W
Wayne
All,
I am not sure if this is the right place to post this issue but I have a
windows 2003 Server SP2 set up as a print spooler and we are getting constand
instances of the print spooler crashing, we have tried moving the spool file,
increasing memory and have changed the drivers of some of the printers all to
no avail.
Could anyone please offer some further advise as this is becoming a really
frustrating issue as users are constantly excperiencing problems when
printing.
I have pasted below an extraction from the Dr Watson log file to assist -
apologies for the rather huge post. If you require a specific part of the log
file please let me know and I will post it as I am unable to see away of
attaching a file to the discussion.
Thanks you in advance for your assitance.
Wayne
***** Dr Watson File *****
*----> State Dump for Thread Id 0xb78 <----*
eax=77f6c9e8 ebx=00000000 ecx=0007fc78 edx=00000000 esi=00000000 edi=00000050
eip=7c8285ec esp=0007fbd0 ebp=0007fc38 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\ntdll.dll -
function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]
*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\ADVAPI32.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\spoolsv.exe -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\kernel32.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
0007fc38 77f65edb 00000050 0007fd04 0000021a ntdll!KiFastSystemCallRet
0007fc64 77f65f82 00000050 0007fd04 0000021a
ADVAPI32!LookupPrivilegeValueW+0x114
0007fcd8 77f51ed9 00000050 0007fd04 0000021a
ADVAPI32!LookupPrivilegeValueW+0x1bb
0007ff3c 01004019 0100d5bc 010047a2 00000001
ADVAPI32!StartServiceCtrlDispatcherW+0x8b
0007ffc0 77e6f23b 00000000 00000000 7ffd7000 spoolsv+0x4019
0007fff0 00000000 0100468c 00000000 78746341
kernel32!ProcessIdToSessionId+0x209
*----> State Dump for Thread Id 0xc00 <----*
eax=00000001 ebx=00095c90 ecx=003aff60 edx=7c8285ec esi=00000078 edi=00000000
eip=7c8285ec esp=003aff0c ebp=003aff7c iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]
*----> Stack Back Trace <----*
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
003aff7c 77e61c8d 00000078 ffffffff 00000000 ntdll!KiFastSystemCallRet
003aff90 010043a3 00000078 ffffffff 00095c90 kernel32!WaitForSingleObject+0x12
003affa4 77f65e91 00000001 00095c9c 00000000 spoolsv+0x43a3
003affb8 77e64829 00095c90 00000000 00000000
ADVAPI32!LookupPrivilegeValueW+0xca
003affec 00000000 77f65e70 00095c90 00000000 kernel32!GetModuleHandleA+0xdf
*----> State Dump for Thread Id 0x5a8 <----*
eax=00000000 ebx=000a5978 ecx=00095860 edx=0009585c esi=000c05a0 edi=00000000
eip=7c8285ec esp=0081fe1c ebp=0081ff84 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]
*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\RPCRT4.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
0081ff84 77c88792 0081ffac 77c8872d 000c05a0 ntdll!KiFastSystemCallRet
0081ff8c 77c8872d 000c05a0 00000000 00000000 RPCRT4!I_RpcFree+0xbd0
0081ffac 77c7b110 000957d0 0081ffec 77e64829 RPCRT4!I_RpcFree+0xb6b
0081ffb8 77e64829 000a5978 00000000 00000000
RPCRT4!NdrFullPointerInsertRefId+0x3ba
0081ffec 00000000 77c7b0f5 000a5978 00000000 kernel32!GetModuleHandleA+0xdf
*----> State Dump for Thread Id 0x744 <----*
eax=00000402 ebx=7c81a3ab ecx=00000410 edx=0001991b esi=0100d620 edi=000cc8e4
eip=7c8285ec esp=0089ff7c ebp=0089ffb8 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]
*----> Stack Back Trace <----*
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
0089ffb8 77e64829 00000000 00000000 00000000 ntdll!KiFastSystemCallRet
0089ffec 00000000 010045b9 00000000 00000000 kernel32!GetModuleHandleA+0xdf
*----> State Dump for Thread Id 0xa10 <----*
eax=004e2028 ebx=00a3f818 ecx=00000000 edx=00000000 esi=00a3f81c edi=7ffd7000
eip=7c8285ec esp=00a3f7cc ebp=00a3f874 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]
*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\USER32.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\SPOOLSS.DLL -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
00a3f874 7739bbd1 00000002 00a3f89c 00000000 ntdll!KiFastSystemCallRet
00a3f8d0 7739ce36 00000001 00a3f930 ffffffff
USER32!MsgWaitForMultipleObjectsEx+0xd7
00a3f8ec 740655f5 00000001 00a3f930 00000000
USER32!MsgWaitForMultipleObjects+0x1f
00a3f938 74064b43 00000000 00000000 008f1ea8
SPOOLSS!BuildOtherNamesFromMachineName+0x6a6
00a3ffb8 77e64829 008f1ea8 00000000 00000000 SPOOLSS!InitializeRouter+0x3f6
00a3ffec 00000000 01003df8 008f1ea8 00000000 kernel32!GetModuleHandleA+0xdf
*----> State Dump for Thread Id 0xbfc <----*
eax=740652c2 ebx=00a7fefc ecx=00000000 edx=00000000 esi=00a7fefc edi=7ffd7000
eip=7c8285ec esp=00a7feb0 ebp=00a7ff58 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]
*----> Stack Back Trace <----*
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
00a7ff58 77e62fbe 00000001 00a7ffac 00000000 ntdll!KiFastSystemCallRet
00a7ff74 7406532a 00000001 00a7ffac 00000000
kernel32!WaitForMultipleObjects+0x18
00a7ffb8 77e64829 000000d0 00000000 00000000
SPOOLSS!BuildOtherNamesFromMachineName+0x3db
00a7ffec 00000000 740652c2 00033b68 00000000 kernel32!GetModuleHandleA+0xdf
*----> State Dump for Thread Id 0xdd8 <----*
eax=724515df ebx=00000000 ecx=00000000 edx=00000000 esi=00000188 edi=00000000
eip=7c8285ec esp=00edff0c ebp=00edff7c iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]
*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\usbmon.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
00edff7c 77e61c8d 00000188 ffffffff 00000000 ntdll!KiFastSystemCallRet
00edff90 724515fa 00000188 ffffffff 00000000 kernel32!WaitForSingleObject+0x12
00edffb8 77e64829 72455068 00000000 00000000
usbmon!InitializePrintMonitor+0x11c
00edffec 00000000 724515df 72455068 00000000 kernel32!GetModuleHandleA+0xdf
*----> State Dump for Thread Id 0x9f4 <----*
eax=6720102d ebx=00f1fec0 ecx=00000000 edx=00000000 esi=00f1fec0 edi=7ffd7000
eip=7c8285ec esp=00f1fe74 ebp=00f1ff1c iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]
*----> Stack Back Trace <----*
*** WARNING: Unable to verify checksum for C:\WINDOWS\system32\HPBHealr.dll
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\HPBHealr.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
00f1ff1c 77e62fbe 00000001 00f1ffa0 00000000 ntdll!KiFastSystemCallRet
00f1ff38 67201138 00000001 00f1ffa0 00000000
kernel32!WaitForMultipleObjects+0x18
00f1ffb8 77e64829 00000000 00000000 00000000
HPBHealr!InitializePrintMonitor+0xfc
00f1ffec 00000000 6720102d 00000000 00000000 kernel32!GetModuleHandleA+0xdf
*----> State Dump for Thread Id 0x6b0 <----*
eax=724664d4 ebx=7246b050 ecx=0003b214 edx=00000000 esi=000001f0 edi=00000000
eip=7c8285ec esp=01a9ff1c ebp=01a9ff8c iopl=0 nv up ei ng nz ac po cy
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000297
function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]
*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\tcpmon.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
01a9ff8c 77e61c8d 000001f0 00007530 00000000 ntdll!KiFastSystemCallRet
01a9ffa0 72461375 000001f0 00007530 00000000 kernel32!WaitForSingleObject+0x12
01a9ffb8 77e64829 7246b050 00000000 00000000 tcpmon+0x1375
01a9ffec 00000000 72461340 7246b050 00000000 kernel32!GetModuleHandleA+0xdf
*----> State Dump for Thread Id 0x534 <----*
eax=00000102 ebx=7c81a360 ecx=77e61d43 edx=7c8285ec esi=0000024c edi=00000000
eip=7c8285ec esp=01adfed8 ebp=01adff48 iopl=0 nv up ei ng nz ac po cy
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000297
function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]
*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\WSNMP32.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\msvcrt.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
01adff48 77e61c8d 0000024c 000003e8 00000000 ntdll!KiFastSystemCallRet
01adff5c 71ff5bf8 0000024c 000003e8 00000000 kernel32!WaitForSingleObject+0x12
01adff84 77bcb530 00000000 00000000 00000000 WSNMP32!SnmpSetPort+0x825
01adffb8 77e64829 0003bdb0 00000000 00000000 msvcrt!endthreadex+0xa3
01adffec 00000000 77bcb4bc 0003bdb0 00000000 kernel32!GetModuleHandleA+0xdf
*----> State Dump for Thread Id 0x65c <----*
eax=000358ec ebx=00000000 ecx=00037d90 edx=00000000 esi=00000254 edi=00000000
eip=7c8285ec esp=01b1fed8 ebp=01b1ff48 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]
*----> Stack Back Trace <----*
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
01b1ff48 77e61c8d 00000254 ffffffff 00000000 ntdll!KiFastSystemCallRet
01b1ff5c 71ff5924 00000254 ffffffff 00000000 kernel32!WaitForSingleObject+0x12
01b1ff84 77bcb530 00000000 00000000 00000000 WSNMP32!SnmpSetPort+0x551
01b1ffb8 77e64829 0003bee0 00000000 00000000 msvcrt!endthreadex+0xa3
01b1ffec 00000000 77bcb4bc 0003bee0 00000000 kernel32!GetModuleHandleA+0xdf
*----> State Dump for Thread Id 0xab4 <----*
eax=006b0050 ebx=00000000 ecx=0000001b edx=0000001b esi=00000184 edi=00000000
eip=7c8285ec esp=01b5ff0c ebp=01b5ff7c iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]
*----> Stack Back Trace <----*
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
01b5ff7c 77e61c8d 00000184 ffffffff 00000000 ntdll!KiFastSystemCallRet
01b5ff90 724515fa 00000184 ffffffff 00000000 kernel32!WaitForSingleObject+0x12
01b5ffb8 77e64829 0097cc58 00000000 00000000
usbmon!InitializePrintMonitor+0x11c
01b5ffec 00000000 724515df 72455068 00000000 kernel32!GetModuleHandleA+0xdf
*----> State Dump for Thread Id 0xea4 <----*
eax=00000000 ebx=01bdfea8 ecx=01bdfef0 edx=00000008 esi=01bdfeac edi=7ffd7000
eip=7c8285ec esp=01bdfe5c ebp=01bdff04 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]
*----> Stack Back Trace <----*
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
01bdff04 71ff69b7 00000002 01bdff58 00000000 ntdll!KiFastSystemCallRet
01bdff84 77bcb530 71ffb5d8 00000000 00000000 WSNMP32!SnmpSetPort+0x15e4
01bdffb8 77e64829 0003c1d8 00000000 00000000 msvcrt!endthreadex+0xa3
01bdffec 00000000 77bcb4bc 0003c1d8 00000000 kernel32!GetModuleHandleA+0xdf
*----> State Dump for Thread Id 0x3ac <----*
eax=00000004 ebx=00000000 ecx=00000001 edx=00000004 esi=000003d8 edi=00000000
eip=7c8285ec esp=01e7ff08 ebp=01e7ff78 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]
*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\localspl.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
01e7ff78 77e61c8d 000003d8 ffffffff 00000000 ntdll!KiFastSystemCallRet
01e7ff8c 7616ba7c 000003d8 ffffffff 00000000 kernel32!WaitForSingleObject+0x12
01e7ffb8 77e64829 00975968 00000000 00000000
localspl!SplLogWmiTraceEventExternal+0x40b0
01e7ffec 00000000 7616b9f0 00975968 00000000 kernel32!GetModuleHandleA+0xdf
I am not sure if this is the right place to post this issue but I have a
windows 2003 Server SP2 set up as a print spooler and we are getting constand
instances of the print spooler crashing, we have tried moving the spool file,
increasing memory and have changed the drivers of some of the printers all to
no avail.
Could anyone please offer some further advise as this is becoming a really
frustrating issue as users are constantly excperiencing problems when
printing.
I have pasted below an extraction from the Dr Watson log file to assist -
apologies for the rather huge post. If you require a specific part of the log
file please let me know and I will post it as I am unable to see away of
attaching a file to the discussion.
Thanks you in advance for your assitance.
Wayne
***** Dr Watson File *****
*----> State Dump for Thread Id 0xb78 <----*
eax=77f6c9e8 ebx=00000000 ecx=0007fc78 edx=00000000 esi=00000000 edi=00000050
eip=7c8285ec esp=0007fbd0 ebp=0007fc38 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\ntdll.dll -
function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]
*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\ADVAPI32.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\spoolsv.exe -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\kernel32.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
0007fc38 77f65edb 00000050 0007fd04 0000021a ntdll!KiFastSystemCallRet
0007fc64 77f65f82 00000050 0007fd04 0000021a
ADVAPI32!LookupPrivilegeValueW+0x114
0007fcd8 77f51ed9 00000050 0007fd04 0000021a
ADVAPI32!LookupPrivilegeValueW+0x1bb
0007ff3c 01004019 0100d5bc 010047a2 00000001
ADVAPI32!StartServiceCtrlDispatcherW+0x8b
0007ffc0 77e6f23b 00000000 00000000 7ffd7000 spoolsv+0x4019
0007fff0 00000000 0100468c 00000000 78746341
kernel32!ProcessIdToSessionId+0x209
*----> State Dump for Thread Id 0xc00 <----*
eax=00000001 ebx=00095c90 ecx=003aff60 edx=7c8285ec esi=00000078 edi=00000000
eip=7c8285ec esp=003aff0c ebp=003aff7c iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]
*----> Stack Back Trace <----*
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
003aff7c 77e61c8d 00000078 ffffffff 00000000 ntdll!KiFastSystemCallRet
003aff90 010043a3 00000078 ffffffff 00095c90 kernel32!WaitForSingleObject+0x12
003affa4 77f65e91 00000001 00095c9c 00000000 spoolsv+0x43a3
003affb8 77e64829 00095c90 00000000 00000000
ADVAPI32!LookupPrivilegeValueW+0xca
003affec 00000000 77f65e70 00095c90 00000000 kernel32!GetModuleHandleA+0xdf
*----> State Dump for Thread Id 0x5a8 <----*
eax=00000000 ebx=000a5978 ecx=00095860 edx=0009585c esi=000c05a0 edi=00000000
eip=7c8285ec esp=0081fe1c ebp=0081ff84 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]
*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\RPCRT4.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
0081ff84 77c88792 0081ffac 77c8872d 000c05a0 ntdll!KiFastSystemCallRet
0081ff8c 77c8872d 000c05a0 00000000 00000000 RPCRT4!I_RpcFree+0xbd0
0081ffac 77c7b110 000957d0 0081ffec 77e64829 RPCRT4!I_RpcFree+0xb6b
0081ffb8 77e64829 000a5978 00000000 00000000
RPCRT4!NdrFullPointerInsertRefId+0x3ba
0081ffec 00000000 77c7b0f5 000a5978 00000000 kernel32!GetModuleHandleA+0xdf
*----> State Dump for Thread Id 0x744 <----*
eax=00000402 ebx=7c81a3ab ecx=00000410 edx=0001991b esi=0100d620 edi=000cc8e4
eip=7c8285ec esp=0089ff7c ebp=0089ffb8 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]
*----> Stack Back Trace <----*
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
0089ffb8 77e64829 00000000 00000000 00000000 ntdll!KiFastSystemCallRet
0089ffec 00000000 010045b9 00000000 00000000 kernel32!GetModuleHandleA+0xdf
*----> State Dump for Thread Id 0xa10 <----*
eax=004e2028 ebx=00a3f818 ecx=00000000 edx=00000000 esi=00a3f81c edi=7ffd7000
eip=7c8285ec esp=00a3f7cc ebp=00a3f874 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]
*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\USER32.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\SPOOLSS.DLL -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
00a3f874 7739bbd1 00000002 00a3f89c 00000000 ntdll!KiFastSystemCallRet
00a3f8d0 7739ce36 00000001 00a3f930 ffffffff
USER32!MsgWaitForMultipleObjectsEx+0xd7
00a3f8ec 740655f5 00000001 00a3f930 00000000
USER32!MsgWaitForMultipleObjects+0x1f
00a3f938 74064b43 00000000 00000000 008f1ea8
SPOOLSS!BuildOtherNamesFromMachineName+0x6a6
00a3ffb8 77e64829 008f1ea8 00000000 00000000 SPOOLSS!InitializeRouter+0x3f6
00a3ffec 00000000 01003df8 008f1ea8 00000000 kernel32!GetModuleHandleA+0xdf
*----> State Dump for Thread Id 0xbfc <----*
eax=740652c2 ebx=00a7fefc ecx=00000000 edx=00000000 esi=00a7fefc edi=7ffd7000
eip=7c8285ec esp=00a7feb0 ebp=00a7ff58 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]
*----> Stack Back Trace <----*
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
00a7ff58 77e62fbe 00000001 00a7ffac 00000000 ntdll!KiFastSystemCallRet
00a7ff74 7406532a 00000001 00a7ffac 00000000
kernel32!WaitForMultipleObjects+0x18
00a7ffb8 77e64829 000000d0 00000000 00000000
SPOOLSS!BuildOtherNamesFromMachineName+0x3db
00a7ffec 00000000 740652c2 00033b68 00000000 kernel32!GetModuleHandleA+0xdf
*----> State Dump for Thread Id 0xdd8 <----*
eax=724515df ebx=00000000 ecx=00000000 edx=00000000 esi=00000188 edi=00000000
eip=7c8285ec esp=00edff0c ebp=00edff7c iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]
*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\usbmon.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
00edff7c 77e61c8d 00000188 ffffffff 00000000 ntdll!KiFastSystemCallRet
00edff90 724515fa 00000188 ffffffff 00000000 kernel32!WaitForSingleObject+0x12
00edffb8 77e64829 72455068 00000000 00000000
usbmon!InitializePrintMonitor+0x11c
00edffec 00000000 724515df 72455068 00000000 kernel32!GetModuleHandleA+0xdf
*----> State Dump for Thread Id 0x9f4 <----*
eax=6720102d ebx=00f1fec0 ecx=00000000 edx=00000000 esi=00f1fec0 edi=7ffd7000
eip=7c8285ec esp=00f1fe74 ebp=00f1ff1c iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]
*----> Stack Back Trace <----*
*** WARNING: Unable to verify checksum for C:\WINDOWS\system32\HPBHealr.dll
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\HPBHealr.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
00f1ff1c 77e62fbe 00000001 00f1ffa0 00000000 ntdll!KiFastSystemCallRet
00f1ff38 67201138 00000001 00f1ffa0 00000000
kernel32!WaitForMultipleObjects+0x18
00f1ffb8 77e64829 00000000 00000000 00000000
HPBHealr!InitializePrintMonitor+0xfc
00f1ffec 00000000 6720102d 00000000 00000000 kernel32!GetModuleHandleA+0xdf
*----> State Dump for Thread Id 0x6b0 <----*
eax=724664d4 ebx=7246b050 ecx=0003b214 edx=00000000 esi=000001f0 edi=00000000
eip=7c8285ec esp=01a9ff1c ebp=01a9ff8c iopl=0 nv up ei ng nz ac po cy
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000297
function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]
*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\tcpmon.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
01a9ff8c 77e61c8d 000001f0 00007530 00000000 ntdll!KiFastSystemCallRet
01a9ffa0 72461375 000001f0 00007530 00000000 kernel32!WaitForSingleObject+0x12
01a9ffb8 77e64829 7246b050 00000000 00000000 tcpmon+0x1375
01a9ffec 00000000 72461340 7246b050 00000000 kernel32!GetModuleHandleA+0xdf
*----> State Dump for Thread Id 0x534 <----*
eax=00000102 ebx=7c81a360 ecx=77e61d43 edx=7c8285ec esi=0000024c edi=00000000
eip=7c8285ec esp=01adfed8 ebp=01adff48 iopl=0 nv up ei ng nz ac po cy
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000297
function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]
*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\WSNMP32.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\msvcrt.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
01adff48 77e61c8d 0000024c 000003e8 00000000 ntdll!KiFastSystemCallRet
01adff5c 71ff5bf8 0000024c 000003e8 00000000 kernel32!WaitForSingleObject+0x12
01adff84 77bcb530 00000000 00000000 00000000 WSNMP32!SnmpSetPort+0x825
01adffb8 77e64829 0003bdb0 00000000 00000000 msvcrt!endthreadex+0xa3
01adffec 00000000 77bcb4bc 0003bdb0 00000000 kernel32!GetModuleHandleA+0xdf
*----> State Dump for Thread Id 0x65c <----*
eax=000358ec ebx=00000000 ecx=00037d90 edx=00000000 esi=00000254 edi=00000000
eip=7c8285ec esp=01b1fed8 ebp=01b1ff48 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]
*----> Stack Back Trace <----*
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
01b1ff48 77e61c8d 00000254 ffffffff 00000000 ntdll!KiFastSystemCallRet
01b1ff5c 71ff5924 00000254 ffffffff 00000000 kernel32!WaitForSingleObject+0x12
01b1ff84 77bcb530 00000000 00000000 00000000 WSNMP32!SnmpSetPort+0x551
01b1ffb8 77e64829 0003bee0 00000000 00000000 msvcrt!endthreadex+0xa3
01b1ffec 00000000 77bcb4bc 0003bee0 00000000 kernel32!GetModuleHandleA+0xdf
*----> State Dump for Thread Id 0xab4 <----*
eax=006b0050 ebx=00000000 ecx=0000001b edx=0000001b esi=00000184 edi=00000000
eip=7c8285ec esp=01b5ff0c ebp=01b5ff7c iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]
*----> Stack Back Trace <----*
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
01b5ff7c 77e61c8d 00000184 ffffffff 00000000 ntdll!KiFastSystemCallRet
01b5ff90 724515fa 00000184 ffffffff 00000000 kernel32!WaitForSingleObject+0x12
01b5ffb8 77e64829 0097cc58 00000000 00000000
usbmon!InitializePrintMonitor+0x11c
01b5ffec 00000000 724515df 72455068 00000000 kernel32!GetModuleHandleA+0xdf
*----> State Dump for Thread Id 0xea4 <----*
eax=00000000 ebx=01bdfea8 ecx=01bdfef0 edx=00000008 esi=01bdfeac edi=7ffd7000
eip=7c8285ec esp=01bdfe5c ebp=01bdff04 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]
*----> Stack Back Trace <----*
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
01bdff04 71ff69b7 00000002 01bdff58 00000000 ntdll!KiFastSystemCallRet
01bdff84 77bcb530 71ffb5d8 00000000 00000000 WSNMP32!SnmpSetPort+0x15e4
01bdffb8 77e64829 0003c1d8 00000000 00000000 msvcrt!endthreadex+0xa3
01bdffec 00000000 77bcb4bc 0003c1d8 00000000 kernel32!GetModuleHandleA+0xdf
*----> State Dump for Thread Id 0x3ac <----*
eax=00000004 ebx=00000000 ecx=00000001 edx=00000004 esi=000003d8 edi=00000000
eip=7c8285ec esp=01e7ff08 ebp=01e7ff78 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]
*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\localspl.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
01e7ff78 77e61c8d 000003d8 ffffffff 00000000 ntdll!KiFastSystemCallRet
01e7ff8c 7616ba7c 000003d8 ffffffff 00000000 kernel32!WaitForSingleObject+0x12
01e7ffb8 77e64829 00975968 00000000 00000000
localspl!SplLogWmiTraceEventExternal+0x40b0
01e7ffec 00000000 7616b9f0 00975968 00000000 kernel32!GetModuleHandleA+0xdf