1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Data Dump - Windows XP Pro SP1

Discussion in 'Windows XP' started by 5J5J, 2005/03/31.

Thread Status:
Not open for further replies.
  1. 2005/03/31
    5J5J

    5J5J Inactive Thread Starter

    Joined:
    2005/03/30
    Messages:
    1
    Likes Received:
    0
    Symptoms are:

    Explorer.exe crashes at 30 second intervals.

    Any insight would be greatly appreciated. Also, some pointers as to how to interpret dump files would be great.


    Opened log file 'c:\debuglog.txt'

    Microsoft (R) Windows Debugger Version 6.4.0007.2
    Copyright (c) Microsoft Corporation. All rights reserved.


    Loading Dump File [C:\Documents and Settings\whower\My Documents\Barnwell Dump Logs\Janet Hamel\user.dmp]
    User Mini Dump File: Only registers, stack and portions of memory are available

    Comment: 'Dr. Watson generated MiniDump'
    Windows XP Version 2600 (Service Pack 1) MP (2 procs) Free x86 compatible
    Product: WinNt, suite: SingleUserTS
    Debug session time: Wed Mar 30 08:28:24.000 2005 (GMT-6)
    System Uptime: not available
    Process Uptime: 0 days 0:00:26.000
    Symbol search path is: SRV*c:\symbols*http://msdl.microsoft.com/download/symbols
    Executable search path is: C:\WINDOWS;C:\WINDOWS\system32;C:\WINDOWS\system32\drivers
    .......................................................................
    (f30.de0): Access violation - code c0000005 (!!! second chance !!!)
    eax=00000007 ebx=00000000 ecx=77d440c6 edx=00000201 esi=067cfde4 edi=00000000
    eip=719a5866 esp=0006fbd0 ebp=0006fbdc iopl=0 nv up ei pl nz na po nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000206
    comctl32!ListView_OnFindItemA+0x11:
    719a5866 f60641 test byte ptr [esi],0x41 ds:0023:067cfde4=??
    0:000> !analyze -v;r;kv;lmtn;.logclose;q
    *******************************************************************************
    * *
    * Exception Analysis *
    * *
    *******************************************************************************


    FAULTING_IP:
    comctl32!ListView_OnFindItemA+11
    719a5866 f60641 test byte ptr [esi],0x41

    EXCEPTION_RECORD: ffffffff -- (.exr ffffffffffffffff)
    .exr ffffffffffffffff
    ExceptionAddress: 719a5866 (comctl32!ListView_OnFindItemA+0x00000011)
    ExceptionCode: c0000005 (Access violation)
    ExceptionFlags: 00000000
    NumberParameters: 2
    Parameter[0]: 00000000
    Parameter[1]: 067cfde4
    Attempt to read from address 067cfde4

    DEFAULT_BUCKET_ID: APPLICATION_FAULT

    PROCESS_NAME: explorer.exe

    ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx ". The memory could not be "%s ".

    READ_ADDRESS: 067cfde4

    BUGCHECK_STR: ACCESS_VIOLATION

    THREAD_ATTRIBUTES:
    LAST_CONTROL_TRANSFER: from 719a8b33 to 719a5866

    STACK_TEXT:
    0006fbdc 719a8b33 000d4a90 ffffffff 067cfde4 comctl32!ListView_OnFindItemA+0x11
    0006fd34 77d43a50 0053015e 0000100d ffffffff comctl32!ListView_WndProc+0xa2e
    0006fd60 77d43b1f 719a8105 0053015e 0000100d user32!InternalCallWinProc+0x1b
    0006fdc8 77d444f5 000849e0 719a8105 0053015e user32!UserCallWinProcCheckWow+0x150
    0006fe1c 77d44525 0048a458 0000100d ffffffff user32!DispatchClientMessage+0xa3
    0006fe44 77f75da3 0006fe54 00000018 0048a458 user32!__fnDWORD+0x22
    0006fe68 77d43ed1 77d43eb4 0006fee0 00000000 ntdll!KiUserCallbackDispatcher+0x13
    0006fe94 77d43fd4 0006fee0 00000000 00000000 user32!NtUserPeekMessage+0xc
    0006fec0 4f539ec9 0006fee0 00000000 00000000 user32!PeekMessageW+0xba
    0006fefc 4f539e88 77e7a1ee 000cc8b0 000cc8b0 shell32!CDesktopBrowser::_PeekForAMessage+0x1b
    0006ff14 4f5563cf 00000000 0100b571 000cc8b0 shell32!CDesktopBrowser::_MessageLoop+0x12
    0006ff1c 0100b571 000cc8b0 7ffdf000 0006ffc0 shell32!SHDesktopMessageLoop+0x20
    0006ff5c 0100b6af 01000000 00000000 0002075c explorer!ExplorerWinMain+0x2ab
    0006ffc0 77e8141a 00000000 00000000 7ffdf000 explorer!ModuleEntry+0x6b
    0006fff0 00000000 0100b644 00000000 00000000 kernel32!BaseProcessStart+0x23


    FOLLOWUP_IP:
    comctl32!ListView_OnFindItemA+11
    719a5866 f60641 test byte ptr [esi],0x41

    SYMBOL_STACK_INDEX: 0

    FOLLOWUP_NAME: MachineOwner

    SYMBOL_NAME: comctl32!ListView_OnFindItemA+11

    MODULE_NAME: comctl32

    IMAGE_NAME: comctl32.dll

    DEBUG_FLR_IMAGE_TIMESTAMP: 412674a9

    STACK_COMMAND: .ecxr ; kb

    FAILURE_BUCKET_ID: ACCESS_VIOLATION_comctl32!ListView_OnFindItemA+11

    BUCKET_ID: ACCESS_VIOLATION_comctl32!ListView_OnFindItemA+11

    Followup: MachineOwner
    ---------

    eax=00000007 ebx=00000000 ecx=77d440c6 edx=00000201 esi=067cfde4 edi=00000000
    eip=719a5866 esp=0006fbd0 ebp=0006fbdc iopl=0 nv up ei pl nz na po nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000206
    comctl32!ListView_OnFindItemA+0x11:
    719a5866 f60641 test byte ptr [esi],0x41 ds:0023:067cfde4=??
    ChildEBP RetAddr Args to Child
    0006fbdc 719a8b33 000d4a90 ffffffff 067cfde4 comctl32!ListView_OnFindItemA+0x11 (FPO: [Non-Fpo])
    0006fd34 77d43a50 0053015e 0000100d ffffffff comctl32!ListView_WndProc+0xa2e (FPO: [Non-Fpo])
    0006fd60 77d43b1f 719a8105 0053015e 0000100d user32!InternalCallWinProc+0x1b
    0006fdc8 77d444f5 000849e0 719a8105 0053015e user32!UserCallWinProcCheckWow+0x150 (FPO: [Non-Fpo])
    0006fe1c 77d44525 0048a458 0000100d ffffffff user32!DispatchClientMessage+0xa3 (FPO: [Non-Fpo])
    0006fe44 77f75da3 0006fe54 00000018 0048a458 user32!__fnDWORD+0x22 (FPO: [Non-Fpo])
    0006fe68 77d43ed1 77d43eb4 0006fee0 00000000 ntdll!KiUserCallbackDispatcher+0x13 (FPO: [0,0,0])
    0006fe94 77d43fd4 0006fee0 00000000 00000000 user32!NtUserPeekMessage+0xc (FPO: [Non-Fpo])
    0006fec0 4f539ec9 0006fee0 00000000 00000000 user32!PeekMessageW+0xba (FPO: [Non-Fpo])
    0006fefc 4f539e88 77e7a1ee 000cc8b0 000cc8b0 shell32!CDesktopBrowser::_PeekForAMessage+0x1b (FPO: [Non-Fpo])
    0006ff14 4f5563cf 00000000 0100b571 000cc8b0 shell32!CDesktopBrowser::_MessageLoop+0x12 (FPO: [Non-Fpo])
    0006ff1c 0100b571 000cc8b0 7ffdf000 0006ffc0 shell32!SHDesktopMessageLoop+0x20 (FPO: [1,0,1])
    0006ff5c 0100b6af 01000000 00000000 0002075c explorer!ExplorerWinMain+0x2ab (FPO: [Non-Fpo])
    0006ffc0 77e8141a 00000000 00000000 7ffdf000 explorer!ModuleEntry+0x6b (FPO: [Non-Fpo])
    0006fff0 00000000 0100b644 00000000 00000000 kernel32!BaseProcessStart+0x23 (FPO: [Non-Fpo])
    start end module name
    01000000 010f7000 explorer explorer.exe Sun May 11 23:12:04 2003 (3EBF1F14)
    01240000 0132a000 NALEXPRS NALEXPRS.DLL Tue Oct 14 17:46:10 2003 (3F8C7CB2)
    01400000 01601000 msi msi.dll Thu Aug 29 05:40:29 2002 (3D6DFA1D)
    01a10000 01aa3000 xpsp2res xpsp2res.dll Fri Jul 30 16:29:58 2004 (410ABDD6)
    10000000 1013b000 NALEXP32 NALEXP32.DLL Tue Oct 14 17:42:27 2003 (3F8C7BD3)
    4f510000 4fd21000 shell32 shell32.dll Fri Aug 20 17:01:15 2004 (412674AB)
    50d00000 50d15000 clnwin32 clnwin32.dll Tue Apr 22 10:26:41 2003 (3EA55F31)
    50d20000 50d48000 calwin32 calwin32.dll Tue Apr 22 10:28:19 2003 (3EA55F93)
    50db0000 50dd9000 ncpwin32 ncpwin32.dll Tue Apr 22 10:26:46 2003 (3EA55F36)
    50df0000 50e10000 locwin32 locwin32.dll Tue Apr 22 10:24:36 2003 (3EA55EB4)
    559e0000 55a51000 themeui themeui.dll Thu Aug 29 05:39:12 2002 (3D6DF9D0)
    589d0000 589f1000 irprops irprops.cpl Fri Nov 22 16:45:37 2002 (3DDEB391)
    5ad70000 5ada4000 uxtheme uxtheme.dll Thu Aug 29 05:39:22 2002 (3D6DF9DA)
    629c0000 629c8000 lpk lpk.dll Wed Sep 25 21:52:35 2002 (3D927673)
    6bd00000 6bd0d000 Syncor11 Syncor11.dll Wed Nov 06 18:00:36 2002 (3DC9AD24)
    70a70000 70ad9000 shlwapi shlwapi.dll Fri Aug 20 17:01:15 2004 (412674AB)
    71500000 715fd000 BROWSEUI BROWSEUI.DLL Sun Aug 22 21:34:03 2004 (4129579B)
    71700000 71849000 SHDOCVW SHDOCVW.DLL Fri Aug 27 15:58:50 2004 (412FA08A)
    71950000 71a34000 comctl32 comctl32.dll Fri Aug 20 17:01:13 2004 (412674A9)
    71aa0000 71aa8000 ws2help ws2help.dll Sat Aug 18 00:33:38 2001 (3B7DFE32)
    71ab0000 71ac4000 ws2_32 ws2_32.dll Thu Jul 10 14:19:08 2003 (3F0DBC2C)
    71ad0000 71ad8000 wsock32 wsock32.dll Sat Aug 18 00:33:37 2001 (3B7DFE31)
    71b20000 71b31000 mpr mpr.dll Sat Aug 18 00:33:37 2001 (3B7DFE31)
    71c20000 71c6e000 netapi32 netapi32.dll Tue Jun 08 17:02:21 2004 (40C6376D)
    71d40000 71d5b000 actxprxy actxprxy.dll Sat Aug 18 00:33:36 2001 (3B7DFE30)
    72a90000 72ad2000 devmgr devmgr.dll Thu Aug 29 05:40:09 2002 (3D6DFA09)
    72d10000 72d18000 msacm32 msacm32.drv Sat Aug 18 00:33:30 2001 (3B7DFE2A)
    72d20000 72d29000 wdmaud wdmaud.drv Sat Aug 18 00:33:30 2001 (3B7DFE2A)
    72fa0000 72ffa000 usp10 usp10.dll Thu Aug 29 05:40:11 2002 (3D6DFA0B)
    73000000 73023000 winspool winspool.drv Thu Aug 29 05:40:11 2002 (3D6DFA0B)
    74ad0000 74ad7000 powrprof powrprof.dll Sat Aug 18 00:33:19 2001 (3B7DFE1F)
    74ae0000 74ae7000 cfgmgr32 cfgmgr32.dll Sat Aug 18 00:33:19 2001 (3B7DFE1F)
    74af0000 74af9000 batmeter batmeter.dll Sat Aug 18 00:33:19 2001 (3B7DFE1F)
    74b00000 74b20000 stobject stobject.dll Thu Aug 29 05:40:17 2002 (3D6DFA11)
    74b30000 74b71000 webcheck webcheck.dll Thu Aug 29 05:40:18 2002 (3D6DFA12)
    74b80000 74c05000 printui printui.dll Tue Sep 24 15:25:17 2002 (3D90CA2D)
    75a70000 75b15000 userenv userenv.dll Thu Aug 29 05:40:26 2002 (3D6DFA1A)
    75cf0000 75e81000 netshell netshell.dll Mon Oct 06 20:30:24 2003 (3F821730)
    75f40000 75f5f000 apphelp apphelp.dll Thu Aug 29 05:40:27 2002 (3D6DFA1B)
    76360000 7636f000 winsta winsta.dll Thu Aug 29 05:40:29 2002 (3D6DFA1D)
    76380000 76385000 msimg32 msimg32.dll Thu Aug 29 05:40:29 2002 (3D6DFA1D)
    76600000 7661b000 cscdll cscdll.dll Sat Aug 18 00:33:09 2001 (3B7DFE15)
    76620000 7666e000 cscui cscui.dll Thu Aug 29 05:40:30 2002 (3D6DFA1E)
    76670000 76757000 setupapi setupapi.dll Thu Aug 29 05:40:30 2002 (3D6DFA1E)
    76980000 76987000 linkinfo linkinfo.dll Fri Aug 20 17:01:15 2004 (412674AB)
    76990000 769b4000 ntshrui ntshrui.dll Thu Aug 29 05:40:31 2002 (3D6DFA1F)
    76b20000 76b35000 atl atl.dll Thu Aug 29 05:40:32 2002 (3D6DFA20)
    76b40000 76b6c000 winmm winmm.dll Thu Aug 29 05:40:32 2002 (3D6DFA20)
    76c00000 76c2d000 credui credui.dll Thu Aug 29 05:40:33 2002 (3D6DFA21)
    76d30000 76d34000 wmi wmi.dll Sat Aug 18 00:33:06 2001 (3B7DFE12)
    76d60000 76d76000 iphlpapi iphlpapi.dll Thu Jul 10 14:19:06 2003 (3F0DBC2A)
    76e10000 76e35000 adsldpc adsldpc.dll Thu Aug 29 05:40:34 2002 (3D6DFA22)
    76e40000 76e6f000 activeds activeds.dll Sat Aug 18 00:33:05 2001 (3B7DFE11)
    76f50000 76f58000 wtsapi32 wtsapi32.dll Thu Aug 29 05:40:34 2002 (3D6DFA22)
    76f60000 76f8c000 wldap32 wldap32.dll Thu Aug 29 05:40:34 2002 (3D6DFA22)
    76f90000 76fa0000 secur32 secur32.dll Thu Aug 29 05:40:34 2002 (3D6DFA22)
    77050000 77115000 comres comres.dll Sat Aug 18 00:33:04 2001 (3B7DFE10)
    77120000 771ab000 oleaut32 oleaut32.dll Thu Aug 29 05:40:34 2002 (3D6DFA22)
    771b0000 772d4000 ole32 ole32.dll Fri Mar 05 20:16:11 2004 (4049346B)
    77340000 773cb000 comctl32_77340000 comctl32.dll Thu Aug 29 05:40:42 2002 (3D6DFA2A)
    77bd0000 77bd7000 midimap midimap.dll Sat Aug 18 00:33:03 2001 (3B7DFE0F)
    77be0000 77bf4000 msacm32_77be0000 msacm32.dll Sat Aug 18 00:33:03 2001 (3B7DFE0F)
    77c00000 77c07000 version version.dll Sat Aug 18 00:33:03 2001 (3B7DFE0F)
    77c10000 77c63000 msvcrt msvcrt.dll Thu Aug 29 05:40:39 2002 (3D6DFA27)
    77d40000 77dcc000 user32 user32.dll Thu Jun 17 12:58:35 2004 (40D1DBCB)
    77dd0000 77e5d000 advapi32 advapi32.dll Thu Aug 29 05:40:40 2002 (3D6DFA28)
    77e60000 77f46000 kernel32 kernel32.dll Thu Jun 17 12:58:35 2004 (40D1DBCB)
    77f50000 77ff7000 ntdll ntdll.dll Thu May 01 18:56:10 2003 (3EB1B41A)
    78000000 78087000 rpcrt4 rpcrt4.dll Fri Mar 05 20:16:11 2004 (4049346B)
    7c890000 7c911000 clbcatq clbcatq.dll Fri Mar 05 20:16:11 2004 (4049346B)
    7f000000 7f041000 gdi32 gdi32.dll Thu Jun 17 12:58:35 2004 (40D1DBCB)
    Closing open log file c:\debuglog.txt
     
    5J5J,
    #1
  2. 2005/03/31
    JoeHobart

    JoeHobart Inactive Alumni

    Joined:
    2004/05/19
    Messages:
    919
    Likes Received:
    1
    Well, this one is kind of tricky. It crashed as the result of receiving a message directed to a list view control. I dont have an SP1 machine, so i can't really unassemble to determine if its trying to send the message to a control thats been destroyed, or if someone sent a bogus message. I'd have to hand debug this to clear it up further.

    However, you are running SP1, which you need to correct.. and you have a large number of shell extensions and trayware running, any of which could be causing this problem.

    Step 1: update to sp2 and get current on windows updates
    step 2: use shellexview to disable all third party shell extensions to see if the problem dissapears
    step 3: start uninstalling the trayware
     

  3. to hide this advert.

Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.