*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck D1, {ffffffffffffb1e0, 2, 8, ffffffffffffb1e0}
Probably caused by : ntkrnlmp.exe ( nt!KiPageFault+260 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: ffffffffffffb1e0, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000008, value 0 = read operation, 1 = write operation
Arg4: ffffffffffffb1e0, address which referenced memory
Debugging Details:
------------------
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80003abd100
GetUlongFromAddress: unable to read from fffff80003abd1c0
ffffffffffffb1e0
CURRENT_IRQL: 2
FAULTING_IP:
+0
ffffffff`ffffb1e0 ?? ???
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
BUGCHECK_STR: 0xD1
PROCESS_NAME: System
TAG_NOT_DEFINED_c000000f: FFFFF80000BA2FB0
TRAP_FRAME: fffff80000b9c290 -- (.trap 0xfffff80000b9c290)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000003 rbx=0000000000000000 rcx=fffffa800cd88100
rdx=0000000000000102 rsi=0000000000000000 rdi=0000000000000000
rip=ffffffffffffb1e0 rsp=fffff80000b9c428 rbp=fffffa800cd88128
r8=fffffa8010687901 r9=0000000000000005 r10=fffff80003810000
r11=fffffa8010687958 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe nc
ffffffff`ffffb1e0 ?? ???
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80003885129 to fffff80003885b80
FAILED_INSTRUCTION_ADDRESS:
+0
ffffffff`ffffb1e0 ?? ???
STACK_TEXT:
fffff800`00b9c148 fffff800`03885129 : 00000000`0000000a ffffffff`ffffb1e0 00000000`00000002 00000000`00000008 : nt!KeBugCheckEx
fffff800`00b9c150 fffff800`03883da0 : 00000000`00000000 fffff880`05d51642 00000000`00000000 fffffa80`0cd88128 : nt!KiBugCheckDispatch+0x69
fffff800`00b9c290 ffffffff`ffffb1e0 : fffff800`0389085c fffff800`00b9c4c0 fffffa80`00000000 00000003`40050088 : nt!KiPageFault+0x260
fffff800`00b9c428 fffff800`0389085c : fffff800`00b9c4c0 fffffa80`00000000 00000003`40050088 00000000`00000005 : 0xffffffff`ffffb1e0
fffff800`00b9c430 fffff800`0389069d : fffffa80`0cd88120 fffffa80`0cd88168 fffffa80`0cd88168 00000000`00000102 : nt!KiProcessTimerDpcTable+0x6c
fffff800`00b9c4a0 fffff800`038905de : 00000003`b83475bf fffff800`00b9cb18 00000000`00019005 fffff800`03a03328 : nt!KiProcessExpiredTimerList+0x6d
fffff800`00b9caf0 fffff800`038903c7 : 00000001`3c932fc2 00000001`00019005 00000001`3c932f54 00000000`00000005 : nt!KiTimerExpiration+0x1be
fffff800`00b9cb90 fffff800`0387d88a : fffff800`03a00e80 fffff800`03a0ecc0 00000000`00000001 fffff880`00000000 : nt!KiRetireDpcList+0x277
fffff800`00b9cc40 00000000`00000000 : fffff800`00b9d000 fffff800`00b97000 fffff800`00b9cc00 00000000`00000000 : nt!KiIdleLoop+0x5a
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!KiPageFault+260
fffff800`03883da0 440f20c0 mov rax,cr8
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: nt!KiPageFault+260
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 51db806a
FAILURE_BUCKET_ID: X64_0xD1_CODE_AV_BAD_IP_nt!KiPageFault+260
BUCKET_ID: X64_0xD1_CODE_AV_BAD_IP_nt!KiPageFault+260
Followup: MachineOwner
---------