Имя пользователя:
Пароль:
 

Показать сообщение отдельно

Аватара для Chinaski

Пользователь


Сообщения: 122
Благодарности: 14

Профиль | Отправить PM | Цитировать


Прописывал я уже по всякому. Вообще символы я качал. Скачал для Windows 7 and Windows Server 2008 R2 - Windows 7 Service Pack 1 x86 retail symbols, all languages. Установил. Предварительно была создана папка c:\windows\symbols, при установке вопросов куда ставить не задавалось. В папку c:\windows\symbols, конечно кое что записалось, размер ее стал 19мб. Зато на диске е: создалась папка symbols и размер ее 1,6гб.
Вообще как я понимаю, при желании на своем ПК свободно анализировать такие дампы я должен скачать и установить символы для всех возможных операционных систем на которых создавался лог? Или я качаю в зависимости от своей ОС?
Указал SRV*E:\Symbols*http://msdl.microsoft.com/download/symbols, вывод такой
Код: Выделить весь код
Microsoft (R) Windows Debugger Version 6.3.9600.17237 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\ProcDump\explorer.exe_141024_124537.dmp]
Comment: '
*** c:\ProcDump\procdump.exe  -accepteula -e -w explorer.exe c:\ProcDump\
*** Unhandled exception: C0000005.ACCESS_VIOLATION'
User Mini Dump File: Only registers, stack and portions of memory are available


************* Symbol Path validation summary **************
Response                         Time (ms)     Location
Deferred                                       SRV*E:\symbols*http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*E:\symbols*http://msdl.microsoft.com/download/symbols
Executable search path is: 
Windows 7 Version 7601 (Service Pack 1) MP (2 procs) Free x86 compatible
Product: WinNt, suite: SingleUserTS
Machine Name:
Debug session time: Fri Oct 24 11:45:40.000 2014 (UTC + 3:00)
System Uptime: not available
Process Uptime: 0 days 0:50:04.000
................................................................
................................................................
..........................................................
Loading unloaded module list
................................................................
This dump file has an exception of interest stored in it.
The stored exception information can be accessed via .ecxr.
(c00.3dc): Access violation - code c0000005 (first/second chance not available)
eax=01a4d710 ebx=01aac680 ecx=3c67d6fb edx=e97fae3b esi=01a4d708 edi=00240000
eip=773b6b0d esp=09a2f034 ebp=09a2f05c iopl=0         nv up ei pl zr na pe nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00010246
ntdll!RtlpCoalesceFreeBlocks+0x268:
773b6b0d 8b4904          mov     ecx,dword ptr [ecx+4] ds:0023:3c67d6ff=????????
0:025> !analyze -v
*******************************************************************************
*                                                                             *
*                        Exception Analysis                                   *
*                                                                             *
*******************************************************************************

*** WARNING: Unable to verify timestamp for GROOVEEX.DLL
*** ERROR: Module load completed but symbols could not be loaded for GROOVEEX.DLL
Cannot find frame 0x14, previous scope unchanged

FAULTING_IP: 
ntdll!RtlpCoalesceFreeBlocks+268
773b6b0d 8b4904          mov     ecx,dword ptr [ecx+4]

EXCEPTION_RECORD:  ffffffff -- (.exr 0xffffffffffffffff)
ExceptionAddress: 773b6b0d (ntdll!RtlpCoalesceFreeBlocks+0x00000268)
   ExceptionCode: c0000005 (Access violation)
  ExceptionFlags: 00000000
NumberParameters: 2
   Parameter[0]: 00000000
   Parameter[1]: 3c67d6ff
Attempt to read from address 3c67d6ff

CONTEXT:  00000000 -- (.cxr 0x0;r)
eax=01a4d710 ebx=01aac680 ecx=3c67d6fb edx=e97fae3b esi=01a4d708 edi=00240000
eip=773b6b0d esp=09a2f034 ebp=09a2f05c iopl=0         nv up ei pl zr na pe nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00010246
ntdll!RtlpCoalesceFreeBlocks+0x268:
773b6b0d 8b4904          mov     ecx,dword ptr [ecx+4] ds:0023:3c67d6ff=????????

PROCESS_NAME:  explorer.exe

ERROR_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text>

EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text>

EXCEPTION_PARAMETER1:  00000000

EXCEPTION_PARAMETER2:  3c67d6ff

READ_ADDRESS:  3c67d6ff 

FOLLOWUP_IP: 
dui70!DirectUI::DeferCycle::_EndDefer+0
746497bb 8bff            mov     edi,edi

NTGLOBALFLAG:  0

APPLICATION_VERIFIER_FLAGS:  0

APP:  explorer.exe

ANALYSIS_VERSION: 6.3.9600.17237 (debuggers(dbg).140716-0327) amd64fre

LAST_CONTROL_TRANSFER:  from 773b6287 to 773b6b0d

ADDITIONAL_DEBUG_TEXT:  Followup set based on attribute [Is_ChosenCrashFollowupThread] from Frame:[0] on thread:[PSEUDO_THREAD]

FAULTING_THREAD:  ffffffff

BUGCHECK_STR:  APPLICATION_FAULT_FTH_ACTIVE_UNKNOWN_XMULTI_ACTIONABLE_HEAP_CORRUPTION_heap_failure_entry_corruption_INVALID_POINTER_READ

PRIMARY_PROBLEM_CLASS:  FTH_ACTIVE_UNKNOWN_XMULTI_ACTIONABLE_HEAP_CORRUPTION_heap_failure_entry_corruption

DEFAULT_BUCKET_ID:  FTH_ACTIVE_UNKNOWN_XMULTI_ACTIONABLE_HEAP_CORRUPTION_heap_failure_entry_corruption

STACK_TEXT:  
00000000 00000000 dui70!DirectUI::DeferCycle::_EndDefer+0x0


SYMBOL_STACK_INDEX:  0

SYMBOL_NAME:  dui70!DirectUI::DeferCycle::_EndDefer+0

FOLLOWUP_NAME:  MachineOwner

MODULE_NAME: dui70

IMAGE_NAME:  dui70.dll

DEBUG_FLR_IMAGE_TIMESTAMP:  4a5bda05

STACK_COMMAND:  ** Pseudo Context ** ; kb

FAILURE_BUCKET_ID:  FTH_ACTIVE_UNKNOWN_XMULTI_ACTIONABLE_HEAP_CORRUPTION_heap_failure_entry_corruption_c0000005_dui70.dll!DirectUI::DeferCycle::_EndDefer

BUCKET_ID:  APPLICATION_FAULT_FTH_ACTIVE_UNKNOWN_XMULTI_ACTIONABLE_HEAP_CORRUPTION_heap_failure_entry_corruption_INVALID_POINTER_READ_dui70!DirectUI::DeferCycle::_EndDefer+0

ANALYSIS_SOURCE:  UM

FAILURE_ID_HASH_STRING:  um:fth_active_unknown_xmulti_actionable_heap_corruption_heap_failure_entry_corruption_c0000005_dui70.dll!directui::defercycle::_enddefer

FAILURE_ID_HASH:  {a5fb570e-c88e-8d32-9a15-cb692db521ed}

Followup: MachineOwner
---------
Опять ошибки символов (но уже меньше) и ни слова о Firebird2Control

-------
В жизни Вам ничего не обещано...


Отправлено: 22:02, 26-10-2014 | #3