none
BSOD 0XC2 Windows Server 2008 R2

    General discussion

  • I have a Hyper-V 2008 R2 server running 6 individual virtual machines (4 which are RD servers). Twice this week one of the VM running RDS has blue screened.  Using WinDbg on the MEMORY.DMP file seems to point to NTFS.  This only occurs on one of the VMs and they are all running the same updates. Don't believe it is memory since no other VM is experiencing problems.  Since it is not instant, I cannot just reboot and disable devices or drivers. Occurred two in 4 days.  Each RDS handles around 20 users.

    Any advice?

    Debug Information:

    0: kd> !analyze -v
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************

    BAD_POOL_CALLER (c2)
    The current thread is making a bad pool request.  Typically this is at a bad IRQL level or double freeing the same allocation, etc.
    Arguments:
    Arg1: 0000000000000099, Attempt to free pool with invalid address  (or corruption in pool header)
    Arg2: fffff8a028fac010, Address being freed
    Arg3: 0000000000000000, 0
    Arg4: 0000000000000000, 0

    Debugging Details:
    ------------------


    FAULTING_IP:
    Ntfs!NtfsDeleteFcb+3a3
    fffff880`01692193 4c893b          mov     qword ptr [rbx],r15

    BUGCHECK_STR:  0xc2_99

    DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

    PROCESS_NAME:  System

    CURRENT_IRQL:  0

    LAST_CONTROL_TRANSFER:  from fffff80001b544ec to fffff800016c6c00

    STACK_TEXT: 
    fffff880`114fc828 fffff800`01b544ec : 00000000`000000c2 00000000`00000099 fffff8a0`28fac010 00000000`00000000 : nt!KeBugCheckEx
    fffff880`114fc830 fffff800`0177c3a1 : fffffa80`0cee9150 fffff880`013756de fffff8a0`29994570 00000000`000000a0 : nt!VerifierBugCheckIfAppropriate+0x3c
    fffff880`114fc870 fffff800`017f9c73 : fffff8a0`28fac000 00000000`00000870 00000000`0000007f fffff880`114fc9e1 : nt!VerifierFreeTrackedPool+0x41
    fffff880`114fc8b0 fffff880`01692193 : fffff8a0`28fac010 00000000`00000000 fffffa80`0f699860 fffffa80`0f699860 : nt!ExDeferredFreePool+0x129f
    fffff880`114fc960 fffff880`0160f7a2 : fffff800`0186c280 fffff880`114fcb01 fffff880`114fc9e1 fffff8a0`28fac010 : Ntfs!NtfsDeleteFcb+0x3a3
    fffff880`114fc9c0 fffff880`0169461c : fffffa80`0f699860 fffffa80`0c75e180 fffff8a0`28fac010 fffff8a0`28fac3a8 : Ntfs!NtfsTeardownFromLcb+0x1e2
    fffff880`114fca50 fffff880`01616ab2 : fffffa80`0f699860 fffffa80`0f699860 fffff8a0`28fac010 00000000`00000000 : Ntfs!NtfsTeardownStructures+0xcc
    fffff880`114fcad0 fffff880`016a3f93 : fffffa80`0f699860 fffff800`0186c280 fffff8a0`28fac010 00000000`00000009 : Ntfs!NtfsDecrementCloseCounts+0xa2
    fffff880`114fcb10 fffff880`0169332b : fffffa80`0f699860 fffff8a0`28fac140 fffff8a0`28fac010 fffffa80`0c75e180 : Ntfs!NtfsCommonClose+0x353
    fffff880`114fcbe0 fffff800`016d0251 : 00000000`00000000 fffff880`02f86300 fffffa80`14f1bd01 00000000`00000002 : Ntfs!NtfsFspClose+0x15f
    fffff880`114fccb0 fffff800`01964ede : fffffa80`00000000 fffffa80`17256140 00000000`00000080 fffffa80`0c2fe9e0 : nt!ExpWorkerThread+0x111
    fffff880`114fcd40 fffff800`016b7906 : fffff800`01841e80 fffffa80`17256140 fffffa80`156016a0 0000000c`23574000 : nt!PspSystemThreadStartup+0x5a
    fffff880`114fcd80 00000000`00000000 : fffff880`114fd000 fffff880`114f7000 fffff880`114fc9e0 00000000`00000000 : nt!KxStartSystemThread+0x16


    STACK_COMMAND:  kb

    FOLLOWUP_IP:
    Ntfs!NtfsDeleteFcb+3a3
    fffff880`01692193 4c893b          mov     qword ptr [rbx],r15

    SYMBOL_STACK_INDEX:  4

    SYMBOL_NAME:  Ntfs!NtfsDeleteFcb+3a3

    FOLLOWUP_NAME:  MachineOwner

    MODULE_NAME: Ntfs

    IMAGE_NAME:  Ntfs.sys

    DEBUG_FLR_IMAGE_TIMESTAMP:  5167f5fc

    FAILURE_BUCKET_ID:  X64_0xc2_99_Ntfs!NtfsDeleteFcb+3a3

    BUCKET_ID:  X64_0xc2_99_Ntfs!NtfsDeleteFcb+3a3

    Followup: MachineOwner
    ---------

    0: kd> lmvm Ntfs
    start             end                 module name
    fffff880`01608000 fffff880`017aa000   Ntfs       (pdb symbols)          e:\websymbols\ntfs.pdb\0842A8FED1C5463FB4078078781F5C622\ntfs.pdb
        Loaded symbol image file: Ntfs.sys
        Image path: \SystemRoot\System32\Drivers\Ntfs.sys
        Image name: Ntfs.sys
        Timestamp:        Fri Apr 12 06:54:36 2013 (5167F5FC)
        CheckSum:         001A27D8
        ImageSize:        001A2000
        File version:     6.1.7601.18127
        Product version:  6.1.7601.18127
        File flags:       0 (Mask 3F)
        File OS:          40004 NT Win32
        File type:        3.7 Driver
        File date:        00000000.00000000
        Translations:     0409.04b0
        CompanyName:      Microsoft Corporation
        ProductName:      Microsoft® Windows® Operating System
        InternalName:     ntfs.sys
        OriginalFilename: ntfs.sys
        ProductVersion:   6.1.7601.18127
        FileVersion:      6.1.7601.18127 (win7sp1_gdr.130412-0013)
        FileDescription:  NT File System Driver
        LegalCopyright:   © Microsoft Corporation. All rights reserved.

    Thursday, July 25, 2013 8:33 PM

All replies