question

SmithColeJ-1432 avatar image
0 Votes"
SmithColeJ-1432 asked Docs-4663 answered

DRIVER_VERIFIER_DMA_VIOLATION (e6) BSOD yet driver verifier is disabled

I get this crash very frequently on my Windows 10 computer. I've turned off the driver verifier and have done every scan recommended to me by various websites, yet nothing has turned up. This crash mostly comes while playing video games on my computer and before it goes to the blue screen, these small diagonal lines of gray squares cover my screen and then it crashes. I have the Windbg analysis of my dump file from the most recent crash. Thanks for any help you can give, i've been working on this for about a month at this point.



  •                      Bugcheck Analysis                                    *
    



DRIVER_VERIFIER_DMA_VIOLATION (e6)
An illegal DMA operation was attempted by a driver being verified.
Arguments:
Arg1: 0000000000000026, IOMMU detected DMA violation.
Arg2: 0000000000000000, Device Object of faulting device.
Arg3: 0000000008c7286c, Faulting information (usually faulting physical address).
Arg4: 0000000000000004, Fault type (hardware specific).

Debugging Details:




KEY_VALUES_STRING: 1

 Key  : Analysis.CPU.mSec
 Value: 1671

 Key  : Analysis.DebugAnalysisManager
 Value: Create

 Key  : Analysis.Elapsed.mSec
 Value: 1669

 Key  : Analysis.Init.CPU.mSec
 Value: 468

 Key  : Analysis.Init.Elapsed.mSec
 Value: 18225

 Key  : Analysis.Memory.CommitPeak.Mb
 Value: 86

 Key  : WER.OS.Branch
 Value: vb_release

 Key  : WER.OS.Timestamp
 Value: 2019-12-06T14:06:00Z

 Key  : WER.OS.Version
 Value: 10.0.19041.1


FILE_IN_CAB: Minidump

BUGCHECK_CODE: e6

BUGCHECK_P1: 26

BUGCHECK_P2: 0

BUGCHECK_P3: 8c7286c

BUGCHECK_P4: 4

BLACKBOXBSD: 1 (!blackboxbsd)


BLACKBOXNTFS: 1 (!blackboxntfs)


BLACKBOXPNP: 1 (!blackboxpnp)


BLACKBOXWINLOGON: 1

PROCESS_NAME: System

STACK_TEXT:
fffff805`38c7eea8 fffff805`356dba57 : 00000000`000000e6 00000000`00000026 00000000`00000000 00000000`08c7286c : nt!KeBugCheckEx
fffff805`38c7eeb0 fffff805`356c74fb : 00000000`00000000 00000000`00000000 fffff805`35e49bf0 fffff805`35e49bf0 : nt!IvtHandleInterrupt+0x1a7
fffff805`38c7ef10 fffff805`354de215 : fffff805`35ef3a80 fffff805`38c6f410 fffff805`35ef3b30 fffff805`38c7efc0 : nt!HalpIommuInterruptRoutine+0x4b
fffff805`38c7ef40 fffff805`355f921c : fffff805`38c6f410 fffff805`35ef3a80 00000000`00000242 fffff805`355f934a : nt!KiCallInterruptServiceRoutine+0xa5
fffff805`38c7ef90 fffff805`355f9627 : fffff805`38c6f4b0 00000000`00000001 00000000`00040046 fffff805`35417138 : nt!KiInterruptSubDispatchNoLock+0x11c
fffff805`38c6f390 fffff805`355fb3ca : 00000000`00000000 fffff805`35f27a00 ffff808f`5b4ae080 00000000`00000242 : nt!KiInterruptDispatchNoLock+0x37
fffff805`38c6f520 00000000`00000000 : fffff805`38c70000 fffff805`38c69000 00000000`00000000 00000000`00000000 : nt!KiIdleLoop+0x5a


SYMBOL_NAME: nt!IvtHandleInterrupt+1a7

MODULE_NAME: nt

IMAGE_NAME: ntkrnlmp.exe

STACK_COMMAND: .cxr; .ecxr ; kb

BUCKET_ID_FUNC_OFFSET: 1a7

FAILURE_BUCKET_ID: 0xE6_nt!IvtHandleInterrupt

OS_VERSION: 10.0.19041.1

BUILDLAB_STR: vb_release

OSPLATFORM_TYPE: x64

OSNAME: Windows 10

FAILURE_ID_HASH: {2cafa897-b47c-7b20-cee6-b1b68f30ec38}

Followup: MachineOwner


windows-10-general
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Docs-4663 avatar image
0 Votes"
Docs-4663 answered

Please run the V2 log collector and post a share link into this thread using one drive, drop box, or google drive.

https://www.tenforums.com/bsod-crashes-debugging/2198-bsod-posting-instructions.html

https://www.elevenforum.com/t/bsod-posting-instructions.103/


Also run this bat file: (bat files by design trigger AV and require a manual override)

https://www.tenforums.com/attachments/bsod-crashes-debugging/360137d1645183388-batch-files-use-bsod-debugging-tuneup_plus_log.bat


.
.
.
.
.

Please remember to vote and to mark the replies as answers if they help.

On the bottom of each post there is:

Propose as answer = answered the question

On the left side of each post there is /\ with a number: click = a helpful post
.
.
.
.
.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

SmithColeJ-1432 avatar image
0 Votes"
SmithColeJ-1432 answered SmithColeJ-1432 commented

Here is the information from the bat file

Microsoft Windows 10 Home Version 21H2 (OS Build 19044.1645)

==================================================================

 Started on Mon 05/09/2022 at 10:01:54.21 
    
     [SFC /ScanNow] 

Beginning system scan. This process will take some time.

Results:


Windows Resource Protection did not find any integrity violations.


==================================================================

 Started on Mon 05/09/2022 at 10:03:15.85 

     [DISM /online /cleanup-image /ScanHealth] 

Deployment Image Servicing and Management tool
Version: 10.0.19041.844

Image Version: 10.0.19044.1645


No component store corruption detected.

The operation completed successfully.


==================================================================

 Started on Mon 05/09/2022 at 10:04:29.31 

     [DISM /online /cleanup-image /RestoreHealth] 

Deployment Image Servicing and Management tool
Version: 10.0.19041.844

Image Version: 10.0.19044.1645


The restore operation completed successfully.

The operation completed successfully.


==================================================================

The second "SFC /ScanNow" was skipped, as the first output the following:

Windows Resource Protection did not find any integrity violations.


==================================================================

 Started on Mon 05/09/2022 at 10:05:51.03 

     [ChkDsk /Scan]  

The type of the file system is NTFS.
Volume label is Windows.


Stage 1: Examining basic file system structure ...
776192 file records processed.
File verification completed.
Phase duration (File record verification): 5.58 seconds.
23358 large file records processed.
Phase duration (Orphan file record recovery): 0.00 milliseconds.
0 bad file records processed.
Phase duration (Bad file record checking): 0.05 milliseconds.


Stage 2: Examining file name linkage ...
384 reparse records processed.
1063882 index entries processed.
Index verification completed.
Phase duration (Index verification): 10.91 seconds.
0 unindexed files scanned.
Phase duration (Orphan reconnection): 3.48 seconds.
0 unindexed files recovered to lost and found.
Phase duration (Orphan recovery to lost and found): 0.33 milliseconds.
384 reparse records processed.
Phase duration (Reparse point and Object ID verification): 2.88 milliseconds.


Stage 3: Examining security descriptors ...
Security descriptor verification completed.
Phase duration (Security descriptor verification): 43.06 milliseconds.
143846 data files processed.
Phase duration (Data attribute verification): 0.08 milliseconds.
CHKDSK is verifying Usn Journal...
34475464 USN bytes processed.
Usn Journal verification completed.
Phase duration (USN journal verification): 60.78 milliseconds.

Windows has scanned the file system and found no problems.

No further action is required.


487651327 KB total disk space.
328696204 KB in 515351 files.
284684 KB in 143847 indexes.
0 KB in bad sectors.
902139 KB in use by the system.
65536 KB occupied by the log file.
157768300 KB available on disk.


4096 bytes in each allocation unit.
121912831 total allocation units on disk.
39442075 allocation units available on disk.
Total duration: 20.10 seconds (20101 ms).


==================================================================


 Started on Mon 05/09/2022 at 10:06:17.62 

AutoReboot


FALSE


==================================================================


     [Set AutoReboot = False] 

Updating property(s) of '\\DESKTOP-BQO86TB\ROOT\CIMV2:Win32_OSRecoveryConfiguration.Name="Microsoft Windows 10 Home|C:\\WINDOWS|\\Device\\Harddisk1\\Partition4"'

Property(s) update successful.

==================================================================


AutoReboot


FALSE


==================================================================


DebugInfoType


7


==================================================================

     [Set DebugInfoType = 7]

Updating property(s) of '\\DESKTOP-BQO86TB\ROOT\CIMV2:Win32_OSRecoveryConfiguration.Name="Microsoft Windows 10 Home|C:\\WINDOWS|\\Device\\Harddisk1\\Partition4"'

Property(s) update successful.

==================================================================


DebugInfoType


7


==================================================================

     [WMIC PageFile list]

AllocatedBaseSize=13312
CurrentUsage=272
Description=C:\pagefile.sys
InstallDate=20220228145006.631161-480
Name=C:\pagefile.sys
PeakUsage=597
Status=
TempPageFile=FALSE


==================================================================


AutomaticManagedPagefile


TRUE


==================================================================

     [Set AutomaticManagedPagefile = True]

Updating property(s) of '\\DESKTOP-BQO86TB\ROOT\CIMV2:Win32_ComputerSystem.Name="DESKTOP-BQO86TB"'

Property(s) update successful.

==================================================================


AutomaticManagedPagefile


TRUE


==================================================================

     [BcdEdit /enum {badmemory}]

RAM Defects


identifier {badmemory}


==================================================================

 Finished on Mon 05/09/2022 at 10:06:18.67
 It took 4 minutes and 24 seconds to complete the operations.



And here is the link to the V2 log file data
https://drive.google.com/file/d/1Sk1ZkledNhl8aFetuXVdLw4CG6e4XXCU/view?usp=sharing

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

On someone else's suggestion, I have also reseated my RAM into another slot and it hasn't crashed since, but long periods of no crashes followed by multiple crashes in a row is common so it doesn't mean it's fixed at all.

0 Votes 0 ·
Docs-4663 avatar image
0 Votes"
Docs-4663 answered

Please run:

https://www.tenforums.com/attachments/bsod-crashes-debugging/358470d1643456903-batch-files-use-bsod-debugging-gather_additional_dump_files.bat


Search for:

C:\windows\memory.dmp
C:\windows\minidump

If the size of each file is < 2.5 GB then save to the downloads folder > zip > post a separate share link for each zipped dump file



.
.
.
.
.

Please remember to vote and to mark the replies as answers if they help.

On the bottom of each post there is:

Propose as answer = answered the question

On the left side of each post there is /\ with a number: click = a helpful post
.
.
.
.
.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

SmithColeJ-1432 avatar image
0 Votes"
SmithColeJ-1432 answered

Sorry, was out of town for a bit and couldn't respond immediately.

This is the result of the newest bat file you told me to run

https://drive.google.com/file/d/1fW_dALV9QxzDG-UNyCn0sDV3oO2QzcyO/view?usp=sharing

and this is my minidump file of a crash I had earlier today.

https://drive.google.com/file/d/1t3V3VteLyl0WQCawaxUREjjzRi8sDQ3q/view?usp=sharing

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Docs-4663 avatar image
0 Votes"
Docs-4663 answered

1) Please uninstall the AMD GPU drivers using Display Driver Uninstaller (DDU).

https://www.wagnardsoft.com/display-driver-uninstaller-ddu-

https://www.sevenforums.com/tutorials/367109-display-driver-uninstaller-how-use.html

https://www.amd.com/en/support

https://www.amd.com/en/support/kb/faq/gpu-driver-autodetect



2) The file labeled mini dump was not able to be viewed.
It displayed error.


The AMD uninstallation and reinstallation may fix the BSOD's.


3) In case there are any BSOD:

a) Run the V2 log collector > post a share link into the newest post

b) Search for C:\windows\memory dump > check the file size > if the size is less than 2.5 GB then zip > post a separate share link with only the zipped memory dump file
(please do not post a share link if the file size is greater than 2.5 GB or if the file is not zipped)

If there are new BSOD they can be found using other methods.



.
.
.
.
.

Please remember to vote and to mark the replies as answers if they help.

On the bottom of each post there is:

Propose as answer = answered the question

On the left side of each post there is /\ with a number: click = a helpful post
.
.
.
.
.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

SmithColeJ-1432 avatar image
0 Votes"
SmithColeJ-1432 answered

Hi,

I had another crash tonight. It's getting very annoying. I have the V2 log collector files. here is the link for them

https://drive.google.com/file/d/1YZXr4uFHWRivO-GXlligarVy-7_45yrO/view?usp=sharing

After looking through the event log around the timestamp of the crash, it seemed like there was an error while creating a dump file and only a mini dump file is produced, I can not find any full dump file. If you can provide any more help, it would be extremely appreciated.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Docs-4663 avatar image
0 Votes"
Docs-4663 answered

Please search for 5/14/2022 1:33:31 AM 1082.04 C:\WINDOWS\Minidump

Zip the file and post a share link into this thread using one drive, drop box, or google drive.


Run:
https://www.tenforums.com/attachments/bsod-crashes-debugging/358470d1643456903-batch-files-use-bsod-debugging-gather_additional_dump_files.bat

Post a separate share link using one drive, drop box, or google drive.

.
.
.
.
.

Please remember to vote and to mark the replies as answers if they help.

On the bottom of each post there is:

Propose as answer = answered the question

On the left side of each post there is /\ with a number: click = a helpful post
.
.
.
.
.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

SmithColeJ-1432 avatar image
0 Votes"
SmithColeJ-1432 answered
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Docs-4663 avatar image
0 Votes"
Docs-4663 answered

Ordinarily the V2 log collector does not collect separate mini dump files outside the typical folder.

On your computer it's collecting a mini dump file that is 1.1 GB or larger.

The typical V2 is viewed immediately but with this download it takes a lot of time.


If possible please delete the separate or added file from the V2: Minidump



The file was not able to be viewed.

For the next BSOD:

a) run the V2 log collector

b) run the DM log collector

https://www.tenforums.com/bsod-crashes-debugging/2198-bsod-posting-instructions.html

https://www.elevenforum.com/t/bsod-posting-instructions.103/

c) search for c;\windows\memory.dmp
if the file size is < 2.5 GB then save to the downloads folder > ZIP > post a separate share link that has only the zipped memory dump


.
.
.
.
.

Please remember to vote and to mark the replies as answers if they help.

On the bottom of each post there is:

Propose as answer = answered the question

On the left side of each post there is /\ with a number: click = a helpful post
.
.
.
.
.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.