Executable search path is:
*** ERROR: Symbol file could not be found. Defaulted to export symbols for ntkrpamp.exe -
Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16695.x86fre.win7_gdr.101026-1503
Machine Name:
Kernel base = 0x82e0e000 PsLoadedModuleList = 0x82f56810
Debug session time: Tue Mar 22 03:12:59.501 2011 (UTC + 1:00)
System Uptime: 0 days 3:53:13.529
*** ERROR: Symbol file could not be found. Defaulted to export symbols for ntkrpamp.exe -
Loading Kernel Symbols
...............................................................
................................................................
.................................
Loading User Symbols
Loading unloaded module list
..........
Unable to load image \SystemRoot\system32\DRIVERS\athr.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for athr.sys
*** ERROR: Module load completed but symbols could not be loaded for athr.sys
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck D1, {30, 2, 0, 91a518a5}
Probably caused by : athr.sys ( athr+428a5 )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: 00000030, memory referenced
Arg2: 00000002, IRQL
Arg3: 00000000, value 0 = read operation, 1 = write operation
Arg4: 91a518a5, address which referenced memory
Debugging Details:
------------------
ADDITIONAL_DEBUG_TEXT:
Use '!findthebuild' command to search for the target build information.
If the build information is available, run '!findthebuild -s ; .reload' to set symbol path and load symbols.
MODULE_NAME: athr
FAULTING_MODULE: 82e0e000 nt
DEBUG_FLR_IMAGE_TIMESTAMP: 4acea1f4
READ_ADDRESS: unable to get nt!MmSpecialPoolStart
unable to get nt!MmSpecialPoolEnd
unable to get nt!MmPoolCodeStart
unable to get nt!MmPoolCodeEnd
00000030
CURRENT_IRQL: 0
FAULTING_IP:
athr+428a5
91a518a5 8b5130 mov edx,dword ptr [ecx+30h]
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xD1
LAST_CONTROL_TRANSFER: from 91a518a5 to 82e5481b
STACK_TEXT:
WARNING: Stack unwind information not available. Following frames may be wrong.
8c0a98f4 91a518a5 badb0d00 00000088 86c3db88 nt!Kei386EoiHelper+0x29d3
8c0a996c 91a51647 00000000 876e34a4 87f81608 athr+0x428a5
8c0a99a4 91a50c52 85aea108 86f03528 00000000 athr+0x42647
8c0a99cc 91a77fc0 85aea028 86f03528 00000018 athr+0x41c52
8c0a9a20 91a788c7 86e84020 86f03528 00000000 athr+0x68fc0
8c0a9b74 91a29cfe 86f03528 8c0a9b90 91a26d2f athr+0x698c7
8c0a9b80 91a26d2f 86f03528 86ad2b68 8c0a9ba0 athr+0x1acfe
8c0a9b90 91a6e9c7 86ad2b68 86f03528 8c0a9bc8 athr+0x17d2f
8c0a9ba0 91a6e6b7 86e9d628 86f03528 00000000 athr+0x5f9c7
8c0a9bc8 91a2262a 86e9d628 86f03528 00000000 athr+0x5f6b7
8c0a9bf4 91a22414 868e0240 86f034a0 870474a0 athr+0x1362a
8c0a9c0c 91a23499 868e0240 88247710 879374b8 athr+0x13414
8c0a9c24 91a23525 868e0240 8c0a9c3c 91a80514 athr+0x14499
8c0a9c30 91a80514 868e0240 8c0a9c58 91a851bf athr+0x14525
8c0a9c3c 91a851bf 86e9a020 8c0a9cc8 00000983 athr+0x71514
8c0a9c58 91a29abd 86e9a020 8c0a9c74 91a10761 athr+0x761bf
8c0a9c64 91a10761 86e84020 868e0240 8c0a9cb0 athr+0x1aabd
8c0a9c74 8ae5b309 868e0240 00000000 8c0a9ca0 athr+0x1761
8c0a9cb0 8ae3c6b2 870474b4 000474a0 00000000 ndis!ndisMiniportDpc+0xe2
8c0a9d10 8ae23976 870475a0 00000000 8606cb60 ndis!ndisQueuedMiniportDpcWorkItem+0xd0
8c0a9d50 8301c9df 00000001 bb08a395 00000000 ndis!ndisReceiveWorkerThread+0xeb
8c0a9d90 82ece1d9 8ae2388b 00000001 00000000 nt!PsCreateSystemThread+0x19a
00000000 00000000 00000000 00000000 00000000 nt!wcsupr+0x13a
STACK_COMMAND: kb
FOLLOWUP_IP:
athr+428a5
91a518a5 8b5130 mov edx,dword ptr [ecx+30h]
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: athr+428a5
FOLLOWUP_NAME: MachineOwner
IMAGE_NAME: athr.sys
BUCKET_ID: WRONG_SYMBOLS
Followup: MachineOwner