Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Windows Explorer Error


  • Please log in to reply
12 replies to this topic

#1 srader

srader

  • Members
  • 35 posts
  • OFFLINE
  •  
  • Local time:08:56 PM

Posted 04 October 2008 - 02:41 PM

After my computer is up and running for a while if I go to click on the taskbar to click on another program often times I will get the following error Windows Explorer Has Encountered an Eroror needs to close. I am pretty well-versed in computers, and this one has me totally baffled. It always has to do with the following file comctl32.dll. Someone suggested that I do a fix from the Windows XP disk. I tried that to no avail. I am getting this error on two different laptops that I have. I am running the following Service Pack 3 and Internet Explorer 7. I went to these because I was getting the same message when I was running Service Pack 2 and Internet Explorer 6. I am at total a total loss. I'm going to paste below the error message from the event viewer. Any help is appreciated. I also have the hijack this log, but I didn't think this was the right place to post it.

Event Type: Error
Event Source: Application Error
Event Category: None
Event ID: 1000
Date: 10/4/2008
Time: 1:37:43 PM
User: N/A
Computer: SCOTT
Description:
Faulting application explorer.exe, version 6.0.2900.5512, faulting module comctl32.dll, version 6.0.2900.5512, fault address 0x00076215.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 46 61 69 6c ion Fail
0010: 75 72 65 20 20 65 78 70 ure exp
0018: 6c 6f 72 65 72 2e 65 78 lorer.ex
0020: 65 20 36 2e 30 2e 32 39 e 6.0.29
0028: 30 30 2e 35 35 31 32 20 00.5512
0030: 69 6e 20 63 6f 6d 63 74 in comct
0038: 6c 33 32 2e 64 6c 6c 20 l32.dll
0040: 36 2e 30 2e 32 39 30 30 6.0.2900
0048: 2e 35 35 31 32 20 61 74 .5512 at
0050: 20 6f 66 66 73 65 74 20 offset
0058: 30 30 30 37 36 32 31 35 00076215
0060: 0d 0a ..

Edited by srader, 04 October 2008 - 02:55 PM.


BC AdBot (Login to Remove)

 


#2 usasma

usasma

    Still visually handicapped (avatar is memory developed by my Dad


  • BSOD Kernel Dump Expert
  • 25,090 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Southeastern CT, USA
  • Local time:09:56 PM

Posted 04 October 2008 - 06:45 PM

- Search your system for "Drwtsn32.log" (without the quotes). Open it in Notepad and copy/paste the contents into your next post.
- Make sure you are current on all Windows updates - check to be sure
- Scan for viruses using an independent scanner (in case your protection has been compromised). Here's a link to a free one: http://housecall.trendmicro.com
- Run SFC.EXE /SCANNOW from the Run dialog (info on it here: http://support.microsoft.com/default.aspx?...kb;en-us;310747 )
My browser caused a flood of traffic, sio my IP address was banned. Hope to fix it soon. Will get back to posting as soon as Im able.

- John  (my website: http://www.carrona.org/ )**If you need a more detailed explanation, please ask for it. I have the Knack. **  If I haven't replied in 48 hours, please send me a message. My eye problems have recently increased and I'm having difficult reading posts. (23 Nov 2017)FYI - I am completely blind in the right eye and ~30% blind in the left eye.<p>If the eye problems get worse suddenly, I may not be able to respond.If that's the case and help is needed, please PM a staff member for assistance.

#3 srader

srader
  • Topic Starter

  • Members
  • 35 posts
  • OFFLINE
  •  
  • Local time:08:56 PM

Posted 04 October 2008 - 08:41 PM

- Search your system for "Drwtsn32.log" (without the quotes). Open it in Notepad and copy/paste the contents into your next post.
- Make sure you are current on all Windows updates - check to be sure
- Scan for viruses using an independent scanner (in case your protection has been compromised). Here's a link to a free one: http://housecall.trendmicro.com
- Run SFC.EXE /SCANNOW from the Run dialog (info on it here: http://support.microsoft.com/default.aspx?...kb;en-us;310747 )



All Windows updates are current, I did check them. Scanned for viruses, and found nothing. Ran the SCANNOW command everything was okay. The only thing is every time I get the above message Dr. Watson also crashes every time and here is the event viewer log from that. I could not find a regular Dr. Watson.32log. I am thinking that is because it crashes every time after Windows Explorer crashes. I searched for it the way you listed above, plus one on the Internet to see where it would be and could not find it under documents and settings/all users. Here is that event log... I'm about ready to pull my hair out so any help is greatly appreciated.



Event Type: Error
Event Source: Application Error
Event Category: (100)
Event ID: 1000
Date: 10/4/2008
Time: 1:38:55 PM
User: N/A
Computer: SCOTT
Description:
Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module dbghelp.dll, version 5.1.2600.5512, fault address 0x0001295d.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 41 70 70 6c 69 63 61 74 Applicat
0008: 69 6f 6e 20 46 61 69 6c ion Fail
0010: 75 72 65 20 20 64 72 77 ure drw
0018: 74 73 6e 33 32 2e 65 78 tsn32.ex
0020: 65 20 35 2e 31 2e 32 36 e 5.1.26
0028: 30 30 2e 30 20 69 6e 20 00.0 in
0030: 64 62 67 68 65 6c 70 2e dbghelp.
0038: 64 6c 6c 20 35 2e 31 2e dll 5.1.
0040: 32 36 30 30 2e 35 35 31 2600.551
0048: 32 20 61 74 20 6f 66 66 2 at off
0050: 73 65 74 20 30 30 30 31 set 0001
0058: 32 39 35 64 295d

#4 usasma

usasma

    Still visually handicapped (avatar is memory developed by my Dad


  • BSOD Kernel Dump Expert
  • 25,090 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Southeastern CT, USA
  • Local time:09:56 PM

Posted 05 October 2008 - 06:04 AM

On my XP system the log is located here: C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson

Beyond that (and lacking any other information about the error) I'd have to suggest a repair install of XP
Read this first if you have IE7 installed: http://support.microsoft.com/kb/917964
Then here's the link to the repair install guide: http://www.michaelstevenstech.com/XPrepairinstall.htm
My browser caused a flood of traffic, sio my IP address was banned. Hope to fix it soon. Will get back to posting as soon as Im able.

- John  (my website: http://www.carrona.org/ )**If you need a more detailed explanation, please ask for it. I have the Knack. **  If I haven't replied in 48 hours, please send me a message. My eye problems have recently increased and I'm having difficult reading posts. (23 Nov 2017)FYI - I am completely blind in the right eye and ~30% blind in the left eye.<p>If the eye problems get worse suddenly, I may not be able to respond.If that's the case and help is needed, please PM a staff member for assistance.

#5 srader

srader
  • Topic Starter

  • Members
  • 35 posts
  • OFFLINE
  •  
  • Local time:08:56 PM

Posted 05 October 2008 - 02:19 PM

Okay, I finally found the log. But, it now contains an error regarding my Sprint wireless card connection. The error is no big deal. Next time I get the error I will post the log. Now that I'm trying to make the error happen it's not happening. Go figure. I have already tried that repair that you are talking about from the Windows XP disk.

#6 srader

srader
  • Topic Starter

  • Members
  • 35 posts
  • OFFLINE
  •  
  • Local time:08:56 PM

Posted 05 October 2008 - 03:22 PM

It happened again. Attached the log.

Attached Files



#7 usasma

usasma

    Still visually handicapped (avatar is memory developed by my Dad


  • BSOD Kernel Dump Expert
  • 25,090 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Southeastern CT, USA
  • Local time:09:56 PM

Posted 05 October 2008 - 04:45 PM

I would uninstall the Sprint PCS Connection Manager. Then reboot and run it for a while without it installed. If it's doing OK, then download (using a wired connection) a new copy of the Sprint PCS Connection Manager and install it.

After that, I might suggest a look at your audior drivers - but it's nothing certain, just several mentions of them near the time of the crash.

After that I'd go with the repair install of Windows.
My browser caused a flood of traffic, sio my IP address was banned. Hope to fix it soon. Will get back to posting as soon as Im able.

- John  (my website: http://www.carrona.org/ )**If you need a more detailed explanation, please ask for it. I have the Knack. **  If I haven't replied in 48 hours, please send me a message. My eye problems have recently increased and I'm having difficult reading posts. (23 Nov 2017)FYI - I am completely blind in the right eye and ~30% blind in the left eye.<p>If the eye problems get worse suddenly, I may not be able to respond.If that's the case and help is needed, please PM a staff member for assistance.

#8 srader

srader
  • Topic Starter

  • Members
  • 35 posts
  • OFFLINE
  •  
  • Local time:08:56 PM

Posted 08 October 2008 - 07:39 PM

Okay disregard the above attachment. That is not what is causing the problem. I had the error come up again and now the log below is the correct log. The Sprint PCS Mobile Broadband Card is not causing the problem. After I leave my mobile broadband connection on my desktop for so long I would always get that error.

When I would get the Windows Explorer Error (comctl32.dll) every time Dr. Watson would also come up with an error and have to shut down in the error would not be reported in the log. But, this time it did not and it reported the error correctly.

Any help is greatly appreciated.

I apologize for pasting the log in this window, but I did not have enough attachment size left to attach this file.

Application exception occurred:
App: C:\WINDOWS\Explorer.EXE (pid=4092)
When: 10/8/2008 @ 19:50:12.187
Exception number: c0000005 (access violation)

*----> System Information <----*
Computer Name: SCOTT
User Name: Scott Rader
Terminal Session Id: 0
Number of Processors: 2
Processor Type: x86 Family 6 Model 15 Stepping 13
Windows Version: 5.1
Current Build: 2600
Service Pack: 3
Current Type: Multiprocessor Free
Registered Organization:
Registered Owner: Scott Rader

*----> Task List <----*
0 System Process
4 System
756 smss.exe
812 csrss.exe
840 winlogon.exe
892 services.exe
904 lsass.exe
1140 svchost.exe
1208 svchost.exe
1260 MsMpEng.exe
1300 svchost.exe
1352 svchost.exe
1492 EvtEng.exe
1552 S24EvMon.exe
1588 WLKeeper.exe
1656 svchost.exe
1688 svchost.exe
1940 spoolsv.exe
1988 LVPrcSrv.exe
2000 SCardSvr.exe
168 AsfIpMon.exe
184 avgwdsvc.exe
216 LVComSer.exe
268 mcmscsvc.exe
568 mcnasvc.exe
448 mcproxy.exe
804 mcshield.exe
1844 MPFSrv.exe
2140 MskSrver.exe
2228 NICCONFIGSVC.exe
2336 nvsvc32.exe
2476 OSCMUtilityService.exe
2560 RegSrvc.exe
2576 avgrsx.exe
3252 StacSV.exe
3328 svchost.exe
3380 tcsd_win32.exe
3440 dllhost.exe
3500 svchost.exe
4092 Explorer.EXE
1672 dllhost.exe
2496 msdtc.exe
932 mcagent.exe
2780 wmiprvse.exe
196 LVComSer.exe
2200 alg.exe
2320 Apoint.exe
3048 ApMsgFwd.exe
2932 Apntex.exe
2808 HidFind.exe
3168 rundll32.exe
3288 RUNDLL32.EXE
1816 rundll32.exe
1340 stsystra.exe
3584 ZCfgSvc.exe
3868 ifrmewrk.exe
396 KADxMain.exe
896 MSASCui.exe
4580 systray.exe
4688 jusched.exe
4900 Dot1XCfg.exe
5564 avgtray.exe
1432 CPMonitor.exe
5160 ctfmon.exe
3352 NetMeter.exe
4128 DLG.exe
4840 natspeak.exe
4892 mcsysmon.exe
6104 OSCM3.exe
6004 OUTLOOK.EXE
5428 WINWORD.EXE
3912 dwwin.exe
2404 MpCmdRun.exe
1376 drwtsn32.exe

*----> Module List <----*
(0000000000370000 - 0000000000375000: C:\WINDOWS\system32\detoured.dll
(00000000003a0000 - 00000000003a5000: C:\WINDOWS\system32\avgrsstx.dll
(0000000000400000 - 0000000000409000: C:\WINDOWS\system32\Normaliz.dll
(0000000000d30000 - 0000000000d4b000: C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll
(0000000000e70000 - 0000000000e82000: C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll
(0000000001000000 - 00000000010ff000: C:\WINDOWS\Explorer.EXE
(0000000001100000 - 0000000001273000: C:\WINDOWS\system32\nview.dll
(00000000014d0000 - 0000000001795000: C:\WINDOWS\system32\xpsp2res.dll
(0000000002560000 - 0000000002687000: C:\WINDOWS\system32\urlmon.dll
(00000000026d0000 - 000000000272c000: C:\Program Files\Roxio\Drag-to-Disc\Shellex.dll
(0000000002730000 - 000000000273c000: C:\WINDOWS\system32\DLAAPI_W.DLL
(0000000002750000 - 000000000276f000: C:\WINDOWS\system32\CDRTC.DLL
(0000000002780000 - 00000000027a5000: C:\Program Files\Roxio\Drag-to-Disc\ShellRes.dll
(0000000010000000 - 0000000010063000: C:\WINDOWS\system32\wxvault.dll
(0000000010930000 - 0000000010979000: C:\WINDOWS\system32\PortableDeviceApi.dll
(00000000109c0000 - 00000000109ec000: C:\WINDOWS\system32\PortableDeviceTypes.dll
(00000000164a0000 - 00000000164c3000: C:\WINDOWS\system32\WPDShServiceObj.dll
(000000002b000000 - 000000002b038000: C:\Program Files\Nuance\NaturallySpeaking10\Program\dd10hook.dll
(0000000040100000 - 000000004013b000: C:\Program Files\Nuance\NaturallySpeaking10\Program\dd10axa.dll
(0000000042e40000 - 0000000042e7c000: C:\WINDOWS\system32\webcheck.dll
(0000000042ef0000 - 00000000434bd000: C:\WINDOWS\system32\ieframe.dll
(00000000478c0000 - 00000000478ca000: C:\WINDOWS\system32\dot3api.dll
(000000004d4f0000 - 000000004d549000: C:\WINDOWS\system32\WINHTTP.dll
(0000000056500000 - 0000000056528000: C:\Program Files\Nuance\NaturallySpeaking10\Program\dgniedct.dll
(000000005a980000 - 000000005a9f2000: C:\WINDOWS\system32\FXSAPI.dll
(000000005ad70000 - 000000005ada8000: C:\WINDOWS\system32\UxTheme.dll
(000000005b860000 - 000000005b8b5000: C:\WINDOWS\system32\NETAPI32.dll
(000000005ba60000 - 000000005bad1000: C:\WINDOWS\system32\themeui.dll
(000000005cb70000 - 000000005cb96000: C:\WINDOWS\system32\ShimEng.dll
(000000005d090000 - 000000005d12a000: C:\WINDOWS\system32\comctl32.dll
(000000005dca0000 - 000000005dcc8000: C:\WINDOWS\system32\OneX.DLL
(000000005dcd0000 - 000000005dcde000: C:\WINDOWS\system32\eappprxy.dll
(000000005f800000 - 000000005f816000: C:\PROGRA~1\WIFD1F~1\MpShHook.dll
(0000000060200000 - 000000006020f000: C:\Program Files\Nuance\NaturallySpeaking10\Program\nlutmgrhook.dll
(00000000605d0000 - 00000000605d9000: C:\WINDOWS\system32\mslbui.dll
(0000000068000000 - 0000000068036000: C:\WINDOWS\system32\rsaenh.dll
(0000000068df0000 - 0000000068e7d000: C:\WINDOWS\system32\fxsst.dll
(000000006f880000 - 000000006fa4a000: C:\WINDOWS\AppPatch\AcGenral.DLL
(0000000071600000 - 0000000071612000: C:\WINDOWS\system32\browselc.dll
(0000000071aa0000 - 0000000071aa8000: C:\WINDOWS\system32\WS2HELP.dll
(0000000071ab0000 - 0000000071ac7000: C:\WINDOWS\system32\WS2_32.dll
(0000000071b20000 - 0000000071b32000: C:\WINDOWS\system32\MPR.dll
(0000000071bf0000 - 0000000071c03000: C:\WINDOWS\system32\SAMLIB.dll
(0000000071c10000 - 0000000071c1e000: C:\WINDOWS\System32\ntlanman.dll
(0000000071c80000 - 0000000071c87000: C:\WINDOWS\System32\NETRAP.dll
(0000000071c90000 - 0000000071cd0000: C:\WINDOWS\System32\NETUI1.dll
(0000000071cd0000 - 0000000071ce7000: C:\WINDOWS\System32\NETUI0.dll
(0000000071d40000 - 0000000071d5b000: C:\WINDOWS\system32\actxprxy.dll
(0000000072410000 - 000000007242a000: C:\WINDOWS\system32\mydocs.dll
(0000000072d10000 - 0000000072d18000: C:\WINDOWS\system32\msacm32.drv
(0000000072d20000 - 0000000072d29000: C:\WINDOWS\system32\wdmaud.drv
(0000000073000000 - 0000000073026000: C:\WINDOWS\system32\WINSPOOL.DRV
(0000000073030000 - 0000000073040000: C:\WINDOWS\system32\WZCSAPI.DLL
(00000000736d0000 - 00000000736d6000: C:\WINDOWS\system32\dot3dlg.dll
(00000000745b0000 - 00000000745d2000: C:\WINDOWS\system32\eappcfg.dll
(0000000074720000 - 000000007476c000: C:\WINDOWS\system32\MSCTF.dll
(0000000074ad0000 - 0000000074ad8000: C:\WINDOWS\system32\POWRPROF.dll
(0000000074af0000 - 0000000074afa000: C:\WINDOWS\system32\BatMeter.dll
(0000000074c80000 - 0000000074cac000: C:\WINDOWS\system32\OLEACC.dll
(00000000754d0000 - 0000000075550000: C:\WINDOWS\system32\CRYPTUI.dll
(00000000755c0000 - 00000000755ee000: C:\WINDOWS\system32\msctfime.ime
(0000000075cf0000 - 0000000075d81000: C:\WINDOWS\system32\MLANG.dll
(0000000075f60000 - 0000000075f67000: C:\WINDOWS\System32\drprov.dll
(0000000075f70000 - 0000000075f7a000: C:\WINDOWS\System32\davclnt.dll
(0000000075f80000 - 000000007607d000: C:\WINDOWS\system32\BROWSEUI.dll
(0000000076080000 - 00000000760e5000: C:\WINDOWS\system32\MSVCP60.dll
(0000000076280000 - 00000000762a1000: C:\WINDOWS\system32\stobject.dll
(0000000076360000 - 0000000076370000: C:\WINDOWS\system32\WINSTA.dll
(0000000076380000 - 0000000076385000: C:\WINDOWS\system32\MSIMG32.dll
(0000000076390000 - 00000000763ad000: C:\WINDOWS\system32\IMM32.DLL
(00000000763b0000 - 00000000763f9000: C:\WINDOWS\system32\comdlg32.dll
(0000000076400000 - 00000000765a5000: C:\WINDOWS\system32\NETSHELL.dll
(0000000076600000 - 000000007661d000: C:\WINDOWS\System32\CSCDLL.dll
(0000000076980000 - 0000000076988000: C:\WINDOWS\system32\LINKINFO.dll
(0000000076990000 - 00000000769b5000: C:\WINDOWS\system32\ntshrui.dll
(00000000769c0000 - 0000000076a74000: C:\WINDOWS\system32\USERENV.dll
(0000000076b20000 - 0000000076b31000: C:\WINDOWS\system32\ATL.DLL
(0000000076b40000 - 0000000076b6d000: C:\WINDOWS\system32\WINMM.dll
(0000000076bf0000 - 0000000076bfb000: C:\WINDOWS\system32\PSAPI.DLL
(0000000076c00000 - 0000000076c2e000: C:\WINDOWS\system32\credui.dll
(0000000076c30000 - 0000000076c5e000: C:\WINDOWS\system32\WINTRUST.dll
(0000000076c90000 - 0000000076cb8000: C:\WINDOWS\system32\IMAGEHLP.dll
(0000000076d60000 - 0000000076d79000: C:\WINDOWS\system32\iphlpapi.dll
(0000000076e80000 - 0000000076e8e000: C:\WINDOWS\system32\rtutils.dll
(0000000076f50000 - 0000000076f58000: C:\WINDOWS\system32\WTSAPI32.dll
(0000000076f60000 - 0000000076f8c000: C:\WINDOWS\system32\WLDAP32.dll
(0000000076fd0000 - 000000007704f000: C:\WINDOWS\system32\CLBCATQ.DLL
(0000000077050000 - 0000000077115000: C:\WINDOWS\system32\COMRes.dll
(0000000077120000 - 00000000771ab000: C:\WINDOWS\system32\OLEAUT32.dll
(00000000773d0000 - 00000000774d3000: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
(00000000774e0000 - 000000007761d000: C:\WINDOWS\system32\ole32.dll
(0000000077690000 - 00000000776b1000: C:\WINDOWS\system32\NTMARTA.DLL
(0000000077920000 - 0000000077a13000: C:\WINDOWS\system32\SETUPAPI.dll
(0000000077a20000 - 0000000077a74000: C:\WINDOWS\System32\cscui.dll
(0000000077a80000 - 0000000077b15000: C:\WINDOWS\system32\CRYPT32.dll
(0000000077b20000 - 0000000077b32000: C:\WINDOWS\system32\MSASN1.dll
(0000000077b40000 - 0000000077b62000: C:\WINDOWS\system32\apphelp.dll
(0000000077bd0000 - 0000000077bd7000: C:\WINDOWS\system32\midimap.dll
(0000000077be0000 - 0000000077bf5000: C:\WINDOWS\system32\MSACM32.dll
(0000000077c00000 - 0000000077c08000: C:\WINDOWS\system32\VERSION.dll
(0000000077c10000 - 0000000077c68000: C:\WINDOWS\system32\msvcrt.dll
(0000000077dd0000 - 0000000077e6b000: C:\WINDOWS\system32\ADVAPI32.dll
(0000000077e70000 - 0000000077f02000: C:\WINDOWS\system32\RPCRT4.dll
(0000000077f10000 - 0000000077f59000: C:\WINDOWS\system32\GDI32.dll
(0000000077f60000 - 0000000077fd6000: C:\WINDOWS\system32\SHLWAPI.dll
(0000000077fe0000 - 0000000077ff1000: C:\WINDOWS\system32\Secur32.dll
(0000000078000000 - 0000000078045000: C:\WINDOWS\system32\iertutil.dll
(0000000078050000 - 0000000078120000: C:\WINDOWS\system32\WININET.dll
(0000000078130000 - 00000000781cb000: C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\MSVCR80.dll
(000000007c420000 - 000000007c4a7000: C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\MSVCP80.dll
(000000007c800000 - 000000007c8f6000: C:\WINDOWS\system32\kernel32.dll
(000000007c900000 - 000000007c9af000: C:\WINDOWS\system32\ntdll.dll
(000000007c9c0000 - 000000007d1d7000: C:\WINDOWS\system32\SHELL32.dll
(000000007d1e0000 - 000000007d49c000: C:\WINDOWS\system32\msi.dll
(000000007e290000 - 000000007e401000: C:\WINDOWS\system32\SHDOCVW.dll
(000000007e410000 - 000000007e4a1000: C:\WINDOWS\system32\USER32.dll
(000000007e720000 - 000000007e7d0000: C:\WINDOWS\system32\SXS.DLL

*----> State Dump for Thread Id 0x748 <----*

eax=7e2939d0 ebx=00000003 ecx=000f5ac0 edx=00001801 esi=00094fd8 edi=00000000
eip=7c90e4f4 esp=0007fef0 ebp=0007ff08 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202

*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\ntdll.dll -
function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\SHELL32.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Module load completed but symbols could not be loaded for C:\WINDOWS\Explorer.EXE
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\kernel32.dll -
ChildEBP RetAddr Args to Child
0007ff08 7ca0d034 00000000 0007ff5c 01013256 ntdll!KiFastSystemCallRet
0007ff14 01013256 00094fd8 7ffd8000 0007ffc0 SHELL32!Ordinal201+0x28
0007ff5c 0101a5c7 00000000 00000000 00020892 Explorer+0x13256
0007ffc0 7c817067 00000010 000810a0 7ffd8000 Explorer+0x1a5c7
0007fff0 00000000 0101a55f 00000000 78746341 kernel32!RegisterWaitForInputIdle+0x49

*----> Raw Stack Dump <----*
000000000007fef0 18 94 41 7e 80 4a 9f 7c - 2e 93 80 7c d8 4f 09 00 ..A~.J.|...|.O..
000000000007ff00 d8 4f 09 00 14 ff 07 00 - 14 ff 07 00 34 d0 a0 7c .O..........4..|
000000000007ff10 00 00 00 00 5c ff 07 00 - 56 32 01 01 d8 4f 09 00 ....\...V2...O..
000000000007ff20 00 80 fd 7f c0 ff 07 00 - 00 00 00 00 24 fd 07 00 ............$...
000000000007ff30 50 ff 07 00 e0 ff 07 00 - ec d7 90 7c f5 ac 80 7c P..........|...|
000000000007ff40 ff ff ff ff 0c 00 00 00 - 00 00 00 00 57 37 01 00 ............W7..
000000000007ff50 ec 00 00 00 01 00 00 00 - d8 4f 09 00 c0 ff 07 00 .........O......
000000000007ff60 c7 a5 01 01 00 00 00 00 - 00 00 00 00 92 08 02 00 ................
000000000007ff70 01 00 00 00 10 00 00 00 - a0 10 08 00 44 00 00 00 ............D...
000000000007ff80 e4 08 02 00 c4 08 02 00 - 94 08 02 00 00 00 00 00 ................
000000000007ff90 00 00 00 00 00 00 00 00 - 00 00 00 00 60 20 19 00 ............` ..
000000000007ffa0 00 00 00 00 f7 6a 91 7c - 01 00 00 00 01 00 00 00 .....j.|........
000000000007ffb0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000007ffc0 f0 ff 07 00 67 70 81 7c - 10 00 00 00 a0 10 08 00 ....gp.|........
000000000007ffd0 00 80 fd 7f ed b6 54 80 - c8 ff 07 00 20 b0 ec 84 ......T..... ...
000000000007ffe0 ff ff ff ff c0 9a 83 7c - 70 70 81 7c 00 00 00 00 .......|pp.|....
000000000007fff0 00 00 00 00 00 00 00 00 - 5f a5 01 01 00 00 00 00 ........_.......
0000000000080000 41 63 74 78 20 00 00 00 - 01 00 00 00 98 24 00 00 Actx ........$..
0000000000080010 c4 00 00 00 00 00 00 00 - 20 00 00 00 00 00 00 00 ........ .......
0000000000080020 14 00 00 00 01 00 00 00 - 06 00 00 00 34 00 00 00 ............4...

*----> State Dump for Thread Id 0xc38 <----*

eax=00000018 ebx=000f2398 ecx=7e419491 edx=00fef624 esi=038afa34 edi=00000445
eip=77446215 esp=00fef464 ebp=00fef4f8 iopl=0 nv up ei ng nz ac pe cy
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000293

*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll -
function: comctl32!CreateToolbar
774461f3 45 inc ebp
774461f4 b88983a000 mov eax,0xa08389
774461f9 0000 add [eax],al
774461fb 6a01 push 0x1
774461fd 6a00 push 0x0
774461ff ff75b4 push dword ptr [ebp-0x4c]
77446202 ff159c143d77 call dword ptr [comctl32!Ordinal249+0x149c (773d149c)]
77446208 e965010000 jmp comctl32!CreateToolbar+0x17be (77446372)
7744620d 8b4360 mov eax,[ebx+0x60]
77446210 e95f010000 jmp comctl32!CreateToolbar+0x17c0 (77446374)
FAULT ->77446215 ff7604 push dword ptr [esi+0x4] ds:0023:038afa38=????????
77446218 ff36 push dword ptr [esi]
7744621a 53 push ebx
7744621b e8aba8ffff call comctl32!Ordinal384+0x54c1b (77440acb)
77446220 e94f010000 jmp comctl32!CreateToolbar+0x17c0 (77446374)
77446225 8b55b8 mov edx,[ebp-0x48]
77446228 8d8bb0000000 lea ecx,[ebx+0xb0]
7744622e 8b01 mov eax,[ecx]
77446230 8bfa mov edi,edx
77446232 23fe and edi,esi
77446234 8939 mov [ecx],edi

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\USER32.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\MSCTF.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\SHLWAPI.dll -
ChildEBP RetAddr Args to Child
00fef4f8 7e418734 000200d2 00000445 00000000 comctl32!CreateToolbar+0x1661
00fef524 7e418816 77444beb 000200d2 00000445 USER32!GetDC+0x6d
00fef58c 7e42a013 000a2650 77444beb 000200d2 USER32!GetDC+0x14f
00fef5bc 7e42a039 77444beb 000200d2 00000445 USER32!IsWindowUnicode+0xa1
00fef5dc 773e1b67 77444beb 000200d2 00000445 USER32!CallWindowProcW+0x1b
00fef5f8 773e1eba 000200d2 00000445 00000000 comctl32!Ordinal11+0x328
00fef654 773e207c 000f0550 000200d2 00000445 comctl32!RemoveWindowSubclass+0x17e
00fef678 010021b2 000200d2 00000445 00000000 comctl32!DefSubclassProc+0x46
00fef694 773e1eba 000200d2 00000445 00000000 Explorer+0x21b2
00fef6f0 773e20df 000f0550 000200d2 00000445 comctl32!RemoveWindowSubclass+0x17e
00fef744 7e418734 000200d2 00000445 00000000 comctl32!DefSubclassProc+0xa9
00fef770 7e418816 773e208b 000200d2 00000445 USER32!GetDC+0x6d
00fef7d8 7e428ea0 000a2650 773e208b 000200d2 USER32!GetDC+0x14f
00fef82c 7e428eec 0057a4c8 00000445 00000000 USER32!DefWindowProcW+0x180
00fef854 7c90e453 00fef864 00000018 0057a4c8 USER32!DefWindowProcW+0x1cc
00fef8a4 7e42a43b 00fef924 00000000 00000200 ntdll!KiUserCallbackDispatcher+0x13
00fef8d0 7473f18f 00fef924 00000000 00000200 USER32!PeekMessageA+0xfb
00fef8fc 7473f734 00fef924 00000000 00000200 MSCTF!TF_CreateCicLoadMutex+0x81a4
00fef944 7473ff89 00000200 00000200 00000000 MSCTF!TF_CreateCicLoadMutex+0x8749
00fef964 74740138 0000010a 00000000 02431a68 MSCTF!TF_CheckThreadInputIdle+0x614
00fef9a0 7474067d 00fefb14 00001474 00fefa00 MSCTF!TF_CheckThreadInputIdle+0x7c3
00fefc24 74740b92 02920028 00000028 00fefce4 MSCTF!TF_CheckThreadInputIdle+0xd08
00fefc38 74740ffa 02431a68 00000028 00000005 MSCTF!TF_CheckThreadInputIdle+0x121d
00fefca4 74741738 00000003 00000001 00fefcb8 MSCTF!TF_CheckThreadInputIdle+0x1685
00fefcd0 7473d307 02431a60 00000007 000900c6 MSCTF!TF_CheckThreadInputIdle+0x1dc3
00fefe0c 7e418734 000900c6 0000c183 00000000 MSCTF!TF_CreateCicLoadMutex+0x631c
00fefe38 7e418816 7474021e 000900c6 0000c183 USER32!GetDC+0x6d
00fefea0 7e4189cd 00000000 7474021e 000900c6 USER32!GetDC+0x14f
00feff00 7e418a10 00feff28 00000000 00feff44 USER32!GetWindowLongW+0x127
00feff10 01001a35 00feff28 00000000 010460f8 USER32!DispatchMessageW+0xf
00feff44 0100ffd1 00000000 00feffb4 77f76f42 Explorer+0x1a35
00feff50 77f76f42 010460f8 0000005c 008a0046 Explorer+0xffd1
00feffb4 7c80b713 00000000 0000005c 008a0046 SHLWAPI!Ordinal505+0x3e9
00feffec 00000000 77f76ed3 0007fdbc 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
0000000000fef464 60 f5 fe 00 eb 4b 44 77 - 00 00 00 00 fc f4 fe 00 `....KDw........
0000000000fef474 1d 1b 00 01 30 01 01 00 - 4e 00 00 00 71 1b 00 01 ....0...N...q...
0000000000fef484 f8 60 04 01 fc f4 fe 00 - 1d 1b 00 01 00 00 00 00 .`..............
0000000000fef494 c0 f4 fe 00 34 87 41 7e - 30 01 01 00 4e 00 00 00 ....4.A~0...N...
0000000000fef4a4 05 a0 00 00 34 fa 8a 03 - d2 00 02 00 00 00 00 00 ....4...........
0000000000fef4b4 00 00 00 00 fc f4 fe 00 - 1d 1b 00 01 28 f5 fe 00 ............(...
0000000000fef4c4 d9 8b 41 7e 00 b0 fd 7f - 28 f5 fe 00 5a 88 41 7e ..A~....(...Z.A~
0000000000fef4d4 e8 f4 fe 00 2a 88 41 7e - 50 26 0a 00 30 01 01 00 ....*.A~P&..0...
0000000000fef4e4 ec f6 fe 00 14 00 00 00 - 04 f5 fe 00 01 b4 42 7e ..............B~
0000000000fef4f4 7e 70 00 00 24 f5 fe 00 - 34 87 41 7e d2 00 02 00 ~p..$...4.A~....
0000000000fef504 45 04 00 00 00 00 00 00 - 34 fa 8a 03 eb 4b 44 77 E.......4....KDw
0000000000fef514 cd ab ba dc 00 00 00 00 - 60 f5 fe 00 eb 4b 44 77 ........`....KDw
0000000000fef524 8c f5 fe 00 16 88 41 7e - eb 4b 44 77 d2 00 02 00 ......A~.KDw....
0000000000fef534 45 04 00 00 00 00 00 00 - 34 fa 8a 03 45 04 00 00 E.......4...E...
0000000000fef544 eb 4b 44 77 00 00 00 00 - 14 00 00 00 01 00 00 00 .KDw............
0000000000fef554 00 00 00 00 00 00 00 00 - 10 00 00 00 00 00 00 00 ................
0000000000fef564 e0 2c 17 01 01 00 00 00 - 00 00 00 00 00 00 00 00 .,..............
0000000000fef574 40 f5 fe 00 88 f0 fe 00 - 44 f6 fe 00 8f 04 44 7e @.......D.....D~
0000000000fef584 30 88 41 7e 00 00 00 00 - bc f5 fe 00 13 a0 42 7e 0.A~..........B~
0000000000fef594 50 26 0a 00 eb 4b 44 77 - d2 00 02 00 45 04 00 00 P&...KDw....E...

*----> State Dump for Thread Id 0xc34 <----*

eax=7c927ebb ebx=00000000 ecx=77dd6a77 edx=77dd6a3e esi=ffffffff edi=7c90f648
eip=7c90e4f4 esp=017dff9c ebp=017dffb4 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
017dffb4 7c80b713 00000000 7c90f648 ffffffff ntdll!KiFastSystemCallRet
017dffec 00000000 7c927ebb 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
00000000017dff9c fc d1 90 7c 02 7f 92 7c - 01 00 00 00 ac ff 7d 01 ...|...|......}.
00000000017dffac 00 00 00 00 00 00 00 80 - ec ff 7d 01 13 b7 80 7c ..........}....|
00000000017dffbc 00 00 00 00 48 f6 90 7c - ff ff ff ff 00 00 00 00 ....H..|........
00000000017dffcc 00 a0 fd 7f 00 e6 1b 87 - c0 ff 7d 01 80 ce 8a 85 ..........}.....
00000000017dffdc ff ff ff ff c0 9a 83 7c - 20 b7 80 7c 00 00 00 00 .......| ..|....
00000000017dffec 00 00 00 00 00 00 00 00 - bb 7e 92 7c 00 00 00 00 .........~.|....
00000000017dfffc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000017e000c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000017e001c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000017e002c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000017e003c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000017e004c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000017e005c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000017e006c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000017e007c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000017e008c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000017e009c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000017e00ac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000017e00bc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000017e00cc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

*----> State Dump for Thread Id 0xc24 <----*

eax=00000102 ebx=00000000 ecx=7ffd9000 edx=7c90e4f4 esi=7c97b420 edi=7c97b440
eip=7c90e4f4 esp=0181ff70 ebp=0181ffb4 iopl=0 nv up ei ng nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000286

function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0181ffb4 7c80b713 00000000 00fefce4 00fefce8 ntdll!KiFastSystemCallRet
0181ffec 00000000 7c910230 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
000000000181ff70 2c da 90 7c 6d 02 91 7c - 1c 02 00 00 ac ff 81 01 ,..|m..|........
000000000181ff80 b0 ff 81 01 98 ff 81 01 - a0 ff 81 01 e4 fc fe 00 ................
000000000181ff90 e8 fc fe 00 00 00 00 00 - 00 00 00 00 38 b4 16 00 ............8...
000000000181ffa0 00 7c 28 e8 ff ff ff ff - a0 4c 95 b8 c9 7a 92 7c .|(......L...z.|
000000000181ffb0 e8 b9 16 00 ec ff 81 01 - 13 b7 80 7c 00 00 00 00 ...........|....
000000000181ffc0 e4 fc fe 00 e8 fc fe 00 - 00 00 00 00 00 90 fd 7f ................
000000000181ffd0 00 e6 1b 87 c0 ff 81 01 - 88 2b 53 85 ff ff ff ff .........+S.....
000000000181ffe0 c0 9a 83 7c 20 b7 80 7c - 00 00 00 00 00 00 00 00 ...| ..|........
000000000181fff0 00 00 00 00 30 02 91 7c - 00 00 00 00 00 00 00 00 ....0..|........
0000000001820000 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001820010 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001820020 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001820030 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001820040 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001820050 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001820060 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001820070 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001820080 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001820090 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000018200a0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

*----> State Dump for Thread Id 0xc9c <----*

eax=000000c0 ebx=00000000 ecx=00fefbbc edx=00000000 esi=00000000 edi=00000001
eip=7c90e4f4 esp=0185fcec ebp=0185ffb4 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0185ffb4 7c80b713 00000000 00000020 00fefce4 ntdll!KiFastSystemCallRet
0185ffec 00000000 7c929b6f 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
000000000185fcec 2c df 90 7c 96 9c 92 7c - 03 00 00 00 30 fd 85 01 ,..|...|....0...
000000000185fcfc 01 00 00 00 01 00 00 00 - 00 00 00 00 20 00 00 00 ............ ...
000000000185fd0c e4 fc fe 00 00 00 00 00 - 80 c9 97 7c 80 c9 97 7c ...........|...|
000000000185fd1c 24 02 00 00 9c 0c 00 00 - 03 00 00 00 03 00 00 00 $...............
000000000185fd2c 02 00 00 00 20 02 00 00 - 08 02 00 00 48 05 00 00 .... .......H...
000000000185fd3c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000185fd4c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000185fd5c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000185fd6c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000185fd7c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000185fd8c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000185fd9c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000185fdac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000185fdbc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000185fdcc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000185fddc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000185fdec 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000185fdfc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000185fe0c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000185fe1c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

*----> State Dump for Thread Id 0xee4 <----*

eax=00000000 ebx=018bfd58 ecx=018bfe2c edx=00001c07 esi=00000000 edi=7ffd8000
eip=7c90e4f4 esp=018bfd30 ebp=018bfdcc iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
018bfdcc 7e4195f9 00000008 018bfdf4 00000000 ntdll!KiFastSystemCallRet
018bfe28 7c9f4d20 00000007 018bfe50 ffffffff USER32!GetLastInputInfo+0x105
018bff4c 7ca0b53c 77f76f42 00000000 7c8099ea SHELL32!Shell_GetCachedImageIndex+0xd40
018bffb4 7c80b713 00000000 7c8099ea 00090000 SHELL32!Ordinal753+0x133
018bffec 00000000 77f76ed3 00fef4d4 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
00000000018bfd30 2c df 90 7c 74 95 80 7c - 08 00 00 00 58 fd 8b 01 ,..|t..|....X...
00000000018bfd40 01 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000018bfd50 08 00 00 00 02 00 00 00 - b8 07 00 00 60 05 00 00 ............`...
00000000018bfd60 00 04 00 00 74 03 00 00 - 50 02 00 00 38 02 00 00 ....t...P...8...
00000000018bfd70 68 02 00 00 44 02 00 00 - 14 00 00 00 01 00 00 00 h...D...........
00000000018bfd80 90 ad 0d 00 00 00 00 00 - 00 00 00 00 ec fd 8b 01 ................
00000000018bfd90 8f 04 44 7e 30 88 41 7e - 00 80 fd 7f 00 60 fd 7f ..D~0.A~.....`..
00000000018bfda0 cd 89 41 7e 00 00 00 00 - 58 fd 8b 01 3c 00 02 00 ..A~....X...<...
00000000018bfdb0 08 00 00 00 4c fd 8b 01 - 03 00 00 00 dc ff 8b 01 ....L...........
00000000018bfdc0 c0 9a 83 7c 68 96 80 7c - 00 00 00 00 28 fe 8b 01 ...|h..|....(...
00000000018bfdd0 f9 95 41 7e 08 00 00 00 - f4 fd 8b 01 00 00 00 00 ..A~............
00000000018bfde0 ff ff ff ff 01 00 00 00 - 70 66 0d 00 07 00 00 00 ........pf......
00000000018bfdf0 00 00 00 00 b8 07 00 00 - 60 05 00 00 00 04 00 00 ........`.......
00000000018bfe00 74 03 00 00 50 02 00 00 - 38 02 00 00 68 02 00 00 t...P...8...h...
00000000018bfe10 44 02 00 00 67 89 00 00 - 00 00 00 00 01 00 00 00 D...g...........
00000000018bfe20 00 60 fd 7f 44 02 00 00 - 4c ff 8b 01 20 4d 9f 7c .`..D...L... M.|
00000000018bfe30 07 00 00 00 50 fe 8b 01 - ff ff ff ff ff 04 00 00 ....P...........
00000000018bfe40 f4 fd 8b 01 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000018bfe50 b8 07 00 00 60 05 00 00 - 00 04 00 00 74 03 00 00 ....`.......t...
00000000018bfe60 50 02 00 00 38 02 00 00 - 68 02 00 00 70 66 0d 00 P...8...h...pf..

*----> State Dump for Thread Id 0x21c <----*

eax=0016c674 ebx=00000000 ecx=000a4058 edx=776061a8 esi=000bcaa8 edi=000bcae4
eip=7c90e4f4 esp=01affe18 ebp=01afff80 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\RPCRT4.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
01afff80 77e76caf 01afffa8 77e76ad1 000bcaa8 ntdll!KiFastSystemCallRet
01afff88 77e76ad1 000bcaa8 5cb77803 00000001 RPCRT4!I_RpcBCacheFree+0x61c
01afffa8 77e76c97 000bc960 01afffec 7c80b713 RPCRT4!I_RpcBCacheFree+0x43e
01afffb4 7c80b713 0013cc60 5cb77803 00000001 RPCRT4!I_RpcBCacheFree+0x604
01afffec 00000000 77e76c7d 0013cc60 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
0000000001affe18 8c da 90 7c e3 65 e7 77 - d4 01 00 00 74 ff af 01 ...|.e.w....t...
0000000001affe28 00 00 00 00 c0 63 42 02 - 00 00 00 00 ff ff ff 03 .....cB.........
0000000001affe38 ff ff ff 03 d0 69 01 82 - 00 00 00 00 fc 3c 88 c0 .....i.......<..
0000000001affe48 98 cf 6c 85 40 25 76 f7 - 02 00 00 00 00 00 4f 80 ..l.@%v.......O.
0000000001affe58 94 bb c4 b9 c0 fe 3f c0 - 00 70 fd 7f 00 00 00 00 ......?..p......
0000000001affe68 b8 fe 3f 02 02 00 00 00 - 9b 38 52 80 00 70 fd 7f ..?......8R..p..
0000000001affe78 01 00 00 00 00 00 00 00 - b8 fe 3f c0 00 00 00 00 ..........?.....
0000000001affe88 00 00 00 00 f8 1f 60 c0 - 30 bc c4 b9 fa 3f 52 80 ......`.0....?R.
0000000001affe98 94 bb c4 b9 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001affea8 a8 3c 04 87 a0 cd 6c 85 - 01 ce 6c 85 00 00 00 00 .<....l...l.....
0000000001affeb8 b8 fe 3f c0 70 b9 6c 85 - 00 00 00 00 ec bb c4 b9 ..?.p.l.........
0000000001affec8 00 00 10 00 8f 1a 00 00 - 6c ce 6c 85 ff ff a8 01 ........l.l.....
0000000001affed8 a0 cd 6c 85 00 00 00 00 - 90 01 d8 f4 00 00 a9 01 ..l.............
0000000001affee8 50 bb c4 b9 60 01 d8 f4 - ff ff ff ff 00 70 fd 7f P...`........p..
0000000001affef8 60 9e 4d 80 ff ff ff ff - 4a 36 5b 80 1c 16 54 80 `.M.....J6[...T.
0000000001afff08 ff ff ff ff d0 bc c4 b9 - d4 bc c4 b9 00 80 00 00 ................
0000000001afff18 38 25 76 f7 b4 58 54 80 - 00 cd 6c 85 a4 b1 4f 80 8%v..XT...l...O.
0000000001afff28 14 cf 6c 85 80 ff af 01 - ae df e7 77 48 ff af 01 ..l........wH...
0000000001afff38 be df e7 77 e0 10 90 7c - 60 4f 12 00 60 cc 13 00 ...w...|`O..`...
0000000001afff48 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff ../M.....]......

*----> State Dump for Thread Id 0xb70 <----*

eax=72d230e8 ebx=01defef8 ecx=00000036 edx=0017ff08 esi=00000000 edi=7ffd8000
eip=7c90e4f4 esp=01defed0 ebp=01deff6c iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\wdmaud.drv -
ChildEBP RetAddr Args to Child
01deff6c 7c80a105 00000002 01deffa4 00000000 ntdll!KiFastSystemCallRet
01deff88 72d2312a 00000002 01deffa4 00000000 kernel32!WaitForMultipleObjects+0x18
01deffb4 7c80b713 00000000 00640075 0064002e wdmaud!midMessage+0x348
01deffec 00000000 72d230e8 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
0000000001defed0 2c df 90 7c 74 95 80 7c - 02 00 00 00 f8 fe de 01 ,..|t..|........
0000000001defee0 01 00 00 00 00 00 00 00 - 00 00 00 00 75 00 64 00 ............u.d.
0000000001defef0 00 00 00 00 00 00 00 00 - dc 03 00 00 c0 03 00 00 ................
0000000001deff00 14 ff de 01 00 26 80 7c - 30 25 80 7c e0 09 18 00 .....&.|0%.|....
0000000001deff10 d1 4c 83 7c 14 00 00 00 - 14 00 00 00 01 00 00 00 .L.|............
0000000001deff20 00 93 0a 00 00 00 00 00 - 00 00 00 00 f0 2c 15 00 .............,..
0000000001deff30 00 80 fd 7f 00 a0 fa 7f - 00 80 fd 7f 00 a0 fa 7f ................
0000000001deff40 08 ff de 01 00 00 00 00 - f8 fe de 01 c0 9a 83 7c ...............|
0000000001deff50 02 00 00 00 ec fe de 01 - 00 26 80 7c dc ff de 01 .........&.|....
0000000001deff60 c0 9a 83 7c 68 96 80 7c - 00 00 00 00 88 ff de 01 ...|h..|........
0000000001deff70 05 a1 80 7c 02 00 00 00 - a4 ff de 01 00 00 00 00 ...|............
0000000001deff80 ff ff ff ff 00 00 00 00 - b4 ff de 01 2a 31 d2 72 ............*1.r
0000000001deff90 02 00 00 00 a4 ff de 01 - 00 00 00 00 ff ff ff ff ................
0000000001deffa0 2e 00 64 00 dc 03 00 00 - c0 03 00 00 02 00 00 00 ..d.............
0000000001deffb0 00 00 00 00 ec ff de 01 - 13 b7 80 7c 00 00 00 00 ...........|....
0000000001deffc0 75 00 64 00 2e 00 64 00 - 00 00 00 00 00 a0 fa 7f u.d...d.........
0000000001deffd0 00 e6 1b 87 c0 ff de 01 - 58 6e 68 85 ff ff ff ff ........Xnh.....
0000000001deffe0 c0 9a 83 7c 20 b7 80 7c - 00 00 00 00 00 00 00 00 ...| ..|........
0000000001defff0 00 00 00 00 e8 30 d2 72 - 00 00 00 00 00 00 00 00 .....0.r........
0000000001df0000 ff ff ff ff 00 00 00 00 - 43 00 3a 00 5c 00 57 00 ........C.:.\.W.

*----> State Dump for Thread Id 0x818 <----*

eax=7ffa9000 ebx=00004e20 ecx=40000000 edx=0000183b esi=0224fd68 edi=7e4191c6
eip=7c90e4f4 esp=0224fcf8 ebp=0224fd14 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\stobject.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0224fd14 76281565 0224fd68 00000000 00000000 ntdll!KiFastSystemCallRet
0224fd8c 7628362e 76280000 00000000 000200fc stobject+0x1565
0224ffb4 7c80b713 00000000 00000000 00000000 stobject!DllCanUnloadNow+0x19e4
0224ffec 00000000 762835df 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
000000000224fcf8 be 91 41 7e f1 91 41 7e - 68 fd 24 02 00 00 00 00 ..A~..A~h.$.....
000000000224fd08 00 00 00 00 00 00 00 00 - 00 00 00 00 8c fd 24 02 ..............$.
000000000224fd18 65 15 28 76 68 fd 24 02 - 00 00 00 00 00 00 00 00 e.(vh.$.........
000000000224fd28 00 00 00 00 00 00 00 00 - 00 00 28 76 00 00 00 00 ..........(v....
000000000224fd38 30 00 00 00 00 40 00 00 - 21 13 28 76 00 00 00 00 0....@..!.(v....
000000000224fd48 1e 00 00 00 00 00 28 76 - 9f 01 02 00 11 00 01 00 ......(v........
000000000224fd58 10 00 00 00 00 00 00 00 - dc 30 28 76 00 00 00 00 .........0(v....
000000000224fd68 fc 00 02 00 df c1 00 00 - 06 00 00 00 03 00 00 00 ................
000000000224fd78 4b 07 1c 00 b1 02 00 00 - de 01 00 00 00 00 00 00 K...............
000000000224fd88 00 00 00 00 b4 ff 24 02 - 2e 36 28 76 00 00 28 76 ......$..6(v..(v
000000000224fd98 00 00 00 00 fc 00 02 00 - 01 00 00 00 00 00 00 00 ................
000000000224fda8 43 00 3a 00 5c 00 57 00 - 49 00 4e 00 44 00 4f 00 C.:.\.W.I.N.D.O.
000000000224fdb8 57 00 53 00 5c 00 73 00 - 79 00 73 00 74 00 65 00 W.S.\.s.y.s.t.e.
000000000224fdc8 6d 00 33 00 32 00 5c 00 - 73 00 74 00 6f 00 62 00 m.3.2.\.s.t.o.b.
000000000224fdd8 6a 00 65 00 63 00 74 00 - 2e 00 64 00 6c 00 6c 00 j.e.c.t...d.l.l.
000000000224fde8 00 00 81 7c 1b 00 00 00 - 00 02 00 00 fc ff 24 02 ...|..........$.
000000000224fdf8 23 00 00 00 04 36 00 e1 - 01 00 00 00 40 a9 f2 01 #....6......@...
000000000224fe08 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000224fe18 00 00 00 00 ff ff ff ff - 40 7b f2 b9 00 c3 1b 87 ........@{......
000000000224fe28 ed b6 54 80 00 00 10 00 - 28 7a 0e 87 ff ff ff 03 ..T.....(z......

*----> State Dump for Thread Id 0xcd4 <----*

eax=7ffa8000 ebx=003fb560 ecx=00000001 edx=00000113 esi=023dfe14 edi=164be000
eip=7c90e4f4 esp=023dfdd0 ebp=023dfdec iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\WPDShServiceObj.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
023dfdec 164aa888 023dfe14 00000000 00000000 ntdll!KiFastSystemCallRet
023dff50 77f76f42 003fb560 00fef314 7c90e900 WPDShServiceObj+0xa888
023dffb4 7c80b713 00000000 00fef314 7c90e900 SHLWAPI!Ordinal505+0x3e9
023dffec 00000000 77f76ed3 00fef3f8 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
00000000023dfdd0 be 91 41 7e f1 91 41 7e - 14 fe 3d 02 00 00 00 00 ..A~..A~..=.....
00000000023dfde0 00 00 00 00 00 00 00 00 - d4 19 4a 16 50 ff 3d 02 ..........J.P.=.
00000000023dfdf0 88 a8 4a 16 14 fe 3d 02 - 00 00 00 00 00 00 00 00 ..J...=.........
00000000023dfe00 00 00 00 00 91 63 3d 02 - 00 00 00 00 00 00 00 00 .....c=.........
00000000023dfe10 00 00 00 00 74 01 02 00 - 13 01 00 00 0d 00 00 00 ....t...........
00000000023dfe20 00 00 00 00 78 0f 1c 00 - b1 02 00 00 de 01 00 00 ....x...........
00000000023dfe30 01 00 00 00 60 b5 3f 00 - a5 83 4a 16 b2 83 4a 16 ....`.?...J...J.
00000000023dfe40 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000023dfe50 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000023dfe60 00 00 00 00 00 00 00 00 - 00 00 00 00 3b 00 00 00 ............;...
00000000023dfe70 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000023dfe80 54 f3 4f 77 c0 68 60 77 - 14 00 00 00 13 00 00 00 T.Ow.h`w........
00000000023dfe90 17 00 00 00 b4 fe 3d 02 - d3 f4 4f 77 64 48 0a 00 ......=...OwdH..
00000000023dfea0 17 00 00 00 01 00 00 00 - cc d6 4f 77 44 38 10 00 ..........OwD8..
00000000023dfeb0 c4 fe 3d 02 ec d7 4f 77 - e8 03 00 00 22 d2 4f 77 ..=...Ow....".Ow
00000000023dfec0 60 68 60 77 ef d1 4f 77 - 68 68 60 77 f1 f5 4f 77 `h`w..Owhh`w..Ow
00000000023dfed0 74 8f 17 00 50 ff 3d 02 - 88 8f 17 00 b5 d8 4f 77 t...P.=.......Ow
00000000023dfee0 3c 48 0a 00 74 8f 17 00 - 50 ff 3d 02 bd f1 4f 77 <H..t...P.=...Ow
00000000023dfef0 f6 97 80 7c 50 ff 3d 02 - 3c 68 60 77 00 00 00 00 ...|P.=.<h`w....
00000000023dff00 28 ff 3d 02 03 f1 4f 77 - 74 8f 17 00 88 8f 17 00 (.=...Owt.......

*----> State Dump for Thread Id 0x74c <----*

eax=02520000 ebx=0241fd0c ecx=0241ff44 edx=7c90e4f4 esi=00000000 edi=7ffd8000
eip=7c90e4f4 esp=0241fce4 ebp=0241fd80 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0241fd80 7e4195f9 00000002 0241fda8 00000000 ntdll!KiFastSystemCallRet
0241fddc 164a9bea 00000001 0241fe2c ffffffff USER32!GetLastInputInfo+0x105
0241ff50 77f76f42 003fb560 00fef314 7c90e900 WPDShServiceObj+0x9bea
0241ffb4 7c80b713 00000000 00fef314 7c90e900 SHLWAPI!Ordinal505+0x3e9
0241ffec 00000000 77f76ed3 00fef3f8 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
000000000241fce4 2c df 90 7c 74 95 80 7c - 02 00 00 00 0c fd 41 02 ,..|t..|......A.
000000000241fcf4 01 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000241fd04 02 00 00 00 02 00 00 00 - 74 04 00 00 8c 04 00 00 ........t.......
000000000241fd14 3e 6a dd 77 77 6a dd 77 - a8 31 4a 16 01 00 00 80 >j.wwj.w.1J.....
000000000241fd24 54 00 00 00 18 00 00 00 - 14 00 00 00 01 00 00 00 T...............
000000000241fd34 40 e6 18 00 00 00 00 00 - 00 00 00 00 56 00 56 00 @...........V.V.
000000000241fd44 a8 31 4a 16 00 00 00 00 - 00 80 fd 7f 00 70 fa 7f .1J..........p..
000000000241fd54 fb bb 00 00 00 00 00 00 - 0c fd 41 02 98 fd 41 02 ..........A...A.
000000000241fd64 02 00 00 00 00 fd 41 02 - 8c fd 41 02 44 ff 41 02 ......A...A.D.A.
000000000241fd74 c0 9a 83 7c 68 96 80 7c - 00 00 00 00 dc fd 41 02 ...|h..|......A.
000000000241fd84 f9 95 41 7e 02 00 00 00 - a8 fd 41 02 00 00 00 00 ..A~......A.....
000000000241fd94 ff ff ff ff 01 00 00 00 - 00 00 00 00 9b 92 41 7e ..............A~
000000000241fda4 01 00 00 00 74 04 00 00 - 8c 04 00 00 63 ae 4b 16 ....t.......c.K.
000000000241fdb4 00 00 00 00 00 00 00 00 - 00 00 00 00 e0 b5 3f 00 ..............?.
000000000241fdc4 04 00 00 00 01 00 00 00 - 00 00 00 00 01 00 00 00 ................
000000000241fdd4 00 70 fa 7f 8c 04 00 00 - 50 ff 41 02 ea 9b 4a 16 .p......P.A...J.
000000000241fde4 01 00 00 00 2c fe 41 02 - ff ff ff ff 00 01 00 00 ....,.A.........
000000000241fdf4 a8 fd 41 02 91 63 41 02 - 00 00 00 00 00 00 00 00 ..A..cA.........
000000000241fe04 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000241fe14 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

*----> State Dump for Thread Id 0x11b8 <----*

eax=68df1c5d ebx=00edfef8 ecx=00010003 edx=00000003 esi=00000000 edi=7ffd8000
eip=7c90e4f4 esp=00edfed0 ebp=00edff6c iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\fxsst.dll -
ChildEBP RetAddr Args to Child
00edff6c 7c80a105 00000002 00edffac 00000000 ntdll!KiFastSystemCallRet
00edff88 68df1cc7 00000002 00edffac 00000000 kernel32!WaitForMultipleObjects+0x18
00edffb4 7c80b713 00010256 00000018 00000000 fxsst!IsFaxMessage+0x352
00edffec 00000000 68df1c5d 00010256 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
0000000000edfed0 2c df 90 7c 74 95 80 7c - 02 00 00 00 f8 fe ed 00 ,..|t..|........
0000000000edfee0 01 00 00 00 00 00 00 00 - 00 00 00 00 b4 ff ed 00 ................
0000000000edfef0 ed a0 80 7c 00 00 00 00 - 6c 06 00 00 3c 06 00 00 ...|....l...<...
0000000000edff00 b4 5e 01 00 0c 00 00 00 - 64 fe ed 00 00 00 09 00 .^......d.......
0000000000edff10 58 ff ed 00 00 e9 90 7c - 14 00 00 00 01 00 00 00 X......|........
0000000000edff20 40 35 17 00 00 00 00 00 - 00 00 00 00 88 fe ed 00 @5..............
0000000000edff30 fd 99 80 7c dc ff ed 00 - 00 80 fd 7f 00 60 fa 7f ...|.........`..
0000000000edff40 ff ff ff ff 00 00 00 00 - f8 fe ed 00 00 00 09 00 ................
0000000000edff50 02 00 00 00 ec fe ed 00 - 68 ff ed 00 dc ff ed 00 ........h.......
0000000000edff60 c0 9a 83 7c 68 96 80 7c - 00 00 00 00 88 ff ed 00 ...|h..|........
0000000000edff70 05 a1 80 7c 02 00 00 00 - ac ff ed 00 00 00 00 00 ...|............
0000000000edff80 ff ff ff ff 00 00 00 00 - b4 ff ed 00 c7 1c df 68 ...............h
0000000000edff90 02 00 00 00 ac ff ed 00 - 00 00 00 00 ff ff ff ff ................
0000000000edffa0 00 00 00 00 18 00 00 00 - 56 02 01 00 6c 06 00 00 ........V...l...
0000000000edffb0 3c 06 00 00 ec ff ed 00 - 13 b7 80 7c 56 02 01 00 <..........|V...
0000000000edffc0 18 00 00 00 00 00 00 00 - 56 02 01 00 00 60 fa 7f ........V....`..
0000000000edffd0 00 c6 1b 87 c0 ff ed 00 - 58 d4 fe 84 ff ff ff ff ........X.......
0000000000edffe0 c0 9a 83 7c 20 b7 80 7c - 00 00 00 00 00 00 00 00 ...| ..|........
0000000000edfff0 00 00 00 00 5d 1c df 68 - 56 02 01 00 00 00 00 00 ....]..hV.......
0000000000ee0000 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

*----> State Dump for Thread Id 0x12b0 <----*

eax=00e3ff98 ebx=000004b0 ecx=00000006 edx=7c90e4f4 esi=00e3ff98 edi=7e42772b
eip=7c90e4f4 esp=00e3ff54 ebp=00e3ff78 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

function: ntdll!KiFastSystemCallRet
7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
7c90e4df 8b0424 mov eax,[esp]
7c90e4e2 8be5 mov esp,ebp
7c90e4e4 5d pop ebp
7c90e4e5 c3 ret
7c90e4e6 8da42400000000 lea esp,[esp]
7c90e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c90e4f0 8bd4 mov edx,esp
7c90e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c90e4f4 c3 ret
7c90e4f5 8da42400000000 lea esp,[esp]
7c90e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c90e500 8d542408 lea edx,[esp+0x8]
7c90e504 cd2e int 2e
7c90e506 c3 ret
7c90e507 90 nop
ntdll!RtlRaiseException:
7c90e508 55 push ebp
7c90e509 8bec mov ebp,esp

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\WINMM.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
00e3ff78 76b44e31 00e3ff98 00000000 00000000 ntdll!KiFastSystemCallRet
00e3ffb4 7c80b713 000004b0 00000200 0000002b WINMM!PlaySoundW+0x7e2
00e3ffec 00000000 76b44dca 000004b0 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
0000000000e3ff54 be 91 41 7e 6b 77 42 7e - 98 ff e3 00 00 00 00 00 ..A~kwB~........
0000000000e3ff64 00 00 00 00 00 00 00 00 - b0 04 00 00 2b 77 42 7e ............+wB~
0000000000e3ff74 00 00 00 00 b4 ff e3 00 - 31 4e b4 76 98 ff e3 00 ........1N.v....
0000000000e3ff84 00 00 00 00 00 00 00 00 - 00 00 00 00 00 02 00 00 ................
0000000000e3ff94 2b 00 00 00 74 03 01 00 - df c1 00 00 06 00 00 00 +...t...........
0000000000e3ffa4 03 00 00 00 4b 07 1c 00 - b1 02 00 00 de 01 00 00 ....K...........
0000000000e3ffb4 ec ff e3 00 13 b7 80 7c - b0 04 00 00 00 02 00 00 .......|........
0000000000e3ffc4 2b 00 00 00 b0 04 00 00 - 00 40 fd 7f 00 c6 1b 87 +........@......
0000000000e3ffd4 c0 ff e3 00 e8 27 e3 84 - ff ff ff ff c0 9a 83 7c .....'.........|
0000000000e3ffe4 20 b7 80 7c 00 00 00 00 - 00 00 00 00 00 00 00 00 ..|............
0000000000e3fff4 ca 4d b4 76 b0 04 00 00 - 00 00 00 00 00 00 00 00 .M.v............
0000000000e40004 00 00 01 00 00 10 00 00 - 00 00 00 00 98 05 09 00 ................
0000000000e40014 00 00 4a 02 00 60 00 00 - 00 00 00 00 10 00 e4 00 ..J..`..........
0000000000e40024 00 90 49 02 00 60 00 00 - 00 00 00 00 d8 05 09 00 ..I..`..........
0000000000e40034 00 b0 48 02 00 60 00 00 - 00 00 00 00 90 00 e4 00 ..H..`..........
0000000000e40044 00 60 4c 02 00 70 00 00 - 00 00 00 00 60 00 e4 00 .`L..p......`...
0000000000e40054 00 e0 4a 02 00 70 00 00 - 00 00 00 00 a8 05 09 00 ..J..p..........
0000000000e40064 00 60 4b 02 00 60 00 00 - 00 00 00 00 f8 05 09 00 .`K..`..........
0000000000e40074 00 d0 47 02 00 40 00 00 - 00 00 00 00 c8 05 09 00 ..G..@..........
0000000000e40084 00 a0 45 02 00 10 00 00 - 00 00 00 00 a0 00 e4 00 ..E.............

Edited by srader, 08 October 2008 - 07:45 PM.


#9 usasma

usasma

    Still visually handicapped (avatar is memory developed by my Dad


  • BSOD Kernel Dump Expert
  • 25,090 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Southeastern CT, USA
  • Local time:09:56 PM

Posted 14 October 2008 - 12:26 PM

I would uninstall the Sprint PCS Connection Manager. Then reboot and run it for a while without it installed. If it's doing OK, then download (using a wired connection) a new copy of the Sprint PCS Connection Manager and install it.

After that, I might suggest a look at your audio drivers - but it's nothing certain, just several mentions of them near the time of the crash.

After that I'd go with the repair install of Windows.


I also noted a mention of the Fax service in one part of the last log - this could tie it in to the Sprint PCS Connection Manager also. Just because this program has caused "stable" errors in the past doesn't mean that it will continue to do this.
My browser caused a flood of traffic, sio my IP address was banned. Hope to fix it soon. Will get back to posting as soon as Im able.

- John  (my website: http://www.carrona.org/ )**If you need a more detailed explanation, please ask for it. I have the Knack. **  If I haven't replied in 48 hours, please send me a message. My eye problems have recently increased and I'm having difficult reading posts. (23 Nov 2017)FYI - I am completely blind in the right eye and ~30% blind in the left eye.<p>If the eye problems get worse suddenly, I may not be able to respond.If that's the case and help is needed, please PM a staff member for assistance.

#10 Zllio

Zllio

  • Members
  • 1,107 posts
  • OFFLINE
  •  
  • Local time:09:56 PM

Posted 14 October 2008 - 01:19 PM

It always has to do with the following file comctl32.dll.



See this article also: http://support.microsoft.com/kb/884883
It has information about when you have two comctl32.dll files running that are different. This causes the program to stop running. I don't know if that is your problem though.

#11 usasma

usasma

    Still visually handicapped (avatar is memory developed by my Dad


  • BSOD Kernel Dump Expert
  • 25,090 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Southeastern CT, USA
  • Local time:09:56 PM

Posted 14 October 2008 - 01:31 PM

Nice catch Zllio!

There's one here: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

And another one here: C:\Windows\System32\comctl32.dll

Both are being used in the error message. I'd suggest checking the versions of each one.

Edited by usasma, 14 October 2008 - 01:32 PM.

My browser caused a flood of traffic, sio my IP address was banned. Hope to fix it soon. Will get back to posting as soon as Im able.

- John  (my website: http://www.carrona.org/ )**If you need a more detailed explanation, please ask for it. I have the Knack. **  If I haven't replied in 48 hours, please send me a message. My eye problems have recently increased and I'm having difficult reading posts. (23 Nov 2017)FYI - I am completely blind in the right eye and ~30% blind in the left eye.<p>If the eye problems get worse suddenly, I may not be able to respond.If that's the case and help is needed, please PM a staff member for assistance.

#12 srader

srader
  • Topic Starter

  • Members
  • 35 posts
  • OFFLINE
  •  
  • Local time:08:56 PM

Posted 16 October 2008 - 04:09 PM

It always has to do with the following file comctl32.dll.



See this article also: http://support.microsoft.com/kb/884883
It has information about when you have two comctl32.dll files running that are different. This causes the program to stop running. I don't know if that is your problem though.


I tried this, and it did not work because I am on Service Pack 3.


Nice catch Zllio!

There's one here: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

And another one here: C:\Windows\System32\comctl32.dll

Both are being used in the error message. I'd suggest checking the versions of each one.



But, I did find this...

comctl32.dll Version C:\WINDOWS\system32 - 5.82.2900.5512

comctl32.dll C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83 - 6.0.2900.5512


Additionally I found this also:
comctl32.dll version C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 - 6.0.2900.2982

I figure I should not do anything with the last one since it is not listed in the report.

Any future advisement from here on what to do is greatly appreciated.

#13 usasma

usasma

    Still visually handicapped (avatar is memory developed by my Dad


  • BSOD Kernel Dump Expert
  • 25,090 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Southeastern CT, USA
  • Local time:09:56 PM

Posted 16 October 2008 - 05:55 PM

I would suggest:
- backing up your data
- ensuring you have a tool to change these files back outside of Windows (for example, the Ultimate Boot CD).
- renaming the older comctl32.dll in the System32 directory to comctl.bak
- copy the newest one to that location.
- reboot and hope for the best.

I don't know if SFC will allow the change to the one in the System32 directory (and you may have to check in your dll cache for the version there.

If it doesn't work and you can't get into Windows, you can re-replace them with the older version outside of Windows. That should allow you to boot into Windows.

A safer alternative would be a repair install of Windows XP.
My browser caused a flood of traffic, sio my IP address was banned. Hope to fix it soon. Will get back to posting as soon as Im able.

- John  (my website: http://www.carrona.org/ )**If you need a more detailed explanation, please ask for it. I have the Knack. **  If I haven't replied in 48 hours, please send me a message. My eye problems have recently increased and I'm having difficult reading posts. (23 Nov 2017)FYI - I am completely blind in the right eye and ~30% blind in the left eye.<p>If the eye problems get worse suddenly, I may not be able to respond.If that's the case and help is needed, please PM a staff member for assistance.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users