Jump to content

Black Hibernate


MtK

Recommended Posts


Everytime I do I get a crc error on extraction - can you extract the original rar file on your box without error?

**** (sorry) - you're right...

have you checked the file I've uploaded to your server?

I'll upload again anyway...

Link to comment
Share on other sites

  • 2 weeks later...
  • 2 weeks later...
  • 5 weeks later...

I think something went wrong:

Microsoft (R) Windows Debugger  Version 6.6.0007.5
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Windows\MEMORY.DMP]
Kernel Complete Dump File: Full address space is available

Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols;c:\websymbols
Executable search path is:
**************************************************************************
THIS DUMP FILE IS PARTIALLY CORRUPT.
KdDebuggerDataBlock is not present or unreadable.
**************************************************************************
Unable to read PsLoadedModuleList
**************************************************************************
THIS DUMP FILE IS PARTIALLY CORRUPT.
KdDebuggerDataBlock is not present or unreadable.
**************************************************************************
KdDebuggerData.KernBase < SystemRangeStart
Windows Vista Kernel Version 6000 MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Kernel base = 0x00000000 PsLoadedModuleList = 0x82908ad0
Debug session time: Sat Nov 10 23:11:54.187 2007 (GMT+2)
System Uptime: 0 days 0:16:36.814
**************************************************************************
THIS DUMP FILE IS PARTIALLY CORRUPT.
KdDebuggerDataBlock is not present or unreadable.
**************************************************************************
Unable to read PsLoadedModuleList
**************************************************************************
THIS DUMP FILE IS PARTIALLY CORRUPT.
KdDebuggerDataBlock is not present or unreadable.
**************************************************************************
KdDebuggerData.KernBase < SystemRangeStart
Loading Kernel Symbols
Unable to read PsLoadedModuleList
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
CS descriptor lookup failed
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
Unable to get program counterGetContextState failed, 0xD0000147
Unable to get current machine context, NTSTATUS 0xC0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 1A, {41287, 5f180010, 0, 0}

***** Debugger could not find nt in module list, module list might be corrupt, error 0x80070057.

GetContextState failed, 0xD0000147
Unable to read selector for PCR for processor 0
GetContextState failed, 0xD0000147
Unable to read selector for PCR for processor 0
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
Unable to get current machine context, NTSTATUS 0xC0000147
GetContextState failed, 0xD0000147
Unable to get current machine context, NTSTATUS 0xC0000147
GetContextState failed, 0xD0000147
Unable to get current machine context, NTSTATUS 0xC0000147
GetContextState failed, 0xD0000147
Unable to get current machine context, NTSTATUS 0xC0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
Unable to get current machine context, NTSTATUS 0xC0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
Unable to get current machine context, NTSTATUS 0xC0000147
GetContextState failed, 0xD0000147
Unable to get current machine context, NTSTATUS 0xC0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
Unable to get current machine context, NTSTATUS 0xC0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
Unable to get current machine context, NTSTATUS 0xC0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
Unable to get current machine context, NTSTATUS 0xC0000147
Probably caused by : Unknown_Image ( ANALYSIS_INCONCLUSIVE )

Followup: MachineOwner
---------

GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
?: kd> .symfix
No downstream store given, using C:\Program Files\Debugging Tools for Windows\sym
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
?: kd> !locks
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147
Unable to get program counterUnable to read PsLoadedModuleList
**** DUMP OF ALL RESOURCE OBJECTS ****
00000000: Unable to get value of ExpSystemResourcesList
GetContextState failed, 0xD0000147
GetContextState failed, 0xD0000147

Link to comment
Share on other sites

OK, this is much better:

Microsoft (R) Windows Debugger  Version 6.6.0007.5
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Users\mtk\Desktop\MEMORY.DMP]
Kernel Complete Dump File: Full address space is available

Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols;c:\websymbols
Executable search path is:
Windows Vista Kernel Version 6000 MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 6000.16514.x86fre.vista_gdr.070627-1500
Kernel base = 0x82400000 PsLoadedModuleList = 0x82508ab0
Debug session time: Wed Sep 19 22:17:50.716 2007 (GMT+2)
System Uptime: 0 days 3:08:28.865
Loading Kernel Symbols
....................................................................................................
............................................................
Loading User Symbols
....................................................................................................
................
Loading unloaded module list
.....Unable to enumerate user-mode unloaded modules, NTSTATUS 0xC0000147
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck E2, {0, 0, 0, 0}

Probably caused by : i8042prt.sys ( i8042prt!I8xProcessCrashDump+255 )

Followup: MachineOwner
---------

0: kd> .symfix
No downstream store given, using C:\Program Files\Debugging Tools for Windows\sym
0: kd> !locks
**** DUMP OF ALL RESOURCE OBJECTS ****
KD: Scanning for held locks...............................................................................................
....................................................................................................
............................................

Resource @ 0x88c55f80 Shared 1 owning threads
Contention Count = 1
Threads: 8893bd78-01<*>
KD: Scanning for held locks...............................................................................................
....................................................................................................
....................................................................................................
....................................................................................................
....................................................................................................
....................................................................................................
....................................................................................................
....................................................................................................
......................
34080 total locks, 1 locks currently held
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

MANUALLY_INITIATED_CRASH (e2)
The user manually initiated this crash dump.
Arguments:
Arg1: 00000000
Arg2: 00000000
Arg3: 00000000
Arg4: 00000000

Debugging Details:
------------------


BUGCHECK_STR: MANUALLY_INITIATED_CRASH

DEFAULT_BUCKET_ID: VISTA_RC

PROCESS_NAME: svchost.exe

CURRENT_IRQL: 6

LAST_CONTROL_TRANSFER: from 8d02c472 to 824acedf

STACK_TEXT:
89fb5de4 8d02c472 000000e2 00000000 00000000 nt!KeBugCheckEx+0x1e
89fb5e14 8d02a37a 002f95e0 474b28c6 00000000 i8042prt!I8xProcessCrashDump+0x255
89fb5e5c 82437051 8736a000 872f9528 00000000 i8042prt!I8042KeyboardInterruptService+0x21e
89fb5e5c 89d8641b 8736a000 872f9528 00000000 nt!KiInterruptDispatch+0x51
WARNING: Frame IP not in any known module. Following frames may be wrong.
89fb5f84 82436e35 00000100 00000072 000001ff 0x89d8641b
89fb5f84 00000000 00000100 00000072 000001ff nt!KiChainedDispatch+0x65


STACK_COMMAND: kb

FOLLOWUP_IP:
i8042prt!I8xProcessCrashDump+255
8d02c472 83fe01 cmp esi,1

SYMBOL_STACK_INDEX: 1

FOLLOWUP_NAME: MachineOwner

MODULE_NAME: i8042prt

IMAGE_NAME: i8042prt.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 4549b180

SYMBOL_NAME: i8042prt!I8xProcessCrashDump+255

FAILURE_BUCKET_ID: MANUALLY_INITIATED_CRASH_i8042prt!I8xProcessCrashDump+255

BUCKET_ID: MANUALLY_INITIATED_CRASH_i8042prt!I8xProcessCrashDump+255

Followup: MachineOwner
---------

as you can see I even used "!analyze -v".

is i8042prt.sys the problem? isn't this a mouse port?

how it is related to my hibernation problem?

Link to comment
Share on other sites

is i8042prt.sys the problem? isn't this a mouse port?

how it is related to my hibernation problem?

It only shows up because you crashed it with the keyboard (hence, i8042prt). You can't use !analyze -v on a manual crash :). Anyway, run the same commands, but this time, also run the commands ".thread 8893bd78", ".reload /user", and "!thread 8893bd78" in that order.

Link to comment
Share on other sites

Microsoft (R) Windows Debugger  Version 6.6.0007.5
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Users\mtk\Desktop\MEMORY.DMP]
Kernel Complete Dump File: Full address space is available

Symbol search path is: SRV**http://msdl.microsoft.com/download/symbols;SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols;c:\websymbols
Executable search path is:
Windows Vista Kernel Version 6000 MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 6000.16514.x86fre.vista_gdr.070627-1500
Kernel base = 0x82400000 PsLoadedModuleList = 0x82508ab0
Debug session time: Wed Sep 19 22:17:50.716 2007 (GMT+2)
System Uptime: 0 days 3:08:28.865
Loading Kernel Symbols
....................................................................................................
............................................................
Loading User Symbols
....................................................................................................
................
Loading unloaded module list
.....Unable to enumerate user-mode unloaded modules, NTSTATUS 0xC0000147
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck E2, {0, 0, 0, 0}

Probably caused by : i8042prt.sys ( i8042prt!I8xProcessCrashDump+255 )

Followup: MachineOwner
---------

0: kd> .symfix
No downstream store given, using C:\Program Files\Debugging Tools for Windows\sym
0: kd> !locks
**** DUMP OF ALL RESOURCE OBJECTS ****
KD: Scanning for held locks...............................................................................................
....................................................................................................
............................................

Resource @ 0x88c55f80 Shared 1 owning threads
Contention Count = 1
Threads: 8893bd78-01<*>
KD: Scanning for held locks...............................................................................................
....................................................................................................
....................................................................................................
....................................................................................................
....................................................................................................
....................................................................................................
....................................................................................................
....................................................................................................
......................
34080 total locks, 1 locks currently held
0: kd> .thread 8893bd78
Implicit thread is now 8893bd78
0: kd> .reload /user
Loading User Symbols
....................................................................................................
................
*** ERROR: Symbol file could not be found. Defaulted to export symbols for ntdll.dll -
0: kd> !thread 8893bd78
THREAD 8893bd78 Cid 0470.0f44 Teb: 7ff8a000 Win32Thread: 00000000 WAIT: (Executive) KernelMode Non-Alertable
9b096c64 NotificationEvent
IRP List:
86db1de0: (0006,0220) Flags: 00020900 Mdl: 00000000
86cff100: (0006,0220) Flags: 00000884 Mdl: 00000000
Impersonation token: a0512360 (Level Impersonation)
Owning Process 88eda550 Image: svchost.exe
Wait Start TickCount 724917 Ticks: 5 (0:00:00:00.078)
Context Switch Count 115839
UserTime 00:00:00.0374
KernelTime 00:00:28.0969
Win32 Start Address sysmain!PfRbPrefetchWorker (0x6f524b78)
Stack Init 9b098000 Current 9b096a38 Base 9b098000 Limit 9b095000 Call 0
Priority 9 BasePriority 7 PriorityDecrement 1
*** ERROR: Module load completed but symbols could not be loaded for amon.sys
ChildEBP RetAddr Args to Child
9b096a50 824697c6 8893be00 8893bd78 8893be30 nt!KiSwapContext+0x26 (FPO: [Uses EBP] [0,0,4])
9b096a8c 8246721c 8893bd78 9b096b14 9b096d10 nt!KiSwapThread+0x36d
9b096ae8 830bed88 9b096c64 00000000 00000000 nt!KeWaitForSingleObject+0x414
9b096b08 830ba3a6 9b096d10 00000000 00000000 Ntfs!NtfsWaitOnIo+0x1c (FPO: [Non-Fpo])
9b096c2c 830b6241 9b096d10 86cd8cf8 a2d3a610 Ntfs!NtfsNonCachedIo+0x402 (FPO: [Non-Fpo])
9b096d00 830b5282 9b096d10 86cd8cf8 00c0070a Ntfs!NtfsCommonRead+0xefd (FPO: [Non-Fpo])
9b096e38 82467928 8654f498 86cd8cf8 86cd8cf8 Ntfs!NtfsFsdRead+0x273 (FPO: [Non-Fpo])
9b096e50 8332ca5c 86548438 86cd8cf8 00000000 nt!IofCallDriver+0x63
9b096e74 8332cc18 9b096e94 86548438 00000000 fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x22a (FPO: [Non-Fpo])
9b096eac 82467928 86548438 86cd8cf8 982ed2b4 fltmgr!FltpDispatch+0xc2 (FPO: [Non-Fpo])
9b096ec4 982a96b6 00000000 8715b2a8 82467928 nt!IofCallDriver+0x63
WARNING: Stack unwind information not available. Following frames may be wrong.
9b096ee8 8249ab0e 8a24ba34 8a24ba54 8893bd78 amon+0x46b6
9b096f04 82459a11 00000043 8893bd78 8a24ba60 nt!IoPageRead+0x176
9b096fb8 82457f18 c4b80000 b732a5f0 00000000 nt!MiDispatchFault+0xbde
9b097028 82497b7d 00000000 c4b80000 00000000 nt!MmAccessFault+0xe36
9b097070 825d77f1 c4b80000 00000000 9b09cbbc nt!MmCheckCachedPageState+0x69b
9b0970fc 830b4c8c 86b2c028 9b097140 000001ff nt!CcCopyRead+0x417
9b097128 830b62a7 86b9b760 86b2c028 86db1de0 Ntfs!NtfsCachedRead+0x11e (FPO: [Non-Fpo])
9b097204 830b5282 86b9b760 86db1de0 9b8a7ca0 Ntfs!NtfsCommonRead+0xf63 (FPO: [Non-Fpo])
9b097274 82467928 8654f498 86db1de0 86db1de0 Ntfs!NtfsFsdRead+0x273 (FPO: [Non-Fpo])
9b09728c 8332ca5c 86548438 86db1de0 00000000 nt!IofCallDriver+0x63
9b0972b0 8332cc18 9b0972d0 86548438 00000000 fltmgr!FltpLegacyProcessingAfterPreCallbacksCompleted+0x22a (FPO: [Non-Fpo])
9b0972e8 82467928 86548438 86db1de0 982ed2b4 fltmgr!FltpDispatch+0xc2 (FPO: [Non-Fpo])
9b097300 982a96b6 86b2c028 8715b2a8 82467928 nt!IofCallDriver+0x63
9b097324 825c80bb 86db1de0 86db1fdc 86b2c028 amon+0x46b6
9b097344 825e084b 8715b2a8 86b2c028 00000001 nt!IopSynchronousServiceTail+0x1e0
9b0973d0 82445f7a 8715b2a8 86db1de0 00000000 nt!NtReadFile+0x646
9b0973d0 82444959 8715b2a8 86db1de0 00000000 nt!KiFastCallEntry+0x12a (FPO: [0,3] TrapFrame @ 9b0973fc)
9b09746c 982aa26c 000007c8 00000000 00000000 nt!ZwReadFile+0x11 (FPO: [9,0,0])
9b0974a8 982aac7e 000007c8 890e2308 000001ff amon+0x526c
9b0974cc 982a92c7 890e22e8 00000000 00000000 amon+0x5c7e
9b097518 82467928 8715b2a8 86cff100 88ec0bb4 amon+0x42c7
9b097530 825c8e87 9b09cea8 88fe4c10 86475d20 nt!IofCallDriver+0x63
9b0975e8 8261857b 8715b2a8 00000000 86c7f008 nt!IopParseDevice+0xcff
9b097620 825da839 88fe4c10 00000000 86c7f008 nt!IopParseFile+0x46
9b0976b0 825cc97e 80000810 9b097708 00000240 nt!ObpLookupObjectName+0x13e
9b097710 825f1f9c 9b09795c 00000000 8654f500 nt!ObOpenObjectByName+0x13c
9b097784 8261c4fc 9b097938 00000081 9b09795c nt!IopCreateFile+0x5ec
9b0977e0 83340c2a 9b097938 00000081 9b09795c nt!IoCreateFileEx+0x9d
9b097864 83321042 85b81530 00000000 9b097938 fltmgr!FltCreateFileEx2+0xae (FPO: [Non-Fpo])

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...