*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck A, {7feff302, 2, 1, fffff8000310b0c5}
[COLOR="Red"]Probably caused by : ntkrnlmp.exe[/COLOR] ( nt!KeStackAttachProcess+115 )
Followup: MachineOwner
-----------------------------------------------
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 000000007feff302, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000001, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff8000310b0c5, address which referenced memory
Debugging Details:
------------------
WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff8000330a100
000000007feff302
CURRENT_IRQL: 2
FAULTING_IP:
nt!KeStackAttachProcess+115
fffff800`0310b0c5 f00fc186dc000000 lock xadd dword ptr [rsi+0DCh],eax
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
[COLOR="Red"]BUGCHECK_STR: 0xA[/COLOR]
PROCESS_NAME: System
TRAP_FRAME: fffff880035c4770 -- (.trap 0xfffff880035c4770)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000008 rbx=0000000000000000 rcx=fffffa8003cd50a0
rdx=fffff880035c4a58 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8000310b0c5 rsp=fffff880035c4900 rbp=fffff880035c4a58
r8=fffffa8003cd5090 r9=0000000000000130 r10=fffff880033660c0
r11=fffffa8003cd5040 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
nt!KeStackAttachProcess+0x115:
fffff800`0310b0c5 f00fc186dc000000 lock xadd dword ptr [rsi+0DCh],eax ds:0e80:00000000`000000dc=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff800030da569 to fffff800030dafc0
STACK_TEXT:
fffff880`035c4628 fffff800`030da569 : 00000000`0000000a 00000000`7feff302 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
fffff880`035c4630 fffff800`030d91e0 : fffff880`035c47b0 fffff8a0`0b600e80 00000000`00000039 fffffa80`03cd5040 : nt!KiBugCheckDispatch+0x69
fffff880`035c4770 fffff800`0310b0c5 : 00000000`00000000 fffffa80`03cd5040 fffffa80`03cd5040 fffff800`033a98e3 : nt!KiPageFault+0x260
fffff880`035c4900 fffffa80`073319c8 : fffff880`035c4a80 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KeStackAttachProcess+0x115
fffff880`035c4980 fffff880`035c4a80 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0xfffffa80`073319c8
fffff880`035c4988 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0xfffff880`035c4a80
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!KeStackAttachProcess+115
fffff800`0310b0c5 f00fc186dc000000 lock xadd dword ptr [rsi+0DCh],eax
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: nt!KeStackAttachProcess+115
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
[COLOR="red"]IMAGE_NAME: ntkrnlmp.exe[/COLOR]
DEBUG_FLR_IMAGE_TIMESTAMP: 503f82be
FAILURE_BUCKET_ID: X64_0xA_nt!KeStackAttachProcess+115
BUCKET_ID: X64_0xA_nt!KeStackAttachProcess+115
Followup: MachineOwner