  • Defrag Tools: #29 - WinDbg - ETW Logging

    Debugging a BSOD due to a bug in Windows 8 64 bit (process MSSE a.k.a. Windows defender during quick scan, driver ndis.sys, error ATTEMPTED_EXECUTE_OF_NOEXECUTE_MEMORY, can reproduce 100% on my system).

    Have a complete memory dump created after xperf –on DiagEasy.

    !wmitrace.logsave command produces a corrupt ETL, both wpa.exe and xperfview.exe say "Trace C:\Temp\Crashes\DISK.etl could not be successfully opened [0x80070570]. Aborting operation".

    Any ideas how to fix?