We have around 50+ workstations with application and device control having BSOD. We removed Application and device control and the problem went away. We have sinces reinstalled with application and device control and the problem is back. We have a directive that we must use this feature so, I could use some help. We are running version 11.0.6100.645. Here is the dumpfile view.
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KERNEL_MODE_EXCEPTION_NOT_HANDLED_M (1000008e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: c0000005, The exception code that was not handled
Arg2: 8053a8f3, The address that the exception occurred at
Arg3: ae64d4c4, Trap Frame
Arg4: 00000000
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s".
FAULTING_IP:
nt!memmove+33
8053a8f3 f3a5 rep movs dword ptr es:[edi],dword ptr [esi]
TRAP_FRAME: ae64d4c4 -- (.trap 0xffffffffae64d4c4)
ErrCode = 00000000
eax=007200b5 ebx=ae64d59c ecx=0000001c edx=00000003 esi=00720042 edi=ae64d59c
eip=8053a8f3 esp=ae64d538 ebp=ae64d540 iopl=0 nv up ei pl nz na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010206
nt!memmove+0x33:
8053a8f3 f3a5 rep movs dword ptr es:[edi],dword ptr [esi]
Resetting default scope
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: DRIVER_FAULT
BUGCHECK_STR: 0x8E
PROCESS_NAME: cscript.exe
LAST_CONTROL_TRANSFER: from 8052bb37 to 8053a8f3
STACK_TEXT:
ae64d540 8052bb37 ae64d59c 00720042 00000073 nt!memmove+0x33
ae64d560 b29da1a0 ae64d590 00000073 88557340 nt!RtlAppendUnicodeStringToString+0x45
WARNING: Stack unwind information not available. Following frames may be wrong.
ae64dc7c b29d926d c0000001 e1a41840 b2b17799 SysPlant+0x61a0
ae64dd3c 8054164c 012bf60c 001f03ff 00000000 SysPlant+0x526d
ae64dd3c 00000008 012bf60c 001f03ff 00000000 nt!KiFastCallEntry+0xfc
ae64ddac ffffffff 0000003b 0013da30 00000104 0x8
ae64ddb0 00000000 0013da30 00000104 00000000 0xffffffff
STACK_COMMAND: kb
FOLLOWUP_IP:
SysPlant+61a0
b29da1a0 ?? ???
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: SysPlant+61a0
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: SysPlant
IMAGE_NAME: SysPlant.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4c5b6605
FAILURE_BUCKET_ID: 0x8E_SysPlant+61a0
BUCKET_ID: 0x8E_SysPlant+61a0
Followup: MachineOwner
---------