Hi all,
Need help finding the root cause of Windows Server Crash, the OS that crashed is Windows Server 2012 (Hyper-V Guest) and the Host is Windows Server 2008 R2.
Trying to debug with Windbg but can't understand it, this is the result:
BugCheck A, {fffff6fb40001dd8, 0, 0, fffff800018d25bc}
Probably caused by : memory_corruption ( nt!MiDeletePageTableHierarchy+9c )
Followup: MachineOwner
---------
16.3: kd:x86> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: fffff6fb40001dd8, memory referenced
Arg2: 0000000000000000, IRQL
Arg3: 0000000000000000, bitfield :
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: fffff800018d25bc, address which referenced memory
Debugging Details:
------------------
DUMP_CLASS: 1
DUMP_QUALIFIER: 401
BUILD_VERSION_STRING: 7601.17514.amd64fre.win7sp1_rtm.101119-1850
SYSTEM_MANUFACTURER: Microsoft Corporation
VIRTUAL_MACHINE: HyperV
SYSTEM_PRODUCT_NAME: Virtual Machine
SYSTEM_VERSION: 7.0
BIOS_VENDOR: American Megatrends Inc.
BIOS_VERSION: 090006
BIOS_DATE: 05/23/2012
BASEBOARD_MANUFACTURER: Microsoft Corporation
BASEBOARD_PRODUCT: Virtual Machine
BASEBOARD_VERSION: 7.0
DUMP_TYPE: 1
BUGCHECK_P1: fffff6fb40001dd8
BUGCHECK_P2: 0
BUGCHECK_P3: 0
BUGCHECK_P4: fffff800018d25bc
READ_ADDRESS: fffff6fb40001dd8
CURRENT_IRQL: 0
FAULTING_IP:
nt!MiDeletePageTableHierarchy+9c
fffff800`018d25bc 49 dec ecx
CPU_COUNT: 4
CPU_MHZ: dac
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 3e
CPU_STEPPING: 4
CPU_MICROCODE: 6,0,0,0 (F,M,S,R) SIG: FFFFFFFF'00000000 (cache) FFFFFFFF'00000000 (init)
BUGCHECK_STR: 0xA
ANALYSIS_SESSION_HOST: XXX
ANALYSIS_SESSION_TIME: 05-13-2016 18:16:45.0464
ANALYSIS_VERSION: 10.0.10586.567 amd64fre
IP_IN_FREE_BLOCK: 0
LAST_CONTROL_TRANSFER: from 0000000000000000 to 0000000000000000
STACK_TEXT:
00000000 00000000 00000000 00000000 00000000 0x0
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!MiDeletePageTableHierarchy+9c
fffff800`018d25bc 49 dec ecx
FAULT_INSTR_CODE: 48068b49
SYMBOL_NAME: nt!MiDeletePageTableHierarchy+9c
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 4ce7951a
IMAGE_VERSION: 6.1.7601.17514
IMAGE_NAME: memory_corruption
BUCKET_ID: INVALID_KERNEL_CONTEXT_0xA
DEFAULT_BUCKET_ID: INVALID_KERNEL_CONTEXT_0xA
PRIMARY_PROBLEM_CLASS: INVALID_KERNEL_CONTEXT
FAILURE_BUCKET_ID: INVALID_KERNEL_CONTEXT_0xA
TARGET_TIME: 2015-11-24T04:21:10.000Z
OSBUILD: 7601
OSSERVICEPACK: 1000
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 3
OSPLATFORM_TYPE: x64
OSNAME: Windows 7
OSEDITION: Windows 7 Server (Service Pack 1) TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 2010-11-20 16:30:02
BUILDDATESTAMP_STR: 101119-1850
BUILDLAB_STR: win7sp1_rtm
BUILDOSVER_STR: 6.1.7601.17514.amd64fre.win7sp1_rtm.101119-1850
ANALYSIS_SESSION_ELAPSED_TIME: 3c4
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:invalid_kernel_context_0xa
FAILURE_ID_HASH: {e1670dde-ec4b-aafd-0053-25c657509baa}
Followup: MachineOwner
Maybe there is someone who have similar case or could read those debug care to help. :)
thank you