[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

Win2k3 Server random BSOD Win32k.sys

Posted on 2008-11-04
3
Medium Priority
?
3,193 Views
Last Modified: 2008-11-18
Hi,

I have a 2k3 enterprise SP2 server running on a VMware ESX 3.5. Every few days I am getting a BSOD, which does not seem to be related to any specific action. Intially the dump file pointed to symevent.sys, so, I suspected Symantec AV, and removed it. Now I am still getting the BSOD, but the dump has changed, and is now pointing to Win32k.sys. See output below. This is now getting very urgent, so any help appreciated.


Microsoft (R) Windows Debugger Version 6.9.0003.113 X86
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [W:\WINDOWS\Minidump\Mini110408-02.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: C:\WINDOWS\Symbols
Executable search path is:
Unable to load image ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
Windows Server 2003 Kernel Version 3790 (Service Pack 2) MP (2 procs) Free x86 compatible
Product: Server, suite: Enterprise TerminalServer SingleUserTS
Kernel base = 0x80800000 PsLoadedModuleList = 0x808a6ea8
Debug session time: Tue Nov  4 11:53:23.572 2008 (GMT+0)
System Uptime: 0 days 2:18:56.204
Unable to load image ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
Loading Kernel Symbols
.......................................................................................................
Loading User Symbols
Loading unloaded module list
..
Unable to load image win32k.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for win32k.sys
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 10000050, {bcfb0ba0, 0, bf8b8449, 0}


Could not read faulting driver name
Probably caused by : win32k.sys ( win32k!GdiThreadCallout+2a )

Followup: MachineOwner
---------

Stack Trace
b855dc58 bf8b703b win32k!GdiThreadCallout+0x2a
b855dc64 bf8b7e98 win32k!bSpBltFromScreen+0x35
b855dc80 8094c2ac win32k!UnlockCaptureWindow+0x14
b855dd0c 8094c63f nt!PpInitializeNotification+0x8a
b855dd24 8094c839 nt!PiProcessQueryRemoveAndEject+0x3ce
b855dd54 8088978c nt!PiProcessQueryRemoveAndEject+0x600
b855dd64 7c8285ec nt!RtlIpv6StringToAddressExA+0x1a6
WARNING: Frame IP not in any known module. Following frames may be wrong.
b855dd78 00000000 0x7c8285ec

Thank you
0
Comment
Question by:atitc
  • 2
3 Comments
 
LVL 24

Accepted Solution

by:
ryansoto earned 1500 total points
ID: 22876984
Its also referring to ntoskrnl.exe
Why not get the updated win32k.sys from SP2 (as the version on your CD may be the outdated version)
and stick it on a floppy along with ntpskrnl.
Boot to the recovery console rename the old existing files then copy the new files and see what happens
0
 

Author Comment

by:atitc
ID: 22877045
I can give it a try, as it is an older version of SP 2 that I downloaded some time ago.

0
 

Author Comment

by:atitc
ID: 22983034
Thanks, this pointed me in the right direction. What I ended up doing was just downloading the latest version of SP2 and re-applied it to the server. Since then the problem seems to have gone away.

Cheers
0

Featured Post

VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

August and September have been big months for VMware—from VMworld last month to our new Course of the Month in VMware Professional - Data Center Virtualization. We reached out to Andrew Hancock, resident VMware vExpert, to have a more in-depth discu…
It’s time for spooky stories and consuming way too much sugar, including the many treats we’ve whipped for you in the world of tech. Check it out!
Teach the user how to rename, unmount, delete and upgrade VMFS datastores. Open vSphere Web Client: Rename VMFS and NFS datastores: Upgrade VMFS-3 volume to VMFS-5: Unmount VMFS datastore: Delete a VMFS datastore:
Advanced tutorial on how to run the esxtop command to capture a batch file in csv format in order to export the file and use it for performance analysis. He demonstrates how to download the file using a vSphere web client (or vSphere client) and exp…
Suggested Courses

834 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question