Такая ситуация.Рабочая машина.Стоит win xp sp3,DrWEB corp,смета. Все лицензионное никаких ломалок. Периодически без всякой на то логике выскакивает ошибка:
BCCode : 100000d1 BCP1 : 00000000 BCP2 : 00000002 BCP3 : 00000008
BCP4 : 00000000 OSVer : 5_1_2600 SP : 3_0 Product : 256_1
Вроде что то с памятью....
Оперативку заменил.
Вот что пишет дамп памяти...
Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\ильина\Mini081809-02.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: C:\WINDOWS\Symbols
Executable search path is:
Unable to load image ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
Windows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Machine Name:
Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720
Debug session time: Tue Aug 18 16:49:23.487 2009 (GMT+4)
System Uptime: 0 days 0:03:56.859
Unable to load image ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
Loading Kernel Symbols
...............................................................
.................................................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck C2, {7, cd4, 0, 60dd68}
Probably caused by : ntoskrnl.exe ( nt!_woutput+414 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
BAD_POOL_CALLER (c2)
The current thread is making a bad pool request. Typically this is at a bad IRQL level or double freeing the same allocation, etc.
Arguments:
Arg1: 00000007, Attempt to free pool which was already freed
Arg2: 00000cd4, (reserved)
Arg3: 00000000, Memory contents of the pool block
Arg4: 0060dd68, Address of the block of pool being deallocated
Debugging Details:
------------------
BUGCHECK_STR: 0xc2_7
CUSTOMER_CRASH_COUNT: 2
DEFAULT_BUCKET_ID: INTEL_CPU_MICROCODE_ZERO
PROCESS_NAME: System
LAST_CONTROL_TRANSFER: from 00000000 to 804f9f43
STACK_TEXT:
f5b48ea4 00000000 00000000 00000000 00000000 nt!_woutput+0x414
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!_woutput+414
804f9f43 5d pop ebp
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!_woutput+414
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntoskrnl.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 498c11d3
FAILURE_BUCKET_ID: 0xc2_7_nt!_woutput+414
BUCKET_ID: 0xc2_7_nt!_woutput+414
Followup: MachineOwner
---------
0: kd> lmvm nt
start end module name
804d7000 806e4000 nt M (pdb symbols) c:\windows\symbols\exe\ntoskrnl.pdb
Loaded symbol image file: ntoskrnl.exe
Image path: ntoskrnl.exe
Image name: ntoskrnl.exe
Timestamp: Fri Feb 06 13:32:51 2009 (498C11D3)
CheckSum: 001F231C
ImageSize: 0020D000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
Помогите разобраться господа,в чем дело???
BCCode : 100000d1 BCP1 : 00000000 BCP2 : 00000002 BCP3 : 00000008
BCP4 : 00000000 OSVer : 5_1_2600 SP : 3_0 Product : 256_1
Вроде что то с памятью....
Оперативку заменил.
Вот что пишет дамп памяти...
Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [F:\ильина\Mini081809-02.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: C:\WINDOWS\Symbols
Executable search path is:
Unable to load image ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
Windows XP Kernel Version 2600 (Service Pack 3) MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Machine Name:
Kernel base = 0x804d7000 PsLoadedModuleList = 0x8055d720
Debug session time: Tue Aug 18 16:49:23.487 2009 (GMT+4)
System Uptime: 0 days 0:03:56.859
Unable to load image ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
Loading Kernel Symbols
...............................................................
.................................................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck C2, {7, cd4, 0, 60dd68}
Probably caused by : ntoskrnl.exe ( nt!_woutput+414 )
Followup: MachineOwner
---------
0: kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
BAD_POOL_CALLER (c2)
The current thread is making a bad pool request. Typically this is at a bad IRQL level or double freeing the same allocation, etc.
Arguments:
Arg1: 00000007, Attempt to free pool which was already freed
Arg2: 00000cd4, (reserved)
Arg3: 00000000, Memory contents of the pool block
Arg4: 0060dd68, Address of the block of pool being deallocated
Debugging Details:
------------------
BUGCHECK_STR: 0xc2_7
CUSTOMER_CRASH_COUNT: 2
DEFAULT_BUCKET_ID: INTEL_CPU_MICROCODE_ZERO
PROCESS_NAME: System
LAST_CONTROL_TRANSFER: from 00000000 to 804f9f43
STACK_TEXT:
f5b48ea4 00000000 00000000 00000000 00000000 nt!_woutput+0x414
STACK_COMMAND: kb
FOLLOWUP_IP:
nt!_woutput+414
804f9f43 5d pop ebp
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!_woutput+414
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntoskrnl.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 498c11d3
FAILURE_BUCKET_ID: 0xc2_7_nt!_woutput+414
BUCKET_ID: 0xc2_7_nt!_woutput+414
Followup: MachineOwner
---------
0: kd> lmvm nt
start end module name
804d7000 806e4000 nt M (pdb symbols) c:\windows\symbols\exe\ntoskrnl.pdb
Loaded symbol image file: ntoskrnl.exe
Image path: ntoskrnl.exe
Image name: ntoskrnl.exe
Timestamp: Fri Feb 06 13:32:51 2009 (498C11D3)
CheckSum: 001F231C
ImageSize: 0020D000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
Помогите разобраться господа,в чем дело???