Word 97: Dr Watson

Status
This thread has been Locked and is not open to further replies. The original thread starter may use the Report button to request it be reopened but anyone else with a similar issue should start a New Thread. Watch our Welcome Guide to learn how to use this site.

chermesh

Thread Starter
Joined
Oct 22, 2000
Messages
43
Hi,
My system (win2k pro, sp2) has an office97 installation.
I can't run winword. Whenever I try, I get the following error message:
Winword.exe has generated errors and will be closed by Windows. You will need to restart the program.
An error log is being created.

The drwatson log is as follows:

Application exception occurred:
App: winword.exe (pid=644)
When: 20/10/2001 @ 19:50:35.650
Exception number: c0000005 (access violation)

*----> System Information <----*
Computer Name: RAN-HOME
User Name: Administrator
Number of Processors: 1
Processor Type: x86 Family 6 Model 7 Stepping 3
Windows 2000 Version: 5.0
Current Build: 2195
Service Pack: 2
Current Type: Uniprocessor Free
Registered Organization: Home
Registered Owner: Ran

*----> Task List <----*
0 Idle.exe
8 System.exe
156 smss.exe
184 csrss.exe
204 winlogon.exe
232 services.exe
244 lsass.exe
412 svchost.exe
440 spoolsv.exe
468 Avsynmgr.exe
480 CDANTSRV.exe
496 cisvc.exe
520 svchost.exe
536 mxtask.exe
564 NPROTECT.exe
608 OOD2000.exe
620 VSStat.exe
640 regsvc.exe
656 RVSINST.exe
664 vshwin32.exe
700 MSTask.exe
776 NOPDB.exe
816 Avconsol.exe
852 WinMgmt.exe
892 Explorer.exe
908 MsPMSPSv.exe
948 Mcshield.exe
1204 Linksts.exe
1212 point32.exe
1228 AlogServ.exe
1244 Gator.exe
1256 internat.exe
1128 babylon.exe
1276 CD_Load.exe
1304 OSA.exe
1080 isdncid.exe
1312 AcroTray.exe
1464 Integrator.exe
1180 cidaemon.exe
644 WINWORD.exe
1264 drwtsn32.exe
0 _Total.exe

(30000000 - 30510000)
(77F80000 - 77FFB000)
(30B50000 - 30CAB000)
(77E80000 - 77F35000)
(77E10000 - 77E74000)
(77F40000 - 77F7C000)
(306C0000 - 30A4C000)
(77DB0000 - 77E0B000)
(77D40000 - 77DB0000)
(77A50000 - 77B46000)
(30B40000 - 30B4C000)
(782F0000 - 78532000)
(70BD0000 - 70C1C000)
(716F0000 - 7177A000)
(77800000 - 7781D000)
(10000000 - 10012000)
(75E60000 - 75E7A000)
(6CA60000 - 6CA68000)
(66650000 - 666A4000)
(6E420000 - 6E426000)
(61210000 - 6121C000)
(775A0000 - 77625000)
(779B0000 - 77A4B000)
(78000000 - 78046000)
(77840000 - 7787C000)
(770C0000 - 770E3000)
(10040000 - 10047000)
(01BD0000 - 01C43000)
(780A0000 - 780B2000)
(01C50000 - 01D59000)
(10020000 - 1003C000)
(73280000 - 732B7000)
(6B2C0000 - 6B2C5000)
(77820000 - 77827000)
(759B0000 - 759B6000)
(01EA0000 - 01ECD000)
(61220000 - 6122E000)

State Dump for Thread Id 0x440

eax=00000018 ebx=00000004 ecx=00000001 edx=016acfec esi=0012cb08 edi=016ad000
eip=300d4f22 esp=0012c67c ebp=0012cf44 iopl=0 nv up ei pl nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000206


function: LAssistCallFn
300d4f10 49 dec ecx
300d4f11 881a mov [edx],bl ds:016acfec=0f
300d4f13 75f6 jnz LAssistCallFn+0xb244 (300daf0b)
300d4f15 5f pop edi
300d4f16 5e pop esi
300d4f17 5b pop ebx
300d4f18 c20400 ret 0x4
300d4f1b 8bc1 mov eax,ecx
300d4f1d c1e902 shr ecx,0x2
300d4f20 8bfa mov edi,edx
FAULT ->300d4f22 f3a5 rep movsd ds:0012cb08=fe988460 es:016ad000=????????
300d4f24 8bc8 mov ecx,eax
300d4f26 83e103 and ecx,0x3
300d4f29 f3a4 rep movsb ds:0012cb08=60 es:016ad000=??
300d4f2b 5f pop edi
300d4f2c 5e pop esi
300d4f2d 5b pop ebx
300d4f2e c20400 ret 0x4
300d4f31 90 nop
300d4f32 90 nop
300d4f33 90 nop
300d4f34 90 nop

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0012CF44 30236A70 016ACFC0 016A0010 00000002 00000000 winword!LAssistCallFn
0012CF68 302369BC 0012CF90 00000004 00000002 00000000 winword!IrultkAbsTokenPos
0012CFB4 3009897C 00000004 00000002 0000000A 0000011A winword!IrultkAbsTokenPos
0012DC98 3009BAB6 00000004 0000000C 0012EA2C 01000003 winword!FDeactivateIrul
0012DED4 30238626 00000000 00000000 00000000 00000000 winword!FDeactivateIrul
0012EB1C 302D8C68 0012EB4C 00000000 01000003 00000000 winword!IrultkAbsTokenPos
0012F178 302D8DFF 00000001 00000000 30759870 00000001 winword!FMsgPresent
0012F1A0 30082925 00000001 00000001 00000000 0000FF00 winword!FMsgPresent
0012F924 30079653 00000003 0012F944 0012FA48 00000001 winword!FInitStaticRuls
0012FA78 30079163 30000000 0013A8F7 00000001 00000000 winword!Ordinal139
0012FF34 30078E14 30000000 00000000 0013A8F7 00000001 winword!Ordinal139
0012FFC0 77E97D08 00000000 07B9DDFC 7FFDF000 C0000005 winword!Ordinal139
0012FFF0 00000000 30078D80 00000000 000000C8 00000100 kernel32!CreateProcessW

*----> Raw Stack Dump <----*
0012c67c 18 00 00 00 ec cf 6a 01 - 04 00 00 00 59 4c 0d 30 ......j.....YL.0
0012c68c 18 00 00 00 98 b2 6a 01 - c0 cf 6a 01 6e 6b 23 30 ......j...j.nk#0
0012c69c 18 00 00 00 c0 cf 6a 01 - e8 cf 6a 01 00 00 00 00 ......j...j.....
0012c6ac 0f 84 08 07 11 84 98 fe - 15 c6 05 00 01 08 07 06 ................
0012c6bc 45 00 00 00 b0 ff 12 00 - 5b 61 e8 77 88 e9 e8 77 E.......[a.w...w
0012c6cc 14 00 00 00 05 00 00 00 - fc c8 12 00 fc c8 12 00 ................
0012c6dc ba 0e 0a 30 44 cf 12 00 - 44 cf 12 00 ea 05 0a 30 ...0D...D......0
0012c6ec 44 cf 12 00 01 00 00 00 - 44 cf 12 00 44 cf 12 00 D.......D...D...
0012c6fc 45 00 3a 00 34 c7 12 00 - 45 00 00 00 c0 29 f8 77 E.:.4...E....).w
0012c70c 00 00 13 00 78 13 13 00 - 45 00 00 00 d0 21 13 00 ....x...E....!..
0012c71c 0c c7 12 00 00 02 00 00 - c8 c8 12 00 a7 9d fb 77 ...............w
0012c72c 08 2a f8 77 ff ff ff ff - 01 80 01 80 ff ff f9 77 .*.w...........w
0012c73c 01 80 ff ff ff ff 00 00 - 00 00 00 00 00 00 00 00 ................
0012c74c 35 26 90 01 a3 00 00 00 - 00 00 00 00 00 00 00 00 5&..............
0012c75c 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0012c76c 00 00 00 00 00 00 00 00 - 54 00 61 00 68 00 6f 00 ........T.a.h.o.
0012c77c 6d 00 61 00 00 00 00 00 - 00 00 00 00 00 00 00 00 m.a.............
0012c78c 14 00 00 00 00 00 6a 01 - 10 c9 12 00 f8 03 00 00 ......j.........
0012c79c 81 9e 75 30 00 50 e7 01 - 00 00 00 00 10 c9 12 00 ..u0.P..........
0012c7ac c8 03 90 00 44 00 00 00 - 02 00 00 00 f8 03 00 00 ....D...........

State Dump for Thread Id 0x158

eax=77d50c62 ebx=0014ae70 ecx=0014ace4 edx=00000000 esi=0014ad28 edi=00000100
eip=77f82a84 esp=00f4fe28 ebp=00f4ff74 iopl=0 nv up ei pl nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000206


function: ZwReplyWaitReceivePortEx
77f82a79 b8ac000000 mov eax,0xac
77f82a7e 8d542404 lea edx,[esp+0x4] ss:01b8d3fb=????????
77f82a82 cd2e int 2e
77f82a84 c21400 ret 0x14

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
00F4FF74 77D50781 77D50D7F 0014AD28 00000000 4014A880 ntdll!ZwReplyWaitReceivePortEx
00F4FFA8 77D50C7A 00149BF0 00F4FFEC 77E8758A 0014AE70 rpcrt4!RpcBindingSetOption
00F4FFB4 77E8758A 0014AE70 00000000 4014A880 0014AE70 rpcrt4!RpcBindingSetOption
00F4FFEC 00000000 77D50C62 0014AE70 00000000 7E447C20 kernel32!SetFilePointer

*----> Raw Stack Dump <----*
00f4fe28 2d 09 d5 77 44 01 00 00 - 54 ff f4 00 00 00 00 00 -..wD...T.......
00f4fe38 78 4e 15 00 58 ff f4 00 - d8 70 14 00 f0 9b 14 00 xN..X....p......
00f4fe48 70 ae 14 00 b0 1d 48 81 - b0 1d 48 81 00 00 00 00 p.....H...H.....
00f4fe58 01 00 00 00 b0 fb 93 be - 00 00 00 00 18 f0 27 e2 ..............'.
00f4fe68 74 fb 93 be 00 00 00 00 - 91 4e 41 80 b0 1e 48 81 t........NA...H.
00f4fe78 40 df 47 81 64 fc 93 be - a8 04 45 80 04 00 00 00 @.G.d.....E.....
00f4fe88 08 6f 8b 80 97 db 49 80 - 80 f3 12 00 00 00 00 00 .o....I.........
00f4fe98 48 f3 12 00 21 7b 05 00 - 00 00 00 00 00 00 00 00 H...!{..........
00f4fea8 01 00 00 00 19 00 02 00 - 00 00 00 00 19 00 02 00 ................
00f4feb8 00 00 00 00 00 00 00 00 - 00 00 00 00 84 02 00 00 ................
00f4fec8 00 00 00 00 08 fc 93 be - 00 00 00 00 00 00 00 00 ................
00f4fed8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00f4fee8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00f4fef8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00f4ff08 00 00 00 00 00 00 00 00 - 7b 00 00 00 7a 00 00 00 ........{...z...
00f4ff18 06 00 02 00 19 00 02 00 - d2 00 00 00 01 00 00 00 ................
00f4ff28 00 20 50 c0 e0 7b d6 83 - 00 fc c2 83 00 00 00 00 . P..{..........
00f4ff38 90 fd c2 83 60 fc 93 be - 46 02 00 00 ec d8 42 80 ....`...F.....B.
00f4ff48 c0 95 06 80 60 fd c2 83 - 00 fc c2 83 70 fc 93 be ....`.......p...
00f4ff58 00 a2 2f 4d ff ff ff ff - 50 fe f4 00 ff ff ff ff ../M....P.......

What's wrong?

Ran
 

eddie5659

Moderator
Malware Specialist
Joined
Mar 19, 2001
Messages
37,310
Hiya

Just browsing through the Latest Posts and I had a quick look at your running tasks. You have CD_Load.exe which is a spyware file. It may be of interest to get AddAware from www.lavasoftusa.com, run it ensuring that all the boxes regarding deep registry scan are checked. You can remove all it says, except any references to Web3000, or you can post the list here.

Didn't look through all, its just that that one stood out. Nothing to do with the question, but still....

Regards

eddie
 

chermesh

Thread Starter
Joined
Oct 22, 2000
Messages
43
Hi,
Thanks for all your suggestions. Since none of them solved my problems, I reinstalled office97.
Touch wood, but the problem disappeared.
Ran
 
Status
This thread has been Locked and is not open to further replies. The original thread starter may use the Report button to request it be reopened but anyone else with a similar issue should start a New Thread. Watch our Welcome Guide to learn how to use this site.

Users Who Are Viewing This Thread (Users: 0, Guests: 1)

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 807,865 other people just like you!

Members online

Top