************* Preparing the environment for Debugger Extensions Gallery repositories **************
ExtensionRepository : Implicit
UseExperimentalFeatureForNugetShare : true
AllowNugetExeUpdate : true
NonInteractiveNuget : true
AllowNugetMSCredentialProviderInstall : true
AllowParallelInitializationOfLocalRepositories : true
EnableRedirectToV8JsProvider : false
-- Configuring repositories
----> Repository : LocalInstalled, Enabled: true
----> Repository : UserExtensions, Enabled: true
>>>>>>>>>>>>> Preparing the environment for Debugger Extensions Gallery repositories completed, duration 0.000 seconds
************* Waiting for Debugger Extensions Gallery to Initialize **************
>>>>>>>>>>>>> Waiting for Debugger Extensions Gallery to Initialize completed, duration 0.032 seconds
----> Repository : UserExtensions, Enabled: true, Packages count: 0
----> Repository : LocalInstalled, Enabled: true, Packages count: 41
Microsoft (R) Windows Debugger Version 10.0.27553.1004 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\smk\Desktop\MEMORY.DMP]
Kernel Bitmap Dump File: Kernel address space is available, User address space may not be available.
Symbol search path is: srv*
Executable search path is:
Windows 8.1 Kernel Version 9600 MP (4 procs) Free x64
Product: Server, suite: TerminalServer DataCenter SingleUserTS
Edition build lab: 9600.18821.amd64fre.winblue_ltsb.170914-0600
Kernel base = 0xfffff800`2dc03000 PsLoadedModuleList = 0xfffff800`2ded5650
Debug session time: Mon Aug 5 17:35:21.097 2024 (UTC + 9:00)
System Uptime: 452 days 21:30:43.781
Loading Kernel Symbols
...............................................................
............................................................Page 434c0d not present in the dump file. Type ".hh dbgerr004" for details
....
....................
Loading User Symbols
PEB is paged out (Peb.Ldr = 00007ff6`6e0b3018). Type ".hh dbgerr001" for details
Loading unloaded module list
.........
For analysis of this file, run !analyze -v
nt!KeBugCheckEx:
fffff800`2dd50ba0 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:ffffd001`0ae2b7a0=000000000000003b
windbg> .hh dbgerr001
2: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
SYSTEM_SERVICE_EXCEPTION (3b)
An exception happened while executing a system service routine.
Arguments:
Arg1: 00000000c0000005, Exception code that caused the BugCheck
Arg2: fffff801bf2ff21c, Address of the instruction which caused the BugCheck
Arg3: ffffd0010ae2c050, Address of the context record for the exception that caused the BugCheck
Arg4: 0000000000000000, zero.
Debugging Details:
------------------
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 1780
Key : Analysis.Elapsed.mSec
Value: 1826
Key : Analysis.IO.Other.Mb
Value: 18
Key : Analysis.IO.Read.Mb
Value: 2
Key : Analysis.IO.Write.Mb
Value: 25
Key : Analysis.Init.CPU.mSec
Value: 1249
Key : Analysis.Init.Elapsed.mSec
Value: 2356164
Key : Analysis.Memory.CommitPeak.Mb
Value: 93
Key : Bugcheck.Code.KiBugCheckData
Value: 0x3b
Key : Bugcheck.Code.LegacyAPI
Value: 0x3b
Key : Bugcheck.Code.TargetModel
Value: 0x3b
Key : Failure.Bucket
Value: AV_msrpc!Ndr64pClientSetupTransferSyntax
Key : Failure.Hash
Value: {73e0f483-a44c-9763-f5a1-e01299452895}
Key : Hypervisor.Enlightenments.Value
Value: 27620
Key : Hypervisor.Enlightenments.ValueHex
Value: 6be4
Key : Hypervisor.Flags.Value
Value: 121
Key : Hypervisor.Flags.ValueHex
Value: 79
Key : WER.OS.Branch
Value: winblue_ltsb
Key : WER.OS.Version
Value: 8.1.9600.18821
BUGCHECK_CODE: 3b
BUGCHECK_P1: c0000005
BUGCHECK_P2: fffff801bf2ff21c
BUGCHECK_P3: ffffd0010ae2c050
BUGCHECK_P4: 0
FILE_IN_CAB: MEMORY.DMP
VIRTUAL_MACHINE: HyperV
CONTEXT: ffffd0010ae2c050 -- (.cxr 0xffffd0010ae2c050)
rax=ffffc001f9675ae0 rbx=ffffc001f9675cc8 rcx=0000000000000018
rdx=0000000000000ca0 rsi=0000000000000000 rdi=ffffc001f9675b30
rip=fffff801bf2ff21c rsp=ffffd0010ae2ca80 rbp=0000000000000064
r8=0000000000000000 r9=000000004d637052 r10=0000000000000801
r11=ffffd0010ae2c9f0 r12=00000000000036b4 r13=ffffd0010ae2d110
r14=fffff96000488e88 r15=ffffc001f9675ae0
iopl=0 nv up ei pl nz na po nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010206
msrpc!Ndr64pClientSetupTransferSyntax+0x20c:
fffff801`bf2ff21c 448b11 mov r10d,dword ptr [rcx] ds:002b:00000000`00000018=????????
Resetting default scope
PROCESS_NAME: csrss.exe
STACK_TEXT:
ffffd001`0ae2ca80 fffff801`bf2e8681 : ffffd001`0ae2d110 ffffd001`0ae2d110 00000000`00000000 00000000`00000001 : msrpc!Ndr64pClientSetupTransferSyntax+0x20c
ffffd001`0ae2cae0 fffff960`001f8605 : ffffe000`9cf59d80 ffffd001`0ae2d150 ffffd001`0ae2cb18 ffffd001`0ae2d110 : msrpc!Ndr64AsyncClientCall+0x111
ffffd001`0ae2d050 fffff960`0051a0b0 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : win32k!ClientI_WMsgkSendPSPMessage+0x3d
ffffd001`0ae2d0b0 fffff960`001f899f : ffffd001`0ae2d228 fffff960`00259cfa fffff960`00474770 fffff960`0047493a : win32k!WmsgpSendPSPMessage+0xa0
ffffd001`0ae2d1b0 fffff960`001f88a6 : 00000000`ffffffff ffffd001`0ae2d288 00000000`00000000 00000000`00000000 : win32k!xxxSendWinlogonPowerMessage+0x67
ffffd001`0ae2d1f0 fffff960`00474877 : 00000000`00000010 00000000`00000001 00000000`00000000 00000000`00000018 : win32k!UpdateDisplayState+0x12a
ffffd001`0ae2d260 fffff960`001f8e71 : 00000000`00000000 00000000`00000004 ffffd001`0ae2d300 00000000`00000004 : win32k!PowerOnMonitor+0x107
ffffd001`0ae2d290 fffff960`001f9905 : ffffe000`9cc99e50 00000004`00000001 00000000`0000001f fffff960`002598fc : win32k!xxxUserPowerEventCalloutWorker+0x4b1
ffffd001`0ae2d330 fffff960`00195974 : ffffe000`a6b70080 00000000`00000000 00000000`00000000 00000000`00000000 : win32k!xxxUserPowerCalloutWorker+0x89
ffffd001`0ae2d390 fffff800`2dd5c3b3 : ffffe000`a6b70080 00000000`0000001f 00000000`00000000 00000080`4340f678 : win32k!NtUserCallNoParam+0x44
ffffd001`0ae2d3c0 00007ffa`b68b18aa : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000080`4340f678 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x00007ffa`b68b18aa
SYMBOL_NAME: msrpc!Ndr64pClientSetupTransferSyntax+20c
MODULE_NAME: msrpc
IMAGE_NAME: msrpc.sys
STACK_COMMAND: .cxr 0xffffd0010ae2c050 ; kb
BUCKET_ID_FUNC_OFFSET: 20c
FAILURE_BUCKET_ID: AV_msrpc!Ndr64pClientSetupTransferSyntax
OS_VERSION: 8.1.9600.18821
BUILDLAB_STR: winblue_ltsb
OSPLATFORM_TYPE: x64
OSNAME: Windows 8.1
FAILURE_ID_HASH: {73e0f483-a44c-9763-f5a1-e01299452895}
Followup: MachineOwner
---------
어떠한 문제로 서버가 강제 재부팅 되었는지 문의 드립니다.