*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 0000000000007703, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff80002abf8c3, address which referenced memory
Debugging Details:
------------------
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002cc50e0
0000000000007703
CURRENT_IRQL: 2
FAULTING_IP:
nt!MiResolveTransitionFault+4a3
fffff800`02abf8c3 f6819000000004 test byte ptr [rcx+90h],4
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xA
PROCESS_NAME: svchost.exe
TRAP_FRAME: fffff880046e44d0 -- (.trap 0xfffff880046e44d0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000001 rbx=0000000000000000 rcx=0000000000218c60
rdx=fffff980248b03a0 rsi=0000000000000000 rdi=0000000000000000
rip=fffff80002a844e0 rsp=fffff880046e4668 rbp=fffffa8007680490
r8=0000000000001000 r9=0000000000000080 r10=fffffa8000484440
r11=0000000000218c60 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na pe cy
nt!memmove+0xb0:
fffff800`02a844e0 488b040a mov rax,qword ptr [rdx+rcx] ds:fffff980`24ac9000=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002a8cca9 to fffff80002a8d740
STACK_TEXT:
fffff880`046e3e58 fffff800`02a8cca9 : 00000000`0000000a 00000000`00007703 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
fffff880`046e3e60 fffff800`02a8b920 : 00000000`00000101 00000000`00000001 fffffa80`09079010 00000000`00000066 : nt!KiBugCheckDispatch+0x69
fffff880`046e3fa0 fffff800`02abf8c3 : 00000000`00000900 fffff880`046e4158 ffffffff`80000cb8 00000000`00000000 : nt!KiPageFault+0x260
fffff880`046e4130 fffff800`02ab3dc9 : 00000000`00000000 00000000`07a128c0 fffffa80`07f573b0 fffff800`02c19e00 : nt!MiResolveTransitionFault+0x4a3
fffff880`046e41c0 fffff800`02aa95be : 00000000`00000000 fffff980`24ac9000 fffff6fc`c0125648 fffff800`02c19e00 : nt!MiResolveProtoPteFault+0x419
fffff880`046e4260 fffff800`02aa7cf1 : fffff8a0`08161c00 00000000`00000000 00000000`00000001 1e33e0eb`d8e795dd : nt!MiDispatchFault+0x1de
fffff880`046e4370 fffff800`02a8b82e : 00000000`00000000 00000000`00001000 00000000`00000000 fffffa80`07923a80 : nt!MmAccessFault+0x8f1
fffff880`046e44d0 fffff800`02a844e0 : fffff800`02da8c51 00000000`00001000 00000000`00000000 fffffa80`07f56330 : nt!KiPageFault+0x16e
fffff880`046e4668 fffff800`02da8c51 : 00000000`00001000 00000000`00000000 fffffa80`07f56330 00000000`00001000 : nt!memmove+0xb0
fffff880`046e4670 fffff800`02da87d2 : 00000000`000c0000 00000000`00218c60 00000000`00001000 00000000`00001000 : nt!CcCopyBytesToUserBuffer+0x41
fffff880`046e46b0 fffff880`012cac48 : fffff880`00000000 00000000`00000005 fffffa80`00001000 fffffa80`00001001 : nt!CcCopyRead+0x1a2
fffff880`046e4770 fffff880`010a20c8 : fffffa80`07680490 fffffa80`07f562c8 fffffa80`063fde00 fffffa80`07680401 : Ntfs!NtfsCopyReadA+0x1a8
fffff880`046e4940 fffff880`010a5c2a : fffff880`046e4a10 00000000`00218c03 00000000`00218c00 fffffa80`07680400 : fltmgr!FltpPerformFastIoCall+0x88
fffff880`046e49a0 fffff880`010c35f0 : fffffa80`07680490 00000000`00000000 fffff880`046e4b00 00000000`00001000 : fltmgr!FltpPassThroughFastIo+0xda
fffff880`046e49e0 fffff800`02da90c9 : fffffa80`07680490 fffffa80`00000001 fffffa80`06a2dc90 fffffa80`07680490 : fltmgr!FltpFastIoRead+0x1d0
fffff880`046e4a80 fffff800`02a8c993 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!NtReadFile+0x417
fffff880`046e4b70 00000000`7705f71a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0434f5c8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7705f71a
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!MiResolveTransitionFault+4a3
fffff800`02abf8c3 f6819000000004 test byte ptr [rcx+90h],4
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: nt!MiResolveTransitionFault+4a3
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 4cc791bd
IMAGE_NAME: [COLOR=red]memory_corruption[/COLOR]
FAILURE_BUCKET_ID: X64_0xA_nt!MiResolveTransitionFault+4a3
BUCKET_ID: X64_0xA_nt!MiResolveTransitionFault+4a3
Followup: MachineOwner
---------