none
Server 2008 crash dump

    Question

  • Hello,

    I need help analyzing this dump file. My server crashed (again) during the night and I can't pinpoint the reason why. This happens roughly every couple of weeks.

    System HP ProLiant DL380p

    OS Windows Server 2008 R2

    Thanks!

    Microsoft (R) Windows Debugger Version 6.12.0002.633 AMD64
    Copyright (c) Microsoft Corporation. All rights reserved.
    Loading Dump File [C:\Windows\Minidump\070913-25084-01.dmp]
    Mini Kernel Dump File: Only registers and stack trace are available
    Symbol search path is: SRV*C:\Symbols*http://msdl.microsoft.com/download/symbols
    Executable search path is: 
    Windows 7 Kernel Version 7601 (Service Pack 1) MP (12 procs) Free x64
    Product: LanManNt, suite: TerminalServer SingleUserTS
    Built by: 7601.17944.amd64fre.win7sp1_gdr.120830-0333
    Machine Name:
    Kernel base = 0xfffff800`01816000 PsLoadedModuleList = 0xfffff800`01a5a670
    Debug session time: Tue Jul  9 23:03:51.081 2013 (UTC + 2:00)
    System Uptime: 19 days 22:55:13.717
    Loading Kernel Symbols
    ...............................................................
    ................................................................
    ..................
    Loading User Symbols
    Loading unloaded module list
    ...........
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    Use !analyze -v to get detailed debugging information.
    BugCheck 3B, {c0000005, fffff88005dd19a1, fffff8800969cb30, 0}
    Probably caused by : zaccess.sys ( zaccess+1d9a1 )
    Followup: MachineOwner
    ---------
    5: kd> !analyze -v
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************
    SYSTEM_SERVICE_EXCEPTION (3b)
    An exception happened while executing a system service routine.
    Arguments:
    Arg1: 00000000c0000005, Exception code that caused the bugcheck
    Arg2: fffff88005dd19a1, Address of the instruction which caused the bugcheck
    Arg3: fffff8800969cb30, Address of the context record for the exception that caused the bugcheck
    Arg4: 0000000000000000, zero.
    Debugging Details:
    ------------------
    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
    FAULTING_IP: 
    zaccess+1d9a1
    fffff880`05dd19a1 0fbe494c        movsx   ecx,byte ptr [rcx+4Ch]
    CONTEXT:  fffff8800969cb30 -- (.cxr 0xfffff8800969cb30)
    rax=000000000000000a rbx=0000000000000005 rcx=0000000000000000
    rdx=fffffa80135c04c0 rsi=fffffa8014dba340 rdi=fffff8800969d580
    rip=fffff88005dd19a1 rsp=fffff8800969d510 rbp=fffffa80133e0968
     r8=fffffa800f903e70  r9=0000000000000000 r10=005c007300780073
    r11=0000000000000022 r12=fffffa80135c04c0 r13=fffffa801b651c00
    r14=0000000000000000 r15=fffffa800f773060
    iopl=0         nv up ei pl nz na po nc
    cs=0010  ss=0018  ds=002b  es=002b  fs=0053  gs=002b             efl=00010206
    zaccess+0x1d9a1:
    fffff880`05dd19a1 0fbe494c        movsx   ecx,byte ptr [rcx+4Ch] ds:002b:00000000`0000004c=??
    Resetting default scope
    CUSTOMER_CRASH_COUNT:  1
    DEFAULT_BUCKET_ID:  DRIVER_FAULT_SERVER_MINIDUMP
    BUGCHECK_STR:  0x3B
    PROCESS_NAME:  caagstart.exe
    CURRENT_IRQL:  0
    LAST_CONTROL_TRANSFER:  from 0000000000000000 to fffff88005dd19a1
    STACK_TEXT:  
    fffff880`0969d510 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : zaccess+0x1d9a1
    FOLLOWUP_IP: 
    zaccess+1d9a1
    fffff880`05dd19a1 0fbe494c        movsx   ecx,byte ptr [rcx+4Ch]
    SYMBOL_STACK_INDEX:  0
    SYMBOL_NAME:  zaccess+1d9a1
    FOLLOWUP_NAME:  MachineOwner
    MODULE_NAME: zaccess
    IMAGE_NAME:  zaccess.sys
    DEBUG_FLR_IMAGE_TIMESTAMP:  5146f52f
    STACK_COMMAND:  .cxr 0xfffff8800969cb30 ; kb
    FAILURE_BUCKET_ID:  X64_0x3B_zaccess+1d9a1
    BUCKET_ID:  X64_0x3B_zaccess+1d9a1
    Followup: MachineOwner
    ---------
    5: kd> lmvm zaccess
    start             end                 module name
    fffff880`05db4000 fffff880`05dfb000   zaccess  T (no symbols)           
        Loaded symbol image file: zaccess.sys
        Image path: \SystemRoot\SYSWOW64\Drivers\zaccess.sys
        Image name: zaccess.sys
        Timestamp:        Mon Mar 18 12:06:23 2013 (5146F52F)
        CheckSum:         0004C1F3
        ImageSize:        00047000
        Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4
    Wednesday, July 10, 2013 1:55 PM

Answers

All replies