCID: 0 OSBUILD_TIMESTAMP: unknown_date BUILDDATESTAMP_STR: 190318-1202 BUILDLAB_STR: 19h1_release BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202 ANALYSIS_SESSION_ELAPSED_TIME: 3a4c ANALYSIS_SOURCE: KM FAILURE_ID_HASH_STRING: km:av_ahcache!driverentry FAILURE_ID_HASH: {74b70fc8-87a4-dbe7-e6b1-1484701ff95f} Followup: MachineOwner --------- 11: kd> lmvm ahcache Browse full module list start end module name fffff80e`3a870000 fffff80e`3a8bf000 ahcache # (pdb symbols) C:\ProgramData\dbg\sym\ahcache.pdb\8D0BE32731068C8D79BCD4D1AED3CBE01\ahcache.pdb Loaded symbol image file: ahcache.sys Mapped memory image file: C:\ProgramData\dbg\sym\ahcache.sys\A8473BE24f000\ahcache.sys Image path: \SystemRoot\system32\DRIVERS\ahcache.sys Image name: ahcache.sys Browse all global symbols functions data Image was built with /Brepro flag. Timestamp: A8473BE2 (This is a reproducible build file hash, not a timestamp) CheckSum: 00056682 ImageSize: 0004F000 File version: 10.0.18362.1216 Product version: 10.0.18362.1216 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 3.7 Driver File date: 00000000.00000000 Translations: 0409.04b0 Information from resource tables: CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: ahcache.sys OriginalFilename: ahcache.sys ProductVersion: 10.0.18362.1216 FileVersion: 10.0.18362.1216 (WinBuild.160101.0800) FileDescription: Application Compatibility Cache LegalCopyright: © Microsoft Corporation. All rights reserved. PAGE_FAULT_IN_NONPAGED_AREA (50) Invalid system memory was referenced. This cannot be protected by try-except. Typically the address is just plain bad or it is pointing at freed memory. Arguments: Arg1: ffffb18ae6205201, memory referenced. Arg2: 0000000000000011, value 0 = read operation, 1 = write operation. Arg3: ffffb18ae6205201, If non-zero, the instruction address which referenced the bad memory address. Arg4: 0000000000000002, (reserved) Debugging Details: ------------------ Could not read faulting driver name KEY_VALUES_STRING: 1 PROCESSES_ANALYSIS: 1 SERVICE_ANALYSIS: 1 STACKHASH_ANALYSIS: 1 TIMELINE_ANALYSIS: 1 DUMP_CLASS: 1 DUMP_QUALIFIER: 400 BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202 DUMP_TYPE: 2 BUGCHECK_P1: ffffb18ae6205201 BUGCHECK_P2: 11 BUGCHECK_P3: ffffb18ae6205201 BUGCHECK_P4: 2 WRITE_ADDRESS: fffff806573733b8: Unable to get MiVisibleState Unable to get NonPagedPoolStart Unable to get NonPagedPoolEnd Unable to get PagedPoolStart Unable to get PagedPoolEnd ffffb18ae6205201 FAULTING_IP: +0 ffffb18a`e6205201 0000 add byte ptr [rax],al MM_INTERNAL_CODE: 2 CPU_COUNT: c CPU_MHZ: e09 CPU_VENDOR: AuthenticAMD CPU_FAMILY: 17 CPU_MODEL: 1 CPU_STEPPING: 1 CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT BUGCHECK_STR: AV PROCESS_NAME: System CURRENT_IRQL: 0 ANALYSIS_SESSION_HOST: DESKTOP-18V31A3 ANALYSIS_SESSION_TIME: 11-12-2019 21:56:33.0686 ANALYSIS_VERSION: 10.0.18362.1 x86fre TRAP_FRAME: ffffb18ae6204f00 -- (.trap 0xffffb18ae6204f00) NOTE: The trap frame does not contain all registers. Some register values may be zeroed or incorrect. rax=ffffb18ae6205290 rbx=0000000000000000 rcx=0000000000008000 rdx=ffffb30ae5daab80 rsi=0000000000000000 rdi=0000000000000000 rip=ffffb18ae6205201 rsp=ffffb18ae6205098 rbp=ffffb18ae6205280 r8=ffffb30ae5da6180 r9=0000000000000000 r10=ffff9e09948a9a10 r11=ffffb18ae62050e0 r12=0000000000000000 r13=0000000000000000 r14=0000000000000000 r15=0000000000000000 iopl=0 nv up ei pl nz na pe nc ffffb18a`e6205201 0000 add byte ptr [rax],al ds:ffffb18a`e6205290=01 Resetting default scope LAST_CONTROL_TRANSFER: from fffff80656fe33d6 to fffff80656fc1220 STACK_TEXT: ffffb18a`e6204c58 fffff806`56fe33d6 : 00000000`00000050 ffffb18a`e6205201 00000000`00000011 ffffb18a`e6204f00 : nt!KeBugCheckEx ffffb18a`e6204c60 fffff806`56e72edf : 00000000`00000000 00000000`00000011 00000000`00000000 ffffb18a`e6205201 : nt!MiSystemFault+0x1d66a6 ffffb18a`e6204d60 fffff806`56fcf320 : 00000000`00000030 fffff806`00000000 00000000`00000000 fffff8fc`7e33c130 : nt!MmAccessFault+0x34f ffffb18a`e6204f00 ffffb18a`e6205201 : 00000000`00989680 00000000`00000002 00000000`00000001 ffffb18a`e62050e0 : nt!KiPageFault+0x360 ffffb18a`e6205098 00000000`00989680 : 00000000`00000002 00000000`00000001 ffffb18a`e62050e0 ffffb18a`e6205120 : 0xffffb18a`e6205201 ffffb18a`e62050a0 00000000`00000002 : 00000000`00000001 ffffb18a`e62050e0 ffffb18a`e6205120 00000000`00000001 : 0x989680 ffffb18a`e62050a8 00000000`00000001 : ffffb18a`e62050e0 ffffb18a`e6205120 00000000`00000001 ffffb18a`e6205278 : 0x2 ffffb18a`e62050b0 ffffb18a`e62050e0 : ffffb18a`e6205120 00000000`00000001 ffffb18a`e6205278 00000000`00000001 : 0x1 ffffb18a`e62050b8 ffffb18a`e6205120 : 00000000`00000001 ffffb18a`e6205278 00000000`00000001 00000000`00000101 : 0xffffb18a`e62050e0 ffffb18a`e62050c0 00000000`00000001 : ffffb18a`e6205278 00000000`00000001 00000000`00000101 ffff9e09`948a9a10 : 0xffffb18a`e6205120 ffffb18a`e62050c8 ffffb18a`e6205278 : 00000000`00000001 00000000`00000101 ffff9e09`948a9a10 ffffb30a`e5bc8c98 : 0x1 ffffb18a`e62050d0 00000000`00000001 : 00000000`00000101 ffff9e09`948a9a10 ffffb30a`e5bc8c98 ffffb30a`00008000 : 0xffffb18a`e6205278 ffffb18a`e62050d8 00000000`00000101 : ffff9e09`948a9a10 ffffb30a`e5bc8c98 ffffb30a`00008000 fffff806`00000002 : 0x1 ffffb18a`e62050e0 ffff9e09`948a9a10 : ffffb30a`e5bc8c98 ffffb30a`00008000 fffff806`00000002 00000000`00365000 : 0x101 ffffb18a`e62050e8 ffffb30a`e5bc8c98 : ffffb30a`00008000 fffff806`00000002 00000000`00365000 ffffb30a`e5d2a940 : 0xffff9e09`948a9a10 ffffb18a`e62050f0 ffffb30a`00008000 : fffff806`00000002 00000000`00365000 ffffb30a`e5d2a940 00008000`00008000 : 0xffffb30a`e5bc8c98 ffffb18a`e62050f8 fffff806`00000002 : 00000000`00365000 ffffb30a`e5d2a940 00008000`00008000 ffffb30a`e5d2a940 : 0xffffb30a`00008000 ffffb18a`e6205100 00000000`00365000 : ffffb30a`e5d2a940 00008000`00008000 ffffb30a`e5d2a940 ffff9e09`948a9c70 : 0xfffff806`00000002 ffffb18a`e6205108 ffffb30a`e5d2a940 : 00008000`00008000 ffffb30a`e5d2a940 ffff9e09`948a9c70 ffffb18a`00000000 : 0x365000 ffffb18a`e6205110 00008000`00008000 : ffffb30a`e5d2a940 ffff9e09`948a9c70 ffffb18a`00000000 00000000`00008000 : 0xffffb30a`e5d2a940 ffffb18a`e6205118 ffffb30a`e5d2a940 : ffff9e09`948a9c70 ffffb18a`00000000 00000000`00008000 00000000`00000000 : 0x00008000`00008000 ffffb18a`e6205120 ffff9e09`948a9c70 : ffffb18a`00000000 00000000`00008000 00000000`00000000 ffffb30a`e5bc8ca0 : 0xffffb30a`e5d2a940 ffffb18a`e6205128 ffffb18a`00000000 : 00000000`00008000 00000000`00000000 ffffb30a`e5bc8ca0 ffffb30a`e5da6180 : 0xffff9e09`948a9c70 ffffb18a`e6205130 00000000`00008000 : 00000000`00000000 ffffb30a`e5bc8ca0 ffffb30a`e5da6180 ffffb30a`e5d97090 : 0xffffb18a`00000000 ffffb18a`e6205138 00000000`00000000 : ffffb30a`e5bc8ca0 ffffb30a`e5da6180 ffffb30a`e5d97090 00000000`0036d000 : 0x8000 THREAD_SHA1_HASH_MOD_FUNC: 35852f70c1fb96d682b5bd0e931cc10c7b9fe1fe THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 0557a0823cb15180d0326192f359dade515cb1e4 THREAD_SHA1_HASH_MOD: d084f7dfa548ce4e51810e4fd5914176ebc66791 FOLLOWUP_IP: nt!MiSystemFault+1d66a6 fffff806`56fe33d6 cc int 3 FAULT_INSTR_CODE: 4d8d48cc SYMBOL_STACK_INDEX: 1 SYMBOL_NAME: nt!MiSystemFault+1d66a6 FOLLOWUP_NAME: MachineOwner MODULE_NAME: nt DEBUG_FLR_IMAGE_TIMESTAMP: 0 IMAGE_VERSION: 10.0.18362.418 STACK_COMMAND: .thread ; .cxr ; kb IMAGE_NAME: memory_corruption BUCKET_ID_FUNC_OFFSET: 1d66a6 FAILURE_BUCKET_ID: AV_INVALID_nt!MiSystemFault BUCKET_ID: AV_INVALID_nt!MiSystemFault PRIMARY_PROBLEM_CLASS: AV_INVALID_nt!MiSystemFault TARGET_TIME: 2019-11-06T17:46:19.000Z OSBUILD: 18362 OSSERVICEPACK: 418 SERVICEPACK_NUMBER: 0 OS_REVISION: 0 SUITE_MASK: 272 PRODUCT_TYPE: 1 OSPLATFORM_TYPE: x64 OSNAME: Windows 10 OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS OS_LOCALE: USER_LCID: 0 OSBUILD_TIMESTAMP: unknown_date BUILDDATESTAMP_STR: 190318-1202 BUILDLAB_STR: 19h1_release BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202 ANALYSIS_SESSION_ELAPSED_TIME: 4d50 ANALYSIS_SOURCE: KM FAILURE_ID_HASH_STRING: km:av_invalid_nt!misystemfault FAILURE_ID_HASH: {8a33c6b1-a9f1-4efe-025b-a861cc33d6e2} Followup: MachineOwner --------- 11: kd> lmvm nt Browse full module list start end module name fffff806`56e00000 fffff806`578b6000 nt (pdb symbols) C:\ProgramData\dbg\sym\ntkrnlmp.pdb\E0093F3AEF15D58168B753C9488A40431\ntkrnlmp.pdb Loaded symbol image file: ntkrnlmp.exe Mapped memory image file: C:\ProgramData\dbg\sym\ntoskrnl.exe\FC9570F2ab6000\ntoskrnl.exe Image path: ntkrnlmp.exe Image name: ntkrnlmp.exe Browse all global symbols functions data Image was built with /Brepro flag. Timestamp: FC9570F2 (This is a reproducible build file hash, not a timestamp) CheckSum: 0097CABE ImageSize: 00AB6000 File version: 10.0.18362.418 Product version: 10.0.18362.418 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 1.0 App File date: 00000000.00000000 Translations: 0409.04b0 Information from resource tables: CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: ntkrnlmp.exe OriginalFilename: ntkrnlmp.exe ProductVersion: 10.0.18362.418 FileVersion: 10.0.18362.418 (WinBuild.160101.0800) FileDescription: NT Kernel & System LegalCopyright: © Microsoft Corporation. All rights reserved.
İşlemci overclock kaldır dene, birde XMP açık Memtest86 yap.Ram 2933 MHz'ye Overclocklu işlemci 3.8GHz'de overclocklu rami overclocklamazsam kesin mavi ekran hatası alıyorum.