New
#1
BSOD irql problem help pl0x
hi guys im getting BSOD irql less than or equal... im running windows 7 64 bit pre-installed with the system plz plz plz help i have the contents from windows/minidump in a zip
hi guys im getting BSOD irql less than or equal... im running windows 7 64 bit pre-installed with the system plz plz plz help i have the contents from windows/minidump in a zip
Please provide this info: https://www.sevenforums.com/crashes-d...tructions.html
Preliminary analysis of the info provided (I did the last 5 memory dumps) shows that the problem is caused by your Storage drivers (iaStor.sys). I'd suggest updating your storage drivers from http://downloadcenter.intel.com
More later, I'm late for work right now! :)
Hi Bravoboy and congrats on getting your dumps uploaded! I've been watching your plight with interest.
STOP 0x000000D1: DRIVER_IRQL_NOT_LESS_OR_EQUAL
Usual causes: Device driver
Your last five dump files list iaStor.sys as the probable cause.
Old and incompatible drivers can and do cause issues with Windows 7.
As a Priority:
iaStor.sys Tue Oct 13 19:15:56 2009 Intel Rapid Storage.
I will update this post in approx 1/2 an hour with a full report of your latest dmp file.
Don't forget to run the TDSSKiller as soon as you possibly can. I think that a rootkit is your main problem.
***UPDATE***
Apart from two, all other dmp files are giving the same D1 stop error code and blaming the same driver, iastor.sys. The "other two" are:
STOP 0x0000003B: SYSTEM_SERVICE_EXCEPTION
Usual causes: System service, Device driver, graphics driver, ?memory
STOP 0x00000050: PAGE_FAULT_IN_NONPAGED_AREA
Usual causes: Defective hardware (particularly memory - but not just RAM), Faulty system service, Antivirus, Device driver, NTFS corruption, BIOS
As Usasma mentioned, run the https://www.sevenforums.com/crashes-debugging/96879-blue-screen-death-bsod-posting-instructions.html / jc_griff tool as soon as possible.
Outdated Drivers. Update:
rimmpx64.sys Fri Oct 03 07:39:15 2008
rimspx64.sys Mon Mar 03 09:19:03 2008
rixdpx64.sys Fri Jul 27 11:45:50 2007 Ricoh Memory Card Reader. Check with your PC or Motherboard Mfr.
Bugcheck Analysis:Drivers:Code:Executable search path is: Windows 7 Kernel Version 7600 MP (4 procs) Free x64 Product: WinNt, suite: TerminalServer SingleUserTS Personal Built by: 7600.16695.amd64fre.win7_gdr.101026-1503 Machine Name: Kernel base = 0xfffff800`02a11000 PsLoadedModuleList = 0xfffff800`02c4ee50 Debug session time: Wed Apr 13 08:40:40.932 2011 (UTC + 1:00) System Uptime: 0 days 0:00:32.806 Loading Kernel Symbols ............................................................... .............................. Loading User Symbols Loading unloaded module list .. ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck D1, {ffffffffffffffe1, 2, 1, fffff8800109c783} Unable to load image \SystemRoot\system32\DRIVERS\iaStor.sys, Win32 error 0n2 *** WARNING: Unable to verify timestamp for iaStor.sys *** ERROR: Module load completed but symbols could not be loaded for iaStor.sys Probably caused by : iaStor.sys ( iaStor+52783 ) Followup: MachineOwnerHTH.Code:fffff880`0293c000 fffff880`0297a000 1394ohci 1394ohci.sys Tue Jul 14 01:07:12 2009 (4A5BCC30) fffff880`02edf000 fffff880`02eee000 Acceler Acceler.sys Mon Nov 23 21:55:13 2009 (4B0B04C1) fffff880`00f76000 fffff880`00fcd000 ACPI ACPI.sys Tue Jul 14 00:19:34 2009 (4A5BC106) fffff880`011b4000 fffff880`011bf000 amdxata amdxata.sys Tue May 19 18:56:59 2009 (4A12F2EB) fffff880`01166000 fffff880`0116f000 atapi atapi.sys Tue Jul 14 00:19:47 2009 (4A5BC113) fffff880`0116f000 fffff880`01199000 ataport ataport.SYS Tue Jul 14 00:19:52 2009 (4A5BC118) fffff880`00e5e000 fffff880`00e6a000 BATTC BATTC.SYS Tue Jul 14 00:31:01 2009 (4A5BC3B5) fffff880`01600000 fffff880`01607000 Beep Beep.SYS Tue Jul 14 01:00:13 2009 (4A5BCA8D) fffff880`02eee000 fffff880`02eff000 blbdrive blbdrive.sys Tue Jul 14 00:35:59 2009 (4A5BC4DF) fffff880`02ea8000 fffff880`02ed2000 cdrom cdrom.sys Tue Jul 14 00:19:54 2009 (4A5BC11A) fffff880`00c00000 fffff880`00cc0000 CI CI.dll Tue Jul 14 02:32:13 2009 (4A5BE01D) fffff880`01286000 fffff880`012b6000 CLASSPNP CLASSPNP.SYS Tue Jul 14 00:19:58 2009 (4A5BC11E) fffff880`00d2a000 fffff880`00d88000 CLFS CLFS.SYS Tue Jul 14 00:19:57 2009 (4A5BC11D) fffff880`0137a000 fffff880`013ed000 cng cng.sys Tue Jul 14 00:49:40 2009 (4A5BC814) fffff880`00e55000 fffff880`00e5e000 compbatt compbatt.sys Tue Jul 14 00:31:02 2009 (4A5BC3B6) fffff880`02eff000 fffff880`02f0f000 CompositeBus CompositeBus.sys Tue Jul 14 01:00:33 2009 (4A5BCAA1) fffff880`02ff1000 fffff880`02fff000 crashdmp crashdmp.sys Tue Jul 14 01:01:01 2009 (4A5BCABD) fffff880`015ea000 fffff880`01600000 disk disk.sys Tue Jul 14 00:19:57 2009 (4A5BC11D) fffff880`037b5000 fffff880`037c8000 dump_dumpfve dump_dumpfve.sys Tue Jul 14 00:21:51 2009 (4A5BC18F) fffff880`03699000 fffff880`037b5000 dump_iaStor dump_iaStor.sys Tue Oct 13 19:15:56 2009 (4AD4C3DC) fffff880`037c8000 fffff880`037d4000 Dxapi Dxapi.sys Tue Jul 14 00:38:28 2009 (4A5BC574) fffff960`004e0000 fffff960`004fe000 dxg dxg.sys unavailable (00000000) fffff880`01308000 fffff880`0131c000 fileinfo fileinfo.sys Tue Jul 14 00:34:25 2009 (4A5BC481) fffff880`012bc000 fffff880`01308000 fltmgr fltmgr.sys Tue Jul 14 00:19:59 2009 (4A5BC11F) fffff960`00920000 fffff960`00929000 framebuf framebuf.dll unavailable (00000000) fffff880`015e0000 fffff880`015ea000 Fs_Rec Fs_Rec.sys Tue Jul 14 00:19:45 2009 (4A5BC111) fffff880`011bf000 fffff880`011f9000 fvevol fvevol.sys Sat Sep 26 03:34:26 2009 (4ABD7DB2) fffff880`01785000 fffff880`017cf000 fwpkclnt fwpkclnt.sys Tue Jul 14 00:21:08 2009 (4A5BC164) fffff880`02ed2000 fffff880`02edf000 GEARAspiWDM GEARAspiWDM.sys Mon May 18 13:17:04 2009 (4A1151C0) fffff800`02fee000 fffff800`03037000 hal hal.dll Tue Jul 14 02:27:36 2009 (4A5BDF08) fffff880`00e99000 fffff880`00ebd000 HDAudBus HDAudBus.sys Tue Jul 14 01:06:13 2009 (4A5BCBF5) fffff880`03629000 fffff880`03642000 HIDCLASS HIDCLASS.SYS Tue Jul 14 01:06:21 2009 (4A5BCBFD) fffff880`03642000 fffff880`0364a080 HIDPARSE HIDPARSE.SYS Tue Jul 14 01:06:17 2009 (4A5BCBF9) fffff880`0361b000 fffff880`03629000 hidusb hidusb.sys Tue Jul 14 01:06:22 2009 (4A5BCBFE) fffff880`017e9000 fffff880`017f2000 hwpolicy hwpolicy.sys Tue Jul 14 00:19:22 2009 (4A5BC0FA) fffff880`0285c000 fffff880`0287a000 i8042prt i8042prt.sys Tue Jul 14 00:19:57 2009 (4A5BC11D) fffff880`0104a000 fffff880`01166000 iaStor iaStor.sys Tue Oct 13 19:15:56 2009 (4AD4C3DC) fffff880`02800000 fffff880`0285c000 itecir itecir.sys Mon Mar 09 08:58:47 2009 (49B4DA47) fffff880`0287a000 fffff880`02889000 kbdclass kbdclass.sys Tue Jul 14 00:19:50 2009 (4A5BC116) fffff880`0364b000 fffff880`03659000 kbdhid kbdhid.sys Tue Jul 14 01:00:20 2009 (4A5BCA94) fffff800`00baf000 fffff800`00bb2000 kdcom kdcom.dll Mon Mar 14 11:05:09 2011 (4D7DF665) fffff880`02f30000 fffff880`02f73000 ks ks.sys Thu Mar 04 04:32:25 2010 (4B8F37D9) fffff880`015b5000 fffff880`015cf000 ksecdd ksecdd.sys Tue Jul 14 00:20:54 2009 (4A5BC156) fffff880`0175a000 fffff880`01785000 ksecpkg ksecpkg.sys Fri Dec 11 06:03:32 2009 (4B21E0B4) fffff880`00cd2000 fffff880`00d16000 mcupdate_GenuineIntel mcupdate_GenuineIntel.dll Tue Jul 14 02:29:10 2009 (4A5BDF66) fffff880`00ff1000 fffff880`01000000 mouclass mouclass.sys Tue Jul 14 00:19:50 2009 (4A5BC116) fffff880`03659000 fffff880`03666000 mouhid mouhid.sys Tue Jul 14 01:00:20 2009 (4A5BCA94) fffff880`00e7f000 fffff880`00e99000 mountmgr mountmgr.sys Tue Jul 14 00:19:54 2009 (4A5BC11A) fffff880`01199000 fffff880`011a4000 msahci msahci.sys Sat Nov 14 04:36:50 2009 (4AFE33E2) fffff880`01025000 fffff880`01030000 Msfs Msfs.SYS Tue Jul 14 00:19:47 2009 (4A5BC113) fffff880`00fd6000 fffff880`00fe0000 msisadrv msisadrv.sys Tue Jul 14 00:19:26 2009 (4A5BC0FE) fffff880`0131c000 fffff880`0137a000 msrpc msrpc.sys Tue Jul 14 00:21:32 2009 (4A5BC17C) fffff880`02f0f000 fffff880`02f1a000 mssmbios mssmbios.sys Tue Jul 14 00:31:10 2009 (4A5BC3BE) fffff880`017d7000 fffff880`017e9000 mup mup.sys Tue Jul 14 00:23:45 2009 (4A5BC201) fffff880`01608000 fffff880`016fa000 ndis ndis.sys Tue Jul 14 00:21:40 2009 (4A5BC184) fffff880`016fa000 fffff880`0175a000 NETIO NETIO.SYS Tue Jul 14 00:21:46 2009 (4A5BC18A) fffff880`01030000 fffff880`01041000 Npfs Npfs.SYS Tue Jul 14 00:19:48 2009 (4A5BC114) fffff800`02a11000 fffff800`02fee000 nt ntkrnlmp.exe Wed Oct 27 03:43:09 2010 (4CC791BD) fffff880`01412000 fffff880`015b5000 Ntfs Ntfs.sys Tue Jul 14 00:20:47 2009 (4A5BC14F) fffff880`017f2000 fffff880`017fb000 Null Null.SYS Tue Jul 14 00:19:37 2009 (4A5BC109) fffff880`00e40000 fffff880`00e55000 partmgr partmgr.sys Tue Jul 14 00:19:58 2009 (4A5BC11E) fffff880`00e00000 fffff880`00e33000 pci pci.sys Tue Jul 14 00:19:51 2009 (4A5BC117) fffff880`011a4000 fffff880`011b4000 PCIIDEX PCIIDEX.SYS Tue Jul 14 00:19:48 2009 (4A5BC114) fffff880`015cf000 fffff880`015e0000 pcw pcw.sys Tue Jul 14 00:19:27 2009 (4A5BC0FF) fffff880`00d16000 fffff880`00d2a000 PSHED PSHED.dll Tue Jul 14 02:32:23 2009 (4A5BE027) fffff880`0124c000 fffff880`01286000 rdyboost rdyboost.sys Tue Jul 14 00:34:34 2009 (4A5BC48A) fffff880`0297a000 fffff880`02990000 rimmpx64 rimmpx64.sys Fri Oct 03 07:39:15 2008 (48E5BE13) fffff880`02990000 fffff880`029a7000 rimspx64 rimspx64.sys Mon Mar 03 09:19:03 2008 (47CBC287) fffff880`029a7000 fffff880`029fe000 rixdpx64 rixdpx64.sys Fri Jul 27 11:45:50 2007 (46A9CCDE) fffff880`02f2e000 fffff880`02f2f480 swenum swenum.sys Tue Jul 14 01:00:18 2009 (4A5BCA92) fffff880`02889000 fffff880`028da000 SynTP SynTP.sys Fri Oct 23 02:20:19 2009 (4AE104D3) fffff880`01802000 fffff880`019ff000 tcpip tcpip.sys Mon Jun 14 04:39:04 2010 (4C15A458) fffff880`02f1a000 fffff880`02f2e000 termdd termdd.sys Tue Jul 14 01:16:36 2009 (4A5BCE64) fffff960`006c0000 fffff960`006ca000 TSDDD TSDDD.dll unavailable (00000000) fffff880`02f85000 fffff880`02f97000 umbus umbus.sys Tue Jul 14 01:06:56 2009 (4A5BCC20) fffff880`037d4000 fffff880`037f1000 usbccgp usbccgp.sys Tue Jul 14 01:06:45 2009 (4A5BCC15) fffff880`028da000 fffff880`028dbf00 USBD USBD.SYS Tue Jul 14 01:06:23 2009 (4A5BCBFF) fffff880`00fe0000 fffff880`00ff1000 usbehci usbehci.sys Tue Jul 14 01:06:30 2009 (4A5BCC06) fffff880`02f97000 fffff880`02ff1000 usbhub usbhub.sys Sat Sep 05 04:24:43 2009 (4AA1D9FB) fffff880`028e6000 fffff880`0293c000 USBPORT USBPORT.SYS Tue Jul 14 01:06:31 2009 (4A5BCC07) fffff880`03600000 fffff880`0361b000 USBSTOR USBSTOR.SYS Tue Jul 14 01:06:34 2009 (4A5BCC0A) fffff880`00e33000 fffff880`00e40000 vdrvroot vdrvroot.sys Tue Jul 14 01:01:31 2009 (4A5BCADB) fffff880`01400000 fffff880`0140e000 vga vga.sys Tue Jul 14 00:38:47 2009 (4A5BC587) fffff880`01000000 fffff880`01025000 VIDEOPRT VIDEOPRT.SYS Tue Jul 14 00:38:51 2009 (4A5BC58B) fffff880`00e6a000 fffff880`00e7f000 volmgr volmgr.sys Tue Jul 14 00:19:57 2009 (4A5BC11D) fffff880`00d88000 fffff880`00de4000 volmgrx volmgrx.sys Tue Jul 14 00:20:33 2009 (4A5BC141) fffff880`01200000 fffff880`0124c000 volsnap volsnap.sys Tue Jul 14 00:20:08 2009 (4A5BC128) fffff880`013ed000 fffff880`013fd000 watchdog watchdog.sys Tue Jul 14 00:37:35 2009 (4A5BC53F) fffff880`00ec3000 fffff880`00f67000 Wdf01000 Wdf01000.sys Tue Jul 14 00:22:07 2009 (4A5BC19F) fffff880`00f67000 fffff880`00f76000 WDFLDR WDFLDR.SYS Tue Jul 14 00:19:54 2009 (4A5BC11A) fffff960`00030000 fffff960`00340000 win32k win32k.sys unavailable (00000000) fffff880`01041000 fffff880`0104a000 wmiacpi wmiacpi.sys Tue Jul 14 00:31:02 2009 (4A5BC3B6) fffff880`00fcd000 fffff880`00fd6000 WMILIB WMILIB.SYS Tue Jul 14 00:19:51 2009 (4A5BC117) fffff880`03666000 fffff880`03687000 WudfPf WudfPf.sys Tue Jul 14 01:05:37 2009 (4A5BCBD1) Unloaded modules: fffff880`02f73000 fffff880`02f85000 circlass.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00012000 fffff880`017cf000 fffff880`017d7000 spldr.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00008000
Last edited by fimble; 13 Apr 2011 at 06:16.
upon running this i got BSOD with system_service_exception message.
In reply to fimble, i cannot run TDSSkiller because i can only access a non administrator account and this program requires administrator clearance. However, i am able to run cmd through administrator (this is how i was able to bring you the dump files) so if there is and way i can run TDSSkiller through cmd it would really help me out
also very nooby question but how would i go about updating the drivers in question? (iaStor.sys, rimmpx64.sys, rimspx64.sys, rixdpx64.sys)
To run TDSSKiller from cmd prompt you are supposed to be able to enter TDSSKiller.exe -l report.txt which should run TDSSKiller and save a report.
That didn't work for me though. By adding its path, in my case C:, it ran straight away. e.g. C:\TDSSKiller.exe -l report.txt Be aware that I did this from inside Windows. I'm hoping that's enough for you to run it.
The link I provided for the iastor.sys driver will take you to a page where you download an auto installer.how would i go about updating the drivers in question?
The Ricoh drivers will be a manual search of your PC or Mobo support sites.
Thank you SO much for this helpful reply! i have yet to try these but il update on the result.
In my case the file is located at the desktop, i would move it to the c: but the same administrator problems prevent me. I tried TDSSKiller.exe -1 report with no luck.
then adding the directory was slightly more complicated than c:\ i used c:\user\ian elsegood\desktop\tdsskiller\tdsskiller.exe -1 report.txt and got a message "the system cannot find the path specified" i have a feeling this is possibly more my fault that the computers. Also to check it is (in your example) c:\TDSSKiller.exe(space)-1(space)report.txt is this correct?
Last edited by BravoBoy; 13 Apr 2011 at 15:41. Reason: update
I'd forget the report, it's a complication! For the record it is l, as in Llama, little lion and lucky me!
Use c:\userS\ian elsegood\desktop\tdsskiller\tdsskiller.exe
Note it is users , not user .
DAMN!! Late Edit!! Also if you do have a space in your user name use quote "" marks so:
"c:\userS\ian elsegood\desktop\tdsskiller\tdsskiller.exe"
Thats why I dropped mine in C:\. Keeps the cmd prompt short n sweet, although I recognise you are unable to do so.
' "c:\users\ian elsegood\desktop\tdsskiller\tdsskiller.exe"' is not recognized as an internal or external commands, operable program or batch file.... still somthing i must be doing wrong? Also in respect to the intel driver update utility is there a downloadable program that does the same thing because i am unable to boot in safe mode with networking, only safe mode so the computer has to internet connection
Can you run a registry (.reg) file? If so, open notepad, copy paste this code:Save as whatever.reg and double click it accept the warning (yes) then ok.Code:Windows Registry Editor Version 5.00 [HKEY_CLASSES_ROOT\directory\shell\CMD] @="Open Elevated Cmd" [HKEY_CLASSES_ROOT\directory\shell\CMD\command] @="cmd.exe /s /k pushd \"%V\""
Now right click on the TDSSKiller folder and select "Open elevated cmd"
Now you should only have to type in TDSSKiller.exe and it will run. I'll admit I'm no expert on changing file paths in command prompt!