Random Musings in IT

By paul on Monday, March 21, 2011 9:57 PM
Many of time I have had to figure out what caused a process to dump and had to analyze a mini dump (mdmp) or a full dump (dmp) from a crash or BSOD. I was at a new customers shop the other day and they said their server rebooted mysteriously sometimes. Well, its never mysterious. I copied the dump to my  usb stick and took it offline to analyze it. Ran the mini dump through win debug and low and behold, another dump caused by......SEP.  Filter drivers are nortorious for this and apparently they had not kept up on their updates. If they would have done their updates they would not have had to be billed for the analysis.

Just how do you do a dump analysis.

1. download the proper version of Windbg (http://msdn.microsoft.com/en-us/windows/hardware/gg463009.aspx) to a machine of preferably the same architecture. If not then just load it on your laptop.

2. Copy the dump file to the analysis machine

3. Open Windbg...

New_Blog

You must be logged in and have permission to create or edit a blog.

Search_Blog

Recent_Comments

panerai power reserve
It's so nice to visit here a nice article.Am so impressed with your such a good hard work,it's definitely a good and different idea for others,your guys are doing good work.Good luck,keep it up...
Re: New Microsoft Security Bulletin
In all cases, an attacker would have no way to force users to view the specially crafted content.swtor credits
firefall gold
swtor credits
Re: Microsoft ANNOUNCEMENT: WINDOWS 7 & SERVER 2008 R2 SP1 ARE RTM!!!
1 will be made generally available for download on February 22.
Re: Mock Disaster Recovery for Sharepoint (WSS 3 SP2) with SSRS 2008R2 Integration
Realigned all the SPNs for MSSQLSvc and HTTP for that single host.
Re: Mock Disaster Recovery for Sharepoint (WSS 3 SP2) with SSRS 2008R2 Integration
I was performing a mock DR on Sharepoint for a company.
Re: What, you still do not know how to analyze a dump with Windbg!
Microsoft gives out some basic public symbols which is usually enough swtor credits swtor credits aion kinah
Re: New Microsoft Security Bulletin
Microsoft will release an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center.swtor credits swtor credits aion kinah
Re: Decreasing NDRs on SMTP relay servers
Create a catch all email box that stores all the unknown recepient email and set up rules to delete them.aion kinah
Re: OMG, SSAS 2008 Server Level Locking!!
Actually for this instance, it was fixed in SQL2008 SP2CU2. This was an example of an undetected deadlock rather than a server wide locking. However, the comment about server level locking is still proper and relevant.