참고링크: http://qaos.com/article.php?sid=2199
참고링크: http://qaos.com/article.php?sid=1837
참고링크: http://www.microsoft.com/whdc/devtools/debugging/install64bit.mspx
참고링크: http://www.microsoft.com/whdc/devtools/debugging/installx86.mspx
참고링크: http://p-nand-q.com/

<디버거 설치 폴더>\kd -y srv*<심볼 폴더>*http://msdl.microsoft.com/download/symbols -i <XP 원본 CD>\i386 -z <미니덤프 폴더>\minidump.dmp

디버깅을 위해 위의 형식에 맞춰서 내가 입력한 부분이 아래의 빨간색 부분이다.
심볼 폴더는 그냥 임의의 폴더로 맞춰주면된다.

참고로 결론으로 나온 klim6.sys 파일은 Kaspersky Anti-Virus NDIS 6 Filter였다... (어쩌란 말이야... -_-;)

Microsoft Windows [Version 6.0.6001]
(C) Copyright 1985-2005 Microsoft Corp.

C:\Users\Administrator>"C:\Program Files\System\Debugging Tools for Windows (x6
)\kd" -y srv*c:\symbols*http://msdl.microsoft.com/download/symbols -i O:\SOURCE
 -z C:\Windows\Minidump\Mini120108-08.dmp

Microsoft (R) Windows Debugger Version 6.10.0003.233 AMD64
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\Windows\Minidump\Mini120108-08.dmp]
Mini Kernel Dump File: Only registers and stack trace are available

Symbol search path is: srv*c:\symbols*http://msdl.microsoft.com/download/symbol

Executable search path is: O:\SOURCES
Windows Server 2008/Windows Vista SP1 Kernel Version 6001 (Service Pack 1) MP (
 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 6001.18145.amd64fre.vistasp1_gdr.080917-1612
Machine Name:
Kernel base = 0xfffff800`01e5f000 PsLoadedModuleList = 0xfffff800`02024db0
Debug session time: Mon Dec  1 07:31:46.614 2008 (GMT+9)
System Uptime: 0 days 0:39:20.454
Loading Kernel Symbols
...............................................................
................................................................
...........................
Loading User Symbols
Loading unloaded module list
........
*******************************************************************************
*                                                                             *
*                        Bugcheck Analysis                                    *
*                                                                             *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck C2, {7, 110b, 460001f, fffffa8008c18950}

Unable to load image \SystemRoot\system32\DRIVERS\klim6.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for klim6.sys
*** ERROR: Module load completed but symbols could not be loaded for klim6.sys
Unable to load image \SystemRoot\system32\DRIVERS\Rtlh64.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for Rtlh64.sys
*** ERROR: Module load completed but symbols could not be loaded for Rtlh64.sys
Unable to load image \SystemRoot\system32\DRIVERS\kl1.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for kl1.sys
*** ERROR: Module load completed but symbols could not be loaded for kl1.sys
GetPointerFromAddress: unable to read from fffff80002088080
Probably caused by : klim6.sys ( klim6+2383 )

Followup: MachineOwner
---------

1: kd>



 
Google+