KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff88009ddc1d1, The address that the exception occurred at
Arg3: 0000000000000000, Parameter 0 of the exception
Arg4: 0000000000000018, Parameter 1 of the exception
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s".
FAULTING_IP:
aksdf+61d1
fffff880`09ddc1d1 488b4818 mov rcx,qword ptr [rax+18h]
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: 0000000000000018
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002f070e0
0000000000000018
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0x1E
PROCESS_NAME: MsMpEng.exe
CURRENT_IRQL: 0
EXCEPTION_RECORD: fffff88009965328 -- (.exr 0xfffff88009965328)
ExceptionAddress: fffff88009ddc1d1 (aksdf+0x00000000000061d1)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: 0000000000000018
Attempt to read from address 0000000000000018
TRAP_FRAME: fffff880099653d0 -- (.trap 0xfffff880099653d0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=f880017c01e20000
rdx=0000000000000001 rsi=0000000000000000 rdi=0000000000000000
rip=fffff88009ddc1d1 rsp=fffff88009965560 rbp=fffffa800482a5c0
r8=fffffa800486e000 r9=0000000000000ec3 r10=fffffa800477ee40
r11=fffffa80045cbcb0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na po nc
aksdf+0x61d1:
fffff880`09ddc1d1 488b4818 mov rcx,qword ptr [rax+18h] ds:3500:00000000`00000018=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002d09a39 to fffff80002ccf740
STACK_TEXT:
fffff880`09964b58 fffff800`02d09a39 : 00000000`0000001e ffffffff`c0000005 fffff880`09ddc1d1 00000000`00000000 : nt!KeBugCheckEx
fffff880`09964b60 fffff800`02cced82 : fffff880`09965328 fffffa80`04053690 fffff880`099653d0 fffffa80`04053540 : nt!KiDispatchException+0x1b9
fffff880`099651f0 fffff800`02ccd8fa : 00000000`00000000 fffffa80`04053690 fffffa80`04593000 fffff800`02cdeb7c : nt!KiExceptionDispatch+0xc2
fffff880`099653d0 fffff880`09ddc1d1 : 00000000`00000000 00000000`00000000 fffff880`09965630 fffffa80`04053660 : nt!KiPageFault+0x23a
fffff880`09965560 00000000`00000000 : 00000000`00000000 fffff880`09965630 fffffa80`04053660 00000000`00000000 : aksdf+0x61d1
STACK_COMMAND: kb
FOLLOWUP_IP:
aksdf+61d1
fffff880`09ddc1d1 488b4818 mov rcx,qword ptr [rax+18h]
SYMBOL_STACK_INDEX: 4
SYMBOL_NAME: aksdf+61d1
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: aksdf
IMAGE_NAME: aksdf.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4b9145c2
FAILURE_BUCKET_ID: X64_0x1E_aksdf+61d1
BUCKET_ID: X64_0x1E_aksdf+61d1
Followup: MachineOwner