******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1) An attempt was made to access a pageable (or completely invalid) address at an interrupt request level (IRQL) that is too high. This is usually caused by drivers using improper addresses. If kernel debugger is available get stack backtrace. Arguments: Arg1: 00000000, memory referenced Arg2: 00000002, IRQL Arg3: 00000000, value 0 = read operation, 1 = write operation Arg4: 87001110, address which referenced memory Debugging Details: ------------------ READ_ADDRESS: GetPointerFromAddress: unable to read from 82db9718 Unable to read MiSystemVaType memory at 82d99160 00000000 CURRENT_IRQL: 2 FAULTING_IP: +63e72faf0351d980 87001110 ?? ??? CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT BUGCHECK_STR: 0xD1 PROCESS_NAME: rundll32.exe TRAP_FRAME: 8ed9ea0c -- (.trap 0xffffffff8ed9ea0c) ErrCode = 00000000 eax=00000000 ebx=853cc4a8 ecx=8ed9ea7c edx=00000000 esi=00000000 edi=853cc48c eip=87001110 esp=8ed9ea80 ebp=853cc4c4 iopl=0 nv up ei pl zr na pe nc cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010246 87001110 ?? ??? Resetting default scope LAST_CONTROL_TRANSFER: from 87001110 to 82c9782b STACK_TEXT: 8ed9ea0c 87001110 badb0d00 00000000 87008dc0 nt!KiTrap0E+0x2cf WARNING: Frame IP not in any known module. Following frames may be wrong. 8ed9ea7c 8ed9eb3c 8ed9eb64 8ed9eb64 8bf04008 0x87001110 8ed9eb14 82ed1187 85a59560 000015b4 8ed9eb64 0x8ed9eb3c 8ed9eb3c 82ea6bc6 85a59560 000015b4 82d91b04 nt!PsCallImageNotifyRoutines+0x62 8ed9ebe8 82ebf979 859e5450 f6fb6760 8ed9ece4 nt!MiMapViewOfImageSection+0x7fd 8ed9ec58 82ed0241 f6fb6760 8ed9ece4 00000000 nt!MiMapViewOfSection+0x22e 8ed9ec88 82ed016c b741e298 f6fb6760 8ed9ece4 nt!MmMapViewOfSection+0x2a 8ed9ed04 82c9444a 000002cc ffffffff 0007ce74 nt!NtMapViewOfSection+0x204 8ed9ed04 778a64f4 000002cc ffffffff 0007ce74 nt!KiFastCallEntry+0x12a 0007cf80 00000000 00000000 00000000 00000000 0x778a64f4 STACK_COMMAND: kb FOLLOWUP_IP: nt!KiTrap0E+2cf 82c9782b 833dc44adb8200 cmp dword ptr [nt!KiFreezeFlag (82db4ac4)],0 SYMBOL_STACK_INDEX: 0 SYMBOL_NAME: nt!KiTrap0E+2cf FOLLOWUP_NAME: MachineOwner MODULE_NAME: nt IMAGE_NAME: ntkrpamp.exe DEBUG_FLR_IMAGE_TIMESTAMP: 4c1c3fac FAILURE_BUCKET_ID: 0xD1_nt!KiTrap0E+2cf BUCKET_ID: 0xD1_nt!KiTrap0E+2cf Followup: MachineOwner ---------