Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\K\Desktop\Windows_NT6_BSOD_jcgriff2\111310-26301-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\Symbols*http://msdl.microsoft.com/download/symbols;srv*e:\symbols
*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16385.x86fre.win7_rtm.090713-1255
Machine Name:
Kernel base = 0x8323e000 PsLoadedModuleList = 0x83386810
Debug session time: Sat Nov 13 11:54:48.310 2010 (GMT-5)
System Uptime: 0 days 0:50:33.980
Loading Kernel Symbols
...............................................................
................................................................
.....................................
Loading User Symbols
Loading unloaded module list
......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck D1, {5b7aa8a7, 2, 1, 9234e585}
Unable to load image \SystemRoot\system32\DRIVERS\HssDrv.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for HssDrv.sys
*** ERROR: Module load completed but symbols could not be loaded for HssDrv.sys
Probably caused by : HssDrv.sys ( HssDrv+4585 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: 5b7aa8a7, memory referenced
Arg2: 00000002, IRQL
Arg3: 00000001, value 0 = read operation, 1 = write operation
Arg4: 9234e585, address which referenced memory
Debugging Details:
------------------
WRITE_ADDRESS: GetPointerFromAddress: unable to read from 833a6718
Unable to read MiSystemVaType memory at 83386160
5b7aa8a7
CURRENT_IRQL: 2
FAULTING_IP:
HssDrv+4585
9234e585 897804 mov dword ptr [eax+4],edi
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xD1
PROCESS_NAME: System
TRAP_FRAME: 8336451c -- (.trap 0xffffffff8336451c)
ErrCode = 00000002
eax=5b7aa8a3 ebx=00000780 ecx=00000000 edx=878651c0 esi=92356200 edi=92356200
eip=9234e585 esp=83364590 ebp=8336459c iopl=0 nv up ei pl nz na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010206
HssDrv+0x4585:
9234e585 897804 mov dword ptr [eax+4],edi ds:0023:5b7aa8a7=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from 9234e585 to 832847eb
STACK_TEXT:
8336451c 9234e585 badb0d00 878651c0 8a1731f8 nt!KiTrap0E+0x2cf
WARNING: Stack unwind information not available. Following frames may be wrong.
8336459c 9234dddd 878651d4 85cd43e4 85cd43e4 HssDrv+0x4585
833645cc 9234b22b 00000042 8750af4c 00000000 HssDrv+0x3ddd
833645f8 9234b482 8750af4c 85cd43e4 00000082 HssDrv+0x122b
83364618 8bca84e5 87d991e0 83364660 00000001 HssDrv+0x1482
83364640 8bca830a 83364664 83364660 00000001 ndis!ndisMSendPacketsXToMiniport+0x142
833646a8 8bc4059d 878660e0 8612a8f0 00000000 ndis!ndisMSendNetBufferListsToPackets+0x84
833646c8 8bc40623 8612a8f0 8612a8f0 00000000 ndis!ndisFilterSendNetBufferLists+0x87
833646e0 904f9c20 88213058 8612a8f0 00000000 ndis!NdisFSendNetBufferLists+0x38
8336475c 8bc40474 859d5410 8612a8f0 00000000 pacer!PcFilterSendNetBufferLists+0x256
83364788 8bca4d8c 878660e0 8612a8f0 00000000 ndis!ndisSendNBLToFilter+0xf2
833647b8 8be9a03e 88fddaa8 8612a8f0 00000000 ndis!NdisSendNetBufferLists+0x162
83364804 8be9a7c1 88fdb278 00000000 00000000 tcpip!FlSendPackets+0x416
83364858 8be9a4d3 8bf1ad98 00000000 00000000 tcpip!IppFragmentPackets+0x2e2
83364890 8bea2273 8bf1ad98 87149d5c 87149df8 tcpip!IppDispatchSendPacketHelper+0x266
83364930 8bea830e 00149d5c 00000000 859815b0 tcpip!IppPacketizeDatagrams+0x8d6
833649b0 8bea8595 00000000 00000007 8bf1ad98 tcpip!IppSendDatagramsCommon+0x652
833649d0 8be891a0 8714fed8 833649ec 00000000 tcpip!IpNlpSendDatagrams+0x4b
83364aa0 8beb5151 891f9190 00000000 00000002 tcpip!TcpTcbHeaderSend+0x53a
83364aec 8beb4c42 00000000 83364bac 00000000 tcpip!TcpFlushDelay+0x257
83364b38 832a804d 8713ed38 00000000 7b39ecb1 tcpip!TcpPeriodicTimeoutHandler+0x389
83364b7c 832a7ff1 83367d20 83364ca8 00000001 nt!KiProcessTimerDpcTable+0x50
83364c68 832a7eae 83367d20 83364ca8 00000000 nt!KiProcessExpiredTimerList+0x101
83364cdc 832a620e 0002f7b4 861674c0 83371280 nt!KiTimerExpiration+0x25c
83364d20 832a6038 00000000 0000000e 00000000 nt!KiRetireDpcList+0xcb
83364d24 00000000 0000000e 00000000 00000000 nt!KiIdleLoop+0x38
STACK_COMMAND: kb
FOLLOWUP_IP:
HssDrv+4585
9234e585 897804 mov dword ptr [eax+4],edi
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: HssDrv+4585
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: HssDrv
IMAGE_NAME: HssDrv.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 498b603e
FAILURE_BUCKET_ID: 0xD1_HssDrv+4585
BUCKET_ID: 0xD1_HssDrv+4585
Followup: MachineOwner
---------