[SOLVED] BSOD ntoskrnl.exe+1c14e0

Feb 2, 2020
11
0
10
I've been having this BSOD on this new build since it started. The motherboard is an MSI Z390 ACE. It is up to date with all of the newest drivers + BIOS installed, according to MSI's website. According to Intel Driver & Support Assistant, all drivers are up to date there, including the Chipset driver which I had to manually update.

I've replaced every component in this machine at this point. I've tried using 1 different DIMM at a time so it isn't a RAM error.

The errors below seem to suggest it is a driver problem. What's the next step to resolve this problem?

I would like to highlight that ntoskrnl.exe+1c14e0 shows up in every one of the errors, and if you google that, it seems to be an increasingly common problem search term in the past few months. Someone probably released a bad driver and it is giving us all grief.

Very curious to hear expert opinions. Thanks



Dump FileCrash TimeBug Check StringBug Check CodeParameter 1Parameter 2Parameter 3Parameter 4Caused By DriverCaused By AddressFile DescriptionProduct NameCompanyFile VersionProcessorCrash AddressStack Address 1Stack Address 2Stack Address 3Computer NameFull PathProcessors CountMajor VersionMinor VersionDump File SizeDump File Time
020220-7703-01.dmp2/2/2020 9:21:13 PMPAGE_FAULT_IN_NONPAGED_AREA0x00000050ffffb603433bf080[/TD] [TD]0000000000000011ffffb603433bf080[/TD] [TD]0000000000000002ntoskrnl.exentoskrnl.exe+1c14e0NT Kernel & SystemMicrosoft® Windows® Operating SystemMicrosoft Corporation10.0.18362.592 (WinBuild.160101.0800)x64ntoskrnl.exe+1c14e0 C:\Windows\Minidump\020220-7703-01.dmp161518362575,2232/2/2020 9:21:48 PM
020220-7750-01.dmp2/2/2020 6:56:37 PMIRQL_NOT_LESS_OR_EQUAL0x0000000a000000000000005c[/TD] [TD]00000000000000020000000000000000[/TD] [TD]fffff8001e23c3c6ntoskrnl.exentoskrnl.exe+1c14e0NT Kernel & SystemMicrosoft® Windows® Operating SystemMicrosoft Corporation10.0.18362.592 (WinBuild.160101.0800)x64ntoskrnl.exe+1c14e0 C:\Windows\Minidump\020220-7750-01.dmp161518362583,1972/2/2020 6:57:11 PM
013020-7609-01.dmp1/30/2020 10:13:18 AMUNEXPECTED_KERNEL_MODE_TRAP0x1000007f0000000000000008[/TD] [TD]ffff8e00e23cb2b0ffff9e0568930f60[/TD] [TD]fffff8074f9cf1d0ntoskrnl.exentoskrnl.exe+1cf1d0NT Kernel & SystemMicrosoft® Windows® Operating SystemMicrosoft Corporation10.0.18362.592 (WinBuild.160101.0800)x64ntoskrnl.exe+1cf1d0 C:\Windows\Minidump\013020-7609-01.dmp161518362602,8711/30/2020 10:13:51 AM
011820-9578-01.dmp1/18/2020 7:39:04 PMDRIVER_IRQL_NOT_LESS_OR_EQUAL0x000000d1fffff805fabd2a76[/TD] [TD]00000000000000ff0000000000000000[/TD] [TD]fffff805fabd2a76ntoskrnl.exentoskrnl.exe+1c14e0NT Kernel & SystemMicrosoft® Windows® Operating SystemMicrosoft Corporation10.0.18362.592 (WinBuild.160101.0800)x64ntoskrnl.exe+1c14e0 C:\Windows\Minidump\011820-9578-01.dmp161518362575,6951/18/2020 7:39:42 PM
011720-11765-01.dmp1/17/2020 12:31:59 PM 0x000001240000000000000000[/TD] [TD]ffffa00589b2b02800000000b2000000[/TD] [TD]0000000000030005ntoskrnl.exentoskrnl.exe+1c14e0NT Kernel & SystemMicrosoft® Windows® Operating SystemMicrosoft Corporation10.0.18362.592 (WinBuild.160101.0800)x64ntoskrnl.exe+1c14e0 C:\Windows\Minidump\011720-11765-01.dmp161518362597,9731/17/2020 12:32:38 PM
 
Solution
The WHEA thing has been occurring since I built the machine. It did it using a different processor, too (tested with a 9900k and a 9900ks).

that would indicate that its not the CPU.

The only component that has not been replaced is the motherboard, but I really don't think that could be the problem. Right?

I believe motherboards are impossible to test. Normally test everything else and use a process of elimination, testing everything else until you either left with Motherboard or have identified the actual cause in another part.

WHEA errors can be fixed with software updates so its always possible the problem has been fixed. I don't like predicting the future :)

PC Tailor

Illustrious
Ambassador
Welcome to the forums my friend!

it seems to be an increasingly common problem search term in the past few months. Someone probably released a bad driver and it is giving us all grief.
Not so, because ntoskrnl.exe is basically your core OS kernel, not a third party module. And unfortunately Windows isn't as smart as we'd like it to be, so when an Issue like a non-paged page fault occurs that it can't resolve, quite often the actual driver causing the issue is in hiding or already passed, so Windows then blames the thing that actually crashed, which is your kernel driver, because it can't see anything else.

Reason why you'll see ntoskrnl.exe as a common problem is because when Windows can't find something like that, it will often just blame the kernel driver, even though it won't be the driver that caused the issue. So unfortunately, it doesn't actually help in any way, and simply indicates the issue is elsewhere, we just have to figure out where.

In the meantime, could you please post your entire system spec including PSU make and model, and also what you've changed.

Also could you post links to the actual dump files, items like WhoCrashed and BlueScreenViewer don't give us the information require in many dump files, so we'd need to manually dig a bit further.
 
Feb 2, 2020
11
0
10
Thank you for the welcome, and thanks for the reply!

The "common" part is the 1c14e0. There are no search results for that up until a few months ago.

i9900ks (tested with a 9900k as well)
Nvidia 1070 (have two, tested with either one, currently running both)
Corsair RAM (16x4) (tested using just 1 or many or different ones)
EVGA 850 watts platinum (have two, tried with both)
MSI MEG Z390 ACE (have not replaced, but I doubt this is a problem)
Windows + all drivers are installed on a Samsung Pro M2 NVME
I am running RAID 0 on a non-system drive, and IRST is up to date.

There are no overclocks applied to the system. Default voltages everywhere, default speeds everywhere.

I am PM-ing you a link with the dmp files. Thank you for reading!
 

Colif

Win 11 Master
Moderator
Always helps to include dumps in your posts as PC Tailor not only one who can read them, and if he goes on a 4 week holiday like he has recently (lol) you might be waiting a while for a reply. I assume you safe though (I am just having a joke at his expense).

4th code that decided to remain nameless is actually a WHEA error, I know that code... its likely it also blames hal.dll. which is another part of windows commonly blamed as they were last things to crash. both ntoskrnl and hal are utterly essential parts of windows, and when asked to do the impossible they crash. WHEA = Windows Hardware Error Architecture. PC likes to blame CPU for them as they are called by the CPU but can be any hardware or drivers.

i found this with same ntoskrnl code - https://windowsforum.com/threads/need-help-with-bsod-ntoskrnl-exe-1c14e0.248207/

his system also has a MSI Z390 motherboard and same CPU
HyperX Predator HX432C16PB3K2 32 GB DDR4 3200 MHz
Intel Core i9 9900KS processor
MSI GeForce RTX 2080 SUPER Sea Hawk X
MSI MPG Z390 GAMING PRO CARBON
NZXT Kraken X62
Samsung 860 EVO 500GB SSD
Seagate ST2000DX001, 2TB SSHD
Sharkoon SilentStorm Cool Zero 750W PSU

no answer on his thread as its literally from today. I had to check his stats to make sure it wasn't you :)

if you looking for a bad driver, my guess is the Nvidia drivers but they aren't often seen causing WHEA errors or IRQ errors, they cause other errors normally.

Dumps might show more.
 
I would like to highlight that ntoskrnl.exe+1c14e0 shows up in every one of the errors, and if you google that, it seems to be an increasingly common problem search term in the past few months. Someone probably released a bad driver and it is giving us all grief.

Unlike what you may think, it's not much special.
Ntoskrnl.exe+1c14e0 means that the memory address is the base address of ntoskrnl + the offset 1c14e0.
However, the meaning behind it is different for each crash, for the 0x50 its meaning is unknown because the parameter is 'reserved', but for the 0xD1 it means that that address referenced the address of parameter 1.

I would like to note that the report doesn't look to be entirely correct, 0xD1 parameter 3, for example, should be a value that represents the type of operation (read, write) that was performed by parameter 4 on parameter 1. I am getting curious about what the actual values of the parameters are seeing potential similar mistakes in the report with the 0x124.
 
Not so, because ntoskrnl.exe is basically your core OS kernel, not a third party module. And unfortunately Windows isn't as smart as we'd like it to be, so when an Issue like a non-paged page fault occurs that it can't resolve, quite often the actual driver causing the issue is in hiding or already passed, so Windows then blames the thing that actually crashed, which is your kernel driver, because it can't see anything else.

Reason why you'll see ntoskrnl.exe as a common problem is because when Windows can't find something like that, it will often just blame the kernel driver, even though it won't be the driver that caused the issue. So unfortunately, it doesn't actually help in any way, and simply indicates the issue is elsewhere, we just have to figure out where.

Windows? Windows generates the dumps but doesn't do anything else with the dumps.

Windbg, or whatever BlueScreen viewer, WhoCrashed and similar tools use, 'interpret' it as in they make the dump file readable for us and may guide us a little. In the end, it's up to a human to interpret it.
 
  • Like
Reactions: PC Tailor
I understand, but there's no need to be worried about security.

The type of dumps often shared, mini kernel dumps, contain limited information. If we're unlucky the minidumps won't be enough because they contain not enough.
Allow me to elaborate on what these mini kernel dumps usually have.

Say there's an organization with a couple of members, this organization is a process that you can also see in task manager and each member is what is called a 'thread'.
Each thread is doing work for the process, but with the work of one of them, something goes wrong and in order to find out what went wrong, there's a 'log' that has been kept track of to see what each thread had done so far. This log is one of the elements in a mini kernel dump that will be looked into, but, as I mentioned 'limited information', the information the log has is limited to a certain extent. It's not possible to look in-depth in the details on how something happened, but rather what happened.

There's also other information that can be found in the minidumps if we're lucky. This information includes some hardware details, you've already shared some of it, but within the minidumps, it's possible to see at what speed the memory and CPU ran, what the voltage of the CPU was, in which slot a memory module was seated, what the BIOS version is, what the model of the pc is (if any, and to a certain extent).
'If we're lucky' because it's not always present.

Here's an example of a minidump, this is most of the information someone will be able to retrieve, notice that I've highlighted a line which already specifies roughly what mini kernel dumps contain.
Rich (BB code):
Microsoft (R) Windows Debugger Version 10.0.18362.1 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Users\axe0\AppData\Local\Temp\Temp1-1-(2020-01-27_17-52-50).zip\Crash Dumps\012720-10156-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available


************* Path validation summary **************
Response                         Time (ms)     Location
Deferred                                       SRV*G:\Symbols*https://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*G:\Symbols*https://msdl.microsoft.com/download/symbols
Executable search path is: 
Windows 10 Kernel Version 18362 MP (8 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 18362.1.amd64fre.19h1_release.190318-1202
Machine Name:
Kernel base = 0xfffff806`60000000 PsLoadedModuleList = 0xfffff806`60448150
Debug session time: Mon Jan 27 18:15:47.999 2020 (UTC + 1:00)
System Uptime: 3 days 0:09:48.650
Loading Kernel Symbols
...............................................................
................................................................
...................................................
Loading User Symbols
Loading unloaded module list
.................................................
For analysis of this file, run !analyze -v
Processing initial command '!load PDE; !load mex; !load niemiro; !load cmkd; !load swishdbgext;!analyze -v;lmtsmn; !rawstack; !dpx; !sysinfo smbios; !sysinfo machineid; !sysinfo cpuspeed; !thread; .bugcheck; .time'
5: kd> !load PDE; !load mex; !load niemiro; !load cmkd; !load swishdbgext;!analyze -v;lmtsmn; !rawstack; !dpx; !sysinfo smbios; !sysinfo machineid; !sysinfo cpuspeed; !thread; .bugcheck; .time
=========================================================================================
 PDE v11.3 - Copyright 2017 Andrew Richards
=========================================================================================
Mex External 3.0.0.7172 Loaded!
       SwishDbgExt 3.0.20180330.1 - Incident Response & Digital Forensics Debugging Extension
       SwishDbgExt Copyright (C) 2016 Comae Technologies FZE
       SwishDbgExt Copyright (C) 2014-2016 Matthieu Suiche (@msuiche) - http://msuiche.net

       This program comes with ABSOLUTELY NO WARRANTY; for details type `show w'.
       This is free software, and you are welcome to redistribute it
       under certain conditions; type `show c' for details.
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

CRITICAL_PROCESS_DIED (ef)
        A critical system process died
Arguments:
Arg1: ffffa208d8e282c0, Process object or thread object
Arg2: 0000000000000000, If this is 0, a process died. If this is 1, a thread died.
Arg3: 0000000000000000
Arg4: 0000000000000000

Debugging Details:
------------------

*** WARNING: Unable to verify checksum for win32k.sys

KEY_VALUES_STRING: 1


PROCESSES_ANALYSIS: 1

SERVICE_ANALYSIS: 1

STACKHASH_ANALYSIS: 1

TIMELINE_ANALYSIS: 1


DUMP_CLASS: 1

DUMP_QUALIFIER: 400

BUILD_VERSION_STRING:  18362.1.amd64fre.19h1_release.190318-1202

SYSTEM_MANUFACTURER:  Gigabyte Technology Co., Ltd.

SYSTEM_PRODUCT_NAME:  B85M-D3H

SYSTEM_SKU:  To be filled by O.E.M.

SYSTEM_VERSION:  To be filled by O.E.M.

BIOS_VENDOR:  American Megatrends Inc.

BIOS_VERSION:  F15

BIOS_DATE:  08/20/2015

BASEBOARD_MANUFACTURER:  Gigabyte Technology Co., Ltd.

BASEBOARD_PRODUCT:  B85M-D3H

BASEBOARD_VERSION:  x.x

DUMP_TYPE:  2

BUGCHECK_P1: ffffa208d8e282c0

BUGCHECK_P2: 0

BUGCHECK_P3: 0

BUGCHECK_P4: 0

PROCESS_NAME:  svchost.exe

CRITICAL_PROCESS:  svchost.exe

EXCEPTION_CODE: (NTSTATUS) 0xd9dcf080 - <Unable to get error code text>

ERROR_CODE: (NTSTATUS) 0xd9dcf080 - <Unable to get error code text>

CRITICAL_PROCESS_REPORTGUID:  {dbdb292d-f916-43bf-9676-097eef806f80}

IMAGE_NAME:  ntdll.dll

DEBUG_FLR_IMAGE_TIMESTAMP:  0

MODULE_NAME: ntdll

FAULTING_MODULE: 0000000000000000 

CPU_COUNT: 8

CPU_MHZ: d40

CPU_VENDOR:  GenuineIntel

CPU_FAMILY: 6

CPU_MODEL: 3c

CPU_STEPPING: 3

CPU_MICROCODE: 6,3c,3,0 (F,M,S,R)  SIG: 25'00000000 (cache) 25'00000000 (init)

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXPNP: 1 (!blackboxpnp)


BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  WIN8_DRIVER_FAULT

BUGCHECK_STR:  0xEF

CURRENT_IRQL:  0

ANALYSIS_SESSION_HOST:  DESKTOP-NPASAR7

ANALYSIS_SESSION_TIME:  02-04-2020 15:55:42.0037

ANALYSIS_VERSION: 10.0.18362.1 amd64fre

LAST_CONTROL_TRANSFER:  from fffff806608cae89 to fffff806601c14e0

STACK_TEXT:  
ffffe18f`b39f0938 fffff806`608cae89 : 00000000`000000ef ffffa208`d8e282c0 00000000`00000000 00000000`00000000 : nt!KeBugCheckEx
ffffe18f`b39f0940 fffff806`607c75c1 : ffffa208`d8e282c0 fffff806`6009c769 ffffa208`d8e282c0 fffff806`6009c8c0 : nt!PspCatchCriticalBreak+0x115
ffffe18f`b39f09e0 fffff806`60639fc0 : ffffa208`00000000 00000000`00000000 ffffa208`d8e282c0 ffffa208`d8e282c0 : nt!PspTerminateAllThreads+0x175e3d
ffffe18f`b39f0a50 fffff806`60639da9 : ffffffff`ffffffff ffffe18f`b39f0b80 ffffa208`dce8f080 00000000`00000501 : nt!PspTerminateProcess+0xe0
ffffe18f`b39f0a90 fffff806`601d2d18 : ffffa208`000003b8 ffffa208`d9dcf080 ffffa208`d8e282c0 00007ffc`4b79bb88 : nt!NtTerminateProcess+0xa9
ffffe18f`b39f0b00 00007ffc`6223c644 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
000000bb`cfbfebc8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffc`6223c644


THREAD_SHA1_HASH_MOD_FUNC:  042a2b51772309c39e12d732cc93cacf0af3064e

THREAD_SHA1_HASH_MOD_FUNC_OFFSET:  579718d2ac9cadd09055086e52eaaf605eedcd78

THREAD_SHA1_HASH_MOD:  ee8fcf1fb60cb6e3e2f60ddbed2ec02b5748a693

FOLLOWUP_NAME:  MachineOwner

STACK_COMMAND:  .thread ; .cxr ; kb

FAILURE_BUCKET_ID:  0xEF_svchost.exe_BUGCHECK_CRITICAL_PROCESS_d9dcf080_ntdll.dll!LdrpICallHandler_IMAGE_ntdll.dll

BUCKET_ID:  0xEF_svchost.exe_BUGCHECK_CRITICAL_PROCESS_d9dcf080_ntdll.dll!LdrpICallHandler_IMAGE_ntdll.dll

PRIMARY_PROBLEM_CLASS:  0xEF_svchost.exe_BUGCHECK_CRITICAL_PROCESS_d9dcf080_ntdll.dll!LdrpICallHandler_IMAGE_ntdll.dll

TARGET_TIME:  2020-01-27T17:15:47.000Z

OSBUILD:  18362

OSSERVICEPACK:  592

SERVICEPACK_NUMBER: 0

OS_REVISION: 0

SUITE_MASK:  272

PRODUCT_TYPE:  1

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

OSEDITION:  Windows 10 WinNt TerminalServer SingleUserTS

OS_LOCALE:  

USER_LCID:  0

OSBUILD_TIMESTAMP:  1972-08-21 17:24:00

BUILDDATESTAMP_STR:  190318-1202

BUILDLAB_STR:  19h1_release

BUILDOSVER_STR:  10.0.18362.1.amd64fre.19h1_release.190318-1202

ANALYSIS_SESSION_ELAPSED_TIME:  2b89

ANALYSIS_SOURCE:  KM

FAILURE_ID_HASH_STRING:  km:0xef_svchost.exe_bugcheck_critical_process_d9dcf080_ntdll.dll!ldrpicallhandler_image_ntdll.dll

FAILURE_ID_HASH:  {aea4d1c6-c813-1563-74bc-00e6069a3e9f}

Followup:     MachineOwner
---------

start             end                 module name
fffff806`654d0000 fffff806`6559c000   ACPI     ACPI.sys     90B929F2 (This is a reproducible build file hash, not a timestamp)
fffff806`65430000 fffff806`65455000   acpiex   acpiex.sys   2B91EDB2 (This is a reproducible build file hash, not a timestamp)
fffff806`67200000 fffff806`672a7000   afd      afd.sys      B88DD13E (This is a reproducible build file hash, not a timestamp)
fffff806`67bc0000 fffff806`67bd3000   afunix   afunix.sys   9D6C12C4 (This is a reproducible build file hash, not a timestamp)
fffff806`635e0000 fffff806`63607000   AgileVpn AgileVpn.sys A96AFF6D (This is a reproducible build file hash, not a timestamp)
fffff806`67560000 fffff806`675af000   ahcache  ahcache.sys  A8473BE2 (This is a reproducible build file hash, not a timestamp)
fffff806`67540000 fffff806`67556000   bam      bam.sys      22198778 (This is a reproducible build file hash, not a timestamp)
fffff806`67a90000 fffff806`67aa6000   BasicDisplay BasicDisplay.sys 4E6E05E1 (This is a reproducible build file hash, not a timestamp)
fffff806`67ab0000 fffff806`67ac1000   BasicRender BasicRender.sys 82A93228 (This is a reproducible build file hash, not a timestamp)
fffff806`66da0000 fffff806`66daa000   Beep     Beep.SYS     528EC21A (This is a reproducible build file hash, not a timestamp)
fffff806`66db0000 fffff806`66dd1000   bindflt  bindflt.sys  29520F5A (This is a reproducible build file hash, not a timestamp)
fffff806`64fa0000 fffff806`64fab000   BOOTVID  BOOTVID.dll  0F301604 (This is a reproducible build file hash, not a timestamp)
fffff806`6b3b0000 fffff806`6b3d5000   bowser   bowser.sys   D37F2E35 (This is a reproducible build file hash, not a timestamp)
ffffdba2`6b060000 ffffdba2`6b0a8000   cdd      cdd.dll      00000000 (This is a reproducible build file hash, not a timestamp)
fffff806`66d20000 fffff806`66d50000   cdrom    cdrom.sys    9F6B0B7B (This is a reproducible build file hash, not a timestamp)
fffff806`65740000 fffff806`65759000   CEA      CEA.sys      F3811107 (This is a reproducible build file hash, not a timestamp)
fffff806`65160000 fffff806`6523c000   CI       CI.dll       E1AF0052 (This is a reproducible build file hash, not a timestamp)
fffff806`66540000 fffff806`665ab000   CLASSPNP CLASSPNP.SYS 09ED6E49 (This is a reproducible build file hash, not a timestamp)
fffff806`66c60000 fffff806`66cd7000   cldflt   cldflt.sys   A5A8679B (This is a reproducible build file hash, not a timestamp)
fffff806`64f10000 fffff806`64f78000   CLFS     CLFS.SYS     2B95B1D7 (This is a reproducible build file hash, not a timestamp)
fffff806`64fb0000 fffff806`650b5000   clipsp   clipsp.sys   Tue Sep 24 05:47:06 2019 (5D8991BA)
fffff806`65140000 fffff806`6514e000   cmimcext cmimcext.sys C7F022B4 (This is a reproducible build file hash, not a timestamp)
fffff806`65240000 fffff806`652fc000   cng      cng.sys      5444B5A1 (This is a reproducible build file hash, not a timestamp)
fffff806`67660000 fffff806`67671000   CompositeBus CompositeBus.sys F050D616 (This is a reproducible build file hash, not a timestamp)
fffff806`6b160000 fffff806`6b173000   condrv   condrv.sys   AEE79CBA (This is a reproducible build file hash, not a timestamp)
fffff806`66c40000 fffff806`66c5d000   crashdmp crashdmp.sys 2985CB13 (This is a reproducible build file hash, not a timestamp)
fffff806`673c0000 fffff806`67454000   csc      csc.sys      576BFE21 (This is a reproducible build file hash, not a timestamp)
fffff806`674f0000 fffff806`6751c000   dfsc     dfsc.sys     FABE3F7D (This is a reproducible build file hash, not a timestamp)
fffff806`66520000 fffff806`6653c000   disk     disk.sys     384FEFED (This is a reproducible build file hash, not a timestamp)
fffff806`68800000 fffff806`68821000   drmk     drmk.sys     ***** Invalid (A3E06FB0)
fffff806`671b0000 fffff806`671be000   dump_diskdump dump_diskdump.sys 5CC3D020 (This is a reproducible build file hash, not a timestamp)
fffff806`66e50000 fffff806`66e6d000   dump_dumpfve dump_dumpfve.sys 4BEDF38A (This is a reproducible build file hash, not a timestamp)
fffff806`66e00000 fffff806`66e2e000   dump_storahci dump_storahci.sys 381E77BB (This is a reproducible build file hash, not a timestamp)
fffff806`676f0000 fffff806`67a64000   dxgkrnl  dxgkrnl.sys  B1B2A7DF (This is a reproducible build file hash, not a timestamp)
fffff806`66e70000 fffff806`66f4a000   dxgmms2  dxgmms2.sys  B4AA8F54 (This is a reproducible build file hash, not a timestamp)
fffff806`659e0000 fffff806`659fb000   EhStorClass EhStorClass.sys 526CC202 (This is a reproducible build file hash, not a timestamp)
fffff806`6b200000 fffff806`6b220000   farflt   farflt.sys   Wed Nov 14 19:02:07 2018 (5BEC631F)
fffff806`66d60000 fffff806`66d75000   filecrypt filecrypt.sys 4EAD73C1 (This is a reproducible build file hash, not a timestamp)
fffff806`65a00000 fffff806`65a1a000   fileinfo fileinfo.sys 24BBED20 (This is a reproducible build file hash, not a timestamp)
fffff806`650c0000 fffff806`65131000   FLTMGR   FLTMGR.SYS   801A5F11 (This is a reproducible build file hash, not a timestamp)
fffff806`65d00000 fffff806`65d0d000   Fs_Rec   Fs_Rec.sys   unavailable (00000000)
fffff806`66320000 fffff806`663e9000   fvevol   fvevol.sys   D4B5A2E7 (This is a reproducible build file hash, not a timestamp)
fffff806`66260000 fffff806`662da000   fwpkclnt fwpkclnt.sys 58C1E6ED (This is a reproducible build file hash, not a timestamp)
fffff806`674b0000 fffff806`674ba000   gpuenergydrv gpuenergydrv.sys 0CC24294 (This is a reproducible build file hash, not a timestamp)
fffff806`60ab6000 fffff806`60b59000   hal      hal.dll      1CD3FB4F (This is a reproducible build file hash, not a timestamp)
fffff806`69f50000 fffff806`69f72000   HDAudBus HDAudBus.sys AECD2958 (This is a reproducible build file hash, not a timestamp)
fffff806`66bb0000 fffff806`66c1e000   HdAudio  HdAudio.sys  4A11F5B5 (This is a reproducible build file hash, not a timestamp)
fffff806`670c0000 fffff806`670fb000   HIDCLASS HIDCLASS.SYS D4D0DEE6 (This is a reproducible build file hash, not a timestamp)
fffff806`67100000 fffff806`67113000   HIDPARSE HIDPARSE.SYS 0D56F932 (This is a reproducible build file hash, not a timestamp)
fffff806`670a0000 fffff806`670b2000   hidusb   hidusb.sys   7B9189FE (This is a reproducible build file hash, not a timestamp)
fffff806`6b260000 fffff806`6b3a5000   HTTP     HTTP.sys     AAC6DF8E (This is a reproducible build file hash, not a timestamp)
fffff806`69300000 fffff806`69323000   i8042prt i8042prt.sys E54F27F7 (This is a reproducible build file hash, not a timestamp)
fffff806`688b0000 fffff806`69071000   igdkmd64 igdkmd64.sys Thu Sep 29 16:43:27 2016 (57ED288F)
fffff806`66a90000 fffff806`66b07000   IntcDAud IntcDAud.sys Tue May 10 10:08:56 2016 (57319718)
fffff806`655b0000 fffff806`6560b000   intelpep intelpep.sys A0B377F1 (This is a reproducible build file hash, not a timestamp)
fffff806`69370000 fffff806`693ae000   intelppm intelppm.sys 8B98A984 (This is a reproducible build file hash, not a timestamp)
fffff806`664f0000 fffff806`66502000   iorate   iorate.sys   18D52DDA (This is a reproducible build file hash, not a timestamp)
fffff806`69330000 fffff806`69344000   kbdclass kbdclass.sys 0B474226 (This is a reproducible build file hash, not a timestamp)
fffff806`64c00000 fffff806`64c0b000   kd       kd.dll       5A75D524 (This is a reproducible build file hash, not a timestamp)
fffff806`67680000 fffff806`6768d000   kdnic    kdnic.sys    1FF5F7F5 (This is a reproducible build file hash, not a timestamp)
fffff806`68830000 fffff806`688a8000   ks       ks.sys       1F5FE6FB (This is a reproducible build file hash, not a timestamp)
fffff806`64e40000 fffff806`64e6a000   ksecdd   ksecdd.sys   A35F28F6 (This is a reproducible build file hash, not a timestamp)
fffff806`65f30000 fffff806`65f62000   ksecpkg  ksecpkg.sys  E1E129D5 (This is a reproducible build file hash, not a timestamp)
fffff806`693c0000 fffff806`693cf000   ksthunk  ksthunk.sys  15502221 (This is a reproducible build file hash, not a timestamp)
fffff806`67120000 fffff806`67138000   LHidFilt LHidFilt.Sys Tue Jun  9 21:25:40 2015 (55773DB4)
fffff806`67be0000 fffff806`67bf8000   lltdio   lltdio.sys   707E9308 (This is a reproducible build file hash, not a timestamp)
fffff806`67160000 fffff806`67174000   LMouFilt LMouFilt.Sys Tue Jun  9 21:25:39 2015 (55773DB3)
fffff806`66f70000 fffff806`66f9a000   luafv    luafv.sys    08A8E82A (This is a reproducible build file hash, not a timestamp)
fffff806`67080000 fffff806`67090000   LUsbFilt LUsbFilt.Sys Tue Jun  9 21:25:36 2015 (55773DB0)
fffff806`674c0000 fffff806`674e6000   mbae64   mbae64.sys   Wed May 30 13:20:29 2018 (5B0E88FD)
fffff806`6b230000 fffff806`6b242000   mbam     mbam.sys     Thu Nov 29 17:55:10 2018 (5C0019EE)
fffff806`676b0000 fffff806`676e2000   MbamChameleon MbamChameleon.sys Thu Nov 15 19:11:24 2018 (5BEDB6CC)
fffff806`6b180000 fffff806`6b1c1000   mbamswissarmy mbamswissarmy.sys Thu Nov 15 15:24:24 2018 (5BED8198)
fffff806`64c10000 fffff806`64e11000   mcupdate_GenuineIntel mcupdate_GenuineIntel.dll 258CAB1A (This is a reproducible build file hash, not a timestamp)
fffff806`6b070000 fffff806`6b084000   mmcss    mmcss.sys    3EE4136D (This is a reproducible build file hash, not a timestamp)
fffff806`66f50000 fffff806`66f68000   monitor  monitor.sys  93F54FB5 (This is a reproducible build file hash, not a timestamp)
fffff806`67180000 fffff806`67193000   mouclass mouclass.sys 4A22FFB8 (This is a reproducible build file hash, not a timestamp)
fffff806`67140000 fffff806`67150000   mouhid   mouhid.sys   A140C187 (This is a reproducible build file hash, not a timestamp)
fffff806`658e0000 fffff806`658ff000   mountmgr mountmgr.sys 63D3E2C9 (This is a reproducible build file hash, not a timestamp)
fffff806`6b3e0000 fffff806`6b3fa000   mpsdrv   mpsdrv.sys   7D5AF2F0 (This is a reproducible build file hash, not a timestamp)
fffff806`6ae00000 fffff806`6ae8f000   mrxsmb   mrxsmb.sys   1E559E99 (This is a reproducible build file hash, not a timestamp)
fffff806`6ae90000 fffff806`6aed5000   mrxsmb20 mrxsmb20.sys 2A968ECC (This is a reproducible build file hash, not a timestamp)
fffff806`67af0000 fffff806`67b01000   Msfs     Msfs.SYS     91FE0FF4 (This is a reproducible build file hash, not a timestamp)
fffff806`65660000 fffff806`6566b000   msisadrv msisadrv.sys 5E470A0E (This is a reproducible build file hash, not a timestamp)
fffff806`69450000 fffff806`69469000   mslldp   mslldp.sys   15C3108A (This is a reproducible build file hash, not a timestamp)
fffff806`64e70000 fffff806`64ed0000   msrpc    msrpc.sys    7862AB08 (This is a reproducible build file hash, not a timestamp)
fffff806`65460000 fffff806`654a2000   mssecflt mssecflt.sys 9C3FCC09 (This is a reproducible build file hash, not a timestamp)
fffff806`67490000 fffff806`674a0000   mssmbios mssmbios.sys E6DC521D (This is a reproducible build file hash, not a timestamp)
fffff806`664c0000 fffff806`664e5000   mup      mup.sys      565E0311 (This is a reproducible build file hash, not a timestamp)
fffff806`637f0000 fffff806`63813000   mwac     mwac.sys     Wed Nov 21 18:51:43 2018 (5BF59B2F)
fffff806`65d10000 fffff806`65e82000   ndis     ndis.sys     20136331 (This is a reproducible build file hash, not a timestamp)
fffff806`636b0000 fffff806`636bf000   ndistapi ndistapi.sys 690D0D05 (This is a reproducible build file hash, not a timestamp)
fffff806`638b0000 fffff806`638c8000   ndisuio  ndisuio.sys  38FD20EE (This is a reproducible build file hash, not a timestamp)
fffff806`693d0000 fffff806`693dd000   NdisVirtualBus NdisVirtualBus.sys D217410A (This is a reproducible build file hash, not a timestamp)
fffff806`636c0000 fffff806`636fa000   ndiswan  ndiswan.sys  FB43C10D (This is a reproducible build file hash, not a timestamp)
fffff806`63590000 fffff806`635d1000   NDProxy  NDProxy.sys  193FE713 (This is a reproducible build file hash, not a timestamp)
fffff806`6af40000 fffff806`6af67000   Ndu      Ndu.sys      23725908 (This is a reproducible build file hash, not a timestamp)
fffff806`67300000 fffff806`67314000   netbios  netbios.sys  B37FD2E9 (This is a reproducible build file hash, not a timestamp)
fffff806`67b60000 fffff806`67bb9000   netbt    netbt.sys    113D2A22 (This is a reproducible build file hash, not a timestamp)
fffff806`65e90000 fffff806`65f24000   NETIO    NETIO.SYS    E3375155 (This is a reproducible build file hash, not a timestamp)
fffff806`67ad0000 fffff806`67aec000   Npfs     Npfs.SYS     B03ECFD3 (This is a reproducible build file hash, not a timestamp)
fffff806`67480000 fffff806`6748d000   npsvctrig npsvctrig.sys 0E7AC006 (This is a reproducible build file hash, not a timestamp)
fffff806`67460000 fffff806`67472000   nsiproxy nsiproxy.sys 528DA18A (This is a reproducible build file hash, not a timestamp)
fffff806`60000000 fffff806`60ab6000   nt       ntkrnlmp.exe 04F6EBA0 (This is a reproducible build file hash, not a timestamp)
fffff806`65a60000 fffff806`65cfd000   Ntfs     Ntfs.sys     B0B0EBAD (This is a reproducible build file hash, not a timestamp)
fffff806`65150000 fffff806`6515c000   ntosext  ntosext.sys  BAC877D8 (This is a reproducible build file hash, not a timestamp)
fffff806`66d90000 fffff806`66d9a000   Null     Null.SYS     unavailable (00000000)
fffff806`69410000 fffff806`69444000   nvhda64v nvhda64v.sys Thu Apr 16 21:03:16 2015 (55300774)
fffff806`69470000 fffff806`69f4c000   nvlddmkm nvlddmkm.sys Wed Jun 17 07:28:00 2015 (55810560)
fffff806`693b0000 fffff806`693bd000   nvvad64v nvvad64v.sys Wed Apr  1 16:36:50 2015 (551C0282)
fffff806`672d0000 fffff806`672fb000   pacer    pacer.sys    E7276BDE (This is a reproducible build file hash, not a timestamp)
fffff806`69350000 fffff806`6936f000   parport  parport.sys  0655C9B7 (This is a reproducible build file hash, not a timestamp)
fffff806`65760000 fffff806`65790000   partmgr  partmgr.sys  89C96AD1 (This is a reproducible build file hash, not a timestamp)
fffff806`65670000 fffff806`656df000   pci      pci.sys      0F525018 (This is a reproducible build file hash, not a timestamp)
fffff806`65640000 fffff806`65655000   pcw      pcw.sys      6B731527 (This is a reproducible build file hash, not a timestamp)
fffff806`65700000 fffff806`65733000   pdc      pdc.sys      87C34D95 (This is a reproducible build file hash, not a timestamp)
fffff806`6af70000 fffff806`6b046000   peauth   peauth.sys   Mon Jan 12 02:52:12 2015 (54B328CC)
fffff806`69f80000 fffff806`69fe7000   portcls  portcls.sys  D4F15BF0 (This is a reproducible build file hash, not a timestamp)
fffff806`64f80000 fffff806`64f9a000   PSHED    PSHED.dll    B21F9DDA (This is a reproducible build file hash, not a timestamp)
fffff806`63610000 fffff806`63632000   rasl2tp  rasl2tp.sys  A7AA404E (This is a reproducible build file hash, not a timestamp)
fffff806`63670000 fffff806`6368c000   raspppoe raspppoe.sys 053A7D72 (This is a reproducible build file hash, not a timestamp)
fffff806`63640000 fffff806`63660000   raspptp  raspptp.sys  54893590 (This is a reproducible build file hash, not a timestamp)
fffff806`63570000 fffff806`6358d000   rassstp  rassstp.sys  6EC6A1E5 (This is a reproducible build file hash, not a timestamp)
fffff806`67340000 fffff806`673bb000   rdbss    rdbss.sys    65292112 (This is a reproducible build file hash, not a timestamp)
fffff806`693f0000 fffff806`693fe000   rdpbus   rdpbus.sys   4E9899F8 (This is a reproducible build file hash, not a timestamp)
fffff806`66470000 fffff806`664be000   rdyboost rdyboost.sys F450CEB3 (This is a reproducible build file hash, not a timestamp)
fffff806`67520000 fffff806`6753b000   rspndr   rspndr.sys   ED98D1EE (This is a reproducible build file hash, not a timestamp)
fffff806`69250000 fffff806`692fd000   rt640x64 rt640x64.sys Fri May 24 10:47:02 2019 (5CE7AF86)
fffff806`67010000 fffff806`6707a000   RtsUer   RtsUer.sys   Mon Apr  1 11:20:46 2019 (5CA1D7EE)
fffff806`691a0000 fffff806`691af000   serenum  serenum.sys  0B8B1DB3 (This is a reproducible build file hash, not a timestamp)
fffff806`67320000 fffff806`6733c000   serial   serial.sys   B6549B39 (This is a reproducible build file hash, not a timestamp)
fffff806`654b0000 fffff806`654ca000   SgrmAgent SgrmAgent.sys F851A195 (This is a reproducible build file hash, not a timestamp)
fffff806`65400000 fffff806`6540f000   SleepStudyHelper SleepStudyHelper.sys BA6E2346 (This is a reproducible build file hash, not a timestamp)
fffff806`657a0000 fffff806`65845000   spaceport spaceport.sys A70F0B50 (This is a reproducible build file hash, not a timestamp)
fffff806`6b090000 fffff806`6b155000   srv2     srv2.sys     BD56ACC9 (This is a reproducible build file hash, not a timestamp)
fffff806`6aee0000 fffff806`6af33000   srvnet   srvnet.sys   220AB43D (This is a reproducible build file hash, not a timestamp)
fffff806`65900000 fffff806`6592e000   storahci storahci.sys 381E77BB (This is a reproducible build file hash, not a timestamp)
fffff806`65930000 fffff806`659d2000   storport storport.sys A692CE5B (This is a reproducible build file hash, not a timestamp)
fffff806`66fe0000 fffff806`66ffa000   storqosflt storqosflt.sys D77C69C8 (This is a reproducible build file hash, not a timestamp)
fffff806`693e0000 fffff806`693ec000   swenum   swenum.sys   C4D73525 (This is a reproducible build file hash, not a timestamp)
fffff806`66d80000 fffff806`66d8e000   tbs      tbs.sys      965BAC31 (This is a reproducible build file hash, not a timestamp)
fffff806`65f70000 fffff806`6625a000   tcpip    tcpip.sys    56FA3E2F (This is a reproducible build file hash, not a timestamp)
fffff806`6b050000 fffff806`6b064000   tcpipreg tcpipreg.sys 3451B629 (This is a reproducible build file hash, not a timestamp)
fffff806`67b40000 fffff806`67b50000   TDI      TDI.SYS      894065A0 (This is a reproducible build file hash, not a timestamp)
fffff806`67b10000 fffff806`67b36000   tdx      tdx.sys      0A1F3DC4 (This is a reproducible build file hash, not a timestamp)
fffff806`69160000 fffff806`69194000   TeeDriverW8x64 TeeDriverW8x64.sys Tue Jul 18 16:15:12 2017 (596E17F0)
fffff806`64ee0000 fffff806`64f07000   tm       tm.sys       9A74C3B7 (This is a reproducible build file hash, not a timestamp)
fffff806`69110000 fffff806`69151000   ucx01000 ucx01000.sys 04268533 (This is a reproducible build file hash, not a timestamp)
fffff806`67690000 fffff806`676a5000   umbus    umbus.sys    3104A4AD (This is a reproducible build file hash, not a timestamp)
fffff806`69400000 fffff806`6940e000   USBD     USBD.SYS     CD63CE9D (This is a reproducible build file hash, not a timestamp)
fffff806`691b0000 fffff806`691cd000   usbehci  usbehci.sys  7C61F55C (This is a reproducible build file hash, not a timestamp)
fffff806`66a00000 fffff806`66a8a000   usbhub   usbhub.sys   813B20B8 (This is a reproducible build file hash, not a timestamp)
fffff806`66b10000 fffff806`66bac000   UsbHub3  UsbHub3.sys  D4267D67 (This is a reproducible build file hash, not a timestamp)
fffff806`691d0000 fffff806`6924a000   USBPORT  USBPORT.SYS  A13767BB (This is a reproducible build file hash, not a timestamp)
fffff806`69080000 fffff806`69109000   USBXHCI  USBXHCI.SYS  951B0A79 (This is a reproducible build file hash, not a timestamp)
fffff806`656e0000 fffff806`656f3000   vdrvroot vdrvroot.sys 0101BCC6 (This is a reproducible build file hash, not a timestamp)
fffff806`675b0000 fffff806`6763c000   Vid      Vid.sys      5684D88D (This is a reproducible build file hash, not a timestamp)
fffff806`65850000 fffff806`6586a000   volmgr   volmgr.sys   211CEF76 (This is a reproducible build file hash, not a timestamp)
fffff806`65870000 fffff806`658d3000   volmgrx  volmgrx.sys  D6F366B7 (This is a reproducible build file hash, not a timestamp)
fffff806`66400000 fffff806`6646d000   volsnap  volsnap.sys  1876F533 (This is a reproducible build file hash, not a timestamp)
fffff806`663f0000 fffff806`663fb000   volume   volume.sys   A4E9FDFA (This is a reproducible build file hash, not a timestamp)
fffff806`672b0000 fffff806`672ca000   vwififlt vwififlt.sys 39396289 (This is a reproducible build file hash, not a timestamp)
fffff806`63690000 fffff806`636ad000   wanarp   wanarp.sys   1766D61C (This is a reproducible build file hash, not a timestamp)
fffff806`67a70000 fffff806`67a86000   watchdog watchdog.sys 21474799 (This is a reproducible build file hash, not a timestamp)
fffff806`66fa0000 fffff806`66fd7000   wcifs    wcifs.sys    6C454D30 (This is a reproducible build file hash, not a timestamp)
fffff806`65300000 fffff806`653d5000   Wdf01000 Wdf01000.sys 116A658A (This is a reproducible build file hash, not a timestamp)
fffff806`653e0000 fffff806`653f3000   WDFLDR   WDFLDR.SYS   3B396780 (This is a reproducible build file hash, not a timestamp)
fffff806`64e20000 fffff806`64e31000   werkernel werkernel.sys 958E14B2 (This is a reproducible build file hash, not a timestamp)
fffff806`662e0000 fffff806`66310000   wfplwfs  wfplwfs.sys  60902CBB (This is a reproducible build file hash, not a timestamp)
ffffdba2`6b670000 ffffdba2`6b6fc000   win32k   win32k.sys   00000000 (This is a reproducible build file hash, not a timestamp)
ffffdba2`6adb0000 ffffdba2`6b055000   win32kbase win32kbase.sys 00000000 (This is a reproducible build file hash, not a timestamp)
ffffdba2`6aa00000 ffffdba2`6ada2000   win32kfull win32kfull.sys 00000000 (This is a reproducible build file hash, not a timestamp)
fffff806`65610000 fffff806`65627000   WindowsTrustedRT WindowsTrustedRT.sys CB95CE3D (This is a reproducible build file hash, not a timestamp)
fffff806`65630000 fffff806`6563b000   WindowsTrustedRTProxy WindowsTrustedRTProxy.sys 514E3023 (This is a reproducible build file hash, not a timestamp)
fffff806`67640000 fffff806`6765f000   winhvr   winhvr.sys   8D332864 (This is a reproducible build file hash, not a timestamp)
fffff806`66ce0000 fffff806`66d18000   winquic  winquic.sys  D60F7863 (This is a reproducible build file hash, not a timestamp)
fffff806`655a0000 fffff806`655ac000   WMILIB   WMILIB.SYS   59021E3D (This is a reproducible build file hash, not a timestamp)
fffff806`65a20000 fffff806`65a5d000   Wof      Wof.sys      EE8C7600 (This is a reproducible build file hash, not a timestamp)
fffff806`65410000 fffff806`65420000   WppRecorder WppRecorder.sys 34A54231 (This is a reproducible build file hash, not a timestamp)

Unloaded modules:
fffff806`63820000 fffff806`6382f000   hiber_storpo
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000F000
fffff806`63830000 fffff806`6385f000   hiber_storah
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0002F000
fffff806`63860000 fffff806`6387e000   hiber_dumpfv
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0001E000
fffff806`63700000 fffff806`63724000   mwac.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00024000
fffff806`63790000 fffff806`6379f000   hiber_storpo
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000F000
fffff806`637a0000 fffff806`637cf000   hiber_storah
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0002F000
fffff806`637d0000 fffff806`637ee000   hiber_dumpfv
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0001E000
fffff806`63730000 fffff806`6373f000   hiber_storpo
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000F000
fffff806`63740000 fffff806`6376f000   hiber_storah
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0002F000
fffff806`63770000 fffff806`6378e000   hiber_dumpfv
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0001E000
fffff806`634e0000 fffff806`63504000   mwac.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00024000
fffff806`63510000 fffff806`6351f000   hiber_storpo
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000F000
fffff806`63520000 fffff806`6354f000   hiber_storah
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0002F000
fffff806`63550000 fffff806`6356e000   hiber_dumpfv
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0001E000
fffff806`63450000 fffff806`63474000   mwac.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00024000
fffff806`63480000 fffff806`6348f000   hiber_storpo
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000F000
fffff806`63490000 fffff806`634bf000   hiber_storah
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0002F000
fffff806`634c0000 fffff806`634de000   hiber_dumpfv
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0001E000
fffff806`63960000 fffff806`63984000   mwac.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00024000
fffff806`639f0000 fffff806`639ff000   hiber_storpo
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000F000
fffff806`63400000 fffff806`6342f000   hiber_storah
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0002F000
fffff806`63430000 fffff806`6344e000   hiber_dumpfv
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0001E000
fffff806`63990000 fffff806`6399f000   hiber_storpo
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000F000
fffff806`639a0000 fffff806`639cf000   hiber_storah
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0002F000
fffff806`639d0000 fffff806`639ee000   hiber_dumpfv
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0001E000
fffff806`638d0000 fffff806`638f4000   mwac.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00024000
fffff806`63900000 fffff806`6390f000   hiber_storpo
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000F000
fffff806`63910000 fffff806`6393f000   hiber_storah
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0002F000
fffff806`63940000 fffff806`6395e000   hiber_dumpfv
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0001E000
fffff806`6b1d0000 fffff806`6b1f4000   mwac.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00024000
fffff806`6b250000 fffff806`6b25f000   hiber_storpo
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000F000
fffff806`63860000 fffff806`6388f000   hiber_storah
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0002F000
fffff806`63890000 fffff806`638ae000   hiber_dumpfv
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0001E000
fffff806`6b250000 fffff806`6b258000   magdrvamd64.
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00008000
fffff806`6b250000 fffff806`6b258000   magdrvamd64.
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00008000
fffff806`6b250000 fffff806`6b25b000   NvStreamKms.
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000B000
fffff806`6b250000 fffff806`6b25b000   NvStreamKms.
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000B000
fffff806`6b250000 fffff806`6b25b000   NvStreamKms.
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000B000
fffff806`6b250000 fffff806`6b25b000   NvStreamKms.
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000B000
fffff806`6b250000 fffff806`6b25f000   hiber_storpo
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000F000
fffff806`66db0000 fffff806`66ddf000   hiber_storah
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0002F000
fffff806`66de0000 fffff806`66dfe000   hiber_dumpfv
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0001E000
fffff806`5f410000 fffff806`5f46d000   WdFilter.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0005D000
fffff806`5f470000 fffff806`5f483000   WdNisDrv.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00013000
fffff806`66c70000 fffff806`66c7f000   dump_storpor
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000F000
fffff806`66cb0000 fffff806`66cdf000   dump_storahc
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0002F000
fffff806`66d00000 fffff806`66d1e000   dump_dumpfve
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0001E000
fffff806`67520000 fffff806`6753e000   dam.sys 
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0001E000
fffff806`66510000 fffff806`66520000   hwpolicy.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00010000
dps ffffe18fb39eb000 ffffe18fb39f0ff8
ffffe18f`b39eb000  00000000`00010084
ffffe18f`b39eb008  00000000`16fe6220
ffffe18f`b39eb010  00000000`00001000
ffffe18f`b39eb018  00000000`00010091
ffffe18f`b39eb020  00000000`0000000f
ffffe18f`b39eb028  0000002d`bd5fbb49
ffffe18f`b39eb030  00000001`0000008c
ffffe18f`b39eb038  00000000`ffffffff
ffffe18f`b39eb040  00640069`006c0000
ffffe18f`b39eb048  00000001`0076008d
ffffe18f`b39eb050  00000000`80001804
ffffe18f`b39eb058  00000000`00000007
ffffe18f`b39eb060  00000001`c09a008e
ffffe18f`b39eb068  00000000`f5bf3fbe
ffffe18f`b39eb070  00000011`bd8aa87f
ffffe18f`b39eb078  00000000`2b170090
ffffe18f`b39eb080  00000000`0000000f
ffffe18f`b39eb088  000f4104`0253fc20
ffffe18f`b39eb090  00000000`001c0093
ffffe18f`b39eb098  00000000`00000001
ffffe18f`b39eb0a0  06a45e27`0014f1c0
ffffe18f`b39eb0a8  00000001`00000098
ffffe18f`b39eb0b0  00000000`4baa1172
ffffe18f`b39eb0b8  00000000`00000000
ffffe18f`b39eb0c0  00000001`000f0099
ffffe18f`b39eb0c8  00010006`000200f6
ffffe18f`b39eb0d0  0000e162`00013bb8
ffffe18f`b39eb0d8  00000001`0000009e
ffffe18f`b39eb0e0  00000000`0002bca8
ffffe18f`b39eb0e8  00000000`00be7065
ffffe18f`b39eb0f0  00000001`0000009f
ffffe18f`b39eb0f8  00000000`000249f0
ffffe18f`b39eb100  ????????`????????
ffffe18f`b39eff20  ????????`????????
ffffe18f`b39eff28  ????????`????????
ffffe18f`b39eff30  00000000`00000000
ffffe18f`b39eff38  00000000`00000000
ffffe18f`b39eff40  fffff806`66c4faf0 crashdmp!Context+0x50
ffffe18f`b39eff48  00000000`00000000
ffffe18f`b39eff50  00000000`00000000
ffffe18f`b39eff58  00000000`00000000
ffffe18f`b39eff60  00000001`00000000
ffffe18f`b39eff68  0001c305`00000001
ffffe18f`b39eff70  00000000`00000000
ffffe18f`b39eff78  00000000`0022e600
ffffe18f`b39eff80  00000000`00000000
ffffe18f`b39eff88  00000000`001beb95
ffffe18f`b39eff90  00000000`00000000
ffffe18f`b39eff98  00000000`00000000
ffffe18f`b39effa0  00000000`00033e6f
ffffe18f`b39effa8  00000000`0001c305
ffffe18f`b39effb0  00000000`00033e6f
ffffe18f`b39effb8  00000000`0022e600
ffffe18f`b39effc0  ffffa208`d7946038
ffffe18f`b39effc8  ffffa208`d8e28200
ffffe18f`b39effd0  00000000`00000000
ffffe18f`b39effd8  ffffa208`d8e28200
ffffe18f`b39effe0  00000000`00040000
ffffe18f`b39effe8  fffff806`6028c520 nt!HvlGetEncryptedData
ffffe18f`b39efff0  fffff806`602a95e0 nt!KiBugCheckProgress
ffffe18f`b39efff8  00000000`00000001
ffffe18f`b39f0000  fffff806`66c4faf0 crashdmp!Context+0x50
ffffe18f`b39f0008  fffff806`66c46265 crashdmp!DumpWrite+0x3d9
ffffe18f`b39f0010  fffff806`66c4faf0 crashdmp!Context+0x50
ffffe18f`b39f0018  fffff806`602a95e0 nt!KiBugCheckProgress
ffffe18f`b39f0020  fffff806`6028c520 nt!HvlGetEncryptedData
ffffe18f`b39f0028  fffff806`66c4b800 crashdmp!CrashdmpTelemetryGetEnvironmentVariable+0x5c
ffffe18f`b39f0030  ffff5c09`418d7b00
ffffe18f`b39f0038  fffff806`66c41d61 crashdmp!CheckContextIntegrity+0x71
ffffe18f`b39f0040  ffffa208`d8e282c0
ffffe18f`b39f0048  ffffa208`d9dcf080
ffffe18f`b39f0050  fffff806`602a95e0 nt!KiBugCheckProgress
ffffe18f`b39f0058  00000000`000000ef
ffffe18f`b39f0060  ????????`????????
ffffe18f`b39f0930  ????????`????????
ffffe18f`b39f0938  fffff806`608cae89 nt!PspCatchCriticalBreak+0x115
ffffe18f`b39f0940  00000000`000000ef
ffffe18f`b39f0948  ffffa208`d8e282c0
ffffe18f`b39f0950  00000000`00000000
ffffe18f`b39f0958  00000000`00000000
ffffe18f`b39f0960  00000000`00000000
ffffe18f`b39f0968  00000000`00000001
ffffe18f`b39f0970  00000000`00000000
ffffe18f`b39f0978  00000000`00000000
ffffe18f`b39f0980  00000000`00000000
ffffe18f`b39f0988  00000000`00000000
ffffe18f`b39f0990  00000000`00000000
ffffe18f`b39f0998  00000000`00000000
ffffe18f`b39f09a0  00000000`00000000
ffffe18f`b39f09a8  ffff785c`f0db8a2d
ffffe18f`b39f09b0  00000000`c0000409
ffffe18f`b39f09b8  ffffa208`d9dcf080
ffffe18f`b39f09c0  ffffa208`d8e282c0
ffffe18f`b39f09c8  00000000`00000000
ffffe18f`b39f09d0  00000000`c0000409
ffffe18f`b39f09d8  fffff806`607c75c1 nt!PspTerminateAllThreads+0x175e3d
ffffe18f`b39f09e0  ffffa208`d8e282c0
ffffe18f`b39f09e8  fffff806`6009c769 nt!EtwTraceProcessTerminate+0x61
ffffe18f`b39f09f0  ffffa208`d8e282c0
ffffe18f`b39f09f8  fffff806`6009c8c0 nt!KeSetProcessSchedulingGroup+0x5c
ffffe18f`b39f0a00  ffffa208`c0000409
ffffe18f`b39f0a08  fffff806`60039c1d nt!ExAcquirePushLockExclusiveEx+0xed
ffffe18f`b39f0a10  ffffa208`d9dcf080
ffffe18f`b39f0a18  00000000`00000000
ffffe18f`b39f0a20  00000000`c0000409
ffffe18f`b39f0a28  00007ffc`4b7a6001
ffffe18f`b39f0a30  00000000`00000000
ffffe18f`b39f0a38  ffffa208`d8e285a0
ffffe18f`b39f0a40  00000000`c0000409
ffffe18f`b39f0a48  fffff806`60639fc0 nt!PspTerminateProcess+0xe0
ffffe18f`b39f0a50  ffffa208`00000000
ffffe18f`b39f0a58  00000000`00000000
ffffe18f`b39f0a60  ffffa208`d8e282c0
ffffe18f`b39f0a68  ffffa208`d8e282c0
ffffe18f`b39f0a70  00000000`00000000
ffffe18f`b39f0a78  ffffa208`d8e282c0
ffffe18f`b39f0a80  ffffa208`d9dcf080
ffffe18f`b39f0a88  fffff806`60639da9 nt!NtTerminateProcess+0xa9
ffffe18f`b39f0a90  ffffffff`ffffffff
ffffe18f`b39f0a98  ffffe18f`b39f0b80
ffffe18f`b39f0aa0  ffffa208`dce8f080
ffffe18f`b39f0aa8  00000000`00000501
ffffe18f`b39f0ab0  00000000`65547350
ffffe18f`b39f0ab8  ffffe18f`b39f0b00
ffffe18f`b39f0ac0  00000000`00000000
ffffe18f`b39f0ac8  ffff920e`23bf0c00
ffffe18f`b39f0ad0  00000000`80004005
ffffe18f`b39f0ad8  00000000`0000024c
ffffe18f`b39f0ae0  0000025d`ded60000
ffffe18f`b39f0ae8  00007ffc`4b7a6038
ffffe18f`b39f0af0  00000000`00000000
ffffe18f`b39f0af8  fffff806`601d2d18 nt!KiSystemServiceCopyEnd+0x28
ffffe18f`b39f0b00  ffffa208`000003b8
ffffe18f`b39f0b08  ffffa208`d9dcf080
ffffe18f`b39f0b10  ffffa208`d8e282c0
ffffe18f`b39f0b18  00007ffc`4b79bb88
ffffe18f`b39f0b20  00000000`00000000
ffffe18f`b39f0b28  00001f80`02080000
ffffe18f`b39f0b30  00000000`0000002c
ffffe18f`b39f0b38  00000000`00000248
ffffe18f`b39f0b40  00000000`c0000409
ffffe18f`b39f0b48  00000000`00000000
ffffe18f`b39f0b50  000000bb`cfbfda50
ffffe18f`b39f0b58  00000000`00000000
ffffe18f`b39f0b60  00000000`00000246
ffffe18f`b39f0b68  000000bb`cf4dd000
ffffe18f`b39f0b70  00000000`00000000
ffffe18f`b39f0b78  00000000`00000000
ffffe18f`b39f0b80  00000000`00000000
ffffe18f`b39f0b88  00000000`00000000
ffffe18f`b39f0b90  00000000`00000000
ffffe18f`b39f0b98  00000000`00000000
ffffe18f`b39f0ba0  00000000`00000000
ffffe18f`b39f0ba8  00000000`00000000
ffffe18f`b39f0bb0  00000000`00000000
ffffe18f`b39f0bb8  00000000`00000000
ffffe18f`b39f0bc0  00000000`00000000
ffffe18f`b39f0bc8  00000000`00000000
ffffe18f`b39f0bd0  00007ffc`62260000
ffffe18f`b39f0bd8  00000000`00000000
ffffe18f`b39f0be0  00000000`00000000
ffffe18f`b39f0be8  00000000`00000000
ffffe18f`b39f0bf0  00000000`00000000
ffffe18f`b39f0bf8  00000000`00000000
ffffe18f`b39f0c00  00000000`00000000
ffffe18f`b39f0c08  00000000`00000000
ffffe18f`b39f0c10  00000000`00000000
ffffe18f`b39f0c18  00000000`00000000
ffffe18f`b39f0c20  00000000`00000000
ffffe18f`b39f0c28  00000000`00000000
ffffe18f`b39f0c30  00000000`00000000
ffffe18f`b39f0c38  00000000`00000000
ffffe18f`b39f0c40  00000000`00000248
ffffe18f`b39f0c48  00000000`c0000409
ffffe18f`b39f0c50  00007ffc`4b79bb88
ffffe18f`b39f0c58  00000000`00000000
ffffe18f`b39f0c60  000000bb`cfbfd980
ffffe18f`b39f0c68  00007ffc`6223c644
ffffe18f`b39f0c70  00000000`00000033
ffffe18f`b39f0c78  00000000`00000246
ffffe18f`b39f0c80  000000bb`cfbfebc8
ffffe18f`b39f0c88  00000000`0000002b
ffffe18f`b39f0c90  ffffe18f`b39f1000
ffffe18f`b39f0c98  ffffe18f`b39eb000
ffffe18f`b39f0ca0  00000000`00000000
ffffe18f`b39f0ca8  00000000`00000000
ffffe18f`b39f0cb0  00000000`00000000
ffffe18f`b39f0cb8  00000000`00000000
ffffe18f`b39f0cc0  00000000`0000027f
ffffe18f`b39f0cc8  00000000`00000000
ffffe18f`b39f0cd0  00000000`00000000
ffffe18f`b39f0cd8  0000ffff`00001f80
ffffe18f`b39f0ce0  00000000`00000000
ffffe18f`b39f0ce8  00000000`00000000
ffffe18f`b39f0cf0  00000000`00000000
ffffe18f`b39f0cf8  00000000`00000000
ffffe18f`b39f0d00  00000000`00000000
ffffe18f`b39f0d08  00000000`00000000
ffffe18f`b39f0d10  00000000`00000000
ffffe18f`b39f0d18  00000000`00000000
ffffe18f`b39f0d20  00000000`00000000
ffffe18f`b39f0d28  00000000`00000000
ffffe18f`b39f0d30  00000000`00000000
ffffe18f`b39f0d38  00000000`00000000
ffffe18f`b39f0d40  00000000`00000000
ffffe18f`b39f0d48  00000000`00000000
ffffe18f`b39f0d50  00000000`00000000
ffffe18f`b39f0d58  00000000`00000000
ffffe18f`b39f0d60  00000000`00000000
ffffe18f`b39f0d68  00000000`00000000
ffffe18f`b39f0d70  00000000`00000000
ffffe18f`b39f0d78  00000000`00000000
ffffe18f`b39f0d80  00000000`00000000
ffffe18f`b39f0d88  00000000`00000000
ffffe18f`b39f0d90  00000000`00000000
ffffe18f`b39f0d98  00000000`00000000
ffffe18f`b39f0da0  00000000`00000000
ffffe18f`b39f0da8  00000000`00000000
ffffe18f`b39f0db0  00000000`00000000
ffffe18f`b39f0db8  00000000`00000000
ffffe18f`b39f0dc0  00000000`00000000
ffffe18f`b39f0dc8  00000000`00000000
ffffe18f`b39f0dd0  00000000`00000000
ffffe18f`b39f0dd8  00000000`00000000
ffffe18f`b39f0de0  00000000`00000000
ffffe18f`b39f0de8  00000000`00000000
ffffe18f`b39f0df0  00000000`00000000
ffffe18f`b39f0df8  00000000`00000000
ffffe18f`b39f0e00  00000000`00000000
ffffe18f`b39f0e08  00000000`00000000
ffffe18f`b39f0e10  00000000`00000000
ffffe18f`b39f0e18  00000000`00000000
ffffe18f`b39f0e20  00000000`00000000
ffffe18f`b39f0e28  00000000`00000000
ffffe18f`b39f0e30  00000000`00000000
ffffe18f`b39f0e38  00000000`00000000
ffffe18f`b39f0e40  00000000`00000000
ffffe18f`b39f0e48  00000000`00000000
ffffe18f`b39f0e50  00000000`00000000
ffffe18f`b39f0e58  00000000`00000000
ffffe18f`b39f0e60  00000000`00000000
ffffe18f`b39f0e68  00000000`00000000
ffffe18f`b39f0e70  00000000`00000000
ffffe18f`b39f0e78  00000000`00000000
ffffe18f`b39f0e80  00000000`00000000
ffffe18f`b39f0e88  00000000`00000000
ffffe18f`b39f0e90  00000000`00000000
ffffe18f`b39f0e98  00000000`00000000
ffffe18f`b39f0ea0  00000000`00000000
ffffe18f`b39f0ea8  00000000`00000000
ffffe18f`b39f0eb0  00000000`00000000
ffffe18f`b39f0eb8  00000000`00000000
ffffe18f`b39f0ec0  00000000`00000001
ffffe18f`b39f0ec8  00000000`00000000
ffffe18f`b39f0ed0  00000000`00000000
ffffe18f`b39f0ed8  00000000`00000000
ffffe18f`b39f0ee0  00000000`00000000
ffffe18f`b39f0ee8  00000000`00000000
ffffe18f`b39f0ef0  00000000`00000000
ffffe18f`b39f0ef8  00000000`00000000
ffffe18f`b39f0f00  00000000`00000000
ffffe18f`b39f0f08  00000000`00000000
ffffe18f`b39f0f10  00000000`00000000
ffffe18f`b39f0f18  00000000`00000000
ffffe18f`b39f0f20  00000000`00000000
ffffe18f`b39f0f28  00000000`00000000
ffffe18f`b39f0f30  00000000`00000000
ffffe18f`b39f0f38  00000000`00000000
ffffe18f`b39f0f40  00000000`00000000
ffffe18f`b39f0f48  00000000`00000000
ffffe18f`b39f0f50  00000000`00000000
ffffe18f`b39f0f58  00000000`00000000
ffffe18f`b39f0f60  00000000`00000000
ffffe18f`b39f0f68  00000000`00000000
ffffe18f`b39f0f70  00000000`00000000
ffffe18f`b39f0f78  00000000`00000000
ffffe18f`b39f0f80  00000000`00000000
ffffe18f`b39f0f88  00000000`00000000
ffffe18f`b39f0f90  00000000`00000000
ffffe18f`b39f0f98  00000000`00000000
ffffe18f`b39f0fa0  00000000`00000000
ffffe18f`b39f0fa8  00000000`00000000
ffffe18f`b39f0fb0  00000000`00000000
ffffe18f`b39f0fb8  00000000`00000000
ffffe18f`b39f0fc0  00000000`00000000
ffffe18f`b39f0fc8  00000000`00000000
ffffe18f`b39f0fd0  00000000`00000000
ffffe18f`b39f0fd8  00000000`00000000
ffffe18f`b39f0fe0  00000000`00000000
ffffe18f`b39f0fe8  00000000`00000000
ffffe18f`b39f0ff0  00000000`00000000
ffffe18f`b39f0ff8  00000000`00000000
Start memory scan  : 0xffffe18fb39f0938 ($csp)
End memory scan    : 0xffffe18fb39f1000 (Kernel Stack Base)

               rsp : 0xffffe18fb39f0938 : 0xfffff806608cae89 : nt!PspCatchCriticalBreak+0x115
               r15 : 0xffffa208d8e28710 :  !da "svchost.exe"
0xffffe18fb39f0938 : 0xfffff806608cae89 : nt!PspCatchCriticalBreak+0x115
0xffffe18fb39f09e8 : 0xfffff8066009c769 : nt!EtwTraceProcessTerminate+0x61
0xffffe18fb39f09f8 : 0xfffff8066009c8c0 : nt!KeSetProcessSchedulingGroup+0x5c
0xffffe18fb39f0a08 : 0xfffff80660039c1d : nt!ExAcquirePushLockExclusiveEx+0xed
0xffffe18fb39f0a48 : 0xfffff80660639fc0 : nt!PspTerminateProcess+0xe0
0xffffe18fb39f0a88 : 0xfffff80660639da9 : nt!NtTerminateProcess+0xa9
0xffffe18fb39f0af8 : 0xfffff806601d2d18 : nt!KiSystemServiceCopyEnd+0x28
0xffffe18fb39f0b00 : 0xffffa208000003b8 :  Trap @ ffffe18fb39f0b00

[SMBIOS Data Tables v2.7]
[DMI Version - 0]
[2.0 Calling Convention - No]
[Table Size - 3103 bytes]

[BIOS Information (Type 0) - Length 24 - Handle 0000h]
  Vendor                        American Megatrends Inc.
  BIOS Version                  F15
  BIOS Starting Address Segment f000
  BIOS Release Date             08/20/2015
  BIOS ROM Size                 800000
  BIOS Characteristics
       07: - PCI Supported
       11: - Upgradeable FLASH BIOS
       12: - BIOS Shadowing Supported
       15: - CD-Boot Supported
       16: - Selectable Boot Supported
       17: - BIOS ROM Socketed
       19: - EDD Supported
       23: - 1.2MB Floppy Supported
       24: - 720KB Floppy Supported
       25: - 2.88MB Floppy Supported
       26: - Print Screen Device Supported
       27: - Keyboard Services Supported
       28: - Serial Services Supported
       29: - Printer Services Supported
       32: - BIOS Vendor Reserved
  BIOS Characteristic Extensions
       00: - ACPI Supported
       01: - USB Legacy Supported
       08: - BIOS Boot Specification Supported
       10: - Enable Targeted Content Distribution
       11: - UEFI Specification Supported
  BIOS Major Revision           4
  BIOS Minor Revision           6
  EC Firmware Major Revision    255
  EC Firmware Minor Revision    255
[System Information (Type 1) - Length 27 - Handle 0001h]
  Manufacturer                  Gigabyte Technology Co., Ltd.
  Product Name                  B85M-D3H
  Version                       To be filled by O.E.M.
  Serial Number                 To be filled by O.E.M.
  UUID                          00000000-0000-0000-0000-000000000000
  Wakeup Type                   Power Switch
  SKUNumber                     To be filled by O.E.M.
  Family                        To be filled by O.E.M.
[BaseBoard Information (Type 2) - Length 15 - Handle 0002h]
  Manufacturer                  Gigabyte Technology Co., Ltd.
  Product                       B85M-D3H
  Version                       x.x
  Serial Number                 To be filled by O.E.M.
  Asset Tag                                           
  Feature Flags                 09h
       00: - Motherboard
       03: - Replaceable
  Location                      To be filled by O.E.M.
  Chassis Handle                0003h
  Board Type                    0ah - Processor/Memory Module
  Number of Child Handles       0
[System Enclosure (Type 3) - Length 22 - Handle 0003h]
  Manufacturer                  Gigabyte Technology Co., Ltd.
  Chassis Type                  Desktop
  Version                       To Be Filled By O.E.M.
  Serial Number                                       
  Asset Tag Number                                    
  Bootup State                  Safe
  Power Supply State            Safe
  Thermal State                 Safe
  Security Status               None
  OEM Defined                   0
  Height                        0U
  Number of Power Cords         1
  Number of Contained Elements  0
  Contained Element Size        0
[Cache Information (Type 7) - Length 19 - Handle 0004h]
  Socket Designation            CPU Internal L1
  Cache Configuration           0180h - WB Enabled Int NonSocketed L1
  Maximum Cache Size            0100h - 256K
  Installed Size                0100h - 256K
  Supported SRAM Type           0002h - Unknown 
  Current SRAM Type             0002h - Unknown 
  Cache Speed                   0ns
  Error Correction Type         Multi-Bit ECC
  System Cache Type             Other
  Associativity                 8-way Set-Associative
[Cache Information (Type 7) - Length 19 - Handle 0005h]
  Socket Designation            CPU Internal L2
  Cache Configuration           0181h - WB Enabled Int NonSocketed L2
  Maximum Cache Size            0400h - 1024K
  Installed Size                0400h - 1024K
  Supported SRAM Type           0002h - Unknown 
  Current SRAM Type             0002h - Unknown 
  Cache Speed                   0ns
  Error Correction Type         Multi-Bit ECC
  System Cache Type             Unified
  Associativity                 8-way Set-Associative
[Cache Information (Type 7) - Length 19 - Handle 0006h]
  Socket Designation            CPU Internal L3
  Cache Configuration           0182h - WB Enabled Int NonSocketed L3
  Maximum Cache Size            2000h - 8192K
  Installed Size                2000h - 8192K
  Supported SRAM Type           0002h - Unknown 
  Current SRAM Type             0002h - Unknown 
  Cache Speed                   0ns
  Error Correction Type         Multi-Bit ECC
  System Cache Type             Unified
  Associativity                 16-way Set-Associative
[Physical Memory Array (Type 16) - Length 23 - Handle 0007h]
  Location                      03h - SystemBoard/Motherboard
  Use                           03h - System Memory
  Memory Error Correction       03h - None
  Maximum Capacity              33554432KB
  Memory Error Inf Handle       [Not Provided]
  Number of Memory Devices      4
[Onboard Devices Information (Type 10) - Length 6 - Handle 0026h]
  Number of Devices             1
  01: Type                      Video [enabled]
  01: Description                  To Be Filled By O.E.M.
[OEM Strings (Type 11) - Length 5 - Handle 0027h]
  Number of Strings             5
   1                            To Be Filled By O.E.M.
   2                            To Be Filled By O.E.M.
   3                            To Be Filled By O.E.M.
   4                            To Be Filled By O.E.M.
   5                            To Be Filled By O.E.M.
[System Configuration Options (Type 12) - Length 5 - Handle 0028h]
[Processor Information (Type 4) - Length 42 - Handle 0041h]
  Socket Designation            SOCKET 0
  Processor Type                Central Processor
  Processor Family              c6h - Specification Reserved
  Processor Manufacturer        Intel
  Processor ID                  c3060300fffbebbf
  Processor Version             Intel(R) Core(TM) i7-4770 CPU @ 3.40GHz
  Processor Voltage             8ah - 1.0V
  External Clock                100MHz
  Max Speed                     7000MHz
  Current Speed                 3700MHz
  Status                        Enabled Populated
  Processor Upgrade             Other
  L1 Cache Handle               0004h
  L2 Cache Handle               0005h
  L3 Cache Handle               0006h
  Serial Number                 [String Not Specified]
  Asset Tag Number                         
  Part Number                   Fill By OEM
[Memory Device (Type 17) - Length 34 - Handle 0042h]
  Physical Memory Array Handle  0007h
  Memory Error Info Handle      [Not Provided]
  Total Width                   64 bits
  Data Width                    64 bits
  Size                          8192MB
  Form Factor                   09h - DIMM
  Device Set                    [None]
  Device Locator                ChannelA-DIMM0
  Bank Locator                  BANK 0
  Memory Type                   18h - Specification Reserved
  Type Detail                   0080h - Synchronous
  Speed                         1333MHz
  Manufacturer                  Kingston
  Serial Number                         
  Asset Tag Number                        
  Part Number                   KHX1600C10D3/8GX  
[Memory Device Mapped Address (Type 20) - Length 35 - Handle 0043h]
  Starting Address              00000000h
  Ending Address                007fffffh
  Memory Device Handle          0042h
  Mem Array Mapped Adr Handle   0047h
  Partition Row Position        [Unknown]
  Interleave Position           [Unknown]
  Interleave Data Depth         [Unknown]
  Extended Starting Address     0000000000000000h
  Extended Ending Address       0000000000000000h
[Memory Device (Type 17) - Length 34 - Handle 0044h]
  Physical Memory Array Handle  0007h
  Memory Error Info Handle      [Not Provided]
  Total Width                   0 bits
  Data Width                    0 bits
  Size                          [Not Populated]
  Form Factor                   09h - DIMM
  Device Set                    [None]
  Device Locator                ChannelA-DIMM1
  Bank Locator                  BANK 1
  Memory Type                   02h - Unknown
  Type Detail                   0000h -
  Speed                         0MHz
  Manufacturer                  [Empty]
  Serial Number                        
  Asset Tag Number                        
  Part Number                   [Empty]
[Memory Device (Type 17) - Length 34 - Handle 0045h]
  Physical Memory Array Handle  0007h
  Memory Error Info Handle      [Not Provided]
  Total Width                   0 bits
  Data Width                    0 bits
  Size                          [Not Populated]
  Form Factor                   09h - DIMM
  Device Set                    [None]
  Device Locator                ChannelB-DIMM0
  Bank Locator                  BANK 2
  Memory Type                   02h - Unknown
  Type Detail                   0000h -
  Speed                         0MHz
  Manufacturer                  [Empty]
  Serial Number                        
  Asset Tag Number                        
  Part Number                   [Empty]
[Memory Device (Type 17) - Length 34 - Handle 0046h]
  Physical Memory Array Handle  0007h
  Memory Error Info Handle      [Not Provided]
  Total Width                   0 bits
  Data Width                    0 bits
  Size                          [Not Populated]
  Form Factor                   09h - DIMM
  Device Set                    [None]
  Device Locator                ChannelB-DIMM1
  Bank Locator                  BANK 3
  Memory Type                   02h - Unknown
  Type Detail                   0000h -
  Speed                         0MHz
  Manufacturer                  [Empty]
  Serial Number                        
  Asset Tag Number                        
  Part Number                   [Empty]
[Memory Array Mapped Address (Type 19) - Length 31 - Handle 0047h]
  Starting Address              00000000h
  Ending Address                007fffffh
  Memory Array Handle           0007h
  Partition Width               04
  Extended Starting Address     0000000000000000h
  Extended Ending Address       0000000000000000h
Machine ID Information [From Smbios 2.7, DMIVersion 0, Size=3103]
BiosMajorRelease = 4
BiosMinorRelease = 6
BiosVendor = American Megatrends Inc.
BiosVersion = F15
BiosReleaseDate = 08/20/2015
SystemManufacturer = Gigabyte Technology Co., Ltd.
SystemProductName = B85M-D3H
SystemFamily = To be filled by O.E.M.
SystemVersion = To be filled by O.E.M.
SystemSKU = To be filled by O.E.M.
BaseBoardManufacturer = Gigabyte Technology Co., Ltd.
BaseBoardProduct = B85M-D3H
BaseBoardVersion = x.x
CPUID:        "Intel(R) Core(TM) i7-4770 CPU @ 3.40GHz"
MaxSpeed:     3400
CurrentSpeed: 3392
THREAD ffffa208d9dcf080  Cid 29b8.05f0  Teb: 000000bbcf4dd000 Win32Thread: 0000000000000000 RUNNING on processor 5
Not impersonating
GetUlongFromAddress: unable to read from fffff8066042ca14
Owning Process            ffffa208dce8f080       Image:         
Attached Process          ffffa208d8e282c0       Image:         svchost.exe
fffff78000000000: Unable to get shared data
Wait Start TickCount      16626473     
Context Switch Count      128            IdealProcessor: 0             
ReadMemory error: Cannot get nt!KeMaximumIncrement value.
UserTime                  00:00:00.000
KernelTime                00:00:00.000
Win32 Start Address 0x00007ffc621d3d60
Stack Init ffffe18fb39f0c90 Current ffffe18fb39eff30
Base ffffe18fb39f1000 Limit ffffe18fb39eb000 Call 0000000000000000
Priority 8 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5
Child-SP          RetAddr           : Args to Child                                                           : Call Site
ffffe18f`b39f0938 fffff806`608cae89 : 00000000`000000ef ffffa208`d8e282c0 00000000`00000000 00000000`00000000 : nt!KeBugCheckEx
ffffe18f`b39f0940 fffff806`607c75c1 : ffffa208`d8e282c0 fffff806`6009c769 ffffa208`d8e282c0 fffff806`6009c8c0 : nt!PspCatchCriticalBreak+0x115
ffffe18f`b39f09e0 fffff806`60639fc0 : ffffa208`00000000 00000000`00000000 ffffa208`d8e282c0 ffffa208`d8e282c0 : nt!PspTerminateAllThreads+0x175e3d
ffffe18f`b39f0a50 fffff806`60639da9 : ffffffff`ffffffff ffffe18f`b39f0b80 ffffa208`dce8f080 00000000`00000501 : nt!PspTerminateProcess+0xe0
ffffe18f`b39f0a90 fffff806`601d2d18 : ffffa208`000003b8 ffffa208`d9dcf080 ffffa208`d8e282c0 00007ffc`4b79bb88 : nt!NtTerminateProcess+0xa9
ffffe18f`b39f0b00 00007ffc`6223c644 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28 (TrapFrame @ ffffe18f`b39f0b00)
000000bb`cfbfebc8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffc`6223c644

Bugcheck code 000000EF
Arguments ffffa208`d8e282c0 00000000`00000000 00000000`00000000 00000000`00000000
Debug session time: Mon Jan 27 18:15:47.999 2020 (UTC + 1:00)
System Uptime: 3 days 0:09:48.650
To put it plain and simple, there's no reason for privacy or security concerns in minidump files, they do not contain any sensitive information.
 

Colif

Win 11 Master
Moderator
while axe waits for the files:

Sep 20 2018e2xw10x64.sysKiller PCI-E Gigabit Ethernet Controller driver
can cause BSOD, I would update it using https://support.killernetworking.com/download/killer-drivers-installation-64bit/
one error occurred while running VPN software so could be the killer drivers.

Apr 18 2019iocbios2.sys!!! Overclocking Software - Intel(R) Extreme Tuning Utility Performance Tuning driver
can cause WhEA errors as it is an overclocking driver - try removing it if you don't use it.

I assume you sent this to axe but I give him parameters he was after

IRQL_NOT_LESS_OR_EQUAL (a)
Arguments:
Arg1: 000000000000005c, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff8001e23c3c6, address which referenced memory
PROCESS_NAME: Ableton Live 9 (note to op, this is what crashed, not the cause)

PAGE_FAULT_IN_NONPAGED_AREA (50)
Arguments:
Arg1: ffffb603433bf080, memory referenced.
Arg2: 0000000000000011, value 0 = read operation, 1 = write operation.
Arg3: ffffb603433bf080, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000002, (reserved)
PROCESS_NAME: Ableton Live 9

UNEXPECTED_KERNEL_MODE_TRAP_M (1000007f)
Arguments:
Arg1: 0000000000000008, EXCEPTION_DOUBLE_FAULT
Arg2: ffff8e00e23cb2b0
Arg3: ffff9e0568930f60
Arg4: fffff8074f9cf1d0
PROCESS_NAME: Ableton Live 9

(3 in a row, same process.. sound drivers? chipset drivers? BIOS?)

DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
Arguments:
Arg1: fffff805fabd2a76, memory referenced
Arg2: 00000000000000ff, IRQL
Arg3: 0000000000000000, value 0 = read operation, 1 = write operation
Arg4: fffff805fabd2a76, address which referenced memory
PROCESS_NAME: IPVanish.exe

the last two errors say - Cannot read PEB32 from WOW64 TEB32 003f4000 - Win32 error 0n30 - which I cannot say I have seen before.

WHEA_UNCORRECTABLE_ERROR (124)
Arguments:
Arg1: 0000000000000000, Machine Check Exception
Arg2: ffffa00589b2b028, Address of the WHEA_ERROR_RECORD structure.
Arg3: 00000000b2000000, High order 32-bits of the MCi_STATUS value.
Arg4: 0000000000030005, Low order 32-bits of the MCi_STATUS value.
PROCESS_NAME: System
FAILURE_ID_HASH_STRING: km:0x124_genuineintel_processor_mae
FAILURE_ID_HASH: {7c95de0c-286c-8226-45c2-422b4de101d6}

if you send dumps to Axe, he can figure out way more than I can :)
 
I received the dumps via PM yesterday and noticed a few things.

Please ensure the pagefile is managed by Windows on the partition where Windows is located and that no custom settings are configured.
Code:
KEY_VALUES_STRING: 1

    Key  : Dump.Attributes.InsufficientDumpfileSize
    Value: 1

I also noticed a network driver that is commonly used by different programs such as VPNs and hardware such as USB network adapter. In order to pinpoint I ask that you download and run https://www.sysnative.com/forums/pages/bsodcollectionapp/, this tool will collect a variety of files.
The files it will collect mainly consist of logs like event logs Windows Error Report logs, hardware information, installed programs, a list of drivers, system information and configuration related to crashes and of course dump files.

With these files, some of them may contain what some consider 'private information' which is inevitable. Event logs may have the path to a program that crashed which may accidentally point to the roaming folder where it is installed which is located within the folder of your username, for example. Please note that I say 'may' as I cannot tell with certainty, but since I am familiar with your view on privacy/security I give you a heads up and let you choose how you would like to provide the zip file (PM or in this thread).
 
Feb 2, 2020
11
0
10
@Colif
I installed the newest Killer drivers.

I removed XTU for now, even though I do use it occasionally.

@axe0axe0
I allowed the system to manage the pagefile size. It demanded 8gb a staggering 32 gb, and I thought that was not reasonable, which is why I nerfed it to begin with.

I am PM-ing you the .zip file now from the sysnative tool.

Thank you!
 
Last edited:
I allowed the system to manage the pagefile size. It demanded 8gb a staggering 32 gb, and I thought that was not reasonable, which is why I nerfed it to begin with.
8GB is normal, about the size of the RAM is normal. The pagefile has many important roles in Windows. Its main job is to allow the memory to not be filled up to the limits by moving data from the RAM to the pagefile that hasn't been used in a while, thus the pagefile, when managed by Windows, may grow and you could see a decrease of free space but the exact opposite is also possible.

Another important role, for crashes, is that the pagefile is used to temporarily store the kernel memory to have it 'converted' into a dump at startup, but it cannot do so when the size of the pagefile is not large enough for the kernel memory that needs to be stored.

Although the size of the kernel memory is commonly at most ~20% still it's best to let Windows manage the pagefile. If you, for any reason, change the startup and recovery settings in control panel and, for example, select a complete memory dump then you're saying that everything in the memory is to be stored in the pagefile in which case the pagefile needs to be of the same size as the RAM.

It's common for kernel dumps to be around a couple of hundred MBs up to a few GB large, but with a custom pagefile configuration, it's usually not possible to make kernel dumps of those sizes.

I notice your system hasn't been able to create memory dumps in a few months from the event logs, hopefully, that stops.
 
Feb 2, 2020
11
0
10
I notice your system hasn't been able to create memory dumps in a few months from the event logs, hopefully, that stops.

Yes, that seems correct. I presume you need to see the kernel memory dump next time it occurs?

Please be aware it could be anywhere from days to a week until it occurs again. It usually happens when the machine is idle and turns off the screen.
 
I'll let you know if I need a kernel dump.

I find it interesting to see that, regardless of lack of dumps, there are a lot of crashes, 71 to be precise, in the past few months.
Rich (BB code):
2020-02-02T21:21:51.504The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0xffffb603433bf080, 0x0000000000000011, 0xffffb603433bf080, 0x0000000000000002). A dump was saved in: C:\Windows\Minidump\020220-7703-01.dmp. Report Id: a0a7bdd6-751b-4fbf-86af-3d0cfb67856e.613
2020-02-02T18:57:14.566The computer has rebooted from a bugcheck. The bugcheck was: 0x0000000a (0x000000000000005c, 0x0000000000000002, 0x0000000000000000, 0xfffff8001e23c3c6). A dump was saved in: C:\Windows\Minidump\020220-7750-01.dmp. Report Id: 160e9e9d-8bfc-4a5e-ada6-8b40365936d5.1714
2020-01-30T10:13:54.444The computer has rebooted from a bugcheck. The bugcheck was: 0x1000007f (0x0000000000000008, 0xffff8e00e23cb2b0, 0xffff9e0568930f60, 0xfffff8074f9cf1d0). A dump was saved in: C:\Windows\Minidump\013020-7609-01.dmp. Report Id: e5665363-9fda-48a5-bc05-af2e66497f47.2333
2020-01-18T19:39:45.387The computer has rebooted from a bugcheck. The bugcheck was: 0x000000d1 (0xfffff805fabd2a76, 0x00000000000000ff, 0x0000000000000000, 0xfffff805fabd2a76). A dump was saved in: C:\Windows\Minidump\011820-9578-01.dmp. Report Id: c32b0a57-8a73-4747-a84b-580f0c9220ee.4284
2020-01-17T12:32:43.573The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffa00589b2b028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\011720-11765-01.dmp. Report Id: 2222d048-bfa5-49fb-b04f-2f28b812ae66.4651
2020-01-16T04:07:13.132The computer has rebooted from a bugcheck. The bugcheck was: 0x00000139 (0x0000000000000003, 0xffff8181a2e11f80, 0xffff8181a2e11ed8, 0x0000000000000000). A dump was saved in: C:\Windows\Minidump\011620-8328-01.dmp. Report Id: de8826df-64a4-4791-9a13-d52d8de7804e.5087
2019-12-31T20:08:17.340The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffa089f9917028, 0x00000000be000000, 0x0000000000800400). A dump was saved in: C:\Windows\Minidump\123119-11578-01.dmp. Report Id: 1e0c6eaa-c7e3-4595-b6f8-7fcdbfb56e4a.7757
2019-12-30T00:16:03.112The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffc60fbff2f028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\123019-12078-01.dmp. Report Id: 8cc9a994-a787-4d79-8640-0a0aa8be59fc.8373
2019-12-27T13:49:59.211The computer has rebooted from a bugcheck. The bugcheck was: 0x0000000a (0xfffffffffffffff8, 0x0000000000000002, 0x0000000000000000, 0xfffff8010e436300). A dump was saved in: C:\Windows\Minidump\122719-9359-01.dmp. Report Id: 67412704-7ffd-4477-897d-fb9c8d7ace8d.9219
2019-12-25T14:43:13.007The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffc5840732b028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\122519-9218-01.dmp. Report Id: a4cbc3ba-67d0-4364-bd5a-76d94a6bf62b.10092
2019-12-24T20:57:47.648The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffaa020f092028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\122419-9312-01.dmp. Report Id: a35604b0-7436-4795-8187-71b3742cd8dc.10283
2019-12-14T21:46:31.442The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffe283acada028, 0x00000000be000000, 0x0000000000800400). A dump was saved in: C:\Windows\Minidump\121419-7640-01.dmp. Report Id: 380beb55-1554-4a43-a895-00545a2ba6d3.12105
2019-12-14T17:00:18.043The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffb60aae13c028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\121419-9218-01.dmp. Report Id: fdd34eed-fba9-4cd1-885f-4190d5bc8a5b.12200
2019-12-09T17:28:25.305The computer has rebooted from a bugcheck. The bugcheck was: 0x0000000a (0x0000000046997420, 0x0000000000000002, 0x0000000000000001, 0xfffff8037441588a). A dump was saved in: C:\Windows\Minidump\120919-9500-01.dmp. Report Id: a8672798-a708-4f85-8a87-2164066ab08b.13389
2019-12-09T13:03:52.411The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffe305766a5028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\120919-9593-01.dmp. Report Id: 270c8525-0c91-42d1-8b0f-c0e72e0f89d2.13480
2019-12-09T12:48:04.244The computer has rebooted from a bugcheck. The bugcheck was: 0x0000003b (0x00000000c0000005, 0xfffff80431804560, 0xfffffc8a2b1bee50, 0x0000000000000000). A dump was saved in: C:\Windows\Minidump\120919-11000-01.dmp. Report Id: 88c95e37-c373-4c08-a4be-865bcf439a6b.13556
2019-12-09T10:01:07.040The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffd60d4a21b028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\120919-10171-01.dmp. Report Id: b2221cd4-35ee-458e-a8fe-570ffdde836a.13648
2019-12-09T00:45:14.723The computer has rebooted from a bugcheck. The bugcheck was: 0x0000001e (0xffffffffc0000005, 0xfffff8018002247d, 0x0000000000000000, 0xffffffffffffffff). A dump was saved in: C:\Windows\Minidump\120919-9921-01.dmp. Report Id: b80c7c00-ef29-4a07-ba31-7e80d883ee47.13859
2019-12-07T08:58:56.836The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffa58fe6519028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\120719-11031-01.dmp. Report Id: 6bdd6194-920f-4011-a88f-e35485f69cfc.14218
2019-12-06T01:48:45.428The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffe68415f28028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\120619-10609-01.dmp. Report Id: eda29a42-dcc3-410f-950e-cc79b818dcf7.14485
2019-12-05T14:29:47.278The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffff95019552c028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\120519-10421-01.dmp. Report Id: 6dba2b7d-c804-4e18-94c5-950d4141aab4.14642
2019-12-04T15:17:45.637The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffab05b6f1c028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\120419-7765-01.dmp. Report Id: b370ad85-81af-48e7-b335-c66c22679887.14880
2019-12-03T21:10:26.136The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffaa0c37317028, 0x00000000be000000, 0x0000000000800400). A dump was saved in: C:\Windows\Minidump\120319-9875-01.dmp. Report Id: 09b64218-1f00-4476-bf53-172402d9436a.15112
2019-12-03T01:32:39.596The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffff810de6d17028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\120319-7781-01.dmp. Report Id: 67b0948d-f33d-4739-a6fe-3c13fe6e427c.15326
2019-11-29T09:45:59.831The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffff800bd0d30028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\112919-8031-01.dmp. Report Id: 645c59a7-8c32-4023-b708-5c0b4482d4f0.16564
2019-11-24T18:52:24.391The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffa482b3d17028, 0x00000000f2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\112419-10531-01.dmp. Report Id: 2b08b736-e568-46ee-94b9-09f2fb7635db.17706
2019-11-24T05:12:18.579The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffe58b03077028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\112419-6765-01.dmp. Report Id: 2ac015c7-3462-47c7-9873-9a531b324a56.17939
2019-11-23T18:45:45.442The computer has rebooted from a bugcheck. The bugcheck was: 0x00000139 (0x0000000000000000, 0x0000000000000000, 0x0000000000000000, 0xffffcd80051e6930). A dump was saved in: C:\Windows\Minidump\112319-8640-01.dmp. Report Id: dd9a541a-82e4-4468-913d-9e80550b1917.18393
2019-11-22T23:13:01.503The computer has rebooted from a bugcheck. The bugcheck was: 0x000000c4 (0x0000000000002000, 0xfffff8005220f387, 0x0000000000000000, 0x00000000786f6273). A dump was saved in: C:\Windows\Minidump\112219-6656-01.dmp. Report Id: 0090fbba-778e-465a-8b7e-ceb854fbb973.18678
2019-11-22T22:48:37.853The computer has rebooted from a bugcheck. The bugcheck was: 0x000000c4 (0x0000000000002004, 0xffff98000e516428, 0xfffff806ba6201f0, 0xffff938e710df0d0). A dump was saved in: C:\Windows\Minidump\112219-7000-01.dmp. Report Id: b18c5ac3-6239-43a9-8443-d52f333ec8af.18770
2019-11-22T22:28:16.459The computer has rebooted from a bugcheck. The bugcheck was: 0x000000c4 (0x0000000000002004, 0xffff870616339d28, 0xfffff8028d6a01e8, 0xffff988356faf0d0). A dump was saved in: C:\Windows\Minidump\112219-6640-01.dmp. Report Id: 4548d895-a591-4629-b99b-1037148a80d8.18871
2019-11-22T22:02:21.072The computer has rebooted from a bugcheck. The bugcheck was: 0x000000c4 (0x0000000000002004, 0xffffa70a43b8ba28, 0xfffff802966801f0, 0xffffb9029d78f0d0). A dump was saved in: C:\Windows\Minidump\112219-7250-01.dmp. Report Id: b81ffa4e-c2f0-4686-83e1-ad75adf30c3f.18970
2019-11-22T20:46:27.628The computer has rebooted from a bugcheck. The bugcheck was: 0x000000c4 (0x0000000000002000, 0xfffff80b9425d9e0, 0x0000000000000000, 0x0000000000000000). A dump was saved in: C:\Windows\Minidump\112219-6765-01.dmp. Report Id: e8c9b409-8738-4b56-bee4-6608e1ab33af.19075
2019-11-22T15:55:10.707The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffc48d13717028, 0x00000000b2000000, 0x0000000000000014). A dump was saved in: C:\Windows\Minidump\112219-6890-01.dmp. Report Id: 737e4fb5-5713-4691-a86c-8e7fc3377e9c.19407
2019-11-21T18:25:25.974The computer has rebooted from a bugcheck. The bugcheck was: 0x00000101 (0x000000000000000c, 0x0000000000000000, 0xffff8580b5079180, 0x000000000000000b). A dump was saved in: C:\Windows\Minidump\112119-7156-01.dmp. Report Id: 3adf214f-78b2-48ca-ba99-9f2ae1ed3a7d.19920
2019-11-20T15:04:48.280The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffe4880c04d028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\112019-7484-01.dmp. Report Id: 25979e99-d11c-4676-ab36-0597e47e0490.20387
2019-11-19T20:59:14.326The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffb80c2552b028, 0x00000000b2000000, 0x0000000000000014). A dump was saved in: C:\Windows\Minidump\111919-10531-01.dmp. Report Id: d37e7338-f895-4e30-89ee-29830aead9e8.20655
2019-11-19T15:44:04.453The computer has rebooted from a bugcheck. The bugcheck was: 0x00000101 (0x000000000000000c, 0x0000000000000000, 0xffffe7803eb14180, 0x0000000000000006). A dump was saved in: C:\Windows\Minidump\111919-6593-01.dmp. Report Id: 0727d7ac-47d2-43d8-954c-adb6bfcf8d49.20858
2019-11-19T14:48:00.700The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffc48e5a92b028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\111919-6906-01.dmp. Report Id: 0d3b3f21-c408-4ce2-973e-8a621466b23e.20945
2019-11-19T00:32:56.112The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffce0f3666c028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\111919-8296-01.dmp. Report Id: 11ead754-6daf-49fc-a028-2172c2517525.21151
2019-11-18T22:57:32.151The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffb28d6c128028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\111819-6343-01.dmp. Report Id: 3cd1f9f3-19e4-40b0-a669-a3b796006bef.21333
2019-11-18T13:26:13.453The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffd58ccf2c6028, 0x00000000b2000000, 0x0000000000000014). A dump was saved in: C:\Windows\Minidump\111819-6656-01.dmp. Report Id: 4d89761d-36d5-4ec0-b122-6c4c04231928.21556
2019-11-16T15:01:25.232The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffb38fe8f2b028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\111619-9562-01.dmp. Report Id: 94ef6c19-98a1-4951-8ae0-9fa08f1b4395.21950
2019-11-16T06:24:03.618The computer has rebooted from a bugcheck. The bugcheck was: 0x1000007f (0x0000000000000008, 0xffffb7005cc842b0, 0xffff8308521d3ff0, 0xfffff80153bcf1fc). A dump was saved in: C:\Windows\Minidump\111619-6812-01.dmp. Report Id: bd90c24a-1dd0-483f-a722-4566a9a17420.22395
2019-11-14T11:17:44.444The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffbc0e9f517028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\111419-10593-01.dmp. Report Id: 9cb9055e-802d-483b-80ca-f0bced2060dd.22887
2019-11-12T23:07:28.935The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffff8f02eec60028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\111219-7140-01.dmp. Report Id: 7dddc1e4-367c-48f7-94f3-471338bbeaea.23329
2019-11-10T23:11:41.386The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffff838ecab2f028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\111019-6578-01.dmp. Report Id: bd334a09-10b7-40ee-8578-742f6a3da04b.23949
2019-11-09T12:06:52.415The computer has rebooted from a bugcheck. The bugcheck was: 0x0000000a (0xffffdb81b9442b4d, 0x00000000000000ff, 0x0000000000000000, 0xfffff80278fcecbc). A dump was saved in: C:\Windows\Minidump\110919-6562-01.dmp. Report Id: a9482df4-431b-4c93-aaf8-6a9c8789ea70.24291
2019-11-08T16:11:08.344The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffbc881432b028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\110819-6546-01.dmp. Report Id: 8efd6b22-582d-47be-ae65-fe17c367cc99.24564
2019-11-08T10:22:49.002The computer has rebooted from a bugcheck. The bugcheck was: 0x0000009c (0x0000000000000000, 0xffffce80565ccf70, 0x0000000000000000, 0x0000000000000000). A dump was saved in: C:\Windows\Minidump\110819-8171-01.dmp. Report Id: a840b714-af42-4045-b508-d82bb56a4bef.24716
2019-11-07T22:14:42.372The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffa50c7a12b028, 0x00000000b2000000, 0x0000000000000014). A dump was saved in: C:\Windows\Minidump\110719-6578-01.dmp. Report Id: 5d62fbd7-4daf-4e3d-8b86-7be880ed84ed.24949
2019-11-07T21:10:41.082The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffcb8215260028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\110719-10171-01.dmp. Report Id: 3a1db837-66ac-486c-aa35-0a45bad5ec80.25040
2019-11-06T15:39:44.429The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffc909ecb2b028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\110619-9640-01.dmp. Report Id: a8d14c03-b38c-4eed-981b-2a12292576ae.25438
2019-11-05T10:42:45.775The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffdc85bdca2028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\110519-12015-01.dmp. Report Id: 145921ca-7508-4690-bd8e-64c045bbdb71.25893
2019-11-03T16:54:32.227The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffd08463928028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\110319-11421-01.dmp. Report Id: 3da1caf1-07d2-4224-bf91-6be06cae77b5.26271
2019-11-03T16:28:10.276The computer has rebooted from a bugcheck. The bugcheck was: 0x1000007f (0x0000000000000008, 0xffffb781ca117290, 0xffff938834f41010, 0xfffff8046f351800). A dump was saved in: C:\Windows\Minidump\110319-10500-01.dmp. Report Id: 2b62a214-0b10-40de-937c-c79d98dad673.26360
2019-11-03T16:25:44.655The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffdd8277f1b028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\110319-11812-01.dmp. Report Id: f3dcccb7-cfc5-46c3-965c-eba40e13f855.26441
2019-11-01T17:00:42.697The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffbb8dcf717028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\110119-8921-01.dmp. Report Id: 38e29285-26c1-4f16-8dcf-d3880652e1a9.26924
2019-10-30T15:25:15.903The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffd986e643b028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\103019-13140-01.dmp. Report Id: 6322dc2a-913d-4c7d-b3e5-760cc7af97b8.27396
2019-10-27T15:00:56.253The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffff8f022626a028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\102719-9484-01.dmp. Report Id: 79f5d335-9d4f-477e-9ebc-f30bc0a75884.27970
2019-10-24T14:29:28.157The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0xfffff8018f638fe0, 0x0000000000000010, 0xfffff8018f638fe0, 0x0000000000000002). A dump was saved in: C:\Windows\Minidump\102419-9390-01.dmp. Report Id: 6f0520f1-5f43-4320-a6cd-f2714f36629d.28570
2019-10-23T09:50:32.977The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffd58f77528028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\102319-7203-01.dmp. Report Id: a1d3082a-f2b7-4a24-a634-c55272715a84.28965
2019-10-22T12:44:26.695The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffbc0f6bd28028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\102219-10921-01.dmp. Report Id: 83f23a7d-6a14-4d36-81fd-1f076197fe7c.29321
2019-10-19T01:04:02.814The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffb785ccb2b028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\101919-9031-01.dmp. Report Id: 07e0f372-3ba8-424e-a5de-8f96ab8597cb.30113
2019-10-17T15:50:18.051The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffd8817ed43028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\101719-7265-01.dmp. Report Id: 28d3cb71-fd0e-4cea-9ba2-f4df3ab2b97a.30483
2019-10-15T19:20:56.600The computer has rebooted from a bugcheck. The bugcheck was: 0x000000f7 (0xf1b40000000045f7, 0x00002f27f1b445f7, 0xffffd0d80e4bba08, 0x0000000000000000). A dump was saved in: C:\Windows\Minidump\101519-6812-01.dmp. Report Id: 2680c452-d9bc-4dde-8d1a-7b9abab61bf6.30965
2019-10-13T16:45:38.987The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffd38839117028, 0x00000000b2000000, 0x0000000000030005). A dump was saved in: C:\Windows\Minidump\101319-7218-01.dmp. Report Id: 53a6ee8c-a3f2-49f2-bd47-1b3377317c0a.31457
2019-10-13T16:13:06.926The computer has rebooted from a bugcheck. The bugcheck was: 0x0000000a (0xffffb28007d8c121, 0x0000000000000002, 0x0000000000000000, 0xfffff8033b83cfa0). A dump was saved in: C:\Windows\Minidump\101319-7140-01.dmp. Report Id: 3209a6b3-e26d-402f-9510-0c5e92c965b6.31742
2019-10-08T16:49:10.500The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffe50ef9e63028, 0x00000000be000000, 0x0000000000800400). A dump was saved in: C:\Windows\Minidump\100819-6656-01.dmp. Report Id: 0e4735ca-b1a4-43cb-bc49-911a753841ee.32691
2019-10-05T18:51:39.357The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffc30821317028, 0x00000000be000000, 0x0000000000800400). A dump was saved in: C:\Windows\Minidump\100519-8578-01.dmp. Report Id: bcd17788-dfdc-4c4f-9a62-03159cc9f51d.33803
2019-10-03T16:25:13.950The computer has rebooted from a bugcheck. The bugcheck was: 0x00000124 (0x0000000000000000, 0xffffe182db32b028, 0x00000000be000000, 0x0000000000800400). A dump was saved in: C:\Windows\Minidump\100319-8187-01.dmp. Report Id: cf4c0993-d337-470e-8a3b-986508e54a95.34528

Looking at the fact that most of them are 0x124 and there are only 2 0x124 dumps in the zip, I think we'll need to wait for more crashes to look into the 0x124. 0x124 can significantly help in finding the cause, but about 5 or more 0x124 dumps are needed. The way I look into 0x124 is by analyzing a couple at a time and looking into the error records searching for patterns.

Before I forget, the overview of crashes in the first post is, as I figured, simply not properly formatted with BB code.
The first two parameters are actually all parameters, the first parameter is the first two parameters of the bugcheck and the second parameter is the latter two parameters. Below is how it should be, but it's really just a copy/paste issue with the editor.
011720-11765-01.dmp1/17/2020 12:31:59 PM0x000001240000000000000000ffffa00589b2b02800000000b20000000000000000030005ntoskrnl.exentoskrnl.exe+1c14e0NT Kernel & SystemMicrosoft® Windows® Operating SystemMicrosoft Corporation10.0.18362.592 (WinBuild.160101.0800)x64ntoskrnl.exe+1c14e0C:\Windows\Minidump\011720-11765-01.dmp161518362597,9731/17/2020 12:32:38 PM

Some may notice that ntoskrnl+<offset> now has a different meaning which is that the dump is 'caused by ntoskrnl+<offset>'.
Just to elaborate with my previous post, all it means is that the debugger couldn't automatically spot another driver, even another Windows driver, so what happens is the debugger is defaulting back to ntoskrnl (or a different Windows driver sometimes) as it needs something at the position of 'caused the crash'.

If ntoskrnl were the cause, there's a good chance you might have had lots of problems with booting which were to be more likely caused by either a bad drive or faulty memory.
 
  • Like
Reactions: PC Tailor

Colif

Win 11 Master
Moderator
Yes, if kernel was cause, windows probably wouldn't work at all.

my usual description - NTOSKRNL = part of the windows kernel. It handles all driver requests, power management, and memory management. It sits between Hardware and Applications. It got blamed but its not the cause

I take it the formatting issue is a Debugger one, and not the forums

So many WHEA errors. Have to think it shouldn't be hardware given PC still works after 5 months of WHEA errors
 

Colif

Win 11 Master
Moderator
It could be hardware still I guess, I just figured if it was hardware it would have perhaps stopped working and shown other signs by now as 5 months is a long time for something to die.

That 5 months might also just be the time since last Windows version update since the dumps are all wiped then, so whatever is causing this might be way older than 5 months.

I was just thinking out loud. I don't like saying anything is not the blame as I am not perfect.
 
Feb 2, 2020
11
0
10
@axe0axe0 @Colif

Thanks for checking in.

The WHEA thing has been occurring since I built the machine. It did it using a different processor, too (tested with a 9900k and a 9900ks).

And, like I said, I tested using only 1 DIMM of RAM at a time, using a different DIMM each time, and the behavior was still observed.

The only component that has not been replaced is the motherboard, but I really don't think that could be the problem. Right?
 

Colif

Win 11 Master
Moderator
The WHEA thing has been occurring since I built the machine. It did it using a different processor, too (tested with a 9900k and a 9900ks).

that would indicate that its not the CPU.

The only component that has not been replaced is the motherboard, but I really don't think that could be the problem. Right?

I believe motherboards are impossible to test. Normally test everything else and use a process of elimination, testing everything else until you either left with Motherboard or have identified the actual cause in another part.

WHEA errors can be fixed with software updates so its always possible the problem has been fixed. I don't like predicting the future :)
 
Solution