BSOD Page Fault in Non Paged Area using SysInternals Sysmon V11

chaps-0125 1 Reputation point
2020-12-07T10:55:03.39+00:00

HI All

We recently been getting BSOD's on our Windows Server 2016 servers. We had Sysmon V11 installed and running since September but the last few days we been getting BSOD's saying Page Fault in Non Paged Area and the mini dump shows Sysmondrv.sys as the fauting bucket.

This only seems to affect Server 2016 and our Server 2012 R2 servers dont seem to have this. Another issue we are seeing is that this seems to cause pagefile issues where after the restart, windows will create a new pagefile showing a corruption in the existing one. Its not till we remove the pagefile and restart and it is OK until the subsequent reboot.

As these are Prod servers, we are anxious to get this sorted ASAP.

Hopefully Someone can assist.

A little bit of info

PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except.
Typically the address is just plain bad or it is pointing at freed memory.
Arguments:
Arg1: ffffc2082219a0e8, memory referenced.
Arg2: 0000000000000000, value 0 = read operation, 1 = write operation.
Arg3: fffff800a3d7b380, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 0000000000000000, (reserved)

FAULT_INSTR_CODE: c085d88b

SYMBOL_STACK_INDEX: 9

SYMBOL_NAME: SysmonDrv+1e9f

MODULE_NAME: SysmonDrv

IMAGE_NAME: SysmonDrv.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 5ea6fa67

STACK_COMMAND: .thread ; .cxr ; kb

BUCKET_ID_FUNC_OFFSET: 1e9f

FAILURE_BUCKET_ID: AV_R_INVALID_SysmonDrv!unknown_function

BUCKET_ID: AV_R_INVALID_SysmonDrv!unknown_function

PRIMARY_PROBLEM_CLASS: AV_R_INVALID_SysmonDrv!unknown_function

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,093 questions
{count} votes