sanity check please
I have dump i went throughand believethe problem is in a raid controler driver can somone confirm what i a reading.this is what i think it says:driver fault. the driver with the fualt is HpCISSs2.sys because of the line below.b9ffe000 ba011000 dump_HpCISSs2 dump_HpCISSs2.sys Thu Jun 21 20:33:49 2007 (467B431D)I have included the dump and the system info. I am getting ready to upgrade firmware and drivers because of what i think i see so i need a sanity check from soneone else before i do all this work on the servers.OS NameMicrosoft(R) Windows(R) Server 2003, Standard EditionVersion5.2.3790 Service Pack 2 Build 3790Other OS Description Not AvailableOS ManufacturerMicrosoft CorporationSystem NameSystem ManufacturerHPSystem ModelProLiant DL385 G2System TypeX86-based PCProcessorx86 Family 15 Model 65 Stepping 3 AuthenticAMD ~3000 MhzProcessorx86 Family 15 Model 65 Stepping 3 AuthenticAMD ~3000 MhzBIOS Version/DateHP A09, 4/7/2007SMBIOS Version2.3Windows DirectoryC:\WINDOWSSystem DirectoryC:\WINDOWS\system32Boot Device\Device\HarddiskVolume1LocaleUnited StatesHardware Abstraction LayerVersion = "5.2.3790.3959 (srv03_sp2_rtm.070216-1710)"User NameTime ZoneUS Mountain Standard TimeTotal Physical Memory4,093.63 MBAvailable Physical Memory3.33 GBTotal Virtual Memory5.83 GBAvailable Virtual Memory4.80 GBPage File Space2.00 GBPage FileC:\pagefile.sys Kernel Summary Dump File: Only kernel address space is available Symbol search path is: SRV*e:\localsymbols*http://msdl.microsoft.com/download/symbols;C:\WINDOWS\Symbols\windowsserversp2;C:\WINDOWS\Symbols\windowsserversp2\acm;C:\WINDOWS\Symbols\windowsserversp2\ax;C:\WINDOWS\Symbols\windowsserversp2\cnv;C:\WINDOWS\Symbols\windowsserversp2\com;C:\WINDOWS\Symbols\windowsserversp2\cpl;C:\WINDOWS\Symbols\windowsserversp2\dic;C:\WINDOWS\Symbols\windowsserversp2\dll;C:\WINDOWS\Symbols\windowsserversp2\drv;C:\WINDOWS\Symbols\windowsserversp2\exe;C:\WINDOWS\Symbols\windowsserversp2\iec;C:\WINDOWS\Symbols\windowsserversp2\ime;C:\WINDOWS\Symbols\windowsserversp2\ntd;C:\WINDOWS\Symbols\windowsserversp2\ocx;C:\WINDOWS\Symbols\windowsserversp2\scr;C:\WINDOWS\Symbols\windowsserversp2\symbolcd;C:\WINDOWS\Symbols\windowsserversp2\sys;C:\WINDOWS\Symbols\windowsserversp2\tpl;C:\WINDOWS\Symbols\windowsserversp2\tsp;C:\WINDOWS\Symbols\windowsserversp2\wpcExecutable search path is: Windows Server 2003 Kernel Version 3790 (Service Pack 2) MP (2 procs) Free x86 compatibleProduct: Server, suite: TerminalServer SingleUserTSBuilt by: 3790.srv03_sp2_gdr.080813-1204Machine Name:Kernel base = 0x80800000 PsLoadedModuleList = 0x808a6ea8Debug session time: Fri Feb 20 15:12:22.240 2009 (GMT-7)System Uptime: 2 days 21:23:26.721Loading Kernel Symbols............................................................................................................Loading User SymbolsPEB is paged out (Peb.Ldr = 7ffd400c). Type ".hh dbgerr001" for detailsLoading unloaded module list......******************************************************************************** ** Bugcheck Analysis ** ******************************************************************************** Use !analyze -v to get detailed debugging information. BugCheck F4, {3, 8a639240, 8a6393a4, 8094c6e6} Page caa76 not present in the dump file. Type ".hh dbgerr004" for detailsPage c6c6a not present in the dump file. Type ".hh dbgerr004" for detailsunable to get nt!KiCurrentEtwBufferOffsetunable to get nt!KiCurrentEtwBufferBasePEB is paged out (Peb.Ldr = 7ffd400c). Type ".hh dbgerr001" for detailsPEB is paged out (Peb.Ldr = 7ffd400c). Type ".hh dbgerr001" for detailsProbably caused by : csrss.exe Followup: MachineOwner--------- 0: kd> !analyze -v******************************************************************************** ** Bugcheck Analysis ** ******************************************************************************** CRITICAL_OBJECT_TERMINATION (f4)A process or thread crucial to system operation has unexpectedly exited or beenterminated.Several processes and threads are necessary for the operation of thesystem; when they are terminated (for any reason), the system can nolonger function.Arguments:Arg1: 00000003, ProcessArg2: 8a639240, Terminating objectArg3: 8a6393a4, Process image file nameArg4: 8094c6e6, Explanatory message (ascii) Debugging Details:------------------ Page caa76 not present in the dump file. Type ".hh dbgerr004" for detailsPage c6c6a not present in the dump file. Type ".hh dbgerr004" for detailsunable to get nt!KiCurrentEtwBufferOffsetunable to get nt!KiCurrentEtwBufferBasePEB is paged out (Peb.Ldr = 7ffd400c). Type ".hh dbgerr001" for detailsPEB is paged out (Peb.Ldr = 7ffd400c). Type ".hh dbgerr001" for details PROCESS_OBJECT: 8a639240 IMAGE_NAME: csrss.exe DEBUG_FLR_IMAGE_TIMESTAMP: 0 MODULE_NAME: csrss FAULTING_MODULE: 00000000 PROCESS_NAME: csrss.exe EXCEPTION_RECORD: b93cc4fc -- (.exr 0xffffffffb93cc4fc)ExceptionAddress: 7c84afa7 ExceptionCode: c0000005 (Access violation) ExceptionFlags: 00000000NumberParameters: 2 Parameter[0]: 00000000 Parameter[1]: ffffffffAttempt to read from address ffffffff EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s". DEFAULT_BUCKET_ID: DRIVER_FAULT CURRENT_IRQL: 0 ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s". EXCEPTION_PARAMETER1: 00000000 EXCEPTION_PARAMETER2: ffffffff READ_ADDRESS: ffffffff FOLLOWUP_IP: +3cb952f016fdfdc7c84afa7 ?? ??? FAULTING_IP: +3cb952f016fdfdc7c84afa7 ?? ??? FAILED_INSTRUCTION_ADDRESS: +3cb952f016fdfdc7c84afa7 ?? ??? BUGCHECK_STR: 0xF4_C0000005 EXCEPTION_STR: 0x2c000000 STACK_TEXT: b93cc048 8094b849 000000f4 00000003 8a639240 nt!KeBugCheckEx+0x1bb93cc06c 8094c78e 8094c6e6 8a639240 8a6393a4 nt!PspCatchCriticalBreak+0x75b93cc09c 808897bc ffffffff c0000005 b93cc4d4 nt!NtTerminateProcess+0x7ab93cc09c 8082fadd ffffffff c0000005 b93cc4d4 nt!KiFastCallEntry+0xfcb93cc11c 8082d80e ffffffff c0000005 b93cc518 nt!ZwTerminateProcess+0x11b93cc4d4 80831156 b93cc4fc 00000000 b93cc884 nt!KiDispatchException+0x390b93cc854 8088d173 0127f2ac 0127f2c8 00000000 nt!KiRaiseException+0x120b93cc870 808897bc 0127f2ac 0127f2c8 00000000 nt!NtRaiseException+0x33b93cc870 7c84afa7 0127f2ac 0127f2c8 00000000 nt!KiFastCallEntry+0xfcWARNING: Frame IP not in any known module. Following frames may be wrong.0127f5bc 00000000 00000000 00000000 00000000 0x7c84afa7 STACK_COMMAND: kb FOLLOWUP_NAME: MachineOwner FAILURE_BUCKET_ID: 0xF4_C0000005_IMAGE_csrss.exe BUCKET_ID: 0xF4_C0000005_IMAGE_csrss.exe Followup: MachineOwner--------- 0: kd> !analyze -v;r;kv;lmtn******************************************************************************** ** Bugcheck Analysis ** ******************************************************************************** CRITICAL_OBJECT_TERMINATION (f4)A process or thread crucial to system operation has unexpectedly exited or beenterminated.Several processes and threads are necessary for the operation of thesystem; when they are terminated (for any reason), the system can nolonger function.Arguments:Arg1: 00000003, ProcessArg2: 8a639240, Terminating objectArg3: 8a6393a4, Process image file nameArg4: 8094c6e6, Explanatory message (ascii) Debugging Details:------------------ Page caa76 not present in the dump file. Type ".hh dbgerr004" for detailsPage c6c6a not present in the dump file. Type ".hh dbgerr004" for detailsunable to get nt!KiCurrentEtwBufferOffsetunable to get nt!KiCurrentEtwBufferBasePEB is paged out (Peb.Ldr = 7ffd400c). Type ".hh dbgerr001" for detailsPEB is paged out (Peb.Ldr = 7ffd400c). Type ".hh dbgerr001" for details PROCESS_OBJECT: 8a639240 IMAGE_NAME: csrss.exe DEBUG_FLR_IMAGE_TIMESTAMP: 0 MODULE_NAME: csrss FAULTING_MODULE: 00000000 PROCESS_NAME: csrss.exe EXCEPTION_RECORD: b93cc4fc -- (.exr 0xffffffffb93cc4fc)ExceptionAddress: 7c84afa7 ExceptionCode: c0000005 (Access violation) ExceptionFlags: 00000000NumberParameters: 2 Parameter[0]: 00000000 Parameter[1]: ffffffffAttempt to read from address ffffffff EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s". DEFAULT_BUCKET_ID: DRIVER_FAULT CURRENT_IRQL: 0 ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s". EXCEPTION_PARAMETER1: 00000000 EXCEPTION_PARAMETER2: ffffffff READ_ADDRESS: ffffffff FOLLOWUP_IP: +3cb952f016fdfdc7c84afa7 ?? ??? FAULTING_IP: +3cb952f016fdfdc7c84afa7 ?? ??? FAILED_INSTRUCTION_ADDRESS: +3cb952f016fdfdc7c84afa7 ?? ??? BUGCHECK_STR: 0xF4_C0000005 EXCEPTION_STR: 0x2c000000 STACK_TEXT: b93cc048 8094b849 000000f4 00000003 8a639240 nt!KeBugCheckEx+0x1bb93cc06c 8094c78e 8094c6e6 8a639240 8a6393a4 nt!PspCatchCriticalBreak+0x75b93cc09c 808897bc ffffffff c0000005 b93cc4d4 nt!NtTerminateProcess+0x7ab93cc09c 8082fadd ffffffff c0000005 b93cc4d4 nt!KiFastCallEntry+0xfcb93cc11c 8082d80e ffffffff c0000005 b93cc518 nt!ZwTerminateProcess+0x11b93cc4d4 80831156 b93cc4fc 00000000 b93cc884 nt!KiDispatchException+0x390b93cc854 8088d173 0127f2ac 0127f2c8 00000000 nt!KiRaiseException+0x120b93cc870 808897bc 0127f2ac 0127f2c8 00000000 nt!NtRaiseException+0x33b93cc870 7c84afa7 0127f2ac 0127f2c8 00000000 nt!KiFastCallEntry+0xfcWARNING: Frame IP not in any known module. Following frames may be wrong.0127f5bc 00000000 00000000 00000000 00000000 0x7c84afa7 STACK_COMMAND: kb FOLLOWUP_NAME: MachineOwner FAILURE_BUCKET_ID: 0xF4_C0000005_IMAGE_csrss.exe BUCKET_ID: 0xF4_C0000005_IMAGE_csrss.exe Followup: MachineOwner--------- eax=ffdff13c ebx=8a639240 ecx=00000001 edx=00000000 esi=ffdff120 edi=8a639480eip=80827c83 esp=b93cc030 ebp=b93cc048 iopl=0 nv up ei ng nz na pe nccs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00000286nt!KeBugCheckEx+0x1b:80827c83 5d pop ebpChildEBP RetAddr Args to Child b93cc048 8094b849 000000f4 00000003 8a639240 nt!KeBugCheckEx+0x1b (FPO: [5,0,0])b93cc06c 8094c78e 8094c6e6 8a639240 8a6393a4 nt!PspCatchCriticalBreak+0x75 (FPO: [3,0,0])b93cc09c 808897bc ffffffff c0000005 b93cc4d4 nt!NtTerminateProcess+0x7a (FPO: [2,4,4])b93cc09c 8082fadd ffffffff c0000005 b93cc4d4 nt!KiFastCallEntry+0xfc (FPO: [0,0] TrapFrame @ b93cc0ac)b93cc11c 8082d80e ffffffff c0000005 b93cc518 nt!ZwTerminateProcess+0x11 (FPO: [2,0,0])b93cc4d4 80831156 b93cc4fc 00000000 b93cc884 nt!KiDispatchException+0x390 (FPO: [SEH])b93cc854 8088d173 0127f2ac 0127f2c8 00000000 nt!KiRaiseException+0x120 (FPO: [SEH])b93cc870 808897bc 0127f2ac 0127f2c8 00000000 nt!NtRaiseException+0x33b93cc870 7c84afa7 0127f2ac 0127f2c8 00000000 nt!KiFastCallEntry+0xfc (FPO: [0,0] TrapFrame @ b93cc884)WARNING: Frame IP not in any known module. Following frames may be wrong.0127f5bc 00000000 00000000 00000000 00000000 0x7c84afa7start end module name80800000 80a5a000 nt ntkrpamp.exe Wed Aug 13 02:42:13 2008 (48A2AC75)80a5a000 80a86000 hal halmacpi.dll Fri Feb 16 22:48:26 2007 (45D6972A)b9485000 b94b0000 RDPWD RDPWD.SYS Fri Feb 16 22:44:38 2007 (45D69646)b9968000 b9973000 TDTCP TDTCP.SYS Fri Feb 16 22:44:32 2007 (45D69640)b9b90000 b9bee000 srv srv.sys Thu Dec 11 04:35:59 2008 (4940FB1F)b9ffe000 ba011000 dump_HpCISSs2 dump_HpCISSs2.sys Thu Jun 21 20:33:49 2007 (467B431D)ba071000 ba07b000 ndisuio ndisuio.sys Fri Feb 16 22:58:25 2007 (45D69981)ba0b1000 ba0c6000 Cdfs Cdfs.SYS Fri Feb 16 23:27:08 2007 (45D6A03C)ba0ee000 ba0ff000 Fips Fips.SYS Fri Feb 16 23:26:33 2007 (45D6A019)ba0ff000 ba175000 mrxsmb mrxsmb.sys Fri Sep 05 08:26:52 2008 (48C14FBC)ba19d000 ba1cd000 rdbss rdbss.sys Fri Feb 16 23:27:37 2007 (45D6A059)ba1cd000 ba1f7000 afd afd.sys Thu Aug 14 03:46:56 2008 (48A40D20)ba1f7000 ba228000 netbt netbt.sys Fri Feb 16 23:28:57 2007 (45D6A0A9)ba228000 ba2b8000 tcpip tcpip.sys Fri Jun 20 07:20:25 2008 (485BBCA9)ba2b8000 ba2d1000 ipsec ipsec.sys Fri Feb 16 23:29:28 2007 (45D6A0C8)ba428000 ba43d000 usbhub usbhub.sys Fri Feb 16 23:13:05 2007 (45D69CF1)ba594000 ba5de000 update update.sys Fri Feb 16 23:28:59 2007 (45D6A0AB)ba606000 ba63d000 rdpdr rdpdr.sys Fri Feb 16 22:51:00 2007 (45D697C4)ba63d000 ba64f000 raspptp raspptp.sys Fri Feb 16 23:29:20 2007 (45D6A0C0)ba64f000 ba668000 ndiswan ndiswan.sys Fri Feb 16 23:29:22 2007 (45D6A0C2)ba668000 ba67c000 rasl2tp rasl2tp.sys Fri Feb 16 23:29:02 2007 (45D6A0AE)ba67c000 ba6f7000 Wdf01000 Wdf01000.sys Thu Nov 02 01:54:18 2006 (4549B23A)ba6f7000 ba75f000 bxvbdx bxvbdx.sys Tue May 22 19:17:20 2007 (4653A430)ba75f000 ba769000 Dxapi Dxapi.sys Tue Mar 25 00:06:01 2003 (3E7FFFD9)ba76f000 ba77c000 wanarp wanarp.sys Fri Feb 16 22:59:17 2007 (45D699B5)ba77f000 ba789000 dump_diskdump dump_diskdump.sys Fri Feb 16 23:07:44 2007 (45D69BB0)ba79f000 ba7a8000 kbdhid kbdhid.sys Fri Feb 16 23:05:42 2007 (45D69B36)ba7af000 ba7bd000 HIDCLASS HIDCLASS.SYS Tue Mar 25 00:10:17 2003 (3E8000D9)ba7bf000 ba7c8000 hidusb hidusb.sys Tue Mar 25 00:10:17 2003 (3E8000D9)ba7cf000 ba7dc000 netbios netbios.sys Fri Feb 16 22:58:29 2007 (45D69985)ba7df000 ba7ed000 msgpc msgpc.sys Fri Feb 16 22:58:37 2007 (45D6998D)ba7ef000 ba7fc000 Npfs Npfs.SYS Fri Feb 16 22:50:36 2007 (45D697AC)ba7ff000 ba814000 serial serial.sys Fri Feb 16 23:06:46 2007 (45D69B76)ba814000 ba827000 i8042prt i8042prt.sys Fri Feb 16 23:30:40 2007 (45D6A110)ba827000 ba84e000 ks ks.sys Fri Feb 16 23:30:40 2007 (45D6A110)ba84e000 ba862000 redbook redbook.sys Fri Feb 16 23:07:26 2007 (45D69B9E)ba862000 ba877000 cdrom cdrom.sys Fri Feb 16 23:07:48 2007 (45D69BB4)ba877000 ba897000 hpqilo2 hpqilo2.sys Mon Jul 16 14:36:14 2007 (469BE4CE)ba897000 ba8c1000 USBPORT USBPORT.SYS Fri Feb 16 23:12:59 2007 (45D69CEB)ba8c1000 ba8dd000 VIDEOPRT VIDEOPRT.SYS Fri Feb 16 23:10:30 2007 (45D69C56)ba8dd000 baa45000 ati2mtag ati2mtag.sys Wed Apr 05 20:03:52 2006 (44348518)bf800000 bf9d0000 win32k win32k.sys Mon Sep 15 06:22:02 2008 (48CE617A)bf9d0000 bf9e7000 dxg dxg.sys Fri Feb 16 23:14:39 2007 (45D69D4F)bf9e7000 bfa2a000 ati2dvag ati2dvag.dll Wed Apr 05 20:04:15 2006 (4434852F)bfa2a000 bfa69000 ati2cqag ati2cqag.dll Wed Apr 05 18:57:18 2006 (4434757E)bfa69000 bfa9f000 atikvmag atikvmag.dll Wed Apr 05 19:25:29 2006 (44347C19)bff60000 bff7e000 RDPDD RDPDD.dll Sat Feb 17 07:01:19 2007 (45D70AAF)bffa0000 bffea000 ATMFD ATMFD.DLL Sat Feb 17 06:59:31 2007 (45D70A43)f7213000 f7239000 KSecDD KSecDD.sys Fri Feb 16 22:46:32 2007 (45D696B8)f7239000 f725e000 fltMgr fltMgr.sys Fri Feb 16 22:51:08 2007 (45D697CC)f725e000 f7271000 CLASSPNP CLASSPNP.SYS Fri Feb 16 23:28:16 2007 (45D6A080)f7271000 f728f000 storport storport.sys Fri Feb 16 23:07:48 2007 (45D69BB4)f728f000 f72a2000 HpCISSs2 HpCISSs2.sys Thu Jun 21 20:33:49 2007 (467B431D)f72a2000 f72bf000 atapi atapi.sys Fri Feb 16 23:07:34 2007 (45D69BA6)f72bf000 f72e9000 volsnap volsnap.sys Fri Feb 16 23:08:23 2007 (45D69BD7)f72e9000 f7315000 dmio dmio.sys Fri Feb 16 23:10:44 2007 (45D69C64)f7315000 f733c000 ftdisk ftdisk.sys Fri Feb 16 23:08:05 2007 (45D69BC5)f733c000 f7352000 pci pci.sys Fri Feb 16 22:59:03 2007 (45D699A7)f7352000 f7386000 ACPI ACPI.sys Fri Feb 16 22:58:47 2007 (45D69997)f7487000 f7490000 WMILIB WMILIB.SYS Tue Mar 25 00:13:00 2003 (3E80017C)f7497000 f74a6000 isapnp isapnp.sys Fri Feb 16 22:58:57 2007 (45D699A1)f74a7000 f74b4000 PCIIDEX PCIIDEX.SYS Fri Feb 16 23:07:32 2007 (45D69BA4)f74b7000 f74c7000 MountMgr MountMgr.sys Fri Feb 16 23:05:35 2007 (45D69B2F)f74c7000 f74d2000 PartMgr PartMgr.sys Fri Feb 16 23:29:25 2007 (45D6A0C5)f74d7000 f74e7000 disk disk.sys Fri Feb 16 23:07:51 2007 (45D69BB7)f74e7000 f74f3000 Dfs Dfs.sys Fri Feb 16 22:51:17 2007 (45D697D5)f74f7000 f7506000 termdd termdd.sys Fri Feb 16 22:44:32 2007 (45D69640)f7507000 f7511000 crcdisk crcdisk.sys Fri Feb 16 23:09:50 2007 (45D69C2E)f7537000 f7547000 bxnd52x bxnd52x.sys Fri May 25 14:29:07 2007 (46575523)f7547000 f7552000 TDI TDI.SYS Fri Feb 16 23:01:19 2007 (45D69A2F)f7557000 f7565000 processr processr.sys Fri Feb 16 22:48:28 2007 (45D6972C)f7567000 f7575000 imapi imapi.sys Fri Feb 16 23:08:22 2007 (45D69BD6)f7577000 f7582000 Msfs Msfs.SYS Fri Feb 16 22:50:33 2007 (45D697A9)f7597000 f75a2000 kbdclass kbdclass.sys Fri Feb 16 23:05:39 2007 (45D69B33)f75a7000 f75b3000 vga vga.sys Fri Feb 16 23:10:30 2007 (45D69C56)f75b7000 f75c2000 ptilink ptilink.sys Fri Feb 16 23:06:38 2007 (45D69B6E)f75c7000 f75d1000 serenum serenum.sys Fri Feb 16 23:06:44 2007 (45D69B74)f75d7000 f75e0000 watchdog watchdog.sys Fri Feb 16 23:11:45 2007 (45D69CA1)f75f7000 f7601000 mouclass mouclass.sys Tue Mar 25 00:03:09 2003 (3E7FFF2D)f7617000 f7622000 cpqcidrv cpqcidrv.sys Fri Jun 22 11:55:11 2007 (467C1B0F)f7627000 f7630000 raspti raspti.sys Fri Feb 16 22:59:23 2007 (45D699BB)f7647000 f7650000 ndistapi ndistapi.sys Fri Feb 16 22:59:19 2007 (45D699B7)f7667000 f7676000 raspppoe raspppoe.sys Fri Feb 16 22:59:23 2007 (45D699BB)f7677000 f7680000 mssmbios mssmbios.sys Fri Feb 16 22:59:12 2007 (45D699B0)f7697000 f76a4000 WDFLDR WDFLDR.SYS Thu Nov 02 01:54:05 2006 (4549B22D)f76b7000 f76c5000 NDProxy NDProxy.SYS Fri Feb 16 22:59:21 2007 (45D699B9)f76c8000 f7707000 NDIS NDIS.sys Fri Feb 16 23:28:49 2007 (45D6A0A1)f7707000 f770f000 kdcom kdcom.dll Tue Mar 25 00:08:00 2003 (3E800050)f770f000 f7717000 BOOTVID BOOTVID.dll Tue Mar 25 00:07:58 2003 (3E80004E)f7717000 f771e000 pciide pciide.sys Tue Mar 25 00:04:46 2003 (3E7FFF8E)f771f000 f7726000 dmload dmload.sys Tue Mar 25 00:08:08 2003 (3E800058)f772f000 f7736d80 usbccgp usbccgp.sys Fri Feb 16 23:13:08 2007 (45D69CF4)f7747000 f774f000 mouhid mouhid.sys Tue Mar 25 00:03:12 2003 (3E7FFF30)f775f000 f7766000 dxgthk dxgthk.sys Tue Mar 25 00:05:52 2003 (3E7FFFD0)f77bf000 f77c4180 usbuhci usbuhci.sys Fri Feb 16 23:13:02 2007 (45D69CEE)f77c7000 f77cb400 usbohci usbohci.sys Fri Feb 16 23:13:01 2007 (45D69CED)f77cf000 f77d5b80 usbehci usbehci.sys Fri Feb 16 23:12:56 2007 (45D69CE8)f77d7000 f77df000 audstub audstub.sys Tue Mar 25 00:09:12 2003 (3E800098)f77ef000 f77f7000 Fs_Rec Fs_Rec.SYS Tue Mar 25 00:08:36 2003 (3E800074)f77f7000 f77fe000 Null Null.SYS Tue Mar 25 00:03:05 2003 (3E7FFF29)f77ff000 f7806000 Beep Beep.SYS Tue Mar 25 00:03:04 2003 (3E7FFF28)f7807000 f780d300 HIDPARSE HIDPARSE.SYS Fri Feb 16 23:12:35 2007 (45D69CD3)f780f000 f7817000 mnmdd mnmdd.SYS Tue Mar 25 00:07:53 2003 (3E800049)f7817000 f781f000 RDPCDD RDPCDD.sys Tue Mar 25 00:03:05 2003 (3E7FFF29)f781f000 f7827000 rasacd rasacd.sys Tue Mar 25 00:11:50 2003 (3E800136)f7968000 f7987000 Mup Mup.sys Fri Feb 16 23:27:41 2007 (45D6A05D)f7997000 f7998280 swenum swenum.sys Fri Feb 16 23:05:56 2007 (45D69B44)f7999000 f799a580 USBD USBD.SYS Tue Mar 25 00:10:39 2003 (3E8000EF)f7b4a000 f7bdf000 Ntfs Ntfs.sys Fri Feb 16 23:27:23 2007 (45D6A04B) Unloaded modules:f7687000 f7690000 kbdhid.sys Timestamp: unavailable (00000000) Checksum: 00000000f77e7000 f77ef000 Sfloppy.SYS Timestamp: unavailable (00000000) Checksum: 00000000f7587000 f7591000 Flpydisk.SYS Timestamp: unavailable (00000000) Checksum: 00000000f7637000 f7642000 Fdc.SYS Timestamp: unavailable (00000000) Checksum: 00000000f74f7000 f7504000 WDFLDR.SYS Timestamp: unavailable (00000000) Checksum: 00000000f782f000 f7897000 bxvbdx.sys Timestamp: unavailable (00000000) Checksum: 000000000: kd> .exr 0xffffffffb93cc4fcExceptionAddress: 7c84afa7 ExceptionCode: c0000005 (Access violation) ExceptionFlags: 00000000NumberParameters: 2 Parameter[0]: 00000000 Parameter[1]: ffffffffAttempt to read from address ffffffff
February 26th, 2009 10:27pm

I could not see anything mentioning SAS Controller. What is the operation that casued the exception? Are you running an application or it occured at the boot time or any other system operation independentof your interference? It is important to know. All I can see is that you've got an access violation because your app or whatnot attempts to access an absurd memory address: ffffffff. AlexB
Free Windows Admin Tool Kit Click here and download it now
February 26th, 2009 11:38pm

I agree with AlexBB. The culprit here seems to be "csrss.exe", or at least it was the process that had an error. It is a critical process, and needs to be running, unless the instance in question is a spoofed version (from a virus). If you have a window of down time (off business hours) try running a memory tester.http://oca.microsoft.com/en/windiag.asp
February 27th, 2009 12:40am

I could not see anything mentioning SAS Controller. i thought thats what these lines meant. DEFAULT_BUCKET_ID: DRIVER_FAULT b9ffe000 ba011000 dump_HpCISSs2 dump_HpCISSs2.sys Thu Jun 21 20:33:49 2007 (467B431D) But that is why i asked. i see now that this is only saying that it is sending the dump to this location. Are you running an applicationat the boot time or any other system operation independentof your interference? the server is running my companies phone system. in particular it runs theIVR side of the multi server contact center solution. it stopped in the middle of the day. basically it was processing phone calls maybe 30 simultaneous calls it records the voice mail, records customer respondes through the menus, text to speach, and access some MS sql databases to record respondses and deside where to send the cutomer be it phoenix, yuma, tucson etc.. The IVR server application is part MS Visual C++ and part Java i do not have a debug from the application at the time of the dump. the java parts run under wrapper.exe. corba is used on occation i will terminal to the server for creating new IVR scripts and forget they are there. i will have sql dev tools, the ivr dev tools, recorder and other things open and forget i left them there. otherwise i do not use the console foranything. all the applciations are services running under system.
Free Windows Admin Tool Kit Click here and download it now
February 27th, 2009 3:51am

The culprit here seems to be "csrss.exe", or at least it was the process that had an error. That is what i thought at first to, but i do not use console very offten i will use terminal conenctions that as i stated above. I thought thatcsrss.exe was for console stuff only. if they are writting to the timer/sysnc direct (thread control) it might effect this? or if the java program / wrapper.exe is started via some batch file then maybe that part of the program is what busted the system. i downloaded the memory tester - long downtimes are very hard to get it is a phone system. i will run the the short tests tonight.
February 27th, 2009 4:01am

Echoing an excellent RandomAdmin idea, I would download and install the following: Microsoft Malicious Software RemovalTool and Spybot Search& Detroy and run them. Is it WinSer2008 or an older version? Windows firewall should be checked and rechecked. Any company should have a Cisco router or good quality with a hardware firewall. Check Mark Rusinovitch's webcasts on Malicious Software removal. Download Microsoft AlexB
Free Windows Admin Tool Kit Click here and download it now
February 27th, 2009 5:48am

Microsoft Malicious Software RemovalTool and Spybot Search& Detroy and run them done automatically already. last full scan was on the 17 and it was free and clear running new full scan now. I had to removeantiv softwarebecause it would stop the IVR program from working correctly. We are behind several firewalls. i have configured some completely myself and worked with one other person on all the others. We are kinda paranoid and have been for years. That is why i run the mrt scan because noantiv on this one server. all other servers and workstation are up to date with antiv software. short scan of memory did apear OK.
February 27th, 2009 8:26pm

Then it means one of the dependentassemblies for this application became corrupted. If you rely on some SDKs or others you may try to uninstall the packages, reinstall them and rebuid your application.AlexB
Free Windows Admin Tool Kit Click here and download it now
February 27th, 2009 9:28pm

ouch, was trying to avoid that i will talk to developers and confirm. tanks r not just toys.
February 27th, 2009 10:54pm

Make a malware removal WinPE boot CD. See: http://www.microsoft.com/technet/security/guidance/disasterrecovery/malware/f1dc9e9f-d718-47ae-8937-00ce15826531.mspx
Free Windows Admin Tool Kit Click here and download it now
February 28th, 2009 1:26am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics