J
James Collins
We run an automated massive mailmerge using word 97, and
eventually our system runs out of memory (takes a week or
so) and freezes everything up. Dr. Watson reports errors
of access violation c00000005. Would an engineer be able
to look at the dump file and see what might be going on
and if it is indeed Word 97 that's causing this leak. Or
if it is happening during word 97?
Here's a copy of the dump file
pplication exception occurred:
App: WinWord.exe (pid=632)
When: 6/20/2003 @ 09:48:06.311
Exception number: c0000005 (access violation)
*----> System Information <----*
Computer Name: APPSERVER2
User Name: appserver2
Number of Processors: 1
Processor Type: x86 Family 15 Model 2 Stepping 7
Windows 2000 Version: 5.0
Current Build: 2195
Service Pack: 3
Current Type: Uniprocessor Free
Registered Organization: DANTOM Systems, Inc.
Registered Owner: Administrator
*----> Task List <----*
0 Idle.exe
8 System.exe
156 smss.exe
180 csrss.exe
200 WINLOGON.exe
228 services.exe
240 LSASS.exe
424 svchost.exe
456 SPOOLSV.exe
528 svchost.exe
556 NMSSvc.exe
592 PRISMXL.SYS.exe
620 Rosnmgr.exe
676 regsvc.exe
692 mstask.exe
768 winmgmt.exe
840 winvnc.exe
860 svchost.exe
960 explorer.exe
1040 BacsTray.exe
1072 PROMon.exe
1100 hkcmd.exe
516 wuauclt.exe
1188 winword.exe
720 APPXCTL.exe
996 ICL003.exe
632 winword.exe
1252 drwtsn32.exe
0 _Total.exe
(30000000 - 30525000)
(77F80000 - 77FFA000)
(30B50000 - 30C6E000)
(77E80000 - 77F31000)
(77E10000 - 77E6F000)
(77F40000 - 77F79000)
(77DB0000 - 77E0B000)
(77D30000 - 77D9D000)
(306C0000 - 30A65000)
(77A50000 - 77B3C000)
(782F0000 - 78534000)
(77C70000 - 77CBA000)
(77B50000 - 77BD9000)
(77800000 - 7781E000)
(76620000 - 76630000)
(10980000 - 10986000)
(775A0000 - 77625000)
(779B0000 - 77A4B000)
(78000000 - 78046000)
(75160000 - 7516C000)
(75210000 - 75225000)
(751D0000 - 75208000)
(75170000 - 751BF000)
(77BE0000 - 77BEF000)
(751C0000 - 751C6000)
(75150000 - 75160000)
(75030000 - 75043000)
(75020000 - 75028000)
(77950000 - 77978000)
(77980000 - 779A4000)
(75050000 - 75058000)
(77840000 - 7787D000)
(770C0000 - 770E3000)
(6A900000 - 6A906000)
(01AD0000 - 01AE4000)
(65000000 - 650BC000)
(65100000 - 6528E000)
(65300000 - 65327000)
State Dump for Thread Id 0x1ec
eax=00191b58 ebx=0012fb40 ecx=00000000 edx=7ffb001c
esi=0000001a edi=0012fb41
eip=6508fc32 esp=0012fa08 ebp=0012fa70 iopl=0 nv
up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038
gs=0000 efl=00200246
function: <nosymbols>
6508fc09 e94cffffff jmp 6508fb5a
6508fc0e 8b4628 mov eax,
[esi+0x28] ds:00a7d5ec=????????
6508fc11 89432c mov
[ebx+0x2c],eax ds:00bad112=????????
6508fc14 e967ffffff jmp 6508fb80
6508fc19 ffb578ffffff push dword ptr
[ebp+0xffffff78] ss:0012f9e8=81c9a6a8
6508fc1f 6a04 push 0x4
6508fc21 e979ffffff jmp 6508fb9f
6508fc26 ff74240c push dword ptr
[esp+0xc] ss:00bacfdb=????????
6508fc2a ff74240c push dword ptr
[esp+0xc] ss:00bacfdb=????????
6508fc2e ff74240c push dword ptr
[esp+0xc] ss:00bacfdb=????????
FAULT ->6508fc32 ff7108 push dword ptr
[ecx+0x8] ds:00a7d5d2=????????
6508fc35 ff1504150065 call dword ptr
[65001504] ds:65001504=77e16860
6508fc3b c20c00 ret 0xc
6508fc3e 55 push ebp
6508fc3f 8bec mov ebp,esp
6508fc41 83ec58 sub esp,0x58
6508fc44 53 push ebx
6508fc45 894df8 mov
[ebp+0xf8],ecx ss:00bad042=????????
6508fc48 56 push esi
6508fc49 57 push edi
6508fc4a 8b750c mov esi,
[ebp+0xc] ss:00bad042=????????
6508fc4d 85f6 test esi,esi
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4
Function Name
0012FA70 650020D0 0012FA8C 1E2701DE 0000001A 0000002F Vbe!
<nosymbols>
0012FA90 77E3A244 1E2701DE 0000001A 0000002F 0012FB40 Vbe!
<nosymbols>
0012FAB0 77E14730 650020B5 1E2701DE 0000001A 0000002F
user32!SetWindowPlacement
0012FACC 77E2D92D 004671D0 0000001A 0000002F 0012FB40
user32!TranslateMessageEx
0012FAFC 77F91A7F 0012FB0C 00000038 00000038 00000003
user32!SendDlgItemMessageA
0012FB68 77E1A84F 30500620 00000000 00000000 00000000
ntdll!KiUserCallbackDispatcher
0012FB94 300FD881 30500620 00000000 00000000 00000000
user32!PeekMessageW
0012FBB8 300FD924 30500620 00000000 00000000 00000000
WinWord!DirultkPrevTokenSkippingIndirect
0012FC04 301F8B52 30500620 00000000 00000000 00000000
WinWord!DirultkPrevTokenSkippingIndirect
00000000 00000000 00000000 00000000 00000000 00000000
WinWord!FMsgPresent
*----> Raw Stack Dump <----*
0012fa08 1a 00 00 00 2f 00 00 00 - 40 fb 12 00 59 69 04
65 ..../[email protected]
0012fa18 1a 00 00 00 2f 00 00 00 - 40 fb 12 00 00 00 04
65 ..../[email protected]
0012fa28 00 00 00 00 0c fb 12 00 - 00 00 00 00 0a 00 00
00 ................
0012fa38 00 00 00 00 01 00 00 00 - 24 92 44 01 01 03 00
00 ........$.D.....
0012fa48 24 fc 12 00 4f 8d 1f 30 - 5c 03 79 00 24 92 44
01 $...O..0\.y.$.D.
0012fa58 ff ff ff 7f 3c fc 12 00 - 01 00 00 00 24 92 44
01 ....<.......$.D.
0012fa68 01 03 00 00 24 92 44 01 - 90 fa 12 00 d0 20 00
65 ....$.D...... .e
0012fa78 8c fa 12 00 de 01 27 1e - 1a 00 00 00 2f 00 00
00 ......'...../...
0012fa88 40 fb 12 00 00 00 00 60 - b0 fa 12 00 44 a2 e3
77 @......`....D..w
0012fa98 de 01 27 1e 1a 00 00 00 - 2f 00 00 00 40 fb 12
00 ..'...../...@...
0012faa8 0c fb 12 00 cd ab ba dc - cc fa 12 00 30 47 e1
77 ............0G.w
0012fab8 b5 20 00 65 de 01 27 1e - 1a 00 00 00 2f 00 00
00 . .e..'...../...
0012fac8 40 fb 12 00 fc fa 12 00 - 2d d9 e2 77 d0 71 46
00 @.......-..w.qF.
0012fad8 1a 00 00 00 2f 00 00 00 - 40 fb 12 00 b5 20 00
65 ..../...@.... .e
0012fae8 02 01 00 00 20 06 50 30 - 00 00 00 00 00 00 00
00 .... .P0........
0012faf8 00 00 00 00 68 fb 12 00 - 7f 1a f9 77 0c fb 12
00 ....h......w....
0012fb08 38 00 00 00 38 00 00 00 - 03 00 00 00 01 00 00
00 8...8...........
0012fb18 38 da 7b b7 30 00 00 00 - 00 00 00 00 d0 71 46
00 8.{.0........qF.
0012fb28 1a 00 00 00 2f 00 00 00 - b5 20 00 65 e5 46 e1
77 ..../.... .e.F.w
0012fb38 40 fb 12 00 2c 00 00 00 - 00 da 7b b7 ef 47 e1
77 @...,.....{..G.w
State Dump for Thread Id 0x1d4
eax=001e67a8 ebx=80030001 ecx=00d9fdf8 edx=00000000
esi=00148e28 edi=00000100
eip=77f88a97 esp=00d9fe28 ebp=00d9ff74 iopl=0 nv
up ei pl nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038
gs=0000 efl=00000206
function: ZwReplyWaitReceivePortEx
77f88a8c b8ac000000 mov eax,0xac
77f88a91 8d542404 lea edx,
[esp+0x4] ss:0181d3fb=????????
77f88a95 cd2e int 2e
77f88a97 c21400 ret 0x14
77f88a9a 8bff mov edi,edi
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4
Function Name
00D9FF74 77D587A2 77D422AE 00148E28 401488F4 00000070
ntdll!ZwReplyWaitReceivePortEx
00D9FFA8 77D3F157 00147E30 00D9FFEC 77E8B2D8 00148D48
rpcrt4!TowerConstruct
00D9FFB4 77E8B2D8 00148D48 401488F4 00000070 00148D48
rpcrt4!I_RpcServerInqTransportType
00D9FFEC 00000000 00000000 00000000 00000000 00000000
kernel32!lstrcmpiW
State Dump for Thread Id 0x3b4
eax=00e9fcd0 ebx=80030001 ecx=00155fa8 edx=00000000
esi=00148e28 edi=00000100
eip=77f88a97 esp=00e9fe28 ebp=00e9ff74 iopl=0 nv
up ei pl nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038
gs=0000 efl=00000206
function: ZwReplyWaitReceivePortEx
77f88a8c b8ac000000 mov eax,0xac
77f88a91 8d542404 lea edx,
[esp+0x4] ss:0191d3fb=????????
77f88a95 cd2e int 2e
77f88a97 c21400 ret 0x14
77f88a9a 8bff mov edi,edi
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4
Function Name
00E9FF74 77D587A2 77D422AE 00148E28 00130000 0014B4C8
ntdll!ZwReplyWaitReceivePortEx
00E9FFA8 77D3F157 00154F00 00E9FFEC 77E8B2D8 00154F28
rpcrt4!TowerConstruct
00E9FFB4 77E8B2D8 00154F28 00130000 0014B4C8 00154F28
rpcrt4!I_RpcServerInqTransportType
00E9FFEC 00000000 77D3F13F 00154F28 00000000 4D944D94
kernel32!lstrcmpiW
*----> Raw Stack Dump <----*
00e9fe28 dc 8e d5 77 44 01 00 00 - 54 ff e9 00 00 00 00
00 ...wD...T.......
00e9fe38 28 15 19 00 58 ff e9 00 - 68 4e 14 00 00 4f 15
00 (...X...hN...O..
00e9fe48 28 4f 15 00 00 00 00 00 - 00 00 00 00 00 00 00
00 (O..............
00e9fe58 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
00e9fe68 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
00e9fe78 00 00 00 00 00 00 00 00 - 00 00 00 00 f9 5e 00
00 .............^..
00e9fe88 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
00e9fe98 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
00e9fea8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
00e9feb8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
00e9fec8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
00e9fed8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
00e9fee8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
00e9fef8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
00e9ff08 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
00e9ff18 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
00e9ff28 00 00 00 00 20 f0 c8 81 - 20 50 bd 81 00 00 00
00 .... ... P......
00e9ff38 20 50 bd 81 b0 51 bd 81 - 64 5c af b7 73 ad 42
80 P...Q..d\..s.B.
00e9ff48 7b ad 42 80 d4 4b 06 80 - 80 51 bd 81 01 00 03
80 {.B..K...Q......
00e9ff58 00 a2 2f 4d ff ff ff ff - 50 fe e9 00 01 00 03
80 ../M....P.......
State Dump for Thread Id 0x380
eax=00000000 ebx=80030001 ecx=00144e68 edx=00000000
esi=00148e28 edi=00000100
eip=77f88a97 esp=015cfe28 ebp=015cff74 iopl=0 nv
up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038
gs=0000 efl=00000202
function: ZwReplyWaitReceivePortEx
77f88a8c b8ac000000 mov eax,0xac
77f88a91 8d542404 lea edx,
[esp+0x4] ss:0204d3fb=????????
77f88a95 cd2e int 2e
77f88a97 c21400 ret 0x14
77f88a9a 8bff mov edi,edi
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4
Function Name
015CFF74 77D587A2 77D422AE 00148E28 00E9FA9C 00000022
ntdll!ZwReplyWaitReceivePortEx
015CFFA8 77D3F157 0016EA90 015CFFEC 77E8B2D8 0016F830
rpcrt4!TowerConstruct
015CFFB4 77E8B2D8 0016F830 00E9FA9C 00000022 0016F830
rpcrt4!I_RpcServerInqTransportType
015CFFEC 00000000 77D3F13F 0016F830 00000000 000000C8
kernel32!lstrcmpiW
*----> Raw Stack Dump <----*
015cfe28 dc 8e d5 77 44 01 00 00 - 54 ff 5c 01 00 00 00
00 ...wD...T.\.....
015cfe38 98 66 1e 00 58 ff 5c 01 - 68 4e 14 00 90 ea 16
00 .f..X.\.hN......
015cfe48 30 f8 16 00 00 00 00 00 - 00 00 00 00 00 00 00
00 0...............
015cfe58 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
015cfe68 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
015cfe78 00 00 00 00 00 00 00 00 - 00 00 00 00 fc 5e 00
00 .............^..
015cfe88 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
015cfe98 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
015cfea8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
015cfeb8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
015cfec8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
015cfed8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
015cfee8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
015cfef8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
015cff08 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
015cff18 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
015cff28 00 00 00 00 20 f0 c8 81 - 80 27 b5 81 00 00 00
00 .... ....'......
015cff38 80 27 b5 81 10 29 b5 81 - 64 4c 82 b7 73 ad 42
80 .'...)..dL..s.B.
015cff48 7b ad 42 80 d4 4b 06 80 - e0 28 b5 81 01 00 03
80 {.B..K...(......
015cff58 00 a2 2f 4d ff ff ff ff - 50 fe 5c 01 01 00 03
80 ../M....P.\.....
State Dump for Thread Id 0x47c
eax=00000000 ebx=00000000 ecx=00000101 edx=00000000
esi=77f882f8 edi=01ccff98
eip=77f88303 esp=01ccff84 ebp=01ccffa0 iopl=0 nv
up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038
gs=0000 efl=00000202
function: NtDelayExecution
77f882f8 b832000000 mov eax,0x32
77f882fd 8d542404 lea edx,
[esp+0x4] ss:0274d557=????????
77f88301 cd2e int 2e
77f88303 c20800 ret 0x8
77f88306 8bff mov edi,edi
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4
Function Name
01CCFFA0 77EA9D5F 00000064 00000000 6510165B 00000064
ntdll!NtDelayExecution
01CCFFEC 00000000 65101653 00000000 00000000 00000000
kernel32!Sleep
*----> Raw Stack Dump <----*
01ccff84 94 9d ea 77 00 00 00 00 - 98 ff cc 01 43 00 3a
00 ...w........C.:.
01ccff94 5c 00 57 00 c0 bd f0 ff - ff ff ff ff ec ff cc
01 \.W.............
01ccffa4 5f 9d ea 77 64 00 00 00 - 00 00 00 00 5b 16 10
65 _..wd.......[..e
01ccffb4 64 00 00 00 d8 b2 e8 77 - 00 00 00 00 43 00 3a
00 d......w....C.:.
01ccffc4 5c 00 57 00 00 00 00 00 - 00 a0 fd 7f 98 25 fb
77 \.W..........%.w
01ccffd4 c0 ff cc 01 98 25 fb 77 - ff ff ff ff 6c 13 ed
77 .....%.w....l..w
01ccffe4 98 2a e8 77 00 00 00 00 - 00 00 00 00 00 00 00
00 .*.w............
01ccfff4 53 16 10 65 00 00 00 00 - 00 00 00 00 00 00 00
00 S..e............
01cd0004 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
01cd0014 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
01cd0024 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
01cd0034 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
01cd0044 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
01cd0054 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
01cd0064 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
01cd0074 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
01cd0084 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
01cd0094 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
01cd00a4 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
01cd00b4 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
State Dump for Thread Id 0x4b0
eax=00155100 ebx=80030001 ecx=00148e9c edx=00000000
esi=00148e28 edi=00000100
eip=77f88a97 esp=024cfe28 ebp=024cff74 iopl=0 nv
up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038
gs=0000 efl=00000202
function: ZwReplyWaitReceivePortEx
77f88a8c b8ac000000 mov eax,0xac
77f88a91 8d542404 lea edx,
[esp+0x4] ss:02f4d3fb=????????
77f88a95 cd2e int 2e
77f88a97 c21400 ret 0x14
77f88a9a 8bff mov edi,edi
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4
Function Name
024CFF74 77D587A2 77D422AE 00148E28 00D9FA9C 00000022
ntdll!ZwReplyWaitReceivePortEx
024CFFA8 77D3F157 0017CA78 024CFFEC 77E8B2D8 001DF1E0
rpcrt4!TowerConstruct
024CFFB4 77E8B2D8 001DF1E0 00D9FA9C 00000022 001DF1E0
rpcrt4!I_RpcServerInqTransportType
024CFFEC 00000000 00000000 00000000 00000000 00000000
kernel32!lstrcmpiW
Thanks,
JC
jcollins@(DONTSPAMME)dantomsystems.(SPAMNO)com
omit () for email address
eventually our system runs out of memory (takes a week or
so) and freezes everything up. Dr. Watson reports errors
of access violation c00000005. Would an engineer be able
to look at the dump file and see what might be going on
and if it is indeed Word 97 that's causing this leak. Or
if it is happening during word 97?
Here's a copy of the dump file
pplication exception occurred:
App: WinWord.exe (pid=632)
When: 6/20/2003 @ 09:48:06.311
Exception number: c0000005 (access violation)
*----> System Information <----*
Computer Name: APPSERVER2
User Name: appserver2
Number of Processors: 1
Processor Type: x86 Family 15 Model 2 Stepping 7
Windows 2000 Version: 5.0
Current Build: 2195
Service Pack: 3
Current Type: Uniprocessor Free
Registered Organization: DANTOM Systems, Inc.
Registered Owner: Administrator
*----> Task List <----*
0 Idle.exe
8 System.exe
156 smss.exe
180 csrss.exe
200 WINLOGON.exe
228 services.exe
240 LSASS.exe
424 svchost.exe
456 SPOOLSV.exe
528 svchost.exe
556 NMSSvc.exe
592 PRISMXL.SYS.exe
620 Rosnmgr.exe
676 regsvc.exe
692 mstask.exe
768 winmgmt.exe
840 winvnc.exe
860 svchost.exe
960 explorer.exe
1040 BacsTray.exe
1072 PROMon.exe
1100 hkcmd.exe
516 wuauclt.exe
1188 winword.exe
720 APPXCTL.exe
996 ICL003.exe
632 winword.exe
1252 drwtsn32.exe
0 _Total.exe
(30000000 - 30525000)
(77F80000 - 77FFA000)
(30B50000 - 30C6E000)
(77E80000 - 77F31000)
(77E10000 - 77E6F000)
(77F40000 - 77F79000)
(77DB0000 - 77E0B000)
(77D30000 - 77D9D000)
(306C0000 - 30A65000)
(77A50000 - 77B3C000)
(782F0000 - 78534000)
(77C70000 - 77CBA000)
(77B50000 - 77BD9000)
(77800000 - 7781E000)
(76620000 - 76630000)
(10980000 - 10986000)
(775A0000 - 77625000)
(779B0000 - 77A4B000)
(78000000 - 78046000)
(75160000 - 7516C000)
(75210000 - 75225000)
(751D0000 - 75208000)
(75170000 - 751BF000)
(77BE0000 - 77BEF000)
(751C0000 - 751C6000)
(75150000 - 75160000)
(75030000 - 75043000)
(75020000 - 75028000)
(77950000 - 77978000)
(77980000 - 779A4000)
(75050000 - 75058000)
(77840000 - 7787D000)
(770C0000 - 770E3000)
(6A900000 - 6A906000)
(01AD0000 - 01AE4000)
(65000000 - 650BC000)
(65100000 - 6528E000)
(65300000 - 65327000)
State Dump for Thread Id 0x1ec
eax=00191b58 ebx=0012fb40 ecx=00000000 edx=7ffb001c
esi=0000001a edi=0012fb41
eip=6508fc32 esp=0012fa08 ebp=0012fa70 iopl=0 nv
up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038
gs=0000 efl=00200246
function: <nosymbols>
6508fc09 e94cffffff jmp 6508fb5a
6508fc0e 8b4628 mov eax,
[esi+0x28] ds:00a7d5ec=????????
6508fc11 89432c mov
[ebx+0x2c],eax ds:00bad112=????????
6508fc14 e967ffffff jmp 6508fb80
6508fc19 ffb578ffffff push dword ptr
[ebp+0xffffff78] ss:0012f9e8=81c9a6a8
6508fc1f 6a04 push 0x4
6508fc21 e979ffffff jmp 6508fb9f
6508fc26 ff74240c push dword ptr
[esp+0xc] ss:00bacfdb=????????
6508fc2a ff74240c push dword ptr
[esp+0xc] ss:00bacfdb=????????
6508fc2e ff74240c push dword ptr
[esp+0xc] ss:00bacfdb=????????
FAULT ->6508fc32 ff7108 push dword ptr
[ecx+0x8] ds:00a7d5d2=????????
6508fc35 ff1504150065 call dword ptr
[65001504] ds:65001504=77e16860
6508fc3b c20c00 ret 0xc
6508fc3e 55 push ebp
6508fc3f 8bec mov ebp,esp
6508fc41 83ec58 sub esp,0x58
6508fc44 53 push ebx
6508fc45 894df8 mov
[ebp+0xf8],ecx ss:00bad042=????????
6508fc48 56 push esi
6508fc49 57 push edi
6508fc4a 8b750c mov esi,
[ebp+0xc] ss:00bad042=????????
6508fc4d 85f6 test esi,esi
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4
Function Name
0012FA70 650020D0 0012FA8C 1E2701DE 0000001A 0000002F Vbe!
<nosymbols>
0012FA90 77E3A244 1E2701DE 0000001A 0000002F 0012FB40 Vbe!
<nosymbols>
0012FAB0 77E14730 650020B5 1E2701DE 0000001A 0000002F
user32!SetWindowPlacement
0012FACC 77E2D92D 004671D0 0000001A 0000002F 0012FB40
user32!TranslateMessageEx
0012FAFC 77F91A7F 0012FB0C 00000038 00000038 00000003
user32!SendDlgItemMessageA
0012FB68 77E1A84F 30500620 00000000 00000000 00000000
ntdll!KiUserCallbackDispatcher
0012FB94 300FD881 30500620 00000000 00000000 00000000
user32!PeekMessageW
0012FBB8 300FD924 30500620 00000000 00000000 00000000
WinWord!DirultkPrevTokenSkippingIndirect
0012FC04 301F8B52 30500620 00000000 00000000 00000000
WinWord!DirultkPrevTokenSkippingIndirect
00000000 00000000 00000000 00000000 00000000 00000000
WinWord!FMsgPresent
*----> Raw Stack Dump <----*
0012fa08 1a 00 00 00 2f 00 00 00 - 40 fb 12 00 59 69 04
65 ..../[email protected]
0012fa18 1a 00 00 00 2f 00 00 00 - 40 fb 12 00 00 00 04
65 ..../[email protected]
0012fa28 00 00 00 00 0c fb 12 00 - 00 00 00 00 0a 00 00
00 ................
0012fa38 00 00 00 00 01 00 00 00 - 24 92 44 01 01 03 00
00 ........$.D.....
0012fa48 24 fc 12 00 4f 8d 1f 30 - 5c 03 79 00 24 92 44
01 $...O..0\.y.$.D.
0012fa58 ff ff ff 7f 3c fc 12 00 - 01 00 00 00 24 92 44
01 ....<.......$.D.
0012fa68 01 03 00 00 24 92 44 01 - 90 fa 12 00 d0 20 00
65 ....$.D...... .e
0012fa78 8c fa 12 00 de 01 27 1e - 1a 00 00 00 2f 00 00
00 ......'...../...
0012fa88 40 fb 12 00 00 00 00 60 - b0 fa 12 00 44 a2 e3
77 @......`....D..w
0012fa98 de 01 27 1e 1a 00 00 00 - 2f 00 00 00 40 fb 12
00 ..'...../...@...
0012faa8 0c fb 12 00 cd ab ba dc - cc fa 12 00 30 47 e1
77 ............0G.w
0012fab8 b5 20 00 65 de 01 27 1e - 1a 00 00 00 2f 00 00
00 . .e..'...../...
0012fac8 40 fb 12 00 fc fa 12 00 - 2d d9 e2 77 d0 71 46
00 @.......-..w.qF.
0012fad8 1a 00 00 00 2f 00 00 00 - 40 fb 12 00 b5 20 00
65 ..../...@.... .e
0012fae8 02 01 00 00 20 06 50 30 - 00 00 00 00 00 00 00
00 .... .P0........
0012faf8 00 00 00 00 68 fb 12 00 - 7f 1a f9 77 0c fb 12
00 ....h......w....
0012fb08 38 00 00 00 38 00 00 00 - 03 00 00 00 01 00 00
00 8...8...........
0012fb18 38 da 7b b7 30 00 00 00 - 00 00 00 00 d0 71 46
00 8.{.0........qF.
0012fb28 1a 00 00 00 2f 00 00 00 - b5 20 00 65 e5 46 e1
77 ..../.... .e.F.w
0012fb38 40 fb 12 00 2c 00 00 00 - 00 da 7b b7 ef 47 e1
77 @...,.....{..G.w
State Dump for Thread Id 0x1d4
eax=001e67a8 ebx=80030001 ecx=00d9fdf8 edx=00000000
esi=00148e28 edi=00000100
eip=77f88a97 esp=00d9fe28 ebp=00d9ff74 iopl=0 nv
up ei pl nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038
gs=0000 efl=00000206
function: ZwReplyWaitReceivePortEx
77f88a8c b8ac000000 mov eax,0xac
77f88a91 8d542404 lea edx,
[esp+0x4] ss:0181d3fb=????????
77f88a95 cd2e int 2e
77f88a97 c21400 ret 0x14
77f88a9a 8bff mov edi,edi
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4
Function Name
00D9FF74 77D587A2 77D422AE 00148E28 401488F4 00000070
ntdll!ZwReplyWaitReceivePortEx
00D9FFA8 77D3F157 00147E30 00D9FFEC 77E8B2D8 00148D48
rpcrt4!TowerConstruct
00D9FFB4 77E8B2D8 00148D48 401488F4 00000070 00148D48
rpcrt4!I_RpcServerInqTransportType
00D9FFEC 00000000 00000000 00000000 00000000 00000000
kernel32!lstrcmpiW
State Dump for Thread Id 0x3b4
eax=00e9fcd0 ebx=80030001 ecx=00155fa8 edx=00000000
esi=00148e28 edi=00000100
eip=77f88a97 esp=00e9fe28 ebp=00e9ff74 iopl=0 nv
up ei pl nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038
gs=0000 efl=00000206
function: ZwReplyWaitReceivePortEx
77f88a8c b8ac000000 mov eax,0xac
77f88a91 8d542404 lea edx,
[esp+0x4] ss:0191d3fb=????????
77f88a95 cd2e int 2e
77f88a97 c21400 ret 0x14
77f88a9a 8bff mov edi,edi
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4
Function Name
00E9FF74 77D587A2 77D422AE 00148E28 00130000 0014B4C8
ntdll!ZwReplyWaitReceivePortEx
00E9FFA8 77D3F157 00154F00 00E9FFEC 77E8B2D8 00154F28
rpcrt4!TowerConstruct
00E9FFB4 77E8B2D8 00154F28 00130000 0014B4C8 00154F28
rpcrt4!I_RpcServerInqTransportType
00E9FFEC 00000000 77D3F13F 00154F28 00000000 4D944D94
kernel32!lstrcmpiW
*----> Raw Stack Dump <----*
00e9fe28 dc 8e d5 77 44 01 00 00 - 54 ff e9 00 00 00 00
00 ...wD...T.......
00e9fe38 28 15 19 00 58 ff e9 00 - 68 4e 14 00 00 4f 15
00 (...X...hN...O..
00e9fe48 28 4f 15 00 00 00 00 00 - 00 00 00 00 00 00 00
00 (O..............
00e9fe58 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
00e9fe68 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
00e9fe78 00 00 00 00 00 00 00 00 - 00 00 00 00 f9 5e 00
00 .............^..
00e9fe88 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
00e9fe98 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
00e9fea8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
00e9feb8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
00e9fec8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
00e9fed8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
00e9fee8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
00e9fef8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
00e9ff08 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
00e9ff18 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
00e9ff28 00 00 00 00 20 f0 c8 81 - 20 50 bd 81 00 00 00
00 .... ... P......
00e9ff38 20 50 bd 81 b0 51 bd 81 - 64 5c af b7 73 ad 42
80 P...Q..d\..s.B.
00e9ff48 7b ad 42 80 d4 4b 06 80 - 80 51 bd 81 01 00 03
80 {.B..K...Q......
00e9ff58 00 a2 2f 4d ff ff ff ff - 50 fe e9 00 01 00 03
80 ../M....P.......
State Dump for Thread Id 0x380
eax=00000000 ebx=80030001 ecx=00144e68 edx=00000000
esi=00148e28 edi=00000100
eip=77f88a97 esp=015cfe28 ebp=015cff74 iopl=0 nv
up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038
gs=0000 efl=00000202
function: ZwReplyWaitReceivePortEx
77f88a8c b8ac000000 mov eax,0xac
77f88a91 8d542404 lea edx,
[esp+0x4] ss:0204d3fb=????????
77f88a95 cd2e int 2e
77f88a97 c21400 ret 0x14
77f88a9a 8bff mov edi,edi
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4
Function Name
015CFF74 77D587A2 77D422AE 00148E28 00E9FA9C 00000022
ntdll!ZwReplyWaitReceivePortEx
015CFFA8 77D3F157 0016EA90 015CFFEC 77E8B2D8 0016F830
rpcrt4!TowerConstruct
015CFFB4 77E8B2D8 0016F830 00E9FA9C 00000022 0016F830
rpcrt4!I_RpcServerInqTransportType
015CFFEC 00000000 77D3F13F 0016F830 00000000 000000C8
kernel32!lstrcmpiW
*----> Raw Stack Dump <----*
015cfe28 dc 8e d5 77 44 01 00 00 - 54 ff 5c 01 00 00 00
00 ...wD...T.\.....
015cfe38 98 66 1e 00 58 ff 5c 01 - 68 4e 14 00 90 ea 16
00 .f..X.\.hN......
015cfe48 30 f8 16 00 00 00 00 00 - 00 00 00 00 00 00 00
00 0...............
015cfe58 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
015cfe68 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
015cfe78 00 00 00 00 00 00 00 00 - 00 00 00 00 fc 5e 00
00 .............^..
015cfe88 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
015cfe98 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
015cfea8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
015cfeb8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
015cfec8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
015cfed8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
015cfee8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
015cfef8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
015cff08 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
015cff18 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
015cff28 00 00 00 00 20 f0 c8 81 - 80 27 b5 81 00 00 00
00 .... ....'......
015cff38 80 27 b5 81 10 29 b5 81 - 64 4c 82 b7 73 ad 42
80 .'...)..dL..s.B.
015cff48 7b ad 42 80 d4 4b 06 80 - e0 28 b5 81 01 00 03
80 {.B..K...(......
015cff58 00 a2 2f 4d ff ff ff ff - 50 fe 5c 01 01 00 03
80 ../M....P.\.....
State Dump for Thread Id 0x47c
eax=00000000 ebx=00000000 ecx=00000101 edx=00000000
esi=77f882f8 edi=01ccff98
eip=77f88303 esp=01ccff84 ebp=01ccffa0 iopl=0 nv
up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038
gs=0000 efl=00000202
function: NtDelayExecution
77f882f8 b832000000 mov eax,0x32
77f882fd 8d542404 lea edx,
[esp+0x4] ss:0274d557=????????
77f88301 cd2e int 2e
77f88303 c20800 ret 0x8
77f88306 8bff mov edi,edi
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4
Function Name
01CCFFA0 77EA9D5F 00000064 00000000 6510165B 00000064
ntdll!NtDelayExecution
01CCFFEC 00000000 65101653 00000000 00000000 00000000
kernel32!Sleep
*----> Raw Stack Dump <----*
01ccff84 94 9d ea 77 00 00 00 00 - 98 ff cc 01 43 00 3a
00 ...w........C.:.
01ccff94 5c 00 57 00 c0 bd f0 ff - ff ff ff ff ec ff cc
01 \.W.............
01ccffa4 5f 9d ea 77 64 00 00 00 - 00 00 00 00 5b 16 10
65 _..wd.......[..e
01ccffb4 64 00 00 00 d8 b2 e8 77 - 00 00 00 00 43 00 3a
00 d......w....C.:.
01ccffc4 5c 00 57 00 00 00 00 00 - 00 a0 fd 7f 98 25 fb
77 \.W..........%.w
01ccffd4 c0 ff cc 01 98 25 fb 77 - ff ff ff ff 6c 13 ed
77 .....%.w....l..w
01ccffe4 98 2a e8 77 00 00 00 00 - 00 00 00 00 00 00 00
00 .*.w............
01ccfff4 53 16 10 65 00 00 00 00 - 00 00 00 00 00 00 00
00 S..e............
01cd0004 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
01cd0014 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
01cd0024 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
01cd0034 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
01cd0044 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
01cd0054 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
01cd0064 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
01cd0074 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
01cd0084 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
01cd0094 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
01cd00a4 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
01cd00b4 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00
00 ................
State Dump for Thread Id 0x4b0
eax=00155100 ebx=80030001 ecx=00148e9c edx=00000000
esi=00148e28 edi=00000100
eip=77f88a97 esp=024cfe28 ebp=024cff74 iopl=0 nv
up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038
gs=0000 efl=00000202
function: ZwReplyWaitReceivePortEx
77f88a8c b8ac000000 mov eax,0xac
77f88a91 8d542404 lea edx,
[esp+0x4] ss:02f4d3fb=????????
77f88a95 cd2e int 2e
77f88a97 c21400 ret 0x14
77f88a9a 8bff mov edi,edi
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4
Function Name
024CFF74 77D587A2 77D422AE 00148E28 00D9FA9C 00000022
ntdll!ZwReplyWaitReceivePortEx
024CFFA8 77D3F157 0017CA78 024CFFEC 77E8B2D8 001DF1E0
rpcrt4!TowerConstruct
024CFFB4 77E8B2D8 001DF1E0 00D9FA9C 00000022 001DF1E0
rpcrt4!I_RpcServerInqTransportType
024CFFEC 00000000 00000000 00000000 00000000 00000000
kernel32!lstrcmpiW
Thanks,
JC
jcollins@(DONTSPAMME)dantomsystems.(SPAMNO)com
omit () for email address