IRQL_NOT_LESS_OR_EQUAL - appears to be related to ntkrnlmp.exe

Anonymous
2020-03-24T03:24:57+00:00

Greetings,

I would be most grateful if someone would be able to help me determine the source of my system instability. First, some context:

I've had BSODs on a particular machine for some time now. I'm not sure exactly when/how they began, but they've been happening an awful lot lately when the system idles, or during use. I can't determine a specific trigger or event that causes them, but it's incredibly disruptive when they do happen, and I'd love to find a cure.

I've run Memtest86, Windows Memory Diagnostics, various HDD diagnostics, etc. and nothing I can find so far points to a hardware failure. I'm running the latest BIOS for my motherboard, although it's happened irrespective of BIOS version. I've tried upgrade-in-places, and clean installs of Windows 10, but all of it is so far to no avail. Most recently, I did a clean install once more, only to find the issue has persisted. I do have one dump file so far that I've shared here. I suspect it's a driver, but I can't figure out what driver it could be on my own. Your assistance is greatly appreciated!

WhoCrashed offers the following information:

Crash Dump Analysis

Crash dumps are enabled on your computer.

Crash dump directories:

C:\Windows

C:\Windows\Minidump

On Mon 3/23/2020 12:47:44 PM your computer crashed or a problem was reported

crash dump file: C:\Windows\Minidump\032320-9390-01.dmp

This was probably caused by the following module: ntoskrnl.exe (nt+0x1C2380)

Bugcheck code: 0xA (0xFFFF89018D47D990, 0xFF, 0xB, 0xFFFFF801326BBF2B)

Error: IRQL_NOT_LESS_OR_EQUAL

file path: C:\Windows\system32\ntoskrnl.exe

product: Microsoft® Windows® Operating System

company: Microsoft Corporation

description: NT Kernel & System

Bug check description: This indicates that Microsoft Windows or a kernel-mode driver accessed paged memory at DISPATCH_LEVEL or above. This is a software bug.

This bug check belongs to the crash dump test that you have performed with WhoCrashed or other software. It means that a crash dump file was properly written out.

The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.

On Mon 3/23/2020 12:47:44 PM your computer crashed or a problem was reported

crash dump file: C:\Windows\MEMORY.DMP

This was probably caused by the following module: ntkrnlmp.exe (nt!setjmpex+0x81A9)

Bugcheck code: 0xA (0xFFFF89018D47D990, 0xFF, 0xB, 0xFFFFF801326BBF2B)

Error: IRQL_NOT_LESS_OR_EQUAL

Bug check description: This indicates that Microsoft Windows or a kernel-mode driver accessed paged memory at DISPATCH_LEVEL or above. This is a software bug.

This bug check belongs to the crash dump test that you have performed with WhoCrashed or other software. It means that a crash dump file was properly written out.

The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.

Here is the summary from WinDBG:

*******************************************************************************

*                                                                             *

*                        Bugcheck Analysis                                    *

*                                                                             *

*******************************************************************************

IRQL_NOT_LESS_OR_EQUAL (a)

An attempt was made to access a pageable (or completely invalid) address at an

interrupt request level (IRQL) that is too high.  This is usually

caused by drivers using improper addresses.

If a kernel debugger is available get the stack backtrace.

Arguments:

Arg1: ffff89018d47d990, memory referenced

Arg2: 00000000000000ff, IRQL

Arg3: 000000000000000b, bitfield :

    bit 0 : value 0 = read operation, 1 = write operation

    bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)

Arg4: fffff801326bbf2b, address which referenced memory

Debugging Details:


KEY_VALUES_STRING: 1

PROCESSES_ANALYSIS: 1

SERVICE_ANALYSIS: 1

STACKHASH_ANALYSIS: 1

TIMELINE_ANALYSIS: 1

DUMP_CLASS: 1

DUMP_QUALIFIER: 401

BUILD_VERSION_STRING:  18362.1.amd64fre.19h1_release.190318-1202

SYSTEM_MANUFACTURER:  Micro-Star International Co., Ltd.

SYSTEM_PRODUCT_NAME:  MS-7C37

SYSTEM_SKU:  To be filled by O.E.M.

SYSTEM_VERSION:  2.0

BIOS_VENDOR:  American Megatrends Inc.

BIOS_VERSION:  A.70

BIOS_DATE:  01/09/2020

BASEBOARD_MANUFACTURER:  Micro-Star International Co., Ltd.

BASEBOARD_PRODUCT:  MPG X570 GAMING PLUS (MS-7C37)

BASEBOARD_VERSION:  2.0

DUMP_TYPE:  1

BUGCHECK_P1: ffff89018d47d990

BUGCHECK_P2: ff

BUGCHECK_P3: b

BUGCHECK_P4: fffff801326bbf2b

WRITE_ADDRESS:  ffff89018d47d990

CURRENT_IRQL:  0

FAULTING_IP:

nt!PpmIdlePrepare+31b

fffff801`326bbf2b 48897d80        mov     qword ptr [rbp-80h],rdi

CPU_COUNT: 10

CPU_MHZ: e10

CPU_VENDOR:  AuthenticAMD

CPU_FAMILY: 17

CPU_MODEL: 71

CPU_STEPPING: 0

BLACKBOXBSD: 1 (!blackboxbsd)

BLACKBOXNTFS: 1 (!blackboxntfs)

BLACKBOXPNP: 1 (!blackboxpnp)

BLACKBOXWINLOGON: 1

DEFAULT_BUCKET_ID:  WIN8_DRIVER_FAULT

BUGCHECK_STR:  AV

PROCESS_NAME:  System

ANALYSIS_SESSION_HOST:  DESKTOP-CDI8JLP

ANALYSIS_SESSION_TIME:  03-23-2020 19:54:15.0849

ANALYSIS_VERSION: 10.0.18362.1 amd64fre

TRAP_FRAME:  ffff89018c47d780 -- (.trap 0xffff89018c47d780)

NOTE: The trap frame does not contain all registers.

Some register values may be zeroed or incorrect.

rax=0000000000000000 rbx=0000000000000000 rcx=0000000000000007

rdx=00000061a74f2c01 rsi=0000000000000000 rdi=0000000000000000

rip=fffff801326bbf2b rsp=ffff89018c47d910 rbp=ffff89018d47da10

 r8=0000000000000000  r9=ffffce819a516180 r10=00000061a798718a

r11=ffffbe79d3c00000 r12=0000000000000000 r13=0000000000000000

r14=0000000000000000 r15=0000000000000000

iopl=0         nv up di pl nz ac po cy

nt!PpmIdlePrepare+0x31b:

fffff801326bbf2b 48897d80        mov     qword ptr [rbp-80h],rdi ss:0018:ffff89018d47d990=ffff8f8c9d7310c0

Resetting default scope

LAST_CONTROL_TRANSFER:  from fffff801327d41e9 to fffff801327c2380

STACK_TEXT: 

ffff89018c47d638 fffff801327d41e9 : 000000000000000a ffff89018d47d990 00000000000000ff 000000000000000b : nt!KeBugCheckEx

ffff89018c47d640 fffff801327d052b : 0000000000000000 0000000000000000 000000000028f578 0000000000000000 : nt!KiBugCheckDispatch+0x69

ffff89018c47d780 fffff801326bbf2b : 00000061a74f5299 0000000000989680 ffff89018c47da10 ffffce819a516180 : nt!KiPageFault+0x46b

ffff89018c47d910 fffff801326bac66 : 0000000000000003 0000000000000002 ffff8f8c97806100 0000000000000008 : nt!PpmIdlePrepare+0x31b

ffff89018c47db00 fffff801327c5e88 : ffffffff00000000 ffffce819a516180 ffff8f8ca71ee080 00000000000006e4 : nt!PoIdle+0x1e6

ffff89018c47dc60 0000000000000000 : ffff89018c47e000 ffff89018c478000 0000000000000000 0000000000000000 : nt!KiIdleLoop+0x48

THREAD_SHA1_HASH_MOD_FUNC:  bac30f8031bbad40506eeaabc9b982d6623c8637

THREAD_SHA1_HASH_MOD_FUNC_OFFSET:  06372c5c8e03168aff9eb00044cd61dcaa3f5946

THREAD_SHA1_HASH_MOD:  ee8fcf1fb60cb6e3e2f60ddbed2ec02b5748a693

FOLLOWUP_IP:

nt!PpmIdlePrepare+31b

fffff801`326bbf2b 48897d80        mov     qword ptr [rbp-80h],rdi

FAULT_INSTR_CODE:  807d8948

SYMBOL_STACK_INDEX:  3

SYMBOL_NAME:  nt!PpmIdlePrepare+31b

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP:  0

STACK_COMMAND:  .thread ; .cxr ; kb

BUCKET_ID_FUNC_OFFSET:  31b

FAILURE_BUCKET_ID:  AV_CODE_AV_nt!PpmIdlePrepare

BUCKET_ID:  AV_CODE_AV_nt!PpmIdlePrepare

PRIMARY_PROBLEM_CLASS:  AV_CODE_AV_nt!PpmIdlePrepare

TARGET_TIME:  2020-03-23T18:47:44.000Z

OSBUILD:  18362

OSSERVICEPACK:  0

SERVICEPACK_NUMBER: 0

OS_REVISION: 0

SUITE_MASK:  272

PRODUCT_TYPE:  1

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

OSEDITION:  Windows 10 WinNt TerminalServer SingleUserTS

OS_LOCALE: 

USER_LCID:  0

OSBUILD_TIMESTAMP:  unknown_date

BUILDDATESTAMP_STR:  190318-1202

BUILDLAB_STR:  19h1_release

BUILDOSVER_STR:  10.0.18362.1.amd64fre.19h1_release.190318-1202

ANALYSIS_SESSION_ELAPSED_TIME:  2501

ANALYSIS_SOURCE:  KM

FAILURE_ID_HASH_STRING:  km:av_code_av_nt!ppmidleprepare

FAILURE_ID_HASH:  {0722116b-c23b-c6c2-0c96-05693152d11a}

Followup:     MachineOwner


Windows for home | Windows 10 | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

41 answers

Sort by: Newest
  1. Anonymous
    2020-03-24T04:04:08+00:00

    Hi PerpetualPlusOne, I am Rob, an independent and a 14 time and dual award MVP specializing in Windows troubleshooting and Bluescreen analysis. Please remember as independents we are not responsible for the development of Windows or the computer hardware and drivers. If you will work with me I will be here to help until the issue is resolved. And your issue is right up my alley.

    The above shows the cause as IMAGE_NAME: ntkrnlmp.exe <-- is a Windows component which means something else drove it into Fault.

    Analyzing minidumps rarely helps with hardware caused issues and even when it does (for BugCheck 124 & a couple of others) no specific hardware is pointed out.

    Is this system still under warranty?

    Since the computer is new and still under warranty please contact System Maker's Support and the seller. As OEM they are responsible for the proper operation of both the hardware and Windows. So regardless of the cause it is theirs to resolve. And the unit is under full warranty and may be in need of repairs or replacement. Added that even if you are able to resolve the issue you would want it fully documented just in case there are related problems down the road. Remember the more you do the more they will say it is something you have done.

    If a home build you should contact MSI Support and as well as the other device makers' supports (such as GPU, PSU, memory, and others).

    Troubleshoot blue screen errors <-- read this link

    http://windows.microsoft.com/en-us/windows-10/t...

    =======

    You have Clean Installed Windows so that removes virtually all the possible software causes (drivers) leaving only hardware.

    You ran memtest86 - did you let it run for 4+ hours (and over-night is best). Also, try running with minimum RAM, in different combinations, to see if that helps.

    If that works : Memory tests do not catch all issues such as the tiny speed differences that can occur between even matched sets of memory. Faster always has to be in front of slow so try different combinations and patterns.

    ======

    Have you tried these :

    Running OCCT for Home Use (Free) may help indicate a cause.

    OCCT - Free for Home use

    https://www.ocbase.com/

    Running Stress Tests might help indicate a cause - use ALL of these.

    PC Stress Test free software for Windows 10

    https://www.thewindowsclub.com/pc-stress-test-f...

    =======

    To double check drivers try running Driver Verifier.

    Driver Verifier can help find some BSOD issues :

    Using Driver Verifier to identify issues with Windows drivers for advanced users

    http://support.microsoft.com/kb/244617

    How To Troubleshoot Driver Problems in Windows Vista or 7. (8/8.1 and 10

    are essentially the same).

    http://www.winvistaclub.com/t79.html

    Using Driver Verifier

    https://msdn.microsoft.com/en-us/library/window...

    WINKEY + X - RUN - type in -> verifier /reset hit enter to disable

    If Driver Verifier creates a minidump upload it and post the link here so we can

    analyze it.

    Here to help,

    Rob


    Standard Disclaimer: Those may be non-Microsoft websites. The pages appear to be providing accurate, safe information. Watch out for ads on the site that may advertise products frequently classified as a PUP (Potentially Unwanted Products). Thoroughly research any product advertised on the site before you decide to download and install it.

    Please let us know the results and if you need further assistance. Feedback definitely helps us help all.

    Was this answer helpful?

    0 comments No comments