RE: [NTSysADM] Analyzing Minidumps

2016-12-16 Thread Charles F Sullivan
*To:* ntsysadm@lists.myitforum.com *Subject:* RE: [NTSysADM] Analyzing Minidumps Thanks much Michael and David. I think there’s a very good chance that you’ve hit the cause. We’re going to check the Guardium version on the crashed server to see if it’s one of the affected versions. We’ll also disable

RE: [NTSysADM] Analyzing Minidumps

2016-12-16 Thread Charles F Sullivan
, December 15, 2016 6:57 PM *To:* ntsysadm@lists.myitforum.com *Subject:* RE: [NTSysADM] Analyzing Minidumps Here is something I just came across. I haven’t used it yet, but I certainly intend to: http://www.leeholmes.com/blog/2009/01/21/scripting-windbg-with-powershell/ (I own this book

RE: [NTSysADM] Analyzing Minidumps

2016-12-15 Thread David Tobias
or not your issue is what’s described in the KB article. ~Dave From: listsad...@lists.myitforum.com [mailto:listsad...@lists.myitforum.com] On Behalf Of Charles F Sullivan Sent: Thursday, December 15, 2016 2:41 PM To: ntsysadm@lists.myitforum.com Subject: RE: [NTSysADM] Analyzing Minidumps Sorry

RE: [NTSysADM] Analyzing Minidumps

2016-12-15 Thread Michael B. Smith
Of Charles F Sullivan Sent: Thursday, December 15, 2016 5:41 PM To: ntsysadm@lists.myitforum.com Subject: RE: [NTSysADM] Analyzing Minidumps Sorry, clfs.sys is correct. I had already gotten the page you reference when I searched REFERENCE_BY_POINTER but I’m not sure it gives me something to look

RE: [NTSysADM] Analyzing Minidumps

2016-12-15 Thread Charles F Sullivan
it, which I hadn’t thought of trying. Thanks for the help. *From:* listsad...@lists.myitforum.com [mailto: listsad...@lists.myitforum.com] *On Behalf Of *Michael B. Smith *Sent:* Thursday, December 15, 2016 5:10 PM *To:* ntsysadm@lists.myitforum.com *Subject:* RE: [NTSysADM] Analyzing

RE: [NTSysADM] Analyzing Minidumps

2016-12-15 Thread Michael B. Smith
After a few minutes of reading around – sounds like a broken AV to me. You wrote below CLFSYS.SYS – did you mean clfs.sys? Because I don’t think there is a CLFSYS.SYS, which would lead me to think “virus”. This is also a worthwhile read: