Sysinternals Homepage
Forum Home Forum Home > Windows Discussions > Troubleshooting
  New Posts New Posts RSS Feed: Svchost.exe crashing randomly - Need expert help!
  FAQ FAQ  Forum Search   Calendar   Register Register  Login Login

Svchost.exe crashing randomly - Need expert help!

 Post Reply Post Reply Page  <1 56789>
Author
Message
  Topic Search Topic Search  Topic Options Topic Options
molotov View Drop Down
Moderator Group
Moderator Group
Avatar

Joined: 04 October 2006
Online Status: Offline
Posts: 17287
  Quote molotov Quote  Post ReplyReply Direct Link To This Post Topic: Svchost.exe crashing randomly - Need expert help!
    Posted: 18 May 2008 at 7:44pm
Wonder if Process Monitor with configured symbols may be worth considering, over Filemon...
Daily affirmation:
net helpmsg 4006
Back to Top
Jackcolt View Drop Down
Groupie
Groupie


Joined: 01 April 2008
Location: Denmark
Online Status: Offline
Posts: 72
  Quote Jackcolt Quote  Post ReplyReply Direct Link To This Post Posted: 18 May 2008 at 11:02pm
Hmm... yeah you might be right. I think I'll actually try with Process Monitor first. Thanks ;D
Back to Top
Jackcolt View Drop Down
Groupie
Groupie


Joined: 01 April 2008
Location: Denmark
Online Status: Offline
Posts: 72
  Quote Jackcolt Quote  Post ReplyReply Direct Link To This Post Posted: 23 May 2008 at 9:48am
My brother just started getting the same errors

We don't use the same software, and our hardware is completely different.

He has downloaded some .avi files from me. I'm kinda of guessing that one of them is causing an error when a thumbnail or something is being generated. Anyways, I'm using both Filemon and Procmon now. Hopefully it will turn up something.

UPDATE:

Yeah! It's promising. It hasn't crashed yet, but I noticed that without me provoking any action to do so, svchost:1608(the instance that is crashing) is requesting query information from some AVI files! Hopefully, it crashes when trying to access one of those files, and then I should be able to see it in FileMon(what I'm using right now)


Edited by Jackcolt - 23 May 2008 at 11:38am
Back to Top
molotov View Drop Down
Moderator Group
Moderator Group
Avatar

Joined: 04 October 2006
Online Status: Offline
Posts: 17287
  Quote molotov Quote  Post ReplyReply Direct Link To This Post Posted: 25 May 2008 at 10:13am
My brother just started getting the same errors
How close to the "same" is the "same"?  (The precise call stack, for example?  Anything else would just be an assumption that would need to be verified...)
 
I'm using both Filemon and Procmon now
Why both?
 
requesting query information from some AVI files
What is the stack of the event? 
FileMon(what I'm using right now)
Oh.  Filemon won't get you the stacks; Process Monitor will.  I'd suggest using just Process Monitor, with symbols configured, so you can get the stack of the events.  That way you can probably determine what service is accessing the file, and why.
 
Hopefully, it crashes when trying to access one of those files
Probably not - the stack of the crash does not suggest that the crash is directly related to accessing a file.  But it could be something with accessing the files that eventually does something that causes a problem much later.


Edited by molotov - 25 May 2008 at 10:13am
Daily affirmation:
net helpmsg 4006
Back to Top
Jackcolt View Drop Down
Groupie
Groupie


Joined: 01 April 2008
Location: Denmark
Online Status: Offline
Posts: 72
  Quote Jackcolt Quote  Post ReplyReply Direct Link To This Post Posted: 25 May 2008 at 11:23am
The stack call is identical except for a few parameters. Everything else is identical.

I actually stopped using ProcMon because it's eating up my pagefile(or any file I want) pretty quickly, because it logs ALL events. Is there a way to dismiss events that is filtered away?(Meaning not having it logged in the backing file)

Didn't get the stack.

Yeah, I didn't mean that accessing the file should cause the crash(because then I would be able to recreate it) - What I'm trying to get at here, is if I can that it access the files, and it then crashing a second or two later, then it might be related.

Procmon would definately be a better tool for the job, but I can't have it creating such huge files.



Edited by Jackcolt - 25 May 2008 at 11:30am
Back to Top
molotov View Drop Down
Moderator Group
Moderator Group
Avatar

Joined: 04 October 2006
Online Status: Offline
Posts: 17287
  Quote molotov Quote  Post ReplyReply Direct Link To This Post Posted: 25 May 2008 at 11:29am
Is there a way to dismiss events that is filtered away
Filter -> Drop Filtered Events
 
The stack call is identical except for a few parameters. Everything else is identical.
With symbols resolving properly, correct?
Daily affirmation:
net helpmsg 4006
Back to Top
Jackcolt View Drop Down
Groupie
Groupie


Joined: 01 April 2008
Location: Denmark
Online Status: Offline
Posts: 72
  Quote Jackcolt Quote  Post ReplyReply Direct Link To This Post Posted: 25 May 2008 at 11:33am
Argh, of course :D

Yeah, ProcMon is running now with configured symbols.

Yeah, with symbols resolving properly
Back to Top
Intuit View Drop Down
Groupie
Groupie


Joined: 19 August 2006
Online Status: Offline
Posts: 81
  Quote Intuit Quote  Post ReplyReply Direct Link To This Post Posted: 25 May 2008 at 1:15pm
I actually stopped using ProcMon because it's eating up my pagefile(or any file I want) pretty quickly,

I configure it use it's own backing file rather than RAM/PageFile. Doesn't have the system-wide performance hit that it might otherwise have.
Back to Top
Jackcolt View Drop Down
Groupie
Groupie


Joined: 01 April 2008
Location: Denmark
Online Status: Offline
Posts: 72
  Quote Jackcolt Quote  Post ReplyReply Direct Link To This Post Posted: 25 May 2008 at 1:50pm
Yeah, I've set it to use it's own backing file.
Back to Top
Jackcolt View Drop Down
Groupie
Groupie


Joined: 01 April 2008
Location: Denmark
Online Status: Offline
Posts: 72
  Quote Jackcolt Quote  Post ReplyReply Direct Link To This Post Posted: 27 May 2008 at 8:59am
By the way, ProcMon shouldn't "interfere" with svchost.exe right? You know, the same way that Debug Diags debugger did. I haven't the crash in a couple of days(even though that far from my "record" with no debugger attached), so I just want to make sure that it's not ProcMon preventing it from crashing.
Back to Top
 Post Reply Post Reply Page  <1 56789>

Forum Jump Forum Permissions View Drop Down

Privacy Statement