K
Kurtis Rich
I get the following error on event log. This happens around the same time every other week/month. This is a VM with Server 2012 R2. It states a disk hardware error but I'm also curious to why it shows that since it's a VM. The host's hardware shows healthy as well.
"The computer has rebooted from a Bugcheck the bugcheck was 0x0000007a"
Dump file:
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: srv*
Executable search path is:
Windows 8.1 Kernel Version 9600 MP (24 procs) Free x64
Product: Server, suite: TerminalServer SingleUserTS
Built by: 9600.19724.amd64fre.winblue_ltsb_escrow.200519-1914
Machine Name:
Kernel base = 0xfffff802`da47e000 PsLoadedModuleList = 0xfffff802`da7435f0
Debug session time: Sat Jul 11 01:00:41.250 2020 (UTC - 4:00)
System Uptime: 8 days 23:58:27.484
Loading Kernel Symbols
...............................................................
................................................................
...
Loading User Symbols
Loading unloaded module list
......
For analysis of this file, run !analyze -v
16: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KERNEL_DATA_INPAGE_ERROR (7a)
The requested page of kernel data could not be read in. Typically caused by
a bad block in the paging file or disk controller error. Also see
KERNEL_STACK_INPAGE_ERROR.
If the error status is 0xC000000E, 0xC000009C, 0xC000009D or 0xC0000185,
it means the disk subsystem has experienced a failure.
If the error status is 0xC000009A, then it means the request failed because
a filesystem failed to make forward progress.
Arguments:
Arg1: fffff6e8009bd0e8, lock type that was held (value 1,2,3, or PTE address)
Arg2: ffffffffc0000185, error status (normally i/o status code)
Arg3: 000000099a350be0, current process (virtual address for lock type 3, or PTE)
Arg4: ffffd00137a1d000, virtual address that could not be in-paged (or PTE contents if arg1 is a PTE address)
Debugging Details:
------------------
fffff802da710e58: Unable to get Flags value from nt!KdVersionBlock
GetUlongPtrFromAddress: unable to read from fffff802da7cd308
KEY_VALUES_STRING: 1
Key : Analysis.CPU.Sec
Value: 3
Key : Analysis.DebugAnalysisProvider.CPP
Value: Create: 8007007e on LRCSRVSEC
Key : Analysis.DebugData
Value: CreateObject
Key : Analysis.DebugModel
Value: CreateObject
Key : Analysis.Elapsed.Sec
Value: 3
Key : Analysis.Memory.CommitPeak.Mb
Value: 66
Key : Analysis.System
Value: CreateObject
VIRTUAL_MACHINE: HyperV
BUGCHECK_CODE: 7a
BUGCHECK_P1: fffff6e8009bd0e8
BUGCHECK_P2: ffffffffc0000185
BUGCHECK_P3: 99a350be0
BUGCHECK_P4: ffffd00137a1d000
ERROR_CODE: (NTSTATUS) 0xc0000185 - The I/O device reported an I/O error.
DISK_HARDWARE_ERROR: There was error with disk hardware
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System
STACK_TEXT:
ffffd001`35367748 fffff802`da566072 : 00000000`0000007a fffff6e8`009bd0e8 ffffffff`c0000185 00000009`9a350be0 : nt!KeBugCheckEx
ffffd001`35367750 fffff802`da6501a0 : 00000000`00000002 ffffd001`35367878 fffff802`da7c5ec0 fffff802`00000000 : nt!MiWaitForInPageComplete+0x722
ffffd001`35367840 fffff802`da4c9492 : 00000000`c0033333 00000000`00000000 ffffe801`2bac4082 ffffd001`37a1d000 : nt!MiIssueHardFault+0x330
ffffd001`353678c0 fffff802`da5645cd : fffff6e8`009bd0e8 fffff802`da415600 fffff802`da47e000 ffffd001`35367a58 : nt!MmAccessFault+0x6f2
ffffd001`353679c0 fffff802`da5a2f23 : ffffe801`2bac4158 00000000`00000080 ffffe801`2bad84d8 ffffe801`00000000 : nt!MiInPageSingleKernelStack+0x2b9
ffffd001`35367ba0 fffff802`da541ab2 : ffffd001`34dc0180 ffffe001`44421640 90000035`25e8cf8b fffff802`da5c16b3 : nt!KeSwapProcessOrStack+0xb3
ffffd001`35367c00 fffff802`da5c5f66 : ffffd001`34dc0180 ffffe001`44760040 ffffd001`34dd0880 00000001`87b274c1 : nt!PspSystemThreadStartup+0x18a
ffffd001`35367c60 00000000`00000000 : ffffd001`35368000 ffffd001`35362000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x16
SYMBOL_NAME: nt!MiWaitForInPageComplete+722
MODULE_NAME: nt
IMAGE_VERSION: 6.3.9600.19724
STACK_COMMAND: .thread ; .cxr ; kb
IMAGE_NAME: memory_corruption
BUCKET_ID_FUNC_OFFSET: 722
FAILURE_BUCKET_ID: 0x7a_c0000185_DUMP_STORVSCDUMP_VMBKMCL_nt!MiWaitForInPageComplete
OS_VERSION: 8.1.9600.19724
BUILDLAB_STR: winblue_ltsb_escrow
OSPLATFORM_TYPE: x64
OSNAME: Windows 8.1
FAILURE_ID_HASH: {43b31b2e-9de6-5ab1-e5c2-c25ab707dd23}
Followup: MachineOwner
---------
Browse full module list
start end module name
fffff802`da47e000 fffff802`dabfb000 nt (pdb symbols) C:\ProgramData\dbg\sym\ntkrnlmp.pdb\FD109C84C7F94AA48CA68F2B2DA36CE31\ntkrnlmp.pdb
Loaded symbol image file: ntkrnlmp.exe
Mapped memory image file: C:\ProgramData\dbg\sym\ntoskrnl.exe\5EC50C3D77d000\ntoskrnl.exe
Image path: ntkrnlmp.exe
Image name: ntkrnlmp.exe
Browse all global symbols functions data
Timestamp: Wed May 20 06:53:49 2020 (5EC50C3D)
CheckSum: 00707F19
ImageSize: 0077D000
File version: 6.3.9600.19724
Product version: 6.3.9600.19724
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 1.0 App
File date: 00000000.00000000
Translations: 0409.04b0
Information from resource tables:
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: ntkrnlmp.exe
OriginalFilename: ntkrnlmp.exe
ProductVersion: 6.3.9600.19724
FileVersion: 6.3.9600.19724 (winblue_ltsb_escrow.200519-1914)
FileDescription: NT Kernel & System
LegalCopyright: © Microsoft Corporation. All rights reserved.
Continue reading...
"The computer has rebooted from a Bugcheck the bugcheck was 0x0000007a"
Dump file:
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: srv*
Executable search path is:
Windows 8.1 Kernel Version 9600 MP (24 procs) Free x64
Product: Server, suite: TerminalServer SingleUserTS
Built by: 9600.19724.amd64fre.winblue_ltsb_escrow.200519-1914
Machine Name:
Kernel base = 0xfffff802`da47e000 PsLoadedModuleList = 0xfffff802`da7435f0
Debug session time: Sat Jul 11 01:00:41.250 2020 (UTC - 4:00)
System Uptime: 8 days 23:58:27.484
Loading Kernel Symbols
...............................................................
................................................................
...
Loading User Symbols
Loading unloaded module list
......
For analysis of this file, run !analyze -v
16: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KERNEL_DATA_INPAGE_ERROR (7a)
The requested page of kernel data could not be read in. Typically caused by
a bad block in the paging file or disk controller error. Also see
KERNEL_STACK_INPAGE_ERROR.
If the error status is 0xC000000E, 0xC000009C, 0xC000009D or 0xC0000185,
it means the disk subsystem has experienced a failure.
If the error status is 0xC000009A, then it means the request failed because
a filesystem failed to make forward progress.
Arguments:
Arg1: fffff6e8009bd0e8, lock type that was held (value 1,2,3, or PTE address)
Arg2: ffffffffc0000185, error status (normally i/o status code)
Arg3: 000000099a350be0, current process (virtual address for lock type 3, or PTE)
Arg4: ffffd00137a1d000, virtual address that could not be in-paged (or PTE contents if arg1 is a PTE address)
Debugging Details:
------------------
fffff802da710e58: Unable to get Flags value from nt!KdVersionBlock
GetUlongPtrFromAddress: unable to read from fffff802da7cd308
KEY_VALUES_STRING: 1
Key : Analysis.CPU.Sec
Value: 3
Key : Analysis.DebugAnalysisProvider.CPP
Value: Create: 8007007e on LRCSRVSEC
Key : Analysis.DebugData
Value: CreateObject
Key : Analysis.DebugModel
Value: CreateObject
Key : Analysis.Elapsed.Sec
Value: 3
Key : Analysis.Memory.CommitPeak.Mb
Value: 66
Key : Analysis.System
Value: CreateObject
VIRTUAL_MACHINE: HyperV
BUGCHECK_CODE: 7a
BUGCHECK_P1: fffff6e8009bd0e8
BUGCHECK_P2: ffffffffc0000185
BUGCHECK_P3: 99a350be0
BUGCHECK_P4: ffffd00137a1d000
ERROR_CODE: (NTSTATUS) 0xc0000185 - The I/O device reported an I/O error.
DISK_HARDWARE_ERROR: There was error with disk hardware
CUSTOMER_CRASH_COUNT: 1
PROCESS_NAME: System
STACK_TEXT:
ffffd001`35367748 fffff802`da566072 : 00000000`0000007a fffff6e8`009bd0e8 ffffffff`c0000185 00000009`9a350be0 : nt!KeBugCheckEx
ffffd001`35367750 fffff802`da6501a0 : 00000000`00000002 ffffd001`35367878 fffff802`da7c5ec0 fffff802`00000000 : nt!MiWaitForInPageComplete+0x722
ffffd001`35367840 fffff802`da4c9492 : 00000000`c0033333 00000000`00000000 ffffe801`2bac4082 ffffd001`37a1d000 : nt!MiIssueHardFault+0x330
ffffd001`353678c0 fffff802`da5645cd : fffff6e8`009bd0e8 fffff802`da415600 fffff802`da47e000 ffffd001`35367a58 : nt!MmAccessFault+0x6f2
ffffd001`353679c0 fffff802`da5a2f23 : ffffe801`2bac4158 00000000`00000080 ffffe801`2bad84d8 ffffe801`00000000 : nt!MiInPageSingleKernelStack+0x2b9
ffffd001`35367ba0 fffff802`da541ab2 : ffffd001`34dc0180 ffffe001`44421640 90000035`25e8cf8b fffff802`da5c16b3 : nt!KeSwapProcessOrStack+0xb3
ffffd001`35367c00 fffff802`da5c5f66 : ffffd001`34dc0180 ffffe001`44760040 ffffd001`34dd0880 00000001`87b274c1 : nt!PspSystemThreadStartup+0x18a
ffffd001`35367c60 00000000`00000000 : ffffd001`35368000 ffffd001`35362000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x16
SYMBOL_NAME: nt!MiWaitForInPageComplete+722
MODULE_NAME: nt
IMAGE_VERSION: 6.3.9600.19724
STACK_COMMAND: .thread ; .cxr ; kb
IMAGE_NAME: memory_corruption
BUCKET_ID_FUNC_OFFSET: 722
FAILURE_BUCKET_ID: 0x7a_c0000185_DUMP_STORVSCDUMP_VMBKMCL_nt!MiWaitForInPageComplete
OS_VERSION: 8.1.9600.19724
BUILDLAB_STR: winblue_ltsb_escrow
OSPLATFORM_TYPE: x64
OSNAME: Windows 8.1
FAILURE_ID_HASH: {43b31b2e-9de6-5ab1-e5c2-c25ab707dd23}
Followup: MachineOwner
---------
Browse full module list
start end module name
fffff802`da47e000 fffff802`dabfb000 nt (pdb symbols) C:\ProgramData\dbg\sym\ntkrnlmp.pdb\FD109C84C7F94AA48CA68F2B2DA36CE31\ntkrnlmp.pdb
Loaded symbol image file: ntkrnlmp.exe
Mapped memory image file: C:\ProgramData\dbg\sym\ntoskrnl.exe\5EC50C3D77d000\ntoskrnl.exe
Image path: ntkrnlmp.exe
Image name: ntkrnlmp.exe
Browse all global symbols functions data
Timestamp: Wed May 20 06:53:49 2020 (5EC50C3D)
CheckSum: 00707F19
ImageSize: 0077D000
File version: 6.3.9600.19724
Product version: 6.3.9600.19724
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 1.0 App
File date: 00000000.00000000
Translations: 0409.04b0
Information from resource tables:
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: ntkrnlmp.exe
OriginalFilename: ntkrnlmp.exe
ProductVersion: 6.3.9600.19724
FileVersion: 6.3.9600.19724 (winblue_ltsb_escrow.200519-1914)
FileDescription: NT Kernel & System
LegalCopyright: © Microsoft Corporation. All rights reserved.
Continue reading...