Share via

Driver Verify Tool crash analysis

Ben Bolt 0 Reputation points
2025-09-14T19:26:54.0066667+00:00

I just ran the Driver Verify Tool and let my computer crash three times before turning the tool off. Below is the dmp file of the first crash. I would like some help as to what my problem could be.

************* Preparing the environment for Debugger Extensions Gallery repositories **************
   ExtensionRepository : Implicit
   UseExperimentalFeatureForNugetShare : true
   AllowNugetExeUpdate : true
   NonInteractiveNuget : true
   AllowNugetMSCredentialProviderInstall : true
   AllowParallelInitializationOfLocalRepositories : true
   EnableRedirectToChakraJsProvider : false

   -- Configuring repositories
      ----> Repository : LocalInstalled, Enabled: true
      ----> Repository : UserExtensions, Enabled: true

>>>>>>>>>>>>> Preparing the environment for Debugger Extensions Gallery repositories completed, duration 0.000 seconds

************* Waiting for Debugger Extensions Gallery to Initialize **************

>>>>>>>>>>>>> Waiting for Debugger Extensions Gallery to Initialize completed, duration 0.015 seconds
   ----> Repository : UserExtensions, Enabled: true, Packages count: 0
   ----> Repository : LocalInstalled, Enabled: true, Packages count: 45

Microsoft (R) Windows Debugger Version 10.0.27920.1001 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Windows\Minidump\091425-20312-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: srv*
Executable search path is: 
Windows 10 Kernel Version 26100 MP (32 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Kernel base = 0xfffff807`ce5c0000 PsLoadedModuleList = 0xfffff807`cf4b4e70
Debug session time: Sun Sep 14 13:40:10.403 2025 (UTC - 7:00)
System Uptime: 0 days 0:00:46.120
Loading Kernel Symbols
..

Press ctrl-c (cdb, kd, ntsd) or ctrl-break (windbg) to abort symbol loads that take too long.
Run !sym noisy before .reload to track down problems loading symbols.

.............................................................
................................................................
................................................................
................
Loading User Symbols
PEB is paged out (Peb.Ldr = 00000089`5615d018).  Type ".hh dbgerr001" for details
Loading unloaded module list
............
For analysis of this file, run !analyze -v
nt!KeBugCheckEx:
fffff807`ceab9280 48894c2408      mov     qword ptr [rsp+8],rcx ss:0018:ffffba0f`45086630=000000000000001a
1: kd> !analyze -v
Loading Kernel Symbols
..

Press ctrl-c (cdb, kd, ntsd) or ctrl-break (windbg) to abort symbol loads that take too long.
Run !sym noisy before .reload to track down problems loading symbols.

.............................................................
................................................................
................................................................
................
Loading User Symbols
PEB is paged out (Peb.Ldr = 00000089`5615d018).  Type ".hh dbgerr001" for details
Loading unloaded module list
............
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

MEMORY_MANAGEMENT (1a)
    # Any other values for parameter 1 must be individually examined.
Arguments:
Arg1: 0000000000041790, A page table page has been corrupted. On a 64 bit OS, parameter 2
	contains the address of the PFN for the corrupted page table page.
	On a 32 bit OS, parameter 2 contains a pointer to the number of used
	PTEs, and parameter 3 contains the number of used PTEs.
Arg2: ffffa9000a095c60
Arg3: 0000000000000000
Arg4: 0000000000000001

Debugging Details:
------------------


KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.mSec
    Value: 890

    Key  : Analysis.Elapsed.mSec
    Value: 3711

    Key  : Analysis.IO.Other.Mb
    Value: 0

    Key  : Analysis.IO.Read.Mb
    Value: 1

    Key  : Analysis.IO.Write.Mb
    Value: 30

    Key  : Analysis.Init.CPU.mSec
    Value: 796

    Key  : Analysis.Init.Elapsed.mSec
    Value: 64630

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 121

    Key  : Analysis.Version.DbgEng
    Value: 10.0.27920.1001

    Key  : Analysis.Version.Description
    Value: 10.2506.23.01 amd64fre

    Key  : Analysis.Version.Ext
    Value: 1.2506.23.1

    Key  : Bugcheck.Code.LegacyAPI
    Value: 0x1a

    Key  : Bugcheck.Code.TargetModel
    Value: 0x1a

    Key  : Dump.Attributes.AsUlong
    Value: 0x21808

    Key  : Dump.Attributes.DiagDataWrittenToHeader
    Value: 1

    Key  : Dump.Attributes.ErrorCode
    Value: 0x0

    Key  : Dump.Attributes.KernelGeneratedTriageDump
    Value: 1

    Key  : Dump.Attributes.LastLine
    Value: Dump completed successfully.

    Key  : Dump.Attributes.ProgressPercentage
    Value: 0

    Key  : Failure.Bucket
    Value: 0x1a_41790_WdFilter!MpCopyCacheOnPostCreate

    Key  : Failure.Hash
    Value: {7d348062-bc54-3c98-df19-738e9c6b2c94}

    Key  : Hypervisor.Enlightenments.ValueHex
    Value: 0x7417df84

    Key  : Hypervisor.Flags.AnyHypervisorPresent
    Value: 1

    Key  : Hypervisor.Flags.ApicEnlightened
    Value: 0

    Key  : Hypervisor.Flags.ApicVirtualizationAvailable
    Value: 1

    Key  : Hypervisor.Flags.AsyncMemoryHint
    Value: 0

    Key  : Hypervisor.Flags.CoreSchedulerRequested
    Value: 0

    Key  : Hypervisor.Flags.CpuManager
    Value: 1

    Key  : Hypervisor.Flags.DeprecateAutoEoi
    Value: 1

    Key  : Hypervisor.Flags.DynamicCpuDisabled
    Value: 1

    Key  : Hypervisor.Flags.Epf
    Value: 0

    Key  : Hypervisor.Flags.ExtendedProcessorMasks
    Value: 1

    Key  : Hypervisor.Flags.HardwareMbecAvailable
    Value: 1

    Key  : Hypervisor.Flags.MaxBankNumber
    Value: 0

    Key  : Hypervisor.Flags.MemoryZeroingControl
    Value: 0

    Key  : Hypervisor.Flags.NoExtendedRangeFlush
    Value: 0

    Key  : Hypervisor.Flags.NoNonArchCoreSharing
    Value: 1

    Key  : Hypervisor.Flags.Phase0InitDone
    Value: 1

    Key  : Hypervisor.Flags.PowerSchedulerQos
    Value: 0

    Key  : Hypervisor.Flags.RootScheduler
    Value: 0

    Key  : Hypervisor.Flags.SynicAvailable
    Value: 1

    Key  : Hypervisor.Flags.UseQpcBias
    Value: 0

    Key  : Hypervisor.Flags.Value
    Value: 55185662

    Key  : Hypervisor.Flags.ValueHex
    Value: 0x34a10fe

    Key  : Hypervisor.Flags.VpAssistPage
    Value: 1

    Key  : Hypervisor.Flags.VsmAvailable
    Value: 1

    Key  : Hypervisor.RootFlags.AccessStats
    Value: 1

    Key  : Hypervisor.RootFlags.CrashdumpEnlightened
    Value: 1

    Key  : Hypervisor.RootFlags.CreateVirtualProcessor
    Value: 1

    Key  : Hypervisor.RootFlags.DisableHyperthreading
    Value: 0

    Key  : Hypervisor.RootFlags.HostTimelineSync
    Value: 1

    Key  : Hypervisor.RootFlags.HypervisorDebuggingEnabled
    Value: 0

    Key  : Hypervisor.RootFlags.IsHyperV
    Value: 1

    Key  : Hypervisor.RootFlags.LivedumpEnlightened
    Value: 1

    Key  : Hypervisor.RootFlags.MapDeviceInterrupt
    Value: 1

    Key  : Hypervisor.RootFlags.MceEnlightened
    Value: 1

    Key  : Hypervisor.RootFlags.Nested
    Value: 0

    Key  : Hypervisor.RootFlags.StartLogicalProcessor
    Value: 1

    Key  : Hypervisor.RootFlags.Value
    Value: 1015

    Key  : Hypervisor.RootFlags.ValueHex
    Value: 0x3f7

    Key  : WER.System.BIOSRevision
    Value: 30.1.0.0


BUGCHECK_CODE:  1a

BUGCHECK_P1: 41790

BUGCHECK_P2: ffffa9000a095c60

BUGCHECK_P3: 0

BUGCHECK_P4: 1

FILE_IN_CAB:  091425-20312-01.dmp

TAG_NOT_DEFINED_202b:  *** Unknown TAG in analysis list 202b


DUMP_FILE_ATTRIBUTES: 0x21808
  Kernel Generated Triage Dump

FAULTING_THREAD:  ffffbc0b0b1cd080

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXWINLOGON: 1 (!blackboxwinlogon)


CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  powershell.exe

STACK_TEXT:  
ffffba0f`45086628 fffff807`ce9ef8af     : 00000000`0000001a 00000000`00041790 ffffa900`0a095c60 00000000`00000000 : nt!KeBugCheckEx
ffffba0f`45086630 fffff807`ce8721ca     : ffffba0f`45086700 ffffba0f`450867a0 00000000`00000000 00000000`00000001 : nt!MiReducePteUseCount+0x1ff
ffffba0f`45086670 fffff807`ce941d71     : 87000003`73330963 ffffba0f`450867a0 87000003`73330963 ffffd041`425e0808 : nt!MiDecommitPagesTail+0x36
ffffba0f`450866a0 fffff807`ce8bab5b     : 00000000`00000001 ffffffff`ffffffff 00000000`00000100 0000007f`fffffff8 : nt!MiDecommitPages+0x291
ffffba0f`45086820 fffff807`ce8b9f81     : 00000000`00001000 ffffba0f`45086951 ffff8284`80100140 00000000`00004000 : nt!MmFreePoolMemory+0xfb
ffffba0f`450868c0 fffff807`ce8b9a4c     : ffff8284`00004000 00000000`ffffffff fffff807`00000000 00001f80`00000001 : nt!RtlpHpSegMgrCommit+0x2d9
ffffba0f`450869a0 fffff807`ce8a0c2c     : ffff8284`000000de ffff8284`bc101bc0 ffff8284`00000000 00000000`fffffffe : nt!RtlpHpSegPageRangeCommit+0x274
ffffba0f`45086a50 fffff807`ce8a0e3b     : ffff8284`00000000 00000000`00000001 00000000`00000000 ffffba0f`45086b30 : nt!RtlpHpSegPageRangeCoalesce+0x1ec
ffffba0f`45086ac0 fffff807`ce89eb40     : ffff8284`bc1def10 00000000`00000000 ffff8284`bc1000ff 00000000`000000f0 : nt!RtlpHpSegPageRangeShrink+0x9b
ffffba0f`45086b20 fffff807`cf123478     : ffffba0f`45086c29 ffffba0f`45086c29 00000000`00000000 fffff807`ce9080f4 : nt!RtlpHpFreeHeap+0x350
ffffba0f`45086b90 fffff807`cebd252c     : ffff8284`bc1def00 ffffbc0a`c147ef60 ffff8284`80100000 ffffbc0a`d090eb00 : nt!ExFreePoolWithTag+0x7a8
ffffba0f`45086c90 fffff807`61661274     : ffff8284`a379af58 ffffba0f`45086f10 ffffba0f`45087058 ffffbc0b`086e0680 : nt!DifExFreePoolWithTagWrapper+0xdc
ffffba0f`45086cf0 fffff807`61685dc5     : 00000000`00000000 00000000`00000000 ffffba0f`45087058 ffff8284`a8e9d850 : WdFilter!MpCopyCacheOnPostCreate+0x204
ffffba0f`45086e10 fffff807`5fdf03f5     : ffffbc0b`0c7aeb58 ffffbc0b`0c7aec00 ffff8284`b7572cc0 fffff807`00000000 : WdFilter!MpPostCreate+0x1305
ffffba0f`45086f80 fffff807`5fd79db7     : ffffbc0b`0c7aea00 ffffbc0b`00080009 ffffbc0b`0c7aeae0 00000000`00000000 : FLTMGR!FltvPostOperation+0xc5
ffffba0f`45087010 fffff807`5fd7958e     : ffffbc0b`0c7aea70 00000000`00000000 ffffbc0a`e48b6af0 ffffbc0b`0c7aea70 : FLTMGR!FltpPerformPostCallbacksWorker+0x577
ffffba0f`450870d0 fffff807`5fd81166     : ffffbc0b`0c7aea70 ffffba0f`45081000 ffffbc0a`e48b6af0 00000000`00000000 : FLTMGR!FltpProcessIoCompletion+0x4e
ffffba0f`45087140 fffff807`5fd78ee1     : ffffbc0b`00000000 00000000`1000000c ffffbc0a`d07bbb00 ffffbc0b`0c7aea88 : FLTMGR!FltpPassThroughCompletionWorker+0x3a6
ffffba0f`450871b0 fffff807`5fde7d16     : ffffba0f`45087260 ffffba0f`00000000 00000000`00000000 00000000`00000000 : FLTMGR!FltpLegacyProcessingAfterPreCallbacksCompleted+0x281
ffffba0f`45087220 fffff807`ce91c20d     : ffffbc0a`e48b6f00 ffffbc0a`d07bbbd0 00000000`00000000 00000000`00000000 : FLTMGR!FltpCreate+0x706
ffffba0f`450872d0 fffff807`cf15c529     : ffffbc0a`e48b6af0 ffffbc0a`d07bbbd0 00000000`00000000 ffffbc0a`d0a08a90 : nt!IopfCallDriver+0xbd
ffffba0f`45087310 fffff807`ce91d424     : ffff8284`8020c605 ffffba0f`45087640 ffffbc0a`e48b6f20 ffffbc0a`d32f6b00 : nt!IovCallDriver+0x47c9
ffffba0f`45087350 fffff807`cee1f8d5     : ffff8284`8020c605 ffffba0f`45087640 ffffbc0a`d07bbbd0 ffffbc0a`d0a08a90 : nt!IofCallDriver+0x104
ffffba0f`45087390 fffff807`cee1d800     : 00000000`00000001 ffff8284`8020c6a0 00000000`00000000 ffffba0f`45087788 : nt!IopParseDevice+0x6e5
ffffba0f`45087540 fffff807`cee1b631     : ffffbc0b`05e94a01 ffffba0f`45087788 ffffbc0a`00000040 ffffbc0a`c17a4b10 : nt!ObpLookupObjectName+0xc90
ffffba0f`45087700 fffff807`ceeae9aa     : ffffba0f`00000000 ffffbc0a`c17a4b10 ffffbc0b`0b68caa0 00000000`00000000 : nt!ObOpenObjectByNameEx+0x201
ffffba0f`45087850 fffff807`ceeae519     : 00000089`57e4b410 00000000`80100080 00000089`57e4b498 00000089`57e4b440 : nt!IopCreateFile+0x47a
ffffba0f`45087920 fffff807`cec73055     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!NtCreateFile+0x79
ffffba0f`450879b0 00007ff9`ea0e3cd4     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
00000089`57e4b398 00000000`00000000     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff9`ea0e3cd4


SYMBOL_NAME:  WdFilter!MpCopyCacheOnPostCreate+204

MODULE_NAME: WdFilter

IMAGE_NAME:  WdFilter.sys

IMAGE_VERSION:  4.18.25070.5

STACK_COMMAND: .process /r /p 0xffffbc0b0b6230c0; .thread 0xffffbc0b0b1cd080 ; kb

BUCKET_ID_FUNC_OFFSET:  204

FAILURE_BUCKET_ID:  0x1a_41790_WdFilter!MpCopyCacheOnPostCreate

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

FAILURE_ID_HASH:  {7d348062-bc54-3c98-df19-738e9c6b2c94}

Followup:     MachineOwner
---------
Windows for home | Windows 11 | Performance and system failures
0 comments No comments

2 answers

Sort by: Most helpful
  1. Lester Bernard Reyes 82,020 Reputation points Independent Advisor
    2025-09-14T22:30:12.1966667+00:00

    Hi, thank you for replying. As per checking and analyzing the DMP files, there are 2 significant errors on the PC. The first is the WdFilter.sys. Have you done the in-place upgrade? If not, kindly proceed to fix the Windows Defender error.

    In addition, there is also an error GenuineIntel.sys. This is actually a processor error. It is either that the processor is getting hardware errors or it is overheating. Moreover, kindly follow the steps below for us to fix the issue:

     

    Method 1. Run the Intel Diagnostic tool:

     

    Go to this link: https://www.intel.com/content/www/us/en/download/15951/19792/intel-processor-diagnostic-tool.html

    Then download and run the tool.

     

    Suppose there is a failure on the test. In that case, that means there is a hardware issue with your processor, which you need to contact Intel support or a local technician for the next step, which might be a processor replacement or board, depending on the diagnosis of the hardware.

     

    Note: This is a non-Microsoft website. The page appears to be providing accurate, safe information. Watch out for ads on the site that may advertise products frequently classified as a PUP (Potentially Unwanted Products). Thoroughly research any product advertised on the site before you decide to download and install it.

    Method 1. Do a clean boot:

    A “clean boot” starts Windows with a minimal set of drivers and startup programs, so that you can determine whether a background program is interfering with your game or program.

    • In the search box on the taskbar, type msconfig and select System Configuration from the results.
    • On the Services tab of System Configuration, select Hide all Microsoft services, and then select Disable all.
    • On the Startup tab of System Configuration, select Open Task Manager.
    • Under Startup in Task Manager, for each startup item, select the item and then select Disable.
    • Close Task Manager.
    • On the Startup tab of System Configuration, select OK. When you restart the computer, it's in a clean boot environment.

    Troubleshooting reference: https://support.microsoft.com/en-us/help/929135/how-to-perform-a-clean-boot-in-windows

    Method 2. Run memory diagnostic tool: The memory diagnostic tool is a RAM test to check if there are any RAM issues.

    • Press Windows key + R, then type in mdsched.exe hit OK, then restart the device.

    Note: If the issue persists, I suggest contacting a local technician to physically check the processor or do a re-paste of thermal paste to optimize the processor.

     

    Was this answer helpful?

    0 comments No comments

  2. Lester Bernard Reyes 82,020 Reputation points Independent Advisor
    2025-09-14T21:29:18.1+00:00

    Hi, I'm Bernard, a fellow Windows user. I'm happy to help!

    I understand the issue you have. There is nothing to worry about. I am here to assist. As per checking and analyzing the DMP log, there is an error WdFilter.sys. This is a file system associated with Windows Defender, and it is either corrupted or miscalibrated. To sort out the issue, kindly follow the steps below:

     

    Method 1. Reinstall Windows Defender

     

    Open the registry, then go to

     

    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender

     

    Then delete the Windows Defender folder, restart the PC, and recheck it.

    If none of the above solutions work, I suggest doing an in-place upgrade, which will update the device to the latest version and repair all issues without deleting any files.

     

    Kindly follow the steps from this link:

    https://learn.microsoft.com/en-us/answers/questions/4252110/how-to-run-in-place-upgrade-in-windows-11

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.