| Previous | Next |
| SAVER_REPORTNOTIFICATIONFAILURE | SAVER_RPCFAILURE |
SAVER_UNEXPECTEDSHUTDOWN
SAVER unexpected-shutdown bucket for SAVER_UNEXPECTEDSHUTDOWN
SAVER_UNEXPECTEDSHUTDOWN is bug check code 0x0000F012. This bucket records an unexpected shutdown condition in the SAVER diagnostic family. It is not enough to explain the shutdown by itself; power, thermal, battery, bug check, and WER evidence must be correlated.
How to read it in a dump for SAVER_UNEXPECTEDSHUTDOWN
- Treat this value as an internal diagnostic bucket from the Windows SAVER family, not as a classic blue-screen stop code with public parameter semantics.
- For SAVER_UNEXPECTEDSHUTDOWN, the useful evidence is the dump type, WER bucket, triggering process, provider-specific data, and event-log context around the capture.
- For SAVER_UNEXPECTEDSHUTDOWN, the symbolic name narrows the subsystem that requested capture; it does not by itself identify a defective driver or application.
What to check for SAVER_UNEXPECTEDSHUTDOWN
- Check Kernel-Power, thermal, battery, firmware, and previous bug check records.
- Determine whether the system lost power, bug-checked, reset, or was forcibly powered off.
- Preserve event logs before repeated restarts overwrite the evidence.
References for SAVER_UNEXPECTEDSHUTDOWN
- Windows SDK bugcodes.h
- Windows Bug Check Codes research index
- Windows Error Reporting
- Microsoft Bug Check Code Reference
- Analyze a kernel-mode dump with WinDbg
Dump evidence for SAVER_UNEXPECTEDSHUTDOWN
For SAVER_UNEXPECTEDSHUTDOWN, preserve the complete dump, the four bug-check parameters, the exact Windows build, loaded-module list, and the event timeline immediately before the stop. AllStat summarizes the condition as “SAVER_UNEXPECTEDSHUTDOWN”; that sentence identifies the failure class, while the parameters and stack determine which object, driver, processor, or subsystem instance was involved.
Analysis order for SAVER_UNEXPECTEDSHUTDOWN
- Run WinDbg
!analyze -v, then inspect the documented meaning of each SAVER_UNEXPECTEDSHUTDOWN parameter instead of relying only on the probably-caused-by line. - For SAVER_UNEXPECTEDSHUTDOWN, find the earliest abnormal event: driver update, firmware change, device reset, storage error, verifier report, resource exhaustion, or application hang connected with saver / unexpectedshutdown.
- For SAVER_UNEXPECTEDSHUTDOWN, keep third-party filter, security, storage, graphics, and virtualization drivers in the module inventory; removing evidence before dump analysis can obscure the responsible path.
Do not repeatedly reboot a machine affected by SAVER_UNEXPECTEDSHUTDOWN before collecting the dump and event logs. For SAVER_UNEXPECTEDSHUTDOWN, recovery actions should follow the component identified by the stack and parameters, not merely the symbolic stop-code name.
Dump evidence for SAVER_UNEXPECTEDSHUTDOWN
For SAVER_UNEXPECTEDSHUTDOWN, preserve the complete dump, the four bug-check parameters, the exact Windows build, loaded-module list, and the event timeline immediately before the stop. AllStat summarizes the condition as “SAVER_UNEXPECTEDSHUTDOWN”; that sentence identifies the failure class, while the parameters and stack determine which object, driver, processor, or subsystem instance was involved.
Analysis order for SAVER_UNEXPECTEDSHUTDOWN
- Run WinDbg
!analyze -v, then inspect the documented meaning of each SAVER_UNEXPECTEDSHUTDOWN parameter instead of relying only on the probably-caused-by line. - For SAVER_UNEXPECTEDSHUTDOWN, find the earliest abnormal event: driver update, firmware change, device reset, storage error, verifier report, resource exhaustion, or application hang connected with saver / unexpectedshutdown.
- For SAVER_UNEXPECTEDSHUTDOWN, keep third-party filter, security, storage, graphics, and virtualization drivers in the module inventory; removing evidence before dump analysis can obscure the responsible path.
Do not repeatedly reboot a machine affected by SAVER_UNEXPECTEDSHUTDOWN before collecting the dump and event logs. For SAVER_UNEXPECTEDSHUTDOWN, recovery actions should follow the component identified by the stack and parameters, not merely the symbolic stop-code name.
Looking for a different code? Search another status or error code.