DRIVER_IRQL_NOT_LESS_OR_EQUAL 0x000000d1 crash

Hi,

I have been having a recurring problem lately where my laptop would repeatedly go to the blue screen with an error stated "DRIVER_IRQL_NOT_LESS_OR_EQUAL". I have included the DMP file for reference and a TXT document.

It seems to be when I go online or do anything streaming related that this screen comes up. All other things I do in windows seems fine.

I would really appreciate anyone's expertise or help on this.

Thanks in advance!
 

Attachments

  • DMP.txt
    1.5 KB · Views: 3
  • 031211-33961-01.dmp
    140.3 KB · Views: 2
The error code d1 usually relates to drivers and the text file shows it as nqdgknvw.sys which I could not find doing a search. This could be a virus so download , install, update and run a full system scan with malwarebytes from the link below.

http://www.malwarebytes.org/mbam.php

Another device to check is your network adapter. Go into device manager, clcik on the + next to Network adapters and then right click on the adapter, select properties and then under the driver tab select update driver and see if it finds any update which it will install.

If none of the above create any improvements then follow this guide to try and find any faulty drivers.

For windows XP - Click on Start and then Run. Type verifier into the box and hit the Enter key.
For Vista and Windows 7 - Click on Start and type verifier into the search box then click on verifier in the list that pops up.

Driver Verifier Manager will open.

Select the first choice "Create Standard Settings" and click on the "Next" button.

Now select "Automatically select all drivers installed on this computer" and click on the "Finish" button.

A box will appear asking you to restart the PC for the changes to take effect. Click on "OK" and reboot the PC.

To stop Auto reboot so you can read the error message do this for Windows XP:
Click the Start button, right-click My Computer, click Properties, click the Advanced tab, and then click Settings under Startup and Recovery.
Under System Failure, uncheck the "Automatically restart" check box.

And do this in Windows 7 and Vista:
Click Start, select 'Control Panel' select 'System' in the left pane select 'Advanced System Settings' in the box select the 'Advanced' tab then under 'Startup and Recovery' select 'Settings.' In the box under 'System Failure' uncheck 'Automatically Restart'.

If the PC reboots normally then there is no problem with any of the drivers. If you get a blue screen straight away it will name the faulty driver. If you are absolutley certain that the named driver is OK then make a note of it.

You will then have to go back into the Verifier and instead of selecting all drivers select "Select drivers from a list". Click on "Next" and the list of drivers will appear. Select them all apart from the one you know to be OK. Click on "Finish" and reboot.

Once you have identified the faulty driver or confirmed that there are none go back to the first page of the Driver Verifier Manager and select "Delete Existing Settings" and click on "Finish"
 
Indeed, and looks like the file is new, dated Sat Mar 05 09:10:16 2011 .

So did you install anything around that date? Can you use system restore and go back before that time?

Also, open \SystemRoot\System32\Drivers\ directory and right click on nqdgknvw.sys and then properties and see if it shows anything to help you figure out what it is.

Try renaming the file and see if it breaks anything? Be careful if you try this one. Might not boot up next time, so be prepared to have a way to rename it back just in case.

*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck D1, {c5604000, 2, 0, 8b441747}

Unable to load image \SystemRoot\System32\Drivers\nqdgknvw.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for nqdgknvw.sys
*** ERROR: Module load completed but symbols could not be loaded for nqdgknvw.sys
Unable to load image \SystemRoot\system32\DRIVERS\vpcnfltr.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for vpcnfltr.sys
*** ERROR: Module load completed but symbols could not be loaded for vpcnfltr.sys
Unable to load image \SystemRoot\system32\DRIVERS\athr.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for athr.sys
*** ERROR: Module load completed but symbols could not be loaded for athr.sys
Probably caused by : nqdgknvw.sys ( nqdgknvw+4747 )

Followup: MachineOwner
---------

0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: c5604000, memory referenced
Arg2: 00000002, IRQL
Arg3: 00000000, value 0 = read operation, 1 = write operation
Arg4: 8b441747, address which referenced memory

Debugging Details:
------------------


READ_ADDRESS: GetPointerFromAddress: unable to read from 82f7f718
Unable to read MiSystemVaType memory at 82f5f160
c5604000

CURRENT_IRQL: 2

FAULTING_IP:
nqdgknvw+4747
8b441747 0fb618 movzx ebx,byte ptr [eax]

CUSTOMER_CRASH_COUNT: 1

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

BUGCHECK_STR: 0xD1

PROCESS_NAME: System

TRAP_FRAME: 82f3cd18 -- (.trap 0xffffffff82f3cd18)
ErrCode = 00000000
eax=c5604000 ebx=000000f0 ecx=c5603fff edx=c5603a60 esi=c5603fff edi=c5603fff
eip=8b441747 esp=82f3cd8c ebp=82f3cd9c iopl=0 nv up ei ng nz na pe cy
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010287
nqdgknvw+0x4747:
8b441747 0fb618 movzx ebx,byte ptr [eax] ds:0023:c5604000=??
Resetting default scope

LAST_CONTROL_TRANSFER: from 8b441747 to 82e5d81b

STACK_TEXT:
82f3cd18 8b441747 badb0d00 c5603a60 000005a0 nt!KiTrap0E+0x2cf
WARNING: Stack unwind information not available. Following frames may be wrong.
82f3cd9c 8b458dd1 c5604000 c5603fff 82f3cecc nqdgknvw+0x4747
82f3cdb8 8b5ba589 82f3d1d4 82f3d1ec 000005a0 nqdgknvw+0x1bdd1
82f3ce10 8b5ba89c 82f3ceac 8a7b7258 8a7b7258 NETIO!StreamInvokeCalloutAndNormalizeAction+0xce
82f3ce40 8b5ba9b7 82f3ceac 8a7b7258 8a7b7258 NETIO!StreamCalloutProcessData+0x31
82f3ce80 8b5bae1d 82f3ceac 8a7b7258 8a7b7258 NETIO!StreamCalloutProcessingLoop+0x55
82f3ceec 8b5a8f56 00000014 8b441038 00000000 NETIO!StreamProcessCallout+0x128
82f3cf50 8b593334 00000014 82f3d1d4 82f3d1ec NETIO!ProcessCallout+0x120
82f3cfc4 8b59225c 00000014 82f3d1d4 82f3d1ec NETIO!ArbitrateAndEnforce+0xae
82f3d0d4 8b5b8332 00000014 82f3d1d4 82f3d1ec NETIO!KfdClassify+0x1c7
82f3d168 8b5b86fe 00000014 82f3d1d4 82f3d1ec NETIO!StreamClassify+0xa0
82f3d348 8b5b8b91 88b4f4e0 00000014 82f3d374 NETIO!StreamCommonInspect+0x252
82f3d37c 8bacfd2d 88b4f4e0 00000000 8651c628 NETIO!WfpStreamInspectReceive+0xb8
82f3d3a4 8ba97362 85e244d8 85e245d0 8651c628 tcpip!TcpInspectReceive+0x55
82f3d3f4 8ba965a6 85e244d8 82f3d418 82f3d450 tcpip!TcpTcbFastDatagram+0x2fd
82f3d45c 8ba969ac 871b8f40 85e244d8 00f3d4d0 tcpip!TcpTcbReceive+0x142
82f3d4c4 8ba85b4c 866f1958 871a7000 00000000 tcpip!TcpMatchReceive+0x237
82f3d514 8ba858ae 871b8f40 871a7000 00003dc4 tcpip!TcpPreValidatedReceive+0x293
82f3d530 8ba8b273 871b8f40 871a7000 82f3d56c tcpip!TcpReceive+0x2d
82f3d540 8babd50e 82f3d554 c000023e 00000000 tcpip!TcpNlClientReceiveDatagrams+0x12
82f3d56c 8babd2d1 8bb1cf88 82f3d5c0 c000023e tcpip!IppDeliverListToProtocol+0x49
82f3d58c 8babcfa6 8bb1cd98 00000006 82f3d5c0 tcpip!IppProcessDeliverList+0x2a
82f3d5e4 8bababe4 8bb1cd98 00000006 00000000 tcpip!IppReceiveHeaderBatch+0x1f2
82f3d678 8bab9b75 89bbdeb8 00000000 00000001 tcpip!IpFlcReceivePackets+0xbe5
82f3d6f4 8bab9ce6 87a12710 89bffc98 00000000 tcpip!FlpReceiveNonPreValidatedNetBufferListChain+0x746
82f3d728 82ea7092 89bffc98 a01dd6f9 87125a88 tcpip!FlReceiveNetBufferListChainCalloutRoutine+0x11e
82f3d790 8bab9d6e 8bab9bc8 82f3d7b8 00000000 nt!KeExpandKernelStackAndCalloutEx+0x132
82f3d7cc 8b79918d 87a12702 89bffc00 00000000 tcpip!FlReceiveNetBufferListChain+0x7c
82f3d804 8b787670 89bab008 89bffc98 00000000 ndis!ndisMIndicateNetBufferListsToOpen+0x188
82f3d82c 8b7875e7 00000000 87a1e1d0 91ecc1ec ndis!ndisIndicateSortedNetBufferLists+0x4a
82f3d9a8 8b732ca5 879170e0 00000000 00000000 ndis!ndisMDispatchReceiveNetBufferLists+0x129
82f3d9c4 8b762a87 879170e0 89bffc98 00000000 ndis!ndisMTopReceiveNetBufferLists+0x2d
82f3d9e0 8b762a21 87a48d18 89bffc98 00000000 ndis!ndisFilterIndicateReceiveNetBufferLists+0x46
82f3d9fc 91ec5426 87a48d18 89bffc98 00000000 ndis!NdisFIndicateReceiveNetBufferLists+0x2f
82f3da3c 8b762a87 87a1e1d0 89bffc98 00000000 vpcnfltr+0x3426
82f3da58 8b762a21 89b30868 89bffc98 00000000 ndis!ndisFilterIndicateReceiveNetBufferLists+0x46
82f3da74 8cf57837 89b30868 89bffc98 00000000 ndis!NdisFIndicateReceiveNetBufferLists+0x2f
82f3da9c 8cf5b497 89b30868 87abea10 87abe9c0 nwifi!Dot11IndicateRecvPackets+0x51
82f3dabc 8b762a87 89bbdab0 89bffc98 00000000 nwifi!Pt6Receive+0x1d3
82f3dad8 8b762a21 87abb780 87a75e70 00000000 ndis!ndisFilterIndicateReceiveNetBufferLists+0x46
82f3daf4 91eb3c85 87abb780 87a75e70 00000000 ndis!NdisFIndicateReceiveNetBufferLists+0x2f
82f3db20 8b787a2e 87abe014 87a75e70 00000000 vwififlt!FilterReceiveNetBufferLists+0xcf
82f3db48 8b732c1e 879170e0 87a75e70 00000000 ndis!ndisMIndicateReceiveNetBufferListsInternal+0x62
82f3db70 93034a59 879170e0 87a75e70 00000000 ndis!NdisMIndicateReceiveNetBufferLists+0x52
82f3dbb8 93033e66 87a69020 00000000 00000000 athr+0x17a59
82f3dbd0 930ba304 87a69020 82f3dbf8 930bfd7f athr+0x16e66
82f3dbdc 930bfd7f 87a49020 82f3dc0c 87a49020 athr+0x9d304
82f3dbf8 9303f40d 87a49020 82f3dc14 9301e481 athr+0xa2d7f
82f3dc04 9301e481 859f9020 87a69020 82f3dc50 athr+0x2240d
82f3dc14 8b787309 87a69020 00000000 82f3dc40 athr+0x1481
82f3dc50 8b7329f4 87a76b0c 00a76af8 00000000 ndis!ndisMiniportDpc+0xe2
82f3dc78 82e7f4f5 87a76b0c 87a76af8 00000000 ndis!ndisInterruptDpc+0xaf
82f3dcd4 82e7f358 82f40d20 82f4a280 00000000 nt!KiExecuteAllDpcs+0xf9
82f3dcd8 82f40d20 82f4a280 00000000 85f50d10 nt!KiRetireDpcList+0xd5
82f3dcdc 82f4a280 00000000 85f50d10 82f4a280 nt!KiInitialPCR+0x120
82f40d20 82f4a280 85f50d10 82f4a280 00000100 nt!KiInitialThread
82f40dec 82e5d81b 00000008 00000206 82f3cd00 nt!KiInitialThread
82f40dec 8b441747 00000008 00000206 82f3cd00 nt!KiTrap0E+0x2cf
82f3cd9c 8b458dd1 c5604000 c5603fff 82f3cecc nqdgknvw+0x4747
82f3cdb8 8b5ba589 82f3d1d4 82f3d1ec 000005a0 nqdgknvw+0x1bdd1
82f3ce10 8b5ba89c 82f3ceac 8a7b7258 8a7b7258 NETIO!StreamInvokeCalloutAndNormalizeAction+0xce
82f3ce40 8b5ba9b7 82f3ceac 8a7b7258 8a7b7258 NETIO!StreamCalloutProcessData+0x31
82f3ce80 8b5bae1d 82f3ceac 8a7b7258 8a7b7258 NETIO!StreamCalloutProcessingLoop+0x55
82f3ceec 8b5a8f56 00000014 8b441038 00000000 NETIO!StreamProcessCallout+0x128
82f3cf50 8b593334 00000014 82f3d1d4 82f3d1ec NETIO!ProcessCallout+0x120
82f3cfc4 8b59225c 00000014 82f3d1d4 82f3d1ec NETIO!ArbitrateAndEnforce+0xae
82f3d0d4 8b5b8332 00000014 82f3d1d4 82f3d1ec NETIO!KfdClassify+0x1c7
82f3d168 8b5b86fe 00000014 82f3d1d4 82f3d1ec NETIO!StreamClassify+0xa0
82f3d348 8b5b8b91 88b4f4e0 00000014 82f3d374 NETIO!StreamCommonInspect+0x252
82f3d37c 8bacfd2d 88b4f4e0 00000000 8651c628 NETIO!WfpStreamInspectReceive+0xb8
82f3d3a4 8ba97362 85e244d8 85e245d0 8651c628 tcpip!TcpInspectReceive+0x55
82f3d3f4 8ba965a6 85e244d8 82f3d418 82f3d450 tcpip!TcpTcbFastDatagram+0x2fd
82f3d45c 8ba969ac 871b8f40 85e244d8 00f3d4d0 tcpip!TcpTcbReceive+0x142
82f3d4c4 8ba85b4c 866f1958 871a7000 00000000 tcpip!TcpMatchReceive+0x237
82f3d514 8ba858ae 871b8f40 871a7000 00003dc4 tcpip!TcpPreValidatedReceive+0x293


STACK_COMMAND: kb

FOLLOWUP_IP:
nqdgknvw+4747
8b441747 0fb618 movzx ebx,byte ptr [eax]

SYMBOL_STACK_INDEX: 1

SYMBOL_NAME: nqdgknvw+4747

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: nqdgknvw

IMAGE_NAME: nqdgknvw.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 4d724448

FAILURE_BUCKET_ID: 0xD1_nqdgknvw+4747

BUCKET_ID: 0xD1_nqdgknvw+4747

Followup: MachineOwner
---------

0: kd> lmvm nqdgknvw
start end module name
8b43d000 8b4fb000 nqdgknvw T (no symbols)
Loaded symbol image file: nqdgknvw.sys
Image path: \SystemRoot\System32\Drivers\nqdgknvw.sys
Image name: nqdgknvw.sys
Timestamp: Sat Mar 05 09:10:16 2011 (4D724448)
CheckSum: 000BD3F3
ImageSize: 000BE000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
 
Back