*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 0000151420204d43, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000001, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff800fd2b1bc4, address which referenced memory
Debugging Details:
------------------
DUMP_FILE_ATTRIBUTES: 0x8
Kernel Generated Triage Dump
WRITE_ADDRESS: unable to get nt!MmSpecialPoolStart
unable to get nt!MmSpecialPoolEnd
unable to get nt!MmPagedPoolEnd
unable to get nt!MmNonPagedPoolStart
unable to get nt!MmSizeOfNonPagedPoolInBytes
0000151420204d43
CURRENT_IRQL: 2
FAULTING_IP:
nt!KxWaitForLockOwnerShip+14
fffff800`fd2b1bc4 48890a mov qword ptr [rdx],rcx
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: AV
PROCESS_NAME: firefox.exe
ANALYSIS_VERSION: 6.3.9600.17298 (debuggers(dbg).141024-1500) amd64fre
TRAP_FRAME: ffffd001af486180 -- (.trap 0xffffd001af486180)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffffa80065d0500 rbx=0000000000000000 rcx=ffffd001af486370
rdx=0000151420204d43 rsi=0000000000000000 rdi=0000000000000000
rip=fffff800fd2b1bc4 rsp=ffffd001af486310 rbp=ffffd001af4863b9
r8=0000000000000001 r9=0000000000000000 r10=0000000000000001
r11=d42000000000371b r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
nt!KxWaitForLockOwnerShip+0x14:
fffff800`fd2b1bc4 48890a mov qword ptr [rdx],rcx ds:00001514`20204d43=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff800fd3ccba9 to fffff800fd3c2220
STACK_TEXT:
ffffd001`af486038 fffff800`fd3ccba9 : 00000000`0000000a 00001514`20204d43 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
ffffd001`af486040 fffff800`fd3cb3c8 : fffffff6`00000000 00000001`ffffffff 00000001`00000005 00000000`000000fe : nt!KiBugCheckDispatch+0x69
ffffd001`af486180 fffff800`fd2b1bc4 : fffffa80`065d07f8 00000000`0003be13 00000000`00000013 fffff800`fd5bba80 : nt!KiPageFault+0x248
ffffd001`af486310 fffff800`fd2c70d7 : fffffa80`007be6a0 ffffd001`af4863b9 ffffe000`91bcd080 e0009230`f1a2d2cd : nt!KxWaitForLockOwnerShip+0x14
ffffd001`af486340 fffff800`fd28667d : 00000000`000294ce fffff6e8`00d5bfa0 00000000`0000000f fffff800`00000001 : nt!MiInsertPageInFreeOrZeroedList+0x5f7
ffffd001`af486420 fffff800`fd2d6b51 : 00000043`f3d640f9 ffffe000`92342840 00000000`00000003 00000000`00000000 : nt!MiPfnShareCountIsZero+0x2ad
ffffd001`af486530 fffff800`fd369ae0 : 00000000`00000006 00000000`00000002 fffff6e8`00d5bf70 00000000`00000000 : nt!MiDeleteKernelStackPages+0x141
ffffd001`af486590 fffff800`fd2f1f33 : 00000000`00000000 00000000`00000002 00000000`00000000 00000000`00000000 : nt!MiDeleteKernelStack+0x64
ffffd001`af4865e0 fffff800`fd6b1657 : 00000000`00000035 ffffe000`00000000 00000000`00000000 00000000`00000006 : nt!MmDeleteKernelStack+0x263
ffffd001`af486670 fffff961`d5a6a2ae : 00000000`0000002f ffffd001`af486760 ffffd001`00000058 ffffd001`af486828 : nt!KeUserModeCallback+0x247
ffffd001`af486710 fffff961`d5a64c54 : fffff901`00000018 00000000`010cf358 fffff901`43e6cc20 00000000`00000000 : win32kfull!fnHkINLPMSG+0x1be
ffffd001`af486820 fffff961`d5a677c0 : fffff901`40782870 ffffd001`af486a48 00000000`00000000 fffff800`00000000 : win32kfull!xxxCallCtfHook+0xe4
ffffd001`af4868d0 fffff961`d5a661d4 : ffffd001`af486a48 ffffd001`af48c240 00000000`00000000 fffff800`ffffffff : win32kfull!xxxRealInternalGetMessage+0xd60
ffffd001`af486a00 fffff800`fd3cc863 : ffffe000`92342840 00000000`00fce618 ffffd001`af486aa8 00000000`010cf3c4 : win32kfull!NtUserPeekMessage+0x94
ffffd001`af486a90 00000000`6c2533fa : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`00fce5f8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x6c2533fa
STACK_COMMAND: kb
FOLLOWUP_IP:
win32kfull!fnHkINLPMSG+1be
fffff961`d5a6a2ae 8bf8 mov edi,eax
SYMBOL_STACK_INDEX: a
SYMBOL_NAME: win32kfull!fnHkINLPMSG+1be
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32kfull
IMAGE_NAME: [COLOR=red]win32kfull.sys[/COLOR]
DEBUG_FLR_IMAGE_TIMESTAMP: 55af1278
IMAGE_VERSION: 10.0.10240.16397
BUCKET_ID_FUNC_OFFSET: 1be
FAILURE_BUCKET_ID: [COLOR=red] AV_win32kfull!fnHkINLPMSG[/COLOR]
BUCKET_ID: AV_win32kfull!fnHkINLPMSG
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:av_win32kfull!fnhkinlpmsg
FAILURE_ID_HASH: {958b90fb-8cc5-b4af-cc1e-1efa23639a6e}
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 0000151420204d43, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000001, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff800fd2b1bc4, address which referenced memory
Debugging Details:
------------------
DUMP_FILE_ATTRIBUTES: 0x8
Kernel Generated Triage Dump
WRITE_ADDRESS: 0000151420204d43
CURRENT_IRQL: 2
FAULTING_IP:
nt!KxWaitForLockOwnerShip+14
fffff800`fd2b1bc4 48890a mov qword ptr [rdx],rcx
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: AV
PROCESS_NAME: firefox.exe
ANALYSIS_VERSION: 6.3.9600.17298 (debuggers(dbg).141024-1500) amd64fre
TRAP_FRAME: ffffd001af486180 -- (.trap 0xffffd001af486180)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffffa80065d0500 rbx=0000000000000000 rcx=ffffd001af486370
rdx=0000151420204d43 rsi=0000000000000000 rdi=0000000000000000
rip=fffff800fd2b1bc4 rsp=ffffd001af486310 rbp=ffffd001af4863b9
r8=0000000000000001 r9=0000000000000000 r10=0000000000000001
r11=d42000000000371b r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
nt!KxWaitForLockOwnerShip+0x14:
fffff800`fd2b1bc4 48890a mov qword ptr [rdx],rcx ds:00001514`20204d43=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff800fd3ccba9 to fffff800fd3c2220
STACK_TEXT:
ffffd001`af486038 fffff800`fd3ccba9 : 00000000`0000000a 00001514`20204d43 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
ffffd001`af486040 fffff800`fd3cb3c8 : fffffff6`00000000 00000001`ffffffff 00000001`00000005 00000000`000000fe : nt!KiBugCheckDispatch+0x69
ffffd001`af486180 fffff800`fd2b1bc4 : fffffa80`065d07f8 00000000`0003be13 00000000`00000013 fffff800`fd5bba80 : nt!KiPageFault+0x248
ffffd001`af486310 fffff800`fd2c70d7 : fffffa80`007be6a0 ffffd001`af4863b9 ffffe000`91bcd080 e0009230`f1a2d2cd : nt!KxWaitForLockOwnerShip+0x14
ffffd001`af486340 fffff800`fd28667d : 00000000`000294ce fffff6e8`00d5bfa0 00000000`0000000f fffff800`00000001 : nt!MiInsertPageInFreeOrZeroedList+0x5f7
ffffd001`af486420 fffff800`fd2d6b51 : 00000043`f3d640f9 ffffe000`92342840 00000000`00000003 00000000`00000000 : nt!MiPfnShareCountIsZero+0x2ad
ffffd001`af486530 fffff800`fd369ae0 : 00000000`00000006 00000000`00000002 fffff6e8`00d5bf70 00000000`00000000 : nt!MiDeleteKernelStackPages+0x141
ffffd001`af486590 fffff800`fd2f1f33 : 00000000`00000000 00000000`00000002 00000000`00000000 00000000`00000000 : nt!MiDeleteKernelStack+0x64
ffffd001`af4865e0 fffff800`fd6b1657 : 00000000`00000035 ffffe000`00000000 00000000`00000000 00000000`00000006 : nt!MmDeleteKernelStack+0x263
ffffd001`af486670 fffff961`d5a6a2ae : 00000000`0000002f ffffd001`af486760 ffffd001`00000058 ffffd001`af486828 : nt!KeUserModeCallback+0x247
ffffd001`af486710 fffff961`d5a64c54 : fffff901`00000018 00000000`010cf358 fffff901`43e6cc20 00000000`00000000 : win32kfull!fnHkINLPMSG+0x1be
ffffd001`af486820 fffff961`d5a677c0 : fffff901`40782870 ffffd001`af486a48 00000000`00000000 fffff800`00000000 : win32kfull!xxxCallCtfHook+0xe4
ffffd001`af4868d0 fffff961`d5a661d4 : ffffd001`af486a48 ffffd001`af48c240 00000000`00000000 fffff800`ffffffff : win32kfull!xxxRealInternalGetMessage+0xd60
ffffd001`af486a00 fffff800`fd3cc863 : ffffe000`92342840 00000000`00fce618 ffffd001`af486aa8 00000000`010cf3c4 : win32kfull!NtUserPeekMessage+0x94
ffffd001`af486a90 00000000`6c2533fa : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`00fce5f8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x6c2533fa
STACK_COMMAND: kb
FOLLOWUP_IP:
win32kfull!fnHkINLPMSG+1be
fffff961`d5a6a2ae 8bf8 mov edi,eax
SYMBOL_STACK_INDEX: a
SYMBOL_NAME: win32kfull!fnHkINLPMSG+1be
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32kfull
IMAGE_NAME: win32kfull.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 55af1278
IMAGE_VERSION: 10.0.10240.16397
BUCKET_ID_FUNC_OFFSET: 1be
FAILURE_BUCKET_ID: AV_win32kfull!fnHkINLPMSG
BUCKET_ID: AV_win32kfull!fnHkINLPMSG
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:av_win32kfull!fnhkinlpmsg
FAILURE_ID_HASH: {958b90fb-8cc5-b4af-cc1e-1efa23639a6e}
Followup: MachineOwner