BSOD IRQL_NOT_LESS_OR_EQUAL

Permalänk
Medlem

BSOD IRQL_NOT_LESS_OR_EQUAL

Hejsan alla sweclockers. Jag har nu fått min "första" bluescreen efter att min flickvän har fått ett flertal bluescreens. Jag vet faktiskt inte vad som är fel längre... Jag använder windows 7 64 bit (giltig såklart) och har testat att installera om hennes dator också. Det är hela tiden samma fil enligt ett program som heter BlueScreenView. ntoskrnl.exe. Den är en av orsakerna till varje BSOD som vi har fått. Jag lägger med min dump fil och så slänger jag med min flickväns senaste dump fil så blir jag överlycklig om jag kan få lite klarhet i detta!

http://www.mediafire.com/?byzi7wqaadjn25c

http://www.mediafire.com/?4b237ojo4jghma3

Fick slänga upp dem på mediafire.

Tacksam för svar!

/Christoffer

Permalänk
Vila i frid

122810-22183-01.dmp - antingen sunkiga ram-minnen eller så är det logiska fel på disken som en CHKDISK fixar

1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

NTFS_FILE_SYSTEM (24)
If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
parameters are the exception record and context record. Do a .cxr
on the 3rd parameter and then kb to obtain a more informative stack
trace.
Arguments:
Arg1: 00000000001904fb
Arg2: fffff880086f3758
Arg3: fffff880086f2fc0
Arg4: fffff880014999ab

Debugging Details:
------------------

EXCEPTION_RECORD: fffff880086f3758 -- (.exr 0xfffff880086f3758)
ExceptionAddress: fffff880014999ab (Ntfs!NtfsFullDeleteLcb+0x00000000000000bb)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff

CONTEXT: fffff880086f2fc0 -- (.cxr 0xfffff880086f2fc0)
rax=ffbff8a00925c030 rbx=fffff880086f3a08 rcx=fffff8a00925c030
rdx=0000000000000001 rsi=0000000000000000 rdi=fffff8a00925c438
rip=fffff880014999ab rsp=fffff880086f3990 rbp=0000000000000000
r8=fffffa8005972de8 r9=0000000000000000 r10=fffff80002c4c000
r11=0000000000000001 r12=fffff8a00925c010 r13=fffff8a0093acbc0
r14=fffff8a00925c300 r15=0000000000000000
iopl=0 nv up ei ng nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010286
Ntfs!NtfsFullDeleteLcb+0xbb:
fffff880`014999ab 488908 mov qword ptr [rax],rcx ds:002b:ffbff8a0`0925c030=????????????????
Resetting default scope

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

PROCESS_NAME: System

CURRENT_IRQL: 1

ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

EXCEPTION_PARAMETER1: 0000000000000000

EXCEPTION_PARAMETER2: ffffffffffffffff

READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002ef40e0
ffffffffffffffff

FOLLOWUP_IP:
Ntfs!NtfsFullDeleteLcb+bb
fffff880`014999ab 488908 mov qword ptr [rax],rcx

FAULTING_IP:
Ntfs!NtfsFullDeleteLcb+bb
fffff880`014999ab 488908 mov qword ptr [rax],rcx

BUGCHECK_STR: 0x24

LAST_CONTROL_TRANSFER: from fffff8800140bea9 to fffff880014999ab

STACK_TEXT:
fffff880`086f3990 fffff880`0140bea9 : fffff8a0`0925c010 fffff800`02e615a0 fffff880`086f3b01 fffff880`014988d5 : Ntfs!NtfsFullDeleteLcb+0xbb
fffff880`086f39c0 fffff880`014962cc : fffffa80`061fd460 fffffa80`062cd180 fffff8a0`0925c010 fffff8a0`0925c3a8 : Ntfs!NtfsTeardownFromLcb+0x129
fffff880`086f3a50 fffff880`01414882 : fffffa80`061fd460 fffffa80`061fd460 fffff8a0`0925c010 fffff880`086f3c00 : Ntfs!NtfsTeardownStructures+0xcc
fffff880`086f3ad0 fffff880`014ad813 : fffffa80`062cd180 fffff800`02e615a0 fffff8a0`6366744e 00000000`00000009 : Ntfs!NtfsDecrementCloseCounts+0xa2
fffff880`086f3b10 fffff880`0148738f : fffffa80`061fd460 fffff8a0`0925c140 fffff8a0`0925c010 fffffa80`062cd180 : Ntfs!NtfsCommonClose+0x353
fffff880`086f3be0 fffff800`02cc9961 : 00000000`00000000 fffff880`01487200 fffffa80`089f0601 00000000`00000002 : Ntfs!NtfsFspClose+0x15f
fffff880`086f3cb0 fffff800`02f60c06 : 00000000`05762776 fffffa80`089f0690 00000000`00000080 fffffa80`0520bb30 : nt!ExpWorkerThread+0x111
fffff880`086f3d40 fffff800`02c9ac26 : fffff880`009e9180 fffffa80`089f0690 fffffa80`082eeb60 fffff880`01411534 : nt!PspSystemThreadStartup+0x5a
fffff880`086f3d80 00000000`00000000 : fffff880`086f4000 fffff880`086ee000 fffff880`086f39f0 00000000`00000000 : nt!KxStartSystemThread+0x16

SYMBOL_STACK_INDEX: 0

SYMBOL_NAME: Ntfs!NtfsFullDeleteLcb+bb

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: Ntfs

IMAGE_NAME: Ntfs.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc14f

STACK_COMMAND: .cxr 0xfffff880086f2fc0 ; kb

FAILURE_BUCKET_ID: X64_0x24_Ntfs!NtfsFullDeleteLcb+bb

BUCKET_ID: X64_0x24_Ntfs!NtfsFullDeleteLcb+bb

Dold text

122910-25334-01.dmp - det är förmodligen NORTON som buggar, avinstallera skiten

0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 0000000000000008, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff800033f67f7, address which referenced memory

Debugging Details:
------------------

OVERLAPPED_MODULE: Address regions for 'EX64' and 'ENG64.SYS' overlap

READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800030be0e0
0000000000000008

CURRENT_IRQL: 2

FAULTING_IP:
hal!HalPutScatterGatherList+a7
fffff800`033f67f7 4d8b642408 mov r12,qword ptr [r12+8]

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

BUGCHECK_STR: 0xA

PROCESS_NAME: System

TRAP_FRAME: fffff8800a6e48a0 -- (.trap 0xfffff8800a6e48a0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=0000000000000002
rdx=0000000000000fff rsi=0000000000000000 rdi=0000000000000000
rip=fffff800033f67f7 rsp=fffff8800a6e4a30 rbp=0000000000000e38
r8=fffffa8004f0b340 r9=00000000169fde38 r10=0000000000000000
r11=000000000000fffb r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
hal!HalPutScatterGatherList+0xa7:
fffff800`033f67f7 4d8b642408 mov r12,qword ptr [r12+8] ds:f9b0:00000000`00000008=????????????????
Resetting default scope

LAST_CONTROL_TRANSFER: from fffff80002e85ca9 to fffff80002e86740

STACK_TEXT:
fffff880`0a6e4758 fffff800`02e85ca9 : 00000000`0000000a 00000000`00000008 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
fffff880`0a6e4760 fffff800`02e84920 : fffff880`0a6e49e0 fffffa80`07714fc8 00000000`00000000 fffff880`0a6e49e0 : nt!KiBugCheckDispatch+0x69
fffff880`0a6e48a0 fffff800`033f67f7 : fffffa80`07714fc8 00000000`169fde38 00000000`000005b4 fffffa80`08831cf0 : nt!KiPageFault+0x260
fffff880`0a6e4a30 fffff880`016e58a1 : fffffa80`098c76f0 fffffa80`077025e0 fffffa80`09821030 00000000`00000000 : hal!HalPutScatterGatherList+0xa7
fffff880`0a6e4a90 fffff880`10d8b751 : fffffa80`07702000 fffffa80`09821030 fffffa80`07702000 00000000`00000000 : ndis!NdisMFreeNetBufferSGList+0x31
fffff880`0a6e4ad0 00000000`00000000 : fffffa80`073491a0 fffffa80`07cab168 00000000`00000000 fffff880`0171c9e0 : Rt64win7!MpHandleRecvIntPriVLanJumboSeventh+0x56d

STACK_COMMAND: kb

FOLLOWUP_IP:
Rt64win7!MpHandleRecvIntPriVLanJumboSeventh+56d
fffff880`10d8b751 ?? ???

SYMBOL_STACK_INDEX: 5

SYMBOL_NAME: Rt64win7!MpHandleRecvIntPriVLanJumboSeventh+56d

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: Rt64win7

IMAGE_NAME: Rt64win7.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 4c21cf95

FAILURE_BUCKET_ID: X64_0xA_Rt64win7!MpHandleRecvIntPriVLanJumboSeventh+56d

BUCKET_ID: X64_0xA_Rt64win7!MpHandleRecvIntPriVLanJumboSeventh+56d

Dold text
Permalänk
Medlem
Skrivet av hasenfrasen:

122810-22183-01.dmp - antingen sunkiga ram-minnen eller så är det logiska fel på disken som en CHKDISK fixar

1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

NTFS_FILE_SYSTEM (24)
If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
parameters are the exception record and context record. Do a .cxr
on the 3rd parameter and then kb to obtain a more informative stack
trace.
Arguments:
Arg1: 00000000001904fb
Arg2: fffff880086f3758
Arg3: fffff880086f2fc0
Arg4: fffff880014999ab

Debugging Details:
------------------

EXCEPTION_RECORD: fffff880086f3758 -- (.exr 0xfffff880086f3758)
ExceptionAddress: fffff880014999ab (Ntfs!NtfsFullDeleteLcb+0x00000000000000bb)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: ffffffffffffffff
Attempt to read from address ffffffffffffffff

CONTEXT: fffff880086f2fc0 -- (.cxr 0xfffff880086f2fc0)
rax=ffbff8a00925c030 rbx=fffff880086f3a08 rcx=fffff8a00925c030
rdx=0000000000000001 rsi=0000000000000000 rdi=fffff8a00925c438
rip=fffff880014999ab rsp=fffff880086f3990 rbp=0000000000000000
r8=fffffa8005972de8 r9=0000000000000000 r10=fffff80002c4c000
r11=0000000000000001 r12=fffff8a00925c010 r13=fffff8a0093acbc0
r14=fffff8a00925c300 r15=0000000000000000
iopl=0 nv up ei ng nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010286
Ntfs!NtfsFullDeleteLcb+0xbb:
fffff880`014999ab 488908 mov qword ptr [rax],rcx ds:002b:ffbff8a0`0925c030=????????????????
Resetting default scope

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

PROCESS_NAME: System

CURRENT_IRQL: 1

ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

EXCEPTION_PARAMETER1: 0000000000000000

EXCEPTION_PARAMETER2: ffffffffffffffff

READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002ef40e0
ffffffffffffffff

FOLLOWUP_IP:
Ntfs!NtfsFullDeleteLcb+bb
fffff880`014999ab 488908 mov qword ptr [rax],rcx

FAULTING_IP:
Ntfs!NtfsFullDeleteLcb+bb
fffff880`014999ab 488908 mov qword ptr [rax],rcx

BUGCHECK_STR: 0x24

LAST_CONTROL_TRANSFER: from fffff8800140bea9 to fffff880014999ab

STACK_TEXT:
fffff880`086f3990 fffff880`0140bea9 : fffff8a0`0925c010 fffff800`02e615a0 fffff880`086f3b01 fffff880`014988d5 : Ntfs!NtfsFullDeleteLcb+0xbb
fffff880`086f39c0 fffff880`014962cc : fffffa80`061fd460 fffffa80`062cd180 fffff8a0`0925c010 fffff8a0`0925c3a8 : Ntfs!NtfsTeardownFromLcb+0x129
fffff880`086f3a50 fffff880`01414882 : fffffa80`061fd460 fffffa80`061fd460 fffff8a0`0925c010 fffff880`086f3c00 : Ntfs!NtfsTeardownStructures+0xcc
fffff880`086f3ad0 fffff880`014ad813 : fffffa80`062cd180 fffff800`02e615a0 fffff8a0`6366744e 00000000`00000009 : Ntfs!NtfsDecrementCloseCounts+0xa2
fffff880`086f3b10 fffff880`0148738f : fffffa80`061fd460 fffff8a0`0925c140 fffff8a0`0925c010 fffffa80`062cd180 : Ntfs!NtfsCommonClose+0x353
fffff880`086f3be0 fffff800`02cc9961 : 00000000`00000000 fffff880`01487200 fffffa80`089f0601 00000000`00000002 : Ntfs!NtfsFspClose+0x15f
fffff880`086f3cb0 fffff800`02f60c06 : 00000000`05762776 fffffa80`089f0690 00000000`00000080 fffffa80`0520bb30 : nt!ExpWorkerThread+0x111
fffff880`086f3d40 fffff800`02c9ac26 : fffff880`009e9180 fffffa80`089f0690 fffffa80`082eeb60 fffff880`01411534 : nt!PspSystemThreadStartup+0x5a
fffff880`086f3d80 00000000`00000000 : fffff880`086f4000 fffff880`086ee000 fffff880`086f39f0 00000000`00000000 : nt!KxStartSystemThread+0x16

SYMBOL_STACK_INDEX: 0

SYMBOL_NAME: Ntfs!NtfsFullDeleteLcb+bb

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: Ntfs

IMAGE_NAME: Ntfs.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc14f

STACK_COMMAND: .cxr 0xfffff880086f2fc0 ; kb

FAILURE_BUCKET_ID: X64_0x24_Ntfs!NtfsFullDeleteLcb+bb

BUCKET_ID: X64_0x24_Ntfs!NtfsFullDeleteLcb+bb

Dold text

Det skumma är att det är ganska nya delar. Vi har dragit chkdsk och den har reparerat så fint osv. Får väl testa o plocka ur ram minne efter ram minne o se vilket som felar.

Citat:

122910-25334-01.dmp - det är förmodligen NORTON som buggar, avinstallera skiten

0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 0000000000000008, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff800033f67f7, address which referenced memory

Debugging Details:
------------------

OVERLAPPED_MODULE: Address regions for 'EX64' and 'ENG64.SYS' overlap

READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800030be0e0
0000000000000008

CURRENT_IRQL: 2

FAULTING_IP:
hal!HalPutScatterGatherList+a7
fffff800`033f67f7 4d8b642408 mov r12,qword ptr [r12+8]

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

BUGCHECK_STR: 0xA

PROCESS_NAME: System

TRAP_FRAME: fffff8800a6e48a0 -- (.trap 0xfffff8800a6e48a0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000000 rbx=0000000000000000 rcx=0000000000000002
rdx=0000000000000fff rsi=0000000000000000 rdi=0000000000000000
rip=fffff800033f67f7 rsp=fffff8800a6e4a30 rbp=0000000000000e38
r8=fffffa8004f0b340 r9=00000000169fde38 r10=0000000000000000
r11=000000000000fffb r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
hal!HalPutScatterGatherList+0xa7:
fffff800`033f67f7 4d8b642408 mov r12,qword ptr [r12+8] ds:f9b0:00000000`00000008=????????????????
Resetting default scope

LAST_CONTROL_TRANSFER: from fffff80002e85ca9 to fffff80002e86740

STACK_TEXT:
fffff880`0a6e4758 fffff800`02e85ca9 : 00000000`0000000a 00000000`00000008 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
fffff880`0a6e4760 fffff800`02e84920 : fffff880`0a6e49e0 fffffa80`07714fc8 00000000`00000000 fffff880`0a6e49e0 : nt!KiBugCheckDispatch+0x69
fffff880`0a6e48a0 fffff800`033f67f7 : fffffa80`07714fc8 00000000`169fde38 00000000`000005b4 fffffa80`08831cf0 : nt!KiPageFault+0x260
fffff880`0a6e4a30 fffff880`016e58a1 : fffffa80`098c76f0 fffffa80`077025e0 fffffa80`09821030 00000000`00000000 : hal!HalPutScatterGatherList+0xa7
fffff880`0a6e4a90 fffff880`10d8b751 : fffffa80`07702000 fffffa80`09821030 fffffa80`07702000 00000000`00000000 : ndis!NdisMFreeNetBufferSGList+0x31
fffff880`0a6e4ad0 00000000`00000000 : fffffa80`073491a0 fffffa80`07cab168 00000000`00000000 fffff880`0171c9e0 : Rt64win7!MpHandleRecvIntPriVLanJumboSeventh+0x56d

STACK_COMMAND: kb

FOLLOWUP_IP:
Rt64win7!MpHandleRecvIntPriVLanJumboSeventh+56d
fffff880`10d8b751 ?? ???

SYMBOL_STACK_INDEX: 5

SYMBOL_NAME: Rt64win7!MpHandleRecvIntPriVLanJumboSeventh+56d

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: Rt64win7

IMAGE_NAME: Rt64win7.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 4c21cf95

FAILURE_BUCKET_ID: X64_0xA_Rt64win7!MpHandleRecvIntPriVLanJumboSeventh+56d

BUCKET_ID: X64_0xA_Rt64win7!MpHandleRecvIntPriVLanJumboSeventh+56d

Dold text

Hur kan du se att det är norton som felar? Och det är konstigt för att min bror som rekomenderade norton (jobbar med datorer osv) säljer det till flera kunder och ingen har några problem med det. Han har inte heller påträffat några problem. Eftersom du skrev antagligen norton som felar, ser du något mer som kan vara orsaken?

Permalänk

Jag hade samma problem förut, fick bluescreen jätteofta, några gånger i veckan.
Vad som löste det, vet jag inte. Men jag har inte fått det längre.
Det stod samma sak (IRQL_NOT_LESS_OR_EQUAL), när jag läste om det på nätet, så fick jag för mig att det var grafikkortet...

Jag TROR att det slutade när jag bytte moderkort...

Visa signatur

My name is legion, for we are many.

Permalänk

Det verkar handla om IRQ, vilket betyder vilken enhet i datorn som hellst, utom chipset, nätagg och processor. Har du 2st ljudkort t.ex? eller nätverkskort?

Visa signatur

Pappy :"Backup: Skyddar mot datafel när du på fyllan raderar 200GB pr0n och laddar hem två säsonger teletubbies istället."
Jocke1100 :"Det är väl en mekanisk kylavledning... Typ analog kylpasta..."

Permalänk
Medlem
Skrivet av fille3002:

Det verkar handla om IRQ, vilket betyder vilken enhet i datorn som hellst, utom chipset, nätagg och processor. Har du 2st ljudkort t.ex? eller nätverkskort?

allt som sitter i datorn är följande:

PSU corsair TX 650W

AMD Phenom2 X4 965 @3.4ghz

Asus M4A77T (moderkort)

A-Data 6 GB Extreme Vitesta

HD500GB Western Digital

Gigabyte GF GTX 460 1GB

DVD/RW Samsung 22X DL

Aerocool S-55 (Chassi)

TFT BenQ 24" E2420HD

dvs inga "dubbla" av någonting och ljud + nätverk körs via moderkortet.

Permalänk
Vila i frid
Skrivet av Zabuko:

Hur kan du se att det är norton som felar?

OVERLAPPED_MODULE: Address regions for 'EX64' and 'ENG64.SYS' overlap

Båda drivarna är Norton. Avast och Avira är gratis - och bra.
http://www.av-comparatives.org/images/stories/test/ondret/avc...

Permalänk
Medlem
Skrivet av hasenfrasen:

OVERLAPPED_MODULE: Address regions for 'EX64' and 'ENG64.SYS' overlap

Båda drivarna är Norton. Avast och Avira är gratis - och bra.
http://www.av-comparatives.org/images/stories/test/ondret/avc...

I länken testar de dock Norton antivirus. Jag har Norton Internet Security 2011. Men jag ska kolla lite på det .Tack så hjärtligt för hjälpen