Unable to load image \SystemRoot\system32\DRIVERS\athwbx.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for athwbx.sys
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_THREAD_EXCEPTION_NOT_HANDLED (7e)
This is a very common BugCheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff8019640f36a, The address that the exception occurred at
Arg3: ffffd0016f7b2608, Exception Record Address
Arg4: ffffd0016f7b1e10, Context Record Address
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : AV.Dereference
Value: NullPtr
Key : AV.Type
Value: Read
Key : Analysis.CPU.mSec
Value: 2281
Key : Analysis.Elapsed.mSec
Value: 59537
Key : Analysis.IO.Other.Mb
Value: 0
Key : Analysis.IO.Read.Mb
Value: 1
Key : Analysis.IO.Write.Mb
Value: 26
Key : Analysis.Init.CPU.mSec
Value: 1312
Key : Analysis.Init.Elapsed.mSec
Value: 38758
Key : Analysis.Memory.CommitPeak.Mb
Value: 84
Key : Analysis.Version.DbgEng
Value: 10.0.29457.1000
Key : Analysis.Version.Description
Value: 10.2506.23.01 amd64fre
Key : Analysis.Version.Ext
Value: 1.2506.23.1
Key : Bugcheck.Code.LegacyAPI
Value: 0x1000007e
Key : Bugcheck.Code.TargetModel
Value: 0x1000007e
Key : Failure.Bucket
Value: AV_athwbx!unknown_function
Key : Failure.Exception.Code
Value: 0xc0000005
Key : Failure.Exception.IP.Address
Value: 0xfffff8019640f36a
Key : Failure.Exception.IP.Module
Value: athwbx
Key : Failure.Exception.IP.Offset
Value: 0x20036a
Key : Failure.Exception.Record
Value: 0xffffd0016f7b2608
Key : Failure.Hash
Value: {251625f9-1ad1-68bd-0f68-604c689b2e53}
Key : Hypervisor.Enlightenments.Value
Value: 0
Key : Hypervisor.Enlightenments.ValueHex
Value: 0x0
Key : Hypervisor.Flags.Value
Value: 0
Key : Hypervisor.Flags.ValueHex
Value: 0x0
Key : WER.OS.Branch
Value: winblue_r4
Key : WER.OS.Version
Value: 8.1.9600.17415
Key : WER.System.BIOSRevision
Value: 3.70.0.0
BUGCHECK_CODE: 7e
BUGCHECK_P1: ffffffffc0000005
BUGCHECK_P2: fffff8019640f36a
BUGCHECK_P3: ffffd0016f7b2608
BUGCHECK_P4: ffffd0016f7b1e10
FILE_IN_CAB: 113025-24875-01.dmp
FAULTING_THREAD: ffffe001f989f040
EXCEPTION_RECORD: ffffd0016f7b2608 -- (.exr 0xffffd0016f7b2608)
ExceptionAddress: fffff8019640f36a (athwbx+0x000000000020036a)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: 0000000000000000
Attempt to read from address 0000000000000000
CONTEXT: ffffd0016f7b1e10 -- (.cxr 0xffffd0016f7b1e10)
rax=0000000000000000 rbx=ffffe001f7ff03b0 rcx=0000000000000000
rdx=0000000000000000 rsi=fffff80193b2b060 rdi=ffffe001f812c050
rip=fffff8019640f36a rsp=ffffd0016f7b2840 rbp=0000000000000000
r8=fffff801965a04e0 r9=fffff80188e88000 r10=ffffd00171440be0
r11=ffffe001fad392a0 r12=0000000000000000 r13=fffff8018913a200
r14=0000000000000000 r15=ffffe001f989f180
iopl=0 nv up ei ng nz na pe nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010282
athwbx+0x20036a:
fffff801`9640f36a 488b08 mov rcx,qword ptr [rax] ds:002b:00000000`00000000=????????????????
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System
READ_ADDRESS: GetUlongPtrFromAddress: unable to read from fffff801891eb298
GetUlongPtrFromAddress: unable to read from fffff801891eb520
0000000000000000
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.
EXCEPTION_CODE_STR: c0000005
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: 0000000000000000
EXCEPTION_STR: 0xc0000005
STACK_TEXT:
ffffd001`6f7b2840 ffffe001`fad392d0 : fffff801`963913ca ffffe001`00000000 fffff801`9639add3 ffffe001`fa487638 : athwbx+0x20036a
ffffd001`6f7b2848 fffff801`963913ca : ffffe001`00000000 fffff801`9639add3 ffffe001`fa487638 fffff801`9641152b : 0xffffe001`fad392d0
ffffd001`6f7b2850 ffffe001`00000000 : fffff801`9639add3 ffffe001`fa487638 fffff801`9641152b 00000000`00000000 : athwbx+0x1823ca
ffffd001`6f7b2858 fffff801`9639add3 : ffffe001`fa487638 fffff801`9641152b 00000000`00000000 ffffe001`fad392d0 : 0xffffe001`00000000
ffffd001`6f7b2860 ffffe001`fa487638 : fffff801`9641152b 00000000`00000000 ffffe001`fad392d0 00000000`00000000 : athwbx+0x18bdd3
ffffd001`6f7b2868 fffff801`9641152b : 00000000`00000000 ffffe001`fad392d0 00000000`00000000 fffff801`96300893 : 0xffffe001`fa487638
ffffd001`6f7b2870 00000000`00000000 : ffffe001`fad392d0 00000000`00000000 fffff801`96300893 ffffe001`00000001 : athwbx+0x20252b
SYMBOL_NAME: athwbx+20036a
MODULE_NAME: athwbx
IMAGE_NAME: athwbx.sys
STACK_COMMAND: .cxr 0xffffd0016f7b1e10 ; kb
BUCKET_ID_FUNC_OFFSET: 20036a
FAILURE_BUCKET_ID: AV_athwbx!unknown_function
OS_VERSION: 8.1.9600.17415
BUILDLAB_STR: winblue_r4
OSPLATFORM_TYPE: x64
OSNAME: Windows 8.1
FAILURE_ID_HASH: {251625f9-1ad1-68bd-0f68-604c689b2e53}
Followup: MachineOwner
---------