Please Help! Irql_not_less_or_equal BSOD

Jamesdean621

Reputable
Sep 4, 2015
5
0
4,510
My new computer has been crashing with the error "IRQL_NOT_LESS_OR_EQUAL". My computer randomly freezes with the BSOD then it just crashes and says "IRQL_NOT_LESS_OR_EQUAL". I know that you need my dump files and they are prepared and zipped but I don't see where I can upload them here. Please advise.

System Specs:
CPU- Intel Core i7 920 2.67GHz
Ram- 12 GB Kingston Hyperx Fury Blue 1600mhz Ddr3 4 Gb x 3
Graphics Card- NVIDIA GeForce 9600
Storage- 250GB Samsung SSD
Motherboard: Gigabyte EX58 - UD3R v1.1

 

Jamesdean621

Reputable
Sep 4, 2015
5
0
4,510


Thank you for the links. These are ones that I have run across but fail to address my specific issue. The first link is for windows 7 and the last link is an ad for repair software.
What I think I need is for someone to look at my dump files to see where my computer is having the issues causing the BSOD.

 
you have to make an account on a cloud server like mediafire or Microsoft onedrive, then copy the files to the server, mark the files as public access then post a link to the file so it can be looked at.

The default location for a memory dump file will be c:\windows\minidump directory.
You can also use an automated memory dump viewer, google whocrashed.exe or bluescreenview.exe. Often these will tell you the driver name that failed, You then look up the driver at http://www.carrona.org/drivers/driver.php?id=atikmdag.sys
it should tell you who makes the driver and where to get a update.

if the driver name is a Microsoft owned component, you most likely have to turn on debug flags to find out the true cause of the failures or have someone look at the memory dump to tell you the true or likely cause of the bugcheck.
 

Jamesdean621

Reputable
Sep 4, 2015
5
0
4,510


Here is the dump file I was able to upload to OneDrive.
https://onedrive.live.com/redir?resid=19AEBE3C3F938AD8!557&authkey=!AOHKspPW9FvuM8U&ithint=file%2cdmp
 
windows memory was corrupted, the data that maps the location of data from your pagefile.sys to where it is placed in memory (ram) was written over by some driver. (I don't see a reason for the corruption)

My guess would be this driver:WinDivert.sys it is a network packet injector, used to steal passwords and to cheat on online games.

I would also update your Realtek PCI/PCIe Adapters
\SystemRoot\system32\DRIVERS\Rt630x64.sys Fri May 10 02:59:08 2013
looks like gigabyte put a current driver under windows 7 64 bit.
dated 2015/04/16 http://www.gigabyte.com/products/product-page.aspx?pid=2989#driver
I would pick it up and run it. The fixes in the network driver help nvidia graphics streaming, streamin games and helps with virus scanners.

Looks like you have old versions of bitdefender from 2013
I would remove it and install a updated version.

machine info:
Vendor Award Software International, Inc.
BIOS Version F2q
BIOS Starting Address Segment e000
BIOS Release Date 03/11/2011
Manufacturer Gigabyte Technology Co., Ltd.
Product Name EX58-UD3R
Socket Designation Socket 1366
Processor Type Central Processor
Processor Family 01h - Other
Processor Manufacturer Intel
Processor ID a5060100fffbebbf
Processor Version Intel(R) Core(TM) i7 CPU
Processor Voltage 8ah - 1.0V
External Clock 133MHz
Max Speed 4000MHz
Current Speed 2800MHz


 

Jamesdean621

Reputable
Sep 4, 2015
5
0
4,510


Thanks for the great info John! Do you think that the problem may lie with my motherboard? I went on Gigabyte's website to download the drivers and this model does not have drivers for Windows 8 or 10.

What should I do about the WinDivert.sys?
 
I think your motherboard is going to be fine, just old
most likely you don't have to get the network driver from gigabyte, it is a common Realtek chip
you have to look at your motherboard specs, find the name and chip number for you ethernet chip then go to
http://www.realtek.com.tw/downloads/downloadsView.aspx?Langid=1&PNid=7&PFid=10&Level=3&Conn=2
and find the chip and load the current driver.

or use the gigabyte windows 7 driver and run windows control panel, device manager, find the device and tell it not to sleep.
(may not even be a problem, but sleep mode problems were common with windows 7 device drivers)

-----------
remove the windivert.sys unless you actually use it. Sometimes it gets installed as part of a malware infection.
Other times it is just used in programs to speed up and help your online games. IE, they delay your characters position data so your game image and your game position don't match and other players can not shoot you unless you don't move for 3 seconds. (or they have to shoot way in front of your image in the game)
in any case it is pretty common for windivert to mess up network drivers and corrupt memory.
it can also be used to steal passwords from your machine. Bank passwords, online game passwords...
people get your password and take what they can from your accounts.



 

Jamesdean621

Reputable
Sep 4, 2015
5
0
4,510


OK, so I've removed WinDivert and updated to the latest Realtek driver for Windows 8 but I'm still getting the BSOD but now its a Service Exception Error instead of the IRQL I was getting before. Any ideas?
 
I would have to see the memory dump, the bugcheck just indicates that a required service shutdown.
in the bugcheck data it will have a error code that may indicate why the service shutdown.
generally, a required service will shutdown if it becomes corrupted or its data becomes corrupted.
There can be many reasons why this happens (hardware and software).\
- malware attacks certain required files, the system detects the changes and shutsdown. do a malwarebytes scan.
(many virus scans will not report malware if you accepted the license agreement during some install) Malwarebytes just reports/fixes them anyway.

-on older machines, dust in the fans can slow down the fan enough to cause a CPU to overheat.
same with older power supply fans, can cause the voltage to change. (i have "fixed" many machines by blowing out dust)

- Solid state drives can have firmware problems that require you to boot into BIOS and leave the system powered on but idle so the firmware can move data off of failing blocks.
- BIOS can be set to overclock memory and cause binary files and data in memory to be written incorrectly. The service detects the corrupt data and shuts down. (reset BIOS to defaults)

- older machines like the generation you have were the first to start using the new lead free solder, this solder was brittle and can pop from circuit boards and causes various problems that show up as the system heats up and cools.
(just very hard to find)