
************* Preparing the environment for Debugger Extensions Gallery repositories **************
   ExtensionRepository : Implicit
   UseExperimentalFeatureForNugetShare : true
   AllowNugetExeUpdate : true
   NonInteractiveNuget : true
   AllowNugetMSCredentialProviderInstall : true
   AllowParallelInitializationOfLocalRepositories : true

   EnableRedirectToV8JsProvider : false

   -- Configuring repositories
      ----> Repository : LocalInstalled, Enabled: true
      ----> Repository : UserExtensions, Enabled: true

>>>>>>>>>>>>> Preparing the environment for Debugger Extensions Gallery repositories completed, duration 0.000 seconds

************* Waiting for Debugger Extensions Gallery to Initialize **************

>>>>>>>>>>>>> Waiting for Debugger Extensions Gallery to Initialize completed, duration 0.031 seconds
   ----> Repository : UserExtensions, Enabled: true, Packages count: 0
   ----> Repository : LocalInstalled, Enabled: true, Packages count: 41

Microsoft (R) Windows Debugger Version 10.0.27553.1004 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Windows\Minidump\050224-23609-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available


************* Path validation summary **************
Response                         Time (ms)     Location
Deferred                                       srv*
Symbol search path is: srv*
Executable search path is: 
Windows 10 Kernel Version 22621 MP (32 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Kernel base = 0xfffff800`44800000 PsLoadedModuleList = 0xfffff800`454134a0
Debug session time: Thu May  2 19:30:19.710 2024 (UTC + 2:00)
System Uptime: 0 days 0:56:24.286
Loading Kernel Symbols
...............................................................
................................................................
................................................................
......................................................
Loading User Symbols
PEB is paged out (Peb.Ldr = 000000cd`4b098018).  Type ".hh dbgerr001" for details
Loading unloaded module list
............
For analysis of this file, run !analyze -v
nt!KeBugCheckEx:
fffff800`44c18040 48894c2408      mov     qword ptr [rsp+8],rcx ss:fffff800`4394be10=00000000000000fc
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\amd64\Visualizers\atlmfc.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\amd64\Visualizers\ObjectiveC.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\amd64\Visualizers\concurrency.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\amd64\Visualizers\cpp_rest.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Kernel.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\amd64\Visualizers\stl.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Windows.Data.Json.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Windows.Devices.Geolocation.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Windows.Devices.Sensors.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Windows.Media.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\amd64\Visualizers\windows.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\amd64\Visualizers\winrt.natvis'
NatVis script unloaded from 'C:\Program Files\WindowsApps\Microsoft.WinDbg_1.2402.24001.0_x64__8wekyb3d8bbwe\amd64\Visualizers\Usb4Kd.natvis'

************* Preparing the environment for Debugger Extensions Gallery repositories **************
   ExtensionRepository : Implicit
   UseExperimentalFeatureForNugetShare : true
   AllowNugetExeUpdate : true
   NonInteractiveNuget : true
   AllowNugetMSCredentialProviderInstall : true
   AllowParallelInitializationOfLocalRepositories : true

   EnableRedirectToV8JsProvider : false

   -- Configuring repositories
      ----> Repository : LocalInstalled, Enabled: true
      ----> Repository : UserExtensions, Enabled: true

>>>>>>>>>>>>> Preparing the environment for Debugger Extensions Gallery repositories completed, duration 0.000 seconds

************* Waiting for Debugger Extensions Gallery to Initialize **************

>>>>>>>>>>>>> Waiting for Debugger Extensions Gallery to Initialize completed, duration 0.032 seconds
   ----> Repository : UserExtensions, Enabled: true, Packages count: 0
   ----> Repository : LocalInstalled, Enabled: true, Packages count: 41

Microsoft (R) Windows Debugger Version 10.0.27553.1004 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Windows\Minidump\050224-23609-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available


************* Path validation summary **************
Response                         Time (ms)     Location
Deferred                                       srv*
Symbol search path is: srv*
Executable search path is: 
Windows 10 Kernel Version 22621 MP (32 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Kernel base = 0xfffff800`44800000 PsLoadedModuleList = 0xfffff800`454134a0
Debug session time: Thu May  2 19:30:19.710 2024 (UTC + 2:00)
System Uptime: 0 days 0:56:24.286
Loading Kernel Symbols
...............................................................
................................................................
................................................................
......................................................
Loading User Symbols
PEB is paged out (Peb.Ldr = 000000cd`4b098018).  Type ".hh dbgerr001" for details
Loading unloaded module list
............
For analysis of this file, run !analyze -v
nt!KeBugCheckEx:
fffff800`44c18040 48894c2408      mov     qword ptr [rsp+8],rcx ss:fffff800`4394be10=00000000000000fc
0: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

ATTEMPTED_EXECUTE_OF_NOEXECUTE_MEMORY (fc)
An attempt was made to execute non-executable memory.  The guilty driver
is on the stack trace (and is typically the current instruction pointer).
When possible, the guilty driver's name is printed on
the BugCheck screen and saved in KiBugCheckDriver.
Arguments:
Arg1: ffffa988828c1480, Virtual address for the attempted execute.
Arg2: 8a000003500009e3, PTE contents.
Arg3: fffff8004394bfc0, (reserved)
Arg4: 0000000000000003, (reserved)

Debugging Details:
------------------


KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.mSec
    Value: 296

    Key  : Analysis.Elapsed.mSec
    Value: 1224

    Key  : Analysis.IO.Other.Mb
    Value: 0

    Key  : Analysis.IO.Read.Mb
    Value: 0

    Key  : Analysis.IO.Write.Mb
    Value: 0

    Key  : Analysis.Init.CPU.mSec
    Value: 108

    Key  : Analysis.Init.Elapsed.mSec
    Value: 61498

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 99

    Key  : Bugcheck.Code.LegacyAPI
    Value: 0xfc

    Key  : Bugcheck.Code.TargetModel
    Value: 0xfc

    Key  : Dump.Attributes.AsUlong
    Value: 1008

    Key  : Dump.Attributes.DiagDataWrittenToHeader
    Value: 1

    Key  : Dump.Attributes.ErrorCode
    Value: 0

    Key  : Dump.Attributes.KernelGeneratedTriageDump
    Value: 1

    Key  : Dump.Attributes.LastLine
    Value: Dump completed successfully.

    Key  : Dump.Attributes.ProgressPercentage
    Value: 0

    Key  : Failure.Bucket
    Value: 0xFC_RtUsbA64!unknown_function

    Key  : Failure.Hash
    Value: {5c88f752-974c-2062-a83a-80638304cada}


BUGCHECK_CODE:  fc

BUGCHECK_P1: ffffa988828c1480

BUGCHECK_P2: 8a000003500009e3

BUGCHECK_P3: fffff8004394bfc0

BUGCHECK_P4: 3

FILE_IN_CAB:  050224-23609-01.dmp

DUMP_FILE_ATTRIBUTES: 0x1008
  Kernel Generated Triage Dump

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXPNP: 1 (!blackboxpnp)


BLACKBOXWINLOGON: 1

CUSTOMER_CRASH_COUNT:  1

PROCESS_NAME:  Sandrock.exe

DPC_STACK_BASE:  FFFFF8004394CFB0

TRAP_FRAME:  fffff8004394bfc0 -- (.trap 0xfffff8004394bfc0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffffa988898c5ca0 rbx=0000000000000000 rcx=ffffa988898c5ca0
rdx=fffff80082e36970 rsi=0000000000000000 rdi=0000000000000000
rip=ffffa988828c1480 rsp=fffff8004394c158 rbp=0000000000000001
 r8=ffffa988828c1480  r9=ffffa988828c1480 r10=0000000000000748
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei ng nz na pe nc
ffffa988`828c1480 20e9            and     cl,ch
Resetting default scope

STACK_TEXT:  
fffff800`4394be08 fffff800`44c97d8e     : 00000000`000000fc ffffa988`828c1480 8a000003`500009e3 fffff800`4394bfc0 : nt!KeBugCheckEx
fffff800`4394be10 fffff800`44c921fc     : 00000000`00000011 00000000`00000003 00000000`00000000 fffff800`4394bee0 : nt!MiCheckSystemNxFault+0x1f637a
fffff800`4394be50 fffff800`44a30213     : ffffa988`000898c5 00000000`00000011 fffff800`4394bf59 00000000`00000000 : nt!MiRaisedIrqlFault+0x200e28
fffff800`4394bea0 fffff800`44c291fa     : ffffa988`0000002f fffff800`4394c070 fffff800`4394bfe6 00000000`00000006 : nt!MmAccessFault+0x363
fffff800`4394bfc0 ffffa988`828c1480     : fffff800`44a96865 ffffa988`00000000 00000000`00000001 fffff800`4394c239 : nt!KiPageFault+0x37a
fffff800`4394c158 fffff800`44a96865     : ffffa988`00000000 00000000`00000001 fffff800`4394c239 ffffa988`8197eeab : 0xffffa988`828c1480
fffff800`4394c160 fffff800`82e35bbb     : ffffa988`7f3a52f0 fffff800`4394c239 ffffa988`8197eeab ffffa988`828c1480 : nt!IoQueueWorkItem+0x15
fffff800`4394c190 ffffa988`7f3a52f0     : fffff800`4394c239 ffffa988`8197eeab ffffa988`828c1480 00000000`00000000 : RtUsbA64+0x45bbb
fffff800`4394c198 fffff800`4394c239     : ffffa988`8197eeab ffffa988`828c1480 00000000`00000000 fffff800`44b332b4 : 0xffffa988`7f3a52f0
fffff800`4394c1a0 ffffa988`8197eeab     : ffffa988`828c1480 00000000`00000000 fffff800`44b332b4 00000000`00000000 : 0xfffff800`4394c239
fffff800`4394c1a8 ffffa988`828c1480     : 00000000`00000000 fffff800`44b332b4 00000000`00000000 fffff800`4394c239 : 0xffffa988`8197eeab
fffff800`4394c1b0 00000000`00000000     : fffff800`44b332b4 00000000`00000000 fffff800`4394c239 ffffa988`8197ee63 : 0xffffa988`828c1480


SYMBOL_NAME:  RtUsbA64+45bbb

MODULE_NAME: RtUsbA64

IMAGE_NAME:  RtUsbA64.sys

STACK_COMMAND:  .cxr; .ecxr ; kb

BUCKET_ID_FUNC_OFFSET:  45bbb

FAILURE_BUCKET_ID:  0xFC_RtUsbA64!unknown_function

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

FAILURE_ID_HASH:  {5c88f752-974c-2062-a83a-80638304cada}

Followup:     MachineOwner
---------

0: kd> !blackboxbsd
Version: 0xc0
Product type: 1

Auto advanced boot: FALSE
Advanced boot menu timeout: 30
Last boot succeeded: TRUE
Last boot shutdown: FALSE
Sleep in progress: FALSE

Power button timestamp: 0x0
System running: TRUE
Connected standby in progress: FALSE
User shutdown in progress: FALSE
System shutdown in progress: FALSE
Sleep in progress: 0
Connected standby scenario instance id: 0
Connected standby entry reason: 0
Connected standby exit reason: 0
System sleep transitions to on: 0
Last reference time: 0x1da9cae93607c34
	2024-05-02T16:34:17.166Z
Last reference time checksum: 0x8452588a
Last update boot id: 37

Boot attempt count: 1
Last boot checkpoint: TRUE
Checksum: 0x47
Last boot id: 37
Last successful shutdown boot id: 36
Last reported abnormal shutdown boot id: 36

Error info boot id: 0
Error info repeat count: 0
Error info other error count: 0
Error info code: 0
Error info status: 0x0

Power button last press time: 0x0
Power button cumulative press count: 0
Power button last press boot id: 0
Power button last power watchdog stage: 0
Power button watchdog armed: FALSE
Power button shutdown in progress: FALSE
Power button last release time: 0x0
Power button cumulative release count: 0
Power button last release boot id: 0
Power button error count: 0
Power button current connected standby phase: 0
Power button transition latest checkpoint id: 0
Power button transition latest checkpoint type: 0
Power button transition latest checkpoint sequence number: 0

Power transition Shutdown Device Type: 0
Power transition Setup In Progress: FALSE
Power transition OOBE In Progress: FALSE
Power transition Sleep Checkpoint Source: 0
Power transition Sleep Checkpoint: 0
Power transition Connected Standby Entry Reason Category: 0
Power transition Connected Standby Exit Reason Category: 0
Power transition Connected Standby Entry Scenario Instance Id: 0x0

Feature Configuration State : Committed

0: kd> !blackboxntfs

NTFS Blackbox Data

0 Slow I/O Timeout Records Found
0 Oplock Break Timeout Records Found
0: kd> !blackboxpnp
    PnpActivityId      : {00000000-0000-0000-0000-000000000000}
    PnpActivityTime    : 133591426093400839
    PnpEventInformation: 3
    PnpEventInProgress : 0
    PnpProblemCode     : 24
    PnpVetoType        : 0
    DeviceId           : USB\VID_045E&PID_02EA&IG_00\00&00&00007ABC4882ED7E
    VetoString         : 

0: kd> !blackboxbsd
Version: 0xc0
Product type: 1

Auto advanced boot: FALSE
Advanced boot menu timeout: 30
Last boot succeeded: TRUE
Last boot shutdown: FALSE
Sleep in progress: FALSE

Power button timestamp: 0x0
System running: TRUE
Connected standby in progress: FALSE
User shutdown in progress: FALSE
System shutdown in progress: FALSE
Sleep in progress: 0
Connected standby scenario instance id: 0
Connected standby entry reason: 0
Connected standby exit reason: 0
System sleep transitions to on: 0
Last reference time: 0x1da9cae93607c34
	2024-05-02T16:34:17.166Z
Last reference time checksum: 0x8452588a
Last update boot id: 37

Boot attempt count: 1
Last boot checkpoint: TRUE
Checksum: 0x47
Last boot id: 37
Last successful shutdown boot id: 36
Last reported abnormal shutdown boot id: 36

Error info boot id: 0
Error info repeat count: 0
Error info other error count: 0
Error info code: 0
Error info status: 0x0

Power button last press time: 0x0
Power button cumulative press count: 0
Power button last press boot id: 0
Power button last power watchdog stage: 0
Power button watchdog armed: FALSE
Power button shutdown in progress: FALSE
Power button last release time: 0x0
Power button cumulative release count: 0
Power button last release boot id: 0
Power button error count: 0
Power button current connected standby phase: 0
Power button transition latest checkpoint id: 0
Power button transition latest checkpoint type: 0
Power button transition latest checkpoint sequence number: 0

Power transition Shutdown Device Type: 0
Power transition Setup In Progress: FALSE
Power transition OOBE In Progress: FALSE
Power transition Sleep Checkpoint Source: 0
Power transition Sleep Checkpoint: 0
Power transition Connected Standby Entry Reason Category: 0
Power transition Connected Standby Exit Reason Category: 0
Power transition Connected Standby Entry Scenario Instance Id: 0x0

Feature Configuration State : Committed

0: kd> .trap 0xfffff8004394bfc0
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=ffffa988898c5ca0 rbx=0000000000000000 rcx=ffffa988898c5ca0
rdx=fffff80082e36970 rsi=0000000000000000 rdi=0000000000000000
rip=ffffa988828c1480 rsp=fffff8004394c158 rbp=0000000000000001
 r8=ffffa988828c1480  r9=ffffa988828c1480 r10=0000000000000748
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei ng nz na pe nc
ffffa988`828c1480 20e9            and     cl,ch
0: kd> lmvm RtUsbA64
Browse full module list
start             end                 module name
fffff800`82df0000 fffff800`82e7c000   RtUsbA64 T (no symbols)           
    Loaded symbol image file: RtUsbA64.sys
    Image path: RtUsbA64.sys
    Image name: RtUsbA64.sys
    Browse all global symbols  functions  data
    Timestamp:        Fri Jul  8 07:16:20 2022 (62C7BDA4)
    CheckSum:         00082FAB
    ImageSize:        0008C000
    Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
    Information from resource tables: