1 Reply Latest reply on Jul 27, 2012 9:29 AM by sbenedix

    Windows shutdown caused by mfehidk!DEVICEDISPATCH::DispatchPassThrough+6cbe

      Hi All

       

      Recently our Windows 2008 Enterprise server restarted by itself. We I analysed the memory.dmp file it gave the below result. Please check and give us the solution. We are using Mcafee 8.8 VSE.

       


      Microsoft (R) Windows Debugger Version 6.11.0001.404 AMD64
      Copyright (c) Microsoft Corporation. All rights reserved.


      Loading Dump File [D:\yyy\MEMORY.DMP]
      Kernel Summary Dump File: Only kernel address space is available

      Symbol search path is: srv*
      Executable search path is:
      Windows Server 2008/Windows Vista Kernel Version 6002 (Service Pack 2) MP (24 procs) Free x64
      Product: Server, suite: Enterprise TerminalServer SingleUserTS
      Built by: 6002.18484.amd64fre.vistasp2_gdr.110617-0336
      Machine Name:
      Kernel base = 0xfffff800`0260e000 PsLoadedModuleList = 0xfffff800`027d2dd0
      Debug session time: Thu Jun 14 21:02:22.181 2012 (GMT+4)
      System Uptime: 78 days 10:11:20.626
      Loading Kernel Symbols
      ...............................................................
      ................................................................
      ...............
      Loading User Symbols
      PEB is paged out (Peb.Ldr = 00000000`fffdf018).  Type ".hh dbgerr001" for details
      Loading unloaded module list
      ..................................................
      *******************************************************************************
      *                                                                             *
      *                        Bugcheck Analysis                                    *
      *                                                                             *
      *******************************************************************************

      Use !analyze -v to get detailed debugging information.

      BugCheck C2, {7, 110b, 409000b, fffffa80280fbac0}

      *** ERROR: Symbol file could not be found.  Defaulted to export symbols for mfehidk.sys -
      PEB is paged out (Peb.Ldr = 00000000`fffdf018).  Type ".hh dbgerr001" for details
      PEB is paged out (Peb.Ldr = 00000000`fffdf018).  Type ".hh dbgerr001" for details
      Probably caused by : mfehidk.sys ( mfehidk!DEVICEDISPATCH::DispatchPassThrough+6cbe )

      Followup: MachineOwner
      ---------

      5: kd> !analyze -v
      *******************************************************************************
      *                                                                             *
      *                        Bugcheck Analysis                                    *
      *                                                                             *
      *******************************************************************************

      BAD_POOL_CALLER (c2)
      The current thread is making a bad pool request.  Typically this is at a bad IRQL level or double freeing the same allocation, etc.
      Arguments:
      Arg1: 0000000000000007, Attempt to free pool which was already freed
      Arg2: 000000000000110b, (reserved)
      Arg3: 000000000409000b, Memory contents of the pool block
      Arg4: fffffa80280fbac0, Address of the block of pool being deallocated

      Debugging Details:
      ------------------

      PEB is paged out (Peb.Ldr = 00000000`fffdf018).  Type ".hh dbgerr001" for details
      PEB is paged out (Peb.Ldr = 00000000`fffdf018).  Type ".hh dbgerr001" for details

      POOL_ADDRESS:  fffffa80280fbac0 Nonpaged pool

      FREED_POOL_TAG:  MFE0

      BUGCHECK_STR:  0xc2_7_MFE0

      DEFAULT_BUCKET_ID:  VISTA_DRIVER_FAULT

      PROCESS_NAME:  vmware-converte

      CURRENT_IRQL:  0

      LAST_CONTROL_TRANSFER:  from fffff800027413a5 to fffff80002668490

      STACK_TEXT: 
      fffffa60`1195c2e8 fffff800`027413a5 : 00000000`000000c2 00000000`00000007 00000000`0000110b 00000000`0409000b : nt!KeBugCheckEx
      fffffa60`1195c2f0 fffffa60`00dc14fe : 130c0000`0210001a fffffa80`280fbac0 fffffa60`007e007e fffffa80`3045464d : nt!ExDeferredFreePool+0x90a
      fffffa60`1195c3a0 fffffa60`00d71e1a : fffffa80`280fbac0 fffffa60`00dd7628 fffffa80`2ac83030 fffffa60`00dc85a0 : mfehidk!DEVICEDISPATCH::DispatchPassThrough+0x6cbe
      fffffa60`1195c3d0 fffffa60`00d72a6c : fffffa60`00dd7628 fffffa80`27bd02e0 00000000`00000000 fffffa80`2621b770 : mfehidk+0x13e1a
      fffffa60`1195c400 fffffa60`00d72c84 : 00000000`00000000 fffffa60`1195c601 00000000`00000000 fffffa80`282f0ce0 : mfehidk+0x14a6c
      fffffa60`1195c4e0 fffffa60`00d75687 : 00000000`00000000 fffff800`0268a301 fffffa60`1195c900 fffffa60`1195c760 : mfehidk+0x14c84
      fffffa60`1195c560 fffffa60`00dba8ee : fffffa80`00100081 fffffa80`3cd296e0 fffffa80`24aa9ba0 00000000`00000040 : mfehidk+0x17687
      fffffa60`1195c690 fffff800`028d69d9 : 00000000`00000025 fffffa80`24aa9ba0 00000000`00000040 fffffa80`24aa9ba0 : mfehidk!DEVICEDISPATCH::DispatchPassThrough+0xae
      fffffa60`1195c700 fffff800`028ceed2 : fffffa80`27ef06c0 00000000`00000000 fffffa80`27e0e7d0 fffffa80`3d045001 : nt!IopParseDevice+0x5f9
      fffffa60`1195c8a0 fffff800`028cfa65 : 00000000`00000000 fffffa80`27e0e8d8 00000000`00000000 00000000`00000000 : nt!ObpLookupObjectName+0x593
      fffffa60`1195c9b0 fffff800`028d5047 : fffff880`00100081 00000000`00100081 00000000`00000001 fffffa60`1195cca0 : nt!ObOpenObjectByName+0x2f5
      fffffa60`1195ca80 fffff800`028deed8 : 00000000`072ee808 fffff800`00100081 fffff880`0e7c78a0 00000000`072ee7f8 : nt!IopCreateFile+0x287
      fffffa60`1195cb20 fffff800`02667f33 : fffff880`125f44d0 fffffa80`268fd700 00000000`00000628 fffff800`028d3734 : nt!NtCreateFile+0x78
      fffffa60`1195cbb0 00000000`775973ca : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
      00000000`072ee778 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x775973ca


      STACK_COMMAND:  kb

      FOLLOWUP_IP:
      mfehidk!DEVICEDISPATCH::DispatchPassThrough+6cbe
      fffffa60`00dc14fe 4883c428        add     rsp,28h

      SYMBOL_STACK_INDEX:  2

      SYMBOL_NAME:  mfehidk!DEVICEDISPATCH::DispatchPassThrough+6cbe

      FOLLOWUP_NAME:  MachineOwner

      MODULE_NAME: mfehidk

      IMAGE_NAME:  mfehidk.sys

      DEBUG_FLR_IMAGE_TIMESTAMP:  4d2e1e54

      FAILURE_BUCKET_ID:  X64_0xc2_7_MFE0_mfehidk!DEVICEDISPATCH::DispatchPassThrough+6cbe

      BUCKET_ID:  X64_0xc2_7_MFE0_mfehidk!DEVICEDISPATCH::DispatchPassThrough+6cbe

      Followup: MachineOwner
      ---------

       

       

      Thanks

      Sundar