dcmathis
asked on
IE Crashes several times per day. Always the same error.
Hello, I have a user who is experiencing periodic IE 7 crashes. When it crashes, event logged states:
++++++++++++++++++++++++++ ++++++++++ ++++++++++ ++++++
Event Type: Error
Event Source: Application Error
Event Category: None
Event ID: 1000
Date: 11/24/2008
Time: 9:36:35 AM
User: N/A
Computer: CHANUS1
Description:
Faulting application iexplore.exe, version 7.0.6000.16735, faulting module rpcrt4.dll, version 5.1.2600.5512, fault address 0x000093df.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 46 61 69 6c ion Fail
0010: 75 72 65 20 20 69 65 78 ure iex
0018: 70 6c 6f 72 65 2e 65 78 plore.ex
0020: 65 20 37 2e 30 2e 36 30 e 7.0.60
0028: 30 30 2e 31 36 37 33 35 00.16735
0030: 20 69 6e 20 72 70 63 72 in rpcr
0038: 74 34 2e 64 6c 6c 20 35 t4.dll 5
0040: 2e 31 2e 32 36 30 30 2e .1.2600.
0048: 35 35 31 32 20 61 74 20 5512 at
0050: 6f 66 66 73 65 74 20 30 offset 0
0058: 30 30 30 39 33 64 66 0d 00093df.
0060: 0a .
++++++++++++++++++++++++++ ++++++++++ ++++++++++ ++++++
Look in the code section for the output from Dr. Watson.
Can anybody help me figure out what is causing this? It seems to happen several times a day for a while, and then it won't happen for several days.
Thanks for any help you can offer.
++++++++++++++++++++++++++
Event Type: Error
Event Source: Application Error
Event Category: None
Event ID: 1000
Date: 11/24/2008
Time: 9:36:35 AM
User: N/A
Computer: CHANUS1
Description:
Faulting application iexplore.exe, version 7.0.6000.16735, faulting module rpcrt4.dll, version 5.1.2600.5512, fault address 0x000093df.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 46 61 69 6c ion Fail
0010: 75 72 65 20 20 69 65 78 ure iex
0018: 70 6c 6f 72 65 2e 65 78 plore.ex
0020: 65 20 37 2e 30 2e 36 30 e 7.0.60
0028: 30 30 2e 31 36 37 33 35 00.16735
0030: 20 69 6e 20 72 70 63 72 in rpcr
0038: 74 34 2e 64 6c 6c 20 35 t4.dll 5
0040: 2e 31 2e 32 36 30 30 2e .1.2600.
0048: 35 35 31 32 20 61 74 20 5512 at
0050: 6f 66 66 73 65 74 20 30 offset 0
0058: 30 30 30 39 33 64 66 0d 00093df.
0060: 0a .
++++++++++++++++++++++++++
Look in the code section for the output from Dr. Watson.
Can anybody help me figure out what is causing this? It seems to happen several times a day for a while, and then it won't happen for several days.
Thanks for any help you can offer.
Application exception occurred:
App: C:\Program Files\Internet Explorer\IEXPLORE.EXE (pid=3760)
When: 11/13/2008 @ 16:36:24.508
Exception number: c0000005 (access violation)
*----> System Information <----*
Computer Name: CHANUS1
User Name: crystal_h
Terminal Session Id: 0
Number of Processors: 2
Processor Type: x86 Family 15 Model 4 Stepping 3
Windows Version: 5.1
Current Build: 2600
Service Pack: 3
Current Type: Multiprocessor Free
Registered Organization: GVNW Consulting, Inc.
Registered Owner: Any User
*----> Task List <----*
0 System Process
4 Error 0xD0000022
784 Error 0xD0000022
832 Error 0xD0000022
856 Error 0xD0000022
900 Error 0xD0000022
912 Error 0xD0000022
1108 Error 0xD0000022
1192 Error 0xD0000022
1316 Error 0xD0000022
1360 Error 0xD0000022
1372 Error 0xD0000022
1668 Error 0xD0000022
1744 Error 0xD0000022
1884 Error 0xD0000022
216 Error 0xD0000022
288 Error 0xD0000022
308 Error 0xD0000022
620 Error 0xD0000022
688 Error 0xD0000022
468 Error 0xD0000022
756 Error 0xD0000022
984 Error 0xD0000022
1132 Error 0xD0000022
1284 Error 0xD0000022
1572 Error 0xD0000022
1612 Error 0xD0000022
1632 Error 0xD0000022
1696 Error 0xD0000022
552 Error 0xD0000022
1220 DWRCST.exe
2576 Explorer.EXE
2996 igfxtray.exe
3016 OUTLOOK.EXE
2948 igfxpers.exe
3180 PDVDServ.exe
3200 zHotkey.exe
3252 PDFClient.exe
3268 QTTask.exe
3388 iTunesHelper.exe
3516 ctfmon.exe
3468 ALMon.exe
3908 apcsystray.exe
524 Error 0xD0000022
3760 IEXPLORE.EXE
1128 CacheCleaner.exe
1000 EXCEL.EXE
2728 drwtsn32.exe
*----> Module List <----*
(0000000000400000 - 000000000049b000: C:\Program Files\Internet Explorer\IEXPLORE.EXE
(0000000000c10000 - 0000000000ed5000: C:\WINDOWS\system32\xpsp2res.dll
(0000000001640000 - 000000000169b000: C:\Program Files\Common Files\Microsoft Shared\INK\SKCHUI.DLL
(00000000017e0000 - 00000000017e9000: C:\WINDOWS\system32\Normaliz.dll
(0000000001a20000 - 0000000001a72000: C:\WINDOWS\Downloaded Program Files\urSuperHost.dll
(0000000002570000 - 0000000002581000: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
(00000000025b0000 - 00000000025c0000: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
(00000000025d0000 - 000000000266b000: C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\MSVCR80.dll
(0000000005420000 - 000000000547b000: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
(0000000005680000 - 00000000056c0000: C:\WINDOWS\Downloaded Program Files\InstallerControl.dll
(0000000005e20000 - 0000000005e52000: C:\WINDOWS\Downloaded Program Files\cachecleaner.dll
(0000000008ca0000 - 0000000008dad000: C:\WINDOWS\Downloaded Program Files\urTermProxy.dll
(0000000010000000 - 0000000010011000: C:\WINDOWS\IME\SPGRMR.DLL
(0000000016080000 - 00000000160a5000: C:\Program Files\Bonjour\mdnsNSP.dll
(000000001b000000 - 000000001b00c000: C:\WINDOWS\system32\ImgUtil.dll
(000000001c000000 - 000000001c006000: C:\WINDOWS\HKNTDLL.dll
(00000000325c0000 - 00000000325d2000: C:\Program Files\Microsoft Office\OFFICE11\msohev.dll
(0000000042aa0000 - 0000000042b12000: C:\WINDOWS\system32\msfeeds.dll
(0000000042b90000 - 0000000042c07000: C:\WINDOWS\system32\mshtmled.dll
(0000000042ef0000 - 00000000434bd000: C:\WINDOWS\system32\IEFRAME.dll
(0000000043560000 - 00000000435c0000: C:\WINDOWS\system32\ieapfltr.dll
(00000000435d0000 - 0000000043944000: C:\WINDOWS\system32\mshtml.dll
(0000000047060000 - 0000000047081000: C:\WINDOWS\system32\xmllite.dll
(000000004ec50000 - 000000004edf6000: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5581_x-ww_dfbc4fc4\gdiplus.dll
(000000005a000000 - 000000005a03d000: C:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll
(000000005a8f0000 - 000000005a900000: C:\Program Files\Sophos\Sophos Anti-Virus\SophosBHORes.dll
(000000005ad70000 - 000000005ada8000: C:\WINDOWS\system32\UxTheme.dll
(000000005b860000 - 000000005b8b5000: C:\WINDOWS\system32\NETAPI32.dll
(000000005c2c0000 - 000000005c300000: C:\WINDOWS\ime\sptip.dll
(000000005d090000 - 000000005d12a000: C:\WINDOWS\system32\comctl32.dll
(000000005dff0000 - 000000005e01f000: C:\WINDOWS\system32\IEUI.dll
(000000005edd0000 - 000000005ede7000: C:\WINDOWS\system32\OLEPRO32.DLL
(00000000605d0000 - 00000000605d9000: C:\WINDOWS\system32\mslbui.dll
(0000000061930000 - 000000006197a000: C:\Program Files\Internet Explorer\ieproxy.dll
(00000000662b0000 - 0000000066308000: C:\WINDOWS\system32\hnetcfg.dll
(0000000068000000 - 0000000068036000: C:\WINDOWS\system32\rsaenh.dll
(0000000068100000 - 0000000068126000: C:\WINDOWS\system32\dssenh.dll
(000000006cc60000 - 000000006cc68000: C:\WINDOWS\system32\dispex.dll
(000000006d430000 - 000000006d43a000: C:\WINDOWS\system32\ddrawex.dll
(000000006d610000 - 000000006d67a000: C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
(0000000071a50000 - 0000000071a8f000: C:\WINDOWS\system32\mswsock.dll
(0000000071a90000 - 0000000071a98000: C:\WINDOWS\System32\wshtcpip.dll
(0000000071aa0000 - 0000000071aa8000: C:\WINDOWS\system32\WS2HELP.dll
(0000000071ab0000 - 0000000071ac7000: C:\WINDOWS\system32\ws2_32.dll
(0000000071b20000 - 0000000071b32000: C:\WINDOWS\system32\MPR.dll
(0000000071bf0000 - 0000000071c03000: C:\WINDOWS\system32\SAMLIB.dll
(0000000071c10000 - 0000000071c1e000: C:\WINDOWS\System32\ntlanman.dll
(0000000071c80000 - 0000000071c87000: C:\WINDOWS\System32\NETRAP.dll
(0000000071c90000 - 0000000071cd0000: C:\WINDOWS\System32\NETUI1.dll
(0000000071cd0000 - 0000000071ce7000: C:\WINDOWS\System32\NETUI0.dll
(0000000071d40000 - 0000000071d5b000: C:\WINDOWS\system32\actxprxy.dll
(00000000722b0000 - 00000000722b5000: C:\WINDOWS\system32\sensapi.dll
(0000000072d10000 - 0000000072d18000: C:\WINDOWS\system32\msacm32.drv
(0000000072d20000 - 0000000072d29000: C:\WINDOWS\system32\wdmaud.drv
(0000000073000000 - 0000000073026000: C:\WINDOWS\system32\WINSPOOL.DRV
(0000000073760000 - 00000000737ab000: C:\WINDOWS\system32\DDRAW.dll
(0000000073b30000 - 0000000073b45000: C:\WINDOWS\system32\mscms.dll
(0000000073bc0000 - 0000000073bc6000: C:\WINDOWS\system32\DCIMAN32.dll
(00000000746c0000 - 00000000746e9000: C:\WINDOWS\system32\msls31.dll
(00000000746f0000 - 000000007471a000: C:\WINDOWS\system32\msimtf.dll
(0000000074720000 - 000000007476c000: C:\WINDOWS\system32\MSCTF.dll
(0000000074980000 - 0000000074a94000: C:\WINDOWS\system32\msxml3.dll
(0000000074c80000 - 0000000074cac000: C:\WINDOWS\system32\OLEACC.dll
(0000000074d90000 - 0000000074dfb000: C:\WINDOWS\system32\USP10.dll
(00000000755c0000 - 00000000755ee000: C:\WINDOWS\system32\msctfime.ime
(0000000075c50000 - 0000000075ccd000: C:\WINDOWS\system32\jscript.dll
(0000000075cf0000 - 0000000075d81000: C:\WINDOWS\system32\MLANG.dll
(0000000075f60000 - 0000000075f67000: C:\WINDOWS\System32\drprov.dll
(0000000075f70000 - 0000000075f7a000: C:\WINDOWS\System32\davclnt.dll
(0000000076080000 - 00000000760e5000: C:\WINDOWS\system32\MSVCP60.dll
(0000000076380000 - 0000000076385000: C:\WINDOWS\system32\MSIMG32.dll
(0000000076390000 - 00000000763ad000: C:\WINDOWS\system32\IMM32.DLL
(0000000076600000 - 000000007661d000: C:\WINDOWS\System32\CSCDLL.dll
(00000000767f0000 - 0000000076817000: C:\WINDOWS\system32\schannel.dll
(00000000769c0000 - 0000000076a74000: C:\WINDOWS\system32\USERENV.dll
(0000000076b40000 - 0000000076b6d000: C:\WINDOWS\system32\WINMM.dll
(0000000076bf0000 - 0000000076bfb000: C:\WINDOWS\system32\PSAPI.DLL
(0000000076c30000 - 0000000076c5e000: C:\WINDOWS\system32\WINTRUST.dll
(0000000076c90000 - 0000000076cb8000: C:\WINDOWS\system32\IMAGEHLP.dll
(0000000076d60000 - 0000000076d79000: C:\WINDOWS\system32\iphlpapi.dll
(0000000076e80000 - 0000000076e8e000: C:\WINDOWS\system32\rtutils.dll
(0000000076e90000 - 0000000076ea2000: C:\WINDOWS\system32\rasman.dll
(0000000076eb0000 - 0000000076edf000: C:\WINDOWS\system32\TAPI32.dll
(0000000076ee0000 - 0000000076f1c000: C:\WINDOWS\system32\RASAPI32.dll
(0000000076f20000 - 0000000076f47000: C:\WINDOWS\system32\DNSAPI.dll
(0000000076f60000 - 0000000076f8c000: C:\WINDOWS\system32\WLDAP32.dll
(0000000076fb0000 - 0000000076fb8000: C:\WINDOWS\System32\winrnr.dll
(0000000076fc0000 - 0000000076fc6000: C:\WINDOWS\system32\rasadhlp.dll
(0000000076fd0000 - 000000007704f000: C:\WINDOWS\system32\CLBCATQ.DLL
(0000000077050000 - 0000000077115000: C:\WINDOWS\system32\COMRes.dll
(0000000077120000 - 00000000771ab000: C:\WINDOWS\system32\OLEAUT32.dll
(00000000773d0000 - 00000000774d3000: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
(00000000774e0000 - 000000007761d000: C:\WINDOWS\system32\ole32.dll
(0000000077690000 - 00000000776b1000: C:\WINDOWS\system32\NTMARTA.DLL
(0000000077920000 - 0000000077a13000: C:\WINDOWS\system32\SETUPAPI.dll
(0000000077a20000 - 0000000077a74000: C:\WINDOWS\System32\cscui.dll
(0000000077a80000 - 0000000077b15000: C:\WINDOWS\system32\CRYPT32.dll
(0000000077b20000 - 0000000077b32000: C:\WINDOWS\system32\MSASN1.dll
(0000000077b40000 - 0000000077b62000: C:\WINDOWS\system32\apphelp.dll
(0000000077bd0000 - 0000000077bd7000: C:\WINDOWS\system32\midimap.dll
(0000000077be0000 - 0000000077bf5000: C:\WINDOWS\system32\MSACM32.dll
(0000000077c00000 - 0000000077c08000: C:\WINDOWS\system32\VERSION.dll
(0000000077c10000 - 0000000077c68000: C:\WINDOWS\system32\msvcrt.dll
(0000000077c70000 - 0000000077c94000: C:\WINDOWS\system32\msv1_0.dll
(0000000077dd0000 - 0000000077e6b000: C:\WINDOWS\system32\ADVAPI32.dll
(0000000077e70000 - 0000000077f02000: C:\WINDOWS\system32\RPCRT4.dll
(0000000077f10000 - 0000000077f59000: C:\WINDOWS\system32\GDI32.dll
(0000000077f60000 - 0000000077fd6000: C:\WINDOWS\system32\SHLWAPI.dll
(0000000077fe0000 - 0000000077ff1000: C:\WINDOWS\system32\Secur32.dll
(0000000078000000 - 0000000078045000: C:\WINDOWS\system32\iertutil.dll
(0000000078050000 - 0000000078120000: C:\WINDOWS\system32\WININET.dll
(0000000078130000 - 0000000078257000: C:\WINDOWS\system32\urlmon.dll
(000000007c420000 - 000000007c4a7000: C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\MSVCP80.dll
(000000007c800000 - 000000007c8f6000: C:\WINDOWS\system32\kernel32.dll
(000000007c900000 - 000000007c9af000: C:\WINDOWS\system32\ntdll.dll
(000000007c9c0000 - 000000007d1d7000: C:\WINDOWS\system32\SHELL32.dll
(000000007d1e0000 - 000000007d49c000: C:\WINDOWS\system32\msi.dll
(000000007e410000 - 000000007e4a1000: C:\WINDOWS\system32\USER32.dll
(000000007e720000 - 000000007e7d0000: C:\WINDOWS\system32\SXS.DLL
*----> State Dump for Thread Id 0x9a4 <----*
eax=00000001 ebx=0012e6c4 ecx=7c8095a4 edx=7c90e4f4 esi=00000000 edi=7ffde000
eip=7c90e4f4 esp=0012e69c ebp=0012e738 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\ntdll.dll -
function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp
*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\USER32.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\IEUI.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\IEFRAME.dll -
*** ERROR: Module load completed but symbols could not be loaded for C:\Program Files\Internet Explorer\IEXPLORE.EXE
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\kernel32.dll -
ChildEBP RetAddr Args to Child
0012e738 7e4195f9 00000002 0012e760 00000000 ntdll!KiFastSystemCallRet
0012e794 5dff6029 00000001 0012e7c8 ffffffff USER32!GetLastInputInfo+0x105
0012e7b4 5dff632d 000004ff ffffffff 00000000 IEUI!DUserRegisterSuper+0x9bd
0012e7dc 5dff60d8 000004ff 00000000 42fa98cd IEUI!PeekMessageExW+0x21f
0012e818 42f9ab4c 0014fe80 0012e848 42f9bbbb IEUI!WaitMessageEx+0x31
0012e824 42f9bbbb 00000000 00000000 0014cec0 IEFRAME!Ordinal300+0xfb0a
0012e848 42f9bb09 19a4000a 0014cec0 00000000 IEFRAME!Ordinal101+0x341
0012f8b8 42f9b9b9 0014cec0 77f648d4 00000000 IEFRAME!Ordinal101+0x28f
0012fae8 0040147c 00144ee0 0000000a 00410070 IEFRAME!Ordinal101+0x13f
0012ff2c 00401317 00400000 00000000 000206c4 IEXPLORE+0x147c
0012ffc0 7c817067 000945d8 00e4f0dc 7ffde000 IEXPLORE+0x1317
0012fff0 00000000 00402e45 00000000 78746341 kernel32!RegisterWaitForInputIdle+0x49
*----> Raw Stack Dump <----*
000000000012e69c 2c df 90 7c 74 95 80 7c - 02 00 00 00 c4 e6 12 00 ,..|t..|........
000000000012e6ac 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000012e6bc 02 00 00 00 00 00 00 00 - 28 01 00 00 28 00 00 00 ........(...(...
000000000012e6cc 00 00 00 00 00 00 00 00 - a0 e6 12 00 00 00 00 00 ................
000000000012e6dc 30 e7 12 00 8f 04 44 7e - 14 00 00 00 01 00 00 00 0.....D~........
000000000012e6ec 00 00 00 00 00 00 00 00 - 10 00 00 00 cd c5 fb 42 ...............B
000000000012e6fc 68 01 08 00 0f 00 00 00 - 00 e0 fd 7f 00 d0 fd 7f h...............
000000000012e70c 44 e2 5e 00 00 00 00 00 - c4 e6 12 00 01 00 00 00 D.^.............
000000000012e71c 02 00 00 00 b8 e6 12 00 - ff ff ff ff b0 ff 12 00 ................
000000000012e72c c0 9a 83 7c 68 96 80 7c - 00 00 00 00 94 e7 12 00 ...|h..|........
000000000012e73c f9 95 41 7e 02 00 00 00 - 60 e7 12 00 00 00 00 00 ..A~....`.......
000000000012e74c ff ff ff ff 00 00 00 00 - ff ff ff ff 01 00 00 00 ................
000000000012e75c 01 00 00 00 28 01 00 00 - 28 00 00 00 bd 62 ff 5d ....(...(....b.]
000000000012e76c f3 73 1d 03 a8 62 15 00 - 01 00 00 00 00 00 00 00 .s...b..........
000000000012e77c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000012e78c 00 d0 fd 7f 28 00 00 00 - b4 e7 12 00 29 60 ff 5d ....(.......)`.]
000000000012e79c 01 00 00 00 c8 e7 12 00 - ff ff ff ff ff 04 00 00 ................
000000000012e7ac 60 e7 12 00 f0 61 15 00 - dc e7 12 00 2d 63 ff 5d `....a......-c.]
000000000012e7bc ff 04 00 00 ff ff ff ff - 00 00 00 00 28 01 00 00 ............(...
000000000012e7cc 00 00 00 00 48 78 f9 42 - 80 fe 14 00 9f 00 00 00 ....Hx.B........
*----> State Dump for Thread Id 0xa80 <----*
eax=00000000 ebx=0113fde8 ecx=0113ffa4 edx=7c90e4f4 esi=00000000 edi=7ffde000
eip=7c90e4f4 esp=0113fdc0 ebp=0113fe5c iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\msvcrt.dll -
ChildEBP RetAddr Args to Child
0113fe5c 7e4195f9 00000002 0113fe84 00000000 ntdll!KiFastSystemCallRet
0113feb8 5dff6029 00000001 0113feec ffffffff USER32!GetLastInputInfo+0x105
0113fed8 5dff93e4 000004ff ffffffff 00000001 IEUI!DUserRegisterSuper+0x9bd
0113ff0c 5dff98a6 0113ff4c 00000000 00000000 IEUI!SetGadgetParent+0x53d
0113ff2c 5dff9806 0113ff4c 00000000 00000000 IEUI!GetMessageExA+0x3d
0113ff80 77c3a3b0 00000000 7c910000 7c912cae IEUI!SetGadgetParent+0x95f
0113ffb4 7c80b713 008d51e8 7c910000 7c912cae msvcrt!endthreadex+0xa9
0113ffec 00000000 77c3a341 008d51e8 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
000000000113fdc0 2c df 90 7c 74 95 80 7c - 02 00 00 00 e8 fd 13 01 ,..|t..|........
000000000113fdd0 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000113fde0 02 00 00 00 04 00 00 00 - 20 01 00 00 1c 01 00 00 ........ .......
000000000113fdf0 78 01 14 00 0c fe 13 01 - 79 a2 ff 5d 5f 3b 01 da x.......y..]_;..
000000000113fe00 b0 02 00 00 20 00 00 00 - 14 00 00 00 01 00 00 00 .... ...........
000000000113fe10 00 00 00 00 00 00 00 00 - 10 00 00 00 f8 e8 0f 0c ................
000000000113fe20 2c fe 13 01 c5 6f ff 5d - 00 e0 fd 7f 00 b0 fd 7f ,....o.]........
000000000113fe30 a2 6f ff 5d 00 00 00 00 - e8 fd 13 01 94 fe 13 01 .o.]............
000000000113fe40 02 00 00 00 dc fd 13 01 - 63 6f ff 5d a4 ff 13 01 ........co.]....
000000000113fe50 c0 9a 83 7c 68 96 80 7c - 00 00 00 00 b8 fe 13 01 ...|h..|........
000000000113fe60 f9 95 41 7e 02 00 00 00 - 84 fe 13 01 00 00 00 00 ..A~............
000000000113fe70 ff ff ff ff 00 00 00 00 - ff ff ff ff 01 00 00 00 ................
000000000113fe80 01 00 00 00 20 01 00 00 - 1c 01 00 00 bd 62 ff 5d .... ........b.]
000000000113fe90 c3 e2 42 02 28 47 15 00 - 01 00 00 00 00 00 00 00 ..B.(G..........
000000000113fea0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000113feb0 00 b0 fd 7f 1c 01 00 00 - d8 fe 13 01 29 60 ff 5d ............)`.]
000000000113fec0 01 00 00 00 ec fe 13 01 - ff ff ff ff ff 04 00 00 ................
000000000113fed0 84 fe 13 01 70 46 15 00 - 0c ff 13 01 e4 93 ff 5d ....pF.........]
000000000113fee0 ff 04 00 00 ff ff ff ff - 01 00 00 00 20 01 00 00 ............ ...
000000000113fef0 00 00 00 00 00 00 00 00 - e8 51 8d 00 01 00 00 00 .........Q......
*----> State Dump for Thread Id 0xac0 <----*
eax=000025ff ebx=00000000 ecx=00000210 edx=00000000 esi=0018b0a8 edi=00000000
eip=7c90e4f4 esp=01bfff50 ebp=01bfffb4 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
01bfffb4 7c80b713 00191400 0014d44c 0012e5b8 ntdll!KiFastSystemCallRet
01bfffec 00000000 42f8e48c 0018b0a8 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
0000000001bfff50 18 94 41 7e 8c f3 f8 42 - 4c d4 14 00 b8 e5 12 00 ..A~...BL.......
0000000001bfff60 a8 b0 18 00 dc 02 02 00 - 13 01 00 00 01 00 00 00 ................
0000000001bfff70 00 00 00 00 00 77 1d 03 - 44 02 00 00 b7 01 00 00 .....w..D.......
0000000001bfff80 90 b0 18 00 d4 d7 18 00 - 01 00 00 00 00 00 00 00 ................
0000000001bfff90 a0 da 19 00 01 00 00 00 - 00 00 00 00 c4 03 04 00 ................
0000000001bfffa0 68 01 08 00 50 37 19 00 - 00 00 00 00 84 13 19 00 h...P7..........
0000000001bfffb0 b8 0d 19 00 ec ff bf 01 - 13 b7 80 7c 00 14 19 00 ...........|....
0000000001bfffc0 4c d4 14 00 b8 e5 12 00 - a8 b0 18 00 00 80 fd 7f L...............
0000000001bfffd0 00 c6 db 86 c0 ff bf 01 - 30 49 57 86 ff ff ff ff ........0IW.....
0000000001bfffe0 c0 9a 83 7c 20 b7 80 7c - 00 00 00 00 00 00 00 00 ...| ..|........
0000000001bffff0 00 00 00 00 8c e4 f8 42 - a8 b0 18 00 00 00 00 00 .......B........
0000000001c00000 41 63 74 78 20 00 00 00 - 01 00 00 00 60 19 00 00 Actx .......`...
0000000001c00010 7c 00 00 00 00 00 00 00 - 20 00 00 00 00 00 00 00 |....... .......
0000000001c00020 14 00 00 00 01 00 00 00 - 03 00 00 00 34 00 00 00 ............4...
0000000001c00030 bc 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001c00040 00 00 00 00 00 00 00 00 - 00 00 00 00 02 00 00 00 ................
0000000001c00050 00 00 00 00 00 00 00 00 - 00 00 00 00 78 01 00 00 ............x...
0000000001c00060 7c 01 00 00 00 00 00 00 - cd ea ce 32 f4 02 00 00 |..........2....
0000000001c00070 42 00 00 00 38 03 00 00 - 02 03 00 00 10 00 00 00 B...8...........
0000000001c00080 03 00 00 00 8c 00 00 00 - 02 00 00 00 01 00 00 00 ................
*----> State Dump for Thread Id 0x8a8 <----*
eax=00000000 ebx=0279feb0 ecx=001a7188 edx=001a7598 esi=00000000 edi=7ffde000
eip=7c90e4f4 esp=0279fe88 ebp=0279ff24 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll -
ChildEBP RetAddr Args to Child
0279ff24 7c80a105 00000003 0279ff78 00000000 ntdll!KiFastSystemCallRet
0279ff40 5a00b0f0 00000003 0279ff78 00000000 kernel32!WaitForMultipleObjects+0x18
0279ffb4 7c80b713 5a034aa4 01bff11c 01bff11c SophosBHO+0xb0f0
0279ffec 00000000 5a00b3d0 5a034aa4 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
000000000279fe88 2c df 90 7c 74 95 80 7c - 03 00 00 00 b0 fe 79 02 ,..|t..|......y.
000000000279fe98 01 00 00 00 00 00 00 00 - 00 00 00 00 24 03 00 00 ............$...
000000000279fea8 a4 4a 03 5a 00 00 00 00 - 10 03 00 00 14 03 00 00 .J.Z............
000000000279feb8 24 03 00 00 b4 7b 02 5a - 0e 01 00 00 28 00 00 00 $....{.Z....(...
000000000279fec8 00 00 00 00 f8 4c 02 5a - 14 00 00 00 01 00 00 00 .....L.Z........
000000000279fed8 00 00 00 00 00 00 00 00 - 10 00 00 00 00 00 00 00 ................
000000000279fee8 d8 fe 79 02 44 ff 79 02 - 00 e0 fd 7f 00 70 fd 7f ..y.D.y......p..
000000000279fef8 50 ff 79 02 00 00 00 00 - b0 fe 79 02 6c d5 90 7c P.y.......y.l..|
000000000279ff08 03 00 00 00 a4 fe 79 02 - 00 00 10 00 a8 ff 79 02 ......y.......y.
000000000279ff18 c0 9a 83 7c 68 96 80 7c - 00 00 00 00 40 ff 79 02 ...|h..|....@.y.
000000000279ff28 05 a1 80 7c 03 00 00 00 - 78 ff 79 02 00 00 00 00 ...|....x.y.....
000000000279ff38 ff ff ff ff 00 00 00 00 - b4 ff 79 02 f0 b0 00 5a ..........y....Z
000000000279ff48 03 00 00 00 78 ff 79 02 - 00 00 00 00 ff ff ff ff ....x.y.........
000000000279ff58 f4 89 bc c1 1c f1 bf 01 - 1c f1 bf 01 a4 4a 03 5a .............J.Z
000000000279ff68 10 03 00 00 14 03 00 00 - 24 03 00 00 28 03 00 00 ........$...(...
000000000279ff78 10 03 00 00 14 03 00 00 - 24 03 00 00 98 68 02 5a ........$....h.Z
000000000279ff88 00 00 00 00 98 68 02 5a - 00 00 00 00 98 68 02 5a .....h.Z.....h.Z
000000000279ff98 24 03 00 00 01 00 00 00 - 00 00 00 00 58 ff 79 02 $...........X.y.
000000000279ffa8 dc ff 79 02 08 2e 02 5a - 03 00 00 00 ec ff 79 02 ..y....Z......y.
000000000279ffb8 13 b7 80 7c a4 4a 03 5a - 1c f1 bf 01 1c f1 bf 01 ...|.J.Z........
*----> State Dump for Thread Id 0x3f0 <----*
eax=00000000 ebx=001c7a90 ecx=02bbfad4 edx=7c90e4f4 esi=7fffffff edi=ffffffff
eip=7c90e4f4 esp=02bbfad4 ebp=02bbfb10 iopl=0 nv up ei ng nz ac po cy
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000297
function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp
*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\mswsock.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\ws2_32.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\WININET.dll -
ChildEBP RetAddr Args to Child
02bbfb10 71a55fa7 00000468 000004c0 00000000 ntdll!KiFastSystemCallRet
02bbfc04 71ab314f 00000001 02bbfe84 02bbfc7c mswsock+0x5fa7
02bbfc54 780760ed 00000001 02bbfe84 02bbfc7c ws2_32!select+0xa7
02bbffac 78072a68 02bbffec 7c80b713 001c7a20 WININET!Ordinal101+0x27ec
02bbffb4 7c80b713 001c7a20 01bf959c 00140000 WININET!InternetSetStatusCallback+0x1d9
02bbffec 00000000 78072a5b 001c7a20 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
0000000002bbfad4 3c df 90 7c 2b 40 a5 71 - 68 04 00 00 01 00 00 00 <..|+@.qh.......
0000000002bbfae4 fc fa bb 02 b4 fb bb 02 - 84 fe bb 02 a4 fb bb 02 ................
0000000002bbfaf4 e8 aa da 3f e0 45 c9 01 - ff ff ff ff ff ff ff 7f ...?.E..........
0000000002bbfb04 90 7a 1c 00 00 00 00 00 - 00 00 00 00 04 fc bb 02 .z..............
0000000002bbfb14 a7 5f a5 71 68 04 00 00 - c0 04 00 00 00 00 00 00 ._.qh...........
0000000002bbfb24 04 00 00 00 80 fd bb 02 - b8 6a 53 02 7c fc bb 02 .........jS.|...
0000000002bbfb34 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000002bbfb44 01 00 00 00 80 0f 05 fd - ff ff ff ff 3d 00 91 7c ............=..|
0000000002bbfb54 00 00 00 00 10 00 00 00 - 20 00 00 00 18 27 9a 02 ........ ....'..
0000000002bbfb64 00 00 00 00 18 27 9a 02 - 18 27 9a 02 18 27 9a 00 .....'...'...'..
0000000002bbfb74 38 fc bb 02 00 00 14 00 - cd 41 a5 71 1c 00 00 00 8........A.q....
0000000002bbfb84 90 7a 1c 00 c0 fb bb 02 - 7c fc bb 02 80 fd bb 02 .z......|.......
0000000002bbfb94 00 00 00 00 a4 fb bb 02 - 00 00 00 00 00 00 00 00 ................
0000000002bbfba4 80 0f 05 fd ff ff ff ff - 01 00 00 00 00 00 91 7c ...............|
0000000002bbfbb4 c0 04 00 00 19 00 00 00 - 00 00 00 00 fd 99 80 7c ...............|
0000000002bbfbc4 34 52 70 07 28 fc 55 04 - 40 52 70 07 e0 fb bb 02 4Rp.(.U.@Rp.....
0000000002bbfbd4 02 3e ab 71 c0 81 53 02 - c0 81 53 02 c4 fb bb 02 .>.q..S...S.....
0000000002bbfbe4 e3 3d ab 71 09 3a 00 00 - 28 fb bb 02 0c 15 aa 71 .=.q.:..(......q
0000000002bbfbf4 44 fc bb 02 28 72 a7 71 - 60 2e a5 71 ff ff ff ff D...(r.q`..q....
0000000002bbfc04 54 fc bb 02 4f 31 ab 71 - 01 00 00 00 84 fe bb 02 T...O1.q........
*----> State Dump for Thread Id 0x690 <----*
eax=000000c0 ebx=00000000 ecx=7c800000 edx=00000000 esi=01bf8bf8 edi=02080000
eip=7c90e4f4 esp=02cbff9c ebp=02cbffb4 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
02cbffb4 7c80b713 00000000 02080000 01bf8bf8 ntdll!KiFastSystemCallRet
02cbffec 00000000 7c927ebb 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
0000000002cbff9c fc d1 90 7c 02 7f 92 7c - 01 00 00 00 ac ff cb 02 ...|...|........
0000000002cbffac 00 00 00 00 00 00 00 80 - ec ff cb 02 13 b7 80 7c ...............|
0000000002cbffbc 00 00 00 00 00 00 08 02 - f8 8b bf 01 00 00 00 00 ................
0000000002cbffcc 00 40 fd 7f 00 e6 db 86 - c0 ff cb 02 a0 37 ca 86 .@...........7..
0000000002cbffdc ff ff ff ff c0 9a 83 7c - 20 b7 80 7c 00 00 00 00 .......| ..|....
0000000002cbffec 00 00 00 00 00 00 00 00 - bb 7e 92 7c 00 00 00 00 .........~.|....
0000000002cbfffc 00 00 00 00 80 09 00 00 - 00 30 00 00 e0 0f d0 b2 .........0......
0000000002cc000c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000002cc001c 00 00 00 00 23 33 01 00 - 00 00 00 00 7a 81 07 00 ....#3......z...
0000000002cc002c 00 00 00 00 d7 11 03 00 - 00 00 00 00 59 00 00 00 ............Y...
0000000002cc003c 41 00 00 00 04 00 00 00 - 3b 00 00 00 00 00 00 00 A.......;.......
0000000002cc004c ea 02 00 00 b6 02 00 00 - 70 00 00 00 00 00 00 00 ........p.......
0000000002cc005c 00 00 00 00 68 26 cc 02 - 68 00 cc 02 80 17 58 04 ....h&..h.....X.
0000000002cc006c 00 00 00 00 48 1d 63 07 - 00 00 00 00 00 00 00 00 ....H.c.........
0000000002cc007c 00 00 00 00 00 00 00 00 - 00 00 00 00 b8 00 62 04 ..............b.
0000000002cc008c 80 49 88 0a 00 00 00 00 - 00 00 00 00 00 00 00 00 .I..............
0000000002cc009c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000002cc00ac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000002cc00bc 98 3f 07 07 e8 5e a5 0a - 00 00 00 00 00 00 00 00 .?...^..........
0000000002cc00cc 00 00 00 00 00 00 00 00 - 38 d9 67 07 00 00 00 00 ........8.g.....
*----> State Dump for Thread Id 0x898 <----*
eax=72d230e8 ebx=03affef8 ecx=000000f8 edx=00000090 esi=00000000 edi=7ffde000
eip=7c90e4f4 esp=03affed0 ebp=03afff6c iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\wdmaud.drv -
ChildEBP RetAddr Args to Child
03afff6c 7c80a105 00000002 03afffa4 00000000 ntdll!KiFastSystemCallRet
03afff88 72d2312a 00000002 03afffa4 00000000 kernel32!WaitForMultipleObjects+0x18
03afffb4 7c80b713 00000000 00000000 001fbd78 wdmaud!midMessage+0x348
03afffec 00000000 72d230e8 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
0000000003affed0 2c df 90 7c 74 95 80 7c - 02 00 00 00 f8 fe af 03 ,..|t..|........
0000000003affee0 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000003affef0 00 00 00 00 00 00 00 00 - 98 06 00 00 50 06 00 00 ............P...
0000000003afff00 46 02 00 00 ab 59 54 80 - 28 4c 94 a9 78 26 85 86 F....YT.(L..x&..
0000000003afff10 20 e1 73 f7 14 28 85 86 - 14 00 00 00 01 00 00 00 .s..(..........
0000000003afff20 00 00 00 00 00 00 00 00 - 10 00 00 00 78 26 85 86 ............x&..
0000000003afff30 ac 26 85 86 00 00 00 00 - 00 e0 fd 7f 00 b0 fa 7f .&..............
0000000003afff40 78 26 85 86 00 00 00 00 - f8 fe af 03 82 2f 50 80 x&.........../P.
0000000003afff50 02 00 00 00 ec fe af 03 - 00 00 00 00 dc ff af 03 ................
0000000003afff60 c0 9a 83 7c 68 96 80 7c - 00 00 00 00 88 ff af 03 ...|h..|........
0000000003afff70 05 a1 80 7c 02 00 00 00 - a4 ff af 03 00 00 00 00 ...|............
0000000003afff80 ff ff ff ff 00 00 00 00 - b4 ff af 03 2a 31 d2 72 ............*1.r
0000000003afff90 02 00 00 00 a4 ff af 03 - 00 00 00 00 ff ff ff ff ................
0000000003afffa0 78 bd 1f 00 98 06 00 00 - 50 06 00 00 f2 6e 6e 80 x.......P....nn.
0000000003afffb0 fc d9 90 7c ec ff af 03 - 13 b7 80 7c 00 00 00 00 ...|.......|....
0000000003afffc0 00 00 00 00 78 bd 1f 00 - 00 00 00 00 00 b0 fa 7f ....x...........
0000000003afffd0 00 c6 db 86 c0 ff af 03 - c0 37 62 86 ff ff ff ff .........7b.....
0000000003afffe0 c0 9a 83 7c 20 b7 80 7c - 00 00 00 00 00 00 00 00 ...| ..|........
0000000003affff0 00 00 00 00 e8 30 d2 72 - 00 00 00 00 00 00 00 00 .....0.r........
0000000003b00000 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
*----> State Dump for Thread Id 0x878 <----*
eax=012300a0 ebx=000006c8 ecx=00000007 edx=00140608 esi=03bfff98 edi=7e42772b
eip=7c90e4f4 esp=03bfff54 ebp=03bfff78 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp
*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\WINMM.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
03bfff78 76b44e31 03bfff98 00000000 00000000 ntdll!KiFastSystemCallRet
03bfffb4 7c80b713 000006c8 00000200 0000002b WINMM!PlaySoundW+0x7e2
03bfffec 00000000 76b44dca 000006c8 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
0000000003bfff54 be 91 41 7e 6b 77 42 7e - 98 ff bf 03 00 00 00 00 ..A~kwB~........
0000000003bfff64 00 00 00 00 00 00 00 00 - c8 06 00 00 2b 77 42 7e ............+wB~
0000000003bfff74 00 00 00 00 b4 ff bf 03 - 31 4e b4 76 98 ff bf 03 ........1N.v....
0000000003bfff84 00 00 00 00 00 00 00 00 - 00 00 00 00 00 02 00 00 ................
0000000003bfff94 2b 00 00 00 ea 02 02 00 - bc 03 00 00 80 96 6b 04 +.............k.
0000000003bfffa4 00 00 00 00 94 04 1c 03 - 73 01 00 00 af 01 00 00 ........s.......
0000000003bfffb4 ec ff bf 03 13 b7 80 7c - c8 06 00 00 00 02 00 00 .......|........
0000000003bfffc4 2b 00 00 00 c8 06 00 00 - 00 a0 fa 7f 00 e6 db 86 +...............
0000000003bfffd4 c0 ff bf 03 f8 37 62 86 - ff ff ff ff c0 9a 83 7c .....7b........|
0000000003bfffe4 20 b7 80 7c 00 00 00 00 - 00 00 00 00 00 00 00 00 ..|............
0000000003bffff4 ca 4d b4 76 c8 06 00 00 - 00 00 00 00 00 00 00 00 .M.v............
0000000003c00004 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000003c00014 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000003c00024 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000003c00034 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000003c00044 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000003c00054 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000003c00064 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000003c00074 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000003c00084 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
*----> State Dump for Thread Id 0x5c8 <----*
eax=00000004 ebx=00000000 ecx=00000001 edx=00000004 esi=7c97b420 edi=7c97b440
eip=7c90e4f4 esp=03dfff70 ebp=03dfffb4 iopl=0 nv up ei ng nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000286
function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
03dfffb4 7c80b713 00000000 001fbd78 00000001 ntdll!KiFastSystemCallRet
03dfffec 00000000 7c910230 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
0000000003dfff70 2c da 90 7c 6d 02 91 7c - 30 04 00 00 ac ff df 03 ,..|m..|0.......
0000000003dfff80 b0 ff df 03 98 ff df 03 - a0 ff df 03 78 bd 1f 00 ............x...
0000000003dfff90 01 00 00 00 00 00 00 00 - 00 00 00 00 18 21 29 07 .............!).
0000000003dfffa0 00 7c 28 e8 ff ff ff ff - 01 00 00 00 c9 7a 92 7c .|(..........z.|
0000000003dfffb0 a0 20 29 07 ec ff df 03 - 13 b7 80 7c 00 00 00 00 . )........|....
0000000003dfffc0 78 bd 1f 00 01 00 00 00 - 00 00 00 00 00 80 fa 7f x...............
0000000003dfffd0 00 c6 db 86 c0 ff df 03 - f8 37 62 86 ff ff ff ff .........7b.....
0000000003dfffe0 c0 9a 83 7c 20 b7 80 7c - 00 00 00 00 00 00 00 00 ...| ..|........
0000000003dffff0 00 00 00 00 30 02 91 7c - 00 00 00 00 00 00 00 00 ....0..|........
0000000003e00000 00 00 00 00 9f 40 13 00 - 10 00 90 01 17 00 b0 01 .....@..........
0000000003e00010 ff ff ff 00 ff ff ff 00 - 00 00 00 00 00 00 00 00 ................
0000000003e00020 ff ff ff 00 ff ff ff 00 - 00 00 00 00 00 00 00 00 ................
0000000003e00030 00 00 00 00 01 00 00 00 - 0d 02 01 01 00 00 00 00 ................
0000000003e00040 00 00 00 00 00 00 00 00 - 00 00 00 00 02 00 00 00 ................
0000000003e00050 01 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000003e00060 00 00 00 00 1f 00 89 01 - 00 00 00 00 ff ff ff ff ................
0000000003e00070 ff ff ff ff 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000003e00080 00 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000003e00090 21 00 8a 01 00 00 00 40 - 06 00 00 00 00 00 00 00 !......@........
0000000003e000a0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 40 ...............@
*----> State Dump for Thread Id 0xa04 <----*
eax=000000c0 ebx=00000000 ecx=03dff5ac edx=7c916fc8 esi=00000000 edi=00000001
eip=7c90e4f4 esp=03cffcec ebp=03cfffb4 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
03cfffb4 7c80b713 00000000 71a569cf 03dff98c ntdll!KiFastSystemCallRet
03cfffec 00000000 7c929b6f 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
0000000003cffcec 2c df 90 7c 96 9c 92 7c - 17 00 00 00 30 fd cf 03 ,..|...|....0...
0000000003cffcfc 01 00 00 00 01 00 00 00 - 00 00 00 00 cf 69 a5 71 .............i.q
0000000003cffd0c 8c f9 df 03 00 00 00 00 - 80 c9 97 7c 80 c9 97 7c ...........|...|
0000000003cffd1c 54 07 00 00 04 0a 00 00 - 17 00 00 00 17 00 00 00 T...............
0000000003cffd2c 16 00 00 00 50 07 00 00 - 4c 07 00 00 b0 05 00 00 ....P...L.......
0000000003cffd3c 68 07 00 00 74 07 00 00 - 90 07 00 00 9c 07 00 00 h...t...........
0000000003cffd4c a8 07 00 00 c8 07 00 00 - d0 07 00 00 d8 07 00 00 ................
0000000003cffd5c e4 07 00 00 ec 07 00 00 - f8 07 00 00 08 08 00 00 ................
0000000003cffd6c 14 08 00 00 1c 08 00 00 - 28 08 00 00 34 08 00 00 ........(...4...
0000000003cffd7c 40 08 00 00 48 08 00 00 - 50 05 00 00 58 05 00 00 @...H...P...X...
0000000003cffd8c f4 0b 00 00 cc 11 00 00 - c0 0d 00 00 10 0d 00 00 ................
0000000003cffd9c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000003cffdac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000003cffdbc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000003cffdcc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000003cffddc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000003cffdec 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000003cffdfc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000003cffe0c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000003cffe1c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
*----> State Dump for Thread Id 0xb40 <----*
eax=00000000 ebx=0402fef4 ecx=7ffa7000 edx=76a613f0 esi=00000000 edi=7ffde000
eip=7c90e4f4 esp=0402fecc ebp=0402ff68 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\USERENV.dll -
ChildEBP RetAddr Args to Child
0402ff68 7c80a105 00000003 76a61348 00000000 ntdll!KiFastSystemCallRet
0402ff84 769c87bd 00000003 76a61348 00000000 kernel32!WaitForMultipleObjects+0x18
0402ffb4 7c80b713 00000000 00000000 00000000 USERENV!RegisterGPNotification+0x1b6
0402ffec 00000000 769c8761 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
000000000402fecc 2c df 90 7c 74 95 80 7c - 03 00 00 00 f4 fe 02 04 ,..|t..|........
000000000402fedc 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000402feec f0 13 a6 76 d7 9b 80 7c - 78 07 00 00 7c 07 00 00 ...v...|x...|...
000000000402fefc 80 07 00 00 5c fe 02 04 - 6c ff 02 04 6c ff 02 04 ....\...l...l...
000000000402ff0c 00 e9 90 7c 40 00 91 7c - 14 00 00 00 01 00 00 00 ...|@..|........
000000000402ff1c 00 00 00 00 00 00 00 00 - 10 00 00 00 fa 1b 80 7c ...............|
000000000402ff2c 00 00 00 00 00 00 00 00 - 00 e0 fd 7f 00 70 fa 7f .............p..
000000000402ff3c d8 01 44 03 00 00 00 00 - f4 fe 02 04 00 00 00 00 ..D.............
000000000402ff4c 03 00 00 00 e8 fe 02 04 - 00 00 00 00 dc ff 02 04 ................
000000000402ff5c c0 9a 83 7c 68 96 80 7c - 00 00 00 00 84 ff 02 04 ...|h..|........
000000000402ff6c 05 a1 80 7c 03 00 00 00 - 48 13 a6 76 00 00 00 00 ...|....H..v....
000000000402ff7c ff ff ff ff 00 00 00 00 - b4 ff 02 04 bd 87 9c 76 ...............v
000000000402ff8c 03 00 00 00 48 13 a6 76 - 00 00 00 00 ff ff ff ff ....H..v........
000000000402ff9c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 9c 76 ...............v
000000000402ffac 03 00 00 00 00 00 00 00 - ec ff 02 04 13 b7 80 7c ...............|
000000000402ffbc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000402ffcc 00 70 fa 7f 00 c6 db 86 - c0 ff 02 04 50 10 bd 86 .p..........P...
000000000402ffdc ff ff ff ff c0 9a 83 7c - 20 b7 80 7c 00 00 00 00 .......| ..|....
000000000402ffec 00 00 00 00 00 00 00 00 - 61 87 9c 76 00 00 00 00 ........a..v....
000000000402fffc 00 00 00 00 08 00 00 00 - c0 60 00 00 00 00 00 00 .........`......
*----> State Dump for Thread Id 0xc1c <----*
eax=0567dcf4 ebx=0001002d ecx=0567f800 edx=0567f8f8 esi=7e42fa6e edi=00010011
eip=7c90e4f4 esp=0567f8fc ebp=0567f914 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202
function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp
*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\mshtml.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0567f914 4374f181 00007f00 00000000 0567fbbc ntdll!KiFastSystemCallRet
0567f93c 436eae22 00007f00 0734b2d0 0567fbbc mshtml!MatchExactGetIDsOfNames+0x1aacd
0567f998 436eac65 00007f00 00000001 0734ebe8 mshtml!ShowModalDialog+0x1668
0567fa7c 4365241c 07132f58 0567fbbc 0734b2d0 mshtml!ShowModalDialog+0x14ab
0567fa98 4364d8ce 0734ebe8 0567fbbc 0734b2d0 mshtml!DllGetClassObject+0x73334
0567fb14 4374ec69 00000001 0734b2d0 00000000 mshtml!DllGetClassObject+0x6e7e6
0567fc60 4374eae8 00000020 00000000 02000001 mshtml!MatchExactGetIDsOfNames+0x1a5b5
0567fd84 4368e0c7 00000000 00000020 000e0340 mshtml!MatchExactGetIDsOfNames+0x1a434
0567fdb0 7e418734 000e0340 00000020 000e0340 mshtml!DllGetClassObject+0xaefdf
0567fddc 7e418816 4368e07b 000e0340 00000020 USER32!GetDC+0x6d
0567fe44 7e428ea0 00000000 4368e07b 000e0340 USER32!GetDC+0x14f
0567fe98 7e428eec 0061fdf8 00000020 000e0340 USER32!DefWindowProcW+0x180
0567fec0 7c90e453 0567fed0 00000018 0061fdf8 USER32!DefWindowProcW+0x1cc
0567ff10 7e419402 0567ff64 00000000 00000000 ntdll!KiUserCallbackDispatcher+0x13
0567ff3c 42f8e61d 0567ff64 00000000 00000000 USER32!PeekMessageW+0x167
0567ffb4 7c80b713 03522f10 04535f88 00140000 IEFRAME!Ordinal300+0x35db
0567ffec 00000000 42f8e48c 04623880 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
000000000567f8fc 3c 99 42 7e 6e f6 73 43 - 11 00 01 00 e8 eb 34 07 <.B~n.sC......4.
000000000567f90c 00 7f 00 00 50 8b 83 0a - 3c f9 67 05 81 f1 74 43 ....P...<.g...tC
000000000567f91c 00 7f 00 00 00 00 00 00 - bc fb 67 05 e8 eb 34 07 ..........g...4.
000000000567f92c 98 bf 10 07 e0 60 f2 02 - 05 40 00 80 00 00 00 00 .....`...@......
000000000567f93c 98 f9 67 05 22 ae 6e 43 - 00 7f 00 00 d0 b2 34 07 ..g.".nC......4.
000000000567f94c bc fb 67 05 01 00 00 00 - 58 2f 13 07 00 00 00 00 ..g.....X/......
000000000567f95c 00 00 00 00 8c 03 00 00 - 18 00 00 00 7a 01 00 00 ............z...
000000000567f96c 37 01 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 7...............
000000000567f97c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000567f98c 00 00 00 00 e0 60 f2 02 - 58 2f 13 07 7c fa 67 05 .....`..X/..|.g.
000000000567f99c 65 ac 6e 43 00 7f 00 00 - 01 00 00 00 e8 eb 34 07 e.nC..........4.
000000000567f9ac bc fb 67 05 01 00 00 00 - df 38 74 00 3d 00 91 7c ..g......8t.=..|
000000000567f9bc 01 00 00 00 28 a8 6a 07 - 00 00 00 00 78 bd 1f 00 ....(.j.....x...
000000000567f9cc 90 fa 67 05 3d 00 91 7c - 98 bf 10 07 10 b4 6a 07 ..g.=..|......j.
000000000567f9dc 00 00 00 00 bc fb 67 05 - e0 60 f2 02 00 02 00 00 ......g..`......
000000000567f9ec 00 00 00 00 01 00 00 00 - d0 b2 34 07 48 61 f2 02 ..........4.Ha..
000000000567f9fc 10 fa 67 05 01 9d 69 43 - 00 00 00 00 d0 b2 34 07 ..g...iC......4.
000000000567fa0c d0 b2 34 07 48 61 f2 02 - 28 fa 67 05 01 9d 69 43 ..4.Ha..(.g...iC
000000000567fa1c d0 b2 34 07 01 00 00 00 - bc fb 67 05 8c fa 67 05 ..4.......g...g.
000000000567fa2c 21 9d 69 43 80 51 2d 07 - 6c 26 65 43 01 01 00 00 !.iC.Q-.l&eC....
*----> State Dump for Thread Id 0x770 <----*
eax=04eb0ff8 ebx=000493e0 ecx=04ff4dd4 edx=ffffffff esi=00001174 edi=00000000
eip=7c90e4f4 esp=0791fed8 ebp=0791ff3c iopl=0 nv up ei ng nz ac po cy
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000297
function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\ole32.dll -
ChildEBP RetAddr Args to Child
0791ff3c 7c802542 00001174 000493e0 00000000 ntdll!KiFastSystemCallRet
0791ff50 77596afb 00001174 000493e0 00000000 kernel32!WaitForSingleObject+0x12
0791ff6c 77566ff9 00001174 00007530 7c802550 ole32!CoInstall+0x11d
0791ff8c 7752687c 0791ffb4 774fe3ee 77606a18 ole32!CoWaitForMultipleHandles+0xfea8
0791ff94 774fe3ee 77606a18 0039002d 0484cef8 ole32!CoGetObject+0x1776
0791ffb4 7c80b713 0484cef8 0039002d 00450043 ole32!StringFromGUID2+0x5dc
0791ffec 00000000 774fe43b 0484cef8 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
000000000791fed8 3c df 90 7c db 25 80 7c - 74 11 00 00 00 00 00 00 <..|.%.|t.......
000000000791fee8 0c ff 91 07 02 01 00 00 - 30 25 80 7c e0 93 04 00 ........0%.|....
000000000791fef8 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000791ff08 10 00 00 00 00 a2 2f 4d - ff ff ff ff 00 e0 fd 7f ....../M........
000000000791ff18 00 e0 f9 7f 0c ff 91 07 - 1c ff 91 07 ec fe 91 07 ................
000000000791ff28 00 00 00 00 dc ff 91 07 - c0 9a 83 7c 08 26 80 7c ...........|.&.|
000000000791ff38 00 00 00 00 50 ff 91 07 - 42 25 80 7c 74 11 00 00 ....P...B%.|t...
000000000791ff48 e0 93 04 00 00 00 00 00 - 6c ff 91 07 fb 6a 59 77 ........l....jYw
000000000791ff58 74 11 00 00 e0 93 04 00 - 00 00 00 00 18 6a 60 77 t............j`w
000000000791ff68 74 11 00 00 8c ff 91 07 - f9 6f 56 77 74 11 00 00 t........oVwt...
000000000791ff78 30 75 00 00 50 25 80 7c - f8 ce 84 04 f0 11 00 00 0u..P%.|........
000000000791ff88 e0 8c 5b 04 94 ff 91 07 - 7c 68 52 77 b4 ff 91 07 ..[.....|hRw....
000000000791ff98 ee e3 4f 77 18 6a 60 77 - 2d 00 39 00 f8 ce 84 04 ..Ow.j`w-.9.....
000000000791ffa8 00 00 4e 77 56 e4 4f 77 - 43 00 45 00 ec ff 91 07 ..NwV.OwC.E.....
000000000791ffb8 13 b7 80 7c f8 ce 84 04 - 2d 00 39 00 43 00 45 00 ...|....-.9.C.E.
000000000791ffc8 f8 ce 84 04 00 e0 f9 7f - 00 c6 db 86 c0 ff 91 07 ................
000000000791ffd8 38 d8 69 86 ff ff ff ff - c0 9a 83 7c 20 b7 80 7c 8.i........| ..|
000000000791ffe8 00 00 00 00 00 00 00 00 - 00 00 00 00 3b e4 4f 77 ............;.Ow
000000000791fff8 f8 ce 84 04 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000007920008 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
*----> State Dump for Thread Id 0xb10 <----*
eax=76b5aeaf ebx=00000000 ecx=00000000 edx=00000000 esi=00000001 edi=00000000
eip=7c90e4f4 esp=0c82ff08 ebp=0c82ffb4 iopl=0 nv up ei ng nz ac po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000296
function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0c82ffb4 7c80b713 00000000 00000000 00000001 ntdll!KiFastSystemCallRet
0c82ffec 00000000 76b5aeaf 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
000000000c82ff08 2c df 90 7c e9 ae b5 76 - 01 00 00 00 6c ff 82 0c ,..|...v....l...
000000000c82ff18 01 00 00 00 01 00 00 00 - 00 00 00 00 01 00 00 00 ................
000000000c82ff28 04 16 c4 86 40 5f 00 00 - cc 14 c4 86 38 e5 73 f7 ....@_......8.s.
000000000c82ff38 26 38 64 80 f8 51 7a 86 - 98 14 c4 86 00 50 f9 7f &8d..Qz......P..
000000000c82ff48 88 fc 51 a9 82 2f 50 80 - 00 00 00 00 05 00 00 00 ..Q../P.........
000000000c82ff58 00 00 00 00 00 00 00 00 - 00 00 00 00 c4 f8 4f 80 ..............O.
000000000c82ff68 60 fc 51 a9 e0 0b 00 00 - f8 0e 00 00 27 64 6e 80 `.Q.........'dn.
000000000c82ff78 98 14 c4 86 50 fd 51 a9 - 00 00 00 00 80 15 c4 86 ....P.Q.........
000000000c82ff88 01 41 21 f7 00 00 00 00 - f8 51 7a 86 5a 2f 50 80 .A!......Qz.Z/P.
000000000c82ff98 00 00 00 00 00 00 00 00 - 00 00 00 00 6a 2f 50 80 ............j/P.
000000000c82ffa8 a0 fc 51 a9 f2 6e 6e 80 - 01 00 00 00 ec ff 82 0c ..Q..nn.........
000000000c82ffb8 13 b7 80 7c 00 00 00 00 - 00 00 00 00 01 00 00 00 ...|............
000000000c82ffc8 00 00 00 00 00 50 f9 7f - 00 e6 db 86 c0 ff 82 0c .....P..........
000000000c82ffd8 28 56 68 86 ff ff ff ff - c0 9a 83 7c 20 b7 80 7c (Vh........| ..|
000000000c82ffe8 00 00 00 00 00 00 00 00 - 00 00 00 00 af ae b5 76 ...............v
000000000c82fff8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000c830008 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000c830018 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000c830028 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000c830038 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
*----> State Dump for Thread Id 0x160 <----*
eax=0000000c ebx=072dd7e4 ecx=0c92ff44 edx=00000000 esi=00000f14 edi=00000000
eip=7c90e4f4 esp=0c92ff04 ebp=0c92ff68 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0c92ff68 7c802542 00000f14 ffffffff 00000000 ntdll!KiFastSystemCallRet
0c92ff7c 436c9520 00000f14 ffffffff 435d0000 kernel32!WaitForSingleObject+0x12
0c92ffa0 43666b4a 09519020 00000020 435ed984 mshtml!DllGetClassObject+0xea438
0c92ffb4 7c80b713 072dd778 09519020 00000020 mshtml!DllGetClassObject+0x87a62
0c92ffec 00000000 435ed977 072dd778 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
000000000c92ff04 3c df 90 7c db 25 80 7c - 14 0f 00 00 00 00 00 00 <..|.%.|........
000000000c92ff14 00 00 00 00 00 00 00 00 - 78 d7 2d 07 e4 d7 2d 07 ........x.-...-.
000000000c92ff24 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000c92ff34 10 00 00 00 03 00 00 00 - f0 3a 30 07 00 e0 fd 7f .........:0.....
000000000c92ff44 00 40 f9 7f 00 00 00 00 - 97 77 68 43 18 ff 92 0c .@.......whC....
000000000c92ff54 f9 77 68 43 dc ff 92 0c - c0 9a 83 7c 08 26 80 7c .whC.......|.&.|
000000000c92ff64 00 00 00 00 7c ff 92 0c - 42 25 80 7c 14 0f 00 00 ....|...B%.|....
000000000c92ff74 ff ff ff ff 00 00 00 00 - a0 ff 92 0c 20 95 6c 43 ............ .lC
000000000c92ff84 14 0f 00 00 ff ff ff ff - 00 00 5d 43 78 d7 2d 07 ..........]Cx.-.
000000000c92ff94 78 d7 2d 07 65 47 30 02 - ff ff ff ff b4 ff 92 0c x.-.eG0.........
000000000c92ffa4 4a 6b 66 43 20 90 51 09 - 20 00 00 00 84 d9 5e 43 JkfC .Q. .....^C
000000000c92ffb4 ec ff 92 0c 13 b7 80 7c - 78 d7 2d 07 20 90 51 09 .......|x.-. .Q.
000000000c92ffc4 20 00 00 00 78 d7 2d 07 - 00 40 f9 7f 00 e6 db 86 ...x.-..@......
000000000c92ffd4 c0 ff 92 0c 28 56 68 86 - ff ff ff ff c0 9a 83 7c ....(Vh........|
000000000c92ffe4 20 b7 80 7c 00 00 00 00 - 00 00 00 00 00 00 00 00 ..|............
000000000c92fff4 77 d9 5e 43 78 d7 2d 07 - 00 00 00 00 00 00 00 00 w.^Cx.-.........
000000000c930004 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000c930014 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000c930024 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000c930034 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
*----> State Dump for Thread Id 0xf88 <----*
eax=00000000 ebx=00000000 ecx=060bfd68 edx=7c90e4f4 esi=00181098 edi=0018113c
eip=7c90e4f4 esp=060bfe18 ebp=060bff80 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp
*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\RPCRT4.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
060bff80 77e76caf 060bffa8 77e76ad1 00181098 ntdll!KiFastSystemCallRet
060bff88 77e76ad1 00181098 7c917de9 1609b9ac RPCRT4!I_RpcBCacheFree+0x61c
060bffa8 77e76c97 0014d388 060bffec 7c80b713 RPCRT4!I_RpcBCacheFree+0x43e
060bffb4 7c80b713 071cf5b0 7c917de9 1609b9ac RPCRT4!I_RpcBCacheFree+0x604
060bffec 00000000 77e76c7d 071cf5b0 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
00000000060bfe18 8c da 90 7c e3 65 e7 77 - 48 02 00 00 74 ff 0b 06 ...|.e.wH...t...
00000000060bfe28 00 00 00 00 00 2d 51 04 - 48 ff 0b 06 ec 9f 7c 86 .....-Q.H.....|.
00000000060bfe38 38 00 50 00 00 00 00 00 - 5c 08 5d 80 00 00 00 00 8.P.....\.].....
00000000060bfe48 00 00 00 00 00 00 00 00 - 02 e0 f2 00 00 00 00 00 ................
00000000060bfe58 00 00 00 00 01 00 00 00 - ff 0f 1f 00 ff 03 1f 00 ................
00000000060bfe68 ff 0f 1f 00 87 00 00 00 - 01 00 00 00 00 00 00 00 ................
00000000060bfe78 01 00 00 00 01 01 01 01 - 00 00 00 00 01 01 01 01 ................
00000000060bfe88 01 01 01 01 01 01 01 01 - 00 00 00 00 90 9d 7c 86 ..............|.
00000000060bfe98 8c 4f dc 86 a0 8b bd a9 - 1e ca 5b 80 a8 9d 7c 86 .O........[...|.
00000000060bfea8 74 14 00 00 90 9d 7c 86 - 00 00 00 00 01 00 00 00 t.....|.........
00000000060bfeb8 01 00 00 00 a8 9d 7c 86 - c8 8b bd a9 3f c3 5b 80 ......|.....?.[.
00000000060bfec8 74 14 00 00 90 9d 7c 86 - 00 00 00 00 47 c3 5b 80 t.....|.....G.[.
00000000060bfed8 c8 49 dc 86 38 0e 00 e1 - 68 28 68 86 70 4e dc 86 .I..8...h(h.pN..
00000000060bfee8 10 8c bd a9 dd c3 5b 80 - 38 0e 00 e1 a8 9d 7c 86 ......[.8.....|.
00000000060bfef8 74 14 00 00 00 00 00 00 - ff 03 1f 00 00 00 00 00 t...............
00000000060bff08 30 8c bd a9 ac 8c bd a9 - f8 c4 5b 80 d5 45 c9 01 0.........[..E..
00000000060bff18 38 e5 73 f7 c4 58 54 80 - 00 f0 78 86 b4 b1 4f 80 8.s..XT...x...O.
00000000060bff28 8c f1 78 86 80 ff 0b 06 - ae df e7 77 48 ff 0b 06 ..x........wH...
00000000060bff38 be df e7 77 e0 10 90 7c - c0 4d 8c 0a b0 f5 1c 07 ...w...|.M......
00000000060bff48 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff ../M.....]......
*----> State Dump for Thread Id 0xa40 <----*
eax=00000000 ebx=00000000 ecx=045419c8 edx=0002da1c esi=045419c8 edi=04541a04
eip=7c90e4f4 esp=0649fe18 ebp=0649ff80 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0649ff80 77e76caf 0649ffa8 77e76ad1 045419c8 ntdll!KiFastSystemCallRet
0649ff88 77e76ad1 045419c8 7c900000 00bdfac8 RPCRT4!I_RpcBCacheFree+0x61c
0649ffa8 77e76c97 0014d388 0649ffec 7c80b713 RPCRT4!I_RpcBCacheFree+0x43e
0649ffb4 7c80b713 045070e8 7c900000 00bdfac8 RPCRT4!I_RpcBCacheFree+0x604
0649ffec 00000000 77e76c7d 045070e8 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
000000000649fe18 8c da 90 7c e3 65 e7 77 - d8 0c 00 00 74 ff 49 06 ...|.e.w....t.I.
000000000649fe28 00 00 00 00 20 3a 51 04 - 00 00 00 00 ff ff ff 03 .... :Q.........
000000000649fe38 ff ff ff 03 c0 9e e1 81 - 00 00 00 00 fc 3c 88 c0 .............<..
000000000649fe48 70 9f 77 86 40 e5 73 f7 - 00 00 00 00 72 b5 4f 80 p.w.@.s.....r.O.
000000000649fe58 94 8b bc a9 d0 fe 3f c0 - 00 90 fd 7f 00 00 00 00 ......?.........
000000000649fe68 c8 fe 3f 02 70 8b bc a9 - ab 38 52 80 00 90 fd 7f ..?.p....8R.....
000000000649fe78 01 00 00 00 00 00 00 00 - c8 fe 3f c0 00 00 00 00 ..........?.....
000000000649fe88 00 00 00 00 f8 1f 60 c0 - 30 8c bc a9 0a 40 52 80 ......`.0....@R.
000000000649fe98 94 8b bc a9 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000649fea8 f0 92 89 86 78 9d 77 86 - 01 9e 77 86 00 00 00 00 ....x.w...w.....
000000000649feb8 c8 fe 3f c0 08 c5 89 86 - 00 00 00 00 d0 8b bc a9 ..?.............
000000000649fec8 00 00 04 00 3f 0a 00 00 - 44 9e 77 86 ff ff a3 00 ....?...D.w.....
000000000649fed8 78 9d 77 86 00 00 00 00 - ec 8b bc a9 00 00 a4 00 x.w.............
000000000649fee8 50 8b bc a9 00 00 00 00 - ff ff ff ff 00 90 fd 7f P...............
000000000649fef8 68 9e 4d 80 ff ff ff ff - 4a 36 5b 80 2c 16 54 80 h.M.....J6[.,.T.
000000000649ff08 ff ff ff ff 00 00 00 00 - a8 5d 60 86 08 00 00 00 .........]`.....
000000000649ff18 38 f5 df ff c4 58 54 80 - 00 b0 8c 86 b4 b1 4f 80 8....XT.......O.
000000000649ff28 8c b1 8c 86 80 ff 49 06 - ae df e7 77 48 ff 49 06 ......I....wH.I.
000000000649ff38 be df e7 77 e0 10 90 7c - 10 55 f9 06 e8 70 50 04 ...w...|.U...pP.
000000000649ff48 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff ../M.....]......
*----> State Dump for Thread Id 0xd80 <----*
eax=0a8ec048 ebx=00007530 ecx=001fbd78 edx=0a8ed0c8 esi=00000000 edi=0289ff50
eip=7c90e4f4 esp=0289ff20 ebp=0289ff78 iopl=0 nv up ei pl nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000206
function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0289ff78 7c802455 0000ea60 00000000 0289ffb4 ntdll!KiFastSystemCallRet
0289ff88 774fe32f 0000ea60 001fb300 774fe3ee kernel32!Sleep+0xf
0289ffb4 7c80b713 001fb300 044d66e0 7c936eb3 ole32!StringFromGUID2+0x51d
0289ffec 00000000 774fe43b 001fb300 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
000000000289ff20 fc d1 90 7c f1 23 80 7c - 00 00 00 00 50 ff 89 02 ...|.#.|....P...
000000000289ff30 50 25 80 7c f8 6d 60 77 - 30 75 00 00 14 00 00 00 P%.|.m`w0u......
000000000289ff40 01 00 00 00 00 00 00 00 - 00 00 00 00 10 00 00 00 ................
000000000289ff50 00 ba 3c dc ff ff ff ff - 68 fe 89 02 50 ff 89 02 ..<.....h...P...
000000000289ff60 30 ff 89 02 f8 fe 89 02 - dc ff 89 02 c0 9a 83 7c 0..............|
000000000289ff70 60 24 80 7c 00 00 00 00 - 88 ff 89 02 55 24 80 7c `$.|........U$.|
000000000289ff80 60 ea 00 00 00 00 00 00 - b4 ff 89 02 2f e3 4f 77 `.........../.Ow
000000000289ff90 60 ea 00 00 00 b3 1f 00 - ee e3 4f 77 00 00 00 00 `.........Ow....
000000000289ffa0 e0 66 4d 04 00 b3 1f 00 - 00 00 4e 77 56 e4 4f 77 .fM.......NwV.Ow
000000000289ffb0 b3 6e 93 7c ec ff 89 02 - 13 b7 80 7c 00 b3 1f 00 .n.|.......|....
000000000289ffc0 e0 66 4d 04 b3 6e 93 7c - 00 b3 1f 00 00 a0 fd 7f .fM..n.|........
000000000289ffd0 00 c6 db 86 c0 ff 89 02 - c0 0b 98 86 ff ff ff ff ................
000000000289ffe0 c0 9a 83 7c 20 b7 80 7c - 00 00 00 00 00 00 00 00 ...| ..|........
000000000289fff0 00 00 00 00 3b e4 4f 77 - 00 b3 1f 00 00 00 00 00 ....;.Ow........
00000000028a0000 c8 00 00 00 43 01 00 00 - ff ee ff ee 02 10 00 00 ....C...........
00000000028a0010 00 00 00 00 00 fe 00 00 - 00 00 10 00 00 20 00 00 ............. ..
00000000028a0020 00 02 00 00 00 20 00 00 - 9a 01 00 00 ff ef fd 7f ..... ..........
00000000028a0030 10 00 08 06 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000028a0040 00 00 00 00 98 05 8a 02 - 0f 00 00 00 f8 ff ff ff ................
00000000028a0050 50 00 8a 02 50 00 8a 02 - 40 06 8a 02 00 00 00 00 P...P...@.......
*----> State Dump for Thread Id 0xdac <----*
eax=00000000 ebx=0639edc0 ecx=00000001 edx=0000c0f6 esi=00000000 edi=7ffde000
eip=7c90e4f4 esp=0639ed98 ebp=0639ee34 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0639ee34 7e4195f9 00000002 0639ee5c 00000000 ntdll!KiFastSystemCallRet
0639ee90 5dff6029 00000001 0639eec4 ffffffff USER32!GetLastInputInfo+0x105
0639eeb0 5dff632d 000004ff ffffffff 00000000 IEUI!DUserRegisterSuper+0x9bd
0639eed8 5dff60d8 000004ff 00000000 42fa98cd IEUI!PeekMessageExW+0x21f
0639ef14 42f9ab4c 077249b8 0639ef44 42f9bbbb IEUI!WaitMessageEx+0x31
0639ef20 42f9bbbb 00000000 00000000 072a4810 IEFRAME!Ordinal300+0xfb0a
0639ef44 42f9bb09 1dac0001 00ec0009 00207a68 IEFRAME!Ordinal101+0x341
0639ffb4 7c80b713 072a4810 00ec0009 00207a68 IEFRAME!Ordinal101+0x28f
0639ffec 00000000 42f9ba53 072a4810 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
000000000639ed98 2c df 90 7c 74 95 80 7c - 02 00 00 00 c0 ed 39 06 ,..|t..|......9.
000000000639eda8 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000639edb8 02 00 00 00 00 00 00 00 - 84 17 00 00 b8 15 00 00 ................
000000000639edc8 21 c6 fb 42 b8 49 72 07 - 44 ee 39 06 cd c5 fb 42 !..B.Ir.D.9....B
000000000639edd8 00 00 00 00 08 ee 39 06 - 14 00 00 00 01 00 00 00 ......9.........
000000000639ede8 00 00 00 00 00 00 00 00 - 10 00 00 00 cd c5 fb 42 ...............B
000000000639edf8 cd ab ba dc 00 00 00 00 - 00 e0 fd 7f 00 60 fa 7f .............`..
000000000639ee08 70 ee 39 06 00 00 00 00 - c0 ed 39 06 70 ee 39 06 p.9.......9.p.9.
000000000639ee18 02 00 00 00 b4 ed 39 06 - ff ff ff ff dc ff 39 06 ......9.......9.
000000000639ee28 c0 9a 83 7c 68 96 80 7c - 00 00 00 00 90 ee 39 06 ...|h..|......9.
000000000639ee38 f9 95 41 7e 02 00 00 00 - 5c ee 39 06 00 00 00 00 ..A~....\.9.....
000000000639ee48 ff ff ff ff 00 00 00 00 - ff ff ff ff 01 00 00 00 ................
000000000639ee58 01 00 00 00 84 17 00 00 - b8 15 00 00 bd 62 ff 5d .............b.]
000000000639ee68 ae f0 1b 03 98 7f 44 03 - 01 00 00 00 00 00 00 00 ......D.........
000000000639ee78 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000639ee88 00 60 fa 7f b8 15 00 00 - b0 ee 39 06 29 60 ff 5d .`........9.)`.]
000000000639ee98 01 00 00 00 c4 ee 39 06 - ff ff ff ff ff 04 00 00 ......9.........
000000000639eea8 5c ee 39 06 a0 9b 1c 00 - d8 ee 39 06 2d 63 ff 5d \.9.......9.-c.]
000000000639eeb8 ff 04 00 00 ff ff ff ff - 00 00 00 00 84 17 00 00 ................
000000000639eec8 00 00 00 00 48 78 f9 42 - b8 49 72 07 9f 00 00 00 ....Hx.B.Ir.....
*----> State Dump for Thread Id 0xd18 <----*
eax=031397d8 ebx=00000000 ecx=0312fc98 edx=000008ee esi=0a825ac0 edi=00000000
eip=7c90e4f4 esp=068bff50 ebp=068bffb4 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
068bffb4 7c80b713 03523bf8 0732ece8 00140000 ntdll!KiFastSystemCallRet
068bffec 00000000 42f8e48c 0a825ac0 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
00000000068bff50 18 94 41 7e 8c f3 f8 42 - e8 ec 32 07 00 00 14 00 ..A~...B..2.....
00000000068bff60 c0 5a 82 0a 20 04 0a 00 - 00 04 00 00 be ba 00 00 .Z.. ...........
00000000068bff70 6c fe 54 03 8b 72 1d 03 - e6 01 00 00 37 02 00 00 l.T..r......7...
00000000068bff80 b8 4a 82 0a 14 55 82 0a - 01 00 00 00 00 00 00 00 .J...U..........
00000000068bff90 30 9f 1f 07 01 00 00 00 - 00 00 00 00 54 04 0b 00 0...........T...
00000000068bffa0 9a 03 18 00 c8 17 1f 07 - 00 00 00 00 8c 1e 1f 07 ................
00000000068bffb0 d0 95 83 0a ec ff 8b 06 - 13 b7 80 7c f8 3b 52 03 ...........|.;R.
00000000068bffc0 e8 ec 32 07 00 00 14 00 - c0 5a 82 0a 00 20 fa 7f ..2......Z... ..
00000000068bffd0 00 c6 db 86 c0 ff 8b 06 - 10 f9 66 86 ff ff ff ff ..........f.....
00000000068bffe0 c0 9a 83 7c 20 b7 80 7c - 00 00 00 00 00 00 00 00 ...| ..|........
00000000068bfff0 00 00 00 00 8c e4 f8 42 - c0 5a 82 0a 00 00 00 00 .......B.Z......
00000000068c0000 08 00 00 00 00 20 00 00 - 00 00 00 00 ff ff ff ff ..... ..........
00000000068c0010 40 1f 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 @...............
00000000068c0020 00 00 00 00 00 00 00 00 - 58 00 00 00 58 00 00 00 ........X...X...
00000000068c0030 a0 e1 db 57 25 de d2 11 - af dd 00 10 5a 27 99 b5 ...W%.......Z'..
00000000068c0040 03 00 00 00 01 00 00 00 - 00 00 00 00 ac 0d 00 00 ................
00000000068c0050 b0 0e 00 00 c0 00 00 00 - 0f d4 d9 02 00 00 00 00 ................
00000000068c0060 00 00 00 00 48 00 00 00 - 00 00 00 00 00 00 00 00 ....H...........
00000000068c0070 08 00 00 00 01 00 04 00 - 07 00 00 00 00 00 00 00 ................
00000000068c0080 00 00 00 00 00 00 00 00 - 08 00 00 00 ff ff ff ff ................
*----> State Dump for Thread Id 0xd58 <----*
eax=00000000 ebx=000006bb ecx=06659580 edx=00000000 esi=0471ed14 edi=046b51a0
eip=77e793df esp=07c9fd58 ebp=07c9fd98 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: RPCRT4!NdrGetTypeFlags
77e793b9 bbbb060000 mov ebx,0x6bb
77e793be 7519 jnz RPCRT4!NdrGetTypeFlags+0xe5 (77e793d9)
77e793c0 a801 test al,0x1
77e793c2 0f841f100000 je RPCRT4!NdrServerInitializeNew+0x44 (77e7a3e7)
77e793c8 8b87fc000000 mov eax,[edi+0xfc]
77e793ce 8b4f6c mov ecx,[edi+0x6c]
77e793d1 3bc1 cmp eax,ecx
77e793d3 0f8dcfc70200 jnl RPCRT4!RpcErrorStartEnumeration+0xe53 (77ea5ba8)
77e793d9 8b4508 mov eax,[ebp+0x8]
77e793dc 8b4d10 mov ecx,[ebp+0x10]
FAULT ->77e793df 3b01 cmp eax,[ecx] ds:0023:06659580=????????
77e793e1 0f83e8c70200 jnb RPCRT4!RpcErrorStartEnumeration+0xe7a (77ea5bcf)
77e793e7 837dfc00 cmp dword ptr [ebp-0x4],0x0
77e793eb 0f85f6fd0100 jne RPCRT4!I_RpcServerRegisterForwardFunction+0x534 (77e991e7)
77e793f1 8b07 mov eax,[edi]
77e793f3 ff4034 inc dword ptr [eax+0x34]
77e793f6 8b461c mov eax,[esi+0x1c]
77e793f9 8b4e08 mov ecx,[esi+0x8]
77e793fc ff7514 push dword ptr [ebp+0x14]
77e793ff 894808 mov [eax+0x8],ecx
77e79402 8b4e08 mov ecx,[esi+0x8]
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
07c9fd98 77e7934e 00000000 00000000 06659580 RPCRT4!NdrGetTypeFlags+0xeb
07c9fdbc 77e7be64 0471ed14 00000000 06659580 RPCRT4!NdrGetTypeFlags+0x5a
07c9fdf8 77e7bcc1 04513160 04541b38 07674580 RPCRT4!NdrConformantArrayFree+0x46e
07c9fe1c 77e7bc05 04541b74 07c9fe38 07674580 RPCRT4!NdrConformantArrayFree+0x2cb
07c9ff80 77e76caf 07c9ffa8 77e76ad1 04541b38 RPCRT4!NdrConformantArrayFree+0x20f
07c9ff88 77e76ad1 04541b38 7c900000 0059fac8 RPCRT4!I_RpcBCacheFree+0x61c
07c9ffa8 77e76c97 0014d388 07c9ffec 7c80b713 RPCRT4!I_RpcBCacheFree+0x43e
07c9ffb4 7c80b713 07726f08 7c900000 0059fac8 RPCRT4!I_RpcBCacheFree+0x604
07c9ffec 00000000 77e76c7d 07726f08 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
0000000007c9fd58 00 00 00 00 a0 51 6b 04 - 14 ed 71 04 f8 45 67 07 .....Qk...q..Eg.
0000000007c9fd68 24 fe c9 07 00 00 00 00 - 00 e0 fd 7f 00 50 fa 7f $............P..
0000000007c9fd78 b0 c8 5b 07 d0 fc c9 07 - ff ff ff ff dc ff c9 07 ..[.............
0000000007c9fd88 00 e9 90 7c e0 15 91 7c - 08 6f 72 07 b3 06 00 00 ...|...|.or.....
0000000007c9fd98 bc fd c9 07 4e 93 e7 77 - 00 00 00 00 00 00 00 00 ....N..w........
0000000007c9fda8 80 95 65 06 ec fd c9 07 - 10 bf 52 07 08 6f 72 07 ..e.......R..or.
0000000007c9fdb8 f0 eb 71 04 f8 fd c9 07 - 64 be e7 77 14 ed 71 04 ..q.....d..w..q.
0000000007c9fdc8 00 00 00 00 80 95 65 06 - ec fd c9 07 e0 10 90 7c ......e........|
0000000007c9fdd8 38 1b 54 04 f0 eb 71 04 - 00 00 00 00 08 6f 72 07 8.T...q......or.
0000000007c9fde8 41 02 00 00 8b 7f 00 00 - 80 95 65 06 76 bc e7 77 A.........e.v..w
0000000007c9fdf8 1c fe c9 07 c1 bc e7 77 - 60 31 51 04 38 1b 54 04 .......w`1Q.8.T.
0000000007c9fe08 80 45 67 07 28 fe c9 07 - ef 22 ea 77 28 fe c9 07 .Eg.(....".w(...
0000000007c9fe18 41 02 00 00 80 ff c9 07 - 05 bc e7 77 74 1b 54 04 A..........wt.T.
0000000007c9fe28 38 fe c9 07 80 45 67 07 - 7c ff c9 07 0d 58 53 80 8....Eg.|....XS.
0000000007c9fe38 2c 00 44 00 84 30 70 86 - b0 0e 00 00 90 04 00 00 ,.D..0p.........
0000000007c9fe48 a1 40 10 00 00 00 00 00 - 02 0b a2 a9 00 00 5b 80 .@............[.
0000000007c9fe58 ff 03 1f 00 70 4e dc 86 - 00 fc e0 ff 6e d4 5b 80 ....pN......n.[.
0000000007c9fe68 90 13 58 86 a8 13 58 86 - bb 06 00 00 07 22 00 00 ..X...X......"..
0000000007c9fe78 43 05 00 00 00 00 00 00 - 00 e0 61 0a 84 0b a2 a9 C.........a.....
0000000007c9fe88 00 00 00 00 40 a7 63 e3 - 9c 0b a2 a9 3b d7 60 80 ....@.c.....;.`.
*----> State Dump for Thread Id 0x858 <----*
eax=77e7802c ebx=00000000 ecx=07674494 edx=076744c8 esi=00181098 edi=0018113c
eip=7c90e4f4 esp=0659fe18 ebp=0659ff80 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0659ff80 77e76caf 0659ffa8 77e76ad1 00181098 ntdll!KiFastSystemCallRet
0659ff88 77e76ad1 00181098 fffffffc ffffffff RPCRT4!I_RpcBCacheFree+0x61c
0659ffa8 77e76c97 0014d388 0659ffec 7c80b713 RPCRT4!I_RpcBCacheFree+0x43e
0659ffb4 7c80b713 0a7a17b0 fffffffc ffffffff RPCRT4!I_RpcBCacheFree+0x604
0659ffec 00000000 77e76c7d 0a7a17b0 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
000000000659fe18 8c da 90 7c e3 65 e7 77 - 48 02 00 00 74 ff 59 06 ...|.e.wH...t.Y.
000000000659fe28 00 00 00 00 d8 53 6b 04 - 48 ff 59 06 3a 02 5c 80 .....Sk.H.Y.:.\.
000000000659fe38 1c bb 56 a9 01 00 00 00 - 24 bb 56 a9 00 00 00 00 ..V.....$.V.....
000000000659fe48 0d 58 53 80 70 4e dc 86 - 02 eb 70 86 00 00 70 86 .XS.pN....p...p.
000000000659fe58 00 00 00 00 fc 4f dc 86 - 00 eb 70 86 c8 bb 56 a9 .....O....p...V.
000000000659fe68 56 d1 5b 80 75 00 00 00 - 70 4e dc 86 00 fc e0 ff V.[.u...pN......
000000000659fe78 6e d4 5b 80 50 37 63 86 - 68 37 63 86 80 19 dc 86 n.[.P7c.h7c.....
000000000659fe88 5f 22 00 00 7e 05 00 00 - 18 db 50 86 01 00 00 00 _"..~.....P.....
000000000659fe98 87 00 00 00 00 00 00 00 - 43 6d 6e 80 28 bc 56 a9 ........Cmn.(.V.
000000000659fea8 27 64 6e 80 00 0d db ba - 00 00 00 00 50 37 63 86 'dn.........P7c.
000000000659feb8 40 a7 63 e3 e0 eb 70 86 - 03 00 00 00 40 a7 63 e3 @.c...p.....@.c.
000000000659fec8 c0 bb 56 a9 3b d7 60 80 - 40 a7 63 e3 70 14 00 00 ..V.;.`.@.c.p...
000000000659fed8 ff 03 1f 00 40 a7 63 e3 - 00 00 00 00 00 00 00 00 ....@.c.........
000000000659fee8 00 00 00 00 1f 00 00 00 - ff ff ff ff 40 e5 73 f7 ............@.s.
000000000659fef8 00 00 00 00 10 64 6e 80 - a4 36 7f 86 28 bc 56 a9 .....dn..6..(.V.
000000000659ff08 00 00 00 00 27 64 6e 80 - 08 00 00 00 46 02 00 00 ....'dn.....F...
000000000659ff18 68 38 50 80 78 35 7f 86 - 08 35 7f 86 78 b0 4f 80 h8P.x5...5..x.O.
000000000659ff28 74 36 7f 86 80 ff 59 06 - ae df e7 77 48 ff 59 06 t6....Y....wH.Y.
000000000659ff38 be df e7 77 e0 10 90 7c - 88 2b 2c 07 b0 17 7a 0a ...w...|.+,...z.
000000000659ff48 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff ../M.....]......
*----> State Dump for Thread Id 0xf68 <----*
eax=71a5d2c6 ebx=c0000000 ecx=7c912d58 edx=ffffffff esi=00000000 edi=71a8793c
eip=7c90e4f4 esp=039bff7c ebp=039bffb4 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202
function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
039bffb4 7c80b713 71a5d65f 08faede0 7c90e900 ntdll!KiFastSystemCallRet
039bffec 00000000 71a5d2c6 07069b00 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
00000000039bff7c 2c da 90 7c 20 d3 a5 71 - 60 05 00 00 bc ff 9b 03 ,..| ..q`.......
00000000039bff8c b0 ff 9b 03 a4 ff 9b 03 - 68 d3 a5 71 e0 ed fa 08 ........h..q....
00000000039bff9c 00 e9 90 7c 00 9b 06 07 - 00 00 00 00 00 00 00 00 ...|............
00000000039bffac 00 00 a5 71 58 2e 9a 02 - ec ff 9b 03 13 b7 80 7c ...qX..........|
00000000039bffbc 5f d6 a5 71 e0 ed fa 08 - 00 e9 90 7c 00 9b 06 07 _..q.......|....
00000000039bffcc 00 90 fd 7f 00 c6 db 86 - c0 ff 9b 03 90 00 ba 86 ................
00000000039bffdc ff ff ff ff c0 9a 83 7c - 20 b7 80 7c 00 00 00 00 .......| ..|....
00000000039bffec 00 00 00 00 00 00 00 00 - c6 d2 a5 71 00 9b 06 07 ...........q....
00000000039bfffc 00 00 00 00 c0 08 00 00 - 01 00 00 00 00 00 00 00 ................
00000000039c000c 08 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000039c001c 00 00 00 00 00 00 00 00 - 5c 00 5c 00 3f 00 5c 00 ........\.\.?.\.
00000000039c002c 68 00 64 00 61 00 75 00 - 64 00 69 00 6f 00 23 00 h.d.a.u.d.i.o.#.
00000000039c003c 66 00 75 00 6e 00 63 00 - 5f 00 30 00 31 00 26 00 f.u.n.c._.0.1.&.
00000000039c004c 76 00 65 00 6e 00 5f 00 - 38 00 33 00 38 00 34 00 v.e.n._.8.3.8.4.
00000000039c005c 26 00 64 00 65 00 76 00 - 5f 00 37 00 36 00 38 00 &.d.e.v._.7.6.8.
00000000039c006c 30 00 26 00 73 00 75 00 - 62 00 73 00 79 00 73 00 0.&.s.u.b.s.y.s.
00000000039c007c 5f 00 31 00 30 00 37 00 - 62 00 35 00 30 00 34 00 _.1.0.7.b.5.0.4.
00000000039c008c 38 00 26 00 72 00 65 00 - 76 00 5f 00 31 00 30 00 8.&.r.e.v._.1.0.
00000000039c009c 33 00 32 00 23 00 34 00 - 26 00 33 00 32 00 39 00 3.2.#.4.&.3.2.9.
00000000039c00ac 34 00 31 00 61 00 39 00 - 39 00 26 00 30 00 26 00 4.1.a.9.9.&.0.&.
*----> State Dump for Thread Id 0x540 <----*
eax=77e76c7d ebx=00000000 ecx=07530958 edx=07c9fb44 esi=04541b38 edi=04541bdc
eip=7c90e4f4 esp=0848fe18 ebp=0848ff80 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0848ff80 77e76caf 0848ffa8 77e76ad1 04541b38 ntdll!KiFastSystemCallRet
0848ff88 77e76ad1 04541b38 fffffffc ffffffff RPCRT4!I_RpcBCacheFree+0x61c
0848ffa8 77e76c97 0014d388 0848ffec 7c80b713 RPCRT4!I_RpcBCacheFree+0x43e
0848ffb4 7c80b713 0a7a10f0 fffffffc ffffffff RPCRT4!I_RpcBCacheFree+0x604
0848ffec 00000000 77e76c7d 0a7a10f0 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
000000000848fe18 8c da 90 7c e3 65 e7 77 - a4 10 00 00 74 ff 48 08 ...|.e.w....t.H.
000000000848fe28 00 00 00 00 68 08 7e 04 - 48 ff 48 08 0d 58 53 80 ....h.~.H.H..XS.
000000000848fe38 70 4e dc 86 44 ac 51 86 - 40 ac 51 86 00 00 00 00 pN..D.Q.@.Q.....
000000000848fe48 54 4f dc 86 00 ac 51 86 - c8 8b 91 a9 56 d1 5b 80 TO....Q.....V.[.
000000000848fe58 ff 03 1f 00 70 4e dc 86 - 00 fc e0 ff 6e d4 5b 80 ....pN......n.[.
000000000848fe68 10 ec 4d 86 28 ec 4d 86 - 80 19 dc 86 79 23 00 00 ..M.(.M.....y#..
000000000848fe78 a1 05 00 00 f8 1a 63 86 - 01 00 00 00 85 00 00 00 ......c.........
000000000848fe88 00 00 00 00 40 a7 63 e3 - 9c 8b 91 a9 3b d7 60 80 ....@.c.....;.`.
000000000848fe98 40 a7 63 e3 b8 0c 00 00 - 43 6d 6e 80 28 8c 91 a9 @.c.....Cmn.(...
000000000848fea8 27 64 6e 80 00 0d db ba - 00 00 00 00 c0 8b 91 a9 'dn.............
000000000848feb8 3b d7 60 80 40 a7 63 e3 - cc 16 00 00 ff 03 1f 00 ;.`.@.c.........
000000000848fec8 40 a7 63 e3 40 a7 63 e3 - cc 16 00 00 00 00 00 00 @.c.@.c.........
000000000848fed8 98 5d b6 e2 dc 8b 91 a9 - 00 00 00 00 00 00 00 00 .]..............
000000000848fee8 00 00 00 00 1f 00 00 00 - ff ff ff ff 40 e5 73 f7 ............@.s.
000000000848fef8 00 00 00 00 10 64 6e 80 - bc c1 71 86 28 8c 91 a9 .....dn...q.(...
000000000848ff08 00 00 00 00 27 64 6e 80 - 08 00 00 00 46 02 00 00 ....'dn.....F...
000000000848ff18 68 38 50 80 90 c0 71 86 - 20 c0 71 86 78 b0 4f 80 h8P...q. .q.x.O.
000000000848ff28 8c c1 71 86 80 ff 48 08 - ae df e7 77 48 ff 48 08 ..q...H....wH.H.
000000000848ff38 be df e7 77 e0 10 90 7c - c0 20 2c 07 f0 10 7a 0a ...w...|. ,...z.
000000000848ff48 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff ../M.....]......
*----> State Dump for Thread Id 0x8b8 <----*
eax=77e76c7d ebx=00000000 ecx=00149234 edx=00000015 esi=00181098 edi=0018113c
eip=7c90e4f4 esp=05bdfe18 ebp=05bdff80 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
05bdff80 77e76caf 05bdffa8 77e76ad1 00181098 ntdll!KiFastSystemCallRet
05bdff88 77e76ad1 00181098 7c9101bb 0469fb98 RPCRT4!I_RpcBCacheFree+0x61c
05bdffa8 77e76c97 0014d388 05bdffec 7c80b713 RPCRT4!I_RpcBCacheFree+0x43e
05bdffb4 7c80b713 070c6d18 7c9101bb 0469fb98 RPCRT4!I_RpcBCacheFree+0x604
05bdffec 00000000 77e76c7d 070c6d18 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
0000000005bdfe18 8c da 90 7c e3 65 e7 77 - 48 02 00 00 74 ff bd 05 ...|.e.wH...t...
0000000005bdfe28 00 00 00 00 48 40 50 04 - 48 ff bd 05 ff ff ff 03 ....H@P.H.......
0000000005bdfe38 ff ff ff 03 c8 3d e9 81 - 00 00 00 00 fc 3c 88 c0 .....=.......<..
0000000005bdfe48 98 9f 81 86 40 e5 73 f7 - 00 00 00 00 72 b5 4f 80 ....@.s.....r.O.
0000000005bdfe58 94 8b a0 aa e0 fe 3f c0 - 00 b0 fd 7f 00 00 00 00 ......?.........
0000000005bdfe68 d8 fe 3f 02 70 8b a0 aa - ab 38 52 80 00 b0 fd 7f ..?.p....8R.....
0000000005bdfe78 01 00 00 00 00 00 00 00 - d8 fe 3f c0 00 00 00 00 ..........?.....
0000000005bdfe88 00 00 00 00 f8 1f 60 c0 - 30 8c a0 aa 0a 40 52 80 ......`.0....@R.
0000000005bdfe98 94 8b a0 aa 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000005bdfea8 00 7e 72 86 a0 9d 81 86 - 01 9e 81 86 00 00 00 00 .~r.............
0000000005bdfeb8 d8 fe 3f c0 38 41 6c 86 - 00 00 00 00 d8 09 98 86 ..?.8Al.........
0000000005bdfec8 00 00 10 00 7f 08 00 00 - 6c 9e 81 86 ff ff 87 00 ........l.......
0000000005bdfed8 a0 9d 81 86 00 00 00 00 - cb 60 d0 aa 00 00 88 00 .........`......
0000000005bdfee8 50 8b a0 aa af 89 1b 00 - ff ff ff ff 00 b0 fd 7f P...............
0000000005bdfef8 68 9e 4d 80 ff ff ff ff - 4a 36 5b 80 2c 16 54 80 h.M.....J6[.,.T.
0000000005bdff08 ff ff ff ff 00 00 00 00 - a8 5d 60 86 0b af c0 86 .........]`.....
0000000005bdff18 38 f5 df ff c4 58 54 80 - 00 c0 31 86 b4 b1 4f 80 8....XT...1...O.
0000000005bdff28 8c c1 31 86 80 ff bd 05 - ae df e7 77 48 ff bd 05 ..1........wH...
0000000005bdff38 be df e7 77 e0 10 90 7c - c0 96 65 04 18 6d 0c 07 ...w...|..e..m..
0000000005bdff48 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff ../M.....]......
*----> State Dump for Thread Id 0x3f4 <----*
eax=000000d0 ebx=00000102 ecx=07723d78 edx=00000000 esi=05cdeef8 edi=00000000
eip=7c90e4f4 esp=05cdee24 ebp=05cdee4c iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
05cdee4c 7e419402 05cdeef8 00000000 00000000 ntdll!KiFastSystemCallRet
05cdee78 5dff5f8c 05cdeef8 00000000 00000000 USER32!PeekMessageW+0x167
05cdeeb0 5dff6150 05cdeef8 00000000 00000000 IEUI!DUserRegisterSuper+0x920
05cdeed0 42f9edf4 05cdeef8 00000000 00000000 IEUI!PeekMessageExW+0x42
05cdef14 42f9ab4c 0730bf58 05cdef44 42f9bbbb IEFRAME!Ordinal101+0x357a
05cdef20 42f9bbbb 00000000 00000000 06f875f0 IEFRAME!Ordinal300+0xfb0a
05cdef44 42f9bb09 13f40001 00020004 00204dd0 IEFRAME!Ordinal101+0x341
05cdffb4 7c80b713 06f875f0 00020004 00204dd0 IEFRAME!Ordinal101+0x28f
05cdffec 00000000 42f9ba53 06f875f0 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
0000000005cdee24 e9 93 41 7e a8 93 41 7e - f8 ee cd 05 00 00 00 00 ..A~..A~........
0000000005cdee34 00 00 00 00 00 00 00 00 - 01 00 00 00 e0 1d 5e 00 ..............^.
0000000005cdee44 00 d0 fa 7f 01 00 00 00 - 78 ee cd 05 02 94 41 7e ........x.....A~
0000000005cdee54 f8 ee cd 05 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000005cdee64 01 00 00 00 00 00 00 00 - ff ff ff ff a0 82 1c 00 ................
0000000005cdee74 01 00 00 00 b0 ee cd 05 - 8c 5f ff 5d f8 ee cd 05 ........._.]....
0000000005cdee84 00 00 00 00 00 00 00 00 - 00 00 00 00 01 00 00 00 ................
0000000005cdee94 00 00 00 00 48 78 f9 42 - 58 bf 30 07 01 00 00 00 ....Hx.BX.0.....
0000000005cdeea4 03 00 00 00 00 00 00 00 - 48 78 f9 01 d0 ee cd 05 ........Hx......
0000000005cdeeb4 50 61 ff 5d f8 ee cd 05 - 00 00 00 00 00 00 00 00 Pa.]............
0000000005cdeec4 00 00 00 00 01 00 00 00 - 00 00 00 00 14 ef cd 05 ................
0000000005cdeed4 f4 ed f9 42 f8 ee cd 05 - 00 00 00 00 00 00 00 00 ...B............
0000000005cdeee4 00 00 00 00 01 00 00 00 - f0 75 f8 06 a0 6b 50 04 .........u...kP.
0000000005cdeef4 00 00 00 00 82 02 52 00 - a2 02 00 00 00 00 00 00 ......R.........
0000000005cdef04 00 00 00 00 70 74 1d 03 - e6 01 00 00 37 02 00 00 ....pt......7...
0000000005cdef14 20 ef cd 05 4c ab f9 42 - 58 bf 30 07 44 ef cd 05 ...L..BX.0.D...
0000000005cdef24 bb bb f9 42 00 00 00 00 - 00 00 00 00 f0 75 f8 06 ...B.........u..
0000000005cdef34 01 00 00 00 01 44 00 80 - 00 00 00 00 00 00 00 00 .....D..........
0000000005cdef44 b4 ff cd 05 09 bb f9 42 - 01 00 f4 13 04 00 02 00 .......B........
0000000005cdef54 d0 4d 20 00 f0 75 f8 06 - 00 00 00 00 00 00 00 00 .M ..u..........
*----> State Dump for Thread Id 0xf20 <----*
eax=01ada000 ebx=045b97a8 ecx=06c18b78 edx=00001000 esi=06c18e1c edi=06c18df0
eip=7c90e4f4 esp=06c18d64 ebp=06c18db0 iopl=0 nv up ei pl nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000206
function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\Downloaded Program Files\urSuperHost.dll -
ChildEBP RetAddr Args to Child
06c18db0 77e7a33e 0450a2b0 06c18dd0 77e7a36f ntdll!KiFastSystemCallRet
06c18dbc 77e7a36f 06c18df0 01ad3ba0 00000000 RPCRT4!I_RpcSendReceive+0x23
06c18dd0 01a27d50 06c18e1c 0450a2b0 01ad3ba0 RPCRT4!NdrSendReceive+0x28
06c18f14 01a285dd 07705100 01ad3ba0 00000000 urSuperHost+0x7d50
06c18f54 01a2832a 0700dd88 01ad3d44 01ad3c2c urSuperHost+0x85dd
06c18f8c 01a21314 438ae044 0a8cb040 06c18fe0 urSuperHost+0x832a
7c9010e0 4affc033 89257508 fff00c42 037d044a urSuperHost+0x1314
0424548b 00000000 00000000 00000000 00000000 0x4affc033
*----> Raw Stack Dump <----*
0000000006c18d64 cc da 90 7c c1 ca e7 77 - 0c 0e 00 00 78 a2 50 04 ...|...w....x.P.
0000000006c18d74 78 a2 50 04 f0 8d c1 06 - 1c 8e c1 06 00 10 90 7c x.P............|
0000000006c18d84 f0 8d c1 06 50 d6 f9 06 - 00 00 00 00 00 00 00 00 ....P...........
0000000006c18d94 1d 8a e7 77 f0 8d c1 06 - 00 00 00 00 1c 8e c1 06 ...w............
0000000006c18da4 00 10 90 7c a0 3b ad 01 - 00 00 00 00 bc 8d c1 06 ...|.;..........
0000000006c18db4 3e a3 e7 77 b0 a2 50 04 - d0 8d c1 06 6f a3 e7 77 >..w..P.....o..w
0000000006c18dc4 f0 8d c1 06 a0 3b ad 01 - 00 00 00 00 14 8f c1 06 .....;..........
0000000006c18dd4 50 7d a2 01 1c 8e c1 06 - b0 a2 50 04 a0 3b ad 01 P}........P..;..
0000000006c18de4 00 00 00 00 00 10 90 7c - 42 00 9e 00 a8 97 5b 04 .......|B.....[.
0000000006c18df4 10 00 00 00 b0 a2 50 04 - 00 00 00 00 00 00 00 00 ......P.........
0000000006c18e04 74 92 02 07 90 0c a5 01 - 78 bd 1f 00 d4 8e c1 06 t.......x.......
0000000006c18e14 3d 00 91 7c 00 00 00 00 - f0 8d c1 06 b0 a2 50 04 =..|..........P.
0000000006c18e24 00 00 00 00 00 00 00 00 - 48 8e c1 06 00 00 00 00 ........H.......
0000000006c18e34 00 00 00 00 65 e4 e7 77 - 01 00 00 00 00 00 00 00 ....e..w........
0000000006c18e44 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000006c18e54 00 00 00 00 f0 8e c1 06 - b8 b2 e7 77 00 51 70 07 ...........w.Qp.
0000000006c18e64 a4 86 a2 01 b1 86 a2 01 - 00 00 00 00 08 bb 51 04 ..............Q.
0000000006c18e74 38 8f c1 06 00 51 70 07 - d8 0c a5 01 08 bb 51 04 8....Qp.......Q.
0000000006c18e84 00 00 00 00 00 00 00 00 - 80 8e c1 06 02 00 00 00 ................
0000000006c18e94 00 00 00 00 72 00 70 00 - 00 00 14 00 00 00 00 00 ....r.p.........
*----> State Dump for Thread Id 0xe48 <----*
eax=00140000 ebx=00000000 ecx=0a7ec880 edx=0000014a esi=00000d58 edi=00000000
eip=7c90e4f4 esp=07a1ff10 ebp=07a1ff74 iopl=0 nv up ei ng nz ac pe cy
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000293
function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
07a1ff74 7c802542 00000d58 000927c0 00000000 ntdll!KiFastSystemCallRet
07a1ff88 4366f455 00000d58 000927c0 435d0000 kernel32!WaitForSingleObject+0x12
07a1ffb4 7c80b713 07328868 ffffffff 7c9101bb mshtml!DllGetClassObject+0x9036d
07a1ffec 00000000 435ed977 07328868 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
0000000007a1ff10 3c df 90 7c db 25 80 7c - 58 0d 00 00 00 00 00 00 <..|.%.|X.......
0000000007a1ff20 44 ff a1 07 00 00 00 00 - 68 88 32 07 00 00 00 00 D.......h.2.....
0000000007a1ff30 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000007a1ff40 10 00 00 00 00 44 5f 9a - fe ff ff ff 00 e0 fd 7f .....D_.........
0000000007a1ff50 00 10 fa 7f 44 ff a1 07 - 0a 00 00 80 24 ff a1 07 ....D.......$...
0000000007a1ff60 59 94 66 43 dc ff a1 07 - c0 9a 83 7c 08 26 80 7c Y.fC.......|.&.|
0000000007a1ff70 00 00 00 00 88 ff a1 07 - 42 25 80 7c 58 0d 00 00 ........B%.|X...
0000000007a1ff80 c0 27 09 00 00 00 00 00 - b4 ff a1 07 55 f4 66 43 .'..........U.fC
0000000007a1ff90 58 0d 00 00 c0 27 09 00 - 00 00 5d 43 68 88 32 07 X....'....]Ch.2.
0000000007a1ffa0 68 88 32 07 4a 6b 66 43 - ff ff ff ff bb 01 91 7c h.2.JkfC.......|
0000000007a1ffb0 84 d9 5e 43 ec ff a1 07 - 13 b7 80 7c 68 88 32 07 ..^C.......|h.2.
0000000007a1ffc0 ff ff ff ff bb 01 91 7c - 68 88 32 07 00 10 fa 7f .......|h.2.....
0000000007a1ffd0 00 e6 db 86 c0 ff a1 07 - 10 41 40 86 ff ff ff ff .........A@.....
0000000007a1ffe0 c0 9a 83 7c 20 b7 80 7c - 00 00 00 00 00 00 00 00 ...| ..|........
0000000007a1fff0 00 00 00 00 77 d9 5e 43 - 68 88 32 07 00 00 00 00 ....w.^Ch.2.....
0000000007a20000 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000007a20010 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000007a20020 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000007a20030 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000007a20040 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
*----> State Dump for Thread Id 0xf94 <----*
eax=77e76c7d ebx=00000000 ecx=0016622a edx=012e009e esi=04541b38 edi=04541bdc
eip=7c90e4f4 esp=0330fe18 ebp=0330ff80 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0330ff80 77e76caf 0330ffa8 77e76ad1 04541b38 ntdll!KiFastSystemCallRet
0330ff88 77e76ad1 04541b38 001fbd78 0048fac8 RPCRT4!I_RpcBCacheFree+0x61c
0330ffa8 77e76c97 0014d388 0330ffec 7c80b713 RPCRT4!I_RpcBCacheFree+0x43e
0330ffb4 7c80b713 044fba68 001fbd78 0048fac8 RPCRT4!I_RpcBCacheFree+0x604
0330ffec 00000000 77e76c7d 044fba68 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
000000000330fe18 8c da 90 7c e3 65 e7 77 - a4 10 00 00 74 ff 30 03 ...|.e.w....t.0.
000000000330fe28 00 00 00 00 b8 9f ff 06 - 48 ff 30 03 20 18 86 86 ........H.0. ...
000000000330fe38 48 6a 59 86 d8 c3 bc 86 - 88 9c bc 86 50 4d 8b 86 HjY.........PM..
000000000330fe48 00 00 00 00 0e 07 e3 aa - 39 ee 4f 80 00 9c 2c 86 ........9.O...,.
000000000330fe58 00 b4 00 00 18 f0 aa 86 - cc 0b 94 a9 f0 0d 94 a9 ................
000000000330fe68 44 0b 94 a9 78 df e3 aa - 0a 00 00 00 58 0b 94 a9 D...x.......X...
000000000330fe78 ec 0b 94 a9 ca 05 e3 aa - 00 9c 2c 86 08 55 7a 86 ..........,..Uz.
000000000330fe88 08 c0 01 00 01 91 53 80 - 04 00 00 00 10 00 00 00 ......S.........
000000000330fe98 30 0e 56 86 54 fc 00 00 - 43 6d 6e 80 28 0c 94 a9 0.V.T...Cmn.(...
000000000330fea8 27 64 6e 80 00 0d db ba - 00 00 00 00 53 fc 00 00 'dn.........S...
000000000330feb8 80 f2 df 86 4d 00 00 00 - a8 0b 94 a9 82 a6 54 80 ....M.........T.
000000000330fec8 30 0e 56 86 4c 0e 56 86 - 0d 00 00 00 38 9f 54 c0 0.V.L.V.....8.T.
000000000330fed8 21 4f 02 00 f0 0b 94 a9 - 00 00 00 00 00 00 00 00 !O..............
000000000330fee8 00 00 00 00 1f 00 00 00 - ff ff ff ff 40 f5 df ff ............@...
000000000330fef8 00 00 00 00 10 64 6e 80 - f4 6a cd 86 28 0c 94 a9 .....dn..j..(...
000000000330ff08 00 00 00 00 27 64 6e 80 - 08 00 00 00 46 02 00 00 ....'dn.....F...
000000000330ff18 68 38 50 80 c8 69 cd 86 - 58 69 cd 86 78 b0 4f 80 h8P..i..Xi..x.O.
000000000330ff28 c4 6a cd 86 80 ff 30 03 - ae df e7 77 48 ff 30 03 .j....0....wH.0.
000000000330ff38 be df e7 77 e0 10 90 7c - b0 87 65 04 68 ba 4f 04 ...w...|..e.h.O.
000000000330ff48 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff ../M.....]......
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Okay, I reregistered the dll, and that didn't help. Attached, please find the hijackthis log for this computer.
Sorry that I haven't gotten this up before now, but other, more pressing issues conspired against it.
Thanks again for the help.
Sorry that I haven't gotten this up before now, but other, more pressing issues conspired against it.
Thanks again for the help.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:04:19 PM, on 12/15/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\DWRCS.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PDFCreatorMessages.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files\Sophos\Remote Management System\RouterNT.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\DWRCST.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\JawsSystems\Jaws PDF Creator\PDFClient.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows Media Player\wmplayer.exe
C:\WINDOWS\Downloaded Program Files\CacheCleaner.exe
C:\Documents and Settings\crystal_h\Desktop\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://quicklink
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://quicklink
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://quicklink
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by GVNW Consulting, INC.
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Sophos Web Content Scanner - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - C:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O4 - HKLM\..\Run: [AsioReg] REGSVR32 /S CTASIO.DLL
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [DevconDefaultDB] C:\WINDOWS\READREG /PSCONV={NO}
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe
O4 - HKLM\..\Run: [PDFCreatorClient] "C:\Program Files\JawsSystems\Jaws PDF Creator\PDFClient.exe"
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DameWare MRC Agent] C:\WINDOWS\system32\DWRCST.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9d.exe
O4 - HKCU\..\RunOnce: [F5 Networks Cleaner] rundll32.exe C:\WINDOWS\DOWNLO~1\CACHEC~1.DLL,Run BROWSER:MSIE URL:neuvpn.neustar.biz
O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientAXDisabler] cmd.exe /C "%systemroot%\Installer\TSClientMsiTrans\tscdsbl.bat" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'Default user')
O4 - Global Startup: APC UPS Status.lnk = ?
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://quicklink
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2A0B9B82-D5C8-4D3D-8338-AD55B23662B1} (F5 Networks CacheCleaner) - https://neuvpn.neustar.biz/vdesk/cachecleaner.cab#version=6020,2007,1001,2137
O16 - DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} (F5 Networks Auto Update) - C:\DOCUME~1\CRYSTA~1\LOCALS~1\Temp\IXP000.TMP\InstallerControl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1228333341939
O16 - DPF: {6C275925-A1ED-4DD2-9CEE-9823F5FDAA10} (F5 Networks SSLTunnel) - https://neuvpn.neustar.biz/vdesk/terminal/urTermProxy.cab#version=6020,2007,1001,2136
O16 - DPF: {CC85ACDF-B277-486F-8C70-2C9B2ED2A4E7} (F5 Networks SuperHost Class) - https://neuvpn.neustar.biz/vdesk/terminal/urxshost.cab#version=6020,2007,1001,2141
O16 - DPF: {E0FF21FA-B857-45C5-8621-F120A0C17FF2} (F5 Networks Host Control) - https://neuvpn.neustar.biz/vdesk/terminal/urxhost.cab#version=6020,2007,1001,2140
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = gvnw.com
O17 - HKLM\Software\..\Telephony: DomainName = gvnw.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = gvnw.com
O20 - AppInit_DLLs: C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINDOWS\system32\DWRCS.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PDFCreatorMessages - Global Graphics Software Ltd. - C:\WINDOWS\system32\PDFCreatorMessages.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
O23 - Service: Sophos Agent - Sophos Plc - C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: Sophos Message Router - Sophos Plc - C:\Program Files\Sophos\Remote Management System\RouterNT.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/CRYSTA~1/LOCALS~1/Temp/msohtml1/01/clip_image002.gif
O24 - Desktop Component 1: (no name) - C:\Client code cheat sheet on desktop.htm
--
End of file - 9517 bytes
ASKER
I'd like to close this. Had to take the jack-hammer approach and wipe/reload the system. So far, it hasn't happened again.
ASKER
Thanks for the help, guys. Unfortunately, nothing I tried (your suggestions included) helped. I ended up reloading the system. Since then, the problem has not resurfaced.
I split the points between you for trying to help.
Thanks.
I split the points between you for trying to help.
Thanks.
ASKER
The PC is up to date with all patches and updates. Running IE7. Unfortunately, a secure website that the user connects to requires IE7, and won't support anything else. I'll try re-registering the dll and get back with you. Unfortunately, due to the inconsistent nature of the issue, it may be a few days.
Thanks.