This is a read-only archive. No new posts or registrations. Privacy Page
Software

IE 7 crashes

47 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Rorschach112 helped me rid my machine of some unsavory nasties. In the process my IE7 no longer works. When I bring it up, I get an unhandled win32 exception in iexplore.exe [3592]. When I click ok on that dialog, the browser crashes.

This started occuring on the last OTMoveit operation I performed (before that operation IE worked fine).

There is a log of what the OTMoveit did from that thread (look at the last log I posted):
http://forums.whatthetech.com/not_sure_wha…15&start=15

Any help would be most appreciated. I tried uninstalling IE7 and reinstalling it, but didn't help. I also ran Netscape Nav. 7.2 (old version) and it let me browse some but also crashed after a few pages.
Hi kingme

That doesn't sound good. I'll explain me a bit, so you'll have a better picture on what is going on.

All error messages with the "unhandled exception" points to the fact that something is interrupting
the process or the data for the CPU. When this happens, the program will often try to access JIT
debugger (JIT: Just in Time), in this case IE7. Failing to do so, it crashes instead. Reason why this
is bad, is because normally programmers makes coding for the program to access this JIT
debugger in order to try handle the error. Failing to do so, indicates a rare or at least a uncommon
problem causing this. Outcome, may be you have to repair or re-install you OS to get rid of the error.

To discover the type of Errors the machine has encountered recently, use Event Viewer.
  • Go to Start - Run, type eventvwr.msc, then Press Enter.
  • When the Event Viewer opens, there will be two panes.
    The left pane is for event categories (Application, Security, and System).
    The right pane is for event messages (Information, Warning, and Error). (We want to find errors.)
  • Left-click the Application category in the left pane and check for any error messages in the right pane.
    You want to find the one(s) that occurred at the same time your system encountered the problem you have posted about.
  • Repeat the previous step for each category, or until you find an appropriate error to investigate.
  • Double-click the error message to bring up the information.
  • Click the third button on the right side of the information window (copies information)
  • Paste the information here

This might shed some light.

You should also try go to the windows update page, via start, and install / re-install any critical updates, if any.
It is likely the error may belong to .Netframework or a windows Service-Pack. (The most likely causes, but other
exists as well) So lets have a look on those first, when you have performed the above.

Regards
Thanks for the assistance!

There wasn't much more in the eventvwr then what I got in the popup:

Application popup: Visual Studio Just-In-Time Debugger : An unhandled win32 exception occurred in iexplore.exe [2952]. Just-In-Time debugging this exception failed with the following error: No installed debugger has Just-In-Time debugging enabled. In Visual Studio, Just-In-Time debugging can be enabled from Tools/Options/Debugging/Just-In-Time.

Check the documentation index for 'Just-in-time debugging, errors' for more information.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.




I also went and installed XP SP3, but that didn't change anything.

Currently, I'm using Firefox as my browser and that seems unaffected by this problem. I don't mind sticking with this browser, but would like to know what happened to IE7 and what might fix it.
Just to note, I was getting assistance with some infections I had on my machine and in the process we ran an OTMoveit3. Before this was run my IE was working fine. Afterwards, it started giving this error. Maybe there is something in the OTMoveit3 log that might give a clue? ========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== DllUnregisterServer procedure not found in C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\ChkDisk.dll C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\ChkDisk.dll NOT unregistered. C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\ChkDisk.dll moved successfully. C:\WINDOWS\system32\MPh.exe moved successfully. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\NAILogs\UpdaterUI_NEILG.log scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\Arj.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\avlib.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\Avp1.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\AvpMgr.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\btimages.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\CAB.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\dmap.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\dtreg.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\FsDrvPlg.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\FSSync.dll scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\HashCont.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\HashMD5.PPL scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\HCCMP.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\ichk2.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\iChkSA.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\Inflate.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\IWGen.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\kave.dll scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\kosglue-7.0.25.0.dll scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\lha.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\L_llio.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\MailMsg.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\mdb.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\MDMAP.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\MemModSc.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\MemScan.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\minizip.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\MKavIO.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\msoe.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\nfio.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\NTFSstrm.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\prKernel.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\prLoader.dll scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\prseqio.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\PrUtil.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\Quantum.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\rar.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\ScanningProcess.exe scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\sfdb.PPL scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\TempFile.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\thpimpl.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\UniArc.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\UnLZX.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\UnStored.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\WDiskIO.ppl scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\hsperfdata_neilg\2572 scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\Google Toolbar\gtb103.tmp.exe scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\Google Toolbar\gtb36F.tmp.exe scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\Google Toolbar\gtb45F.tmp.exe scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\fla480.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\me_ scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\me_0I8VWVBlIaUSnKE scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\me_7onBbL0w scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\neilg\LOCALS~1\Temp\me_IUpzWEzQyrbuMNl scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\Google Toolbar\gtm104.tmp scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\Google Toolbar\gtm370.tmp scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\Google Toolbar\gtm460.tmp scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\GoogleToolbarInstaller2.log scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\ssjs-service.log scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\WFV46B.tmp scheduled to be deleted on reboot. Windows Temp folder emptied. File delete failed. C:\Documents and Settings\neilg\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\kos-main.jar-a28c4e6-443b852b.zip scheduled to be deleted on reboot. Java cache emptied. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03182009_161525 Files moved on Reboot… C:\DOCUME~1\neilg\LOCALS~1\Temp\NAILogs\UpdaterUI_NEILG.log moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\Arj.ppl moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\avlib.ppl moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\Avp1.ppl moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\AvpMgr.ppl moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\btimages.ppl moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\CAB.ppl moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\dmap.ppl moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\dtreg.ppl moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\FsDrvPlg.ppl moved successfully. DllUnregisterServer procedure not found in C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\FSSync.dll C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\FSSync.dll NOT unregistered. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\FSSync.dll moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\HashCont.ppl moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\HashMD5.PPL moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\HCCMP.ppl moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\ichk2.ppl moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\iChkSA.ppl moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\Inflate.ppl moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\IWGen.ppl moved successfully. DllUnregisterServer procedure not found in C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\kave.dll C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\kave.dll NOT unregistered. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\kave.dll moved successfully. DllUnregisterServer procedure not found in C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\kosglue-7.0.25.0.dll C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\kosglue-7.0.25.0.dll NOT unregistered. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\kosglue-7.0.25.0.dll moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\lha.ppl moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\L_llio.ppl moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\MailMsg.ppl moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\mdb.ppl moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\MDMAP.ppl moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\MemModSc.ppl moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\MemScan.ppl moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\minizip.ppl moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\MKavIO.ppl moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\msoe.ppl moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\nfio.ppl moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\NTFSstrm.ppl moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\prKernel.ppl moved successfully. DllUnregisterServer procedure not found in C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\prLoader.dll C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\prLoader.dll NOT unregistered. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\prLoader.dll moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\prseqio.ppl moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\PrUtil.ppl moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\Quantum.ppl moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\rar.ppl moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\ScanningProcess.exe moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\sfdb.PPL moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\TempFile.ppl moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\thpimpl.ppl moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\UniArc.ppl moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\UnLZX.ppl moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\UnStored.ppl moved successfully. C:\DOCUME~1\neilg\LOCALS~1\Temp\jkos-neilg\binaries\WDiskIO.ppl moved successfully. File C:\DOCUME~1\neilg\LOCALS~1\Temp\hsperfdata_neilg\2572 not found! File C:\DOCUME~1\neilg\LOCALS~1\Temp\Google Toolbar\gtb103.tmp.exe not found! File C:\DOCUME~1\neilg\LOCALS~1\Temp\Google Toolbar\gtb36F.tmp.exe not found! File C:\DOCUME~1\neilg\LOCALS~1\Temp\Google Toolbar\gtb45F.tmp.exe not found! File C:\DOCUME~1\neilg\LOCALS~1\Temp\fla480.tmp not found! File C:\DOCUME~1\neilg\LOCALS~1\Temp\me_ not found! File C:\DOCUME~1\neilg\LOCALS~1\Temp\me_0I8VWVBlIaUSnKE not found! File C:\DOCUME~1\neilg\LOCALS~1\Temp\me_7onBbL0w not found! File C:\DOCUME~1\neilg\LOCALS~1\Temp\me_IUpzWEzQyrbuMNl not found! File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. File C:\WINDOWS\temp\Google Toolbar\gtm104.tmp not found! File C:\WINDOWS\temp\Google Toolbar\gtm370.tmp not found! File C:\WINDOWS\temp\Google Toolbar\gtm460.tmp not found! C:\WINDOWS\temp\GoogleToolbarInstaller2.log moved successfully. File move failed. C:\WINDOWS\temp\ssjs-service.log scheduled to be moved on reboot. File C:\WINDOWS\temp\WFV46B.tmp not found! C:\Documents and Settings\neilg\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\kos-main.jar-a28c4e6-443b852b.zip moved successfully.
Hi kingme

Firstly, before we do anything else, we have to make sure that "Dr.Watson" is going to handle
all 3rd party debugging instead of Visual studio. To do this, follow directions below.

Go to start, choose RUN, then type: drwtsn32 -i (note the space between 32 and -i)

Reboot, and try open IE7.

If lucky, this should do the trick.

As for the log, it can't tell us much, as all those files listed are TEMP.Files, and deleted.

Regards
Dr. Watson is now capturing it (but didn't fix it) Not sure if any of this is useful, but here is the log from the dump: Application exception occurred: App: C:\Program Files\Internet Explorer\iexplore.exe (pid=4108) When: 3/19/2009 @ 13:53:13.359 Exception number: c0000005 (access violation) *—-> System Information <—-* Computer Name: NEILG User Name: neilg Terminal Session Id: 0 Number of Processors: 1 Processor Type: x86 Family 15 Model 2 Stepping 7 Windows Version: 5.1 Current Build: 2600 Service Pack: 3 Current Type: Uniprocessor Free Registered Organization: Avaya Labs Registered Owner: Avaya *—-> Task List <—-* 0 System Process 4 System 440 smss.exe 496 csrss.exe 520 winlogon.exe 564 services.exe 576 lsass.exe 732 Ati2evxx.exe 748 svchost.exe 804 svchost.exe 872 svchost.exe 932 svchost.exe 1004 svchost.exe 1140 AAWService.exe 1216 spoolsv.exe 1628 qntorbsvr.exe 1660 vmm_service.exe 1740 AvVpnService.exe 1804 cvpnd.exe 1856 cvsservice.exe 1868 cvslock.exe 1908 db2dasrrm.exe 1920 db2licd.exe 1936 db2sec.exe 1948 db2rcmd.exe 1976 dcfssvc.exe 2004 FireSvc.exe 2044 svchost.exe 156 ssjs-srv.exe 204 RAService.exe 220 ssjs.exe 388 inetinfo.exe 480 IntuitUpdateService.exe 624 FrameworkService.exe 1432 Mcshield.exe 1436 VsTskMgr.exe 1620 mnmsrvc.exe 1672 rundll32.exe 1748 naPrdMgr.exe 2112 sqlservr.exe 2144 mysqld-nt.exe 2208 sqlwriter.exe 2268 tardisnt.exe 2360 TiVoBeacon.exe 2528 WinVNC.exe 2592 Wuser32.exe 2696 CcmExec.exe 2776 db2syscs.exe 2852 db2jds.exe 2916 WMPNetwk.exe 3460 unsecapp.exe 3636 wmiprvse.exe 3784 alg.exe 4052 wmiprvse.exe 2448 wmiprvse.exe 3280 AAWTray.exe 3956 Ati2evxx.exe 3004 Explorer.EXE 2456 atiptaxx.exe 1644 jusched.exe 340 SHSTAT.EXE 3400 ATALauncher.exe 3776 Firetray.exe 716 UdaterUI.exe 1640 apdproxy.exe 3944 E_S4I2G1.EXE 3940 McTray.exe 300 qttask.exe 2800 msmsgs.exe 2140 launchpd.exe 3492 TiVoTransfer.exe 3676 TiVoNotify.exe 1172 GoogleToolbarNotifier.exe 888 ctfmon.exe 1460 SUPERAntiSpyware.exe 3960 rundll32.exe 3816 EasyShare.exe 5132 winmysqladmin.exe 1604 TiVoServer.exe 5444 firefox.exe 4108 iexplore.exe 976 drwtsn32.exe 4320 dwwin.exe *—-> Module List <—-* (00000000003d0000 - 00000000003d9000: C:\WINDOWS\system32\Normaliz.dll (0000000000400000 - 000000000049b000: C:\Program Files\Internet Explorer\iexplore.exe (0000000000c20000 - 0000000000ee5000: C:\WINDOWS\system32\xpsp2res.dll (0000000002840000 - 0000000002bbf000: c:\program files\google\googletoolbar1.dll (00000000031f0000 - 0000000003200000: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (0000000003210000 - 00000000032ab000: C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\MSVCR80.dll (0000000003ba0000 - 0000000003c58000: C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll (0000000003c70000 - 0000000003c8a000: C:\Program Files\Avaya\Avaya IP Softphone\AvayaWebDial.dll (000000000a000000 - 000000000a012000: C:\WINDOWS\system32\EntApi.dll (0000000010000000 - 0000000010008000: C:\DOCUME~1\neilg\protect.dll (0000000010930000 - 0000000010979000: C:\WINDOWS\system32\PortableDeviceApi.dll (0000000042ef0000 - 00000000434bd000: C:\WINDOWS\system32\IEFRAME.dll (0000000047060000 - 0000000047081000: C:\WINDOWS\system32\xmllite.dll (000000004ec50000 - 000000004edf6000: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5581_x-ww_dfbc4fc4\gdiplus.dll (0000000059a60000 - 0000000059b01000: C:\WINDOWS\system32\DBGHELP.DLL (000000005ad70000 - 000000005ada8000: C:\WINDOWS\system32\UxTheme.dll (000000005b860000 - 000000005b8b5000: C:\WINDOWS\system32\NETAPI32.dll (000000005d090000 - 000000005d12a000: C:\WINDOWS\system32\comctl32.dll (000000005dff0000 - 000000005e01f000: C:\WINDOWS\system32\IEUI.dll (000000005edd0000 - 000000005ede7000: C:\WINDOWS\system32\OLEPRO32.DLL (0000000061930000 - 000000006197a000: C:\Program Files\Internet Explorer\ieproxy.dll (00000000662b0000 - 0000000066308000: C:\WINDOWS\system32\hnetcfg.dll (0000000068000000 - 0000000068036000: C:\WINDOWS\system32\rsaenh.dll (0000000069450000 - 0000000069466000: C:\WINDOWS\system32\faultrep.dll (000000006d600000 - 000000006d62d000: C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (0000000071a50000 - 0000000071a8f000: C:\WINDOWS\system32\mswsock.dll (0000000071a90000 - 0000000071a98000: C:\WINDOWS\System32\wshtcpip.dll (0000000071aa0000 - 0000000071aa8000: C:\WINDOWS\system32\WS2HELP.dll (0000000071ab0000 - 0000000071ac7000: C:\WINDOWS\system32\WS2_32.dll (0000000071ad0000 - 0000000071ad9000: C:\WINDOWS\system32\WSOCK32.dll (0000000071b20000 - 0000000071b32000: C:\WINDOWS\system32\MPR.dll (0000000071bf0000 - 0000000071c03000: C:\WINDOWS\System32\SAMLIB.dll (0000000071c10000 - 0000000071c1e000: C:\WINDOWS\System32\ntlanman.dll (0000000071c80000 - 0000000071c87000: C:\WINDOWS\System32\NETRAP.dll (0000000071c90000 - 0000000071cd0000: C:\WINDOWS\System32\NETUI1.dll (0000000071cd0000 - 0000000071ce7000: C:\WINDOWS\System32\NETUI0.dll (0000000071d40000 - 0000000071d5b000: C:\WINDOWS\system32\actxprxy.dll (00000000722b0000 - 00000000722b5000: C:\WINDOWS\system32\sensapi.dll (00000000746f0000 - 000000007471a000: C:\WINDOWS\System32\msimtf.dll (0000000074720000 - 000000007476c000: C:\WINDOWS\system32\MSCTF.dll (0000000074980000 - 0000000074a94000: C:\WINDOWS\System32\msxml3.dll (00000000755c0000 - 00000000755ee000: C:\WINDOWS\system32\msctfime.ime (0000000075cf0000 - 0000000075d81000: C:\WINDOWS\system32\MLANG.dll (0000000075f60000 - 0000000075f67000: C:\WINDOWS\System32\drprov.dll (0000000075f70000 - 0000000075f7a000: C:\WINDOWS\System32\davclnt.dll (0000000076360000 - 0000000076370000: C:\WINDOWS\system32\WINSTA.dll (0000000076380000 - 0000000076385000: C:\WINDOWS\system32\MSIMG32.dll (0000000076390000 - 00000000763ad000: C:\WINDOWS\system32\IMM32.DLL (0000000076600000 - 000000007661d000: C:\WINDOWS\System32\CSCDLL.dll (0000000076990000 - 00000000769b5000: C:\WINDOWS\system32\ntshrui.dll (00000000769c0000 - 0000000076a74000: C:\WINDOWS\system32\USERENV.dll (0000000076b20000 - 0000000076b31000: C:\WINDOWS\system32\ATL.DLL (0000000076b40000 - 0000000076b6d000: C:\WINDOWS\system32\WINMM.dll (0000000076bf0000 - 0000000076bfb000: C:\WINDOWS\system32\PSAPI.DLL (0000000076c30000 - 0000000076c5e000: C:\WINDOWS\system32\WINTRUST.dll (0000000076c90000 - 0000000076cb8000: C:\WINDOWS\system32\imagehlp.dll (0000000076d60000 - 0000000076d79000: C:\WINDOWS\system32\iphlpapi.dll (0000000076e80000 - 0000000076e8e000: C:\WINDOWS\system32\rtutils.dll (0000000076e90000 - 0000000076ea2000: C:\WINDOWS\system32\rasman.dll (0000000076eb0000 - 0000000076edf000: C:\WINDOWS\system32\TAPI32.dll (0000000076ee0000 - 0000000076f1c000: C:\WINDOWS\system32\RASAPI32.dll (0000000076f20000 - 0000000076f47000: C:\WINDOWS\system32\DNSAPI.dll (0000000076f50000 - 0000000076f58000: C:\WINDOWS\system32\WTSAPI32.dll (0000000076fc0000 - 0000000076fc6000: C:\WINDOWS\system32\rasadhlp.dll (0000000076fd0000 - 000000007704f000: C:\WINDOWS\system32\CLBCATQ.DLL (0000000077050000 - 0000000077115000: C:\WINDOWS\system32\COMRes.dll (0000000077120000 - 00000000771ab000: C:\WINDOWS\system32\OLEAUT32.dll (00000000773d0000 - 00000000774d3000: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll (00000000774e0000 - 000000007761d000: C:\WINDOWS\system32\ole32.dll (0000000077920000 - 0000000077a13000: C:\WINDOWS\system32\SETUPAPI.dll (0000000077a20000 - 0000000077a74000: C:\WINDOWS\System32\cscui.dll (0000000077a80000 - 0000000077b15000: C:\WINDOWS\system32\CRYPT32.dll (0000000077b20000 - 0000000077b32000: C:\WINDOWS\system32\MSASN1.dll (0000000077b40000 - 0000000077b62000: C:\WINDOWS\system32\apphelp.dll (0000000077c00000 - 0000000077c08000: C:\WINDOWS\system32\VERSION.dll (0000000077c10000 - 0000000077c68000: C:\WINDOWS\system32\msvcrt.dll (0000000077c70000 - 0000000077c94000: C:\WINDOWS\system32\msv1_0.dll (0000000077dd0000 - 0000000077e6b000: C:\WINDOWS\system32\ADVAPI32.dll (0000000077e70000 - 0000000077f02000: C:\WINDOWS\system32\RPCRT4.dll (0000000077f10000 - 0000000077f59000: C:\WINDOWS\system32\GDI32.dll (0000000077f60000 - 0000000077fd6000: C:\WINDOWS\system32\SHLWAPI.dll (0000000077fe0000 - 0000000077ff1000: C:\WINDOWS\system32\Secur32.dll (0000000078000000 - 0000000078045000: C:\WINDOWS\system32\iertutil.dll (0000000078050000 - 0000000078120000: C:\WINDOWS\system32\WININET.dll (0000000078130000 - 0000000078257000: C:\WINDOWS\system32\urlmon.dll (000000007c800000 - 000000007c8f6000: C:\WINDOWS\system32\kernel32.dll (000000007c900000 - 000000007c9af000: C:\WINDOWS\system32\ntdll.dll (000000007c9c0000 - 000000007d1d7000: C:\WINDOWS\system32\SHELL32.dll (000000007d1e0000 - 000000007d49c000: C:\WINDOWS\system32\msi.dll (000000007e410000 - 000000007e4a1000: C:\WINDOWS\system32\USER32.dll (000000007e720000 - 000000007e7d0000: C:\WINDOWS\system32\SXS.DLL *—-> State Dump for Thread Id 0xed0 <—-* eax=71d4d9fc ebx=0012e6c4 ecx=0012d400 edx=0000001b esi=00000000 edi=7ffde000 eip=7c90e4f4 esp=0012e69c ebp=0012e738 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\ntdll.dll - function: ntdll!KiFastSystemCallRet 7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508) 7c90e4df 8b0424 mov eax,[esp] 7c90e4e2 8be5 mov esp,ebp 7c90e4e4 5d pop ebp 7c90e4e5 c3 ret 7c90e4e6 8da42400000000 lea esp,[esp] 7c90e4ed 8d4900 lea ecx,[ecx] ntdll!KiFastSystemCall: 7c90e4f0 8bd4 mov edx,esp 7c90e4f2 0f34 sysenter ntdll!KiFastSystemCallRet: 7c90e4f4 c3 ret 7c90e4f5 8da42400000000 lea esp,[esp] 7c90e4fc 8d642400 lea esp,[esp] ntdll!KiIntSystemCall: 7c90e500 8d542408 lea edx,[esp+0x8] 7c90e504 cd2e int 2e 7c90e506 c3 ret 7c90e507 90 nop ntdll!RtlRaiseException: 7c90e508 55 push ebp 7c90e509 8bec mov ebp,esp *—-> Stack Back Trace <—-* *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\USER32.dll - WARNING: Stack unwind information not available. Following frames may be wrong. *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\IEUI.dll - *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\IEFRAME.dll - *** ERROR: Module load completed but symbols could not be loaded for C:\Program Files\Internet Explorer\iexplore.exe *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\kernel32.dll - ChildEBP RetAddr Args to Child 0012e738 7e4195f9 00000002 0012e760 00000000 ntdll!KiFastSystemCallRet 0012e794 5dff6029 00000001 0012e7c8 ffffffff USER32!GetLastInputInfo+0x105 0012e7b4 5dff632d 000004ff ffffffff 00000000 IEUI!DUserRegisterSuper+0x9bd 0012e7dc 5dff60d8 000004ff 00000000 42fa992d IEUI!PeekMessageExW+0x21f 0012e818 42f9abac 00172ca8 0012e848 42f9bc1b IEUI!WaitMessageEx+0x31 0012e824 42f9bc1b 00000000 00000000 0015ef38 IEFRAME!Ordinal300+0xfb12 0012e848 42f9bb69 1ed0000b 0015ef38 00000000 IEFRAME!Ordinal101+0x341 0012f8b8 42f9ba19 0015ef38 77f648d4 00000000 IEFRAME!Ordinal101+0x28f 0012fae8 0040147c 00157798 00000001 00410070 IEFRAME!Ordinal101+0x13f 0012ff2c 00401317 00400000 00000000 00020b20 iexplore+0x147c 0012ffc0 7c817067 0144d15c 00000018 7ffde000 iexplore+0x1317 0012fff0 00000000 00402e45 00000000 78746341 kernel32!RegisterWaitForInputIdle+0x49 *—-> Raw Stack Dump <—-* 000000000012e69c 2c df 90 7c 74 95 80 7c - 02 00 00 00 c4 e6 12 00 ,..|t..|…….. 000000000012e6ac 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. 000000000012e6bc 02 00 00 00 00 00 00 00 - 58 01 00 00 28 00 00 00 ……..X…(… 000000000012e6cc 00 00 00 00 00 00 00 00 - a0 e6 12 00 00 00 00 00 ……………. 000000000012e6dc 30 e7 12 00 8f 04 44 7e - 14 00 00 00 01 00 00 00 0…..D~…….. 000000000012e6ec 00 00 00 00 00 00 00 00 - 10 00 00 00 37 6b ff 5d …………7k.] 000000000012e6fc 5a 06 03 00 0f 00 00 00 - 00 e0 fd 7f 00 d0 fd 7f Z…………… 000000000012e70c 9c e6 6d 00 00 00 00 00 - c4 e6 12 00 fc e7 12 00 ..m…………. 000000000012e71c 02 00 00 00 b8 e6 12 00 - ff ff ff ff b0 ff 12 00 ……………. 000000000012e72c c0 9a 83 7c 68 96 80 7c - 00 00 00 00 94 e7 12 00 …|h..|…….. 000000000012e73c f9 95 41 7e 02 00 00 00 - 60 e7 12 00 00 00 00 00 ..A~….`……. 000000000012e74c ff ff ff ff 00 00 00 00 - ff ff ff ff 01 00 00 00 ……………. 000000000012e75c 01 00 00 00 58 01 00 00 - 28 00 00 00 bd 62 ff 5d ….X…(….b.] 000000000012e76c 83 0c 5c 00 18 88 16 00 - 01 00 00 00 00 00 00 00 ..\…………. 000000000012e77c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. 000000000012e78c 00 d0 fd 7f 28 00 00 00 - b4 e7 12 00 29 60 ff 5d ….(…….)`.] 000000000012e79c 01 00 00 00 c8 e7 12 00 - ff ff ff ff ff 04 00 00 ……………. 000000000012e7ac 60 e7 12 00 88 4a 17 00 - dc e7 12 00 2d 63 ff 5d `….J……-c.] 000000000012e7bc ff 04 00 00 ff ff ff ff - 00 00 00 00 58 01 00 00 …………X… 000000000012e7cc 00 00 00 00 a8 78 f9 42 - a8 2c 17 00 9f 00 00 00 …..x.B.,…… *—-> State Dump for Thread Id 0xbf4 <—-* eax=00985884 ebx=00b7fed0 ecx=7ffdc000 edx=77e46660 esi=00000000 edi=7ffde000 eip=7c90e4f4 esp=00b7fea8 ebp=00b7ff44 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 function: ntdll!KiFastSystemCallRet 7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508) 7c90e4df 8b0424 mov eax,[esp] 7c90e4e2 8be5 mov esp,ebp 7c90e4e4 5d pop ebp 7c90e4e5 c3 ret 7c90e4e6 8da42400000000 lea esp,[esp] 7c90e4ed 8d4900 lea ecx,[ecx] ntdll!KiFastSystemCall: 7c90e4f0 8bd4 mov edx,esp 7c90e4f2 0f34 sysenter ntdll!KiFastSystemCallRet: 7c90e4f4 c3 ret 7c90e4f5 8da42400000000 lea esp,[esp] 7c90e4fc 8d642400 lea esp,[esp] ntdll!KiIntSystemCall: 7c90e500 8d542408 lea edx,[esp+0x8] 7c90e504 cd2e int 2e 7c90e506 c3 ret 7c90e507 90 nop ntdll!RtlRaiseException: 7c90e508 55 push ebp 7c90e509 8bec mov ebp,esp *—-> Stack Back Trace <—-* *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\ADVAPI32.dll - WARNING: Stack unwind information not available. Following frames may be wrong. ChildEBP RetAddr Args to Child 00b7ff44 77df8601 00000002 00b7ff6c 00000000 ntdll!KiFastSystemCallRet 00b7ffb4 7c80b713 00000000 7c91428f 00000000 ADVAPI32!WmiFreeBuffer+0x24e 00b7ffec 00000000 77df845a 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4 *—-> Raw Stack Dump <—-* 0000000000b7fea8 2c df 90 7c 74 95 80 7c - 02 00 00 00 d0 fe b7 00 ,..|t..|…….. 0000000000b7feb8 01 00 00 00 01 00 00 00 - 04 ff b7 00 e8 3e 98 00 ………….>.. 0000000000b7fec8 60 66 e4 77 00 10 00 00 - 64 00 00 00 6c 00 00 00 `f.w….d…l… 0000000000b7fed8 c0 fe b7 00 ec 6b 1a ae - dc ff b7 00 c0 9a 83 7c …..k………| 0000000000b7fee8 40 0b 81 7c ff ff ff ff - 14 00 00 00 01 00 00 00 @..|………… 0000000000b7fef8 00 00 00 00 00 00 00 00 - 10 00 00 00 00 a2 2f 4d …………../M 0000000000b7ff08 ff ff ff ff 00 10 00 00 - 00 e0 fd 7f 00 c0 fd 7f ……………. 0000000000b7ff18 00 10 00 00 04 ff b7 00 - d0 fe b7 00 88 66 e4 77 ………….f.w 0000000000b7ff28 02 00 00 00 c4 fe b7 00 - 20 00 00 00 dc ff b7 00 …….. ……. 0000000000b7ff38 c0 9a 83 7c 68 96 80 7c - 00 00 00 00 b4 ff b7 00 …|h..|…….. 0000000000b7ff48 01 86 df 77 02 00 00 00 - 6c ff b7 00 00 00 00 00 …w….l……. 0000000000b7ff58 e0 93 04 00 01 00 00 00 - 8f 42 91 7c 00 00 00 00 ………B.|…. 0000000000b7ff68 00 00 00 00 64 00 00 00 - 6c 00 00 00 00 10 00 00 ….d…l……. 0000000000b7ff78 e8 3e 98 00 00 00 00 00 - 00 10 00 00 e0 2e 98 00 .>………….. 0000000000b7ff88 e0 66 e4 77 58 00 00 00 - 00 67 e4 77 00 10 00 00 .f.wX….g.w…. 0000000000b7ff98 00 00 00 00 00 00 00 00 - e8 3e 98 00 00 67 e4 77 ………>…g.w 0000000000b7ffa8 e5 03 00 00 00 10 00 00 - e0 2e 98 00 ec ff b7 00 ……………. 0000000000b7ffb8 13 b7 80 7c 00 00 00 00 - 8f 42 91 7c 00 00 00 00 …|…..B.|…. 0000000000b7ffc8 00 00 00 00 00 c0 fd 7f - 00 06 bc 86 c0 ff b7 00 ……………. 0000000000b7ffd8 40 73 e7 84 ff ff ff ff - c0 9a 83 7c 20 b7 80 7c @s………| ..| *—-> State Dump for Thread Id 0xf88 <—-* eax=00160001 ebx=0115fde8 ecx=0016fd30 edx=00000001 esi=00000000 edi=7ffde000 eip=7c90e4f4 esp=0115fdc0 ebp=0115fe5c iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 function: ntdll!KiFastSystemCallRet 7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508) 7c90e4df 8b0424 mov eax,[esp] 7c90e4e2 8be5 mov esp,ebp 7c90e4e4 5d pop ebp 7c90e4e5 c3 ret 7c90e4e6 8da42400000000 lea esp,[esp] 7c90e4ed 8d4900 lea ecx,[ecx] ntdll!KiFastSystemCall: 7c90e4f0 8bd4 mov edx,esp 7c90e4f2 0f34 sysenter ntdll!KiFastSystemCallRet: 7c90e4f4 c3 ret 7c90e4f5 8da42400000000 lea esp,[esp] 7c90e4fc 8d642400 lea esp,[esp] ntdll!KiIntSystemCall: 7c90e500 8d542408 lea edx,[esp+0x8] 7c90e504 cd2e int 2e 7c90e506 c3 ret 7c90e507 90 nop ntdll!RtlRaiseException: 7c90e508 55 push ebp 7c90e509 8bec mov ebp,esp *—-> Stack Back Trace <—-* WARNING: Stack unwind information not available. Following frames may be wrong. *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\msvcrt.dll - ChildEBP RetAddr Args to Child 0115fe5c 7e4195f9 00000002 0115fe84 00000000 ntdll!KiFastSystemCallRet 0115feb8 5dff6029 00000001 0115feec ffffffff USER32!GetLastInputInfo+0x105 0115fed8 5dff93e4 000004ff ffffffff 00000001 IEUI!DUserRegisterSuper+0x9bd 0115ff0c 5dff98a6 0115ff4c 00000000 00000000 IEUI!SetGadgetParent+0x53d 0115ff2c 5dff9806 0115ff4c 00000000 00000000 IEUI!GetMessageExA+0x3d 0115ff80 77c3a3b0 00000000 7c910000 7c912cae IEUI!SetGadgetParent+0x95f 0115ffb4 7c80b713 0036cb08 7c910000 7c912cae msvcrt!endthreadex+0xa9 0115ffec 00000000 77c3a341 0036cb08 00000000 kernel32!GetModuleFileNameA+0x1b4 *—-> Raw Stack Dump <—-* 000000000115fdc0 2c df 90 7c 74 95 80 7c - 02 00 00 00 e8 fd 15 01 ,..|t..|…….. 000000000115fdd0 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. 000000000115fde0 02 00 00 00 04 00 00 00 - 50 01 00 00 4c 01 00 00 ……..P…L… 000000000115fdf0 00 00 00 00 0c fe 15 01 - 79 a2 ff 5d 59 00 01 01 ……..y..]Y… 000000000115fe00 90 04 00 00 30 00 00 00 - 14 00 00 00 01 00 00 00 ….0……….. 000000000115fe10 00 00 00 00 00 00 00 00 - 10 00 00 00 58 dd 12 00 …………X… 000000000115fe20 2c fe 15 01 c5 6f ff 5d - 00 e0 fd 7f 00 b0 fd 7f ,….o.]…….. 000000000115fe30 a2 6f ff 5d 00 00 00 00 - e8 fd 15 01 94 fe 15 01 .o.]………… 000000000115fe40 02 00 00 00 dc fd 15 01 - 63 6f ff 5d a4 ff 15 01 ……..co.]…. 000000000115fe50 c0 9a 83 7c 68 96 80 7c - 00 00 00 00 b8 fe 15 01 …|h..|…….. 000000000115fe60 f9 95 41 7e 02 00 00 00 - 84 fe 15 01 00 00 00 00 ..A~………… 000000000115fe70 ff ff ff ff 00 00 00 00 - ff ff ff ff 01 00 00 00 ……………. 000000000115fe80 01 00 00 00 50 01 00 00 - 4c 01 00 00 bd 62 ff 5d ….P…L….b.] 000000000115fe90 1d f6 5b 00 78 6e 16 00 - 01 00 00 00 00 00 00 00 ..[.xn………. 000000000115fea0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. 000000000115feb0 00 b0 fd 7f 4c 01 00 00 - d8 fe 15 01 29 60 ff 5d ….L…….)`.] 000000000115fec0 01 00 00 00 ec fe 15 01 - ff ff ff ff ff 04 00 00 ……………. 000000000115fed0 84 fe 15 01 b8 fc 16 00 - 0c ff 15 01 e4 93 ff 5d ……………] 000000000115fee0 ff 04 00 00 ff ff ff ff - 01 00 00 00 50 01 00 00 …………P… 000000000115fef0 00 00 00 00 00 00 00 00 - 08 cb 36 00 01 00 00 00 ……….6….. *—-> State Dump for Thread Id 0x1034 <—-* eax=00000000 ebx=00000000 ecx=0248fe18 edx=7c90e4f4 esi=0018aae0 edi=00000100 eip=7c90e4f4 esp=0248fe18 ebp=0248ff80 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 function: ntdll!KiFastSystemCallRet 7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508) 7c90e4df 8b0424 mov eax,[esp] 7c90e4e2 8be5 mov esp,ebp 7c90e4e4 5d pop ebp 7c90e4e5 c3 ret 7c90e4e6 8da42400000000 lea esp,[esp] 7c90e4ed 8d4900 lea ecx,[ecx] ntdll!KiFastSystemCall: 7c90e4f0 8bd4 mov edx,esp 7c90e4f2 0f34 sysenter ntdll!KiFastSystemCallRet: 7c90e4f4 c3 ret 7c90e4f5 8da42400000000 lea esp,[esp] 7c90e4fc 8d642400 lea esp,[esp] ntdll!KiIntSystemCall: 7c90e500 8d542408 lea edx,[esp+0x8] 7c90e504 cd2e int 2e 7c90e506 c3 ret 7c90e507 90 nop ntdll!RtlRaiseException: 7c90e508 55 push ebp 7c90e509 8bec mov ebp,esp *—-> Stack Back Trace <—-* *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\RPCRT4.dll - WARNING: Stack unwind information not available. Following frames may be wrong. ChildEBP RetAddr Args to Child 0248ff80 77e76caf 0248ffa8 77e76ad1 0018aae0 ntdll!KiFastSystemCallRet 0248ff88 77e76ad1 0018aae0 0012e420 0012df9c RPCRT4!I_RpcBCacheFree+0x61c 0248ffa8 77e76c97 0016b958 0248ffec 7c80b713 RPCRT4!I_RpcBCacheFree+0x43e 0248ffb4 7c80b713 0019ae08 0012e420 0012df9c RPCRT4!I_RpcBCacheFree+0x604 0248ffec 00000000 77e76c7d 0019ae08 00000000 kernel32!GetModuleFileNameA+0x1b4 *—-> Raw Stack Dump <—-* 000000000248fe18 8c da 90 7c e3 65 e7 77 - c4 02 00 00 74 ff 48 02 …|.e.w….t.H. 000000000248fe28 00 00 00 00 30 3a 22 00 - 50 ff 48 02 f0 fd fc 00 ….0:".P.H….. 000000000248fe38 10 00 00 00 00 00 00 00 - 00 00 00 00 b3 58 b9 b4 ………….X.. 000000000248fe48 18 6f ee 85 00 44 38 85 - 30 50 b9 b4 d0 47 39 85 .o…D8.0P…G9. 000000000248fe58 00 00 00 00 00 00 00 00 - 58 2b f5 ac 35 0c 6f 80 ……..X+..5.o. 000000000248fe68 00 00 00 00 00 00 00 00 - 58 2b f5 ac 00 00 00 00 ……..X+…… 000000000248fe78 e8 2b f5 ac 66 08 6f 80 - 00 0d db ba 00 00 00 00 .+..f.o……… 000000000248fe88 20 ef bf 86 90 3d 07 00 - 00 00 00 00 91 3d 07 00 ….=…….=.. 000000000248fe98 10 ee bf 86 a0 2b f5 ac - ad ae 54 80 08 c0 bf 86 …..+….T….. 000000000248fea8 ac ae 2b c0 9c c6 00 00 - 01 00 00 00 00 00 00 00 ..+…………. 000000000248feb8 00 00 00 00 54 fd fc 00 - 01 00 00 00 00 00 00 00 ….T……….. 000000000248fec8 00 00 00 00 e0 dc ed 84 - 60 17 5e 85 01 00 00 00 ……..`.^….. 000000000248fed8 e8 2b f5 ac 00 00 00 00 - 66 08 6f 80 08 00 00 00 .+……f.o….. 000000000248fee8 02 02 00 00 88 35 b9 b4 - 00 44 38 85 d0 76 37 85 …..5…D8..v7. 000000000248fef8 18 60 ba 84 00 3c e8 85 - 42 f0 b9 b4 e8 24 60 85 .`…<..B….$`. 000000000248ff08 e8 24 60 85 d0 76 37 85 - 50 08 6f 80 bc f1 ea 84 .$`..v7.P.o….. 000000000248ff18 24 2c f5 ac b2 c2 4d 80 - ba c2 4d 80 8c f1 ea 84 $,….M…M….. 000000000248ff28 20 f0 ea 84 80 ff 48 02 - ae df e7 77 48 ff 48 02 …..H….wH.H. 000000000248ff38 be df e7 77 e0 10 90 7c - 28 f5 1a 00 08 ae 19 00 …w…|(……. 000000000248ff48 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff ../M…..]…… *—-> State Dump for Thread Id 0xe88 <—-* eax=774fe43b ebx=00007530 ecx=7ffde000 edx=00000000 esi=00000000 edi=0258ff50 eip=7c90e4f4 esp=0258ff20 ebp=0258ff78 iopl=0 nv up ei pl nz na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000206 function: ntdll!KiFastSystemCallRet 7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508) 7c90e4df 8b0424 mov eax,[esp] 7c90e4e2 8be5 mov esp,ebp 7c90e4e4 5d pop ebp 7c90e4e5 c3 ret 7c90e4e6 8da42400000000 lea esp,[esp] 7c90e4ed 8d4900 lea ecx,[ecx] ntdll!KiFastSystemCall: 7c90e4f0 8bd4 mov edx,esp 7c90e4f2 0f34 sysenter ntdll!KiFastSystemCallRet: 7c90e4f4 c3 ret 7c90e4f5 8da42400000000 lea esp,[esp] 7c90e4fc 8d642400 lea esp,[esp] ntdll!KiIntSystemCall: 7c90e500 8d542408 lea edx,[esp+0x8] 7c90e504 cd2e int 2e 7c90e506 c3 ret 7c90e507 90 nop ntdll!RtlRaiseException: 7c90e508 55 push ebp 7c90e509 8bec mov ebp,esp *—-> Stack Back Trace <—-* WARNING: Stack unwind information not available. Following frames may be wrong. *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\ole32.dll - ChildEBP RetAddr Args to Child 0258ff78 7c802455 0000ea60 00000000 0258ffb4 ntdll!KiFastSystemCallRet 0258ff88 774fe32f 0000ea60 001b19a8 774fe3ee kernel32!Sleep+0xf 0258ffb4 7c80b713 001b19a8 7c910415 00150178 ole32!StringFromGUID2+0x51d 0258ffec 00000000 774fe43b 001b19a8 00000000 kernel32!GetModuleFileNameA+0x1b4 *—-> Raw Stack Dump <—-* 000000000258ff20 fc d1 90 7c f1 23 80 7c - 00 00 00 00 50 ff 58 02 …|.#.|….P.X. 000000000258ff30 50 25 80 7c f8 6d 60 77 - 30 75 00 00 14 00 00 00 P%.|.m`w0u…… 000000000258ff40 01 00 00 00 00 00 00 00 - 00 00 00 00 10 00 00 00 ……………. 000000000258ff50 00 ba 3c dc ff ff ff ff - 10 d1 4e 77 50 ff 58 02 ..<…….NwP.X. 000000000258ff60 30 ff 58 02 a8 26 1b 00 - dc ff 58 02 c0 9a 83 7c 0.X..&….X….| 000000000258ff70 60 24 80 7c 00 00 00 00 - 88 ff 58 02 55 24 80 7c `$.|……X.U$.| 000000000258ff80 60 ea 00 00 00 00 00 00 - b4 ff 58 02 2f e3 4f 77 `………X./.Ow 000000000258ff90 60 ea 00 00 a8 19 1b 00 - ee e3 4f 77 00 00 00 00 `………Ow…. 000000000258ffa0 15 04 91 7c a8 19 1b 00 - 00 00 4e 77 56 e4 4f 77 …|……NwV.Ow 000000000258ffb0 78 01 15 00 ec ff 58 02 - 13 b7 80 7c a8 19 1b 00 x…..X….|…. 000000000258ffc0 15 04 91 7c 78 01 15 00 - a8 19 1b 00 00 90 fd 7f …|x……….. 000000000258ffd0 00 06 bc 86 c0 ff 58 02 - 70 51 e1 84 ff ff ff ff ……X.pQ…… 000000000258ffe0 c0 9a 83 7c 20 b7 80 7c - 00 00 00 00 00 00 00 00 …| ..|…….. 000000000258fff0 00 00 00 00 3b e4 4f 77 - a8 19 1b 00 00 00 00 00 ….;.Ow…….. 0000000002590000 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. 0000000002590010 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. 0000000002590020 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. 0000000002590030 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. 0000000002590040 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. 0000000002590050 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. *—-> State Dump for Thread Id 0x6f4 <—-* eax=00f11520 ebx=00000102 ecx=7c80a085 edx=00001000 esi=0268ff64 edi=00000000 eip=7c90e4f4 esp=0268fee8 ebp=0268ff10 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 function: ntdll!KiFastSystemCallRet 7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508) 7c90e4df 8b0424 mov eax,[esp] 7c90e4e2 8be5 mov esp,ebp 7c90e4e4 5d pop ebp 7c90e4e5 c3 ret 7c90e4e6 8da42400000000 lea esp,[esp] 7c90e4ed 8d4900 lea ecx,[ecx] ntdll!KiFastSystemCall: 7c90e4f0 8bd4 mov edx,esp 7c90e4f2 0f34 sysenter ntdll!KiFastSystemCallRet: 7c90e4f4 c3 ret 7c90e4f5 8da42400000000 lea esp,[esp] 7c90e4fc 8d642400 lea esp,[esp] ntdll!KiIntSystemCall: 7c90e500 8d542408 lea edx,[esp+0x8] 7c90e504 cd2e int 2e 7c90e506 c3 ret 7c90e507 90 nop ntdll!RtlRaiseException: 7c90e508 55 push ebp 7c90e509 8bec mov ebp,esp *—-> Stack Back Trace <—-* WARNING: Stack unwind information not available. Following frames may be wrong. ChildEBP RetAddr Args to Child 0268ff10 7e419402 0268ff64 00000000 00000000 ntdll!KiFastSystemCallRet 0268ff3c 42f8e675 0268ff64 00000000 00000000 USER32!PeekMessageW+0x167 0268ffb4 7c80b713 001bb100 0012e490 0012e5b8 IEFRAME!Ordinal300+0x35db 0268ffec 00000000 42f8e4e4 001af310 00000000 kernel32!GetModuleFileNameA+0x1b4 *—-> Raw Stack Dump <—-* 000000000268fee8 e9 93 41 7e a8 93 41 7e - 64 ff 68 02 00 00 00 00 ..A~..A~d.h….. 000000000268fef8 00 00 00 00 00 00 00 00 - 01 00 00 00 a8 9d 73 00 …………..s. 000000000268ff08 00 80 fd 7f 00 00 00 00 - 3c ff 68 02 02 94 41 7e ……..<.h…A~ 000000000268ff18 64 ff 68 02 00 00 00 00 - 00 00 00 00 00 00 00 00 d.h…………. 000000000268ff28 01 00 00 00 00 00 00 00 - 00 00 00 00 10 f3 1a 00 ……………. 000000000268ff38 00 00 00 00 b4 ff 68 02 - 75 e6 f8 42 64 ff 68 02 ……h.u..Bd.h. 000000000268ff48 00 00 00 00 00 00 00 00 - 00 00 00 00 01 00 00 00 ……………. 000000000268ff58 90 e4 12 00 b8 e5 12 00 - 10 f3 1a 00 00 00 00 00 ……………. 000000000268ff68 16 c1 00 00 01 00 00 00 - 00 00 00 00 bf 0f 5c 00 …………..\. 000000000268ff78 e9 00 00 00 78 04 00 00 - e8 cb 1a 00 14 6c 1b 00 ….x……..l.. 000000000268ff88 01 00 00 00 00 00 00 00 - e8 88 21 00 01 00 00 00 ……….!….. 000000000268ff98 00 00 00 00 7c 05 03 00 - 88 06 0e 00 f0 74 1b 00 ….|……..t.. 000000000268ffa8 00 00 00 00 24 6c 1b 00 - 10 70 1b 00 ec ff 68 02 ….$l…p….h. 000000000268ffb8 13 b7 80 7c 00 b1 1b 00 - 90 e4 12 00 b8 e5 12 00 …|………… 000000000268ffc8 10 f3 1a 00 00 80 fd 7f - 00 06 bc 86 c0 ff 68 02 …………..h. 000000000268ffd8 70 51 e1 84 ff ff ff ff - c0 9a 83 7c 20 b7 80 7c pQ………| ..| 000000000268ffe8 00 00 00 00 00 00 00 00 - 00 00 00 00 e4 e4 f8 42 ……………B 000000000268fff8 10 f3 1a 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. 0000000002690008 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. 0000000002690018 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. *—-> State Dump for Thread Id 0x1314 <—-* eax=77e76c7d ebx=00000000 ecx=00000000 edx=00000000 esi=0018aae0 edi=00000100 eip=7c90e4f4 esp=027bfe18 ebp=027bff80 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 function: ntdll!KiFastSystemCallRet 7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508) 7c90e4df 8b0424 mov eax,[esp] 7c90e4e2 8be5 mov esp,ebp 7c90e4e4 5d pop ebp 7c90e4e5 c3 ret 7c90e4e6 8da42400000000 lea esp,[esp] 7c90e4ed 8d4900 lea ecx,[ecx] ntdll!KiFastSystemCall: 7c90e4f0 8bd4 mov edx,esp 7c90e4f2 0f34 sysenter ntdll!KiFastSystemCallRet: 7c90e4f4 c3 ret 7c90e4f5 8da42400000000 lea esp,[esp] 7c90e4fc 8d642400 lea esp,[esp] ntdll!KiIntSystemCall: 7c90e500 8d542408 lea edx,[esp+0x8] 7c90e504 cd2e int 2e 7c90e506 c3 ret 7c90e507 90 nop ntdll!RtlRaiseException: 7c90e508 55 push ebp 7c90e509 8bec mov ebp,esp *—-> Stack Back Trace <—-* WARNING: Stack unwind information not available. Following frames may be wrong. ChildEBP RetAddr Args to Child 027bff80 77e76caf 027bffa8 77e76ad1 0018aae0 ntdll!KiFastSystemCallRet 027bff88 77e76ad1 0018aae0 00000000 00000000 RPCRT4!I_RpcBCacheFree+0x61c 027bffa8 77e76c97 0016b958 027bffec 7c80b713 RPCRT4!I_RpcBCacheFree+0x43e 027bffb4 7c80b713 001b7c48 00000000 00000000 RPCRT4!I_RpcBCacheFree+0x604 027bffec 00000000 77e76c7d 001b7c48 00000000 kernel32!GetModuleFileNameA+0x1b4 *—-> Raw Stack Dump <—-* 00000000027bfe18 8c da 90 7c e3 65 e7 77 - c4 02 00 00 74 ff 7b 02 …|.e.w….t.{. 00000000027bfe28 00 00 00 00 70 91 1b 00 - 50 ff 7b 02 d8 e9 ec 00 ….p…P.{….. 00000000027bfe38 d8 e9 ec 00 d8 e9 ec 00 - d8 e9 ec 00 d8 e9 ec 00 ……………. 00000000027bfe48 d8 e9 ec 00 d8 e9 ec 00 - d8 e9 ec 00 d8 e9 ec 00 ……………. 00000000027bfe58 d8 e9 ec 00 d8 e9 ec 00 - d8 e9 ec 00 d8 e9 ec 00 ……………. 00000000027bfe68 d8 e9 ec 00 d8 e9 ec 00 - d8 e9 ec 00 d8 e9 ec 00 ……………. 00000000027bfe78 d8 e9 ec 00 d8 e9 ec 00 - d8 e9 ec 00 d8 e9 ec 00 ……………. 00000000027bfe88 d8 e9 ec 00 d8 e9 ec 00 - d8 e9 ec 00 d8 e9 ec 00 ……………. 00000000027bfe98 d8 e9 ec 00 d8 e9 ec 00 - d8 e9 ec 00 d8 e9 ec 00 ……………. 00000000027bfea8 d8 e9 ec 00 d8 e9 ec 00 - d8 e9 ec 00 d8 e9 ec 00 ……………. 00000000027bfeb8 d8 e9 ec 00 d8 e9 ec 00 - d8 e9 ec 00 d8 e9 ec 00 ……………. 00000000027bfec8 d8 e9 ec 00 d8 e9 ec 00 - d8 e9 ec 00 d8 e9 ec 00 ……………. 00000000027bfed8 d8 e9 ec 00 d8 e9 ec 00 - d8 e9 ec 00 d8 e9 ec 00 ……………. 00000000027bfee8 d8 e9 ec 00 d8 e9 ec 00 - d8 e9 ec 00 d8 e9 ec 00 ……………. 00000000027bfef8 d8 e9 ec 00 d8 e9 ec 00 - d8 e9 ec 00 d8 e9 ec 00 ……………. 00000000027bff08 d8 e9 ec 00 d8 e9 ec 00 - d8 e9 ec 00 bc b1 27 85 …………..'. 00000000027bff18 24 cc aa ae b2 c2 4d 80 - ba c2 4d 80 8c b1 27 85 $…..M…M…'. 00000000027bff28 20 b0 27 85 80 ff 7b 02 - ae df e7 77 48 ff 7b 02 .'…{….wH.{. 00000000027bff38 be df e7 77 e0 10 90 7c - b8 74 1b 00 48 7c 1b 00 …w…|.t..H|.. 00000000027bff48 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff ../M…..]…… *—-> State Dump for Thread Id 0x13b8 <—-* eax=00000000 ebx=0363fa98 ecx=01b70000 edx=0000007f esi=00000000 edi=7ffde000 eip=7c90e4f4 esp=0363fa70 ebp=0363fb0c iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 function: ntdll!KiFastSystemCallRet 7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508) 7c90e4df 8b0424 mov eax,[esp] 7c90e4e2 8be5 mov esp,ebp 7c90e4e4 5d pop ebp 7c90e4e5 c3 ret 7c90e4e6 8da42400000000 lea esp,[esp] 7c90e4ed 8d4900 lea ecx,[ecx] ntdll!KiFastSystemCall: 7c90e4f0 8bd4 mov edx,esp 7c90e4f2 0f34 sysenter ntdll!KiFastSystemCallRet: 7c90e4f4 c3 ret 7c90e4f5 8da42400000000 lea esp,[esp] 7c90e4fc 8d642400 lea esp,[esp] ntdll!KiIntSystemCall: 7c90e500 8d542408 lea edx,[esp+0x8] 7c90e504 cd2e int 2e 7c90e506 c3 ret 7c90e507 90 nop ntdll!RtlRaiseException: 7c90e508 55 push ebp 7c90e509 8bec mov ebp,esp *—-> Stack Back Trace <—-* WARNING: Stack unwind information not available. Following frames may be wrong. *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\urlmon.dll - *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\System32\msxml3.dll - *** ERROR: Symbol file could not be found. Defaulted to export symbols for c:\program files\google\googletoolbar1.dll - ChildEBP RetAddr Args to Child 0363fb0c 7e4195f9 00000001 0363fb34 00000000 ntdll!KiFastSystemCallRet 0363fb68 7e4196a8 00000000 00000000 00001388 USER32!GetLastInputInfo+0x105 0363fb84 78154412 00000000 00000000 00000000 USER32!MsgWaitForMultipleObjects+0x1f 0363fbd4 78154474 00000000 001e59e8 00000000 urlmon!CoInternetCombineUrl+0xb16 0363fc10 7813b0a3 001ede80 00000000 001e5928 urlmon!CoInternetCombineUrl+0xb78 0363fc94 7813ad01 001e52a8 001e5c00 74988880 urlmon!CreateURLMonikerEx2+0xc53 0363fcd8 7813b13a 001e7170 00000000 001e5c00 urlmon!CreateURLMonikerEx2+0x8b1 0363fcfc 749c8b2f 001e7170 001e5c00 00000000 urlmon!CreateURLMonikerEx2+0xcea 0363fd48 749ab35e 001e7170 00000000 00000001 msxml3+0x48b2f 0363fd64 749a475e 0363fd80 00000001 02cc7060 msxml3!DllGetClassObject+0x7b76 0363fd98 749a4c83 00000000 02d9e120 00000000 msxml3!DllGetClassObject+0xf76 0363fdc4 749a5da2 001e4a1b 00000000 02d9e120 msxml3!DllGetClassObject+0x149b 0363fe48 749a5e65 00000000 00000000 00000000 msxml3!DllGetClassObject+0x25ba 0363fe64 749a5433 02d9e110 00000000 0363ff00 msxml3!DllGetClassObject+0x267d 0363fee4 028bd31b 02cc7298 03630008 774ff06b msxml3!DllGetClassObject+0x1c4b 0363ff44 028caf0a 033c110c 00000001 00000000 googletoolbar1!DllCanUnloadNow+0x45648 0363ff70 0284917a 0237cec8 0268edc8 033c1348 googletoolbar1+0x8af0a 0363ffb4 7c80b713 0237cec8 0268edc8 7c9c7cd4 googletoolbar1+0x917a 0363ffec 00000000 02905639 0237cec8 00000000 kernel32!GetModuleFileNameA+0x1b4 *—-> Raw Stack Dump <—-* 000000000363fa70 2c df 90 7c 74 95 80 7c - 01 00 00 00 98 fa 63 03 ,..|t..|……c. 000000000363fa80 01 00 00 00 00 00 00 00 - cc fa 63 03 00 00 00 00 ……….c….. 000000000363fa90 01 00 00 00 00 00 00 00 - 88 04 00 00 65 04 00 00 …………e… 000000000363faa0 00 00 00 00 80 de 1e 00 - fe d5 15 78 cd ab ba dc ………..x…. 000000000363fab0 00 00 00 00 f8 fa 63 03 - 14 00 00 00 01 00 00 00 ……c……… 000000000363fac0 00 00 00 00 00 00 00 00 - 10 00 00 00 80 0f 05 fd ……………. 000000000363fad0 ff ff ff ff 2a 88 41 7e - 00 e0 fd 7f 00 50 fd 7f ….*.A~…..P.. 000000000363fae0 20 4b 74 00 cc fa 63 03 - 98 fa 63 03 00 00 00 00 Kt…c…c….. 000000000363faf0 01 00 00 00 8c fa 63 03 - 00 00 00 00 38 fe 63 03 ……c…..8.c. 000000000363fb00 c0 9a 83 7c 68 96 80 7c - 00 00 00 00 68 fb 63 03 …|h..|….h.c. 000000000363fb10 f9 95 41 7e 01 00 00 00 - 34 fb 63 03 00 00 00 00 ..A~….4.c….. 000000000363fb20 88 13 00 00 00 00 00 00 - 00 04 00 00 80 de 1e 00 ……………. 000000000363fb30 75 04 00 00 88 04 00 00 - 3b a4 42 7e ac fb 63 03 u…….;.B~..c. 000000000363fb40 96 06 08 00 00 04 00 00 - 00 00 00 00 03 00 00 00 ……………. 000000000363fb50 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. 000000000363fb60 00 50 fd 7f 88 04 00 00 - 84 fb 63 03 a8 96 41 7e .P……..c…A~ 000000000363fb70 00 00 00 00 00 00 00 00 - 88 13 00 00 08 00 00 00 ……………. 000000000363fb80 34 fb 63 03 d4 fb 63 03 - 12 44 15 78 00 00 00 00 4.c…c..D.x…. 000000000363fb90 00 00 00 00 00 00 00 00 - 88 13 00 00 08 00 00 00 ……………. 000000000363fba0 bc df 1e 00 00 00 00 00 - 14 df 1e 00 96 06 08 00 ……………. *—-> State Dump for Thread Id 0x166c <—-* eax=000000c0 ebx=00000000 ecx=00000000 edx=7ffd8c00 esi=00000000 edi=00000000 eip=7c90e4f4 esp=0373ff9c ebp=0373ffb4 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 function: ntdll!KiFastSystemCallRet 7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508) 7c90e4df 8b0424 mov eax,[esp] 7c90e4e2 8be5 mov esp,ebp 7c90e4e4 5d pop ebp 7c90e4e5 c3 ret 7c90e4e6 8da42400000000 lea esp,[esp] 7c90e4ed 8d4900 lea ecx,[ecx] ntdll!KiFastSystemCall: 7c90e4f0 8bd4 mov edx,esp 7c90e4f2 0f34 sysenter ntdll!KiFastSystemCallRet: 7c90e4f4 c3 ret 7c90e4f5 8da42400000000 lea esp,[esp] 7c90e4fc 8d642400 lea esp,[esp] ntdll!KiIntSystemCall: 7c90e500 8d542408 lea edx,[esp+0x8] 7c90e504 cd2e int 2e 7c90e506 c3 ret 7c90e507 90 nop ntdll!RtlRaiseException: 7c90e508 55 push ebp 7c90e509 8bec mov ebp,esp *—-> Stack Back Trace <—-* WARNING: Stack unwind information not available. Following frames may be wrong. ChildEBP RetAddr Args to Child 0373ffb4 7c80b713 00000000 00000000 00000000 ntdll!KiFastSystemCallRet 0373ffec 00000000 7c927ebb 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4 *—-> Raw Stack Dump <—-* 000000000373ff9c fc d1 90 7c 02 7f 92 7c - 01 00 00 00 ac ff 73 03 …|…|……s. 000000000373ffac 00 00 00 00 00 00 00 80 - ec ff 73 03 13 b7 80 7c ……….s….| 000000000373ffbc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. 000000000373ffcc 00 40 fd 7f 00 06 bc 86 - c0 ff 73 03 c8 cd 41 85 .@……..s…A. 000000000373ffdc ff ff ff ff c0 9a 83 7c - 20 b7 80 7c 00 00 00 00 …….| ..|…. 000000000373ffec 00 00 00 00 00 00 00 00 - bb 7e 92 7c 00 00 00 00 ………~.|…. 000000000373fffc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. 000000000374000c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. 000000000374001c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. 000000000374002c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. 000000000374003c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. 000000000374004c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. 000000000374005c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. 000000000374006c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. 000000000374007c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. 000000000374008c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. 000000000374009c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. 00000000037400ac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. 00000000037400bc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. 00000000037400cc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. *—-> State Dump for Thread Id 0x13a4 <—-* eax=00000510 ebx=001f1658 ecx=00000001 edx=780f082c esi=001f1658 edi=001f1684 eip=99161983 esp=0383f9a4 ebp=0383f9bc iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 function: No prior disassembly possible 99161983 ?? ??? 99161985 ?? ??? 99161987 ?? ??? 99161989 ?? ??? 9916198b ?? ??? 9916198d ?? ??? 9916198f ?? ??? 99161991 ?? ??? 99161993 ?? ??? FAULT ->99161983 ?? ??? Error 0x00000001 99161985 ?? ??? 99161987 ?? ??? 99161989 ?? ??? 9916198b ?? ??? 9916198d ?? ??? 9916198f ?? ??? 99161991 ?? ??? 99161993 ?? ??? 99161995 ?? ??? 99161997 ?? ??? *—-> Stack Back Trace <—-* *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\DOCUME~1\neilg\protect.dll - *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\WININET.dll - WARNING: Stack unwind information not available. Following frames may be wrong. *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\SHLWAPI.dll - ChildEBP RetAddr Args to Child 0383f9a0 10003d8f 00000510 780f082c 00000001 0x99161983 0383f9bc 7806c612 00000510 780f082c 00000001 protect+0x3d8f 0383f9ec 780635bc 00201538 0383fcb4 7806bef7 WININET!InternetUnlockRequestFile+0x276 0383f9f8 7806bef7 00201538 00000570 00000000 WININET!InternetLockRequestFile+0x13e6 0383fcb4 7806b461 00201538 0383fcd8 7805edef WININET!InternetQueryDataAvailable+0x1102 0383fcc0 7805edef 00201538 7806c5a0 00000000 WININET!InternetQueryDataAvailable+0x66c 0383fcd8 7805fedf 00201020 00000000 00000000 WININET!InternetCloseHandle+0x1396 0383fcf0 7806c040 00201538 001f18a8 0383fd40 WININET!HttpAddRequestHeadersA+0x3aa 0383fd00 7806c1ef 000493e0 00000005 00000060 WININET!InternetQueryDataAvailable+0x124b 0383fd40 7806244b 0020b220 0383fd64 7805edef WININET!InternetQueryDataAvailable+0x13fa 0383fd4c 7805edef 0020b220 00000000 00000000 WININET!InternetLockRequestFile+0x275 0383fd64 7805fedf 00201020 00000000 00000000 WININET!InternetCloseHandle+0x1396 0383fd7c 780632e2 0020b220 001f18a8 0383fdb0 WININET!HttpAddRequestHeadersA+0x3aa 0383fd8c 780629a6 00000000 00000000 00201020 WININET!InternetLockRequestFile+0x110c 0383fdb0 78062923 00207430 0383fdd4 7805edef WININET!InternetLockRequestFile+0x7d0 0383fdbc 7805edef 00207430 001f18a8 00000000 WININET!InternetLockRequestFile+0x74d 0383fdd4 7805fedf 00201020 00000000 00000000 WININET!InternetCloseHandle+0x1396 0383fdec 780627ad 00207430 00201020 001ece48 WININET!HttpAddRequestHeadersA+0x3aa 0383fe2c 7806270a 001ece48 0383fe50 7805edef WININET!InternetLockRequestFile+0x5d7 0383fe38 7805edef 001ece48 001f18a8 00000000 WININET!InternetLockRequestFile+0x534 0383fe50 7805fedf 00201020 00000000 00000000 WININET!InternetCloseHandle+0x1396 0383fe68 78060393 001ece48 001f18a8 00201b18 WININET!HttpAddRequestHeadersA+0x3aa 0383fe84 7805ee6b 00000001 00201020 00201b18 WININET!HttpAddRequestHeadersA+0x85e 0383fe98 7805edef 00201b18 00201020 00201b18 WININET!InternetCloseHandle+0x1412 0383feb0 7805ef53 00201020 0383fee8 0383fedc WININET!InternetCloseHandle+0x1396 0383fee0 77f69588 00000000 001e7260 77f6956b WININET!InternetCloseHandle+0x14fa 0383fef8 7c927aa2 001e7260 7c97b440 001f2228 SHLWAPI!Ordinal120+0xbf 0383ff40 7c927ae3 77f6956b 001e7260 00000000 ntdll!RtlSetEnvironmentVariable+0x30a 0383ff60 7c927ba5 00000000 001e7260 001f2228 ntdll!RtlSetEnvironmentVariable+0x34b 0383ff74 7c927b7c 7c927ac9 00000000 001e7260 ntdll!RtlSetEnvironmentVariable+0x40d 0383ffb4 7c80b713 00000000 0268ebf4 0268ebf4 ntdll!RtlSetEnvironmentVariable+0x3e4 0383ffec 00000000 7c910230 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4 *—-> Raw Stack Dump <—-* 000000000383f9a4 8f 3d 00 10 10 05 00 00 - 2c 08 0f 78 01 00 00 00 .=……,..x…. 000000000383f9b4 00 00 00 00 00 00 00 00 - ec f9 83 03 12 c6 06 78 ……………x 000000000383f9c4 10 05 00 00 2c 08 0f 78 - 01 00 00 00 00 00 00 00 ….,..x…….. 000000000383f9d4 3c 15 20 00 20 10 20 00 - 08 36 06 78 b0 b2 20 00 <. . . ..6.x.. . 000000000383f9e4 38 15 20 00 e0 93 04 00 - f8 f9 83 03 bc 35 06 78 8. ……….5.x 000000000383f9f4 38 15 20 00 b4 fc 83 03 - f7 be 06 78 38 15 20 00 8. ……..x8. . 000000000383fa04 70 05 00 00 00 00 00 00 - 20 10 20 00 38 15 20 00 p……. . .8. . 000000000383fa14 04 00 00 00 04 00 00 00 - 00 00 00 00 00 fd 83 03 ……………. 000000000383fa24 00 00 00 00 cf 44 f6 77 - 1c fa 83 03 44 fa 83 03 …..D.w….D… 000000000383fa34 68 fa 83 03 00 00 15 00 - 02 02 91 7c 29 00 00 00 h……….|)… 000000000383fa44 38 0e 15 00 00 00 15 00 - 38 15 20 00 40 fa 83 03 8…….8. .@… 000000000383fa54 02 02 91 7c 84 fc 83 03 - 00 e9 90 7c 08 02 91 7c …|…….|…| 000000000383fa64 ff ff ff ff 02 02 91 7c - 7b 01 91 7c bb 01 91 7c …….|{..|…| 000000000383fa74 00 00 00 00 b0 b2 20 00 - 00 00 00 00 02 02 91 7c …… ……..| 000000000383fa84 66 10 91 7c bb 01 91 7c - 00 00 00 00 a8 18 1f 00 f..|…|…….. 000000000383fa94 00 00 00 00 b7 a0 80 7c - 18 b2 20 00 00 00 00 00 …….|.. ….. 000000000383faa4 00 f0 fa 7f 08 fb 83 03 - d8 08 00 00 d0 fa 83 03 ……………. 000000000383fab4 7a 6a f6 77 09 04 00 00 - 0d 00 00 00 f4 fa 83 03 zj.w………… 000000000383fac4 00 00 15 00 02 02 91 7c - 12 00 00 00 e8 09 15 00 …….|…….. 000000000383fad4 00 00 15 00 00 00 00 00 - cc fa 83 03 30 03 15 00 …………0… *—-> State Dump for Thread Id 0x13c8 <—-* eax=00000000 ebx=001f16c8 ecx=00000000 edx=00000001 esi=7fffffff edi=ffffffff eip=7c90e4f4 esp=0397fad4 ebp=0397fb10 iopl=0 nv up ei ng nz ac pe cy cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000293 function: ntdll!KiFastSystemCallRet 7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508) 7c90e4df 8b0424 mov eax,[esp] 7c90e4e2 8be5 mov esp,ebp 7c90e4e4 5d pop ebp 7c90e4e5 c3 ret 7c90e4e6 8da42400000000 lea esp,[esp] 7c90e4ed 8d4900 lea ecx,[ecx] ntdll!KiFastSystemCall: 7c90e4f0 8bd4 mov edx,esp 7c90e4f2 0f34 sysenter ntdll!KiFastSystemCallRet: 7c90e4f4 c3 ret 7c90e4f5 8da42400000000 lea esp,[esp] 7c90e4fc 8d642400 lea esp,[esp] ntdll!KiIntSystemCall: 7c90e500 8d542408 lea edx,[esp+0x8] 7c90e504 cd2e int 2e 7c90e506 c3 ret 7c90e507 90 nop ntdll!RtlRaiseException: 7c90e508 55 push ebp 7c90e509 8bec mov ebp,esp *—-> Stack Back Trace <—-* *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\mswsock.dll - WARNING: Stack unwind information not available. Following frames may be wrong. *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\WS2_32.dll - ChildEBP RetAddr Args to Child 0397fb10 71a55fa7 00000504 00000510 00000000 ntdll!KiFastSystemCallRet 0397fc04 71ab314f 00000001 0397fe84 0397fc7c mswsock+0x5fa7 0397fc54 780760ed 00000001 0397fe84 0397fc7c WS2_32!select+0xa7 0397ffac 78072a68 0397ffec 7c80b713 001f1658 WININET!Ordinal101+0x27ec 0397ffb4 7c80b713 001f1658 0363f778 00150000 WININET!InternetSetStatusCallback+0x1d9 0397ffec 00000000 78072a5b 001f1658 00000000 kernel32!GetModuleFileNameA+0x1b4 *—-> Raw Stack Dump <—-* 000000000397fad4 3c df 90 7c 2b 40 a5 71 - 04 05 00 00 01 00 00 00 <..|+@.q…….. 000000000397fae4 fc fa 97 03 b4 fb 97 03 - 84 fe 97 03 a4 fb 97 03 ……………. 000000000397faf4 e4 25 07 92 bb a8 c9 01 - ff ff ff ff ff ff ff 7f .%………….. 000000000397fb04 c8 16 1f 00 00 00 00 00 - 00 00 00 00 04 fc 97 03 ……………. 000000000397fb14 a7 5f a5 71 04 05 00 00 - 10 05 00 00 00 00 00 00 ._.q………… 000000000397fb24 04 00 00 00 80 fd 97 03 - 18 28 1f 00 7c fc 97 03 ………(..|… 000000000397fb34 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. 000000000397fb44 01 00 00 00 80 0f 05 fd - ff ff ff ff 00 00 00 00 ……………. 000000000397fb54 00 e0 fa 7f 14 00 00 00 - 01 00 00 00 00 00 00 00 ……………. 000000000397fb64 00 00 00 00 dc fd 90 7c - 00 00 00 00 00 00 00 00 …….|…….. 000000000397fb74 38 fc 97 03 44 fb 97 03 - c8 fb 97 03 1c 00 00 00 8…D……….. 000000000397fb84 c8 16 1f 00 c0 fb 97 03 - 7c fc 97 03 80 fd 97 03 ……..|……. 000000000397fb94 00 00 00 00 a4 fb 97 03 - 00 00 00 00 00 00 00 00 ……………. 000000000397fba4 80 0f 05 fd ff ff ff ff - 01 00 00 00 00 00 00 00 ……………. 000000000397fbb4 10 05 00 00 19 00 00 00 - f1 7d 92 7c 1c 04 00 00 ………}.|…. 000000000397fbc4 c9 7a 92 7c 68 24 22 00 - 00 00 00 00 b8 22 22 00 .z.|h$"……"". 000000000397fbd4 01 00 00 00 00 00 00 00 - e8 03 00 00 0c fc 97 03 ……………. 000000000397fbe4 00 00 00 00 bb 5e 00 00 - 28 fb 97 03 0c 15 aa 71 …..^..(……q 000000000397fbf4 44 fc 97 03 28 72 a7 71 - 60 2e a5 71 ff ff ff ff D…(r.q`..q…. 000000000397fc04 54 fc 97 03 4f 31 ab 71 - 01 00 00 00 84 fe 97 03 T…O1.q…….. *—-> State Dump for Thread Id 0x1780 <—-* eax=71a5d2c6 ebx=c0000000 ecx=7c912d58 edx=ffffffff esi=00000000 edi=71a8793c eip=7c90e4f4 esp=03a7ff7c ebp=03a7ffb4 iopl=0 nv up ei pl nz na pe nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202 function: ntdll!KiFastSystemCallRet 7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508) 7c90e4df 8b0424 mov eax,[esp] 7c90e4e2 8be5 mov esp,ebp 7c90e4e4 5d pop ebp 7c90e4e5 c3 ret 7c90e4e6 8da42400000000 lea esp,[esp] 7c90e4ed 8d4900 lea ecx,[ecx] ntdll!KiFastSystemCall: 7c90e4f0 8bd4 mov edx,esp 7c90e4f2 0f34 sysenter ntdll!KiFastSystemCallRet: 7c90e4f4 c3 ret 7c90e4f5 8da42400000000 lea esp,[esp] 7c90e4fc 8d642400 lea esp,[esp] ntdll!KiIntSystemCall: 7c90e500 8d542408 lea edx,[esp+0x8] 7c90e504 cd2e int 2e 7c90e506 c3 ret 7c90e507 90 nop ntdll!RtlRaiseException: 7c90e508 55 push ebp 7c90e509 8bec mov ebp,esp *—-> Stack Back Trace <—-* WARNING: Stack unwind information not available. Following frames may be wrong. ChildEBP RetAddr Args to Child 03a7ffb4 7c80b713 71a5d65f 0383f67c 7c90e900 ntdll!KiFastSystemCallRet 03a7ffec 00000000 71a5d2c6 0020b378 00000000 kernel32!GetModuleFileNameA+0x1b4 *—-> Raw Stack Dump <—-* 0000000003a7ff7c 2c da 90 7c 20 d3 a5 71 - 7c 05 00 00 bc ff a7 03 ,..| ..q|……. 0000000003a7ff8c b0 ff a7 03 a4 ff a7 03 - 68 d3 a5 71 7c f6 83 03 ……..h..q|… 0000000003a7ff9c 00 e9 90 7c 78 b3 20 00 - 00 00 00 00 00 00 00 00 …|x. ……… 0000000003a7ffac 00 00 a5 71 10 49 22 00 - ec ff a7 03 13 b7 80 7c …q.I"……..| 0000000003a7ffbc 5f d6 a5 71 7c f6 83 03 - 00 e9 90 7c 78 b3 20 00 _..q|……|x. . 0000000003a7ffcc 00 60 fd 7f 00 06 bc 86 - c0 ff a7 03 88 a7 28 86 .`…………(. 0000000003a7ffdc ff ff ff ff c0 9a 83 7c - 20 b7 80 7c 00 00 00 00 …….| ..|…. 0000000003a7ffec 00 00 00 00 00 00 00 00 - c6 d2 a5 71 78 b3 20 00 ………..qx. . 0000000003a7fffc 00 00 00 00 50 1c 00 00 - 0c 10 00 00 e0 13 00 00 ….P……….. 0000000003a8000c 83 19 16 99 cc f9 03 04 - 58 06 00 00 00 00 00 00 ……..X……. 0000000003a8001c 5c 06 00 00 60 06 00 00 - 74 06 00 00 50 81 19 00 \…`…t…P… 0000000003a8002c 01 00 00 00 00 00 00 00 - 01 00 00 00 00 00 00 00 ……………. 0000000003a8003c 01 00 00 00 00 00 00 00 - 00 00 00 00 49 00 6e 00 …………I.n. 0000000003a8004c 74 00 65 00 72 00 6e 00 - 65 00 74 00 20 00 45 00 t.e.r.n.e.t. .E. 0000000003a8005c 78 00 70 00 6c 00 6f 00 - 72 00 65 00 72 00 00 00 x.p.l.o.r.e.r… 0000000003a8006c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. 0000000003a8007c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. 0000000003a8008c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. 0000000003a8009c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. 0000000003a800ac 00 00 00 00 00 00 00 00 - 00 00 00 00 43 00 3a 00 …………C.:. *—-> State Dump for Thread Id 0xfa4 <—-* eax=77a8964d ebx=03e0ff18 ecx=001fb2f8 edx=00150000 esi=00000000 edi=7ffde000 eip=7c90e4f4 esp=03e0fef0 ebp=03e0ff8c iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 function: ntdll!KiFastSystemCallRet 7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508) 7c90e4df 8b0424 mov eax,[esp] 7c90e4e2 8be5 mov esp,ebp 7c90e4e4 5d pop ebp 7c90e4e5 c3 ret 7c90e4e6 8da42400000000 lea esp,[esp] 7c90e4ed 8d4900 lea ecx,[ecx] ntdll!KiFastSystemCall: 7c90e4f0 8bd4 mov edx,esp 7c90e4f2 0f34 sysenter ntdll!KiFastSystemCallRet: 7c90e4f4 c3 ret 7c90e4f5 8da42400000000 lea esp,[esp] 7c90e4fc 8d642400 lea esp,[esp] ntdll!KiIntSystemCall: 7c90e500 8d542408 lea edx,[esp+0x8] 7c90e504 cd2e int 2e 7c90e506 c3 ret 7c90e507 90 nop ntdll!RtlRaiseException: 7c90e508 55 push ebp 7c90e509 8bec mov ebp,esp *—-> Stack Back Trace <—-* *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\CRYPT32.dll - WARNING: Stack unwind information not available. Following frames may be wrong. ChildEBP RetAddr Args to Child 03e0ff8c 77a89678 00000001 001fa558 00000000 ntdll!KiFastSystemCallRet 03e0ffb4 7c80b713 00000001 7c910a16 00000218 CRYPT32!I_CryptRegisterSmartCardStore+0x2767 03e0ffec 00000000 77a8964d 001fa550 00000000 kernel32!GetModuleFileNameA+0x1b4 *—-> Raw Stack Dump <—-* 0000000003e0fef0 2c df 90 7c 74 95 80 7c - 01 00 00 00 18 ff e0 03 ,..|t..|…….. 0000000003e0ff00 01 00 00 00 00 00 00 00 - 4c ff e0 03 00 00 00 00 ……..L……. 0000000003e0ff10 50 a5 1f 00 58 a5 1f 00 - 2c 05 00 00 b2 c2 4d 80 P…X…,…..M. 0000000003e0ff20 ba c2 4d 80 fc 09 ba 84 - 90 08 ba 84 c4 08 ba 84 ..M…………. 0000000003e0ff30 00 00 00 00 70 ea 58 80 - 14 00 00 00 01 00 00 00 ….p.X……… 0000000003e0ff40 00 00 00 00 00 00 00 00 - 10 00 00 00 80 2e 0f f7 ……………. 0000000003e0ff50 ff ff ff ff 00 63 9a 06 - 00 e0 fd 7f 00 c0 fa 7f …..c………. 0000000003e0ff60 d1 00 00 00 4c ff e0 03 - 18 ff e0 03 00 0d db ba ….L……….. 0000000003e0ff70 01 00 00 00 0c ff e0 03 - 50 9d c9 ad dc ff e0 03 ……..P……. 0000000003e0ff80 c0 9a 83 7c 68 96 80 7c - 00 00 00 00 b4 ff e0 03 …|h..|…….. 0000000003e0ff90 78 96 a8 77 01 00 00 00 - 58 a5 1f 00 00 00 00 00 x..w….X……. 0000000003e0ffa0 98 3a 00 00 00 00 00 00 - 16 0a 91 7c 18 02 00 00 .:………|…. 0000000003e0ffb0 50 a5 1f 00 ec ff e0 03 - 13 b7 80 7c 01 00 00 00 P……….|…. 0000000003e0ffc0 16 0a 91 7c 18 02 00 00 - 50 a5 1f 00 00 c0 fa 7f …|….P……. 0000000003e0ffd0 00 06 bc 86 c0 ff e0 03 - 88 a7 28 86 ff ff ff ff ……….(….. 0000000003e0ffe0 c0 9a 83 7c 20 b7 80 7c - 00 00 00 00 00 00 00 00 …| ..|…….. 0000000003e0fff0 00 00 00 00 4d 96 a8 77 - 50 a5 1f 00 00 00 00 00 ….M..wP……. 0000000003e10000 4d 5a 90 00 03 00 00 00 - 04 00 00 00 ff ff 00 00 MZ………….. 0000000003e10010 b8 00 00 00 00 00 00 00 - 40 00 00 00 00 00 00 00 ……..@……. 0000000003e10020 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ……………. *—-> State Dump for Thread Id 0x13e0 <—-* eax=03a90000 ebx=0403dc98 ecx=00001000 edx=7c90e4f4 esi=00000000 edi=7ffde000 eip=7c90e4f4 esp=0403dc70 ebp=0403dd0c iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 function: ntdll!KiFastSystemCallRet 7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508) 7c90e4df 8b0424 mov eax,[esp] 7c90e4e2 8be5 mov esp,ebp 7c90e4e4 5d pop ebp 7c90e4e5 c3 ret 7c90e4e6 8da42400000000 lea esp,[esp] 7c90e4ed 8d4900 lea ecx,[ecx] ntdll!KiFastSystemCall: 7c90e4f0 8bd4 mov edx,esp 7c90e4f2 0f34 sysenter ntdll!KiFastSystemCallRet: 7c90e4f4 c3 ret 7c90e4f5 8da42400000000 lea esp,[esp] 7c90e4fc 8d642400 lea esp,[esp] ntdll!KiIntSystemCall: 7c90e500 8d542408 lea edx,[esp+0x8] 7c90e504 cd2e int 2e 7c90e506 c3 ret 7c90e507 90 nop ntdll!RtlRaiseException: 7c90e508 55 push ebp 7c90e509 8bec mov ebp,esp *—-> Stack Back Trace <—-* WARNING: Stack unwind information not available. Following frames may be wrong. *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\faultrep.dll - ChildEBP RetAddr Args to Child 0403dd0c 7c80a105 00000002 0403de3c 00000000 ntdll!KiFastSystemCallRet 0403dd28 6945763c 00000002 0403de3c 00000000 kernel32!WaitForMultipleObjects+0x18 0403e6bc 694582b1 0403f9cc ffffffff 00198110 faultrep!ReportFaultDWM+0x14cf 0403f730 7c8643c6 0403f9cc ffffffff 00000000 faultrep!ReportFault+0x533 0403f9a4 7c83ab38 0403f9cc 7c839b21 0403f9d4 kernel32!UnhandledExceptionFilter+0x55c 0403ffec 00000000 7c910230 00000000 00000000 kernel32!ValidateLocale+0x1328 *—-> Raw Stack Dump <—-* 000000000403dc70 2c df 90 7c 74 95 80 7c - 02 00 00 00 98 dc 03 04 ,..|t..|…….. 000000000403dc80 01 00 00 00 00 00 00 00 - cc dc 03 04 30 25 80 7c …………0%.| 000000000403dc90 00 00 a8 03 01 fe 90 7c - 5c 06 00 00 b4 05 00 00 …….|\……. 000000000403dca0 00 00 00 00 c0 dd 03 04 - 48 92 45 69 00 00 b4 77 ……..H.Ei…w 000000000403dcb0 43 00 3a 00 00 00 00 00 - 14 00 00 00 01 00 00 00 C.:…………. 000000000403dcc0 00 00 00 00 00 00 00 00 - 10 00 00 00 00 a2 2f 4d …………../M 000000000403dcd0 ff ff ff ff 01 fe 90 7c - 00 e0 fd 7f 00 d0 fa 7f …….|…….. 000000000403dce0 00 00 00 00 cc dc 03 04 - 98 dc 03 04 00 00 00 00 ……………. 000000000403dcf0 02 00 00 00 8c dc 03 04 - 00 d0 fa 7f ac e6 03 04 ……………. 000000000403dd00 c0 9a 83 7c 68 96 80 7c - 00 00 00 00 28 dd 03 04 …|h..|….(… 000000000403dd10 05 a1 80 7c 02 00 00 00 - 3c de 03 04 00 00 00 00 …|….<……. 000000000403dd20 e0 93 04 00 00 00 00 00 - bc e6 03 04 3c 76 45 69 …………
Hi again :wavey:

Hmmm, I was hoping for a somewhat different result. I am not that good to read dumps, so I may have
to enlist another tech to have a look at it ;)

One thing I would like you to run, before that, is to run the CHKDSK command.

Go to start, choose RUN, then type: CMD

This will open the command-prompt.

In the prompt, type: CHKDSK "Volume": /f (Replace "volume" with your system drive letter, by default C)

You will probably recieve this message:

Chkdsk cannot run because the volume is in use by another process. Would you like to schedule this volume to be checked the next time the system restarts? (Y/N)

Answer Y, and reboot. Let it run through and see how it goes when you open IE.
This scan can take anywhere from 15 minutes to several hours depending on severity
of errors found (if any).

Regards
Chkdsk didn't even run upon reboot. It did ask if I wanted to run it next time I rebooted and I said yet then rebooted and it never ran. Maybe things are worse than expected? I tried to install IE 8 and that gave me the same results.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI