无法抓DUMP, 报错"Could not attach to process XXXX, NTSTATUS 0xC0000048"

本文详细介绍了使用AD Plus捕获dump文件时遇到NTSTATUS 0xC0000048错误的解决方法。通过使用DebugDiag清理规则并结束相关进程,成功解决了问题。

摘要生成于 C知道 ,由 DeepSeek-R1 满血版支持, 前往体验 >

Problem Description

=================

We tried to use ADPlus to capture dump file. But the size of dump files are all under 20K.

We tried it many times.

Trouble Shoot

=================

I tried to use the “PsExec.exe –s –i –d cmd.exe” to initialize ADPLUS. No luck.

I tried to use WinDBG attach to the process, I failed with information below.

clip_image001

Detail Message is as below.

---------------------------

Could not attach to process 1272, NTSTATUS 0xC0000048

已试图设置进程的 DebugPort 或 ExceptionPort,但该进程中已存在端口,或试图设置文件的 CompletionPort,但文件中已设置端口,或已试图设置 ALPC 端口的相关完成端口,但该端口已设置。

Did more research, we found the root cause and solution.

We saw DebugDiag, and we asked customer to open that. We see the dialog below.

clip_image002

There it is! 1272 is our SharePoint w3wp.exe process.

 

Root Cause

========================

Debug Diag already attached to the process.

Debug Diag has rules, which can attach to target process. Even if the rule is completed, it won’t let go of the process.

Another word to say is the debug port is still occurpied by DebugDiag, so other debuggers such as WinDBG or CDB.exe cannot attach and write dump file.

 

Solution

========================

1. Clear the Rules in DebugDiag.

2. Kill the following processes in task manager.

· DbgSvc.exe

· Dbghost.exe

Problem Resolved.

Dump can now be successfully written.

 

Lesson Learned

========================

Be careful with DebugDiag. When its rules are finished, it won’t let go of the process.

 

Reference

========================

How to resolve "Cannot debug pid <pid>, NTSTATUS 0xC0000048" - "An attempt to set a process's DebugPort or ExceptionPort was made ..."

http://blogs.msdn.com/b/spike/archive/2011/10/21/how-to-resolve-quot-cannot-debug-pid-lt-pid-gt-ntstatus-0xc0000048-quot-quot-an-attempt-to-set-a-process-s-debugport-or-exceptionport-was-made-quot.aspx?CommentPosted=true#commentmessage

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值