I've reviewed the event filters settings in WinDbg and tried to modify
them, but it didn't help.
Is there anything to do with it? I would really appreciate any help or
advice.
Thanks,
Sergey Levi.
Can you post a stack trace and output from 'sx' and '!gflag'?
--
This posting is provided "AS IS" with no warranties, and confers no
rights.
On Jun 11, 12:31 pm, "Pavel Lebedinsky [MSFT]"
<pa...@online.microsoft.com> wrote:
>
> Can you post a stack trace and output from 'sx' and '!gflag'?
>
Here's the output:
nt!DebugService2+0x5:
fffff800`0104b3a5 cc int 3
0: kd> kb
RetAddr : Args to
Child : Call
Site
fffff800`010fa646 : fffffadf`67727453 00000000`00000000
00000000`00000000 00000000`ffffffff : nt!DebugService2+0x5
fffff800`012b8bb0 : 00000000`00000001 fffff800`00000012
fffffadf`e61e4700 0000007f`fffffff8 : nt!DbgUnLoadImageSymbols+0x26
fffff800`01316ffc : fffffadf`e61e4710 fffffadf`e61e4740
fffffadf`e61e4740 fffffadf`e61e4740 : nt!MmUnloadSystemImage+0x3a5
fffff800`0129040d : fffffadf`e61e46f0 fffff800`0127ee0a
fffffadf`e61e46f0 00000000`00000000 : nt!IopDeleteDriver+0x4c
fffff800`0105a92b : fffffadf`e61e4710 00000000`00000001
fffffadf`e61e4740 00000000`00000000 : nt!ObpRemoveObjectRoutine+0x144
fffff800`010bfa03 : fffffadf`e602d680 fffffadf`e602d680
fffffadf`e61e4740 00000000`00000000 : nt!ObfDereferenceObject+0x83
fffff800`01273573 : fffffadf`e5f04550 00000000`00000000
fffffadf`e5f04550 00000000`00000000 : nt!IopCompleteUnloadOrDelete
+0x567
fffff800`0129040d : fffffadf`e5f04520 fffffadf`e5f04550
fffffadf`e5f04550 00000000`00000000 : nt!IopDeleteFile+0x3f0
fffff800`0105a92b : fffffadf`e5f04520 00000000`00000548
fffffadf`e5f04550 00000000`00000000 : nt!ObpRemoveObjectRoutine+0x144
fffff800`0128d6c7 : fffffa80`01110520 fffffa80`01110520
fffffa80`00e91470 00000000`00000000 : nt!ObfDereferenceObject+0x83
fffff800`0128d5b4 : fffffadf`e784bbd0 00000000`00000548
fffffadf`e5e0f040 fffffadf`e784bbd0 : nt!ObpCloseHandleTableEntry
+0x24b
fffff800`0104fce2 : fffffadf`e784bbd0 fffffadf`e383ccf0
00000000`00000000 00000000`00000000 : nt!ObpCloseHandle+0xb0
00000000`78ef135a : 000007ff`7b2f7702 00000000`00144007
00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x3
000007ff`7b2f7702 : 00000000`00144007 00000000`00000000
00000000`00000000 00000000`00000001 : ntdll!ZwClose+0xa
00000000`00144007 : 00000000`00000000 00000000`00000000
00000000`00000001 00000000`00000000 : 0x7ff`7b2f7702
00000000`00000000 : 00000000`00000000 00000000`00000001
00000000`00000000 000007ff`7b2f037c : 0x144007
00000000`00000000 : 00000000`00000001 00000000`00000000
000007ff`7b2f037c 00000000`00120510 : 0x0
00000000`00000001 : 00000000`00000000 000007ff`7b2f037c
00000000`00120510 000007ff`7b2e3720 : 0x0
00000000`00000000 : 000007ff`7b2f037c 00000000`00120510
000007ff`7b2e3720 000007ff`7b2e9090 : 0x1
000007ff`7b2f037c : 00000000`00120510 000007ff`7b2e3720
000007ff`7b2e9090 00000000`00000001 : 0x0
0: kd> sx
ct - Create thread - ignore
et - Exit thread - ignore
cpr - Create process - ignore
epr - Exit process - ignore
ld - Load module - ignore
ud - Unload module - ignore
ser - System error - ignore
ibp - Initial breakpoint - ignore
iml - Initial module load - ignore
out - Debuggee output - output
av - Access violation - break - not handled
asrt - Assertion failure - break - not handled
aph - Application hang - break - not handled
bpe - Break instruction exception - break
bpec - Break instruction exception continue - handled
eh - C++ EH exception - second-chance break - not handled
clr - CLR exception - second-chance break - not handled
clrn - CLR notification exception - second-chance break - handled
cce - Control-Break exception - break
cc - Control-Break exception continue - handled
cce - Control-C exception - break
cc - Control-C exception continue - handled
dm - Data misaligned - break - not handled
dbce - Debugger command exception - ignore - handled
gp - Guard page violation - break - not handled
ii - Illegal instruction - second-chance break - not handled
ip - In-page I/O error - break - not handled
dz - Integer divide-by-zero - break - not handled
iov - Integer overflow - break - not handled
ch - Invalid handle - break
hc - Invalid handle continue - not handled
lsq - Invalid lock sequence - break - not handled
isc - Invalid system call - break - not handled
3c - Port disconnected - second-chance break - not handled
svh - Service hang - break - not handled
sse - Single step exception - break
ssec - Single step exception continue - handled
sbo - Stack buffer overflow - break - not handled
sov - Stack overflow - break - not handled
vs - Verifier stop - break - not handled
vcpp - Visual C++ exception - ignore - handled
wkd - Wake debugger - break - not handled
wob - WOW64 breakpoint - break - handled
wos - WOW64 single step exception - break - handled
* - Other exception - second-chance break - not handled
0: kd> !gflag
Current NtGlobalFlag contents: 0x00000000
--
Thanks,
Sergey.
We got rid of these breakins by stopping using remote debugger
connections.