MEMORY_MANAGEMENT (1a)
# Any other values for parameter 1 must be individually examined.
Arguments:
[COLOR="#FF0000"]Arg1: 0000000000041792[/COLOR], A corrupt PTE has been detected. Parameter 2 contains the address of
the PTE. Parameters 3/4 contain the low/high parts of the PTE.
Arg2: ffffec000022ba60
Arg3: 0000010000000000
Arg4: 0000000000000000
.....
DEFAULT_BUCKET_ID: CODE_CORRUPTION
[COLOR="#FF0000"]PROCESS_NAME: QtWebEngineProcess.exe[/COLOR]
.......
CHKIMG_EXTENSION: !chkimg -lo 50 -d !nt
!chkimg -lo 50 -d !nt
fffff803b352ce6d-fffff803b352ce6e 2 bytes - [COLOR="#FF0000"]nt!MiPurgeZeroList[/COLOR]+6d
[COLOR="#FF0000"][ 80 fa:00 f9 ][/COLOR]
[COLOR="#008000"]Beim Bereinigen der Liste wurde der Wert "80 fa" erwartet, aber der Wert "00 f9" vorgefunden[/COLOR]
fffff803b366b387-fffff803b366b389 3 bytes - [COLOR="#FF0000"]nt!ExFreePoolWithTag[/COLOR]+387
[COLOR="#FF0000"][ 40 fb f6:00 79 f2 ][/COLOR]
[COLOR="#008000"]Beim Freigeben des Pools wurde der Wert "40 fb f6" erwartet, aber der Wert "00 79 f2" vorgefunden[/COLOR]
5 errors : !nt (fffff803b352ce6d-fffff803b366b389)
.....
3: kd> !thread
THREAD ffffa18e202af080 Cid 1808.10b0 Teb: 00000000005b6000 Win32Thread: ffffa18e202e8940 RUNNING on processor 3
Not impersonating
GetUlongFromAddress: unable to read from fffff800f950e924
[COLOR="#FF0000"]Owning Process ffffa18e202a6080 Image: QtWebEngineProcess.exe[/COLOR]
[COLOR="#008000"]Der auslösende Thread gehört dem Prozess QtWebEngineProcess.exe [/COLOR]
Attached Process N/A Image: N/A
fffff78000000000: Unable to get shared data
Wait Start TickCount 35257
Context Switch Count 481 IdealProcessor: 0
ReadMemory error: Cannot get nt!KeMaximumIncrement value.
UserTime 00:00:00.000
KernelTime 00:00:00.000
Win32 Start Address 0x00000000011d2381
Stack Init ffffb180606aac90 Current ffffb180606aa710
Base ffffb180606ab000 Limit ffffb180606a5000 Call 0000000000000000
Priority 9 BasePriority 8 PriorityDecrement 0 IoPriority 2 PagePriority 5
Child-SP RetAddr : Args to Child : Call Site
ffffb180`606aa658 fffff800`f93afae3 : 00000000`0000001a 00000000`00041792 ffffec00`0022ba60 00000100`00000000 : nt!KeBugCheckEx
ffffb180`606aa660 fffff800`f92b2473 : ffffa18e`00000000 ffffa18e`1f1e2ab0 00000000`00000000 ffffa18e`202af080 : nt! ?? ::FNODOBFM::`string'+0x3e143
ffffb180`606aa870 fffff800`f9228739 : 00000000`457fffff 00000000`457fffff 00000000`45600000 ffffa18e`20528730 : nt!MiDeleteVad+0x7f3
ffffb180`606aa9a0 fffff800`f962866d : 00000000`00000000 00000000`45600000 00000000`00000000 00000000`00000001 : nt!MiFreeVadRange+0x4d
ffffb180`606aa9e0 fffff800`f936d193 : ffffa18e`202af080 00000000`00000000 00000000`00000000 00000000`005b6000 : nt!NtFreeVirtualMemory+0x2dd
ffffb180`606aab00 00007ffe`2d5f5224 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13 (TrapFrame @ ffffb180`606aab00)
00000000`0066e308 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffe`2d5f5224