<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ClusterFunk &#187; WinDbg</title>
	<atom:link href="http://www.clusterfunk.co.uk/category/windbg/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.clusterfunk.co.uk</link>
	<description>Stuff I do with Zeus, Microsoft and Virtualisation. Oh and I can&#039;t spell ;)</description>
	<lastBuildDate>Wed, 23 Jun 2010 09:26:43 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>New to blogging? WinDbg notes from the field.</title>
		<link>http://www.clusterfunk.co.uk/new-to-blogging-windbg-notes-from-the-field/</link>
		<comments>http://www.clusterfunk.co.uk/new-to-blogging-windbg-notes-from-the-field/#comments</comments>
		<pubDate>Sun, 09 Nov 2008 01:55:42 +0000</pubDate>
		<dc:creator>Antony Joyce</dc:creator>
				<category><![CDATA[Tool, Tips and Tricks]]></category>
		<category><![CDATA[Vista]]></category>
		<category><![CDATA[WinDbg]]></category>

		<guid isPermaLink="false">http://www.clusterfunk.co.uk/?p=23</guid>
		<description><![CDATA[Here is my first top tip, its real basic stuff this! Are you ready? Autosave. There I said it. I have just written a blog entry to end all blog entries when “pop” …. BSOD win32k.sys has blown you’re last hour and a half into oblivion….. 
I’ll just save this ….. (Pause click save draft [...]]]></description>
			<content:encoded><![CDATA[<p>Here is my first top tip, its real basic stuff this! Are you ready? Autosave. There I said it. I have just written a blog entry to end all blog entries when “pop” …. BSOD win32k.sys has blown you’re last hour and a half into oblivion….. </p>
<p>I’ll just save this ….. (Pause click save draft <img src='http://www.clusterfunk.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  ) </p>
<p><a href="http://www.clusterfunk.co.uk/wp-content/uploads/2008/11/image.png"><img title="image" style="border-top-width: 0px; display: inline; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="190" alt="image" src="http://www.clusterfunk.co.uk/wp-content/uploads/2008/11/image-thumb.png" width="334" border="0" /></a> </p>
<p>Well this takes me neatly onto two things </p>
<p>Firstly </p>
<p>I was lucky enough to see <a href="http://www.microsoft.com/emea/spotlight/sessionh.aspx?videoid=722" target="_blank">this</a> presentation at Tech-Ed 2008 EMEA from the IT God that is Mark Russinovich called a “case of the unexplained”&#160; </p>
<p>He reminds me of <a href="http://en.wikipedia.org/wiki/Marvin_the_Paranoid_Android" target="_blank">Marvin</a> the Paranoid Android&#160; from hitch hikers guide, well at least the brain the size of a planet bit anyway…&#160; </p>
<p>Secondly </p>
<p>I wanted to have a chance to put what I had learned into practice and also get the opportunity to blog about it, hey every cloud has a silver lining. So..&#160;&#160; </p>
<p>I had already downloaded <a href="http://www.microsoft.com/whdc/devtools/debugging/debugstart.mspx" target="_blank">WinDbg</a> so all I needed to do was update the symbols path …</p>
<p><b>SRV*c:\websymbols*http://msdl.microsoft.com/download/symbols</b></p>
<p>and away we go.. </p>
<p>So I locate the Crash Dump, I’m running Vista so its c:\windows\MEMORY.DMP</p>
<p><a href="http://www.clusterfunk.co.uk/wp-content/uploads/2008/11/image1.png"><img title="image" style="border-top-width: 0px; display: inline; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="76" alt="image" src="http://www.clusterfunk.co.uk/wp-content/uploads/2008/11/image-thumb1.png" width="450" border="0" /></a> </p>
</p>
<p>Open CrashDbg and (Ctrl+D) Open Crash Dump</p>
<p><a href="http://www.clusterfunk.co.uk/wp-content/uploads/2008/11/image2.png"><img title="image" style="border-top-width: 0px; display: inline; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="279" alt="image" src="http://www.clusterfunk.co.uk/wp-content/uploads/2008/11/image-thumb2.png" width="367" border="0" /></a> </p>
<p>There are two things I can do as a novice </p>
<p>I can click the nice little hyper link to see if this reveals anything </p>
<p><a href="http://www.clusterfunk.co.uk/wp-content/uploads/2008/11/image3.png"><img title="image" style="border-top-width: 0px; display: inline; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="160" alt="image" src="http://www.clusterfunk.co.uk/wp-content/uploads/2008/11/image-thumb3.png" width="430" border="0" /></a> </p>
<p>So I click !analyze –v and first of all see this</p>
<p>&#160;<a href="http://www.clusterfunk.co.uk/wp-content/uploads/2008/11/image6.png"><img title="image" style="border-right: 0px; border-top: 0px; display: inline; border-left: 0px; border-bottom: 0px" height="445" alt="image" src="http://www.clusterfunk.co.uk/wp-content/uploads/2008/11/image-thumb6.png" width="449" border="0" /></a></p>
<p><em>“KERNEL_MODE_EXCEPTION_NOT_HANDLED (8e)      <br />This is a very common bugcheck.&#160; Usually the exception address pinpoints the driver/function that caused the problem.&#160; Always note this address as well as the link date of the driver/image that contains this address.       <br />Some common problems are exception code 0&#215;80000003.&#160; This means a hard coded breakpoint or assertion was hit, but this system was booted /NODEBUG.&#160; This is not supposed to happen as developers should never have hardcoded breakpoints in retail code, but &#8230;       <br />If this happens, make sure a debugger gets connected, and the       <br />system is booted /DEBUG.&#160; This will let us see why this breakpoint is       <br />happening.</em></p>
<p><em>Arguments:      <br />Arg1: c0000005, The exception code that was not handled       <br />Arg2: 97b13949, The address that the exception occurred at       <br />Arg3: beb70034, Trap Frame       <br />Arg4: 00000000”</em></p>
<p>I look further down the irony is killing me <img src='http://www.clusterfunk.co.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  …..</p>
<p>So I mentioned I was new to blogging, I have just set up an account today (well technically yesterday now) and installed Windows Live Writer<strong> Beta</strong> to write my blog entries </p>
<p><a href="http://www.clusterfunk.co.uk/wp-content/uploads/2008/11/image5.png"><img title="image" style="border-top-width: 0px; display: inline; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="85" alt="image" src="http://www.clusterfunk.co.uk/wp-content/uploads/2008/11/image-thumb5.png" width="438" border="0" /></a> </p>
<p>WinDbg   <br />This is a great tool and while I admit I am a complete novice at this I’m sure you’ll agree that this is really useful information it even tells me what to do next … </p>
<p>Followup: MachineOwner</p>
<p><em>“but &#8230;If this happens, make sure a debugger gets connected, and the      <br />system is booted /DEBUG.&#160; This will let us see why this breakpoint is       <br />happening.”</em></p>
<p>As I am using a Beta version of the software I am going to follow the advice to boot my system /DEBUG, save frequently and if it happens again hopefully submit a useful crash dump to Microsoft! </p>
<p>Happy Hunting</p>
</p>
</p>
</p>
</p>
</p>
<p>Now the last time it crashed was when I pre-viewed my post ….. “pop”</p>
]]></content:encoded>
			<wfw:commentRss>http://www.clusterfunk.co.uk/new-to-blogging-windbg-notes-from-the-field/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
