forked from killbug2004/CodeMachineCourse
-
Notifications
You must be signed in to change notification settings - Fork 3
/
Copy pathwindbg.day4.log
2716 lines (2244 loc) · 190 KB
/
windbg.day4.log
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
Opened log file 'c:\course\windbg.day4.log'
0: kd> !object \Objecttypes
Object: ffffc0013201bae0 Type: (ffffe000dd063e90) Directory
ObjectHeader: ffffc0013201bab0 (new version)
HandleCount: 0 PointerCount: 54
Directory Object: ffffc00132017160 Name: ObjectTypes
Hash Address Type Name
---- ------- ---- ----
00 ffffe000dd10a590 Type TmTm
01 ffffe000dd107b00 Type Desktop
ffffe000dd061f20 Type Process
03 ffffe000dd05c660 Type DebugObject
04 ffffe000ddbf69c0 Type DmaDomain
ffffe000dd108dc0 Type TpWorkerFactory
05 ffffe000dd109f20 Type Adapter
ffffe000dd05da40 Type Token
06 ffffe000de412940 Type DxgkSharedResource
08 ffffe000dea77980 Type NetworkNamespace
09 ffffe000de4c7d00 Type PcwObject
ffffe000dd170960 Type WmiGuid
11 ffffe000ddbf6b20 Type DmaAdapter
ffffe000dd1a7f20 Type EtwRegistration
12 ffffe000dd10ef20 Type Session
ffffe000dd108f20 Type RawInputManager
ffffe000dd106b40 Type Timer
13 ffffe000dd068be0 Type Mutant
14 ffffe000dd1069e0 Type IRTimer
16 ffffe000dd1099a0 Type IoCompletion
17 ffffe000de40fbb0 Type DxgkSharedSyncObject
ffffe000dd107c60 Type WindowStation
ffffe000dd107f20 Type Profile
18 ffffe000dd10af20 Type File
20 ffffe000dd10edc0 Type Partition
21 ffffe000dd106ca0 Type Semaphore
23 ffffe000dd1a7dc0 Type EtwConsumer
ffffe000dd1079a0 Type Composition
25 ffffe000dd10a430 Type TmTx
ffffe000dd05a5f0 Type SymbolicLink
26 ffffe000de5f1440 Type FilterConnectionPort
ffffe000dd117b70 Type Key
ffffe000dd107dc0 Type KeyedEvent
ffffe000dd068a80 Type Callback
27 ffffe000dd10a080 Type WaitCompletionPacket
28 ffffe000dd05c290 Type UserApcReserve
ffffe000dd059870 Type Job
29 ffffe000de40fa50 Type DxgkSharedSwapChainObject
ffffe000dd109dc0 Type Controller
ffffe000dd05c7c0 Type IoCompletionReserve
30 ffffe000dd109c60 Type Device
ffffe000dd063e90 Type Directory
31 ffffe000dd10baa0 Type Section
ffffe000dd10bf20 Type TmEn
ffffe000dd05c080 Type Thread
32 ffffe000dd0622a0 Type Type
33 ffffe000de5f12e0 Type FilterCommunicationPort
ffffe000dd1188c0 Type PowerRequest
35 ffffe000dd10a2d0 Type TmRm
ffffe000dd068d40 Type Event
36 ffffe000dd16aa20 Type ALPC Port
ffffe000dd109b00 Type Driver
0: kd> !object \FileSystem
Object: ffffc001320a2700 Type: (ffffe000dd063e90) Directory
ObjectHeader: ffffc001320a26d0 (new version)
HandleCount: 0 PointerCount: 33
Directory Object: ffffc00132017160 Name: FileSystem
Hash Address Type Name
---- ------- ---- ----
02 ffffe000dff923a0 Driver mrxsmb10
ffffe000dfdf6cf0 Driver mrxsmb
03 ffffe000dfdf7b80 Driver mrxsmb20
ffffe000dfccb9d0 Driver storqosflt
04 ffffe000dfcaba50 Driver luafv
ffffe000de5ff080 Driver Wof
11 ffffe000dece6230 Driver rdbss
ffffe000dea75570 Device CdfsRecognizer
12 ffffe000dea75c00 Device UdfsDiskRecognizer
ffffe000dea5f170 Driver Fs_Rec
13 Unable to read directory entry at ffffc00132170ae0
15 ffffe000de41be60 Driver Dfsc
17 ffffe000dff69cf0 Driver srvnet
19 ffffe000dffa9080 Driver srv
ffffc001320b0650 Directory Filters
21 ffffe000dfdee100 Driver bowser
ffffe000de5f1e60 Driver FltMgr
22 ffffe000dea759d0 Device FatCdRomRecognizer
23 ffffe000dea05910 Driver NTFS
24 ffffe000de40e3c0 Driver Npfs
ffffe000deb2b610 Driver Mup
ffffe000de4bb8a0 Driver RAW
25 ffffe000dea75060 Device ReFSRecognizer
ffffe000dea00600 Driver WdFilter
28 ffffe000de5fee60 Driver FileInfo
31 ffffe000dea74900 Device FatDiskRecognizer
32 ffffe000dea75e30 Device ReFSv1Recognizer
33 ffffe000dff60600 Driver srv2
ffffe000ded02370 Driver NetBIOS
ffffe000de403e60 Driver FileCrypt
ffffe000dea746d0 Device ExFatRecognizer
35 ffffe000dea757a0 Device UdfsCdRomRecognizer
0: kd> !object \FileSystem\Filters
Object: ffffc001320b0650 Type: (ffffe000dd063e90) Directory
ObjectHeader: ffffc001320b0620 (new version)
HandleCount: 0 PointerCount: 3
Directory Object: ffffc001320a2700 Name: Filters
Hash Address Type Name
---- ------- ---- ----
19 ffffe000de5f2060 Device FltMgrMsg
21 ffffe000de5f1980 Device FltMgr
0: kd> !process 0 0 cmd.exe
0: kd> g
shell\ext\inputswitch\switch\ctfhandler.cpp(1976)\InputSwitch.dll!00007FFC5C322993: (caller: 00007FFC604DD533) LogHr(1) tid(4fc) 80004005 Unspecified error
CallContext:[\Startup]
shell\roaming\settingsync\settingprofilehandler.cpp(85)\SettingSync.dll!00007FFC5459D02E: (caller: 00007FFC5990BA23) LogHr(1) tid(530) 80070002 The system cannot find the file specified.
shell\roaming\settingsync\settingprofilehandler.cpp(24)\SettingSync.dll!00007FFC54593CBC: (caller: 00007FFC5990BA23) LogHr(2) tid(530) 800704EC This program is blocked by group policy. For more information, contact your system administrator.
base\appmodel\execmodel\modern\lifetimemanager\deskstartupmgr.cpp(52)\modernexecserver.dll!00007FFC53BA8CCC: (caller: 00007FFC53BA8D9B) ReturnHr[PreRelease](1) tid(af4) 80070002 The system cannot find the file specified.
base\diagnosis\diagtrack\engine\settingsmanager.cpp(589)\diagtrack.dll!00007FFC533BFFB3: (caller: 00007FFC533BF9A6) ReturnHr[PreRelease](116) tid(a08) 80070002 The system cannot find the file specified.
base\diagnosis\diagtrack\engine\settingsmanager.cpp(507)\diagtrack.dll!00007FFC533BFC2B: (caller: 00007FFC533BF6ED) LogHr(19) tid(a08) 80070002 The system cannot find the file specified.
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](117) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](118) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](119) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](120) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](121) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](122) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](123) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](124) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](125) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](126) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](127) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](128) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](129) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](130) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](131) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](132) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](133) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](134) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](135) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](136) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](137) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](138) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](139) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](140) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](141) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](142) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](143) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](144) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](145) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](146) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](147) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](148) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](149) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](150) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](151) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](152) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](153) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](154) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](155) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](156) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](157) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](158) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](159) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](160) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](161) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](162) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](163) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](164) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](165) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](166) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](167) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](168) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](169) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](170) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](171) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](172) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](173) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](174) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](175) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](176) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](177) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](178) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](179) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](180) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](181) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](182) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](183) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](184) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](185) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](186) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](187) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](188) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](189) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](190) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](191) tid(a08) 800401F3 Invalid class string
base\diagnosis\diagtrack\include\Utils.h(2581)\diagtrack.dll!00007FFC53371784: (caller: 00007FFC533A83EC) ReturnHr[PreRelease](192) tid(a08) 800401F3 Invalid class string
base\appmodel\execmodel\modern\policies\preinstalltaskpolicy\preinstalltaskutils.cpp(162)\ACPBackgroundManagerPolicy.dll!00007FFC53064C0B: (caller: 00007FFC530647E3) ReturnHr[PreRelease](1) tid(c84) 80070002 The system cannot find the file specified.
base\appmodel\execmodel\modern\policies\preinstalltaskpolicy\preinstalltaskutils.cpp(248)\ACPBackgroundManagerPolicy.dll!00007FFC53064AD4: (caller: 00007FFC530664A3) ReturnHr[PreRelease](2) tid(c84) 80070002 The system cannot find the file specified.
base\appmodel\execmodel\modern\lifetimemanager\plmlegacy.cpp(174)\modernexecserver.dll!00007FFC53B783C0: (caller: 00007FFC604DD533) ReturnHr[PreRelease](2) tid(c68) 8002802B Element not found.
base\appmodel\execmodel\modern\lifetimemanager\plmlegacy.cpp(174)\modernexecserver.dll!00007FFC53B783C0: (caller: 00007FFC604DD533) ReturnHr[PreRelease](3) tid(c68) 8002802B Element not found.
base\appmodel\execmodel\shared\resourcetimers\lib\applicationdata.cpp(197)\modernexecserver.dll!00007FFC53B9D2C4: (caller: 00007FFC53B9B4AA) ReturnHr[PreRelease](4) tid(c98) 80070002 The system cannot find the file specified.
base\appmodel\execmodel\shared\resourcetimers\lib\applicationdata.cpp(197)\modernexecserver.dll!00007FFC53B9D2C4: (caller: 00007FFC53B9AD06) ReturnHr[PreRelease](5) tid(c68) 80070002 The system cannot find the file specified.
base\appmodel\execmodel\shared\resourcetimers\lib\applicationdata.cpp(197)\modernexecserver.dll!00007FFC53B9D2C4: (caller: 00007FFC53B9AD06) ReturnHr[PreRelease](6) tid(c68) 80070002 The system cannot find the file specified.
base\appmodel\execmodel\shared\resourcetimers\lib\applicationdata.cpp(197)\modernexecserver.dll!00007FFC53B9D2C4: (caller: 00007FFC53B9AD06) ReturnHr[PreRelease](7) tid(c68) 80070002 The system cannot find the file specified.
base\appmodel\execmodel\shared\resourcetimers\lib\applicationdata.cpp(197)\modernexecserver.dll!00007FFC53B9D2C4: (caller: 00007FFC53B9AD06) ReturnHr[PreRelease](8) tid(c68) 80070002 The system cannot find the file specified.
shell\ext\thumbnailcache\lib\thumbcacheapi.cpp(243)\thumbcache.dll!00007FFC4E1C32DC: (caller: 00007FFC4E1C34FF) ReturnHr[PreRelease](1) tid(e9c) 8004B200 base\appmodel\execmodel\shared\resourcetimers\lib\applicationdata.cpp(197)\modernexecserver.dll!00007FFC53B9D2C4: (caller: 00007FFC53B9B4AA) ReturnHr[PreRelease](9) tid(c98) 80070002 The system cannot find the file specified.
base\appmodel\execmodel\shared\resourcetimers\lib\applicationdata.cpp(197)\modernexecserver.dll!00007FFC53B9D2C4: (caller: 00007FFC53B9AD06) ReturnHr[PreRelease](10) tid(ef0) 80070002 The system cannot find the file specified.
base\appmodel\execmodel\shared\resourcetimers\lib\applicationdata.cpp(197)\modernexecserver.dll!00007FFC53B9D2C4: (caller: 00007FFC53B9AD06) ReturnHr[PreRelease](11) tid(ef0) 80070002 The system cannot find the file specified.
base\appmodel\execmodel\shared\resourcetimers\lib\applicationdata.cpp(197)\modernexecserver.dll!00007FFC53B9D2C4: (caller: 00007FFC53B9AD06) ReturnHr[PreRelease](12) tid(ef0) 80070002 The system cannot find the file specified.
base\appmodel\execmodel\shared\resourcetimers\lib\applicationdata.cpp(197)\modernexecserver.dll!00007FFC53B9D2C4: (caller: 00007FFC53B9AD06) ReturnHr[PreRelease](13) tid(ef0) 80070002 The system cannot find the file specified.
base\appmodel\execmodel\shared\resourcetimers\lib\applicationdata.cpp(197)\modernexecserver.dll!00007FFC53B9D2C4: (caller: 00007FFC53B9AD06) ReturnHr[PreRelease](14) tid(ef0) 80070002 The system cannot find the file specified.
StartUI.LauncherFrame
shell\ext\inputswitch\switch\ctfhandler.cpp(1976)\InputSwitch.dll!00007FFC5C322993: (caller: 00007FF693676D86) LogHr(1) tid(dc8) 80004005 Unspecified error
CallContext:[\Startup]
shell\ext\thumbnailcache\lib\thumbcacheapi.cpp(243)\thumbcache.dll!00007FFC4E1C32DC: (caller: 00007FFC4E1C34FF) ReturnHr[PreRelease](2) tid(e9c) 8004B200 base\appmodel\appcontracts\lib\backgroundcontractstore.cpp(32)\AppContracts.dll!00007FFC53097C7A: (caller: 00007FFC604DD533) ReturnHr[PreRelease](1) tid(c60) 80070002 The system cannot find the file specified.
base\appmodel\execmodel\modern\lifetimemanager\plmutil.cpp(281)\modernexecserver.dll!00007FFC53B76FC4: (caller: 00007FFC53B98CFA) ReturnHr[PreRelease](15) tid(cac) 80070002 The system cannot find the file specified.
Break instruction exception - code 80000003 (first chance)
*******************************************************************************
* *
* You are seeing this message because you pressed either *
* CTRL+C (if you run console kernel debugger) or, *
* CTRL+BREAK (if you run GUI kernel debugger), *
* on your debugger machine's keyboard. *
* *
* THIS IS NOT A BUG OR A SYSTEM CRASH *
* *
* If you did not intend to break into the debugger, press the "g" key, then *
* press the "Enter" key now. This message might immediately reappear. If it *
* does, press "g" and "Enter" again. *
* *
*******************************************************************************
nt!DbgBreakPointWithStatus:
fffff803`f0dbb6d0 cc int 3
1: kd> !process 0 0 cmd.exe
PROCESS ffffe000de390200
SessionId: 2 Cid: 10b8 Peb: 784be03000 ParentCid: 0d4c
DirBase: 14ae3000 ObjectTable: ffffc00134ae3c40 HandleCount: <Data Not Accessible>
Image: cmd.exe
1: kd> !handle 0 3 ffffe000de390200
PROCESS ffffe000de390200
SessionId: 2 Cid: 10b8 Peb: 784be03000 ParentCid: 0d4c
DirBase: 14ae3000 ObjectTable: ffffc00134ae3c40 HandleCount: <Data Not Accessible>
Image: cmd.exe
Handle Error reading handle count.
0004: Object: ffffc001320ec4e0 GrantedAccess: 00000003 (Protected) (Inherit) Entry: ffffc00133d70010
Object: ffffc001320ec4e0 Type: (ffffe000dd063e90) Directory
ObjectHeader: ffffc001320ec4b0 (new version)
HandleCount: 46 PointerCount: 1504810
Directory Object: ffffc00132017160 Name: KnownDlls
Hash Address Type Name
---- ------- ---- ----
00 ffffc00132aa9f00 Section kernel32.dll
01 ffffc00137a66c40 Section kernel.appcore.dll
ffffc00137a64ef0 Section windows.storage.dll
02 ffffc00137a21fc0 Section MSCTF.dll
ffffc00132aa92c0 Section WS2_32.dll
ffffc00137a06660 Section SHLWAPI.dll
03 ffffc00137a69fc0 Section kernelbase.dll
04 ffffc00132f4f7b0 Section Wow64.dll
05 ffffc00137a33c60 Section gdiplus.dll
ffffc001320ec160 SymbolicLink KnownDllPath
06 ffffc00137a52610 Section MSASN1.dll
ffffc00137a24c10 Section user32.dll
10 ffffc00137a50240 Section COMCTL32.dll
11 ffffc00137a64970 Section cfgmgr32.dll
12 ffffc00137a2e790 Section IMM32.dll
ffffc00132f50ad0 Section combase.dll
13 ffffc001320ed4e0 Section rpcrt4.dll
14 ffffc00137a45f00 Section ntdll.dll
ffffc00137a45fc0 Section bcryptPrimitives.dll
ffffc00137a33250 Section coml2.dll
17 ffffc00137a34400 Section Wow64cpu.dll
18 ffffc00132134320 Section COMDLG32.dll
19 ffffc00137a1a080 Section IMAGEHLP.dll
20 ffffc00137a3aef0 Section SHELL32.dll
21 ffffc00137a2ddc0 Section sechost.dll
22 ffffc00137a45220 Section WINTRUST.dll
24 ffffc00137a2d620 Section LPK.dll
ffffc00132aa94c0 Section NORMALIZ.dll
25 ffffc00132763fc0 Section difxapi.dll
26 ffffc00137a521d0 Section profapi.dll
ffffc00137a4fa40 Section Setupapi.dll
27 ffffc00137a4eef0 Section CRYPT32.dll
28 ffffc00137a4d590 Section FirewallAPI.dll
ffffc00137a23350 Section gdi32.dll
ffffc00132f4fdb0 Section MSVCRT.dll
29 ffffc00137a4dfc0 Section NETAPI32.dll
ffffc00132f4edb0 Section advapi32.dll
ffffc001338a7580 Section Wow64win.dll
30 ffffc00137a33810 Section PSAPI.DLL
ffffc00137a06be0 Section NSI.dll
31 ffffc00137a1f230 Section WLDAP32.dll
ffffc00137a08420 Section OLEAUT32.dll
33 ffffc00137a51ef0 Section shcore.dll
34 ffffc00132f505a0 Section ole32.dll
35 ffffc00132f4fbb0 Section clbcatq.dll
36 ffffc00137a657e0 Section powrprof.dll
0008: Object: ffffe000de940550 GrantedAccess: 001f0003 (Inherit) Entry: ffffc00133d70020
Object: ffffe000de940550 Type: (ffffe000dd068d40) Event
ObjectHeader: ffffe000de940520 (new version)
HandleCount: 1 PointerCount: 32764
000c: Object: ffffe000de73b5c0 GrantedAccess: 001f0003 (Protected) Entry: ffffc00133d70030
Object: ffffe000de73b5c0 Type: (ffffe000dd068d40) Event
ObjectHeader: ffffe000de73b590 (new version)
HandleCount: 1 PointerCount: 32766
0010: Object: ffffe000dfba7f20 GrantedAccess: 00100020 (Protected) (Inherit) (Audit) Entry: ffffc00133d70040
Object: ffffe000dfba7f20 Type: (ffffe000dd10af20) File
ObjectHeader: ffffe000dfba7ef0 (new version)
HandleCount: 1 PointerCount: 32768
Directory Object: 00000000 Name: \Windows\System32 {HarddiskVolume2}
0014: Object: ffffe000ddcac0b0 GrantedAccess: 00120089 Entry: ffffc00133d70050
Object: ffffe000ddcac0b0 Type: (ffffe000dd10af20) File
ObjectHeader: ffffe000ddcac080 (new version)
HandleCount: 1 PointerCount: 32768
Directory Object: 00000000 Name: \Windows\System32\en-US\cmd.exe.mui {HarddiskVolume2}
0018: Object: ffffe000ddf260b0 GrantedAccess: 0012019f Entry: ffffc00133d70060
Object: ffffe000ddf260b0 Type: (ffffe000dd10af20) File
ObjectHeader: ffffe000ddf26080 (new version)
HandleCount: 1 PointerCount: 32768
Directory Object: 00000000 Name: \Reference {ConDrv}
001c: Object: ffffe000de981e20 GrantedAccess: 001f0001 (Protected) (Inherit) (Audit) Entry: ffffc00133d70070
Object: ffffe000de981e20 Type: (ffffe000dd16aa20) ALPC Port
ObjectHeader: ffffe000de981df0 (new version)
HandleCount: 1 PointerCount: 32770
0020: Object: ffffe000ddf2af20 GrantedAccess: 0012019f (Protected) (Inherit) (Audit) Entry: ffffc00133d70080
Object: ffffe000ddf2af20 Type: (ffffe000dd10af20) File
ObjectHeader: ffffe000ddf2aef0 (new version)
HandleCount: 1 PointerCount: 32710
Directory Object: 00000000 Name: \Connect {ConDrv}
0024: Object: ffffe000dfe8b310 GrantedAccess: 0012019f (Inherit) (Audit) Entry: ffffc00133d70090
Object: ffffe000dfe8b310 Type: (ffffe000dd10af20) File
ObjectHeader: ffffe000dfe8b2e0 (new version)
HandleCount: 1 PointerCount: 32760
Directory Object: 00000000 Name: \Input {ConDrv}
0028: Object: ffffe000de47ff20 GrantedAccess: 0012019f (Protected) (Inherit) (Audit) Entry: ffffc00133d700a0
Object: ffffe000de47ff20 Type: (ffffe000dd10af20) File
ObjectHeader: ffffe000de47fef0 (new version)
HandleCount: 2 PointerCount: 65507
Directory Object: 00000000 Name: \Output {ConDrv}
002c: Object: ffffe000de47ff20 GrantedAccess: 0012019f (Protected) (Inherit) (Audit) Entry: ffffc00133d700b0
Object: ffffe000de47ff20 Type: (ffffe000dd10af20) File
ObjectHeader: ffffe000de47fef0 (new version)
HandleCount: 2 PointerCount: 65507
Directory Object: 00000000 Name: \Output {ConDrv}
0030: Object: ffffe000deb676a0 GrantedAccess: 001f0003 (Protected) (Inherit) (Audit) Entry: ffffc00133d700c0
Object: ffffe000deb676a0 Type: (ffffe000dd068d40) Event
ObjectHeader: ffffe000deb67670 (new version)
HandleCount: 1 PointerCount: 32769
0034: Object: ffffe000ddd45f90 GrantedAccess: 00000001 (Inherit) (Audit) Entry: ffffc00133d700d0
Object: ffffe000ddd45f90 Type: (ffffe000dd10a080) WaitCompletionPacket
ObjectHeader: ffffe000ddd45f60 (new version)
HandleCount: 1 PointerCount: 32769
0038: Object: ffffe000dde1bf80 GrantedAccess: 001f0003 (Protected) (Audit) Entry: ffffc00133d700e0
Object: ffffe000dde1bf80 Type: (ffffe000dd1099a0) IoCompletion
ObjectHeader: ffffe000dde1bf50 (new version)
HandleCount: 1 PointerCount: 32769
003c: Object: ffffe000ddf76540 GrantedAccess: 000f00ff (Protected) Entry: ffffc00133d700f0
Object: ffffe000ddf76540 Type: (ffffe000dd108dc0) TpWorkerFactory
ObjectHeader: ffffe000ddf76510 (new version)
HandleCount: 1 PointerCount: 32768
0040: Object: ffffe000ddd0ebd0 GrantedAccess: 00100002 (Inherit) Entry: ffffc00133d70100
Object: ffffe000ddd0ebd0 Type: (ffffe000dd1069e0) IRTimer
ObjectHeader: ffffe000ddd0eba0 (new version)
HandleCount: 1 PointerCount: 32769
0044: Object: ffffe000df6712a0 GrantedAccess: 00000001 (Protected) (Inherit) (Audit) Entry: ffffc00133d70110
Object: ffffe000df6712a0 Type: (ffffe000dd10a080) WaitCompletionPacket
ObjectHeader: ffffe000df671270 (new version)
HandleCount: 1 PointerCount: 32769
0048: Object: ffffe000dded9060 GrantedAccess: 00100002 (Protected) (Inherit) Entry: ffffc00133d70120
Object: ffffe000dded9060 Type: (ffffe000dd1069e0) IRTimer
ObjectHeader: ffffe000dded9030 (new version)
HandleCount: 1 PointerCount: 32769
004c: Object: ffffe000dec2abb0 GrantedAccess: 00000001 Entry: ffffc00133d70130
Object: ffffe000dec2abb0 Type: (ffffe000dd10a080) WaitCompletionPacket
ObjectHeader: ffffe000dec2ab80 (new version)
HandleCount: 1 PointerCount: 32769
0050: Object: ffffe000ddcb9540 GrantedAccess: 00000804 (Protected) Entry: ffffc00133d70140
Object: ffffe000ddcb9540 Type: (ffffe000dd1a7f20) EtwRegistration
ObjectHeader: ffffe000ddcb9510 (new version)
HandleCount: 1 PointerCount: 32768
0054: Object: ffffe000de370bc0 GrantedAccess: 001f0003 (Protected) Entry: ffffc00133d70150
Object: ffffe000de370bc0 Type: (ffffe000dd1099a0) IoCompletion
ObjectHeader: ffffe000de370b90 (new version)
HandleCount: 1 PointerCount: 32769
0058: Object: ffffe000ddd9d290 GrantedAccess: 000f00ff (Inherit) (Audit) Entry: ffffc00133d70160
Object: ffffe000ddd9d290 Type: (ffffe000dd108dc0) TpWorkerFactory
ObjectHeader: ffffe000ddd9d260 (new version)
HandleCount: 1 PointerCount: 32762
005c: Object: ffffe000ddc4e7f0 GrantedAccess: 00100002 (Audit) Entry: ffffc00133d70170
Object: ffffe000ddc4e7f0 Type: (ffffe000dd1069e0) IRTimer
ObjectHeader: ffffe000ddc4e7c0 (new version)
HandleCount: 1 PointerCount: 32769
0060: Object: ffffe000dfcd5670 GrantedAccess: 00000001 (Audit) Entry: ffffc00133d70180
Object: ffffe000dfcd5670 Type: (ffffe000dd10a080) WaitCompletionPacket
ObjectHeader: ffffe000dfcd5640 (new version)
HandleCount: 1 PointerCount: 32769
0064: Object: ffffe000e0118d10 GrantedAccess: 00100002 (Inherit) (Audit) Entry: ffffc00133d70190
Object: ffffe000e0118d10 Type: (ffffe000dd1069e0) IRTimer
ObjectHeader: ffffe000e0118ce0 (new version)
HandleCount: 1 PointerCount: 32769
0068: Object: ffffe000df76a270 GrantedAccess: 00000001 (Audit) Entry: ffffc00133d701a0
Object: ffffe000df76a270 Type: (ffffe000dd10a080) WaitCompletionPacket
ObjectHeader: ffffe000df76a240 (new version)
HandleCount: 1 PointerCount: 32769
006c: Object: ffffc001353811d0 GrantedAccess: 00020019 (Inherit) Entry: ffffc00133d701b0
Object: ffffc001353811d0 Type: (ffffe000dd117b70) Key
ObjectHeader: ffffc001353811a0 (new version)
HandleCount: 1 PointerCount: 32767
Directory Object: 00000000 Name: \REGISTRY\MACHINE\SYSTEM\CONTROLSET001\CONTROL\NLS\SORTING\VERSIONS
0070: Object: ffffe000e0d03840 GrantedAccess: 001fffff (Protected) Entry: ffffc00133d701c0
Object: ffffe000e0d03840 Type: (ffffe000dd05c080) Thread
ObjectHeader: ffffe000e0d03810 (new version)
HandleCount: 2 PointerCount: 65531
0074: Object: ffffc001343167e0 GrantedAccess: 000f003f (Protected) (Inherit) Entry: ffffc00133d701d0
Object: ffffc001343167e0 Type: (ffffe000dd117b70) Key
ObjectHeader: ffffc001343167b0 (new version)
HandleCount: 1 PointerCount: 32765
Directory Object: 00000000 Name: \REGISTRY\USER\S-1-5-21-2257097422-1553991371-2697796969-1001
0078: Object: ffffc0013af4e3e0 GrantedAccess: 000f003f (Protected) (Inherit) Entry: ffffc00133d701e0
Object: ffffc0013af4e3e0 Type: (ffffe000dd117b70) Key
ObjectHeader: ffffc0013af4e3b0 (new version)
HandleCount: 1 PointerCount: 32767
Directory Object: 00000000 Name: \REGISTRY\MACHINE
007c: Object: ffffc00134a38990 GrantedAccess: 00020019 (Inherit) (Audit) Entry: ffffc00133d701f0
Object: ffffc00134a38990 Type: (ffffe000dd117b70) Key
ObjectHeader: ffffc00134a38960 (new version)
HandleCount: 1 PointerCount: 32768
Directory Object: 00000000 Name: \REGISTRY\MACHINE\SYSTEM\CONTROLSET001\CONTROL\NLS\LOCALE
0080: Object: ffffc00134658390 GrantedAccess: 00020019 (Inherit) (Audit) Entry: ffffc00133d70200
Object: ffffc00134658390 Type: (ffffe000dd117b70) Key
ObjectHeader: ffffc00134658360 (new version)
HandleCount: 1 PointerCount: 1
Directory Object: 00000000 Name: \REGISTRY\MACHINE\SYSTEM\CONTROLSET001\CONTROL\NLS\LOCALE\ALTERNATE SORTS
0084: Object: ffffc001349801d0 GrantedAccess: 00020019 (Inherit) Entry: ffffc00133d70210
Object: ffffc001349801d0 Type: (ffffe000dd117b70) Key
ObjectHeader: ffffc001349801a0 (new version)
HandleCount: 1 PointerCount: 32768
Directory Object: 00000000 Name: \REGISTRY\MACHINE\SYSTEM\CONTROLSET001\CONTROL\NLS\LANGUAGE GROUPS
0088: Object: ffffe000de2659e0 GrantedAccess: 00000804 (Protected) (Inherit) Entry: ffffc00133d70220
Object: ffffe000de2659e0 Type: (ffffe000dd1a7f20) EtwRegistration
ObjectHeader: ffffe000de2659b0 (new version)
HandleCount: 1 PointerCount: 1
008c: Object: ffffc001346ef9f0 GrantedAccess: 00000001 (Audit) Entry: ffffc00133d70230
Object: ffffc001346ef9f0 Type: (ffffe000dd117b70) Key
ObjectHeader: ffffc001346ef9c0 (new version)
HandleCount: 1 PointerCount: 32768
Directory Object: 00000000 Name: \REGISTRY\MACHINE\SYSTEM\CONTROLSET001\CONTROL\SESSION MANAGER
0090: Object: ffffc001351f88b0 GrantedAccess: 00020019 Entry: ffffc00133d70240
Object: ffffc001351f88b0 Type: (ffffe000dd117b70) Key
ObjectHeader: ffffc001351f8880 (new version)
HandleCount: 1 PointerCount: 32767
Directory Object: 00000000 Name: \REGISTRY\MACHINE\SYSTEM\CONTROLSET001\CONTROL\NLS\SORTING\IDS
1: kd> .logfile
Log 'c:\course\windbg.day4.log' open
1: kd> !drvobj i8042prt
Driver object (ffffe000ded99080) is for:
\Driver\i8042prt
Driver Extension List: (id , addr)
Device Object list:
ffffe000ded9e810 ffffe000ded9a780
1: kd> !devobj ffffe000ded9e810
Device object (ffffe000ded9e810) is for:
\Driver\i8042prt DriverObject ffffe000ded99080
Current Irp 00000000 RefCount 0 Type 00000027 Flags 00002004
Dacl ffffc1023210f411 DevExt ffffe000ded9e960 DevObjExt ffffe000ded9edb8
ExtensionFlags (0x30000800) DOE_DEFAULT_SD_PRESENT, DOE_RAW_FDO
Unknown flags 0x10000000
Characteristics (0000000000)
AttachedDevice (Upper) ffffe000ded9e4b0 \Driver\mouclass
AttachedTo (Lower) ffffe000dd020bb0 \Driver\ACPI
Device queue is not busy.
1: kd> !devobj ffffe000ded9a780
Device object (ffffe000ded9a780) is for:
\Driver\i8042prt DriverObject ffffe000ded99080
Current Irp 00000000 RefCount 0 Type 00000027 Flags 00002004
Dacl ffffc1023210f411 DevExt ffffe000ded9a8d0 DevObjExt ffffe000ded9ad28
ExtensionFlags (0x30000800) DOE_DEFAULT_SD_PRESENT, DOE_RAW_FDO
Unknown flags 0x10000000
Characteristics (0000000000)
AttachedDevice (Upper) ffffe000ded9a400 \Driver\kbdclass
AttachedTo (Lower) ffffe000dd020e40 \Driver\ACPI
Device queue is not busy.
1: kd> !drvobj \Driver\kbdclass
Driver object (ffffe000ded9a080) is for:
\Driver\kbdclass
Driver Extension List: (id , addr)
Device Object list:
ffffe000dfa59890 ffffe000dedb9690 ffffe000ded9a400
1: kd> !devobj ffffe000dfa59890
Device object (ffffe000dfa59890) is for:
KeyboardClass2 \Driver\kbdclass DriverObject ffffe000ded9a080
Current Irp 00000000 RefCount 0 Type 0000000b Flags 00002044
Dacl ffffc1023210f411 DevExt ffffe000dfa599e0 DevObjExt ffffe000dfa59b60
ExtensionFlags (0x00000c00) DOE_SESSION_DEVICE, DOE_DEFAULT_SD_PRESENT
Characteristics (0x00000100) FILE_DEVICE_SECURE_OPEN
AttachedTo (Lower) ffffe000de212630 \Driver\terminpt
Device queue is not busy.
1: kd> !devobj ffffe000dedb9690
Device object (ffffe000dedb9690) is for:
KeyboardClass1 \Driver\kbdclass DriverObject ffffe000ded9a080
Current Irp 00000000 RefCount 0 Type 0000000b Flags 00002044
Dacl ffffc1023210f411 DevExt ffffe000dedb97e0 DevObjExt ffffe000dedb9960
ExtensionFlags (0x00000800) DOE_DEFAULT_SD_PRESENT
Characteristics (0x00000100) FILE_DEVICE_SECURE_OPEN
AttachedTo (Lower) ffffe000dedb7d60 \Driver\hyperkbd
Device queue is not busy.
1: kd> !devobj ffffe000ded9a400
Device object (ffffe000ded9a400) is for:
KeyboardClass0 \Driver\kbdclass DriverObject ffffe000ded9a080
Current Irp 00000000 RefCount 0 Type 0000000b Flags 00002044
Dacl ffffc1023210f411 DevExt ffffe000ded9a550 DevObjExt ffffe000ded9a6d0
ExtensionFlags (0x00000800) DOE_DEFAULT_SD_PRESENT
Characteristics (0000000000)
AttachedTo (Lower) ffffe000ded9a780 \Driver\i8042prt
Device queue is not busy.
1: kd> !process 0 0 winlogon.exe
PROCESS ffffe000df68e080
SessionId: 1 Cid: 022c Peb: 50ea522000 ParentCid: 01f0
DirBase: 0b681000 ObjectTable: ffffc0013ae982c0 HandleCount: <Data Not Accessible>
Image: winlogon.exe
PROCESS ffffe000de1f2080
SessionId: 2 Cid: 09b0 Peb: 87fecf2000 ParentCid: 09d4
DirBase: 1ffd2000 ObjectTable: ffffc00133eb8040 HandleCount: <Data Not Accessible>
Image: winlogon.exe
1: kd> .process /i ffffe000df68e080
You need to continue execution (press 'g' <enter>) for the context
to be switched. When the debugger breaks in again, you will be in
the new process context.
1: kd> g
Break instruction exception - code 80000003 (first chance)
nt!DbgBreakPointWithStatus:
fffff803`f0dbb6d0 cc int 3
0: kd> !process
PROCESS ffffe000df68e080
SessionId: 1 Cid: 022c Peb: 50ea522000 ParentCid: 01f0
DirBase: 0b681000 ObjectTable: ffffc0013ae982c0 HandleCount: <Data Not Accessible>
Image: winlogon.exe
VadRoot ffffe000df764c70 Vads 56 Clone 0 Private 228. Modified 427. Locked 0.
DeviceMap ffffc0013201b770
Token ffffc0013af26b30
ElapsedTime 02:25:18.243
UserTime 00:00:00.000
KernelTime 00:00:00.031
QuotaPoolUsage[PagedPool] 119848
QuotaPoolUsage[NonPagedPool] 7800
Working Set Sizes (now,min,max) (1141, 50, 345) (4564KB, 200KB, 1380KB)
PeakWorkingSetSize 2068
VirtualSize 2097206 Mb
PeakVirtualSize 2097208 Mb
PageFaultCount 2988
MemoryPriority BACKGROUND
BasePriority 13
CommitCharge 466
THREAD ffffe000df690080 Cid 022c.0230 Teb: 00000050ea523000 Win32Thread: ffffe000df775c80 WAIT: (UserRequest) UserMode Non-Alertable
ffffe000df957c80 SynchronizationEvent
THREAD ffffe000decf6040 Cid 022c.0248 Teb: 00000050ea529000 Win32Thread: ffffe000df7d1bf0 WAIT: (WrQueue) UserMode Alertable
ffffe000df690ec0 QueueObject
THREAD ffffe000df94e080 Cid 022c.0394 Teb: 00000050ea52f000 Win32Thread: ffffe000df7e4740 WAIT: (WrLpcReply) UserMode Non-Alertable
ffffe000df94e6b8 Semaphore Limit 0x1
THREAD ffffe000de7ef840 Cid 022c.0c94 Teb: 00000050ea533000 Win32Thread: 0000000000000000 WAIT: (WrQueue) UserMode Alertable
ffffe000df690ec0 QueueObject
0: kd> !handle 0 3 ffffe000df68e080 File
Searching for handles of type File
PROCESS ffffe000df68e080
SessionId: 1 Cid: 022c Peb: 50ea522000 ParentCid: 01f0
DirBase: 0b681000 ObjectTable: ffffc0013ae982c0 HandleCount: <Data Not Accessible>
Image: winlogon.exe
Handle Error reading handle count.
0010: Object: ffffe000df5c2310 GrantedAccess: 00100020 (Inherit) (Audit) Entry: ffffc0013af25040
Object: ffffe000df5c2310 Type: (ffffe000dd10af20) File
ObjectHeader: ffffe000df5c22e0 (new version)
HandleCount: 1 PointerCount: 32768
Directory Object: 00000000 Name: \Windows\System32 {HarddiskVolume2}
0074: Object: ffffe000df69aea0 GrantedAccess: 00100003 (Protected) (Inherit) (Audit) Entry: ffffc0013af251d0
Object: ffffe000df69aea0 Type: (ffffe000dd10af20) File
ObjectHeader: ffffe000df69ae70 (new version)
HandleCount: 1 PointerCount: 32768
0104: Object: ffffe000df5935f0 GrantedAccess: 00120089 (Audit) Entry: ffffc0013af25410
Object: ffffe000df5935f0 Type: (ffffe000dd10af20) File
ObjectHeader: ffffe000df5935c0 (new version)
HandleCount: 1 PointerCount: 32768
Directory Object: 00000000 Name: \Windows\System32\en-US\user32.dll.mui {HarddiskVolume2}
0148: Object: ffffe000df91b3f0 GrantedAccess: 00100001 (Audit) Entry: ffffc0013af25520
Object: ffffe000df91b3f0 Type: (ffffe000dd10af20) File
ObjectHeader: ffffe000df91b3c0 (new version)
HandleCount: 1 PointerCount: 32768
01a4: Object: ffffe000decbd660 GrantedAccess: 00100001 (Protected) (Inherit) Entry: ffffc0013af25690
Object: ffffe000decbd660 Type: (ffffe000dd10af20) File
ObjectHeader: ffffe000decbd630 (new version)
HandleCount: 1 PointerCount: 32768
01e4: Object: ffffe000df9e4430 GrantedAccess: 00120089 Entry: ffffc0013af25790
Object: ffffe000df9e4430 Type: (ffffe000dd10af20) File
ObjectHeader: ffffe000df9e4400 (new version)
HandleCount: 1 PointerCount: 32768
Directory Object: 00000000 Name: \Windows\System32\en-US\winlogon.exe.mui {HarddiskVolume2}
0: kd> !fileobj ffffe000df9e4430
\Windows\System32\en-US\winlogon.exe.mui
Device Object: 0xffffe000deb93690 \Driver\volmgr
Vpb: 0xffffe000deb95870
Event signalled
Access: Read SharedRead SharedDelete
Flags: 0x40040
Cache Supported
Handle Created
FsContext: 0xffffcf80c46e6c00 FsContext2: 0xffffcf80c5490f70
CurrentByteOffset: 0
Cache Data:
Section Object Pointers: ffffcf80c4222f58
Shared Cache Map: 00000000
0: kd> !devobj 0xffffe000deb93690
Device object (ffffe000deb93690) is for:
HarddiskVolume2 \Driver\volmgr DriverObject ffffe000de5ccd20
Current Irp 00000000 RefCount 3966 Type 00000007 Flags 00001150
Vpb ffffe000deb95870 Dacl ffffc10232304490 DevExt ffffe000deb937e0 DevObjExt ffffe000deb939a0 Dope ffffe000deb95800 DevNode ffffe000deb94d30
ExtensionFlags (0x00000800) DOE_DEFAULT_SD_PRESENT
Characteristics (0x00020000) FILE_DEVICE_ALLOW_APPCONTAINER_TRAVERSAL
AttachedDevice (Upper) ffffe000deb99030 \Driver\fvevol
Device queue is not busy.
0: kd> !drvobj ffffe000de5ccd20
fffff803f0f50800: Unable to get value of ObpRootDirectoryObject
Driver object (ffffe000de5ccd20) is for:
Cannot read _DRIVER_OBJECT at ffffe000de5ccd20
0: kd> !drvobj \Driver\volmgr
Driver object \Driver\volmgr not found
0: kd> !drvobj \Driver\volmgr 2
Driver object (ffffe000de5ccd20) is for:
\Driver\volmgr
DriverEntry: fffff800bb394000
DriverStartIo: 00000000
DriverUnload: fffff800bb3932a0
AddDevice: 00000000
Dispatch routines:
[00] IRP_MJ_CREATE fffff800bb381f90 +0xfffff800bb381f90
[01] IRP_MJ_CREATE_NAMED_PIPE fffff803f0d4aa00 nt!IopInvalidDeviceRequest
[02] IRP_MJ_CLOSE fffff803f0d4aa00 nt!IopInvalidDeviceRequest
[03] IRP_MJ_READ fffff800bb381000 +0xfffff800bb381000
[04] IRP_MJ_WRITE fffff800bb381000 +0xfffff800bb381000
[05] IRP_MJ_QUERY_INFORMATION fffff803f0d4aa00 nt!IopInvalidDeviceRequest
[06] IRP_MJ_SET_INFORMATION fffff803f0d4aa00 nt!IopInvalidDeviceRequest
[07] IRP_MJ_QUERY_EA fffff803f0d4aa00 nt!IopInvalidDeviceRequest
[08] IRP_MJ_SET_EA fffff803f0d4aa00 nt!IopInvalidDeviceRequest
[09] IRP_MJ_FLUSH_BUFFERS fffff800bb381e50 +0xfffff800bb381e50
[0a] IRP_MJ_QUERY_VOLUME_INFORMATION fffff803f0d4aa00 nt!IopInvalidDeviceRequest
[0b] IRP_MJ_SET_VOLUME_INFORMATION fffff803f0d4aa00 nt!IopInvalidDeviceRequest
[0c] IRP_MJ_DIRECTORY_CONTROL fffff803f0d4aa00 nt!IopInvalidDeviceRequest
[0d] IRP_MJ_FILE_SYSTEM_CONTROL fffff803f0d4aa00 nt!IopInvalidDeviceRequest
[0e] IRP_MJ_DEVICE_CONTROL fffff800bb3812e0 +0xfffff800bb3812e0
[0f] IRP_MJ_INTERNAL_DEVICE_CONTROL fffff800bb382300 +0xfffff800bb382300
[10] IRP_MJ_SHUTDOWN fffff800bb384690 +0xfffff800bb384690
[11] IRP_MJ_LOCK_CONTROL fffff803f0d4aa00 nt!IopInvalidDeviceRequest
[12] IRP_MJ_CLEANUP fffff800bb381e00 +0xfffff800bb381e00
[13] IRP_MJ_CREATE_MAILSLOT fffff803f0d4aa00 nt!IopInvalidDeviceRequest
[14] IRP_MJ_QUERY_SECURITY fffff803f0d4aa00 nt!IopInvalidDeviceRequest
[15] IRP_MJ_SET_SECURITY fffff803f0d4aa00 nt!IopInvalidDeviceRequest
[16] IRP_MJ_POWER fffff800bb3821f0 +0xfffff800bb3821f0
[17] IRP_MJ_SYSTEM_CONTROL fffff800bb381fc0 +0xfffff800bb381fc0
[18] IRP_MJ_DEVICE_CHANGE fffff803f0d4aa00 nt!IopInvalidDeviceRequest
[19] IRP_MJ_QUERY_QUOTA fffff803f0d4aa00 nt!IopInvalidDeviceRequest
[1a] IRP_MJ_SET_QUOTA fffff803f0d4aa00 nt!IopInvalidDeviceRequest
[1b] IRP_MJ_PNP fffff800bb38bb60 +0xfffff800bb38bb60
0: kd> .reload
Connected to Windows 10 10586 x64 target at (Thu May 5 11:07:59.856 2016 (UTC + 10:00)), ptr64 TRUE
Loading Kernel Symbols
...............................................................
....
Press ctrl-c (cdb, kd, ntsd) or ctrl-break (windbg) to abort symbol loads that take too long.
Run !sym noisy before .reload to track down problems loading symbols.
............................................................
..........................
Loading User Symbols
......................
Press ctrl-c (cdb, kd, ntsd) or ctrl-break (windbg) to abort symbol loads that take too long.
Run !sym noisy before .reload to track down problems loading symbols.
.....
Loading unloaded module list
.......
0: kd> !drvobj \Driver\volmgr 2
Driver object (ffffe000de5ccd20) is for:
\Driver\volmgr
DriverEntry: fffff800bb394000 volmgr!GsDriverEntry
DriverStartIo: 00000000
DriverUnload: fffff800bb3932a0 volmgr!VmUnload
AddDevice: 00000000
Dispatch routines:
[00] IRP_MJ_CREATE fffff800bb381f90 volmgr!VmCreate
[01] IRP_MJ_CREATE_NAMED_PIPE fffff803f0d4aa00 nt!IopInvalidDeviceRequest
[02] IRP_MJ_CLOSE fffff803f0d4aa00 nt!IopInvalidDeviceRequest
[03] IRP_MJ_READ fffff800bb381000 volmgr!VmReadWrite
[04] IRP_MJ_WRITE fffff800bb381000 volmgr!VmReadWrite
[05] IRP_MJ_QUERY_INFORMATION fffff803f0d4aa00 nt!IopInvalidDeviceRequest
[06] IRP_MJ_SET_INFORMATION fffff803f0d4aa00 nt!IopInvalidDeviceRequest
[07] IRP_MJ_QUERY_EA fffff803f0d4aa00 nt!IopInvalidDeviceRequest
[08] IRP_MJ_SET_EA fffff803f0d4aa00 nt!IopInvalidDeviceRequest
[09] IRP_MJ_FLUSH_BUFFERS fffff800bb381e50 volmgr!VmFlushBuffers
[0a] IRP_MJ_QUERY_VOLUME_INFORMATION fffff803f0d4aa00 nt!IopInvalidDeviceRequest
[0b] IRP_MJ_SET_VOLUME_INFORMATION fffff803f0d4aa00 nt!IopInvalidDeviceRequest
[0c] IRP_MJ_DIRECTORY_CONTROL fffff803f0d4aa00 nt!IopInvalidDeviceRequest
[0d] IRP_MJ_FILE_SYSTEM_CONTROL fffff803f0d4aa00 nt!IopInvalidDeviceRequest
[0e] IRP_MJ_DEVICE_CONTROL fffff800bb3812e0 volmgr!VmDeviceControl
[0f] IRP_MJ_INTERNAL_DEVICE_CONTROL fffff800bb382300 volmgr!VmInternalDeviceControl
[10] IRP_MJ_SHUTDOWN fffff800bb384690 volmgr!VmShutdown
[11] IRP_MJ_LOCK_CONTROL fffff803f0d4aa00 nt!IopInvalidDeviceRequest
[12] IRP_MJ_CLEANUP fffff800bb381e00 volmgr!VmCleanup
[13] IRP_MJ_CREATE_MAILSLOT fffff803f0d4aa00 nt!IopInvalidDeviceRequest
[14] IRP_MJ_QUERY_SECURITY fffff803f0d4aa00 nt!IopInvalidDeviceRequest
[15] IRP_MJ_SET_SECURITY fffff803f0d4aa00 nt!IopInvalidDeviceRequest
[16] IRP_MJ_POWER fffff800bb3821f0 volmgr!VmPower
[17] IRP_MJ_SYSTEM_CONTROL fffff800bb381fc0 volmgr!VmWmi
[18] IRP_MJ_DEVICE_CHANGE fffff803f0d4aa00 nt!IopInvalidDeviceRequest
[19] IRP_MJ_QUERY_QUOTA fffff803f0d4aa00 nt!IopInvalidDeviceRequest
[1a] IRP_MJ_SET_QUOTA fffff803f0d4aa00 nt!IopInvalidDeviceRequest
[1b] IRP_MJ_PNP fffff800bb38bb60 volmgr!VmPnp
0: kd> .logfile
Log 'c:\course\windbg.day4.log' open
0: kd> !drvobj kbdclass
Driver object (ffffe000ded9a080) is for:
\Driver\kbdclass
Driver Extension List: (id , addr)
Device Object list:
ffffe000dfa59890 ffffe000dedb9690 ffffe000ded9a400
0: kd> !drvobj kbdclass
Driver object (ffffe000ded9a080) is for:
\Driver\kbdclass
Driver Extension List: (id , addr)
Device Object list:
ffffe000dfa59890 ffffe000dedb9690 ffffe000ded9a400
0: kd> lm
start end module name
00007ff7`93770000 00007ff7`93804000 winlogon (deferred)
00007ffc`5cb90000 00007ffc`5cc09000 apphelp (deferred)
00007ffc`5cc40000 00007ffc`5cc54000 dwminit (deferred)
00007ffc`5cd10000 00007ffc`5cda6000 UxTheme (deferred)
00007ffc`5ce90000 00007ffc`5ceaa000 UXINIT (deferred)
00007ffc`5d9e0000 00007ffc`5d9ea000 DPAPI (deferred)
00007ffc`5de30000 00007ffc`5de3b000 CRYPTBASE (deferred)
00007ffc`5e010000 00007ffc`5e03d000 SspiCli (deferred)
00007ffc`5e1c0000 00007ffc`5e216000 winsta (deferred)
00007ffc`5e2d0000 00007ffc`5e2f9000 bcrypt (deferred)
00007ffc`5e3a0000 00007ffc`5e3eb000 powrprof (deferred)
00007ffc`5e3f0000 00007ffc`5e404000 profapi (deferred)
00007ffc`5e410000 00007ffc`5e420000 MSASN1 (deferred)
00007ffc`5e4d0000 00007ffc`5e585000 shcore (deferred)
00007ffc`5ecc0000 00007ffc`5ee87000 CRYPT32 (deferred)
00007ffc`5ef10000 00007ffc`5ef7a000 bcryptPrimitives (deferred)
00007ffc`5ef80000 00007ffc`5f168000 KERNELBASE (deferred)
00007ffc`5f7d0000 00007ffc`5f82b000 sechost (deferred)
00007ffc`5f830000 00007ffc`5f86b000 IMM32 (deferred)
00007ffc`5f870000 00007ffc`5f9c6000 user32 (deferred)
00007ffc`5fb90000 00007ffc`5fd16000 GDI32 (deferred)
00007ffc`60070000 00007ffc`6011d000 KERNEL32 (deferred)
00007ffc`60120000 00007ffc`601c7000 advapi32 (deferred)
00007ffc`601d0000 00007ffc`6044d000 combase (deferred)
00007ffc`60450000 00007ffc`6056c000 RPCRT4 (deferred)
00007ffc`60650000 00007ffc`606ed000 msvcrt (deferred)
00007ffc`61d70000 00007ffc`61f31000 ntdll (pdb symbols) c:\course\symbols\ntdll.pdb\4E4F50879F8345499DAE85935D2391CE1\ntdll.pdb
fffff800`ba200000 fffff800`ba299000 CI (deferred)
fffff800`ba2a0000 fffff800`ba2fc000 msrpc (deferred)
fffff800`ba300000 fffff800`ba362000 FLTMGR (deferred)
fffff800`ba370000 fffff800`ba395000 ksecdd (deferred)
fffff800`ba3a0000 fffff800`ba445000 clipsp (deferred)
fffff800`ba450000 fffff800`ba515000 Wdf01000 (deferred)
fffff800`ba520000 fffff800`ba533000 WDFLDR (deferred)
fffff800`ba540000 fffff800`ba563000 acpiex (deferred)
fffff800`ba570000 fffff800`ba57d000 WppRecorder (deferred)
fffff800`ba580000 fffff800`ba618000 cng (deferred)
fffff800`ba620000 fffff800`ba6b0000 ACPI (deferred)
fffff800`ba6b0000 fffff800`ba6bc000 WMILIB (deferred)
fffff800`ba6d0000 fffff800`ba6ef000 WindowsTrustedRT (deferred)
fffff800`ba6f0000 fffff800`ba6fb000 WindowsTrustedRTProxy (deferred)
fffff800`ba700000 fffff800`ba712000 pcw (deferred)
fffff800`ba720000 fffff800`ba72b000 msisadrv (deferred)
fffff800`ba730000 fffff800`ba786000 pci (deferred)
fffff800`ba790000 fffff800`ba7a2000 vdrvroot (deferred)
fffff800`ba7b0000 fffff800`ba7ce000 pdc (deferred)
fffff800`ba7d0000 fffff800`ba7e9000 CEA (deferred)
fffff800`ba7f0000 fffff800`ba812000 partmgr (deferred)
fffff800`ba820000 fffff800`ba841000 vmbus (deferred)
fffff800`ba850000 fffff800`ba970000 NDIS (deferred)
fffff800`ba970000 fffff800`ba9e8000 NETIO (deferred)
fffff800`ba9f0000 fffff800`baa0b000 hvsocket (deferred)
fffff800`baa10000 fffff800`baa28000 vmbkmcl (deferred)
fffff800`baa30000 fffff800`baa3e000 winhv (deferred)
fffff800`baa50000 fffff800`baade000 mcupdate_GenuineIntel (deferred)
fffff800`baae0000 fffff800`baaf0000 werkernel (deferred)
fffff800`baaf0000 fffff800`bab55000 CLFS (deferred)
fffff800`bab60000 fffff800`bab85000 tm (deferred)
fffff800`bab90000 fffff800`baba7000 PSHED (deferred)
fffff800`babb0000 fffff800`babbb000 BOOTVID (deferred)
fffff800`babc0000 fffff800`babce000 cmimcext (deferred)
fffff800`babd0000 fffff800`babdc000 ntosext (deferred)
fffff800`bac00000 fffff800`bac1d000 mountmgr (deferred)
fffff800`bac20000 fffff800`bac2c000 atapi (deferred)
fffff800`bac30000 fffff800`bac65000 ataport (deferred)
fffff800`bac70000 fffff800`bac8c000 EhStorClass (deferred)
fffff800`bac90000 fffff800`baca9000 fileinfo (deferred)
fffff800`bacb0000 fffff800`bace8000 Wof (deferred)
fffff800`bacf0000 fffff800`bad3c000 WdFilter (deferred)
fffff800`bad40000 fffff800`baf58000 NTFS (deferred)
fffff800`baf60000 fffff800`baf6e000 storvsc (deferred)
fffff800`baf70000 fffff800`bafe8000 storport (deferred)
fffff800`baff0000 fffff800`baffd000 Fs_Rec (deferred)
fffff800`bb000000 fffff800`bb02e000 ksecpkg (deferred)
fffff800`bb030000 fffff800`bb287000 tcpip (deferred)
fffff800`bb290000 fffff800`bb2bb000 intelppm (deferred)
fffff800`bb2c0000 fffff800`bb346000 spaceport (deferred)
fffff800`bb350000 fffff800`bb35b000 intelide (deferred)
fffff800`bb360000 fffff800`bb371000 PCIIDEX (deferred)
fffff800`bb380000 fffff800`bb398000 volmgr (pdb symbols) c:\course\symbols\volmgr.pdb\44F7F9DEEF2E44AC9141AFBDB5F67D391\volmgr.pdb
fffff800`bb3a0000 fffff800`bb3fe000 volmgrx (deferred)
fffff800`bb400000 fffff800`bb469000 volsnap (deferred)
fffff800`bb470000 fffff800`bb4b4000 rdyboost (deferred)
fffff800`bb4c0000 fffff800`bb4e5000 mup (deferred)
fffff800`bb4f0000 fffff800`bb4fb000 vmgencounter (deferred)
fffff800`bb500000 fffff800`bb51f000 disk (deferred)
fffff800`bb520000 fffff800`bb580000 CLASSPNP (deferred)
fffff800`bb5a0000 fffff800`bb5b9000 crashdmp (deferred)
fffff800`bb640000 fffff800`bb671000 cdrom (deferred)
fffff800`bb680000 fffff800`bb69d000 filecrypt (deferred)
fffff800`bb6a0000 fffff800`bb6ac000 tbs (deferred)
fffff800`bb6b0000 fffff800`bb6ba000 Null (deferred)
fffff800`bb6c0000 fffff800`bb6ca000 Beep (deferred)
fffff800`bb6d0000 fffff800`bb6e4000 BasicDisplay (deferred)
fffff800`bb6f0000 fffff800`bb705000 watchdog (deferred)
fffff800`bb710000 fffff800`bb8fd000 dxgkrnl (deferred)
fffff800`bb900000 fffff800`bb912000 BasicRender (deferred)
fffff800`bb920000 fffff800`bb939000 Npfs (deferred)
fffff800`bb940000 fffff800`bb94f000 Msfs (deferred)
fffff800`bb950000 fffff800`bb973000 tdx (deferred)
fffff800`bb980000 fffff800`bb98f000 TDI (deferred)
fffff800`bb990000 fffff800`bb9db000 netbt (deferred)
fffff800`bb9e0000 fffff800`bba73000 afd (deferred)
fffff800`bba80000 fffff800`bba99000 vwififlt (deferred)
fffff800`bbaa0000 fffff800`bbacb000 pacer (deferred)
fffff800`bbad0000 fffff800`bbae2000 netbios (deferred)
fffff800`bbaf0000 fffff800`bbb61000 rdbss (deferred)
fffff800`bbb70000 fffff800`bbbfe000 csc (deferred)
fffff800`bbc00000 fffff800`bbc10000 nsiproxy (deferred)
fffff800`bbc10000 fffff800`bbc1d000 npsvctrig (deferred)
fffff800`bbc20000 fffff800`bbc30000 mssmbios (deferred)
fffff800`bbc30000 fffff800`bbc3a000 gpuenergydrv (deferred)
fffff800`bbc40000 fffff800`bbc6a000 dfsc (deferred)
fffff800`bbc70000 fffff800`bbc7d000 NdisVirtualBus (deferred)
fffff800`bbc80000 fffff800`bbc8c000 swenum (deferred)
fffff800`bbc90000 fffff800`bbccc000 ahcache (deferred)
fffff800`bbcd0000 fffff800`bbce1000 CompositeBus (deferred)
fffff800`bbcf0000 fffff800`bbcfd000 kdnic (deferred)
fffff800`bbd00000 fffff800`bbd15000 umbus (deferred)
fffff800`bbd20000 fffff800`bbd42000 i8042prt (deferred)
fffff800`bbd50000 fffff800`bbd63000 kbdclass (pdb symbols) c:\course\symbols\kbdclass.pdb\AC3D9BC841F049A6BBEDFF33A0F1B1D71\kbdclass.pdb
fffff800`bbd70000 fffff800`bbd82000 mouclass (deferred)
fffff800`bbd90000 fffff800`bbdab000 serial (deferred)
fffff800`bbdb0000 fffff800`bbdbf000 serenum (deferred)
fffff800`bbdc0000 fffff800`bbdcf000 fdc (deferred)
fffff800`bbdd0000 fffff800`bbddf000 dmvsc (deferred)
fffff800`bbde0000 fffff800`bbdee000 VMBusHID (deferred)
fffff800`bbdf0000 fffff800`bbe1e000 HIDCLASS (deferred)
fffff800`bbe20000 fffff800`bbe31000 HIDPARSE (deferred)
fffff800`bbe40000 fffff800`bbe4c000 hyperkbd (deferred)
fffff800`bbe50000 fffff800`bbe5f000 HyperVideo (deferred)
fffff800`bbe60000 fffff800`bbec7000 fwpkclnt (deferred)
fffff800`bbed0000 fffff800`bbefa000 wfplwfs (deferred)
fffff800`bbf00000 fffff800`bbf10000 vmstorfl (deferred)
fffff800`bbf10000 fffff800`bbfb1000 fvevol (deferred)
fffff800`bbfc0000 fffff800`bbfe1000 netvsc (deferred)
fffff800`bbff0000 fffff800`bbffb000 vms3cap (deferred)
fffff800`bc200000 fffff800`bc222000 WdNisDrv (deferred)
fffff800`bc230000 fffff800`bc23f000 terminpt (deferred)
fffff800`bc700000 fffff800`bc710000 monitor (deferred)
fffff800`bc710000 fffff800`bc7a2000 dxgmms2 (deferred)
fffff800`bc7b0000 fffff800`bc7bd000 rdpvideominiport (deferred)
fffff800`bc7c0000 fffff800`bc7f0000 rdpdr (deferred)
fffff800`bc7f0000 fffff800`bc816000 luafv (deferred)
fffff800`bc820000 fffff800`bc839000 storqosflt (deferred)
fffff800`bc840000 fffff800`bc865000 tsusbhub (deferred)
fffff800`bc870000 fffff800`bc886000 lltdio (deferred)
fffff800`bc890000 fffff800`bc8aa000 mslldp (deferred)
fffff800`bc8b0000 fffff800`bc8ca000 rspndr (deferred)
fffff800`bc8d0000 fffff800`bc9e1000 HTTP (deferred)
fffff800`bc9f0000 fffff800`bca0d000 WudfPf (deferred)
fffff800`bca10000 fffff800`bca33000 bowser (deferred)
fffff800`bca40000 fffff800`bcab2000 mrxsmb (deferred)
fffff800`bcac0000 fffff800`bcafa000 mrxsmb20 (deferred)
fffff800`bcb00000 fffff800`bcb19000 mpsdrv (deferred)
fffff800`bcb20000 fffff800`bcb61000 srvnet (deferred)
fffff800`bcb70000 fffff800`bcc1f000 srv2 (deferred)
fffff800`bcc20000 fffff800`bcc6e000 mrxsmb10 (deferred)
fffff800`bcc70000 fffff800`bcc84000 mmcss (deferred)
fffff800`bcc90000 fffff800`bccb6000 Ndu (deferred)
fffff800`bccc0000 fffff800`bcd4c000 srv (deferred)
fffff800`bcd50000 fffff800`bcd64000 tcpipreg (deferred)
fffff800`bcda0000 fffff800`bce08000 ks (deferred)
fffff800`bce10000 fffff800`bce1e000 rdpbus (deferred)
fffff800`bce20000 fffff800`bce2e000 flpydisk (deferred)
fffff800`bce30000 fffff800`bce3f000 mouhid (deferred)
fffff800`bce50000 fffff800`bce5f000 dump_dumpata (deferred)
fffff800`bce70000 fffff800`bce7c000 dump_atapi (deferred)
fffff800`bcea0000 fffff800`bcebc000 dump_dumpfve (deferred)
fffff800`bcec0000 fffff800`bcf80000 peauth (deferred)
fffff800`bcf80000 fffff800`bcfaf000 tunnel (deferred)
fffff800`bcfe0000 fffff800`bcff1000 condrv (deferred)
fffff803`efce5000 fffff803`efcf3000 kdcom (deferred)
fffff803`f0c01000 fffff803`f0c74000 hal (deferred)
fffff803`f0c74000 fffff803`f1440000 nt (pdb symbols) c:\course\symbols\ntkrnlmp.pdb\0DE6DC238E194BB78608D54B1E6FA3791\ntkrnlmp.pdb
fffff961`33200000 fffff961`33582000 win32kfull (deferred)
fffff961`33590000 fffff961`336f2000 win32kbase (deferred)
fffff961`33710000 fffff961`3371a000 TSDDD (deferred)
fffff961`33720000 fffff961`3375c000 cdd (deferred)
fffff961`33780000 fffff961`3379c000 RDPUDD (deferred)
fffff961`33b20000 fffff961`33b43000 win32k (deferred)
Unloaded modules:
fffff800`bcfb0000 fffff800`bcfd2000 WdNisDrv.sys
fffff800`bb5d0000 fffff800`bb5df000 dump_ataport.sys
fffff800`bb5f0000 fffff800`bb5fc000 dump_atapi.sys
fffff800`bb620000 fffff800`bb63c000 dump_dumpfve.sys
fffff800`bbc70000 fffff800`bbc83000 dam.sys
fffff800`ba6c0000 fffff800`ba6d0000 WdBoot.sys
fffff800`bb4f0000 fffff800`bb4fe000 hwpolicy.sys
0: kd> !drvobj kbdclass
Driver object (ffffe000ded9a080) is for:
\Driver\kbdclass
Driver Extension List: (id , addr)