Share via

BUG Check crash

Anonymous
2021-10-14T02:46:26+00:00

Hi All, Recently one of our production windows server crashed, I took the memory dump and load in Win Dbg tool and below is the output.

what is the cause for the crash?

Microsoft (R) Windows Debugger Version 10.0.22415.1003 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.

Loading Dump File [C:\MEMORY\MEMORY.DMP]
Kernel Bitmap Dump File: Kernel address space is available, User address space may not be available.

************* Path validation summary **************
Response                         Time (ms)     Location
Deferred                                       srv*
Symbol search path is: srv*
Executable search path is: 
Windows 10 Kernel Version 14393 MP (16 procs) Free x64
Product: Server, suite: TerminalServer DataCenter SingleUserTS
Edition build lab: 14393.4530.amd64fre.rs1_release.210705-0736
Machine Name:
Kernel base = 0xfffff801`d627c000 PsLoadedModuleList = 0xfffff801`d6580060
Debug session time: Sat Oct  9 19:39:56.508 2021 (UTC + 10:30)
System Uptime: 14 days 0:04:22.478
Loading Kernel Symbols
...............................................................
................................................................
..........
Loading User Symbols
PEB is paged out (Peb.Ldr = 00000000`00312018).  Type ".hh dbgerr001" for details
Loading unloaded module list
......................
For analysis of this file, run !analyze -v
nt!KeBugCheck:
fffff801`d63d9570 4883ec28        sub     rsp,28h

Loading Dump File [C:\MEMORY\MEMORY.DMP]
Kernel Bitmap Dump File: Kernel address space is available, User address space may not be available.

Can't set dump file contexts
MachineInfo::SetContext failed - Thread: 000001D884C6FA50  Handle: b  Id: b - Error == 0x8000FFFF

************* Path validation summary **************
Response                         Time (ms)     Location
Deferred                                       srv*
Symbol search path is: srv*
Executable search path is: 
Windows 10 Kernel Version 14393 MP (16 procs) Free x64
Product: Server, suite: TerminalServer DataCenter SingleUserTS
Edition build lab: 14393.4530.amd64fre.rs1_release.210705-0736
Machine Name:
Kernel base = 0xfffff801`d627c000 PsLoadedModuleList = 0xfffff801`d6580060
Debug session time: Sat Oct  9 19:39:56.508 2021 (UTC + 10:30)
System Uptime: 14 days 0:04:22.478
Loading Kernel Symbols
...............................................................
................................................................
..........
Loading User Symbols
PEB is paged out (Peb.Ldr = 00000000`00312018).  Type ".hh dbgerr001" for details
Loading unloaded module list
......................
nt!KeBugCheck:
fffff801`d63d9570 4883ec28        sub     rsp,28h

Loading Dump File [C:\MEMORY\MEMORY.DMP]
Kernel Bitmap Dump File: Kernel address space is available, User address space may not be available.

Can't set dump file contexts
MachineInfo::SetContext failed - Thread: 000001D884C815D0  Handle: b  Id: b - Error == 0x8000FFFF

************* Path validation summary **************
Response                         Time (ms)     Location
Deferred                                       srv*
Symbol search path is: srv*
Executable search path is: 
Windows 10 Kernel Version 14393 MP (16 procs) Free x64
Product: Server, suite: TerminalServer DataCenter SingleUserTS
Edition build lab: 14393.4530.amd64fre.rs1_release.210705-0736
Machine Name:
Kernel base = 0xfffff801`d627c000 PsLoadedModuleList = 0xfffff801`d6580060
Debug session time: Sat Oct  9 19:39:56.508 2021 (UTC + 10:30)
System Uptime: 14 days 0:04:22.478
Loading Kernel Symbols
...............................................................
................................................................
..........
Loading User Symbols
PEB is paged out (Peb.Ldr = 00000000`00312018).  Type ".hh dbgerr001" for details
Loading unloaded module list
......................
nt!KeBugCheck:
fffff801`d63d9570 4883ec28        sub     rsp,28h
||2:10: kd> !analyze -v
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

PFN_REFERENCE_COUNT (1c)
Arguments:
Arg1: 0000000000000000
Arg2: 0000000000000000
Arg3: 0000000000000000
Arg4: 0000000000000000

Debugging Details:
------------------

Page 5100 not present in the dump file. Type ".hh dbgerr004" for details
Page 5100 not present in the dump file. Type ".hh dbgerr004" for details
Page 5100 not present in the dump file. Type ".hh dbgerr004" for details

KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.mSec
    Value: 3999

    Key  : Analysis.DebugAnalysisManager
    Value: Create

    Key  : Analysis.Elapsed.mSec
    Value: 4074
Windows for home | Other | Apps

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

1 answer

Sort by: Most helpful
  1. Anonymous
    2021-10-14T03:51:29+00:00

    Hi Prabhuatadl, I am Rob, an Independent Advisor not affiliated with Microsoft and a 15 time and dual award Microsoft MVP specializing in Windows troubleshooting and Bluescreen analysis. Please remember as independents we are not responsible for the development of Windows or the computer hardware and drivers. If you will work with me I will be here to help until the issue is resolved.

    The Microsoft Community is a peer review forum for the consumer versions of Windows Home and Pro and some other Microsoft products. The Business, large networks, domains, Windows Servers, Enterprise, Education, and Business Pro versions are supported by Microsoft's Q & A which is also a free support forum.

    Microsoft Q & A - Server and IT Pro forums - Free

    https://docs.microsoft.com/en-us/windows/

    Please check with them and they will be able to analyze the DMP files and help resolve the BSOD issue.

    Here to help,

    Rob


    Standard Disclaimer: Those may be non-Microsoft websites. The pages appear to be providing accurate, safe information. Watch out for ads on the site that may advertise products frequently classified as a PUP (Potentially Unwanted Products). Thoroughly research any product advertised on the site before you decide to download and install it.

    Please let us know the results and if you need further assistance. Feedback definitely helps us help all.

    Was this answer helpful?

    0 comments No comments