Hi all, I have a lot of problems with a Windows 2003 Small Business Server. Suddently it just stops and the only thing i can find in the eventlog is: System error - Event: 1003. Description: Error code 0000000a, parameter1 00000016, parameter2 0000001b, parameter3 00000000, parameter4 8083fc20. For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp. Bytes data: 0000: 53 79 73 74 65 6d 20 45 System E 0008: 72 72 6f 72 20 20 45 72 rror Er 0010: 72 6f 72 20 63 6f 64 65 ror code 0018: 20 30 30 30 30 30 30 30 0000000 0020: 61 20 20 50 61 72 61 6d a Param 0028: 65 74 65 72 73 20 30 30 eters 00 0030: 30 30 30 30 31 36 2c 20 000016, 0038: 30 30 30 30 30 30 31 62 0000001b 0040: 2c 20 30 30 30 30 30 30 , 000000 0048: 30 30 2c 20 38 30 38 33 00, 8083 0050: 66 63 32 30 fc20 Sadly i don't know what to do. The server is a HP ProLiant ML350 G4. Hope that you're more into stop errors than i am. Thanks in advance.
Debugging Now i just tried debugging the minidump. Can anybody see what seems to be the problem? Opened log file 'c:\debuglog.txt' 1: kd> .sympath srv*c:\symbols*http://msdl.microsoft.com/download/symbols Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbols 1: kd> .reload;!analyze -v;r;kv;lmnt;.logclose;q Loading Kernel Symbols ................................................................................................................................. Loading User Symbols Loading unloaded module list .. ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* IRQL_NOT_LESS_OR_EQUAL (a) An attempt was made to access a pageable (or completely invalid) address at an interrupt request level (IRQL) that is too high. This is usually caused by drivers using improper addresses. If a kernel debugger is available get the stack backtrace. Arguments: Arg1: 00000016, memory referenced Arg2: 0000001b, IRQL Arg3: 00000000, value 0 = read operation, 1 = write operation Arg4: 8083fc20, address which referenced memory Debugging Details: ------------------ Unable to load image \??\C:\WINDOWS\system32\Drivers\NETFLTDI.SYS, Win32 error 2 *** WARNING: Unable to verify timestamp for NETFLTDI.SYS *** ERROR: Module load completed but symbols could not be loaded for NETFLTDI.SYS READ_ADDRESS: 00000016 CURRENT_IRQL: 1b FAULTING_IP: nt!KeSetEvent+6f 8083fc20 385816 cmp byte ptr [eax+16h],bl CUSTOMER_CRASH_COUNT: 2 DEFAULT_BUCKET_ID: DRIVER_FAULT_SERVER_MINIDUMP BUGCHECK_STR: 0xA PROCESS_NAME: System TRAP_FRAME: bac4ab48 -- (.trap ffffffffbac4ab48) .trap ffffffffbac4ab48 ErrCode = 00000000 eax=00000000 ebx=00000001 ecx=808b9380 edx=00000000 esi=8a1f3644 edi=8a1f364c eip=8083fc20 esp=bac4abbc ebp=bac4abcc iopl=0 nv up ei pl nz na pe nc cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010206 nt!KeSetEvent+0x6f: 8083fc20 385816 cmp byte ptr [eax+16h],bl ds:0023:00000016=?? .trap Resetting default scope LAST_CONTROL_TRANSFER: from 8083fc20 to 80837ed5 STACK_TEXT: bac4ab48 8083fc20 badb0d00 00000000 bac4ab70 nt!KiTrap0E+0x2a7 bac4abcc b9342fd9 001f3644 00000000 00000000 nt!KeSetEvent+0x6f bac4abf0 b933fe07 8a328b90 c000023a 00000000 tcpip!TCPDataRequestComplete+0x93 bac4ac20 b9335fda 8a328b90 8a1f365c 8a328c40 tcpip!TCPSendData+0xa6 bac4ac3c 8083f9d0 89c26388 8a328b90 8a328c64 tcpip!TCPDispatchInternalDeviceControl+0x19a bac4ac50 f76595e1 888e5340 89a786d0 8a328c48 nt!IofCallDriver+0x45 WARNING: Stack unwind information not available. Following frames may be wrong. bac4ac64 f765a398 8a328b90 89cfb548 f765a11a NETFLTDI+0x25e1 bac4ac88 f765e15b 8a328b90 8a328c48 89cfb548 NETFLTDI+0x3398 bac4aca8 8083f9d0 89cfb490 8a328b90 00000048 NETFLTDI+0x715b bac4acbc b92fd7bb 895213d0 88e236f0 00000000 nt!IofCallDriver+0x45 bac4acd8 b9303916 8a328b90 00000000 00000048 netbt!TdiSend+0x102 bac4ad28 b930051b 88e236d0 00000000 00000000 netbt!SessionStartupContinue+0x436 bac4ad44 8083ec8a 89a746d8 888bee28 889c1008 netbt!TcpConnectComplete+0x43 bac4ad74 f76591e3 00000000 89a7a780 00000000 nt!IopfCompleteRequest+0xcd bac4adac 8092ccff 00000000 00000000 00000000 NETFLTDI+0x21e3 bac4addc 80841a96 f7658904 00000000 00000000 nt!PspSystemThreadStartup+0x2e 00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x16 STACK_COMMAND: kb FOLLOWUP_IP: NETFLTDI+25e1 f76595e1 ?? ??? SYMBOL_STACK_INDEX: 6 SYMBOL_NAME: NETFLTDI+25e1 FOLLOWUP_NAME: MachineOwner MODULE_NAME: NETFLTDI IMAGE_NAME: NETFLTDI.SYS DEBUG_FLR_IMAGE_TIMESTAMP: 43ec46d4 FAILURE_BUCKET_ID: 0xA_NETFLTDI+25e1 BUCKET_ID: 0xA_NETFLTDI+25e1 Followup: MachineOwner --------- eax=f772f13c ebx=0000001b ecx=00000001 edx=40000000 esi=f772f120 edi=00000016 eip=80837ed5 esp=bac4ab30 ebp=bac4ab48 iopl=0 nv up ei ng nz na pe nc cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00000286 nt!KiTrap0E+0x2a7: 80837ed5 833d00ee8a8000 cmp dword ptr [nt!KiFreezeFlag (808aee00)],0 ds:0023:808aee00=???????? ChildEBP RetAddr Args to Child bac4ab48 8083fc20 badb0d00 00000000 bac4ab70 nt!KiTrap0E+0x2a7 (FPO: [0,0] TrapFrame @ bac4ab48) bac4abcc b9342fd9 001f3644 00000000 00000000 nt!KeSetEvent+0x6f (FPO: [Non-Fpo]) bac4abf0 b933fe07 8a328b90 c000023a 00000000 tcpip!TCPDataRequestComplete+0x93 (FPO: [Non-Fpo]) bac4ac20 b9335fda 8a328b90 8a1f365c 8a328c40 tcpip!TCPSendData+0xa6 (FPO: [Non-Fpo]) bac4ac3c 8083f9d0 89c26388 8a328b90 8a328c64 tcpip!TCPDispatchInternalDeviceControl+0x19a (FPO: [Non-Fpo]) bac4ac50 f76595e1 888e5340 89a786d0 8a328c48 nt!IofCallDriver+0x45 (FPO: [Non-Fpo]) WARNING: Stack unwind information not available. Following frames may be wrong. bac4ac64 f765a398 8a328b90 89cfb548 f765a11a NETFLTDI+0x25e1 bac4ac88 f765e15b 8a328b90 8a328c48 89cfb548 NETFLTDI+0x3398 bac4aca8 8083f9d0 89cfb490 8a328b90 00000048 NETFLTDI+0x715b bac4acbc b92fd7bb 895213d0 88e236f0 00000000 nt!IofCallDriver+0x45 (FPO: [Non-Fpo]) bac4acd8 b9303916 8a328b90 00000000 00000048 netbt!TdiSend+0x102 (FPO: [Non-Fpo]) bac4ad28 b930051b 88e236d0 00000000 00000000 netbt!SessionStartupContinue+0x436 (FPO: [Non-Fpo]) bac4ad44 8083ec8a 89a746d8 888bee28 889c1008 netbt!TcpConnectComplete+0x43 (FPO: [Non-Fpo]) bac4ad74 f76591e3 00000000 89a7a780 00000000 nt!IopfCompleteRequest+0xcd (FPO: [Non-Fpo]) bac4adac 8092ccff 00000000 00000000 00000000 NETFLTDI+0x21e3 bac4addc 80841a96 f7658904 00000000 00000000 nt!PspSystemThreadStartup+0x2e (FPO: [Non-Fpo]) 00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x16 start end module name 80800000 80a75000 nt ntkrnlmp.exe Fri Mar 25 01:42:08 2005 (42435E60) 80a75000 80aa1000 hal halaacpi.dll Fri Mar 25 01:28:37 2005 (42435B35) b6a4c000 b6a79000 RDPWD RDPWD.SYS Wed Jun 15 17:33:14 2005 (42B04A3A) b6af1000 b6afc000 TDTCP TDTCP.SYS Fri Mar 25 01:27:15 2005 (42435AE3) b6c31000 b6c46f80 av5flt av5flt.sys Mon Oct 17 12:28:05 2005 (43537CB5) b78d1000 b78fb000 Fastfat Fastfat.SYS Fri Mar 25 01:40:20 2005 (42435DF4) b7a13000 b7a3af00 PavProc PavProc.sys Thu Jan 08 08:54:16 2004 (3FFD0CA8) b7fc7000 b8017000 HTTP HTTP.sys Fri Mar 25 01:40:36 2005 (42435E04) b835f000 b83cb000 srv srv.sys Fri Sep 01 16:32:26 2006 (44F8447A) b83f3000 b8427000 mrxdav mrxdav.sys Fri Mar 25 01:30:11 2005 (42435B93) b85ef000 b85f1c00 IPCap IPCap.sys Thu May 19 06:00:42 2005 (428C0F6A) b8747000 b8758700 PavDrv51 PavDrv51.sys Mon Jun 13 16:51:39 2005 (42AD9D7B) b8793000 b87c2d80 exifs exifs.sys Fri Apr 02 09:08:21 2004 (406D1165) b88db000 b88e0e80 npaflt npaflt.sys Mon Jan 09 11:55:15 2006 (43C24113) b891b000 b8922000 parvdm parvdm.sys Tue Mar 25 08:03:49 2003 (3E7FFF55) b8953000 b8968000 Cdfs Cdfs.SYS Fri Mar 25 01:40:55 2005 (42435E17) b909f000 b90b0000 Fips Fips.SYS Fri Mar 25 01:40:33 2005 (42435E01) b90d8000 b9100a80 IDSFLT IDSFLT.SYS Thu Jan 05 12:33:10 2006 (43BD03F6) b9101000 b9181000 mrxsmb mrxsmb.sys Mon May 08 19:18:45 2006 (445F7D75) b9181000 b91ba000 rdbss rdbss.sys Mon May 08 19:18:53 2006 (445F7D7D) b91e2000 b920c000 afd afd.sys unavailable (00000000) b92d4000 b92fb000 ipnat ipnat.sys Fri Mar 25 01:34:00 2005 (42435C78) b92fb000 b932c000 netbt netbt.sys Fri Mar 25 01:40:31 2005 (42435DFF) b932c000 b938d000 tcpip tcpip.sys Wed May 24 03:02:22 2006 (4473B09E) b938d000 b93a6000 ipsec ipsec.sys Fri Mar 25 01:40:49 2005 (42435E11) ba72c000 ba740000 usbhub usbhub.sys Fri Mar 25 01:30:46 2005 (42435BB6) ba779000 ba77b280 fnetmon fnetmon.SYS Thu Jul 14 14:22:04 2005 (42D658EC) ba781000 ba7975a0 MMP2000 MMP2000.sys Fri Nov 19 10:44:21 2004 (419DC075) ba798000 ba7d8000 update update.sys Fri Mar 25 01:40:27 2005 (42435DFB) ba858000 ba862000 Dxapi Dxapi.sys Tue Mar 25 08:06:01 2003 (3E7FFFD9) ba868000 ba872000 dump_diskdump dump_diskdump.sys Fri Mar 25 01:28:56 2005 (42435B48) ba878000 ba8af000 rdpdr rdpdr.sys Fri Mar 25 01:30:20 2005 (42435B9C) ba8af000 ba8c2000 raspptp raspptp.sys Fri Mar 25 01:40:43 2005 (42435E0B) ba8c2000 ba8dc000 ndiswan ndiswan.sys Fri Mar 25 01:40:46 2005 (42435E0E) ba8dc000 ba8f1000 rasl2tp rasl2tp.sys Fri Mar 25 01:40:29 2005 (42435DFD) ba8f1000 ba919000 ks ks.sys Fri Mar 25 01:41:03 2005 (42435E1F) ba919000 ba92d000 redbook redbook.sys Fri Mar 25 01:28:46 2005 Unloaded modules: f7667000 f7675000 imapi.sys Timestamp: unavailable (00000000) Checksum: 00000000 f77d7000 f77df000 Sfloppy.SYS Timestamp: unavailable (00000000) Checksum: 00000000 Closing open log file c:\debuglog.txt