none
windows 2003 ent 입니다. 하루에 한번꼴로 세이브 덤프를 찍으면서 재부팅 됩니다. RRS feed

  • 질문

  • 안녕하십니까. windows 2003 ent 서버를 운영중입니다.

    비슷한 시간대에 하루 간격으로 서버가 덤프를 찍고 재부팅 됩니다.

    OS를 재설치 후에도 동일 증상이 나오는데 어떤부분을 체크해야 되는지 자문을 구합니다.

    Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [C:\Documents and Settings\Administrator\바탕 화면\MEMORY.DMP]
    Kernel Summary Dump File: Only kernel address space is available

    Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
    Executable search path is:
    Windows Server 2003 Kernel Version 3790 (Service Pack 2) MP (16 procs) Free x86 compatible
    Product: Server, suite: Enterprise TerminalServer SingleUserTS
    Built by: 3790.srv03_sp2_rtm.070216-1710
    Machine Name:
    Kernel base = 0x80800000 PsLoadedModuleList = 0x808a6ea8
    Debug session time: Tue Sep 29 06:56:57.890 2009 (GMT+9)
    System Uptime: 0 days 17:08:28.567
    Loading Kernel Symbols
    ...............................................................
    ...................................................
    Loading User Symbols

    Loading unloaded module list
    .........................
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck D1, {bb84, d0000002, 0, b915a6b9}

    Probably caused by : TDI.SYS ( TDI!CTEpTimerHandler+f )

    Followup: MachineOwner
    ---------

    0: kd> !analyze -v
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************

    DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
    An attempt was made to access a pageable (or completely invalid) address at an
    interrupt request level (IRQL) that is too high.  This is usually
    caused by drivers using improper addresses.
    If kernel debugger is available get stack backtrace.
    Arguments:
    Arg1: 0000bb84, memory referenced
    Arg2: d0000002, IRQL
    Arg3: 00000000, value 0 = read operation, 1 = write operation
    Arg4: b915a6b9, address which referenced memory

    Debugging Details:
    ------------------


    READ_ADDRESS:  0000bb84

    CURRENT_IRQL:  2

    FAULTING_IP:
    tcpip!IterateOverSTrie+153
    b915a6b9 8b4104          mov     eax,dword ptr [ecx+4]

    DEFAULT_BUCKET_ID:  DRIVER_FAULT

    BUGCHECK_STR:  0xD1

    PROCESS_NAME:  Idle

    TRAP_FRAME:  8089a334 -- (.trap 0xffffffff8089a334)
    ErrCode = 00000000
    eax=8b462568 ebx=00000004 ecx=0000bb80 edx=00000000 esi=8089a4c0 edi=8b470960
    eip=b915a6b9 esp=8089a3a8 ebp=8089a44c iopl=0         nv up ei ng nz na po nc
    cs=0008  ss=0010  ds=0023  es=0023  fs=0030  gs=0000             efl=00010282
    tcpip!IterateOverSTrie+0x153:
    b915a6b9 8b4104          mov     eax,dword ptr [ecx+4] ds:0023:0000bb84=????????
    Resetting default scope

    LAST_CONTROL_TRANSFER:  from b915a6b9 to 8088c963

    STACK_TEXT: 
    8089a334 b915a6b9 badb0d00 00000000 808b4902 nt!KiTrap0E+0x2a7
    8089a44c b915a784 8089a4b0 00000000 8089a4d4 tcpip!IterateOverSTrie+0x153
    8089a45c b91598b9 8089a4c0 8089a4b0 badf0070 tcpip!GetNextRoute+0x1a
    8089a4d4 badf007f b9194be0 00000000 8089a5a8 tcpip!IPRouteTimeout+0x90
    8089a4e4 80831cb0 b9194bf0 b9194be0 9985008a TDI!CTEpTimerHandler+0xf
    8089a5a8 8083208b 00000000 00000000 023c4323 nt!KiTimerExpiration+0x548
    8089a600 8088de1f 00000000 0000000e 00000000 nt!KiRetireDpcList+0x65
    8089a604 00000000 0000000e 00000000 00000000 nt!KiIdleLoop+0x37


    STACK_COMMAND:  kb

    FOLLOWUP_IP:
    TDI!CTEpTimerHandler+f
    badf007f 5d              pop     ebp

    SYMBOL_STACK_INDEX:  4

    SYMBOL_NAME:  TDI!CTEpTimerHandler+f

    FOLLOWUP_NAME:  MachineOwner

    MODULE_NAME: TDI

    IMAGE_NAME:  TDI.SYS

    DEBUG_FLR_IMAGE_TIMESTAMP:  45d69a2f

    FAILURE_BUCKET_ID:  0xD1_TDI!CTEpTimerHandler+f

    BUCKET_ID:  0xD1_TDI!CTEpTimerHandler+f

    Followup: MachineOwner
    ---------

    0: kd> lmvm TDI
    start    end        module name
    badef000 badfa000   TDI        (pdb symbols)          c:\websymbols\tdi.pdb\0A6B164853FB4C3CA35A39F06BCF263B1\tdi.pdb
        Loaded symbol image file: TDI.SYS
        Image path: \SystemRoot\system32\DRIVERS\TDI.SYS
        Image name: TDI.SYS
        Timestamp:        Sat Feb 17 15:01:19 2007 (45D69A2F)
        CheckSum:         0000C620
        ImageSize:        0000B000
        File version:     5.2.3790.3959
        Product version:  5.2.3790.3959
        File flags:       0 (Mask 3F)
        File OS:          40004 NT Win32
        File type:        3.6 Driver
        File date:        00000000.00000000
        Translations:     0409.04b0
        CompanyName:      Microsoft Corporation
        ProductName:      Microsoft® Windows® Operating System
        InternalName:     tdi.sys
        OriginalFilename: tdi.sys
        ProductVersion:   5.2.3790.3959
        FileVersion:      5.2.3790.3959 (srv03_sp2_rtm.070216-1710)
        FileDescription:  TDI Wrapper
        LegalCopyright:   © Microsoft Corporation. All rights reserved.
    0: kd> .trap 0xffffffff8089a334
    ErrCode = 00000000
    eax=8b462568 ebx=00000004 ecx=0000bb80 edx=00000000 esi=8089a4c0 edi=8b470960
    eip=b915a6b9 esp=8089a3a8 ebp=8089a44c iopl=0         nv up ei ng nz na po nc
    cs=0008  ss=0010  ds=0023  es=0023  fs=0030  gs=0000             efl=00010282
    tcpip!IterateOverSTrie+0x153:
    b915a6b9 8b4104          mov     eax,dword ptr [ecx+4] ds:0023:0000bb84=????????

    덤프 전체 내용입니다.

    과연 어떤 문제 일까요 ??

    2009년 9월 29일 화요일 오전 1:52

모든 응답

  • 안녕하십니까. windows 2003 ent 서버를 운영중입니다.

    비슷한 시간대에 하루 간격으로 서버가 덤프를 찍고 재부팅 됩니다.

    OS를 재설치 후에도 동일 증상이 나오는데 어떤부분을 체크해야 되는지 자문을 구합니다.

    Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [C:\Documents and Settings\Administrator\바탕 화면\MEMORY.DMP]
    Kernel Summary Dump File: Only kernel address space is available

    Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
    Executable search path is:
    Windows Server 2003 Kernel Version 3790 (Service Pack 2) MP (16 procs) Free x86 compatible
    Product: Server, suite: Enterprise TerminalServer SingleUserTS
    Built by: 3790.srv03_sp2_rtm.070216-1710
    Machine Name:
    Kernel base = 0x80800000 PsLoadedModuleList = 0x808a6ea8
    Debug session time: Tue Sep 29 06:56:57.890 2009 (GMT+9)
    System Uptime: 0 days 17:08:28.567
    Loading Kernel Symbols
    ...............................................................
    ...................................................
    Loading User Symbols

    Loading unloaded module list
    .........................
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck D1, {bb84, d0000002, 0, b915a6b9}

    Probably caused by : TDI.SYS ( TDI!CTEpTimerHandler+f )

    Followup: MachineOwner
    ---------

    0: kd> !analyze -v
    *******************************************************************************
    *                                                                             *
    *                        Bugcheck Analysis                                    *
    *                                                                             *
    *******************************************************************************

    DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)
    An attempt was made to access a pageable (or completely invalid) address at an
    interrupt request level (IRQL) that is too high.  This is usually
    caused by drivers using improper addresses.
    If kernel debugger is available get stack backtrace.
    Arguments:
    Arg1: 0000bb84, memory referenced
    Arg2: d0000002, IRQL
    Arg3: 00000000, value 0 = read operation, 1 = write operation
    Arg4: b915a6b9, address which referenced memory

    Debugging Details:
    ------------------


    READ_ADDRESS:  0000bb84

    CURRENT_IRQL:  2

    FAULTING_IP:
    tcpip!IterateOverSTrie+153
    b915a6b9 8b4104          mov     eax,dword ptr [ecx+4]

    DEFAULT_BUCKET_ID:  DRIVER_FAULT

    BUGCHECK_STR:  0xD1

    PROCESS_NAME:  Idle

    TRAP_FRAME:  8089a334 -- (.trap 0xffffffff8089a334)
    ErrCode = 00000000
    eax=8b462568 ebx=00000004 ecx=0000bb80 edx=00000000 esi=8089a4c0 edi=8b470960
    eip=b915a6b9 esp=8089a3a8 ebp=8089a44c iopl=0         nv up ei ng nz na po nc
    cs=0008  ss=0010  ds=0023  es=0023  fs=0030  gs=0000             efl=00010282
    tcpip!IterateOverSTrie+0x153:
    b915a6b9 8b4104          mov     eax,dword ptr [ecx+4] ds:0023:0000bb84=????????
    Resetting default scope

    LAST_CONTROL_TRANSFER:  from b915a6b9 to 8088c963

    STACK_TEXT: 
    8089a334 b915a6b9 badb0d00 00000000 808b4902 nt!KiTrap0E+0x2a7
    8089a44c b915a784 8089a4b0 00000000 8089a4d4 tcpip!IterateOverSTrie+0x153
    8089a45c b91598b9 8089a4c0 8089a4b0 badf0070 tcpip!GetNextRoute+0x1a
    8089a4d4 badf007f b9194be0 00000000 8089a5a8 tcpip!IPRouteTimeout+0x90
    8089a4e4 80831cb0 b9194bf0 b9194be0 9985008a TDI!CTEpTimerHandler+0xf
    8089a5a8 8083208b 00000000 00000000 023c4323 nt!KiTimerExpiration+0x548
    8089a600 8088de1f 00000000 0000000e 00000000 nt!KiRetireDpcList+0x65
    8089a604 00000000 0000000e 00000000 00000000 nt!KiIdleLoop+0x37


    STACK_COMMAND:  kb

    FOLLOWUP_IP:
    TDI!CTEpTimerHandler+f
    badf007f 5d              pop     ebp

    SYMBOL_STACK_INDEX:  4

    SYMBOL_NAME:  TDI!CTEpTimerHandler+f

    FOLLOWUP_NAME:  MachineOwner

    MODULE_NAME: TDI

    IMAGE_NAME:  TDI.SYS

    DEBUG_FLR_IMAGE_TIMESTAMP:  45d69a2f

    FAILURE_BUCKET_ID:  0xD1_TDI!CTEpTimerHandler+f

    BUCKET_ID:  0xD1_TDI!CTEpTimerHandler+f

    Followup: MachineOwner
    ---------

    0: kd> lmvm TDI
    start    end        module name
    badef000 badfa000   TDI        (pdb symbols)          c:\websymbols\tdi.pdb\0A6B164853FB4C3CA35A39F06BCF263B1\tdi.pdb
        Loaded symbol image file: TDI.SYS
        Image path: \SystemRoot\system32\DRIVERS\TDI.SYS
        Image name: TDI.SYS
        Timestamp:        Sat Feb 17 15:01:19 2007 (45D69A2F)
        CheckSum:         0000C620
        ImageSize:        0000B000
        File version:     5.2.3790.3959
        Product version:  5.2.3790.3959
        File flags:       0 (Mask 3F)
        File OS:          40004 NT Win32
        File type:        3.6 Driver
        File date:        00000000.00000000
        Translations:     0409.04b0
        CompanyName:      Microsoft Corporation
        ProductName:      Microsoft® Windows® Operating System
        InternalName:     tdi.sys
        OriginalFilename: tdi.sys
        ProductVersion:   5.2.3790.3959
        FileVersion:      5.2.3790.3959 (srv03_sp2_rtm.070216-1710)
        FileDescription:  TDI Wrapper
        LegalCopyright:   © Microsoft Corporation. All rights reserved.
    0: kd> .trap 0xffffffff8089a334
    ErrCode = 00000000
    eax=8b462568 ebx=00000004 ecx=0000bb80 edx=00000000 esi=8089a4c0 edi=8b470960
    eip=b915a6b9 esp=8089a3a8 ebp=8089a44c iopl=0         nv up ei ng nz na po nc
    cs=0008  ss=0010  ds=0023  es=0023  fs=0030  gs=0000             efl=00010282
    tcpip!IterateOverSTrie+0x153:
    b915a6b9 8b4104          mov     eax,dword ptr [ecx+4] ds:0023:0000bb84=????????

    덤프 전체 내용입니다.

    과연 어떤 문제 일까요 ??


    • 답변으로 제안됨 jungran park 2009년 9월 30일 수요일 오후 6:05
    2009년 9월 30일 수요일 오후 6:04