BSOD Issues - Windows 10

eman

Member
Joined
Feb 26, 2019
Posts
7
Hi guys,

Just wondering if I have missed something in checking the dumps of a Windows 7 laptop we're having BSOD issues on. It's been happening for awhile but logs only show two dumps as the logs have been cleared before I took notice.
I would like to try to run Drive Verifier but since the laptop is overseas I won't be able to do a system restore if it fails to boot. Worse case I'll probably just replace the person's laptop and have this one shipped back to me haha.
I've checked the dumps using Windbg and unless i missed something there I couldn't find a clear culprit.
With that in mind, just asking to see if anyone else sees something I don't in terms of finding out what driver may be causing this BSOD.

  • Windows 7 64 bit (Also original installed that is OEM from Lenovo)
  • Approx 3-4 years old in terms of age of system and OS.
  • CPU: i5-5200U
  • Video Card: Intel HD Graphics 520
  • Lenovo T460 20FN003SUS
Memtest was also run and returned with no errors. Ran Lenovo's Hardware scan and checked for disk health and they came back good.
I've attached the Sysnative File collection file and the memory.dmp file can be found here.

Thanks guys!
 

Attachments

Last edited:
Hi. . .

The system has had 41 BSODs according to the Windows app msinfo32. You can find these in the future in the msinfo32.nfo file - "Software Environment"; "Windows Error Reporting" (WERCON).

I extracted the 41 BSOD WERCON records: (scroll to the right and look for BlueScreen -
Code:
27-2-2019 8:34 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\022719-11934-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-197887-0.sysdata.xml C:\Users\svenv\AppData\Local\Temp\WER1A72.tmp.WERInternalMetadata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_121524be Analysis symbol: Rechecking for solution: 0 Report Id: 022719-11934-01 Report Status: 0
21-2-2019 22:28 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\022119-32635-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-169027-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_1ce6bc2d Analysis symbol: Rechecking for solution: 0 Report Id: 022119-32635-01 Report Status: 0
12-2-2019 11:05 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\120318-12402-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-2149880-0.sysdata.xml These files may be available here: Analysis symbol: Rechecking for solution: 1 Report Id: 120318-12402-01 Report Status: 0
12-2-2019 11:05 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\011719-18267-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-162911-0.sysdata.xml These files may be available here: Analysis symbol: Rechecking for solution: 1 Report Id: 011719-18267-01 Report Status: 0
12-2-2019 11:05 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\012819-23025-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-201319-0.sysdata.xml These files may be available here: Analysis symbol: Rechecking for solution: 1 Report Id: 012819-23025-01 Report Status: 0
12-2-2019 11:05 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\120518-66128-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-1445411-0.sysdata.xml These files may be available here: Analysis symbol: Rechecking for solution: 1 Report Id: 120518-66128-01 Report Status: 0
12-2-2019 11:05 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\112918-10623-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-651428-0.sysdata.xml These files may be available here: Analysis symbol: Rechecking for solution: 1 Report Id: 112918-10623-01 Report Status: 0
12-2-2019 11:05 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\021019-11996-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-36451209-0.sysdata.xml These files may be available here: Analysis symbol: Rechecking for solution: 1 Report Id: 021019-11996-01 Report Status: 0
12-2-2019 11:05 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\013019-12121-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-89609017-0.sysdata.xml These files may be available here: Analysis symbol: Rechecking for solution: 1 Report Id: 013019-12121-01 Report Status: 0
12-2-2019 11:05 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\123118-13135-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-118981-0.sysdata.xml These files may be available here: Analysis symbol: Rechecking for solution: 1 Report Id: 123118-13135-01 Report Status: 0
12-2-2019 11:05 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\121218-17206-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-145517-0.sysdata.xml These files may be available here: Analysis symbol: Rechecking for solution: 1 Report Id: 121218-17206-01 Report Status: 0
12-2-2019 11:05 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\021119-15553-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-162287-0.sysdata.xml These files may be available here: Analysis symbol: Rechecking for solution: 1 Report Id: 021119-15553-01 Report Status: 0
12-2-2019 11:04 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\110718-26613-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-180415-0.sysdata.xml C:\Users\svenv\AppData\Local\Temp\WER962.tmp.WERInternalMetadata.xml These files may be available here: Analysis symbol: Rechecking for solution: 1 Report Id: 110718-26613-01 Report Status: 0
12-2-2019 11:04 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\111218-10264-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-290661-0.sysdata.xml C:\Users\svenv\AppData\Local\Temp\WERBA2A.tmp.WERInternalMetadata.xml These files may be available here: Analysis symbol: Rechecking for solution: 1 Report Id: 111218-10264-01 Report Status: 0
12-2-2019 11:04 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\021219-10951-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-305278-0.sysdata.xml C:\Users\svenv\AppData\Local\Temp\WER8600.tmp.WERInternalMetadata.xml These files may be available here: Analysis symbol: Rechecking for solution: 1 Report Id: 021219-10951-01 Report Status: 0
12-2-2019 11:02 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\021219-10951-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-305278-0.sysdata.xml C:\Users\svenv\AppData\Local\Temp\WER8600.tmp.WERInternalMetadata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_18ea904d Analysis symbol: Rechecking for solution: 0 Report Id: 021219-10951-01 Report Status: 0
11-2-2019 9:08 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\021119-15553-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-162287-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_0ceb0be2 Analysis symbol: Rechecking for solution: 0 Report Id: 021119-15553-01 Report Status: 0
10-2-2019 12:40 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\021019-11996-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-36451209-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_19a4a5fa Analysis symbol: Rechecking for solution: 0 Report Id: 021019-11996-01 Report Status: 0
31-1-2019 9:46 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\013019-12121-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-89609017-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_1930137c Analysis symbol: Rechecking for solution: 0 Report Id: 013019-12121-01 Report Status: 2
28-1-2019 9:54 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\012819-23025-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-201319-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_1e4b8130 Analysis symbol: Rechecking for solution: 0 Report Id: 012819-23025-01 Report Status: 0
17-1-2019 23:26 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\011719-18267-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-162911-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_2008c497 Analysis symbol: Rechecking for solution: 0 Report Id: 011719-18267-01 Report Status: 0
31-12-2018 21:27 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\123118-13135-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-118981-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_183a6d04 Analysis symbol: Rechecking for solution: 0 Report Id: 123118-13135-01 Report Status: 2
12-12-2018 9:28 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\121218-17206-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-145517-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_16a00f2c Analysis symbol: Rechecking for solution: 0 Report Id: 121218-17206-01 Report Status: 0
5-12-2018 9:01 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\120518-66128-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-1445411-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_1c3dd7f7 Analysis symbol: Rechecking for solution: 0 Report Id: 120518-66128-01 Report Status: 0
3-12-2018 9:03 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\120318-12402-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-2149880-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_27bcfb6e Analysis symbol: Rechecking for solution: 0 Report Id: 120318-12402-01 Report Status: 0
29-11-2018 13:55 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\112918-10623-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-651428-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_1a9a3091 Analysis symbol: Rechecking for solution: 0 Report Id: 112918-10623-01 Report Status: 0
12-11-2018 8:25 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\111218-10264-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-290661-0.sysdata.xml C:\Users\svenv\AppData\Local\Temp\WERBA2A.tmp.WERInternalMetadata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_1d0dc467 Analysis symbol: Rechecking for solution: 0 Report Id: 111218-10264-01 Report Status: 0
7-11-2018 13:03 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\110718-26613-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-180415-0.sysdata.xml C:\Users\svenv\AppData\Local\Temp\WER962.tmp.WERInternalMetadata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_1d8313dd Analysis symbol: Rechecking for solution: 0 Report Id: 110718-26613-01 Report Status: 0
13-8-2018 17:51 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\081318-48672-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-191413-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_0e3efeb8 Analysis symbol: Rechecking for solution: 0 Report Id: 081318-48672-01 Report Status: 0
13-8-2018 8:09 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\081318-30295-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-1068981-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_1fe521b3 Analysis symbol: Rechecking for solution: 0 Report Id: 081318-30295-01 Report Status: 0
24-7-2018 15:31 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\072418-51885-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-137561-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_12525668 Analysis symbol: Rechecking for solution: 0 Report Id: 072418-51885-01 Report Status: 0
16-7-2018 7:50 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\071618-17160-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-219852-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_2193fbbc Analysis symbol: Rechecking for solution: 0 Report Id: 071618-17160-01 Report Status: 0
19-6-2018 20:51 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\061918-13806-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-277806-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_1da0644d Analysis symbol: Rechecking for solution: 0 Report Id: 061918-13806-01 Report Status: 0
12-6-2018 13:27 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\061218-25693-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-9236756-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_129e3c95 Analysis symbol: Rechecking for solution: 0 Report Id: 061218-25693-01 Report Status: 0
1-6-2018 9:33 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\060118-12807-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-156079-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_0c92a533 Analysis symbol: Rechecking for solution: 0 Report Id: 060118-12807-01 Report Status: 0
11-5-2018 8:41 Windows Error Reporting Fault bucket X64_0xC5_2_nt!ExAllocatePoolWithTag+537, type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\051118-11216-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-2737567-0.sysdata.xml C:\Users\svenv\AppData\Local\Temp\WERB52B.tmp.WERInternalMetadata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_1f5ed6ee Analysis symbol: X64_0xC5_2_nt!ExAllocatePoolWithTag+537 Rechecking for solution: 0 Report Id: 051118-11216-01 Report Status: 0
26-4-2018 14:42 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\042618-9484-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-883106-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_0ee243b3 Analysis symbol: Rechecking for solution: 0 Report Id: 042618-9484-01 Report Status: 0
26-4-2018 7:55 Windows Error Reporting Fault bucket X64_0x4E_7_nt!MiPfnReferenceCountIsZero+83319, type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\042518-9032-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-54397080-0.sysdata.xml C:\Users\svenv\AppData\Local\Temp\WERE86B.tmp.WERInternalMetadata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_1d09ffc2 Analysis symbol: X64_0x4E_7_nt!MiPfnReferenceCountIsZero+83319 Rechecking for solution: 0 Report Id: 042518-9032-01 Report Status: 0
25-4-2018 7:30 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\042518-12838-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-73148-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_1941de3d Analysis symbol: Rechecking for solution: 0 Report Id: 042518-12838-01 Report Status: 2
25-4-2018 6:58 Windows Error Reporting Fault bucket , type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\042418-9094-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-35646774-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_0598f570 Analysis symbol: Rechecking for solution: 0 Report Id: 042418-9094-01 Report Status: 0
9-4-2018 7:25 Windows Error Reporting Fault bucket X64_0x3B_nt!ExDeferredFreePool+1df, type 0 Event Name: [color=red]BlueScreen[/color] Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\040918-10296-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-153005-0.sysdata.xml C:\Users\svenv\AppData\Local\Temp\WERAD00.tmp.WERInternalMetadata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_1622c7e0 Analysis symbol: X64_0x3B_nt!ExDeferredFreePool+1df Rechecking for solution: 0 Report Id: 040918-10296-01 Report Status: 0

The earliest date that I see off-hand is January 2018 - some 13 months ago.

You can find the actual WERCON reports (*.wer) and very likely some/many of the mini kernel memory dumps in two locations -
  • %programdata%\microsoft\windows\wer
  • %userprofile%\appdata\local\microsoft\windows\wer
There will be 2 sub-directories under each directory. You'll just have to go through them 1-by-1 if you wish to. The sub-directories will likely be colored blue indicating compressed files, but you should be able to open them. If you have problems with Windows Explorer, use Altap Salamander, a 3rd party file manager that I've used in lieu of Windows Explorer for over 12 years now.

Altap is a 30-day trial, but can be used far after that date. Installation is easy and clean (no surprise junk is installed); likewise, uninstallation is easy and complete - no remnants left behind.

Download - Altap Salamander File Manager

Now... on to your 2 mini kernel memory dumps....

Bugchecks:
  • 0x1a - severe memory management error; NT Kernel named probable cause. NT can never be the cause. It is named here as a default since the real culprit cannot be identified
  • 0xc5 - indicates that the system attempted to access invalid memory at a process IRQL that was too high; so basically invalid memory referenced. The probable cause listed as the Microsoft Windows FileInfo Filter Driver fileinfo.sys. Again, like NT, this driver is not the cause of this BSOD because it is a Microsoft Windows driver and is therefore sacrosanct. The real culprit either got away or could not be identified

Of course, the only other cause besides a <1% chance of a Windows Update driver is unknown hardware failure.

I would highly recommend that you test both RAM and al hard drives. I know you said this is a remote system, but these 2 tests really should be done -

I would start with SeaTools for DOS. Windows does not load for either test, so there is no chance of getting BSODs during the testing.

There are 3 drives listed, including a ~4 GB USB (likely a thumb drive -?), and a 64 GB drive listed as "SDXC Card". If this drive is like an SSD, it could definitely give off memory related bugchecks like the 0x1a memory management error.

I do think your issue here is unknown hardware failure with an indication toward a storage device given that fileinfo.sys was named, even though it was not the cause.

The other odd item in the dump that named NT were the high number of unloaded drivers, specifically hiber_iaStor and hiber_storpo - which are likely actually an Intel storage driver and storport.sys - another storage driver. I don't know why these would constantly be unloaded then reloaded. It is odd to say the least.

As you indicated, you could run Driver Verifier, but with just 2 dumps to work with out of 41 and both having different bugchecks, again, I do believe the cause here is unknown hardware failure.

That is it for now!

Regards. . .

jcgriff2

Code:
Microsoft (R) Windows Debugger Version 10.0.10075.9 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Users\PalmDesert\AppData\Local\Temp\SAL424.tmp\022119-32635-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available


************* Symbol Path validation summary **************
Response                         Time (ms)     Location
Deferred                                       SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.24354.amd64fre.win7sp1_ldr_escrow.190108-1700
Machine Name:
Kernel base = 0xfffff800`03602000 PsLoadedModuleList = 0xfffff800`0383bc90
Debug session time: Thu Feb 21 17:24:03.275 2019 (UTC - 5:00)
System Uptime: 7 days 14:30:39.060
Loading Kernel Symbols
...............................................................
................................................................
..........................................................
Loading User Symbols
Loading unloaded module list
..................................................
No .natvis files found at C:\Program Files (x86)\Windows Kits\10\Debuggers\x64\Visualizers.
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 1A, {41287, 0, 0, 0}

Probably caused by : ntkrnlmp.exe ( nt!KiPageFault+356 )

Followup:     MachineOwner
---------

Processing initial command '!analyze -v;r;kv;lmtn;lmtsmn;.bugcheck'
1: kd> !analyze -v;r;kv;lmtn;lmtsmn;.bugcheck
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

MEMORY_MANAGEMENT (1a)
    # Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041287, An illegal page fault occurred while holding working set synchronization.
 Parameter 2 contains the referenced virtual address.
Arg2: 0000000000000000
Arg3: 0000000000000000
Arg4: 0000000000000000

Debugging Details:
------------------


SYSTEM_SKU:  LENOVO_MT_20FN_BU_Think_FM_ThinkPad T460

SYSTEM_VERSION:  ThinkPad T460

BIOS_DATE:  12/27/2018

BASEBOARD_PRODUCT:  20FN003SUS

BASEBOARD_VERSION:  SDK0J40705 WIN

BUGCHECK_P1: 41287

BUGCHECK_P2: 0

BUGCHECK_P3: 0

BUGCHECK_P4: 0

BUGCHECK_STR:  0x1a_41287

CPU_COUNT: 4

CPU_MHZ: 960

CPU_VENDOR:  GenuineIntel

CPU_FAMILY: 6

CPU_MODEL: 4e

CPU_STEPPING: 3

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  WIN7_DRIVER_FAULT

PROCESS_NAME:  dllhost.exe

CURRENT_IRQL:  0

ANALYSIS_VERSION: 10.0.10075.9 amd64fre

TRAP_FRAME:  fffff88024712bb0 -- (.trap 0xfffff88024712bb0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffffffffffffffff rbx=0000000000000000 rcx=fffffa8011d48e20
rdx=0000000000000001 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8000364feb1 rsp=fffff88024712d40 rbp=fffffa8009c82e78
 r8=fffffa8009692320  r9=000000000657b701 r10=0000000000000000
r11=fffffa8011d48e20 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei ng nz na pe nc
nt!MiRebalanceNode+0x21:
fffff800`0364feb1 498b0a          mov     rcx,qword ptr [r10] ds:00000000`00000000=????????????????
Resetting default scope

LAST_CONTROL_TRANSFER:  from fffff8000376f93e to fffff80003695ba0

STACK_TEXT:  
fffff880`24712a58 fffff800`0376f93e : 00000000`0000001a 00000000`00041287 00000000`00000000 00000000`00000000 : nt!KeBugCheckEx
fffff880`24712a60 fffff800`036a1c96 : 00000000`00000000 00000000`00000000 fffff800`037e6100 ffffffff`ffffffff : nt!MmAccessFault+0x26fe
fffff880`24712bb0 fffff800`0364feb1 : 00000000`00000000 fffff800`038fac13 fffffa80`132316a0 00000000`00000090 : nt!KiPageFault+0x356
fffff880`24712d40 fffff800`03646873 : fffffa80`06d2c7d0 fffffa80`0dcb6410 fffffa80`09c82a00 00000000`00010000 : nt!MiRebalanceNode+0x21
fffff880`24712d70 fffff800`03646568 : fffffa80`0dcb6410 00000000`00000000 fffffa80`09c82a30 fffffa80`0fea5860 : nt!MiRemoveNode+0x233
fffff880`24712da0 fffff800`038f5c41 : fffffa80`0fea5860 00000000`00010000 0007ffff`ffffffff fffffa80`09c82a30 : nt!MiRemoveVadAndView+0x68
fffff880`24712dd0 fffff800`0390578b : fffff880`00000000 00000000`0d570000 fffffa80`00000001 ffffffff`00007f01 : nt!MiUnmapViewOfSection+0x1b1
fffff880`24712e90 fffff800`036a3bd3 : 00000000`00000001 00000000`0bc4dfff fffffa80`09c82a30 00000000`065992c0 : nt!NtUnmapViewOfSection+0x5f
fffff880`24712ee0 00000000`76f09b2a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`06d1ca18 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x76f09b2a


STACK_COMMAND:  kb

FOLLOWUP_IP:
nt!KiPageFault+356
fffff800`036a1c96 85c0            test    eax,eax

SYMBOL_STACK_INDEX:  2

SYMBOL_NAME:  nt!KiPageFault+356

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP:  5c355e0b

IMAGE_VERSION:  6.1.7601.24354

FAILURE_BUCKET_ID:  X64_0x1a_41287_nt!KiPageFault+356

BUCKET_ID:  X64_0x1a_41287_nt!KiPageFault+356

PRIMARY_PROBLEM_CLASS:  X64_0x1a_41287_nt!KiPageFault+356

ANALYSIS_SOURCE:  KM

FAILURE_ID_HASH_STRING:  km:x64_0x1a_41287_nt!kipagefault+356

FAILURE_ID_HASH:  {57c1a06a-3107-678e-b2be-207e9cbf3f0f}

Followup:     MachineOwner
---------

rax=0000000000000000 rbx=ffffffffffffffff rcx=000000000000001a
rdx=0000000000041287 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80003695ba0 rsp=fffff88024712a58 rbp=fffff88024712ac0
 r8=0000000000000000  r9=0000000000000000 r10=ffff080000000000
r11=fffff6fb7da00000 r12=fffffa800dcb6410 r13=fffffa8009c82dc8
r14=0000000000000000 r15=fffff6fb7dbed000
iopl=0         nv up ei pl zr na po nc
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00000246
nt!KeBugCheckEx:
fffff800`03695ba0 48894c2408      mov     qword ptr [rsp+8],rcx ss:0018:fffff880`24712a60=000000000000001a
 # Child-SP          RetAddr           : Args to Child                                                           : Call Site
00 fffff880`24712a58 fffff800`0376f93e : 00000000`0000001a 00000000`00041287 00000000`00000000 00000000`00000000 : nt!KeBugCheckEx
01 fffff880`24712a60 fffff800`036a1c96 : 00000000`00000000 00000000`00000000 fffff800`037e6100 ffffffff`ffffffff : nt!MmAccessFault+0x26fe
02 fffff880`24712bb0 fffff800`0364feb1 : 00000000`00000000 fffff800`038fac13 fffffa80`132316a0 00000000`00000090 : nt!KiPageFault+0x356 (TrapFrame @ fffff880`24712bb0)
03 fffff880`24712d40 fffff800`03646873 : fffffa80`06d2c7d0 fffffa80`0dcb6410 fffffa80`09c82a00 00000000`00010000 : nt!MiRebalanceNode+0x21
04 fffff880`24712d70 fffff800`03646568 : fffffa80`0dcb6410 00000000`00000000 fffffa80`09c82a30 fffffa80`0fea5860 : nt!MiRemoveNode+0x233
05 fffff880`24712da0 fffff800`038f5c41 : fffffa80`0fea5860 00000000`00010000 0007ffff`ffffffff fffffa80`09c82a30 : nt!MiRemoveVadAndView+0x68
06 fffff880`24712dd0 fffff800`0390578b : fffff880`00000000 00000000`0d570000 fffffa80`00000001 ffffffff`00007f01 : nt!MiUnmapViewOfSection+0x1b1
07 fffff880`24712e90 fffff800`036a3bd3 : 00000000`00000001 00000000`0bc4dfff fffffa80`09c82a30 00000000`065992c0 : nt!NtUnmapViewOfSection+0x5f
08 fffff880`24712ee0 00000000`76f09b2a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13 (TrapFrame @ fffff880`24712ee0)
09 00000000`06d1ca18 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x76f09b2a
start             end                 module name
fffff800`03602000 fffff800`03bde000   nt       ntkrnlmp.exe Tue Jan 08 21:35:55 2019 (5C355E0B)
fffff800`03bde000 fffff800`03c26000   hal      hal.dll      Tue Jan 08 22:06:48 2019 (5C356548)
fffff800`04000000 fffff800`0400a000   kdcom    kdcom.dll    Sat Feb 05 11:52:49 2011 (4D4D8061)
fffff880`00c00000 fffff880`00c73000   CI       CI.dll       Fri May 11 17:20:19 2018 (5AF60913)
fffff880`00c73000 fffff880`00cd1000   msrpc    msrpc.sys    Sun Nov 11 11:15:23 2018 (5BE8559B)
fffff880`00ce1000 fffff880`00d30000   mcupdate_GenuineIntel mcupdate_GenuineIntel.dll Sat Nov 20 08:03:51 2010 (4CE7C737)
fffff880`00d30000 fffff880`00d44000   PSHED    PSHED.dll    Mon Jul 13 21:32:23 2009 (4A5BE027)
fffff880`00d44000 fffff880`00da3000   CLFS     CLFS.SYS     Sat Apr 07 11:45:40 2018 (5AC8E7A4)
fffff880`00da3000 fffff880`00dd9000   WUDFRd   WUDFRd.sys   Wed Jul 25 22:26:06 2012 (5010AABE)
fffff880`00e00000 fffff880`00e4a000   FLTMGR   FLTMGR.SYS   Sun Dec 31 20:41:16 2017 (5A4991BC)
fffff880`00e4a000 fffff880`00e64000   mountmgr mountmgr.sys Sun May 07 10:52:08 2017 (590F3498)
fffff880`00e64000 fffff880`00e8e000   ataport  ataport.SYS  Sun Aug 04 21:02:45 2013 (51FEF9B5)
fffff880`00eb7000 fffff880`00f79000   Wdf01000 Wdf01000.sys Fri Jun 21 23:13:05 2013 (51C51641)
fffff880`00f79000 fffff880`00f89000   WDFLDR   WDFLDR.SYS   Wed Jul 25 22:29:04 2012 (5010AB70)
fffff880`00f89000 fffff880`00f9d000   volmgr   volmgr.sys   Sat Feb 10 12:21:56 2018 (5A7F2A34)
fffff880`00f9d000 fffff880`00ff9000   volmgrx  volmgrx.sys  Fri Jul 07 10:53:40 2017 (595FA074)
fffff880`01000000 fffff880`01015000   partmgr  partmgr.sys  Sat Mar 17 01:06:09 2012 (4F641BC1)
fffff880`01015000 fffff880`0101e000   compbatt compbatt.sys Mon Jul 13 19:31:02 2009 (4A5BC3B6)
fffff880`0101e000 fffff880`0102a000   BATTC    BATTC.SYS    Mon Jul 13 19:31:01 2009 (4A5BC3B5)
fffff880`0102a000 fffff880`0103a000   klbackupdisk klbackupdisk.sys Mon Aug 06 02:56:33 2018 (5B67F121)
fffff880`0103c000 fffff880`01745000   kl1      kl1.sys      Fri Apr 01 10:20:28 2016 (56FE83AC)
fffff880`01745000 fffff880`0179c000   ACPI     ACPI.sys     Sat Feb 10 12:21:53 2018 (5A7F2A31)
fffff880`0179c000 fffff880`017a5000   WMILIB   WMILIB.SYS   Mon Jul 13 19:19:51 2009 (4A5BC117)
fffff880`017a5000 fffff880`017af000   msisadrv msisadrv.sys Sat Feb 10 12:21:45 2018 (5A7F2A29)
fffff880`017af000 fffff880`017e2000   pci      pci.sys      Sat Feb 10 12:22:10 2018 (5A7F2A42)
fffff880`017e2000 fffff880`017ef000   vdrvroot vdrvroot.sys Sat Feb 10 12:38:45 2018 (5A7F2E25)
fffff880`017ef000 fffff880`017f8000   atapi    atapi.sys    Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`01800000 fffff880`01814000   fileinfo fileinfo.sys Mon Jul 13 19:34:25 2009 (4A5BC481)
fffff880`0183e000 fffff880`0238b000   iaStorA  iaStorA.sys  Tue Jun 06 12:27:18 2017 (5936D7E6)
fffff880`0238b000 fffff880`023ef000   storport storport.sys Fri Aug 14 13:09:20 2015 (55CE20C0)
fffff880`023ef000 fffff880`023fa000   amdxata  amdxata.sys  Fri Mar 19 12:18:18 2010 (4BA3A3CA)
fffff880`02400000 fffff880`02415000   NDProxy  NDProxy.SYS  Fri Dec 07 21:47:15 2018 (5C0B30B3)
fffff880`0241f000 fffff880`025c7000   Ntfs     Ntfs.sys     Fri Dec 28 14:28:19 2018 (5C267953)
fffff880`025c7000 fffff880`025e2000   ksecdd   ksecdd.sys   Tue Jan 15 01:31:27 2019 (5C3D7E3F)
fffff880`02600000 fffff880`0263a000   fvevol   fvevol.sys   Wed Jan 23 22:11:24 2013 (5100A65C)
fffff880`0263a000 fffff880`0264f000   disk     disk.sys     Tue Jan 19 21:12:06 2016 (569EECF6)
fffff880`0264f000 fffff880`02680000   CLASSPNP CLASSPNP.SYS Sun Sep 28 20:46:24 2014 (5428ABE0)
fffff880`0268d000 fffff880`02702000   cng      cng.sys      Thu May 10 22:25:10 2018 (5AF4FF06)
fffff880`02702000 fffff880`02713000   pcw      pcw.sys      Mon Jul 13 19:19:27 2009 (4A5BC0FF)
fffff880`02713000 fffff880`0271e000   pmdrvs   pmdrvs.sys   Thu Aug 30 20:38:36 2018 (5B888E0C)
fffff880`0271e000 fffff880`02728000   Fs_Rec   Fs_Rec.sys   Wed Feb 29 22:41:06 2012 (4F4EEFD2)
fffff880`02728000 fffff880`02774000   volsnap  volsnap.sys  Thu Feb 24 22:38:18 2011 (4D67242A)
fffff880`02774000 fffff880`027ae000   rdyboost rdyboost.sys Sun Dec 31 20:44:40 2017 (5A499288)
fffff880`027ae000 fffff880`027d8000   Apsx64   Apsx64.sys   Mon Mar 13 09:19:24 2017 (58C69C5C)
fffff880`027d8000 fffff880`027f6000   mup      mup.sys      Tue Jan 06 20:48:27 2015 (54AC906B)
fffff880`02800000 fffff880`0282b000   ksecpkg  ksecpkg.sys  Tue Jan 15 01:38:02 2019 (5C3D7FCA)
fffff880`0282b000 fffff880`02874000   fwpkclnt fwpkclnt.sys Sun Aug 12 15:45:55 2018 (5B708E73)
fffff880`02874000 fffff880`02884000   vmstorfl vmstorfl.sys Sat Nov 20 04:57:30 2010 (4CE79B8A)
fffff880`02884000 fffff880`0288f000   ApsHM64  ApsHM64.sys  Mon Mar 13 09:16:44 2017 (58C69BBC)
fffff880`0288f000 fffff880`02897000   spldr    spldr.sys    Mon May 11 12:56:27 2009 (4A0858BB)
fffff880`02897000 fffff880`028a0000   hwpolicy hwpolicy.sys Sat Nov 20 04:18:54 2010 (4CE7927E)
fffff880`028a2000 fffff880`02994000   ndis     ndis.sys     Fri Jul 06 11:18:04 2018 (5B3F882C)
fffff880`02994000 fffff880`029f4000   NETIO    NETIO.SYS    Sun Aug 12 15:46:07 2018 (5B708E7F)
fffff880`029f4000 fffff880`02a00000   iaStorF  iaStorF.sys  Tue Jun 06 12:27:23 2017 (5936D7EB)
fffff880`02a02000 fffff880`02bfd000   tcpip    tcpip.sys    Sun Aug 12 15:46:49 2018 (5B708EA9)
fffff880`03e00000 fffff880`03e22000   tdx      tdx.sys      Sat Jul 29 10:56:29 2017 (597CA21D)
fffff880`03e22000 fffff880`03e2f000   TDI      TDI.SYS      Sat Nov 20 04:22:06 2010 (4CE7933E)
fffff880`03e39000 fffff880`03f90000   klhk     klhk.sys     Wed Sep 19 05:58:51 2018 (5BA21DDB)
fffff880`03f90000 fffff880`03fa2000   kltdi    kltdi.sys    Thu Jun 15 04:57:08 2017 (59424BE4)
fffff880`03fa2000 fffff880`03fb1000   discache discache.sys Mon Jul 13 19:37:18 2009 (4A5BC52E)
fffff880`03fba000 fffff880`03fd5000   klbackupflt klbackupflt.sys Wed Jan 31 11:07:22 2018 (5A71E9BA)
fffff880`03fd5000 fffff880`03fea000   FortiShield FortiShield.sys Thu Nov 05 14:10:29 2015 (563BA9A5)
fffff880`03fea000 fffff880`03ffb000   Npfs     Npfs.SYS     Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`04e00000 fffff880`04e43000   ks       ks.sys       Tue Aug 28 01:50:19 2018 (5B84E29B)
fffff880`04e43000 fffff880`04e4e000   klpd     klpd.sys     Fri Mar 24 09:45:18 2017 (58D522EE)
fffff880`04e4e000 fffff880`04e57000   Null     Null.SYS     Mon Jul 13 19:19:37 2009 (4A5BC109)
fffff880`04e57000 fffff880`04e5e000   Beep     Beep.SYS     Mon Jul 13 20:00:13 2009 (4A5BCA8D)
fffff880`04e5e000 fffff880`04e6c000   vga      vga.sys      Mon Jul 13 19:38:47 2009 (4A5BC587)
fffff880`04e6c000 fffff880`04e91000   VIDEOPRT VIDEOPRT.SYS Tue Jan 08 21:38:22 2019 (5C355E9E)
fffff880`04e91000 fffff880`04e9d000   iwdbus   iwdbus.sys   Tue Feb 10 14:04:50 2015 (54DA5652)
fffff880`04e9d000 fffff880`04fbe000   klif     klif.sys     Fri Sep 28 07:25:59 2018 (5BAE0FC7)
fffff880`04fbe000 fffff880`04fce000   watchdog watchdog.sys Mon Jul 13 19:37:35 2009 (4A5BC53F)
fffff880`04fce000 fffff880`04fd7000   RDPCDD   RDPCDD.sys   Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`04fd7000 fffff880`04fe0000   rdpencdd rdpencdd.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`04fe0000 fffff880`04fe9000   rdprefmp rdprefmp.sys Mon Jul 13 20:16:35 2009 (4A5BCE63)
fffff880`04fe9000 fffff880`04ff4000   Msfs     Msfs.SYS     Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`04ff4000 fffff880`04fff000   klfltdev klfltdev.sys Fri Dec 09 06:52:49 2016 (584A9B11)
fffff880`05400000 fffff880`05430000   kneps    kneps.sys    Thu Sep 13 05:08:32 2018 (5B9A2910)
fffff880`05436000 fffff880`054bf000   afd      afd.sys      Tue Apr 04 10:53:16 2017 (58E3B35C)
fffff880`054bf000 fffff880`054c8000   wfplwf   wfplwf.sys   Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff880`054c8000 fffff880`054ee000   pacer    pacer.sys    Sun Dec 31 20:55:04 2017 (5A4994F8)
fffff880`054ee000 fffff880`05504000   vwififlt vwififlt.sys Mon Jul 13 20:07:22 2009 (4A5BCC3A)
fffff880`05504000 fffff880`0550e000   FortiFilter FortiFilter.sys Tue Nov 18 14:09:01 2014 (546B994D)
fffff880`0550e000 fffff880`05537000   klwtp    klwtp.sys    Wed May 16 08:27:39 2018 (5AFC23BB)
fffff880`05537000 fffff880`05543000   klim6    klim6.sys    Thu May 17 07:43:44 2018 (5AFD6AF0)
fffff880`05543000 fffff880`05553000   netbios  netbios.sys  Sun Dec 31 20:55:00 2017 (5A4994F4)
fffff880`05553000 fffff880`0556e000   wanarp   wanarp.sys   Fri Dec 07 21:47:22 2018 (5C0B30BA)
fffff880`0556e000 fffff880`05577000   Tppwr64v Tppwr64v.sys Wed Feb 15 23:57:36 2017 (58A53140)
fffff880`05577000 fffff880`0558b000   termdd   termdd.sys   Sat Feb 10 12:45:02 2018 (5A7F2F9E)
fffff880`0558b000 fffff880`055de000   rdbss    rdbss.sys    Wed Oct 11 20:20:28 2017 (59DEB54C)
fffff880`055de000 fffff880`055e5000   omnismi  omnismi.sys  Wed Apr 03 23:39:27 2013 (515CF5EF)
fffff880`055e5000 fffff880`055f1000   nsiproxy nsiproxy.sys Fri Aug 11 01:58:55 2017 (598D479F)
fffff880`055f1000 fffff880`055fc000   mssmbios mssmbios.sys Sat Feb 10 12:25:38 2018 (5A7F2B12)
fffff880`05600000 fffff880`056f5000   dxgkrnl  dxgkrnl.sys  Sat Sep 08 20:21:17 2018 (5B94677D)
fffff880`056fb000 fffff880`05780000   csc      csc.sys      Fri Jun 29 11:14:18 2018 (5B364CCA)
fffff880`05780000 fffff880`057a1000   dfsc     dfsc.sys     Wed Apr 25 11:18:53 2018 (5AE09C5D)
fffff880`057a1000 fffff880`057b2000   blbdrive blbdrive.sys Mon Jul 13 19:35:59 2009 (4A5BC4DF)
fffff880`057b2000 fffff880`057d8000   tunnel   tunnel.sys   Sat Nov 20 05:51:50 2010 (4CE7A846)
fffff880`057d8000 fffff880`057ee000   intelppm intelppm.sys Tue Jan 08 21:34:40 2019 (5C355DC0)
fffff880`057ee000 fffff880`057fc000   psadd    psadd.sys    Mon Dec 26 20:09:28 2011 (4EF91AC8)
fffff880`05800000 fffff880`0582d000   mrxsmb   mrxsmb.sys   Tue Jan 15 01:32:34 2019 (5C3D7E82)
fffff880`05842000 fffff880`05896000   nwifi    nwifi.sys    Wed Sep 13 11:05:20 2017 (59B94930)
fffff880`05896000 fffff880`058a9000   ndisuio  ndisuio.sys  Sat Nov 20 05:50:08 2010 (4CE7A7E0)
fffff880`058a9000 fffff880`058c1000   rspndr   rspndr.sys   Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`058c1000 fffff880`058f6000   exfat    exfat.SYS    Fri Mar 10 10:55:25 2017 (58C2CC6D)
fffff880`058f6000 fffff880`05900000   vwifimp  vwifimp.sys  Mon Jul 13 20:07:28 2009 (4A5BCC40)
fffff880`05900000 fffff880`059c8000   HTTP     HTTP.sys     Sun Dec 31 20:41:37 2017 (5A4991D1)
fffff880`059c8000 fffff880`059e5000   bowser   bowser.sys   Wed Jul 18 11:18:04 2018 (5B4F5A2C)
fffff880`059e5000 fffff880`059fd000   mpsdrv   mpsdrv.sys   Fri Aug 10 11:27:40 2018 (5B6DAEEC)
fffff880`05a00000 fffff880`05a45000   klflt    klflt.sys    Fri Aug 24 04:01:37 2018 (5B7FBB61)
fffff880`05a45000 fffff880`05a8a000   netbt    netbt.sys    Fri Aug 11 01:59:59 2017 (598D47DF)
fffff880`05a8a000 fffff880`065d7000   dump_iaStorA dump_iaStorA.sys Tue Jun 06 12:27:18 2017 (5936D7E6)
fffff880`065d7000 fffff880`065ec000   lltdio   lltdio.sys   Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`065ed000 fffff880`065ff000   umbus    umbus.sys    Sat Nov 20 05:44:37 2010 (4CE7A695)
fffff880`06800000 fffff880`06838000   usb3Hub  usb3Hub.sys  Fri Jan 09 00:53:47 2015 (54AF6CEB)
fffff880`0683a000 fffff880`06905000   iusb3xhc iusb3xhc.sys Thu May 11 08:15:19 2017 (591455D7)
fffff880`06905000 fffff880`06906e80   USBD     USBD.SYS     Wed May 02 11:32:25 2018 (5AE9DA09)
fffff880`06907000 fffff880`06939000   TeeDriverx64 TeeDriverx64.sys Sun Nov 19 06:39:31 2017 (5A116D73)
fffff880`06939000 fffff880`069f8000   RtsPer   RtsPer.sys   Fri Nov 13 01:22:42 2015 (564581B2)
fffff880`06a00000 fffff880`06a83000   e1d62x64 e1d62x64.sys Sun Nov 27 08:03:30 2016 (583AD9A2)
fffff880`06a83000 fffff880`06a8c000   wmiacpi  wmiacpi.sys  Sat Feb 10 12:25:26 2018 (5A7F2B06)
fffff880`06a8c000 fffff880`06ab3000   tpm      tpm.sys      Fri Feb 05 12:39:10 2016 (56B4DE3E)
fffff880`06ab3000 fffff880`06ac3000   XtuAcpiDriver XtuAcpiDriver.sys Wed Apr 12 04:58:50 2017 (58EDEC4A)
fffff880`06ac3000 fffff880`06acb000   ftvnic   ftvnic.sys   Thu Feb 12 19:37:53 2009 (4994C0E1)
fffff880`06acd000 fffff880`06b80000   SynTP    SynTP.sys    Wed Oct 31 23:50:00 2018 (5BDA77E8)
fffff880`06b80000 fffff880`06b88280   HIDPARSE HIDPARSE.SYS Tue Jan 08 21:45:27 2019 (5C356047)
fffff880`06b89000 fffff880`06b98000   kbdclass kbdclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff880`06b98000 fffff880`06ba7000   mouclass mouclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff880`06ba7000 fffff880`06bab500   CmBatt   CmBatt.sys   Mon Jul 13 19:31:03 2009 (4A5BC3B7)
fffff880`06bac000 fffff880`06bc2000   ibmpmdrv ibmpmdrv.sys Thu Aug 30 20:38:23 2018 (5B888DFF)
fffff880`06bc2000 fffff880`06be6000   HDAudBus HDAudBus.sys Tue Aug 27 21:35:47 2013 (521D53F3)
fffff880`06be6000 fffff880`06bf5000   Smb_driver_Intel Smb_driver_Intel.sys Wed Oct 31 23:50:28 2018 (5BDA7804)
fffff880`06bf5000 fffff880`06bfdc00   pppop64  pppop64.sys  Wed Jul 15 17:57:15 2009 (4A5E50BB)
fffff880`06bfe000 fffff880`06bff480   swenum   swenum.sys   Sat Feb 10 12:38:10 2018 (5A7F2E02)
fffff880`06c00000 fffff880`06f9f000   Netwsw04 Netwsw04.sys Mon Aug 27 05:17:21 2018 (5B83C1A1)
fffff880`06f9f000 fffff880`06fac000   vwifibus vwifibus.sys Mon Jul 13 20:07:21 2009 (4A5BCC39)
fffff880`06fac000 fffff880`06fca000   i8042prt i8042prt.sys Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`06fca000 fffff880`06fda000   CompositeBus CompositeBus.sys Sat Nov 20 05:33:17 2010 (4CE7A3ED)
fffff880`06fda000 fffff880`06ff0000   AgileVpn AgileVpn.sys Mon Jul 13 20:10:24 2009 (4A5BCCF0)
fffff880`06ff0000 fffff880`06ffc000   ndistapi ndistapi.sys Fri Dec 07 21:47:13 2018 (5C0B30B1)
fffff880`07200000 fffff880`07277000   IntcDAud IntcDAud.sys Wed Jun 21 22:59:52 2017 (594B32A8)
fffff880`07277000 fffff880`07294000   usbccgp  usbccgp.sys  Wed May 02 11:32:35 2018 (5AE9DA13)
fffff880`07294000 fffff880`072ad000   HIDCLASS HIDCLASS.SYS Tue Jan 08 21:45:27 2019 (5C356047)
fffff880`072ad000 fffff880`072c6000   WudfPf   WudfPf.sys   Wed Jul 25 22:26:45 2012 (5010AAE5)
fffff880`072c6000 fffff880`0732c000   iusb3hub iusb3hub.sys Thu May 11 08:15:16 2017 (591455D4)
fffff880`0732c000 fffff880`07369000   portcls  portcls.sys  Tue Dec 08 13:12:06 2015 (56671D76)
fffff880`07369000 fffff880`0738b000   drmk     drmk.sys     Tue Dec 08 13:54:36 2015 (5667276C)
fffff880`0738b000 fffff880`073ae000   luafv    luafv.sys    Wed Oct 11 20:20:09 2017 (59DEB539)
fffff880`073ae000 fffff880`073bf000   WinUSB   WinUSB.sys   Sat Nov 20 05:43:56 2010 (4CE7A66C)
fffff880`073c1000 fffff880`073cf000   crashdmp crashdmp.sys Mon Jul 13 20:01:01 2009 (4A5BCABD)
fffff880`073cf000 fffff880`073e2000   dump_dumpfve dump_dumpfve.sys Mon Jul 13 19:21:51 2009 (4A5BC18F)
fffff880`07600000 fffff880`0762f000   ndiswan  ndiswan.sys  Sat Nov 20 05:52:32 2010 (4CE7A870)
fffff880`0762f000 fffff880`0764a000   raspppoe raspppoe.sys Mon Jul 13 20:10:17 2009 (4A5BCCE9)
fffff880`0764a000 fffff880`0766b000   raspptp  raspptp.sys  Sat Nov 20 05:52:31 2010 (4CE7A86F)
fffff880`0766b000 fffff880`07676000   rdpbus   rdpbus.sys   Mon Jul 13 20:17:46 2009 (4A5BCEAA)
fffff880`0767f000 fffff880`0813e000   igdkmd64 igdkmd64.sys Wed Oct 31 10:32:25 2018 (5BD9BCF9)
fffff880`0813e000 fffff880`08174000   fastfat  fastfat.SYS  Fri Mar 10 10:55:26 2017 (58C2CC6E)
fffff880`08174000 fffff880`081ba000   dxgmms1  dxgmms1.sys  Sat Sep 08 20:21:01 2018 (5B94676D)
fffff880`081ba000 fffff880`081de000   rasl2tp  rasl2tp.sys  Sat Nov 20 05:52:34 2010 (4CE7A872)
fffff880`081de000 fffff880`081f8000   rassstp  rassstp.sys  Mon Jul 13 20:10:25 2009 (4A5BCCF1)
fffff880`08800000 fffff880`0880d000   mouhid   mouhid.sys   Mon Jul 13 20:00:20 2009 (4A5BCA94)
fffff880`0880e000 fffff880`08de3000   RTKVHD64 RTKVHD64.sys Tue Aug 01 06:05:51 2017 (5980527F)
fffff880`08de3000 fffff880`08de8200   ksthunk  ksthunk.sys  Mon Jul 13 20:00:19 2009 (4A5BCA93)
fffff880`08de9000 fffff880`08df7000   hidusb   hidusb.sys   Tue Jan 08 21:45:28 2019 (5C356048)
fffff880`09031000 fffff880`0907f000   mrxsmb10 mrxsmb10.sys Tue Jan 15 01:32:11 2019 (5C3D7E6B)
fffff880`0907f000 fffff880`090a3000   mrxsmb20 mrxsmb20.sys Tue Jan 15 01:32:08 2019 (5C3D7E68)
fffff880`090a3000 fffff880`0914d000   peauth   peauth.sys   Tue Jun 14 13:11:06 2016 (57603AAA)
fffff880`0914d000 fffff880`0917e000   srvnet   srvnet.sys   Tue Jan 08 21:35:27 2019 (5C355DEF)
fffff880`0917e000 fffff880`09186000   SSPORT   SSPORT.sys   Thu Aug 11 19:07:32 2005 (42FBDA34)
fffff880`09188000 fffff880`0919a000   tcpipreg tcpipreg.sys Thu Jul 07 11:08:06 2016 (577E7056)
fffff880`0a829000 fffff880`0a835000   Dxapi    Dxapi.sys    Mon Jul 13 19:38:28 2009 (4A5BC574)
fffff880`0a835000 fffff880`0a83f000   dump_diskdump dump_diskdump.sys Mon Feb 03 20:36:25 2014 (52F04419)
fffff880`0a840000 fffff880`0a9e1000   SPUVCbv64 SPUVCbv64.sys Mon Apr 25 02:47:22 2016 (571DBD7A)
fffff880`0bc13000 fffff880`0bc7b000   srv2     srv2.sys     Tue Jan 08 21:35:33 2019 (5C355DF5)
fffff880`0bc7b000 fffff880`0bd12000   srv      srv.sys      Tue Jan 08 21:35:42 2019 (5C355DFE)
fffff880`0bd12000 fffff880`0bd40000   rdpdr    rdpdr.sys    Sat Nov 20 06:06:41 2010 (4CE7ABC1)
fffff880`0bd40000 fffff880`0bd4b000   tdtcp    tdtcp.sys    Thu Feb 16 23:57:32 2012 (4F3DDE3C)
fffff880`0bd4b000 fffff880`0bd5b000   tssecsrv tssecsrv.sys Sun Aug 13 17:45:28 2017 (5990C878)
fffff880`0bd5b000 fffff880`0bd95000   RDPWD    RDPWD.SYS    Wed Jul 16 21:21:53 2014 (53C72531)
fffff880`0d071000 fffff880`0d09a000   mrxdav   mrxdav.sys   Thu Sep 08 10:55:15 2016 (57D17BD3)
fffff880`0d15b000 fffff880`0d166000   asyncmac asyncmac.sys Mon Jul 13 20:10:13 2009 (4A5BCCE5)
fffff880`27b70000 fffff880`27b7e000   monitor  monitor.sys  Mon Jul 13 19:38:52 2009 (4A5BC58C)
fffff960`00070000 fffff960`00399000   win32k   win32k.sys   Mon Jan 07 12:18:58 2019 (5C338A02)
fffff960`005f0000 fffff960`005fa000   TSDDD    TSDDD.dll    unavailable (00000000)
fffff960`007b0000 fffff960`007d7000   cdd      cdd.dll      Sat Sep 08 20:58:16 2018 (5B947028)
fffff960`00830000 fffff960`00893000   ATMFD    ATMFD.DLL    Sat Oct 06 11:21:10 2018 (5BB8D2E6)

Unloaded modules:
fffff880`0d018000 fffff880`0d022000   hiber_storpo
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000A000
fffff880`27010000 fffff880`27b5d000   hiber_iaStor
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00B4D000
fffff880`27b5d000 fffff880`27b70000   hiber_dumpfv
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00013000
fffff880`0d00a000 fffff880`0d018000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`2b5e5000 fffff880`2b5f3000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`2aa00000 fffff880`2aa71000   spsys.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00071000
fffff880`0d000000 fffff880`0d00a000   hiber_storpo
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000A000
fffff880`2aa85000 fffff880`2b5d2000   hiber_iaStor
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00B4D000
fffff880`2b5d2000 fffff880`2b5e5000   hiber_dumpfv
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00013000
fffff880`0d1f0000 fffff880`0d1fe000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`2b571000 fffff880`2b57f000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0d1e6000 fffff880`0d1f0000   hiber_storpo
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000A000
fffff880`2aa11000 fffff880`2b55e000   hiber_iaStor
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00B4D000
fffff880`2b55e000 fffff880`2b571000   hiber_dumpfv
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00013000
fffff880`0d1d8000 fffff880`0d1e6000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0d1ca000 fffff880`0d1d8000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0d1b2000 fffff880`0d1c0000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0d1c0000 fffff880`0d1ca000   hiber_storpo
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000A000
fffff880`2ee75000 fffff880`2f9c2000   hiber_iaStor
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00B4D000
fffff880`2f9c2000 fffff880`2f9d5000   hiber_dumpfv
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00013000
fffff880`2f9e6000 fffff880`2f9f4000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0d1a8000 fffff880`0d1b2000   hiber_storpo
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000A000
fffff880`2ee86000 fffff880`2f9d3000   hiber_iaStor
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00B4D000
fffff880`2f9d3000 fffff880`2f9e6000   hiber_dumpfv
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00013000
fffff880`0d19a000 fffff880`0d1a8000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0d18c000 fffff880`0d19a000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0d174000 fffff880`0d182000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0d182000 fffff880`0d18c000   hiber_storpo
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000A000
fffff880`2aaa5000 fffff880`2b5f2000   hiber_iaStor
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00B4D000
fffff880`2aa00000 fffff880`2aa13000   hiber_dumpfv
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00013000
fffff880`0d166000 fffff880`0d174000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0d13e000 fffff880`0d14c000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0d14c000 fffff880`0d156000   hiber_storpo
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000A000
fffff880`2ee88000 fffff880`2f9d5000   hiber_iaStor
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00B4D000
fffff880`2f9d5000 fffff880`2f9e8000   hiber_dumpfv
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00013000
fffff880`2f9e2000 fffff880`2f9f0000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0d134000 fffff880`0d13e000   hiber_storpo
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000A000
fffff880`2ee82000 fffff880`2f9cf000   hiber_iaStor
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00B4D000
fffff880`2f9cf000 fffff880`2f9e2000   hiber_dumpfv
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00013000
fffff880`0d126000 fffff880`0d134000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0d10e000 fffff880`0d11c000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0d11c000 fffff880`0d126000   hiber_storpo
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000A000
fffff880`2aa04000 fffff880`2b551000   hiber_iaStor
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00B4D000
fffff880`2b551000 fffff880`2b564000   hiber_dumpfv
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00013000
fffff880`0d100000 fffff880`0d10e000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0d0e8000 fffff880`0d0f6000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0d0f6000 fffff880`0d100000   hiber_storpo
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000A000
fffff880`2aa2d000 fffff880`2b57a000   hiber_iaStor
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00B4D000
fffff880`2b57a000 fffff880`2b58d000   hiber_dumpfv
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00013000
fffff880`0d0da000 fffff880`0d0e8000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
start             end                 module name
fffff880`01745000 fffff880`0179c000   ACPI     ACPI.sys     Sat Feb 10 12:21:53 2018 (5A7F2A31)
fffff880`05436000 fffff880`054bf000   afd      afd.sys      Tue Apr 04 10:53:16 2017 (58E3B35C)
fffff880`06fda000 fffff880`06ff0000   AgileVpn AgileVpn.sys Mon Jul 13 20:10:24 2009 (4A5BCCF0)
fffff880`023ef000 fffff880`023fa000   amdxata  amdxata.sys  Fri Mar 19 12:18:18 2010 (4BA3A3CA)
fffff880`02884000 fffff880`0288f000   ApsHM64  ApsHM64.sys  Mon Mar 13 09:16:44 2017 (58C69BBC)
fffff880`027ae000 fffff880`027d8000   Apsx64   Apsx64.sys   Mon Mar 13 09:19:24 2017 (58C69C5C)
fffff880`0d15b000 fffff880`0d166000   asyncmac asyncmac.sys Mon Jul 13 20:10:13 2009 (4A5BCCE5)
fffff880`017ef000 fffff880`017f8000   atapi    atapi.sys    Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`00e64000 fffff880`00e8e000   ataport  ataport.SYS  Sun Aug 04 21:02:45 2013 (51FEF9B5)
fffff960`00830000 fffff960`00893000   ATMFD    ATMFD.DLL    Sat Oct 06 11:21:10 2018 (5BB8D2E6)
fffff880`0101e000 fffff880`0102a000   BATTC    BATTC.SYS    Mon Jul 13 19:31:01 2009 (4A5BC3B5)
fffff880`04e57000 fffff880`04e5e000   Beep     Beep.SYS     Mon Jul 13 20:00:13 2009 (4A5BCA8D)
fffff880`057a1000 fffff880`057b2000   blbdrive blbdrive.sys Mon Jul 13 19:35:59 2009 (4A5BC4DF)
fffff880`059c8000 fffff880`059e5000   bowser   bowser.sys   Wed Jul 18 11:18:04 2018 (5B4F5A2C)
fffff960`007b0000 fffff960`007d7000   cdd      cdd.dll      Sat Sep 08 20:58:16 2018 (5B947028)
fffff880`00c00000 fffff880`00c73000   CI       CI.dll       Fri May 11 17:20:19 2018 (5AF60913)
fffff880`0264f000 fffff880`02680000   CLASSPNP CLASSPNP.SYS Sun Sep 28 20:46:24 2014 (5428ABE0)
fffff880`00d44000 fffff880`00da3000   CLFS     CLFS.SYS     Sat Apr 07 11:45:40 2018 (5AC8E7A4)
fffff880`06ba7000 fffff880`06bab500   CmBatt   CmBatt.sys   Mon Jul 13 19:31:03 2009 (4A5BC3B7)
fffff880`0268d000 fffff880`02702000   cng      cng.sys      Thu May 10 22:25:10 2018 (5AF4FF06)
fffff880`01015000 fffff880`0101e000   compbatt compbatt.sys Mon Jul 13 19:31:02 2009 (4A5BC3B6)
fffff880`06fca000 fffff880`06fda000   CompositeBus CompositeBus.sys Sat Nov 20 05:33:17 2010 (4CE7A3ED)
fffff880`073c1000 fffff880`073cf000   crashdmp crashdmp.sys Mon Jul 13 20:01:01 2009 (4A5BCABD)
fffff880`056fb000 fffff880`05780000   csc      csc.sys      Fri Jun 29 11:14:18 2018 (5B364CCA)
fffff880`05780000 fffff880`057a1000   dfsc     dfsc.sys     Wed Apr 25 11:18:53 2018 (5AE09C5D)
fffff880`03fa2000 fffff880`03fb1000   discache discache.sys Mon Jul 13 19:37:18 2009 (4A5BC52E)
fffff880`0263a000 fffff880`0264f000   disk     disk.sys     Tue Jan 19 21:12:06 2016 (569EECF6)
fffff880`07369000 fffff880`0738b000   drmk     drmk.sys     Tue Dec 08 13:54:36 2015 (5667276C)
fffff880`0a835000 fffff880`0a83f000   dump_diskdump dump_diskdump.sys Mon Feb 03 20:36:25 2014 (52F04419)
fffff880`073cf000 fffff880`073e2000   dump_dumpfve dump_dumpfve.sys Mon Jul 13 19:21:51 2009 (4A5BC18F)
fffff880`05a8a000 fffff880`065d7000   dump_iaStorA dump_iaStorA.sys Tue Jun 06 12:27:18 2017 (5936D7E6)
fffff880`0a829000 fffff880`0a835000   Dxapi    Dxapi.sys    Mon Jul 13 19:38:28 2009 (4A5BC574)
fffff880`05600000 fffff880`056f5000   dxgkrnl  dxgkrnl.sys  Sat Sep 08 20:21:17 2018 (5B94677D)
fffff880`08174000 fffff880`081ba000   dxgmms1  dxgmms1.sys  Sat Sep 08 20:21:01 2018 (5B94676D)
fffff880`06a00000 fffff880`06a83000   e1d62x64 e1d62x64.sys Sun Nov 27 08:03:30 2016 (583AD9A2)
fffff880`058c1000 fffff880`058f6000   exfat    exfat.SYS    Fri Mar 10 10:55:25 2017 (58C2CC6D)
fffff880`0813e000 fffff880`08174000   fastfat  fastfat.SYS  Fri Mar 10 10:55:26 2017 (58C2CC6E)
fffff880`01800000 fffff880`01814000   fileinfo fileinfo.sys Mon Jul 13 19:34:25 2009 (4A5BC481)
fffff880`00e00000 fffff880`00e4a000   FLTMGR   FLTMGR.SYS   Sun Dec 31 20:41:16 2017 (5A4991BC)
fffff880`05504000 fffff880`0550e000   FortiFilter FortiFilter.sys Tue Nov 18 14:09:01 2014 (546B994D)
fffff880`03fd5000 fffff880`03fea000   FortiShield FortiShield.sys Thu Nov 05 14:10:29 2015 (563BA9A5)
fffff880`0271e000 fffff880`02728000   Fs_Rec   Fs_Rec.sys   Wed Feb 29 22:41:06 2012 (4F4EEFD2)
fffff880`06ac3000 fffff880`06acb000   ftvnic   ftvnic.sys   Thu Feb 12 19:37:53 2009 (4994C0E1)
fffff880`02600000 fffff880`0263a000   fvevol   fvevol.sys   Wed Jan 23 22:11:24 2013 (5100A65C)
fffff880`0282b000 fffff880`02874000   fwpkclnt fwpkclnt.sys Sun Aug 12 15:45:55 2018 (5B708E73)
fffff800`03bde000 fffff800`03c26000   hal      hal.dll      Tue Jan 08 22:06:48 2019 (5C356548)
fffff880`06bc2000 fffff880`06be6000   HDAudBus HDAudBus.sys Tue Aug 27 21:35:47 2013 (521D53F3)
fffff880`07294000 fffff880`072ad000   HIDCLASS HIDCLASS.SYS Tue Jan 08 21:45:27 2019 (5C356047)
fffff880`06b80000 fffff880`06b88280   HIDPARSE HIDPARSE.SYS Tue Jan 08 21:45:27 2019 (5C356047)
fffff880`08de9000 fffff880`08df7000   hidusb   hidusb.sys   Tue Jan 08 21:45:28 2019 (5C356048)
fffff880`05900000 fffff880`059c8000   HTTP     HTTP.sys     Sun Dec 31 20:41:37 2017 (5A4991D1)
fffff880`02897000 fffff880`028a0000   hwpolicy hwpolicy.sys Sat Nov 20 04:18:54 2010 (4CE7927E)
fffff880`06fac000 fffff880`06fca000   i8042prt i8042prt.sys Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`0183e000 fffff880`0238b000   iaStorA  iaStorA.sys  Tue Jun 06 12:27:18 2017 (5936D7E6)
fffff880`029f4000 fffff880`02a00000   iaStorF  iaStorF.sys  Tue Jun 06 12:27:23 2017 (5936D7EB)
fffff880`06bac000 fffff880`06bc2000   ibmpmdrv ibmpmdrv.sys Thu Aug 30 20:38:23 2018 (5B888DFF)
fffff880`0767f000 fffff880`0813e000   igdkmd64 igdkmd64.sys Wed Oct 31 10:32:25 2018 (5BD9BCF9)
fffff880`07200000 fffff880`07277000   IntcDAud IntcDAud.sys Wed Jun 21 22:59:52 2017 (594B32A8)
fffff880`057d8000 fffff880`057ee000   intelppm intelppm.sys Tue Jan 08 21:34:40 2019 (5C355DC0)
fffff880`072c6000 fffff880`0732c000   iusb3hub iusb3hub.sys Thu May 11 08:15:16 2017 (591455D4)
fffff880`0683a000 fffff880`06905000   iusb3xhc iusb3xhc.sys Thu May 11 08:15:19 2017 (591455D7)
fffff880`04e91000 fffff880`04e9d000   iwdbus   iwdbus.sys   Tue Feb 10 14:04:50 2015 (54DA5652)
fffff880`06b89000 fffff880`06b98000   kbdclass kbdclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff800`04000000 fffff800`0400a000   kdcom    kdcom.dll    Sat Feb 05 11:52:49 2011 (4D4D8061)
fffff880`0103c000 fffff880`01745000   kl1      kl1.sys      Fri Apr 01 10:20:28 2016 (56FE83AC)
fffff880`0102a000 fffff880`0103a000   klbackupdisk klbackupdisk.sys Mon Aug 06 02:56:33 2018 (5B67F121)
fffff880`03fba000 fffff880`03fd5000   klbackupflt klbackupflt.sys Wed Jan 31 11:07:22 2018 (5A71E9BA)
fffff880`05a00000 fffff880`05a45000   klflt    klflt.sys    Fri Aug 24 04:01:37 2018 (5B7FBB61)
fffff880`04ff4000 fffff880`04fff000   klfltdev klfltdev.sys Fri Dec 09 06:52:49 2016 (584A9B11)
fffff880`03e39000 fffff880`03f90000   klhk     klhk.sys     Wed Sep 19 05:58:51 2018 (5BA21DDB)
fffff880`04e9d000 fffff880`04fbe000   klif     klif.sys     Fri Sep 28 07:25:59 2018 (5BAE0FC7)
fffff880`05537000 fffff880`05543000   klim6    klim6.sys    Thu May 17 07:43:44 2018 (5AFD6AF0)
fffff880`04e43000 fffff880`04e4e000   klpd     klpd.sys     Fri Mar 24 09:45:18 2017 (58D522EE)
fffff880`03f90000 fffff880`03fa2000   kltdi    kltdi.sys    Thu Jun 15 04:57:08 2017 (59424BE4)
fffff880`0550e000 fffff880`05537000   klwtp    klwtp.sys    Wed May 16 08:27:39 2018 (5AFC23BB)
fffff880`05400000 fffff880`05430000   kneps    kneps.sys    Thu Sep 13 05:08:32 2018 (5B9A2910)
fffff880`04e00000 fffff880`04e43000   ks       ks.sys       Tue Aug 28 01:50:19 2018 (5B84E29B)
fffff880`025c7000 fffff880`025e2000   ksecdd   ksecdd.sys   Tue Jan 15 01:31:27 2019 (5C3D7E3F)
fffff880`02800000 fffff880`0282b000   ksecpkg  ksecpkg.sys  Tue Jan 15 01:38:02 2019 (5C3D7FCA)
fffff880`08de3000 fffff880`08de8200   ksthunk  ksthunk.sys  Mon Jul 13 20:00:19 2009 (4A5BCA93)
fffff880`065d7000 fffff880`065ec000   lltdio   lltdio.sys   Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`0738b000 fffff880`073ae000   luafv    luafv.sys    Wed Oct 11 20:20:09 2017 (59DEB539)
fffff880`00ce1000 fffff880`00d30000   mcupdate_GenuineIntel mcupdate_GenuineIntel.dll Sat Nov 20 08:03:51 2010 (4CE7C737)
fffff880`27b70000 fffff880`27b7e000   monitor  monitor.sys  Mon Jul 13 19:38:52 2009 (4A5BC58C)
fffff880`06b98000 fffff880`06ba7000   mouclass mouclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff880`08800000 fffff880`0880d000   mouhid   mouhid.sys   Mon Jul 13 20:00:20 2009 (4A5BCA94)
fffff880`00e4a000 fffff880`00e64000   mountmgr mountmgr.sys Sun May 07 10:52:08 2017 (590F3498)
fffff880`059e5000 fffff880`059fd000   mpsdrv   mpsdrv.sys   Fri Aug 10 11:27:40 2018 (5B6DAEEC)
fffff880`0d071000 fffff880`0d09a000   mrxdav   mrxdav.sys   Thu Sep 08 10:55:15 2016 (57D17BD3)
fffff880`05800000 fffff880`0582d000   mrxsmb   mrxsmb.sys   Tue Jan 15 01:32:34 2019 (5C3D7E82)
fffff880`09031000 fffff880`0907f000   mrxsmb10 mrxsmb10.sys Tue Jan 15 01:32:11 2019 (5C3D7E6B)
fffff880`0907f000 fffff880`090a3000   mrxsmb20 mrxsmb20.sys Tue Jan 15 01:32:08 2019 (5C3D7E68)
fffff880`04fe9000 fffff880`04ff4000   Msfs     Msfs.SYS     Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`017a5000 fffff880`017af000   msisadrv msisadrv.sys Sat Feb 10 12:21:45 2018 (5A7F2A29)
fffff880`00c73000 fffff880`00cd1000   msrpc    msrpc.sys    Sun Nov 11 11:15:23 2018 (5BE8559B)
fffff880`055f1000 fffff880`055fc000   mssmbios mssmbios.sys Sat Feb 10 12:25:38 2018 (5A7F2B12)
fffff880`027d8000 fffff880`027f6000   mup      mup.sys      Tue Jan 06 20:48:27 2015 (54AC906B)
fffff880`028a2000 fffff880`02994000   ndis     ndis.sys     Fri Jul 06 11:18:04 2018 (5B3F882C)
fffff880`06ff0000 fffff880`06ffc000   ndistapi ndistapi.sys Fri Dec 07 21:47:13 2018 (5C0B30B1)
fffff880`05896000 fffff880`058a9000   ndisuio  ndisuio.sys  Sat Nov 20 05:50:08 2010 (4CE7A7E0)
fffff880`07600000 fffff880`0762f000   ndiswan  ndiswan.sys  Sat Nov 20 05:52:32 2010 (4CE7A870)
fffff880`02400000 fffff880`02415000   NDProxy  NDProxy.SYS  Fri Dec 07 21:47:15 2018 (5C0B30B3)
fffff880`05543000 fffff880`05553000   netbios  netbios.sys  Sun Dec 31 20:55:00 2017 (5A4994F4)
fffff880`05a45000 fffff880`05a8a000   netbt    netbt.sys    Fri Aug 11 01:59:59 2017 (598D47DF)
fffff880`02994000 fffff880`029f4000   NETIO    NETIO.SYS    Sun Aug 12 15:46:07 2018 (5B708E7F)
fffff880`06c00000 fffff880`06f9f000   Netwsw04 Netwsw04.sys Mon Aug 27 05:17:21 2018 (5B83C1A1)
fffff880`03fea000 fffff880`03ffb000   Npfs     Npfs.SYS     Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`055e5000 fffff880`055f1000   nsiproxy nsiproxy.sys Fri Aug 11 01:58:55 2017 (598D479F)
fffff800`03602000 fffff800`03bde000   nt       ntkrnlmp.exe Tue Jan 08 21:35:55 2019 (5C355E0B)
fffff880`0241f000 fffff880`025c7000   Ntfs     Ntfs.sys     Fri Dec 28 14:28:19 2018 (5C267953)
fffff880`04e4e000 fffff880`04e57000   Null     Null.SYS     Mon Jul 13 19:19:37 2009 (4A5BC109)
fffff880`05842000 fffff880`05896000   nwifi    nwifi.sys    Wed Sep 13 11:05:20 2017 (59B94930)
fffff880`055de000 fffff880`055e5000   omnismi  omnismi.sys  Wed Apr 03 23:39:27 2013 (515CF5EF)
fffff880`054c8000 fffff880`054ee000   pacer    pacer.sys    Sun Dec 31 20:55:04 2017 (5A4994F8)
fffff880`01000000 fffff880`01015000   partmgr  partmgr.sys  Sat Mar 17 01:06:09 2012 (4F641BC1)
fffff880`017af000 fffff880`017e2000   pci      pci.sys      Sat Feb 10 12:22:10 2018 (5A7F2A42)
fffff880`02702000 fffff880`02713000   pcw      pcw.sys      Mon Jul 13 19:19:27 2009 (4A5BC0FF)
fffff880`090a3000 fffff880`0914d000   peauth   peauth.sys   Tue Jun 14 13:11:06 2016 (57603AAA)
fffff880`02713000 fffff880`0271e000   pmdrvs   pmdrvs.sys   Thu Aug 30 20:38:36 2018 (5B888E0C)
fffff880`0732c000 fffff880`07369000   portcls  portcls.sys  Tue Dec 08 13:12:06 2015 (56671D76)
fffff880`06bf5000 fffff880`06bfdc00   pppop64  pppop64.sys  Wed Jul 15 17:57:15 2009 (4A5E50BB)
fffff880`057ee000 fffff880`057fc000   psadd    psadd.sys    Mon Dec 26 20:09:28 2011 (4EF91AC8)
fffff880`00d30000 fffff880`00d44000   PSHED    PSHED.dll    Mon Jul 13 21:32:23 2009 (4A5BE027)
fffff880`081ba000 fffff880`081de000   rasl2tp  rasl2tp.sys  Sat Nov 20 05:52:34 2010 (4CE7A872)
fffff880`0762f000 fffff880`0764a000   raspppoe raspppoe.sys Mon Jul 13 20:10:17 2009 (4A5BCCE9)
fffff880`0764a000 fffff880`0766b000   raspptp  raspptp.sys  Sat Nov 20 05:52:31 2010 (4CE7A86F)
fffff880`081de000 fffff880`081f8000   rassstp  rassstp.sys  Mon Jul 13 20:10:25 2009 (4A5BCCF1)
fffff880`0558b000 fffff880`055de000   rdbss    rdbss.sys    Wed Oct 11 20:20:28 2017 (59DEB54C)
fffff880`0766b000 fffff880`07676000   rdpbus   rdpbus.sys   Mon Jul 13 20:17:46 2009 (4A5BCEAA)
fffff880`04fce000 fffff880`04fd7000   RDPCDD   RDPCDD.sys   Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`0bd12000 fffff880`0bd40000   rdpdr    rdpdr.sys    Sat Nov 20 06:06:41 2010 (4CE7ABC1)
fffff880`04fd7000 fffff880`04fe0000   rdpencdd rdpencdd.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`04fe0000 fffff880`04fe9000   rdprefmp rdprefmp.sys Mon Jul 13 20:16:35 2009 (4A5BCE63)
fffff880`0bd5b000 fffff880`0bd95000   RDPWD    RDPWD.SYS    Wed Jul 16 21:21:53 2014 (53C72531)
fffff880`02774000 fffff880`027ae000   rdyboost rdyboost.sys Sun Dec 31 20:44:40 2017 (5A499288)
fffff880`058a9000 fffff880`058c1000   rspndr   rspndr.sys   Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`0880e000 fffff880`08de3000   RTKVHD64 RTKVHD64.sys Tue Aug 01 06:05:51 2017 (5980527F)
fffff880`06939000 fffff880`069f8000   RtsPer   RtsPer.sys   Fri Nov 13 01:22:42 2015 (564581B2)
fffff880`06be6000 fffff880`06bf5000   Smb_driver_Intel Smb_driver_Intel.sys Wed Oct 31 23:50:28 2018 (5BDA7804)
fffff880`0288f000 fffff880`02897000   spldr    spldr.sys    Mon May 11 12:56:27 2009 (4A0858BB)
fffff880`0a840000 fffff880`0a9e1000   SPUVCbv64 SPUVCbv64.sys Mon Apr 25 02:47:22 2016 (571DBD7A)
fffff880`0bc7b000 fffff880`0bd12000   srv      srv.sys      Tue Jan 08 21:35:42 2019 (5C355DFE)
fffff880`0bc13000 fffff880`0bc7b000   srv2     srv2.sys     Tue Jan 08 21:35:33 2019 (5C355DF5)
fffff880`0914d000 fffff880`0917e000   srvnet   srvnet.sys   Tue Jan 08 21:35:27 2019 (5C355DEF)
fffff880`0917e000 fffff880`09186000   SSPORT   SSPORT.sys   Thu Aug 11 19:07:32 2005 (42FBDA34)
fffff880`0238b000 fffff880`023ef000   storport storport.sys Fri Aug 14 13:09:20 2015 (55CE20C0)
fffff880`06bfe000 fffff880`06bff480   swenum   swenum.sys   Sat Feb 10 12:38:10 2018 (5A7F2E02)
fffff880`06acd000 fffff880`06b80000   SynTP    SynTP.sys    Wed Oct 31 23:50:00 2018 (5BDA77E8)
fffff880`02a02000 fffff880`02bfd000   tcpip    tcpip.sys    Sun Aug 12 15:46:49 2018 (5B708EA9)
fffff880`09188000 fffff880`0919a000   tcpipreg tcpipreg.sys Thu Jul 07 11:08:06 2016 (577E7056)
fffff880`03e22000 fffff880`03e2f000   TDI      TDI.SYS      Sat Nov 20 04:22:06 2010 (4CE7933E)
fffff880`0bd40000 fffff880`0bd4b000   tdtcp    tdtcp.sys    Thu Feb 16 23:57:32 2012 (4F3DDE3C)
fffff880`03e00000 fffff880`03e22000   tdx      tdx.sys      Sat Jul 29 10:56:29 2017 (597CA21D)
fffff880`06907000 fffff880`06939000   TeeDriverx64 TeeDriverx64.sys Sun Nov 19 06:39:31 2017 (5A116D73)
fffff880`05577000 fffff880`0558b000   termdd   termdd.sys   Sat Feb 10 12:45:02 2018 (5A7F2F9E)
fffff880`06a8c000 fffff880`06ab3000   tpm      tpm.sys      Fri Feb 05 12:39:10 2016 (56B4DE3E)
fffff880`0556e000 fffff880`05577000   Tppwr64v Tppwr64v.sys Wed Feb 15 23:57:36 2017 (58A53140)
fffff960`005f0000 fffff960`005fa000   TSDDD    TSDDD.dll    unavailable (00000000)
fffff880`0bd4b000 fffff880`0bd5b000   tssecsrv tssecsrv.sys Sun Aug 13 17:45:28 2017 (5990C878)
fffff880`057b2000 fffff880`057d8000   tunnel   tunnel.sys   Sat Nov 20 05:51:50 2010 (4CE7A846)
fffff880`065ed000 fffff880`065ff000   umbus    umbus.sys    Sat Nov 20 05:44:37 2010 (4CE7A695)
fffff880`06800000 fffff880`06838000   usb3Hub  usb3Hub.sys  Fri Jan 09 00:53:47 2015 (54AF6CEB)
fffff880`07277000 fffff880`07294000   usbccgp  usbccgp.sys  Wed May 02 11:32:35 2018 (5AE9DA13)
fffff880`06905000 fffff880`06906e80   USBD     USBD.SYS     Wed May 02 11:32:25 2018 (5AE9DA09)
fffff880`017e2000 fffff880`017ef000   vdrvroot vdrvroot.sys Sat Feb 10 12:38:45 2018 (5A7F2E25)
fffff880`04e5e000 fffff880`04e6c000   vga      vga.sys      Mon Jul 13 19:38:47 2009 (4A5BC587)
fffff880`04e6c000 fffff880`04e91000   VIDEOPRT VIDEOPRT.SYS Tue Jan 08 21:38:22 2019 (5C355E9E)
fffff880`02874000 fffff880`02884000   vmstorfl vmstorfl.sys Sat Nov 20 04:57:30 2010 (4CE79B8A)
fffff880`00f89000 fffff880`00f9d000   volmgr   volmgr.sys   Sat Feb 10 12:21:56 2018 (5A7F2A34)
fffff880`00f9d000 fffff880`00ff9000   volmgrx  volmgrx.sys  Fri Jul 07 10:53:40 2017 (595FA074)
fffff880`02728000 fffff880`02774000   volsnap  volsnap.sys  Thu Feb 24 22:38:18 2011 (4D67242A)
fffff880`06f9f000 fffff880`06fac000   vwifibus vwifibus.sys Mon Jul 13 20:07:21 2009 (4A5BCC39)
fffff880`054ee000 fffff880`05504000   vwififlt vwififlt.sys Mon Jul 13 20:07:22 2009 (4A5BCC3A)
fffff880`058f6000 fffff880`05900000   vwifimp  vwifimp.sys  Mon Jul 13 20:07:28 2009 (4A5BCC40)
fffff880`05553000 fffff880`0556e000   wanarp   wanarp.sys   Fri Dec 07 21:47:22 2018 (5C0B30BA)
fffff880`04fbe000 fffff880`04fce000   watchdog watchdog.sys Mon Jul 13 19:37:35 2009 (4A5BC53F)
fffff880`00eb7000 fffff880`00f79000   Wdf01000 Wdf01000.sys Fri Jun 21 23:13:05 2013 (51C51641)
fffff880`00f79000 fffff880`00f89000   WDFLDR   WDFLDR.SYS   Wed Jul 25 22:29:04 2012 (5010AB70)
fffff880`054bf000 fffff880`054c8000   wfplwf   wfplwf.sys   Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff960`00070000 fffff960`00399000   win32k   win32k.sys   Mon Jan 07 12:18:58 2019 (5C338A02)
fffff880`073ae000 fffff880`073bf000   WinUSB   WinUSB.sys   Sat Nov 20 05:43:56 2010 (4CE7A66C)
fffff880`06a83000 fffff880`06a8c000   wmiacpi  wmiacpi.sys  Sat Feb 10 12:25:26 2018 (5A7F2B06)
fffff880`0179c000 fffff880`017a5000   WMILIB   WMILIB.SYS   Mon Jul 13 19:19:51 2009 (4A5BC117)
fffff880`072ad000 fffff880`072c6000   WudfPf   WudfPf.sys   Wed Jul 25 22:26:45 2012 (5010AAE5)
fffff880`00da3000 fffff880`00dd9000   WUDFRd   WUDFRd.sys   Wed Jul 25 22:26:06 2012 (5010AABE)
fffff880`06ab3000 fffff880`06ac3000   XtuAcpiDriver XtuAcpiDriver.sys Wed Apr 12 04:58:50 2017 (58EDEC4A)

Unloaded modules:
fffff880`0d018000 fffff880`0d022000   hiber_storpo
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000A000
fffff880`27010000 fffff880`27b5d000   hiber_iaStor
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00B4D000
fffff880`27b5d000 fffff880`27b70000   hiber_dumpfv
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00013000
fffff880`0d00a000 fffff880`0d018000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`2b5e5000 fffff880`2b5f3000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`2aa00000 fffff880`2aa71000   spsys.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00071000
fffff880`0d000000 fffff880`0d00a000   hiber_storpo
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000A000
fffff880`2aa85000 fffff880`2b5d2000   hiber_iaStor
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00B4D000
fffff880`2b5d2000 fffff880`2b5e5000   hiber_dumpfv
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00013000
fffff880`0d1f0000 fffff880`0d1fe000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`2b571000 fffff880`2b57f000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0d1e6000 fffff880`0d1f0000   hiber_storpo
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000A000
fffff880`2aa11000 fffff880`2b55e000   hiber_iaStor
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00B4D000
fffff880`2b55e000 fffff880`2b571000   hiber_dumpfv
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00013000
fffff880`0d1d8000 fffff880`0d1e6000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0d1ca000 fffff880`0d1d8000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0d1b2000 fffff880`0d1c0000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0d1c0000 fffff880`0d1ca000   hiber_storpo
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000A000
fffff880`2ee75000 fffff880`2f9c2000   hiber_iaStor
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00B4D000
fffff880`2f9c2000 fffff880`2f9d5000   hiber_dumpfv
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00013000
fffff880`2f9e6000 fffff880`2f9f4000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0d1a8000 fffff880`0d1b2000   hiber_storpo
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000A000
fffff880`2ee86000 fffff880`2f9d3000   hiber_iaStor
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00B4D000
fffff880`2f9d3000 fffff880`2f9e6000   hiber_dumpfv
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00013000
fffff880`0d19a000 fffff880`0d1a8000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0d18c000 fffff880`0d19a000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0d174000 fffff880`0d182000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0d182000 fffff880`0d18c000   hiber_storpo
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000A000
fffff880`2aaa5000 fffff880`2b5f2000   hiber_iaStor
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00B4D000
fffff880`2aa00000 fffff880`2aa13000   hiber_dumpfv
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00013000
fffff880`0d166000 fffff880`0d174000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0d13e000 fffff880`0d14c000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0d14c000 fffff880`0d156000   hiber_storpo
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000A000
fffff880`2ee88000 fffff880`2f9d5000   hiber_iaStor
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00B4D000
fffff880`2f9d5000 fffff880`2f9e8000   hiber_dumpfv
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00013000
fffff880`2f9e2000 fffff880`2f9f0000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0d134000 fffff880`0d13e000   hiber_storpo
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000A000
fffff880`2ee82000 fffff880`2f9cf000   hiber_iaStor
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00B4D000
fffff880`2f9cf000 fffff880`2f9e2000   hiber_dumpfv
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00013000
fffff880`0d126000 fffff880`0d134000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0d10e000 fffff880`0d11c000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0d11c000 fffff880`0d126000   hiber_storpo
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000A000
fffff880`2aa04000 fffff880`2b551000   hiber_iaStor
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00B4D000
fffff880`2b551000 fffff880`2b564000   hiber_dumpfv
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00013000
fffff880`0d100000 fffff880`0d10e000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0d0e8000 fffff880`0d0f6000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0d0f6000 fffff880`0d100000   hiber_storpo
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000A000
fffff880`2aa2d000 fffff880`2b57a000   hiber_iaStor
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00B4D000
fffff880`2b57a000 fffff880`2b58d000   hiber_dumpfv
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00013000
fffff880`0d0da000 fffff880`0d0e8000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
Bugcheck code 0000001A
Arguments 00000000`00041287 00000000`00000000 00000000`00000000 00000000`00000000
 
The other dump -

Code:
Microsoft (R) Windows Debugger Version 10.0.10075.9 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Users\PalmDesert\AppData\Local\Temp\SAL424.tmp\022719-11934-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available


************* Symbol Path validation summary **************
Response                         Time (ms)     Location
Deferred                                       SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.24358.amd64fre.win7sp1_ldr_escrow.190208-1418
Machine Name:
Kernel base = 0xfffff800`03651000 PsLoadedModuleList = 0xfffff800`0388ac90
Debug session time: Wed Feb 27 03:28:17.002 2019 (UTC - 5:00)
System Uptime: 0 days 12:19:34.879
Loading Kernel Symbols
...............................................................
................................................................
.........................................................
Loading User Symbols
Loading unloaded module list
.............................
No .natvis files found at C:\Program Files (x86)\Windows Kits\10\Debuggers\x64\Visualizers.
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck C5, {8, 2, 1, fffff8000382b077}

Probably caused by : fileinfo.sys ( fileinfo!FIStreamQueryWorker+9e )

Followup:     MachineOwner
---------

Processing initial command '!analyze -v;r;kv;lmtn;lmtsmn;.bugcheck'
1: kd> !analyze -v;r;kv;lmtn;lmtsmn;.bugcheck
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

DRIVER_CORRUPTED_EXPOOL (c5)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high.  This is
caused by drivers that have corrupted the system pool.  Run the driver
verifier against any new (or suspect) drivers, and if that doesn't turn up
the culprit, then use gflags to enable special pool.
Arguments:
Arg1: 0000000000000008, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000001, value 0 = read operation, 1 = write operation
Arg4: fffff8000382b077, address which referenced memory

Debugging Details:
------------------


SYSTEM_SKU:  LENOVO_MT_20FN_BU_Think_FM_ThinkPad T460

SYSTEM_VERSION:  ThinkPad T460

BIOS_DATE:  01/25/2019

BASEBOARD_PRODUCT:  20FN003SUS

BASEBOARD_VERSION:  SDK0J40705 WIN

BUGCHECK_P1: 8

BUGCHECK_P2: 2

BUGCHECK_P3: 1

BUGCHECK_P4: fffff8000382b077

BUGCHECK_STR:  0xC5_2

CURRENT_IRQL:  2

FAULTING_IP:
nt!ExAllocatePoolWithTag+537
fffff800`0382b077 48895808        mov     qword ptr [rax+8],rbx

CPU_COUNT: 4

CPU_MHZ: 960

CPU_VENDOR:  GenuineIntel

CPU_FAMILY: 6

CPU_MODEL: 4e

CPU_STEPPING: 3

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  WIN7_DRIVER_FAULT

PROCESS_NAME:  System

ANALYSIS_VERSION: 10.0.10075.9 amd64fre

TRAP_FRAME:  fffff880043f01b0 -- (.trap 0xfffff880043f01b0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=fffffa8013509010
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8000382b077 rsp=fffff880043f0340 rbp=0000000000001000
 r8=0000000000000000  r9=fffff8000384bdb0 r10=fffff8000384b888
r11=fffff880043f05b8 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei pl zr na po nc
nt!ExAllocatePoolWithTag+0x537:
fffff800`0382b077 48895808        mov     qword ptr [rax+8],rbx ds:00000000`00000008=????????????????
Resetting default scope

LAST_CONTROL_TRANSFER:  from fffff800036f2f69 to fffff800036e4ba0

STACK_TEXT:  
fffff880`043f0068 fffff800`036f2f69 : 00000000`0000000a 00000000`00000008 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
fffff880`043f0070 fffff800`036f0d88 : 00000000`00000001 00000000`00000008 fffff880`043f0300 fffff800`0384bdb0 : nt!KiBugCheckDispatch+0x69
fffff880`043f01b0 fffff800`0382b077 : fffffa80`13388c58 fffff800`03687f1e fffffa80`0945b8b0 00000000`00000000 : nt!KiPageFault+0x448
fffff880`043f0340 fffff800`03669a2e : fffffa80`00000000 fffffa80`13061ef0 fffffa80`13061dc0 fffffa80`00000000 : nt!ExAllocatePoolWithTag+0x537
fffff880`043f0430 fffff800`036762de : fffffa80`13061ef0 00000000`00000000 00000000`00000000 fffffa80`067a2b50 : nt!ExpExpandResourceOwnerTable+0x4e
fffff880`043f0480 fffff800`036886f6 : fffffa80`0ff89dd0 fffff800`0382a23d fffffa80`0fa83f30 00000000`00000020 : nt!ExpFindEmptyEntry+0x4e
fffff880`043f04b0 fffff880`0241e549 : 00000000`c00000d8 fffff8a0`15179010 00000000`00000000 fffff880`043f06e0 : nt!ExAcquireResourceSharedLite+0x276
fffff880`043f0520 fffff880`0249b09f : 00000000`00000000 00000000`0000000c fffff8a0`1d425010 fffff880`043f06e0 : Ntfs!NtfsAcquireSharedFcb+0x69
fffff880`043f0570 fffff880`02499816 : fffff880`043f06e0 fffffa80`121bdb80 00000000`0000000c fffffa80`0000000c : Ntfs!NtfsCommonQueryInformation+0x35f
fffff880`043f0640 fffff880`02499ff4 : fffff880`043f06e0 fffffa80`121bdb80 fffffa80`121bdb80 00000000`00000000 : Ntfs!NtfsFsdDispatchSwitch+0x106
fffff880`043f06c0 fffff880`00e7ebbc : 00000000`00000001 fffff880`043f09a0 00000000`0000000c fffff880`009c0180 : Ntfs!NtfsFsdDispatchWait+0x14
fffff880`043f08b0 fffff880`00e8041b : fffff880`043f09a0 fffffa80`095a5010 fffffa80`0959f030 fffffa80`0a196960 : FLTMGR!FltpQueryInformationFile+0xfc
fffff880`043f0920 fffff880`00e85eac : 00000000`0000199a fffffa80`095a5010 fffff880`043f0af0 00000000`00000000 : FLTMGR!QueryStandardLinkInformation+0x4b
fffff880`043f0980 fffff880`00e624eb : fffffa80`10223310 fffffa80`095adbb0 fffff880`043f0af0 00000000`00000000 : FLTMGR! ?? ::NNGAKEGL::`string'+0x24ba
fffff880`043f09e0 fffff880`00e7d5bf : fffffa80`130fbc40 fffff8a0`03c643b8 00000000`00000000 fffffa80`10223310 : FLTMGR!FltpGetFileNameInformation+0x1fb
fffff880`043f0a50 fffff880`023d5962 : fffffa80`10223310 00000000`00000000 fffffa80`0a196960 fffff880`00e63e79 : FLTMGR!FltGetFileNameInformationUnsafe+0x7f
fffff880`043f0ac0 fffff880`00e8b2b3 : 00000000`00000000 00000000`00000001 fffffa80`095adbb0 00000000`00000000 : fileinfo!FIStreamQueryWorker+0x9e
fffff880`043f0b30 fffff800`0367fb39 : fffff880`00e8b270 fffff800`038617f8 fffffa80`067a2b50 fffffa80`0b244550 : FLTMGR!FltpProcessGenericWorkItem+0x43
fffff880`043f0b70 fffff800`03992890 : 00000000`00000000 fffff880`041bb180 00000000`00000080 00000000`00000001 : nt!ExpWorkerThread+0x111
fffff880`043f0c00 fffff800`036eaba6 : fffff880`041bb180 fffffa80`067a2b50 fffff880`041ca140 00000000`00000000 : nt!PspSystemThreadStartup+0x194
fffff880`043f0c40 00000000`00000000 : fffff880`043f1000 fffff880`043eb000 fffff880`043f08a0 00000000`00000000 : nt!KxStartSystemThread+0x16


STACK_COMMAND:  kb

FOLLOWUP_IP:
fileinfo!FIStreamQueryWorker+9e
fffff880`023d5962 85c0            test    eax,eax

SYMBOL_STACK_INDEX:  10

SYMBOL_NAME:  fileinfo!FIStreamQueryWorker+9e

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: fileinfo

IMAGE_NAME:  fileinfo.sys

DEBUG_FLR_IMAGE_TIMESTAMP:  4a5bc481

IMAGE_VERSION:  6.1.7600.16385

FAILURE_BUCKET_ID:  X64_0xC5_2_fileinfo!FIStreamQueryWorker+9e

BUCKET_ID:  X64_0xC5_2_fileinfo!FIStreamQueryWorker+9e

PRIMARY_PROBLEM_CLASS:  X64_0xC5_2_fileinfo!FIStreamQueryWorker+9e

ANALYSIS_SOURCE:  KM

FAILURE_ID_HASH_STRING:  km:x64_0xc5_2_fileinfo!fistreamqueryworker+9e

FAILURE_ID_HASH:  {611e7bee-1c2d-e5b9-260a-8632ad31b8df}

Followup:     MachineOwner
---------

rax=fffff880043f0170 rbx=fffff8000384bdb0 rcx=000000000000000a
rdx=0000000000000008 rsi=0000000000000004 rdi=0000000000000000
rip=fffff800036e4ba0 rsp=fffff880043f0068 rbp=fffff880043f0230
 r8=0000000000000002  r9=0000000000000001 r10=fffff8000382b077
r11=fffff6fb7da00000 r12=fffff8000384b880 r13=0000000000000000
r14=0000000000000000 r15=0000000061546552
iopl=0         nv up ei ng nz na pe nc
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00000282
nt!KeBugCheckEx:
fffff800`036e4ba0 48894c2408      mov     qword ptr [rsp+8],rcx ss:0018:fffff880`043f0070=000000000000000a
 # Child-SP          RetAddr           : Args to Child                                                           : Call Site
00 fffff880`043f0068 fffff800`036f2f69 : 00000000`0000000a 00000000`00000008 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
01 fffff880`043f0070 fffff800`036f0d88 : 00000000`00000001 00000000`00000008 fffff880`043f0300 fffff800`0384bdb0 : nt!KiBugCheckDispatch+0x69
02 fffff880`043f01b0 fffff800`0382b077 : fffffa80`13388c58 fffff800`03687f1e fffffa80`0945b8b0 00000000`00000000 : nt!KiPageFault+0x448 (TrapFrame @ fffff880`043f01b0)
03 fffff880`043f0340 fffff800`03669a2e : fffffa80`00000000 fffffa80`13061ef0 fffffa80`13061dc0 fffffa80`00000000 : nt!ExAllocatePoolWithTag+0x537
04 fffff880`043f0430 fffff800`036762de : fffffa80`13061ef0 00000000`00000000 00000000`00000000 fffffa80`067a2b50 : nt!ExpExpandResourceOwnerTable+0x4e
05 fffff880`043f0480 fffff800`036886f6 : fffffa80`0ff89dd0 fffff800`0382a23d fffffa80`0fa83f30 00000000`00000020 : nt!ExpFindEmptyEntry+0x4e
06 fffff880`043f04b0 fffff880`0241e549 : 00000000`c00000d8 fffff8a0`15179010 00000000`00000000 fffff880`043f06e0 : nt!ExAcquireResourceSharedLite+0x276
07 fffff880`043f0520 fffff880`0249b09f : 00000000`00000000 00000000`0000000c fffff8a0`1d425010 fffff880`043f06e0 : Ntfs!NtfsAcquireSharedFcb+0x69
08 fffff880`043f0570 fffff880`02499816 : fffff880`043f06e0 fffffa80`121bdb80 00000000`0000000c fffffa80`0000000c : Ntfs!NtfsCommonQueryInformation+0x35f
09 fffff880`043f0640 fffff880`02499ff4 : fffff880`043f06e0 fffffa80`121bdb80 fffffa80`121bdb80 00000000`00000000 : Ntfs!NtfsFsdDispatchSwitch+0x106
0a fffff880`043f06c0 fffff880`00e7ebbc : 00000000`00000001 fffff880`043f09a0 00000000`0000000c fffff880`009c0180 : Ntfs!NtfsFsdDispatchWait+0x14
0b fffff880`043f08b0 fffff880`00e8041b : fffff880`043f09a0 fffffa80`095a5010 fffffa80`0959f030 fffffa80`0a196960 : FLTMGR!FltpQueryInformationFile+0xfc
0c fffff880`043f0920 fffff880`00e85eac : 00000000`0000199a fffffa80`095a5010 fffff880`043f0af0 00000000`00000000 : FLTMGR!QueryStandardLinkInformation+0x4b
0d fffff880`043f0980 fffff880`00e624eb : fffffa80`10223310 fffffa80`095adbb0 fffff880`043f0af0 00000000`00000000 : FLTMGR! ?? ::NNGAKEGL::`string'+0x24ba
0e fffff880`043f09e0 fffff880`00e7d5bf : fffffa80`130fbc40 fffff8a0`03c643b8 00000000`00000000 fffffa80`10223310 : FLTMGR!FltpGetFileNameInformation+0x1fb
0f fffff880`043f0a50 fffff880`023d5962 : fffffa80`10223310 00000000`00000000 fffffa80`0a196960 fffff880`00e63e79 : FLTMGR!FltGetFileNameInformationUnsafe+0x7f
10 fffff880`043f0ac0 fffff880`00e8b2b3 : 00000000`00000000 00000000`00000001 fffffa80`095adbb0 00000000`00000000 : fileinfo!FIStreamQueryWorker+0x9e
11 fffff880`043f0b30 fffff800`0367fb39 : fffff880`00e8b270 fffff800`038617f8 fffffa80`067a2b50 fffffa80`0b244550 : FLTMGR!FltpProcessGenericWorkItem+0x43
12 fffff880`043f0b70 fffff800`03992890 : 00000000`00000000 fffff880`041bb180 00000000`00000080 00000000`00000001 : nt!ExpWorkerThread+0x111
13 fffff880`043f0c00 fffff800`036eaba6 : fffff880`041bb180 fffffa80`067a2b50 fffff880`041ca140 00000000`00000000 : nt!PspSystemThreadStartup+0x194
14 fffff880`043f0c40 00000000`00000000 : fffff880`043f1000 fffff880`043eb000 fffff880`043f08a0 00000000`00000000 : nt!KxStartSystemThread+0x16
start             end                 module name
fffff800`00bf5000 fffff800`00bff000   kdcom    kdcom.dll    Sat Feb 05 11:52:49 2011 (4D4D8061)
fffff800`03609000 fffff800`03651000   hal      hal.dll      Fri Feb 08 19:23:37 2019 (5C5E1D89)
fffff800`03651000 fffff800`03c2d000   nt       ntkrnlmp.exe Fri Feb 08 18:52:23 2019 (5C5E1637)
fffff880`00c00000 fffff880`00c73000   CI       CI.dll       Fri May 11 17:20:19 2018 (5AF60913)
fffff880`00c73000 fffff880`00cd1000   msrpc    msrpc.sys    Sun Nov 11 11:15:23 2018 (5BE8559B)
fffff880`00cdf000 fffff880`00d2e000   mcupdate_GenuineIntel mcupdate_GenuineIntel.dll Sat Nov 20 08:03:51 2010 (4CE7C737)
fffff880`00d2e000 fffff880`00d42000   PSHED    PSHED.dll    Mon Jul 13 21:32:23 2009 (4A5BE027)
fffff880`00d42000 fffff880`00da1000   CLFS     CLFS.SYS     Sat Apr 07 11:45:40 2018 (5AC8E7A4)
fffff880`00da1000 fffff880`00dd2000   CLASSPNP CLASSPNP.SYS Sun Sep 28 20:46:24 2014 (5428ABE0)
fffff880`00e00000 fffff880`00e5c000   volmgrx  volmgrx.sys  Fri Jul 07 10:53:40 2017 (595FA074)
fffff880`00e5c000 fffff880`00ea6000   FLTMGR   FLTMGR.SYS   Sun Dec 31 20:41:16 2017 (5A4991BC)
fffff880`00ea6000 fffff880`00ec0000   mountmgr mountmgr.sys Sun May 07 10:52:08 2017 (590F3498)
fffff880`00ee2000 fffff880`00fa4000   Wdf01000 Wdf01000.sys Fri Jun 21 23:13:05 2013 (51C51641)
fffff880`00fa4000 fffff880`00fb4000   WDFLDR   WDFLDR.SYS   Wed Jul 25 22:29:04 2012 (5010AB70)
fffff880`00fb4000 fffff880`00fc8000   volmgr   volmgr.sys   Sat Feb 10 12:21:56 2018 (5A7F2A34)
fffff880`00fc8000 fffff880`00ff2000   ataport  ataport.SYS  Sun Aug 04 21:02:45 2013 (51FEF9B5)
fffff880`01000000 fffff880`01015000   partmgr  partmgr.sys  Sat Mar 17 01:06:09 2012 (4F641BC1)
fffff880`01015000 fffff880`0101e000   compbatt compbatt.sys Mon Jul 13 19:31:02 2009 (4A5BC3B6)
fffff880`0101e000 fffff880`0102a000   BATTC    BATTC.SYS    Mon Jul 13 19:31:01 2009 (4A5BC3B5)
fffff880`0102a000 fffff880`0103a000   klbackupdisk klbackupdisk.sys Mon Aug 06 02:56:33 2018 (5B67F121)
fffff880`0103c000 fffff880`01745000   kl1      kl1.sys      Fri Apr 01 10:20:28 2016 (56FE83AC)
fffff880`01745000 fffff880`0179c000   ACPI     ACPI.sys     Sat Feb 10 12:21:53 2018 (5A7F2A31)
fffff880`0179c000 fffff880`017a5000   WMILIB   WMILIB.SYS   Mon Jul 13 19:19:51 2009 (4A5BC117)
fffff880`017a5000 fffff880`017af000   msisadrv msisadrv.sys Sat Feb 10 12:21:45 2018 (5A7F2A29)
fffff880`017af000 fffff880`017e2000   pci      pci.sys      Sat Feb 10 12:22:10 2018 (5A7F2A42)
fffff880`017e2000 fffff880`017ef000   vdrvroot vdrvroot.sys Sat Feb 10 12:38:45 2018 (5A7F2E25)
fffff880`017ef000 fffff880`017f8000   atapi    atapi.sys    Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`01810000 fffff880`0235d000   iaStorA  iaStorA.sys  Tue Jun 06 12:27:18 2017 (5936D7E6)
fffff880`0235d000 fffff880`023c1000   storport storport.sys Fri Aug 14 13:09:20 2015 (55CE20C0)
fffff880`023c1000 fffff880`023cc000   amdxata  amdxata.sys  Fri Mar 19 12:18:18 2010 (4BA3A3CA)
fffff880`023cc000 fffff880`023e0000   fileinfo fileinfo.sys Mon Jul 13 19:34:25 2009 (4A5BC481)
fffff880`0240d000 fffff880`025b5000   Ntfs     Ntfs.sys     Fri Dec 28 14:28:19 2018 (5C267953)
fffff880`025b5000 fffff880`025d0000   ksecdd   ksecdd.sys   Fri Feb 08 18:51:16 2019 (5C5E15F4)
fffff880`02600000 fffff880`0263a000   fvevol   fvevol.sys   Wed Jan 23 22:11:24 2013 (5100A65C)
fffff880`02648000 fffff880`0265d000   NDProxy  NDProxy.SYS  Fri Dec 07 21:47:15 2018 (5C0B30B3)
fffff880`0265d000 fffff880`026d2000   cng      cng.sys      Thu May 10 22:25:10 2018 (5AF4FF06)
fffff880`026d2000 fffff880`026e3000   pcw      pcw.sys      Mon Jul 13 19:19:27 2009 (4A5BC0FF)
fffff880`026e3000 fffff880`026ee000   pmdrvs   pmdrvs.sys   Thu Aug 30 20:38:36 2018 (5B888E0C)
fffff880`026ee000 fffff880`026f8000   Fs_Rec   Fs_Rec.sys   Wed Feb 29 22:41:06 2012 (4F4EEFD2)
fffff880`026f8000 fffff880`027ea000   ndis     ndis.sys     Fri Jul 06 11:18:04 2018 (5B3F882C)
fffff880`02800000 fffff880`0282a000   Apsx64   Apsx64.sys   Mon Mar 13 09:19:24 2017 (58C69C5C)
fffff880`0282a000 fffff880`02848000   mup      mup.sys      Tue Jan 06 20:48:27 2015 (54AC906B)
fffff880`02848000 fffff880`02854000   iaStorF  iaStorF.sys  Tue Jun 06 12:27:23 2017 (5936D7EB)
fffff880`02854000 fffff880`0285d000   hwpolicy hwpolicy.sys Sat Nov 20 04:18:54 2010 (4CE7927E)
fffff880`0286a000 fffff880`028ca000   NETIO    NETIO.SYS    Sun Aug 12 15:46:07 2018 (5B708E7F)
fffff880`028ca000 fffff880`028f5000   ksecpkg  ksecpkg.sys  Fri Feb 08 18:57:41 2019 (5C5E1775)
fffff880`028f5000 fffff880`0293e000   fwpkclnt fwpkclnt.sys Sun Aug 12 15:45:55 2018 (5B708E73)
fffff880`0293e000 fffff880`0294e000   vmstorfl vmstorfl.sys Sat Nov 20 04:57:30 2010 (4CE79B8A)
fffff880`0294e000 fffff880`0299a000   volsnap  volsnap.sys  Thu Feb 24 22:38:18 2011 (4D67242A)
fffff880`0299a000 fffff880`029a5000   ApsHM64  ApsHM64.sys  Mon Mar 13 09:16:44 2017 (58C69BBC)
fffff880`029a5000 fffff880`029ad000   spldr    spldr.sys    Mon May 11 12:56:27 2009 (4A0858BB)
fffff880`029ad000 fffff880`029e7000   rdyboost rdyboost.sys Sun Dec 31 20:44:40 2017 (5A499288)
fffff880`029e7000 fffff880`029fc000   disk     disk.sys     Tue Jan 19 21:12:06 2016 (569EECF6)
fffff880`02a03000 fffff880`02bfe000   tcpip    tcpip.sys    Sun Aug 12 15:46:49 2018 (5B708EA9)
fffff880`03e00000 fffff880`03e11000   Npfs     Npfs.SYS     Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`03e11000 fffff880`03e23000   kltdi    kltdi.sys    Thu Jun 15 04:57:08 2017 (59424BE4)
fffff880`03e2a000 fffff880`03e45000   klbackupflt klbackupflt.sys Wed Jan 31 11:07:22 2018 (5A71E9BA)
fffff880`03e45000 fffff880`03e8a000   klflt    klflt.sys    Fri Aug 24 04:01:37 2018 (5B7FBB61)
fffff880`03e8a000 fffff880`03e9f000   FortiShield FortiShield.sys Thu Nov 05 14:10:29 2015 (563BA9A5)
fffff880`03ea5000 fffff880`03ffc000   klhk     klhk.sys     Wed Sep 19 05:58:51 2018 (5BA21DDB)
fffff880`04c18000 fffff880`04c6c000   nwifi    nwifi.sys    Wed Sep 13 11:05:20 2017 (59B94930)
fffff880`04c6c000 fffff880`04c7f000   ndisuio  ndisuio.sys  Sat Nov 20 05:50:08 2010 (4CE7A7E0)
fffff880`04c7f000 fffff880`04c97000   rspndr   rspndr.sys   Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`04c97000 fffff880`04ccc000   exfat    exfat.SYS    Fri Mar 10 10:55:25 2017 (58C2CC6D)
fffff880`04ccc000 fffff880`04cd6000   vwifimp  vwifimp.sys  Mon Jul 13 20:07:28 2009 (4A5BCC40)
fffff880`04cd6000 fffff880`04d9e000   HTTP     HTTP.sys     Sun Dec 31 20:41:37 2017 (5A4991D1)
fffff880`04d9e000 fffff880`04dbb000   bowser   bowser.sys   Wed Jul 18 11:18:04 2018 (5B4F5A2C)
fffff880`04dbb000 fffff880`04dd3000   mpsdrv   mpsdrv.sys   Fri Aug 10 11:27:40 2018 (5B6DAEEC)
fffff880`04dd3000 fffff880`04e00000   mrxsmb   mrxsmb.sys   Fri Feb 08 18:52:21 2019 (5C5E1635)
fffff880`05000000 fffff880`05043000   ks       ks.sys       Tue Aug 28 01:50:19 2018 (5B84E29B)
fffff880`05043000 fffff880`0504e000   klpd     klpd.sys     Fri Mar 24 09:45:18 2017 (58D522EE)
fffff880`0504e000 fffff880`05057000   Null     Null.SYS     Mon Jul 13 19:19:37 2009 (4A5BC109)
fffff880`05057000 fffff880`0505e000   Beep     Beep.SYS     Mon Jul 13 20:00:13 2009 (4A5BCA8D)
fffff880`0505e000 fffff880`0506c000   vga      vga.sys      Mon Jul 13 19:38:47 2009 (4A5BC587)
fffff880`0506c000 fffff880`05091000   VIDEOPRT VIDEOPRT.SYS Fri Feb 08 18:54:51 2019 (5C5E16CB)
fffff880`05091000 fffff880`050a1000   watchdog watchdog.sys Mon Jul 13 19:37:35 2009 (4A5BC53F)
fffff880`050a1000 fffff880`050aa000   RDPCDD   RDPCDD.sys   Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`050aa000 fffff880`050b3000   rdpencdd rdpencdd.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`050b3000 fffff880`050bc000   rdprefmp rdprefmp.sys Mon Jul 13 20:16:35 2009 (4A5BCE63)
fffff880`050bc000 fffff880`050c7000   Msfs     Msfs.SYS     Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`050d1000 fffff880`051f2000   klif     klif.sys     Fri Sep 28 07:25:59 2018 (5BAE0FC7)
fffff880`051f2000 fffff880`051ff000   TDI      TDI.SYS      Sat Nov 20 04:22:06 2010 (4CE7933E)
fffff880`05200000 fffff880`0520c000   nsiproxy nsiproxy.sys Fri Aug 11 01:58:55 2017 (598D479F)
fffff880`0520c000 fffff880`05217000   mssmbios mssmbios.sys Sat Feb 10 12:25:38 2018 (5A7F2B12)
fffff880`05217000 fffff880`05247000   kneps    kneps.sys    Thu Sep 13 05:08:32 2018 (5B9A2910)
fffff880`0524d000 fffff880`052d6000   afd      afd.sys      Tue Apr 04 10:53:16 2017 (58E3B35C)
fffff880`052d6000 fffff880`052df000   wfplwf   wfplwf.sys   Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff880`052df000 fffff880`05305000   pacer    pacer.sys    Sun Dec 31 20:55:04 2017 (5A4994F8)
fffff880`05305000 fffff880`0531b000   vwififlt vwififlt.sys Mon Jul 13 20:07:22 2009 (4A5BCC3A)
fffff880`0531b000 fffff880`05325000   FortiFilter FortiFilter.sys Tue Nov 18 14:09:01 2014 (546B994D)
fffff880`05325000 fffff880`0534e000   klwtp    klwtp.sys    Wed May 16 08:27:39 2018 (5AFC23BB)
fffff880`0534e000 fffff880`0535a000   klim6    klim6.sys    Thu May 17 07:43:44 2018 (5AFD6AF0)
fffff880`0535a000 fffff880`0536a000   netbios  netbios.sys  Sun Dec 31 20:55:00 2017 (5A4994F4)
fffff880`0536a000 fffff880`05385000   wanarp   wanarp.sys   Fri Dec 07 21:47:22 2018 (5C0B30BA)
fffff880`05385000 fffff880`0538e000   Tppwr64v Tppwr64v.sys Wed Feb 15 23:57:36 2017 (58A53140)
fffff880`0538e000 fffff880`053a2000   termdd   termdd.sys   Sat Feb 10 12:45:02 2018 (5A7F2F9E)
fffff880`053a2000 fffff880`053f5000   rdbss    rdbss.sys    Wed Oct 11 20:20:28 2017 (59DEB54C)
fffff880`053f5000 fffff880`053fc000   omnismi  omnismi.sys  Wed Apr 03 23:39:27 2013 (515CF5EF)
fffff880`05600000 fffff880`056bf000   RtsPer   RtsPer.sys   Fri Nov 13 01:22:42 2015 (564581B2)
fffff880`056bf000 fffff880`056cd000   psadd    psadd.sys    Mon Dec 26 20:09:28 2011 (4EF91AC8)
fffff880`056cd000 fffff880`05752000   csc      csc.sys      Fri Jun 29 11:14:18 2018 (5B364CCA)
fffff880`05752000 fffff880`05773000   dfsc     dfsc.sys     Wed Apr 25 11:18:53 2018 (5AE09C5D)
fffff880`05773000 fffff880`05784000   blbdrive blbdrive.sys Mon Jul 13 19:35:59 2009 (4A5BC4DF)
fffff880`05784000 fffff880`057aa000   tunnel   tunnel.sys   Sat Nov 20 05:51:50 2010 (4CE7A846)
fffff880`057aa000 fffff880`057c0000   intelppm intelppm.sys Fri Feb 08 18:51:11 2019 (5C5E15EF)
fffff880`057c0000 fffff880`057e1000   raspptp  raspptp.sys  Sat Nov 20 05:52:31 2010 (4CE7A86F)
fffff880`057e1000 fffff880`057fb000   rassstp  rassstp.sys  Mon Jul 13 20:10:25 2009 (4A5BCCF1)
fffff880`05a00000 fffff880`05a45000   netbt    netbt.sys    Fri Aug 11 01:59:59 2017 (598D47DF)
fffff880`05a45000 fffff880`05a50000   klfltdev klfltdev.sys Fri Dec 09 06:52:49 2016 (584A9B11)
fffff880`05a50000 fffff880`05a5f000   discache discache.sys Mon Jul 13 19:37:18 2009 (4A5BC52E)
fffff880`05a5f000 fffff880`065ac000   dump_iaStorA dump_iaStorA.sys Tue Jun 06 12:27:18 2017 (5936D7E6)
fffff880`065c8000 fffff880`065ea000   tdx      tdx.sys      Sat Jul 29 10:56:29 2017 (597CA21D)
fffff880`065ea000 fffff880`065fc000   umbus    umbus.sys    Sat Nov 20 05:44:37 2010 (4CE7A695)
fffff880`06800000 fffff880`06824000   HDAudBus HDAudBus.sys Tue Aug 27 21:35:47 2013 (521D53F3)
fffff880`06824000 fffff880`06833000   Smb_driver_Intel Smb_driver_Intel.sys Wed Oct 31 23:50:28 2018 (5BDA7804)
fffff880`06833000 fffff880`068b6000   e1d62x64 e1d62x64.sys Sun Nov 27 08:03:30 2016 (583AD9A2)
fffff880`068b6000 fffff880`068bf000   wmiacpi  wmiacpi.sys  Sat Feb 10 12:25:26 2018 (5A7F2B06)
fffff880`068bf000 fffff880`068e6000   tpm      tpm.sys      Fri Feb 05 12:39:10 2016 (56B4DE3E)
fffff880`068e6000 fffff880`068f2000   ndistapi ndistapi.sys Fri Dec 07 21:47:13 2018 (5C0B30B1)
fffff880`068f3000 fffff880`069a6000   SynTP    SynTP.sys    Wed Oct 31 23:50:00 2018 (5BDA77E8)
fffff880`069a6000 fffff880`069ae280   HIDPARSE HIDPARSE.SYS Tue Jan 08 21:45:27 2019 (5C356047)
fffff880`069af000 fffff880`069be000   kbdclass kbdclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff880`069be000 fffff880`069cd000   mouclass mouclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff880`069cd000 fffff880`069d1500   CmBatt   CmBatt.sys   Mon Jul 13 19:31:03 2009 (4A5BC3B7)
fffff880`069d2000 fffff880`069e8000   ibmpmdrv ibmpmdrv.sys Thu Aug 30 20:38:23 2018 (5B888DFF)
fffff880`069e8000 fffff880`069f8000   XtuAcpiDriver XtuAcpiDriver.sys Wed Apr 12 04:58:50 2017 (58EDEC4A)
fffff880`069f8000 fffff880`06a00000   ftvnic   ftvnic.sys   Thu Feb 12 19:37:53 2009 (4994C0E1)
fffff880`06a02000 fffff880`06da1000   Netwsw04 Netwsw04.sys Mon Aug 27 05:17:21 2018 (5B83C1A1)
fffff880`06da1000 fffff880`06dae000   vwifibus vwifibus.sys Mon Jul 13 20:07:21 2009 (4A5BCC39)
fffff880`06dae000 fffff880`06dcc000   i8042prt i8042prt.sys Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`06dcc000 fffff880`06ddc000   CompositeBus CompositeBus.sys Sat Nov 20 05:33:17 2010 (4CE7A3ED)
fffff880`06ddc000 fffff880`06df2000   AgileVpn AgileVpn.sys Mon Jul 13 20:10:24 2009 (4A5BCCF0)
fffff880`06df2000 fffff880`06dfac00   pppop64  pppop64.sys  Wed Jul 15 17:57:15 2009 (4A5E50BB)
fffff880`06dfb000 fffff880`06dfc480   swenum   swenum.sys   Sat Feb 10 12:38:10 2018 (5A7F2E02)
fffff880`06e00000 fffff880`06e24000   rasl2tp  rasl2tp.sys  Sat Nov 20 05:52:34 2010 (4CE7A872)
fffff880`06e24000 fffff880`06e3f000   raspppoe raspppoe.sys Mon Jul 13 20:10:17 2009 (4A5BCCE9)
fffff880`06e43000 fffff880`06f38000   dxgkrnl  dxgkrnl.sys  Sat Sep 08 20:21:17 2018 (5B94677D)
fffff880`06f38000 fffff880`06f7e000   dxgmms1  dxgmms1.sys  Sat Sep 08 20:21:01 2018 (5B94676D)
fffff880`06f7e000 fffff880`06f7fe80   USBD     USBD.SYS     Wed May 02 11:32:25 2018 (5AE9DA09)
fffff880`06f80000 fffff880`06fb2000   TeeDriverx64 TeeDriverx64.sys Sun Nov 19 06:39:31 2017 (5A116D73)
fffff880`06fb2000 fffff880`06fea000   usb3Hub  usb3Hub.sys  Fri Jan 09 00:53:47 2015 (54AF6CEB)
fffff880`06fea000 fffff880`06ff5000   rdpbus   rdpbus.sys   Mon Jul 13 20:17:46 2009 (4A5BCEAA)
fffff880`07000000 fffff880`07036000   WUDFRd   WUDFRd.sys   Wed Jul 25 22:26:06 2012 (5010AABE)
fffff880`07036000 fffff880`07053000   usbccgp  usbccgp.sys  Wed May 02 11:32:35 2018 (5AE9DA13)
fffff880`07061000 fffff880`07084000   luafv    luafv.sys    Wed Oct 11 20:20:09 2017 (59DEB539)
fffff880`07084000 fffff880`0709d000   WudfPf   WudfPf.sys   Wed Jul 25 22:26:45 2012 (5010AAE5)
fffff880`0709d000 fffff880`070ae000   WinUSB   WinUSB.sys   Sat Nov 20 05:43:56 2010 (4CE7A66C)
fffff880`070bd000 fffff880`07123000   iusb3hub iusb3hub.sys Thu May 11 08:15:16 2017 (591455D4)
fffff880`07123000 fffff880`07160000   portcls  portcls.sys  Tue Dec 08 13:12:06 2015 (56671D76)
fffff880`07160000 fffff880`071d7000   IntcDAud IntcDAud.sys Wed Jun 21 22:59:52 2017 (594B32A8)
fffff880`071d7000 fffff880`071ec000   lltdio   lltdio.sys   Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`07600000 fffff880`0762f000   ndiswan  ndiswan.sys  Sat Nov 20 05:52:32 2010 (4CE7A870)
fffff880`07633000 fffff880`080f2000   igdkmd64 igdkmd64.sys Wed Oct 31 10:32:25 2018 (5BD9BCF9)
fffff880`080f2000 fffff880`08128000   fastfat  fastfat.SYS  Fri Mar 10 10:55:26 2017 (58C2CC6E)
fffff880`08128000 fffff880`081f3000   iusb3xhc iusb3xhc.sys Thu May 11 08:15:19 2017 (591455D7)
fffff880`081f3000 fffff880`081ff000   iwdbus   iwdbus.sys   Tue Feb 10 14:04:50 2015 (54DA5652)
fffff880`0821d000 fffff880`0826b000   mrxsmb10 mrxsmb10.sys Fri Feb 08 18:51:56 2019 (5C5E161C)
fffff880`0826b000 fffff880`0828f000   mrxsmb20 mrxsmb20.sys Fri Feb 08 18:51:54 2019 (5C5E161A)
fffff880`0828f000 fffff880`08339000   peauth   peauth.sys   Tue Jun 14 13:11:06 2016 (57603AAA)
fffff880`0833b000 fffff880`0836c000   srvnet   srvnet.sys   Tue Jan 08 21:35:27 2019 (5C355DEF)
fffff880`0836e000 fffff880`08376000   SSPORT   SSPORT.sys   Thu Aug 11 19:07:32 2005 (42FBDA34)
fffff880`08376000 fffff880`08388000   tcpipreg tcpipreg.sys Thu Jul 07 11:08:06 2016 (577E7056)
fffff880`08388000 fffff880`083f0000   srv2     srv2.sys     Tue Jan 08 21:35:33 2019 (5C355DF5)
fffff880`08800000 fffff880`08822000   drmk     drmk.sys     Tue Dec 08 13:54:36 2015 (5667276C)
fffff880`08824000 fffff880`08df9000   RTKVHD64 RTKVHD64.sys Tue Aug 01 06:05:51 2017 (5980527F)
fffff880`08df9000 fffff880`08dfe200   ksthunk  ksthunk.sys  Mon Jul 13 20:00:19 2009 (4A5BCA93)
fffff880`0aa0d000 fffff880`0aa19000   Dxapi    Dxapi.sys    Mon Jul 13 19:38:28 2009 (4A5BC574)
fffff880`0aa19000 fffff880`0aa27000   crashdmp crashdmp.sys Mon Jul 13 20:01:01 2009 (4A5BCABD)
fffff880`0aa27000 fffff880`0aa31000   dump_diskdump dump_diskdump.sys Mon Feb 03 20:36:25 2014 (52F04419)
fffff880`0aa31000 fffff880`0aa44000   dump_dumpfve dump_dumpfve.sys Mon Jul 13 19:21:51 2009 (4A5BC18F)
fffff880`0aa45000 fffff880`0ab4d900   SPUVCbv64 SPUVCbv64.sys Wed Jan 17 21:30:41 2018 (5A6006D1)
fffff880`0c000000 fffff880`0c00e000   monitor  monitor.sys  Mon Jul 13 19:38:52 2009 (4A5BC58C)
fffff880`0c076000 fffff880`0c081000   asyncmac asyncmac.sys Mon Jul 13 20:10:13 2009 (4A5BCCE5)
fffff880`0c08d000 fffff880`0c124000   srv      srv.sys      Tue Jan 08 21:35:42 2019 (5C355DFE)
fffff880`0c124000 fffff880`0c152000   rdpdr    rdpdr.sys    Sat Nov 20 06:06:41 2010 (4CE7ABC1)
fffff880`0c152000 fffff880`0c15d000   tdtcp    tdtcp.sys    Thu Feb 16 23:57:32 2012 (4F3DDE3C)
fffff880`0c15d000 fffff880`0c16d000   tssecsrv tssecsrv.sys Sun Aug 13 17:45:28 2017 (5990C878)
fffff880`0c16d000 fffff880`0c1a7000   RDPWD    RDPWD.SYS    Wed Jul 16 21:21:53 2014 (53C72531)
fffff880`0c1a7000 fffff880`0c1b5000   hidusb   hidusb.sys   Tue Jan 08 21:45:28 2019 (5C356048)
fffff880`0c1b5000 fffff880`0c1ce000   HIDCLASS HIDCLASS.SYS Tue Jan 08 21:45:27 2019 (5C356047)
fffff880`0c1ce000 fffff880`0c1db000   mouhid   mouhid.sys   Mon Jul 13 20:00:20 2009 (4A5BCA94)
fffff960`00000000 fffff960`00329000   win32k   win32k.sys   unavailable (00000000)
fffff960`00510000 fffff960`0051a000   TSDDD    TSDDD.dll    unavailable (00000000)
fffff960`00730000 fffff960`00757000   cdd      cdd.dll      unavailable (00000000)
fffff960`008a0000 fffff960`00903000   ATMFD    ATMFD.DLL    unavailable (00000000)

Unloaded modules:
fffff880`0c1db000 fffff880`0c1e9000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0c1e9000 fffff880`0c1f3000   hiber_storpo
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000A000
fffff880`27283000 fffff880`27dd0000   hiber_iaStor
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00B4D000
fffff880`27dd0000 fffff880`27de3000   hiber_dumpfv
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00013000
fffff880`07053000 fffff880`07061000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0abcc000 fffff880`0abe5000   HIDCLASS.SYS
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00019000
fffff880`0abbe000 fffff880`0abcc000   hidusb.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0abef000 fffff880`0abfd000   kbdhid.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0aa00000 fffff880`0aa0d000   mouhid.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000D000
fffff880`0abe5000 fffff880`0abef000   Dot4Prt.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000A000
fffff880`0aba3000 fffff880`0abbe000   USBSTOR.SYS
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0001B000
fffff880`0ab7b000 fffff880`0aba3000   Dot4.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00028000
fffff880`0ab5f000 fffff880`0ab6b000   usbprint.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000C000
fffff880`0ab4e000 fffff880`0ab5f000   usbscan.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00011000
fffff880`0ab6b000 fffff880`0ab7b000   dot4usb.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00010000
fffff880`0c1a7000 fffff880`0c1b2000   WSDPrint.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000B000
fffff880`0c1b2000 fffff880`0c1be000   WSDScan.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000C000
fffff880`0c071000 fffff880`0c073000   MSTEE.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00002000
fffff880`0c073000 fffff880`0c076000   MSKSSRV.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00003000
fffff880`0c000000 fffff880`0c071000   spsys.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00071000
fffff880`0836c000 fffff880`0836e000   MSPCLOCK.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00002000
fffff880`08339000 fffff880`0833b000   MSPQM.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00002000
fffff880`0263a000 fffff880`02648000   crashdmp.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0285d000 fffff880`02867000   dump_storpor
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000A000
fffff880`05a68000 fffff880`065b5000   dump_iaStorA
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00B4D000
fffff880`065b5000 fffff880`065c8000   dump_dumpfve
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00013000
fffff880`071d7000 fffff880`071e8000   WinUSB.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00011000
fffff880`07000000 fffff880`07036000   WUDFRd.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00036000
fffff880`03e00000 fffff880`03e2a000   cdrom.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0002A000
start             end                 module name
fffff880`01745000 fffff880`0179c000   ACPI     ACPI.sys     Sat Feb 10 12:21:53 2018 (5A7F2A31)
fffff880`0524d000 fffff880`052d6000   afd      afd.sys      Tue Apr 04 10:53:16 2017 (58E3B35C)
fffff880`06ddc000 fffff880`06df2000   AgileVpn AgileVpn.sys Mon Jul 13 20:10:24 2009 (4A5BCCF0)
fffff880`023c1000 fffff880`023cc000   amdxata  amdxata.sys  Fri Mar 19 12:18:18 2010 (4BA3A3CA)
fffff880`0299a000 fffff880`029a5000   ApsHM64  ApsHM64.sys  Mon Mar 13 09:16:44 2017 (58C69BBC)
fffff880`02800000 fffff880`0282a000   Apsx64   Apsx64.sys   Mon Mar 13 09:19:24 2017 (58C69C5C)
fffff880`0c076000 fffff880`0c081000   asyncmac asyncmac.sys Mon Jul 13 20:10:13 2009 (4A5BCCE5)
fffff880`017ef000 fffff880`017f8000   atapi    atapi.sys    Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`00fc8000 fffff880`00ff2000   ataport  ataport.SYS  Sun Aug 04 21:02:45 2013 (51FEF9B5)
fffff960`008a0000 fffff960`00903000   ATMFD    ATMFD.DLL    unavailable (00000000)
fffff880`0101e000 fffff880`0102a000   BATTC    BATTC.SYS    Mon Jul 13 19:31:01 2009 (4A5BC3B5)
fffff880`05057000 fffff880`0505e000   Beep     Beep.SYS     Mon Jul 13 20:00:13 2009 (4A5BCA8D)
fffff880`05773000 fffff880`05784000   blbdrive blbdrive.sys Mon Jul 13 19:35:59 2009 (4A5BC4DF)
fffff880`04d9e000 fffff880`04dbb000   bowser   bowser.sys   Wed Jul 18 11:18:04 2018 (5B4F5A2C)
fffff960`00730000 fffff960`00757000   cdd      cdd.dll      unavailable (00000000)
fffff880`00c00000 fffff880`00c73000   CI       CI.dll       Fri May 11 17:20:19 2018 (5AF60913)
fffff880`00da1000 fffff880`00dd2000   CLASSPNP CLASSPNP.SYS Sun Sep 28 20:46:24 2014 (5428ABE0)
fffff880`00d42000 fffff880`00da1000   CLFS     CLFS.SYS     Sat Apr 07 11:45:40 2018 (5AC8E7A4)
fffff880`069cd000 fffff880`069d1500   CmBatt   CmBatt.sys   Mon Jul 13 19:31:03 2009 (4A5BC3B7)
fffff880`0265d000 fffff880`026d2000   cng      cng.sys      Thu May 10 22:25:10 2018 (5AF4FF06)
fffff880`01015000 fffff880`0101e000   compbatt compbatt.sys Mon Jul 13 19:31:02 2009 (4A5BC3B6)
fffff880`06dcc000 fffff880`06ddc000   CompositeBus CompositeBus.sys Sat Nov 20 05:33:17 2010 (4CE7A3ED)
fffff880`0aa19000 fffff880`0aa27000   crashdmp crashdmp.sys Mon Jul 13 20:01:01 2009 (4A5BCABD)
fffff880`056cd000 fffff880`05752000   csc      csc.sys      Fri Jun 29 11:14:18 2018 (5B364CCA)
fffff880`05752000 fffff880`05773000   dfsc     dfsc.sys     Wed Apr 25 11:18:53 2018 (5AE09C5D)
fffff880`05a50000 fffff880`05a5f000   discache discache.sys Mon Jul 13 19:37:18 2009 (4A5BC52E)
fffff880`029e7000 fffff880`029fc000   disk     disk.sys     Tue Jan 19 21:12:06 2016 (569EECF6)
fffff880`08800000 fffff880`08822000   drmk     drmk.sys     Tue Dec 08 13:54:36 2015 (5667276C)
fffff880`0aa27000 fffff880`0aa31000   dump_diskdump dump_diskdump.sys Mon Feb 03 20:36:25 2014 (52F04419)
fffff880`0aa31000 fffff880`0aa44000   dump_dumpfve dump_dumpfve.sys Mon Jul 13 19:21:51 2009 (4A5BC18F)
fffff880`05a5f000 fffff880`065ac000   dump_iaStorA dump_iaStorA.sys Tue Jun 06 12:27:18 2017 (5936D7E6)
fffff880`0aa0d000 fffff880`0aa19000   Dxapi    Dxapi.sys    Mon Jul 13 19:38:28 2009 (4A5BC574)
fffff880`06e43000 fffff880`06f38000   dxgkrnl  dxgkrnl.sys  Sat Sep 08 20:21:17 2018 (5B94677D)
fffff880`06f38000 fffff880`06f7e000   dxgmms1  dxgmms1.sys  Sat Sep 08 20:21:01 2018 (5B94676D)
fffff880`06833000 fffff880`068b6000   e1d62x64 e1d62x64.sys Sun Nov 27 08:03:30 2016 (583AD9A2)
fffff880`04c97000 fffff880`04ccc000   exfat    exfat.SYS    Fri Mar 10 10:55:25 2017 (58C2CC6D)
fffff880`080f2000 fffff880`08128000   fastfat  fastfat.SYS  Fri Mar 10 10:55:26 2017 (58C2CC6E)
fffff880`023cc000 fffff880`023e0000   fileinfo fileinfo.sys Mon Jul 13 19:34:25 2009 (4A5BC481)
fffff880`00e5c000 fffff880`00ea6000   FLTMGR   FLTMGR.SYS   Sun Dec 31 20:41:16 2017 (5A4991BC)
fffff880`0531b000 fffff880`05325000   FortiFilter FortiFilter.sys Tue Nov 18 14:09:01 2014 (546B994D)
fffff880`03e8a000 fffff880`03e9f000   FortiShield FortiShield.sys Thu Nov 05 14:10:29 2015 (563BA9A5)
fffff880`026ee000 fffff880`026f8000   Fs_Rec   Fs_Rec.sys   Wed Feb 29 22:41:06 2012 (4F4EEFD2)
fffff880`069f8000 fffff880`06a00000   ftvnic   ftvnic.sys   Thu Feb 12 19:37:53 2009 (4994C0E1)
fffff880`02600000 fffff880`0263a000   fvevol   fvevol.sys   Wed Jan 23 22:11:24 2013 (5100A65C)
fffff880`028f5000 fffff880`0293e000   fwpkclnt fwpkclnt.sys Sun Aug 12 15:45:55 2018 (5B708E73)
fffff800`03609000 fffff800`03651000   hal      hal.dll      Fri Feb 08 19:23:37 2019 (5C5E1D89)
fffff880`06800000 fffff880`06824000   HDAudBus HDAudBus.sys Tue Aug 27 21:35:47 2013 (521D53F3)
fffff880`0c1b5000 fffff880`0c1ce000   HIDCLASS HIDCLASS.SYS Tue Jan 08 21:45:27 2019 (5C356047)
fffff880`069a6000 fffff880`069ae280   HIDPARSE HIDPARSE.SYS Tue Jan 08 21:45:27 2019 (5C356047)
fffff880`0c1a7000 fffff880`0c1b5000   hidusb   hidusb.sys   Tue Jan 08 21:45:28 2019 (5C356048)
fffff880`04cd6000 fffff880`04d9e000   HTTP     HTTP.sys     Sun Dec 31 20:41:37 2017 (5A4991D1)
fffff880`02854000 fffff880`0285d000   hwpolicy hwpolicy.sys Sat Nov 20 04:18:54 2010 (4CE7927E)
fffff880`06dae000 fffff880`06dcc000   i8042prt i8042prt.sys Mon Jul 13 19:19:57 2009 (4A5BC11D)
fffff880`01810000 fffff880`0235d000   iaStorA  iaStorA.sys  Tue Jun 06 12:27:18 2017 (5936D7E6)
fffff880`02848000 fffff880`02854000   iaStorF  iaStorF.sys  Tue Jun 06 12:27:23 2017 (5936D7EB)
fffff880`069d2000 fffff880`069e8000   ibmpmdrv ibmpmdrv.sys Thu Aug 30 20:38:23 2018 (5B888DFF)
fffff880`07633000 fffff880`080f2000   igdkmd64 igdkmd64.sys Wed Oct 31 10:32:25 2018 (5BD9BCF9)
fffff880`07160000 fffff880`071d7000   IntcDAud IntcDAud.sys Wed Jun 21 22:59:52 2017 (594B32A8)
fffff880`057aa000 fffff880`057c0000   intelppm intelppm.sys Fri Feb 08 18:51:11 2019 (5C5E15EF)
fffff880`070bd000 fffff880`07123000   iusb3hub iusb3hub.sys Thu May 11 08:15:16 2017 (591455D4)
fffff880`08128000 fffff880`081f3000   iusb3xhc iusb3xhc.sys Thu May 11 08:15:19 2017 (591455D7)
fffff880`081f3000 fffff880`081ff000   iwdbus   iwdbus.sys   Tue Feb 10 14:04:50 2015 (54DA5652)
fffff880`069af000 fffff880`069be000   kbdclass kbdclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff800`00bf5000 fffff800`00bff000   kdcom    kdcom.dll    Sat Feb 05 11:52:49 2011 (4D4D8061)
fffff880`0103c000 fffff880`01745000   kl1      kl1.sys      Fri Apr 01 10:20:28 2016 (56FE83AC)
fffff880`0102a000 fffff880`0103a000   klbackupdisk klbackupdisk.sys Mon Aug 06 02:56:33 2018 (5B67F121)
fffff880`03e2a000 fffff880`03e45000   klbackupflt klbackupflt.sys Wed Jan 31 11:07:22 2018 (5A71E9BA)
fffff880`03e45000 fffff880`03e8a000   klflt    klflt.sys    Fri Aug 24 04:01:37 2018 (5B7FBB61)
fffff880`05a45000 fffff880`05a50000   klfltdev klfltdev.sys Fri Dec 09 06:52:49 2016 (584A9B11)
fffff880`03ea5000 fffff880`03ffc000   klhk     klhk.sys     Wed Sep 19 05:58:51 2018 (5BA21DDB)
fffff880`050d1000 fffff880`051f2000   klif     klif.sys     Fri Sep 28 07:25:59 2018 (5BAE0FC7)
fffff880`0534e000 fffff880`0535a000   klim6    klim6.sys    Thu May 17 07:43:44 2018 (5AFD6AF0)
fffff880`05043000 fffff880`0504e000   klpd     klpd.sys     Fri Mar 24 09:45:18 2017 (58D522EE)
fffff880`03e11000 fffff880`03e23000   kltdi    kltdi.sys    Thu Jun 15 04:57:08 2017 (59424BE4)
fffff880`05325000 fffff880`0534e000   klwtp    klwtp.sys    Wed May 16 08:27:39 2018 (5AFC23BB)
fffff880`05217000 fffff880`05247000   kneps    kneps.sys    Thu Sep 13 05:08:32 2018 (5B9A2910)
fffff880`05000000 fffff880`05043000   ks       ks.sys       Tue Aug 28 01:50:19 2018 (5B84E29B)
fffff880`025b5000 fffff880`025d0000   ksecdd   ksecdd.sys   Fri Feb 08 18:51:16 2019 (5C5E15F4)
fffff880`028ca000 fffff880`028f5000   ksecpkg  ksecpkg.sys  Fri Feb 08 18:57:41 2019 (5C5E1775)
fffff880`08df9000 fffff880`08dfe200   ksthunk  ksthunk.sys  Mon Jul 13 20:00:19 2009 (4A5BCA93)
fffff880`071d7000 fffff880`071ec000   lltdio   lltdio.sys   Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`07061000 fffff880`07084000   luafv    luafv.sys    Wed Oct 11 20:20:09 2017 (59DEB539)
fffff880`00cdf000 fffff880`00d2e000   mcupdate_GenuineIntel mcupdate_GenuineIntel.dll Sat Nov 20 08:03:51 2010 (4CE7C737)
fffff880`0c000000 fffff880`0c00e000   monitor  monitor.sys  Mon Jul 13 19:38:52 2009 (4A5BC58C)
fffff880`069be000 fffff880`069cd000   mouclass mouclass.sys Mon Jul 13 19:19:50 2009 (4A5BC116)
fffff880`0c1ce000 fffff880`0c1db000   mouhid   mouhid.sys   Mon Jul 13 20:00:20 2009 (4A5BCA94)
fffff880`00ea6000 fffff880`00ec0000   mountmgr mountmgr.sys Sun May 07 10:52:08 2017 (590F3498)
fffff880`04dbb000 fffff880`04dd3000   mpsdrv   mpsdrv.sys   Fri Aug 10 11:27:40 2018 (5B6DAEEC)
fffff880`04dd3000 fffff880`04e00000   mrxsmb   mrxsmb.sys   Fri Feb 08 18:52:21 2019 (5C5E1635)
fffff880`0821d000 fffff880`0826b000   mrxsmb10 mrxsmb10.sys Fri Feb 08 18:51:56 2019 (5C5E161C)
fffff880`0826b000 fffff880`0828f000   mrxsmb20 mrxsmb20.sys Fri Feb 08 18:51:54 2019 (5C5E161A)
fffff880`050bc000 fffff880`050c7000   Msfs     Msfs.SYS     Mon Jul 13 19:19:47 2009 (4A5BC113)
fffff880`017a5000 fffff880`017af000   msisadrv msisadrv.sys Sat Feb 10 12:21:45 2018 (5A7F2A29)
fffff880`00c73000 fffff880`00cd1000   msrpc    msrpc.sys    Sun Nov 11 11:15:23 2018 (5BE8559B)
fffff880`0520c000 fffff880`05217000   mssmbios mssmbios.sys Sat Feb 10 12:25:38 2018 (5A7F2B12)
fffff880`0282a000 fffff880`02848000   mup      mup.sys      Tue Jan 06 20:48:27 2015 (54AC906B)
fffff880`026f8000 fffff880`027ea000   ndis     ndis.sys     Fri Jul 06 11:18:04 2018 (5B3F882C)
fffff880`068e6000 fffff880`068f2000   ndistapi ndistapi.sys Fri Dec 07 21:47:13 2018 (5C0B30B1)
fffff880`04c6c000 fffff880`04c7f000   ndisuio  ndisuio.sys  Sat Nov 20 05:50:08 2010 (4CE7A7E0)
fffff880`07600000 fffff880`0762f000   ndiswan  ndiswan.sys  Sat Nov 20 05:52:32 2010 (4CE7A870)
fffff880`02648000 fffff880`0265d000   NDProxy  NDProxy.SYS  Fri Dec 07 21:47:15 2018 (5C0B30B3)
fffff880`0535a000 fffff880`0536a000   netbios  netbios.sys  Sun Dec 31 20:55:00 2017 (5A4994F4)
fffff880`05a00000 fffff880`05a45000   netbt    netbt.sys    Fri Aug 11 01:59:59 2017 (598D47DF)
fffff880`0286a000 fffff880`028ca000   NETIO    NETIO.SYS    Sun Aug 12 15:46:07 2018 (5B708E7F)
fffff880`06a02000 fffff880`06da1000   Netwsw04 Netwsw04.sys Mon Aug 27 05:17:21 2018 (5B83C1A1)
fffff880`03e00000 fffff880`03e11000   Npfs     Npfs.SYS     Mon Jul 13 19:19:48 2009 (4A5BC114)
fffff880`05200000 fffff880`0520c000   nsiproxy nsiproxy.sys Fri Aug 11 01:58:55 2017 (598D479F)
fffff800`03651000 fffff800`03c2d000   nt       ntkrnlmp.exe Fri Feb 08 18:52:23 2019 (5C5E1637)
fffff880`0240d000 fffff880`025b5000   Ntfs     Ntfs.sys     Fri Dec 28 14:28:19 2018 (5C267953)
fffff880`0504e000 fffff880`05057000   Null     Null.SYS     Mon Jul 13 19:19:37 2009 (4A5BC109)
fffff880`04c18000 fffff880`04c6c000   nwifi    nwifi.sys    Wed Sep 13 11:05:20 2017 (59B94930)
fffff880`053f5000 fffff880`053fc000   omnismi  omnismi.sys  Wed Apr 03 23:39:27 2013 (515CF5EF)
fffff880`052df000 fffff880`05305000   pacer    pacer.sys    Sun Dec 31 20:55:04 2017 (5A4994F8)
fffff880`01000000 fffff880`01015000   partmgr  partmgr.sys  Sat Mar 17 01:06:09 2012 (4F641BC1)
fffff880`017af000 fffff880`017e2000   pci      pci.sys      Sat Feb 10 12:22:10 2018 (5A7F2A42)
fffff880`026d2000 fffff880`026e3000   pcw      pcw.sys      Mon Jul 13 19:19:27 2009 (4A5BC0FF)
fffff880`0828f000 fffff880`08339000   peauth   peauth.sys   Tue Jun 14 13:11:06 2016 (57603AAA)
fffff880`026e3000 fffff880`026ee000   pmdrvs   pmdrvs.sys   Thu Aug 30 20:38:36 2018 (5B888E0C)
fffff880`07123000 fffff880`07160000   portcls  portcls.sys  Tue Dec 08 13:12:06 2015 (56671D76)
fffff880`06df2000 fffff880`06dfac00   pppop64  pppop64.sys  Wed Jul 15 17:57:15 2009 (4A5E50BB)
fffff880`056bf000 fffff880`056cd000   psadd    psadd.sys    Mon Dec 26 20:09:28 2011 (4EF91AC8)
fffff880`00d2e000 fffff880`00d42000   PSHED    PSHED.dll    Mon Jul 13 21:32:23 2009 (4A5BE027)
fffff880`06e00000 fffff880`06e24000   rasl2tp  rasl2tp.sys  Sat Nov 20 05:52:34 2010 (4CE7A872)
fffff880`06e24000 fffff880`06e3f000   raspppoe raspppoe.sys Mon Jul 13 20:10:17 2009 (4A5BCCE9)
fffff880`057c0000 fffff880`057e1000   raspptp  raspptp.sys  Sat Nov 20 05:52:31 2010 (4CE7A86F)
fffff880`057e1000 fffff880`057fb000   rassstp  rassstp.sys  Mon Jul 13 20:10:25 2009 (4A5BCCF1)
fffff880`053a2000 fffff880`053f5000   rdbss    rdbss.sys    Wed Oct 11 20:20:28 2017 (59DEB54C)
fffff880`06fea000 fffff880`06ff5000   rdpbus   rdpbus.sys   Mon Jul 13 20:17:46 2009 (4A5BCEAA)
fffff880`050a1000 fffff880`050aa000   RDPCDD   RDPCDD.sys   Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`0c124000 fffff880`0c152000   rdpdr    rdpdr.sys    Sat Nov 20 06:06:41 2010 (4CE7ABC1)
fffff880`050aa000 fffff880`050b3000   rdpencdd rdpencdd.sys Mon Jul 13 20:16:34 2009 (4A5BCE62)
fffff880`050b3000 fffff880`050bc000   rdprefmp rdprefmp.sys Mon Jul 13 20:16:35 2009 (4A5BCE63)
fffff880`0c16d000 fffff880`0c1a7000   RDPWD    RDPWD.SYS    Wed Jul 16 21:21:53 2014 (53C72531)
fffff880`029ad000 fffff880`029e7000   rdyboost rdyboost.sys Sun Dec 31 20:44:40 2017 (5A499288)
fffff880`04c7f000 fffff880`04c97000   rspndr   rspndr.sys   Mon Jul 13 20:08:50 2009 (4A5BCC92)
fffff880`08824000 fffff880`08df9000   RTKVHD64 RTKVHD64.sys Tue Aug 01 06:05:51 2017 (5980527F)
fffff880`05600000 fffff880`056bf000   RtsPer   RtsPer.sys   Fri Nov 13 01:22:42 2015 (564581B2)
fffff880`06824000 fffff880`06833000   Smb_driver_Intel Smb_driver_Intel.sys Wed Oct 31 23:50:28 2018 (5BDA7804)
fffff880`029a5000 fffff880`029ad000   spldr    spldr.sys    Mon May 11 12:56:27 2009 (4A0858BB)
fffff880`0aa45000 fffff880`0ab4d900   SPUVCbv64 SPUVCbv64.sys Wed Jan 17 21:30:41 2018 (5A6006D1)
fffff880`0c08d000 fffff880`0c124000   srv      srv.sys      Tue Jan 08 21:35:42 2019 (5C355DFE)
fffff880`08388000 fffff880`083f0000   srv2     srv2.sys     Tue Jan 08 21:35:33 2019 (5C355DF5)
fffff880`0833b000 fffff880`0836c000   srvnet   srvnet.sys   Tue Jan 08 21:35:27 2019 (5C355DEF)
fffff880`0836e000 fffff880`08376000   SSPORT   SSPORT.sys   Thu Aug 11 19:07:32 2005 (42FBDA34)
fffff880`0235d000 fffff880`023c1000   storport storport.sys Fri Aug 14 13:09:20 2015 (55CE20C0)
fffff880`06dfb000 fffff880`06dfc480   swenum   swenum.sys   Sat Feb 10 12:38:10 2018 (5A7F2E02)
fffff880`068f3000 fffff880`069a6000   SynTP    SynTP.sys    Wed Oct 31 23:50:00 2018 (5BDA77E8)
fffff880`02a03000 fffff880`02bfe000   tcpip    tcpip.sys    Sun Aug 12 15:46:49 2018 (5B708EA9)
fffff880`08376000 fffff880`08388000   tcpipreg tcpipreg.sys Thu Jul 07 11:08:06 2016 (577E7056)
fffff880`051f2000 fffff880`051ff000   TDI      TDI.SYS      Sat Nov 20 04:22:06 2010 (4CE7933E)
fffff880`0c152000 fffff880`0c15d000   tdtcp    tdtcp.sys    Thu Feb 16 23:57:32 2012 (4F3DDE3C)
fffff880`065c8000 fffff880`065ea000   tdx      tdx.sys      Sat Jul 29 10:56:29 2017 (597CA21D)
fffff880`06f80000 fffff880`06fb2000   TeeDriverx64 TeeDriverx64.sys Sun Nov 19 06:39:31 2017 (5A116D73)
fffff880`0538e000 fffff880`053a2000   termdd   termdd.sys   Sat Feb 10 12:45:02 2018 (5A7F2F9E)
fffff880`068bf000 fffff880`068e6000   tpm      tpm.sys      Fri Feb 05 12:39:10 2016 (56B4DE3E)
fffff880`05385000 fffff880`0538e000   Tppwr64v Tppwr64v.sys Wed Feb 15 23:57:36 2017 (58A53140)
fffff960`00510000 fffff960`0051a000   TSDDD    TSDDD.dll    unavailable (00000000)
fffff880`0c15d000 fffff880`0c16d000   tssecsrv tssecsrv.sys Sun Aug 13 17:45:28 2017 (5990C878)
fffff880`05784000 fffff880`057aa000   tunnel   tunnel.sys   Sat Nov 20 05:51:50 2010 (4CE7A846)
fffff880`065ea000 fffff880`065fc000   umbus    umbus.sys    Sat Nov 20 05:44:37 2010 (4CE7A695)
fffff880`06fb2000 fffff880`06fea000   usb3Hub  usb3Hub.sys  Fri Jan 09 00:53:47 2015 (54AF6CEB)
fffff880`07036000 fffff880`07053000   usbccgp  usbccgp.sys  Wed May 02 11:32:35 2018 (5AE9DA13)
fffff880`06f7e000 fffff880`06f7fe80   USBD     USBD.SYS     Wed May 02 11:32:25 2018 (5AE9DA09)
fffff880`017e2000 fffff880`017ef000   vdrvroot vdrvroot.sys Sat Feb 10 12:38:45 2018 (5A7F2E25)
fffff880`0505e000 fffff880`0506c000   vga      vga.sys      Mon Jul 13 19:38:47 2009 (4A5BC587)
fffff880`0506c000 fffff880`05091000   VIDEOPRT VIDEOPRT.SYS Fri Feb 08 18:54:51 2019 (5C5E16CB)
fffff880`0293e000 fffff880`0294e000   vmstorfl vmstorfl.sys Sat Nov 20 04:57:30 2010 (4CE79B8A)
fffff880`00fb4000 fffff880`00fc8000   volmgr   volmgr.sys   Sat Feb 10 12:21:56 2018 (5A7F2A34)
fffff880`00e00000 fffff880`00e5c000   volmgrx  volmgrx.sys  Fri Jul 07 10:53:40 2017 (595FA074)
fffff880`0294e000 fffff880`0299a000   volsnap  volsnap.sys  Thu Feb 24 22:38:18 2011 (4D67242A)
fffff880`06da1000 fffff880`06dae000   vwifibus vwifibus.sys Mon Jul 13 20:07:21 2009 (4A5BCC39)
fffff880`05305000 fffff880`0531b000   vwififlt vwififlt.sys Mon Jul 13 20:07:22 2009 (4A5BCC3A)
fffff880`04ccc000 fffff880`04cd6000   vwifimp  vwifimp.sys  Mon Jul 13 20:07:28 2009 (4A5BCC40)
fffff880`0536a000 fffff880`05385000   wanarp   wanarp.sys   Fri Dec 07 21:47:22 2018 (5C0B30BA)
fffff880`05091000 fffff880`050a1000   watchdog watchdog.sys Mon Jul 13 19:37:35 2009 (4A5BC53F)
fffff880`00ee2000 fffff880`00fa4000   Wdf01000 Wdf01000.sys Fri Jun 21 23:13:05 2013 (51C51641)
fffff880`00fa4000 fffff880`00fb4000   WDFLDR   WDFLDR.SYS   Wed Jul 25 22:29:04 2012 (5010AB70)
fffff880`052d6000 fffff880`052df000   wfplwf   wfplwf.sys   Mon Jul 13 20:09:26 2009 (4A5BCCB6)
fffff960`00000000 fffff960`00329000   win32k   win32k.sys   unavailable (00000000)
fffff880`0709d000 fffff880`070ae000   WinUSB   WinUSB.sys   Sat Nov 20 05:43:56 2010 (4CE7A66C)
fffff880`068b6000 fffff880`068bf000   wmiacpi  wmiacpi.sys  Sat Feb 10 12:25:26 2018 (5A7F2B06)
fffff880`0179c000 fffff880`017a5000   WMILIB   WMILIB.SYS   Mon Jul 13 19:19:51 2009 (4A5BC117)
fffff880`07084000 fffff880`0709d000   WudfPf   WudfPf.sys   Wed Jul 25 22:26:45 2012 (5010AAE5)
fffff880`07000000 fffff880`07036000   WUDFRd   WUDFRd.sys   Wed Jul 25 22:26:06 2012 (5010AABE)
fffff880`069e8000 fffff880`069f8000   XtuAcpiDriver XtuAcpiDriver.sys Wed Apr 12 04:58:50 2017 (58EDEC4A)

Unloaded modules:
fffff880`0c1db000 fffff880`0c1e9000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0c1e9000 fffff880`0c1f3000   hiber_storpo
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000A000
fffff880`27283000 fffff880`27dd0000   hiber_iaStor
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00B4D000
fffff880`27dd0000 fffff880`27de3000   hiber_dumpfv
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00013000
fffff880`07053000 fffff880`07061000   monitor.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0abcc000 fffff880`0abe5000   HIDCLASS.SYS
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00019000
fffff880`0abbe000 fffff880`0abcc000   hidusb.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0abef000 fffff880`0abfd000   kbdhid.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0aa00000 fffff880`0aa0d000   mouhid.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000D000
fffff880`0abe5000 fffff880`0abef000   Dot4Prt.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000A000
fffff880`0aba3000 fffff880`0abbe000   USBSTOR.SYS
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0001B000
fffff880`0ab7b000 fffff880`0aba3000   Dot4.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00028000
fffff880`0ab5f000 fffff880`0ab6b000   usbprint.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000C000
fffff880`0ab4e000 fffff880`0ab5f000   usbscan.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00011000
fffff880`0ab6b000 fffff880`0ab7b000   dot4usb.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00010000
fffff880`0c1a7000 fffff880`0c1b2000   WSDPrint.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000B000
fffff880`0c1b2000 fffff880`0c1be000   WSDScan.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000C000
fffff880`0c071000 fffff880`0c073000   MSTEE.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00002000
fffff880`0c073000 fffff880`0c076000   MSKSSRV.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00003000
fffff880`0c000000 fffff880`0c071000   spsys.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00071000
fffff880`0836c000 fffff880`0836e000   MSPCLOCK.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00002000
fffff880`08339000 fffff880`0833b000   MSPQM.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00002000
fffff880`0263a000 fffff880`02648000   crashdmp.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000E000
fffff880`0285d000 fffff880`02867000   dump_storpor
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0000A000
fffff880`05a68000 fffff880`065b5000   dump_iaStorA
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00B4D000
fffff880`065b5000 fffff880`065c8000   dump_dumpfve
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00013000
fffff880`071d7000 fffff880`071e8000   WinUSB.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00011000
fffff880`07000000 fffff880`07036000   WUDFRd.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  00036000
fffff880`03e00000 fffff880`03e2a000   cdrom.sys
    Timestamp: unavailable (00000000)
    Checksum:  00000000
    ImageSize:  0002A000
Bugcheck code 000000C5
Arguments 00000000`00000008 00000000`00000002 00000000`00000001 fffff800`0382b077
1: kd> lmvm fileinfo
Browse full module list
start             end                 module name
fffff880`023cc000 fffff880`023e0000   fileinfo   (pdb symbols)          c:\symbols\fileinfo.pdb\99DAA03EB2014EFE91E56C3EF9ADE0F01\fileinfo.pdb
    Loaded symbol image file: fileinfo.sys
    Mapped memory image file: c:\symbols\fileinfo.sys\4A5BC48114000\fileinfo.sys
    Image path: \SystemRoot\system32\drivers\fileinfo.sys
    Image name: fileinfo.sys
    Browse all global symbols  functions  data
    Timestamp:        Mon Jul 13 19:34:25 2009 (4A5BC481)
    CheckSum:         00015644
    ImageSize:        00014000
    File version:     6.1.7600.16385
    Product version:  6.1.7600.16385
    File flags:       0 (Mask 3F)
    File OS:          40004 NT Win32
    File type:        3.7 Driver
    File date:        00000000.00000000
    Translations:     0409.04b0
    CompanyName:      Microsoft Corporation
    ProductName:      Microsoft® Windows® Operating System
    InternalName:     FileInfo.sys
    OriginalFilename: FileInfo.sys
    ProductVersion:   6.1.7600.16385
    FileVersion:      6.1.7600.16385 (win7_rtm.090713-1255)
    FileDescription:  FileInfo Filter Driver
    LegalCopyright:   © Microsoft Corporation. All rights reserved.
1: kd> .bugcheck
Bugcheck code 000000C5
Arguments 00000000`00000008 00000000`00000002 00000000`00000001 fffff800`0382b077
 
Hi. . .

The system has had 41 BSODs according to the Windows app msinfo32. You can find these in the future in the msinfo32.nfo file - "Software Environment"; "Windows Error Reporting" (WERCON).

I extracted the 41 BSOD WERCON records: (scroll to the right and look for BlueScreen -
Code:
27-2-2019 8:34 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\022719-11934-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-197887-0.sysdata.xml C:\Users\svenv\AppData\Local\Temp\WER1A72.tmp.WERInternalMetadata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_121524be Analysis symbol: Rechecking for solution: 0 Report Id: 022719-11934-01 Report Status: 0
21-2-2019 22:28 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\022119-32635-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-169027-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_1ce6bc2d Analysis symbol: Rechecking for solution: 0 Report Id: 022119-32635-01 Report Status: 0
12-2-2019 11:05 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\120318-12402-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-2149880-0.sysdata.xml These files may be available here: Analysis symbol: Rechecking for solution: 1 Report Id: 120318-12402-01 Report Status: 0
12-2-2019 11:05 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\011719-18267-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-162911-0.sysdata.xml These files may be available here: Analysis symbol: Rechecking for solution: 1 Report Id: 011719-18267-01 Report Status: 0
12-2-2019 11:05 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\012819-23025-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-201319-0.sysdata.xml These files may be available here: Analysis symbol: Rechecking for solution: 1 Report Id: 012819-23025-01 Report Status: 0
12-2-2019 11:05 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\120518-66128-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-1445411-0.sysdata.xml These files may be available here: Analysis symbol: Rechecking for solution: 1 Report Id: 120518-66128-01 Report Status: 0
12-2-2019 11:05 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\112918-10623-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-651428-0.sysdata.xml These files may be available here: Analysis symbol: Rechecking for solution: 1 Report Id: 112918-10623-01 Report Status: 0
12-2-2019 11:05 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\021019-11996-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-36451209-0.sysdata.xml These files may be available here: Analysis symbol: Rechecking for solution: 1 Report Id: 021019-11996-01 Report Status: 0
12-2-2019 11:05 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\013019-12121-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-89609017-0.sysdata.xml These files may be available here: Analysis symbol: Rechecking for solution: 1 Report Id: 013019-12121-01 Report Status: 0
12-2-2019 11:05 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\123118-13135-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-118981-0.sysdata.xml These files may be available here: Analysis symbol: Rechecking for solution: 1 Report Id: 123118-13135-01 Report Status: 0
12-2-2019 11:05 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\121218-17206-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-145517-0.sysdata.xml These files may be available here: Analysis symbol: Rechecking for solution: 1 Report Id: 121218-17206-01 Report Status: 0
12-2-2019 11:05 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\021119-15553-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-162287-0.sysdata.xml These files may be available here: Analysis symbol: Rechecking for solution: 1 Report Id: 021119-15553-01 Report Status: 0
12-2-2019 11:04 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\110718-26613-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-180415-0.sysdata.xml C:\Users\svenv\AppData\Local\Temp\WER962.tmp.WERInternalMetadata.xml These files may be available here: Analysis symbol: Rechecking for solution: 1 Report Id: 110718-26613-01 Report Status: 0
12-2-2019 11:04 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\111218-10264-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-290661-0.sysdata.xml C:\Users\svenv\AppData\Local\Temp\WERBA2A.tmp.WERInternalMetadata.xml These files may be available here: Analysis symbol: Rechecking for solution: 1 Report Id: 111218-10264-01 Report Status: 0
12-2-2019 11:04 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\021219-10951-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-305278-0.sysdata.xml C:\Users\svenv\AppData\Local\Temp\WER8600.tmp.WERInternalMetadata.xml These files may be available here: Analysis symbol: Rechecking for solution: 1 Report Id: 021219-10951-01 Report Status: 0
12-2-2019 11:02 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\021219-10951-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-305278-0.sysdata.xml C:\Users\svenv\AppData\Local\Temp\WER8600.tmp.WERInternalMetadata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_18ea904d Analysis symbol: Rechecking for solution: 0 Report Id: 021219-10951-01 Report Status: 0
11-2-2019 9:08 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\021119-15553-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-162287-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_0ceb0be2 Analysis symbol: Rechecking for solution: 0 Report Id: 021119-15553-01 Report Status: 0
10-2-2019 12:40 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\021019-11996-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-36451209-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_19a4a5fa Analysis symbol: Rechecking for solution: 0 Report Id: 021019-11996-01 Report Status: 0
31-1-2019 9:46 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\013019-12121-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-89609017-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_1930137c Analysis symbol: Rechecking for solution: 0 Report Id: 013019-12121-01 Report Status: 2
28-1-2019 9:54 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\012819-23025-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-201319-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_1e4b8130 Analysis symbol: Rechecking for solution: 0 Report Id: 012819-23025-01 Report Status: 0
17-1-2019 23:26 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\011719-18267-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-162911-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_2008c497 Analysis symbol: Rechecking for solution: 0 Report Id: 011719-18267-01 Report Status: 0
31-12-2018 21:27 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\123118-13135-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-118981-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_183a6d04 Analysis symbol: Rechecking for solution: 0 Report Id: 123118-13135-01 Report Status: 2
12-12-2018 9:28 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\121218-17206-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-145517-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_16a00f2c Analysis symbol: Rechecking for solution: 0 Report Id: 121218-17206-01 Report Status: 0
5-12-2018 9:01 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\120518-66128-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-1445411-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_1c3dd7f7 Analysis symbol: Rechecking for solution: 0 Report Id: 120518-66128-01 Report Status: 0
3-12-2018 9:03 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\120318-12402-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-2149880-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_27bcfb6e Analysis symbol: Rechecking for solution: 0 Report Id: 120318-12402-01 Report Status: 0
29-11-2018 13:55 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\112918-10623-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-651428-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_1a9a3091 Analysis symbol: Rechecking for solution: 0 Report Id: 112918-10623-01 Report Status: 0
12-11-2018 8:25 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\111218-10264-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-290661-0.sysdata.xml C:\Users\svenv\AppData\Local\Temp\WERBA2A.tmp.WERInternalMetadata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_1d0dc467 Analysis symbol: Rechecking for solution: 0 Report Id: 111218-10264-01 Report Status: 0
7-11-2018 13:03 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\110718-26613-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-180415-0.sysdata.xml C:\Users\svenv\AppData\Local\Temp\WER962.tmp.WERInternalMetadata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_1d8313dd Analysis symbol: Rechecking for solution: 0 Report Id: 110718-26613-01 Report Status: 0
13-8-2018 17:51 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\081318-48672-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-191413-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_0e3efeb8 Analysis symbol: Rechecking for solution: 0 Report Id: 081318-48672-01 Report Status: 0
13-8-2018 8:09 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\081318-30295-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-1068981-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_1fe521b3 Analysis symbol: Rechecking for solution: 0 Report Id: 081318-30295-01 Report Status: 0
24-7-2018 15:31 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\072418-51885-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-137561-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_12525668 Analysis symbol: Rechecking for solution: 0 Report Id: 072418-51885-01 Report Status: 0
16-7-2018 7:50 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\071618-17160-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-219852-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_2193fbbc Analysis symbol: Rechecking for solution: 0 Report Id: 071618-17160-01 Report Status: 0
19-6-2018 20:51 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\061918-13806-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-277806-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_1da0644d Analysis symbol: Rechecking for solution: 0 Report Id: 061918-13806-01 Report Status: 0
12-6-2018 13:27 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\061218-25693-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-9236756-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_129e3c95 Analysis symbol: Rechecking for solution: 0 Report Id: 061218-25693-01 Report Status: 0
1-6-2018 9:33 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\060118-12807-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-156079-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_0c92a533 Analysis symbol: Rechecking for solution: 0 Report Id: 060118-12807-01 Report Status: 0
11-5-2018 8:41 Windows Error Reporting Fault bucket X64_0xC5_2_nt!ExAllocatePoolWithTag+537, type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\051118-11216-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-2737567-0.sysdata.xml C:\Users\svenv\AppData\Local\Temp\WERB52B.tmp.WERInternalMetadata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_1f5ed6ee Analysis symbol: X64_0xC5_2_nt!ExAllocatePoolWithTag+537 Rechecking for solution: 0 Report Id: 051118-11216-01 Report Status: 0
26-4-2018 14:42 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\042618-9484-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-883106-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_0ee243b3 Analysis symbol: Rechecking for solution: 0 Report Id: 042618-9484-01 Report Status: 0
26-4-2018 7:55 Windows Error Reporting Fault bucket X64_0x4E_7_nt!MiPfnReferenceCountIsZero+83319, type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\042518-9032-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-54397080-0.sysdata.xml C:\Users\svenv\AppData\Local\Temp\WERE86B.tmp.WERInternalMetadata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_1d09ffc2 Analysis symbol: X64_0x4E_7_nt!MiPfnReferenceCountIsZero+83319 Rechecking for solution: 0 Report Id: 042518-9032-01 Report Status: 0
25-4-2018 7:30 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\042518-12838-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-73148-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_1941de3d Analysis symbol: Rechecking for solution: 0 Report Id: 042518-12838-01 Report Status: 2
25-4-2018 6:58 Windows Error Reporting Fault bucket , type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\042418-9094-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-35646774-0.sysdata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_0598f570 Analysis symbol: Rechecking for solution: 0 Report Id: 042418-9094-01 Report Status: 0
9-4-2018 7:25 Windows Error Reporting Fault bucket X64_0x3B_nt!ExDeferredFreePool+1df, type 0 Event Name: BlueScreen Response: Not available Cab Id: 0 Problem signature: P1: P2: P3: P4: P5: P6: P7: P8: P9: P10: Attached files: C:\Windows\Minidump\040918-10296-01.dmp C:\Users\svenv\AppData\Local\Temp\WER-153005-0.sysdata.xml C:\Users\svenv\AppData\Local\Temp\WERAD00.tmp.WERInternalMetadata.xml These files may be available here: C:\Users\svenv\AppData\Local\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_1622c7e0 Analysis symbol: X64_0x3B_nt!ExDeferredFreePool+1df Rechecking for solution: 0 Report Id: 040918-10296-01 Report Status: 0

The earliest date that I see off-hand is January 2018 - some 13 months ago.

You can find the actual WERCON reports (*.wer) and very likely some/many of the mini kernel memory dumps in two locations -
  • %programdata%\microsoft\windows\wer
  • %userprofile%\appdata\local\microsoft\windows\wer
There will be 2 sub-directories under each directory. You'll just have to go through them 1-by-1 if you wish to. The sub-directories will likely be colored blue indicating compressed files, but you should be able to open them. If you have problems with Windows Explorer, use Altap Salamander, a 3rd party file manager that I've used in lieu of Windows Explorer for over 12 years now.

Altap is a 30-day trial, but can be used far after that date. Installation is easy and clean (no surprise junk is installed); likewise, uninstallation is easy and complete - no remnants left behind.

Download - Altap Salamander File Manager

Now... on to your 2 mini kernel memory dumps....

Bugchecks:
  • 0x1a - severe memory management error; NT Kernel named probable cause. NT can never be the cause. It is named here as a default since the real culprit cannot be identified
  • 0xc5 - indicates that the system attempted to access invalid memory at a process IRQL that was too high; so basically invalid memory referenced. The probable cause listed as the Microsoft Windows FileInfo Filter Driver fileinfo.sys. Again, like NT, this driver is not the cause of this BSOD because it is a Microsoft Windows driver and is therefore sacrosanct. The real culprit either got away or could not be identified
Of course, the only other cause besides a <1% chance of a Windows Update driver is unknown hardware failure.

I would highly recommend that you test both RAM and al hard drives. I know you said this is a remote system, but these 2 tests really should be done -
I would start with SeaTools for DOS. Windows does not load for either test, so there is no chance of getting BSODs during the testing.

There are 3 drives listed, including a ~4 GB USB (likely a thumb drive -?), and a 64 GB drive listed as "SDXC Card". If this drive is like an SSD, it could definitely give off memory related bugchecks like the 0x1a memory management error.

I do think your issue here is unknown hardware failure with an indication toward a storage device given that fileinfo.sys was named, even though it was not the cause.

The other odd item in the dump that named NT were the high number of unloaded drivers, specifically hiber_iaStor and hiber_storpo - which are likely actually an Intel storage driver and storport.sys - another storage driver. I don't know why these would constantly be unloaded then reloaded. It is odd to say the least.

As you indicated, you could run Driver Verifier, but with just 2 dumps to work with out of 41 and both having different bugchecks, again, I do believe the cause here is unknown hardware failure.

That is it for now!

Regards. . .

jcgriff2

Thanks so much for this info. We were able to get new ram shipped over to us and replaced the old one. With that I was able to narrow the search and I believe we may be able to conclude that ram is not the issue. The BSOD occured again before the RAM replacement (03-04-19 dump) and after the ram replacement (03-07-19 dump). The dumps have been attached.

Running windbg on both dumps showed me that Firefox may have been the cause of the latest BSOD... The BSOD prior to the ram replacement it I believe has something to do with the file system?

With the three drives listed, yes one is a thumb drive and the other is an SD card. I will try to get those sticks removed and see if that will help remedy the issue as well as reinstall firefox.
 

Attachments

Hi. . .

You are still suffering from memory corruption; the 0x4e bugcheck BSOD tells us that.

It could be RAM or other unknown hardware failure that is preventing RAM from properly holding kernel code.

I know that you have 1 new RAM stick, but you must run memtest86+ again on both sticks - 1 stick at a time; alternate the slots.

Test RAM with memtest.org MemTest86+

Regards. . .

jcgriff2

p.s. I firmly believe that your BSODs are related to unknown hardware failure.
 
Hi. . .

You are still suffering from memory corruption; the 0x4e bugcheck BSOD tells us that.

It could be RAM or other unknown hardware failure that is preventing RAM from properly holding kernel code.

I know that you have 1 new RAM stick, but you must run memtest86+ again on both sticks - 1 stick at a time; alternate the slots.

Test RAM with memtest.org MemTest86+

Regards. . .

jcgriff2

p.s. I firmly believe that your BSODs are related to unknown hardware failure.
Both RAM sticks were actually replaced before this latest BSOD that was attached.
I guess it could be possible that these replacements have issues as well.
Would memtest be able to tell if the issue is outside ram? I guess we'll know if the results from the ram come clean haha.
I will try and get the user to attempt memtest and walk them through it.

Thanks again!
 
The RDR_FILE_SYSTEM bug check has a value of 0x00000027. This indicates that a problem occurred in the SMB redirector file system.
Code:
Loading Dump File [F:\030419-9999-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available


************* Symbol Path validation summary **************
Response                         Time (ms)     Location
Deferred                                       SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.24358.amd64fre.win7sp1_ldr_escrow.190208-1418
Machine Name:
Kernel base = 0xfffff800`03604000 PsLoadedModuleList = 0xfffff800`0383dc90
Debug session time: Mon Mar  4 13:15:23.987 2019 (UTC + 1:00)
System Uptime: 3 days 17:46:00.864
Loading Kernel Symbols
...............................................................
................................................................
................................................................

Loading User Symbols
Loading unloaded module list
.............................
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 27, {baad0073, fffff8800b7d3eb8, fffff8800b7d3720, fffff88000e05099}

Probably caused by : rdbss.sys ( rdbss!RxExceptionFilter+ea )

Followup:     MachineOwner
---------

1: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

RDR_FILE_SYSTEM (27)
    If you see RxExceptionFilter on the stack then the 2nd and 3rd parameters are the
    exception record and context record. Do a .cxr on the 3rd parameter and then kb to
    obtain a more informative stack trace.
    The high 16 bits of the first parameter is the RDBSS bugcheck code, which is defined
    as follows:
     RDBSS_BUG_CHECK_CACHESUP  = 0xca550000,
     RDBSS_BUG_CHECK_CLEANUP   = 0xc1ee0000,
     RDBSS_BUG_CHECK_CLOSE     = 0xc10e0000,
     RDBSS_BUG_CHECK_NTEXCEPT  = 0xbaad0000,
Arguments:
Arg1: 00000000baad0073
Arg2: fffff8800b7d3eb8
Arg3: fffff8800b7d3720
Arg4: fffff88000e05099

Debugging Details:
------------------


DUMP_CLASS: 1

DUMP_QUALIFIER: 400

BUILD_VERSION_STRING:  7601.24358.amd64fre.win7sp1_ldr_escrow.190208-1418

SYSTEM_MANUFACTURER:  LENOVO

SYSTEM_PRODUCT_NAME:  20FN003SUS

SYSTEM_SKU:  LENOVO_MT_20FN_BU_Think_FM_ThinkPad T460

SYSTEM_VERSION:  ThinkPad T460

BIOS_VENDOR:  LENOVO

BIOS_VERSION:  R06ET66W (1.40 )

BIOS_DATE:  01/25/2019

BASEBOARD_MANUFACTURER:  LENOVO

BASEBOARD_PRODUCT:  20FN003SUS

BASEBOARD_VERSION:  SDK0J40705 WIN

DUMP_TYPE:  2

BUGCHECK_P1: baad0073

BUGCHECK_P2: fffff8800b7d3eb8

BUGCHECK_P3: fffff8800b7d3720

BUGCHECK_P4: fffff88000e05099

EXCEPTION_RECORD:  fffff8800b7d3eb8 -- (.exr 0xfffff8800b7d3eb8)
ExceptionAddress: fffff88000e05099 (FLTMGR!GetContextFromStreamList+0x0000000000000099)
   ExceptionCode: c0000005 (Access violation)
  ExceptionFlags: 00000000
NumberParameters: 2
   Parameter[0]: 0000000000000000
   Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff

CONTEXT:  fffff8800b7d3720 -- (.cxr 0xfffff8800b7d3720)
rax=2000000000000000 rbx=0000000000000000 rcx=2000000000000000
rdx=fffffa80096e2990 rsi=fffffa8012e7f2a0 rdi=fffffa8012e7f250
rip=fffff88000e05099 rsp=fffff8800b7d40f0 rbp=fffff8800b7d4230
 r8=0000000000000000  r9=fffff8800b7d4228 r10=fffffa8012e7f258
r11=0000000000000011 r12=fffff8800b7d4228 r13=fffffa800eb01538
r14=0000000000000000 r15=fffffa80096e2990
iopl=0         nv up ei pl nz na po nc
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010206
FLTMGR!GetContextFromStreamList+0x99:
fffff880`00e05099 488b4820        mov     rcx,qword ptr [rax+20h] ds:002b:20000000`00000020=????????????????
Resetting default scope

CPU_COUNT: 4

CPU_MHZ: 960

CPU_VENDOR:  GenuineIntel

CPU_FAMILY: 6

CPU_MODEL: 4e

CPU_STEPPING: 3

CPU_MICROCODE: 6,4e,3,0 (F,M,S,R)  SIG: C6'00000000 (cache) C6'00000000 (init)

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  WIN7_DRIVER_FAULT

PROCESS_NAME:  svchost.exe

CURRENT_IRQL:  0

ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

EXCEPTION_CODE_STR:  c0000005

EXCEPTION_PARAMETER1:  0000000000000000

EXCEPTION_PARAMETER2:  ffffffffffffffff

READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800038a1100
Unable to get MmSystemRangeStart
 ffffffffffffffff

FOLLOWUP_IP:
rdbss!RxExceptionFilter+ea
fffff880`0545a4e2 cc              int     3

FAULTING_IP:
FLTMGR!GetContextFromStreamList+99
fffff880`00e05099 488b4820        mov     rcx,qword ptr [rax+20h]

BUGCHECK_STR:  0x27

ANALYSIS_SESSION_HOST:  MICHAL

ANALYSIS_SESSION_TIME:  03-07-2019 17:41:09.0364

ANALYSIS_VERSION: 10.0.10586.567 amd64fre

LAST_CONTROL_TRANSFER:  from 0000000000000000 to fffff88000e05099

STACK_TEXT: 
fffff880`0b7d2e98 fffff880`0545a4e2 : 00000000`00000027 00000000`baad0073 fffff880`0b7d3eb8 fffff880`0b7d3720 : nt!KeBugCheckEx
fffff880`0b7d2ea0 fffff880`054605a5 : fffff880`05462268 fffff880`0b7d5630 fffff880`0b7d55f0 fffff880`0b7d31b0 : rdbss!RxExceptionFilter+0xea
fffff880`0b7d2ef0 fffff800`03685e78 : 00000000`00000000 fffff880`024bb900 00000000`00000000 00000001`00000001 : rdbss! ?? ::FNODOBFM::`string'+0x768
fffff880`0b7d2f40 fffff880`0545fdd5 : fffff880`05462270 fffff880`0b7d55f0 fffff880`0b7d3eb8 fffff880`0b7d55f0 : nt!_C_specific_handler+0x8c
fffff880`0b7d2fb0 fffff800`0369eedd : fffff880`0546225c 00000000`00000000 fffff880`05448000 00000000`00000000 : rdbss!_GSHandlerCheck_SEH+0x75
fffff880`0b7d2fe0 fffff800`03620435 : fffff880`0546225c fffff880`0b7d3058 fffff880`0b7d3eb8 fffff880`05448000 : nt!RtlpExecuteHandlerForException+0xd
fffff880`0b7d3010 fffff800`0377ea9e : fffff880`0b7d3eb8 fffff880`0b7d3720 fffff880`00000000 fffffa80`12e7f250 : nt!RtlDispatchException+0x415
fffff880`0b7d36f0 fffff800`036a6042 : fffff880`0b7d3eb8 00000000`00000000 fffff880`0b7d3f60 fffffa80`12e7f2a0 : nt!KiDispatchException+0x17e
fffff880`0b7d3d80 fffff800`036a3932 : fffff880`0b7d4088 00000000`c0000225 00000000`00000000 00000000`00000000 : nt!KiExceptionDispatch+0xc2
fffff880`0b7d3f60 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiGeneralProtectionFault+0x2f2


STACK_COMMAND:  kb

THREAD_SHA1_HASH_MOD_FUNC:  20682c173eb10834a187637b767293998fbc2b0a

THREAD_SHA1_HASH_MOD_FUNC_OFFSET:  3303bc3a273381f39d292eb6bf1e06c10cec1ea1

THREAD_SHA1_HASH_MOD:  790f207622ed08ccb0e82cb2af91581839567bf6

FAULT_INSTR_CODE:  f68548cc

SYMBOL_STACK_INDEX:  1

SYMBOL_NAME:  rdbss!RxExceptionFilter+ea

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: rdbss

IMAGE_NAME:  rdbss.sys

DEBUG_FLR_IMAGE_TIMESTAMP:  59deb54c

IMAGE_VERSION:  6.1.7601.23930

FAILURE_BUCKET_ID:  X64_0x27_rdbss!RxExceptionFilter+ea

BUCKET_ID:  X64_0x27_rdbss!RxExceptionFilter+ea

PRIMARY_PROBLEM_CLASS:  X64_0x27_rdbss!RxExceptionFilter+ea

TARGET_TIME:  2019-03-04T12:15:23.000Z

OSBUILD:  7601

OSSERVICEPACK:  1000

SERVICEPACK_NUMBER: 0

OS_REVISION: 0

SUITE_MASK:  272

PRODUCT_TYPE:  1

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 7

OSEDITION:  Windows 7 WinNt (Service Pack 1) TerminalServer SingleUserTS

OS_LOCALE: 

USER_LCID:  0

OSBUILD_TIMESTAMP:  2019-02-09 00:52:23

BUILDDATESTAMP_STR:  190208-1418

BUILDLAB_STR:  win7sp1_ldr_escrow

BUILDOSVER_STR:  6.1.7601.24358.amd64fre.win7sp1_ldr_escrow.190208-1418

ANALYSIS_SESSION_ELAPSED_TIME: 4fe

ANALYSIS_SOURCE:  KM

FAILURE_ID_HASH_STRING:  km:x64_0x27_rdbss!rxexceptionfilter+ea

FAILURE_ID_HASH:  {74cfe8d4-f062-cf00-4dc4-66cb7cb230c6}

Followup:     MachineOwner
---------

1: kd> .cxr fffff8800b7d3720
rax=2000000000000000 rbx=0000000000000000 rcx=2000000000000000
rdx=fffffa80096e2990 rsi=fffffa8012e7f2a0 rdi=fffffa8012e7f250
rip=fffff88000e05099 rsp=fffff8800b7d40f0 rbp=fffff8800b7d4230
 r8=0000000000000000  r9=fffff8800b7d4228 r10=fffffa8012e7f258
r11=0000000000000011 r12=fffff8800b7d4228 r13=fffffa800eb01538
r14=0000000000000000 r15=fffffa80096e2990
iopl=0         nv up ei pl nz na po nc
cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010206
FLTMGR!GetContextFromStreamList+0x99:
fffff880`00e05099 488b4820        mov     rcx,qword ptr [rax+20h] ds:002b:20000000`00000020=????????????????
1: kd> kb
  *** Stack trace for last set context - .thread/.cxr resets it
 # RetAddr           : Args to Child                                                           : Call Site
00 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : FLTMGR!GetContextFromStreamList+0x99
Check S.M.A.R.T with HD Tune

The PFN_LIST_CORRUPT bug check has a value of 0x0000004E. This indicates that the page frame number (PFN) list is corrupted.
Code:
Loading Dump File [F:\030719-15600-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available


************* Symbol Path validation summary **************
Response                         Time (ms)     Location
Deferred                                       SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.24358.amd64fre.win7sp1_ldr_escrow.190208-1418
Machine Name:
Kernel base = 0xfffff800`03616000 PsLoadedModuleList = 0xfffff800`0384fc90
Debug session time: Thu Mar  7 13:25:02.609 2019 (UTC + 1:00)
System Uptime: 0 days 23:22:30.278
Loading Kernel Symbols
...............................................................
................................................................
................................................................

Loading User Symbols
Loading unloaded module list
.................
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 4E, {99, 5df75, 0, 1}

Probably caused by : memory_corruption ( nt!MiBadShareCount+4c )

Followup:     MachineOwner
---------

0: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

PFN_LIST_CORRUPT (4e)
Typically caused by drivers passing bad memory descriptor lists (ie: calling
MmUnlockPages twice with the same list, etc).  If a kernel debugger is
available get the stack trace.
Arguments:
Arg1: 0000000000000099, A PTE or PFN is corrupt
Arg2: 000000000005df75, page frame number
Arg3: 0000000000000000, current page state
Arg4: 0000000000000001, 0

Debugging Details:
------------------


DUMP_CLASS: 1

DUMP_QUALIFIER: 400

BUILD_VERSION_STRING:  7601.24358.amd64fre.win7sp1_ldr_escrow.190208-1418

SYSTEM_MANUFACTURER:  LENOVO

SYSTEM_PRODUCT_NAME:  20FN003SUS

SYSTEM_SKU:  LENOVO_MT_20FN_BU_Think_FM_ThinkPad T460

SYSTEM_VERSION:  ThinkPad T460

BIOS_VENDOR:  LENOVO

BIOS_VERSION:  R06ET66W (1.40 )

BIOS_DATE:  01/25/2019

BASEBOARD_MANUFACTURER:  LENOVO

BASEBOARD_PRODUCT:  20FN003SUS

BASEBOARD_VERSION:  SDK0J40705 WIN

DUMP_TYPE:  2

BUGCHECK_P1: 99

BUGCHECK_P2: 5df75

BUGCHECK_P3: 0

BUGCHECK_P4: 1

BUGCHECK_STR:  0x4E_99

CPU_COUNT: 4

CPU_MHZ: 960

CPU_VENDOR:  GenuineIntel

CPU_FAMILY: 6

CPU_MODEL: 4e

CPU_STEPPING: 3

CPU_MICROCODE: 6,4e,3,0 (F,M,S,R)  SIG: C6'00000000 (cache) C6'00000000 (init)

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  WIN7_DRIVER_FAULT

PROCESS_NAME:  firefox.exe

CURRENT_IRQL:  2

ANALYSIS_SESSION_HOST:  MICHAL

ANALYSIS_SESSION_TIME:  03-07-2019 17:45:11.0451

ANALYSIS_VERSION: 10.0.10586.567 amd64fre

LAST_CONTROL_TRANSFER:  from fffff800036eec8c to fffff800036a9ba0

STACK_TEXT: 
fffff880`239ce068 fffff800`036eec8c : 00000000`0000004e 00000000`00000099 00000000`0005df75 00000000`00000000 : nt!KeBugCheckEx
fffff880`239ce070 fffff800`03767d95 : fffff8a0`00000002 00002000`00000202 00000000`00000000 00000000`26d53000 : nt!MiBadShareCount+0x4c
fffff880`239ce0b0 fffff800`0378bef7 : ceb00000`00000000 fffffa80`12cef1b0 00002000`00000200 fffffa80`00000001 : nt!MiDeletePteList+0x4c5
fffff880`239ce140 fffff800`0366160b : ffffffff`ffffffff fffff680`00130b38 fffffa80`12cef1b0 00000000`00000000 : nt!MiDecommitPages+0x547
fffff880`239ce9f0 fffff800`036b7bd3 : ffffffff`ffffffff fffffa80`0f3e7b50 00000000`00002000 00000000`00004000 : nt!NtFreeVirtualMemory+0xe6b
fffff880`239ceae0 00000000`77669a6a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0032ed88 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77669a6a


STACK_COMMAND:  kb

THREAD_SHA1_HASH_MOD_FUNC:  be512df5023ca8055c9c2f79a90fb01e57d72b91

THREAD_SHA1_HASH_MOD_FUNC_OFFSET:  8c1701343a54bf1f5952beefe54e9fe9bbdf7bad

THREAD_SHA1_HASH_MOD:  ee8fcf1fb60cb6e3e2f60ddbed2ec02b5748a693

FOLLOWUP_IP:
nt!MiBadShareCount+4c
fffff800`036eec8c cc              int     3

FAULT_INSTR_CODE:  cccccccc

SYMBOL_STACK_INDEX:  1

SYMBOL_NAME:  nt!MiBadShareCount+4c

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

DEBUG_FLR_IMAGE_TIMESTAMP:  5c5e1637

IMAGE_VERSION:  6.1.7601.24358

IMAGE_NAME:  memory_corruption

FAILURE_BUCKET_ID:  X64_0x4E_99_nt!MiBadShareCount+4c

BUCKET_ID:  X64_0x4E_99_nt!MiBadShareCount+4c

PRIMARY_PROBLEM_CLASS:  X64_0x4E_99_nt!MiBadShareCount+4c

TARGET_TIME:  2019-03-07T12:25:02.000Z

OSBUILD:  7601

OSSERVICEPACK:  1000

SERVICEPACK_NUMBER: 0

OS_REVISION: 0

SUITE_MASK:  272

PRODUCT_TYPE:  1

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 7

OSEDITION:  Windows 7 WinNt (Service Pack 1) TerminalServer SingleUserTS

OS_LOCALE: 

USER_LCID:  0

OSBUILD_TIMESTAMP:  2019-02-09 00:52:23

BUILDDATESTAMP_STR:  190208-1418

BUILDLAB_STR:  win7sp1_ldr_escrow

BUILDOSVER_STR:  6.1.7601.24358.amd64fre.win7sp1_ldr_escrow.190208-1418

ANALYSIS_SESSION_ELAPSED_TIME: 507

ANALYSIS_SOURCE:  KM

FAILURE_ID_HASH_STRING:  km:x64_0x4e_99_nt!mibadsharecount+4c

FAILURE_ID_HASH:  {4c83cdad-f603-74ff-b7e1-9eb7f3029c2a}

Followup:     MachineOwner
---------

0: kd> !dpx
No export dpx found
0: kd> !pfn
Unable to get PFN database address fffff800038b3280
It is possible that some driver is burning in PTE, but without a full memory dump it is difficult to tell. Is there any possibility of downloading it?
 
For the full kernel memory dump that MrPepka is asking for . . .

Go to \windows\memory.dmp and copy it out to Documents or Desktop.

Zip up the memory.dmp file.

Upload it to a site like Google Docs or other 3rd party hosting site and provide us with a link.

Google Docs: Free Online Documents for Personal Use

Full kernel dumps can easily be several hundred MB in size. Zipping it will heavily compress it.

It must be copied out of \windows as described as Windows will prevent you from zipping it in the \windows directory.

Regards. . .

jcgriff2
 
Both RAM sticks were actually replaced before this latest BSOD that was attached.

Would memtest be able to tell if the issue is outside ram?

Oh... I wasn't aware that both sticks had been replaced. It is best to always replace RAM sticks in pairs - so you're good on that.

What exactly do you mean by "outside RAM?

There are basically two types of memory -
  1. Physical RAM - this would be the RAM stick(s) themselves
  2. Virtual memory - when your system runs out of physical memory (RAM), Windows will start using your HDD (Hard Disk Drive) page file as RAM, which slows the system down considerably due to the use of your hard drive in lieu of RAM, which if a SATA HDD, there are moving parts. If you have an SSD (Solid State Drive) instead of an HDD, it will likely speed things up, but will still not be as fast as RAM.
Regards. . .

jcgriff2
 
Oh... I wasn't aware that both sticks had been replaced. It is best to always replace RAM sticks in pairs - so you're good on that.

What exactly do you mean by "outside RAM?

There are basically two types of memory -
  1. Physical RAM - this would be the RAM stick(s) themselves
  2. Virtual memory - when your system runs out of physical memory (RAM), Windows will start using your HDD (Hard Disk Drive) page file as RAM, which slows the system down considerably due to the use of your hard drive in lieu of RAM, which if a SATA HDD, there are moving parts. If you have an SSD (Solid State Drive) instead of an HDD, it will likely speed things up, but will still not be as fast as RAM.
Regards. . .

jcgriff2
Yep, both sticks were replaced!
I was curious if memtest would be able to tell what the issue might be if it's not related to the physical ram.

Additionally, I have attached another Sysnative file collection zip file along with the memory dumps which can be found here under today's date March 7th, 2019.

Thanks!

EDIT: Forgot to add, I have ran an Error check with HD tune and it came back all green. Health also showed as all ok aside from Interface CRC error Count as below:
44758
 

Attachments

The MEMORY_MANAGEMENT bug check has a value of 0x0000001A. This indicates that a severe memory management error occurred.
1st parameter = 41287. Internal memory management structures are corrupted. To further investigate the cause, a kernel memory dump file is needed. So please send memory.dmp in \windows root directory
Code:
Loading Dump File [F:\022119-32635-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available


************* Symbol Path validation summary **************
Response                         Time (ms)     Location
Deferred                                       SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.24354.amd64fre.win7sp1_ldr_escrow.190108-1700
Machine Name:
Kernel base = 0xfffff800`03602000 PsLoadedModuleList = 0xfffff800`0383bc90
Debug session time: Thu Feb 21 23:24:03.275 2019 (UTC + 1:00)
System Uptime: 7 days 14:30:39.060
Loading Kernel Symbols
...............................................................
................................................................
..........................................................
Loading User Symbols
Loading unloaded module list
..................................................
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 1A, {41287, 0, 0, 0}

Probably caused by : ntkrnlmp.exe ( nt!KiPageFault+356 )

Followup:     MachineOwner
---------

1: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

MEMORY_MANAGEMENT (1a)
    # Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041287, An illegal page fault occurred while holding working set synchronization.
    Parameter 2 contains the referenced virtual address.
Arg2: 0000000000000000
Arg3: 0000000000000000
Arg4: 0000000000000000

Debugging Details:
------------------


DUMP_CLASS: 1

DUMP_QUALIFIER: 400

BUILD_VERSION_STRING:  7601.24354.amd64fre.win7sp1_ldr_escrow.190108-1700

SYSTEM_MANUFACTURER:  LENOVO

SYSTEM_PRODUCT_NAME:  20FN003SUS

SYSTEM_SKU:  LENOVO_MT_20FN_BU_Think_FM_ThinkPad T460

SYSTEM_VERSION:  ThinkPad T460

BIOS_VENDOR:  LENOVO

BIOS_VERSION:  R06ET65W (1.39 )

BIOS_DATE:  12/27/2018

BASEBOARD_MANUFACTURER:  LENOVO

BASEBOARD_PRODUCT:  20FN003SUS

BASEBOARD_VERSION:  SDK0J40705 WIN

DUMP_TYPE:  2

BUGCHECK_P1: 41287

BUGCHECK_P2: 0

BUGCHECK_P3: 0

BUGCHECK_P4: 0

BUGCHECK_STR:  0x1a_41287

CPU_COUNT: 4

CPU_MHZ: 960

CPU_VENDOR:  GenuineIntel

CPU_FAMILY: 6

CPU_MODEL: 4e

CPU_STEPPING: 3

CPU_MICROCODE: 6,4e,3,0 (F,M,S,R)  SIG: C6'00000000 (cache) C6'00000000 (init)

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  WIN7_DRIVER_FAULT

PROCESS_NAME:  dllhost.exe

CURRENT_IRQL:  0

ANALYSIS_SESSION_HOST:  MICHAL

ANALYSIS_SESSION_TIME:  03-07-2019 20:55:58.0751

ANALYSIS_VERSION: 10.0.10586.567 amd64fre

TRAP_FRAME:  fffff88024712bb0 -- (.trap 0xfffff88024712bb0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffffffffffffffff rbx=0000000000000000 rcx=fffffa8011d48e20
rdx=0000000000000001 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8000364feb1 rsp=fffff88024712d40 rbp=fffffa8009c82e78
 r8=fffffa8009692320  r9=000000000657b701 r10=0000000000000000
r11=fffffa8011d48e20 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei ng nz na pe nc
nt!MiRebalanceNode+0x21:
fffff800`0364feb1 498b0a          mov     rcx,qword ptr [r10] ds:00000000`00000000=????????????????
Resetting default scope

LAST_CONTROL_TRANSFER:  from fffff8000376f93e to fffff80003695ba0

STACK_TEXT: 
fffff880`24712a58 fffff800`0376f93e : 00000000`0000001a 00000000`00041287 00000000`00000000 00000000`00000000 : nt!KeBugCheckEx
fffff880`24712a60 fffff800`036a1c96 : 00000000`00000000 00000000`00000000 fffff800`037e6100 ffffffff`ffffffff : nt!MmAccessFault+0x26fe
fffff880`24712bb0 fffff800`0364feb1 : 00000000`00000000 fffff800`038fac13 fffffa80`132316a0 00000000`00000090 : nt!KiPageFault+0x356
fffff880`24712d40 fffff800`03646873 : fffffa80`06d2c7d0 fffffa80`0dcb6410 fffffa80`09c82a00 00000000`00010000 : nt!MiRebalanceNode+0x21
fffff880`24712d70 fffff800`03646568 : fffffa80`0dcb6410 00000000`00000000 fffffa80`09c82a30 fffffa80`0fea5860 : nt!MiRemoveNode+0x233
fffff880`24712da0 fffff800`038f5c41 : fffffa80`0fea5860 00000000`00010000 0007ffff`ffffffff fffffa80`09c82a30 : nt!MiRemoveVadAndView+0x68
fffff880`24712dd0 fffff800`0390578b : fffff880`00000000 00000000`0d570000 fffffa80`00000001 ffffffff`00007f01 : nt!MiUnmapViewOfSection+0x1b1
fffff880`24712e90 fffff800`036a3bd3 : 00000000`00000001 00000000`0bc4dfff fffffa80`09c82a30 00000000`065992c0 : nt!NtUnmapViewOfSection+0x5f
fffff880`24712ee0 00000000`76f09b2a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`06d1ca18 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x76f09b2a


STACK_COMMAND:  kb

THREAD_SHA1_HASH_MOD_FUNC:  91593fec8f8a6bc58ac92a00911f21c2ce392583

THREAD_SHA1_HASH_MOD_FUNC_OFFSET:  70b0c34f32645e65d34d6acb04e94e83943227a4

THREAD_SHA1_HASH_MOD:  9f457f347057f10e1df248e166a3e95e6570ecfe

FOLLOWUP_IP:
nt!KiPageFault+356
fffff800`036a1c96 85c0            test    eax,eax

FAULT_INSTR_CODE:  367cc085

SYMBOL_STACK_INDEX:  2

SYMBOL_NAME:  nt!KiPageFault+356

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP:  5c355e0b

IMAGE_VERSION:  6.1.7601.24354

FAILURE_BUCKET_ID:  X64_0x1a_41287_nt!KiPageFault+356

BUCKET_ID:  X64_0x1a_41287_nt!KiPageFault+356

PRIMARY_PROBLEM_CLASS:  X64_0x1a_41287_nt!KiPageFault+356

TARGET_TIME:  2019-02-21T22:24:03.000Z

OSBUILD:  7601

OSSERVICEPACK:  1000

SERVICEPACK_NUMBER: 0

OS_REVISION: 0

SUITE_MASK:  272

PRODUCT_TYPE:  1

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 7

OSEDITION:  Windows 7 WinNt (Service Pack 1) TerminalServer SingleUserTS

OS_LOCALE: 

USER_LCID:  0

OSBUILD_TIMESTAMP:  2019-01-09 03:35:55

BUILDDATESTAMP_STR:  190108-1700

BUILDLAB_STR:  win7sp1_ldr_escrow

BUILDOSVER_STR:  6.1.7601.24354.amd64fre.win7sp1_ldr_escrow.190108-1700

ANALYSIS_SESSION_ELAPSED_TIME: 4fc

ANALYSIS_SOURCE:  KM

FAILURE_ID_HASH_STRING:  km:x64_0x1a_41287_nt!kipagefault+356

FAILURE_ID_HASH:  {57c1a06a-3107-678e-b2be-207e9cbf3f0f}

Followup:     MachineOwner
---------
The DRIVER_CORRUPTED_EXPOOL bug check has a value of 0x000000C5. This indicates that the system attempted to access invalid memory at a process IRQL that was too high.
Please enable special pool option in Driver Verifier (Driver Verifier - BSOD related - Windows 10, 8.1, 8, 7 + Vista)
Code:
Loading Dump File [F:\022719-11934-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available


************* Symbol Path validation summary **************
Response                         Time (ms)     Location
Deferred                                       SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.24358.amd64fre.win7sp1_ldr_escrow.190208-1418
Machine Name:
Kernel base = 0xfffff800`03651000 PsLoadedModuleList = 0xfffff800`0388ac90
Debug session time: Wed Feb 27 09:28:17.002 2019 (UTC + 1:00)
System Uptime: 0 days 12:19:34.879
Loading Kernel Symbols
...............................................................
................................................................
.........................................................
Loading User Symbols
Loading unloaded module list
.............................
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck C5, {8, 2, 1, fffff8000382b077}

Probably caused by : fileinfo.sys ( fileinfo!FIStreamQueryWorker+9e )

Followup:     MachineOwner
---------

1: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

DRIVER_CORRUPTED_EXPOOL (c5)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high.  This is
caused by drivers that have corrupted the system pool.  Run the driver
verifier against any new (or suspect) drivers, and if that doesn't turn up
the culprit, then use gflags to enable special pool.
Arguments:
Arg1: 0000000000000008, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000001, value 0 = read operation, 1 = write operation
Arg4: fffff8000382b077, address which referenced memory

Debugging Details:
------------------


DUMP_CLASS: 1

DUMP_QUALIFIER: 400

BUILD_VERSION_STRING:  7601.24358.amd64fre.win7sp1_ldr_escrow.190208-1418

SYSTEM_MANUFACTURER:  LENOVO

SYSTEM_PRODUCT_NAME:  20FN003SUS

SYSTEM_SKU:  LENOVO_MT_20FN_BU_Think_FM_ThinkPad T460

SYSTEM_VERSION:  ThinkPad T460

BIOS_VENDOR:  LENOVO

BIOS_VERSION:  R06ET66W (1.40 )

BIOS_DATE:  01/25/2019

BASEBOARD_MANUFACTURER:  LENOVO

BASEBOARD_PRODUCT:  20FN003SUS

BASEBOARD_VERSION:  SDK0J40705 WIN

DUMP_TYPE:  2

BUGCHECK_P1: 8

BUGCHECK_P2: 2

BUGCHECK_P3: 1

BUGCHECK_P4: fffff8000382b077

BUGCHECK_STR:  0xC5_2

CURRENT_IRQL:  2

FAULTING_IP:
nt!ExAllocatePoolWithTag+537
fffff800`0382b077 48895808        mov     qword ptr [rax+8],rbx

CPU_COUNT: 4

CPU_MHZ: 960

CPU_VENDOR:  GenuineIntel

CPU_FAMILY: 6

CPU_MODEL: 4e

CPU_STEPPING: 3

CPU_MICROCODE: 6,4e,3,0 (F,M,S,R)  SIG: C6'00000000 (cache) C6'00000000 (init)

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  WIN7_DRIVER_FAULT

PROCESS_NAME:  System

ANALYSIS_SESSION_HOST:  MICHAL

ANALYSIS_SESSION_TIME:  03-07-2019 20:58:45.0147

ANALYSIS_VERSION: 10.0.10586.567 amd64fre

TRAP_FRAME:  fffff880043f01b0 -- (.trap 0xfffff880043f01b0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=fffffa8013509010
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8000382b077 rsp=fffff880043f0340 rbp=0000000000001000
 r8=0000000000000000  r9=fffff8000384bdb0 r10=fffff8000384b888
r11=fffff880043f05b8 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei pl zr na po nc
nt!ExAllocatePoolWithTag+0x537:
fffff800`0382b077 48895808        mov     qword ptr [rax+8],rbx ds:00000000`00000008=????????????????
Resetting default scope

LAST_CONTROL_TRANSFER:  from fffff800036f2f69 to fffff800036e4ba0

STACK_TEXT: 
fffff880`043f0068 fffff800`036f2f69 : 00000000`0000000a 00000000`00000008 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
fffff880`043f0070 fffff800`036f0d88 : 00000000`00000001 00000000`00000008 fffff880`043f0300 fffff800`0384bdb0 : nt!KiBugCheckDispatch+0x69
fffff880`043f01b0 fffff800`0382b077 : fffffa80`13388c58 fffff800`03687f1e fffffa80`0945b8b0 00000000`00000000 : nt!KiPageFault+0x448
fffff880`043f0340 fffff800`03669a2e : fffffa80`00000000 fffffa80`13061ef0 fffffa80`13061dc0 fffffa80`00000000 : nt!ExAllocatePoolWithTag+0x537
fffff880`043f0430 fffff800`036762de : fffffa80`13061ef0 00000000`00000000 00000000`00000000 fffffa80`067a2b50 : nt!ExpExpandResourceOwnerTable+0x4e
fffff880`043f0480 fffff800`036886f6 : fffffa80`0ff89dd0 fffff800`0382a23d fffffa80`0fa83f30 00000000`00000020 : nt!ExpFindEmptyEntry+0x4e
fffff880`043f04b0 fffff880`0241e549 : 00000000`c00000d8 fffff8a0`15179010 00000000`00000000 fffff880`043f06e0 : nt!ExAcquireResourceSharedLite+0x276
fffff880`043f0520 fffff880`0249b09f : 00000000`00000000 00000000`0000000c fffff8a0`1d425010 fffff880`043f06e0 : Ntfs!NtfsAcquireSharedFcb+0x69
fffff880`043f0570 fffff880`02499816 : fffff880`043f06e0 fffffa80`121bdb80 00000000`0000000c fffffa80`0000000c : Ntfs!NtfsCommonQueryInformation+0x35f
fffff880`043f0640 fffff880`02499ff4 : fffff880`043f06e0 fffffa80`121bdb80 fffffa80`121bdb80 00000000`00000000 : Ntfs!NtfsFsdDispatchSwitch+0x106
fffff880`043f06c0 fffff880`00e7ebbc : 00000000`00000001 fffff880`043f09a0 00000000`0000000c fffff880`009c0180 : Ntfs!NtfsFsdDispatchWait+0x14
fffff880`043f08b0 fffff880`00e8041b : fffff880`043f09a0 fffffa80`095a5010 fffffa80`0959f030 fffffa80`0a196960 : FLTMGR!FltpQueryInformationFile+0xfc
fffff880`043f0920 fffff880`00e85eac : 00000000`0000199a fffffa80`095a5010 fffff880`043f0af0 00000000`00000000 : FLTMGR!QueryStandardLinkInformation+0x4b
fffff880`043f0980 fffff880`00e624eb : fffffa80`10223310 fffffa80`095adbb0 fffff880`043f0af0 00000000`00000000 : FLTMGR! ?? ::NNGAKEGL::`string'+0x24ba
fffff880`043f09e0 fffff880`00e7d5bf : fffffa80`130fbc40 fffff8a0`03c643b8 00000000`00000000 fffffa80`10223310 : FLTMGR!FltpGetFileNameInformation+0x1fb
fffff880`043f0a50 fffff880`023d5962 : fffffa80`10223310 00000000`00000000 fffffa80`0a196960 fffff880`00e63e79 : FLTMGR!FltGetFileNameInformationUnsafe+0x7f
fffff880`043f0ac0 fffff880`00e8b2b3 : 00000000`00000000 00000000`00000001 fffffa80`095adbb0 00000000`00000000 : fileinfo!FIStreamQueryWorker+0x9e
fffff880`043f0b30 fffff800`0367fb39 : fffff880`00e8b270 fffff800`038617f8 fffffa80`067a2b50 fffffa80`0b244550 : FLTMGR!FltpProcessGenericWorkItem+0x43
fffff880`043f0b70 fffff800`03992890 : 00000000`00000000 fffff880`041bb180 00000000`00000080 00000000`00000001 : nt!ExpWorkerThread+0x111
fffff880`043f0c00 fffff800`036eaba6 : fffff880`041bb180 fffffa80`067a2b50 fffff880`041ca140 00000000`00000000 : nt!PspSystemThreadStartup+0x194
fffff880`043f0c40 00000000`00000000 : fffff880`043f1000 fffff880`043eb000 fffff880`043f08a0 00000000`00000000 : nt!KxStartSystemThread+0x16


STACK_COMMAND:  kb

THREAD_SHA1_HASH_MOD_FUNC:  310f600bf7e8471e92e2774c85fccd65a8a8dde8

THREAD_SHA1_HASH_MOD_FUNC_OFFSET:  715b772cd82121ceeaf0b518d840c1882ee967b1

THREAD_SHA1_HASH_MOD:  fe470d75c5d074cd8f8075a96d8a123d2fc3bf39

FOLLOWUP_IP:
fileinfo!FIStreamQueryWorker+9e
fffff880`023d5962 85c0            test    eax,eax

FAULT_INSTR_CODE:  a79c085

SYMBOL_STACK_INDEX:  10

SYMBOL_NAME:  fileinfo!FIStreamQueryWorker+9e

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: fileinfo

IMAGE_NAME:  fileinfo.sys

DEBUG_FLR_IMAGE_TIMESTAMP:  4a5bc481

IMAGE_VERSION:  6.1.7600.16385

FAILURE_BUCKET_ID:  X64_0xC5_2_fileinfo!FIStreamQueryWorker+9e

BUCKET_ID:  X64_0xC5_2_fileinfo!FIStreamQueryWorker+9e

PRIMARY_PROBLEM_CLASS:  X64_0xC5_2_fileinfo!FIStreamQueryWorker+9e

TARGET_TIME:  2019-02-27T08:28:17.000Z

OSBUILD:  7601

OSSERVICEPACK:  1000

SERVICEPACK_NUMBER: 0

OS_REVISION: 0

SUITE_MASK:  272

PRODUCT_TYPE:  1

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 7

OSEDITION:  Windows 7 WinNt (Service Pack 1) TerminalServer SingleUserTS

OS_LOCALE: 

USER_LCID:  0

OSBUILD_TIMESTAMP:  2019-02-09 00:52:23

BUILDDATESTAMP_STR:  190208-1418

BUILDLAB_STR:  win7sp1_ldr_escrow

BUILDOSVER_STR:  6.1.7601.24358.amd64fre.win7sp1_ldr_escrow.190208-1418

ANALYSIS_SESSION_ELAPSED_TIME: 510

ANALYSIS_SOURCE:  KM

FAILURE_ID_HASH_STRING:  km:x64_0xc5_2_fileinfo!fistreamqueryworker+9e

FAILURE_ID_HASH:  {611e7bee-1c2d-e5b9-260a-8632ad31b8df}

Followup:     MachineOwner
---------
 
The MEMORY_MANAGEMENT bug check has a value of 0x0000001A. This indicates that a severe memory management error occurred.
1st parameter = 41287. Internal memory management structures are corrupted. To further investigate the cause, a kernel memory dump file is needed. So please send memory.dmp in \windows root directory
Memory dumps can be found under this hyperlink. The latest memory.dmp which you asked for earlier can be found under the 3-7-2019 folder.

Thanks!
 
The BAD_POOL_CALLER bug check has a value of 0x000000C2. This indicates that the current thread is making a bad pool request.
1st parameter 0x7 = The current thread attempted to free the pool, which was already freed.
I see the driver verifier on, but as you can see I miss the full memory dump for proper analysis again. At the moment, update the drivers for the graphics card
Code:
Microsoft (R) Windows Debugger Version 10.0.10586.567 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [F:\030819-10436-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available


************* Symbol Path validation summary **************
Response                         Time (ms)     Location
Deferred                                       SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.24358.amd64fre.win7sp1_ldr_escrow.190208-1418
Machine Name:
Kernel base = 0xfffff800`03648000 PsLoadedModuleList = 0xfffff800`03881c90
Debug session time: Fri Mar  8 15:02:25.931 2019 (UTC + 1:00)
System Uptime: 0 days 17:27:21.921
Loading Kernel Symbols
...............................................................
................................................................
................................................................
..........
Loading User Symbols
Loading unloaded module list
...........................
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck C2, {7, 109b, 0, fffffa80150d2430}

GetPointerFromAddress: unable to read from fffff800038e5100
Unable to get MmSystemRangeStart
Probably caused by : dxgmms1.sys ( dxgmms1!DXGFASTMUTEX::`scalar deleting destructor'+b6 )

Followup:     MachineOwner
---------

2: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

BAD_POOL_CALLER (c2)
The current thread is making a bad pool request.  Typically this is at a bad IRQL level or double freeing the same allocation, etc.
Arguments:
Arg1: 0000000000000007, Attempt to free pool which was already freed
Arg2: 000000000000109b, (reserved)
Arg3: 0000000000000000, Memory contents of the pool block
Arg4: fffffa80150d2430, Address of the block of pool being deallocated

Debugging Details:
------------------

GetPointerFromAddress: unable to read from fffff800038e5100
Unable to get MmSystemRangeStart

DUMP_CLASS: 1

DUMP_QUALIFIER: 400

BUILD_VERSION_STRING:  7601.24358.amd64fre.win7sp1_ldr_escrow.190208-1418

SYSTEM_MANUFACTURER:  LENOVO

SYSTEM_PRODUCT_NAME:  20FN003SUS

SYSTEM_SKU:  LENOVO_MT_20FN_BU_Think_FM_ThinkPad T460

SYSTEM_VERSION:  ThinkPad T460

BIOS_VENDOR:  LENOVO

BIOS_VERSION:  R06ET66W (1.40 )

BIOS_DATE:  01/25/2019

BASEBOARD_MANUFACTURER:  LENOVO

BASEBOARD_PRODUCT:  20FN003SUS

BASEBOARD_VERSION:  SDK0J40705 WIN

DUMP_TYPE:  2

BUGCHECK_P1: 7

BUGCHECK_P2: 109b

BUGCHECK_P3: 0

BUGCHECK_P4: fffffa80150d2430

POOL_ADDRESS: GetPointerFromAddress: unable to read from fffff800038e5100
Unable to get MmSystemRangeStart
fffffa80150d2430

BUGCHECK_STR:  0xc2_7

CPU_COUNT: 4

CPU_MHZ: 960

CPU_VENDOR:  GenuineIntel

CPU_FAMILY: 6

CPU_MODEL: 4e

CPU_STEPPING: 3

CPU_MICROCODE: 6,4e,3,0 (F,M,S,R)  SIG: C6'00000000 (cache) C6'00000000 (init)

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  WIN7_DRIVER_FAULT

PROCESS_NAME:  firefox.exe

CURRENT_IRQL:  0

ANALYSIS_SESSION_HOST:  MICHAL

ANALYSIS_SESSION_TIME:  03-08-2019 17:42:11.0122

ANALYSIS_VERSION: 10.0.10586.567 amd64fre

LAST_CONTROL_TRANSFER:  from fffff80003823a01 to fffff800036dbba0

STACK_TEXT:
fffff880`1ffea248 fffff800`03823a01 : 00000000`000000c2 00000000`00000007 00000000`0000109b 00000000`00000000 : nt!KeBugCheckEx
fffff880`1ffea250 fffff880`05731ad2 : 00000000`00000000 fffffa80`0ce78000 fffff8a0`15890000 fffffa80`0ce78000 : nt!ExFreePool+0xca9
fffff880`1ffea300 fffff880`05746dcb : fffff8a0`2a3db7e0 00000000`00000000 fffffa80`6d4d6956 00000000`00000174 : dxgmms1!DXGFASTMUTEX::`scalar deleting destructor'+0xb6
fffff880`1ffea330 fffff880`0572d98f : fffffa80`116bc000 fffff8a0`06ebe590 fffffa80`0ce78000 fffff8a0`06abfa50 : dxgmms1!VIDMM_GLOBAL::DestroyOneAllocation+0x2fb
fffff880`1ffea410 fffff880`081011bb : 00000000`00000000 00000000`00000000 fffff8a0`15890000 00000000`00000174 : dxgmms1!VidMmDestroyAllocation+0x4f
fffff880`1ffea440 fffff880`08113b0c : 00000000`00000001 00000000`00000000 00000000`00000000 fffff8a0`00000799 : dxgkrnl!DXGDEVICE::DestroyAllocations+0x5eb
fffff880`1ffea530 fffff880`080f8909 : 00000000`fffffeda fffff8a0`156e46b0 fffff8a0`15890000 fffffa80`0ab14000 : dxgkrnl!DXGDEVICE::~DXGDEVICE+0x19c
fffff880`1ffea5a0 fffff880`08137252 : 00000000`00000000 fffffa80`0ab14000 fffff8a0`156e46b0 fffff8a0`156e4730 : dxgkrnl!DXGADAPTER::DestroyDevice+0x1c9
fffff880`1ffea5d0 fffff880`08136be8 : fffff900`c07ddcd0 00000000`00000000 00000000`00000001 fffff900`c07ddcd0 : dxgkrnl!DXGPROCESS::Destroy+0xba
fffff880`1ffea680 fffff960`001184f0 : 00000000`000011d0 fffff900`c07ddcd0 00000000`00000000 fffff900`c07ddcd0 : dxgkrnl!DxgkProcessCallout+0x268
fffff880`1ffea710 fffff960`00117be7 : fffffa80`0d56a700 fffff880`1ffeaae0 fffffa80`13dd07f0 00000000`00000001 : win32k!GdiProcessCallout+0x244
fffff880`1ffea790 fffff800`03a78af3 : fffffa80`0d56a790 00000000`00000000 00000000`00000000 fffffa80`13dd07f0 : win32k!W32pProcessCallout+0x6b
fffff880`1ffea7c0 fffff800`03911155 : fffffa80`00000000 fffff800`03821d01 fffffa80`78457300 fffffa80`12ad4060 : nt!PspExitThread+0x563
fffff880`1ffea880 fffff800`03675664 : 00000000`085e4e01 fffff800`036b0b2f fffff8a0`15890000 fffff8a0`06e2a670 : nt!PsExitSpecialApc+0x1d
fffff880`1ffea8b0 fffff800`036e06e0 : 00000000`00000000 fffff880`1ffea930 fffff800`0395bef8 00000000`00000001 : nt!KiDeliverApc+0x2e4
fffff880`1ffea930 fffff800`036e9c77 : fffffa80`13dd07f0 00000000`0d88f538 fffff880`1ffeaa88 00000000`0d88f500 : nt!KiInitiateUserApc+0x70
fffff880`1ffeaa70 00000000`76ec9e3a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExit+0x9c
00000000`0d88f518 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x76ec9e3a


STACK_COMMAND:  kb

THREAD_SHA1_HASH_MOD_FUNC:  079ba154f485a127c8f7c4d22242e8b2a33a6d96

THREAD_SHA1_HASH_MOD_FUNC_OFFSET:  74f55a2e4e1265b734c99750cae5bfdbd0e44be8

THREAD_SHA1_HASH_MOD:  321fcbd20d6be8ab503bda1aa8aecd778898a985

FOLLOWUP_IP:
dxgmms1!DXGFASTMUTEX::`scalar deleting destructor'+b6
fffff880`05731ad2 488bc3          mov     rax,rbx

FAULT_INSTR_CODE:  48c38b48

SYMBOL_STACK_INDEX:  2

SYMBOL_NAME:  dxgmms1!DXGFASTMUTEX::`scalar deleting destructor'+b6

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: dxgmms1

IMAGE_NAME:  dxgmms1.sys

DEBUG_FLR_IMAGE_TIMESTAMP:  5b94676d

IMAGE_VERSION:  6.1.7601.24260

FAILURE_BUCKET_ID:  X64_0xc2_7_dxgmms1!DXGFASTMUTEX::_scalar_deleting_destructor_+b6

BUCKET_ID:  X64_0xc2_7_dxgmms1!DXGFASTMUTEX::_scalar_deleting_destructor_+b6

PRIMARY_PROBLEM_CLASS:  X64_0xc2_7_dxgmms1!DXGFASTMUTEX::_scalar_deleting_destructor_+b6

TARGET_TIME:  2019-03-08T14:02:25.000Z

OSBUILD:  7601

OSSERVICEPACK:  1000

SERVICEPACK_NUMBER: 0

OS_REVISION: 0

SUITE_MASK:  272

PRODUCT_TYPE:  1

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 7

OSEDITION:  Windows 7 WinNt (Service Pack 1) TerminalServer SingleUserTS

OS_LOCALE:

USER_LCID:  0

OSBUILD_TIMESTAMP:  2019-02-09 00:52:23

BUILDDATESTAMP_STR:  190208-1418

BUILDLAB_STR:  win7sp1_ldr_escrow

BUILDOSVER_STR:  6.1.7601.24358.amd64fre.win7sp1_ldr_escrow.190208-1418

ANALYSIS_SESSION_ELAPSED_TIME: 52c

ANALYSIS_SOURCE:  KM

FAILURE_ID_HASH_STRING:  km:x64_0xc2_7_dxgmms1!dxgfastmutex::_scalar_deleting_destructor_+b6

FAILURE_ID_HASH:  {df932a3d-4ce9-d5f9-8f20-2c86c0cc87d1}

Followup:     MachineOwner
---------

2: kd> !poolval fffffa80150d2430
GetPointerFromAddress: unable to read from fffff800038e5100
Unable to get MmSystemRangeStart
2: kd> !pool fffffa80150d2430
GetPointerFromAddress: unable to read from fffff800038e5100
Unable to get MmSystemRangeStart
GetPointerFromAddress: unable to read from fffff800038e5100
Unable to get MmSystemRangeStart
GetPointerFromAddress: unable to read from fffff800038e5100
Unable to get MmSystemRangeStart
Pool page fffffa80150d2430 region is Unknown
GetUlongFromAddress: unable to read from fffff80003858f58
Unable to get pool big page table. Check for valid symbols.
fffffa80150d2000 is not valid pool. Checking for freed (or corrupt) pool
Bad allocation size @fffffa80150d2000, zero is invalid
2: kd> !verifier

Verify Flags Level 0x00000000

  STANDARD FLAGS:
    [X] (0x00000000) Automatic Checks
    [ ] (0x00000001) Special pool
    [ ] (0x00000002) Force IRQL checking
    [ ] (0x00000008) Pool tracking
    [ ] (0x00000010) I/O verification
    [ ] (0x00000020) Deadlock detection
    [ ] (0x00000080) DMA checking
    [ ] (0x00000100) Security checks
    [ ] (0x00000800) Miscellaneous checks

  ADDITIONAL FLAGS:
    [ ] (0x00000004) Randomized low resources simulation
    [ ] (0x00000200) Force pending I/O requests
    [ ] (0x00000400) IRP logging

    [X] Indicates flag is enabled


Summary of All Verifier Statistics

  RaiseIrqls           0x0
  AcquireSpinLocks     0x0
  Synch Executions     0x0
  Trims                0x0

  Pool Allocations Attempted             0x0
  Pool Allocations Succeeded             0x0
  Pool Allocations Succeeded SpecialPool 0x0
  Pool Allocations With NO TAG           0x0
  Pool Allocations Failed                0x0

  Current paged pool allocations         0x0 for 00000000 bytes
  Peak paged pool allocations            0x0 for 00000000 bytes
  Current nonpaged pool allocations      0x0 for 00000000 bytes
  Peak nonpaged pool allocations         0x0 for 00000000 bytes
Code:
2: kd> lmvm igdkmd64
Browse full module list
start             end                 module name
fffff880`0760a000 fffff880`080c9000   igdkmd64   (deferred)            
    Image path: \SystemRoot\system32\DRIVERS\igdkmd64.sys
    Image name: igdkmd64.sys
    Browse all global symbols  functions  data
    Timestamp:        Wed Oct 31 15:32:25 2018 (5BD9BCF9)
    CheckSum:         00A9D4BB
    ImageSize:        00ABF000
    Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
Code:
2: kd> !thread
GetPointerFromAddress: unable to read from fffff800038e5000
THREAD fffffa8013dd07f0  Cid 11d0.2724  Teb: 000007fffff6e000 Win32Thread: 0000000000000000 RUNNING on processor 2
Not impersonating
GetUlongFromAddress: unable to read from fffff80003827c20
Owning Process            fffffa800fdb0b00       Image:         firefox.exe
Attached Process          N/A            Image:         N/A
fffff78000000000: Unable to get shared data
Wait Start TickCount      4028302     
Context Switch Count      146            IdealProcessor: 2                 LargeStack
ReadMemory error: Cannot get nt!KeMaximumIncrement value.
UserTime                  00:00:00.000
KernelTime                00:00:00.000
Win32 Start Address 0x000007fee0cf8614
Stack Init fffff8801ffeac70 Current fffff8801ffe9de0
Base fffff8801ffeb000 Limit fffff8801ffe5000 Call 0
Priority 6 BasePriority 4 UnusualBoost 0 ForegroundBoost 0 IoPriority 0 PagePriority 1
Child-SP          RetAddr           : Args to Child                                                           : Call Site
fffff880`1ffea248 fffff800`03823a01 : 00000000`000000c2 00000000`00000007 00000000`0000109b 00000000`00000000 : nt!KeBugCheckEx
fffff880`1ffea250 fffff880`05731ad2 : 00000000`00000000 fffffa80`0ce78000 fffff8a0`15890000 fffffa80`0ce78000 : nt!ExFreePool+0xca9
fffff880`1ffea300 fffff880`05746dcb : fffff8a0`2a3db7e0 00000000`00000000 fffffa80`6d4d6956 00000000`00000174 : dxgmms1!DXGFASTMUTEX::`scalar deleting destructor'+0xb6
fffff880`1ffea330 fffff880`0572d98f : fffffa80`116bc000 fffff8a0`06ebe590 fffffa80`0ce78000 fffff8a0`06abfa50 : dxgmms1!VIDMM_GLOBAL::DestroyOneAllocation+0x2fb
fffff880`1ffea410 fffff880`081011bb : 00000000`00000000 00000000`00000000 fffff8a0`15890000 00000000`00000174 : dxgmms1!VidMmDestroyAllocation+0x4f
fffff880`1ffea440 fffff880`08113b0c : 00000000`00000001 00000000`00000000 00000000`00000000 fffff8a0`00000799 : dxgkrnl!DXGDEVICE::DestroyAllocations+0x5eb
fffff880`1ffea530 fffff880`080f8909 : 00000000`fffffeda fffff8a0`156e46b0 fffff8a0`15890000 fffffa80`0ab14000 : dxgkrnl!DXGDEVICE::~DXGDEVICE+0x19c
fffff880`1ffea5a0 fffff880`08137252 : 00000000`00000000 fffffa80`0ab14000 fffff8a0`156e46b0 fffff8a0`156e4730 : dxgkrnl!DXGADAPTER::DestroyDevice+0x1c9
fffff880`1ffea5d0 fffff880`08136be8 : fffff900`c07ddcd0 00000000`00000000 00000000`00000001 fffff900`c07ddcd0 : dxgkrnl!DXGPROCESS::Destroy+0xba
fffff880`1ffea680 fffff960`001184f0 : 00000000`000011d0 fffff900`c07ddcd0 00000000`00000000 fffff900`c07ddcd0 : dxgkrnl!DxgkProcessCallout+0x268
fffff880`1ffea710 fffff960`00117be7 : fffffa80`0d56a700 fffff880`1ffeaae0 fffffa80`13dd07f0 00000000`00000001 : win32k!GdiProcessCallout+0x244
fffff880`1ffea790 fffff800`03a78af3 : fffffa80`0d56a790 00000000`00000000 00000000`00000000 fffffa80`13dd07f0 : win32k!W32pProcessCallout+0x6b
fffff880`1ffea7c0 fffff800`03911155 : fffffa80`00000000 fffff800`03821d01 fffffa80`78457300 fffffa80`12ad4060 : nt!PspExitThread+0x563
fffff880`1ffea880 fffff800`03675664 : 00000000`085e4e01 fffff800`036b0b2f fffff8a0`15890000 fffff8a0`06e2a670 : nt!PsExitSpecialApc+0x1d
fffff880`1ffea8b0 fffff800`036e06e0 : 00000000`00000000 fffff880`1ffea930 fffff800`0395bef8 00000000`00000001 : nt!KiDeliverApc+0x2e4
fffff880`1ffea930 fffff800`036e9c77 : fffffa80`13dd07f0 00000000`0d88f538 fffff880`1ffeaa88 00000000`0d88f500 : nt!KiInitiateUserApc+0x70
fffff880`1ffeaa70 00000000`76ec9e3a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExit+0x9c (TrapFrame @ fffff880`1ffeaae0)
00000000`0d88f518 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x76ec9e3a
 
Dump file shows the failure pool. Please launch Driver Verifier and in it option special pool (Driver Verifier - BSOD related - Windows 10, 8.1, 8, 7 + Vista)
Code:
Loading Dump File [F:\MEMORY.DMP]
Kernel Summary Dump File: Kernel address space is available, User address space may not be available.


************* Symbol Path validation summary **************
Response                         Time (ms)     Location
Deferred                                       SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*C:\SymCache*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7601.24358.amd64fre.win7sp1_ldr_escrow.190208-1418
Machine Name:
Kernel base = 0xfffff800`03648000 PsLoadedModuleList = 0xfffff800`03881c90
Debug session time: Fri Mar  8 15:02:25.931 2019 (UTC + 1:00)
System Uptime: 0 days 17:27:21.921
Loading Kernel Symbols
...............................................................
................................................................
................................................................
..........
Loading User Symbols
PEB is paged out (Peb.Ldr = 000007ff`fffd4018).  Type ".hh dbgerr001" for details
Loading unloaded module list
...........................
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck C2, {7, 109b, 0, fffffa80150d2430}

Probably caused by : dxgmms1.sys ( dxgmms1!DXGFASTMUTEX::`scalar deleting destructor'+b6 )

Followup:     MachineOwner
---------

2: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

BAD_POOL_CALLER (c2)
The current thread is making a bad pool request.  Typically this is at a bad IRQL level or double freeing the same allocation, etc.
Arguments:
Arg1: 0000000000000007, Attempt to free pool which was already freed
Arg2: 000000000000109b, (reserved)
Arg3: 0000000000000000, Memory contents of the pool block
Arg4: fffffa80150d2430, Address of the block of pool being deallocated

Debugging Details:
------------------


DUMP_CLASS: 1

DUMP_QUALIFIER: 401

BUILD_VERSION_STRING:  7601.24358.amd64fre.win7sp1_ldr_escrow.190208-1418

SYSTEM_MANUFACTURER:  LENOVO

SYSTEM_PRODUCT_NAME:  20FN003SUS

SYSTEM_SKU:  LENOVO_MT_20FN_BU_Think_FM_ThinkPad T460

SYSTEM_VERSION:  ThinkPad T460

BIOS_VENDOR:  LENOVO

BIOS_VERSION:  R06ET66W (1.40 )

BIOS_DATE:  01/25/2019

BASEBOARD_MANUFACTURER:  LENOVO

BASEBOARD_PRODUCT:  20FN003SUS

BASEBOARD_VERSION:  SDK0J40705 WIN

DUMP_TYPE:  1

BUGCHECK_P1: 7

BUGCHECK_P2: 109b

BUGCHECK_P3: 0

BUGCHECK_P4: fffffa80150d2430

POOL_ADDRESS:  fffffa80150d2430 Nonpaged pool

BUGCHECK_STR:  0xc2_7

CPU_COUNT: 4

CPU_MHZ: 960

CPU_VENDOR:  GenuineIntel

CPU_FAMILY: 6

CPU_MODEL: 4e

CPU_STEPPING: 3

CPU_MICROCODE: 6,4e,3,0 (F,M,S,R)  SIG: C6'00000000 (cache) C6'00000000 (init)

DEFAULT_BUCKET_ID:  WIN7_DRIVER_FAULT

PROCESS_NAME:  firefox.exe

CURRENT_IRQL:  0

ANALYSIS_SESSION_HOST:  MICHAL

ANALYSIS_SESSION_TIME:  03-08-2019 19:08:44.0487

ANALYSIS_VERSION: 10.0.10586.567 amd64fre

LAST_CONTROL_TRANSFER:  from fffff80003823a01 to fffff800036dbba0

STACK_TEXT:
fffff880`1ffea248 fffff800`03823a01 : 00000000`000000c2 00000000`00000007 00000000`0000109b 00000000`00000000 : nt!KeBugCheckEx
fffff880`1ffea250 fffff880`05731ad2 : 00000000`00000000 fffffa80`0ce78000 fffff8a0`15890000 fffffa80`0ce78000 : nt!ExFreePool+0xca9
fffff880`1ffea300 fffff880`05746dcb : fffff8a0`2a3db7e0 00000000`00000000 fffffa80`6d4d6956 00000000`00000174 : dxgmms1!DXGFASTMUTEX::`scalar deleting destructor'+0xb6
fffff880`1ffea330 fffff880`0572d98f : fffffa80`116bc000 fffff8a0`06ebe590 fffffa80`0ce78000 fffff8a0`06abfa50 : dxgmms1!VIDMM_GLOBAL::DestroyOneAllocation+0x2fb
fffff880`1ffea410 fffff880`081011bb : 00000000`00000000 00000000`00000000 fffff8a0`15890000 00000000`00000174 : dxgmms1!VidMmDestroyAllocation+0x4f
fffff880`1ffea440 fffff880`08113b0c : 00000000`00000001 00000000`00000000 00000000`00000000 fffff8a0`00000799 : dxgkrnl!DXGDEVICE::DestroyAllocations+0x5eb
fffff880`1ffea530 fffff880`080f8909 : 00000000`fffffeda fffff8a0`156e46b0 fffff8a0`15890000 fffffa80`0ab14000 : dxgkrnl!DXGDEVICE::~DXGDEVICE+0x19c
fffff880`1ffea5a0 fffff880`08137252 : 00000000`00000000 fffffa80`0ab14000 fffff8a0`156e46b0 fffff8a0`156e4730 : dxgkrnl!DXGADAPTER::DestroyDevice+0x1c9
fffff880`1ffea5d0 fffff880`08136be8 : fffff900`c07ddcd0 00000000`00000000 00000000`00000001 fffff900`c07ddcd0 : dxgkrnl!DXGPROCESS::Destroy+0xba
fffff880`1ffea680 fffff960`001184f0 : 00000000`000011d0 fffff900`c07ddcd0 00000000`00000000 fffff900`c07ddcd0 : dxgkrnl!DxgkProcessCallout+0x268
fffff880`1ffea710 fffff960`00117be7 : fffffa80`0d56a700 fffff880`1ffeaae0 fffffa80`13dd07f0 00000000`00000001 : win32k!GdiProcessCallout+0x244
fffff880`1ffea790 fffff800`03a78af3 : fffffa80`0d56a790 00000000`00000000 00000000`00000000 fffffa80`13dd07f0 : win32k!W32pProcessCallout+0x6b
fffff880`1ffea7c0 fffff800`03911155 : fffffa80`00000000 fffff800`03821d01 fffffa80`78457300 fffffa80`12ad4060 : nt!PspExitThread+0x563
fffff880`1ffea880 fffff800`03675664 : 00000000`085e4e01 fffff800`036b0b2f fffff8a0`15890000 fffff8a0`06e2a670 : nt!PsExitSpecialApc+0x1d
fffff880`1ffea8b0 fffff800`036e06e0 : 00000000`00000000 fffff880`1ffea930 fffff800`0395bef8 00000000`00000001 : nt!KiDeliverApc+0x2e4
fffff880`1ffea930 fffff800`036e9c77 : fffffa80`13dd07f0 00000000`0d88f538 fffff880`1ffeaa88 00000000`0d88f500 : nt!KiInitiateUserApc+0x70
fffff880`1ffeaa70 00000000`76ec9e3a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExit+0x9c
00000000`0d88f518 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x76ec9e3a


STACK_COMMAND:  kb

THREAD_SHA1_HASH_MOD_FUNC:  079ba154f485a127c8f7c4d22242e8b2a33a6d96

THREAD_SHA1_HASH_MOD_FUNC_OFFSET:  74f55a2e4e1265b734c99750cae5bfdbd0e44be8

THREAD_SHA1_HASH_MOD:  321fcbd20d6be8ab503bda1aa8aecd778898a985

FOLLOWUP_IP:
dxgmms1!DXGFASTMUTEX::`scalar deleting destructor'+b6
fffff880`05731ad2 488bc3          mov     rax,rbx

FAULT_INSTR_CODE:  48c38b48

SYMBOL_STACK_INDEX:  2

SYMBOL_NAME:  dxgmms1!DXGFASTMUTEX::`scalar deleting destructor'+b6

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: dxgmms1

IMAGE_NAME:  dxgmms1.sys

DEBUG_FLR_IMAGE_TIMESTAMP:  5b94676d

IMAGE_VERSION:  6.1.7601.24260

FAILURE_BUCKET_ID:  X64_0xc2_7_dxgmms1!DXGFASTMUTEX::_scalar_deleting_destructor_+b6

BUCKET_ID:  X64_0xc2_7_dxgmms1!DXGFASTMUTEX::_scalar_deleting_destructor_+b6

PRIMARY_PROBLEM_CLASS:  X64_0xc2_7_dxgmms1!DXGFASTMUTEX::_scalar_deleting_destructor_+b6

TARGET_TIME:  2019-03-08T14:02:25.000Z

OSBUILD:  7601

OSSERVICEPACK:  1000

SERVICEPACK_NUMBER: 0

OS_REVISION: 0

SUITE_MASK:  272

PRODUCT_TYPE:  1

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 7

OSEDITION:  Windows 7 WinNt (Service Pack 1) TerminalServer SingleUserTS

OS_LOCALE:

USER_LCID:  0

OSBUILD_TIMESTAMP:  2019-02-09 00:52:23

BUILDDATESTAMP_STR:  190208-1418

BUILDLAB_STR:  win7sp1_ldr_escrow

BUILDOSVER_STR:  6.1.7601.24358.amd64fre.win7sp1_ldr_escrow.190208-1418

ANALYSIS_SESSION_ELAPSED_TIME: 1a17

ANALYSIS_SOURCE:  KM

FAILURE_ID_HASH_STRING:  km:x64_0xc2_7_dxgmms1!dxgfastmutex::_scalar_deleting_destructor_+b6

FAILURE_ID_HASH:  {df932a3d-4ce9-d5f9-8f20-2c86c0cc87d1}

Followup:     MachineOwner
---------

2: kd> !poolval fffffa80150d2430
Pool page fffffa80150d2430 region is Nonpaged pool

Validating Pool headers for pool page: fffffa80150d2430

Pool page [ fffffa80150d2000 ] is __inVALID.

Analyzing linked list...
[ fffffa80150d2000 ]: invalid block size [ 0x0 ] should be [ 0x14 ]
[ fffffa80150d22d0 --> fffffa80150d2470 (size = 0x1a0 bytes)]: Corrupt region


Scanning for single bit errors...

None found
 
Last edited:

Has Sysnative Forums helped you? Please consider donating to help us support the site!

Back
Top