*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck D1, {1c, 2, 1, fffff8800536d8e8}
*** WARNING: Unable to verify timestamp for athrx.sys
*** ERROR: Module load completed but symbols could not be loaded for athrx.sys
Probably caused by : athrx.sys ( athrx+ff8e8 )
Followup: MachineOwner
---------
4: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: 000000000000001c, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000001, value 0 = read operation, 1 = write operation
Arg4: fffff8800536d8e8, address which referenced memory
Debugging Details:
------------------
WRITE_ADDRESS: GetPointerFromAddress: unable to read from fffff800036c8100
GetUlongFromAddress: unable to read from fffff800036c81c0
000000000000001c Nonpaged pool
CURRENT_IRQL: 2
FAULTING_IP:
athrx+ff8e8
fffff880`0536d8e8 c7401c00000000 mov dword ptr [rax+1Ch],0
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
BUGCHECK_STR: 0xD1
PROCESS_NAME: System
TRAP_FRAME: fffff8800354d810 -- (.trap 0xfffff8800354d810)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=0000000000000000
rdx=0000000000009920 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8800536d8e8 rsp=fffff8800354d9a0 rbp=fffff80003636280
r8=000000000491a000 r9=0000000000000000 r10=0000000000000050
r11=fffffa80078590f8 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na pe nc
athrx+0xff8e8:
fffff880`0536d8e8 c7401c00000000 mov dword ptr [rax+1Ch],0 ds:00000000`0000001c=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff800034901a9 to fffff80003490c00
STACK_TEXT:
fffff880`0354d6c8 fffff800`034901a9 : 00000000`0000000a 00000000`0000001c 00000000`00000002 00000000`00000001 : nt!KeBugCheckEx
fffff880`0354d6d0 fffff800`0348ee20 : 00000000`00000000 00000000`00000000 00000000`00000000 fffffa80`076b4050 : nt!KiBugCheckDispatch+0x69
fffff880`0354d810 fffff880`0536d8e8 : fffffa80`0784c030 fffffa80`078590f8 fffffa80`00000008 fffff880`00000000 : nt!KiPageFault+0x260
fffff880`0354d9a0 fffffa80`0784c030 : fffffa80`078590f8 fffffa80`00000008 fffff880`00000000 00000000`000186a0 : athrx+0xff8e8
fffff880`0354d9a8 fffffa80`078590f8 : fffffa80`00000008 fffff880`00000000 00000000`000186a0 fffffa80`07823fc0 : 0xfffffa80`0784c030
fffff880`0354d9b0 fffffa80`00000008 : fffff880`00000000 00000000`000186a0 fffffa80`07823fc0 00000000`00000000 : 0xfffffa80`078590f8
fffff880`0354d9b8 fffff880`00000000 : 00000000`000186a0 fffffa80`07823fc0 00000000`00000000 fffffa80`0784c030 : 0xfffffa80`00000008
fffff880`0354d9c0 00000000`000186a0 : fffffa80`07823fc0 00000000`00000000 fffffa80`0784c030 fffff880`0354dc54 : 0xfffff880`00000000
fffff880`0354d9c8 fffffa80`07823fc0 : 00000000`00000000 fffffa80`0784c030 fffff880`0354dc54 fffff880`0536648c : 0x186a0
fffff880`0354d9d0 00000000`00000000 : fffffa80`0784c030 fffff880`0354dc54 fffff880`0536648c fffffa80`0784c030 : 0xfffffa80`07823fc0
STACK_COMMAND: kb
FOLLOWUP_IP:
athrx+ff8e8
fffff880`0536d8e8 c7401c00000000 mov dword ptr [rax+1Ch],0
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: athrx+ff8e8
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: athrx
IMAGE_NAME: [COLOR="Red"]athrx.sys[/COLOR]
DEBUG_FLR_IMAGE_TIMESTAMP: 4ae25d38
FAILURE_BUCKET_ID: X64_0xD1_athrx+ff8e8
BUCKET_ID: X64_0xD1_athrx+ff8e8
Followup: MachineOwner
---------
4: kd> lmvm athrx
start end module name
fffff880`0526e000 fffff880`053eb000 athrx T (no symbols)
Loaded symbol image file: athrx.sys
[COLOR="red"] Image path: \SystemRoot\system32\DRIVERS\athrx.sys
Image name: athrx.sys[/COLOR]
Timestamp: Sat Oct 24 05:49:44 2009 (4AE25D38)
CheckSum: 0017F4D3
ImageSize: 0017D000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4