thodges5
01-14-2002, 11:32 AM
Does anyone understand how to make sense of what the Dr. Watson log is saying? Here is an example of what I am trying to resolve.
Thanks. TH
Application exception occurred:
App: (pid=235)
When: 1/12/2002 @ 0:6:26.234
Exception number: c0000005 (access violation)
*----> System Information <----*
Computer Name: MULTI_SERVER2
User Name: Administrator
Number of Processors: 1
Processor Type: x86 Family 6 Model 8 Stepping 3
Windows Version: 4.0
Current Build: 1381
Service Pack: 6
Current Type: Uniprocessor Free
Registered Organization:
Registered Owner:
*----> Task List <----*
0 Idle.exe
2 System.exe
28 SMSS.exe
44 CSRSS.exe
34 WINLOGON.exe
49 SERVICES.exe
52 LSASS.exe
78 SPOOLSS.exe
90 amgrsrvc.exe
96 AWHOST32.exe
107 LLSSRV.exe
110 MCSHIELD.exe
125 VsTskMgr.exe
140 RPCSS.exe
163 DKService.exe
166 inetinfo.exe
171 PSTORES.exe
176 mstask.exe
56 NDDEAGNT.exe
69 EXPLORER.exe
208 PROMon.exe
213 LOADWC.exe
222 shstat.exe
234 rdrs.exe
238 Results.exe
235 stats.exe
122 DRWTSN32.exe
0 _Total.exe
(00400000 - 00400000)
(77f60000 - 77fbe000) dll\ntdll.dbg
(77800000 - 7783a000) dll\netapi32.dbg
(78000000 - 7803d000)
(77f00000 - 77f5e000) dll\kernel32.dbg
(77dc0000 - 77dff000) dll\advapi32.dbg
(77e70000 - 77ec5000) dll\user32.dbg
(77ed0000 - 77efc000) dll\gdi32.dbg
(77e10000 - 77e67000) dll\rpcrt4.dbg
(77840000 - 77849000) dll\NetRap.dbg
(777e0000 - 777ed000) dll\samlib.dbg
(77c00000 - 77c18000) drv\winspool.dbg
State Dump for Thread Id 0xda
eax=002f1f10 ebx=0000001f ecx=20202000 edx=0030cb7c esi=00000001 edi=00001500
eip=78001799 esp=0012fd20 ebp=0012fd40 iopl=0 nv up ei ng nz na po cy
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000287
function: memcpy
7800177c d3ef shr edi,cl
7800177e 8d4c0104 lea ecx,[ecx+eax+0x4] ds:01000917=????????
78001782 f7d7 not edi
78001784 217cb044 and [eax+esi*4+0x44],edi ds:00d0ea08=????????
78001788 fe09 dec byte ptr [ecx] ds:20202000=??
7800178a 7505 jnz memcpy+0x28d (78001791)
7800178c 8b4d08 mov ecx,[ebp+0x8] ss:00e3e746=????????
7800178f 2139 and [ecx],edi ds:20202000=????????
78001791 8b4c1308 mov ecx,[ebx+edx+0x8] ds:0101b583=????????
78001795 8b7c1304 mov edi,[ebx+edx+0x4] ds:0101b583=????????
FAULT ->78001799 897904 mov [ecx+0x4],edi ds:20f10a06=????????
7800179c 8b4c1304 mov ecx,[ebx+edx+0x4] ds:0101b583=????????
780017a0 8b7c1308 mov edi,[ebx+edx+0x8] ds:0101b583=????????
780017a4 035df8 add ebx,[ebp-0x8] ss:00e3e746=????????
780017a7 897908 mov [ecx+0x8],edi ds:20f10a06=????????
780017aa 895df4 mov [ebp-0xc],ebx ss:00e3e746=????????
780017ad e985feffff jmp memcpy+0x133 (78001637)
780017b2 897d0c mov [ebp+0xc],edi ss:00e3e746=????????
780017b5 ebae jmp memcpy+0x261 (78001765)
780017b7 83c1e0 add ecx,0xe0
780017ba bf00000080 mov edi,0x80000000
780017bf d3ef shr edi,cl
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0012fd40 78001465 002f1dc8 0000003f 00000000 004037ff !memcpy
00000001 00000000 00000000 00000000 00000000 00000000 !free
*----> Raw Stack Dump <----*
0012fd20 80 cb 30 00 80 cb 30 00 - 00 00 00 00 13 00 00 00 ..0...0.........
0012fd30 58 22 2f 00 1f 00 00 00 - 00 31 00 00 21 00 00 00 X"/......1..!...
0012fd40 01 00 00 00 65 14 00 78 - c8 1d 2f 00 3f 00 00 00 ....e..x../.?...
0012fd50 00 00 00 00 ff 37 40 00 - 80 cb 30 00 83 93 40 00 .....7@...0...@.
0012fd60 80 cb 30 00 3c 3b 90 00 - 00 00 00 00 64 ca 3f 3c ..0.<;......d.?<
0012fd70 1c 00 00 00 2d 03 01 18 - 01 00 00 00 da 0d 62 08 ....-.........b.
0012fd80 f5 00 2f 00 04 00 00 00 - 00 00 00 00 da 0d 63 08 ../...........c.
0012fd90 1e 06 3f 3c bd 07 00 00 - 00 00 00 00 00 00 00 00 ..?<............
0012fda0 00 00 00 00 00 00 00 00 - 00 00 00 00 6f 05 00 00 ............o...
0012fdb0 00 00 00 00 97 01 00 00 - 4b 00 00 00 6c 00 00 00 ........K...l...
0012fdc0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0012fdd0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0012fde0 00 00 00 00 f5 00 4e 00 - 00 00 00 00 00 00 00 00 ......N.........
0012fdf0 df 0f 41 00 da 0d 62 08 - 62 08 64 ca 44 3b 91 00 ..A...b.b.d.D;..
0012fe00 00 00 00 00 e8 0d e8 0d - da 0d 62 08 64 ca 3f 3c ..........b.d.?<
0012fe10 60 d2 3f 3c 04 00 00 00 - da 0d 00 00 da 0d 62 08 `.?<..........b.
0012fe20 b9 0b 00 00 9c fb 3e 3c - 11 05 3f 3c fe fb 3e 3c ......><..?<..><
0012fe30 9a ca 3f 3c 35 09 00 00 - 35 09 00 00 00 00 00 00 ..?<5...5.......
0012fe40 da 0d 62 08 64 ca 3f 3c - aa d8 3f 3c 60 d2 3f 3c ..b.d.?<..?<`.?<
0012fe50 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
State Dump for Thread Id 0x7e
eax=000000c0 ebx=00000000 ecx=7ffdd000 edx=00000000 esi=0046e838 edi=77836070
eip=77f682db esp=00cfffa0 ebp=00cfffec iopl=0 nv up ei ng nz ac po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000296
function: NtWaitForSingleObject
77f682d0 b8c5000000 mov eax,0xc5
77f682d5 8d542404 lea edx,[esp+0x4] ss:01a0e9a7=????????
77f682d9 cd2e int 2e
77f682db c20c00 ret 0xc
77f682de 8bc0 mov eax,eax
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
00cfffec 00000000 00000000 00000000 00000000 00000000 ntdll!NtWaitForSingleObject
00000000 00000000 00000000 00000000 00000000 00000000 !<nosymbols>
Thanks. TH
Application exception occurred:
App: (pid=235)
When: 1/12/2002 @ 0:6:26.234
Exception number: c0000005 (access violation)
*----> System Information <----*
Computer Name: MULTI_SERVER2
User Name: Administrator
Number of Processors: 1
Processor Type: x86 Family 6 Model 8 Stepping 3
Windows Version: 4.0
Current Build: 1381
Service Pack: 6
Current Type: Uniprocessor Free
Registered Organization:
Registered Owner:
*----> Task List <----*
0 Idle.exe
2 System.exe
28 SMSS.exe
44 CSRSS.exe
34 WINLOGON.exe
49 SERVICES.exe
52 LSASS.exe
78 SPOOLSS.exe
90 amgrsrvc.exe
96 AWHOST32.exe
107 LLSSRV.exe
110 MCSHIELD.exe
125 VsTskMgr.exe
140 RPCSS.exe
163 DKService.exe
166 inetinfo.exe
171 PSTORES.exe
176 mstask.exe
56 NDDEAGNT.exe
69 EXPLORER.exe
208 PROMon.exe
213 LOADWC.exe
222 shstat.exe
234 rdrs.exe
238 Results.exe
235 stats.exe
122 DRWTSN32.exe
0 _Total.exe
(00400000 - 00400000)
(77f60000 - 77fbe000) dll\ntdll.dbg
(77800000 - 7783a000) dll\netapi32.dbg
(78000000 - 7803d000)
(77f00000 - 77f5e000) dll\kernel32.dbg
(77dc0000 - 77dff000) dll\advapi32.dbg
(77e70000 - 77ec5000) dll\user32.dbg
(77ed0000 - 77efc000) dll\gdi32.dbg
(77e10000 - 77e67000) dll\rpcrt4.dbg
(77840000 - 77849000) dll\NetRap.dbg
(777e0000 - 777ed000) dll\samlib.dbg
(77c00000 - 77c18000) drv\winspool.dbg
State Dump for Thread Id 0xda
eax=002f1f10 ebx=0000001f ecx=20202000 edx=0030cb7c esi=00000001 edi=00001500
eip=78001799 esp=0012fd20 ebp=0012fd40 iopl=0 nv up ei ng nz na po cy
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000287
function: memcpy
7800177c d3ef shr edi,cl
7800177e 8d4c0104 lea ecx,[ecx+eax+0x4] ds:01000917=????????
78001782 f7d7 not edi
78001784 217cb044 and [eax+esi*4+0x44],edi ds:00d0ea08=????????
78001788 fe09 dec byte ptr [ecx] ds:20202000=??
7800178a 7505 jnz memcpy+0x28d (78001791)
7800178c 8b4d08 mov ecx,[ebp+0x8] ss:00e3e746=????????
7800178f 2139 and [ecx],edi ds:20202000=????????
78001791 8b4c1308 mov ecx,[ebx+edx+0x8] ds:0101b583=????????
78001795 8b7c1304 mov edi,[ebx+edx+0x4] ds:0101b583=????????
FAULT ->78001799 897904 mov [ecx+0x4],edi ds:20f10a06=????????
7800179c 8b4c1304 mov ecx,[ebx+edx+0x4] ds:0101b583=????????
780017a0 8b7c1308 mov edi,[ebx+edx+0x8] ds:0101b583=????????
780017a4 035df8 add ebx,[ebp-0x8] ss:00e3e746=????????
780017a7 897908 mov [ecx+0x8],edi ds:20f10a06=????????
780017aa 895df4 mov [ebp-0xc],ebx ss:00e3e746=????????
780017ad e985feffff jmp memcpy+0x133 (78001637)
780017b2 897d0c mov [ebp+0xc],edi ss:00e3e746=????????
780017b5 ebae jmp memcpy+0x261 (78001765)
780017b7 83c1e0 add ecx,0xe0
780017ba bf00000080 mov edi,0x80000000
780017bf d3ef shr edi,cl
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0012fd40 78001465 002f1dc8 0000003f 00000000 004037ff !memcpy
00000001 00000000 00000000 00000000 00000000 00000000 !free
*----> Raw Stack Dump <----*
0012fd20 80 cb 30 00 80 cb 30 00 - 00 00 00 00 13 00 00 00 ..0...0.........
0012fd30 58 22 2f 00 1f 00 00 00 - 00 31 00 00 21 00 00 00 X"/......1..!...
0012fd40 01 00 00 00 65 14 00 78 - c8 1d 2f 00 3f 00 00 00 ....e..x../.?...
0012fd50 00 00 00 00 ff 37 40 00 - 80 cb 30 00 83 93 40 00 .....7@...0...@.
0012fd60 80 cb 30 00 3c 3b 90 00 - 00 00 00 00 64 ca 3f 3c ..0.<;......d.?<
0012fd70 1c 00 00 00 2d 03 01 18 - 01 00 00 00 da 0d 62 08 ....-.........b.
0012fd80 f5 00 2f 00 04 00 00 00 - 00 00 00 00 da 0d 63 08 ../...........c.
0012fd90 1e 06 3f 3c bd 07 00 00 - 00 00 00 00 00 00 00 00 ..?<............
0012fda0 00 00 00 00 00 00 00 00 - 00 00 00 00 6f 05 00 00 ............o...
0012fdb0 00 00 00 00 97 01 00 00 - 4b 00 00 00 6c 00 00 00 ........K...l...
0012fdc0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0012fdd0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0012fde0 00 00 00 00 f5 00 4e 00 - 00 00 00 00 00 00 00 00 ......N.........
0012fdf0 df 0f 41 00 da 0d 62 08 - 62 08 64 ca 44 3b 91 00 ..A...b.b.d.D;..
0012fe00 00 00 00 00 e8 0d e8 0d - da 0d 62 08 64 ca 3f 3c ..........b.d.?<
0012fe10 60 d2 3f 3c 04 00 00 00 - da 0d 00 00 da 0d 62 08 `.?<..........b.
0012fe20 b9 0b 00 00 9c fb 3e 3c - 11 05 3f 3c fe fb 3e 3c ......><..?<..><
0012fe30 9a ca 3f 3c 35 09 00 00 - 35 09 00 00 00 00 00 00 ..?<5...5.......
0012fe40 da 0d 62 08 64 ca 3f 3c - aa d8 3f 3c 60 d2 3f 3c ..b.d.?<..?<`.?<
0012fe50 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
State Dump for Thread Id 0x7e
eax=000000c0 ebx=00000000 ecx=7ffdd000 edx=00000000 esi=0046e838 edi=77836070
eip=77f682db esp=00cfffa0 ebp=00cfffec iopl=0 nv up ei ng nz ac po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000296
function: NtWaitForSingleObject
77f682d0 b8c5000000 mov eax,0xc5
77f682d5 8d542404 lea edx,[esp+0x4] ss:01a0e9a7=????????
77f682d9 cd2e int 2e
77f682db c20c00 ret 0xc
77f682de 8bc0 mov eax,eax
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
00cfffec 00000000 00000000 00000000 00000000 00000000 ntdll!NtWaitForSingleObject
00000000 00000000 00000000 00000000 00000000 00000000 !<nosymbols>