Windows BBS The Place for Microsoft Windows Support! Windows, Support, Help Site

Go Back   Windows BBS > Operating Systems > Windows Server System

Windows Server System Post your Windows Server System question here. Besides Windows Server 2003, Windows Server System also includes other Microsoft Server software (such as BizTalk Server, Exchange Server, ISA Server & others).

Register your FREE account to unlock additional features at WindowsBBS.com
Register
Welcome to WindowsBBS.com
Microsoft Windows Support

Mission Statement

WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.

Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.


Discussion Forums
Operating Systems
Windows 7 Windows 7
Windows Vista Windows Vista
Windows XP Windows XP
Windows Server System Windows Server System
Windows 2000 Windows 2000
Windows 95/98/Me/NT Windows 95/98/Me/NT
Internet & Networking
Networking
Internet Explorer
Microsoft Mail
Firefox, Thunderbird
      & SeaMonkey

General Internet
Security
General Security
Malware and Virus
     Removal

Other
Other Software
Hardware
Test Posts
Community
Introductions
General Discussions
Comments
      & Suggestions

News @ WindowsBBS

Forum Sponsor
 Image

Reply
 
LinkBack Thread Tools
Old 4th November 2008   #1
Member
 
Profile:
Join Date: Nov 2008
Posts: 2
Computer Experience:
experienced
matthewgunn1974 Reputation Level


W2K Server Constantly rebooting

I've got a windows 2K Terminal server which randomly reboots

There does not appear to be any pattern as to when the server creashes and reboots.



here is the latest windbg report

Opened log file 'c:temp\debuglog.txt'

Microsoft (R) Windows Debugger Version 6.9.0003.113 X86
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Documents and Settings\gunnm\Desktop\53MEMORY.DMP]
Kernel Complete Dump File: Full address space is available

Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is: C:\WINDOWS;C:\WINDOWS\system32;C:\WINDOWS\system32\drivers
Windows 2000 Kernel Version 2195 (Service Pack 4) MP (2 procs) Free x86 compatible
Product: Server, suite: TerminalServer
Kernel base = 0x80400000 PsLoadedModuleList = 0x80485b80
Debug session time: Mon Nov 3 13:47:12.400 2008 (GMT+0)
System Uptime: 1 days 8:04:08.187
Loading Kernel Symbols
........................................................................... ..............................
Loading User Symbols
PEB is paged out (Peb.Ldr = 7ffdf00c). Type ".hh dbgerr001" for details
Loading unloaded module list
...
*************************************************************************** ****
* *
* Bugcheck Analysis *
* *
*************************************************************************** ****

Use !analyze -v to get detailed debugging information.

BugCheck CB, {804af764, 80468389, 8816fee8, 0}

PEB is paged out (Peb.Ldr = 7ffdf00c). Type ".hh dbgerr001" for details
PEB is paged out (Peb.Ldr = 7ffdf00c). Type ".hh dbgerr001" for details
Probably caused by : ntkrnlmp.exe ( nt!NtReadFile+538 )

Followup: MachineOwner
---------

1: kd> !analyze -v;r;kv;lmtn;.logclose;q
*************************************************************************** ****
* *
* Bugcheck Analysis *
* *
*************************************************************************** ****

DRIVER_LEFT_LOCKED_PAGES_IN_PROCESS (cb)
Caused by a driver not cleaning up completely after an I/O.
When possible, the guilty driver's name (Unicode string) is printed on
the bugcheck screen and saved in KiBugCheckDriver.
Arguments:
Arg1: 804af764, The calling address in the driver that locked the pages or if the
IO manager locked the pages this points to the dispatch routine of
the top driver on the stack to which the IRP was sent.
Arg2: 80468389, The caller of the calling address in the driver that locked the
pages. If the IO manager locked the pages this points to the device
object of the top driver on the stack to which the IRP was sent.
Arg3: 8816fee8, A pointer to the MDL containing the locked pages.
Arg4: 00000000, The number of locked pages.

Debugging Details:
------------------

PEB is paged out (Peb.Ldr = 7ffdf00c). Type ".hh dbgerr001" for details
PEB is paged out (Peb.Ldr = 7ffdf00c). Type ".hh dbgerr001" for details

FAULTING_IP:
nt!NtReadFile+538
804af764 834dfcff or dword ptr [ebp-4],0FFFFFFFFh

DEFAULT_BUCKET_ID: INTEL_CPU_MICROCODE_ZERO

BUGCHECK_STR: 0xCB

PROCESS_NAME: WinMgmt.exe

LAST_CONTROL_TRANSFER: from 804e8582 to 804421ee

STACK_TEXT:
beee7c84 804e8582 886ba020 885ee260 00000000 nt!MmCleanProcessAddressSpace+0x438
beee7d34 804e78a6 c000004b 00000000 00000000 nt!PspExitThread+0x4e4
beee7d50 8046c966 00000000 7c57b740 00000001 nt!PspUserThreadStartup+0xb2
00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x16


STACK_COMMAND: .bugcheck ; kb

FOLLOWUP_IP:
nt!NtReadFile+538
804af764 834dfcff or dword ptr [ebp-4],0FFFFFFFFh

SYMBOL_NAME: nt!NtReadFile+538

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: nt

IMAGE_NAME: ntkrnlmp.exe

DEBUG_FLR_IMAGE_TIMESTAMP: 45ec3c8f

FAILURE_BUCKET_ID: 0xCB_nt!NtReadFile+538

BUCKET_ID: 0xCB_nt!NtReadFile+538

Followup: MachineOwner
---------

eax=8908e13c ebx=000000cb ecx=00000004 edx=00000001 esi=886ba020 edi=00000000
eip=804421ee esp=beee7bc8 ebp=beee7c84 iopl=0 nv up ei ng nz na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00000286
nt!MmCleanProcessAddressSpace+0x438:
804421ee ffb628020000 push dword ptr [esi+228h] ds:0023:886ba248=886bde08
ChildEBP RetAddr Args to Child
beee7c84 804e8582 886ba020 885ee260 00000000 nt!MmCleanProcessAddressSpace+0x438 (FPO: [Non-Fpo])
beee7d34 804e78a6 c000004b 00000000 00000000 nt!PspExitThread+0x4e4 (FPO: [Non-Fpo])
beee7d50 8046c966 00000000 7c57b740 00000001 nt!PspUserThreadStartup+0xb2 (FPO: [Non-Fpo])
00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x16
start end module name
80062000 80076f80 hal halmacpi.dll Fri Dec 03 03:29:15 2004 (41AFDD8B)
80400000 805a2940 nt ntkrnlmp.exe Mon Mar 05 15:51:43 2007 (45EC3C8F)
a0000000 a0191520 win32k win32k.sys Wed Mar 19 09:26:24 2008 (47E0DC40)
a0192000 a01e9000 ati2drad ati2drad.dll Mon Feb 09 21:56:08 2004 (402801F8)
bde93000 bdea8f20 RDPWD RDPWD.SYS Fri Jun 17 07:41:40 2005 (42B270A4)
bdef9000 bdf0cac0 ipsec ipsec.sys Mon Apr 21 19:19:40 2003 (3EA4363C)
bdf45000 bdf47100 EntDrv50 EntDrv50.sys Wed Sep 20 17:17:05 2006 (45116981)
be755000 be771920 naiavf5x naiavf5x.sys Thu Dec 21 01:39:47 2006 (4589E5E3)
be9a2000 be9c4ac0 Fastfat Fastfat.SYS Tue Jul 19 11:44:42 2005 (42DCD99A)
beacd000 beadc600 Cdfs Cdfs.SYS Sat Apr 02 02:23:36 2005 (424DF418)
beadd000 beae5a60 termdd termdd.sys Fri Mar 21 21:43:08 2003 (3E7B876C)
beb81000 beb83f20 spud spud.sys Fri Nov 19 23:36:27 1999 (3835DEFB)
beddd000 bee175a0 srv srv.sys Fri Aug 11 15:16:58 2006 (44DC915A)
bef58000 bef75060 afd afd.sys Thu May 08 09:38:05 2008 (4822BBED)
bf00a000 bf00cdc0 ndisuio ndisuio.sys Wed Jan 15 19:55:21 2003 (3E25BCA9)
bf066000 bf06e240 Fips Fips.SYS Tue May 09 16:28:29 2000 (39182E9D)
bf106000 bf16b620 mrxsmb mrxsmb.sys Wed May 31 08:14:13 2006 (447D4245)
bf17e000 bf1a7a20 rdbss rdbss.sys Tue Jul 19 06:42:03 2005 (42DC92AB)
bf1a8000 bf1d2d00 netbt netbt.sys Sat Apr 02 02:23:24 2005 (424DF40C)
bf273000 bf2c1300 tcpip tcpip.sys Wed Jun 18 11:05:04 2008 (4858DDD0)
bf3a6000 bf3a96c0 dump_diskdump dump_diskdump.sys Tue Feb 25 19:18:04 2003 (3E5BC16C)
bfbd2000 bfbfc3a0 update update.sys Wed Apr 16 05:22:01 2003 (3E9CDA69)
bfbfd000 bfc18b40 ks ks.sys Wed Apr 16 05:02:11 2003 (3E9CD5C3)
bfc2b000 bfc4e060 rdpdr rdpdr.sys Fri Mar 21 21:43:14 2003 (3E7B8772)
bfc4f000 bfc65ba0 ndiswan ndiswan.sys Wed Apr 30 00:05:01 2003 (3EAF051D)
bfc66000 bfc93600 cpqteam cpqteam.sys Wed Jul 19 10:05:22 2006 (44BDF5D2)
bfc94000 bfcb9100 q57w2k q57w2k.sys Wed May 10 22:55:03 2006 (44626137)
bfcba000 bfcfaf00 cpqasm2 cpqasm2.sys Fri Jul 14 19:56:47 2006 (44B7E8EF)
bfcfb000 bfd50600 ati2mpad ati2mpad.sys Mon Feb 09 21:54:11 2004 (40280183)
bfd69000 bfd6c580 vga vga.sys Sat Sep 25 19:37:40 1999 (37ED1674)
bfdc1000 bfdc4e60 TDI TDI.SYS Wed Jan 15 19:56:26 2003 (3E25BCEA)
bfe0d000 bfe0f2e0 ndistapi ndistapi.sys Wed Jan 15 19:54:15 2003 (3E25BC67)
bfe19000 bfe1c640 serenum serenum.sys Wed Jan 15 19:47:01 2003 (3E25BAB5)
bfe51000 bfe6b000 CPQPHP CPQPHP.SYS Fri Apr 23 17:44:10 2004 (408947DA)
bfe6b000 bfe80be0 Mup Mup.sys Fri Dec 03 03:37:23 2004 (41AFDF73)
bfe81000 bfeaaaa0 NDIS NDIS.sys Wed Apr 30 00:05:01 2003 (3EAF051D)
bfeab000 bff28480 Ntfs Ntfs.sys Tue May 10 10:20:29 2005 (42807CDD)
bff29000 bff3a7c0 KSecDD KSecDD.sys Sun Sep 21 01:32:19 2003 (3F6CF193)
bff3b000 bff4d1c0 Dfs Dfs.sys Wed Feb 12 02:19:06 2003 (3E49AF1A)
bff4e000 bff6f5c0 fltmgr fltmgr.sys Tue Aug 22 08:18:38 2006 (44EAAFCE)
bff70000 bff85180 atapi atapi.sys Tue Apr 01 19:08:25 2003 (3E89D599)
bff86000 bff98180 SCSIPORT SCSIPORT.SYS Thu Jul 14 13:24:06 2005 (42D65966)
bff99000 bffba9c0 dmio dmio.sys Wed Jan 15 19:47:04 2003 (3E25BAB8)
bffbb000 bffd75a0 ftdisk ftdisk.sys Fri Dec 03 03:29:58 2004 (41AFDDB6)
bffd8000 bffffc20 ACPI ACPI.sys Wed Jan 15 19:44:22 2003 (3E25BA16)
eb000000 eb00e6a0 pci pci.sys Wed Jan 15 19:44:07 2003 (3E25BA07)
eb010000 eb01b680 isapnp isapnp.sys Wed Jan 15 19:43:47 2003 (3E25B9F3)
eb020000 eb02fb20 cpq32fs2 cpq32fs2.sys Tue Jul 09 15:57:41 2002 (3D2AF9E5)
eb030000 eb03faa0 adpu160m adpu160m.sys Wed Jan 15 19:42:27 2003 (3E25B9A3)
eb040000 eb048700 CLASSPNP CLASSPNP.SYS Wed Jan 15 19:42:51 2003 (3E25B9BB)
eb050000 eb05b980 vsp vsp.sys Tue Sep 25 19:52:27 2007 (46F958EB)
eb060000 eb06c4c0 VIDEOPRT VIDEOPRT.SYS Wed Jan 15 19:47:20 2003 (3E25BAC8)
eb0a0000 eb0ab680 i8042prt i8042prt.sys Wed Apr 16 05:00:59 2003 (3E9CD57B)
eb0b0000 eb0bf400 serial serial.sys Wed Apr 16 05:19:39 2003 (3E9CD9DB)
eb0c0000 eb0ce580 CPQCISSE CPQCISSE.sys Fri Jun 16 18:13:23 2006 (4492E6B3)
eb0d0000 eb0dca80 rasl2tp rasl2tp.sys Wed Apr 30 00:05:06 2003 (3EAF0522)
eb0e0000 eb0ebc40 raspptp raspptp.sys Thu May 15 00:47:00 2003 (3EC2D574)
eb100000 eb109be0 usbhub usbhub.sys Tue Mar 18 23:30:41 2003 (3E77AC21)
eb130000 eb139ce0 NDProxy NDProxy.SYS Fri Oct 01 00:25:35 1999 (37F3F16F)
eb140000 eb148fa0 Npfs Npfs.SYS Sun Oct 10 00:58:07 1999 (37FFD68F)
eb150000 eb158680 msgpc msgpc.sys Wed Jan 15 19:54:25 2003 (3E25BC71)
eb160000 eb16d960 NEOFLTR_540_11529 NEOFLTR_540_11529.SYS Tue Jan 30 01:33:31 2007 (45BEA06B)
eb170000 eb17ea00 mvstdi5x mvstdi5x.sys Wed Jul 26 22:39:35 2006 (44C7E117)
eb180000 eb1881a0 netbios netbios.sys Tue Oct 12 20:34:19 1999 (38038D3B)
eb280000 eb285520 PCIIDEX PCIIDEX.SYS Tue Feb 25 18:31:08 2003 (3E5BB66C)
eb288000 eb28f4c0 MountMgr MountMgr.sys Tue Aug 16 09:40:55 2005 (4301A697)
eb290000 eb296320 symc8xx symc8xx.sys Fri Mar 30 18:01:54 2001 (3AC4BC02)
eb298000 eb29d180 sym_hi sym_hi.sys Sat Sep 25 20:11:49 1999 (37ED1E75)
eb2a0000 eb2a4080 cpqcissm cpqcissm.sys Fri May 19 18:12:50 2006 (446DFC92)
eb2a8000 eb2af720 disk disk.sys Wed Jan 15 19:43:05 2003 (3E25B9C9)
eb2c0000 eb2c7000 sysmgmt sysmgmt.sys Fri Jul 14 19:57:28 2006 (44B7E918)
eb2d8000 eb2de900 CpqCiDrv CpqCiDrv.sys Fri Mar 10 19:40:39 2006 (4411D637)
eb2e8000 eb2edec0 kbdclass kbdclass.sys Thu Feb 20 16:37:30 2003 (3E55044A)
eb2f8000 eb2fd400 mouclass mouclass.sys Thu Feb 20 16:37:45 2003 (3E550459)
eb308000 eb30c4a0 asyncmac asyncmac.sys Wed Jan 15 19:54:23 2003 (3E25BC6F)
eb310000 eb316580 fdc fdc.sys Wed Jan 15 19:42:51 2003 (3E25B9BB)
eb320000 eb326c40 cdrom cdrom.sys Wed Jan 15 19:43:04 2003 (3E25B9C8)
eb330000 eb335fc0 openhci openhci.sys Sat Mar 01 00:28:59 2003 (3E5FFECB)
eb338000 eb33c8c0 TDTCP TDTCP.SYS Fri Mar 21 21:43:08 2003 (3E7B876C)
eb348000 eb34cfc0 USBD USBD.SYS Wed Jan 22 17:05:33 2003 (3E2ECF5D)
eb360000 eb364080 dump_cpqcissm dump_cpqcissm.sys Fri May 19 18:12:50 2006 (446DFC92)
eb368000 eb36f0e0 Modem Modem.SYS Wed Jan 15 19:43:48 2003 (3E25B9F4)
eb388000 eb38c400 ptilink ptilink.sys Wed Jan 15 19:47:15 2003 (3E25BAC3)
eb398000 eb39c0e0 raspti raspti.sys Fri Oct 08 21:45:10 1999 (37FE57D6)
eb3b0000 eb3b4a60 flpydisk flpydisk.sys Wed Jan 15 19:42:52 2003 (3E25B9BC)
eb3c0000 eb3c6a20 EFS EFS.SYS Wed Jan 15 19:46:55 2003 (3E25BAAF)
eb3e0000 eb3e5240 Msfs Msfs.SYS Wed Oct 27 00:21:32 1999 (3816377C)
eb400000 eb407d00 wanarp wanarp.sys Fri Aug 16 13:25:01 2002 (3D5CEF1D)
eb410000 eb412a20 BOOTVID BOOTVID.dll Thu Nov 04 01:24:33 1999 (3820E051)
eb414000 eb416d00 PartMgr PartMgr.sys Wed Jan 15 19:43:07 2003 (3E25B9CB)
eb418000 eb41a9e0 cpqarray cpqarray.sys Wed Jan 15 19:42:35 2003 (3E25B9AB)
eb41c000 eb41ffe0 symc810 symc810.sys Sat Sep 25 20:11:49 1999 (37ED1E75)
eb420000 eb423360 cpqarry2 cpqarry2.sys Sat Oct 02 00:47:57 1999 (37F5482D)
eb500000 eb501d20 Diskperf Diskperf.sys Wed Feb 12 21:34:38 2003 (3E4ABDEE)
eb502000 eb503b80 dmload dmload.sys Wed Jan 15 19:47:06 2003 (3E25BABA)
eb508000 eb509680 RootMdm RootMdm.sys Sat Sep 25 19:34:56 1999 (37ED15D0)
eb510000 eb511ca0 Fs_Rec Fs_Rec.SYS Wed Jan 15 19:53:30 2003 (3E25BC3A)
eb518000 eb519e40 rasacd rasacd.sys Sat Sep 25 19:41:23 1999 (37ED1753)
eb586000 eb587400 EGATHDRV EGATHDRV.SYS Mon Jun 23 11:47:13 2003 (3EF6DAB1)
eb5c8000 eb5c8f80 WMILIB WMILIB.SYS Sat Sep 25 19:36:47 1999 (37ED163F)
eb5c9000 eb5c9b00 pciide pciide.sys Wed Jan 15 19:43:03 2003 (3E25B9C7)
eb5f3000 eb5f3a40 audstub audstub.sys Sat Sep 25 19:35:33 1999 (37ED15F5)
eb5ff000 eb5ffd80 swenum swenum.sys Sat Sep 25 19:36:31 1999 (37ED162F)
eb612000 eb6129e0 Null Null.SYS Sat Sep 25 19:34:58 1999 (37ED15D2)
eb614000 eb614ee0 Beep Beep.SYS Wed Oct 20 23:18:59 1999 (380E3FD3)
eb617000 eb617f80 mnmdd mnmdd.SYS Sat Sep 25 19:37:40 1999 (37ED1674)

Unloaded modules:
eb190000 eb199000 redbook.sys
Timestamp: unavailable (00000000)
Checksum: 00000000
eb3d0000 eb3d5000 Cdaudio.SYS
Timestamp: unavailable (00000000)
Checksum: 00000000
bfd71000 bfd74000 Sfloppy.SYS
Timestamp: unavailable (00000000)
Checksum: 00000000
Closing open log file c:temp\debuglog.txt

matthewgunn1974 is offline   Reply With Quote
Didn't find the information you thought to find?
Check out these Similar Threads
Old 5th November 2008   #2
Administrator
Microsoft MVP
 
Arie's Avatar
 
Profile:
Join Date: Dec 2001
Location: Birkirkara, Malta
Posts: 7,685
Computer Experience:
***
Arie Reputation LevelArie Reputation LevelArie Reputation LevelArie Reputation LevelArie Reputation LevelArie Reputation LevelArie Reputation LevelArie Reputation LevelArie Reputation LevelArie Reputation LevelArie Reputation Level

My System

Have a look at Interpreting Bug Check 0xCB. It has instructions on how to find the offending driver.
Arie is offline   Reply With Quote
Old 6th November 2008   #3
Member
 
Profile:
Join Date: Nov 2008
Posts: 2
Computer Experience:
experienced
matthewgunn1974 Reputation Level


Looked at the link and tried the following

1: kd> !search 804e8582
Searching pfn's in range 00000001 - 0007FFF9 for [804E8582 - 804E8582]

Pfn Offset Va
--------------------------------
Search done.


which did not show me any thing as expected.

matthewgunn1974 is offline   Reply With Quote
Reply

Thread Tools


Similar Threads
Thread Thread Starter Forum Replies Last Post
Microsoft Knowledge Base Articles published 16-Oct-2006 through 23-Oct-2006 Arie New Microsoft Knowledge Base Articles 0 9th February 2007 21:49
Microsoft Knowledge Base Articles published 05-Sep-2006 through 12-Sep-2006 Arie New Microsoft Knowledge Base Articles 0 19th September 2006 22:13
Microsoft Knowledge Base Articles published 14-Aug-2006 through 21-Aug-2006 Arie New Microsoft Knowledge Base Articles 0 5th September 2006 11:53
ftp from wan w2k server jawdoc Windows Server System 1 21st April 2006 17:16
Gigabit very slow - w2k3 server and w2k pro cerulean Networking 4 11th March 2005 17:02


All times are GMT +1. The time now is 22:12.






Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0
Copyright © 2002 - 2008 WindowsBBS.com. All rights reserved.
Terms of Use, Legal Information & Privacy Policy
[]