DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: 00000000154e03dc, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000001, value 0 = read operation, 1 = write operation
Arg4: fffff8072c202076, address which referenced memory
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.Sec
Value: 1
Key : Analysis.DebugAnalysisProvider.CPP
Value: Create: 8007007e on M70QDS6L
Key : Analysis.DebugData
Value: CreateObject
Key : Analysis.DebugModel
Value: CreateObject
Key : Analysis.Elapsed.Sec
Value: 65
Key : Analysis.Memory.CommitPeak.Mb
Value: 73
Key : Analysis.System
Value: CreateObject
DUMP_FILE_ATTRIBUTES: 0x21000
BUGCHECK_CODE: d1
BUGCHECK_P1: 154e03dc
BUGCHECK_P2: 2
BUGCHECK_P3: 1
BUGCHECK_P4: fffff8072c202076
WRITE_ADDRESS: Unable to get offset of nt!_MI_VISIBLE_STATE.SessionWsList
Unable to get nt!MiVisibleState->SessionIdBitmap
MAX_SYSTEM_VA_ASSIGNMENTS needs to be increased
00000000154e03dc
BLACKBOXBSD: 1 (!blackboxbsd)
BLACKBOXNTFS: 1 (!blackboxntfs)
BLACKBOXPNP: 1 (!blackboxpnp)
BLACKBOXWINLOGON: 1
PROCESS_NAME: NoxVMHandle.exe
TRAP_FRAME: ffffac0c56e2eed0 -- (.trap 0xffffac0c56e2eed0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000001035000 rbx=0000000000000000 rcx=00000000154e03c0
rdx=000ffffffffff000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8072c202076 rsp=ffffac0c56e2f060 rbp=0000000001035e1d
r8=0000000001035e1d r9=0000000001035e1d r10=ffffe4005f100000
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na po nc
YSR0!PGMPhysRead+0x1f6:
fffff807`2c202076 ff411c inc dword ptr [rcx+1Ch] ds:00000000`154e03dc=????????
Resetting default scope
评论
直达楼层