1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_OVERRAN_STACK_BUFFER (f7)
A driver has overrun a stack-based buffer. This overrun could potentially
allow a malicious user to gain control of this machine.
DESCRIPTION
A driver overran a stack-based buffer (or local variable) in a way that would
have overwritten the function's return address and jumped back to an arbitrary
address when the function returned. This is the classic "buffer overrun"
hacking attack and the system has been brought down to prevent a malicious user
from gaining complete control of it.
Do a kb to get a stack backtrace -- the last routine on the stack before the
buffer overrun handlers and BugCheck call is the one that overran its local
variable(s).
Arguments:
Arg1: 8e3fd78353115990, Actual security check cookie from the stack
Arg2: 00004c41cb910e69, Expected security check cookie
Arg3: ffffb3be346ef196, Complement of the expected security check cookie
Arg4: 0000000000000000, zero
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for WdFilter.sys
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 2452
Key : Analysis.DebugAnalysisManager
Value: Create
Key : Analysis.Elapsed.mSec
Value: 2471
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 0
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 390
Key : Analysis.Init.Elapsed.mSec
Value: 5559
Key : Analysis.Memory.CommitPeak.Mb
Value: 82
Key : Bugcheck.Code.DumpHeader
Value: 0xf7
Key : Bugcheck.Code.Register
Value: 0xf7
Key : Dump.Attributes.AsUlong
Value: 8
Key : Dump.Attributes.KernelGeneratedTriageDump
Value: 1
FILE_IN_CAB: 060423-8343-01.dmp
DUMP_FILE_ATTRIBUTES: 0x8
Kernel Generated Triage Dump
BUGCHECK_CODE: f7
BUGCHECK_P1: 8e3fd78353115990
BUGCHECK_P2: 4c41cb910e69
BUGCHECK_P3: ffffb3be346ef196
BUGCHECK_P4: 0
SECURITY_COOKIE: Expected 00004c41cb910e69 found 8e3fd78353115990
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System
STACK_TEXT:
ffffd783`53115948 fffff802`57ab49f5 : 00000000`000000f7 8e3fd783`53115990 00004c41`cb910e69 ffffb3be`346ef196 : nt!KeBugCheckEx
ffffd783`53115950 fffff802`578dd168 : 00000000`00000000 00000000`00000000 00000000`00000100 00000000`00000000 : nt!_report_gsfailure+0x25
ffffd783`53115990 fffff802`5ad81d16 : ffffffff`fd050f80 ffff878f`00000000 ffff9f01`7e202b78 00000000`00000000 : nt!KeWaitForMultipleObjects+0x318
ffffd783`53115aa0 ffffffff`fd050f80 : ffff878f`00000000 ffff9f01`7e202b78 00000000`00000000 00000000`00000100 : WdFilter+0x21d16
ffffd783`53115aa8 ffff878f`00000000 : ffff9f01`7e202b78 00000000`00000000 00000000`00000100 00000000`00000000 : 0xffffffff`fd050f80
ffffd783`53115ab0 ffff9f01`7e202b78 : 00000000`00000000 00000000`00000100 00000000`00000000 00000000`00000000 : 0xffff878f`00000000
ffffd783`53115ab8 00000000`00000000 : 00000000`00000100 00000000`00000000 00000000`00000000 00000000`00000000 : 0xffff9f01`7e202b78
SYMBOL_NAME: WdFilter+21d16
MODULE_NAME: WdFilter
IMAGE_NAME: WdFilter.sys
STACK_COMMAND: .cxr; .ecxr ; kb
BUCKET_ID_FUNC_OFFSET: 21d16
FAILURE_BUCKET_ID: 0xF7_MISSING_GSFRAME_WdFilter!unknown_function
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {3620ba2e-b4c0-25d0-6437-846ff96c5b64}
Followup: MachineOwner
---------
1: kd> lm
start end module name
ffff822a`11800000 ffff822a`11ad1000 win32kbase (pdb symbols) C:\ProgramData\Dbg\sym\win32kbase.pdb\1C27DBD3D6FED13B61F3BBB46D814B9C1\win32kbase.pdb
ffff822a`11ae0000 ffff822a`11e95000 win32kfull (deferred)
ffff822a`11ea0000 ffff822a`11ee9000 cdd (deferred)
ffff822a`12520000 ffff822a`125bb000 win32k (deferred)
fffff802`54780000 fffff802`54a0f000 mcupdate (deferred)
fffff802`54a10000 fffff802`54a16000 hal (deferred)
fffff802`54a20000 fffff802`54a2b000 kdcom (deferred)
fffff802`54a30000 fffff802`54a57000 tm (deferred)
fffff802`54a60000 fffff802`54acc000 CLFS (deferred)
fffff802`54ad0000 fffff802`54aea000 PSHED (deferred)
fffff802`54af0000 fffff802`54afb000 BOOTVID (deferred)
fffff802`54b00000 fffff802`54b6d000 FLTMGR (deferred)
fffff802`54b70000 fffff802`54b7e000 cmimcext (deferred)
fffff802`57600000 fffff802`58646000 nt (pdb symbols) C:\ProgramData\Dbg\sym\ntkrnlmp.pdb\40B8DB4FCF8B9D0352BFF2EF2903CB891\ntkrnlmp.pdb
fffff802`5a000000 fffff802`5a117000 clipsp (deferred)
fffff802`5a120000 fffff802`5a149000 ksecdd (deferred)
fffff802`5a150000 fffff802`5a1b3000 msrpc (deferred)
fffff802`5a1c0000 fffff802`5a1d1000 werkernel (deferred)
fffff802`5a1e0000 fffff802`5a1ec000 ntosext (deferred)
fffff802`5a1f0000 fffff802`5a2d8000 CI (deferred)
fffff802`5a2e0000 fffff802`5a39b000 cng (deferred)
fffff802`5a3a0000 fffff802`5a471000 Wdf01000 (deferred)
fffff802`5a480000 fffff802`5a493000 WDFLDR (deferred)
fffff802`5a4a0000 fffff802`5a4af000 SleepStudyHelper (deferred)
fffff802`5a4b0000 fffff802`5a4c1000 WppRecorder (deferred)
fffff802`5a4d0000 fffff802`5a4f6000 acpiex (deferred)
fffff802`5a500000 fffff802`5a50d000 msseccore (deferred)
fffff802`5a510000 fffff802`5a52a000 SgrmAgent (deferred)
fffff802`5a530000 fffff802`5a5fc000 ACPI (deferred)
fffff802`5a600000 fffff802`5a60c000 WMILIB (deferred)
fffff802`5a610000 fffff802`5a61b000 msisadrv (deferred)
fffff802`5a620000 fffff802`5a697000 pci (deferred)
fffff802`5a6a0000 fffff802`5a6e4000 tpm (deferred)
fffff802`5a710000 fffff802`5a77b000 intelpep (deferred)
fffff802`5a780000 fffff802`5a797000 WindowsTrustedRT (deferred)
fffff802`5a7a0000 fffff802`5a7ab000 IntelTA (deferred)
fffff802`5a7b0000 fffff802`5a7bb000 WindowsTrustedRTProxy (deferred)
fffff802`5a7c0000 fffff802`5a7d4000 pcw (deferred)
fffff802`5a7e0000 fffff802`5a7f5000 vdrvroot (deferred)
fffff802`5a800000 fffff802`5a82f000 pdc (deferred)
fffff802`5a830000 fffff802`5a849000 CEA (deferred)
fffff802`5a850000 fffff802`5a881000 partmgr (deferred)
fffff802`5a890000 fffff802`5a93c000 spaceport (deferred)
fffff802`5a940000 fffff802`5a959000 volmgr (deferred)
fffff802`5a960000 fffff802`5a9c3000 volmgrx (deferred)
fffff802`5a9d0000 fffff802`5a9ee000 mountmgr (deferred)
fffff802`5a9f0000 fffff802`5aa20000 stornvme (deferred)
fffff802`5aa30000 fffff802`5aae5000 storport (deferred)
fffff802`5aaf0000 fffff802`5acce000 iaStorAC (deferred)
fffff802`5acd0000 fffff802`5acec000 EhStorClass (deferred)
fffff802`5acf0000 fffff802`5ad0a000 fileinfo (deferred)
fffff802`5ad10000 fffff802`5ad50000 Wof (deferred)
fffff802`5ad60000 fffff802`5adde000 WdFilter T (no symbols)
fffff802`5ade0000 fffff802`5b0b6000 Ntfs (deferred)
fffff802`5b0c0000 fffff802`5b0cd000 Fs_Rec (deferred)
fffff802`5b0d0000 fffff802`5b23f000 ndis (deferred)
fffff802`5b240000 fffff802`5b2dc000 NETIO (deferred)
fffff802`5b2e0000 fffff802`5b312000 ksecpkg (deferred)
fffff802`5b320000 fffff802`5b60e000 tcpip (deferred)
fffff802`5b610000 fffff802`5b68f000 fwpkclnt (deferred)
fffff802`5b690000 fffff802`5b6c0000 wfplwfs (deferred)
fffff802`5b6d0000 fffff802`5b798000 fvevol (deferred)
fffff802`5b7a0000 fffff802`5b7ab000 volume (deferred)
fffff802`5b7b0000 fffff802`5b81d000 volsnap (deferred)
fffff802`5b820000 fffff802`5b870000 rdyboost (deferred)
fffff802`5b880000 fffff802`5b8a6000 mup (deferred)
fffff802`5b8b0000 fffff802`5b8c2000 iorate (deferred)
fffff802`5b8f0000 fffff802`5b90f000 disk (deferred)
fffff802`5b910000 fffff802`5b983000 CLASSPNP (deferred)
fffff802`6e600000 fffff802`6e9aa000 dxgkrnl (deferred)
fffff802`6e9b0000 fffff802`6ea2b000 rdbss (deferred)
fffff802`6ea30000 fffff802`6eac5000 csc (deferred)
fffff802`6ead0000 fffff802`6eae0000 mssmbios (deferred)
fffff802`6eaf0000 fffff802`6eb1c000 dfsc (deferred)
fffff802`6eb20000 fffff802`6eb3c000 serial (deferred)
fffff802`6eb40000 fffff802`6ebac000 fastfat (deferred)
fffff802`6ebb0000 fffff802`6ebc7000 bam (deferred)
fffff802`6ebd0000 fffff802`6ec1e000 ahcache (deferred)
fffff802`6ec20000 fffff802`6ec32000 CompositeBus (deferred)
fffff802`6ec40000 fffff802`6ec4d000 kdnic (deferred)
fffff802`6ec50000 fffff802`6ec65000 umbus (deferred)
fffff802`6ec70000 fffff802`6ec88000 lltdio (deferred)
fffff802`6ecc0000 fffff802`6ecde000 crashdmp (deferred)
fffff802`6ece0000 fffff802`6ecfd000 wanarp (deferred)
fffff802`6ed00000 fffff802`6ed1b000 rspndr (deferred)
fffff802`6edc0000 fffff802`6edd4000 kbdclass (deferred)
fffff802`6ede0000 fffff802`6edf3000 mouclass (deferred)
fffff802`73400000 fffff802`7345c000 netbt (deferred)
fffff802`73460000 fffff802`73474000 afunix (deferred)
fffff802`73480000 fffff802`73527000 afd (deferred)
fffff802`73530000 fffff802`7354a000 vwififlt (deferred)
fffff802`73550000 fffff802`7357b000 pacer (deferred)
fffff802`73580000 fffff802`73594000 ndiscap (deferred)
fffff802`735a0000 fffff802`735b4000 netbios (deferred)
fffff802`735c0000 fffff802`73661000 Vid (deferred)
fffff802`73670000 fffff802`73691000 winhvr (deferred)
fffff802`736a0000 fffff802`74c14000 vgk (deferred)
fffff802`74c20000 fffff802`74c50000 cdrom (deferred)
fffff802`74c60000 fffff802`74c75000 filecrypt (deferred)
fffff802`74c80000 fffff802`74c8e000 tbs (deferred)
fffff802`74c90000 fffff802`74c9a000 Null (deferred)
fffff802`74ca0000 fffff802`74caa000 Beep (deferred)
fffff802`74cb0000 fffff802`74cc8000 watchdog (deferred)
fffff802`74cd0000 fffff802`74ce6000 BasicDisplay (deferred)
fffff802`74cf0000 fffff802`74d01000 BasicRender (deferred)
fffff802`74d10000 fffff802`74d2c000 Npfs (deferred)
fffff802`74d30000 fffff802`74d41000 Msfs (deferred)
fffff802`74d50000 fffff802`74d6e000 CimFS (deferred)
fffff802`74d70000 fffff802`74d92000 tdx (deferred)
fffff802`74da0000 fffff802`74db0000 TDI (deferred)
fffff802`74dc0000 fffff802`74dd2000 nsiproxy (deferred)
fffff802`74de0000 fffff802`74dee000 npsvctrig (deferred)
fffff802`74df0000 fffff802`74dfa000 gpuenergydrv (deferred)
fffff802`80800000 fffff802`80821000 drmk (deferred)
fffff802`80830000 fffff802`808a6000 ks (deferred)
fffff802`808b0000 fffff802`8094d000 USBXHCI (deferred)
fffff802`80950000 fffff802`80994000 ucx01000 (deferred)
fffff802`809a0000 fffff802`80a4f000 UcmCxUcsiNvppc (deferred)
fffff802`80a50000 fffff802`80a7c000 UcmCx (deferred)
fffff802`80a80000 fffff802`80acf000 TeeDriverW10x64 (deferred)
fffff802`80ad0000 fffff802`80bf1000 rt640x64 (deferred)
fffff802`80c00000 fffff802`80c0f000 serenum (deferred)
fffff802`80c10000 fffff802`8455f000 nvlddmkm (deferred)
fffff802`84560000 fffff802`84585000 HDAudBus (deferred)
fffff802`84590000 fffff802`845f6000 portcls (deferred)
fffff802`8d400000 fffff802`8d40e000 UEFI (deferred)
fffff802`8d410000 fffff802`8d41f000 nvvad64v (deferred)
fffff802`8d420000 fffff802`8d42f000 ksthunk (deferred)
fffff802`8d430000 fffff802`8d43d000 NvModuleTracker (deferred)
fffff802`8d440000 fffff802`8d450000 nvvhci (deferred)
fffff802`8d460000 fffff802`8d46d000 NdisVirtualBus (deferred)
fffff802`8d470000 fffff802`8d47c000 swenum (deferred)
fffff802`8d480000 fffff802`8d48e000 CorsairVBusDriver (deferred)
fffff802`8d490000 fffff802`8d49e000 rdpbus (deferred)
fffff802`8d4a0000 fffff802`8d4ac000 droidcamvideo (deferred)
fffff802`8d4b0000 fffff802`8d4cc000 STREAM (deferred)
fffff802`8d4d0000 fffff802`8d4da000 droidcam (deferred)
fffff802`8d4f0000 fffff802`8d531000 HIDCLASS (deferred)
fffff802`8d540000 fffff802`8d553000 HIDPARSE (deferred)
fffff802`8d560000 fffff802`8d56c000 ICCWDT (deferred)
fffff802`8d570000 fffff802`8d57f000 Smb_driver_Intel (deferred)
fffff802`8d580000 fffff802`8d58c000 wmiacpi (deferred)
fffff802`8d590000 fffff802`8d5d1000 intelppm (deferred)
fffff802`8d5e0000 fffff802`8d5eb000 acpipagr (deferred)
fffff802`8d5f0000 fffff802`8d5fc000 acpitime (deferred)
fffff802`8d600000 fffff802`8d611000 kbdhid (deferred)
fffff802`8d620000 fffff802`8d63e000 nvhda64v (deferred)
fffff802`8d6b0000 fffff802`8d6e4000 usbccgp (deferred)
fffff802`8d6f0000 fffff802`8d702000 hidusb (deferred)
fffff802`8d710000 fffff802`8d74a000 usbaudio (deferred)
fffff802`8d750000 fffff802`8d761000 CorsairGamingAudio64 (deferred)
fffff802`8d770000 fffff802`8d780000 mouhid (deferred)
fffff802`8d7a0000 fffff802`8d7af000 dump_storport (deferred)
fffff802`8d7f0000 fffff802`8d820000 dump_stornvme (deferred)
fffff802`8d850000 fffff802`8d86d000 dump_dumpfve (deferred)
fffff802`8d870000 fffff802`8d951000 dxgmms2 (deferred)
fffff802`8d960000 fffff802`8d97b000 monitor (deferred)
fffff802`8d980000 fffff802`8d9ab000 luafv (deferred)
fffff802`8d9b0000 fffff802`8d9e7000 wcifs (deferred)
fffff802`8d9f0000 fffff802`8da70000 cldflt (deferred)
fffff802`8da80000 fffff802`8da94000 mmcss (deferred)
fffff802`8daa0000 fffff802`8daba000 storqosflt (deferred)
fffff802`8dac0000 fffff802`8dae7000 bindflt (deferred)
fffff802`8daf0000 fffff802`8db08000 mslldp (deferred)
fffff802`8db30000 fffff802`8dbd3000 UsbHub3 (deferred)
fffff802`8dbe0000 fffff802`8dbee000 USBD (deferred)
fffff802`bb800000 fffff802`bb894000 mrxsmb (deferred)
fffff802`bb8a0000 fffff802`bb8e6000 mrxsmb20 (deferred)
fffff802`bb8f0000 fffff802`bb8f9000 CorsairLLAccess64 (deferred)
fffff802`bb900000 fffff802`bb957000 srvnet (deferred)
fffff802`bb960000 fffff802`bb987000 Ndu (deferred)
fffff802`bb990000 fffff802`bba67000 peauth (deferred)
fffff802`bba70000 fffff802`bba85000 tcpipreg (deferred)
fffff802`bba90000 fffff802`bbb57000 srv2 (deferred)
fffff802`bbb60000 fffff802`bbb7d000 rassstp (deferred)
fffff802`bbb80000 fffff802`bbb9d000 NDProxy (deferred)
fffff802`bbba0000 fffff802`bbbc9000 AgileVpn (deferred)
fffff802`bbbd0000 fffff802`bbbf3000 rasl2tp (deferred)
fffff802`bbc00000 fffff802`bbc12000 condrv (deferred)
fffff802`bbc20000 fffff802`bbc41000 raspptp (deferred)
fffff802`bbc50000 fffff802`bbc6e000 raspppoe (deferred)
fffff802`bbc70000 fffff802`bbc7f000 ndistapi (deferred)
fffff802`bbc80000 fffff802`bbcba000 ndiswan (deferred)
fffff802`bbcc0000 fffff802`bbdb3000 xvdd (deferred)
fffff802`bbdc0000 fffff802`bbde0000 gameflt (deferred)
fffff802`bbdf0000 fffff802`bbdfd000 cpuz157_x64 (deferred)
fffff802`bbe00000 fffff802`bbe1c000 WdNisDrv (deferred)
fffff802`bbe20000 fffff802`bbe2e000 ALSysIO64 (deferred)
fffff802`bbe30000 fffff802`bbe39000 CorsairVHidDriver (deferred)
fffff802`bc3b0000 fffff802`bc406000 msquic (deferred)
fffff802`bc410000 fffff802`bc597000 HTTP (deferred)
fffff802`bc5a0000 fffff802`bc5c5000 bowser (deferred)
fffff802`bc5d0000 fffff802`bc5ea000 mpsdrv (deferred)
fffff804`17ab0000 fffff804`18057000 RTKVHD64 (deferred)
Unloaded modules:
fffff804`14c00000 fffff804`151a8000 RTKVHD64.sys
fffff802`8d4e0000 fffff802`8d4ea000 CorsairVHidD
fffff802`8d640000 fffff802`8d6b0000 HdAudio.sys
fffff802`8db10000 fffff802`8db23000 MSKSSRV.sys
fffff802`6ecf0000 fffff802`6ed00000 dump_storpor
fffff802`6ed40000 fffff802`6ed71000 dump_stornvm
fffff802`6eda0000 fffff802`6edbe000 dump_dumpfve
fffff802`6ec70000 fffff802`6ec92000 i8042prt.sys
fffff802`6eb20000 fffff802`6eb3c000 dam.sys
fffff802`5a6f0000 fffff802`5a701000 WdBoot.sys
fffff802`5b8d0000 fffff802`5b8e1000 hwpolicy.sys
1: kd> !sysinfo machineid
Machine ID Information [From Smbios 2.8, DMIVersion 0, Size=4609]
BiosMajorRelease = 5
BiosMinorRelease = 12
BiosVendor = American Megatrends Inc.
BiosVersion = 1.50
BiosReleaseDate = 06/04/2020
SystemManufacturer = Micro-Star International Co., Ltd.
SystemProductName = MS-7C31
SystemFamily = Default string
SystemVersion = 1.0
SystemSKU = Default string
BaseBoardManufacturer = Micro-Star International Co., Ltd.
BaseBoardProduct = B365M PRO-VH (MS-7C31)