VSS BSOD server 2019

%3CLINGO-SUB%20id%3D%22lingo-sub-1100952%22%20slang%3D%22en-US%22%3EVSS%20BSOD%20server%202019%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1100952%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3EI%20have%20Shadow%20Copies%20enabled%20for%20some%20network%20shares%20on%20a%20Windows%20Server%202019%20vm.%20When%20a%20VSS%20copy%20is%20made%2C%20it%20blue%20screens%20the%20vm.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CDIV%20class%3D%22MainContainer%20InsightsEnabled%22%3E%3CDIV%20class%3D%22PrimaryContainer%22%3E%3CDIV%3E%3CDIV%20class%3D%22BodyContainer%22%3E%3CDIV%20class%3D%22Normal%20Section%22%3E%3CDIV%20class%3D%22Content%22%3E%3CDIV%20class%3D%22EntityBodyEnhancedText%22%3E%3CSPAN%20class%3D%22Content%22%3EThe%20computer%20has%20rebooted%20from%20a%20bugcheck.%20The%20bugcheck%20was%3A%200x000000ef%20(0xffff8785861be080%2C%200x0000000000000000%2C%200x0000000000000000%2C%200x0000000000000000).%3C%2FSPAN%3E%3C%2FDIV%3E%3CDIV%20class%3D%22EntityBodyEnhancedText%22%3E%26nbsp%3B%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3CP%3EThe%20problem%20started%20on%2031-12-2019.%20No%20recent%20windows%20updates%20were%20installed.%3C%2FP%3E%3CP%3EOnly%20fix%20for%20now%20is%20to%20disable%20VSS%20on%20that%20drive%2Fshares.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESFC%20%2FSCANNOW%20does%20not%20solve%20the%20problem!%3C%2FP%3E%3CDIV%20class%3D%22MainContainer%20InsightsEnabled%22%3E%3CDIV%20class%3D%22PrimaryContainer%22%3E%3CDIV%20class%3D%22TabContainer%20Active%20ActivityTabContainer%22%3E%3CDIV%20class%3D%22ActivityTabShell%22%3E%3CDIV%20class%3D%22Content%22%3E%3CDIV%20class%3D%22Conversation%20Active%22%3E%3CDIV%20class%3D%22ConversationChunk%22%3E%3CDIV%20class%3D%22ConversationItem%22%3E%3CDIV%20class%3D%22Details%22%3E%3CDIV%20class%3D%22Message%22%3E%3CDIV%20class%3D%22Searchable%22%3E%3CSPAN%3Edism.exe%20%2Fonline%20%2Fcleanup-image%20%2Frestorehealth%20does%20not%20solve%20the%20problem!%3C%2FSPAN%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3C%2FDIV%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThere%20is%20a%20minidump%20available%2C%20but%20with%20the%20minidump%20i%20am%20not%20able%20to%20solve%20the%20issue.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20there%20someone%20else%20who%20is%20experiencing%20this%20issue%20and%20has%20a%20fix%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1100952%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EWindows%20Server%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1101609%22%20slang%3D%22en-US%22%3ERe%3A%20VSS%20BSOD%20server%202019%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1101609%22%20slang%3D%22en-US%22%3E%3CP%3EMight%20work%20through%20this%20one.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows-hardware%2Fdrivers%2Fdebugger%2Fbug-check-0xef--critical-process-died%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3E%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows-hardware%2Fdrivers%2Fdebugger%2Fbug-check-0xef--critical-process-died%3C%2FFONT%3E%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3E%26nbsp%3B%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3E%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3EDebugging%20is%20beyond%20the%20scope%20of%20forums%20support%2C%20you%20can%20start%20a%20case%20here%20with%20product%20support.%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3E%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3E%26nbsp%3B%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Fhub%2F4343728%2Fsupport-for-business%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3E%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3Ehttps%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Fhub%2F4343728%2Fsupport-for-business%3C%2FFONT%3E%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3E%26nbsp%3B%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3E%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3E%26nbsp%3B%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3E%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3E%26nbsp%3B%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3E%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3E%26nbsp%3B%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1240187%22%20slang%3D%22en-US%22%3ERe%3A%20VSS%20BSOD%20server%202019%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1240187%22%20slang%3D%22en-US%22%3E%3CP%3EI%20am%20experiencing%20the%20same%20issue%20on%20customers%20servers%20with%20Server%202019%20where%20I%20have%20had%20to%20disable%20Shadow%20Copies%2C%20a%20much%20needed%20feature%20for%20the%20customer.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20servers%20are%20very%20vanilla%20part%20from%20Webroot%20AV%20and%20our%20Labtech%2FConnectwise%20monitoring%20agent.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAnother%20MSP%20worker%20has%20the%20same%20at%20customers%20here%3A%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fcommunity.spiceworks.com%2Ftopic%2F2249667-vss-bsod-server-2019%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fcommunity.spiceworks.com%2Ftopic%2F2249667-vss-bsod-server-2019%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EClearly%20something%20is%20broken%20that%20needs%20to%20be%20fixed.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1250010%22%20slang%3D%22en-US%22%3ERe%3A%20VSS%20BSOD%20server%202019%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1250010%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F587743%22%20target%3D%22_blank%22%3E%40Wadeal%3C%2FA%3E%26nbsp%3BWe%20are%20facing%20this%20issue%20as%20well%20on%203%20servers%20at%20the%20moment.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20run%20LT%2BWR%2BAcronis.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt%20occurs%20only%20with%20the%20windows%20scheduled%20task%20shadow%20copy%20jobs.%20If%20i%20create%20them%20via%20the%20Prev%20Versions%20module%20it%20does%20not%20crash%20the%20system.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1250569%22%20slang%3D%22en-US%22%3ERe%3A%20VSS%20BSOD%20server%202019%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1250569%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F587743%22%20target%3D%22_blank%22%3E%40Wadeal%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20resolved%20this%20on%203%20servers%20by%20removing%26nbsp%3B%20KB4538461%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1318058%22%20slang%3D%22en-US%22%3ERe%3A%20VSS%20BSOD%20server%202019%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1318058%22%20slang%3D%22en-US%22%3E%3CP%3EJust%20installed%20a%20fresh%202019%20server%2C%20enabled%20shadow%20copies.%20Ran%20the%20scheduled%20task%20and%20it%20BSOD's%20immediately.%20I%20am%20unable%20to%20remove%20the%20update%20that%20previously%20fixed%20this%20as%20it%20is%20built%20into%20the%20OS%20now.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1318068%22%20slang%3D%22en-US%22%3ERe%3A%20VSS%20BSOD%20server%202019%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1318068%22%20slang%3D%22en-US%22%3E%3CP%3EYou%20can%20start%20a%20case%20here%20with%20product%20support.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Fhub%2F4343728%2Fsupport-for-business%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3E%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3Ehttps%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Fhub%2F4343728%2Fsupport-for-business%3C%2FFONT%3E%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3E%26nbsp%3B%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3E%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3E%26nbsp%3B%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1341045%22%20slang%3D%22en-US%22%3ERe%3A%20VSS%20BSOD%20server%202019%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1341045%22%20slang%3D%22en-US%22%3E%3CP%3EI%20posted%20last%20month%20about%20this%2C%20after%20installation%20of%20KB4538461%20on%20a%20client's%20RDS%20servers%20caused%20BSODs%20at%2012pm%2C%20and%20several%20users%20lost%20hours%20worth%20of%20work.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EToday%2C%20same%20thing%20occurs%20after%20the%20latest%20cumulative%20update%2C%20%3CSPAN%3EKB4549949%3C%2FSPAN%3E.%26nbsp%3B%26nbsp%3B%20For%20now%2C%20we've%20disabled%20patching%20entirely%20on%20the%20environment.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThere%20must%20be%20something%20unique%20to%20the%20RDS%20Servers%20themselves%2C%20as%20the%20RDSGW%20server%20was%20built%20from%20the%20same%202019%20Datacenter%20OVA%20template%2Fclone%20in%20VMware.%26nbsp%3B%26nbsp%3B%20This%20does%20not%20occur%20on%20this%20server%2C%20despite%20having%20%3CSPAN%3EKB4549949%3C%2FSPAN%3E%20installed.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Visitor

Hello,

I have Shadow Copies enabled for some network shares on a Windows Server 2019 vm. When a VSS copy is made, it blue screens the vm.

 

The computer has rebooted from a bugcheck. The bugcheck was: 0x000000ef (0xffff8785861be080, 0x0000000000000000, 0x0000000000000000, 0x0000000000000000).
 

The problem started on 31-12-2019. No recent windows updates were installed.

Only fix for now is to disable VSS on that drive/shares. 

 

SFC /SCANNOW does not solve the problem!

dism.exe /online /cleanup-image /restorehealth does not solve the problem!

 

There is a minidump available, but with the minidump i am not able to solve the issue.

 

Is there someone else who is experiencing this issue and has a fix?

 

 

8 Replies
Highlighted

Might work through this one.

 

https://docs.microsoft.com/en-us/windows-hardware/drivers/debugger/bug-check-0xef--critical-process-...

 

Debugging is beyond the scope of forums support, you can start a case here with product support.

 

https://support.microsoft.com/en-us/hub/4343728/support-for-business

 

 

 

 

 

Highlighted

I am experiencing the same issue on customers servers with Server 2019 where I have had to disable Shadow Copies, a much needed feature for the customer.

 

The servers are very vanilla part from Webroot AV and our Labtech/Connectwise monitoring agent.

 

Another MSP worker has the same at customers here:

https://community.spiceworks.com/topic/2249667-vss-bsod-server-2019

 

Clearly something is broken that needs to be fixed.

Highlighted

@Wadeal We are facing this issue as well on 3 servers at the moment. 

 

We run LT+WR+Acronis.

 

It occurs only with the windows scheduled task shadow copy jobs. If i create them via the Prev Versions module it does not crash the system.

Highlighted

@Wadeal 

I resolved this on 3 servers by removing  KB4538461

Highlighted

Just installed a fresh 2019 server, enabled shadow copies. Ran the scheduled task and it BSOD's immediately. I am unable to remove the update that previously fixed this as it is built into the OS now.

 

 

Highlighted

You can start a case here with product support.

 

https://support.microsoft.com/en-us/hub/4343728/support-for-business

 

 

 

Highlighted

I posted last month about this, after installation of KB4538461 on a client's RDS servers caused BSODs at 12pm, and several users lost hours worth of work.

 

Today, same thing occurs after the latest cumulative update, KB4549949.   For now, we've disabled patching entirely on the environment.

 

There must be something unique to the RDS Servers themselves, as the RDSGW server was built from the same 2019 Datacenter OVA template/clone in VMware.   This does not occur on this server, despite having KB4549949 installed.

Highlighted
1 out of the 6 RDS servers apparently does not experience the issue, either.

Trying to determine what is different is going to be a chore.