The most common types are 2 (interactive) and 3 (network). The logon type field indicates the kind of logon that occurred. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe. The subject fields indicate the account on the local system which requested the logon. It is generated on the computer that was accessed. This event is generated when a logon session is created. Use !analyze -v to get detailed debugging information.īugCheck 1A, Product: WinNt, suite: TerminalServer SingleUserTSīuilt by: 7sp1_gdr.140706-1506 Windows Vista Kernel Version 7601 (Service Pack 1) MP (4 procs) Free 圆4 *** ERROR: Module load completed but symbols could not be loaded for ntoskrnl.exe *** WARNING: Unable to verify timestamp for ntoskrnl.exe Unable to load image \SystemRoot\system32\ntoskrnl.exe, Win32 error 2 * using the -y argument when starting the debugger. * using the _NT_SYMBOL_PATH environment variable. * Symbols can not be loaded because symbol path is not initialized. symfix to have the debugger choose a symbol path. * Symbol loading may be unreliable without a symbol search path. Mini Kernel Dump File: Only registers and stack trace are available
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |