Jump to content

Recommended Posts

Posted

Hi all,

 

Been looking at this most of the morning, my PDC BSOD'd this morning but has done it a couple of times in the past, I have had a look through the minidump and taken a look at all the drivers to make sure that none of them have been updated since the first BSOD however they haven't, im at a bit of a dead end now and having a flap as its our only physical DC..

 

If anyone has any ideas I would be eternally thankful!

 

Bug Check String: DRIVER_IRQL_NOT_LESS_OR_EQUAL

Bug Check Code: 0x000000d1

Caused by Driver: rdbss.sys

 

Microsoft ® Windows Debugger Version 6.3.9600.17237 AMD64

Copyright © Microsoft Corporation. All rights reserved.

 

 

Loading Dump File [C:\Users\Desktop\092614-15740-01.dmp]

Mini Kernel Dump File: Only registers and stack trace are available

 

 

************* Symbol Path validation summary **************

Response Time (ms) Location

Deferred SRV*c:\symbols*http://msdl.microsoft.com/download/symbols

Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols

Executable search path is:

Windows 7 Kernel Version 7601 (Service Pack 1) MP (8 procs) Free x64

Product: LanManNt, suite: Enterprise TerminalServer SingleUserTS

Built by: 7601.22616.amd64fre.win7sp1_ldr.140303-2307

Machine Name:

Kernel base = 0xfffff800`01e4a000 PsLoadedModuleList = 0xfffff800`0208e890

Debug session time: Fri Sep 26 08:58:04.985 2014 (UTC + 1:00)

System Uptime: 3 days 22:52:18.000

Loading Kernel Symbols

...............................................................

................................................................

.............................

Loading User Symbols

Loading unloaded module list

.....

*******************************************************************************

* *

* Bugcheck Analysis *

* *

*******************************************************************************

 

Use !analyze -v to get detailed debugging information.

 

BugCheck D1, {30, 2, 0, fffff8800371c5e9}

 

Probably caused by : rdbss.sys ( rdbss!RxTimerDispatch+49 )

 

Followup: MachineOwner

---------

 

0: kd> !analyze -v

*******************************************************************************

* *

* Bugcheck Analysis *

* *

*******************************************************************************

 

DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)

An attempt was made to access a pageable (or completely invalid) address at an

interrupt request level (IRQL) that is too high. This is usually

caused by drivers using improper addresses.

If kernel debugger is available get stack backtrace.

Arguments:

Arg1: 0000000000000030, memory referenced

Arg2: 0000000000000002, IRQL

Arg3: 0000000000000000, value 0 = read operation, 1 = write operation

Arg4: fffff8800371c5e9, address which referenced memory

 

Debugging Details:

------------------

 

 

READ_ADDRESS: GetPointerFromAddress: unable to read from fffff800020f8100

GetUlongFromAddress: unable to read from fffff800020f81c0

0000000000000030 Nonpaged pool

 

CURRENT_IRQL: 2

 

FAULTING_IP:

rdbss!RxTimerDispatch+49

fffff880`0371c5e9 45395830 cmp dword ptr [r8+30h],r11d

 

CUSTOMER_CRASH_COUNT: 1

 

DEFAULT_BUCKET_ID: WIN7_DRIVER_FAULT_SERVER

 

BUGCHECK_STR: 0xD1

 

PROCESS_NAME: System

 

ANALYSIS_VERSION: 6.3.9600.17237 (debuggers(dbg).140716-0327) amd64fre

 

DPC_STACK_BASE: FFFFF8000363CFB0

 

TRAP_FRAME: fffff80003636390 -- (.trap 0xfffff80003636390)

NOTE: The trap frame does not contain all registers.

Some register values may be zeroed or incorrect.

rax=fffff80003636550 rbx=0000000000000000 rcx=fffff88003738a00

rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000

rip=fffff8800371c5e9 rsp=fffff80003636520 rbp=0000000000000000

r8=0000000000000000 r9=fffff880037389b0 r10=0000000000000323

r11=000000000000de56 r12=0000000000000000 r13=0000000000000000

r14=0000000000000000 r15=0000000000000000

iopl=0 nv up ei pl nz na po cy

rdbss!RxTimerDispatch+0x49:

fffff880`0371c5e9 45395830 cmp dword ptr [r8+30h],r11d ds:00000000`00000030=????????

Resetting default scope

 

LAST_CONTROL_TRANSFER: from fffff80001ebdae9 to fffff80001ebe540

 

STACK_TEXT:

fffff800`03636248 fffff800`01ebdae9 : 00000000`0000000a 00000000`00000030 00000000`00000002 00000000`00000000 : nt!KeBugCheckEx

fffff800`03636250 fffff800`01ebc760 : 00000000`ffffffff fffffa80`1461e710 fffff800`020c5a60 fffff800`03636660 : nt!KiBugCheckDispatch+0x69

fffff800`03636390 fffff880`0371c5e9 : fffff800`03636660 fffff880`01020000 00000000`00000001 fffff800`01fb7420 : nt!KiPageFault+0x260

fffff800`03636520 fffff800`01ec925c : 00000000`00000002 fffff800`03636648 00000000`00000002 00000000`00000000 : rdbss!RxTimerDispatch+0x49

fffff800`03636570 fffff800`01ec90f6 : fffffa80`1744a998 fffffa80`1744a998 00000000`00000000 00000000`00000000 : nt!KiProcessTimerDpcTable+0x6c

fffff800`036365e0 fffff800`01ec8fde : 0000031b`348307dc fffff800`03636c58 00000000`014e10c9 fffff800`0203fba8 : nt!KiProcessExpiredTimerList+0xc6

fffff800`03636c30 fffff800`01ec8dc7 : 000000ba`52db24c8 000000ba`014e10c9 000000ba`52db24b4 00000000`000000c9 : nt!KiTimerExpiration+0x1be

fffff800`03636cd0 fffff800`01eb624a : fffff800`0203be80 fffff800`02049cc0 00000000`00000001 fffff800`00000000 : nt!KiRetireDpcList+0x277

fffff800`03636d80 00000000`00000000 : fffff800`03637000 fffff800`03631000 fffff800`03636d40 00000000`00000000 : nt!KiIdleLoop+0x5a

 

 

STACK_COMMAND: kb

 

FOLLOWUP_IP:

rdbss!RxTimerDispatch+49

fffff880`0371c5e9 45395830 cmp dword ptr [r8+30h],r11d

 

SYMBOL_STACK_INDEX: 3

 

SYMBOL_NAME: rdbss!RxTimerDispatch+49

 

FOLLOWUP_NAME: MachineOwner

 

MODULE_NAME: rdbss

 

IMAGE_NAME: rdbss.sys

 

DEBUG_FLR_IMAGE_TIMESTAMP: 50e79603

 

IMAGE_VERSION: 6.1.7601.22210

 

FAILURE_BUCKET_ID: X64_0xD1_rdbss!RxTimerDispatch+49

 

BUCKET_ID: X64_0xD1_rdbss!RxTimerDispatch+49

 

ANALYSIS_SOURCE: KM

 

FAILURE_ID_HASH_STRING: km:x64_0xd1_rdbss!rxtimerdispatch+49

 

FAILURE_ID_HASH: {c5674c2a-abf0-8335-bd73-f6921423a27d}

 

Followup: MachineOwner

---------

 

Posted

Checked back through Windows Updates and nothings pulled down driver wise in the last year, no new hardware, no new software either.

 

After a bit of googling I found a hotfix for the issue reported in the minidump, FIX: Stop error 0X000000D1 in rdbss!RxTimerDispatch occurs on a server that is running Windows 7 Service Pack 1 or Windows Server 2008 R2 Service Pack 1, ive applied this and I guess its just a waiting game now really. I will leave the server doing a RAM check over night regardless, see if it comes back with anything.

 

Thanks for your reply though, its greatly appreciated!

Posted

You have approached this exactly as I would, both with the hotfix and RAM check. My next trick would be to knock together another DC or transfer over the FSMO roles to the (stable?) VM temporarily, as a 2008 R2 domain isn't supported on VMs only.

 

Also look at running chkdsk, removing any USB devices you might have plugged in (beyond a KVM) and removing any old programs or services that aren't needed.

Posted

I do have a secondary DC running on a VM however its incredibly sluggish. However replication is setup between the two.

 

Ive got a chkdsk scheduled this afternoon, hopefully I can hang around until the chkdsk has finished and then set the RAM check off, taken multiple backups of the server and of all my GPOs, just incase!

 

Thanks for the pointers

Posted

Left memtest running for a day and a half, 10 successful runs without any issues on the RAM

Ran SFC and everything fine

Ran CHKDSK and everything fine....

 

I am hoping the hotfix that I installed has addressed the issue,

 

Thanks for all your suggestions guys!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...