Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\K\Desktop\072110-21824-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*C:\symbols*http://msdl.microsoft.com/download/symbols;srv*e:\symbols
*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16385.amd64fre.win7_rtm.090713-1255
Machine Name:
Kernel base = 0xfffff800`03017000 PsLoadedModuleList = 0xfffff800`03254e50
Debug session time: Wed Jul 21 03:31:48.252 2010 (GMT-4)
System Uptime: 0 days 0:08:23.250
Loading Kernel Symbols
.
Press ctrl-c (cdb, kd, ntsd) or ctrl-break (windbg) to abort symbol loads that take too long.
Run !sym noisy before .reload to track down problems loading symbols.
..............................................................
................................................................
.......................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck D1, {28, 2, 0, fffff880014c5c1e}
Unable to load image \SystemRoot\system32\DRIVERS\L1E60x64.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for L1E60x64.sys
*** ERROR: Module load completed but symbols could not be loaded for L1E60x64.sys
Unable to load image \SystemRoot\system32\drivers\afwcore.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for afwcore.sys
*** ERROR: Module load completed but symbols could not be loaded for afwcore.sys
Probably caused by : L1E60x64.sys ( L1E60x64+6fa8 )
Followup: MachineOwner
---------
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: 0000000000000028, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, value 0 = read operation, 1 = write operation
Arg4: fffff880014c5c1e, address which referenced memory
Debugging Details:
------------------
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800032bf0e0
0000000000000028
CURRENT_IRQL: 2
FAULTING_IP:
ndis! ?? ::FNODOBFM::`string'+14dd
fffff880`014c5c1e 8b4728 mov eax,dword ptr [rdi+28h]
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xD1
PROCESS_NAME: uTorrent.exe
TRAP_FRAME: fffff880065c6600 -- (.trap 0xfffff880065c6600)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=0000000000000036
rdx=fffffa800a33e030 rsi=0000000000000000 rdi=0000000000000000
rip=fffff880014c5c1e rsp=fffff880065c6790 rbp=fffffa800bb0b2a0
r8=fffffa800bf4a570 r9=0000000000000001 r10=0000000000000000
r11=fffffa800750e1a0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na po nc
ndis! ?? ::FNODOBFM::`string'+0x14dd:
fffff880`014c5c1e 8b4728 mov eax,dword ptr [rdi+28h] ds:7820:00000000`00000028=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80003088469 to fffff80003088f00
STACK_TEXT:
fffff880`065c64b8 fffff800`03088469 : 00000000`0000000a 00000000`00000028 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
fffff880`065c64c0 fffff800`030870e0 : fffffa80`0bf4a518 fffffa80`0a33e030 fffffa80`0bf71ff0 00000000`00000000 : nt!KiBugCheckDispatch+0x69
fffff880`065c6600 fffff880`014c5c1e : fffffa80`0a12e640 fffffa80`0bb0b2a0 00000000`000000a0 00000000`00000000 : nt!KiPageFault+0x260
fffff880`065c6790 fffff880`06194fa8 : fffffa80`0750e1a0 fffff880`03ea16fc fffffa80`0bf4a570 fffffa80`0bb0b2a0 : ndis! ?? ::FNODOBFM::`string'+0x14dd
fffff880`065c6830 fffffa80`0750e1a0 : fffff880`03ea16fc fffffa80`0bf4a570 fffffa80`0bb0b2a0 fffffa80`0bf72180 : L1E60x64+0x6fa8
fffff880`065c6838 fffff880`03ea16fc : fffffa80`0bf4a570 fffffa80`0bb0b2a0 fffffa80`0bf72180 fffffa80`000001c0 : 0xfffffa80`0750e1a0
fffff880`065c6840 fffffa80`0bf4a570 : fffffa80`0bb0b2a0 fffffa80`0bf72180 fffffa80`000001c0 00000000`00000000 : afwcore+0x3b6fc
fffff880`065c6848 fffffa80`0bb0b2a0 : fffffa80`0bf72180 fffffa80`000001c0 00000000`00000000 00000000`00000000 : 0xfffffa80`0bf4a570
fffff880`065c6850 fffffa80`0bf72180 : fffffa80`000001c0 00000000`00000000 00000000`00000000 00000000`00000000 : 0xfffffa80`0bb0b2a0
fffff880`065c6858 fffffa80`000001c0 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0xfffffa80`0bf72180
fffff880`065c6860 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 fffffa80`0c9717c0 : 0xfffffa80`000001c0
STACK_COMMAND: kb
FOLLOWUP_IP:
L1E60x64+6fa8
fffff880`06194fa8 ?? ???
SYMBOL_STACK_INDEX: 4
SYMBOL_NAME: L1E60x64+6fa8
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: L1E60x64
IMAGE_NAME: L1E60x64.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4869eab8
FAILURE_BUCKET_ID: X64_0xD1_L1E60x64+6fa8
BUCKET_ID: X64_0xD1_L1E60x64+6fa8
Followup: MachineOwner
---------