unexpected shutdown win server 2008
Hai, I want to know what is the source problem of unexpected shutodown on my computer (windows server 2008 R2 enterprise, 64 bit). I already check dump file, but I confuse to find cause of the problem. below the dump file: Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64 Copyright (c) Microsoft Corporation. All rights reserved. Loading Dump File [D:\problem\071711-16395-01.dmp] Mini Kernel Dump File: Only registers and stack trace are available Symbol search path is: SRV*C:\Symbols*http://msdl.microsoft.com/download/symbols Executable search path is: Windows 7 Kernel Version 7600 MP (4 procs) Free x64 Product: Server, suite: Enterprise TerminalServer SingleUserTS Built by: 7600.16792.amd64fre.win7_gdr.110408-1633 Machine Name: Kernel base = 0xfffff800`01613000 PsLoadedModuleList = 0xfffff800`01850e50 Debug session time: Sun Jul 17 02:40:01.804 2011 (UTC + 7:00) System Uptime: 8 days 4:51:29.682 Loading Kernel Symbols ............................................................... ................................................................ ................ Loading User Symbols Loading unloaded module list .................................................. ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* Use !analyze -v to get detailed debugging information. BugCheck 4A, {7764f72a, 2, 0, fffff88005598ca0} Probably caused by : ntkrnlmp.exe ( nt!KiSystemServiceExit+245 ) Followup: MachineOwner --------- 0: kd> !analyze -v ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* IRQL_GT_ZERO_AT_SYSTEM_SERVICE (4a) Returning to usermode from a system call at an IRQL > PASSIVE_LEVEL. Arguments: Arg1: 000000007764f72a, Address of system function (system call routine) Arg2: 0000000000000002, Current IRQL Arg3: 0000000000000000, 0 Arg4: fffff88005598ca0, 0 Debugging Details: ------------------ PROCESS_NAME: NisSrv.exe BUGCHECK_STR: RAISED_IRQL_FAULT FAULTING_IP: +3334386361643739 00000000`7764f72a ?? ??? CUSTOMER_CRASH_COUNT: 1 DEFAULT_BUCKET_ID: DRIVER_FAULT_SERVER_MINIDUMP CURRENT_IRQL: 2 LAST_CONTROL_TRANSFER: from fffff80001682c69 to fffff80001683700 STACK_TEXT: fffff880`05598a68 fffff800`01682c69 : 00000000`0000004a 00000000`7764f72a 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx fffff880`05598a70 fffff800`01682ba0 : fffffa80`16dc5b60 00000000`0837fad8 fffff880`05598bc8 fffff800`01998164 : nt!KiBugCheckDispatch+0x69 fffff880`05598bb0 00000000`7764f72a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceExit+0x245 00000000`0837f228 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7764f72a STACK_COMMAND: kb FOLLOWUP_IP: nt!KiSystemServiceExit+245 fffff800`01682ba0 4883ec50 sub rsp,50h SYMBOL_STACK_INDEX: 2 SYMBOL_NAME: nt!KiSystemServiceExit+245 FOLLOWUP_NAME: MachineOwner MODULE_NAME: nt IMAGE_NAME: ntkrnlmp.exe DEBUG_FLR_IMAGE_TIMESTAMP: 4d9fdd34 FAILURE_BUCKET_ID: X64_RAISED_IRQL_FAULT_NisSrv.exe_nt!KiSystemServiceExit+245 BUCKET_ID: X64_RAISED_IRQL_FAULT_NisSrv.exe_nt!KiSystemServiceExit+245 Followup: MachineOwner --------- 0: kd> lmvm nt start end module name fffff800`01613000 fffff800`01bef000 nt (pdb symbols) c:\symbols\ntkrnlmp.pdb\DE7B3DD8AC5343B3B4874BAB3F4599DD2\ntkrnlmp.pdb Loaded symbol image file: ntkrnlmp.exe Mapped memory image file: c:\symbols\ntoskrnl.exe\4D9FDD345dc000\ntoskrnl.exe Image path: ntkrnlmp.exe Image name: ntkrnlmp.exe Timestamp: Sat Apr 09 11:14:44 2011 (4D9FDD34) CheckSum: 00547734 ImageSize: 005DC000 File version: 6.1.7600.16792 Product version: 6.1.7600.16792 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 1.0 App File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: ntkrnlmp.exe OriginalFilename: ntkrnlmp.exe ProductVersion: 6.1.7600.16792 FileVersion: 6.1.7600.16792 (win7_gdr.110408-1633) FileDescription: NT Kernel & System LegalCopyright: © Microsoft Corporation. All rights reserved. 0: kd> start end module name fffff800`01613000 fffff800`01bef000 nt (pdb symbols) c:\symbols\ntkrnlmp.pdb\DE7B3DD8AC5343B3B4874BAB3F4599DD2\ntkrnlmp.pdb Loaded symbol image file: ntkrnlmp.exe Mapped memory image file: c:\symbols\ntoskrnl.exe\4D9FDD345dc000\ntoskrnl.exe Image path: ntkrnlmp.exe Image name: ntkrnlmp.exe Timestamp: Sat Apr 09 11:14:44 2011 (4D9FDD34) CheckSum: 00547734 ImageSize: 005DC000 File version: 6.1.7600.16792 Product version: 6.1.7600.16792 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 1.0 App File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: ntkrnlmp.exe OriginalFilename: ntkrnlmp.exe ProductVersion: 6.1.7600.16792 FileVersion: 6.1.7600.16792 (win7_gdr.110408-1633) FileDescription: NT Kernel & System LegalCopyright: © Microsoft Corporation. All rights reserved. 0: kd> start end module name fffff800`01613000 fffff800`01bef000 nt (pdb symbols) c:\symbols\ntkrnlmp.pdb\DE7B3DD8AC5343B3B4874BAB3F4599DD2\ntkrnlmp.pdb Loaded symbol image file: ntkrnlmp.exe Mapped memory image file: c:\symbols\ntoskrnl.exe\4D9FDD345dc000\ntoskrnl.exe Image path: ntkrnlmp.exe Image name: ntkrnlmp.exe Timestamp: Sat Apr 09 11:14:44 2011 (4D9FDD34) CheckSum: 00547734 ImageSize: 005DC000 File version: 6.1.7600.16792 Product version: 6.1.7600.16792 File flags: 0 (Mask 3F) File OS: 40004 NT Win32 File type: 1.0 App File date: 00000000.00000000 Translations: 0409.04b0 CompanyName: Microsoft Corporation ProductName: Microsoft® Windows® Operating System InternalName: ntkrnlmp.exe OriginalFilename: ntkrnlmp.exe ProductVersion: 6.1.7600.16792 FileVersion: 6.1.7600.16792 (win7_gdr.110408-1633) FileDescription: NT Kernel & System LegalCopyright: © Microsoft Corporation. All rights reserved. 0: kd> lmtsmn start end module name fffff880`010e3000 fffff880`0113a000 ACPI ACPI.sys Tue Jul 14 06:19:34 2009 (4A5BC106) fffff880`02a84000 fffff880`02b0d000 afd afd.sys Mon Apr 25 09:43:58 2011 (4DB4DFEE) fffff880`032fd000 fffff880`03313000 AgileVpn AgileVpn.sys Tue Jul 14 07:10:24 2009 (4A5BCCF0) fffff880`012fc000 fffff880`01307000 amdxata amdxata.sys Fri Mar 19 23:18:18 2010 (4BA3A3CA) fffff880`066a5000 fffff880`066b0000 asyncmac asyncmac.sys Tue Jul 14 07:10:13 2009 (4A5BCCE5) fffff880`03000000 fffff880`03048000 b57nd60a b57nd60a.sys Sun Apr 26 18:14:55 2009 (49F4422F) fffff880`030f7000 fffff880`03108000 blbdrive blbdrive.sys Tue Jul 14 06:35:59 2009 (4A5BC4DF) fffff880`01952000 fffff880`01970000 bowser bowser.sys Wed Feb 23 12:15:06 2011 (4D6497DA) fffff880`02970000 fffff880`02986000 bxnd60a bxnd60a.sys Wed Dec 24 02:08:14 2008 (4951371E) fffff880`03144000 fffff880`031bf000 bxvbda bxvbda.sys Sat Feb 14 05:18:07 2009 (4995F19F) fffff880`00c00000 fffff880`00cc0000 CI CI.dll Tue Jul 14 08:32:13 2009 (4A5BE01D) fffff880`0190a000 fffff880`0193a000 CLASSPNP CLASSPNP.SYS Tue Jul 14 06:19:58 2009 (4A5BC11E) fffff880`00d2c000 fffff880`00d8a000 CLFS CLFS.SYS Tue Jul 14 06:19:57 2009 (4A5BC11D) fffff880`01353000 fffff880`013c6000 cng cng.sys Tue Jul 14 06:49:40 2009 (4A5BC814) fffff880`032ed000 fffff880`032fd000 CompositeBus CompositeBus.sys Tue Jul 14 07:00:33 2009 (4A5BCAA1) fffff880`02986000 fffff880`02994000 crashdmp crashdmp.sys Tue Jul 14 07:01:01 2009 (4A5BCABD) fffff880`030d9000 fffff880`030f7000 dfsc dfsc.sys Wed Apr 27 09:57:39 2011 (4DB78623) fffff880`030ca000 fffff880`030d9000 discache discache.sys Tue Jul 14 06:37:18 2009 (4A5BC52E) fffff880`018f4000 fffff880`0190a000 disk disk.sys Tue Jul 14 06:19:57 2009 (4A5BC11D) fffff880`02994000 fffff880`0299e000 dump_diskdump dump_diskdump.sys Sat Apr 23 01:11:55 2011 (4DB1C4EB) fffff880`0299e000 fffff880`029b5000 dump_HpSAMD dump_HpSAMD.sys Tue May 19 06:43:49 2009 (4A11F2B5) fffff880`03298000 fffff880`032a4000 Dxapi Dxapi.sys Tue Jul 14 06:38:28 2009 (4A5BC574) fffff960`00460000 fffff960`0047e000 dxg dxg.sys Tue Jul 14 06:38:28 2009 (4A5BC574) fffff880`032e0000 fffff880`032ed000 fdc fdc.sys Tue Jul 14 07:00:54 2009 (4A5BCAB6) fffff880`01307000 fffff880`01353000 fltmgr fltmgr.sys Tue Jul 14 06:19:59 2009 (4A5BC11F) fffff960`009f0000 fffff960`009f9000 framebuf framebuf.dll unavailable (00000000) fffff880`015f6000 fffff880`01600000 Fs_Rec Fs_Rec.sys Tue Jul 14 06:19:45 2009 (4A5BC111) fffff880`0588a000 fffff880`0589c000 FsDepends FsDepends.sys Tue Jul 14 06:26:13 2009 (4A5BC295) fffff880`00da5000 fffff880`00def000 fwpkclnt fwpkclnt.sys Tue Jul 14 06:21:08 2009 (4A5BC164) fffff800`01bef000 fffff800`01c38000 hal hal.dll Tue Jul 14 08:27:36 2009 (4A5BDF08) fffff880`06600000 fffff880`06619000 HIDCLASS HIDCLASS.SYS Tue Jul 14 07:06:21 2009 (4A5BCBFD) fffff880`02800000 fffff880`02808080 HIDPARSE HIDPARSE.SYS Tue Jul 14 07:06:17 2009 (4A5BCBF9) fffff880`067ea000 fffff880`067f8000 hidusb hidusb.sys Tue Jul 14 07:06:22 2009 (4A5BCBFE) fffff880`01283000 fffff880`0129a000 HpSAMD HpSAMD.sys Tue May 19 06:43:49 2009 (4A11F2B5) fffff880`05318000 fffff880`053e0000 HTTP HTTP.sys Tue Jul 14 06:22:16 2009 (4A5BC1A8) fffff880`02b90000 fffff880`02bef000 hvboot hvboot.sys Tue Jul 14 06:20:18 2009 (4A5BC132) fffff880`018eb000 fffff880`018f4000 hwpolicy hwpolicy.sys Tue Jul 14 06:19:22 2009 (4A5BC0FA) fffff880`0312e000 fffff880`03144000 intelppm intelppm.sys Tue Jul 14 06:19:25 2009 (4A5BC0FD) fffff880`03280000 fffff880`03298000 IPMIDrv IPMIDrv.sys Tue Jul 14 06:47:45 2009 (4A5BC7A1) fffff880`032b6000 fffff880`032c5000 kbdclass kbdclass.sys Tue Jul 14 06:19:50 2009 (4A5BC116) fffff880`06619000 fffff880`06627000 kbdhid kbdhid.sys Tue Jul 14 07:00:20 2009 (4A5BCA94) fffff800`015a4000 fffff800`015ae000 kdcom kdcom.dll Sat Feb 05 19:21:45 2011 (4D4D40D9) fffff880`011b7000 fffff880`011fa000 ks ks.sys Tue Jul 14 07:00:31 2009 (4A5BCA9F) fffff880`015cb000 fffff880`015e5000 ksecdd ksecdd.sys Tue Jul 14 06:20:54 2009 (4A5BC156) fffff880`013c6000 fffff880`013f1000 ksecpkg ksecpkg.sys Fri Dec 11 13:03:32 2009 (4B21E0B4) fffff880`02a60000 fffff880`02a75000 lltdio lltdio.sys Tue Jul 14 07:08:50 2009 (4A5BCC92) fffff880`031d1000 fffff880`031f4000 luafv luafv.sys Tue Jul 14 06:26:13 2009 (4A5BC295) fffff880`00cd4000 fffff880`00d18000 mcupdate_GenuineIntel mcupdate_GenuineIntel.dll Tue Jul 14 08:29:10 2009 (4A5BDF66) fffff880`032a4000 fffff880`032b2000 monitor monitor.sys Tue Jul 14 06:38:52 2009 (4A5BC58C) fffff880`032c5000 fffff880`032d4000 mouclass mouclass.sys Tue Jul 14 06:19:50 2009 (4A5BC116) fffff880`06627000 fffff880`06634000 mouhid mouhid.sys Tue Jul 14 07:00:20 2009 (4A5BCA94) fffff880`01269000 fffff880`01283000 mountmgr mountmgr.sys Tue Jul 14 06:19:54 2009 (4A5BC11A) fffff880`01993000 fffff880`019c4000 MpFilter MpFilter.sys Wed Sep 15 07:19:28 2010 (4C901110) fffff880`059c1000 fffff880`059d1000 MpNWMon MpNWMon.sys Wed Sep 15 07:19:30 2010 (4C901112) fffff880`01970000 fffff880`01988000 mpsdrv mpsdrv.sys Tue Jul 14 07:08:25 2009 (4A5BCC79) fffff880`01000000 fffff880`0102d000 mrxsmb mrxsmb.sys Wed May 04 09:51:06 2011 (4DC0BF1A) fffff880`052a7000 fffff880`052f5000 mrxsmb10 mrxsmb10.sys Wed May 04 09:51:08 2011 (4DC0BF1C) fffff880`052f5000 fffff880`05318000 mrxsmb20 mrxsmb20.sys Wed May 04 09:51:05 2011 (4DC0BF19) fffff880`0182b000 fffff880`01836000 Msfs Msfs.SYS Tue Jul 14 06:19:47 2009 (4A5BC113) fffff880`01143000 fffff880`0114d000 msisadrv msisadrv.sys Tue Jul 14 06:19:26 2009 (4A5BC0FE) fffff880`00f15000 fffff880`00f73000 msrpc msrpc.sys Tue Jul 14 06:21:32 2009 (4A5BC17C) fffff880`030bf000 fffff880`030ca000 mssmbios mssmbios.sys Tue Jul 14 06:31:10 2009 (4A5BC3BE) fffff880`018d9000 fffff880`018eb000 mup mup.sys Tue Jul 14 06:23:45 2009 (4A5BC201) fffff880`00e23000 fffff880`00f15000 NDIS NDIS.SYS Tue Jul 14 06:21:40 2009 (4A5BC184) fffff880`03337000 fffff880`03343000 ndistapi ndistapi.sys Tue Jul 14 07:10:00 2009 (4A5BCCD8) fffff880`03343000 fffff880`03372000 ndiswan ndiswan.sys Tue Jul 14 07:10:11 2009 (4A5BCCE3) fffff880`0295b000 fffff880`02970000 NDProxy NDProxy.SYS Tue Jul 14 07:10:05 2009 (4A5BCCDD) fffff880`02b81000 fffff880`02b90000 netbios netbios.sys Tue Jul 14 07:09:26 2009 (4A5BCCB6) fffff880`02b0d000 fffff880`02b52000 netbt netbt.sys Tue Jul 14 06:21:28 2009 (4A5BC178) fffff880`00f73000 fffff880`00fd3000 NETIO NETIO.SYS Fri Apr 09 09:43:59 2010 (4BBE946F) fffff880`059d1000 fffff880`059e6000 NisDrvWFP NisDrvWFP.sys Wed Sep 15 07:20:25 2010 (4C901149) fffff880`01836000 fffff880`01847000 Npfs Npfs.SYS Tue Jul 14 06:19:48 2009 (4A5BC114) fffff880`030b3000 fffff880`030bf000 nsiproxy nsiproxy.sys Tue Jul 14 06:21:02 2009 (4A5BC15E) fffff800`01613000 fffff800`01bef000 nt ntkrnlmp.exe Sat Apr 09 11:14:44 2011 (4D9FDD34) fffff880`01429000 fffff880`015cb000 Ntfs Ntfs.sys Fri Mar 11 10:39:25 2011 (4D79996D) fffff880`019c4000 fffff880`019cd000 Null Null.SYS Tue Jul 14 06:19:37 2009 (4A5BC109) fffff880`02b5b000 fffff880`02b81000 pacer pacer.sys Tue Jul 14 07:09:41 2009 (4A5BCCC5) fffff880`0118d000 fffff880`011a2000 partmgr partmgr.sys Tue Jul 14 06:19:58 2009 (4A5BC11E) fffff880`066ed000 fffff880`066f8000 passthruparser passthruparser.sys Tue Jul 14 06:42:52 2009 (4A5BC67C) fffff880`0114d000 fffff880`01180000 pci pci.sys Tue Jul 14 06:19:51 2009 (4A5BC117) fffff880`015e5000 fffff880`015f6000 pcw pcw.sys Tue Jul 14 06:19:27 2009 (4A5BC0FF) fffff880`05200000 fffff880`052a6000 peauth peauth.sys Tue Jul 14 08:01:19 2009 (4A5BD8DF) fffff880`06709000 fffff880`06714000 prepdrv prepdrv.sys Fri Sep 18 15:15:16 2009 (4AB34194) fffff880`00d18000 fffff880`00d2c000 PSHED PSHED.dll Tue Jul 14 08:32:23 2009 (4A5BE027) fffff880`03313000 fffff880`03337000 rasl2tp rasl2tp.sys Tue Jul 14 07:10:11 2009 (4A5BCCE3) fffff880`03372000 fffff880`0338d000 raspppoe raspppoe.sys Tue Jul 14 07:10:17 2009 (4A5BCCE9) fffff880`0338d000 fffff880`033ae000 raspptp raspptp.sys Tue Jul 14 07:10:18 2009 (4A5BCCEA) fffff880`033ae000 fffff880`033c8000 rassstp rassstp.sys Tue Jul 14 07:10:25 2009 (4A5BCCF1) fffff880`03062000 fffff880`030b3000 rdbss rdbss.sys Tue Jul 14 06:24:09 2009 (4A5BC219) fffff880`033c8000 fffff880`033d3000 rdpbus rdpbus.sys Tue Jul 14 07:17:46 2009 (4A5BCEAA) fffff880`01810000 fffff880`01819000 RDPCDD RDPCDD.sys Tue Jul 14 07:16:34 2009 (4A5BCE62) fffff880`05800000 fffff880`0582e000 rdpdr rdpdr.sys Tue Jul 14 07:18:02 2009 (4A5BCEBA) fffff880`01819000 fffff880`01822000 rdpencdd rdpencdd.sys Tue Jul 14 07:16:34 2009 (4A5BCE62) fffff880`01822000 fffff880`0182b000 rdprefmp rdprefmp.sys Tue Jul 14 07:16:35 2009 (4A5BCE63) fffff880`05848000 fffff880`05880000 RDPWD RDPWD.SYS Tue Jul 14 07:16:47 2009 (4A5BCE6F) fffff880`0193a000 fffff880`01952000 rspndr rspndr.sys Tue Jul 14 07:08:50 2009 (4A5BCC92) fffff880`00d8a000 fffff880`00da5000 sacdrv sacdrv.sys Tue Jul 14 07:00:40 2009 (4A5BCAA8) fffff880`053e0000 fffff880`053eb000 secdrv secdrv.SYS Wed Sep 13 20:18:38 2006 (4508052E) fffff880`032d4000 fffff880`032e0000 serenum serenum.sys Tue Jul 14 07:00:33 2009 (4A5BCAA1) fffff880`02a14000 fffff880`02a31000 serial serial.sys Tue Jul 14 07:00:40 2009 (4A5BCAA8) fffff880`018d1000 fffff880`018d9000 spldr spldr.sys Mon May 11 23:56:27 2009 (4A0858BB) fffff880`0592c000 fffff880`059c1000 srv srv.sys Fri Apr 29 10:13:05 2011 (4DBA2CC1) fffff880`058c5000 fffff880`0592c000 srv2 srv2.sys Fri Apr 29 10:12:51 2011 (4DBA2CB3) fffff880`00fd3000 fffff880`01000000 srvnet srvnet.sys Fri Apr 29 10:12:35 2011 (4DBA2CA3) fffff880`0129a000 fffff880`012fc000 storport storport.sys Fri Mar 11 11:24:35 2011 (4D79A403) fffff880`033d3000 fffff880`033f6000 storvsp storvsp.sys Sat May 14 12:11:08 2011 (4DCE0EEC) fffff880`033f6000 fffff880`033f7480 swenum swenum.sys Tue Jul 14 07:00:18 2009 (4A5BCA92) fffff880`01601000 fffff880`017fe000 tcpip tcpip.sys Mon Apr 25 09:47:33 2011 (4DB4E0C5) fffff880`053eb000 fffff880`053fd000 tcpipreg tcpipreg.sys Tue Jul 14 07:09:49 2009 (4A5BCCCD) fffff880`01865000 fffff880`01872000 TDI TDI.SYS Tue Jul 14 06:21:18 2009 (4A5BC16E) fffff880`0582e000 fffff880`05839000 tdtcp tdtcp.sys Tue Jul 14 07:16:32 2009 (4A5BCE60) fffff880`01847000 fffff880`01865000 tdx tdx.sys Tue Jul 14 06:21:15 2009 (4A5BC16B) fffff880`02a4c000 fffff880`02a60000 termdd termdd.sys Tue Jul 14 07:16:36 2009 (4A5BCE64) fffff960`00680000 fffff960`0068a000 TSDDD TSDDD.dll Tue Jul 14 07:16:34 2009 (4A5BCE62) fffff880`05839000 fffff880`05848000 tssecsrv tssecsrv.sys Tue Jul 14 07:16:41 2009 (4A5BCE69) fffff880`03108000 fffff880`0312e000 tunnel tunnel.sys Tue Jul 14 07:09:37 2009 (4A5BCCC1) fffff880`031bf000 fffff880`031d1000 umbus umbus.sys Tue Jul 14 07:06:56 2009 (4A5BCC20) fffff880`067cb000 fffff880`067e8000 usbccgp usbccgp.sys Fri Mar 25 10:23:03 2011 (4D8C0A97) fffff880`067e8000 fffff880`067e9f00 USBD USBD.SYS Fri Mar 25 10:22:51 2011 (4D8C0A8B) fffff880`066f8000 fffff880`06709000 usbehci usbehci.sys Fri Mar 25 10:22:57 2011 (4D8C0A91) fffff880`02901000 fffff880`0295b000 usbhub usbhub.sys Fri Mar 25 10:23:22 2011 (4D8C0AAA) fffff880`0320b000 fffff880`03261000 USBPORT USBPORT.SYS Fri Mar 25 10:23:03 2011 (4D8C0A97) fffff880`03048000 fffff880`03055000 usbuhci usbuhci.sys Fri Mar 25 10:22:55 2011 (4D8C0A8F) fffff880`01180000 fffff880`0118d000 vdrvroot vdrvroot.sys Tue Jul 14 07:01:31 2009 (4A5BCADB) fffff880`019cd000 fffff880`019db000 vga vga.sys Tue Jul 14 06:38:47 2009 (4A5BC587) fffff880`03272000 fffff880`03280000 vgapnp vgapnp.sys Tue Jul 14 06:38:47 2009 (4A5BC587) fffff880`066b5000 fffff880`066ed000 vhdmp vhdmp.sys Tue Jul 14 07:01:36 2009 (4A5BCAE0) fffff880`05880000 fffff880`0588a000 vhdparser vhdparser.sys Tue Jul 14 06:42:56 2009 (4A5BC680) fffff880`0282b000 fffff880`0285f000 Vid Vid.sys Wed Dec 02 12:32:24 2009 (4B15FBE8) fffff880`019db000 fffff880`01a00000 VIDEOPRT VIDEOPRT.SYS Tue Jul 14 06:38:51 2009 (4A5BC58B) fffff880`0285f000 fffff880`0289b000 vmbus vmbus.sys Sat May 14 12:11:05 2011 (4DCE0EE9) fffff880`01400000 fffff880`01410000 vmstorfl vmstorfl.sys Tue Jul 14 06:42:54 2009 (4A5BC67E) fffff880`0289b000 fffff880`02901000 vmswitch vmswitch.sys Sat May 14 12:11:22 2011 (4DCE0EFA) fffff880`011a2000 fffff880`011b7000 volmgr volmgr.sys Tue Jul 14 06:19:57 2009 (4A5BC11D) fffff880`0120d000 fffff880`01269000 volmgrx volmgrx.sys Tue Jul 14 06:20:33 2009 (4A5BC141) fffff880`01885000 fffff880`018d1000 volsnap volsnap.sys Tue Jul 14 06:20:08 2009 (4A5BC128) fffff880`02a31000 fffff880`02a4c000 wanarp wanarp.sys Tue Jul 14 07:10:21 2009 (4A5BCCED) fffff880`01800000 fffff880`01810000 watchdog watchdog.sys Tue Jul 14 06:37:35 2009 (4A5BC53F) fffff880`01030000 fffff880`010d4000 Wdf01000 Wdf01000.sys Tue Jul 14 06:22:07 2009 (4A5BC19F) fffff880`010d4000 fffff880`010e3000 WDFLDR WDFLDR.SYS Tue Jul 14 06:19:54 2009 (4A5BC11A) fffff880`02b52000 fffff880`02b5b000 wfplwf wfplwf.sys Tue Jul 14 07:09:26 2009 (4A5BCCB6) fffff960`000c0000 fffff960`003d2000 win32k win32k.sys Sat May 28 10:06:29 2011 (4DE066B5) fffff880`02a00000 fffff880`02a14000 winhv winhv.sys Tue Jul 14 06:19:58 2009 (4A5BC11E) fffff880`0113a000 fffff880`01143000 WMILIB WMILIB.SYS Tue Jul 14 06:19:51 2009 (4A5BC117) Unloaded modules: fffff880`06634000 fffff880`066a5000 spsys.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00071000 fffff880`06714000 fffff880`06785000 spsys.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00071000 fffff880`06634000 fffff880`066a5000 spsys.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00071000 fffff880`06714000 fffff880`06785000 spsys.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00071000 fffff880`06634000 fffff880`066a5000 spsys.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00071000 fffff880`06714000 fffff880`06785000 spsys.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00071000 fffff880`06634000 fffff880`066a5000 spsys.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00071000 fffff880`06714000 fffff880`06785000 spsys.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00071000 fffff880`06634000 fffff880`066a5000 spsys.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00071000 fffff880`06714000 fffff880`06785000 spsys.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00071000 fffff880`06634000 fffff880`066a5000 spsys.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00071000 fffff880`06714000 fffff880`06785000 spsys.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00071000 fffff880`06634000 fffff880`066a5000 spsys.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00071000 fffff880`06714000 fffff880`06785000 spsys.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00071000 fffff880`06634000 fffff880`066a5000 spsys.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00071000 fffff880`06714000 fffff880`06785000 spsys.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00071000 fffff880`06634000 fffff880`066a5000 spsys.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00071000 fffff880`06714000 fffff880`06785000 spsys.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00071000 fffff880`06634000 fffff880`066a5000 spsys.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00071000 fffff880`06714000 fffff880`06785000 spsys.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00071000 fffff880`06634000 fffff880`066a5000 spsys.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00071000 fffff880`06714000 fffff880`06785000 spsys.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00071000 fffff880`06634000 fffff880`066a5000 spsys.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00071000 fffff880`06714000 fffff880`06785000 spsys.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00071000 fffff880`06634000 fffff880`066a5000 spsys.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00071000 fffff880`06714000 fffff880`06785000 spsys.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00071000 fffff880`06634000 fffff880`066a5000 spsys.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00071000 fffff880`06787000 fffff880`06789000 USBD.SYS Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00002000 fffff880`0676a000 fffff880`06787000 usbccgp.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 0001D000 fffff880`06797000 fffff880`067b0000 HIDCLASS.SYS Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00019000 fffff880`06789000 fffff880`06797000 hidusb.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 0000E000 fffff880`067b0000 fffff880`067be000 kbdhid.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 0000E000 fffff880`067be000 fffff880`067cb000 mouhid.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 0000D000 fffff880`06726000 fffff880`06728000 USBD.SYS Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00002000 fffff880`06709000 fffff880`06726000 usbccgp.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 0001D000 fffff880`06736000 fffff880`0674f000 HIDCLASS.SYS Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00019000 fffff880`06728000 fffff880`06736000 hidusb.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 0000E000 fffff880`0674f000 fffff880`0675d000 kbdhid.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 0000E000 fffff880`0675d000 fffff880`0676a000 mouhid.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 0000D000 fffff880`029d2000 fffff880`029d4000 USBD.SYS Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00002000 fffff880`029b5000 fffff880`029d2000 usbccgp.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 0001D000 fffff880`029e2000 fffff880`029fb000 HIDCLASS.SYS Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00019000 fffff880`029d4000 fffff880`029e2000 hidusb.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 0000E000 fffff880`02809000 fffff880`02817000 kbdhid.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 0000E000 fffff880`02817000 fffff880`02824000 mouhid.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 0000D000 fffff880`03261000 fffff880`03272000 usbehci.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00011000 fffff880`0193a000 fffff880`01948000 crashdmp.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 0000E000 fffff880`01948000 fffff880`01952000 dump_storpor Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 0000A000 fffff880`01952000 fffff880`01969000 dump_HpSAMD. Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 00017000 fffff880`03298000 fffff880`032b6000 i8042prt.sys Timestamp: unavailable (00000000) Checksum: 00000000 ImageSize: 0001E000 0: kd> Regards, Sutisna
July 20th, 2011 9:32am

Please let me know if you find a resolution to this problem. I am receiving the exact same dump file as you on my Windows Server 2008R2 server. The main culprit looks like "NisSrv.exe" (a conponent of Forefront) and "ntkrnlmp.exe." Lastly, my server is virtual running on VMware ESXi 4.1.0. Regards, T
Free Windows Admin Tool Kit Click here and download it now
July 20th, 2011 8:52pm

I'am sorry, I have not found the resolution. FYI, My server is installed a Forefront Endpoint Protection 2010 and Hyper-V role. Hai, expert, please help us. What is the resolution and How to solve this problem. Thanks, Sutisna
July 21st, 2011 7:12am

Hi, Since Windows system uses separated user mode and kernel mode memory space, stop errors are always caused by kernel portion components, such as a third-party device drivers, backup software or anti-virus services (buggy services). The system goes to a BSOD because there is some exceptions happened in the kernel (either the device driver errors or the service errors), and Windows implements this mechanism: When it detects some errors occur in the kernel, it will kill the box in case some more severe damage happens. Then we get a blue screen or the system reboots (it depends on what the system settings are). To troubleshoot this kind of kernel crash issue, we need to debug the crashed system dump. Unfortunately, debugging is beyond what we can do in the forum. A suggestion would be to contact Microsoft Customer Service and Support (CSS) via telephone so that a dedicated Support Professional can assist with your request. Please be advised that contacting phone support will be a charged call. To obtain the phone numbers for specific technology request please take a look at the web site listed below: Microsoft - Help and Support http://support.microsoft.com/default.aspx?scid=fh;EN-US;PHONENUMBERS If Please remember to click Mark as Answer on the post that helps you, and to click Unmark as Answer if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
Free Windows Admin Tool Kit Click here and download it now
July 25th, 2011 11:09am

Thank Liu for reply. We got reference from the links below: http://social.technet.microsoft.com/Forums/en-US/winservergen/thread/86757d35-995c-408d-9dc2-eccc31f65542/ http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Windows/Windows_7/Q_27024109.html Regards, Sutisna
August 23rd, 2011 2:51am

Hello, Bug Check Code 0x4A: http://msdn.microsoft.com/en-us/library/ff559001(VS.85).aspx The BSOD occured when NisSrv.exe process was running. More about it: http://www.whatisexe.com/process/NisSrv.exe.html Please proceed like that: Perform a full scan on your disks to delete all viruses / spywares / malware programs Uninstall all programs that you don't use Disable all security softwares Install latest Microsoft Windows Updates Run msconfig and disable all startup items except Microsoft ones Once done, check again. Is there a dump file named c:\windows\MEMORY.DMP ? If yes, please use Microsoft Skydrive to upload it. You can also contact Microsoft CSS for more assistance. This posting is provided "AS IS" with no warranties or guarantees , and confers no rights. Microsoft Student Partner 2010 / 2011 Microsoft Certified Professional Microsoft Certified Systems Administrator: Security Microsoft Certified Systems Engineer: Security Microsoft Certified Technology Specialist: Windows Server 2008 Active Directory, Configuration Microsoft Certified Technology Specialist: Windows Server 2008 Network Infrastructure, Configuration Microsoft Certified Technology Specialist: Windows Server 2008 Applications Infrastructure, Configuration Microsoft Certified Technology Specialist: Windows 7, Configuring Microsoft Certified IT Professional: Enterprise Administrator Microsoft Certified IT Professional: Server Administrator
Free Windows Admin Tool Kit Click here and download it now
August 23rd, 2011 3:01am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics