*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck D1, {0, 2, 8, 0}
*** WARNING: Unable to verify timestamp for e1d62x64.sys
*** ERROR: Module load completed but symbols could not be loaded for e1d62x64.sys
Probably caused by : e1d62x64.sys ( e1d62x64+254d3 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: 0000000000000000, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000008, value 0 = read operation, 1 = write operation
Arg4: 0000000000000000, address which referenced memory
Debugging Details:
------------------
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800036c0100
GetUlongFromAddress: unable to read from fffff800036c01c0
0000000000000000 Nonpaged pool
CURRENT_IRQL: 2
FAULTING_IP:
+34cd690
00000000`00000000 ?? ???
PROCESS_NAME: System
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT
BUGCHECK_STR: 0xD1
ANALYSIS_VERSION: 6.3.9600.16384 (debuggers(dbg).130821-1623) amd64fre
TRAP_FRAME: fffff880063eb600 -- (.trap 0xfffff880063eb600)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=0000000000000000
rdx=fffffa8007cf8340 rsi=0000000000000000 rdi=0000000000000000
rip=0000000000000000 rsp=fffff880063eb798 rbp=fffffa8007cf8340
r8=0000000000000000 r9=0000000000000001 r10=0000000000000000
r11=fffffa800795a000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl nz na po cy
00000000`00000000 ?? ???
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80003488169 to fffff80003488bc0
FAILED_INSTRUCTION_ADDRESS:
+34cd690
00000000`00000000 ?? ???
STACK_TEXT:
fffff880`063eb798 fffff880`0151b0a7 : fffffa80`075a01a0 00000000`00000002 00000000`00000003 00000000`00000000 : 0x0
fffff880`063eb7a0 fffff880`02d2a4d3 : fffffa80`0795a000 00000000`00000001 fffffa80`07cf8340 fffffa80`0795adc0 : ndis! ?? ::FNODOBFM::`string'+0xcd8f
fffff880`063eb7f0 fffffa80`0795a000 : 00000000`00000001 fffffa80`07cf8340 fffffa80`0795adc0 00000000`00000801 : e1d62x64+0x254d3
fffff880`063eb7f8 00000000`00000001 : fffffa80`07cf8340 fffffa80`0795adc0 00000000`00000801 00000000`00000001 : 0xfffffa80`0795a000
fffff880`063eb800 fffffa80`07cf8340 : fffffa80`0795adc0 00000000`00000801 00000000`00000001 00000000`00000001 : 0x1
fffff880`063eb808 fffffa80`0795adc0 : 00000000`00000801 00000000`00000001 00000000`00000001 fffff880`02d2a6a1 : 0xfffffa80`07cf8340
fffff880`063eb810 00000000`00000801 : 00000000`00000001 00000000`00000001 fffff880`02d2a6a1 00000000`00000001 : 0xfffffa80`0795adc0
fffff880`063eb818 00000000`00000001 : 00000000`00000001 fffff880`02d2a6a1 00000000`00000001 fffffa80`07cf8340 : 0x801
fffff880`063eb820 00000000`00000001 : fffff880`02d2a6a1 00000000`00000001 fffffa80`07cf8340 fffffa80`07cf8340 : 0x1
fffff880`063eb828 fffff880`02d2a6a1 : 00000000`00000001 fffffa80`07cf8340 fffffa80`07cf8340 fffffa80`0795a000 : 0x1
fffff880`063eb830 00000000`00000001 : fffffa80`07cf8340 fffffa80`07cf8340 fffffa80`0795a000 fffffa80`00000000 : e1d62x64+0x256a1
fffff880`063eb838 fffffa80`07cf8340 : fffffa80`07cf8340 fffffa80`0795a000 fffffa80`00000000 fffff800`0348be53 : 0x1
fffff880`063eb840 fffffa80`07cf8340 : fffffa80`0795a000 fffffa80`00000000 fffff800`0348be53 0000000a`00000001 : 0xfffffa80`07cf8340
fffff880`063eb848 fffffa80`0795a000 : fffffa80`00000000 fffff800`0348be53 0000000a`00000001 00000000`00000000 : 0xfffffa80`07cf8340
fffff880`063eb850 fffffa80`00000000 : fffff800`0348be53 0000000a`00000001 00000000`00000000 00000000`00000000 : 0xfffffa80`0795a000
fffff880`063eb858 fffff800`0348be53 : 0000000a`00000001 00000000`00000000 00000000`00000000 fffff880`063ebad8 : 0xfffffa80`00000000
fffff880`063eb860 00000000`00000000 : fffffa80`0795a040 fffff880`02d1d941 fffffa80`0795a000 00000000`00000000 : nt!SwapContext_PatchXSave+0xa3
STACK_COMMAND: .trap 0xfffff880063eb600 ; kb
FOLLOWUP_IP:
e1d62x64+254d3
fffff880`02d2a4d3 ?? ???
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: e1d62x64+254d3
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: e1d62x64
IMAGE_NAME: e1d62x64.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 510011be
FAILURE_BUCKET_ID: X64_0xD1_CODE_AV_NULL_IP_e1d62x64+254d3
BUCKET_ID: X64_0xD1_CODE_AV_NULL_IP_e1d62x64+254d3
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:x64_0xd1_code_av_null_ip_e1d62x64+254d3
FAILURE_ID_HASH: {ce516679-e802-c4a6-4644-02b7de80f5d2}
Followup: MachineOwner
---------
0: kd> lmvm e1d62x64
start end module name
fffff880`02d05000 fffff880`02d80000 e1d62x64 T (no symbols)
Loaded symbol image file: e1d62x64.sys
Image path: \SystemRoot\system32\DRIVERS\e1d62x64.sys
Image name: e1d62x64.sys
Timestamp: Wed Jan 23 22:07:18 2013 (510011BE)
CheckSum: 0007EAF6
ImageSize: 0007B000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4