Hello Ivona,
Yup,this is a disk encryption driver, and im
encrypting a particular partition.
No, Im not passing the request down.Im just parsing
the data in the dispatch routine and I free the buffer
thereitself.
This is the Debug info....(VSI)
BUGCHECK: a IRQL_NOT_LESS_OR_EQUAL
An attempt was made to touch pageable memory at an
IRQL that is too high.
Parameter 1 : 00000000 Memory Address referenced
Parameter 2 : 00000002 IRQL at fault
Parameter 3 : 00000001 Write access attempt
Parameter 4 : 8046b0de Address of instruction
executing (if known)
Probably caused by : ntoskrnl!KiTrap0E+27c
TrapFrame Address : 80473628
Context Instruction
Ptr Stack Ptr Frame Ptr Parameters
Function Table
Status
ntoskrnl!KiTrap0E+27c 8046856f
80473614 80473628
TRAP|Params:0|Registers Saved:0|#Locals:0|EBP
Allocated:0
ntoskrnl!ExFreePoolWithTag+32a 8046b0de
8047369c 804736c0
EBP |Params:2|Registers Saved:3|#Locals:6|EBP
Allocated:1
ntoskrnl!ExFreePool+b 8046ace2
804736c8 804736cc 810e0ca8,
FPO |Params:1|Registers Saved:0|#Locals:0|EBP
Allocated:0
BCHKD!_Section.text+14cdc bff7115c
804736d4 80473704 8396e000,1000,0,8396e000,
EBP
diskenc!FilterReadCompletionRoutine+80 eb818d80
8047370c 80473730 81fc49c0,810daa28,0,811a40e8,
EBP
Couldn't find call instruction preceding return
location.
Stack Frame Information for ntoskrnl!KiTrap0E+27c on
thread(0)
Count: 16
Name Value
eax 0
ebx 0
ecx 0
edx 0
esi 0
edi 0
eip 8046856f
esp 80473614
ebp 80473628
eflags 0
cs 0
ds 0
es 0
fs 0
gs 0
ss 0
ntoskrnl!KiTrap0E+27c
8046856f test
dword ptr [ebp + 70], 00020000
80468576 jz
80468585 // ntoskrnl!KiTrap0E+292
80468578 cmp
dword ptr [8046e42c], 00
8046857f jnz
80468391 // ntoskrnl!KiTrap0E+9e
80468585 cmp
dword ptr [80481c44], 00
8046858c jnz
80468391 // ntoskrnl!KiTrap0E+9e
80468592 cmp
dword ptr [804822a0], 00
80468599 jnz
80468391 // ntoskrnl!KiTrap0E+9e
8046859f mov eax,
000000ff
804685a4 jmp
80468552 // ntoskrnl!KiTrap0E+25f
804685a6 mov eax,
[ffdff052]
804685ab mov byte
ptr [ffdff052], 00
804685b2 cmp al,
0d
804685b4 jnz
804685bd // ntoskrnl!KiTrap0E+2ca
804685b6 mov eax,
80467bc7
804685bb jmp
804685d6 // ntoskrnl!KiTrap0E+2e3
804685bd cmp al,
10
804685bf jnz
804685c8 // ntoskrnl!KiTrap0E+2d5
I will do some further debugging and get back to you.
Cheers and Regards
V.S.
Do you Yahoo!?
Yahoo! Mail - You care about security. So do we.