*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except.
Typically the address is just plain bad or it is pointing at freed memory.
Arguments:
Arg1: fffffffffffffbd4, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff8014f663600, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000002, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
SYSTEM_MANUFACTURER: MONSTER
SYSTEM_PRODUCT_NAME: ABRA A5 V9.2
SYSTEM_SKU: Not Applicable
SYSTEM_VERSION: Not Applicable
BIOS_VENDOR: American Megatrends Inc.
BIOS_VERSION: 1.05.22
BIOS_DATE: 03/27/2018
BASEBOARD_MANUFACTURER: MONSTER
BASEBOARD_PRODUCT: ABRA A5 V9.2
BASEBOARD_VERSION: Not Applicable
DUMP_TYPE: 2
BUGCHECK_P1: fffffffffffffbd4
BUGCHECK_P2: 0
BUGCHECK_P3: fffff8014f663600
BUGCHECK_P4: 2
READ_ADDRESS: fffff8014f5733b8: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
fffffffffffffbd4
FAULTING_IP:
nt!PsQueryStatisticsProcess+d0
fffff801`4f663600 03aed4fbffff add ebp,dword ptr [rsi-42Ch]
MM_INTERNAL_CODE: 2
CPU_COUNT: 8
CPU_MHZ: af8
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 9e
CPU_STEPPING: 9
CPU_MICROCODE: 6,9e,9,0 (F,M,S,R) SIG: 8E'00000000 (cache) 8E'00000000 (init)
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: AV
PROCESS_NAME: Monitor.exe
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-18V31A3
ANALYSIS_SESSION_TIME: 12-07-2019 16:51:28.0330
ANALYSIS_VERSION: 10.0.18362.1 x86fre
TRAP_FRAME: fffffd831e99eea0 -- (.trap 0xfffffd831e99eea0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=ffff9200f154b180
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8014f663600 rsp=fffffd831e99f030 rbp=0000000000000791
r8=0000000000000000 r9=00000000000015ea r10=0000000000001352
r11=ffff800710c09d40 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz ac po cy
nt!PsQueryStatisticsProcess+0xd0:
fffff801`4f663600 03aed4fbffff add ebp,dword ptr [rsi-42Ch] ds:ffffffff`fffffbd4=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff8014f1e35d6 to fffff8014f1c14e0
STACK_TEXT:
fffffd83`1e99ebf8 fffff801`4f1e35d6 : 00000000`00000050 ffffffff`fffffbd4 00000000`00000000 fffffd83`1e99eea0 : nt!KeBugCheckEx
fffffd83`1e99ec00 fffff801`4f072eef : fffff801`4d0537e8 00000000`00000000 00000000`00000000 ffffffff`fffffbd4 : nt!MiSystemFault+0x1d6866
fffffd83`1e99ed00 fffff801`4f1cf520 : 00000000`00000000 00000000`00000000 ffffa983`dbe7f788 00000000`00000000 : nt!MmAccessFault+0x34f
fffffd83`1e99eea0 fffff801`4f663600 : fffffd83`00000000 fffff801`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x360
fffffd83`1e99f030 fffff801`4f663444 : ffffa983`eba65080 00000000`00000000 ffff8007`10c09b00 ffffa983`dbec69b0 : nt!PsQueryStatisticsProcess+0xd0
fffffd83`1e99f0a0 fffff801`4f5f007a : 00000000`00000000 00000000`0294a250 ffffa983`dbe7f300 fffff801`4f438b80 : nt!ExpCopyProcessInfo+0x274
fffffd83`1e99f140 fffff801`4f5e1e48 : 00000000`00000000 ffff8007`00063400 fffffd83`1e99f900 00000000`00000000 : nt!ExpGetProcessInformation+0x9ca
fffffd83`1e99f7b0 fffff801`4f5e150b : 00000000`00000000 ffffa983`eed46ad0 ffffffff`fb3b4c00 00000000`00989680 : nt!ExpQuerySystemInformation+0x818
fffffd83`1e99f9c0 fffff801`4f1d2d15 : ffffa983`eba65080 00000000`00a7f7f0 fffffd83`1e99fa18 ffffffff`fb3b4c00 : nt!NtQuerySystemInformation+0x2b
fffffd83`1e99fa00 00007ff8`b1c5c784 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
00000000`06dce608 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff8`b1c5c784
THREAD_SHA1_HASH_MOD_FUNC: c93e45bb7ea27a58536ecd79217c1c11ac4886fb
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 77365c6ae052853ff78502c49ac0939826ebe147
THREAD_SHA1_HASH_MOD: bc100a5647b828107ac4e18055e00abcbe1ec406
FOLLOWUP_IP:
nt!PsQueryStatisticsProcess+d0
fffff801`4f663600 03aed4fbffff add ebp,dword ptr [rsi-42Ch]
FAULT_INSTR_CODE: fbd4ae03
SYMBOL_STACK_INDEX: 4
SYMBOL_NAME: nt!PsQueryStatisticsProcess+d0
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4efcf7a9
IMAGE_VERSION: 10.0.18362.476
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: d0
FAILURE_BUCKET_ID: AV_R_INVALID_nt!PsQueryStatisticsProcess
BUCKET_ID: AV_R_INVALID_nt!PsQueryStatisticsProcess
PRIMARY_PROBLEM_CLASS: AV_R_INVALID_nt!PsQueryStatisticsProcess
TARGET_TIME: 2019-12-07T09:51:29.000Z
OSBUILD: 18362
OSSERVICEPACK: 476
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 784
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS Personal
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 2011-12-30 02:28:41
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: 36d0
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:av_r_invalid_nt!psquerystatisticsprocess
FAILURE_ID_HASH: {3f41bc41-95dc-0efd-2b3e-aa8c85eb6516}
Followup: MachineOwner
---------
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except.
Typically the address is just plain bad or it is pointing at freed memory.
Arguments:
Arg1: fffffffffffffbd4, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff80667c63600, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000002, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
SYSTEM_MANUFACTURER: MONSTER
SYSTEM_PRODUCT_NAME: ABRA A5 V9.2
SYSTEM_SKU: Not Applicable
SYSTEM_VERSION: Not Applicable
BIOS_VENDOR: American Megatrends Inc.
BIOS_VERSION: 1.05.22
BIOS_DATE: 03/27/2018
BASEBOARD_MANUFACTURER: MONSTER
BASEBOARD_PRODUCT: ABRA A5 V9.2
BASEBOARD_VERSION: Not Applicable
DUMP_TYPE: 2
BUGCHECK_P1: fffffffffffffbd4
BUGCHECK_P2: 0
BUGCHECK_P3: fffff80667c63600
BUGCHECK_P4: 2
READ_ADDRESS: fffff80667b733b8: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
fffffffffffffbd4
FAULTING_IP:
nt!PsQueryStatisticsProcess+d0
fffff806`67c63600 03aed4fbffff add ebp,dword ptr [rsi-42Ch]
MM_INTERNAL_CODE: 2
CPU_COUNT: 8
CPU_MHZ: af8
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 9e
CPU_STEPPING: 9
CPU_MICROCODE: 6,9e,9,0 (F,M,S,R) SIG: 8E'00000000 (cache) 8E'00000000 (init)
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: AV
PROCESS_NAME: esrv_svc.exe
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-18V31A3
ANALYSIS_SESSION_TIME: 12-07-2019 16:51:30.0470
ANALYSIS_VERSION: 10.0.18362.1 x86fre
TRAP_FRAME: fffff481836b6ea0 -- (.trap 0xfffff481836b6ea0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=ffff9481214a5180
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80667c63600 rsp=fffff481836b7030 rbp=0000000000000502
r8=0000000000000000 r9=0000000000001585 r10=000000000000153d
r11=ffffa707fa809d40 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz ac po cy
nt!PsQueryStatisticsProcess+0xd0:
fffff806`67c63600 03aed4fbffff add ebp,dword ptr [rsi-42Ch] ds:ffffffff`fffffbd4=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff806677e35d6 to fffff806677c14e0
STACK_TEXT:
fffff481`836b6bf8 fffff806`677e35d6 : 00000000`00000050 ffffffff`fffffbd4 00000000`00000000 fffff481`836b6ea0 : nt!KeBugCheckEx
fffff481`836b6c00 fffff806`67672eef : 00000000`00000000 00000000`00000000 00000000`00000000 ffffffff`fffffbd4 : nt!MiSystemFault+0x1d6866
fffff481`836b6d00 fffff806`677cf520 : 00000000`00000000 00000000`00000000 ffffcd88`2ec7f788 00000000`00000000 : nt!MmAccessFault+0x34f
fffff481`836b6ea0 fffff806`67c63600 : fffff481`00000000 fffff806`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x360
fffff481`836b7030 fffff806`67c63444 : ffffcd88`4089a080 00000000`00000000 ffffa707`fa809b00 ffffcd88`2ecc61b0 : nt!PsQueryStatisticsProcess+0xd0
fffff481`836b70a0 fffff806`67bf007a : 00000000`00000000 000001c7`f5fd04f0 ffffcd88`2ec7f300 fffff806`67a38b80 : nt!ExpCopyProcessInfo+0x274
fffff481`836b7140 fffff806`67be1e48 : 0000002e`463f2618 00000000`0005e000 0000002e`463f2538 00000000`00000000 : nt!ExpGetProcessInformation+0x9ca
fffff481`836b77b0 fffff806`67be150b : 00000000`00022101 0000002e`00000000 00000000`463f2620 00000000`00010000 : nt!ExpQuerySystemInformation+0x818
fffff481`836b79c0 fffff806`677d2d15 : ffffcd88`4089a080 000001c7`00000001 00000000`00000001 fffff481`836b7a80 : nt!NtQuerySystemInformation+0x2b
fffff481`836b7a00 00007fff`bfe9c784 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
0000002e`463f24f8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007fff`bfe9c784
THREAD_SHA1_HASH_MOD_FUNC: c93e45bb7ea27a58536ecd79217c1c11ac4886fb
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 77365c6ae052853ff78502c49ac0939826ebe147
THREAD_SHA1_HASH_MOD: bc100a5647b828107ac4e18055e00abcbe1ec406
FOLLOWUP_IP:
nt!PsQueryStatisticsProcess+d0
fffff806`67c63600 03aed4fbffff add ebp,dword ptr [rsi-42Ch]
FAULT_INSTR_CODE: fbd4ae03
SYMBOL_STACK_INDEX: 4
SYMBOL_NAME: nt!PsQueryStatisticsProcess+d0
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4efcf7a9
IMAGE_VERSION: 10.0.18362.476
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: d0
FAILURE_BUCKET_ID: AV_R_INVALID_nt!PsQueryStatisticsProcess
BUCKET_ID: AV_R_INVALID_nt!PsQueryStatisticsProcess
PRIMARY_PROBLEM_CLASS: AV_R_INVALID_nt!PsQueryStatisticsProcess
TARGET_TIME: 2019-12-07T09:54:23.000Z
OSBUILD: 18362
OSSERVICEPACK: 476
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 784
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS Personal
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 2011-12-30 02:28:41
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: 2712
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:av_r_invalid_nt!psquerystatisticsprocess
FAILURE_ID_HASH: {3f41bc41-95dc-0efd-2b3e-aa8c85eb6516}
Followup: MachineOwner
---------
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except.
Typically the address is just plain bad or it is pointing at freed memory.
Arguments:
Arg1: fffffffffffffbd4, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff80138863600, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000002, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
SYSTEM_MANUFACTURER: MONSTER
SYSTEM_PRODUCT_NAME: ABRA A5 V9.2
SYSTEM_SKU: Not Applicable
SYSTEM_VERSION: Not Applicable
BIOS_VENDOR: American Megatrends Inc.
BIOS_VERSION: 1.05.22
BIOS_DATE: 03/27/2018
BASEBOARD_MANUFACTURER: MONSTER
BASEBOARD_PRODUCT: ABRA A5 V9.2
BASEBOARD_VERSION: Not Applicable
DUMP_TYPE: 2
BUGCHECK_P1: fffffffffffffbd4
BUGCHECK_P2: 0
BUGCHECK_P3: fffff80138863600
BUGCHECK_P4: 2
READ_ADDRESS: fffff801387733b8: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
fffffffffffffbd4
FAULTING_IP:
nt!PsQueryStatisticsProcess+d0
fffff801`38863600 03aed4fbffff add ebp,dword ptr [rsi-42Ch]
MM_INTERNAL_CODE: 2
CPU_COUNT: 8
CPU_MHZ: af8
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 9e
CPU_STEPPING: 9
CPU_MICROCODE: 6,9e,9,0 (F,M,S,R) SIG: 8E'00000000 (cache) 8E'00000000 (init)
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: AV
PROCESS_NAME: ASCService.exe
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-18V31A3
ANALYSIS_SESSION_TIME: 12-07-2019 16:51:34.0266
ANALYSIS_VERSION: 10.0.18362.1 x86fre
TRAP_FRAME: fffffa0c157a6ea0 -- (.trap 0xfffffa0c157a6ea0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=ffffd70049cb9180
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80138863600 rsp=fffffa0c157a7030 rbp=000000000000030f
r8=0000000000000000 r9=000000000000131a r10=000000000000128a
r11=ffffaa0f08009d40 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz ac pe cy
nt!PsQueryStatisticsProcess+0xd0:
fffff801`38863600 03aed4fbffff add ebp,dword ptr [rsi-42Ch] ds:ffffffff`fffffbd4=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff801383e35d6 to fffff801383c14e0
STACK_TEXT:
fffffa0c`157a6bf8 fffff801`383e35d6 : 00000000`00000050 ffffffff`fffffbd4 00000000`00000000 fffffa0c`157a6ea0 : nt!KeBugCheckEx
fffffa0c`157a6c00 fffff801`38272eef : fffffa0c`157a6df8 00000000`00000000 00000000`00000000 ffffffff`fffffbd4 : nt!MiSystemFault+0x1d6866
fffffa0c`157a6d00 fffff801`383cf520 : 00000000`00000000 00000000`00000000 ffffbc8b`e1cb87c8 00000000`00000000 : nt!MmAccessFault+0x34f
fffffa0c`157a6ea0 fffff801`38863600 : fffffa0c`00000000 fffff801`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x360
fffffa0c`157a7030 fffff801`38863444 : ffffbc8b`ee76b080 00000000`00000000 ffffaa0f`08009b00 ffffbc8b`e1c92e30 : nt!PsQueryStatisticsProcess+0xd0
fffffa0c`157a70a0 fffff801`387f007a : 00000000`00000000 00000000`01302230 ffffbc8b`e1cb8340 fffff801`38638b80 : nt!ExpCopyProcessInfo+0x274
fffffa0c`157a7140 fffff801`387e1e48 : 00000000`0009e5d0 00000000`00010400 00000000`0009e5c0 00000000`00000000 : nt!ExpGetProcessInformation+0x9ca
fffffa0c`157a77b0 fffff801`387e150b : 00000000`0019fb40 00000000`00208000 00000000`77203620 00000000`0009fda0 : nt!ExpQuerySystemInformation+0x818
fffffa0c`157a79c0 fffff801`383d2d15 : ffffbc8b`ee76b080 00000000`00000001 fffffa0c`157a7a80 fffffa0c`157a7a80 : nt!NtQuerySystemInformation+0x2b
fffffa0c`157a7a00 00007ffe`8161c784 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
00000000`0009e1c8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffe`8161c784
THREAD_SHA1_HASH_MOD_FUNC: c93e45bb7ea27a58536ecd79217c1c11ac4886fb
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 77365c6ae052853ff78502c49ac0939826ebe147
THREAD_SHA1_HASH_MOD: bc100a5647b828107ac4e18055e00abcbe1ec406
FOLLOWUP_IP:
nt!PsQueryStatisticsProcess+d0
fffff801`38863600 03aed4fbffff add ebp,dword ptr [rsi-42Ch]
FAULT_INSTR_CODE: fbd4ae03
SYMBOL_STACK_INDEX: 4
SYMBOL_NAME: nt!PsQueryStatisticsProcess+d0
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4efcf7a9
IMAGE_VERSION: 10.0.18362.476
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: d0
FAILURE_BUCKET_ID: AV_R_INVALID_nt!PsQueryStatisticsProcess
BUCKET_ID: AV_R_INVALID_nt!PsQueryStatisticsProcess
PRIMARY_PROBLEM_CLASS: AV_R_INVALID_nt!PsQueryStatisticsProcess
TARGET_TIME: 2019-12-07T09:56:02.000Z
OSBUILD: 18362
OSSERVICEPACK: 476
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 784
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS Personal
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 2011-12-30 02:28:41
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: 1dcb
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:av_r_invalid_nt!psquerystatisticsprocess
FAILURE_ID_HASH: {3f41bc41-95dc-0efd-2b3e-aa8c85eb6516}
Followup: MachineOwner
---------
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except.
Typically the address is just plain bad or it is pointing at freed memory.
Arguments:
Arg1: fffffffffffffbd4, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff8075f063600, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000002, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
DUMP_TYPE: 2
BUGCHECK_P1: fffffffffffffbd4
BUGCHECK_P2: 0
BUGCHECK_P3: fffff8075f063600
BUGCHECK_P4: 2
READ_ADDRESS: fffff8075ef733b8: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
fffffffffffffbd4
FAULTING_IP:
nt!PsQueryStatisticsProcess+d0
fffff807`5f063600 03aed4fbffff add ebp,dword ptr [rsi-42Ch]
MM_INTERNAL_CODE: 2
CPU_COUNT: 8
CPU_MHZ: af8
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 9e
CPU_STEPPING: 9
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: AV
PROCESS_NAME: Suo12_StartupManager.exe
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-18V31A3
ANALYSIS_SESSION_TIME: 12-07-2019 16:51:38.0124
ANALYSIS_VERSION: 10.0.18362.1 x86fre
TRAP_FRAME: ffff870b147d6ea0 -- (.trap 0xffff870b147d6ea0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=ffffb6019d2b9180
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8075f063600 rsp=ffff870b147d7030 rbp=00000000000001f2
r8=0000000000000000 r9=0000000000001295 r10=0000000000001286
r11=ffffe101bf809d40 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz ac po cy
nt!PsQueryStatisticsProcess+0xd0:
fffff807`5f063600 03aed4fbffff add ebp,dword ptr [rsi-42Ch] ds:ffffffff`fffffbd4=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff8075ebe35d6 to fffff8075ebc14e0
STACK_TEXT:
ffff870b`147d6bf8 fffff807`5ebe35d6 : 00000000`00000050 ffffffff`fffffbd4 00000000`00000000 ffff870b`147d6ea0 : nt!KeBugCheckEx
ffff870b`147d6c00 fffff807`5ea72eef : 00000000`00000000 00000000`00000000 00000000`00000000 ffffffff`fffffbd4 : nt!MiSystemFault+0x1d6866
ffff870b`147d6d00 fffff807`5ebcf520 : 00000000`00000000 00000000`00000000 ffff880b`5d87f788 00000000`00000000 : nt!MmAccessFault+0x34f
ffff870b`147d6ea0 fffff807`5f063600 : ffff870b`00000000 fffff807`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x360
ffff870b`147d7030 fffff807`5f063444 : ffff880b`6a748080 00000000`00000000 ffffe101`bf809b00 ffff880b`5d8c62b0 : nt!PsQueryStatisticsProcess+0xd0
ffff870b`147d70a0 fffff807`5eff007a : 00000000`00000000 00000000`01a80580 ffff880b`5d87f300 fffff807`5ee38b80 : nt!ExpCopyProcessInfo+0x274
ffff870b`147d7140 fffff807`5efe1e48 : 00000000`00000000 00000000`0005b570 00000000`00000000 00000000`00000000 : nt!ExpGetProcessInformation+0x9ca
ffff870b`147d77b0 fffff807`5efe150b : ffff870b`147d7a80 fffff807`5efeb1bf ffff880b`6a748080 00000000`0019fb48 : nt!ExpQuerySystemInformation+0x818
ffff870b`147d79c0 fffff807`5ebd2d15 : ffff880b`6a748080 00000000`00000000 ffffffff`fff85ee0 00000000`00000000 : nt!NtQuerySystemInformation+0x2b
ffff870b`147d7a00 00007ff9`f4f3c784 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
00000000`0009e1c8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff9`f4f3c784
THREAD_SHA1_HASH_MOD_FUNC: c93e45bb7ea27a58536ecd79217c1c11ac4886fb
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 77365c6ae052853ff78502c49ac0939826ebe147
THREAD_SHA1_HASH_MOD: bc100a5647b828107ac4e18055e00abcbe1ec406
FOLLOWUP_IP:
nt!PsQueryStatisticsProcess+d0
fffff807`5f063600 03aed4fbffff add ebp,dword ptr [rsi-42Ch]
FAULT_INSTR_CODE: fbd4ae03
SYMBOL_STACK_INDEX: 4
SYMBOL_NAME: nt!PsQueryStatisticsProcess+d0
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4efcf7a9
IMAGE_VERSION: 10.0.18362.476
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: d0
FAILURE_BUCKET_ID: AV_R_INVALID_nt!PsQueryStatisticsProcess
BUCKET_ID: AV_R_INVALID_nt!PsQueryStatisticsProcess
PRIMARY_PROBLEM_CLASS: AV_R_INVALID_nt!PsQueryStatisticsProcess
TARGET_TIME: 2019-12-07T09:57:06.000Z
OSBUILD: 18362
OSSERVICEPACK: 476
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 784
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS Personal
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 2011-12-30 02:28:41
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: 82ff
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:av_r_invalid_nt!psquerystatisticsprocess
FAILURE_ID_HASH: {3f41bc41-95dc-0efd-2b3e-aa8c85eb6516}
Followup: MachineOwner
---------
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except.
Typically the address is just plain bad or it is pointing at freed memory.
Arguments:
Arg1: fffffffffffffbd4, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff80052e63600, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000002, (reserved)
Debugging Details:
------------------
Could not read faulting driver name
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 18362.1.amd64fre.19h1_release.190318-1202
SYSTEM_MANUFACTURER: MONSTER
SYSTEM_PRODUCT_NAME: ABRA A5 V9.2
SYSTEM_SKU: Not Applicable
SYSTEM_VERSION: Not Applicable
BIOS_VENDOR: American Megatrends Inc.
BIOS_VERSION: 1.05.22
BIOS_DATE: 03/27/2018
BASEBOARD_MANUFACTURER: MONSTER
BASEBOARD_PRODUCT: ABRA A5 V9.2
BASEBOARD_VERSION: Not Applicable
DUMP_TYPE: 2
BUGCHECK_P1: fffffffffffffbd4
BUGCHECK_P2: 0
BUGCHECK_P3: fffff80052e63600
BUGCHECK_P4: 2
READ_ADDRESS: fffff80052d733b8: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
fffffffffffffbd4
FAULTING_IP:
nt!PsQueryStatisticsProcess+d0
fffff800`52e63600 03aed4fbffff add ebp,dword ptr [rsi-42Ch]
MM_INTERNAL_CODE: 2
CPU_COUNT: 8
CPU_MHZ: af8
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 9e
CPU_STEPPING: 9
CPU_MICROCODE: 6,9e,9,0 (F,M,S,R) SIG: 8E'00000000 (cache) 8E'00000000 (init)
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: AV
PROCESS_NAME: WmiPrvSE.exe
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-18V31A3
ANALYSIS_SESSION_TIME: 12-07-2019 16:51:41.0846
ANALYSIS_VERSION: 10.0.18362.1 x86fre
TRAP_FRAME: ffffa204117aeea0 -- (.trap 0xffffa204117aeea0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=ffffa9011134b180
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80052e63600 rsp=ffffa204117af030 rbp=0000000000000a21
r8=0000000000000000 r9=00000000000015ea r10=0000000000001253
r11=ffffd10eab409d40 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz ac pe cy
nt!PsQueryStatisticsProcess+0xd0:
fffff800`52e63600 03aed4fbffff add ebp,dword ptr [rsi-42Ch] ds:ffffffff`fffffbd4=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff800529e35d6 to fffff800529c14e0
STACK_TEXT:
ffffa204`117aebf8 fffff800`529e35d6 : 00000000`00000050 ffffffff`fffffbd4 00000000`00000000 ffffa204`117aeea0 : nt!KeBugCheckEx
ffffa204`117aec00 fffff800`52872eef : 00000000`00000000 00000000`00000000 00000000`00000000 ffffffff`fffffbd4 : nt!MiSystemFault+0x1d6866
ffffa204`117aed00 fffff800`529cf520 : 00000000`00000000 00000000`00000000 ffffe28f`9b298708 00000000`00000000 : nt!MmAccessFault+0x34f
ffffa204`117aeea0 fffff800`52e63600 : ffffa204`00000000 fffff800`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x360
ffffa204`117af030 fffff800`52e63444 : ffffe28f`a91f0080 00000000`00000000 ffffd10e`ab409b00 ffffe28f`9b2c3eb0 : nt!PsQueryStatisticsProcess+0xd0
ffffa204`117af0a0 fffff800`52df007a : 00000000`00000000 0000019b`72beeab0 ffffe28f`9b298280 fffff800`52c38b80 : nt!ExpCopyProcessInfo+0x274
ffffa204`117af140 fffff800`52de1e48 : fffff97c`be5f020b ffffe28f`00040000 00000000`00001000 00000000`00000000 : nt!ExpGetProcessInformation+0x9ca
ffffa204`117af7b0 fffff800`52de150b : 0000019b`72bee5b0 00000000`00004001 00000000`00000000 00000000`00000da0 : nt!ExpQuerySystemInformation+0x818
ffffa204`117af9c0 fffff800`529d2d15 : ffffe28f`00000000 00000000`00000001 00000000`00000000 ffffa204`117afa80 : nt!NtQuerySystemInformation+0x2b
ffffa204`117afa00 00007fff`0cb9c784 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
00000041`6297d308 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007fff`0cb9c784
THREAD_SHA1_HASH_MOD_FUNC: c93e45bb7ea27a58536ecd79217c1c11ac4886fb
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 77365c6ae052853ff78502c49ac0939826ebe147
THREAD_SHA1_HASH_MOD: bc100a5647b828107ac4e18055e00abcbe1ec406
FOLLOWUP_IP:
nt!PsQueryStatisticsProcess+d0
fffff800`52e63600 03aed4fbffff add ebp,dword ptr [rsi-42Ch]
FAULT_INSTR_CODE: fbd4ae03
SYMBOL_STACK_INDEX: 4
SYMBOL_NAME: nt!PsQueryStatisticsProcess+d0
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 4efcf7a9
IMAGE_VERSION: 10.0.18362.476
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: d0
FAILURE_BUCKET_ID: AV_R_INVALID_nt!PsQueryStatisticsProcess
BUCKET_ID: AV_R_INVALID_nt!PsQueryStatisticsProcess
PRIMARY_PROBLEM_CLASS: AV_R_INVALID_nt!PsQueryStatisticsProcess
TARGET_TIME: 2019-12-07T10:07:18.000Z
OSBUILD: 18362
OSSERVICEPACK: 476
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 784
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS Personal
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 2011-12-30 02:28:41
BUILDDATESTAMP_STR: 190318-1202
BUILDLAB_STR: 19h1_release
BUILDOSVER_STR: 10.0.18362.1.amd64fre.19h1_release.190318-1202
ANALYSIS_SESSION_ELAPSED_TIME: 173f
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:av_r_invalid_nt!psquerystatisticsprocess
FAILURE_ID_HASH: {3f41bc41-95dc-0efd-2b3e-aa8c85eb6516}
Followup: MachineOwner
---------