*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck D1, {1c, 2, 1, 91cc38c5}
Unable to load image \SystemRoot\system32\DRIVERS\athr.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for athr.sys
*** ERROR: Module load completed but symbols could not be loaded for athr.sys
Probably caused by : athr.sys ( athr+c18c5 )
Followup: MachineOwner
---------
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: 0000001c, memory referenced
Arg2: 00000002, IRQL
Arg3: 00000001, value 0 = read operation, 1 = write operation
Arg4: 91cc38c5, address which referenced memory
Debugging Details:
------------------
WRITE_ADDRESS: GetPointerFromAddress: unable to read from 82d69718
Unable to read MiSystemVaType memory at 82d49160
0000001c
CURRENT_IRQL: 2
FAULTING_IP:
athr+c18c5
91cc38c5 c7401c00000000 mov dword ptr [eax+1Ch],0
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xD1
PROCESS_NAME: System
TRAP_FRAME: b68a9b2c -- (.trap 0xffffffffb68a9b2c)
ErrCode = 00000002
eax=00000000 ebx=82d3b580 ecx=00000000 edx=870f8020 esi=00000040 edi=868b0c28
eip=91cc38c5 esp=b68a9ba0 ebp=b68a9ba8 iopl=0 nv up ei pl zr na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00210246
athr+0xc18c5:
91cc38c5 c7401c00000000 mov dword ptr [eax+1Ch],0 ds:0023:0000001c=????????
Resetting default scope
LAST_CONTROL_TRANSFER: from 91cc38c5 to 82c4781b
STACK_TEXT:
b68a9b2c 91cc38c5 badb0d00 870f8020 870f8020 nt!KiTrap0E+0x2cf
WARNING: Stack unwind information not available. Following frames may be wrong.
b68a9ba8 91cbdb2a 870f8020 870f6000 b68a9bcc athr+0xc18c5
b68a9bf8 91c7efd8 870f8020 00000001 870f6000 athr+0xbbb2a
b68a9c38 91c76704 870f4020 86c8d020 b68a9c6c athr+0x7cfd8
b68a9c48 91c38d40 86c8d020 868b0c28 00000040 athr+0x74704
b68a9c6c 91c048b8 8af8e028 b68a9ca8 00000000 athr+0x36d40
b68a9c88 91c07892 870e7028 b68a9ca8 8af79748 athr+0x28b8
b68a9cdc 8b31330a 8af79748 86b486b8 b68a9d00 athr+0x5892
b68a9cec 82e21b25 86cd0028 86b486b8 85cfed48 ndis!ndisDispatchIoWorkItem+0xf
b68a9d00 82c6f03b 868b0c28 00000000 85cfed48 nt!IopProcessWorkItem+0x23
b68a9d50 82e0f9df 80000000 8cfcfa25 00000000 nt!ExpWorkerThread+0x10d
b68a9d90 82cc11d9 82c6ef2e 80000000 00000000 nt!PspSystemThreadStartup+0x9e
00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x19
STACK_COMMAND: kb
FOLLOWUP_IP:
athr+c18c5
91cc38c5 c7401c00000000 mov dword ptr [eax+1Ch],0
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: athr+c18c5
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: athr
IMAGE_NAME: athr.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4aca1f74
FAILURE_BUCKET_ID: 0xD1_athr+c18c5
BUCKET_ID: 0xD1_athr+c18c5
Followup: MachineOwner