Using WinDbg

Discussion in 'Software' started by asingh, Feb 22, 2010.

  1. asingh

    asingh Private E-2

    Hi,

    I have installed the Window Debugger tool, for Win7 64BIT. I got the installation file from here.


    Download link:
    http://www.microsoft.com/whdc/devtools/debugging/install64bit.mspx#

    I used this link "Install 64-bit Native x64 version 6.11.1.404 [15.2 MB]"

    After installing this application I was reading a thread from this forum. The thread is:
    http://forums.majorgeeks.com/showthread.php?t=35246

    As it is mentioned there, I set the symbol search path file a
    s:
    SRV*c:\symbols*http://msdl.microsoft.com/download/symbols

    Now I have some crash dump files from my friends. I am 100% sure, they are from Win7 64BIT system. When I load them, and the analysis tool runs..I get the following error:

    *************************************************************************
    *** ***
    *** ***
    *** Your debugger is not using the correct symbols ***
    *** ***
    *** In order for this command to work properly, your symbol path ***
    *** must point to .pdb files that have full type information. ***
    *** ***
    *** Certain .pdb files (such as the public OS symbols) do not ***
    *** contain the required information. Contact the group that ***
    *** provided you with these symbols if you need this command to ***
    *** work. ***
    *** ***
    *** Type referenced: nt!_KPRCB ***
    *** ***
    *************************************************************************

    It goes onto to give me:
    Probably caused by : ntoskrnl.exe ( nt+1a50f3 )


    Is it doing the analysis correctly..?

    When I run the '!analyze -v' command I get the same above error message and then this
    :

    ADDITIONAL_DEBUG_TEXT:
    Use '!findthebuild' command to search for the target build information.
    If the build information is available, run '!findthebuild -s ; .reload' to set symbol path and load symbols.

    MODULE_NAME: nt

    FAULTING_MODULE: fffff80001c03000 nt

    DEBUG_FLR_IMAGE_TIMESTAMP: 4a5bc600

    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.

    FAULTING_IP:
    nt+1a50f3
    fffff800`01da80f3 418b45f0 mov eax,dword ptr [r13-10h]

    EXCEPTION_RECORD: fffff88001fb9918 -- (.exr 0xfffff88001fb9918)
    ExceptionAddress: fffff80001da80f3 (nt+0x00000000001a50f3)
    ExceptionCode: c0000005 (Access violation)
    ExceptionFlags: 00000000
    NumberParameters: 2
    Parameter[0]: 0000000000000000
    Parameter[1]: 00000000000001f0
    Attempt to read from address 00000000000001f0

    CONTEXT: fffff88001fb9170 -- (.cxr 0xfffff88001fb9170)
    rax=0000000000000000 rbx=fffff8a0023dfcc0 rcx=0000000000000200
    rdx=00000000624e4d43 rsi=0000000000000001 rdi=fffff8a0023dfcc0
    rip=fffff80001da80f3 rsp=fffff88001fb9b50 rbp=ffffffffffffffff
    r8=0000000000000001 r9=000000002ff19715 r10=fffff8a0019a0948
    r11=fffffa800371f040 r12=000000006b8c611c r13=0000000000000200
    r14=0000000000000000 r15=0000000000000001
    iopl=0 nv up ei pl nz na po nc
    cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010206
    nt+0x1a50f3:
    fffff800`01da80f3 418b45f0 mov eax,dword ptr [r13-10h] ds:002b:00000000`000001f0=????????
    Resetting default scope

    CUSTOMER_CRASH_COUNT: 1

    DEFAULT_BUCKET_ID: VISTA_DRIVER_FAULT

    BUGCHECK_STR: 0x7E

    CURRENT_IRQL: 0

    LAST_CONTROL_TRANSFER: from fffff8a000f69660 to fffff80001da80f3

    STACK_TEXT:
    fffff880`01fb9b50 fffff8a0`00f69660 : 00000000`00000001 00000000`00000001 00000000`00000000 00000000`00000001 : nt+0x1a50f3
    fffff880`01fb9b58 00000000`00000001 : 00000000`00000001 00000000`00000000 00000000`00000001 fffff8a0`00f69630 : 0xfffff8a0`00f69660
    fffff880`01fb9b60 00000000`00000001 : 00000000`00000000 00000000`00000001 fffff8a0`00f69630 fffff8a0`00f69638 : 0x1
    fffff880`01fb9b68 00000000`00000000 : 00000000`00000001 fffff8a0`00f69630 fffff8a0`00f69638 00000000`00000fc0 : 0x1


    FOLLOWUP_IP:
    nt+1a50f3
    fffff800`01da80f3 418b45f0 mov eax,dword ptr [r13-10h]

    SYMBOL_STACK_INDEX: 0

    SYMBOL_NAME: nt+1a50f3

    FOLLOWUP_NAME: MachineOwner

    IMAGE_NAME: ntoskrnl.exe

    STACK_COMMAND: .cxr 0xfffff88001fb9170 ; kb

    BUCKET_ID: WRONG_SYMBOLS

    Followup: MachineOwner

    Why do I keep getting that the Debugger application is using incorrect symbols....?

    Thanks a ton for the help.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds