*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: 000000000000000d, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, value 0 = read operation, 1 = write operation
Arg4: fffff8800c2bcd70, address which referenced memory
Debugging Details:
------------------
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80003b11100
000000000000000d
CURRENT_IRQL: 2
[COLOR="Red"]FAULTING_IP:
mfefirek+1ad70[/COLOR]
fffff880`0c2bcd70 8a400d mov al,byte ptr [rax+0Dh]
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xD1
PROCESS_NAME: explorer.exe
TRAP_FRAME: fffff80000b9f430 -- (.trap 0xfffff80000b9f430)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=fffffa800e87c010
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8800c2bcd70 rsp=fffff80000b9f5c8 rbp=fffffa800b3eb840
r8=fffff80000b9f5f0 r9=0000000000000004 r10=0000000000000001
r11=fffff8800c2fc6b0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
[COLOR="red"]mfefirek+0x1ad70:[/COLOR]
fffff880`0c2bcd70 8a400d mov al,byte ptr [rax+0Dh] ds:4e80:00000000`0000000d=??
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff800038d81e9 to fffff800038d8c40
STACK_TEXT:
fffff800`00b9f2e8 fffff800`038d81e9 : 00000000`0000000a 00000000`0000000d 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
fffff800`00b9f2f0 fffff800`038d6e60 : 00000000`00000012 fffffa80`0e6f5908 00000000`0002000e 00000000`00000001 : nt!KiBugCheckDispatch+0x69
fffff800`00b9f430 fffff880`0c2bcd70 : fffff880`0c2cbb2c fffffa80`0f660010 00000000`00000000 fffffa80`0b39f240 : nt!KiPageFault+0x260
fffff800`00b9f5c8 fffff880`0c2cbb2c : fffffa80`0f660010 00000000`00000000 fffffa80`0b39f240 fffff800`038eedef : mfefirek+0x1ad70
fffff800`00b9f5d0 fffffa80`0f660010 : 00000000`00000000 fffffa80`0b39f240 fffff800`038eedef fffff880`064e69d0 : mfefirek+0x29b2c
fffff800`00b9f5d8 00000000`00000000 : fffffa80`0b39f240 fffff800`038eedef fffff880`064e69d0 fffffa80`0b3eb910 : 0xfffffa80`0f660010
STACK_COMMAND: kb
[COLOR="red"]FOLLOWUP_IP:
mfefirek+1ad70[/COLOR]
fffff880`0c2bcd70 8a400d mov al,byte ptr [rax+0Dh]
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: mfefirek+1ad70
FOLLOWUP_NAME: MachineOwner
[COLOR="Red"]MODULE_NAME: mfefirek
IMAGE_NAME: mfefirek.sys[/COLOR]
DEBUG_FLR_IMAGE_TIMESTAMP: 4fc63ee2
FAILURE_BUCKET_ID: X64_0xD1_mfefirek+1ad70
BUCKET_ID: X64_0xD1_mfefirek+1ad70
Followup: MachineOwner