the system running Windows 2008 R2, all the time blue screen. attached filed is the dump file after analysis

Microsoft (R) Windows Debugger Version 6.12.0002.633 X86
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [D:\SyngoPlaza\CasesPlaza\081615-37565-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

WARNING: Whitespace at end of path element
Symbol search path is: SRV*C:\websymbols*http://msdl.microsoft.com/download/symbols


Executable search path is: 
Windows 7 Kernel Version 7601 (Service Pack 1) MP (48 procs) Free x64
Product: Server, suite: Enterprise TerminalServer SingleUserTS
Built by: 7601.18869.amd64fre.win7sp1_gdr.150525-0603
Machine Name:
Kernel base = 0xfffff800`01e60000 PsLoadedModuleList = 0xfffff800`020a7730
Debug session time: Sun Aug 16 10:34:47.646 2015 (UTC + 8:00)
System Uptime: 1 days 16:15:01.240
Loading Kernel Symbols
...............................................................
................................................................
...........................................
Loading User Symbols
Loading unloaded module list
.......
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck D1, {28, 2, 0, fffff88001a6609b}

Probably caused by : tcpip.sys ( tcpip!TcpSegmentTcbSend+1ab )

Followup: MachineOwner
---------

2: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high.  This is usually
caused by drivers using improper addresses.
If kernel debugger is available get stack backtrace.
Arguments:
Arg1: 0000000000000028, memory referenced
Arg2: 0000000000000002, IRQL
Arg3: 0000000000000000, value 0 = read operation, 1 = write operation
Arg4: fffff88001a6609b, address which referenced memory

Debugging Details:
------------------


READ_ADDRESS: GetPointerFromAddress: unable to read from fffff80002111100
 0000000000000028 

CURRENT_IRQL:  2

FAULTING_IP: 
tcpip!TcpSegmentTcbSend+1ab
fffff880`01a6609b 418b4828        mov     ecx,dword ptr [r8+28h]

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  DRIVER_FAULT_SERVER_MINIDUMP

BUGCHECK_STR:  0xD1

PROCESS_NAME:  System

TRAP_FRAME:  fffff880046726c0 -- (.trap 0xfffff880046726c0)
NOTE: The trap frame does not contain all registers.
Some register values may be zeroed or incorrect.
rax=0000000000000020 rbx=0000000000000000 rcx=0000000000000020
rdx=0000000000000020 rsi=0000000000000000 rdi=0000000000000000
rip=fffff88001a6609b rsp=fffff88004672850 rbp=0000000000000020
 r8=0000000000000000  r9=0000000000000000 r10=fffffa8047cde428
r11=fffffa803ba797a0 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up ei pl zr na po nc
tcpip!TcpSegmentTcbSend+0x1ab:
fffff880`01a6609b 418b4828        mov     ecx,dword ptr [r8+28h] ds:00000000`00000028=????????
Resetting default scope

LAST_CONTROL_TRANSFER:  from fffff80001ed3e69 to fffff80001ed48c0

STACK_TEXT:  
fffff880`04672578 fffff800`01ed3e69 : 00000000`0000000a 00000000`00000028 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx
fffff880`04672580 fffff800`01ed2ae0 : fffffa80`00000006 fffffa80`2a8a6cb0 fffffa80`1b360002 fffff880`04672a60 : nt!KiBugCheckDispatch+0x69
fffff880`046726c0 fffff880`01a6609b : 00000000`00000020 fffff880`04672a60 fffffa80`49010360 fffff880`04672a60 : nt!KiPageFault+0x260
fffff880`04672850 fffff880`01a643c6 : 00000000`b9022d1f fffffa80`3a900f20 fffffa80`47cde428 fffffa80`3a900fe8 : tcpip!TcpSegmentTcbSend+0x1ab
fffff880`04672950 fffff880`01a685d9 : fffffa80`1b86c080 fffffa80`1ce73101 00000000`0000c099 00000000`00010000 : tcpip!TcpBeginTcbSend+0xa66
fffff880`04672bd0 fffff880`01a69450 : fffffa80`1b092000 fffff880`0209a270 00000000`00000000 fffff880`0207dac0 : tcpip!TcpTcbSend+0x1d9
fffff880`04672e50 fffff880`01a681a8 : 00000000`00000000 00000000`00000000 fffff880`0209a890 fffff880`0209a970 : tcpip!TcpEnqueueTcbSendOlmNotifySendComplete+0xa0
fffff880`04672e80 fffff880`01a6836b : fffff880`0209a6a0 fffff880`0209a720 fffff880`0207dac0 00000000`00000246 : tcpip!TcpEnqueueTcbSend+0x258
fffff880`04672f30 fffff800`01ecc3b7 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : tcpip!TcpTlConnectionSendCalloutRoutine+0x1b
fffff880`04672f60 fffff800`01ecc378 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KySwitchKernelStackCallout+0x27
fffff880`0209a760 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSwitchKernelStackContinue


STACK_COMMAND:  kb

FOLLOWUP_IP: 
tcpip!TcpSegmentTcbSend+1ab
fffff880`01a6609b 418b4828        mov     ecx,dword ptr [r8+28h]

SYMBOL_STACK_INDEX:  3

SYMBOL_NAME:  tcpip!TcpSegmentTcbSend+1ab

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: tcpip

IMAGE_NAME:  tcpip.sys

DEBUG_FLR_IMAGE_TIMESTAMP:  533f5bd4

FAILURE_BUCKET_ID:  X64_0xD1_tcpip!TcpSegmentTcbSend+1ab

BUCKET_ID:  X64_0xD1_tcpip!TcpSegmentTcbSend+1ab

Followup: MachineOwner
---------
August 18th, 2015 2:56am

On Tue, 18 Aug 2015 06:55:32 +0000, Yonglin Li wrote:

Microsoft (R) Windows Debugger Version 6.12.0002.633 X86
Copyright (c) Microsoft Corporation. All rights reserved.

You're posting in the wrong group. This group is for Windows Server 2016,
not 20

Free Windows Admin Tool Kit Click here and download it now
August 18th, 2015 3:28am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics