Driver_IRQL_Not_Less_Or_Equal (?)

Discussion in 'Software' started by smcgarty, Jul 30, 2009.

  1. smcgarty

    smcgarty Private E-2

    Well,whenever I play Combat Arms (A game) after around 5 minutes, the game closes and a blue screen comes up saying something like this:

    Driver_IRQL_Not_Less_Or_Equal
    blah blah blah

    ***STOP 0x000000D1 (0xE1E50000,0x00000002,0x00000000,0xECEBFA60)

    Uhmmm,how do I fix this? xD
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi

    What Windows version and Service Pack are you using?

    What Firewall software are you using as that Game iirc is an online FPS and just wonder if your Firewall (if not the built in Windows one) is causing this, also network drivers can cause this, especially with IRQL errors, so update your network drivers and if your firewall as updates, update that also or disable the firewall for a short while to test.
     
  3. rjc862003

    rjc862003 Corporal

    if you want help please post the EXACT error msg including any files listed names or anything else

    I can't tell you what 'blah blah blah' is doing because I don't know what "blah blah blah" is

    that error is usely driver related
     
  4. smcgarty

    smcgarty Private E-2

    Where do I see what service pack i'm running and what firewall?
    Also, how do I update my drivers? xD

    There are no files listed, where I said blah it just says dumping whatever and stuff.
     
  5. smcgarty

    smcgarty Private E-2

    EnumProcess says
    Windows Firewall is on
    antispy process from Ad-Aware detected

    And I have Microsoft Windows XP Professional Version 2002
    Service pack 3.
     
  6. smcgarty

    smcgarty Private E-2

    That's all Enumprocess says o-o
     
  7. XTAL256

    XTAL256 Private First Class

    I got this problem when i was using Windows 7 (on a VM). Try updating your video driver and see if that helps, i think that solved my problem. Although Win7 isn't actually supported on the VM i was using so that might have caused the problem.
     
  8. smcgarty

    smcgarty Private E-2

    Okay; Enum now says:

    Windows Firewall is on
    [System Process]
    System
    \SystemRoot\System32\smss.exe
    csrss.exe (Microsoft Corporation / Client Server Runtime Process)
    \??\C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe (Microsoft Corporation / Services and Controller app)
    C:\WINDOWS\system32\lsass.exe (Microsoft Corporation / LSA Shell (Export Version))
    C:\WINDOWS\system32\svchost.exe (Microsoft Corporation / Generic Host Process for Win32 Services)
    svchost.exe (Microsoft Corporation / Generic Host Process for Win32 Services)
    C:\WINDOWS\System32\svchost.exe (Microsoft Corporation / Generic Host Process for Win32 Services)
    svchost.exe (Microsoft Corporation / Generic Host Process for Win32 Services)
    svchost.exe (Microsoft Corporation / Generic Host Process for Win32 Services)
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (Lavasoft / Ad-Aware Service)
    C:\WINDOWS\system32\spoolsv.exe (Microsoft Corporation / Spooler SubSystem App)
    svchost.exe (Microsoft Corporation / Generic Host Process for Win32 Services)
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc. / Apple Mobile Device Service)
    C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. / Bonjour Service)
    C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc. / Java(TM) Quick Starter Service)
    sqlservr.exe
    C:\WINDOWS\System32\svchost.exe (Microsoft Corporation / Generic Host Process for Win32 Services)
    C:\WINDOWS\System32\svchost.exe (Microsoft Corporation / Generic Host Process for Win32 Services)
    C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit / QuickBooks Company File Monitoring Service)
    c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Microsoft Corporation / SQL Server VSS Writer)
    C:\WINDOWS\system32\svchost.exe (Microsoft Corporation / Generic Host Process for Win32 Services)
    C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation / ViewMgr)
    alg.exe (Microsoft Corporation / Application Layer Gateway Service)
    C:\Program Files\iPod\bin\iPodService.exe (Apple Inc. / iPodService Module)
    C:\WINDOWS\Explorer.EXE (Microsoft Corporation / Windows Explorer)
    C:\WINDOWS\system32\hkcmd.exe (Intel Corporation / hkcmd Module)
    C:\WINDOWS\system32\igfxpers.exe (Intel Corporation / persistence Module)
    C:\WINDOWS\system32\dla\tfswctrl.exe (Sonic Solutions / Drive Letter Access Component)
    C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc. / iTunesHelper Module)
    C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation / CTF Loader)
    C:\Program Files\MSN Messenger\msnmsgr.exe (Microsoft Corporation / Messenger)
    C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc. / QuickBooks Automatic Update)
    C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation / Internet Explorer)
    C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation / Run a DLL as an App)
    C:\WINDOWS\system32\msiexec.exe (Microsoft Corporation / Windows® installer)
    C:\Program Files\Debugging Tools for Windows (x86)\windbg.exe (Microsoft Corporation / Windows GUI symbolic debugger)
    C:\Documents and Settings\Sean\Local Settings\Temporary Internet Files\Content.IE5\3H154LDF\EnumProcess[1].exe (Me, myself and I / EnumProcess)

    And the debug or whatever of the BSOD says:

    Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [C:\WINDOWS\Minidump\Mini073009-04.dmp]
    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
    Executable search path is:
    Windows XP Kernel Version 2600 (Service Pack 3) UP Free x86 compatible
    Product: WinNt, suite: TerminalServer SingleUserTS
    Built by: 2600.xpsp_sp3_gdr.090206-1234
    Machine Name:
    Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055b1c0
    Debug session time: Thu Jul 30 22:52:10.281 2009 (GMT-4)
    System Uptime: 0 days 3:02:32.830
    Loading Kernel Symbols
    ...............................................................
    ................................................................
    .................
    Loading User Symbols
    Loading unloaded module list
    ...............
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 100000D1, {e1e8d000, 2, 0, ecf2ca60}

    *** WARNING: Unable to verify timestamp for P16X.sys
    *** ERROR: Module load completed but symbols could not be loaded for P16X.sys
    Probably caused by : P16X.sys ( P16X+1d9de )

    Followup: MachineOwner
    ---------

    kd> !analyze -v
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
    An attempt was made to access a pageable (or completely invalid) address at an
    interrupt request level (IRQL) that is too high. This is usually
    caused by drivers using improper addresses.
    If kernel debugger is available get stack backtrace.
    Arguments:
    Arg1: e1e8d000, memory referenced
    Arg2: 00000002, IRQL
    Arg3: 00000000, value 0 = read operation, 1 = write operation
    Arg4: ecf2ca60, address which referenced memory

    Debugging Details:
    ------------------


    READ_ADDRESS: e1e8d000

    CURRENT_IRQL: 2

    FAULTING_IP:
    +1d9de
    ecf2ca60 f3a5 rep movs dword ptr es:[edi],dword ptr [esi]

    CUSTOMER_CRASH_COUNT: 4

    DEFAULT_BUCKET_ID: COMMON_SYSTEM_FAULT

    BUGCHECK_STR: 0xD1

    PROCESS_NAME: System

    LAST_CONTROL_TRANSFER: from ecf2b976 to ecf2ca60

    SYMBOL_ON_RAW_STACK: 1

    STACK_ADDR_RAW_STACK_SYMBOL: fffffffff7b26dfc

    STACK_COMMAND: dds F7B26DFC-0x20 ; kb

    STACK_TEXT:
    f7b26ddc 00000000
    f7b26de0 804f88ea nt!KiThreadStartup+0x16
    f7b26de4 804e4196 nt!ExpWorkerThread
    f7b26de8 00000001
    f7b26dec 00000000
    f7b26df0 0020027f
    f7b26df4 00000000
    f7b26df8 f66d29de P16X+0x1d9de
    f7b26dfc 00000008
    f7b26e00 f6770008 P16X+0xbb008
    f7b26e04 00000023
    f7b26e08 00001f80
    f7b26e0c 0000ffff
    f7b26e10 00000000
    f7b26e14 00000000
    f7b26e18 00000000
    f7b26e1c 00000000
    f7b26e20 00000000
    f7b26e24 00000000
    f7b26e28 00000000
    f7b26e2c 00000000
    f7b26e30 00000000
    f7b26e34 00000000
    f7b26e38 00000000
    f7b26e3c 00000000
    f7b26e40 00000000
    f7b26e44 00000000
    f7b26e48 00000000
    f7b26e4c 00000000
    f7b26e50 00000000
    f7b26e54 00000000
    f7b26e58 00000000


    FOLLOWUP_IP:
    P16X+1d9de
    f66d29de ?? ???

    SYMBOL_NAME: P16X+1d9de

    FOLLOWUP_NAME: MachineOwner

    MODULE_NAME: P16X

    IMAGE_NAME: P16X.sys

    DEBUG_FLR_IMAGE_TIMESTAMP: 3f6e7dd8

    FAILURE_BUCKET_ID: 0xD1_P16X+1d9de

    BUCKET_ID: 0xD1_P16X+1d9de

    Followup: MachineOwner
    ---------

    Dang,this is a lot of stuff.
     
  9. smcgarty

    smcgarty Private E-2

    Windbg or whatever saaays:
    Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [C:\WINDOWS\Minidump\Mini073109-01.dmp]
    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
    Executable search path is:
    Windows XP Kernel Version 2600 (Service Pack 3) UP Free x86 compatible
    Product: WinNt, suite: TerminalServer SingleUserTS
    Built by: 2600.xpsp_sp3_gdr.090206-1234
    Machine Name:
    Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055b1c0
    Debug session time: Fri Jul 31 22:20:54.640 2009 (GMT-4)
    System Uptime: 0 days 3:23:20.199
    Loading Kernel Symbols
    ...............................................................
    ................................................................
    ...........
    Loading User Symbols
    Loading unloaded module list
    .......................
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 100000D1, {e1ea9000, 2, 0, ecf3ca60}

    *** WARNING: Unable to verify timestamp for P16X.sys
    *** ERROR: Module load completed but symbols could not be loaded for P16X.sys
    Probably caused by : P16X.sys ( P16X+1d9de )

    Followup: MachineOwner
    ---------

    kd> !analyze -v
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
    An attempt was made to access a pageable (or completely invalid) address at an
    interrupt request level (IRQL) that is too high. This is usually
    caused by drivers using improper addresses.
    If kernel debugger is available get stack backtrace.
    Arguments:
    Arg1: e1ea9000, memory referenced
    Arg2: 00000002, IRQL
    Arg3: 00000000, value 0 = read operation, 1 = write operation
    Arg4: ecf3ca60, address which referenced memory

    Debugging Details:
    ------------------


    READ_ADDRESS: e1ea9000

    CURRENT_IRQL: 2

    FAULTING_IP:
    +1d9de
    ecf3ca60 f3a5 rep movs dword ptr es:[edi],dword ptr [esi]

    CUSTOMER_CRASH_COUNT: 1

    DEFAULT_BUCKET_ID: DRIVER_FAULT

    BUGCHECK_STR: 0xD1

    PROCESS_NAME: System

    LAST_CONTROL_TRANSFER: from ecf3b976 to ecf3ca60

    SYMBOL_ON_RAW_STACK: 1

    STACK_ADDR_RAW_STACK_SYMBOL: fffffffff7b26dfc

    STACK_COMMAND: dds F7B26DFC-0x20 ; kb

    STACK_TEXT:
    f7b26ddc 00000000
    f7b26de0 804f88ea nt!KiThreadStartup+0x16
    f7b26de4 804e4196 nt!ExpWorkerThread
    f7b26de8 00000001
    f7b26dec 00000000
    f7b26df0 0020027f
    f7b26df4 00000000
    f7b26df8 f66e29de P16X+0x1d9de
    f7b26dfc 00000008
    f7b26e00 f6780008 P16X+0xbb008
    f7b26e04 00000023
    f7b26e08 00001f80
    f7b26e0c 0000ffff
    f7b26e10 00000000
    f7b26e14 00000000
    f7b26e18 00000000
    f7b26e1c 00000000
    f7b26e20 00000000
    f7b26e24 00000000
    f7b26e28 00000000
    f7b26e2c 00000000
    f7b26e30 00000000
    f7b26e34 00000000
    f7b26e38 00000000
    f7b26e3c 00000000
    f7b26e40 00000000
    f7b26e44 00000000
    f7b26e48 00000000
    f7b26e4c 00000000
    f7b26e50 00000000
    f7b26e54 00000000
    f7b26e58 00000000


    FOLLOWUP_IP:
    P16X+1d9de
    f66e29de ?? ???

    SYMBOL_NAME: P16X+1d9de

    FOLLOWUP_NAME: MachineOwner

    MODULE_NAME: P16X

    IMAGE_NAME: P16X.sys

    DEBUG_FLR_IMAGE_TIMESTAMP: 3f6e7dd8

    FAILURE_BUCKET_ID: 0xD1_P16X+1d9de

    BUCKET_ID: 0xD1_P16X+1d9de

    Followup: MachineOwner
    ---------
     
  10. smcgarty

    smcgarty Private E-2

    Sorry I posted that twice; It didn't show up at first. And to update you, i now get the BSOD even when i'm just on the internet. :\
     
  11. rjc862003

    rjc862003 Corporal

    k P16X.sys is part of the drivers for the creative sound card try reinstalling the drivers

    or remove the card
     
  12. smcgarty

    smcgarty Private E-2

    How do I reinstall it?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds