MEMORY.DMP

27/08/2005 - 21:14 por Javier Garcia Rodriguez | Informe spam
Hola
He conseguido un volcado de memoria, acto seguido lo he debugueado y la
verdad, ¡no entiendo nada!.
Una vez hecho el volcado por un bloqueo de la máquina, al reiniciar me da
error y no es la primera vez, "tray application ha detectado
ghosttray.exe.." y el sistema se ha recuperado de un error grave
Mando el debug del memory.dmp y acto seguido el error generado por la
aplicación.
Gracias


DEBUG DEL MEMORY.DMP


Microsoft (R) Windows Debugger Version 6.5.0003.7
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\WINDOWS\Volcados\MEMORY.DMP]
Kernel Summary Dump File: Only kernel address space is available

Symbol search path is: SRV*c:\archivos de
programa\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 2600.xpsp_sp2_gdr.050301-1519
Kernel base = 0x804d7000 PsLoadedModuleList = 0x805531a0
Debug session time: Sat Aug 27 16:36:07.031 2005 (GMT+2)
System Uptime: 0 days 2:43:04.603
Loading Kernel Symbols
.
Loading unloaded module list
...
Loading User Symbols
*******************************************************************************
*
*
* Bugcheck Analysis
*
*
*
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck E2, {0, 0, 0, 0}

*** ERROR: Module load completed but symbols could not be loaded for
yk51x86.sys
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
halaacpi.dll -
Probably caused by : i8042prt.sys ( i8042prt!I8xProcessCrashDump+237 )

Followup: MachineOwner





kd> !analyze -v
*******************************************************************************
*
*
* Bugcheck Analysis
*
*
*
*******************************************************************************

MANUALLY_INITIATED_CRASH (e2)
The user manually initiated this crash dump.
Arguments:
Arg1: 00000000
Arg2: 00000000
Arg3: 00000000
Arg4: 00000000

Debugging Details:



BUGCHECK_STR: MANUALLY_INITIATED_CRASH

DEFAULT_BUCKET_ID: DRIVER_FAULT

LAST_CONTROL_TRANSFER: from baa8a7fa to 804f8925

STACK_TEXT:
80548b68 baa8a7fa 000000e2 00000000 00000000 nt!KeBugCheckEx+0x1b
80548b84 baa8a032 0049e0d8 010001c6 00000000
i8042prt!I8xProcessCrashDump+0x237
80548bcc 8054071d 89c1f788 8a49e020 00010009
i8042prt!I8042KeyboardInterruptService+0x21c
80548bcc ba1f9b7a 89c1f788 8a49e020 00010009 nt!KiInterruptDispatch+0x3d
WARNING: Stack unwind information not available. Following frames may be
wrong.
80548ca0 ba1eeceb 89e91004 00000180 00000184 yk51x86+0x10b7a
80548cc0 ba58afca 00000000 89e91004 00000000 yk51x86+0x5ceb
80548ce4 804ff234 89e92104 89e920dc 6f74d694 NDIS!ndisMTimerDpcX+0x7a
80548e00 804ff34b 80551b80 80551920 ffdff000 nt!KiTimerListExpire+0x122
80548e2c 80540d5d 80551f80 00000000 00061b16 nt!KiTimerExpiration+0xaf
80548e50 80540cd6 00000000 0000000e 00000000 nt!KiRetireDpcList+0x46
80548e54 00000000 0000000e 00000000 00000000 nt!KiIdleLoop+0x26


FOLLOWUP_IP:
i8042prt!I8xProcessCrashDump+237
baa8a7fa 5d pop ebp

SYMBOL_STACK_INDEX: 1

FOLLOWUP_NAME: MachineOwner

SYMBOL_NAME: i8042prt!I8xProcessCrashDump+237

MODULE_NAME: i8042prt

IMAGE_NAME: i8042prt.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 41107ecc

STACK_COMMAND: kb

FAILURE_BUCKET_ID:
MANUALLY_INITIATED_CRASH_i8042prt!I8xProcessCrashDump+237

BUCKET_ID: MANUALLY_INITIATED_CRASH_i8042prt!I8xProcessCrashDump+237

Followup: MachineOwner




ERROR GENERADO POR EL GHOST 9

<?xml version="1.0" encoding="UTF-16"?>
<DATABASE>
<EXE NAME="GhostTray.exe" FILTER="GRABMI_FILTER_PRIVACY">
<MATCHING_FILE NAME="gearaw32.dll" SIZE="1425408" CHECKSUM="0xED711529"
BIN_FILE_VERSION="3.51.1.6" BIN_PRODUCT_VERSION="3.51.1.6"
PRODUCT_VERSION="3.51.001.06" FILE_DESCRIPTION="GEARAW32 DLL"
COMPANY_NAME="GEAR-Software" PRODUCT_NAME="Gear Internal API 3.xx for
Windows 95/98/NT (Dynamic Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARAW32.DLL" INTERNAL_NAME="GEARAW32"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004" VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x0" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 10:03:17"
UPTO_LINK_DATE="03/02/2004 10:03:17" VER_LANGUAGE="Inglés (Estados Unidos)
[0x409]" />
<MATCHING_FILE NAME="GhostTray.exe" SIZE="1126400" CHECKSUM="0xD87F35DA"
BIN_FILE_VERSION="9.0.2.3981" BIN_PRODUCT_VERSION="9.0.2.3981"
PRODUCT_VERSION="9.0.2.3981" FILE_DESCRIPTION="Tray Application"
COMPANY_NAME="Symantec Corporation" PRODUCT_NAME="Norton Ghost"
FILE_VERSION="9.0.2.3981" ORIGINAL_FILENAME="V2iTray.exe"
INTERNAL_NAME="V2iTray" LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec
Corporation. All rights reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0"
VERFILEOS="0x4" VERFILETYPE="0x1" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="9.0.2.3981"
UPTO_BIN_PRODUCT_VERSION="9.0.2.3981" LINK_DATE="11/23/2004 00:02:36"
UPTO_LINK_DATE="11/23/2004 00:02:36" VER_LANGUAGE="Inglés (Estados Unidos)
[0x409]" />
<MATCHING_FILE NAME="gwlangde.dll" SIZE="143360" CHECKSUM="0x67BDF9A8"
BIN_FILE_VERSION="3.51.1.6" BIN_PRODUCT_VERSION="3.51.1.6"
PRODUCT_VERSION="3.51.001.06" FILE_DESCRIPTION="GEARLANG.DLL"
COMPANY_NAME="GEAR-Software" PRODUCT_NAME="Gear Language Resource DLL for
Windows 95/98/NT (Dynamic Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004" VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x0" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:29"
UPTO_LINK_DATE="03/02/2004 09:56:29" VER_LANGUAGE="Inglés (Estados Unidos)
[0x409]" />
<MATCHING_FILE NAME="gwlangen.dll" SIZE="135168" CHECKSUM="0x8AC4E354"
BIN_FILE_VERSION="3.51.1.6" BIN_PRODUCT_VERSION="3.51.1.6"
PRODUCT_VERSION="3.51.001.06" FILE_DESCRIPTION="GEARLANG.DLL"
COMPANY_NAME="GEAR-Software" PRODUCT_NAME="Gear Language Resource DLL for
Windows 95/98/NT (Dynamic Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004" VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x0" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:34"
UPTO_LINK_DATE="03/02/2004 09:56:34" VER_LANGUAGE="Inglés (Estados Unidos)
[0x409]" />
<MATCHING_FILE NAME="gwlanges.dll" SIZE="147456" CHECKSUM="0xCD96CD5D"
BIN_FILE_VERSION="3.51.1.6" BIN_PRODUCT_VERSION="3.51.1.6"
PRODUCT_VERSION="3.51.001.06" FILE_DESCRIPTION="GEARLANG.DLL"
COMPANY_NAME="GEAR-Software" PRODUCT_NAME="Gear Language Resource DLL for
Windows 95/98/NT (Dynamic Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004" VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x0" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:35"
UPTO_LINK_DATE="03/02/2004 09:56:35" VER_LANGUAGE="Inglés (Estados Unidos)
[0x409]" />
<MATCHING_FILE NAME="gwlangfr.dll" SIZE="151552" CHECKSUM="0x697B0A2D"
BIN_FILE_VERSION="3.51.1.6" BIN_PRODUCT_VERSION="3.51.1.6"
PRODUCT_VERSION="3.51.001.06" FILE_DESCRIPTION="GEARLANG.DLL"
COMPANY_NAME="GEAR-Software" PRODUCT_NAME="Gear Language Resource DLL for
Windows 95/98/NT (Dynamic Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004" VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x0" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:28"
UPTO_LINK_DATE="03/02/2004 09:56:28" VER_LANGUAGE="Inglés (Estados Unidos)
[0x409]" />
<MATCHING_FILE NAME="gwlangit.dll" SIZE="147456" CHECKSUM="0xCD9ACD5D"
BIN_FILE_VERSION="3.51.1.6" BIN_PRODUCT_VERSION="3.51.1.6"
PRODUCT_VERSION="3.51.001.06" FILE_DESCRIPTION="GEARLANG.DLL"
COMPANY_NAME="GEAR-Software" PRODUCT_NAME="Gear Language Resource DLL for
Windows 95/98/NT (Dynamic Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004" VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x0" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:33"
UPTO_LINK_DATE="03/02/2004 09:56:33" VER_LANGUAGE="Inglés (Estados Unidos)
[0x409]" />
<MATCHING_FILE NAME="gwlangnl.dll" SIZE="147456" CHECKSUM="0xCD988D5D"
BIN_FILE_VERSION="3.51.1.6" BIN_PRODUCT_VERSION="3.51.1.6"
PRODUCT_VERSION="3.51.001.06" FILE_DESCRIPTION="GEARLANG.DLL"
COMPANY_NAME="GEAR-Software" PRODUCT_NAME="Gear Language Resource DLL for
Windows 95/98/NT (Dynamic Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004" VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x0" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:31"
UPTO_LINK_DATE="03/02/2004 09:56:31" VER_LANGUAGE="Inglés (Estados Unidos)
[0x409]" />
<MATCHING_FILE NAME="gwlangpl.dll" SIZE="139264" CHECKSUM="0x724C0217"
BIN_FILE_VERSION="3.51.1.6" BIN_PRODUCT_VERSION="3.51.1.6"
PRODUCT_VERSION="3.51.001.06" FILE_DESCRIPTION="GEARLANG.DLL"
COMPANY_NAME="GEAR-Software" PRODUCT_NAME="Gear Language Resource DLL for
Windows 95/98/NT (Dynamic Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004" VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x0" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:27"
UPTO_LINK_DATE="03/02/2004 09:56:27" VER_LANGUAGE="Inglés (Estados Unidos)
[0x409]" />
<MATCHING_FILE NAME="gwlangsv.dll" SIZE="139264" CHECKSUM="0x6B279217"
BIN_FILE_VERSION="3.51.1.6" BIN_PRODUCT_VERSION="3.51.1.6"
PRODUCT_VERSION="3.51.001.06" FILE_DESCRIPTION="GEARLANG.DLL"
COMPANY_NAME="GEAR-Software" PRODUCT_NAME="Gear Language Resource DLL for
Windows 95/98/NT (Dynamic Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004" VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x0" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:30"
UPTO_LINK_DATE="03/02/2004 09:56:30" VER_LANGUAGE="Inglés (Estados Unidos)
[0x409]" />
<MATCHING_FILE NAME="gwrks32.dll" SIZE="204800" CHECKSUM="0x42B52563"
BIN_FILE_VERSION="3.51.1.6" BIN_PRODUCT_VERSION="3.51.1.6"
PRODUCT_VERSION="3.51.001.06" FILE_DESCRIPTION="GEAR.wrks main dll"
COMPANY_NAME="GEAR-Software" PRODUCT_NAME="GEAR.wrks 3.00 for Windows
95/98/NT" FILE_VERSION="3.51.001.06" ORIGINAL_FILENAME="GWRKS32.DLL"
INTERNAL_NAME="GWRKS32" LEGAL_COPYRIGHT="Copyright © GEAR-Software
1992-2004" VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0" LINKER_VERSION="0x0"
UPTO_BIN_FILE_VERSION="3.51.1.6" UPTO_BIN_PRODUCT_VERSION="3.51.1.6"
LINK_DATE="03/02/2004 10:04:54" UPTO_LINK_DATE="03/02/2004 10:04:54"
VER_LANGUAGE="Inglés (Estados Unidos) [0x409]" />
<MATCHING_FILE NAME="PQImaging.dll" SIZE="794624" CHECKSUM="0x4DC6D82"
BIN_FILE_VERSION="9.0.2.3981" BIN_PRODUCT_VERSION="9.0.2.3981"
PRODUCT_VERSION="9.0.2.3981" FILE_DESCRIPTION="Imaging Module"
COMPANY_NAME="Symantec Corporation" PRODUCT_NAME="Norton Ghost"
FILE_VERSION="9.0.2.3981" ORIGINAL_FILENAME="PQImaging.dll"
INTERNAL_NAME="PQImaging" LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec
Corporation. All rights reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0"
VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="9.0.2.3981"
UPTO_BIN_PRODUCT_VERSION="9.0.2.3981" LINK_DATE="11/23/2004 00:03:25"
UPTO_LINK_DATE="11/23/2004 00:03:25" VER_LANGUAGE="Inglés (Estados Unidos)
[0x409]" />
<MATCHING_FILE NAME="PQSmeCOM.dll" SIZE="5775360" CHECKSUM="0x8A1C9BEC"
BIN_FILE_VERSION="9.0.2.3981" BIN_PRODUCT_VERSION="9.0.2.3981"
PRODUCT_VERSION="9.0.2.3981" FILE_DESCRIPTION="SME COM Module"
COMPANY_NAME="Symantec Corporation" PRODUCT_NAME="Norton Ghost"
FILE_VERSION="9.0.2.3981" ORIGINAL_FILENAME="PQSmeCOM.dll"
INTERNAL_NAME="PQSmeCOM" LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec
Corporation. All rights reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0"
VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="9.0.2.3981"
UPTO_BIN_PRODUCT_VERSION="9.0.2.3981" LINK_DATE="11/23/2004 00:03:00"
UPTO_LINK_DATE="11/23/2004 00:03:00" VER_LANGUAGE="Inglés (Estados Unidos)
[0x409]" />
<MATCHING_FILE NAME="PQV2iCOM.dll" SIZE="696320" CHECKSUM="0x94D9445E"
BIN_FILE_VERSION="9.0.2.3981" BIN_PRODUCT_VERSION="9.0.2.3981"
PRODUCT_VERSION="9.0.2.3981" FILE_DESCRIPTION="Virtual Volume Imaging COM
Module" COMPANY_NAME="Symantec Corporation" PRODUCT_NAME="Norton Ghost"
FILE_VERSION="9.0.2.3981" ORIGINAL_FILENAME="PQV2iCOM.dll"
INTERNAL_NAME="PQV2iCOM" LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec
Corporation. All rights reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0"
VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="9.0.2.3981"
UPTO_BIN_PRODUCT_VERSION="9.0.2.3981" LINK_DATE="11/22/2004 23:52:25"
UPTO_LINK_DATE="11/22/2004 23:52:25" VER_LANGUAGE="Inglés (Estados Unidos)
[0x409]" />
<MATCHING_FILE NAME="PQV2ISECURITY.EXE" SIZE="770048"
CHECKSUM="0x657E041B" BIN_FILE_VERSION="9.0.2.3981"
BIN_PRODUCT_VERSION="9.0.2.3981" PRODUCT_VERSION="9.0.2.3981"
FILE_DESCRIPTION="DCOMSetup Application" COMPANY_NAME="Symantec Corporation"
PRODUCT_NAME="Norton Ghost" FILE_VERSION="9.0.2.3981"
ORIGINAL_FILENAME="DCOMSetup.EXE" INTERNAL_NAME="DCOMSetup"
LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec Corporation. All rights
reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x1" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0" LINKER_VERSION="0x0"
UPTO_BIN_FILE_VERSION="9.0.2.3981" UPTO_BIN_PRODUCT_VERSION="9.0.2.3981"
LINK_DATE="11/23/2004 00:14:17" UPTO_LINK_DATE="11/23/2004 00:14:17"
VER_LANGUAGE="Inglés (Estados Unidos) [0x409]" />
<MATCHING_FILE NAME="PQV2iSvc.exe" SIZE="1273856" CHECKSUM="0x7B88A325"
BIN_FILE_VERSION="9.0.2.3981" BIN_PRODUCT_VERSION="9.0.2.3981"
PRODUCT_VERSION="9.0.2.3981" FILE_DESCRIPTION="Service Module"
COMPANY_NAME="Symantec Corporation" PRODUCT_NAME="Norton Ghost"
FILE_VERSION="9.0.2.3981" ORIGINAL_FILENAME="PQV2iSvc.exe"
INTERNAL_NAME="PQV2iSvc" LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec
Corporation. All rights reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0"
VERFILEOS="0x4" VERFILETYPE="0x1" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="9.0.2.3981"
UPTO_BIN_PRODUCT_VERSION="9.0.2.3981" LINK_DATE="11/23/2004 00:04:13"
UPTO_LINK_DATE="11/23/2004 00:04:13" VER_LANGUAGE="Inglés (Estados Unidos)
[0x409]" />
<MATCHING_FILE NAME="psikey.dll" SIZE="1060864" CHECKSUM="0x3BBF1B39"
BIN_FILE_VERSION="1.3.0.43" BIN_PRODUCT_VERSION="1.3.0.43"
PRODUCT_VERSION="1.3.0.43" FILE_DESCRIPTION="nTitles Activator"
COMPANY_NAME="Protexis Inc." PRODUCT_NAME="Protexis nTitles"
FILE_VERSION="1.3.0.43" ORIGINAL_FILENAME="PSIKey.DLL"
INTERNAL_NAME="SecureInstall" LEGAL_COPYRIGHT="Copyright (C) 2000-2002
Protexis Inc." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0" LINKER_VERSION="0x0"
UPTO_BIN_FILE_VERSION="1.3.0.43" UPTO_BIN_PRODUCT_VERSION="1.3.0.43"
LINK_DATE="03/27/2003 20:19:53" UPTO_LINK_DATE="03/27/2003 20:19:53"
VER_LANGUAGE="Inglés (Estados Unidos) [0x409]" />
</EXE>
<EXE NAME="kernel32.dll" FILTER="GRABMI_FILTER_THISFILEONLY">
<MATCHING_FILE NAME="kernel32.dll" SIZE="1036800" CHECKSUM="0x4B5D905A"
BIN_FILE_VERSION="5.1.2600.2180" BIN_PRODUCT_VERSION="5.1.2600.2180"
PRODUCT_VERSION="5.1.2600.2180" FILE_DESCRIPTION="DLL de cliente API BASE de
Windows NT" COMPANY_NAME="Microsoft Corporation" PRODUCT_NAME="Sistema
operativo Microsoft® Windows®" FILE_VERSION="5.1.2600.2180
(xpsp_sp2_rtm.040803-2158)" ORIGINAL_FILENAME="kernel32"
INTERNAL_NAME="kernel32" LEGAL_COPYRIGHT="Copyright (C) Microsoft
Corporation. Reservados todos los derechos." VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x2"
MODULE_TYPE="WIN32" PE_CHECKSUM="0x106088" LINKER_VERSION="0x50001"
UPTO_BIN_FILE_VERSION="5.1.2600.2180"
UPTO_BIN_PRODUCT_VERSION="5.1.2600.2180" LINK_DATE="08/19/2004 22:41:31"
UPTO_LINK_DATE="08/19/2004 22:41:31" VER_LANGUAGE="Español (alfabetización
internacional) [0xc0a]" />
</EXE>
</DATABASE>











Atentamente
Javier García Rodríguez

Preguntas similare

Leer las respuestas

#1 Javier Garcia Rodriguez
27/08/2005 - 22:16 | Informe spam
En un principio ya tengo eliminado del sistema el norton ghost.
Uno menos para interferir en el sistema, si es que interfería.
Saludos

"Javier Garcia Rodriguez" escribió en el mensaje
news:%23%
Hola
He conseguido un volcado de memoria, acto seguido lo he debugueado y la
verdad, ¡no entiendo nada!.
Una vez hecho el volcado por un bloqueo de la máquina, al reiniciar me da
error y no es la primera vez, "tray application ha detectado
ghosttray.exe.." y el sistema se ha recuperado de un error grave
Mando el debug del memory.dmp y acto seguido el error generado por la
aplicación.
Gracias


DEBUG DEL MEMORY.DMP


Microsoft (R) Windows Debugger Version 6.5.0003.7
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\WINDOWS\Volcados\MEMORY.DMP]
Kernel Summary Dump File: Only kernel address space is available

Symbol search path is: SRV*c:\archivos de
programa\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 2600.xpsp_sp2_gdr.050301-1519
Kernel base = 0x804d7000 PsLoadedModuleList = 0x805531a0
Debug session time: Sat Aug 27 16:36:07.031 2005 (GMT+2)
System Uptime: 0 days 2:43:04.603
Loading Kernel Symbols
.
Loading unloaded module list
...
Loading User Symbols
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck E2, {0, 0, 0, 0}

*** ERROR: Module load completed but symbols could not be loaded for
yk51x86.sys
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for halaacpi.dll -
Probably caused by : i8042prt.sys ( i8042prt!I8xProcessCrashDump+237 )

Followup: MachineOwner





kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

MANUALLY_INITIATED_CRASH (e2)
The user manually initiated this crash dump.
Arguments:
Arg1: 00000000
Arg2: 00000000
Arg3: 00000000
Arg4: 00000000

Debugging Details:



BUGCHECK_STR: MANUALLY_INITIATED_CRASH

DEFAULT_BUCKET_ID: DRIVER_FAULT

LAST_CONTROL_TRANSFER: from baa8a7fa to 804f8925

STACK_TEXT:
80548b68 baa8a7fa 000000e2 00000000 00000000 nt!KeBugCheckEx+0x1b
80548b84 baa8a032 0049e0d8 010001c6 00000000
i8042prt!I8xProcessCrashDump+0x237
80548bcc 8054071d 89c1f788 8a49e020 00010009
i8042prt!I8042KeyboardInterruptService+0x21c
80548bcc ba1f9b7a 89c1f788 8a49e020 00010009 nt!KiInterruptDispatch+0x3d
WARNING: Stack unwind information not available. Following frames may be
wrong.
80548ca0 ba1eeceb 89e91004 00000180 00000184 yk51x86+0x10b7a
80548cc0 ba58afca 00000000 89e91004 00000000 yk51x86+0x5ceb
80548ce4 804ff234 89e92104 89e920dc 6f74d694 NDIS!ndisMTimerDpcX+0x7a
80548e00 804ff34b 80551b80 80551920 ffdff000 nt!KiTimerListExpire+0x122
80548e2c 80540d5d 80551f80 00000000 00061b16 nt!KiTimerExpiration+0xaf
80548e50 80540cd6 00000000 0000000e 00000000 nt!KiRetireDpcList+0x46
80548e54 00000000 0000000e 00000000 00000000 nt!KiIdleLoop+0x26


FOLLOWUP_IP:
i8042prt!I8xProcessCrashDump+237
baa8a7fa 5d pop ebp

SYMBOL_STACK_INDEX: 1

FOLLOWUP_NAME: MachineOwner

SYMBOL_NAME: i8042prt!I8xProcessCrashDump+237

MODULE_NAME: i8042prt

IMAGE_NAME: i8042prt.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 41107ecc

STACK_COMMAND: kb

FAILURE_BUCKET_ID:
MANUALLY_INITIATED_CRASH_i8042prt!I8xProcessCrashDump+237

BUCKET_ID: MANUALLY_INITIATED_CRASH_i8042prt!I8xProcessCrashDump+237

Followup: MachineOwner




ERROR GENERADO POR EL GHOST 9

<?xml version="1.0" encoding="UTF-16"?>
<DATABASE>
<EXE NAME="GhostTray.exe" FILTER="GRABMI_FILTER_PRIVACY">
<MATCHING_FILE NAME="gearaw32.dll" SIZE="1425408" CHECKSUM="0xED711529"
BIN_FILE_VERSION="3.51.1.6" BIN_PRODUCT_VERSION="3.51.1.6"
PRODUCT_VERSION="3.51.001.06" FILE_DESCRIPTION="GEARAW32 DLL"
COMPANY_NAME="GEAR-Software" PRODUCT_NAME="Gear Internal API 3.xx for
Windows 95/98/NT (Dynamic Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARAW32.DLL" INTERNAL_NAME="GEARAW32"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004" VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x0" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 10:03:17"
UPTO_LINK_DATE="03/02/2004 10:03:17" VER_LANGUAGE="Inglés (Estados Unidos)
[0x409]" />
<MATCHING_FILE NAME="GhostTray.exe" SIZE="1126400"
CHECKSUM="0xD87F35DA" BIN_FILE_VERSION="9.0.2.3981"
BIN_PRODUCT_VERSION="9.0.2.3981" PRODUCT_VERSION="9.0.2.3981"
FILE_DESCRIPTION="Tray Application" COMPANY_NAME="Symantec Corporation"
PRODUCT_NAME="Norton Ghost" FILE_VERSION="9.0.2.3981"
ORIGINAL_FILENAME="V2iTray.exe" INTERNAL_NAME="V2iTray"
LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec Corporation. All rights
reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x1" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="9.0.2.3981"
UPTO_BIN_PRODUCT_VERSION="9.0.2.3981" LINK_DATE="11/23/2004 00:02:36"
UPTO_LINK_DATE="11/23/2004 00:02:36" VER_LANGUAGE="Inglés (Estados Unidos)
[0x409]" />
<MATCHING_FILE NAME="gwlangde.dll" SIZE="143360" CHECKSUM="0x67BDF9A8"
BIN_FILE_VERSION="3.51.1.6" BIN_PRODUCT_VERSION="3.51.1.6"
PRODUCT_VERSION="3.51.001.06" FILE_DESCRIPTION="GEARLANG.DLL"
COMPANY_NAME="GEAR-Software" PRODUCT_NAME="Gear Language Resource DLL for
Windows 95/98/NT (Dynamic Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004" VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x0" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:29"
UPTO_LINK_DATE="03/02/2004 09:56:29" VER_LANGUAGE="Inglés (Estados Unidos)
[0x409]" />
<MATCHING_FILE NAME="gwlangen.dll" SIZE="135168" CHECKSUM="0x8AC4E354"
BIN_FILE_VERSION="3.51.1.6" BIN_PRODUCT_VERSION="3.51.1.6"
PRODUCT_VERSION="3.51.001.06" FILE_DESCRIPTION="GEARLANG.DLL"
COMPANY_NAME="GEAR-Software" PRODUCT_NAME="Gear Language Resource DLL for
Windows 95/98/NT (Dynamic Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004" VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x0" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:34"
UPTO_LINK_DATE="03/02/2004 09:56:34" VER_LANGUAGE="Inglés (Estados Unidos)
[0x409]" />
<MATCHING_FILE NAME="gwlanges.dll" SIZE="147456" CHECKSUM="0xCD96CD5D"
BIN_FILE_VERSION="3.51.1.6" BIN_PRODUCT_VERSION="3.51.1.6"
PRODUCT_VERSION="3.51.001.06" FILE_DESCRIPTION="GEARLANG.DLL"
COMPANY_NAME="GEAR-Software" PRODUCT_NAME="Gear Language Resource DLL for
Windows 95/98/NT (Dynamic Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004" VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x0" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:35"
UPTO_LINK_DATE="03/02/2004 09:56:35" VER_LANGUAGE="Inglés (Estados Unidos)
[0x409]" />
<MATCHING_FILE NAME="gwlangfr.dll" SIZE="151552" CHECKSUM="0x697B0A2D"
BIN_FILE_VERSION="3.51.1.6" BIN_PRODUCT_VERSION="3.51.1.6"
PRODUCT_VERSION="3.51.001.06" FILE_DESCRIPTION="GEARLANG.DLL"
COMPANY_NAME="GEAR-Software" PRODUCT_NAME="Gear Language Resource DLL for
Windows 95/98/NT (Dynamic Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004" VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x0" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:28"
UPTO_LINK_DATE="03/02/2004 09:56:28" VER_LANGUAGE="Inglés (Estados Unidos)
[0x409]" />
<MATCHING_FILE NAME="gwlangit.dll" SIZE="147456" CHECKSUM="0xCD9ACD5D"
BIN_FILE_VERSION="3.51.1.6" BIN_PRODUCT_VERSION="3.51.1.6"
PRODUCT_VERSION="3.51.001.06" FILE_DESCRIPTION="GEARLANG.DLL"
COMPANY_NAME="GEAR-Software" PRODUCT_NAME="Gear Language Resource DLL for
Windows 95/98/NT (Dynamic Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004" VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x0" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:33"
UPTO_LINK_DATE="03/02/2004 09:56:33" VER_LANGUAGE="Inglés (Estados Unidos)
[0x409]" />
<MATCHING_FILE NAME="gwlangnl.dll" SIZE="147456" CHECKSUM="0xCD988D5D"
BIN_FILE_VERSION="3.51.1.6" BIN_PRODUCT_VERSION="3.51.1.6"
PRODUCT_VERSION="3.51.001.06" FILE_DESCRIPTION="GEARLANG.DLL"
COMPANY_NAME="GEAR-Software" PRODUCT_NAME="Gear Language Resource DLL for
Windows 95/98/NT (Dynamic Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004" VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x0" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:31"
UPTO_LINK_DATE="03/02/2004 09:56:31" VER_LANGUAGE="Inglés (Estados Unidos)
[0x409]" />
<MATCHING_FILE NAME="gwlangpl.dll" SIZE="139264" CHECKSUM="0x724C0217"
BIN_FILE_VERSION="3.51.1.6" BIN_PRODUCT_VERSION="3.51.1.6"
PRODUCT_VERSION="3.51.001.06" FILE_DESCRIPTION="GEARLANG.DLL"
COMPANY_NAME="GEAR-Software" PRODUCT_NAME="Gear Language Resource DLL for
Windows 95/98/NT (Dynamic Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004" VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x0" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:27"
UPTO_LINK_DATE="03/02/2004 09:56:27" VER_LANGUAGE="Inglés (Estados Unidos)
[0x409]" />
<MATCHING_FILE NAME="gwlangsv.dll" SIZE="139264" CHECKSUM="0x6B279217"
BIN_FILE_VERSION="3.51.1.6" BIN_PRODUCT_VERSION="3.51.1.6"
PRODUCT_VERSION="3.51.001.06" FILE_DESCRIPTION="GEARLANG.DLL"
COMPANY_NAME="GEAR-Software" PRODUCT_NAME="Gear Language Resource DLL for
Windows 95/98/NT (Dynamic Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004" VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x0" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:30"
UPTO_LINK_DATE="03/02/2004 09:56:30" VER_LANGUAGE="Inglés (Estados Unidos)
[0x409]" />
<MATCHING_FILE NAME="gwrks32.dll" SIZE="204800" CHECKSUM="0x42B52563"
BIN_FILE_VERSION="3.51.1.6" BIN_PRODUCT_VERSION="3.51.1.6"
PRODUCT_VERSION="3.51.001.06" FILE_DESCRIPTION="GEAR.wrks main dll"
COMPANY_NAME="GEAR-Software" PRODUCT_NAME="GEAR.wrks 3.00 for Windows
95/98/NT" FILE_VERSION="3.51.001.06" ORIGINAL_FILENAME="GWRKS32.DLL"
INTERNAL_NAME="GWRKS32" LEGAL_COPYRIGHT="Copyright © GEAR-Software
1992-2004" VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 10:04:54"
UPTO_LINK_DATE="03/02/2004 10:04:54" VER_LANGUAGE="Inglés (Estados Unidos)
[0x409]" />
<MATCHING_FILE NAME="PQImaging.dll" SIZE="794624" CHECKSUM="0x4DC6D82"
BIN_FILE_VERSION="9.0.2.3981" BIN_PRODUCT_VERSION="9.0.2.3981"
PRODUCT_VERSION="9.0.2.3981" FILE_DESCRIPTION="Imaging Module"
COMPANY_NAME="Symantec Corporation" PRODUCT_NAME="Norton Ghost"
FILE_VERSION="9.0.2.3981" ORIGINAL_FILENAME="PQImaging.dll"
INTERNAL_NAME="PQImaging" LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec
Corporation. All rights reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0"
VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="9.0.2.3981"
UPTO_BIN_PRODUCT_VERSION="9.0.2.3981" LINK_DATE="11/23/2004 00:03:25"
UPTO_LINK_DATE="11/23/2004 00:03:25" VER_LANGUAGE="Inglés (Estados Unidos)
[0x409]" />
<MATCHING_FILE NAME="PQSmeCOM.dll" SIZE="5775360" CHECKSUM="0x8A1C9BEC"
BIN_FILE_VERSION="9.0.2.3981" BIN_PRODUCT_VERSION="9.0.2.3981"
PRODUCT_VERSION="9.0.2.3981" FILE_DESCRIPTION="SME COM Module"
COMPANY_NAME="Symantec Corporation" PRODUCT_NAME="Norton Ghost"
FILE_VERSION="9.0.2.3981" ORIGINAL_FILENAME="PQSmeCOM.dll"
INTERNAL_NAME="PQSmeCOM" LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec
Corporation. All rights reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0"
VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="9.0.2.3981"
UPTO_BIN_PRODUCT_VERSION="9.0.2.3981" LINK_DATE="11/23/2004 00:03:00"
UPTO_LINK_DATE="11/23/2004 00:03:00" VER_LANGUAGE="Inglés (Estados Unidos)
[0x409]" />
<MATCHING_FILE NAME="PQV2iCOM.dll" SIZE="696320" CHECKSUM="0x94D9445E"
BIN_FILE_VERSION="9.0.2.3981" BIN_PRODUCT_VERSION="9.0.2.3981"
PRODUCT_VERSION="9.0.2.3981" FILE_DESCRIPTION="Virtual Volume Imaging COM
Module" COMPANY_NAME="Symantec Corporation" PRODUCT_NAME="Norton Ghost"
FILE_VERSION="9.0.2.3981" ORIGINAL_FILENAME="PQV2iCOM.dll"
INTERNAL_NAME="PQV2iCOM" LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec
Corporation. All rights reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0"
VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="9.0.2.3981"
UPTO_BIN_PRODUCT_VERSION="9.0.2.3981" LINK_DATE="11/22/2004 23:52:25"
UPTO_LINK_DATE="11/22/2004 23:52:25" VER_LANGUAGE="Inglés (Estados Unidos)
[0x409]" />
<MATCHING_FILE NAME="PQV2ISECURITY.EXE" SIZE="770048"
CHECKSUM="0x657E041B" BIN_FILE_VERSION="9.0.2.3981"
BIN_PRODUCT_VERSION="9.0.2.3981" PRODUCT_VERSION="9.0.2.3981"
FILE_DESCRIPTION="DCOMSetup Application" COMPANY_NAME="Symantec
Corporation" PRODUCT_NAME="Norton Ghost" FILE_VERSION="9.0.2.3981"
ORIGINAL_FILENAME="DCOMSetup.EXE" INTERNAL_NAME="DCOMSetup"
LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec Corporation. All rights
reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x1" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="9.0.2.3981"
UPTO_BIN_PRODUCT_VERSION="9.0.2.3981" LINK_DATE="11/23/2004 00:14:17"
UPTO_LINK_DATE="11/23/2004 00:14:17" VER_LANGUAGE="Inglés (Estados Unidos)
[0x409]" />
<MATCHING_FILE NAME="PQV2iSvc.exe" SIZE="1273856" CHECKSUM="0x7B88A325"
BIN_FILE_VERSION="9.0.2.3981" BIN_PRODUCT_VERSION="9.0.2.3981"
PRODUCT_VERSION="9.0.2.3981" FILE_DESCRIPTION="Service Module"
COMPANY_NAME="Symantec Corporation" PRODUCT_NAME="Norton Ghost"
FILE_VERSION="9.0.2.3981" ORIGINAL_FILENAME="PQV2iSvc.exe"
INTERNAL_NAME="PQV2iSvc" LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec
Corporation. All rights reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0"
VERFILEOS="0x4" VERFILETYPE="0x1" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="9.0.2.3981"
UPTO_BIN_PRODUCT_VERSION="9.0.2.3981" LINK_DATE="11/23/2004 00:04:13"
UPTO_LINK_DATE="11/23/2004 00:04:13" VER_LANGUAGE="Inglés (Estados Unidos)
[0x409]" />
<MATCHING_FILE NAME="psikey.dll" SIZE="1060864" CHECKSUM="0x3BBF1B39"
BIN_FILE_VERSION="1.3.0.43" BIN_PRODUCT_VERSION="1.3.0.43"
PRODUCT_VERSION="1.3.0.43" FILE_DESCRIPTION="nTitles Activator"
COMPANY_NAME="Protexis Inc." PRODUCT_NAME="Protexis nTitles"
FILE_VERSION="1.3.0.43" ORIGINAL_FILENAME="PSIKey.DLL"
INTERNAL_NAME="SecureInstall" LEGAL_COPYRIGHT="Copyright (C) 2000-2002
Protexis Inc." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="1.3.0.43"
UPTO_BIN_PRODUCT_VERSION="1.3.0.43" LINK_DATE="03/27/2003 20:19:53"
UPTO_LINK_DATE="03/27/2003 20:19:53" VER_LANGUAGE="Inglés (Estados Unidos)
[0x409]" />
</EXE>
<EXE NAME="kernel32.dll" FILTER="GRABMI_FILTER_THISFILEONLY">
<MATCHING_FILE NAME="kernel32.dll" SIZE="1036800" CHECKSUM="0x4B5D905A"
BIN_FILE_VERSION="5.1.2600.2180" BIN_PRODUCT_VERSION="5.1.2600.2180"
PRODUCT_VERSION="5.1.2600.2180" FILE_DESCRIPTION="DLL de cliente API BASE
de Windows NT" COMPANY_NAME="Microsoft Corporation" PRODUCT_NAME="Sistema
operativo Microsoft® Windows®" FILE_VERSION="5.1.2600.2180
(xpsp_sp2_rtm.040803-2158)" ORIGINAL_FILENAME="kernel32"
INTERNAL_NAME="kernel32" LEGAL_COPYRIGHT="Copyright (C) Microsoft
Corporation. Reservados todos los derechos." VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x2"
MODULE_TYPE="WIN32" PE_CHECKSUM="0x106088" LINKER_VERSION="0x50001"
UPTO_BIN_FILE_VERSION="5.1.2600.2180"
UPTO_BIN_PRODUCT_VERSION="5.1.2600.2180" LINK_DATE="08/19/2004 22:41:31"
UPTO_LINK_DATE="08/19/2004 22:41:31" VER_LANGUAGE="Español (alfabetización
internacional) [0xc0a]" />
</EXE>
</DATABASE>











Atentamente
Javier García Rodríguez


Respuesta Responder a este mensaje
#2 JM Tella Llop [MVP Windows]
27/08/2005 - 22:24 | Informe spam
pues tenía toda la pinta...

Jose Manuel Tella Llop
MVP - Windows
(quitar XXX)
http://www.multingles.net/jmt.htm

Este mensaje se proporciona "como está" sin garantías de ninguna clase,
y no otorga ningún derecho.

This posting is provided "AS IS" with no warranties, and confers no
rights.
You assume all risk for your use.



"Javier Garcia Rodriguez" wrote in message
news:
En un principio ya tengo eliminado del sistema el norton ghost.
Uno menos para interferir en el sistema, si es que interfería.
Saludos

"Javier Garcia Rodriguez" escribió en el mensaje
news:%23%
Hola
He conseguido un volcado de memoria, acto seguido lo he debugueado y la
verdad, ¡no entiendo nada!.
Una vez hecho el volcado por un bloqueo de la máquina, al reiniciar me da
error y no es la primera vez, "tray application ha detectado
ghosttray.exe.." y el sistema se ha recuperado de un error grave
Mando el debug del memory.dmp y acto seguido el error generado por la
aplicación.
Gracias


DEBUG DEL MEMORY.DMP


Microsoft (R) Windows Debugger Version 6.5.0003.7
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\WINDOWS\Volcados\MEMORY.DMP]
Kernel Summary Dump File: Only kernel address space is available

Symbol search path is: SRV*c:\archivos de
programa\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 2600.xpsp_sp2_gdr.050301-1519
Kernel base = 0x804d7000 PsLoadedModuleList = 0x805531a0
Debug session time: Sat Aug 27 16:36:07.031 2005 (GMT+2)
System Uptime: 0 days 2:43:04.603
Loading Kernel Symbols
.
Loading unloaded module list
...
Loading User Symbols
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck E2, {0, 0, 0, 0}

*** ERROR: Module load completed but symbols could not be loaded for
yk51x86.sys
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for halaacpi.dll -
Probably caused by : i8042prt.sys ( i8042prt!I8xProcessCrashDump+237 )

Followup: MachineOwner





kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

MANUALLY_INITIATED_CRASH (e2)
The user manually initiated this crash dump.
Arguments:
Arg1: 00000000
Arg2: 00000000
Arg3: 00000000
Arg4: 00000000

Debugging Details:



BUGCHECK_STR: MANUALLY_INITIATED_CRASH

DEFAULT_BUCKET_ID: DRIVER_FAULT

LAST_CONTROL_TRANSFER: from baa8a7fa to 804f8925

STACK_TEXT:
80548b68 baa8a7fa 000000e2 00000000 00000000 nt!KeBugCheckEx+0x1b
80548b84 baa8a032 0049e0d8 010001c6 00000000
i8042prt!I8xProcessCrashDump+0x237
80548bcc 8054071d 89c1f788 8a49e020 00010009
i8042prt!I8042KeyboardInterruptService+0x21c
80548bcc ba1f9b7a 89c1f788 8a49e020 00010009 nt!KiInterruptDispatch+0x3d
WARNING: Stack unwind information not available. Following frames may be
wrong.
80548ca0 ba1eeceb 89e91004 00000180 00000184 yk51x86+0x10b7a
80548cc0 ba58afca 00000000 89e91004 00000000 yk51x86+0x5ceb
80548ce4 804ff234 89e92104 89e920dc 6f74d694 NDIS!ndisMTimerDpcX+0x7a
80548e00 804ff34b 80551b80 80551920 ffdff000 nt!KiTimerListExpire+0x122
80548e2c 80540d5d 80551f80 00000000 00061b16 nt!KiTimerExpiration+0xaf
80548e50 80540cd6 00000000 0000000e 00000000 nt!KiRetireDpcList+0x46
80548e54 00000000 0000000e 00000000 00000000 nt!KiIdleLoop+0x26


FOLLOWUP_IP:
i8042prt!I8xProcessCrashDump+237
baa8a7fa 5d pop ebp

SYMBOL_STACK_INDEX: 1

FOLLOWUP_NAME: MachineOwner

SYMBOL_NAME: i8042prt!I8xProcessCrashDump+237

MODULE_NAME: i8042prt

IMAGE_NAME: i8042prt.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 41107ecc

STACK_COMMAND: kb

FAILURE_BUCKET_ID:
MANUALLY_INITIATED_CRASH_i8042prt!I8xProcessCrashDump+237

BUCKET_ID: MANUALLY_INITIATED_CRASH_i8042prt!I8xProcessCrashDump+237

Followup: MachineOwner




ERROR GENERADO POR EL GHOST 9

<?xml version="1.0" encoding="UTF-16"?>
<DATABASE>
<EXE NAME="GhostTray.exe" FILTER="GRABMI_FILTER_PRIVACY">
<MATCHING_FILE NAME="gearaw32.dll" SIZE="1425408"
CHECKSUM="0xED711529" BIN_FILE_VERSION="3.51.1.6"
BIN_PRODUCT_VERSION="3.51.1.6" PRODUCT_VERSION="3.51.001.06"
FILE_DESCRIPTION="GEARAW32 DLL" COMPANY_NAME="GEAR-Software"
PRODUCT_NAME="Gear Internal API 3.xx for Windows 95/98/NT (Dynamic Link
Library)" FILE_VERSION="3.51.001.06" ORIGINAL_FILENAME="GEARAW32.DLL"
INTERNAL_NAME="GEARAW32" LEGAL_COPYRIGHT="Copyright © GEAR-Software
1992-2004" VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 10:03:17"
UPTO_LINK_DATE="03/02/2004 10:03:17" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="GhostTray.exe" SIZE="1126400"
CHECKSUM="0xD87F35DA" BIN_FILE_VERSION="9.0.2.3981"
BIN_PRODUCT_VERSION="9.0.2.3981" PRODUCT_VERSION="9.0.2.3981"
FILE_DESCRIPTION="Tray Application" COMPANY_NAME="Symantec Corporation"
PRODUCT_NAME="Norton Ghost" FILE_VERSION="9.0.2.3981"
ORIGINAL_FILENAME="V2iTray.exe" INTERNAL_NAME="V2iTray"
LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec Corporation. All rights
reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x1" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="9.0.2.3981"
UPTO_BIN_PRODUCT_VERSION="9.0.2.3981" LINK_DATE="11/23/2004 00:02:36"
UPTO_LINK_DATE="11/23/2004 00:02:36" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwlangde.dll" SIZE="143360" CHECKSUM="0x67BDF9A8"
BIN_FILE_VERSION="3.51.1.6" BIN_PRODUCT_VERSION="3.51.1.6"
PRODUCT_VERSION="3.51.001.06" FILE_DESCRIPTION="GEARLANG.DLL"
COMPANY_NAME="GEAR-Software" PRODUCT_NAME="Gear Language Resource DLL for
Windows 95/98/NT (Dynamic Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004" VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x0" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:29"
UPTO_LINK_DATE="03/02/2004 09:56:29" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwlangen.dll" SIZE="135168" CHECKSUM="0x8AC4E354"
BIN_FILE_VERSION="3.51.1.6" BIN_PRODUCT_VERSION="3.51.1.6"
PRODUCT_VERSION="3.51.001.06" FILE_DESCRIPTION="GEARLANG.DLL"
COMPANY_NAME="GEAR-Software" PRODUCT_NAME="Gear Language Resource DLL for
Windows 95/98/NT (Dynamic Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004" VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x0" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:34"
UPTO_LINK_DATE="03/02/2004 09:56:34" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwlanges.dll" SIZE="147456" CHECKSUM="0xCD96CD5D"
BIN_FILE_VERSION="3.51.1.6" BIN_PRODUCT_VERSION="3.51.1.6"
PRODUCT_VERSION="3.51.001.06" FILE_DESCRIPTION="GEARLANG.DLL"
COMPANY_NAME="GEAR-Software" PRODUCT_NAME="Gear Language Resource DLL for
Windows 95/98/NT (Dynamic Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004" VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x0" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:35"
UPTO_LINK_DATE="03/02/2004 09:56:35" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwlangfr.dll" SIZE="151552" CHECKSUM="0x697B0A2D"
BIN_FILE_VERSION="3.51.1.6" BIN_PRODUCT_VERSION="3.51.1.6"
PRODUCT_VERSION="3.51.001.06" FILE_DESCRIPTION="GEARLANG.DLL"
COMPANY_NAME="GEAR-Software" PRODUCT_NAME="Gear Language Resource DLL for
Windows 95/98/NT (Dynamic Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004" VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x0" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:28"
UPTO_LINK_DATE="03/02/2004 09:56:28" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwlangit.dll" SIZE="147456" CHECKSUM="0xCD9ACD5D"
BIN_FILE_VERSION="3.51.1.6" BIN_PRODUCT_VERSION="3.51.1.6"
PRODUCT_VERSION="3.51.001.06" FILE_DESCRIPTION="GEARLANG.DLL"
COMPANY_NAME="GEAR-Software" PRODUCT_NAME="Gear Language Resource DLL for
Windows 95/98/NT (Dynamic Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004" VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x0" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:33"
UPTO_LINK_DATE="03/02/2004 09:56:33" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwlangnl.dll" SIZE="147456" CHECKSUM="0xCD988D5D"
BIN_FILE_VERSION="3.51.1.6" BIN_PRODUCT_VERSION="3.51.1.6"
PRODUCT_VERSION="3.51.001.06" FILE_DESCRIPTION="GEARLANG.DLL"
COMPANY_NAME="GEAR-Software" PRODUCT_NAME="Gear Language Resource DLL for
Windows 95/98/NT (Dynamic Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004" VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x0" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:31"
UPTO_LINK_DATE="03/02/2004 09:56:31" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwlangpl.dll" SIZE="139264" CHECKSUM="0x724C0217"
BIN_FILE_VERSION="3.51.1.6" BIN_PRODUCT_VERSION="3.51.1.6"
PRODUCT_VERSION="3.51.001.06" FILE_DESCRIPTION="GEARLANG.DLL"
COMPANY_NAME="GEAR-Software" PRODUCT_NAME="Gear Language Resource DLL for
Windows 95/98/NT (Dynamic Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004" VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x0" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:27"
UPTO_LINK_DATE="03/02/2004 09:56:27" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwlangsv.dll" SIZE="139264" CHECKSUM="0x6B279217"
BIN_FILE_VERSION="3.51.1.6" BIN_PRODUCT_VERSION="3.51.1.6"
PRODUCT_VERSION="3.51.001.06" FILE_DESCRIPTION="GEARLANG.DLL"
COMPANY_NAME="GEAR-Software" PRODUCT_NAME="Gear Language Resource DLL for
Windows 95/98/NT (Dynamic Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004" VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x0" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:30"
UPTO_LINK_DATE="03/02/2004 09:56:30" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwrks32.dll" SIZE="204800" CHECKSUM="0x42B52563"
BIN_FILE_VERSION="3.51.1.6" BIN_PRODUCT_VERSION="3.51.1.6"
PRODUCT_VERSION="3.51.001.06" FILE_DESCRIPTION="GEAR.wrks main dll"
COMPANY_NAME="GEAR-Software" PRODUCT_NAME="GEAR.wrks 3.00 for Windows
95/98/NT" FILE_VERSION="3.51.001.06" ORIGINAL_FILENAME="GWRKS32.DLL"
INTERNAL_NAME="GWRKS32" LEGAL_COPYRIGHT="Copyright © GEAR-Software
1992-2004" VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 10:04:54"
UPTO_LINK_DATE="03/02/2004 10:04:54" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="PQImaging.dll" SIZE="794624" CHECKSUM="0x4DC6D82"
BIN_FILE_VERSION="9.0.2.3981" BIN_PRODUCT_VERSION="9.0.2.3981"
PRODUCT_VERSION="9.0.2.3981" FILE_DESCRIPTION="Imaging Module"
COMPANY_NAME="Symantec Corporation" PRODUCT_NAME="Norton Ghost"
FILE_VERSION="9.0.2.3981" ORIGINAL_FILENAME="PQImaging.dll"
INTERNAL_NAME="PQImaging" LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec
Corporation. All rights reserved." VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x0" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="9.0.2.3981"
UPTO_BIN_PRODUCT_VERSION="9.0.2.3981" LINK_DATE="11/23/2004 00:03:25"
UPTO_LINK_DATE="11/23/2004 00:03:25" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="PQSmeCOM.dll" SIZE="5775360"
CHECKSUM="0x8A1C9BEC" BIN_FILE_VERSION="9.0.2.3981"
BIN_PRODUCT_VERSION="9.0.2.3981" PRODUCT_VERSION="9.0.2.3981"
FILE_DESCRIPTION="SME COM Module" COMPANY_NAME="Symantec Corporation"
PRODUCT_NAME="Norton Ghost" FILE_VERSION="9.0.2.3981"
ORIGINAL_FILENAME="PQSmeCOM.dll" INTERNAL_NAME="PQSmeCOM"
LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec Corporation. All rights
reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="9.0.2.3981"
UPTO_BIN_PRODUCT_VERSION="9.0.2.3981" LINK_DATE="11/23/2004 00:03:00"
UPTO_LINK_DATE="11/23/2004 00:03:00" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="PQV2iCOM.dll" SIZE="696320" CHECKSUM="0x94D9445E"
BIN_FILE_VERSION="9.0.2.3981" BIN_PRODUCT_VERSION="9.0.2.3981"
PRODUCT_VERSION="9.0.2.3981" FILE_DESCRIPTION="Virtual Volume Imaging COM
Module" COMPANY_NAME="Symantec Corporation" PRODUCT_NAME="Norton Ghost"
FILE_VERSION="9.0.2.3981" ORIGINAL_FILENAME="PQV2iCOM.dll"
INTERNAL_NAME="PQV2iCOM" LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec
Corporation. All rights reserved." VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32"
PE_CHECKSUM="0x0" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="9.0.2.3981"
UPTO_BIN_PRODUCT_VERSION="9.0.2.3981" LINK_DATE="11/22/2004 23:52:25"
UPTO_LINK_DATE="11/22/2004 23:52:25" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="PQV2ISECURITY.EXE" SIZE="770048"
CHECKSUM="0x657E041B" BIN_FILE_VERSION="9.0.2.3981"
BIN_PRODUCT_VERSION="9.0.2.3981" PRODUCT_VERSION="9.0.2.3981"
FILE_DESCRIPTION="DCOMSetup Application" COMPANY_NAME="Symantec
Corporation" PRODUCT_NAME="Norton Ghost" FILE_VERSION="9.0.2.3981"
ORIGINAL_FILENAME="DCOMSetup.EXE" INTERNAL_NAME="DCOMSetup"
LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec Corporation. All rights
reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x1" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="9.0.2.3981"
UPTO_BIN_PRODUCT_VERSION="9.0.2.3981" LINK_DATE="11/23/2004 00:14:17"
UPTO_LINK_DATE="11/23/2004 00:14:17" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="PQV2iSvc.exe" SIZE="1273856"
CHECKSUM="0x7B88A325" BIN_FILE_VERSION="9.0.2.3981"
BIN_PRODUCT_VERSION="9.0.2.3981" PRODUCT_VERSION="9.0.2.3981"
FILE_DESCRIPTION="Service Module" COMPANY_NAME="Symantec Corporation"
PRODUCT_NAME="Norton Ghost" FILE_VERSION="9.0.2.3981"
ORIGINAL_FILENAME="PQV2iSvc.exe" INTERNAL_NAME="PQV2iSvc"
LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec Corporation. All rights
reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x1" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="9.0.2.3981"
UPTO_BIN_PRODUCT_VERSION="9.0.2.3981" LINK_DATE="11/23/2004 00:04:13"
UPTO_LINK_DATE="11/23/2004 00:04:13" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="psikey.dll" SIZE="1060864" CHECKSUM="0x3BBF1B39"
BIN_FILE_VERSION="1.3.0.43" BIN_PRODUCT_VERSION="1.3.0.43"
PRODUCT_VERSION="1.3.0.43" FILE_DESCRIPTION="nTitles Activator"
COMPANY_NAME="Protexis Inc." PRODUCT_NAME="Protexis nTitles"
FILE_VERSION="1.3.0.43" ORIGINAL_FILENAME="PSIKey.DLL"
INTERNAL_NAME="SecureInstall" LEGAL_COPYRIGHT="Copyright (C) 2000-2002
Protexis Inc." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="1.3.0.43"
UPTO_BIN_PRODUCT_VERSION="1.3.0.43" LINK_DATE="03/27/2003 20:19:53"
UPTO_LINK_DATE="03/27/2003 20:19:53" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
</EXE>
<EXE NAME="kernel32.dll" FILTER="GRABMI_FILTER_THISFILEONLY">
<MATCHING_FILE NAME="kernel32.dll" SIZE="1036800"
CHECKSUM="0x4B5D905A" BIN_FILE_VERSION="5.1.2600.2180"
BIN_PRODUCT_VERSION="5.1.2600.2180" PRODUCT_VERSION="5.1.2600.2180"
FILE_DESCRIPTION="DLL de cliente API BASE de Windows NT"
COMPANY_NAME="Microsoft Corporation" PRODUCT_NAME="Sistema operativo
Microsoft® Windows®" FILE_VERSION="5.1.2600.2180
(xpsp_sp2_rtm.040803-2158)" ORIGINAL_FILENAME="kernel32"
INTERNAL_NAME="kernel32" LEGAL_COPYRIGHT="Copyright (C) Microsoft
Corporation. Reservados todos los derechos." VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x2"
MODULE_TYPE="WIN32" PE_CHECKSUM="0x106088" LINKER_VERSION="0x50001"
UPTO_BIN_FILE_VERSION="5.1.2600.2180"
UPTO_BIN_PRODUCT_VERSION="5.1.2600.2180" LINK_DATE="08/19/2004 22:41:31"
UPTO_LINK_DATE="08/19/2004 22:41:31" VER_LANGUAGE="Español
(alfabetización internacional) [0xc0a]" />
</EXE>
</DATABASE>











Atentamente
Javier García Rodríguez






Respuesta Responder a este mensaje
#3 Javier Garcia Rodriguez
27/08/2005 - 22:30 | Informe spam
Estoy probando para ver si se bloquea o no. La verdad que podían pasar días
sin bloquearse hacerlo cada 5 minutos. ¡No canto victoria!.
Gracias

"JM Tella Llop [MVP Windows]" escribió en el mensaje
news:%
pues tenía toda la pinta...

Jose Manuel Tella Llop
MVP - Windows
(quitar XXX)
http://www.multingles.net/jmt.htm

Este mensaje se proporciona "como está" sin garantías de ninguna clase,
y no otorga ningún derecho.

This posting is provided "AS IS" with no warranties, and confers no
rights.
You assume all risk for your use.



"Javier Garcia Rodriguez" wrote in message
news:
En un principio ya tengo eliminado del sistema el norton ghost.
Uno menos para interferir en el sistema, si es que interfería.
Saludos

"Javier Garcia Rodriguez" escribió en el mensaje
news:%23%
Hola
He conseguido un volcado de memoria, acto seguido lo he debugueado y la
verdad, ¡no entiendo nada!.
Una vez hecho el volcado por un bloqueo de la máquina, al reiniciar me
da error y no es la primera vez, "tray application ha detectado
ghosttray.exe.." y el sistema se ha recuperado de un error grave
Mando el debug del memory.dmp y acto seguido el error generado por la
aplicación.
Gracias


DEBUG DEL MEMORY.DMP


Microsoft (R) Windows Debugger Version 6.5.0003.7
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\WINDOWS\Volcados\MEMORY.DMP]
Kernel Summary Dump File: Only kernel address space is available

Symbol search path is: SRV*c:\archivos de
programa\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 2600.xpsp_sp2_gdr.050301-1519
Kernel base = 0x804d7000 PsLoadedModuleList = 0x805531a0
Debug session time: Sat Aug 27 16:36:07.031 2005 (GMT+2)
System Uptime: 0 days 2:43:04.603
Loading Kernel Symbols
.
Loading unloaded module list
...
Loading User Symbols
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck E2, {0, 0, 0, 0}

*** ERROR: Module load completed but symbols could not be loaded for
yk51x86.sys
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for halaacpi.dll -
Probably caused by : i8042prt.sys ( i8042prt!I8xProcessCrashDump+237 )

Followup: MachineOwner





kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

MANUALLY_INITIATED_CRASH (e2)
The user manually initiated this crash dump.
Arguments:
Arg1: 00000000
Arg2: 00000000
Arg3: 00000000
Arg4: 00000000

Debugging Details:



BUGCHECK_STR: MANUALLY_INITIATED_CRASH

DEFAULT_BUCKET_ID: DRIVER_FAULT

LAST_CONTROL_TRANSFER: from baa8a7fa to 804f8925

STACK_TEXT:
80548b68 baa8a7fa 000000e2 00000000 00000000 nt!KeBugCheckEx+0x1b
80548b84 baa8a032 0049e0d8 010001c6 00000000
i8042prt!I8xProcessCrashDump+0x237
80548bcc 8054071d 89c1f788 8a49e020 00010009
i8042prt!I8042KeyboardInterruptService+0x21c
80548bcc ba1f9b7a 89c1f788 8a49e020 00010009 nt!KiInterruptDispatch+0x3d
WARNING: Stack unwind information not available. Following frames may be
wrong.
80548ca0 ba1eeceb 89e91004 00000180 00000184 yk51x86+0x10b7a
80548cc0 ba58afca 00000000 89e91004 00000000 yk51x86+0x5ceb
80548ce4 804ff234 89e92104 89e920dc 6f74d694 NDIS!ndisMTimerDpcX+0x7a
80548e00 804ff34b 80551b80 80551920 ffdff000 nt!KiTimerListExpire+0x122
80548e2c 80540d5d 80551f80 00000000 00061b16 nt!KiTimerExpiration+0xaf
80548e50 80540cd6 00000000 0000000e 00000000 nt!KiRetireDpcList+0x46
80548e54 00000000 0000000e 00000000 00000000 nt!KiIdleLoop+0x26


FOLLOWUP_IP:
i8042prt!I8xProcessCrashDump+237
baa8a7fa 5d pop ebp

SYMBOL_STACK_INDEX: 1

FOLLOWUP_NAME: MachineOwner

SYMBOL_NAME: i8042prt!I8xProcessCrashDump+237

MODULE_NAME: i8042prt

IMAGE_NAME: i8042prt.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 41107ecc

STACK_COMMAND: kb

FAILURE_BUCKET_ID:
MANUALLY_INITIATED_CRASH_i8042prt!I8xProcessCrashDump+237

BUCKET_ID: MANUALLY_INITIATED_CRASH_i8042prt!I8xProcessCrashDump+237

Followup: MachineOwner




ERROR GENERADO POR EL GHOST 9

<?xml version="1.0" encoding="UTF-16"?>
<DATABASE>
<EXE NAME="GhostTray.exe" FILTER="GRABMI_FILTER_PRIVACY">
<MATCHING_FILE NAME="gearaw32.dll" SIZE="1425408"
CHECKSUM="0xED711529" BIN_FILE_VERSION="3.51.1.6"
BIN_PRODUCT_VERSION="3.51.1.6" PRODUCT_VERSION="3.51.001.06"
FILE_DESCRIPTION="GEARAW32 DLL" COMPANY_NAME="GEAR-Software"
PRODUCT_NAME="Gear Internal API 3.xx for Windows 95/98/NT (Dynamic Link
Library)" FILE_VERSION="3.51.001.06" ORIGINAL_FILENAME="GEARAW32.DLL"
INTERNAL_NAME="GEARAW32" LEGAL_COPYRIGHT="Copyright © GEAR-Software
1992-2004" VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 10:03:17"
UPTO_LINK_DATE="03/02/2004 10:03:17" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="GhostTray.exe" SIZE="1126400"
CHECKSUM="0xD87F35DA" BIN_FILE_VERSION="9.0.2.3981"
BIN_PRODUCT_VERSION="9.0.2.3981" PRODUCT_VERSION="9.0.2.3981"
FILE_DESCRIPTION="Tray Application" COMPANY_NAME="Symantec Corporation"
PRODUCT_NAME="Norton Ghost" FILE_VERSION="9.0.2.3981"
ORIGINAL_FILENAME="V2iTray.exe" INTERNAL_NAME="V2iTray"
LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec Corporation. All rights
reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x1" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="9.0.2.3981"
UPTO_BIN_PRODUCT_VERSION="9.0.2.3981" LINK_DATE="11/23/2004 00:02:36"
UPTO_LINK_DATE="11/23/2004 00:02:36" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwlangde.dll" SIZE="143360"
CHECKSUM="0x67BDF9A8" BIN_FILE_VERSION="3.51.1.6"
BIN_PRODUCT_VERSION="3.51.1.6" PRODUCT_VERSION="3.51.001.06"
FILE_DESCRIPTION="GEARLANG.DLL" COMPANY_NAME="GEAR-Software"
PRODUCT_NAME="Gear Language Resource DLL for Windows 95/98/NT (Dynamic
Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004"
VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:29"
UPTO_LINK_DATE="03/02/2004 09:56:29" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwlangen.dll" SIZE="135168"
CHECKSUM="0x8AC4E354" BIN_FILE_VERSION="3.51.1.6"
BIN_PRODUCT_VERSION="3.51.1.6" PRODUCT_VERSION="3.51.001.06"
FILE_DESCRIPTION="GEARLANG.DLL" COMPANY_NAME="GEAR-Software"
PRODUCT_NAME="Gear Language Resource DLL for Windows 95/98/NT (Dynamic
Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004"
VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:34"
UPTO_LINK_DATE="03/02/2004 09:56:34" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwlanges.dll" SIZE="147456"
CHECKSUM="0xCD96CD5D" BIN_FILE_VERSION="3.51.1.6"
BIN_PRODUCT_VERSION="3.51.1.6" PRODUCT_VERSION="3.51.001.06"
FILE_DESCRIPTION="GEARLANG.DLL" COMPANY_NAME="GEAR-Software"
PRODUCT_NAME="Gear Language Resource DLL for Windows 95/98/NT (Dynamic
Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004"
VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:35"
UPTO_LINK_DATE="03/02/2004 09:56:35" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwlangfr.dll" SIZE="151552"
CHECKSUM="0x697B0A2D" BIN_FILE_VERSION="3.51.1.6"
BIN_PRODUCT_VERSION="3.51.1.6" PRODUCT_VERSION="3.51.001.06"
FILE_DESCRIPTION="GEARLANG.DLL" COMPANY_NAME="GEAR-Software"
PRODUCT_NAME="Gear Language Resource DLL for Windows 95/98/NT (Dynamic
Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004"
VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:28"
UPTO_LINK_DATE="03/02/2004 09:56:28" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwlangit.dll" SIZE="147456"
CHECKSUM="0xCD9ACD5D" BIN_FILE_VERSION="3.51.1.6"
BIN_PRODUCT_VERSION="3.51.1.6" PRODUCT_VERSION="3.51.001.06"
FILE_DESCRIPTION="GEARLANG.DLL" COMPANY_NAME="GEAR-Software"
PRODUCT_NAME="Gear Language Resource DLL for Windows 95/98/NT (Dynamic
Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004"
VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:33"
UPTO_LINK_DATE="03/02/2004 09:56:33" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwlangnl.dll" SIZE="147456"
CHECKSUM="0xCD988D5D" BIN_FILE_VERSION="3.51.1.6"
BIN_PRODUCT_VERSION="3.51.1.6" PRODUCT_VERSION="3.51.001.06"
FILE_DESCRIPTION="GEARLANG.DLL" COMPANY_NAME="GEAR-Software"
PRODUCT_NAME="Gear Language Resource DLL for Windows 95/98/NT (Dynamic
Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004"
VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:31"
UPTO_LINK_DATE="03/02/2004 09:56:31" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwlangpl.dll" SIZE="139264"
CHECKSUM="0x724C0217" BIN_FILE_VERSION="3.51.1.6"
BIN_PRODUCT_VERSION="3.51.1.6" PRODUCT_VERSION="3.51.001.06"
FILE_DESCRIPTION="GEARLANG.DLL" COMPANY_NAME="GEAR-Software"
PRODUCT_NAME="Gear Language Resource DLL for Windows 95/98/NT (Dynamic
Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004"
VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:27"
UPTO_LINK_DATE="03/02/2004 09:56:27" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwlangsv.dll" SIZE="139264"
CHECKSUM="0x6B279217" BIN_FILE_VERSION="3.51.1.6"
BIN_PRODUCT_VERSION="3.51.1.6" PRODUCT_VERSION="3.51.001.06"
FILE_DESCRIPTION="GEARLANG.DLL" COMPANY_NAME="GEAR-Software"
PRODUCT_NAME="Gear Language Resource DLL for Windows 95/98/NT (Dynamic
Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004"
VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:30"
UPTO_LINK_DATE="03/02/2004 09:56:30" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwrks32.dll" SIZE="204800" CHECKSUM="0x42B52563"
BIN_FILE_VERSION="3.51.1.6" BIN_PRODUCT_VERSION="3.51.1.6"
PRODUCT_VERSION="3.51.001.06" FILE_DESCRIPTION="GEAR.wrks main dll"
COMPANY_NAME="GEAR-Software" PRODUCT_NAME="GEAR.wrks 3.00 for Windows
95/98/NT" FILE_VERSION="3.51.001.06" ORIGINAL_FILENAME="GWRKS32.DLL"
INTERNAL_NAME="GWRKS32" LEGAL_COPYRIGHT="Copyright © GEAR-Software
1992-2004" VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 10:04:54"
UPTO_LINK_DATE="03/02/2004 10:04:54" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="PQImaging.dll" SIZE="794624"
CHECKSUM="0x4DC6D82" BIN_FILE_VERSION="9.0.2.3981"
BIN_PRODUCT_VERSION="9.0.2.3981" PRODUCT_VERSION="9.0.2.3981"
FILE_DESCRIPTION="Imaging Module" COMPANY_NAME="Symantec Corporation"
PRODUCT_NAME="Norton Ghost" FILE_VERSION="9.0.2.3981"
ORIGINAL_FILENAME="PQImaging.dll" INTERNAL_NAME="PQImaging"
LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec Corporation. All rights
reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="9.0.2.3981"
UPTO_BIN_PRODUCT_VERSION="9.0.2.3981" LINK_DATE="11/23/2004 00:03:25"
UPTO_LINK_DATE="11/23/2004 00:03:25" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="PQSmeCOM.dll" SIZE="5775360"
CHECKSUM="0x8A1C9BEC" BIN_FILE_VERSION="9.0.2.3981"
BIN_PRODUCT_VERSION="9.0.2.3981" PRODUCT_VERSION="9.0.2.3981"
FILE_DESCRIPTION="SME COM Module" COMPANY_NAME="Symantec Corporation"
PRODUCT_NAME="Norton Ghost" FILE_VERSION="9.0.2.3981"
ORIGINAL_FILENAME="PQSmeCOM.dll" INTERNAL_NAME="PQSmeCOM"
LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec Corporation. All rights
reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="9.0.2.3981"
UPTO_BIN_PRODUCT_VERSION="9.0.2.3981" LINK_DATE="11/23/2004 00:03:00"
UPTO_LINK_DATE="11/23/2004 00:03:00" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="PQV2iCOM.dll" SIZE="696320"
CHECKSUM="0x94D9445E" BIN_FILE_VERSION="9.0.2.3981"
BIN_PRODUCT_VERSION="9.0.2.3981" PRODUCT_VERSION="9.0.2.3981"
FILE_DESCRIPTION="Virtual Volume Imaging COM Module"
COMPANY_NAME="Symantec Corporation" PRODUCT_NAME="Norton Ghost"
FILE_VERSION="9.0.2.3981" ORIGINAL_FILENAME="PQV2iCOM.dll"
INTERNAL_NAME="PQV2iCOM" LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec
Corporation. All rights reserved." VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2"
MODULE_TYPE="WIN32" PE_CHECKSUM="0x0" LINKER_VERSION="0x0"
UPTO_BIN_FILE_VERSION="9.0.2.3981" UPTO_BIN_PRODUCT_VERSION="9.0.2.3981"
LINK_DATE="11/22/2004 23:52:25" UPTO_LINK_DATE="11/22/2004 23:52:25"
VER_LANGUAGE="Inglés (Estados Unidos) [0x409]" />
<MATCHING_FILE NAME="PQV2ISECURITY.EXE" SIZE="770048"
CHECKSUM="0x657E041B" BIN_FILE_VERSION="9.0.2.3981"
BIN_PRODUCT_VERSION="9.0.2.3981" PRODUCT_VERSION="9.0.2.3981"
FILE_DESCRIPTION="DCOMSetup Application" COMPANY_NAME="Symantec
Corporation" PRODUCT_NAME="Norton Ghost" FILE_VERSION="9.0.2.3981"
ORIGINAL_FILENAME="DCOMSetup.EXE" INTERNAL_NAME="DCOMSetup"
LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec Corporation. All rights
reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x1" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="9.0.2.3981"
UPTO_BIN_PRODUCT_VERSION="9.0.2.3981" LINK_DATE="11/23/2004 00:14:17"
UPTO_LINK_DATE="11/23/2004 00:14:17" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="PQV2iSvc.exe" SIZE="1273856"
CHECKSUM="0x7B88A325" BIN_FILE_VERSION="9.0.2.3981"
BIN_PRODUCT_VERSION="9.0.2.3981" PRODUCT_VERSION="9.0.2.3981"
FILE_DESCRIPTION="Service Module" COMPANY_NAME="Symantec Corporation"
PRODUCT_NAME="Norton Ghost" FILE_VERSION="9.0.2.3981"
ORIGINAL_FILENAME="PQV2iSvc.exe" INTERNAL_NAME="PQV2iSvc"
LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec Corporation. All rights
reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x1" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="9.0.2.3981"
UPTO_BIN_PRODUCT_VERSION="9.0.2.3981" LINK_DATE="11/23/2004 00:04:13"
UPTO_LINK_DATE="11/23/2004 00:04:13" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="psikey.dll" SIZE="1060864" CHECKSUM="0x3BBF1B39"
BIN_FILE_VERSION="1.3.0.43" BIN_PRODUCT_VERSION="1.3.0.43"
PRODUCT_VERSION="1.3.0.43" FILE_DESCRIPTION="nTitles Activator"
COMPANY_NAME="Protexis Inc." PRODUCT_NAME="Protexis nTitles"
FILE_VERSION="1.3.0.43" ORIGINAL_FILENAME="PSIKey.DLL"
INTERNAL_NAME="SecureInstall" LEGAL_COPYRIGHT="Copyright (C) 2000-2002
Protexis Inc." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="1.3.0.43"
UPTO_BIN_PRODUCT_VERSION="1.3.0.43" LINK_DATE="03/27/2003 20:19:53"
UPTO_LINK_DATE="03/27/2003 20:19:53" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
</EXE>
<EXE NAME="kernel32.dll" FILTER="GRABMI_FILTER_THISFILEONLY">
<MATCHING_FILE NAME="kernel32.dll" SIZE="1036800"
CHECKSUM="0x4B5D905A" BIN_FILE_VERSION="5.1.2600.2180"
BIN_PRODUCT_VERSION="5.1.2600.2180" PRODUCT_VERSION="5.1.2600.2180"
FILE_DESCRIPTION="DLL de cliente API BASE de Windows NT"
COMPANY_NAME="Microsoft Corporation" PRODUCT_NAME="Sistema operativo
Microsoft® Windows®" FILE_VERSION="5.1.2600.2180
(xpsp_sp2_rtm.040803-2158)" ORIGINAL_FILENAME="kernel32"
INTERNAL_NAME="kernel32" LEGAL_COPYRIGHT="Copyright (C) Microsoft
Corporation. Reservados todos los derechos." VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x2"
MODULE_TYPE="WIN32" PE_CHECKSUM="0x106088" LINKER_VERSION="0x50001"
UPTO_BIN_FILE_VERSION="5.1.2600.2180"
UPTO_BIN_PRODUCT_VERSION="5.1.2600.2180" LINK_DATE="08/19/2004 22:41:31"
UPTO_LINK_DATE="08/19/2004 22:41:31" VER_LANGUAGE="Español
(alfabetización internacional) [0xc0a]" />
</EXE>
</DATABASE>











Atentamente
Javier García Rodríguez










Respuesta Responder a este mensaje
#4 Javier Garcia Rodriguez
27/08/2005 - 22:36 | Informe spam
De todas las maneras, necesito un software para hacer copias - clonar los
discos duros de este equipo. ¿Habrá algún problema con el acronis?, ¿qué me
recomiendas?, ¿corporate workstation o server?.
saludos y gracias

"JM Tella Llop [MVP Windows]" escribió en el mensaje
news:%
pues tenía toda la pinta...

Jose Manuel Tella Llop
MVP - Windows
(quitar XXX)
http://www.multingles.net/jmt.htm

Este mensaje se proporciona "como está" sin garantías de ninguna clase,
y no otorga ningún derecho.

This posting is provided "AS IS" with no warranties, and confers no
rights.
You assume all risk for your use.



"Javier Garcia Rodriguez" wrote in message
news:
En un principio ya tengo eliminado del sistema el norton ghost.
Uno menos para interferir en el sistema, si es que interfería.
Saludos

"Javier Garcia Rodriguez" escribió en el mensaje
news:%23%
Hola
He conseguido un volcado de memoria, acto seguido lo he debugueado y la
verdad, ¡no entiendo nada!.
Una vez hecho el volcado por un bloqueo de la máquina, al reiniciar me
da error y no es la primera vez, "tray application ha detectado
ghosttray.exe.." y el sistema se ha recuperado de un error grave
Mando el debug del memory.dmp y acto seguido el error generado por la
aplicación.
Gracias


DEBUG DEL MEMORY.DMP


Microsoft (R) Windows Debugger Version 6.5.0003.7
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\WINDOWS\Volcados\MEMORY.DMP]
Kernel Summary Dump File: Only kernel address space is available

Symbol search path is: SRV*c:\archivos de
programa\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 2600.xpsp_sp2_gdr.050301-1519
Kernel base = 0x804d7000 PsLoadedModuleList = 0x805531a0
Debug session time: Sat Aug 27 16:36:07.031 2005 (GMT+2)
System Uptime: 0 days 2:43:04.603
Loading Kernel Symbols
.
Loading unloaded module list
...
Loading User Symbols
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck E2, {0, 0, 0, 0}

*** ERROR: Module load completed but symbols could not be loaded for
yk51x86.sys
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for halaacpi.dll -
Probably caused by : i8042prt.sys ( i8042prt!I8xProcessCrashDump+237 )

Followup: MachineOwner





kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

MANUALLY_INITIATED_CRASH (e2)
The user manually initiated this crash dump.
Arguments:
Arg1: 00000000
Arg2: 00000000
Arg3: 00000000
Arg4: 00000000

Debugging Details:



BUGCHECK_STR: MANUALLY_INITIATED_CRASH

DEFAULT_BUCKET_ID: DRIVER_FAULT

LAST_CONTROL_TRANSFER: from baa8a7fa to 804f8925

STACK_TEXT:
80548b68 baa8a7fa 000000e2 00000000 00000000 nt!KeBugCheckEx+0x1b
80548b84 baa8a032 0049e0d8 010001c6 00000000
i8042prt!I8xProcessCrashDump+0x237
80548bcc 8054071d 89c1f788 8a49e020 00010009
i8042prt!I8042KeyboardInterruptService+0x21c
80548bcc ba1f9b7a 89c1f788 8a49e020 00010009 nt!KiInterruptDispatch+0x3d
WARNING: Stack unwind information not available. Following frames may be
wrong.
80548ca0 ba1eeceb 89e91004 00000180 00000184 yk51x86+0x10b7a
80548cc0 ba58afca 00000000 89e91004 00000000 yk51x86+0x5ceb
80548ce4 804ff234 89e92104 89e920dc 6f74d694 NDIS!ndisMTimerDpcX+0x7a
80548e00 804ff34b 80551b80 80551920 ffdff000 nt!KiTimerListExpire+0x122
80548e2c 80540d5d 80551f80 00000000 00061b16 nt!KiTimerExpiration+0xaf
80548e50 80540cd6 00000000 0000000e 00000000 nt!KiRetireDpcList+0x46
80548e54 00000000 0000000e 00000000 00000000 nt!KiIdleLoop+0x26


FOLLOWUP_IP:
i8042prt!I8xProcessCrashDump+237
baa8a7fa 5d pop ebp

SYMBOL_STACK_INDEX: 1

FOLLOWUP_NAME: MachineOwner

SYMBOL_NAME: i8042prt!I8xProcessCrashDump+237

MODULE_NAME: i8042prt

IMAGE_NAME: i8042prt.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 41107ecc

STACK_COMMAND: kb

FAILURE_BUCKET_ID:
MANUALLY_INITIATED_CRASH_i8042prt!I8xProcessCrashDump+237

BUCKET_ID: MANUALLY_INITIATED_CRASH_i8042prt!I8xProcessCrashDump+237

Followup: MachineOwner




ERROR GENERADO POR EL GHOST 9

<?xml version="1.0" encoding="UTF-16"?>
<DATABASE>
<EXE NAME="GhostTray.exe" FILTER="GRABMI_FILTER_PRIVACY">
<MATCHING_FILE NAME="gearaw32.dll" SIZE="1425408"
CHECKSUM="0xED711529" BIN_FILE_VERSION="3.51.1.6"
BIN_PRODUCT_VERSION="3.51.1.6" PRODUCT_VERSION="3.51.001.06"
FILE_DESCRIPTION="GEARAW32 DLL" COMPANY_NAME="GEAR-Software"
PRODUCT_NAME="Gear Internal API 3.xx for Windows 95/98/NT (Dynamic Link
Library)" FILE_VERSION="3.51.001.06" ORIGINAL_FILENAME="GEARAW32.DLL"
INTERNAL_NAME="GEARAW32" LEGAL_COPYRIGHT="Copyright © GEAR-Software
1992-2004" VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 10:03:17"
UPTO_LINK_DATE="03/02/2004 10:03:17" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="GhostTray.exe" SIZE="1126400"
CHECKSUM="0xD87F35DA" BIN_FILE_VERSION="9.0.2.3981"
BIN_PRODUCT_VERSION="9.0.2.3981" PRODUCT_VERSION="9.0.2.3981"
FILE_DESCRIPTION="Tray Application" COMPANY_NAME="Symantec Corporation"
PRODUCT_NAME="Norton Ghost" FILE_VERSION="9.0.2.3981"
ORIGINAL_FILENAME="V2iTray.exe" INTERNAL_NAME="V2iTray"
LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec Corporation. All rights
reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x1" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="9.0.2.3981"
UPTO_BIN_PRODUCT_VERSION="9.0.2.3981" LINK_DATE="11/23/2004 00:02:36"
UPTO_LINK_DATE="11/23/2004 00:02:36" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwlangde.dll" SIZE="143360"
CHECKSUM="0x67BDF9A8" BIN_FILE_VERSION="3.51.1.6"
BIN_PRODUCT_VERSION="3.51.1.6" PRODUCT_VERSION="3.51.001.06"
FILE_DESCRIPTION="GEARLANG.DLL" COMPANY_NAME="GEAR-Software"
PRODUCT_NAME="Gear Language Resource DLL for Windows 95/98/NT (Dynamic
Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004"
VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:29"
UPTO_LINK_DATE="03/02/2004 09:56:29" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwlangen.dll" SIZE="135168"
CHECKSUM="0x8AC4E354" BIN_FILE_VERSION="3.51.1.6"
BIN_PRODUCT_VERSION="3.51.1.6" PRODUCT_VERSION="3.51.001.06"
FILE_DESCRIPTION="GEARLANG.DLL" COMPANY_NAME="GEAR-Software"
PRODUCT_NAME="Gear Language Resource DLL for Windows 95/98/NT (Dynamic
Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004"
VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:34"
UPTO_LINK_DATE="03/02/2004 09:56:34" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwlanges.dll" SIZE="147456"
CHECKSUM="0xCD96CD5D" BIN_FILE_VERSION="3.51.1.6"
BIN_PRODUCT_VERSION="3.51.1.6" PRODUCT_VERSION="3.51.001.06"
FILE_DESCRIPTION="GEARLANG.DLL" COMPANY_NAME="GEAR-Software"
PRODUCT_NAME="Gear Language Resource DLL for Windows 95/98/NT (Dynamic
Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004"
VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:35"
UPTO_LINK_DATE="03/02/2004 09:56:35" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwlangfr.dll" SIZE="151552"
CHECKSUM="0x697B0A2D" BIN_FILE_VERSION="3.51.1.6"
BIN_PRODUCT_VERSION="3.51.1.6" PRODUCT_VERSION="3.51.001.06"
FILE_DESCRIPTION="GEARLANG.DLL" COMPANY_NAME="GEAR-Software"
PRODUCT_NAME="Gear Language Resource DLL for Windows 95/98/NT (Dynamic
Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004"
VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:28"
UPTO_LINK_DATE="03/02/2004 09:56:28" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwlangit.dll" SIZE="147456"
CHECKSUM="0xCD9ACD5D" BIN_FILE_VERSION="3.51.1.6"
BIN_PRODUCT_VERSION="3.51.1.6" PRODUCT_VERSION="3.51.001.06"
FILE_DESCRIPTION="GEARLANG.DLL" COMPANY_NAME="GEAR-Software"
PRODUCT_NAME="Gear Language Resource DLL for Windows 95/98/NT (Dynamic
Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004"
VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:33"
UPTO_LINK_DATE="03/02/2004 09:56:33" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwlangnl.dll" SIZE="147456"
CHECKSUM="0xCD988D5D" BIN_FILE_VERSION="3.51.1.6"
BIN_PRODUCT_VERSION="3.51.1.6" PRODUCT_VERSION="3.51.001.06"
FILE_DESCRIPTION="GEARLANG.DLL" COMPANY_NAME="GEAR-Software"
PRODUCT_NAME="Gear Language Resource DLL for Windows 95/98/NT (Dynamic
Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004"
VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:31"
UPTO_LINK_DATE="03/02/2004 09:56:31" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwlangpl.dll" SIZE="139264"
CHECKSUM="0x724C0217" BIN_FILE_VERSION="3.51.1.6"
BIN_PRODUCT_VERSION="3.51.1.6" PRODUCT_VERSION="3.51.001.06"
FILE_DESCRIPTION="GEARLANG.DLL" COMPANY_NAME="GEAR-Software"
PRODUCT_NAME="Gear Language Resource DLL for Windows 95/98/NT (Dynamic
Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004"
VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:27"
UPTO_LINK_DATE="03/02/2004 09:56:27" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwlangsv.dll" SIZE="139264"
CHECKSUM="0x6B279217" BIN_FILE_VERSION="3.51.1.6"
BIN_PRODUCT_VERSION="3.51.1.6" PRODUCT_VERSION="3.51.001.06"
FILE_DESCRIPTION="GEARLANG.DLL" COMPANY_NAME="GEAR-Software"
PRODUCT_NAME="Gear Language Resource DLL for Windows 95/98/NT (Dynamic
Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004"
VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:30"
UPTO_LINK_DATE="03/02/2004 09:56:30" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwrks32.dll" SIZE="204800" CHECKSUM="0x42B52563"
BIN_FILE_VERSION="3.51.1.6" BIN_PRODUCT_VERSION="3.51.1.6"
PRODUCT_VERSION="3.51.001.06" FILE_DESCRIPTION="GEAR.wrks main dll"
COMPANY_NAME="GEAR-Software" PRODUCT_NAME="GEAR.wrks 3.00 for Windows
95/98/NT" FILE_VERSION="3.51.001.06" ORIGINAL_FILENAME="GWRKS32.DLL"
INTERNAL_NAME="GWRKS32" LEGAL_COPYRIGHT="Copyright © GEAR-Software
1992-2004" VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 10:04:54"
UPTO_LINK_DATE="03/02/2004 10:04:54" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="PQImaging.dll" SIZE="794624"
CHECKSUM="0x4DC6D82" BIN_FILE_VERSION="9.0.2.3981"
BIN_PRODUCT_VERSION="9.0.2.3981" PRODUCT_VERSION="9.0.2.3981"
FILE_DESCRIPTION="Imaging Module" COMPANY_NAME="Symantec Corporation"
PRODUCT_NAME="Norton Ghost" FILE_VERSION="9.0.2.3981"
ORIGINAL_FILENAME="PQImaging.dll" INTERNAL_NAME="PQImaging"
LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec Corporation. All rights
reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="9.0.2.3981"
UPTO_BIN_PRODUCT_VERSION="9.0.2.3981" LINK_DATE="11/23/2004 00:03:25"
UPTO_LINK_DATE="11/23/2004 00:03:25" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="PQSmeCOM.dll" SIZE="5775360"
CHECKSUM="0x8A1C9BEC" BIN_FILE_VERSION="9.0.2.3981"
BIN_PRODUCT_VERSION="9.0.2.3981" PRODUCT_VERSION="9.0.2.3981"
FILE_DESCRIPTION="SME COM Module" COMPANY_NAME="Symantec Corporation"
PRODUCT_NAME="Norton Ghost" FILE_VERSION="9.0.2.3981"
ORIGINAL_FILENAME="PQSmeCOM.dll" INTERNAL_NAME="PQSmeCOM"
LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec Corporation. All rights
reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="9.0.2.3981"
UPTO_BIN_PRODUCT_VERSION="9.0.2.3981" LINK_DATE="11/23/2004 00:03:00"
UPTO_LINK_DATE="11/23/2004 00:03:00" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="PQV2iCOM.dll" SIZE="696320"
CHECKSUM="0x94D9445E" BIN_FILE_VERSION="9.0.2.3981"
BIN_PRODUCT_VERSION="9.0.2.3981" PRODUCT_VERSION="9.0.2.3981"
FILE_DESCRIPTION="Virtual Volume Imaging COM Module"
COMPANY_NAME="Symantec Corporation" PRODUCT_NAME="Norton Ghost"
FILE_VERSION="9.0.2.3981" ORIGINAL_FILENAME="PQV2iCOM.dll"
INTERNAL_NAME="PQV2iCOM" LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec
Corporation. All rights reserved." VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2"
MODULE_TYPE="WIN32" PE_CHECKSUM="0x0" LINKER_VERSION="0x0"
UPTO_BIN_FILE_VERSION="9.0.2.3981" UPTO_BIN_PRODUCT_VERSION="9.0.2.3981"
LINK_DATE="11/22/2004 23:52:25" UPTO_LINK_DATE="11/22/2004 23:52:25"
VER_LANGUAGE="Inglés (Estados Unidos) [0x409]" />
<MATCHING_FILE NAME="PQV2ISECURITY.EXE" SIZE="770048"
CHECKSUM="0x657E041B" BIN_FILE_VERSION="9.0.2.3981"
BIN_PRODUCT_VERSION="9.0.2.3981" PRODUCT_VERSION="9.0.2.3981"
FILE_DESCRIPTION="DCOMSetup Application" COMPANY_NAME="Symantec
Corporation" PRODUCT_NAME="Norton Ghost" FILE_VERSION="9.0.2.3981"
ORIGINAL_FILENAME="DCOMSetup.EXE" INTERNAL_NAME="DCOMSetup"
LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec Corporation. All rights
reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x1" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="9.0.2.3981"
UPTO_BIN_PRODUCT_VERSION="9.0.2.3981" LINK_DATE="11/23/2004 00:14:17"
UPTO_LINK_DATE="11/23/2004 00:14:17" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="PQV2iSvc.exe" SIZE="1273856"
CHECKSUM="0x7B88A325" BIN_FILE_VERSION="9.0.2.3981"
BIN_PRODUCT_VERSION="9.0.2.3981" PRODUCT_VERSION="9.0.2.3981"
FILE_DESCRIPTION="Service Module" COMPANY_NAME="Symantec Corporation"
PRODUCT_NAME="Norton Ghost" FILE_VERSION="9.0.2.3981"
ORIGINAL_FILENAME="PQV2iSvc.exe" INTERNAL_NAME="PQV2iSvc"
LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec Corporation. All rights
reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x1" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="9.0.2.3981"
UPTO_BIN_PRODUCT_VERSION="9.0.2.3981" LINK_DATE="11/23/2004 00:04:13"
UPTO_LINK_DATE="11/23/2004 00:04:13" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="psikey.dll" SIZE="1060864" CHECKSUM="0x3BBF1B39"
BIN_FILE_VERSION="1.3.0.43" BIN_PRODUCT_VERSION="1.3.0.43"
PRODUCT_VERSION="1.3.0.43" FILE_DESCRIPTION="nTitles Activator"
COMPANY_NAME="Protexis Inc." PRODUCT_NAME="Protexis nTitles"
FILE_VERSION="1.3.0.43" ORIGINAL_FILENAME="PSIKey.DLL"
INTERNAL_NAME="SecureInstall" LEGAL_COPYRIGHT="Copyright (C) 2000-2002
Protexis Inc." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="1.3.0.43"
UPTO_BIN_PRODUCT_VERSION="1.3.0.43" LINK_DATE="03/27/2003 20:19:53"
UPTO_LINK_DATE="03/27/2003 20:19:53" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
</EXE>
<EXE NAME="kernel32.dll" FILTER="GRABMI_FILTER_THISFILEONLY">
<MATCHING_FILE NAME="kernel32.dll" SIZE="1036800"
CHECKSUM="0x4B5D905A" BIN_FILE_VERSION="5.1.2600.2180"
BIN_PRODUCT_VERSION="5.1.2600.2180" PRODUCT_VERSION="5.1.2600.2180"
FILE_DESCRIPTION="DLL de cliente API BASE de Windows NT"
COMPANY_NAME="Microsoft Corporation" PRODUCT_NAME="Sistema operativo
Microsoft® Windows®" FILE_VERSION="5.1.2600.2180
(xpsp_sp2_rtm.040803-2158)" ORIGINAL_FILENAME="kernel32"
INTERNAL_NAME="kernel32" LEGAL_COPYRIGHT="Copyright (C) Microsoft
Corporation. Reservados todos los derechos." VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x2"
MODULE_TYPE="WIN32" PE_CHECKSUM="0x106088" LINKER_VERSION="0x50001"
UPTO_BIN_FILE_VERSION="5.1.2600.2180"
UPTO_BIN_PRODUCT_VERSION="5.1.2600.2180" LINK_DATE="08/19/2004 22:41:31"
UPTO_LINK_DATE="08/19/2004 22:41:31" VER_LANGUAGE="Español
(alfabetización internacional) [0xc0a]" />
</EXE>
</DATABASE>











Atentamente
Javier García Rodríguez










Respuesta Responder a este mensaje
#5 JM Tella Llop [MVP Windows]
27/08/2005 - 22:39 | Informe spam
Con Acronis no he encontrado problemas..

Jose Manuel Tella Llop
MVP - Windows
(quitar XXX)
http://www.multingles.net/jmt.htm

Este mensaje se proporciona "como está" sin garantías de ninguna clase,
y no otorga ningún derecho.

This posting is provided "AS IS" with no warranties, and confers no
rights.
You assume all risk for your use.



"Javier Garcia Rodriguez" wrote in message
news:
De todas las maneras, necesito un software para hacer copias - clonar los
discos duros de este equipo. ¿Habrá algún problema con el acronis?, ¿qué
me recomiendas?, ¿corporate workstation o server?.
saludos y gracias

"JM Tella Llop [MVP Windows]" escribió en el mensaje
news:%
pues tenía toda la pinta...

Jose Manuel Tella Llop
MVP - Windows
(quitar XXX)
http://www.multingles.net/jmt.htm

Este mensaje se proporciona "como está" sin garantías de ninguna clase,
y no otorga ningún derecho.

This posting is provided "AS IS" with no warranties, and confers no
rights.
You assume all risk for your use.



"Javier Garcia Rodriguez" wrote in message
news:
En un principio ya tengo eliminado del sistema el norton ghost.
Uno menos para interferir en el sistema, si es que interfería.
Saludos

"Javier Garcia Rodriguez" escribió en el mensaje
news:%23%
Hola
He conseguido un volcado de memoria, acto seguido lo he debugueado y la
verdad, ¡no entiendo nada!.
Una vez hecho el volcado por un bloqueo de la máquina, al reiniciar me
da error y no es la primera vez, "tray application ha detectado
ghosttray.exe.." y el sistema se ha recuperado de un error
grave
Mando el debug del memory.dmp y acto seguido el error generado por la
aplicación.
Gracias


DEBUG DEL MEMORY.DMP


Microsoft (R) Windows Debugger Version 6.5.0003.7
Copyright (c) Microsoft Corporation. All rights reserved.


Loading Dump File [C:\WINDOWS\Volcados\MEMORY.DMP]
Kernel Summary Dump File: Only kernel address space is available

Symbol search path is: SRV*c:\archivos de
programa\websymbols*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows XP Kernel Version 2600 (Service Pack 2) UP Free x86 compatible
Product: WinNt, suite: TerminalServer SingleUserTS
Built by: 2600.xpsp_sp2_gdr.050301-1519
Kernel base = 0x804d7000 PsLoadedModuleList = 0x805531a0
Debug session time: Sat Aug 27 16:36:07.031 2005 (GMT+2)
System Uptime: 0 days 2:43:04.603
Loading Kernel Symbols
.
Loading unloaded module list
...
Loading User Symbols
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck E2, {0, 0, 0, 0}

*** ERROR: Module load completed but symbols could not be loaded for
yk51x86.sys
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for halaacpi.dll -
Probably caused by : i8042prt.sys ( i8042prt!I8xProcessCrashDump+237 )

Followup: MachineOwner





kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

MANUALLY_INITIATED_CRASH (e2)
The user manually initiated this crash dump.
Arguments:
Arg1: 00000000
Arg2: 00000000
Arg3: 00000000
Arg4: 00000000

Debugging Details:



BUGCHECK_STR: MANUALLY_INITIATED_CRASH

DEFAULT_BUCKET_ID: DRIVER_FAULT

LAST_CONTROL_TRANSFER: from baa8a7fa to 804f8925

STACK_TEXT:
80548b68 baa8a7fa 000000e2 00000000 00000000 nt!KeBugCheckEx+0x1b
80548b84 baa8a032 0049e0d8 010001c6 00000000
i8042prt!I8xProcessCrashDump+0x237
80548bcc 8054071d 89c1f788 8a49e020 00010009
i8042prt!I8042KeyboardInterruptService+0x21c
80548bcc ba1f9b7a 89c1f788 8a49e020 00010009
nt!KiInterruptDispatch+0x3d
WARNING: Stack unwind information not available. Following frames may
be wrong.
80548ca0 ba1eeceb 89e91004 00000180 00000184 yk51x86+0x10b7a
80548cc0 ba58afca 00000000 89e91004 00000000 yk51x86+0x5ceb
80548ce4 804ff234 89e92104 89e920dc 6f74d694 NDIS!ndisMTimerDpcX+0x7a
80548e00 804ff34b 80551b80 80551920 ffdff000 nt!KiTimerListExpire+0x122
80548e2c 80540d5d 80551f80 00000000 00061b16 nt!KiTimerExpiration+0xaf
80548e50 80540cd6 00000000 0000000e 00000000 nt!KiRetireDpcList+0x46
80548e54 00000000 0000000e 00000000 00000000 nt!KiIdleLoop+0x26


FOLLOWUP_IP:
i8042prt!I8xProcessCrashDump+237
baa8a7fa 5d pop ebp

SYMBOL_STACK_INDEX: 1

FOLLOWUP_NAME: MachineOwner

SYMBOL_NAME: i8042prt!I8xProcessCrashDump+237

MODULE_NAME: i8042prt

IMAGE_NAME: i8042prt.sys

DEBUG_FLR_IMAGE_TIMESTAMP: 41107ecc

STACK_COMMAND: kb

FAILURE_BUCKET_ID:
MANUALLY_INITIATED_CRASH_i8042prt!I8xProcessCrashDump+237

BUCKET_ID: MANUALLY_INITIATED_CRASH_i8042prt!I8xProcessCrashDump+237

Followup: MachineOwner




ERROR GENERADO POR EL GHOST 9

<?xml version="1.0" encoding="UTF-16"?>
<DATABASE>
<EXE NAME="GhostTray.exe" FILTER="GRABMI_FILTER_PRIVACY">
<MATCHING_FILE NAME="gearaw32.dll" SIZE="1425408"
CHECKSUM="0xED711529" BIN_FILE_VERSION="3.51.1.6"
BIN_PRODUCT_VERSION="3.51.1.6" PRODUCT_VERSION="3.51.001.06"
FILE_DESCRIPTION="GEARAW32 DLL" COMPANY_NAME="GEAR-Software"
PRODUCT_NAME="Gear Internal API 3.xx for Windows 95/98/NT (Dynamic Link
Library)" FILE_VERSION="3.51.001.06" ORIGINAL_FILENAME="GEARAW32.DLL"
INTERNAL_NAME="GEARAW32" LEGAL_COPYRIGHT="Copyright © GEAR-Software
1992-2004" VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 10:03:17"
UPTO_LINK_DATE="03/02/2004 10:03:17" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="GhostTray.exe" SIZE="1126400"
CHECKSUM="0xD87F35DA" BIN_FILE_VERSION="9.0.2.3981"
BIN_PRODUCT_VERSION="9.0.2.3981" PRODUCT_VERSION="9.0.2.3981"
FILE_DESCRIPTION="Tray Application" COMPANY_NAME="Symantec Corporation"
PRODUCT_NAME="Norton Ghost" FILE_VERSION="9.0.2.3981"
ORIGINAL_FILENAME="V2iTray.exe" INTERNAL_NAME="V2iTray"
LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec Corporation. All rights
reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x1" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="9.0.2.3981"
UPTO_BIN_PRODUCT_VERSION="9.0.2.3981" LINK_DATE="11/23/2004 00:02:36"
UPTO_LINK_DATE="11/23/2004 00:02:36" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwlangde.dll" SIZE="143360"
CHECKSUM="0x67BDF9A8" BIN_FILE_VERSION="3.51.1.6"
BIN_PRODUCT_VERSION="3.51.1.6" PRODUCT_VERSION="3.51.001.06"
FILE_DESCRIPTION="GEARLANG.DLL" COMPANY_NAME="GEAR-Software"
PRODUCT_NAME="Gear Language Resource DLL for Windows 95/98/NT (Dynamic
Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004"
VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:29"
UPTO_LINK_DATE="03/02/2004 09:56:29" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwlangen.dll" SIZE="135168"
CHECKSUM="0x8AC4E354" BIN_FILE_VERSION="3.51.1.6"
BIN_PRODUCT_VERSION="3.51.1.6" PRODUCT_VERSION="3.51.001.06"
FILE_DESCRIPTION="GEARLANG.DLL" COMPANY_NAME="GEAR-Software"
PRODUCT_NAME="Gear Language Resource DLL for Windows 95/98/NT (Dynamic
Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004"
VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:34"
UPTO_LINK_DATE="03/02/2004 09:56:34" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwlanges.dll" SIZE="147456"
CHECKSUM="0xCD96CD5D" BIN_FILE_VERSION="3.51.1.6"
BIN_PRODUCT_VERSION="3.51.1.6" PRODUCT_VERSION="3.51.001.06"
FILE_DESCRIPTION="GEARLANG.DLL" COMPANY_NAME="GEAR-Software"
PRODUCT_NAME="Gear Language Resource DLL for Windows 95/98/NT (Dynamic
Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004"
VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:35"
UPTO_LINK_DATE="03/02/2004 09:56:35" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwlangfr.dll" SIZE="151552"
CHECKSUM="0x697B0A2D" BIN_FILE_VERSION="3.51.1.6"
BIN_PRODUCT_VERSION="3.51.1.6" PRODUCT_VERSION="3.51.001.06"
FILE_DESCRIPTION="GEARLANG.DLL" COMPANY_NAME="GEAR-Software"
PRODUCT_NAME="Gear Language Resource DLL for Windows 95/98/NT (Dynamic
Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004"
VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:28"
UPTO_LINK_DATE="03/02/2004 09:56:28" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwlangit.dll" SIZE="147456"
CHECKSUM="0xCD9ACD5D" BIN_FILE_VERSION="3.51.1.6"
BIN_PRODUCT_VERSION="3.51.1.6" PRODUCT_VERSION="3.51.001.06"
FILE_DESCRIPTION="GEARLANG.DLL" COMPANY_NAME="GEAR-Software"
PRODUCT_NAME="Gear Language Resource DLL for Windows 95/98/NT (Dynamic
Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004"
VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:33"
UPTO_LINK_DATE="03/02/2004 09:56:33" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwlangnl.dll" SIZE="147456"
CHECKSUM="0xCD988D5D" BIN_FILE_VERSION="3.51.1.6"
BIN_PRODUCT_VERSION="3.51.1.6" PRODUCT_VERSION="3.51.001.06"
FILE_DESCRIPTION="GEARLANG.DLL" COMPANY_NAME="GEAR-Software"
PRODUCT_NAME="Gear Language Resource DLL for Windows 95/98/NT (Dynamic
Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004"
VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:31"
UPTO_LINK_DATE="03/02/2004 09:56:31" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwlangpl.dll" SIZE="139264"
CHECKSUM="0x724C0217" BIN_FILE_VERSION="3.51.1.6"
BIN_PRODUCT_VERSION="3.51.1.6" PRODUCT_VERSION="3.51.001.06"
FILE_DESCRIPTION="GEARLANG.DLL" COMPANY_NAME="GEAR-Software"
PRODUCT_NAME="Gear Language Resource DLL for Windows 95/98/NT (Dynamic
Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004"
VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:27"
UPTO_LINK_DATE="03/02/2004 09:56:27" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwlangsv.dll" SIZE="139264"
CHECKSUM="0x6B279217" BIN_FILE_VERSION="3.51.1.6"
BIN_PRODUCT_VERSION="3.51.1.6" PRODUCT_VERSION="3.51.001.06"
FILE_DESCRIPTION="GEARLANG.DLL" COMPANY_NAME="GEAR-Software"
PRODUCT_NAME="Gear Language Resource DLL for Windows 95/98/NT (Dynamic
Link Library)" FILE_VERSION="3.51.001.06"
ORIGINAL_FILENAME="GEARLANG.DLL" INTERNAL_NAME="GEARLANG"
LEGAL_COPYRIGHT="Copyright © GEAR-Software 1992-2004"
VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 09:56:30"
UPTO_LINK_DATE="03/02/2004 09:56:30" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="gwrks32.dll" SIZE="204800"
CHECKSUM="0x42B52563" BIN_FILE_VERSION="3.51.1.6"
BIN_PRODUCT_VERSION="3.51.1.6" PRODUCT_VERSION="3.51.001.06"
FILE_DESCRIPTION="GEAR.wrks main dll" COMPANY_NAME="GEAR-Software"
PRODUCT_NAME="GEAR.wrks 3.00 for Windows 95/98/NT"
FILE_VERSION="3.51.001.06" ORIGINAL_FILENAME="GWRKS32.DLL"
INTERNAL_NAME="GWRKS32" LEGAL_COPYRIGHT="Copyright © GEAR-Software
1992-2004" VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="3.51.1.6"
UPTO_BIN_PRODUCT_VERSION="3.51.1.6" LINK_DATE="03/02/2004 10:04:54"
UPTO_LINK_DATE="03/02/2004 10:04:54" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="PQImaging.dll" SIZE="794624"
CHECKSUM="0x4DC6D82" BIN_FILE_VERSION="9.0.2.3981"
BIN_PRODUCT_VERSION="9.0.2.3981" PRODUCT_VERSION="9.0.2.3981"
FILE_DESCRIPTION="Imaging Module" COMPANY_NAME="Symantec Corporation"
PRODUCT_NAME="Norton Ghost" FILE_VERSION="9.0.2.3981"
ORIGINAL_FILENAME="PQImaging.dll" INTERNAL_NAME="PQImaging"
LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec Corporation. All rights
reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="9.0.2.3981"
UPTO_BIN_PRODUCT_VERSION="9.0.2.3981" LINK_DATE="11/23/2004 00:03:25"
UPTO_LINK_DATE="11/23/2004 00:03:25" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="PQSmeCOM.dll" SIZE="5775360"
CHECKSUM="0x8A1C9BEC" BIN_FILE_VERSION="9.0.2.3981"
BIN_PRODUCT_VERSION="9.0.2.3981" PRODUCT_VERSION="9.0.2.3981"
FILE_DESCRIPTION="SME COM Module" COMPANY_NAME="Symantec Corporation"
PRODUCT_NAME="Norton Ghost" FILE_VERSION="9.0.2.3981"
ORIGINAL_FILENAME="PQSmeCOM.dll" INTERNAL_NAME="PQSmeCOM"
LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec Corporation. All rights
reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="9.0.2.3981"
UPTO_BIN_PRODUCT_VERSION="9.0.2.3981" LINK_DATE="11/23/2004 00:03:00"
UPTO_LINK_DATE="11/23/2004 00:03:00" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="PQV2iCOM.dll" SIZE="696320"
CHECKSUM="0x94D9445E" BIN_FILE_VERSION="9.0.2.3981"
BIN_PRODUCT_VERSION="9.0.2.3981" PRODUCT_VERSION="9.0.2.3981"
FILE_DESCRIPTION="Virtual Volume Imaging COM Module"
COMPANY_NAME="Symantec Corporation" PRODUCT_NAME="Norton Ghost"
FILE_VERSION="9.0.2.3981" ORIGINAL_FILENAME="PQV2iCOM.dll"
INTERNAL_NAME="PQV2iCOM" LEGAL_COPYRIGHT="Copyright © 1994-2004
Symantec Corporation. All rights reserved." VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2"
MODULE_TYPE="WIN32" PE_CHECKSUM="0x0" LINKER_VERSION="0x0"
UPTO_BIN_FILE_VERSION="9.0.2.3981"
UPTO_BIN_PRODUCT_VERSION="9.0.2.3981" LINK_DATE="11/22/2004 23:52:25"
UPTO_LINK_DATE="11/22/2004 23:52:25" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="PQV2ISECURITY.EXE" SIZE="770048"
CHECKSUM="0x657E041B" BIN_FILE_VERSION="9.0.2.3981"
BIN_PRODUCT_VERSION="9.0.2.3981" PRODUCT_VERSION="9.0.2.3981"
FILE_DESCRIPTION="DCOMSetup Application" COMPANY_NAME="Symantec
Corporation" PRODUCT_NAME="Norton Ghost" FILE_VERSION="9.0.2.3981"
ORIGINAL_FILENAME="DCOMSetup.EXE" INTERNAL_NAME="DCOMSetup"
LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec Corporation. All rights
reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x1" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="9.0.2.3981"
UPTO_BIN_PRODUCT_VERSION="9.0.2.3981" LINK_DATE="11/23/2004 00:14:17"
UPTO_LINK_DATE="11/23/2004 00:14:17" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="PQV2iSvc.exe" SIZE="1273856"
CHECKSUM="0x7B88A325" BIN_FILE_VERSION="9.0.2.3981"
BIN_PRODUCT_VERSION="9.0.2.3981" PRODUCT_VERSION="9.0.2.3981"
FILE_DESCRIPTION="Service Module" COMPANY_NAME="Symantec Corporation"
PRODUCT_NAME="Norton Ghost" FILE_VERSION="9.0.2.3981"
ORIGINAL_FILENAME="PQV2iSvc.exe" INTERNAL_NAME="PQV2iSvc"
LEGAL_COPYRIGHT="Copyright © 1994-2004 Symantec Corporation. All rights
reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x1" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="9.0.2.3981"
UPTO_BIN_PRODUCT_VERSION="9.0.2.3981" LINK_DATE="11/23/2004 00:04:13"
UPTO_LINK_DATE="11/23/2004 00:04:13" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
<MATCHING_FILE NAME="psikey.dll" SIZE="1060864"
CHECKSUM="0x3BBF1B39" BIN_FILE_VERSION="1.3.0.43"
BIN_PRODUCT_VERSION="1.3.0.43" PRODUCT_VERSION="1.3.0.43"
FILE_DESCRIPTION="nTitles Activator" COMPANY_NAME="Protexis Inc."
PRODUCT_NAME="Protexis nTitles" FILE_VERSION="1.3.0.43"
ORIGINAL_FILENAME="PSIKey.DLL" INTERNAL_NAME="SecureInstall"
LEGAL_COPYRIGHT="Copyright (C) 2000-2002 Protexis Inc."
VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4"
VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0"
LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="1.3.0.43"
UPTO_BIN_PRODUCT_VERSION="1.3.0.43" LINK_DATE="03/27/2003 20:19:53"
UPTO_LINK_DATE="03/27/2003 20:19:53" VER_LANGUAGE="Inglés (Estados
Unidos) [0x409]" />
</EXE>
<EXE NAME="kernel32.dll" FILTER="GRABMI_FILTER_THISFILEONLY">
<MATCHING_FILE NAME="kernel32.dll" SIZE="1036800"
CHECKSUM="0x4B5D905A" BIN_FILE_VERSION="5.1.2600.2180"
BIN_PRODUCT_VERSION="5.1.2600.2180" PRODUCT_VERSION="5.1.2600.2180"
FILE_DESCRIPTION="DLL de cliente API BASE de Windows NT"
COMPANY_NAME="Microsoft Corporation" PRODUCT_NAME="Sistema operativo
Microsoft® Windows®" FILE_VERSION="5.1.2600.2180
(xpsp_sp2_rtm.040803-2158)" ORIGINAL_FILENAME="kernel32"
INTERNAL_NAME="kernel32" LEGAL_COPYRIGHT="Copyright (C) Microsoft
Corporation. Reservados todos los derechos." VERFILEDATEHI="0x0"
VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x2"
MODULE_TYPE="WIN32" PE_CHECKSUM="0x106088" LINKER_VERSION="0x50001"
UPTO_BIN_FILE_VERSION="5.1.2600.2180"
UPTO_BIN_PRODUCT_VERSION="5.1.2600.2180" LINK_DATE="08/19/2004
22:41:31" UPTO_LINK_DATE="08/19/2004 22:41:31" VER_LANGUAGE="Español
(alfabetización internacional) [0xc0a]" />
</EXE>
</DATABASE>











Atentamente
Javier García Rodríguez














Respuesta Responder a este mensaje
Ads by Google
Help Hacer una preguntaSiguiente Respuesta Tengo una respuesta
Search Busqueda sugerida