*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck D1, {30, 2, 0, 8f0488a5}
Unable to load image \SystemRoot\system32\DRIVERS\athr.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for athr.sys
*** ERROR: Module load completed but symbols could not be loaded for athr.sys
Probably caused by : athr.sys ( athr+428a5 )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: 00000030, memory referenced
Arg2: 00000002, IRQL
Arg3: 00000000, value 0 = read operation, 1 = write operation
Arg4: 8f0488a5, address which referenced memory
Debugging Details:
------------------
READ_ADDRESS: GetPointerFromAddress: unable to read from 82dbb718
Unable to read MiSystemVaType memory at 82d9b160
00000030
CURRENT_IRQL: 2
FAULTING_IP:
athr+428a5
8f0488a5 8b5130 mov edx,dword ptr [ecx+30h]
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xD1
PROCESS_NAME: System
TRAP_FRAME: 8ad1c894 -- (.trap 0xffffffff8ad1c894)
ErrCode = 00000000
eax=0000001a ebx=87e3e258 ecx=00000000 edx=00000088 esi=00000000 edi=00000000
eip=8f0488a5 esp=8ad1c908 ebp=8ad1c90c iopl=0 nv up ei pl nz na po nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010202
athr+0x428a5:
8f0488a5 8b5130 mov edx,dword ptr [ecx+30h] ds:0023:00000030=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from 8f0488a5 to 82c9982b
STACK_TEXT:
8ad1c894 8f0488a5 badb0d00 00000088 00000001 nt!KiTrap0E+0x2cf
WARNING: Stack unwind information not available. Following frames may be wrong.
8ad1c90c 8f048647 00000000 c64a83cc ada5c490 athr+0x428a5
8ad1c944 8f047c52 885f6108 87bcdda8 00000000 athr+0x42647
8ad1c96c 8f06efc0 885f6028 87bcdda8 00000018 athr+0x41c52
8ad1c9c0 8f06f8c7 8792b020 87bcdda8 00000000 athr+0x68fc0
8ad1cb14 8f020cfe 87bcdda8 8ad1cb30 8f01dd2f athr+0x698c7
8ad1cb20 8f01dd2f 87bcdda8 879ff5f8 8ad1cb40 athr+0x1acfe
8ad1cb30 8f0659c7 879ff5f8 87bcdda8 8ad1cb68 athr+0x17d2f
8ad1cb40 8f0656b7 87b59628 87bcdda8 00000000 athr+0x5f9c7
8ad1cb68 8f01962a 87b59628 87bcdda8 00000000 athr+0x5f6b7
8ad1cb94 8f019414 879ff8c0 87bcdd20 87e3e258 athr+0x1362a
8ad1cbac 8f01a499 879ff8c0 883d6828 c642c0f0 athr+0x13414
8ad1cbc4 8f01a525 879ff8c0 8ad1cbdc 8f077554 athr+0x14499
8ad1cbd0 8f077554 879ff8c0 8ad1cbf8 8f07c1ff athr+0x14525
8ad1cbdc 8f07c1ff 87b56020 87e30022 8ad01a54 athr+0x71554
8ad1cbf8 8f020abd 87b56020 8ad1cc14 8f007761 athr+0x761ff
8ad1cc04 8f007761 8792b020 879ff8c0 8ad1cc50 athr+0x1aabd
8ad1cc14 88e7c309 879ff8c0 00000000 8ad1cc40 athr+0x1761
8ad1cc50 88e279f4 87e3e26c 00e3e258 00000000 ndis!ndisMiniportDpc+0xe2
8ad1cc78 82cbb3b5 87e3e26c 87e3e258 00000000 ndis!ndisInterruptDpc+0xaf
8ad1ccd4 82cbb218 8ad00120 8ad05800 00000000 nt!KiExecuteAllDpcs+0xf9
8ad1cd20 82cbb038 00000000 0000000e 00000000 nt!KiRetireDpcList+0xd5
8ad1cd24 00000000 0000000e 00000000 00000000 nt!KiIdleLoop+0x38
STACK_COMMAND: kb
FOLLOWUP_IP:
athr+428a5
8f0488a5 8b5130 mov edx,dword ptr [ecx+30h]
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: athr+428a5
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: athr
IMAGE_NAME: athr.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4a2ea444
FAILURE_BUCKET_ID: 0xD1_athr+428a5
BUCKET_ID: 0xD1_athr+428a5
Followup: MachineOwner
---------
2: kd> lmvm athr
start end module name
8f006000 8f116000 athr T (no symbols)
Loaded symbol image file: athr.sys
Image path: \SystemRoot\system32\DRIVERS\athr.sys
Image name: athr.sys
Timestamp: Tue Jun 09 11:04:52 2009 (4A2EA444)
CheckSum: 0011A043
ImageSize: 00110000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4