Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\K\Desktop\020110-17472-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*d:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
[B]Built by: 7600.16385.amd64fre.win7_rtm.090713-1255[/B]
Machine Name:
Kernel base = 0xfffff800`02c0e000 PsLoadedModuleList = 0xfffff800`02e4be50
Debug session time: Mon Feb 1 10:44:44.707 2010 (GMT-5)
System Uptime: 0 days 0:37:44.299
Loading Kernel Symbols
...............................................................
................................................................
............................
Loading User Symbols
Loading unloaded module list
.......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
[B]
BugCheck D1, {fffffab7cc1d97a8, 2, 0, fffff88003f64ca8}
Unable to load image \SystemRoot\system32\DRIVERS\e1e6032e.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for e1e6032e.sys
*** ERROR: Module load completed but symbols could not be loaded for e1e6032e.sys[/B]
[B][U][I]Probably caused by : e1e603[/I][/U]2e.sys ( e1e6032e+6ca8 )[/B]
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
[B]DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.[/B]
Arguments:
Arg1: fffffab7cc1d97a8, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, value 0 = read operation, 1 = write operation
Arg4: fffff88003f64ca8, address which referenced memory
Debugging Details:
------------------
READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002eb60e0
fffffab7cc1d97a8
CURRENT_IRQL: 2
FAULTING_IP:
e1e6032e+6ca8
fffff880`03f64ca8 498b4210 mov rax,qword ptr [r10+10h]
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xD1
PROCESS_NAME: System
TRAP_FRAME: fffff80000b9c8e0 -- (.trap 0xfffff80000b9c8e0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=00000037c7c7c790 rbx=0000000000000000 rcx=fffffa800455d000
rdx=0000000000028063 rsi=0000000000000000 rdi=0000000000000000
rip=fffff88003f64ca8 rsp=fffff80000b9ca70 rbp=fffffa80043ba000
r8=0000000000000001 r9=0000000000000001 r10=fffffab7cc1d9798
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
e1e6032e+0x6ca8:
fffff880`03f64ca8 498b4210 mov rax,qword ptr [r10+10h] ds:fffffab7`cc1d97a8=????????????????
Resetting default scope
LAST_CONTROL_TRANSFER: from fffff80002c7f469 to fffff80002c7ff00
STACK_TEXT:
fffff800`00b9c798 fffff800`02c7f469 : 00000000`0000000a fffffab7`cc1d97a8 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
fffff800`00b9c7a0 fffff800`02c7e0e0 : 00000000`00000004 fffffa80`04279028 00000000`00000004 fffffa80`033066a8 : nt!KiBugCheckDispatch+0x69
fffff800`00b9c8e0 fffff880`03f64ca8 : 00000000`00000000 fffffa80`04251800 00000000`00000000 fffffa80`04251c00 : nt!KiPageFault+0x260
fffff800`00b9ca70 00000000`00000000 : fffffa80`04251800 00000000`00000000 fffffa80`04251c00 fffffa80`00000001 : e1e6032e+0x6ca8
STACK_COMMAND: kb
FOLLOWUP_IP:
e1e6032e+6ca8
fffff880`03f64ca8 498b4210 mov rax,qword ptr [r10+10h]
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: e1e6032e+6ca8
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: e1e6032e
IMAGE_NAME: [B]e1e6032e.sys[/B]
DEBUG_FLR_IMAGE_TIMESTAMP: 49c923b3
FAILURE_BUCKET_ID: X64_0xD1_e1e6032e+6ca8
BUCKET_ID: X64_0xD1_e1e6032e+6ca8
Followup: MachineOwner
---------