无法抓DUMP, 报错"Could not attach to process XXXX, NTSTATUS 0xC0000048"

Problem Description

=================

We tried to use ADPlus to capture dump file. But the size of dump files are all under 20K.

We tried it many times.

Trouble Shoot

=================

I tried to use the “PsExec.exe –s –i –d cmd.exe” to initialize ADPLUS. No luck.

I tried to use WinDBG attach to the process, I failed with information below.

clip_image001

Detail Message is as below.

---------------------------

Could not attach to process 1272, NTSTATUS 0xC0000048

已试图设置进程的 DebugPort 或 ExceptionPort,但该进程中已存在端口,或试图设置文件的 CompletionPort,但文件中已设置端口,或已试图设置 ALPC 端口的相关完成端口,但该端口已设置。

Did more research, we found the root cause and solution.

We saw DebugDiag, and we asked customer to open that. We see the dialog below.

clip_image002

There it is! 1272 is our SharePoint w3wp.exe process.

 

Root Cause

========================

Debug Diag already attached to the process.

Debug Diag has rules, which can attach to target process. Even if the rule is completed, it won’t let go of the process.

Another word to say is the debug port is still occurpied by DebugDiag, so other debuggers such as WinDBG or CDB.exe cannot attach and write dump file.

 

Solution

========================

1. Clear the Rules in DebugDiag.

2. Kill the following processes in task manager.

· DbgSvc.exe

· Dbghost.exe

Problem Resolved.

Dump can now be successfully written.

 

Lesson Learned

========================

Be careful with DebugDiag. When its rules are finished, it won’t let go of the process.

 

Reference

========================

How to resolve "Cannot debug pid <pid>, NTSTATUS 0xC0000048" - "An attempt to set a process's DebugPort or ExceptionPort was made ..."

http://blogs.msdn.com/b/spike/archive/2011/10/21/how-to-resolve-quot-cannot-debug-pid-lt-pid-gt-ntstatus-0xc0000048-quot-quot-an-attempt-to-set-a-process-s-debugport-or-exceptionport-was-made-quot.aspx?CommentPosted=true#commentmessage

posted on   中道学友  阅读(10253)  评论(0编辑  收藏  举报

编辑推荐:
· AI与.NET技术实操系列:向量存储与相似性搜索在 .NET 中的实现
· 基于Microsoft.Extensions.AI核心库实现RAG应用
· Linux系列:如何用heaptrack跟踪.NET程序的非托管内存泄露
· 开发者必知的日志记录最佳实践
· SQL Server 2025 AI相关能力初探
阅读排行:
· 震惊!C++程序真的从main开始吗?99%的程序员都答错了
· 【硬核科普】Trae如何「偷看」你的代码?零基础破解AI编程运行原理
· 单元测试从入门到精通
· 上周热点回顾(3.3-3.9)
· winform 绘制太阳,地球,月球 运作规律
历史上的今天:
2010-03-09 STSADM 命令使用大全
2010-03-09 Security Group: Domain Local, Global, 和Universal 有什么区别?
2010-03-09 Builtin\administrators 与 Domain Admins 用户组的来历与区别

导航

< 2012年3月 >
26 27 28 29 1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31
1 2 3 4 5 6 7

技术追求准确,态度积极向上

点击右上角即可分享
微信分享提示