分析结果如下:
Microsoft (R) Windows Debugger Version 6.11.0001.404 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Documents and Settings\Administrator\桌面\Mini050309-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available
Symbol search path is: *** Invalid ***
****************************************************************************
* Symbol loading may be unreliable without a symbol search path. *
* Use .symfix to have the debugger choose a symbol path. *
* After setting your symbol path, use .reload to refresh symbol locations. *
****************************************************************************
Executable search path is:
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
Unable to load image \SystemRoot\system32\ntkrnlpa.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntkrnlpa.exe
*** ERROR: Module load completed but symbols could not be loaded for ntkrnlpa.exe
Windows Server 2008/Windows Vista Kernel Version 6001 (Service Pack 1) MP (2 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Machine Name:
Kernel base = 0x82444000 PsLoadedModuleList = 0x8255bc70
Debug session time: Sun May 3 21:54:17.902 2009 (GMT+8)
System Uptime: 0 days 11:51:30.200
*********************************************************************
* Symbols can not be loaded because symbol path is not initialized. *
* *
* The Symbol Path can be set by: *
* using the _NT_SYMBOL_PATH environment variable. *
* using the -y <symbol_path> argument when starting the debugger. *
* using .sympath and .sympath+ *
*********************************************************************
Unable to load image \SystemRoot\system32\ntkrnlpa.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntkrnlpa.exe
*** ERROR: Module load completed but symbols could not be loaded for ntkrnlpa.exe
Loading Kernel Symbols
...............................................................
................................................................
...............................................
Loading User Symbols
Loading unloaded module list
.......
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck C2, {7, 110b, 85e0001, 8624f158}
*** WARNING: Unable to verify timestamp for ndis.sys
*** ERROR: Module load completed but symbols could not be loaded for ndis.sys
*** WARNING: Unable to verify timestamp for HssDrv.sys
*** ERROR: Module load completed but symbols could not be loaded for HssDrv.sys
*** WARNING: Unable to verify timestamp for kantiarp.sys
*** ERROR: Module load completed but symbols could not be loaded for kantiarp.sys
*** WARNING: Unable to verify timestamp for VMNetSrv.sys
*** ERROR: Module load completed but symbols could not be loaded for VMNetSrv.sys
***** Kernel symbols are WRONG. Please fix symbols to do analysis.
*************************************************************************
…………………………………………………………
*********************************************************************
Probably caused by :
HssDrv.sys ( HssDrv+1e2f )
Followup: MachineOwner
---------
【建议】c:\windows\system32\drivers目录下找到这个hssdrv.sys,右键“属性”,看看这驱动是干么的,如果知道这文件是安装什么软件后带来的,卸载那个软件看看。
个人感觉也有可能是金山arp防火墙的驱动(c:\windows\system32\drivers\kantiarp.sys)与什么软件冲突造成的。如果上面那个方法不行,也可以卸掉金山arp防火墙看看。