

*** WARNING: Unable to verify timestamp for npf.sysīUILD_VERSION_STRING: 1_release.160213-0213ĮXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. I analyzed the minidump file and the output is below: 0: kd> !analyze -v I fount out that if when the packet sending is going on, I disable the corresponding adapter in Network Connections (aka ncpa.cpl). This driver receives the packet data from the user-mode applications and send them out using NdisFSendNetBufferLists (See Line 631 in ).

It's an update of WinPcap from NDIS 5 to NDIS 6. I have a NDIS 6.x LWF driver that can capture and send packets on Windows.
