O
OvErboRed
Hi, I have a few small kernel memory dumps that were generated into %
systemroot%\minidumps after Win XP Pro restarted because of driver
issues. I would like to learn how to use windbg (or perhaps VS.NET, if
possible) to analyze system crashes, and in this case, find out what the
exact problem is from a different machine (the problem is actually
because of the ATI video driver). I'm not going to be debugging, just
determining the cause of these crashes. However, I ran into the
following problem, which seems to have been mentioned many times before
on these newsgroups, but for which I couldn't find a straight answer:
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for
ntoskrnl.exe
My symbol search path is: "srv*C:
\images*http://msdl.microsoft.com/download/symbols"
My image search path is: "C:\windows\system32" **
I've put up the actual minidump at http://overbored.net/minidumps.zip. I
would appreciate any help with this issue. But I also have some general
questions:
- After reading the windbg documentation, I'm wondering how the minidump
specifies the exact file to use; does it have a hash, or does it just
have the filename and timestamp? Where might I find more information
about details like this?
- I've read the windbg documentation, various MSKB articles, and a few
newsgroup articles, but I still feel a bit lost. Can anyone point me to
some primer(s) that explain dumps, symbols, images, etc.? Maybe with
examples?
** The computer I'm running windbg on is not the same as the one that
crashes, so I'm guessing this won't work, but I don't think it's causing
the problem I'm currently having...or is it? Should I set it to the C:
\Windows directory on the crashing computer? or the I386 installation
CD? Also, according to previous posts, the images as well as the symbols
for XP and later are available on Microsoft's public server. What's the
URL to the former?
Thanks!
systemroot%\minidumps after Win XP Pro restarted because of driver
issues. I would like to learn how to use windbg (or perhaps VS.NET, if
possible) to analyze system crashes, and in this case, find out what the
exact problem is from a different machine (the problem is actually
because of the ATI video driver). I'm not going to be debugging, just
determining the cause of these crashes. However, I ran into the
following problem, which seems to have been mentioned many times before
on these newsgroups, but for which I couldn't find a straight answer:
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for
ntoskrnl.exe
My symbol search path is: "srv*C:
\images*http://msdl.microsoft.com/download/symbols"
My image search path is: "C:\windows\system32" **
I've put up the actual minidump at http://overbored.net/minidumps.zip. I
would appreciate any help with this issue. But I also have some general
questions:
- After reading the windbg documentation, I'm wondering how the minidump
specifies the exact file to use; does it have a hash, or does it just
have the filename and timestamp? Where might I find more information
about details like this?
- I've read the windbg documentation, various MSKB articles, and a few
newsgroup articles, but I still feel a bit lost. Can anyone point me to
some primer(s) that explain dumps, symbols, images, etc.? Maybe with
examples?
** The computer I'm running windbg on is not the same as the one that
crashes, so I'm guessing this won't work, but I don't think it's causing
the problem I'm currently having...or is it? Should I set it to the C:
\Windows directory on the crashing computer? or the I386 installation
CD? Also, according to previous posts, the images as well as the symbols
for XP and later are available on Microsoft's public server. What's the
URL to the former?
Thanks!