﻿<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/"><channel><title>IT博客-Share Mind ----GuoMing's Blogs-随笔分类-Windows Applicatios</title><link>http://www.cnitblog.com/royhuang/category/6373.html</link><description>人的一生是很短暂的，珍惜眼前所有的一切，过好每一天！</description><language>zh-cn</language><lastBuildDate>Fri, 30 Sep 2011 03:33:34 GMT</lastBuildDate><pubDate>Fri, 30 Sep 2011 03:33:34 GMT</pubDate><ttl>60</ttl><item><title>How to open crash dump (e.g. memory.DMP) file</title><link>http://www.cnitblog.com/royhuang/archive/2008/02/14/39761.html</link><dc:creator>GuoMing</dc:creator><author>GuoMing</author><pubDate>Thu, 14 Feb 2008 15:02:00 GMT</pubDate><guid>http://www.cnitblog.com/royhuang/archive/2008/02/14/39761.html</guid><wfw:comment>http://www.cnitblog.com/royhuang/comments/39761.html</wfw:comment><comments>http://www.cnitblog.com/royhuang/archive/2008/02/14/39761.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/royhuang/comments/commentRss/39761.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/royhuang/services/trackbacks/39761.html</trackback:ping><description><![CDATA[<p>memory.dmp was created when your computer shutdown unexpected or blue screen or application crash. just google , found out using windebug (dbg_x86_6.6.07.5.exe) to analys it. (all method from internet)</p>
<p>method 1:</p>
<p>系統藍屏debug方法 <br>1. 我的電腦，屬性-&gt;高級-&gt;啟動，最下面的記憶體調試選最後一項的全部，確定後重新啟動 <br>2. 藍屏後不要急著重啟，系統會保存整個記憶體內容，然後會自動重啟 <br>3. 重啟後,windows目錄會多出 MEMORY.DMP, 如果1步驟選完全調試，那麼這個檔和你的記憶體一樣大 <br>4. 下載安裝windwos 的 debug tools, 我這有下載地址，或微軟網站 <br><a href="http://public.hshh.org/SysTools/debug/dbg_x86_6.6.07.5.exe">http://public.hshh.org/SysTools/debug/dbg_x86_6.6.07.5.exe</a> <br>5. 安裝後創建一個臨時目錄，例如 c:\temp <br>6. 啟動 windbg <br>7. windbg介面: file-&gt;symbol file path (ctrl+s) 輸入: <br>SRV*c:\temp*http://msdl.microsoft.com/download/symbols <br>然後確定</p>
<p>(为什么要这样输入，请参考KB311503) <br>8. windbg介面: file-&gt;open crash dump(ctrl+d)，打開windows目錄下面的 memory.dmp <br>9. 打開後，等待提示 <br>當出現 Use !analyze -v to get detailed debugging information. 字樣後，在下面輸入框 <br>!analyze -v <br>10. 等待分析完畢，可以知道什麼導致的出錯 <br>11. windbg使用中需要網上下載調試內容，這個速度嘛，取決於你的網路了。</p>
<p>&nbsp;</p>
<p>method 2:</p>
<p>一、下載並安裝dbg_x86_6.6.07.5.exe(用google找一下就有了) <br>二、cmd, 切換到C:\Program Files\Debugging Tools for Windows <br>三、執行 <br>dumpchk - y <a href="http://msdl.microsoft.com/download/symbols">http://msdl.microsoft.com/download/symbols</a> c:</p>
<p>\windows\memory.dmp &gt; dmp.txt</p>
<p><br>註一、http://msdl.microsoft.com/download/symbols 是MS提供的網路symbol server <br>註二、c:\windows\Memory.dmp&nbsp; 是memory.dmp預設的存放路徑 <br>註三、將結果寫到bbb.txt檔案</p>
<img src ="http://www.cnitblog.com/royhuang/aggbug/39761.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/royhuang/" target="_blank">GuoMing</a> 2008-02-14 23:02 <a href="http://www.cnitblog.com/royhuang/archive/2008/02/14/39761.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>security log _ Audit object access_delete</title><link>http://www.cnitblog.com/royhuang/archive/2008/02/14/39744.html</link><dc:creator>GuoMing</dc:creator><author>GuoMing</author><pubDate>Thu, 14 Feb 2008 09:25:00 GMT</pubDate><guid>http://www.cnitblog.com/royhuang/archive/2008/02/14/39744.html</guid><wfw:comment>http://www.cnitblog.com/royhuang/comments/39744.html</wfw:comment><comments>http://www.cnitblog.com/royhuang/archive/2008/02/14/39744.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/royhuang/comments/commentRss/39744.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/royhuang/services/trackbacks/39744.html</trackback:ping><description><![CDATA[<blockquote> <p>purpose of the test is for obviousing the security log entry when you delete a audited file:</p> <p>test approach:</p> <p>1. delete an auditing file.</p> <p>2. open eventvwr.msc, check security event. have 3 event about the delete audit(<font color="#ff0000">notice those font be highlight in red</font>)</p> <p>first event entry: </p> <p>**************************************************************************</p> <p>Event Type:&nbsp;&nbsp;&nbsp; Success Audit<br>Event Source:&nbsp;&nbsp;&nbsp; Security<br>Event Category:&nbsp;&nbsp;&nbsp; Object Access <br>Event ID:&nbsp;&nbsp;&nbsp; 560<br>Date:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 2008-2-14<br>Time:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 17:00:08<br>User:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ASIA\dmnroyhu<br>Computer:&nbsp;&nbsp;&nbsp; DMNM3037<br>Description:<br><font color="#ff0000">Object Open</font>:<br>&nbsp;&nbsp;&nbsp;&nbsp; Object Server:&nbsp;&nbsp;&nbsp; Security<br>&nbsp;&nbsp;&nbsp;&nbsp; Object Type:&nbsp;&nbsp;&nbsp; File<br>&nbsp;&nbsp;&nbsp;&nbsp; Object Name:&nbsp;&nbsp;&nbsp; D:\Temp\rbgwssuser.txt<br>&nbsp;&nbsp;&nbsp;&nbsp; Handle ID:&nbsp;&nbsp;&nbsp; 2608<br>&nbsp;&nbsp;&nbsp;&nbsp; Operation ID:&nbsp;&nbsp;&nbsp; {0,25009233}<br>&nbsp;&nbsp;&nbsp;&nbsp; Process ID:&nbsp;&nbsp;&nbsp; 752<br>&nbsp;&nbsp;&nbsp;&nbsp; Image File Name:&nbsp;&nbsp;&nbsp; C:\WINDOWS\explorer.exe<br>&nbsp;&nbsp;&nbsp;&nbsp; Primary User Name:&nbsp;&nbsp;&nbsp; dmnroyhu<br>&nbsp;&nbsp;&nbsp;&nbsp; Primary Domain:&nbsp;&nbsp;&nbsp; ASIA<br>&nbsp;&nbsp;&nbsp;&nbsp; Primary Logon ID:&nbsp;&nbsp;&nbsp; (0x0,0x13E8845)<br>&nbsp;&nbsp;&nbsp;&nbsp; Client User Name:&nbsp;&nbsp;&nbsp; -<br>&nbsp;&nbsp;&nbsp;&nbsp; Client Domain:&nbsp;&nbsp;&nbsp; -<br>&nbsp;&nbsp;&nbsp;&nbsp; Client Logon ID:&nbsp;&nbsp;&nbsp; -<br>&nbsp;&nbsp;&nbsp;&nbsp; Accesses:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; DELETE <br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; READ_CONTROL <br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ReadAttributes <br>&nbsp;&nbsp;&nbsp;&nbsp; Privileges:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; -<br>&nbsp;&nbsp;&nbsp;&nbsp; Restricted Sid Count: 0  <p>For more information, see Help and Support Center at <a href="http://go.microsoft.com/fwlink/events.asp">http://go.microsoft.com/fwlink/events.asp</a>. <p>*******************************************************************************************</p></blockquote> <blockquote> <p>second event entry: <p>******************************************************************************************* <p>Event Type:&nbsp;&nbsp;&nbsp; Success Audit<br>Event Source:&nbsp;&nbsp;&nbsp; Security<br>Event Category:&nbsp;&nbsp;&nbsp; Object Access <br>Event ID:&nbsp;&nbsp;&nbsp; 567<br>Date:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 2008-2-14<br>Time:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 17:00:08<br>User:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ASIA\dmnroyhu<br>Computer:&nbsp;&nbsp;&nbsp; DMNM3037<br>Description:<br><font color="#ff0000">Object Access Attempt</font>:<br>&nbsp;&nbsp;&nbsp;&nbsp; Object Server:&nbsp;&nbsp;&nbsp; Security<br>&nbsp;&nbsp;&nbsp;&nbsp; Handle ID:&nbsp;&nbsp;&nbsp; 2608<br>&nbsp;&nbsp;&nbsp;&nbsp; Object Type:&nbsp;&nbsp;&nbsp; File<br>&nbsp;&nbsp;&nbsp;&nbsp; Process ID:&nbsp;&nbsp;&nbsp; 752<br>&nbsp;&nbsp;&nbsp;&nbsp; Image File Name:&nbsp;&nbsp;&nbsp; C:\WINDOWS\explorer.exe<br>&nbsp;&nbsp;&nbsp;&nbsp; Access Mask:&nbsp;&nbsp;&nbsp; DELETE  <p>For more information, see Help and Support Center at <a href="http://go.microsoft.com/fwlink/events.asp">http://go.microsoft.com/fwlink/events.asp</a>. <p>******************************************************************************************* <p>third event entry: <p>******************************************************************************************* <p>Event Type:&nbsp;&nbsp;&nbsp; Success Audit<br>Event Source:&nbsp;&nbsp;&nbsp; Security<br>Event Category:&nbsp;&nbsp;&nbsp; Object Access <br>Event ID:&nbsp;&nbsp;&nbsp; 564<br>Date:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 2008-2-14<br>Time:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 17:00:08<br>User:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ASIA\dmnroyhu<br>Computer:&nbsp;&nbsp;&nbsp; DMNM3037<br>Description:<br><font color="#ff0000">Object Deleted</font>:<br>&nbsp;&nbsp;&nbsp;&nbsp; Object Server:&nbsp;&nbsp;&nbsp; Security<br>&nbsp;&nbsp;&nbsp;&nbsp; Handle ID:&nbsp;&nbsp;&nbsp; 2608<br>&nbsp;&nbsp;&nbsp;&nbsp; Process ID:&nbsp;&nbsp;&nbsp; 752<br>&nbsp;&nbsp;&nbsp;&nbsp; Image File Name:&nbsp;&nbsp;&nbsp; C:\WINDOWS\explorer.exe  <p>For more information, see Help and Support Center at <a href="http://go.microsoft.com/fwlink/events.asp">http://go.microsoft.com/fwlink/events.asp</a>.</p></blockquote> <blockquote> <p>******************************************************************************************* <p>forth event entry: <p>******************************************************************************************* <p>Event Type:&nbsp;&nbsp;&nbsp; Success Audit<br>Event Source:&nbsp;&nbsp;&nbsp; Security<br>Event Category:&nbsp;&nbsp;&nbsp; Object Access <br>Event ID:&nbsp;&nbsp;&nbsp; 562<br>Date:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 2008-2-14</p> <p><br>Time:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 17:00:08<br>User:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ASIA\dmnroyhu<br>Computer:&nbsp;&nbsp;&nbsp; DMNM3037<br>Description:<br><font color="#ff0000"><u>Handle Closed</u>:<br></font>&nbsp;&nbsp;&nbsp;&nbsp; Object Server:&nbsp;&nbsp;&nbsp; Security<br>&nbsp;&nbsp;&nbsp;&nbsp; Handle ID:&nbsp;&nbsp;&nbsp; 2608<br>&nbsp;&nbsp;&nbsp;&nbsp; Process ID:&nbsp;&nbsp;&nbsp; 752<br>&nbsp;&nbsp;&nbsp;&nbsp; Image File Name:&nbsp;&nbsp;&nbsp; C:\WINDOWS\explorer.exe </p> <p>For more information, see Help and Support Center at <a href="http://go.microsoft.com/fwlink/events.asp">http://go.microsoft.com/fwlink/events.asp</a>.</p></blockquote> <blockquote> <p>*******************************************************************************************</p></blockquote><img src ="http://www.cnitblog.com/royhuang/aggbug/39744.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/royhuang/" target="_blank">GuoMing</a> 2008-02-14 17:25 <a href="http://www.cnitblog.com/royhuang/archive/2008/02/14/39744.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>How to configure Live Writer for cnitlbolg</title><link>http://www.cnitblog.com/royhuang/archive/2007/10/16/34946.html</link><dc:creator>GuoMing</dc:creator><author>GuoMing</author><pubDate>Tue, 16 Oct 2007 08:52:00 GMT</pubDate><guid>http://www.cnitblog.com/royhuang/archive/2007/10/16/34946.html</guid><wfw:comment>http://www.cnitblog.com/royhuang/comments/34946.html</wfw:comment><comments>http://www.cnitblog.com/royhuang/archive/2007/10/16/34946.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnitblog.com/royhuang/comments/commentRss/34946.html</wfw:commentRss><trackback:ping>http://www.cnitblog.com/royhuang/services/trackbacks/34946.html</trackback:ping><description><![CDATA[<p>1、在菜单中选择&#8220;Weblog&#8221;，然后选择&#8220;Another Weblog Service&#8221;。<br>2、在Weblog Homepage URL中输入Blog主页地址:<a title=http://www.cnitblog.com/royhuang/ href="http://www.cnitblog.com/royhuang/">http://www.cnitblog.com/royhuang/</a>。<br>3、输入用户名与密码。<br>4、在&#8220;Type of&nbsp; weblog that you are using&#8221;中选择&#8220;Metaweblog API&#8221;。<br>5、&#8220;Remote posting URL for your weblog&#8221;中输入&#8220;http://www.cnitblog.com/royhuang/services/metaweblog.aspx&#8221;。<br><br>refer document : <a href="http://www.cnblogs.com/dudu/articles/495718.html">http://www.cnblogs.com/dudu/articles/495718.html</a></p>
<img src ="http://www.cnitblog.com/royhuang/aggbug/34946.html" width = "1" height = "1" /><br><br><div align=right><a style="text-decoration:none;" href="http://www.cnitblog.com/royhuang/" target="_blank">GuoMing</a> 2007-10-16 16:52 <a href="http://www.cnitblog.com/royhuang/archive/2007/10/16/34946.html#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item></channel></rss>