*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
[COLOR=Red]BugCheck D1[/COLOR], {4, 2, 0, 89e5db02}
Unable to load image \SystemRoot\system32\DRIVERS\athr.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for athr.sys
*** ERROR: Module load completed but symbols could not be loaded for athr.sys
[COLOR=Red]Probably caused by : athr.sys[/COLOR] ( athr+3a5c1 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: 00000004, memory referenced
Arg2: 00000002, IRQL
Arg3: 00000000, value 0 = read operation, 1 = write operation
Arg4: 89e5db02, address which referenced memory
Debugging Details:
------------------
READ_ADDRESS: GetPointerFromAddress: unable to read from 83f71718
Unable to read MiSystemVaType memory at 83f51160
00000004
CURRENT_IRQL: 2
FAULTING_IP:
ndis!NdisFreeTimerObject+18
89e5db02 8b4b04 mov ecx,dword ptr [ebx+4]
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
BUGCHECK_STR: 0xD1
PROCESS_NAME: System
ANALYSIS_VERSION: 6.3.9600.17237 (debuggers(dbg).140716-0327) amd64fre
TRAP_FRAME: 8bd03bac -- (.trap 0xffffffff8bd03bac)
ErrCode = 00000000
eax=00000000 ebx=00000000 ecx=89e69970 edx=87e8bc08 esi=86eaf028 edi=89e69970
eip=89e5db02 esp=8bd03c20 ebp=8bd03c2c iopl=0 nv up ei ng nz na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010286
ndis!NdisFreeTimerObject+0x18:
89e5db02 8b4b04 mov ecx,dword ptr [ebx+4] ds:0023:00000004=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from 89e5db02 to 83e4f7eb
STACK_TEXT:
8bd03bac 89e5db02 badb0d00 87e8bc08 8bd03bc8 nt!KiTrap0E+0x2cf
8bd03c2c 922705c1 00000000 8bd03c44 9225563f ndis!NdisFreeTimerObject+0x18
WARNING: Stack unwind information not available. Following frames may be wrong.
8bd03c38 9225563f 87e8bdd8 8bd03c50 9225acac athr+0x3a5c1
8bd03c44 9225acac 87e8bc08 8bd03c68 9225ac5f athr+0x1f63f
8bd03c50 9225ac5f 87e8bc08 c000009a 87e8bc08 athr+0x24cac
8bd03c68 9224d13e 87045750 8bd03c7c 00000001 athr+0x24c5f
8bd03c88 9224669c 87045750 00000001 8bd03ca0 athr+0x1713e
8bd03cc4 92246598 87045750 8bd2338c 87045750 athr+0x1069c
8bd03cdc 89e2830a 87045750 87002160 8bd03d00 athr+0x10598
8bd03cec 840297b5 86eaf028 87002160 85cf4d48 ndis!ndisDispatchIoWorkItem+0xf
8bd03d00 83e76f2b 87016828 00000000 85cf4d48 nt!IopProcessWorkItem+0x23
8bd03d50 8401766d 00000000 a89dc910 00000000 nt!ExpWorkerThread+0x10d
8bd03d90 83ec90d9 83e76e1e 00000000 00000000 nt!PspSystemThreadStartup+0x9e
00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x19
STACK_COMMAND: kb
FOLLOWUP_IP:
athr+3a5c1
922705c1 ?? ???
SYMBOL_STACK_INDEX: 2
[COLOR=Red]SYMBOL_NAME: athr+3a5c1[/COLOR]
FOLLOWUP_NAME: MachineOwner
[COLOR=Red]MODULE_NAME: athr[/COLOR]
[COLOR=Red]IMAGE_NAME: athr.sys[/COLOR]
DEBUG_FLR_IMAGE_TIMESTAMP: 4a2ea444
[COLOR=Red]FAILURE_BUCKET_ID: 0xD1_athr+3a5c1[/COLOR]
[COLOR=Red]BUCKET_ID: 0xD1_athr+3a5c1[/COLOR]
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0xd1_athr+3a5c1
FAILURE_ID_HASH: {6d282917-417f-44c5-95fd-299bd00232ad}
Followup: MachineOwner
---------
0: kd> lmvm athr
start end module name
92236000 92346000 athr T (no symbols)
Loaded symbol image file: athr.sys
Image path: \SystemRoot\system32\DRIVERS\athr.sys
[COLOR=Red] Image name: athr.sys
Timestamp: Tue Jun 09 23:34:52 2009[/COLOR] (4A2EA444)
CheckSum: 0011A043
ImageSize: 00110000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4