okay, I think this is it:
*----> State Dump for Thread Id 0xac8 <----*
eax=00000000 ebx=00000000 ecx=00000002 edx=00000000 esi=77fc306c edi=00000000
eip=7ffe0304 esp=0091fc0c ebp=0091fc94 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202
function: <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 8bd4 mov edx,esp
7ffe0307 0f05 syscall
7ffe0309 c3 ret
7ffe030a 8ac8 mov cl,al
7ffe030c ff1570464d80 call dword ptr [804d4670]
7ffe0312 8b4510 mov eax,[ebp+0x10]
7ffe0315 33c9 xor ecx,ecx
7ffe0317 663908 cmp [eax],cx
7ffe031a 894dfc mov [ebp-0x4],ecx
7ffe031d 0f840d000000 je 7ffe0330
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0091fc08 77f7671a 77f51bdb 0000017c 00000000 *SharedUserSystemCall+0xc (FPO: [0,0,0])
0091fc94 77f7561d 01fc306c 77f586d2 77fc306c ntdll!NtWaitForSingleObject+0xc
0091fd18 77fb4d8a 0091fd2c 77f50000 00000000 ntdll!RtlEnterCriticalSection+0x3f
00000000 00000000 00000000 00000000 00000000 ntdll!KiUserApcDispatcher+0x7
*----> Raw Stack Dump <----*
000000000091fc0c 1a 67 f7 77 db 1b f5 77 - 7c 01 00 00 00 00 00 00 .g.w...w|.......
000000000091fc1c 00 00 00 00 00 e0 fa 7f - 00 f0 fd 7f 00 00 00 00 ................
000000000091fc2c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000091fc3c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000091fc4c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000091fc5c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000091fc6c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000091fc7c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000091fc8c 00 00 00 00 7c 01 00 00 - 18 fd 91 00 1d 56 f7 77 ....|........V.w
000000000091fc9c 6c 30 fc 01 d2 86 f5 77 - 6c 30 fc 77 2c fd 91 00 l0.....wl0.w,...
000000000091fcac 04 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000091fcbc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000091fccc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000091fcdc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000091fcec 00 e0 fa 7f 00 f0 fd 7f - 00 00 00 00 00 00 00 00 ................
000000000091fcfc 00 00 00 00 a8 fc 91 00 - 00 00 00 00 ff ff ff ff ................
000000000091fd0c 05 90 f7 77 10 dd f6 77 - ff ff ff ff 00 00 00 00 ...w...w........
000000000091fd1c 8a 4d fb 77 2c fd 91 00 - 00 00 f5 77 00 00 00 00 .M.w,......w....
000000000091fd2c 17 00 01 00 ff ff 00 00 - ff ff 00 00 ff ff 00 00 ................
000000000091fd3c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 01 ................
The error signature is:
BCCode : 1000008e BCP1 : C0000005 BCP2 : 00000000 BCP3 : F4B0DC50
BCP4 : 00000000 OSVer : 5_1_2600 SP : 1_0 Product : 768_1
The files in the report are:
C:\WINDOWS\Minidump\Mini091805-02.dmp
C:\DOCUME~1\Moira\LOCALS~1\Temp\WER2.tmp.dir00\sysdata.xml