Error Code BCCode : 100000d1

A

aYie28

These few Days, When i want to print, My PC Was hang...So i must
restart it and loss my currently data ....
After restart, and log into windows, it give me error code :

BCCode : 100000d1 BCP1 : 7FFD5010 BCP2 : 00000002 BCP3 :
00000000
BCP4 : F787BD22 OSVer : 5_1_2600 SP : 2_0 Product :
256_1

C:\DOCUME~1\ancient\LOCALS~1\Temp\WERc6b9.dir00\Mini011208-01.dmp
C:\DOCUME~1\ancient\LOCALS~1\Temp\WERc6b9.dir00\sysdata.xml

Does anyone know what it means ?
 
D

devil_himself

These few Days, When i want to print, My PC Was hang...So i must
restart it and loss my currently data ....
After restart, and log into windows, it give me error code :

BCCode : 100000d1 BCP1 : 7FFD5010 BCP2 : 00000002 BCP3 :
00000000
BCP4 : F787BD22 OSVer : 5_1_2600 SP : 2_0 Product :
256_1

C:\DOCUME~1\ancient\LOCALS~1\Temp\WERc6b9.dir00\Mini011208-01.dmp
C:\DOCUME~1\ancient\LOCALS~1\Temp\WERc6b9.dir00\sysdata.xml

Does anyone know what it means ?

Navigate To C:\windows\minidump
Zip Some of the recent minidumps and upload them to any free web
hosting and Give us the Link
 
G

Gerry

Background information on Stop error message

http://msdn2.microsoft.com/en-us/library/ms795930.aspx

0x000000D1: DRIVER_IRQL_NOT_LESS_OR_EQUAL
The system attempted to access pageable memory using a kernel process
IRQL that was too high. The most typical cause is a bad device driver
(one that uses improper addresses). It can also be caused by caused by
faulty or mismatched RAM, or a damaged pagefile.
Source: http://aumha.org/a/stop.htm

Are there any yellow question marks in Device Manager? Right click on
the My Computer icon on your Desktop and select Properties,
Hardware,Device Manager. If yes what is the Device Error code?

Try Start, Run, type "sigverif.exe" without quotes and hit OK. What
drivers are listed as unsigned? Disregard those which are not checked.

What is your printer make and model?


--



Hope this helps.

Gerry
~~~~
FCA
Stourport, England
Enquire, plan and execute
~~~~~~~~~~~~~~~~~~~
 
N

nass

These few Days, When i want to print, My PC Was hang...So i must
restart it and loss my currently data ....
After restart, and log into windows, it give me error code :

BCCode : 100000d1 BCP1 : 7FFD5010 BCP2 : 00000002 BCP3 :
00000000
BCP4 : F787BD22 OSVer : 5_1_2600 SP : 2_0 Product :
256_1

C:\DOCUME~1\ancient\LOCALS~1\Temp\WERc6b9.dir00\Mini011208-01.dmp
C:\DOCUME~1\ancient\LOCALS~1\Temp\WERc6b9.dir00\sysdata.xml

Does anyone know what it means ?


Either a bad Driver for a hardware or an Overheated System, also a Bad RAM
or Corrupt Page File can cause this scenario to happen!.

You may have a bad RAM try to test your RAM by running Memtest by
downloading this tool and unzip it and make a floppy or CD/DVD and run it on
Reboot.
http://www.memtest86.com/
You may need to reposition/reset the RAM sticks in their slots.
After that you could do a repair install, and then test.
Open a Notepad, customize or minimize to the taskbar as you will need it
later for this step to copy the error message on it.
Open a run command and type in:
eventvwr.msc click [OK] you will get the Event viewer control Panel.
click on each of these:
Application
System
Security
Look in the right Pane/window for error message with red (X) or Yellow
exclamation mark /!\ , double click each one to get more info about the
causer.
On the Event error properties message you will see:
Up Arrow
Down arrow
Two pages
Click on the two pages to copy the error message then bring up the Notepad
you opened earlier and right click on the first line and select Paste from
the list, this will paste the error message on a Notepad.
Please don't duplicate the error message one of each kind will be sufficient.
HOW TO: View and Manage Event Logs in Event Viewer in Windows XP
http://support.microsoft.com/kb/308427/en-us

Please we need just the error messages with Red (X) and don't repeat the
error, just one of each kind and post them back in your next post.

How to perform a clean boot in Windows XP
http://support.microsoft.com/?id=310353
A description of the Safe Mode Boot options in Windows XP
http://support.microsoft.com/kb/315222/en-us

If the pagefile that was corrupted. selected no pagefile option under the
perfomance menu in system properties, reboot your system and then recreated
the pagefile again on your system.

If the above doesn't help, back up your data try the info below:
http://www.michaelstevenstech.com/XPrepairinstall.htm

HTH.
nass
 
A

aYie28

As requested by devil_, below is the link of my recent minidump
files :

http://www.mediafire.com/?e1i4wijylgy

As requested by Gerry, below is the link of sigverif.exe :

http://www.mediafire.com/?0yz1qnxdoob

and as per nass, I just do memory test using memtest86, and i didn't
get any error message regarding my memory.
Event viewer give me too much red and yellow exclamation, and as what
i see, event the application i've uninstall still there with red and
yellow exclamation, is there anyway how to remove them ?
 
N

nass

Hi, did you recreate the Page File?.

Right click My Computer >> Select properties.
On the system properties click on Advanced tab then click on Settings Button
opposite Performance.
Then click on Advanced Tab ans click Change Button under: Virtual Memory
option.
On the Virtual memory window check this Radio Button:
(*)No Paging File click [Set...] then [OK] and Reboot the machine.
Repeat the above steps to recreate the paging file to:
Select (*) Custom size:
Initial Size(MB): [360 ] or what was been set before
Maximum Size(MB): [720 ] or what been set before.

Click [Set ] then [OK] and Reboot the machine, monitor the behaviour and
see if the error will happen again.


Please send the error message in a plain text in your next post as
instructed in my previous post.

Also have a look in the Device manager for malfunctioning Devices or IRQ
conflict and the Sigverifier report.
HTH.
nass
 
G

Gerry

Please send these reports in a plain text message.

--



Hope this helps.

Gerry
~~~~
FCA
Stourport, England
Enquire, plan and execute
~~~~~~~~~~~~~~~~~~~
 
D

devil_himself

Please send these reports in a plain text message.

--

Hope this helps.

Gerry
~~~~
FCA
Stourport, England
Enquire, plan and execute
~~~~~~~~~~~~~~~~~~~

Bugcheck Analysis

///

BugCheck 100000D1, {7ffd5010, 2, 0, f787bd22}
Probably caused by : DrvFltIp ( DrvFltIp+4d22 )

Followup: MachineOwner
---------

0: kd> !analyze -v
*******************************************************************************
*
*
* Bugcheck
Analysis *
*
*
*******************************************************************************

DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid)
address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: 7ffd5010, memory referenced
Arg2: 00000002, IRQL
Arg3: 00000000, value 0 = read operation, 1 = write operation
Arg4: f787bd22, address which referenced memory

Debugging Details:
------------------




READ_ADDRESS: 7ffd5010
CURRENT_IRQL: 2
FAULTING_IP:
DrvFltIp+4d22
f787bd22 8b08 mov ecx,dword ptr [eax]
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: DRIVER_FAULT
BUGCHECK_STR: 0xD1
PROCESS_NAME: System
LAST_CONTROL_TRANSFER: from f78780e1 to f787bd22

STACK_TEXT:
WARNING: Stack unwind information not available. Following frames may
be wrong.
f78aac34 f78780e1 000007a8 f77ef400 86468920 DrvFltIp+0x4d22
f78aac54 f78783a8 f78aac90 f78aac8f 000007a8 DrvFltIp+0x10e1
f78aaca0 f78793a6 000007a8 00000000 0affffff DrvFltIp+0x13a8
f78aacf0 f787a119 865caf18 000007a8 862528fc DrvFltIp+0x23a6
f78aad5c 804e13d9 865caf18 86252868 00000032 DrvFltIp+0x3119
f78aad5c 856203a8 865caf18 86252868 00000032 nt!KiTrap0B+0x10f
f78aae00 00000000 00000000 00000000 00000000 0x856203a8


STACK_COMMAND: kb
FOLLOWUP_IP:
DrvFltIp+4d22
f787bd22 8b08 mov ecx,dword ptr [eax]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: DrvFltIp+4d22
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: DrvFltIp
IMAGE_NAME: DrvFltIp
DEBUG_FLR_IMAGE_TIMESTAMP: 4589e4bb
FAILURE_BUCKET_ID: 0xD1_DrvFltIp+4d22
BUCKET_ID: 0xD1_DrvFltIp+4d22

Followup: MachineOwner
---------

0: kd> lmvm DrvFltIp
start end module name
f7877000 f787e200 DrvFltIp T (no symbols)
Loaded symbol image file: DrvFltIp
Image path: DrvFltIp
Image name: DrvFltIp
Timestamp: Thu Dec 21 07:04:51 2006 (4589E4BB)
CheckSum: 0000EE55
ImageSize: 00007200
Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0

\\\
 
D

devil_himself

Please send these reports in a plain text message.

--

Hope this helps.

Gerry
~~~~
FCA
Stourport, England
Enquire, plan and execute
~~~~~~~~~~~~~~~~~~~
--------

STACK_TEXT:
WARNING: Stack unwind information not available. Following frames may
be wrong.
f78aac34 f78780e1 000007a8 f77ef400 86468920 DrvFltIp+0x4d22f78aad5c 856203a8 865caf18 86252868 00000032 nt!KiTrap0B+0x10f
f78aae00 00000000 00000000 00000000 00000000 0x856203a8
 
N

nass

devil_himself said:
Please send these reports in a plain text message.

--

Hope this helps.

Gerry
~~~~
FCA
Stourport, England
Enquire, plan and execute
~~~~~~~~~~~~~~~~~~~

Bugcheck Analysis

///

BugCheck 100000D1, {7ffd5010, 2, 0, f787bd22}
Probably caused by : DrvFltIp ( DrvFltIp+4d22 )

Followup: MachineOwner
---------

0: kd> !analyze -v
*******************************************************************************
*
*
* Bugcheck
Analysis *
*
*
*******************************************************************************

DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid)
address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: 7ffd5010, memory referenced
Arg2: 00000002, IRQL
Arg3: 00000000, value 0 = read operation, 1 = write operation
Arg4: f787bd22, address which referenced memory

Debugging Details:
------------------




READ_ADDRESS: 7ffd5010
CURRENT_IRQL: 2
FAULTING_IP:
DrvFltIp+4d22
f787bd22 8b08 mov ecx,dword ptr [eax]
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: DRIVER_FAULT
BUGCHECK_STR: 0xD1
PROCESS_NAME: System
LAST_CONTROL_TRANSFER: from f78780e1 to f787bd22

STACK_TEXT:
WARNING: Stack unwind information not available. Following frames may
be wrong.
f78aac34 f78780e1 000007a8 f77ef400 86468920 DrvFltIp+0x4d22
f78aac54 f78783a8 f78aac90 f78aac8f 000007a8 DrvFltIp+0x10e1
f78aaca0 f78793a6 000007a8 00000000 0affffff DrvFltIp+0x13a8
f78aacf0 f787a119 865caf18 000007a8 862528fc DrvFltIp+0x23a6
f78aad5c 804e13d9 865caf18 86252868 00000032 DrvFltIp+0x3119
f78aad5c 856203a8 865caf18 86252868 00000032 nt!KiTrap0B+0x10f
f78aae00 00000000 00000000 00000000 00000000 0x856203a8


STACK_COMMAND: kb
FOLLOWUP_IP:
DrvFltIp+4d22
f787bd22 8b08 mov ecx,dword ptr [eax]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: DrvFltIp+4d22
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: DrvFltIp
IMAGE_NAME: DrvFltIp
DEBUG_FLR_IMAGE_TIMESTAMP: 4589e4bb
FAILURE_BUCKET_ID: 0xD1_DrvFltIp+4d22
BUCKET_ID: 0xD1_DrvFltIp+4d22

Followup: MachineOwner
---------

0: kd> lmvm DrvFltIp
start end module name
f7877000 f787e200 DrvFltIp T (no symbols)
Loaded symbol image file: DrvFltIp
Image path: DrvFltIp
Image name: DrvFltIp
Timestamp: Thu Dec 21 07:04:51 2006 (4589E4BB)
CheckSum: 0000EE55
ImageSize: 00007200
Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0

\\\

That Dump doesn't really show the real causer in this situation as such or
in accurate way for troubleshooting!.
Read here:
DrvFltIp.sys is Spyware.SpySure
http://www.symantec.com/security_response/writeup.jsp?docid=2007-092009-4412-99&tabid=2

DrvFltIp encountered a error at BADFCD22 x BADF8000".
http://forums.nvidia.com/lofiversion/index.php?t28205.html
HTH.
nass
 
D

devil_himself

Bugcheck Analysis

BugCheck 100000D1, {7ffd5010, 2, 0, f787bd22}
Probably caused by : DrvFltIp ( DrvFltIp+4d22 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
*
*
* Bugcheck
Analysis *
*
*
*******************************************************************************
DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid)
address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: 7ffd5010, memory referenced
Arg2: 00000002, IRQL
Arg3: 00000000, value 0 = read operation, 1 = write operation
Arg4: f787bd22, address which referenced memory
Debugging Details:
------------------
READ_ADDRESS: 7ffd5010
CURRENT_IRQL: 2
FAULTING_IP:
DrvFltIp+4d22
f787bd22 8b08 mov ecx,dword ptr [eax]
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: DRIVER_FAULT
BUGCHECK_STR: 0xD1
PROCESS_NAME: System
LAST_CONTROL_TRANSFER: from f78780e1 to f787bd22
STACK_TEXT:
WARNING: Stack unwind information not available. Following frames may
be wrong.
f78aac34 f78780e1 000007a8 f77ef400 86468920 DrvFltIp+0x4d22
f78aac54 f78783a8 f78aac90 f78aac8f 000007a8 DrvFltIp+0x10e1
f78aaca0 f78793a6 000007a8 00000000 0affffff DrvFltIp+0x13a8
f78aacf0 f787a119 865caf18 000007a8 862528fc DrvFltIp+0x23a6
f78aad5c 804e13d9 865caf18 86252868 00000032 DrvFltIp+0x3119
f78aad5c 856203a8 865caf18 86252868 00000032 nt!KiTrap0B+0x10f
f78aae00 00000000 00000000 00000000 00000000 0x856203a8
STACK_COMMAND: kb
FOLLOWUP_IP:
DrvFltIp+4d22
f787bd22 8b08 mov ecx,dword ptr [eax]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: DrvFltIp+4d22
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: DrvFltIp
IMAGE_NAME: DrvFltIp
DEBUG_FLR_IMAGE_TIMESTAMP: 4589e4bb
FAILURE_BUCKET_ID: 0xD1_DrvFltIp+4d22
BUCKET_ID: 0xD1_DrvFltIp+4d22
Followup: MachineOwner
---------
0: kd> lmvm DrvFltIp
start end module name
f7877000 f787e200 DrvFltIp T (no symbols)
Loaded symbol image file: DrvFltIp
Image path: DrvFltIp
Image name: DrvFltIp
Timestamp: Thu Dec 21 07:04:51 2006 (4589E4BB)
CheckSum: 0000EE55
ImageSize: 00007200
Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0

That Dump doesn't really show the real causer in this situation as such or
in accurate way for troubleshooting!.
Read here:
DrvFltIp.sys is Spyware.SpySure.http://www.symantec.com/security_response/writeup.jsp?docid=2007-0920...

DrvFltIp encountered a error at BADFCD22 x BADF8000".http://forums.nvidia.com/lofiversion/index.php?t28205.html
HTH.
nass
---http://www.nasstec.co.uk

The Module_Name and The Stack Trace Shows "DrvFltIp" As The
Culprit .....

If You Have any Objections ... Then Provide Evidence In Support

yes .. It may be a trojan or spyware.

also the "lmvm" doesn't actually tells to what does "DrvFltIp" belongs
to ...so it may be a dodgy file....
 
N

nass

devil_himself said:
devil_himself said:
Please send these reports in a plain text message.

Hope this helps.
Gerry
~~~~
FCA
Stourport, England
Enquire, plan and execute
~~~~~~~~~~~~~~~~~~~
(e-mail address removed) wrote:
As requested by devil_, below is the link of my recent minidump
files :

As requested by Gerry, below is the link of sigverif.exe :

and as per nass, I just do memory test using memtest86, and i didn't
get any error message regarding my memory.
Event viewer give me too much red and yellow exclamation, and as what
i see, event the application i've uninstall still there with red and
yellow exclamation, is there anyway how to remove them ?
Bugcheck Analysis

BugCheck 100000D1, {7ffd5010, 2, 0, f787bd22}
Probably caused by : DrvFltIp ( DrvFltIp+4d22 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
*
*
* Bugcheck
Analysis *
*
*
*******************************************************************************
DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid)
address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: 7ffd5010, memory referenced
Arg2: 00000002, IRQL
Arg3: 00000000, value 0 = read operation, 1 = write operation
Arg4: f787bd22, address which referenced memory
Debugging Details:
------------------
READ_ADDRESS: 7ffd5010
CURRENT_IRQL: 2
FAULTING_IP:
DrvFltIp+4d22
f787bd22 8b08 mov ecx,dword ptr [eax]
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: DRIVER_FAULT
BUGCHECK_STR: 0xD1
PROCESS_NAME: System
LAST_CONTROL_TRANSFER: from f78780e1 to f787bd22
STACK_TEXT:
WARNING: Stack unwind information not available. Following frames may
be wrong.
f78aac34 f78780e1 000007a8 f77ef400 86468920 DrvFltIp+0x4d22
f78aac54 f78783a8 f78aac90 f78aac8f 000007a8 DrvFltIp+0x10e1
f78aaca0 f78793a6 000007a8 00000000 0affffff DrvFltIp+0x13a8
f78aacf0 f787a119 865caf18 000007a8 862528fc DrvFltIp+0x23a6
f78aad5c 804e13d9 865caf18 86252868 00000032 DrvFltIp+0x3119
f78aad5c 856203a8 865caf18 86252868 00000032 nt!KiTrap0B+0x10f
f78aae00 00000000 00000000 00000000 00000000 0x856203a8
STACK_COMMAND: kb
FOLLOWUP_IP:
DrvFltIp+4d22
f787bd22 8b08 mov ecx,dword ptr [eax]
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: DrvFltIp+4d22
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: DrvFltIp
IMAGE_NAME: DrvFltIp
DEBUG_FLR_IMAGE_TIMESTAMP: 4589e4bb
FAILURE_BUCKET_ID: 0xD1_DrvFltIp+4d22
BUCKET_ID: 0xD1_DrvFltIp+4d22
Followup: MachineOwner
---------
0: kd> lmvm DrvFltIp
start end module name
f7877000 f787e200 DrvFltIp T (no symbols)
Loaded symbol image file: DrvFltIp
Image path: DrvFltIp
Image name: DrvFltIp
Timestamp: Thu Dec 21 07:04:51 2006 (4589E4BB)
CheckSum: 0000EE55
ImageSize: 00007200
Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0

That Dump doesn't really show the real causer in this situation as such or
in accurate way for troubleshooting!.
Read here:
DrvFltIp.sys is Spyware.SpySure.http://www.symantec.com/security_response/writeup.jsp?docid=2007-0920...

DrvFltIp encountered a error at BADFCD22 x BADF8000".http://forums.nvidia.com/lofiversion/index.php?t28205.html
HTH.
nass
---http://www.nasstec.co.uk

The Module_Name and The Stack Trace Shows "DrvFltIp" As The
Culprit .....

If You Have any Objections ... Then Provide Evidence In Support

yes .. It may be a trojan or spyware.

also the "lmvm" doesn't actually tells to what does "DrvFltIp" belongs
to ...so it may be a dodgy file....

So, I'm right about there is no Clear Cut from the Dump, I'm not objecting
as there is nothing to object , just an opinion to share.
I seen many dump that not accurate and corrupted , at best meaningless.
HTH.
nass
 
V

voja

hi all,
i have a same error msg appear on me out of a blue, nothing to do with
printing... actually, i think it appears once the computer is started when
being hibernated before, than a blue screen appears, forces a restart and
then upon booting this message comes up. I copied my minidump below in case
it can shed any light. Thanks in advance!
http://www.mediafire.com/?4uttandxadt
 
D

devil_himself

hi all,
i have a same error msg appear on me out of a blue, nothing to do with
printing... actually, i think it appears once the computer is started when
being hibernated before, than a blue screen appears, forces a restart and
then upon booting this message comes up. I copied my minidump below in case
it can shed any light. Thanks in advance!http://www.mediafire.com/?4uttandxadt

BugCheck 100000D1, {4, 2, 1, f8347ed0}
Probably caused by : tnet1130.sys ( tnet1130+70d ) <<<<---- TI ACX100
WLAN Driver

lmvm tnet1130
start end module name
f814f000 f81ad680 tnet1130 T (no symbols)
Loaded symbol image file: tnet1130.sys
Image path: tnet1130.sys
Image name: tnet1130.sys
Timestamp: Fri Jun 18 02:11:13 2004 (40D201E9) <<<------ 2
Years Behind , Update IT
CheckSum: 0006220E
ImageSize: 0005E680
Translations: 0000.04b0 0000.04e0 0409.04b0 0409.04e0
===================================================================================
 
G

Gerry

voja

FWIW relates to Linksys network card. Try updating driver from Linksys
suport site?


--



Hope this helps.

Gerry
~~~~
FCA
Stourport, England
Enquire, plan and execute
~~~~~~~~~~~~~~~~~~~
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads


Top