*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck FC, {fffff8800cfedc08, 800000022bb5f121, fffff880031c3a50, 2}
[COLOR="red"]Probably caused by : WudfPf.sys[/COLOR] ( WudfPf!WdfLpc::WdfLpc+3f1 )
Followup: MachineOwner
---------
0: kd> !analyze -v
ATTEMPTED_EXECUTE_OF_NOEXECUTE_MEMORY (fc)
An attempt was made to execute non-executable memory. The guilty driver
is on the stack trace (and is typically the current instruction pointer).
When possible, the guilty driver's name (Unicode string) is printed on
the bugcheck screen and saved in KiBugCheckDriver.
Arguments:
Arg1: fffff8800cfedc08, Virtual address for the attempted execute.
Arg2: 800000022bb5f121, PTE contents.
Arg3: fffff880031c3a50, (reserved)
Arg4: 0000000000000002, (reserved)
Debugging Details:
------------------
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xFC
PROCESS_NAME: System
CURRENT_IRQL: 0
TRAP_FRAME: fffff880031c3a50 -- (.trap 0xfffff880031c3a50)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffffa800f23bba0 rbx=0000000000000000 rcx=fffff880031c3d90
rdx=fffff880019b8718 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8800cfedc08 rsp=fffff880031c3be8 rbp=fffff880031c3d90
r8=fffff880019c25c0 r9=0000000000000000 r10=fffff80002e427c0
r11=fffff880019c5730 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na po nc
WUDFRd!RdDriver::`vftable':
fffff880`0cfedc08 a4 movs byte ptr [rdi],byte ptr [rsi] ds:1170:00000000`00000000=?? ds:1170:00000000`00000000=??
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002c76bb4 to fffff80002ccefc0
STACK_TEXT:
fffff880`031c38e8 fffff800`02c76bb4 : 00000000`000000fc fffff880`0cfedc08 80000002`2bb5f121 fffff880`031c3a50 : nt!KeBugCheckEx
fffff880`031c38f0 fffff800`02ccd0ee : 00000000`00000008 fffff880`0cfedc08 00000000`00000000 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x44dbc
fffff880`031c3a50 fffff880`0cfedc08 : fffff880`019bc19d 00000000`00000000 fffff880`031c3d90 fffffa80`0df31170 : nt!KiPageFault+0x16e
fffff880`031c3be8 fffff880`019bc19d : 00000000`00000000 fffff880`031c3d90 fffffa80`0df31170 fffffa80`0742c8f0 : WUDFRd!RdDriver::`vftable'
fffff880`031c3bf0 fffff880`019b8a6c : 00000000`00000000 00000000`071c6cd0 fffff880`031c3d49 00000000`00000002 : WudfPf!WdfLpc::WdfLpc+0x3f1
fffff880`031c3ca0 00000000`071c6cd0 : fffff880`031c3d49 00000000`00000002 00000000`00000000 fffff880`0cfca82b : WudfPf!WdfLpcInterface::WdfGetLpc+0xc
fffff880`031c3cb0 fffff880`031c3d49 : 00000000`00000002 00000000`00000000 fffff880`0cfca82b fffffa80`0f23bc78 : 0x71c6cd0
fffff880`031c3cb8 00000000`00000002 : 00000000`00000000 fffff880`0cfca82b fffffa80`0f23bc78 00000000`00000000 : 0xfffff880`031c3d49
fffff880`031c3cc0 00000000`00000000 : fffff880`0cfca82b fffffa80`0f23bc78 00000000`00000000 00000000`00000000 : 0x2
fffff880`031c3308 fffff880`04585c7bUnable to load image \SystemRoot\System32\Drivers\aswSP.SYS, Win32 error 0n2
[COLOR="Red"]*** WARNING: Unable to verify timestamp for aswSP.SYS
*** ERROR: Module load completed but symbols could not be loaded for aswSP.SYS
aswSP+0x10c7b[/COLOR]
STACK_COMMAND: kb
FOLLOWUP_IP:
WudfPf!WdfLpc::WdfLpc+3f1
fffff880`019bc19d 53 push rbx
SYMBOL_STACK_INDEX: 4
SYMBOL_NAME: WudfPf!WdfLpc::WdfLpc+3f1
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: WudfPf
IMAGE_NAME: WudfPf.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4ce7a624
FAILURE_BUCKET_ID: X64_0xFC_WudfPf!WdfLpc::WdfLpc+3f1
BUCKET_ID: X64_0xFC_WudfPf!WdfLpc::WdfLpc+3f1
Followup: MachineOwner
---------