Windows VM crash investigation: network traffic blocked," "DSwitch-vm," and "Synthetic MSR"
search cancel

Windows VM crash investigation: network traffic blocked," "DSwitch-vm," and "Synthetic MSR"

book

Article ID: 443141

calendar_today

Updated On:

Products

VMware vSphere ESXi

Issue/Introduction

  • A Windows virtual machine experiences an unexpected crash, Blue Screen of Death (BSOD), or appears to go offline and reconnect.
  • The VM may enter an "Invalid" or "Orphaned" state in vCenter inventory.
  • In the VM's vmware.log, entries similar to the following are found: Wa(03) vcpu-2 - WinBSOD: Synthetic MSR[0x40000100] 0x50 Wa(03) vcpu-2 - WinBSOD: Synthetic MSR[0x40000101] 0xffffffffffdff290

Environment

  • VMware vSphere ESXi 6.7, 7.x, 8.x
  • Microsoft Windows Guest Operating System

Cause

The Guest Operating System experienced a fatal kernel error (e.g., Windows Bugcheck code 0x50). The WinBSOD: Synthetic MSR logs indicate that the Windows kernel successfully trapped its own crash and transmitted the bugcheck parameters to the VMware hypervisor via Model-Specific Registers (MSRs). This confirms the crash originated within the OS layer, not the hypervisor.

Resolution

 The issue resides within the third-party Operating System. Engage Microsoft Support to perform a memory dump analysis (e.g., MEMORY.DMP) to isolate the specific faulting driver or module.

  1. Collect logs: Retrieve the vmware.log and Windows crash dump.
  2. Verify versions: Ensure VMware Tools is up to date.
  3. Relocate if necessary: If the VM is running on an unsupported host version (e.g., ESXi 6.7), migrate the VM to a supported version (ESXi 7.x or 8.x).
  4. Engage Vendor: Provide the dump file to Microsoft for root cause analysis.

Additional Information

To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on your respective region.