Fehlerprotokoll...(siehe counterstike-thread)
dieses mal ist es der internet
explorer:Anwendungsausnahme aufgetreten:
* * * *Anwendung: *(pid=1160)
* * * *Wann: 04.08.2002 @ 15:39:34.437
* * * *Ausnahmenummer: c0000005 (Zugriffsverletzung)
*----> Systeminformationen <----*
* * * *Computername: ---------)_Das ist unwichtig
* * * *Benutzername: ----------)
* * * *Prozessoranzahl: 1
* * * *Prozessortyp: x86 Family 6 Model 6 Stepping 2
* * * *Windows 2000-Version: 5.0
* * * *Aktuelles Build: 2195
* * * *Service Pack: 1
* * * *Aktueller Typ: Uniprocessor Free
* * * *Firma:
* * * *Besitzer: ---
*----> Taskliste <----*
* 0 Idle.exe
* 8 System.exe
176 smss.exe
200 csrss.exe
220 winlogon.exe
248 services.exe
260 lsass.exe
424 svchost.exe
464 SPOOLSV.exe
508 svchost.exe
536 nvsvc32.exe
560 regsvc.exe
592 mstask.exe
616 winmgmt.exe
896 explorer.exe
796 Directcd.exe
968 dw.exe
976 internat.exe
996 FriWeb32.exe
320 getright.exe
768 msiexec.exe
1160 Kazaa.exe
1124 mspaint.exe
672 drwtsn32.exe
* 0 _Total.exe
(00400000 - 0074F000)
(77F80000 - 78000000)
(77E70000 - 77F33000)
(77E00000 - 77E64000)
(77F40000 - 77F7C000)
(77C60000 - 77CAA000)
(77DA0000 - 77DFA000)
(77D30000 - 77DA0000)
(76B00000 - 76B3F000)
(77B40000 - 77BC9000)
(77580000 - 777C8000)
(78000000 - 78046000)
(777F0000 - 7780D000)
(75260000 - 75280000)
(77A40000 - 77B35000)
(69470000 - 69499000)
(779A0000 - 77A35000)
(76BD0000 - 76C45000)
(77540000 - 77571000)
(74FC0000 - 74FC9000)
(74FA0000 - 74FB4000)
(74F90000 - 74F98000)
(77810000 - 77817000)
(75940000 - 75946000)
(6E330000 - 6E336000)
(75DF0000 - 75E0A000)
(10000000 - 10093000)
(6E1E0000 - 6E1EB000)
(75440000 - 75448000)
(77310000 - 77323000)
(774F0000 - 774F5000)
(772F0000 - 77307000)
(750C0000 - 750CF000)
(750E0000 - 7512F000)
(77BD0000 - 77BDF000)
(75130000 - 75136000)
(77940000 - 7796A000)
(77970000 - 77994000)
(77380000 - 773AF000)
(77350000 - 77372000)
(77820000 - 7782E000)
(78310000 - 783A0000)
(77C00000 - 77C5E000)
(774B0000 - 774E2000)
(77490000 - 774A1000)
(77500000 - 77522000)
(77330000 - 77349000)
(78280000 - 78305000)
(76C50000 - 76D60000)
(770C0000 - 7727E000)
(76D60000 - 76DB7000)
(02110000 - 0212D000)
(773B0000 - 773C2000)
(783B0000 - 78422000)
(02230000 - 0226E000)
(77840000 - 7787D000)
(77090000 - 770B3000)
(75CE0000 - 75D62000)
(74F40000 - 74F5D000)
(74F80000 - 74F87000)
(75A40000 - 75A45000)
(75A80000 - 75CC0000)
(75D70000 - 75DE7000)
(77830000 - 7783C000)
(75A50000 - 75A78000)
(777D0000 - 777D8000)
(777E0000 - 777E5000)
(6B270000 - 6B2AC000)
(77530000 - 77539000)
(64920000 - 649F1000)
(35500000 - 35622000)
(751A0000 - 751B5000)
(35680000 - 3568F000)
(51080000 - 510D4000)
(773D0000 - 773D8000)
(773E0000 - 773F3000)
(1C400000 - 1C418000)
Statusabbild für Threadkennung 0x660
eax=00000000 ebx=77e734fd ecx=00000000 edx=00012b36 esi=02d26230 edi=012b3615
eip=75ad52c0 esp=0012f334 ebp=012b36dd iopl=0 * * * * nv up ei pl zr na po nc
cs=001b *ss=0023 *ds=0023 *es=0023 *fs=003b *gs=0000 * * * * * * efl=00000246
Funktion: <nosymbols>
* * * *75ad5294 8b8698000000 * * mov * * eax,[esi+0x98] * * * * ds:02d262c8=00000001
* * * *75ad529a 85c0 * * * * * * test * *eax,eax
* * * *75ad529c 8dafc8000000 * * lea * * ebp,[edi+0xc8] * * * * ds:012b36dd=????????
* * * *75ad52a2 744d * * * * * * jz * * *DllGetClassObject+0x316bb (75adddf1)
* * * *75ad52a4 8b8694000000 * * mov * * eax,[esi+0x94] * * * * ds:02d262c4=00000000
* * * *75ad52aa 85c0 * * * * * * test * *eax,eax
* * * *75ad52ac 750c * * * * * * jnz * * DllGetClassObject+0x31684 (75adddba)
* * * *75ad52ae 8b8e90000000 * * mov * * ecx,[esi+0x90] * * * * ds:02d262c0=00000000
* * * *75ad52b4 898e94000000 * * mov * * [esi+0x94],ecx * * * * ds:02d262c4=00000000
* * * *75ad52ba 8b8694000000 * * mov * * eax,[esi+0x94] * * * * ds:02d262c4=00000000
FEHLER ->75ad52c0 8b5034 * * * * * mov * * edx,[eax+0x34] * * * * ds:00a8d5d6=????????
* * * *75ad52c3 899694000000 * * mov * * [esi+0x94],edx * * * * ds:02d262c4=00000000
* * * *75ad52c9 8b4810 * * * * * mov * * ecx,[eax+0x10] * * * * ds:00a8d5d6=????????
* * * *75ad52cc f7c180010000 * * test * *ecx,0x180
* * * *75ad52d2 75d0 * * * * * * jnz * * DllGetClassObject+0x2dc6e (75ada3a4)
* * * *75ad52d4 50 * * * * * * * push * *eax
* * * *75ad52d5 55 * * * * * * * push * *ebp
* * * *75ad52d6 56 * * * * * * * push * *esi
* * * *75ad52d7 e8dd98ffff * * * call * *DllGetClassObject+0x22483 (75acebb9)
* * * *75ad52dc ffd3 * * * * * * call * *ebx
* * * *75ad52de 2bc7 * * * * * * sub * * eax,edi
* * * *75ad52e0 3dc8000000 * * * cmp * * eax,0xc8
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 *Param#2 *Param#3 *Param#4 *Function Name
012B36DD 00000000 00000000 00000000 00000000 00000000 mshtml!DllGetClassObject
*----> Raw Stack Dump <----*
0012f334 *a4 2d 53 01 30 4c 13 00 - 60 f3 12 00 00 00 00 00 *.-S.0L..`.......
0012f344 *dc 48 e0 77 48 02 05 00 - 13 01 00 00 03 10 00 00 *.H.wH...........
0012f354 *15 36 2b 01 30 4c 13 00 - cd ab ba dc 7c f3 12 00 *.6+.0L......|...
0012f364 *fb 63 e0 77 78 52 ad 75 - 48 02 05 00 13 01 00 00 *.c.wxR.uH.......
0012f374 *03 10 00 00 15 36 2b 01 - a4 f3 12 00 3d 64 e0 77 *.....6+.....=d.w
0012f384 *e0 bc 7f 00 13 01 00 00 - 03 10 00 00 15 36 2b 01 *.............6+.
0012f394 *78 52 ad 75 30 00 00 00 - 00 00 00 00 00 00 00 00 *xR.u0...........
0012f3a4 *e8 f3 12 00 4b f0 f9 77 - b4 f3 12 00 18 00 00 00 *....K..w........
0012f3b4 *e0 bc 7f 00 13 01 00 00 - 03 10 00 00 15 36 2b 01 *.............6+.
0012f3c4 *78 52 ad 75 cc 63 e0 77 - ff 8c e4 77 dd 02 c2 02 *xR.u.c.w...w....
0012f3d4 *02 00 00 00 fd 01 00 00 - 1a 01 00 00 f0 01 0c 00 *................
0012f3e4 *00 00 00 00 1c f4 12 00 - 7e 52 4f 00 dd 02 c2 02 *........~RO.....
0012f3f4 *02 00 00 00 fd 01 00 00 - 1a 01 00 00 00 00 00 00 *................
0012f404 *f0 01 0c 00 00 00 00 00 - 5c 5a e0 77 a4 2d 53 01 *........\Z.w.-S.
0012f414 *01 c2 e0 77 00 00 00 00 - 4a 84 e0 77 b2 bc 40 00 *...w....J..w..@.
0012f424 *02 00 00 00 fd 01 00 00 - 1a 01 00 00 f8 34 56 01 *.............4V.
0012f434 *00 00 00 00 50 08 56 01 - 1a 01 00 00 04 f5 12 00 *....P.V.........
0012f444 *30 b7 40 00 20 11 53 01 - 38 8e c6 02 88 8e c6 02 *0.@. .S.8.......
0012f454 *78 05 c6 02 50 08 56 01 - 23 00 00 00 68 9c 1b 00 *x...P.V.#...h...
0012f464 *60 b5 52 00 db 03 8b 04 - 0e 79 4f 00 d0 02 1c 00 *`.R......yO.....
Statusabbild für Threadkennung 0x438
eax=778221fe ebx=00000004 ecx=77da0260 edx=00000000 esi=77f820e5 edi=00000004
eip=77f820f0 esp=0193fd24 ebp=0193fd70 iopl=0 * * * * nv up ei pl zr na po nc
cs=001b *ss=0023 *ds=0023 *es=0023 *fs=0038 *gs=0000 * * * * * * efl=00000246
Funktion: NtWaitForMultipleObjects
* * * *77f820e5 b8e9000000 * * * mov * * eax,0xe9
* * * *77f820ea 8d542404 * * * * lea * * edx,[esp+0x4] * * * * *ss:023cd2fb=????????
* * * *77f820ee cd2e * * * * * * int * * 2e
* * * *77f820f0 c21400 * * * * * ret * * 0x14
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 *Param#2 *Param#3 *Param#4 *Function Name
0193FD70 77E760C6 0193FD48 00000001 00000000 00000000 ntdll!NtWaitForMultipleObjects
0193FFB4 77E737CD 00000005 00000000 000B000A 0016B820 kernel32!WaitForMultipleObjects
0193FFEC 00000000 778221FE 0016B820 00000000 000000C8 kernel32!TlsSetValue
*----> Raw Stack Dump <----*
0193fd24 *6e 36 e7 77 04 00 00 00 - 48 fd 93 01 01 00 00 00 *n6.w....H.......
0193fd34 *00 00 00 00 00 00 00 00 - 01 00 00 00 20 b8 16 00 *............ ...
0193fd44 *01 00 00 00 40 01 00 00 - 44 01 00 00 54 01 00 00 *....@...D...T...
0193fd54 *ac 03 00 00 8c 22 63 e1 - 04 00 00 00 00 00 00 00 *....."c.........
0193fd64 *00 00 00 00 e8 53 8a 81 - 04 00 00 00 b4 ff 93 01 *.....S..........
0193fd74 *c6 60 e7 77 48 fd 93 01 - 01 00 00 00 00 00 00 00 *.`.wH...........
0193fd84 *00 00 00 00 00 00 00 00 - b2 22 82 77 04 00 00 00 *.........".w....
0193fd94 *b0 fe 93 01 00 00 00 00 - ff ff ff ff 20 b8 16 00 *............ ...
0193fda4 *0a 00 0b 00 00 00 00 00 - 7e fa 44 80 d1 a1 49 80 *........~.D...I.
0193fdb4 *78 df 44 80 00 00 00 00 - 01 00 00 00 38 00 00 00 *x.D.........8...
0193fdc4 *23 00 00 00 23 00 00 00 - 00 00 00 00 0a 00 0b 00 *#...#...........
0193fdd4 *20 b8 16 00 b8 71 f8 77 - 60 02 da 77 fe 21 82 77 * ....q.w`..w.!.w
0193fde4 *00 00 00 00 75 37 e7 77 - 1b 00 00 00 00 02 00 00 *....u7.w........
0193fdf4 *fc ff 93 01 23 00 00 00 - 0c cb 0c b8 04 00 00 00 *....#...........
0193fe04 *e2 f2 40 80 05 00 00 00 - f8 00 00 00 98 00 00 00 *..@.............
0193fe14 *74 cb 0c b8 a1 e8 44 80 - 00 ad 3a 81 05 00 00 00 *t.....D...:.....
0193fe24 *24 00 01 e1 05 00 00 00 - fe ff f8 00 38 ae 3a 81 *$...........8.:.
0193fe34 *34 00 00 c0 68 f8 3e e2 - 02 00 00 00 49 03 00 00 *4...h.>.....I...
0193fe44 *68 f8 3e e2 64 cb 0c b8 - 50 87 8a 81 b4 cb 0c b8 *h.>.d...P.......
0193fe54 *f2 f0 44 80 e8 84 00 e1 - 00 52 8a 81 87 fa 49 80 *..D......R....I.
Statusabbild für Threadkennung 0x37c
eax=00000000 ebx=00000000 ecx=00000113 edx=00000000 esi=77f820b1 edi=01a8fdb0
eip=77f820bc esp=01a8fd9c ebp=01a8fdb8 iopl=0 * * * * nv up ei pl nz na pe nc
cs=001b *ss=0023 *ds=0023 *es=0023 *fs=0038 *gs=0000 * * * * * * efl=00000202
Funktion: NtDelayExecution
* * * *77f820b1 b832000000 * * * mov * * eax,0x32
* * * *77f820b6 8d542404 * * * * lea * * edx,[esp+0x4] * * * * *ss:0251d373=????????
* * * *77f820ba cd2e * * * * * * int * * 2e
* * * *77f820bc c20800 * * * * * ret * * 0x8
* * * *77f820bf 53 * * * * * * * push * *ebx
* * * *77f820c0 51 * * * * * * * push * *ecx
* * * *77f820c1 6a00 * * * * * * push * *0x0
* * * *77f820c3 c70701000000 * * mov * * dword ptr [edi],0x1 * *ds:01a8fdb0=fff85ee0
* * * *77f820c9 ff750c * * * * * push * *dword ptr [ebp+0xc] * *ss:0251d38e=????????
* * * *77f820cc 50 * * * * * * * push * *eax
* * * *77f820cd e88af8ffff * * * call * *RtlMultiByteToUnicodeN (77f8195c)
* * * *77f820d2 e97ffeffff * * * jmp *RtlConsoleMultiByteToUnicodeN+0x333 (77f81f56)
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 *Param#2 *Param#3 *Param#4 *Function Name
01A8FDB8 77E734FA 00000032 00000000 10014A41 00000032 ntdll!NtDelayExecution
01A8FE2C 10014F67 00140084 00000113 00000001 00000000 kernel32!Sleep
01A8FE60 77E048DC 00140084 00000113 00000001 00000000 !<nosymbols>
01A8FE80 77E04AA7 10014F27 00140084 00000113 00000001 user32!PtInRect
01A8FF0C 77E166FD 01A8FF60 00000001 10014883 01A8FF60 user32!TranslateMessageEx
01A8FF80 1002E109 018138A0 7FFDEBF8 00000000 01814798 user32!DispatchMessageA
01A8FFB4 77E737CD 01814798 7FFDEBF8 00000000 01814798 !<nosymbols>
01A8FFEC 00000000 00000000 00000000 00000000 00000000 kernel32!TlsSetValue
Statusabbild für Threadkennung 0x28c
eax=1002e0b2 ebx=00000000 ecx=00000000 edx=00000000 esi=77f82147 edi=0000020c
eip=77f82152 esp=01c8ff18 ebp=01c8ff3c iopl=0 * * * * nv up ei pl zr na po nc
cs=001b *ss=0023 *ds=0023 *es=0023 *fs=0038 *gs=0000 * * * * * * efl=00000246
Funktion: NtWaitForSingleObject
* * * *77f82147 b8ea000000 * * * mov * * eax,0xea
* * * *77f8214c 8d542404 * * * * lea * * edx,[esp+0x4] * * * * *ss:0271d4ef=????????
* * * *77f82150 cd2e * * * * * * int * * 2e
* * * *77f82152 c20c00 * * * * * ret * * 0xc
* * * *77f82155 8d0c1b * * * * * lea * * ecx,[ebx+ebx] * * * * *ds:00000000=????????
* * * *77f82158 8908 * * * * * * mov * * [eax],ecx * * * * * * *ds:1002e0b2=6aec8b55
* * * *77f8215a e92bf8ffff * * * jmp * * RtlMultiByteToUnicodeN+0x2e (77f8198a)
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 *Param#2 *Param#3 *Param#4 *Function Name
01C8FF3C 77E73126 0000020C FFFFFFFF 00000000 10005B79 ntdll!NtWaitForSingleObject
01C8FF80 1002E109 00000000 00000018 00000044 018157A0 kernel32!WaitForSingleObject
01C8FFB4 77E737CD 018157A0 00000018 00000044 018157A0 !<nosymbols>
01C8FFEC 00000000 00000000 00000000 00000000 00000000 kernel32!TlsSetValue
Statusabbild für Threadkennung 0x6a4
eax=0000006d ebx=00000024 ecx=007fac78 edx=00000000 esi=01d8ff60 edi=00000000
eip=77e048fc esp=01d8feec ebp=01d8ff0c iopl=0 * * * * nv up ei pl zr na po nc
cs=001b *ss=0023 *ds=0023 *es=0023 *fs=0038 *gs=0000 * * * * * * efl=00000246
Funktion: PtInRect
* * * *77e048d6 ff750c * * * * * push * *dword ptr [ebp+0xc] * *ss:0281d4e2=????????
* * * *77e048d9 ff5508 * * * * * call * *dword ptr [ebp+0x8] * *ss:0281d4e2=????????
* * * *77e048dc 817c2404cdabbadc * * * * * * * * * * * * * * * *ss:0281d4c3=????????
* * * * * * * * * * * * * * * * *cmp * * dword ptr [esp+0x4],0xdcbaabcd
* * * *77e048e4 0f85c8690300 * * jne * * SetClassLongW+0x556 (77e3b2b2)
* * * *77e048ea 83c408 * * * * * add * * esp,0x8
* * * *77e048ed 5d * * * * * * * pop * * ebp
* * * *77e048ee c21400 * * * * * ret * * 0x14
* * * *77e048f1 b89a110000 * * * mov * * eax,0x119a
* * * *77e048f6 8d542404 * * * * lea * * edx,[esp+0x4] * * * * *ss:0281d4c3=????????
* * * *77e048fa cd2e * * * * * * int * * 2e
* * * *77e048fc c21000 * * * * * ret * * 0x10
* * * *77e048ff b8cb110000 * * * mov * * eax,0x11cb
* * * *77e04904 8d542404 * * * * lea * * edx,[esp+0x4] * * * * *ss:0281d4c3=????????
* * * *77e04908 cd2e * * * * * * int * * 2e
* * * *77e0490a c21000 * * * * * ret * * 0x10
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 *Param#2 *Param#3 *Param#4 *Function Name
01D8FF0C 1001486B 01D8FF60 00000000 00000000 00000000 user32!PtInRect
01D8FF80 1002E109 01815828 7FFDEBF8 00000000 01816738 !<nosymbols>
01D8FFB4 77E737CD 01816738 7FFDEBF8 00000000 01816738 !<nosymbols>
01D8FFEC 00000000 1002E0B2 01816738 00000000 65696C43 kernel32!TlsSetValue
*----> Raw Stack Dump <----*
01d8feec *3c 67 e1 77 60 ff d8 01 - 00 00 00 00 00 00 00 00 *<g.w`...........
01d8fefc *00 00 00 00 24 00 00 00 - 00 67 e1 77 00 00 00 00 *....$....g.w....
01d8ff0c *80 ff d8 01 6b 48 01 10 - 60 ff d8 01 00 00 00 00 *....kH..`.......
01d8ff1c *00 00 00 00 00 00 00 00 - f8 eb fd 7f 38 67 81 01 *............8g..
01d8ff2c *38 67 81 01 30 00 00 00 - 23 08 00 00 27 4f 01 10 *8g..0...#...'O..
01d8ff3c *00 00 00 00 00 00 00 00 - 00 00 40 00 00 00 00 00 *..........@.....
01d8ff4c *2f 02 d2 00 00 00 00 00 - 00 00 00 00 c9 5d 81 01 */............]..
01d8ff5c *00 00 00 00 e2 00 06 00 - 13 01 00 00 01 00 00 00 *................
01d8ff6c *00 00 00 00 0d 3a 2b 01 - 71 01 00 00 05 01 00 00 *.....:+.q.......
01d8ff7c *00 00 00 50 b4 ff d8 01 - 09 e1 02 10 28 58 81 01 *...P........(X..
01d8ff8c *f8 eb fd 7f 00 00 00 00 - 38 67 81 01 20 73 41 81 *........8g.. sA.
01d8ff9c *8c ff d8 01 ff ff ff ff - dc ff d8 01 cc 40 03 10 *.............@..
01d8ffac *40 c9 03 10 00 00 00 00 - ec ff d8 01 cd 37 e7 77 *@............7.w
01d8ffbc *38 67 81 01 f8 eb fd 7f - 00 00 00 00 38 67 81 01 *8g..........8g..
01d8ffcc *00 90 fd 7f bc 73 12 00 - c0 ff d8 01 bc 73 12 00 *.....s.......s..
01d8ffdc *ff ff ff ff be dc e8 77 - 80 81 e7 77 00 00 00 00 *.......w...w....
01d8ffec *00 00 00 00 00 00 00 00 - b2 e0 02 10 38 67 81 01 *............8g..
01d8fffc *00 00 00 00 43 6c 69 65 - 6e 74 20 55 72 6c 43 61 *....Client UrlCa
01d9000c *63 68 65 20 4d 4d 46 20 - 56 65 72 20 35 2e 32 00 *che MMF Ver 5.2.
01d9001c *00 c0 0a 00 00 50 00 00 - 00 15 00 00 c1 14 00 00 *.....P..........
Statusabbild für Threadkennung 0x47c
eax=fffffcbd ebx=80030000 ecx=80010100 edx=00000000 esi=0017caf0 edi=00000100
eip=77f82230 esp=0200fe28 ebp=0200ff74 iopl=0 * * * * nv up ei pl nz na pe nc
cs=001b *ss=0023 *ds=0023 *es=0023 *fs=0038 *gs=0000 * * * * * * efl=00000202
Funktion: NtReplyWaitReceivePortEx
* * * *77f82225 b8ac000000 * * * mov * * eax,0xac
* * * *77f8222a 8d542404 * * * * lea * * edx,[esp+0x4] * * * * *ss:02a9d3ff=????????
* * * *77f8222e cd2e * * * * * * int * * 2e
* * * *77f82230 c21400 * * * * * ret * * 0x14
* * * *77f82233 55 * * * * * * * push * *ebp
* * * *77f82234 8bec * * * * * * mov * * ebp,esp
* * * *77f82236 56 * * * * * * * push * *esi
* * * *77f82237 57 * * * * * * * push * *edi
* * * *77f82238 53 * * * * * * * push * *ebx
* * * *77f82239 8bf4 * * * * * * mov * * esi,esp
* * * *77f8223b ff7514 * * * * * push * *dword ptr [ebp+0x14] * ss:02a9d54a=????????
* * * *77f8223e ff7510 * * * * * push * *dword ptr [ebp+0x10] * ss:02a9d54a=????????
* * * *77f82241 ff750c * * * * * push * *dword ptr [ebp+0xc] * *ss:02a9d54a=????????
* * * *77f82244 ff5508 * * * * * call * *dword ptr [ebp+0x8] * *ss:02a9d54a=????????
* * * *77f82247 8be6 * * * * * * mov * * esp,esi
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 *Param#2 *Param#3 *Param#4 *Function Name
0200FF74 77D425D2 77D42C07 0017CAF0 00000000 4016E244 ntdll!NtReplyWaitReceivePortEx
0200FFA8 77D42BB9 0017C6E0 0200FFEC 77E737CD 0017CC08 rpcrt4!NdrVaryingArrayFree
0200FFB4 77E737CD 0017CC08 00000000 4016E244 0017CC08 rpcrt4!NdrVaryingArrayFree
0200FFEC 00000000 00000000 00000000 00000000 00000000 kernel32!TlsSetValue
Statusabbild für Threadkennung 0x6d0
eax=0018fd98 ebx=ffffffff ecx=0018fd70 edx=00000000 esi=7fffffff edi=00000102
eip=77f82152 esp=02a0facc ebp=02a0fb04 iopl=0 * * * * nv up ei ng nz ac po cy
cs=001b *ss=0023 *ds=0023 *es=0023 *fs=0038 *gs=0000 * * * * * * efl=00000297
Funktion: NtWaitForSingleObject
* * * *77f82147 b8ea000000 * * * mov * * eax,0xea
* * * *77f8214c 8d542404 * * * * lea * * edx,[esp+0x4] * * * * *ss:0349d0a3=????????
* * * *77f82150 cd2e * * * * * * int * * 2e
* * * *77f82152 c20c00 * * * * * ret * * 0xc
* * * *77f82155 8d0c1b * * * * * lea * * ecx,[ebx+ebx] * * * * *ds:ffffffff=????????
* * * *77f82158 8908 * * * * * * mov * * [eax],ecx * * * * * * *ds:0018fd98=ffffffff
* * * *77f8215a e92bf8ffff * * * jmp * * RtlMultiByteToUnicodeN+0x2e (77f8198a)
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 *Param#2 *Param#3 *Param#4 *Function Name
02A0FB04 74F42908 00000350 00000640 00000000 00000004 ntdll!NtWaitForSingleObject
02A0FBF0 74FA1A5E 00000003 02A0FE84 02A0FC7C 02A0FD80 msafd!WSPGetSockOpt
02A0FC54 76BEDB86 00000003 02A0FE84 02A0FC7C 02A0FD80 ws2_32!select
02A0FFB0 76BED891 77E737CD 0018FD70 00129F0C 00000001 wininet!InternetSetStatusCallbackA
02A0FFEC 00000000 00000000 00000000 00000000 00000000 wininet!InternetSetStatusCallbackA
*----> Raw Stack Dump <----*
02a0facc *25 2b f4 74 50 03 00 00 - 01 00 00 00 f0 fa a0 02 *%+.tP...........
02a0fadc *84 fe a0 02 00 c8 5f 04 - f0 c7 5f 04 bc f5 34 5d *......_..._...4]
02a0faec *bc 3b c2 01 ff ff ff ff - ff ff ff 7f 40 5e 18 00 *.;..........@^..
02a0fafc *00 00 00 00 00 00 00 00 - f0 fb a0 02 08 29 f4 74 *.............).t
02a0fb0c *50 03 00 00 40 06 00 00 - 00 00 00 00 04 00 00 00 *P...@...........
02a0fb1c *80 fd a0 02 28 1e 59 04 - 7c fc a0 02 20 a8 f1 ff *....(.Y.|... ...
02a0fb2c *ff ff ff ff 00 fc 91 4f - ff ff ff ff 54 03 00 00 *.......O....T...
02a0fb3c *50 03 00 00 00 00 00 00 - 00 00 00 00 90 fb a0 02 *P...............
02a0fb4c *17 20 01 00 80 fb a0 02 - 10 00 00 00 00 00 00 00 *. ..............
02a0fb5c *01 00 00 00 20 a8 f1 ff - ff ff ff ff 00 00 00 00 *.... ...........
02a0fb6c *ff ff ff ff 01 00 00 00 - 40 5e 18 00 50 03 00 00 *........@^..P...
02a0fb7c *01 00 00 00 24 fc a0 02 - 01 00 00 00 00 00 00 00 *....$...........
02a0fb8c *20 00 00 00 00 00 00 00 - 01 00 00 00 00 00 00 00 * ...............
02a0fb9c *ff ff ff ff 90 fb a0 02 - 00 00 00 00 00 00 00 00 *................
02a0fbac *40 5e 18 00 fc fb a0 02 - 02 00 00 00 f0 c7 5f 04 *@^............_.
02a0fbbc *5c 00 00 00 05 00 00 00 - 00 00 00 00 00 00 00 00 *\...............
02a0fbcc *54 03 00 00 24 fc a0 02 - 3c c8 5f 04 1c fb a0 02 *T...$...<._.....
02a0fbdc *24 fc a0 02 44 fc a0 02 - 00 e2 f4 74 50 2b f4 74 *$...D......tP+.t
02a0fbec *ff ff ff ff 54 fc a0 02 - 5e 1a fa 74 03 00 00 00 *....T...^..t....
02a0fbfc *84 fe a0 02 7c fc a0 02 - 80 fd a0 02 90 ff a0 02 *....|...........
Statusabbild für Threadkennung 0x440
eax=02d27f94 ebx=00000002 ecx=7ffd5000 edx=00000000 esi=77f820e5 edi=00000002
eip=77f820f0 esp=02b0fe5c ebp=02b0fea8 iopl=0 * * * * nv up ei pl zr na po nc
cs=001b *ss=0023 *ds=0023 *es=0023 *fs=0038 *gs=0000 * * * * * * efl=00000246
Funktion: NtWaitForMultipleObjects
* * * *77f820e5 b8e9000000 * * * mov * * eax,0xe9
* * * *77f820ea 8d542404 * * * * lea * * edx,[esp+0x4] * * * * *ss:0359d433=????????
* * * *77f820ee cd2e * * * * * * int * * 2e
* * * *77f820f0 c21400 * * * * * ret * * 0x14
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 *Param#2 *Param#3 *Param#4 *Function Name
02B0FEA8 77E160F8 02B0FE80 00000001 00000000 02B0FEA0 ntdll!NtWaitForMultipleObjects
02B0FF04 77E161C5 02B0FED0 77CA4150 0000EA60 00000041 user32!MsgWaitForMultipleObjectsEx
02B0FF20 77C61AD9 00000001 77CA4150 00000000 0000EA60 user32!MsgWaitForMultipleObjects
02B0FF74 77C67D65 02B0FFA0 02B0FFA4 02B0FFA8 02B0FF9C shlwapi!Ordinal116
02B0FFAC 77C67CED 76BEA741 77E737CD 00000000 00130178 shlwapi!StrStrIW
02B0FFEC 00000000 00000000 00000000 00000000 00000000 shlwapi!StrStrIW
Statusabbild für Threadkennung 0x480
eax=0022cfd8 ebx=0322ff74 ecx=00000010 edx=00000000 esi=77f82147 edi=00000394
eip=77f82152 esp=0322ff58 ebp=0322ff7c iopl=0 * * * * nv up ei ng nz ac pe cy
cs=001b *ss=0023 *ds=0023 *es=0023 *fs=0038 *gs=0000 * * * * * * efl=00000293
Funktion: NtWaitForSingleObject
* * * *77f82147 b8ea000000 * * * mov * * eax,0xea
* * * *77f8214c 8d542404 * * * * lea * * edx,[esp+0x4] * * * * *ss:03cbd52f=????????
* * * *77f82150 cd2e * * * * * * int * * 2e
* * * *77f82152 c20c00 * * * * * ret * * 0xc
* * * *77f82155 8d0c1b * * * * * lea * * ecx,[ebx+ebx] * * * * *ds:0322ff74=9a5f4400
* * * *77f82158 8908 * * * * * * mov * * [eax],ecx * * * * * * *ds:0022cfd8=00000000
* * * *77f8215a e92bf8ffff * * * jmp * * RtlMultiByteToUnicodeN+0x2e (77f8198a)
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 *Param#2 *Param#3 *Param#4 *Function Name
0322FF7C 77E73126 00000394 000927C0 00000000 75AA6D7F ntdll!NtWaitForSingleObject
77F81B73 4AFFC033 BE850F08 89000005 FF900C42 8D0F044A kernel32!WaitForSingleObject
0424548B 00000000 00000000 00000000 00000000 00000000 <nosymbols>
*----> Raw Stack Dump <----*
0322ff58 *fe 30 e7 77 94 03 00 00 - 00 00 00 00 74 ff 22 03 *.0.w........t.".
0322ff68 *00 00 00 00 f0 1e d2 02 - 42 1b f8 77 00 44 5f 9a *........B..w.D_.
0322ff78 *fe ff ff ff 73 1b f8 77 - 26 31 e7 77 94 03 00 00 *....s..w&1.w....
0322ff88 *c0 27 09 00 00 00 00 00 - 7f 6d aa 75 94 03 00 00 *.'.......m.u....
0322ff98 *c0 27 09 00 1c ee d7 01 - f0 1e d2 02 ec ff 22 03 *.'............".
0322ffa8 *f0 1e d2 02 ae 6c aa 75 - 01 00 00 00 88 6c aa 75 *.....l.u.....l.u
0322ffb8 *cd 37 e7 77 f0 1e d2 02 - 1c ee d7 01 01 00 00 00 *.7.w............
0322ffc8 *f0 1e d2 02 00 f0 fa 7f - 18 6a 19 00 c0 ff 22 03 *.........j....".
0322ffd8 *18 6a 19 00 ff ff ff ff - be dc e8 77 80 81 e7 77 *.j.........w...w
0322ffe8 *00 00 00 00 00 00 00 00 - 00 00 00 00 7f 6c aa 75 *.............l.u
0322fff8 *f0 1e d2 02 00 00 00 00 - 08 00 00 00 01 01 00 00 *................
03230008 *ee ff ee ff 00 00 00 00 - 00 00 81 01 00 70 0c 00 *.............p..
03230018 *00 00 23 03 00 01 00 00 - 40 00 23 03 00 00 33 03 *..#.....@.#...3.
03230028 *ec 00 00 00 0b 00 00 00 - f8 05 81 01 00 00 00 00 *................
03230038 *48 8d 26 03 00 00 00 00 - 0f 00 08 00 01 00 08 00 *H.&.............
03230048 *d0 ac 23 03 a8 37 81 01 - fe 00 f2 8c 00 f8 f3 c6 *..#..7..........
03230058 *0c 00 03 00 01 00 08 00 - d8 01 81 01 18 ab 23 03 *..............#.
03230068 *00 fe 00 f6 00 00 0d 66 - 09 00 03 00 01 00 08 00 *.......f........
03230078 *c0 01 81 01 d8 00 23 03 - fc fc 00 cd 00 19 63 ed *......#.......c.
03230088 *03 00 03 00 01 01 08 00 - ed fe fe fe 22 00 81 01 *............"...
Statusabbild für Threadkennung 0x6ac
eax=0354ff74 ebx=0354ff74 ecx=0354ff74 edx=00000000 esi=77f82147 edi=000003c8
eip=77f82152 esp=0354ff58 ebp=0354ff7c iopl=0 * * * * nv up ei ng nz ac pe cy
cs=001b *ss=0023 *ds=0023 *es=0023 *fs=0038 *gs=0000 * * * * * * efl=00000293
Funktion: NtWaitForSingleObject
* * * *77f82147 b8ea000000 * * * mov * * eax,0xea
* * * *77f8214c 8d542404 * * * * lea * * edx,[esp+0x4] * * * * *ss:03fdd52f=????????
* * * *77f82150 cd2e * * * * * * int * * 2e
* * * *77f82152 c20c00 * * * * * ret * * 0xc
* * * *77f82155 8d0c1b * * * * * lea * * ecx,[ebx+ebx] * * * * *ds:0354ff74=9a5f4400
* * * *77f82158 8908 * * * * * * mov * * [eax],ecx * * * * * * *ds:0354ff74=9a5f4400
* * * *77f8215a e92bf8ffff * * * jmp * * RtlMultiByteToUnicodeN+0x2e (77f8198a)
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 *Param#2 *Param#3 *Param#4 *Function Name
0354FF7C 77E73126 000003C8 000927C0 00000000 75AA6D7F ntdll!NtWaitForSingleObject
77F81B73 4AFFC033 BE850F08 89000005 FF900C42 8D0F044A kernel32!WaitForSingleObject
0424548B 00000000 00000000 00000000 00000000 00000000 <nosymbols>
*----> Raw Stack Dump <----*
0354ff58 *fe 30 e7 77 c8 03 00 00 - 00 00 00 00 74 ff 54 03 *.0.w........t.T.
0354ff68 *00 00 00 00 a0 35 d2 02 - 42 1b f8 77 00 44 5f 9a *.....5..B..w.D_.
0354ff78 *fe ff ff ff 73 1b f8 77 - 26 31 e7 77 c8 03 00 00 *....s..w&1.w....
0354ff88 *c0 27 09 00 00 00 00 00 - 7f 6d aa 75 c8 03 00 00 *.'.......m.u....
0354ff98 *c0 27 09 00 00 00 00 00 - a0 35 d2 02 ec ff 54 03 *.'.......5....T.
0354ffa8 *a0 35 d2 02 ae 6c aa 75 - 00 00 00 00 88 6c aa 75 *.5...l.u.....l.u
0354ffb8 *cd 37 e7 77 a0 35 d2 02 - 00 00 00 00 00 00 00 00 *.7.w.5..........
0354ffc8 *a0 35 d2 02 00 e0 fa 7f - 00 00 00 00 c0 ff 54 03 *.5............T.
0354ffd8 *00 00 00 00 ff ff ff ff - be dc e8 77 80 81 e7 77 *...........w...w
0354ffe8 *00 00 00 00 00 00 00 00 - 00 00 00 00 7f 6c aa 75 *.............l.u
0354fff8 *a0 35 d2 02 00 00 00 00 - 17 ef c8 ca 01 00 00 00 *.5..............
03550008 *00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 *................
03550018 *00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 *................
03550028 *00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 *................
03550038 *00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 *................
03550048 *8b 4e b2 1a 5a 00 40 00 - 00 00 00 00 00 00 00 00 *.N..Z.@.........
03550058 *a6 c8 1c d4 86 00 37 00 - 00 00 00 00 00 00 00 00 *......7.........
03550068 *00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 *................
03550078 *00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 *................
03550088 *00 00 00 00 00 00 00 00 - 30 cf 34 54 09 00 09 00 *........0.4T....
Statusabbild für Threadkennung 0x2fc
eax=0458b250 ebx=00196e38 ecx=00000101 edx=00000000 esi=74f59398 edi=00000000
eip=77f82194 esp=0377ff84 ebp=0377ffb4 iopl=0 * * * * nv up ei pl nz na pe nc
cs=001b *ss=0023 *ds=0023 *es=0023 *fs=0038 *gs=0000 * * * * * * efl=00000202
Funktion: ZwRemoveIoCompletion
* * * *77f82189 b8a8000000 * * * mov * * eax,0xa8
* * * *77f8218e 8d542404 * * * * lea * * edx,[esp+0x4] * * * * *ss:0420d55b=????????
* * * *77f82192 cd2e * * * * * * int * * 2e
* * * *77f82194 c21400 * * * * * ret * * 0x14
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 *Param#2 *Param#3 *Param#4 *Function Name
0377FFB4 77E737CD 74F46AD7 7FFD5000 FFFFFFFF 00196E38 ntdll!ZwRemoveIoCompletion
0377FFEC 00000000 74F454A2 00196E38 00000000 00000000 kernel32!TlsSetValue
*----> Raw Stack Dump <----*
0377ff84 *25 38 f4 74 f4 03 00 00 - bc ff 77 03 b0 ff 77 03 *%8.t......w...w.
0377ff94 *a4 ff 77 03 00 38 f4 74 - 00 50 fd 7f ff ff ff ff *..w..8.t.P......
0377ffa4 *41 02 00 c0 00 00 00 00 - 00 00 f4 74 10 f4 5f 04 *A..........t.._.
0377ffb4 *ec ff 77 03 cd 37 e7 77 - d7 6a f4 74 00 50 fd 7f *..w..7.w.j.t.P..
0377ffc4 *ff ff ff ff 38 6e 19 00 - 00 d0 fa 7f f8 0e 13 00 *....8n..........
0377ffd4 *c0 ff 77 03 f8 0e 13 00 - ff ff ff ff be dc e8 77 *..w............w
0377ffe4 *80 81 e7 77 00 00 00 00 - 00 00 00 00 00 00 00 00 *...w............
0377fff4 *a2 54 f4 74 38 6e 19 00 - 00 00 00 00 00 00 00 00 *.T.t8n..........
03780004 *9f 00 13 00 10 00 90 01 - 17 00 b0 01 ff ff ff 00 *................
03780014 *ff ff ff 00 00 00 00 00 - 00 00 00 00 ff ff ff 00 *................
03780024 *ff ff ff 00 00 00 00 00 - 00 00 00 00 00 00 00 00 *................
03780034 *01 00 00 00 0d 02 01 01 - 00 00 00 00 00 00 00 00 *................
03780044 *00 00 00 00 00 00 00 00 - 02 00 00 00 01 00 00 00 *................
03780054 *01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 *................
03780064 *1f 00 89 01 00 00 00 00 - ff ff ff ff ff ff ff ff *................
03780074 *00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 *................
03780084 *01 00 00 00 00 00 00 00 - 00 00 00 00 21 00 8a 01 *............!...
03780094 *00 00 00 40 06 00 00 00 - 00 00 00 00 00 00 00 00 *...@............
037800a4 *00 00 00 00 00 00 00 00 - 00 00 00 40 06 00 00 00 *...........@....
037800b4 *00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 *................
Statusabbild für Threadkennung 0x490
eax=77532bdf ebx=00000002 ecx=00000000 edx=00000000 esi=77f820e5 edi=00000002
eip=77f820f0 esp=03f1ff24 ebp=03f1ff70 iopl=0 * * * * nv up ei pl zr na po nc
cs=001b *ss=0023 *ds=0023 *es=0023 *fs=0038 *gs=0000 * * * * * * efl=00000246
Funktion: NtWaitForMultipleObjects
* * * *77f820e5 b8e9000000 * * * mov * * eax,0xe9
* * * *77f820ea 8d542404 * * * * lea * * edx,[esp+0x4] * * * * *ss:049ad4fb=????????
* * * *77f820ee cd2e * * * * * * int * * 2e
* * * *77f820f0 c21400 * * * * * ret * * 0x14
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 *Param#2 *Param#3 *Param#4 *Function Name
03F1FF70 77E760C6 03F1FF48 00000001 00000000 00000000 ntdll!NtWaitForMultipleObjects
03F1FFB4 77E737CD 00000000 7FFDEBF8 00000000 00000000 kernel32!WaitForMultipleObjects
03F1FFEC 00000000 77532BDF 00000000 00000000 00000000 kernel32!TlsSetValue
*----> Raw Stack Dump <----*
03f1ff24 *6e 36 e7 77 02 00 00 00 - 48 ff f1 03 01 00 00 00 *n6.w....H.......
03f1ff34 *00 00 00 00 00 00 00 00 - f8 eb fd 7f 00 00 00 00 *................
03f1ff44 *00 00 00 00 58 04 00 00 - 54 04 00 00 20 48 3e 81 *....X...T... H>.
03f1ff54 *c0 46 3e 81 00 00 00 00 - 00 00 00 00 00 00 00 00 *.F>.............
03f1ff64 *00 00 00 00 00 00 00 00 - 00 00 00 00 b4 ff f1 03 *................
03f1ff74 *c6 60 e7 77 48 ff f1 03 - 01 00 00 00 00 00 00 00 *.`.wH...........
03f1ff84 *00 00 00 00 00 00 00 00 - 1f 2c 53 77 02 00 00 00 *.........,Sw....
03f1ff94 *a4 ff f1 03 00 00 00 00 - ff ff ff ff 00 00 00 00 *................
03f1ffa4 *58 04 00 00 54 04 00 00 - 00 00 00 00 00 00 00 00 *X...T...........
03f1ffb4 *ec ff f1 03 cd 37 e7 77 - 00 00 00 00 f8 eb fd 7f *.....7.w........
03f1ffc4 *00 00 00 00 00 00 00 00 - 00 40 fd 7f 00 00 00 00 *.........@......
03f1ffd4 *c0 ff f1 03 00 00 00 00 - ff ff ff ff be dc e8 77 *...............w
03f1ffe4 *80 81 e7 77 00 00 00 00 - 00 00 00 00 00 00 00 00 *...w............
03f1fff4 *df 2b 53 77 00 00 00 00 - 00 00 00 00 00 00 00 00 *.+Sw............
03f20004 *00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 *................
03f20014 *00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 *................
03f20024 *00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 *................
03f20034 *00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 *................
03f20044 *00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 *................
03f20054 *00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 *................
Statusabbild für Threadkennung 0x4e0
eax=00000045 ebx=0426ff48 ecx=0153ad70 edx=00000000 esi=77f82147 edi=000004b4
eip=77f82152 esp=0426ff2c ebp=0426ff50 iopl=0 * * * * nv up ei ng nz ac po cy
cs=001b *ss=0023 *ds=0023 *es=0023 *fs=0038 *gs=0000 * * * * * * efl=00000297
Funktion: NtWaitForSingleObject
* * * *77f82147 b8ea000000 * * * mov * * eax,0xea
* * * *77f8214c 8d542404 * * * * lea * * edx,[esp+0x4] * * * * *ss:04cfd503=????????
* * * *77f82150 cd2e * * * * * * int * * 2e
* * * *77f82152 c20c00 * * * * * ret * * 0xc
* * * *77f82155 8d0c1b * * * * * lea * * ecx,[ebx+ebx] * * * * *ds:0426ff48=ffb3b4c0
* * * *77f82158 8908 * * * * * * mov * * [eax],ecx * * * * * * *ds:00000045=????????
* * * *77f8215a e92bf8ffff * * * jmp * * RtlMultiByteToUnicodeN+0x2e (77f8198a)
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 *Param#2 *Param#3 *Param#4 *Function Name
0426FF50 77E73126 000004B4 000001F4 00000000 00467DDF ntdll!NtWaitForSingleObject
0426FFB4 77E737CD 01538CB0 00000000 00000000 01538CB0 kernel32!WaitForSingleObject
0426FFEC 00000000 00000000 00000000 00000000 00000000 kernel32!TlsSetValue
Statusabbild für Threadkennung 0x6a8
eax=015517a0 ebx=0436ff54 ecx=0436ff40 edx=00000000 esi=77f82147 edi=000004ac
eip=77f82152 esp=0436ff38 ebp=0436ff5c iopl=0 * * * * nv up ei ng nz ac po cy
cs=001b *ss=0023 *ds=0023 *es=0023 *fs=0038 *gs=0000 * * * * * * efl=00000297
Funktion: NtWaitForSingleObject
* * * *77f82147 b8ea000000 * * * mov * * eax,0xea
* * * *77f8214c 8d542404 * * * * lea * * edx,[esp+0x4] * * * * *ss:04dfd50f=????????
* * * *77f82150 cd2e * * * * * * int * * 2e
* * * *77f82152 c20c00 * * * * * ret * * 0xc
* * * *77f82155 8d0c1b * * * * * lea * * ecx,[ebx+ebx] * * * * *ds:0436ff54=b8797400
* * * *77f82158 8908 * * * * * * mov * * [eax],ecx * * * * * * *ds:015517a0=01551650
* * * *77f8215a e92bf8ffff * * * jmp * * RtlMultiByteToUnicodeN+0x2e (77f8198a)
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 *Param#2 *Param#3 *Param#4 *Function Name
0436FF5C 77E73126 000004AC 0001D4C0 00000000 00467DDF ntdll!NtWaitForSingleObject
0436FFB4 77E737CD 01538EC0 00000000 00000000 01538EC0 kernel32!WaitForSingleObject
0436FFEC 00000000 00000000 00000000 00000000 00000000 kernel32!TlsSetValue
Statusabbild für Threadkennung 0x1e8
eax=a6345ea4 ebx=77f82147 ecx=0000000d edx=00000000 esi=00000000 edi=00000001
eip=77f82152 esp=0446c49c ebp=0446c4d4 iopl=0 * * * * nv up ei ng nz na po nc
cs=001b *ss=0023 *ds=0023 *es=0023 *fs=003b *gs=0000 * * * * * * efl=00000286
Funktion: NtWaitForSingleObject
* * * *77f82147 b8ea000000 * * * mov * * eax,0xea
* * * *77f8214c 8d542404 * * * * lea * * edx,[esp+0x4] * * * * *ss:04ef9a73=????????
* * * *77f82150 cd2e * * * * * * int * * 2e
* * * *77f82152 c20c00 * * * * * ret * * 0xc
* * * *77f82155 8d0c1b * * * * * lea * * ecx,[ebx+ebx] * * * * *ds:77f82147=0000eab8
* * * *77f82158 8908 * * * * * * mov * * [eax],ecx * * * * * * *ds:a6345ea4=????????
* * * *77f8215a e92bf8ffff * * * jmp * * RtlMultiByteToUnicodeN+0x2e (77f8198a)
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 *Param#2 *Param#3 *Param#4 *Function Name
0446C4D4 74F42908 0000052C 00000530 00000001 00000004 ntdll!NtWaitForSingleObject
0446C5C0 74FA1A5E 00000001 0446C65C 0446D660 0446E664 msafd!WSPGetSockOpt
0446C624 004A8851 00000001 0446C65C 0446D660 0446E664 ws2_32!select
0000001E 00000000 00000000 00000000 00000000 00000000 !<nosymbols>
*----> Raw Stack Dump <----*
0446c49c *26 2a f4 74 2c 05 00 00 - 01 00 00 00 c0 c4 46 04 *&*.t,.........F.
0446c4ac *5c c6 46 04 30 14 1c 00 - 20 14 1c 00 d0 01 00 00 *\.F.0... .......
0446c4bc *01 00 00 00 c0 b4 b3 ff - ff ff ff ff 48 03 59 04 *............H.Y.
0446c4cc *00 00 00 00 00 00 00 00 - c0 c5 46 04 08 29 f4 74 *..........F..).t
0446c4dc *2c 05 00 00 30 05 00 00 - 01 00 00 00 04 00 00 00 *,...0...........
0446c4ec *64 e6 46 04 98 dd 58 04 - 60 d6 46 04 c0 bd f0 ff *d.F...X.`.F.....
0446c4fc *ff ff ff ff 00 00 00 00 - 00 00 00 00 a3 7a e7 77 *.............z.w
0446c50c *ff ff ff ff 00 00 00 00 - 00 00 00 00 48 4e 19 00 *............HN..
0446c51c *00 00 00 00 00 00 00 00 - 01 00 00 00 00 00 00 00 *................
0446c52c *00 00 00 00 c0 bd f0 ff - ff ff ff ff c0 bd f0 ff *................
0446c53c *ff ff ff ff 00 00 00 00 - 00 c5 46 04 30 05 00 00 *..........F.0...
0446c54c *19 00 00 00 00 00 00 00 - 20 05 00 00 19 00 00 00 *........ .......
0446c55c *d8 c5 46 04 18 05 00 00 - 19 00 00 00 fe ff ff ff *..F.............
0446c56c *ff ff ff ff 48 4e 19 00 - 00 00 00 00 00 00 00 00 *....HN..........
0446c57c *48 03 59 04 58 4e 19 00 - 05 00 00 00 20 14 1c 00 *H.Y.XN...... ...
0446c58c *c4 01 00 00 23 00 00 00 - 00 00 00 00 00 00 00 00 *....#...........
0446c59c *00 00 00 00 10 00 00 00 - d4 15 1c 00 ec c4 46 04 *..............F.
0446c5ac *f4 c5 46 04 14 c6 46 04 - 00 e2 f4 74 50 2b f4 74 *..F...F....tP+.t
0446c5bc *ff ff ff ff 24 c6 46 04 - 5e 1a fa 74 01 00 00 00 *....$.F.^..t....
0446c5cc *5c c6 46 04 60 d6 46 04 - 64 e6 46 04 54 c6 46 04 *\.F.`.F.d.F.T.F.
Statusabbild für Threadkennung 0x2e0
eax=7ffa9c00 ebx=00000000 ecx=7ffb001c edx=00000000 esi=77f82147 edi=00000504
eip=77f82152 esp=0456ff08 ebp=0456ff2c iopl=0 * * * * nv up ei pl zr na po nc
cs=001b *ss=0023 *ds=0023 *es=0023 *fs=0038 *gs=0000 * * * * * * efl=00000246
Funktion: NtWaitForSingleObject
* * * *77f82147 b8ea000000 * * * mov * * eax,0xea
* * * *77f8214c 8d542404 * * * * lea * * edx,[esp+0x4] * * * * *ss:04ffd4df=????????
* * * *77f82150 cd2e * * * * * * int * * 2e
* * * *77f82152 c20c00 * * * * * ret * * 0xc
* * * *77f82155 8d0c1b * * * * * lea * * ecx,[ebx+ebx] * * * * *ds:00000000=????????
* * * *77f82158 8908 * * * * * * mov * * [eax],ecx * * * * * * *ds:7ffa9c00=00780045
* * * *77f8215a e92bf8ffff * * * jmp * * RtlMultiByteToUnicodeN+0x2e (77f8198a)
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 *Param#2 *Param#3 *Param#4 *Function Name
0456FF2C 77E73126 00000504 FFFFFFFF 00000000 00467DDF ntdll!NtWaitForSingleObject
0456FF8C 00468165 00000000 0012E16C 0155F5E0 FFFFFFFF kernel32!WaitForSingleObject
00000000 00000000 00000000 00000000 00000000 00000000 !<nosymbols>
*----> Raw Stack Dump <----*
0456ff08 *fe 30 e7 77 04 05 00 00 - 00 00 00 00 00 00 00 00 *.0.w............
0456ff18 *ee f5 55 01 ff ff ff ff - ff ff ff ff 04 05 00 00 *..U.............
0456ff28 *04 05 00 00 8c ff 56 04 - 26 31 e7 77 04 05 00 00 *......V.&1.w....
0456ff38 *ff ff ff ff 00 00 00 00 - df 7d 46 00 04 05 00 00 *.........}F.....
0456ff48 *ff ff ff ff 4b 7e 46 00 - 66 80 46 00 ff ff ff ff *....K~F.f.F.....
0456ff58 *d0 27 5a 01 e0 f5 55 01 - b4 ff 56 04 ee f5 55 01 *.'Z...U...V...U.
0456ff68 *3f 00 00 00 e0 f5 55 01 - d5 16 2b 01 7e 2a 4a 00 *?.....U...+.~*J.
0456ff78 *8c ff 56 04 ff ff ff ff - 00 00 00 00 e0 f5 55 01 *..V...........U.
0456ff88 *e0 f5 55 01 00 00 00 00 - 65 81 46 00 00 00 00 00 *..U.....e.F.....
0456ff98 *6c e1 12 00 e0 f5 55 01 - ff ff ff ff 94 ff 56 04 *l.....U.......V.
0456ffa8 *dc ff 56 04 b0 28 52 00 - 00 00 00 00 ec ff 56 04 *..V..(R.......V.
0456ffb8 *cd 37 e7 77 e0 f5 55 01 - 00 00 00 00 6c e1 12 00 *.7.w..U.....l...
0456ffc8 *e0 f5 55 01 00 90 fa 7f - 45 90 fb 77 c0 ff 56 04 *..U.....E..w..V.
0456ffd8 *45 90 fb 77 ff ff ff ff - be dc e8 77 80 81 e7 77 *E..w.......w...w
0456ffe8 *00 00 00 00 00 00 00 00 - 00 00 00 00 30 81 46 00 *............0.F.
0456fff8 *e0 f5 55 01 00 00 00 00 - 08 00 00 00 01 01 00 00 *..U.............
04570008 *ee ff ee ff 00 00 00 00 - 00 00 13 00 00 c0 06 00 *................
04570018 *00 00 57 04 00 01 00 00 - 40 00 57 04 00 00 67 04 *..W.....@.W...g.
04570028 *b9 00 00 00 12 00 00 00 - 98 05 13 00 00 00 00 00 *................
04570038 *b8 7f 57 04 00 00 00 00 - 55 00 08 00 01 01 08 00 *..W.....U.......
Statusabbild für Threadkennung 0x148
eax=00000006 ebx=00000003 ecx=355ca000 edx=00000000 esi=77f820e5 edi=00000003
eip=77f820f0 esp=05a2ff04 ebp=05a2ff50 iopl=0 * * * * nv up ei pl zr na po nc
cs=001b *ss=0023 *ds=0023 *es=0023 *fs=0038 *gs=0000 * * * * * * efl=00000246
Funktion: NtWaitForMultipleObjects
* * * *77f820e5 b8e9000000 * * * mov * * eax,0xe9
* * * *77f820ea 8d542404 * * * * lea * * edx,[esp+0x4] * * * * *ss:064bd4db=????????
* * * *77f820ee cd2e * * * * * * int * * 2e
* * * *77f820f0 c21400 * * * * * ret * * 0x14
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 *Param#2 *Param#3 *Param#4 *Function Name
05A2FF50 77E760C6 05A2FF28 00000001 00000000 00000000 ntdll!NtWaitForMultipleObjects
05A2FFB0 35527F2B 77E737CD 0520CDD4 0012F634 80000000 kernel32!WaitForMultipleObjects
05A2FFEC 00000000 35527F22 0520CDD4 00000000 18A21A5B !DBToAmpFactor
*----> Raw Stack Dump <----*
05a2ff04 *6e 36 e7 77 03 00 00 00 - 28 ff a2 05 01 00 00 00 *n6.w....(.......
05a2ff14 *00 00 00 00 00 00 00 00 - cc 13 da 9b d4 cd 20 05 *.............. .
05a2ff24 *00 00 00 00 24 09 00 00 - 00 07 00 00 2c 06 00 00 *....$.......,...
05a2ff34 *4d 31 e7 77 24 09 00 00 - 01 00 00 00 ab 75 50 35 *M1.w$........uP5
05a2ff44 *24 cd 20 05 24 cd 20 05 - 00 00 00 00 b0 ff a2 05 *$. .$. .........
05a2ff54 *c6 60 e7 77 28 ff a2 05 - 01 00 00 00 00 00 00 00 *.`.w(...........
05a2ff64 *00 00 00 00 00 00 00 00 - b0 7f 52 35 03 00 00 00 *..........R5....
05a2ff74 *8c ff a2 05 00 00 00 00 - ff ff ff ff 34 f6 12 00 *............4...
05a2ff84 *00 00 00 80 d4 cd 20 05 - 24 09 00 00 00 07 00 00 *...... .$.......
05a2ff94 *2c 06 00 00 2c 06 00 00 - 70 24 3a 9a 2d 00 00 00 *,...,...p$:.-...
05a2ffa4 *24 cd 20 05 ff ff ff ff - 03 00 00 00 ec ff a2 05 *$. .............
05a2ffb4 *2b 7f 52 35 cd 37 e7 77 - d4 cd 20 05 34 f6 12 00 *+.R5.7.w.. .4...
05a2ffc4 *00 00 00 80 d4 cd 20 05 - 00 b0 fd 7f 00 f7 12 00 *...... .........
05a2ffd4 *c0 ff a2 05 00 f7 12 00 - ff ff ff ff be dc e8 77 *...............w
05a2ffe4 *80 81 e7 77 00 00 00 00 - 00 00 00 00 00 00 00 00 *...w............
05a2fff4 *22 7f 52 35 d4 cd 20 05 - 00 00 00 00 5b 1a a2 18 *".R5.. .....[...
05a30004 *88 18 c2 16 dd 15 0e 14 - 1c 13 42 11 62 11 7f 0f *..........B.b...
05a30014 *6e 11 81 0f 6d 13 72 11 - 20 17 1b 15 c6 1b b7 19 *n...m.r. .......
05a30024 *5c 20 46 1e 1e 24 00 22 - 87 26 5b 24 86 27 4f 25 *\ F..$.".&[$.'O%
05a30034 *a5 27 69 25 a5 27 62 25 - 26 28 db 25 62 29 0f 27 *.'i%.'b%&(.%b).'
Statusabbild für Threadkennung 0x684
eax=0210f9e0 ebx=00000024 ecx=0211e1d0 edx=00000000 esi=0210ff60 edi=00000000
eip=77e048fc esp=0210feec ebp=0210ff0c iopl=0 * * * * nv up ei pl zr na po nc
cs=001b *ss=0023 *ds=0023 *es=0023 *fs=0038 *gs=0000 * * * * * * efl=00000246
Funktion: PtInRect
* * * *77e048d6 ff750c * * * * * push * *dword ptr [ebp+0xc] * *ss:02b9d4e2=????????
* * * *77e048d9 ff5508 * * * * * call * *dword ptr [ebp+0x8] * *ss:02b9d4e2=????????
* * * *77e048dc 817c2404cdabbadc * * * * * * * * * * * * * * * *ss:02b9d4c3=????????
* * * * * * * * * * * * * * * * *cmp * * dword ptr [esp+0x4],0xdcbaabcd
* * * *77e048e4 0f85c8690300 * * jne * * SetClassLongW+0x556 (77e3b2b2)
* * * *77e048ea 83c408 * * * * * add * * esp,0x8
* * * *77e048ed 5d * * * * * * * pop * * ebp
* * * *77e048ee c21400 * * * * * ret * * 0x14
* * * *77e048f1 b89a110000 * * * mov * * eax,0x119a
* * * *77e048f6 8d542404 * * * * lea * * edx,[esp+0x4] * * * * *ss:02b9d4c3=????????
* * * *77e048fa cd2e * * * * * * int * * 2e
* * * *77e048fc c21000 * * * * * ret * * 0x10
* * * *77e048ff b8cb110000 * * * mov * * eax,0x11cb
* * * *77e04904 8d542404 * * * * lea * * edx,[esp+0x4] * * * * *ss:02b9d4c3=????????
* * * *77e04908 cd2e * * * * * * int * * 2e
* * * *77e0490a c21000 * * * * * ret * * 0x10
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 *Param#2 *Param#3 *Param#4 *Function Name
0210FF0C 1001486B 0210FF60 00000000 00000000 00000000 user32!PtInRect
0210FF80 1002E109 01814820 7FFDEBF8 00000000 03268008 !<nosymbols>
0210FFB4 77E737CD 03268008 7FFDEBF8 00000000 03268008 !<nosymbols>
0210FFEC 00000000 1002E0B2 03268008 00000000 00905A4D kernel32!TlsSetValue
*----> Raw Stack Dump <----*
0210feec *3c 67 e1 77 60 ff 10 02 - 00 00 00 00 00 00 00 00 *<g.w`...........
0210fefc *00 00 00 00 24 00 00 00 - 00 67 e1 77 00 00 00 00 *....$....g.w....
0210ff0c *80 ff 10 02 6b 48 01 10 - 60 ff 10 02 00 00 00 00 *....kH..`.......
0210ff1c *00 00 00 00 00 00 00 00 - f8 eb fd 7f 08 80 26 03 *..............&.
0210ff2c *08 80 26 03 30 00 00 00 - 23 08 00 00 27 4f 01 10 *..&.0...#...'O..
0210ff3c *00 00 00 00 00 00 00 00 - 00 00 40 00 00 00 00 00 *..........@.....
0210ff4c *2f 02 d2 00 00 00 00 00 - 00 00 00 00 c1 4d 81 01 */............M..
0210ff5c *00 00 00 00 52 02 30 00 - 13 01 00 00 01 00 00 00 *....R.0.........
0210ff6c *00 00 00 00 0d 3a 2b 01 - 71 01 00 00 05 01 00 00 *.....:+.q.......
0210ff7c *00 00 00 50 b4 ff 10 02 - 09 e1 02 10 20 48 81 01 *...P........ H..
0210ff8c *f8 eb fd 7f 00 00 00 00 - 08 80 26 03 20 73 41 81 *..........&. sA.
0210ff9c *8c ff 10 02 ff ff ff ff - dc ff 10 02 cc 40 03 10 *.............@..
0210ffac *40 c9 03 10 00 00 00 00 - ec ff 10 02 cd 37 e7 77 *@............7.w
0210ffbc *08 80 26 03 f8 eb fd 7f - 00 00 00 00 08 80 26 03 *..&...........&.
0210ffcc *00 70 fd 7f e4 72 12 00 - c0 ff 10 02 e4 72 12 00 *.p...r.......r..
0210ffdc *ff ff ff ff be dc e8 77 - 80 81 e7 77 00 00 00 00 *.......w...w....
0210ffec *00 00 00 00 00 00 00 00 - b2 e0 02 10 08 80 26 03 *..............&.
0210fffc *00 00 00 00 4d 5a 90 00 - 03 00 00 00 04 00 00 00 *....MZ..........
0211000c *ff ff 00 00 b8 00 00 00 - 00 00 00 00 40 00 00 00 *............@...
0211001c *00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 *................
ich erwarte nicht dass sich da irgentwer auskennt aber man kann ja mal probieren
__________________
"Will Paul sich hierhin setzen?"
"Nein Paul sitzt hier gut"
|