My first BSOD blog post 0x21A Analysis complete

This blog is focused on my first BSOD blog post.
Descriptions about BSOD error codes are from my own opinion based on 1.5+ year BSOD debugging experience.
 
 
 
Some information about the situation

The problem description:

While playing my Computer randomly crashes. It happended several times now and i don’t know where the issue is. The Computer once had a several BSOD in succession, but works again. It also happend while watching a movie.
I also get a Blackscreen randomly without doing anything. The screen becomes black,sometimes red, and works again after a reset. Therefore i guess it is GPU related but i am not very sure, because it also happend just while watching a movie.
 

Link: BSOD playing Games like CIV 6

 
 
 
The BSOD present with usual causes
– 0x21A,

  • User-mode device driver,
  • system service or 3rd party application,
  • Mismatched system files

– 0x34,

  • Insufficient physical memory,
  • Indexing,
  • Device driver

– 0x109,

  • Device driver,
  • Breakpoint set with no debugger attached,
  • Hardware (Memory in particular)

My own experience with these bugchecks:
– The 0x21A is IMO usually caused by HDD and RAM issues rather than mismatched system files. Mismatched system files are usually the result of a different cause.

– The 0x34 is IMO similar to the 0x24 crash, which is a NTFS related crash.

– The 0x109 is in this case caused by a ‘Modification of a function or .pdata’, usually caused by buggy drivers or bad RAM.

These crashes in combination have a few causes.
– HDD
– RAM
With bad luck it may also be the motherboard that you can include in the list due to problems in communication with the RAM or HDD to say it very basically.
 
 
 
So, with this all in mind I wanted to find out what the 0x21A is complaining about so I ran the !error command on the second parameter.

WINLOGON_FATAL_ERROR (c000021a)
The Winlogon process terminated unexpectedly.
Arguments:
Arg1: ffffb082ec613ab0, String that identifies the problem.
Arg2: ffffffffc0000428, Error Code.
Arg3: 0000000000000000
Arg4: 000001898e8a0000

6: kd> !error ffffffffc0000428
Error code: (NTSTATUS) 0xc0000428 (3221226536) - Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Windows marks some files as critical files, because Windows cannot run when any problem happens with these files. If any problem occurs the system crashes with a 0xC000021A.
In the case of the 0x21A it is about the termination of a critical file, this can happen for various of reasons like malware or in this case an invalid digital signature.
The 0x21A is compaining about the smss.exe file, this is the Windows application that handles the sessions in Windows.
A little in-depth information about the first tasks that smss.exe does.
Smss.exe initializes the Windows subsystem, as a side note, this is the reason why smss.exe is a Windows application that doesn’t use the API’s of Windows, instead it uses the core executive API’s a.k.a. the Windows native API.
After the Windows subsystem is initialized, the smss.exe maps the registry by calling the configuration manager subsystem. The configuration manager is programmed to know where the corresponding hive is stored on the disk and records the paths to the hives it loads in HKLM\SYSTEM\CurrentControlSet\Control\hivelist.
 
 
 
Back to the analysis.
When looking at the time of the 0x21A crash, we see that the system lasted 9 seconds

System Uptime: 0 days 0:00:09.093

This indicates that the smss.exe was working on its second task indicating that there may be a problem with the RAM.

I let the user ran SeaTools, HDTunes, chkdsk, MemTest86+ and sfc/scannow.
SFC I doubted to give results in FS corruption, but better safe than sorry so I suggested it.
Unfortunately all attachments of the user were deleted, except for the chkdsk result, so I can only say that a few security descriptors were removed.

MemTest86+ however, did show errors on every slot combination possible meaning that the motherboard needed to be RMA’ed.

This concludes the first blog post.

Reference

BSOD Index
Windows Internals 6th Edition Part 1 & 2.
 
 
 
 
 
 

Short analysis:

**************************Tue Dec 27 21:20:46.433 2016 (UTC + 1:00)**************************
Loading Dump File [E:\Installaties\SysnativeBSODApps\122816-4406-01.dmp]
Windows 10 Kernel Version 14393 MP (8 procs) Free x64
Built by: 14393.447.amd64fre.rs1_release_inmarket.161102-0100
System Uptime:0 days 0:00:09.093
Probably caused by :ntkrnlmp.exe ( nt! ?? ::OKHAJAOM::`string'+1a64 )
BugCheck C000021A, {ffffb082ec613ab0, ffffffffc0000428, 0, 1898e8a0000}
BugCheck Info: WINLOGON_FATAL_ERROR (c000021a)
Arguments:
Arg1: ffffb082ec613ab0, String that identifies the problem.
Arg2: ffffffffc0000428, Error Code.
Arg3: 0000000000000000
Arg4: 000001898e8a0000
Arg2: ffffffffc0000428, Error Code.
PROCESS_NAME: smss.exe
BUGCHECK_STR: 0xc000021a_SmpDestroyControlBlock_smss.exe_Terminated_c0000428
FAILURE_BUCKET_ID: 0xc000021a_SmpDestroyControlBlock_smss.exe_Terminated_c0000428_nt!_??_::OKHAJAOM::_string_
CPUID: "Intel(R) Core(TM) i7-4790 CPU @ 3.60GHz"
MaxSpeed: 3600
CurrentSpeed: 3600
BIOS Version V17.0
BIOS Release Date 04/16/2014
Manufacturer ECT
Baseboard Manufacturer MSI
Product Name
Baseboard Product Z97-G43 (MS-7816)
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
**************************Tue Dec 27 16:34:35.017 2016 (UTC + 1:00)**************************
Loading Dump File [E:\Installaties\SysnativeBSODApps\122716-4437-01.dmp]
Windows 10 Kernel Version 14393 MP (8 procs) Free x64
Built by: 14393.447.amd64fre.rs1_release_inmarket.161102-0100
System Uptime:0 days 0:43:10.677
*** WARNING: Unable to verify timestamp for win32k.sys
*** ERROR: Module load completed but symbols could not be loaded for win32k.sys
Probably caused by :memory_corruption
BugCheck 109, {a39ff25a86e62573, b3b6fee0d96732e1, fffff80274356af8, 1}
BugCheck Info: CRITICAL_STRUCTURE_CORRUPTION (109)
Arguments:
Arg1: a39ff25a86e62573, Reserved
Arg2: b3b6fee0d96732e1, Reserved
Arg3: fffff80274356af8, Failure type dependent information
Arg4: 0000000000000001, Type of corrupted region, can be
0 : A generic data region
1 : Modification of a function or .pdata
2 : A processor IDT
3 : A processor GDT
4 : Type 1 process list corruption
5 : Type 2 process list corruption
6 : Debug routine modification
7 : Critical MSR modification
8 : Object type
9 : A processor IVT
a : Modification of a system service function
b : A generic session data region
c : Modification of a session function or .pdata
d : Modification of an import table
e : Modification of a session import table
f : Ps Win32 callout modification
10 : Debug switch routine modification
11 : IRP allocator modification
12 : Driver call dispatcher modification
13 : IRP completion dispatcher modification
14 : IRP deallocator modification
15 : A processor control register
16 : Critical floating point control register modification
17 : Local APIC modification
18 : Kernel notification callout modification
19 : Loaded module list modification
1a : Type 3 process list corruption
1b : Type 4 process list corruption
1c : Driver object corruption
1d : Executive callback object modification
1e : Modification of module padding
1f : Modification of a protected process
20 : A generic data region
21 : A page hash mismatch
22 : A session page hash mismatch
23 : Load config directory modification
24 : Inverted function table modification
25 : Session configuration modification
26 : An extended processor control register
27 : Type 1 pool corruption
28 : Type 2 pool corruption
29 : Type 3 pool corruption
101 : General pool corruption
102 : Modification of win32k.sys
BUGCHECK_STR: 0x109
DEFAULT_BUCKET_ID: CODE_CORRUPTION
PROCESS_NAME: System
FAILURE_BUCKET_ID: MEMORY_CORRUPTION_ONE_BIT
CPUID: "Intel(R) Core(TM) i7-4790 CPU @ 3.60GHz"
MaxSpeed: 3600
CurrentSpeed: 3600
BIOS Version V17.0
BIOS Release Date 04/16/2014
Manufacturer ECT
Baseboard Manufacturer MSI
Product Name
Baseboard Product Z97-G43 (MS-7816)
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
**************************Sun Dec 18 14:00:12.779 2016 (UTC + 1:00)**************************
Loading Dump File [E:\Installaties\SysnativeBSODApps\121816-19093-01.dmp]
Windows 10 Kernel Version 14393 MP (8 procs) Free x64
Built by: 14393.447.amd64fre.rs1_release_inmarket.161102-0100
System Uptime:0 days 2:01:51.440
*** WARNING: Unable to verify timestamp for win32k.sys
*** ERROR: Module load completed but symbols could not be loaded for win32k.sys
Probably caused by :memory_corruption
BugCheck 34, {5117a, ffff9200577f90a8, ffff9200577f88d0, fffff8024825ce30}
BugCheck Info: CACHE_MANAGER (34)
Arguments:
Arg1: 000000000005117a
Arg2: ffff9200577f90a8
Arg3: ffff9200577f88d0
Arg4: fffff8024825ce30
PROCESS_NAME: System
BUGCHECK_STR: 0x34
DEFAULT_BUCKET_ID: CODE_CORRUPTION
FAILURE_BUCKET_ID: MEMORY_CORRUPTION_ONE_BYTE
CPUID: "Intel(R) Core(TM) i7-4790 CPU @ 3.60GHz"
MaxSpeed: 3600
CurrentSpeed: 3600
BIOS Version V17.0
BIOS Release Date 04/16/2014
Manufacturer ECT
Baseboard Manufacturer MSI
Product Name
Baseboard Product Z97-G43 (MS-7816)
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``

Built by: 14393.447.amd64fre.rs1_release_inmarket.161102-0100
Debug session time: Tue Dec 27 21:20:46.433 2016 (UTC + 1:00)
System Uptime: 0 days 0:00:09.093
BugCheck C000021A, {ffffb082ec613ab0, ffffffffc0000428, 0, 1898e8a0000}
Probably caused by : ntkrnlmp.exe ( nt! ?? ::OKHAJAOM::`string'+1a64 )
BUGCHECK_STR: 0xc000021a_SmpDestroyControlBlock_smss.exe_Terminated_c0000428
PROCESS_NAME: smss.exe
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
Built by: 14393.447.amd64fre.rs1_release_inmarket.161102-0100
Debug session time: Tue Dec 27 16:34:35.017 2016 (UTC + 1:00)
System Uptime: 0 days 0:43:10.677
BugCheck 109, {a39ff25a86e62573, b3b6fee0d96732e1, fffff80274356af8, 1}
*** WARNING: Unable to verify timestamp for win32k.sys
*** ERROR: Module load completed but symbols could not be loaded for win32k.sys
Probably caused by : memory_corruption
BUGCHECK_STR: 0x109
PROCESS_NAME: System
¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨¨``
Built by: 14393.447.amd64fre.rs1_release_inmarket.161102-0100
Debug session time: Sun Dec 18 14:00:12.779 2016 (UTC + 1:00)
System Uptime: 0 days 2:01:51.440
BugCheck 34, {5117a, ffff9200577f90a8, ffff9200577f88d0, fffff8024825ce30}
*** WARNING: Unable to verify timestamp for win32k.sys
*** ERROR: Module load completed but symbols could not be loaded for win32k.sys
Probably caused by : memory_corruption
BUGCHECK_STR: 0x34
PROCESS_NAME: System

 
 
 
 
 
 

Complete analysis:

*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.

BugCheck C000021A, {ffffb082ec613ab0, ffffffffc0000428, 0, 1898e8a0000}

ETW minidump data unavailable
Probably caused by : Processing initial command '!analyze -v; lmtsmn; !sysinfo smbios; !sysinfo machineid; !sysinfo cpuspeed; !sysinfo cpuinfo; !thread; .bugcheck; .time;'
ntkrnlmp.exe ( nt! ?? ::OKHAJAOM::`string'+1a64 )

Followup: MachineOwner
---------

6: kd> !analyze -v; lmtsmn; !sysinfo smbios; !sysinfo machineid; !sysinfo cpuspeed; !sysinfo cpuinfo; !thread; .bugcheck; .time;
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

WINLOGON_FATAL_ERROR (c000021a)
The Winlogon process terminated unexpectedly.
Arguments:
Arg1: ffffb082ec613ab0, String that identifies the problem.
Arg2: ffffffffc0000428, Error Code.
Arg3: 0000000000000000
Arg4: 000001898e8a0000

Debugging Details:
------------------

ETW minidump data unavailable

DUMP_CLASS: 1

DUMP_QUALIFIER: 400

BUILD_VERSION_STRING: 10.0.14393.447 (rs1_release_inmarket.161102-0100)

SYSTEM_MANUFACTURER: ECT

SYSTEM_SKU: To be filled by O.E.M.

BIOS_VENDOR: American Megatrends Inc.

BIOS_VERSION: V17.0

BIOS_DATE: 04/16/2014

BASEBOARD_MANUFACTURER: MSI

BASEBOARD_PRODUCT: Z97-G43 (MS-7816)

BASEBOARD_VERSION: 3.0

ERROR_CODE: (NTSTATUS) 0xc000021a - {Fatal System Error} The %hs system process terminated unexpectedly with a status of 0x%08x (0x%08x 0x%08x). The system has been shut down.

EXCEPTION_CODE: (NTSTATUS) 0xc000021a - {Fatal System Error} The %hs system process terminated unexpectedly with a status of 0x%08x (0x%08x 0x%08x). The system has been shut down.

EXCEPTION_CODE_STR: c000021a

EXCEPTION_PARAMETER1: ffffb082ec613ab0

EXCEPTION_PARAMETER2: ffffffffc0000428

EXCEPTION_PARAMETER3: 0000000000000000

EXCEPTION_PARAMETER4: 1898e8a0000

DUMP_TYPE: 2

BUGCHECK_P1: ffffb082ec613ab0

BUGCHECK_P2: ffffffffc0000428

BUGCHECK_P3: 0

BUGCHECK_P4: 1898e8a0000

PROCESS_NAME: smss.exe

ADDITIONAL_DEBUG_TEXT: initial session process or

BUGCHECK_STR: 0xc000021a_SmpDestroyControlBlock_smss.exe_Terminated_c0000428

IMAGE_NAME: ntkrnlmp.exe

MODULE_NAME: nt

CPU_COUNT: 8

CPU_MHZ: e10

CPU_VENDOR: GenuineIntel

CPU_FAMILY: 6

CPU_MODEL: 3c

CPU_STEPPING: 3

CPU_MICROCODE: 6,3c,3,0 (F,M,S,R) SIG: 1E'00000000 (cache) 1E'00000000 (init)

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT

CURRENT_IRQL: 0

ANALYSIS_SESSION_HOST: MARTIJN

ANALYSIS_SESSION_TIME: 12-30-2016 12:04:06.0661

ANALYSIS_VERSION: 10.0.14321.1024 amd64fre

LAST_CONTROL_TRANSFER: from fffff8001f26c37c to fffff8001efdb510

STACK_TEXT:
ffffe481`c8b0e6b8 fffff800`1f26c37c : 00000000`0000004c 00000000`c000021a ffffe481`c8b153f8 ffffd481`c9f6a820 : nt!KeBugCheckEx
ffffe481`c8b0e6c0 fffff800`1f265ef4 : ffffffff`800003e0 00000000`00000002 ffffe481`c8b0e800 00000000`00000002 : nt!PopGracefulShutdown+0x268
ffffe481`c8b0e700 fffff800`1efe6193 : ffffe481`00000004 00000000`00000004 00000000`c0000004 ffffe481`c8b0e900 : nt! ?? ::OKHAJAOM::`string'+0x1a64
ffffe481`c8b0e880 fffff800`1efde6d0 : fffff800`1f442a84 00000000`00000000 ffffe481`c8b0ea98 00000000`00000014 : nt!KiSystemServiceCopyEnd+0x13
ffffe481`c8b0ea18 fffff800`1f442a84 : 00000000`00000000 ffffe481`c8b0ea98 00000000`00000014 fffff800`1f24e100 : nt!KiServiceLinkage
ffffe481`c8b0ea20 fffff800`1f3a8995 : 00000000`00000000 00000000`00000000 00000000`00000000 fffff800`1f24e280 : nt! ?? ::NNGAKEGL::`string'+0x37864
ffffe481`c8b0eae0 fffff800`1ef89125 : 00000000`00000001 fffff800`1ef890b8 00000000`00000002 00000000`00000000 : nt!PopPolicyWorkerAction+0x69
ffffe481`c8b0eb50 fffff800`1ef27fd9 : ffffd481`c8d77040 fffff800`1f192b00 fffff800`00000000 ffffd481`0017f000 : nt!PopPolicyWorkerThread+0x6d
ffffe481`c8b0eb80 fffff800`1ee93729 : ffffe481`c8780180 00000000`00000080 ffffd481`c84b3040 ffffd481`c8d77040 : nt!ExpWorkerThread+0xe9
ffffe481`c8b0ec10 fffff800`1efe09d6 : ffffe481`c8780180 ffffd481`c8d77040 fffff800`1ee936e8 219e0589`48c08b49 : nt!PspSystemThreadStartup+0x41
ffffe481`c8b0ec60 00000000`00000000 : ffffe481`c8b0f000 ffffe481`c8b09000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x16

STACK_COMMAND: kb

THREAD_SHA1_HASH_MOD_FUNC: ca83477c6c105b050cb3ec79e1112ae3fe845ead

THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 3dcfac3b33000d5bd2eb5f6949434e66c835c39f

THREAD_SHA1_HASH_MOD: b28610981796779b4ac02f58898fde25728a775c

FOLLOWUP_IP:
nt! ?? ::OKHAJAOM::`string'+1a64
fffff800`1f265ef4 cc int 3

FAULT_INSTR_CODE: e9df8bcc

SYMBOL_STACK_INDEX: 2

SYMBOL_NAME: nt! ?? ::OKHAJAOM::`string'+1a64

FOLLOWUP_NAME: MachineOwner

DEBUG_FLR_IMAGE_TIMESTAMP: 5819bd1f

IMAGE_VERSION: 10.0.14393.447

BUCKET_ID_FUNC_OFFSET: 1a64

FAILURE_BUCKET_ID: 0xc000021a_SmpDestroyControlBlock_smss.exe_Terminated_c0000428_nt!_??_::OKHAJAOM::_string_

BUCKET_ID: 0xc000021a_SmpDestroyControlBlock_smss.exe_Terminated_c0000428_nt!_??_::OKHAJAOM::_string_

PRIMARY_PROBLEM_CLASS: 0xc000021a_SmpDestroyControlBlock_smss.exe_Terminated_c0000428_nt!_??_::OKHAJAOM::_string_

TARGET_TIME: 2016-12-27T20:20:46.000Z

OSBUILD: 14393

OSSERVICEPACK: 447

SERVICEPACK_NUMBER: 0

OS_REVISION: 0

SUITE_MASK: 784

PRODUCT_TYPE: 1

OSPLATFORM_TYPE: x64

OSNAME: Windows 10

OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS Personal

OS_LOCALE:

USER_LCID: 0

OSBUILD_TIMESTAMP: 2016-11-02 11:17:03

BUILDDATESTAMP_STR: 161102-0100

BUILDLAB_STR: rs1_release_inmarket

BUILDOSVER_STR: 10.0.14393.447

ANALYSIS_SESSION_ELAPSED_TIME: 1400

ANALYSIS_SOURCE: KM

FAILURE_ID_HASH_STRING: km:0xc000021a_smpdestroycontrolblock_smss.exe_terminated_c0000428_nt!_??_::okhajaom::_string_

FAILURE_ID_HASH: {341f3cd7-cdf2-aefe-6083-b8fc309194a4}

Followup: MachineOwner
---------

start end module name
fffff800`d4260000 fffff800`d4313000 ACPI ACPI.sys Sat Jul 16 04:10:47 2016 (578997A7)
fffff800`d4220000 fffff800`d4243000 acpiex acpiex.sys Sat Jul 16 04:28:23 2016 (57899BC7)
fffff800`d9590000 fffff800`d959b000 acpipagr acpipagr.sys Sat Jul 16 04:29:00 2016 (57899BEC)
fffff800`d66c0000 fffff800`d6755000 afd afd.sys Sat Oct 15 05:53:45 2016 (5801A849)
fffff800`d68f0000 fffff800`d692f000 ahcache ahcache.sys Sat Oct 15 05:31:36 2016 (5801A318)
fffff800`d53d0000 fffff800`d53e3000 amdkmpfd amdkmpfd.sys Tue Oct 28 00:26:38 2014 (544ED4AE)
fffff800`d9680000 fffff800`d969e000 AtihdWT6 AtihdWT6.sys Wed Sep 21 01:17:24 2016 (57E1C384)
fffff800`d9960000 fffff800`db4fb000 atikmdag atikmdag.sys Sun Dec 4 17:30:19 2016 (5844449B)
fffff800`d6980000 fffff800`d6a03000 atikmpag atikmpag.sys Sun Dec 4 17:07:30 2016 (58443F42)
fffff800`d5c70000 fffff800`d5c84000 BasicDisplay BasicDisplay.sys Sat Jul 16 04:28:02 2016 (57899BB2)
fffff800`d75e0000 fffff800`d75f2000 BasicRender BasicRender.sys Sat Jul 16 04:28:14 2016 (57899BBE)
fffff800`d5c60000 fffff800`d5c6a000 Beep Beep.SYS Sat Jul 16 04:22:02 2016 (57899A4A)
fffff800`d3ec0000 fffff800`d3ecc000 BOOTVID BOOTVID.dll Sat Jul 16 04:10:37 2016 (5789979D)
fffff800`d5be0000 fffff800`d5c11000 cdrom cdrom.sys Sat Jul 16 04:10:42 2016 (578997A2)
fffff800`d4470000 fffff800`d4489000 CEA CEA.sys Sat Jul 16 04:28:38 2016 (57899BD6)
fffff800`d4dd0000 fffff800`d4e70000 CI CI.dll Thu Sep 15 18:40:08 2016 (57DACEE8)
fffff800`d5530000 fffff800`d5592000 CLASSPNP CLASSPNP.SYS Wed Sep 7 06:33:32 2016 (57CF989C)
fffff800`d3e00000 fffff800`d3e63000 CLFS CLFS.SYS Wed Nov 2 11:12:36 2016 (5819BC14)
fffff800`d3fd0000 fffff800`d4080000 clipsp clipsp.sys Wed Sep 7 06:57:27 2016 (57CF9E37)
fffff800`d4080000 fffff800`d408d000 cmimcext cmimcext.sys Thu Sep 15 18:15:09 2016 (57DAC90D)
fffff800`d4e70000 fffff800`d4f0c000 cng cng.sys Sat Aug 6 05:38:01 2016 (57A55B99)
fffff800`d6930000 fffff800`d6941000 CompositeBus CompositeBus.sys Sat Jul 16 04:20:11 2016 (578999DB)
fffff800`d55c0000 fffff800`d55d9000 crashdmp crashdmp.sys Sat Oct 15 05:46:27 2016 (5801A693)
fffff800`d9870000 fffff800`d9887000 dc1_controller dc1-controller.sys Sat Jul 16 04:28:18 2016 (57899BC2)
fffff800`d9890000 fffff800`d98a3000 DevAuthE DevAuthE.sys Sat Jul 16 04:29:16 2016 (57899BFC)
fffff800`d68a0000 fffff800`d68ca000 dfsc dfsc.sys Wed Oct 5 11:34:11 2016 (57F4C913)
fffff800`d5510000 fffff800`d552e000 disk disk.sys Sat Jul 16 04:10:52 2016 (578997AC)
fffff800`db5a0000 fffff800`db5c1000 drmk drmk.sys Sat Jul 16 04:27:13 2016 (57899B81)
fffff800`d9750000 fffff800`d975f000 dump_diskdump dump_diskdump.sys Sat Jul 16 04:21:57 2016 (57899A45)
fffff800`d9780000 fffff800`d979d000 dump_dumpfve dump_dumpfve.sys Sat Jul 16 04:27:46 2016 (57899BA2)
fffff800`d55e0000 fffff800`d58a3000 dump_iaStorA dump_iaStorA.sys Fri Apr 4 01:00:05 2014 (533DE7F5)
fffff800`d73c0000 fffff800`d75de000 dxgkrnl dxgkrnl.sys Sat Oct 15 05:36:30 2016 (5801A43E)
fffff800`d4950000 fffff800`d496c000 EhStorClass EhStorClass.sys Sat Jul 16 04:18:35 2016 (5789997B)
fffff800`d5c20000 fffff800`d5c3d000 filecrypt filecrypt.sys Sat Jul 16 04:22:39 2016 (57899A6F)
fffff800`d4970000 fffff800`d4989000 fileinfo fileinfo.sys Sat Jul 16 04:26:05 2016 (57899B3D)
fffff800`d3ed0000 fffff800`d3f32000 FLTMGR FLTMGR.SYS Sat Jul 16 04:10:45 2016 (578997A5)
fffff800`d4c60000 fffff800`d4c6d000 Fs_Rec Fs_Rec.sys Sat Jul 16 04:10:37 2016 (5789979D)
fffff800`d5320000 fffff800`d53c3000 fvevol fvevol.sys Thu Sep 15 18:36:20 2016 (57DACE04)
fffff800`d5280000 fffff800`d52e9000 fwpkclnt fwpkclnt.sys Sat Oct 15 05:53:56 2016 (5801A854)
fffff800`d6890000 fffff800`d689a000 gpuenergydrv gpuenergydrv.sys Sat Jul 16 04:28:09 2016 (57899BB9)
fffff800`1ee1c000 fffff800`1ee91000 hal hal.dll Thu Sep 15 18:15:22 2016 (57DAC91A)
fffff800`db510000 fffff800`db52b000 HDAudBus HDAudBus.sys Sat Jul 16 04:27:11 2016 (57899B7F)
fffff800`d97f0000 fffff800`d981f000 HIDCLASS HIDCLASS.SYS Sat Oct 15 05:55:48 2016 (5801A8C4)
fffff800`d9820000 fffff800`d9832000 HIDPARSE HIDPARSE.SYS Sat Aug 6 05:46:37 2016 (57A55D9D)
fffff800`d97d0000 fffff800`d97e1000 hidusb hidusb.sys Sat Aug 6 05:47:49 2016 (57A55DE5)
fffff800`d45f0000 fffff800`d48b3000 iaStorA iaStorA.sys Fri Apr 4 01:00:05 2014 (533DE7F5)
fffff800`d4340000 fffff800`d4351000 intelpep intelpep.sys Sat Jul 16 04:18:27 2016 (57899973)
fffff800`d9560000 fffff800`d958b000 intelppm intelppm.sys Sat Jul 16 04:10:43 2016 (578997A3)
fffff800`d54f0000 fffff800`d5500000 iorate iorate.sys Wed Nov 2 11:12:31 2016 (5819BC0F)
fffff800`d95a0000 fffff800`d95b0000 ISCTD64 ISCTD64.sys Tue Aug 23 19:32:39 2011 (4E53E437)
fffff800`d9850000 fffff800`d9863000 kbdclass kbdclass.sys Sat Jul 16 04:26:27 2016 (57899B53)
fffff800`d9840000 fffff800`d9850000 kbdhid kbdhid.sys Thu Sep 15 18:43:23 2016 (57DACFAB)
fffff800`1db8a000 fffff800`1db95000 kd kd.dll Sat Jul 16 04:29:16 2016 (57899BFC)
fffff800`d6950000 fffff800`d695e000 kdnic kdnic.sys Sat Jul 16 04:28:28 2016 (57899BCC)
fffff800`d9200000 fffff800`d9268000 ks ks.sys Sat Jul 16 04:24:18 2016 (57899AD2)
fffff800`d3fa0000 fffff800`d3fc8000 ksecdd ksecdd.sys Wed Sep 7 07:00:34 2016 (57CF9EF2)
fffff800`d5ed0000 fffff800`d5f00000 ksecpkg ksecpkg.sys Sat Aug 6 05:44:30 2016 (57A55D1E)
fffff800`d96a0000 fffff800`d96ae000 ksthunk ksthunk.sys Sat Jul 16 04:28:56 2016 (57899BE8)
fffff800`d95d0000 fffff800`d95d3d80 LGBusEnum LGBusEnum.sys Tue Nov 24 02:36:48 2009 (4B0B38B0)
fffff800`d98b0000 fffff800`d98c5000 LGSHidFilt LGSHidFilt.Sys Thu May 30 17:16:33 2013 (51A76D51)
fffff800`d4100000 fffff800`d418e000 mcupdate_GenuineIntel mcupdate_GenuineIntel.dll Sat Jul 16 04:28:05 2016 (57899BB5)
fffff800`d98e0000 fffff800`d98f2000 mouclass mouclass.sys Sat Jul 16 04:26:40 2016 (57899B60)
fffff800`d98d0000 fffff800`d98df000 mouhid mouhid.sys Sat Jul 16 04:27:35 2016 (57899B97)
fffff800`d45d0000 fffff800`d45ee000 mountmgr mountmgr.sys Sat Jul 16 04:10:42 2016 (578997A2)
fffff800`d6620000 fffff800`d6630000 Msfs Msfs.SYS Sat Jul 16 04:10:38 2016 (5789979E)
fffff800`d43b0000 fffff800`d43bb000 msisadrv msisadrv.sys Sat Jul 16 04:28:51 2016 (57899BE3)
fffff800`d3f40000 fffff800`d3f9d000 msrpc msrpc.sys Sat Jul 16 04:23:06 2016 (57899A8A)
fffff800`d6880000 fffff800`d6890000 mssmbios mssmbios.sys Sat Jul 16 04:26:00 2016 (57899B38)
fffff800`d54c0000 fffff800`d54e5000 mup mup.sys Sat Jul 16 04:11:22 2016 (578997CA)
fffff800`d4c70000 fffff800`d4d98000 ndis ndis.sys Wed Oct 5 11:19:09 2016 (57F4C58D)
fffff800`d95b0000 fffff800`d95bd000 NdisVirtualBus NdisVirtualBus.sys Sat Jul 16 04:26:32 2016 (57899B58)
fffff800`d67b0000 fffff800`d67c2000 netbios netbios.sys Sat Jul 16 04:27:18 2016 (57899B86)
fffff800`d6670000 fffff800`d66bb000 netbt netbt.sys Sat Jul 16 04:25:07 2016 (57899B03)
fffff800`d5e50000 fffff800`d5ec9000 NETIO NETIO.SYS Sat Jul 16 04:26:08 2016 (57899B40)
fffff800`d6600000 fffff800`d6619000 Npfs Npfs.SYS Sat Jul 16 04:10:38 2016 (5789979E)
fffff800`d6870000 fffff800`d687d000 npsvctrig npsvctrig.sys Sat Jul 16 04:28:33 2016 (57899BD1)
fffff800`d6850000 fffff800`d6861000 nsiproxy nsiproxy.sys Sat Jul 16 04:26:45 2016 (57899B65)
fffff800`1ee91000 fffff800`1f6b1000 nt ntkrnlmp.exe Wed Nov 2 11:17:03 2016 (5819BD1F)
fffff800`d4a20000 fffff800`d4c52000 NTFS NTFS.sys Wed Nov 2 11:15:32 2016 (5819BCC4)
fffff800`d4090000 fffff800`d409c000 ntosext ntosext.sys Sat Jul 16 04:10:37 2016 (5789979D)
fffff800`d5c50000 fffff800`d5c5a000 Null Null.SYS Sat Jul 16 04:10:37 2016 (5789979D)
fffff800`d6780000 fffff800`d67ab000 pacer pacer.sys Sat Jul 16 04:25:21 2016 (57899B11)
fffff800`d4490000 fffff800`d44b4000 partmgr partmgr.sys Thu Sep 15 18:15:19 2016 (57DAC917)
fffff800`d43c0000 fffff800`d4417000 pci pci.sys Sat Oct 15 05:49:22 2016 (5801A742)
fffff800`d4390000 fffff800`d43a2000 pcw pcw.sys Sat Jul 16 04:10:37 2016 (5789979D)
fffff800`d4440000 fffff800`d4461000 pdc pdc.sys Sat Aug 20 06:51:30 2016 (57B7E1D2)
fffff800`db530000 fffff800`db591000 portcls portcls.sys Sat Jul 16 04:25:10 2016 (57899B06)
fffff800`d3ea0000 fffff800`d3eb7000 PSHED PSHED.dll Sat Jul 16 04:10:44 2016 (578997A4)
fffff800`d67d0000 fffff800`d6845000 rdbss rdbss.sys Thu Sep 15 18:23:45 2016 (57DACB11)
fffff800`d95e0000 fffff800`d95ee000 rdpbus rdpbus.sys Sat Jul 16 04:11:15 2016 (578997C3)
fffff800`d5470000 fffff800`d54b8000 rdyboost rdyboost.sys Sat Jul 16 04:25:16 2016 (57899B0C)
fffff800`d93f0000 fffff800`d9484000 rt640x64 rt640x64.sys Thu Jan 21 09:17:40 2016 (56A09424)
fffff800`d6a10000 fffff800`d6e92000 RTKVHD64 RTKVHD64.sys Tue Jun 16 12:55:05 2015 (55800089)
fffff800`d9490000 fffff800`d9539000 rtl819xp rtl819xp.sys Mon Apr 8 05:00:34 2013 (516232D2)
fffff800`d44c0000 fffff800`d454d000 spaceport spaceport.sys Sat Oct 15 05:46:37 2016 (5801A69D)
fffff800`d48c0000 fffff800`d4942000 storport storport.sys Sat Oct 15 05:45:16 2016 (5801A64C)
fffff800`d95c0000 fffff800`d95cc000 swenum swenum.sys Sat Jul 16 04:28:55 2016 (57899BE7)
fffff800`d5c40000 fffff800`d5c4e000 tbs tbs.sys Sat Jul 16 04:27:47 2016 (57899BA3)
fffff800`d5000000 fffff800`d5278000 tcpip tcpip.sys Sat Oct 15 05:32:46 2016 (5801A35E)
fffff800`d6660000 fffff800`d6670000 TDI TDI.SYS Sat Jul 16 04:28:10 2016 (57899BBA)
fffff800`d6630000 fffff800`d6653000 tdx tdx.sys Sat Jul 16 04:27:16 2016 (57899B84)
fffff800`d9320000 fffff800`d9343000 TeeDriverx64 TeeDriverx64.sys Tue Sep 23 22:01:14 2014 (5421D18A)
fffff800`d3e70000 fffff800`d3e95000 tm tm.sys Wed Oct 5 11:11:00 2016 (57F4C3A4)
fffff800`d92e0000 fffff800`d9318000 ucx01000 ucx01000.sys Sat Jul 16 04:25:10 2016 (57899B06)
fffff800`d6960000 fffff800`d6975000 umbus umbus.sys Sat Jul 16 04:22:33 2016 (57899A69)
fffff800`d97a0000 fffff800`d97d0000 usbccgp usbccgp.sys Sat Jul 16 04:28:03 2016 (57899BB3)
fffff800`d9670000 fffff800`d967e000 USBD USBD.SYS Sat Jul 16 04:28:27 2016 (57899BCB)
fffff800`d9350000 fffff800`d936c000 usbehci usbehci.sys Sat Jul 16 04:23:07 2016 (57899A8B)
fffff800`d95f0000 fffff800`d9670000 usbhub usbhub.sys Sat Jul 16 04:18:19 2016 (5789996B)
fffff800`d96b0000 fffff800`d9737000 UsbHub3 UsbHub3.sys Sat Jul 16 04:18:54 2016 (5789998E)
fffff800`d9370000 fffff800`d93e6000 USBPORT USBPORT.SYS Sat Jul 16 04:23:09 2016 (57899A8D)
fffff800`d9270000 fffff800`d92d3000 USBXHCI USBXHCI.SYS Sat Jul 16 04:20:30 2016 (578999EE)
fffff800`d4420000 fffff800`d4432000 vdrvroot vdrvroot.sys Sat Jul 16 04:25:58 2016 (57899B36)
fffff800`d4550000 fffff800`d4568000 volmgr volmgr.sys Sat Jul 16 04:10:43 2016 (578997A3)
fffff800`d4570000 fffff800`d45ce000 volmgrx volmgrx.sys Sat Jul 16 04:10:45 2016 (578997A5)
fffff800`d5400000 fffff800`d5464000 volsnap volsnap.sys Sat Jul 16 04:10:44 2016 (578997A4)
fffff800`d53f0000 fffff800`d53fb000 volume volume.sys Sat Jul 16 04:10:37 2016 (5789979D)
fffff800`d9540000 fffff800`d954e000 vwifibus vwifibus.sys Sat Jul 16 04:27:29 2016 (57899B91)
fffff800`d6760000 fffff800`d6779000 vwififlt vwififlt.sys Sat Jul 16 04:28:07 2016 (57899BB7)
fffff800`d5c90000 fffff800`d5ca4000 watchdog watchdog.sys Sat Jul 16 04:27:39 2016 (57899B9B)
fffff800`d4f10000 fffff800`d4fe4000 Wdf01000 Wdf01000.sys Sat Jul 16 04:13:12 2016 (57899838)
fffff800`d49d0000 fffff800`d4a1d000 WdFilter WdFilter.sys Sat Jul 16 04:25:21 2016 (57899B11)
fffff800`d4200000 fffff800`d4213000 WDFLDR WDFLDR.SYS Sat Jul 16 04:10:39 2016 (5789979F)
fffff800`d4190000 fffff800`d41a0000 werkernel werkernel.sys Sat Jul 16 04:28:51 2016 (57899BE3)
fffff800`d52f0000 fffff800`d531a000 wfplwfs wfplwfs.sys Sat Jul 16 04:25:57 2016 (57899B35)
fffff800`d4360000 fffff800`d437f000 WindowsTrustedRT WindowsTrustedRT.sys Sat Jul 16 04:27:05 2016 (57899B79)
fffff800`d4380000 fffff800`d438b000 WindowsTrustedRTProxy WindowsTrustedRTProxy.sys Sat Jul 16 04:27:05 2016 (57899B79)
fffff800`d9550000 fffff800`d955c000 wmiacpi wmiacpi.sys Sat Jul 16 04:18:19 2016 (5789996B)
fffff800`d4320000 fffff800`d432c000 WMILIB WMILIB.SYS Sat Jul 16 04:10:37 2016 (5789979D)
fffff800`d4990000 fffff800`d49c8000 Wof Wof.sys Sat Aug 6 05:45:24 2016 (57A55D54)
fffff800`d4250000 fffff800`d425e000 WppRecorder WppRecorder.sys Sat Jul 16 04:29:12 2016 (57899BF8)
fffff800`d7170000 fffff800`d728a000 xboxgip xboxgip.sys Sat Oct 15 05:58:34 2016 (5801A96A)

Unloaded modules:
fffff800`d55f0000 fffff800`d55ff000 dump_storpor
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0000F000
fffff800`d58d0000 fffff800`d5b93000 dump_iaStorA
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 002C3000
fffff800`d5bc0000 fffff800`d5bdd000 dump_dumpfve
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0001D000
fffff800`db500000 fffff800`db50a000 amdkmafd.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0000A000
fffff800`d68d0000 fffff800`d68e4000 dam.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 00014000
fffff800`d4330000 fffff800`d4340000 WdBoot.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 00010000
fffff800`d5500000 fffff800`d550f000 hwpolicy.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0000F000
[SMBIOS Data Tables v2.8]
[DMI Version - 0]
[2.0 Calling Convention - No]
[Table Size - 2948 bytes]

[BIOS Information (Type 0) - Length 24 - Handle 0000h]
Vendor American Megatrends Inc.
BIOS Version V17.0
BIOS Starting Address Segment f000
BIOS Release Date 04/16/2014
BIOS ROM Size 800000
BIOS Characteristics
07: - PCI Supported
11: - Upgradeable FLASH BIOS
12: - BIOS Shadowing Supported
15: - CD-Boot Supported
16: - Selectable Boot Supported
17: - BIOS ROM Socketed
19: - EDD Supported
23: - 1.2MB Floppy Supported
24: - 720KB Floppy Supported
25: - 2.88MB Floppy Supported
26: - Print Screen Device Supported
27: - Keyboard Services Supported
28: - Serial Services Supported
29: - Printer Services Supported
32: - BIOS Vendor Reserved
BIOS Characteristic Extensions
00: - ACPI Supported
01: - USB Legacy Supported
08: - BIOS Boot Specification Supported
10: - Specification Reserved
11: - Specification Reserved
BIOS Major Revision 4
BIOS Minor Revision 6
EC Firmware Major Revision 255
EC Firmware Minor Revision 255
[System Information (Type 1) - Length 27 - Handle 0001h]
Manufacturer ECT
Product Name
Version
Serial Number 1467308
UUID 00000000-0000-0000-0000-000000000000
Wakeup Type Power Switch
SKUNumber To be filled by O.E.M.
Family To be filled by O.E.M.
[BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
Manufacturer MSI
Product Z97-G43 (MS-7816)
Version 3.0
Serial Number To be filled by O.E.M.
Asset Tag
Feature Flags 09h
-93931808: - -93931760: - §'©-ù
Location To be filled by O.E.M.
Chassis Handle 0003h
Board Type 0ah - Processor/Memory Module
Number of Child Handles 0
[System Enclosure (Type 3) - Length 25 - Handle 0003h]
Manufacturer MSI
Chassis Type Desktop
Version 3.0
Serial Number
Asset Tag Number
Bootup State Safe
Power Supply State Safe
Thermal State Safe
Security Status None
OEM Defined 0
Height 0U
Number of Power Cords 1
Number of Contained Elements 1
Contained Element Size 3
[OEM Strings (Type 11) - Length 5 - Handle 0021h]
Number of Strings 1
1 To Be Filled By O.E.M.
[System Configuration Options (Type 12) - Length 5 - Handle 0022h]
[Processor Information (Type 4) - Length 42 - Handle 003dh]
Socket Designation SOCKET 0
Processor Type Central Processor
Processor Family c6h - Specification Reserved
Processor Manufacturer Intel
Processor ID c3060300fffbebbf
Processor Version Intel(R) Core(TM) i7-4790 CPU @ 3.60GHz
Processor Voltage 8ch - 1.2V
External Clock 100MHz
Max Speed 3800MHz
Current Speed 3600MHz
Status Enabled Populated
Processor Upgrade Specification Reserved
L1 Cache Handle 003eh
L2 Cache Handle 003fh
L3 Cache Handle 0040h
Serial Number [String Not Specified]
Asset Tag Number
Part Number Fill By OEM
[Cache Information (Type 7) - Length 19 - Handle 003eh]
Socket Designation CPU Internal L1
Cache Configuration 0180h - WB Enabled Int NonSocketed L1
Maximum Cache Size 0100h - 256K
Installed Size 0100h - 256K
Supported SRAM Type 0020h - Synchronous
Current SRAM Type 0020h - Synchronous
Cache Speed 0ns
Error Correction Type ParitySingle-Bit ECC
System Cache Type Other
Associativity 8-way Set-Associative
[Cache Information (Type 7) - Length 19 - Handle 003fh]
Socket Designation CPU Internal L2
Cache Configuration 0181h - WB Enabled Int NonSocketed L2
Maximum Cache Size 0400h - 1024K
Installed Size 0400h - 1024K
Supported SRAM Type 0020h - Synchronous
Current SRAM Type 0020h - Synchronous
Cache Speed 0ns
Error Correction Type Multi-Bit ECC
System Cache Type Unified
Associativity 8-way Set-Associative
[Cache Information (Type 7) - Length 19 - Handle 0040h]
Socket Designation CPU Internal L3
Cache Configuration 0182h - WB Enabled Int NonSocketed L3
Maximum Cache Size 2000h - 8192K
Installed Size 2000h - 8192K
Supported SRAM Type 0020h - Synchronous
Current SRAM Type 0020h - Synchronous
Cache Speed 0ns
Error Correction Type Specification Reserved
System Cache Type Unified
Associativity 16-way Set-Associative
[Physical Memory Array (Type 16) - Length 23 - Handle 0042h]
Location 03h - SystemBoard/Motherboard
Use 03h - System Memory
Memory Error Correction 03h - None
Maximum Capacity 33554432KB
Memory Error Inf Handle [Not Provided]
Number of Memory Devices 4
[Memory Device (Type 17) - Length 40 - Handle 0043h]
Physical Memory Array Handle 0042h
Memory Error Info Handle [Not Provided]
Total Width 0 bits
Data Width 0 bits
Size [Not Populated]
Form Factor 09h - DIMM
Device Set [None]
Device Locator ChannelA-DIMM0
Bank Locator BANK 0
Memory Type 02h - Unknown
Type Detail 0000h -
Speed 0MHz
Manufacturer [Empty]
Serial Number
Asset Tag Number [String Not Specified]
Part Number [Empty]
[Memory Device (Type 17) - Length 40 - Handle 0044h]
Physical Memory Array Handle 0042h
Memory Error Info Handle [Not Provided]
Total Width 64 bits
Data Width 64 bits
Size 8192MB
Form Factor 09h - DIMM
Device Set [None]
Device Locator ChannelA-DIMM1
Bank Locator BANK 1
Memory Type 18h - Specification Reserved
Type Detail 0080h - Synchronous
Speed 1600MHz
Manufacturer 1315
Serial Number
Asset Tag Number
Part Number BLS8G3D1609DS1S00.
[Memory Device (Type 17) - Length 40 - Handle 0045h]
Physical Memory Array Handle 0042h
Memory Error Info Handle [Not Provided]
Total Width 0 bits
Data Width 0 bits
Size [Not Populated]
Form Factor 09h - DIMM
Device Set [None]
Device Locator ChannelB-DIMM0
Bank Locator BANK 2
Memory Type 02h - Unknown
Type Detail 0000h -
Speed 0MHz
Manufacturer [Empty]
Serial Number
Asset Tag Number [String Not Specified]
Part Number [Empty]
[Memory Device (Type 17) - Length 40 - Handle 0046h]
Physical Memory Array Handle 0042h
Memory Error Info Handle [Not Provided]
Total Width 64 bits
Data Width 64 bits
Size 8192MB
Form Factor 09h - DIMM
Device Set [None]
Device Locator ChannelB-DIMM1
Bank Locator BANK 3
Memory Type 18h - Specification Reserved
Type Detail 0080h - Synchronous
Speed 1600MHz
Manufacturer 1315
Serial Number
Asset Tag Number
Part Number BLS8G3D1609DS1S00.
[Memory Array Mapped Address (Type 19) - Length 31 - Handle 0047h]
Starting Address 00000000h
Ending Address 00ffffffh
Memory Array Handle 0042h
Partition Width 04
[Memory Device Mapped Address (Type 20) - Length 35 - Handle 0048h]
Starting Address 00000000h
Ending Address 007fffffh
Memory Device Handle 0046h
Mem Array Mapped Adr Handle 0047h
Partition Row Position [Unknown]
Interleave Position 01
Interleave Data Depth 02
[Memory Device Mapped Address (Type 20) - Length 35 - Handle 0049h]
Starting Address 00800000h
Ending Address 00ffffffh
Memory Device Handle 0046h
Mem Array Mapped Adr Handle 0047h
Partition Row Position [Unknown]
Interleave Position 02
Interleave Data Depth 02
Machine ID Information [From Smbios 2.8, DMIVersion 0, Size=2948]
BiosMajorRelease = 4
BiosMinorRelease = 6
BiosVendor = American Megatrends Inc.
BiosVersion = V17.0
BiosReleaseDate = 04/16/2014
SystemManufacturer = ECT
SystemProductName =
SystemFamily = To be filled by O.E.M.
SystemVersion =
SystemSKU = To be filled by O.E.M.
BaseBoardManufacturer = MSI
BaseBoardProduct = Z97-G43 (MS-7816)
BaseBoardVersion = 3.0
CPUID: "Intel(R) Core(TM) i7-4790 CPU @ 3.60GHz"
MaxSpeed: 3600
CurrentSpeed: 3600
[CPU Information]
~MHz = REG_DWORD 3600
Component Information = REG_BINARY 0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0
Configuration Data = REG_FULL_RESOURCE_DESCRIPTOR ff,ff,ff,ff,ff,ff,ff,ff,0,0,0,0,0,0,0,0
Identifier = REG_SZ Intel64 Family 6 Model 60 Stepping 3
ProcessorNameString = REG_SZ Intel(R) Core(TM) i7-4790 CPU @ 3.60GHz
Update Status = REG_DWORD 0
VendorIdentifier = REG_SZ GenuineIntel
MSR8B = REG_QWORD 1e00000000
THREAD ffffd481c8d77040 Cid 0004.010c Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor 6
Not impersonating
GetUlongFromAddress: unable to read from fffff8001f187924
Owning Process ffffd481c84b3040 Image: System Process
Attached Process ffffd481ca3c2740 Image: smss.exe
Wait Start TickCount 581 Ticks: 0
Context Switch Count 4816 IdealProcessor: 4 NoStackSwap
ReadMemory error: Cannot get nt!KeMaximumIncrement value.
UserTime 00:00:00.000
KernelTime 00:00:00.000
Win32 Start Address nt!ExpWorkerThread (0xfffff8001ef27ef0)
Stack Init ffffe481c8b0ec90 Current ffffe481c8b0e2e0
Base ffffe481c8b0f000 Limit ffffe481c8b09000 Call 0000000000000000
Priority 13 BasePriority 12 PriorityDecrement 0 IoPriority 2 PagePriority 5
Child-SP RetAddr : Args to Child : Call Site
ffffe481`c8b0e6b8 fffff800`1f26c37c : 00000000`0000004c 00000000`c000021a ffffe481`c8b153f8 ffffd481`c9f6a820 : nt!KeBugCheckEx
ffffe481`c8b0e6c0 fffff800`1f265ef4 : ffffffff`800003e0 00000000`00000002 ffffe481`c8b0e800 00000000`00000002 : nt!PopGracefulShutdown+0x268
ffffe481`c8b0e700 fffff800`1efe6193 : ffffe481`00000004 00000000`00000004 00000000`c0000004 ffffe481`c8b0e900 : nt! ?? ::OKHAJAOM::`string'+0x1a64
ffffe481`c8b0e880 fffff800`1efde6d0 : fffff800`1f442a84 00000000`00000000 ffffe481`c8b0ea98 00000000`00000014 : nt!KiSystemServiceCopyEnd+0x13 (TrapFrame @ ffffe481`c8b0e880)
ffffe481`c8b0ea18 fffff800`1f442a84 : 00000000`00000000 ffffe481`c8b0ea98 00000000`00000014 fffff800`1f24e100 : nt!KiServiceLinkage
ffffe481`c8b0ea20 fffff800`1f3a8995 : 00000000`00000000 00000000`00000000 00000000`00000000 fffff800`1f24e280 : nt! ?? ::NNGAKEGL::`string'+0x37864
ffffe481`c8b0eae0 fffff800`1ef89125 : 00000000`00000001 fffff800`1ef890b8 00000000`00000002 00000000`00000000 : nt!PopPolicyWorkerAction+0x69
ffffe481`c8b0eb50 fffff800`1ef27fd9 : ffffd481`c8d77040 fffff800`1f192b00 fffff800`00000000 ffffd481`0017f000 : nt!PopPolicyWorkerThread+0x6d
ffffe481`c8b0eb80 fffff800`1ee93729 : ffffe481`c8780180 00000000`00000080 ffffd481`c84b3040 ffffd481`c8d77040 : nt!ExpWorkerThread+0xe9
ffffe481`c8b0ec10 fffff800`1efe09d6 : ffffe481`c8780180 ffffd481`c8d77040 fffff800`1ee936e8 219e0589`48c08b49 : nt!PspSystemThreadStartup+0x41
ffffe481`c8b0ec60 00000000`00000000 : ffffe481`c8b0f000 ffffe481`c8b09000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x16

Bugcheck code C000021A
Arguments ffffb082`ec613ab0 ffffffff`c0000428 00000000`00000000 00000189`8e8a0000
Debug session time: Tue Dec 27 21:20:46.433 2016 (UTC + 1:00)
System Uptime: 0 days 0:00:09.093

6: kd> !error ffffffffc0000428
Error code: (NTSTATUS) 0xc0000428 (3221226536) - Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 109, {a39ff25a86e62573, b3b6fee0d96732e1, fffff80274356af8, 1}

*** WARNING: Unable to verify checksum for win32k.sys
Probably caused by : Processing initial command '!analyze -v; lmtsmn; !sysinfo smbios; !sysinfo machineid; !sysinfo cpuspeed; !sysinfo cpuinfo; !thread; .bugcheck; .time;'
memory_corruption

Followup: memory_corruption
---------

4: kd> !analyze -v; lmtsmn; !sysinfo smbios; !sysinfo machineid; !sysinfo cpuspeed; !sysinfo cpuinfo; !thread; .bugcheck; .time;
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

CRITICAL_STRUCTURE_CORRUPTION (109)
This bugcheck is generated when the kernel detects that critical kernel code or
data have been corrupted. There are generally three causes for a corruption:
1) A driver has inadvertently or deliberately modified critical kernel code
or data. See http://www.microsoft.com/whdc/driver/kernel/64bitPatching.mspx
2) A developer attempted to set a normal kernel breakpoint using a kernel
debugger that was not attached when the system was booted. Normal breakpoints,
"bp", can only be set if the debugger is attached at boot time. Hardware
breakpoints, "ba", can be set at any time.
3) A hardware corruption occurred, e.g. failing RAM holding kernel code or data.
Arguments:
Arg1: a39ff25a86e62573, Reserved
Arg2: b3b6fee0d96732e1, Reserved
Arg3: fffff80274356af8, Failure type dependent information
Arg4: 0000000000000001, Type of corrupted region, can be
0 : A generic data region
1 : Modification of a function or .pdata
2 : A processor IDT
3 : A processor GDT
4 : Type 1 process list corruption
5 : Type 2 process list corruption
6 : Debug routine modification
7 : Critical MSR modification
8 : Object type
9 : A processor IVT
a : Modification of a system service function
b : A generic session data region
c : Modification of a session function or .pdata
d : Modification of an import table
e : Modification of a session import table
f : Ps Win32 callout modification
10 : Debug switch routine modification
11 : IRP allocator modification
12 : Driver call dispatcher modification
13 : IRP completion dispatcher modification
14 : IRP deallocator modification
15 : A processor control register
16 : Critical floating point control register modification
17 : Local APIC modification
18 : Kernel notification callout modification
19 : Loaded module list modification
1a : Type 3 process list corruption
1b : Type 4 process list corruption
1c : Driver object corruption
1d : Executive callback object modification
1e : Modification of module padding
1f : Modification of a protected process
20 : A generic data region
21 : A page hash mismatch
22 : A session page hash mismatch
23 : Load config directory modification
24 : Inverted function table modification
25 : Session configuration modification
26 : An extended processor control register
27 : Type 1 pool corruption
28 : Type 2 pool corruption
29 : Type 3 pool corruption
101 : General pool corruption
102 : Modification of win32k.sys

Debugging Details:
------------------

DUMP_CLASS: 1

DUMP_QUALIFIER: 400

BUILD_VERSION_STRING: 10.0.14393.447 (rs1_release_inmarket.161102-0100)

SYSTEM_MANUFACTURER: ECT

SYSTEM_SKU: To be filled by O.E.M.

BIOS_VENDOR: American Megatrends Inc.

BIOS_VERSION: V17.0

BIOS_DATE: 04/16/2014

BASEBOARD_MANUFACTURER: MSI

BASEBOARD_PRODUCT: Z97-G43 (MS-7816)

BASEBOARD_VERSION: 3.0

DUMP_TYPE: 2

BUGCHECK_P1: a39ff25a86e62573

BUGCHECK_P2: b3b6fee0d96732e1

BUGCHECK_P3: fffff80274356af8

BUGCHECK_P4: 1

PG_MISMATCH: 80000

MEMORY_CORRUPTOR: ONE_BIT

FAULTING_IP:
NTFS!TxfUndoMoveAttr+0
fffff802`74356af8 4c8bdc mov r11,rsp

CPU_COUNT: 8

CPU_MHZ: e10

CPU_VENDOR: GenuineIntel

CPU_FAMILY: 6

CPU_MODEL: 3c

CPU_STEPPING: 3

CPU_MICROCODE: 6,3c,3,0 (F,M,S,R) SIG: 1E'00000000 (cache) 1E'00000000 (init)

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: CODE_CORRUPTION

BUGCHECK_STR: 0x109

PROCESS_NAME: System

CURRENT_IRQL: 2

ANALYSIS_SESSION_HOST: MARTIJN

ANALYSIS_SESSION_TIME: 12-30-2016 12:04:18.0054

ANALYSIS_VERSION: 10.0.14321.1024 amd64fre

STACK_TEXT:
ffffb301`f0112038 00000000`00000000 : 00000000`00000109 a39ff25a`86e62573 b3b6fee0`d96732e1 fffff802`74356af8 : nt!KeBugCheckEx

STACK_COMMAND: kb

CHKIMG_EXTENSION: !chkimg -lo 50 -d !NTFS
fffff80274357faf - NTFS!TxfUndoMoveAttr+14b7
[ 49:41 ]
1 error : !NTFS (fffff80274357faf)

MODULE_NAME: memory_corruption

IMAGE_NAME: memory_corruption

FOLLOWUP_NAME: memory_corruption

DEBUG_FLR_IMAGE_TIMESTAMP: 0

FAILURE_BUCKET_ID: MEMORY_CORRUPTION_ONE_BIT

BUCKET_ID: MEMORY_CORRUPTION_ONE_BIT

PRIMARY_PROBLEM_CLASS: MEMORY_CORRUPTION_ONE_BIT

TARGET_TIME: 2016-12-27T15:34:35.000Z

OSBUILD: 14393

OSSERVICEPACK: 447

SERVICEPACK_NUMBER: 0

OS_REVISION: 0

SUITE_MASK: 784

PRODUCT_TYPE: 1

OSPLATFORM_TYPE: x64

OSNAME: Windows 10

OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS Personal

OS_LOCALE:

USER_LCID: 0

OSBUILD_TIMESTAMP: 2016-11-02 11:17:03

BUILDDATESTAMP_STR: 161102-0100

BUILDLAB_STR: rs1_release_inmarket

BUILDOSVER_STR: 10.0.14393.447

ANALYSIS_SESSION_ELAPSED_TIME: 399d

ANALYSIS_SOURCE: KM

FAILURE_ID_HASH_STRING: km:memory_corruption_one_bit

FAILURE_ID_HASH: {e3faf315-c3d0-81db-819a-6c43d23c63a7}

Followup: memory_corruption
---------

start end module name
fffff802`73980000 fffff802`73a33000 ACPI ACPI.sys Sat Jul 16 04:10:47 2016 (578997A7)
fffff802`73940000 fffff802`73963000 acpiex acpiex.sys Sat Jul 16 04:28:23 2016 (57899BC7)
fffff802`7a330000 fffff802`7a33b000 acpipagr acpipagr.sys Sat Jul 16 04:29:00 2016 (57899BEC)
fffff802`75700000 fffff802`75795000 afd afd.sys Sat Oct 15 05:53:45 2016 (5801A849)
fffff802`75970000 fffff802`759af000 ahcache ahcache.sys Sat Oct 15 05:31:36 2016 (5801A318)
fffff802`775e0000 fffff802`7762c000 amdacpksd amdacpksd.sys Wed Jul 6 04:29:03 2016 (577C6CEF)
fffff802`74960000 fffff802`74973000 amdkmpfd amdkmpfd.sys Tue Oct 28 00:26:38 2014 (544ED4AE)
fffff802`75b70000 fffff802`75b8e000 AtihdWT6 AtihdWT6.sys Wed Sep 21 01:17:24 2016 (57E1C384)
fffff802`78790000 fffff802`7a32b000 atikmdag atikmdag.sys Sun Dec 4 17:30:19 2016 (5844449B)
fffff802`75a00000 fffff802`75a83000 atikmpag atikmpag.sys Sun Dec 4 17:07:30 2016 (58443F42)
fffff802`75810000 fffff802`7581b000 avkmgr avkmgr.sys Tue Oct 20 15:16:43 2015 (56263EBB)
fffff802`76770000 fffff802`76784000 BasicDisplay BasicDisplay.sys Sat Jul 16 04:28:02 2016 (57899BB2)
fffff802`75620000 fffff802`75632000 BasicRender BasicRender.sys Sat Jul 16 04:28:14 2016 (57899BBE)
fffff802`76760000 fffff802`7676a000 Beep Beep.SYS Sat Jul 16 04:22:02 2016 (57899A4A)
fffff802`73f20000 fffff802`73f2c000 BOOTVID BOOTVID.dll Sat Jul 16 04:10:37 2016 (5789979D)
fffff802`774b0000 fffff802`774d2000 bowser bowser.sys Wed Nov 2 11:23:23 2016 (5819BE9B)
ffff854d`bf7b0000 ffff854d`bf7f0000 cdd cdd.dll unavailable (00000000)
fffff802`766e0000 fffff802`76711000 cdrom cdrom.sys Sat Jul 16 04:10:42 2016 (578997A2)
fffff802`73b90000 fffff802`73ba9000 CEA CEA.sys Sat Jul 16 04:28:38 2016 (57899BD6)
fffff802`73700000 fffff802`737a0000 CI CI.dll Thu Sep 15 18:40:08 2016 (57DACEE8)
fffff802`74ac0000 fffff802`74b22000 CLASSPNP CLASSPNP.SYS Wed Sep 7 06:33:32 2016 (57CF989C)
fffff802`73e60000 fffff802`73ec3000 CLFS CLFS.SYS Wed Nov 2 11:12:36 2016 (5819BC14)
fffff802`73630000 fffff802`736e0000 clipsp clipsp.sys Wed Sep 7 06:57:27 2016 (57CF9E37)
fffff802`736e0000 fffff802`736ed000 cmimcext cmimcext.sys Thu Sep 15 18:15:09 2016 (57DAC90D)
fffff802`737a0000 fffff802`7383c000 cng cng.sys Sat Aug 6 05:38:01 2016 (57A55B99)
fffff802`759b0000 fffff802`759c1000 CompositeBus CompositeBus.sys Sat Jul 16 04:20:11 2016 (578999DB)
fffff802`77a20000 fffff802`77a32000 condrv condrv.sys Sat Jul 16 04:10:38 2016 (5789979E)
fffff802`74b50000 fffff802`74b69000 crashdmp crashdmp.sys Sat Oct 15 05:46:27 2016 (5801A693)
fffff802`765b0000 fffff802`765c7000 dc1_controller dc1-controller.sys Sat Jul 16 04:28:18 2016 (57899BC2)
fffff802`77d40000 fffff802`77d53000 DevAuthE DevAuthE.sys Sat Jul 16 04:29:16 2016 (57899BFC)
fffff802`75920000 fffff802`7594a000 dfsc dfsc.sys Wed Oct 5 11:34:11 2016 (57F4C913)
fffff802`74aa0000 fffff802`74abe000 disk disk.sys Sat Jul 16 04:10:52 2016 (578997AC)
fffff802`7a3d0000 fffff802`7a3f1000 drmk drmk.sys Sat Jul 16 04:27:13 2016 (57899B81)
fffff802`76600000 fffff802`7660f000 dump_diskdump dump_diskdump.sys Sat Jul 16 04:21:57 2016 (57899A45)
fffff802`763b0000 fffff802`763cd000 dump_dumpfve dump_dumpfve.sys Sat Jul 16 04:27:46 2016 (57899BA2)
fffff802`74b70000 fffff802`74e33000 dump_iaStorA dump_iaStorA.sys Fri Apr 4 01:00:05 2014 (533DE7F5)
fffff802`75400000 fffff802`7561e000 dxgkrnl dxgkrnl.sys Sat Oct 15 05:36:30 2016 (5801A43E)
fffff802`764f0000 fffff802`76597000 dxgmms2 dxgmms2.sys Sat Oct 15 05:53:08 2016 (5801A824)
fffff802`74090000 fffff802`740ac000 EhStorClass EhStorClass.sys Sat Jul 16 04:18:35 2016 (5789997B)
fffff802`76720000 fffff802`7673d000 filecrypt filecrypt.sys Sat Jul 16 04:22:39 2016 (57899A6F)
fffff802`740b0000 fffff802`740c9000 fileinfo fileinfo.sys Sat Jul 16 04:26:05 2016 (57899B3D)
fffff802`73f30000 fffff802`73f92000 FLTMGR FLTMGR.SYS Sat Jul 16 04:10:45 2016 (578997A5)
fffff802`743a0000 fffff802`743ad000 Fs_Rec Fs_Rec.sys Sat Jul 16 04:10:37 2016 (5789979D)
fffff802`748b0000 fffff802`74953000 fvevol fvevol.sys Thu Sep 15 18:36:20 2016 (57DACE04)
fffff802`74810000 fffff802`74879000 fwpkclnt fwpkclnt.sys Sat Oct 15 05:53:56 2016 (5801A854)
fffff802`75910000 fffff802`7591a000 gpuenergydrv gpuenergydrv.sys Sat Jul 16 04:28:09 2016 (57899BB9)
fffff801`1281a000 fffff801`1288f000 hal hal.dll Thu Sep 15 18:15:22 2016 (57DAC91A)
fffff802`7a340000 fffff802`7a35b000 HDAudBus HDAudBus.sys Sat Jul 16 04:27:11 2016 (57899B7F)
fffff802`76420000 fffff802`7644f000 HIDCLASS HIDCLASS.SYS Sat Oct 15 05:55:48 2016 (5801A8C4)
fffff802`76450000 fffff802`76462000 HIDPARSE HIDPARSE.SYS Sat Aug 6 05:46:37 2016 (57A55D9D)
fffff802`76400000 fffff802`76411000 hidusb hidusb.sys Sat Aug 6 05:47:49 2016 (57A55DE5)
fffff802`77370000 fffff802`77482000 HTTP HTTP.sys Sat Oct 15 05:41:03 2016 (5801A54F)
fffff802`74f20000 fffff802`751e3000 iaStorA iaStorA.sys Fri Apr 4 01:00:05 2014 (533DE7F5)
fffff802`73a60000 fffff802`73a71000 intelpep intelpep.sys Sat Jul 16 04:18:27 2016 (57899973)
fffff802`78760000 fffff802`7878b000 intelppm intelppm.sys Sat Jul 16 04:10:43 2016 (578997A3)
fffff802`74a80000 fffff802`74a90000 iorate iorate.sys Wed Nov 2 11:12:31 2016 (5819BC0F)
fffff802`75a90000 fffff802`75aa0000 ISCTD64 ISCTD64.sys Tue Aug 23 19:32:39 2011 (4E53E437)
fffff802`764d0000 fffff802`764e3000 kbdclass kbdclass.sys Sat Jul 16 04:26:27 2016 (57899B53)
fffff802`764c0000 fffff802`764d0000 kbdhid kbdhid.sys Thu Sep 15 18:43:23 2016 (57DACFAB)
fffff801`11552000 fffff801`1155d000 kd kd.dll Sat Jul 16 04:29:16 2016 (57899BFC)
fffff802`759d0000 fffff802`759de000 kdnic kdnic.sys Sat Jul 16 04:28:28 2016 (57899BCC)
fffff802`78400000 fffff802`78468000 ks ks.sys Sat Jul 16 04:24:18 2016 (57899AD2)
fffff802`73600000 fffff802`73628000 ksecdd ksecdd.sys Wed Sep 7 07:00:34 2016 (57CF9EF2)
fffff802`74560000 fffff802`74590000 ksecpkg ksecpkg.sys Sat Aug 6 05:44:30 2016 (57A55D1E)
fffff802`75b90000 fffff802`75b9e000 ksthunk ksthunk.sys Sat Jul 16 04:28:56 2016 (57899BE8)
fffff802`75ac0000 fffff802`75ac3d80 LGBusEnum LGBusEnum.sys Tue Nov 24 02:36:48 2009 (4B0B38B0)
fffff802`76470000 fffff802`76485000 LGSHidFilt LGSHidFilt.Sys Thu May 30 17:16:33 2013 (51A76D51)
fffff802`77a10000 fffff802`77a12480 LGVirHid LGVirHid.sys Tue Nov 24 02:36:48 2009 (4B0B38B0)
fffff802`77240000 fffff802`77256000 lltdio lltdio.sys Sat Jul 16 04:27:11 2016 (57899B7F)
fffff802`77d80000 fffff802`77da6000 luafv luafv.sys Sat Jul 16 04:21:48 2016 (57899A3C)
fffff802`73dc0000 fffff802`73e4e000 mcupdate_GenuineIntel mcupdate_GenuineIntel.dll Sat Jul 16 04:28:05 2016 (57899BB5)
fffff802`777f0000 fffff802`77804000 mmcss mmcss.sys Sat Jul 16 04:20:45 2016 (578999FD)
fffff802`765a0000 fffff802`765b0000 monitor monitor.sys Sat Jul 16 04:28:26 2016 (57899BCA)
fffff802`764a0000 fffff802`764b2000 mouclass mouclass.sys Sat Jul 16 04:26:40 2016 (57899B60)
fffff802`76490000 fffff802`7649f000 mouhid mouhid.sys Sat Jul 16 04:27:35 2016 (57899B97)
fffff802`73cf0000 fffff802`73d0e000 mountmgr mountmgr.sys Sat Jul 16 04:10:42 2016 (578997A2)
fffff802`775a0000 fffff802`775b9000 mpsdrv mpsdrv.sys Sat Jul 16 04:27:16 2016 (57899B84)
fffff802`774e0000 fffff802`77555000 mrxsmb mrxsmb.sys Wed Sep 7 06:48:56 2016 (57CF9C38)
fffff802`777a0000 fffff802`777ed000 mrxsmb10 mrxsmb10.sys Wed Sep 7 06:50:18 2016 (57CF9C8A)
fffff802`77560000 fffff802`7759b000 mrxsmb20 mrxsmb20.sys Thu Sep 15 18:30:52 2016 (57DACCBC)
fffff802`75660000 fffff802`75670000 Msfs Msfs.SYS Sat Jul 16 04:10:38 2016 (5789979E)
fffff802`73ad0000 fffff802`73adb000 msisadrv msisadrv.sys Sat Jul 16 04:28:51 2016 (57899BE3)
fffff802`77260000 fffff802`77278000 mslldp mslldp.sys Sat Jul 16 04:28:24 2016 (57899BC8)
fffff802`73fa0000 fffff802`73ffd000 msrpc msrpc.sys Sat Jul 16 04:23:06 2016 (57899A8A)
fffff802`75900000 fffff802`75910000 mssmbios mssmbios.sys Sat Jul 16 04:26:00 2016 (57899B38)
fffff802`74a50000 fffff802`74a75000 mup mup.sys Sat Jul 16 04:11:22 2016 (578997CA)
fffff802`743b0000 fffff802`744d8000 ndis ndis.sys Wed Oct 5 11:19:09 2016 (57F4C58D)
fffff802`772c0000 fffff802`772d6000 ndisuio ndisuio.sys Sat Jul 16 04:26:32 2016 (57899B58)
fffff802`75aa0000 fffff802`75aad000 NdisVirtualBus NdisVirtualBus.sys Sat Jul 16 04:26:32 2016 (57899B58)
fffff802`77770000 fffff802`77796000 Ndu Ndu.sys Sat Jul 16 04:26:12 2016 (57899B44)
fffff802`757f0000 fffff802`75802000 netbios netbios.sys Sat Jul 16 04:27:18 2016 (57899B86)
fffff802`756b0000 fffff802`756fb000 netbt netbt.sys Sat Jul 16 04:25:07 2016 (57899B03)
fffff802`744e0000 fffff802`74559000 NETIO NETIO.SYS Sat Jul 16 04:26:08 2016 (57899B40)
fffff802`75640000 fffff802`75659000 Npfs Npfs.SYS Sat Jul 16 04:10:38 2016 (5789979E)
fffff802`758f0000 fffff802`758fd000 npsvctrig npsvctrig.sys Sat Jul 16 04:28:33 2016 (57899BD1)
fffff802`758d0000 fffff802`758e1000 nsiproxy nsiproxy.sys Sat Jul 16 04:26:45 2016 (57899B65)
fffff801`1288f000 fffff801`130af000 nt ntkrnlmp.exe Wed Nov 2 11:17:03 2016 (5819BD1F)
fffff802`74160000 fffff802`74392000 NTFS NTFS.sys Wed Nov 2 11:15:32 2016 (5819BCC4)
fffff802`736f0000 fffff802`736fc000 ntosext ntosext.sys Sat Jul 16 04:10:37 2016 (5789979D)
fffff802`76750000 fffff802`7675a000 Null Null.SYS Sat Jul 16 04:10:37 2016 (5789979D)
fffff802`772e0000 fffff802`77369000 nwifi nwifi.sys Sat Jul 16 04:25:03 2016 (57899AFF)
fffff802`757c0000 fffff802`757eb000 pacer pacer.sys Sat Jul 16 04:25:21 2016 (57899B11)
fffff802`73bb0000 fffff802`73bd4000 partmgr partmgr.sys Thu Sep 15 18:15:19 2016 (57DAC917)
fffff802`73ae0000 fffff802`73b37000 pci pci.sys Sat Oct 15 05:49:22 2016 (5801A742)
fffff802`73ab0000 fffff802`73ac2000 pcw pcw.sys Sat Jul 16 04:10:37 2016 (5789979D)
fffff802`73b60000 fffff802`73b81000 pdc pdc.sys Sat Aug 20 06:51:30 2016 (57B7E1D2)
fffff802`776a0000 fffff802`77762000 peauth peauth.sys Sat Jul 16 04:24:39 2016 (57899AE7)
fffff802`7a360000 fffff802`7a3c1000 portcls portcls.sys Sat Jul 16 04:25:10 2016 (57899B06)
fffff802`73f00000 fffff802`73f17000 PSHED PSHED.dll Sat Jul 16 04:10:44 2016 (578997A4)
fffff802`75850000 fffff802`758c5000 rdbss rdbss.sys Thu Sep 15 18:23:45 2016 (57DACB11)
fffff802`75ad0000 fffff802`75ade000 rdpbus rdpbus.sys Sat Jul 16 04:11:15 2016 (578997C3)
fffff802`74a00000 fffff802`74a48000 rdyboost rdyboost.sys Sat Jul 16 04:25:16 2016 (57899B0C)
fffff802`77220000 fffff802`77238000 registry registry.sys Sat Jul 16 04:27:04 2016 (57899B78)
fffff802`77280000 fffff802`7729a000 rspndr rspndr.sys Sat Jul 16 04:27:29 2016 (57899B91)
fffff802`785f0000 fffff802`78684000 rt640x64 rt640x64.sys Thu Jan 21 09:17:40 2016 (56A09424)
fffff802`75c30000 fffff802`760b2000 RTKVHD64 RTKVHD64.sys Tue Jun 16 12:55:05 2015 (55800089)
fffff802`78690000 fffff802`78739000 rtl819xp rtl819xp.sys Mon Apr 8 05:00:34 2013 (516232D2)
fffff802`73be0000 fffff802`73c6d000 spaceport spaceport.sys Sat Oct 15 05:46:37 2016 (5801A69D)
fffff802`778f0000 fffff802`7797c000 srv srv.sys Wed Sep 7 06:49:09 2016 (57CF9C45)
fffff802`77830000 fffff802`778e4000 srv2 srv2.sys Thu Sep 15 18:30:41 2016 (57DACCB1)
fffff802`77650000 fffff802`77694000 srvnet srvnet.sys Wed Sep 7 06:45:09 2016 (57CF9B55)
fffff802`74000000 fffff802`74082000 storport storport.sys Sat Oct 15 05:45:16 2016 (5801A64C)
fffff802`77db0000 fffff802`77dc9000 storqosflt storqosflt.sys Sat Jul 16 04:26:43 2016 (57899B63)
fffff802`75ab0000 fffff802`75abc000 swenum swenum.sys Sat Jul 16 04:28:55 2016 (57899BE7)
fffff802`76740000 fffff802`7674e000 tbs tbs.sys Sat Jul 16 04:27:47 2016 (57899BA3)
fffff802`74590000 fffff802`74808000 tcpip tcpip.sys Sat Oct 15 05:32:46 2016 (5801A35E)
fffff802`77810000 fffff802`77824000 tcpipreg tcpipreg.sys Sat Jul 16 04:25:32 2016 (57899B1C)
fffff802`756a0000 fffff802`756b0000 TDI TDI.SYS Sat Jul 16 04:28:10 2016 (57899BBA)
fffff802`75670000 fffff802`75693000 tdx tdx.sys Sat Jul 16 04:27:16 2016 (57899B84)
fffff802`78520000 fffff802`78543000 TeeDriverx64 TeeDriverx64.sys Tue Sep 23 22:01:14 2014 (5421D18A)
fffff802`73ed0000 fffff802`73ef5000 tm tm.sys Wed Oct 5 11:11:00 2016 (57F4C3A4)
ffff854d`bf7a0000 ffff854d`bf7aa000 TSDDD TSDDD.dll unavailable (00000000)
fffff802`779e0000 fffff802`77a0f000 tunnel tunnel.sys Sat Jul 16 04:26:20 2016 (57899B4C)
fffff802`784e0000 fffff802`78518000 ucx01000 ucx01000.sys Sat Jul 16 04:25:10 2016 (57899B06)
fffff802`759e0000 fffff802`759f5000 umbus umbus.sys Sat Jul 16 04:22:33 2016 (57899A69)
fffff802`763d0000 fffff802`76400000 usbccgp usbccgp.sys Sat Jul 16 04:28:03 2016 (57899BB3)
fffff802`75b60000 fffff802`75b6e000 USBD USBD.SYS Sat Jul 16 04:28:27 2016 (57899BCB)
fffff802`78550000 fffff802`7856c000 usbehci usbehci.sys Sat Jul 16 04:23:07 2016 (57899A8B)
fffff802`75ae0000 fffff802`75b60000 usbhub usbhub.sys Sat Jul 16 04:18:19 2016 (5789996B)
fffff802`75ba0000 fffff802`75c27000 UsbHub3 UsbHub3.sys Sat Jul 16 04:18:54 2016 (5789998E)
fffff802`78570000 fffff802`785e6000 USBPORT USBPORT.SYS Sat Jul 16 04:23:09 2016 (57899A8D)
fffff802`78470000 fffff802`784d3000 USBXHCI USBXHCI.SYS Sat Jul 16 04:20:30 2016 (578999EE)
fffff802`73b40000 fffff802`73b52000 vdrvroot vdrvroot.sys Sat Jul 16 04:25:58 2016 (57899B36)
fffff802`73c70000 fffff802`73c88000 volmgr volmgr.sys Sat Jul 16 04:10:43 2016 (578997A3)
fffff802`73c90000 fffff802`73cee000 volmgrx volmgrx.sys Sat Jul 16 04:10:45 2016 (578997A5)
fffff802`74990000 fffff802`749f4000 volsnap volsnap.sys Sat Jul 16 04:10:44 2016 (578997A4)
fffff802`74980000 fffff802`7498b000 volume volume.sys Sat Jul 16 04:10:37 2016 (5789979D)
fffff802`78740000 fffff802`7874e000 vwifibus vwifibus.sys Sat Jul 16 04:27:29 2016 (57899B91)
fffff802`757a0000 fffff802`757b9000 vwififlt vwififlt.sys Sat Jul 16 04:28:07 2016 (57899BB7)
fffff802`772a0000 fffff802`772bb000 wanarp wanarp.sys Sat Jul 16 04:28:56 2016 (57899BE8)
fffff802`76790000 fffff802`767a4000 watchdog watchdog.sys Sat Jul 16 04:27:39 2016 (57899B9B)
fffff802`77d60000 fffff802`77d80000 wcifs wcifs.sys Thu Sep 15 18:42:03 2016 (57DACF5B)
fffff802`77200000 fffff802`77216000 wcnfs wcnfs.sys Sat Jul 16 04:28:27 2016 (57899BCB)
fffff802`73840000 fffff802`73914000 Wdf01000 Wdf01000.sys Sat Jul 16 04:13:12 2016 (57899838)
fffff802`74110000 fffff802`7415d000 WdFilter WdFilter.sys Sat Jul 16 04:25:21 2016 (57899B11)
fffff802`73920000 fffff802`73933000 WDFLDR WDFLDR.SYS Sat Jul 16 04:10:39 2016 (5789979F)
fffff802`77a40000 fffff802`77a62000 WdNisDrv WdNisDrv.sys Sat Jul 16 04:25:56 2016 (57899B34)
fffff802`73e50000 fffff802`73e60000 werkernel werkernel.sys Sat Jul 16 04:28:51 2016 (57899BE3)
fffff802`74880000 fffff802`748aa000 wfplwfs wfplwfs.sys Sat Jul 16 04:25:57 2016 (57899B35)
ffff854d`bf840000 ffff854d`bf87b000 win32k win32k.sys unavailable (00000000)
ffff854d`bf880000 ffff854d`bfa00000 win32kbase win32kbase.sys unavailable (00000000)
ffff854d`bf400000 ffff854d`bf788000 win32kfull win32kfull.sys unavailable (00000000)
fffff802`73a80000 fffff802`73a9f000 WindowsTrustedRT WindowsTrustedRT.sys Sat Jul 16 04:27:05 2016 (57899B79)
fffff802`73aa0000 fffff802`73aab000 WindowsTrustedRTProxy WindowsTrustedRTProxy.sys Sat Jul 16 04:27:05 2016 (57899B79)
fffff802`78750000 fffff802`7875c000 wmiacpi wmiacpi.sys Sat Jul 16 04:18:19 2016 (5789996B)
fffff802`73a40000 fffff802`73a4c000 WMILIB WMILIB.SYS Sat Jul 16 04:10:37 2016 (5789979D)
fffff802`740d0000 fffff802`74108000 Wof Wof.sys Sat Aug 6 05:45:24 2016 (57A55D54)
fffff802`73970000 fffff802`7397e000 WppRecorder WppRecorder.sys Sat Jul 16 04:29:12 2016 (57899BF8)
fffff802`77490000 fffff802`774ae000 WudfPf WudfPf.sys Sat Jul 16 04:26:10 2016 (57899B42)
fffff802`77c20000 fffff802`77d3a000 xboxgip xboxgip.sys Sat Oct 15 05:58:34 2016 (5801A96A)
fffff802`775c0000 fffff802`775d3000 xinputhid xinputhid.sys Sat Aug 20 07:20:50 2016 (57B7E8B2)

Unloaded modules:
fffff802`75820000 fffff802`75849000 avipbb.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 00029000
fffff802`77dd0000 fffff802`77dfb000 avgntflt.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0002B000
fffff802`77630000 fffff802`77644000 avnetflt.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 00014000
fffff802`779b0000 fffff802`779d2000 WdNisDrv.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 00022000
fffff802`77980000 fffff802`779af000 tunnel.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0002F000
fffff802`74b80000 fffff802`74b8f000 dump_storpor
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0000F000
fffff802`763d0000 fffff802`76693000 dump_iaStorA
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 002C3000
fffff802`766c0000 fffff802`766dd000 dump_dumpfve
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0001D000
fffff802`7a330000 fffff802`7a33a000 amdkmafd.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0000A000
fffff802`75950000 fffff802`75964000 dam.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 00014000
fffff802`73a50000 fffff802`73a60000 WdBoot.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 00010000
fffff802`74a90000 fffff802`74a9f000 hwpolicy.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0000F000
[SMBIOS Data Tables v2.8]
[DMI Version - 0]
[2.0 Calling Convention - No]
[Table Size - 2948 bytes]

[BIOS Information (Type 0) - Length 24 - Handle 0000h]
Vendor American Megatrends Inc.
BIOS Version V17.0
BIOS Starting Address Segment f000
BIOS Release Date 04/16/2014
BIOS ROM Size 800000
BIOS Characteristics
07: - PCI Supported
11: - Upgradeable FLASH BIOS
12: - BIOS Shadowing Supported
15: - CD-Boot Supported
16: - Selectable Boot Supported
17: - BIOS ROM Socketed
19: - EDD Supported
23: - 1.2MB Floppy Supported
24: - 720KB Floppy Supported
25: - 2.88MB Floppy Supported
26: - Print Screen Device Supported
27: - Keyboard Services Supported
28: - Serial Services Supported
29: - Printer Services Supported
32: - BIOS Vendor Reserved
BIOS Characteristic Extensions
00: - ACPI Supported
01: - USB Legacy Supported
08: - BIOS Boot Specification Supported
10: - Specification Reserved
11: - Specification Reserved
BIOS Major Revision 4
BIOS Minor Revision 6
EC Firmware Major Revision 255
EC Firmware Minor Revision 255
[System Information (Type 1) - Length 27 - Handle 0001h]
Manufacturer ECT
Product Name
Version
Serial Number 1467308
UUID 00000000-0000-0000-0000-000000000000
Wakeup Type Power Switch
SKUNumber To be filled by O.E.M.
Family To be filled by O.E.M.
[BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
Manufacturer MSI
Product Z97-G43 (MS-7816)
Version 3.0
Serial Number To be filled by O.E.M.
Asset Tag
Feature Flags 09h
-93931808: - -93931760: - §'©-ù
Location To be filled by O.E.M.
Chassis Handle 0003h
Board Type 0ah - Processor/Memory Module
Number of Child Handles 0
[System Enclosure (Type 3) - Length 25 - Handle 0003h]
Manufacturer MSI
Chassis Type Desktop
Version 3.0
Serial Number
Asset Tag Number
Bootup State Safe
Power Supply State Safe
Thermal State Safe
Security Status None
OEM Defined 0
Height 0U
Number of Power Cords 1
Number of Contained Elements 1
Contained Element Size 3
[OEM Strings (Type 11) - Length 5 - Handle 0021h]
Number of Strings 1
1 To Be Filled By O.E.M.
[System Configuration Options (Type 12) - Length 5 - Handle 0022h]
[Processor Information (Type 4) - Length 42 - Handle 003dh]
Socket Designation SOCKET 0
Processor Type Central Processor
Processor Family c6h - Specification Reserved
Processor Manufacturer Intel
Processor ID c3060300fffbebbf
Processor Version Intel(R) Core(TM) i7-4790 CPU @ 3.60GHz
Processor Voltage 8ch - 1.2V
External Clock 100MHz
Max Speed 3800MHz
Current Speed 3600MHz
Status Enabled Populated
Processor Upgrade Specification Reserved
L1 Cache Handle 003eh
L2 Cache Handle 003fh
L3 Cache Handle 0040h
Serial Number [String Not Specified]
Asset Tag Number
Part Number Fill By OEM
[Cache Information (Type 7) - Length 19 - Handle 003eh]
Socket Designation CPU Internal L1
Cache Configuration 0180h - WB Enabled Int NonSocketed L1
Maximum Cache Size 0100h - 256K
Installed Size 0100h - 256K
Supported SRAM Type 0020h - Synchronous
Current SRAM Type 0020h - Synchronous
Cache Speed 0ns
Error Correction Type ParitySingle-Bit ECC
System Cache Type Other
Associativity 8-way Set-Associative
[Cache Information (Type 7) - Length 19 - Handle 003fh]
Socket Designation CPU Internal L2
Cache Configuration 0181h - WB Enabled Int NonSocketed L2
Maximum Cache Size 0400h - 1024K
Installed Size 0400h - 1024K
Supported SRAM Type 0020h - Synchronous
Current SRAM Type 0020h - Synchronous
Cache Speed 0ns
Error Correction Type Multi-Bit ECC
System Cache Type Unified
Associativity 8-way Set-Associative
[Cache Information (Type 7) - Length 19 - Handle 0040h]
Socket Designation CPU Internal L3
Cache Configuration 0182h - WB Enabled Int NonSocketed L3
Maximum Cache Size 2000h - 8192K
Installed Size 2000h - 8192K
Supported SRAM Type 0020h - Synchronous
Current SRAM Type 0020h - Synchronous
Cache Speed 0ns
Error Correction Type Specification Reserved
System Cache Type Unified
Associativity 16-way Set-Associative
[Physical Memory Array (Type 16) - Length 23 - Handle 0042h]
Location 03h - SystemBoard/Motherboard
Use 03h - System Memory
Memory Error Correction 03h - None
Maximum Capacity 33554432KB
Memory Error Inf Handle [Not Provided]
Number of Memory Devices 4
[Memory Device (Type 17) - Length 40 - Handle 0043h]
Physical Memory Array Handle 0042h
Memory Error Info Handle [Not Provided]
Total Width 0 bits
Data Width 0 bits
Size [Not Populated]
Form Factor 09h - DIMM
Device Set [None]
Device Locator ChannelA-DIMM0
Bank Locator BANK 0
Memory Type 02h - Unknown
Type Detail 0000h -
Speed 0MHz
Manufacturer [Empty]
Serial Number
Asset Tag Number [String Not Specified]
Part Number [Empty]
[Memory Device (Type 17) - Length 40 - Handle 0044h]
Physical Memory Array Handle 0042h
Memory Error Info Handle [Not Provided]
Total Width 64 bits
Data Width 64 bits
Size 8192MB
Form Factor 09h - DIMM
Device Set [None]
Device Locator ChannelA-DIMM1
Bank Locator BANK 1
Memory Type 18h - Specification Reserved
Type Detail 0080h - Synchronous
Speed 1600MHz
Manufacturer 1315
Serial Number
Asset Tag Number
Part Number BLS8G3D1609DS1S00.
[Memory Device (Type 17) - Length 40 - Handle 0045h]
Physical Memory Array Handle 0042h
Memory Error Info Handle [Not Provided]
Total Width 0 bits
Data Width 0 bits
Size [Not Populated]
Form Factor 09h - DIMM
Device Set [None]
Device Locator ChannelB-DIMM0
Bank Locator BANK 2
Memory Type 02h - Unknown
Type Detail 0000h -
Speed 0MHz
Manufacturer [Empty]
Serial Number
Asset Tag Number [String Not Specified]
Part Number [Empty]
[Memory Device (Type 17) - Length 40 - Handle 0046h]
Physical Memory Array Handle 0042h
Memory Error Info Handle [Not Provided]
Total Width 64 bits
Data Width 64 bits
Size 8192MB
Form Factor 09h - DIMM
Device Set [None]
Device Locator ChannelB-DIMM1
Bank Locator BANK 3
Memory Type 18h - Specification Reserved
Type Detail 0080h - Synchronous
Speed 1600MHz
Manufacturer 1315
Serial Number
Asset Tag Number
Part Number BLS8G3D1609DS1S00.
[Memory Array Mapped Address (Type 19) - Length 31 - Handle 0047h]
Starting Address 00000000h
Ending Address 00ffffffh
Memory Array Handle 0042h
Partition Width 04
[Memory Device Mapped Address (Type 20) - Length 35 - Handle 0048h]
Starting Address 00000000h
Ending Address 007fffffh
Memory Device Handle 0046h
Mem Array Mapped Adr Handle 0047h
Partition Row Position [Unknown]
Interleave Position 01
Interleave Data Depth 02
[Memory Device Mapped Address (Type 20) - Length 35 - Handle 0049h]
Starting Address 00800000h
Ending Address 00ffffffh
Memory Device Handle 0046h
Mem Array Mapped Adr Handle 0047h
Partition Row Position [Unknown]
Interleave Position 02
Interleave Data Depth 02
Machine ID Information [From Smbios 2.8, DMIVersion 0, Size=2948]
BiosMajorRelease = 4
BiosMinorRelease = 6
BiosVendor = American Megatrends Inc.
BiosVersion = V17.0
BiosReleaseDate = 04/16/2014
SystemManufacturer = ECT
SystemProductName =
SystemFamily = To be filled by O.E.M.
SystemVersion =
SystemSKU = To be filled by O.E.M.
BaseBoardManufacturer = MSI
BaseBoardProduct = Z97-G43 (MS-7816)
BaseBoardVersion = 3.0
CPUID: "Intel(R) Core(TM) i7-4790 CPU @ 3.60GHz"
MaxSpeed: 3600
CurrentSpeed: 3600
[CPU Information]
~MHz = REG_DWORD 3600
Component Information = REG_BINARY 0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0
Configuration Data = REG_FULL_RESOURCE_DESCRIPTOR ff,ff,ff,ff,ff,ff,ff,ff,0,0,0,0,0,0,0,0
Identifier = REG_SZ Intel64 Family 6 Model 60 Stepping 3
ProcessorNameString = REG_SZ Intel(R) Core(TM) i7-4790 CPU @ 3.60GHz
Update Status = REG_DWORD 0
VendorIdentifier = REG_SZ GenuineIntel
MSR8B = REG_QWORD 1e00000000
THREAD ffffa30be8370040 Cid 0004.0158 Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor 4
Not impersonating
GetUlongFromAddress: unable to read from fffff80112b85924
Owning Process ffffa30be52b3040 Image: System
Attached Process N/A Image: N/A
fffff78000000000: Unable to get shared data
Wait Start TickCount 165618
Context Switch Count 161379 IdealProcessor: 3
ReadMemory error: Cannot get nt!KeMaximumIncrement value.
UserTime 00:00:00.000
KernelTime 00:00:00.000
Stack Init ffffb301f0112c90 Current ffffb301f0111cc0
Base ffffb301f0113000 Limit ffffb301f010d000 Call 0000000000000000
Priority 12 BasePriority 12 PriorityDecrement 0 IoPriority 2 PagePriority 5
Child-SP RetAddr : Args to Child : Call Site
ffffb301`f0112038 00000000`00000000 : 00000000`00000109 a39ff25a`86e62573 b3b6fee0`d96732e1 fffff802`74356af8 : nt!KeBugCheckEx

Bugcheck code 00000109
Arguments a39ff25a`86e62573 b3b6fee0`d96732e1 fffff802`74356af8 00000000`00000001
Debug session time: Tue Dec 27 16:34:35.017 2016 (UTC + 1:00)
System Uptime: 0 days 0:43:10.677

*** WARNING: Unable to verify timestamp for atikmdag.sys
*** ERROR: Module load completed but symbols could not be loaded for atikmdag.sys
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 1000007E, {ffffffffc0000005, fffff80644579eb0, ffffe4002cfef4e8, ffffe4002cfeed10}

Probably caused by : atikmdag.sys ( atikmdag+239eb0 )

Followup: MachineOwner
---------

Processing initial command '!analyze -v; lmtsmn; !sysinfo smbios; !sysinfo machineid; !sysinfo cpuspeed; !sysinfo cpuinfo; !thread; .bugcheck; .time;'
5: kd> !analyze -v; lmtsmn; !sysinfo smbios; !sysinfo machineid; !sysinfo cpuspeed; !sysinfo cpuinfo; !thread; .bugcheck; .time;
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff80644579eb0, The address that the exception occurred at
Arg3: ffffe4002cfef4e8, Exception Record Address
Arg4: ffffe4002cfeed10, Context Record Address

Debugging Details:
------------------

DUMP_CLASS: 1

DUMP_QUALIFIER: 400

BUILD_VERSION_STRING: 10.0.14393.447 (rs1_release_inmarket.161102-0100)

SYSTEM_MANUFACTURER: ECT

SYSTEM_SKU: To be filled by O.E.M.

BIOS_VENDOR: American Megatrends Inc.

BIOS_VERSION: V17.0

BIOS_DATE: 04/16/2014

BASEBOARD_MANUFACTURER: MSI

BASEBOARD_PRODUCT: Z97-G43 (MS-7816)

BASEBOARD_VERSION: 3.0

DUMP_TYPE: 2

BUGCHECK_P1: ffffffffc0000005

BUGCHECK_P2: fffff80644579eb0

BUGCHECK_P3: ffffe4002cfef4e8

BUGCHECK_P4: ffffe4002cfeed10

EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.

FAULTING_IP:
atikmdag+239eb0
fffff806`44579eb0 8b4108 mov eax,dword ptr [rcx+8]

EXCEPTION_RECORD: ffffe4002cfef4e8 -- (.exr 0xffffe4002cfef4e8)
ExceptionAddress: fffff80644579eb0 (atikmdag+0x0000000000239eb0)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff

CONTEXT: ffffe4002cfeed10 -- (.cxr 0xffffe4002cfeed10)
rax=ffffcd8d472ddb80 rbx=fdff9d005c734010 rcx=fdff9d005c734010
rdx=ffffe4002cfef7f0 rsi=ffff9d005c734170 rdi=ffffcd8d423596e0
rip=fffff80644579eb0 rsp=ffffe4002cfef728 rbp=0000000000000000
r8=00000000000007ff r9=fffff8015501e000 r10=ffffe40021440000
r11=ffffcd8d472ddb80 r12=0000000000000000 r13=ffffcd8d47a72280
r14=ffffe4002cfef850 r15=ffffcd8d417d0310
iopl=0 nv up ei ng nz na pe nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010282
atikmdag+0x239eb0:
fffff806`44579eb0 8b4108 mov eax,dword ptr [rcx+8] ds:002b:fdff9d00`5c734018=????????
Resetting default scope

CPU_COUNT: 8

CPU_MHZ: e10

CPU_VENDOR: GenuineIntel

CPU_FAMILY: 6

CPU_MODEL: 3c

CPU_STEPPING: 3

CPU_MICROCODE: 6,3c,3,0 (F,M,S,R) SIG: 1E'00000000 (cache) 1E'00000000 (init)

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT

PROCESS_NAME: Dishonored.exe

CURRENT_IRQL: 0

ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.

EXCEPTION_CODE_STR: c0000005

EXCEPTION_PARAMETER1: 0000000000000000

EXCEPTION_PARAMETER2: ffffffffffffffff

FOLLOWUP_IP:
atikmdag+239eb0
fffff806`44579eb0 8b4108 mov eax,dword ptr [rcx+8]

READ_ADDRESS: fffff801553c5338: Unable to get MiVisibleState
ffffffffffffffff

BUGCHECK_STR: AV

ANALYSIS_SESSION_HOST: MARTIJN

ANALYSIS_SESSION_TIME: 12-30-2016 12:04:21.0342

ANALYSIS_VERSION: 10.0.14321.1024 amd64fre

LAST_CONTROL_TRANSFER: from fffff806444276ef to fffff80644579eb0

STACK_TEXT:
ffffe400`2cfef728 fffff806`444276ef : fffff801`55357540 ffffe400`21440000 fffff801`55357540 00000000`00000080 : atikmdag+0x239eb0
ffffe400`2cfef730 fffff801`55357540 : ffffe400`21440000 fffff801`55357540 00000000`00000080 ffffcd8d`475cc800 : atikmdag+0xe76ef
ffffe400`2cfef738 ffffe400`21440000 : fffff801`55357540 00000000`00000080 ffffcd8d`475cc800 fffff806`44415ff2 : nt!NonPagedPoolDescriptor
ffffe400`2cfef740 fffff801`55357540 : 00000000`00000080 ffffcd8d`475cc800 fffff806`44415ff2 00000000`00000008 : 0xffffe400`21440000
ffffe400`2cfef748 00000000`00000080 : ffffcd8d`475cc800 fffff806`44415ff2 00000000`00000008 fffff801`00000290 : nt!NonPagedPoolDescriptor
ffffe400`2cfef750 ffffcd8d`475cc800 : fffff806`44415ff2 00000000`00000008 fffff801`00000290 fffff801`55357540 : 0x80
ffffe400`2cfef758 fffff806`44415ff2 : 00000000`00000008 fffff801`00000290 fffff801`55357540 00000000`00000000 : 0xffffcd8d`475cc800
ffffe400`2cfef760 00000000`00000008 : fffff801`00000290 fffff801`55357540 00000000`00000000 00000000`00000000 : atikmdag+0xd5ff2
ffffe400`2cfef768 fffff801`00000290 : fffff801`55357540 00000000`00000000 00000000`00000000 00000000`c0000001 : 0x8
ffffe400`2cfef770 fffff801`55357540 : 00000000`00000000 00000000`00000000 00000000`c0000001 ffffe400`2cfef7f0 : 0xfffff801`00000290
ffffe400`2cfef778 00000000`00000000 : 00000000`00000000 00000000`c0000001 ffffe400`2cfef7f0 fffff806`443d10f5 : nt!NonPagedPoolDescriptor

THREAD_SHA1_HASH_MOD_FUNC: 862cbb9555593bc8f6f29895eee07ae8ce837dc4

THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 2d5497f9c71b0f53a5a684fc73954f8b03c74cf2

THREAD_SHA1_HASH_MOD: 33160c9fac6c9c4982d5fcf334d79377da7ec981

FAULT_INSTR_CODE: c308418b

SYMBOL_STACK_INDEX: 0

SYMBOL_NAME: atikmdag+239eb0

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: atikmdag

IMAGE_NAME: atikmdag.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 5844449b

STACK_COMMAND: .cxr 0xffffe4002cfeed10 ; kb

BUCKET_ID_FUNC_OFFSET: 239eb0

FAILURE_BUCKET_ID: AV_atikmdag!unknown_function

BUCKET_ID: AV_atikmdag!unknown_function

PRIMARY_PROBLEM_CLASS: AV_atikmdag!unknown_function

TARGET_TIME: 2016-12-20T13:00:33.000Z

OSBUILD: 14393

OSSERVICEPACK: 447

SERVICEPACK_NUMBER: 0

OS_REVISION: 0

SUITE_MASK: 784

PRODUCT_TYPE: 1

OSPLATFORM_TYPE: x64

OSNAME: Windows 10

OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS Personal

OS_LOCALE:

USER_LCID: 0

OSBUILD_TIMESTAMP: 2016-11-02 11:17:03

BUILDDATESTAMP_STR: 161102-0100

BUILDLAB_STR: rs1_release_inmarket

BUILDOSVER_STR: 10.0.14393.447

ANALYSIS_SESSION_ELAPSED_TIME: 4725

ANALYSIS_SOURCE: KM

FAILURE_ID_HASH_STRING: km:av_atikmdag!unknown_function

FAILURE_ID_HASH: {0252e3ed-fc29-a2ca-0f7a-b32a5492113a}

Followup: MachineOwner
---------

start end module name
fffff806`3f480000 fffff806`3f533000 ACPI ACPI.sys Sat Jul 16 04:10:47 2016 (578997A7)
fffff806`3f440000 fffff806`3f463000 acpiex acpiex.sys Sat Jul 16 04:28:23 2016 (57899BC7)
fffff806`45ff0000 fffff806`45ffb000 acpipagr acpipagr.sys Sat Jul 16 04:29:00 2016 (57899BEC)
fffff806`418e0000 fffff806`41975000 afd afd.sys Sat Oct 15 05:53:45 2016 (5801A849)
fffff806`41b50000 fffff806`41b8f000 ahcache ahcache.sys Sat Oct 15 05:31:36 2016 (5801A318)
fffff806`3f940000 fffff806`3f98c000 amdacpksd amdacpksd.sys Wed Jul 6 04:29:03 2016 (577C6CEF)
fffff806`40480000 fffff806`40493000 amdkmpfd amdkmpfd.sys Tue Oct 28 00:26:38 2014 (544ED4AE)
fffff806`41d50000 fffff806`41d6e000 AtihdWT6 AtihdWT6.sys Wed Sep 21 01:17:24 2016 (57E1C384)
fffff806`44340000 fffff806`45edb000 atikmdag atikmdag.sys Sun Dec 4 17:30:19 2016 (5844449B)
fffff806`41be0000 fffff806`41c63000 atikmpag atikmpag.sys Sun Dec 4 17:07:30 2016 (58443F42)
fffff806`42380000 fffff806`423ab000 avgntflt avgntflt.sys Mon Oct 17 15:02:38 2016 (5804CBEE)
fffff806`41a00000 fffff806`41a29000 avipbb avipbb.sys Mon Oct 17 11:01:27 2016 (58049367)
fffff806`419f0000 fffff806`419fb000 avkmgr avkmgr.sys Tue Oct 20 15:16:43 2015 (56263EBB)
fffff806`3f990000 fffff806`3f9a4000 avnetflt avnetflt.sys Wed Mar 23 21:46:57 2016 (56F300C1)
fffff806`415a0000 fffff806`415b4000 BasicDisplay BasicDisplay.sys Sat Jul 16 04:28:02 2016 (57899BB2)
fffff806`41800000 fffff806`41812000 BasicRender BasicRender.sys Sat Jul 16 04:28:14 2016 (57899BBE)
fffff806`41590000 fffff806`4159a000 Beep Beep.SYS Sat Jul 16 04:22:02 2016 (57899A4A)
fffff806`3f020000 fffff806`3f02c000 BOOTVID BOOTVID.dll Sat Jul 16 04:10:37 2016 (5789979D)
fffff806`407a0000 fffff806`407c2000 bowser bowser.sys Wed Nov 2 11:23:23 2016 (5819BE9B)
fffff4c5`14f90000 fffff4c5`14fd0000 cdd cdd.dll Sat Oct 15 05:56:14 2016 (5801A8DE)
fffff806`41510000 fffff806`41541000 cdrom cdrom.sys Sat Jul 16 04:10:42 2016 (578997A2)
fffff806`3f680000 fffff806`3f699000 CEA CEA.sys Sat Jul 16 04:28:38 2016 (57899BD6)
fffff806`3f200000 fffff806`3f2a0000 CI CI.dll Thu Sep 15 18:40:08 2016 (57DACEE8)
fffff806`405e0000 fffff806`40642000 CLASSPNP CLASSPNP.SYS Wed Sep 7 06:33:32 2016 (57CF989C)
fffff806`3fb50000 fffff806`3fbb3000 CLFS CLFS.SYS Wed Nov 2 11:12:36 2016 (5819BC14)
fffff806`3f130000 fffff806`3f1e0000 clipsp clipsp.sys Wed Sep 7 06:57:27 2016 (57CF9E37)
fffff806`3f1e0000 fffff806`3f1ed000 cmimcext cmimcext.sys Thu Sep 15 18:15:09 2016 (57DAC90D)
fffff806`3f2a0000 fffff806`3f33c000 cng cng.sys Sat Aug 6 05:38:01 2016 (57A55B99)
fffff806`41b90000 fffff806`41ba1000 CompositeBus CompositeBus.sys Sat Jul 16 04:20:11 2016 (578999DB)
fffff806`46150000 fffff806`46162000 condrv condrv.sys Sat Jul 16 04:10:38 2016 (5789979E)
fffff806`40670000 fffff806`40689000 crashdmp crashdmp.sys Sat Oct 15 05:46:27 2016 (5801A693)
fffff806`42fd0000 fffff806`42fe7000 dc1_controller dc1-controller.sys Sat Jul 16 04:28:18 2016 (57899BC2)
fffff806`422b0000 fffff806`422c3000 DevAuthE DevAuthE.sys Sat Jul 16 04:29:16 2016 (57899BFC)
fffff806`41b00000 fffff806`41b2a000 dfsc dfsc.sys Wed Oct 5 11:34:11 2016 (57F4C913)
fffff806`405c0000 fffff806`405de000 disk disk.sys Sat Jul 16 04:10:52 2016 (578997AC)
fffff806`45f80000 fffff806`45fa1000 drmk drmk.sys Sat Jul 16 04:27:13 2016 (57899B81)
fffff806`42ec0000 fffff806`42ecf000 dump_diskdump dump_diskdump.sys Sat Jul 16 04:21:57 2016 (57899A45)
fffff806`42ef0000 fffff806`42f0d000 dump_dumpfve dump_dumpfve.sys Sat Jul 16 04:27:46 2016 (57899BA2)
fffff806`41e10000 fffff806`420d3000 dump_iaStorA dump_iaStorA.sys Fri Apr 4 01:00:05 2014 (533DE7F5)
fffff806`415e0000 fffff806`417fe000 dxgkrnl dxgkrnl.sys Sat Oct 15 05:36:30 2016 (5801A43E)
fffff806`420e0000 fffff806`42187000 dxgmms2 dxgmms2.sys Sat Oct 15 05:53:08 2016 (5801A824)
fffff806`3fc00000 fffff806`3fc1c000 EhStorClass EhStorClass.sys Sat Jul 16 04:18:35 2016 (5789997B)
fffff806`41550000 fffff806`4156d000 filecrypt filecrypt.sys Sat Jul 16 04:22:39 2016 (57899A6F)
fffff806`3fc20000 fffff806`3fc39000 fileinfo fileinfo.sys Sat Jul 16 04:26:05 2016 (57899B3D)
fffff806`3f030000 fffff806`3f092000 FLTMGR FLTMGR.SYS Sat Jul 16 04:10:45 2016 (578997A5)
fffff806`3fec0000 fffff806`3fecd000 Fs_Rec Fs_Rec.sys Sat Jul 16 04:10:37 2016 (5789979D)
fffff806`403d0000 fffff806`40473000 fvevol fvevol.sys Thu Sep 15 18:36:20 2016 (57DACE04)
fffff806`40330000 fffff806`40399000 fwpkclnt fwpkclnt.sys Sat Oct 15 05:53:56 2016 (5801A854)
fffff806`41af0000 fffff806`41afa000 gpuenergydrv gpuenergydrv.sys Sat Jul 16 04:28:09 2016 (57899BB9)
fffff801`5583e000 fffff801`558b3000 hal hal.dll Thu Sep 15 18:15:22 2016 (57DAC91A)
fffff806`45ef0000 fffff806`45f0b000 HDAudBus HDAudBus.sys Sat Jul 16 04:27:11 2016 (57899B7F)
fffff806`42f60000 fffff806`42f8f000 HIDCLASS HIDCLASS.SYS Sat Oct 15 05:55:48 2016 (5801A8C4)
fffff806`42e90000 fffff806`42ea2000 HIDPARSE HIDPARSE.SYS Sat Aug 6 05:46:37 2016 (57A55D9D)
fffff806`42f40000 fffff806`42f51000 hidusb hidusb.sys Sat Aug 6 05:47:49 2016 (57A55DE5)
fffff806`3f800000 fffff806`3f912000 HTTP HTTP.sys Sat Oct 15 05:41:03 2016 (5801A54F)
fffff806`40890000 fffff806`40b53000 iaStorA iaStorA.sys Fri Apr 4 01:00:05 2014 (533DE7F5)
fffff806`3f550000 fffff806`3f561000 intelpep intelpep.sys Sat Jul 16 04:18:27 2016 (57899973)
fffff806`45fc0000 fffff806`45feb000 intelppm intelppm.sys Sat Jul 16 04:10:43 2016 (578997A3)
fffff806`405a0000 fffff806`405b0000 iorate iorate.sys Wed Nov 2 11:12:31 2016 (5819BC0F)
fffff806`41c70000 fffff806`41c80000 ISCTD64 ISCTD64.sys Tue Aug 23 19:32:39 2011 (4E53E437)
fffff806`42fa0000 fffff806`42fb3000 kbdclass kbdclass.sys Sat Jul 16 04:26:27 2016 (57899B53)
fffff806`42f90000 fffff806`42fa0000 kbdhid kbdhid.sys Thu Sep 15 18:43:23 2016 (57DACFAB)
fffff801`53d90000 fffff801`53d9b000 kd kd.dll Sat Jul 16 04:29:16 2016 (57899BFC)
fffff806`41bb0000 fffff806`41bbe000 kdnic kdnic.sys Sat Jul 16 04:28:28 2016 (57899BCC)
fffff806`44000000 fffff806`44068000 ks ks.sys Sat Jul 16 04:24:18 2016 (57899AD2)
fffff806`3f100000 fffff806`3f128000 ksecdd ksecdd.sys Wed Sep 7 07:00:34 2016 (57CF9EF2)
fffff806`40080000 fffff806`400b0000 ksecpkg ksecpkg.sys Sat Aug 6 05:44:30 2016 (57A55D1E)
fffff806`41d70000 fffff806`41d7e000 ksthunk ksthunk.sys Sat Jul 16 04:28:56 2016 (57899BE8)
fffff806`41ca0000 fffff806`41ca3d80 LGBusEnum LGBusEnum.sys Tue Nov 24 02:36:48 2009 (4B0B38B0)
fffff806`422d0000 fffff806`422e5000 LGSHidFilt LGSHidFilt.Sys Thu May 30 17:16:33 2013 (51A76D51)
fffff806`46140000 fffff806`46142480 LGVirHid LGVirHid.sys Tue Nov 24 02:36:48 2009 (4B0B38B0)
fffff806`414d0000 fffff806`414e6000 lltdio lltdio.sys Sat Jul 16 04:27:11 2016 (57899B7F)
fffff806`42330000 fffff806`42356000 luafv luafv.sys Sat Jul 16 04:21:48 2016 (57899A3C)
fffff806`3fab0000 fffff806`3fb3e000 mcupdate_GenuineIntel mcupdate_GenuineIntel.dll Sat Jul 16 04:28:05 2016 (57899BB5)
fffff806`46da0000 fffff806`46db4000 mmcss mmcss.sys Sat Jul 16 04:20:45 2016 (578999FD)
fffff806`42fc0000 fffff806`42fd0000 monitor monitor.sys Sat Jul 16 04:28:26 2016 (57899BCA)
fffff806`422f0000 fffff806`42302000 mouclass mouclass.sys Sat Jul 16 04:26:40 2016 (57899B60)
fffff806`42ff0000 fffff806`42fff000 mouhid mouhid.sys Sat Jul 16 04:27:35 2016 (57899B97)
fffff806`3f7e0000 fffff806`3f7fe000 mountmgr mountmgr.sys Sat Jul 16 04:10:42 2016 (578997A2)
fffff806`40690000 fffff806`406a9000 mpsdrv mpsdrv.sys Sat Jul 16 04:27:16 2016 (57899B84)
fffff806`407d0000 fffff806`40845000 mrxsmb mrxsmb.sys Wed Sep 7 06:48:56 2016 (57CF9C38)
fffff806`46030000 fffff806`4607d000 mrxsmb10 mrxsmb10.sys Wed Sep 7 06:50:18 2016 (57CF9C8A)
fffff806`40850000 fffff806`4088b000 mrxsmb20 mrxsmb20.sys Thu Sep 15 18:30:52 2016 (57DACCBC)
fffff806`41840000 fffff806`41850000 Msfs Msfs.SYS Sat Jul 16 04:10:38 2016 (5789979E)
fffff806`3f5c0000 fffff806`3f5cb000 msisadrv msisadrv.sys Sat Jul 16 04:28:51 2016 (57899BE3)
fffff806`414f0000 fffff806`41508000 mslldp mslldp.sys Sat Jul 16 04:28:24 2016 (57899BC8)
fffff806`3f0a0000 fffff806`3f0fd000 msrpc msrpc.sys Sat Jul 16 04:23:06 2016 (57899A8A)
fffff806`41ae0000 fffff806`41af0000 mssmbios mssmbios.sys Sat Jul 16 04:26:00 2016 (57899B38)
fffff806`40570000 fffff806`40595000 mup mup.sys Sat Jul 16 04:11:22 2016 (578997CA)
fffff806`3fed0000 fffff806`3fff8000 ndis ndis.sys Wed Oct 5 11:19:09 2016 (57F4C58D)
fffff806`406d0000 fffff806`406e6000 ndisuio ndisuio.sys Sat Jul 16 04:26:32 2016 (57899B58)
fffff806`41c80000 fffff806`41c8d000 NdisVirtualBus NdisVirtualBus.sys Sat Jul 16 04:26:32 2016 (57899B58)
fffff806`46000000 fffff806`46026000 Ndu Ndu.sys Sat Jul 16 04:26:12 2016 (57899B44)
fffff806`419d0000 fffff806`419e2000 netbios netbios.sys Sat Jul 16 04:27:18 2016 (57899B86)
fffff806`41890000 fffff806`418db000 netbt netbt.sys Sat Jul 16 04:25:07 2016 (57899B03)
fffff806`40000000 fffff806`40079000 NETIO NETIO.SYS Sat Jul 16 04:26:08 2016 (57899B40)
fffff806`41820000 fffff806`41839000 Npfs Npfs.SYS Sat Jul 16 04:10:38 2016 (5789979E)
fffff806`41ad0000 fffff806`41add000 npsvctrig npsvctrig.sys Sat Jul 16 04:28:33 2016 (57899BD1)
fffff806`41ab0000 fffff806`41ac1000 nsiproxy nsiproxy.sys Sat Jul 16 04:26:45 2016 (57899B65)
fffff801`5501e000 fffff801`5583e000 nt ntkrnlmp.exe Wed Nov 2 11:17:03 2016 (5819BD1F)
fffff806`3fc80000 fffff806`3feb2000 NTFS NTFS.sys Wed Nov 2 11:15:32 2016 (5819BCC4)
fffff806`3f1f0000 fffff806`3f1fc000 ntosext ntosext.sys Sat Jul 16 04:10:37 2016 (5789979D)
fffff806`41580000 fffff806`4158a000 Null Null.SYS Sat Jul 16 04:10:37 2016 (5789979D)
fffff806`406f0000 fffff806`40779000 nwifi nwifi.sys Sat Jul 16 04:25:03 2016 (57899AFF)
fffff806`419a0000 fffff806`419cb000 pacer pacer.sys Sat Jul 16 04:25:21 2016 (57899B11)
fffff806`3f6a0000 fffff806`3f6c4000 partmgr partmgr.sys Thu Sep 15 18:15:19 2016 (57DAC917)
fffff806`3f5d0000 fffff806`3f627000 pci pci.sys Sat Oct 15 05:49:22 2016 (5801A742)
fffff806`3f5a0000 fffff806`3f5b2000 pcw pcw.sys Sat Jul 16 04:10:37 2016 (5789979D)
fffff806`3f650000 fffff806`3f671000 pdc pdc.sys Sat Aug 20 06:51:30 2016 (57B7E1D2)
fffff806`46cd0000 fffff806`46d92000 peauth peauth.sys Sat Jul 16 04:24:39 2016 (57899AE7)
fffff806`45f10000 fffff806`45f71000 portcls portcls.sys Sat Jul 16 04:25:10 2016 (57899B06)
fffff806`3f000000 fffff806`3f017000 PSHED PSHED.dll Sat Jul 16 04:10:44 2016 (578997A4)
fffff806`41a30000 fffff806`41aa5000 rdbss rdbss.sys Thu Sep 15 18:23:45 2016 (57DACB11)
fffff806`41cb0000 fffff806`41cbe000 rdpbus rdpbus.sys Sat Jul 16 04:11:15 2016 (578997C3)
fffff806`46170000 fffff806`4617d000 rdpvideominiport rdpvideominiport.sys Sat Jul 16 04:11:10 2016 (578997BE)
fffff806`40520000 fffff806`40568000 rdyboost rdyboost.sys Sat Jul 16 04:25:16 2016 (57899B0C)
fffff806`423d0000 fffff806`423e8000 registry registry.sys Sat Jul 16 04:27:04 2016 (57899B78)
fffff806`41b30000 fffff806`41b4a000 rspndr rspndr.sys Sat Jul 16 04:27:29 2016 (57899B91)
fffff806`441f0000 fffff806`44284000 rt640x64 rt640x64.sys Thu Jan 21 09:17:40 2016 (56A09424)
fffff806`42a00000 fffff806`42e82000 RTKVHD64 RTKVHD64.sys Tue Jun 16 12:55:05 2015 (55800089)
fffff806`44290000 fffff806`44339000 rtl819xp rtl819xp.sys Mon Apr 8 05:00:34 2013 (516232D2)
fffff806`3f6d0000 fffff806`3f75d000 spaceport spaceport.sys Sat Oct 15 05:46:37 2016 (5801A69D)
fffff806`46080000 fffff806`4610c000 srv srv.sys Wed Sep 7 06:49:09 2016 (57CF9C45)
fffff806`46c10000 fffff806`46cc4000 srv2 srv2.sys Thu Sep 15 18:30:41 2016 (57DACCB1)
fffff806`3f9b0000 fffff806`3f9f4000 srvnet srvnet.sys Wed Sep 7 06:45:09 2016 (57CF9B55)
fffff806`40b60000 fffff806`40be2000 storport storport.sys Sat Oct 15 05:45:16 2016 (5801A64C)
fffff806`42360000 fffff806`42379000 storqosflt storqosflt.sys Sat Jul 16 04:26:43 2016 (57899B63)
fffff806`41c90000 fffff806`41c9c000 swenum swenum.sys Sat Jul 16 04:28:55 2016 (57899BE7)
fffff806`41570000 fffff806`4157e000 tbs tbs.sys Sat Jul 16 04:27:47 2016 (57899BA3)
fffff806`400b0000 fffff806`40328000 tcpip tcpip.sys Sat Oct 15 05:32:46 2016 (5801A35E)
fffff806`46dc0000 fffff806`46dd4000 tcpipreg tcpipreg.sys Sat Jul 16 04:25:32 2016 (57899B1C)
fffff806`41880000 fffff806`41890000 TDI TDI.SYS Sat Jul 16 04:28:10 2016 (57899BBA)
fffff806`41850000 fffff806`41873000 tdx tdx.sys Sat Jul 16 04:27:16 2016 (57899B84)
fffff806`44120000 fffff806`44143000 TeeDriverx64 TeeDriverx64.sys Tue Sep 23 22:01:14 2014 (5421D18A)
fffff806`3fbc0000 fffff806`3fbe5000 tm tm.sys Wed Oct 5 11:11:00 2016 (57F4C3A4)
fffff4c5`14f20000 fffff4c5`14f2a000 TSDDD TSDDD.dll unavailable (00000000)
fffff806`46110000 fffff806`4613f000 tunnel tunnel.sys Sat Jul 16 04:26:20 2016 (57899B4C)
fffff806`440e0000 fffff806`44118000 ucx01000 ucx01000.sys Sat Jul 16 04:25:10 2016 (57899B06)
fffff806`41bc0000 fffff806`41bd5000 umbus umbus.sys Sat Jul 16 04:22:33 2016 (57899A69)
fffff806`42f10000 fffff806`42f40000 usbccgp usbccgp.sys Sat Jul 16 04:28:03 2016 (57899BB3)
fffff806`41d40000 fffff806`41d4e000 USBD USBD.SYS Sat Jul 16 04:28:27 2016 (57899BCB)
fffff806`44150000 fffff806`4416c000 usbehci usbehci.sys Sat Jul 16 04:23:07 2016 (57899A8B)
fffff806`41cc0000 fffff806`41d40000 usbhub usbhub.sys Sat Jul 16 04:18:19 2016 (5789996B)
fffff806`41d80000 fffff806`41e07000 UsbHub3 UsbHub3.sys Sat Jul 16 04:18:54 2016 (5789998E)
fffff806`44170000 fffff806`441e6000 USBPORT USBPORT.SYS Sat Jul 16 04:23:09 2016 (57899A8D)
fffff806`44070000 fffff806`440d3000 USBXHCI USBXHCI.SYS Sat Jul 16 04:20:30 2016 (578999EE)
fffff806`3f630000 fffff806`3f642000 vdrvroot vdrvroot.sys Sat Jul 16 04:25:58 2016 (57899B36)
fffff806`3f760000 fffff806`3f778000 volmgr volmgr.sys Sat Jul 16 04:10:43 2016 (578997A3)
fffff806`3f780000 fffff806`3f7de000 volmgrx volmgrx.sys Sat Jul 16 04:10:45 2016 (578997A5)
fffff806`404b0000 fffff806`40514000 volsnap volsnap.sys Sat Jul 16 04:10:44 2016 (578997A4)
fffff806`404a0000 fffff806`404ab000 volume volume.sys Sat Jul 16 04:10:37 2016 (5789979D)
fffff806`45ee0000 fffff806`45eee000 vwifibus vwifibus.sys Sat Jul 16 04:27:29 2016 (57899B91)
fffff806`41980000 fffff806`41999000 vwififlt vwififlt.sys Sat Jul 16 04:28:07 2016 (57899BB7)
fffff806`406b0000 fffff806`406cb000 wanarp wanarp.sys Sat Jul 16 04:28:56 2016 (57899BE8)
fffff806`415c0000 fffff806`415d4000 watchdog watchdog.sys Sat Jul 16 04:27:39 2016 (57899B9B)
fffff806`42310000 fffff806`42330000 wcifs wcifs.sys Thu Sep 15 18:42:03 2016 (57DACF5B)
fffff806`423b0000 fffff806`423c6000 wcnfs wcnfs.sys Sat Jul 16 04:28:27 2016 (57899BCB)
fffff806`3f340000 fffff806`3f414000 Wdf01000 Wdf01000.sys Sat Jul 16 04:13:12 2016 (57899838)
fffff806`3f420000 fffff806`3f433000 WDFLDR WDFLDR.SYS Sat Jul 16 04:10:39 2016 (5789979F)
fffff806`3fb40000 fffff806`3fb50000 werkernel werkernel.sys Sat Jul 16 04:28:51 2016 (57899BE3)
fffff806`403a0000 fffff806`403ca000 wfplwfs wfplwfs.sys Sat Jul 16 04:25:57 2016 (57899B35)
fffff4c5`15310000 fffff4c5`1534b000 win32k win32k.sys Wed Nov 2 11:33:56 2016 (5819C114)
fffff4c5`14d90000 fffff4c5`14f10000 win32kbase win32kbase.sys Wed Nov 2 11:14:58 2016 (5819BCA2)
fffff4c5`14a00000 fffff4c5`14d88000 win32kfull win32kfull.sys Wed Nov 2 11:15:17 2016 (5819BCB5)
fffff806`3f570000 fffff806`3f58f000 WindowsTrustedRT WindowsTrustedRT.sys Sat Jul 16 04:27:05 2016 (57899B79)
fffff806`3f590000 fffff806`3f59b000 WindowsTrustedRTProxy WindowsTrustedRTProxy.sys Sat Jul 16 04:27:05 2016 (57899B79)
fffff806`45fb0000 fffff806`45fbc000 wmiacpi wmiacpi.sys Sat Jul 16 04:18:19 2016 (5789996B)
fffff806`3f540000 fffff806`3f54c000 WMILIB WMILIB.SYS Sat Jul 16 04:10:37 2016 (5789979D)
fffff806`3fc40000 fffff806`3fc78000 Wof Wof.sys Sat Aug 6 05:45:24 2016 (57A55D54)
fffff806`3f470000 fffff806`3f47e000 WppRecorder WppRecorder.sys Sat Jul 16 04:29:12 2016 (57899BF8)
fffff806`40780000 fffff806`4079e000 WudfPf WudfPf.sys Sat Jul 16 04:26:10 2016 (57899B42)
fffff806`42190000 fffff806`422aa000 xboxgip xboxgip.sys Sat Oct 15 05:58:34 2016 (5801A96A)
fffff806`46480000 fffff806`46493000 xinputhid xinputhid.sys Sat Aug 20 07:20:50 2016 (57B7E8B2)

Unloaded modules:
fffff806`3f920000 fffff806`3f933000 xinputhid.sy
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 00013000
fffff806`46180000 fffff806`4618f000 hiber_storpo
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0000F000
fffff806`46190000 fffff806`46453000 hiber_iaStor
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 002C3000
fffff806`46460000 fffff806`4647d000 hiber_dumpfv
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0001D000
fffff806`406a0000 fffff806`406af000 dump_storpor
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0000F000
fffff806`41200000 fffff806`414c3000 dump_iaStorA
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 002C3000
fffff806`414f0000 fffff806`4150d000 dump_dumpfve
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0001D000
fffff806`45ee0000 fffff806`45eea000 amdkmafd.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0000A000
fffff806`41b30000 fffff806`41b44000 dam.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 00014000
fffff806`405b0000 fffff806`405bf000 hwpolicy.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
ImageSize: 0000F000
[SMBIOS Data Tables v2.8]
[DMI Version - 0]
[2.0 Calling Convention - No]
[Table Size - 2948 bytes]

[BIOS Information (Type 0) - Length 24 - Handle 0000h]
Vendor American Megatrends Inc.
BIOS Version V17.0
BIOS Starting Address Segment f000
BIOS Release Date 04/16/2014
BIOS ROM Size 800000
BIOS Characteristics
07: - PCI Supported
11: - Upgradeable FLASH BIOS
12: - BIOS Shadowing Supported
15: - CD-Boot Supported
16: - Selectable Boot Supported
17: - BIOS ROM Socketed
19: - EDD Supported
23: - 1.2MB Floppy Supported
24: - 720KB Floppy Supported
25: - 2.88MB Floppy Supported
26: - Print Screen Device Supported
27: - Keyboard Services Supported
28: - Serial Services Supported
29: - Printer Services Supported
32: - BIOS Vendor Reserved
BIOS Characteristic Extensions
00: - ACPI Supported
01: - USB Legacy Supported
08: - BIOS Boot Specification Supported
10: - Specification Reserved
11: - Specification Reserved
BIOS Major Revision 4
BIOS Minor Revision 6
EC Firmware Major Revision 255
EC Firmware Minor Revision 255
[System Information (Type 1) - Length 27 - Handle 0001h]
Manufacturer ECT
Product Name
Version
Serial Number 1467308
UUID 00000000-0000-0000-0000-000000000000
Wakeup Type Power Switch
SKUNumber To be filled by O.E.M.
Family To be filled by O.E.M.
[BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
Manufacturer MSI
Product Z97-G43 (MS-7816)
Version 3.0
Serial Number To be filled by O.E.M.
Asset Tag
Feature Flags 09h
-93931808: - -93931760: - §'©-ù
Location To be filled by O.E.M.
Chassis Handle 0003h
Board Type 0ah - Processor/Memory Module
Number of Child Handles 0
[System Enclosure (Type 3) - Length 25 - Handle 0003h]
Manufacturer MSI
Chassis Type Desktop
Version 3.0
Serial Number
Asset Tag Number
Bootup State Safe
Power Supply State Safe
Thermal State Safe
Security Status None
OEM Defined 0
Height 0U
Number of Power Cords 1
Number of Contained Elements 1
Contained Element Size 3
[OEM Strings (Type 11) - Length 5 - Handle 0021h]
Number of Strings 1
1 To Be Filled By O.E.M.
[System Configuration Options (Type 12) - Length 5 - Handle 0022h]
[Processor Information (Type 4) - Length 42 - Handle 003dh]
Socket Designation SOCKET 0
Processor Type Central Processor
Processor Family c6h - Specification Reserved
Processor Manufacturer Intel
Processor ID c3060300fffbebbf
Processor Version Intel(R) Core(TM) i7-4790 CPU @ 3.60GHz
Processor Voltage 8ch - 1.2V
External Clock 100MHz
Max Speed 3800MHz
Current Speed 3600MHz
Status Enabled Populated
Processor Upgrade Specification Reserved
L1 Cache Handle 003eh
L2 Cache Handle 003fh
L3 Cache Handle 0040h
Serial Number [String Not Specified]
Asset Tag Number
Part Number Fill By OEM
[Cache Information (Type 7) - Length 19 - Handle 003eh]
Socket Designation CPU Internal L1
Cache Configuration 0180h - WB Enabled Int NonSocketed L1
Maximum Cache Size 0100h - 256K
Installed Size 0100h - 256K
Supported SRAM Type 0020h - Synchronous
Current SRAM Type 0020h - Synchronous
Cache Speed 0ns
Error Correction Type ParitySingle-Bit ECC
System Cache Type Other
Associativity 8-way Set-Associative
[Cache Information (Type 7) - Length 19 - Handle 003fh]
Socket Designation CPU Internal L2
Cache Configuration 0181h - WB Enabled Int NonSocketed L2
Maximum Cache Size 0400h - 1024K
Installed Size 0400h - 1024K
Supported SRAM Type 0020h - Synchronous
Current SRAM Type 0020h - Synchronous
Cache Speed 0ns
Error Correction Type Multi-Bit ECC
System Cache Type Unified
Associativity 8-way Set-Associative
[Cache Information (Type 7) - Length 19 - Handle 0040h]
Socket Designation CPU Internal L3
Cache Configuration 0182h - WB Enabled Int NonSocketed L3
Maximum Cache Size 2000h - 8192K
Installed Size 2000h - 8192K
Supported SRAM Type 0020h - Synchronous
Current SRAM Type 0020h - Synchronous
Cache Speed 0ns
Error Correction Type Specification Reserved
System Cache Type Unified
Associativity 16-way Set-Associative
[Physical Memory Array (Type 16) - Length 23 - Handle 0042h]
Location 03h - SystemBoard/Motherboard
Use 03h - System Memory
Memory Error Correction 03h - None
Maximum Capacity 33554432KB
Memory Error Inf Handle [Not Provided]
Number of Memory Devices 4
[Memory Device (Type 17) - Length 40 - Handle 0043h]
Physical Memory Array Handle 0042h
Memory Error Info Handle [Not Provided]
Total Width 0 bits
Data Width 0 bits
Size [Not Populated]
Form Factor 09h - DIMM
Device Set [None]
Device Locator ChannelA-DIMM0
Bank Locator BANK 0
Memory Type 02h - Unknown
Type Detail 0000h -
Speed 0MHz
Manufacturer [Empty]
Serial Number
Asset Tag Number [String Not Specified]
Part Number [Empty]
[Memory Device (Type 17) - Length 40 - Handle 0044h]
Physical Memory Array Handle 0042h
Memory Error Info Handle [Not Provided]
Total Width 64 bits
Data Width 64 bits
Size 8192MB
Form Factor 09h - DIMM
Device Set [None]
Device Locator ChannelA-DIMM1
Bank Locator BANK 1
Memory Type 18h - Specification Reserved
Type Detail 0080h - Synchronous
Speed 1600MHz
Manufacturer 1315
Serial Number
Asset Tag Number
Part Number BLS8G3D1609DS1S00.
[Memory Device (Type 17) - Length 40 - Handle 0045h]
Physical Memory Array Handle 0042h
Memory Error Info Handle [Not Provided]
Total Width 0 bits
Data Width 0 bits
Size [Not Populated]
Form Factor 09h - DIMM
Device Set [None]
Device Locator ChannelB-DIMM0
Bank Locator BANK 2
Memory Type 02h - Unknown
Type Detail 0000h -
Speed 0MHz
Manufacturer [Empty]
Serial Number
Asset Tag Number [String Not Specified]
Part Number [Empty]
[Memory Device (Type 17) - Length 40 - Handle 0046h]
Physical Memory Array Handle 0042h
Memory Error Info Handle [Not Provided]
Total Width 64 bits
Data Width 64 bits
Size 8192MB
Form Factor 09h - DIMM
Device Set [None]
Device Locator ChannelB-DIMM1
Bank Locator BANK 3
Memory Type 18h - Specification Reserved
Type Detail 0080h - Synchronous
Speed 1600MHz
Manufacturer 1315
Serial Number
Asset Tag Number
Part Number BLS8G3D1609DS1S00.
[Memory Array Mapped Address (Type 19) - Length 31 - Handle 0047h]
Starting Address 00000000h
Ending Address 00ffffffh
Memory Array Handle 0042h
Partition Width 04
[Memory Device Mapped Address (Type 20) - Length 35 - Handle 0048h]
Starting Address 00000000h
Ending Address 007fffffh
Memory Device Handle 0046h
Mem Array Mapped Adr Handle 0047h
Partition Row Position [Unknown]
Interleave Position 01
Interleave Data Depth 02
[Memory Device Mapped Address (Type 20) - Length 35 - Handle 0049h]
Starting Address 00800000h
Ending Address 00ffffffh
Memory Device Handle 0046h
Mem Array Mapped Adr Handle 0047h
Partition Row Position [Unknown]
Interleave Position 02
Interleave Data Depth 02
Machine ID Information [From Smbios 2.8, DMIVersion 0, Size=2948]
BiosMajorRelease = 4
BiosMinorRelease = 6
BiosVendor = American Megatrends Inc.
BiosVersion = V17.0
BiosReleaseDate = 04/16/2014
SystemManufacturer = ECT
SystemProductName =
SystemFamily = To be filled by O.E.M.
SystemVersion =
SystemSKU = To be filled by O.E.M.
BaseBoardManufacturer = MSI
BaseBoardProduct = Z97-G43 (MS-7816)
BaseBoardVersion = 3.0
CPUID: "Intel(R) Core(TM) i7-4790 CPU @ 3.60GHz"
MaxSpeed: 3600
CurrentSpeed: 3600
[CPU Information]
~MHz = REG_DWORD 3600
Component Information = REG_BINARY 0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0
Configuration Data = REG_FULL_RESOURCE_DESCRIPTOR ff,ff,ff,ff,ff,ff,ff,ff,0,0,0,0,0,0,0,0
Identifier = REG_SZ Intel64 Family 6 Model 60 Stepping 3
ProcessorNameString = REG_SZ Intel(R) Core(TM) i7-4790 CPU @ 3.60GHz
Update Status = REG_DWORD 0
VendorIdentifier = REG_SZ GenuineIntel
MSR8B = REG_QWORD 1e00000000
THREAD ffffcd8d46f68240 Cid 0004.1bbc Teb: 0000000000000000 Win32Thread: 0000000000000000 RUNNING on processor 5
Not impersonating
GetUlongFromAddress: unable to read from fffff80155314924
Owning Process ffffcd8d3d2ae040 Image: System Process
Attached Process ffffcd8d470a9080 Image: Dishonored.exe
fffff78000000000: Unable to get shared data
Wait Start TickCount 3665351 Ticks: 0
Context Switch Count 10943 IdealProcessor: 4
ReadMemory error: Cannot get nt!KeMaximumIncrement value.
UserTime 00:00:00.000
KernelTime 00:00:00.000
Win32 Start Address nt!ExpWorkerThread (0xfffff801550b4ef0)
Stack Init ffffe4002cfefc90 Current ffffe4002cfef2c0
Base ffffe4002cff0000 Limit ffffe4002cfea000 Call 0000000000000000
Priority 12 BasePriority 12 PriorityDecrement 0 IoPriority 2 PagePriority 5
Child-SP RetAddr : Args to Child : Call Site
ffffe400`2cfef728 fffff806`444276ef : fffff801`55357540 ffffe400`21440000 fffff801`55357540 00000000`00000080 : atikmdag+0x239eb0
ffffe400`2cfef730 fffff801`55357540 : ffffe400`21440000 fffff801`55357540 00000000`00000080 ffffcd8d`475cc800 : atikmdag+0xe76ef
ffffe400`2cfef738 ffffe400`21440000 : fffff801`55357540 00000000`00000080 ffffcd8d`475cc800 fffff806`44415ff2 : nt!NonPagedPoolDescriptor
ffffe400`2cfef740 fffff801`55357540 : 00000000`00000080 ffffcd8d`475cc800 fffff806`44415ff2 00000000`00000008 : 0xffffe400`21440000
ffffe400`2cfef748 00000000`00000080 : ffffcd8d`475cc800 fffff806`44415ff2 00000000`00000008 fffff801`00000290 : nt!NonPagedPoolDescriptor
ffffe400`2cfef750 ffffcd8d`475cc800 : fffff806`44415ff2 00000000`00000008 fffff801`00000290 fffff801`55357540 : 0x80
ffffe400`2cfef758 fffff806`44415ff2 : 00000000`00000008 fffff801`00000290 fffff801`55357540 00000000`00000000 : 0xffffcd8d`475cc800
ffffe400`2cfef760 00000000`00000008 : fffff801`00000290 fffff801`55357540 00000000`00000000 00000000`00000000 : atikmdag+0xd5ff2
ffffe400`2cfef768 fffff801`00000290 : fffff801`55357540 00000000`00000000 00000000`00000000 00000000`c0000001 : 0x8
ffffe400`2cfef770 fffff801`55357540 : 00000000`00000000 00000000`00000000 00000000`c0000001 ffffe400`2cfef7f0 : 0xfffff801`00000290
ffffe400`2cfef778 00000000`00000000 : 00000000`00000000 00000000`c0000001 ffffe400`2cfef7f0 fffff806`443d10f5 : nt!NonPagedPoolDescriptor

Bugcheck code 1000007E
Arguments ffffffff`c0000005 fffff806`44579eb0 ffffe400`2cfef4e8 ffffe400`2cfeed10
Debug session time: Tue Dec 20 14:00:33.453 2016 (UTC + 1:00)
System Uptime: 0 days 15:54:31.111

5 thoughts on “My first BSOD blog post 0x21A Analysis complete”

  1. Greetings from California! I’m bored to tears at work so
    I decided to check out your website on my iphone during lunch
    break. I really like the knowledge you provide here and can’t wait to take a look when I get home.
    I’m shocked at how quick your blog loaded on my mobile
    .. I’m not even using WIFI, just 3G .. Anyhow, superb site!

Leave a Reply

Your email address will not be published. Required fields are marked *