Hi Guys,
All of the sudden a virtual machines started periodically go into BSOD.
Crash Dump Analysis provided by OSR Open Systems Resources, Inc. (http://www.osr.com) Online Crash Dump Analysis Service See http://www.osronline.com for more information Windows 8 Kernel Version 9600 MP (8 procs) Free x64 Product: Server, suite: TerminalServer DataCenter Built by: 9600.19067.amd64fre.winblue_ltsb_escrow.180619-2033 Machine Name: Kernel base = 0xfffff803`c5076000 PsLoadedModuleList = 0xfffff803`c5341610 Debug session time: Mon Aug 13 21:45:07.299 2018 (UTC - 4:00) System Uptime: 0 days 7:14:49.311 ******************************************************************************* * * * Bugcheck Analysis * * * ******************************************************************************* SYSTEM_SERVICE_EXCEPTION (3b) An exception happened while executing a system service routine. Arguments: Arg1: 00000000c0000005, Exception code that caused the bugcheck Arg2: 0000000000000000, Address of the instruction which caused the bugcheck Arg3: ffffd000208860a0, Address of the context record for the exception that caused the bugcheck Arg4: 0000000000000000, zero. Debugging Details: ------------------ TRIAGER: Could not open triage file : e:\dump_analysis\program\triage\modclass.ini, error 2 EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s". FAULTING_IP: +13 00000000`00000000 ?? ??? CONTEXT: ffffd000208860a0 -- (.cxr 0xffffd000208860a0) rax=0000000000000000 rbx=000000000f1212a5 rcx=fffff9014318bca8 rdx=0000000080003d42 rsi=fffff9014318bca8 rdi=0000000080003d42 rip=0000000000000000 rsp=ffffd00020886ac8 rbp=0000000080003d42 r8=000000000f1212a5 r9=0000014200000690 r10=fffff96000922aa0 r11=ffffd00020886a40 r12=fffff9600019ae80 r13=000000d29dfa0b30 r14=fffff90140162010 r15=0000000000000001 iopl=0 nv up ei pl zr na po nc cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010246 00000000`00000000 ?? ??? Resetting default scope DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT_SERVER BUGCHECK_STR: 0x3B PROCESS_NAME: dwm.exe CURRENT_IRQL: 0 LAST_CONTROL_TRANSFER: from fffff96000918da3 to 0000000000000000 STACK_TEXT: ffffd000`20886ac8 fffff960`00918da3 : 00000000`0f1212a5 00000000`80003d42 fffff901`423787a0 fffff960`001a3704 : 0x0 ffffd000`20886ad0 fffff960`0044b504 : fffff901`423787a0 00000000`0f1212a5 000012a5`0f1212a5 00000142`00000690 : cdd!RmtAssociateSharedSurface+0x5f ffffd000`20886b20 fffff960`002b4c84 : 00000000`0f1212a5 fffff901`423787a0 00000000`80003d42 00000000`00000000 : win32k!MulAssociateSharedSurface+0x24 ffffd000`20886b50 fffff960`002b4a1b : 00000000`c000000d ffffd000`20886cc0 000000d2`9c82eef0 00000000`00005902 : win32k!GreSetRedirectionSurfaceSignaling+0x110 ffffd000`20886bc0 fffff803`c51db3a3 : ffffe000`4db57880 00000000`00000000 000000d2`00000000 ffffe000`49b97d00 : win32k!NtGdiHLSurfSetInformation+0x243 ffffd000`20886c40 00007ffc`5b2027ca : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13 000000d2`9c82ee28 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x7ffc`5b2027ca FOLLOWUP_IP: cdd!RmtAssociateSharedSurface+5f fffff960`00918da3 488d4c2420 lea rcx,[rsp+20h] SYMBOL_STACK_INDEX: 1 SYMBOL_NAME: cdd!RmtAssociateSharedSurface+5f FOLLOWUP_NAME: MachineOwner MODULE_NAME: cdd IMAGE_NAME: cdd.dll DEBUG_FLR_IMAGE_TIMESTAMP: 54506444 STACK_COMMAND: .cxr 0xffffd000208860a0 ; kb FAILURE_BUCKET_ID: X64_0x3B_cdd!RmtAssociateSharedSurface+5f BUCKET_ID: X64_0x3B_cdd!RmtAssociateSharedSurface+5f Followup: MachineOwner
Looks like something related to display driver.
Run sfc /scannow - nothing found related to resource integrity violations.
Microsoft Windows [Version 6.3.9600] (c) 2013 Microsoft Corporation. All rights reserved. C:\Users\administrator.INCLOUD>sfc /scannow Beginning system scan. This process will take some time. Beginning verification phase of system scan. Verification 100% complete. Windows Resource Protection did not find any integrity violations.
Checked updates and programs installed close to the day it happened. Can't see any suspicious.
Please advise what else should be checked.