Facebook
From Sole Ibis, 2 Years ago, written in Plain Text.
Embed
Download Paste or View Raw
Hits: 133
  1. Opened log file 'E:\Windows\msdart_crashanalyzer_kd_ansi.log'
  2.  
  3. Microsoft (R) Windows Debugger Version 10.0.10240.9 AMD64
  4. Copyright (c) Microsoft Corporation. All rights reserved.
  5.  
  6.  
  7. Loading Dump File [E:\Windows\MEMORY.DMP]
  8. Kernel Bitmap Dump File: Kernel address space is available, User address space may not be available.
  9.  
  10.  
  11. ************* Symbol Path validation summary **************
  12. Response                         Time (ms)     Location
  13. Deferred                                       srv*c:\symbols*http://msdl.microsoft.com/download/symbols
  14. Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols
  15. Executable search path is:
  16. *** ERROR: Symbol file could not be found.  Defaulted to export symbols for ntkrnlmp.exe -
  17. Windows 10 Kernel Version 19041 MP (8 procs) Free x64
  18. Product: WinNt, suite: TerminalServer SingleUserTS
  19. Built by: 19041.1.amd64fre.vb_release.191206-1406
  20. Machine Name:
  21. Kernel base = 0xfffff800`7be00000 PsLoadedModuleList = 0xfffff800`7ca2a310
  22. Debug session time: Mon Sep 20 03:12:30.931 2021 (UTC - 8:00)
  23. System Uptime: 0 days 6:10:01.548
  24. *** ERROR: Symbol file could not be found.  Defaulted to export symbols for ntkrnlmp.exe -
  25. Loading Kernel Symbols
  26. ...............................................................
  27. .................Page 20001f64b too large to be in the dump file.
  28. ...............................................
  29. ................................................................
  30. ......
  31. Loading User Symbols
  32.  
  33. Loading unloaded module list
  34. .....................
  35.  
  36. ************* Symbol Loading Error Summary **************
  37. Module name            Error
  38. ntkrnlmp               The system cannot find the file specified
  39.  
  40. You can troubleshoot most symbol related issues by turning on symbol loading diagnostics (!sym noisy) and repeating the command that caused symbols to be loaded.
  41. You should also verify that your symbol search path (.sympath) is correct.
  42. No .natvis files found at X:\windows\system32\DebugTools\Visualizers.
  43. *******************************************************************************
  44. *                                                                             *
  45. *                        Bugcheck Analysis                                    *
  46. *                                                                             *
  47. *******************************************************************************
  48.  
  49. Use !analyze -v to get detailed debugging information.
  50.  
  51. BugCheck BE, {ffff900035b3a334, 8a00000005300021, ffffdc82017c6550, a}
  52.  
  53. ***** Kernel symbols are WRONG. Please fix symbols to do analysis.
  54.  
  55. *************************************************************************
  56. ***                                                                   ***
  57. ***                                                                   ***
  58. ***    Either you specified an unqualified symbol, or your debugger   ***
  59. ***    doesn't have full symbol information.  Unqualified symbol      ***
  60. ***    resolution is turned off by default. Please either specify a   ***
  61. ***    fully qualified symbol module!symbolname, or enable resolution ***
  62. ***    of unqualified symbols by typing ".symopt- 100". Note that   ***
  63. ***    enabling unqualified symbol resolution with network symbol     ***
  64. ***    server shares in the symbol path may cause the debugger to     ***
  65. ***    appear to hang for long periods of time when an incorrect      ***
  66. ***    symbol name is typed or the network symbol server is down.     ***
  67. ***                                                                   ***
  68. ***    For some commands to work properly, your symbol path           ***
  69. ***    must point to .pdb files that have full type information.      ***
  70. ***                                                                   ***
  71. ***    Certain .pdb files (such as the public OS symbols) do not      ***
  72. ***    contain the required information.  Contact the group that      ***
  73. ***    provided you with these symbols if you need this command to    ***
  74. ***    work.                                                          ***
  75. ***                                                                   ***
  76. ***    Type referenced: nt!_KPRCB                                     ***
  77. ***                                                                   ***
  78. *************************************************************************
  79. *************************************************************************
  80. ***                                                                   ***
  81. ***                                                                   ***
  82. ***    Either you specified an unqualified symbol, or your debugger   ***
  83. ***    doesn't have full symbol information.  Unqualified symbol      ***
  84. ***    resolution is turned off by default. Please either specify a   ***
  85. ***    fully qualified symbol module!symbolname, or enable resolution ***
  86. ***    of unqualified symbols by typing ".symopt- 100". Note that   ***
  87. ***    enabling unqualified symbol resolution with network symbol     ***
  88. ***    server shares in the symbol path may cause the debugger to     ***
  89. ***    appear to hang for long periods of time when an incorrect      ***
  90. ***    symbol name is typed or the network symbol server is down.     ***
  91. ***                                                                   ***
  92. ***    For some commands to work properly, your symbol path           ***
  93. ***    must point to .pdb files that have full type information.      ***
  94. ***                                                                   ***
  95. ***    Certain .pdb files (such as the public OS symbols) do not      ***
  96. ***    contain the required information.  Contact the group that      ***
  97. ***    provided you with these symbols if you need this command to    ***
  98. ***    work.                                                          ***
  99. ***                                                                   ***
  100. ***    Type referenced: nt!KPRCB                                      ***
  101. ***                                                                   ***
  102. *************************************************************************
  103. *************************************************************************
  104. ***                                                                   ***
  105. ***                                                                   ***
  106. ***    Either you specified an unqualified symbol, or your debugger   ***
  107. ***    doesn't have full symbol information.  Unqualified symbol      ***
  108. ***    resolution is turned off by default. Please either specify a   ***
  109. ***    fully qualified symbol module!symbolname, or enable resolution ***
  110. ***    of unqualified symbols by typing ".symopt- 100". Note that   ***
  111. ***    enabling unqualified symbol resolution with network symbol     ***
  112. ***    server shares in the symbol path may cause the debugger to     ***
  113. ***    appear to hang for long periods of time when an incorrect      ***
  114. ***    symbol name is typed or the network symbol server is down.     ***
  115. ***                                                                   ***
  116. ***    For some commands to work properly, your symbol path           ***
  117. ***    must point to .pdb files that have full type information.      ***
  118. ***                                                                   ***
  119. ***    Certain .pdb files (such as the public OS symbols) do not      ***
  120. ***    contain the required information.  Contact the group that      ***
  121. ***    provided you with these symbols if you need this command to    ***
  122. ***    work.                                                          ***
  123. ***                                                                   ***
  124. ***    Type referenced: nt!_KPRCB                                     ***
  125. ***                                                                   ***
  126. *************************************************************************
  127. *************************************************************************
  128. ***                                                                   ***
  129. ***                                                                   ***
  130. ***    Either you specified an unqualified symbol, or your debugger   ***
  131. ***    doesn't have full symbol information.  Unqualified symbol      ***
  132. ***    resolution is turned off by default. Please either specify a   ***
  133. ***    fully qualified symbol module!symbolname, or enable resolution ***
  134. ***    of unqualified symbols by typing ".symopt- 100". Note that   ***
  135. ***    enabling unqualified symbol resolution with network symbol     ***
  136. ***    server shares in the symbol path may cause the debugger to     ***
  137. ***    appear to hang for long periods of time when an incorrect      ***
  138. ***    symbol name is typed or the network symbol server is down.     ***
  139. ***                                                                   ***
  140. ***    For some commands to work properly, your symbol path           ***
  141. ***    must point to .pdb files that have full type information.      ***
  142. ***                                                                   ***
  143. ***    Certain .pdb files (such as the public OS symbols) do not      ***
  144. ***    contain the required information.  Contact the group that      ***
  145. ***    provided you with these symbols if you need this command to    ***
  146. ***    work.                                                          ***
  147. ***                                                                   ***
  148. ***    Type referenced: nt!KPRCB                                      ***
  149. ***                                                                   ***
  150. *************************************************************************
  151. *************************************************************************
  152. ***                                                                   ***
  153. ***                                                                   ***
  154. ***    Either you specified an unqualified symbol, or your debugger   ***
  155. ***    doesn't have full symbol information.  Unqualified symbol      ***
  156. ***    resolution is turned off by default. Please either specify a   ***
  157. ***    fully qualified symbol module!symbolname, or enable resolution ***
  158. ***    of unqualified symbols by typing ".symopt- 100". Note that   ***
  159. ***    enabling unqualified symbol resolution with network symbol     ***
  160. ***    server shares in the symbol path may cause the debugger to     ***
  161. ***    appear to hang for long periods of time when an incorrect      ***
  162. ***    symbol name is typed or the network symbol server is down.     ***
  163. ***                                                                   ***
  164. ***    For some commands to work properly, your symbol path           ***
  165. ***    must point to .pdb files that have full type information.      ***
  166. ***                                                                   ***
  167. ***    Certain .pdb files (such as the public OS symbols) do not      ***
  168. ***    contain the required information.  Contact the group that      ***
  169. ***    provided you with these symbols if you need this command to    ***
  170. ***    work.                                                          ***
  171. ***                                                                   ***
  172. ***    Type referenced: nt!_KPRCB                                     ***
  173. ***                                                                   ***
  174. *************************************************************************
  175. *************************************************************************
  176. ***                                                                   ***
  177. ***                                                                   ***
  178. ***    Either you specified an unqualified symbol, or your debugger   ***
  179. ***    doesn't have full symbol information.  Unqualified symbol      ***
  180. ***    resolution is turned off by default. Please either specify a   ***
  181. ***    fully qualified symbol module!symbolname, or enable resolution ***
  182. ***    of unqualified symbols by typing ".symopt- 100". Note that   ***
  183. ***    enabling unqualified symbol resolution with network symbol     ***
  184. ***    server shares in the symbol path may cause the debugger to     ***
  185. ***    appear to hang for long periods of time when an incorrect      ***
  186. ***    symbol name is typed or the network symbol server is down.     ***
  187. ***                                                                   ***
  188. ***    For some commands to work properly, your symbol path           ***
  189. ***    must point to .pdb files that have full type information.      ***
  190. ***                                                                   ***
  191. ***    Certain .pdb files (such as the public OS symbols) do not      ***
  192. ***    contain the required information.  Contact the group that      ***
  193. ***    provided you with these symbols if you need this command to    ***
  194. ***    work.                                                          ***
  195. ***                                                                   ***
  196. ***    Type referenced: nt!_KPRCB                                     ***
  197. ***                                                                   ***
  198. *************************************************************************
  199. *************************************************************************
  200. ***                                                                   ***
  201. ***                                                                   ***
  202. ***    Either you specified an unqualified symbol, or your debugger   ***
  203. ***    doesn't have full symbol information.  Unqualified symbol      ***
  204. ***    resolution is turned off by default. Please either specify a   ***
  205. ***    fully qualified symbol module!symbolname, or enable resolution ***
  206. ***    of unqualified symbols by typing ".symopt- 100". Note that   ***
  207. ***    enabling unqualified symbol resolution with network symbol     ***
  208. ***    server shares in the symbol path may cause the debugger to     ***
  209. ***    appear to hang for long periods of time when an incorrect      ***
  210. ***    symbol name is typed or the network symbol server is down.     ***
  211. ***                                                                   ***
  212. ***    For some commands to work properly, your symbol path           ***
  213. ***    must point to .pdb files that have full type information.      ***
  214. ***                                                                   ***
  215. ***    Certain .pdb files (such as the public OS symbols) do not      ***
  216. ***    contain the required information.  Contact the group that      ***
  217. ***    provided you with these symbols if you need this command to    ***
  218. ***    work.                                                          ***
  219. ***                                                                   ***
  220. ***    Type referenced: nt!_KPRCB                                     ***
  221. ***                                                                   ***
  222. *************************************************************************
  223. *************************************************************************
  224. ***                                                                   ***
  225. ***                                                                   ***
  226. ***    Either you specified an unqualified symbol, or your debugger   ***
  227. ***    doesn't have full symbol information.  Unqualified symbol      ***
  228. ***    resolution is turned off by default. Please either specify a   ***
  229. ***    fully qualified symbol module!symbolname, or enable resolution ***
  230. ***    of unqualified symbols by typing ".symopt- 100". Note that   ***
  231. ***    enabling unqualified symbol resolution with network symbol     ***
  232. ***    server shares in the symbol path may cause the debugger to     ***
  233. ***    appear to hang for long periods of time when an incorrect      ***
  234. ***    symbol name is typed or the network symbol server is down.     ***
  235. ***                                                                   ***
  236. ***    For some commands to work properly, your symbol path           ***
  237. ***    must point to .pdb files that have full type information.      ***
  238. ***                                                                   ***
  239. ***    Certain .pdb files (such as the public OS symbols) do not      ***
  240. ***    contain the required information.  Contact the group that      ***
  241. ***    provided you with these symbols if you need this command to    ***
  242. ***    work.                                                          ***
  243. ***                                                                   ***
  244. ***    Type referenced: nt!_KPRCB                                     ***
  245. ***                                                                   ***
  246. *************************************************************************
  247. *************************************************************************
  248. ***                                                                   ***
  249. ***                                                                   ***
  250. ***    Either you specified an unqualified symbol, or your debugger   ***
  251. ***    doesn't have full symbol information.  Unqualified symbol      ***
  252. ***    resolution is turned off by default. Please either specify a   ***
  253. ***    fully qualified symbol module!symbolname, or enable resolution ***
  254. ***    of unqualified symbols by typing ".symopt- 100". Note that   ***
  255. ***    enabling unqualified symbol resolution with network symbol     ***
  256. ***    server shares in the symbol path may cause the debugger to     ***
  257. ***    appear to hang for long periods of time when an incorrect      ***
  258. ***    symbol name is typed or the network symbol server is down.     ***
  259. ***                                                                   ***
  260. ***    For some commands to work properly, your symbol path           ***
  261. ***    must point to .pdb files that have full type information.      ***
  262. ***                                                                   ***
  263. ***    Certain .pdb files (such as the public OS symbols) do not      ***
  264. ***    contain the required information.  Contact the group that      ***
  265. ***    provided you with these symbols if you need this command to    ***
  266. ***    work.                                                          ***
  267. ***                                                                   ***
  268. ***    Type referenced: nt!_KPRCB                                     ***
  269. ***                                                                   ***
  270. *************************************************************************
  271. *************************************************************************
  272. ***                                                                   ***
  273. ***                                                                   ***
  274. ***    Either you specified an unqualified symbol, or your debugger   ***
  275. ***    doesn't have full symbol information.  Unqualified symbol      ***
  276. ***    resolution is turned off by default. Please either specify a   ***
  277. ***    fully qualified symbol module!symbolname, or enable resolution ***
  278. ***    of unqualified symbols by typing ".symopt- 100". Note that   ***
  279. ***    enabling unqualified symbol resolution with network symbol     ***
  280. ***    server shares in the symbol path may cause the debugger to     ***
  281. ***    appear to hang for long periods of time when an incorrect      ***
  282. ***    symbol name is typed or the network symbol server is down.     ***
  283. ***                                                                   ***
  284. ***    For some commands to work properly, your symbol path           ***
  285. ***    must point to .pdb files that have full type information.      ***
  286. ***                                                                   ***
  287. ***    Certain .pdb files (such as the public OS symbols) do not      ***
  288. ***    contain the required information.  Contact the group that      ***
  289. ***    provided you with these symbols if you need this command to    ***
  290. ***    work.                                                          ***
  291. ***                                                                   ***
  292. ***    Type referenced: nt!_KPCR                                      ***
  293. ***                                                                   ***
  294. *************************************************************************
  295. *************************************************************************
  296. ***                                                                   ***
  297. ***                                                                   ***
  298. ***    Either you specified an unqualified symbol, or your debugger   ***
  299. ***    doesn't have full symbol information.  Unqualified symbol      ***
  300. ***    resolution is turned off by default. Please either specify a   ***
  301. ***    fully qualified symbol module!symbolname, or enable resolution ***
  302. ***    of unqualified symbols by typing ".symopt- 100". Note that   ***
  303. ***    enabling unqualified symbol resolution with network symbol     ***
  304. ***    server shares in the symbol path may cause the debugger to     ***
  305. ***    appear to hang for long periods of time when an incorrect      ***
  306. ***    symbol name is typed or the network symbol server is down.     ***
  307. ***                                                                   ***
  308. ***    For some commands to work properly, your symbol path           ***
  309. ***    must point to .pdb files that have full type information.      ***
  310. ***                                                                   ***
  311. ***    Certain .pdb files (such as the public OS symbols) do not      ***
  312. ***    contain the required information.  Contact the group that      ***
  313. ***    provided you with these symbols if you need this command to    ***
  314. ***    work.                                                          ***
  315. ***                                                                   ***
  316. ***    Type referenced: nt!_KTHREAD                                   ***
  317. ***                                                                   ***
  318. *************************************************************************
  319. *************************************************************************
  320. ***                                                                   ***
  321. ***                                                                   ***
  322. ***    Either you specified an unqualified symbol, or your debugger   ***
  323. ***    doesn't have full symbol information.  Unqualified symbol      ***
  324. ***    resolution is turned off by default. Please either specify a   ***
  325. ***    fully qualified symbol module!symbolname, or enable resolution ***
  326. ***    of unqualified symbols by typing ".symopt- 100". Note that   ***
  327. ***    enabling unqualified symbol resolution with network symbol     ***
  328. ***    server shares in the symbol path may cause the debugger to     ***
  329. ***    appear to hang for long periods of time when an incorrect      ***
  330. ***    symbol name is typed or the network symbol server is down.     ***
  331. ***                                                                   ***
  332. ***    For some commands to work properly, your symbol path           ***
  333. ***    must point to .pdb files that have full type information.      ***
  334. ***                                                                   ***
  335. ***    Certain .pdb files (such as the public OS symbols) do not      ***
  336. ***    contain the required information.  Contact the group that      ***
  337. ***    provided you with these symbols if you need this command to    ***
  338. ***    work.                                                          ***
  339. ***                                                                   ***
  340. ***    Type referenced: nt!_KPRCB                                     ***
  341. ***                                                                   ***
  342. *************************************************************************
  343. *************************************************************************
  344. ***                                                                   ***
  345. ***                                                                   ***
  346. ***    Either you specified an unqualified symbol, or your debugger   ***
  347. ***    doesn't have full symbol information.  Unqualified symbol      ***
  348. ***    resolution is turned off by default. Please either specify a   ***
  349. ***    fully qualified symbol module!symbolname, or enable resolution ***
  350. ***    of unqualified symbols by typing ".symopt- 100". Note that   ***
  351. ***    enabling unqualified symbol resolution with network symbol     ***
  352. ***    server shares in the symbol path may cause the debugger to     ***
  353. ***    appear to hang for long periods of time when an incorrect      ***
  354. ***    symbol name is typed or the network symbol server is down.     ***
  355. ***                                                                   ***
  356. ***    For some commands to work properly, your symbol path           ***
  357. ***    must point to .pdb files that have full type information.      ***
  358. ***                                                                   ***
  359. ***    Certain .pdb files (such as the public OS symbols) do not      ***
  360. ***    contain the required information.  Contact the group that      ***
  361. ***    provided you with these symbols if you need this command to    ***
  362. ***    work.                                                          ***
  363. ***                                                                   ***
  364. ***    Type referenced: nt!_KPRCB                                     ***
  365. ***                                                                   ***
  366. *************************************************************************
  367. Probably caused by : ntoskrnl.wrong.symbols.exe ( nt_wrong_symbols!A371A2E91046000 )
  368.  
  369. Followup:     MachineOwner
  370. ---------
  371.  
  372. 6: kd> .logclose
  373. Closing open log file E:\Windows\msdart_crashanalyzer_kd_ansi.log
  374. Opened log file 'E:\Windows\msdart_crashanalyzer_kd_unicode.log'
  375. 6: kd> !analyze -v
  376. *******************************************************************************
  377. *                                                                             *
  378. *                        Bugcheck Analysis                                    *
  379. *                                                                             *
  380. *******************************************************************************
  381.  
  382. ATTEMPTED_WRITE_TO_READONLY_MEMORY (be)
  383. An attempt was made to write to readonly memory.  The guilty driver is on the
  384. stack trace (and is typically the current instruction pointer).
  385. When possible, the guilty driver's name (Unicode string) is printed on
  386. the bugcheck screen and saved in KiBugCheckDriver.
  387. Arguments:
  388. Arg1: ffff900035b3a334, Virtual address for the attempted write.
  389. Arg2: 8a00000005300021, PTE contents.
  390. Arg3: ffffdc82017c6550, (reserved)
  391. Arg4: 000000000000000a, (reserved)
  392.  
  393. Debugging Details:
  394. ------------------
  395.  
  396. ***** Kernel symbols are WRONG. Please fix symbols to do analysis.
  397.  
  398. *************************************************************************
  399. ***                                                                   ***
  400. ***                                                                   ***
  401. ***    Either you specified an unqualified symbol, or your debugger   ***
  402. ***    doesn't have full symbol information.  Unqualified symbol      ***
  403. ***    resolution is turned off by default. Please either specify a   ***
  404. ***    fully qualified symbol module!symbolname, or enable resolution ***
  405. ***    of unqualified symbols by typing ".symopt- 100". Note that   ***
  406. ***    enabling unqualified symbol resolution with network symbol     ***
  407. ***    server shares in the symbol path may cause the debugger to     ***
  408. ***    appear to hang for long periods of time when an incorrect      ***
  409. ***    symbol name is typed or the network symbol server is down.     ***
  410. ***                                                                   ***
  411. ***    For some commands to work properly, your symbol path           ***
  412. ***    must point to .pdb files that have full type information.      ***
  413. ***                                                                   ***
  414. ***    Certain .pdb files (such as the public OS symbols) do not      ***
  415. ***    contain the required information.  Contact the group that      ***
  416. ***    provided you with these symbols if you need this command to    ***
  417. ***    work.                                                          ***
  418. ***                                                                   ***
  419. ***    Type referenced: nt!_KPRCB                                     ***
  420. ***                                                                   ***
  421. *************************************************************************
  422. *************************************************************************
  423. ***                                                                   ***
  424. ***                                                                   ***
  425. ***    Either you specified an unqualified symbol, or your debugger   ***
  426. ***    doesn't have full symbol information.  Unqualified symbol      ***
  427. ***    resolution is turned off by default. Please either specify a   ***
  428. ***    fully qualified symbol module!symbolname, or enable resolution ***
  429. ***    of unqualified symbols by typing ".symopt- 100". Note that   ***
  430. ***    enabling unqualified symbol resolution with network symbol     ***
  431. ***    server shares in the symbol path may cause the debugger to     ***
  432. ***    appear to hang for long periods of time when an incorrect      ***
  433. ***    symbol name is typed or the network symbol server is down.     ***
  434. ***                                                                   ***
  435. ***    For some commands to work properly, your symbol path           ***
  436. ***    must point to .pdb files that have full type information.      ***
  437. ***                                                                   ***
  438. ***    Certain .pdb files (such as the public OS symbols) do not      ***
  439. ***    contain the required information.  Contact the group that      ***
  440. ***    provided you with these symbols if you need this command to    ***
  441. ***    work.                                                          ***
  442. ***                                                                   ***
  443. ***    Type referenced: nt!KPRCB                                      ***
  444. ***                                                                   ***
  445. *************************************************************************
  446. *************************************************************************
  447. ***                                                                   ***
  448. ***                                                                   ***
  449. ***    Either you specified an unqualified symbol, or your debugger   ***
  450. ***    doesn't have full symbol information.  Unqualified symbol      ***
  451. ***    resolution is turned off by default. Please either specify a   ***
  452. ***    fully qualified symbol module!symbolname, or enable resolution ***
  453. ***    of unqualified symbols by typing ".symopt- 100". Note that   ***
  454. ***    enabling unqualified symbol resolution with network symbol     ***
  455. ***    server shares in the symbol path may cause the debugger to     ***
  456. ***    appear to hang for long periods of time when an incorrect      ***
  457. ***    symbol name is typed or the network symbol server is down.     ***
  458. ***                                                                   ***
  459. ***    For some commands to work properly, your symbol path           ***
  460. ***    must point to .pdb files that have full type information.      ***
  461. ***                                                                   ***
  462. ***    Certain .pdb files (such as the public OS symbols) do not      ***
  463. ***    contain the required information.  Contact the group that      ***
  464. ***    provided you with these symbols if you need this command to    ***
  465. ***    work.                                                          ***
  466. ***                                                                   ***
  467. ***    Type referenced: nt!_KPRCB                                     ***
  468. ***                                                                   ***
  469. *************************************************************************
  470. *************************************************************************
  471. ***                                                                   ***
  472. ***                                                                   ***
  473. ***    Either you specified an unqualified symbol, or your debugger   ***
  474. ***    doesn't have full symbol information.  Unqualified symbol      ***
  475. ***    resolution is turned off by default. Please either specify a   ***
  476. ***    fully qualified symbol module!symbolname, or enable resolution ***
  477. ***    of unqualified symbols by typing ".symopt- 100". Note that   ***
  478. ***    enabling unqualified symbol resolution with network symbol     ***
  479. ***    server shares in the symbol path may cause the debugger to     ***
  480. ***    appear to hang for long periods of time when an incorrect      ***
  481. ***    symbol name is typed or the network symbol server is down.     ***
  482. ***                                                                   ***
  483. ***    For some commands to work properly, your symbol path           ***
  484. ***    must point to .pdb files that have full type information.      ***
  485. ***                                                                   ***
  486. ***    Certain .pdb files (such as the public OS symbols) do not      ***
  487. ***    contain the required information.  Contact the group that      ***
  488. ***    provided you with these symbols if you need this command to    ***
  489. ***    work.                                                          ***
  490. ***                                                                   ***
  491. ***    Type referenced: nt!KPRCB                                      ***
  492. ***                                                                   ***
  493. *************************************************************************
  494. *************************************************************************
  495. ***                                                                   ***
  496. ***                                                                   ***
  497. ***    Either you specified an unqualified symbol, or your debugger   ***
  498. ***    doesn't have full symbol information.  Unqualified symbol      ***
  499. ***    resolution is turned off by default. Please either specify a   ***
  500. ***    fully qualified symbol module!symbolname, or enable resolution ***
  501. ***    of unqualified symbols by typing ".symopt- 100". Note that   ***
  502. ***    enabling unqualified symbol resolution with network symbol     ***
  503. ***    server shares in the symbol path may cause the debugger to     ***
  504. ***    appear to hang for long periods of time when an incorrect      ***
  505. ***    symbol name is typed or the network symbol server is down.     ***
  506. ***                                                                   ***
  507. ***    For some commands to work properly, your symbol path           ***
  508. ***    must point to .pdb files that have full type information.      ***
  509. ***                                                                   ***
  510. ***    Certain .pdb files (such as the public OS symbols) do not      ***
  511. ***    contain the required information.  Contact the group that      ***
  512. ***    provided you with these symbols if you need this command to    ***
  513. ***    work.                                                          ***
  514. ***                                                                   ***
  515. ***    Type referenced: nt!_KPRCB                                     ***
  516. ***                                                                   ***
  517. *************************************************************************
  518. *************************************************************************
  519. ***                                                                   ***
  520. ***                                                                   ***
  521. ***    Either you specified an unqualified symbol, or your debugger   ***
  522. ***    doesn't have full symbol information.  Unqualified symbol      ***
  523. ***    resolution is turned off by default. Please either specify a   ***
  524. ***    fully qualified symbol module!symbolname, or enable resolution ***
  525. ***    of unqualified symbols by typing ".symopt- 100". Note that   ***
  526. ***    enabling unqualified symbol resolution with network symbol     ***
  527. ***    server shares in the symbol path may cause the debugger to     ***
  528. ***    appear to hang for long periods of time when an incorrect      ***
  529. ***    symbol name is typed or the network symbol server is down.     ***
  530. ***                                                                   ***
  531. ***    For some commands to work properly, your symbol path           ***
  532. ***    must point to .pdb files that have full type information.      ***
  533. ***                                                                   ***
  534. ***    Certain .pdb files (such as the public OS symbols) do not      ***
  535. ***    contain the required information.  Contact the group that      ***
  536. ***    provided you with these symbols if you need this command to    ***
  537. ***    work.                                                          ***
  538. ***                                                                   ***
  539. ***    Type referenced: nt!_KPRCB                                     ***
  540. ***                                                                   ***
  541. *************************************************************************
  542. *************************************************************************
  543. ***                                                                   ***
  544. ***                                                                   ***
  545. ***    Either you specified an unqualified symbol, or your debugger   ***
  546. ***    doesn't have full symbol information.  Unqualified symbol      ***
  547. ***    resolution is turned off by default. Please either specify a   ***
  548. ***    fully qualified symbol module!symbolname, or enable resolution ***
  549. ***    of unqualified symbols by typing ".symopt- 100". Note that   ***
  550. ***    enabling unqualified symbol resolution with network symbol     ***
  551. ***    server shares in the symbol path may cause the debugger to     ***
  552. ***    appear to hang for long periods of time when an incorrect      ***
  553. ***    symbol name is typed or the network symbol server is down.     ***
  554. ***                                                                   ***
  555. ***    For some commands to work properly, your symbol path           ***
  556. ***    must point to .pdb files that have full type information.      ***
  557. ***                                                                   ***
  558. ***    Certain .pdb files (such as the public OS symbols) do not      ***
  559. ***    contain the required information.  Contact the group that      ***
  560. ***    provided you with these symbols if you need this command to    ***
  561. ***    work.                                                          ***
  562. ***                                                                   ***
  563. ***    Type referenced: nt!_KPRCB                                     ***
  564. ***                                                                   ***
  565. *************************************************************************
  566. *************************************************************************
  567. ***                                                                   ***
  568. ***                                                                   ***
  569. ***    Either you specified an unqualified symbol, or your debugger   ***
  570. ***    doesn't have full symbol information.  Unqualified symbol      ***
  571. ***    resolution is turned off by default. Please either specify a   ***
  572. ***    fully qualified symbol module!symbolname, or enable resolution ***
  573. ***    of unqualified symbols by typing ".symopt- 100". Note that   ***
  574. ***    enabling unqualified symbol resolution with network symbol     ***
  575. ***    server shares in the symbol path may cause the debugger to     ***
  576. ***    appear to hang for long periods of time when an incorrect      ***
  577. ***    symbol name is typed or the network symbol server is down.     ***
  578. ***                                                                   ***
  579. ***    For some commands to work properly, your symbol path           ***
  580. ***    must point to .pdb files that have full type information.      ***
  581. ***                                                                   ***
  582. ***    Certain .pdb files (such as the public OS symbols) do not      ***
  583. ***    contain the required information.  Contact the group that      ***
  584. ***    provided you with these symbols if you need this command to    ***
  585. ***    work.                                                          ***
  586. ***                                                                   ***
  587. ***    Type referenced: nt!_KPRCB                                     ***
  588. ***                                                                   ***
  589. *************************************************************************
  590. *************************************************************************
  591. ***                                                                   ***
  592. ***                                                                   ***
  593. ***    Either you specified an unqualified symbol, or your debugger   ***
  594. ***    doesn't have full symbol information.  Unqualified symbol      ***
  595. ***    resolution is turned off by default. Please either specify a   ***
  596. ***    fully qualified symbol module!symbolname, or enable resolution ***
  597. ***    of unqualified symbols by typing ".symopt- 100". Note that   ***
  598. ***    enabling unqualified symbol resolution with network symbol     ***
  599. ***    server shares in the symbol path may cause the debugger to     ***
  600. ***    appear to hang for long periods of time when an incorrect      ***
  601. ***    symbol name is typed or the network symbol server is down.     ***
  602. ***                                                                   ***
  603. ***    For some commands to work properly, your symbol path           ***
  604. ***    must point to .pdb files that have full type information.      ***
  605. ***                                                                   ***
  606. ***    Certain .pdb files (such as the public OS symbols) do not      ***
  607. ***    contain the required information.  Contact the group that      ***
  608. ***    provided you with these symbols if you need this command to    ***
  609. ***    work.                                                          ***
  610. ***                                                                   ***
  611. ***    Type referenced: nt!_KPRCB                                     ***
  612. ***                                                                   ***
  613. *************************************************************************
  614. *************************************************************************
  615. ***                                                                   ***
  616. ***                                                                   ***
  617. ***    Either you specified an unqualified symbol, or your debugger   ***
  618. ***    doesn't have full symbol information.  Unqualified symbol      ***
  619. ***    resolution is turned off by default. Please either specify a   ***
  620. ***    fully qualified symbol module!symbolname, or enable resolution ***
  621. ***    of unqualified symbols by typing ".symopt- 100". Note that   ***
  622. ***    enabling unqualified symbol resolution with network symbol     ***
  623. ***    server shares in the symbol path may cause the debugger to     ***
  624. ***    appear to hang for long periods of time when an incorrect      ***
  625. ***    symbol name is typed or the network symbol server is down.     ***
  626. ***                                                                   ***
  627. ***    For some commands to work properly, your symbol path           ***
  628. ***    must point to .pdb files that have full type information.      ***
  629. ***                                                                   ***
  630. ***    Certain .pdb files (such as the public OS symbols) do not      ***
  631. ***    contain the required information.  Contact the group that      ***
  632. ***    provided you with these symbols if you need this command to    ***
  633. ***    work.                                                          ***
  634. ***                                                                   ***
  635. ***    Type referenced: nt!_KPCR                                      ***
  636. ***                                                                   ***
  637. *************************************************************************
  638. *************************************************************************
  639. ***                                                                   ***
  640. ***                                                                   ***
  641. ***    Either you specified an unqualified symbol, or your debugger   ***
  642. ***    doesn't have full symbol information.  Unqualified symbol      ***
  643. ***    resolution is turned off by default. Please either specify a   ***
  644. ***    fully qualified symbol module!symbolname, or enable resolution ***
  645. ***    of unqualified symbols by typing ".symopt- 100". Note that   ***
  646. ***    enabling unqualified symbol resolution with network symbol     ***
  647. ***    server shares in the symbol path may cause the debugger to     ***
  648. ***    appear to hang for long periods of time when an incorrect      ***
  649. ***    symbol name is typed or the network symbol server is down.     ***
  650. ***                                                                   ***
  651. ***    For some commands to work properly, your symbol path           ***
  652. ***    must point to .pdb files that have full type information.      ***
  653. ***                                                                   ***
  654. ***    Certain .pdb files (such as the public OS symbols) do not      ***
  655. ***    contain the required information.  Contact the group that      ***
  656. ***    provided you with these symbols if you need this command to    ***
  657. ***    work.                                                          ***
  658. ***                                                                   ***
  659. ***    Type referenced: nt!_KTHREAD                                   ***
  660. ***                                                                   ***
  661. *************************************************************************
  662. *************************************************************************
  663. ***                                                                   ***
  664. ***                                                                   ***
  665. ***    Either you specified an unqualified symbol, or your debugger   ***
  666. ***    doesn't have full symbol information.  Unqualified symbol      ***
  667. ***    resolution is turned off by default. Please either specify a   ***
  668. ***    fully qualified symbol module!symbolname, or enable resolution ***
  669. ***    of unqualified symbols by typing ".symopt- 100". Note that   ***
  670. ***    enabling unqualified symbol resolution with network symbol     ***
  671. ***    server shares in the symbol path may cause the debugger to     ***
  672. ***    appear to hang for long periods of time when an incorrect      ***
  673. ***    symbol name is typed or the network symbol server is down.     ***
  674. ***                                                                   ***
  675. ***    For some commands to work properly, your symbol path           ***
  676. ***    must point to .pdb files that have full type information.      ***
  677. ***                                                                   ***
  678. ***    Certain .pdb files (such as the public OS symbols) do not      ***
  679. ***    contain the required information.  Contact the group that      ***
  680. ***    provided you with these symbols if you need this command to    ***
  681. ***    work.                                                          ***
  682. ***                                                                   ***
  683. ***    Type referenced: nt!_KPRCB                                     ***
  684. ***                                                                   ***
  685. *************************************************************************
  686. *************************************************************************
  687. ***                                                                   ***
  688. ***                                                                   ***
  689. ***    Either you specified an unqualified symbol, or your debugger   ***
  690. ***    doesn't have full symbol information.  Unqualified symbol      ***
  691. ***    resolution is turned off by default. Please either specify a   ***
  692. ***    fully qualified symbol module!symbolname, or enable resolution ***
  693. ***    of unqualified symbols by typing ".symopt- 100". Note that   ***
  694. ***    enabling unqualified symbol resolution with network symbol     ***
  695. ***    server shares in the symbol path may cause the debugger to     ***
  696. ***    appear to hang for long periods of time when an incorrect      ***
  697. ***    symbol name is typed or the network symbol server is down.     ***
  698. ***                                                                   ***
  699. ***    For some commands to work properly, your symbol path           ***
  700. ***    must point to .pdb files that have full type information.      ***
  701. ***                                                                   ***
  702. ***    Certain .pdb files (such as the public OS symbols) do not      ***
  703. ***    contain the required information.  Contact the group that      ***
  704. ***    provided you with these symbols if you need this command to    ***
  705. ***    work.                                                          ***
  706. ***                                                                   ***
  707. ***    Type referenced: nt!_KPRCB                                     ***
  708. ***                                                                   ***
  709. *************************************************************************
  710.  
  711. SYSTEM_SKU:  To be filled by O.E.M.
  712.  
  713. SYSTEM_VERSION:  To be filled by O.E.M.
  714.  
  715. BIOS_DATE:  03/18/2014
  716.  
  717. BASEBOARD_PRODUCT:  Z87X-UD3H-CF
  718.  
  719. BASEBOARD_VERSION:  x.x
  720.  
  721. ADDITIONAL_DEBUG_TEXT:  
  722.  
  723. You can run '.symfix; .reload' to try to fix the symbol path and load symbols.
  724.  
  725. WRONG_SYMBOLS_TIMESTAMP: a371a2e9
  726.  
  727. WRONG_SYMBOLS_SIZE: 1046000
  728.  
  729. FAULTING_MODULE: fffff8007be00000 nt
  730.  
  731. DEBUG_FLR_IMAGE_TIMESTAMP:  a371a2e9
  732.  
  733. BUGCHECK_P1: ffff900035b3a334
  734.  
  735. BUGCHECK_P2: 8a00000005300021
  736.  
  737. BUGCHECK_P3: ffffdc82017c6550
  738.  
  739. BUGCHECK_P4: a
  740.  
  741. CPU_COUNT: 8
  742.  
  743. CPU_MHZ: d48
  744.  
  745. CPU_VENDOR:  GenuineIntel
  746.  
  747. CPU_FAMILY: 6
  748.  
  749. CPU_MODEL: 3c
  750.  
  751. CPU_STEPPING: 3
  752.  
  753. CURRENT_IRQL:  0
  754.  
  755. ANALYSIS_VERSION: 10.0.10240.9 amd64fre
  756.  
  757. LAST_CONTROL_TRANSFER:  from fffff8007c22f11a to fffff8007c1f3ea0
  758.  
  759. STACK_TEXT:  
  760. ffffdc82`017c6358 fffff800`7c22f11a : 00000000`000000be ffff9000`35b3a334 8a000000`05300021 ffffdc82`017c6550 : nt!KeBugCheckEx
  761. ffffdc82`017c6360 fffff800`7c0eec6f : 8a000000`05300021 00000000`00000003 ffffdc82`017c65d0 00000000`00000000 : nt!memset+0x2809a
  762. ffffdc82`017c63b0 fffff800`7c20205e : ffff9000`018cda70 fffff800`7c125b72 ffff9000`018cda70 00000000`00000000 : nt!SeAccessCheckWithHint+0x37ff
  763. ffffdc82`017c6550 fffff800`7c0f9d81 : 000000fa`00000040 ffffa307`e840ed00 ffffa307`efb15740 fffff800`7ca51bf0 : nt!setjmpex+0x446e
  764. ffffdc82`017c66e0 fffff800`7c1285ba : 00000000`00067b60 00000000`00000000 00000000`001fd9ba ffff9000`05f8d2e0 : nt!SeAccessCheckWithHint+0xe911
  765. ffffdc82`017c6770 fffff800`7c111095 : 00000000`00000000 00000000`00000000 00000000`00000011 80000001`00000001 : nt!RtlAvlRemoveNode+0x3e3a
  766. ffffdc82`017c67f0 fffff800`7c151f8e : ffffa307`f2a8e850 ffffdc82`017c6918 00000000`00000000 00000000`00000000 : nt!IoGetBaseFileSystemDeviceObject+0x1345
  767. ffffdc82`017c68b0 fffff800`7c4e793e : 00000000`00088089 00000000`00000000 fffff800`7ca50b80 00000000`00088089 : nt!IoApplyPriorityInfoThread+0x42e
  768. ffffdc82`017c6910 fffff800`7c17ad04 : ffffa307`00000001 ffffa307`efb15740 00000000`00000000 00000000`00000000 : nt!CcUnpinData+0x92e
  769. ffffdc82`017c6960 fffff800`7c322f8d : 00000000`00000001 00000000`00000000 ffffdc82`017c69e0 ffffdc82`017c69e8 : nt!ExRegisterCallback+0x1e4
  770. ffffdc82`017c6990 fffff800`7c2a793b : 00000000`00000000 ffffa307`efb15740 fffff800`7ca51228 fffff800`7ca51290 : nt!KeStallWhileFrozen+0xb29d
  771. ffffdc82`017c69e0 fffff800`7c066dd5 : ffffa307`dafa1040 ffffa307`dafa1040 00000000`00000080 fffff800`7c1b8670 : nt!memset+0xa08bb
  772. ffffdc82`017c6c10 fffff800`7c1fb4f8 : ffffca80`8f1d2180 ffffa307`dafa1040 fffff800`7c066d80 00000000`00000000 : nt!RtlEndEnumerationHashTable+0x905
  773. ffffdc82`017c6c60 00000000`00000000 : ffffdc82`017c7000 ffffdc82`017c1000 00000000`00000000 00000000`00000000 : nt!KeSynchronizeExecution+0x6438
  774.  
  775.  
  776. STACK_COMMAND:  kb
  777.  
  778. FOLLOWUP_IP:
  779. nt!SeAccessCheckWithHint+37ff
  780. fffff800`7c0eec6f e90ffeffff      jmp     nt!SeAccessCheckWithHint+0x3613 (fffff800`7c0eea83)
  781.  
  782. SYMBOL_STACK_INDEX:  2
  783.  
  784. FOLLOWUP_NAME:  MachineOwner
  785.  
  786. BUGCHECK_STR:  A371A2E9
  787.  
  788. EXCEPTION_CODE: (HRESULT) 0xa371a2e9 (2742133481) - <Unable to get error code text>
  789.  
  790. FAILURE_EXCEPTION_CODE:  A371A2E9
  791.  
  792. EXCEPTION_STR:  WRONG_SYMBOLS
  793.  
  794. IMAGE_NAME:  ntoskrnl.wrong.symbols.exe
  795.  
  796. MODULE_NAME: nt_wrong_symbols
  797.  
  798. SYMBOL_NAME:  nt_wrong_symbols!A371A2E91046000
  799.  
  800. BUCKET_ID:  WRONG_SYMBOLS_X64_19041.1.amd64fre.vb_release.191206-1406_TIMESTAMP_561122-154441
  801.  
  802. DEFAULT_BUCKET_ID:  WRONG_SYMBOLS_X64_19041.1.amd64fre.vb_release.191206-1406_TIMESTAMP_561122-154441
  803.  
  804. PRIMARY_PROBLEM_CLASS:  WRONG_SYMBOLS
  805.  
  806. FAILURE_BUCKET_ID:  WRONG_SYMBOLS_X64_19041.1.amd64fre.vb_release.191206-1406_TIMESTAMP_561122-154441_A371A2E9_nt_wrong_symbols!A371A2E91046000
  807.  
  808. ANALYSIS_SOURCE:  KM
  809.  
  810. FAILURE_ID_HASH_STRING:  km:wrong_symbols_x64_19041.1.amd64fre.vb_release.191206-1406_timestamp_561122-154441_a371a2e9_nt_wrong_symbols!a371a2e91046000
  811.  
  812. FAILURE_ID_HASH:  {e49aa84d-2ad1-9204-635d-8eb9b164a458}
  813.  
  814. Followup:     MachineOwner
  815. ---------
  816.  
  817. 6: kd> !thread
  818. *************************************************************************
  819. ***                                                                   ***
  820. ***                                                                   ***
  821. ***    Either you specified an unqualified symbol, or your debugger   ***
  822. ***    doesn't have full symbol information.  Unqualified symbol      ***
  823. ***    resolution is turned off by default. Please either specify a   ***
  824. ***    fully qualified symbol module!symbolname, or enable resolution ***
  825. ***    of unqualified symbols by typing ".symopt- 100". Note that   ***
  826. ***    enabling unqualified symbol resolution with network symbol     ***
  827. ***    server shares in the symbol path may cause the debugger to     ***
  828. ***    appear to hang for long periods of time when an incorrect      ***
  829. ***    symbol name is typed or the network symbol server is down.     ***
  830. ***                                                                   ***
  831. ***    For some commands to work properly, your symbol path           ***
  832. ***    must point to .pdb files that have full type information.      ***
  833. ***                                                                   ***
  834. ***    Certain .pdb files (such as the public OS symbols) do not      ***
  835. ***    contain the required information.  Contact the group that      ***
  836. ***    provided you with these symbols if you need this command to    ***
  837. ***    work.                                                          ***
  838. ***                                                                   ***
  839. ***    Type referenced: nt!_ETHREAD                                   ***
  840. ***                                                                   ***
  841. *************************************************************************
  842. ffffa307dafa1040: Unable to get thread contents
  843. 6: kd> lm kv
  844. start             end                 module name
  845. ffff944c`38a60000 ffff944c`38afa000   win32k     (deferred)            
  846.     Image path: \SystemRoot\System32\win32k.sys
  847.     Image name: win32k.sys
  848.     Timestamp:        ***** Invalid (E87370BB)
  849.     CheckSum:         0009C34C
  850.     ImageSize:        0009A000
  851.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  852. ffff944c`38cc0000 ffff944c`38fa2000   win32kbase   (deferred)            
  853.     Image path: \SystemRoot\System32\win32kbase.sys
  854.     Image name: win32kbase.sys
  855.     Timestamp:        ***** Invalid (883B3E7C)
  856.     CheckSum:         002DB69F
  857.     ImageSize:        002E2000
  858.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  859. ffff944c`39000000 ffff944c`39048000   cdd        (deferred)            
  860.     Image path: \SystemRoot\System32\cdd.dll
  861.     Image name: cdd.dll
  862.     Timestamp:        Mon Jan 22 05:06:28 1996 (31038BD4)
  863.     CheckSum:         0004D704
  864.     ImageSize:        00048000
  865.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  866. ffff944c`39c10000 ffff944c`39fc6000   win32kfull   (deferred)            
  867.     Image path: \SystemRoot\System32\win32kfull.sys
  868.     Image name: win32kfull.sys
  869.     Timestamp:        ***** Invalid (EBAA7588)
  870.     CheckSum:         003A7C43
  871.     ImageSize:        003B6000
  872.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  873. fffff800`7ac10000 fffff800`7ae9f000   mcupdate_GenuineIntel   (deferred)            
  874.     Image path: \SystemRoot\system32\mcupdate_GenuineIntel.dll
  875.     Image name: mcupdate_GenuineIntel.dll
  876.     Timestamp:        ***** Invalid (9FB1DE46)
  877.     CheckSum:         0028C60B
  878.     ImageSize:        0028F000
  879.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  880. fffff800`7aea0000 fffff800`7aea6000   hal        (deferred)            
  881.     Image path: hal.dll
  882.     Image name: hal.dll
  883.     Timestamp:        Mon Jan 30 08:29:29 1984 (1A7BE8E9)
  884.     CheckSum:         0000CE9F
  885.     ImageSize:        00006000
  886.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  887. fffff800`7aeb0000 fffff800`7aebb000   kd         (deferred)            
  888.     Image path: \SystemRoot\system32\kd.dll
  889.     Image name: kd.dll
  890.     Timestamp:        ***** Invalid (FE185FA8)
  891.     CheckSum:         00004EF6
  892.     ImageSize:        0000B000
  893.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  894. fffff800`7aec0000 fffff800`7aee7000   tm         (deferred)            
  895.     Image path: \SystemRoot\System32\drivers\tm.sys
  896.     Image name: tm.sys
  897.     Timestamp:        Thu Nov 24 15:38:59 2011 (4ECED593)
  898.     CheckSum:         00029C42
  899.     ImageSize:        00027000
  900.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  901. fffff800`7aef0000 fffff800`7af59000   CLFS       (deferred)            
  902.     Image path: \SystemRoot\System32\drivers\CLFS.SYS
  903.     Image name: CLFS.SYS
  904.     Timestamp:        Fri Dec 30 13:11:01 2005 (43B5A265)
  905.     CheckSum:         0006BD72
  906.     ImageSize:        00069000
  907.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  908. fffff800`7af60000 fffff800`7af7a000   PSHED      (deferred)            
  909.     Image path: \SystemRoot\system32\PSHED.dll
  910.     Image name: PSHED.dll
  911.     Timestamp:        Sun Aug 01 12:44:09 2010 (4C55DC99)
  912.     CheckSum:         000201A9
  913.     ImageSize:        0001A000
  914.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  915. fffff800`7af80000 fffff800`7af8b000   BOOTVID    (deferred)            
  916.     Image path: \SystemRoot\system32\BOOTVID.dll
  917.     Image name: BOOTVID.dll
  918.     Timestamp:        ***** Invalid (D13EE5B6)
  919.     CheckSum:         00013A3C
  920.     ImageSize:        0000B000
  921.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  922. fffff800`7af90000 fffff800`7afff000   FLTMGR     (deferred)            
  923.     Image path: \SystemRoot\System32\drivers\FLTMGR.SYS
  924.     Image name: FLTMGR.SYS
  925.     Timestamp:        Mon May 03 20:30:30 1971 (02839B66)
  926.     CheckSum:         00072E12
  927.     ImageSize:        0006F000
  928.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  929. fffff800`7b000000 fffff800`7b00e000   cmimcext   (deferred)            
  930.     Image path: \SystemRoot\System32\drivers\cmimcext.sys
  931.     Image name: cmimcext.sys
  932.     Timestamp:        ***** Invalid (94809681)
  933.     CheckSum:         00010F8E
  934.     ImageSize:        0000E000
  935.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  936. fffff800`7be00000 fffff800`7ce46000   nt         (export symbols)       ntkrnlmp.exe
  937.     Loaded symbol image file: ntkrnlmp.exe
  938.     Image path: ntkrnlmp.exe
  939.     Image name: ntkrnlmp.exe
  940.     Timestamp:        ***** Invalid (A371A2E9)
  941.     CheckSum:         00A611D3
  942.     ImageSize:        01046000
  943.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  944. fffff800`7eba0000 fffff800`7ebeb000   klupd_KLIF_klark   (deferred)            
  945.     Image path: \SystemRoot\System32\Drivers\klupd_KLIF_klark.sys
  946.     Image name: klupd_KLIF_klark.sys
  947.     Timestamp:        Wed Mar 24 02:58:59 2021 (605B1B73)
  948.     CheckSum:         00054599
  949.     ImageSize:        0004B000
  950.     File version:     4.7.3.0
  951.     Product version:  4.7.3.0
  952.     File flags:       0 (Mask 3F)
  953.     File OS:          40004 NT Win32
  954.     File type:        2.0 Dll
  955.     File date:        00000000.00000000
  956.     Translations:     0409.04b0
  957.     CompanyName:      AO Kaspersky Lab
  958.     ProductName:      Kaspersky Bases
  959.     InternalName:     klark
  960.     OriginalFilename: klark.sys
  961.     ProductVersion:   4.7.3.0
  962.     FileVersion:      4.7.3.0
  963.     FileDescription:  Kaspersky Lab Anti-Rootkit
  964.     LegalCopyright:   © 2021 AO Kaspersky Lab. All Rights Reserved.
  965.     LegalTrademarks:  Registered trademarks and service marks are the property of their respective owners
  966. fffff800`80600000 fffff800`80713000   clipsp     (deferred)            
  967.     Image path: \SystemRoot\System32\drivers\clipsp.sys
  968.     Image name: clipsp.sys
  969.     Timestamp:        Tue Sep 01 15:19:42 2020 (5F4ED70E)
  970.     CheckSum:         0011953D
  971.     ImageSize:        00113000
  972.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  973. fffff800`80720000 fffff800`80749000   ksecdd     (deferred)            
  974.     Image path: \SystemRoot\System32\drivers\ksecdd.sys
  975.     Image name: ksecdd.sys
  976.     Timestamp:        Fri Sep 25 14:37:08 2020 (5F6E7114)
  977.     CheckSum:         0002AB02
  978.     ImageSize:        00029000
  979.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  980. fffff800`80750000 fffff800`807b2000   msrpc      (deferred)            
  981.     Image path: \SystemRoot\System32\drivers\msrpc.sys
  982.     Image name: msrpc.sys
  983.     Timestamp:        ***** Invalid (BD46698A)
  984.     CheckSum:         00062C96
  985.     ImageSize:        00062000
  986.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  987. fffff800`807c0000 fffff800`807d1000   werkernel   (deferred)            
  988.     Image path: \SystemRoot\System32\drivers\werkernel.sys
  989.     Image name: werkernel.sys
  990.     Timestamp:        Wed Oct 17 15:21:51 1984 (1BD4610F)
  991.     CheckSum:         0000F1D5
  992.     ImageSize:        00011000
  993.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  994. fffff800`807e0000 fffff800`807ec000   ntosext    (deferred)            
  995.     Image path: \SystemRoot\System32\drivers\ntosext.sys
  996.     Image name: ntosext.sys
  997.     Timestamp:        Sun Jul 14 21:39:43 2030 (71DD3C9F)
  998.     CheckSum:         00009677
  999.     ImageSize:        0000C000
  1000.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1001. fffff800`807f0000 fffff800`808d3000   CI         (deferred)            
  1002.     Image path: \SystemRoot\system32\CI.dll
  1003.     Image name: CI.dll
  1004.     Timestamp:        ***** Invalid (8BECF5E0)
  1005.     CheckSum:         000E72BB
  1006.     ImageSize:        000E3000
  1007.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1008. fffff800`808e0000 fffff800`80997000   cng        (deferred)            
  1009.     Image path: \SystemRoot\System32\drivers\cng.sys
  1010.     Image name: cng.sys
  1011.     Timestamp:        Tue May 30 08:27:56 1989 (2482C10C)
  1012.     CheckSum:         000B7883
  1013.     ImageSize:        000B7000
  1014.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1015. fffff800`809a0000 fffff800`80a71000   Wdf01000   (deferred)            
  1016.     Image path: \SystemRoot\system32\drivers\Wdf01000.sys
  1017.     Image name: Wdf01000.sys
  1018.     Timestamp:        ***** Invalid (A9A9D36E)
  1019.     CheckSum:         000D3980
  1020.     ImageSize:        000D1000
  1021.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1022. fffff800`80a80000 fffff800`80a93000   WDFLDR     (deferred)            
  1023.     Image path: \SystemRoot\system32\drivers\WDFLDR.SYS
  1024.     Image name: WDFLDR.SYS
  1025.     Timestamp:        ***** Invalid (977C0BBB)
  1026.     CheckSum:         00013DC3
  1027.     ImageSize:        00013000
  1028.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1029. fffff800`80aa0000 fffff800`80aaf000   SleepStudyHelper   (deferred)            
  1030.     Image path: \SystemRoot\system32\drivers\SleepStudyHelper.sys
  1031.     Image name: SleepStudyHelper.sys
  1032.     Timestamp:        Thu May 23 08:28:59 2024 (664F6ECB)
  1033.     CheckSum:         0000FC58
  1034.     ImageSize:        0000F000
  1035.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1036. fffff800`80ab0000 fffff800`80ac1000   WppRecorder   (deferred)            
  1037.     Image path: \SystemRoot\system32\drivers\WppRecorder.sys
  1038.     Image name: WppRecorder.sys
  1039.     Timestamp:        Fri Mar 06 01:14:40 1981 (15060D00)
  1040.     CheckSum:         0001415E
  1041.     ImageSize:        00011000
  1042.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1043. fffff800`80ad0000 fffff800`80af6000   acpiex     (deferred)            
  1044.     Image path: \SystemRoot\System32\Drivers\acpiex.sys
  1045.     Image name: acpiex.sys
  1046.     Timestamp:        ***** Invalid (C8D60B44)
  1047.     CheckSum:         000302D2
  1048.     ImageSize:        00026000
  1049.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1050. fffff800`80b00000 fffff800`80b4b000   mssecflt   (deferred)            
  1051.     Image path: \SystemRoot\system32\drivers\mssecflt.sys
  1052.     Image name: mssecflt.sys
  1053.     Timestamp:        ***** Invalid (A0E0786E)
  1054.     CheckSum:         0004FC86
  1055.     ImageSize:        0004B000
  1056.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1057. fffff800`80b50000 fffff800`80b6a000   SgrmAgent   (deferred)            
  1058.     Image path: \SystemRoot\system32\drivers\SgrmAgent.sys
  1059.     Image name: SgrmAgent.sys
  1060.     Timestamp:        ***** Invalid (A6474774)
  1061.     CheckSum:         0001E4FC
  1062.     ImageSize:        0001A000
  1063.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1064. fffff800`80b70000 fffff800`80c3c000   ACPI       (deferred)            
  1065.     Image path: \SystemRoot\System32\drivers\ACPI.sys
  1066.     Image name: ACPI.sys
  1067.     Timestamp:        Thu Feb 10 11:30:37 1994 (2D5A8B5D)
  1068.     CheckSum:         000D341C
  1069.     ImageSize:        000CC000
  1070.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1071. fffff800`80c40000 fffff800`80c4c000   WMILIB     (deferred)            
  1072.     Image path: \SystemRoot\System32\drivers\WMILIB.SYS
  1073.     Image name: WMILIB.SYS
  1074.     Timestamp:        ***** Invalid (CD518505)
  1075.     CheckSum:         00009CB9
  1076.     ImageSize:        0000C000
  1077.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1078. fffff800`80c60000 fffff800`80ccb000   intelpep   (deferred)            
  1079.     Image path: \SystemRoot\System32\drivers\intelpep.sys
  1080.     Image name: intelpep.sys
  1081.     Timestamp:        ***** Invalid (81D95014)
  1082.     CheckSum:         0007468F
  1083.     ImageSize:        0006B000
  1084.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1085. fffff800`80cd0000 fffff800`80ce7000   WindowsTrustedRT   (deferred)            
  1086.     Image path: \SystemRoot\system32\drivers\WindowsTrustedRT.sys
  1087.     Image name: WindowsTrustedRT.sys
  1088.     Timestamp:        Sat May 19 00:53:30 2035 (7AF9978A)
  1089.     CheckSum:         0001BFFA
  1090.     ImageSize:        00017000
  1091.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1092. fffff800`80cf0000 fffff800`80cfb000   IntelTA    (deferred)            
  1093.     Image path: \SystemRoot\System32\drivers\IntelTA.sys
  1094.     Image name: IntelTA.sys
  1095.     Timestamp:        ***** Invalid (AFECFEC8)
  1096.     CheckSum:         00008349
  1097.     ImageSize:        0000B000
  1098.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1099. fffff800`80d00000 fffff800`80d0b000   WindowsTrustedRTProxy   (deferred)            
  1100.     Image path: \SystemRoot\System32\drivers\WindowsTrustedRTProxy.sys
  1101.     Image name: WindowsTrustedRTProxy.sys
  1102.     Timestamp:        ***** Invalid (AA5F5790)
  1103.     CheckSum:         00007869
  1104.     ImageSize:        0000B000
  1105.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1106. fffff800`80d10000 fffff800`80d24000   pcw        (deferred)            
  1107.     Image path: \SystemRoot\System32\drivers\pcw.sys
  1108.     Image name: pcw.sys
  1109.     Timestamp:        ***** Invalid (D212A83E)
  1110.     CheckSum:         000163F7
  1111.     ImageSize:        00014000
  1112.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1113. fffff800`80d30000 fffff800`80d70000   klupd_klif_arkmon   (deferred)            
  1114.     Image path: \SystemRoot\system32\DRIVERS\klupd_klif_arkmon.sys
  1115.     Image name: klupd_klif_arkmon.sys
  1116.     Timestamp:        Wed Mar 24 02:36:11 2021 (605B161B)
  1117.     CheckSum:         00043547
  1118.     ImageSize:        00040000
  1119.     File version:     2.7.4.0
  1120.     Product version:  2.7.4.0
  1121.     File flags:       0 (Mask 3F)
  1122.     File OS:          40004 NT Win32
  1123.     File type:        2.0 Dll
  1124.     File date:        00000000.00000000
  1125.     Translations:     0409.04b0
  1126.     CompanyName:      AO Kaspersky Lab
  1127.     ProductName:      Kaspersky Bases
  1128.     InternalName:     arkmon
  1129.     OriginalFilename: arkmon.sys
  1130.     ProductVersion:   2.7.4.0
  1131.     FileVersion:      2.7.4.0
  1132.     FileDescription:  Kaspersky Lab Anti-Rootkit Monitor Driver
  1133.     LegalCopyright:   © 2021 AO Kaspersky Lab. All Rights Reserved.
  1134.     LegalTrademarks:  Registered trademarks and service marks are the property of their respective owners
  1135. fffff800`80d80000 fffff800`80d8b000   msisadrv   (deferred)            
  1136.     Image path: \SystemRoot\System32\drivers\msisadrv.sys
  1137.     Image name: msisadrv.sys
  1138.     Timestamp:        ***** Invalid (D84D625E)
  1139.     CheckSum:         0000B688
  1140.     ImageSize:        0000B000
  1141.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1142. fffff800`80d90000 fffff800`80da5000   vdrvroot   (deferred)            
  1143.     Image path: \SystemRoot\System32\drivers\vdrvroot.sys
  1144.     Image name: vdrvroot.sys
  1145.     Timestamp:        ***** Invalid (E613EBA7)
  1146.     CheckSum:         000184EC
  1147.     ImageSize:        00015000
  1148.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1149. fffff800`80db0000 fffff800`80ddf000   pdc        (deferred)            
  1150.     Image path: \SystemRoot\system32\drivers\pdc.sys
  1151.     Image name: pdc.sys
  1152.     Timestamp:        Sat May 26 23:23:12 1984 (1B16F9E0)
  1153.     CheckSum:         000324F1
  1154.     ImageSize:        0002F000
  1155.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1156. fffff800`80de0000 fffff800`80df9000   CEA        (deferred)            
  1157.     Image path: \SystemRoot\system32\drivers\CEA.sys
  1158.     Image name: CEA.sys
  1159.     Timestamp:        Thu Jun 10 08:40:49 2032 (75736B91)
  1160.     CheckSum:         00022BC5
  1161.     ImageSize:        00019000
  1162.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1163. fffff800`80e00000 fffff800`80e78000   pci        (deferred)            
  1164.     Image path: \SystemRoot\System32\drivers\pci.sys
  1165.     Image name: pci.sys
  1166.     Timestamp:        Wed Jul 29 03:09:24 2037 (7F1B0A64)
  1167.     CheckSum:         0007F6EF
  1168.     ImageSize:        00078000
  1169.     File version:     10.0.19041.488
  1170.     Product version:  10.0.19041.488
  1171.     File flags:       0 (Mask 3F)
  1172.     File OS:          40004 NT Win32
  1173.     File type:        2.0 Dll
  1174.     File date:        00000000.00000000
  1175.     Translations:     0409.04b0
  1176.     CompanyName:      Microsoft Corporation
  1177.     ProductName:      Microsoft® Windows® Operating System
  1178.     InternalName:     pci.sys
  1179.     OriginalFilename: pci.sys
  1180.     ProductVersion:   10.0.19041.488
  1181.     FileVersion:      10.0.19041.488 (WinBuild.160101.0800)
  1182.     FileDescription:  NT Plug and Play PCI Enumerator
  1183.     LegalCopyright:   © Microsoft Corporation. All rights reserved.
  1184. fffff800`80e80000 fffff800`80eb1000   partmgr    (deferred)            
  1185.     Image path: \SystemRoot\System32\drivers\partmgr.sys
  1186.     Image name: partmgr.sys
  1187.     Timestamp:        Sat Aug 06 18:26:06 2016 (57A69C3E)
  1188.     CheckSum:         0002D745
  1189.     ImageSize:        00031000
  1190.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1191. fffff800`80ec0000 fffff800`80f6a000   spaceport   (deferred)            
  1192.     Image path: \SystemRoot\System32\drivers\spaceport.sys
  1193.     Image name: spaceport.sys
  1194.     Timestamp:        ***** Invalid (ABAEDF84)
  1195.     CheckSum:         000B3A4F
  1196.     ImageSize:        000AA000
  1197.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1198. fffff800`80f70000 fffff800`80f89000   volmgr     (deferred)            
  1199.     Image path: \SystemRoot\System32\drivers\volmgr.sys
  1200.     Image name: volmgr.sys
  1201.     Timestamp:        Thu Nov 20 06:06:06 2025 (691F204E)
  1202.     CheckSum:         00021FF2
  1203.     ImageSize:        00019000
  1204.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1205. fffff800`80f90000 fffff800`80ff3000   volmgrx    (deferred)            
  1206.     Image path: \SystemRoot\System32\drivers\volmgrx.sys
  1207.     Image name: volmgrx.sys
  1208.     Timestamp:        Fri Nov 29 10:04:07 2013 (5298D717)
  1209.     CheckSum:         0006AB53
  1210.     ImageSize:        00063000
  1211.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1212. fffff800`81000000 fffff800`8101e000   mountmgr   (deferred)            
  1213.     Image path: \SystemRoot\System32\drivers\mountmgr.sys
  1214.     Image name: mountmgr.sys
  1215.     Timestamp:        Fri May 11 14:20:58 2029 (6FA7424A)
  1216.     CheckSum:         00024BD0
  1217.     ImageSize:        0001E000
  1218.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1219. fffff800`81020000 fffff800`810b5000   mvs91xx    (deferred)            
  1220.     Image path: \SystemRoot\System32\drivers\mvs91xx.sys
  1221.     Image name: mvs91xx.sys
  1222.     Timestamp:        Tue Jan 19 21:47:12 2016 (569F1F60)
  1223.     CheckSum:         000577B0
  1224.     ImageSize:        00095000
  1225.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1226. fffff800`810c0000 fffff800`81170000   storport   (deferred)            
  1227.     Image path: \SystemRoot\System32\drivers\storport.sys
  1228.     Image name: storport.sys
  1229.     Timestamp:        ***** Invalid (8566CB6A)
  1230.     CheckSum:         000B9B99
  1231.     ImageSize:        000B0000
  1232.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1233. fffff800`81180000 fffff800`81188000   mvxxmm     (deferred)            
  1234.     Image path: \SystemRoot\System32\drivers\mvxxmm.sys
  1235.     Image name: mvxxmm.sys
  1236.     Timestamp:        Tue Jan 19 21:46:43 2016 (569F1F43)
  1237.     CheckSum:         0000BA29
  1238.     ImageSize:        00008000
  1239.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1240. fffff800`81190000 fffff800`812bf000   iaStorE    (deferred)            
  1241.     Image path: \SystemRoot\System32\drivers\iaStorE.sys
  1242.     Image name: iaStorE.sys
  1243.     Timestamp:        Mon Jan 13 13:05:06 2020 (5E1CDB82)
  1244.     CheckSum:         00110008
  1245.     ImageSize:        0012F000
  1246.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1247. fffff800`812e0000 fffff800`812fa000   fileinfo   (deferred)            
  1248.     Image path: \SystemRoot\System32\drivers\fileinfo.sys
  1249.     Image name: fileinfo.sys
  1250.     Timestamp:        ***** Invalid (AEE275C2)
  1251.     CheckSum:         0002169B
  1252.     ImageSize:        0001A000
  1253.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1254. fffff800`81300000 fffff800`81340000   Wof        (deferred)            
  1255.     Image path: \SystemRoot\System32\Drivers\Wof.sys
  1256.     Image name: Wof.sys
  1257.     Timestamp:        ***** Invalid (97F984C4)
  1258.     CheckSum:         0003D008
  1259.     ImageSize:        00040000
  1260.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1261. fffff800`81350000 fffff800`81629000   Ntfs       (deferred)            
  1262.     Image path: \SystemRoot\System32\Drivers\Ntfs.sys
  1263.     Image name: Ntfs.sys
  1264.     Timestamp:        Sun Dec 21 22:54:01 1997 (349E0E89)
  1265.     CheckSum:         002C1FB0
  1266.     ImageSize:        002D9000
  1267.     File version:     10.0.19041.508
  1268.     Product version:  10.0.19041.508
  1269.     File flags:       0 (Mask 3F)
  1270.     File OS:          40004 NT Win32
  1271.     File type:        3.7 Driver
  1272.     File date:        00000000.00000000
  1273.     Translations:     0409.04b0
  1274.     CompanyName:      Microsoft Corporation
  1275.     ProductName:      Microsoft® Windows® Operating System
  1276.     InternalName:     ntfs.sys
  1277.     OriginalFilename: ntfs.sys
  1278.     ProductVersion:   10.0.19041.508
  1279.     FileVersion:      10.0.19041.508 (WinBuild.160101.0800)
  1280.     FileDescription:  NT File System Driver
  1281.     LegalCopyright:   © Microsoft Corporation. All rights reserved.
  1282. fffff800`81630000 fffff800`8163d000   Fs_Rec     (deferred)            
  1283.     Image path: \SystemRoot\System32\Drivers\Fs_Rec.sys
  1284.     Image name: Fs_Rec.sys
  1285.     Timestamp:        ***** Invalid (B9E5C55C)
  1286.     CheckSum:         00017B4B
  1287.     ImageSize:        0000D000
  1288.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1289. fffff800`81640000 fffff800`817af000   ndis       (deferred)            
  1290.     Image path: \SystemRoot\system32\drivers\ndis.sys
  1291.     Image name: ndis.sys
  1292.     Timestamp:        ***** Invalid (A3B0E6FE)
  1293.     CheckSum:         0016EB12
  1294.     ImageSize:        0016F000
  1295.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1296. fffff800`817b0000 fffff800`81848000   NETIO      (deferred)            
  1297.     Image path: \SystemRoot\system32\drivers\NETIO.SYS
  1298.     Image name: NETIO.SYS
  1299.     Timestamp:        Wed Jul 22 02:46:16 2015 (55AF7478)
  1300.     CheckSum:         000A160A
  1301.     ImageSize:        00098000
  1302.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1303. fffff800`81850000 fffff800`81882000   ksecpkg    (deferred)            
  1304.     Image path: \SystemRoot\System32\Drivers\ksecpkg.sys
  1305.     Image name: ksecpkg.sys
  1306.     Timestamp:        ***** Invalid (EB0A8339)
  1307.     CheckSum:         0002E880
  1308.     ImageSize:        00032000
  1309.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1310. fffff800`81890000 fffff800`81b7c000   tcpip      (deferred)            
  1311.     Image path: \SystemRoot\System32\drivers\tcpip.sys
  1312.     Image name: tcpip.sys
  1313.     Timestamp:        ***** Invalid (9976B086)
  1314.     CheckSum:         002E509B
  1315.     ImageSize:        002EC000
  1316.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1317. fffff800`81b80000 fffff800`81bff000   fwpkclnt   (deferred)            
  1318.     Image path: \SystemRoot\System32\drivers\fwpkclnt.sys
  1319.     Image name: fwpkclnt.sys
  1320.     Timestamp:        Wed Dec 18 17:08:15 1985 (1E076A7F)
  1321.     CheckSum:         0007F498
  1322.     ImageSize:        0007F000
  1323.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1324. fffff800`81c00000 fffff800`81c30000   wfplwfs    (deferred)            
  1325.     Image path: \SystemRoot\System32\drivers\wfplwfs.sys
  1326.     Image name: wfplwfs.sys
  1327.     Timestamp:        Mon Mar 31 19:31:38 1997 (3340819A)
  1328.     CheckSum:         00035119
  1329.     ImageSize:        00030000
  1330.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1331. fffff800`81c40000 fffff800`81d09000   fvevol     (deferred)            
  1332.     Image path: \SystemRoot\System32\DRIVERS\fvevol.sys
  1333.     Image name: fvevol.sys
  1334.     Timestamp:        Sat Nov 26 02:24:12 1994 (2ED70CCC)
  1335.     CheckSum:         000C5DEF
  1336.     ImageSize:        000C9000
  1337.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1338. fffff800`81d10000 fffff800`81d1c000   apmwin     (deferred)            
  1339.     Image path: \SystemRoot\system32\DRIVERS\apmwin.sys
  1340.     Image name: apmwin.sys
  1341.     Timestamp:        Wed Dec 28 01:12:34 2016 (58638202)
  1342.     CheckSum:         00012FAA
  1343.     ImageSize:        0000C000
  1344.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1345. fffff800`81d20000 fffff800`81d33000   gpt_loader   (deferred)            
  1346.     Image path: \SystemRoot\system32\DRIVERS\gpt_loader.sys
  1347.     Image name: gpt_loader.sys
  1348.     Timestamp:        Wed Dec 28 01:12:24 2016 (586381F8)
  1349.     CheckSum:         00014F27
  1350.     ImageSize:        00013000
  1351.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1352. fffff800`81d40000 fffff800`81d4f000   mounthlp   (deferred)            
  1353.     Image path: \SystemRoot\system32\DRIVERS\mounthlp.sys
  1354.     Image name: mounthlp.sys
  1355.     Timestamp:        Wed Dec 28 01:12:27 2016 (586381FB)
  1356.     CheckSum:         0000FBFA
  1357.     ImageSize:        0000F000
  1358.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1359. fffff800`81d50000 fffff800`81d5b000   volume     (deferred)            
  1360.     Image path: \SystemRoot\System32\drivers\volume.sys
  1361.     Image name: volume.sys
  1362.     Timestamp:        ***** Invalid (83CF10C9)
  1363.     CheckSum:         000083D7
  1364.     ImageSize:        0000B000
  1365.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1366. fffff800`81d60000 fffff800`81dcd000   volsnap    (deferred)            
  1367.     Image path: \SystemRoot\System32\drivers\volsnap.sys
  1368.     Image name: volsnap.sys
  1369.     Timestamp:        ***** Invalid (8AFD80F6)
  1370.     CheckSum:         00077353
  1371.     ImageSize:        0006D000
  1372.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1373. fffff800`81dd0000 fffff800`81e20000   rdyboost   (deferred)            
  1374.     Image path: \SystemRoot\System32\drivers\rdyboost.sys
  1375.     Image name: rdyboost.sys
  1376.     Timestamp:        Fri Feb 25 08:44:32 2033 (76CA3270)
  1377.     CheckSum:         00048E48
  1378.     ImageSize:        00050000
  1379.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1380. fffff800`81e30000 fffff800`81e56000   mup        (deferred)            
  1381.     Image path: \SystemRoot\System32\Drivers\mup.sys
  1382.     Image name: mup.sys
  1383.     Timestamp:        ***** Invalid (FB1EDB95)
  1384.     CheckSum:         0002B433
  1385.     ImageSize:        00026000
  1386.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1387. fffff800`81e60000 fffff800`81e79000   klupd_KLIF_klbg   (deferred)            
  1388.     Image path: \SystemRoot\System32\Drivers\klupd_KLIF_klbg.sys
  1389.     Image name: klupd_KLIF_klbg.sys
  1390.     Timestamp:        Wed Mar 24 02:58:58 2021 (605B1B72)
  1391.     CheckSum:         000257EF
  1392.     ImageSize:        00019000
  1393.     File version:     11.7.3.0
  1394.     Product version:  11.7.3.0
  1395.     File flags:       0 (Mask 3F)
  1396.     File OS:          40004 NT Win32
  1397.     File type:        2.0 Dll
  1398.     File date:        00000000.00000000
  1399.     Translations:     0409.04b0
  1400.     CompanyName:      AO Kaspersky Lab
  1401.     ProductName:      Kaspersky Bases
  1402.     InternalName:     klbg
  1403.     OriginalFilename: klbg.sys
  1404.     ProductVersion:   11.7.3.0
  1405.     FileVersion:      11.7.3.0
  1406.     FileDescription:  Kaspersky Lab Boot Guard Driver
  1407.     LegalCopyright:   © 2021 AO Kaspersky Lab. All Rights Reserved.
  1408.     LegalTrademarks:  Registered trademarks and service marks are the property of their respective owners
  1409. fffff800`81e80000 fffff800`81e92000   iorate     (deferred)            
  1410.     Image path: \SystemRoot\system32\drivers\iorate.sys
  1411.     Image name: iorate.sys
  1412.     Timestamp:        ***** Invalid (94A693A6)
  1413.     CheckSum:         0001BF87
  1414.     ImageSize:        00012000
  1415.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1416. fffff800`81ea0000 fffff800`81eab000   iaStorF    (deferred)            
  1417.     Image path: \SystemRoot\System32\drivers\iaStorF.sys
  1418.     Image name: iaStorF.sys
  1419.     Timestamp:        Fri Nov 24 02:31:28 2017 (5A17F500)
  1420.     CheckSum:         00016CC4
  1421.     ImageSize:        0000B000
  1422.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1423. fffff800`81ed0000 fffff800`81eec000   disk       (deferred)            
  1424.     Image path: \SystemRoot\System32\drivers\disk.sys
  1425.     Image name: disk.sys
  1426.     Timestamp:        Tue Feb 01 17:11:22 1994 (2D4EFDBA)
  1427.     CheckSum:         00020B81
  1428.     ImageSize:        0001C000
  1429.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1430. fffff800`81ef0000 fffff800`81f5c000   CLASSPNP   (deferred)            
  1431.     Image path: \SystemRoot\System32\drivers\CLASSPNP.SYS
  1432.     Image name: CLASSPNP.SYS
  1433.     Timestamp:        Tue Jun 30 09:16:26 1981 (159F6BEA)
  1434.     CheckSum:         0006AD87
  1435.     ImageSize:        0006C000
  1436.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1437. fffff800`82400000 fffff800`824d6000   peauth     (deferred)            
  1438.     Image path: \SystemRoot\system32\drivers\peauth.sys
  1439.     Image name: peauth.sys
  1440.     Timestamp:        Thu Jun 30 12:25:54 1977 (0E1978D2)
  1441.     CheckSum:         000CAE00
  1442.     ImageSize:        000D6000
  1443.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1444. fffff800`824e0000 fffff800`824fc000   rassstp    (deferred)            
  1445.     Image path: \SystemRoot\System32\drivers\rassstp.sys
  1446.     Image name: rassstp.sys
  1447.     Timestamp:        Fri Feb 01 21:39:06 2002 (3C5B7B7A)
  1448.     CheckSum:         0001D4E6
  1449.     ImageSize:        0001C000
  1450.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1451. fffff800`82500000 fffff800`8251d000   NDProxy    (deferred)            
  1452.     Image path: \SystemRoot\System32\DRIVERS\NDProxy.sys
  1453.     Image name: NDProxy.sys
  1454.     Timestamp:        ***** Invalid (D564EC29)
  1455.     CheckSum:         00022253
  1456.     ImageSize:        0001D000
  1457.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1458. fffff800`82520000 fffff800`82547000   AgileVpn   (deferred)            
  1459.     Image path: \SystemRoot\System32\drivers\AgileVpn.sys
  1460.     Image name: AgileVpn.sys
  1461.     Timestamp:        ***** Invalid (F4378452)
  1462.     CheckSum:         00023624
  1463.     ImageSize:        00027000
  1464.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1465. fffff800`82550000 fffff800`82568000   uaspstor   (deferred)            
  1466.     Image path: \SystemRoot\System32\drivers\uaspstor.sys
  1467.     Image name: uaspstor.sys
  1468.     Timestamp:        Thu Jun 24 20:11:29 2004 (40DBA5F1)
  1469.     CheckSum:         0001535A
  1470.     ImageSize:        00018000
  1471.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1472. fffff800`82570000 fffff800`82589000   klbackupdisk   (deferred)            
  1473.     Image path: \SystemRoot\system32\DRIVERS\klbackupdisk.sys
  1474.     Image name: klbackupdisk.sys
  1475.     Timestamp:        Mon Jan 25 08:51:07 2021 (600EF6FB)
  1476.     CheckSum:         00029377
  1477.     ImageSize:        00019000
  1478.     File version:     30.587.0.170
  1479.     Product version:  30.587.0.170
  1480.     File flags:       0 (Mask 3F)
  1481.     File OS:          40004 NT Win32
  1482.     File type:        2.0 Dll
  1483.     File date:        00000000.00000000
  1484.     Translations:     0409.04b0
  1485.     CompanyName:      AO Kaspersky Lab
  1486.     ProductName:      Coretech Delivery
  1487.     InternalName:     klbackupdisk
  1488.     ProductVersion:   30.587.0.170-e30f0c58d6
  1489.     FileVersion:      30.587.0.170
  1490.     FileDescription:  Backup Disk Filter [fre_win7_x64]
  1491.     LegalCopyright:   © 2021 AO Kaspersky Lab. All Rights Reserved.
  1492.     LegalTrademarks:  Registered trademarks and service marks are the property of their respective owners
  1493. fffff800`82590000 fffff800`825c0000   cdrom      (deferred)            
  1494.     Image path: \SystemRoot\System32\drivers\cdrom.sys
  1495.     Image name: cdrom.sys
  1496.     Timestamp:        ***** Invalid (D4B31131)
  1497.     CheckSum:         000346A0
  1498.     ImageSize:        00030000
  1499.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1500. fffff800`825d0000 fffff800`8265a000   klflt      (deferred)            
  1501.     Image path: \SystemRoot\system32\DRIVERS\klflt.sys
  1502.     Image name: klflt.sys
  1503.     Timestamp:        Fri Feb 19 05:50:35 2021 (602FC22B)
  1504.     CheckSum:         00088DDE
  1505.     ImageSize:        0008A000
  1506.     File version:     30.587.0.1070
  1507.     Product version:  30.587.0.1070
  1508.     File flags:       0 (Mask 3F)
  1509.     File OS:          40004 NT Win32
  1510.     File type:        2.0 Dll
  1511.     File date:        00000000.00000000
  1512.     Translations:     0409.04b0
  1513.     CompanyName:      AO Kaspersky Lab
  1514.     ProductName:      Coretech Delivery
  1515.     InternalName:     klflt
  1516.     ProductVersion:   30.587.0.1070-a81ac642e3
  1517.     FileVersion:      30.587.0.1070
  1518.     FileDescription:  Filter Core [fre_win7_x64]
  1519.     LegalCopyright:   © 2021 AO Kaspersky Lab. All Rights Reserved.
  1520.     LegalTrademarks:  Registered trademarks and service marks are the property of their respective owners
  1521. fffff800`82660000 fffff800`82691000   klbackupflt   (deferred)            
  1522.     Image path: \SystemRoot\system32\DRIVERS\klbackupflt.sys
  1523.     Image name: klbackupflt.sys
  1524.     Timestamp:        Fri Feb 05 16:46:23 2021 (601DE6DF)
  1525.     CheckSum:         00037AFC
  1526.     ImageSize:        00031000
  1527.     File version:     30.587.0.810
  1528.     Product version:  30.587.0.810
  1529.     File flags:       0 (Mask 3F)
  1530.     File OS:          40004 NT Win32
  1531.     File type:        2.0 Dll
  1532.     File date:        00000000.00000000
  1533.     Translations:     0409.04b0
  1534.     CompanyName:      AO Kaspersky Lab
  1535.     ProductName:      Coretech Delivery
  1536.     InternalName:     klbackupflt
  1537.     ProductVersion:   30.587.0.810-636fda9fe5
  1538.     FileVersion:      30.587.0.810
  1539.     FileDescription:  Backup File Filter [fre_win7_x64]
  1540.     LegalCopyright:   © 2021 AO Kaspersky Lab. All Rights Reserved.
  1541.     LegalTrademarks:  Registered trademarks and service marks are the property of their respective owners
  1542. fffff800`826a0000 fffff800`826b5000   filecrypt   (deferred)            
  1543.     Image path: \SystemRoot\system32\drivers\filecrypt.sys
  1544.     Image name: filecrypt.sys
  1545.     Timestamp:        Fri Mar 01 03:12:42 2002 (3C7F622A)
  1546.     CheckSum:         0000FEC3
  1547.     ImageSize:        00015000
  1548.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1549. fffff800`826c0000 fffff800`826ce000   tbs        (deferred)            
  1550.     Image path: \SystemRoot\system32\drivers\tbs.sys
  1551.     Image name: tbs.sys
  1552.     Timestamp:        ***** Invalid (BBC1ED87)
  1553.     CheckSum:         00011119
  1554.     ImageSize:        0000E000
  1555.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1556. fffff800`826d0000 fffff800`827d9000   klif       (deferred)            
  1557.     Image path: \SystemRoot\system32\DRIVERS\klif.sys
  1558.     Image name: klif.sys
  1559.     Timestamp:        Fri Feb 19 05:51:17 2021 (602FC255)
  1560.     CheckSum:         0010D1EF
  1561.     ImageSize:        00109000
  1562.     File version:     30.587.0.1070
  1563.     Product version:  30.587.0.1070
  1564.     File flags:       0 (Mask 3F)
  1565.     File OS:          40004 NT Win32
  1566.     File type:        2.0 Dll
  1567.     File date:        00000000.00000000
  1568.     Translations:     0409.04b0
  1569.     CompanyName:      AO Kaspersky Lab
  1570.     ProductName:      Coretech Delivery
  1571.     InternalName:     klif
  1572.     ProductVersion:   30.587.0.1070-a81ac642e3
  1573.     FileVersion:      30.587.0.1070
  1574.     FileDescription:  Core System Interceptors [fre_win7_x64]
  1575.     LegalCopyright:   © 2021 AO Kaspersky Lab. All Rights Reserved.
  1576.     LegalTrademarks:  Registered trademarks and service marks are the property of their respective owners
  1577. fffff800`827e0000 fffff800`82856000   ks         (deferred)            
  1578.     Image path: \SystemRoot\system32\DRIVERS\ks.sys
  1579.     Image name: ks.sys
  1580.     Timestamp:        ***** Invalid (F812DE3F)
  1581.     CheckSum:         000751CB
  1582.     ImageSize:        00076000
  1583.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1584. fffff800`82860000 fffff800`829df000   klhk       (deferred)            
  1585.     Image path: \SystemRoot\system32\DRIVERS\klhk.sys
  1586.     Image name: klhk.sys
  1587.     Timestamp:        Mon Jan 25 08:51:13 2021 (600EF701)
  1588.     CheckSum:         0015F58F
  1589.     ImageSize:        0017F000
  1590.     File version:     30.587.0.170
  1591.     Product version:  30.587.0.170
  1592.     File flags:       0 (Mask 3F)
  1593.     File OS:          40004 NT Win32
  1594.     File type:        2.0 Dll
  1595.     File date:        00000000.00000000
  1596.     Translations:     0409.04b0
  1597.     CompanyName:      AO Kaspersky Lab
  1598.     ProductName:      Coretech Delivery
  1599.     InternalName:     klhk
  1600.     ProductVersion:   30.587.0.170-e30f0c58d6
  1601.     FileVersion:      30.587.0.170
  1602.     FileDescription:  klhk [fre_win7_x64]
  1603.     LegalCopyright:   © 2021 AO Kaspersky Lab. All Rights Reserved.
  1604.     LegalTrademarks:  Registered trademarks and service marks are the property of their respective owners
  1605. fffff800`829e0000 fffff800`82a0b000   pacer      (deferred)            
  1606.     Image path: \SystemRoot\System32\drivers\pacer.sys
  1607.     Image name: pacer.sys
  1608.     Timestamp:        ***** Invalid (FECCC466)
  1609.     CheckSum:         0003603B
  1610.     ImageSize:        0002B000
  1611.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1612. fffff800`82a40000 fffff800`82a5e000   crashdmp   (deferred)            
  1613.     Image path: \SystemRoot\System32\Drivers\crashdmp.sys
  1614.     Image name: crashdmp.sys
  1615.     Timestamp:        ***** Invalid (9A19AF81)
  1616.     CheckSum:         0002129E
  1617.     ImageSize:        0001E000
  1618.     File version:     10.0.19041.1
  1619.     Product version:  10.0.19041.1
  1620.     File flags:       0 (Mask 3F)
  1621.     File OS:          40004 NT Win32
  1622.     File type:        3.7 Driver
  1623.     File date:        00000000.00000000
  1624.     Translations:     0409.04b0
  1625.     CompanyName:      Microsoft Corporation
  1626.     ProductName:      Microsoft® Windows® Operating System
  1627.     InternalName:     crashdmp.sys
  1628.     OriginalFilename: crashdmp.sys
  1629.     ProductVersion:   10.0.19041.1
  1630.     FileVersion:      10.0.19041.1 (WinBuild.160101.0800)
  1631.     FileDescription:  Crash Dump Driver
  1632.     LegalCopyright:   © Microsoft Corporation. All rights reserved.
  1633. fffff800`82ae0000 fffff800`82b1a000   ndiswan    (deferred)            
  1634.     Image path: \SystemRoot\System32\drivers\ndiswan.sys
  1635.     Image name: ndiswan.sys
  1636.     Timestamp:        ***** Invalid (88F100F4)
  1637.     CheckSum:         0003FFCA
  1638.     ImageSize:        0003A000
  1639.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1640. fffff800`82b20000 fffff800`82b57000   klupd_KLIF_mark   (deferred)            
  1641.     Image path: \SystemRoot\System32\Drivers\klupd_KLIF_mark.sys
  1642.     Image name: klupd_KLIF_mark.sys
  1643.     Timestamp:        Wed Mar 24 02:34:52 2021 (605B15CC)
  1644.     CheckSum:         0003EA59
  1645.     ImageSize:        00037000
  1646.     File version:     6.6.3.0
  1647.     Product version:  6.6.3.0
  1648.     File flags:       0 (Mask 3F)
  1649.     File OS:          40004 NT Win32
  1650.     File type:        2.0 Dll
  1651.     File date:        00000000.00000000
  1652.     Translations:     0409.04b0
  1653.     CompanyName:      AO Kaspersky Lab
  1654.     ProductName:      Kaspersky Bases
  1655.     InternalName:     mark
  1656.     OriginalFilename: mark.sys
  1657.     ProductVersion:   6.6.3.0
  1658.     FileVersion:      6.6.3.0
  1659.     FileDescription:  Kaspersky Lab Anti-Rootkit Memory Driver
  1660.     LegalCopyright:   © 2021 AO Kaspersky Lab. All Rights Reserved.
  1661.     LegalTrademarks:  Registered trademarks and service marks are the property of their respective owners
  1662. fffff800`82b60000 fffff800`82b9c000   klupd_KLIF_swmon   (deferred)            
  1663.     Image path: \SystemRoot\System32\Drivers\klupd_KLIF_swmon.sys
  1664.     Image name: klupd_KLIF_swmon.sys
  1665.     Timestamp:        Thu Aug 19 08:36:35 2021 (611E8893)
  1666.     CheckSum:         00047C85
  1667.     ImageSize:        0003C000
  1668.     File version:     1.12.5.0
  1669.     Product version:  1.12.5.0
  1670.     File flags:       0 (Mask 3F)
  1671.     File OS:          40004 NT Win32
  1672.     File type:        2.0 Dll
  1673.     File date:        00000000.00000000
  1674.     Translations:     0409.04b0
  1675.     CompanyName:      AO Kaspersky Lab
  1676.     ProductName:      Kaspersky Bases
  1677.     InternalName:     swmon
  1678.     OriginalFilename: swmon.sys
  1679.     ProductVersion:   1.12.5.0
  1680.     FileVersion:      1.12.5.0
  1681.     FileDescription:  Kaspersky Lab System Watcher Monitor Driver
  1682.     LegalCopyright:   © 2021 AO Kaspersky Lab. All Rights Reserved.
  1683.     LegalTrademarks:  Registered trademarks and service marks are the property of their respective owners
  1684. fffff800`82bb0000 fffff800`82bc4000   ndiscap    (deferred)            
  1685.     Image path: \SystemRoot\System32\drivers\ndiscap.sys
  1686.     Image name: ndiscap.sys
  1687.     Timestamp:        ***** Invalid (DCEEC70E)
  1688.     CheckSum:         0001C38B
  1689.     ImageSize:        00014000
  1690.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1691. fffff800`82bd0000 fffff800`82be4000   netbios    (deferred)            
  1692.     Image path: \SystemRoot\system32\drivers\netbios.sys
  1693.     Image name: netbios.sys
  1694.     Timestamp:        Fri Nov 12 13:10:06 2021 (618ED82E)
  1695.     CheckSum:         0001A9AF
  1696.     ImageSize:        00014000
  1697.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1698. fffff800`82c00000 fffff800`82fa4000   dxgkrnl    (deferred)            
  1699.     Image path: \SystemRoot\System32\drivers\dxgkrnl.sys
  1700.     Image name: dxgkrnl.sys
  1701.     Timestamp:        ***** Invalid (B20216B8)
  1702.     CheckSum:         0039F5F1
  1703.     ImageSize:        003A4000
  1704.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1705. fffff800`82fb0000 fffff800`82fc8000   watchdog   (deferred)            
  1706.     Image path: \SystemRoot\System32\drivers\watchdog.sys
  1707.     Image name: watchdog.sys
  1708.     Timestamp:        Fri Jun 16 16:44:59 2006 (4493508B)
  1709.     CheckSum:         000222BD
  1710.     ImageSize:        00018000
  1711.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1712. fffff800`82fd0000 fffff800`82fe6000   BasicDisplay   (deferred)            
  1713.     Image path: \SystemRoot\System32\DriverStore\FileRepository\basicdisplay.inf_amd64_62ba5773ba05edee\BasicDisplay.sys
  1714.     Image name: BasicDisplay.sys
  1715.     Timestamp:        ***** Invalid (A2092B45)
  1716.     CheckSum:         0001C212
  1717.     ImageSize:        00016000
  1718.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1719. fffff800`82ff0000 fffff800`83001000   BasicRender   (deferred)            
  1720.     Image path: \SystemRoot\System32\DriverStore\FileRepository\basicrender.inf_amd64_49a8589f00d970d9\BasicRender.sys
  1721.     Image name: BasicRender.sys
  1722.     Timestamp:        ***** Invalid (EE8C9717)
  1723.     CheckSum:         00016443
  1724.     ImageSize:        00011000
  1725.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1726. fffff800`83010000 fffff800`83017000   DamewareMini   (deferred)            
  1727.     Image path: \SystemRoot\System32\drivers\DamewareMini.sys
  1728.     Image name: DamewareMini.sys
  1729.     Timestamp:        Sun Mar 16 10:42:28 2008 (47DD6A14)
  1730.     CheckSum:         0000921C
  1731.     ImageSize:        00007000
  1732.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1733. fffff800`83020000 fffff800`83035000   VIDEOPRT   (deferred)            
  1734.     Image path: \SystemRoot\System32\drivers\VIDEOPRT.SYS
  1735.     Image name: VIDEOPRT.SYS
  1736.     Timestamp:        Thu Jan 18 03:16:03 1979 (11047A73)
  1737.     CheckSum:         000159DE
  1738.     ImageSize:        00015000
  1739.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1740. fffff800`83040000 fffff800`8305c000   Npfs       (deferred)            
  1741.     Image path: \SystemRoot\System32\Drivers\Npfs.SYS
  1742.     Image name: Npfs.SYS
  1743.     Timestamp:        ***** Invalid (9E3E4C73)
  1744.     CheckSum:         000192F7
  1745.     ImageSize:        0001C000
  1746.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1747. fffff800`83060000 fffff800`83071000   Msfs       (deferred)            
  1748.     Image path: \SystemRoot\System32\Drivers\Msfs.SYS
  1749.     Image name: Msfs.SYS
  1750.     Timestamp:        ***** Invalid (95155DF1)
  1751.     CheckSum:         0001A9B5
  1752.     ImageSize:        00011000
  1753.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1754. fffff800`83080000 fffff800`8309b000   CimFS      (deferred)            
  1755.     Image path: \SystemRoot\System32\Drivers\CimFS.SYS
  1756.     Image name: CimFS.SYS
  1757.     Timestamp:        Sun Nov 15 00:49:44 2037 (7FAA9D28)
  1758.     CheckSum:         00018CE5
  1759.     ImageSize:        0001B000
  1760.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1761. fffff800`830a0000 fffff800`830c4000   klwfp      (deferred)            
  1762.     Image path: \SystemRoot\system32\DRIVERS\klwfp.sys
  1763.     Image name: klwfp.sys
  1764.     Timestamp:        ***** Invalid (EB577675)
  1765.     CheckSum:         0002CDC2
  1766.     ImageSize:        00024000
  1767.     File version:     30.587.0.170
  1768.     Product version:  30.587.0.170
  1769.     File flags:       0 (Mask 3F)
  1770.     File OS:          40004 NT Win32
  1771.     File type:        2.0 Dll
  1772.     File date:        00000000.00000000
  1773.     Translations:     0409.04b0
  1774.     CompanyName:      AO Kaspersky Lab
  1775.     ProductName:      Coretech Delivery
  1776.     InternalName:     klwfp
  1777.     ProductVersion:   30.587.0.170-e30f0c58d6
  1778.     FileVersion:      30.587.0.170
  1779.     FileDescription:  WFP Network Filter [fre_win7_x64]
  1780.     LegalCopyright:   © 2021 AO Kaspersky Lab. All Rights Reserved.
  1781.     LegalTrademarks:  Registered trademarks and service marks are the property of their respective owners
  1782. fffff800`830d0000 fffff800`830f2000   tdx        (deferred)            
  1783.     Image path: \SystemRoot\system32\DRIVERS\tdx.sys
  1784.     Image name: tdx.sys
  1785.     Timestamp:        Thu Oct 03 22:47:28 1991 (28EC0E80)
  1786.     CheckSum:         000273F3
  1787.     ImageSize:        00022000
  1788.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1789. fffff800`83100000 fffff800`83110000   TDI        (deferred)            
  1790.     Image path: \SystemRoot\system32\DRIVERS\TDI.SYS
  1791.     Image name: TDI.SYS
  1792.     Timestamp:        ***** Invalid (D1AD2BD4)
  1793.     CheckSum:         0000D19A
  1794.     ImageSize:        00010000
  1795.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1796. fffff800`83120000 fffff800`83135000   klim6      (deferred)            
  1797.     Image path: \SystemRoot\system32\DRIVERS\klim6.sys
  1798.     Image name: klim6.sys
  1799.     Timestamp:        ***** Invalid (D15AC501)
  1800.     CheckSum:         0002025E
  1801.     ImageSize:        00015000
  1802.     File version:     30.587.0.930
  1803.     Product version:  30.587.0.930
  1804.     File flags:       0 (Mask 3F)
  1805.     File OS:          40004 NT Win32
  1806.     File type:        2.0 Dll
  1807.     File date:        00000000.00000000
  1808.     Translations:     0409.04b0
  1809.     CompanyName:      AO Kaspersky Lab
  1810.     ProductName:      Coretech Delivery
  1811.     InternalName:     klim6
  1812.     ProductVersion:   30.587.0.930-ef5965511c
  1813.     FileVersion:      30.587.0.930
  1814.     FileDescription:  Packet Network Filter [fre_win7_x64]
  1815.     LegalCopyright:   © 2021 AO Kaspersky Lab. All Rights Reserved.
  1816.     LegalTrademarks:  Registered trademarks and service marks are the property of their respective owners
  1817. fffff800`83140000 fffff800`8315a000   vwififlt   (deferred)            
  1818.     Image path: \SystemRoot\System32\drivers\vwififlt.sys
  1819.     Image name: vwififlt.sys
  1820.     Timestamp:        Wed Jan 06 23:07:33 2010 (4B458835)
  1821.     CheckSum:         0001814D
  1822.     ImageSize:        0001A000
  1823.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1824. fffff800`83170000 fffff800`83212000   klgse      (deferred)            
  1825.     Image path: \SystemRoot\system32\DRIVERS\klgse.sys
  1826.     Image name: klgse.sys
  1827.     Timestamp:        Mon Feb 08 07:51:31 2021 (60215E03)
  1828.     CheckSum:         000A7591
  1829.     ImageSize:        000A2000
  1830.     File version:     30.587.0.830
  1831.     Product version:  30.587.0.830
  1832.     File flags:       0 (Mask 3F)
  1833.     File OS:          40004 NT Win32
  1834.     File type:        2.0 Dll
  1835.     File date:        00000000.00000000
  1836.     Translations:     0409.04b0
  1837.     CompanyName:      AO Kaspersky Lab
  1838.     ProductName:      Coretech Delivery
  1839.     InternalName:     klgse
  1840.     ProductVersion:   30.587.0.830-2713fb5b5d
  1841.     FileVersion:      30.587.0.830
  1842.     FileDescription:  Security Extender [fre_win7_x64]
  1843.     LegalCopyright:   © 2021 AO Kaspersky Lab. All Rights Reserved.
  1844.     LegalTrademarks:  Registered trademarks and service marks are the property of their respective owners
  1845. fffff800`83220000 fffff800`83232000   klpd       (deferred)            
  1846.     Image path: \SystemRoot\system32\DRIVERS\klpd.sys
  1847.     Image name: klpd.sys
  1848.     Timestamp:        Mon Jan 25 08:51:07 2021 (600EF6FB)
  1849.     CheckSum:         0001F6D9
  1850.     ImageSize:        00012000
  1851.     File version:     30.587.0.170
  1852.     Product version:  30.587.0.170
  1853.     File flags:       0 (Mask 3F)
  1854.     File OS:          40004 NT Win32
  1855.     File type:        2.0 Dll
  1856.     File date:        00000000.00000000
  1857.     Translations:     0409.04b0
  1858.     CompanyName:      AO Kaspersky Lab
  1859.     ProductName:      Coretech Delivery
  1860.     InternalName:     klpd
  1861.     ProductVersion:   30.587.0.170-e30f0c58d6
  1862.     FileVersion:      30.587.0.170
  1863.     FileDescription:  Format Recognizer [fre_win7_x64]
  1864.     LegalCopyright:   © 2021 AO Kaspersky Lab. All Rights Reserved.
  1865.     LegalTrademarks:  Registered trademarks and service marks are the property of their respective owners
  1866. Page 20001f64b too large to be in the dump file.
  1867. fffff800`83240000 fffff800`8324a000   Null       (deferred)            
  1868.     Image path: \SystemRoot\System32\Drivers\Null.SYS
  1869.     Image name: Null.SYS
  1870. Page 20001f64b too large to be in the dump file.
  1871.     Timestamp:        unavailable (FFFFFFFE)
  1872.     CheckSum:         missing
  1873.     ImageSize:        0000A000
  1874. Page 20001f64b too large to be in the dump file.
  1875. Page 20001f64b too large to be in the dump file.
  1876.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1877. Page 20001f64b too large to be in the dump file.
  1878. Page 20001f64b too large to be in the dump file.
  1879. Page 20001f64b too large to be in the dump file.
  1880. Page 20001f64b too large to be in the dump file.
  1881. Page 20001f64b too large to be in the dump file.
  1882. Page 20001f64b too large to be in the dump file.
  1883. Page 20001f64b too large to be in the dump file.
  1884. Page 20001f64b too large to be in the dump file.
  1885. Page 20001f64b too large to be in the dump file.
  1886. Page 20001f64b too large to be in the dump file.
  1887. Page 20001f64b too large to be in the dump file.
  1888. Page 20001f64b too large to be in the dump file.
  1889. Page 20001f64b too large to be in the dump file.
  1890. Page 20001f64b too large to be in the dump file.
  1891. Page 20001f64b too large to be in the dump file.
  1892. Page 20001f64b too large to be in the dump file.
  1893. Page 20001f64b too large to be in the dump file.
  1894. Page 20001f64b too large to be in the dump file.
  1895. Page 20001f64b too large to be in the dump file.
  1896. Page 20001f64b too large to be in the dump file.
  1897. Page 20001f64b too large to be in the dump file.
  1898. Page 20001f64b too large to be in the dump file.
  1899. Page 20001f64b too large to be in the dump file.
  1900. Page 20001f64b too large to be in the dump file.
  1901. Page 20001f64b too large to be in the dump file.
  1902. Page 20001f64b too large to be in the dump file.
  1903. Page 20001f64b too large to be in the dump file.
  1904. Page 20001f64b too large to be in the dump file.
  1905. Page 20001f64b too large to be in the dump file.
  1906. Page 20001f64b too large to be in the dump file.
  1907. Page 20001f64b too large to be in the dump file.
  1908. Page 20001f64b too large to be in the dump file.
  1909. Page 20001f64b too large to be in the dump file.
  1910. Page 20001f64b too large to be in the dump file.
  1911. Page 20001f64b too large to be in the dump file.
  1912. Page 20001f64b too large to be in the dump file.
  1913. Page 20001f64b too large to be in the dump file.
  1914. Page 20001f64b too large to be in the dump file.
  1915. Page 20001f64b too large to be in the dump file.
  1916. Page 20001f64b too large to be in the dump file.
  1917. Page 20001f64b too large to be in the dump file.
  1918. Page 20001f64b too large to be in the dump file.
  1919. Page 20001f64b too large to be in the dump file.
  1920. Page 20001f64b too large to be in the dump file.
  1921. Page 20001f64b too large to be in the dump file.
  1922. Page 20001f64b too large to be in the dump file.
  1923. Page 20001f64b too large to be in the dump file.
  1924. Page 20001f64b too large to be in the dump file.
  1925. fffff800`83250000 fffff800`8325a000   Beep       (deferred)            
  1926.     Image path: \SystemRoot\System32\Drivers\Beep.SYS
  1927.     Image name: Beep.SYS
  1928.     Timestamp:        ***** Invalid (E4AC8238)
  1929.     CheckSum:         00008685
  1930.     ImageSize:        0000A000
  1931.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1932. fffff800`83260000 fffff800`8326d000   dwvkbd64   (deferred)            
  1933.     Image path: \SystemRoot\system32\DRIVERS\dwvkbd64.sys
  1934.     Image name: dwvkbd64.sys
  1935.     Timestamp:        Wed Apr 11 13:22:37 2007 (461D519D)
  1936.     CheckSum:         0000A755
  1937.     ImageSize:        0000D000
  1938.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1939. fffff800`83270000 fffff800`832cc000   netbt      (deferred)            
  1940.     Image path: \SystemRoot\System32\DRIVERS\netbt.sys
  1941.     Image name: netbt.sys
  1942.     Timestamp:        ***** Invalid (8908830E)
  1943.     CheckSum:         000553BD
  1944.     ImageSize:        0005C000
  1945.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1946. fffff800`832d0000 fffff800`832e3000   afunix     (deferred)            
  1947.     Image path: \SystemRoot\system32\drivers\afunix.sys
  1948.     Image name: afunix.sys
  1949.     Timestamp:        ***** Invalid (9501F0D8)
  1950.     CheckSum:         00018987
  1951.     ImageSize:        00013000
  1952.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1953. fffff800`832f0000 fffff800`83393000   afd        (deferred)            
  1954.     Image path: \SystemRoot\system32\drivers\afd.sys
  1955.     Image name: afd.sys
  1956.     Timestamp:        ***** Invalid (CC0C9B73)
  1957.     CheckSum:         000A334A
  1958.     ImageSize:        000A3000
  1959.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1960. fffff800`833a0000 fffff800`833eb000   klwtp      (deferred)            
  1961.     Image path: \SystemRoot\system32\DRIVERS\klwtp.sys
  1962.     Image name: klwtp.sys
  1963.     Timestamp:        ***** Invalid (F54B0C36)
  1964.     CheckSum:         0005B951
  1965.     ImageSize:        0004B000
  1966.     File version:     30.587.0.590
  1967.     Product version:  30.587.0.590
  1968.     File flags:       0 (Mask 3F)
  1969.     File OS:          40004 NT Win32
  1970.     File type:        2.0 Dll
  1971.     File date:        00000000.00000000
  1972.     Translations:     0409.04b0
  1973.     CompanyName:      AO Kaspersky Lab
  1974.     ProductName:      Coretech Delivery
  1975.     InternalName:     klwtp
  1976.     ProductVersion:   30.587.0.590-5f439758d8
  1977.     FileVersion:      30.587.0.590
  1978.     FileDescription:  WFP Network Connection Filter Driver [fre_win7_x64]
  1979.     LegalCopyright:   © 2021 AO Kaspersky Lab. All Rights Reserved.
  1980.     LegalTrademarks:  Registered trademarks and service marks are the property of their respective owners
  1981. fffff800`83400000 fffff800`83412000   nsiproxy   (deferred)            
  1982.     Image path: \SystemRoot\system32\drivers\nsiproxy.sys
  1983.     Image name: nsiproxy.sys
  1984.     Timestamp:        ***** Invalid (E65AB811)
  1985.     CheckSum:         0001515A
  1986.     ImageSize:        00012000
  1987.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1988. fffff800`83420000 fffff800`8342e000   npsvctrig   (deferred)            
  1989.     Image path: \SystemRoot\System32\drivers\npsvctrig.sys
  1990.     Image name: npsvctrig.sys
  1991.     Timestamp:        Sun Jan 05 18:41:12 2025 (677B42C8)
  1992.     CheckSum:         000119D3
  1993.     ImageSize:        0000E000
  1994.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  1995. fffff800`83430000 fffff800`83440000   mssmbios   (deferred)            
  1996.     Image path: \SystemRoot\System32\drivers\mssmbios.sys
  1997.     Image name: mssmbios.sys
  1998.     Timestamp:        Thu Mar 17 08:26:02 2022 (6233611A)
  1999.     CheckSum:         0000DD1D
  2000.     ImageSize:        00010000
  2001.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2002. fffff800`83450000 fffff800`83499000   kneps      (deferred)            
  2003.     Image path: \SystemRoot\system32\DRIVERS\kneps.sys
  2004.     Image name: kneps.sys
  2005.     Timestamp:        ***** Invalid (CEAE8F0E)
  2006.     CheckSum:         00049AF2
  2007.     ImageSize:        00049000
  2008.     File version:     30.587.0.460
  2009.     Product version:  30.587.0.460
  2010.     File flags:       0 (Mask 3F)
  2011.     File OS:          40004 NT Win32
  2012.     File type:        2.0 Dll
  2013.     File date:        00000000.00000000
  2014.     Translations:     0409.04b0
  2015.     CompanyName:      AO Kaspersky Lab
  2016.     ProductName:      Coretech Delivery
  2017.     InternalName:     kneps
  2018.     ProductVersion:   30.587.0.460-f74872ca72
  2019.     FileVersion:      30.587.0.460
  2020.     FileDescription:  Network Processor [fre_win7_x64]
  2021.     LegalCopyright:   © 2021 AO Kaspersky Lab. All Rights Reserved.
  2022.     LegalTrademarks:  Registered trademarks and service marks are the property of their respective owners
  2023. fffff800`834f0000 fffff800`834fa000   gpuenergydrv   (deferred)            
  2024.     Image path: \SystemRoot\System32\drivers\gpuenergydrv.sys
  2025.     Image name: gpuenergydrv.sys
  2026.     Timestamp:        ***** Invalid (F10C03D8)
  2027.     CheckSum:         00009EA6
  2028.     ImageSize:        0000A000
  2029.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2030. fffff800`83500000 fffff800`8352c000   dfsc       (deferred)            
  2031.     Image path: \SystemRoot\System32\Drivers\dfsc.sys
  2032.     Image name: dfsc.sys
  2033.     Timestamp:        ***** Invalid (F5D01020)
  2034.     CheckSum:         00031317
  2035.     ImageSize:        0002C000
  2036.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2037. fffff800`83530000 fffff800`83545000   tcpipreg   (deferred)            
  2038.     Image path: \SystemRoot\System32\drivers\tcpipreg.sys
  2039.     Image name: tcpipreg.sys
  2040.     Timestamp:        Fri May 11 20:43:31 1973 (0651E2F3)
  2041.     CheckSum:         0001BF67
  2042.     ImageSize:        00015000
  2043.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2044. fffff800`83550000 fffff800`83567000   bam        (deferred)            
  2045.     Image path: \SystemRoot\system32\drivers\bam.sys
  2046.     Image name: bam.sys
  2047.     Timestamp:        Fri Mar 26 23:41:44 2010 (4BADB6B8)
  2048.     CheckSum:         00019328
  2049.     ImageSize:        00017000
  2050.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2051. fffff800`83570000 fffff800`835be000   ahcache    (deferred)            
  2052.     Image path: \SystemRoot\system32\DRIVERS\ahcache.sys
  2053.     Image name: ahcache.sys
  2054.     Timestamp:        Tue Mar 26 11:33:15 2019 (5C9A7E7B)
  2055.     CheckSum:         00052E71
  2056.     ImageSize:        0004E000
  2057.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2058. fffff800`835c0000 fffff800`835d4000   kbdclass   (deferred)            
  2059.     Image path: \SystemRoot\System32\drivers\kbdclass.sys
  2060.     Image name: kbdclass.sys
  2061.     Timestamp:        Mon Mar 25 01:20:10 1996 (3156654A)
  2062.     CheckSum:         0001CE1A
  2063.     ImageSize:        00014000
  2064.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2065. fffff800`835e0000 fffff800`835f2000   CompositeBus   (deferred)            
  2066.     Image path: \SystemRoot\System32\DriverStore\FileRepository\compositebus.inf_amd64_7500cffa210c6946\CompositeBus.sys
  2067.     Image name: CompositeBus.sys
  2068.     Timestamp:        Wed Oct 28 00:32:02 2026 (6AE1B302)
  2069.     CheckSum:         00015BD2
  2070.     ImageSize:        00012000
  2071.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2072. fffff800`83600000 fffff800`8360d000   kdnic      (deferred)            
  2073.     Image path: \SystemRoot\System32\drivers\kdnic.sys
  2074.     Image name: kdnic.sys
  2075.     Timestamp:        ***** Invalid (9401D3B8)
  2076.     CheckSum:         000178DD
  2077.     ImageSize:        0000D000
  2078.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2079. fffff800`83610000 fffff800`83625000   umbus      (deferred)            
  2080.     Image path: \SystemRoot\System32\DriverStore\FileRepository\umbus.inf_amd64_b78a9c5b6fd62c27\umbus.sys
  2081.     Image name: umbus.sys
  2082.     Timestamp:        ***** Invalid (E7B4847E)
  2083.     CheckSum:         0001394F
  2084.     ImageSize:        00015000
  2085.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2086. fffff800`83630000 fffff800`8375f000   dump_iaStorE   (deferred)            
  2087.     Image path: \SystemRoot\System32\drivers\dump_iaStorE.sys
  2088.     Image name: dump_iaStorE.sys
  2089.     Timestamp:        Mon Jan 13 13:05:06 2020 (5E1CDB82)
  2090.     CheckSum:         00110008
  2091.     ImageSize:        0012F000
  2092.     File version:     6.3.0.1022
  2093.     Product version:  6.3.0.1022
  2094.     File flags:       8 (Mask 3F) Private
  2095.     File OS:          40004 NT Win32
  2096.     File type:        3.7 Driver
  2097.     File date:        00000000.00000000
  2098.     Translations:     0409.04b0
  2099.     CompanyName:      Intel Corporation
  2100.     ProductName:      Intel Virtual RAID on CPUdriver
  2101.     InternalName:     iaStor.sys
  2102.     OriginalFilename: iaStor.sys
  2103.     ProductVersion:   6.3.0.1022
  2104.     FileVersion:      6.3.0.1022
  2105.     PrivateBuild:     6.3.0.1022
  2106.     SpecialBuild:     6.3.0.1022
  2107.     FileDescription:  Intel Virtual RAID on CPUdriver - x64
  2108.     LegalCopyright:   Copyright(C) Intel Corporation 1994-2019
  2109.     LegalTrademarks:  Copyright(C) Intel Corporation 1994-2019
  2110.     Comments:         -x64
  2111. fffff800`83760000 fffff800`83841000   dxgmms2    (deferred)            
  2112.     Image path: \SystemRoot\System32\drivers\dxgmms2.sys
  2113.     Image name: dxgmms2.sys
  2114.     Timestamp:        Thu Apr 09 16:03:45 1970 (00828561)
  2115.     CheckSum:         000EB4C5
  2116.     ImageSize:        000E1000
  2117.     File version:     10.0.19041.508
  2118.     Product version:  10.0.19041.508
  2119.     File flags:       0 (Mask 3F)
  2120.     File OS:          40004 NT Win32
  2121.     File type:        3.7 Driver
  2122.     File date:        00000000.00000000
  2123.     Translations:     0409.04b0
  2124.     CompanyName:      Microsoft Corporation
  2125.     ProductName:      Microsoft® Windows® Operating System
  2126.     InternalName:     dxgmms2.sys
  2127.     OriginalFilename: dxgmms2.sys
  2128.     ProductVersion:   10.0.19041.508
  2129.     FileVersion:      10.0.19041.508 (WinBuild.160101.0800)
  2130.     FileDescription:  DirectX Graphics MMS
  2131.     LegalCopyright:   © Microsoft Corporation. All rights reserved.
  2132. fffff800`83850000 fffff800`83886000   wcifs      (deferred)            
  2133.     Image path: \SystemRoot\system32\drivers\wcifs.sys
  2134.     Image name: wcifs.sys
  2135.     Timestamp:        Sun Jan 31 18:32:49 2027 (6B5FEED1)
  2136.     CheckSum:         0004091A
  2137.     ImageSize:        00036000
  2138.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2139. fffff800`83890000 fffff800`83910000   cldflt     (deferred)            
  2140.     Image path: \SystemRoot\system32\drivers\cldflt.sys
  2141.     Image name: cldflt.sys
  2142.     Timestamp:        Thu Mar 20 15:36:50 2003 (3E7A5092)
  2143.     CheckSum:         0007EBD7
  2144.     ImageSize:        00080000
  2145.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2146. fffff800`83920000 fffff800`83947000   tsusbhub   (deferred)            
  2147.     Image path: \SystemRoot\System32\drivers\tsusbhub.sys
  2148.     Image name: tsusbhub.sys
  2149.     Timestamp:        Sun Dec 06 01:15:32 2020 (5FCCA134)
  2150.     CheckSum:         0002CCCD
  2151.     ImageSize:        00027000
  2152.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2153. fffff800`83950000 fffff800`83977000   bindflt    (deferred)            
  2154.     Image path: \SystemRoot\system32\drivers\bindflt.sys
  2155.     Image name: bindflt.sys
  2156.     Timestamp:        ***** Invalid (E3483DD4)
  2157.     CheckSum:         0002F4EE
  2158.     ImageSize:        00027000
  2159.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2160. fffff800`83980000 fffff800`839a5000   bowser     (deferred)            
  2161.     Image path: \SystemRoot\system32\DRIVERS\bowser.sys
  2162.     Image name: bowser.sys
  2163.     Timestamp:        ***** Invalid (EDAC6813)
  2164.     CheckSum:         00024E4F
  2165.     ImageSize:        00025000
  2166.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2167. fffff800`839b0000 fffff800`83a06000   msquic     (deferred)            
  2168.     Image path: \SystemRoot\system32\drivers\msquic.sys
  2169.     Image name: msquic.sys
  2170.     Timestamp:        ***** Invalid (DE688303)
  2171.     CheckSum:         0005615F
  2172.     ImageSize:        00056000
  2173.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2174. fffff800`83a10000 fffff800`83aa3000   mrxsmb     (deferred)            
  2175.     Image path: \SystemRoot\system32\DRIVERS\mrxsmb.sys
  2176.     Image name: mrxsmb.sys
  2177.     Timestamp:        ***** Invalid (CDB159C0)
  2178.     CheckSum:         0008D9C7
  2179.     ImageSize:        00093000
  2180.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2181. fffff800`83ab0000 fffff800`83af5000   mrxsmb20   (deferred)            
  2182.     Image path: \SystemRoot\system32\DRIVERS\mrxsmb20.sys
  2183.     Image name: mrxsmb20.sys
  2184.     Timestamp:        ***** Invalid (C5AEA72C)
  2185.     CheckSum:         0004D662
  2186.     ImageSize:        00045000
  2187.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2188. fffff800`83b00000 fffff800`83b13000   condrv     (deferred)            
  2189.     Image path: \SystemRoot\System32\drivers\condrv.sys
  2190.     Image name: condrv.sys
  2191.     Timestamp:        ***** Invalid (B47B2254)
  2192.     CheckSum:         0001B87D
  2193.     ImageSize:        00013000
  2194.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2195. fffff800`83b20000 fffff800`83b72000   srvnet     (deferred)            
  2196.     Image path: \SystemRoot\System32\DRIVERS\srvnet.sys
  2197.     Image name: srvnet.sys
  2198.     Timestamp:        Sat Aug 04 03:40:17 2001 (3B6BDF21)
  2199.     CheckSum:         000539AC
  2200.     ImageSize:        00052000
  2201.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2202. fffff800`83b80000 fffff800`83c47000   srv2       (deferred)            
  2203.     Image path: \SystemRoot\System32\DRIVERS\srv2.sys
  2204.     Image name: srv2.sys
  2205.     Timestamp:        ***** Invalid (EE8E2F4F)
  2206.     CheckSum:         000C31D2
  2207.     ImageSize:        000C7000
  2208.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2209. fffff800`83c50000 fffff800`83c68000   lltdio     (deferred)            
  2210.     Image path: \SystemRoot\system32\drivers\lltdio.sys
  2211.     Image name: lltdio.sys
  2212.     Timestamp:        ***** Invalid (D4D91B57)
  2213.     CheckSum:         00012B46
  2214.     ImageSize:        00018000
  2215.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2216. fffff800`83c70000 fffff800`83c8b000   rspndr     (deferred)            
  2217.     Image path: \SystemRoot\system32\drivers\rspndr.sys
  2218.     Image name: rspndr.sys
  2219.     Timestamp:        ***** Invalid (9E43BCCD)
  2220.     CheckSum:         000194E8
  2221.     ImageSize:        0001B000
  2222.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2223. fffff800`83c90000 fffff800`83cad000   wanarp     (deferred)            
  2224.     Image path: \SystemRoot\System32\DRIVERS\wanarp.sys
  2225.     Image name: wanarp.sys
  2226.     Timestamp:        Wed Dec 08 07:58:18 1976 (0D0C481A)
  2227.     CheckSum:         0001B428
  2228.     ImageSize:        0001D000
  2229.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2230. fffff800`83cb0000 fffff800`83cca000   mpsdrv     (deferred)            
  2231.     Image path: \SystemRoot\System32\drivers\mpsdrv.sys
  2232.     Image name: mpsdrv.sys
  2233.     Timestamp:        Thu Nov 03 06:07:36 1977 (0EBF3D28)
  2234.     CheckSum:         00019727
  2235.     ImageSize:        0001A000
  2236.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2237. fffff800`83cd0000 fffff800`83e56000   HTTP       (deferred)            
  2238.     Image path: \SystemRoot\system32\drivers\HTTP.sys
  2239.     Image name: HTTP.sys
  2240.     Timestamp:        Sat Aug 09 12:01:22 2003 (3F355312)
  2241.     CheckSum:         0018B770
  2242.     ImageSize:        00186000
  2243.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2244. fffff800`83e60000 fffff800`83e6f000   ndistapi   (deferred)            
  2245.     Image path: \SystemRoot\System32\DRIVERS\ndistapi.sys
  2246.     Image name: ndistapi.sys
  2247.     Timestamp:        Mon Aug 10 20:11:42 1987 (211E997E)
  2248.     CheckSum:         0001530C
  2249.     ImageSize:        0000F000
  2250.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2251. fffff800`83e70000 fffff800`83e84000   mmcss      (deferred)            
  2252.     Image path: \SystemRoot\system32\drivers\mmcss.sys
  2253.     Image name: mmcss.sys
  2254.     Timestamp:        ***** Invalid (A1F3B590)
  2255.     CheckSum:         000108D9
  2256.     ImageSize:        00014000
  2257.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2258. fffff800`83e90000 fffff800`83ee2000   mrxsmb10   (deferred)            
  2259.     Image path: \SystemRoot\system32\DRIVERS\mrxsmb10.sys
  2260.     Image name: mrxsmb10.sys
  2261.     Timestamp:        ***** Invalid (ABA1F2CF)
  2262.     CheckSum:         0005A30C
  2263.     ImageSize:        00052000
  2264.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2265. fffff800`83ef0000 fffff800`83f17000   Ndu        (deferred)            
  2266.     Image path: \SystemRoot\system32\drivers\Ndu.sys
  2267.     Image name: Ndu.sys
  2268.     Timestamp:        ***** Invalid (ABC6C894)
  2269.     CheckSum:         000213E1
  2270.     ImageSize:        00027000
  2271.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2272. fffff800`83f20000 fffff800`83fb4000   srv        (deferred)            
  2273.     Image path: \SystemRoot\System32\DRIVERS\srv.sys
  2274.     Image name: srv.sys
  2275.     Timestamp:        Mon Mar 31 20:28:23 1997 (33408EE7)
  2276.     CheckSum:         0006E57C
  2277.     ImageSize:        00094000
  2278.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2279. fffff800`83fc0000 fffff800`84061000   Vid        (deferred)            
  2280.     Image path: \SystemRoot\System32\drivers\Vid.sys
  2281.     Image name: Vid.sys
  2282.     Timestamp:        ***** Invalid (D8B48452)
  2283.     CheckSum:         000AB1EA
  2284.     ImageSize:        000A1000
  2285.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2286. fffff800`84070000 fffff800`84091000   winhvr     (deferred)            
  2287.     Image path: \SystemRoot\System32\drivers\winhvr.sys
  2288.     Image name: winhvr.sys
  2289.     Timestamp:        ***** Invalid (C1F13DBD)
  2290.     CheckSum:         0001EA8A
  2291.     ImageSize:        00021000
  2292.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2293. fffff800`840a0000 fffff800`840b5000   klpnpflt   (deferred)            
  2294.     Image path: \SystemRoot\system32\DRIVERS\klpnpflt.sys
  2295.     Image name: klpnpflt.sys
  2296.     Timestamp:        Mon Jan 25 08:51:08 2021 (600EF6FC)
  2297.     CheckSum:         0002062B
  2298.     ImageSize:        00015000
  2299.     File version:     30.587.0.170
  2300.     Product version:  30.587.0.170
  2301.     File flags:       0 (Mask 3F)
  2302.     File OS:          40004 NT Win32
  2303.     File type:        2.0 Dll
  2304.     File date:        00000000.00000000
  2305.     Translations:     0409.04b0
  2306.     CompanyName:      AO Kaspersky Lab
  2307.     ProductName:      Coretech Delivery
  2308.     InternalName:     klpnpflt
  2309.     ProductVersion:   30.587.0.170-e30f0c58d6
  2310.     FileVersion:      30.587.0.170
  2311.     FileDescription:  Generic PnP filter [fre_win7_x64]
  2312.     LegalCopyright:   © 2021 AO Kaspersky Lab. All Rights Reserved.
  2313.     LegalTrademarks:  Registered trademarks and service marks are the property of their respective owners
  2314. fffff800`840c0000 fffff800`840d7000   klfltdev   (deferred)            
  2315.     Image path: \SystemRoot\system32\DRIVERS\klfltdev.sys
  2316.     Image name: klfltdev.sys
  2317.     Timestamp:        Mon Jan 25 08:51:08 2021 (600EF6FC)
  2318.     CheckSum:         00021681
  2319.     ImageSize:        00017000
  2320.     File version:     30.587.0.170
  2321.     Product version:  30.587.0.170
  2322.     File flags:       0 (Mask 3F)
  2323.     File OS:          40004 NT Win32
  2324.     File type:        2.0 Dll
  2325.     File date:        00000000.00000000
  2326.     Translations:     0409.04b0
  2327.     CompanyName:      AO Kaspersky Lab
  2328.     ProductName:      Coretech Delivery
  2329.     InternalName:     klfltdev
  2330.     ProductVersion:   30.587.0.170-e30f0c58d6
  2331.     FileVersion:      30.587.0.170
  2332.     FileDescription:  PnP Device Filter [fre_win7_x64]
  2333.     LegalCopyright:   © 2021 AO Kaspersky Lab. All Rights Reserved.
  2334.     LegalTrademarks:  Registered trademarks and service marks are the property of their respective owners
  2335. fffff800`840e0000 fffff800`8415b000   rdbss      (deferred)            
  2336.     Image path: \SystemRoot\system32\DRIVERS\rdbss.sys
  2337.     Image name: rdbss.sys
  2338.     Timestamp:        Sat Jul 10 02:51:55 2010 (4C3850CB)
  2339.     CheckSum:         0007E4B9
  2340.     ImageSize:        0007B000
  2341.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2342. fffff800`84160000 fffff800`841f4000   csc        (deferred)            
  2343.     Image path: \SystemRoot\system32\drivers\csc.sys
  2344.     Image name: csc.sys
  2345.     Timestamp:        Thu Sep 22 14:17:30 1994 (2E82027A)
  2346.     CheckSum:         00091932
  2347.     ImageSize:        00094000
  2348.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2349. fffff800`85400000 fffff800`85444000   ucx01000   (deferred)            
  2350.     Image path: \SystemRoot\system32\drivers\ucx01000.sys
  2351.     Image name: ucx01000.sys
  2352.     Timestamp:        Wed Mar 07 16:31:05 1979 (11447CC9)
  2353.     CheckSum:         0004DFDA
  2354.     ImageSize:        00044000
  2355.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2356. fffff800`85450000 fffff800`85484000   TeeDriverW8x64   (deferred)            
  2357.     Image path: \SystemRoot\System32\drivers\TeeDriverW8x64.sys
  2358.     Image name: TeeDriverW8x64.sys
  2359.     Timestamp:        Sun Nov 19 03:39:59 2017 (5A116D8F)
  2360.     CheckSum:         0003F054
  2361.     ImageSize:        00034000
  2362.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2363. fffff800`85490000 fffff800`85526000   e1d68x64   (deferred)            
  2364.     Image path: \SystemRoot\System32\DriverStore\FileRepository\e1d68x64.inf_amd64_26255692c8b1c6b6\e1d68x64.sys
  2365.     Image name: e1d68x64.sys
  2366.     Timestamp:        Tue Sep 29 07:11:02 2020 (5F734E86)
  2367.     CheckSum:         00099A08
  2368.     ImageSize:        00096000
  2369.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2370. fffff800`85530000 fffff800`8554a000   usbehci    (deferred)            
  2371.     Image path: \SystemRoot\System32\drivers\usbehci.sys
  2372.     Image name: usbehci.sys
  2373.     Timestamp:        Mon Jan 08 08:10:05 1979 (10F7905D)
  2374.     CheckSum:         000239DC
  2375.     ImageSize:        0001A000
  2376.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2377. fffff800`85550000 fffff800`855c9000   USBPORT    (deferred)            
  2378.     Image path: \SystemRoot\System32\drivers\USBPORT.SYS
  2379.     Image name: USBPORT.SYS
  2380.     Timestamp:        Sat Nov 03 06:27:44 2029 (708EDB60)
  2381.     CheckSum:         0007822B
  2382.     ImageSize:        00079000
  2383.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2384. fffff800`855d0000 fffff800`855f1000   i8042prt   (deferred)            
  2385.     Image path: \SystemRoot\System32\drivers\i8042prt.sys
  2386.     Image name: i8042prt.sys
  2387.     Timestamp:        Wed Apr 03 23:16:01 2013 (515D28B1)
  2388.     CheckSum:         00022B0C
  2389.     ImageSize:        00021000
  2390.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2391. fffff800`85600000 fffff800`8561c000   serial     (deferred)            
  2392.     Image path: \SystemRoot\System32\drivers\serial.sys
  2393.     Image name: serial.sys
  2394.     Timestamp:        Wed Apr 19 02:23:01 2017 (58F73A85)
  2395.     CheckSum:         0001B585
  2396.     ImageSize:        0001C000
  2397.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2398. fffff800`85620000 fffff800`8562f000   serenum    (deferred)            
  2399.     Image path: \SystemRoot\System32\drivers\serenum.sys
  2400.     Image name: serenum.sys
  2401.     Timestamp:        ***** Invalid (A5178D42)
  2402.     CheckSum:         00009616
  2403.     ImageSize:        0000F000
  2404.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2405. fffff800`85630000 fffff800`8563c000   wmiacpi    (deferred)            
  2406.     Image path: \SystemRoot\System32\drivers\wmiacpi.sys
  2407.     Image name: wmiacpi.sys
  2408.     Timestamp:        Wed Aug 19 05:20:44 2009 (4A8BFC2C)
  2409.     CheckSum:         0000CC2F
  2410.     ImageSize:        0000C000
  2411.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2412. fffff800`85640000 fffff800`85680000   intelppm   (deferred)            
  2413.     Image path: \SystemRoot\System32\drivers\intelppm.sys
  2414.     Image name: intelppm.sys
  2415.     Timestamp:        Tue Jun 14 02:18:00 2016 (575FD9D8)
  2416.     CheckSum:         00047AB7
  2417.     ImageSize:        00040000
  2418.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2419. fffff800`85690000 fffff800`856a0000   XtuAcpiDriver   (deferred)            
  2420.     Image path: \SystemRoot\System32\drivers\XtuAcpiDriver.sys
  2421.     Image name: XtuAcpiDriver.sys
  2422.     Timestamp:        Thu Mar 05 16:20:30 2020 (5E61974E)
  2423.     CheckSum:         0001DB9D
  2424.     ImageSize:        00010000
  2425.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2426. fffff800`856b0000 fffff800`856bd000   NdisVirtualBus   (deferred)            
  2427.     Image path: \SystemRoot\System32\drivers\NdisVirtualBus.sys
  2428.     Image name: NdisVirtualBus.sys
  2429.     Timestamp:        ***** Invalid (A7AE93D1)
  2430.     CheckSum:         00014F1D
  2431.     ImageSize:        0000D000
  2432.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2433. fffff800`856c0000 fffff800`856cc000   swenum     (deferred)            
  2434.     Image path: \SystemRoot\System32\DriverStore\FileRepository\swenum.inf_amd64_16a14542b63c02af\swenum.sys
  2435.     Image name: swenum.sys
  2436.     Timestamp:        ***** Invalid (E117266B)
  2437.     CheckSum:         000082C9
  2438.     ImageSize:        0000C000
  2439.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2440. fffff800`856d0000 fffff800`856de000   rdpbus     (deferred)            
  2441.     Image path: \SystemRoot\System32\drivers\rdpbus.sys
  2442.     Image name: rdpbus.sys
  2443.     Timestamp:        ***** Invalid (84DFD52A)
  2444.     CheckSum:         000106CE
  2445.     ImageSize:        0000E000
  2446.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2447. fffff800`856e0000 fffff800`85765000   usbhub     (deferred)            
  2448.     Image path: \SystemRoot\System32\drivers\usbhub.sys
  2449.     Image name: usbhub.sys
  2450.     Timestamp:        Mon Apr 24 01:59:16 2017 (58FDCC74)
  2451.     CheckSum:         00084516
  2452.     ImageSize:        00085000
  2453.     File version:     10.0.19041.1
  2454.     Product version:  10.0.19041.1
  2455.     File flags:       0 (Mask 3F)
  2456.     File OS:          40004 NT Win32
  2457.     File type:        2.0 Dll
  2458.     File date:        00000000.00000000
  2459.     Translations:     0409.04b0
  2460.     CompanyName:      Microsoft Corporation
  2461.     ProductName:      Microsoft® Windows® Operating System
  2462.     InternalName:     usbhub.sys
  2463.     OriginalFilename: usbhub.sys
  2464.     ProductVersion:   10.0.19041.1
  2465.     FileVersion:      10.0.19041.1 (WinBuild.160101.0800)
  2466.     FileDescription:  Default Hub Driver for USB
  2467.     LegalCopyright:   © Microsoft Corporation. All rights reserved.
  2468. fffff800`85770000 fffff800`8577e000   USBD       (deferred)            
  2469.     Image path: \SystemRoot\System32\drivers\USBD.SYS
  2470.     Image name: USBD.SYS
  2471.     Timestamp:        Wed Feb 02 14:47:35 2033 (76AC3507)
  2472.     CheckSum:         0000FFB7
  2473.     ImageSize:        0000E000
  2474.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2475. fffff800`85780000 fffff800`857b8000   nvhda64v   (deferred)            
  2476.     Image path: \SystemRoot\system32\drivers\nvhda64v.sys
  2477.     Image name: nvhda64v.sys
  2478.     Timestamp:        Tue Jun 09 10:01:25 2020 (5EDFCE75)
  2479.     CheckSum:         0003B8F0
  2480.     ImageSize:        00038000
  2481.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2482. fffff800`857c0000 fffff800`857cf000   ksthunk    (deferred)            
  2483.     Image path: \SystemRoot\system32\drivers\ksthunk.sys
  2484.     Image name: ksthunk.sys
  2485.     Timestamp:        Thu Apr 25 06:23:02 1991 (2816E646)
  2486.     CheckSum:         00007961
  2487.     ImageSize:        0000F000
  2488.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2489. fffff800`857d0000 fffff800`85873000   UsbHub3    (deferred)            
  2490.     Image path: \SystemRoot\System32\drivers\UsbHub3.sys
  2491.     Image name: UsbHub3.sys
  2492.     Timestamp:        ***** Invalid (FDA30E83)
  2493.     CheckSum:         000AC346
  2494.     ImageSize:        000A3000
  2495.     File version:     10.0.19041.264
  2496.     Product version:  10.0.19041.264
  2497.     File flags:       0 (Mask 3F)
  2498.     File OS:          40004 NT Win32
  2499.     File type:        3.7 Driver
  2500.     File date:        00000000.00000000
  2501.     Translations:     0409.04b0
  2502.     CompanyName:      Microsoft Corporation
  2503.     ProductName:      Microsoft® Windows® Operating System
  2504.     InternalName:     usbhub3.sys
  2505.     OriginalFilename: usbhub3.sys
  2506.     ProductVersion:   10.0.19041.264
  2507.     FileVersion:      10.0.19041.264 (WinBuild.160101.0800)
  2508.     FileDescription:  USB3 HUB Driver
  2509.     LegalCopyright:   © Microsoft Corporation. All rights reserved.
  2510. fffff800`85880000 fffff800`85e5e000   RTKVHD64   (deferred)            
  2511.     Image path: \SystemRoot\system32\drivers\RTKVHD64.sys
  2512.     Image name: RTKVHD64.sys
  2513.     Timestamp:        Thu Sep 24 02:20:38 2020 (5F6C72F6)
  2514.     CheckSum:         005EDBA6
  2515.     ImageSize:        005DE000
  2516.     File version:     6.0.9035.1
  2517.     Product version:  6.0.9035.1
  2518.     File flags:       8 (Mask 3F) Private
  2519.     File OS:          40004 NT Win32
  2520.     File type:        3.9 Driver
  2521.     File date:        00000000.00000000
  2522.     Translations:     0409.04b0
  2523.     CompanyName:      Realtek Semiconductor Corp.
  2524.     ProductName:      Realtek(r) High Definition Audio Function Driver
  2525.     InternalName:     RTKVHD64.sys 9035
  2526.     OriginalFilename: RTKVHD64.sys
  2527.     ProductVersion:   6.0.9035.1
  2528.     FileVersion:      6.0.9035.1 built by: WinDDK
  2529.     FileDescription:  Realtek(r) High Definition Audio Function Driver
  2530.     LegalCopyright:   Copyright (c) Realtek Semiconductor Corp.1998-2013
  2531. fffff800`85e60000 fffff800`85e78000   mslldp     (deferred)            
  2532.     Image path: \SystemRoot\system32\drivers\mslldp.sys
  2533.     Image name: mslldp.sys
  2534.     Timestamp:        Wed Aug 07 19:50:12 2030 (71FCC6F4)
  2535.     CheckSum:         00016923
  2536.     ImageSize:        00018000
  2537.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2538. fffff800`85e80000 fffff800`85e92000   hidusb     (deferred)            
  2539.     Image path: \SystemRoot\System32\drivers\hidusb.sys
  2540.     Image name: hidusb.sys
  2541.     Timestamp:        ***** Invalid (A66785A7)
  2542.     CheckSum:         000170ED
  2543.     ImageSize:        00012000
  2544.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2545. fffff800`85ea0000 fffff800`85edf000   HIDCLASS   (deferred)            
  2546.     Image path: \SystemRoot\System32\drivers\HIDCLASS.SYS
  2547.     Image name: HIDCLASS.SYS
  2548.     Timestamp:        ***** Invalid (A07210A7)
  2549.     CheckSum:         0003DA22
  2550.     ImageSize:        0003F000
  2551.     File version:     10.0.19041.1
  2552.     Product version:  10.0.19041.1
  2553.     File flags:       0 (Mask 3F)
  2554.     File OS:          40004 NT Win32
  2555.     File type:        2.0 Dll
  2556.     File date:        00000000.00000000
  2557.     Translations:     0409.04b0
  2558.     CompanyName:      Microsoft Corporation
  2559.     ProductName:      Microsoft® Windows® Operating System
  2560.     InternalName:     hidclass.sys
  2561.     OriginalFilename: hidclass.sys
  2562.     ProductVersion:   10.0.19041.1
  2563.     FileVersion:      10.0.19041.1 (WinBuild.160101.0800)
  2564.     FileDescription:  Hid Class Library
  2565.     LegalCopyright:   © Microsoft Corporation. All rights reserved.
  2566. fffff800`85ee0000 fffff800`85ef3000   HIDPARSE   (deferred)            
  2567.     Image path: \SystemRoot\System32\drivers\HIDPARSE.SYS
  2568.     Image name: HIDPARSE.SYS
  2569.     Timestamp:        Wed Aug 27 17:20:06 1997 (3404D246)
  2570.     CheckSum:         00016359
  2571.     ImageSize:        00013000
  2572.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2573. fffff800`85f00000 fffff800`85f10000   mouhid     (deferred)            
  2574.     Image path: \SystemRoot\System32\drivers\mouhid.sys
  2575.     Image name: mouhid.sys
  2576.     Timestamp:        ***** Invalid (E502FBD9)
  2577.     CheckSum:         000173E5
  2578.     ImageSize:        00010000
  2579.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2580. fffff800`85f20000 fffff800`85f33000   mouclass   (deferred)            
  2581.     Image path: \SystemRoot\System32\drivers\mouclass.sys
  2582.     Image name: mouclass.sys
  2583.     Timestamp:        Tue Jan 07 02:19:56 2003 (3E1AA9CC)
  2584.     CheckSum:         00019679
  2585.     ImageSize:        00013000
  2586.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2587. fffff800`85f50000 fffff800`85f5e000   dump_diskdump   (deferred)            
  2588.     Image path: \SystemRoot\System32\Drivers\dump_diskdump.sys
  2589.     Image name: dump_diskdump.sys
  2590.     Timestamp:        ***** Invalid (95F39C8A)
  2591.     CheckSum:         0000B16B
  2592.     ImageSize:        0000E000
  2593.     File version:     10.0.19041.1
  2594.     Product version:  10.0.19041.1
  2595.     File flags:       0 (Mask 3F)
  2596.     File OS:          40004 NT Win32
  2597.     File type:        3.7 Driver
  2598.     File date:        00000000.00000000
  2599.     Translations:     0409.04b0
  2600.     CompanyName:      Microsoft Corporation
  2601.     ProductName:      Microsoft® Windows® Operating System
  2602.     InternalName:     diskdump.sys
  2603.     OriginalFilename: diskdump.sys
  2604.     ProductVersion:   10.0.19041.1
  2605.     FileVersion:      10.0.19041.1 (WinBuild.160101.0800)
  2606.     FileDescription:  Crash Dump Disk Driver
  2607.     LegalCopyright:   © Microsoft Corporation. All rights reserved.
  2608. fffff800`860b0000 fffff800`860cd000   dump_dumpfve   (deferred)            
  2609.     Image path: \SystemRoot\System32\Drivers\dump_dumpfve.sys
  2610.     Image name: dump_dumpfve.sys
  2611.     Timestamp:        Thu Oct 05 10:32:17 2023 (651F0131)
  2612.     CheckSum:         00022E48
  2613.     ImageSize:        0001D000
  2614.     File version:     10.0.19041.1
  2615.     Product version:  10.0.19041.1
  2616.     File flags:       0 (Mask 3F)
  2617.     File OS:          40004 NT Win32
  2618.     File type:        3.7 Driver
  2619.     File date:        00000000.00000000
  2620.     Translations:     0000.04b0
  2621.     CompanyName:      Microsoft Corporation
  2622.     ProductName:      Microsoft® Windows® Operating System
  2623.     InternalName:     dumpfve.sys
  2624.     OriginalFilename: dumpfve.sys
  2625.     ProductVersion:   10.0.19041.1
  2626.     FileVersion:      10.0.19041.1 (WinBuild.160101.0800)
  2627.     FileDescription:  Bitlocker Drive Encryption Crashdump Filter
  2628.     LegalCopyright:   © Microsoft Corporation. All rights reserved.
  2629. fffff800`860d0000 fffff800`860eb000   monitor    (deferred)            
  2630.     Image path: \SystemRoot\System32\drivers\monitor.sys
  2631.     Image name: monitor.sys
  2632.     Timestamp:        Wed May 01 10:30:47 1985 (1CD682D7)
  2633.     CheckSum:         0001751B
  2634.     ImageSize:        0001B000
  2635.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2636. fffff800`860f0000 fffff800`860fd000   rdpvideominiport   (deferred)            
  2637.     Image path: \SystemRoot\System32\drivers\rdpvideominiport.sys
  2638.     Image name: rdpvideominiport.sys
  2639.     Timestamp:        Sun Jul 12 11:13:17 1981 (15AF594D)
  2640.     CheckSum:         00015381
  2641.     ImageSize:        0000D000
  2642.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2643. fffff800`86100000 fffff800`8612f000   rdpdr      (deferred)            
  2644.     Image path: \SystemRoot\System32\drivers\rdpdr.sys
  2645.     Image name: rdpdr.sys
  2646.     Timestamp:        ***** Invalid (9EEF34DA)
  2647.     CheckSum:         0002BAD1
  2648.     ImageSize:        0002F000
  2649.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2650. fffff800`86130000 fffff800`86159000   luafv      (deferred)            
  2651.     Image path: \SystemRoot\system32\drivers\luafv.sys
  2652.     Image name: luafv.sys
  2653.     Timestamp:        Sat Jan 23 18:15:51 2016 (56A433D7)
  2654.     CheckSum:         00030A3A
  2655.     ImageSize:        00029000
  2656.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2657. fffff800`86160000 fffff800`8726d000   nvlddmkm   (deferred)            
  2658.     Image path: \SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_c1a085cc86772d3f\nvlddmkm.sys
  2659.     Image name: nvlddmkm.sys
  2660.     Timestamp:        Fri Mar 23 15:02:22 2018 (5AB5877E)
  2661.     CheckSum:         010C6B80
  2662.     ImageSize:        0110D000
  2663.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2664. fffff800`87270000 fffff800`87295000   HDAudBus   (deferred)            
  2665.     Image path: \SystemRoot\System32\drivers\HDAudBus.sys
  2666.     Image name: HDAudBus.sys
  2667.     Timestamp:        Wed Nov 17 21:08:44 2021 (6195DFDC)
  2668.     CheckSum:         000268EC
  2669.     ImageSize:        00025000
  2670.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2671. fffff800`872a0000 fffff800`87306000   portcls    (deferred)            
  2672.     Image path: \SystemRoot\System32\drivers\portcls.sys
  2673.     Image name: portcls.sys
  2674.     Timestamp:        Mon Dec 23 15:28:58 2002 (3E079C3A)
  2675.     CheckSum:         0006B23D
  2676.     ImageSize:        00066000
  2677.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2678. fffff800`87310000 fffff800`87331000   drmk       (deferred)            
  2679.     Image path: \SystemRoot\System32\drivers\drmk.sys
  2680.     Image name: drmk.sys
  2681.     Timestamp:        ***** Invalid (92B1AC47)
  2682.     CheckSum:         0001A51A
  2683.     ImageSize:        00021000
  2684.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2685. fffff800`87340000 fffff800`873d8000   USBXHCI    (deferred)            
  2686.     Image path: \SystemRoot\System32\drivers\USBXHCI.SYS
  2687.     Image name: USBXHCI.SYS
  2688.     Timestamp:        Sun Aug 07 06:37:42 1994 (2E44F1B6)
  2689.     CheckSum:         0009CD76
  2690.     ImageSize:        00098000
  2691.     File version:     10.0.19041.488
  2692.     Product version:  10.0.19041.488
  2693.     File flags:       0 (Mask 3F)
  2694.     File OS:          40004 NT Win32
  2695.     File type:        3.7 Driver
  2696.     File date:        00000000.00000000
  2697.     Translations:     0409.04b0
  2698.     CompanyName:      Microsoft Corporation
  2699.     ProductName:      Microsoft® Windows® Operating System
  2700.     InternalName:     usbxhci.sys
  2701.     OriginalFilename: usbxhci.sys
  2702.     ProductVersion:   10.0.19041.488
  2703.     FileVersion:      10.0.19041.488 (WinBuild.160101.0800)
  2704.     FileDescription:  USB XHCI Driver
  2705.     LegalCopyright:   © Microsoft Corporation. All rights reserved.
  2706. fffff800`873e0000 fffff800`873fa000   storqosflt   (deferred)            
  2707.     Image path: \SystemRoot\system32\drivers\storqosflt.sys
  2708.     Image name: storqosflt.sys
  2709.     Timestamp:        Mon Apr 09 10:08:30 2007 (461A811E)
  2710.     CheckSum:         00025AFB
  2711.     ImageSize:        0001A000
  2712.     Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
  2713.  
  2714. Unloaded modules:
  2715. fffff800`834a0000 fffff800`834e2000   klids.sys
  2716.     Timestamp: unavailable (00000000)
  2717.     Checksum:  00000000
  2718.     ImageSize:  00042000
  2719. fffff800`82ac0000 fffff800`82add000   raspppoe.sys
  2720.     Timestamp: unavailable (00000000)
  2721.     Checksum:  00000000
  2722.     ImageSize:  0001D000
  2723. fffff800`82a90000 fffff800`82ab2000   raspptp.sys
  2724.     Timestamp: unavailable (00000000)
  2725.     Checksum:  00000000
  2726.     ImageSize:  00022000
  2727. fffff800`82a60000 fffff800`82a82000   rasl2tp.sys
  2728.     Timestamp: unavailable (00000000)
  2729.     Checksum:  00000000
  2730.     ImageSize:  00022000
  2731. fffff800`83160000 fffff800`8316e000   WSDPrint.sys
  2732.     Timestamp: unavailable (00000000)
  2733.     Checksum:  00000000
  2734.     ImageSize:  0000E000
  2735. fffff800`7eb70000 fffff800`7eb7f000   WpdUpFltr.sys
  2736.     Timestamp: unavailable (00000000)
  2737.     Checksum:  00000000
  2738.     ImageSize:  0000F000
  2739. fffff800`7eb10000 fffff800`7eb65000   WUDFRd.sys
  2740.     Timestamp: unavailable (00000000)
  2741.     Checksum:  00000000
  2742.     ImageSize:  00055000
  2743. fffff800`7eb80000 fffff800`7eb9d000   EhStorClass.sys
  2744.     Timestamp: unavailable (00000000)
  2745.     Checksum:  00000000
  2746.     ImageSize:  0001D000
  2747. fffff800`7f280000 fffff800`7f29d000   EhStorClass.sys
  2748.     Timestamp: unavailable (00000000)
  2749.     Checksum:  00000000
  2750.     ImageSize:  0001D000
  2751. fffff800`82550000 fffff800`82569000   uaspstor.sys
  2752.     Timestamp: unavailable (00000000)
  2753.     Checksum:  00000000
  2754.     ImageSize:  00019000
  2755. fffff800`7ed60000 fffff800`7ed7d000   EhStorClass.sys
  2756.     Timestamp: unavailable (00000000)
  2757.     Checksum:  00000000
  2758.     ImageSize:  0001D000
  2759. fffff800`834a0000 fffff800`834e2000   klids.sys
  2760.     Timestamp: unavailable (00000000)
  2761.     Checksum:  00000000
  2762.     ImageSize:  00042000
  2763. fffff800`83e60000 fffff800`83e6d000   csvol.sys
  2764.     Timestamp: unavailable (00000000)
  2765.     Checksum:  00000000
  2766.     ImageSize:  0000D000
  2767. fffff800`82a70000 fffff800`82a7f000   dump_storport.sys
  2768.     Timestamp: unavailable (00000000)
  2769.     Checksum:  00000000
  2770.     ImageSize:  0000F000
  2771. fffff800`82400000 fffff800`82530000   dump_iaStorE.sys
  2772.     Timestamp: unavailable (00000000)
  2773.     Checksum:  00000000
  2774.     ImageSize:  00130000
  2775. fffff800`82550000 fffff800`8256e000   dump_dumpfve.sys
  2776.     Timestamp: unavailable (00000000)
  2777.     Checksum:  00000000
  2778.     ImageSize:  0001E000
  2779. fffff800`85e60000 fffff800`85e79000   uaspstor.sys
  2780.     Timestamp: unavailable (00000000)
  2781.     Checksum:  00000000
  2782.     ImageSize:  00019000
  2783. fffff800`812c0000 fffff800`812dd000   EhStorClass.sys
  2784.     Timestamp: unavailable (00000000)
  2785.     Checksum:  00000000
  2786.     ImageSize:  0001D000
  2787. fffff800`83530000 fffff800`8354c000   dam.sys
  2788.     Timestamp: unavailable (00000000)
  2789.     Checksum:  00000000
  2790.     ImageSize:  0001C000
  2791. fffff800`80c50000 fffff800`80c5f000   klelam.sys
  2792.     Timestamp: unavailable (00000000)
  2793.     Checksum:  00000000
  2794.     ImageSize:  0000F000
  2795. fffff800`81eb0000 fffff800`81ec1000   hwpolicy.sys
  2796.     Timestamp: unavailable (00000000)
  2797.     Checksum:  00000000
  2798.     ImageSize:  00011000
  2799. 6: kd> q
  2800. quit: