Hello Mohamdr,
thanks,
there are error messages in Drwatson.log each time after the crash,
but how can I see what's the meaning of it?
Here it is:
Anwendungsausnahme aufgetreten:
Anwendung: (pid=2548)
Wann: 17.01.2004 @ 13:50:30.500
Ausnahmenummer: c0000005 (Zugriffsverletzung)
*----> Systeminformationen <----*
Computername: BRK_FP_S1
Benutzername: SYSTEM
Prozessoranzahl: 1
Prozessortyp: x86 Family 6 Model 8 Stepping 6
Windows 2000-Version: 5.0
Aktuelles Build: 2195
Service Pack: 4
Aktueller Typ: Uniprocessor Free
Firma: Brockhaus Commission
Besitzer: Administrator
*----> Taskliste <----*
0 Idle.exe
8 System.exe
184 SMSS.exe
208 CSRSS.exe
228 WINLOGON.exe
256 SERVICES.exe
268 LSASS.exe
440 svchost.exe
492 svchost.exe
536 spoolsv.exe
612 msdtc.exe
732 amgrsrvc.exe
756 DBENG.exe
768 jobeng.exe
780 rds.exe
792 msgeng.exe
832 casmrtbk.exe
848 asrsrvc.exe
876 tapeeng.exe
904 AWHOST32.exe
928 FlushServ.exe
948 hpesysvc.exe
960 hpevtsvc.exe
984 hpipmsvc.exe
1000 hplersvc.exe
1012 hppfmsvc.exe
1020 hpler.exe
1032 HPRccSvc.exe
1060 hpsdnsvc.exe
1072 hpwebjetd.exe
1128 hpwebsvc.exe
1144 webs.exe
1152 inetinfo.exe
1172 LLSSRV.exe
1196 LogWatNT.exe
1256 Mcshield.exe
1288 VsTskMgr.exe
1424 MEGASERV.exe
1448 regsvc.exe
1460 mstask.exe
1500 SNMP.exe
1528 svchost.exe
1604 win32sl.exe
1664 WinMgmt.exe
1688 svchost.exe
1704 dfssvc.exe
1888 hpcmpsvc.exe
1572 asdscsvc.exe
1944 liccheck.exe
972 snmptrap.exe
2192 LOCATOR.exe
1744 svchost.exe
1896 DLLHOST.exe
2336 explorer.exe
2440 shstat.exe
2452 internat.exe
2460 dcf77mon.exe
2548 asrunjob.exe
2488 DRWTSN32.exe
0 _Total.exe
(00400000 - 00405000)
(77880000 - 77901000)
(23600000 - 2360B000)
(77E70000 - 77F30000)
(77E00000 - 77E5F000)
(77F40000 - 77F79000)
(79350000 - 793B2000)
(77D20000 - 77D8E000)
(21200000 - 21223000)
(687D0000 - 687D9000)
(750E0000 - 7512F000)
(78000000 - 78045000)
(79430000 - 7943F000)
(75130000 - 75136000)
(750C0000 - 750CF000)
(74FA0000 - 74FB4000)
(74F90000 - 74F98000)
(77940000 - 7796B000)
(77970000 - 77994000)
(74FC0000 - 74FC9000)
(25400000 - 25434000)
(25600000 - 2562A000)
(782F0000 - 78301000)
(10000000 - 10013000)
(20A00000 - 20C81000)
(00A00000 - 00A11000)
(00A20000 - 00A6A000)
(28E00000 - 28E7E000)
(22C00000 - 22C2B000)
(00A70000 - 00A8E000)
(00A90000 - 00ABA000)
(77310000 - 77323000)
(774F0000 - 774F5000)
(772F0000 - 77307000)
(77A40000 - 77B2C000)
(779A0000 - 77A3B000)
(77380000 - 773B0000)
(77350000 - 77373000)
(77820000 - 7782E000)
(78310000 - 783A1000)
(791A0000 - 79202000)
(774B0000 - 774E3000)
(77490000 - 774A1000)
(77500000 - 77522000)
(71710000 - 71794000)
(70A70000 - 70AD5000)
(77330000 - 77349000)
(00AC0000 - 00AD5000)
(00AE0000 - 00AE8000)
(29200000 - 2920D000)
(23800000 - 2380F000)
(00AF0000 - 00B49000)
(28A00000 - 28A5A000)
(24200000 - 242C5000)
(20E00000 - 20E17000)
(20800000 - 20809000)
(74F60000 - 74F73000)
(00B50000 - 00B5C000)
(21600000 - 2162B000)
(00B70000 - 00B7C000)
(00B80000 - 00B8B000)
(00B90000 - 00B98000)
(00BA0000 - 00BA5000)
(00BB0000 - 00BB5000)
(00BC0000 - 00BCA000)
(00BD0000 - 00BDC000)
(00BE0000 - 00C03000)
(21800000 - 21811000)
(76920000 - 7693B000)
(67E80000 - 67F71000)
(75380000 - 7538A000)
(73D60000 - 73D71000)
(773B0000 - 773C5000)
(754F0000 - 75514000)
(77410000 - 77488000)
(77400000 - 77410000)
(738A0000 - 738B0000)
(69AE0000 - 69AF0000)
(6C070000 - 6C07A000)
(784A0000 - 78526000)
(71BF0000 - 71C0A000)
(74F40000 - 74F5E000)
(74F80000 - 74F87000)
(77830000 - 7783C000)
(777D0000 - 777D8000)
(763E0000 - 76417000)
(6B490000 - 6B528000)
(02BC0000 - 02DC4000)
(77580000 - 777CE000)
(75990000 - 759A3000)
(1A400000 - 1A47A000)
(77810000 - 77817000)
(75940000 - 75946000)
(75480000 - 75484000)
(741A0000 - 741D0000)
(72F70000 - 730DD000)
(78190000 - 781F4000)
(6DF90000 - 6E047000)
(6A620000 - 6A630000)
(68860000 - 6886D000)
(750D0000 - 750DC000)
(75180000 - 75195000)
(75140000 - 75178000)
(777E0000 - 777E5000)
(75430000 - 75435000)
Statusabbild fr Threadkennung 0x98c
eax=00000000 ebx=77e9a0ad ecx=01010101 edx=00000000 esi=77889153 edi=0012ff00
eip=7788915e esp=0012feec ebp=0012ff08 iopl=0 nv up ei pl nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000206
Funktion: ZwDelayExecution
77889153 b832000000 mov eax,0x32
77889158 8d542404 lea edx,[esp+0x4] ss:00949dd3=????????
7788915c cd2e int 2e
7788915e c20800 ret 0x8
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0012FF08 77E9A0B8 00002710 00000000 004011AF 00002710 ntdll!ZwDelayExecution
77E77E4D 000018A1 30488B00 8308458B 1A74F4F8 74F5F883 kernel32!Sleep
*----> Raw Stack Dump <----*
0012feec ed a0 e9 77 00 00 00 00 - 00 ff 12 00 68 02 00 00 ...w........h...
0012fefc 00 00 00 00 00 1f 0a fa - ff ff ff ff 4d 7e e7 77 ............M~.w
0012ff0c b8 a0 e9 77 10 27 00 00 - 00 00 00 00 af 11 40 00 ...w.'........@.
0012ff1c 10 27 00 00 00 f0 fd 7f - c0 ff 12 00 00 00 00 00 .'..............
0012ff2c 27 00 00 00 14 00 00 00 - 3c ff 12 00 01 00 00 00 '.......<.......
0012ff3c 01 00 04 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0012ff4c 00 00 00 00 92 26 40 00 - 04 00 00 00 80 37 8b 00 .....&@......7..
0012ff5c 68 29 8b 00 00 40 40 00 - 04 40 40 00 a4 ff 12 00 h)...@@..@@.....
0012ff6c 94 ff 12 00 a0 ff 12 00 - 00 00 00 00 98 ff 12 00 ................
0012ff7c 08 40 40 00 0c 40 40 00 - 00 00 00 00 27 00 00 00 .@@..@@.....'...
0012ff8c 00 f0 fd 7f 00 00 00 00 - 80 37 8b 00 00 00 00 00 .........7......
0012ff9c c0 88 e8 81 68 29 8b 00 - 04 00 00 00 84 ff 12 00 ....h)..........
0012ffac 00 00 00 00 e0 ff 12 00 - f0 26 40 00 50 31 40 00 .........&@.P1@.
0012ffbc 00 00 00 00 f0 ff 12 00 - e7 87 e9 77 00 00 00 00 ...........w....
0012ffcc 27 00 00 00 00 f0 fd 7f - 00 00 00 00 c8 ff 12 00 '...............
0012ffdc 00 00 00 00 ff ff ff ff - b4 1b ec 77 00 2b e7 77 ...........w.+.w
0012ffec 00 00 00 00 00 00 00 00 - 00 00 00 00 af 25 40 00 .............%@.
0012fffc 00 00 00 00 c8 00 00 00 - 00 01 00 00 ff ee ff ee ................
0013000c 02 00 00 00 00 00 00 00 - 00 fe 00 00 00 00 10 00 ................
0013001c 00 20 00 00 00 02 00 00 - 00 20 00 00 fe 1e 00 00 . ....... ......
Statusabbild fr Threadkennung 0xa1c
eax=000002f0 ebx=00000004 ecx=00000000 edx=00000000 esi=77893233 edi=00000004
eip=7789323e esp=0128fd24 ebp=0128fd70 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000246
Funktion: NtWaitForMultipleObjects
77893233 b8e9000000 mov eax,0xe9
77893238 8d542404 lea edx,[esp+0x4] ss:01aa9c0b=????????
7789323c cd2e int 2e
7789323e c21400 ret 0x14
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0128FD70 77E99F6C 0128FD48 00000001 00000000 00000000 ntdll!NtWaitForMultipleObjects
0128FFB4 77E7B382 00000005 000B000A 793502A7 0013ACC0 kernel32!WaitForMultipleObjects
0128FFEC 00000000 778221FE 0013ACC0 00000000 000000C8 kernel32!lstrcmpiW
*----> Raw Stack Dump <----*
0128fd24 59 a0 e9 77 04 00 00 00 - 48 fd 28 01 01 00 00 00 Y..w....H.(.....
0128fd34 00 00 00 00 00 00 00 00 - 01 00 00 00 c0 ac 13 00 ................
0128fd44 01 00 00 00 f0 02 00 00 - ec 02 00 00 dc 02 00 00 ................
0128fd54 40 04 00 00 00 00 00 00 - 00 00 00 00 a8 d2 01 82 @...............
0128fd64 04 00 00 00 01 00 00 00 - 80 d2 01 82 b4 ff 28 01 ..............(.
0128fd74 6c 9f e9 77 48 fd 28 01 - 01 00 00 00 00 00 00 00 l..wH.(.........
0128fd84 00 00 00 00 00 00 00 00 - b2 22 82 77 04 00 00 00 .........".w....
0128fd94 b0 fe 28 01 00 00 00 00 - ff ff ff ff c0 ac 13 00 ..(.............
0128fda4 a7 02 35 79 0a 00 0b 00 - 14 04 45 80 18 16 e6 e1 ..5y......E.....
0128fdb4 01 00 00 00 00 00 00 00 - 01 00 00 00 38 00 00 00 ............8...
0128fdc4 23 00 00 00 23 00 00 00 - 0a 00 0b 00 a7 02 35 79 #...#.........5y
0128fdd4 c0 ac 13 00 68 02 35 79 - 4c 00 00 00 fe 21 82 77 ....h.5yL....!.w
0128fde4 f8 eb fd 7f 00 b7 e7 77 - 1b 00 00 00 00 02 00 00 .......w........
0128fdf4 fc ff 28 01 23 00 00 00 - 0c eb 80 f7 05 00 00 00 ..(.#...........
0128fe04 67 f5 40 80 98 00 00 00 - f8 00 00 00 98 00 00 00 g.@.............
0128fe14 00 eb 80 f7 05 00 00 00 - 24 00 01 e1 05 00 00 00 ........$.......
0128fe24 fe ff f8 00 98 c8 14 ff - 34 00 00 c0 88 33 61 e3 ........4....3a.
0128fe34 02 00 00 00 49 03 00 00 - 88 33 61 e3 5c eb 80 f7 ....I....3a.\...
0128fe44 90 12 02 82 b4 eb 80 f7 - 3d 16 45 80 08 20 01 e1 ........=.E.. ..
0128fe54 40 c7 01 82 00 e4 46 80 - 28 12 02 82 b0 ec 80 f7 @.....F.(.......
Statusabbild fr Threadkennung 0x5fc
eax=6800016c ebx=00000001 ecx=00000000 edx=008ddb60 esi=008d6e38 edi=00000000
eip=20e0cef9 esp=0200d93c ebp=02df0000 iopl=0 nv up ei pl nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000206
Funktion: <nosymbols>
20e0cedc 895a1c mov [edx+0x1c],ebx ds:010f7a46=????????
20e0cedf eb0f jmp 20e159f0
20e0cee1 8b06 mov eax,[esi] ds:008d6e38=0202a2a8
20e0cee3 895018 mov [eax+0x18],edx ds:6881a052=????????
20e0cee6 e969020000 jmp 20e0d154
20e0ceeb 8b0e mov ecx,[esi] ds:008d6e38=0202a2a8
20e0ceed 89591c mov [ecx+0x1c],ebx ds:00819ee6=????????
20e0cef0 8b560c mov edx,[esi+0xc] ds:010f0d1e=????????
20e0cef3 8b4270 mov eax,[edx+0x70] ds:010f7a46=????????
20e0cef6 8b4030 mov eax,[eax+0x30] ds:6881a052=????????
FEHLER ->20e0cef9 668b5004 mov dx,[eax+0x4] ds:6881a053=????
20e0cefd 668b6802 mov bp,[eax+0x2] ds:6881a053=????
20e0cf01 663bd3 cmp dx,bx
20e0cf04 0f8246020000 jb 20e0d150
20e0cf0a 663beb cmp bp,bx
20e0cf0d 7304 jnb 20e15a13
20e0cf0f 8b6c2428 mov ebp,[esp+0x28] ss:02827823=????????
20e0cf13 8bca mov ecx,edx
20e0cf15 33db xor ebx,ebx
20e0cf17 81e1ffff0000 and ecx,0xffff
20e0cf1d 8bc1 mov eax,ecx
20e0cf1f a30031e120 mov [20e13100],eax ds:20e13100=0000000b
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
02DF0000 00000000 00000000 00000000 00000000 00000000 !<nosymbols>
*----> Raw Stack Dump <----*
0200d93c 50 02 00 64 38 6e 8d 00 - 00 00 00 00 03 00 00 00 P..d8n..........
0200d94c 00 00 df 02 00 00 00 00 - 00 00 00 00 a0 c7 e0 20 ...............
0200d95c 00 00 00 00 50 02 00 64 - 01 00 00 02 01 00 00 00 ....P..d........
0200d96c 00 00 00 00 00 00 00 00 - b8 84 8d 00 e0 6e 8d 00 .............n..
0200d97c 38 6e 8d 00 66 00 79 00 - 48 00 02 02 4d 00 69 00 8n..f.y.H...M.i.
0200d98c 74 00 74 00 77 00 6f 00 - 63 00 68 00 73 00 20 00 t.t.w.o.c.h.s. .
0200d99c 42 00 61 00 6e 00 64 00 - 00 00 73 00 29 00 00 00 B.a.n.d...s.)...
0200d9ac 01 00 00 00 00 00 00 00 - 45 82 e7 77 1d 59 c1 22 ........E..w.Y."
0200d9bc 41 e7 a2 20 50 4f 8e 00 - 01 00 00 02 01 00 00 00 A.. PO..........
0200d9cc 01 00 00 00 f8 d9 00 02 - 01 00 00 00 00 00 00 00 ................
0200d9dc 00 00 00 02 00 00 00 00 - 9c f0 00 02 38 6e 8d 00 ............8n..
0200d9ec 45 82 e7 77 93 67 e9 77 - 0e 00 00 00 00 00 00 00 E..w.g.w........
0200d9fc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0200da0c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0200da1c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0200da2c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0200da3c 00 00 00 00 00 00 00 00 - 00 00 10 00 0c 00 0e 00 ................
0200da4c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0200da5c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0200da6c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
Statusabbild fr Threadkennung 0x4c8
eax=00482df8 ebx=00000002 ecx=00000000 edx=00000000 esi=77893233 edi=00000002
eip=7789323e esp=0269fe94 ebp=0269fee0 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000246
Funktion: NtWaitForMultipleObjects
77893233 b8e9000000 mov eax,0xe9
77893238 8d542404 lea edx,[esp+0x4] ss:02eb9d7b=????????
7789323c cd2e int 2e
7789323e c21400 ret 0x14
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0269FEE0 77E0E9FB 0269FEB8 00000001 00000000 00000000 ntdll!NtWaitForMultipleObjects
0269FF3C 77E0EA48 0269FF08 001501C4 FFFFFFFF 000000FF user32!MsgWaitForMultipleObjectsEx
0269FF58 71BF7A07 00000001 001501C4 00000000 FFFFFFFF user32!MsgWaitForMultipleObjects
0269FFB4 77E7B382 00000001 0024005C 00750051 001501B8 dskquota!DllUnregisterServer
0269FFEC 00000000 71BF7950 001501B8 00000000 26003210 kernel32!lstrcmpiW
*----> Raw Stack Dump <----*
0269fe94 59 a0 e9 77 02 00 00 00 - b8 fe 69 02 01 00 00 00 Y..w......i.....
0269fea4 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0269feb4 02 00 00 00 14 01 00 00 - 08 01 00 00 f8 fe 69 02 ..............i.
0269fec4 01 00 00 00 17 00 00 00 - 8d ac a9 77 01 00 00 00 ...........w....
0269fed4 00 00 00 00 40 26 15 00 - b0 26 15 00 3c ff 69 02 ....@&...&..<.i.
0269fee4 fb e9 e0 77 b8 fe 69 02 - 01 00 00 00 00 00 00 00 ...w..i.........
0269fef4 00 00 00 00 00 00 00 00 - b8 01 15 00 00 00 00 00 ................
0269ff04 00 00 00 00 14 01 00 00 - 08 01 00 00 00 00 00 00 ................
0269ff14 00 00 00 00 00 00 00 00 - 01 00 00 00 00 00 00 00 ................
0269ff24 00 90 fd 7f 00 00 00 00 - 00 00 00 00 cc 96 fd 7f ................
0269ff34 00 00 00 00 08 01 00 00 - 58 ff 69 02 48 ea e0 77 ........X.i.H..w
0269ff44 08 ff 69 02 c4 01 15 00 - ff ff ff ff ff 00 00 00 ..i.............
0269ff54 00 00 00 00 b4 ff 69 02 - 07 7a bf 71 01 00 00 00 ......i..z.q....
0269ff64 c4 01 15 00 00 00 00 00 - ff ff ff ff ff 00 00 00 ................
0269ff74 5c 00 24 00 51 00 75 00 - b8 01 15 00 00 00 00 00 \.$.Q.u.........
0269ff84 00 00 00 00 d6 11 43 80 - 00 00 00 00 00 00 00 00 ......C.........
0269ff94 0f 12 43 80 60 4d fb fd - 60 87 0a 81 b8 01 15 00 ..C.`M..`.......
0269ffa4 74 ff 69 02 dc ff 69 02 - c8 db bf 71 00 00 00 00 t.i...i....q....
0269ffb4 ec ff 69 02 82 b3 e7 77 - 01 00 00 00 5c 00 24 00 ..i....w....\.$.
0269ffc4 51 00 75 00 b8 01 15 00 - 00 90 fd 7f 24 00 51 00 Q.u.........$.Q.
Statusabbild fr Threadkennung 0x7fc
eax=71bf7950 ebx=00000002 ecx=00510024 edx=00000000 esi=77893233 edi=00000002
eip=7789323e esp=027bfe94 ebp=027bfee0 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000246
Funktion: NtWaitForMultipleObjects
77893233 b8e9000000 mov eax,0xe9
77893238 8d542404 lea edx,[esp+0x4] ss:02fd9d7b=????????
7789323c cd2e int 2e
7789323e c21400 ret 0x14
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
027BFEE0 77E0E9FB 027BFEB8 00000001 00000000 00000000 ntdll!NtWaitForMultipleObjects
027BFF3C 77E0EA48 027BFF08 0015047C FFFFFFFF 000000FF user32!MsgWaitForMultipleObjectsEx
027BFF58 71BF7A07 00000001 0015047C 00000000 FFFFFFFF user32!MsgWaitForMultipleObjects
027BFFB4 77E7B382 00000001 0024005C 00750051 00150470 dskquota!DllUnregisterServer
027BFFEC 00000000 00000000 00000000 00000000 00000000 kernel32!lstrcmpiW
Statusabbild fr Threadkennung 0x968
eax=71bf7950 ebx=00000002 ecx=00510024 edx=00000000 esi=77893233 edi=00000002
eip=7789323e esp=028bfe94 ebp=028bfee0 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000246
Funktion: NtWaitForMultipleObjects
77893233 b8e9000000 mov eax,0xe9
77893238 8d542404 lea edx,[esp+0x4] ss:030d9d7b=????????
7789323c cd2e int 2e
7789323e c21400 ret 0x14
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
028BFEE0 77E0E9FB 028BFEB8 00000001 00000000 00000000 ntdll!NtWaitForMultipleObjects
028BFF3C 77E0EA48 028BFF08 0015C6DC FFFFFFFF 000000FF user32!MsgWaitForMultipleObjectsEx
028BFF58 71BF7A07 00000001 0015C6DC 00000000 FFFFFFFF user32!MsgWaitForMultipleObjects
028BFFB4 77E7B382 00000001 0024005C 00750051 0015C6D0 dskquota!DllUnregisterServer
028BFFEC 00000000 00000000 00000000 00000000 00000000 kernel32!lstrcmpiW
Statusabbild fr Threadkennung 0xa4
eax=77d31c54 ebx=fdcf0240 ecx=001304e0 edx=00000000 esi=001504c8 edi=00150508
eip=778839c7 esp=02abfe28 ebp=02abff74 iopl=0 nv up ei pl nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000206
Funktion: NtReplyWaitReceivePortEx
778839bc b8ac000000 mov eax,0xac
778839c1 8d542404 lea edx,[esp+0x4] ss:032d9d0f=????????
778839c5 cd2e int 2e
778839c7 c21400 ret 0x14
778839ca 8b4710 mov eax,[edi+0x10] ds:0096a3ee=????????
778839cd 8b483c mov ecx,[eax+0x3c] ds:7854bb3a=????????
778839d0 f6400801 test byte ptr [eax+0x8],0x1 ds:7854bb3a=??
778839d4 7502 jnz RtlCreateProcessParameters+0xd (77883cd8)
778839d6 03c8 add ecx,eax
778839d8 894de4 mov [ebp+0xe4],ecx ss:032d9e5a=????????
778839db 8b4710 mov eax,[edi+0x10] ds:0096a3ee=????????
778839de 668b4038 mov ax,[eax+0x38] ds:7854bb3b=????
778839e2 668945e0 mov [ebp+0xe0],ax ss:032d9e5b=????
778839e6 668945e2 mov [ebp+0xe2],ax ss:032d9e5b=????
778839ea 53 push ebx
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
02ABFF74 77D46D9E 77D29A00 001504C8 00000000 00000000 ntdll!NtReplyWaitReceivePortEx
02ABFFA8 77D31C6C 001C7FB0 02ABFFEC 77E7B382 001652F0 rpcrt4!TowerConstruct
02ABFFB4 77E7B382 001652F0 00000000 00000000 001652F0 rpcrt4!I_RpcServerInqTransportType
02ABFFEC 00000000 77D31C54 001652F0 00000000 00000008 kernel32!lstrcmpiW
*----> Raw Stack Dump <----*
02abfe28 d4 74 d4 77 30 01 00 00 - 54 ff ab 02 00 00 00 00 .t.w0...T.......
02abfe38 a0 c0 16 00 00 00 00 00 - 40 06 14 00 b0 7f 1c 00 ........@.......
02abfe48 f0 52 16 00 01 c2 fa 7f - d9 11 00 00 f1 da 44 80 .R............D.
02abfe58 d9 11 00 00 d0 c7 cb 81 - 00 c0 fa 7f fc 07 30 c0 ..............0.
02abfe68 00 00 00 00 90 2b 94 f7 - d9 11 00 00 58 2c 94 f7 .....+......X,..
02abfe78 00 00 00 00 01 00 00 00 - 00 00 00 00 00 d0 fa 7f ................
02abfe88 fc 07 30 c0 38 2c 94 f7 - 78 d9 44 80 00 c0 fa 7f ..0.8,..x.D.....
02abfe98 00 00 00 00 00 00 00 00 - 00 c0 fa 7f a8 9a 27 81 ..............'.
02abfea8 01 c8 cb 81 00 00 00 00 - b0 fe 1f c0 f1 da 44 80 ..............D.
02abfeb8 b5 10 00 00 d0 c7 cb 81 - 00 f0 4c 02 24 00 30 c0 ..........L.$.0.
02abfec8 00 00 00 00 00 00 00 00 - b5 10 00 00 01 00 00 00 ................
02abfed8 00 00 00 00 01 00 00 00 - 00 00 00 00 00 00 4d 02 ..............M.
02abfee8 24 00 30 c0 00 c0 fa 7f - 78 d9 44 80 00 f0 4c 02 $.0.....x.D...L.
02abfef8 00 00 00 00 80 a9 c1 fd - 01 00 00 00 70 80 e1 81 ............p...
02abff08 00 96 e1 81 82 5b 45 80 - c0 ea 10 e2 00 00 00 82 .....[E.........
02abff18 00 00 00 82 00 00 00 02 - 64 2c 94 f7 64 32 49 80 ........d,..d2I.
02abff28 88 19 02 82 60 4d fb fd - 40 02 cf fd 00 00 00 00 ....`M..@.......
02abff38 40 02 cf fd d0 03 cf fd - 64 2c 94 f7 41 df 42 80 @.......d,..A.B.
02abff48 f2 de 42 80 d4 4b 06 80 - a0 03 cf fd 40 02 cf fd ..B..K......@...
02abff58 00 a2 2f 4d ff ff ff ff - 50 fe ab 02 ff ff ff ff ../M....P.......
For me this isn't an information.
Does anybody know more?
Thanks and regards,
Peter