*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck D1, {28, 2, 0, fffff8800172eb2d}
Probably caused by : NETIO.SYS ( NETIO!RtlCopyBufferToMdl+1d )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: 0000000000000028, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, value 0 = read operation, 1 = write operation
Arg4: fffff8800172eb2d, address which referenced memory
Debugging Details:
------------------
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80003ac9100
GetUlongFromAddress: unable to read from fffff80003ac91c0
0000000000000028 Nonpaged pool
CURRENT_IRQL: 2
FAULTING_IP:
NETIO!RtlCopyBufferToMdl+1d
fffff880`0172eb2d 448b5228 mov r10d,dword ptr [rdx+28h]
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
BUGCHECK_STR: 0xD1
PROCESS_NAME: System
TRAP_FRAME: fffff880033ae6f0 -- (.trap 0xfffff880033ae6f0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffff880033ae910 rbx=0000000000000000 rcx=0000000000000000
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=fffff8800172eb2d rsp=fffff880033ae880 rbp=fffff880033ae9b0
r8=00000000ffffffbc r9=0000000000000044 r10=0000000000000000
r11=fffffa8006ea1b90 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
NETIO!RtlCopyBufferToMdl+0x1d:
fffff880`0172eb2d 448b5228 mov r10d,dword ptr [rdx+28h] ds:00000000`00000028=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80003899569 to fffff80003899fc0
STACK_TEXT:
fffff880`033ae5a8 fffff800`03899569 : 00000000`0000000a 00000000`00000028 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
fffff880`033ae5b0 fffff800`038981e0 : 00000000`000009ab 00000000`00000000 00000000`00000001 00000000`00000044 : nt!KiBugCheckDispatch+0x69
fffff880`033ae6f0 fffff880`0172eb2d : 00000000`00000096 fffff880`0181a1cc 00000000`0000000a fffffa80`09720f58 : nt!KiPageFault+0x260
fffff880`033ae880 fffff880`018a70cc : 00000000`00000000 fffff880`018756b6 00000000`00000001 00000000`00000000 : NETIO!RtlCopyBufferToMdl+0x1d
fffff880`033ae8e0 fffff880`01872ca3 : fffffa80`06ea1b90 00000000`00000001 fffffa80`04b90010 00000000`00000000 : tcpip! ?? ::FNODOBFM::`string'+0x1d1ef
fffff880`033ae950 fffff880`01865a84 : fffff880`033aee08 00000000`00000029 fffffa80`04b90010 00000000`00000000 : tcpip!TcpTcbCarefulDatagram+0x543
fffff880`033aeb00 fffff880`018643aa : fffffa80`068d23a0 fffff880`0185d294 fffffa80`04afe1f0 00000000`00000000 : tcpip!TcpTcbReceive+0x694
fffff880`033aecb0 fffff880`01865fdb : fffff880`06354068 fffffa80`068c5000 00000000`00000000 fffff880`033af000 : tcpip!TcpMatchReceive+0x1fa
fffff880`033aee00 fffff880`0185d927 : fffffa80`068d23a0 fffffa80`04b25bc5 fffffa80`0000f881 00000000`0000f881 : tcpip!TcpPreValidatedReceive+0x36b
fffff880`033aeed0 fffff880`0185d49a : 00000000`00000000 fffff880`01971800 fffff880`033af090 fffffa80`0a2758b0 : tcpip!IppDeliverListToProtocol+0x97
fffff880`033aef90 fffff880`0185ca99 : fffff880`033af158 00000000`00000000 fffff880`033af058 fffff880`033af080 : tcpip!IppProcessDeliverList+0x5a
fffff880`033af030 fffff880`0185a7ff : 00000000`00000000 00000000`07468400 fffff880`01971800 fffff880`01971800 : tcpip!IppReceiveHeaderBatch+0x23a
fffff880`033af110 fffff880`01859df2 : fffffa80`073d48b0 00000000`00000000 fffffa80`07468400 00000000`00000001 : tcpip!IpFlcReceivePackets+0x64f
fffff880`033af310 fffff880`018d22ea : fffffa80`00000000 fffffa80`0a2758b0 fffffa80`074684a0 fffff880`033af400 : tcpip!FlpReceiveNonPreValidatedNetBufferListChain+0x2b2
fffff880`033af3f0 fffff800`038a5c48 : fffffa80`0a2758b0 fffffa80`04b3190c fffffa80`03fd7b50 00000000`00000001 : tcpip! ?? ::FNODOBFM::`string'+0x52f02
fffff880`033af440 fffff880`01859952 : fffff880`018591b0 00000000`00000014 00000000`00000000 fffffa80`04cbea01 : nt!KeExpandKernelStackAndCalloutEx+0xd8
fffff880`033af520 fffff880`016e90eb : fffffa80`0746b010 00000000`00000000 fffffa80`06fe21a0 00000000`00000000 : tcpip!FlReceiveNetBufferListChain+0xb2
fffff880`033af590 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ndis!ndisMIndicateNetBufferListsToOpen+0xdb
STACK_COMMAND: kb
FOLLOWUP_IP:
NETIO!RtlCopyBufferToMdl+1d
fffff880`0172eb2d 448b5228 mov r10d,dword ptr [rdx+28h]
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: NETIO!RtlCopyBufferToMdl+1d
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: NETIO
IMAGE_NAME: NETIO.SYS
DEBUG_FLR_IMAGE_TIMESTAMP: 4ce79381
FAILURE_BUCKET_ID: X64_0xD1_NETIO!RtlCopyBufferToMdl+1d
BUCKET_ID: X64_0xD1_NETIO!RtlCopyBufferToMdl+1d
Followup: MachineOwner
---------