*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except.
Typically the address is just plain bad or it is pointing at freed memory.
Arguments:
Arg1: ffffc3810025744c, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff8057c3c752b, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000002, (reserved)
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 9046
Key : Analysis.DebugAnalysisProvider.CPP
Value: Create: 8007007e on DESKTOP-J7A11VA
Key : Analysis.DebugData
Value: CreateObject
Key : Analysis.DebugModel
Value: CreateObject
Key : Analysis.Elapsed.mSec
Value: 28614
Key : Analysis.Memory.CommitPeak.Mb
Value: 75
Key : Analysis.System
Value: CreateObject
Key : WER.OS.Branch
Value: vb_release
Key : WER.OS.Timestamp
Value: 2019-12-06T14:06:00Z
Key : WER.OS.Version
Value: 10.0.19041.1
ADDITIONAL_XML: 1
OS_BUILD_LAYERS: 1
BUGCHECK_CODE: 50
BUGCHECK_P1: ffffc3810025744c
BUGCHECK_P2: 0
BUGCHECK_P3: fffff8057c3c752b
BUGCHECK_P4: 2
READ_ADDRESS: fffff8056eafb390: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
fffff8056ea0f340: Unable to get Flags value from nt!KdVersionBlock
fffff8056ea0f340: Unable to get Flags value from nt!KdVersionBlock
unable to get nt!MmSpecialPagesInUse
ffffc3810025744c
MM_INTERNAL_CODE: 2
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: ATISetup.exe
TRAP_FRAME: ffff89035c37fd90 -- (.trap 0xffff89035c37fd90)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=00007ff433f2743e rbx=0000000000000000 rcx=ffffc38100257438
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8057c3c752b rsp=ffff89035c37ff20 rbp=0000000000000000
r8=0000000000007001 r9=fffff8057c3afa1c r10=fffff8056e1cf8b0
r11=0000000000000020 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
ahcache!SdbGetFirstChild+0x10b:
fffff805`7c3c752b 8b4114 mov eax,dword ptr [rcx+14h] ds:ffffc381`0025744c=????????
Resetting default scope
STACK_TEXT:
ffff8903`5c37fae8 fffff805`6e27a665 : 00000000`00000050 ffffc381`0025744c 00000000`00000000 ffff8903`5c37fd90 : nt!KeBugCheckEx
ffff8903`5c37faf0 fffff805`6e0ea4a0 : 00000000`00000000 00000000`00000000 ffff8903`5c37fe10 00000000`00000000 : nt!MiSystemFault+0x172315
ffff8903`5c37fbf0 fffff805`6e20335e : ffffbe5b`2a3c4d4d 00000000`0024121c 00000000`00015e08 ffff8903`5c380060 : nt!MmAccessFault+0x400
ffff8903`5c37fd90 fffff805`7c3c752b : 00000000`00000000 fffff805`7c3c6a30 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x35e
ffff8903`5c37ff20 fffff805`7c3c792d : ffffc381`00257438 00000000`00000000 ffff8903`5c3800c8 00000000`00000000 : ahcache!SdbGetFirstChild+0x10b
ffff8903`5c37ff80 fffff805`7c3e4896 : ffffc381`00257438 ffffc381`e4ef39e0 ffff8903`5c3800c8 ffffc381`e4ef39e0 : ahcache!SdbFindFirstTag+0x1d
ffff8903`5c37fff0 fffff805`7c3dc8ee : ffffc381`e4ef39e0 00000000`00000000 00000000`00000000 00000000`0000700b : ahcache!SdbpGetNamedLayerFromExe+0x96
ffff8903`5c380040 fffff805`7c3e451e : ffffc381`f3659ba0 ffff8903`00000000 ffffc381`e4ef39e0 ffffc381`f3657802 : ahcache!SdbpAddMatch+0xfdce
ffff8903`5c3800c0 fffff805`7c3c0145 : ffff8903`0003f38c 00000000`00000000 00000000`00000000 00000000`00000000 : ahcache!SdbParseLayerString+0x13a
ffff8903`5c380150 fffff805`7c3bf853 : ffffc381`e5728490 00000000`00000000 ffffc381`e5728490 ffffc381`de36a730 : ahcache!SdbGetMatchingExeEx+0x389
ffff8903`5c380350 fffff805`7c3cbd1b : ffffc381`e5728490 ffff8903`5c380579 00000000`00000000 ffffc381`e5728490 : ahcache!AhcpSdbQueryLookupExe+0x9f
ffff8903`5c3803c0 fffff805`7c3c0d24 : 00000000`00000000 ffffc381`f14a90c0 00000000`00000001 00000000`00000000 : ahcache!AhcSdbQueryLookup+0x15f
ffff8903`5c3804c0 fffff805`7c3c23da : ffff8903`5c380628 00000000`00000000 ffffc381`d815d030 00000000`00000000 : ahcache!AhcpCacheBuildSdbInfo+0x1fc
ffff8903`5c3805c0 fffff805`7c3c16a6 : ffff8903`5c380700 ffffc381`d49546a0 ffffc381`d815d030 ffff8903`5c380770 : ahcache!AhcCacheLookup+0x94a
ffff8903`5c380710 fffff805`7c3c43a7 : 0000007b`f1cfc9d0 00000000`0000000b ffffffff`80004c7c fffff805`7c3a6878 : ahcache!AhcApiLookupAndWriteToProcess+0xda
ffff8903`5c3807e0 fffff805`7c3c40d1 : ffffb306`5ecfa250 00000000`00001000 0000007b`f1cfc860 00000000`0022002f : ahcache!AhcDispatch+0x2a7
ffff8903`5c3809d0 fffff805`6e0cd6c5 : ffffb306`5ecfa250 00000000`00000000 00000000`00000000 ffff8903`5c380ac0 : ahcache!AhcDriverDispatchDeviceControl+0x41
ffff8903`5c380a10 fffff805`6e461f10 : 00000000`00000001 ffffb306`5ba10340 ffffb306`5ba10340 ffffb306`5f5b2080 : nt!IofCallDriver+0x55
ffff8903`5c380a50 fffff805`6e206bb8 : ffffb306`5f5b2080 00000000`00001000 00000000`00000000 00000000`00000000 : nt!NtApphelpCacheControl+0xf0
ffff8903`5c380b00 00007ff8`c0cac724 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x28
0000007b`f1cfc7c8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ff8`c0cac724
SYMBOL_NAME: ahcache!SdbGetFirstChild+10b
MODULE_NAME: ahcache
IMAGE_NAME: ahcache.sys
IMAGE_VERSION: 10.0.19041.1030
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: 10b
FAILURE_BUCKET_ID: AV_R_INVALID_ahcache!SdbGetFirstChild
OS_VERSION: 10.0.19041.1
BUILDLAB_STR: vb_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
FAILURE_ID_HASH: {d6ca2f22-9c1f-8a6b-b0cf-d6d5c3a20f5b}
Followup: MachineOwner
---------
8: kd> lmvm ahcache
Browse full module list
start end module name
fffff805`7c3a0000 fffff805`7c3ee000 ahcache # (pdb symbols) c:\programdata\dbg\sym\ahcache.pdb\3125557991B4ECB0F08DB7AEF1D3E4F11\ahcache.pdb
Loaded symbol image file: ahcache.sys
Mapped memory image file: c:\programdata\dbg\sym\ahcache.sys\5C9A7E7B4e000\ahcache.sys
Image path: \SystemRoot\system32\DRIVERS\ahcache.sys
Image name: ahcache.sys
Browse all global symbols functions data
Image was built with /Brepro flag.
Timestamp: 5C9A7E7B (This is a reproducible build file hash, not a timestamp)
CheckSum: 00052E71
ImageSize: 0004E000
File version: 10.0.19041.1030
Product version: 10.0.19041.1030
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
Information from resource tables:
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: ahcache.sys
OriginalFilename: ahcache.sys
ProductVersion: 10.0.19041.1030
FileVersion: 10.0.19041.1030 (WinBuild.160101.0800)
FileDescription: Application Compatibility Cache
LegalCopyright: © Microsoft Corporation. All rights reserved.