1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Memory Dump W2k3

Discussion in 'Windows Server System' started by jvrocamora, 2007/10/02.

  1. 2007/10/02
    jvrocamora

    jvrocamora Inactive Thread Starter

    Joined:
    2007/10/02
    Messages:
    1
    Likes Received:
    0
    Hello, need help. My server is down and is restarted.

    I see with windbg the memory.dmp, but i can't solve the problem. Put the log:

    THANK YOU.


    --------------------------------------------------------------------

    Opened log file 'c:\debuglog.txt'

    Microsoft (R) Windows Debugger Version 6.7.0005.1
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [c:\memory\MEMORY.DMP]
    Kernel Summary Dump File: Only kernel address space is available

    Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
    Executable search path is: C:\WINDOWS;C:\WINDOWS\system32;C:\WINDOWS\system32\drivers
    Windows Server 2003 Kernel Version 3790 MP (4 procs) Free x86 compatible
    Product: Server, suite: Enterprise TerminalServer SingleUserTS
    Built by: 3790.srv03_gdr.040410-1234
    Kernel base = 0x804de000 PsLoadedModuleList = 0x80567aa8
    Debug session time: Mon Oct 1 09:24:09.390 2007 (GMT+2)
    System Uptime: 4 days 22:48:14.427
    Loading Kernel Symbols
    ................................................................................................
    Loading User Symbols
    PEB is paged out (Peb.Ldr = 7ffdf00c). Type ".hh dbgerr001" for details
    Loading unloaded module list
    ...
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 50, {e56ef0dc, 0, bf869328, 1}

    Probably caused by : win32k.sys ( win32k!IFIOBJR::IFIOBJR+61 )

    Followup: MachineOwner
    ---------

    0: kd> !analyze -v;r;kv;lmtn;.logclose;q
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    PAGE_FAULT_IN_NONPAGED_AREA (50)
    Invalid system memory was referenced. This cannot be protected by try-except,
    it must be protected by a Probe. Typically the address is just plain bad or it
    is pointing at freed memory.
    Arguments:
    Arg1: e56ef0dc, memory referenced.
    Arg2: 00000000, value 0 = read operation, 1 = write operation.
    Arg3: bf869328, If non-zero, the instruction address which referenced the bad memory
    address.
    Arg4: 00000001, (reserved)

    Debugging Details:
    ------------------


    READ_ADDRESS: e56ef0dc Paged pool

    FAULTING_IP:
    win32k!IFIOBJR::IFIOBJR+61
    bf869328 f3a5 rep movs dword ptr es:[edi],dword ptr [esi]

    MM_INTERNAL_CODE: 1

    IMAGE_NAME: win32k.sys

    DEBUG_FLR_IMAGE_TIMESTAMP: 41d1eb91

    MODULE_NAME: win32k

    FAULTING_MODULE: bf800000 win32k

    DEFAULT_BUCKET_ID: DRIVER_FAULT

    BUGCHECK_STR: 0x50

    PROCESS_NAME: EXCEL.EXE

    CURRENT_IRQL: 1

    TRAP_FRAME: 8e461ba4 -- (.trap 0xffffffff8e461ba4)
    .trap 0xffffffff8e461ba4
    ErrCode = 00000000
    eax=e56eefe0 ebx=8e461c44 ecx=00000005 edx=00006000 esi=e56ef0dc edi=8e461c50
    eip=bf869328 esp=8e461c18 ebp=8e461c24 iopl=0 nv up ei ng nz na po nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010282
    win32k!IFIOBJR::IFIOBJR+0x61:
    bf869328 f3a5 rep movs dword ptr es:[edi],dword ptr [esi] es:0023:8e461c50=8e461cd4 ds:0023:e56ef0dc=????????
    .trap
    Resetting default scope

    LAST_CONTROL_TRANSFER: from 8052a9a8 to 805011b9

    STACK_TEXT:
    8e461b30 8052a9a8 00000050 e56ef0dc 00000000 nt!KeBugCheckEx+0x19
    8e461b8c 8054d1f0 00000000 e56ef0dc 00000000 nt!MmAccessFault+0x972
    8e461b8c bf869328 00000000 e56ef0dc 00000000 nt!KiTrap0E+0xc8
    8e461c24 bf868ecd e56eeef0 8e461cd4 8e461ce0 win32k!IFIOBJR::IFIOBJR+0x61
    8e461c7c bf869356 8e461cd4 8e461ce0 8e461cf4 win32k!bIFIMetricsToTextMetricWStrict+0x1c
    8e461ca0 bf83d47e 8e461cd4 8e461ce0 8e461cf4 win32k!bIFIMetricsToTextMetricW+0x1a
    8e461cbc bf83d4c0 8e461cd4 8e461ce0 8e461cf4 win32k!bGetTextMetrics+0x73
    8e461cd8 bf83d51b edf91008 8e461cf4 8e461d64 win32k!GreGetTextMetricsW+0x3b
    8e461d50 8054a42d 27210f09 0013f750 00000044 win32k!NtGdiGetTextMetricsW+0x20
    8e461d50 7ffe0304 27210f09 0013f750 00000044 nt!KiSystemService+0xd0
    0013f794 00000000 00000000 00000000 00000000 SharedUserData!SystemCallStub+0x4


    STACK_COMMAND: kb

    FOLLOWUP_IP:
    win32k!IFIOBJR::IFIOBJR+61
    bf869328 f3a5 rep movs dword ptr es:[edi],dword ptr [esi]

    SYMBOL_STACK_INDEX: 3

    FOLLOWUP_NAME: MachineOwner

    SYMBOL_NAME: win32k!IFIOBJR::IFIOBJR+61

    FAILURE_BUCKET_ID: 0x50_win32k!IFIOBJR::IFIOBJR+61

    BUCKET_ID: 0x50_win32k!IFIOBJR::IFIOBJR+61

    Followup: MachineOwner
    ---------

    eax=ffdff13c ebx=00000050 ecx=87f31370 edx=8054ea91 esi=ffdff120 edi=00000000
    eip=805011b9 esp=8e461b18 ebp=8e461b30 iopl=0 nv up ei ng nz na pe nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00000286
    nt!KeBugCheckEx+0x19:
    805011b9 5d pop ebp
    ChildEBP RetAddr Args to Child
    8e461b30 8052a9a8 00000050 e56ef0dc 00000000 nt!KeBugCheckEx+0x19 (FPO: [Non-Fpo])
    8e461b8c 8054d1f0 00000000 e56ef0dc 00000000 nt!MmAccessFault+0x972 (FPO: [Non-Fpo])
    8e461b8c bf869328 00000000 e56ef0dc 00000000 nt!KiTrap0E+0xc8 (FPO: [0,0] TrapFrame @ 8e461ba4)
    8e461c24 bf868ecd e56eeef0 8e461cd4 8e461ce0 win32k!IFIOBJR::IFIOBJR+0x61 (FPO: [Non-Fpo])
    8e461c7c bf869356 8e461cd4 8e461ce0 8e461cf4 win32k!bIFIMetricsToTextMetricWStrict+0x1c (FPO: [Non-Fpo])
    8e461ca0 bf83d47e 8e461cd4 8e461ce0 8e461cf4 win32k!bIFIMetricsToTextMetricW+0x1a (FPO: [Non-Fpo])
    8e461cbc bf83d4c0 8e461cd4 8e461ce0 8e461cf4 win32k!bGetTextMetrics+0x73 (FPO: [Non-Fpo])
    8e461cd8 bf83d51b edf91008 8e461cf4 8e461d64 win32k!GreGetTextMetricsW+0x3b (FPO: [Non-Fpo])
    8e461d50 8054a42d 27210f09 0013f750 00000044 win32k!NtGdiGetTextMetricsW+0x20 (FPO: [Non-Fpo])
    8e461d50 7ffe0304 27210f09 0013f750 00000044 nt!KiSystemService+0xd0 (FPO: [0,0] TrapFrame @ 8e461d64)
    0013f794 00000000 00000000 00000000 00000000 SharedUserData!SystemCallStub+0x4 (FPO: [0,0,0])
    start end module name
    804de000 806fe000 nt ntkrpamp.exe Thu May 27 01:51:22 2004 (40B52D7A)
    806fe000 80726000 hal halmacpi.dll Tue Mar 25 08:07:28 2003 (3E800030)
    b532e000 b5350000 RDPWD RDPWD.SYS Tue Mar 25 08:03:00 2003 (3E7FFF24)
    b5c59000 b5cb8000 srv srv.sys Tue Mar 25 09:49:51 2003 (3E80182F)
    b5d08000 b5d60000 HTTP HTTP.sys Tue Mar 25 09:55:21 2003 (3E801979)
    b5ec8000 b5ef7000 afd afd.sys Tue Mar 25 08:40:50 2003 (3E800802)
    b6425000 b643d000 Cdfs Cdfs.SYS Tue Mar 25 09:17:19 2003 (3E80108F)
    b65ab000 b65b4000 dump_diskdump dump_diskdump.sys Tue Mar 25 08:05:15 2003 (3E7FFFAB)
    b65db000 b65e5000 Dxapi Dxapi.sys Tue Mar 25 08:06:01 2003 (3E7FFFD9)
    b6a7f000 b6a86000 dxgthk dxgthk.sys Tue Mar 25 08:05:52 2003 (3E7FFFD0)
    b7331000 b733c000 dump_nfrd960 dump_nfrd960.sys Tue Mar 25 08:04:58 2003 (3E7FFF9A)
    b9670000 b967a000 TDTCP TDTCP.SYS Tue Mar 25 08:02:52 2003 (3E7FFF1C)
    b973b000 b974e000 Fips Fips.SYS Tue Mar 25 09:54:59 2003 (3E801963)
    b974e000 b97ba000 mrxsmb mrxsmb.sys Wed Jan 19 02:35:18 2005 (41EDB956)
    b97ba000 b97e5000 rdbss rdbss.sys Tue Oct 12 02:38:09 2004 (416B2771)
    b97e5000 b981a000 netbt netbt.sys Fri Jul 18 19:16:03 2003 (3F182B53)
    b98ba000 b991c000 tcpip tcpip.sys Tue Mar 25 09:04:01 2003 (3E800D71)
    b991c000 b9938000 ipsec ipsec.sys Tue Mar 25 08:55:45 2003 (3E800B81)
    b9958000 b996b000 usbhub usbhub.sys Tue Mar 25 08:10:46 2003 (3E8000F6)
    b998b000 b99be000 update update.sys Tue Mar 25 09:59:59 2003 (3E801A8F)
    b99be000 b99f2000 rdpdr rdpdr.sys Tue Mar 25 08:09:30 2003 (3E8000AA)
    b99f2000 b9a07000 raspptp raspptp.sys Tue Mar 25 09:19:09 2003 (3E8010FD)
    b9a07000 b9a22000 ndiswan ndiswan.sys Tue Mar 25 09:48:19 2003 (3E8017D3)
    b9a22000 b9a39000 rasl2tp rasl2tp.sys Tue Mar 25 08:54:46 2003 (3E800B46)
    b9a39000 b9a5b400 b57xp32 b57xp32.sys Mon Jan 13 19:43:21 2003 (3E2308C9)
    b9a5c000 b9a7de80 USBPORT USBPORT.SYS Tue Mar 25 08:10:43 2003 (3E8000F3)
    b9a7e000 b9aa8000 ks ks.sys Tue Mar 25 09:47:36 2003 (3E8017A8)
    b9aa8000 b9abc000 redbook redbook.sys Tue Mar 25 08:04:38 2003 (3E7FFF86)
    b9abc000 b9ad0000 cdrom cdrom.sys Tue Mar 25 08:05:18 2003 (3E7FFFAE)
    b9ad0000 b9ae8000 serial serial.sys Tue Mar 25 08:40:08 2003 (3E8007D8)
    b9ae8000 b9afe000 i8042prt i8042prt.sys Tue Mar 25 10:01:43 2003 (3E801AF7)
    b9afe000 b9b17000 VIDEOPRT VIDEOPRT.SYS Tue Mar 25 08:08:02 2003 (3E800052)
    b9b17000 b9b6ad80 ati2mpad ati2mpad.sys Fri Jul 19 03:13:20 2002 (3D3767B0)
    b9e84000 b9e91000 netbios netbios.sys Tue Mar 25 08:09:53 2003 (3E8000C1)
    b9e94000 b9ea1000 wanarp wanarp.sys Tue Mar 25 08:11:22 2003 (3E80011A)
    b9ea4000 b9eb3000 msgpc msgpc.sys Tue Mar 25 08:10:12 2003 (3E8000D4)
    b9eb4000 b9ec0000 Npfs Npfs.SYS Tue Mar 25 08:08:59 2003 (3E80008B)
    b9ec4000 b9ece000 Msfs Msfs.SYS Tue Mar 25 08:08:56 2003 (3E800088)
    b9ed4000 b9ee0000 vga vga.sys Tue Mar 25 08:08:03 2003 (3E800053)
    ba509000 ba50c900 ibmhpa ibmhpa.sys Sat Feb 08 08:02:30 2003 (3E44AB86)
    ba54d000 ba56f000 Mup Mup.sys Tue Mar 25 09:55:58 2003 (3E80199E)
    ba56f000 ba5b0000 NDIS NDIS.sys Tue Mar 25 09:45:35 2003 (3E80172F)
    ba5b0000 ba64d000 Ntfs Ntfs.sys Tue Mar 25 08:40:05 2003 (3E8007D5)
    ba64d000 ba66e000 KSecDD KSecDD.sys Tue Mar 25 08:05:39 2003 (3E7FFFC3)
    ba66e000 ba684000 CLASSPNP CLASSPNP.SYS Tue Mar 25 08:38:14 2003 (3E800766)
    ba684000 ba695b60 AACMgt AACMgt.sys Fri Apr 28 06:49:19 2006 (44519ECF)
    ba696000 ba6aee80 adpu160m adpu160m.sys Mon Sep 17 22:55:53 2001 (3BA66359)
    ba6af000 ba6d5000 SCSIPORT SCSIPORT.SYS Tue Mar 25 09:01:25 2003 (3E800CD5)
    ba6d5000 ba6f1000 atapi atapi.sys Tue Mar 25 08:04:48 2003 (3E7FFF90)
    ba6f1000 ba712000 volsnap volsnap.sys Tue Mar 25 08:05:47 2003 (3E7FFFCB)
    ba712000 ba73c000 dmio dmio.sys Tue Mar 25 08:08:14 2003 (3E80005E)
    ba73c000 ba761000 ftdisk ftdisk.sys Tue Mar 25 08:05:26 2003 (3E7FFFB6)
    ba761000 ba776000 pci pci.sys Tue Mar 25 08:16:40 2003 (3E800258)
    ba776000 ba7a7000 ACPI ACPI.sys Tue Mar 25 08:16:21 2003 (3E800245)
    ba8a8000 ba8b1000 WMILIB WMILIB.SYS Tue Mar 25 08:13:00 2003 (3E80017C)
    ba8b8000 ba8c7000 isapnp isapnp.sys Tue Mar 25 08:16:35 2003 (3E800253)
    ba8c8000 ba8d5000 PCIIDEX PCIIDEX.SYS Tue Mar 25 08:04:44 2003 (3E7FFF8C)
    ba8d8000 ba8e7000 MountMgr MountMgr.sys Tue Mar 25 08:03:05 2003 (3E7FFF29)
    ba8e8000 ba8f6000 PartMgr PartMgr.sys Tue Mar 25 09:04:02 2003 (3E800D72)
    ba8f8000 ba903000 nfrd960 nfrd960.sys Tue Mar 25 08:04:58 2003 (3E7FFF9A)
    ba908000 ba917000 disk disk.sys Tue Mar 25 08:05:20 2003 (3E7FFFB0)
    ba918000 ba924000 Dfs Dfs.sys Tue Mar 25 08:09:52 2003 (3E8000C0)
    ba928000 ba931000 crcdisk crcdisk.sys Tue Mar 25 08:07:23 2003 (3E80002B)
    ba978000 ba984000 processr processr.sys Tue Mar 25 08:07:36 2003 (3E800038)
    ba988000 ba991000 watchdog watchdog.sys Tue Mar 25 08:09:01 2003 (3E80008D)
    ba998000 ba9a2000 kbdclass kbdclass.sys Tue Mar 25 08:03:10 2003 (3E7FFF2E)
    ba9a8000 ba9b2000 mouclass mouclass.sys Tue Mar 25 08:03:09 2003 (3E7FFF2D)
    ba9b8000 ba9c3000 fdc fdc.sys Tue Mar 25 08:04:31 2003 (3E7FFF7F)
    ba9c8000 ba9d2000 serenum serenum.sys Tue Mar 25 08:04:01 2003 (3E7FFF61)
    ba9d8000 ba9e1000 ndistapi ndistapi.sys Tue Mar 25 08:11:28 2003 (3E800120)
    ba9e8000 ba9f6000 raspppoe raspppoe.sys Tue Mar 25 08:11:37 2003 (3E800129)
    ba9f8000 baa03000 TDI TDI.SYS Tue Mar 25 08:14:28 2003 (3E8001D4)
    baa08000 baa13000 ptilink ptilink.sys Tue Mar 25 08:03:51 2003 (3E7FFF57)
    baa18000 baa21000 raspti raspti.sys Tue Mar 25 08:11:36 2003 (3E800128)
    baa28000 baa37000 termdd termdd.sys Tue Mar 25 08:02:52 2003 (3E7FFF1C)
    baa48000 baa56000 NDProxy NDProxy.SYS Tue Mar 25 08:11:30 2003 (3E800122)
    bab18000 bab21000 ndisuio ndisuio.sys Tue Mar 25 08:09:47 2003 (3E8000BB)
    bab28000 bab30000 kdcom kdcom.dll Tue Mar 25 08:08:00 2003 (3E800050)
    bab30000 bab38000 BOOTVID BOOTVID.dll Tue Mar 25 08:07:58 2003 (3E80004E)
    bab38000 bab3f000 pciide pciide.sys Tue Mar 25 08:04:46 2003 (3E7FFF8E)
    bab40000 bab47000 dmload dmload.sys Tue Mar 25 08:08:08 2003 (3E800058)
    bac00000 bac05a00 RTL8139 RTL8139.SYS Wed May 30 08:14:57 2001 (3B148FE1)
    bac08000 bac0c200 usbohci usbohci.sys Tue Mar 25 08:10:41 2003 (3E8000F1)
    bac10000 bac18000 audstub audstub.sys Tue Mar 25 08:09:12 2003 (3E800098)
    bac28000 bac30000 Fs_Rec Fs_Rec.SYS Tue Mar 25 08:08:36 2003 (3E800074)
    bac30000 bac37000 Null Null.SYS Tue Mar 25 08:03:05 2003 (3E7FFF29)
    bac38000 bac3f000 Beep Beep.SYS Tue Mar 25 08:03:04 2003 (3E7FFF28)
    bac40000 bac48000 mnmdd mnmdd.SYS Tue Mar 25 08:07:53 2003 (3E800049)
    bac48000 bac50000 RDPCDD RDPCDD.sys Tue Mar 25 08:03:05 2003 (3E7FFF29)
    bac50000 bac58000 rasacd rasacd.sys Tue Mar 25 08:11:50 2003 (3E800136)
    badb6000 badb7200 swenum swenum.sys Tue Mar 25 08:03:22 2003 (3E7FFF3A)
    badbc000 badbd580 USBD USBD.SYS Tue Mar 25 08:10:39 2003 (3E8000EF)
    bf800000 bf9c7000 win32k win32k.sys Wed Dec 29 00:26:09 2004 (41D1EB91)
    bf9c7000 bfa1d680 ati2drad ati2drad.dll Tue Mar 25 10:43:37 2003 (3E8024C9)
    bff60000 bff7b000 RDPDD RDPDD.dll Tue Mar 25 21:12:05 2003 (3E80B815)
    bff80000 bff96000 dxg dxg.sys Tue Mar 25 10:46:23 2003 (3E80256F)
    bffa0000 bffe8000 ATMFD ATMFD.DLL Tue Mar 25 10:46:23 2003 (3E80256F)

    Unloaded modules:
    b9e74000 b9e82000 imapi.sys
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    bac20000 bac28000 Sfloppy.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    b9ee4000 b9eee000 Flpydisk.SYS
    Timestamp: unavailable (00000000)
    Checksum: 00000000
    Closing open log file c:\debuglog.txt
     
  2. 2007/10/22
    cpc2004

    cpc2004 Inactive

    Joined:
    2005/07/08
    Messages:
    366
    Likes Received:
    0
    Upgrade graphical card device driver

    Your windows is crashed at GDI routine. I resolved a similar problem and the culprit is graphical card device driver.
     

  3. to hide this advert.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.