Endpoint Protection

 View Only
  • 1.  Help!! The bluesrean is caused by Symantec AV 10.0.1.1000

    Posted Sep 02, 2009 06:11 AM

    My computer always restart 2 day time
    How to get the “dmp" file?
    http://patch.patchsource.cn/download/Mini082809Symantec.dmp


    The forlowing is the Mimidump information:
    FAULTING_MODULE: 804d8000 nt

    DEBUG_FLR_IMAGE_TIMESTAMP:  4272844c

    EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - "0x%08lx"

    FAULTING_IP:
    nt+b1754
    80589754 8a470c          mov     al,byte ptr [edi+0Ch]

    TRAP_FRAME:  a994f708 -- (.trap ffffffffa994f708)
    ErrCode = 00000000
    eax=a994f820 ebx=00000001 ecx=a994f858 edx=a994f85c esi=e12a6cd8 edi=0000b7f8
    eip=80589754 esp=a994f77c ebp=a994f830 iopl=0         nv up ei pl nz na po cy
    cs=0008  ss=0010  ds=0023  es=0023  fs=0030  gs=0000             efl=00010203
    nt+0xb1754:
    80589754 8a470c          mov     al,byte ptr [edi+0Ch]      ds:0023:0000b804=??
    Resetting default scope

    CUSTOMER_CRASH_COUNT:  1

    DEFAULT_BUCKET_ID:  WRONG_SYMBOLS

    BUGCHECK_STR:  0x8E

    LAST_CONTROL_TRANSFER:  from a6cb8e06 to 80589754

    STACK_TEXT: 
    WARNING: Stack unwind information not available. Following frames may be wrong.
    a994f830 a6cb8e06 0000b810 a994f85c 00000008 nt+0xb1754
    a994f834 00000000 a994f85c 00000008 a994f858 SYMEVENT+0x5e06


    STACK_COMMAND:  kb

    FOLLOWUP_IP:
    SYMEVENT+5e06
    a6cb8e06 ??              ???

    SYMBOL_STACK_INDEX:  1

    SYMBOL_NAME:  SYMEVENT+5e06

    FOLLOWUP_NAME:  MachineOwner

    MODULE_NAME: SYMEVENT

    IMAGE_NAME:  SYMEVENT.SYS

    BUCKET_ID:  WRONG_SYMBOLS

    Followup: MachineOwner
     



  • 2.  RE: Help!! The bluesrean is caused by Symantec AV 10.0.1.1000

    Posted Sep 02, 2009 06:25 AM

    if you are using 10.0.1 it seems to be a bug please upgrade to latest version here is the supporting document

    http://service1.symantec.com/SUPPORT/ent-security.nsf/pfdocs/2005081909325748?Open&dtype=corp

    This problem is fixed in Symantec AntiVirus 10.0.2



  • 3.  RE: Help!! The bluesrean is caused by Symantec AV 10.0.1.1000

    Broadcom Employee
    Posted Sep 02, 2009 06:59 AM

    looks like its caused due to symevent. check by updating symevent files
    http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/1998092408260848

    but yes definetly update the sav version to the latest one 10.1.8