POOL_CORRUPTION_IN_FILE_AREA (de)
A driver corrupted pool memory used for holding pages destined for disk.
This was discovered by the memory manager when dereferencing the file.
Arguments:
Arg1: 0000000000000002
Arg2: ffffe7894aefcdd0
Arg3: ffdfe7894aefcdd0
Arg4: 00000004aab538c0
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for WdFilter.sys
KEY_VALUES_STRING: 1
Key : Analysis.CPU.Sec
Value: 3
Key : Analysis.DebugAnalysisProvider.CPP
Value: Create: 8007007e on DESKTOP-HH6FM2D
Key : Analysis.DebugData
Value: CreateObject
Key : Analysis.DebugModel
Value: CreateObject
Key : Analysis.Elapsed.Sec
Value: 27
Key : Analysis.Memory.CommitPeak.Mb
Value: 72
Key : Analysis.System
Value: CreateObject
BUGCHECK_CODE: de
BUGCHECK_P1: 2
BUGCHECK_P2: ffffe7894aefcdd0
BUGCHECK_P3: ffdfe7894aefcdd0
BUGCHECK_P4: 4aab538c0
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: MsMpEng.exe
STACK_TEXT:
ffff860c`3de77108 fffff804`08fecd7b : 00000000`000000de 00000000`00000002 ffffe789`4aefcdd0 ffdfe789`4aefcdd0 : nt!KeBugCheckEx
ffff860c`3de77110 fffff804`08ed75d8 : ffffc00f`e9c7b900 ffffc00f`d7093b00 ffffc00f`eaa94030 ffff860c`00000000 : nt!MmPurgeSection+0x1cee3b
ffff860c`3de77210 fffff804`08e89a81 : ffffc00f`eaa94000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!CcPurgeCacheSection+0xd8
ffff860c`3de772d0 fffff804`08e5fc00 : ffffc00f`e8d70eb0 00000000`00000000 00000003`29234565 ffff860c`3de773c0 : nt!CcZeroEndOfLastPage+0xe1
ffff860c`3de77320 fffff804`0ad482f4 : ffff860c`3de77490 ffff860c`3de774a0 00000000`00000000 ffffe789`3572a2f0 : nt!FsRtlCreateSectionForDataScan+0x130
ffff860c`3de773c0 fffff804`0b68bb2a : 00000000`00000000 ffff860c`3de77489 fffff804`0b671000 ffffe789`3352f2b0 : FLTMGR!FltCreateSectionForDataScan+0xf4
ffff860c`3de77420 00000000`00000000 : ffff860c`3de77489 fffff804`0b671000 ffffe789`3352f2b0 00000000`00000000 : WdFilter+0x2bb2a
SYMBOL_NAME: WdFilter+2bb2a
MODULE_NAME: WdFilter
IMAGE_NAME: WdFilter.sys
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: 2bb2a
FAILURE_BUCKET_ID: 0xDE_WdFilter!unknown_function
OS_VERSION: 10.0.18362.1
BUILDLAB_STR: 19h1_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {542ae2ff-06ad-eeb2-749c-f8a1e4cc21e8}
Followup: MachineOwner
---------
4: kd> lmvm WdFilter
Browse full module list
start end module name
fffff804`0b660000 fffff804`0b6ba000 WdFilter T (no symbols)
Loaded symbol image file: WdFilter.sys
Image path: \SystemRoot\system32\drivers\wd\WdFilter.sys
Image name: WdFilter.sys
Browse all global symbols functions data
Timestamp: ***** Invalid (9228F2A8)
CheckSum: 00061A14
ImageSize: 0005A000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
Information from resource tables:
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff80736586579, Address of the instruction which caused the bugcheck
Arg3: fffff58fd077e420, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.Sec
Value: 4
Key : Analysis.DebugAnalysisProvider.CPP
Value: Create: 8007007e on DESKTOP-HH6FM2D
Key : Analysis.DebugData
Value: CreateObject
Key : Analysis.DebugModel
Value: CreateObject
Key : Analysis.Elapsed.Sec
Value: 32
Key : Analysis.Memory.CommitPeak.Mb
Value: 78
Key : Analysis.System
Value: CreateObject
BUGCHECK_CODE: 3b
BUGCHECK_P1: c0000005
BUGCHECK_P2: fffff80736586579
BUGCHECK_P3: fffff58fd077e420
BUGCHECK_P4: 0
CONTEXT: fffff58fd077e420 -- (.cxr 0xfffff58fd077e420)
rax=ffdf810f56f1bfd0 rbx=0000000000000001 rcx=ffff810f4ed79080
rdx=0000000000020000 rsi=ffff810f5157e000 rdi=ffff810f56ae2e10
rip=fffff80736586579 rsp=fffff58fd077ee10 rbp=fffff58fd077eed1
r8=fffff58fd077ede8 r9=00000000ffffffff r10=fffff80719438fe0
r11=fffff58fd077ef80 r12=00000000000d8001 r13=ffffab829661f5a0
r14=ffff810f51588118 r15=ffff810f52f66960
iopl=0 nv up ei pl zr na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050246
dxgmms2!VIDMM_GLOBAL::TerminateOneAllocation+0x109:
fffff807`36586579 f70000000020 test dword ptr [rax],20000000h ds:002b:ffdf810f`56f1bfd0=????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: dwm.exe
STACK_TEXT:
fffff58f`d077ee10 fffff807`3658f60f : 00000000`00000001 ffffab82`8ee2b5a0 ffffab82`94d75390 fffff58f`d077f110 : dxgmms2!VIDMM_GLOBAL::TerminateOneAllocation+0x109
fffff58f`d077ef30 fffff807`36523fa3 : ffff810f`4ed79080 ffffab82`8ee2b628 00000000`00000000 ffffab82`962b5c20 : dxgmms2!VIDMM_GLOBAL::TerminateAllocation+0x13
fffff58f`d077ef70 fffff807`2f9034a9 : ffffab82`94d75390 00000000`00000000 ffffab82`00000002 ffffab82`8ee2b5a0 : dxgmms2!VidMmTerminateAllocation+0x13
fffff58f`d077efb0 fffff807`2f901d29 : 00000000`00020000 00000000`00000000 ffff810f`00000000 ffffab82`94d75390 : dxgkrnl!DXGDEVICE::TerminateAllocations+0x5d9
fffff58f`d077f040 fffff807`2f901744 : ffff810f`4dbb3490 fffff58f`d077f550 ffffffff`ffffffff ffffffff`ffffffff : dxgkrnl!DxgkDestroyAllocationInternal+0x479
fffff58f`d077f450 fffff807`2f901179 : 000000f9`46f1df10 00000213`3c9cdc80 fffff58f`d077fa80 000000f9`46f1f260 : dxgkrnl!DxgkDestroyAllocationHelper+0x574
fffff58f`d077f920 fffff807`195d2d15 : 00000000`00000000 ffff810f`4ed79080 00000213`3c9cdc80 00000000`00000020 : dxgkrnl!DxgkDestroyAllocation2+0x219
fffff58f`d077fa00 00007ff8`d3fb4904 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
000000f9`46f1de78 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff8`d3fb4904
SYMBOL_NAME: dxgmms2!VIDMM_GLOBAL::TerminateOneAllocation+109
MODULE_NAME: dxgmms2
IMAGE_NAME: dxgmms2.sys
IMAGE_VERSION: 10.0.18362.418
STACK_COMMAND: .cxr 0xfffff58fd077e420 ; kb
BUCKET_ID_FUNC_OFFSET: 109
FAILURE_BUCKET_ID: 0x3B_c0000005_dxgmms2!VIDMM_GLOBAL::TerminateOneAllocation
OS_VERSION: 10.0.18362.1
BUILDLAB_STR: 19h1_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {24b4c026-df6d-cd11-5167-794f99bfaf47}
Followup: MachineOwner
---------
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the bugcheck
Arg2: fffff802627ea18a, Address of the instruction which caused the bugcheck
Arg3: fffff6830a976a50, Address of the context record for the exception that caused the bugcheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.Sec
Value: 2
Key : Analysis.DebugAnalysisProvider.CPP
Value: Create: 8007007e on DESKTOP-HH6FM2D
Key : Analysis.DebugData
Value: CreateObject
Key : Analysis.DebugModel
Value: CreateObject
Key : Analysis.Elapsed.Sec
Value: 15
Key : Analysis.Memory.CommitPeak.Mb
Value: 68
Key : Analysis.System
Value: CreateObject
BUGCHECK_CODE: 3b
BUGCHECK_P1: c0000005
BUGCHECK_P2: fffff802627ea18a
BUGCHECK_P3: fffff6830a976a50
BUGCHECK_P4: 0
CONTEXT: fffff6830a976a50 -- (.cxr 0xfffff6830a976a50)
rax=0000000000000000 rbx=0000000000000000 rcx=ffffbb0f48d3d080
rdx=ffffd00f91205bc0 rsi=ffdfd00f91282dd0 rdi=ffffd00f91205bc0
rip=fffff802627ea18a rsp=fffff6830a977440 rbp=fffff6830a977560
r8=fffff6830a977448 r9=7fffbb0f496d3fc0 r10=7ffffffffffffffc
r11=0000000000000070 r12=0000000000000000 r13=ffffbb0f48d3d080
r14=0000000000000000 r15=0000000000000009
iopl=0 nv up ei ng nz na pe nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00050282
nt!ObpCreateHandle+0x41a:
fffff802`627ea18a 488b4608 mov rax,qword ptr [rsi+8] ds:002b:ffdfd00f`91282dd8=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: Corsair.Service.exe
STACK_TEXT:
fffff683`0a977440 fffff802`627dc616 : 00000000`00000080 ffffbb0f`37c02000 00000000`00000000 ffffffff`ffffffff : nt!ObpCreateHandle+0x41a
fffff683`0a977670 fffff802`627dba19 : 00000000`0510e958 fffff683`0a977a80 00000000`00000001 00000000`0510e958 : nt!ObInsertObjectEx+0x146
fffff683`0a977920 fffff802`623d2d15 : ffffbb0f`48d3d080 00000000`0510e8f8 fffff683`0a9779a8 00000000`00000000 : nt!NtCreateEvent+0xd9
fffff683`0a977990 00007ff8`b289c9c4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
00000000`0510e8d8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff8`b289c9c4
SYMBOL_NAME: nt!ObpCreateHandle+41a
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
IMAGE_VERSION: 10.0.18362.476
STACK_COMMAND: .cxr 0xfffff6830a976a50 ; kb
BUCKET_ID_FUNC_OFFSET: 41a
FAILURE_BUCKET_ID: 0x3B_c0000005_nt!ObpCreateHandle
OS_VERSION: 10.0.18362.1
BUILDLAB_STR: 19h1_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {dcd9630c-1938-35ea-221a-7b842c7aa859}
Followup: MachineOwner
---------