windows server 2008 r2 sp1 不定期蓝屏重启
我公司有一台DELL R620服务器不定期蓝屏重启,系统是windows server 2008 r2 sp1,不知道是什么原因?以下是Dump文件的分析:
Microsoft (R) Windows Debugger Version 10.0.14321.1024 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\Administrator\Desktop\MEMORY.DMP]
Kernel Summary Dump File: Kernel address space is available, User address space may not be available.
************* Symbol Path validation summary **************
Response Time (ms) Location
OK
C:\Symbols
Symbol search path is: C:\Symbols
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: Server, suite: Enterprise TerminalServer
Built by: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
Machine Name:
Kernel base = 0xfffff800`02019000 PsLoadedModuleList = 0xfffff800`0225ee90
Debug session time: Wed Nov 2 17:59:18.362 2016 (UTC + 8:00)
System Uptime: 6 days 2:06:18.734
Loading Kernel Symbols
...............................................................
................................................................
...........
Loading User Symbols
PEB is paged out (Peb.Ldr = 00000000`7efdf018). Type ".hh dbgerr001" for details
Loading unloaded module list
........
The context is partially valid. Only x86 user-mode context is available.
*******************************************************************************
*
*
* Bugcheck Analysis
*
*
*
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 3B, {c0000005, fb87c, 1494fad0, 0}
Page 401897 not present in the dump file. Type ".hh dbgerr004" for details
Page 401897 not present in the dump file. Type ".hh dbgerr004" for details
Page 3aa1eb not present in the dump file. Type ".hh dbgerr004" for details
Page 3aa1eb not present in the dump file. Type ".hh dbgerr004" for details
Page 402ca7 not present in the dump file. Type ".hh dbgerr004" for details
Page 402651 not present in the dump file. Type ".hh dbgerr004" for details
Probably caused by : win32k.sys ( win32k!xxxProcessEventMessage+1c0 )
Followup: MachineOwner
---------
16.0: kd:x86> !analyze -v
*******************************************************************************
*
*
* Bugcheck Analysis
*
*
*
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: c0000005, Exception code that caused the bugcheck
Arg2: 000fb87c, Address of the instruction which caused the bugcheck
Arg3: 1494fad0, Address of the context record for the exception that caused the bugcheck
Arg4: 00000000, zero.
Debugging Details:
------------------
DUMP_CLASS: 1
DUMP_QUALIFIER: 401
BUILD_VERSION_STRING: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
SYSTEM_MANUFACTURER: Dell Inc.
SYSTEM_PRODUCT_NAME: PowerEdge R620
SYSTEM_SKU: SKU=NotProvided;ModelName=PowerEdge R620
BIOS_VENDOR: Dell Inc.
BIOS_VERSION: 2.5.4
BIOS_DATE: 01/22/2016
BASEBOARD_MANUFACTURER: Dell Inc.
BASEBOARD_PRODUCT: 046R5M
BASEBOARD_VERSION: A05
DUMP_TYPE: 1
BUGCHECK_P1: c0000005
BUGCHECK_P2: fffff960000fb87c
BUGCHECK_P3: fffff8801494fad0
BUGCHECK_P4: 0
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - 0x%08lx
FAULTING_IP:
win32k!xxxProcessEventMessage+1c0
fffff960`000fb87c 017308 add dword ptr [ebx+8],esi
CONTEXT: 1494fad0 -- (.cxr 0xfffff8801494fad0)
eax=00000000 ebx=fffff880 ecx=00000000 edx=00000001 esi=14950650 edi=fffff880
eip=00000000 esp=00000000 ebp=00000000 iopl=0 nv up di pl nz na po nc
cs=0000 ss=0018 ds=04b0 es=0000 fs=0000 gs=f900 efl=00000000
00000000`00000000 ?? ???
Resetting default scope
CPU_COUNT: 4
CPU_MHZ: 708
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 3e
CPU_STEPPING: 4
CPU_MICROCODE: 6,0,0,0 (F,M,S,R) SIG: 428'00000000 (cache) 428'00000000 (init)
BUGCHECK_STR: 0x3B
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: WIN-LI41GQCKC1K
ANALYSIS_SESSION_TIME: 11-20-2016 20:31:34.0250
ANALYSIS_VERSION: 10.0.14321.1024 amd64fre
IP_IN_FREE_BLOCK: 0
LAST_CONTROL_TRANSFER: from 00000000 to 00000000
STACK_TEXT:
00000000 00000000 00000000 00000000 00000000 0x0
STACK_COMMAND: kb
FOLLOWUP_IP:
win32k!xxxProcessEventMessage+1c0
fffff960`000fb87c 017308 add dword ptr [ebx+8],esi
FAULT_INSTR_CODE: f0087301
SYMBOL_NAME: win32k!xxxProcessEventMessage+1c0
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: win32k
IMAGE_NAME: win32k.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 4ce79a73
IMAGE_VERSION: 6.1.7601.17514
BUCKET_ID: INVALID_KERNEL_CONTEXT_0x3B
DEFAULT_BUCKET_ID: INVALID_KERNEL_CONTEXT_0x3B
PRIMARY_PROBLEM_CLASS: INVALID_KERNEL_CONTEXT
FAILURE_BUCKET_ID: INVALID_KERNEL_CONTEXT_0x3B
TARGET_TIME: 2016-11-02T09:59:18.000Z
OSBUILD: 7601
OSSERVICEPACK: 1000
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 18
PRODUCT_TYPE: 3
OSPLATFORM_TYPE: x64
OSNAME: Windows 7
OSEDITION: Windows 7 Server (Service Pack 1) Enterprise TerminalServer
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 2010-11-20 17:30:02
BUILDDATESTAMP_STR: 101119-1850
BUILDLAB_STR: win7sp1_rtm
BUILDOSVER_STR: 6.1.7601.17514.amd64fre.win7sp1_rtm.101119-1850
ANALYSIS_SESSION_ELAPSED_TIME: 405
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:invalid_kernel_context_0x3b
FAILURE_ID_HASH: {47d39f4d-e8b2-9190-8f3e-f596bd729a8d}
Followup: MachineOwner
---------