10: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KERNEL_SECURITY_CHECK_FAILURE (139)
A kernel component has corrupted a critical data structure. The corruption
could potentially allow a malicious user to gain control of this machine.
Arguments:
Arg1: 0000000000000039, A shadow stack violation has occurred due to mismatched return addresses
on the call stack vs the shadow stack.
Arg2: ffffc80fd7c17280, Address of the trap frame for the exception that caused the BugCheck
Arg3: ffffc80fd7c171d8, Address of the exception record for the exception that caused the BugCheck
Arg4: 0000000000000000, Reserved
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for xhunter1.sys
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 2125
Key : Analysis.DebugAnalysisManager
Value: Create
Key : Analysis.Elapsed.mSec
Value: 5458
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 0
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 421
Key : Analysis.Init.Elapsed.mSec
Value: 7689
Key : Analysis.Memory.CommitPeak.Mb
Value: 87
Key : Bugcheck.Code.DumpHeader
Value: 0x139
Key : Bugcheck.Code.Register
Value: 0x139
Key : Dump.Attributes.AsUlong
Value: 1808
Key : Dump.Attributes.DiagDataWrittenToHeader
Value: 1
Key : Dump.Attributes.ErrorCode
Value: 0
Key : Dump.Attributes.KernelGeneratedTriageDump
Value: 1
Key : Dump.Attributes.LastLine
Value: Dump completed successfully.
Key : Dump.Attributes.ProgressPercentage
Value: 0
Key : FailFast.Name
Value: CONTROL_INVALID_RETURN_ADDRESS
Key : FailFast.Type
Value: 57
FILE_IN_CAB: 050323-14421-01.dmp
TAG_NOT_DEFINED_202b: *** Unknown TAG in analysis list 202b
DUMP_FILE_ATTRIBUTES: 0x1808
Kernel Generated Triage Dump
BUGCHECK_CODE: 139
BUGCHECK_P1: 39
BUGCHECK_P2: ffffc80fd7c17280
BUGCHECK_P3: ffffc80fd7c171d8
BUGCHECK_P4: 0
TRAP_FRAME: ffffc80fd7c17280 -- (.trap 0xffffc80fd7c17280)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffff800645e0000 rbx=0000000000000000 rcx=fffff801a45ee0a0
rdx=0000000000000018 rsi=0000000000000000 rdi=0000000000000000
rip=fffff801a4707596 rsp=ffffc80fd7c17418 rbp=fffffffffffb91fb
r8=0000000140013dac r9=fffff800645e0000 r10=ffffc80fd7c175b0
r11=fffff801a46813a1 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz ac pe cy
xhunter1+0x127596:
fffff801`a4707596 ?? ???
Resetting default scope
EXCEPTION_RECORD: ffffc80fd7c171d8 -- (.exr 0xffffc80fd7c171d8)
ExceptionAddress: fffff801a4707596 (xhunter1+0x0000000000127596)
ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
ExceptionFlags: 00000001
NumberParameters: 2
Parameter[0]: 0000000000000039
Parameter[1]: ffffc782aecebfb8
Subcode: 0x39 FAST_FAIL_CONTROL_INVALID_RETURN_ADDRESS Shadow stack violation
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System
ERROR_CODE: (NTSTATUS) 0xc0000409 - Sistem, bu uygulamada y n tabanl bir arabelle in ta t n alg lad . Bu ta ma, k t niyetli bir kullan c n n bu uygulaman n denetimini ele ge irmesine olanak verebilir.
EXCEPTION_CODE_STR: c0000409
EXCEPTION_PARAMETER1: 0000000000000039
EXCEPTION_PARAMETER2: ffffc782aecebfb8
EXCEPTION_STR: 0xc0000409
STACK_TEXT:
ffffc80f`d7c16f58 fffff801`3803e9a9 : 00000000`00000139 00000000`00000039 ffffc80f`d7c17280 ffffc80f`d7c171d8 : nt!KeBugCheckEx
ffffc80f`d7c16f60 fffff801`3803ef32 : 00000000`00000000 ffffc80f`d7c17151 00000000`0000090d ffff9407`00000090 : nt!KiBugCheckDispatch+0x69
ffffc80f`d7c170a0 fffff801`3803c67d : 00000000`00000000 00000001`00000000 ffff9407`8a2d94ed ffff8003`00000000 : nt!KiFastFailDispatch+0xb2
ffffc80f`d7c17280 fffff801`a4707596 : fffff801`a46813a1 00000000`00000000 00000000`00000001 00000000`00000002 : nt!KiControlProtectionFault+0x3bd
ffffc80f`d7c17418 fffff801`a46813a1 : 00000000`00000000 00000000`00000001 00000000`00000002 fffff800`645e0000 : xhunter1+0x127596
ffffc80f`d7c17420 00000000`00000000 : 00000000`00000001 00000000`00000002 fffff800`645e0000 00000000`000000a0 : xhunter1+0xa13a1
-----------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DPC_WATCHDOG_VIOLATION (133)
The DPC watchdog detected a prolonged run time at an IRQL of DISPATCH_LEVEL
or above.
Arguments:
Arg1: 0000000000000001, The system cumulatively spent an extended period of time at
DISPATCH_LEVEL or above.
Arg2: 0000000000001e00, The watchdog period (in ticks).
Arg3: fffff8035111c340, cast to nt!DPC_WATCHDOG_GLOBAL_TRIAGE_BLOCK, which contains
additional information regarding the cumulative timeout
Arg4: 0000000000000000
Debugging Details:
------------------
*************************************************************************
*** ***
*** ***
*** Either you specified an unqualified symbol, or your debugger ***
*** doesn't have full symbol information. Unqualified symbol ***
*** resolution is turned off by default. Please either specify a ***
*** fully qualified symbol module!symbolname, or enable resolution ***
*** of unqualified symbols by typing ".symopt- 100". Note that ***
*** enabling unqualified symbol resolution with network symbol ***
*** server shares in the symbol path may cause the debugger to ***
*** appear to hang for long periods of time when an incorrect ***
*** symbol name is typed or the network symbol server is down. ***
*** ***
*** For some commands to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: TickPeriods ***
*** ***
*************************************************************************
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 3092
Key : Analysis.DebugAnalysisManager
Value: Create
Key : Analysis.Elapsed.mSec
Value: 6890
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 0
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 437
Key : Analysis.Init.Elapsed.mSec
Value: 5654
Key : Analysis.Memory.CommitPeak.Mb
Value: 99
Key : Bugcheck.Code.DumpHeader
Value: 0x133
Key : Bugcheck.Code.Register
Value: 0x133
Key : Dump.Attributes.AsUlong
Value: 1808
Key : Dump.Attributes.DiagDataWrittenToHeader
Value: 1
Key : Dump.Attributes.ErrorCode
Value: 0
Key : Dump.Attributes.KernelGeneratedTriageDump
Value: 1
Key : Dump.Attributes.LastLine
Value: Dump completed successfully.
Key : Dump.Attributes.ProgressPercentage
Value: 0
FILE_IN_CAB: 041923-14265-01.dmp
TAG_NOT_DEFINED_202b: *** Unknown TAG in analysis list 202b
DUMP_FILE_ATTRIBUTES: 0x1808
Kernel Generated Triage Dump
BUGCHECK_CODE: 133
BUGCHECK_P1: 1
BUGCHECK_P2: 1e00
BUGCHECK_P3: fffff8035111c340
BUGCHECK_P4: 0
DPC_TIMEOUT_TYPE: DPC_QUEUE_EXECUTION_TIMEOUT_EXCEEDED
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System
STACK_TEXT:
fffff803`4e4f2c68 fffff803`506bb9af : 00000000`00000133 00000000`00000001 00000000`00001e00 fffff803`5111c340 : nt!KeBugCheckEx
fffff803`4e4f2c70 fffff803`506ba7f4 : 00010ef8`72057a18 00000000`00000000 00000000`00d10097 00000000`00000000 : nt!KeAccumulateTicks+0x23f
fffff803`4e4f2cd0 fffff803`506b8c83 : fffff803`5105ffa8 00000000`00000000 fffff803`4e11f180 fffff803`4e4e2ad0 : nt!KiUpdateRunTime+0xf4
fffff803`4e4f2e90 fffff803`506b810a : fffff803`5105ffa8 fffff803`5110df20 fffff803`5110df20 00000000`00000000 : nt!KeClockInterruptNotify+0x763
fffff803`4e4f2f40 fffff803`5074b46e : 000001f2`5162352b fffff803`5110de70 fffff803`4e11f180 00000000`00000000 : nt!HalpTimerClockInterrupt+0x10a
fffff803`4e4f2f70 fffff803`5082b4fa : fffff803`4e4e2b50 fffff803`5110de70 ffffb684`e405fb98 00000000`00000000 : nt!KiCallInterruptServiceRoutine+0x19e
fffff803`4e4f2fb0 fffff803`5082bd67 : 001e0000`00000000 00000000`00000001 00000000`00200000 001f0000`00000000 : nt!KiInterruptSubDispatchNoLockNoEtw+0xfa
fffff803`4e4e2ad0 fffff803`85d6a37c : 00000000`00000000 00000000`0010a0f4 ffffb684`e9c80a10 00000000`00000000 : nt!KiInterruptDispatchNoLockNoEtw+0x37
fffff803`4e4e2c60 00000000`00000000 : 00000000`0010a0f4 ffffb684`e9c80a10 00000000`00000000 00000000`00000020 : nvlddmkm+0x9a37c
SYMBOL_NAME: nvlddmkm+9a37c
MODULE_NAME: nvlddmkm
IMAGE_NAME: nvlddmkm.sys
STACK_COMMAND: .cxr; .ecxr ; kb
BUCKET_ID_FUNC_OFFSET: 9a37c
FAILURE_BUCKET_ID: 0x133_ISR_nvlddmkm!unknown_function
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {f97493a5-ea2b-23ca-a808-8602773c2a86}
Followup: MachineOwner
---------
0: kd> !sysinfo machineid
Machine ID Information [From Smbios 3.5, DMIVersion 0, Size=4944]
BiosMajorRelease = 3
BiosMinorRelease = 5
BiosVendor = American Megatrends International, LLC.
BiosVersion = E17L5IMS.305
BiosReleaseDate = 12/28/2022
SystemManufacturer = Micro-Star International Co., Ltd.
SystemProductName = Katana 17 B12VEK
SystemFamily = GF
SystemVersion = REV:1.0
SystemSKU = 17L5.3
BaseBoardManufacturer = Micro-Star International Co., Ltd.
BaseBoardProduct = MS-17L5
BaseBoardVersion = REV:1.0
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DPC_WATCHDOG_VIOLATION (133)
The DPC watchdog detected a prolonged run time at an IRQL of DISPATCH_LEVEL
or above.
Arguments:
Arg1: 0000000000000001, The system cumulatively spent an extended period of time at
DISPATCH_LEVEL or above.
Arg2: 0000000000001e00, The watchdog period (in ticks).
Arg3: fffff8011b31c340, cast to nt!DPC_WATCHDOG_GLOBAL_TRIAGE_BLOCK, which contains
additional information regarding the cumulative timeout
Arg4: 0000000000000000
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for nvlddmkm.sys
*************************************************************************
*** ***
*** ***
*** Either you specified an unqualified symbol, or your debugger ***
*** doesn't have full symbol information. Unqualified symbol ***
*** resolution is turned off by default. Please either specify a ***
*** fully qualified symbol module!symbolname, or enable resolution ***
*** of unqualified symbols by typing ".symopt- 100". Note that ***
*** enabling unqualified symbol resolution with network symbol ***
*** server shares in the symbol path may cause the debugger to ***
*** appear to hang for long periods of time when an incorrect ***
*** symbol name is typed or the network symbol server is down. ***
*** ***
*** For some commands to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: TickPeriods ***
*** ***
*************************************************************************
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 2624
Key : Analysis.DebugAnalysisManager
Value: Create
Key : Analysis.Elapsed.mSec
Value: 2661
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 0
Key : Analysis.IO.Write.Mb
Value: 0
Key : Analysis.Init.CPU.mSec
Value: 390
Key : Analysis.Init.Elapsed.mSec
Value: 5669
Key : Analysis.Memory.CommitPeak.Mb
Value: 88
Key : Bugcheck.Code.DumpHeader
Value: 0x133
Key : Bugcheck.Code.Register
Value: 0x133
Key : Dump.Attributes.AsUlong
Value: 1808
Key : Dump.Attributes.DiagDataWrittenToHeader
Value: 1
Key : Dump.Attributes.ErrorCode
Value: 0
Key : Dump.Attributes.KernelGeneratedTriageDump
Value: 1
Key : Dump.Attributes.LastLine
Value: Dump completed successfully.
Key : Dump.Attributes.ProgressPercentage
Value: 0
FILE_IN_CAB: 042023-13109-01.dmp
TAG_NOT_DEFINED_202b: *** Unknown TAG in analysis list 202b
DUMP_FILE_ATTRIBUTES: 0x1808
Kernel Generated Triage Dump
BUGCHECK_CODE: 133
BUGCHECK_P1: 1
BUGCHECK_P2: 1e00
BUGCHECK_P3: fffff8011b31c340
BUGCHECK_P4: 0
DPC_TIMEOUT_TYPE: DPC_QUEUE_EXECUTION_TIMEOUT_EXCEEDED
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System
STACK_TEXT:
ffffc080`6f5abc68 fffff801`1a8bb9af : 00000000`00000133 00000000`00000001 00000000`00001e00 fffff801`1b31c340 : nt!KeBugCheckEx
ffffc080`6f5abc70 fffff801`1a8ba7f4 : 000024fb`79c216b3 00000000`00000000 00000000`000ec3bd 00000000`00000000 : nt!KeAccumulateTicks+0x23f
ffffc080`6f5abcd0 fffff801`1a8b8c83 : fffff801`1b25fea0 00000000`00000000 ffffc080`6f591180 fffff883`1e646b40 : nt!KiUpdateRunTime+0xf4
ffffc080`6f5abe90 fffff801`1a8b810a : fffff801`1b25fea0 ffffe787`40155410 ffffe787`40155410 00000000`00000000 : nt!KeClockInterruptNotify+0x763
ffffc080`6f5abf40 fffff801`1a94b46e : 00000023`339fdf6d ffffe787`40155360 ffffc080`6f591180 00000000`ffffffff : nt!HalpTimerClockInterrupt+0x10a
ffffc080`6f5abf70 fffff801`1aa2b4fa : fffff883`1e646bc0 ffffe787`40155360 00000000`0010a004 00000000`00000000 : nt!KiCallInterruptServiceRoutine+0x19e
ffffc080`6f5abfb0 fffff801`1aa2bd67 : ffffffff`ffffffff 00000000`000000ff 00000000`00000001 00000000`00000001 : nt!KiInterruptSubDispatchNoLockNoEtw+0xfa
fffff883`1e646b40 fffff801`4f6da3ef : 00000000`00000000 00000000`01000000 00000000`01000000 ffffe787`50e17b98 : nt!KiInterruptDispatchNoLockNoEtw+0x37
fffff883`1e646cd0 00000000`00000000 : 00000000`01000000 00000000`01000000 ffffe787`50e17b98 00000000`0010a000 : nvlddmkm+0x9a3ef
SYMBOL_NAME: nvlddmkm+9a3ef
MODULE_NAME: nvlddmkm
IMAGE_NAME: nvlddmkm.sys
STACK_COMMAND: .cxr; .ecxr ; kb
BUCKET_ID_FUNC_OFFSET: 9a3ef
FAILURE_BUCKET_ID: 0x133_ISR_nvlddmkm!unknown_function
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {f97493a5-ea2b-23ca-a808-8602773c2a86}
Followup: MachineOwner
---------