Mijn server reboot sinds 4 dagen regelmatig terwijl er normaal eigenlijk nooit problemen waren. Nou ben ik eens aan de gang gegaan met de debugger van microsoft. Ik krijg dit,(zie verder naar onder)
De meeste keren komt ie met bad_pool_caller op het scherm. In de dump zie je dat ie het over symevent.sys heeft en dat heeft met NAV te maken. deze heb ik opnieuw gedownload en geinstalleerd en maakt niet uit. Ik heb een geheugen tester gedraaid omdat in meedere dump dezelfde READ_ADDRESS: unable to read from 8047fdd8 voorkwam of dezelfde melding met WRITE_ADDRESS.
Heeft iemand een idee? Alvast bedankt
Microsoft (R) Windows Debugger Version 6.1.0017.2
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [\\server\c$\WINNT\Minidump\Mini051903-02.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is: \\server\c$\winnt
Windows 2000 Kernel Version 2195 (Service Pack 3) UP Free x86 compatible
Kernel base = 0x80400000 PsLoadedModuleList = 0x8047fd80
Debug session time: Mon May 19 18:25:54 2003
System Uptime: not available
Loading Kernel Symbols
...........................................................................................
Loading unloaded module list
....
Loading User Symbols
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1E, {c0000005, 740073, 0, 740073}
Unable to load image SYMEVENT.SYS
*** WARNING: Unable to verify timestamp for SYMEVENT.SYS
*** ERROR: Module load completed but symbols could not be loaded for SYMEVENT.SYS
Probably caused by : SYMEVENT.SYS ( SYMEVENT+84dc )
Followup: MachineOwner
---------
kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: c0000005, The exception code that was not handled
Arg2: 00740073, The address that the exception occurred at
Arg3: 00000000, Parameter 0 of the exception
Arg4: 00740073, Parameter 1 of the exception
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - De instructie op 0x%08lx verwijst naar geheugen op 0x%08lx. De lees- of schrijfbewerking ("%s") op het geheugen is mislukt.
FAULTING_IP:
+740073
00740073 ?? ???
EXCEPTION_PARAMETER1: 00000000
EXCEPTION_PARAMETER2: 00740073
READ_ADDRESS: unable to read from 8047fdd8
unable to read from 8047f788
unable to read from 8047f660
unable to read from 804714e8
unable to read from 8047f678
unable to read from 8047f784
unable to read from 804714ec
unable to read from 8047f844
unable to read from 8047fd78
00740073
DEFAULT_BUCKET_ID: DRIVER_FAULT
BUGCHECK_STR: 0x1E
TRAP_FRAME: f68f0c2c -- (.trap fffffffff68f0c2c)
ErrCode = 00000000
eax=824c0da0 ebx=000005c8 ecx=8265d536 edx=825a80c0 esi=825a80a8 edi=e1d35390
eip=00740073 esp=f68f0ca0 ebp=f68f0d4c iopl=0 nv up ei pl nz na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010202
00740073 ?? ???
Resetting default context
LAST_CONTROL_TRANSFER: from 8044cecf to 00740073
STACK_TEXT:
WARNING: Frame IP not in any known module. Following frames may be wrong.
f68f0c9c 8044cecf 824fa480 825a80c0 000005c8 0x740073
f68f0d4c f5dfb4dc 000005c8 014afe50 80462f14 nt!NtClose+0xf1
f68f0d64 00000000 00000000 00000000 00000000 SYMEVENT+0x84dc
FAILED_INSTRUCTION_ADDRESS:
+740073
00740073 ?? ???
FOLLOWUP_IP:
SYMEVENT+84dc
f5dfb4dc ?? ???
FOLLOWUP_NAME: MachineOwner
SYMBOL_NAME: SYMEVENT+84dc
MODULE_NAME: SYMEVENT
IMAGE_NAME: SYMEVENT.SYS
DEBUG_FLR_IMAGE_TIMESTAMP: 3b6701a9
STACK_COMMAND: .trap fffffffff68f0c2c ; kb
BUCKET_ID: 0x1E_BAD_IP_SYMEVENT+84dc
Followup: MachineOwner
---------
De meeste keren komt ie met bad_pool_caller op het scherm. In de dump zie je dat ie het over symevent.sys heeft en dat heeft met NAV te maken. deze heb ik opnieuw gedownload en geinstalleerd en maakt niet uit. Ik heb een geheugen tester gedraaid omdat in meedere dump dezelfde READ_ADDRESS: unable to read from 8047fdd8 voorkwam of dezelfde melding met WRITE_ADDRESS.
Heeft iemand een idee? Alvast bedankt
Microsoft (R) Windows Debugger Version 6.1.0017.2
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [\\server\c$\WINNT\Minidump\Mini051903-02.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is: \\server\c$\winnt
Windows 2000 Kernel Version 2195 (Service Pack 3) UP Free x86 compatible
Kernel base = 0x80400000 PsLoadedModuleList = 0x8047fd80
Debug session time: Mon May 19 18:25:54 2003
System Uptime: not available
Loading Kernel Symbols
...........................................................................................
Loading unloaded module list
....
Loading User Symbols
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck 1E, {c0000005, 740073, 0, 740073}
Unable to load image SYMEVENT.SYS
*** WARNING: Unable to verify timestamp for SYMEVENT.SYS
*** ERROR: Module load completed but symbols could not be loaded for SYMEVENT.SYS
Probably caused by : SYMEVENT.SYS ( SYMEVENT+84dc )
Followup: MachineOwner
---------
kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
KMODE_EXCEPTION_NOT_HANDLED (1e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Arguments:
Arg1: c0000005, The exception code that was not handled
Arg2: 00740073, The address that the exception occurred at
Arg3: 00000000, Parameter 0 of the exception
Arg4: 00740073, Parameter 1 of the exception
Debugging Details:
------------------
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - De instructie op 0x%08lx verwijst naar geheugen op 0x%08lx. De lees- of schrijfbewerking ("%s") op het geheugen is mislukt.
FAULTING_IP:
+740073
00740073 ?? ???
EXCEPTION_PARAMETER1: 00000000
EXCEPTION_PARAMETER2: 00740073
READ_ADDRESS: unable to read from 8047fdd8
unable to read from 8047f788
unable to read from 8047f660
unable to read from 804714e8
unable to read from 8047f678
unable to read from 8047f784
unable to read from 804714ec
unable to read from 8047f844
unable to read from 8047fd78
00740073
DEFAULT_BUCKET_ID: DRIVER_FAULT
BUGCHECK_STR: 0x1E
TRAP_FRAME: f68f0c2c -- (.trap fffffffff68f0c2c)
ErrCode = 00000000
eax=824c0da0 ebx=000005c8 ecx=8265d536 edx=825a80c0 esi=825a80a8 edi=e1d35390
eip=00740073 esp=f68f0ca0 ebp=f68f0d4c iopl=0 nv up ei pl nz na pe nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010202
00740073 ?? ???
Resetting default context
LAST_CONTROL_TRANSFER: from 8044cecf to 00740073
STACK_TEXT:
WARNING: Frame IP not in any known module. Following frames may be wrong.
f68f0c9c 8044cecf 824fa480 825a80c0 000005c8 0x740073
f68f0d4c f5dfb4dc 000005c8 014afe50 80462f14 nt!NtClose+0xf1
f68f0d64 00000000 00000000 00000000 00000000 SYMEVENT+0x84dc
FAILED_INSTRUCTION_ADDRESS:
+740073
00740073 ?? ???
FOLLOWUP_IP:
SYMEVENT+84dc
f5dfb4dc ?? ???
FOLLOWUP_NAME: MachineOwner
SYMBOL_NAME: SYMEVENT+84dc
MODULE_NAME: SYMEVENT
IMAGE_NAME: SYMEVENT.SYS
DEBUG_FLR_IMAGE_TIMESTAMP: 3b6701a9
STACK_COMMAND: .trap fffffffff68f0c2c ; kb
BUCKET_ID: 0x1E_BAD_IP_SYMEVENT+84dc
Followup: MachineOwner
---------