Hello Suchit,
Cluster bugchecked machine because Resource Host Monitor has not completed termination in 20 minutes. One of the RHS threads is stuck in the kernel for
about 20 minutes. Looks like things are getting stuck in TmXPFlt.sys.
As a remediation you might want to uninstall this product until issue is resolved. I would also suggest to talk to support of the company that provided
that solution to see if they have a fix and to make sure they are aware of that issue.
I see lots of threads in the system are stuck with a similar call stack.
Loaded symbol image file: TmXPFlt.sys
Image path: \??\C:\Program Files (x86)\Trend Micro\OfficeScan Client\TmXPFlt.sys
Image name: TmXPFlt.sys
Timestamp: Sat Aug 30 06:11:38 2014 (5401CD8A)
CheckSum: 0005DDB6
ImageSize: 0006C000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
THREAD fffffa806e2d6080 Cid 0d94.0f6c
Teb: 000007f7a0c6e000 Win32Thread: fffff90102e3ab80 WAIT: (Executive) KernelMode Non-Alertable
fffff88007394440 SynchronizationEvent
IRP List:
fffffa8033b24010: (0006,03e8) Flags: 00000884 Mdl: 00000000
Not impersonating
DeviceMap
fffff8a00000c310
Owning Process
fffffa8032dd9980 Image:
rhs.exe
Attached Process
N/A
Image: N/A
Wait Start TickCount
750939 Ticks: 76757
(0:00:19:59.328)
Context Switch Count 378
IdealProcessor: 5
UserTime
00:00:00.015
KernelTime
00:00:00.015
Win32 Start Address 0x000007f7a13cbc24
Stack Init fffff88007395c90 Current fffff88007394190
Base fffff88007396000 Limit fffff88007390000 Call 0
Priority 14 BasePriority 13 UnusualBoost 0 ForegroundBoost 0 IoPriority 2 PagePriority 5
Child-SP
RetAddr
Call Site
fffff880`073941d0 fffff800`342aff79 nt!KiSwapContext+0x76
(Inline Function) --------`-------- nt!KiSwapThread+0xfa (Inline Function @ fffff800`342aff79)
fffff880`07394310 fffff800`342ac21f nt!KiCommitThreadWait+0x229
fffff880`07394380 fffff880`05050457 nt!KeWaitForSingleObject+0x1cf
fffff880`07394410 fffff880`050460df TmXPFlt+0xe457
fffff880`07394470 fffff880`04384df5 TmXPFlt+0x40df
fffff880`07394590 fffff880`016ae844 TmPreFlt!TmpQueryFullName+0xd61
fffff880`07394660 fffff880`016afa6c fltmgr!FltpPerformPreCallbacks+0x324
fffff880`07394770 fffff880`016da349 fltmgr!FltpPassThroughInternal+0x8c
fffff880`073947a0 fffff800`34655228 fltmgr!FltpCreate+0x339
(Inline Function) --------`-------- nt!IoCallDriverWithTracing+0xc3 (Inline Function @ fffff800`34655228)
fffff880`07394850 fffff800`34668470 nt!IopParseDevice+0x173c
fffff880`07394a30 fffff800`34656978 nt!ObpLookupObjectName+0x644
fffff880`07394b40 fffff800`3466930e nt!ObOpenObjectByName+0x258
fffff880`07394c10 fffff800`3463f96c nt!IopCreateFile+0x37c
fffff880`07394cb0 fffff800`34284d53 nt!NtOpenFile+0x58
fffff880`07394d40 fffff800`34289f30 nt!KiSystemServiceCopyEnd+0x13 (TrapFrame @ fffff880`07394db0)
fffff880`07394f48 fffff800`34626a68 nt!KiServiceLinkage
fffff880`07394f50 fffff800`34284d53 nt!NtCreateUserProcess+0x400
fffff880`07395a90 000007fb`572a371b nt!KiSystemServiceCopyEnd+0x13 (TrapFrame @ fffff880`07395b00)
000000a4`76ced028 00000000`00000000 0x000007fb`572a371b
Ive also noticed several threads where TmXPFlt is trying to open a file over SMB. Perhaps all other activity is stuck behind these activities, but it is hard to tell without symbols.
THREAD fffffa806e078080
Cid 0004.0c9c Teb: 0000000000000000 Win32Thread: 0000000000000000 WAIT: (Executive) KernelMode Non-Alertable
fffffa803444e190 SynchronizationEvent
IRP List:
fffffa806f440010: (0006,01f0) Flags: 00000884 Mdl: 00000000
Impersonation token:
fffff8a00dc72270 (Level Impersonation)
DeviceMap
fffff8a00e5514b0
Owning Process
fffffa8030bc9980 Image:
System
Attached Process
N/A
Image: N/A
Wait Start TickCount
728673 Ticks: 99023 (0:00:25:47.234)
Context Switch Count
42000 IdealProcessor: 7
UserTime
00:00:00.000
KernelTime
00:00:40.156
Win32 Start Address TmXPFlt (0xfffff8800504dddc)
Stack Init fffff88009395fd0 Current fffff88009395b80
Base fffff88009396000 Limit fffff88009390000 Call 0
Priority 12 BasePriority 8 UnusualBoost 3 ForegroundBoost 0 IoPriority 2 PagePriority 5
Child-SP
RetAddr
Call Site
fffff880`09395bc0 fffff800`342aff79 nt!KiSwapContext+0x76
(Inline Function) --------`-------- nt!KiSwapThread+0xfa (Inline Function @ fffff800`342aff79)
fffff880`09395d00 fffff800`342ac21f nt!KiCommitThreadWait+0x229
fffff880`09395d70 fffff880`056483bb nt!KeWaitForSingleObject+0x1cf
fffff880`09395e00 fffff880`0563ffde mrxsmb10!SmbCeInitiateExchange+0x30f
fffff880`09395e70 fffff880`043a40db mrxsmb10!MRxSmbCreate+0x8d6
fffff880`09395f50 fffff800`342804a7 mrxsmb!SmbpShellCreateWithNewStack+0x1b
fffff880`09395f80 fffff800`3428046d nt!KySwitchKernelStackCallout+0x27 (TrapFrame @ fffff880`09395e40)
fffff880`0664b880 fffff800`342c786e nt!KiSwitchKernelStackContinue
fffff880`0664b8a0 fffff800`34243fc5 nt!KeExpandKernelStackAndCalloutInternal+0x20e
fffff880`0664b9a0 fffff880`043a40aa nt!KeExpandKernelStackAndCallout+0x15
fffff880`0664b9e0 fffff880`01ba8620 mrxsmb!SmbShellCreate+0x4a
fffff880`0664ba10 fffff880`01ba547d rdbss!RxCollapseOrCreateSrvOpen+0x210
fffff880`0664baa0 fffff880`01ba69ab rdbss!RxCreateFromNetRoot+0x63d
fffff880`0664bbd0 fffff880`01b6e652 rdbss!RxCommonCreate+0x15b
fffff880`0664bc70 fffff880`01ba059b rdbss!RxFsdCommonDispatch+0x522
fffff880`0664bdd0 fffff880`043d209c rdbss!RxFsdDispatch+0xcb
fffff880`0664be30 fffff880`01f37161 mrxsmb!MRxSmbFsdDispatch+0x8c
fffff880`0664be70 fffff880`01f34215 mup!MupiCallUncProvider+0x1b1
fffff880`0664bee0 fffff880`01f32475 mup!MupStateMachine+0xb6
fffff880`0664bf10 fffff880`016b04ee mup!MupCreate+0x165
fffff880`0664bf80 fffff880`016da35d fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x25e
fffff880`0664c020 fffff800`34655228 fltmgr!FltpCreate+0x34d
(Inline Function) --------`-------- nt!IoCallDriverWithTracing+0xc3 (Inline Function @ fffff800`34655228)
fffff880`0664c0d0 fffff800`34668470 nt!IopParseDevice+0x173c
fffff880`0664c2b0 fffff800`34656978 nt!ObpLookupObjectName+0x644
fffff880`0664c3c0 fffff800`3466930e nt!ObOpenObjectByName+0x258
fffff880`0664c490 fffff800`34669a59 nt!IopCreateFile+0x37c
fffff880`0664c530 fffff800`34284d53 nt!NtCreateFile+0x79
fffff880`0664c5c0 fffff800`34289f30 nt!KiSystemServiceCopyEnd+0x13 (TrapFrame @ fffff880`0664c630)
fffff880`0664c7c8 fffff880`04fb1651 nt!KiServiceLinkage
fffff880`0664c7d0 fffff880`04fb243a VSApiNt!VSSwapShortTable+0x721
fffff880`0664c840 fffff880`05049d16 VSApiNt!VSKDZwCreateFile+0x5a
fffff880`0664c8b0 fffff880`0504c1b9 TmXPFlt+0x7d16
fffff880`0664c980 fffff880`0504ce6e TmXPFlt+0xa1b9
fffff880`0664c9e0 fffff880`0504da7f TmXPFlt+0xae6e
fffff880`0664cb20 fffff880`0504def1 TmXPFlt+0xba7f
fffff880`0664cbe0 fffff800`3422f2c5 TmXPFlt+0xbef1
fffff880`0664cc10 fffff800`3426c656 nt!PspSystemThreadStartup+0x59 [d:\win8_ldr\minkernel\ntos\ps\psexec.c @ 5691]
fffff880`0664cc60 00000000`00000000 nt!KxStartSystemThread+0x16 [d:\win8_ldr\minkernel\ntos\ke\amd64\threadbg.asm @ 75]
Loaded symbol image file: VSApiNt.sys
Image path: \??\C:\Program Files (x86)\Trend Micro\OfficeScan Client\VSApiNt.sys
Image name: VSApiNt.sys
Timestamp: Sat Aug 30 06:03:46 2014 (5401CBB2)
CheckSum: 0024476C
ImageSize: 00238000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
Here is a list of all opens that are stack over SMB.
RxContext
RDR [ Maj, Min] Irp
Thread
FCB
fffffa8032dd4bb0
0 [ 0x 0, 0x 0] fffffa806e7df010 fffffa806eea9440 0000000000000000
16:08.471 CREATE
'\HMEL-BTH-DC03.hmel.int\IPC$'
fffffa8034749950
0 [ 0x 0, 0x 0] fffffa806f624d90 fffffa80342c4b00 fffff88001b998c0
13:29.967 CREATE
'<<empty>>'
fffffa8033ce44b0
0 [ 0x 0, 0x 0] fffffa806f130d10 fffffa80338bbb00 fffff8a00e5bf010
25:47.248 CREATE
'\Hmelbthdd\bth-evmjavsp01\EVMJAVSP01\2015\08-18\F\0E4\F0E43290E239950FABB7730FEA0B4421.DVS'
fffffa8033ee15e0
0 [ 0x 0, 0x 0] fffffa8033f27400 fffffa806f4a0900 fffff8a00ee432a0
25:47.248 CREATE
'\Hmelbthdd\bth-evmjavsp01\EVMJAVSP02\2015\05-07\6\125\6125F1071BA45DE8BA67A9D1E7004ED1~90~9F3EAD6D~00~1.DVSSP'
fffffa8034459200
0 [ 0x 0, 0x 0] fffffa806ef81be0 fffffa803413cb00 fffff8a00d5d4670
25:47.247 CREATE
'\Hmelbthdd\bth-evmjavsp01\EVMJAVSP01\2015\08-18\F\0E4\F0E4B8A43ECF2FB81443FFE354A7A931.DVS'
fffffa8033ac7950
2 [ 0x e, 0x 0] fffffa8032de64f0 fffffa8033896080 fffff8a00f667610
76:14.999 IOCTL
'\2'
fffffa8031f94010
2 [ 0x e, 0x 0] fffffa80335c2010 fffffa803216b600 fffff8a00f667610
44:46.553 IOCTL
'\2'
fffffa80335e05a0
0 [ 0x 0, 0x 0] fffffa803453ec20 fffffa8033ff5080 fffff8a00daac010
25:47.250 CREATE
'\Hmelbthdd\bth-evmjavsp01\EVMJAVSP01\2015\08-16\F\051\F0516C6C8D4D24CED66C01341EBC0F71.DVS'
fffffa8033b59610
0 [ 0x 0, 0x 0] fffffa80342b9600 fffffa806f8af5c0 fffff8a0118532a0
25:47.248 CREATE
'\Hmelbthdd\bth-evmjavsp01\EVMJAVSP02\2015\08-18\6\11D\611D856FB14A3D5416A61EF0D7116911~0F~C97B4131~00~1.DVSSP'
fffffa8033c93240
0 [ 0x 0, 0x 0] fffffa8033b2c580 fffffa8034381b00 fffff8a00da1d600
25:47.248 CREATE
'\Hmelbthdd\bth-evmjavsp01\EVMJAVSP01\2014\07-17\6\0A5\60A5BB94AFB6B48F2B15E53045337701~35~1FD28490~00~1.DVSSP'
fffffa806ef187f0
0 [ 0x 0, 0x 0] fffffa80340a4630 fffffa806e0c0080 fffff8a010c947e0
25:46.524 CREATE
'\Hmelbthdd\bth-evmjavsp01\EVMJAVSP02\2015\05-17\D\06B\D06B43ABD3EEB44CA7CB2FE2CAB27721~39~6A552458~00~1.DVSSP'
fffffa80336269a0
0 [ 0x 0, 0x 0] fffffa8033528780 fffffa806e0fa080 fffff8a012ccf010
25:46.499 CREATE
'\Hmelbthdd\bth-evmjavsp01\EVMJAVSP02\2015\03-05\3\03B\303B66B5ACE86D5696529DF90977A8F1~6D~5FD6F55D~00~1.DVSSP'
fffffa8034749cb0
0 [ 0x 0, 0x 0] fffffa806f030750 fffffa806f53e080 fffff88001b998c0
13:29.967 CREATE
'<<empty>>'
fffffa806f35fc20
0 [ 0x 0, 0x 0] fffffa80343ced10 fffffa803417fb00 fffff8a00d22e350
25:47.247 CREATE
'\Hmelbthdd\bth-evmjavsp01\EVMJAVSP02\2015\08-18\6\11D\611D8ED60F35534A9D9860B16528A501~C4~46589CF8~00~1.DVSSP'
fffffa803444e010
0 [ 0x 0, 0x 0] fffffa806f440010 fffffa806e078080 fffff8a00dd3e2f0
25:47.241 CREATE
'\Hmelbthdd\bth-evmjavsp01\EVMJAVSP02\2015\08-18\6\11D\611D8CD7E12525CA7EE50328316C7AF1~85~6174E8BD~00~1.DVSSP'
fffffa8034151010
0 [ 0x 0, 0x 0] fffffa8034366690 fffffa806e0fab00 fffff8a00d89d8e0
25:47.234 CREATE
'\Hmelbthdd\bth-evmjavsp01\EVMJAVSP01\2015\08-18\F\0E4\F0E4B2D443D4F8D070887D83728C6411.DVS'
fffffa8033fe7cb0
0 [ 0x 0, 0x 0] fffffa8033bf2d80 fffffa806e031b00 fffff8a00d66b500
25:47.234 CREATE
'\Hmelbthdd\bth-evmjavsp01\EVMJAVSP02\2015\08-18\6\11D\611D83CE4F080D152AB519841E0F9551.DVS'
fffffa806e9acb30
0 [ 0x 0, 0x 0] fffffa8033468940 fffffa806e0bfb00 fffff8a00e6bf010
25:47.234 CREATE
'\Hmelbthdd\bth-evmjavsp01\EVMJAVSP02\2015\08-18\6\11D\611D8585CAAFD30258F5F9204E8B8F21.DVS'
fffffa806f214cb0
0 [ 0x 0, 0x 0] fffffa8033e719a0 fffffa806f56e080 fffff8a012de3010
25:46.500 CREATE
'\Hmelbthdd\bth-evmjavsp01\EVMJAVSP02\2015\06-15\5\048\50488155ACE08770781A75BBD1F269C1~29~B78492F0~00~1.DVSSP'
fffffa8034747cb0
0 [ 0x 0, 0x 0] fffffa806f567380 fffffa806ebda480 fffff88001b998c0
13:29.967 CREATE
'<<empty>>'
fffffa80346e2010
0 [ 0x 0, 0x 0] fffffa8033c48730 fffffa803424ca80 fffff88001b998c0
13:29.967 CREATE
'<<empty>>'
fffffa80349fd310
0 [ 0x 0, 0x 0] fffffa8033d55b00 fffffa8033dbd100 fffff88001b998c0
3:29.963 CREATE
'<<empty>>'
fffffa803493e010
0 [ 0x 0, 0x 0] fffffa8033c3c010 fffffa80341a1b00 fffff88001b998c0
3:29.962 CREATE
'<<empty>>'
fffffa806f6fe010
0 [ 0x 0, 0x 0] fffffa806f32b680 fffffa806e0bdb00 fffff8a010d06730
25:47.234 CREATE
'\Hmelbthdd\bth-evmjavsp01\EVMJAVSP01\2015\08-18\F\0E9\F0E9001E013394D9C07EF02330BFB911.DVS'
fffffa806ec38010
0 [ 0x 0, 0x 0] fffffa806f07e700 fffffa806f366b00 fffff8a012ca2a80
25:47.225 CREATE
'\Hmelbthdd\bth-evmjavsp01\EVMJAVSP01\2015\08-18\F\0E7\F0E756057B9D6D2ABECB8E13E3415CC1.DVS'
fffffa806ee48230
0 [ 0x 0, 0x 0] fffffa806f132010 fffffa806e0be6c0 fffff8a01242a010
25:47.014 CREATE
'\Hmelbthdd\bth-evmjavsp01\EVMJAVSP01\2014\12-20\D\0C2\D0C292F3FB7A73F70208526C10EAF491.DVS'
fffffa806f78e9a0
0 [ 0x 0, 0x 0] fffffa806e8e12c0 fffffa8034337b00 fffff8a004aea010
25:46.501 CREATE
'\Hmelbthdd\bth-evmjavsp01\EVMJAVSP02\2015\05-17\C\0E1\C0E1AAE496323E417F8B4BEFFAAE1FB1~D5~E770E121~00~1.DVSSP'
fffffa806eb5a450
0 [ 0x 0, 0x 0] fffffa806ef3b6b0 fffffa806ee98b00 fffff88001b998c0
13:29.967 CREATE
'<<empty>>'
fffffa806f5f87f0
0 [ 0x 0, 0x 0] fffffa806f677010 fffffa806e0bf080 fffff8a00ffa4a60
25:47.190 CREATE
'\Hmelbthdd\bth-evmjavsp01\EVMJAVSP02\2015\05-29\5\0BC\50BCEB2E36C8C4FABB47EC3453CB13B1~F3~00A34DF4~00~1.DVSSP'
fffffa806f1d9770
0 [ 0x 0, 0x 0] fffffa806f46d390 fffffa806f048080 fffff8a01282a010
25:47.249 CREATE
'\Hmelbthdd\bth-evmjavsp01\EVMJAVSP01\2015\01-16\1\124\1124F16CCD8694D455954CAABDF10111~97~5E195B14~00~1.DVSSP'
fffffa806f71ecb0
0 [ 0x 0, 0x 0] fffffa806f543370 fffffa806f5cb080 fffff8a012705a80
25:47.248 CREATE
'\Hmelbthdd\bth-evmjavsp01\EVMJAVSP01\2015\08-15\1\00F\100F697A6B99B08748C65EBD6A56BC21.DVS'
fffffa806f703900
0 [ 0x 0, 0x 0] fffffa806f742010 fffffa806e0c06c0 fffff8a012b51380
25:47.221 CREATE
'\Hmelbthdd\bth-evmjavsp01\EVMJAVSP01\2015\08-13\F\011\F0116842118398CEE7462D0AE65D7601.DVS'
fffffa806eeee780
0 [ 0x 0, 0x 0] fffffa80345d6a10 fffffa806f38b300 fffff88001b998c0
3:29.962 CREATE
'<<empty>>'
fffffa806f529190
0 [ 0x 0, 0x 0] fffffa806f7f8320 fffffa806e0bab00 fffff8a012b145b0
25:47.249 CREATE
'\Hmelbthdd\bth-evmjavsp01'
fffffa806eb4b910
0 [ 0x 0, 0x 0] fffffa8034263e10 fffffa803438e080 fffff8a010b89a80
25:47.027 CREATE
'\Hmelbthdd\bth-evmjavsp01\EVMJAVSP01\2015\08-16\F\054\F054CC18A0FC36B2B94C5D416455D4B1.DVS'
fffffa803415c010
0 [ 0x 0, 0x 0] fffffa806f800510 fffffa806f267680 fffff88001b998c0
13:29.967 CREATE
'<<empty>>'
fffffa806ebee830
0 [ 0x 0, 0x 0] fffffa806f6fd010 fffffa8033ee4080 fffff88001b998c0
13:29.966 CREATE
'<<empty>>'
SMB client has several Irps stuck in the networking stack for a long time
Time Pending
IRP
25:47.251
fffffa806f775010
16:08.472
fffffa8033fb3b90
6: kd> !irp fffffa806f775010
Irp is active with 2 stacks 1 is current (= 0xfffffa806f7750e0)
No Mdl: No System Buffer: Thread 00000000:
Irp stack trace.
cmd flg cl Device File
Completion-Context
>[IRP_MJ_INTERNAL_DEVICE_CONTROL(f), N/A(10)]
0 e1 fffffa80315c6c10 00000000 fffff8800439d8b0-fffffa8033a6fd10 Success Error Cancel pending
\Driver\AFD
mrxsmb!SmbWskGetAddressInfoComplete
Args: fffffa803209e410 fffff880096e5ae0 fffffa803392d5c0 00000000
[N/A(0), N/A(0)]
0 0 00000000 00000000 00000000-00000000
Args: fffff88001b97a00 fffff88001b97a00 fffffa806f775010 7184f95f
6: kd> !irp fffffa8033fb3b90
Irp is active with 2 stacks 1 is current (= 0xfffffa8033fb3c60)
No Mdl: No System Buffer: Thread 00000000:
Irp stack trace.
cmd flg cl Device File
Completion-Context
>[IRP_MJ_INTERNAL_DEVICE_CONTROL(f), N/A(10)]
0 e1 fffffa80315c6c10 00000000 fffff8800439d8b0-fffffa806f77a240 Success Error Cancel pending
\Driver\AFD
mrxsmb!SmbWskGetAddressInfoComplete
Args: fffffa803209e410 fffff8800bf71c50 fffffa8033c71ec0 00000000
[N/A(0), N/A(0)]
0 0 00000000 00000000 00000000-00000000
Args: fffff88001b98b00 fffff88001b98b00 fffffa8033fb3b90 718dce3a
Looks like these Irps are calls from SMB client to DNS client to resolve names. NDIS should send up-call back to the DNS client service in user mode to resolve them. DNS client service is hosted in
one of the svchost.exe processes. I see many threads from svchost processes are stuck in TmXPFlt so it is possible that this is what is causing the deadlock.