ntoskrnl 的 WinDbg 问题

Wil*_*ilf 5 windows windows-vista 64-bit windbg

我遇到了与“ BSOD - 无法验证 ntoskrnl.exe 的时间戳”类似的问题,因为我似乎无法读取正确的符号ntoskrnl

我遵循了BK1E 给出建议,但仍然无法得到结果。

调试文本如下:

Loading Dump File [C:\Users\XXXX\AppData\Local\Temp\WER9D78.tmp\Mini030610-01.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: SRV*c:\Windows\Symbols*http://msdl.microsoft.com/download/symbols
Executable search path is: 
Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
Windows Server 2008/Windows Vista Kernel Version 6002 (Service Pack 2) MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Machine Name:
Kernel base = 0xfffff800`01e59000 PsLoadedModuleList = 0xfffff800`0201ddd0
Debug session time: Sat Mar  6 14:08:20.516 2010 (UTC + 0:00)
System Uptime: 0 days 0:42:01.723
Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ntoskrnl.exe
*** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe
Loading Kernel Symbols
...............................................................
................................................................
.........................
Loading User Symbols
Loading unloaded module list
....
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck A, {11, c, 0, fffff80001ec9489}

***** Kernel symbols are WRONG. Please fix symbols to do analysis.
Run Code Online (Sandbox Code Playgroud)

我该如何解决这个问题?

操作系统是 Windows Vista x64 SP2。

小智 2

看起来您正在加载一个小型转储,它需要可执行文件的路径。将 _NT_EXECUTABLE_IMAGE_PATH 环境变量设置为指向 %windir%\system32 文件夹(或保存可执行文件的任何文件夹),或者使用.exepathWindbg 中的命令。