HOW TO DECODE DR. WATSON ERRORS

F

felsi

hi all,
Does any body help me in understanding the drwatson log
file ..
It is as follows:From one of the website i came to know
that if function is mentioned(in this case RtlRandom)we
will be able to get more information from the log.Do you
know how?





Application exception occurred:
App: (pid=180)
When: 9/18/2003 @ 11:27:34.139
Exception number: c0000025
()

*----> System Information <----*
Computer Name: C1006
User Name: A-1538
Number of Processors: 1
Processor Type: x86 Family 6 Model 8 Stepping 6
Windows Version: 4.0
Current Build: 1381
Service Pack: 6
Current Type: Uniprocessor Free
Registered Organization: IBS
Registered Owner: IBS

*----> Task List <----*
0 Idle.exe
2 System.exe
20 SMSS.exe
24 CSRSS.exe
34 WINLOGON.exe
40 SERVICES.exe
43 LSASS.exe
67 SPOOLSS.exe
74 AClient.exe
82 ibguard.exe
89 navapsvc.exe
100 NPSSVC.exe
106 RPCSS.exe
118 PSTORES.exe
121 mstask.exe
132 ibserver.exe
137 alertsvc.exe
134 NDDEAGNT.exe
163 EXPLORER.exe
167 systray.exe
171 LOADWC.exe
169 MWProEng.exe
173 navapw32.exe
187 CMD.exe
70 CMD.exe
180 tas.exe
80 DRWTSN32.exe
0 _Total.exe

(00400000 - 00400000)
(77f60000 - 77fbe000) dll\ntdll.dbg
(77f00000 - 77f5e000) dll\kernel32.dbg
(77e70000 - 77ec5000) dll\user32.dbg
(77ed0000 - 77efc000) dll\gdi32.dbg
(77dc0000 - 77dff000) dll\advapi32.dbg
(77e10000 - 77e67000) dll\rpcrt4.dbg
(65340000 - 653d2000) oleaut32.dbg
(77b20000 - 77bd7000) dll\ole32.dbg
(77720000 - 77731000) dll\mpr.dbg
(77a90000 - 77a9b000) dll\version.dbg
(77c40000 - 77d7c000) dll\shell32.dbg
(71700000 - 7178a000) COMCTL32.dbg
(779c0000 - 779c8000) dll\lz32.dbg
(77d80000 - 77db2000) dll\comdlg32.dbg
(5f300000 - 5f329000) olepro32.dbg
(48000000 - 4804d000) riched20.opt.dbg
(77630000 - 77657000) dll\crtdll.dbg
(76ab0000 - 76ab5000) dll\imm32.dbg
(777f0000 - 777fc000) dll\ntlanman.dbg
(78000000 - 78040000)
(77890000 - 778a5000) dll\netui0.dbg
(77850000 - 7788a000) dll\netui1.dbg
(77800000 - 7783a000) dll\netapi32.dbg
(77840000 - 77849000) dll\NetRap.dbg
(777e0000 - 777ed000) dll\samlib.dbg
(77bf0000 - 77bf7000) dll\rpcltc1.dbg
(4bde0000 - 4bde0000)
(4c9e0000 - 4c9e0000)
(4e8e0000 - 4e8e0000)
(1f7d0000 - 1f804000) dll\ODBC32.dbg
(1f8c0000 - 1f8c0000)

State Dump for Thread Id 0x73

eax=0012faf8 ebx=0012fb74 ecx=0012fac4 edx=ffffffff
esi=0012ffb4 edi=00000000
eip=77f892e5 esp=0012faec ebp=0012fb5c iopl=0 nv
up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b
gs=0000 efl=00000202


function: RtlRandom
77f892bc eb35 jmp RtlRandom+0x147
(77f892f3)
77f892be f6430401 test byte ptr
[ebx+0x4],0x1 ds:0104e57a=??
77f892c2 7445 jz RtlRandom+0x15d
(77f89309)
77f892c4 8d459c lea eax,[ebp-
0x64] ss:0104e562=????????
77f892c7 895da4 mov [ebp-
0x5c],ebx ss:0104e562=????????
77f892ca
c7459c250000c0
ss:0104e562=????????
mov dword ptr [ebp-
0x64],0xc0000025
77f892d1 c745a001000000 mov dword ptr [ebp-
0x60],0x1 ss:0104e562=????????
77f892d8 c745ac00000000 mov dword ptr [ebp-
0x54],0x0 ss:0104e562=????????
77f892df 50 push eax
77f892e0 e8c7fdffff call
RtlRaiseException (77f890ac)
FAULT ->77f892e5 eb0c jmp RtlRandom+0x147
(77f892f3)
77f892e7 804b0410 or byte ptr
[ebx+0x4],0x10 ds:0104e57a=??
77f892eb 3b7dfc cmp edi,[ebp-
0x4] ss:0104e562=????????
77f892ee 7303 jnb RtlRandom+0x147
(77f892f3)
77f892f0 8b7dfc mov edi,[ebp-
0x4] ss:0104e562=????????
77f892f3 8b36 mov esi,
[esi] ds:0012ffb4=0012ffe0
77f892f5 83feff cmp esi,0xff
77f892f8 0f8521ffffff jne RtlRandom+0x73
(77f8921f)
77f892fe 32c0 xor al,al
77f89300 5f pop edi
77f89301 5e pop esi
77f89302 5b pop ebx

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4
Function Name
0012fb5c 77f76406 0012fb74 0012fba4 0012fb74 0012fba4
ntdll!RtlRandom
0012fcc4 0047ca32 0eedfade 00000001 00000007 0012fcdc
ntdll!KiUserExceptionDispatcher

*----> Raw Stack Dump <----*
0012faec 00 00 00 00 a4 fc 12 00 - 74 fb 12 00 25 00 00
c0 ........t...%...
0012fafc 01 00 00 00 74 fb 12 00 - e5 92 f8 77 00 00 00
00 ....t......w....
0012fb0c 14 a9 e1 00 70 fb 12 00 - 76 39 40 00 2c a9 e1
00 ....p...v9@.,...
0012fb1c 70 fb 12 00 ca 27 40 00 - 34 a9 e1 00 19 25 40
00 p....'@.4....%@.
0012fb2c 38 c4 58 00 76 39 40 00 - 97 24 40 00 00 fc 12
00 8.X.v9@..$@.....
0012fb3c 1a 25 40 00 54 fb 12 00 - 01 00 00 00 00 c0 12
00 .%@.T...........
0012fb4c 00 00 13 00 00 00 00 00 - 00 00 00 00 e2 27 40
00 .............'@.
0012fb5c c4 fc 12 00 06 64 f7 77 - 74 fb 12 00 a4 fb 12
00 .....d.wt.......
0012fb6c 74 fb 12 00 a4 fb 12 00 - de fa ed 0e 01 00 00
00 t...............
0012fb7c 00 00 00 00 79 d4 f1 77 - 07 00 00 00 32 ca 47
00 ....y..w....2.G.
0012fb8c 30 a8 e1 00 1e 27 00 00 - 00 00 00 00 00 00 00
00 0....'..........
0012fb9c 9c fd 12 00 f8 fc 12 00 - 1f 00 01 00 00 00 00
00 ................
0012fbac 00 00 00 00 00 00 00 00 - 00 00 00 00 03 c0 00
00 ................
0012fbbc 00 00 00 00 72 12 ff ff - 00 00 ff ff ff ff ff
ff ....r...........
0012fbcc d3 2b 40 00 1b 00 3c 07 - 20 fd 12 00 23 00 ff
ff .+@...<. ...#...
0012fbdc 08 02 00 00 00 00 00 00 - 08 f5 12 00 d4 2c f9
77 .............,.w
0012fbec 60 d8 f9 77 ff ff ff ff - e8 f4 12 00 06 00 08
00 `..w............
0012fbfc 44 fa 12 00 06 00 08 02 - 08 f5 12 00 00 00 00
00 D...............
0012fc0c 00 00 00 00 34 f4 12 00 - 70 79 fa 77 00 00 00
00 ....4...py.w....
0012fc1c 00 00 80 ce 07 40 00 38 - 33 33 33 33 33 a5 06
40 [email protected]..@
Regds
fel
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top