WinDbg Help (realy desperate)

Discussion in 'Software' started by eheva, Oct 12, 2006.

  1. eheva

    eheva Private E-2

    Howdy all, i have a repport from windbg here but i just dont get it, id greatly appreciate any help, many thanks


    Microsoft (R) Windows Debugger Version 6.6.0007.5
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [C:\WINDOWS\Minidump\Mini101006-01.dmp]
    Mini Kernel Dump File: Only registers and stack trace are available

    Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
    Executable search path is:
    Windows XP Kernel Version 2600 (Service Pack 2) MP (2 procs) Free x86 compatible
    Product: WinNt, suite: TerminalServer SingleUserTS Personal
    Built by: 2600.xpsp.050928-1517
    Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055c700
    Debug session time: Tue Oct 10 09:54:13.078 2006 (GMT+1)
    System Uptime: 0 days 0:38:53.800
    Loading Kernel Symbols
    .....................................................................................................................................
    Loading User Symbols
    Loading unloaded module list
    ...........
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    Use !analyze -v to get detailed debugging information.

    BugCheck 24, {1902fe, b5adc6f8, b5adc3f4, 804ef333}

    *** WARNING: Unable to verify timestamp for SiWinAcc.sys
    *** ERROR: Module load completed but symbols could not be loaded for SiWinAcc.sys
    Probably caused by : Ntfs.sys ( Ntfs!NtfsDeleteInternalAttributeStream+a0 )

    Followup: MachineOwner
    ---------

    0: kd> !analyze -v
    *******************************************************************************
    * *
    * Bugcheck Analysis *
    * *
    *******************************************************************************

    NTFS_FILE_SYSTEM (24)
    If you see NtfsExceptionFilter on the stack then the 2nd and 3rd
    parameters are the exception record and context record. Do a .cxr
    on the 3rd parameter and then kb to obtain a more informative stack
    trace.
    Arguments:
    Arg1: 001902fe
    Arg2: b5adc6f8
    Arg3: b5adc3f4
    Arg4: 804ef333

    Debugging Details:
    ------------------


    EXCEPTION_RECORD: b5adc6f8 -- (.exr ffffffffb5adc6f8)
    ExceptionAddress: 804ef333 (nt!IopFreeIrp+0x0000008b)
    ExceptionCode: c0000005 (Access violation)
    ExceptionFlags: 00000000
    NumberParameters: 2
    Parameter[0]: 00000001
    Parameter[1]: 00000000
    Attempt to write to address 00000000

    CONTEXT: b5adc3f4 -- (.cxr ffffffffb5adc3f4)
    eax=ffdff120 ebx=00000001 ecx=000001fc edx=848101fc esi=8481eb98 edi=00000000
    eip=804ef333 esp=b5adc7c0 ebp=b5adc7cc iopl=0 nv up ei pl zr na pe nc
    cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010246
    nt!IopFreeIrp+0x8b:
    804ef333 894e1c mov dword ptr [esi+1Ch],ecx ds:0023:8481ebb4=????????
    Resetting default scope

    CUSTOMER_CRASH_COUNT: 1

    PROCESS_NAME: iexplore.exe

    ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s".

    WRITE_ADDRESS: 00000000

    BUGCHECK_STR: 0x24

    DEFAULT_BUCKET_ID: NULL_DEREFERENCE

    LAST_CONTROL_TRANSFER: from 8058280f to 804ef333

    STACK_TEXT:
    b5adc7cc 8058280f 8481eb98 847d0dc0 00000000 nt!IopFreeIrp+0x8b
    b5adc808 805b9e31 007d0dd8 00000000 847d0dc0 nt!IopDeleteFile+0x16d
    b5adc824 805258f4 847d0dd8 00000000 e3d3d950 nt!ObpRemoveObjectRoutine+0xdf
    b5adc83c f73d5b11 e3d3d990 e3d30705 00000000 nt!ObfDereferenceObject+0x4c
    b5adc854 f73ac978 e3d3d950 00000001 00000000 Ntfs!NtfsDeleteInternalAttributeStream+0xa0
    b5adc874 f73cdc40 e3d3d950 e3d3dae8 00008800 Ntfs!NtfsDecrementCleanupCounts+0xb1
    b5adca84 f73cdd83 b5adcaa0 848157f8 86d0ae88 Ntfs!NtfsCommonCleanup+0x2542
    b5adcbfc 804eef95 86d0a520 848157f8 86cebd00 Ntfs!NtfsFsdCleanup+0xcf
    b5adcc0c f7a64325 804eef95 86d09670 848157f8 nt!IopfCallDriver+0x31
    WARNING: Stack unwind information not available. Following frames may be wrong.
    b5adcc30 804eef95 86d0add0 e1b1da68 848157f8 SiWinAcc+0x325
    b5adcc64 804eef95 85c75700 008157f8 848157f8 nt!IopfCallDriver+0x31
    b5adcc74 8058262f 847d4228 86de7ad0 00000001 nt!IopfCallDriver+0x31
    b5adcc64 804eef95 85c75700 008157f8 848157f8 nt!IopCloseFile+0x26b
    b5adcc98 80534969 847d4228 b5adccd4 805bb3ad nt!IopfCallDriver+0x31
    b5adcca4 805bb3ad 848dc560 85c75648 00010080 nt!ExReleaseResourceLite+0x8d
    b5adccd4 805bacff 848dc560 017d4228 86de7ad0 nt!ObpDecrementHandleCount+0x11b
    b5adccfc 805bad9d e28874a0 847d4240 0000061c nt!ObpCloseHandleTableEntry+0x14d
    b5adcd44 805baed5 0000061c 00000001 00000000 nt!ObpCloseHandle+0x87
    b5adcd58 8054078c 0000061c 0843cde4 7c90eb94 nt!NtClose+0x1d
    b5adcd58 7c90eb94 0000061c 0843cde4 7c90eb94 nt!KiFastCallEntry+0xfc
    0843cde4 00000000 00000000 00000000 00000000 0x7c90eb94


    FOLLOWUP_IP:
    Ntfs!NtfsDeleteInternalAttributeStream+a0
    f73d5b11 c645ff01 mov byte ptr [ebp-1],1

    SYMBOL_STACK_INDEX: 4

    FOLLOWUP_NAME: MachineOwner

    MODULE_NAME: Ntfs

    IMAGE_NAME: Ntfs.sys

    DEBUG_FLR_IMAGE_TIMESTAMP: 41107eea

    SYMBOL_NAME: Ntfs!NtfsDeleteInternalAttributeStream+a0

    STACK_COMMAND: .cxr 0xffffffffb5adc3f4 ; kb

    FAILURE_BUCKET_ID: 0x24_Ntfs!NtfsDeleteInternalAttributeStream+a0

    BUCKET_ID: 0x24_Ntfs!NtfsDeleteInternalAttributeStream+a0

    Followup: MachineOwner
    ---------
     
  2. erikske

    erikske Sergeant

    At first sight i would say iexplore.exe (internet explorer) caused a file system error. Run chkdsk /f and you should be fine :).
    If not, your drive may be heavily fragmented. defragment it. If the error still doesn't go away, disable any anti-virus, firewall and backup utilities and try again.
     
  3. eheva

    eheva Private E-2

    Thanks dude, ill try it and see what happens. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds