*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
CRITICAL_PROCESS_DIED (ef)
A critical system process died
Arguments:
Arg1: ffff800f39b10180, Process object or thread object
Arg2: 0000000000000000, If this is 0, a process died. If this is 1, a thread died.
Arg3: 0000000000000000
Arg4: 0000000000000000
Debugging Details:
------------------
SYMSRV: BYINDEX: 0x6
C:\ProgramData\Dbg\sym*https://msdl.microsoft.com/download/symbols
cdd.dll
0000000000000000000000000000000048000
SYMSRV: UNC: C:\ProgramData\Dbg\sym\cdd.dll\0000000000000000000000000000000048000\cdd.dll - path not found
SYMSRV: UNC: C:\ProgramData\Dbg\sym\cdd.dll\0000000000000000000000000000000048000\cdd.dl_ - path not found
SYMSRV: UNC: C:\ProgramData\Dbg\sym\cdd.dll\0000000000000000000000000000000048000\file.ptr - path not found
SYMSRV: HTTPGET: /download/symbols/index2.txt
SYMSRV: HttpQueryInfo: 80190190 - HTTP_STATUS_BAD_REQUEST
SYMSRV: HTTPGET: /download/symbols/cdd.dll/0000000000000000000000000000000048000/cdd.dll
SYMSRV: HttpQueryInfo: 80190194 - HTTP_STATUS_NOT_FOUND
SYMSRV: HTTPGET: /download/symbols/cdd.dll/0000000000000000000000000000000048000/cdd.dl_
SYMSRV: HttpQueryInfo: 80190194 - HTTP_STATUS_NOT_FOUND
SYMSRV: HTTPGET: /download/symbols/cdd.dll/0000000000000000000000000000000048000/file.ptr
SYMSRV: HttpQueryInfo: 80190194 - HTTP_STATUS_NOT_FOUND
SYMSRV: RESULT: 0x80190194
DBGHELP: C:\Windows\cdd.dll - file not found
SYMSRV: BYINDEX: 0x7
https://msdl.microsoft.com/download/symbols
cdd.dll
0000000000000000000000000000000048000
SYMSRV: UNC: C:\ProgramData\Dbg\sym\cdd.dll\0000000000000000000000000000000048000\cdd.dll - path not found
SYMSRV: UNC: C:\ProgramData\Dbg\sym\cdd.dll\0000000000000000000000000000000048000\cdd.dl_ - path not found
SYMSRV: UNC: C:\ProgramData\Dbg\sym\cdd.dll\0000000000000000000000000000000048000\file.ptr - path not found
SYMSRV: HTTPGET: /download/symbols/cdd.dll/0000000000000000000000000000000048000/cdd.dll
SYMSRV: HttpQueryInfo: 80190194 - HTTP_STATUS_NOT_FOUND
SYMSRV: HTTPGET: /download/symbols/cdd.dll/0000000000000000000000000000000048000/cdd.dl_
SYMSRV: HttpQueryInfo: 80190194 - HTTP_STATUS_NOT_FOUND
SYMSRV: HTTPGET: /download/symbols/cdd.dll/0000000000000000000000000000000048000/file.ptr
SYMSRV: HttpQueryInfo: 80190194 - HTTP_STATUS_NOT_FOUND
SYMSRV: RESULT: 0x80190194
DBGENG: \SystemRoot\System32\cdd.dll - Image mapping disallowed by non-local path.
SYMSRV: BYINDEX: 0x8
C:\ProgramData\Dbg\sym*https://msdl.microsoft.com/download/symbols
Null.SYS
00000000000000000000000000000000a000
SYMSRV: UNC: C:\ProgramData\Dbg\sym\Null.SYS\00000000000000000000000000000000a000\Null.SYS - path not found
SYMSRV: UNC: C:\ProgramData\Dbg\sym\Null.SYS\00000000000000000000000000000000a000\Null.SY_ - path not found
SYMSRV: UNC: C:\ProgramData\Dbg\sym\Null.SYS\00000000000000000000000000000000a000\file.ptr - path not found
SYMSRV: HTTPGET: /download/symbols/Null.SYS/00000000000000000000000000000000a000/Null.SYS
SYMSRV: HttpQueryInfo: 80190194 - HTTP_STATUS_NOT_FOUND
SYMSRV: HTTPGET: /download/symbols/Null.SYS/00000000000000000000000000000000a000/Null.SY_
SYMSRV: HttpQueryInfo: 80190194 - HTTP_STATUS_NOT_FOUND
SYMSRV: HTTPGET: /download/symbols/Null.SYS/00000000000000000000000000000000a000/file.ptr
SYMSRV: HttpQueryInfo: 80190194 - HTTP_STATUS_NOT_FOUND
SYMSRV: RESULT: 0x80190194
DBGHELP: C:\Windows\Null.SYS - file not found
SYMSRV: BYINDEX: 0x9
https://msdl.microsoft.com/download/symbols
Null.SYS
00000000000000000000000000000000a000
SYMSRV: UNC: C:\ProgramData\Dbg\sym\Null.SYS\00000000000000000000000000000000a000\Null.SYS - path not found
SYMSRV: UNC: C:\ProgramData\Dbg\sym\Null.SYS\00000000000000000000000000000000a000\Null.SY_ - path not found
SYMSRV: UNC: C:\ProgramData\Dbg\sym\Null.SYS\00000000000000000000000000000000a000\file.ptr - path not found
SYMSRV: HTTPGET: /download/symbols/Null.SYS/00000000000000000000000000000000a000/Null.SYS
SYMSRV: HttpQueryInfo: 80190194 - HTTP_STATUS_NOT_FOUND
SYMSRV: HTTPGET: /download/symbols/Null.SYS/00000000000000000000000000000000a000/Null.SY_
SYMSRV: HttpQueryInfo: 80190194 - HTTP_STATUS_NOT_FOUND
SYMSRV: HTTPGET: /download/symbols/Null.SYS/00000000000000000000000000000000a000/file.ptr
SYMSRV: HttpQueryInfo: 80190194 - HTTP_STATUS_NOT_FOUND
SYMSRV: RESULT: 0x80190194
DBGENG: \SystemRoot\System32\Drivers\Null.SYS - Image mapping disallowed by non-local path.
SYMSRV: BYINDEX: 0xA
C:\ProgramData\Dbg\sym
umbus.sys
E7B4847E15000
SYMSRV: PATH: C:\ProgramData\Dbg\sym\umbus.sys\E7B4847E15000\umbus.sys
SYMSRV: RESULT: 0x00000000
DBGHELP: C:\ProgramData\Dbg\sym\umbus.sys\E7B4847E15000\umbus.sys - OK
DBGENG: C:\ProgramData\Dbg\sym\umbus.sys\E7B4847E15000\umbus.sys - Mapped image memory
SYMSRV: BYINDEX: 0xB
https://msdl.microsoft.com/download/symbols
dump_diskdump.sys
95F39C8Ae000
SYMSRV: UNC: C:\ProgramData\Dbg\sym\dump_diskdump.sys\95F39C8Ae000\dump_diskdump.sys - path not found
SYMSRV: UNC: C:\ProgramData\Dbg\sym\dump_diskdump.sys\95F39C8Ae000\dump_diskdump.sy_ - path not found
SYMSRV: UNC: C:\ProgramData\Dbg\sym\dump_diskdump.sys\95F39C8Ae000\file.ptr - path not found
SYMSRV: HTTPGET: /download/symbols/dump_diskdump.sys/95F39C8Ae000/dump_diskdump.sys
SYMSRV: HttpQueryInfo: 80190194 - HTTP_STATUS_NOT_FOUND
SYMSRV: HTTPGET: /download/symbols/dump_diskdump.sys/95F39C8Ae000/dump_diskdump.sy_
SYMSRV: HttpQueryInfo: 80190194 - HTTP_STATUS_NOT_FOUND
SYMSRV: HTTPGET: /download/symbols/dump_diskdump.sys/95F39C8Ae000/file.ptr
SYMSRV: HttpQueryInfo: 80190194 - HTTP_STATUS_NOT_FOUND
SYMSRV: RESULT: 0x80190194
SYMSRV: BYINDEX: 0xC
https://msdl.microsoft.com/download/symbols
dump_diskdump.sys
95F39C8Ae000
SYMSRV: UNC: C:\ProgramData\Dbg\sym\dump_diskdump.sys\95F39C8Ae000\dump_diskdump.sys - path not found
SYMSRV: UNC: C:\ProgramData\Dbg\sym\dump_diskdump.sys\95F39C8Ae000\dump_diskdump.sy_ - path not found
SYMSRV: UNC: C:\ProgramData\Dbg\sym\dump_diskdump.sys\95F39C8Ae000\file.ptr - path not found
SYMSRV: HTTPGET: /download/symbols/dump_diskdump.sys/95F39C8Ae000/dump_diskdump.sys
SYMSRV: HttpQueryInfo: 80190194 - HTTP_STATUS_NOT_FOUND
SYMSRV: HTTPGET: /download/symbols/dump_diskdump.sys/95F39C8Ae000/dump_diskdump.sy_
SYMSRV: HttpQueryInfo: 80190194 - HTTP_STATUS_NOT_FOUND
SYMSRV: HTTPGET: /download/symbols/dump_diskdump.sys/95F39C8Ae000/file.ptr
SYMSRV: HttpQueryInfo: 80190194 - HTTP_STATUS_NOT_FOUND
SYMSRV: RESULT: 0x80190194
SYMSRV: BYINDEX: 0xD
https://msdl.microsoft.com/download/symbols
dump_storahci.sys
8528F23B32000
SYMSRV: UNC: C:\ProgramData\Dbg\sym\dump_storahci.sys\8528F23B32000\dump_storahci.sys - path not found
SYMSRV: UNC: C:\ProgramData\Dbg\sym\dump_storahci.sys\8528F23B32000\dump_storahci.sy_ - path not found
SYMSRV: UNC: C:\ProgramData\Dbg\sym\dump_storahci.sys\8528F23B32000\file.ptr - path not found
SYMSRV: HTTPGET: /download/symbols/dump_storahci.sys/8528F23B32000/dump_storahci.sys
SYMSRV: HttpQueryInfo: 80190194 - HTTP_STATUS_NOT_FOUND
SYMSRV: HTTPGET: /download/symbols/dump_storahci.sys/8528F23B32000/dump_storahci.sy_
SYMSRV: HttpQueryInfo: 80190194 - HTTP_STATUS_NOT_FOUND
SYMSRV: HTTPGET: /download/symbols/dump_storahci.sys/8528F23B32000/file.ptr
SYMSRV: HttpQueryInfo: 80190194 - HTTP_STATUS_NOT_FOUND
SYMSRV: RESULT: 0x80190194
SYMSRV: BYINDEX: 0xE
C:\ProgramData\Dbg\sym
win32k.sys
E87370BB9a000
SYMSRV: PATH: C:\ProgramData\Dbg\sym\win32k.sys\E87370BB9a000\win32k.sys
SYMSRV: RESULT: 0x00000000
DBGHELP: C:\ProgramData\Dbg\sym\win32k.sys\E87370BB9a000\win32k.sys - OK
DBGENG: C:\ProgramData\Dbg\sym\win32k.sys\E87370BB9a000\win32k.sys - Mapped image memory
SYMSRV: BYINDEX: 0xF
C:\ProgramData\Dbg\sym
win32k.pdb
ED706A38659240A066E6FB19B994BAAA1
SYMSRV: PATH: C:\ProgramData\Dbg\sym\win32k.pdb\ED706A38659240A066E6FB19B994BAAA1\win32k.pdb
SYMSRV: RESULT: 0x00000000
DBGHELP: win32k - public symbols
C:\ProgramData\Dbg\sym\win32k.pdb\ED706A38659240A066E6FB19B994BAAA1\win32k.pdb
SYMSRV: BYINDEX: 0x10
https://msdl.microsoft.com/download/symbols
CI.dll
CD35337Ee3000
SYMSRV: PATH: C:\ProgramData\Dbg\sym\CI.dll\CD35337Ee3000\CI.dll
SYMSRV: RESULT: 0x00000000
DBGHELP: C:\ProgramData\Dbg\sym\CI.dll\CD35337Ee3000\CI.dll - OK
SYMSRV: BYINDEX: 0x11
C:\ProgramData\Dbg\sym
CI.dll
CD35337Ee3000
SYMSRV: PATH: C:\ProgramData\Dbg\sym\CI.dll\CD35337Ee3000\CI.dll
SYMSRV: RESULT: 0x00000000
DBGHELP: C:\ProgramData\Dbg\sym\CI.dll\CD35337Ee3000\CI.dll - OK
DBGENG: C:\ProgramData\Dbg\sym\CI.dll\CD35337Ee3000\CI.dll - Mapped image memory
SYMSRV: BYINDEX: 0x12
https://msdl.microsoft.com/download/symbols
fileinfo.sys
AEE275C21a000
SYMSRV: PATH: C:\ProgramData\Dbg\sym\fileinfo.sys\AEE275C21a000\fileinfo.sys
SYMSRV: RESULT: 0x00000000
DBGHELP: C:\ProgramData\Dbg\sym\fileinfo.sys\AEE275C21a000\fileinfo.sys - mismatched
SYMSRV: BYINDEX: 0x13
https://msdl.microsoft.com/download/symbols
fileinfo.sys
AEE275C21a000
SYMSRV: PATH: C:\ProgramData\Dbg\sym\fileinfo.sys\AEE275C21a000\fileinfo.sys
SYMSRV: RESULT: 0x00000000
DBGHELP: C:\ProgramData\Dbg\sym\fileinfo.sys\AEE275C21a000\fileinfo.sys - mismatched
SYMSRV: BYINDEX: 0x14
https://msdl.microsoft.com/download/symbols
fileinfo.sys
AEE275C21a000
SYMSRV: PATH: C:\ProgramData\Dbg\sym\fileinfo.sys\AEE275C21a000\fileinfo.sys
SYMSRV: RESULT: 0x00000000
DBGHELP: C:\ProgramData\Dbg\sym\fileinfo.sys\AEE275C21a000\fileinfo.sys - mismatched
SYMSRV: BYINDEX: 0x15
https://msdl.microsoft.com/download/symbols
fileinfo.sys
AEE275C21a000
SYMSRV: PATH: C:\ProgramData\Dbg\sym\fileinfo.sys\AEE275C21a000\fileinfo.sys
SYMSRV: RESULT: 0x00000000
DBGHELP: C:\ProgramData\Dbg\sym\fileinfo.sys\AEE275C21a000\fileinfo.sys - mismatched
SYMSRV: BYINDEX: 0x16
https://msdl.microsoft.com/download/symbols
fileinfo.sys
AEE275C21a000
SYMSRV: PATH: C:\ProgramData\Dbg\sym\fileinfo.sys\AEE275C21a000\fileinfo.sys
SYMSRV: RESULT: 0x00000000
DBGHELP: C:\ProgramData\Dbg\sym\fileinfo.sys\AEE275C21a000\fileinfo.sys - mismatched
SYMSRV: BYINDEX: 0x17
https://msdl.microsoft.com/download/symbols
fileinfo.sys
AEE275C21a000
SYMSRV: PATH: C:\ProgramData\Dbg\sym\fileinfo.sys\AEE275C21a000\fileinfo.sys
SYMSRV: RESULT: 0x00000000
DBGHELP: C:\ProgramData\Dbg\sym\fileinfo.sys\AEE275C21a000\fileinfo.sys - mismatched
SYMSRV: BYINDEX: 0x18
https://msdl.microsoft.com/download/symbols
fileinfo.sys
AEE275C21a000
SYMSRV: PATH: C:\ProgramData\Dbg\sym\fileinfo.sys\AEE275C21a000\fileinfo.sys
SYMSRV: RESULT: 0x00000000
DBGHELP: C:\ProgramData\Dbg\sym\fileinfo.sys\AEE275C21a000\fileinfo.sys - mismatched
SYMSRV: BYINDEX: 0x19
https://msdl.microsoft.com/download/symbols
fileinfo.sys
AEE275C21a000
SYMSRV: PATH: C:\ProgramData\Dbg\sym\fileinfo.sys\AEE275C21a000\fileinfo.sys
SYMSRV: RESULT: 0x00000000
DBGHELP: C:\ProgramData\Dbg\sym\fileinfo.sys\AEE275C21a000\fileinfo.sys - mismatched
SYMSRV: BYINDEX: 0x1A
https://msdl.microsoft.com/download/symbols
Wof.sys
6F60A68B3f000
SYMSRV: PATH: C:\ProgramData\Dbg\sym\Wof.sys\6F60A68B3f000\Wof.sys
SYMSRV: RESULT: 0x00000000
DBGHELP: C:\ProgramData\Dbg\sym\Wof.sys\6F60A68B3f000\Wof.sys - OK
SYMSRV: BYINDEX: 0x1B
C:\ProgramData\Dbg\sym
Wof.sys
6F60A68B3f000
SYMSRV: PATH: C:\ProgramData\Dbg\sym\Wof.sys\6F60A68B3f000\Wof.sys
SYMSRV: RESULT: 0x00000000
DBGHELP: C:\ProgramData\Dbg\sym\Wof.sys\6F60A68B3f000\Wof.sys - OK
DBGENG: C:\ProgramData\Dbg\sym\Wof.sys\6F60A68B3f000\Wof.sys - Mapped image memory
SYMSRV: BYINDEX: 0x1C
https://msdl.microsoft.com/download/symbols
Ntfs.sys
77A1338E2d9000
SYMSRV: PATH: C:\ProgramData\Dbg\sym\Ntfs.sys\77A1338E2d9000\Ntfs.sys
SYMSRV: RESULT: 0x00000000
DBGHELP: C:\ProgramData\Dbg\sym\Ntfs.sys\77A1338E2d9000\Ntfs.sys - OK
SYMSRV: BYINDEX: 0x1D
https://msdl.microsoft.com/download/symbols
tcpip.sys
9503E2DE2eb000
SYMSRV: PATH: C:\ProgramData\Dbg\sym\tcpip.sys\9503E2DE2eb000\tcpip.sys
SYMSRV: RESULT: 0x00000000
DBGHELP: C:\ProgramData\Dbg\sym\tcpip.sys\9503E2DE2eb000\tcpip.sys - OK
SYMSRV: BYINDEX: 0x1E
https://msdl.microsoft.com/download/symbols
crashdmp.sys
9A19AF811e000
SYMSRV: PATH: C:\ProgramData\Dbg\sym\crashdmp.sys\9A19AF811e000\crashdmp.sys
SYMSRV: RESULT: 0x00000000
DBGHELP: C:\ProgramData\Dbg\sym\crashdmp.sys\9A19AF811e000\crashdmp.sys - mismatched
SYMSRV: BYINDEX: 0x1F
https://msdl.microsoft.com/download/symbols
crashdmp.sys
9A19AF811e000
SYMSRV: PATH: C:\ProgramData\Dbg\sym\crashdmp.sys\9A19AF811e000\crashdmp.sys
SYMSRV: RESULT: 0x00000000
DBGHELP: C:\ProgramData\Dbg\sym\crashdmp.sys\9A19AF811e000\crashdmp.sys - mismatched
SYMSRV: BYINDEX: 0x20
https://msdl.microsoft.com/download/symbols
crashdmp.sys
9A19AF811e000
SYMSRV: PATH: C:\ProgramData\Dbg\sym\crashdmp.sys\9A19AF811e000\crashdmp.sys
SYMSRV: RESULT: 0x00000000
DBGHELP: C:\ProgramData\Dbg\sym\crashdmp.sys\9A19AF811e000\crashdmp.sys - mismatched
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 8030
Key : Analysis.DebugAnalysisProvider.CPP
Value: Create: 8007007e on DESKTOP-772SIBS
Key : Analysis.DebugData
Value: CreateObject
Key : Analysis.DebugModel
Value: CreateObject
Key : Analysis.Elapsed.mSec
Value: 14786
Key : Analysis.Memory.CommitPeak.Mb
Value: 76
Key : Analysis.System
Value: CreateObject
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Timestamp
Value: 2019-12-06T14:06:00Z
Key : WER.OS.Version
Value: 10.0.19041.1
ADDITIONAL_XML: 1
OS_BUILD_LAYERS: 1
BUGCHECK_CODE: ef
BUGCHECK_P1: ffff800f39b10180
BUGCHECK_P2: 0
BUGCHECK_P3: 0
BUGCHECK_P4: 0
PROCESS_NAME: services.exe
CRITICAL_PROCESS: services.exe
EXCEPTION_RECORD: ffff800f39b108c0 -- (.exr 0xffff800f39b108c0)
ExceptionAddress: 0000000000000000
ExceptionCode: 00000000
ExceptionFlags: 00000000
NumberParameters: 0
ERROR_CODE: (NTSTATUS) 0x3da540c0 - <Unable to get error code text>
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
EXCEPTION_STR: 0x0
STACK_TEXT:
ffffc407`c3a4bd88 fffff807`695068e2 : 00000000`000000ef ffff800f`39b10180 00000000`00000000 00000000`00000000 : nt!KeBugCheckEx
ffffc407`c3a4bd90 fffff807`69449b39 : 00000000`00000001 fffff807`68f5971d 00000000`00000002 fffff807`68f58d37 : nt!PspCatchCriticalBreak+0x10e
ffffc407`c3a4be30 fffff807`69309724 : ffff800f`00000000 00000000`00000000 ffff800f`39b10180 ffff800f`39b105b8 : nt!PspTerminateAllThreads+0x140b4d
ffffc407`c3a4bea0 fffff807`69309a4c : ffff800f`39b10180 00000000`00000001 ffffffff`ffffffff 00000000`00000000 : nt!PspTerminateProcess+0xe0
ffffc407`c3a4bee0 fffff807`690071b8 : ffff800f`39b10180 ffff800f`3da540c0 ffffc407`c3a4bfd0 fffff807`6931da92 : nt!NtTerminateProcess+0x9c
ffffc407`c3a4bf50 fffff807`68ff95e0 : fffff807`69091307 ffffc407`c3a4ca58 ffffc407`c3a4ca58 ffffffff`ffffffff : nt!KiSystemServiceCopyEnd+0x28
ffffc407`c3a4c0e8 fffff807`69091307 : ffffc407`c3a4ca58 ffffc407`c3a4ca58 ffffffff`ffffffff 00007ff7`715a1000 : nt!KiServiceLinkage
ffffc407`c3a4c0f0 fffff807`690078ac : ffff800f`39b108c0 fffff807`68f540e6 00000000`00003200 ffffc407`c3a4cb00 : nt!KiDispatchException+0x166907
ffffc407`c3a4c920 fffff807`69003a43 : 00000000`00000004 00000000`00000000 ffffc407`c3a4cb80 ffff800f`00000000 : nt!KiExceptionDispatch+0x12c
ffffc407`c3a4cb00 00007ff8`975d4042 : 00000000`00000000 0000002c`00000000 0000002c`4a201480 0000002c`4a201488 : nt!KiPageFault+0x443
0000002c`4a201460 00000000`00000000 : 0000002c`00000000 0000002c`4a201480 0000002c`4a201488 00007ff7`715a1000 : 0x00007ff8`975d4042
SYMBOL_NAME: nt!PspCatchCriticalBreak+10e
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
IMAGE_VERSION: 10.0.19041.685
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: 10e
FAILURE_BUCKET_ID: 0xEF_services.exe_BUGCHECK_CRITICAL_PROCESS_3da540c0_nt!PspCatchCriticalBreak
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {74088727-1c50-c2ec-092e-0c09fca96b35}
Followup: MachineOwner
---------
1: kd> lm
start end module name
fffff20f`a3200000 fffff20f`a34de000 win32kbase (deferred)
fffff20f`a3830000 fffff20f`a38ca000 win32k # (pdb symbols) C:\ProgramData\Dbg\sym\win32k.pdb\ED706A38659240A066E6FB19B994BAAA1\win32k.pdb
fffff20f`a4170000 fffff20f`a4526000 win32kfull (deferred)
fffff20f`a4530000 fffff20f`a4578000 cdd (deferred)
fffff807`65ec0000 fffff807`65ee8000 mcupdate_AuthenticAMD (deferred)
fffff807`65ef0000 fffff807`65ef6000 hal (deferred)
fffff807`65f00000 fffff807`65f0b000 kd (deferred)
fffff807`65f10000 fffff807`65f37000 tm (deferred)
fffff807`65f40000 fffff807`65faa000 CLFS (deferred)
fffff807`65fb0000 fffff807`65fca000 PSHED (deferred)
fffff807`65fd0000 fffff807`65fdb000 BOOTVID (deferred)
fffff807`65fe0000 fffff807`660f3000 clipsp (deferred)
fffff807`66100000 fffff807`6616f000 FLTMGR (deferred)
fffff807`66170000 fffff807`66199000 ksecdd (deferred)
fffff807`661a0000 fffff807`66202000 msrpc (deferred)
fffff807`66210000 fffff807`6621e000 cmimcext (deferred)
fffff807`66220000 fffff807`66231000 werkernel (deferred)
fffff807`66240000 fffff807`6624c000 ntosext (deferred)
fffff807`66250000 fffff807`66263000 WDFLDR (deferred)
fffff807`66270000 fffff807`6627f000 SleepStudyHelper (deferred)
fffff807`66280000 fffff807`66291000 WppRecorder (deferred)
fffff807`662a0000 fffff807`662ba000 SgrmAgent (deferred)
fffff807`66a00000 fffff807`66a11000 kbdhid (deferred)
fffff807`66a20000 fffff807`66a34000 kbdclass (deferred)
fffff807`66a40000 fffff807`66a69000 UAExt (deferred)
fffff807`66a70000 fffff807`66aa7000 usbaudio (deferred)
fffff807`66ab0000 fffff807`66ad5000 USBSTOR (deferred)
fffff807`66af0000 fffff807`66afe000 dump_diskdump (deferred)
fffff807`66b40000 fffff807`66b72000 dump_storahci (deferred)
fffff807`66ba0000 fffff807`66bbd000 dump_dumpfve (deferred)
fffff807`66bc0000 fffff807`66ca2000 dxgmms2 (deferred)
fffff807`66cb0000 fffff807`66ccb000 monitor (deferred)
fffff807`66cd0000 fffff807`66cf9000 luafv (deferred)
fffff807`66d00000 fffff807`66d36000 wcifs (deferred)
fffff807`66d40000 fffff807`66d94000 WUDFRd (deferred)
fffff807`66da0000 fffff807`66e20000 cldflt (deferred)
fffff807`66e30000 fffff807`66e4a000 storqosflt (deferred)
fffff807`66e50000 fffff807`66e78000 bindflt (deferred)
fffff807`66e80000 fffff807`66e8e000 WpdUpFltr (deferred)
fffff807`66e90000 fffff807`66ea8000 mslldp (deferred)
fffff807`66eb0000 fffff807`66ec8000 lltdio (deferred)
fffff807`66ed0000 fffff807`66eeb000 rspndr (deferred)
fffff807`66ef0000 fffff807`66f0d000 wanarp (deferred)
fffff807`66f10000 fffff807`66f66000 msquic (deferred)
fffff807`66f70000 fffff807`670f6000 HTTP (deferred)
fffff807`67100000 fffff807`67125000 bowser (deferred)
fffff807`67130000 fffff807`6714a000 mpsdrv (deferred)
fffff807`67150000 fffff807`671e3000 mrxsmb (deferred)
fffff807`671f0000 fffff807`67235000 mrxsmb20 (deferred)
fffff807`67240000 fffff807`67293000 srvnet (deferred)
fffff807`672a0000 fffff807`672b4000 mmcss (deferred)
fffff807`672c0000 fffff807`672e7000 Ndu (deferred)
fffff807`672f0000 fffff807`67305000 tcpipreg (deferred)
fffff807`67310000 fffff807`678d5000 RTKVHD64 (deferred)
fffff807`678e0000 fffff807`678f2000 hidusb (deferred)
fffff807`67900000 fffff807`6793f000 HIDCLASS (deferred)
fffff807`67940000 fffff807`67953000 HIDPARSE (deferred)
fffff807`67960000 fffff807`67970000 libusbK (deferred)
fffff807`67980000 fffff807`679b3000 usbccgp (deferred)
fffff807`679c0000 fffff807`679d0000 mouhid (deferred)
fffff807`679e0000 fffff807`679f3000 mouclass (deferred)
fffff807`68c00000 fffff807`69c46000 nt (pdb symbols) C:\ProgramData\Dbg\sym\ntkrnlmp.pdb\4EF9A5375F61FE84B7EAEF54BF025C0E1\ntkrnlmp.pdb
fffff807`6b800000 fffff807`6b8e3000 CI (deferred)
fffff807`6b8f0000 fffff807`6b9a7000 cng (deferred)
fffff807`6b9b0000 fffff807`6ba81000 Wdf01000 (deferred)
fffff807`6ba90000 fffff807`6bab6000 acpiex (deferred)
fffff807`6bac0000 fffff807`6bb0b000 mssecflt (deferred)
fffff807`6bb10000 fffff807`6bbdc000 ACPI (deferred)
fffff807`6bbe0000 fffff807`6bbec000 WMILIB (deferred)
fffff807`6bc10000 fffff807`6bc7b000 intelpep (deferred)
fffff807`6bc80000 fffff807`6bc97000 WindowsTrustedRT (deferred)
fffff807`6bca0000 fffff807`6bcab000 IntelTA (deferred)
fffff807`6bcb0000 fffff807`6bcbb000 WindowsTrustedRTProxy (deferred)
fffff807`6bcc0000 fffff807`6bcd4000 pcw (deferred)
fffff807`6bce0000 fffff807`6bceb000 msisadrv (deferred)
fffff807`6bcf0000 fffff807`6bd66000 pci (deferred)
fffff807`6bd70000 fffff807`6bd85000 vdrvroot (deferred)
fffff807`6bd90000 fffff807`6bda7000 amdkmpfd (deferred)
fffff807`6bdb0000 fffff807`6bddf000 pdc (deferred)
fffff807`6bde0000 fffff807`6bdf9000 CEA (deferred)
fffff807`6be00000 fffff807`6be31000 partmgr (deferred)
fffff807`6be40000 fffff807`6beea000 spaceport (deferred)
fffff807`6bef0000 fffff807`6bf09000 volmgr (deferred)
fffff807`6bf10000 fffff807`6bf73000 volmgrx (deferred)
fffff807`6bf80000 fffff807`6bf9e000 mountmgr (deferred)
fffff807`6bfa0000 fffff807`6bfd2000 storahci (deferred)
fffff807`6c000000 fffff807`6c0b0000 storport (deferred)
fffff807`6c0c0000 fffff807`6c0da000 fileinfo (deferred)
fffff807`6c0e0000 fffff807`6c11f000 Wof (deferred)
fffff807`6c120000 fffff807`6c18c000 WdFilter (deferred)
fffff807`6c190000 fffff807`6c469000 Ntfs (deferred)
fffff807`6c470000 fffff807`6c47d000 Fs_Rec (deferred)
fffff807`6c480000 fffff807`6c5ef000 ndis (deferred)
fffff807`6c5f0000 fffff807`6c688000 NETIO (deferred)
fffff807`6c690000 fffff807`6c6c2000 ksecpkg (deferred)
fffff807`6c6d0000 fffff807`6c6f2000 amdpsp (deferred)
fffff807`6c700000 fffff807`6c9eb000 tcpip (deferred)
fffff807`6c9f0000 fffff807`6ca6f000 fwpkclnt (deferred)
fffff807`6ca70000 fffff807`6caa0000 wfplwfs (deferred)
fffff807`6cab0000 fffff807`6cb78000 fvevol (deferred)
fffff807`6cb80000 fffff807`6cb8b000 volume (deferred)
fffff807`6cb90000 fffff807`6cbfd000 volsnap (deferred)
fffff807`6cc00000 fffff807`6cc50000 rdyboost (deferred)
fffff807`6cc60000 fffff807`6cc86000 mup (deferred)
fffff807`6cc90000 fffff807`6cca2000 iorate (deferred)
fffff807`6ccd0000 fffff807`6ccec000 disk (deferred)
fffff807`6ccf0000 fffff807`6cd5c000 CLASSPNP (deferred)
fffff807`75200000 fffff807`7521e000 crashdmp (deferred)
fffff807`75300000 fffff807`75330000 cdrom (deferred)
fffff807`75340000 fffff807`75355000 filecrypt (deferred)
fffff807`75360000 fffff807`7536e000 tbs (deferred)
fffff807`75370000 fffff807`7537a000 Null (deferred)
fffff807`75380000 fffff807`7538a000 Beep (deferred)
fffff807`75800000 fffff807`7581b000 CimFS (deferred)
fffff807`75820000 fffff807`75842000 tdx (deferred)
fffff807`75850000 fffff807`75860000 TDI (deferred)
fffff807`75870000 fffff807`758cc000 netbt (deferred)
fffff807`758d0000 fffff807`758e3000 afunix (deferred)
fffff807`758f0000 fffff807`75993000 afd (deferred)
fffff807`759a0000 fffff807`759ba000 vwififlt (deferred)
fffff807`759c0000 fffff807`759eb000 pacer (deferred)
fffff807`759f0000 fffff807`75a04000 ndiscap (deferred)
fffff807`75a10000 fffff807`75a24000 netbios (deferred)
fffff807`75a30000 fffff807`75ad1000 Vid (deferred)
fffff807`75ae0000 fffff807`75b01000 winhvr (deferred)
fffff807`75b10000 fffff807`75b8c000 rdbss (deferred)
fffff807`75b90000 fffff807`75c24000 csc (deferred)
fffff807`75c30000 fffff807`75c42000 nsiproxy (deferred)
fffff807`75c50000 fffff807`75c5e000 npsvctrig (deferred)
fffff807`75c60000 fffff807`75c70000 mssmbios (deferred)
fffff807`75c80000 fffff807`75c8a000 gpuenergydrv (deferred)
fffff807`75c90000 fffff807`75cbc000 dfsc (deferred)
fffff807`75ce0000 fffff807`75d4c000 fastfat (deferred)
fffff807`75d50000 fffff807`75d67000 bam (deferred)
fffff807`75d70000 fffff807`75dbe000 ahcache (deferred)
fffff807`75dc0000 fffff807`75dce000 amdxe (deferred)
fffff807`75dd0000 fffff807`75dea000 amdfendr (deferred)
fffff807`75df0000 fffff807`75e02000 CompositeBus (deferred)
fffff807`75e10000 fffff807`75e1d000 kdnic (deferred)
fffff807`75e20000 fffff807`75e35000 umbus (deferred)
fffff807`75e40000 fffff807`75ed8000 USBXHCI (deferred)
fffff807`75ee0000 fffff807`75f24000 ucx01000 (deferred)
fffff807`75f30000 fffff807`7604c000 rt640x64 (deferred)
fffff807`76050000 fffff807`76117000 srv2 (deferred)
fffff807`76120000 fffff807`7613d000 NDProxy (deferred)
fffff807`76140000 fffff807`76168000 AgileVpn (deferred)
fffff807`76170000 fffff807`76191000 rasl2tp (deferred)
fffff807`761a0000 fffff807`761c1000 raspptp (deferred)
fffff807`761d0000 fffff807`761ec000 raspppoe (deferred)
fffff807`761f0000 fffff807`761ff000 ndistapi (deferred)
fffff807`76200000 fffff807`7623a000 ndiswan (deferred)
fffff807`76240000 fffff807`76253000 condrv (deferred)
fffff807`76260000 fffff807`76276000 WdNisDrv (deferred)
fffff807`765a0000 fffff807`76943000 dxgkrnl (deferred)
fffff807`76950000 fffff807`76968000 watchdog (deferred)
fffff807`76970000 fffff807`76986000 BasicDisplay (deferred)
fffff807`76990000 fffff807`769a1000 BasicRender (deferred)
fffff807`769b0000 fffff807`769cc000 Npfs (deferred)
fffff807`769d0000 fffff807`769e1000 Msfs (deferred)
fffff807`7b600000 fffff807`7b676000 ks (deferred)
fffff807`7b680000 fffff807`7b68a000 AMDPCIDev (deferred)
fffff807`7b690000 fffff807`7b69d000 amdgpio2 (deferred)
fffff807`7b6a0000 fffff807`7b6d2000 msgpioclx (deferred)
fffff807`7b6e0000 fffff807`7b71b000 amdppm (deferred)
fffff807`7b720000 fffff807`7b72c000 wmiacpi (deferred)
fffff807`7b730000 fffff807`7b73a000 amdgpio3 (deferred)
fffff807`7b740000 fffff807`7b74e000 UEFI (deferred)
fffff807`7b750000 fffff807`7b75d000 NdisVirtualBus (deferred)
fffff807`7b760000 fffff807`7b76c000 swenum (deferred)
fffff807`7b770000 fffff807`7b77e000 ScpVBus (deferred)
fffff807`7b780000 fffff807`7b78e000 rdpbus (deferred)
fffff807`7b790000 fffff807`7b833000 UsbHub3 (deferred)
fffff807`7b840000 fffff807`7b84e000 USBD (deferred)
fffff807`7b850000 fffff807`7b86d000 AtihdWT6 (deferred)
fffff807`7b870000 fffff807`7b87f000 ksthunk (deferred)
fffff807`7b880000 fffff807`7b956000 peauth (deferred)
fffff807`7b960000 fffff807`8050f000 amdkmdag (deferred)
fffff807`80510000 fffff807`80535000 HDAudBus (deferred)
fffff807`80540000 fffff807`805a6000 portcls (deferred)
fffff807`805b0000 fffff807`805d1000 drmk (deferred)
fffff807`805e0000 fffff807`805fc000 rassstp (deferred)
Unloaded modules:
fffff807`75230000 fffff807`7523f000 dump_storpor
fffff807`75280000 fffff807`752b3000 dump_storahc
fffff807`752e0000 fffff807`752fe000 dump_dumpfve
fffff807`6bfe0000 fffff807`6bffd000 EhStorClass.
fffff807`75cc0000 fffff807`75cdc000 dam.sys
fffff807`75e30000 fffff807`763b4000 vgk.sys
fffff807`6bbf0000 fffff807`6bc01000 WdBoot.sys
fffff807`6ccb0000 fffff807`6ccc1000 hwpolicy.sys
1: kd> !blackboxbsd
Stream size mismatch (expected = 192, read = 176)
1: kd> !blackboxntfs
NTFS Blackbox Data
0 Slow I/O Timeout Records Found
0 Oplock Break Timeout Records Found
1: kd> .exr 0xffff800f39b108c0
ExceptionAddress: 0000000000000000
ExceptionCode: 00000000
ExceptionFlags: 00000000
NumberParameters: 0
1: kd> !process
PROCESS ffff800f39b10180
SessionId: 0 Cid: 03b0 Peb: 2c49fe1000 ParentCid: 0368
DirBase: 16f3b7000 ObjectTable: ffffe204e24a2b80 HandleCount: <Data Not Accessible>
Image: services.exe
VadRoot ffff800f396f8b70 Vads 76 Clone 0 Private 1317. Modified 721. Locked 2.
DeviceMap ffffe204dc237240
Token ffffe204e02bba70
ReadMemory error: Cannot get nt!KeMaximumIncrement value.
fffff78000000000: Unable to get shared data
ElapsedTime 00:00:00.000
UserTime 00:00:00.000
KernelTime 00:00:00.000
QuotaPoolUsage[PagedPool] 161976
QuotaPoolUsage[NonPagedPool] 13704
Working Set Sizes (now,min,max) (2856, 50, 345) (11424KB, 200KB, 1380KB)
PeakWorkingSetSize 2786
VirtualSize 2101320 Mb
PeakVirtualSize 2101329 Mb
PageFaultCount 4494
MemoryPriority BACKGROUND
BasePriority 9
CommitCharge 1609
*** Error in reading nt!_ETHREAD @ ffff800f39a10080
1: kd> !Thread
THREAD ffff800f3da540c0 Cid 03b0.0a84 Teb: 0000002c49e52000 Win32Thread: 0000000000000000 RUNNING on processor 1
Not impersonating
GetUlongFromAddress: unable to read from fffff807698114cc
Owning Process ffff800f39b10180 Image: services.exe
Attached Process N/A Image: N/A
fffff78000000000: Unable to get shared data
Wait Start TickCount 36894
Context Switch Count 193 IdealProcessor: 1
ReadMemory error: Cannot get nt!KeMaximumIncrement value.
UserTime 00:00:00.000
KernelTime 00:00:00.000
Win32 Start Address 0x00007ff8975c20e0
Stack Init ffffc407c3a4cc90 Current ffffc407c3a4ba40
Base ffffc407c3a4d000 Limit ffffc407c3a47000 Call 0000000000000000
Priority 9 BasePriority 9 PriorityDecrement 0 IoPriority 2 PagePriority 5
Child-SP RetAddr : Args to Child : Call Site
ffffc407`c3a4bd88 fffff807`695068e2 : 00000000`000000ef ffff800f`39b10180 00000000`00000000 00000000`00000000 : nt!KeBugCheckEx
ffffc407`c3a4bd90 fffff807`69449b39 : 00000000`00000001 fffff807`68f5971d 00000000`00000002 fffff807`68f58d37 : nt!PspCatchCriticalBreak+0x10e
ffffc407`c3a4be30 fffff807`69309724 : ffff800f`00000000 00000000`00000000 ffff800f`39b10180 ffff800f`39b105b8 : nt!PspTerminateAllThreads+0x140b4d
ffffc407`c3a4bea0 fffff807`69309a4c : ffff800f`39b10180 00000000`00000001 ffffffff`ffffffff 00000000`00000000 : nt!PspTerminateProcess+0xe0
ffffc407`c3a4bee0 fffff807`690071b8 : ffff800f`39b10180 ffff800f`3da540c0 ffffc407`c3a4bfd0 fffff807`6931da92 : nt!NtTerminateProcess+0x9c
ffffc407`c3a4bf50 fffff807`68ff95e0 : fffff807`69091307 ffffc407`c3a4ca58 ffffc407`c3a4ca58 ffffffff`ffffffff : nt!KiSystemServiceCopyEnd+0x28 (TrapFrame @ ffffc407`c3a4bf50)
ffffc407`c3a4c0e8 fffff807`69091307 : ffffc407`c3a4ca58 ffffc407`c3a4ca58 ffffffff`ffffffff 00007ff7`715a1000 : nt!KiServiceLinkage
ffffc407`c3a4c0f0 fffff807`690078ac : ffff800f`39b108c0 fffff807`68f540e6 00000000`00003200 ffffc407`c3a4cb00 : nt!KiDispatchException+0x166907
ffffc407`c3a4c920 fffff807`69003a43 : 00000000`00000004 00000000`00000000 ffffc407`c3a4cb80 ffff800f`00000000 : nt!KiExceptionDispatch+0x12c
ffffc407`c3a4cb00 00007ff8`975d4042 : 00000000`00000000 0000002c`00000000 0000002c`4a201480 0000002c`4a201488 : nt!KiPageFault+0x443 (TrapFrame @ ffffc407`c3a4cb00)
0000002c`4a201460 00000000`00000000 : 0000002c`00000000 0000002c`4a201480 0000002c`4a201488 00007ff7`715a1000 : 0x00007ff8`975d4042
1: kd> .thread /p ffff800f3da540c0; !teb 0000002c49e52000
Implicit thread is now ffff800f`3da540c0
Implicit process is now ffff800f`39b10180
TEB at 0000002c49e52000
ExceptionList: 0000000000000000
StackBase: 0000002c4a280000
StackLimit: 0000002c4a201000
SubSystemTib: 0000000000000000
FiberData: 0000000000001e00
ArbitraryUserPointer: 0000000000000000
Self: 0000002c49e52000
EnvironmentPointer: 0000000000000000
ClientId: 00000000000003b0 . 0000000000000a84
Real ClientId: 0000000000000000 . 0000000000000000
RpcHandle: 0000000000000000
Tls Storage: 000001a042ea5110
PEB Address: 0000002c49fe1000
LastErrorValue: 2
LastStatusValue: 0
Count Owned Locks: 0
HardErrorMode: 0
1: kd> !thread ffff800f3da540c0
THREAD ffff800f3da540c0 Cid 03b0.0a84 Teb: 0000002c49e52000 Win32Thread: 0000000000000000 RUNNING on processor 1
Not impersonating
GetUlongFromAddress: unable to read from fffff807698114cc
Owning Process ffff800f39b10180 Image: services.exe
Attached Process N/A Image: N/A
fffff78000000000: Unable to get shared data
Wait Start TickCount 36894
Context Switch Count 193 IdealProcessor: 1
ReadMemory error: Cannot get nt!KeMaximumIncrement value.
UserTime 00:00:00.000
KernelTime 00:00:00.000
Win32 Start Address 0x00007ff8975c20e0
Stack Init ffffc407c3a4cc90 Current ffffc407c3a4ba40
Base ffffc407c3a4d000 Limit ffffc407c3a47000 Call 0000000000000000
Priority 9 BasePriority 9 PriorityDecrement 0 IoPriority 2 PagePriority 5
Child-SP RetAddr : Args to Child : Call Site
ffffc407`c3a4bd88 fffff807`695068e2 : 00000000`000000ef ffff800f`39b10180 00000000`00000000 00000000`00000000 : nt!KeBugCheckEx
ffffc407`c3a4bd90 fffff807`69449b39 : 00000000`00000001 fffff807`68f5971d 00000000`00000002 fffff807`68f58d37 : nt!PspCatchCriticalBreak+0x10e
ffffc407`c3a4be30 fffff807`69309724 : ffff800f`00000000 00000000`00000000 ffff800f`39b10180 ffff800f`39b105b8 : nt!PspTerminateAllThreads+0x140b4d
ffffc407`c3a4bea0 fffff807`69309a4c : ffff800f`39b10180 00000000`00000001 ffffffff`ffffffff 00000000`00000000 : nt!PspTerminateProcess+0xe0
ffffc407`c3a4bee0 fffff807`690071b8 : ffff800f`39b10180 ffff800f`3da540c0 ffffc407`c3a4bfd0 fffff807`6931da92 : nt!NtTerminateProcess+0x9c
ffffc407`c3a4bf50 fffff807`68ff95e0 : fffff807`69091307 ffffc407`c3a4ca58 ffffc407`c3a4ca58 ffffffff`ffffffff : nt!KiSystemServiceCopyEnd+0x28 (TrapFrame @ ffffc407`c3a4bf50)
ffffc407`c3a4c0e8 fffff807`69091307 : ffffc407`c3a4ca58 ffffc407`c3a4ca58 ffffffff`ffffffff 00007ff7`715a1000 : nt!KiServiceLinkage
ffffc407`c3a4c0f0 fffff807`690078ac : ffff800f`39b108c0 fffff807`68f540e6 00000000`00003200 ffffc407`c3a4cb00 : nt!KiDispatchException+0x166907
ffffc407`c3a4c920 fffff807`69003a43 : 00000000`00000004 00000000`00000000 ffffc407`c3a4cb80 ffff800f`00000000 : nt!KiExceptionDispatch+0x12c
ffffc407`c3a4cb00 00007ff8`975d4042 : 00000000`00000000 0000002c`00000000 0000002c`4a201480 0000002c`4a201488 : nt!KiPageFault+0x443 (TrapFrame @ ffffc407`c3a4cb00)
0000002c`4a201460 00000000`00000000 : 0000002c`00000000 0000002c`4a201480 0000002c`4a201488 00007ff7`715a1000 : 0x00007ff8`975d4042
1: kd> .lastevent
Last event: Break instruction exception - code 80000003 (first/second chance not available)
debugger time: Mon Dec 14 23:55:04.817 2020 (UTC + 3:00)
1: kd> !process ffff800f39b10180
PROCESS ffff800f39b10180
SessionId: 0 Cid: 03b0 Peb: 2c49fe1000 ParentCid: 0368
DirBase: 16f3b7000 ObjectTable: ffffe204e24a2b80 HandleCount: <Data Not Accessible>
Image: services.exe
VadRoot ffff800f396f8b70 Vads 76 Clone 0 Private 1317. Modified 721. Locked 2.
DeviceMap ffffe204dc237240
Token ffffe204e02bba70
ReadMemory error: Cannot get nt!KeMaximumIncrement value.
fffff78000000000: Unable to get shared data
ElapsedTime 00:00:00.000
UserTime 00:00:00.000
KernelTime 00:00:00.000
QuotaPoolUsage[PagedPool] 161976
QuotaPoolUsage[NonPagedPool] 13704
Working Set Sizes (now,min,max) (2856, 50, 345) (11424KB, 200KB, 1380KB)
PeakWorkingSetSize 2786
VirtualSize 2101320 Mb
PeakVirtualSize 2101329 Mb
PageFaultCount 4494
MemoryPriority BACKGROUND
BasePriority 9
CommitCharge 1609
*** Error in reading nt!_ETHREAD @ ffff800f39a10080
1: kd> !error
Error code: (Win32) 0 (0) - lem ba ar yla tamamland .
kd> !Memusage
fffff807698fa390: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
fffff8076980f330: Unable to get Flags value from nt!KdVersionBlock
Search: READ_PVOID error
InitTypeRead(nt!MmPhysicalMemoryBlock, nt!_PHYSICAL_MEMORY_DESCRIPTOR) error 1