Execl DrWatson Error 80000007

A

Andreas.Wizemann

Hello,
my EXECL stops working and i didn't know why !?
Can anybody help me.


Microsoft (R) DrWtsn32
Copyright (C) 1985-2001 Microsoft Corp. Alle Rechte vorbehalten.



Anwendungsausnahme aufgetreten:
Anwendung: C:\Programme\Microsoft Office\Office\EXCEL.EXE
(pid=3048)
Wann: 08.09.2007 @ 13:42:37.953
Ausnahmenummer: 80000007
()

*----> Systeminformationen <----*
Computername: ITNB01171
Benutzername: AWizeman
Terminalsitzungskennung: 0
Prozessoranzahl: 2
Prozessortyp: x86 Family 6 Model 15 Stepping 6
Windows-Version: 5.1
Aktuelles Build: 2600
Service Pack: 2
Aktueller Typ: Multiprocessor Free
Firma:
Besitzer: supervisor

*----> Taskliste <----*
0 System Process
4 System
1680 smss.exe
1980 csrss.exe
504 winlogon.exe
560 services.exe
572 lsass.exe
796 ibmpmsvc.exe
824 Ati2evxx.exe
840 svchost.exe
924 svchost.exe
968 svchost.exe
1024 btwdins.exe
1088 Ati2evxx.exe
1156 S24EvMon.exe
1276 svchost.exe
1312 svchost.exe
1332 Error 0xD0000022
2036 AppSvc32.exe
1664 spoolsv.exe
2012 IPSSVC.EXE
2104 AcPrfMgrSvc.exe
2144 acs.exe
2168 ALUSchedulerSvc.exe
2208 WlanNetService.exe
2240 ccSvcHst.exe
2316 EvtEng.exe
2436 GoogleUpdaterService.exe
2476 nalntsrv.exe
2524 NPROTECT.EXE
2612 ntrtscan.exe
2704 oodag.exe
3504 WolSerNT.exe
3720 RegSrvc.exe
3868 ZenRem32.exe
3004 rxapi.exe
3028 NOPDB.EXE
3124 suservice.exe
3372 tvt_reg_monitor_svc.exe
3396 tmlisten.exe
3448 TPHDEXLG.exe
3660 TpKmpSVC.exe
3696 tsmmgr_agent.exe
3756 tvttcsd.exe
1032 rrservice.exe
3892 tvtsched.exe
3928 IUService.exe
3964 vmware-ufad.exe
4004 logmon.exe
1752 wdfmgr.exe
1956 vmware-authd.exe
2644 vmount2.exe
2712 vmnat.exe
2856 wm.exe
3252 vmnetdhcp.exe
3516 AcSvc.exe
1160 wmiapsrv.exe
492 SvcGuiHlpr.exe
2916 WMRUNDLL.EXE
1292 Explorer.EXE
5972 rundll32.exe
1012 SynTPLpr.exe
4164 SynTPEnh.exe
4896 EzEjMnAp.Exe
5004 svchost.exe
4036 TpShocks.exe
5524 TPOSDSVC.exe
5584 TPONSCR.exe
5812 TpScrex.exe
5984 LPMGR.exe
6060 jusched.exe
780 Amsg.exe
4596 issch.exe
4640 AwaySch.EXE
236 scheduler_proxy.exe
2932 ACTray.exe
5092 ACWLIcon.exe
5208 cssauth.exe
5328 smax4pnp.exe
1580 TPFNF7SP.exe
5396 dpmw32.exe
5596 NWTRAY.EXE
5684 pccntmon.exe
1936 vmware-tray.exe
1632 hqtray.exe
2792 ccApp.exe
4808 oodtray.exe
1392 wlangui.exe
5424 realsched.exe
5464 ctfmon.exe
1432 SCREEN~1.EXE
5852 taskbarshuffle.exe
4236 Wcescomm.exe
4064 MOM.EXE
4968 rapimgr.exe
3096 symlcsvc.exe
5040 NALDESK.EXE
5376 BTTray.exe
4776 FilePathSrv.exe
2944 GoogleUpdater.exe
4196 hardcopy.exe
5128 tclock2.exe
2888 ccc.exe
4892 firefox.exe
5512 Error 0xD0000022
2192 iexplore.exe
5756 UD.EXE
6016 ud_17356044.exe
4728 WCGrid_AutoDock.exe
4952 RealPlay.exe
5508 ccSvcHst.exe
3048 EXCEL.EXE
5848 drwtsn32.exe

*----> Modulliste <----*
(0000000000e70000 - 0000000000e85000: C:\WINDOWS\system32\btmmhook.dll
(0000000001090000 - 0000000001094000: C:\Programme\Norton
AntiVirus\rcOffcAV.dll
(0000000001ad0000 - 0000000001afc000:
C:\WINDOWS\system32\btsendto_office.dll
(0000000001b00000 - 0000000001b20000: C:\WINDOWS\system32\btosif.dll
(0000000001b20000 - 0000000001b55000: C:\WINDOWS\system32\btsendto.dll
(0000000002510000 - 0000000002614000:
C:\WINDOWS\system32\WidcommSdk.dll
(0000000002620000 - 00000000026d8000: C:\WINDOWS\system32\wbtapi.dll
(000000000ffd0000 - 000000000fff8000: C:\WINDOWS\system32\rsaenh.dll
(0000000010000000 - 0000000010011000:
C:\Programme\Hardcopy\HcDLL2_J_Win32.dll
(0000000020000000 - 00000000202d9000: C:\WINDOWS\system32\xpsp2res.dll
(0000000030000000 - 00000000306d9000: C:\Programme\Microsoft
Office\Office\EXCEL.EXE
(00000000308c0000 - 0000000030e19000: C:\Programme\Microsoft
Office\Office\MSO9.DLL
(000000005d450000 - 000000005d4ea000: C:\WINDOWS\system32\comctl32.dll
(00000000609d0000 - 00000000609d9000: C:\WINDOWS\system32\mslbui.dll
(0000000061dc0000 - 0000000061dce000: C:\WINDOWS\system32\MFC42LOC.DLL
(0000000063000000 - 0000000063014000: C:\WINDOWS\system32\SynTPFcs.dll
(0000000065000000 - 0000000065263000:
C:\PROGRA~1\GEMEIN~1\MICROS~1\VBA\VBA6\VBE6.DLL
(0000000065300000 - 000000006532e000:
C:\PROGRA~1\GEMEIN~1\MICROS~1\VBA\VBA6\1031\VBE6INTL.DLL
(0000000069a10000 - 0000000069a55000: C:\Programme\Norton
AntiVirus\AVPSVC32.dll
(0000000069a60000 - 0000000069a63000: C:\Programme\Norton
AntiVirus\AVPSVC32.loc
(0000000069a70000 - 0000000069ad2000: C:\Programme\Norton
AntiVirus\avScanUI.dll
(0000000069b30000 - 0000000069b73000: C:\Programme\Norton
AntiVirus\AVSubmit.dll
(0000000069d90000 - 0000000069dbd000: C:\Programme\Norton
AntiVirus\NAVEvent.dll
(0000000069dc0000 - 0000000069e56000: C:\Programme\Norton
AntiVirus\NAVLOGV.dll
(0000000069e60000 - 0000000069e6a000: C:\Programme\Norton
AntiVirus\navlogv.loc
(000000006a140000 - 000000006a159000: C:\Programme\Norton
AntiVirus\OfficeAV.dll
(000000006ad60000 - 000000006ad94000:
C:\PROGRA~1\GEMEIN~1\SYMANT~1\ccEvtCli.dll
(000000006ae80000 - 000000006af05000: C:\Programme\Gemeinsame
Dateien\Symantec Shared\ccL60U.dll
(000000006b500000 - 000000006b54a000: C:\Programme\Gemeinsame
Dateien\Symantec Shared\ccSvc.dll
(000000006b790000 - 000000006b7af000: C:\Programme\Gemeinsame
Dateien\Symantec Shared\ccVrTrst.dll
(000000006fb20000 - 000000006fb52000: C:\Programme\Gemeinsame
Dateien\Symantec Shared\AppCore\AppMgr32.dll
(000000006fde0000 - 000000006fe2a000: C:\Programme\Gemeinsame
Dateien\Symantec Shared\AntiVirus\AVIfc.dll
(0000000071a00000 - 0000000071a08000: C:\WINDOWS\system32\WS2HELP.dll
(0000000071a10000 - 0000000071a27000: C:\WINDOWS\system32\ws2_32.dll
(0000000071a30000 - 0000000071a3a000: C:\WINDOWS\system32\WSOCK32.dll
(0000000072f70000 - 0000000072f96000: C:\WINDOWS\system32\WINSPOOL.DRV
(0000000073d30000 - 0000000073e2e000: C:\WINDOWS\system32\MFC42.DLL
(00000000746a0000 - 00000000746eb000: C:\WINDOWS\system32\MSCTF.dll
(0000000075250000 - 000000007527e000: C:\WINDOWS\system32\msctfime.ime
(0000000076020000 - 0000000076085000: C:\WINDOWS\system32\MSVCP60.dll
(0000000076330000 - 000000007634d000: C:\WINDOWS\system32\IMM32.DLL
(0000000076350000 - 000000007639a000: C:\WINDOWS\system32\comdlg32.dll
(0000000076620000 - 00000000766d5000: C:\WINDOWS\system32\USERENV.dll
(0000000076970000 - 0000000076a21000: C:\WINDOWS\system32\SXS.DLL
(0000000076bf0000 - 0000000076c1e000: C:\WINDOWS\system32\WinTrust.dll
(0000000076c50000 - 0000000076c78000: C:\WINDOWS\system32\IMAGEHLP.dll
(0000000076f90000 - 000000007700f000: C:\WINDOWS\system32\CLBCATQ.DLL
(0000000077010000 - 00000000770e3000: C:\WINDOWS\system32\COMRes.dll
(00000000770f0000 - 000000007717b000: C:\WINDOWS\system32\OLEAUT32.dll
(00000000773a0000 - 00000000774a3000:
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
(00000000774b0000 - 00000000775ed000: C:\WINDOWS\system32\ole32.dll
(00000000778f0000 - 00000000779e4000: C:\WINDOWS\system32\SETUPAPI.dll
(0000000077a50000 - 0000000077ae5000: C:\WINDOWS\system32\Crypt32.dll
(0000000077af0000 - 0000000077b02000: C:\WINDOWS\system32\MSASN1.dll
(0000000077b10000 - 0000000077b32000: C:\WINDOWS\system32\Apphelp.dll
(0000000077bd0000 - 0000000077bd8000: C:\WINDOWS\system32\VERSION.dll
(0000000077be0000 - 0000000077c38000: C:\WINDOWS\system32\msvcrt.dll
(0000000077da0000 - 0000000077e4a000: C:\WINDOWS\system32\ADVAPI32.dll
(0000000077e50000 - 0000000077ee1000: C:\WINDOWS\system32\RPCRT4.dll
(0000000077ef0000 - 0000000077f37000: C:\WINDOWS\system32\GDI32.dll
(0000000077f40000 - 0000000077fb6000: C:\WINDOWS\system32\SHLWAPI.dll
(0000000077fc0000 - 0000000077fd1000: C:\WINDOWS\system32\Secur32.dll
(000000007c120000 - 000000007c139000: C:\WINDOWS\system32\ATL71.DLL
(000000007c340000 - 000000007c396000: C:\WINDOWS\system32\MSVCR71.dll
(000000007c3a0000 - 000000007c41b000: C:\WINDOWS\system32\MSVCP71.dll
(000000007c800000 - 000000007c907000: C:\WINDOWS\system32\kernel32.dll
(000000007c910000 - 000000007c9c7000: C:\WINDOWS\system32\ntdll.dll
(000000007c9d0000 - 000000007d1f0000: C:\WINDOWS\system32\shell32.dll
(000000007d1f0000 - 000000007d4ae000: C:\WINDOWS\system32\msi.dll
(000000007e360000 - 000000007e3f1000: C:\WINDOWS\system32\USER32.dll

*----> Statusabbild für Threadkennung 0xf48 <----*

eax=00001ff4 ebx=01044a60 ecx=0291000c edx=00000000 esi=000001bc
edi=00000000
eip=7c91eb94 esp=0013c2d4 ebp=0013c338 iopl=0 nv up ei pl zr
na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

*** ERROR: Symbol file could not be found. Defaulted to export
symbols for C:\WINDOWS\system32\ntdll.dll -
Funktion: ntdll!KiFastSystemCallRet
7c91eb89 90 nop
7c91eb8a 90 nop
ntdll!KiFastSystemCall:
7c91eb8b 8bd4 mov edx,esp
7c91eb8d 0f34 sysenter
7c91eb8f 90 nop
7c91eb90 90 nop
7c91eb91 90 nop
7c91eb92 90 nop
7c91eb93 90 nop
FEHLER ->ntdll!KiFastSystemCallRet:
7c91eb94 c3 ret
7c91eb95 8da42400000000 lea esp,[esp]
7c91eb9c 8d642400 lea esp,[esp]
7c91eba0 90 nop
7c91eba1 90 nop
7c91eba2 90 nop
7c91eba3 90 nop
7c91eba4 90 nop
ntdll!KiIntSystemCall:
7c91eba5 8d542408 lea edx,[esp+0x8]
7c91eba9 cd2e int 2e

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export
symbols for C:\WINDOWS\system32\kernel32.dll -
WARNING: Stack unwind information not available. Following frames may
be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export
symbols for C:\Programme\Gemeinsame Dateien\Symantec Shared\ccL60U.dll
-
*** ERROR: Symbol file could not be found. Defaulted to export
symbols for C:\Programme\Norton AntiVirus\OfficeAV.dll -
*** ERROR: Symbol file could not be found. Defaulted to export
symbols for C:\Programme\Microsoft Office\Office\MSO9.DLL -
*** ERROR: Symbol file could not be found. Defaulted to export
symbols for C:\Programme\Microsoft Office\Office\EXCEL.EXE -
ChildEBP RetAddr Args to Child
0013c338 7c802532 000001bc ffffffff 00000000 ntdll!KiFastSystemCallRet
0013c34c 6aea772e 000001bc ffffffff 6aeb5e9a
kernel32!WaitForSingleObject+0x12
0013c378 6a144b6f ffffffff 0013d2f8 0013d0f0 ccL60U!Ordinal1452+0x15
0013d0a0 30cf7e5b 01044958 0013d2f8 00000001 OfficeAV+0x4b6f
0013d0d8 303e6bd5 009d0cf4 0013d2f8 00000001
MSO9!MsoFDoAntiVirusScan+0x97
0013d310 301b7e43 0013d860 00000000 00000000 EXCEL!MdCallBack+0x4112a
0013dd54 300db9d9 0013e200 00000001 00000000 EXCEL!Ordinal41+0x1b7e43
0013e538 300db502 0013f8cc 00000001 00000000 EXCEL!Ordinal41+0xdb9d9
0013e570 30036a1f 0013f8cc 00000001 00000000 EXCEL!Ordinal41+0xdb502
0013e710 30363d8e 00000001 0013f8cc 00000001 EXCEL!Ordinal41+0x36a1f
0013f998 302e0248 001c4a98 0013fde8 00020000 EXCEL!Ordinal41+0x363d8e
0013fe34 301d5aac 0013fe4c 00000000 000080df EXCEL!Ordinal41+0x2e0248
0013fe60 30178f0b 00000001 00090000 001523ba EXCEL!Ordinal41+0x1d5aac
0013ff28 300027fa 00000000 0013ffc0 300026e5 EXCEL!Ordinal41+0x178f0b
0013ff34 300026e5 30000000 00000000 001523ba EXCEL!Ordinal41+0x27fa
0013ffc0 7c816fd7 00090000 012ae82e 7ffdf000 EXCEL!Ordinal41+0x26e5
0013fff0 00000000 30002658 00000000 78746341
kernel32!RegisterWaitForInputIdle+0x49

*----> Raw Stack Dump <----*
000000000013c2d4 c0 e9 91 7c cb 25 80 7c - bc 01 00 00 00 00 00 00
....|.%.|........
000000000013c2e4 00 00 00 00 58 49 04 01 - 5c 49 04 01 60 4a 04 01
.....XI..\I..`J..
000000000013c2f4 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00
.................
000000000013c304 10 00 00 00 10 00 00 00 - 00 00 00 00 00 f0 fd 7f
.................
000000000013c314 00 e0 fd 7f 00 00 00 00 - 0c c3 13 00 e8 c2 13 00
.................
000000000013c324 ec c2 13 00 94 d0 13 00 - a8 9a 83 7c f8 25 80 7c
............|.%.|
000000000013c334 00 00 00 00 4c c3 13 00 - 32 25 80 7c bc 01 00 00
.....L...2%.|....
000000000013c344 ff ff ff ff 00 00 00 00 - 78 c3 13 00 2e 77 ea 6a
.........x....w.j
000000000013c354 bc 01 00 00 ff ff ff ff - 9a 5e eb 6a bc 01 00 00
..........^.j....
000000000013c364 ff ff ff ff 5c 49 04 01 - d0 35 ee 6a 00 00 00 00
.....\I...5.j....
000000000013c374 00 00 00 00 a0 d0 13 00 - 6f 4b 14 6a ff ff ff ff
.........oK.j....
000000000013c384 f8 d2 13 00 f0 d0 13 00 - f0 d0 13 00 f8 55 14 6a
..............U.j
000000000013c394 f0 d0 13 00 cc d0 13 00 - 00 13 43 00 90 08 43 00
...........C...C.
000000000013c3a4 f0 d0 13 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
000000000013c3b4 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
000000000013c3c4 00 00 00 00 16 00 01 01 - 01 00 00 00 05 00 00 00
.................
000000000013c3d4 03 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
000000000013c3e4 00 00 00 00 00 00 00 00 - 10 23 2c 4e c2 ee c7 01
..........#,N....
000000000013c3f4 d0 d2 48 4e c2 ee c7 01 - 00 00 00 00 00 00 00 00
...HN............
000000000013c404 00 00 00 00 30 00 30 00 - 30 00 31 00 00 00 00 00
.....0.0.0.1.....

*----> Statusabbild für Threadkennung 0x600 <----*

eax=006cd9c8 ebx=013efe48 ecx=00000000 edx=00000000 esi=00000000
edi=7ffdf000
eip=7c91eb94 esp=013efe20 ebp=013efebc iopl=0 nv up ei pl zr
na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

Funktion: ntdll!KiFastSystemCallRet
7c91eb89 90 nop
7c91eb8a 90 nop
ntdll!KiFastSystemCall:
7c91eb8b 8bd4 mov edx,esp
7c91eb8d 0f34 sysenter
7c91eb8f 90 nop
7c91eb90 90 nop
7c91eb91 90 nop
7c91eb92 90 nop
7c91eb93 90 nop
ntdll!KiFastSystemCallRet:
7c91eb94 c3 ret
7c91eb95 8da42400000000 lea esp,[esp]
7c91eb9c 8d642400 lea esp,[esp]
7c91eba0 90 nop
7c91eba1 90 nop
7c91eba2 90 nop
7c91eba3 90 nop
7c91eba4 90 nop
ntdll!KiIntSystemCall:
7c91eba5 8d542408 lea edx,[esp+0x8]
7c91eba9 cd2e int 2e

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export
symbols for C:\WINDOWS\system32\USER32.dll -
WARNING: Stack unwind information not available. Following frames may
be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export
symbols for C:\Programme\Gemeinsame Dateien\Symantec
Shared\AppCore\AppMgr32.dll -
ChildEBP RetAddr Args to Child
013efebc 7e3695e9 00000002 013efee4 00000000 ntdll!KiFastSystemCallRet
013eff18 7e369698 00000001 013eff88 00007530
USER32!GetLastInputInfo+0x105
013eff34 6fb21615 00000001 013eff88 00000000
USER32!MsgWaitForMultipleObjects+0x1f
00000000 00000000 00000000 00000000 00000000 AppMgr32+0x1615

*----> Raw Stack Dump <----*
00000000013efe20 ab e9 91 7c e2 94 80 7c - 02 00 00 00 48 fe 3e 01
....|...|....H.>.
00000000013efe30 01 00 00 00 00 00 00 00 - 7c fe 3e 01 00 00 00 00
.........|.>.....
00000000013efe40 02 00 00 00 00 00 00 00 - fc 01 00 00 08 02 00 00
.................
00000000013efe50 70 05 92 7c 48 00 00 00 - 6d 05 92 7c 8a 21 34 7c
p..|H...m..|.!4|
00000000013efe60 00 00 04 01 00 00 00 00 - 14 00 00 00 01 00 00 00
.................
00000000013efe70 00 00 00 00 00 00 00 00 - 10 00 00 00 00 5d 1e ee
..............]..
00000000013efe80 ff ff ff ff 70 05 92 7c - 00 f0 fd 7f 00 c0 fd 7f
.....p..|........
00000000013efe90 00 00 00 00 7c fe 3e 01 - 48 fe 3e 01 f8 fd 3e 01
.....|.>.H.>...>.
00000000013efea0 02 00 00 00 3c fe 3e 01 - 18 ee 91 7c a4 ff 3e 01
.....<.>....|..>.
00000000013efeb0 a8 9a 83 7c d8 95 80 7c - 00 00 00 00 18 ff 3e 01
....|...|......>.
00000000013efec0 e9 95 36 7e 02 00 00 00 - e4 fe 3e 01 00 00 00 00
...6~......>.....
00000000013efed0 30 75 00 00 00 00 00 00 - 9e a8 00 68 0d f2 c7 01
0u.........h....
00000000013efee0 00 00 00 00 fc 01 00 00 - 08 02 00 00 fc 7f 04 01
.................
00000000013efef0 00 00 00 00 00 5e b2 6f - d8 74 04 01 1a a0 b2 6f
......^.o.t.....o
00000000013eff00 00 73 04 01 28 c3 b4 6f - 00 00 00 00 00 00 00 00
..s..(..o........
00000000013eff10 00 c0 fd 7f 08 02 00 00 - 34 ff 3e 01 98 96 36 7e
.........4.>...6~
00000000013eff20 01 00 00 00 88 ff 3e 01 - 30 75 00 00 ff 04 00 00
.......>.0u......
00000000013eff30 e4 fe 3e 01 00 00 00 00 - 15 16 b2 6f 01 00 00 00
...>........o....
00000000013eff40 88 ff 3e 01 00 00 00 00 - 30 75 00 00 ff 04 00 00
...>.....0u......
00000000013eff50 02 01 00 00 28 c3 b4 6f - b0 ff 3e 01 00 00 00 00
.....(..o..>.....

*----> Statusabbild für Threadkennung 0x1740 <----*

eax=00000102 ebx=00000000 ecx=014efe1c edx=7c91eb94 esi=00153008
edi=001530ac
eip=7c91eb94 esp=014efe1c ebp=014eff80 iopl=0 nv up ei pl zr
na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

Funktion: ntdll!KiFastSystemCallRet
7c91eb89 90 nop
7c91eb8a 90 nop
ntdll!KiFastSystemCall:
7c91eb8b 8bd4 mov edx,esp
7c91eb8d 0f34 sysenter
7c91eb8f 90 nop
7c91eb90 90 nop
7c91eb91 90 nop
7c91eb92 90 nop
7c91eb93 90 nop
ntdll!KiFastSystemCallRet:
7c91eb94 c3 ret
7c91eb95 8da42400000000 lea esp,[esp]
7c91eb9c 8d642400 lea esp,[esp]
7c91eba0 90 nop
7c91eba1 90 nop
7c91eba2 90 nop
7c91eba3 90 nop
7c91eba4 90 nop
ntdll!KiIntSystemCall:
7c91eba5 8d542408 lea edx,[esp+0x8]
7c91eba9 cd2e int 2e

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export
symbols for C:\WINDOWS\system32\RPCRT4.dll -
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
014eff80 77e56c23 014effa8 77e56a45 00153008 ntdll!KiFastSystemCallRet
014eff88 77e56a45 00153008 00000000 013ef96c
RPCRT4!I_RpcBCacheFree+0x5eb
014effa8 77e56c0b 0015bad0 014effec 7c80b683
RPCRT4!I_RpcBCacheFree+0x40d
014effb4 7c80b683 0017c448 00000000 013ef96c
RPCRT4!I_RpcBCacheFree+0x5d3
014effec 00000000 77e56bf1 0017c448 00000000
kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
00000000014efe1c 99 e3 91 7c 03 67 e5 77 - 3c 02 00 00 70 ff 4e 01
....|.g.w<...p.N.
00000000014efe2c 00 00 00 00 18 68 18 00 - 4c ff 4e 01 34 00 4c 00
......h..L.N.4.L.
00000000014efe3c 00 00 00 00 f4 07 00 00 - cc 15 00 00 b8 62 37 01
..............b7.
00000000014efe4c 00 00 00 00 02 9d 5d f7 - 01 00 ff ff 31 30 5c f7
.......].....10\.
00000000014efe5c d9 13 4e 80 70 87 75 86 - 08 40 c0 81 08 40 c0 81
...N.p.u..@...@..
00000000014efe6c 9e 00 69 f7 01 00 00 00 - 00 00 00 00 00 00 00 00
...i.............
00000000014efe7c 00 00 00 00 00 00 00 00 - 78 01 15 00 00 00 00 00
.........x.......
00000000014efe8c 05 00 00 00 42 85 0f 07 - 96 6e 64 86 94 6e 21 92
.....B....nd..n!.
00000000014efe9c d6 4c f9 a3 09 30 00 00 - e8 0b 00 00 a5 c2 3b 61
..L...0........;a
00000000014efeac 78 12 bc b5 00 00 00 00 - 80 cb e0 85 50 51 50 c0
x...........PQP.
00000000014efebc 00 30 50 c0 57 02 00 00 - ad 06 00 00 50 51 50 c0
..0P.W.......PQP.
00000000014efecc 00 40 70 c0 00 30 50 c0 - 18 c2 d1 81 08 00 00 00
[email protected].........
00000000014efedc 00 60 70 c0 00 40 70 c0 - 9c 36 50 c0 00 30 50 c0
..`[email protected].
00000000014efeec 18 c2 d1 81 1f 00 00 00 - 40 b5 af f7 0d ca 4d 80
[email protected].
00000000014efefc ff ff ff ff 46 02 00 00 - 4d c8 4d 80 28 7c fa a7
.....F...M.M.(|..
00000000014eff0c 98 56 ac 83 20 b1 af f7 - 34 58 ac 83 e8 1b 4e 80
..V.. ...4X....N.
00000000014eff1c 08 57 ac 83 98 56 ac 83 - 1e 1c 4e 80 04 58 ac 83
..W...V....N..X..
00000000014eff2c 98 56 ac 83 80 ff 4e 01 - 99 66 e5 77 4c ff 4e 01
..V....N..f.wL.N.
00000000014eff3c a9 66 e5 77 ed 10 91 7c - 38 bb 17 00 48 c4 17 00
..f.w...|8...H...
00000000014eff4c 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff
.../M.....]......

*----> Statusabbild für Threadkennung 0x105c <----*

eax=00181000 ebx=00007530 ecx=015efc40 edx=00001000 esi=00000000
edi=015eff50
eip=7c91eb94 esp=015eff20 ebp=015eff78 iopl=0 nv up ei pl nz
na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000206

Funktion: ntdll!KiFastSystemCallRet
7c91eb89 90 nop
7c91eb8a 90 nop
ntdll!KiFastSystemCall:
7c91eb8b 8bd4 mov edx,esp
7c91eb8d 0f34 sysenter
7c91eb8f 90 nop
7c91eb90 90 nop
7c91eb91 90 nop
7c91eb92 90 nop
7c91eb93 90 nop
ntdll!KiFastSystemCallRet:
7c91eb94 c3 ret
7c91eb95 8da42400000000 lea esp,[esp]
7c91eb9c 8d642400 lea esp,[esp]
7c91eba0 90 nop
7c91eba1 90 nop
7c91eba2 90 nop
7c91eba3 90 nop
7c91eba4 90 nop
ntdll!KiIntSystemCall:
7c91eba5 8d542408 lea edx,[esp+0x8]
7c91eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export
symbols for C:\WINDOWS\system32\ole32.dll -
ChildEBP RetAddr Args to Child
015eff78 7c802451 0000ea60 00000000 015effb4 ntdll!KiFastSystemCallRet
015eff88 774ce31d 0000ea60 0017b400 774ce3dc kernel32!Sleep+0xf
015effb4 7c80b683 0017b400 00000000 0017fb58
ole32!StringFromGUID2+0x51b
015effec 00000000 774ce429 0017b400 00000000
kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
00000000015eff20 5c d8 91 7c ed 23 80 7c - 00 00 00 00 50 ff 5e 01
\..|.#.|....P.^.
00000000015eff30 40 25 80 7c f8 6d 5d 77 - 30 75 00 00 14 00 00 00
@%.|.m]w0u......
00000000015eff40 01 00 00 00 00 00 00 00 - 00 00 00 00 10 00 00 00
.................
00000000015eff50 00 ba 3c dc ff ff ff ff - 00 d1 4b 77 50 ff 5e 01
...<.......KwP.^.
00000000015eff60 30 ff 5e 01 28 0b 18 00 - dc ff 5e 01 a8 9a 83 7c
0.^.(.....^....|
00000000015eff70 58 24 80 7c 00 00 00 00 - 88 ff 5e 01 51 24 80 7c
X$.|......^.Q$.|
00000000015eff80 60 ea 00 00 00 00 00 00 - b4 ff 5e 01 1d e3 4c 77
`.........^...Lw
00000000015eff90 60 ea 00 00 00 b4 17 00 - dc e3 4c 77 00 00 00 00
`.........Lw....
00000000015effa0 00 00 00 00 00 b4 17 00 - 00 00 4b 77 44 e4 4c 77
...........KwD.Lw
00000000015effb0 58 fb 17 00 ec ff 5e 01 - 83 b6 80 7c 00 b4 17 00
X.....^....|....
00000000015effc0 00 00 00 00 58 fb 17 00 - 00 b4 17 00 00 a0 fd 7f
.....X...........
00000000015effd0 00 c6 7b 86 c0 ff 5e 01 - 40 79 f1 81 ff ff ff ff
...{...^.@y......
00000000015effe0 a8 9a 83 7c 90 b6 80 7c - 00 00 00 00 00 00 00 00
....|...|........
00000000015efff0 00 00 00 00 29 e4 4c 77 - 00 b4 17 00 00 00 00 00
.....).Lw........
00000000015f0000 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
00000000015f0010 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
00000000015f0020 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
00000000015f0030 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
00000000015f0040 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
00000000015f0050 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................

*----> Statusabbild für Threadkennung 0x1770 <----*

eax=00000102 ebx=00000000 ecx=016efe1c edx=7c91eb94 esi=00153008
edi=001530ac
eip=7c91eb94 esp=016efe1c ebp=016eff80 iopl=0 nv up ei pl zr
na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

Funktion: ntdll!KiFastSystemCallRet
7c91eb89 90 nop
7c91eb8a 90 nop
ntdll!KiFastSystemCall:
7c91eb8b 8bd4 mov edx,esp
7c91eb8d 0f34 sysenter
7c91eb8f 90 nop
7c91eb90 90 nop
7c91eb91 90 nop
7c91eb92 90 nop
7c91eb93 90 nop
ntdll!KiFastSystemCallRet:
7c91eb94 c3 ret
7c91eb95 8da42400000000 lea esp,[esp]
7c91eb9c 8d642400 lea esp,[esp]
7c91eba0 90 nop
7c91eba1 90 nop
7c91eba2 90 nop
7c91eba3 90 nop
7c91eba4 90 nop
ntdll!KiIntSystemCall:
7c91eba5 8d542408 lea edx,[esp+0x8]
7c91eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
016eff80 77e56c23 016effa8 77e56a45 00153008 ntdll!KiFastSystemCallRet
016eff88 77e56a45 00153008 100092b8 00e520b0
RPCRT4!I_RpcBCacheFree+0x5eb
016effa8 77e56c0b 0015bad0 016effec 7c80b683
RPCRT4!I_RpcBCacheFree+0x40d
016effb4 7c80b683 00182598 100092b8 00e520b0
RPCRT4!I_RpcBCacheFree+0x5d3
016effec 00000000 77e56bf1 00182598 00000000
kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
00000000016efe1c 99 e3 91 7c 03 67 e5 77 - 3c 02 00 00 70 ff 6e 01
....|.g.w<...p.n.
00000000016efe2c 00 00 00 00 f0 77 18 00 - 4c ff 6e 01 34 00 4c 00
......w..L.n.4.L.
00000000016efe3c 00 00 00 00 f4 07 00 00 - cc 15 00 00 b9 62 37 01
..............b7.
00000000016efe4c 00 00 00 00 02 ff ff ff - 01 00 ff ff ff ff ff ff
.................
00000000016efe5c ff ff ff ff ff ff ff ff - ff ff ff ff ff ff ff ff
.................
00000000016efe6c ff ff ff ff 01 00 00 00 - 00 00 00 00 00 00 00 00
.................
00000000016efe7c 00 00 00 00 ff ff ff ff - ff ff ff ff ff ff ff ff
.................
00000000016efe8c ff ff ff ff ff ff ff ff - ff ff ff ff ff ff ff ff
.................
00000000016efe9c ff ff ff ff 43 0d 70 80 - 28 4c d0 a7 27 04 70 80
.....C.p.(L..'.p.
00000000016efeac 00 0d db ba 00 00 00 00 - ff ff ff ff ff ff ff ff
.................
00000000016efebc ff ff ff ff ff ff ff ff - ff ff ff ff ff ff ff ff
.................
00000000016efecc ff ff ff ff ff ff ff ff - ff ff ff ff ff ff ff ff
.................
00000000016efedc ff ff ff ff 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
00000000016efeec ff ff ff ff ff ff ff ff - 40 f5 df ff 00 00 00 00
.........@.......
00000000016efefc 10 04 70 80 a4 37 9e 83 - 28 4c d0 a7 00 00 00 00
...p..7..(L......
00000000016eff0c 27 04 70 80 08 00 00 00 - 46 02 00 00 e8 1b 4e 80
'.p.....F.....N.
00000000016eff1c 78 36 9e 83 08 36 9e 83 - 1e 1c 4e 80 74 37 9e 83
x6...6....N.t7..
00000000016eff2c 08 36 9e 83 80 ff 6e 01 - 99 66 e5 77 4c ff 6e 01
..6....n..f.wL.n.
00000000016eff3c a9 66 e5 77 ed 10 91 7c - f8 24 18 00 98 25 18 00
..f.w...|.$...%..
00000000016eff4c 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff
.../M.....]......

*----> Statusabbild für Threadkennung 0x1200 <----*

eax=00186000 ebx=00000000 ecx=017efc40 edx=00001000 esi=7c98c0d8
edi=00000000
eip=7c91eb94 esp=017efe18 ebp=017efea0 iopl=0 nv up ei pl zr
na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

Funktion: ntdll!KiFastSystemCallRet
7c91eb89 90 nop
7c91eb8a 90 nop
ntdll!KiFastSystemCall:
7c91eb8b 8bd4 mov edx,esp
7c91eb8d 0f34 sysenter
7c91eb8f 90 nop
7c91eb90 90 nop
7c91eb91 90 nop
7c91eb92 90 nop
7c91eb93 90 nop
ntdll!KiFastSystemCallRet:
7c91eb94 c3 ret
7c91eb95 8da42400000000 lea esp,[esp]
7c91eb9c 8d642400 lea esp,[esp]
7c91eba0 90 nop
7c91eba1 90 nop
7c91eba2 90 nop
7c91eba3 90 nop
7c91eba4 90 nop
ntdll!KiIntSystemCall:
7c91eba5 8d542408 lea edx,[esp+0x8]
7c91eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
017efea0 7c91104b 0198c0d8 7c927332 7c98c0d8 ntdll!KiFastSystemCallRet
017eff94 7c80c186 774b0000 017effb4 774ce45d
ntdll!RtlEnterCriticalSection+0x46
017effa0 774ce45d 774b0000 00000000 006e0049
kernel32!FreeLibraryAndExitThread+0x16
017effb4 7c80b683 00180988 005c007d 006e0049
ole32!StringFromGUID2+0x65b
017effec 00000000 774ce429 00180988 00000000
kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
00000000017efe18 c0 e9 91 7c 1b 90 92 7c - c8 01 00 00 00 00 00 00
....|...|........
00000000017efe28 00 00 00 00 7d 00 5c 00 - 00 00 4b 77 00 00 00 00
.....}.\...Kw....
00000000017efe38 5c f1 4d 77 28 d3 01 00 - 0e 00 00 00 a0 fd 7e 01
\.Mw(.........~.
00000000017efe48 0a d2 4c 77 68 94 5d 77 - d7 d1 4c 77 68 94 5d 77
...Lwh.]w..Lwh.]w
00000000017efe58 78 01 15 00 20 06 00 00 - 78 fe 7e 01 ec d2 4c 77
x... ...x.~...Lw
00000000017efe68 48 72 5d 77 18 c1 15 00 - 60 94 5d 77 18 c1 15 00
Hr]w....`.]w....
00000000017efe78 88 fe 7e 01 81 f8 4d 77 - 18 c1 15 00 00 00 15 00
...~...Mw........
00000000017efe88 00 00 00 00 4f f8 4d 77 - 01 00 00 00 00 00 00 00
.....O.Mw........
00000000017efe98 00 00 00 00 c8 01 00 00 - 94 ff 7e 01 4b 10 91 7c
...........~.K..|
00000000017efea8 d8 c0 98 01 32 73 92 7c - d8 c0 98 7c 7d 00 5c 00
.....2s.|...|}.\.
00000000017efeb8 00 00 4b 77 88 09 18 00 - 6d 05 92 7c 7d 00 5c 00
...Kw....m..|}.\.
00000000017efec8 88 09 18 00 88 09 18 00 - 00 00 00 00 78 02 00 00
.............x...
00000000017efed8 44 ff 7e 01 86 77 92 7c - a8 79 18 00 f8 6d 5d 77
D.~..w.|.y...m]w
00000000017efee8 00 00 00 00 e8 e0 16 00 - 00 00 00 00 98 81 15 00
.................
00000000017efef8 10 00 00 00 00 00 00 00 - 00 10 00 00 00 00 00 00
.................
00000000017eff08 1a 97 92 7c 40 25 80 7c - 88 09 18 00 30 75 00 00
....|@%.|....0u..
00000000017eff18 70 ce 17 00 01 00 00 00 - 20 00 00 00 00 00 00 00
p....... .......
00000000017eff28 00 80 fd 7f 8c ff 7e 01 - 1a 26 80 7c 48 ff 7e 01
.......~..&.|H.~.
00000000017eff38 f0 25 80 7c 40 25 80 7c - 88 09 18 00 30 75 00 00
..%.|@%.|....0u..
00000000017eff48 00 00 15 00 01 00 00 00 - 00 00 00 00 00 00 00 00
.................

*----> Statusabbild für Threadkennung 0x118c <----*

eax=6fb36296 ebx=0194fee4 ecx=6fb4c544 edx=7c9206eb esi=00000000
edi=7ffdf000
eip=7c91eb94 esp=0194febc ebp=0194ff58 iopl=0 nv up ei pl zr
na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

Funktion: ntdll!KiFastSystemCallRet
7c91eb89 90 nop
7c91eb8a 90 nop
ntdll!KiFastSystemCall:
7c91eb8b 8bd4 mov edx,esp
7c91eb8d 0f34 sysenter
7c91eb8f 90 nop
7c91eb90 90 nop
7c91eb91 90 nop
7c91eb92 90 nop
7c91eb93 90 nop
ntdll!KiFastSystemCallRet:
7c91eb94 c3 ret
7c91eb95 8da42400000000 lea esp,[esp]
7c91eb9c 8d642400 lea esp,[esp]
7c91eba0 90 nop
7c91eba1 90 nop
7c91eba2 90 nop
7c91eba3 90 nop
7c91eba4 90 nop
ntdll!KiIntSystemCall:
7c91eba5 8d542408 lea edx,[esp+0x8]
7c91eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
0194ff58 7c80a075 00000003 01045688 00000000 ntdll!KiFastSystemCallRet
0194ff74 6fb362e8 00000003 01045688 00000000
kernel32!WaitForMultipleObjects+0x18
0194ffb0 6fb3629f 7c80b683 01045408 ffffffff AppMgr32+0x162e8
0194ffec 00000000 6fb36296 01045408 00000000 AppMgr32+0x1629f

*----> Raw Stack Dump <----*
000000000194febc ab e9 91 7c e2 94 80 7c - 03 00 00 00 e4 fe 94 01
....|...|........
000000000194fecc 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
000000000194fedc 08 54 04 01 00 00 00 00 - a8 02 00 00 98 02 00 00
..T..............
000000000194feec 10 03 00 00 1b 90 92 7c - 1c 03 00 00 00 00 00 00
........|........
000000000194fefc 00 00 00 00 38 54 04 01 - 14 00 00 00 01 00 00 00
.....8T..........
000000000194ff0c 00 00 00 00 00 00 00 00 - 10 00 00 00 e8 1b 4e 80
...............N.
000000000194ff1c 70 b5 bd 85 00 b5 bd 85 - 00 f0 fd 7f 00 70 fd 7f
p............p..
000000000194ff2c 00 b5 bd 85 00 00 00 00 - e4 fe 94 01 00 00 00 00
.................
000000000194ff3c 03 00 00 00 d8 fe 94 01 - 00 70 fd 7f a4 ff 94 01
..........p......
000000000194ff4c a8 9a 83 7c d8 95 80 7c - 00 00 00 00 74 ff 94 01
....|...|....t...
000000000194ff5c 75 a0 80 7c 03 00 00 00 - 88 56 04 01 00 00 00 00
u..|.....V......
000000000194ff6c ff ff ff ff 00 00 00 00 - b0 ff 94 01 e8 62 b3 6f
..............b.o
000000000194ff7c 03 00 00 00 88 56 04 01 - 00 00 00 00 ff ff ff ff
......V..........
000000000194ff8c ff ff ff ff 08 54 04 01 - a0 0f 00 00 00 00 00 00
......T..........
000000000194ff9c 00 00 00 00 ae 62 b3 6f - dc ff 94 01 fa f5 b3 6f
......b.o.......o
000000000194ffac ff ff ff ff ec ff 94 01 - 9f 62 b3 6f 83 b6 80 7c
..........b.o...|
000000000194ffbc 08 54 04 01 ff ff ff ff - a0 0f 00 00 08 54 04 01
..T...........T..
000000000194ffcc 00 70 fd 7f 00 e6 7b 86 - c0 ff 94 01 a0 c1 74 83
..p....{.......t.
000000000194ffdc ff ff ff ff a8 9a 83 7c - 90 b6 80 7c 00 00 00 00
........|...|....
000000000194ffec 00 00 00 00 00 00 00 00 - 96 62 b3 6f 08 54 04 01
..........b.o.T..

*----> Statusabbild für Threadkennung 0x1470 <----*

eax=77e56bf1 ebx=00000000 ecx=01a9f600 edx=00000004 esi=001808d0
edi=00180974
eip=7c91eb94 esp=01c9fe1c ebp=01c9ff80 iopl=0 nv up ei pl zr
na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

Funktion: ntdll!KiFastSystemCallRet
7c91eb89 90 nop
7c91eb8a 90 nop
ntdll!KiFastSystemCall:
7c91eb8b 8bd4 mov edx,esp
7c91eb8d 0f34 sysenter
7c91eb8f 90 nop
7c91eb90 90 nop
7c91eb91 90 nop
7c91eb92 90 nop
7c91eb93 90 nop
ntdll!KiFastSystemCallRet:
7c91eb94 c3 ret
7c91eb95 8da42400000000 lea esp,[esp]
7c91eb9c 8d642400 lea esp,[esp]
7c91eba0 90 nop
7c91eba1 90 nop
7c91eba2 90 nop
7c91eba3 90 nop
7c91eba4 90 nop
ntdll!KiIntSystemCall:
7c91eba5 8d542408 lea edx,[esp+0x8]
7c91eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
01c9ff80 77e56c23 01c9ffa8 77e56a45 001808d0 ntdll!KiFastSystemCallRet
01c9ff88 77e56a45 001808d0 00000000 00000000
RPCRT4!I_RpcBCacheFree+0x5eb
01c9ffa8 77e56c0b 0015bad0 01c9ffec 7c80b683
RPCRT4!I_RpcBCacheFree+0x40d
01c9ffb4 7c80b683 0018f510 00000000 00000000
RPCRT4!I_RpcBCacheFree+0x5d3
01c9ffec 00000000 77e56bf1 0018f510 00000000
kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
0000000001c9fe1c 99 e3 91 7c 03 67 e5 77 - 68 03 00 00 70 ff c9 01
....|.g.wh...p...
0000000001c9fe2c 00 00 00 00 b8 fa 18 00 - 54 ff c9 01 00 00 00 00
.........T.......
0000000001c9fe3c 4c 32 be 85 00 00 00 00 - 50 32 be 85 01 00 00 00
L2......P2......
0000000001c9fe4c 46 00 00 00 50 8b 71 a7 - 17 69 c1 eb f0 a3 b9 85
F...P.q..i......
0000000001c9fe5c 06 02 00 00 25 9e 4d 80 - 01 00 00 00 01 00 00 00
.....%.M.........
0000000001c9fe6c f8 79 b1 85 45 5a 4e 80 - 20 5c 5a 83 f8 79 b1 85
..y..EZN. \Z..y..
0000000001c9fe7c 0a 00 00 00 f8 79 b1 85 - f8 79 b1 00 7c 8b 71 a7
......y...y..|.q.
0000000001c9fe8c 84 9f 4d 80 f8 79 b1 85 - 06 02 00 00 25 9e 4d 80
...M..y......%.M.
0000000001c9fe9c 01 00 00 00 a8 fc df ff - 20 f1 df ff 45 5a 4e 80
......... ...EZN.
0000000001c9feac 00 00 00 00 20 d0 6e 83 - 08 00 00 00 20 b1 af f7
..... .n..... ...
0000000001c9febc 20 d0 6e 00 b4 8b 71 a7 - 84 9f 4d 80 90 d0 6e 83
..n...q...M...n.
0000000001c9fecc 02 15 d8 85 00 00 00 00 - 38 b5 af f7 66 c7 4d 80
.........8...f.M.
0000000001c9fedc 02 00 00 00 c3 20 4e 80 - 20 b4 a9 85 08 26 54 83
...... N. ....&T.
0000000001c9feec 80 15 d8 85 1f 00 00 00 - 40 b5 af f7 0d ca 4d 80
[email protected].
0000000001c9fefc ff ff ff ff 46 02 00 00 - 4d c8 4d 80 28 8c 71 a7
.....F...M.M.(.q.
0000000001c9ff0c d0 db ab 83 20 b1 af f7 - 6c dd ab 83 e8 1b 4e 80
..... ...l.....N.
0000000001c9ff1c 40 dc ab 83 d0 db ab 83 - 1e 1c 4e 80 3c dd ab 83
@.........N.<...
0000000001c9ff2c d0 db ab 83 80 ff c9 01 - 99 66 e5 77 4c ff c9 01
..........f.wL...
0000000001c9ff3c a9 66 e5 77 ed 10 91 7c - 88 fa 18 00 10 f5 18 00
..f.w...|........
0000000001c9ff4c 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff
.../M.....]......

*----> Statusabbild für Threadkennung 0x430 <----*

eax=00000000 ebx=00000000 ecx=0290ff44 edx=7c91eb94 esi=00000000
edi=0290ff74
eip=7c91eb94 esp=0290ff44 ebp=0290ff9c iopl=0 nv up ei pl nz
na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000206

Funktion: ntdll!KiFastSystemCallRet
7c91eb89 90 nop
7c91eb8a 90 nop
ntdll!KiFastSystemCall:
7c91eb8b 8bd4 mov edx,esp
7c91eb8d 0f34 sysenter
7c91eb8f 90 nop
7c91eb90 90 nop
7c91eb91 90 nop
7c91eb92 90 nop
7c91eb93 90 nop
ntdll!KiFastSystemCallRet:
7c91eb94 c3 ret
7c91eb95 8da42400000000 lea esp,[esp]
7c91eb9c 8d642400 lea esp,[esp]
7c91eba0 90 nop
7c91eba1 90 nop
7c91eba2 90 nop
7c91eba3 90 nop
7c91eba4 90 nop
ntdll!KiIntSystemCall:
7c91eba5 8d542408 lea edx,[esp+0x8]
7c91eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export
symbols for C:\PROGRA~1\GEMEIN~1\MICROS~1\VBA\VBA6\VBE6.DLL -
ChildEBP RetAddr Args to Child
0290ff9c 7c802451 000000c8 00000000 0290ffec ntdll!KiFastSystemCallRet
0290ffac 650210b3 000000c8 7c80b683 00000000 kernel32!Sleep+0xf
0290ffec 00000000 650210a8 00000000 00000000
VBE6!rtcBstrFromFormatVar+0x687

*----> Raw Stack Dump <----*
000000000290ff44 5c d8 91 7c ed 23 80 7c - 00 00 00 00 74 ff 90 02
\..|.#.|....t...
000000000290ff54 2e 00 2e 00 00 00 6e 00 - 00 00 00 00 14 00 00 00
.......n.........
000000000290ff64 01 00 00 00 00 00 00 00 - 00 00 00 00 10 00 00 00
.................
000000000290ff74 80 7b e1 ff ff ff ff ff - 00 00 00 00 74 ff 90 02
..{..........t...
000000000290ff84 54 ff 90 02 01 4d 74 00 - dc ff 90 02 a8 9a 83 7c
T....Mt........|
000000000290ff94 58 24 80 7c 00 00 00 00 - ac ff 90 02 51 24 80 7c
X$.|........Q$.|
000000000290ffa4 c8 00 00 00 00 00 00 00 - ec ff 90 02 b3 10 02 65
................e
000000000290ffb4 c8 00 00 00 83 b6 80 7c - 00 00 00 00 2e 00 2e 00
........|........
000000000290ffc4 00 00 6e 00 00 00 00 00 - 00 d0 fd 7f 00 e6 7b 86
...n...........{.
000000000290ffd4 c0 ff 90 02 58 79 7b 83 - ff ff ff ff a8 9a 83 7c
.....Xy{........|
000000000290ffe4 90 b6 80 7c 00 00 00 00 - 00 00 00 00 00 00 00 00
....|............
000000000290fff4 a8 10 02 65 00 00 00 00 - 00 00 00 00 00 00 00 00
....e............
0000000002910004 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002910014 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002910024 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002910034 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002910044 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002910054 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002910064 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002910074 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................

*----> Statusabbild für Threadkennung 0x744 <----*

eax=00000000 ebx=00000000 ecx=02c0fe48 edx=010474d8 esi=7c98c0d8
edi=00000000
eip=7c91eb94 esp=02c0fe80 ebp=02c0ff08 iopl=0 nv up ei pl zr
na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

Funktion: ntdll!KiFastSystemCallRet
7c91eb89 90 nop
7c91eb8a 90 nop
ntdll!KiFastSystemCall:
7c91eb8b 8bd4 mov edx,esp
7c91eb8d 0f34 sysenter
7c91eb8f 90 nop
7c91eb90 90 nop
7c91eb91 90 nop
7c91eb92 90 nop
7c91eb93 90 nop
ntdll!KiFastSystemCallRet:
7c91eb94 c3 ret
7c91eb95 8da42400000000 lea esp,[esp]
7c91eb9c 8d642400 lea esp,[esp]
7c91eba0 90 nop
7c91eba1 90 nop
7c91eba2 90 nop
7c91eba3 90 nop
7c91eba4 90 nop
ntdll!KiIntSystemCall:
7c91eba5 8d542408 lea edx,[esp+0x8]
7c91eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
02c0ff08 7c91104b 0198c0d8 7c929148 7c98c0d8 ntdll!KiFastSystemCallRet
02c0ff7c 7c80c096 00000000 00000000 010462e0
ntdll!RtlEnterCriticalSection+0x46
02c0ffb4 7c80b689 00000000 00000000 00000000 kernel32!ExitThread+0x3e
02c0ffec 00000000 6fb37d45 010462e0 00000000
kernel32!GetModuleFileNameA+0x1ba

*----> Raw Stack Dump <----*
0000000002c0fe80 c0 e9 91 7c 1b 90 92 7c - c8 01 00 00 00 00 00 00
....|...|........
0000000002c0fe90 00 00 00 00 00 f0 fd 7f - 00 f0 fa 7f e0 62 04 01
..............b..
0000000002c0fea0 08 ad 04 01 a0 01 04 01 - 06 00 01 00 18 00 00 00
.................
0000000002c0feb0 0c fe c0 02 fc fe c0 02 - 00 ff c0 02 18 ee 91 7c
................|
0000000002c0fec0 70 05 92 7c ff ff ff ff - 6d 05 92 7c 8a 21 34 7c
p..|....m..|.!4|
0000000002c0fed0 00 00 04 01 00 00 04 01 - 8f 21 34 7c e4 75 04 01
..........!4|.u..
0000000002c0fee0 38 00 00 00 00 00 00 00 - 00 00 00 00 a0 ff 01 01
8...............
0000000002c0fef0 00 00 00 00 50 fe c0 02 - dc fe c0 02 44 ff c0 02
.....P.......D...
0000000002c0ff00 00 00 00 00 c8 01 00 00 - 7c ff c0 02 4b 10 91 7c
.........|...K..|
0000000002c0ff10 d8 c0 98 01 48 91 92 7c - d8 c0 98 7c 00 00 00 00
.....H..|...|....
0000000002c0ff20 00 f0 fa 7f e0 62 04 01 - e0 62 04 01 94 87 04 01
......b...b......
0000000002c0ff30 a0 ff c0 02 18 ee 91 7c - 70 05 92 7c 20 ff c0 02
........|p..| ...
0000000002c0ff40 6d 05 92 7c a0 ff c0 02 - 0d 24 34 7c a8 a3 37 7c
m..|.....$4|..7|
0000000002c0ff50 ff ff ff ff 8f 21 34 7c - 00 f0 fd 7f e0 62 04 01
......!4|.....b..
0000000002c0ff60 00 00 00 00 1c ff c0 02 - 3c e0 91 7c a4 ff c0 02
.........<..|....
0000000002c0ff70 18 ee 91 7c 68 91 92 7c - ff ff ff ff b4 ff c0 02
....|h..|........
0000000002c0ff80 96 c0 80 7c 00 00 00 00 - 00 00 00 00 e0 62 04 01
....|.........b..
0000000002c0ff90 00 00 00 00 00 f0 fa 7f - 00 00 00 00 84 ff c0 02
.................
0000000002c0ffa0 dc ff c0 02 dc ff c0 02 - a8 9a 83 7c c0 c0 80 7c
............|...|
0000000002c0ffb0 ff ff ff ff ec ff c0 02 - 89 b6 80 7c 00 00 00 00
............|....

*----> Statusabbild für Threadkennung 0xcfc <----*

eax=77e56bf1 ebx=00000000 ecx=00000002 edx=00000001 esi=001c5350
edi=001c53f4
eip=7c91eb94 esp=02d0fe1c ebp=02d0ff80 iopl=0 nv up ei pl zr
na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

Funktion: ntdll!KiFastSystemCallRet
7c91eb89 90 nop
7c91eb8a 90 nop
ntdll!KiFastSystemCall:
7c91eb8b 8bd4 mov edx,esp
7c91eb8d 0f34 sysenter
7c91eb8f 90 nop
7c91eb90 90 nop
7c91eb91 90 nop
7c91eb92 90 nop
7c91eb93 90 nop
ntdll!KiFastSystemCallRet:
7c91eb94 c3 ret
7c91eb95 8da42400000000 lea esp,[esp]
7c91eb9c 8d642400 lea esp,[esp]
7c91eba0 90 nop
7c91eba1 90 nop
7c91eba2 90 nop
7c91eba3 90 nop
7c91eba4 90 nop
ntdll!KiIntSystemCall:
7c91eba5 8d542408 lea edx,[esp+0x8]
7c91eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
02d0ff80 77e56c23 02d0ffa8 77e56a45 001c5350 ntdll!KiFastSystemCallRet
02d0ff88 77e56a45 001c5350 00000000 00690065
RPCRT4!I_RpcBCacheFree+0x5eb
02d0ffa8 77e56c0b 0015bad0 02d0ffec 7c80b683
RPCRT4!I_RpcBCacheFree+0x40d
02d0ffb4 7c80b683 001cada0 00000000 00690065
RPCRT4!I_RpcBCacheFree+0x5d3
02d0ffec 00000000 77e56bf1 001cada0 00000000
kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
0000000002d0fe1c 99 e3 91 7c 03 67 e5 77 - e4 03 00 00 70 ff d0 02
....|.g.w....p...
0000000002d0fe2c 00 00 00 00 f8 89 18 00 - 4c ff d0 02 34 4b 29 a7
.........L...4K).
0000000002d0fe3c 34 4b 29 a7 00 00 00 00 - 05 c6 4d 80 40 77 71 83
4K).......M.@wq.
0000000002d0fe4c 00 00 00 00 00 00 02 00 - 90 82 3a ae 00 00 02 00
...........:.....
0000000002d0fe5c 90 82 3a ae 0a 00 00 00 - 01 00 00 00 20 c0 d1 81
...:......... ...
0000000002d0fe6c e8 50 b3 83 ff ff ff ff - ff ff ff ff ff ff ff ff
..P..............
0000000002d0fe7c ff ff ff ff e8 0b 00 00 - f0 88 3a ae 01 00 00 00
...........:.....
0000000002d0fe8c 20 c0 d1 81 e8 50 b3 83 - ec c0 d1 81 a0 4c 29 a7
.....P.......L).
0000000002d0fe9c 13 01 57 80 00 00 30 c0 - 20 c0 d1 81 fe fd 56 80
...W...0. .....V.
0000000002d0feac 01 00 00 c0 70 4d a1 e1 - 50 4d a1 e1 30 00 00 00
.....pM..PM..0...
0000000002d0febc 2c 4c 29 a7 b8 4b 29 a7 - 1f 00 00 00 a8 9d 50 83
,L)..K).......P.
0000000002d0fecc 0d ca 4d 80 a0 4c 29 a7 - 46 02 00 00 4d c8 4d 80
...M..L).F...M.M.
0000000002d0fedc fc 4b 29 a7 a8 9d 50 83 - 20 f1 df ff 9c 9f 50 83
..K)...P. .....P.
0000000002d0feec e8 1b 4e 80 1f 00 00 00 - 40 b5 af f7 0d ca 4d 80
[email protected].
0000000002d0fefc ff ff ff ff 46 02 00 00 - 4d c8 4d 80 28 4c 29 a7
.....F...M.M.(L).
0000000002d0ff0c 20 50 ab 83 20 b1 af f7 - bc 51 ab 83 e8 1b 4e 80
P.. ....Q....N.
0000000002d0ff1c 90 50 ab 83 20 50 ab 83 - 1e 1c 4e 80 8c 51 ab 83
..P.. P....N..Q..
0000000002d0ff2c 20 50 ab 83 80 ff d0 02 - 99 66 e5 77 4c ff d0 02
P.......f.wL...
0000000002d0ff3c a9 66 e5 77 ed 10 91 7c - d0 94 1c 00 a0 ad 1c 00
..f.w...|........
0000000002d0ff4c 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff
.../M.....]......

*----> Statusabbild für Threadkennung 0x1198 <----*

eax=02a20000 ebx=02a0f154 ecx=00001000 edx=7c91eb94 esi=000003b4
edi=00000000
eip=7c91eb94 esp=02a0f138 ebp=02a0f86c iopl=0 nv up ei pl nz
na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000206

Funktion: ntdll!KiFastSystemCallRet
7c91eb89 90 nop
7c91eb8a 90 nop
ntdll!KiFastSystemCall:
7c91eb8b 8bd4 mov edx,esp
7c91eb8d 0f34 sysenter
7c91eb8f 90 nop
7c91eb90 90 nop
7c91eb91 90 nop
7c91eb92 90 nop
7c91eb93 90 nop
ntdll!KiFastSystemCallRet:
7c91eb94 c3 ret
7c91eb95 8da42400000000 lea esp,[esp]
7c91eb9c 8d642400 lea esp,[esp]
7c91eba0 90 nop
7c91eba1 90 nop
7c91eba2 90 nop
7c91eba3 90 nop
7c91eba4 90 nop
ntdll!KiIntSystemCall:
7c91eba5 8d542408 lea edx,[esp+0x8]
7c91eba9 cd2e int 2e

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export
symbols for C:\WINDOWS\system32\MSVCR71.dll -
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
02a0f86c 7c34c456 02a0f8b4 00000000 00000000 ntdll!KiFastSystemCallRet
02a0f888 7c34957c 00000000 02a0f8b4 7c34246e MSVCR71!XcptFilter+0x15f
02a0ffb4 7c80b683 01047170 ffffffff 0013d0f0 MSVCR71!endthreadex+0xb7
02a0ffec 00000000 7c3494f6 01047170 00000000
kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
0000000002a0f138 ab e9 91 7c 2c 37 86 7c - 02 00 00 00 70 f2 a0 02
....|,7.|....p...
0000000002a0f148 01 00 00 00 01 00 00 00 - 00 00 00 00 43 00 3a 00
.............C.:.
0000000002a0f158 5c 00 57 00 49 00 4e 00 - 44 00 4f 00 57 00 53 00
\.W.I.N.D.O.W.S.
0000000002a0f168 5c 00 73 00 79 00 73 00 - 74 00 65 00 6d 00 33 00
\.s.y.s.t.e.m.3.
0000000002a0f178 32 00 5c 00 64 00 72 00 - 77 00 74 00 73 00 6e 00
2.\.d.r.w.t.s.n.
0000000002a0f188 33 00 32 00 20 00 2d 00 - 70 00 20 00 33 00 30 00
3.2. .-.p. .3.0.
0000000002a0f198 34 00 38 00 20 00 2d 00 - 65 00 20 00 39 00 34 00
4.8. .-.e. .9.4.
0000000002a0f1a8 38 00 20 00 2d 00 67 00 - 00 00 00 00 00 00 00 00 8.
..-.g.........
0000000002a0f1b8 2e 00 00 00 00 00 00 00 - 00 00 00 00 6c f8 a0 02
.............l...
0000000002a0f1c8 66 35 86 7c 05 00 00 00 - 6c f8 a0 02 98 35 86 7c
f5.|....l....5.|
0000000002a0f1d8 c0 35 86 7c 05 00 00 c0 - 40 88 04 01 00 00 00 00
..5.|....@.......
0000000002a0f1e8 44 00 00 00 00 00 00 00 - d0 37 86 7c 00 00 00 00
D........7.|....
0000000002a0f1f8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002a0f208 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002a0f218 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002a0f228 00 00 00 00 d8 c0 98 7c - 00 60 fd 7f 00 60 fd 7f
........|.`...`..
0000000002a0f238 00 00 00 00 08 00 0a 00 - 88 3e 92 7c 1a 02 00 00
..........>.|....
0000000002a0f248 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002a0f258 54 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
T...............
0000000002a0f268 54 00 56 00 a0 f8 a0 02 - b4 03 00 00 cc 03 00 00
T.V.............

*----> Statusabbild für Threadkennung 0x16a0 <----*

eax=00000000 ebx=00000000 ecx=00000002 edx=00000003 esi=7c98c0d8
edi=00000000
eip=7c91eb94 esp=02a2fc10 ebp=02a2fc98 iopl=0 nv up ei pl zr
na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

Funktion: ntdll!KiFastSystemCallRet
7c91eb89 90 nop
7c91eb8a 90 nop
ntdll!KiFastSystemCall:
7c91eb8b 8bd4 mov edx,esp
7c91eb8d 0f34 sysenter
7c91eb8f 90 nop
7c91eb90 90 nop
7c91eb91 90 nop
7c91eb92 90 nop
7c91eb93 90 nop
ntdll!KiFastSystemCallRet:
7c91eb94 c3 ret
7c91eb95 8da42400000000 lea esp,[esp]
7c91eb9c 8d642400 lea esp,[esp]
7c91eba0 90 nop
7c91eba1 90 nop
7c91eba2 90 nop
7c91eba3 90 nop
7c91eba4 90 nop
ntdll!KiIntSystemCall:
7c91eba5 8d542408 lea edx,[esp+0x8]
7c91eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
02a2fc98 7c91104b 0198c0d8 7c937357 7c98c0d8 ntdll!KiFastSystemCallRet
02a2fd18 7c91eac7 02a2fd2c 7c910000 00000000
ntdll!RtlEnterCriticalSection+0x46
00000000 00000000 00000000 00000000 00000000
ntdll!KiUserApcDispatcher+0x7

*----> Raw Stack Dump <----*
0000000002a2fc10 c0 e9 91 7c 1b 90 92 7c - c8 01 00 00 00 00 00 00
....|...|........
0000000002a2fc20 00 00 00 00 00 50 fd 7f - 00 f0 fd 7f 00 00 00 00
......P..........
0000000002a2fc30 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002a2fc40 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002a2fc50 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002a2fc60 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002a2fc70 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002a2fc80 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002a2fc90 00 00 00 00 c8 01 00 00 - 18 fd a2 02 4b 10 91 7c
.............K..|
0000000002a2fca0 d8 c0 98 01 57 73 93 7c - d8 c0 98 7c 2c fd a2 02
.....Ws.|...|,...
0000000002a2fcb0 04 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002a2fcc0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002a2fcd0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002a2fce0 00 00 00 00 00 00 00 00 - 00 50 fd 7f 00 00 00 00
..........P......
0000000002a2fcf0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002a2fd00 ac fc a2 02 00 00 00 00 - ff ff ff ff 18 ee 91 7c
................|
0000000002a2fd10 00 8e 92 7c ff ff ff ff - 00 00 00 00 c7 ea 91 7c
....|...........|
0000000002a2fd20 2c fd a2 02 00 00 91 7c - 00 00 00 00 17 00 01 00
,......|........
0000000002a2fd30 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002a2fd40 00 00 00 00 00 00 00 00 - b6 17 4e 80 30 c8 c2 81
...........N.0...

*----> Statusabbild für Threadkennung 0x1418 <----*

eax=77e56bf1 ebx=00000000 ecx=7c98c0d8 edx=7c929b3f esi=7c98c0d8
edi=00000000
eip=7c91eb94 esp=02e0fc14 ebp=02e0fc9c iopl=0 nv up ei pl zr
na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

Funktion: ntdll!KiFastSystemCallRet
7c91eb89 90 nop
7c91eb8a 90 nop
ntdll!KiFastSystemCall:
7c91eb8b 8bd4 mov edx,esp
7c91eb8d 0f34 sysenter
7c91eb8f 90 nop
7c91eb90 90 nop
7c91eb91 90 nop
7c91eb92 90 nop
7c91eb93 90 nop
ntdll!KiFastSystemCallRet:
7c91eb94 c3 ret
7c91eb95 8da42400000000 lea esp,[esp]
7c91eb9c 8d642400 lea esp,[esp]
7c91eba0 90 nop
7c91eba1 90 nop
7c91eba2 90 nop
7c91eba3 90 nop
7c91eba4 90 nop
ntdll!KiIntSystemCall:
7c91eba5 8d542408 lea edx,[esp+0x8]
7c91eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
02e0fc9c 7c91104b 0198c0d8 7c937357 7c98c0d8 ntdll!KiFastSystemCallRet
02e0fd1c 7c91eac7 02e0fd30 7c910000 00000000
ntdll!RtlEnterCriticalSection+0x46
00000000 00000000 00000000 00000000 00000000
ntdll!KiUserApcDispatcher+0x7

*----> Raw Stack Dump <----*
0000000002e0fc14 c0 e9 91 7c 1b 90 92 7c - c8 01 00 00 00 00 00 00
....|...|........
0000000002e0fc24 00 00 00 00 00 d0 fa 7f - 00 f0 fd 7f 00 00 00 00
.................
0000000002e0fc34 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002e0fc44 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002e0fc54 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002e0fc64 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002e0fc74 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002e0fc84 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002e0fc94 00 00 00 00 c8 01 00 00 - 1c fd e0 02 4b 10 91 7c
.............K..|
0000000002e0fca4 d8 c0 98 01 57 73 93 7c - d8 c0 98 7c 30 fd e0 02
.....Ws.|...|0...
0000000002e0fcb4 c8 fa c9 01 78 b6 1c 00 - 00 00 00 00 00 00 00 00
.....x...........
0000000002e0fcc4 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002e0fcd4 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002e0fce4 00 00 00 00 00 00 00 00 - 00 d0 fa 7f 00 00 00 00
.................
0000000002e0fcf4 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002e0fd04 b0 fc e0 02 00 00 00 00 - ff ff ff ff 18 ee 91 7c
................|
0000000002e0fd14 00 8e 92 7c ff ff ff ff - 00 00 00 00 c7 ea 91 7c
....|...........|
0000000002e0fd24 30 fd e0 02 00 00 91 7c - 00 00 00 00 17 00 01 00
0......|........
0000000002e0fd34 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002e0fd44 00 00 00 00 00 00 00 00 - b6 17 4e 80 30 c8 c2 81
...........N.0...

*----> Statusabbild für Threadkennung 0x8b0 <----*

eax=77e56bf1 ebx=00000000 ecx=7c98c0d8 edx=7c929b3f esi=7c98c0d8
edi=00000000
eip=7c91eb94 esp=02f0fc14 ebp=02f0fc9c iopl=0 nv up ei pl zr
na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

Funktion: ntdll!KiFastSystemCallRet
7c91eb89 90 nop
7c91eb8a 90 nop
ntdll!KiFastSystemCall:
7c91eb8b 8bd4 mov edx,esp
7c91eb8d 0f34 sysenter
7c91eb8f 90 nop
7c91eb90 90 nop
7c91eb91 90 nop
7c91eb92 90 nop
7c91eb93 90 nop
ntdll!KiFastSystemCallRet:
7c91eb94 c3 ret
7c91eb95 8da42400000000 lea esp,[esp]
7c91eb9c 8d642400 lea esp,[esp]
7c91eba0 90 nop
7c91eba1 90 nop
7c91eba2 90 nop
7c91eba3 90 nop
7c91eba4 90 nop
ntdll!KiIntSystemCall:
7c91eba5 8d542408 lea edx,[esp+0x8]
7c91eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
02f0fc9c 7c91104b 0198c0d8 7c937357 7c98c0d8 ntdll!KiFastSystemCallRet
02f0fd1c 7c91eac7 02f0fd30 7c910000 00000000
ntdll!RtlEnterCriticalSection+0x46
00000000 00000000 00000000 00000000 00000000
ntdll!KiUserApcDispatcher+0x7

*----> Raw Stack Dump <----*
0000000002f0fc14 c0 e9 91 7c 1b 90 92 7c - c8 01 00 00 00 00 00 00
....|...|........
0000000002f0fc24 00 00 00 00 00 c0 fa 7f - 00 f0 fd 7f 00 00 00 00
.................
0000000002f0fc34 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002f0fc44 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002f0fc54 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002f0fc64 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002f0fc74 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002f0fc84 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002f0fc94 00 00 00 00 c8 01 00 00 - 1c fd f0 02 4b 10 91 7c
.............K..|
0000000002f0fca4 d8 c0 98 01 57 73 93 7c - d8 c0 98 7c 30 fd f0 02
.....Ws.|...|0...
0000000002f0fcb4 c8 fa d0 02 f0 ab 1c 00 - 00 00 00 00 00 00 00 00
.................
0000000002f0fcc4 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002f0fcd4 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002f0fce4 00 00 00 00 00 00 00 00 - 00 c0 fa 7f 00 00 00 00
.................
0000000002f0fcf4 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002f0fd04 b0 fc f0 02 00 00 00 00 - ff ff ff ff 18 ee 91 7c
................|
0000000002f0fd14 00 8e 92 7c ff ff ff ff - 00 00 00 00 c7 ea 91 7c
....|...........|
0000000002f0fd24 30 fd f0 02 00 00 91 7c - 00 00 00 00 17 00 01 00
0......|........
0000000002f0fd34 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000002f0fd44 00 00 00 00 00 00 00 00 - b6 17 4e 80 30 c8 c2 81
...........N.0...

Andreas Wizemann
 
D

Dave Peterson

I don't know anyone who can interpret Dr Watson dumps.

You may want to describe what you were doing when excel crashed.

And if it happens with all workbooks or just one (or some).

And what version of excel you're using.

Hello,
my EXECL stops working and i didn't know why !?
Can anybody help me.
<<snipped>>
 
A

Andreas.Wizemann

On Mon, 10 Sep 2007 05:58:55 -0500, Dave Peterson

I'm just starting EXECL.

It happens with ALL workbooks.

I'm using EXECL 2000 on WinXP.

And now i can not use EXECL anymore, as it always crashes !

I don't know anyone who can interpret Dr Watson dumps.

You may want to describe what you were doing when excel crashed.

And if it happens with all workbooks or just one (or some).

And what version of excel you're using.


<<snipped>>
Andreas Wizemann
 
D

Dave Peterson

Sometimes, the file that holds the customized toolbar gets corrupted.

Can you try this:
Close excel (if you have it open(!))
windows start button|Run
excel /safe

This starts excel in safe mode. Macros are disabled and your toolbar file isn't
loaded (along with addins and other startup files).

Does that work?

If yes:

Close excel
Windows start button|Search
look for *.xlb
in hidden folders, too

Rename them all to *.xlbOLD and restart excel to see if it helps.

If it doesn't help, rename them back to *.xlb.

If it does, delete those *.xlbOLD files and recreate any customized toolbars.

If it didn't work, then the next step will be doing some detective work.

Chip Pearson has some notes on how to diagnose startup errors:
http://www.cpearson.com/excel/StartupErrors.htm

And Jan Karel Pieterse has more notes:
http://www.jkp-ads.com/Articles/StartupProblems.asp
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top