Home

BSOD on Server 2016 hal.dll (WATCHDOG_VIOLATION)

%3CLINGO-SUB%20id%3D%22lingo-sub-785581%22%20slang%3D%22en-US%22%3EBSOD%20on%20Server%202016%20hal.dll%20(WATCHDOG_VIOLATION)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-785581%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20have%20a%20client%20with%20a%20Windows%20Server%202016%20standard%20installation%20that%20gives%20BSOD%20at%20random%20times.%20We're%20talking%20about%20only%20three%20times%20a%20month%2C%20but%20since%20it%20is%20a%20server%20with%20important%20roles%20(Hyper-V%2C%20AD%2C%20DNS%2C%20DHCP)%20we're%20investigating%20the%20issue.%20I%20am%20aware%20that%20you'd%20normally%20want%20to%20split%20some%20of%20the%20roles%2C%20but%20that%20is%20not%20within%20our%20power%20to%20change.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20bluescreenview%20which%20reports%20back%20that%20the%20culprit%20is%20hal.dll%20with%20ntoskrnl.exe%20for%20each%20of%20the%20blue%20screens%20that%20we%20still%20have%20a%20.dmp%20file%20for.%20Looking%20into%20the%20MEMORY.dmp%20file%2C%20I%20can%20see%3A%3CBR%20%2F%3E%3CSPAN%3EDPC_WATCHDOG_VIOLATION%20(133)%3C%2FSPAN%3E%3CBR%20%2F%3E%3CSPAN%3EDPC_QUEUE_EXECUTION_TIMEOUT_EXCEEDED%3C%2FSPAN%3E%3CBR%20%2F%3E%3CSPAN%3EDEFAULT_BUCKET_ID%3A%20%26nbsp%3BWIN8_DRIVER_FAULT%3C%2FSPAN%3E%3CBR%20%2F%3E%3CBR%20%2F%3EI'm%20unfortunately%20unable%20to%20really%20deep%20digger%20into%20this%2C%20as%20I%20have%20never%20before%20had%20to.%20I%20ran%20some%20commands%20within%20the%20Windows%20debugger%20and%20all%20the%20information%20is%20uploaded%20in%20the%20attached%20text%20file.%20Is%20anyone%20experienced%20with%20troubleshooting%20such%20a%20problem%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20couldn't%20run%20sfc%2Fscannow%20at%20first%2C%20so%20we%20repaired%20with%20dism%20with%20a%20local%20source%2C%20and%20then%20ran%20sfc%2Fscannow%20successfully.%20The%20repaired%20files%20pointed%20towards%20Windows%20defender%20and%20I%20do%20not%20think%20its%20related.%20Good%20to%20know%3A%20Symantec%20is%20running%20on%20the%20server%2C%20defender%20real%20time%20protection%20is%20off.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAll%20I%20need%20is%20a%20push%20into%20the%20right%20direction%2C%20and%20then%20I'll%20dig%20into%20it%20myself%20%3A)%3C%2Fimg%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%2C%3C%2FP%3E%3CP%3EDennis%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-785581%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EHyper-V%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EWindows%20Server%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-790989%22%20slang%3D%22en-US%22%3ERe%3A%20BSOD%20on%20Server%202016%20hal.dll%20(WATCHDOG_VIOLATION)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-790989%22%20slang%3D%22en-US%22%3E%3CP%3EHost%20or%20guest%20BSOD%3F%20Hopefully%20the%20Hyper-V%20role%20is%20only%20role%20on%20host%20and%20active%20directory%20domain%20services%20are%20on%20a%20separate%20VM%20windows%20instance.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-792579%22%20slang%3D%22en-US%22%3ERe%3A%20BSOD%20on%20Server%202016%20hal.dll%20(WATCHDOG_VIOLATION)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-792579%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F51719%22%20target%3D%22_blank%22%3E%40Dave%20Patrick%3C%2FA%3E%26nbsp%3BHost%20BSOD%20unfortunately.%20And%20nope%2C%20all%20the%20roles%20are%20installed%20on%20the%20host%20itself.%20It%20is%20not%20something%20done%20by%20me%20or%20my%20colleagues%2C%20and%20its%20not%20within%20our%20power%20to%20change.%20The%20host%20is%20powerful%20enough%20to%20virtualise%20the%20roles%2C%20but%20the%20client%20is%20reluctant%20to%20do%20so.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20the%20system%20is%20more%20or%20less%20contaminated%20with%20(at%20least)%20the%20following%3A%3C%2FP%3E%3CP%3E-%20AD%2FDNS%2FDHCP%2FIIS%2FNAP%20roles%20installed%3C%2FP%3E%3CP%3E-%20Symantec%20antivirus%20%3CSTRONG%3Emanager%20%3C%2FSTRONG%3E(not%20just%20the%20client)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhich%20makes%20it%20all%20the%20harder%20to%20really%20guarantee%20a%20stable%20system%2C%20even%20if%20we%20end%20up%20finding%20what%20causes%20this.%20The%20host%20has%20not%20crashed%20yet%20since%20we%20last%20ran%20some%20basic%20repair%20commands%2C%20but%20we'll%20keep%20an%20eye%20on%20it%20..%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-793060%22%20slang%3D%22en-US%22%3ERe%3A%20BSOD%20on%20Server%202016%20hal.dll%20(WATCHDOG_VIOLATION)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-793060%22%20slang%3D%22en-US%22%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI'd%20work%20to%20move%20the%20roles%20(other%20than%20Hyper-V)%20off%20the%20host%20by%20standing%20up%20the%20required%20guests.%20You%20can%20do%20this%20rather%20easily.%26nbsp%3B%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3EI'd%20use%20dcdiag%20%2F%20repadmin%20tools%20to%20verify%20health%20%3CU%3Ecorrecting%20all%20errors%20found%3C%2FU%3E%20before%20starting.%20Then%20stand%20up%20the%20new%20guest%2C%20patch%20it%20fully%2C%20license%20it%2C%20join%20existing%20domain%2C%20add%20active%20directory%20domain%20services%2C%20promote%20it%20also%20making%20it%20a%20GC%20(recommended)%2C%20transfer%20FSMO%20roles%20over%20(optional)%2C%20transfer%20pdc%20emulator%20role%20(optional)%2C%20use%20dcdiag%20%2F%20repadmin%20tools%20to%20again%20verify%20health%2C%20when%20all%20is%20good%20you%20can%20decommission%20%2F%20demote%20old%20one.%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ETo%20the%20bsod%20issues.%20I'd%20check%20here%20and%20with%20manufacturer%20about%20support%20for%20Server%202019%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fwww.windowsservercatalog.com%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3E%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3Ehttps%3A%2F%2Fwww.windowsservercatalog.com%2F%3C%2FFONT%3E%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3E%26nbsp%3B%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3E%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3EAlso%20check%20with%20manufacturer%20for%20the%20latest%20ROM%20bios%2C%20firmware%2C%20chipset%20and%20driver%20support%20pack.%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3E%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3E%26nbsp%3B%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3E%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3E%26nbsp%3B%3C%2FFONT%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-799738%22%20slang%3D%22en-US%22%3ERe%3A%20BSOD%20on%20Server%202016%20hal.dll%20(WATCHDOG_VIOLATION)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-799738%22%20slang%3D%22en-US%22%3E%3CP%3EHe%20already%20said%20he%20can't%20do%20that...%20and%20whilst%20I%20agree%20it%20is%20far%20from%20ideal%20having%20them%20all%20on%20the%20same%20box%20-%20it%20shouldn't%20be%20causing%20a%20BSOD%20should%20it.%20So%20just%20moving%20the%20DC%20role%20to%20another%20machine%20is%20almost%20certainly%20not%20going%20to%20fix%20this%20anyway.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt%20seems%20much%20more%20likely%20this%20is%20from%20a%20hardware%20driver.%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F321331%22%20target%3D%22_blank%22%3E%40DLans%3C%2FA%3E%26nbsp%3B%20would%20it%20be%20possible%20to%20ZIP%20the%20MEMORY.dmp%20file%20and%20upload%20it%20somewhere%20for%20us%20to%20take%20a%20look%20at%3F%20You've%20done%20a%20great%20job%20with%20that%20initial%20text%20file%20showing%20various%20outputs%20from%20the%20debugger%2C%20but%20there's%20a%20few%20more%20things%20I%20want%20to%20take%20a%20look%20at%20and%20it%20will%20be%20a%20lot%20quicker%20to%20explore%20the%20file%20rather%20than%20relaying%20commands%20and%20results%20back%20and%20forth%20between%20us%20on%20here.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-799932%22%20slang%3D%22en-US%22%3ERe%3A%20BSOD%20on%20Server%202016%20hal.dll%20(WATCHDOG_VIOLATION)%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-799932%22%20slang%3D%22en-US%22%3E%3CP%3EIn%20my%20experience%20you%20always%20fix%20everything%20you%20%3CU%3Eknow%3C%2FU%3Eis%20wrong%20as%20first%20steps%2C%20then%20work%20from%20there.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
DLans
New Contributor

We have a client with a Windows Server 2016 standard installation that gives BSOD at random times. We're talking about only three times a month, but since it is a server with important roles (Hyper-V, AD, DNS, DHCP) we're investigating the issue. I am aware that you'd normally want to split some of the roles, but that is not within our power to change. 

 

We bluescreenview which reports back that the culprit is hal.dll with ntoskrnl.exe for each of the blue screens that we still have a .dmp file for. Looking into the MEMORY.dmp file, I can see:
DPC_WATCHDOG_VIOLATION (133)
DPC_QUEUE_EXECUTION_TIMEOUT_EXCEEDED
DEFAULT_BUCKET_ID:  WIN8_DRIVER_FAULT

I'm unfortunately unable to really deep digger into this, as I have never before had to. I ran some commands within the Windows debugger and all the information is uploaded in the attached text file. Is anyone experienced with troubleshooting such a problem?

 

We couldn't run sfc/scannow at first, so we repaired with dism with a local source, and then ran sfc/scannow successfully. The repaired files pointed towards Windows defender and I do not think its related. Good to know: Symantec is running on the server, defender real time protection is off.

 

All I need is a push into the right direction, and then I'll dig into it myself :) 

 

Thanks,

Dennis

 

5 Replies

Host or guest BSOD? Hopefully the Hyper-V role is only role on host and active directory domain services are on a separate VM windows instance.

 

 

@Dave Patrick Host BSOD unfortunately. And nope, all the roles are installed on the host itself. It is not something done by me or my colleagues, and its not within our power to change. The host is powerful enough to virtualise the roles, but the client is reluctant to do so.

 

So the system is more or less contaminated with (at least) the following:

- AD/DNS/DHCP/IIS/NAP roles installed

- Symantec antivirus manager (not just the client)

 

Which makes it all the harder to really guarantee a stable system, even if we end up finding what causes this. The host has not crashed yet since we last ran some basic repair commands, but we'll keep an eye on it ..

 

 

I'd work to move the roles (other than Hyper-V) off the host by standing up the required guests. You can do this rather easily. I'd use dcdiag / repadmin tools to verify health correcting all errors found before starting. Then stand up the new guest, patch it fully, license it, join existing domain, add active directory domain services, promote it also making it a GC (recommended), transfer FSMO roles over (optional), transfer pdc emulator role (optional), use dcdiag / repadmin tools to again verify health, when all is good you can decommission / demote old one.

 

To the bsod issues. I'd check here and with manufacturer about support for Server 2019

https://www.windowsservercatalog.com/

 

Also check with manufacturer for the latest ROM bios, firmware, chipset and driver support pack.

 

 

He already said he can't do that... and whilst I agree it is far from ideal having them all on the same box - it shouldn't be causing a BSOD should it. So just moving the DC role to another machine is almost certainly not going to fix this anyway.

 

It seems much more likely this is from a hardware driver. @DLans  would it be possible to ZIP the MEMORY.dmp file and upload it somewhere for us to take a look at? You've done a great job with that initial text file showing various outputs from the debugger, but there's a few more things I want to take a look at and it will be a lot quicker to explore the file rather than relaying commands and results back and forth between us on here.

In my experience you always fix everything you know is wrong as first steps, then work from there.

 

 

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
35 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies