VM웨어에서 기동 중인 시스템이고
그룹웨어로 이용 중인 서버이기도 합니다.
마땅한 이유없이 BSOD와 함께 리부트 됐습니다.
도움을 요청하는 바입니다 ㅠㅠ
Microsoft (R) Windows Debugger Version 10.0.10586.567 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\LEE\Desktop\MEMORY.DMP]
Kernel Summary Dump File: Kernel address space is available, User address space may not be available.
Symbol search path is: srv*
Executable search path is:
Windows Server 2003 Kernel Version 3790 (Service Pack 2) MP (4 procs) Free x86 compatible
Product: Server, suite: TerminalServer SingleUserTS
Built by: 3790.srv03_sp2_qfe.120503-0334
Machine Name:
Kernel base = 0x80800000 PsLoadedModuleList = 0x808a8ee8
Debug session time: Wed Apr 13 01:45:03.018 2016 (UTC + 9:00)
System Uptime: 27 days 5:28:53.671
Loading Kernel Symbols
...............................................................
................................................................
.....
Loading User Symbols
PEB is paged out (Peb.Ldr = 7ffde00c). Type ".hh dbgerr001" for details
Loading unloaded module list
.....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 8E, {c0000005, 808941dd, b44deacc, 0}
Probably caused by : Pool_Corruption ( nt!ExDeferredFreePool+1d7 )
Followup: Pool_corruption
1: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KERNEL_MODE_EXCEPTION_NOT_HANDLED (8e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: c0000005, The exception code that was not handled
Arg2: 808941dd, The address that the exception occurred at
Arg3: b44deacc, Trap Frame
Arg4: 00000000
Debugging Details:
DUMP_CLASS: 1
DUMP_QUALIFIER: 401
BUILD_VERSION_STRING: 3790.srv03_sp2_qfe.120503-0334
SYSTEM_MANUFACTURER: VMware, Inc.
VIRTUAL_MACHINE: VMware
SYSTEM_PRODUCT_NAME: VMware Virtual Platform
SYSTEM_VERSION: None
BIOS_VENDOR: Phoenix Technologies LTD
BIOS_VERSION: 6.00
BIOS_DATE: 07/30/2013
BASEBOARD_MANUFACTURER: Intel Corporation
BASEBOARD_PRODUCT: 440BX Desktop Reference Platform
BASEBOARD_VERSION: None
DUMP_TYPE: 1
BUGCHECK_P1: ffffffffc0000005
BUGCHECK_P2: ffffffff808941dd
BUGCHECK_P3: ffffffffb44deacc
BUGCHECK_P4: 0
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - 0x%p
FAULTING_IP:
nt!ExDeferredFreePool+1d7
808941dd 8937 mov dword ptr [edi],esi
TRAP_FRAME: b44deacc -- (.trap 0xffffffffb44deacc)
ErrCode = 00000002
eax=e328e780 ebx=00000004 ecx=000001ff edx=e328e758 esi=00040807 edi=73687366
eip=808941dd esp=b44deb40 ebp=b44deb78 iopl=0 nv up ei pl nz na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010206
nt!ExDeferredFreePool+0x1d7:
808941dd 8937 mov dword ptr [edi],esi ds:0023:73687366=????????
Resetting default scope
CPU_COUNT: 4
CPU_MHZ: 95a
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 3e
CPU_STEPPING: 4
CPU_MICROCODE: 6,3e,4,0 (F,M,S,R) SIG: 417'00000000 (cache) 417'00000000 (init)
DEFAULT_BUCKET_ID: DRIVER_FAULT
BUGCHECK_STR: 0x8E
PROCESS_NAME: lsass.exe
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: BLOODYRED
ANALYSIS_SESSION_TIME: 04-22-2016 19:30:39.0493
ANALYSIS_VERSION: 10.0.10586.567 amd64fre
LAST_CONTROL_TRANSFER: from 8082d9c0 to 80827e33
STACK_TEXT:
b44de698 8082d9c0 0000008e c0000005 808941dd nt!KeBugCheckEx+0x1b
b44dea5c 8088bf4a b44dea78 00000000 b44deacc nt!KiDispatchException+0x3a2
b44deac4 8088befe b44deb78 808941dd badb0d00 nt!CommonDispatchException+0x4a
b44deae8 8098cc9e e1e48e98 00000011 00000000 nt!Kei386EoiHelper+0x186
b44deb78 808948c3 8b3b10c0 00000000 00000000 nt!ExpAllocateHandleTableEntry+0xf4
b44debd0 8093bc14 e121c008 e56b6f54 8b374ad0 nt!ExFreePoolWithTag+0x57f
b44debec 80935e32 80a63f00 e121c018 00000000 nt!ObpFreeObject+0x192
b44dec04 8086dfd7 e121c030 00000000 e121c030 nt!ObpRemoveObjectRoutine+0xe4
b44dec24 8094b8df 00000000 00000000 00000004 nt!ObfDereferenceObject+0x67
b44dec38 8094b90f 8925fab0 00000002 00000000 nt!PsRevertThreadToSelf+0xa3
b44dec50 809495e8 8925f880 00000000 b44ded64 nt!PsAssignImpersonationToken+0x1d
b44ded4c 8088b46c fffffffe 00000005 00c3f6d8 nt!NtSetInformationThread+0x208
b44ded4c 7c96845c fffffffe 00000005 00c3f6d8 nt!KiFastCallEntry+0xfc
WARNING: Frame IP not in any known module. Following frames may be wrong.
00c3f6dc 00000000 00000000 00000000 00000000 0x7c96845c
STACK_COMMAND: kb
THREAD_SHA1_HASH_MOD_FUNC: e1165d5611342865fb479525b14bc36561d3c0de
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: e58f9a770b2a681a055f3a6a647fcd8c1b8c92b2
THREAD_SHA1_HASH_MOD: fe34192f63d13620a8987d294372ee74d699cfee
FOLLOWUP_IP:
nt!ExDeferredFreePool+1d7
808941dd 8937 mov dword ptr [edi],esi
FAULT_INSTR_CODE: 7e893789
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!ExDeferredFreePool+1d7
FOLLOWUP_NAME: Pool_corruption
IMAGE_NAME: Pool_Corruption
DEBUG_FLR_IMAGE_TIMESTAMP: 0
IMAGE_VERSION: 5.2.3790.4998
MODULE_NAME: Pool_Corruption
FAILURE_BUCKET_ID: 0x8E_nt!ExDeferredFreePool+1d7
BUCKET_ID: 0x8E_nt!ExDeferredFreePool+1d7
PRIMARY_PROBLEM_CLASS: 0x8E_nt!ExDeferredFreePool+1d7
TARGET_TIME: 2016-04-12T16:45:03.000Z
OSBUILD: 3790
OSSERVICEPACK: 2000
SERVICEPACK_NUMBER: 2
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 3
OSPLATFORM_TYPE: x86
OSNAME: Windows Server 2003
OSEDITION: Windows Server 2003 Server (Service Pack 2) TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 2012-05-03 21:38:32
BUILDOSVER_STR: 5.2.3790.srv03_sp2_qfe.120503-0334
ANALYSIS_SESSION_ELAPSED_TIME: 81ba
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0x8e_nt!exdeferredfreepool+1d7
FAILURE_ID_HASH: {06579ab7-33f6-f56c-30f2-7e0193287670}
Followup: Pool_corruption