MtK Posted September 19, 2007 Author Posted September 19, 2007 have you managed to download the file?
cluberti Posted September 19, 2007 Posted September 19, 2007 Everytime I do I get a crc error on extraction - can you extract the original rar file on your box without error?
MtK Posted September 19, 2007 Author Posted September 19, 2007 Everytime I do I get a crc error on extraction - can you extract the original rar file on your box without error?**** (sorry) - you're right...have you checked the file I've uploaded to your server?I'll upload again anyway...
MtK Posted September 20, 2007 Author Posted September 20, 2007 I've uploaded again a working RAR to my Server.The copy to your server is on the way...
cluberti Posted September 30, 2007 Posted September 30, 2007 Sorry, I haven't had the chance to take a look at the file yet. I'll see if I can get to it tomorrow or Monday .
MtK Posted September 30, 2007 Author Posted September 30, 2007 Sorry, I haven't had the chance to take a look at the file yet. I'll see if I can get to it tomorrow or Monday .10x, let me know...
MtK Posted November 14, 2007 Author Posted November 14, 2007 can any1 tell me how to check the DUMP, or anything else to do?
cluberti Posted November 14, 2007 Posted November 14, 2007 Open the dump file in windbg, then run ".symfix", then "!locks" and output here.I cannot get that dump file no matter what I try.
MtK Posted November 15, 2007 Author Posted November 15, 2007 I think something went wrong:Microsoft (R) Windows Debugger Version 6.6.0007.5Copyright (c) Microsoft Corporation. All rights reserved.Loading Dump File [C:\Windows\MEMORY.DMP]Kernel Complete Dump File: Full address space is availableSymbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols;c:\websymbolsExecutable search path is: **************************************************************************THIS DUMP FILE IS PARTIALLY CORRUPT.KdDebuggerDataBlock is not present or unreadable.**************************************************************************Unable to read PsLoadedModuleList**************************************************************************THIS DUMP FILE IS PARTIALLY CORRUPT.KdDebuggerDataBlock is not present or unreadable.**************************************************************************KdDebuggerData.KernBase < SystemRangeStartWindows Vista Kernel Version 6000 MP (2 procs) Free x86 compatibleProduct: WinNt, suite: TerminalServer SingleUserTSKernel base = 0x00000000 PsLoadedModuleList = 0x82908ad0Debug session time: Sat Nov 10 23:11:54.187 2007 (GMT+2)System Uptime: 0 days 0:16:36.814**************************************************************************THIS DUMP FILE IS PARTIALLY CORRUPT.KdDebuggerDataBlock is not present or unreadable.**************************************************************************Unable to read PsLoadedModuleList**************************************************************************THIS DUMP FILE IS PARTIALLY CORRUPT.KdDebuggerDataBlock is not present or unreadable.**************************************************************************KdDebuggerData.KernBase < SystemRangeStartLoading Kernel SymbolsUnable to read PsLoadedModuleListGetContextState failed, 0xD0000147GetContextState failed, 0xD0000147CS descriptor lookup failedGetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147Unable to get program counterGetContextState failed, 0xD0000147Unable to get current machine context, NTSTATUS 0xC0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147******************************************************************************** ** Bugcheck Analysis ** ********************************************************************************Use !analyze -v to get detailed debugging information.BugCheck 1A, {41287, 5f180010, 0, 0}***** Debugger could not find nt in module list, module list might be corrupt, error 0x80070057.GetContextState failed, 0xD0000147Unable to read selector for PCR for processor 0GetContextState failed, 0xD0000147Unable to read selector for PCR for processor 0GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147Unable to get current machine context, NTSTATUS 0xC0000147GetContextState failed, 0xD0000147Unable to get current machine context, NTSTATUS 0xC0000147GetContextState failed, 0xD0000147Unable to get current machine context, NTSTATUS 0xC0000147GetContextState failed, 0xD0000147Unable to get current machine context, NTSTATUS 0xC0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147Unable to get current machine context, NTSTATUS 0xC0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147Unable to get current machine context, NTSTATUS 0xC0000147GetContextState failed, 0xD0000147Unable to get current machine context, NTSTATUS 0xC0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147Unable to get current machine context, NTSTATUS 0xC0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147Unable to get current machine context, NTSTATUS 0xC0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147Unable to get current machine context, NTSTATUS 0xC0000147Probably caused by : Unknown_Image ( ANALYSIS_INCONCLUSIVE )Followup: MachineOwner---------GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147?: kd> .symfixNo downstream store given, using C:\Program Files\Debugging Tools for Windows\symGetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147GetContextState failed, 0xD0000147?: kd> !locksGetContextState failed, 0xD0000147GetContextState failed, 0xD0000147Unable to get program counterUnable to read PsLoadedModuleList**** DUMP OF ALL RESOURCE OBJECTS ****00000000: Unable to get value of ExpSystemResourcesListGetContextState failed, 0xD0000147GetContextState failed, 0xD0000147
MtK Posted November 15, 2007 Author Posted November 15, 2007 OK, this is much better:Microsoft (R) Windows Debugger Version 6.6.0007.5Copyright (c) Microsoft Corporation. All rights reserved.Loading Dump File [C:\Users\mtk\Desktop\MEMORY.DMP]Kernel Complete Dump File: Full address space is availableSymbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols;c:\websymbolsExecutable search path is: Windows Vista Kernel Version 6000 MP (2 procs) Free x86 compatibleProduct: WinNt, suite: TerminalServer SingleUserTSBuilt by: 6000.16514.x86fre.vista_gdr.070627-1500Kernel base = 0x82400000 PsLoadedModuleList = 0x82508ab0Debug session time: Wed Sep 19 22:17:50.716 2007 (GMT+2)System Uptime: 0 days 3:08:28.865Loading Kernel Symbols................................................................................................................................................................Loading User Symbols....................................................................................................................Loading unloaded module list.....Unable to enumerate user-mode unloaded modules, NTSTATUS 0xC0000147******************************************************************************** ** Bugcheck Analysis ** ********************************************************************************Use !analyze -v to get detailed debugging information.BugCheck E2, {0, 0, 0, 0}Probably caused by : i8042prt.sys ( i8042prt!I8xProcessCrashDump+255 )Followup: MachineOwner---------0: kd> .symfixNo downstream store given, using C:\Program Files\Debugging Tools for Windows\sym0: kd> !locks**** DUMP OF ALL RESOURCE OBJECTS ****KD: Scanning for held locks...............................................................................................................................................................................................................................................Resource @ 0x88c55f80 Shared 1 owning threads Contention Count = 1 Threads: 8893bd78-01<*> KD: Scanning for held locks.................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................34080 total locks, 1 locks currently held0: kd> !analyze -v******************************************************************************** ** Bugcheck Analysis ** ********************************************************************************MANUALLY_INITIATED_CRASH (e2)The user manually initiated this crash dump.Arguments:Arg1: 00000000Arg2: 00000000Arg3: 00000000Arg4: 00000000Debugging Details:------------------BUGCHECK_STR: MANUALLY_INITIATED_CRASHDEFAULT_BUCKET_ID: VISTA_RCPROCESS_NAME: svchost.exeCURRENT_IRQL: 6LAST_CONTROL_TRANSFER: from 8d02c472 to 824acedfSTACK_TEXT: 89fb5de4 8d02c472 000000e2 00000000 00000000 nt!KeBugCheckEx+0x1e89fb5e14 8d02a37a 002f95e0 474b28c6 00000000 i8042prt!I8xProcessCrashDump+0x25589fb5e5c 82437051 8736a000 872f9528 00000000 i8042prt!I8042KeyboardInterruptService+0x21e89fb5e5c 89d8641b 8736a000 872f9528 00000000 nt!KiInterruptDispatch+0x51WARNING: Frame IP not in any known module. Following frames may be wrong.89fb5f84 82436e35 00000100 00000072 000001ff 0x89d8641b89fb5f84 00000000 00000100 00000072 000001ff nt!KiChainedDispatch+0x65STACK_COMMAND: kbFOLLOWUP_IP: i8042prt!I8xProcessCrashDump+2558d02c472 83fe01 cmp esi,1SYMBOL_STACK_INDEX: 1FOLLOWUP_NAME: MachineOwnerMODULE_NAME: i8042prtIMAGE_NAME: i8042prt.sysDEBUG_FLR_IMAGE_TIMESTAMP: 4549b180SYMBOL_NAME: i8042prt!I8xProcessCrashDump+255FAILURE_BUCKET_ID: MANUALLY_INITIATED_CRASH_i8042prt!I8xProcessCrashDump+255BUCKET_ID: MANUALLY_INITIATED_CRASH_i8042prt!I8xProcessCrashDump+255Followup: MachineOwner---------as you can see I even used "!analyze -v".is i8042prt.sys the problem? isn't this a mouse port?how it is related to my hibernation problem?
cluberti Posted November 15, 2007 Posted November 15, 2007 is i8042prt.sys the problem? isn't this a mouse port?how it is related to my hibernation problem?It only shows up because you crashed it with the keyboard (hence, i8042prt). You can't use !analyze -v on a manual crash . Anyway, run the same commands, but this time, also run the commands ".thread 8893bd78", ".reload /user", and "!thread 8893bd78" in that order.
MtK Posted November 15, 2007 Author Posted November 15, 2007 Microsoft (R) Windows Debugger Version 6.6.0007.5Copyright (c) Microsoft Corporation. All rights reserved.Loading Dump File [C:\Users\mtk\Desktop\MEMORY.DMP]Kernel Complete Dump File: Full address space is availableSymbol search path is: SRV**http://msdl.microsoft.com/download/symbols;SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols;c:\websymbolsExecutable search path is: Windows Vista Kernel Version 6000 MP (2 procs) Free x86 compatibleProduct: WinNt, suite: TerminalServer SingleUserTSBuilt by: 6000.16514.x86fre.vista_gdr.070627-1500Kernel base = 0x82400000 PsLoadedModuleList = 0x82508ab0Debug session time: Wed Sep 19 22:17:50.716 2007 (GMT+2)System Uptime: 0 days 3:08:28.865Loading Kernel Symbols................................................................................................................................................................Loading User Symbols....................................................................................................................Loading unloaded module list.....Unable to enumerate user-mode unloaded modules, NTSTATUS 0xC0000147******************************************************************************** ** Bugcheck Analysis ** ********************************************************************************Use !analyze -v to get detailed debugging information.BugCheck E2, {0, 0, 0, 0}Probably caused by : i8042prt.sys ( i8042prt!I8xProcessCrashDump+255 )Followup: MachineOwner---------0: kd> .symfixNo downstream store given, using C:\Program Files\Debugging Tools for Windows\sym0: kd> !locks**** DUMP OF ALL RESOURCE OBJECTS ****KD: Scanning for held locks...............................................................................................................................................................................................................................................Resource @ 0x88c55f80 Shared 1 owning threads Contention Count = 1 Threads: 8893bd78-01<*> KD: Scanning for held locks.................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................34080 total locks, 1 locks currently held0: kd> .thread 8893bd78Implicit thread is now 8893bd780: kd> .reload /userLoading User Symbols....................................................................................................................*** ERROR: Symbol file could not be found. Defaulted to export symbols for ntdll.dll - 0: kd> !thread 8893bd78THREAD 8893bd78 Cid 0470.0f44 Teb: 7ff8a000 Win32Thread: 00000000 WAIT: (Executive) KernelMode Non-Alertable 9b096c64 NotificationEventIRP List: 86db1de0: (0006,0220) Flags: 00020900 Mdl: 00000000 86cff100: (0006,0220) Flags: 00000884 Mdl: 00000000Impersonation token: a0512360 (Level Impersonation)Owning Process 88eda550 Image: svchost.exeWait Start TickCount 724917 Ticks: 5 (0:00:00:00.078)Context Switch Count 115839 UserTime 00:00:00.0374KernelTime 00:00:28.0969Win32 Start Address sysmain!PfRbPrefetchWorker (0x6f524b78)Stack Init 9b098000 Current 9b096a38 Base 9b098000 Limit 9b095000 Call 0Priority 9 BasePriority 7 PriorityDecrement 1*** ERROR: Module load completed but symbols could not be loaded for amon.sysChildEBP RetAddr Args to Child 9b096a50 824697c6 8893be00 8893bd78 8893be30 nt!KiSwapContext+0x26 (FPO: [Uses EBP] [0,0,4])9b096a8c 8246721c 8893bd78 9b096b14 9b096d10 nt!KiSwapThread+0x36d9b096ae8 830bed88 9b096c64 00000000 00000000 nt!KeWaitForSingleObject+0x4149b096b08 830ba3a6 9b096d10 00000000 00000000 Ntfs!NtfsWaitOnIo+0x1c (FPO: [Non-Fpo])9b096c2c 830b6241 9b096d10 86cd8cf8 a2d3a610 Ntfs!NtfsNonCachedIo+0x402 (FPO: [Non-Fpo])9b096d00 830b5282 9b096d10 86cd8cf8 00c0070a Ntfs!NtfsCommonRead+0xefd (FPO: [Non-Fpo])9b096e38 82467928 8654f498 86cd8cf8 86cd8cf8 Ntfs!NtfsFsdRead+0x273 (FPO: [Non-Fpo])9b096e50 8332ca5c 86548438 86cd8cf8 00000000 nt!IofCallDriver+0x639b096e74 8332cc18 9b096e94 86548438 00000000 fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x22a (FPO: [Non-Fpo])9b096eac 82467928 86548438 86cd8cf8 982ed2b4 fltmgr!FltpDispatch+0xc2 (FPO: [Non-Fpo])9b096ec4 982a96b6 00000000 8715b2a8 82467928 nt!IofCallDriver+0x63WARNING: Stack unwind information not available. Following frames may be wrong.9b096ee8 8249ab0e 8a24ba34 8a24ba54 8893bd78 amon+0x46b69b096f04 82459a11 00000043 8893bd78 8a24ba60 nt!IoPageRead+0x1769b096fb8 82457f18 c4b80000 b732a5f0 00000000 nt!MiDispatchFault+0xbde9b097028 82497b7d 00000000 c4b80000 00000000 nt!MmAccessFault+0xe369b097070 825d77f1 c4b80000 00000000 9b09cbbc nt!MmCheckCachedPageState+0x69b9b0970fc 830b4c8c 86b2c028 9b097140 000001ff nt!CcCopyRead+0x4179b097128 830b62a7 86b9b760 86b2c028 86db1de0 Ntfs!NtfsCachedRead+0x11e (FPO: [Non-Fpo])9b097204 830b5282 86b9b760 86db1de0 9b8a7ca0 Ntfs!NtfsCommonRead+0xf63 (FPO: [Non-Fpo])9b097274 82467928 8654f498 86db1de0 86db1de0 Ntfs!NtfsFsdRead+0x273 (FPO: [Non-Fpo])9b09728c 8332ca5c 86548438 86db1de0 00000000 nt!IofCallDriver+0x639b0972b0 8332cc18 9b0972d0 86548438 00000000 fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x22a (FPO: [Non-Fpo])9b0972e8 82467928 86548438 86db1de0 982ed2b4 fltmgr!FltpDispatch+0xc2 (FPO: [Non-Fpo])9b097300 982a96b6 86b2c028 8715b2a8 82467928 nt!IofCallDriver+0x639b097324 825c80bb 86db1de0 86db1fdc 86b2c028 amon+0x46b69b097344 825e084b 8715b2a8 86b2c028 00000001 nt!IopSynchronousServiceTail+0x1e09b0973d0 82445f7a 8715b2a8 86db1de0 00000000 nt!NtReadFile+0x6469b0973d0 82444959 8715b2a8 86db1de0 00000000 nt!KiFastCallEntry+0x12a (FPO: [0,3] TrapFrame @ 9b0973fc)9b09746c 982aa26c 000007c8 00000000 00000000 nt!ZwReadFile+0x11 (FPO: [9,0,0])9b0974a8 982aac7e 000007c8 890e2308 000001ff amon+0x526c9b0974cc 982a92c7 890e22e8 00000000 00000000 amon+0x5c7e9b097518 82467928 8715b2a8 86cff100 88ec0bb4 amon+0x42c79b097530 825c8e87 9b09cea8 88fe4c10 86475d20 nt!IofCallDriver+0x639b0975e8 8261857b 8715b2a8 00000000 86c7f008 nt!IopParseDevice+0xcff9b097620 825da839 88fe4c10 00000000 86c7f008 nt!IopParseFile+0x469b0976b0 825cc97e 80000810 9b097708 00000240 nt!ObpLookupObjectName+0x13e9b097710 825f1f9c 9b09795c 00000000 8654f500 nt!ObOpenObjectByName+0x13c9b097784 8261c4fc 9b097938 00000081 9b09795c nt!IopCreateFile+0x5ec9b0977e0 83340c2a 9b097938 00000081 9b09795c nt!IoCreateFileEx+0x9d9b097864 83321042 85b81530 00000000 9b097938 fltmgr!FltCreateFileEx2+0xae (FPO: [Non-Fpo])
cluberti Posted November 15, 2007 Posted November 15, 2007 Great - same thing as previous, but now add "!irp 86db1de0", "!irp 86cff100", and "lmvm amon"
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now