24: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
UNEXPECTED_KERNEL_MODE_TRAP (7f)
This means a trap occurred in kernel mode, and it's a trap of a kind
that the kernel isn't allowed to have/catch (bound trap) or that
is always instant death (double fault). The first number in the
BugCheck params is the number of the trap (8 = double fault, etc)
Consult an Intel x86 family manual to learn more about what these
traps are. Here is a *portion* of those codes:
If kv shows a taskGate
use .tss on the part before the colon, then kv.
Else if kv shows a trapframe
use .trap on that value
Else
.trap on the appropriate frame will show where the trap was taken
(on x86, this will be the ebp that goes with the procedure KiTrap)
Endif
kb will then show the corrected stack.
Arguments:
Arg1: 0000000000000008, EXCEPTION_DOUBLE_FAULT
Arg2: ffffba00f6206e70
Arg3: 001bfbd74307408c
Arg4: fffff8066c2df738
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for FACEIT.sys
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 3608
Key : Analysis.DebugAnalysisManager
Value: Create
Key : Analysis.Elapsed.mSec
Value: 22160
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 0
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 358
Key : Analysis.Init.Elapsed.mSec
Value: 2015
Key : Analysis.Memory.CommitPeak.Mb
Value: 80
Key : Bugcheck.Code.DumpHeader
Value: 0x7f
Key : Bugcheck.Code.Register
Value: 0x7f
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Timestamp
Value: 2019-12-06T14:06:00Z
Key : WER.OS.Version
Value: 10.0.19041.1
FILE_IN_CAB: 052323-11000-01.dmp
BUGCHECK_CODE: 7f
BUGCHECK_P1: 8
BUGCHECK_P2: ffffba00f6206e70
BUGCHECK_P3: 1bfbd74307408c
BUGCHECK_P4: fffff8066c2df738
TRAP_FRAME: ffffba00f6206e70 -- (.trap 0xffffba00f6206e70)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=001bfbd74307408c rbx=0000000000000000 rcx=000000000c1d0200
rdx=006fef5d0c1d0230 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8066c2df738 rsp=001bfbd74307408c rbp=0000000060e81103
r8=006fef5d0c1d0230 r9=000000001d023001 r10=000000000c1d0201
r11=0000002bdf7e2501 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe nc
FACEIT+0x1bcf738:
fffff806`6c2df738 8a842420040000 mov al,byte ptr [rsp+420h] ss:001bfbd7`430744ac=??
Resetting default scope
BLACKBOXNTFS: 1 (!blackboxntfs)
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System
STACK_TEXT:
ffffba00`f6206d28 fffff806`4580fd29 : 00000000`0000007f 00000000`00000008 ffffba00`f6206e70 001bfbd7`4307408c : nt!KeBugCheckEx
ffffba00`f6206d30 fffff806`4580a43d : 00000250`840fed85 840f01a8`04458b41 e5358d48`00000244 81058b1f`eb001817 : nt!KiBugCheckDispatch+0x69
ffffba00`f6206e70 fffff806`6c2df738 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDoubleFaultAbort+0x2bd
001bfbd7`4307408c 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : FACEIT+0x1bcf738
SYMBOL_NAME: FACEIT+1bcf738
MODULE_NAME: FACEIT
IMAGE_NAME: FACEIT.sys
STACK_COMMAND: .cxr; .ecxr ; kb
BUCKET_ID_FUNC_OFFSET: 1bcf738
FAILURE_BUCKET_ID: 0x7f_8_FACEIT!unknown_function
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {bf6dd99d-dbdc-fc43-2be1-8afaf11bffd3}
Followup: MachineOwner
---------
24: kd> !sysinfo machineid
sysinfo: could not find necessary interfaces.
sysinfo: note that mssmbios.sys must be loaded (XPSP2+).
24: kd> lm
start end module name
fffff806`42c40000 fffff806`42ecf000 mcupdate_GenuineIntel # (pdb symbols) C:\ProgramData\Dbg\sym\mcupdate_GenuineIntel.pdb\2C3A3196EBAFC0B94B0D69BAE95496D91\mcupdate_GenuineIntel.pdb
fffff806`42ed0000 fffff806`42ed6000 hal (deferred)
fffff806`42ee0000 fffff806`42eeb000 kd (deferred)
fffff806`42ef0000 fffff806`42f17000 tm (deferred)
fffff806`42f20000 fffff806`42f8c000 CLFS (deferred)
fffff806`42f90000 fffff806`42faa000 PSHED (deferred)
fffff806`42fb0000 fffff806`42fbb000 BOOTVID (deferred)
fffff806`42fc0000 fffff806`4302d000 FLTMGR (deferred)
fffff806`43030000 fffff806`4303e000 cmimcext (deferred)
fffff806`45400000 fffff806`46446000 nt (pdb symbols) C:\ProgramData\Dbg\sym\ntkrnlmp.pdb\89284D0CA6ACC8274B9A44BD5AF9290B1\ntkrnlmp.pdb
fffff806`48600000 fffff806`48716000 clipsp (deferred)
fffff806`48720000 fffff806`48749000 ksecdd (deferred)
fffff806`48750000 fffff806`487b3000 msrpc (deferred)
fffff806`487c0000 fffff806`487d1000 werkernel (deferred)
fffff806`487e0000 fffff806`487ec000 ntosext (deferred)
fffff806`487f0000 fffff806`488d9000 CI (deferred)
fffff806`488e0000 fffff806`4899b000 cng (deferred)
fffff806`489a0000 fffff806`48a71000 Wdf01000 (deferred)
fffff806`48a80000 fffff806`48a93000 WDFLDR (deferred)
fffff806`48aa0000 fffff806`48aaf000 SleepStudyHelper (deferred)
fffff806`48ab0000 fffff806`48ac1000 WppRecorder (deferred)
fffff806`48ad0000 fffff806`48af6000 acpiex (deferred)
fffff806`48b00000 fffff806`48b0d000 msseccore (deferred)
fffff806`48b10000 fffff806`48b2a000 SgrmAgent (deferred)
fffff806`48b30000 fffff806`48bfc000 ACPI (deferred)
fffff806`48c00000 fffff806`48c0c000 WMILIB (deferred)
fffff806`48c10000 fffff806`48c1b000 msisadrv (deferred)
fffff806`48c20000 fffff806`48c97000 pci (deferred)
fffff806`48ca0000 fffff806`48ce4000 tpm (deferred)
fffff806`48d10000 fffff806`48d7b000 intelpep (deferred)
fffff806`48d80000 fffff806`48d97000 WindowsTrustedRT (deferred)
fffff806`48da0000 fffff806`48dab000 IntelTA (deferred)
fffff806`48db0000 fffff806`48dbb000 WindowsTrustedRTProxy (deferred)
fffff806`48dc0000 fffff806`48dd4000 pcw (deferred)
fffff806`48de0000 fffff806`48df5000 vdrvroot (deferred)
fffff806`48e00000 fffff806`48e2f000 pdc (deferred)
fffff806`48e30000 fffff806`48e49000 CEA (deferred)
fffff806`48e50000 fffff806`48e81000 partmgr (deferred)
fffff806`48e90000 fffff806`48f3c000 spaceport (deferred)
fffff806`48f40000 fffff806`48f59000 volmgr (deferred)
fffff806`48f60000 fffff806`48fc3000 volmgrx (deferred)
fffff806`48fd0000 fffff806`48fee000 mountmgr (deferred)
fffff806`48ff0000 fffff806`49022000 storahci (deferred)
fffff806`49030000 fffff806`490e5000 storport (deferred)
fffff806`490f0000 fffff806`49120000 stornvme (deferred)
fffff806`49130000 fffff806`4932d000 iaStorVD (deferred)
fffff806`49330000 fffff806`4934c000 EhStorClass (deferred)
fffff806`49350000 fffff806`4936a000 fileinfo (deferred)
fffff806`49370000 fffff806`493b0000 Wof (deferred)
fffff806`493c0000 fffff806`4943e000 WdFilter (deferred)
fffff806`49440000 fffff806`49716000 Ntfs (deferred)
fffff806`49720000 fffff806`4972d000 Fs_Rec (deferred)
fffff806`49730000 fffff806`4989f000 ndis (deferred)
fffff806`498a0000 fffff806`4993c000 NETIO (deferred)
fffff806`49940000 fffff806`49972000 ksecpkg (deferred)
fffff806`49980000 fffff806`49c6e000 tcpip (deferred)
fffff806`49c70000 fffff806`49cef000 fwpkclnt (deferred)
fffff806`49cf0000 fffff806`49d20000 wfplwfs (deferred)
fffff806`49d30000 fffff806`49df8000 fvevol (deferred)
fffff806`49e00000 fffff806`49e0b000 volume (deferred)
fffff806`49e10000 fffff806`49e7d000 volsnap (deferred)
fffff806`49e80000 fffff806`49ed0000 rdyboost (deferred)
fffff806`49ee0000 fffff806`49f06000 mup (deferred)
fffff806`49f10000 fffff806`49f22000 iorate (deferred)
fffff806`49f50000 fffff806`49f6f000 disk (deferred)
fffff806`49f70000 fffff806`49fe3000 CLASSPNP (deferred)
fffff806`5d000000 fffff806`5d030000 dump_stornvme (deferred)
fffff806`5d060000 fffff806`5d07d000 dump_dumpfve (deferred)
fffff806`5d350000 fffff806`5d36e000 crashdmp (deferred)
fffff806`5d380000 fffff806`5d38f000 dump_dumpstorport (deferred)
fffff806`6a710000 fffff806`6e94a000 FACEIT T (no symbols)
fffff806`6e950000 fffff806`6e980000 cdrom (deferred)
fffff806`6e990000 fffff806`6e9a5000 filecrypt (deferred)
fffff806`6e9b0000 fffff806`6e9be000 tbs (deferred)
fffff806`6e9c0000 fffff806`6e9ca000 Null (deferred)
fffff806`6e9d0000 fffff806`6e9da000 Beep (deferred)
fffff806`7ae00000 fffff806`7aea7000 afd (deferred)
fffff806`7aeb0000 fffff806`7aeca000 vwififlt (deferred)
fffff806`7aed0000 fffff806`7aefb000 pacer (deferred)
fffff806`7af00000 fffff806`7af14000 ndiscap (deferred)
fffff806`7af20000 fffff806`7af34000 netbios (deferred)
fffff806`7af40000 fffff806`7afe1000 Vid (deferred)
fffff806`7aff0000 fffff806`7b011000 winhvr (deferred)
fffff806`7b020000 fffff806`7b09b000 rdbss (deferred)
fffff806`7b0a0000 fffff806`7b135000 csc (deferred)
fffff806`7b140000 fffff806`7b152000 nsiproxy (deferred)
fffff806`7b160000 fffff806`7b16e000 npsvctrig (deferred)
fffff806`7b170000 fffff806`7b180000 mssmbios # (pdb symbols) C:\ProgramData\Dbg\sym\mssmbios.pdb\53ADC03D875B3F78AC94CE4D75054C461\mssmbios.pdb
fffff806`7b190000 fffff806`7b197000 MsIo64 (deferred)
fffff806`7b1a0000 fffff806`7b1aa000 gpuenergydrv (deferred)
fffff806`7b1b0000 fffff806`7b1dc000 dfsc (deferred)
fffff806`7b200000 fffff806`7b26c000 fastfat (deferred)
fffff806`7b270000 fffff806`7b27a000 CtiAIo64 (deferred)
fffff806`7b280000 fffff806`7b297000 bam (deferred)
fffff806`7b2a0000 fffff806`7b2ac000 AsIO3 (deferred)
fffff806`7b2b0000 fffff806`7b2fe000 ahcache (deferred)
fffff806`7b300000 fffff806`7b312000 CompositeBus (deferred)
fffff806`7b320000 fffff806`7b32d000 kdnic (deferred)
fffff806`7b330000 fffff806`7b345000 umbus (deferred)
fffff806`7b350000 fffff806`7b35c000 wmiacpi (deferred)
fffff806`7b6b0000 fffff806`7ba5a000 dxgkrnl (deferred)
fffff806`7ba60000 fffff806`7ba78000 watchdog (deferred)
fffff806`7ba80000 fffff806`7ba96000 BasicDisplay (deferred)
fffff806`7baa0000 fffff806`7bab1000 BasicRender (deferred)
fffff806`7bac0000 fffff806`7badc000 Npfs (deferred)
fffff806`7bae0000 fffff806`7baf1000 Msfs (deferred)
fffff806`7bb00000 fffff806`7bb1e000 CimFS (deferred)
fffff806`7bb20000 fffff806`7bb42000 tdx (deferred)
fffff806`7bb50000 fffff806`7bb60000 TDI (deferred)
fffff806`7bb70000 fffff806`7bbcc000 netbt (deferred)
fffff806`7bbd0000 fffff806`7bbe4000 afunix (deferred)
fffff806`8fa00000 fffff806`8fa21000 drmk (deferred)
fffff806`8fa30000 fffff806`8faa6000 ks (deferred)
fffff806`904b0000 fffff806`93d48000 nvlddmkm (deferred)
fffff806`93d50000 fffff806`93d77000 HDAudBus (deferred)
fffff806`93d80000 fffff806`93de6000 portcls (deferred)
Unloaded modules:
fffff806`7b1e0000 fffff806`7b1fc000 dam.sys
fffff806`48cf0000 fffff806`48d01000 WdBoot.sys
fffff806`49f30000 fffff806`49f41000 hwpolicy.sys
24: kd> lmDvmmcupdate_GenuineIntel
Browse full module list
start end module name
fffff806`42c40000 fffff806`42ecf000 mcupdate_GenuineIntel # (pdb symbols) C:\ProgramData\Dbg\sym\mcupdate_GenuineIntel.pdb\2C3A3196EBAFC0B94B0D69BAE95496D91\mcupdate_GenuineIntel.pdb
Loaded symbol image file: mcupdate_GenuineIntel.dll
Mapped memory image file: C:\ProgramData\Dbg\sym\mcupdate_GenuineIntel.dll\9FB1DE4628f000\mcupdate_GenuineIntel.dll
Image path: \SystemRoot\system32\mcupdate_GenuineIntel.dll
Image name: mcupdate_GenuineIntel.dll
Browse all global symbols functions data
Image was built with /Brepro flag.
Timestamp: 9FB1DE46 (This is a reproducible build file hash, not a timestamp)
CheckSum: 0028C60B
ImageSize: 0028F000
File version: 10.0.19041.1030
Product version: 10.0.19041.1030
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.A Driver
File date: 00000000.00000000
Translations: 0409.04b0
Information from resource tables:
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: mcupdate.dll
OriginalFilename: mcupdate_GenuineIntel.dll
ProductVersion: 10.0.19041.1030
FileVersion: 10.0.19041.1030 (WinBuild.160101.0800)
FileDescription: Intel Microcode Update Library
LegalCopyright: © Microsoft Corporation. All rights reserved.
24: kd> x /D /d mcupdate_GenuineIntel!a*
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z
24: kd> x /D /f mcupdate_GenuineIntel!a*
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z
24: kd> lmDvmFACEIT
Browse full module list
start end module name
fffff806`6a710000 fffff806`6e94a000 FACEIT T (no symbols)
Loaded symbol image file: FACEIT.sys
Image path: \??\C:\Program Files\FACEIT AC\FACEIT.sys
Image name: FACEIT.sys
Browse all global symbols functions data
Timestamp: Tue May 23 16:46:12 2023 (646CC3A4)
CheckSum: 04242565
ImageSize: 0423A000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
Information from resource tables:
24: kd> lmDvmFs_Rec
Browse full module list
start end module name
fffff806`49720000 fffff806`4972d000 Fs_Rec (deferred)
Mapped memory image file: C:\ProgramData\Dbg\sym\Fs_Rec.sys\B9E5C55Cd000\Fs_Rec.sys
Image path: \SystemRoot\System32\Drivers\Fs_Rec.sys
Image name: Fs_Rec.sys
Browse all global symbols functions data
Image was built with /Brepro flag.
Timestamp: B9E5C55C (This is a reproducible build file hash, not a timestamp)
CheckSum: 00017B4B
ImageSize: 0000D000
File version: 10.0.19041.1030
Product version: 10.0.19041.1030
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
Information from resource tables:
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: fs_rec.sys
OriginalFilename: fs_rec.sys
ProductVersion: 10.0.19041.1030
FileVersion: 10.0.19041.1030 (WinBuild.160101.0800)
FileDescription: File System Recognizer Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
24: kd> lmDvmnvlddmkm
Browse full module list
start end module name
fffff806`904b0000 fffff806`93d48000 nvlddmkm (deferred)
Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_e34a87a86b660c23\nvlddmkm.sys
Image name: nvlddmkm.sys
Browse all global symbols functions data
Timestamp: Tue Apr 25 21:16:05 2023 (644818E5)
CheckSum: 037998A4
ImageSize: 03898000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
Information from resource tables: