Hi,
Several users have been getting BSOD recently in our office and the error appears to be the same:
DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: 000000000058000b, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, value 0 = read operation, 1 = write operation
Arg4: fffff88001a99c17, address which referenced memory
Debugging Details:
------------------
TRIAGER: Could not open triage file : e:\dump_analysis\program\triage\modclass.ini, error 2
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800032be100
GetUlongFromAddress: unable to read from fffff800032be1c8
000000000058000b Nonpaged pool
CURRENT_IRQL: 2
FAULTING_IP:
tcpip! ?? ::FNODOBFM::`string'+23d7
fffff880`01a99c17 488b4108 mov rax,qword ptr [rcx+8]
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
BUGCHECK_STR: 0xD1
PROCESS_NAME: LMS.exe
TRAP_FRAME: fffff880030aa040 -- (.trap 0xfffff880030aa040)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffffa8021ab79d0 rbx=0000000000000000 rcx=0000000000580003
rdx=fffffa801daadc02 rsi=0000000000000000 rdi=0000000000000000
rip=fffff88001a99c17 rsp=fffff880030aa1d8 rbp=fffffa800c9b4000
r8=fffff880030aa248 r9=fffff880030aa200 r10=fffffa8023978c30
r11=000000000000c00f r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
tcpip! ?? ::FNODOBFM::`string'+0x23d7:
fffff880`01a99c17 488b4108 mov rax,qword ptr [rcx+8] ds:00000000`0058000b=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff800030cdd69 to fffff800030bf8a0
STACK_TEXT:
fffff880`030a9ef8 fffff800`030cdd69 : 00000000`0000000a 00000000`0058000b 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
fffff880`030a9f00 fffff800`030cbb88 : 00000000`00000000 00000000`0058000b fffff880`030aa100 fffffa80`1f9e50f8 : nt!KiBugCheckDispatch+0x69
fffff880`030aa040 fffff880`01a99c17 : fffff880`01a97259 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x448
fffff880`030aa1d8 fffff880`01a97259 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : tcpip! ?? ::FNODOBFM::`string'+0x23d7
fffff880`030aa1e0 fffff880`01a864c7 : 00000000`00000000 00000000`00000000 fffffa80`1daadcd0 fffffa80`0c9b4000 : tcpip!EnumerateEndpointInAssignment+0x59
fffff880`030aa220 fffff880`01a86114 : 00000000`00000000 fffffa80`0c9b4000 fffffa80`1f9e50f0 fffffa80`1daadcd0 : tcpip!EnumerateAndReferenceEndpointInAssignment+0x4b
fffff880`030aa260 fffff880`01a0c123 : 00000000`0000c00b 00000000`0000c00f fffffa80`0c9b4000 fffffa80`0c9b4000 : tcpip!InetBeginEnumeratePort+0x74
fffff880`030aa2c0 fffff880`01a1c3a2 : 00000000`0000003f 00000000`00000000 fffffa80`1f934f50 00000000`00000000 : tcpip!InetContinueEnumeratePortPool+0x93
fffff880`030aa320 fffff880`01a1c196 : 00000000`0000003f fffffa80`1dcce240 fffff880`030aa578 00000000`0000003f : tcpip!TcpEnumerateListeners+0x1c2
fffff880`030aa3c0 fffff880`0196fa5b : fffff880`01b740a0 fffffa80`1dccd000 fffff880`01b73758 fffffa80`1db31f40 : tcpip!TcpEnumerateConnectionType+0x106
fffff880`030aa410 fffff880`04d9be18 : fffffa80`1dccd000 00000000`00000070 00000000`00000001 fffff880`030aa750 : NETIO!NsiEnumerateObjectsAllParametersEx+0x24f
fffff880`030aa5f0 fffff880`04d9d9c2 : 00000000`024ff6c0 00000000`0000003c 00000000`00000000 fffffa80`223d6f18 : nsiproxy!NsippEnumerateObjectsAllParameters+0x300
fffff880`030aa7e0 fffff880`04d9db23 : 00000000`00000000 00000000`00000000 fffffa80`223d6fb0 fffffa80`223d6ee0 : nsiproxy!NsippDispatchDeviceControl+0xb6
fffff880`030aa820 fffff800`03302f8a : 00000000`00000002 fffffa80`1ee44920 fffffa80`1ee44920 fffffa80`223d6ee0 : nsiproxy!NsippDispatch+0x4b
fffff880`030aa850 fffff800`034da819 : fffffa80`1ee44920 fffffa80`1ee44920 fffffa80`1ee44920 fffff880`03316180 : nt!IopSynchronousServiceTail+0xfa
fffff880`030aa8c0 fffff800`0336cf86 : 00000000`00fbe318 00000000`000005e0 00000000`00000001 00000000`00000000 : nt!IopXxxControlFile+0xc49
fffff880`030aaa00 fffff800`030cd9d3 : fffffa80`1de37060 00000000`00fbe2b8 fffff880`030aaa88 00000000`00000001 : nt!NtDeviceIoControlFile+0x56
fffff880`030aaa70 00000000`74802e09 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`00fbebc8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x74802e09
STACK_COMMAND: kb
FOLLOWUP_IP:
NETIO!NsiEnumerateObjectsAllParametersEx+24f
fffff880`0196fa5b 8bd8 mov ebx,eax
SYMBOL_STACK_INDEX: a
SYMBOL_NAME: NETIO!NsiEnumerateObjectsAllParametersEx+24f
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: NETIO
IMAGE_NAME: NETIO.SYS
DEBUG_FLR_IMAGE_TIMESTAMP: 5b101559
FAILURE_BUCKET_ID: X64_0xD1_NETIO!NsiEnumerateObjectsAllParametersEx+24f
BUCKET_ID: X64_0xD1_NETIO!NsiEnumerateObjectsAllParametersEx+24f
Followup: MachineOwner
Any suggestions as I have tried a few things but am having no luck.
Several users have been getting BSOD recently in our office and the error appears to be the same:
DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: 000000000058000b, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, value 0 = read operation, 1 = write operation
Arg4: fffff88001a99c17, address which referenced memory
Debugging Details:
------------------
TRIAGER: Could not open triage file : e:\dump_analysis\program\triage\modclass.ini, error 2
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800032be100
GetUlongFromAddress: unable to read from fffff800032be1c8
000000000058000b Nonpaged pool
CURRENT_IRQL: 2
FAULTING_IP:
tcpip! ?? ::FNODOBFM::`string'+23d7
fffff880`01a99c17 488b4108 mov rax,qword ptr [rcx+8]
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
BUGCHECK_STR: 0xD1
PROCESS_NAME: LMS.exe
TRAP_FRAME: fffff880030aa040 -- (.trap 0xfffff880030aa040)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffffa8021ab79d0 rbx=0000000000000000 rcx=0000000000580003
rdx=fffffa801daadc02 rsi=0000000000000000 rdi=0000000000000000
rip=fffff88001a99c17 rsp=fffff880030aa1d8 rbp=fffffa800c9b4000
r8=fffff880030aa248 r9=fffff880030aa200 r10=fffffa8023978c30
r11=000000000000c00f r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
tcpip! ?? ::FNODOBFM::`string'+0x23d7:
fffff880`01a99c17 488b4108 mov rax,qword ptr [rcx+8] ds:00000000`0058000b=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff800030cdd69 to fffff800030bf8a0
STACK_TEXT:
fffff880`030a9ef8 fffff800`030cdd69 : 00000000`0000000a 00000000`0058000b 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
fffff880`030a9f00 fffff800`030cbb88 : 00000000`00000000 00000000`0058000b fffff880`030aa100 fffffa80`1f9e50f8 : nt!KiBugCheckDispatch+0x69
fffff880`030aa040 fffff880`01a99c17 : fffff880`01a97259 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiPageFault+0x448
fffff880`030aa1d8 fffff880`01a97259 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : tcpip! ?? ::FNODOBFM::`string'+0x23d7
fffff880`030aa1e0 fffff880`01a864c7 : 00000000`00000000 00000000`00000000 fffffa80`1daadcd0 fffffa80`0c9b4000 : tcpip!EnumerateEndpointInAssignment+0x59
fffff880`030aa220 fffff880`01a86114 : 00000000`00000000 fffffa80`0c9b4000 fffffa80`1f9e50f0 fffffa80`1daadcd0 : tcpip!EnumerateAndReferenceEndpointInAssignment+0x4b
fffff880`030aa260 fffff880`01a0c123 : 00000000`0000c00b 00000000`0000c00f fffffa80`0c9b4000 fffffa80`0c9b4000 : tcpip!InetBeginEnumeratePort+0x74
fffff880`030aa2c0 fffff880`01a1c3a2 : 00000000`0000003f 00000000`00000000 fffffa80`1f934f50 00000000`00000000 : tcpip!InetContinueEnumeratePortPool+0x93
fffff880`030aa320 fffff880`01a1c196 : 00000000`0000003f fffffa80`1dcce240 fffff880`030aa578 00000000`0000003f : tcpip!TcpEnumerateListeners+0x1c2
fffff880`030aa3c0 fffff880`0196fa5b : fffff880`01b740a0 fffffa80`1dccd000 fffff880`01b73758 fffffa80`1db31f40 : tcpip!TcpEnumerateConnectionType+0x106
fffff880`030aa410 fffff880`04d9be18 : fffffa80`1dccd000 00000000`00000070 00000000`00000001 fffff880`030aa750 : NETIO!NsiEnumerateObjectsAllParametersEx+0x24f
fffff880`030aa5f0 fffff880`04d9d9c2 : 00000000`024ff6c0 00000000`0000003c 00000000`00000000 fffffa80`223d6f18 : nsiproxy!NsippEnumerateObjectsAllParameters+0x300
fffff880`030aa7e0 fffff880`04d9db23 : 00000000`00000000 00000000`00000000 fffffa80`223d6fb0 fffffa80`223d6ee0 : nsiproxy!NsippDispatchDeviceControl+0xb6
fffff880`030aa820 fffff800`03302f8a : 00000000`00000002 fffffa80`1ee44920 fffffa80`1ee44920 fffffa80`223d6ee0 : nsiproxy!NsippDispatch+0x4b
fffff880`030aa850 fffff800`034da819 : fffffa80`1ee44920 fffffa80`1ee44920 fffffa80`1ee44920 fffff880`03316180 : nt!IopSynchronousServiceTail+0xfa
fffff880`030aa8c0 fffff800`0336cf86 : 00000000`00fbe318 00000000`000005e0 00000000`00000001 00000000`00000000 : nt!IopXxxControlFile+0xc49
fffff880`030aaa00 fffff800`030cd9d3 : fffffa80`1de37060 00000000`00fbe2b8 fffff880`030aaa88 00000000`00000001 : nt!NtDeviceIoControlFile+0x56
fffff880`030aaa70 00000000`74802e09 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`00fbebc8 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x74802e09
STACK_COMMAND: kb
FOLLOWUP_IP:
NETIO!NsiEnumerateObjectsAllParametersEx+24f
fffff880`0196fa5b 8bd8 mov ebx,eax
SYMBOL_STACK_INDEX: a
SYMBOL_NAME: NETIO!NsiEnumerateObjectsAllParametersEx+24f
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: NETIO
IMAGE_NAME: NETIO.SYS
DEBUG_FLR_IMAGE_TIMESTAMP: 5b101559
FAILURE_BUCKET_ID: X64_0xD1_NETIO!NsiEnumerateObjectsAllParametersEx+24f
BUCKET_ID: X64_0xD1_NETIO!NsiEnumerateObjectsAllParametersEx+24f
Followup: MachineOwner
Any suggestions as I have tried a few things but am having no luck.
My Computer
- Computer type
- PC/Desktop
- OS
- Windows 7 64 bit