William Palmer7 said:It's a bit tough to say for sure without seeing the symbols and the stack trace. If you're feeling up for a little technical deep dive, you could grab some Windows debugging tools and try running an analysis just like this was done here: https://www.instructables.com/How-to...OD-Crash-Dump/
I downloaded everything and followed the instructions exactly as they were laid out.
Here is one of the results I pulled. I have several more of these crash reports, but I’ll just share this one for now instead of copying everything over.
Windows Debugger version 10.0.19041.1 AMD64 copyright
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump file [C:\Windows\Minidump\103020-15968-01.dmp]
Mini kernel Dump file: I only have access to the registers and the stack trace.
************* Path validation summary **************
Response Time (ms) | Location
Deferred. SRV*C:\Windows\symbol_cache*
You can find the symbols at this link: http://msdl.microsoft.com/download/symbolsThe symbol search path is set to: SRV*C:\Windows\symbol_cache*
You can find the symbols here: http://msdl.microsoft.com/download/symbolsThe executable search path is:
Windows 10 kernel version 18362 MP (8 procs) Free x64
WinNt, suite: TerminalServer SingleUserTS Personal
Build version: 18362.1.amd64fre.19h1_release.190318-1202
Machine Name:
Kernel base is 0xfffff800`30200000 and the PsLoadedModuleList is 0xfffff800`306461b0.
Debug session started: Fri Oct 30 11:52:59.104 2020 (UTC - 5:00)
The system has been running for 15 days, 18 hours, 11 minutes, and 55 seconds.
Loading user Symbols Loading
.................................................. .............
.................................................. ..............
.................................................. ..............
.............................................
Loading user Symbols Loading
Loading unloaded module list
..................................................
To perform a full analysis of this file, please run !analyze -v
6: kd> !analyze -v
************************************************** *****************************
* *
* Bugcheck Analysis *
* *
************************************************** *****************************
The system hit a PAGE_FAULT_IN_NONPAGED_AREA error, specifically code 50. This usually points to an issue with memory or a driver trying to access a memory address that doesn't exist.
An invalid system memory reference occurred. This type of error can't be handled by a try-except block.
Usually, the address is either completely invalid or it's just pointing to memory that’s already been freed.
Arguments:
Arg1: ffff9589a20fdff0, memory referenced.
Arg2: 0000000000000002, where a value of 0 indicates a read operation and 1 signifies a write operation.
Arg3: fffff80048ed1a95. This represents the specific instruction address that attempted to access the faulty memory location, provided it isn't zero.
address.
Arg4: 0000000000000000, (reserved)
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for aswArPot.sys
The system was unable to identify the specific driver causing the crash.
KEY_VALUES_STRING: 1
SEC Value : 4 Key : analysis
SEC Value : 4 Key : analysis
CPP Value : Create
Value: Create: 8007007e on Mark Key
DebugData Value : CreateObject Key : analysis
Value: CreateObject
Key : Analysis.DebugModel
Value: CreateObject
Key : Analysis.Elapsed.Sec
Value: 30
Key : Analysis.Memory.CommitPeak.Mb
Value: 97
Key : Analysis.System
Value: CreateObject
BUGCHECK_CODE: 50
BUGCHECK_P1: ffff9589a20fdff0
BUGCHECK_P2: 2
BUGCHECK_P3: fffff80048ed1a95
BUGCHECK_P4: 0
READ_ADDRESS: fffff800307713b8: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
fffff800306283b8: Unable to get Flags value from nt!KdVersionBlock
fffff800306283b8: Unable to get Flags value from nt!KdVersionBlock
unable to get nt!MmSpecialPagesInUse
ffff9589a20fdff0
MM_INTERNAL_CODE: 0
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: EFRService.exe
TRAP_FRAME: ffffee837fb25160 -- (.trap 0xffffee837fb25160)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffff9589a20ff818 rbx=0000000000000000 rcx=ffff9589a20fdff0
rdx=00006a765fb5a700 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80048ed1a95 rsp=ffffee837fb252f8 rbp=ffffee837fb25560
r8=0000000000000010 r9=00000000000004c5 r10=000007ffb8d7cf30
r11=ffff9589a20f4760 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na po nc
aswArPot+0x21a95:
fffff800`48ed1a95 660f7f09 movdqa xmmword ptr [rcx],xmm1 ds:ffff9589`a20fdff0=????????????????????????????? ???
Resetting default scope
STACK_TEXT:
ffffee83`7fb24eb8 fffff800`3040842b : 00000000`00000050 ffff9589`a20fdff0 00000000`00000002 ffffee83`7fb25160 : nt!KeBugCheckEx
ffffee83`7fb24ec0 fffff800`3029559f : 00000000`00000114 00000000`00000002 00000000`00000000 ffff9589`a20fdff0 : nt!MiSystemFault+0x19df7b
ffffee83`7fb24fc0 fffff800`303d0d5e : fffff800`30670300 fffff800`3022d628 ffffda8f`5e572000 ffffee83`7fb25270 : nt!MmAccessFault+0x34f
ffffee83`7fb25160 fffff800`48ed1a95 : fffff800`48eba283 00000000`0237b090 ffffee83`7fb25560 00000000`00000237 : nt!KiPageFault+0x35e
ffffee83`7fb252f8 fffff800`48eba283 : 00000000`0237b090 ffffee83`7fb25560 00000000`00000237 ffffee83`00000000 : aswArPot+0x21a95
ffffee83`7fb25300 00000000`0237b090 : ffffee83`7fb25560 00000000`00000237 ffffee83`00000000 00000000`00000003 : aswArPot+0xa283
ffffee83`7fb25308 ffffee83`7fb25560 : 00000000`00000237 ffffee83`00000000 00000000`00000003 00000000`00000000 : 0x237b090
ffffee83`7fb25310 00000000`00000237 : ffffee83`00000000 00000000`00000003 00000000`00000000 ffff9589`a20f4760 : 0xffffee83`7fb25560
ffffee83`7fb25318 ffffee83`00000000 : 00000000`00000003 00000000`00000000 ffff9589`a20f4760 ffffeb75`80000070 : 0x237
ffffee83`7fb25320 00000000`00000003 : 00000000`00000000 ffff9589`a20f4760 ffffeb75`80000070 ffffeb75`bac00000 : 0xffffee83`00000000
ffffee83`7fb25328 00000000`00000000 : ffff9589`a20f4760 ffffeb75`80000070 ffffeb75`bac00000 ffffeb75`badd6000 : 0x3
SYMBOL_NAME: aswArPot+21a95
MODULE_NAME: aswArPot
IMAGE_NAME: aswArPot.sys
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: 21a95
FAILURE_BUCKET_ID: AV_INVALID_aswArPot!unknown_function
OS_VERSION: 10.0.18362.1
BUILDLAB_STR: 19h1_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {de4fbdf8-f109-a005-5489-cc580a726af4}
Followup: MachineOwner
---------