Print Spooler Crashes on a regular basis - Windows 2003 Server


W

Wayne

All,

I am not sure if this is the right place to post this issue but I have a
windows 2003 Server SP2 set up as a print spooler and we are getting constand
instances of the print spooler crashing, we have tried moving the spool file,
increasing memory and have changed the drivers of some of the printers all to
no avail.

Could anyone please offer some further advise as this is becoming a really
frustrating issue as users are constantly excperiencing problems when
printing.

I have pasted below an extraction from the Dr Watson log file to assist -
apologies for the rather huge post. If you require a specific part of the log
file please let me know and I will post it as I am unable to see away of
attaching a file to the discussion.

Thanks you in advance for your assitance.

Wayne

***** Dr Watson File *****



*----> State Dump for Thread Id 0xb78 <----*

eax=77f6c9e8 ebx=00000000 ecx=0007fc78 edx=00000000 esi=00000000 edi=00000050
eip=7c8285ec esp=0007fbd0 ebp=0007fc38 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\ntdll.dll -
function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\ADVAPI32.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\spoolsv.exe -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\kernel32.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
0007fc38 77f65edb 00000050 0007fd04 0000021a ntdll!KiFastSystemCallRet
0007fc64 77f65f82 00000050 0007fd04 0000021a
ADVAPI32!LookupPrivilegeValueW+0x114
0007fcd8 77f51ed9 00000050 0007fd04 0000021a
ADVAPI32!LookupPrivilegeValueW+0x1bb
0007ff3c 01004019 0100d5bc 010047a2 00000001
ADVAPI32!StartServiceCtrlDispatcherW+0x8b
0007ffc0 77e6f23b 00000000 00000000 7ffd7000 spoolsv+0x4019
0007fff0 00000000 0100468c 00000000 78746341
kernel32!ProcessIdToSessionId+0x209

*----> State Dump for Thread Id 0xc00 <----*

eax=00000001 ebx=00095c90 ecx=003aff60 edx=7c8285ec esi=00000078 edi=00000000
eip=7c8285ec esp=003aff0c ebp=003aff7c iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
003aff7c 77e61c8d 00000078 ffffffff 00000000 ntdll!KiFastSystemCallRet
003aff90 010043a3 00000078 ffffffff 00095c90 kernel32!WaitForSingleObject+0x12
003affa4 77f65e91 00000001 00095c9c 00000000 spoolsv+0x43a3
003affb8 77e64829 00095c90 00000000 00000000
ADVAPI32!LookupPrivilegeValueW+0xca
003affec 00000000 77f65e70 00095c90 00000000 kernel32!GetModuleHandleA+0xdf

*----> State Dump for Thread Id 0x5a8 <----*

eax=00000000 ebx=000a5978 ecx=00095860 edx=0009585c esi=000c05a0 edi=00000000
eip=7c8285ec esp=0081fe1c ebp=0081ff84 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\RPCRT4.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
0081ff84 77c88792 0081ffac 77c8872d 000c05a0 ntdll!KiFastSystemCallRet
0081ff8c 77c8872d 000c05a0 00000000 00000000 RPCRT4!I_RpcFree+0xbd0
0081ffac 77c7b110 000957d0 0081ffec 77e64829 RPCRT4!I_RpcFree+0xb6b
0081ffb8 77e64829 000a5978 00000000 00000000
RPCRT4!NdrFullPointerInsertRefId+0x3ba
0081ffec 00000000 77c7b0f5 000a5978 00000000 kernel32!GetModuleHandleA+0xdf

*----> State Dump for Thread Id 0x744 <----*

eax=00000402 ebx=7c81a3ab ecx=00000410 edx=0001991b esi=0100d620 edi=000cc8e4
eip=7c8285ec esp=0089ff7c ebp=0089ffb8 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
0089ffb8 77e64829 00000000 00000000 00000000 ntdll!KiFastSystemCallRet
0089ffec 00000000 010045b9 00000000 00000000 kernel32!GetModuleHandleA+0xdf

*----> State Dump for Thread Id 0xa10 <----*

eax=004e2028 ebx=00a3f818 ecx=00000000 edx=00000000 esi=00a3f81c edi=7ffd7000
eip=7c8285ec esp=00a3f7cc ebp=00a3f874 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\USER32.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\SPOOLSS.DLL -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
00a3f874 7739bbd1 00000002 00a3f89c 00000000 ntdll!KiFastSystemCallRet
00a3f8d0 7739ce36 00000001 00a3f930 ffffffff
USER32!MsgWaitForMultipleObjectsEx+0xd7
00a3f8ec 740655f5 00000001 00a3f930 00000000
USER32!MsgWaitForMultipleObjects+0x1f
00a3f938 74064b43 00000000 00000000 008f1ea8
SPOOLSS!BuildOtherNamesFromMachineName+0x6a6
00a3ffb8 77e64829 008f1ea8 00000000 00000000 SPOOLSS!InitializeRouter+0x3f6
00a3ffec 00000000 01003df8 008f1ea8 00000000 kernel32!GetModuleHandleA+0xdf

*----> State Dump for Thread Id 0xbfc <----*

eax=740652c2 ebx=00a7fefc ecx=00000000 edx=00000000 esi=00a7fefc edi=7ffd7000
eip=7c8285ec esp=00a7feb0 ebp=00a7ff58 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
00a7ff58 77e62fbe 00000001 00a7ffac 00000000 ntdll!KiFastSystemCallRet
00a7ff74 7406532a 00000001 00a7ffac 00000000
kernel32!WaitForMultipleObjects+0x18
00a7ffb8 77e64829 000000d0 00000000 00000000
SPOOLSS!BuildOtherNamesFromMachineName+0x3db
00a7ffec 00000000 740652c2 00033b68 00000000 kernel32!GetModuleHandleA+0xdf

*----> State Dump for Thread Id 0xdd8 <----*

eax=724515df ebx=00000000 ecx=00000000 edx=00000000 esi=00000188 edi=00000000
eip=7c8285ec esp=00edff0c ebp=00edff7c iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\usbmon.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
00edff7c 77e61c8d 00000188 ffffffff 00000000 ntdll!KiFastSystemCallRet
00edff90 724515fa 00000188 ffffffff 00000000 kernel32!WaitForSingleObject+0x12
00edffb8 77e64829 72455068 00000000 00000000
usbmon!InitializePrintMonitor+0x11c
00edffec 00000000 724515df 72455068 00000000 kernel32!GetModuleHandleA+0xdf

*----> State Dump for Thread Id 0x9f4 <----*

eax=6720102d ebx=00f1fec0 ecx=00000000 edx=00000000 esi=00f1fec0 edi=7ffd7000
eip=7c8285ec esp=00f1fe74 ebp=00f1ff1c iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
*** WARNING: Unable to verify checksum for C:\WINDOWS\system32\HPBHealr.dll
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\HPBHealr.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
00f1ff1c 77e62fbe 00000001 00f1ffa0 00000000 ntdll!KiFastSystemCallRet
00f1ff38 67201138 00000001 00f1ffa0 00000000
kernel32!WaitForMultipleObjects+0x18
00f1ffb8 77e64829 00000000 00000000 00000000
HPBHealr!InitializePrintMonitor+0xfc
00f1ffec 00000000 6720102d 00000000 00000000 kernel32!GetModuleHandleA+0xdf

*----> State Dump for Thread Id 0x6b0 <----*

eax=724664d4 ebx=7246b050 ecx=0003b214 edx=00000000 esi=000001f0 edi=00000000
eip=7c8285ec esp=01a9ff1c ebp=01a9ff8c iopl=0 nv up ei ng nz ac po cy
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000297

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\tcpmon.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
01a9ff8c 77e61c8d 000001f0 00007530 00000000 ntdll!KiFastSystemCallRet
01a9ffa0 72461375 000001f0 00007530 00000000 kernel32!WaitForSingleObject+0x12
01a9ffb8 77e64829 7246b050 00000000 00000000 tcpmon+0x1375
01a9ffec 00000000 72461340 7246b050 00000000 kernel32!GetModuleHandleA+0xdf

*----> State Dump for Thread Id 0x534 <----*

eax=00000102 ebx=7c81a360 ecx=77e61d43 edx=7c8285ec esi=0000024c edi=00000000
eip=7c8285ec esp=01adfed8 ebp=01adff48 iopl=0 nv up ei ng nz ac po cy
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000297

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\WSNMP32.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\msvcrt.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
01adff48 77e61c8d 0000024c 000003e8 00000000 ntdll!KiFastSystemCallRet
01adff5c 71ff5bf8 0000024c 000003e8 00000000 kernel32!WaitForSingleObject+0x12
01adff84 77bcb530 00000000 00000000 00000000 WSNMP32!SnmpSetPort+0x825
01adffb8 77e64829 0003bdb0 00000000 00000000 msvcrt!endthreadex+0xa3
01adffec 00000000 77bcb4bc 0003bdb0 00000000 kernel32!GetModuleHandleA+0xdf

*----> State Dump for Thread Id 0x65c <----*

eax=000358ec ebx=00000000 ecx=00037d90 edx=00000000 esi=00000254 edi=00000000
eip=7c8285ec esp=01b1fed8 ebp=01b1ff48 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
01b1ff48 77e61c8d 00000254 ffffffff 00000000 ntdll!KiFastSystemCallRet
01b1ff5c 71ff5924 00000254 ffffffff 00000000 kernel32!WaitForSingleObject+0x12
01b1ff84 77bcb530 00000000 00000000 00000000 WSNMP32!SnmpSetPort+0x551
01b1ffb8 77e64829 0003bee0 00000000 00000000 msvcrt!endthreadex+0xa3
01b1ffec 00000000 77bcb4bc 0003bee0 00000000 kernel32!GetModuleHandleA+0xdf

*----> State Dump for Thread Id 0xab4 <----*

eax=006b0050 ebx=00000000 ecx=0000001b edx=0000001b esi=00000184 edi=00000000
eip=7c8285ec esp=01b5ff0c ebp=01b5ff7c iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
01b5ff7c 77e61c8d 00000184 ffffffff 00000000 ntdll!KiFastSystemCallRet
01b5ff90 724515fa 00000184 ffffffff 00000000 kernel32!WaitForSingleObject+0x12
01b5ffb8 77e64829 0097cc58 00000000 00000000
usbmon!InitializePrintMonitor+0x11c
01b5ffec 00000000 724515df 72455068 00000000 kernel32!GetModuleHandleA+0xdf

*----> State Dump for Thread Id 0xea4 <----*

eax=00000000 ebx=01bdfea8 ecx=01bdfef0 edx=00000008 esi=01bdfeac edi=7ffd7000
eip=7c8285ec esp=01bdfe5c ebp=01bdff04 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
01bdff04 71ff69b7 00000002 01bdff58 00000000 ntdll!KiFastSystemCallRet
01bdff84 77bcb530 71ffb5d8 00000000 00000000 WSNMP32!SnmpSetPort+0x15e4
01bdffb8 77e64829 0003c1d8 00000000 00000000 msvcrt!endthreadex+0xa3
01bdffec 00000000 77bcb4bc 0003c1d8 00000000 kernel32!GetModuleHandleA+0xdf

*----> State Dump for Thread Id 0x3ac <----*

eax=00000004 ebx=00000000 ecx=00000001 edx=00000004 esi=000003d8 edi=00000000
eip=7c8285ec esp=01e7ff08 ebp=01e7ff78 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException (7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\localspl.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
01e7ff78 77e61c8d 000003d8 ffffffff 00000000 ntdll!KiFastSystemCallRet
01e7ff8c 7616ba7c 000003d8 ffffffff 00000000 kernel32!WaitForSingleObject+0x12
01e7ffb8 77e64829 00975968 00000000 00000000
localspl!SplLogWmiTraceEventExternal+0x40b0
01e7ffec 00000000 7616b9f0 00975968 00000000 kernel32!GetModuleHandleA+0xdf
 
Ad

Advertisements

A

Alan Morris [MSFT]

This is a fine place to start. There is also a Server General newsgroup.

In the watson log is there a FAULT statement?

If you are using an HP driver that uses this module (hpzui4wm) make sure you
have the latest driver for the device.



--
Alan Morris
Windows Printing Team
Search the Microsoft Knowledge Base here:
http://support.microsoft.com/search/?adv=1

This posting is provided "AS IS" with no warranties, and confers no rights.

Wayne said:
All,

I am not sure if this is the right place to post this issue but I have a
windows 2003 Server SP2 set up as a print spooler and we are getting
constand
instances of the print spooler crashing, we have tried moving the spool
file,
increasing memory and have changed the drivers of some of the printers all
to
no avail.

Could anyone please offer some further advise as this is becoming a really
frustrating issue as users are constantly excperiencing problems when
printing.

I have pasted below an extraction from the Dr Watson log file to assist -
apologies for the rather huge post. If you require a specific part of the
log
file please let me know and I will post it as I am unable to see away of
attaching a file to the discussion.

Thanks you in advance for your assitance.

Wayne

***** Dr Watson File *****



*----> State Dump for Thread Id 0xb78 <----*

eax=77f6c9e8 ebx=00000000 ecx=0007fc78 edx=00000000 esi=00000000
edi=00000050
eip=7c8285ec esp=0007fbd0 ebp=0007fc38 iopl=0 nv up ei pl zr na po
nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246

*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:\WINDOWS\system32\ntdll.dll -
function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException
(7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:\WINDOWS\system32\ADVAPI32.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:\WINDOWS\system32\spoolsv.exe -
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:\WINDOWS\system32\kernel32.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
0007fc38 77f65edb 00000050 0007fd04 0000021a ntdll!KiFastSystemCallRet
0007fc64 77f65f82 00000050 0007fd04 0000021a
ADVAPI32!LookupPrivilegeValueW+0x114
0007fcd8 77f51ed9 00000050 0007fd04 0000021a
ADVAPI32!LookupPrivilegeValueW+0x1bb
0007ff3c 01004019 0100d5bc 010047a2 00000001
ADVAPI32!StartServiceCtrlDispatcherW+0x8b
0007ffc0 77e6f23b 00000000 00000000 7ffd7000 spoolsv+0x4019
0007fff0 00000000 0100468c 00000000 78746341
kernel32!ProcessIdToSessionId+0x209

*----> State Dump for Thread Id 0xc00 <----*

eax=00000001 ebx=00095c90 ecx=003aff60 edx=7c8285ec esi=00000078
edi=00000000
eip=7c8285ec esp=003aff0c ebp=003aff7c iopl=0 nv up ei pl zr na po
nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException
(7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
003aff7c 77e61c8d 00000078 ffffffff 00000000 ntdll!KiFastSystemCallRet
003aff90 010043a3 00000078 ffffffff 00095c90
kernel32!WaitForSingleObject+0x12
003affa4 77f65e91 00000001 00095c9c 00000000 spoolsv+0x43a3
003affb8 77e64829 00095c90 00000000 00000000
ADVAPI32!LookupPrivilegeValueW+0xca
003affec 00000000 77f65e70 00095c90 00000000
kernel32!GetModuleHandleA+0xdf

*----> State Dump for Thread Id 0x5a8 <----*

eax=00000000 ebx=000a5978 ecx=00095860 edx=0009585c esi=000c05a0
edi=00000000
eip=7c8285ec esp=0081fe1c ebp=0081ff84 iopl=0 nv up ei pl zr na po
nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException
(7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:\WINDOWS\system32\RPCRT4.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
0081ff84 77c88792 0081ffac 77c8872d 000c05a0 ntdll!KiFastSystemCallRet
0081ff8c 77c8872d 000c05a0 00000000 00000000 RPCRT4!I_RpcFree+0xbd0
0081ffac 77c7b110 000957d0 0081ffec 77e64829 RPCRT4!I_RpcFree+0xb6b
0081ffb8 77e64829 000a5978 00000000 00000000
RPCRT4!NdrFullPointerInsertRefId+0x3ba
0081ffec 00000000 77c7b0f5 000a5978 00000000
kernel32!GetModuleHandleA+0xdf

*----> State Dump for Thread Id 0x744 <----*

eax=00000402 ebx=7c81a3ab ecx=00000410 edx=0001991b esi=0100d620
edi=000cc8e4
eip=7c8285ec esp=0089ff7c ebp=0089ffb8 iopl=0 nv up ei pl zr na po
nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException
(7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
0089ffb8 77e64829 00000000 00000000 00000000 ntdll!KiFastSystemCallRet
0089ffec 00000000 010045b9 00000000 00000000
kernel32!GetModuleHandleA+0xdf

*----> State Dump for Thread Id 0xa10 <----*

eax=004e2028 ebx=00a3f818 ecx=00000000 edx=00000000 esi=00a3f81c
edi=7ffd7000
eip=7c8285ec esp=00a3f7cc ebp=00a3f874 iopl=0 nv up ei pl zr na po
nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException
(7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:\WINDOWS\system32\USER32.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:\WINDOWS\system32\SPOOLSS.DLL -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
00a3f874 7739bbd1 00000002 00a3f89c 00000000 ntdll!KiFastSystemCallRet
00a3f8d0 7739ce36 00000001 00a3f930 ffffffff
USER32!MsgWaitForMultipleObjectsEx+0xd7
00a3f8ec 740655f5 00000001 00a3f930 00000000
USER32!MsgWaitForMultipleObjects+0x1f
00a3f938 74064b43 00000000 00000000 008f1ea8
SPOOLSS!BuildOtherNamesFromMachineName+0x6a6
00a3ffb8 77e64829 008f1ea8 00000000 00000000
SPOOLSS!InitializeRouter+0x3f6
00a3ffec 00000000 01003df8 008f1ea8 00000000
kernel32!GetModuleHandleA+0xdf

*----> State Dump for Thread Id 0xbfc <----*

eax=740652c2 ebx=00a7fefc ecx=00000000 edx=00000000 esi=00a7fefc
edi=7ffd7000
eip=7c8285ec esp=00a7feb0 ebp=00a7ff58 iopl=0 nv up ei pl zr na po
nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException
(7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
00a7ff58 77e62fbe 00000001 00a7ffac 00000000 ntdll!KiFastSystemCallRet
00a7ff74 7406532a 00000001 00a7ffac 00000000
kernel32!WaitForMultipleObjects+0x18
00a7ffb8 77e64829 000000d0 00000000 00000000
SPOOLSS!BuildOtherNamesFromMachineName+0x3db
00a7ffec 00000000 740652c2 00033b68 00000000
kernel32!GetModuleHandleA+0xdf

*----> State Dump for Thread Id 0xdd8 <----*

eax=724515df ebx=00000000 ecx=00000000 edx=00000000 esi=00000188
edi=00000000
eip=7c8285ec esp=00edff0c ebp=00edff7c iopl=0 nv up ei pl zr na po
nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException
(7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:\WINDOWS\system32\usbmon.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
00edff7c 77e61c8d 00000188 ffffffff 00000000 ntdll!KiFastSystemCallRet
00edff90 724515fa 00000188 ffffffff 00000000
kernel32!WaitForSingleObject+0x12
00edffb8 77e64829 72455068 00000000 00000000
usbmon!InitializePrintMonitor+0x11c
00edffec 00000000 724515df 72455068 00000000
kernel32!GetModuleHandleA+0xdf

*----> State Dump for Thread Id 0x9f4 <----*

eax=6720102d ebx=00f1fec0 ecx=00000000 edx=00000000 esi=00f1fec0
edi=7ffd7000
eip=7c8285ec esp=00f1fe74 ebp=00f1ff1c iopl=0 nv up ei pl zr na po
nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException
(7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
*** WARNING: Unable to verify checksum for
C:\WINDOWS\system32\HPBHealr.dll
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:\WINDOWS\system32\HPBHealr.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
00f1ff1c 77e62fbe 00000001 00f1ffa0 00000000 ntdll!KiFastSystemCallRet
00f1ff38 67201138 00000001 00f1ffa0 00000000
kernel32!WaitForMultipleObjects+0x18
00f1ffb8 77e64829 00000000 00000000 00000000
HPBHealr!InitializePrintMonitor+0xfc
00f1ffec 00000000 6720102d 00000000 00000000
kernel32!GetModuleHandleA+0xdf

*----> State Dump for Thread Id 0x6b0 <----*

eax=724664d4 ebx=7246b050 ecx=0003b214 edx=00000000 esi=000001f0
edi=00000000
eip=7c8285ec esp=01a9ff1c ebp=01a9ff8c iopl=0 nv up ei ng nz ac po
cy
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000297

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException
(7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:\WINDOWS\system32\tcpmon.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
01a9ff8c 77e61c8d 000001f0 00007530 00000000 ntdll!KiFastSystemCallRet
01a9ffa0 72461375 000001f0 00007530 00000000
kernel32!WaitForSingleObject+0x12
01a9ffb8 77e64829 7246b050 00000000 00000000 tcpmon+0x1375
01a9ffec 00000000 72461340 7246b050 00000000
kernel32!GetModuleHandleA+0xdf

*----> State Dump for Thread Id 0x534 <----*

eax=00000102 ebx=7c81a360 ecx=77e61d43 edx=7c8285ec esi=0000024c
edi=00000000
eip=7c8285ec esp=01adfed8 ebp=01adff48 iopl=0 nv up ei ng nz ac po
cy
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000297

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException
(7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:\WINDOWS\system32\WSNMP32.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:\WINDOWS\system32\msvcrt.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
01adff48 77e61c8d 0000024c 000003e8 00000000 ntdll!KiFastSystemCallRet
01adff5c 71ff5bf8 0000024c 000003e8 00000000
kernel32!WaitForSingleObject+0x12
01adff84 77bcb530 00000000 00000000 00000000 WSNMP32!SnmpSetPort+0x825
01adffb8 77e64829 0003bdb0 00000000 00000000 msvcrt!endthreadex+0xa3
01adffec 00000000 77bcb4bc 0003bdb0 00000000
kernel32!GetModuleHandleA+0xdf

*----> State Dump for Thread Id 0x65c <----*

eax=000358ec ebx=00000000 ecx=00037d90 edx=00000000 esi=00000254
edi=00000000
eip=7c8285ec esp=01b1fed8 ebp=01b1ff48 iopl=0 nv up ei pl zr na po
nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException
(7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
01b1ff48 77e61c8d 00000254 ffffffff 00000000 ntdll!KiFastSystemCallRet
01b1ff5c 71ff5924 00000254 ffffffff 00000000
kernel32!WaitForSingleObject+0x12
01b1ff84 77bcb530 00000000 00000000 00000000 WSNMP32!SnmpSetPort+0x551
01b1ffb8 77e64829 0003bee0 00000000 00000000 msvcrt!endthreadex+0xa3
01b1ffec 00000000 77bcb4bc 0003bee0 00000000
kernel32!GetModuleHandleA+0xdf

*----> State Dump for Thread Id 0xab4 <----*

eax=006b0050 ebx=00000000 ecx=0000001b edx=0000001b esi=00000184
edi=00000000
eip=7c8285ec esp=01b5ff0c ebp=01b5ff7c iopl=0 nv up ei pl zr na po
nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException
(7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
01b5ff7c 77e61c8d 00000184 ffffffff 00000000 ntdll!KiFastSystemCallRet
01b5ff90 724515fa 00000184 ffffffff 00000000
kernel32!WaitForSingleObject+0x12
01b5ffb8 77e64829 0097cc58 00000000 00000000
usbmon!InitializePrintMonitor+0x11c
01b5ffec 00000000 724515df 72455068 00000000
kernel32!GetModuleHandleA+0xdf

*----> State Dump for Thread Id 0xea4 <----*

eax=00000000 ebx=01bdfea8 ecx=01bdfef0 edx=00000008 esi=01bdfeac
edi=7ffd7000
eip=7c8285ec esp=01bdfe5c ebp=01bdff04 iopl=0 nv up ei pl zr na po
nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException
(7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
01bdff04 71ff69b7 00000002 01bdff58 00000000 ntdll!KiFastSystemCallRet
01bdff84 77bcb530 71ffb5d8 00000000 00000000 WSNMP32!SnmpSetPort+0x15e4
01bdffb8 77e64829 0003c1d8 00000000 00000000 msvcrt!endthreadex+0xa3
01bdffec 00000000 77bcb4bc 0003c1d8 00000000
kernel32!GetModuleHandleA+0xdf

*----> State Dump for Thread Id 0x3ac <----*

eax=00000004 ebx=00000000 ecx=00000001 edx=00000004 esi=000003d8
edi=00000000
eip=7c8285ec esp=01e7ff08 ebp=01e7ff78 iopl=0 nv up ei pl zr na po
nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException
(7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:\WINDOWS\system32\localspl.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
01e7ff78 77e61c8d 000003d8 ffffffff 00000000 ntdll!KiFastSystemCallRet
01e7ff8c 7616ba7c 000003d8 ffffffff 00000000
kernel32!WaitForSingleObject+0x12
01e7ffb8 77e64829 00975968 00000000 00000000
localspl!SplLogWmiTraceEventExternal+0x40b0
01e7ffec 00000000 7616b9f0 00975968 00000000
kernel32!GetModuleHandleA+0xdf
 
W

Wayne

Alan,

Thanks for replying I have searched the log file and am unable to find
"hpzui4wm" anywhere in the file however the "Fault" statement is as below:-

function: ntdll!RtlCreateUnicodeStringFromAsciiz
7c819737 ff7630 push dword ptr [esi+0x30]
7c81973a e8cc110000 call ntdll!aulldiv (7c81a90b)
7c81973f 894618 mov [esi+0x18],eax
7c819742 89561c mov [esi+0x1c],edx
7c819745 895e3c mov [esi+0x3c],ebx
7c819748 895e30 mov [esi+0x30],ebx
7c81974b 895e34 mov [esi+0x34],ebx
7c81974e e989110100 jmp ntdll!wcslen+0x35e (7c82a8dc)
7c819753 8b8f80050000 mov ecx,[edi+0x580]
7c819759 e9f4060100 jmp ntdll!RtlFreeHeap+0x3b (7c829e52)
FAULT ->7c81975e 807affff cmp byte ptr [edx-0x1],0xff
ds:0023:00000033=??
7c819762 0f82f5060100 jb ntdll!RtlFreeHeap+0x46 (7c829e5d)
7c819768 8b5510 mov edx,[ebp+0x10]
7c81976b e815020000 call
ntdll!RtlCreateUnicodeStringFromAsciiz+0x2cb (7c819985)
7c819770 84c0 test al,al
7c819772 0f84c4750200 je ntdll!mbstowcs+0x7f9 (7c840d3c)
7c819778 f605f002fe7f02 test byte ptr [SharedUserData+0x2f0
(7ffe02f0)],0x2
7c81977f 0f84cd070100 je ntdll!RtlFreeHeap+0x13b (7c829f52)
7c819785 e9dcae0200 jmp ntdll!RtlIpv4StringToAddressExW+0x2ce8
(7c844666)
7c81978a 8bbb80050000 mov edi,[ebx+0x580]
7c819790 e992080100 jmp ntdll!RtlAllocateHeap+0x51
(7c82a027)

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\spool\PRTPROCS\W32X86\hpprn03.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
0297e2d0 7406280c 008f0000 00000000 00000034
ntdll!RtlCreateUnicodeStringFromAsciiz+0xa4
0297e2e4 740627dd 00000034 0297eea4 01cf8247 SPOOLSS!DllFreeSplMem+0x3c
0297e2f0 01cf8247 00000034 00920ef0 009e1190 SPOOLSS!DllFreeSplMem+0xd
0297eea4 01cf269a 00912260 0297f304 7615a229
hpprn03!ControlPrintProcessor+0x5af5
0297f948 7615aadd 00920ef0 0297f970 00000000
hpprn03!PrintDocumentOnPrintProcessor+0x3a
0297ffb8 77e64829 00920ef0 00000000 00000000 localspl!SplDeleteSpooler+0x1484
0297ffec 00000000 7615a83a 00920ef0 00000000 kernel32!GetModuleHandleA+0xdf

*----> Raw Stack Dump <----*



Alan Morris said:
This is a fine place to start. There is also a Server General newsgroup.

In the watson log is there a FAULT statement?

If you are using an HP driver that uses this module (hpzui4wm) make sure you
have the latest driver for the device.



--
Alan Morris
Windows Printing Team
Search the Microsoft Knowledge Base here:
http://support.microsoft.com/search/?adv=1

This posting is provided "AS IS" with no warranties, and confers no rights.

Wayne said:
All,

I am not sure if this is the right place to post this issue but I have a
windows 2003 Server SP2 set up as a print spooler and we are getting
constand
instances of the print spooler crashing, we have tried moving the spool
file,
increasing memory and have changed the drivers of some of the printers all
to
no avail.

Could anyone please offer some further advise as this is becoming a really
frustrating issue as users are constantly excperiencing problems when
printing.

I have pasted below an extraction from the Dr Watson log file to assist -
apologies for the rather huge post. If you require a specific part of the
log
file please let me know and I will post it as I am unable to see away of
attaching a file to the discussion.

Thanks you in advance for your assitance.

Wayne

***** Dr Watson File *****



*----> State Dump for Thread Id 0xb78 <----*

eax=77f6c9e8 ebx=00000000 ecx=0007fc78 edx=00000000 esi=00000000
edi=00000050
eip=7c8285ec esp=0007fbd0 ebp=0007fc38 iopl=0 nv up ei pl zr na po
nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246

*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:\WINDOWS\system32\ntdll.dll -
function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException
(7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:\WINDOWS\system32\ADVAPI32.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:\WINDOWS\system32\spoolsv.exe -
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:\WINDOWS\system32\kernel32.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
0007fc38 77f65edb 00000050 0007fd04 0000021a ntdll!KiFastSystemCallRet
0007fc64 77f65f82 00000050 0007fd04 0000021a
ADVAPI32!LookupPrivilegeValueW+0x114
0007fcd8 77f51ed9 00000050 0007fd04 0000021a
ADVAPI32!LookupPrivilegeValueW+0x1bb
0007ff3c 01004019 0100d5bc 010047a2 00000001
ADVAPI32!StartServiceCtrlDispatcherW+0x8b
0007ffc0 77e6f23b 00000000 00000000 7ffd7000 spoolsv+0x4019
0007fff0 00000000 0100468c 00000000 78746341
kernel32!ProcessIdToSessionId+0x209

*----> State Dump for Thread Id 0xc00 <----*

eax=00000001 ebx=00095c90 ecx=003aff60 edx=7c8285ec esi=00000078
edi=00000000
eip=7c8285ec esp=003aff0c ebp=003aff7c iopl=0 nv up ei pl zr na po
nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException
(7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
003aff7c 77e61c8d 00000078 ffffffff 00000000 ntdll!KiFastSystemCallRet
003aff90 010043a3 00000078 ffffffff 00095c90
kernel32!WaitForSingleObject+0x12
003affa4 77f65e91 00000001 00095c9c 00000000 spoolsv+0x43a3
003affb8 77e64829 00095c90 00000000 00000000
ADVAPI32!LookupPrivilegeValueW+0xca
003affec 00000000 77f65e70 00095c90 00000000
kernel32!GetModuleHandleA+0xdf

*----> State Dump for Thread Id 0x5a8 <----*

eax=00000000 ebx=000a5978 ecx=00095860 edx=0009585c esi=000c05a0
edi=00000000
eip=7c8285ec esp=0081fe1c ebp=0081ff84 iopl=0 nv up ei pl zr na po
nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException
(7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:\WINDOWS\system32\RPCRT4.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
0081ff84 77c88792 0081ffac 77c8872d 000c05a0 ntdll!KiFastSystemCallRet
0081ff8c 77c8872d 000c05a0 00000000 00000000 RPCRT4!I_RpcFree+0xbd0
0081ffac 77c7b110 000957d0 0081ffec 77e64829 RPCRT4!I_RpcFree+0xb6b
0081ffb8 77e64829 000a5978 00000000 00000000
RPCRT4!NdrFullPointerInsertRefId+0x3ba
0081ffec 00000000 77c7b0f5 000a5978 00000000
kernel32!GetModuleHandleA+0xdf

*----> State Dump for Thread Id 0x744 <----*

eax=00000402 ebx=7c81a3ab ecx=00000410 edx=0001991b esi=0100d620
edi=000cc8e4
eip=7c8285ec esp=0089ff7c ebp=0089ffb8 iopl=0 nv up ei pl zr na po
nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException
(7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
0089ffb8 77e64829 00000000 00000000 00000000 ntdll!KiFastSystemCallRet
0089ffec 00000000 010045b9 00000000 00000000
kernel32!GetModuleHandleA+0xdf

*----> State Dump for Thread Id 0xa10 <----*

eax=004e2028 ebx=00a3f818 ecx=00000000 edx=00000000 esi=00a3f81c
edi=7ffd7000
eip=7c8285ec esp=00a3f7cc ebp=00a3f874 iopl=0 nv up ei pl zr na po
nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException
(7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:\WINDOWS\system32\USER32.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:\WINDOWS\system32\SPOOLSS.DLL -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
00a3f874 7739bbd1 00000002 00a3f89c 00000000 ntdll!KiFastSystemCallRet
00a3f8d0 7739ce36 00000001 00a3f930 ffffffff
USER32!MsgWaitForMultipleObjectsEx+0xd7
00a3f8ec 740655f5 00000001 00a3f930 00000000
USER32!MsgWaitForMultipleObjects+0x1f
00a3f938 74064b43 00000000 00000000 008f1ea8
SPOOLSS!BuildOtherNamesFromMachineName+0x6a6
00a3ffb8 77e64829 008f1ea8 00000000 00000000
SPOOLSS!InitializeRouter+0x3f6
 
A

Alan Morris [MSFT]

thanks you found the file that's corrupting the spooler process
hpprn03.dll

you can use the prndrvr.vbs script to list any print driver using this file.


prndrvr -l

prndrvr -l |findstr /I /C:"Driver name" /C:hpprn03.dll

--
Alan Morris
Windows Printing Team
Search the Microsoft Knowledge Base here:
http://support.microsoft.com/search/?adv=1

This posting is provided "AS IS" with no warranties, and confers no rights.

Wayne said:
Alan,

Thanks for replying I have searched the log file and am unable to find
"hpzui4wm" anywhere in the file however the "Fault" statement is as
below:-

function: ntdll!RtlCreateUnicodeStringFromAsciiz
7c819737 ff7630 push dword ptr [esi+0x30]
7c81973a e8cc110000 call ntdll!aulldiv (7c81a90b)
7c81973f 894618 mov [esi+0x18],eax
7c819742 89561c mov [esi+0x1c],edx
7c819745 895e3c mov [esi+0x3c],ebx
7c819748 895e30 mov [esi+0x30],ebx
7c81974b 895e34 mov [esi+0x34],ebx
7c81974e e989110100 jmp ntdll!wcslen+0x35e (7c82a8dc)
7c819753 8b8f80050000 mov ecx,[edi+0x580]
7c819759 e9f4060100 jmp ntdll!RtlFreeHeap+0x3b (7c829e52)
FAULT ->7c81975e 807affff cmp byte ptr [edx-0x1],0xff
ds:0023:00000033=??
7c819762 0f82f5060100 jb ntdll!RtlFreeHeap+0x46 (7c829e5d)
7c819768 8b5510 mov edx,[ebp+0x10]
7c81976b e815020000 call
ntdll!RtlCreateUnicodeStringFromAsciiz+0x2cb (7c819985)
7c819770 84c0 test al,al
7c819772 0f84c4750200 je ntdll!mbstowcs+0x7f9 (7c840d3c)
7c819778 f605f002fe7f02 test byte ptr [SharedUserData+0x2f0
(7ffe02f0)],0x2
7c81977f 0f84cd070100 je ntdll!RtlFreeHeap+0x13b
(7c829f52)
7c819785 e9dcae0200 jmp ntdll!RtlIpv4StringToAddressExW+0x2ce8
(7c844666)
7c81978a 8bbb80050000 mov edi,[ebx+0x580]
7c819790 e992080100 jmp ntdll!RtlAllocateHeap+0x51
(7c82a027)

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:\WINDOWS\system32\spool\PRTPROCS\W32X86\hpprn03.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
0297e2d0 7406280c 008f0000 00000000 00000034
ntdll!RtlCreateUnicodeStringFromAsciiz+0xa4
0297e2e4 740627dd 00000034 0297eea4 01cf8247 SPOOLSS!DllFreeSplMem+0x3c
0297e2f0 01cf8247 00000034 00920ef0 009e1190 SPOOLSS!DllFreeSplMem+0xd
0297eea4 01cf269a 00912260 0297f304 7615a229
hpprn03!ControlPrintProcessor+0x5af5
0297f948 7615aadd 00920ef0 0297f970 00000000
hpprn03!PrintDocumentOnPrintProcessor+0x3a
0297ffb8 77e64829 00920ef0 00000000 00000000
localspl!SplDeleteSpooler+0x1484
0297ffec 00000000 7615a83a 00920ef0 00000000
kernel32!GetModuleHandleA+0xdf

*----> Raw Stack Dump <----*



Alan Morris said:
This is a fine place to start. There is also a Server General newsgroup.

In the watson log is there a FAULT statement?

If you are using an HP driver that uses this module (hpzui4wm) make sure
you
have the latest driver for the device.



--
Alan Morris
Windows Printing Team
Search the Microsoft Knowledge Base here:
http://support.microsoft.com/search/?adv=1

This posting is provided "AS IS" with no warranties, and confers no
rights.

Wayne said:
All,

I am not sure if this is the right place to post this issue but I have
a
windows 2003 Server SP2 set up as a print spooler and we are getting
constand
instances of the print spooler crashing, we have tried moving the spool
file,
increasing memory and have changed the drivers of some of the printers
all
to
no avail.

Could anyone please offer some further advise as this is becoming a
really
frustrating issue as users are constantly excperiencing problems when
printing.

I have pasted below an extraction from the Dr Watson log file to
assist -
apologies for the rather huge post. If you require a specific part of
the
log
file please let me know and I will post it as I am unable to see away
of
attaching a file to the discussion.

Thanks you in advance for your assitance.

Wayne

***** Dr Watson File *****



*----> State Dump for Thread Id 0xb78 <----*

eax=77f6c9e8 ebx=00000000 ecx=0007fc78 edx=00000000 esi=00000000
edi=00000050
eip=7c8285ec esp=0007fbd0 ebp=0007fc38 iopl=0 nv up ei pl zr na
po
nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246

*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:\WINDOWS\system32\ntdll.dll -
function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException
(7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:\WINDOWS\system32\ADVAPI32.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:\WINDOWS\system32\spoolsv.exe -
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:\WINDOWS\system32\kernel32.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may
be
wrong.
0007fc38 77f65edb 00000050 0007fd04 0000021a ntdll!KiFastSystemCallRet
0007fc64 77f65f82 00000050 0007fd04 0000021a
ADVAPI32!LookupPrivilegeValueW+0x114
0007fcd8 77f51ed9 00000050 0007fd04 0000021a
ADVAPI32!LookupPrivilegeValueW+0x1bb
0007ff3c 01004019 0100d5bc 010047a2 00000001
ADVAPI32!StartServiceCtrlDispatcherW+0x8b
0007ffc0 77e6f23b 00000000 00000000 7ffd7000 spoolsv+0x4019
0007fff0 00000000 0100468c 00000000 78746341
kernel32!ProcessIdToSessionId+0x209

*----> State Dump for Thread Id 0xc00 <----*

eax=00000001 ebx=00095c90 ecx=003aff60 edx=7c8285ec esi=00000078
edi=00000000
eip=7c8285ec esp=003aff0c ebp=003aff7c iopl=0 nv up ei pl zr na
po
nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException
(7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may
be
wrong.
003aff7c 77e61c8d 00000078 ffffffff 00000000 ntdll!KiFastSystemCallRet
003aff90 010043a3 00000078 ffffffff 00095c90
kernel32!WaitForSingleObject+0x12
003affa4 77f65e91 00000001 00095c9c 00000000 spoolsv+0x43a3
003affb8 77e64829 00095c90 00000000 00000000
ADVAPI32!LookupPrivilegeValueW+0xca
003affec 00000000 77f65e70 00095c90 00000000
kernel32!GetModuleHandleA+0xdf

*----> State Dump for Thread Id 0x5a8 <----*

eax=00000000 ebx=000a5978 ecx=00095860 edx=0009585c esi=000c05a0
edi=00000000
eip=7c8285ec esp=0081fe1c ebp=0081ff84 iopl=0 nv up ei pl zr na
po
nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException
(7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:\WINDOWS\system32\RPCRT4.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may
be
wrong.
0081ff84 77c88792 0081ffac 77c8872d 000c05a0 ntdll!KiFastSystemCallRet
0081ff8c 77c8872d 000c05a0 00000000 00000000 RPCRT4!I_RpcFree+0xbd0
0081ffac 77c7b110 000957d0 0081ffec 77e64829 RPCRT4!I_RpcFree+0xb6b
0081ffb8 77e64829 000a5978 00000000 00000000
RPCRT4!NdrFullPointerInsertRefId+0x3ba
0081ffec 00000000 77c7b0f5 000a5978 00000000
kernel32!GetModuleHandleA+0xdf

*----> State Dump for Thread Id 0x744 <----*

eax=00000402 ebx=7c81a3ab ecx=00000410 edx=0001991b esi=0100d620
edi=000cc8e4
eip=7c8285ec esp=0089ff7c ebp=0089ffb8 iopl=0 nv up ei pl zr na
po
nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException
(7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may
be
wrong.
0089ffb8 77e64829 00000000 00000000 00000000 ntdll!KiFastSystemCallRet
0089ffec 00000000 010045b9 00000000 00000000
kernel32!GetModuleHandleA+0xdf

*----> State Dump for Thread Id 0xa10 <----*

eax=004e2028 ebx=00a3f818 ecx=00000000 edx=00000000 esi=00a3f81c
edi=7ffd7000
eip=7c8285ec esp=00a3f7cc ebp=00a3f874 iopl=0 nv up ei pl zr na
po
nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException
(7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:\WINDOWS\system32\USER32.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:\WINDOWS\system32\SPOOLSS.DLL -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may
be
wrong.
00a3f874 7739bbd1 00000002 00a3f89c 00000000 ntdll!KiFastSystemCallRet
00a3f8d0 7739ce36 00000001 00a3f930 ffffffff
USER32!MsgWaitForMultipleObjectsEx+0xd7
00a3f8ec 740655f5 00000001 00a3f930 00000000
USER32!MsgWaitForMultipleObjects+0x1f
00a3f938 74064b43 00000000 00000000 008f1ea8
SPOOLSS!BuildOtherNamesFromMachineName+0x6a6
00a3ffb8 77e64829 008f1ea8 00000000 00000000
SPOOLSS!InitializeRouter+0x3f6
 
Ad

Advertisements

W

Wayne

Alan,

Thanks for the advice unfortunately being in the UK our replies might be a
bit slow to you and also came in this morning to find the server had crashed,
so as soon as we get it back up and running we will look into the dll you
mentioned.

I will update the post once we have had a chance to look into it butonce
again thanks for hte advice

Wayne

Alan Morris said:
thanks you found the file that's corrupting the spooler process
hpprn03.dll

you can use the prndrvr.vbs script to list any print driver using this file.


prndrvr -l

prndrvr -l |findstr /I /C:"Driver name" /C:hpprn03.dll

--
Alan Morris
Windows Printing Team
Search the Microsoft Knowledge Base here:
http://support.microsoft.com/search/?adv=1

This posting is provided "AS IS" with no warranties, and confers no rights.

Wayne said:
Alan,

Thanks for replying I have searched the log file and am unable to find
"hpzui4wm" anywhere in the file however the "Fault" statement is as
below:-

function: ntdll!RtlCreateUnicodeStringFromAsciiz
7c819737 ff7630 push dword ptr [esi+0x30]
7c81973a e8cc110000 call ntdll!aulldiv (7c81a90b)
7c81973f 894618 mov [esi+0x18],eax
7c819742 89561c mov [esi+0x1c],edx
7c819745 895e3c mov [esi+0x3c],ebx
7c819748 895e30 mov [esi+0x30],ebx
7c81974b 895e34 mov [esi+0x34],ebx
7c81974e e989110100 jmp ntdll!wcslen+0x35e (7c82a8dc)
7c819753 8b8f80050000 mov ecx,[edi+0x580]
7c819759 e9f4060100 jmp ntdll!RtlFreeHeap+0x3b (7c829e52)
FAULT ->7c81975e 807affff cmp byte ptr [edx-0x1],0xff
ds:0023:00000033=??
7c819762 0f82f5060100 jb ntdll!RtlFreeHeap+0x46 (7c829e5d)
7c819768 8b5510 mov edx,[ebp+0x10]
7c81976b e815020000 call
ntdll!RtlCreateUnicodeStringFromAsciiz+0x2cb (7c819985)
7c819770 84c0 test al,al
7c819772 0f84c4750200 je ntdll!mbstowcs+0x7f9 (7c840d3c)
7c819778 f605f002fe7f02 test byte ptr [SharedUserData+0x2f0
(7ffe02f0)],0x2
7c81977f 0f84cd070100 je ntdll!RtlFreeHeap+0x13b
(7c829f52)
7c819785 e9dcae0200 jmp ntdll!RtlIpv4StringToAddressExW+0x2ce8
(7c844666)
7c81978a 8bbb80050000 mov edi,[ebx+0x580]
7c819790 e992080100 jmp ntdll!RtlAllocateHeap+0x51
(7c82a027)

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:\WINDOWS\system32\spool\PRTPROCS\W32X86\hpprn03.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may be
wrong.
0297e2d0 7406280c 008f0000 00000000 00000034
ntdll!RtlCreateUnicodeStringFromAsciiz+0xa4
0297e2e4 740627dd 00000034 0297eea4 01cf8247 SPOOLSS!DllFreeSplMem+0x3c
0297e2f0 01cf8247 00000034 00920ef0 009e1190 SPOOLSS!DllFreeSplMem+0xd
0297eea4 01cf269a 00912260 0297f304 7615a229
hpprn03!ControlPrintProcessor+0x5af5
0297f948 7615aadd 00920ef0 0297f970 00000000
hpprn03!PrintDocumentOnPrintProcessor+0x3a
0297ffb8 77e64829 00920ef0 00000000 00000000
localspl!SplDeleteSpooler+0x1484
0297ffec 00000000 7615a83a 00920ef0 00000000
kernel32!GetModuleHandleA+0xdf

*----> Raw Stack Dump <----*



Alan Morris said:
This is a fine place to start. There is also a Server General newsgroup.

In the watson log is there a FAULT statement?

If you are using an HP driver that uses this module (hpzui4wm) make sure
you
have the latest driver for the device.



--
Alan Morris
Windows Printing Team
Search the Microsoft Knowledge Base here:
http://support.microsoft.com/search/?adv=1

This posting is provided "AS IS" with no warranties, and confers no
rights.

All,

I am not sure if this is the right place to post this issue but I have
a
windows 2003 Server SP2 set up as a print spooler and we are getting
constand
instances of the print spooler crashing, we have tried moving the spool
file,
increasing memory and have changed the drivers of some of the printers
all
to
no avail.

Could anyone please offer some further advise as this is becoming a
really
frustrating issue as users are constantly excperiencing problems when
printing.

I have pasted below an extraction from the Dr Watson log file to
assist -
apologies for the rather huge post. If you require a specific part of
the
log
file please let me know and I will post it as I am unable to see away
of
attaching a file to the discussion.

Thanks you in advance for your assitance.

Wayne

***** Dr Watson File *****



*----> State Dump for Thread Id 0xb78 <----*

eax=77f6c9e8 ebx=00000000 ecx=0007fc78 edx=00000000 esi=00000000
edi=00000050
eip=7c8285ec esp=0007fbd0 ebp=0007fc38 iopl=0 nv up ei pl zr na
po
nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246

*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:\WINDOWS\system32\ntdll.dll -
function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException
(7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:\WINDOWS\system32\ADVAPI32.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:\WINDOWS\system32\spoolsv.exe -
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:\WINDOWS\system32\kernel32.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may
be
wrong.
0007fc38 77f65edb 00000050 0007fd04 0000021a ntdll!KiFastSystemCallRet
0007fc64 77f65f82 00000050 0007fd04 0000021a
ADVAPI32!LookupPrivilegeValueW+0x114
0007fcd8 77f51ed9 00000050 0007fd04 0000021a
ADVAPI32!LookupPrivilegeValueW+0x1bb
0007ff3c 01004019 0100d5bc 010047a2 00000001
ADVAPI32!StartServiceCtrlDispatcherW+0x8b
0007ffc0 77e6f23b 00000000 00000000 7ffd7000 spoolsv+0x4019
0007fff0 00000000 0100468c 00000000 78746341
kernel32!ProcessIdToSessionId+0x209

*----> State Dump for Thread Id 0xc00 <----*

eax=00000001 ebx=00095c90 ecx=003aff60 edx=7c8285ec esi=00000078
edi=00000000
eip=7c8285ec esp=003aff0c ebp=003aff7c iopl=0 nv up ei pl zr na
po
nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException
(7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may
be
wrong.
003aff7c 77e61c8d 00000078 ffffffff 00000000 ntdll!KiFastSystemCallRet
003aff90 010043a3 00000078 ffffffff 00095c90
kernel32!WaitForSingleObject+0x12
003affa4 77f65e91 00000001 00095c9c 00000000 spoolsv+0x43a3
003affb8 77e64829 00095c90 00000000 00000000
ADVAPI32!LookupPrivilegeValueW+0xca
003affec 00000000 77f65e70 00095c90 00000000
kernel32!GetModuleHandleA+0xdf

*----> State Dump for Thread Id 0x5a8 <----*

eax=00000000 ebx=000a5978 ecx=00095860 edx=0009585c esi=000c05a0
edi=00000000
eip=7c8285ec esp=0081fe1c ebp=0081ff84 iopl=0 nv up ei pl zr na
po
nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246

function: ntdll!KiFastSystemCallRet
7c8285ce e82c000000 call ntdll!RtlRaiseException
(7c8285ff)
7c8285d3 8b0424 mov eax,[esp]
7c8285d6 8be5 mov esp,ebp
7c8285d8 5d pop ebp
7c8285d9 c3 ret
7c8285da 8da42400000000 lea esp,[esp]
7c8285e1 8da42400000000 lea esp,[esp]
ntdll!KiFastSystemCall:
7c8285e8 8bd4 mov edx,esp
7c8285ea 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c8285ec c3 ret
7c8285ed 8da42400000000 lea esp,[esp]
7c8285f4 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c8285f8 8d542408 lea edx,[esp+0x8]
7c8285fc cd2e int 2e
7c8285fe c3 ret
ntdll!RtlRaiseException:
7c8285ff 55 push ebp
7c828600 8bec mov ebp,esp
7c828602 8da42430fdffff lea esp,[esp-0x2d0]

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for
C:\WINDOWS\system32\RPCRT4.dll -
ChildEBP RetAddr Args to Child
WARNING: Stack unwind information not available. Following frames may
be
wrong.
0081ff84 77c88792 0081ffac 77c8872d 000c05a0 ntdll!KiFastSystemCallRet
0081ff8c 77c8872d 000c05a0 00000000 00000000 RPCRT4!I_RpcFree+0xbd0
0081ffac 77c7b110 000957d0 0081ffec 77e64829 RPCRT4!I_RpcFree+0xb6b
0081ffb8 77e64829 000a5978 00000000 00000000
RPCRT4!NdrFullPointerInsertRefId+0x3ba
0081ffec 00000000 77c7b0f5 000a5978 00000000
kernel32!GetModuleHandleA+0xdf
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top