5: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_THREAD_EXCEPTION_NOT_HANDLED (7e)
This is a very common BugCheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff8007badd2a2, The address that the exception occurred at
Arg3: ffffce046026e488, Exception Record Address
Arg4: ffffce046026dcc0, Context Record Address
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for nvlddmkm.sys
KEY_VALUES_STRING: 1
Key : AV.Dereference
Value: NullClassPtr
Key : AV.Fault
Value: Read
Key : Analysis.CPU.mSec
Value: 3734
Key : Analysis.Elapsed.mSec
Value: 9451
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 0
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 437
Key : Analysis.Init.Elapsed.mSec
Value: 2826
Key : Analysis.Memory.CommitPeak.Mb
Value: 99
Key : Bugcheck.Code.LegacyAPI
Value: 0x1000007e
Key : Failure.Bucket
Value: AV_nvlddmkm!unknown_function
Key : Failure.Hash
Value: {7eea5677-f68d-2154-717e-887e07e55cd3}
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Version
Value: 10.0.19041.1
BUGCHECK_CODE: 7e
BUGCHECK_P1: ffffffffc0000005
BUGCHECK_P2: fffff8007badd2a2
BUGCHECK_P3: ffffce046026e488
BUGCHECK_P4: ffffce046026dcc0
FILE_IN_CAB: 062423-6906-01.dmp
EXCEPTION_RECORD: ffffce046026e488 -- (.exr 0xffffce046026e488)
ExceptionAddress: fffff8007badd2a2 (nvlddmkm+0x00000000004ed2a2)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: 00000000000001c7
Attempt to read from address 00000000000001c7
CONTEXT: ffffce046026dcc0 -- (.cxr 0xffffce046026dcc0)
rax=000000000000000f rbx=ffff918145802000 rcx=ffff918145802000
rdx=0000000000000004 rsi=ffff918141fb6000 rdi=0000000000000000
rip=fffff8007badd2a2 rsp=ffffce046026e6c0 rbp=ffffce046026e6f8
r8=0000000000000000 r9=0000000000000000 r10=0000000000000000
r11=ffffce046026e450 r12=0000000000000000 r13=ffff918141de1c20
r14=0000000000000004 r15=000000000000000f
iopl=0 nv up ei pl nz na po nc
cs=0010 ss=0000 ds=002b es=002b fs=0053 gs=002b efl=00050206
nvlddmkm+0x4ed2a2:
fffff800`7badd2a2 488b80b8010000 mov rax,qword ptr [rax+1B8h] ds:002b:00000000`000001c7=????????????????
Resetting default scope
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System
READ_ADDRESS: fffff800576fb390: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
unable to get nt!MmSpecialPagesInUse
00000000000001c7
ERROR_CODE: (NTSTATUS) 0xc0000005 - 0x%p adresindeki y nerge 0x%p adresindeki belle e ba vurdu. Bellek u olamaz %s.
EXCEPTION_CODE_STR: c0000005
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: 00000000000001c7
EXCEPTION_STR: 0xc0000005
STACK_TEXT:
ffffce04`6026e6c0 ffff9181`45802000 : ffff9181`41fb6000 ffff9181`41fb6000 00000000`ffffffff 00000000`ffffffef : nvlddmkm+0x4ed2a2
ffffce04`6026e6c8 ffff9181`41fb6000 : ffff9181`41fb6000 00000000`ffffffff 00000000`ffffffef 00000000`006104e8 : 0xffff9181`45802000
ffffce04`6026e6d0 ffff9181`41fb6000 : 00000000`ffffffff 00000000`ffffffef 00000000`006104e8 00000000`00000001 : 0xffff9181`41fb6000
ffffce04`6026e6d8 00000000`ffffffff : 00000000`ffffffef 00000000`006104e8 00000000`00000001 00000000`00000002 : 0xffff9181`41fb6000
ffffce04`6026e6e0 00000000`ffffffef : 00000000`006104e8 00000000`00000001 00000000`00000002 00000000`00000001 : 0xffffffff
ffffce04`6026e6e8 00000000`006104e8 : 00000000`00000001 00000000`00000002 00000000`00000001 ffff9181`41fea0d0 : 0xffffffef
ffffce04`6026e6f0 00000000`00000001 : 00000000`00000002 00000000`00000001 ffff9181`41fea0d0 00000000`ff1fe100 : 0x6104e8
ffffce04`6026e6f8 00000000`00000002 : 00000000`00000001 ffff9181`41fea0d0 00000000`ff1fe100 00000000`00000006 : 0x1
ffffce04`6026e700 00000000`00000001 : ffff9181`41fea0d0 00000000`ff1fe100 00000000`00000006 ffff9181`45802000 : 0x2
ffffce04`6026e708 ffff9181`41fea0d0 : 00000000`ff1fe100 00000000`00000006 ffff9181`45802000 ffff9181`41fb6000 : 0x1
ffffce04`6026e710 00000000`ff1fe100 : 00000000`00000006 ffff9181`45802000 ffff9181`41fb6000 ffffce04`6026e7d0 : 0xffff9181`41fea0d0
ffffce04`6026e718 00000000`00000006 : ffff9181`45802000 ffff9181`41fb6000 ffffce04`6026e7d0 fffff800`7baf79ea : 0xff1fe100
ffffce04`6026e720 ffff9181`45802000 : ffff9181`41fb6000 ffffce04`6026e7d0 fffff800`7baf79ea 00000000`ffffff00 : 0x6
ffffce04`6026e728 ffff9181`41fb6000 : ffffce04`6026e7d0 fffff800`7baf79ea 00000000`ffffff00 00000000`ffffffff : 0xffff9181`45802000
ffffce04`6026e730 ffffce04`6026e7d0 : fffff800`7baf79ea 00000000`ffffff00 00000000`ffffffff 00000000`00000001 : 0xffff9181`41fb6000
ffffce04`6026e738 fffff800`7baf79ea : 00000000`ffffff00 00000000`ffffffff 00000000`00000001 00000000`00000000 : 0xffffce04`6026e7d0
ffffce04`6026e740 00000000`ffffff00 : 00000000`ffffffff 00000000`00000001 00000000`00000000 ffff9181`00000000 : nvlddmkm+0x5079ea
ffffce04`6026e748 00000000`ffffffff : 00000000`00000001 00000000`00000000 ffff9181`00000000 ffff9181`41fea0d0 : 0xffffff00
ffffce04`6026e750 00000000`00000001 : 00000000`00000000 ffff9181`00000000 ffff9181`41fea0d0 00000000`00000002 : 0xffffffff
ffffce04`6026e758 00000000`00000000 : ffff9181`00000000 ffff9181`41fea0d0 00000000`00000002 00000000`00000001 : 0x1
SYMBOL_NAME: nvlddmkm+4ed2a2
MODULE_NAME: nvlddmkm
IMAGE_NAME: nvlddmkm.sys
STACK_COMMAND: .cxr 0xffffce046026dcc0 ; kb
BUCKET_ID_FUNC_OFFSET: 4ed2a2
FAILURE_BUCKET_ID: AV_nvlddmkm!unknown_function
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {7eea5677-f68d-2154-717e-887e07e55cd3}
Followup: MachineOwner
---------
3: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
WHEA_UNCORRECTABLE_ERROR (124)
A fatal hardware error has occurred. Parameter 1 identifies the type of error
source that reported the error. Parameter 2 holds the address of the
nt!_WHEA_ERROR_RECORD structure that describes the error condition. Try !errrec Address of the nt!_WHEA_ERROR_RECORD structure to get more details.
Arguments:
Arg1: 0000000000000000, Machine Check Exception
Arg2: ffffe78e0b893028, Address of the nt!_WHEA_ERROR_RECORD structure.
Arg3: 00000000fe000000, High order 32-bits of the MCi_STATUS value.
Arg4: 0000000000801136, Low order 32-bits of the MCi_STATUS value.
Debugging Details:
------------------
*************************************************************************
*** ***
*** ***
*** Either you specified an unqualified symbol, or your debugger ***
*** doesn't have full symbol information. Unqualified symbol ***
*** resolution is turned off by default. Please either specify a ***
*** fully qualified symbol module!symbolname, or enable resolution ***
*** of unqualified symbols by typing ".symopt- 100". Note that ***
*** enabling unqualified symbol resolution with network symbol ***
*** server shares in the symbol path may cause the debugger to ***
*** appear to hang for long periods of time when an incorrect ***
*** symbol name is typed or the network symbol server is down. ***
*** ***
*** For some commands to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: hal!_WHEA_PROCESSOR_GENERIC_ERROR_SECTION ***
*** ***
*************************************************************************
*************************************************************************
*** ***
*** ***
*** Either you specified an unqualified symbol, or your debugger ***
*** doesn't have full symbol information. Unqualified symbol ***
*** resolution is turned off by default. Please either specify a ***
*** fully qualified symbol module!symbolname, or enable resolution ***
*** of unqualified symbols by typing ".symopt- 100". Note that ***
*** enabling unqualified symbol resolution with network symbol ***
*** server shares in the symbol path may cause the debugger to ***
*** appear to hang for long periods of time when an incorrect ***
*** symbol name is typed or the network symbol server is down. ***
*** ***
*** For some commands to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: hal!_WHEA_PROCESSOR_GENERIC_ERROR_SECTION ***
*** ***
*************************************************************************
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 4312
Key : Analysis.Elapsed.mSec
Value: 6550
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 0
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 374
Key : Analysis.Init.Elapsed.mSec
Value: 1701
Key : Analysis.Memory.CommitPeak.Mb
Value: 97
Key : Bugcheck.Code.LegacyAPI
Value: 0x124
Key : Failure.Bucket
Value: 0x124_0_GenuineIntel_PROCESSOR__UNKNOWN_IMAGE_GenuineIntel.sys
Key : Failure.Hash
Value: {5371cb52-c3d9-558e-47d4-d31c09567ca2}
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Version
Value: 10.0.19041.1
BUGCHECK_CODE: 124
BUGCHECK_P1: 0
BUGCHECK_P2: ffffe78e0b893028
BUGCHECK_P3: fe000000
BUGCHECK_P4: 801136
FILE_IN_CAB: 062523-7484-01.dmp
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: MsMpEng.exe
STACK_TEXT:
ffffc200`5f6948e8 fffff807`4e4b77ba : 00000000`00000124 00000000`00000000 ffffe78e`0b893028 00000000`fe000000 : nt!KeBugCheckEx
ffffc200`5f6948f0 fffff807`4d0b15b0 : 00000000`00000000 ffffe78e`0b893028 ffffe78e`092d9e30 ffffe78e`0b893028 : nt!HalBugCheckSystem+0xca
ffffc200`5f694930 fffff807`4e5b9a9e : 00000000`00000000 ffffc200`5f6949d9 ffffe78e`0b893028 ffffe78e`092d9e30 : PSHED!PshedBugCheckSystem+0x10
ffffc200`5f694960 fffff807`4e4b90e1 : ffffe78e`091029c0 ffffe78e`091029c0 ffffe78e`092d9e80 ffffe78e`092d9e30 : nt!WheaReportHwError+0x46e
ffffc200`5f694a40 fffff807`4e4b9453 : 00000000`00000003 ffffe78e`092d9e80 ffffe78e`092d9e30 00000000`00000003 : nt!HalpMcaReportError+0xb1
ffffc200`5f694bb0 fffff807`4e4b9330 : ffffe78e`09124ba8 00000001`00000001 00000000`00000000 00000000`00000000 : nt!HalpMceHandlerCore+0xef
ffffc200`5f694c00 fffff807`4e4b9581 : 00000000`0000000c 00000000`00000001 00000000`00000000 00000000`00000000 : nt!HalpMceHandler+0xe0
ffffc200`5f694c40 fffff807`4e4b87eb : 00000000`00000000 00000000`00000000 ffffc200`5f694ed0 00000000`00000000 : nt!HalpMceHandlerWithRendezvous+0xc9
ffffc200`5f694c70 fffff807`4e4bb035 : ffffe78e`09124ba8 00000000`00000000 00000000`00000000 00000000`00000000 : nt!HalpHandleMachineCheck+0x5f
ffffc200`5f694ca0 fffff807`4e510b59 : 00000001`40cfb1d0 00000000`00000000 00000000`00000000 00000000`00000000 : nt!HalHandleMcheck+0x35
ffffc200`5f694cd0 fffff807`4e40cbba : 00000001`40cfb1d8 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiHandleMcheck+0x9
ffffc200`5f694d00 fffff807`4e40c877 : 00000000`00000000 00000000`00000000 00000200`a6562680 00000000`00000000 : nt!KxMcheckAbort+0x7a
ffffc200`5f694e40 00007fff`a6eec95a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiMcheckAbort+0x277
000000b1`1fdfa0b0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007fff`a6eec95a
MODULE_NAME: GenuineIntel
IMAGE_NAME: GenuineIntel.sys
STACK_COMMAND: .cxr; .ecxr ; kb
FAILURE_BUCKET_ID: 0x124_0_GenuineIntel_PROCESSOR__UNKNOWN_IMAGE_GenuineIntel.sys
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {5371cb52-c3d9-558e-47d4-d31c09567ca2}
Followup: MachineOwner
---------