*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck D1, {ffffea00336f264a, 2, 0, fffff88001b3f6d6}
Probably caused by : hardware ( NETIO!StreamInjectReceiveToStack+96 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: ffffea00336f264a, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, value 0 = read operation, 1 = write operation
Arg4: fffff88001b3f6d6, address which referenced memory
Debugging Details:
------------------
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800030cb100
GetUlongFromAddress: unable to read from fffff800030cb1c0
ffffea00336f264a Nonpaged pool
CURRENT_IRQL: 2
FAULTING_IP:
afd!AfdIndicateEventSelectEvent+6
fffff880`01b3f6d6 d8448bca fadd dword ptr [rbx+rcx*4-36h]
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
BUGCHECK_STR: 0xD1
PROCESS_NAME: [COLOR=red]AvastSvc.exe[/COLOR]
ANALYSIS_VERSION: 6.3.9600.17298 (debuggers(dbg).141024-1500) amd64fre
DPC_STACK_BASE: FFFFF80000BA0FB0
TRAP_FRAME: fffff80000ba0640 -- (.trap 0xfffff80000ba0640)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=fffffa800cdbc9a0
rdx=0000000000000001 rsi=0000000000000000 rdi=0000000000000000
rip=fffff88001b3f6d6 rsp=fffff80000ba07d8 rbp=0000000000000000
r8=0000000000000000 r9=00000000000003e8 r10=0000000000000000
r11=fffff88001b5b820 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na pe nc
afd!AfdIndicateEventSelectEvent+0x6:
fffff880`01b3f6d6 d8448bca fadd dword ptr [rbx+rcx*4-36h] ds:ffffea00`336f264a=????????
Resetting default scope
MISALIGNED_IP:
afd!AfdIndicateEventSelectEvent+6
fffff880`01b3f6d6 d8448bca fadd dword ptr [rbx+rcx*4-36h]
LAST_CONTROL_TRANSFER: from fffff80002e8de69 to fffff80002e8e8c0
STACK_TEXT:
fffff800`00ba04f8 fffff800`02e8de69 : 00000000`0000000a ffffea00`336f264a 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
fffff800`00ba0500 fffff800`02e8cae0 : fffffa80`0a0951a0 00000000`00000002 fffffa80`0a095f68 00000000`00000000 : nt!KiBugCheckDispatch+0x69
fffff800`00ba0640 fffff880`01b3f6d6 : ffffffff`ffffff8b fffff800`00ba0980 00000000`0000106e 00000000`0000000c : nt!KiPageFault+0x260
fffff800`00ba07d8 fffffa80`0c82ee00 : fffff880`01b82336 00000000`00000000 fffffa80`0726af50 fffffa80`0cdbc9a0 : afd!AfdIndicateEventSelectEvent+0x6
fffff800`00ba0808 fffff880`01b82336 : 00000000`00000000 fffffa80`0726af50 fffffa80`0cdbc9a0 00000000`00000000 : 0xfffffa80`0c82ee00
fffff800`00ba0810 fffff880`01865f44 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : afd!AfdBCommonChainedReceiveEventHandler+0x406
fffff800`00ba0950 fffff880`018656a7 : 00000000`00000000 fffffa80`0b7a6a78 fffffa80`0b7a6a78 00000000`00000000 : tcpip!TcpIndicateData+0x104
fffff800`00ba0a50 fffff880`018640a7 : 00000000`00000000 fffff880`04608d0f 00000000`00000000 fffffa80`00000003 : tcpip!TcpDeliverDataToClient+0x2b7
fffff800`00ba0bd0 fffff880`01933c0f : fffffa80`0726ae00 fffffa80`0cadf420 fffffa80`0cadf420 ffffffff`ffffef92 : tcpip!TcpDeliverReceive+0xa7
fffff800`00ba0cd0 fffff880`01933f48 : fffff880`009f1f40 fffffa80`07d93c10 00000000`00000000 fffffa80`0abe4e80 : tcpip!TcpInjectReceive+0x30f
fffff800`00ba0dc0 fffff880`017a8ee6 : fffffa80`07d93c10 fffffa80`07d93c10 fffffa80`0cadf420 fffffa80`0cadf420 : tcpip!InetInspectInjectReceive+0x38
fffff800`00ba0e00 fffff880`017aef67 : fffffa80`07d93c10 fffffa80`0726ae20 fffffa80`0726ae20 fffffa80`07d93c10 : NETIO!StreamInjectReceiveToStack+0x96
fffff800`00ba0e60 fffff880`017b06b4 : fffffa80`07d93c10 00000000`00000000 fffffa80`07d93c10 00000000`00000000 : NETIO!StreamPermitDataHelper+0x67
fffff800`00ba0e90 fffff800`02e9a1dc : fffff800`0300de80 fffffa80`0abe4e80 fffffa80`0abe4e80 00000000`00000000 : NETIO!StreamPermitRemoveDataDpc+0x84
fffff800`00ba0f00 fffff800`02e91335 : 00000000`00000000 fffffa80`0bb14b50 00000000`00000000 fffff880`017b0630 : nt!KiRetireDpcList+0x1bc
fffff800`00ba0fb0 fffff800`02e9114c : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KyRetireDpcList+0x5
fffff880`0ad3fd80 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDispatchInterruptContinue
STACK_COMMAND: kb
FOLLOWUP_IP:
NETIO!StreamInjectReceiveToStack+96
fffff880`017a8ee6 488b0d6ba40100 mov rcx,qword ptr [NETIO!WPP_GLOBAL_Control (fffff880`017c3358)]
SYMBOL_STACK_INDEX: b
SYMBOL_NAME: NETIO!StreamInjectReceiveToStack+96
FOLLOWUP_NAME: MachineOwner
IMAGE_NAME: hardware
DEBUG_FLR_IMAGE_TIMESTAMP: 0
IMAGE_VERSION: 6.1.7601.18327
MODULE_NAME: hardware
FAILURE_BUCKET_ID: X64_IP_MISALIGNED
BUCKET_ID: X64_IP_MISALIGNED
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:x64_ip_misaligned
FAILURE_ID_HASH: {45769616-fd06-8c70-4b8b-74a01eddc0cd}
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: ffffea00336f264a, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, value 0 = read operation, 1 = write operation
Arg4: fffff88001b3f6d6, address which referenced memory
Debugging Details:
------------------
READ_ADDRESS: ffffea00336f264a Nonpaged pool
CURRENT_IRQL: 2
FAULTING_IP:
afd!AfdIndicateEventSelectEvent+6
fffff880`01b3f6d6 d8448bca fadd dword ptr [rbx+rcx*4-36h]
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
BUGCHECK_STR: 0xD1
PROCESS_NAME: [COLOR=red]AvastSvc.exe[/COLOR]
ANALYSIS_VERSION: 6.3.9600.17298 (debuggers(dbg).141024-1500) amd64fre
DPC_STACK_BASE: FFFFF80000BA0FB0
TRAP_FRAME: fffff80000ba0640 -- (.trap 0xfffff80000ba0640)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=fffffa800cdbc9a0
rdx=0000000000000001 rsi=0000000000000000 rdi=0000000000000000
rip=fffff88001b3f6d6 rsp=fffff80000ba07d8 rbp=0000000000000000
r8=0000000000000000 r9=00000000000003e8 r10=0000000000000000
r11=fffff88001b5b820 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na pe nc
afd!AfdIndicateEventSelectEvent+0x6:
fffff880`01b3f6d6 d8448bca fadd dword ptr [rbx+rcx*4-36h] ds:ffffea00`336f264a=????????
Resetting default scope
MISALIGNED_IP:
afd!AfdIndicateEventSelectEvent+6
fffff880`01b3f6d6 d8448bca fadd dword ptr [rbx+rcx*4-36h]
LAST_CONTROL_TRANSFER: from fffff80002e8de69 to fffff80002e8e8c0
STACK_TEXT:
fffff800`00ba04f8 fffff800`02e8de69 : 00000000`0000000a ffffea00`336f264a 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
fffff800`00ba0500 fffff800`02e8cae0 : fffffa80`0a0951a0 00000000`00000002 fffffa80`0a095f68 00000000`00000000 : nt!KiBugCheckDispatch+0x69
fffff800`00ba0640 fffff880`01b3f6d6 : ffffffff`ffffff8b fffff800`00ba0980 00000000`0000106e 00000000`0000000c : nt!KiPageFault+0x260
fffff800`00ba07d8 fffffa80`0c82ee00 : fffff880`01b82336 00000000`00000000 fffffa80`0726af50 fffffa80`0cdbc9a0 : afd!AfdIndicateEventSelectEvent+0x6
fffff800`00ba0808 fffff880`01b82336 : 00000000`00000000 fffffa80`0726af50 fffffa80`0cdbc9a0 00000000`00000000 : 0xfffffa80`0c82ee00
fffff800`00ba0810 fffff880`01865f44 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : afd!AfdBCommonChainedReceiveEventHandler+0x406
fffff800`00ba0950 fffff880`018656a7 : 00000000`00000000 fffffa80`0b7a6a78 fffffa80`0b7a6a78 00000000`00000000 : tcpip!TcpIndicateData+0x104
fffff800`00ba0a50 fffff880`018640a7 : 00000000`00000000 fffff880`04608d0f 00000000`00000000 fffffa80`00000003 : tcpip!TcpDeliverDataToClient+0x2b7
fffff800`00ba0bd0 fffff880`01933c0f : fffffa80`0726ae00 fffffa80`0cadf420 fffffa80`0cadf420 ffffffff`ffffef92 : tcpip!TcpDeliverReceive+0xa7
fffff800`00ba0cd0 fffff880`01933f48 : fffff880`009f1f40 fffffa80`07d93c10 00000000`00000000 fffffa80`0abe4e80 : tcpip!TcpInjectReceive+0x30f
fffff800`00ba0dc0 fffff880`017a8ee6 : fffffa80`07d93c10 fffffa80`07d93c10 fffffa80`0cadf420 fffffa80`0cadf420 : tcpip!InetInspectInjectReceive+0x38
fffff800`00ba0e00 fffff880`017aef67 : fffffa80`07d93c10 fffffa80`0726ae20 fffffa80`0726ae20 fffffa80`07d93c10 : NETIO!StreamInjectReceiveToStack+0x96
fffff800`00ba0e60 fffff880`017b06b4 : fffffa80`07d93c10 00000000`00000000 fffffa80`07d93c10 00000000`00000000 : NETIO!StreamPermitDataHelper+0x67
fffff800`00ba0e90 fffff800`02e9a1dc : fffff800`0300de80 fffffa80`0abe4e80 fffffa80`0abe4e80 00000000`00000000 : NETIO!StreamPermitRemoveDataDpc+0x84
fffff800`00ba0f00 fffff800`02e91335 : 00000000`00000000 fffffa80`0bb14b50 00000000`00000000 fffff880`017b0630 : nt!KiRetireDpcList+0x1bc
fffff800`00ba0fb0 fffff800`02e9114c : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KyRetireDpcList+0x5
fffff880`0ad3fd80 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiDispatchInterruptContinue
STACK_COMMAND: kb
FOLLOWUP_IP:
NETIO!StreamInjectReceiveToStack+96
fffff880`017a8ee6 488b0d6ba40100 mov rcx,qword ptr [NETIO!WPP_GLOBAL_Control (fffff880`017c3358)]
SYMBOL_STACK_INDEX: b
SYMBOL_NAME: NETIO!StreamInjectReceiveToStack+96
FOLLOWUP_NAME: MachineOwner
IMAGE_NAME: hardware
DEBUG_FLR_IMAGE_TIMESTAMP: 0
IMAGE_VERSION: 6.1.7601.18327
MODULE_NAME: hardware
FAILURE_BUCKET_[COLOR=red]ID: X64_IP_MISALIGNED[/COLOR]
BUCKET_ID: [COLOR=red]X64_IP_MISALIGNED[/COLOR]
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:x64_ip_misaligned
FAILURE_ID_HASH: {45769616-fd06-8c70-4b8b-74a01eddc0cd}
Followup: MachineOwner
---------