Volledige versie bekijken : explorer "hangt"



frozenmermaid
3 December 2008, 20:58
Nu heb ik al veel meegemaakt, maar dat gewoon windows explorer blijft hangen, dat snap ik niet.
Ik blader door een map, open een foto, open een tweede, bewerk wat, blah blah en bij de derde foto "hangt" explorer en moet ik via taakbeheer afsluiten.
Op dat moment kan ik ook niks anders meer.

Dopey
3 December 2008, 23:33
Krijg je geen foutmelding of dergelijke?

compuchrisje
3 December 2008, 23:49
Eerste vraagje terug: zijn je updates geïnstalleerd, zo ja, komt dit euvel sindsdien op de proppen? Dan kan je eventueel een systeemherstel overwegen.
Tweede optie: malware. Scan met een geupdate antivirus, een evenzo geupdate anti malware prog (Ad-aware, ASquared, of andere die je in gebruik hebt).

Peter.B
4 December 2008, 07:40
ik heb hier sinds enkele dagen ook last van.
probeer dit eens(heb dit ook gedaan);start-uitvoeren,daar intikken drwtsn32 en het vinkje verwijderen naast "alle thread-contexten dumpen" en "crashdump-bestand maken".
je zal bij toepassingsfouten iets zien staan,laat eens weten wat daar staat misschien kunnen we helpen.

Peter.B
4 December 2008, 11:51
steek eens uw windows cd in de speler/brander.
start-uitvoeren en daar intikken sfc /scannow .wel een spatie laten tussen de c en /
daardoor wordt uwe windows hersteld.bij mij zou dit "blijkbaar" het probleem geweest zijn.

frozenmermaid
4 December 2008, 15:08
drwtsn32

daar gaat mij een lichtje branden, dat heb ik gisteren ergens zien voorbijflitsen maar weet niet meer wanneer.

ik heb je eerste optie gedaan, er staan twee toepassingsfouten, wil je de hele litanie lezen?
maar het gaat idd over windows explorer (de fout)

Dopey
4 December 2008, 16:03
Laat ons de litanie eens lezen, wie weet worden we er allemaal wijzer door:good:

frozenmermaid
4 December 2008, 16:42
ok, je vraagt erom :)



Toepassingsuitzondering:
Toep: C:\WINDOWS\Explorer.EXE (PID=656)
Tijd: 3/12/2008 @ 19:07:29.000
Uitzonderingsnummer: 80000007
()

*----> Systeemgegevens <----*
Computernaam: 118781360319
Gebruikersnaam: Robin Put
Terminalsessie-id: 0
Aantal processors: 2
Processortype: x86 Family 15 Model 4 Stepping 9
Windows-versie: 5.1
Actieve gecompileerde versie: 2600
Service Pack: 2
Huidig type: Multiprocessor Free
Geregistreerde organisatie:
Geregistreerde eigenaar:

*----> Taakoverzicht <----*
0 System Process
4 System
440 smss.exe
500 csrss.exe
532 winlogon.exe
576 services.exe
588 lsass.exe
728 Ati2evxx.exe
780 svchost.exe
836 svchost.exe
908 svchost.exe
976 svchost.exe
1080 svchost.exe
1192 spoolsv.exe
1324 AppleMobileDeviceService.exe
1340 mDNSResponder.exe
1364 CLCapSvc.exe
1380 CLMLServer.exe
1492 Omniserv.exe
1588 PSIService.exe
1692 seekeen.exe
1760 Tablet.exe
1776 ULCDRSvr.exe
1796 USBDeviceService.exe
1840 CLSched.exe
2000 OPXPApp.exe
156 alg.exe
324 wscntfy.exe
1544 Ati2evxx.exe
656 Explorer.EXE
204 seekeen.exe
644 cli.exe
1852 wuauclt.exe
1012 QTTask.exe
1416 iTunesHelper.exe
168 winampa.exe
2080 FireWall.exe
2088 CorelIOMonitor.exe
2096 Corel Photo Downloader.exe
2132 ctfmon.exe
2152 svchost.exe
2160 msnmsgr.exe
2332 TabUserW.exe
2404 soffice.exe
2416 soffice.BIN
2464 iPodService.exe
2968 cli.exe
2976 cli.exe
3356 KWallet.exe
3016 wlcomm.exe
1940 Corel Paint Shop Pro Photo.exe
2712 MediaCataloger.exe
3644 drwtsn32.exe

*----> Modulelijst <----*
(0000000000b40000 - 0000000000b4e000: C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
(0000000000bf0000 - 0000000000c7c000: C:\WINDOWS\system32\shdoclc.dll
(0000000000e80000 - 0000000000e9c000: C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
(0000000001000000 - 0000000001100000: C:\WINDOWS\Explorer.EXE
(0000000001150000 - 0000000001163000: C:\WINDOWS\system32\browselc.dll
(0000000001f50000 - 0000000001f68000: C:\WINDOWS\system32\odbcint.dll
(0000000001f70000 - 0000000001f76000: C:\Apps\Softex\OmniPass\cryptodll.dll
(0000000003300000 - 0000000003306000: C:\Apps\Softex\OmniPass\ssplogon.dll
(0000000003320000 - 0000000003329000: C:\Apps\Softex\OmniPass\hdddrv.dll
(00000000033f0000 - 0000000003410000: C:\Apps\Softex\OmniPass\ldapdrv.dll
(00000000034c0000 - 00000000034dc000: C:\Apps\Softex\OmniPass\mstrpwd.dll
(0000000003f50000 - 0000000003faa000: C:\Apps\Softex\OmniPass\storeng.dll
(0000000003fd0000 - 0000000004296000: C:\WINDOWS\system32\msi.dll
(0000000004f20000 - 000000000501f000: C:\PROGRA~1\ZIPGEN~1\contmenu.dll
(0000000005090000 - 000000000516d000: C:\Apps\Softex\OmniPass\autheng.dll
(00000000054d0000 - 0000000005539000: C:\Apps\Softex\OmniPass\authntec.dll
(0000000007b40000 - 0000000008017000: C:\WINDOWS\system32\atioglxx.dll
(000000000ffd0000 - 000000000fff8000: C:\WINDOWS\system32\rsaenh.dll
(0000000010000000 - 000000001007b000: C:\Program Files\Seekeen\seekeen.dll
(0000000010930000 - 0000000010979000: C:\WINDOWS\system32\PortableDeviceApi.dll
(00000000109c0000 - 00000000109ec000: C:\WINDOWS\system32\PortableDeviceTypes.dll
(00000000164a0000 - 00000000164c3000: C:\WINDOWS\system32\WPDShServiceObj.dll
(0000000020000000 - 00000000202d5000: C:\WINDOWS\system32\xpsp2res.dll
(0000000030000000 - 0000000030224000: C:\WINDOWS\system32\Macromed\Flash\Flash8b.ocx
(000000004d580000 - 000000004d5d8000: C:\WINDOWS\system32\WINHTTP.dll
(000000004eb80000 - 000000004ed26000: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_65 95b64144ccf1df_1.0.2600.3352_x-ww_81af8e88\gdiplus.dll
(00000000596c0000 - 000000005988a000: C:\WINDOWS\AppPatch\AcGenral.DLL
(000000005b190000 - 000000005b1c8000: C:\WINDOWS\system32\UxTheme.dll
(000000005ba50000 - 000000005bac2000: C:\WINDOWS\system32\themeui.dll
(000000005cf30000 - 000000005cf9e000: C:\WINDOWS\system32\shimgvw.dll
(000000005cfa0000 - 000000005cfc6000: C:\WINDOWS\system32\ShimEng.dll
(000000005d4e0000 - 000000005d577000: C:\WINDOWS\system32\comctl32.dll
(0000000060070000 - 00000000600a3000: C:\WINDOWS\system32\msutb.dll
(0000000061e00000 - 0000000061e0e000: C:\WINDOWS\system32\MFC42LOC.DLL
(0000000062e40000 - 0000000062e49000: C:\WINDOWS\system32\LPK.DLL
(0000000068cd0000 - 0000000068d11000: C:\WINDOWS\system32\icm32.dll
(0000000069000000 - 000000006900e000: C:\WINDOWS\system32\Macromed\Common\SwSupport.dll
(000000006c6a0000 - 000000006c6ed000: C:\WINDOWS\system32\DUSER.dll
(000000006d940000 - 000000006d94a000: C:\WINDOWS\system32\ddrawex.dll
(000000006ff20000 - 000000006ff74000: C:\WINDOWS\system32\NETAPI32.dll
(0000000071a20000 - 0000000071a28000: C:\WINDOWS\system32\WS2HELP.dll
(0000000071a30000 - 0000000071a47000: C:\WINDOWS\system32\WS2_32.dll
(0000000071a50000 - 0000000071a5a000: C:\WINDOWS\system32\wsock32.dll
(0000000071aa0000 - 0000000071ab2000: C:\WINDOWS\system32\MPR.dll
(0000000071b80000 - 0000000071b93000: C:\WINDOWS\System32\SAMLIB.dll
(0000000071ba0000 - 0000000071bae000: C:\WINDOWS\System32\ntlanman.dll
(0000000071c10000 - 0000000071c17000: C:\WINDOWS\System32\NETRAP.dll
(0000000071c20000 - 0000000071c60000: C:\WINDOWS\System32\NETUI1.dll
(0000000071c60000 - 0000000071c77000: C:\WINDOWS\System32\NETUI0.dll
(0000000071cd0000 - 0000000071cec000: C:\WINDOWS\system32\actxprxy.dll
(0000000072240000 - 0000000072245000: C:\WINDOWS\system32\sensapi.dll
(00000000723a0000 - 00000000723ba000: C:\WINDOWS\system32\mydocs.dll
(0000000072c80000 - 0000000072c88000: C:\WINDOWS\system32\msacm32.drv
(0000000072c90000 - 0000000072c99000: C:\WINDOWS\system32\wdmaud.drv
(0000000072f70000 - 0000000072f96000: C:\WINDOWS\system32\WINSPOOL.DRV
(0000000073270000 - 00000000732d7000: C:\WINDOWS\system32\vbscript.dll
(0000000073620000 - 0000000073627000: C:\WINDOWS\system32\msdmo.dll
(00000000736d0000 - 0000000073719000: C:\WINDOWS\system32\DDRAW.dll
(0000000073aa0000 - 0000000073ab5000: C:\WINDOWS\system32\mscms.dll
(0000000073b30000 - 0000000073b36000: C:\WINDOWS\system32\DCIMAN32.dll
(0000000073d40000 - 0000000073e3e000: C:\WINDOWS\system32\MFC42.DLL
(00000000745d0000 - 000000007460d000: C:\WINDOWS\system32\ODBC32.dll
(0000000074640000 - 0000000074667000: C:\WINDOWS\system32\msls31.dll
(0000000074670000 - 000000007469a000: C:\WINDOWS\system32\msimtf.dll
(00000000746a0000 - 00000000746eb000: C:\WINDOWS\system32\MSCTF.dll
(0000000074a50000 - 0000000074a58000: C:\WINDOWS\system32\POWRPROF.dll
(0000000074a70000 - 0000000074a7a000: C:\WINDOWS\system32\BatMeter.dll
(0000000074ab0000 - 0000000074af7000: C:\WINDOWS\system32\webcheck.dll
(0000000074d10000 - 0000000074d7b000: C:\WINDOWS\system32\USP10.dll
(0000000075250000 - 000000007527e000: C:\WINDOWS\system32\msctfime.ime
(0000000075910000 - 0000000075a08000: C:\WINDOWS\system32\MSGINA.dll
(0000000075bf0000 - 0000000075c5f000: C:\WINDOWS\system32\jscript.dll
(0000000075d40000 - 0000000075dd1000: C:\WINDOWS\system32\mlang.dll
(0000000075e30000 - 0000000075ee0000: C:\WINDOWS\system32\SXS.DLL
(0000000075f00000 - 0000000075f07000: C:\WINDOWS\System32\drprov.dll
(0000000075f10000 - 0000000075f19000: C:\WINDOWS\System32\davclnt.dll
(0000000075f20000 - 000000007601d000: C:\WINDOWS\system32\BROWSEUI.dll
(0000000076300000 - 0000000076310000: C:\WINDOWS\system32\WINSTA.dll
(0000000076320000 - 0000000076325000: C:\WINDOWS\system32\MSIMG32.dll
(0000000076330000 - 000000007634d000: C:\WINDOWS\system32\IMM32.DLL
(0000000076350000 - 000000007639a000: C:\WINDOWS\system32\comdlg32.dll
(00000000763a0000 - 000000007654a000: C:\WINDOWS\system32\NETSHELL.dll
(0000000076550000 - 0000000076571000: C:\WINDOWS\system32\stobject.dll
(00000000765a0000 - 00000000765bd000: C:\WINDOWS\System32\CSCDLL.dll
(0000000076880000 - 0000000076904000: C:\WINDOWS\system32\CRYPTUI.dll
(0000000076930000 - 0000000076938000: C:\WINDOWS\system32\LINKINFO.dll
(0000000076940000 - 0000000076966000: C:\WINDOWS\system32\ntshrui.dll
(0000000076970000 - 0000000076a24000: C:\WINDOWS\system32\USERENV.dll
(0000000076ad0000 - 0000000076ae1000: C:\WINDOWS\system32\ATL.DLL
(0000000076af0000 - 0000000076b1e000: C:\WINDOWS\system32\WINMM.dll
(0000000076bb0000 - 0000000076bbb000: C:\WINDOWS\system32\PSAPI.DLL
(0000000076bc0000 - 0000000076bee000: C:\WINDOWS\system32\credui.dll
(0000000076bf0000 - 0000000076c1e000: C:\WINDOWS\system32\WINTRUST.dll
(0000000076c50000 - 0000000076c78000: C:\WINDOWS\system32\IMAGEHLP.dll
(0000000076d20000 - 0000000076d39000: C:\WINDOWS\system32\iphlpapi.dll
(0000000076dd0000 - 0000000076df5000: C:\WINDOWS\system32\adsldpc.dll
(0000000076e40000 - 0000000076e4e000: C:\WINDOWS\system32\rtutils.dll
(0000000076e50000 - 0000000076e62000: C:\WINDOWS\system32\rasman.dll
(0000000076e70000 - 0000000076e9f000: C:\WINDOWS\system32\TAPI32.dll
(0000000076ea0000 - 0000000076edc000: C:\WINDOWS\system32\RASAPI32.DLL
(0000000076f10000 - 0000000076f18000: C:\WINDOWS\system32\WTSAPI32.dll
(0000000076f20000 - 0000000076f4d000: C:\WINDOWS\system32\WLDAP32.dll
(0000000076f90000 - 000000007700f000: C:\WINDOWS\system32\CLBCATQ.DLL
(0000000077010000 - 00000000770dd000: C:\WINDOWS\system32\COMRes.dll
(00000000770e0000 - 000000007716c000: C:\WINDOWS\system32\OLEAUT32.dll
(0000000077170000 - 0000000077217000: C:\WINDOWS\system32\WININET.dll
(0000000077390000 - 0000000077492000: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
(00000000774a0000 - 00000000775dd000: C:\WINDOWS\system32\ole32.dll
(0000000077650000 - 0000000077671000: C:\WINDOWS\system32\NTMARTA.DLL
(00000000778e0000 - 00000000779d7000: C:\WINDOWS\system32\SETUPAPI.dll
(00000000779e0000 - 0000000077a36000: C:\WINDOWS\System32\cscui.dll
(0000000077a40000 - 0000000077ad5000: C:\WINDOWS\system32\CRYPT32.dll
(0000000077ae0000 - 0000000077af2000: C:\WINDOWS\system32\MSASN1.dll
(0000000077b00000 - 0000000077b22000: C:\WINDOWS\system32\appHelp.dll
(0000000077ba0000 - 0000000077ba7000: C:\WINDOWS\system32\midimap.dll
(0000000077bb0000 - 0000000077bc5000: C:\WINDOWS\system32\MSACM32.dll
(0000000077bd0000 - 0000000077bd8000: C:\WINDOWS\system32\VERSION.dll
(0000000077be0000 - 0000000077c38000: C:\WINDOWS\system32\msvcrt.dll
(0000000077c40000 - 0000000077c63000: C:\WINDOWS\system32\msv1_0.dll
(0000000077c90000 - 0000000077cc2000: C:\WINDOWS\system32\ACTIVEDS.dll
(0000000077d10000 - 0000000077da0000: C:\WINDOWS\system32\USER32.dll
(0000000077da0000 - 0000000077e31000: C:\WINDOWS\system32\RPCRT4.dll
(0000000077e40000 - 0000000077e87000: C:\WINDOWS\system32\GDI32.dll
(0000000077e90000 - 0000000077f06000: C:\WINDOWS\system32\SHLWAPI.dll
(0000000077f10000 - 0000000077f21000: C:\WINDOWS\system32\Secur32.dll
(0000000077f40000 - 0000000077feb000: C:\WINDOWS\system32\ADVAPI32.dll
(000000007c140000 - 000000007c243000: C:\WINDOWS\system32\MFC71.DLL
(000000007c340000 - 000000007c396000: C:\WINDOWS\system32\MSVCR71.dll
(000000007c800000 - 000000007c8fe000: C:\WINDOWS\system32\kernel32.dll
(000000007c900000 - 000000007c9b6000: C:\WINDOWS\system32\ntdll.dll
(000000007c9c0000 - 000000007d1e0000: C:\WINDOWS\system32\SHELL32.dll
(000000007dbe0000 - 000000007ded6000: C:\WINDOWS\system32\mshtml.dll
(000000007df20000 - 000000007dfc1000: C:\WINDOWS\system32\urlmon.dll
(000000007e210000 - 000000007e37f000: C:\WINDOWS\system32\SHDOCVW.dll

*----> Statusdump voor subproces-ID 0x680 <----*

eax=0007fb80 ebx=00000003 ecx=0007fb80 edx=00000003 esi=000e93d8 edi=00000000
eip=7c90eb94 esp=0007fef0 ebp=0007ff08 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202

*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\ntdll.dll -
functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
Fout ->ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\SHELL32.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Module load completed but symbols could not be loaded for C:\WINDOWS\Explorer.EXE
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\kernel32.dll -
ChildEBP RetAddr Args to Child
0007ff08 7ca0bde0 00000000 0007ff5c 01016e95 ntdll!KiFastSystemCallRet
0007ff14 01016e95 000e93d8 7ffde000 0007ffc0 SHELL32!Ordinal201+0x28
0007ff5c 0101e2b6 00000000 00000000 000206fa Explorer+0x16e95
0007ffc0 7c816d4f 00000010 000810a0 7ffde000 Explorer+0x1e2b6
0007fff0 00000000 0101e24e 00000000 78746341 kernel32!RegisterWaitForInputIdle+0x49

*----> Raw Stack Dump <----*
000000000007fef0 18 94 d1 77 4a 3b a2 7c - ac 92 80 7c d8 93 0e 00 ...wJ;.|...|....
000000000007ff00 d8 93 0e 00 14 ff 07 00 - 14 ff 07 00 e0 bd a0 7c ...............|
000000000007ff10 00 00 00 00 5c ff 07 00 - 95 6e 01 01 d8 93 0e 00 ....\....n......
000000000007ff20 00 e0 fd 7f c0 ff 07 00 - 00 00 00 00 24 fd 07 00 ............$...
000000000007ff30 50 ff 07 00 e0 ff 07 00 - 27 e0 90 7c ed aa 80 7c P.......'..|...|
000000000007ff40 ff ff ff ff 0c 00 00 00 - 00 00 00 00 cb 1e 08 00 ................
000000000007ff50 a8 00 00 00 01 00 00 00 - d8 93 0e 00 c0 ff 07 00 ................
000000000007ff60 b6 e2 01 01 00 00 00 00 - 00 00 00 00 fa 06 02 00 ................
000000000007ff70 01 00 00 00 10 00 00 00 - a0 10 08 00 44 00 00 00 ............D...
000000000007ff80 4c 07 02 00 2c 07 02 00 - fc 06 02 00 00 00 00 00 L...,...........
000000000007ff90 00 00 00 00 00 00 00 00 - 00 00 00 00 48 22 19 00 ............H"..
000000000007ffa0 00 00 00 00 1d 69 91 7c - 01 00 00 00 01 00 00 00 .....i.|........
000000000007ffb0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000007ffc0 f0 ff 07 00 4f 6d 81 7c - 10 00 00 00 a0 10 08 00 ....Om.|........
000000000007ffd0 00 e0 fd 7f 00 00 00 00 - c8 ff 07 00 a8 1d 07 89 ................
000000000007ffe0 ff ff ff ff f3 99 83 7c - 58 6d 81 7c 00 00 00 00 .......|Xm.|....
000000000007fff0 00 00 00 00 00 00 00 00 - 4e e2 01 01 00 00 00 00 ........N.......
0000000000080000 41 63 74 78 20 00 00 00 - 01 00 00 00 98 24 00 00 Actx ........$..
0000000000080010 c4 00 00 00 00 00 00 00 - 20 00 00 00 00 00 00 00 ........ .......
0000000000080020 14 00 00 00 01 00 00 00 - 06 00 00 00 34 00 00 00 ............4...

*----> Statusdump voor subproces-ID 0x6ec <----*

eax=011cf7d4 ebx=77d1b8ba ecx=00000001 edx=0000001e esi=010460d8 edi=00000000
eip=7c90eb94 esp=011cff14 ebp=011cff44 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\SHLWAPI.dll -
ChildEBP RetAddr Args to Child
011cff44 01011e8b 00000000 011cffb4 77ea429a ntdll!KiFastSystemCallRet
011cff50 77ea429a 010460d8 0000005c 0007fc04 Explorer+0x11e8b
011cffb4 7c80b50b 00000000 0000005c 0007fc04 SHLWAPI!Ordinal505+0x3e9
011cffec 00000000 77ea422b 0007fdbc 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
00000000011cff14 18 94 d1 77 40 1a 00 01 - 00 00 00 00 d8 60 04 01 ...w@........`..
00000000011cff24 00 00 00 00 00 00 00 00 - eb c0 00 00 00 00 00 00 ................
00000000011cff34 70 0d 00 00 f5 58 27 02 - a8 02 00 00 70 03 00 00 p....X'.....p...
00000000011cff44 50 ff 1c 01 8b 1e 01 01 - 00 00 00 00 b4 ff 1c 01 P...............
00000000011cff54 9a 42 ea 77 d8 60 04 01 - 5c 00 00 00 04 fc 07 00 .B.w.`..\.......
00000000011cff64 bc fd 07 00 62 1e 01 01 - b1 79 01 01 a8 01 00 00 ....b....y......
00000000011cff74 d8 60 04 01 08 00 00 00 - 00 00 00 00 00 00 00 00 .`..............
00000000011cff84 00 00 00 00 00 00 00 00 - 00 00 00 00 80 a7 05 89 ................
00000000011cff94 2a 2f 50 80 00 00 00 00 - 00 00 00 00 00 00 00 00 */P.............
00000000011cffa4 32 2f 50 80 00 00 00 00 - f2 5e 6e 80 dc e2 90 7c 2/P......^n....|
00000000011cffb4 ec ff 1c 01 0b b5 80 7c - 00 00 00 00 5c 00 00 00 .......|....\...
00000000011cffc4 04 fc 07 00 bc fd 07 00 - 00 a0 fd 7f 00 86 c7 89 ................
00000000011cffd4 c0 ff 1c 01 d0 3f 08 89 - ff ff ff ff f3 99 83 7c .....?.........|
00000000011cffe4 18 b5 80 7c 00 00 00 00 - 00 00 00 00 00 00 00 00 ...|............
00000000011cfff4 2b 42 ea 77 bc fd 07 00 - 00 00 00 00 00 00 00 00 +B.w............
00000000011d0004 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000011d0014 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000011d0024 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000011d0034 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000011d0044 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

*----> Statusdump voor subproces-ID 0x7c4 <----*

eax=000000c0 ebx=00000000 ecx=77f46a51 edx=77f46a18 esi=ffffffff edi=7c90fb78
eip=7c90eb94 esp=0120ff9c ebp=0120ffb4 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0120ffb4 7c80b50b 00000000 7c90fb78 ffffffff ntdll!KiFastSystemCallRet
0120ffec 00000000 7c92798d 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
000000000120ff9c 5c d8 90 7c d4 79 92 7c - 01 00 00 00 ac ff 20 01 \..|.y.|...... .
000000000120ffac 00 00 00 00 00 00 00 80 - ec ff 20 01 0b b5 80 7c .......... ....|
000000000120ffbc 00 00 00 00 78 fb 90 7c - ff ff ff ff 00 00 00 00 ....x..|........
000000000120ffcc 00 90 fd 7f 00 a6 c7 89 - c0 ff 20 01 a8 ab b7 89 .......... .....
000000000120ffdc ff ff ff ff f3 99 83 7c - 18 b5 80 7c 00 00 00 00 .......|...|....
000000000120ffec 00 00 00 00 00 00 00 00 - 8d 79 92 7c 00 00 00 00 .........y.|....
000000000120fffc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000121000c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000121001c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000121002c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000121003c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000121004c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000121005c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000121006c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000121007c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000121008c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000121009c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000012100ac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000012100bc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000012100cc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

*----> Statusdump voor subproces-ID 0x7c8 <----*

eax=000000c0 ebx=00000000 ecx=011cfbbc edx=00000000 esi=00000000 edi=00000001
eip=7c90eb94 esp=0128fcec ebp=0128ffb4 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0128ffb4 7c80b50b 00000000 00000020 011cfce4 ntdll!KiFastSystemCallRet
0128ffec 00000000 7c929fae 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
000000000128fcec ab e9 90 7c d5 a0 92 7c - 03 00 00 00 30 fd 28 01 ...|...|....0.(.
000000000128fcfc 01 00 00 00 01 00 00 00 - 00 00 00 00 20 00 00 00 ............ ...
000000000128fd0c e4 fc 1c 01 00 00 00 00 - 08 e5 97 7c 08 e5 97 7c ...........|...|
000000000128fd1c d8 01 00 00 c8 07 00 00 - 03 00 00 00 03 00 00 00 ................
000000000128fd2c 02 00 00 00 d4 01 00 00 - bc 01 00 00 30 06 00 00 ............0...
000000000128fd3c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000128fd4c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000128fd5c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000128fd6c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000128fd7c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000128fd8c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000128fd9c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000128fdac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000128fdbc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000128fdcc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000128fddc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000128fdec 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000128fdfc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000128fe0c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000128fe1c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

*----> Statusdump voor subproces-ID 0x7b0 <----*

eax=0134fe50 ebx=04b1ffa0 ecx=0134fe2c edx=7c90eb94 esi=00000000 edi=7ffde000
eip=7c90eb94 esp=0134fd30 ebp=0134fdcc iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\USER32.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0134fdcc 77d195f9 0000000a 077fa260 00000000 ntdll!KiFastSystemCallRet
0134fe28 7c9f4dd7 00000009 0134fe50 ffffffff USER32!GetLastInputInfo+0x105
0134ff4c 7ca0a2dc 77ea429a 00000000 7c809988 SHELL32!Ordinal646+0x21d2
0134ffb4 7c80b50b 00000000 7c809988 00090000 SHELL32!Ordinal753+0x133
0134ffec 00000000 77ea422b 011cf4d4 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
000000000134fd30 ab e9 90 7c f2 94 80 7c - 0a 00 00 00 a0 ff b1 04 ...|...|........
000000000134fd40 01 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000134fd50 0a 00 00 00 02 00 00 00 - 00 00 00 00 60 a2 7f 07 ............`...
000000000134fd60 01 00 00 00 00 00 00 00 - 30 00 00 00 10 00 00 00 ........0.......
000000000134fd70 00 00 09 00 6c fb 34 01 - 14 00 00 00 01 00 00 00 ....l.4.........
000000000134fd80 c8 6b 0d 00 00 00 00 00 - 00 00 00 00 eb 06 91 7c .k.............|
000000000134fd90 0f 9a 80 7c 00 00 09 00 - 00 e0 fd 7f 00 60 fd 7f ...|.........`..
000000000134fda0 00 60 fd 7f 00 00 00 00 - a0 ff b1 04 20 01 01 00 .`.......... ...
000000000134fdb0 0a 00 00 00 4c fd 34 01 - 00 00 00 00 dc ff 34 01 ....L.4.......4.
000000000134fdc0 f3 99 83 7c 90 95 80 7c - 00 00 00 00 28 fe 34 01 ...|...|....(.4.
000000000134fdd0 f9 95 d1 77 0a 00 00 00 - 60 a2 7f 07 00 00 00 00 ...w....`.......
000000000134fde0 ff ff ff ff 01 00 00 00 - 30 40 13 00 09 00 00 00 ........0@......
000000000134fdf0 00 00 00 00 9b 92 d1 77 - 00 00 00 00 3c fe 34 01 .......w....<.4.
000000000134fe00 e8 4e 9f 7c 20 fe 34 01 - 00 00 00 00 00 00 00 00 .N.| .4.........
000000000134fe10 00 00 00 00 48 a2 00 00 - 00 00 00 00 01 00 00 00 ....H...........
000000000134fe20 00 60 fd 7f 08 02 00 00 - 4c ff 34 01 d7 4d 9f 7c .`......L.4..M.|
000000000134fe30 09 00 00 00 50 fe 34 01 - ff ff ff ff ff 04 00 00 ....P.4.........
000000000134fe40 60 a2 7f 07 00 00 00 00 - 00 00 00 00 00 00 00 00 `...............
000000000134fe50 a8 07 00 00 4c 0a 00 00 - cc 09 00 00 e4 08 00 00 ....L...........
000000000134fe60 50 08 00 00 08 06 00 00 - 28 02 00 00 30 02 00 00 P.......(...0...

*----> Statusdump voor subproces-ID 0x5fc <----*

eax=72c930e8 ebx=00fbfef8 ecx=0000006b edx=0000895d esi=00000000 edi=7ffde000
eip=7c90eb94 esp=00fbfed0 ebp=00fbff6c iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\wdmaud.drv -
ChildEBP RetAddr Args to Child
00fbff6c 7c809c86 00000002 00fbffa4 00000000 ntdll!KiFastSystemCallRet
00fbff88 72c9312a 00000002 00fbffa4 00000000 kernel32!WaitForMultipleObjects+0x18
00fbffb4 7c80b50b 00000000 00000008 020a0014 wdmaud!midMessage+0x348
00fbffec 00000000 72c930e8 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
0000000000fbfed0 ab e9 90 7c f2 94 80 7c - 02 00 00 00 f8 fe fb 00 ...|...|........
0000000000fbfee0 01 00 00 00 00 00 00 00 - 00 00 00 00 08 00 00 00 ................
0000000000fbfef0 00 00 00 00 00 00 00 00 - d8 04 00 00 40 04 00 00 ............@...
0000000000fbff00 44 e9 ba 89 28 5c 23 a7 - 00 00 00 00 27 54 6e 80 D...(\#.....'Tn.
0000000000fbff10 08 00 00 00 46 02 00 00 - 14 00 00 00 01 00 00 00 ....F...........
0000000000fbff20 b0 d4 0d 03 00 00 00 00 - 00 00 00 00 a8 e7 ba 89 ................
0000000000fbff30 dc e7 ba 89 01 00 00 00 - 00 e0 fd 7f 00 d0 fa 7f ................
0000000000fbff40 a8 e7 ba 89 00 00 00 00 - f8 fe fb 00 4a 2f 50 80 ............J/P.
0000000000fbff50 02 00 00 00 ec fe fb 00 - 00 00 00 00 dc ff fb 00 ................
0000000000fbff60 f3 99 83 7c 90 95 80 7c - 00 00 00 00 88 ff fb 00 ...|...|........
0000000000fbff70 86 9c 80 7c 02 00 00 00 - a4 ff fb 00 00 00 00 00 ...|............
0000000000fbff80 ff ff ff ff 00 00 00 00 - b4 ff fb 00 2a 31 c9 72 ............*1.r
0000000000fbff90 02 00 00 00 a4 ff fb 00 - 00 00 00 00 ff ff ff ff ................
0000000000fbffa0 14 00 0a 02 d8 04 00 00 - 40 04 00 00 f2 5e 6e 80 ........@....^n.
0000000000fbffb0 dc e2 90 7c ec ff fb 00 - 0b b5 80 7c 00 00 00 00 ...|.......|....
0000000000fbffc0 08 00 00 00 14 00 0a 02 - 00 00 00 00 00 d0 fa 7f ................
0000000000fbffd0 00 a6 c7 89 c0 ff fb 00 - c0 31 f6 88 ff ff ff ff .........1......
0000000000fbffe0 f3 99 83 7c 18 b5 80 7c - 00 00 00 00 00 00 00 00 ...|...|........
0000000000fbfff0 00 00 00 00 e8 30 c9 72 - 00 00 00 00 00 00 00 00 .....0.r........
0000000000fc0000 4d 5a 90 00 03 00 00 00 - 04 00 00 00 ff ff 00 00 MZ..............

*----> Statusdump voor subproces-ID 0x660 <----*

eax=00000000 ebx=02275e54 ecx=0366ff40 edx=01430304 esi=000005d8 edi=00000000
eip=7c90eb94 esp=0366ff08 ebp=0366ff6c iopl=0 nv up ei ng nz ac po cy
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000297

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\mshtml.dll -
ChildEBP RetAddr Args to Child
0366ff6c 7c802542 000005d8 00000061 00000000 ntdll!KiFastSystemCallRet
0366ff80 7ddad9a3 000005d8 00000061 00000000 kernel32!WaitForSingleObject+0x12
0366ffa4 7dcc71b6 00000000 7dcc7188 0366ffec mshtml+0x1cd9a3
0366ffb4 7c80b50b 0143aa10 00000000 00000000 mshtml+0xe71b6
0366ffec 00000000 7dcc717b 0143aa10 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
000000000366ff08 c0 e9 90 7c db 25 80 7c - d8 05 00 00 00 00 00 00 ...|.%.|........
000000000366ff18 3c ff 66 03 54 aa 43 01 - 10 aa 43 01 54 5e 27 02 <.f.T.C...C.T^'.
000000000366ff28 14 00 00 00 01 00 00 00 - 90 7f 10 03 00 00 00 00 ................
000000000366ff38 00 00 00 00 f0 32 f1 ff - ff ff ff ff 00 e0 fd 7f .....2..........
000000000366ff48 00 70 fa 7f 3c ff 66 03 - 00 00 00 00 1c ff 66 03 .p..<.f.......f.
000000000366ff58 0b d4 c4 7d dc ff 66 03 - f3 99 83 7c 08 26 80 7c ...}..f....|.&.|
000000000366ff68 00 00 00 00 80 ff 66 03 - 42 25 80 7c d8 05 00 00 ......f.B%.|....
000000000366ff78 61 00 00 00 00 00 00 00 - a4 ff 66 03 a3 d9 da 7d a.........f....}
000000000366ff88 d8 05 00 00 61 00 00 00 - 00 00 00 00 10 aa 43 01 ....a.........C.
000000000366ff98 10 aa 43 01 00 00 00 00 - 61 00 00 00 b4 ff 66 03 ..C.....a.....f.
000000000366ffa8 b6 71 cc 7d 00 00 00 00 - 88 71 cc 7d ec ff 66 03 .q.}.....q.}..f.
000000000366ffb8 0b b5 80 7c 10 aa 43 01 - 00 00 00 00 00 00 00 00 ...|..C.........
000000000366ffc8 10 aa 43 01 00 70 fa 7f - 00 86 c7 89 c0 ff 66 03 ..C..p........f.
000000000366ffd8 88 1e 08 89 ff ff ff ff - f3 99 83 7c 18 b5 80 7c ...........|...|
000000000366ffe8 00 00 00 00 00 00 00 00 - 00 00 00 00 7b 71 cc 7d ............{q.}
000000000366fff8 10 aa 43 01 00 00 00 00 - 41 63 74 78 20 00 00 00 ..C.....Actx ...
0000000003670008 01 00 00 00 40 19 00 00 - 7c 00 00 00 00 00 00 00 ....@...|.......
0000000003670018 20 00 00 00 00 00 00 00 - 14 00 00 00 01 00 00 00 ...............
0000000003670028 03 00 00 00 34 00 00 00 - bc 00 00 00 01 00 00 00 ....4...........
0000000003670038 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

*----> Statusdump voor subproces-ID 0x408 <----*

eax=00000002 ebx=00004e20 ecx=00000000 edx=036cf88c esi=036cfd68 edi=77d191c6
eip=7c90eb94 esp=036cfcf8 ebp=036cfd14 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\stobject.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
036cfd14 76551513 036cfd68 00000000 00000000 ntdll!KiFastSystemCallRet
036cfd8c 76553746 76550000 00000000 00030138 stobject+0x1513
036cffb4 7c80b50b 00000000 00000000 00000000 stobject!DllCanUnloadNow+0x1fa4
036cffec 00000000 765536f7 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
00000000036cfcf8 be 91 d1 77 f1 91 d1 77 - 68 fd 6c 03 00 00 00 00 ...w...wh.l.....
00000000036cfd08 00 00 00 00 00 00 00 00 - 00 00 00 00 8c fd 6c 03 ..............l.
00000000036cfd18 13 15 55 76 68 fd 6c 03 - 00 00 00 00 00 00 00 00 ..Uvh.l.........
00000000036cfd28 00 00 00 00 00 00 00 00 - 00 00 55 76 00 00 00 00 ..........Uv....
00000000036cfd38 30 00 00 00 00 40 00 00 - 21 13 55 76 00 00 00 00 0....@..!.Uv....
00000000036cfd48 1e 00 00 00 00 00 55 76 - c7 01 02 00 11 00 01 00 ......Uv........
00000000036cfd58 10 00 00 00 00 00 00 00 - f4 31 55 76 00 00 00 00 .........1Uv....
00000000036cfd68 38 01 03 00 13 01 00 00 - 05 00 00 00 00 00 00 00 8...............
00000000036cfd78 b1 42 23 02 ef 00 00 00 - 09 01 00 00 00 00 00 00 .B#.............
00000000036cfd88 00 00 00 00 b4 ff 6c 03 - 46 37 55 76 00 00 55 76 ......l.F7Uv..Uv
00000000036cfd98 00 00 00 00 38 01 03 00 - 01 00 00 00 00 00 00 00 ....8...........
00000000036cfda8 43 00 3a 00 5c 00 57 00 - 49 00 4e 00 44 00 4f 00 C.:.\.W.I.N.D.O.
00000000036cfdb8 57 00 53 00 5c 00 73 00 - 79 00 73 00 74 00 65 00 W.S.\.s.y.s.t.e.
00000000036cfdc8 6d 00 33 00 32 00 5c 00 - 73 00 74 00 6f 00 62 00 m.3.2.\.s.t.o.b.
00000000036cfdd8 6a 00 65 00 63 00 74 00 - 2e 00 64 00 6c 00 6c 00 j.e.c.t...d.l.l.
00000000036cfde8 00 00 81 7c 1b 00 00 00 - 00 02 00 00 fc ff 6c 03 ...|..........l.
00000000036cfdf8 23 00 00 00 aa d3 2b ba - 58 dc 00 00 d1 9b 03 a7 #.....+.X.......
00000000036cfe08 04 00 00 00 7c 9b 03 a7 - 00 00 00 00 00 00 00 00 ....|...........
00000000036cfe18 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000036cfe28 00 00 00 00 00 00 00 00 - 00 00 00 00 04 00 00 00 ................

*----> Statusdump voor subproces-ID 0x47c <----*

eax=00000000 ebx=00d86cf0 ecx=00000fe7 edx=0003cddc esi=038bfe14 edi=164be000
eip=7c90eb94 esp=038bfdd0 ebp=038bfdec iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\WPDShServiceObj.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
038bfdec 164aa888 038bfe14 00000000 00000000 ntdll!KiFastSystemCallRet
038bff50 77ea429a 00d86cf0 011cf314 7c90ee18 WPDShServiceObj+0xa888
038bffb4 7c80b50b 00000000 011cf314 7c90ee18 SHLWAPI!Ordinal505+0x3e9
038bffec 00000000 77ea422b 011cf3f8 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
00000000038bfdd0 be 91 d1 77 f1 91 d1 77 - 14 fe 8b 03 00 00 00 00 ...w...w........
00000000038bfde0 00 00 00 00 00 00 00 00 - d4 19 4a 16 50 ff 8b 03 ..........J.P...
00000000038bfdf0 88 a8 4a 16 14 fe 8b 03 - 00 00 00 00 00 00 00 00 ..J.............
00000000038bfe00 00 00 00 00 b7 f0 8b 03 - 00 00 00 00 00 00 00 00 ................
00000000038bfe10 00 00 00 00 92 01 01 00 - 13 01 00 00 0d 00 00 00 ................
00000000038bfe20 00 00 00 00 a2 5e 27 02 - a8 02 00 00 70 03 00 00 .....^'.....p...
00000000038bfe30 01 00 00 00 f0 6c d8 00 - a5 83 4a 16 b2 83 4a 16 .....l....J...J.
00000000038bfe40 00 00 00 01 00 5c 09 a7 - 3e 69 5b 80 d0 52 00 c0 .....\..>i[..R..
00000000038bfe50 25 32 14 14 00 00 00 80 - c9 6b 5b 80 20 20 16 89 %2.......k[. ..
00000000038bfe60 ff af a5 00 40 2b 12 03 - 13 37 62 ba 3b 00 00 00 ....@+...7b.;...
00000000038bfe70 99 00 00 00 00 00 00 00 - 00 04 00 00 14 4f 88 c0 .............O..
00000000038bfe80 44 f3 4b 77 c0 68 5c 77 - 11 00 00 00 10 00 00 00 D.Kw.h\w........
00000000038bfe90 17 00 00 00 b4 fe 8b 03 - c3 f4 4b 77 2c 27 0a 00 ..........Kw,'..
00000000038bfea0 17 00 00 00 01 00 00 00 - bc d6 4b 77 44 2b 12 03 ..........KwD+..
00000000038bfeb0 c4 fe 8b 03 dc d7 4b 77 - e8 03 00 00 0a d2 4b 77 ......Kw......Kw
00000000038bfec0 60 68 5c 77 d7 d1 4b 77 - 68 68 5c 77 e1 f5 4b 77 `h\w..Kwhh\w..Kw
00000000038bfed0 54 2a 12 03 50 ff 8b 03 - 68 2a 12 03 a5 d8 4b 77 T*..P...h*....Kw
00000000038bfee0 04 27 0a 00 54 2a 12 03 - 50 ff 8b 03 ad f1 4b 77 .'..T*..P.....Kw
00000000038bfef0 7b 97 80 7c 50 ff 8b 03 - 3c 68 5c 77 00 00 00 00 {..|P...<h\w....
00000000038bff00 28 ff 8b 03 f3 f0 4b 77 - 54 2a 12 03 68 2a 12 03 (.....KwT*..h*..

*----> Statusdump voor subproces-ID 0x480 <----*

eax=038ff424 ebx=038ffd0c ecx=00000000 edx=038ff680 esi=00000000 edi=7ffde000
eip=7c90eb94 esp=038ffce4 ebp=038ffd80 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
038ffd80 77d195f9 00000002 038ffda8 00000000 ntdll!KiFastSystemCallRet
038ffddc 164a9bea 00000001 038ffe2c ffffffff USER32!GetLastInputInfo+0x105
038fff50 77ea429a 00d86cf0 011cf314 7c90ee18 WPDShServiceObj+0x9bea
038fffb4 7c80b50b 00000000 011cf314 7c90ee18 SHLWAPI!Ordinal505+0x3e9
038fffec 00000000 77ea422b 011cf3f8 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
00000000038ffce4 ab e9 90 7c f2 94 80 7c - 02 00 00 00 0c fd 8f 03 ...|...|........
00000000038ffcf4 01 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000038ffd04 02 00 00 00 02 00 00 00 - 3c 06 00 00 54 06 00 00 ........<...T...
00000000038ffd14 18 6a f4 77 51 6a f4 77 - a8 31 4a 16 01 00 00 80 .j.wQj.w.1J.....
00000000038ffd24 5c 00 00 00 18 00 00 00 - 14 00 00 00 01 00 00 00 \...............
00000000038ffd34 30 2d 12 03 00 00 00 00 - 00 00 00 00 56 00 56 00 0-..........V.V.
00000000038ffd44 a8 31 4a 16 00 00 00 00 - 00 e0 fd 7f 00 40 fa 7f .1J..........@..
00000000038ffd54 5d 89 00 00 00 00 00 00 - 0c fd 8f 03 98 fd 8f 03 ]...............
00000000038ffd64 02 00 00 00 00 fd 8f 03 - 8c fd 8f 03 44 ff 8f 03 ............D...
00000000038ffd74 f3 99 83 7c 90 95 80 7c - 00 00 00 00 dc fd 8f 03 ...|...|........
00000000038ffd84 f9 95 d1 77 02 00 00 00 - a8 fd 8f 03 00 00 00 00 ...w............
00000000038ffd94 ff ff ff ff 01 00 00 00 - 00 00 00 00 9b 92 d1 77 ...............w
00000000038ffda4 01 00 00 00 3c 06 00 00 - 54 06 00 00 63 ae 4b 16 ....<...T...c.K.
00000000038ffdb4 00 00 00 00 00 00 00 00 - 00 00 00 00 70 6d d8 00 ............pm..
00000000038ffdc4 04 00 00 00 01 00 00 00 - 00 00 00 00 01 00 00 00 ................
00000000038ffdd4 00 40 fa 7f 54 06 00 00 - 50 ff 8f 03 ea 9b 4a 16 .@..T...P.....J.
00000000038ffde4 01 00 00 00 2c fe 8f 03 - ff ff ff ff 00 01 00 00 ....,...........
00000000038ffdf4 a8 fd 8f 03 b7 f0 8f 03 - 00 00 00 00 00 00 00 00 ................
00000000038ffe04 00 00 00 00 c0 49 47 00 - 2c 9a 03 a7 18 9b 03 a7 .....IG.,.......
00000000038ffe14 44 9d 03 a7 78 01 09 00 - 48 96 4d 80 ff ff ff ff D...x...H.M.....

*----> Statusdump voor subproces-ID 0x584 <----*

eax=00000001 ebx=00000668 ecx=0370ff14 edx=7c90eb94 esi=0370ff98 edi=77d21042
eip=7c90eb94 esp=0370ff54 ebp=0370ff78 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\WINMM.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0370ff78 76af4e3d 0370ff98 00000000 00000000 ntdll!KiFastSystemCallRet
0370ffb4 7c80b50b 00000668 00000200 0000002b WINMM!PlaySoundW+0x7e6
0370ffec 00000000 76af4dd6 00000668 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
000000000370ff54 be 91 d1 77 82 10 d2 77 - 98 ff 70 03 00 00 00 00 ...w...w..p.....
000000000370ff64 00 00 00 00 00 00 00 00 - 68 06 00 00 42 10 d2 77 ........h...B..w
000000000370ff74 00 00 00 00 b4 ff 70 03 - 3d 4e af 76 98 ff 70 03 ......p.=N.v..p.
000000000370ff84 00 00 00 00 00 00 00 00 - 00 00 00 00 00 02 00 00 ................
000000000370ff94 2b 00 00 00 8a 01 01 00 - bc 03 00 00 a0 74 14 00 +............t..
000000000370ffa4 00 00 00 00 f0 a6 25 02 - 6f 00 00 00 14 02 00 00 ......%.o.......
000000000370ffb4 ec ff 70 03 0b b5 80 7c - 68 06 00 00 00 02 00 00 ..p....|h.......
000000000370ffc4 2b 00 00 00 68 06 00 00 - 00 90 fa 7f 00 a6 c7 89 +...h...........
000000000370ffd4 c0 ff 70 03 f8 6c 00 89 - ff ff ff ff f3 99 83 7c ..p..l.........|
000000000370ffe4 18 b5 80 7c 00 00 00 00 - 00 00 00 00 00 00 00 00 ...|............
000000000370fff4 d6 4d af 76 68 06 00 00 - 00 00 00 00 00 00 00 00 .M.vh...........
0000000003710004 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000003710014 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000003710024 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000003710034 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000003710044 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000003710054 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000003710064 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000003710074 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000003710084 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

*----> Statusdump voor subproces-ID 0x8a4 <----*

eax=0000018e ebx=00000000 ecx=00039ecd edx=00000110 esi=000a6d18 edi=000a6dbc
eip=7c90eb94 esp=01e0fe1c ebp=01e0ff80 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\RPCRT4.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
01e0ff80 77da6c22 01e0ffa8 77da6a3b 000a6d18 ntdll!KiFastSystemCallRet
01e0ff88 77da6a3b 000a6d18 7c9106eb 04a97380 RPCRT4!I_RpcBCacheFree+0x5ea
01e0ffa8 77da6c0a 000b9678 01e0ffec 7c80b50b RPCRT4!I_RpcBCacheFree+0x403
01e0ffb4 7c80b50b 030da840 7c9106eb 04a97380 RPCRT4!I_RpcBCacheFree+0x5d2
01e0ffec 00000000 77da6bf0 030da840 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
0000000001e0fe1c 99 e3 90 7c 03 67 da 77 - 88 01 00 00 70 ff e0 01 ...|.g.w....p...
0000000001e0fe2c 00 00 00 00 90 e2 12 03 - 4c ff e0 01 00 00 00 00 ........L.......
0000000001e0fe3c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001e0fe4c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001e0fe5c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001e0fe6c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001e0fe7c 00 00 00 00 00 00 00 00 - 00 00 00 00 06 02 00 00 ................
0000000001e0fe8c 60 fb 4f 80 86 08 54 80 - 40 a3 ec 88 28 9c 7e a6 `.O...T.@...(.~.
0000000001e0fe9c 00 51 6e 80 43 5d 6e 80 - 28 9c 7e a6 27 54 6e 80 .Qn.C]n.(.~.'Tn.
0000000001e0feac 00 0d db ba 00 00 00 00 - 86 08 54 80 00 0d db ba ..........T.....
0000000001e0febc 81 28 55 80 00 00 00 00 - 00 00 00 00 00 00 00 00 .(U.............
0000000001e0fecc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001e0fedc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001e0feec 81 28 55 80 ff ff ff ff - 40 f5 df ff 00 00 00 00 .(U.....@.......
0000000001e0fefc 10 54 6e 80 dc a4 ec 88 - 28 9c 7e a6 00 00 00 00 .Tn.....(.~.....
0000000001e0ff0c 27 54 6e 80 08 00 00 00 - 46 02 00 00 30 38 50 80 'Tn.....F...08P.
0000000001e0ff1c b0 a3 ec 88 40 a3 ec 88 - 42 b0 4f 80 ac a4 ec 88 ....@...B.O.....
0000000001e0ff2c 40 a3 ec 88 80 ff e0 01 - 99 66 da 77 4c ff e0 01 @........f.wL...
0000000001e0ff3c a9 66 da 77 ed 10 90 7c - e0 54 12 03 40 a8 0d 03 .f.w...|.T..@...
0000000001e0ff4c 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff ../M.....]......

*----> Statusdump voor subproces-ID 0x814 <----*

eax=806e5410 ebx=0124fb6c ecx=00000000 edx=bab98540 esi=00000000 edi=7ffde000
eip=7c90eb94 esp=0124fb44 ebp=0124fbe0 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=dd3c es=001f fs=003b gs=0000 efl=00000246

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\DUSER.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\BROWSEUI.dll -
ChildEBP RetAddr Args to Child
0124fbe0 77d195f9 00000002 0124fc08 00000000 ntdll!KiFastSystemCallRet
0124fc3c 6c6d4b92 00000001 0124fc70 ffffffff USER32!GetLastInputInfo+0x105
0124fc5c 6c6d4cfd 000024ff ffffffff 00000000 DUSER+0x34b92
0124fc80 6c6d4ef9 000024ff 00000000 0124fcac DUSER+0x34cfd
0124fc90 77d589eb 000024ff 00000000 00000064 DUSER+0x34ef9
0124fcac 7c90eae3 0124fcbc 00000008 000024ff USER32!DdeConnectList+0x955
0124ff20 75f45385 030d53b0 00000000 00000000 ntdll!KiUserCallbackDispatcher+0x13
0124ffb4 7c80b50b 030d53b0 00000000 00000000 BROWSEUI!Ordinal138+0x7b7d
0124ffec 00000000 75f45335 030d53b0 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
000000000124fb44 ab e9 90 7c f2 94 80 7c - 02 00 00 00 6c fb 24 01 ...|...|....l.$.
000000000124fb54 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000124fb64 02 00 00 00 00 00 00 00 - d0 0a 00 00 8c 05 00 00 ................
000000000124fb74 e8 05 06 00 13 01 00 00 - 01 00 00 00 0c fc 24 01 ..............$.
000000000124fb84 66 f8 40 77 a8 02 00 00 - 14 00 00 00 01 00 00 00 f.@w............
000000000124fb94 00 00 00 00 00 00 00 00 - 10 00 00 00 b8 5c 00 00 .............\..
000000000124fba4 d0 fb 24 01 34 87 d1 77 - 00 e0 fd 7f 00 c0 fd 7f ..$.4..w........
000000000124fbb4 01 00 00 00 00 00 00 00 - 6c fb 24 01 cd ab ba dc ........l.$.....
000000000124fbc4 02 00 00 00 60 fb 24 01 - 66 f8 40 77 a4 ff 24 01 ....`.$.f.@w..$.
000000000124fbd4 f3 99 83 7c 90 95 80 7c - 00 00 00 00 3c fc 24 01 ...|...|....<.$.
000000000124fbe4 f9 95 d1 77 02 00 00 00 - 08 fc 24 01 00 00 00 00 ...w......$.....
000000000124fbf4 ff ff ff ff 00 00 00 00 - ff ff ff ff 01 00 00 00 ................
000000000124fc04 ac 92 80 7c d0 0a 00 00 - 8c 05 00 00 8e 72 6d 6c ...|.........rml
000000000124fc14 ff ff ff ff a9 72 6d 6c - 52 f1 26 02 f8 46 5a 07 .....rmlR.&..FZ.
000000000124fc24 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000124fc34 00 c0 fd 7f 8c 05 00 00 - 5c fc 24 01 92 4b 6d 6c ........\.$..Kml
000000000124fc44 01 00 00 00 70 fc 24 01 - ff ff ff ff ff 24 00 00 ....p.$......$..
000000000124fc54 08 fc 24 01 e0 b8 c7 04 - 80 fc 24 01 fd 4c 6d 6c ..$.......$..Lml
000000000124fc64 ff 24 00 00 ff ff ff ff - 00 00 00 00 d0 0a 00 00 .$..............
000000000124fc74 00 00 00 00 90 a0 0a 06 - 00 00 00 00 90 fc 24 01 ..............$.

*----> Statusdump voor subproces-ID 0xfc8 <----*

eax=01a41010 ebx=01edfde8 ecx=01350760 edx=00000002 esi=00000000 edi=7ffde000
eip=7c90eb94 esp=01edfdc0 ebp=01edfe5c iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\msvcrt.dll -
ChildEBP RetAddr Args to Child
01edfe5c 77d195f9 00000002 01edfe84 00000000 ntdll!KiFastSystemCallRet
01edfeb8 6c6d4b92 00000001 01edfeec ffffffff USER32!GetLastInputInfo+0x105
01edfed8 6c6d4ddc 000004ff ffffffff 00000001 DUSER+0x34b92
01edff0c 6c6ce394 01edff4c 00000000 00000000 DUSER+0x34ddc
01edff2c 6c6ca6f1 01edff4c 00000000 00000000 DUSER!GetMessageExA+0x44
01edff80 77c0a3b0 00000000 7c910000 7c9131dc DUSER!DUserStopAnimation+0xa505
01edffb4 7c80b50b 00dcd530 7c910000 7c9131dc msvcrt!endthreadex+0xa9
01edffec 00000000 77c0a341 00dcd530 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
0000000001edfdc0 ab e9 90 7c f2 94 80 7c - 02 00 00 00 e8 fd ed 01 ...|...|........
0000000001edfdd0 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001edfde0 02 00 00 00 04 00 00 00 - 5c 0a 00 00 54 09 00 00 ........\...T...
0000000001edfdf0 68 00 f1 00 60 07 35 01 - 02 00 00 00 0c 20 a4 01 h...`.5...... ..
0000000001edfe00 00 00 f1 00 0c 00 00 00 - 14 00 00 00 01 00 00 00 ................
0000000001edfe10 00 00 00 00 00 00 00 00 - 10 00 00 00 0a 18 6d 6c ..............ml
0000000001edfe20 0c 00 00 00 00 00 00 00 - 00 e0 fd 7f 00 b0 fd 7f ................
0000000001edfe30 02 00 00 00 00 00 00 00 - e8 fd ed 01 2c fe ed 01 ............,...
0000000001edfe40 02 00 00 00 dc fd ed 01 - e6 1f 6d 6c a4 ff ed 01 ..........ml....
0000000001edfe50 f3 99 83 7c 90 95 80 7c - 00 00 00 00 b8 fe ed 01 ...|...|........
0000000001edfe60 f9 95 d1 77 02 00 00 00 - 84 fe ed 01 00 00 00 00 ...w............
0000000001edfe70 ff ff ff ff 00 00 00 00 - 08 22 0f 03 01 00 00 00 ........."......
0000000001edfe80 4c ff ed 01 5c 0a 00 00 - 54 09 00 00 8e 72 6d 6c L...\...T....rml
0000000001edfe90 ff ff ff ff a9 72 6d 6c - cb 70 01 02 f0 c3 aa 04 .....rml.p......
0000000001edfea0 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001edfeb0 00 b0 fd 7f 54 09 00 00 - d8 fe ed 01 92 4b 6d 6c ....T........Kml
0000000001edfec0 01 00 00 00 ec fe ed 01 - ff ff ff ff ff 04 00 00 ................
0000000001edfed0 84 fe ed 01 ff ff ff ff - 0c ff ed 01 dc 4d 6d 6c .............Mml
0000000001edfee0 ff 04 00 00 ff ff ff ff - 01 00 00 00 5c 0a 00 00 ............\...
0000000001edfef0 00 00 00 00 00 00 00 00 - 30 d5 dc 00 01 00 00 00 ........0.......

*----> Statusdump voor subproces-ID 0x148 <----*

eax=4eb972b0 ebx=033efe7c ecx=00000005 edx=7c910732 esi=00000000 edi=7ffde000
eip=7c90eb94 esp=033efe54 ebp=033efef0 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_65 95b64144ccf1df_1.0.2600.3352_x-ww_81af8e88\gdiplus.dll -
ChildEBP RetAddr Args to Child
033efef0 77d195f9 00000002 033eff18 00000000 ntdll!KiFastSystemCallRet
033eff4c 77d196a8 00000001 033effac ffffffff USER32!GetLastInputInfo+0x105
033eff68 4eb9730c 00000001 033effac 00000000 USER32!MsgWaitForMultipleObjects+0x1f
033effb4 7c80b50b 00000000 00000000 0124d718 gdiplus!GdipCreateFontFamilyFromName+0x23d
033effec 00000000 4eb972b0 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
00000000033efe54 ab e9 90 7c f2 94 80 7c - 02 00 00 00 7c fe 3e 03 ...|...|....|.>.
00000000033efe64 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000033efe74 02 00 00 00 00 00 00 00 - 8c 0b 00 00 bc 09 00 00 ................
00000000033efe84 e0 03 00 00 04 05 2b 00 - 63 c0 09 c0 54 0d 5e 00 ......+.c...T.^.
00000000033efe94 cb b4 d1 77 00 00 00 00 - 14 00 00 00 01 00 00 00 ...w............
00000000033efea4 00 00 00 00 00 00 00 00 - 10 00 00 00 cc ff 66 00 ..............f.
00000000033efeb4 dc ff 3e 03 67 04 d4 77 - 00 e0 fd 7f 00 f0 fa 7f ..>.g..w........
00000000033efec4 cb b4 d1 77 00 00 00 00 - 7c fe 3e 03 e0 03 00 00 ...w....|.>.....
00000000033efed4 02 00 00 00 70 fe 3e 03 - 00 00 00 00 dc ff 3e 03 ....p.>.......>.
00000000033efee4 f3 99 83 7c 90 95 80 7c - 00 00 00 00 4c ff 3e 03 ...|...|....L.>.
00000000033efef4 f9 95 d1 77 02 00 00 00 - 18 ff 3e 03 00 00 00 00 ...w......>.....
00000000033eff04 ff ff ff ff 00 00 00 00 - 6c c9 d1 77 b8 09 d0 4e ........l..w...N
00000000033eff14 00 00 00 00 8c 0b 00 00 - bc 09 00 00 00 00 00 00 ................
00000000033eff24 00 00 00 00 00 00 00 00 - 01 00 00 00 c0 59 59 00 .............YY.
00000000033eff34 00 f0 fa 7f 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000033eff44 00 f0 fa 7f bc 09 00 00 - 68 ff 3e 03 a8 96 d1 77 ........h.>....w
00000000033eff54 01 00 00 00 ac ff 3e 03 - ff ff ff ff ff 04 00 00 ......>.........
00000000033eff64 18 ff 3e 03 b4 ff 3e 03 - 0c 73 b9 4e 01 00 00 00 ..>...>..s.N....
00000000033eff74 ac ff 3e 03 00 00 00 00 - ff ff ff ff ff 04 00 00 ..>.............
00000000033eff84 00 00 00 00 18 d7 24 01 - 00 00 00 00 80 a7 05 89 ......$.........

*----> Statusdump voor subproces-ID 0x78c <----*

eax=774be429 ebx=00007530 ecx=0124e35c edx=00090000 esi=00000000 edi=034bff50
eip=7c90eb94 esp=034bff20 ebp=034bff78 iopl=0 nv up ei pl nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000206

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\ole32.dll -
ChildEBP RetAddr Args to Child
034bff78 7c802451 0000ea60 00000000 034bffb4 ntdll!KiFastSystemCallRet
034bff88 774be31d 0000ea60 076b9f90 774be3dc kernel32!Sleep+0xf
034bffb4 7c80b50b 076b9f90 0124e60c 00000010 ole32!StringFromGUID2+0x51b
034bffec 00000000 774be429 076b9f90 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
00000000034bff20 5c d8 90 7c ed 23 80 7c - 00 00 00 00 50 ff 4b 03 \..|.#.|....P.K.
00000000034bff30 50 25 80 7c f8 6d 5c 77 - 30 75 00 00 14 00 00 00 P%.|.m\w0u......
00000000034bff40 01 00 00 00 00 00 00 00 - 00 00 00 00 10 00 00 00 ................
00000000034bff50 00 ba 3c dc ff ff ff ff - 10 00 00 00 50 ff 4b 03 ..<.........P.K.
00000000034bff60 30 ff 4b 03 00 e0 fd 7f - dc ff 4b 03 f3 99 83 7c 0.K.......K....|
00000000034bff70 58 24 80 7c 00 00 00 00 - 88 ff 4b 03 51 24 80 7c X$.|......K.Q$.|
00000000034bff80 60 ea 00 00 00 00 00 00 - b4 ff 4b 03 1d e3 4b 77 `.........K...Kw
00000000034bff90 60 ea 00 00 90 9f 6b 07 - dc e3 4b 77 00 00 00 00 `.....k...Kw....
00000000034bffa0 0c e6 24 01 90 9f 6b 07 - 00 00 4a 77 44 e4 4b 77 ..$...k...JwD.Kw
00000000034bffb0 10 00 00 00 ec ff 4b 03 - 0b b5 80 7c 90 9f 6b 07 ......K....|..k.
00000000034bffc0 0c e6 24 01 10 00 00 00 - 90 9f 6b 07 00 50 fd 7f ..$.......k..P..
00000000034bffd0 00 a6 c7 89 c0 ff 4b 03 - b8 9c bc 88 ff ff ff ff ......K.........
00000000034bffe0 f3 99 83 7c 18 b5 80 7c - 00 00 00 00 00 00 00 00 ...|...|........
00000000034bfff0 00 00 00 00 29 e4 4b 77 - 90 9f 6b 07 00 00 00 00 ....).Kw..k.....
00000000034c0000 4d 5a 90 00 03 00 00 00 - 04 00 00 00 ff ff 00 00 MZ..............
00000000034c0010 b8 00 00 00 00 00 00 00 - 40 00 00 00 00 00 00 00 ........@.......
00000000034c0020 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000034c0030 00 00 00 00 00 00 00 00 - 00 00 00 00 10 01 00 00 ................
00000000034c0040 0e 1f ba 0e 00 b4 09 cd - 21 b8 01 4c cd 21 54 68 ........!..L.!Th
00000000034c0050 69 73 20 70 72 6f 67 72 - 61 6d 20 63 61 6e 6e 6f is program canno

*----> Statusdump voor subproces-ID 0xe48 <----*

eax=01f40000 ebx=0359ef38 ecx=00001000 edx=7c90eb94 esi=000009b4 edi=00000000
eip=7c90eb94 esp=0359ef1c ebp=0359f224 iopl=0 nv up ei pl nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000206

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
*** WARNING: Unable to verify checksum for C:\PROGRA~1\ZIPGEN~1\contmenu.dll
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\PROGRA~1\ZIPGEN~1\contmenu.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0359f224 04f2445c 0359f234 7c9037bf 0359f318 ntdll!KiFastSystemCallRet
0359f250 7c90378b 0359f318 0359fa84 0359f334 contmenu+0x445c
0359f300 7c90eafa 00000000 0359f334 0359f318 ntdll!RtlConvertUlongToLargeInteger+0x46
0359fa30 04f2488e 0359fa90 0359fa80 04ffc664 ntdll!KiUserExceptionDispatcher+0xe
0359fa90 7c9011a7 04f20000 00000000 00000000 contmenu+0x488e
0359fab0 7c91e6f4 04ff3094 04f20000 00000000 ntdll!LdrInitializeThunk+0x29
0359fba8 7c80aa7f 04f20000 0359fd34 0359fdf4 ntdll!LdrDisableThreadCalloutsForDll+0x949
0359fbbc 774d3442 04f20000 0359fe18 774d3456 kernel32!FreeLibrary+0x19
0359fbc8 774d3456 0359fd40 775c67e0 00000000 ole32!CoFreeUnusedLibraries+0xa9
0359fe18 774c2243 00132ed8 00000080 00000001 ole32!CoFreeUnusedLibraries+0xbd
0359fe44 774c2171 00000000 0359fe90 775c67e8 ole32!CoCreateInstance+0x2780
0359fe60 774bf221 00000000 00000000 00132ed8 ole32!CoCreateInstance+0x26ae
0359fe78 774bee88 0359fe90 00000000 00000001 ole32!CoInitializeEx+0x2b6
0359fe94 774d31f0 774a0000 774bd1a2 0359fec4 ole32!CoUninitialize+0x52
0359fea4 774bd141 774a0000 00000003 00000000 ole32!CoImpersonateClient+0x7c1
0359fec4 774bd0e9 774a0000 00000003 00000000 ole32!CoTaskMemAlloc+0xf9
0359fee4 7c9011a7 774a0000 00000003 00000000 ole32!CoTaskMemAlloc+0xa1
0359ff04 7c919213 774bd0a1 774a0000 00000003 ntdll!LdrInitializeThunk+0x29
0359ff7c 7c80cce7 00000000 031717f8 0124e858 ntdll!LdrShutdownThread+0xed
0359ffb4 7c80b511 00000000 00000000 031717f8 kernel32!ExitThread+0x3e
0359ffec 00000000 77ea422b 0124e858 00000000 kernel32!GetModuleFileNameA+0x1ba

*----> Raw Stack Dump <----*
000000000359ef1c ab e9 90 7c d5 33 86 7c - 02 00 00 00 54 f0 59 03 ...|.3.|....T.Y.
000000000359ef2c 01 00 00 00 01 00 00 00 - 00 00 00 00 43 00 3a 00 ............C.:.
000000000359ef3c 5c 00 57 00 49 00 4e 00 - 44 00 4f 00 57 00 53 00 \.W.I.N.D.O.W.S.
000000000359ef4c 5c 00 73 00 79 00 73 00 - 74 00 65 00 6d 00 33 00 \.s.y.s.t.e.m.3.
000000000359ef5c 32 00 5c 00 64 00 72 00 - 77 00 74 00 73 00 6e 00 2.\.d.r.w.t.s.n.
000000000359ef6c 33 00 32 00 20 00 2d 00 - 70 00 20 00 36 00 35 00 3.2. .-.p. .6.5.
000000000359ef7c 36 00 20 00 2d 00 65 00 - 20 00 32 00 34 00 38 00 6. .-.e. .2.4.8.
000000000359ef8c 34 00 20 00 2d 00 67 00 - 00 00 00 00 00 00 00 00 4. .-.g.........
000000000359ef9c 2e 00 00 00 00 00 00 00 - 00 00 00 00 24 f2 59 03 ............$.Y.
000000000359efac 0f 32 86 7c 05 00 00 00 - 24 f2 59 03 41 32 86 7c .2.|....$.Y.A2.|
000000000359efbc 69 32 86 7c 00 00 00 00 - 00 00 00 00 00 00 00 00 i2.|............
000000000359efcc 44 00 00 00 00 00 00 00 - 78 34 86 7c 00 00 00 00 D.......x4.|....
000000000359efdc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000359efec 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000359effc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000359f00c 00 00 00 00 00 e0 fa 7f - d8 c0 97 7c cc c5 ff 04 ...........|....
000000000359f01c 27 23 f2 04 00 e0 fa 7f - 60 f0 59 03 a4 f4 59 03 '#......`.Y...Y.
000000000359f02c 3f 00 00 00 28 23 3b 05 - f8 f5 59 03 83 27 f2 04 ?...(#;...Y..'..
000000000359f03c a4 f4 59 03 f5 49 f2 04 - 30 23 3b 05 60 f0 59 03 ..Y..I..0#;.`.Y.
000000000359f04c 38 4a f2 04 00 00 00 00 - b4 09 00 00 2c 0c 00 00 8J..........,...

*----> Statusdump voor subproces-ID 0x87c <----*

eax=03940033 ebx=00000000 ecx=0394e220 edx=03380000 esi=7c97c380 edi=7c97c3a0
eip=7c90eb94 esp=0394ff70 ebp=0394ffb4 iopl=0 nv up ei ng nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000286

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0394ffb4 7c80b50b 00000000 0359f87c 0359f87c ntdll!KiFastSystemCallRet
0394ffec 00000000 7c910760 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
000000000394ff70 1b e3 90 7c 9d 07 91 7c - d0 01 00 00 ac ff 94 03 ...|...|........
000000000394ff80 b0 ff 94 03 98 ff 94 03 - a0 ff 94 03 7c f8 59 03 ............|.Y.
000000000394ff90 7c f8 59 03 00 00 00 00 - 00 00 00 00 b0 45 12 00 |.Y..........E..
000000000394ffa0 00 7c 28 e8 ff ff ff ff - a0 fc 4f a6 69 75 92 7c .|(.......O.iu.|
000000000394ffb0 00 61 0e 03 ec ff 94 03 - 0b b5 80 7c 00 00 00 00 .a.........|....
000000000394ffc0 7c f8 59 03 7c f8 59 03 - 00 00 00 00 00 c0 fa 7f |.Y.|.Y.........
000000000394ffd0 00 86 c7 89 c0 ff 94 03 - 30 ee c3 88 ff ff ff ff ........0.......
000000000394ffe0 f3 99 83 7c 18 b5 80 7c - 00 00 00 00 00 00 00 00 ...|...|........
000000000394fff0 00 00 00 00 60 07 91 7c - 00 00 00 00 00 00 00 00 ....`..|........
0000000003950000 00 00 00 00 59 e9 c2 1c - 03 03 e8 f5 ff ff ff 00 ....Y...........
0000000003950010 00 00 00 00 00 00 00 e8 - e8 ff ff ff 0a 00 95 03 ................
0000000003950020 00 00 00 00 e8 db ff ff - ff 17 00 95 03 00 00 00 ................
0000000003950030 00 e8 ce ff ff ff 24 00 - 95 03 00 00 00 00 e8 c1 ......$.........
0000000003950040 ff ff ff 31 00 95 03 00 - 00 00 00 e8 b4 ff ff ff ...1............
0000000003950050 3e 00 95 03 00 00 00 00 - e8 a7 ff ff ff 4b 00 95 >............K..
0000000003950060 03 00 00 00 00 e8 9a ff - ff ff 58 00 95 03 00 00 ..........X.....
0000000003950070 00 00 e8 8d ff ff ff 65 - 00 95 03 00 00 00 00 e8 .......e........
0000000003950080 80 ff ff ff 72 00 95 03 - 00 00 00 00 e8 73 ff ff ....r........s..
0000000003950090 ff 7f 00 95 03 00 00 00 - 00 e8 66 ff ff ff 8c 00 ..........f.....
00000000039500a0 95 03 00 00 00 00 e8 59 - ff ff ff 99 00 95 03 00 .......Y........

*----> Statusdump voor subproces-ID 0xeb4 <----*

eax=033fb300 ebx=00000000 ecx=00000000 edx=00000018 esi=7c97c0d8 edi=00000000
eip=7c90eb94 esp=03adfe80 ebp=03adff08 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
03adff08 7c90104b 0197c0d8 7c919148 7c97c0d8 ntdll!KiFastSystemCallRet
03adff7c 7c80cce7 ffffffff 00000005 00000000 ntdll!RtlEnterCriticalSection+0x46
03adffb4 7c80b511 00000000 ffffffff 00000005 kernel32!ExitThread+0x3e
03adffec 00000000 033fb300 00000000 00000000 kernel32!GetModuleFileNameA+0x1ba

*----> Raw Stack Dump <----*
0000000003adfe80 c0 e9 90 7c 1b 90 91 7c - bc 02 00 00 00 00 00 00 ...|...|........
0000000003adfe90 00 00 00 00 00 e0 fd 7f - 00 b0 fa 7f 00 00 00 00 ................
0000000003adfea0 43 5d 6e 80 e0 b9 c7 04 - 78 01 09 00 00 0d db ba C]n.....x.......
0000000003adfeb0 e8 b9 c7 04 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000003adfec0 50 fa 4f 07 a0 2d 76 89 - 00 20 c2 04 00 00 00 00 P.O..-v.. ......
0000000003adfed0 00 00 00 00 58 0b 00 00 - 00 00 00 00 e0 ab 80 a7 ....X...........
0000000003adfee0 00 00 00 00 00 00 00 00 - 08 20 c2 04 20 06 00 00 ......... .. ...
0000000003adfef0 00 00 00 00 40 85 b9 ba - 00 00 00 00 10 54 6e 80 ....@........Tn.
0000000003adff00 00 00 00 00 bc 02 00 00 - 7c ff ad 03 4b 10 90 7c ........|...K..|
0000000003adff10 d8 c0 97 01 48 91 91 7c - d8 c0 97 7c 00 00 00 00 ....H..|...|....
0000000003adff20 00 b0 fa 7f 00 00 00 00 - 00 00 00 00 8c ff 01 01 ................
0000000003adff30 c4 00 00 00 90 fe ad 03 - 00 26 80 7c a4 ff ad 03 .........&.|....
0000000003adff40 18 ee 90 7c 70 05 91 7c - ff ff ff ff 6d 05 91 7c ...|p..|....m..|
0000000003adff50 da 76 91 7c 00 00 09 00 - 00 e0 fd 7f e8 b9 c7 04 .v.|............
0000000003adff60 00 ba c7 04 1c ff ad 03 - b4 ff ad 03 a4 ff ad 03 ................
0000000003adff70 18 ee 90 7c 68 91 91 7c - ff ff ff ff b4 ff ad 03 ...|h..|........
0000000003adff80 e7 cc 80 7c ff ff ff ff - 05 00 00 00 00 00 00 00 ...|............
0000000003adff90 42 25 80 7c 00 b0 fa 7f - 00 00 00 00 84 ff ad 03 B%.|............
0000000003adffa0 00 00 00 00 dc ff ad 03 - f3 99 83 7c 10 cd 80 7c ...........|...|
0000000003adffb0 ff ff ff ff ec ff ad 03 - 11 b5 80 7c 00 00 00 00 ...........|....

*----> Statusdump voor subproces-ID 0x7c0 <----*

eax=7ffaa000 ebx=00000000 ecx=7c800000 edx=00000003 esi=7c97c0d8 edi=00000000
eip=7c90eb94 esp=03b4fe44 ebp=03b4fecc iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
03b4fecc 7c90104b 0197c0d8 7c919148 7c97c0d8 ntdll!KiFastSystemCallRet
03b4ff40 7c80cce7 7c9180ff 06d22040 06d21fa8 ntdll!RtlEnterCriticalSection+0x46
03b4ff78 06c0e4a3 00000000 06d22040 06c0e516 kernel32!ExitThread+0x3e
03b4ffb4 7c80b50b 06d21fa8 7c9180ff ffffffff 0x6c0e4a3
03b4ffec 00000000 06c0e4a4 06d21fa8 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
0000000003b4fe44 c0 e9 90 7c 1b 90 91 7c - bc 02 00 00 00 00 00 00 ...|...|........
0000000003b4fe54 00 00 00 00 00 e0 fd 7f - 00 a0 fa 7f a8 1f d2 06 ................
0000000003b4fe64 10 29 d2 06 d0 e0 4d 07 - 78 01 09 00 c8 05 91 7c .)....M.x......|
0000000003b4fe74 d8 e0 4d 07 44 ff b4 03 - 51 05 91 7c 18 0a af 03 ..M.D...Q..|....
0000000003b4fe84 50 fa 4f 07 48 0a 00 00 - d0 7e af 04 a8 1f d2 06 P.O.H....~......
0000000003b4fe94 09 00 00 00 d0 f3 d4 88 - 98 00 00 00 03 00 00 00 ................
0000000003b4fea4 30 ff b4 03 00 00 00 00 - d8 7e af 04 20 06 00 00 0........~.. ...
0000000003b4feb4 00 00 00 00 f8 62 73 e2 - 18 00 00 00 a8 3d c5 88 .....bs......=..
0000000003b4fec4 00 00 00 00 bc 02 00 00 - 40 ff b4 03 4b 10 90 7c ........@...K..|
0000000003b4fed4 d8 c0 97 01 48 91 91 7c - d8 c0 97 7c 00 00 00 00 ....H..|...|....
0000000003b4fee4 00 a0 fa 7f a8 1f d2 06 - 00 00 00 00 18 ee 01 01 ................
0000000003b4fef4 c4 00 00 00 54 fe b4 03 - 6d 05 91 7c 68 ff b4 03 ....T...m..|h...
0000000003b4ff04 18 ee 90 7c 70 05 91 7c - ff ff ff ff 6d 05 91 7c ...|p..|....m..|
0000000003b4ff14 da 76 91 7c 00 00 09 00 - 00 e0 fd 7f d8 e0 4d 07 .v.|..........M.
0000000003b4ff24 f0 e0 4d 07 e0 fe b4 03 - 78 ff b4 03 68 ff b4 03 ..M.....x...h...
0000000003b4ff34 18 ee 90 7c 68 91 91 7c - ff ff ff ff 78 ff b4 03 ...|h..|....x...
0000000003b4ff44 e7 cc 80 7c ff 80 91 7c - 40 20 d2 06 a8 1f d2 06 ...|...|@ ......
0000000003b4ff54 00 00 00 00 00 a0 fa 7f - 00 00 00 00 48 ff b4 03 ............H...
0000000003b4ff64 ff 80 91 7c a4 ff b4 03 - f3 99 83 7c 10 cd 80 7c ...|.......|...|
0000000003b4ff74 ff ff ff ff b4 ff b4 03 - a3 e4 c0 06 00 00 00 00 ................

*----> Statusdump voor subproces-ID 0x464 <----*

eax=0000010f ebx=00000000 ecx=03f4fef4 edx=7ffe0300 esi=7c97c0d8 edi=00000000
eip=7c90eb94 esp=03f4fe44 ebp=03f4fecc iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
03f4fecc 7c90104b 0197c0d8 7c919148 7c97c0d8 ntdll!KiFastSystemCallRet
03f4ff40 7c80cce7 0359c608 06d226c0 06d21fa8 ntdll!RtlEnterCriticalSection+0x46
03f4ff78 06c0e4a3 00000000 06d226c0 06c0e516 kernel32!ExitThread+0x3e
03f4ffb4 7c80b50b 06d21fa8 0359c608 06c0e4a4 0x6c0e4a3
03f4ffec 00000000 06c0e4a4 06d21fa8 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
0000000003f4fe44 c0 e9 90 7c 1b 90 91 7c - bc 02 00 00 00 00 00 00 ...|...|........
0000000003f4fe54 00 00 00 00 00 e0 fd 7f - 00 80 fa 7f a8 1f d2 06 ................
0000000003f4fe64 ff ff ff 03 d0 7e af 04 - 78 01 09 00 48 0a 00 00 .....~..x...H...
0000000003f4fe74 d8 7e af 04 44 ff f4 03 - 00 00 00 00 f0 0b 00 00 .~..D...........
0000000003f4fe84 50 fa 4f 07 03 00 00 00 - 00 80 c7 04 00 00 00 00 P.O.............
0000000003f4fe94 f8 28 d2 06 24 ff f4 03 - 98 00 00 00 18 00 00 00 .(..$...........
0000000003f4fea4 2a 26 00 7c 00 00 af 03 - 08 80 c7 04 20 06 00 00 *&.|........ ...
0000000003f4feb4 00 00 00 00 00 00 00 00 - f8 28 d2 06 00 00 00 00 .........(......
0000000003f4fec4 00 00 00 00 bc 02 00 00 - 40 ff f4 03 4b 10 90 7c ........@...K..|
0000000003f4fed4 d8 c0 97 01 48 91 91 7c - d8 c0 97 7c 00 00 00 00 ....H..|...|....
0000000003f4fee4 00 80 fa 7f a8 1f d2 06 - 00 00 00 00 18 ee 01 01 ................
0000000003f4fef4 c4 00 00 00 54 fe f4 03 - 6d 05 91 7c 68 ff f4 03 ....T...m..|h...
0000000003f4ff04 18 ee 90 7c 70 05 91 7c - ff ff ff ff 6d 05 91 7c ...|p..|....m..|
0000000003f4ff14 da 76 91 7c 00 00 09 00 - 00 e0 fd 7f d8 7e af 04 .v.|.........~..
0000000003f4ff24 f0 7e af 04 e0 fe f4 03 - 78 ff f4 03 68 ff f4 03 .~......x...h...
0000000003f4ff34 18 ee 90 7c 68 91 91 7c - ff ff ff ff 78 ff f4 03 ...|h..|....x...
0000000003f4ff44 e7 cc 80 7c 08 c6 59 03 - c0 26 d2 06 a8 1f d2 06 ...|..Y..&......
0000000003f4ff54 00 00 00 00 00 80 fa 7f - 00 00 00 00 48 ff f4 03 ............H...
0000000003f4ff64 08 c6 59 03 a4 ff f4 03 - f3 99 83 7c 10 cd 80 7c ..Y........|...|
0000000003f4ff74 ff ff ff ff b4 ff f4 03 - a3 e4 c0 06 00 00 00 00 ................

*----> Statusdump voor subproces-ID 0xafc <----*

eax=00000000 ebx=00000000 ecx=044cfefc edx=7c90eb94 esi=7c97c0d8 edi=00000000
eip=7c90eb94 esp=044cfe44 ebp=044cfecc iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
044cfecc 7c90104b 0197c0d8 7c919148 7c97c0d8 ntdll!KiFastSystemCallRet
044cff40 7c80cce7 03b4fffc 06d22758 06d21fa8 ntdll!RtlEnterCriticalSection+0x46
044cff78 06c0e4a3 00000000 06d22758 06c0e516 kernel32!ExitThread+0x3e
044cffb4 7c80b50b 06d21fa8 03b4fffc 7c810856 0x6c0e4a3
044cffec 00000000 06c0e4a4 06d21fa8 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
00000000044cfe44 c0 e9 90 7c 1b 90 91 7c - bc 02 00 00 00 00 00 00 ...|...|........
00000000044cfe54 00 00 00 00 00 e0 fd 7f - 00 30 fa 7f a8 1f d2 06 .........0......
00000000044cfe64 08 06 af 03 50 89 b3 04 - 78 01 09 00 c8 28 d2 06 ....P...x....(..
00000000044cfe74 58 89 b3 04 00 00 00 00 - 00 00 00 00 c0 28 d2 06 X............(..
00000000044cfe84 50 fa 4f 07 48 0a 00 00 - d0 e0 4d 07 00 00 00 00 P.O.H.....M.....
00000000044cfe94 c8 28 d2 06 00 00 00 00 - 98 00 00 00 2c ff 4c 04 .(..........,.L.
00000000044cfea4 00 00 00 00 00 00 00 00 - d8 e0 4d 07 20 06 00 00 ..........M. ...
00000000044cfeb4 00 00 00 00 18 00 00 00 - 00 00 00 00 90 01 af 03 ................
00000000044cfec4 00 00 00 00 bc 02 00 00 - 40 ff 4c 04 4b 10 90 7c ........@.L.K..|
00000000044cfed4 d8 c0 97 01 48 91 91 7c - d8 c0 97 7c 00 00 00 00 ....H..|...|....
00000000044cfee4 00 30 fa 7f a8 1f d2 06 - 00 00 00 00 18 ee 01 01 .0..............
00000000044cfef4 c4 00 00 00 54 fe 4c 04 - 6d 05 91 7c 68 ff 4c 04 ....T.L.m..|h.L.
00000000044cff04 18 ee 90 7c 70 05 91 7c - ff ff ff ff 6d 05 91 7c ...|p..|....m..|
00000000044cff14 da 76 91 7c 00 00 09 00 - 00 e0 fd 7f 58 89 b3 04 .v.|........X...
00000000044cff24 70 89 b3 04 e0 fe 4c 04 - 78 ff 4c 04 68 ff 4c 04 p.....L.x.L.h.L.
00000000044cff34 18 ee 90 7c 68 91 91 7c - ff ff ff ff 78 ff 4c 04 ...|h..|....x.L.
00000000044cff44 e7 cc 80 7c fc ff b4 03 - 58 27 d2 06 a8 1f d2 06 ...|....X'......
00000000044cff54 00 00 00 00 00 30 fa 7f - 00 00 00 00 48 ff 4c 04 .....0......H.L.
00000000044cff64 fc ff b4 03 a4 ff 4c 04 - f3 99 83 7c 10 cd 80 7c ......L....|...|
00000000044cff74 ff ff ff ff b4 ff 4c 04 - a3 e4 c0 06 00 00 00 00 ......L.........

*----> Statusdump voor subproces-ID 0x904 <----*

eax=77da6bf0 ebx=00000000 ecx=00000000 edx=00000000 esi=000a6d18 edi=000a6dbc
eip=7c90eb94 esp=0505fe1c ebp=0505ff80 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0505ff80 77da6c22 0505ffa8 77da6a3b 000a6d18 ntdll!KiFastSystemCallRet
0505ff88 77da6a3b 000a6d18 00000000 00000000 RPCRT4!I_RpcBCacheFree+0x5ea
0505ffa8 77da6c0a 000b9678 0505ffec 7c80b50b RPCRT4!I_RpcBCacheFree+0x403
0505ffb4 7c80b50b 00122700 00000000 00000000 RPCRT4!I_RpcBCacheFree+0x5d2
0505ffec 00000000 77da6bf0 00122700 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
000000000505fe1c 99 e3 90 7c 03 67 da 77 - 88 01 00 00 70 ff 05 05 ...|.g.w....p...
000000000505fe2c 00 00 00 00 48 6d 0e 03 - 4c ff 05 05 58 3b 4f a6 ....Hm..L...X;O.
000000000505fe3c 00 83 c7 89 ed a6 54 80 - 06 02 00 00 71 fc 4f 80 ......T.....q.O.
000000000505fe4c 01 00 00 00 00 c0 fd 7f - 01 00 00 00 0a b5 4f 80 ..............O.
000000000505fe5c 01 00 00 00 01 00 00 00 - 40 85 b9 ba 00 00 00 00 ........@.......
000000000505fe6c 3c b5 4f 80 ac 3b 4f a6 - e0 fe 3f c0 00 b0 fd 7f <.O..;O...?.....
000000000505fe7c 00 00 00 00 d8 fe 3f 02 - 88 3b 4f a6 5d 36 52 80 ......?..;O.]6R.
000000000505fe8c 00 b0 fd 7f 01 00 00 00 - 00 00 00 00 d8 fe 3f c0 ..............?.
000000000505fe9c 00 00 00 00 00 00 00 00 - f8 1f 60 c0 48 3c 4f a6 ..........`.H<O.
000000000505feac bc 3d 52 80 ac 3b 4f a6 - 00 00 00 00 00 00 00 00 .=R..;O.........
000000000505febc 00 00 00 00 e8 b2 d5 88 - a0 3d 75 89 01 3e 75 89 .........=u..>u.
000000000505fecc 00 00 00 00 d8 fe 3f c0 - 70 32 bf 88 00 00 00 00 ......?.p2......
000000000505fedc e0 3b 4f a6 00 00 04 00 - 9f 0a 00 00 6c 3e 75 89 .;O.........l>u.
000000000505feec 1f 00 00 00 98 dc e3 88 - 40 f5 df ff 3c 59 54 80 ........@...<YT.
000000000505fefc ff ff ff ff 46 02 00 00 - 7b 57 54 80 28 3c 4f a6 ....F...{WT.(<O.
000000000505ff0c 98 dc e3 88 20 81 b9 ba - 34 de e3 88 30 38 50 80 .... ...4...08P.
000000000505ff1c 08 dd e3 88 98 dc e3 88 - 42 b0 4f 80 04 de e3 88 ........B.O.....
000000000505ff2c 98 dc e3 88 80 ff 05 05 - 99 66 da 77 4c ff 05 05 .........f.wL...
000000000505ff3c a9 66 da 77 ed 10 90 7c - 80 09 b6 04 00 27 12 00 .f.w...|.....'..
000000000505ff4c 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff ../M.....]......

*----> Statusdump voor subproces-ID 0xcb8 <----*

eax=00000048 ebx=00000000 ecx=00000048 edx=0000bfff esi=7c97c0d8 edi=00000000
eip=7c90eb94 esp=033af290 ebp=033af318 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\shimgvw.dll -
ChildEBP RetAddr Args to Child
033af318 7c90104b 0197c0d8 7c9131dc 7c97c0d8 ntdll!KiFastSystemCallRet
033af35c 7c80b297 00000001 00000000 033af398 ntdll!RtlEnterCriticalSection+0x46
033af3b4 77d22935 5cf30000 033af408 00000104 kernel32!GetModuleFileNameW+0x3a
033af3c8 77d2290b 5cf30000 033af408 00000104 USER32!EnumDisplayDevicesA+0x7b6
033af614 77d21305 5cf30000 00000001 00000003 USER32!EnumDisplayDevicesA+0x78c
033af634 5cf42b73 5cf30000 00000001 00000000 USER32!LoadIconW+0x1b
033af660 5cf46afb 00000001 00000000 033af81c shimgvw!ImageView_PrintToW+0x6fc0
033af684 5cf418c4 00110530 00000001 00000000 shimgvw!ImageView_PrintToW+0xaf48
033af6cc 77d18734 03144ac8 00000001 00000000 shimgvw!ImageView_PrintToW+0x5d11
033af6f8 77d1d05b 035b0f10 00110530 00000001 USER32!GetDC+0x6d
033af760 77d1b4c0 000e5de0 035b0f10 00110530 USER32!EnumDisplayMonitors+0xf8
033af7b4 77d1fd29 0060a878 00000001 00000000 USER32!DefWindowProcW+0x184
033af7e4 7c90eae3 033af7f4 00000060 00000060 USER32!UserClientDllInitialize+0x7f1
033afcf4 77d201f7 00000000 0000c1f0 00000000 ntdll!KiUserCallbackDispatcher+0x13
033afda0 77d1ff83 00000000 0000c1f0 00000000 USER32!CreateWindowExW+0x2a7
033afddc 5cf5516f 00000000 0000c1f0 00000000 USER32!CreateWindowExW+0x33
033afe40 5cf3e029 00000000 0000c1f0 00000000 shimgvw+0x2516f
033afe7c 5cf3e29d 00000000 033aff04 00000000 shimgvw!ImageView_PrintToW+0x2476
033afea8 5cf42731 00000000 033aff04 00000000 shimgvw!ImageView_PrintToW+0x26ea
033aff24 5cf3c35a 00000000 05f96e78 00000000 shimgvw!ImageView_PrintToW+0x6b7e
033aff50 77ea429a 05f96e78 00000000 0017e740 shimgvw!ImageView_PrintToW+0x7a7
033affb4 7c80b50b 00000000 00000000 0017e740 SHLWAPI!Ordinal505+0x3e9
033affec 00000000 77ea422b 0124e858 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
00000000033af290 c0 e9 90 7c 1b 90 91 7c - bc 02 00 00 00 00 00 00 ...|...|........
00000000033af2a0 00 00 00 00 98 f3 3a 03 - 00 00 00 00 01 00 00 00 ......:.........
00000000033af2b0 60 57 59 00 74 57 59 00 - 14 00 00 00 01 00 00 00 `WY.tWY.........
00000000033af2c0 00 00 00 00 00 00 00 00 - 10 00 00 00 00 00 00 00 ................
00000000033af2d0 9b b8 d1 77 01 00 00 00 - 00 00 00 00 01 00 00 00 ...w............
00000000033af2e0 6b fe d1 77 00 00 00 00 - 00 00 00 00 00 00 00 00 k..w............
00000000033af2f0 00 00 00 00 2c f3 3a 03 - e3 ea 90 7c 04 f3 3a 03 ....,.:....|..:.
00000000033af300 00 00 00 00 f0 0f 5b 03 - be d5 d1 77 01 d6 d1 77 ......[....w...w
00000000033af310 00 00 00 00 bc 02 00 00 - 5c f3 3a 03 4b 10 90 7c ........\.:.K..|
00000000033af320 d8 c0 97 01 dc 31 91 7c - d8 c0 97 7c 00 00 00 00 .....1.|...|....
00000000033af330 01 00 00 00 08 02 00 00 - fc ff ff ff f0 0f 5b 03 ..............[.
00000000033af340 00 00 00 00 2c f3 3a 03 - b7 19 f4 5c a4 f3 3a 03 ....,.:....\..:.
00000000033af350 18 ee 90 7c 18 32 91 7c - ff ff ff ff b4 f3 3a 03 ...|.2.|......:.
00000000033af360 97 b2 80 7c 01 00 00 00 - 00 00 00 00 98 f3 3a 03 ...|..........:.
00000000033af370 00 00 f3 5c 01 00 00 00 - 03 00 00 00 00 00 00 00 ...\............
00000000033af380 a1 01 00 00 04 00 00 00 - 00 00 00 00 ff ff ff ff ................
00000000033af390 00 00 f3 5c 00 00 00 00 - 00 00 00 00 70 f3 3a 03 ...\........p.:.
00000000033af3a0 ff ff ff ff 50 f7 3a 03 - f3 99 83 7c b8 b2 80 7c ....P.:....|...|
00000000033af3b0 ff ff ff ff c8 f3 3a 03 - 35 29 d2 77 00 00 f3 5c ......:.5).w...\
00000000033af3c0 08 f4 3a 03 04 01 00 00 - 14 f6 3a 03 0b 29 d2 77 ..:.......:..).w

*----> Statusdump voor subproces-ID 0xf20 <----*

eax=00000000 ebx=00000000 ecx=00000002 edx=00000003 esi=7c97c0d8 edi=00000000
eip=7c90eb94 esp=01f4fc10 ebp=01f4fc98 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

functie: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
01f4fc98 7c90104b 0197c0d8 7c927357 7c97c0d8 ntdll!KiFastSystemCallRet
01f4fd18 7c90eac7 01f4fd2c 7c900000 00000000 ntdll!RtlEnterCriticalSection+0x46
00000000 00000000 00000000 00000000 00000000 ntdll!KiUserApcDispatcher+0x7

*----> Raw Stack Dump <----*
0000000001f4fc10 c0 e9 90 7c 1b 90 91 7c - bc 02 00 00 00 00 00 00 ...|...|........
0000000001f4fc20 00 00 00 00 00 10 fa 7f - 00 e0 fd 7f 00 00 00 00 ................
0000000001f4fc30 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001f4fc40 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001f4fc50 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001f4fc60 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001f4fc70 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001f4fc80 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001f4fc90 00 00 00 00 bc 02 00 00 - 18 fd f4 01 4b 10 90 7c ............K..|
0000000001f4fca0 d8 c0 97 01 57 73 92 7c - d8 c0 97 7c 2c fd f4 01 ....Ws.|...|,...
0000000001f4fcb0 04 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001f4fcc0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001f4fcd0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001f4fce0 00 00 00 00 00 00 00 00 - 00 10 fa 7f 00 00 00 00 ................
0000000001f4fcf0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001f4fd00 ac fc f4 01 00 00 00 00 - ff ff ff ff 18 ee 90 7c ...............|
0000000001f4fd10 00 8e 91 7c ff ff ff ff - 00 00 00 00 c7 ea 90 7c ...|...........|
0000000001f4fd20 2c fd f4 01 00 00 90 7c - 00 00 00 00 17 00 01 00 ,......|........
0000000001f4fd30 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001f4fd40 00 00 00 00 00 00 00 00 - 17 2f 50 80 50 4b bd 88 ........./P.PK..


het rood heb ik voor de gemakkelijkheid maar ff gedaan

Dopey
4 December 2008, 22:32
Heb je iets van DivX op je pc? Kijk dan eens HIER (http://www.helpmij.nl/forum/showthread.php?t=200522). In geval van nvidia, kijk dan eens naar deze post (http://gathering.tweakers.net/forum/list_messages/953244).:good: