*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck D1, {4, 2, 0, 980c03d2}
Unable to load image \SystemRoot\system32\DRIVERS\athr.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for athr.sys
*** ERROR: Module load completed but symbols could not be loaded for athr.sys
Probably caused by : athr.sys ( athr+bc3d2 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: 00000004, memory referenced
Arg2: 00000002, IRQL
Arg3: 00000000, value 0 = read operation, 1 = write operation
Arg4: 980c03d2, address which referenced memory
Debugging Details:
------------------
READ_ADDRESS: GetPointerFromAddress: unable to read from 833a484c
Unable to read MiSystemVaType memory at 83383f00
00000004
CURRENT_IRQL: 2
FAULTING_IP:
athr+bc3d2
980c03d2 83780401 cmp dword ptr [eax+4],1
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
BUGCHECK_STR: 0xD1
PROCESS_NAME: System
ANALYSIS_VERSION: 6.3.9600.17237 (debuggers(dbg).140716-0327) amd64fre
TRAP_FRAME: 833629e4 -- (.trap 0xffffffff833629e4)
ErrCode = 00000000
eax=00000000 ebx=870ec490 ecx=87366020 edx=00000000 esi=8704d0e0 edi=8334bce6
eip=980c03d2 esp=83362a58 ebp=83362a64 iopl=0 nv up ei pl zr na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010246
athr+0xbc3d2:
980c03d2 83780401 cmp dword ptr [eax+4],1 ds:0023:00000004=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from 980c03d2 to 8327bb7f
STACK_TEXT:
833629e4 980c03d2 badb0d00 00000000 000099b4 nt!KiTrap0E+0x1b3
WARNING: Stack unwind information not available. Following frames may be wrong.
83362a64 980848b8 87366020 87339000 00000001 athr+0xbc3d2
83362adc 9808744a 87337020 8733a46c 83362b08 athr+0x808b8
83362aec 98043af2 00000000 8733a46c 00000000 athr+0x8344a
83362b08 8c2f16f2 00000000 8733a46c 00000000 athr+0x3faf2
83362b38 832b4639 870ec4c8 000ec490 b51eae95 ndis!ndisMTimerObjectDpc+0xbc
83362b7c 832b45dd 83365d20 83362ca8 00000001 nt!KiProcessTimerDpcTable+0x50
83362c68 832b449a 83365d20 83362ca8 00000000 nt!KiProcessExpiredTimerList+0x101
83362cdc 832b262e 000d7eb0 85ef5030 8336f380 nt!KiTimerExpiration+0x25c
83362d20 832b2458 00000000 0000000e 00000000 nt!KiRetireDpcList+0xcb
83362d24 00000000 0000000e 00000000 00000000 nt!KiIdleLoop+0x38
STACK_COMMAND: kb
FOLLOWUP_IP:
athr+bc3d2
980c03d2 83780401 cmp dword ptr [eax+4],1
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: athr+bc3d2
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: athr
IMAGE_NAME: athr.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4ae25cc1
FAILURE_BUCKET_ID: 0xD1_athr+bc3d2
BUCKET_ID: 0xD1_athr+bc3d2
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0xd1_athr+bc3d2
FAILURE_ID_HASH: {38dee476-bd3b-00ed-d4fa-a781c787a256}
Followup: MachineOwner
---------
0: kd> lmvm athr
start end module name
98004000 98131000 athr T (no symbols)
Loaded symbol image file: athr.sys
Image path: \SystemRoot\system32\DRIVERS\athr.sys
Image name: athr.sys
Timestamp: Sat Oct 24 07:17:45 2009 (4AE25CC1)
CheckSum: 0012D65A
ImageSize: 0012D000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4