Strugling to detect cause of BSOD

Associate
Joined
8 Nov 2008
Posts
2,140
Location
UK
About 1 month ago I did a complete new instillation of windows 7 64bit and added a new sound card. Since then I have been getting random BSOD. I took the sound card out and replaced with my old one (That worked fine)and did a new instillation of windows to prevent driver problems.

Yet the BSOD is still occurring. I remembered updating my gpu drivers about the same time so i uninstalled with driver cleaner ect and reinstalled older ones that I had no problems with. Yet the BSOD is still persisting. I have checked all wiring inside the pc and that is fine.

Due to the randomness of the BSOD I cannot duplicate it and so far have failed to get the error codes but have managed to get crash dump file.

080111-15802-01.dmp (284.94 KB)http://www.multiupload.com/FTYUJVC26X

Any help would be welcome thanks.
 
Here are the results of the bugcheck:

Code:
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high.  This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: fffffa7f98253570, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, value 0 = read operation, 1 = write operation
Arg4: fffff880014d51b6, address which referenced memory

Debugging Details:
------------------


READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002ef8100
 fffffa7f98253570 

CURRENT_IRQL:  2

FAULTING_IP: 
ndis!ndisReferenceTopMiniportByNameForNsi+f6
fffff880`014d51b6 488b93d0130000  mov     rdx,qword ptr [rbx+13D0h]

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

BUGCHECK_STR:  0xD1

PROCESS_NAME:  svchost.exe

TRAP_FRAME:  fffff88006c432d0 -- (.trap 0xfffff88006c432d0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000002 rbx=0000000000000000 rcx=fffffa8007b00808
rdx=0000000000000002 rsi=0000000000000000 rdi=0000000000000000
rip=fffff880014d51b6 rsp=fffff88006c43460 rbp=0000000000000002
 r8=0000000000000000  r9=0000000000000000 r10=0074006c00610065
r11=0000000000000002 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei ng nz na po nc
ndis!ndisReferenceTopMiniportByNameForNsi+0xf6:
fffff880`014d51b6 488b93d0130000  mov     rdx,qword ptr [rbx+13D0h] ds:01a0:00000000`000013d0=????????????????
Resetting default scope

LAST_CONTROL_TRANSFER:  from fffff80002cc82a9 to fffff80002cc8d00

STACK_TEXT:  
fffff880`06c43188 fffff800`02cc82a9 : 00000000`0000000a fffffa7f`98253570 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
fffff880`06c43190 fffff800`02cc6f20 : 006c0075`00640065 0030002d`00720065 00000030`00300030 fffffa80`082521a0 : nt!KiBugCheckDispatch+0x69
fffff880`06c432d0 fffff880`014d51b6 : fffffa80`07b00808 fffff880`014d006c 00000000`80200020 fffffa80`08b7a301 : nt!KiPageFault+0x260
fffff880`06c43460 fffff880`014d6c77 : fffffa80`08b7a338 fffffa80`079cc100 fffffa80`079cc202 fffffa80`08b7de00 : ndis!ndisReferenceTopMiniportByNameForNsi+0xf6
fffff880`06c434e0 fffff880`01403aab : 00000000`00000000 fffffa80`00000008 00000000`00000290 fffffa80`00000238 : ndis!ndisNsiEnumerateAllInterfaceInformation+0x248
fffff880`06c435d0 fffff880`03edde29 : fffffa80`08b79000 fffff8a0`00000070 fffffa80`06b7c230 00000000`0599ef10 : NETIO!NsiEnumerateObjectsAllParametersEx+0x24f
fffff880`06c437b0 fffff880`03edf8e8 : fffffa80`06b7c230 fffffa80`06b7c160 00000000`00000003 fffffa80`06b7c198 : nsiproxy!NsippEnumerateObjectsAllParameters+0x305
fffff880`06c439a0 fffff880`03edf9db : fffffa80`07850920 00000000`00000000 00000000`00000001 00000000`00000003 : nsiproxy!NsippDispatchDeviceControl+0x70
fffff880`06c439e0 fffff800`02fe3127 : fffffa80`098dc550 fffffa80`098dc550 fffffa80`06b7c278 fffffa80`06b7c160 : nsiproxy!NsippDispatch+0x4b
fffff880`06c43a10 fffff800`02fe3986 : 00000000`0599ed90 00000000`000002c0 00000000`00000000 00000000`00000000 : nt!IopXxxControlFile+0x607
fffff880`06c43b40 fffff800`02cc7f93 : fffffa80`08131b60 00000000`0599ed78 fffff880`06c43bc8 00000000`00000001 : nt!NtDeviceIoControlFile+0x56
fffff880`06c43bb0 00000000`7774138a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0599ee08 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7774138a


STACK_COMMAND:  kb

FOLLOWUP_IP: 
NETIO!NsiEnumerateObjectsAllParametersEx+24f
fffff880`01403aab 8bd8            mov     ebx,eax

SYMBOL_STACK_INDEX:  5

SYMBOL_NAME:  NETIO!NsiEnumerateObjectsAllParametersEx+24f

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: NETIO

IMAGE_NAME:  NETIO.SYS

DEBUG_FLR_IMAGE_TIMESTAMP:  4ce79381

FAILURE_BUCKET_ID:  X64_0xD1_NETIO!NsiEnumerateObjectsAllParametersEx+24f

BUCKET_ID:  X64_0xD1_NETIO!NsiEnumerateObjectsAllParametersEx+24f

Followup: MachineOwner
---------

0: kd> lmvm NETIO
start             end                 module name
fffff880`01400000 fffff880`01460000   NETIO      (pdb symbols)          c:\windows\symbols\netio.pdb\DD06DDC1DE2F426D85400E127C2DF49A2\netio.pdb
    Loaded symbol image file: NETIO.SYS
    Mapped memory image file: c:\Windows\Symbols\NETIO.SYS\4CE7938160000\NETIO.SYS
    Image path: \SystemRoot\system32\drivers\NETIO.SYS
    Image name: NETIO.SYS
    Timestamp:        Sat Nov 20 04:23:13 2010 (4CE79381)
    CheckSum:         00066D17
    ImageSize:        00060000
    File version:     6.1.7601.17514
    Product version:  6.1.7601.17514
    File flags:       0 (Mask 3F)
    File OS:          40004 NT Win32
    File type:        3.6 Driver
    File date:        00000000.00000000
    Translations:     0409.04b0
    CompanyName:      Microsoft Corporation
    ProductName:      Microsoft® Windows® Operating System
    InternalName:     netio.sys
    OriginalFilename: netio.sys
    ProductVersion:   6.1.7601.17514
    FileVersion:      6.1.7601.17514 (win7sp1_rtm.101119-1850)
    FileDescription:  Network I/O Subsystem
    LegalCopyright:   © Microsoft Corporation. All rights reserved.

Looked it up at Microsoft, seems like it might be a conflict with a 32-bit driver for ZoneAlarm or one of the Symantec applications. Do any of those apply to you?

http://answers.microsoft.com/en-us/...netiosys/c35935ae-f6d2-455f-8304-9dfcd6422528

I hope that helps.
 
Here are the results of the bugcheck:
Looked it up at Microsoft, seems like it might be a conflict with a 32-bit driver for ZoneAlarm or one of the Symantec applications. Do any of those apply to you?

http://answers.microsoft.com/en-us/...netiosys/c35935ae-f6d2-455f-8304-9dfcd6422528

I hope that helps.

No sadly :( i use nothing made by them. Due to it seemingly being net related I have rolled back the nic driver and Disable NetBIOS over TCP/IP to see if that helps.
 
Last edited:
As with any BSOD, especially random ones, it's worth checking the memory.

Also, when you say new installation of W7 64bit, was this a reinstall or did you upgrade from something like XP or Vista?
 
Ok last night I noticed that my system was still overclokced (thought had undone the overclock when the bsod started must have forgotten to save settings.) Anyways I removed the overclock and see how it goes before try anything else.
 
Code:
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high.  This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: fffff88003274434, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000008, value 0 = read operation, 1 = write operation
Arg4: fffff88003274434, address which referenced memory

Debugging Details:
------------------


READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002f00100
 fffff88003274434 

CURRENT_IRQL:  2

FAULTING_IP: 
+55e2952f02fede18
fffff880`03274434 ??              ???

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

BUGCHECK_STR:  0xD1

PROCESS_NAME:  System

TRAP_FRAME:  fffff88002ffdaa0 -- (.trap 0xfffff88002ffdaa0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=fffffa8008c43c20 rbx=0000000000000000 rcx=fffffa8008c6a890
rdx=0000000043787254 rsi=0000000000000000 rdi=0000000000000000
rip=fffff88003274434 rsp=fffff88002ffdc38 rbp=0000000000000000
 r8=0000000043787254  r9=00000000ffffffff r10=fffffa800798d1a0
r11=fffffa800798d1a0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei ng nz na po nc
fffff880`03274434 ??              ???
Resetting default scope

LAST_CONTROL_TRANSFER:  from fffff80002cd02a9 to fffff80002cd0d00

FAILED_INSTRUCTION_ADDRESS: 
+55e2952f02fede18
fffff880`03274434 ??              ???

STACK_TEXT:  
fffff880`02ffd958 fffff800`02cd02a9 : 00000000`0000000a fffff880`03274434 00000000`00000002 00000000`00000008 : nt!KeBugCheckEx
fffff880`02ffd960 fffff800`02ccef20 : fffffa80`098fd040 fffff800`02c0d156 fffffa80`08168660 fffffa80`0798d050 : nt!KiBugCheckDispatch+0x69
fffff880`02ffdaa0 fffff880`03274434 : fffff880`0427ec7f fffffa80`0798d050 00000000`00000000 fffffa80`0798dd02 : nt!KiPageFault+0x260
fffff880`02ffdc38 fffff880`0427ec7f : fffffa80`0798d050 00000000`00000000 fffffa80`0798dd02 fffffa80`0798d1a0 : 0xfffff880`03274434
fffff880`02ffdc40 fffff880`0426ff89 : fffffa80`0798d050 00000000`00000000 fffffa80`0798dd02 fffffa80`0798dd28 : USBPORT!USBPORT_Core_UsbMapDpc_Worker+0x6f
fffff880`02ffdca0 fffff800`02cdc10c : fffff880`02fd5180 fffffa80`0798dd28 fffffa80`0798dd40 00000000`00000000 : USBPORT!USBPORT_Xdpc_Worker+0x1d9
fffff880`02ffdcd0 fffff800`02cc8a2a : fffff880`02fd5180 fffff880`02fdffc0 00000000`00000000 fffff880`0426fdb0 : nt!KiRetireDpcList+0x1bc
fffff880`02ffdd80 00000000`00000000 : fffff880`02ffe000 fffff880`02ff8000 fffff880`02ffdd40 00000000`00000000 : nt!KiIdleLoop+0x5a


STACK_COMMAND:  kb

FOLLOWUP_IP: 
USBPORT!USBPORT_Core_UsbMapDpc_Worker+6f
fffff880`0427ec7f 4c8b4340        mov     r8,qword ptr [rbx+40h]

SYMBOL_STACK_INDEX:  4

SYMBOL_NAME:  USBPORT!USBPORT_Core_UsbMapDpc_Worker+6f

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: USBPORT

IMAGE_NAME:  USBPORT.SYS

DEBUG_FLR_IMAGE_TIMESTAMP:  4d8c0c08

FAILURE_BUCKET_ID:  X64_0xD1_CODE_AV_BAD_IP_USBPORT!USBPORT_Core_UsbMapDpc_Worker+6f

BUCKET_ID:  X64_0xD1_CODE_AV_BAD_IP_USBPORT!USBPORT_Core_UsbMapDpc_Worker+6f

Followup: MachineOwner
---------

3: kd> lmvm USBPORT
start             end                 module name
fffff880`0426d000 fffff880`042c3000   USBPORT    (pdb symbols)          c:\windows\symbols\usbport.pdb\47451B86B21D42BDADD411F6892B8A0D1\usbport.pdb
    Loaded symbol image file: USBPORT.SYS
    Mapped memory image file: c:\Windows\Symbols\USBPORT.SYS\4D8C0C0856000\USBPORT.SYS
    Image path: \SystemRoot\system32\DRIVERS\USBPORT.SYS
    Image name: USBPORT.SYS
    Timestamp:        Thu Mar 24 23:29:12 2011 (4D8C0C08)
    CheckSum:         00056970
    ImageSize:        00056000
    File version:     6.1.7601.17586
    Product version:  6.1.7601.17586
    File flags:       0 (Mask 3F)
    File OS:          40004 NT Win32
    File type:        2.0 Dll
    File date:        00000000.00000000
    Translations:     0409.04b0
    CompanyName:      Microsoft Corporation
    ProductName:      Microsoft® Windows® Operating System
    InternalName:     usbport.sys
    OriginalFilename: usbport.sys
    ProductVersion:   6.1.7601.17586
    FileVersion:      6.1.7601.17586 (win7sp1_gdr.110324-1501)
    FileDescription:  USB 1.1 & 2.0 Port Driver
    LegalCopyright:   © Microsoft Corporation. All rights reserved.
This, along with the first crash, seems to be related to interrupt conflicts. Try toggling your BIOS to allow the OS to manage interrupts (or the other way around). Otherwise you may be correct regarding the overclocking, and resetting your BIOS to defaults might help.

After doing so, I think I would scan for hardware changes in the OS also.
 
Are all your drivers properly up to date? Chipset, USB, network, graphics, sound card, the lot. It can be easy to forget to update one sometimes.

Can you check the event viewer > Windows Log > System and see if anything crops up in there after a BSOD. That can sometimes reveal more information than a cryptic crash dump.
 
Ok last night I noticed that my system was still overclokced (thought had undone the overclock when the bsod started must have forgotten to save settings.) Anyways I removed the overclock and see how it goes before try anything else.

Not had BSOD since doing this so touch wood its fixed. Feel like idiot not saving settings.
 
Back
Top Bottom