Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[npcap] Wireshark + Avast Anti-Virus = BSOD (IRQL_NOT_LESS_OR_EQUAL) #1681

Open
Newcool1230 opened this issue Aug 8, 2019 · 6 comments

Comments

@Newcool1230
Copy link

commented Aug 8, 2019

Its been a full day of debugging and testing. I have gotten over 20 BSOD with the same error msg.

I have installed Wireshark + npcap. Whenever I restart/shutdown/go to adapter properties/shift+restart/uninstall driver/update driver/uninstall VMware/ ...anything related to network adapters I will BSOD. I have also tried safe mode to remove the adapters but they also give me the same BSOD.

Went to my 20 minidumps found the same error with "ndis.sys". In event viewer there was an error

The following boot-start or system driver did not load:
dam
npcap

After 6 hours, I found this https://www.bleepingcomputer.com/forums/t/701547/bsod-when-shutting-down-or-restarting/

I uninstalled Avast, tried restarting, BSOD, installed Wireshark + npcap again, restarted, no BSOD this time, uninstalled wireshark + npcap (properly this time, without BSOD), restarted computer again without BSOD.

I believe the many BSOD (IRQL_NOT_LESS_OR_EQUAL BSOD) issues users are having is with Avast anti-virus.
I will install avast again to see if my issues has been resolved.

I was just wondering are there any adapters that don't get cleaned out by the uninstaller? or any extra files/services npcap is running even after uninstall?

@Newcool1230 Newcool1230 changed the title npcap IRQL_NOT_LESS_OR_EQUAL BSOD + Avast Anti-Virus npcap Wireshark + Avast Anti-Virus = BSOD (IRQL_NOT_LESS_OR_EQUAL) Aug 9, 2019

@Newcool1230 Newcool1230 changed the title npcap Wireshark + Avast Anti-Virus = BSOD (IRQL_NOT_LESS_OR_EQUAL) [npcap] Wireshark + Avast Anti-Virus = BSOD (IRQL_NOT_LESS_OR_EQUAL) Aug 9, 2019

@Cloudthumper

This comment has been minimized.

Copy link

commented Aug 10, 2019

I installed npcap when I installed wireshark. I found that wireshark wouldn't work the way I wanted it to so I uninstalled it. After that I found that everytime I reboot my computer I get the BSOD with the following message: IRQL NOT LESS OR EQUAL. Nothing followed, just that. I found what I believe to be the problem: Device Manager > Network adapters > Npcap Loopback Adapter. My every attempt to uninstall, disable, or others remove it results in the same BSOD. I can't even go into Safe Mode. I am just short of using Windows Recovery. Please help me get rid of this. Until it's gone, I can't run diagnostics, create an image, etc.

@Newcool1230

This comment has been minimized.

Copy link
Author

commented Aug 10, 2019

I installed npcap when I installed wireshark. I found that wireshark wouldn't work the way I wanted it to so I uninstalled it. After that I found that everytime I reboot my computer I get the BSOD with the following message: IRQL NOT LESS OR EQUAL. Nothing followed, just that. I found what I believe to be the problem: Device Manager > Network adapters > Npcap Loopback Adapter. My every attempt to uninstall, disable, or others remove it results in the same BSOD. I can't even go into Safe Mode. I am just short of using Windows Recovery. Please help me get rid of this. Until it's gone, I can't run diagnostics, create an image, etc.

I'm not the dev but can you upload your minidump and also remove avast. If you can I recommend re-installing Wireshark with npcap. Then restarting computer. Then uninstalling it.

@Cloudthumper

This comment has been minimized.

Copy link

commented Aug 10, 2019

I tried to reinstall Wireshark. When it wanted to reboot, I got the BSOD. Avast is not installed on my computer. I'll upload the dump when I download the utility that will open the file.

@Cloudthumper

This comment has been minimized.

Copy link

commented Aug 10, 2019

081019-49890-01.txt
Here's the minidump as a .txt file. I can't may head nor tails of it. Hope this helps.

@Cloudthumper

This comment has been minimized.

Copy link

commented Aug 10, 2019

minidump.txt
This is the analysis from windbg.exe

@Cloudthumper

This comment has been minimized.

Copy link

commented Aug 10, 2019

minidump-2.txt
Yet another minidump file.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
2 participants
You can’t perform that action at this time.