Windows 2008 unexpected restart

  • Thread starter Thread starter efeb
  • Start date Start date
E

efeb

Guest
Windows 2008 restrarts unexpectedly and I'm getting this message:

Problem signature:
Problem Event Name: BlueScreen
OS Version: 6.0.6001.2.1.0.274.10
Locale ID: 1050

Additional information about the problem:
BCCode: be
BCP1: 000006427FB3F478
BCP2: 64D00000E1C9E025
BCP3: FFFFFA60051D4730
BCP4: 000000000000000A
OS Version: 6_0_6001
Service Pack: 1_0
Product: 274_3

Files that help describe the problem:
C:\Windows\Minidump\Mini031508-02.dmp
C:\Users\exadmin.ERSTE\AppData\Local\Temp\2\WER-191046-0.sysdata.xml


here is dump file:

http://193.198.102.182:8080/dump/

Can anyone help?

Thank you.
 
Re: Windows 2008 unexpected restart

Hello,

1) cannot download file supplied (404) (try renaming it to .txt)
2) Most probably will also need memory.dmp located in c:\windows.

Regards,

Andrew

"efeb" <efeb@discussions.microsoft.com> wrote in message
news:04F41F69-BF3B-4118-AA25-5E4A8B41ECE7@microsoft.com...
> Windows 2008 restrarts unexpectedly and I'm getting this message:
>
> Problem signature:
> Problem Event Name: BlueScreen
> OS Version: 6.0.6001.2.1.0.274.10
> Locale ID: 1050
>
> Additional information about the problem:
> BCCode: be
> BCP1: 000006427FB3F478
> BCP2: 64D00000E1C9E025
> BCP3: FFFFFA60051D4730
> BCP4: 000000000000000A
> OS Version: 6_0_6001
> Service Pack: 1_0
> Product: 274_3
>
> Files that help describe the problem:
> C:\Windows\Minidump\Mini031508-02.dmp
> C:\Users\exadmin.ERSTE\AppData\Local\Temp\2\WER-191046-0.sysdata.xml
>
>
> here is dump file:
>
> http://193.198.102.182:8080/dump/
>
> Can anyone help?
>
> Thank you.
 
Re: Windows 2008 unexpected restart

Try again, I put it in .zip file so you can download it.

Tnx for quick reply.

"Andrew Lomakin" wrote:

> Hello,
>
> 1) cannot download file supplied (404) (try renaming it to .txt)
> 2) Most probably will also need memory.dmp located in c:\windows.
>
> Regards,
>
> Andrew
>
> "efeb" <efeb@discussions.microsoft.com> wrote in message
> news:04F41F69-BF3B-4118-AA25-5E4A8B41ECE7@microsoft.com...
> > Windows 2008 restrarts unexpectedly and I'm getting this message:
> >
> > Problem signature:
> > Problem Event Name: BlueScreen
> > OS Version: 6.0.6001.2.1.0.274.10
> > Locale ID: 1050
> >
> > Additional information about the problem:
> > BCCode: be
> > BCP1: 000006427FB3F478
> > BCP2: 64D00000E1C9E025
> > BCP3: FFFFFA60051D4730
> > BCP4: 000000000000000A
> > OS Version: 6_0_6001
> > Service Pack: 1_0
> > Product: 274_3
> >
> > Files that help describe the problem:
> > C:\Windows\Minidump\Mini031508-02.dmp
> > C:\Users\exadmin.ERSTE\AppData\Local\Temp\2\WER-191046-0.sysdata.xml
> >
> >
> > here is dump file:
> >
> > http://193.198.102.182:8080/dump/
> >
> > Can anyone help?
> >
> > Thank you.

>
>
 
Re: Windows 2008 unexpected restart

As i expected - minidump appears to be corrupt.

Can you find `memory.dmp` file in your windows folder. Can you publish that
please?

Regards,

Andrew

"efeb" <efeb@discussions.microsoft.com> wrote in message
news:5655307D-EEE4-491D-B69C-F8CC4B1FEEB1@microsoft.com...
> Try again, I put it in .zip file so you can download it.
>
> Tnx for quick reply.
>
> "Andrew Lomakin" wrote:
>
>> Hello,
>>
>> 1) cannot download file supplied (404) (try renaming it to .txt)
>> 2) Most probably will also need memory.dmp located in c:\windows.
>>
>> Regards,
>>
>> Andrew
>>
>> "efeb" <efeb@discussions.microsoft.com> wrote in message
>> news:04F41F69-BF3B-4118-AA25-5E4A8B41ECE7@microsoft.com...
>> > Windows 2008 restrarts unexpectedly and I'm getting this message:
>> >
>> > Problem signature:
>> > Problem Event Name: BlueScreen
>> > OS Version: 6.0.6001.2.1.0.274.10
>> > Locale ID: 1050
>> >
>> > Additional information about the problem:
>> > BCCode: be
>> > BCP1: 000006427FB3F478
>> > BCP2: 64D00000E1C9E025
>> > BCP3: FFFFFA60051D4730
>> > BCP4: 000000000000000A
>> > OS Version: 6_0_6001
>> > Service Pack: 1_0
>> > Product: 274_3
>> >
>> > Files that help describe the problem:
>> > C:\Windows\Minidump\Mini031508-02.dmp
>> > C:\Users\exadmin.ERSTE\AppData\Local\Temp\2\WER-191046-0.sysdata.xml
>> >
>> >
>> > here is dump file:
>> >
>> > http://193.198.102.182:8080/dump/
>> >
>> > Can anyone help?
>> >
>> > Thank you.

>>
>>
 
Re: Windows 2008 unexpected restart

Uploaded.

memory.zip

Thank you Andrew.

"Andrew Lomakin" wrote:

> As i expected - minidump appears to be corrupt.
>
> Can you find `memory.dmp` file in your windows folder. Can you publish that
> please?
>
> Regards,
>
> Andrew
>
> "efeb" <efeb@discussions.microsoft.com> wrote in message
> news:5655307D-EEE4-491D-B69C-F8CC4B1FEEB1@microsoft.com...
> > Try again, I put it in .zip file so you can download it.
> >
> > Tnx for quick reply.
> >
> > "Andrew Lomakin" wrote:
> >
> >> Hello,
> >>
> >> 1) cannot download file supplied (404) (try renaming it to .txt)
> >> 2) Most probably will also need memory.dmp located in c:\windows.
> >>
> >> Regards,
> >>
> >> Andrew
> >>
> >> "efeb" <efeb@discussions.microsoft.com> wrote in message
> >> news:04F41F69-BF3B-4118-AA25-5E4A8B41ECE7@microsoft.com...
> >> > Windows 2008 restrarts unexpectedly and I'm getting this message:
> >> >
> >> > Problem signature:
> >> > Problem Event Name: BlueScreen
> >> > OS Version: 6.0.6001.2.1.0.274.10
> >> > Locale ID: 1050
> >> >
> >> > Additional information about the problem:
> >> > BCCode: be
> >> > BCP1: 000006427FB3F478
> >> > BCP2: 64D00000E1C9E025
> >> > BCP3: FFFFFA60051D4730
> >> > BCP4: 000000000000000A
> >> > OS Version: 6_0_6001
> >> > Service Pack: 1_0
> >> > Product: 274_3
> >> >
> >> > Files that help describe the problem:
> >> > C:\Windows\Minidump\Mini031508-02.dmp
> >> > C:\Users\exadmin.ERSTE\AppData\Local\Temp\2\WER-191046-0.sysdata.xml
> >> >
> >> >
> >> > here is dump file:
> >> >
> >> > http://193.198.102.182:8080/dump/
> >> >
> >> > Can anyone help?
> >> >
> >> > Thank you.
> >>
> >>

>
>
 
Re: Windows 2008 unexpected restart

Debugging Details:
------------------

DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

BUGCHECK_STR: 0xBE

PROCESS_NAME: Microsoft.Excha

CURRENT_IRQL: 2

TRAP_FRAME: fffffa60051d4730 -- (.trap 0xfffffa60051d4730)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=00000000ff96f20c rbx=fffffa8000000aa8 rcx=00000000ff96f20d
rdx=fffffa80079fe010 rsi=0000000000000001 rdi=fffffa80075a5a40
rip=fffffa6003510a0c rsp=fffffa60051d48c0 rbp=0000000000000000
r8=fffffa8006d93ae2 r9=0000000000000002 r10=fffffa80079fe068
r11=0000000000000001 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na pe nc
rdbss!RxCancelRoutine+0x44:
fffffa60`03510a0c f00fb18bc8000000 lock cmpxchg dword ptr [rbx+0C8h],ecx ds:c1f0:0b70=????????
Resetting default scope

LAST_CONTROL_TRANSFER: from fffff800016af28a to fffff800016a1390

STACK_TEXT:
fffffa60`051d4638 fffff800`016af28a : 00000000`000000be 00000642`7fb3f478 64d00000`e1c9e025 fffffa60`051d4730 : nt!KeBugCheckEx
fffffa60`051d4640 fffff800`0169ff19 : 00000000`00000001 fffff800`016787f9 00000000`00000000 00000642`7fb3f3b0 : nt!MmAccessFault+0x28a
fffffa60`051d4730 fffffa60`03510a0c : fffffa60`013e0101 fffffa80`07626550 fffffa60`013df360 fffffa80`076c0011 : nt!KiPageFault+0x119
fffffa60`051d48c0 fffff800`01653783 : fffffa80`079fe010 fffffa80`07624670 00000000`00000000 fffffa60`013e0011 : rdbss!RxCancelRoutine+0x44
fffffa60`051d4900 fffff800`01708042 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!IoCancelIrp+0x63
fffffa60`051d4940 fffff800`01903e45 : fffffa80`00000001 fffffa80`06d93ae0 00000000`00000000 00000000`00000000 : nt! ?? ::FNODOBFM::`string'+0x27ce8
fffffa60`051d49d0 fffff800`019222f1 : fffffa80`076245b0 fffff800`01781781 fffffa80`07c29f30 fffff800`017df160 : nt!IopCleanupProcessResources+0x25
fffffa60`051d4a10 fffff800`0191f890 : 00000000`00000000 fffffa80`076245b0 fffff880`0510e8f0 00000000`00000000 : nt!IopCloseFile+0x251
fffffa60`051d4aa0 fffff800`0191fc47 : fffff880`0510e8f0 fffffa80`00000001 fffffa80`06d93ae0 00000000`00000000 : nt!ObpDecrementHandleCount+0xc0
fffffa60`051d4b30 fffff800`0191fe04 : fffff880`04e62510 fffff880`04e62500 00000000`00000001 00000000`00000a3c : nt!ObpCloseHandleTableEntry+0xb7
fffffa60`051d4bd0 fffff800`016a0e33 : fffffa80`075a5a40 fffffa60`051d4ca0 00000000`1e77e570 00000000`00000000 : nt!ObpCloseHandle+0x94
fffffa60`051d4c20 00000000`776f5b6a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`1e77e248 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x776f5b6a


STACK_COMMAND: kb

FOLLOWUP_IP:
rdbss!RxCancelRoutine+44
fffffa60`03510a0c f00fb18bc8000000 lock cmpxchg dword ptr [rbx+0C8h],ecx

SYMBOL_STACK_INDEX: 3

SYMBOL_NAME: rdbss!RxCancelRoutine+44

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: rdbss

IMAGE_NAME: rdbss.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 479190bd

FAILURE_BUCKET_ID: X64_0xBE_rdbss!RxCancelRoutine+44

BUCKET_ID: X64_0xBE_rdbss!RxCancelRoutine+44

Followup: MachineOwner
---------


Concluding from the above, an error occurs in rdbss.sys (Redirected Drive Buffering SubSystem Driver) when it tries to cancel an IRP (very nice cool feature in vista/2008...let's see how many problems we'll have with it)
If i understand correctly, you run the server inside a VM...so hardware is most likely out of the question :)...i think it might have something to do with VM then...

Digging a bit in:
We're trying to close a file (as seen from the line below), which for some reasons we cancel out (not sure why though)
fffffa60`051d4a10 fffff800`0191f890 : 00000000`00000000 fffffa80`076245b0 fffff880`0510e8f0 00000000`00000000 : nt!IopCloseFile+0x251

So the file we're trying to close is....
1: kd> !object fffffa80`076245b0
Object: fffffa80076245b0 Type: (fffffa80054e0080) File
ObjectHeader: fffffa8007624580 (old version)
HandleCount: 0 PointerCount: 1
Directory Object: 00000000 Name: \exbjnod1\18c72dd1-2e60-4330-984e-2d0dff196502$ {Mup}

not too sure what good does that give us though...

Call for MS debugging gurus here :)

Regards,

Andrew


"efeb" <efeb@discussions.microsoft.com> wrote in message news:4F80583D-9183-43A5-AED2-5383C3E573A0@microsoft.com...
> Uploaded.
>
> memory.zip
>
> Thank you Andrew.
>
> "Andrew Lomakin" wrote:
>
>> As i expected - minidump appears to be corrupt.
>>
>> Can you find `memory.dmp` file in your windows folder. Can you publish that
>> please?
>>
>> Regards,
>>
>> Andrew
>>
>> "efeb" <efeb@discussions.microsoft.com> wrote in message
>> news:5655307D-EEE4-491D-B69C-F8CC4B1FEEB1@microsoft.com...
>> > Try again, I put it in .zip file so you can download it.
>> >
>> > Tnx for quick reply.
>> >
>> > "Andrew Lomakin" wrote:
>> >
>> >> Hello,
>> >>
>> >> 1) cannot download file supplied (404) (try renaming it to .txt)
>> >> 2) Most probably will also need memory.dmp located in c:\windows.
>> >>
>> >> Regards,
>> >>
>> >> Andrew
>> >>
>> >> "efeb" <efeb@discussions.microsoft.com> wrote in message
>> >> news:04F41F69-BF3B-4118-AA25-5E4A8B41ECE7@microsoft.com...
>> >> > Windows 2008 restrarts unexpectedly and I'm getting this message:
>> >> >
>> >> > Problem signature:
>> >> > Problem Event Name: BlueScreen
>> >> > OS Version: 6.0.6001.2.1.0.274.10
>> >> > Locale ID: 1050
>> >> >
>> >> > Additional information about the problem:
>> >> > BCCode: be
>> >> > BCP1: 000006427FB3F478
>> >> > BCP2: 64D00000E1C9E025
>> >> > BCP3: FFFFFA60051D4730
>> >> > BCP4: 000000000000000A
>> >> > OS Version: 6_0_6001
>> >> > Service Pack: 1_0
>> >> > Product: 274_3
>> >> >
>> >> > Files that help describe the problem:
>> >> > C:\Windows\Minidump\Mini031508-02.dmp
>> >> > C:\Users\exadmin.ERSTE\AppData\Local\Temp\2\WER-191046-0.sysdata.xml
>> >> >
>> >> >
>> >> > here is dump file:
>> >> >
>> >> > http://193.198.102.182:8080/dump/
>> >> >
>> >> > Can anyone help?
>> >> >
>> >> > Thank you.
>> >>
>> >>

>>
>>
 
Re: Windows 2008 unexpected restart

Hello Andrew,

I noticed that two warning events happens priror to restarting w2k8 machine.
(Btw, that machine is virtual machine).

Those are about LSI_SCSI and storflt.

Here is description:


Log Name: System
Source: LSI_SCSI
Date: 19.3.2008 18:29:26
Event ID: 26
Task Category: None
Level: Warning
Keywords: Classic
User: N/A
Computer: EXBJNOD2.erste.hr

Description:
The driver has detected that device \Device\RaidPort0 has old or out-of-date
firmware. Reduced performance may result.

Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="LSI_SCSI" />
<EventID Qualifiers="32772">26</EventID>
<Level>3</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2008-03-19T17:29:26.859Z" />
<EventRecordID>17775</EventRecordID>
<Channel>System</Channel>
<Computer>EXBJNOD2.erste.hr</Computer>
<Security />
</System>
<EventData>
<Data>\Device\RaidPort0</Data>

<Binary>0F00180001000000000000001A0004800000000000000000000000000000000000000000000000000000000000000000000000001A0004800000000000000000</Binary>
</EventData>
</Event>



and



Log Name: System
Source: storflt
Date: 19.3.2008 18:29:27
Event ID: 5
Task Category: None
Level: Warning
Keywords: Classic
User: N/A
Computer: EXBJNOD2.erste.hr

Description:
The Virtual Storage Filter Driver is disabled through the registry. It is
inactive for all disk drives.

Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="storflt" />
<EventID Qualifiers="32774">5</EventID>
<Level>3</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2008-03-19T17:29:27.140Z" />
<EventRecordID>17778</EventRecordID>
<Channel>System</Channel>
<Computer>EXBJNOD2.erste.hr</Computer>
<Security />
</System>
<EventData>
<Data>
</Data>

<Binary>00000000010000000000000005000680000000000000000000000000000000000000000000000000</Binary>
</EventData>
</Event>


Tnx.
 
Re: Windows 2008 unexpected restart

Some problem here.

Environment:

Physical Machines
Two Windows 2008 Core(HP ML 380 G5)

Virtual

Core 1 - 2k8 Web and Standart edition
Core 2 - 2k8 Web and Standat edition

Three of the virtual machines restart unexpected. They seem to be ok 2 days
but after that i notice unexpted shutdown's on virtual machines.

I Am using Hyper-V RC0 on Core machines.

To reach that point it was a litle nightmare but it seemed to get start
working. Guess not.


--
Best Regards,
Sérgio Machado


"efeb" wrote:

> Hello Andrew,
>
> I noticed that two warning events happens priror to restarting w2k8 machine.
> (Btw, that machine is virtual machine).
>
> Those are about LSI_SCSI and storflt.
>
> Here is description:
>
>
> Log Name: System
> Source: LSI_SCSI
> Date: 19.3.2008 18:29:26
> Event ID: 26
> Task Category: None
> Level: Warning
> Keywords: Classic
> User: N/A
> Computer: EXBJNOD2.erste.hr
>
> Description:
> The driver has detected that device \Device\RaidPort0 has old or out-of-date
> firmware. Reduced performance may result.
>
> Event Xml:
> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
> <System>
> <Provider Name="LSI_SCSI" />
> <EventID Qualifiers="32772">26</EventID>
> <Level>3</Level>
> <Task>0</Task>
> <Keywords>0x80000000000000</Keywords>
> <TimeCreated SystemTime="2008-03-19T17:29:26.859Z" />
> <EventRecordID>17775</EventRecordID>
> <Channel>System</Channel>
> <Computer>EXBJNOD2.erste.hr</Computer>
> <Security />
> </System>
> <EventData>
> <Data>\Device\RaidPort0</Data>
>
> <Binary>0F00180001000000000000001A0004800000000000000000000000000000000000000000000000000000000000000000000000001A0004800000000000000000</Binary>
> </EventData>
> </Event>
>
>
>
> and
>
>
>
> Log Name: System
> Source: storflt
> Date: 19.3.2008 18:29:27
> Event ID: 5
> Task Category: None
> Level: Warning
> Keywords: Classic
> User: N/A
> Computer: EXBJNOD2.erste.hr
>
> Description:
> The Virtual Storage Filter Driver is disabled through the registry. It is
> inactive for all disk drives.
>
> Event Xml:
> <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
> <System>
> <Provider Name="storflt" />
> <EventID Qualifiers="32774">5</EventID>
> <Level>3</Level>
> <Task>0</Task>
> <Keywords>0x80000000000000</Keywords>
> <TimeCreated SystemTime="2008-03-19T17:29:27.140Z" />
> <EventRecordID>17778</EventRecordID>
> <Channel>System</Channel>
> <Computer>EXBJNOD2.erste.hr</Computer>
> <Security />
> </System>
> <EventData>
> <Data>
> </Data>
>
> <Binary>00000000010000000000000005000680000000000000000000000000000000000000000000000000</Binary>
> </EventData>
> </Event>
>
>
> Tnx.
>
 
Back
Top