On Sun, 14 May 2006 17:35:17 GMT,
(E-Mail Removed)rd wrote:
>Also, WHERE, exactly, would I find the error log that was created when
>autorun.exe generated errors?
I did a little digging and found a log file in a directory called
C:\Documents and Settings\All Users\Documents\DrWatson (side note:
DrWatson? I have NO idea what this software is, or ever installing
it. But the log file is massive and seems to have captured every
abnormal ending to a program going back 15 months on this computer).
The log file was called drwtsn32.log. The time stamp on it seems to
coincide exactly with when I got the error message.
The portion relevant to this adend follows, and I'd welcome an
interpretation of what it all means.
Application exception occurred:
App: (pid=1684)
When: 5/14/2006 @ 13:18:15.360
Exception number: c0000006 (in page io error)
*----> System Information <----*
Computer Name: W2000
User Name: Administrator
Number of Processors: 1
Processor Type: x86 Family 6 Model 8 Stepping 1
Windows 2000 Version: 5.0
Current Build: 2195
Service Pack: 4
Current Type: Uniprocessor Free
Registered Organization: None
Registered Owner: [my name]
*----> Task List <----*
0 Idle.exe
8 System.exe
224 SMSS.exe
252 CSRSS.exe
248 WINLOGON.exe
300 SERVICES.exe
312 LSASS.exe
464 svchost.exe
492 CCSETMGR.exe
520 CCEVTMGR.exe
648 spoolsv.exe
676 AluSchedulerSvc.exe
716 svchost.exe
744 NAVAPSVC.exe
816 regsvc.exe
844 SAVSCAN.exe
916 mstask.exe
956 stisvc.exe
992 symlcsvc.exe
1040 PQV2iSvc.exe
1060 WinMgmt.exe
1064 svchost.exe
1308 AKProg.exe
1324 hpztsb04.exe
1332 igfxtray.exe
1344 hkcmd.exe
1352 PDVDServ.exe
1396 Dit.exe
1424 UMonit2K.exe
1436 DitExp.exe
1460 jusched.exe
1468 CCAPP.exe
1488 PlaxoHelper.exe
1512 wlancfg5.exe
1540 wkcalrem.exe
1148 explorer.exe
948 firefox.exe
1684 autorun.exe
1628 DRWTSN32.exe
0 _Total.exe
(00400000 - 00424000)
(77F80000 - 77FFC000)
(7C570000 - 7C623000)
(77E10000 - 77E79000)
(77F40000 - 77F7C000)
(7CF30000 - 7D176000)
(7C2D0000 - 7C335000)
(77D30000 - 77DA8000)
(70A70000 - 70AD6000)
(78000000 - 78045000)
(71710000 - 71794000)
(77570000 - 775A0000)
(732E0000 - 73305000)
State Dump for Thread Id 0x21c
eax=00000000 ebx=7ffdf000 ecx=00010101 edx=ffffffff esi=00000000
edi=00000000
eip=00408a4c esp=0012ffc4 ebp=0012fff0 iopl=0 nv up ei pl zr
na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000246
function: <nosymbols>
00408a3e 8d42fd lea eax,[edx+0xfd]
ds:012d9ee5=????????
00408a41 5e pop esi
00408a42 5f pop edi
00408a43 5b pop ebx
00408a44 c3 ret
00408a45 8d42fc lea eax,[edx+0xfc]
ds:012d9ee5=????????
00408a48 5e pop esi
00408a49 5f pop edi
00408a4a 5b pop ebx
00408a4b c3 ret
FAULT ->00408a4c 55 push ebp
00408a4d 8bec mov ebp,esp
00408a4f 6aff push 0xff
00408a51 6860224100 push 0x412260
00408a56 68fcca4000 push 0x40cafc
00408a5b 64a100000000 mov eax,fs:[00000000]
fs:00000000=????????
00408a61 50 push eax
00408a62 64892500000000 mov fs:[00000000],esp
fs:00000000=????????
00408a69 83ec58 sub esp,0x58
00408a6c 53 push ebx
00408a6d 56 push esi
00408a6e 57 push edi
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0012FFC0 7C598989 00000000 00000000 7FFDF000 C0000006 !<nosymbols>
0012FFF0 00000000 00408A4C 00000000 000000C8 00000100
kernel32!ProcessIdToSessionId
*----> Raw Stack Dump <----*
0012ffc4 89 89 59 7c 00 00 00 00 - 00 00 00 00 00 f0 fd 7f
...Y|............
0012ffd4 06 00 00 c0 c8 ff 12 00 - 0c fc 12 00 ff ff ff ff
.................
0012ffe4 54 1f 5c 7c 18 2b 57 7c - 00 00 00 00 00 00 00 00
T.\|.+W|........
0012fff4 00 00 00 00 4c 8a 40 00 - 00 00 00 00 c8 00 00 00
.....L.@.........
00130004 00 01 00 00 ff ee ff ee - 02 00 00 00 00 00 00 00
.................
00130014 00 fe 00 00 00 00 10 00 - 00 20 00 00 00 02 00 00 .........
.......
00130024 00 20 00 00 3a 02 00 00 - ff ef fd 7f 01 00 08 06 .
...:...........
00130034 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
00130044 98 05 13 00 0f 00 00 00 - f8 ff ff ff 50 00 13 00
.............P...
00130054 50 00 13 00 40 06 13 00 - 00 00 00 00 00 00 00 00
P...@...........
00130064 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
00130074 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
00130084 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
00130094 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
001300a4 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
001300b4 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
001300c4 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
001300d4 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
001300e4 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
001300f4 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................