2nd October 2007
#1
Inactive
Profile:
Join Date: Oct 2007
Posts: 1
Computer Experience: EXPERIENCED
Memory Dump W2k3
Hello, need help. My server is down and is restarted.
I see with windbg the memory.dmp, but i can't solve the problem. Put the log:
THANK YOU.
--------------------------------------------------------------------
Opened log file 'c:\debuglog.txt'
Microsoft (R) Windows Debugger Version 6.7.0005.1
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [c:\memory\MEMORY.DMP]
Kernel Summary Dump File: Only kernel address space is available
Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is: C:\WINDOWS;C:\WINDOWS\system32;C:\WINDOWS\system32\drivers
Windows Server 2003 Kernel Version 3790 MP (4 procs) Free x86 compatible
Product: Server, suite: Enterprise TerminalServer SingleUserTS
Built by: 3790.srv03_gdr.040410-1234
Kernel base = 0x804de000 PsLoadedModuleList = 0x80567aa8
Debug session time: Mon Oct 1 09:24:09.390 2007 (GMT+2)
System Uptime: 4 days 22:48:14.427
Loading Kernel Symbols
........................................................................... .....................
Loading User Symbols
PEB is paged out (Peb.Ldr = 7ffdf00c). Type ".hh dbgerr001" for details
Loading unloaded module list
...
*************************************************************************** ****
* *
* Bugcheck Analysis *
* *
*************************************************************************** ****
Use !analyze -v to get detailed debugging information.
BugCheck 50, {e56ef0dc, 0, bf869328, 1}
Probably caused by : win32k.sys ( win32k!IFIOBJR::IFIOBJR+61 )
Followup: MachineOwner
---------
0: kd> !analyze -v;r;kv;lmtn;.logclose;q
*************************************************************************** ****
* *
* Bugcheck Analysis *
* *
*************************************************************************** ****
PAGE_FAULT_IN_NONPAGED_AREA (50)
Invalid system memory was referenced. This cannot be protected by try-except,
it must be protected by a Probe. Typically the address is just plain bad or it
is pointing at freed memory.
Arguments:
Arg1: e56ef0dc, memory referenced.
Arg2: 00000000, value 0 = read operation, 1 = write operation.
Arg3: bf869328, If non-zero, the instruction address which referenced the bad memory
address.
Arg4: 00000001, (reserved)
Debugging Details:
------------------
READ_ADDRESS: e56ef0dc Paged pool
FAULTING_IP:
win32k!IFIOBJR::IFIOBJR+61
bf869328 f3a5 rep movs dword ptr es:[edi],dword ptr [esi]
MM_INTERNAL_CODE: 1
IMAGE_NAME: win32k.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 41d1eb91
MODULE_NAME: win32k
FAULTING_MODULE: bf800000 win32k
DEFAULT_BUCKET_ID: DRIVER_FAULT
BUGCHECK_STR: 0x50
PROCESS_NAME: EXCEL.EXE
CURRENT_IRQL: 1
TRAP_FRAME: 8e461ba4 -- (.trap 0xffffffff8e461ba4)
.trap 0xffffffff8e461ba4
ErrCode = 00000000
eax=e56eefe0 ebx=8e461c44 ecx=00000005 edx=00006000 esi=e56ef0dc edi=8e461c50
eip=bf869328 esp=8e461c18 ebp=8e461c24 iopl=0 nv up ei ng nz na po nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010282
win32k!IFIOBJR::IFIOBJR+0x61:
bf869328 f3a5 rep movs dword ptr es:[edi],dword ptr [esi] es:0023:8e461c50=8e461cd4 ds:0023:e56ef0dc=????????
.trap
Resetting default scope
LAST_CONTROL_TRANSFER: from 8052a9a8 to 805011b9
STACK_TEXT:
8e461b30 8052a9a8 00000050 e56ef0dc 00000000 nt!KeBugCheckEx+0x19
8e461b8c 8054d1f0 00000000 e56ef0dc 00000000 nt!MmAccessFault+0x972
8e461b8c bf869328 00000000 e56ef0dc 00000000 nt!KiTrap0E+0xc8
8e461c24 bf868ecd e56eeef0 8e461cd4 8e461ce0 win32k!IFIOBJR::IFIOBJR+0x61
8e461c7c bf869356 8e461cd4 8e461ce0 8e461cf4 win32k!bIFIMetricsToTextMetricWStrict+0x1c
8e461ca0 bf83d47e 8e461cd4 8e461ce0 8e461cf4 win32k!bIFIMetricsToTextMetricW+0x1a
8e461cbc bf83d4c0 8e461cd4 8e461ce0 8e461cf4 win32k!bGetTextMetrics+0x73
8e461cd8 bf83d51b edf91008 8e461cf4 8e461d64 win32k!GreGetTextMetricsW+0x3b
8e461d50 8054a42d 27210f09 0013f750 00000044 win32k!NtGdiGetTextMetricsW+0x20
8e461d50 7ffe0304 27210f09 0013f750 00000044 nt!KiSystemService+0xd0
0013f794 00000000 00000000 00000000 00000000 SharedUserData!SystemCallStub+0x4
STACK_COMMAND: kb
FOLLOWUP_IP:
win32k!IFIOBJR::IFIOBJR+61
bf869328 f3a5 rep movs dword ptr es:[edi],dword ptr [esi]
SYMBOL_STACK_INDEX: 3
FOLLOWUP_NAME: MachineOwner
SYMBOL_NAME: win32k!IFIOBJR::IFIOBJR+61
FAILURE_BUCKET_ID: 0x50_win32k!IFIOBJR::IFIOBJR+61
BUCKET_ID: 0x50_win32k!IFIOBJR::IFIOBJR+61
Followup: MachineOwner
---------
eax=ffdff13c ebx=00000050 ecx=87f31370 edx=8054ea91 esi=ffdff120 edi=00000000
eip=805011b9 esp=8e461b18 ebp=8e461b30 iopl=0 nv up ei ng nz na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00000286
nt!KeBugCheckEx+0x19:
805011b9 5d pop ebp
ChildEBP RetAddr Args to Child
8e461b30 8052a9a8 00000050 e56ef0dc 00000000 nt!KeBugCheckEx+0x19 (FPO: [Non-Fpo])
8e461b8c 8054d1f0 00000000 e56ef0dc 00000000 nt!MmAccessFault+0x972 (FPO: [Non-Fpo])
8e461b8c bf869328 00000000 e56ef0dc 00000000 nt!KiTrap0E+0xc8 (FPO: [0,0] TrapFrame @ 8e461ba4)
8e461c24 bf868ecd e56eeef0 8e461cd4 8e461ce0 win32k!IFIOBJR::IFIOBJR+0x61 (FPO: [Non-Fpo])
8e461c7c bf869356 8e461cd4 8e461ce0 8e461cf4 win32k!bIFIMetricsToTextMetricWStrict+0x1c (FPO: [Non-Fpo])
8e461ca0 bf83d47e 8e461cd4 8e461ce0 8e461cf4 win32k!bIFIMetricsToTextMetricW+0x1a (FPO: [Non-Fpo])
8e461cbc bf83d4c0 8e461cd4 8e461ce0 8e461cf4 win32k!bGetTextMetrics+0x73 (FPO: [Non-Fpo])
8e461cd8 bf83d51b edf91008 8e461cf4 8e461d64 win32k!GreGetTextMetricsW+0x3b (FPO: [Non-Fpo])
8e461d50 8054a42d 27210f09 0013f750 00000044 win32k!NtGdiGetTextMetricsW+0x20 (FPO: [Non-Fpo])
8e461d50 7ffe0304 27210f09 0013f750 00000044 nt!KiSystemService+0xd0 (FPO: [0,0] TrapFrame @ 8e461d64)
0013f794 00000000 00000000 00000000 00000000 SharedUserData!SystemCallStub+0x4 (FPO: [0,0,0])
start end module name
804de000 806fe000 nt ntkrpamp.exe Thu May 27 01:51:22 2004 (40B52D7A)
806fe000 80726000 hal halmacpi.dll Tue Mar 25 08:07:28 2003 (3E800030)
b532e000 b5350000 RDPWD RDPWD.SYS Tue Mar 25 08:03:00 2003 (3E7FFF24)
b5c59000 b5cb8000 srv srv.sys Tue Mar 25 09:49:51 2003 (3E80182F)
b5d08000 b5d60000 HTTP HTTP .sys Tue Mar 25 09:55:21 2003 (3E801979)
b5ec8000 b5ef7000 afd afd.sys Tue Mar 25 08:40:50 2003 (3E800802)
b6425000 b643d000 Cdfs Cdfs.SYS Tue Mar 25 09:17:19 2003 (3E80108F)
b65ab000 b65b4000 dump_diskdump dump_diskdump.sys Tue Mar 25 08:05:15 2003 (3E7FFFAB)
b65db000 b65e5000 Dxapi Dxapi.sys Tue Mar 25 08:06:01 2003 (3E7FFFD9)
b6a7f000 b6a86000 dxgthk dxgthk.sys Tue Mar 25 08:05:52 2003 (3E7FFFD0)
b7331000 b733c000 dump_nfrd960 dump_nfrd960.sys Tue Mar 25 08:04:58 2003 (3E7FFF9A)
b9670000 b967a000 TDTCP TDTCP.SYS Tue Mar 25 08:02:52 2003 (3E7FFF1C)
b973b000 b974e000 Fips Fips.SYS Tue Mar 25 09:54:59 2003 (3E801963)
b974e000 b97ba000 mrxsmb mrxsmb.sys Wed Jan 19 02:35:18 2005 (41EDB956)
b97ba000 b97e5000 rdbss rdbss.sys Tue Oct 12 02:38:09 2004 (416B2771)
b97e5000 b981a000 netbt netbt.sys Fri Jul 18 19:16:03 2003 (3F182B53)
b98ba000 b991c000 tcpip tcpip.sys Tue Mar 25 09:04:01 2003 (3E800D71)
b991c000 b9938000 ipsec ipsec.sys Tue Mar 25 08:55:45 2003 (3E800B81)
b9958000 b996b000 usbhub usbhub.sys Tue Mar 25 08:10:46 2003 (3E8000F6)
b998b000 b99be000 update update.sys Tue Mar 25 09:59:59 2003 (3E801A8F)
b99be000 b99f2000 rdpdr rdpdr.sys Tue Mar 25 08:09:30 2003 (3E8000AA)
b99f2000 b9a07000 raspptp raspptp.sys Tue Mar 25 09:19:09 2003 (3E8010FD)
b9a07000 b9a22000 ndiswan ndiswan.sys Tue Mar 25 09:48:19 2003 (3E8017D3)
b9a22000 b9a39000 rasl2tp rasl2tp.sys Tue Mar 25 08:54:46 2003 (3E800B46)
b9a39000 b9a5b400 b57xp32 b57xp32.sys Mon Jan 13 19:43:21 2003 (3E2308C9)
b9a5c000 b9a7de80 USBPORT USBPORT.SYS Tue Mar 25 08:10:43 2003 (3E8000F3)
b9a7e000 b9aa8000 ks ks.sys Tue Mar 25 09:47:36 2003 (3E8017A8)
b9aa8000 b9abc000 redbook redbook.sys Tue Mar 25 08:04:38 2003 (3E7FFF86)
b9abc000 b9ad0000 cdrom cdrom.sys Tue Mar 25 08:05:18 2003 (3E7FFFAE)
b9ad0000 b9ae8000 serial serial.sys Tue Mar 25 08:40:08 2003 (3E8007D8)
b9ae8000 b9afe000 i8042prt i8042prt.sys Tue Mar 25 10:01:43 2003 (3E801AF7)
b9afe000 b9b17000 VIDEOPRT VIDEOPRT.SYS Tue Mar 25 08:08:02 2003 (3E800052)
b9b17000 b9b6ad80 ati2mpad ati2mpad.sys Fri Jul 19 03:13:20 2002 (3D3767B0)
b9e84000 b9e91000 netbios netbios.sys Tue Mar 25 08:09:53 2003 (3E8000C1)
b9e94000 b9ea1000 wanarp wanarp.sys Tue Mar 25 08:11:22 2003 (3E80011A)
b9ea4000 b9eb3000 msgpc msgpc.sys Tue Mar 25 08:10:12 2003 (3E8000D4)
b9eb4000 b9ec0000 Npfs Npfs.SYS Tue Mar 25 08:08:59 2003 (3E80008B)
b9ec4000 b9ece000 Msfs Msfs.SYS Tue Mar 25 08:08:56 2003 (3E800088)
b9ed4000 b9ee0000 vga vga.sys Tue Mar 25 08:08:03 2003 (3E800053)
ba509000 ba50c900 ibmhpa ibmhpa.sys Sat Feb 08 08:02:30 2003 (3E44AB86)
ba54d000 ba56f000 Mup Mup.sys Tue Mar 25 09:55:58 2003 (3E80199E)
ba56f000 ba5b0000 NDIS NDIS.sys Tue Mar 25 09:45:35 2003 (3E80172F)
ba5b0000 ba64d000 Ntfs Ntfs.sys Tue Mar 25 08:40:05 2003 (3E8007D5)
ba64d000 ba66e000 KSecDD KSecDD.sys Tue Mar 25 08:05:39 2003 (3E7FFFC3)
ba66e000 ba684000 CLASSPNP CLASSPNP.SYS Tue Mar 25 08:38:14 2003 (3E800766)
ba684000 ba695b60 AACMgt AACMgt.sys Fri Apr 28 06:49:19 2006 (44519ECF)
ba696000 ba6aee80 adpu160m adpu160m.sys Mon Sep 17 22:55:53 2001 (3BA66359)
ba6af000 ba6d5000 SCSIPORT SCSIPORT.SYS Tue Mar 25 09:01:25 2003 (3E800CD5)
ba6d5000 ba6f1000 atapi atapi .sys Tue Mar 25 08:04:48 2003 (3E7FFF90)
ba6f1000 ba712000 volsnap volsnap.sys Tue Mar 25 08:05:47 2003 (3E7FFFCB)
ba712000 ba73c000 dmio dmio.sys Tue Mar 25 08:08:14 2003 (3E80005E)
ba73c000 ba761000 ftdisk ftdisk.sys Tue Mar 25 08:05:26 2003 (3E7FFFB6)
ba761000 ba776000 pci pci .sys Tue Mar 25 08:16:40 2003 (3E800258)
ba776000 ba7a7000 ACPI ACPI.sys Tue Mar 25 08:16:21 2003 (3E800245)
ba8a8000 ba8b1000 WMILIB WMILIB.SYS Tue Mar 25 08:13:00 2003 (3E80017C)
ba8b8000 ba8c7000 isapnp isapnp.sys Tue Mar 25 08:16:35 2003 (3E800253)
ba8c8000 ba8d5000 PCIIDEX PCIIDEX.SYS Tue Mar 25 08:04:44 2003 (3E7FFF8C)
ba8d8000 ba8e7000 MountMgr MountMgr.sys Tue Mar 25 08:03:05 2003 (3E7FFF29)
ba8e8000 ba8f6000 PartMgr PartMgr.sys Tue Mar 25 09:04:02 2003 (3E800D72)
ba8f8000 ba903000 nfrd960 nfrd960.sys Tue Mar 25 08:04:58 2003 (3E7FFF9A)
ba908000 ba917000 disk disk.sys Tue Mar 25 08:05:20 2003 (3E7FFFB0)
ba918000 ba924000 Dfs Dfs.sys Tue Mar 25 08:09:52 2003 (3E8000C0)
ba928000 ba931000 crcdisk crcdisk.sys Tue Mar 25 08:07:23 2003 (3E80002B)
ba978000 ba984000 processr processr.sys Tue Mar 25 08:07:36 2003 (3E800038)
ba988000 ba991000 watchdog watchdog.sys Tue Mar 25 08:09:01 2003 (3E80008D)
ba998000 ba9a2000 kbdclass kbdclass.sys Tue Mar 25 08:03:10 2003 (3E7FFF2E)
ba9a8000 ba9b2000 mouclass mouclass.sys Tue Mar 25 08:03:09 2003 (3E7FFF2D)
ba9b8000 ba9c3000 fdc fdc.sys Tue Mar 25 08:04:31 2003 (3E7FFF7F)
ba9c8000 ba9d2000 serenum serenum.sys Tue Mar 25 08:04:01 2003 (3E7FFF61)
ba9d8000 ba9e1000 ndistapi ndistapi.sys Tue Mar 25 08:11:28 2003 (3E800120)
ba9e8000 ba9f6000 raspppoe raspppoe.sys Tue Mar 25 08:11:37 2003 (3E800129)
ba9f8000 baa03000 TDI TDI.SYS Tue Mar 25 08:14:28 2003 (3E8001D4)
baa08000 baa13000 ptilink ptilink.sys Tue Mar 25 08:03:51 2003 (3E7FFF57)
baa18000 baa21000 raspti raspti.sys Tue Mar 25 08:11:36 2003 (3E800128)
baa28000 baa37000 termdd termdd.sys Tue Mar 25 08:02:52 2003 (3E7FFF1C)
baa48000 baa56000 NDProxy NDProxy.SYS Tue Mar 25 08:11:30 2003 (3E800122)
bab18000 bab21000 ndisuio ndisuio.sys Tue Mar 25 08:09:47 2003 (3E8000BB)
bab28000 bab30000 kdcom kdcom.dll Tue Mar 25 08:08:00 2003 (3E800050)
bab30000 bab38000 BOOTVID BOOTVID.dll Tue Mar 25 08:07:58 2003 (3E80004E)
bab38000 bab3f000 pciide pciide.sys Tue Mar 25 08:04:46 2003 (3E7FFF8E)
bab40000 bab47000 dmload dmload.sys Tue Mar 25 08:08:08 2003 (3E800058)
bac00000 bac05a00 RTL8139 RTL8139.SYS Wed May 30 08:14:57 2001 (3B148FE1)
bac08000 bac0c200 usbohci usbohci.sys Tue Mar 25 08:10:41 2003 (3E8000F1)
bac10000 bac18000 audstub audstub.sys Tue Mar 25 08:09:12 2003 (3E800098)
bac28000 bac30000 Fs_Rec Fs_Rec.SYS Tue Mar 25 08:08:36 2003 (3E800074)
bac30000 bac37000 Null Null.SYS Tue Mar 25 08:03:05 2003 (3E7FFF29)
bac38000 bac3f000 Beep Beep.SYS Tue Mar 25 08:03:04 2003 (3E7FFF28)
bac40000 bac48000 mnmdd mnmdd.SYS Tue Mar 25 08:07:53 2003 (3E800049)
bac48000 bac50000 RDPCDD RDPCDD.sys Tue Mar 25 08:03:05 2003 (3E7FFF29)
bac50000 bac58000 rasacd rasacd.sys Tue Mar 25 08:11:50 2003 (3E800136)
badb6000 badb7200 swenum swenum.sys Tue Mar 25 08:03:22 2003 (3E7FFF3A)
badbc000 badbd580 USBD USBD.SYS Tue Mar 25 08:10:39 2003 (3E8000EF)
bf800000 bf9c7000 win32k win32k.sys Wed Dec 29 00:26:09 2004 (41D1EB91)
bf9c7000 bfa1d680 ati2drad ati2drad.dll Tue Mar 25 10:43:37 2003 (3E8024C9)
bff60000 bff7b000 RDPDD RDPDD.dll Tue Mar 25 21:12:05 2003 (3E80B815)
bff80000 bff96000 dxg dxg.sys Tue Mar 25 10:46:23 2003 (3E80256F)
bffa0000 bffe8000 ATMFD ATMFD.DLL Tue Mar 25 10:46:23 2003 (3E80256F)
Unloaded modules:
b9e74000 b9e82000 imapi.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
bac20000 bac28000 Sfloppy.SYS
Timestamp: unavailable (00000000)
Checksum: 00000000
b9ee4000 b9eee000 Flpydisk.SYS
Timestamp: unavailable (00000000)
Checksum: 00000000
Closing open log file c:\debuglog.txt