Y
YongyuthJeenbanjob
Dear all expert,
Please help me to analyse BSOD : BugCheck F4, {3, fffffa801e4d1b00, fffffa801e4d1de0, fffff80001fa80e0} , Probably caused by : csrss.exe as below details.
- Find the root cause. What is problem?
- Solution, How to fix.
Thank you in advance.
*************************************************************************************************************
Windows Server 2008 R2 Standard Service Pack 1
64-Bits
**************************************************************************************************************
Microsoft (R) Windows Debugger Version 6.3.9600.17336 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\PublicShare\MEMORYDUMP_10.4.81.138\102519-17312-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
************* Symbol Path validation summary **************
Response Time (ms) Location
Deferred SRV*C:\SymCache*Symbol information
Symbol search path is: SRV*C:\SymCache*Symbol information
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: Server, suite: TerminalServer
Built by: 7601.24093.amd64fre.win7sp1_ldr_escrow.180327-2230
Machine Name:
Kernel base = 0xfffff800`01c49000 PsLoadedModuleList = 0xfffff800`01e88c90
Debug session time: Fri Oct 25 10:58:11.191 2019 (UTC + 7:00)
System Uptime: 120 days 13:48:44.517
Loading Kernel Symbols
...............................................................
................................................................
...........
Loading User Symbols
Loading unloaded module list
.....
ERROR: FindPlugIns 80070015
ERROR: Some plugins may not be available [80070015]
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck F4, {3, fffffa801e4d1b00, fffffa801e4d1de0, fffff80001fa80e0}
----- ETW minidump data unavailable-----
Probably caused by : csrss.exe
Followup: MachineOwner
---------
3: kd> !analyze -v
ERROR: FindPlugIns 80070015
ERROR: Some plugins may not be available [80070015]
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
CRITICAL_OBJECT_TERMINATION (f4)
A process or thread crucial to system operation has unexpectedly exited or been
terminated.
Several processes and threads are necessary for the operation of the
system; when they are terminated (for any reason), the system can no
longer function.
Arguments:
Arg1: 0000000000000003, Process
Arg2: fffffa801e4d1b00, Terminating object
Arg3: fffffa801e4d1de0, Process image file name
Arg4: fffff80001fa80e0, Explanatory message (ascii)
Debugging Details:
------------------
----- ETW minidump data unavailable-----
PROCESS_OBJECT: fffffa801e4d1b00
IMAGE_NAME: csrss.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MODULE_NAME: csrss
FAULTING_MODULE: 0000000000000000
PROCESS_NAME: WmiPrvSE.exe
BUGCHECK_STR: 0xF4_WmiPrvSE.exe
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT_SERVER
CURRENT_IRQL: 0
ANALYSIS_VERSION: 6.3.9600.17336 (debuggers(dbg).150226-1500) amd64fre
LAST_CONTROL_TRANSFER: from fffff80002014912 to fffff80001ced4a0
STACK_TEXT:
fffff880`0b28bb18 fffff800`02014912 : 00000000`000000f4 00000000`00000003 fffffa80`1e4d1b00 fffffa80`****x92
fffff880`0b28bb60 fffff800`020dd404 : 00000000`00000001 00000000`000002f0 fffffa80`1e4d1b00 fffffa80`00000008 : nt! ?? ::NNGAKEG****x284
fffff880`0b28bc20 00000000`77ce9b6a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0104e028 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77ce9b6a
STACK_COMMAND: kb
FOLLOWUP_NAME: MachineOwner
IMAGE_VERSION:
FAILURE_BUCKET_ID: X64_0xF4_WmiPrvSE.exe_IMAGE_csrss.exe
BUCKET_ID: X64_0xF4_WmiPrvSE.exe_IMAGE_csrss.exe
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:x64_0xf4_wmiprvse.exe_image_csrss.exe
FAILURE_ID_HASH: {e7a66c29-612b-cafc-e198-d096f9807081}
Followup: MachineOwner
---------
3: kd> !process fffffa801e4d1b00 3
GetPointerFromAddress: unable to read from fffff80001eec000
PROCESS fffffa801e4d1b00
SessionId: none Cid: 19e0 Peb: 7fffffd6000 ParentCid: 1834
DirBase: 4c706000 ObjectTable: fffff8a007391db0 HandleCount: <Data Not Accessible>
Image: csrss.exe
VadRoot fffffa801e60b160 Vads 80 Clone 0 Private 455. Modified 43059. Locked 0.
DeviceMap fffff8a000008a70
Token fffff8a011aec3e0
ReadMemory error: Cannot get nt!KeMaximumIncrement value.
fffff78000000000: Unable to get shared data
ElapsedTime 00:00:00.000
UserTime 00:00:00.000
KernelTime 00:00:00.000
QuotaPoolUsage[PagedPool] 256376
QuotaPoolUsage[NonPagedPool] 9736
Working Set Sizes (now,min,max) (2051, 50, 345) (8204KB, 200KB, 1380KB)
PeakWorkingSetSize 2250
VirtualSize 112 Mb
PeakVirtualSize 130 Mb
PageFaultCount 53155
MemoryPriority BACKGROUND
BasePriority 13
CommitCharge 610
*** Error in reading nt!_ETHREAD @ fffffa801e373930
3: kd> lmvm csrss
start end module name
********************************************************************************************************************
Continue reading...
Please help me to analyse BSOD : BugCheck F4, {3, fffffa801e4d1b00, fffffa801e4d1de0, fffff80001fa80e0} , Probably caused by : csrss.exe as below details.
- Find the root cause. What is problem?
- Solution, How to fix.
Thank you in advance.
*************************************************************************************************************
Windows Server 2008 R2 Standard Service Pack 1
64-Bits
**************************************************************************************************************
Microsoft (R) Windows Debugger Version 6.3.9600.17336 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\PublicShare\MEMORYDUMP_10.4.81.138\102519-17312-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
************* Symbol Path validation summary **************
Response Time (ms) Location
Deferred SRV*C:\SymCache*Symbol information
Symbol search path is: SRV*C:\SymCache*Symbol information
Executable search path is:
Windows 7 Kernel Version 7601 (Service Pack 1) MP (4 procs) Free x64
Product: Server, suite: TerminalServer
Built by: 7601.24093.amd64fre.win7sp1_ldr_escrow.180327-2230
Machine Name:
Kernel base = 0xfffff800`01c49000 PsLoadedModuleList = 0xfffff800`01e88c90
Debug session time: Fri Oct 25 10:58:11.191 2019 (UTC + 7:00)
System Uptime: 120 days 13:48:44.517
Loading Kernel Symbols
...............................................................
................................................................
...........
Loading User Symbols
Loading unloaded module list
.....
ERROR: FindPlugIns 80070015
ERROR: Some plugins may not be available [80070015]
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck F4, {3, fffffa801e4d1b00, fffffa801e4d1de0, fffff80001fa80e0}
----- ETW minidump data unavailable-----
Probably caused by : csrss.exe
Followup: MachineOwner
---------
3: kd> !analyze -v
ERROR: FindPlugIns 80070015
ERROR: Some plugins may not be available [80070015]
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
CRITICAL_OBJECT_TERMINATION (f4)
A process or thread crucial to system operation has unexpectedly exited or been
terminated.
Several processes and threads are necessary for the operation of the
system; when they are terminated (for any reason), the system can no
longer function.
Arguments:
Arg1: 0000000000000003, Process
Arg2: fffffa801e4d1b00, Terminating object
Arg3: fffffa801e4d1de0, Process image file name
Arg4: fffff80001fa80e0, Explanatory message (ascii)
Debugging Details:
------------------
----- ETW minidump data unavailable-----
PROCESS_OBJECT: fffffa801e4d1b00
IMAGE_NAME: csrss.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 0
MODULE_NAME: csrss
FAULTING_MODULE: 0000000000000000
PROCESS_NAME: WmiPrvSE.exe
BUGCHECK_STR: 0xF4_WmiPrvSE.exe
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT_SERVER
CURRENT_IRQL: 0
ANALYSIS_VERSION: 6.3.9600.17336 (debuggers(dbg).150226-1500) amd64fre
LAST_CONTROL_TRANSFER: from fffff80002014912 to fffff80001ced4a0
STACK_TEXT:
fffff880`0b28bb18 fffff800`02014912 : 00000000`000000f4 00000000`00000003 fffffa80`1e4d1b00 fffffa80`****x92
fffff880`0b28bb60 fffff800`020dd404 : 00000000`00000001 00000000`000002f0 fffffa80`1e4d1b00 fffffa80`00000008 : nt! ?? ::NNGAKEG****x284
fffff880`0b28bc20 00000000`77ce9b6a : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`0104e028 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77ce9b6a
STACK_COMMAND: kb
FOLLOWUP_NAME: MachineOwner
IMAGE_VERSION:
FAILURE_BUCKET_ID: X64_0xF4_WmiPrvSE.exe_IMAGE_csrss.exe
BUCKET_ID: X64_0xF4_WmiPrvSE.exe_IMAGE_csrss.exe
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:x64_0xf4_wmiprvse.exe_image_csrss.exe
FAILURE_ID_HASH: {e7a66c29-612b-cafc-e198-d096f9807081}
Followup: MachineOwner
---------
3: kd> !process fffffa801e4d1b00 3
GetPointerFromAddress: unable to read from fffff80001eec000
PROCESS fffffa801e4d1b00
SessionId: none Cid: 19e0 Peb: 7fffffd6000 ParentCid: 1834
DirBase: 4c706000 ObjectTable: fffff8a007391db0 HandleCount: <Data Not Accessible>
Image: csrss.exe
VadRoot fffffa801e60b160 Vads 80 Clone 0 Private 455. Modified 43059. Locked 0.
DeviceMap fffff8a000008a70
Token fffff8a011aec3e0
ReadMemory error: Cannot get nt!KeMaximumIncrement value.
fffff78000000000: Unable to get shared data
ElapsedTime 00:00:00.000
UserTime 00:00:00.000
KernelTime 00:00:00.000
QuotaPoolUsage[PagedPool] 256376
QuotaPoolUsage[NonPagedPool] 9736
Working Set Sizes (now,min,max) (2051, 50, 345) (8204KB, 200KB, 1380KB)
PeakWorkingSetSize 2250
VirtualSize 112 Mb
PeakVirtualSize 130 Mb
PageFaultCount 53155
MemoryPriority BACKGROUND
BasePriority 13
CommitCharge 610
*** Error in reading nt!_ETHREAD @ fffffa801e373930
3: kd> lmvm csrss
start end module name
********************************************************************************************************************
Continue reading...