「WinDbg」にて、DumpFile解析に初挑戦してみましたが対応策がよくわかりません。

Anonymous
2010-05-18T09:12:37+00:00

[win32k.sys]というファイルが問題を起しているように読み取れますが、

その後の対応策がどうしてもわかりません。

[win32k.sys]というファイル自体も何者かわかりません。

原因及び対処方法について教えてください。

問題が起きた時、自分は不在だったので正確さに欠けるかもしれませんが、

普通にウェブサイトを参照しながらOfficeのAccessソフトを使って作業を行っていると、

いきなりシャットダウンされたそうです。

この作業はいつもしている作業で特別な作業をしていたわけではないようです。

以下がダンプファイルの内容です。

ご教授よろしくお願いいたします。

*****

Microsoft (R) Windows Debugger Version 6.11.0001.404 X86

Copyright (c) Microsoft Corporation. All rights reserved.

Loading Dump File [C:\Users\owner\Desktop\Mini051710-01.dmp]

Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*c:\Symbols\MsSymbols*http://msdl.microsoft.com/dow

nload/symbols

Executable search path is:

Unable to load image ntoskrnl.exe, Win32 error 0n2

*** WARNING: Unable to verify timestamp for ntoskrnl.exe

*** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe

Windows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free x86 compatible

Product: WinNt, suite: TerminalServer SingleUserTS

Machine Name:

Kernel base = 0x804d9000 PsLoadedModuleList = 0x8055f720

Debug session time: Mon May 17 11:27:23.984 2010 (GMT+9)

System Uptime: 0 days 3:00:08.663

Unable to load image ntoskrnl.exe, Win32 error 0n2

*** WARNING: Unable to verify timestamp for ntoskrnl.exe

*** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe

Loading Kernel Symbols

...............................................................

................................................................

...

Loading User Symbols

Loading unloaded module list

.................

*** WARNING: Unable to verify timestamp for win32k.sys

*** ERROR: Module load completed but symbols could not be loaded for win32k.sys

******************************************************************************

*                                                                            

*                        Bugcheck Analysis                                   

*                                                                            

******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck 1000007F, {8, f788bd70, 0, 0}

***** Kernel symbols are WRONG. Please fix symbols to do analysis.

**********************************************************************

***                                                                  

***                                                                  

***    Your debugger is not using the correct symbols                

***                                                                  

***    In order for this command to work properly, your symbol path  

***    must point to .pdb files that have full type information.     

***                                                                  

***    Certain .pdb files (such as the public OS symbols) do not     

***    contain the required information.  Contact the group that     

***    provided you with these symbols if you need this command to   

***    work.                                                         

***                                                                  

***    Type referenced: nt!_KPRCB                                    

***                                                                  

**********************************************************************

**********************************************************************

***                                                                  

***                                                                  

***    Your debugger is not using the correct symbols                

***                                                                  

***    In order for this command to work properly, your symbol path  

***    must point to .pdb files that have full type information.     

***                                                                  

***    Certain .pdb files (such as the public OS symbols) do not     

***    contain the required information.  Contact the group that     

***    provided you with these symbols if you need this command to   

***    work.                                                         

***                                                                  

***    Type referenced: nt!KPRCB                                     

***                                                                  

**********************************************************************

**********************************************************************

***                                                                  

***                                                                  

***    Your debugger is not using the correct symbols                

***                                                                  

***    In order for this command to work properly, your symbol path  

***    must point to .pdb files that have full type information.     

***                                                                  

***    Certain .pdb files (such as the public OS symbols) do not     

***    contain the required information.  Contact the group that     

***    provided you with these symbols if you need this command to   

***    work.                                                         

***                                                                  

***    Type referenced: nt!_KPRCB                                    

***                                                                  

**********************************************************************

**********************************************************************

***                                                                  

***                                                                  

***    Your debugger is not using the correct symbols                

***                                                                  

***    In order for this command to work properly, your symbol path  

***    must point to .pdb files that have full type information.     

***                                                                  

***    Certain .pdb files (such as the public OS symbols) do not     

***    contain the required information.  Contact the group that     

***    provided you with these symbols if you need this command to   

***    work.                                                         

***                                                                  

***    Type referenced: nt!KPRCB                                     

***                                                                  

**********************************************************************

**********************************************************************

***                                                                  

***                                                                  

***    Your debugger is not using the correct symbols                

***                                                                  

***    In order for this command to work properly, your symbol path  

***    must point to .pdb files that have full type information.     

***                                                                  

***    Certain .pdb files (such as the public OS symbols) do not     

***    contain the required information.  Contact the group that     

***    provided you with these symbols if you need this command to   

***    work.                                                         

***                                                                  

***    Type referenced: nt!_KPRCB                                    

***                                                                  

**********************************************************************

**********************************************************************

***                                                                  

***                                                                  

***    Your debugger is not using the correct symbols                

***                                                                  

***    In order for this command to work properly, your symbol path  

***    must point to .pdb files that have full type information.     

***                                                                  

***    Certain .pdb files (such as the public OS symbols) do not     

***    contain the required information.  Contact the group that     

***    provided you with these symbols if you need this command to   

***    work.                                                         

***                                                                  

***    Type referenced: nt!_KPRCB                                    

***                                                                  

**********************************************************************

**********************************************************************

***                                                                  

***                                                                  

***    Your debugger is not using the correct symbols                

***                                                                  

***    In order for this command to work properly, your symbol path  

***    must point to .pdb files that have full type information.     

***                                                                  

***    Certain .pdb files (such as the public OS symbols) do not     

***    contain the required information.  Contact the group that     

***    provided you with these symbols if you need this command to   

***    work.                                                         

***                                                                  

***    Type referenced: nt!_KPRCB                                    

***                                                                  

**********************************************************************

Probably caused by : win32k.sys ( win32k+d83f8 )

Followup: MachineOwner


1: kd> !analyze -v

******************************************************************************

*                                                                            

*                        Bugcheck Analysis                                   

*                                                                            

******************************************************************************

UNEXPECTED_KERNEL_MODE_TRAP_M (1000007f)

This means a trap occurred in kernel mode, and it's a trap of a kind

that the kernel isn't allowed to have/catch (bound trap) or that

is always instant death (double fault).  The first number in the

bugcheck params is the number of the trap (8 = double fault, etc)

Consult an Intel x86 family manual to learn more about what these

traps are. Here is a *portion* of those codes:

If kv shows a taskGate

        use .tss on the part before the colon, then kv.

Else if kv shows a trapframe

        use .trap on that value

Else

        .trap on the appropriate frame will show where the trap was taken

        (on x86, this will be the ebp that goes with the procedure KiTrap)

Endif

kb will then show the corrected stack.

Arguments:

Arg1: 00000008, EXCEPTION_DOUBLE_FAULT

Arg2: f788bd70

Arg3: 00000000

Arg4: 00000000

Debugging Details:


***** Kernel symbols are WRONG. Please fix symbols to do analysis.

/*********

   中略

*********/

ADDITIONAL_DEBUG_TEXT: 

Use '!findthebuild' command to search for the target build information.

If the build information is available, run '!findthebuild -s ; .reload' to set symbol path and load symbols.

MODULE_NAME: win32k

FAULTING_MODULE: 804d9000 nt

DEBUG_FLR_IMAGE_TIMESTAMP:  4a8564c7

BUGCHECK_STR:  0x7f_8

CUSTOMER_CRASH_COUNT:  1

DEFAULT_BUCKET_ID:  DRIVER_FAULT

LAST_CONTROL_TRANSFER:  from 00000000 to bf8d83f8

STACK_TEXT: 

a8e9e204 00000000 bf8d840e 000f4240 a8e9e204 win32k+0xd83f8

STACK_COMMAND:  kb

FOLLOWUP_IP:

win32k+d83f8

bf8d83f8 ??              ???

SYMBOL_STACK_INDEX:  0

SYMBOL_NAME:  win32k+d83f8

FOLLOWUP_NAME:  MachineOwner

IMAGE_NAME:  win32k.sys

BUCKET_ID:  WRONG_SYMBOLS

Followup: MachineOwner


1: kd> lmvm win32k

start    end        module name

bf800000 bf9c3b80   win32k   T (no symbols)          

    Loaded symbol image file: win32k.sys

    Image path: win32k.sys

    Image name: win32k.sys

    Timestamp:        Fri Aug 14 22:21:11 2009 (4A8564C7)

    CheckSum:         001CF394

    ImageSize:        001C3B80

    Translations:     0000.04b0 0000.04e4 0409.04b0 0409.04e4

*****

以上です。

家庭向け Windows | その他 | アプリ

ロックされた質問。 この質問は、Microsoft サポート コミュニティから移行されました。 役に立つかどうかに投票することはできますが、コメントの追加、質問への返信やフォローはできません。

0 件のコメント コメントはありません
質問作成者が受け入れた回答
Anonymous
2010-05-18T14:26:36+00:00

WinDbg でダンプファイルを解析するのはソフトウェア開発者が不具合を解析するための手段です。

エンドユーザの視点でこの解析結果を見ても、あまり手がないのが実情です。

エンドユーザ視点の場合、BSOD (ブルースクリーン)での STOP コードを元に調べることになります。

今回の場合、0x10000078 や 0x00000078 にあたるのかもしれません。

これで検索すると、下記のような情報があたりますが、正直なところ、プンスク さんの場合に該当するかどうかはわかりません。

http://support.microsoft.com/kb/842465/ja


質問スレッドで解決した場合は、解決の参考になった投稿に対して「回答としてマーク」のボタンを押すことで、同じ問題に遭遇した別のユーザが役立つ投稿を見つけやすくなります。

この回答は役に立ちましたか?

0 件のコメント コメントはありません

1 件の追加の回答

並べ替え方法: 最も役に立つ
  1. Anonymous
    2010-05-20T09:49:57+00:00

    プンスクさん、こんにちは。佐伯です。

    その後いかがでしょうか?

    Azuleanさんからのアドバイスは確認していただけましたでしょうか?

    今回は、同じような情報をお探しの方にも、参考にしていただけると思いましたので、\[回答としてマーク\]させていただきました。

    MS Answersのご利用ありがとうございます。


    佐伯 星奈– Microsoft Support

    この回答は役に立ちましたか?

    0 件のコメント コメントはありません