Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

BSOD - Aaaaaah?! IRQL_NOT_LESS_OR_EQUAL


  • Please log in to reply
No replies to this topic

#1 justjen

justjen

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:02:48 PM

Posted 24 April 2009 - 11:16 AM

Hey everyone. Bit of a newb here. I have had a custom built PC for a couple of weeks, and experimented with 64-bit Vista Ultimate, but had several issues with BSOD and flash issues in IE8, so decided to revert to x86 version of Vista Ultimate to see if the problems got any better. Well suffice to say I am getting them EVEN more. I am in the position where I can send the PC back, but want to get enough evidence of the problem to get the right component swapped out. I have installed WinDbg and fiddled around with the symbols, and finally got a readout which may be of use to someone who may be able to pinpoint my problems. Besides the BSOD, the PC decides to occasionally reset, which too is a little alarming. Here's the readout, and thanks in advance. Happy to tinker around with any suggestions ... -
Microsoft ® Windows Debugger Version 6.11.0001.404 X86
Copyright © Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Windows\MEMORY.DMP]
Kernel Summary Dump File: Only kernel address space is available

Symbol search path is: C:\Windows\Symbols
Executable search path is:
Windows Server 2008/Windows Vista Kernel Version 6001 (Service Pack 1) MP (4 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 6001.18000.x86fre.longhorn_rtm.080118-1840
Machine Name:
Kernel base = 0x8220e000 PsLoadedModuleList = 0x82325c70
Debug session time: Fri Apr 24 12:54:56.598 2009 (GMT+1)
System Uptime: 0 days 1:13:26.113
Loading Kernel Symbols
...............................................................
................................................................
...
Loading User Symbols
PEB is paged out (Peb.Ldr = 7ffda00c). Type ".hh dbgerr001" for details
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck A, {24, 2, 0, 8224347c}

Page 9be73 not present in the dump file. Type ".hh dbgerr004" for details
PEB is paged out (Peb.Ldr = 7ffda00c). Type ".hh dbgerr001" for details
PEB is paged out (Peb.Ldr = 7ffda00c). Type ".hh dbgerr001" for details
Probably caused by : memory_corruption ( nt!MiIdentifyPfn+649 )

Followup: MachineOwner
---------

3: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 00000024, memory referenced
Arg2: 00000002, IRQL
Arg3: 00000000, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: 8224347c, address which referenced memory

Debugging Details:
------------------

Page 9be73 not present in the dump file. Type ".hh dbgerr004" for details
PEB is paged out (Peb.Ldr = 7ffda00c). Type ".hh dbgerr001" for details
PEB is paged out (Peb.Ldr = 7ffda00c). Type ".hh dbgerr001" for details

READ_ADDRESS: 00000024

CURRENT_IRQL: 2

FAULTING_IP:
nt!MiIdentifyPfn+649
8224347c 8b4124 mov eax,dword ptr [ecx+24h]

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

BUGCHECK_STR: 0xA

PROCESS_NAME: svchost.exe

TRAP_FRAME: 987fd7e4 -- (.trap 0xffffffff987fd7e4)
ErrCode = 00000000
eax=00000400 ebx=85096530 ecx=00000000 edx=00000002 esi=873240b0 edi=0a000000
eip=8224347c esp=987fd858 ebp=987fd8b8 iopl=0 nv up ei pl nz na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010206
nt!MiIdentifyPfn+0x649:
8224347c 8b4124 mov eax,dword ptr [ecx+24h] ds:0023:00000024=????????
Resetting default scope

LAST_CONTROL_TRANSFER: from 8224347c to 82268d84

STACK_TEXT:
987fd7e4 8224347c badb0d00 00000002 822cb27c nt!KiTrap0E+0x2ac
987fd8b8 822a1d1d 987fd864 02096530 85096000 nt!MiIdentifyPfn+0x649
987fd8ec 82420a8f 85acfff6 987fd978 00000006 nt!MmQueryPfnList+0x130
987fd930 8243bb3e 8ad35101 85acff66 00000014 nt!PfpPfnPrioRequest+0xdc
987fd9a0 824470ca 00000000 8ad35101 987fdd30 nt!PfQuerySuperfetchInformation+0xea
987fdd4c 82265a7a 0000004f 016af390 00000014 nt!NtQuerySystemInformation+0x2201
987fdd4c 771d9a94 0000004f 016af390 00000014 nt!KiFastCallEntry+0x12a
WARNING: Frame IP not in any known module. Following frames may be wrong.
016af35c 00000000 00000000 00000000 00000000 0x771d9a94


STACK_COMMAND: kb

FOLLOWUP_IP:
nt!MiIdentifyPfn+649
8224347c 8b4124 mov eax,dword ptr [ecx+24h]

SYMBOL_STACK_INDEX: 1

SYMBOL_NAME: nt!MiIdentifyPfn+649

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: nt

DEBUG_FLR_IMAGE_TIMESTAMP: 47918b12

IMAGE_NAME: memory_corruption

FAILURE_BUCKET_ID: 0xA_nt!MiIdentifyPfn+649

BUCKET_ID: 0xA_nt!MiIdentifyPfn+649

Followup: MachineOwner
---------

3: kd> .trap 0xffffffff987fd7e4
ErrCode = 00000000
eax=00000400 ebx=85096530 ecx=00000000 edx=00000002 esi=873240b0 edi=0a000000
eip=8224347c esp=987fd858 ebp=987fd8b8 iopl=0 nv up ei pl nz na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010206
nt!MiIdentifyPfn+0x649:
8224347c 8b4124 mov eax,dword ptr [ecx+24h] ds:0023:00000024=????????

BC AdBot (Login to Remove)

 





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users