IE6 crash, ModName: unknown

  • Thread starter Thread starter Rodi
  • Start date Start date
R

Rodi

hi everyone,

we've developed an asp.net site for one of our customers' intranet.
however, on some of their computers IE6 crashes when browsing the site.
the crash occurs when switching several times between a popup (opened
by clicking links on the main site) and the main site itself (again, by
clicking links in the main site which are opened in the same popup
window, sometimes closing the popup between views). when viewing the
error signature by clicking the "click here" link in the error report
dialog, the following signature is displayed:

AppName: iexplore.exe
AppVer: 6.0.2800.1106
ModName: unknown
ModVer: 0.0.0.0
Offset: 00000001

the crash only occurs on several computers (XP and 2000) at our
customer. i've never seen the error on my computer.. does anyone know
how to go about solving this one? i've read that the dr. watson log
could be helpful, but i have no idea how to interpret this log file.
i'll include the file at the end of this post.

please, help :-)

kind regards,
-rodi.

---
drwtsn32.log
---
*----> Taakoverzicht <----*
0 System Process
4 Error 0xD0000022
584 Error 0xD0000022
632 Error 0xD0000022
656 Error 0xD0000022
700 Error 0xD0000022
712 Error 0xD0000022
892 Error 0xD0000022
960 Error 0xD0000022
1056 Error 0xD0000022
1180 Error 0xD0000022
1252 Error 0xD0000022
1416 Error 0xD0000022
1624 Error 0xD0000022
1728 Error 0xD0000022
1796 Error 0xD0000022
1988 Error 0xD0000022
2004 Error 0xD0000022
232 Error 0xD0000022
1392 Explorer.EXE
808 ZLH.EXE
2016 hkcmd.exe
900 igfxpers.exe
1672 RTHDCPL.EXE
1864 realsched.exe
340 qttask.exe
408 ctfmon.exe
424 cclaw.exe
2244 OUTLOOK.EXE
3396 ImmixWindows.exe
3784 WINWORD.EXE
2876 iexplore.exe
2516 drwtsn32.exe

*----> Modulelijst <----*
(0000000000400000 - 0000000000419000: C:\Program Files\Internet
Explorer\iexplore.exe
(0000000000e60000 - 0000000000eec000: C:\WINDOWS\system32\shdoclc.dll
(0000000000ef0000 - 00000000011c5000: C:\WINDOWS\system32\xpsp2res.dll
(0000000010000000 - 000000001000e000: C:\Program Files\Adobe\Acrobat
7.0\ActiveX\AcroIEHelper.dll
(0000000020000000 - 0000000020013000: C:\WINDOWS\system32\browselc.dll
(00000000325c0000 - 00000000325d2000: C:\Program Files\Microsoft Office
2003\OFFICE11\msohev.dll
(000000004d580000 - 000000004d5d8000: C:\WINDOWS\system32\WINHTTP.dll
(000000005b190000 - 000000005b1c8000: C:\WINDOWS\system32\UxTheme.dll
(000000005d4e0000 - 000000005d577000: C:\WINDOWS\system32\comctl32.dll
(000000005e770000 - 000000005e77c000: C:\WINDOWS\system32\pngfilt.dll
(0000000061200000 - 0000000061259000: C:\WINDOWS\system32\hnetcfg.dll
(0000000066d30000 - 0000000066d3c000: C:\WINDOWS\system32\ImgUtil.dll
(0000000069b10000 - 0000000069c52000: C:\Program Files\Common
Files\Microsoft Shared\OFFICE11\MSXML5.DLL
(000000006d170000 - 000000006d17b000: C:\WINDOWS\system32\dispex.dll
(000000006ff20000 - 000000006ff74000: C:\WINDOWS\system32\NETAPI32.dll
(00000000719d0000 - 0000000071a10000: C:\WINDOWS\system32\mswsock.dll
(0000000071a10000 - 0000000071a18000: C:\WINDOWS\System32\wshtcpip.dll
(0000000071a20000 - 0000000071a28000: C:\WINDOWS\system32\WS2HELP.dll
(0000000071a30000 - 0000000071a47000: C:\WINDOWS\system32\WS2_32.dll
(0000000071a50000 - 0000000071a5a000: C:\WINDOWS\system32\wsock32.dll
(0000000071aa0000 - 0000000071ab2000: C:\WINDOWS\system32\MPR.dll
(0000000071b80000 - 0000000071b93000: C:\WINDOWS\System32\SAMLIB.dll
(0000000071ba0000 - 0000000071bae000: C:\WINDOWS\System32\ntlanman.dll
(0000000071c10000 - 0000000071c17000: C:\WINDOWS\System32\NETRAP.dll
(0000000071c20000 - 0000000071c60000: C:\WINDOWS\System32\NETUI1.dll
(0000000071c60000 - 0000000071c77000: C:\WINDOWS\System32\NETUI0.dll
(0000000071cd0000 - 0000000071cec000: C:\WINDOWS\system32\ACTXPRXY.DLL
(0000000072240000 - 0000000072245000: C:\WINDOWS\system32\sensapi.dll
(0000000074640000 - 0000000074667000: C:\WINDOWS\system32\msls31.dll
(0000000074670000 - 000000007469a000: C:\WINDOWS\system32\msimtf.dll
(00000000746a0000 - 00000000746eb000: C:\WINDOWS\system32\MSCTF.dll
(0000000074900000 - 0000000074a30000: C:\WINDOWS\system32\msxml3.dll
(0000000075bf0000 - 0000000075c5e000: C:\WINDOWS\system32\jscript.dll
(0000000075d40000 - 0000000075dd1000: C:\WINDOWS\system32\mlang.dll
(0000000075e30000 - 0000000075ee0000: C:\WINDOWS\system32\SXS.DLL
(0000000075f00000 - 0000000075f07000: C:\WINDOWS\System32\drprov.dll
(0000000075f10000 - 0000000075f19000: C:\WINDOWS\System32\davclnt.dll
(0000000075f20000 - 000000007601d000: C:\WINDOWS\system32\BROWSEUI.dll
(0000000076260000 - 00000000762d1000: C:\WINDOWS\system32\mshtmled.dll
(0000000076330000 - 000000007634d000: C:\WINDOWS\system32\IMM32.DLL
(00000000765a0000 - 00000000765bd000: C:\WINDOWS\System32\CSCDLL.dll
(0000000076880000 - 0000000076904000: C:\WINDOWS\system32\CRYPTUI.dll
(0000000076970000 - 0000000076a24000: C:\WINDOWS\system32\USERENV.dll
(0000000076af0000 - 0000000076b1e000: C:\WINDOWS\system32\WINMM.dll
(0000000076bf0000 - 0000000076c1e000: C:\WINDOWS\system32\WINTRUST.dll
(0000000076c50000 - 0000000076c78000: C:\WINDOWS\system32\IMAGEHLP.dll
(0000000076e40000 - 0000000076e4e000: C:\WINDOWS\system32\rtutils.dll
(0000000076e50000 - 0000000076e62000: C:\WINDOWS\system32\rasman.dll
(0000000076e70000 - 0000000076e9f000: C:\WINDOWS\system32\TAPI32.dll
(0000000076ea0000 - 0000000076edc000: C:\WINDOWS\system32\RASAPI32.DLL
(0000000076ee0000 - 0000000076f07000: C:\WINDOWS\system32\DNSAPI.dll
(0000000076f20000 - 0000000076f4d000: C:\WINDOWS\system32\WLDAP32.dll
(0000000076f70000 - 0000000076f78000: C:\WINDOWS\System32\winrnr.dll
(0000000076f80000 - 0000000076f86000: C:\WINDOWS\system32\rasadhlp.dll
(0000000076f90000 - 000000007700f000: C:\WINDOWS\system32\CLBCATQ.DLL
(0000000077010000 - 00000000770dd000: C:\WINDOWS\system32\COMRes.dll
(00000000770e0000 - 000000007716c000: C:\WINDOWS\system32\OLEAUT32.dll
(0000000077170000 - 0000000077217000: C:\WINDOWS\system32\WININET.dll
(0000000077220000 - 00000000772be000: C:\WINDOWS\system32\urlmon.dll
(0000000077390000 - 0000000077492000:
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
(00000000774a0000 - 00000000775dd000: C:\WINDOWS\system32\ole32.dll
(0000000077720000 - 000000007788e000: C:\WINDOWS\system32\SHDOCVW.dll
(00000000778e0000 - 00000000779d7000: C:\WINDOWS\system32\SETUPAPI.dll
(00000000779e0000 - 0000000077a36000: C:\WINDOWS\System32\cscui.dll
(0000000077a40000 - 0000000077ad5000: C:\WINDOWS\system32\CRYPT32.dll
(0000000077ae0000 - 0000000077af2000: C:\WINDOWS\system32\MSASN1.dll
(0000000077b00000 - 0000000077b22000: C:\WINDOWS\system32\appHelp.dll
(0000000077bd0000 - 0000000077bd8000: C:\WINDOWS\system32\VERSION.dll
(0000000077be0000 - 0000000077c38000: C:\WINDOWS\system32\msvcrt.dll
(0000000077d10000 - 0000000077da0000: C:\WINDOWS\system32\USER32.dll
(0000000077da0000 - 0000000077e31000: C:\WINDOWS\system32\RPCRT4.dll
(0000000077e40000 - 0000000077e87000: C:\WINDOWS\system32\GDI32.dll
(0000000077e90000 - 0000000077f06000: C:\WINDOWS\system32\SHLWAPI.dll
(0000000077f10000 - 0000000077f21000: C:\WINDOWS\system32\Secur32.dll
(0000000077f40000 - 0000000077feb000: C:\WINDOWS\system32\ADVAPI32.dll
(000000007c340000 - 000000007c396000: C:\WINDOWS\system32\MSVCR71.dll
(000000007c800000 - 000000007c8fe000: C:\WINDOWS\system32\kernel32.dll
(000000007c900000 - 000000007c9b6000: C:\WINDOWS\system32\ntdll.dll
(000000007c9c0000 - 000000007d1e0000: C:\WINDOWS\system32\SHELL32.dll
(000000007d4b0000 - 000000007d796000: C:\WINDOWS\system32\mshtml.dll

*----> Statusdump voor subproces-ID 0xa64 <----*

eax=01c6840f ebx=00000000 ecx=01c68170 edx=0012df8c esi=00151f80
edi=00000000
eip=7c90eb94 esp=0012eb7c ebp=0012edd8 iopl=0 nv up ei pl nz na
pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000202

*** ERROR: Symbol file could not be found. Defaulted to export symbols
for C:\WINDOWS\system32\ntdll.dll -
functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for C:\WINDOWS\system32\BROWSEUI.dll -
WARNING: Stack unwind information not available. Following frames may
be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for C:\WINDOWS\system32\SHDOCVW.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for C:\Program Files\Internet Explorer\iexplore.exe -
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for C:\WINDOWS\system32\kernel32.dll -
ChildEBP RetAddr Args to Child
0012edd8 75f4eab5 00151d38 0012ee98 00151d38 ntdll!KiFastSystemCallRet
0012ee6c 75f4ed7d 00151d38 00151d38 00000000 BROWSEUI!Ordinal107+0xbff6
0012fef0 777a80aa 00151d38 00000000 00000000 BROWSEUI!Ordinal102+0x22c
0012ff10 00402372 001423ba 00000001 00090000 SHDOCVW!Ordinal211+0xc0ed
0012ff60 00402444 00400000 00000000 001423ba iexplore+0x2372
0012ffc0 7c816d4f 00090000 001515d2 7ffd5000 iexplore+0x2444
0012fff0 00000000 00402451 00000000 78746341
kernel32!RegisterWaitForInputIdle+0x49

*----> Raw Stack Dump <----*
000000000012eb7c 18 94 d1 77 99 e9 f4 75 - 98 ee 12 00 00 00 00 00
....w...u........
000000000012eb8c 00 00 00 00 d6 07 02 00 - 13 01 00 00 0f 47 00 00
..............G..
000000000012eb9c 00 00 00 00 99 b3 9c 00 - 94 01 00 00 71 02 00 00
.............q...
000000000012ebac 01 00 00 00 01 44 00 90 - 80 1f 15 00 00 00 00 00
......D..........
000000000012ebbc a4 07 03 00 b0 3c 14 00 - 01 00 00 00 00 00 00 00
......<..........
000000000012ebcc 4d 00 69 00 63 00 72 00 - 6f 00 73 00 6f 00 66 00
M.i.c.r.o.s.o.f.
000000000012ebdc 74 00 20 00 49 00 6e 00 - 74 00 65 00 72 00 6e 00 t.
..I.n.t.e.r.n.
000000000012ebec 65 00 74 00 20 00 45 00 - 78 00 70 00 6c 00 6f 00
e.t. .E.x.p.l.o.
000000000012ebfc 72 00 65 00 72 00 00 00 - 37 42 2d 31 00 00 00 00
r.e.r...7B-1....
000000000012ec0c 39 44 31 46 2d 30 30 30 - 90 29 15 00 35 43 41 35
9D1F-000.)..5CA5
000000000012ec1c 37 7d 00 00 0c 00 00 00 - dd 43 e9 77 48 53 9c 7c
7}.......C.wHS.|
000000000012ec2c 78 01 14 00 00 00 00 00 - 08 00 00 00 00 00 00 00
x...............
000000000012ec3c 70 23 15 00 08 00 00 00 - 70 1e 15 00 c0 e4 97 7c
p#......p......|
000000000012ec4c 78 23 15 00 78 01 14 00 - a1 43 91 7c 40 1e 15 00
x#..x....C.|@...
000000000012ec5c 08 00 0a 00 70 1e 15 00 - 00 00 14 00 98 29 15 00
.....p........)..
000000000012ec6c 00 00 00 00 68 1e 15 00 - a0 6e 00 00 78 01 14 00
.....h....n..x...
000000000012ec7c b9 43 e9 77 c0 ed 12 00 - d0 43 e9 77 98 89 9e 7c
..C.w.....C.w...|
000000000012ec8c 5a ed 12 00 d0 78 9e 7c - ae 00 00 00 e8 ec 12 00
Z....x.|........
000000000012ec9c d3 9b 91 7c 5a ed 12 00 - 35 01 00 00 00 00 9c 7c
....|Z...5......|
000000000012ecac ce 00 00 00 98 89 9e 7c - 00 00 00 00 84 00 00 00
........|........

*----> Statusdump voor subproces-ID 0x9a8 <----*

eax=0136fba0 ebx=00000000 ecx=00000001 edx=7c90eb94 esi=00140608
edi=00000000
eip=7c90eb94 esp=0136f908 ebp=0136f990 iopl=0 nv up ei pl zr na
po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for C:\WINDOWS\system32\SHLWAPI.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for C:\WINDOWS\system32\WININET.dll -
ChildEBP RetAddr Args to Child
0136f990 7c90104b 00140608 7c911320 00140608 ntdll!KiFastSystemCallRet
0136fbc4 7c92781a 00140000 00000008 00000010
ntdll!RtlEnterCriticalSection+0x46
0136fbdc 7c9277db 77e9947b 00184930 00000000
ntdll!RtlQueueWorkItem+0x142
0136fc08 7c81e10e 77e9947b 00184930 00000000
ntdll!RtlQueueWorkItem+0x103
0136fc1c 77e99550 77e9947b 00184930 00000000
kernel32!QueueUserWorkItem+0x14
0136fc3c 771972eb 77197309 001b2280 00000000 SHLWAPI!Ordinal260+0xa1
0136ffac 77199283 0136ffec 7c80b50b 00174aa0
WININET!InternetGetConnectedStateExA+0xa9
0136ffb4 7c80b50b 00174aa0 71a31404 0000005d
WININET!InternetSetStatusCallback+0x1d7
0136ffec 00000000 77199276 00174aa0 00000000
kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
000000000136f908 c0 e9 90 7c 1b 90 91 7c - a8 04 00 00 00 00 00 00
....|...|........
000000000136f918 00 00 00 00 03 00 00 00 - 00 00 00 00 00 00 14 00
.................
000000000136f928 00 00 00 00 54 f9 36 01 - 47 20 01 00 6c f9 36 01
.....T.6.G ..l.6.
000000000136f938 f8 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
000000000136f948 f0 25 21 01 8d 4d 9d 71 - ec f9 36 01 00 00 00 00
..%!..M.q..6.....
000000000136f958 00 00 00 00 f8 00 00 00 - 38 4a 18 00 98 f9 36 01
.........8J....6.
000000000136f968 00 00 14 00 32 07 91 7c - 03 00 00 00 18 07 14 00
.....2..|........
000000000136f978 00 00 00 00 00 00 00 00 - 70 f9 36 01 74 f9 36 01
.........p.6.t.6.
000000000136f988 00 00 00 00 a8 04 00 00 - c4 fb 36 01 4b 10 90 7c
...........6.K..|
000000000136f998 08 06 14 00 20 13 91 7c - 08 06 14 00 09 00 00 00
..... ..|........
000000000136f9a8 e8 03 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
000000000136f9b8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
000000000136f9c8 00 00 00 00 60 2b 21 01 - 00 00 00 00 68 00 00 00
.....`+!.....h...
000000000136f9d8 e6 1b 80 7c 02 00 04 cf - 7f 00 00 01 00 00 00 00
....|............
000000000136f9e8 00 00 00 00 0c 00 00 00 - 7f 00 00 01 00 00 00 00
.................
000000000136f9f8 f8 04 21 01 02 00 00 00 - 68 2b 21 01 00 00 00 00
...!.....h+!.....
000000000136fa08 0e 00 00 00 90 01 14 00 - 90 01 14 00 08 00 00 00
.................
000000000136fa18 00 00 00 00 50 05 21 01 - 5c 00 49 00 6e 00 74 00
.....P.!.\.I.n.t.
000000000136fa28 65 00 72 00 00 01 00 00 - 00 00 a2 02 44 fa 36 01
e.r.........D.6.
000000000136fa38 00 00 00 00 c8 05 91 7c - 08 2b 21 01 10 fb 36 01
........|.+!...6.

*----> Statusdump voor subproces-ID 0xa74 <----*

eax=000000c0 ebx=00000000 ecx=7c800000 edx=00000000 esi=00128b44
edi=02080000
eip=7c90eb94 esp=0146ff9c ebp=0146ffb4 iopl=0 nv up ei pl zr na
po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
0146ffb4 7c80b50b 00000000 02080000 00128b44 ntdll!KiFastSystemCallRet
0146ffec 00000000 7c92798d 00000000 00000000
kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
000000000146ff9c 5c d8 90 7c d4 79 92 7c - 01 00 00 00 ac ff 46 01
\..|.y.|......F.
000000000146ffac 00 00 00 00 00 00 00 80 - ec ff 46 01 0b b5 80 7c
...........F....|
000000000146ffbc 00 00 00 00 00 00 08 02 - 44 8b 12 00 00 00 00 00
.........D.......
000000000146ffcc 00 d0 fd 7f 00 e6 5b 86 - c0 ff 46 01 90 6a ea 85
.......[...F..j..
000000000146ffdc ff ff ff ff f3 99 83 7c - 18 b5 80 7c 00 00 00 00
........|...|....
000000000146ffec 00 00 00 00 00 00 00 00 - 8d 79 92 7c 00 00 00 00
..........y.|....
000000000146fffc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
000000000147000c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
000000000147001c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
000000000147002c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
000000000147003c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
000000000147004c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
000000000147005c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
000000000147006c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
000000000147007c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
000000000147008c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
000000000147009c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
00000000014700ac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
00000000014700bc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
00000000014700cc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................

*----> Statusdump voor subproces-ID 0x864 <----*

eax=00140101 ebx=00140000 ecx=0022aa58 edx=2f616c6c esi=0022aa50
edi=697a6f4d
eip=7c911f6c esp=0156fa8c ebp=0156fcac iopl=0 nv up ei pl nz na
po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000206

functie: ntdll!RtlInitializeCriticalSection
7c911f4b 0483 add al,0x83
7c911f4d ee out dx,al
7c911f4e 088975c88a46 or [ecx+0x468ac875],cl
7c911f54 058845e38d add eax,0x8de34588
7c911f59 4e dec esi
7c911f5a 088b3989bd48 or [ebx+0x48bd8939],cl
7c911f60 feff ??? bh
7c911f62 ff8b560c8995 dec dword ptr [ebx+0x95890c56]
7c911f68 78ff js
ntdll!RtlInitializeCriticalSection+0x43c (7c911f69)
7c911f6a ffff ???
Fout ->7c911f6c 8b12 mov edx,[edx]
ds:0023:2f616c6c=????????
7c911f6e 3b5704 cmp edx,[edi+0x4]
7c911f71 0f85f3230200 jne
ntdll!RtlInitializeContext+0x2e9 (7c93436a)
7c911f77 3bd1 cmp edx,ecx
7c911f79 0f85eb230200 jne
ntdll!RtlInitializeContext+0x2e9 (7c93436a)
7c911f7f 8b8d78ffffff mov ecx,[ebp-0x88]
7c911f85 8939 mov [ecx],edi
7c911f87 894f04 mov [edi+0x4],ecx
7c911f8a 3bf9 cmp edi,ecx
7c911f8c 752f jnz
ntdll!RtlInitializeCriticalSection+0x490 (7c911fbd)
7c911f8e 0fb70e movzx ecx,word ptr [esi]

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
0156fcac 7c809a0f 00140000 00140000 00000050
ntdll!RtlInitializeCriticalSection+0x43f
0156fcf8 77171718 00000000 00000050 0156fd30 kernel32!LocalAlloc+0x52
0156fd08 771803ea 00000050 02982850 00000000 WININET+0x1718
0156fd30 771803ad 02982850 771f9080 02982850 WININET!Ordinal101+0x3a00
0156fd4c 7718029c 02982850 00178460 001783d8 WININET!Ordinal101+0x39c3
0156fd70 7717fdc6 02982850 000003e5 02982854 WININET!Ordinal101+0x38b2
0156fd84 77180203 02982850 029827a8 029c73f8 WININET!Ordinal101+0x33dc
0156fda0 7717fecb 029827a8 001783d8 0156fe10 WININET!Ordinal101+0x3819
0156fe64 7717ce3d 00000000 00000000 029c73f8 WININET!Ordinal101+0x34e1
0156fe84 7717cc35 00000000 0017ab88 029827a8 WININET!Ordinal101+0x453
0156fe98 7717cb2c 029827a8 0017ab88 029827a8 WININET!Ordinal101+0x24b
0156feb0 7719736a 0017ab88 0156fee8 0156fedc WININET!Ordinal101+0x142
0156fee0 77e99498 00000000 001921c0 77e9947b
WININET!InternetGetConnectedStateExA+0x128
0156fef8 7c927545 001921c0 7c97c3a0 02984368 SHLWAPI!Ordinal120+0xbf
0156ff40 7c927583 77e9947b 001921c0 00000000
ntdll!RtlUpcaseUnicodeString+0x159
0156ff60 7c927645 00000000 001921c0 02984368
ntdll!RtlUpcaseUnicodeString+0x197
0156ff74 7c92761c 7c927569 00000000 001921c0
ntdll!RtlUpcaseUnicodeString+0x259
0156ffb4 7c80b50b 00000000 00000000 00000000
ntdll!RtlUpcaseUnicodeString+0x230
0156ffec 00000000 7c910760 00000000 00000000
kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
000000000156fa8c 00 00 00 00 90 7a 19 00 - 50 28 98 02 20 bf 14 00
......z..P(.. ...
000000000156fa9c 00 00 00 00 0e 00 0f 00 - 70 74 17 77 02 00 00 00
.........pt.w....
000000000156faac 00 00 00 00 f4 18 22 77 - 01 00 00 00 00 00 00 00
......."w........
000000000156fabc 88 c9 17 77 f8 9d 1f 77 - 40 f9 15 00 01 00 00 00
....w...w@.......
000000000156facc 01 00 00 00 9e c9 17 77 - 04 00 00 00 00 00 00 00
........w........
000000000156fadc 04 00 00 00 14 fb 56 01 - 00 00 14 00 32 07 91 7c
.......V.....2..|
000000000156faec 0a 00 00 00 68 08 14 00 - 4d 6f 7a 69 f8 da 1b 00
.....h...Mozi....
000000000156fafc ec fa 56 01 10 fd 56 01 - 30 fd 56 01 18 ee 90 7c
...V...V.0.V....|
000000000156fb0c 38 07 91 7c ff ff ff ff - 32 07 91 7c 00 00 a2 02
8..|....2..|....
000000000156fb1c eb 06 91 7c 00 00 00 00 - 10 e7 99 02 40 00 00 00
....|........@...
000000000156fb2c d6 74 17 77 70 74 17 77 - 54 fb 56 01 00 00 00 00
..t.wpt.wT.V.....
000000000156fb3c 00 00 00 00 ff 74 17 77 - 70 fd 56 01 80 fe 56 01
......t.wp.V...V.
000000000156fb4c 38 07 91 7c 01 00 00 00 - 00 00 00 00 ab 06 91 7c
8..|...........|
000000000156fb5c eb 06 91 7c 12 9f 80 7c - b3 9e 80 7c 48 40 99 02
....|...|...|H@..
000000000156fb6c 01 00 00 00 91 a3 51 7d - fc 9c bd 01 00 00 00 00
.......Q}........
000000000156fb7c 2c 9d bd 01 85 6d 59 7d - 48 40 99 02 01 00 00 00
,....mY}H@......
000000000156fb8c a0 fb 56 01 89 e0 22 77 - 2c 9d bd 01 20 00 00 00
...V..."w,... ...
000000000156fb9c 00 00 00 00 c8 fb 56 01 - 59 e0 22 77 c8 fb 56 01
.......V.Y."w..V.
000000000156fbac 62 e0 22 77 00 00 00 00 - 00 00 00 00 48 40 99 02
b."w........H@..
000000000156fbbc 00 00 00 00 08 41 99 02 - 00 00 00 00 e4 fb 56 01
......A........V.

*----> Statusdump voor subproces-ID 0x2cc <----*

eax=77da6bf0 ebx=00000000 ecx=00000009 edx=7c910732 esi=0014b438
edi=00000100
eip=7c90eb94 esp=0166fe1c ebp=0166ff80 iopl=0 nv up ei pl zr na
po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for C:\WINDOWS\system32\RPCRT4.dll -
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
0166ff80 77da6c22 0166ffa8 77da6a3b 0014b438 ntdll!KiFastSystemCallRet
0166ff88 77da6a3b 0014b438 00000000 0012d7dc
RPCRT4!I_RpcBCacheFree+0x5ea
0166ffa8 77da6c0a 00159ac8 0166ffec 7c80b50b
RPCRT4!I_RpcBCacheFree+0x403
0166ffb4 7c80b50b 00187798 00000000 0012d7dc
RPCRT4!I_RpcBCacheFree+0x5d2
0166ffec 00000000 77da6bf0 00187798 00000000
kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
000000000166fe1c 99 e3 90 7c 03 67 da 77 - e8 02 00 00 70 ff 66 01
....|.g.w....p.f.
000000000166fe2c 00 00 00 00 30 9c 18 00 - 54 ff 66 01 80 a9 5b 86
.....0...T.f...[.
000000000166fe3c 38 cb 7a aa 38 cb 7a aa - 00 00 00 00 f1 47 53 80
8.z.8.z......GS.
000000000166fe4c b0 c8 28 e3 02 c8 28 e3 - 00 00 5b 86 00 00 00 00
...(...(...[.....
000000000166fe5c 64 aa 5b 86 00 c8 28 e3 - cc cb 7a aa 5d ba 5b 80
d.[...(...z.].[.
000000000166fe6c 08 80 2a 86 40 00 00 00 - 80 a9 5b 86 7b ef 4f 80
...*.@.....[.{.O.
000000000166fe7c 01 00 00 00 01 00 00 00 - 06 00 00 00 01 00 00 00
.................
000000000166fe8c 84 04 00 00 9c cb 7a aa - 8c cb 7a aa f8 00 00 00
.......z...z.....
000000000166fe9c 06 00 00 00 00 00 00 00 - 80 46 47 e2 58 97 90 e1
..........FG.X...
000000000166feac 08 f6 cd 85 00 00 00 00 - c8 95 13 e1 c4 cb 7a aa
...............z.
000000000166febc a9 be 60 80 c8 95 13 e1 - a4 02 00 00 08 80 2a 86
...`...........*.
000000000166fecc c8 95 13 e1 ac 80 2a 86 - a4 02 00 00 00 00 00 00
.......*.........
000000000166fedc 48 35 1d e3 e0 cb 7a aa - 13 c5 60 80 c8 95 13 e1
H5....z...`.....
000000000166feec 1f 00 00 00 f0 15 e5 85 - 40 f5 df ff 73 4b 54 80
[email protected].
000000000166fefc ff ff ff ff 46 02 00 00 - 8b 49 54 80 28 cc 7a aa
.....F....IT.(.z.
000000000166ff0c f0 15 e5 85 20 f1 df ff - 8c 17 e5 85 39 2b 50 80
..... .......9+P.
000000000166ff1c 60 16 e5 85 f0 15 e5 85 - 6c ad 4f 80 5c 17 e5 85
`.......l.O.\...
000000000166ff2c f0 15 e5 85 80 ff 66 01 - 99 66 da 77 4c ff 66 01
.......f..f.wL.f.
000000000166ff3c a9 66 da 77 ed 10 90 7c - b0 70 18 00 98 77 18 00
..f.w...|.p...w..
000000000166ff4c 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff
.../M.....]......

*----> Statusdump voor subproces-ID 0x404 <----*

eax=774be429 ebx=00007530 ecx=7ffd5000 edx=00000000 esi=00000000
edi=0176ff50
eip=7c90eb94 esp=0176ff20 ebp=0176ff78 iopl=0 nv up ei pl nz na
po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000206

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for C:\WINDOWS\system32\ole32.dll -
ChildEBP RetAddr Args to Child
0176ff78 7c802451 0000ea60 00000000 0176ffb4 ntdll!KiFastSystemCallRet
0176ff88 774be31d 0000ea60 00189d38 774be3dc kernel32!Sleep+0xf
0176ffb4 7c80b50b 00189d38 7c910945 7c91094e
ole32!StringFromGUID2+0x51b
0176ffec 00000000 774be429 00189d38 00000000
kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
000000000176ff20 5c d8 90 7c ed 23 80 7c - 00 00 00 00 50 ff 76 01
\..|.#.|....P.v.
000000000176ff30 50 25 80 7c f8 6d 5c 77 - 30 75 00 00 14 00 00 00
P%.|.m\w0u......
000000000176ff40 01 00 00 00 00 00 00 00 - 00 00 00 00 10 00 00 00
.................
000000000176ff50 00 ba 3c dc ff ff ff ff - dc fe 76 01 50 ff 76 01
...<.......v.P.v.
000000000176ff60 30 ff 76 01 dc fe 76 01 - dc ff 76 01 f3 99 83 7c
0.v...v...v....|
000000000176ff70 58 24 80 7c 00 00 00 00 - 88 ff 76 01 51 24 80 7c
X$.|......v.Q$.|
000000000176ff80 60 ea 00 00 00 00 00 00 - b4 ff 76 01 1d e3 4b 77
`.........v...Kw
000000000176ff90 60 ea 00 00 38 9d 18 00 - dc e3 4b 77 00 00 00 00
`...8.....Kw....
000000000176ffa0 45 09 91 7c 38 9d 18 00 - 00 00 4a 77 44 e4 4b 77
E..|8.....JwD.Kw
000000000176ffb0 4e 09 91 7c ec ff 76 01 - 0b b5 80 7c 38 9d 18 00
N..|..v....|8...
000000000176ffc0 45 09 91 7c 4e 09 91 7c - 38 9d 18 00 00 a0 fd 7f
E..|N..|8.......
000000000176ffd0 00 c6 5b 86 c0 ff 76 01 - 68 86 1f 86 ff ff ff ff
...[...v.h.......
000000000176ffe0 f3 99 83 7c 18 b5 80 7c - 00 00 00 00 00 00 00 00
....|...|........
000000000176fff0 00 00 00 00 29 e4 4b 77 - 38 9d 18 00 00 00 00 00
.....).Kw8.......
0000000001770000 02 00 00 00 28 00 00 00 - 5b 59 00 00 70 5f 01 00
.....(...[Y..p_..
0000000001770010 01 00 00 00 01 00 00 00 - 70 5f 01 00 00 00 00 00
.........p_......
0000000001770020 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000001770030 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000001770040 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000001770050 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................

*----> Statusdump voor subproces-ID 0x988 <----*

eax=000000c4 ebx=00000000 ecx=0018c3d0 edx=7ffe0300 esi=0014b438
edi=00000100
eip=7c90eb94 esp=0188fe1c ebp=0188ff80 iopl=0 nv up ei pl zr na
po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
0188ff80 77da6c22 0188ffa8 77da6a3b 0014b438 ntdll!KiFastSystemCallRet
0188ff88 77da6a3b 0014b438 00bd0360 00e40178
RPCRT4!I_RpcBCacheFree+0x5ea
0188ffa8 77da6c0a 00159ac8 0188ffec 7c80b50b
RPCRT4!I_RpcBCacheFree+0x403
0188ffb4 7c80b50b 0018c3d0 00bd0360 00e40178
RPCRT4!I_RpcBCacheFree+0x5d2
0188ffec 00000000 77da6bf0 0018c3d0 00000000
kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
000000000188fe1c 99 e3 90 7c 03 67 da 77 - e8 02 00 00 70 ff 88 01
....|.g.w....p...
000000000188fe2c 00 00 00 00 40 66 98 02 - 54 ff 88 01 28 78 55 e2
[email protected]...(xU.
000000000188fe3c a0 b5 0c e1 b8 db 2b aa - 00 00 00 00 ec db 2b aa
.......+.......+.
000000000188fe4c 28 78 1d e2 02 db 2b aa - 00 00 5e 80 68 1e 00 e1
(x....+...^.h...
000000000188fe5c 50 34 24 e3 ec db 2b aa - 48 34 24 e3 00 00 00 02
P4$...+.H4$.....
000000000188fe6c 13 00 00 00 5b e0 5e 80 - 0e 00 00 00 0c 00 00 00
.....[.^.........
000000000188fe7c 50 34 24 e3 00 00 00 00 - 00 00 00 00 30 a0 46 e3
P4$.........0.F.
000000000188fe8c 06 02 00 00 7b ef 4f 80 - 02 00 00 00 02 00 00 00
.....{.O.........
000000000188fe9c d0 03 e8 85 37 27 50 80 - d0 03 e8 85 18 8c 29 86
.....7'P.......).
000000000188feac 40 85 81 f7 4c 4b 54 80 - ff ff ff ff 02 02 00 00
@...LKT.........
000000000188febc 47 4a 54 80 c4 db 2b aa - f5 59 6e 80 c8 0f d2 85
GJT...+..Yn.....
000000000188fecc 63 5f 6e 80 00 00 00 00 - 54 dc 2b aa 06 51 6e 80
c_n.....T.+..Qn.
000000000188fedc 00 00 00 00 43 5d 6e 80 - 54 dc 2b aa f5 59 6e 80
.....C]n.T.+..Yn.
000000000188feec 00 0d db ba 48 dc 2b aa - d8 89 07 e1 00 00 00 00
.....H.+.........
000000000188fefc 68 dc 2b aa 2c 34 24 e3 - 01 00 00 00 28 dc 2b 01
h.+.,4$.....(.+.
000000000188ff0c 00 00 00 00 00 00 00 00 - 00 00 00 00 38 f5 df ff
.............8...
000000000188ff1c a4 48 54 80 00 a0 e3 85 - a8 ae 4f 80 8c a1 e3 85
..HT.......O.....
000000000188ff2c 20 a0 e3 85 80 ff 88 01 - 99 66 da 77 4c ff 88 01
.........f.wL...
000000000188ff3c a9 66 da 77 ed 10 90 7c - a0 07 17 00 d0 c3 18 00
..f.w...|........
000000000188ff4c 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff
.../M.....]......

*----> Statusdump voor subproces-ID 0xa60 <----*

eax=0198fc44 ebx=0198fee0 ecx=00140718 edx=00000010 esi=00000000
edi=7ffd5000
eip=7c90eb94 esp=0198feb8 ebp=0198ff54 iopl=0 nv up ei pl zr na
po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
0198ff54 7c809c86 00000002 0198ffa8 00000000 ntdll!KiFastSystemCallRet
0198ff70 771718fe 00000002 0198ffa8 00000000
kernel32!WaitForMultipleObjects+0x18
0198ffb0 7718da2d 7c80b50b 00197a90 7c9106eb WININET+0x18fe
0198ffec 00000000 7718da22 00197a90 00000000
WININET!InternetLockRequestFile+0x13d9

*----> Raw Stack Dump <----*
000000000198feb8 ab e9 90 7c f2 94 80 7c - 02 00 00 00 e0 fe 98 01
....|...|........
000000000198fec8 01 00 00 00 00 00 00 00 - 14 ff 98 01 eb 06 91 7c
................|
000000000198fed8 90 7a 19 00 00 7a 19 00 - 50 03 00 00 4c 03 00 00
..z...z..P...L...
000000000198fee8 64 95 e9 77 30 d4 ef 77 - e5 03 00 00 7c 44 22 00
d..w0..w....|D".
000000000198fef8 40 ff 98 01 eb 72 19 77 - 14 00 00 00 01 00 00 00
@....r.w........
000000000198ff08 00 00 00 00 00 00 00 00 - 10 00 00 00 00 5d 1e ee
..............]..
000000000198ff18 ff ff ff ff a0 4a 17 00 - 00 50 fd 7f 00 80 fd 7f
......J...P......
000000000198ff28 ac 4a 17 00 14 ff 98 01 - e0 fe 98 01 ac 4a 17 00
..J...........J..
000000000198ff38 02 00 00 00 d4 fe 98 01 - 5c ff 98 01 dc ff 98 01
.........\.......
000000000198ff48 f3 99 83 7c 90 95 80 7c - 00 00 00 00 70 ff 98 01
....|...|....p...
000000000198ff58 86 9c 80 7c 02 00 00 00 - a8 ff 98 01 00 00 00 00
....|............
000000000198ff68 30 75 00 00 00 00 00 00 - b0 ff 98 01 fe 18 17 77
0u.............w
000000000198ff78 02 00 00 00 a8 ff 98 01 - 00 00 00 00 30 75 00 00
.............0u..
000000000198ff88 24 fc 56 01 38 53 1d 01 - 03 01 00 00 00 00 00 00
$.V.8S..........
000000000198ff98 00 00 00 00 00 00 00 00 - 4c 03 00 00 7c ee 96 00
.........L...|...
000000000198ffa8 50 03 00 00 4c 03 00 00 - ec ff 98 01 2d da 18 77
P...L.......-..w
000000000198ffb8 0b b5 80 7c 90 7a 19 00 - eb 06 91 7c 24 fc 56 01
....|.z.....|$.V.
000000000198ffc8 90 7a 19 00 00 80 fd 7f - 00 c6 5b 86 c0 ff 98 01
..z........[.....
000000000198ffd8 68 86 1f 86 ff ff ff ff - f3 99 83 7c 18 b5 80 7c
h..........|...|
000000000198ffe8 00 00 00 00 00 00 00 00 - 00 00 00 00 22 da 18 77
............."..w

*----> Statusdump voor subproces-ID 0x914 <----*

eax=719dd5af ebx=c0000000 ecx=7c913288 edx=ffffffff esi=00000000
edi=71a07558
eip=7c90eb94 esp=01b6ff7c ebp=01b6ffb4 iopl=0 nv up ei pl nz na
pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000202

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
01b6ffb4 7c80b50b 719dd8ec 0156f910 7c90ee18 ntdll!KiFastSystemCallRet
01b6ffec 00000000 719dd5af 00196618 00000000
kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
0000000001b6ff7c 1b e3 90 7c 09 d6 9d 71 - a8 03 00 00 bc ff b6 01
....|...q........
0000000001b6ff8c b0 ff b6 01 a4 ff b6 01 - 50 d6 9d 71 10 f9 56 01
.........P..q..V.
0000000001b6ff9c 18 ee 90 7c 18 66 19 00 - 00 00 00 00 00 00 00 00
....|.f..........
0000000001b6ffac 00 00 9d 71 e8 29 21 01 - ec ff b6 01 0b b5 80 7c
....q.)!........|
0000000001b6ffbc ec d8 9d 71 10 f9 56 01 - 18 ee 90 7c 18 66 19 00
....q..V....|.f..
0000000001b6ffcc 00 70 fd 7f 00 c6 5b 86 - c0 ff b6 01 78 84 eb 85
..p....[.....x...
0000000001b6ffdc ff ff ff ff f3 99 83 7c - 18 b5 80 7c 00 00 00 00
........|...|....
0000000001b6ffec 00 00 00 00 00 00 00 00 - af d5 9d 71 18 66 19 00
............q.f..
0000000001b6fffc 00 00 00 00 bc 00 b7 01 - 06 00 00 00 07 00 00 00
.................
0000000001b7000c 00 00 00 0a 00 00 00 00 - 00 00 00 00 00 06 00 00
.................
0000000001b7001c 00 00 00 06 00 00 00 00 - 00 1f 00 00 00 00 00 00
.................
0000000001b7002c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000001b7003c 00 00 00 00 00 00 00 00 - 01 01 0c 00 00 00 00 00
.................
0000000001b7004c 00 00 00 00 00 00 01 0a - 00 00 00 00 00 00 00 00
.................
0000000001b7005c 00 01 00 00 00 00 01 01 - 02 00 01 00 00 00 00 00
.................
0000000001b7006c 00 00 00 00 00 00 00 00 - 03 00 00 00 00 00 00 00
.................
0000000001b7007c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 10 00
.................
0000000001b7008c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 05 00
.................
0000000001b7009c 00 00 00 01 05 00 00 00 - 00 00 00 01 00 00 00 00
.................
0000000001b700ac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................

*----> Statusdump voor subproces-ID 0xa50 <----*

eax=0207fee0 ebx=00000000 ecx=01c41b40 edx=0207ff68 esi=00140608
edi=00000000
eip=7c90eb94 esp=0207da68 ebp=0207daf0 iopl=0 nv up ei pl zr na
po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for C:\WINDOWS\system32\urlmon.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for C:\WINDOWS\system32\mshtml.dll -
ChildEBP RetAddr Args to Child
0207daf0 7c90104b 00140608 7c911320 00140608 ntdll!KiFastSystemCallRet
0207dd24 774bd023 00140000 00000000 0000004c
ntdll!RtlEnterCriticalSection+0x46
0207dd38 774bd05b 775c6034 0000004c 0207dd54 ole32!IsValidIid+0xfa
0207dd48 77222819 0000004c 0207dd70 77223545 ole32!CoTaskMemAlloc+0x13
0207dd54 77223545 0000004c 02a12964 00000000
urlmon!CoInternetIsFeatureEnabled+0x69
0207dd70 772230ee 00000000 77223464 0207ddb0
urlmon!CoInternetCreateSecurityManager+0x46e
0207dd88 7d58474e 00000000 0207ddb0 00000000
urlmon!CoInternetCreateSecurityManager+0x17
0207ddb4 7d5274ad 0207de50 01bd91a0 00000001 mshtml+0xd474e
0207ddd8 7d51bce3 01bd92e0 00000001 00000000 mshtml+0x774ad
0207ddfc 7d5266e4 00000001 0207de50 00000000 mshtml+0x6bce3
0207de18 7d58f351 01bd91a0 00000001 0207de50 mshtml+0x766e4
0207fea0 7d575dd9 00000001 029f2cfc 0000001d mshtml+0xdf351
00000000 00000000 00000000 00000000 00000000 mshtml+0xc5dd9

*----> Raw Stack Dump <----*
000000000207da68 c0 e9 90 7c 1b 90 91 7c - a8 04 00 00 00 00 00 00
....|...|........
000000000207da78 00 00 00 00 0b 00 00 00 - 00 00 00 00 00 00 14 00
.................
000000000207da88 00 2b ae 00 c0 88 ae 00 - 01 00 00 00 c0 01 16 00
..+..............
000000000207da98 00 00 00 00 7c da 01 00 - 11 00 00 00 00 da 07 02
.....|...........
000000000207daa8 be 63 1f 77 f4 da 07 02 - 18 ee 90 7c 70 05 91 7c
..c.w.......|p..|
000000000207dab8 ff ff ff ff 6d 05 91 7c - 88 99 80 7c f8 da 07 02
.....m..|...|....
000000000207dac8 00 00 14 00 32 07 91 7c - 0b 00 00 00 98 08 14 00
.....2..|........
000000000207dad8 00 00 00 00 00 00 00 00 - d0 da 07 02 80 df 21 00
...............!.
000000000207dae8 00 00 00 00 a8 04 00 00 - 24 dd 07 02 4b 10 90 7c
.........$...K..|
000000000207daf8 08 06 14 00 20 13 91 7c - 08 06 14 00 64 29 a1 02
..... ..|....d)..
000000000207db08 00 00 00 00 4c 29 22 77 - 00 00 00 00 d4 91 bd 01
.....L)"w........
000000000207db18 a0 91 bd 01 7e 00 00 00 - 3e 00 00 00 80 df 21 00
.....~...>.....!.
000000000207db28 01 00 00 00 00 00 00 00 - 5c dd 07 02 2f 4c 5e 7d
.........\.../L^}
000000000207db38 55 09 00 00 dc d6 07 02 - d4 91 bd 01 dc ff 07 02
U...............
000000000207db48 f3 99 83 7c 30 e8 80 7c - ff ff ff ff 2b e8 80 7c
....|0..|....+..|
000000000207db58 5b e6 80 7c 01 00 00 00 - 02 00 00 00 9c 47 58 7d
[..|.........GX}
000000000207db68 74 db 07 02 90 dd 07 02 - 1c b1 ea 77 24 b1 ea 77
t..........w$..w
000000000207db78 78 00 74 00 72 00 61 00 - 6e 00 65 00 74 00 32 00
x.t.r.a.n.e.t.2.
000000000207db88 61 00 2f 00 53 00 69 00 - 00 00 a2 02 73 00 2f 00
a./.S.i.....s./.
000000000207db98 42 00 69 00 7a 00 69 00 - 2f 00 69 00 6d 00 61 00
B.i.z.i./.i.m.a.

*----> Statusdump voor subproces-ID 0x804 <----*

eax=00000001 ebx=7c901005 ecx=029246a8 edx=000046ad esi=00000454
edi=00000000
eip=7c90eb94 esp=0218ff14 ebp=0218ff78 iopl=0 nv up ei ng nz ac
pe cy
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000293

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
0218ff78 7c802542 00000454 000927c0 00000000 ntdll!KiFastSystemCallRet
0218ff8c 7d5336af 00000454 000927c0 77291808
kernel32!WaitForSingleObject+0x12
0218ffb4 7c80b50b 01b804c0 77291808 00000004 mshtml+0x836af
0218ffec 00000000 7d596b9f 01b804c0 00000000
kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
000000000218ff14 c0 e9 90 7c db 25 80 7c - 54 04 00 00 00 00 00 00
....|.%.|T.......
000000000218ff24 48 ff 18 02 00 00 00 00 - c0 04 b8 01 05 10 90 7c
H..............|
000000000218ff34 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00
.................
000000000218ff44 10 00 00 00 00 44 5f 9a - fe ff ff ff 00 50 fd 7f
......D_......P..
000000000218ff54 00 40 fd 7f 48 ff 18 02 - 6c ff 18 02 28 ff 18 02
[email protected]...(...
000000000218ff64 40 57 23 00 dc ff 18 02 - f3 99 83 7c 08 26 80 7c
@W#........|.&.|
000000000218ff74 00 00 00 00 8c ff 18 02 - 42 25 80 7c 54 04 00 00
.........B%.|T...
000000000218ff84 c0 27 09 00 00 00 00 00 - b4 ff 18 02 af 36 53 7d
..'...........6S}
000000000218ff94 54 04 00 00 c0 27 09 00 - 08 18 29 77 c0 04 b8 01
T....'....)w....
000000000218ffa4 c0 04 b8 01 da 6b 59 7d - 04 00 00 00 ac 6b 59 7d
......kY}.....kY}
000000000218ffb4 ec ff 18 02 0b b5 80 7c - c0 04 b8 01 08 18 29 77
........|......)w
000000000218ffc4 04 00 00 00 c0 04 b8 01 - 00 40 fd 7f 00 c6 5b 86
..........@....[.
000000000218ffd4 c0 ff 18 02 78 84 eb 85 - ff ff ff ff f3 99 83 7c
.....x..........|
000000000218ffe4 18 b5 80 7c 00 00 00 00 - 00 00 00 00 00 00 00 00
....|............
000000000218fff4 9f 6b 59 7d c0 04 b8 01 - 00 00 00 00 00 00 00 00
..kY}............
0000000002190004 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002190014 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002190024 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002190034 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002190044 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................

*----> Statusdump voor subproces-ID 0x9fc <----*

eax=77f69981 ebx=025cfed0 ecx=00000006 edx=00000000 esi=00000000
edi=7ffd5000
eip=7c90eb94 esp=025cfea8 ebp=025cff44 iopl=0 nv up ei pl zr na
po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for C:\WINDOWS\system32\ADVAPI32.dll -
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
025cff44 77f69b26 00000002 025cff6c 00000000 ntdll!KiFastSystemCallRet
025cffb4 7c80b50b 00000000 7c9140bb 00000000
ADVAPI32!RegDeleteKeyW+0x2a2
025cffec 00000000 77f69981 00000000 00000000
kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
00000000025cfea8 ab e9 90 7c f2 94 80 7c - 02 00 00 00 d0 fe 5c 02
....|...|......\.
00000000025cfeb8 01 00 00 00 01 00 00 00 - 04 ff 5c 02 b0 30 3d 02
...........\..0=.
00000000025cfec8 40 65 fb 77 00 10 00 00 - 64 04 00 00 70 04 00 00
@e.w....d...p...
00000000025cfed8 c0 fe 5c 02 ff 00 00 00 - dc ff 5c 02 f3 99 83 7c
...\.......\....|
00000000025cfee8 c8 0c 81 7c 00 10 00 00 - 14 00 00 00 01 00 00 00
....|............
00000000025cfef8 00 00 00 00 00 00 00 00 - 10 00 00 00 00 a2 2f 4d
.............../M
00000000025cff08 ff ff ff ff 00 10 00 00 - 00 50 fd 7f 00 f0 fa 7f
..........P......
00000000025cff18 dc ff 5c 02 04 ff 5c 02 - d0 fe 5c 02 06 00 00 00
...\...\...\.....
00000000025cff28 02 00 00 00 c4 fe 5c 02 - 06 00 00 00 dc ff 5c 02
.......\.......\.
00000000025cff38 f3 99 83 7c 90 95 80 7c - 00 00 00 00 b4 ff 5c 02
....|...|......\.
00000000025cff48 26 9b f6 77 02 00 00 00 - 6c ff 5c 02 00 00 00 00
&..w....l.\.....
00000000025cff58 e0 93 04 00 01 00 00 00 - bb 40 91 7c 00 00 00 00
..........@.|....
00000000025cff68 00 00 00 00 64 04 00 00 - 70 04 00 00 00 10 00 00
.....d...p.......
00000000025cff78 b0 30 3d 02 00 00 00 00 - 00 10 00 00 b8 40 3d 02
..0=..........@=.
00000000025cff88 a0 66 fb 77 20 00 00 00 - 80 66 fb 77 00 10 00 00
..f.w ....f.w....
00000000025cff98 00 00 00 00 a0 66 fb 77 - b0 30 3d 02 80 66 fb 77
......f.w.0=..f.w
00000000025cffa8 e5 03 00 00 00 10 00 00 - b8 40 3d 02 ec ff 5c 02
..........@=...\.
00000000025cffb8 0b b5 80 7c 00 00 00 00 - bb 40 91 7c 00 00 00 00
....|.....@.|....
00000000025cffc8 00 00 00 00 00 f0 fa 7f - 00 c6 5b 86 c0 ff 5c 02
...........[...\.
00000000025cffd8 b0 b3 ec 85 ff ff ff ff - f3 99 83 7c 18 b5 80 7c
............|...|

*----> Statusdump voor subproces-ID 0x898 <----*

eax=00000000 ebx=00000000 ecx=029231f4 edx=02923280 esi=00140608
edi=00000000
eip=7c90eb94 esp=02c5fc0c ebp=02c5fc94 iopl=0 nv up ei pl zr na
po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
02c5fc94 7c90104b 00140608 7c910d35 00140608 ntdll!KiFastSystemCallRet
02c5fd64 7c809988 00140000 00000000 0297d708
ntdll!RtlEnterCriticalSection+0x46
02c5fdac 77185177 0297d708 00000000 02922fb0 kernel32!LocalFree+0x2b
02c5fdcc 771f6c27 00000000 0417a4bf 00000000
WININET!InternetCloseHandle+0x3db
02c5fde0 771a2c90 00000000 00000000 00001200 WININET+0x86c27
02c5fe2c 771a2eb8 00000001 00000000 00000000
WININET!InternetTimeFromSystemTimeA+0x8f50
02c5fe64 7717d07d 00000130 001cb348 02922fb0
WININET!InternetTimeFromSystemTimeA+0x9178
02c5fe84 7717cc35 00000000 001ab920 001b9da0 WININET!Ordinal101+0x693
02c5fe98 7717cb2c 001b9da0 001ab920 001b9da0 WININET!Ordinal101+0x24b
02c5feb0 7719736a 001ab920 02c5fee8 02c5fedc WININET!Ordinal101+0x142
02c5fee0 77e99498 00000000 001921c0 77e9947b
WININET!InternetGetConnectedStateExA+0x128
02c5fef8 7c927545 001921c0 7c97c3a0 0020af68 SHLWAPI!Ordinal120+0xbf
02c5ff40 7c927583 77e9947b 001921c0 00000000
ntdll!RtlUpcaseUnicodeString+0x159
02c5ff60 7c927645 00000000 001921c0 0020af68
ntdll!RtlUpcaseUnicodeString+0x197
02c5ff74 7c92761c 7c927569 00000000 001921c0
ntdll!RtlUpcaseUnicodeString+0x259
02c5ffb4 7c80b50b 00000000 00000000 001c28c8
ntdll!RtlUpcaseUnicodeString+0x230
02c5ffec 00000000 7c910760 00000000 00000000
kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
0000000002c5fc0c c0 e9 90 7c 1b 90 91 7c - a8 04 00 00 00 00 00 00
....|...|........
0000000002c5fc1c 00 00 00 00 00 00 14 00 - 00 d7 97 02 00 00 00 00
.................
0000000002c5fc2c 20 31 37 3a 31 39 3a 31 - 36 20 47 4d 54 00 20 00
17:19:16 GMT. .
0000000002c5fc3c b8 28 9c 02 00 00 14 00 - 88 15 22 00 81 02 00 00
..(........".....
0000000002c5fc4c 70 fc c5 02 ff 1b 91 7c - 00 00 14 00 88 15 22 00
p......|......".
0000000002c5fc5c 88 15 22 00 00 00 14 00 - 00 20 22 00 40 06 14 00
..."...... ".@...
0000000002c5fc6c 00 00 00 00 b8 fc c5 02 - 2e 1e 91 7c 88 fc c5 02
............|....
0000000002c5fc7c 00 00 00 00 c8 05 91 7c - 58 1e 1d 00 54 fd c5 02
........|X...T...
0000000002c5fc8c 00 00 00 00 a8 04 00 00 - 64 fd c5 02 4b 10 90 7c
.........d...K..|
0000000002c5fc9c 08 06 14 00 35 0d 91 7c - 08 06 14 00 5c 33 92 02
.....5..|....\3..
0000000002c5fcac b0 2f 92 02 08 d7 97 02 - 00 00 a2 02 88 fd c5 02
../..............
0000000002c5fcbc ca 0e 91 7c 91 0e 91 7c - 54 01 00 00 6d 05 91 7c
....|...|T...m..|
0000000002c5fccc 00 14 00 00 5d 99 80 7c - 90 15 22 00 00 00 a2 02
.....]..|..".....
0000000002c5fcdc 38 33 92 02 88 15 22 00 - 90 15 22 00 ff ff ff ff
83...."...".....
0000000002c5fcec c4 fd c5 02 08 d7 97 02 - 48 01 00 00 38 1d 15 00
.........H...8...
0000000002c5fcfc 58 95 22 00 ed 02 91 7c - 08 04 00 00 01 00 00 00
X."....|........
0000000002c5fd0c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 e0 fa 7f
.................
0000000002c5fd1c 00 00 14 00 4f 04 00 00 - 00 83 f3 01 44 fd c5 02
.....O.......D...
0000000002c5fd2c 00 00 14 00 12 00 00 00 - 00 00 01 00 29 00 00 00
.............)...
0000000002c5fd3c 00 00 00 00 00 00 00 00 - 8c fd 01 00 81 00 00 00
.................

*----> Statusdump voor subproces-ID 0xb08 <----*

eax=0000002b ebx=00000000 ecx=01bb1d30 edx=01bb1b60 esi=7c97c380
edi=7c97c3a0
eip=7c90eb94 esp=02b2ff70 ebp=02b2ffb4 iopl=0 nv up ei ng nz na
po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000286

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
02b2ffb4 7c80b50b 00000000 7c8399f3 7c8099a0 ntdll!KiFastSystemCallRet
02b2ffec 00000000 7c910760 00000000 00000000
kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
0000000002b2ff70 1b e3 90 7c 9d 07 91 7c - 94 02 00 00 ac ff b2 02
....|...|........
0000000002b2ff80 b0 ff b2 02 98 ff b2 02 - a0 ff b2 02 f3 99 83 7c
................|
0000000002b2ff90 a0 99 80 7c 00 00 00 00 - 00 00 00 00 20 2d 19 00
....|........ -..
0000000002b2ffa0 00 7c 28 e8 ff ff ff ff - a0 bc 54 aa 69 75 92 7c
..|(.......T.iu.|
0000000002b2ffb0 f0 10 20 00 ec ff b2 02 - 0b b5 80 7c 00 00 00 00 ..
.........|....
0000000002b2ffc0 f3 99 83 7c a0 99 80 7c - 00 00 00 00 00 d0 fa 7f
....|...|........
0000000002b2ffd0 00 c6 5b 86 c0 ff b2 02 - 60 9c 51 86 ff ff ff ff
...[.....`.Q.....
0000000002b2ffe0 f3 99 83 7c 18 b5 80 7c - 00 00 00 00 00 00 00 00
....|...|........
0000000002b2fff0 00 00 00 00 60 07 91 7c - 00 00 00 00 00 00 00 00
.....`..|........
0000000002b30000 4d 5a 90 00 03 00 00 00 - 04 00 00 00 ff ff 00 00
MZ..............
0000000002b30010 b8 00 00 00 00 00 00 00 - 40 00 00 00 00 00 00 00
.........@.......
0000000002b30020 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002b30030 00 00 00 00 00 00 00 00 - 00 00 00 00 b0 00 00 00
.................
0000000002b30040 0e 1f ba 0e 00 b4 09 cd - 21 b8 01 4c cd 21 54 68
.........!..L.!Th
0000000002b30050 69 73 20 70 72 6f 67 72 - 61 6d 20 63 61 6e 6e 6f is
program canno
0000000002b30060 74 20 62 65 20 72 75 6e - 20 69 6e 20 44 4f 53 20 t
be run in DOS
0000000002b30070 6d 6f 64 65 2e 0d 0d 0a - 24 00 00 00 00 00 00 00
mode....$.......
0000000002b30080 eb 20 35 db af 41 5b 88 - af 41 5b 88 af 41 5b 88 .
5..A[..A[..A[.
0000000002b30090 68 47 5d 88 ae 41 5b 88 - 52 69 63 68 af 41 5b 88
hG]..A[.Rich.A[.
0000000002b300a0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
 
Rodi said:
hi everyone,

we've developed an asp.net site for one of our customers' intranet.
however, on some of their computers IE6 crashes when browsing the site.
the crash occurs when switching several times between a popup (opened
by clicking links on the main site) and the main site itself (again, by
clicking links in the main site which are opened in the same popup
window, sometimes closing the popup between views). when viewing the
error signature by clicking the "click here" link in the error report
dialog, the following signature is displayed:

AppName: iexplore.exe
AppVer: 6.0.2800.1106
ModName: unknown
ModVer: 0.0.0.0
Offset: 00000001


This is not the same crash as the attached dump is showing...
Fout ->7c911f6c 8b12 mov edx,[edx]
(000000007c900000 - 000000007c9b6000: C:\WINDOWS\system32\ntdll.dll


Hint: look at the timestamp of the dump (in the headers you suppressed)
and the FAULT -> line (Fout -> line in your language. <w>) to be sure
that you are capturing the dump you want.


HTH

Robert Aldwinckle
---
 
This is not the same crash as the attached dump is showing...
Fout ->7c911f6c 8b12 mov edx,[edx]
(000000007c900000 - 000000007c9b6000: C:\WINDOWS\system32\ntdll.dll


Hint: look at the timestamp of the dump (in the headers you suppressed)
and the FAULT -> line (Fout -> line in your language. <w>) to be sure
that you are capturing the dump you want.


HTH

Robert Aldwinckle

hi robert, thanks for taking the time to reply to my post! by now i've
paid a visit to the customer, and it 'seems' that the crash was caused
by some custom software created by another supplier.. the dump was sent
to me by the customer, so i assumed it was good. but obviously i have
no idea how to interpret the dump log :-)

thanks again!
-rodi.
 
Back
Top