Event viewer now crashes if I attempt to sort by date or time.

Event viewer now crashes if I attempt to sort by date or time.

Post by Robbie Hat » Tue, 09 Mar 2010 18:19:57


ust yesterday, my Event Viewer starting crashing if I click on the
"Time" or "Date" headers. What could cause this? Hopefully the
program itself (mmc or it's event-viewer plugin) is not corrupt.
I'm hoping it's due to something else, like too much data
overflowing a buffer, or some needed service is stopped or disabled.

I see that Dr. Watson records these crashes. He says, for what
(if anything) it's worth:

============ BEGIN DR. WATSON'S REPORT =================================

Application exception occurred:
App: mmc.exe (pid=888)
When: 2010-03-08 @ 00:09:24.875
Exception number: c0000005 (access violation)

*----> System Information <----*
Computer Name: [removed for security reasons]
User Name: [removed for security reasons]
Number of Processors: 1
Processor Type: x86 Family 6 Model 10 Stepping 0
Windows 2000 Version: 5.0
Current Build: 2195
Service Pack: 4
Current Type: Uniprocessor Free
Registered Organization: Tustin Free Zone
Registered Owner: Robbie Hatley

*----> Task List <----*
0 Idle.exe
8 System.exe
160 SMSS.exe
188 CSRSS.exe
208 WINLOGON.exe
236 SERVICES.exe
248 LSASS.exe
400 svchost.exe
424 spoolsv.exe
456 svchost.exe
484 NPROTECT.exe
536 nvsvc32.exe
604 stisvc.exe
688 svchost.exe
372 WinMgmt.exe
932 explorer.exe
1024 rundll32.exe
1032 sstray.exe
1040 E_FATIACA.exe
740 firefox.exe
888 mmc.exe
940 DRWTSN32.exe
0 _Total.exe

(01000000 - 01098000)
(77F80000 - 77FFC000)
(76FB0000 - 770AB000)
(78000000 - 78045000)
(7C570000 - 7C624000)
(77F40000 - 77F7D000)
(77E10000 - 77E6F000)
(780C0000 - 7814D000)
(773E0000 - 773F6000)
(7C2D0000 - 7C335000)
(77D30000 - 77D9F000)
(779B0000 - 77A4C000)
(7CE20000 - 7CF0F000)
(71710000 - 71794000)
(7CF30000 - 7D176000)
(70A70000 - 70AD6000)
(75E60000 - 75E7A000)
(6CA60000 - 6CA68000)
(66650000 - 666A4000)
(7C950000 - 7C9DF000)
(77840000 - 7787E000)
(770C0000 - 770E3000)
(7D190000 - 7D261000)
(76B30000 - 76B6E000)
(71320000 - 7134B000)
(7CDC0000 - 7CE10000)
(7C340000 - 7C34E000)
(77BF0000 - 77C01000)
(77980000 - 779A5000)
(75050000 - 75058000)
(75030000 - 75044000)
(75020000 - 75028000)
(77950000 - 7797B000)
(751C0000 - 751C6000)
(75150000 - 75160000)
(77820000 - 77827000)
(759B0000 - 759B6000)
(773B0000 - 773DF000)
(77380000 - 773A3000)
(76620000 - 76631000)
(76B20000 - 76B25000)
(772B0000 - 7731D000)
(70440000 - 704CF000)

State Dump for Thread Id 0x370

eax=0006e2d8 ebx=00c3d64c ecx=0006e324 edx=00c3dadc esi=00000000 edi=00c8b274
eip=71332715 esp=0006e0c0 ebp=0006e2f0 iopl=0 nv up ei ng nz ac pe cy
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000293


function: <nosymbols>
713326ef 83f807 cmp eax,0x7
713326f2 0f87fd000000 jnbe 713327f5
713326f8 ff248532283371 jmp dword ptr [71332832+eax*4] ds:0006e2d8=000107b2
713326ff 8a4618 mov al,[esi+0x18] ds:00b09ee6=??
71332702 8807 mov [edi],al ds:00c8b274=00
71332704 e9ec000000 jmp 713327f5
71332709 8b460c mov eax,[esi+0xc] ds:00b09ee6=????????
7133270c e9e2000000 jmp 713327f3
71332711 8d45e8 lea eax,[ebp+0xe8] ss:00b781d6=????????