S
Svengali
My laptop recently crashed with the BSOD error:
windowx xp boot sequence
Stop c000021a {Fatal System Error}
The session manager initialization system process terminated unexpectedly
with a status of 0xc0000034 (0x00000000, 0x0000000)
The system has been shut down.
I cannot start the machine in any mode. My only hope is to use the Recovery
Console to perform the necessary repairs as I
don’t have a rescue disk. The problem occurred after I updated some
TrendMicro Internet Security virus pattern file. The
computer took a really abnormally long time to shut down and the problem
started the next day when I started the machine.
It seems from all my research that I might have a corrupt registry, but I am
not sure. I am trying to go about this in a
systematic way. So far I have backed up my data, but I have some
applications that I want to save if I can. I managed to
copy the Dr. Watson log and also the dump file from the laptop. I can’t do
much with the dump file since I can’t debug code.
Although, I imported it in Visual C++ so see if I could get any clues. But,
some scary things happened, so I quickly backed
out. I also downloaded and installed the Windows Debug Tool and used that to
open the dump file. Finally, I imported the
Application, Security, and System Event logs into the Event Viewer on
another machine.
I would like to share the results and solicit some input as to the best way
to solve this problem. To avoid too mush
confusion, I am going to post the results of each tool that I used
separately so that the post does not become too cumbersome
to read.
Below is a portion of the last Dr. Watson log entry. I am of the opinion
that the Internet Explorer error in the Dr. Watson
log is just a red herring, and the real problem can be found in the event
viewer logs. BTW, I get a lot of these IE errors in
the Dr. Watson log any those were the only type of log entries for the past
two days. Therefore I really think that the Dr.
Watson log is a red herring. I think that my suspension about a corrupt
registry is confirmed by the Event Viewer Logs. But I
am not an expert. BTW, I am Running IE 6. on XP Home SP2, and I forgot which
service pack for IE.
I would like any suggestions on other MS groups that I can post this message
to for a better resolution.
Dr. Watson Log, This is rather large file, so I just included a portion of
the final entry.
_______________________________________________________
Application exception occurred:
App: C:\Program Files\Internet Explorer\iexplore.exe (pid=2856)
When: 11/24/2007 @ 05:11:38.500
Exception number: c0000005 (access violation)
*----> System Information <----*
Computer Name: OWNER
User Name: OWNER
Terminal Session Id: 0
Number of Processors: 2
Processor Type: x86 Family 15 Model 2 Stepping 9
Windows Version: 5.1
Current Build: 2600
Service Pack: 2
Current Type: Multiprocessor Free
Registered Organization:
Registered Owner: OWNER
*----> Task List <----*
0 System Process
4 System
900 smss.exe
952 csrss.exe
992 winlogon.exe
1036 services.exe
1048 lsass.exe
1252 svchost.exe
1296 svchost.exe
1348 svchost.exe
1388 svchost.exe
1440 svchost.exe
1536 svchost.exe
1856 spoolsv.exe
1956 CeEPwrSvc.exe
1972 DVDRAMSV.exe
2044 lkcitdl.exe
168 lkads.exe
204 lktsrv.exe
276 matlabserver.exe
444 mdm.exe
548 matlab.exe
556 sqlservr.exe
728 nimxs.exe
748 nidmsrv.exe
768 nisvcloc.exe
780 tagsrv.exe
1428 nvsvc32.exe
1664 PcCtlCom.exe
620 PcScnSrv.exe
1452 SMARTBoardService.exe
1756 svchost.exe
2224 Tmntsrv.exe
2240 TmPfw.exe
2272 tmproxy.exe
2568 CALMAIN.exe
1484 alg.exe
3452 ctfmon.exe
932 Explorer.EXE
2676 PccGuide.exe
3768 Apoint.exe
532 CplBTQ00.EXE
3948 CeEKey.exe
3968 TPTray.exe
3984 CePMTray.exe
608 opware32.exe
3832 qttask.exe
176 AGRSMMSG.exe
688 WatchDog.exe
3952 V0230Mon.exe
792 Apntex.exe
820 jusched.exe
2288 StickyPad.exe
2376 CTLCMgr.exe
2992 AcroTray.exe
3392 RAMASST.exe
2328 wudfhost.exe
3356 ivpsvmgr.exe
4068 iexplore.exe
3652 PCCMAIN.EXE
3440 AcroRd32.exe
3920 iexplore.exe
3800 drwtsn32.exe
*----> Module List <----*
(0000000000400000 - 0000000000419000: C:\Program Files\Internet
Explorer\iexplore.exe
(0000000000c70000 - 0000000000ccb000: C:\Program Files\Common
Files\Microsoft Shared\INK\SKCHUI.DLL
(0000000002470000 - 000000000247e000: C:\Program Files\Adobe\Acrobat
7.0\ActiveX\AcroIEHelper.dll
(0000000002520000 - 00000000025a8000: C:\WINDOWS\system32\shdoclc.dll
(00000000025b0000 - 0000000002875000: C:\WINDOWS\system32\xpsp2res.dll
(0000000002980000 - 000000000298e000: C:\WINDOWS\system32\bmi_lsp.dll
(0000000002990000 - 000000000299e000: C:\WINDOWS\system32\bmzlib.dll
(000000000ffd0000 - 000000000fff8000: C:\WINDOWS\system32\rsaenh.dll
(0000000010000000 - 000000001002b000: C:\Program
Files\ScanSoft\OmniPageSE\ophook32.dll
(0000000020000000 - 0000000020012000: C:\WINDOWS\system32\browselc.dll
(0000000030000000 - 00000000302ef000:
C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx
(0000000032520000 - 0000000032532000: C:\Program Files\Microsoft
Office\Office10\msohev.dll
(00000000506a0000 - 0000000050728000: C:\WINDOWS\system32\wuapi.dll
(000000005ad70000 - 000000005ada8000: C:\WINDOWS\system32\uxtheme.dll
(000000005b860000 - 000000005b8b4000: C:\WINDOWS\system32\NETAPI32.dll
(000000005d090000 - 000000005d12a000: C:\WINDOWS\system32\comctl32.dll
(00000000662b0000 - 0000000066308000: C:\WINDOWS\system32\hnetcfg.dll
(0000000066e50000 - 0000000066e90000: C:\WINDOWS\System32\iepeers.dll
(000000006bdd0000 - 000000006be06000: C:\WINDOWS\System32\dxtrans.dll
(000000006be10000 - 000000006be6a000: C:\WINDOWS\System32\dxtmsft.dll
(000000006d430000 - 000000006d43a000: C:\WINDOWS\System32\ddrawex.dll
(000000006d7c0000 - 000000006d839000: C:\Program
Files\Java\jre1.6.0_03\bin\ssv.dll
(0000000071a50000 - 0000000071a8f000: C:\WINDOWS\system32\mswsock.dll
(0000000071a90000 - 0000000071a98000: C:\WINDOWS\System32\wshtcpip.dll
(0000000071aa0000 - 0000000071aa8000: C:\WINDOWS\system32\WS2HELP.dll
(0000000071ab0000 - 0000000071ac7000: C:\WINDOWS\system32\WS2_32.dll
(0000000071ad0000 - 0000000071ad9000: C:\WINDOWS\system32\wsock32.dll
(00000000722b0000 - 00000000722b5000: C:\WINDOWS\system32\sensapi.dll
(0000000072d10000 - 0000000072d18000: C:\WINDOWS\system32\msacm32.drv
(0000000072d20000 - 0000000072d29000: C:\WINDOWS\system32\wdmaud.drv
(0000000073000000 - 0000000073026000: C:\WINDOWS\System32\WINSPOOL.DRV
(0000000073080000 - 000000007309c000: C:\WINDOWS\system32\rsvpsp.dll
(0000000073760000 - 00000000737a9000: C:\WINDOWS\System32\DDRAW.dll
(0000000073bc0000 - 0000000073bc6000: C:\WINDOWS\System32\DCIMAN32.dll
(00000000746c0000 - 00000000746e7000: C:\WINDOWS\System32\msls31.dll
(00000000746f0000 - 000000007471a000: C:\WINDOWS\System32\msimtf.dll
(0000000074720000 - 000000007476b000: C:\WINDOWS\system32\MSCTF.dll
(0000000075150000 - 0000000075164000: C:\WINDOWS\system32\Cabinet.dll
(00000000754d0000 - 0000000075550000: C:\WINDOWS\system32\CRYPTUI.dll
(00000000755c0000 - 00000000755ee000: C:\WINDOWS\system32\msctfime.ime
(0000000075c50000 - 0000000075cbe000: c:\windows\system32\jscript.dll
(0000000075cf0000 - 0000000075d81000: C:\WINDOWS\system32\mlang.dll
(0000000075e90000 - 0000000075f40000: C:\WINDOWS\system32\SXS.DLL
(0000000075f80000 - 000000007607d000: C:\WINDOWS\system32\BROWSEUI.dll
(0000000076200000 - 0000000076271000: C:\WINDOWS\System32\mshtmled.dll
(0000000076390000 - 00000000763ad000: C:\WINDOWS\system32\IMM32.DLL
(00000000763b0000 - 00000000763f9000: C:\WINDOWS\system32\comdlg32.dll
(0000000076600000 - 000000007661d000: C:\WINDOWS\System32\CSCDLL.dll
(0000000076990000 - 00000000769b5000: C:\WINDOWS\system32\ntshrui.dll
(00000000769c0000 - 0000000076a73000: C:\WINDOWS\system32\USERENV.dll
(0000000076b20000 - 0000000076b31000: C:\WINDOWS\System32\ATL.DLL
(0000000076b40000 - 0000000076b6d000: C:\WINDOWS\system32\WINMM.dll
(0000000076bf0000 - 0000000076bfb000: C:\WINDOWS\System32\PSAPI.DLL
(0000000076c30000 - 0000000076c5e000: C:\WINDOWS\system32\WINTRUST.dll
(0000000076c90000 - 0000000076cb8000: C:\WINDOWS\system32\IMAGEHLP.dll
(0000000076d60000 - 0000000076d79000: C:\WINDOWS\system32\iphlpapi.dll
(0000000076e80000 - 0000000076e8e000: C:\WINDOWS\system32\rtutils.dll
(0000000076e90000 - 0000000076ea2000: C:\WINDOWS\system32\rasman.dll
(0000000076eb0000 - 0000000076edf000: C:\WINDOWS\system32\TAPI32.dll
(0000000076ee0000 - 0000000076f1c000: C:\WINDOWS\system32\RASAPI32.DLL
(0000000076f20000 - 0000000076f47000: C:\WINDOWS\system32\DNSAPI.dll
(0000000076f60000 - 0000000076f8c000: C:\WINDOWS\system32\WLDAP32.dll
(0000000076fb0000 - 0000000076fb8000: C:\WINDOWS\System32\winrnr.dll
(0000000076fc0000 - 0000000076fc6000: C:\WINDOWS\system32\rasadhlp.dll
(0000000076fd0000 - 000000007704f000: C:\WINDOWS\system32\CLBCATQ.DLL
(0000000077050000 - 0000000077115000: C:\WINDOWS\system32\COMRes.dll
(0000000077120000 - 00000000771ab000: C:\WINDOWS\system32\OLEAUT32.dll
(00000000771b0000 - 0000000077256000: C:\WINDOWS\system32\WININET.dll
(00000000773d0000 - 00000000774d3000:
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
(00000000774e0000 - 000000007761d000: C:\WINDOWS\system32\ole32.dll
(0000000077920000 - 0000000077a13000: C:\WINDOWS\system32\SETUPAPI.dll
(0000000077a20000 - 0000000077a74000: C:\WINDOWS\System32\cscui.dll
(0000000077a80000 - 0000000077b14000: C:\WINDOWS\system32\CRYPT32.dll
(0000000077b20000 - 0000000077b32000: C:\WINDOWS\system32\MSASN1.dll
(0000000077b40000 - 0000000077b62000: C:\WINDOWS\system32\appHelp.dll
(0000000077bd0000 - 0000000077bd7000: C:\WINDOWS\system32\midimap.dll
(0000000077be0000 - 0000000077bf5000: C:\WINDOWS\system32\MSACM32.dll
(0000000077c00000 - 0000000077c08000: C:\WINDOWS\system32\VERSION.dll
(0000000077c10000 - 0000000077c68000: C:\WINDOWS\system32\msvcrt.dll
(0000000077c70000 - 0000000077c93000: C:\WINDOWS\system32\msv1_0.dll
(0000000077dd0000 - 0000000077e6b000: C:\WINDOWS\system32\ADVAPI32.dll
(0000000077e70000 - 0000000077f02000: C:\WINDOWS\system32\RPCRT4.dll
(0000000077f10000 - 0000000077f57000: C:\WINDOWS\system32\GDI32.dll
(0000000077f60000 - 0000000077fd6000: C:\WINDOWS\system32\SHLWAPI.dll
(0000000077fe0000 - 0000000077ff1000: C:\WINDOWS\system32\Secur32.dll
(000000007c340000 - 000000007c396000: C:\WINDOWS\system32\MSVCR71.dll
(000000007c800000 - 000000007c8f5000: C:\WINDOWS\system32\kernel32.dll
(000000007c900000 - 000000007c9b0000: C:\WINDOWS\system32\ntdll.dll
(000000007c9c0000 - 000000007d1d6000: C:\WINDOWS\system32\SHELL32.dll
(000000007d1e0000 - 000000007d49e000: C:\WINDOWS\system32\msi.dll
(000000007dc30000 - 000000007df21000: C:\WINDOWS\System32\mshtml.dll
(000000007e1e0000 - 000000007e280000: C:\WINDOWS\system32\urlmon.dll
(000000007e290000 - 000000007e3ff000: C:\WINDOWS\system32\SHDOCVW.dll
(000000007e410000 - 000000007e4a0000: C:\WINDOWS\system32\USER32.dll
*----> State Dump for Thread Id 0xb98 <----*
eax=00720070 ebx=036232f0 ecx=001b4398 edx=7ded4de0 esi=036c97f0 edi=03623310
eip=7dd3f491 esp=001361b8 ebp=001361cc iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\System32\mshtml.dll -
function: mshtml!DllGetClassObject
7dd3f469 e8c25b0500 call mshtml!CreateHTMLPropertyPage+0x20250
(7dd95030)
7dd3f46e e966e5f8ff jmp mshtml+0x9d9d9 (7dccd9d9)
7dd3f473 095810 or [eax+0x10],ebx
7dd3f476 8b45fc mov eax,[ebp-0x4]
7dd3f479 e9a9e5f8ff jmp mshtml+0x9da27 (7dccda27)
7dd3f47e 8b4dfc mov ecx,[ebp-0x4]
7dd3f481 e80fb5f8ff call mshtml+0x9a995 (7dcca995)
7dd3f486 85c0 test eax,eax
7dd3f488 0f84ec25f8ff je mshtml+0x91a7a (7dcc1a7a)
7dd3f48e 8b4324 mov eax,[ebx+0x24]
FAULT ->7dd3f491 8b30 mov esi,[eax]
ds:0023:00720070=????????
7dd3f493 6a00 push 0x0
7dd3f495 8bcf mov ecx,edi
7dd3f497 e8b496f6ff call mshtml+0x78b50 (7dca8b50)
7dd3f49c 33c0 xor eax,eax
7dd3f49e 50 push eax
7dd3f49f 50 push eax
7dd3f4a0 50 push eax
7dd3f4a1 8bce mov ecx,esi
7dd3f4a3 e85097f8ff call mshtml+0x98bf8 (7dcc8bf8)
7dd3f4a8 85c0 test eax,eax
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be
wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\USER32.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\SHLWAPI.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\WININET.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
c:\windows\system32\jscript.dll -
ChildEBP RetAddr Args to Child
windowx xp boot sequence
Stop c000021a {Fatal System Error}
The session manager initialization system process terminated unexpectedly
with a status of 0xc0000034 (0x00000000, 0x0000000)
The system has been shut down.
I cannot start the machine in any mode. My only hope is to use the Recovery
Console to perform the necessary repairs as I
don’t have a rescue disk. The problem occurred after I updated some
TrendMicro Internet Security virus pattern file. The
computer took a really abnormally long time to shut down and the problem
started the next day when I started the machine.
It seems from all my research that I might have a corrupt registry, but I am
not sure. I am trying to go about this in a
systematic way. So far I have backed up my data, but I have some
applications that I want to save if I can. I managed to
copy the Dr. Watson log and also the dump file from the laptop. I can’t do
much with the dump file since I can’t debug code.
Although, I imported it in Visual C++ so see if I could get any clues. But,
some scary things happened, so I quickly backed
out. I also downloaded and installed the Windows Debug Tool and used that to
open the dump file. Finally, I imported the
Application, Security, and System Event logs into the Event Viewer on
another machine.
I would like to share the results and solicit some input as to the best way
to solve this problem. To avoid too mush
confusion, I am going to post the results of each tool that I used
separately so that the post does not become too cumbersome
to read.
Below is a portion of the last Dr. Watson log entry. I am of the opinion
that the Internet Explorer error in the Dr. Watson
log is just a red herring, and the real problem can be found in the event
viewer logs. BTW, I get a lot of these IE errors in
the Dr. Watson log any those were the only type of log entries for the past
two days. Therefore I really think that the Dr.
Watson log is a red herring. I think that my suspension about a corrupt
registry is confirmed by the Event Viewer Logs. But I
am not an expert. BTW, I am Running IE 6. on XP Home SP2, and I forgot which
service pack for IE.
I would like any suggestions on other MS groups that I can post this message
to for a better resolution.
Dr. Watson Log, This is rather large file, so I just included a portion of
the final entry.
_______________________________________________________
Application exception occurred:
App: C:\Program Files\Internet Explorer\iexplore.exe (pid=2856)
When: 11/24/2007 @ 05:11:38.500
Exception number: c0000005 (access violation)
*----> System Information <----*
Computer Name: OWNER
User Name: OWNER
Terminal Session Id: 0
Number of Processors: 2
Processor Type: x86 Family 15 Model 2 Stepping 9
Windows Version: 5.1
Current Build: 2600
Service Pack: 2
Current Type: Multiprocessor Free
Registered Organization:
Registered Owner: OWNER
*----> Task List <----*
0 System Process
4 System
900 smss.exe
952 csrss.exe
992 winlogon.exe
1036 services.exe
1048 lsass.exe
1252 svchost.exe
1296 svchost.exe
1348 svchost.exe
1388 svchost.exe
1440 svchost.exe
1536 svchost.exe
1856 spoolsv.exe
1956 CeEPwrSvc.exe
1972 DVDRAMSV.exe
2044 lkcitdl.exe
168 lkads.exe
204 lktsrv.exe
276 matlabserver.exe
444 mdm.exe
548 matlab.exe
556 sqlservr.exe
728 nimxs.exe
748 nidmsrv.exe
768 nisvcloc.exe
780 tagsrv.exe
1428 nvsvc32.exe
1664 PcCtlCom.exe
620 PcScnSrv.exe
1452 SMARTBoardService.exe
1756 svchost.exe
2224 Tmntsrv.exe
2240 TmPfw.exe
2272 tmproxy.exe
2568 CALMAIN.exe
1484 alg.exe
3452 ctfmon.exe
932 Explorer.EXE
2676 PccGuide.exe
3768 Apoint.exe
532 CplBTQ00.EXE
3948 CeEKey.exe
3968 TPTray.exe
3984 CePMTray.exe
608 opware32.exe
3832 qttask.exe
176 AGRSMMSG.exe
688 WatchDog.exe
3952 V0230Mon.exe
792 Apntex.exe
820 jusched.exe
2288 StickyPad.exe
2376 CTLCMgr.exe
2992 AcroTray.exe
3392 RAMASST.exe
2328 wudfhost.exe
3356 ivpsvmgr.exe
4068 iexplore.exe
3652 PCCMAIN.EXE
3440 AcroRd32.exe
3920 iexplore.exe
3800 drwtsn32.exe
*----> Module List <----*
(0000000000400000 - 0000000000419000: C:\Program Files\Internet
Explorer\iexplore.exe
(0000000000c70000 - 0000000000ccb000: C:\Program Files\Common
Files\Microsoft Shared\INK\SKCHUI.DLL
(0000000002470000 - 000000000247e000: C:\Program Files\Adobe\Acrobat
7.0\ActiveX\AcroIEHelper.dll
(0000000002520000 - 00000000025a8000: C:\WINDOWS\system32\shdoclc.dll
(00000000025b0000 - 0000000002875000: C:\WINDOWS\system32\xpsp2res.dll
(0000000002980000 - 000000000298e000: C:\WINDOWS\system32\bmi_lsp.dll
(0000000002990000 - 000000000299e000: C:\WINDOWS\system32\bmzlib.dll
(000000000ffd0000 - 000000000fff8000: C:\WINDOWS\system32\rsaenh.dll
(0000000010000000 - 000000001002b000: C:\Program
Files\ScanSoft\OmniPageSE\ophook32.dll
(0000000020000000 - 0000000020012000: C:\WINDOWS\system32\browselc.dll
(0000000030000000 - 00000000302ef000:
C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx
(0000000032520000 - 0000000032532000: C:\Program Files\Microsoft
Office\Office10\msohev.dll
(00000000506a0000 - 0000000050728000: C:\WINDOWS\system32\wuapi.dll
(000000005ad70000 - 000000005ada8000: C:\WINDOWS\system32\uxtheme.dll
(000000005b860000 - 000000005b8b4000: C:\WINDOWS\system32\NETAPI32.dll
(000000005d090000 - 000000005d12a000: C:\WINDOWS\system32\comctl32.dll
(00000000662b0000 - 0000000066308000: C:\WINDOWS\system32\hnetcfg.dll
(0000000066e50000 - 0000000066e90000: C:\WINDOWS\System32\iepeers.dll
(000000006bdd0000 - 000000006be06000: C:\WINDOWS\System32\dxtrans.dll
(000000006be10000 - 000000006be6a000: C:\WINDOWS\System32\dxtmsft.dll
(000000006d430000 - 000000006d43a000: C:\WINDOWS\System32\ddrawex.dll
(000000006d7c0000 - 000000006d839000: C:\Program
Files\Java\jre1.6.0_03\bin\ssv.dll
(0000000071a50000 - 0000000071a8f000: C:\WINDOWS\system32\mswsock.dll
(0000000071a90000 - 0000000071a98000: C:\WINDOWS\System32\wshtcpip.dll
(0000000071aa0000 - 0000000071aa8000: C:\WINDOWS\system32\WS2HELP.dll
(0000000071ab0000 - 0000000071ac7000: C:\WINDOWS\system32\WS2_32.dll
(0000000071ad0000 - 0000000071ad9000: C:\WINDOWS\system32\wsock32.dll
(00000000722b0000 - 00000000722b5000: C:\WINDOWS\system32\sensapi.dll
(0000000072d10000 - 0000000072d18000: C:\WINDOWS\system32\msacm32.drv
(0000000072d20000 - 0000000072d29000: C:\WINDOWS\system32\wdmaud.drv
(0000000073000000 - 0000000073026000: C:\WINDOWS\System32\WINSPOOL.DRV
(0000000073080000 - 000000007309c000: C:\WINDOWS\system32\rsvpsp.dll
(0000000073760000 - 00000000737a9000: C:\WINDOWS\System32\DDRAW.dll
(0000000073bc0000 - 0000000073bc6000: C:\WINDOWS\System32\DCIMAN32.dll
(00000000746c0000 - 00000000746e7000: C:\WINDOWS\System32\msls31.dll
(00000000746f0000 - 000000007471a000: C:\WINDOWS\System32\msimtf.dll
(0000000074720000 - 000000007476b000: C:\WINDOWS\system32\MSCTF.dll
(0000000075150000 - 0000000075164000: C:\WINDOWS\system32\Cabinet.dll
(00000000754d0000 - 0000000075550000: C:\WINDOWS\system32\CRYPTUI.dll
(00000000755c0000 - 00000000755ee000: C:\WINDOWS\system32\msctfime.ime
(0000000075c50000 - 0000000075cbe000: c:\windows\system32\jscript.dll
(0000000075cf0000 - 0000000075d81000: C:\WINDOWS\system32\mlang.dll
(0000000075e90000 - 0000000075f40000: C:\WINDOWS\system32\SXS.DLL
(0000000075f80000 - 000000007607d000: C:\WINDOWS\system32\BROWSEUI.dll
(0000000076200000 - 0000000076271000: C:\WINDOWS\System32\mshtmled.dll
(0000000076390000 - 00000000763ad000: C:\WINDOWS\system32\IMM32.DLL
(00000000763b0000 - 00000000763f9000: C:\WINDOWS\system32\comdlg32.dll
(0000000076600000 - 000000007661d000: C:\WINDOWS\System32\CSCDLL.dll
(0000000076990000 - 00000000769b5000: C:\WINDOWS\system32\ntshrui.dll
(00000000769c0000 - 0000000076a73000: C:\WINDOWS\system32\USERENV.dll
(0000000076b20000 - 0000000076b31000: C:\WINDOWS\System32\ATL.DLL
(0000000076b40000 - 0000000076b6d000: C:\WINDOWS\system32\WINMM.dll
(0000000076bf0000 - 0000000076bfb000: C:\WINDOWS\System32\PSAPI.DLL
(0000000076c30000 - 0000000076c5e000: C:\WINDOWS\system32\WINTRUST.dll
(0000000076c90000 - 0000000076cb8000: C:\WINDOWS\system32\IMAGEHLP.dll
(0000000076d60000 - 0000000076d79000: C:\WINDOWS\system32\iphlpapi.dll
(0000000076e80000 - 0000000076e8e000: C:\WINDOWS\system32\rtutils.dll
(0000000076e90000 - 0000000076ea2000: C:\WINDOWS\system32\rasman.dll
(0000000076eb0000 - 0000000076edf000: C:\WINDOWS\system32\TAPI32.dll
(0000000076ee0000 - 0000000076f1c000: C:\WINDOWS\system32\RASAPI32.DLL
(0000000076f20000 - 0000000076f47000: C:\WINDOWS\system32\DNSAPI.dll
(0000000076f60000 - 0000000076f8c000: C:\WINDOWS\system32\WLDAP32.dll
(0000000076fb0000 - 0000000076fb8000: C:\WINDOWS\System32\winrnr.dll
(0000000076fc0000 - 0000000076fc6000: C:\WINDOWS\system32\rasadhlp.dll
(0000000076fd0000 - 000000007704f000: C:\WINDOWS\system32\CLBCATQ.DLL
(0000000077050000 - 0000000077115000: C:\WINDOWS\system32\COMRes.dll
(0000000077120000 - 00000000771ab000: C:\WINDOWS\system32\OLEAUT32.dll
(00000000771b0000 - 0000000077256000: C:\WINDOWS\system32\WININET.dll
(00000000773d0000 - 00000000774d3000:
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
(00000000774e0000 - 000000007761d000: C:\WINDOWS\system32\ole32.dll
(0000000077920000 - 0000000077a13000: C:\WINDOWS\system32\SETUPAPI.dll
(0000000077a20000 - 0000000077a74000: C:\WINDOWS\System32\cscui.dll
(0000000077a80000 - 0000000077b14000: C:\WINDOWS\system32\CRYPT32.dll
(0000000077b20000 - 0000000077b32000: C:\WINDOWS\system32\MSASN1.dll
(0000000077b40000 - 0000000077b62000: C:\WINDOWS\system32\appHelp.dll
(0000000077bd0000 - 0000000077bd7000: C:\WINDOWS\system32\midimap.dll
(0000000077be0000 - 0000000077bf5000: C:\WINDOWS\system32\MSACM32.dll
(0000000077c00000 - 0000000077c08000: C:\WINDOWS\system32\VERSION.dll
(0000000077c10000 - 0000000077c68000: C:\WINDOWS\system32\msvcrt.dll
(0000000077c70000 - 0000000077c93000: C:\WINDOWS\system32\msv1_0.dll
(0000000077dd0000 - 0000000077e6b000: C:\WINDOWS\system32\ADVAPI32.dll
(0000000077e70000 - 0000000077f02000: C:\WINDOWS\system32\RPCRT4.dll
(0000000077f10000 - 0000000077f57000: C:\WINDOWS\system32\GDI32.dll
(0000000077f60000 - 0000000077fd6000: C:\WINDOWS\system32\SHLWAPI.dll
(0000000077fe0000 - 0000000077ff1000: C:\WINDOWS\system32\Secur32.dll
(000000007c340000 - 000000007c396000: C:\WINDOWS\system32\MSVCR71.dll
(000000007c800000 - 000000007c8f5000: C:\WINDOWS\system32\kernel32.dll
(000000007c900000 - 000000007c9b0000: C:\WINDOWS\system32\ntdll.dll
(000000007c9c0000 - 000000007d1d6000: C:\WINDOWS\system32\SHELL32.dll
(000000007d1e0000 - 000000007d49e000: C:\WINDOWS\system32\msi.dll
(000000007dc30000 - 000000007df21000: C:\WINDOWS\System32\mshtml.dll
(000000007e1e0000 - 000000007e280000: C:\WINDOWS\system32\urlmon.dll
(000000007e290000 - 000000007e3ff000: C:\WINDOWS\system32\SHDOCVW.dll
(000000007e410000 - 000000007e4a0000: C:\WINDOWS\system32\USER32.dll
*----> State Dump for Thread Id 0xb98 <----*
eax=00720070 ebx=036232f0 ecx=001b4398 edx=7ded4de0 esi=036c97f0 edi=03623310
eip=7dd3f491 esp=001361b8 ebp=001361cc iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\System32\mshtml.dll -
function: mshtml!DllGetClassObject
7dd3f469 e8c25b0500 call mshtml!CreateHTMLPropertyPage+0x20250
(7dd95030)
7dd3f46e e966e5f8ff jmp mshtml+0x9d9d9 (7dccd9d9)
7dd3f473 095810 or [eax+0x10],ebx
7dd3f476 8b45fc mov eax,[ebp-0x4]
7dd3f479 e9a9e5f8ff jmp mshtml+0x9da27 (7dccda27)
7dd3f47e 8b4dfc mov ecx,[ebp-0x4]
7dd3f481 e80fb5f8ff call mshtml+0x9a995 (7dcca995)
7dd3f486 85c0 test eax,eax
7dd3f488 0f84ec25f8ff je mshtml+0x91a7a (7dcc1a7a)
7dd3f48e 8b4324 mov eax,[ebx+0x24]
FAULT ->7dd3f491 8b30 mov esi,[eax]
ds:0023:00720070=????????
7dd3f493 6a00 push 0x0
7dd3f495 8bcf mov ecx,edi
7dd3f497 e8b496f6ff call mshtml+0x78b50 (7dca8b50)
7dd3f49c 33c0 xor eax,eax
7dd3f49e 50 push eax
7dd3f49f 50 push eax
7dd3f4a0 50 push eax
7dd3f4a1 8bce mov ecx,esi
7dd3f4a3 e85097f8ff call mshtml+0x98bf8 (7dcc8bf8)
7dd3f4a8 85c0 test eax,eax
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be
wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\USER32.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\SHLWAPI.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\WININET.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
c:\windows\system32\jscript.dll -
ChildEBP RetAddr Args to Child