IRQL_NOT_LESS_OR_EQUAL - appears to be related to ntkrnlmp.exe

Anonymous
2020-03-24T03:24:57+00:00

Greetings,

I would be most grateful if someone would be able to help me determine the source of my system instability. First, some context:

I've had BSODs on a particular machine for some time now. I'm not sure exactly when/how they began, but they've been happening an awful lot lately when the system idles, or during use. I can't determine a specific trigger or event that causes them, but it's incredibly disruptive when they do happen, and I'd love to find a cure.

I've run Memtest86, Windows Memory Diagnostics, various HDD diagnostics, etc. and nothing I can find so far points to a hardware failure. I'm running the latest BIOS for my motherboard, although it's happened irrespective of BIOS version. I've tried upgrade-in-places, and clean installs of Windows 10, but all of it is so far to no avail. Most recently, I did a clean install once more, only to find the issue has persisted. I do have one dump file so far that I've shared here. I suspect it's a driver, but I can't figure out what driver it could be on my own. Your assistance is greatly appreciated!

WhoCrashed offers the following information:

Crash Dump Analysis

Crash dumps are enabled on your computer.

Crash dump directories:

C:\Windows

C:\Windows\Minidump

On Mon 3/23/2020 12:47:44 PM your computer crashed or a problem was reported

crash dump file: C:\Windows\Minidump\032320-9390-01.dmp

This was probably caused by the following module: ntoskrnl.exe (nt+0x1C2380)

Bugcheck code: 0xA (0xFFFF89018D47D990, 0xFF, 0xB, 0xFFFFF801326BBF2B)

Error: IRQL_NOT_LESS_OR_EQUAL

file path: C:\Windows\system32\ntoskrnl.exe

product: Microsoft® Windows® Operating System

company: Microsoft Corporation

description: NT Kernel & System

Bug check description: This indicates that Microsoft Windows or a kernel-mode driver accessed paged memory at DISPATCH_LEVEL or above. This is a software bug.

This bug check belongs to the crash dump test that you have performed with WhoCrashed or other software. It means that a crash dump file was properly written out.

The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.

On Mon 3/23/2020 12:47:44 PM your computer crashed or a problem was reported

crash dump file: C:\Windows\MEMORY.DMP

This was probably caused by the following module: ntkrnlmp.exe (nt!setjmpex+0x81A9)

Bugcheck code: 0xA (0xFFFF89018D47D990, 0xFF, 0xB, 0xFFFFF801326BBF2B)

Error: IRQL_NOT_LESS_OR_EQUAL

Bug check description: This indicates that Microsoft Windows or a kernel-mode driver accessed paged memory at DISPATCH_LEVEL or above. This is a software bug.

This bug check belongs to the crash dump test that you have performed with WhoCrashed or other software. It means that a crash dump file was properly written out.

The crash took place in the Windows kernel. Possibly this problem is caused by another driver that cannot be identified at this time.

Here is the summary from WinDBG:

*******************************************************************************

*                                                                             *

*                        Bugcheck Analysis                                    *

*                                                                             *

*******************************************************************************

IRQL_NOT_LESS_OR_EQUAL (a)

An attempt was made to access a pageable (or completely invalid) address at an

interrupt request level (IRQL) that is too high.  This is usually

caused by drivers using improper addresses.

If a kernel debugger is available get the stack backtrace.

Arguments:

Arg1: ffff89018d47d990, memory referenced

Arg2: 00000000000000ff, IRQL

Arg3: 000000000000000b, bitfield :

    bit 0 : value 0 = read operation, 1 = write operation

    bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)

Arg4: fffff801326bbf2b, address which referenced memory

Debugging Details:


KEY_VALUES_STRING: 1

PROCESSES_ANALYSIS: 1

SERVICE_ANALYSIS: 1

STACKHASH_ANALYSIS: 1

TIMELINE_ANALYSIS: 1

DUMP_CLASS: 1

DUMP_QUALIFIER: 401

BUILD_VERSION_STRING:  18362.1.amd64fre.19h1_release.190318-1202

SYSTEM_MANUFACTURER:  Micro-Star International Co., Ltd.

SYSTEM_PRODUCT_NAME:  MS-7C37

SYSTEM_SKU:  To be filled by O.E.M.

SYSTEM_VERSION:  2.0

BIOS_VENDOR:  American Megatrends Inc.

BIOS_VERSION:  A.70

BIOS_DATE:  01/09/2020

BASEBOARD_MANUFACTURER:  Micro-Star International Co., Ltd.

BASEBOARD_PRODUCT:  MPG X570 GAMING PLUS (MS-7C37)

BASEBOARD_VERSION:  2.0

DUMP_TYPE:  1

BUGCHECK_P1: ffff89018d47d990

BUGCHECK_P2: ff

BUGCHECK_P3: b

BUGCHECK_P4: fffff801326bbf2b

WRITE_ADDRESS:  ffff89018d47d990

CURRENT_IRQL:  0

FAULTING_IP:

nt!PpmIdlePrepare+31b

fffff801`326bbf2b 48897d80        mov     qword ptr [rbp-80h],rdi

CPU_COUNT: 10

CPU_MHZ: e10

CPU_VENDOR:  AuthenticAMD

CPU_FAMILY: 17

CPU_MODEL: 71

CPU_STEPPING: 0

BLACKBOXBSD: 1 (!blackboxbsd)

BLACKBOXNTFS: 1 (!blackboxntfs)

BLACKBOXPNP: 1 (!blackboxpnp)

BLACKBOXWINLOGON: 1

DEFAULT_BUCKET_ID:  WIN8_DRIVER_FAULT

BUGCHECK_STR:  AV

PROCESS_NAME:  System

ANALYSIS_SESSION_HOST:  DESKTOP-CDI8JLP

ANALYSIS_SESSION_TIME:  03-23-2020 19:54:15.0849

ANALYSIS_VERSION: 10.0.18362.1 amd64fre

TRAP_FRAME:  ffff89018c47d780 -- (.trap 0xffff89018c47d780)

NOTE: The trap frame does not contain all registers.

Some register values may be zeroed or incorrect.

rax=0000000000000000 rbx=0000000000000000 rcx=0000000000000007

rdx=00000061a74f2c01 rsi=0000000000000000 rdi=0000000000000000

rip=fffff801326bbf2b rsp=ffff89018c47d910 rbp=ffff89018d47da10

 r8=0000000000000000  r9=ffffce819a516180 r10=00000061a798718a

r11=ffffbe79d3c00000 r12=0000000000000000 r13=0000000000000000

r14=0000000000000000 r15=0000000000000000

iopl=0         nv up di pl nz ac po cy

nt!PpmIdlePrepare+0x31b:

fffff801326bbf2b 48897d80        mov     qword ptr [rbp-80h],rdi ss:0018:ffff89018d47d990=ffff8f8c9d7310c0

Resetting default scope

LAST_CONTROL_TRANSFER:  from fffff801327d41e9 to fffff801327c2380

STACK_TEXT: 

ffff89018c47d638 fffff801327d41e9 : 000000000000000a ffff89018d47d990 00000000000000ff 000000000000000b : nt!KeBugCheckEx

ffff89018c47d640 fffff801327d052b : 0000000000000000 0000000000000000 000000000028f578 0000000000000000 : nt!KiBugCheckDispatch+0x69

ffff89018c47d780 fffff801326bbf2b : 00000061a74f5299 0000000000989680 ffff89018c47da10 ffffce819a516180 : nt!KiPageFault+0x46b

ffff89018c47d910 fffff801326bac66 : 0000000000000003 0000000000000002 ffff8f8c97806100 0000000000000008 : nt!PpmIdlePrepare+0x31b

ffff89018c47db00 fffff801327c5e88 : ffffffff00000000 ffffce819a516180 ffff8f8ca71ee080 00000000000006e4 : nt!PoIdle+0x1e6

ffff89018c47dc60 0000000000000000 : ffff89018c47e000 ffff89018c478000 0000000000000000 0000000000000000 : nt!KiIdleLoop+0x48

THREAD_SHA1_HASH_MOD_FUNC:  bac30f8031bbad40506eeaabc9b982d6623c8637

THREAD_SHA1_HASH_MOD_FUNC_OFFSET:  06372c5c8e03168aff9eb00044cd61dcaa3f5946

THREAD_SHA1_HASH_MOD:  ee8fcf1fb60cb6e3e2f60ddbed2ec02b5748a693

FOLLOWUP_IP:

nt!PpmIdlePrepare+31b

fffff801`326bbf2b 48897d80        mov     qword ptr [rbp-80h],rdi

FAULT_INSTR_CODE:  807d8948

SYMBOL_STACK_INDEX:  3

SYMBOL_NAME:  nt!PpmIdlePrepare+31b

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: nt

IMAGE_NAME:  ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP:  0

STACK_COMMAND:  .thread ; .cxr ; kb

BUCKET_ID_FUNC_OFFSET:  31b

FAILURE_BUCKET_ID:  AV_CODE_AV_nt!PpmIdlePrepare

BUCKET_ID:  AV_CODE_AV_nt!PpmIdlePrepare

PRIMARY_PROBLEM_CLASS:  AV_CODE_AV_nt!PpmIdlePrepare

TARGET_TIME:  2020-03-23T18:47:44.000Z

OSBUILD:  18362

OSSERVICEPACK:  0

SERVICEPACK_NUMBER: 0

OS_REVISION: 0

SUITE_MASK:  272

PRODUCT_TYPE:  1

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

OSEDITION:  Windows 10 WinNt TerminalServer SingleUserTS

OS_LOCALE: 

USER_LCID:  0

OSBUILD_TIMESTAMP:  unknown_date

BUILDDATESTAMP_STR:  190318-1202

BUILDLAB_STR:  19h1_release

BUILDOSVER_STR:  10.0.18362.1.amd64fre.19h1_release.190318-1202

ANALYSIS_SESSION_ELAPSED_TIME:  2501

ANALYSIS_SOURCE:  KM

FAILURE_ID_HASH_STRING:  km:av_code_av_nt!ppmidleprepare

FAILURE_ID_HASH:  {0722116b-c23b-c6c2-0c96-05693152d11a}

Followup:     MachineOwner


Windows for home | Windows 10 | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

41 answers

Sort by: Oldest
  1. Anonymous
    2020-04-06T07:20:43+00:00

    Do not run Driver Verifier all the time as it can cause instability when there would otherwise be none. 

    Very happy to help.

    Rob - SpiritX

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2020-04-06T07:36:03+00:00

    Understood! I have not run it at all since we last spoke, as I was waiting to see if the system would BSOD on its own as had been happening in the past. Since uninstalling the MSI software, this has not happened, but I thought it would be a good idea to run Driver Verifier to see if anything else turns up. :-)

    Will keep you posted! Thanks again, Rob.

    Best,

    Tony

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2020-04-06T18:27:15+00:00

    I think this one is resolved. Excellent troubleshooting!

    Glad to have helped, and stay well......

    Rob - SpiritX

    "I never thought I'd ever have my freedom

    An age ago my maker was refusing me

    The pleasure of the view"

    - The Moody Blues

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2020-04-08T00:59:33+00:00

    Thank you, Rob!

    Can I trouble you with (hopefully) one last question?

    Just as I was about to do one final, clean install of Windows 10...the system BlueScreened, as if on cue! Driver Verifier was running at the time (I haven't had it running for more than 2 days...I think it's been running for about a day). The StopCode was CRITICAL_PROCESS_DIED.

    It looks like ntdll.sys was at least partially responsible for the crash, but I'd be very grateful if you'd be able to take a look. (I just don't want to risk missing a potential cause, but perhaps it was a completely unrelated issue — perhaps even with the Windows install itself and/or Driver Verifier.)

    https://send.firefox.com/download/3e2a281fca8d7b13/#zrJ2vgFNNLQeXg_z-52kNg

    Thank you, Rob! Be well.

    Best,

    Tony

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2020-04-08T01:41:41+00:00

    Do not run DV all the time as it can cause instability when there would otherwise be none.

    BugCheck EF, {ffffca0d8e01d2c0, 0, 0, 0}

    Probably caused by : RPCRT4.dll

    RPCRT4.dll is a Windows component which means something else drove it into Fault.

    BugCheck EF is another one that is most often a hardware problem. Could be heat related.

    Further analysis did not help which is not surprising.

    BCCode: EF    0x0000000EF  <-- read this link

    https://tinyurl.com/uacwe5n

    Double check all the seating on everything. Especially the new GPU.

    Do you have enough cooling.

    Troubleshoot blue screen errors <-- read this link ****http://windows.microsoft.com/en-us/windows-10/troubleshoot-blue-screen-errors

    Rob - SpiritX

    Was this answer helpful?

    0 comments No comments