Problem name: APPCRASH, App name: rrservice.​exe version: 4.0.121.0
Hi there everybody, I need a bit of help. My Thinkpad R61 8918 A19 started to work slowly at begining and now everytime i login it gets stocked so i can't work on it.
The error messagge that appears is this one.
Problem event name: APPCRASH
Application name: rrservice.exe
Application version: 4.0.121.0
Application timestamp: 45a2e978
Fault module name: rrservice.exe
Fault module version: 4.0.121.0
Fault module timestamp: 45a2e978
Exception code c0000005
Exception offset 000018ff
OS version 6.0.6001.2.1.0.7683
Additional Info1 af50
Additional Info2 289a6097cb7lec
Additional Info3 9658d4b9b3d90ef8437768
Additional Info4 bde892ee40a7ae18aa6dec7f983e68fd
I'm not sure if this would be the only problem with the Thinkpad but is the only clue that i've got so i hope somebody could help me with it.
Thnx !
Welcome to lenovo user forums!
That must be the rescue and recovery service.Have you tried disabling that service? You may upgrade to the latest version(4.21)and see if your problem is resolved.
http://www-307.ibm.com/pc/support/site.wss/MIGR-4Q2QAK.html
Note:
Rescue and Recovery 4.21 is not integrated with ThinkVantage Productivity Center 1.0. ThinkVantage Productivity Center users should update to ThinkVantage Productivity Center 2.0 or later for the best user experience.
Cheers and regards,
• » νιנαソѕαяα∂нι ѕαмανє∂αм ™ « •
●๋•کáŕádhí'ک díáŕý ツ
I am a volunteer here. I don't work for Lenovo
Similar Messages
-
Hi, I'm running Windows 8.1 Pro, and having problems where explorer will crash every couple of hours.
here's the event viewer log info:
Faulting application name: explorer.exe, version: 6.3.9600.17039, time stamp: 0x53156588
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x0000000000000000
Faulting process id: 0x2dfc
Faulting application start time: 0x01cf7e970bd1516c
Faulting application path: C:\windows\explorer.exe
Faulting module path: unknown
Report Id: a2e8b887-ea95-11e3-8265-0050b66098e2
Faulting package full name:
Faulting package-relative application ID:
I opened up the dump file, and i'm having a hard time making out what the issue might be. Any assistance would be appreciated. Thank you!
************* Symbol Path validation summary **************
Response Time (ms) Location
Deferred SRV*C:\SYMBOLS*http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*C:\SYMBOLS*http://msdl.microsoft.com/download/symbols
Executable search path is:
Windows 8 Version 9600 MP (4 procs) Free x64
Product: WinNt, suite: SingleUserTS
Built by: 6.3.9600.17031 (winblue_gdr.140221-1952)
Machine Name:
Debug session time: Mon Jun 2 12:15:42.000 2014 (UTC - 7:00)
System Uptime: not available
Process Uptime: 0 days 0:07:27.000
Loading unloaded module list
This dump file has an exception of interest stored in it.
The stored exception information can be accessed via .ecxr.
(2230.9d4): Access violation - code c0000005 (first/second chance not available)
ntdll!NtWaitForMultipleObjects+0xa:
00007ffc`20b2b13a c3 ret
0:054> !analyze -v
* Exception Analysis *
*** ERROR: Symbol file could not be found. Defaulted to export symbols for sppc.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for dlumd11.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for ClassicStartMenuDLL.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for ClassicExplorer64.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for GROOVEEX.DLL -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for msvcr90.dll -
FAULTING_IP:
+50951de2c52b
00000000`00000000 ?? ???
EXCEPTION_RECORD: ffffffffffffffff -- (.exr 0xffffffffffffffff)
ExceptionAddress: 0000000000000000
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000008
Parameter[1]: 0000000000000000
Attempt to execute non-executable address 0000000000000000
CONTEXT: 0000000000000000 -- (.cxr 0x0;r)
rax=00000000066e0000 rbx=0000000000000003 rcx=00000000066e0000
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000003
rip=00007ffc20b2b13a rsp=000000000980d428 rbp=000000000980dee0
r8=0000000000001000 r9=0000000000000000 r10=0000000000000040
r11=0000000000000286 r12=0000000000000010 r13=000000000980d840
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei pl zr na po nc
cs=0033 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00000246
ntdll!NtWaitForMultipleObjects+0xa:
00007ffc`20b2b13a c3 ret
PROCESS_NAME: explorer.exe
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%08lx referenced memory at 0x%08lx. The memory could not be %s.
EXCEPTION_PARAMETER1: 0000000000000008
EXCEPTION_PARAMETER2: 0000000000000000
WRITE_ADDRESS: 0000000000000000
FOLLOWUP_IP:
propsys!PSPropertyBag_WriteInt+3c
00007ffc`19a2945c 488b4c2438 mov rcx,qword ptr [rsp+38h]
FAILED_INSTRUCTION_ADDRESS:
+3c
00000000`00000000 ?? ???
NTGLOBALFLAG: 0
APPLICATION_VERIFIER_FLAGS: 0
APP: explorer.exe
ANALYSIS_VERSION: 6.3.9600.17029 (debuggers(dbg).140219-1702) amd64fre
FAULTING_THREAD: 00000000000009d4
BUGCHECK_STR: APPLICATION_FAULT_SOFTWARE_NX_FAULT_NULL
PRIMARY_PROBLEM_CLASS: SOFTWARE_NX_FAULT_NULL
DEFAULT_BUCKET_ID: SOFTWARE_NX_FAULT_NULL
LAST_CONTROL_TRANSFER: from 00007ffc19a2945c to 0000000000000000
STACK_TEXT:
00000000`0980ed68 00007ffc`19a2945c : 00000000`1edc55b0 00000000`1edc55b0 00000000`00000000 00007ffc`1c581762 : 0x0
00000000`0980ed70 00007ffc`08848361 : 00000000`183c3ad0 00000000`1edc55b0 00000000`1edc55b0 00000000`00000000 : propsys!PSPropertyBag_WriteInt+0x3c
00000000`0980edc0 00007ffc`088482c4 : 00000000`00000000 00000000`00000425 00007ffc`16461240 00000000`00000425 : explorerframe!CShellBrowser::_OnFrameStateChanged+0x81
00000000`0980ee10 00007ffc`087ef021 : 00000000`00000001 00000000`00000425 00000000`00000425 00000000`00000033 : explorerframe!CShellBrowser::WndProcBS+0x8aa
00000000`0980f0b0 00007ffc`1ff62434 : 00000000`00000001 00000000`0980f360 00000000`00000000 00000002`00000030 : explorerframe!IEFrameWndProc+0x7d
00000000`0980f100 00007ffc`1ff63fe2 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : user32!UserCallWinProcCheckWow+0x140
00000000`0980f1c0 00007ffc`1ff6409d : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : user32!DispatchClientMessage+0xa2
00000000`0980f220 00007ffc`20b2c99f : 00000000`18215570 00007ffc`087ffd50 00000000`18215570 00000000`0980f310 : user32!_fnDWORD+0x2d
00000000`0980f280 00007ffc`1ff61fea : 00007ffc`1ff6341d 00000000`00000064 00000000`00000000 00000000`0980f3a0 : ntdll!KiUserCallbackDispatcherContinue
00000000`0980f308 00007ffc`1ff6341d : 00000000`00000064 00000000`00000000 00000000`0980f3a0 00007ffc`087f0dab : user32!NtUserMessageCall+0xa
00000000`0980f310 00007ffc`1ff65191 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00abecc0 : user32!SendMessageWorker+0x118
00000000`0980f3a0 00007ffc`087f736c : 00000000`183111e0 00000000`17e90f80 00000000`00020732 00000000`00000000 : user32!SendMessageW+0x105
00000000`0980f400 00007ffc`088479bb : 00000000`0000000c 00000000`183111e0 00000000`00000000 00000000`00000000 : explorerframe!CBrowserHost::ForwardMessageToBrowser+0x1c
00000000`0980f430 00007ffc`088484e1 : 00000000`17e90ef8 00000000`00020732 00000000`00000000 00000000`17e90f80 : explorerframe!CExplorerFrame::OnBrowserCreated+0xcb
00000000`0980f480 00007ffc`08847dcb : 00000000`203caba8 00000000`1edc55b0 00000000`17e90ee0 00000000`16237630 : explorerframe!CBrowserHost::OnBrowserCreated+0xb5
00000000`0980f4c0 00007ffc`08843133 : 00000000`16237630 00000000`16237630 00000000`16237630 00000000`1edc55b0 : explorerframe!CShellBrowser::AfterWindowCreated+0xc7
00000000`0980f500 00007ffc`08842f80 : 00000000`16237630 00000000`0980f730 00000000`00000003 00000000`18311140 : explorerframe!CBrowserHost::Initialize+0xef
00000000`0980f530 00007ffc`087f9bc0 : 00000000`18311140 00000000`00200000 00000000`0980f730 00000000`00000003 : explorerframe!CExplorerFrame::Initialize+0x3c
00000000`0980f560 00007ffc`087fb3b6 : 00000000`18311140 00000000`16237630 00000000`00200000 00007ffc`1e102d9d : explorerframe!BrowserThreadProc+0x50
00000000`0980f5a0 00007ffc`087fb366 : 18bc0f9b`000047ae 00000000`15ff61e0 00000000`00000000 00007ffc`1ff62f2f : explorerframe!BrowserNewThreadProc+0x3a
00000000`0980f5d0 00007ffc`087f8549 : 00000000`00002230 00000000`000009d4 00000000`0000000f 00000000`0000000b : explorerframe!CExplorerTask::InternalResumeRT+0x12
00000000`0980f600 00007ffc`1ebde4fc : 00000000`00000000 00000000`00000000 ffffffff`fffffffe 00000000`00200000 : explorerframe!CRunnableTask::Run+0xc9
00000000`0980f630 00007ffc`1ebde6df : 00000000`10605f50 00000000`10605f50 00000000`00000000 00000000`00000010 : shell32!CShellTaskThread::ThreadProc+0x284
00000000`0980f780 00007ffc`1c588023 : 00000000`00000001 00000000`00000001 00000000`00000000 00000000`00000000 : shell32!CShellTaskThread::s_ThreadProc+0x2f
00000000`0980f7b0 00007ffc`200e16ad : 00000000`0040e300 00000000`00000000 00000000`80004005 00000000`00000000 : SHCore!Microsoft::WRL::FtmBase::MarshalInterface+0x17b
00000000`0980f8d0 00007ffc`20b04629 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : kernel32!BaseThreadInitThunk+0xd
00000000`0980f900 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!RtlUserThreadStart+0x1d
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: propsys!PSPropertyBag_WriteInt+3c
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: propsys
IMAGE_NAME: propsys.dll
DEBUG_FLR_IMAGE_TIMESTAMP: 53511853
STACK_COMMAND: ~54s; .ecxr ; kb
FAILURE_BUCKET_ID: SOFTWARE_NX_FAULT_NULL_c0000005_propsys.dll!PSPropertyBag_WriteInt
BUCKET_ID: APPLICATION_FAULT_SOFTWARE_NX_FAULT_NULL_NULL_IP_propsys!PSPropertyBag_WriteInt+3c
ANALYSIS_SOURCE: UM
FAILURE_ID_HASH_STRING: um:software_nx_fault_null_c0000005_propsys.dll!pspropertybag_writeint
FAILURE_ID_HASH: {a6c58e48-fd4e-59a9-7e83-f1b082937554}
Followup: MachineOwnerHi,
Please upload the dump file to a public folder such as OneDrive, then paste the download link here for further analyzing.
Have you installed any third party tool which might be related with Explorer in your system? if you have, please uninstalled it as a test.
Windows Explorer crashes are mostly caused by an incompatible Shell Extension.
You can run tool ShellExView to find the culprit, in the pane sort the entries with manufacturers. Disable all non-Microsoft *.dll files, and check the result. If the issue does not occur, one of the files can be the culprit. We could narrow down it one by
one.
For download link and user guide, please see this link (ShellExView is included in it)
http://technet.microsoft.com/en-us/magazine/2009.06.toolbox.aspx
Yolanda Zhu
TechNet Community Support -
Log Name: Application
Source: Application Error
Date: 2/26/2014 2:16:26 PM
Event ID: 1000
Task Category: (100)
Level: Error
Keywords: Classic
User: N/A
Computer: SuperFlyXPS
Description:
Faulting application name: msn.exe, version: 10.50.19.1000, time stamp: 0x51ddb7de
Faulting module name: MSHTML.dll, version: 11.0.9600.16518, time stamp: 0x52f365cb
Exception code: 0xc0000005
Fault offset: 0x00175363
Faulting process id: 0x1260
Faulting application start time: 0x01cf32a011d4aeb4
Faulting application path: C:\Program Files (x86)\MSN\MSNCoreFiles\msn.exe
Faulting module path: C:\Windows\system32\MSHTML.dll
Report Id: a1704306-9f33-11e3-acde-782bcbac25e5
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Application Error" />
<EventID Qualifiers="0">1000</EventID>
<Level>2</Level>
<Task>100</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2014-02-26T22:16:26.000000000Z" />
<EventRecordID>80997</EventRecordID>
<Channel>Application</Channel>
<Computer>SuperFlyXPS</Computer>
<Security />
</System>
<EventData>
<Data>msn.exe</Data>
<Data>10.50.19.1000</Data>
<Data>51ddb7de</Data>
<Data>MSHTML.dll</Data>
<Data>11.0.9600.16518</Data>
<Data>52f365cb</Data>
<Data>c0000005</Data>
<Data>00175363</Data>
<Data>1260</Data>
<Data>01cf32a011d4aeb4</Data>
<Data>C:\Program Files (x86)\MSN\MSNCoreFiles\msn.exe</Data>
<Data>C:\Windows\system32\MSHTML.dll</Data>
<Data>a1704306-9f33-11e3-acde-782bcbac25e5</Data>
</EventData>
</Event>
need help with . . .Hi,
I found a useful link:
MSN has encountered a problem needs to close or MSN is not responding Error
https://answers.msn.com/solution.aspx?solutionid=11abae39-d906-4113-bb4e-ecfaa81798f0
Please take a look of this part
(Common Faulty Module on MSN
Mshtml.dll)
*Instead of MSN, here is a another software called Skype, just instroduce it to you, hope you can enjoy it.*
Yolanda Zhu
TechNet Community Support -
Nome evento problema: APPCRASH
Nome applicazione: iTunes.exe
Versione applicazione: 11.1.4.62
Timestamp applicazione: 52ddbf7a
Nome modulo con errori: StackHash_1025
Versione modulo con errori: 6.0.6002.18881
Timestamp modulo con errori: 51da3e27
Codice eccezione: c0000374
Offset eccezione: 000b06fc
Versione SO: 6.0.6002.2.2.0.256.6
ID impostazioni locali: 1040
Informazioni aggiuntive 1: 1025
Ulteriori informazioni 2: 491df5c84464b99ef8f61e542b4c9ce4
Ulteriori informazioni 3: 9ade
Ulteriori informazioni 4: 7f7b00bf8397fb6909813f504d7de648Nome evento problema:
APPCRASH
Nome applicazione:
Adobe Premiere Pro.exe
Versione applicazione:
5.0.3.0
Timestamp applicazione:
4ce382d1
Nome modulo con errori:
StackHash_8659
Versione modulo con errori:
6.1.7601.18247
Timestamp modulo con errori:
521eaf24
Codice eccezione:
c0000374
Offset eccezione:
00000000000c4102
Versione SO:
6.1.7601.2.1.0.256.48
ID impostazioni locali:
1040
Informazioni aggiuntive 1:
8659
Ulteriori informazioni 2:
865914f2b0aba0a7f763eb3f160d9c9b
Ulteriori informazioni 3:
5def
Ulteriori informazioni 4:
5defc8630ba14d9bda1ae72188ae0e03@
E' da quando ho istallato il plug-in Heroglift della Pro-Dad
Fino ad ora con istallati: Magic Bullet, New Blue, ProDad Vitascene e Boris non mi aveva dato eccessivi problemi.
Qualcuno ha avuto la stessa triste esperienza? Grazie e spero qualcuno possa aiutarmi -
Faulting application name: Explorer.EXE, version: 6.3.9600.16441, time stamp: 0x5265dec8
Faulting module name: verifier.dll, version: 6.3.9600.16384, time stamp: 0x5215f8f7
Exception code: 0x80000003
Fault offset: 0x000000000000abd4
Faulting process id: 0x13fc
Faulting application start time: 0x01cf2a60ac1727ab
Faulting application path: C:\WINDOWS\Explorer.EXE
Faulting module path: C:\WINDOWS\system32\verifier.dll
Report Id: d489ba61-9655-11e3-bf26-f82fa8e6dde2
Faulting package full name:
Faulting package-relative application ID:Hi,
Try to run sfc /scannow command to repair the corrupted system file:
Use the System File Checker tool to repair missing or corrupted system files
http://support.microsoft.com/kb/929833
Also we could a easier way system restore to roll back to a time when everything works fine:
How to refresh, reset, or restore your PC
http://windows.microsoft.com/en-IN/windows-8/restore-refresh-reset-pc
Karen Hu
TechNet Community Support -
I have one user on Windows 7 Pro x64 that will have his GroupWise crash out about once a day. He says sometimes he will be working in other programs and a popup will come up that GroupWise has stopped responding and to close program.
The event log shows:
Faulting application name: grpwise.exe, version: 14.0.0.25243, time stamp: 0x5334b3ec
Faulting module name: gwenv1.dll, version: 14.0.0.25243, time stamp: 0x5334b1f9
Exception code: 0xc0000005
Fault offset: 0x00450dfb
Faulting process id: 0x2308
Faulting application start time: 0x01cfc22505c31a56
Faulting application path: C:\Program Files (x86)\Novell\GroupWise\grpwise.exe
Faulting module path: C:\Program Files (x86)\Novell\GroupWise\gwenv1.dll
Report Id: f3b0976c-2e26-11e4-8725-f8b156b229f2
Any ideas why?
KenOriginally Posted by smflood
On 28/08/2014 14:06, RLMILLIES wrote:
> I have one user on Windows 7 Pro x64 that will have his GroupWise crash
> out about once a day. He says sometimes he will be working in other
> programs and a popup will come up that GroupWise has stopped responding
> and to close program.
>
> The event log shows:
>
> Faulting application name: grpwise.exe, version: 14.0.0.25243, time
> stamp: 0x5334b3ec
> Faulting module name: gwenv1.dll, version: 14.0.0.25243, time stamp:
> 0x5334b1f9
> Exception code: 0xc0000005
> Fault offset: 0x00450dfb
> Faulting process id: 0x2308
> Faulting application start time: 0x01cfc22505c31a56
> Faulting application path: C:\Program Files
> (x86)\Novell\GroupWise\grpwise.exe
> Faulting module path: C:\Program Files
> (x86)\Novell\GroupWise\gwenv1.dll
> Report Id: f3b0976c-2e26-11e4-8725-f8b156b229f2
>
> Any ideas why?
No but please can you try the SP1 client which was recently released.
It's available for download @
https://download.novell.com/Download...d=adKLQO6vZjA~
HTH.
Simon
Novell Knowledge Partner
If you find this post helpful and are logged into the web interface,
please show your appreciation and click on the star below. Thanks.
So far so good - The client has not crashed since the update.
Sincerely,
Ken -
The environment is aSharepoint2010 and ProjectServer2010we hadlast nighta crach ofapplication poolwithan error on thew3wpandkernelbase.
We canrevivetheappbutthe firstaccess to the sitewe have thew3wpcrash.
we did adumpand here are thedetails.
Information 12/08/2014 15:28:45 Windows Error Reporting 1001 None
Fault bucket , type 0
Event Name: APPCRASH
Response: Not available
Cab Id: 0
Problem signature:
P1: w3wp.exe
P2: 7.5.7601.17514
P3: 4ce7afa2
P4: KERNELBASE.dll
P5: 6.1.7601.18409
P6: 5315a05a
P7: c06d007e
P8: 000000000000940d
P9:
P10:
Attached files:
These files may be available here:
Analysis symbol:
Rechecking for solution: 0
Report Id: 9561bd5d-2224-11e4-9566-0050569a0110
Report Status: 0
Error 12/08/2014 15:28:46 Application Error 1000 (100)
Faulting application name: w3wp.exe, version: 7.5.7601.17514, time stamp:
0x4ce7afa2
Faulting module name: KERNELBASE.dll, version: 6.1.7601.18409, time stamp: 0x5315a05a
Exception code: 0xc06d007e
Fault offset: 0x000000000000940d
Faulting process id: 0x15d0
Faulting application start time: 0x01cfb6315831ebbb
Faulting application path: c:\windows\system32\inetsrv\w3wp.exe
Faulting module path: C:\Windows\system32\KERNELBASE.dll
Report Id: 95eaafc7-2224-11e4-9566-0050569a0110
Warning 12/08/2014 15:28:51 WAS 5011 None
A process serving application pool 'SharePoint Central Administration v4'
suffered a fatal communication error with the Windows Process Activation
Service. The process id was '2448'. The data field contains the error number
Error 12/08/2014 15:28:51 WAS 5002 None
Application pool 'SharePoint Central Administration v4' is being automatically
disabled due to a series of failures in the process(es) serving that
application pool.
Le dump du crach donne les informations suivantes
(990.fb4): Unknown exception - code c06d007e (first/second chance not
available)
KERNELBASE!RaiseException+0x39:
000007fe`fda5940d 4881c4c8000000 add rsp,0C8h
0:004> .loadby sos clr
Unable to find module 'clr'
0:004> .loadby sos clr
Unable to find module 'clr'
0:004> !analyze -v
* Exception Analysis *
GetPageUrlData failed, server returned HTTP status 404
URL requested:
http://watson.microsoft.com/StageOne/w3wp_exe/7_5_7601_17514/4ce7afa2/KERNELBASE_dll/6_1_7601_18409/5315a05a/c06d007e/0000940d.htm?Retriage=1
FAULTING_IP:
KERNELBASE!RaiseException+39
000007fe`fda5940d 4881c4c8000000 add rsp,0C8h
EXCEPTION_RECORD: ffffffffffffffff -- (.exr 0xffffffffffffffff)
ExceptionAddress: 000007fefda5940d (KERNELBASE!RaiseException+0x0000000000000039)
ExceptionCode: c06d007e
ExceptionFlags: 00000000
NumberParameters: 1
Parameter[0]: 000000000092e820
DEFAULT_BUCKET_ID: APPLICATION_FAULT
PROCESS_NAME: w3wp.exe
ERROR_CODE: (NTSTATUS) 0xc06d007e -
<unable code="" error="" get="" text="" to="">
EXCEPTION_CODE: (NTSTATUS) 0xc06d007e -
<unable code="" error="" get="" text="" to="">
EXCEPTION_PARAMETER1: 000000000092e820
MOD_LIST:
<analysis>
NTGLOBALFLAG: 0
APPLICATION_VERIFIER_FLAGS: 0
MANAGED_STACK: !dumpstack -EE
OS Thread Id: 0xfb4 (4)
Child-SP RetAddr Call Site
FAULTING_THREAD: 0000000000000fb4
PRIMARY_PROBLEM_CLASS: APPLICATION_FAULT
BUGCHECK_STR: APPLICATION_FAULT_APPLICATION_FAULT
LAST_CONTROL_TRANSFER: from 000007fee99ed41d to 000007fefda5940d
STACK_TEXT:
00000000`0092e730 000007fe`e99ed41d : 00000000`00000000 00000000`00000000
00000000`00000391 000007fe`e9b40cd0 : KERNELBASE!RaiseException+0x39
00000000`0092e800 000007fe`e996d57f : 000007fe`e9c78e70 00000000`0092e820
00000000`00000000 00000000`00000000 : OWSSVR!DllCanUnloadNow+0x8cfad
00000000`0092e8b0 000007fe`e96c5244 : 00000000`0000000d 00000000`010dd4f0
0000000f`001d000b 00000010`001a000c : OWSSVR!DllCanUnloadNow+0xd10f
00000000`0092e920 000007fe`e96c5313 : 00000000`00000000 00000000`00328ad0
00000000`778d4564 000007fe`e9c78e28 : OWSSVR!TerminateExtension+0x158
00000000`0092eaa0 000007fe`e96c5379 : 00000000`0128fcd0 00000000`000000a4
00000000`00000024 000007fe`faf11827 : OWSSVR!TerminateExtension+0x227
00000000`0092ebf0 000007fe`e96c18d8 : 00000000`00000000 00000000`00000000
00000000`01290840 00000000`00000021 : OWSSVR!TerminateExtension+0x28d
00000000`0092ec20 000007fe`cf5cf94a : 00000000`00000000 00000000`01290840
00000000`01290840 00000000`0128f800 : OWSSVR!RegisterModule+0x1c
00000000`0092ec50 000007fe`cf5d9aa4 : 00000000`00000000 00000000`00000000
00000000`00000000 00000000`00000000 : iiscore!VIRTUAL_MODULE::RegisterModule+0x2a
00000000`0092ec80 000007fe`cf5daeeb : 00000000`00000078 000007fe`cf5ba944
00000000`0128f800 000007fe`cf5e87b8 :
iiscore!W3_SERVER::LoadModulesFromConfig+0x394
00000000`0092eda0 000007fe`cf5dc2ff : 00000000`0128f800 000007fe`cf5e87b8
00000000`00000000 00000000`0121fb10 :
iiscore!W3_SERVER::InitializeGlobalModules+0x3b
00000000`0092ede0 000007fe`cf5e234d : 00000000`0128f800 00000000`00000002
00000000`0121fb10 00000000`0000017c : iiscore!W3_SERVER::Initialize+0xaaf
00000000`0092f040 000007fe`cf5e2405 : 00000000`0128f6b0 00000000`00000000
00000000`00000000 00000000`0000000c :
iiscore!IISCORE_PROTOCOL_MANAGER::InitializeGlobals+0x1fd
00000000`0092f2e0 000007fe`e27a9316 : 00000000`00000000 00000000`00000000
00000000`005fa7e0 00000000`00000000 :
iiscore!IISCORE_PROTOCOL_MANAGER::PreloadApplication+0x45
00000000`0092f320 000007fe`e27a7dd2 : 00000000`005ff4b0 00000000`77997ef5
00000000`0128f6b0 00000000`0021f070 :
w3wphost!WP_IPM::HandlePreloadApplications+0xc2
00000000`0092f370 000007fe`faf141f3 : 00000000`005ff508 00000000`00000000
00000000`00000000 00000000`00000000 : w3wphost!WP_IPM::AcceptMessage+0x16e
00000000`0092f3b0 00000000`77bbc251 : 00000000`00000000 00000000`003b3bf0
00000000`00000000 00000000`0000000c : iisutil!IPM_MESSAGE_PIPE::MessagePipeCompletion+0x44f
00000000`0092f430 00000000`77bc658c : 00000000`003b3b40 00000000`003693f0
00000000`0092f5e8 00000000`00000000 : ntdll!RtlpTpWaitCallback+0x92
00000000`0092f480 00000000`77bd0c56 : 00000000`0035d110 00000000`77cb45e8 00000000`00000000
00000000`77cb4610 : ntdll!TppWaitpExecuteCallback+0x10c
00000000`0092f4e0 00000000`779a59ed : 00000000`00000000 00000000`00000000
00000000`00000000 00000000`00000000 : ntdll!TppWorkerThread+0x5ff
00000000`0092f7e0 00000000`77bdc541 : 00000000`00000000 00000000`00000000
00000000`00000000 00000000`00000000 : kernel32!BaseThreadInitThunk+0xd
00000000`0092f810 00000000`00000000 : 00000000`00000000 00000000`00000000
00000000`00000000 00000000`00000000 : ntdll!RtlUserThreadStart+0x1d
STACK_COMMAND: ~4s; .ecxr ; kb
FOLLOWUP_IP:
OWSSVR!DllCanUnloadNow+8cfad
000007fe`e99ed41d 488b442458 mov rax,qword ptr [rsp+58h]
SYMBOL_STACK_INDEX: 1
SYMBOL_NAME: owssvr!DllCanUnloadNow+8cfad
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: OWSSVR
IMAGE_NAME: OWSSVR.DLL
DEBUG_FLR_IMAGE_TIMESTAMP: 51c91cf5
FAILURE_BUCKET_ID: APPLICATION_FAULT_c06d007e_OWSSVR.DLL!DllCanUnloadNow
BUCKET_ID: X64_APPLICATION_FAULT_APPLICATION_FAULT_owssvr!DllCanUnloadNow+8cfad
WATSON_STAGEONE_URL:
http://watson.microsoft.com/StageOne/w3wp_exe/7_5_7601_17514/4ce7afa2/KERNELBASE_dll/6_1_7601_18409/5315a05a/c06d007e/0000940d.htm?Retriage=1
Followup: MachineOwner </analysis></unable></unable>Hello Roland_Zeki,
Can you check System in the Windows Log of Event Viewer? Maybe you have some logon failure for one of the services, like in this blog:
http://www.shareesblog.com/?p=363
- Dennis | Netherlands | Blog |
Twitter
Yes I have verify this point I suspected to be the origine of the problem. But no, the accounts have fixed password and are not locked. I test this point with a valide login on the server, and I reenter the login password for each app pool. -
Hello Guys,
While running a web application am getting an error like: Remote server not responding. Below are the details of event viewers which been captured at the same time when this error happened:
Event 1000, Application Error
Faulting application name: w3wp.exe, version: 7.5.7600.16385, time stamp: 0x4a5bd0eb
Faulting module name: KERNELBASE.dll, version: 6.1.7600.16850, time stamp: 0x4e211da1
Exception code: 0xe053534f
Fault offset: 0x000000000000a88d
Faulting process id: 0x%9
Faulting application start time: 0x%10
Faulting application path: %11
Faulting module path: %12
Report Id: %13
Event 1001, Windows Error Reporting
Fault bucket , type 0
Event Name: APPCRASH
Response: Not available
Cab Id: 0
Problem signature:
P1: w3wp.exe
P2: 7.5.7600.16385
P3: 4a5bd0eb
P4: KERNELBASE.dll
P5: 6.1.7600.16850
P6: 4e211da1
P7: e053534f
P8: 000000000000a88d
P9:
P10:
Attached files:
C:\Windows\Temp\WERC9CD.tmp.WERInternalMetadata.xml
C:\Windows\Temp\WERC9CE.tmp.hdmp
C:\Windows\Temp\WEREE30.tmp.mdmp
These files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_w3wp.exe_30877924d6b2c607fe88a8718915f25fb79093_cab_e905f2b0
Analysis symbol:
Rechecking for solution: 0
Report Id: d46a6849-8f6a-11e1-98af-00215e6e4855
Report Status: 4
This is an priority issue which we are facing in IIS. IIS is configured for Framework 2.0 and underlying OS is - Windows
Server 2008 R2 Standard.This issue is replicable and occurring frequently Please suggest how to resolve it. Any input related to above issue is appreciable.Please refer similar discussions and see if they help
Faulting application name: w3wp.exe
http://telligent.com/support/communityserver/community_server_2008/f/288/t/1067447.aspx
Event ID: 1000, Faulting application w3wp.exe, faulting module unknown,
http://social.msdn.microsoft.com/forums/en-US/clr/thread/9be88a2f-c8cc-4a73-9371-45ab73982123
For IIS related queries, please post them in IIS forum - http://forums.iis.net/
A UNIVERSE without WINDOWS is CHAOS !
This posting is provided "AS IS" with no warranties or guarantees and confers no rights.
About Me !!! -
Configuration Manager 2012 Agent Crashing - Faulting Application Name: CcmExec.exe
We have recently experienced ~1,000 systems that have the SCCM 2012 SP1 client crashing every 5 to 10 minutes. The SCCM 2012 environment is SP1 CU3 and most SCCM clients are running the SP1 version of 5.00.7804.1000.
The following errors are written in the Application Event Log every time this occurs:
Log Name: Application
Source: Configuration Manager Agent
Date: 12/5/2013 8:32:07 AM
Event ID: 669
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: %ComputerName%
Description:
The component raised an exception but failed to handle it and will be stopped immediately.
Component name: KERNELBASE.dll
Executable:
Process ID:
Thread ID:
Instruction address: 8791750393037
Exception code: -286326786
Client version: 5.00.7804.1000
Log Name: Application
Source: Application Error
Date: 12/5/2013 8:32:07 AM
Event ID: 1000
Task Category: (100)
Level: Error
Keywords: Classic
User: N/A
Computer: %ComputerName%
Description:
Faulting application name: CcmExec.exe, version: 5.0.7804.1000, time stamp: 0x50add6eb
Faulting module name: KERNELBASE.dll, version: 6.1.7601.17965, time stamp: 0x506dcae6
Exception code: 0xeeeefffe
Fault offset: 0x000000000000bccd
Faulting process id: 0x1120
Faulting application start time: 0x01cef1be5aad21ad
Faulting application path: C:\Windows\CCM\CcmExec.exe
Faulting module path: C:\Windows\system32\KERNELBASE.dll
Report Id: a24071a5-5db1-11e3-b5bc-d4bed936cdee
Log Name: Application
Source: Windows Error Reporting
Date: 12/5/2013 8:32:07 AM
Event ID: 1001
Task Category: None
Level: Information
Keywords: Classic
User: N/A
Computer: %ComputerName%
Description:
Fault bucket , type 0
Event Name: APPCRASH
Response: Not available
Cab Id: 0
Problem signature:
P1: CcmExec.exe
P2: 5.0.7804.1000
P3: 50add6eb
P4: KERNELBASE.dll
P5: 6.1.7601.17965
P6: 506dcae6
P7: eeeefffe
P8: 000000000000bccd
P9:
P10:
I also saw the post below regarding a similar issue, but nothing has helped resolve the issue as of yet.
http://social.technet.microsoft.com/Forums/en-US/5ad3d7d4-2a87-473d-8c9d-41ad100e134a/random-client-failures-ccmexecexe-exception-code-0xeeeefffe?forum=configmanagergeneral#30791e92-6dc3-4466-9e07-bc2552e6aa3b
Any assistance or guidance is greatly appreciated. Thanks!Yes, I know that this is an old post, I’m just trying to clean them up. Did you find the answer for this?
By change do you have McAfee and have you told McAfee to exclude ccmexec.exe from AV scanning?
http://www.enhansoft.com/ -
Event 1000 and event 1026 Faulting application name: DistributedCacheService.exe
I have 2 WFE, 1 App, all 3 Distributed Cache in Services On Server of CA are started, but only 2 AppFabricCachingService are started on 3 server Services. When I go to notable server which AppFabricCachingService not started, found
the application event log 1000 and 1026.
Event 1000:
Faulting application name: DistributedCacheService.exe, version: 1.0.4632.0, time stamp: 0x4eafeccf
Faulting module name: KERNELBASE.dll, version: 6.1.7601.17514, time stamp: 0x4ce7c78c
Exception code: 0xe0434352
Fault offset: 0x000000000000a49d
Faulting process id: 0x3ff0
Faulting application start time: 0x01cf5e97bc497df8
Faulting application path: C:\Program Files\AppFabric 1.1 for Windows Server\DistributedCacheService.exe
Faulting module path: C:\Windows\system32\KERNELBASE.dll
Report Id: 1bb07d62-ca8c-11e3-a299-005056b837e0
Event 1026:
Application: DistributedCacheService.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: Microsoft.ApplicationServer.Caching.DataCacheException
Stack:
at Microsoft.ApplicationServer.Caching.VelocityWindowsService.StartServiceCallback(System.Object)
at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
at System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
at System.Threading.ThreadPoolWorkQueue.Dispatch()
I tried many times and many method, sometimes it is WFE1, sometimes it is WFE2, now it is APP server.
Don't know why.
Thanks in advance.
AwenStop it on all servers then start on App servers, if it is stable then you can add another server and more.
But it is not recommended to run the DC on all servers in farm, but in your case you have 3 servers.here MSFT position.
"On a farm with four or more servers, you must not start the Distributed Cache service on all servers on the farm. If you configure all
servers as cache hosts, you may experience reliability and performance problems in the farm."
Are all of your server in the farm have the same memory, if not then that's your problem.
Please remember to mark your question as answered &Vote helpful,if this solves/helps your problem. ****************************************************************************************** Thanks -WS MCITP(SharePoint 2010, 2013) Blog: http://wscheema.com/blog -
We're experiencing an issue with one of our Windows Server 2008R2 Standard Edition SP1 servers where an Application error occurs at least twice, and sometimes up to 5 or 6 times per day. The following error is what we see. Any help would be greatly
appreciated, and I'll be checking back frequently to check for updates and provide more info whenever needed. Thanks!
General:
Faulting application name: wmiprvse.exe, version: 6.1.7601.17514, time stamp: 0x4ce79d42
Faulting module name: ntdll.dll, version: 6.1.7601.17514, time stamp: 0x4ce7c8f9
Exception code: 0xc0000374
Fault offset: 0x00000000000c40f2
Faulting process id: 0x1bbc
Faulting application start time: 0x01cd5d65dbeb2e7c
Faulting application path: C:\Windows\system32\wbem\wmiprvse.exe
Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Details:
System
Provider
[ Name]
Application Error
EventID
1000
[ Qualifiers]
0
Level
2
Task
100
Keywords
0x80000000000000
TimeCreated
[ SystemTime]
2012-07-09T08:34:39.000000000Z
EventRecordID
6812
Channel
Application
Computer
{FQDN}
Security
EventData
wmiprvse.exe
6.1.7601.17514
4ce79d42
ntdll.dll
6.1.7601.17514
4ce7c8f9
c0000374
00000000000c40f2
1bbc
01cd5d65dbeb2e7c
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\SYSTEM32\ntdll.dll
ebe1621c-c9a0-11e1-a1d4-5cf3fce8cef6
ETA: I also ran the wmidiag.exe tool from Microsoft. I saw it as a suggestion on another forum and ran it. I don't know if it has any bearing here, but this is the log in case it's helpful
show
06604 14:51:25 (0) ** WMIDiag v2.1 started on Tuesday, July 10, 2012 at 14:40.
06605 14:51:25 (0) **
06606 14:51:25 (0) ** Copyright (c) Microsoft Corporation. All rights reserved - July 2007.
06607 14:51:25 (0) **
06608 14:51:25 (0) ** This script is not supported under any Microsoft standard support program or service.
06609 14:51:25 (0) ** The script is provided AS IS without warranty of any kind. Microsoft further disclaims all
06610 14:51:25 (0) ** implied warranties including, without limitation, any implied warranties of merchantability
06611 14:51:25 (0) ** or of fitness for a particular purpose. The entire risk arising out of the use or performance
06612 14:51:25 (0) ** of the scripts and documentation remains with you. In no event shall Microsoft, its authors,
06613 14:51:25 (0) ** or anyone else involved in the creation, production, or delivery of the script be liable for
06614 14:51:25 (0) ** any damages whatsoever (including, without limitation, damages for loss of business profits,
06615 14:51:25 (0) ** business interruption, loss of business information, or other pecuniary loss) arising out of
06616 14:51:25 (0) ** the use of or inability to use the script or documentation, even if Microsoft has been advised
06617 14:51:25 (0) ** of the possibility of such damages.
06618 14:51:25 (0) **
06619 14:51:25 (0) **
06620 14:51:25 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
06621 14:51:25 (0) ** ----------------------------------------------------- WMI REPORT: BEGIN ----------------------------------------------------------
06622 14:51:25 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
06623 14:51:25 (0) **
06624 14:51:25 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
06625 14:51:25 (0) ** Windows Server 2008 R2 - Service pack 1 - 64-bit (7601) - User {Username} on computer {ComputerName}.
06626 14:51:25 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
06627 14:51:25 (0) ** Environment: ........................................................................................................ OK.
06628 14:51:25 (0) ** System drive: ....................................................................................................... C: (Disk #0 Partition #1).
06629 14:51:25 (0) ** Drive type: ......................................................................................................... SCSI (IBM ServeRAID M5015 SCSI Disk Device).
06630 14:51:25 (0) ** There are no missing WMI system files: .............................................................................. OK.
06631 14:51:25 (0) ** There are no missing WMI repository files: .......................................................................... OK.
06632 14:51:25 (0) ** WMI repository state: ............................................................................................... CONSISTENT.
06633 14:51:25 (0) ** AFTER running WMIDiag:
06634 14:51:25 (0) ** The WMI repository has a size of: ................................................................................... 90 MB.
06635 14:51:25 (0) ** - Disk free space on 'C:': .......................................................................................... 75295 MB.
06636 14:51:25 (0) ** - INDEX.BTR, 15818752 bytes, 7/10/2012 2:38:58 PM
06637 14:51:25 (0) ** - MAPPING1.MAP, 242388 bytes, 7/10/2012 2:33:33 PM
06638 14:51:25 (0) ** - MAPPING2.MAP, 242388 bytes, 7/10/2012 2:38:58 PM
06639 14:51:25 (0) ** - OBJECTS.DATA, 77570048 bytes, 7/10/2012 2:38:58 PM
06640 14:51:25 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
06641 14:51:25 (2) !! WARNING: Windows Firewall: .......................................................................................... DISABLED.
06642 14:51:25 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
06643 14:51:25 (0) ** DCOM Status: ........................................................................................................ OK.
06644 14:51:25 (0) ** WMI registry setup: ................................................................................................. OK.
06645 14:51:25 (0) ** INFO: WMI service has dependents: ................................................................................... 1 SERVICE(S)!
06646 14:51:25 (0) ** - Internet Connection Sharing (ICS) (SHAREDACCESS, StartMode='Disabled')
06647 14:51:25 (0) ** => If the WMI service is stopped, the listed service(s) will have to be stopped as well.
06648 14:51:25 (0) ** Note: If the service is marked with (*), it means that the service/application uses WMI but
06649 14:51:25 (0) ** there is no hard dependency on WMI. However, if the WMI service is stopped,
06650 14:51:25 (0) ** this can prevent the service/application to work as expected.
06651 14:51:25 (0) **
06652 14:51:25 (0) ** RPCSS service: ...................................................................................................... OK (Already started).
06653 14:51:25 (0) ** WINMGMT service: .................................................................................................... OK (Already started).
06654 14:51:25 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
06655 14:51:25 (0) ** WMI service DCOM setup: ............................................................................................. OK.
06656 14:51:25 (0) ** WMI components DCOM registrations: .................................................................................. OK.
06657 14:51:25 (0) ** WMI ProgID registrations: ........................................................................................... OK.
06658 14:51:25 (0) ** WMI provider DCOM registrations: .................................................................................... OK.
06659 14:51:25 (0) ** WMI provider CIM registrations: ..................................................................................... OK.
06660 14:51:25 (0) ** WMI provider CLSIDs: ................................................................................................ OK.
06661 14:51:25 (2) !! WARNING: Some WMI providers EXE/DLL file(s) are missing: ............................................................ 18 WARNING(S)!
06662 14:51:25 (0) ** - ROOT/QLOGIC_CMPI, QLogic_NIC_Provider, C:\Program Files (x86)\Common Files\IBM\icc\cimom\bin\wmicpa.exe /G{28A5F598-F699-4A6B-B9F9-8C7EB9B7359F}:QLogic_NIC_Provider
06663 14:51:25 (0) ** - ROOT/QLOGIC_CMPI, QLogic_FCHBA_Provider, C:\Program Files (x86)\Common Files\IBM\icc\cimom\bin\wmicpa.exe /G{0AE588DD-D2E9-41EB-BCD1-8BF474187EC5}:QLogic_FCHBA_Provider
06664 14:51:25 (0) ** - ROOT/IBMSD, ADPT_Module, C:\Program Files (x86)\Common Files\IBM\icc\cimom\bin\wmicpa.exe /G{B007445E-6AF0-4CBD-9009-809F071FCE69}:ADPT_Module
06665 14:51:25 (0) ** - ROOT/IBMSD, IBM_PA_Providers, C:\Program Files (x86)\Common Files\IBM\icc\cimom\bin\wmicpa.exe /G{2244E0FA-D37A-4F6E-82FB-92F1DB78716D}:IBM_PA_Providers
06666 14:51:25 (0) ** - ROOT/IBMSD, EndpointRegistrationProviderModule, C:\Program Files (x86)\Common Files\IBM\icc\cimom\bin\wmicpa.exe /G{BF833E81-33AA-40ED-B74A-329F006DB4F8}:EndpointRegistrationProviderModule
06667 14:51:25 (0) ** - ROOT/CIMV2, SBLIM_Data_Gatherer, C:\Program Files (x86)\Common Files\IBM\icc\cimom\bin\wmicpa.exe /G{0D03AF80-A160-44EF-9E8B-318201F41693}:SBLIM_Data_Gatherer
06668 14:51:25 (0) ** - ROOT/ADPT, ADPT_Module, C:\Program Files (x86)\Common Files\IBM\icc\cimom\bin\wmicpa.exe /G{B007445E-6AF0-4CBD-9009-809F071FCE69}:ADPT_Module
06669 14:51:25 (0) ** - ROOT/PG_INTEROP, SBLIM_Data_Gatherer, C:\Program Files (x86)\Common Files\IBM\icc\cimom\bin\wmicpa.exe /G{0D03AF80-A160-44EF-9E8B-318201F41693}:SBLIM_Data_Gatherer
06670 14:51:25 (0) ** - ROOT/PG_INTEROP, LSIESG_SMIS13_HHR_ProviderModule, C:\Program Files (x86)\Common Files\IBM\icc\cimom\bin\wmicpa.exe /G{E21064DD-757A-4F2D-B798-81CDFF03B48C}:LSIESG_SMIS13_HHR_ProviderModule
06671 14:51:25 (0) ** - ROOT/PG_INTEROP, emulex_fc_provider_Module, C:\Program Files (x86)\Common Files\IBM\icc\cimom\bin\wmicpa.exe /G{27734403-1E6C-4BC7-B97D-1FE9657B35EC}:emulex_fc_provider_Module
06672 14:51:25 (0) ** - ROOT/PG_INTEROP, emulex_ucna_provider_Module, C:\Program Files (x86)\Common Files\IBM\icc\cimom\bin\wmicpa.exe /G{68D3C192-F517-41CC-B852-BA74A8D05A85}:emulex_ucna_provider_Module
06673 14:51:25 (0) ** - ROOT/IBMSE, emulex_fc_provider_Module, C:\Program Files (x86)\Common Files\IBM\icc\cimom\bin\wmicpa.exe /G{27734403-1E6C-4BC7-B97D-1FE9657B35EC}:emulex_fc_provider_Module
06674 14:51:25 (0) ** - ROOT/IBMSE, IBM_PA_Providers, C:\Program Files (x86)\Common Files\IBM\icc\cimom\bin\wmicpa.exe /G{2244E0FA-D37A-4F6E-82FB-92F1DB78716D}:IBM_PA_Providers
06675 14:51:25 (0) ** - ROOT/IBMSE, emulex_ucna_provider_Module, C:\Program Files (x86)\Common Files\IBM\icc\cimom\bin\wmicpa.exe /G{68D3C192-F517-41CC-B852-BA74A8D05A85}:emulex_ucna_provider_Module
06676 14:51:25 (0) ** - ROOT/LSI_MR_1_3_0, LSIESG_SMIS13_HHR_ProviderModule, C:\Program Files (x86)\Common Files\IBM\icc\cimom\bin\wmicpa.exe /G{E21064DD-757A-4F2D-B798-81CDFF03B48C}:LSIESG_SMIS13_HHR_ProviderModule
06677 14:51:25 (0) ** - ROOT/EMULEX, emulex_fc_provider_Module, C:\Program Files (x86)\Common Files\IBM\icc\cimom\bin\wmicpa.exe /G{27734403-1E6C-4BC7-B97D-1FE9657B35EC}:emulex_fc_provider_Module
06678 14:51:25 (0) ** - ROOT/EMULEX, emulex_ucna_provider_Module, C:\Program Files (x86)\Common Files\IBM\icc\cimom\bin\wmicpa.exe /G{68D3C192-F517-41CC-B852-BA74A8D05A85}:emulex_ucna_provider_Module
06679 14:51:25 (0) ** - ROOT/BROCADE, brcdprovider_Module, C:\Program Files (x86)\Common Files\IBM\icc\cimom\bin\wmicpa.exe /G{48898EFD-0F9A-4657-B03D-FF400A7D2CDE}:brcdprovider_Module
06680 14:51:25 (0) ** => This will make any operations related to the WMI class supported by the provider(s) to fail.
06681 14:51:25 (0) ** This can be due to:
06682 14:51:25 (0) ** - the de-installation of the software.
06683 14:51:25 (0) ** - the deletion of some files.
06684 14:51:25 (0) ** => If the software has been de-installed intentionally, then this information must be
06685 14:51:25 (0) ** removed from the WMI repository. You can use the 'WMIC.EXE' command to remove
06686 14:51:25 (0) ** the provider registration data.
06687 14:51:25 (0) ** i.e. 'WMIC.EXE /NAMESPACE:\\ROOT\BROCADE path __Win32Provider Where Name='brcdprovider_Module' DELETE'
06688 14:51:25 (0) ** => If not, you must restore a copy of the missing provider EXE/DLL file(s) as indicated by the path.
06689 14:51:25 (0) ** You can retrieve the missing file from:
06690 14:51:25 (0) ** - A backup.
06691 14:51:25 (0) ** - The Windows CD.
06692 14:51:25 (0) ** - Another Windows installation using the same version and service pack level of the examined system.
06693 14:51:25 (0) ** - The original CD or software package installing this WMI provider.
06694 14:51:25 (0) **
06695 14:51:25 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
06696 14:51:25 (0) ** INFO: User Account Control (UAC): ................................................................................... DISABLED.
06697 14:51:25 (0) ** INFO: Local Account Filtering: ...................................................................................... ENABLED.
06698 14:51:25 (0) ** => WMI tasks remotely accessing WMI information on this computer and requiring Administrative
06699 14:51:25 (0) ** privileges MUST use a DOMAIN account part of the Local Administrators group of this computer
06700 14:51:25 (0) ** to ensure that administrative privileges are granted. If a Local User account is used for remote
06701 14:51:25 (0) ** accesses, it will be reduced to a plain user (filtered token), even if it is part of the Local Administrators group.
06702 14:51:25 (0) **
06703 14:51:25 (0) ** Overall DCOM security status: ....................................................................................... OK.
06704 14:51:25 (0) ** Overall WMI security status: ........................................................................................ OK.
06705 14:51:25 (0) ** - Started at 'Root' --------------------------------------------------------------------------------------------------------------
06706 14:51:25 (0) ** INFO: WMI permanent SUBSCRIPTION(S): ................................................................................ 2.
06707 14:51:25 (0) ** - ROOT/SUBSCRIPTION, CommandLineEventConsumer.Name="BVTConsumer".
06708 14:51:25 (0) ** 'SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99'
06709 14:51:25 (0) ** - ROOT/SUBSCRIPTION, NTEventLogEventConsumer.Name="SCM Event Log Consumer".
06710 14:51:25 (0) ** 'select * from MSFT_SCMEventLogEvent'
06711 14:51:25 (0) **
06712 14:51:25 (0) ** WMI TIMER instruction(s): ........................................................................................... NONE.
06713 14:51:25 (0) ** INFO: WMI namespace(s) requiring PACKET PRIVACY: .................................................................... 3 NAMESPACE(S)!
06714 14:51:25 (0) ** - ROOT/CIMV2/SECURITY/MICROSOFTTPM.
06715 14:51:25 (0) ** - ROOT/CIMV2/TERMINALSERVICES.
06716 14:51:25 (0) ** - ROOT/SERVICEMODEL.
06717 14:51:25 (0) ** => When remotely connecting, the namespace(s) listed require(s) the WMI client to
06718 14:51:25 (0) ** use an encrypted connection by specifying the PACKET PRIVACY authentication level.
06719 14:51:25 (0) ** (RPC_C_AUTHN_LEVEL_PKT_PRIVACY or PktPrivacy flags)
06720 14:51:25 (0) ** i.e. 'WMIC.EXE /NODE:"{ComputerName}" /AUTHLEVEL:Pktprivacy /NAMESPACE:\\ROOT\SERVICEMODEL Class __SystemSecurity'
06721 14:51:25 (0) **
06722 14:51:25 (0) ** WMI MONIKER CONNECTIONS: ............................................................................................ OK.
06723 14:51:25 (0) ** WMI CONNECTIONS: .................................................................................................... OK.
06724 14:51:25 (1) !! ERROR: WMI GET operation errors reported: ........................................................................... 30 ERROR(S)!
06725 14:51:25 (0) ** - Root/CIMV2, MSFT_NetInvalidDriverDependency, 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found.
06726 14:51:25 (0) ** MOF Registration: ''
06727 14:51:25 (0) ** - Root/CIMV2, Win32_OsBaselineProvider, 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found.
06728 14:51:25 (0) ** MOF Registration: ''
06729 14:51:25 (0) ** - Root/CIMV2, Win32_OsBaseline, 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found.
06730 14:51:25 (0) ** MOF Registration: ''
06731 14:51:25 (0) ** - Root/CIMV2, Win32_DriverVXD, 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found.
06732 14:51:25 (0) ** MOF Registration: ''
06733 14:51:25 (0) ** - Root/CIMV2, Win32_PerfFormattedData_Counters_GenericIKEandAuthIP, 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found.
06734 14:51:25 (0) ** MOF Registration: ''
06735 14:51:25 (0) ** - Root/CIMV2, Win32_PerfRawData_Counters_GenericIKEandAuthIP, 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found.
06736 14:51:25 (0) ** MOF Registration: ''
06737 14:51:25 (0) ** - Root/CIMV2, Win32_PerfFormattedData_Counters_IPsecAuthIPv4, 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found.
06738 14:51:25 (0) ** MOF Registration: ''
06739 14:51:25 (0) ** - Root/CIMV2, Win32_PerfRawData_Counters_IPsecAuthIPv4, 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found.
06740 14:51:25 (0) ** MOF Registration: ''
06741 14:51:25 (0) ** - Root/CIMV2, Win32_PerfFormattedData_Counters_IPsecAuthIPv6, 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found.
06742 14:51:25 (0) ** MOF Registration: ''
06743 14:51:25 (0) ** - Root/CIMV2, Win32_PerfRawData_Counters_IPsecAuthIPv6, 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found.
06744 14:51:25 (0) ** MOF Registration: ''
06745 14:51:25 (0) ** - Root/CIMV2, Win32_PerfFormattedData_Counters_IPsecIKEv4, 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found.
06746 14:51:25 (0) ** MOF Registration: ''
06747 14:51:25 (0) ** - Root/CIMV2, Win32_PerfRawData_Counters_IPsecIKEv4, 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found.
06748 14:51:25 (0) ** MOF Registration: ''
06749 14:51:25 (0) ** - Root/CIMV2, Win32_PerfFormattedData_Counters_IPsecIKEv6, 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found.
06750 14:51:25 (0) ** MOF Registration: ''
06751 14:51:25 (0) ** - Root/CIMV2, Win32_PerfRawData_Counters_IPsecIKEv6, 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found.
06752 14:51:25 (0) ** MOF Registration: ''
06753 14:51:25 (0) ** - Root/CIMV2, Win32_PerfFormattedData_TermService_TerminalServices, 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found.
06754 14:51:25 (0) ** MOF Registration: ''
06755 14:51:25 (0) ** - Root/CIMV2, Win32_PerfRawData_TermService_TerminalServices, 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found.
06756 14:51:25 (0) ** MOF Registration: ''
06757 14:51:25 (0) ** - Root/WMI, ReserveDisjoinThread, 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found.
06758 14:51:25 (0) ** MOF Registration: ''
06759 14:51:25 (0) ** - Root/WMI, ReserveLateCount, 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found.
06760 14:51:25 (0) ** MOF Registration: ''
06761 14:51:25 (0) ** - Root/WMI, ReserveJoinThread, 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found.
06762 14:51:25 (0) ** MOF Registration: ''
06763 14:51:25 (0) ** - Root/WMI, ReserveDelete, 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found.
06764 14:51:25 (0) ** MOF Registration: ''
06765 14:51:25 (0) ** - Root/WMI, ReserveBandwidth, 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found.
06766 14:51:25 (0) ** MOF Registration: ''
06767 14:51:25 (0) ** - Root/WMI, ReserveCreate, 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found.
06768 14:51:25 (0) ** MOF Registration: ''
06769 14:51:25 (0) ** - Root/WMI, SystemConfig_PhyDisk, 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found.
06770 14:51:25 (0) ** MOF Registration: ''
06771 14:51:25 (0) ** - Root/WMI, SystemConfig_Video, 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found.
06772 14:51:25 (0) ** MOF Registration: ''
06773 14:51:25 (0) ** - Root/WMI, SystemConfig_IDEChannel, 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found.
06774 14:51:25 (0) ** MOF Registration: ''
06775 14:51:25 (0) ** - Root/WMI, SystemConfig_NIC, 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found.
06776 14:51:25 (0) ** MOF Registration: ''
06777 14:51:25 (0) ** - Root/WMI, SystemConfig_Network, 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found.
06778 14:51:25 (0) ** MOF Registration: ''
06779 14:51:25 (0) ** - Root/WMI, SystemConfig_CPU, 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found.
06780 14:51:25 (0) ** MOF Registration: ''
06781 14:51:25 (0) ** - Root/WMI, SystemConfig_LogDisk, 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found.
06782 14:51:25 (0) ** MOF Registration: ''
06783 14:51:25 (0) ** - Root/WMI, SystemConfig_Power, 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found.
06784 14:51:25 (0) ** MOF Registration: ''
06785 14:51:25 (0) ** => When a WMI performance class is missing (i.e. 'Win32_PerfRawData_TermService_TerminalServices'), it is generally due to
06786 14:51:25 (0) ** a lack of buffer refresh of the WMI class provider exposing the WMI performance counters.
06787 14:51:25 (0) ** You can refresh the WMI class provider buffer with the following command:
06788 14:51:25 (0) **
06789 14:51:25 (0) ** i.e. 'WINMGMT.EXE /SYNCPERF'
06790 14:51:25 (0) **
06791 14:51:25 (0) ** WMI MOF representations: ............................................................................................ OK.
06792 14:51:25 (0) ** WMI QUALIFIER access operations: .................................................................................... OK.
06793 14:51:25 (0) ** WMI ENUMERATION operations: ......................................................................................... OK.
06794 14:51:25 (2) !! WARNING: WMI EXECQUERY operation errors reported: ................................................................... 2 WARNING(S)!
06795 14:51:25 (0) ** - Root/CIMV2, 'Select * From Win32_PointingDevice WHERE Status = "OK"' did not return any instance while AT LEAST 1 instance is expected.
06796 14:51:25 (0) ** - Root/CIMV2, 'Select * From Win32_Keyboard' did not return any instance while AT LEAST 1 instance is expected.
06797 14:51:25 (0) **
06798 14:51:25 (2) !! WARNING: WMI GET VALUE operation errors reported: ................................................................... 5 WARNING(S)!
06799 14:51:25 (0) ** - Root, Instance: __EventConsumerProviderCacheControl=@, Property: ClearAfter='00000000000030.000000:000' (Expected default='00000000000500.000000:000').
06800 14:51:25 (0) ** - Root, Instance: __EventProviderCacheControl=@, Property: ClearAfter='00000000000030.000000:000' (Expected default='00000000000500.000000:000').
06801 14:51:25 (0) ** - Root, Instance: __EventSinkCacheControl=@, Property: ClearAfter='00000000000015.000000:000' (Expected default='00000000000230.000000:000').
06802 14:51:25 (0) ** - Root, Instance: __ObjectProviderCacheControl=@, Property: ClearAfter='00000000000030.000000:000' (Expected default='00000000000500.000000:000').
06803 14:51:25 (0) ** - Root, Instance: __PropertyProviderCacheControl=@, Property: ClearAfter='00000000000030.000000:000' (Expected default='00000000000500.000000:000').
06804 14:51:25 (0) **
06805 14:51:25 (0) ** WMI WRITE operations: ............................................................................................... NOT TESTED.
06806 14:51:25 (0) ** WMI PUT operations: ................................................................................................. NOT TESTED.
06807 14:51:25 (0) ** WMI DELETE operations: .............................................................................................. NOT TESTED.
06808 14:51:25 (0) ** WMI static instances retrieved: ..................................................................................... 2072.
06809 14:51:25 (0) ** WMI dynamic instances retrieved: .................................................................................... 0.
06810 14:51:25 (0) ** WMI instance request cancellations (to limit performance impact): ................................................... 1.
06811 14:51:25 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
06812 14:51:25 (0) ** # of Event Log events BEFORE WMIDiag execution since the last 20 day(s):
06813 14:51:25 (0) ** DCOM: ............................................................................................................. 0.
06814 14:51:25 (0) ** WINMGMT: .......................................................................................................... 0.
06815 14:51:25 (0) ** WMIADAPTER: ....................................................................................................... 0.
06816 14:51:25 (0) **
06817 14:51:25 (0) ** # of additional Event Log events AFTER WMIDiag execution:
06818 14:51:25 (0) ** DCOM: ............................................................................................................. 0.
06819 14:51:25 (0) ** WINMGMT: .......................................................................................................... 0.
06820 14:51:25 (0) ** WMIADAPTER: ....................................................................................................... 0.
06821 14:51:25 (0) **
06822 14:51:25 (0) ** 30 error(s) 0x80041002 - (WBEM_E_NOT_FOUND) Object cannot be found
06823 14:51:25 (0) ** => This error is typically a WMI error. This WMI error is due to:
06824 14:51:25 (0) ** - a missing WMI class definition or object.
06825 14:51:25 (0) ** (See any GET, ENUMERATION, EXECQUERY and GET VALUE operation failures).
06826 14:51:25 (0) ** You can correct the missing class definitions by:
06827 14:51:25 (0) ** - Manually recompiling the MOF file(s) with the 'MOFCOMP <FileName.MOF>' command.
06828 14:51:25 (0) ** Note: You can build a list of classes in relation with their WMI provider and MOF file with WMIDiag.
06829 14:51:25 (0) ** (This list can be built on a similar and working WMI Windows installation)
06830 14:51:25 (0) ** The following command line must be used:
06831 14:51:25 (0) ** i.e. 'WMIDiag CorrelateClassAndProvider'
06832 14:51:25 (0) ** Note: When a WMI performance class is missing, you can manually resynchronize performance counters
06833 14:51:25 (0) ** with WMI by starting the ADAP process.
06834 14:51:25 (0) ** - a WMI repository corruption.
06835 14:51:25 (0) ** In such a case, you must rerun WMIDiag with 'WriteInRepository' parameter
06836 14:51:25 (0) ** to validate the WMI repository operations.
06837 14:51:25 (0) ** Note: ENSURE you are an administrator with FULL access to WMI EVERY namespaces of the computer before
06838 14:51:25 (0) ** executing the WriteInRepository command. To write temporary data from the Root namespace, use:
06839 14:51:25 (0) ** i.e. 'WMIDiag WriteInRepository=Root'
06840 14:51:25 (0) ** - If the WriteInRepository command fails, while being an Administrator with ALL accesses to ALL namespaces
06841 14:51:25 (0) ** the WMI repository must be reconstructed.
06842 14:51:25 (0) ** Note: The WMI repository reconstruction requires to locate all MOF files needed to rebuild the repository,
06843 14:51:25 (0) ** otherwise some applications may fail after the reconstruction.
06844 14:51:25 (0) ** This can be achieved with the following command:
06845 14:51:25 (0) ** i.e. 'WMIDiag ShowMOFErrors'
06846 14:51:25 (0) ** Note: The repository reconstruction must be a LAST RESORT solution and ONLY after executing
06847 14:51:25 (0) ** ALL fixes previously mentioned.
06848 14:51:25 (2) !! WARNING: Static information stored by external applications in the repository will be LOST! (i.e. SMS Inventory)
06849 14:51:25 (0) **
06850 14:51:25 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
06851 14:51:25 (0) ** Unexpected, wrong or missing registry key values: ................................................................... 1 KEY(S)!
06852 14:51:25 (0) ** INFO: Unexpected registry key value:
06853 14:51:25 (0) ** - Current: HKLM\SOFTWARE\Microsoft\WBEM\CIMOM\Logging (REG_SZ) -> 0
06854 14:51:25 (0) ** - Expected: HKLM\SOFTWARE\Microsoft\WBEM\CIMOM\Logging (REG_SZ) -> 1
06855 14:51:25 (0) ** From the command line, the registry configuration can be corrected with the following command:
06856 14:51:25 (0) ** i.e. 'REG.EXE Add "HKLM\SOFTWARE\Microsoft\WBEM\CIMOM" /v "Logging" /t "REG_SZ" /d "1" /f'
06857 14:51:25 (0) **
06858 14:51:25 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
06859 14:51:25 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
06860 14:51:25 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
06861 14:51:25 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
06862 14:51:25 (0) **
06863 14:51:25 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
06864 14:51:25 (0) ** ------------------------------------------------------ WMI REPORT: END -----------------------------------------------------------
06865 14:51:25 (0) ** ----------------------------------------------------------------------------------------------------------------------------------
06866 14:51:25 (0) **
06867 14:51:25 (0) ** ERROR: WMIDiag detected issues that could prevent WMI to work properly!. Check 'C:\USERS\{Username}\APPDATA\LOCAL\TEMP\WMIDIAG-V2.1_2K8R2.SRV.SP1.64_{ComputerName}_2012.07.10_14.40.25.LOG' for details.
06868 14:51:25 (0) **
06869 14:51:25 (0) ** WMIDiag v2.1 ended on Tuesday, July 10, 2012 at 14:51 (W:103 E:51 S:1).Following might help
A Wmiprvse.exe process crashes in Windows Server 2008 R2 when you use the WMI interface to query the hardware status on a computer that supports the IPMI standard
http://support.microsoft.com/kb/2280777
I do not represent the organisation I work for, all the opinions expressed here are my own.
This posting is provided "AS IS" with no warranties or guarantees and confers no rights.
I saw this in my googling. Listed as the cause on the hotfix page is the following: "This
problem occurs because the Ipmiprv.dll module leads the Wmiprvse.exe process to crash. This behavior depends on certain hardware sensor types when the sensor is enumerated." The
faulting module for that hotfix is ipmiprv.dll, and our faulting module is ntdll.dll. I'm thinking that this hotfix isn't applicable, but I'm open to hearing why I'm incorrect if I am.
Seth Johnson -
Faulting module name: Flash10e.ocx, version: 10.0.45.2
Getting these flash errors periodically in my application event log.
Log Name: Application
Source: Application Error
Date: 6/7/2010 10:12:29 AM
Event ID: 1000
Task Category: (100)
Level: Error
Keywords: Classic
User: N/A
Computer: IsleOfMine
Description:
Faulting application name: iexplore.exe, version: 8.0.7600.16385, time stamp: 0x4a5bc69e
Faulting module name: Flash10e.ocx, version: 10.0.45.2, time stamp: 0x4b5f8faa
Exception code: 0xc0000005
Fault offset: 0x0012c71f
Faulting process id: 0x1158
Faulting application start time: 0x01cb065365dfc380
Faulting application path: C:\Program Files (x86)\Internet Explorer\iexplore.exe
Faulting module path: C:\Windows\SysWow64\Macromed\Flash\Flash10e.ocx
Report Id: 1607ebdb-7247-11df-853d-0023aee6baaf
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Application Error" />
<EventID Qualifiers="0">1000</EventID>
<Level>2</Level>
<Task>100</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2010-06-07T15:12:29.000000000Z" />
<EventRecordID>66779</EventRecordID>
<Channel>Application</Channel>
<Computer>IsleOfMine</Computer>
<Security />
</System>
<EventData>
<Data>iexplore.exe</Data>
<Data>8.0.7600.16385</Data>
<Data>4a5bc69e</Data>
<Data>Flash10e.ocx</Data>
<Data>10.0.45.2</Data>
<Data>4b5f8faa</Data>
<Data>c0000005</Data>
<Data>0012c71f</Data>
<Data>1158</Data>
<Data>01cb065365dfc380</Data>
<Data>C:\Program Files (x86)\Internet Explorer\iexplore.exe</Data>
<Data>C:\Windows\SysWow64\Macromed\Flash\Flash10e.ocx</Data>
<Data>1607ebdb-7247-11df-853d-0023aee6baaf</Data>
</EventData>
</Event>
Is Adobe aware? Is there a fix?Shockwave Flash Object..ActiveX Control...Flash10e.ocx (latest vs 10.0.45.2) is Enabled
Directory contents
#powershell output
#cd "C:\Windows\SysWOW64\Macromed\Flash"
#get-itemproperty * |format-list -property *
PSPath : Microsoft.PowerShell.Core\FileSystem::C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerTrust
PSParentPath : Microsoft.PowerShell.Core\FileSystem::C:\Windows\SysWOW64\Macromed\Flash
PSChildName : FlashPlayerTrust
PSDrive : C
PSProvider : Microsoft.PowerShell.Core\FileSystem
BaseName : FlashPlayerTrust
Mode : d----
Name : FlashPlayerTrust
Parent : Flash
Exists : True
Root : C:\
FullName : C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerTrust
Extension :
CreationTime : 1/8/2010 11:23:28 AM
CreationTimeUtc : 1/8/2010 5:23:28 PM
LastAccessTime : 1/8/2010 11:23:28 AM
LastAccessTimeUtc : 1/8/2010 5:23:28 PM
LastWriteTime : 1/8/2010 11:23:28 AM
LastWriteTimeUtc : 1/8/2010 5:23:28 PM
Attributes : Directory
PSPath : Microsoft.PowerShell.Core\FileSystem::C:\Windows\SysWOW64\Macromed\Flash\Flash10e.ocx
PSParentPath : Microsoft.PowerShell.Core\FileSystem::C:\Windows\SysWOW64\Macromed\Flash
PSChildName : Flash10e.ocx
PSDrive : C
PSProvider : Microsoft.PowerShell.Core\FileSystem
VersionInfo : File: C:\Windows\SysWOW64\Macromed\Flash\Flash10e.ocx
InternalName: Adobe Flash Player 10.0
OriginalFilename: Flash.ocx
FileVersion: 10,0,45,2
FileDescription: Adobe Flash Player 10.0 r45
Product: Shockwave Flash
ProductVersion: 10,0,45,2
Debug: False
Patched: False
PreRelease: False
PrivateBuild: False
SpecialBuild: False
Language: English (United States)
BaseName : Flash10e
Mode : -ar--
Name : Flash10e.ocx
Length : 3981080
DirectoryName : C:\Windows\SysWOW64\Macromed\Flash
Directory : C:\Windows\SysWOW64\Macromed\Flash
IsReadOnly : True
Exists : True
FullName : C:\Windows\SysWOW64\Macromed\Flash\Flash10e.ocx
Extension : .ocx
CreationTime : 1/26/2010 6:58:36 PM
CreationTimeUtc : 1/27/2010 12:58:36 AM
LastAccessTime : 6/6/2010 11:30:26 AM
LastAccessTimeUtc : 6/6/2010 4:30:26 PM
LastWriteTime : 1/26/2010 6:58:36 PM
LastWriteTimeUtc : 1/27/2010 12:58:36 AM
Attributes : ReadOnly, Archive
PSPath : Microsoft.PowerShell.Core\FileSystem::C:\Windows\SysWOW64\Macromed\Flash\flashplayer.xpt
PSParentPath : Microsoft.PowerShell.Core\FileSystem::C:\Windows\SysWOW64\Macromed\Flash
PSChildName : flashplayer.xpt
PSDrive : C
PSProvider : Microsoft.PowerShell.Core\FileSystem
VersionInfo : File: C:\Windows\SysWOW64\Macromed\Flash\flashplayer.xpt
InternalName:
OriginalFilename:
FileVersion:
FileDescription:
Product:
ProductVersion:
Debug: False
Patched: False
PreRelease: False
PrivateBuild: False
SpecialBuild: False
Language:
BaseName : flashplayer
Mode : -a---
Name : flashplayer.xpt
Length : 856
DirectoryName : C:\Windows\SysWOW64\Macromed\Flash
Directory : C:\Windows\SysWOW64\Macromed\Flash
IsReadOnly : False
Exists : True
FullName : C:\Windows\SysWOW64\Macromed\Flash\flashplayer.xpt
Extension : .xpt
CreationTime : 7/17/2009 10:06:32 PM
CreationTimeUtc : 7/18/2009 3:06:32 AM
LastAccessTime : 8/12/2009 7:02:37 PM
LastAccessTimeUtc : 8/13/2009 12:02:37 AM
LastWriteTime : 7/17/2009 10:06:32 PM
LastWriteTimeUtc : 7/18/2009 3:06:32 AM
Attributes : Archive
PSPath : Microsoft.PowerShell.Core\FileSystem::C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10e.exe
PSParentPath : Microsoft.PowerShell.Core\FileSystem::C:\Windows\SysWOW64\Macromed\Flash
PSChildName : FlashUtil10e.exe
PSDrive : C
PSProvider : Microsoft.PowerShell.Core\FileSystem
VersionInfo : File: C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10e.exe
InternalName: Adobe Flash Player Helper 10.0
OriginalFilename: FlashBroker.exe
FileVersion: 10,0,45,2
FileDescription: Adobe Flash Player Helper 10.0 r45
Product: Flash Player Helper
ProductVersion: 10,0,45,2
Debug: False
Patched: False
PreRelease: False
PrivateBuild: False
SpecialBuild: False
Language: English (United States)
BaseName : FlashUtil10e
Mode : -ar--
Name : FlashUtil10e.exe
Length : 256280
DirectoryName : C:\Windows\SysWOW64\Macromed\Flash
Directory : C:\Windows\SysWOW64\Macromed\Flash
IsReadOnly : True
Exists : True
FullName : C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10e.exe
Extension : .exe
CreationTime : 1/26/2010 6:58:38 PM
CreationTimeUtc : 1/27/2010 12:58:38 AM
LastAccessTime : 6/6/2010 11:30:26 AM
LastAccessTimeUtc : 6/6/2010 4:30:26 PM
LastWriteTime : 1/26/2010 6:58:38 PM
LastWriteTimeUtc : 1/27/2010 12:58:38 AM
Attributes : ReadOnly, Archive
PSPath : Microsoft.PowerShell.Core\FileSystem::C:\Windows\SysWOW64\Macromed\Flash\install.log
PSParentPath : Microsoft.PowerShell.Core\FileSystem::C:\Windows\SysWOW64\Macromed\Flash
PSChildName : install.log
PSDrive : C
PSProvider : Microsoft.PowerShell.Core\FileSystem
VersionInfo : File: C:\Windows\SysWOW64\Macromed\Flash\install.log
InternalName:
OriginalFilename:
FileVersion:
FileDescription:
Product:
ProductVersion:
Debug: False
Patched: False
PreRelease: False
PrivateBuild: False
SpecialBuild: False
Language:
BaseName : install
Mode : -a---
Name : install.log
Length : 36489
DirectoryName : C:\Windows\SysWOW64\Macromed\Flash
Directory : C:\Windows\SysWOW64\Macromed\Flash
IsReadOnly : False
Exists : True
FullName : C:\Windows\SysWOW64\Macromed\Flash\install.log
Extension : .log
CreationTime : 4/8/2009 1:32:57 PM
CreationTimeUtc : 4/8/2009 6:32:57 PM
LastAccessTime : 6/6/2010 11:30:24 AM
LastAccessTimeUtc : 6/6/2010 4:30:24 PM
LastWriteTime : 6/6/2010 11:30:29 AM
LastWriteTimeUtc : 6/6/2010 4:30:29 PM
Attributes : Archive
PSPath : Microsoft.PowerShell.Core\FileSystem::C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
PSParentPath : Microsoft.PowerShell.Core\FileSystem::C:\Windows\SysWOW64\Macromed\Flash
PSChildName : NPSWF32.dll
PSDrive : C
PSProvider : Microsoft.PowerShell.Core\FileSystem
VersionInfo : File: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
InternalName: Adobe Flash Player 10.0
OriginalFilename: npswf32.dll
FileVersion: 10,0,32,18
FileDescription: Shockwave Flash 10.0 r32
Product: Shockwave Flash
ProductVersion: 10,0,32,18
Debug: False
Patched: False
PreRelease: False
PrivateBuild: False
SpecialBuild: False
Language: English (United States)
BaseName : NPSWF32
Mode : -a---
Name : NPSWF32.dll
Length : 3883424
DirectoryName : C:\Windows\SysWOW64\Macromed\Flash
Directory : C:\Windows\SysWOW64\Macromed\Flash
IsReadOnly : False
Exists : True
FullName : C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
Extension : .dll
CreationTime : 7/17/2009 10:21:00 PM
CreationTimeUtc : 7/18/2009 3:21:00 AM
LastAccessTime : 8/12/2009 7:02:37 PM
LastAccessTimeUtc : 8/13/2009 12:02:37 AM
LastWriteTime : 7/17/2009 10:21:00 PM
LastWriteTimeUtc : 7/18/2009 3:21:00 AM
Attributes : Archive
PSPath : Microsoft.PowerShell.Core\FileSystem::C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_FlashUti l.exe
PSParentPath : Microsoft.PowerShell.Core\FileSystem::C:\Windows\SysWOW64\Macromed\Flash
PSChildName : NPSWF32_FlashUtil.exe
PSDrive : C
PSProvider : Microsoft.PowerShell.Core\FileSystem
VersionInfo : File: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_FlashUtil.exe
InternalName: Adobe Flash Player Helper 10.0
OriginalFilename: FlashBroker.exe
FileVersion: 10,0,32,18
FileDescription: Adobe Flash Player Helper 10.0 r32
Product: Flash Player Helper
ProductVersion: 10,0,32,18
Debug: False
Patched: False
PreRelease: False
PrivateBuild: False
SpecialBuild: False
Language: English (United States)
BaseName : NPSWF32_FlashUtil
Mode : -a---
Name : NPSWF32_FlashUtil.exe
Length : 257440
DirectoryName : C:\Windows\SysWOW64\Macromed\Flash
Directory : C:\Windows\SysWOW64\Macromed\Flash
IsReadOnly : False
Exists : True
FullName : C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_FlashUtil.exe
Extension : .exe
CreationTime : 7/17/2009 10:21:02 PM
CreationTimeUtc : 7/18/2009 3:21:02 AM
LastAccessTime : 8/12/2009 7:02:37 PM
LastAccessTimeUtc : 8/13/2009 12:02:37 AM
LastWriteTime : 7/17/2009 10:21:02 PM
LastWriteTimeUtc : 7/18/2009 3:21:02 AM
Attributes : Archive
PSPath : Microsoft.PowerShell.Core\FileSystem::C:\Windows\SysWOW64\Macromed\Flash\uninstall_active X.exe
PSParentPath : Microsoft.PowerShell.Core\FileSystem::C:\Windows\SysWOW64\Macromed\Flash
PSChildName : uninstall_activeX.exe
PSDrive : C
PSProvider : Microsoft.PowerShell.Core\FileSystem
VersionInfo : File: C:\Windows\SysWOW64\Macromed\Flash\uninstall_activeX.exe
InternalName:
OriginalFilename:
FileVersion: 1.0.20
FileDescription: Adobe® Flash® Player ActiveX Installer
Product: Adobe® Flash® Player ActiveX
ProductVersion: 10.0.45.2
Debug: False
Patched: False
PreRelease: False
PrivateBuild: False
SpecialBuild: False
Language: English (United States)
BaseName : uninstall_activeX
Mode : -a---
Name : uninstall_activeX.exe
Length : 84507
DirectoryName : C:\Windows\SysWOW64\Macromed\Flash
Directory : C:\Windows\SysWOW64\Macromed\Flash
IsReadOnly : False
Exists : True
FullName : C:\Windows\SysWOW64\Macromed\Flash\uninstall_activeX.exe
Extension : .exe
CreationTime : 4/8/2009 1:32:59 PM
CreationTimeUtc : 4/8/2009 6:32:59 PM
LastAccessTime : 6/6/2010 11:30:27 AM
LastAccessTimeUtc : 6/6/2010 4:30:27 PM
LastWriteTime : 6/6/2010 11:30:27 AM
LastWriteTimeUtc : 6/6/2010 4:30:27 PM
Attributes : Archive
PSPath : Microsoft.PowerShell.Core\FileSystem::C:\Windows\SysWOW64\Macromed\Flash\uninstall_plugin .exe
PSParentPath : Microsoft.PowerShell.Core\FileSystem::C:\Windows\SysWOW64\Macromed\Flash
PSChildName : uninstall_plugin.exe
PSDrive : C
PSProvider : Microsoft.PowerShell.Core\FileSystem
VersionInfo : File: C:\Windows\SysWOW64\Macromed\Flash\uninstall_plugin.exe
InternalName:
OriginalFilename:
FileVersion: 1.0.20
FileDescription: Adobe® Flash® Player Plugin Installer
Product: Adobe® Flash® Player Plugin
ProductVersion: 10.0.32.18
Debug: False
Patched: False
PreRelease: False
PrivateBuild: False
SpecialBuild: False
Language: English (United States)
BaseName : uninstall_plugin
Mode : -a---
Name : uninstall_plugin.exe
Length : 84661
DirectoryName : C:\Windows\SysWOW64\Macromed\Flash
Directory : C:\Windows\SysWOW64\Macromed\Flash
IsReadOnly : False
Exists : True
FullName : C:\Windows\SysWOW64\Macromed\Flash\uninstall_plugin.exe
Extension : .exe
CreationTime : 8/12/2009 7:02:37 PM
CreationTimeUtc : 8/13/2009 12:02:37 AM
LastAccessTime : 8/12/2009 7:02:37 PM
LastAccessTimeUtc : 8/13/2009 12:02:37 AM
LastWriteTime : 8/12/2009 7:02:37 PM
LastWriteTimeUtc : 8/13/2009 12:02:37 AM
Attributes : Archive
>>If all is correct then something else would be causing the problem.
Eidnolb, I am puzzled as to why you are dismissing Flash ocx as the problem when you have this error message. Can you explain how you arrive at that conclusion? -
Faulting application name: InDesign.exe
Hi I am a systems admin trying to sort out a problem for a client. The client will be working on files in Indesign and it will crash. Also other Adobe products are crashing Here is the errors from the application logs:
Faulting application name: InDesign.exe, version: 7.0.4.553, time stamp: 0x4d890440
Faulting module name: Public.dll, version: 7.0.4.553, time stamp: 0x4d8903ca
Exception code: 0xc0000005
Fault offset: 0x00086386
Faulting process id: 0x944
Faulting application start time: 0x01cdad8f9442ec86
Faulting application path: C:\Program Files (x86)\Adobe\Adobe InDesign CS5\InDesign.exe
Faulting module path: C:\Program Files (x86)\Adobe\Adobe InDesign CS5\Public.dll
Report Id: d644ce0a-1982-11e2-991c-70f39503ee79
Faulting application name: InDesign.exe, version: 7.0.4.553, time stamp: 0x4d890440
Faulting module name: PACKAGE AND PREFLIGHT.APLN, version: 7.0.4.553, time stamp: 0x4d890c60
Exception code: 0xc0000005
Fault offset: 0x000a091f
Faulting process id: 0x11b4
Faulting application start time: 0x01cdad7d3927e8cb
Faulting application path: C:\Program Files (x86)\Adobe\Adobe InDesign CS5\InDesign.exe
Faulting module path: C:\Program Files (x86)\Adobe\Adobe InDesign CS5\Plug-ins\PREPRESS\PACKAGE AND PREFLIGHT.APLN
Report Id: d214a4b8-1976-11e2-991c-70f39503ee79
The program InDesign.exe version 7.0.4.553 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: e80
Start Time: 01cdacaa992f0edd
Termination Time: 84
Application Path: C:\Program Files (x86)\Adobe\Adobe InDesign CS5\InDesign.exe
Report Id:
Faulting application name: Illustrator.exe, version: 15.0.2.399, time stamp: 0x4ce0f2fc
Faulting module name: Illustrator.exe, version: 15.0.2.399, time stamp: 0x4ce0f2fc
Exception code: 0xc000041d
Fault offset: 0x001f2fa9
Faulting process id: 0x1540
Faulting application start time: 0x01cdab2d0dab9c25
Faulting application path: C:\Program Files (x86)\Adobe\Adobe Illustrator CS5\Support Files\Contents\Windows\Illustrator.exe
Faulting module path: C:\Program Files (x86)\Adobe\Adobe Illustrator CS5\Support Files\Contents\Windows\Illustrator.exe
Report Id: 83f06ce6-1720-11e2-82c6-70f39503ee79
The program Illustrator.exe version 15.0.2.399 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: 408
Start Time: 01cda7617e2ec691
Termination Time: 16
Application Path: C:\Program Files (x86)\Adobe\Adobe Illustrator CS5\Support Files\Contents\Windows\Illustrator.exe
Report Id: 40de045a-1356-11e2-b4ad-70f39503ee79
The program Photoshop.exe version 12.0.4.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: 169c
Start Time: 01cda5f02fe864ed
Termination Time: 46
Application Path: C:\Program Files\Adobe\Adobe Photoshop CS5 (64 Bit)\Photoshop.exe
Report Id:
The program Bridge.exe version 4.0.5.11 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: eb8
Start Time: 01cdb23b0604ac5e
Termination Time: 31
Application Path: C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe
Report Id: 221b451f-1e44-11e2-9ea6-70f39503ee79
This we have done to fix:
- Reinstalled CS5
- Updated drivers
- Installed the Partner Certified Nvidia driver forAdobe CS5
- Removed Symantec AV
Can anybody help.
Thanks.Hi Mylenium,
Thanks for your reply. Its a Lenovo S20 4105-P15. Here are the system details
Operating System - Windows 7 Professional (64bit)
Processor - Intel® Xeon® Processor W3690 (12M Cache, 3.46 GHz, 3.73GHz Turbo 6.40 GT/s Intel® QPI)
Memory - 8GB Memory RAM
Graphics - Nvidia Quadro 2000 2GB
Is there anything else you need to know.
Thanks. -
Hello, dear colleagues!
I have problem with printing on RDS (Windows Server 2012 R2). We are executing printer drivers in isolated processes. But sometimes PrintIsolationHost.exe faults 200 times a hour and causes Print Spooler to fail.
Examples of errors:
Faulting application name: PrintIsolationHost.exe, version: 6.3.9600.16384, time stamp: 0x5215f03c
Faulting module name: ntdll.dll, version: 6.3.9600.17114, time stamp: 0x53649e73
Exception code: 0xc0000374
Fault offset: 0x00000000000f87a8
Faulting process id: 0x1347c
Faulting application start time: 0x01d0187efb514f3b
Faulting application path: C:\Windows\system32\PrintIsolationHost.exe
Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report Id: 423cfe70-8472-11e4-95a3-005056a224fb
Faulting package full name:
Faulting package-relative application ID:
Faulting application name: splwow64.exe, version: 6.3.9600.16384, time stamp: 0x5215f01d
Faulting module name: ntdll.dll, version: 6.3.9600.17114, time stamp: 0x53649e73
Exception code: 0xc0000374
Fault offset: 0x00000000000f87a8
Faulting process id: 0xae7c
Faulting application start time: 0x01d01846b8f40037
Faulting application path: C:\Windows\splwow64.exe
Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report Id: 2d5ef196-8472-11e4-95a3-005056a224fb
Faulting package full name:
Faulting package-relative application ID:
Faulting application name: spoolsv.exe, version: 6.3.9600.16384, time stamp: 0x5215d570
Faulting module name: ntdll.dll, version: 6.3.9600.17114, time stamp: 0x53649e73
Exception code: 0xc0000005
Fault offset: 0x0000000000030489
Faulting process id: 0x143b0
Faulting application start time: 0x01d0187a74d7b105
Faulting application path: C:\Windows\System32\spoolsv.exe
Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report Id: ddb33928-8472-11e4-95a3-005056a224fb
Faulting package full name:
Faulting package-relative application ID:
Faulting application name: spoolsv.exe, version: 6.3.9600.16384, time stamp: 0x5215d570
Faulting module name: KERNELBASE.dll, version: 6.3.9600.17055, time stamp: 0x532954fb
Exception code: 0xc0000002
Fault offset: 0x0000000000005bf8
Faulting process id: 0x142b8
Faulting application start time: 0x01d0187fab656d9c
Faulting application path: C:\Windows\System32\spoolsv.exe
Faulting module path: C:\Windows\system32\KERNELBASE.dll
Report Id: f10aa42a-8472-11e4-95a3-005056a224fb
Faulting package full name:
Faulting package-relative application ID:
How can I explore it?
Thanks.Hi,
Thank you for posting in Windows Server Forum.
Generally the error which you are facing occurs due to many different scenario. But the main reason to cause this will result from a corrupt or damaged version of the ntdll.dll file itself, corrupt hardware drivers, corrupt printer drivers, or issues between
Windows and other programs.
- Please run sfc /scannow from your command prompt.
- Delete the printer driver and re-install again with specific printing models.
Apart you can check below link for print spooler crash troubleshooting guides.
Print Spooler Crash Troubleshooting Steps
http://blogs.technet.com/b/perfguru/archive/2008/08/06/print-spooler-crash-troubleshooting-steps.aspx
Hope it helps!
Thanks.
Dharmesh Solanki
TechNet Community Support
Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact [email protected] -
IIS charsh with error: Faulting application name: w3wp.exe
Hi Team,Question
I am new to Window Azure. Recently I encounter a issue on my production server, where my application hosted on Azure server was automatically getting down in every 2 Hrs,when i have checked the error logs I got the error:
Faulting application name: w3wp.exe,version: 8.5.9600.16384,time stamp: 0X5215df96
Please help me out to solve the problem.
Thanks,
Ashwin
Thanks AshwinHi,
Thanks for Posting.
Please refer to the following thread which talks about the same error, and suggests analyzing the crash dump
https://social.msdn.microsoft.com/Forums/en-US/5df570d8-1f19-47b3-9d76-e737e858aa6d/iis-crash-with-faulting-application-w3wpexe-faulting-module-mscorwksdll-version-205072742?forum=clr
If this does not help, i would suggest to get a Support Ticket created so that an engineer from the TechSupport team can personally look into this issue. you can create a support ticket from within the management portal or using the following link.
http://azure.microsoft.com/en-us/support/options/
Regards,
Nithin.Rathnakar.
**There is Duplicate thread for this issue, which i will be closing marking the link for this thread.
Maybe you are looking for
-
My home sharing continually fails between mac and apple tv 2.
my home sharing continually fails between mac and apple tv 2, even during watching a movie. I go to the mac to re-turn on home sharing but it is still on. Any tips? I also have to turn off and back on at the mac every time i switch on my apple tv.
-
Can't reinstall os x - please help I'm desperate and at the end of my rope
We have an iMac G5 running OS X 10.4 all of a sudden it stopped working (when we tried to reformat a G3 ipod from PC to mac) so we restarted - it gave us the question mark restarted again, unplugged for 30 seconds, still question mark so we're readin
-
Cross company stock transfer, in which table "stock in transfer CC"
Dear Gurus, When I do cross company stock transfer, in which table quantity for "stock in transfer CC" will get updated? Rgds Sar
-
I have the latest flash player installed in my windows 7 computer. it works fine in Chrome and Firefox. When I try to use Internet Explorer, any site that calls for Flash, Internet Explorer 9 tells me I have to install Flash Player. I followed direct
-
i m rajan i want to generate report which provides me output in bold & italic format plsz help me out .