Ulead crash dump

Ulead crash dump

Postby Fatima Mansour » Tue Oct 24, 2006 9:08 pm

Hello Dimitri

How are you?

I am sorry to bother you and if you don't have time to check this, don't worry about it! Ramzy made me register on your Forum and since Dr. Watson seems to have worked I am sending you the crash dump...

As I work with this application it crashes very often, so if there is any advice you can give me about it, would be great!

Thanks a lot

I uloaded the crashdumo to Sendspace, but if you wnat me to upload it to your link just let me know, I can do it easily!

http://www.sendspace.com/file/iys84w

Microsoft (R) DrWtsn32
Copyright (C) 1985-2001 Microsoft Corp. Alle Rechte vorbehalten.



Anwendungsausnahme aufgetreten:
Anwendung: C:\WINDOWS\Explorer.EXE (pid=1868)
Wann: 22.02.2004 @ 22:37:11.203
Ausnahmenummer: c0000005 (Zugriffsverletzung)

*----> Systeminformationen <----*
Computername: RMA
Benutzername: Ramzy
Terminalsitzungskennung: 0
Prozessoranzahl: 2
Prozessortyp: x86 Family 15 Model 2 Stepping 9
Windows-Version: 5.1
Aktuelles Build: 2600
Service Pack: 1
Aktueller Typ: Multiprocessor Free
Firma: Privat
Besitzer: R.M

*----> Taskliste <----*
0 System Process
4 System
604 smss.exe
660 csrss.exe
684 winlogon.exe
728 services.exe
740 savedump.exe
764 lsass.exe
924 Ati2evxx.exe
948 svchost.exe
1052 svchost.exe
1220 svchost.exe
1252 svchost.exe
1440 spoolsv.exe
1820 Ati2evxx.exe
1868 Explorer.EXE
464 drwtsn32.exe

*----> Modulliste <----*
(0000000001000000 - 00000000010f8000: C:\WINDOWS\Explorer.EXE
(000000005b0f0000 - 000000005b124000: C:\WINDOWS\System32\UxTheme.dll
(000000005b9b0000 - 000000005ba22000: C:\WINDOWS\System32\themeui.dll
(0000000070a70000 - 0000000070ad5000: C:\WINDOWS\system32\SHLWAPI.dll
(0000000071500000 - 00000000715fd000: C:\WINDOWS\System32\BROWSEUI.dll
(0000000071700000 - 0000000071849000: C:\WINDOWS\System32\SHDOCVW.dll
(0000000075ee0000 - 0000000075eff000: C:\WINDOWS\system32\appHelp.dll
(0000000076320000 - 0000000076325000: C:\WINDOWS\System32\MSIMG32.dll
(00000000765a0000 - 00000000765bb000: C:\WINDOWS\System32\CSCDLL.dll
(00000000765c0000 - 0000000076610000: C:\WINDOWS\System32\cscui.dll
(0000000076f50000 - 0000000076f60000: C:\WINDOWS\System32\Secur32.dll
(0000000076f90000 - 0000000077008000: C:\WINDOWS\System32\CLBCATQ.DLL
(0000000077010000 - 00000000770e3000: C:\WINDOWS\System32\COMRes.dll
(00000000770f0000 - 000000007717b000: C:\WINDOWS\system32\OLEAUT32.dll
(0000000077310000 - 000000007739b000: C:\WINDOWS\system32\comctl32.dll
(00000000773a0000 - 0000000077b9c000: C:\WINDOWS\system32\SHELL32.dll
(0000000077bd0000 - 0000000077bd7000: C:\WINDOWS\system32\VERSION.dll
(0000000077be0000 - 0000000077c33000: C:\WINDOWS\system32\msvcrt.dll
(0000000077c40000 - 0000000077c80000: C:\WINDOWS\system32\GDI32.dll
(0000000077d10000 - 0000000077d9c000: C:\WINDOWS\system32\USER32.dll
(0000000077da0000 - 0000000077e3c000: C:\WINDOWS\system32\ADVAPI32.dll
(0000000077e40000 - 0000000077f38000: C:\WINDOWS\system32\kernel32.dll
(0000000077f40000 - 0000000077fee000: C:\WINDOWS\System32\ntdll.dll
(0000000078000000 - 0000000078086000: C:\WINDOWS\system32\RPCRT4.dll
(0000000078090000 - 0000000078174000: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805\comctl32.dll
(000000007ccc0000 - 000000007cde1000: C:\WINDOWS\system32\ole32.dll

*----> Statusabbild für Threadkennung 0x750 <----*

eax=7170e9d8 ebx=0006fc88 ecx=0006fe50 edx=00000000 esi=00000000 edi=7ffdf000
eip=7ffe0304 esp=0006fc40 ebp=0006fcdc iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202

Funktion: <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 9c pushfd
7ffe0306 810c2400010000 or dword ptr [esp],0x100
7ffe030d 9d popfd
7ffe030e c3 ret
7ffe030f 8bd4 mov edx,esp
7ffe0311 0f05 syscall
7ffe0313 c3 ret
7ffe0314 9c pushfd
7ffe0315 810c2400010000 or dword ptr [esp],0x100
7ffe031c 9d popfd

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\System32\ntdll.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\USER32.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\SHLWAPI.dll -
ChildEBP RetAddr Args to Child
0006fc3c 77f4c524 77e55ee0 00000002 0006fc88 *SharedUserSystemCall+0xc (FPO: [0,0,0])
0006fcdc 77d163eb 00000002 0006fd04 00000000 ntdll!NtWaitForMultipleObjects+0xc
0006fd38 77d16466 00000001 0006fda0 ffffffff USER32!SetScrollInfo+0x21f
0006fd54 70aaa1a9 00000001 0006fda0 00000000 USER32!MsgWaitForMultipleObjects+0x1d
77e5a29b f7028b7f ac0f0462 8bc318d0 83082444 SHLWAPI!Ordinal194+0x2a
fe0000ba 00000000 00000000 00000000 00000000 0xf7028b7f

*----> Raw Stack Dump <----*
000000000006fc40 24 c5 f4 77 e0 5e e5 77 - 02 00 00 00 88 fc 06 00 $..w.^.w........
000000000006fc50 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000006fc60 02 00 00 00 00 00 00 00 - 00 00 00 00 00 40 08 00 .............@..
000000000006fc70 00 00 00 00 58 fc 06 00 - b9 17 da 77 02 00 00 00 ....X......w....
000000000006fc80 00 f0 fd 7f 00 e0 fd 7f - 4c 01 00 00 20 00 00 00 ........L... ...
000000000006fc90 29 13 a9 70 e0 48 08 00 - 06 00 00 00 00 00 00 00 )..p.H..........
000000000006fca0 c0 fc 06 00 ad 48 a9 70 - 88 fc 06 00 01 00 00 00 .....H.p........
000000000006fcb0 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000006fcc0 10 00 00 00 5c fc 06 00 - 01 00 00 00 e0 ff 06 00 ....\...........
000000000006fcd0 09 48 e7 77 78 32 e6 77 - 00 00 00 00 38 fd 06 00 .H.wx2.w....8...
000000000006fce0 eb 63 d1 77 02 00 00 00 - 04 fd 06 00 00 00 00 00 .c.w............
000000000006fcf0 ff ff ff ff 00 00 00 00 - d3 64 00 00 ff ff ff ff .........d......
000000000006fd00 00 00 00 00 4c 01 00 00 - 20 00 00 00 02 00 00 00 ....L... .......
000000000006fd10 b8 70 09 00 0c fd 06 00 - 9c fc 06 00 d0 fc 06 00 .p..............
000000000006fd20 74 b6 f4 77 82 4d e5 77 - 00 00 00 00 00 00 00 00 t..w.M.w........
000000000006fd30 00 e0 fd 7f 20 00 00 00 - 54 fd 06 00 66 64 d1 77 .... ...T...fd.w
000000000006fd40 01 00 00 00 a0 fd 06 00 - ff ff ff ff 40 00 00 00 ............@...
000000000006fd50 04 fd 06 00 9b a2 e5 77 - a9 a1 aa 70 01 00 00 00 .......w...p....
000000000006fd60 a0 fd 06 00 00 00 00 00 - ff ff ff ff 40 00 00 00 ............@...
000000000006fd70 f0 a6 e5 77 00 00 00 00 - 00 ff 06 00 08 00 00 00 ...w............

*----> Statusabbild für Threadkennung 0x764 <----*

eax=780015dd ebx=000a0030 ecx=77f47f98 edx=00000000 esi=b2ab5d40 edi=00000000
eip=7ffe0304 esp=00bdfe28 ebp=00bdff90 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202

Funktion: <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 9c pushfd
7ffe0306 810c2400010000 or dword ptr [esp],0x100
7ffe030d 9d popfd
7ffe030e c3 ret
7ffe030f 8bd4 mov edx,esp
7ffe0311 0f05 syscall
7ffe0313 c3 ret
7ffe0314 9c pushfd
7ffe0315 810c2400010000 or dword ptr [esp],0x100
7ffe031c 9d popfd

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\RPCRT4.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\GDI32.dll -
ChildEBP RetAddr Args to Child
00bdfe24 77f4c084 780016a4 0000012c 00bdff80 *SharedUserSystemCall+0xc (FPO: [0,0,0])
00bdff90 78001601 780019d6 000959a0 77f988f0 ntdll!NtReplyWaitReceivePortEx+0xc
0009fa40 ffffffff 00000144 00000148 00000000 RPCRT4+0x1601
00000000 00000000 00000000 00000000 00000000 0xffffffff

*----> Raw Stack Dump <----*
0000000000bdfe28 84 c0 f4 77 a4 16 00 78 - 2c 01 00 00 80 ff bd 00 ...w...x,.......
0000000000bdfe38 00 00 00 00 30 00 0a 00 - 58 ff bd 00 90 4d 4e e1 ....0...X....MN.
0000000000bdfe48 30 ed f7 81 00 00 00 00 - 48 b5 f7 81 00 ed f7 81 0.......H.......
0000000000bdfe58 14 b5 f7 81 b4 5b ab b2 - ff 08 40 f8 ce 08 40 f8 .....[....@...@.
0000000000bdfe68 90 4d 4e e1 fc 5b ab b2 - 00 00 00 00 40 f5 df ff .MN..[......@...
0000000000bdfe78 02 bc 1d c0 08 69 4f 80 - 00 10 f1 76 a8 8d c7 81 .....iO....v....
0000000000bdfe88 44 bc 1d c0 98 5b ab b2 - 74 54 51 80 00 10 f1 76 D....[..tTQ....v
0000000000bdfe98 00 00 00 00 48 f5 df ff - a9 bb 6b 80 e0 54 51 80 ....H.....k..TQ.
0000000000bdfea8 48 54 d8 80 a8 8d c7 81 - 00 30 d8 01 24 5c ab b2 HT.......0..$\..
0000000000bdfeb8 27 98 59 80 67 38 d8 0c - 25 30 d8 0c 60 9a 59 80 '.Y.g8..%0..`.Y.
0000000000bdfec8 ff 1f f1 76 a8 8d c7 81 - 58 15 ca 81 80 2d db 81 ...v....X....-..
0000000000bdfed8 a8 8d c7 81 08 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000bdfee8 00 00 00 00 78 c8 f7 81 - ff ff ff ff 40 d5 7c f8 ....x.......@.|.
0000000000bdfef8 00 00 00 00 cc b2 6b 80 - 00 00 00 00 30 5c ab b2 ......k.....0\..
0000000000bdff08 00 00 00 00 e3 b2 6b 80 - 08 00 00 00 46 02 00 00 ......k.....F...
0000000000bdff18 ae d7 4f 80 f8 54 c1 81 - 88 54 c1 81 24 56 c1 81 ..O..T...T..$V..
0000000000bdff28 e8 64 4f 80 f4 55 c1 81 - 88 54 c1 81 1f c5 61 80 .dO..U...T....a.
0000000000bdff38 20 15 eb 81 88 54 c1 81 - 2f 16 00 78 60 ff bd 00 ....T../..x`...
0000000000bdff48 4a 16 00 78 58 58 09 00 - c0 f0 09 00 40 fa 09 00 J..xXX......@...
0000000000bdff58 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff ../M.....]......

*----> Statusabbild für Threadkennung 0x768 <----*

eax=00c2f0f8 ebx=00c2f248 ecx=00000008 edx=01010055 esi=00000000 edi=01010055
eip=77d1708d esp=00c2f0dc ebp=00c2f174 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

Funktion: USER32!SendMessageTimeoutW
No prior disassembly possible
77d1708d 650100 add gs:[eax],eax
77d17090 0085c00f842f add [ebp+0x2f840fc0],al
77d17096 0300 add eax,[eax]
77d17098 0039 add [ecx],bh
77d1709a 75a4 jnz USER32!SendMessageTimeoutW+0x20 (77d17040)
77d1709c 8b4520 mov eax,[ebp+0x20]
77d1709f 8945bc mov [ebp-0x44],eax
77d170a2 0f8e01050000 jle USER32!DrawTextExW+0x87 (77d175a9)
77d170a8 8b4518 mov eax,[ebp+0x18]
FEHLER ->77d1708d 650100 add gs:[eax],eax gs:00c2f0f8=006c006b
77d17090 0085c00f842f add [ebp+0x2f840fc0],al
77d17096 0300 add eax,[eax]
77d17098 0039 add [ecx],bh
77d1709a 75a4 jnz USER32!SendMessageTimeoutW+0x20 (77d17040)
77d1709c 8b4520 mov eax,[ebp+0x20]
77d1709f 8945bc mov [ebp-0x44],eax
77d170a2 0f8e01050000 jle USER32!DrawTextExW+0x87 (77d175a9)
77d170a8 8b4518 mov eax,[ebp+0x18]
77d170ab 2500000200 and eax,0x20000
77d170b0 8945d4 mov [ebp-0x2c],eax

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\System32\UxTheme.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805\comctl32.dll -
*** ERROR: Module load completed but symbols could not be loaded for C:\WINDOWS\Explorer.EXE
ChildEBP RetAddr Args to Child
00c2f174 77d1753e 01010055 00c2f248 00000005 USER32!SendMessageTimeoutW+0x6d
00c2f198 5b0f28b8 01010055 00c2f248 00000005 USER32!DrawTextExW+0x1c
00c2f1dc 5b0f2828 00267030 01010055 00000001 UxTheme!GetThemeTextExtent+0x143
00c2f21c 780c21c4 007a11b0 01010055 00000001 UxTheme!GetThemeTextExtent+0xb3
00c2f2ac 780c396c 01010055 0103f4b8 00c2f3a0 comctl32!Ordinal384+0xd4d2
00c2f32c 77d13a50 0003003e 00001601 00000000 comctl32!Ordinal384+0xec7a
00c2f358 77d13b1f 780c2edd 0003003e 00001601 USER32+0x3a50
00c2f3c0 77d15b2c 000858b0 780c2edd 0003003e USER32+0x3b1f
00c2f3f0 77d15b4b 780c2edd 0003003e 00001601 USER32!IsWindowVisible+0x80
00c2f410 01005f89 780c2edd 0003003e 00001601 USER32!CallWindowProcW+0x19
00c2f454 77d13a50 0003003e 00001601 00000000 Explorer+0x5f89
00c2f480 77d13b1f 01005f13 0003003e 00001601 USER32+0x3a50
00c2f4e8 77d15453 000858b0 01005f13 0003003e USER32+0x3b1f
00c2f524 77d154b4 00477140 00475a40 00000000 USER32!ReleaseDC+0x12a
00c2f544 0100ca97 0003003e 00001601 00000000 USER32!SendMessageW+0x47
00c2f5e8 0100cca3 0103f0f8 00000000 00740053 Explorer+0xca97
00c2f698 010146e1 0003003c 0103f0f8 00c2f6c8 Explorer+0xcca3
0101d5a8 00720061 00000074 00690077 006d006e Explorer+0x146e1
00740053 00000000 00000000 00000000 00000000 0x720061

*----> Raw Stack Dump <----*
0000000000c2f0dc c4 f1 c2 00 00 04 00 00 - f8 f0 c2 00 00 00 00 00 ................
0000000000c2f0ec d4 f1 c2 00 00 00 00 00 - 00 04 00 00 6b 00 6c 00 ............k.l.
0000000000c2f0fc 69 00 6e 00 20 00 47 00 - 6f 00 74 00 68 00 69 00 i.n. .G.o.t.h.i.
0000000000c2f10c 63 00 20 00 4d 00 65 00 - 64 00 69 00 75 00 6d 00 c. .M.e.d.i.u.m.
0000000000c2f11c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000c2f12c 00 00 00 00 00 00 00 00 - a8 f1 c2 00 d2 2a 0f 5b .............*.[
0000000000c2f13c 55 00 01 01 e0 11 7a 00 - fc f1 c2 00 00 00 00 00 U.....z.........
0000000000c2f14c b4 f1 c2 00 1f 3b d1 77 - 00 c0 fd 7f b4 f1 c2 00 .....;.w........
0000000000c2f15c 4f 3b d1 77 80 f1 c2 00 - 33 3b d1 77 28 f1 c2 00 O;.w....3;.w(...
0000000000c2f16c f4 f0 c2 00 54 71 47 00 - 98 f1 c2 00 3e 75 d1 77 ....TqG.....>u.w
0000000000c2f17c 55 00 01 01 48 f2 c2 00 - 05 00 00 00 c4 f1 c2 00 U...H...........
0000000000c2f18c 00 04 00 00 00 00 00 00 - ff ff ff ff dc f1 c2 00 ................
0000000000c2f19c b8 28 0f 5b 55 00 01 01 - 48 f2 c2 00 05 00 00 00 .(.[U...H.......
0000000000c2f1ac c4 f1 c2 00 00 04 00 00 - 00 00 00 00 05 00 00 00 ................
0000000000c2f1bc 0d 5b e5 77 98 af 09 00 - 00 00 00 00 00 00 00 00 .[.w............
0000000000c2f1cc 00 00 00 00 00 00 00 00 - 00 00 00 00 89 03 0a 0f ................
0000000000c2f1dc 1c f2 c2 00 28 28 0f 5b - 30 70 26 00 55 00 01 01 ....((.[0p&.U...
0000000000c2f1ec 01 00 00 00 01 00 00 00 - 48 f2 c2 00 05 00 00 00 ........H.......
0000000000c2f1fc 8a 03 0a 0a 80 f2 c2 00 - 80 f2 c2 00 00 00 00 00 ................
0000000000c2f20c 05 00 00 00 00 00 00 00 - 03 00 00 00 01 00 00 00 ................

*----> Statusabbild für Threadkennung 0x76c <----*

eax=77f783de ebx=00000000 ecx=00000000 edx=00000000 esi=000848f0 edi=70a908d3
eip=7ffe0304 esp=00c6ff9c ebp=00c6ffb4 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202

Funktion: <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 9c pushfd
7ffe0306 810c2400010000 or dword ptr [esp],0x100
7ffe030d 9d popfd
7ffe030e c3 ret
7ffe030f 8bd4 mov edx,esp
7ffe0311 0f05 syscall
7ffe0313 c3 ret
7ffe0314 9c pushfd
7ffe0315 810c2400010000 or dword ptr [esp],0x100
7ffe031c 9d popfd

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\kernel32.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
00c6ff98 77f4b7f4 77f78423 00000001 00c6ffac *SharedUserSystemCall+0xc (FPO: [0,0,0])
00c6ffb4 77e5d33b 00000000 70a908d3 000848f0 ntdll!ZwDelayExecution+0xc
00c6ffec 00000000 77f783de 00000000 00000000 kernel32!RegisterWaitForInputIdle+0x43

*----> Raw Stack Dump <----*
0000000000c6ff9c f4 b7 f4 77 23 84 f7 77 - 01 00 00 00 ac ff c6 00 ...w#..w........
0000000000c6ffac 00 00 00 00 00 00 00 80 - ec ff c6 00 3b d3 e5 77 ............;..w
0000000000c6ffbc 00 00 00 00 d3 08 a9 70 - f0 48 08 00 00 00 00 00 .......p.H......
0000000000c6ffcc 00 00 00 00 00 b0 fd 7f - c0 ff c6 00 07 00 00 00 ................
0000000000c6ffdc ff ff ff ff 09 48 e7 77 - b8 3d e6 77 00 00 00 00 .....H.w.=.w....
0000000000c6ffec 00 00 00 00 00 00 00 00 - de 83 f7 77 00 00 00 00 ...........w....
0000000000c6fffc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000c7000c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000c7001c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000c7002c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000c7003c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000c7004c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000c7005c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000c7006c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000c7007c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000c7008c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000c7009c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000c700ac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000c700bc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000c700cc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

*----> Statusabbild für Threadkennung 0x770 <----*

eax=77f85b06 ebx=00000000 ecx=00080000 edx=00000000 esi=77fb59a0 edi=77fb59fc
eip=7ffe0304 esp=00caff70 ebp=00caffb4 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202

Funktion: <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 9c pushfd
7ffe0306 810c2400010000 or dword ptr [esp],0x100
7ffe030d 9d popfd
7ffe030e c3 ret
7ffe030f 8bd4 mov edx,esp
7ffe0311 0f05 syscall
7ffe0313 c3 ret
7ffe0314 9c pushfd
7ffe0315 810c2400010000 or dword ptr [esp],0x100
7ffe031c 9d popfd

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
00caff6c 77f4c024 77f85b41 00000174 00caffac *SharedUserSystemCall+0xc (FPO: [0,0,0])
00caffb4 77e5d33b 00000000 00080000 77f844a8 ntdll!ZwRemoveIoCompletion+0xc
00caffec 00000000 77f85b06 00000000 00000000 kernel32!RegisterWaitForInputIdle+0x43

*----> Raw Stack Dump <----*
0000000000caff70 24 c0 f4 77 41 5b f8 77 - 74 01 00 00 ac ff ca 00 $..wA[.wt.......
0000000000caff80 b0 ff ca 00 98 ff ca 00 - a0 ff ca 00 00 00 08 00 ................
0000000000caff90 a8 44 f8 77 00 00 00 00 - 5e cf 4f 80 00 00 00 00 .D.w....^.O.....
0000000000caffa0 00 7c 28 e8 ff ff ff ff - 62 cf 4f 80 a8 dc aa b2 .|(.....b.O.....
0000000000caffb0 f4 bf f4 77 ec ff ca 00 - 3b d3 e5 77 00 00 00 00 ...w....;..w....
0000000000caffc0 00 00 08 00 a8 44 f8 77 - 00 00 00 00 00 00 00 00 .....D.w........
0000000000caffd0 00 a0 fd 7f c0 ff ca 00 - 07 00 00 00 ff ff ff ff ................
0000000000caffe0 09 48 e7 77 b8 3d e6 77 - 00 00 00 00 00 00 00 00 .H.w.=.w........
0000000000cafff0 00 00 00 00 06 5b f8 77 - 00 00 00 00 00 00 00 00 .....[.w........
0000000000cb0000 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000cb0010 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000cb0020 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000cb0030 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000cb0040 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000cb0050 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000cb0060 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000cb0070 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000cb0080 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000cb0090 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000cb00a0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

*----> Statusabbild für Threadkennung 0x774 <----*

eax=000000c0 ebx=00000000 ecx=00000000 edx=00000000 esi=00000000 edi=00000001
eip=7ffe0304 esp=00cefcec ebp=00ceffb4 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202

Funktion: <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 9c pushfd
7ffe0306 810c2400010000 or dword ptr [esp],0x100
7ffe030d 9d popfd
7ffe030e c3 ret
7ffe030f 8bd4 mov edx,esp
7ffe0311 0f05 syscall
7ffe0313 c3 ret
7ffe0314 9c pushfd
7ffe0315 810c2400010000 or dword ptr [esp],0x100
7ffe031c 9d popfd

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
00cefce8 77f4c524 77f81f83 00000002 00cefd30 *SharedUserSystemCall+0xc (FPO: [0,0,0])
00ceffb4 77e5d33b 00000000 00000020 00000020 ntdll!NtWaitForMultipleObjects+0xc
00ceffec 00000000 77f81e38 00000000 00000000 kernel32!RegisterWaitForInputIdle+0x43

*----> Raw Stack Dump <----*
0000000000cefcec 24 c5 f4 77 83 1f f8 77 - 02 00 00 00 30 fd ce 00 $..w...w....0...
0000000000cefcfc 01 00 00 00 01 00 00 00 - 00 00 00 00 20 00 00 00 ............ ...
0000000000cefd0c 20 00 00 00 00 00 00 00 - 20 5a fb 77 20 5a fb 77 ....... Z.w Z.w
0000000000cefd1c 7c 01 00 00 74 07 00 00 - 02 00 00 00 02 00 00 00 |...t...........
0000000000cefd2c 01 00 00 00 78 01 00 00 - 60 01 00 00 00 00 00 00 ....x...`.......
0000000000cefd3c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000cefd4c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000cefd5c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000cefd6c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000cefd7c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000cefd8c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000cefd9c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000cefdac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000cefdbc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000cefdcc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000cefddc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000cefdec 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000cefdfc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000cefe0c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000cefe1c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................



Anwendungsausnahme aufgetreten:
Anwendung: C:\WINDOWS\System32\taskmgr.exe (pid=500)
Wann: 22.02.2004 @ 22:37:28.609
Ausnahmenummer: c0000005 (Zugriffsverletzung)

*----> Systeminformationen <----*
Computername: RMA
Benutzername: Ramzy
Terminalsitzungskennung: 0
Prozessoranzahl: 2
Prozessortyp: x86 Family 15 Model 2 Stepping 9
Windows-Version: 5.1
Aktuelles Build: 2600
Service Pack: 1
Aktueller Typ: Multiprocessor Free
Firma: Privat
Besitzer: R.M

*----> Taskliste <----*
0 System Process
4 System
604 smss.exe
660 csrss.exe
684 winlogon.exe
728 services.exe
740 savedump.exe
764 lsass.exe
924 Ati2evxx.exe
948 svchost.exe
1052 svchost.exe
1220 svchost.exe
1252 svchost.exe
1440 spoolsv.exe
1820 Ati2evxx.exe
500 taskmgr.exe
368 drwtsn32.exe

*----> Modulliste <----*
(0000000001000000 - 0000000001024000: C:\WINDOWS\System32\taskmgr.exe
(000000005b0d0000 - 000000005b0d9000: C:\WINDOWS\System32\VDMDBG.dll
(000000005b0f0000 - 000000005b124000: C:\WINDOWS\System32\uxtheme.dll
(000000005b130000 - 000000005b13a000: C:\WINDOWS\System32\UTILDLL.dll
(0000000070a70000 - 0000000070ad5000: C:\WINDOWS\system32\SHLWAPI.dll
(0000000071500000 - 00000000715fd000: C:\WINDOWS\System32\browseui.dll
(0000000071a00000 - 0000000071a08000: C:\WINDOWS\System32\WS2HELP.dll
(0000000071a10000 - 0000000071a25000: C:\WINDOWS\System32\WS2_32.dll
(0000000071b70000 - 0000000071b81000: C:\WINDOWS\System32\SAMLIB.dll
(0000000071ba0000 - 0000000071bee000: C:\WINDOWS\System32\NETAPI32.dll
(0000000074a60000 - 0000000074a67000: C:\WINDOWS\System32\cfgmgr32.dll
(0000000076300000 - 000000007630f000: C:\WINDOWS\System32\WINSTA.dll
(0000000076620000 - 0000000076708000: C:\WINDOWS\System32\SETUPAPI.dll
(0000000076af0000 - 0000000076b1d000: C:\WINDOWS\System32\WINMM.dll
(0000000076d20000 - 0000000076d37000: C:\WINDOWS\System32\iphlpapi.dll
(0000000076e40000 - 0000000076e4d000: C:\WINDOWS\System32\rtutils.dll
(0000000076e70000 - 0000000076e9b000: C:\WINDOWS\System32\TAPI32.dll
(0000000076f10000 - 0000000076f18000: C:\WINDOWS\System32\WTSAPI32.dll
(0000000076f50000 - 0000000076f60000: C:\WINDOWS\System32\Secur32.dll
(0000000076f90000 - 0000000077008000: C:\WINDOWS\System32\CLBCATQ.DLL
(0000000077010000 - 00000000770e3000: C:\WINDOWS\System32\COMRes.dll
(00000000770f0000 - 000000007717b000: C:\WINDOWS\system32\OLEAUT32.dll
(00000000773a0000 - 0000000077b9c000: C:\WINDOWS\system32\SHELL32.dll
(0000000077bd0000 - 0000000077bd7000: C:\WINDOWS\system32\VERSION.dll
(0000000077be0000 - 0000000077c33000: C:\WINDOWS\system32\msvcrt.dll
(0000000077c40000 - 0000000077c80000: C:\WINDOWS\system32\GDI32.dll
(0000000077d10000 - 0000000077d9c000: C:\WINDOWS\system32\USER32.dll
(0000000077da0000 - 0000000077e3c000: C:\WINDOWS\system32\ADVAPI32.dll
(0000000077e40000 - 0000000077f38000: C:\WINDOWS\system32\kernel32.dll
(0000000077f40000 - 0000000077fee000: C:\WINDOWS\System32\ntdll.dll
(0000000078000000 - 0000000078086000: C:\WINDOWS\system32\RPCRT4.dll
(0000000078090000 - 0000000078174000: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805\COMCTL32.dll
(000000007ccc0000 - 000000007cde1000: C:\WINDOWS\system32\ole32.dll

*----> Statusabbild für Threadkennung 0x70 <----*

eax=0006e368 ebx=0006e4c4 ecx=0006e4c4 edx=00800980 esi=00000000 edi=01010056
eip=77d1708d esp=0006e34c ebp=0006e3e4 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\USER32.dll -
Funktion: USER32!SendMessageTimeoutW
No prior disassembly possible
77d1708d 650100 add gs:[eax],eax
77d17090 0085c00f842f add [ebp+0x2f840fc0],al
77d17096 0300 add eax,[eax]
77d17098 0039 add [ecx],bh
77d1709a 75a4 jnz USER32!SendMessageTimeoutW+0x20 (77d17040)
77d1709c 8b4520 mov eax,[ebp+0x20]
77d1709f 8945bc mov [ebp-0x44],eax
77d170a2 0f8e01050000 jle USER32!DrawTextExW+0x87 (77d175a9)
77d170a8 8b4518 mov eax,[ebp+0x18]
FEHLER ->77d1708d 650100 add gs:[eax],eax gs:0006e368=00000003
77d17090 0085c00f842f add [ebp+0x2f840fc0],al
77d17096 0300 add eax,[eax]
77d17098 0039 add [ecx],bh
77d1709a 75a4 jnz USER32!SendMessageTimeoutW+0x20 (77d17040)
77d1709c 8b4520 mov eax,[ebp+0x20]
77d1709f 8945bc mov [ebp-0x44],eax
77d170a2 0f8e01050000 jle USER32!DrawTextExW+0x87 (77d175a9)
77d170a8 8b4518 mov eax,[ebp+0x18]
77d170ab 2500000200 and eax,0x20000
77d170b0 8945d4 mov [ebp-0x2c],eax

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\System32\uxtheme.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805\COMCTL32.dll -
ChildEBP RetAddr Args to Child
0006e3e4 77d1753e 01010056 0006e4c4 0000000c USER32!SendMessageTimeoutW+0x6d
0006e408 5b0f28b8 01010056 0006e4c4 ffffffff USER32!DrawTextExW+0x1c
0006e44c 5b0f2828 00774708 01010056 00000000 uxtheme!GetThemeTextExtent+0x143
0006e48c 780a75ec 00800980 01010056 00000000 uxtheme!GetThemeTextExtent+0xb3
0006e5e8 00000000 00000000 00000000 0006e840 COMCTL32!CreateStatusWindowA+0x2d6

*----> Raw Stack Dump <----*
000000000006e34c 34 e4 06 00 20 04 00 00 - 68 e3 06 00 00 00 00 00 4... ...h.......
000000000006e35c 44 e4 06 00 00 00 00 00 - 20 04 00 00 03 00 00 00 D....... .......
000000000006e36c 9b 01 85 03 00 00 00 00 - ec e3 06 00 6f 22 0f 5b ............o".[
000000000006e37c 9c 1e 82 00 f4 1a 82 00 - 01 00 00 00 08 47 77 00 .............Gw.
000000000006e38c 56 00 01 01 9b 01 85 03 - c8 e3 06 00 00 00 00 00 V...............
000000000006e39c b8 e3 06 00 00 00 00 00 - 50 e1 06 00 00 00 00 00 ........P.......
000000000006e3ac 56 00 01 01 98 1e 82 00 - 08 47 77 00 00 00 00 00 V........Gw.....
000000000006e3bc 02 00 00 00 02 00 00 00 - 02 00 00 00 00 00 00 00 ................
000000000006e3cc 02 00 00 00 60 00 00 00 - 17 00 00 00 60 00 00 00 ....`.......`...
000000000006e3dc 15 00 00 00 01 00 00 00 - 08 e4 06 00 3e 75 d1 77 ............>u.w
000000000006e3ec 56 00 01 01 c4 e4 06 00 - 0c 00 00 00 34 e4 06 00 V...........4...
000000000006e3fc 20 04 00 00 00 00 00 00 - ff ff ff ff 4c e4 06 00 ...........L...
000000000006e40c b8 28 0f 5b 56 00 01 01 - c4 e4 06 00 ff ff ff ff .(.[V...........
000000000006e41c 34 e4 06 00 20 04 00 00 - 00 00 00 00 ff ff ff ff 4... ...........
000000000006e42c 0d 5b e5 77 00 00 00 00 - 00 00 00 00 00 00 00 00 .[.w............
000000000006e43c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000006e44c 8c e4 06 00 28 28 0f 5b - 08 47 77 00 56 00 01 01 ....((.[.Gw.V...
000000000006e45c 00 00 00 00 00 00 00 00 - c4 e4 06 00 ff ff ff ff ................
000000000006e46c 00 00 00 00 e4 e5 06 00 - e4 e5 06 00 f4 e5 06 00 ................
000000000006e47c c4 e4 06 00 00 00 00 00 - 02 00 00 00 e4 e5 06 00 ................

*----> Statusabbild für Threadkennung 0x204 <----*

eax=00000d24 ebx=00000000 ecx=00000000 edx=00000000 esi=0089ff94 edi=0089f824
eip=7ffe0304 esp=0089f42c ebp=0089f448 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202

Funktion: <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 9c pushfd
7ffe0306 810c2400010000 or dword ptr [esp],0x100
7ffe030d 9d popfd
7ffe030e c3 ret
7ffe030f 8bd4 mov edx,esp
7ffe0311 0f05 syscall
7ffe0313 c3 ret
7ffe0314 9c pushfd
7ffe0315 810c2400010000 or dword ptr [esp],0x100
7ffe031c 9d popfd

*----> Stack Back Trace <----*
*** ERROR: Module load completed but symbols could not be loaded for C:\WINDOWS\System32\taskmgr.exe
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\kernel32.dll -
ChildEBP RetAddr Args to Child
0089f428 77d13a09 77d13c7d 0089ff94 00000000 *SharedUserSystemCall+0xc (FPO: [0,0,0])
0089f448 0100e612 0089ff94 00000000 00000000 USER32+0x3a09
0089ffb4 77e5d33b 00000000 77d18cd0 77d1b7d2 taskmgr+0xe612
0089ffec 00000000 0100e3cb 00000000 00000000 kernel32!RegisterWaitForInputIdle+0x43

*----> Raw Stack Dump <----*
000000000089f42c 09 3a d1 77 7d 3c d1 77 - 94 ff 89 00 00 00 00 00 .:.w}<.w........
000000000089f43c 00 00 00 00 00 00 00 00 - 79 7e 44 77 b4 ff 89 00 ........y~Dw....
000000000089f44c 12 e6 00 01 94 ff 89 00 - 00 00 00 00 00 00 00 00 ................
000000000089f45c 00 00 00 00 d0 8c d1 77 - d2 b7 d1 77 00 00 00 00 .......w...w....
000000000089f46c b8 03 00 00 3c 00 04 00 - 00 00 00 00 0e 00 00 00 ....<...........
000000000089f47c 00 00 00 00 45 00 03 00 - 43 00 50 00 55 00 2d 00 ....E...C.P.U.-.
000000000089f48c 41 00 75 00 73 00 6c 00 - 61 00 73 00 74 00 75 00 A.u.s.l.a.s.t.u.
000000000089f49c 6e 00 67 00 3a 00 20 00 - 32 00 25 00 00 00 00 00 n.g.:. .2.%.....
000000000089f4ac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000089f4bc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000089f4cc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000089f4dc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000089f4ec 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000089f4fc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000089f50c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000089f51c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000089f52c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000089f53c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000089f54c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000089f55c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

*----> Statusabbild für Threadkennung 0x208 <----*

eax=00461a40 ebx=77e55e37 ecx=002701f8 edx=00000000 esi=0000008c edi=00000000
eip=7ffe0304 esp=0090ff28 ebp=0090ff8c iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202

Funktion: <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 9c pushfd
7ffe0306 810c2400010000 or dword ptr [esp],0x100
7ffe030d 9d popfd
7ffe030e c3 ret
7ffe030f 8bd4 mov edx,esp
7ffe0311 0f05 syscall
7ffe0313 c3 ret
7ffe0314 9c pushfd
7ffe0315 810c2400010000 or dword ptr [esp],0x100
7ffe031c 9d popfd

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\System32\ntdll.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0090ff24 77f4c534 77e5a62d 0000008c 00000000 *SharedUserSystemCall+0xc (FPO: [0,0,0])
0090ff8c 77e5ac21 0000008c ffffffff 00000000 ntdll!NtWaitForSingleObject+0xc
0090ffec 00000000 0100c965 00094d44 00000000 kernel32!WaitForSingleObject+0xf

*----> Raw Stack Dump <----*
000000000090ff28 34 c5 f4 77 2d a6 e5 77 - 8c 00 00 00 00 00 00 00 4..w-..w........
000000000090ff38 00 00 00 00 12 ac e5 77 - 44 4d 09 00 37 5e e5 77 .......wDM..7^.w
000000000090ff48 00 00 00 00 00 00 00 00 - 7a cf 4f 80 00 00 00 00 ........z.O.....
000000000090ff58 00 f0 fd 7f 00 c0 fd 7f - 14 00 00 00 01 00 00 00 ................
000000000090ff68 00 00 00 00 00 00 00 00 - 10 00 00 00 3c ff 90 00 ............<...
000000000090ff78 f8 2b c6 81 dc ff 90 00 - 09 48 e7 77 e0 3a e6 77 .+.......H.w.:.w
000000000090ff88 00 00 00 00 ec ff 90 00 - 21 ac e5 77 8c 00 00 00 ........!..w....
000000000090ff98 ff ff ff ff 00 00 00 00 - 9b c9 00 01 8c 00 00 00 ................
000000000090ffa8 ff ff ff ff 98 6a 46 00 - ac 6a 46 00 44 4d 09 00 .....jF..jF.DM..
000000000090ffb8 3b d3 e5 77 44 4d 09 00 - 98 6a 46 00 ac 6a 46 00 ;..wDM...jF..jF.
000000000090ffc8 44 4d 09 00 00 00 00 00 - 00 c0 fd 7f c0 ff 90 00 DM..............
000000000090ffd8 07 00 00 00 ff ff ff ff - 09 48 e7 77 b8 3d e6 77 .........H.w.=.w
000000000090ffe8 00 00 00 00 00 00 00 00 - 00 00 00 00 65 c9 00 01 ............e...
000000000090fff8 44 4d 09 00 00 00 00 00 - 03 00 00 00 e0 8a 0a 00 DM..............
0000000000910008 03 00 00 00 68 fa 0a 00 - 03 00 00 00 18 fc 0a 00 ....h...........
0000000000910018 03 00 00 00 98 fc 0a 00 - 03 00 00 00 18 fd 0a 00 ................
0000000000910028 03 00 00 00 d0 03 0b 00 - 03 00 00 00 80 05 0b 00 ................
0000000000910038 03 00 00 00 30 07 0b 00 - 03 00 00 00 e0 08 0b 00 ....0...........
0000000000910048 03 00 00 00 90 0a 0b 00 - 03 00 00 00 40 0c 0b 00 ............@...
0000000000910058 03 00 00 00 f0 0d 0b 00 - 03 00 00 00 a0 0f 0b 00 ................

*----> Statusabbild für Threadkennung 0x210 <----*

eax=77f783de ebx=00000000 ecx=00000000 edx=00000000 esi=00000000 edi=00000000
eip=7ffe0304 esp=00a2ff9c ebp=00a2ffb4 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202

Funktion: <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 9c pushfd
7ffe0306 810c2400010000 or dword ptr [esp],0x100
7ffe030d 9d popfd
7ffe030e c3 ret
7ffe030f 8bd4 mov edx,esp
7ffe0311 0f05 syscall
7ffe0313 c3 ret
7ffe0314 9c pushfd
7ffe0315 810c2400010000 or dword ptr [esp],0x100
7ffe031c 9d popfd

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
00a2ff98 77f4b7f4 77f78423 00000001 00a2ffac *SharedUserSystemCall+0xc (FPO: [0,0,0])
00a2ffb4 77e5d33b 00000000 00000000 00000000 ntdll!ZwDelayExecution+0xc
00a2ffec 00000000 77f783de 00000000 00000000 kernel32!RegisterWaitForInputIdle+0x43

*----> Raw Stack Dump <----*
0000000000a2ff9c f4 b7 f4 77 23 84 f7 77 - 01 00 00 00 ac ff a2 00 ...w#..w........
0000000000a2ffac 00 00 00 00 00 00 00 80 - ec ff a2 00 3b d3 e5 77 ............;..w
0000000000a2ffbc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000a2ffcc 1f 00 00 00 00 b0 fd 7f - c0 ff a2 00 78 5d 77 b2 ............x]w.
0000000000a2ffdc ff ff ff ff 09 48 e7 77 - b8 3d e6 77 00 00 00 00 .....H.w.=.w....
0000000000a2ffec 00 00 00 00 00 00 00 00 - de 83 f7 77 00 00 00 00 ...........w....
0000000000a2fffc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000a3000c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000a3001c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000a3002c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000a3003c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000a3004c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000a3005c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000a3006c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000a3007c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000a3008c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000a3009c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000a300ac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000a300bc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000a300cc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

*----> Statusabbild für Threadkennung 0x214 <----*

eax=00000000 ebx=00a6fdbc ecx=00a70000 edx=00000000 esi=00000000 edi=7ffdf000
eip=7ffe0304 esp=00a6fd74 ebp=00a6fe10 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202

Funktion: <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 9c pushfd
7ffe0306 810c2400010000 or dword ptr [esp],0x100
7ffe030d 9d popfd
7ffe030e c3 ret
7ffe030f 8bd4 mov edx,esp
7ffe0311 0f05 syscall
7ffe0313 c3 ret
7ffe0314 9c pushfd
7ffe0315 810c2400010000 or dword ptr [esp],0x100
7ffe031c 9d popfd

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\System32\browseui.dll -
ChildEBP RetAddr Args to Child
00a6fd70 77f4c524 77e55ee0 00000001 00a6fdbc *SharedUserSystemCall+0xc (FPO: [0,0,0])
00a6fe10 77d163eb 00000001 00a6fe38 00000000 ntdll!NtWaitForMultipleObjects+0xc
00a6fe6c 77d16466 00000000 00000000 ffffffff USER32!SetScrollInfo+0x21f
00a6fe88 7150fa07 00000000 00000000 00000000 USER32!MsgWaitForMultipleObjects+0x1d
00a6fee0 7150f91e 7150f906 71500000 70aba72e browseui!DllGetClassObject+0x1737
00a6ff48 77f8613d 70aba715 000bc888 00094810 browseui!DllGetClassObject+0x164e
00a6ffb4 77e5d33b 00000000 0006e900 00090000 ntdll!RtlSetIoCompletionCallback+0xaf
00a6ffec 00000000 77f85b06 00000000 00000000 kernel32!RegisterWaitForInputIdle+0x43

*----> Raw Stack Dump <----*
0000000000a6fd74 24 c5 f4 77 e0 5e e5 77 - 01 00 00 00 bc fd a6 00 $..w.^.w........
0000000000a6fd84 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000a6fd94 01 00 00 00 00 00 00 00 - 4f d9 60 87 94 cd 05 43 ........O.`....C
0000000000a6fda4 00 00 00 00 97 b4 6b 9d - 6e ff f0 0b 01 00 00 00 ......k.n.......
0000000000a6fdb4 00 f0 fd 7f 00 a0 fd 7f - a4 01 00 00 51 fd a1 b3 ............Q...
0000000000a6fdc4 06 27 0f 72 99 c2 90 81 - fd 61 70 c5 75 6d 2f f5 .'.r.....ap.um/.
0000000000a6fdd4 80 d4 1c 63 8c 28 36 36 - bc fd a6 00 fe 90 fd be ...c.(66........
0000000000a6fde4 14 00 00 00 01 00 00 00 - 24 ff a6 00 00 00 00 00 ........$.......
0000000000a6fdf4 00 00 00 00 90 fd a6 00 - 90 3f 02 05 38 ff a6 00 .........?..8...
0000000000a6fe04 09 48 e7 77 78 32 e6 77 - 00 00 00 00 6c fe a6 00 .H.wx2.w....l...
0000000000a6fe14 eb 63 d1 77 01 00 00 00 - 38 fe a6 00 00 00 00 00 .c.w....8.......
0000000000a6fe24 ff ff ff ff 00 00 00 00 - 00 00 00 00 01 00 00 00 ................
0000000000a6fe34 d1 bd a9 70 a4 01 00 00 - b0 fe a6 00 00 00 00 00 ...p............
0000000000a6fe44 00 04 00 00 06 04 00 00 - 01 00 00 00 00 00 00 00 ................
0000000000a6fe54 00 a0 fd 7f d1 bd a9 70 - 00 00 00 00 00 00 00 00 .......p........
0000000000a6fe64 00 a0 fd 7f a4 01 00 00 - 88 fe a6 00 66 64 d1 77 ............fd.w
0000000000a6fe74 00 00 00 00 00 00 00 00 - ff ff ff ff ff 00 00 00 ................
0000000000a6fe84 38 fe a6 00 e0 fe a6 00 - 07 fa 50 71 00 00 00 00 8.........Pq....
0000000000a6fe94 00 00 00 00 00 00 00 00 - ff ff ff ff ff 00 00 00 ................
0000000000a6fea4 00 00 00 00 98 d7 0a 00 - 98 d7 0a 00 e8 0e cd 7c ...............|



Anwendungsausnahme aufgetreten:
Anwendung: C:\WINDOWS\System32\taskmgr.exe (pid=620)
Wann: 22.02.2004 @ 22:37:38.234
Ausnahmenummer: c0000005 (Zugriffsverletzung)

*----> Systeminformationen <----*
Computername: RMA
Benutzername: Ramzy
Terminalsitzungskennung: 0
Prozessoranzahl: 2
Prozessortyp: x86 Family 15 Model 2 Stepping 9
Windows-Version: 5.1
Aktuelles Build: 2600
Service Pack: 1
Aktueller Typ: Multiprocessor Free
Firma: Privat
Besitzer: R.M

*----> Taskliste <----*
0 System Process
4 System
604 smss.exe
660 csrss.exe
684 winlogon.exe
728 services.exe
740 savedump.exe
764 lsass.exe
924 Ati2evxx.exe
948 svchost.exe
1052 svchost.exe
1220 svchost.exe
1252 svchost.exe
1440 spoolsv.exe
1820 Ati2evxx.exe
620 taskmgr.exe
816 drwtsn32.exe

*----> Modulliste <----*
(0000000001000000 - 0000000001024000: C:\WINDOWS\System32\taskmgr.exe
(000000005b0d0000 - 000000005b0d9000: C:\WINDOWS\System32\VDMDBG.dll
(000000005b0f0000 - 000000005b124000: C:\WINDOWS\System32\uxtheme.dll
(000000005b130000 - 000000005b13a000: C:\WINDOWS\System32\UTILDLL.dll
(0000000070a70000 - 0000000070ad5000: C:\WINDOWS\system32\SHLWAPI.dll
(0000000071a00000 - 0000000071a08000: C:\WINDOWS\System32\WS2HELP.dll
(0000000071a10000 - 0000000071a25000: C:\WINDOWS\System32\WS2_32.dll
(0000000071b70000 - 0000000071b81000: C:\WINDOWS\System32\SAMLIB.dll
(0000000071ba0000 - 0000000071bee000: C:\WINDOWS\System32\NETAPI32.dll
(0000000074a60000 - 0000000074a67000: C:\WINDOWS\System32\cfgmgr32.dll
(0000000076300000 - 000000007630f000: C:\WINDOWS\System32\WINSTA.dll
(0000000076620000 - 0000000076708000: C:\WINDOWS\System32\SETUPAPI.dll
(0000000076af0000 - 0000000076b1d000: C:\WINDOWS\System32\WINMM.dll
(0000000076d20000 - 0000000076d37000: C:\WINDOWS\System32\iphlpapi.dll
(0000000076e40000 - 0000000076e4d000: C:\WINDOWS\System32\rtutils.dll
(0000000076e70000 - 0000000076e9b000: C:\WINDOWS\System32\TAPI32.dll
(0000000076f10000 - 0000000076f18000: C:\WINDOWS\System32\WTSAPI32.dll
(0000000076f50000 - 0000000076f60000: C:\WINDOWS\System32\Secur32.dll
(00000000773a0000 - 0000000077b9c000: C:\WINDOWS\system32\SHELL32.dll
(0000000077bd0000 - 0000000077bd7000: C:\WINDOWS\system32\VERSION.dll
(0000000077be0000 - 0000000077c33000: C:\WINDOWS\system32\msvcrt.dll
(0000000077c40000 - 0000000077c80000: C:\WINDOWS\system32\GDI32.dll
(0000000077d10000 - 0000000077d9c000: C:\WINDOWS\system32\USER32.dll
(0000000077da0000 - 0000000077e3c000: C:\WINDOWS\system32\ADVAPI32.dll
(0000000077e40000 - 0000000077f38000: C:\WINDOWS\system32\kernel32.dll
(0000000077f40000 - 0000000077fee000: C:\WINDOWS\System32\ntdll.dll
(0000000078000000 - 0000000078086000: C:\WINDOWS\system32\RPCRT4.dll
(0000000078090000 - 0000000078174000: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805\COMCTL32.dll

*----> Statusabbild für Threadkennung 0x274 <----*

eax=0006e974 ebx=0006ead0 ecx=0006ead0 edx=00800980 esi=00000000 edi=020103d9
eip=77d1708d esp=0006e958 ebp=0006e9f0 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\USER32.dll -
Funktion: USER32!SendMessageTimeoutW
No prior disassembly possible
77d1708d 650100 add gs:[eax],eax
77d17090 0085c00f842f add [ebp+0x2f840fc0],al
77d17096 0300 add eax,[eax]
77d17098 0039 add [ecx],bh
77d1709a 75a4 jnz USER32!SendMessageTimeoutW+0x20 (77d17040)
77d1709c 8b4520 mov eax,[ebp+0x20]
77d1709f 8945bc mov [ebp-0x44],eax
77d170a2 0f8e01050000 jle USER32!DrawTextExW+0x87 (77d175a9)
77d170a8 8b4518 mov eax,[ebp+0x18]
FEHLER ->*** ERROR: Module load completed but symbols could not be loaded for C:\WINDOWS\System32\taskmgr.exe
77d1708d 650100 add gs:[eax],eax gs:0006e974=00000000
77d17090 0085c00f842f add [ebp+0x2f840fc0],al
77d17096 0300 add eax,[eax]
77d17098 0039 add [ecx],bh
77d1709a 75a4 jnz USER32!SendMessageTimeoutW+0x20 (77d17040)
77d1709c 8b4520 mov eax,[ebp+0x20]
77d1709f 8945bc mov [ebp-0x44],eax
77d170a2 0f8e01050000 jle USER32!DrawTextExW+0x87 (77d175a9)
77d170a8 8b4518 mov eax,[ebp+0x18]
77d170ab 2500000200 and eax,0x20000
77d170b0 8945d4 mov [ebp-0x2c],eax

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\System32\uxtheme.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805\COMCTL32.dll -
ChildEBP RetAddr Args to Child
0006e9f0 77d1753e 020103d9 0006ead0 00000000 USER32!SendMessageTimeoutW+0x6d
0006ea14 5b0f28b8 020103d9 0006ead0 ffffffff USER32!DrawTextExW+0x1c
0006ea58 5b0f2828 00774708 020103d9 00000000 uxtheme!GetThemeTextExtent+0x143
0006ea98 780a75ec 00800980 020103d9 00000000 uxtheme!GetThemeTextExtent+0xb3
0006ebf4 00000000 00000000 00000000 0006ee4c COMCTL32!CreateStatusWindowA+0x2d6

*----> Raw Stack Dump <----*
000000000006e958 40 ea 06 00 20 04 00 00 - 74 e9 06 00 00 00 00 00 @... ...t.......
000000000006e968 50 ea 06 00 00 00 00 00 - 20 04 00 00 00 00 00 00 P....... .......
000000000006e978 f0 e9 06 00 6f 22 0f 5b - 54 1c 82 00 4c 1a 82 00 ....o".[T...L...
000000000006e988 01 00 00 00 08 47 77 00 - d9 03 01 02 99 01 85 03 .....Gw.........
000000000006e998 cc e9 06 00 00 00 00 00 - bc e9 06 00 00 00 00 00 ................
000000000006e9a8 54 e7 06 00 00 00 00 00 - d9 03 01 02 50 1c 82 00 T...........P...
000000000006e9b8 08 47 77 00 32 00 00 00 - 11 00 00 00 05 00 00 00 .Gw.2...........
000000000006e9c8 09 00 00 00 00 00 00 00 - 00 00 00 00 8c 01 00 00 ................
000000000006e9d8 17 00 00 00 8c 01 00 00 - 17 00 00 00 01 00 00 00 ................
000000000006e9e8 00 00 80 3f 4c 1a 82 00 - 14 ea 06 00 3e 75 d1 77 ...?L.......>u.w
000000000006e9f8 d9 03 01 02 d0 ea 06 00 - 00 00 00 00 40 ea 06 00 ............@...
000000000006ea08 20 04 00 00 00 00 00 00 - ff ff ff ff 58 ea 06 00 ...........X...
000000000006ea18 b8 28 0f 5b d9 03 01 02 - d0 ea 06 00 ff ff ff ff .(.[............
000000000006ea28 40 ea 06 00 20 04 00 00 - 00 00 00 00 ff ff ff ff @... ...........
000000000006ea38 0d 5b e5 77 00 00 00 00 - 00 00 00 00 00 00 00 00 .[.w............
000000000006ea48 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000006ea58 98 ea 06 00 28 28 0f 5b - 08 47 77 00 d9 03 01 02 ....((.[.Gw.....
000000000006ea68 00 00 00 00 00 00 00 00 - d0 ea 06 00 ff ff ff ff ................
000000000006ea78 00 00 00 00 f0 eb 06 00 - f0 eb 06 00 00 ec 06 00 ................
000000000006ea88 d0 ea 06 00 00 00 00 00 - 02 00 00 00 f0 eb 06 00 ................

*----> Statusabbild für Threadkennung 0x280 <----*

eax=00000d24 ebx=00000000 ecx=00000000 edx=00000000 esi=0089ff94 edi=0089f824
eip=7ffe0304 esp=0089f42c ebp=0089f448 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202

Funktion: <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 9c pushfd
7ffe0306 810c2400010000 or dword ptr [esp],0x100
7ffe030d 9d popfd
7ffe030e c3 ret
7ffe030f 8bd4 mov edx,esp
7ffe0311 0f05 syscall
7ffe0313 c3 ret
7ffe0314 9c pushfd
7ffe0315 810c2400010000 or dword ptr [esp],0x100
7ffe031c 9d popfd

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\kernel32.dll -
ChildEBP RetAddr Args to Child
0089f428 77d13a09 77d13c7d 0089ff94 00000000 *SharedUserSystemCall+0xc (FPO: [0,0,0])
0089f448 0100e612 0089ff94 00000000 00000000 USER32+0x3a09
0089ffb4 77e5d33b 00000000 77d18cd0 77d1b7d2 taskmgr+0xe612
0089ffec 00000000 0100e3cb 00000000 00000000 kernel32!RegisterWaitForInputIdle+0x43

*----> Raw Stack Dump <----*
000000000089f42c 09 3a d1 77 7d 3c d1 77 - 94 ff 89 00 00 00 00 00 .:.w}<.w........
000000000089f43c 00 00 00 00 00 00 00 00 - 79 7e 44 77 b4 ff 89 00 ........y~Dw....
000000000089f44c 12 e6 00 01 94 ff 89 00 - 00 00 00 00 00 00 00 00 ................
000000000089f45c 00 00 00 00 d0 8c d1 77 - d2 b7 d1 77 00 00 00 00 .......w...w....
000000000089f46c b8 03 00 00 2e 01 02 00 - 00 00 00 00 0e 00 00 00 ................
000000000089f47c 00 00 00 00 7d 00 02 00 - 43 00 50 00 55 00 2d 00 ....}...C.P.U.-.
000000000089f48c 41 00 75 00 73 00 6c 00 - 61 00 73 00 74 00 75 00 A.u.s.l.a.s.t.u.
000000000089f49c 6e 00 67 00 3a 00 20 00 - 33 00 25 00 00 00 00 00 n.g.:. .3.%.....
000000000089f4ac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000089f4bc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000089f4cc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000089f4dc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000089f4ec 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000089f4fc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000089f50c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000089f51c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000089f52c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000089f53c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000089f54c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000089f55c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

*----> Statusabbild für Threadkennung 0x284 <----*

eax=00461a40 ebx=77e55e37 ecx=002701f8 edx=00000000 esi=0000008c edi=00000000
eip=7ffe0304 esp=0090ff28 ebp=0090ff8c iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202

Funktion: <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 9c pushfd
7ffe0306 810c2400010000 or dword ptr [esp],0x100
7ffe030d 9d popfd
7ffe030e c3 ret
7ffe030f 8bd4 mov edx,esp
7ffe0311 0f05 syscall
7ffe0313 c3 ret
7ffe0314 9c pushfd
7ffe0315 810c2400010000 or dword ptr [esp],0x100
7ffe031c 9d popfd

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\System32\ntdll.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0090ff24 77f4c534 77e5a62d 0000008c 00000000 *SharedUserSystemCall+0xc (FPO: [0,0,0])
0090ff8c 77e5ac21 0000008c ffffffff 00000000 ntdll!NtWaitForSingleObject+0xc
0090ffec 00000000 0100c965 00094d44 00000000 kernel32!WaitForSingleObject+0xf

*----> Raw Stack Dump <----*
000000000090ff28 34 c5 f4 77 2d a6 e5 77 - 8c 00 00 00 00 00 00 00 4..w-..w........
000000000090ff38 00 00 00 00 12 ac e5 77 - 44 4d 09 00 37 5e e5 77 .......wDM..7^.w
000000000090ff48 00 00 00 00 00 00 00 00 - 7a cf 4f 80 00 00 00 00 ........z.O.....
000000000090ff58 00 f0 fd 7f 00 c0 fd 7f - 14 00 00 00 01 00 00 00 ................
000000000090ff68 00 00 00 00 00 00 00 00 - 10 00 00 00 3c ff 90 00 ............<...
000000000090ff78 00 9c d8 81 dc ff 90 00 - 09 48 e7 77 e0 3a e6 77 .........H.w.:.w
000000000090ff88 00 00 00 00 ec ff 90 00 - 21 ac e5 77 8c 00 00 00 ........!..w....
000000000090ff98 ff ff ff ff 00 00 00 00 - 9b c9 00 01 8c 00 00 00 ................
000000000090ffa8 ff ff ff ff 68 b3 46 00 - 7c b3 46 00 44 4d 09 00 ....h.F.|.F.DM..
000000000090ffb8 3b d3 e5 77 44 4d 09 00 - 68 b3 46 00 7c b3 46 00 ;..wDM..h.F.|.F.
000000000090ffc8 44 4d 09 00 00 00 00 00 - 00 c0 fd 7f c0 ff 90 00 DM..............
000000000090ffd8 07 00 00 00 ff ff ff ff - 09 48 e7 77 b8 3d e6 77 .........H.w.=.w
000000000090ffe8 00 00 00 00 00 00 00 00 - 00 00 00 00 65 c9 00 01 ............e...
000000000090fff8 44 4d 09 00 00 00 00 00 - 03 00 00 00 e0 8a 0a 00 DM..............
0000000000910008 03 00 00 00 68 fa 0a 00 - 03 00 00 00 18 fc 0a 00 ....h...........
0000000000910018 03 00 00 00 98 fc 0a 00 - 03 00 00 00 18 fd 0a 00 ................
0000000000910028 03 00 00 00 d0 03 0b 00 - 03 00 00 00 80 05 0b 00 ................
0000000000910038 03 00 00 00 30 07 0b 00 - 03 00 00 00 e0 08 0b 00 ....0...........
0000000000910048 03 00 00 00 90 0a 0b 00 - 03 00 00 00 40 0c 0b 00 ............@...
0000000000910058 03 00 00 00 f0 0d 0b 00 - 03 00 00 00 a0 0f 0b 00 ................



Anwendungsausnahme aufgetreten:
Anwendung: D:\FILES\SETUP\OSE.EXE (pid=1316)
Wann: 22.02.2004 @ 22:57:27.390
Ausnahmenummer: c0000005 (Zugriffsverletzung)

*----> Systeminformationen <----*
Computername: RMA
Benutzername: Ramzy
Terminalsitzungskennung: 0
Prozessoranzahl: 2
Prozessortyp: x86 Family 15 Model 2 Stepping 9
Windows-Version: 5.1
Aktuelles Build: 2600
Service Pack: 1
Aktueller Typ: Multiprocessor Free
Firma: Privat
Besitzer: R.M

*----> Taskliste <----*
0 System Process
4 System
604 sms
Fatima Mansour
 
Posts: 4
Joined: Tue Oct 24, 2006 7:59 pm
Location: Dublin

Postby VDO » Tue Oct 24, 2006 10:19 pm

Fatima, I'm downloading the dump. Tell Ramzy it is very good idea to use SendSpace! It transforms this forum into distributed dump analysis workspace :-)
VDO
Site Admin
 
Posts: 552
Joined: Mon May 01, 2006 10:34 am
Location: Dublin, Ireland

Postby VDO » Tue Oct 24, 2006 10:51 pm

Unfortunately the dump is corrupt:

Image

You probably should have zipped it before uploading to SendSpace or checked it beforehand by using Citrix DumpCheck (download requires free registration):

http://support.citrix.com/article/CTX108825

or

http://support.citrix.com/article/CTX108890
Last edited by VDO on Tue Oct 24, 2006 11:42 pm, edited 1 time in total.
VDO
Site Admin
 
Posts: 552
Joined: Mon May 01, 2006 10:34 am
Location: Dublin, Ireland

Postby VDO » Tue Oct 24, 2006 10:56 pm

Also I see only explorer.exe and taskmgr.exe crashes (log could have been truncated) and that happend long time ago: 22.02.2004 @ 22:37 or your log is so big that it still keeps old crashes.
In case your Dr. Watson doesn't work anymore or overwrites dump files you need to set up NTSD as a default debugger:

http://support.citrix.com/article/CTX105888
VDO
Site Admin
 
Posts: 552
Joined: Mon May 01, 2006 10:34 am
Location: Dublin, Ireland

Postby Fatima Mansour » Wed Oct 25, 2006 9:12 am

Thanks ! he, he.. the idea of Sendspace was mine.. He didn't want that I used it... :D, but I could not think about another way to upload the file.

I will zip and upload the file again! But.. uhm, uhm... whatever information you have, I will not understand anyway... so I will have to wait until Ramzy comes and check it for me! Just sending the messages you know! :wink: Thanks!
Fatima Mansour
 
Posts: 4
Joined: Tue Oct 24, 2006 7:59 pm
Location: Dublin

Postby Fatima Mansour » Sat Oct 28, 2006 4:23 pm

Hey dmitry,

Sorry for taking so long... it was my fault!
Ramzy said you were waiting for it!

I hope it works now, there you go the link:

http://www.sendspace.com/file/hvhl5w

Have a good weekend!
Fatima Mansour
 
Posts: 4
Joined: Tue Oct 24, 2006 7:59 pm
Location: Dublin

Postby VDO » Sun Oct 29, 2006 2:07 pm

Hi Fatima,

The dump is unfortunately corrupt but Dr. Watson shows the problem DLL: ulPPMgr.dll (vstudio.exe). You might need to upgrade your Ulead VideoStudio 10 :-)

Code: Select all
FEHLER ->04e924cc 8b86ac010000     mov     eax,[esi+0x1ac]   ds:0023:000001ac=????????

01b7aec0 01bade90 0000012c 00000162 1dfd7dc4 ulPPMgr+0x24cc


I have found people already experienced exactly the same crash (at ulPPMgr+0x24cc):

http://phpbb.ulead.com.tw/EN/viewtopic.php?t=14435

Thanks,
Dmitry
VDO
Site Admin
 
Posts: 552
Joined: Mon May 01, 2006 10:34 am
Location: Dublin, Ireland

Thanks!

Postby Fatima Mansour » Mon Oct 30, 2006 7:42 pm

Hi dmitry

Thank you very much! Sorry that the dump was corrupt, next time we will check better... we will use your dumpcheck.

Unfortunately seems that there's no solution posted on the Ulead Forum yet. So Ramzy said we will still bother you... :D

greetings from us
Fatima Mansour
 
Posts: 4
Joined: Tue Oct 24, 2006 7:59 pm
Location: Dublin


Return to User mode dumps

Who is online

Users browsing this forum: No registered users and 0 guests

cron