Dear all,
I tried to run a snapshot on WMware server for a Windows 2008 R2 VM. It failed with the below error message on event log.
Does anyone have idea to fix the below error message? I google the error and have not figured out what is the problem.
| | | | | [ SystemTime] | 2019-01-18T06:50:46.000000000Z |
|
| | | Computer | le-it-s003.le-intl.com.cn |
|
| | | CreateFileW(\\.\PHYSICALDRIVE1) - BuildLunInfoForDrive |
| | | 0x80070020, The process cannot access the file because it is being used by another process. |
| | | Context: Device: \\.\PHYSICALDRIVE1 Device: \\?\STORAGE#Volume#{877708f9-14ba-11e9-bffc-000c292e2feb}#0000000000100000#{7f108a28-9833-4b3b-b780-2c6b5fa5c062} Examining Detected Hidden Volume: Arrival -
\\?\STORAGE#Volume#{877708f9-14ba-11e9-bffc-000c292e2feb}#0000000000100000#{7f108a28-9833-4b3b-b780-2c6b5fa5c062} |
| | | 2D20436F64653A20434F52485755544330303030303335392D2043616C6C3A20434F52485755544330303030303331352D205049443A202030303030373338302D205449443A202030303030373734342D20434D443A2020433A5C57696E646F77735C73797374656D33325C76737376632E6578652020202D20557365723A204E616D653A204E5420415554484F524954595C53595354454D2C205349443A532D312D352D313820 |
Binary data:
In Words
0000: 6F43202D 203A6564 48524F43 43545557
0008: 30303030 39353330 6143202D 203A6C6C
0010: 48524F43 43545557 30303030 35313330
0018: 4950202D 20203A44 30303030 30383337
0020: 4954202D 20203A44 30303030 34343737
0028: 4D43202D 20203A44 575C3A43 6F646E69
0030: 735C7377 65747379 5C32336D 76737376
0038: 78652E63 20202065 7355202D 203A7265
0040: 656D614E 544E203A 54554120 49524F48
0048: 535C5954 45545359 53202C4D 533A4449
0050: 352D312D 2038312D
In Bytes
0000: 2D 20 43 6F 64 65 3A 20 - Code:
0008: 43 4F 52 48 57 55 54 43 CORHWUTC
0010: 30 30 30 30 30 33 35 39 00000359
0018: 2D 20 43 61 6C 6C 3A 20 - Call:
0020: 43 4F 52 48 57 55 54 43 CORHWUTC
0028: 30 30 30 30 30 33 31 35 00000315
0030: 2D 20 50 49 44 3A 20 20 - PID:
0038: 30 30 30 30 37 33 38 30 00007380
0040: 2D 20 54 49 44 3A 20 20 - TID:
0048: 30 30 30 30 37 37 34 34 00007744
0050: 2D 20 43 4D 44 3A 20 20 - CMD:
0058: 43 3A 5C 57 69 6E 64 6F C:\Windo
0060: 77 73 5C 73 79 73 74 65 ws\syste
0068: 6D 33 32 5C 76 73 73 76 m32\vssv
0070: 63 2E 65 78 65 20 20 20 c.exe
0078: 2D 20 55 73 65 72 3A 20 - User:
0080: 4E 61 6D 65 3A 20 4E 54 Name: NT
0088: 20 41 55 54 48 4F 52 49 AUTHORI
0090: 54 59 5C 53 59 53 54 45 TY\SYSTE
0098: 4D 2C 20 53 49 44 3A 53 M, SID:S
00a0: 2D 31 2D 35 2D 31 38 20 -1-5-18
Thanks.
Best regards,
Tom