Абсолютно внезапно начались BSoD'ы на сервере Win2k3 Std SP1, являющемся всем сразу -- терминал+AD. Что характерно, происходят по большей части вечером около 18-19 часов, когда основная нагрузка спадает. Возможная проблема -- установка нескольких сетевых принтеров HP3050 локально на сервере через Tcp/ip, но удаление их и драйверов не помогло.
Анализ дамп-файлов (последний, коррупт):
Цитата:
Цитата:
И ещё полный вариант прошлого падения:
Цитата:
Заранее спасибо за любую помощь.
Анализ дамп-файлов (последний, коррупт):
Цитата:
SESSION_HAS_VALID_POOL_ON_EXIT (ab)
Caused by a session driver not freeing its pool allocations prior to a
session unload. This indicates a bug in win32k.sys, atmfd.dll,
rdpdd.dll or a video driver
Цитата:
DEFAULT_BUCKET_ID: DRIVER_FAULT
BUGCHECK_STR: 0xAB
STACK_TEXT:
Page 273726 too large to be in the dump file.
GetContextState failed, 0x80004002
Unable to get current machine context, HRESULT 0x80004002
STACK_COMMAND: kb
SYMBOL_NAME: ANALYSIS_INCONCLUSIVE
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Unknown_Module
IMAGE_NAME: Unknown_Image
DEBUG_FLR_IMAGE_TIMESTAMP: 0
BUCKET_ID: CORRUPT_MODULELIST
Followup: MachineOwner
И ещё полный вариант прошлого падения:
Цитата:
Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [D:\Debugging\Mini100509-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: srv*c:\symbols *http://msdl.microsoft.com/download/symbols
Executable search path is: srv*c:\symbols *http://msdl.microsoft.com/download/symbols
Windows Server 2003 Kernel Version 3790 (Service Pack 1) MP (4 procs) Free x86 compatible
Product: LanManNt, suite: TerminalServer
Built by: 3790.srv03_sp1_rtm.050324-1447
Machine Name:
Kernel base = 0x80800000 PsLoadedModuleList = 0x808a6ea8
Debug session time: Mon Oct 5 16:35:45.953 2009 (GMT+4)
System Uptime: 58 days 4:12:07.593
Loading Kernel Symbols
...............................................................
................................................
Loading User Symbols
Loading unloaded module list
........................................
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck AB, {8, c0, 0, 4}
Probably caused by : memory_corruption ( nt!MiCheckSessionPoolAllocations+107 )
Followup: MachineOwner
---------
1: kd> kd: Reading initial command '!analyze -v; q'
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SESSION_HAS_VALID_POOL_ON_EXIT (ab)
Caused by a session driver not freeing its pool allocations prior to a
session unload. This indicates a bug in win32k.sys, atmfd.dll,
rdpdd.dll or a video driver.
Arguments:
Arg1: 00000008, session ID
Arg2: 000000c0, number of paged pool bytes that are leaking
Arg3: 00000000, number of nonpaged pool bytes that are leaking
Arg4: 00000004, total number of paged and nonpaged allocations that are leaking.
nonpaged allocations are in the upper half of this word,
paged allocations are in the lower half of this word.
Debugging Details:
------------------
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: DRIVER_FAULT_SERVER_MINIDUMP
BUGCHECK_STR: 0xAB
PROCESS_NAME: csrss.exe
CURRENT_IRQL: 0
LAST_CONTROL_TRANSFER: from 8092ea6f to 80827451
STACK_TEXT:
ee465b88 8092ea6f 000000ab 00000008 000000c0 nt!KeBugCheckEx+0x1b
ee465bcc 809ab017 873b8020 873b8020 00000000 nt!MiCheckSessionPoolAllocations+0x107
ee465c4c 8084c1a7 873b8020 00000000 83890348 nt!MiDereferenceSessionFinal+0x183
ee465c68 8094b539 873b8020 832faa10 00000000 nt!MmCleanProcessAddressSpace+0x6b
ee465cf0 8094b5b7 00000000 ee465d4c 8082d8b8 nt!PspExitThread+0x5f1
ee465cfc 8082d8b8 832faa10 ee465d48 ee465d3c nt!PsExitSpecialApc+0x1d
ee465d4c 80888cd4 00000001 00000000 ee465d64 nt!KiDeliverApc+0x1ae
ee465d4c 7c93ed54 00000001 00000000 ee465d64 nt!KiServiceExit+0x56
WARNING: Frame IP not in any known module. Following frames may be wrong.
0061fff4 00000000 00000000 00000000 00000000 0x7c93ed54
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!MiCheckSessionPoolAllocations+107
8092ea6f 5f pop edi
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: nt!MiCheckSessionPoolAllocations+107
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
DEBUG_FLR_IMAGE_TIMESTAMP: 42435b14
IMAGE_NAME: memory_corruption
FAILURE_BUCKET_ID: 0xAB_nt!MiCheckSessionPoolAllocations+107
BUCKET_ID: 0xAB_nt!MiCheckSessionPoolAllocations+107
Followup: MachineOwner
---------
quit:
Заранее спасибо за любую помощь.