(no subject)

Steve Bray brays "at" tideway.e-sussex.sch.uk
Wed Mar 17 10:41:01 2004


Here's a copy of the log that Dr Watson generated...




Application exception occurred:
        App:  (pid=279)
        When: 3/17/2004 @ 10:6:15.984
        Exception number: c0000005 (access violation)

*----> System Information <----*
        Computer Name: TIDEWAY3
        User Name: SYSTEM
        Number of Processors: 2
        Processor Type: x86 Family 6 Model 8 Stepping 10
        Windows Version: 4.0
        Current Build: 1381
        Service Pack: 6
        Current Type: Multiprocessor Free
        Registered Organization: Tideway School Network
        Registered Owner: Tideway Community School

*----> Task List <----*
   0 Idle.exe
   2 System.exe
  25 SMSS.exe
  33 CSRSS.exe
  39 WINLOGON.exe
  45 SERVICES.exe
  48 LSASS.exe
  74 SPOOLSS.exe
  95 amgrsrvc.exe
 100 ati2plxx.exe
 105 LLSSRV.exe
 112 Mcshield.exe
 123 VsTskMgr.exe
 131 LOCATOR.exe
 160 rpcss.exe
 164 Smserve.exe
 171 Smtimeck.exe
 174 SNMP.exe
 177 WINS.exe
 181 TCPSVCS.exe
 188 dns.exe
 191 NMSSvc.exe
 212 PSTORES.exe
 219 mstask.exe
 279 winvnc.exe
  49 DRWTSN32.exe
   0 _Total.exe

(00400000 - 00400000) 
(77f60000 - 77fbf000) dll\ntdll.dbg
(77f00000 - 77f5f000) dll\kernel32.dbg
(77e70000 - 77ec2000) dll\user32.dbg
(77ed0000 - 77efc000) dll\gdi32.dbg
(77dc0000 - 77dff000) dll\advapi32.dbg
(77e10000 - 77e67000) dll\rpcrt4.dbg
(776d0000 - 776d8000) dll\wsock32.dbg
(776b0000 - 776c4000) dll\ws2_32.dbg
(78000000 - 78044000) 
(776a0000 - 776a7000) dll\ws2help.dbg
(77c40000 - 77d7b000) dll\shell32.dbg
(71710000 - 71794000) dll\comctl32.dbg
(77b20000 - 77bd1000) dll\ole32.dbg
(10000000 - 10000000) 
(00230000 - 00230000) 
(77bf0000 - 77bf7000) dll\rpcltc1.dbg
(77660000 - 7766f000) dll\msafd.dbg
(77690000 - 77699000) dll\wshtcpip.dbg
(74ff0000 - 74ffe000) dll\rnr20.dbg
(71300000 - 71306000) dll\msidle.dbg

State Dump for Thread Id 0x120

eax=77bf4030 ebx=0012feb4 ecx=77bf0000 edx=00000000 esi=00000050 edi=00000000
eip=77f67fc7 esp=0012fdd4 ebp=0012fe3c iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=0038  gs=0000             efl=00000246


function: ZwReadFile
        77f67fbc b886000000       mov     eax,0x86
        77f67fc1 8d542404         lea     edx,[esp+0x4]          
ss:0116e7db=????????
        77f67fc5 cd2e             int     2e
        77f67fc7 c22400           ret     0x24
        77f67fca 8bc0             mov     eax,eax

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1  Param#2  Param#3  Param#4  Function Name
0012fe3c 77dd8a61 00000050 00133168 0000021a 0012fe6c ntdll!ZwReadFile 
0012fe70 77dd84ad 00000050 00133168 0000021a 0012feb4 
advapi32!RegisterServiceCtrlHandlerA 
0012fed4 77dd82ca 00000050 00133168 0000021a 0042be69 
advapi32!StartServiceCtrlDispatcherW 
0012fef8 00419e05 0012ff0c 0042be69 0013350d 004378f0 
advapi32!StartServiceCtrlDispatcherA

*----> Raw Stack Dump <----*
0012fdd4  91 d2 f0 77 50 00 00 00 - 00 00 00 00 00 00 00 00  ...wP...........
0012fde4  00 00 00 00 10 fe 12 00 - 68 31 13 00 1a 02 00 00  ........h1......
0012fdf4  00 00 00 00 00 00 00 00 - 00 00 00 00 68 31 13 00  ............h1..
0012fe04  b4 fe 12 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0012fe14  3c fe 12 00 84 fe 12 00 - 04 00 00 00 00 00 00 00  <...............
0012fe24  fc fd 12 00 00 00 00 00 - c4 fe 12 00 a8 ba f3 77  ...............w
0012fe34  40 ca f3 77 ff ff ff ff - 70 fe 12 00 61 8a dd 77  @..w....p...a..w
0012fe44  50 00 00 00 68 31 13 00 - 1a 02 00 00 6c fe 12 00  P...h1......l...
0012fe54  00 00 00 00 00 00 00 00 - 00 00 00 00 84 75 13 00  .............u..
0012fe64  50 00 00 00 84 fe 12 00 - 00 00 00 00 d4 fe 12 00  P...............
0012fe74  ad 84 dd 77 50 00 00 00 - 68 31 13 00 1a 02 00 00  ...wP...h1......
0012fe84  b4 fe 12 00 68 31 13 00 - 00 00 00 00 1a 02 00 00  ....h1..........
0012fe94  04 01 00 00 00 00 00 00 - 00 00 00 00 01 00 00 00  ................
0012fea4  6c 31 13 00 00 00 00 00 - 01 00 00 00 30 64 13 00  l1..........0d..
0012feb4  00 00 00 00 00 00 00 00 - 88 fe 12 00 04 00 00 00  ................
0012fec4  b0 ff 12 00 64 11 de 77 - b8 e0 de 77 ff ff ff ff  ....d..w...w....
0012fed4  f8 fe 12 00 ca 82 dd 77 - 50 00 00 00 68 31 13 00  .......wP...h1..
0012fee4  1a 02 00 00 69 be 42 00 - 0d 35 13 00 0d 35 13 00  ....i.B..5...5..
0012fef4  50 00 00 00 00 00 00 00 - 05 9e 41 00 0c ff 12 00  P.........A.....
0012ff04  69 be 42 00 0d 35 13 00 - f0 78 43 00 70 9e 41 00  i.B..5...xC.p.A.

State Dump for Thread Id 0x11e

eax=00e6f324 ebx=00b71100 ecx=74ff9400 edx=00000000 esi=00e6ff2c edi=00000000
eip=77f6839b esp=00e6fa74 ebp=00000000 iopl=0         nv up ei pl nz na pe nc
cs=001b  ss=0023  ds=0023  es=0023  fs=0038  gs=0000             efl=00000202


function: NtWaitForSingleObject
        77f68390 b8c5000000       mov     eax,0xc5
        77f68395 8d542404         lea     edx,[esp+0x4]          
ss:01eae47b=????????
        77f68399 cd2e             int     2e
        77f6839b c20c00           ret     0xc
        77f6839e 8bc0             mov     eax,eax

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1  Param#2  Param#3  Param#4  Function Name
00000000 00000000 00000000 00000000 00000000 00000000 
ntdll!NtWaitForSingleObject

*----> Raw Stack Dump <----*
00e6fa74  e2 cf f6 77 d8 00 00 00 - 00 00 00 00 00 00 00 00  ...w............
00e6fa84  80 fc e6 00 2c ff e6 00 - 94 fc e6 00 60 11 b7 00  ....,.......`...
00e6fa94  04 00 00 00 b8 fa e6 00 - ae 12 e7 77 48 00 4e 00  ...........wH.N.
00e6faa4  eb ff ff ff 01 00 00 00 - 0c 01 40 00 78 fc e6 00  .......... "at" .x...
00e6fab4  01 00 00 00 f4 fa e6 00 - ee 22 e7 77 48 00 4e 00  .........".wH.N.
00e6fac4  eb ff ff ff 01 00 00 00 - 0c 01 40 00 e0 62 e7 77  .......... "at" ..b.w
00e6fad4  0c 01 40 00 54 00 00 00 - 00 00 00 00 00 00 00 00  .. "at" .T...........
00e6fae4  46 76 f6 77 2c ff e6 00 - 27 10 23 00 2c ff e6 00  Fv.w,...'.#.,...
00e6faf4  41 76 41 00 0c 01 40 00 - 13 01 00 00 9c 44 41 00  AvA... "at" ......DA.
00e6fb04  48 00 4e 00 78 fc e6 00 - 01 00 00 00 00 00 00 00  H.N.x...........
00e6fb14  af 19 00 10 00 64 6d 69 - 6e 00 00 00 e8 c0 00 00  .....dmin.......
00e6fb24  44 1e 00 10 17 01 34 01 - 00 00 00 00 01 00 00 00  D.....4.........
00e6fb34  04 fc e6 00 74 c0 fd 7f - 78 fc e6 00 3f 00 00 00  ....t...x...?...
00e6fb44  60 11 b7 00 19 17 00 10 - 3a 01 18 00 00 00 00 00  `.......:.......
00e6fb54  01 00 00 00 c0 fb e6 00 - 78 fb e6 00 2a a1 e7 77  ........x...*..w
00e6fb64  b0 fe 4d 00 1c 00 00 00 - 00 00 00 00 3f 00 00 00  ..M.........?...
00e6fb74  00 00 00 00 9c fb e6 00 - f0 4b e1 77 6c ff e6 00  .........K.wl...
00e6fb84  2a a0 42 00 ff ff ff ff - 84 14 e7 77 0c 01 40 00  *.B........w.. "at" .
00e6fb94  19 02 00 00 04 80 00 00 - 10 fc e6 00 cc fb e6 00  ................
00e6fba4  26 12 e9 77 48 00 4e 00 - 19 02 00 00 04 80 00 00  &..wH.N.........

State Dump for Thread Id 0x129

eax=00e6fc94 ebx=7766b100 ecx=00b72c40 edx=00000000 esi=00e72798 edi=000000c0
eip=77f6839b esp=00fefa48 ebp=00fefa9c iopl=0         nv up ei ng nz ac pe cy
cs=001b  ss=0023  ds=0023  es=0023  fs=0038  gs=0000             efl=00000293


function: NtWaitForSingleObject
        77f68390 b8c5000000       mov     eax,0xc5
        77f68395 8d542404         lea     edx,[esp+0x4]          
ss:0202e44f=????????
        77f68399 cd2e             int     2e
        77f6839b c20c00           ret     0xc
        77f6839e 8bc0             mov     eax,eax

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1  Param#2  Param#3  Param#4  Function Name
00fefa9c 77661202 000000c0 00000098 00000002 00000004 
ntdll!NtWaitForSingleObject 
00feff04 776bb416 00000098 00000000 00000000 00000000 msafd!<nosymbols> 
00feff3c 776bb3a1 00000098 00000000 00000000 00000000 ws2_32!WSAAccept 
00feffb8 77f04eeb 00a60900 00e6f8bc 00e6f960 00a60900 ws2_32!accept 
00feffec 00000000 00000000 00000000 00000000 00000000 kernel32!lstrcmpiW 
00000000 00000000 00000000 00000000 00000000 00000000 !<nosymbols>

*----> Raw Stack Dump <----*
00fefa48  ce 89 66 77 c0 00 00 00 - 01 00 00 00 74 fa fe 00  ..fw........t...
00fefa58  b4 27 e7 00 9c 27 e7 00 - 1a 00 00 00 ca 2f c8 78  .'...'......./.x
00fefa68  07 0c c4 01 ff ff ff ff - ff ff ff 7f ff ff ff ff  ................
00fefa78  ff ff ff 7f 00 00 00 00 - f0 84 13 00 ad 1f 6a 77  ..............jw
00fefa88  d8 11 66 77 98 00 00 00 - 00 00 00 00 00 00 00 00  ..fw............
00fefa98  00 00 00 00 04 ff fe 00 - 02 12 66 77 c0 00 00 00  ..........fw....
00fefaa8  98 00 00 00 02 00 00 00 - 04 00 00 00 00 00 00 00  ................
00fefab8  a0 39 90 00 c0 37 90 00 - 66 00 02 00 00 00 00 00  .9...7..f.......
00fefac8  00 00 00 00 00 00 00 00 - 08 00 00 00 00 00 00 00  ................
00fefad8  00 00 00 00 00 00 00 00 - 00 00 00 00 e9 03 00 00  ................
00fefae8  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
00fefaf8  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
00fefb08  00 00 00 00 02 00 00 00 - 00 00 00 00 00 00 00 00  ................
00fefb18  01 00 00 00 06 00 00 00 - 00 00 00 00 00 00 00 00  ................
00fefb28  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
00fefb38  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
00fefb48  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
00fefb58  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
00fefb68  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
00fefb78  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................

State Dump for Thread Id 0x48

eax=009037a8 ebx=7766b100 ecx=00000000 edx=00000000 esi=00e72518 edi=0000008c
eip=77f6839b esp=010efa48 ebp=010efa9c iopl=0         nv up ei ng nz ac po cy
cs=001b  ss=0023  ds=0023  es=0023  fs=0038  gs=0000             efl=00000297


function: NtWaitForSingleObject
        77f68390 b8c5000000       mov     eax,0xc5
        77f68395 8d542404         lea     edx,[esp+0x4]          
ss:0212e44f=????????
        77f68399 cd2e             int     2e
        77f6839b c20c00           ret     0xc
        77f6839e 8bc0             mov     eax,eax

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1  Param#2  Param#3  Param#4  Function Name
010efa9c 77661202 0000008c 000000b4 00000002 00000004 
ntdll!NtWaitForSingleObject 
010eff04 776bb416 000000b4 00000000 00000000 00000000 msafd!<nosymbols> 
010eff3c 776bb3a1 000000b4 00000000 00000000 00000000 ws2_32!WSAAccept 
010effb8 77f04eeb 00a60880 00e6f8a0 00e6f944 00a60880 ws2_32!accept 
010effec 00000000 00232a25 00a60880 00000000 010f0010 kernel32!lstrcmpiW 
00000000 00000000 00000000 00000000 00000000 00000000 !<nosymbols>

*----> Raw Stack Dump <----*
010efa48  ce 89 66 77 8c 00 00 00 - 01 00 00 00 74 fa 0e 01  ..fw........t...
010efa58  34 25 e7 00 1c 25 e7 00 - 1a 00 00 00 00 33 8b 77  4%...%.......3.w
010efa68  35 0b c4 01 ff ff ff ff - ff ff ff 7f ff ff ff ff  5...............
010efa78  ff ff ff 7f 00 00 00 00 - c0 84 13 00 ad 1f 6a 77  ..............jw
010efa88  d8 11 66 77 b4 00 00 00 - 00 00 00 00 00 00 00 00  ..fw............
010efa98  00 00 00 00 04 ff 0e 01 - 02 12 66 77 8c 00 00 00  ..........fw....
010efaa8  b4 00 00 00 02 00 00 00 - 04 00 00 00 00 00 00 00  ................
010efab8  68 38 90 00 c0 37 90 00 - 00 00 00 00 00 00 00 00  h8...7..........
010efac8  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
010efad8  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
010efae8  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
010efaf8  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
010efb08  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
010efb18  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
010efb28  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
010efb38  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
010efb48  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
010efb58  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
010efb68  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
010efb78  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................

State Dump for Thread Id 0x125

eax=77e17bf2 ebx=00000000 ecx=00000000 edx=00000000 esi=0013f078 edi=0013ea80
eip=77f68067 esp=01e9fdf0 ebp=01e9ff90 iopl=0         nv up ei pl nz na pe nc
cs=001b  ss=0023  ds=0023  es=0023  fs=0038  gs=0000             efl=00000202


function: ZwReplyWaitReceivePort
        77f6805c b890000000       mov     eax,0x90
        77f68061 8d542404         lea     edx,[esp+0x4]          
ss:02ede7f7=????????
        77f68065 cd2e             int     2e
        77f68067 c21000           ret     0x10
        77f6806a 8bc0             mov     eax,eax

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1  Param#2  Param#3  Param#4  Function Name
01e9ff90 77e17f38 77e17b56 0013ea80 01e9ffec 00139630 
ntdll!ZwReplyWaitReceivePort 
00003a98 00000000 00000000 00000000 00000000 00000000 rpcrt4!I_RpcAllocate

State Dump for Thread Id 0xb6

eax=00000c80 ebx=00000c80 ecx=00000150 edx=067fe020 esi=067fe760 edi=06bbe760
eip=00407afb esp=060bfe00 ebp=00b73b38 iopl=0         nv up ei pl nz na pe nc
cs=001b  ss=0023  ds=0023  es=0023  fs=0038  gs=0000             efl=00000202


function: <nosymbols>
        00407ae0 89442410         mov     [esp+0x10],eax         
ss:070fe807=????????
        00407ae4 3bf1             cmp     esi,ecx
        00407ae6 7333             jnb     00407b1b
        00407ae8 2bce             sub     ecx,esi
        00407aea 894c2414         mov     [esp+0x14],ecx         
ss:070fe807=????????
        00407aee 8b4c241c         mov     ecx,[esp+0x1c]         
ss:070fe807=????????
        00407af2 8bf8             mov     edi,eax
        00407af4 8bc1             mov     eax,ecx
        00407af6 8bf2             mov     esi,edx
        00407af8 c1e902           shr     ecx,0x2
FAULT ->00407afb f3a5            rep  movsd ds:067fe760=???????? 
es:06bbe760=00000000
        00407afd 8bc8             mov     ecx,eax
        00407aff 8b442410         mov     eax,[esp+0x10]         
ss:070fe807=????????
        00407b03 83e103           and     ecx,0x3
        00407b06 03d3             add     edx,ebx
        00407b08 f3a4             rep     movsb         ds:067fe760=?? 
es:06bbe760=00
        00407b0a 8b4c2414         mov     ecx,[esp+0x14]         
ss:070fe807=????????
        00407b0e 03c3             add     eax,ebx
        00407b10 49               dec     ecx
        00407b11 89442410         mov     [esp+0x10],eax         
ss:070fe807=????????
        00407b15 894c2414         mov     [esp+0x14],ecx         
ss:070fe807=????????
        00407b19 75d3             jnz     00407aee

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1  Param#2  Param#3  Param#4  Function Name
00b73b38 001d4c0c 06a60020 001d4c00 01002020 00ff00ff <nosymbols>

State Dump for Thread Id 0x105

eax=00000000 ebx=00e6ff00 ecx=00000308 edx=00000000 esi=00e6ff2c edi=00000000
eip=77f6839b esp=061bfde4 ebp=00000000 iopl=0         nv up ei pl nz na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=0038  gs=0000             efl=00000206


function: NtWaitForSingleObject
        77f68390 b8c5000000       mov     eax,0xc5
        77f68395 8d542404         lea     edx,[esp+0x4]          
ss:071fe7eb=????????
        77f68399 cd2e             int     2e
        77f6839b c20c00           ret     0xc
        77f6839e 8bc0             mov     eax,eax

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1  Param#2  Param#3  Param#4  Function Name
00000000 00000000 00000000 00000000 00000000 00000000 
ntdll!NtWaitForSingleObject