zoriza פורסם 2009 בינואר 13 מחבר Share פורסם 2009 בינואר 13 אנליזה לא טובה בגלל לא נטען SYMBOLE TABLE תריץ עוד פעם נכון.שגיאה IRQL_NOT_LESS_OR_EQUAL בגלל דרייבראיזה ? אי אפשר לדעת.לחשוד בדריבר בלי חתימה. לריץ הפקודהsigverif ותקבל רשימה של דריברים לא חתומים. אולי 1 מהם סיבה. לנסותלעדכן אותם. ולעדכן חלונות בכל עידכונים קריטים שיש.Microsoft (R) Windows Debugger Version 6.10.0003.233 X86Copyright (c) Microsoft Corporation. All rights reserved.Loading Dump File [C:\WINDOWS\Minidump\Mini011209-01.dmp]Mini Kernel Dump File: Only registers and stack trace are availableSymbol search path is: C:\WINDOWS\SymbolsExecutable search path is: Unable to load image ntoskrnl.exe, Win32 error 0n2*** WARNING: Unable to verify timestamp for ntoskrnl.exeWindows XP Kernel Version 2600 (Service Pack 3.3264) MP (2 procs) Free x86 compatibleProduct: WinNt, suite: TerminalServer SingleUserTSMachine Name:Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720Debug session time: Mon Jan 12 19:15:13.750 2009 (GMT+2)System Uptime: 0 days 0:02:07.484Unable to load image ntoskrnl.exe, Win32 error 0n2*** WARNING: Unable to verify timestamp for ntoskrnl.exeLoading Kernel Symbols........................................................................................................Loading User SymbolsLoading unloaded module list.....******************************************************************************** ** Bugcheck Analysis ** ********************************************************************************Use !analyze -v to get detailed debugging information.BugCheck 1000000A, {24, 2, 0, 80515da9}Probably caused by : ntoskrnl.exe ( nt!FsRtlAcquireFileForModWriteEx+26b )Followup: MachineOwner---------1: kd> !analyze -v******************************************************************************** ** Bugcheck Analysis ** ********************************************************************************IRQL_NOT_LESS_OR_EQUAL (a)An attempt was made to access a pageable (or completely invalid) address at aninterrupt request level (IRQL) that is too high. This is usuallycaused by drivers using improper addresses.If a kernel debugger is available get the stack backtrace.Arguments:Arg1: 00000024, memory referencedArg2: 00000002, IRQLArg3: 00000000, bitfield : bit 0 : value 0 = read operation, 1 = write operation bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)Arg4: 80515da9, address which referenced memoryDebugging Details:------------------READ_ADDRESS: 00000024 CURRENT_IRQL: 2FAULTING_IP: nt!FsRtlAcquireFileForModWriteEx+26b80515da9 395e24 cmp dword ptr [esi+24h],ebxCUSTOMER_CRASH_COUNT: 1DEFAULT_BUCKET_ID: DRIVER_FAULTBUGCHECK_STR: 0xAPROCESS_NAME: IEXPLORE.EXELAST_CONTROL_TRANSFER: from 00000000 to 80515da9STACK_TEXT: b706dd88 00000000 00000000 00000000 00000023 nt!FsRtlAcquireFileForModWriteEx+0x26bSTACK_COMMAND: kbFOLLOWUP_IP: nt!FsRtlAcquireFileForModWriteEx+26b80515da9 395e24 cmp dword ptr [esi+24h],ebxSYMBOL_STACK_INDEX: 0SYMBOL_NAME: nt!FsRtlAcquireFileForModWriteEx+26bFOLLOWUP_NAME: MachineOwnerMODULE_NAME: ntIMAGE_NAME: ntoskrnl.exeDEBUG_FLR_IMAGE_TIMESTAMP: 474ffa09FAILURE_BUCKET_ID: 0xA_nt!FsRtlAcquireFileForModWriteEx+26bBUCKET_ID: 0xA_nt!FsRtlAcquireFileForModWriteEx+26bFollowup: MachineOwner---------Microsoft (R) Windows Debugger Version 6.10.0003.233 X86Copyright (c) Microsoft Corporation. All rights reserved.Loading Dump File [C:\WINDOWS\Minidump\Mini011209-02.dmp]Mini Kernel Dump File: Only registers and stack trace are availableSymbol search path is: C:\WINDOWS\SymbolsExecutable search path is: Unable to load image ntoskrnl.exe, Win32 error 0n2*** WARNING: Unable to verify timestamp for ntoskrnl.exeWindows XP Kernel Version 2600 (Service Pack 3.3264) MP (2 procs) Free x86 compatibleProduct: WinNt, suite: TerminalServer SingleUserTSMachine Name:Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720Debug session time: Mon Jan 12 19:18:07.875 2009 (GMT+2)System Uptime: 0 days 0:02:28.597Unable to load image ntoskrnl.exe, Win32 error 0n2*** WARNING: Unable to verify timestamp for ntoskrnl.exeLoading Kernel Symbols........................................................................................................Loading User SymbolsLoading unloaded module list.....******************************************************************************** ** Bugcheck Analysis ** ********************************************************************************Use !analyze -v to get detailed debugging information.BugCheck 1000000A, {1c, 2, 1, 80525789}Probably caused by : ntoskrnl.exe ( nt!PoCallDriver+139 )Followup: MachineOwner---------0: kd> !analyze -v******************************************************************************** ** Bugcheck Analysis ** ********************************************************************************IRQL_NOT_LESS_OR_EQUAL (a)An attempt was made to access a pageable (or completely invalid) address at aninterrupt request level (IRQL) that is too high. This is usuallycaused by drivers using improper addresses.If a kernel debugger is available get the stack backtrace.Arguments:Arg1: 0000001c, memory referencedArg2: 00000002, IRQLArg3: 00000001, bitfield : bit 0 : value 0 = read operation, 1 = write operation bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)Arg4: 80525789, address which referenced memoryDebugging Details:------------------WRITE_ADDRESS: 0000001c CURRENT_IRQL: 2FAULTING_IP: nt!PoCallDriver+13980525789 ff4b1c dec dword ptr [ebx+1Ch]CUSTOMER_CRASH_COUNT: 2DEFAULT_BUCKET_ID: DRIVER_FAULTBUGCHECK_STR: 0xAPROCESS_NAME: rundll32.exeLAST_CONTROL_TRANSFER: from 80523d1c to 80525789STACK_TEXT: b6a2bb40 80523d1c 00000000 00000000 898e6c28 nt!PoCallDriver+0x139b6a2bb7c 80523fa0 00000000 01233000 00000000 nt!MiFreeNonPagedPool+0xb5b6a2bc44 8051a1c5 e2a453a0 012b1fff 00000000 nt!MmAccessFault+0x156b6a2bc48 e2a453a0 012b1fff 00000000 89880df8 nt!CcGetVacbMiss+0x3f2WARNING: Frame IP not in any known module. Following frames may be wrong.b6a2bcf4 805b2d71 898e6c28 89880df8 b6a2bd64 0xe2a453a0b6a2bd38 805b2e60 87cb9588 881bc6e8 00000000 nt!CcPfBootWorker+0x74b6a2bd54 8054161c ffffffff 898e6c28 00e5bca4 nt!CcPfBootWorker+0x16db6a2bd64 7c90e4f4 badb0d00 00e5bc94 00000000 nt!RtlIpv4StringToAddressExW+0x9db6a2bd78 00000000 00000000 00000000 00000000 0x7c90e4f4STACK_COMMAND: kbFOLLOWUP_IP: nt!PoCallDriver+13980525789 ff4b1c dec dword ptr [ebx+1Ch]SYMBOL_STACK_INDEX: 0SYMBOL_NAME: nt!PoCallDriver+139FOLLOWUP_NAME: MachineOwnerMODULE_NAME: ntIMAGE_NAME: ntoskrnl.exeDEBUG_FLR_IMAGE_TIMESTAMP: 474ffa09FAILURE_BUCKET_ID: 0xA_nt!PoCallDriver+139BUCKET_ID: 0xA_nt!PoCallDriver+139Followup: MachineOwner---------Microsoft (R) Windows Debugger Version 6.10.0003.233 X86Copyright (c) Microsoft Corporation. All rights reserved.Loading Dump File [C:\WINDOWS\Minidump\Mini011309-01.dmp]Mini Kernel Dump File: Only registers and stack trace are availableSymbol search path is: C:\WINDOWS\SymbolsExecutable search path is: Unable to load image ntoskrnl.exe, Win32 error 0n2*** WARNING: Unable to verify timestamp for ntoskrnl.exeWindows XP Kernel Version 2600 (Service Pack 3.5657) MP (2 procs) Free x86 compatibleProduct: WinNt, suite: TerminalServer SingleUserTSMachine Name:Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720Debug session time: Tue Jan 13 09:32:15.546 2009 (GMT+2)System Uptime: 0 days 0:04:24.265Unable to load image ntoskrnl.exe, Win32 error 0n2*** WARNING: Unable to verify timestamp for ntoskrnl.exeLoading Kernel Symbols........................................................................................................Loading User SymbolsLoading unloaded module list.....******************************************************************************** ** Bugcheck Analysis ** ********************************************************************************Use !analyze -v to get detailed debugging information.BugCheck 4E, {99, 2d810, 1, 0}Probably caused by : ntoskrnl.exe ( nt!_woutput+414 )Followup: MachineOwner---------1: kd> !analyze -v******************************************************************************** ** Bugcheck Analysis ** ********************************************************************************PFN_LIST_CORRUPT (4e)Typically caused by drivers passing bad memory descriptor lists (ie: callingMmUnlockPages twice with the same list, etc). If a kernel debugger isavailable get the stack trace.Arguments:Arg1: 00000099, A PTE or PFN is corruptArg2: 0002d810, page frame numberArg3: 00000001, current page stateArg4: 00000000, 0Debugging Details:------------------BUGCHECK_STR: 0x4E_99CUSTOMER_CRASH_COUNT: 1DEFAULT_BUCKET_ID: DRIVER_FAULTPROCESS_NAME: Firefox.exeLAST_CONTROL_TRANSFER: from 00000000 to 804f9f43STACK_TEXT: b6addbc0 00000000 0000004e 00000099 0002d810 nt!_woutput+0x414STACK_COMMAND: kbFOLLOWUP_IP: nt!_woutput+414804f9f43 5d pop ebpSYMBOL_STACK_INDEX: 0SYMBOL_NAME: nt!_woutput+414FOLLOWUP_NAME: MachineOwnerMODULE_NAME: ntIMAGE_NAME: ntoskrnl.exeDEBUG_FLR_IMAGE_TIMESTAMP: 48a3fbd9FAILURE_BUCKET_ID: 0x4E_99_nt!_woutput+414BUCKET_ID: 0x4E_99_nt!_woutput+414Followup: MachineOwner---------Microsoft (R) Windows Debugger Version 6.10.0003.233 X86Copyright (c) Microsoft Corporation. All rights reserved.Loading Dump File [C:\WINDOWS\Minidump\Mini011309-02.dmp]Mini Kernel Dump File: Only registers and stack trace are availableSymbol search path is: C:\WINDOWS\SymbolsExecutable search path is: Unable to load image ntoskrnl.exe, Win32 error 0n2*** WARNING: Unable to verify timestamp for ntoskrnl.exeWindows XP Kernel Version 2600 (Service Pack 3.5657) MP (2 procs) Free x86 compatibleProduct: WinNt, suite: TerminalServer SingleUserTSMachine Name:Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720Debug session time: Tue Jan 13 09:34:21.625 2009 (GMT+2)System Uptime: 0 days 0:01:40.359Unable to load image ntoskrnl.exe, Win32 error 0n2*** WARNING: Unable to verify timestamp for ntoskrnl.exeLoading Kernel Symbols........................................................................................................Loading User SymbolsLoading unloaded module list.....******************************************************************************** ** Bugcheck Analysis ** ********************************************************************************Use !analyze -v to get detailed debugging information.BugCheck 1000000A, {1c, 2, 1, 805257a1}*** WARNING: Unable to verify timestamp for win32k.sysProbably caused by : win32k.sys ( win32k!vCleanupBrushes+13 )Followup: MachineOwner---------1: kd> !analyze -v******************************************************************************** ** Bugcheck Analysis ** ********************************************************************************IRQL_NOT_LESS_OR_EQUAL (a)An attempt was made to access a pageable (or completely invalid) address at aninterrupt request level (IRQL) that is too high. This is usuallycaused by drivers using improper addresses.If a kernel debugger is available get the stack backtrace.Arguments:Arg1: 0000001c, memory referencedArg2: 00000002, IRQLArg3: 00000001, bitfield : bit 0 : value 0 = read operation, 1 = write operation bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)Arg4: 805257a1, address which referenced memoryDebugging Details:------------------WRITE_ADDRESS: 0000001c CURRENT_IRQL: 2FAULTING_IP: nt!PoCallDriver+14e805257a1 ff4b1c dec dword ptr [ebx+1Ch]CUSTOMER_CRASH_COUNT: 2DEFAULT_BUCKET_ID: DRIVER_FAULTBUGCHECK_STR: 0xAPROCESS_NAME: dwwin.exeLAST_CONTROL_TRANSFER: from 80523d34 to 805257a1STACK_TEXT: b6d4b894 80523d34 00000000 00000000 889f1bc8 nt!PoCallDriver+0x14eb6d4b8d0 80523fb8 00000000 00831000 00000000 nt!MiFreeNonPagedPool+0xe3b6d4b998 8051a1dc e1db5248 008effff 00000000 nt!MmAccessFault+0x18ab6d4b99c e1db5248 008effff 00000000 87f2c6e8 nt!CcGetVacbMiss+0x409WARNING: Frame IP not in any known module. Following frames may be wrong.b6d4ba48 805b2d79 889f1bc8 87f2c6e8 89893ce8 0xe1db5248b6d4ba8c 805b2e0a 87f266e8 87f2d6e8 00000000 nt!CcPfBootWorker+0x7cb6d4baa0 bf8c0a9b 889f1bc8 005f0000 89893ce8 nt!CcPfBootWorker+0x10db6d4bad4 bf8c0b84 889f1bc8 00000000 89893cd0 win32k!vCleanupBrushes+0x13b6d4baf0 8060cd9c b6d4bb34 89893cd0 00000000 win32k!OkayToCloseDesktop+0x15b6d4bb1c 8060ce5e bf8c0b42 b6d4bb34 00000000 nt!CmpDoOpen+0x1a0b6d4bb48 805bca16 889f1bc8 89893ce8 000f01ff nt!CmpAddInfoAfterParseFailure+0x330b6d4bb7c 805bc33f 889f1bc8 00000001 89db6730 nt!PopCreateHiberFile+0x9bb6d4bba4 805bc3dd e1c46c60 89893ce8 000007d0 nt!NtCreatePagingFile+0x6d4b6d4bbec 805bc4ee 000007d0 00000001 00000001 nt!MiZeroPageFileFirstPage+0x59b6d4bc00 bf8c0e42 000007d0 00000001 00000000 nt!IopCompleteDumpInitialization+0xbcb6d4bc20 bf8bc7e3 e10e4e68 e10e4e68 8983e8e8 win32k!DestroyProcessInfo+0xc9b6d4bc48 bf8bc88b e10e4e68 00000000 8983e8e8 win32k!xxxUserProcessCallout+0x53b6d4bc64 805d249b 889f1bc8 00000000 8983e8e8 win32k!xxxUserProcessCallout+0xa9b6d4bd08 805d28d4 00000000 8983e8e8 00000000 nt!IopCombineCmResourceList+0x2fb6d4bd28 805d2aaf 8983e8e8 00000000 b6d4bd64 nt!NtPowerInformation+0x413b6d4bd54 8054162c 00000000 00000000 0013ff5c nt!WmipStartLogger+0x16b6d4bd64 7c90e4f4 badb0d00 0013fe68 00000000 nt!RtlIpv4StringToAddressExW+0xadb6d4bd78 00000000 00000000 00000000 00000000 0x7c90e4f4STACK_COMMAND: kbFOLLOWUP_IP: win32k!vCleanupBrushes+13bf8c0a9b ?? ???SYMBOL_STACK_INDEX: 7SYMBOL_NAME: win32k!vCleanupBrushes+13FOLLOWUP_NAME: MachineOwnerMODULE_NAME: win32kIMAGE_NAME: win32k.sysDEBUG_FLR_IMAGE_TIMESTAMP: 48ce513aFAILURE_BUCKET_ID: 0xA_win32k!vCleanupBrushes+13BUCKET_ID: 0xA_win32k!vCleanupBrushes+13Followup: MachineOwner---------הקבצים אשר לא עברו חתימה :sfcfiles.dlluxtheme.dll קישור לתוכן שתף באתרים אחרים More sharing options...
Ivan פורסם 2009 בינואר 13 Share פורסם 2009 בינואר 13 יש או היה סקינים ששמת שלא של XP ?התקנת PATCH ל"שיפור" כל מיני דברים ?קבצים לא חתומים שלך הם לא של מיקרוסופט ! קישור לתוכן שתף באתרים אחרים More sharing options...
zoriza פורסם 2009 בינואר 13 מחבר Share פורסם 2009 בינואר 13 יש או היה סקינים ששמת שלא של XP ?התקנת PATCH ל"שיפור" כל מיני דברים ?קבצים לא חתומים שלך הם לא של מיקרוסופט !התקנתי סקינים של Vista , יכול להיות שזו הסיבה ? קישור לתוכן שתף באתרים אחרים More sharing options...
Ivan פורסם 2009 בינואר 13 Share פורסם 2009 בינואר 13 מי יודע ? כל סכויים שכן. קישור לתוכן שתף באתרים אחרים More sharing options...
עדי נסטסה פורסם 2009 בינואר 13 Share פורסם 2009 בינואר 13 תסיר את הקבצים הלא חתומים. כמה סטיקים של זיכרון יש לך?במידה ויש לך 2, תסיר אחד מהם (ולחליפין) ותבדוק אם הבעייה נפתרה.באיזה memtest השתמשת? קישור לתוכן שתף באתרים אחרים More sharing options...
zoriza פורסם 2009 בינואר 14 מחבר Share פורסם 2009 בינואר 14 תסיר את הקבצים הלא חתומים. כמה סטיקים של זיכרון יש לך?במידה ויש לך 2, תסיר אחד מהם (ולחליפין) ותבדוק אם הבעייה נפתרה.באיזה memtest השתמשת?Memtest86+ V2.11 ויש לי 4 סטיקים .הסרתי אך לצערי זה לא עזר .פירוט קובץ dump חדש :Microsoft (R) Windows Debugger Version 6.10.0003.233 X86Copyright (c) Microsoft Corporation. All rights reserved.Loading Dump File [C:\WINDOWS\Minidump\Mini011409-01.dmp]Mini Kernel Dump File: Only registers and stack trace are availableSymbol search path is: C:\WINDOWS\SymbolsExecutable search path is: Unable to load image ntoskrnl.exe, Win32 error 0n2*** WARNING: Unable to verify timestamp for ntoskrnl.exeWindows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free x86 compatibleProduct: WinNt, suite: TerminalServer SingleUserTSMachine Name:Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720Debug session time: Wed Jan 14 10:57:21.828 2009 (GMT+2)System Uptime: 0 days 0:05:02.559Unable to load image ntoskrnl.exe, Win32 error 0n2*** WARNING: Unable to verify timestamp for ntoskrnl.exeLoading Kernel Symbols....................................................................................................Loading User SymbolsLoading unloaded module list............******************************************************************************** ** Bugcheck Analysis ** ********************************************************************************Use !analyze -v to get detailed debugging information.BugCheck 7A, {2, c0000005, 8987dda0, 0}Probably caused by : ntoskrnl.exe ( nt!_woutput+414 )Followup: MachineOwner---------1: kd> !analyze -v******************************************************************************** ** Bugcheck Analysis ** ********************************************************************************KERNEL_DATA_INPAGE_ERROR (7a)The requested page of kernel data could not be read in. Typically caused bya bad block in the paging file or disk controller error. Also seeKERNEL_STACK_INPAGE_ERROR.If the error status is 0xC000000E, 0xC000009C, 0xC000009D or 0xC0000185,it means the disk subsystem has experienced a failure.If the error status is 0xC000009A, then it means the request failed becausea filesystem failed to make forward progress.Arguments:Arg1: 00000002, lock type that was held (value 1,2,3, or PTE address)Arg2: c0000005, error status (normally i/o status code)Arg3: 8987dda0, current process (virtual address for lock type 3, or PTE)Arg4: 00000000, virtual address that could not be in-paged (or PTE contents if arg1 is a PTE address)Debugging Details:------------------ERROR_CODE: (NTSTATUS) 0xc0000005 - ההוראה ב- " 0x%08lx" ביצעה הפניה לזיכרון ב- " 0x%08lx" . לזיכרון לא היתה אפשרות להיות "%s" .BUGCHECK_STR: 0x7a_c0000005CUSTOMER_CRASH_COUNT: 1DEFAULT_BUCKET_ID: DRIVER_FAULTPROCESS_NAME: explorer.exeLAST_CONTROL_TRANSFER: from 00090000 to 804f9f43STACK_TEXT: b5e79fc8 00090000 7c960202 00000003 00090718 nt!_woutput+0x414WARNING: Frame IP not in any known module. Following frames may be wrong.b5e79fd8 00090000 000c0948 0007fc50 0007fcbc 0x90000b5e79fdc 000c0948 0007fc50 0007fcbc 0007fe94 0x90000b5e79fe0 0007fc50 0007fcbc 0007fe94 006f006c 0xc0948b5e79fe4 0007fcbc 0007fe94 006f006c 00490077 0x7fc50b5e79fe8 0007fe94 006f006c 00490077 00000000 0x7fcbcb5e79fec 006f006c 00490077 00000000 00000000 0x7fe94b5e79ff0 00490077 00000000 00000000 00000000 0x6f006cb5e79ff4 00000000 00000000 00000000 00000000 0x490077STACK_COMMAND: kbFOLLOWUP_IP: nt!_woutput+414804f9f43 5d pop ebpSYMBOL_STACK_INDEX: 0SYMBOL_NAME: nt!_woutput+414FOLLOWUP_NAME: MachineOwnerMODULE_NAME: ntIMAGE_NAME: ntoskrnl.exeDEBUG_FLR_IMAGE_TIMESTAMP: 48a3fbd9FAILURE_BUCKET_ID: 0x7a_c0000005_nt!_woutput+414BUCKET_ID: 0x7a_c0000005_nt!_woutput+414Followup: MachineOwner--------- קישור לתוכן שתף באתרים אחרים More sharing options...
zoriza פורסם 2009 בינואר 15 מחבר Share פורסם 2009 בינואר 15 מי יודע ? כל סכויים שכן.ראה הודעה קודמת . קישור לתוכן שתף באתרים אחרים More sharing options...
Ivan פורסם 2009 בינואר 15 Share פורסם 2009 בינואר 15 תשמעעכשיו זה בגלל קונן קשיח שלך. צריך להריץ תיקון שגיות מלא עליו.אני חושב הגיע זמן לעשות התקנה REPAIR למערכת שלך. קישור לתוכן שתף באתרים אחרים More sharing options...
zoriza פורסם 2009 בינואר 15 מחבר Share פורסם 2009 בינואר 15 תשמעעכשיו זה בגלל קונן קשיח שלך. צריך להריץ תיקון שגיות מלא עליו.אני חושב הגיע זמן לעשות התקנה REPAIR למערכת שלך.התקנתי אתמול מערכת הפעלה חדשה ובכל זאת ישנם מסכים כחולים . איך אני מריץ תיקון תשגיאות ? קישור לתוכן שתף באתרים אחרים More sharing options...
Ivan פורסם 2009 בינואר 15 Share פורסם 2009 בינואר 15 עם פקודהchkdsk /r ב RECOVERY CONSOLE קישור לתוכן שתף באתרים אחרים More sharing options...
zoriza פורסם 2009 בינואר 17 מחבר Share פורסם 2009 בינואר 17 עם פקודהchkdsk /r ב RECOVERY CONSOLE הרצתי ובסופו של דבר היה כתוב שכל השגיאות תוקנו , בכל מקרה זה לא עזר .פירוט 2 קבצי דאמפ' האחרונים :Microsoft (R) Windows Debugger Version 6.10.0003.233 X86Copyright (c) Microsoft Corporation. All rights reserved.Loading Dump File [C:\WINDOWS\Minidump\Mini011709-01.dmp]Mini Kernel Dump File: Only registers and stack trace are availableSymbol search path is: C:\WINDOWS\SymbolsExecutable search path is: Unable to load image ntoskrnl.exe, Win32 error 0n2*** WARNING: Unable to verify timestamp for ntoskrnl.exeWindows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free x86 compatibleProduct: WinNt, suite: TerminalServer SingleUserTSMachine Name:Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720Debug session time: Sat Jan 17 10:37:02.203 2009 (GMT+2)System Uptime: 0 days 0:04:08.943Unable to load image ntoskrnl.exe, Win32 error 0n2*** WARNING: Unable to verify timestamp for ntoskrnl.exeLoading Kernel Symbols.....................................................................................................Loading User SymbolsLoading unloaded module list..............******************************************************************************** ** Bugcheck Analysis ** ********************************************************************************Use !analyze -v to get detailed debugging information.BugCheck 1000000A, {1c, 2, 1, 805257a1}Probably caused by : ntoskrnl.exe ( nt!PoCallDriver+14e )Followup: MachineOwner---------1: kd> !analyze -v******************************************************************************** ** Bugcheck Analysis ** ********************************************************************************IRQL_NOT_LESS_OR_EQUAL (a)An attempt was made to access a pageable (or completely invalid) address at aninterrupt request level (IRQL) that is too high. This is usuallycaused by drivers using improper addresses.If a kernel debugger is available get the stack backtrace.Arguments:Arg1: 0000001c, memory referencedArg2: 00000002, IRQLArg3: 00000001, bitfield : bit 0 : value 0 = read operation, 1 = write operation bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)Arg4: 805257a1, address which referenced memoryDebugging Details:------------------WRITE_ADDRESS: 0000001c CURRENT_IRQL: 2FAULTING_IP: nt!PoCallDriver+14e805257a1 ff4b1c dec dword ptr [ebx+1Ch]CUSTOMER_CRASH_COUNT: 1DEFAULT_BUCKET_ID: DRIVER_FAULTBUGCHECK_STR: 0xAPROCESS_NAME: update.exeLAST_CONTROL_TRANSFER: from 80523d34 to 805257a1STACK_TEXT: b4a3eb8c 80523d34 00000000 00000000 87c60da0 nt!PoCallDriver+0x14eb4a3ebc8 80523fb8 00000000 00e33000 00000000 nt!MiFreeNonPagedPool+0xe3b4a3ec90 8051a628 00000018 00e3ffff 00000000 nt!MmAccessFault+0x18ab4a3ecac 805b33ac 00e30000 00e3ffff b4a3ed64 nt!FsRtlAddLargeMcbEntry+0x390b4a3eccc 8150f308 00000000 c0600038 c0007180 nt!RtlStringFromGUID+0x87WARNING: Frame IP not in any known module. Following frames may be wrong.b4a3ed4c 8054162c ffffffff 00dfcf3c 00dfcf40 0x8150f308b4a3ed64 7c95e4f4 badb0d00 00dfcf18 00000000 nt!RtlIpv4StringToAddressExW+0xadb4a3ed78 00000000 00000000 00000000 00000000 0x7c95e4f4STACK_COMMAND: kbFOLLOWUP_IP: nt!PoCallDriver+14e805257a1 ff4b1c dec dword ptr [ebx+1Ch]SYMBOL_STACK_INDEX: 0SYMBOL_NAME: nt!PoCallDriver+14eFOLLOWUP_NAME: MachineOwnerMODULE_NAME: ntIMAGE_NAME: ntoskrnl.exeDEBUG_FLR_IMAGE_TIMESTAMP: 48a3fbd9FAILURE_BUCKET_ID: 0xA_nt!PoCallDriver+14eBUCKET_ID: 0xA_nt!PoCallDriver+14eFollowup: MachineOwner---------Microsoft (R) Windows Debugger Version 6.10.0003.233 X86Copyright (c) Microsoft Corporation. All rights reserved.Loading Dump File [C:\WINDOWS\Minidump\Mini011709-02.dmp]Mini Kernel Dump File: Only registers and stack trace are availableSymbol search path is: C:\WINDOWS\SymbolsExecutable search path is: Unable to load image ntoskrnl.exe, Win32 error 0n2*** WARNING: Unable to verify timestamp for ntoskrnl.exeWindows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free x86 compatibleProduct: WinNt, suite: TerminalServer SingleUserTSMachine Name:Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720Debug session time: Sat Jan 17 10:38:05.625 2009 (GMT+2)System Uptime: 0 days 0:00:36.359Unable to load image ntoskrnl.exe, Win32 error 0n2*** WARNING: Unable to verify timestamp for ntoskrnl.exeLoading Kernel Symbols.....................................................................................................Loading User SymbolsLoading unloaded module list...........******************************************************************************** ** Bugcheck Analysis ** ********************************************************************************Use !analyze -v to get detailed debugging information.BugCheck 1000000A, {1c, 2, 1, 805257a1}Probably caused by : ntoskrnl.exe ( nt!PoCallDriver+14e )Followup: MachineOwner---------1: kd> !analyze -v******************************************************************************** ** Bugcheck Analysis ** ********************************************************************************IRQL_NOT_LESS_OR_EQUAL (a)An attempt was made to access a pageable (or completely invalid) address at aninterrupt request level (IRQL) that is too high. This is usuallycaused by drivers using improper addresses.If a kernel debugger is available get the stack backtrace.Arguments:Arg1: 0000001c, memory referencedArg2: 00000002, IRQLArg3: 00000001, bitfield : bit 0 : value 0 = read operation, 1 = write operation bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)Arg4: 805257a1, address which referenced memoryDebugging Details:------------------WRITE_ADDRESS: 0000001c CURRENT_IRQL: 2FAULTING_IP: nt!PoCallDriver+14e805257a1 ff4b1c dec dword ptr [ebx+1Ch]CUSTOMER_CRASH_COUNT: 2DEFAULT_BUCKET_ID: DRIVER_FAULTBUGCHECK_STR: 0xAPROCESS_NAME: dwwin.exeLAST_CONTROL_TRANSFER: from 80523d34 to 805257a1STACK_TEXT: b59c3b40 80523d34 00000000 00000000 87b123f0 nt!PoCallDriver+0x14eb59c3b7c 80523fb8 00000000 00e31000 00000000 nt!MiFreeNonPagedPool+0xe3b59c3c44 8051a1dc e16da9a0 00e6dfff 00000000 nt!MmAccessFault+0x18ab59c3c48 e16da9a0 00e6dfff 00000000 884dc718 nt!CcGetVacbMiss+0x409WARNING: Frame IP not in any known module. Following frames may be wrong.b59c3cf4 805b2d79 87b123f0 884dc718 b59c3d64 0xe16da9a0b59c3d38 805b2e68 884db718 884f36e8 00000000 nt!CcPfBootWorker+0x7cb59c3d54 8054162c ffffffff 87b123f0 00d8d654 nt!CcPfBootWorker+0x175b59c3d64 7c95e4f4 badb0d00 00d8d3a4 02104583 nt!RtlIpv4StringToAddressExW+0xadb59c3d78 00000000 00000000 00000000 00000000 0x7c95e4f4STACK_COMMAND: kbFOLLOWUP_IP: nt!PoCallDriver+14e805257a1 ff4b1c dec dword ptr [ebx+1Ch]SYMBOL_STACK_INDEX: 0SYMBOL_NAME: nt!PoCallDriver+14eFOLLOWUP_NAME: MachineOwnerMODULE_NAME: ntIMAGE_NAME: ntoskrnl.exeDEBUG_FLR_IMAGE_TIMESTAMP: 48a3fbd9FAILURE_BUCKET_ID: 0xA_nt!PoCallDriver+14eBUCKET_ID: 0xA_nt!PoCallDriver+14eFollowup: MachineOwner--------- קישור לתוכן שתף באתרים אחרים More sharing options...
zoriza פורסם 2009 בינואר 18 מחבר Share פורסם 2009 בינואר 18 מקפיץ... קישור לתוכן שתף באתרים אחרים More sharing options...
Recommended Posts
ארכיון
דיון זה הועבר לארכיון ולא ניתן להוסיף בו תגובות חדשות.