Link to home
Start Free TrialLog in
Avatar of dcmathis
dcmathis

asked on

IE Crashes several times per day. Always the same error.

Hello, I have a user who is experiencing periodic IE 7 crashes.  When it crashes, event logged states:

++++++++++++++++++++++++++++++++++++++++++++++++++++
Event Type:      Error
Event Source:      Application Error
Event Category:      None
Event ID:      1000
Date:            11/24/2008
Time:            9:36:35 AM
User:            N/A
Computer:      CHANUS1
Description:
Faulting application iexplore.exe, version 7.0.6000.16735, faulting module rpcrt4.dll, version 5.1.2600.5512, fault address 0x000093df.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74   Applicat
0008: 69 6f 6e 20 46 61 69 6c   ion Fail
0010: 75 72 65 20 20 69 65 78   ure  iex
0018: 70 6c 6f 72 65 2e 65 78   plore.ex
0020: 65 20 37 2e 30 2e 36 30   e 7.0.60
0028: 30 30 2e 31 36 37 33 35   00.16735
0030: 20 69 6e 20 72 70 63 72    in rpcr
0038: 74 34 2e 64 6c 6c 20 35   t4.dll 5
0040: 2e 31 2e 32 36 30 30 2e   .1.2600.
0048: 35 35 31 32 20 61 74 20   5512 at
0050: 6f 66 66 73 65 74 20 30   offset 0
0058: 30 30 30 39 33 64 66 0d   00093df.
0060: 0a                        .      

++++++++++++++++++++++++++++++++++++++++++++++++++++


Look in the code section for the output from Dr. Watson.



Can anybody help me figure out what is causing this?  It seems to happen several times a day for a while, and then it won't happen for several days.


Thanks for any help you can offer.


Application exception occurred:
        App: C:\Program Files\Internet Explorer\IEXPLORE.EXE (pid=3760)
        When: 11/13/2008 @ 16:36:24.508
        Exception number: c0000005 (access violation)
 
*----> System Information <----*
        Computer Name: CHANUS1
        User Name: crystal_h
        Terminal Session Id: 0
        Number of Processors: 2
        Processor Type: x86 Family 15 Model 4 Stepping 3
        Windows Version: 5.1
        Current Build: 2600
        Service Pack: 3
        Current Type: Multiprocessor Free
        Registered Organization: GVNW Consulting, Inc.
        Registered Owner: Any User
 
*----> Task List <----*
   0 System Process
   4 Error 0xD0000022
 784 Error 0xD0000022
 832 Error 0xD0000022
 856 Error 0xD0000022
 900 Error 0xD0000022
 912 Error 0xD0000022
1108 Error 0xD0000022
1192 Error 0xD0000022
1316 Error 0xD0000022
1360 Error 0xD0000022
1372 Error 0xD0000022
1668 Error 0xD0000022
1744 Error 0xD0000022
1884 Error 0xD0000022
 216 Error 0xD0000022
 288 Error 0xD0000022
 308 Error 0xD0000022
 620 Error 0xD0000022
 688 Error 0xD0000022
 468 Error 0xD0000022
 756 Error 0xD0000022
 984 Error 0xD0000022
1132 Error 0xD0000022
1284 Error 0xD0000022
1572 Error 0xD0000022
1612 Error 0xD0000022
1632 Error 0xD0000022
1696 Error 0xD0000022
 552 Error 0xD0000022
1220 DWRCST.exe
2576 Explorer.EXE
2996 igfxtray.exe
3016 OUTLOOK.EXE
2948 igfxpers.exe
3180 PDVDServ.exe
3200 zHotkey.exe
3252 PDFClient.exe
3268 QTTask.exe
3388 iTunesHelper.exe
3516 ctfmon.exe
3468 ALMon.exe
3908 apcsystray.exe
 524 Error 0xD0000022
3760 IEXPLORE.EXE
1128 CacheCleaner.exe
1000 EXCEL.EXE
2728 drwtsn32.exe
 
*----> Module List <----*
(0000000000400000 - 000000000049b000: C:\Program Files\Internet Explorer\IEXPLORE.EXE
(0000000000c10000 - 0000000000ed5000: C:\WINDOWS\system32\xpsp2res.dll
(0000000001640000 - 000000000169b000: C:\Program Files\Common Files\Microsoft Shared\INK\SKCHUI.DLL
(00000000017e0000 - 00000000017e9000: C:\WINDOWS\system32\Normaliz.dll
(0000000001a20000 - 0000000001a72000: C:\WINDOWS\Downloaded Program Files\urSuperHost.dll
(0000000002570000 - 0000000002581000: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
(00000000025b0000 - 00000000025c0000: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
(00000000025d0000 - 000000000266b000: C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\MSVCR80.dll
(0000000005420000 - 000000000547b000: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
(0000000005680000 - 00000000056c0000: C:\WINDOWS\Downloaded Program Files\InstallerControl.dll
(0000000005e20000 - 0000000005e52000: C:\WINDOWS\Downloaded Program Files\cachecleaner.dll
(0000000008ca0000 - 0000000008dad000: C:\WINDOWS\Downloaded Program Files\urTermProxy.dll
(0000000010000000 - 0000000010011000: C:\WINDOWS\IME\SPGRMR.DLL
(0000000016080000 - 00000000160a5000: C:\Program Files\Bonjour\mdnsNSP.dll
(000000001b000000 - 000000001b00c000: C:\WINDOWS\system32\ImgUtil.dll
(000000001c000000 - 000000001c006000: C:\WINDOWS\HKNTDLL.dll
(00000000325c0000 - 00000000325d2000: C:\Program Files\Microsoft Office\OFFICE11\msohev.dll
(0000000042aa0000 - 0000000042b12000: C:\WINDOWS\system32\msfeeds.dll
(0000000042b90000 - 0000000042c07000: C:\WINDOWS\system32\mshtmled.dll
(0000000042ef0000 - 00000000434bd000: C:\WINDOWS\system32\IEFRAME.dll
(0000000043560000 - 00000000435c0000: C:\WINDOWS\system32\ieapfltr.dll
(00000000435d0000 - 0000000043944000: C:\WINDOWS\system32\mshtml.dll
(0000000047060000 - 0000000047081000: C:\WINDOWS\system32\xmllite.dll
(000000004ec50000 - 000000004edf6000: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5581_x-ww_dfbc4fc4\gdiplus.dll
(000000005a000000 - 000000005a03d000: C:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll
(000000005a8f0000 - 000000005a900000: C:\Program Files\Sophos\Sophos Anti-Virus\SophosBHORes.dll
(000000005ad70000 - 000000005ada8000: C:\WINDOWS\system32\UxTheme.dll
(000000005b860000 - 000000005b8b5000: C:\WINDOWS\system32\NETAPI32.dll
(000000005c2c0000 - 000000005c300000: C:\WINDOWS\ime\sptip.dll
(000000005d090000 - 000000005d12a000: C:\WINDOWS\system32\comctl32.dll
(000000005dff0000 - 000000005e01f000: C:\WINDOWS\system32\IEUI.dll
(000000005edd0000 - 000000005ede7000: C:\WINDOWS\system32\OLEPRO32.DLL
(00000000605d0000 - 00000000605d9000: C:\WINDOWS\system32\mslbui.dll
(0000000061930000 - 000000006197a000: C:\Program Files\Internet Explorer\ieproxy.dll
(00000000662b0000 - 0000000066308000: C:\WINDOWS\system32\hnetcfg.dll
(0000000068000000 - 0000000068036000: C:\WINDOWS\system32\rsaenh.dll
(0000000068100000 - 0000000068126000: C:\WINDOWS\system32\dssenh.dll
(000000006cc60000 - 000000006cc68000: C:\WINDOWS\system32\dispex.dll
(000000006d430000 - 000000006d43a000: C:\WINDOWS\system32\ddrawex.dll
(000000006d610000 - 000000006d67a000: C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
(0000000071a50000 - 0000000071a8f000: C:\WINDOWS\system32\mswsock.dll
(0000000071a90000 - 0000000071a98000: C:\WINDOWS\System32\wshtcpip.dll
(0000000071aa0000 - 0000000071aa8000: C:\WINDOWS\system32\WS2HELP.dll
(0000000071ab0000 - 0000000071ac7000: C:\WINDOWS\system32\ws2_32.dll
(0000000071b20000 - 0000000071b32000: C:\WINDOWS\system32\MPR.dll
(0000000071bf0000 - 0000000071c03000: C:\WINDOWS\system32\SAMLIB.dll
(0000000071c10000 - 0000000071c1e000: C:\WINDOWS\System32\ntlanman.dll
(0000000071c80000 - 0000000071c87000: C:\WINDOWS\System32\NETRAP.dll
(0000000071c90000 - 0000000071cd0000: C:\WINDOWS\System32\NETUI1.dll
(0000000071cd0000 - 0000000071ce7000: C:\WINDOWS\System32\NETUI0.dll
(0000000071d40000 - 0000000071d5b000: C:\WINDOWS\system32\actxprxy.dll
(00000000722b0000 - 00000000722b5000: C:\WINDOWS\system32\sensapi.dll
(0000000072d10000 - 0000000072d18000: C:\WINDOWS\system32\msacm32.drv
(0000000072d20000 - 0000000072d29000: C:\WINDOWS\system32\wdmaud.drv
(0000000073000000 - 0000000073026000: C:\WINDOWS\system32\WINSPOOL.DRV
(0000000073760000 - 00000000737ab000: C:\WINDOWS\system32\DDRAW.dll
(0000000073b30000 - 0000000073b45000: C:\WINDOWS\system32\mscms.dll
(0000000073bc0000 - 0000000073bc6000: C:\WINDOWS\system32\DCIMAN32.dll
(00000000746c0000 - 00000000746e9000: C:\WINDOWS\system32\msls31.dll
(00000000746f0000 - 000000007471a000: C:\WINDOWS\system32\msimtf.dll
(0000000074720000 - 000000007476c000: C:\WINDOWS\system32\MSCTF.dll
(0000000074980000 - 0000000074a94000: C:\WINDOWS\system32\msxml3.dll
(0000000074c80000 - 0000000074cac000: C:\WINDOWS\system32\OLEACC.dll
(0000000074d90000 - 0000000074dfb000: C:\WINDOWS\system32\USP10.dll
(00000000755c0000 - 00000000755ee000: C:\WINDOWS\system32\msctfime.ime
(0000000075c50000 - 0000000075ccd000: C:\WINDOWS\system32\jscript.dll
(0000000075cf0000 - 0000000075d81000: C:\WINDOWS\system32\MLANG.dll
(0000000075f60000 - 0000000075f67000: C:\WINDOWS\System32\drprov.dll
(0000000075f70000 - 0000000075f7a000: C:\WINDOWS\System32\davclnt.dll
(0000000076080000 - 00000000760e5000: C:\WINDOWS\system32\MSVCP60.dll
(0000000076380000 - 0000000076385000: C:\WINDOWS\system32\MSIMG32.dll
(0000000076390000 - 00000000763ad000: C:\WINDOWS\system32\IMM32.DLL
(0000000076600000 - 000000007661d000: C:\WINDOWS\System32\CSCDLL.dll
(00000000767f0000 - 0000000076817000: C:\WINDOWS\system32\schannel.dll
(00000000769c0000 - 0000000076a74000: C:\WINDOWS\system32\USERENV.dll
(0000000076b40000 - 0000000076b6d000: C:\WINDOWS\system32\WINMM.dll
(0000000076bf0000 - 0000000076bfb000: C:\WINDOWS\system32\PSAPI.DLL
(0000000076c30000 - 0000000076c5e000: C:\WINDOWS\system32\WINTRUST.dll
(0000000076c90000 - 0000000076cb8000: C:\WINDOWS\system32\IMAGEHLP.dll
(0000000076d60000 - 0000000076d79000: C:\WINDOWS\system32\iphlpapi.dll
(0000000076e80000 - 0000000076e8e000: C:\WINDOWS\system32\rtutils.dll
(0000000076e90000 - 0000000076ea2000: C:\WINDOWS\system32\rasman.dll
(0000000076eb0000 - 0000000076edf000: C:\WINDOWS\system32\TAPI32.dll
(0000000076ee0000 - 0000000076f1c000: C:\WINDOWS\system32\RASAPI32.dll
(0000000076f20000 - 0000000076f47000: C:\WINDOWS\system32\DNSAPI.dll
(0000000076f60000 - 0000000076f8c000: C:\WINDOWS\system32\WLDAP32.dll
(0000000076fb0000 - 0000000076fb8000: C:\WINDOWS\System32\winrnr.dll
 
 
(0000000076fc0000 - 0000000076fc6000: C:\WINDOWS\system32\rasadhlp.dll
(0000000076fd0000 - 000000007704f000: C:\WINDOWS\system32\CLBCATQ.DLL
(0000000077050000 - 0000000077115000: C:\WINDOWS\system32\COMRes.dll
(0000000077120000 - 00000000771ab000: C:\WINDOWS\system32\OLEAUT32.dll
(00000000773d0000 - 00000000774d3000: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
(00000000774e0000 - 000000007761d000: C:\WINDOWS\system32\ole32.dll
(0000000077690000 - 00000000776b1000: C:\WINDOWS\system32\NTMARTA.DLL
(0000000077920000 - 0000000077a13000: C:\WINDOWS\system32\SETUPAPI.dll
(0000000077a20000 - 0000000077a74000: C:\WINDOWS\System32\cscui.dll
(0000000077a80000 - 0000000077b15000: C:\WINDOWS\system32\CRYPT32.dll
(0000000077b20000 - 0000000077b32000: C:\WINDOWS\system32\MSASN1.dll
(0000000077b40000 - 0000000077b62000: C:\WINDOWS\system32\apphelp.dll
(0000000077bd0000 - 0000000077bd7000: C:\WINDOWS\system32\midimap.dll
(0000000077be0000 - 0000000077bf5000: C:\WINDOWS\system32\MSACM32.dll
(0000000077c00000 - 0000000077c08000: C:\WINDOWS\system32\VERSION.dll
(0000000077c10000 - 0000000077c68000: C:\WINDOWS\system32\msvcrt.dll
(0000000077c70000 - 0000000077c94000: C:\WINDOWS\system32\msv1_0.dll
(0000000077dd0000 - 0000000077e6b000: C:\WINDOWS\system32\ADVAPI32.dll
(0000000077e70000 - 0000000077f02000: C:\WINDOWS\system32\RPCRT4.dll
(0000000077f10000 - 0000000077f59000: C:\WINDOWS\system32\GDI32.dll
(0000000077f60000 - 0000000077fd6000: C:\WINDOWS\system32\SHLWAPI.dll
(0000000077fe0000 - 0000000077ff1000: C:\WINDOWS\system32\Secur32.dll
(0000000078000000 - 0000000078045000: C:\WINDOWS\system32\iertutil.dll
(0000000078050000 - 0000000078120000: C:\WINDOWS\system32\WININET.dll
(0000000078130000 - 0000000078257000: C:\WINDOWS\system32\urlmon.dll
(000000007c420000 - 000000007c4a7000: C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\MSVCP80.dll
(000000007c800000 - 000000007c8f6000: C:\WINDOWS\system32\kernel32.dll
(000000007c900000 - 000000007c9af000: C:\WINDOWS\system32\ntdll.dll
(000000007c9c0000 - 000000007d1d7000: C:\WINDOWS\system32\SHELL32.dll
(000000007d1e0000 - 000000007d49c000: C:\WINDOWS\system32\msi.dll
(000000007e410000 - 000000007e4a1000: C:\WINDOWS\system32\USER32.dll
(000000007e720000 - 000000007e7d0000: C:\WINDOWS\system32\SXS.DLL
 
*----> State Dump for Thread Id 0x9a4 <----*
 
eax=00000001 ebx=0012e6c4 ecx=7c8095a4 edx=7c90e4f4 esi=00000000 edi=7ffde000
eip=7c90e4f4 esp=0012e69c ebp=0012e738 iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246
 
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\ntdll.dll - 
function: ntdll!KiFastSystemCallRet
        7c90e4da e829000000       call    ntdll!RtlRaiseException (7c90e508)
        7c90e4df 8b0424           mov     eax,[esp]
        7c90e4e2 8be5             mov     esp,ebp
        7c90e4e4 5d               pop     ebp
        7c90e4e5 c3               ret
        7c90e4e6 8da42400000000   lea     esp,[esp]
        7c90e4ed 8d4900           lea     ecx,[ecx]
        ntdll!KiFastSystemCall:
        7c90e4f0 8bd4             mov     edx,esp
        7c90e4f2 0f34             sysenter
        ntdll!KiFastSystemCallRet:
        7c90e4f4 c3               ret
        7c90e4f5 8da42400000000   lea     esp,[esp]
        7c90e4fc 8d642400         lea     esp,[esp]
        ntdll!KiIntSystemCall:
        7c90e500 8d542408         lea     edx,[esp+0x8]
        7c90e504 cd2e             int     2e
        7c90e506 c3               ret
        7c90e507 90               nop
        ntdll!RtlRaiseException:
        7c90e508 55               push    ebp
        7c90e509 8bec             mov     ebp,esp
 
*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\USER32.dll - 
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\IEUI.dll - 
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\IEFRAME.dll - 
*** ERROR: Module load completed but symbols could not be loaded for C:\Program Files\Internet Explorer\IEXPLORE.EXE
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\kernel32.dll - 
ChildEBP RetAddr  Args to Child              
0012e738 7e4195f9 00000002 0012e760 00000000 ntdll!KiFastSystemCallRet
0012e794 5dff6029 00000001 0012e7c8 ffffffff USER32!GetLastInputInfo+0x105
0012e7b4 5dff632d 000004ff ffffffff 00000000 IEUI!DUserRegisterSuper+0x9bd
0012e7dc 5dff60d8 000004ff 00000000 42fa98cd IEUI!PeekMessageExW+0x21f
0012e818 42f9ab4c 0014fe80 0012e848 42f9bbbb IEUI!WaitMessageEx+0x31
0012e824 42f9bbbb 00000000 00000000 0014cec0 IEFRAME!Ordinal300+0xfb0a
0012e848 42f9bb09 19a4000a 0014cec0 00000000 IEFRAME!Ordinal101+0x341
0012f8b8 42f9b9b9 0014cec0 77f648d4 00000000 IEFRAME!Ordinal101+0x28f
0012fae8 0040147c 00144ee0 0000000a 00410070 IEFRAME!Ordinal101+0x13f
0012ff2c 00401317 00400000 00000000 000206c4 IEXPLORE+0x147c
0012ffc0 7c817067 000945d8 00e4f0dc 7ffde000 IEXPLORE+0x1317
0012fff0 00000000 00402e45 00000000 78746341 kernel32!RegisterWaitForInputIdle+0x49
 
*----> Raw Stack Dump <----*
000000000012e69c  2c df 90 7c 74 95 80 7c - 02 00 00 00 c4 e6 12 00  ,..|t..|........
000000000012e6ac  01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000012e6bc  02 00 00 00 00 00 00 00 - 28 01 00 00 28 00 00 00  ........(...(...
000000000012e6cc  00 00 00 00 00 00 00 00 - a0 e6 12 00 00 00 00 00  ................
000000000012e6dc  30 e7 12 00 8f 04 44 7e - 14 00 00 00 01 00 00 00  0.....D~........
000000000012e6ec  00 00 00 00 00 00 00 00 - 10 00 00 00 cd c5 fb 42  ...............B
000000000012e6fc  68 01 08 00 0f 00 00 00 - 00 e0 fd 7f 00 d0 fd 7f  h...............
000000000012e70c  44 e2 5e 00 00 00 00 00 - c4 e6 12 00 01 00 00 00  D.^.............
000000000012e71c  02 00 00 00 b8 e6 12 00 - ff ff ff ff b0 ff 12 00  ................
000000000012e72c  c0 9a 83 7c 68 96 80 7c - 00 00 00 00 94 e7 12 00  ...|h..|........
000000000012e73c  f9 95 41 7e 02 00 00 00 - 60 e7 12 00 00 00 00 00  ..A~....`.......
000000000012e74c  ff ff ff ff 00 00 00 00 - ff ff ff ff 01 00 00 00  ................
000000000012e75c  01 00 00 00 28 01 00 00 - 28 00 00 00 bd 62 ff 5d  ....(...(....b.]
000000000012e76c  f3 73 1d 03 a8 62 15 00 - 01 00 00 00 00 00 00 00  .s...b..........
000000000012e77c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000012e78c  00 d0 fd 7f 28 00 00 00 - b4 e7 12 00 29 60 ff 5d  ....(.......)`.]
000000000012e79c  01 00 00 00 c8 e7 12 00 - ff ff ff ff ff 04 00 00  ................
000000000012e7ac  60 e7 12 00 f0 61 15 00 - dc e7 12 00 2d 63 ff 5d  `....a......-c.]
000000000012e7bc  ff 04 00 00 ff ff ff ff - 00 00 00 00 28 01 00 00  ............(...
000000000012e7cc  00 00 00 00 48 78 f9 42 - 80 fe 14 00 9f 00 00 00  ....Hx.B........
 
*----> State Dump for Thread Id 0xa80 <----*
 
eax=00000000 ebx=0113fde8 ecx=0113ffa4 edx=7c90e4f4 esi=00000000 edi=7ffde000
eip=7c90e4f4 esp=0113fdc0 ebp=0113fe5c iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246
 
function: ntdll!KiFastSystemCallRet
        7c90e4da e829000000       call    ntdll!RtlRaiseException (7c90e508)
        7c90e4df 8b0424           mov     eax,[esp]
        7c90e4e2 8be5             mov     esp,ebp
        7c90e4e4 5d               pop     ebp
        7c90e4e5 c3               ret
        7c90e4e6 8da42400000000   lea     esp,[esp]
        7c90e4ed 8d4900           lea     ecx,[ecx]
        ntdll!KiFastSystemCall:
        7c90e4f0 8bd4             mov     edx,esp
        7c90e4f2 0f34             sysenter
        ntdll!KiFastSystemCallRet:
        7c90e4f4 c3               ret
        7c90e4f5 8da42400000000   lea     esp,[esp]
        7c90e4fc 8d642400         lea     esp,[esp]
        ntdll!KiIntSystemCall:
        7c90e500 8d542408         lea     edx,[esp+0x8]
        7c90e504 cd2e             int     2e
        7c90e506 c3               ret
        7c90e507 90               nop
        ntdll!RtlRaiseException:
        7c90e508 55               push    ebp
        7c90e509 8bec             mov     ebp,esp
 
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\msvcrt.dll - 
ChildEBP RetAddr  Args to Child              
0113fe5c 7e4195f9 00000002 0113fe84 00000000 ntdll!KiFastSystemCallRet
0113feb8 5dff6029 00000001 0113feec ffffffff USER32!GetLastInputInfo+0x105
0113fed8 5dff93e4 000004ff ffffffff 00000001 IEUI!DUserRegisterSuper+0x9bd
0113ff0c 5dff98a6 0113ff4c 00000000 00000000 IEUI!SetGadgetParent+0x53d
0113ff2c 5dff9806 0113ff4c 00000000 00000000 IEUI!GetMessageExA+0x3d
0113ff80 77c3a3b0 00000000 7c910000 7c912cae IEUI!SetGadgetParent+0x95f
0113ffb4 7c80b713 008d51e8 7c910000 7c912cae msvcrt!endthreadex+0xa9
0113ffec 00000000 77c3a341 008d51e8 00000000 kernel32!GetModuleFileNameA+0x1b4
 
*----> Raw Stack Dump <----*
000000000113fdc0  2c df 90 7c 74 95 80 7c - 02 00 00 00 e8 fd 13 01  ,..|t..|........
000000000113fdd0  01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000113fde0  02 00 00 00 04 00 00 00 - 20 01 00 00 1c 01 00 00  ........ .......
000000000113fdf0  78 01 14 00 0c fe 13 01 - 79 a2 ff 5d 5f 3b 01 da  x.......y..]_;..
000000000113fe00  b0 02 00 00 20 00 00 00 - 14 00 00 00 01 00 00 00  .... ...........
000000000113fe10  00 00 00 00 00 00 00 00 - 10 00 00 00 f8 e8 0f 0c  ................
000000000113fe20  2c fe 13 01 c5 6f ff 5d - 00 e0 fd 7f 00 b0 fd 7f  ,....o.]........
000000000113fe30  a2 6f ff 5d 00 00 00 00 - e8 fd 13 01 94 fe 13 01  .o.]............
000000000113fe40  02 00 00 00 dc fd 13 01 - 63 6f ff 5d a4 ff 13 01  ........co.]....
000000000113fe50  c0 9a 83 7c 68 96 80 7c - 00 00 00 00 b8 fe 13 01  ...|h..|........
000000000113fe60  f9 95 41 7e 02 00 00 00 - 84 fe 13 01 00 00 00 00  ..A~............
000000000113fe70  ff ff ff ff 00 00 00 00 - ff ff ff ff 01 00 00 00  ................
000000000113fe80  01 00 00 00 20 01 00 00 - 1c 01 00 00 bd 62 ff 5d  .... ........b.]
000000000113fe90  c3 e2 42 02 28 47 15 00 - 01 00 00 00 00 00 00 00  ..B.(G..........
000000000113fea0  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000113feb0  00 b0 fd 7f 1c 01 00 00 - d8 fe 13 01 29 60 ff 5d  ............)`.]
000000000113fec0  01 00 00 00 ec fe 13 01 - ff ff ff ff ff 04 00 00  ................
000000000113fed0  84 fe 13 01 70 46 15 00 - 0c ff 13 01 e4 93 ff 5d  ....pF.........]
000000000113fee0  ff 04 00 00 ff ff ff ff - 01 00 00 00 20 01 00 00  ............ ...
000000000113fef0  00 00 00 00 00 00 00 00 - e8 51 8d 00 01 00 00 00  .........Q......
 
*----> State Dump for Thread Id 0xac0 <----*
 
eax=000025ff ebx=00000000 ecx=00000210 edx=00000000 esi=0018b0a8 edi=00000000
eip=7c90e4f4 esp=01bfff50 ebp=01bfffb4 iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246
 
function: ntdll!KiFastSystemCallRet
        7c90e4da e829000000       call    ntdll!RtlRaiseException (7c90e508)
        7c90e4df 8b0424           mov     eax,[esp]
        7c90e4e2 8be5             mov     esp,ebp
        7c90e4e4 5d               pop     ebp
        7c90e4e5 c3               ret
        7c90e4e6 8da42400000000   lea     esp,[esp]
        7c90e4ed 8d4900           lea     ecx,[ecx]
        ntdll!KiFastSystemCall:
        7c90e4f0 8bd4             mov     edx,esp
        7c90e4f2 0f34             sysenter
        ntdll!KiFastSystemCallRet:
        7c90e4f4 c3               ret
        7c90e4f5 8da42400000000   lea     esp,[esp]
        7c90e4fc 8d642400         lea     esp,[esp]
        ntdll!KiIntSystemCall:
        7c90e500 8d542408         lea     edx,[esp+0x8]
        7c90e504 cd2e             int     2e
        7c90e506 c3               ret
        7c90e507 90               nop
        ntdll!RtlRaiseException:
        7c90e508 55               push    ebp
        7c90e509 8bec             mov     ebp,esp
 
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr  Args to Child              
01bfffb4 7c80b713 00191400 0014d44c 0012e5b8 ntdll!KiFastSystemCallRet
01bfffec 00000000 42f8e48c 0018b0a8 00000000 kernel32!GetModuleFileNameA+0x1b4
 
*----> Raw Stack Dump <----*
0000000001bfff50  18 94 41 7e 8c f3 f8 42 - 4c d4 14 00 b8 e5 12 00  ..A~...BL.......
0000000001bfff60  a8 b0 18 00 dc 02 02 00 - 13 01 00 00 01 00 00 00  ................
0000000001bfff70  00 00 00 00 00 77 1d 03 - 44 02 00 00 b7 01 00 00  .....w..D.......
0000000001bfff80  90 b0 18 00 d4 d7 18 00 - 01 00 00 00 00 00 00 00  ................
0000000001bfff90  a0 da 19 00 01 00 00 00 - 00 00 00 00 c4 03 04 00  ................
0000000001bfffa0  68 01 08 00 50 37 19 00 - 00 00 00 00 84 13 19 00  h...P7..........
0000000001bfffb0  b8 0d 19 00 ec ff bf 01 - 13 b7 80 7c 00 14 19 00  ...........|....
0000000001bfffc0  4c d4 14 00 b8 e5 12 00 - a8 b0 18 00 00 80 fd 7f  L...............
0000000001bfffd0  00 c6 db 86 c0 ff bf 01 - 30 49 57 86 ff ff ff ff  ........0IW.....
0000000001bfffe0  c0 9a 83 7c 20 b7 80 7c - 00 00 00 00 00 00 00 00  ...| ..|........
0000000001bffff0  00 00 00 00 8c e4 f8 42 - a8 b0 18 00 00 00 00 00  .......B........
0000000001c00000  41 63 74 78 20 00 00 00 - 01 00 00 00 60 19 00 00  Actx .......`...
0000000001c00010  7c 00 00 00 00 00 00 00 - 20 00 00 00 00 00 00 00  |....... .......
0000000001c00020  14 00 00 00 01 00 00 00 - 03 00 00 00 34 00 00 00  ............4...
0000000001c00030  bc 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000001c00040  00 00 00 00 00 00 00 00 - 00 00 00 00 02 00 00 00  ................
0000000001c00050  00 00 00 00 00 00 00 00 - 00 00 00 00 78 01 00 00  ............x...
0000000001c00060  7c 01 00 00 00 00 00 00 - cd ea ce 32 f4 02 00 00  |..........2....
0000000001c00070  42 00 00 00 38 03 00 00 - 02 03 00 00 10 00 00 00  B...8...........
0000000001c00080  03 00 00 00 8c 00 00 00 - 02 00 00 00 01 00 00 00  ................
 
*----> State Dump for Thread Id 0x8a8 <----*
 
eax=00000000 ebx=0279feb0 ecx=001a7188 edx=001a7598 esi=00000000 edi=7ffde000
eip=7c90e4f4 esp=0279fe88 ebp=0279ff24 iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246
 
function: ntdll!KiFastSystemCallRet
        7c90e4da e829000000       call    ntdll!RtlRaiseException (7c90e508)
        7c90e4df 8b0424           mov     eax,[esp]
        7c90e4e2 8be5             mov     esp,ebp
        7c90e4e4 5d               pop     ebp
        7c90e4e5 c3               ret
        7c90e4e6 8da42400000000   lea     esp,[esp]
        7c90e4ed 8d4900           lea     ecx,[ecx]
        ntdll!KiFastSystemCall:
        7c90e4f0 8bd4             mov     edx,esp
        7c90e4f2 0f34             sysenter
        ntdll!KiFastSystemCallRet:
        7c90e4f4 c3               ret
        7c90e4f5 8da42400000000   lea     esp,[esp]
        7c90e4fc 8d642400         lea     esp,[esp]
        ntdll!KiIntSystemCall:
        7c90e500 8d542408         lea     edx,[esp+0x8]
        7c90e504 cd2e             int     2e
        7c90e506 c3               ret
        7c90e507 90               nop
        ntdll!RtlRaiseException:
        7c90e508 55               push    ebp
        7c90e509 8bec             mov     ebp,esp
 
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll - 
ChildEBP RetAddr  Args to Child              
0279ff24 7c80a105 00000003 0279ff78 00000000 ntdll!KiFastSystemCallRet
0279ff40 5a00b0f0 00000003 0279ff78 00000000 kernel32!WaitForMultipleObjects+0x18
0279ffb4 7c80b713 5a034aa4 01bff11c 01bff11c SophosBHO+0xb0f0
0279ffec 00000000 5a00b3d0 5a034aa4 00000000 kernel32!GetModuleFileNameA+0x1b4
 
*----> Raw Stack Dump <----*
000000000279fe88  2c df 90 7c 74 95 80 7c - 03 00 00 00 b0 fe 79 02  ,..|t..|......y.
000000000279fe98  01 00 00 00 00 00 00 00 - 00 00 00 00 24 03 00 00  ............$...
000000000279fea8  a4 4a 03 5a 00 00 00 00 - 10 03 00 00 14 03 00 00  .J.Z............
000000000279feb8  24 03 00 00 b4 7b 02 5a - 0e 01 00 00 28 00 00 00  $....{.Z....(...
000000000279fec8  00 00 00 00 f8 4c 02 5a - 14 00 00 00 01 00 00 00  .....L.Z........
000000000279fed8  00 00 00 00 00 00 00 00 - 10 00 00 00 00 00 00 00  ................
000000000279fee8  d8 fe 79 02 44 ff 79 02 - 00 e0 fd 7f 00 70 fd 7f  ..y.D.y......p..
000000000279fef8  50 ff 79 02 00 00 00 00 - b0 fe 79 02 6c d5 90 7c  P.y.......y.l..|
000000000279ff08  03 00 00 00 a4 fe 79 02 - 00 00 10 00 a8 ff 79 02  ......y.......y.
000000000279ff18  c0 9a 83 7c 68 96 80 7c - 00 00 00 00 40 ff 79 02  ...|h..|....@.y.
000000000279ff28  05 a1 80 7c 03 00 00 00 - 78 ff 79 02 00 00 00 00  ...|....x.y.....
000000000279ff38  ff ff ff ff 00 00 00 00 - b4 ff 79 02 f0 b0 00 5a  ..........y....Z
000000000279ff48  03 00 00 00 78 ff 79 02 - 00 00 00 00 ff ff ff ff  ....x.y.........
000000000279ff58  f4 89 bc c1 1c f1 bf 01 - 1c f1 bf 01 a4 4a 03 5a  .............J.Z
000000000279ff68  10 03 00 00 14 03 00 00 - 24 03 00 00 28 03 00 00  ........$...(...
000000000279ff78  10 03 00 00 14 03 00 00 - 24 03 00 00 98 68 02 5a  ........$....h.Z
000000000279ff88  00 00 00 00 98 68 02 5a - 00 00 00 00 98 68 02 5a  .....h.Z.....h.Z
000000000279ff98  24 03 00 00 01 00 00 00 - 00 00 00 00 58 ff 79 02  $...........X.y.
000000000279ffa8  dc ff 79 02 08 2e 02 5a - 03 00 00 00 ec ff 79 02  ..y....Z......y.
000000000279ffb8  13 b7 80 7c a4 4a 03 5a - 1c f1 bf 01 1c f1 bf 01  ...|.J.Z........
 
*----> State Dump for Thread Id 0x3f0 <----*
 
eax=00000000 ebx=001c7a90 ecx=02bbfad4 edx=7c90e4f4 esi=7fffffff edi=ffffffff
eip=7c90e4f4 esp=02bbfad4 ebp=02bbfb10 iopl=0         nv up ei ng nz ac po cy
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000297
 
function: ntdll!KiFastSystemCallRet
        7c90e4da e829000000       call    ntdll!RtlRaiseException (7c90e508)
        7c90e4df 8b0424           mov     eax,[esp]
        7c90e4e2 8be5             mov     esp,ebp
        7c90e4e4 5d               pop     ebp
        7c90e4e5 c3               ret
        7c90e4e6 8da42400000000   lea     esp,[esp]
        7c90e4ed 8d4900           lea     ecx,[ecx]
        ntdll!KiFastSystemCall:
        7c90e4f0 8bd4             mov     edx,esp
        7c90e4f2 0f34             sysenter
        ntdll!KiFastSystemCallRet:
        7c90e4f4 c3               ret
        7c90e4f5 8da42400000000   lea     esp,[esp]
        7c90e4fc 8d642400         lea     esp,[esp]
        ntdll!KiIntSystemCall:
        7c90e500 8d542408         lea     edx,[esp+0x8]
        7c90e504 cd2e             int     2e
        7c90e506 c3               ret
        7c90e507 90               nop
        ntdll!RtlRaiseException:
        7c90e508 55               push    ebp
        7c90e509 8bec             mov     ebp,esp
 
*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\mswsock.dll - 
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\ws2_32.dll - 
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\WININET.dll - 
ChildEBP RetAddr  Args to Child              
02bbfb10 71a55fa7 00000468 000004c0 00000000 ntdll!KiFastSystemCallRet
02bbfc04 71ab314f 00000001 02bbfe84 02bbfc7c mswsock+0x5fa7
02bbfc54 780760ed 00000001 02bbfe84 02bbfc7c ws2_32!select+0xa7
02bbffac 78072a68 02bbffec 7c80b713 001c7a20 WININET!Ordinal101+0x27ec
02bbffb4 7c80b713 001c7a20 01bf959c 00140000 WININET!InternetSetStatusCallback+0x1d9
02bbffec 00000000 78072a5b 001c7a20 00000000 kernel32!GetModuleFileNameA+0x1b4
 
*----> Raw Stack Dump <----*
0000000002bbfad4  3c df 90 7c 2b 40 a5 71 - 68 04 00 00 01 00 00 00  <..|+@.qh.......
0000000002bbfae4  fc fa bb 02 b4 fb bb 02 - 84 fe bb 02 a4 fb bb 02  ................
0000000002bbfaf4  e8 aa da 3f e0 45 c9 01 - ff ff ff ff ff ff ff 7f  ...?.E..........
0000000002bbfb04  90 7a 1c 00 00 00 00 00 - 00 00 00 00 04 fc bb 02  .z..............
0000000002bbfb14  a7 5f a5 71 68 04 00 00 - c0 04 00 00 00 00 00 00  ._.qh...........
0000000002bbfb24  04 00 00 00 80 fd bb 02 - b8 6a 53 02 7c fc bb 02  .........jS.|...
0000000002bbfb34  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000002bbfb44  01 00 00 00 80 0f 05 fd - ff ff ff ff 3d 00 91 7c  ............=..|
0000000002bbfb54  00 00 00 00 10 00 00 00 - 20 00 00 00 18 27 9a 02  ........ ....'..
0000000002bbfb64  00 00 00 00 18 27 9a 02 - 18 27 9a 02 18 27 9a 00  .....'...'...'..
0000000002bbfb74  38 fc bb 02 00 00 14 00 - cd 41 a5 71 1c 00 00 00  8........A.q....
0000000002bbfb84  90 7a 1c 00 c0 fb bb 02 - 7c fc bb 02 80 fd bb 02  .z......|.......
0000000002bbfb94  00 00 00 00 a4 fb bb 02 - 00 00 00 00 00 00 00 00  ................
0000000002bbfba4  80 0f 05 fd ff ff ff ff - 01 00 00 00 00 00 91 7c  ...............|
0000000002bbfbb4  c0 04 00 00 19 00 00 00 - 00 00 00 00 fd 99 80 7c  ...............|
0000000002bbfbc4  34 52 70 07 28 fc 55 04 - 40 52 70 07 e0 fb bb 02  4Rp.(.U.@Rp.....
0000000002bbfbd4  02 3e ab 71 c0 81 53 02 - c0 81 53 02 c4 fb bb 02  .>.q..S...S.....
0000000002bbfbe4  e3 3d ab 71 09 3a 00 00 - 28 fb bb 02 0c 15 aa 71  .=.q.:..(......q
0000000002bbfbf4  44 fc bb 02 28 72 a7 71 - 60 2e a5 71 ff ff ff ff  D...(r.q`..q....
0000000002bbfc04  54 fc bb 02 4f 31 ab 71 - 01 00 00 00 84 fe bb 02  T...O1.q........
 
*----> State Dump for Thread Id 0x690 <----*
 
eax=000000c0 ebx=00000000 ecx=7c800000 edx=00000000 esi=01bf8bf8 edi=02080000
eip=7c90e4f4 esp=02cbff9c ebp=02cbffb4 iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246
 
function: ntdll!KiFastSystemCallRet
        7c90e4da e829000000       call    ntdll!RtlRaiseException (7c90e508)
        7c90e4df 8b0424           mov     eax,[esp]
        7c90e4e2 8be5             mov     esp,ebp
        7c90e4e4 5d               pop     ebp
        7c90e4e5 c3               ret
        7c90e4e6 8da42400000000   lea     esp,[esp]
        7c90e4ed 8d4900           lea     ecx,[ecx]
        ntdll!KiFastSystemCall:
        7c90e4f0 8bd4             mov     edx,esp
        7c90e4f2 0f34             sysenter
        ntdll!KiFastSystemCallRet:
        7c90e4f4 c3               ret
        7c90e4f5 8da42400000000   lea     esp,[esp]
        7c90e4fc 8d642400         lea     esp,[esp]
        ntdll!KiIntSystemCall:
        7c90e500 8d542408         lea     edx,[esp+0x8]
        7c90e504 cd2e             int     2e
        7c90e506 c3               ret
        7c90e507 90               nop
        ntdll!RtlRaiseException:
        7c90e508 55               push    ebp
        7c90e509 8bec             mov     ebp,esp
 
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr  Args to Child              
02cbffb4 7c80b713 00000000 02080000 01bf8bf8 ntdll!KiFastSystemCallRet
02cbffec 00000000 7c927ebb 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4
 
*----> Raw Stack Dump <----*
0000000002cbff9c  fc d1 90 7c 02 7f 92 7c - 01 00 00 00 ac ff cb 02  ...|...|........
0000000002cbffac  00 00 00 00 00 00 00 80 - ec ff cb 02 13 b7 80 7c  ...............|
0000000002cbffbc  00 00 00 00 00 00 08 02 - f8 8b bf 01 00 00 00 00  ................
0000000002cbffcc  00 40 fd 7f 00 e6 db 86 - c0 ff cb 02 a0 37 ca 86  .@...........7..
0000000002cbffdc  ff ff ff ff c0 9a 83 7c - 20 b7 80 7c 00 00 00 00  .......| ..|....
0000000002cbffec  00 00 00 00 00 00 00 00 - bb 7e 92 7c 00 00 00 00  .........~.|....
0000000002cbfffc  00 00 00 00 80 09 00 00 - 00 30 00 00 e0 0f d0 b2  .........0......
0000000002cc000c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000002cc001c  00 00 00 00 23 33 01 00 - 00 00 00 00 7a 81 07 00  ....#3......z...
0000000002cc002c  00 00 00 00 d7 11 03 00 - 00 00 00 00 59 00 00 00  ............Y...
0000000002cc003c  41 00 00 00 04 00 00 00 - 3b 00 00 00 00 00 00 00  A.......;.......
0000000002cc004c  ea 02 00 00 b6 02 00 00 - 70 00 00 00 00 00 00 00  ........p.......
0000000002cc005c  00 00 00 00 68 26 cc 02 - 68 00 cc 02 80 17 58 04  ....h&..h.....X.
0000000002cc006c  00 00 00 00 48 1d 63 07 - 00 00 00 00 00 00 00 00  ....H.c.........
0000000002cc007c  00 00 00 00 00 00 00 00 - 00 00 00 00 b8 00 62 04  ..............b.
0000000002cc008c  80 49 88 0a 00 00 00 00 - 00 00 00 00 00 00 00 00  .I..............
0000000002cc009c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000002cc00ac  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000002cc00bc  98 3f 07 07 e8 5e a5 0a - 00 00 00 00 00 00 00 00  .?...^..........
0000000002cc00cc  00 00 00 00 00 00 00 00 - 38 d9 67 07 00 00 00 00  ........8.g.....
 
*----> State Dump for Thread Id 0x898 <----*
 
eax=72d230e8 ebx=03affef8 ecx=000000f8 edx=00000090 esi=00000000 edi=7ffde000
eip=7c90e4f4 esp=03affed0 ebp=03afff6c iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246
 
function: ntdll!KiFastSystemCallRet
        7c90e4da e829000000       call    ntdll!RtlRaiseException (7c90e508)
        7c90e4df 8b0424           mov     eax,[esp]
        7c90e4e2 8be5             mov     esp,ebp
        7c90e4e4 5d               pop     ebp
        7c90e4e5 c3               ret
        7c90e4e6 8da42400000000   lea     esp,[esp]
        7c90e4ed 8d4900           lea     ecx,[ecx]
        ntdll!KiFastSystemCall:
        7c90e4f0 8bd4             mov     edx,esp
        7c90e4f2 0f34             sysenter
        ntdll!KiFastSystemCallRet:
        7c90e4f4 c3               ret
        7c90e4f5 8da42400000000   lea     esp,[esp]
        7c90e4fc 8d642400         lea     esp,[esp]
        ntdll!KiIntSystemCall:
        7c90e500 8d542408         lea     edx,[esp+0x8]
        7c90e504 cd2e             int     2e
        7c90e506 c3               ret
        7c90e507 90               nop
        ntdll!RtlRaiseException:
        7c90e508 55               push    ebp
        7c90e509 8bec             mov     ebp,esp
 
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\wdmaud.drv - 
ChildEBP RetAddr  Args to Child              
03afff6c 7c80a105 00000002 03afffa4 00000000 ntdll!KiFastSystemCallRet
03afff88 72d2312a 00000002 03afffa4 00000000 kernel32!WaitForMultipleObjects+0x18
03afffb4 7c80b713 00000000 00000000 001fbd78 wdmaud!midMessage+0x348
03afffec 00000000 72d230e8 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4
 
*----> Raw Stack Dump <----*
0000000003affed0  2c df 90 7c 74 95 80 7c - 02 00 00 00 f8 fe af 03  ,..|t..|........
0000000003affee0  01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000003affef0  00 00 00 00 00 00 00 00 - 98 06 00 00 50 06 00 00  ............P...
0000000003afff00  46 02 00 00 ab 59 54 80 - 28 4c 94 a9 78 26 85 86  F....YT.(L..x&..
0000000003afff10  20 e1 73 f7 14 28 85 86 - 14 00 00 00 01 00 00 00   .s..(..........
0000000003afff20  00 00 00 00 00 00 00 00 - 10 00 00 00 78 26 85 86  ............x&..
0000000003afff30  ac 26 85 86 00 00 00 00 - 00 e0 fd 7f 00 b0 fa 7f  .&..............
0000000003afff40  78 26 85 86 00 00 00 00 - f8 fe af 03 82 2f 50 80  x&.........../P.
0000000003afff50  02 00 00 00 ec fe af 03 - 00 00 00 00 dc ff af 03  ................
0000000003afff60  c0 9a 83 7c 68 96 80 7c - 00 00 00 00 88 ff af 03  ...|h..|........
0000000003afff70  05 a1 80 7c 02 00 00 00 - a4 ff af 03 00 00 00 00  ...|............
0000000003afff80  ff ff ff ff 00 00 00 00 - b4 ff af 03 2a 31 d2 72  ............*1.r
0000000003afff90  02 00 00 00 a4 ff af 03 - 00 00 00 00 ff ff ff ff  ................
0000000003afffa0  78 bd 1f 00 98 06 00 00 - 50 06 00 00 f2 6e 6e 80  x.......P....nn.
0000000003afffb0  fc d9 90 7c ec ff af 03 - 13 b7 80 7c 00 00 00 00  ...|.......|....
0000000003afffc0  00 00 00 00 78 bd 1f 00 - 00 00 00 00 00 b0 fa 7f  ....x...........
0000000003afffd0  00 c6 db 86 c0 ff af 03 - c0 37 62 86 ff ff ff ff  .........7b.....
0000000003afffe0  c0 9a 83 7c 20 b7 80 7c - 00 00 00 00 00 00 00 00  ...| ..|........
0000000003affff0  00 00 00 00 e8 30 d2 72 - 00 00 00 00 00 00 00 00  .....0.r........
0000000003b00000  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
 
*----> State Dump for Thread Id 0x878 <----*
 
eax=012300a0 ebx=000006c8 ecx=00000007 edx=00140608 esi=03bfff98 edi=7e42772b
eip=7c90e4f4 esp=03bfff54 ebp=03bfff78 iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246
 
function: ntdll!KiFastSystemCallRet
        7c90e4da e829000000       call    ntdll!RtlRaiseException (7c90e508)
        7c90e4df 8b0424           mov     eax,[esp]
        7c90e4e2 8be5             mov     esp,ebp
        7c90e4e4 5d               pop     ebp
        7c90e4e5 c3               ret
        7c90e4e6 8da42400000000   lea     esp,[esp]
        7c90e4ed 8d4900           lea     ecx,[ecx]
        ntdll!KiFastSystemCall:
        7c90e4f0 8bd4             mov     edx,esp
        7c90e4f2 0f34             sysenter
        ntdll!KiFastSystemCallRet:
        7c90e4f4 c3               ret
        7c90e4f5 8da42400000000   lea     esp,[esp]
        7c90e4fc 8d642400         lea     esp,[esp]
        ntdll!KiIntSystemCall:
        7c90e500 8d542408         lea     edx,[esp+0x8]
        7c90e504 cd2e             int     2e
        7c90e506 c3               ret
        7c90e507 90               nop
        ntdll!RtlRaiseException:
        7c90e508 55               push    ebp
        7c90e509 8bec             mov     ebp,esp
 
*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\WINMM.dll - 
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr  Args to Child              
03bfff78 76b44e31 03bfff98 00000000 00000000 ntdll!KiFastSystemCallRet
03bfffb4 7c80b713 000006c8 00000200 0000002b WINMM!PlaySoundW+0x7e2
03bfffec 00000000 76b44dca 000006c8 00000000 kernel32!GetModuleFileNameA+0x1b4
 
*----> Raw Stack Dump <----*
0000000003bfff54  be 91 41 7e 6b 77 42 7e - 98 ff bf 03 00 00 00 00  ..A~kwB~........
0000000003bfff64  00 00 00 00 00 00 00 00 - c8 06 00 00 2b 77 42 7e  ............+wB~
0000000003bfff74  00 00 00 00 b4 ff bf 03 - 31 4e b4 76 98 ff bf 03  ........1N.v....
0000000003bfff84  00 00 00 00 00 00 00 00 - 00 00 00 00 00 02 00 00  ................
0000000003bfff94  2b 00 00 00 ea 02 02 00 - bc 03 00 00 80 96 6b 04  +.............k.
0000000003bfffa4  00 00 00 00 94 04 1c 03 - 73 01 00 00 af 01 00 00  ........s.......
0000000003bfffb4  ec ff bf 03 13 b7 80 7c - c8 06 00 00 00 02 00 00  .......|........
0000000003bfffc4  2b 00 00 00 c8 06 00 00 - 00 a0 fa 7f 00 e6 db 86  +...............
0000000003bfffd4  c0 ff bf 03 f8 37 62 86 - ff ff ff ff c0 9a 83 7c  .....7b........|
0000000003bfffe4  20 b7 80 7c 00 00 00 00 - 00 00 00 00 00 00 00 00   ..|............
0000000003bffff4  ca 4d b4 76 c8 06 00 00 - 00 00 00 00 00 00 00 00  .M.v............
0000000003c00004  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000003c00014  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000003c00024  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000003c00034  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000003c00044  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000003c00054  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000003c00064  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000003c00074  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000003c00084  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
 
*----> State Dump for Thread Id 0x5c8 <----*
 
eax=00000004 ebx=00000000 ecx=00000001 edx=00000004 esi=7c97b420 edi=7c97b440
eip=7c90e4f4 esp=03dfff70 ebp=03dfffb4 iopl=0         nv up ei ng nz na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000286
 
function: ntdll!KiFastSystemCallRet
        7c90e4da e829000000       call    ntdll!RtlRaiseException (7c90e508)
        7c90e4df 8b0424           mov     eax,[esp]
        7c90e4e2 8be5             mov     esp,ebp
        7c90e4e4 5d               pop     ebp
        7c90e4e5 c3               ret
        7c90e4e6 8da42400000000   lea     esp,[esp]
        7c90e4ed 8d4900           lea     ecx,[ecx]
        ntdll!KiFastSystemCall:
        7c90e4f0 8bd4             mov     edx,esp
        7c90e4f2 0f34             sysenter
        ntdll!KiFastSystemCallRet:
        7c90e4f4 c3               ret
        7c90e4f5 8da42400000000   lea     esp,[esp]
        7c90e4fc 8d642400         lea     esp,[esp]
        ntdll!KiIntSystemCall:
        7c90e500 8d542408         lea     edx,[esp+0x8]
        7c90e504 cd2e             int     2e
        7c90e506 c3               ret
        7c90e507 90               nop
        ntdll!RtlRaiseException:
        7c90e508 55               push    ebp
        7c90e509 8bec             mov     ebp,esp
 
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr  Args to Child              
03dfffb4 7c80b713 00000000 001fbd78 00000001 ntdll!KiFastSystemCallRet
03dfffec 00000000 7c910230 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4
 
*----> Raw Stack Dump <----*
0000000003dfff70  2c da 90 7c 6d 02 91 7c - 30 04 00 00 ac ff df 03  ,..|m..|0.......
0000000003dfff80  b0 ff df 03 98 ff df 03 - a0 ff df 03 78 bd 1f 00  ............x...
0000000003dfff90  01 00 00 00 00 00 00 00 - 00 00 00 00 18 21 29 07  .............!).
0000000003dfffa0  00 7c 28 e8 ff ff ff ff - 01 00 00 00 c9 7a 92 7c  .|(..........z.|
0000000003dfffb0  a0 20 29 07 ec ff df 03 - 13 b7 80 7c 00 00 00 00  . )........|....
0000000003dfffc0  78 bd 1f 00 01 00 00 00 - 00 00 00 00 00 80 fa 7f  x...............
0000000003dfffd0  00 c6 db 86 c0 ff df 03 - f8 37 62 86 ff ff ff ff  .........7b.....
0000000003dfffe0  c0 9a 83 7c 20 b7 80 7c - 00 00 00 00 00 00 00 00  ...| ..|........
0000000003dffff0  00 00 00 00 30 02 91 7c - 00 00 00 00 00 00 00 00  ....0..|........
0000000003e00000  00 00 00 00 9f 40 13 00 - 10 00 90 01 17 00 b0 01  .....@..........
0000000003e00010  ff ff ff 00 ff ff ff 00 - 00 00 00 00 00 00 00 00  ................
0000000003e00020  ff ff ff 00 ff ff ff 00 - 00 00 00 00 00 00 00 00  ................
0000000003e00030  00 00 00 00 01 00 00 00 - 0d 02 01 01 00 00 00 00  ................
0000000003e00040  00 00 00 00 00 00 00 00 - 00 00 00 00 02 00 00 00  ................
0000000003e00050  01 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000003e00060  00 00 00 00 1f 00 89 01 - 00 00 00 00 ff ff ff ff  ................
0000000003e00070  ff ff ff ff 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000003e00080  00 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000003e00090  21 00 8a 01 00 00 00 40 - 06 00 00 00 00 00 00 00  !......@........
0000000003e000a0  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 40  ...............@
 
*----> State Dump for Thread Id 0xa04 <----*
 
eax=000000c0 ebx=00000000 ecx=03dff5ac edx=7c916fc8 esi=00000000 edi=00000001
eip=7c90e4f4 esp=03cffcec ebp=03cfffb4 iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246
 
function: ntdll!KiFastSystemCallRet
        7c90e4da e829000000       call    ntdll!RtlRaiseException (7c90e508)
        7c90e4df 8b0424           mov     eax,[esp]
        7c90e4e2 8be5             mov     esp,ebp
        7c90e4e4 5d               pop     ebp
        7c90e4e5 c3               ret
        7c90e4e6 8da42400000000   lea     esp,[esp]
        7c90e4ed 8d4900           lea     ecx,[ecx]
        ntdll!KiFastSystemCall:
        7c90e4f0 8bd4             mov     edx,esp
        7c90e4f2 0f34             sysenter
        ntdll!KiFastSystemCallRet:
        7c90e4f4 c3               ret
        7c90e4f5 8da42400000000   lea     esp,[esp]
        7c90e4fc 8d642400         lea     esp,[esp]
        ntdll!KiIntSystemCall:
        7c90e500 8d542408         lea     edx,[esp+0x8]
        7c90e504 cd2e             int     2e
        7c90e506 c3               ret
        7c90e507 90               nop
        ntdll!RtlRaiseException:
        7c90e508 55               push    ebp
        7c90e509 8bec             mov     ebp,esp
 
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr  Args to Child              
03cfffb4 7c80b713 00000000 71a569cf 03dff98c ntdll!KiFastSystemCallRet
03cfffec 00000000 7c929b6f 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4
 
*----> Raw Stack Dump <----*
0000000003cffcec  2c df 90 7c 96 9c 92 7c - 17 00 00 00 30 fd cf 03  ,..|...|....0...
0000000003cffcfc  01 00 00 00 01 00 00 00 - 00 00 00 00 cf 69 a5 71  .............i.q
0000000003cffd0c  8c f9 df 03 00 00 00 00 - 80 c9 97 7c 80 c9 97 7c  ...........|...|
0000000003cffd1c  54 07 00 00 04 0a 00 00 - 17 00 00 00 17 00 00 00  T...............
0000000003cffd2c  16 00 00 00 50 07 00 00 - 4c 07 00 00 b0 05 00 00  ....P...L.......
0000000003cffd3c  68 07 00 00 74 07 00 00 - 90 07 00 00 9c 07 00 00  h...t...........
0000000003cffd4c  a8 07 00 00 c8 07 00 00 - d0 07 00 00 d8 07 00 00  ................
0000000003cffd5c  e4 07 00 00 ec 07 00 00 - f8 07 00 00 08 08 00 00  ................
0000000003cffd6c  14 08 00 00 1c 08 00 00 - 28 08 00 00 34 08 00 00  ........(...4...
0000000003cffd7c  40 08 00 00 48 08 00 00 - 50 05 00 00 58 05 00 00  @...H...P...X...
0000000003cffd8c  f4 0b 00 00 cc 11 00 00 - c0 0d 00 00 10 0d 00 00  ................
0000000003cffd9c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000003cffdac  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000003cffdbc  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000003cffdcc  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000003cffddc  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000003cffdec  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000003cffdfc  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000003cffe0c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000003cffe1c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
 
*----> State Dump for Thread Id 0xb40 <----*
 
eax=00000000 ebx=0402fef4 ecx=7ffa7000 edx=76a613f0 esi=00000000 edi=7ffde000
eip=7c90e4f4 esp=0402fecc ebp=0402ff68 iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246
 
function: ntdll!KiFastSystemCallRet
        7c90e4da e829000000       call    ntdll!RtlRaiseException (7c90e508)
        7c90e4df 8b0424           mov     eax,[esp]
        7c90e4e2 8be5             mov     esp,ebp
        7c90e4e4 5d               pop     ebp
        7c90e4e5 c3               ret
        7c90e4e6 8da42400000000   lea     esp,[esp]
        7c90e4ed 8d4900           lea     ecx,[ecx]
        ntdll!KiFastSystemCall:
        7c90e4f0 8bd4             mov     edx,esp
        7c90e4f2 0f34             sysenter
        ntdll!KiFastSystemCallRet:
        7c90e4f4 c3               ret
        7c90e4f5 8da42400000000   lea     esp,[esp]
        7c90e4fc 8d642400         lea     esp,[esp]
        ntdll!KiIntSystemCall:
        7c90e500 8d542408         lea     edx,[esp+0x8]
        7c90e504 cd2e             int     2e
        7c90e506 c3               ret
        7c90e507 90               nop
        ntdll!RtlRaiseException:
        7c90e508 55               push    ebp
        7c90e509 8bec             mov     ebp,esp
 
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\USERENV.dll - 
ChildEBP RetAddr  Args to Child              
0402ff68 7c80a105 00000003 76a61348 00000000 ntdll!KiFastSystemCallRet
0402ff84 769c87bd 00000003 76a61348 00000000 kernel32!WaitForMultipleObjects+0x18
0402ffb4 7c80b713 00000000 00000000 00000000 USERENV!RegisterGPNotification+0x1b6
0402ffec 00000000 769c8761 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4
 
*----> Raw Stack Dump <----*
000000000402fecc  2c df 90 7c 74 95 80 7c - 03 00 00 00 f4 fe 02 04  ,..|t..|........
000000000402fedc  01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000402feec  f0 13 a6 76 d7 9b 80 7c - 78 07 00 00 7c 07 00 00  ...v...|x...|...
000000000402fefc  80 07 00 00 5c fe 02 04 - 6c ff 02 04 6c ff 02 04  ....\...l...l...
000000000402ff0c  00 e9 90 7c 40 00 91 7c - 14 00 00 00 01 00 00 00  ...|@..|........
000000000402ff1c  00 00 00 00 00 00 00 00 - 10 00 00 00 fa 1b 80 7c  ...............|
000000000402ff2c  00 00 00 00 00 00 00 00 - 00 e0 fd 7f 00 70 fa 7f  .............p..
000000000402ff3c  d8 01 44 03 00 00 00 00 - f4 fe 02 04 00 00 00 00  ..D.............
000000000402ff4c  03 00 00 00 e8 fe 02 04 - 00 00 00 00 dc ff 02 04  ................
000000000402ff5c  c0 9a 83 7c 68 96 80 7c - 00 00 00 00 84 ff 02 04  ...|h..|........
000000000402ff6c  05 a1 80 7c 03 00 00 00 - 48 13 a6 76 00 00 00 00  ...|....H..v....
000000000402ff7c  ff ff ff ff 00 00 00 00 - b4 ff 02 04 bd 87 9c 76  ...............v
000000000402ff8c  03 00 00 00 48 13 a6 76 - 00 00 00 00 ff ff ff ff  ....H..v........
000000000402ff9c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 9c 76  ...............v
000000000402ffac  03 00 00 00 00 00 00 00 - ec ff 02 04 13 b7 80 7c  ...............|
000000000402ffbc  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000402ffcc  00 70 fa 7f 00 c6 db 86 - c0 ff 02 04 50 10 bd 86  .p..........P...
000000000402ffdc  ff ff ff ff c0 9a 83 7c - 20 b7 80 7c 00 00 00 00  .......| ..|....
000000000402ffec  00 00 00 00 00 00 00 00 - 61 87 9c 76 00 00 00 00  ........a..v....
000000000402fffc  00 00 00 00 08 00 00 00 - c0 60 00 00 00 00 00 00  .........`......
 
*----> State Dump for Thread Id 0xc1c <----*
 
eax=0567dcf4 ebx=0001002d ecx=0567f800 edx=0567f8f8 esi=7e42fa6e edi=00010011
eip=7c90e4f4 esp=0567f8fc ebp=0567f914 iopl=0         nv up ei pl nz na pe nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000202
 
function: ntdll!KiFastSystemCallRet
        7c90e4da e829000000       call    ntdll!RtlRaiseException (7c90e508)
        7c90e4df 8b0424           mov     eax,[esp]
        7c90e4e2 8be5             mov     esp,ebp
        7c90e4e4 5d               pop     ebp
        7c90e4e5 c3               ret
        7c90e4e6 8da42400000000   lea     esp,[esp]
        7c90e4ed 8d4900           lea     ecx,[ecx]
        ntdll!KiFastSystemCall:
        7c90e4f0 8bd4             mov     edx,esp
        7c90e4f2 0f34             sysenter
        ntdll!KiFastSystemCallRet:
        7c90e4f4 c3               ret
        7c90e4f5 8da42400000000   lea     esp,[esp]
        7c90e4fc 8d642400         lea     esp,[esp]
        ntdll!KiIntSystemCall:
        7c90e500 8d542408         lea     edx,[esp+0x8]
        7c90e504 cd2e             int     2e
        7c90e506 c3               ret
        7c90e507 90               nop
        ntdll!RtlRaiseException:
        7c90e508 55               push    ebp
        7c90e509 8bec             mov     ebp,esp
 
*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\mshtml.dll - 
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr  Args to Child              
0567f914 4374f181 00007f00 00000000 0567fbbc ntdll!KiFastSystemCallRet
0567f93c 436eae22 00007f00 0734b2d0 0567fbbc mshtml!MatchExactGetIDsOfNames+0x1aacd
0567f998 436eac65 00007f00 00000001 0734ebe8 mshtml!ShowModalDialog+0x1668
0567fa7c 4365241c 07132f58 0567fbbc 0734b2d0 mshtml!ShowModalDialog+0x14ab
0567fa98 4364d8ce 0734ebe8 0567fbbc 0734b2d0 mshtml!DllGetClassObject+0x73334
0567fb14 4374ec69 00000001 0734b2d0 00000000 mshtml!DllGetClassObject+0x6e7e6
0567fc60 4374eae8 00000020 00000000 02000001 mshtml!MatchExactGetIDsOfNames+0x1a5b5
0567fd84 4368e0c7 00000000 00000020 000e0340 mshtml!MatchExactGetIDsOfNames+0x1a434
0567fdb0 7e418734 000e0340 00000020 000e0340 mshtml!DllGetClassObject+0xaefdf
0567fddc 7e418816 4368e07b 000e0340 00000020 USER32!GetDC+0x6d
0567fe44 7e428ea0 00000000 4368e07b 000e0340 USER32!GetDC+0x14f
0567fe98 7e428eec 0061fdf8 00000020 000e0340 USER32!DefWindowProcW+0x180
0567fec0 7c90e453 0567fed0 00000018 0061fdf8 USER32!DefWindowProcW+0x1cc
0567ff10 7e419402 0567ff64 00000000 00000000 ntdll!KiUserCallbackDispatcher+0x13
0567ff3c 42f8e61d 0567ff64 00000000 00000000 USER32!PeekMessageW+0x167
0567ffb4 7c80b713 03522f10 04535f88 00140000 IEFRAME!Ordinal300+0x35db
0567ffec 00000000 42f8e48c 04623880 00000000 kernel32!GetModuleFileNameA+0x1b4
 
*----> Raw Stack Dump <----*
000000000567f8fc  3c 99 42 7e 6e f6 73 43 - 11 00 01 00 e8 eb 34 07  <.B~n.sC......4.
000000000567f90c  00 7f 00 00 50 8b 83 0a - 3c f9 67 05 81 f1 74 43  ....P...<.g...tC
000000000567f91c  00 7f 00 00 00 00 00 00 - bc fb 67 05 e8 eb 34 07  ..........g...4.
000000000567f92c  98 bf 10 07 e0 60 f2 02 - 05 40 00 80 00 00 00 00  .....`...@......
000000000567f93c  98 f9 67 05 22 ae 6e 43 - 00 7f 00 00 d0 b2 34 07  ..g.".nC......4.
000000000567f94c  bc fb 67 05 01 00 00 00 - 58 2f 13 07 00 00 00 00  ..g.....X/......
000000000567f95c  00 00 00 00 8c 03 00 00 - 18 00 00 00 7a 01 00 00  ............z...
000000000567f96c  37 01 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  7...............
000000000567f97c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000567f98c  00 00 00 00 e0 60 f2 02 - 58 2f 13 07 7c fa 67 05  .....`..X/..|.g.
000000000567f99c  65 ac 6e 43 00 7f 00 00 - 01 00 00 00 e8 eb 34 07  e.nC..........4.
000000000567f9ac  bc fb 67 05 01 00 00 00 - df 38 74 00 3d 00 91 7c  ..g......8t.=..|
000000000567f9bc  01 00 00 00 28 a8 6a 07 - 00 00 00 00 78 bd 1f 00  ....(.j.....x...
000000000567f9cc  90 fa 67 05 3d 00 91 7c - 98 bf 10 07 10 b4 6a 07  ..g.=..|......j.
000000000567f9dc  00 00 00 00 bc fb 67 05 - e0 60 f2 02 00 02 00 00  ......g..`......
000000000567f9ec  00 00 00 00 01 00 00 00 - d0 b2 34 07 48 61 f2 02  ..........4.Ha..
000000000567f9fc  10 fa 67 05 01 9d 69 43 - 00 00 00 00 d0 b2 34 07  ..g...iC......4.
000000000567fa0c  d0 b2 34 07 48 61 f2 02 - 28 fa 67 05 01 9d 69 43  ..4.Ha..(.g...iC
000000000567fa1c  d0 b2 34 07 01 00 00 00 - bc fb 67 05 8c fa 67 05  ..4.......g...g.
000000000567fa2c  21 9d 69 43 80 51 2d 07 - 6c 26 65 43 01 01 00 00  !.iC.Q-.l&eC....
 
*----> State Dump for Thread Id 0x770 <----*
 
eax=04eb0ff8 ebx=000493e0 ecx=04ff4dd4 edx=ffffffff esi=00001174 edi=00000000
eip=7c90e4f4 esp=0791fed8 ebp=0791ff3c iopl=0         nv up ei ng nz ac po cy
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000297
 
function: ntdll!KiFastSystemCallRet
        7c90e4da e829000000       call    ntdll!RtlRaiseException (7c90e508)
        7c90e4df 8b0424           mov     eax,[esp]
        7c90e4e2 8be5             mov     esp,ebp
        7c90e4e4 5d               pop     ebp
        7c90e4e5 c3               ret
        7c90e4e6 8da42400000000   lea     esp,[esp]
        7c90e4ed 8d4900           lea     ecx,[ecx]
        ntdll!KiFastSystemCall:
        7c90e4f0 8bd4             mov     edx,esp
        7c90e4f2 0f34             sysenter
        ntdll!KiFastSystemCallRet:
        7c90e4f4 c3               ret
        7c90e4f5 8da42400000000   lea     esp,[esp]
        7c90e4fc 8d642400         lea     esp,[esp]
        ntdll!KiIntSystemCall:
        7c90e500 8d542408         lea     edx,[esp+0x8]
        7c90e504 cd2e             int     2e
        7c90e506 c3               ret
        7c90e507 90               nop
        ntdll!RtlRaiseException:
        7c90e508 55               push    ebp
        7c90e509 8bec             mov     ebp,esp
 
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\ole32.dll - 
ChildEBP RetAddr  Args to Child              
0791ff3c 7c802542 00001174 000493e0 00000000 ntdll!KiFastSystemCallRet
0791ff50 77596afb 00001174 000493e0 00000000 kernel32!WaitForSingleObject+0x12
0791ff6c 77566ff9 00001174 00007530 7c802550 ole32!CoInstall+0x11d
0791ff8c 7752687c 0791ffb4 774fe3ee 77606a18 ole32!CoWaitForMultipleHandles+0xfea8
0791ff94 774fe3ee 77606a18 0039002d 0484cef8 ole32!CoGetObject+0x1776
0791ffb4 7c80b713 0484cef8 0039002d 00450043 ole32!StringFromGUID2+0x5dc
0791ffec 00000000 774fe43b 0484cef8 00000000 kernel32!GetModuleFileNameA+0x1b4
 
*----> Raw Stack Dump <----*
000000000791fed8  3c df 90 7c db 25 80 7c - 74 11 00 00 00 00 00 00  <..|.%.|t.......
000000000791fee8  0c ff 91 07 02 01 00 00 - 30 25 80 7c e0 93 04 00  ........0%.|....
000000000791fef8  14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000791ff08  10 00 00 00 00 a2 2f 4d - ff ff ff ff 00 e0 fd 7f  ....../M........
000000000791ff18  00 e0 f9 7f 0c ff 91 07 - 1c ff 91 07 ec fe 91 07  ................
000000000791ff28  00 00 00 00 dc ff 91 07 - c0 9a 83 7c 08 26 80 7c  ...........|.&.|
000000000791ff38  00 00 00 00 50 ff 91 07 - 42 25 80 7c 74 11 00 00  ....P...B%.|t...
000000000791ff48  e0 93 04 00 00 00 00 00 - 6c ff 91 07 fb 6a 59 77  ........l....jYw
000000000791ff58  74 11 00 00 e0 93 04 00 - 00 00 00 00 18 6a 60 77  t............j`w
000000000791ff68  74 11 00 00 8c ff 91 07 - f9 6f 56 77 74 11 00 00  t........oVwt...
000000000791ff78  30 75 00 00 50 25 80 7c - f8 ce 84 04 f0 11 00 00  0u..P%.|........
000000000791ff88  e0 8c 5b 04 94 ff 91 07 - 7c 68 52 77 b4 ff 91 07  ..[.....|hRw....
000000000791ff98  ee e3 4f 77 18 6a 60 77 - 2d 00 39 00 f8 ce 84 04  ..Ow.j`w-.9.....
000000000791ffa8  00 00 4e 77 56 e4 4f 77 - 43 00 45 00 ec ff 91 07  ..NwV.OwC.E.....
000000000791ffb8  13 b7 80 7c f8 ce 84 04 - 2d 00 39 00 43 00 45 00  ...|....-.9.C.E.
000000000791ffc8  f8 ce 84 04 00 e0 f9 7f - 00 c6 db 86 c0 ff 91 07  ................
000000000791ffd8  38 d8 69 86 ff ff ff ff - c0 9a 83 7c 20 b7 80 7c  8.i........| ..|
000000000791ffe8  00 00 00 00 00 00 00 00 - 00 00 00 00 3b e4 4f 77  ............;.Ow
000000000791fff8  f8 ce 84 04 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000007920008  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
 
*----> State Dump for Thread Id 0xb10 <----*
 
eax=76b5aeaf ebx=00000000 ecx=00000000 edx=00000000 esi=00000001 edi=00000000
eip=7c90e4f4 esp=0c82ff08 ebp=0c82ffb4 iopl=0         nv up ei ng nz ac po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000296
 
function: ntdll!KiFastSystemCallRet
        7c90e4da e829000000       call    ntdll!RtlRaiseException (7c90e508)
        7c90e4df 8b0424           mov     eax,[esp]
        7c90e4e2 8be5             mov     esp,ebp
        7c90e4e4 5d               pop     ebp
        7c90e4e5 c3               ret
        7c90e4e6 8da42400000000   lea     esp,[esp]
        7c90e4ed 8d4900           lea     ecx,[ecx]
        ntdll!KiFastSystemCall:
        7c90e4f0 8bd4             mov     edx,esp
        7c90e4f2 0f34             sysenter
        ntdll!KiFastSystemCallRet:
        7c90e4f4 c3               ret
        7c90e4f5 8da42400000000   lea     esp,[esp]
        7c90e4fc 8d642400         lea     esp,[esp]
        ntdll!KiIntSystemCall:
        7c90e500 8d542408         lea     edx,[esp+0x8]
        7c90e504 cd2e             int     2e
        7c90e506 c3               ret
        7c90e507 90               nop
        ntdll!RtlRaiseException:
        7c90e508 55               push    ebp
        7c90e509 8bec             mov     ebp,esp
 
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr  Args to Child              
0c82ffb4 7c80b713 00000000 00000000 00000001 ntdll!KiFastSystemCallRet
0c82ffec 00000000 76b5aeaf 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4
 
*----> Raw Stack Dump <----*
000000000c82ff08  2c df 90 7c e9 ae b5 76 - 01 00 00 00 6c ff 82 0c  ,..|...v....l...
000000000c82ff18  01 00 00 00 01 00 00 00 - 00 00 00 00 01 00 00 00  ................
000000000c82ff28  04 16 c4 86 40 5f 00 00 - cc 14 c4 86 38 e5 73 f7  ....@_......8.s.
000000000c82ff38  26 38 64 80 f8 51 7a 86 - 98 14 c4 86 00 50 f9 7f  &8d..Qz......P..
000000000c82ff48  88 fc 51 a9 82 2f 50 80 - 00 00 00 00 05 00 00 00  ..Q../P.........
000000000c82ff58  00 00 00 00 00 00 00 00 - 00 00 00 00 c4 f8 4f 80  ..............O.
000000000c82ff68  60 fc 51 a9 e0 0b 00 00 - f8 0e 00 00 27 64 6e 80  `.Q.........'dn.
000000000c82ff78  98 14 c4 86 50 fd 51 a9 - 00 00 00 00 80 15 c4 86  ....P.Q.........
000000000c82ff88  01 41 21 f7 00 00 00 00 - f8 51 7a 86 5a 2f 50 80  .A!......Qz.Z/P.
000000000c82ff98  00 00 00 00 00 00 00 00 - 00 00 00 00 6a 2f 50 80  ............j/P.
000000000c82ffa8  a0 fc 51 a9 f2 6e 6e 80 - 01 00 00 00 ec ff 82 0c  ..Q..nn.........
000000000c82ffb8  13 b7 80 7c 00 00 00 00 - 00 00 00 00 01 00 00 00  ...|............
000000000c82ffc8  00 00 00 00 00 50 f9 7f - 00 e6 db 86 c0 ff 82 0c  .....P..........
000000000c82ffd8  28 56 68 86 ff ff ff ff - c0 9a 83 7c 20 b7 80 7c  (Vh........| ..|
000000000c82ffe8  00 00 00 00 00 00 00 00 - 00 00 00 00 af ae b5 76  ...............v
000000000c82fff8  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000c830008  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000c830018  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000c830028  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000c830038  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
 
*----> State Dump for Thread Id 0x160 <----*
 
eax=0000000c ebx=072dd7e4 ecx=0c92ff44 edx=00000000 esi=00000f14 edi=00000000
eip=7c90e4f4 esp=0c92ff04 ebp=0c92ff68 iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246
 
function: ntdll!KiFastSystemCallRet
        7c90e4da e829000000       call    ntdll!RtlRaiseException (7c90e508)
        7c90e4df 8b0424           mov     eax,[esp]
        7c90e4e2 8be5             mov     esp,ebp
        7c90e4e4 5d               pop     ebp
        7c90e4e5 c3               ret
        7c90e4e6 8da42400000000   lea     esp,[esp]
        7c90e4ed 8d4900           lea     ecx,[ecx]
        ntdll!KiFastSystemCall:
        7c90e4f0 8bd4             mov     edx,esp
        7c90e4f2 0f34             sysenter
        ntdll!KiFastSystemCallRet:
        7c90e4f4 c3               ret
        7c90e4f5 8da42400000000   lea     esp,[esp]
        7c90e4fc 8d642400         lea     esp,[esp]
        ntdll!KiIntSystemCall:
        7c90e500 8d542408         lea     edx,[esp+0x8]
        7c90e504 cd2e             int     2e
        7c90e506 c3               ret
        7c90e507 90               nop
        ntdll!RtlRaiseException:
        7c90e508 55               push    ebp
        7c90e509 8bec             mov     ebp,esp
 
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr  Args to Child              
0c92ff68 7c802542 00000f14 ffffffff 00000000 ntdll!KiFastSystemCallRet
0c92ff7c 436c9520 00000f14 ffffffff 435d0000 kernel32!WaitForSingleObject+0x12
0c92ffa0 43666b4a 09519020 00000020 435ed984 mshtml!DllGetClassObject+0xea438
0c92ffb4 7c80b713 072dd778 09519020 00000020 mshtml!DllGetClassObject+0x87a62
0c92ffec 00000000 435ed977 072dd778 00000000 kernel32!GetModuleFileNameA+0x1b4
 
*----> Raw Stack Dump <----*
000000000c92ff04  3c df 90 7c db 25 80 7c - 14 0f 00 00 00 00 00 00  <..|.%.|........
000000000c92ff14  00 00 00 00 00 00 00 00 - 78 d7 2d 07 e4 d7 2d 07  ........x.-...-.
000000000c92ff24  14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000c92ff34  10 00 00 00 03 00 00 00 - f0 3a 30 07 00 e0 fd 7f  .........:0.....
000000000c92ff44  00 40 f9 7f 00 00 00 00 - 97 77 68 43 18 ff 92 0c  .@.......whC....
000000000c92ff54  f9 77 68 43 dc ff 92 0c - c0 9a 83 7c 08 26 80 7c  .whC.......|.&.|
000000000c92ff64  00 00 00 00 7c ff 92 0c - 42 25 80 7c 14 0f 00 00  ....|...B%.|....
000000000c92ff74  ff ff ff ff 00 00 00 00 - a0 ff 92 0c 20 95 6c 43  ............ .lC
000000000c92ff84  14 0f 00 00 ff ff ff ff - 00 00 5d 43 78 d7 2d 07  ..........]Cx.-.
000000000c92ff94  78 d7 2d 07 65 47 30 02 - ff ff ff ff b4 ff 92 0c  x.-.eG0.........
000000000c92ffa4  4a 6b 66 43 20 90 51 09 - 20 00 00 00 84 d9 5e 43  JkfC .Q. .....^C
000000000c92ffb4  ec ff 92 0c 13 b7 80 7c - 78 d7 2d 07 20 90 51 09  .......|x.-. .Q.
000000000c92ffc4  20 00 00 00 78 d7 2d 07 - 00 40 f9 7f 00 e6 db 86   ...x.-..@......
000000000c92ffd4  c0 ff 92 0c 28 56 68 86 - ff ff ff ff c0 9a 83 7c  ....(Vh........|
000000000c92ffe4  20 b7 80 7c 00 00 00 00 - 00 00 00 00 00 00 00 00   ..|............
000000000c92fff4  77 d9 5e 43 78 d7 2d 07 - 00 00 00 00 00 00 00 00  w.^Cx.-.........
000000000c930004  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000c930014  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000c930024  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000c930034  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
 
*----> State Dump for Thread Id 0xf88 <----*
 
eax=00000000 ebx=00000000 ecx=060bfd68 edx=7c90e4f4 esi=00181098 edi=0018113c
eip=7c90e4f4 esp=060bfe18 ebp=060bff80 iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246
 
function: ntdll!KiFastSystemCallRet
        7c90e4da e829000000       call    ntdll!RtlRaiseException (7c90e508)
        7c90e4df 8b0424           mov     eax,[esp]
        7c90e4e2 8be5             mov     esp,ebp
        7c90e4e4 5d               pop     ebp
        7c90e4e5 c3               ret
        7c90e4e6 8da42400000000   lea     esp,[esp]
        7c90e4ed 8d4900           lea     ecx,[ecx]
        ntdll!KiFastSystemCall:
        7c90e4f0 8bd4             mov     edx,esp
        7c90e4f2 0f34             sysenter
        ntdll!KiFastSystemCallRet:
        7c90e4f4 c3               ret
        7c90e4f5 8da42400000000   lea     esp,[esp]
        7c90e4fc 8d642400         lea     esp,[esp]
        ntdll!KiIntSystemCall:
        7c90e500 8d542408         lea     edx,[esp+0x8]
        7c90e504 cd2e             int     2e
        7c90e506 c3               ret
        7c90e507 90               nop
        ntdll!RtlRaiseException:
        7c90e508 55               push    ebp
        7c90e509 8bec             mov     ebp,esp
 
*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\RPCRT4.dll - 
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr  Args to Child              
060bff80 77e76caf 060bffa8 77e76ad1 00181098 ntdll!KiFastSystemCallRet
060bff88 77e76ad1 00181098 7c917de9 1609b9ac RPCRT4!I_RpcBCacheFree+0x61c
060bffa8 77e76c97 0014d388 060bffec 7c80b713 RPCRT4!I_RpcBCacheFree+0x43e
060bffb4 7c80b713 071cf5b0 7c917de9 1609b9ac RPCRT4!I_RpcBCacheFree+0x604
060bffec 00000000 77e76c7d 071cf5b0 00000000 kernel32!GetModuleFileNameA+0x1b4
 
*----> Raw Stack Dump <----*
00000000060bfe18  8c da 90 7c e3 65 e7 77 - 48 02 00 00 74 ff 0b 06  ...|.e.wH...t...
00000000060bfe28  00 00 00 00 00 2d 51 04 - 48 ff 0b 06 ec 9f 7c 86  .....-Q.H.....|.
00000000060bfe38  38 00 50 00 00 00 00 00 - 5c 08 5d 80 00 00 00 00  8.P.....\.].....
00000000060bfe48  00 00 00 00 00 00 00 00 - 02 e0 f2 00 00 00 00 00  ................
00000000060bfe58  00 00 00 00 01 00 00 00 - ff 0f 1f 00 ff 03 1f 00  ................
00000000060bfe68  ff 0f 1f 00 87 00 00 00 - 01 00 00 00 00 00 00 00  ................
00000000060bfe78  01 00 00 00 01 01 01 01 - 00 00 00 00 01 01 01 01  ................
00000000060bfe88  01 01 01 01 01 01 01 01 - 00 00 00 00 90 9d 7c 86  ..............|.
00000000060bfe98  8c 4f dc 86 a0 8b bd a9 - 1e ca 5b 80 a8 9d 7c 86  .O........[...|.
00000000060bfea8  74 14 00 00 90 9d 7c 86 - 00 00 00 00 01 00 00 00  t.....|.........
00000000060bfeb8  01 00 00 00 a8 9d 7c 86 - c8 8b bd a9 3f c3 5b 80  ......|.....?.[.
00000000060bfec8  74 14 00 00 90 9d 7c 86 - 00 00 00 00 47 c3 5b 80  t.....|.....G.[.
00000000060bfed8  c8 49 dc 86 38 0e 00 e1 - 68 28 68 86 70 4e dc 86  .I..8...h(h.pN..
00000000060bfee8  10 8c bd a9 dd c3 5b 80 - 38 0e 00 e1 a8 9d 7c 86  ......[.8.....|.
00000000060bfef8  74 14 00 00 00 00 00 00 - ff 03 1f 00 00 00 00 00  t...............
00000000060bff08  30 8c bd a9 ac 8c bd a9 - f8 c4 5b 80 d5 45 c9 01  0.........[..E..
00000000060bff18  38 e5 73 f7 c4 58 54 80 - 00 f0 78 86 b4 b1 4f 80  8.s..XT...x...O.
00000000060bff28  8c f1 78 86 80 ff 0b 06 - ae df e7 77 48 ff 0b 06  ..x........wH...
00000000060bff38  be df e7 77 e0 10 90 7c - c0 4d 8c 0a b0 f5 1c 07  ...w...|.M......
00000000060bff48  00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff  ../M.....]......
 
*----> State Dump for Thread Id 0xa40 <----*
 
eax=00000000 ebx=00000000 ecx=045419c8 edx=0002da1c esi=045419c8 edi=04541a04
eip=7c90e4f4 esp=0649fe18 ebp=0649ff80 iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246
 
function: ntdll!KiFastSystemCallRet
        7c90e4da e829000000       call    ntdll!RtlRaiseException (7c90e508)
        7c90e4df 8b0424           mov     eax,[esp]
        7c90e4e2 8be5             mov     esp,ebp
        7c90e4e4 5d               pop     ebp
        7c90e4e5 c3               ret
        7c90e4e6 8da42400000000   lea     esp,[esp]
        7c90e4ed 8d4900           lea     ecx,[ecx]
        ntdll!KiFastSystemCall:
        7c90e4f0 8bd4             mov     edx,esp
        7c90e4f2 0f34             sysenter
        ntdll!KiFastSystemCallRet:
        7c90e4f4 c3               ret
        7c90e4f5 8da42400000000   lea     esp,[esp]
        7c90e4fc 8d642400         lea     esp,[esp]
        ntdll!KiIntSystemCall:
        7c90e500 8d542408         lea     edx,[esp+0x8]
        7c90e504 cd2e             int     2e
        7c90e506 c3               ret
        7c90e507 90               nop
        ntdll!RtlRaiseException:
        7c90e508 55               push    ebp
        7c90e509 8bec             mov     ebp,esp
 
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr  Args to Child              
0649ff80 77e76caf 0649ffa8 77e76ad1 045419c8 ntdll!KiFastSystemCallRet
0649ff88 77e76ad1 045419c8 7c900000 00bdfac8 RPCRT4!I_RpcBCacheFree+0x61c
0649ffa8 77e76c97 0014d388 0649ffec 7c80b713 RPCRT4!I_RpcBCacheFree+0x43e
0649ffb4 7c80b713 045070e8 7c900000 00bdfac8 RPCRT4!I_RpcBCacheFree+0x604
0649ffec 00000000 77e76c7d 045070e8 00000000 kernel32!GetModuleFileNameA+0x1b4
 
*----> Raw Stack Dump <----*
000000000649fe18  8c da 90 7c e3 65 e7 77 - d8 0c 00 00 74 ff 49 06  ...|.e.w....t.I.
000000000649fe28  00 00 00 00 20 3a 51 04 - 00 00 00 00 ff ff ff 03  .... :Q.........
000000000649fe38  ff ff ff 03 c0 9e e1 81 - 00 00 00 00 fc 3c 88 c0  .............<..
000000000649fe48  70 9f 77 86 40 e5 73 f7 - 00 00 00 00 72 b5 4f 80  p.w.@.s.....r.O.
000000000649fe58  94 8b bc a9 d0 fe 3f c0 - 00 90 fd 7f 00 00 00 00  ......?.........
000000000649fe68  c8 fe 3f 02 70 8b bc a9 - ab 38 52 80 00 90 fd 7f  ..?.p....8R.....
000000000649fe78  01 00 00 00 00 00 00 00 - c8 fe 3f c0 00 00 00 00  ..........?.....
000000000649fe88  00 00 00 00 f8 1f 60 c0 - 30 8c bc a9 0a 40 52 80  ......`.0....@R.
000000000649fe98  94 8b bc a9 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000649fea8  f0 92 89 86 78 9d 77 86 - 01 9e 77 86 00 00 00 00  ....x.w...w.....
000000000649feb8  c8 fe 3f c0 08 c5 89 86 - 00 00 00 00 d0 8b bc a9  ..?.............
000000000649fec8  00 00 04 00 3f 0a 00 00 - 44 9e 77 86 ff ff a3 00  ....?...D.w.....
000000000649fed8  78 9d 77 86 00 00 00 00 - ec 8b bc a9 00 00 a4 00  x.w.............
000000000649fee8  50 8b bc a9 00 00 00 00 - ff ff ff ff 00 90 fd 7f  P...............
000000000649fef8  68 9e 4d 80 ff ff ff ff - 4a 36 5b 80 2c 16 54 80  h.M.....J6[.,.T.
000000000649ff08  ff ff ff ff 00 00 00 00 - a8 5d 60 86 08 00 00 00  .........]`.....
000000000649ff18  38 f5 df ff c4 58 54 80 - 00 b0 8c 86 b4 b1 4f 80  8....XT.......O.
000000000649ff28  8c b1 8c 86 80 ff 49 06 - ae df e7 77 48 ff 49 06  ......I....wH.I.
000000000649ff38  be df e7 77 e0 10 90 7c - 10 55 f9 06 e8 70 50 04  ...w...|.U...pP.
000000000649ff48  00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff  ../M.....]......
 
*----> State Dump for Thread Id 0xd80 <----*
 
eax=0a8ec048 ebx=00007530 ecx=001fbd78 edx=0a8ed0c8 esi=00000000 edi=0289ff50
eip=7c90e4f4 esp=0289ff20 ebp=0289ff78 iopl=0         nv up ei pl nz na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000206
 
function: ntdll!KiFastSystemCallRet
        7c90e4da e829000000       call    ntdll!RtlRaiseException (7c90e508)
        7c90e4df 8b0424           mov     eax,[esp]
        7c90e4e2 8be5             mov     esp,ebp
        7c90e4e4 5d               pop     ebp
        7c90e4e5 c3               ret
        7c90e4e6 8da42400000000   lea     esp,[esp]
        7c90e4ed 8d4900           lea     ecx,[ecx]
        ntdll!KiFastSystemCall:
        7c90e4f0 8bd4             mov     edx,esp
        7c90e4f2 0f34             sysenter
        ntdll!KiFastSystemCallRet:
        7c90e4f4 c3               ret
        7c90e4f5 8da42400000000   lea     esp,[esp]
        7c90e4fc 8d642400         lea     esp,[esp]
        ntdll!KiIntSystemCall:
        7c90e500 8d542408         lea     edx,[esp+0x8]
        7c90e504 cd2e             int     2e
        7c90e506 c3               ret
        7c90e507 90               nop
        ntdll!RtlRaiseException:
        7c90e508 55               push    ebp
        7c90e509 8bec             mov     ebp,esp
 
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr  Args to Child              
0289ff78 7c802455 0000ea60 00000000 0289ffb4 ntdll!KiFastSystemCallRet
0289ff88 774fe32f 0000ea60 001fb300 774fe3ee kernel32!Sleep+0xf
0289ffb4 7c80b713 001fb300 044d66e0 7c936eb3 ole32!StringFromGUID2+0x51d
0289ffec 00000000 774fe43b 001fb300 00000000 kernel32!GetModuleFileNameA+0x1b4
 
*----> Raw Stack Dump <----*
000000000289ff20  fc d1 90 7c f1 23 80 7c - 00 00 00 00 50 ff 89 02  ...|.#.|....P...
000000000289ff30  50 25 80 7c f8 6d 60 77 - 30 75 00 00 14 00 00 00  P%.|.m`w0u......
000000000289ff40  01 00 00 00 00 00 00 00 - 00 00 00 00 10 00 00 00  ................
000000000289ff50  00 ba 3c dc ff ff ff ff - 68 fe 89 02 50 ff 89 02  ..<.....h...P...
000000000289ff60  30 ff 89 02 f8 fe 89 02 - dc ff 89 02 c0 9a 83 7c  0..............|
000000000289ff70  60 24 80 7c 00 00 00 00 - 88 ff 89 02 55 24 80 7c  `$.|........U$.|
000000000289ff80  60 ea 00 00 00 00 00 00 - b4 ff 89 02 2f e3 4f 77  `.........../.Ow
000000000289ff90  60 ea 00 00 00 b3 1f 00 - ee e3 4f 77 00 00 00 00  `.........Ow....
000000000289ffa0  e0 66 4d 04 00 b3 1f 00 - 00 00 4e 77 56 e4 4f 77  .fM.......NwV.Ow
000000000289ffb0  b3 6e 93 7c ec ff 89 02 - 13 b7 80 7c 00 b3 1f 00  .n.|.......|....
000000000289ffc0  e0 66 4d 04 b3 6e 93 7c - 00 b3 1f 00 00 a0 fd 7f  .fM..n.|........
000000000289ffd0  00 c6 db 86 c0 ff 89 02 - c0 0b 98 86 ff ff ff ff  ................
000000000289ffe0  c0 9a 83 7c 20 b7 80 7c - 00 00 00 00 00 00 00 00  ...| ..|........
000000000289fff0  00 00 00 00 3b e4 4f 77 - 00 b3 1f 00 00 00 00 00  ....;.Ow........
00000000028a0000  c8 00 00 00 43 01 00 00 - ff ee ff ee 02 10 00 00  ....C...........
00000000028a0010  00 00 00 00 00 fe 00 00 - 00 00 10 00 00 20 00 00  ............. ..
00000000028a0020  00 02 00 00 00 20 00 00 - 9a 01 00 00 ff ef fd 7f  ..... ..........
00000000028a0030  10 00 08 06 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
00000000028a0040  00 00 00 00 98 05 8a 02 - 0f 00 00 00 f8 ff ff ff  ................
00000000028a0050  50 00 8a 02 50 00 8a 02 - 40 06 8a 02 00 00 00 00  P...P...@.......
 
*----> State Dump for Thread Id 0xdac <----*
 
eax=00000000 ebx=0639edc0 ecx=00000001 edx=0000c0f6 esi=00000000 edi=7ffde000
eip=7c90e4f4 esp=0639ed98 ebp=0639ee34 iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246
 
function: ntdll!KiFastSystemCallRet
        7c90e4da e829000000       call    ntdll!RtlRaiseException (7c90e508)
        7c90e4df 8b0424           mov     eax,[esp]
        7c90e4e2 8be5             mov     esp,ebp
        7c90e4e4 5d               pop     ebp
        7c90e4e5 c3               ret
        7c90e4e6 8da42400000000   lea     esp,[esp]
        7c90e4ed 8d4900           lea     ecx,[ecx]
        ntdll!KiFastSystemCall:
        7c90e4f0 8bd4             mov     edx,esp
        7c90e4f2 0f34             sysenter
        ntdll!KiFastSystemCallRet:
        7c90e4f4 c3               ret
        7c90e4f5 8da42400000000   lea     esp,[esp]
        7c90e4fc 8d642400         lea     esp,[esp]
        ntdll!KiIntSystemCall:
        7c90e500 8d542408         lea     edx,[esp+0x8]
        7c90e504 cd2e             int     2e
        7c90e506 c3               ret
        7c90e507 90               nop
        ntdll!RtlRaiseException:
        7c90e508 55               push    ebp
        7c90e509 8bec             mov     ebp,esp
 
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr  Args to Child              
0639ee34 7e4195f9 00000002 0639ee5c 00000000 ntdll!KiFastSystemCallRet
0639ee90 5dff6029 00000001 0639eec4 ffffffff USER32!GetLastInputInfo+0x105
0639eeb0 5dff632d 000004ff ffffffff 00000000 IEUI!DUserRegisterSuper+0x9bd
0639eed8 5dff60d8 000004ff 00000000 42fa98cd IEUI!PeekMessageExW+0x21f
0639ef14 42f9ab4c 077249b8 0639ef44 42f9bbbb IEUI!WaitMessageEx+0x31
0639ef20 42f9bbbb 00000000 00000000 072a4810 IEFRAME!Ordinal300+0xfb0a
0639ef44 42f9bb09 1dac0001 00ec0009 00207a68 IEFRAME!Ordinal101+0x341
0639ffb4 7c80b713 072a4810 00ec0009 00207a68 IEFRAME!Ordinal101+0x28f
0639ffec 00000000 42f9ba53 072a4810 00000000 kernel32!GetModuleFileNameA+0x1b4
 
*----> Raw Stack Dump <----*
000000000639ed98  2c df 90 7c 74 95 80 7c - 02 00 00 00 c0 ed 39 06  ,..|t..|......9.
000000000639eda8  01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000639edb8  02 00 00 00 00 00 00 00 - 84 17 00 00 b8 15 00 00  ................
000000000639edc8  21 c6 fb 42 b8 49 72 07 - 44 ee 39 06 cd c5 fb 42  !..B.Ir.D.9....B
000000000639edd8  00 00 00 00 08 ee 39 06 - 14 00 00 00 01 00 00 00  ......9.........
000000000639ede8  00 00 00 00 00 00 00 00 - 10 00 00 00 cd c5 fb 42  ...............B
000000000639edf8  cd ab ba dc 00 00 00 00 - 00 e0 fd 7f 00 60 fa 7f  .............`..
000000000639ee08  70 ee 39 06 00 00 00 00 - c0 ed 39 06 70 ee 39 06  p.9.......9.p.9.
000000000639ee18  02 00 00 00 b4 ed 39 06 - ff ff ff ff dc ff 39 06  ......9.......9.
000000000639ee28  c0 9a 83 7c 68 96 80 7c - 00 00 00 00 90 ee 39 06  ...|h..|......9.
000000000639ee38  f9 95 41 7e 02 00 00 00 - 5c ee 39 06 00 00 00 00  ..A~....\.9.....
000000000639ee48  ff ff ff ff 00 00 00 00 - ff ff ff ff 01 00 00 00  ................
000000000639ee58  01 00 00 00 84 17 00 00 - b8 15 00 00 bd 62 ff 5d  .............b.]
000000000639ee68  ae f0 1b 03 98 7f 44 03 - 01 00 00 00 00 00 00 00  ......D.........
000000000639ee78  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000639ee88  00 60 fa 7f b8 15 00 00 - b0 ee 39 06 29 60 ff 5d  .`........9.)`.]
000000000639ee98  01 00 00 00 c4 ee 39 06 - ff ff ff ff ff 04 00 00  ......9.........
000000000639eea8  5c ee 39 06 a0 9b 1c 00 - d8 ee 39 06 2d 63 ff 5d  \.9.......9.-c.]
000000000639eeb8  ff 04 00 00 ff ff ff ff - 00 00 00 00 84 17 00 00  ................
000000000639eec8  00 00 00 00 48 78 f9 42 - b8 49 72 07 9f 00 00 00  ....Hx.B.Ir.....
 
*----> State Dump for Thread Id 0xd18 <----*
 
eax=031397d8 ebx=00000000 ecx=0312fc98 edx=000008ee esi=0a825ac0 edi=00000000
eip=7c90e4f4 esp=068bff50 ebp=068bffb4 iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246
 
function: ntdll!KiFastSystemCallRet
        7c90e4da e829000000       call    ntdll!RtlRaiseException (7c90e508)
        7c90e4df 8b0424           mov     eax,[esp]
        7c90e4e2 8be5             mov     esp,ebp
        7c90e4e4 5d               pop     ebp
        7c90e4e5 c3               ret
        7c90e4e6 8da42400000000   lea     esp,[esp]
        7c90e4ed 8d4900           lea     ecx,[ecx]
        ntdll!KiFastSystemCall:
        7c90e4f0 8bd4             mov     edx,esp
        7c90e4f2 0f34             sysenter
        ntdll!KiFastSystemCallRet:
        7c90e4f4 c3               ret
        7c90e4f5 8da42400000000   lea     esp,[esp]
        7c90e4fc 8d642400         lea     esp,[esp]
        ntdll!KiIntSystemCall:
        7c90e500 8d542408         lea     edx,[esp+0x8]
        7c90e504 cd2e             int     2e
        7c90e506 c3               ret
        7c90e507 90               nop
        ntdll!RtlRaiseException:
        7c90e508 55               push    ebp
        7c90e509 8bec             mov     ebp,esp
 
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr  Args to Child              
068bffb4 7c80b713 03523bf8 0732ece8 00140000 ntdll!KiFastSystemCallRet
068bffec 00000000 42f8e48c 0a825ac0 00000000 kernel32!GetModuleFileNameA+0x1b4
 
*----> Raw Stack Dump <----*
00000000068bff50  18 94 41 7e 8c f3 f8 42 - e8 ec 32 07 00 00 14 00  ..A~...B..2.....
00000000068bff60  c0 5a 82 0a 20 04 0a 00 - 00 04 00 00 be ba 00 00  .Z.. ...........
00000000068bff70  6c fe 54 03 8b 72 1d 03 - e6 01 00 00 37 02 00 00  l.T..r......7...
00000000068bff80  b8 4a 82 0a 14 55 82 0a - 01 00 00 00 00 00 00 00  .J...U..........
00000000068bff90  30 9f 1f 07 01 00 00 00 - 00 00 00 00 54 04 0b 00  0...........T...
00000000068bffa0  9a 03 18 00 c8 17 1f 07 - 00 00 00 00 8c 1e 1f 07  ................
00000000068bffb0  d0 95 83 0a ec ff 8b 06 - 13 b7 80 7c f8 3b 52 03  ...........|.;R.
00000000068bffc0  e8 ec 32 07 00 00 14 00 - c0 5a 82 0a 00 20 fa 7f  ..2......Z... ..
00000000068bffd0  00 c6 db 86 c0 ff 8b 06 - 10 f9 66 86 ff ff ff ff  ..........f.....
00000000068bffe0  c0 9a 83 7c 20 b7 80 7c - 00 00 00 00 00 00 00 00  ...| ..|........
00000000068bfff0  00 00 00 00 8c e4 f8 42 - c0 5a 82 0a 00 00 00 00  .......B.Z......
00000000068c0000  08 00 00 00 00 20 00 00 - 00 00 00 00 ff ff ff ff  ..... ..........
00000000068c0010  40 1f 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00  @...............
00000000068c0020  00 00 00 00 00 00 00 00 - 58 00 00 00 58 00 00 00  ........X...X...
00000000068c0030  a0 e1 db 57 25 de d2 11 - af dd 00 10 5a 27 99 b5  ...W%.......Z'..
00000000068c0040  03 00 00 00 01 00 00 00 - 00 00 00 00 ac 0d 00 00  ................
00000000068c0050  b0 0e 00 00 c0 00 00 00 - 0f d4 d9 02 00 00 00 00  ................
00000000068c0060  00 00 00 00 48 00 00 00 - 00 00 00 00 00 00 00 00  ....H...........
00000000068c0070  08 00 00 00 01 00 04 00 - 07 00 00 00 00 00 00 00  ................
00000000068c0080  00 00 00 00 00 00 00 00 - 08 00 00 00 ff ff ff ff  ................
 
*----> State Dump for Thread Id 0xd58 <----*
 
eax=00000000 ebx=000006bb ecx=06659580 edx=00000000 esi=0471ed14 edi=046b51a0
eip=77e793df esp=07c9fd58 ebp=07c9fd98 iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246
 
function: RPCRT4!NdrGetTypeFlags
        77e793b9 bbbb060000       mov     ebx,0x6bb
        77e793be 7519             jnz     RPCRT4!NdrGetTypeFlags+0xe5 (77e793d9)
        77e793c0 a801             test    al,0x1
        77e793c2 0f841f100000     je    RPCRT4!NdrServerInitializeNew+0x44 (77e7a3e7)
        77e793c8 8b87fc000000     mov     eax,[edi+0xfc]
        77e793ce 8b4f6c           mov     ecx,[edi+0x6c]
        77e793d1 3bc1             cmp     eax,ecx
        77e793d3 0f8dcfc70200    jnl RPCRT4!RpcErrorStartEnumeration+0xe53 (77ea5ba8)
        77e793d9 8b4508           mov     eax,[ebp+0x8]
        77e793dc 8b4d10           mov     ecx,[ebp+0x10]
FAULT ->77e793df 3b01             cmp     eax,[ecx]         ds:0023:06659580=????????
        77e793e1 0f83e8c70200    jnb RPCRT4!RpcErrorStartEnumeration+0xe7a (77ea5bcf)
        77e793e7 837dfc00         cmp     dword ptr [ebp-0x4],0x0
        77e793eb 0f85f6fd0100 jne RPCRT4!I_RpcServerRegisterForwardFunction+0x534 (77e991e7)
        77e793f1 8b07             mov     eax,[edi]
        77e793f3 ff4034           inc     dword ptr [eax+0x34]
        77e793f6 8b461c           mov     eax,[esi+0x1c]
        77e793f9 8b4e08           mov     ecx,[esi+0x8]
        77e793fc ff7514           push    dword ptr [ebp+0x14]
        77e793ff 894808           mov     [eax+0x8],ecx
        77e79402 8b4e08           mov     ecx,[esi+0x8]
 
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr  Args to Child              
07c9fd98 77e7934e 00000000 00000000 06659580 RPCRT4!NdrGetTypeFlags+0xeb
07c9fdbc 77e7be64 0471ed14 00000000 06659580 RPCRT4!NdrGetTypeFlags+0x5a
07c9fdf8 77e7bcc1 04513160 04541b38 07674580 RPCRT4!NdrConformantArrayFree+0x46e
07c9fe1c 77e7bc05 04541b74 07c9fe38 07674580 RPCRT4!NdrConformantArrayFree+0x2cb
07c9ff80 77e76caf 07c9ffa8 77e76ad1 04541b38 RPCRT4!NdrConformantArrayFree+0x20f
07c9ff88 77e76ad1 04541b38 7c900000 0059fac8 RPCRT4!I_RpcBCacheFree+0x61c
07c9ffa8 77e76c97 0014d388 07c9ffec 7c80b713 RPCRT4!I_RpcBCacheFree+0x43e
07c9ffb4 7c80b713 07726f08 7c900000 0059fac8 RPCRT4!I_RpcBCacheFree+0x604
07c9ffec 00000000 77e76c7d 07726f08 00000000 kernel32!GetModuleFileNameA+0x1b4
 
*----> Raw Stack Dump <----*
0000000007c9fd58  00 00 00 00 a0 51 6b 04 - 14 ed 71 04 f8 45 67 07  .....Qk...q..Eg.
0000000007c9fd68  24 fe c9 07 00 00 00 00 - 00 e0 fd 7f 00 50 fa 7f  $............P..
0000000007c9fd78  b0 c8 5b 07 d0 fc c9 07 - ff ff ff ff dc ff c9 07  ..[.............
0000000007c9fd88  00 e9 90 7c e0 15 91 7c - 08 6f 72 07 b3 06 00 00  ...|...|.or.....
0000000007c9fd98  bc fd c9 07 4e 93 e7 77 - 00 00 00 00 00 00 00 00  ....N..w........
0000000007c9fda8  80 95 65 06 ec fd c9 07 - 10 bf 52 07 08 6f 72 07  ..e.......R..or.
0000000007c9fdb8  f0 eb 71 04 f8 fd c9 07 - 64 be e7 77 14 ed 71 04  ..q.....d..w..q.
0000000007c9fdc8  00 00 00 00 80 95 65 06 - ec fd c9 07 e0 10 90 7c  ......e........|
0000000007c9fdd8  38 1b 54 04 f0 eb 71 04 - 00 00 00 00 08 6f 72 07  8.T...q......or.
0000000007c9fde8  41 02 00 00 8b 7f 00 00 - 80 95 65 06 76 bc e7 77  A.........e.v..w
0000000007c9fdf8  1c fe c9 07 c1 bc e7 77 - 60 31 51 04 38 1b 54 04  .......w`1Q.8.T.
0000000007c9fe08  80 45 67 07 28 fe c9 07 - ef 22 ea 77 28 fe c9 07  .Eg.(....".w(...
0000000007c9fe18  41 02 00 00 80 ff c9 07 - 05 bc e7 77 74 1b 54 04  A..........wt.T.
0000000007c9fe28  38 fe c9 07 80 45 67 07 - 7c ff c9 07 0d 58 53 80  8....Eg.|....XS.
0000000007c9fe38  2c 00 44 00 84 30 70 86 - b0 0e 00 00 90 04 00 00  ,.D..0p.........
0000000007c9fe48  a1 40 10 00 00 00 00 00 - 02 0b a2 a9 00 00 5b 80  .@............[.
0000000007c9fe58  ff 03 1f 00 70 4e dc 86 - 00 fc e0 ff 6e d4 5b 80  ....pN......n.[.
0000000007c9fe68  90 13 58 86 a8 13 58 86 - bb 06 00 00 07 22 00 00  ..X...X......"..
0000000007c9fe78  43 05 00 00 00 00 00 00 - 00 e0 61 0a 84 0b a2 a9  C.........a.....
0000000007c9fe88  00 00 00 00 40 a7 63 e3 - 9c 0b a2 a9 3b d7 60 80  ....@.c.....;.`.
 
*----> State Dump for Thread Id 0x858 <----*
 
eax=77e7802c ebx=00000000 ecx=07674494 edx=076744c8 esi=00181098 edi=0018113c
eip=7c90e4f4 esp=0659fe18 ebp=0659ff80 iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246
 
function: ntdll!KiFastSystemCallRet
        7c90e4da e829000000       call    ntdll!RtlRaiseException (7c90e508)
        7c90e4df 8b0424           mov     eax,[esp]
        7c90e4e2 8be5             mov     esp,ebp
        7c90e4e4 5d               pop     ebp
        7c90e4e5 c3               ret
        7c90e4e6 8da42400000000   lea     esp,[esp]
        7c90e4ed 8d4900           lea     ecx,[ecx]
        ntdll!KiFastSystemCall:
        7c90e4f0 8bd4             mov     edx,esp
        7c90e4f2 0f34             sysenter
        ntdll!KiFastSystemCallRet:
        7c90e4f4 c3               ret
        7c90e4f5 8da42400000000   lea     esp,[esp]
        7c90e4fc 8d642400         lea     esp,[esp]
        ntdll!KiIntSystemCall:
        7c90e500 8d542408         lea     edx,[esp+0x8]
        7c90e504 cd2e             int     2e
        7c90e506 c3               ret
        7c90e507 90               nop
        ntdll!RtlRaiseException:
        7c90e508 55               push    ebp
        7c90e509 8bec             mov     ebp,esp
 
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr  Args to Child              
0659ff80 77e76caf 0659ffa8 77e76ad1 00181098 ntdll!KiFastSystemCallRet
0659ff88 77e76ad1 00181098 fffffffc ffffffff RPCRT4!I_RpcBCacheFree+0x61c
0659ffa8 77e76c97 0014d388 0659ffec 7c80b713 RPCRT4!I_RpcBCacheFree+0x43e
0659ffb4 7c80b713 0a7a17b0 fffffffc ffffffff RPCRT4!I_RpcBCacheFree+0x604
0659ffec 00000000 77e76c7d 0a7a17b0 00000000 kernel32!GetModuleFileNameA+0x1b4
 
*----> Raw Stack Dump <----*
000000000659fe18  8c da 90 7c e3 65 e7 77 - 48 02 00 00 74 ff 59 06  ...|.e.wH...t.Y.
000000000659fe28  00 00 00 00 d8 53 6b 04 - 48 ff 59 06 3a 02 5c 80  .....Sk.H.Y.:.\.
000000000659fe38  1c bb 56 a9 01 00 00 00 - 24 bb 56 a9 00 00 00 00  ..V.....$.V.....
000000000659fe48  0d 58 53 80 70 4e dc 86 - 02 eb 70 86 00 00 70 86  .XS.pN....p...p.
000000000659fe58  00 00 00 00 fc 4f dc 86 - 00 eb 70 86 c8 bb 56 a9  .....O....p...V.
000000000659fe68  56 d1 5b 80 75 00 00 00 - 70 4e dc 86 00 fc e0 ff  V.[.u...pN......
000000000659fe78  6e d4 5b 80 50 37 63 86 - 68 37 63 86 80 19 dc 86  n.[.P7c.h7c.....
000000000659fe88  5f 22 00 00 7e 05 00 00 - 18 db 50 86 01 00 00 00  _"..~.....P.....
000000000659fe98  87 00 00 00 00 00 00 00 - 43 6d 6e 80 28 bc 56 a9  ........Cmn.(.V.
000000000659fea8  27 64 6e 80 00 0d db ba - 00 00 00 00 50 37 63 86  'dn.........P7c.
000000000659feb8  40 a7 63 e3 e0 eb 70 86 - 03 00 00 00 40 a7 63 e3  @.c...p.....@.c.
000000000659fec8  c0 bb 56 a9 3b d7 60 80 - 40 a7 63 e3 70 14 00 00  ..V.;.`.@.c.p...
000000000659fed8  ff 03 1f 00 40 a7 63 e3 - 00 00 00 00 00 00 00 00  ....@.c.........
000000000659fee8  00 00 00 00 1f 00 00 00 - ff ff ff ff 40 e5 73 f7  ............@.s.
000000000659fef8  00 00 00 00 10 64 6e 80 - a4 36 7f 86 28 bc 56 a9  .....dn..6..(.V.
000000000659ff08  00 00 00 00 27 64 6e 80 - 08 00 00 00 46 02 00 00  ....'dn.....F...
000000000659ff18  68 38 50 80 78 35 7f 86 - 08 35 7f 86 78 b0 4f 80  h8P.x5...5..x.O.
000000000659ff28  74 36 7f 86 80 ff 59 06 - ae df e7 77 48 ff 59 06  t6....Y....wH.Y.
000000000659ff38  be df e7 77 e0 10 90 7c - 88 2b 2c 07 b0 17 7a 0a  ...w...|.+,...z.
000000000659ff48  00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff  ../M.....]......
 
*----> State Dump for Thread Id 0xf68 <----*
 
eax=71a5d2c6 ebx=c0000000 ecx=7c912d58 edx=ffffffff esi=00000000 edi=71a8793c
eip=7c90e4f4 esp=039bff7c ebp=039bffb4 iopl=0         nv up ei pl nz na pe nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000202
 
function: ntdll!KiFastSystemCallRet
        7c90e4da e829000000       call    ntdll!RtlRaiseException (7c90e508)
        7c90e4df 8b0424           mov     eax,[esp]
        7c90e4e2 8be5             mov     esp,ebp
        7c90e4e4 5d               pop     ebp
        7c90e4e5 c3               ret
        7c90e4e6 8da42400000000   lea     esp,[esp]
        7c90e4ed 8d4900           lea     ecx,[ecx]
        ntdll!KiFastSystemCall:
        7c90e4f0 8bd4             mov     edx,esp
        7c90e4f2 0f34             sysenter
        ntdll!KiFastSystemCallRet:
        7c90e4f4 c3               ret
        7c90e4f5 8da42400000000   lea     esp,[esp]
        7c90e4fc 8d642400         lea     esp,[esp]
        ntdll!KiIntSystemCall:
        7c90e500 8d542408         lea     edx,[esp+0x8]
        7c90e504 cd2e             int     2e
        7c90e506 c3               ret
        7c90e507 90               nop
        ntdll!RtlRaiseException:
        7c90e508 55               push    ebp
        7c90e509 8bec             mov     ebp,esp
 
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr  Args to Child              
039bffb4 7c80b713 71a5d65f 08faede0 7c90e900 ntdll!KiFastSystemCallRet
039bffec 00000000 71a5d2c6 07069b00 00000000 kernel32!GetModuleFileNameA+0x1b4
 
*----> Raw Stack Dump <----*
00000000039bff7c  2c da 90 7c 20 d3 a5 71 - 60 05 00 00 bc ff 9b 03  ,..| ..q`.......
00000000039bff8c  b0 ff 9b 03 a4 ff 9b 03 - 68 d3 a5 71 e0 ed fa 08  ........h..q....
00000000039bff9c  00 e9 90 7c 00 9b 06 07 - 00 00 00 00 00 00 00 00  ...|............
00000000039bffac  00 00 a5 71 58 2e 9a 02 - ec ff 9b 03 13 b7 80 7c  ...qX..........|
00000000039bffbc  5f d6 a5 71 e0 ed fa 08 - 00 e9 90 7c 00 9b 06 07  _..q.......|....
00000000039bffcc  00 90 fd 7f 00 c6 db 86 - c0 ff 9b 03 90 00 ba 86  ................
00000000039bffdc  ff ff ff ff c0 9a 83 7c - 20 b7 80 7c 00 00 00 00  .......| ..|....
00000000039bffec  00 00 00 00 00 00 00 00 - c6 d2 a5 71 00 9b 06 07  ...........q....
00000000039bfffc  00 00 00 00 c0 08 00 00 - 01 00 00 00 00 00 00 00  ................
00000000039c000c  08 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
00000000039c001c  00 00 00 00 00 00 00 00 - 5c 00 5c 00 3f 00 5c 00  ........\.\.?.\.
00000000039c002c  68 00 64 00 61 00 75 00 - 64 00 69 00 6f 00 23 00  h.d.a.u.d.i.o.#.
00000000039c003c  66 00 75 00 6e 00 63 00 - 5f 00 30 00 31 00 26 00  f.u.n.c._.0.1.&.
00000000039c004c  76 00 65 00 6e 00 5f 00 - 38 00 33 00 38 00 34 00  v.e.n._.8.3.8.4.
00000000039c005c  26 00 64 00 65 00 76 00 - 5f 00 37 00 36 00 38 00  &.d.e.v._.7.6.8.
00000000039c006c  30 00 26 00 73 00 75 00 - 62 00 73 00 79 00 73 00  0.&.s.u.b.s.y.s.
00000000039c007c  5f 00 31 00 30 00 37 00 - 62 00 35 00 30 00 34 00  _.1.0.7.b.5.0.4.
00000000039c008c  38 00 26 00 72 00 65 00 - 76 00 5f 00 31 00 30 00  8.&.r.e.v._.1.0.
00000000039c009c  33 00 32 00 23 00 34 00 - 26 00 33 00 32 00 39 00  3.2.#.4.&.3.2.9.
00000000039c00ac  34 00 31 00 61 00 39 00 - 39 00 26 00 30 00 26 00  4.1.a.9.9.&.0.&.
 
*----> State Dump for Thread Id 0x540 <----*
 
eax=77e76c7d ebx=00000000 ecx=07530958 edx=07c9fb44 esi=04541b38 edi=04541bdc
eip=7c90e4f4 esp=0848fe18 ebp=0848ff80 iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246
 
function: ntdll!KiFastSystemCallRet
        7c90e4da e829000000       call    ntdll!RtlRaiseException (7c90e508)
        7c90e4df 8b0424           mov     eax,[esp]
        7c90e4e2 8be5             mov     esp,ebp
        7c90e4e4 5d               pop     ebp
        7c90e4e5 c3               ret
        7c90e4e6 8da42400000000   lea     esp,[esp]
        7c90e4ed 8d4900           lea     ecx,[ecx]
        ntdll!KiFastSystemCall:
        7c90e4f0 8bd4             mov     edx,esp
        7c90e4f2 0f34             sysenter
        ntdll!KiFastSystemCallRet:
        7c90e4f4 c3               ret
        7c90e4f5 8da42400000000   lea     esp,[esp]
        7c90e4fc 8d642400         lea     esp,[esp]
        ntdll!KiIntSystemCall:
        7c90e500 8d542408         lea     edx,[esp+0x8]
        7c90e504 cd2e             int     2e
        7c90e506 c3               ret
        7c90e507 90               nop
        ntdll!RtlRaiseException:
        7c90e508 55               push    ebp
        7c90e509 8bec             mov     ebp,esp
 
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr  Args to Child              
0848ff80 77e76caf 0848ffa8 77e76ad1 04541b38 ntdll!KiFastSystemCallRet
0848ff88 77e76ad1 04541b38 fffffffc ffffffff RPCRT4!I_RpcBCacheFree+0x61c
0848ffa8 77e76c97 0014d388 0848ffec 7c80b713 RPCRT4!I_RpcBCacheFree+0x43e
0848ffb4 7c80b713 0a7a10f0 fffffffc ffffffff RPCRT4!I_RpcBCacheFree+0x604
0848ffec 00000000 77e76c7d 0a7a10f0 00000000 kernel32!GetModuleFileNameA+0x1b4
 
*----> Raw Stack Dump <----*
000000000848fe18  8c da 90 7c e3 65 e7 77 - a4 10 00 00 74 ff 48 08  ...|.e.w....t.H.
000000000848fe28  00 00 00 00 68 08 7e 04 - 48 ff 48 08 0d 58 53 80  ....h.~.H.H..XS.
000000000848fe38  70 4e dc 86 44 ac 51 86 - 40 ac 51 86 00 00 00 00  pN..D.Q.@.Q.....
000000000848fe48  54 4f dc 86 00 ac 51 86 - c8 8b 91 a9 56 d1 5b 80  TO....Q.....V.[.
000000000848fe58  ff 03 1f 00 70 4e dc 86 - 00 fc e0 ff 6e d4 5b 80  ....pN......n.[.
000000000848fe68  10 ec 4d 86 28 ec 4d 86 - 80 19 dc 86 79 23 00 00  ..M.(.M.....y#..
000000000848fe78  a1 05 00 00 f8 1a 63 86 - 01 00 00 00 85 00 00 00  ......c.........
000000000848fe88  00 00 00 00 40 a7 63 e3 - 9c 8b 91 a9 3b d7 60 80  ....@.c.....;.`.
000000000848fe98  40 a7 63 e3 b8 0c 00 00 - 43 6d 6e 80 28 8c 91 a9  @.c.....Cmn.(...
000000000848fea8  27 64 6e 80 00 0d db ba - 00 00 00 00 c0 8b 91 a9  'dn.............
000000000848feb8  3b d7 60 80 40 a7 63 e3 - cc 16 00 00 ff 03 1f 00  ;.`.@.c.........
000000000848fec8  40 a7 63 e3 40 a7 63 e3 - cc 16 00 00 00 00 00 00  @.c.@.c.........
000000000848fed8  98 5d b6 e2 dc 8b 91 a9 - 00 00 00 00 00 00 00 00  .]..............
000000000848fee8  00 00 00 00 1f 00 00 00 - ff ff ff ff 40 e5 73 f7  ............@.s.
000000000848fef8  00 00 00 00 10 64 6e 80 - bc c1 71 86 28 8c 91 a9  .....dn...q.(...
000000000848ff08  00 00 00 00 27 64 6e 80 - 08 00 00 00 46 02 00 00  ....'dn.....F...
000000000848ff18  68 38 50 80 90 c0 71 86 - 20 c0 71 86 78 b0 4f 80  h8P...q. .q.x.O.
000000000848ff28  8c c1 71 86 80 ff 48 08 - ae df e7 77 48 ff 48 08  ..q...H....wH.H.
000000000848ff38  be df e7 77 e0 10 90 7c - c0 20 2c 07 f0 10 7a 0a  ...w...|. ,...z.
000000000848ff48  00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff  ../M.....]......
 
*----> State Dump for Thread Id 0x8b8 <----*
 
eax=77e76c7d ebx=00000000 ecx=00149234 edx=00000015 esi=00181098 edi=0018113c
eip=7c90e4f4 esp=05bdfe18 ebp=05bdff80 iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246
 
function: ntdll!KiFastSystemCallRet
        7c90e4da e829000000       call    ntdll!RtlRaiseException (7c90e508)
        7c90e4df 8b0424           mov     eax,[esp]
        7c90e4e2 8be5             mov     esp,ebp
        7c90e4e4 5d               pop     ebp
        7c90e4e5 c3               ret
        7c90e4e6 8da42400000000   lea     esp,[esp]
        7c90e4ed 8d4900           lea     ecx,[ecx]
        ntdll!KiFastSystemCall:
        7c90e4f0 8bd4             mov     edx,esp
        7c90e4f2 0f34             sysenter
        ntdll!KiFastSystemCallRet:
        7c90e4f4 c3               ret
        7c90e4f5 8da42400000000   lea     esp,[esp]
        7c90e4fc 8d642400         lea     esp,[esp]
        ntdll!KiIntSystemCall:
        7c90e500 8d542408         lea     edx,[esp+0x8]
        7c90e504 cd2e             int     2e
        7c90e506 c3               ret
        7c90e507 90               nop
        ntdll!RtlRaiseException:
        7c90e508 55               push    ebp
        7c90e509 8bec             mov     ebp,esp
 
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr  Args to Child              
05bdff80 77e76caf 05bdffa8 77e76ad1 00181098 ntdll!KiFastSystemCallRet
05bdff88 77e76ad1 00181098 7c9101bb 0469fb98 RPCRT4!I_RpcBCacheFree+0x61c
05bdffa8 77e76c97 0014d388 05bdffec 7c80b713 RPCRT4!I_RpcBCacheFree+0x43e
05bdffb4 7c80b713 070c6d18 7c9101bb 0469fb98 RPCRT4!I_RpcBCacheFree+0x604
05bdffec 00000000 77e76c7d 070c6d18 00000000 kernel32!GetModuleFileNameA+0x1b4
 
*----> Raw Stack Dump <----*
0000000005bdfe18  8c da 90 7c e3 65 e7 77 - 48 02 00 00 74 ff bd 05  ...|.e.wH...t...
0000000005bdfe28  00 00 00 00 48 40 50 04 - 48 ff bd 05 ff ff ff 03  ....H@P.H.......
0000000005bdfe38  ff ff ff 03 c8 3d e9 81 - 00 00 00 00 fc 3c 88 c0  .....=.......<..
0000000005bdfe48  98 9f 81 86 40 e5 73 f7 - 00 00 00 00 72 b5 4f 80  ....@.s.....r.O.
0000000005bdfe58  94 8b a0 aa e0 fe 3f c0 - 00 b0 fd 7f 00 00 00 00  ......?.........
0000000005bdfe68  d8 fe 3f 02 70 8b a0 aa - ab 38 52 80 00 b0 fd 7f  ..?.p....8R.....
0000000005bdfe78  01 00 00 00 00 00 00 00 - d8 fe 3f c0 00 00 00 00  ..........?.....
0000000005bdfe88  00 00 00 00 f8 1f 60 c0 - 30 8c a0 aa 0a 40 52 80  ......`.0....@R.
0000000005bdfe98  94 8b a0 aa 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000005bdfea8  00 7e 72 86 a0 9d 81 86 - 01 9e 81 86 00 00 00 00  .~r.............
0000000005bdfeb8  d8 fe 3f c0 38 41 6c 86 - 00 00 00 00 d8 09 98 86  ..?.8Al.........
0000000005bdfec8  00 00 10 00 7f 08 00 00 - 6c 9e 81 86 ff ff 87 00  ........l.......
0000000005bdfed8  a0 9d 81 86 00 00 00 00 - cb 60 d0 aa 00 00 88 00  .........`......
0000000005bdfee8  50 8b a0 aa af 89 1b 00 - ff ff ff ff 00 b0 fd 7f  P...............
0000000005bdfef8  68 9e 4d 80 ff ff ff ff - 4a 36 5b 80 2c 16 54 80  h.M.....J6[.,.T.
0000000005bdff08  ff ff ff ff 00 00 00 00 - a8 5d 60 86 0b af c0 86  .........]`.....
0000000005bdff18  38 f5 df ff c4 58 54 80 - 00 c0 31 86 b4 b1 4f 80  8....XT...1...O.
0000000005bdff28  8c c1 31 86 80 ff bd 05 - ae df e7 77 48 ff bd 05  ..1........wH...
0000000005bdff38  be df e7 77 e0 10 90 7c - c0 96 65 04 18 6d 0c 07  ...w...|..e..m..
0000000005bdff48  00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff  ../M.....]......
 
*----> State Dump for Thread Id 0x3f4 <----*
 
eax=000000d0 ebx=00000102 ecx=07723d78 edx=00000000 esi=05cdeef8 edi=00000000
eip=7c90e4f4 esp=05cdee24 ebp=05cdee4c iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246
 
function: ntdll!KiFastSystemCallRet
        7c90e4da e829000000       call    ntdll!RtlRaiseException (7c90e508)
        7c90e4df 8b0424           mov     eax,[esp]
        7c90e4e2 8be5             mov     esp,ebp
        7c90e4e4 5d               pop     ebp
        7c90e4e5 c3               ret
        7c90e4e6 8da42400000000   lea     esp,[esp]
        7c90e4ed 8d4900           lea     ecx,[ecx]
        ntdll!KiFastSystemCall:
        7c90e4f0 8bd4             mov     edx,esp
        7c90e4f2 0f34             sysenter
        ntdll!KiFastSystemCallRet:
        7c90e4f4 c3               ret
        7c90e4f5 8da42400000000   lea     esp,[esp]
        7c90e4fc 8d642400         lea     esp,[esp]
        ntdll!KiIntSystemCall:
        7c90e500 8d542408         lea     edx,[esp+0x8]
        7c90e504 cd2e             int     2e
        7c90e506 c3               ret
        7c90e507 90               nop
        ntdll!RtlRaiseException:
        7c90e508 55               push    ebp
        7c90e509 8bec             mov     ebp,esp
 
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr  Args to Child              
05cdee4c 7e419402 05cdeef8 00000000 00000000 ntdll!KiFastSystemCallRet
05cdee78 5dff5f8c 05cdeef8 00000000 00000000 USER32!PeekMessageW+0x167
05cdeeb0 5dff6150 05cdeef8 00000000 00000000 IEUI!DUserRegisterSuper+0x920
05cdeed0 42f9edf4 05cdeef8 00000000 00000000 IEUI!PeekMessageExW+0x42
05cdef14 42f9ab4c 0730bf58 05cdef44 42f9bbbb IEFRAME!Ordinal101+0x357a
05cdef20 42f9bbbb 00000000 00000000 06f875f0 IEFRAME!Ordinal300+0xfb0a
05cdef44 42f9bb09 13f40001 00020004 00204dd0 IEFRAME!Ordinal101+0x341
05cdffb4 7c80b713 06f875f0 00020004 00204dd0 IEFRAME!Ordinal101+0x28f
05cdffec 00000000 42f9ba53 06f875f0 00000000 kernel32!GetModuleFileNameA+0x1b4
 
*----> Raw Stack Dump <----*
0000000005cdee24  e9 93 41 7e a8 93 41 7e - f8 ee cd 05 00 00 00 00  ..A~..A~........
0000000005cdee34  00 00 00 00 00 00 00 00 - 01 00 00 00 e0 1d 5e 00  ..............^.
0000000005cdee44  00 d0 fa 7f 01 00 00 00 - 78 ee cd 05 02 94 41 7e  ........x.....A~
0000000005cdee54  f8 ee cd 05 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000005cdee64  01 00 00 00 00 00 00 00 - ff ff ff ff a0 82 1c 00  ................
0000000005cdee74  01 00 00 00 b0 ee cd 05 - 8c 5f ff 5d f8 ee cd 05  ........._.]....
0000000005cdee84  00 00 00 00 00 00 00 00 - 00 00 00 00 01 00 00 00  ................
0000000005cdee94  00 00 00 00 48 78 f9 42 - 58 bf 30 07 01 00 00 00  ....Hx.BX.0.....
0000000005cdeea4  03 00 00 00 00 00 00 00 - 48 78 f9 01 d0 ee cd 05  ........Hx......
0000000005cdeeb4  50 61 ff 5d f8 ee cd 05 - 00 00 00 00 00 00 00 00  Pa.]............
0000000005cdeec4  00 00 00 00 01 00 00 00 - 00 00 00 00 14 ef cd 05  ................
0000000005cdeed4  f4 ed f9 42 f8 ee cd 05 - 00 00 00 00 00 00 00 00  ...B............
0000000005cdeee4  00 00 00 00 01 00 00 00 - f0 75 f8 06 a0 6b 50 04  .........u...kP.
0000000005cdeef4  00 00 00 00 82 02 52 00 - a2 02 00 00 00 00 00 00  ......R.........
0000000005cdef04  00 00 00 00 70 74 1d 03 - e6 01 00 00 37 02 00 00  ....pt......7...
0000000005cdef14  20 ef cd 05 4c ab f9 42 - 58 bf 30 07 44 ef cd 05   ...L..BX.0.D...
0000000005cdef24  bb bb f9 42 00 00 00 00 - 00 00 00 00 f0 75 f8 06  ...B.........u..
0000000005cdef34  01 00 00 00 01 44 00 80 - 00 00 00 00 00 00 00 00  .....D..........
0000000005cdef44  b4 ff cd 05 09 bb f9 42 - 01 00 f4 13 04 00 02 00  .......B........
0000000005cdef54  d0 4d 20 00 f0 75 f8 06 - 00 00 00 00 00 00 00 00  .M ..u..........
 
*----> State Dump for Thread Id 0xf20 <----*
 
eax=01ada000 ebx=045b97a8 ecx=06c18b78 edx=00001000 esi=06c18e1c edi=06c18df0
eip=7c90e4f4 esp=06c18d64 ebp=06c18db0 iopl=0         nv up ei pl nz na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000206
 
function: ntdll!KiFastSystemCallRet
        7c90e4da e829000000       call    ntdll!RtlRaiseException (7c90e508)
        7c90e4df 8b0424           mov     eax,[esp]
        7c90e4e2 8be5             mov     esp,ebp
        7c90e4e4 5d               pop     ebp
        7c90e4e5 c3               ret
        7c90e4e6 8da42400000000   lea     esp,[esp]
        7c90e4ed 8d4900           lea     ecx,[ecx]
        ntdll!KiFastSystemCall:
        7c90e4f0 8bd4             mov     edx,esp
        7c90e4f2 0f34             sysenter
        ntdll!KiFastSystemCallRet:
        7c90e4f4 c3               ret
        7c90e4f5 8da42400000000   lea     esp,[esp]
        7c90e4fc 8d642400         lea     esp,[esp]
        ntdll!KiIntSystemCall:
        7c90e500 8d542408         lea     edx,[esp+0x8]
        7c90e504 cd2e             int     2e
        7c90e506 c3               ret
        7c90e507 90               nop
        ntdll!RtlRaiseException:
        7c90e508 55               push    ebp
        7c90e509 8bec             mov     ebp,esp
 
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\Downloaded Program Files\urSuperHost.dll - 
ChildEBP RetAddr  Args to Child              
06c18db0 77e7a33e 0450a2b0 06c18dd0 77e7a36f ntdll!KiFastSystemCallRet
06c18dbc 77e7a36f 06c18df0 01ad3ba0 00000000 RPCRT4!I_RpcSendReceive+0x23
06c18dd0 01a27d50 06c18e1c 0450a2b0 01ad3ba0 RPCRT4!NdrSendReceive+0x28
06c18f14 01a285dd 07705100 01ad3ba0 00000000 urSuperHost+0x7d50
06c18f54 01a2832a 0700dd88 01ad3d44 01ad3c2c urSuperHost+0x85dd
06c18f8c 01a21314 438ae044 0a8cb040 06c18fe0 urSuperHost+0x832a
7c9010e0 4affc033 89257508 fff00c42 037d044a urSuperHost+0x1314
0424548b 00000000 00000000 00000000 00000000 0x4affc033
 
*----> Raw Stack Dump <----*
0000000006c18d64  cc da 90 7c c1 ca e7 77 - 0c 0e 00 00 78 a2 50 04  ...|...w....x.P.
0000000006c18d74  78 a2 50 04 f0 8d c1 06 - 1c 8e c1 06 00 10 90 7c  x.P............|
0000000006c18d84  f0 8d c1 06 50 d6 f9 06 - 00 00 00 00 00 00 00 00  ....P...........
0000000006c18d94  1d 8a e7 77 f0 8d c1 06 - 00 00 00 00 1c 8e c1 06  ...w............
0000000006c18da4  00 10 90 7c a0 3b ad 01 - 00 00 00 00 bc 8d c1 06  ...|.;..........
0000000006c18db4  3e a3 e7 77 b0 a2 50 04 - d0 8d c1 06 6f a3 e7 77  >..w..P.....o..w
0000000006c18dc4  f0 8d c1 06 a0 3b ad 01 - 00 00 00 00 14 8f c1 06  .....;..........
0000000006c18dd4  50 7d a2 01 1c 8e c1 06 - b0 a2 50 04 a0 3b ad 01  P}........P..;..
0000000006c18de4  00 00 00 00 00 10 90 7c - 42 00 9e 00 a8 97 5b 04  .......|B.....[.
0000000006c18df4  10 00 00 00 b0 a2 50 04 - 00 00 00 00 00 00 00 00  ......P.........
0000000006c18e04  74 92 02 07 90 0c a5 01 - 78 bd 1f 00 d4 8e c1 06  t.......x.......
0000000006c18e14  3d 00 91 7c 00 00 00 00 - f0 8d c1 06 b0 a2 50 04  =..|..........P.
0000000006c18e24  00 00 00 00 00 00 00 00 - 48 8e c1 06 00 00 00 00  ........H.......
0000000006c18e34  00 00 00 00 65 e4 e7 77 - 01 00 00 00 00 00 00 00  ....e..w........
0000000006c18e44  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000006c18e54  00 00 00 00 f0 8e c1 06 - b8 b2 e7 77 00 51 70 07  ...........w.Qp.
0000000006c18e64  a4 86 a2 01 b1 86 a2 01 - 00 00 00 00 08 bb 51 04  ..............Q.
0000000006c18e74  38 8f c1 06 00 51 70 07 - d8 0c a5 01 08 bb 51 04  8....Qp.......Q.
0000000006c18e84  00 00 00 00 00 00 00 00 - 80 8e c1 06 02 00 00 00  ................
0000000006c18e94  00 00 00 00 72 00 70 00 - 00 00 14 00 00 00 00 00  ....r.p.........
 
*----> State Dump for Thread Id 0xe48 <----*
 
eax=00140000 ebx=00000000 ecx=0a7ec880 edx=0000014a esi=00000d58 edi=00000000
eip=7c90e4f4 esp=07a1ff10 ebp=07a1ff74 iopl=0         nv up ei ng nz ac pe cy
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000293
 
function: ntdll!KiFastSystemCallRet
        7c90e4da e829000000       call    ntdll!RtlRaiseException (7c90e508)
        7c90e4df 8b0424           mov     eax,[esp]
        7c90e4e2 8be5             mov     esp,ebp
        7c90e4e4 5d               pop     ebp
        7c90e4e5 c3               ret
        7c90e4e6 8da42400000000   lea     esp,[esp]
        7c90e4ed 8d4900           lea     ecx,[ecx]
        ntdll!KiFastSystemCall:
        7c90e4f0 8bd4             mov     edx,esp
        7c90e4f2 0f34             sysenter
        ntdll!KiFastSystemCallRet:
        7c90e4f4 c3               ret
        7c90e4f5 8da42400000000   lea     esp,[esp]
        7c90e4fc 8d642400         lea     esp,[esp]
        ntdll!KiIntSystemCall:
        7c90e500 8d542408         lea     edx,[esp+0x8]
        7c90e504 cd2e             int     2e
        7c90e506 c3               ret
        7c90e507 90               nop
        ntdll!RtlRaiseException:
        7c90e508 55               push    ebp
        7c90e509 8bec             mov     ebp,esp
 
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr  Args to Child              
07a1ff74 7c802542 00000d58 000927c0 00000000 ntdll!KiFastSystemCallRet
07a1ff88 4366f455 00000d58 000927c0 435d0000 kernel32!WaitForSingleObject+0x12
07a1ffb4 7c80b713 07328868 ffffffff 7c9101bb mshtml!DllGetClassObject+0x9036d
07a1ffec 00000000 435ed977 07328868 00000000 kernel32!GetModuleFileNameA+0x1b4
 
*----> Raw Stack Dump <----*
0000000007a1ff10  3c df 90 7c db 25 80 7c - 58 0d 00 00 00 00 00 00  <..|.%.|X.......
0000000007a1ff20  44 ff a1 07 00 00 00 00 - 68 88 32 07 00 00 00 00  D.......h.2.....
0000000007a1ff30  14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000007a1ff40  10 00 00 00 00 44 5f 9a - fe ff ff ff 00 e0 fd 7f  .....D_.........
0000000007a1ff50  00 10 fa 7f 44 ff a1 07 - 0a 00 00 80 24 ff a1 07  ....D.......$...
0000000007a1ff60  59 94 66 43 dc ff a1 07 - c0 9a 83 7c 08 26 80 7c  Y.fC.......|.&.|
0000000007a1ff70  00 00 00 00 88 ff a1 07 - 42 25 80 7c 58 0d 00 00  ........B%.|X...
0000000007a1ff80  c0 27 09 00 00 00 00 00 - b4 ff a1 07 55 f4 66 43  .'..........U.fC
0000000007a1ff90  58 0d 00 00 c0 27 09 00 - 00 00 5d 43 68 88 32 07  X....'....]Ch.2.
0000000007a1ffa0  68 88 32 07 4a 6b 66 43 - ff ff ff ff bb 01 91 7c  h.2.JkfC.......|
0000000007a1ffb0  84 d9 5e 43 ec ff a1 07 - 13 b7 80 7c 68 88 32 07  ..^C.......|h.2.
0000000007a1ffc0  ff ff ff ff bb 01 91 7c - 68 88 32 07 00 10 fa 7f  .......|h.2.....
0000000007a1ffd0  00 e6 db 86 c0 ff a1 07 - 10 41 40 86 ff ff ff ff  .........A@.....
0000000007a1ffe0  c0 9a 83 7c 20 b7 80 7c - 00 00 00 00 00 00 00 00  ...| ..|........
0000000007a1fff0  00 00 00 00 77 d9 5e 43 - 68 88 32 07 00 00 00 00  ....w.^Ch.2.....
0000000007a20000  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000007a20010  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000007a20020  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000007a20030  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000007a20040  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
 
*----> State Dump for Thread Id 0xf94 <----*
 
eax=77e76c7d ebx=00000000 ecx=0016622a edx=012e009e esi=04541b38 edi=04541bdc
eip=7c90e4f4 esp=0330fe18 ebp=0330ff80 iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246
 
function: ntdll!KiFastSystemCallRet
        7c90e4da e829000000       call    ntdll!RtlRaiseException (7c90e508)
        7c90e4df 8b0424           mov     eax,[esp]
        7c90e4e2 8be5             mov     esp,ebp
        7c90e4e4 5d               pop     ebp
        7c90e4e5 c3               ret
        7c90e4e6 8da42400000000   lea     esp,[esp]
        7c90e4ed 8d4900           lea     ecx,[ecx]
        ntdll!KiFastSystemCall:
        7c90e4f0 8bd4             mov     edx,esp
        7c90e4f2 0f34             sysenter
        ntdll!KiFastSystemCallRet:
        7c90e4f4 c3               ret
        7c90e4f5 8da42400000000   lea     esp,[esp]
        7c90e4fc 8d642400         lea     esp,[esp]
        ntdll!KiIntSystemCall:
        7c90e500 8d542408         lea     edx,[esp+0x8]
        7c90e504 cd2e             int     2e
        7c90e506 c3               ret
        7c90e507 90               nop
        ntdll!RtlRaiseException:
        7c90e508 55               push    ebp
        7c90e509 8bec             mov     ebp,esp
 
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr  Args to Child              
0330ff80 77e76caf 0330ffa8 77e76ad1 04541b38 ntdll!KiFastSystemCallRet
0330ff88 77e76ad1 04541b38 001fbd78 0048fac8 RPCRT4!I_RpcBCacheFree+0x61c
0330ffa8 77e76c97 0014d388 0330ffec 7c80b713 RPCRT4!I_RpcBCacheFree+0x43e
0330ffb4 7c80b713 044fba68 001fbd78 0048fac8 RPCRT4!I_RpcBCacheFree+0x604
0330ffec 00000000 77e76c7d 044fba68 00000000 kernel32!GetModuleFileNameA+0x1b4
 
*----> Raw Stack Dump <----*
000000000330fe18  8c da 90 7c e3 65 e7 77 - a4 10 00 00 74 ff 30 03  ...|.e.w....t.0.
000000000330fe28  00 00 00 00 b8 9f ff 06 - 48 ff 30 03 20 18 86 86  ........H.0. ...
000000000330fe38  48 6a 59 86 d8 c3 bc 86 - 88 9c bc 86 50 4d 8b 86  HjY.........PM..
000000000330fe48  00 00 00 00 0e 07 e3 aa - 39 ee 4f 80 00 9c 2c 86  ........9.O...,.
000000000330fe58  00 b4 00 00 18 f0 aa 86 - cc 0b 94 a9 f0 0d 94 a9  ................
000000000330fe68  44 0b 94 a9 78 df e3 aa - 0a 00 00 00 58 0b 94 a9  D...x.......X...
000000000330fe78  ec 0b 94 a9 ca 05 e3 aa - 00 9c 2c 86 08 55 7a 86  ..........,..Uz.
000000000330fe88  08 c0 01 00 01 91 53 80 - 04 00 00 00 10 00 00 00  ......S.........
000000000330fe98  30 0e 56 86 54 fc 00 00 - 43 6d 6e 80 28 0c 94 a9  0.V.T...Cmn.(...
000000000330fea8  27 64 6e 80 00 0d db ba - 00 00 00 00 53 fc 00 00  'dn.........S...
000000000330feb8  80 f2 df 86 4d 00 00 00 - a8 0b 94 a9 82 a6 54 80  ....M.........T.
000000000330fec8  30 0e 56 86 4c 0e 56 86 - 0d 00 00 00 38 9f 54 c0  0.V.L.V.....8.T.
000000000330fed8  21 4f 02 00 f0 0b 94 a9 - 00 00 00 00 00 00 00 00  !O..............
000000000330fee8  00 00 00 00 1f 00 00 00 - ff ff ff ff 40 f5 df ff  ............@...
000000000330fef8  00 00 00 00 10 64 6e 80 - f4 6a cd 86 28 0c 94 a9  .....dn..j..(...
000000000330ff08  00 00 00 00 27 64 6e 80 - 08 00 00 00 46 02 00 00  ....'dn.....F...
000000000330ff18  68 38 50 80 c8 69 cd 86 - 58 69 cd 86 78 b0 4f 80  h8P..i..Xi..x.O.
000000000330ff28  c4 6a cd 86 80 ff 30 03 - ae df e7 77 48 ff 30 03  .j....0....wH.0.
000000000330ff38  be df e7 77 e0 10 90 7c - b0 87 65 04 68 ba 4f 04  ...w...|..e.h.O.
000000000330ff48  00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff  ../M.....]......

Open in new window

ASKER CERTIFIED SOLUTION
Avatar of Mohamed Osama
Mohamed Osama
Flag of Egypt image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of dcmathis
dcmathis

ASKER

Sorry to be so long in getting back to this...

The PC is up to date with all patches and updates.  Running IE7.  Unfortunately, a secure website that the user connects to requires IE7, and won't support anything else.  I'll try re-registering the dll and get back with you.  Unfortunately, due to the inconsistent nature of the issue, it may be a few days.

Thanks.
Okay, I reregistered the dll, and that didn't help.  Attached, please find the hijackthis log for this computer.

Sorry that I haven't gotten this up before now, but other, more pressing issues conspired against it.

Thanks again for the help.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:04:19 PM, on 12/15/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
 
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\DWRCS.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PDFCreatorMessages.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files\Sophos\Remote Management System\RouterNT.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\DWRCST.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\JawsSystems\Jaws PDF Creator\PDFClient.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows Media Player\wmplayer.exe
C:\WINDOWS\Downloaded Program Files\CacheCleaner.exe
C:\Documents and Settings\crystal_h\Desktop\HiJackThis.exe
 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://quicklink
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://quicklink
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://quicklink
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by GVNW Consulting, INC.
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Sophos Web Content Scanner - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - C:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O4 - HKLM\..\Run: [AsioReg] REGSVR32 /S CTASIO.DLL
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [DevconDefaultDB] C:\WINDOWS\READREG /PSCONV={NO}
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe
O4 - HKLM\..\Run: [PDFCreatorClient] "C:\Program Files\JawsSystems\Jaws PDF Creator\PDFClient.exe"
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DameWare MRC Agent] C:\WINDOWS\system32\DWRCST.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9d.exe
O4 - HKCU\..\RunOnce: [F5 Networks Cleaner] rundll32.exe C:\WINDOWS\DOWNLO~1\CACHEC~1.DLL,Run BROWSER:MSIE URL:neuvpn.neustar.biz
O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientAXDisabler] cmd.exe /C "%systemroot%\Installer\TSClientMsiTrans\tscdsbl.bat" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'Default user')
O4 - Global Startup: APC UPS Status.lnk = ?
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://quicklink
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2A0B9B82-D5C8-4D3D-8338-AD55B23662B1} (F5 Networks CacheCleaner) - https://neuvpn.neustar.biz/vdesk/cachecleaner.cab#version=6020,2007,1001,2137
O16 - DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} (F5 Networks Auto Update) - C:\DOCUME~1\CRYSTA~1\LOCALS~1\Temp\IXP000.TMP\InstallerControl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1228333341939
O16 - DPF: {6C275925-A1ED-4DD2-9CEE-9823F5FDAA10} (F5 Networks SSLTunnel) - https://neuvpn.neustar.biz/vdesk/terminal/urTermProxy.cab#version=6020,2007,1001,2136
O16 - DPF: {CC85ACDF-B277-486F-8C70-2C9B2ED2A4E7} (F5 Networks SuperHost Class) - https://neuvpn.neustar.biz/vdesk/terminal/urxshost.cab#version=6020,2007,1001,2141
O16 - DPF: {E0FF21FA-B857-45C5-8621-F120A0C17FF2} (F5 Networks Host Control) - https://neuvpn.neustar.biz/vdesk/terminal/urxhost.cab#version=6020,2007,1001,2140
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = gvnw.com
O17 - HKLM\Software\..\Telephony: DomainName = gvnw.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = gvnw.com
O20 - AppInit_DLLs: C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINDOWS\system32\DWRCS.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PDFCreatorMessages - Global Graphics Software Ltd. - C:\WINDOWS\system32\PDFCreatorMessages.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
O23 - Service: Sophos Agent - Sophos Plc - C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: Sophos Message Router - Sophos Plc - C:\Program Files\Sophos\Remote Management System\RouterNT.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/CRYSTA~1/LOCALS~1/Temp/msohtml1/01/clip_image002.gif
O24 - Desktop Component 1: (no name) - C:\Client code cheat sheet on desktop.htm
 
--
End of file - 9517 bytes

Open in new window

I'd like to close this.  Had to take the jack-hammer approach and wipe/reload the system.  So far, it hasn't happened again.  
Thanks for the help, guys.  Unfortunately, nothing I tried (your suggestions included) helped.  I ended up reloading the system.  Since then, the problem has not resurfaced.

I split the points between you for trying to help.

Thanks.