Hello vivs_lunchtime,
On which dump did you execute that !pte command? That requires more than a minidump to work and I have not seen an example of this problem in a large dump.
On the dumps from Alex, the stack in the first trap frame contains this:
dqs @rsp+70 l 1
ffff928ae6356820 fffff8001ada1f90 ndis!ndisOidPreAddWakeUpPattern
The bold pointer is always ndisOidPreAddWakeUpPattern in Alex's dumps or is the routine reported by PatchGuard.
In Damian's dump. the equivalent stack content is:
dqs @rsp+70 l 1
fffffc8307d8e7f0 fffff802701a1ff8 tcpip!RtlCookUrl
So the first patch target system to be consistent per system but differ between systems.
In the PatchGuard dump from Alex, the patch to ndisOidPreAddWakeUpPattern looks like this (with surrounding unpatched bytes for context):
ndis!ndisOidPreAddWakeUpPattern+0x5d:
fffff802`4d1a1fed 83a79800000000 and dword ptr [rdi+98h],0
fffff802`4d1a1ff4 4885c9 test rcx,rcx
fffff8024d1a1ff7 7419 je ndis!ndisOidPreAddWakeUpPattern+0x82 (fffff8024d1a2012) Branch
ndis!ndisOidPreAddWakeUpPattern+0x69:
fffff802`4d1a1ff9 4c8d44 ac13 lea r8,[rsp+rbp*4+13h]
fffff802`4d1a1ffa 8d 44 ac 13 0a 92 54 54-10 00 00 8e be 09 61 54 .D....TT......aT
fffff802`4d1a200a 10 00 28 8e be 09 6e 54-10 00 3b 8e be 09 7b 54 ..(...nT..;...{T
fffff802`4d1a201a 10 00 77 8e be 09 88 54-10 00 73 8e be 09 95 54 ..w....T..s....T
fffff802`4d1a202a 10 00 8b 8e be 09 a2 54-10 00 00 8e be 09 af 54 .......T.......T
fffff802`4d1a203a 10 00 30 8e be 09 bc 54-10 00 00 8e be 09 c9 54 ..0....T.......T
fffff802`4d1a204a 10 00 80 8e be 09 d6 54-10 00 24 8e be 09 e3 54 .......T..$....T
fffff802`4d1a205a 10 00 e8 8e be 09 f0 54-10 00 30 8e be 09 fd 54 .......T..0....T
fffff802`4d1a206a 10 00 38 8e be 09 0a 55-10 00 48 8e be 09 17 55 ..8....U..H....U
fffff802`4d1a207a 10 00 cc 8e be 09 24 55-10 00 cc 8e be 09 31 55 ......$U......1U
fffff802`4d1a208a 10 00 cc 8e be 09 3e 55-10 00 48 8e be 09 4b 55 ......>U..H...KU
fffff802`4d1a209a 10 00 c2 8e be 09 58 55-10 00 01 8e be 09 65 55 ......XU......eU
fffff802`4d1a20aa 10 00 e8 8e be 09 72 55-10 00 41 8e be 09 7f 55 ......rU..A....U
fffff802`4d1a20ba 10 00 e8 8e be 09 8c 55-10 00 28 8e be 09 99 55 .......U..(....U
fffff802`4d1a20ca 10 00 cc 8e be 09 a6 55-10 00 48 8e be 09 b3 55 .......U..H....U
fffff802`4d1a20da 10 00 04 8e be 09 c0 55-10 00 00 8e be 09 cd 55 .......U.......U
fffff802`4d1a20ea 10 00 33 8e be 09 da 55-10 00 00 8e be 09 e7 55 ..3....U.......U
fffff802`4d1a20fa 10 00 77 8e be 09 41 80-78 21 14 73 09 c7 42 28 ..w...A.x!.s..B(
fffff802`4d1a210a bb 00 00 c0 eb 65 83 .....e.
fffff802`4d1a210f 65 83783004 cmp dword ptr gs:[rax+30h],4
fffff8024d1a2114 7310 jae ndis!ndisOidPreGetPMProtocolOffload+0x56 (fffff8024d1a2126) Branch
ndis!ndisOidPreGetPMProtocolOffload+0x46:
fffff802`4d1a2116 c74228140001c0 mov dword ptr [rdx+28h],0C0010014h
fffff802`4d1a211d c7404404000000 mov dword ptr [rax+44h],4
fffff8024d1a2124 eb4f jmp ndis!ndisOidPreGetPMProtocolOffload+0xa5 (fffff8024d1a2175) Branch
I can't imagine what the purpose of those bytes are...
Searching the web shows other possible instances of this problem stretching back many months - it is disappointing that anti-malware defences are not detecting anything.
Gary