Hello,

I have five servers in a backup set. All servers are NW6 SP5 with TSA5UP18 installed. Backup software is BackupExec 9.1 1127. All servers run McAfee Netshield 4.6.3 scanning incoming only and full scans every Sunday. The Backup server and two of the remotes run with no problems. 2 of the remotes abend every few days during backups, and only during backups. The two servers that are abending are also the oldest two servers and have seen numerous upgrades. They started as 4.11 upgraded to 5.1 upgraded to 6.0. Neither server has hyper threading. Other than that there is nothing unique about these two servers. both are simply file and print servers, one host the ZFD database.

Shutting off the Virus Defense is not an option here. We are a college and students have access to these servers. Any suggestions or ideas will be appreciated.

Typical abend log:





************************************************** *

Server BRWD halted Sunday, December 25, 2005 12:14:00.965 am
Abend 1 on P00: Server-5.60.05-4348: Kernel detected an attempted context switch when it was not allowed


Registers:
CS = 0008 DS = 0010 ES = 0010 FS = 0010 GS = 0010 SS = 0010
EAX = 00000000 EBX = 00000001 ECX = 00000000 EDX = FCE23FAC
ESI = 82EFA340 EDI = 81380AA0 EBP = CE79C9E8 ESP = 8138093C
EIP = 00223AA8 FLAGS = 00000002
00223AA8 83C404 ADD ESP,00000004
EIP in SERVER.NLM at code start +00018408h

The violation occurred while processing the following instruction:
00223AA8 83C404 ADD ESP,00000004
00223AAB 5D POP EBP
00223AAC 5E POP ESI
00223AAD 5B POP EBX
00223AAE C3 RET
00223AAF A19447E0FC MOV EAX,[FCE04794]=FCE25BB7
00223AB4 50 PUSH EAX
00223AB5 E84CE1EEFF CALL SERVER.NLM|Abend
00223ABA 83C404 ADD ESP,00000004
00223ABD 5D POP EBP



Running process: TSA Open: 89916540 Process
Thread Owned by NLM: SERVER.NLM
Stack pointer: 813806F4
OS Stack limit: 81379040
CPU 0 (Thread CFFDD100) is in a NO SLEEP state
Scheduling priority: 67371008
Wait state: 5050100 Delayed
Stack: --FCE23FAC ?
--CE79C9E8 (NSPNDS.NLM|asciiIdentifier+8504)
--82EFA340 ?
--813809D4 ?
00221A10 (SERVER.NLM|SchedSwitch+48)
--00000001 ?
--CE79C9E8 (NSPNDS.NLM|asciiIdentifier+8504)
--81380AA0 ?
--82EFA340 ?
--813809D4 ?
0032FD5B (SERVER.NLM|RescheduleLastWithDelay+EB)
--00000000 ?
0021A1D4 (SERVER.NLM|StartTempHandicappedThreadAgain+0)
--FFFFFFFF (LOADER.EXE|KernelTempAliasesEnd+FFF)
--CFFDD100 ?
--CE79C9E8 (NSPNDS.NLM|asciiIdentifier+8504)
--82EFA340 ?
--813809B0 ?
0032FC4A (SERVER.NLM|CRescheduleLastWithDelay+6)
--00000202 ?
CE191991 (THREADS.NLM|ThreadSwitchWithDelay+5)
847D85B5 (NETSHLD.NLM|REG_Open+B5)
--813809EC ?
--00000000 ?
--000109B0 ?
--8997E0C0 ?
--00000000 ?
--89799201 ?
--81380A74 ?
--813809DC ?
847D953B (NETSHLD.NLM|REG_IsSessionStampingDisabled+3B)
--813809D4 ?
--00000002 ?
--00000000 ?
--89799200 ?
--00000000 ?
--00000000 ?
--00000000 ?
--8997E0C0 ?
--00000000 ?
--813809EC ?
8482158D (NETSHLD.NLM|RefreshSessionStampMode+2D)
--84727200 ?
--43AE2A99 ?
--813809F4 ?
848215C8 (NETSHLD.NLM|IsSessionStampingEnabled+8)
--81380A10 ?
847FA86C (NETSHLD.NLM|ProcessPostOpen+C)
--81380A78 ?
--00000001 ?
--89799200 ?
--00002000 ?
--81380A74 ?
--81380A30 ?
847FAAFD (NETSHLD.NLM|WatchPostOpen+3D)
--00000000 ?
--000050F9 ?
--0000006D ?
--00000000 ?
--80000109 ?
--FFFFFF92 (LOADER.EXE|KernelTempAliasesEnd+F92)
--81380C68 ?
CE17BFCC (THREADS.NLM|_DestroyCallBackBlock+260)
--81380AA0 ?
--00000000 ?
--FFFFFFFF (LOADER.EXE|KernelTempAliasesEnd+FFF)
--81380C68 ?
--00000006 ?
--0000006D ?
--FFFFFF92 (LOADER.EXE|KernelTempAliasesEnd+F92)
CE17A591 (THREADS.NLM|__CHK+21)
--82EFA340 ?
--81380A60 ?
--00000006 ?
--0000006D ?
--FFFFFF92 (LOADER.EXE|KernelTempAliasesEnd+F92)
--81380C68 ?
CB8F466D (LFS.NLM|FSMonitorExit+25)
--81380AA0 ?
--00000000 ?
--00000000 ?
--00000006 ?
--0000006D ?
--FFFFFF92 (LOADER.EXE|KernelTempAliasesEnd+F92)
--81380C68 ?
--00000000 ?
--834A3180 ?
CB8F5123 (LFS.NLM|OpenFile+C6)
CBDC748F (NWSA.NSS|ZH_OpenFile+55F)
--0000006D ?
--FFFFFF92 (LOADER.EXE|KernelTempAliasesEnd+F92)
--00000000 ?
--03000A34 ?
--00000000 ?
--00000000 ?
--00000000 ?
--00000006 ?
--80000109 ?
--00000000 ?
--81380CAC ?

Additional Information:
The NetWare OS detected a problem with the system while executing a process owned by SERVER.NLM. It may be the source of the problem or there may have been a memory corruption.


Loaded modules are in attachment.


Ed Connelly
Briarwood College
connellye@briarwood.edu