Microsoft (R) Windows Debugger Version 6.11.0001.404 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\Jonathan\Desktop\021110-19016-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16385.amd64fre.win7_rtm.090713-1255
Machine Name:
Kernel base = 0xfffff800`02a63000 PsLoadedModuleList = 0xfffff800`02ca0e50
Debug session time: Thu Feb 11 08:35:07.143 2010 (GMT-5)
System Uptime: 0 days 6:03:53.312
Loading Kernel Symbols
...............................................................
................................................................
.........................
Loading User Symbols
Loading unloaded module list
.......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck D1, {2e, 2, 1, fffff88000e3b891}
Unable to load image \SystemRoot\system32\DRIVERS\LHidFilt.Sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for LHidFilt.Sys
*** ERROR: Module load completed but symbols could not be loaded for LHidFilt.Sys
Probably caused by : hardware ( LHidFilt+9131 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: 000000000000002e, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000001, value 0 = read operation, 1 = write operation
Arg4: fffff88000e3b891, address which referenced memory
Debugging Details:
------------------
WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff80002d0b0e0
000000000000002e
CURRENT_IRQL: 2
FAULTING_IP:
Wdf01000!FxRequest::GetMemoryObject+4a5
fffff880`00e3b891 01752d add dword ptr [rbp+2Dh],esi
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xD1
PROCESS_NAME: Wow.exe
TRAP_FRAME: fffff80000ba2520 -- (.trap 0xfffff80000ba2520)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffffa80057ce2b0 rbx=0000000000000000 rcx=fffffa80057e6650
rdx=0000000000000001 rsi=0000000000000000 rdi=0000000000000000
rip=fffff88000e3b891 rsp=fffff80000ba26b0 rbp=0000000000000001
r8=fffff80000ba2703 r9=0000000000000000 r10=fffffa800592dd30
r11=0000000000000002 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na pe nc
Wdf01000!FxRequest::GetMemoryObject+0x4a5:
fffff880`00e3b891 01752d add dword ptr [rbp+2Dh],esi ss:00000000`0000002e=????????
Resetting default scope
MISALIGNED_IP:
Wdf01000!FxRequest::GetMemoryObject+4a5
fffff880`00e3b891 01752d add dword ptr [rbp+2Dh],esi
LAST_CONTROL_TRANSFER: from fffff80002ad4469 to fffff80002ad4f00
STACK_TEXT:
fffff800`00ba23d8 fffff800`02ad4469 : 00000000`0000000a 00000000`0000002e 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
fffff800`00ba23e0 fffff800`02ad30e0 : 00000000`00000000 fffffa80`0592dd30 00000000`00000413 00000000`00000000 : nt!KiBugCheckDispatch+0x69
fffff800`00ba2520 fffff880`00e3b891 : fffffa80`057ce698 ffffffff`fff24460 00000000`00000000 fffffa80`0592dd30 : nt!KiPageFault+0x260
fffff800`00ba26b0 fffff880`00e2b96b : fffffa80`04f00000 fffff800`00ba27d8 fffff800`00ba2820 00000000`00000000 : Wdf01000!FxRequest::GetMemoryObject+0x4a5
fffff800`00ba2740 fffff880`05bd5131 : fffffa80`0592dd30 00000000`00000000 fffffa80`0592dd30 00000000`00000001 : Wdf01000!imp_WdfRequestRetrieveOutputBuffer+0x14b
fffff800`00ba27d0 fffffa80`0592dd30 : 00000000`00000000 fffffa80`0592dd30 00000000`00000001 fffff800`00ba2820 : LHidFilt+0x9131
fffff800`00ba27d8 00000000`00000000 : fffffa80`0592dd30 00000000`00000001 fffff800`00ba2820 00000000`00000002 : 0xfffffa80`0592dd30
STACK_COMMAND: kb
FOLLOWUP_IP:
LHidFilt+9131
fffff880`05bd5131 ?? ???
SYMBOL_STACK_INDEX: 5
SYMBOL_NAME: LHidFilt+9131
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: hardware
IMAGE_NAME: hardware
DEBUG_FLR_IMAGE_TIMESTAMP: 0
FAILURE_BUCKET_ID: X64_IP_MISALIGNED
BUCKET_ID: X64_IP_MISALIGNED
Followup: MachineOwner
---------