多谢帮忙分析一下
Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Windows\Minidump\051110-25812-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\temp*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 7 Kernel Version 7600 MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 7600.16539.x86fre.win7_gdr.100226-1909
Machine Name:
Kernel base = 0x84011000 PsLoadedModuleList = 0x84159810
Debug session time: Tue May 11 00:32:15.540 2010 (GMT+8)
System Uptime: 0 days 5:04:19.368
Loading Kernel Symbols
...............................................................
................................................................
....................................
Loading User Symbols
Loading unloaded module list
......
Unable to load image kl1.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for kl1.sys
*** ERROR: Module load completed but symbols could not be loaded for kl1.sys
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 100000D1, {87cb5d, 2, 0, 9685f23c}
*** WARNING: Unable to verify timestamp for Hookport.sys
*** ERROR: Module load completed but symbols could not be loaded for Hookport.sys
Probably caused by : kl1.sys ( kl1+3e23c )
Followup: MachineOwner
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: 0087cb5d, memory referenced
Arg2: 00000002, IRQL
Arg3: 00000000, value 0 = read operation, 1 = write operation
Arg4: 9685f23c, address which referenced memory
Debugging Details:
READ_ADDRESS: GetPointerFromAddress: unable to read from 84179718
Unable to read MiSystemVaType memory at 84159160
0087cb5d
CURRENT_IRQL: 2
FAULTING_IP:
kl1+3e23c
9685f23c 393c18 cmp dword ptr [eax+ebx],edi
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT
BUGCHECK_STR: 0xD1
PROCESS_NAME: BitComet.exe
LAST_CONTROL_TRANSFER: from 94efc0cd to 9685f23c
STACK_TEXT:
WARNING: Stack unwind information not available. Following frames may be wrong.
a8b705dc 94efc0cd 87d17df0 00000011 86d28a08 kl1+0x3e23c
a8b70600 8404d4bc 876cd5c8 86e36468 86e3653c tdx!TdxTdiDispatchCreate+0x213
a8b70618 9685e3ca 86d28a10 87ca2cc8 9685c993 nt!IofCallDriver+0x63
a8b706ac 8404d4bc 87ca2c10 86e36468 86e36468 kl1+0x3d3ca
a8b706d8 8404d4bc 87d515e8 86e36468 87635094 nt!IofCallDriver+0x63
a8b706f0 8425166d 824efb1f a8b70898 00000000 nt!IofCallDriver+0x63
a8b707c8 8423221f 87d17df0 84bf3378 86defd20 nt!IopParseDevice+0xed7
a8b70844 8425828d 00000000 a8b70898 00000240 nt!ObpLookupObjectName+0x4fa
a8b708a4 842505eb a8b709bc 86bf3378 aeff4b00 nt!ObOpenObjectByName+0x159
a8b70920 8429b0bd 8a0ac134 c0100000 a8b709bc nt!IopCreateFile+0x673
a8b70968 96d66199 8a0ac134 c0100000 a8b709bc nt!IoCreateFile+0x38
a8b70a08 96d68105 893d4480 8000288c 0000af00 afd!AfdCreateConnection+0x17a
a8b70afc 96d62504 8734e830 87d27338 a8b70b24 afd!AfdConnect+0x6d0
a8b70b0c 8404d4bc 87d27338 86f3fd70 86f3fd70 afd!AfdDispatchDeviceControl+0x3b
a8b70b24 8424ef2e 8734e830 86f3fd70 86f3fe4c nt!IofCallDriver+0x63
a8b70b44 8426bd11 87d27338 8734e830 00000000 nt!IopSynchronousServiceTail+0x1f8
a8b70be0 8426e4ec 87d27338 86f3fd70 00000000 nt!IopXxxControlFile+0x6aa
a8b70c14 84d3681f 00000638 00000000 00000000 nt!NtDeviceIoControlFile+0x2a
a8b70d04 8405444a 00000638 00000000 00000000 Hookport+0x481f
a8b70d04 779364f4 00000638 00000000 00000000 nt!KiFastCallEntry+0x12a
0012f57c 00000000 00000000 00000000 00000000 0x779364f4
STACK_COMMAND: kb
FOLLOWUP_IP:
kl1+3e23c
9685f23c 393c18 cmp dword ptr [eax+ebx],edi
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: kl1+3e23c
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: kl1
IMAGE_NAME: kl1.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4a361baf
FAILURE_BUCKET_ID: 0xD1_kl1+3e23c
BUCKET_ID: 0xD1_kl1+3e23c
Followup: MachineOwner