IE crashes when I open windows media player

B

BWIL22

Win 2K IE ver 5.5 SP1
I do re-install of win2k - media player works (streaming radio staion
- kgsr.com) Sometimes hrs, sometimes days later it begins to crash
with dialog box: IE has generated errors and will close.

event viewer description: The application, iexplore.exe, generated an
application error The error occurred on 10/16/2003 @ 15:09:12.554 The
exception generated was c0000005 at address 4802F544 (<nosymbols>)

(abbreviated)log file contents: (really long)

Microsoft (R) Windows 2000 (TM) Version 5.00 DrWtsn32
Copyright (C) 1985-1999 Microsoft Corp. All rights reserved.



Application exception occurred:
App: iexplore.exe (pid=1488)
When: 10/16/2003 @ 13:43:28.327
Exception number: c0000005 (access violation)

*----> System Information <----*
Computer Name: B000802500F11
User Name: nbk941i
Number of Processors: 1
Processor Type: x86 Family 15 Model 1 Stepping 2
Windows 2000 Version: 5.0
Current Build: 2195
Service Pack: 3
Current Type: Uniprocessor Free
Registered Organization: Bank of America
Registered Owner: Bank of America

*----> Task List <----*
0 Idle.exe
8 System.exe
136 SMSS.exe
160 CSRSS.exe
180 WINLOGON.exe
208 SERVICES.exe
220 LSASS.exe
388 svchost.exe
420 spoolsv.exe
488 defwatch.exe
508 domtimec.exe
532 svchost.exe
580 rtvscan.exe
628 nvsvc32.exe
648 regsvc.exe
664 mstask.exe
712 WinMgmt.exe
756 MsPMSPSv.exe
932 MSGSYS.exe
1076 explorer.exe
1224 vptray.exe
1216 promon.exe
316 OUTLOOK.exe
608 MAPISP32.exe
452 omtsreco.exe
1444 sndvol32.exe
1080 pb70.exe
1524 agentsvr.exe
1488 IEXPLORE.exe
736 DRWTSN32.exe
0 _Total.exe

(00400000 - 00412000)
(77F80000 - 77FFB000)
(77E80000 - 77F31000)
(77E10000 - 77E6F000)
(77F40000 - 77F79000)
(70BD0000 - 70C1C000)
(77DB0000 - 77E0B000)
(77D30000 - 77D9D000)
(71500000 - 7161C000)
(78000000 - 78046000)
(71700000 - 7178A000)
(782F0000 - 78536000)
(77A50000 - 77B3A000)
(71110000 - 711D9000)
(775A0000 - 77626000)
(779B0000 - 77A4B000)
(71920000 - 7192B000)
(63000000 - 63079000)
(77530000 - 77552000)
(77840000 - 7787D000)
(770C0000 - 770E3000)
(10000000 - 100BC000)
(77880000 - 7790D000)
(77C10000 - 77C6D000)
(1A400000 - 1A472000)
(77820000 - 77827000)
(759B0000 - 759B6000)
(75050000 - 75058000)
(75030000 - 75043000)
(75020000 - 75028000)
(77440000 - 774B5000)
(77430000 - 77440000)
(76930000 - 7695B000)
(77920000 - 77943000)
(77570000 - 775A0000)
(774E0000 - 77512000)
(774C0000 - 774D1000)
(77830000 - 7783E000)
(75AB0000 - 75AB5000)
(75170000 - 751BF000)
(77BE0000 - 77BEF000)
(751C0000 - 751C6000)
(75150000 - 75160000)
(77950000 - 77978000)
(77980000 - 779A4000)
(01020000 - 01028000)
(76710000 - 76719000)
(76FA0000 - 76FAF000)
(773E0000 - 773F5000)
(76620000 - 76630000)
(75160000 - 7516C000)
(75210000 - 75225000)
(751D0000 - 75208000)
(718A0000 - 71902000)
(70420000 - 704A8000)
(74FD0000 - 74FED000)
(75010000 - 75017000)
(782C0000 - 782CC000)
(77340000 - 77353000)
(77520000 - 77525000)
(77320000 - 77337000)
(773B0000 - 773DE000)
(77380000 - 773A2000)
(77360000 - 77379000)
(777E0000 - 777E8000)
(777F0000 - 777F5000)
(70000000 - 70037000)
(71300000 - 71309000)
(012C0000 - 012C7000)
(6B700000 - 6B787000)
(01410000 - 016B3000)
(75E60000 - 75E7A000)
(75AC0000 - 75AE8000)
(72000000 - 72066000)
(77560000 - 77569000)
(77400000 - 77408000)
(77410000 - 77423000)
(75D40000 - 75D46000)
(69000000 - 6900C000)
(63700000 - 63716000)
(70F90000 - 70FCC000)
(77800000 - 7781E000)
(6B600000 - 6B66E000)
(038D0000 - 03A73000)
(76B30000 - 76B6D000)
(727F0000 - 727F9000)
(51000000 - 51044000)
(728A0000 - 728A6000)
(79170000 - 79191000)
(79410000 - 79422000)
(7C000000 - 7C054000)
(1D300000 - 1D3D0000)
(35500000 - 35620000)
(04990000 - 049A6000)
(35680000 - 3568F000)
(1FF00000 - 1FF7D000)
(41B00000 - 41B41000)
(48000000 - 4803F000)
(04A50000 - 04A57000)

State Dump for Thread Id 0x3f8

eax=000bfda8 ebx=00000000 ecx=00000200 edx=00000000 esi=0007ab58
edi=00000000
eip=77e58615 esp=0006dd48 ebp=0006dd8c iopl=0 nv up ei pl nz
na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000202


function: WaitMessage
77e5860a b836120000 mov eax,0x1236
77e5860f 8d542404 lea edx,[esp+0x4]
ss:00aeb31b=????????
77e58613 cd2e int 2e
77e58615 c3 ret

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0006DD8C 711219A5 00070110 0006EE88 0007A978 00000000
user32!WaitMessage
0006DE14 711218BF 0007A978 00000001 0007A978 00000000
BROWSEUI!Ordinal102
0006EE90 7151DC1B 0007A978 7151D997 0007A978 00000001
BROWSEUI!Ordinal102
0006FF00 004013B6 000728F2 00000001 00401A46 000728F2
shdocvw!Ordinal131
0006FF60 00401452 00400000 00000000 000728F2 00000001
iexplore!<nosymbols>
0006FFC0 77EA847C 00000000 00000000 7FFDF000 00000000
iexplore!<nosymbols>
0006FFF0 00000000 004013B9 00000000 000000C8 00000100
kernel32!ProcessIdToSessionId

*----> Raw Stack Dump <----*
0006dd48 49 1b 12 71 88 ee 06 00 - 78 a9 07 00 00 00 00 00
I..q....x.......
0006dd58 a8 01 03 00 0f 00 00 00 - 00 00 00 00 00 00 00 00
.................
0006dd68 23 eb 85 04 a9 01 00 00 - 06 02 00 00 00 00 00 00
#...............
0006dd78 02 00 00 00 58 ab 07 00 - 01 44 00 80 18 53 07 00
.....X....D...S..
0006dd88 00 00 00 00 14 de 06 00 - a5 19 12 71 10 01 07 00
............q....
0006dd98 88 ee 06 00 78 a9 07 00 - 00 00 00 00 00 00 00 00
.....x...........
0006dda8 e0 ff 06 00 e0 ff 06 00 - 00 de 06 00 1e 5b 11 71
..............[.q
0006ddb8 00 00 2f 78 0c 00 02 00 - 0b 01 09 00 60 00 00 00
.../x........`...
0006ddc8 03 00 00 00 04 00 00 00 - 0c 00 00 00 01 00 00 00
.................
0006ddd8 01 00 00 00 74 00 00 00 - 00 de 06 00 f3 55 12 71
.....t........U.q
0006dde8 f8 c2 18 71 0c 00 00 00 - be 55 12 71 f8 c2 18 71
....q.....U.q...q
0006ddf8 0c 00 00 00 98 dd 06 00 - 00 00 00 00 e0 ff 06 00
.................
0006de08 b1 8d 18 71 b8 4c 12 71 - 00 00 00 00 90 ee 06 00
....q.L.q........
0006de18 bf 18 12 71 78 a9 07 00 - 01 00 00 00 78 a9 07 00
....qx.......x...
0006de28 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0006de38 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0006de48 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0006de58 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0006de68 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0006de78 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................

State Dump for Thread Id 0x5ac

eax=778321fe ebx=00000004 ecx=7ffde000 edx=00000000 esi=77f837a7
edi=00000004
eip=77f837b2 esp=00fbfd24 ebp=00fbfd70 iopl=0 nv up ei pl zr
na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000246


function: NtWaitForMultipleObjects
77f837a7 b8e9000000 mov eax,0xe9
77f837ac 8d542404 lea edx,[esp+0x4]
ss:01a3d2f7=????????
77f837b0 cd2e int 2e
77f837b2 c21400 ret 0x14

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
00FBFD70 77EA9C13 00FBFD48 00000001 00000000 00000000
ntdll!NtWaitForMultipleObjects
00FBFFB4 77E8B2D8 00000005 000A0A6C 7FFDE000 000A3290
kernel32!WaitForMultipleObjects
00FBFFEC 00000000 778321FE 000A3290 00000000 00000001
kernel32!lstrcmpiW

*----> Raw Stack Dump <----*
00fbfd24 00 9d ea 77 04 00 00 00 - 48 fd fb 00 01 00 00 00
....w....H.......
00fbfd34 00 00 00 00 00 00 00 00 - 01 00 00 00 90 32 0a 00
..............2..
00fbfd44 01 00 00 00 c4 01 00 00 - c8 01 00 00 d8 01 00 00
.................
00fbfd54 14 03 00 00 60 d9 46 80 - 4a e7 49 80 00 00 00 00
.....`.F.J.I.....
00fbfd64 e8 69 78 e2 60 d9 46 80 - 00 00 00 00 b4 ff fb 00
..ix.`.F.........
00fbfd74 13 9c ea 77 48 fd fb 00 - 01 00 00 00 00 00 00 00
....wH...........
00fbfd84 00 00 00 00 00 00 00 00 - b2 22 83 77 04 00 00 00
..........".w....
00fbfd94 b0 fe fb 00 00 00 00 00 - ff ff ff ff 90 32 0a 00
..............2..
00fbfda4 00 e0 fd 7f 6c 0a 0a 00 - a6 cf 52 80 d8 7b c5 bc
.....l.....R..{..
00fbfdb4 c0 7a c5 bc 00 00 00 00 - 01 00 00 00 38 00 00 00
..z..........8...
00fbfdc4 23 00 00 00 23 00 00 00 - 6c 0a 0a 00 00 e0 fd 7f
#...#...l.......
00fbfdd4 90 32 0a 00 00 e0 fd 7f - 00 e0 fd 7f fe 21 83 77
..2...........!.w
00fbfde4 35 83 f8 77 50 b6 e8 77 - 1b 00 00 00 00 02 00 00
5..wP..w........
00fbfdf4 fc ff fb 00 23 00 00 00 - 01 40 26 81 40 c0 46 e1
.....#....@&[email protected].
00fbfe04 c0 00 00 00 78 ac 47 81 - 77 ed 00 00 28 73 a3 81
.....x.G.w...(s..
00fbfe14 00 07 00 00 ae cc 44 80 - 77 ed 00 00 28 73 a3 81
.......D.w...(s..
00fbfe24 77 ed 00 00 28 73 a3 81 - 01 42 fd 7f 0d 0d 00 00
w...(s...B......
00fbfe34 41 d6 44 80 0d 0d 00 00 - 50 14 56 81 00 40 fd 7f
A.D.....P.V..@..
00fbfe44 fc 07 30 c0 00 00 00 00 - 94 7b c5 bc 0d 0d 00 00
...0......{......
00fbfe54 74 7b c5 bc 00 00 00 00 - 01 00 00 00 00 00 00 00
t{..............

State Dump for Thread Id 0x568

eax=00000000 ebx=77f8377b ecx=00000101 edx=00000000 esi=00000000
edi=00000001
eip=77f83786 esp=0114facc ebp=0114fb04 iopl=0 nv up ei ng nz
na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000286


function: NtWaitForSingleObject
77f8377b b8ea000000 mov eax,0xea
77f83780 8d542404 lea edx,[esp+0x4]
ss:01bcd09f=????????
77f83784 cd2e int 2e
77f83786 c20c00 ret 0xc

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0114FB04 74FD7EE6 00000288 0000028C 00000001 00000004
ntdll!NtWaitForSingleObject
0114FBF0 75031DA9 00000001 0114FE84 0114FC7C 0114FD80
msafd!WSPSetSockOpt
0114FC54 63017912 00000001 0114FE84 0114FC7C 0114FD80 ws2_32!select
0114FFB0 630176D8 77E8B2D8 000AC750 7FFDE000 00000040
wininet!InternetSetStatusCallbackA
0114FFEC 00000000 00000000 00000000 00000000 00000000
wininet!InternetSetStatusCallbackA

*----> Raw Stack Dump <----*
0114facc 62 bb fd 74 88 02 00 00 - 01 00 00 00 f0 fa 14 01
b..t............
0114fadc 84 fe 14 01 78 fb 14 01 - 68 fb 14 01 01 00 00 00
.....x...h.......
0114faec e5 38 f8 77 c0 b4 b3 ff - ff ff ff ff 78 4e 09 00
..8.w........xN..
0114fafc 00 00 00 00 00 00 00 00 - f0 fb 14 01 e6 7e fd 74
..............~.t
0114fb0c 88 02 00 00 8c 02 00 00 - 01 00 00 00 04 00 00 00
.................
0114fb1c 80 fd 14 01 10 7e 0b 00 - 7c fc 14 01 00 00 00 00
......~..|.......
0114fb2c 00 00 00 00 80 0f 05 fd - ff ff ff ff 8c 02 00 00
.................
0114fb3c 88 02 00 00 00 00 00 00 - 00 00 07 00 90 fb 14 01
.................
0114fb4c 17 20 01 00 80 fb 14 01 - 10 00 00 00 00 00 00 00 .
...............
0114fb5c 06 00 00 00 00 00 00 00 - 00 00 00 00 80 0f 05 fd
.................
0114fb6c ff ff ff ff 01 00 00 00 - 00 4e 09 00 8c 02 00 00
..........N......
0114fb7c 19 00 00 00 30 00 00 00 - 8c 02 00 00 88 60 c1 70
.....0........`.p
0114fb8c 88 60 c1 70 dc fb 14 01 - 95 2b f8 77 08 36 f8 77
..`.p.....+.w.6.w
0114fb9c ff ff ff ff ec fb 14 01 - 36 91 e8 77 00 00 07 00
.........6..w....
0114fbac 78 4e 09 00 24 00 00 00 - 00 00 00 00 68 fb 14 01
xN..$.......h...
0114fbbc 2c 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00
,...............
0114fbcc 00 00 00 00 1c 00 00 00 - 84 fb 14 01 1c fb 14 01
.................
0114fbdc 24 fc 14 01 44 fc 14 01 - 36 df fd 74 78 30 fd 74
$...D...6..tx0.t
0114fbec ff ff ff ff 54 fc 14 01 - a9 1d 03 75 01 00 00 00
.....T......u....
0114fbfc 84 fe 14 01 7c fc 14 01 - 80 fd 14 01 90 ff 14 01
.....|...........

State Dump for Thread Id 0x5b8

eax=0118fe64 ebx=00000000 ecx=00071258 edx=00000000 esi=77f8377b
edi=0000014c
eip=77f83786 esp=0118ea0c ebp=0118ea30 iopl=0 nv up ei pl zr
na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000246


function: NtWaitForSingleObject
77f8377b b8ea000000 mov eax,0xea
77f83780 8d542404 lea edx,[esp+0x4]
ss:01c0bfdf=????????
77f83784 cd2e int 2e
77f83786 c20c00 ret 0xc

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0118EA30 77E8B32B 0000014C FFFFFFFF 00000000 630023B5
ntdll!NtWaitForSingleObject
0118EA68 63003BED 00000002 63066D90 6300B9FE 00000002
kernel32!WaitForSingleObject
0118EAE0 6301CEB6 024B6408 00119B50 0118EB00 00000002
wininet!InternetQueryOptionA
0118FF10 630090F2 024DC928 024B6408 024DC858 00000001
wininet!InternetSetCookieA
0118FF30 63008C1C 00000000 000B60A8 024DC858 6300849B
wininet!HttpQueryInfoA
0118FF84 70BDAF87 00000000 00070178 70BD0000 00000000
wininet!HttpQueryInfoA
0118FFAC 70BDAED7 00000000 77E8B2D8 00000000 00070178
SHLWAPI!PathRemoveFileSpecW
0118FFEC 00000000 00000000 00000000 00000000 00000000
SHLWAPI!PathRemoveFileSpecW

*----> Raw Stack Dump <----*
0118ea0c 35 9b ea 77 4c 01 00 00 - 00 00 00 00 00 00 00 00
5..wL...........
0118ea1c 64 ea 18 01 f8 7b 08 00 - 20 90 08 00 f8 7b 08 00 d....{..
.....{..
0118ea2c f8 7b 08 00 68 ea 18 01 - 2b b3 e8 77 4c 01 00 00
..{..h...+..wL...
0118ea3c ff ff ff ff 00 00 00 00 - b5 23 00 63 4c 01 00 00
..........#.cL...
0118ea4c ff ff ff ff 00 00 00 00 - f8 7b 08 00 3f 24 00 63
..........{..?$.c
0118ea5c 64 ea 18 01 e8 00 00 00 - 00 00 00 00 e0 ea 18 01
d...............
0118ea6c ed 3b 00 63 02 00 00 00 - 90 6d 06 63 fe b9 00 63
..;.c.....m.c...c
0118ea7c 02 00 00 00 90 6d 06 63 - ba b9 00 63 02 00 00 00
......m.c...c....
0118ea8c 90 6d 06 63 20 90 08 00 - 8c b9 00 63 60 6d 06 63 .m.c
.......c`m.c
0118ea9c 73 c8 01 63 01 00 00 00 - 08 64 4b 02 28 c9 4d 02
s..c.....dK.(.M.
0118eaac ff ff ff ff ff ff ff 7f - d0 be db 01 0d 94 c3 01
.................
0118eabc 00 00 00 00 02 00 00 00 - 01 00 00 00 0a eb 18 01
.................
0118eacc 00 eb 18 01 a0 be 0a 00 - 08 20 10 00 3f eb 18 01 .........
...?...
0118eadc 2a eb 18 01 10 ff 18 01 - b6 ce 01 63 08 64 4b 02
*..........c.dK.
0118eaec 50 9b 11 00 00 eb 18 01 - 02 00 00 00 58 c8 4d 02
P...........X.M.
0118eafc 08 64 4b 02 72 37 44 30 - 41 46 31 44 44 00 42 44
..dK.r7D0AF1DD.BD
0118eb0c 73 76 4d 6a 6b 30 34 6d - 40 69 33 76 57 77 73 42
svMjk04m@i3vWwsB
0118eb1c 6b 2b 2b 3a 00 20 64 6f - 6d 61 69 6e 00 2e 6d 6f k++:.
domain..mo
0118eb2c 63 2e 6b 63 69 6c 63 65 - 75 6c 61 76 00 20 70 61
c.kcilceulav. pa
0118eb3c 74 68 00 2f 00 00 00 00 - 03 00 00 00 98 eb 18 01
th./............

State Dump for Thread Id 0x648

eax=012de6c0 ebx=011cff88 ecx=012de69c edx=00000000 esi=77f8377b
edi=0000026c
eip=77f83786 esp=011cff6c ebp=011cff90 iopl=0 nv up ei ng nz
ac po cy
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000297


function: NtWaitForSingleObject
77f8377b b8ea000000 mov eax,0xea
77f83780 8d542404 lea edx,[esp+0x4]
ss:01c4d53f=????????
77f83784 cd2e int 2e
77f83786 c20c00 ret 0xc

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
011CFF90 77E8B32B 0000026C 00007530 00000000 63045F68
ntdll!NtWaitForSingleObject
011CFFEC 00000000 00000000 00000000 00000000 00000000
kernel32!WaitForSingleObject

State Dump for Thread Id 0x518

eax=00000000 ebx=00050003 ecx=000b9bf8 edx=00000000 esi=0007e320
edi=00000100
eip=77f83bb8 esp=0120fe28 ebp=0120ff74 iopl=0 nv up ei pl nz
na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000202


function: NtReplyWaitReceivePortEx
77f83bad b8ac000000 mov eax,0xac
77f83bb2 8d542404 lea edx,[esp+0x4]
ss:01c8d3fb=????????
77f83bb6 cd2e int 2e
77f83bb8 c21400 ret 0x14

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0120FF74 77D5878E 77D42363 0007E320 00000000 00000000
ntdll!NtReplyWaitReceivePortEx
0120FFA8 77D3F139 0007C060 0120FFEC 77E8B2D8 000AD090
rpcrt4!TowerConstruct
0120FFB4 77E8B2D8 000AD090 00000000 00000000 000AD090
rpcrt4!I_RpcServerInqTransportType
0120FFEC 00000000 00000000 00000000 00000000 00000000
kernel32!lstrcmpiW

State Dump for Thread Id 0x604

eax=77ab3e61 ebx=00000102 ecx=00420043 edx=00000000 esi=77f8318c
edi=0124ff74
eip=77f83197 esp=0124ff60 ebp=0124ff7c iopl=0 nv up ei pl nz
na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000206


function: NtDelayExecution
77f8318c b832000000 mov eax,0x32
77f83191 8d542404 lea edx,[esp+0x4]
ss:01ccd533=????????
77f83195 cd2e int 2e
77f83197 c20800 ret 0x8

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0124FF7C 77EA9D5F 0000EA60 00000000 77AB7DC8 0000EA60
ntdll!NtDelayExecution
00007530 00000000 00000000 00000000 00000000 00000000 kernel32!Sleep

State Dump for Thread Id 0x65c

eax=00000000 ebx=00050003 ecx=0007e65c edx=00000000 esi=0007e320
edi=00000100
eip=77f83bb8 esp=0128fe28 ebp=0128ff74 iopl=0 nv up ei pl nz
na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000206


function: NtReplyWaitReceivePortEx
77f83bad b8ac000000 mov eax,0xac
77f83bb2 8d542404 lea edx,[esp+0x4]
ss:01d0d3fb=????????
77f83bb6 cd2e int 2e
77f83bb8 c21400 ret 0x14

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0128FF74 77D5878E 77D42363 0007E320 00000000 00000000
ntdll!NtReplyWaitReceivePortEx
0128FFA8 77D3F139 0007C060 0128FFEC 77E8B2D8 000ABB48
rpcrt4!TowerConstruct
0128FFB4 77E8B2D8 000ABB48 00000000 00000000 000ABB48
rpcrt4!I_RpcServerInqTransportType
0128FFEC 00000000 77D3F121 000ABB48 00000000 00000000
kernel32!lstrcmpiW

*----> Raw Stack Dump <----*
0128fe28 c4 8e d5 77 00 01 00 00 - 54 ff 28 01 00 00 00 00
....w....T.(.....
0128fe38 18 c1 0b 00 58 ff 28 01 - e8 bf 07 00 e8 76 0b 00
.....X.(......v..
0128fe48 6d 31 f8 77 00 00 00 00 - 00 00 00 00 00 00 00 00
m1.w............
0128fe58 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0128fe68 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0128fe78 00 00 00 00 00 00 00 00 - 00 00 00 00 01 00 00 00
.................
0128fe88 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0128fe98 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0128fea8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0128feb8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0128fec8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0128fed8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0128fee8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0128fef8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0128ff08 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0128ff18 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0128ff28 00 00 00 00 20 c2 43 81 - 20 05 4c 81 00 00 00 00 .... .C.
..L.....
0128ff38 b0 06 4c 81 60 7c 12 bc - 46 02 00 00 a4 da 42 80
...L.`|..F.....B.
0128ff48 10 2f 06 80 80 06 4c 81 - 20 05 4c 81 03 00 05 00 ./....L.
..L.....
0128ff58 00 a2 2f 4d ff ff ff ff - 50 fe 28 01 00 00 02 80
.../M....P.(.....

State Dump for Thread Id 0x5d4

eax=0000ffff ebx=000e50e8 ecx=0250e5fc edx=00000000 esi=74fe93a0
edi=00000000
eip=77f837dc esp=0140ff84 ebp=0140ffb4 iopl=0 nv up ei pl nz
na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000202


function: ZwRemoveIoCompletion
77f837d1 b8a8000000 mov eax,0xa8
77f837d6 8d542404 lea edx,[esp+0x4]
ss:01e8d557=????????
77f837da cd2e int 2e
77f837dc c21400 ret 0x14
77f837df 53 push ebx
77f837e0 f7e1 mul ecx
77f837e2 8bd8 mov ebx,eax
77f837e4 8b442408 mov eax,[esp+0x8]
ss:01e8d557=????????
77f837e8 f7642414 mul dword ptr [esp+0x14]
ss:01e8d557=????????
77f837ec 03d8 add ebx,eax
77f837ee 8b442408 mov eax,[esp+0x8]
ss:01e8d557=????????
77f837f2 f7e1 mul ecx
77f837f4 03d3 add edx,ebx
77f837f6 5b pop ebx
77f837f7 c21000 ret 0x10

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0140FFB4 77E8B2D8 74FD8540 7FFDA000 00000000 000E50E8
ntdll!ZwRemoveIoCompletion
0140FFEC 00000000 74FD4766 000E50E8 00000000 00905A4D
kernel32!lstrcmpiW

*----> Raw Stack Dump <----*
0140ff84 b8 47 fd 74 34 03 00 00 - bc ff 40 01 b0 ff 40 01
..G.t4.....@...@.
0140ff94 a4 ff 40 01 28 2c fd 74 - 00 a0 fd 7f 00 00 00 00
...@.(,.t........
0140ffa4 00 00 00 00 1c 00 00 00 - 00 00 fd 74 c8 2d 4c 02
............t.-L.
0140ffb4 ec ff 40 01 d8 b2 e8 77 - 40 85 fd 74 00 a0 fd 7f
[email protected]@..t....
0140ffc4 00 00 00 00 e8 50 0e 00 - 00 50 fd 7f 64 f7 18 01
......P...P..d...
0140ffd4 c0 ff 40 01 64 f7 18 01 - ff ff ff ff 6c 13 ed 77
[email protected]
0140ffe4 98 2a e8 77 00 00 00 00 - 00 00 00 00 00 00 00 00
..*.w............
0140fff4 66 47 fd 74 e8 50 0e 00 - 00 00 00 00 4d 5a 90 00
fG.t.P......MZ..
01410004 03 00 00 00 04 00 00 00 - ff ff 00 00 b8 00 00 00
.................
01410014 00 00 00 00 40 00 00 00 - 00 00 00 00 00 00 00 00
.....@...........
01410024 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
01410034 00 00 00 00 00 00 00 00 - c0 00 00 00 0e 1f ba 0e
.................
01410044 00 b4 09 cd 21 b8 01 4c - cd 21 54 68 69 73 20 70
.....!..L.!This p
01410054 72 6f 67 72 61 6d 20 63 - 61 6e 6e 6f 74 20 62 65 rogram
cannot be
01410064 20 72 75 6e 20 69 6e 20 - 44 4f 53 20 6d 6f 64 65 run in
DOS mode
01410074 2e 0d 0d 0a 24 00 00 00 - 00 00 00 00 44 24 da f8
.....$.......D$..
01410084 00 45 b4 ab 00 45 b4 ab - 00 45 b4 ab 00 45 b5 ab
..E...E...E...E..
01410094 55 47 b4 ab 59 66 a7 ab - 10 45 b4 ab 00 45 b4 ab
UG..Yf...E...E..
014100a4 7a 47 b4 ab 56 4d b2 ab - 01 45 b4 ab 52 69 63 68
zG..VM...E..Rich
014100b4 00 45 b4 ab 00 00 00 00 - 00 00 00 00 50 45 00 00
..E..........PE..

State Dump for Thread Id 0x64c

eax=00000015 ebx=01afff74 ecx=0000001a edx=00000000 esi=77f8377b
edi=0000032c
eip=77f83786 esp=01afff58 ebp=01afff7c iopl=0 nv up ei ng nz
ac pe cy
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000293
 
G

George Hester

You have a few strange processes running. It would help us to know what they are:

defwatch.exe
domtimec.exe
rtvscan.exe
nvsvc32.exe (Norton?)
vptray.exe
MAPISP32.exe (Not from Outlook I assure you)
omtsreco.exe
pb70.exe (Likely the culprit)
agentsvr.exe

--
George Hester
__________________________________
BWIL22 said:
Win 2K IE ver 5.5 SP1
I do re-install of win2k - media player works (streaming radio staion
- kgsr.com) Sometimes hrs, sometimes days later it begins to crash
with dialog box: IE has generated errors and will close.

event viewer description: The application, iexplore.exe, generated an
application error The error occurred on 10/16/2003 @ 15:09:12.554 The
exception generated was c0000005 at address 4802F544 (<nosymbols>)

(abbreviated)log file contents: (really long)

Microsoft (R) Windows 2000 (TM) Version 5.00 DrWtsn32
Copyright (C) 1985-1999 Microsoft Corp. All rights reserved.



Application exception occurred:
App: iexplore.exe (pid=1488)
When: 10/16/2003 @ 13:43:28.327
Exception number: c0000005 (access violation)

*----> System Information <----*
Computer Name: B000802500F11
User Name: nbk941i
Number of Processors: 1
Processor Type: x86 Family 15 Model 1 Stepping 2
Windows 2000 Version: 5.0
Current Build: 2195
Service Pack: 3
Current Type: Uniprocessor Free
Registered Organization: Bank of America
Registered Owner: Bank of America

*----> Task List <----*
0 Idle.exe
8 System.exe
136 SMSS.exe
160 CSRSS.exe
180 WINLOGON.exe
208 SERVICES.exe
220 LSASS.exe
388 svchost.exe
420 spoolsv.exe
488 defwatch.exe
508 domtimec.exe
532 svchost.exe
580 rtvscan.exe
628 nvsvc32.exe
648 regsvc.exe
664 mstask.exe
712 WinMgmt.exe
756 MsPMSPSv.exe
932 MSGSYS.exe
1076 explorer.exe
1224 vptray.exe
1216 promon.exe
316 OUTLOOK.exe
608 MAPISP32.exe
452 omtsreco.exe
1444 sndvol32.exe
1080 pb70.exe
1524 agentsvr.exe
1488 IEXPLORE.exe
736 DRWTSN32.exe
0 _Total.exe

(00400000 - 00412000)
(77F80000 - 77FFB000)
(77E80000 - 77F31000)
(77E10000 - 77E6F000)
(77F40000 - 77F79000)
(70BD0000 - 70C1C000)
(77DB0000 - 77E0B000)
(77D30000 - 77D9D000)
(71500000 - 7161C000)
(78000000 - 78046000)
(71700000 - 7178A000)
(782F0000 - 78536000)
(77A50000 - 77B3A000)
(71110000 - 711D9000)
(775A0000 - 77626000)
(779B0000 - 77A4B000)
(71920000 - 7192B000)
(63000000 - 63079000)
(77530000 - 77552000)
(77840000 - 7787D000)
(770C0000 - 770E3000)
(10000000 - 100BC000)
(77880000 - 7790D000)
(77C10000 - 77C6D000)
(1A400000 - 1A472000)
(77820000 - 77827000)
(759B0000 - 759B6000)
(75050000 - 75058000)
(75030000 - 75043000)
(75020000 - 75028000)
(77440000 - 774B5000)
(77430000 - 77440000)
(76930000 - 7695B000)
(77920000 - 77943000)
(77570000 - 775A0000)
(774E0000 - 77512000)
(774C0000 - 774D1000)
(77830000 - 7783E000)
(75AB0000 - 75AB5000)
(75170000 - 751BF000)
(77BE0000 - 77BEF000)
(751C0000 - 751C6000)
(75150000 - 75160000)
(77950000 - 77978000)
(77980000 - 779A4000)
(01020000 - 01028000)
(76710000 - 76719000)
(76FA0000 - 76FAF000)
(773E0000 - 773F5000)
(76620000 - 76630000)
(75160000 - 7516C000)
(75210000 - 75225000)
(751D0000 - 75208000)
(718A0000 - 71902000)
(70420000 - 704A8000)
(74FD0000 - 74FED000)
(75010000 - 75017000)
(782C0000 - 782CC000)
(77340000 - 77353000)
(77520000 - 77525000)
(77320000 - 77337000)
(773B0000 - 773DE000)
(77380000 - 773A2000)
(77360000 - 77379000)
(777E0000 - 777E8000)
(777F0000 - 777F5000)
(70000000 - 70037000)
(71300000 - 71309000)
(012C0000 - 012C7000)
(6B700000 - 6B787000)
(01410000 - 016B3000)
(75E60000 - 75E7A000)
(75AC0000 - 75AE8000)
(72000000 - 72066000)
(77560000 - 77569000)
(77400000 - 77408000)
(77410000 - 77423000)
(75D40000 - 75D46000)
(69000000 - 6900C000)
(63700000 - 63716000)
(70F90000 - 70FCC000)
(77800000 - 7781E000)
(6B600000 - 6B66E000)
(038D0000 - 03A73000)
(76B30000 - 76B6D000)
(727F0000 - 727F9000)
(51000000 - 51044000)
(728A0000 - 728A6000)
(79170000 - 79191000)
(79410000 - 79422000)
(7C000000 - 7C054000)
(1D300000 - 1D3D0000)
(35500000 - 35620000)
(04990000 - 049A6000)
(35680000 - 3568F000)
(1FF00000 - 1FF7D000)
(41B00000 - 41B41000)
(48000000 - 4803F000)
(04A50000 - 04A57000)

State Dump for Thread Id 0x3f8

eax=000bfda8 ebx=00000000 ecx=00000200 edx=00000000 esi=0007ab58
edi=00000000
eip=77e58615 esp=0006dd48 ebp=0006dd8c iopl=0 nv up ei pl nz
na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000202


function: WaitMessage
77e5860a b836120000 mov eax,0x1236
77e5860f 8d542404 lea edx,[esp+0x4]
ss:00aeb31b=????????
77e58613 cd2e int 2e
77e58615 c3 ret

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0006DD8C 711219A5 00070110 0006EE88 0007A978 00000000
user32!WaitMessage
0006DE14 711218BF 0007A978 00000001 0007A978 00000000
BROWSEUI!Ordinal102
0006EE90 7151DC1B 0007A978 7151D997 0007A978 00000001
BROWSEUI!Ordinal102
0006FF00 004013B6 000728F2 00000001 00401A46 000728F2
shdocvw!Ordinal131
0006FF60 00401452 00400000 00000000 000728F2 00000001
iexplore!<nosymbols>
0006FFC0 77EA847C 00000000 00000000 7FFDF000 00000000
iexplore!<nosymbols>
0006FFF0 00000000 004013B9 00000000 000000C8 00000100
kernel32!ProcessIdToSessionId

*----> Raw Stack Dump <----*
0006dd48 49 1b 12 71 88 ee 06 00 - 78 a9 07 00 00 00 00 00
I..q....x.......
0006dd58 a8 01 03 00 0f 00 00 00 - 00 00 00 00 00 00 00 00
................
0006dd68 23 eb 85 04 a9 01 00 00 - 06 02 00 00 00 00 00 00
#...............
0006dd78 02 00 00 00 58 ab 07 00 - 01 44 00 80 18 53 07 00
....X....D...S..
0006dd88 00 00 00 00 14 de 06 00 - a5 19 12 71 10 01 07 00
...........q....
0006dd98 88 ee 06 00 78 a9 07 00 - 00 00 00 00 00 00 00 00
....x...........
0006dda8 e0 ff 06 00 e0 ff 06 00 - 00 de 06 00 1e 5b 11 71
.............[.q
0006ddb8 00 00 2f 78 0c 00 02 00 - 0b 01 09 00 60 00 00 00
../x........`...
0006ddc8 03 00 00 00 04 00 00 00 - 0c 00 00 00 01 00 00 00
................
0006ddd8 01 00 00 00 74 00 00 00 - 00 de 06 00 f3 55 12 71
....t........U.q
0006dde8 f8 c2 18 71 0c 00 00 00 - be 55 12 71 f8 c2 18 71
...q.....U.q...q
0006ddf8 0c 00 00 00 98 dd 06 00 - 00 00 00 00 e0 ff 06 00
................
0006de08 b1 8d 18 71 b8 4c 12 71 - 00 00 00 00 90 ee 06 00
...q.L.q........
0006de18 bf 18 12 71 78 a9 07 00 - 01 00 00 00 78 a9 07 00
...qx.......x...
0006de28 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
0006de38 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
0006de48 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
0006de58 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
0006de68 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
0006de78 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................

State Dump for Thread Id 0x5ac

eax=778321fe ebx=00000004 ecx=7ffde000 edx=00000000 esi=77f837a7
edi=00000004
eip=77f837b2 esp=00fbfd24 ebp=00fbfd70 iopl=0 nv up ei pl zr
na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000246


function: NtWaitForMultipleObjects
77f837a7 b8e9000000 mov eax,0xe9
77f837ac 8d542404 lea edx,[esp+0x4]
ss:01a3d2f7=????????
77f837b0 cd2e int 2e
77f837b2 c21400 ret 0x14

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
00FBFD70 77EA9C13 00FBFD48 00000001 00000000 00000000
ntdll!NtWaitForMultipleObjects
00FBFFB4 77E8B2D8 00000005 000A0A6C 7FFDE000 000A3290
kernel32!WaitForMultipleObjects
00FBFFEC 00000000 778321FE 000A3290 00000000 00000001
kernel32!lstrcmpiW

*----> Raw Stack Dump <----*
00fbfd24 00 9d ea 77 04 00 00 00 - 48 fd fb 00 01 00 00 00
...w....H.......
00fbfd34 00 00 00 00 00 00 00 00 - 01 00 00 00 90 32 0a 00
.............2..
00fbfd44 01 00 00 00 c4 01 00 00 - c8 01 00 00 d8 01 00 00
................
00fbfd54 14 03 00 00 60 d9 46 80 - 4a e7 49 80 00 00 00 00
....`.F.J.I.....
00fbfd64 e8 69 78 e2 60 d9 46 80 - 00 00 00 00 b4 ff fb 00
.ix.`.F.........
00fbfd74 13 9c ea 77 48 fd fb 00 - 01 00 00 00 00 00 00 00
...wH...........
00fbfd84 00 00 00 00 00 00 00 00 - b2 22 83 77 04 00 00 00
.........".w....
00fbfd94 b0 fe fb 00 00 00 00 00 - ff ff ff ff 90 32 0a 00
.............2..
00fbfda4 00 e0 fd 7f 6c 0a 0a 00 - a6 cf 52 80 d8 7b c5 bc
....l.....R..{..
00fbfdb4 c0 7a c5 bc 00 00 00 00 - 01 00 00 00 38 00 00 00
.z..........8...
00fbfdc4 23 00 00 00 23 00 00 00 - 6c 0a 0a 00 00 e0 fd 7f
#...#...l.......
00fbfdd4 90 32 0a 00 00 e0 fd 7f - 00 e0 fd 7f fe 21 83 77
.2...........!.w
00fbfde4 35 83 f8 77 50 b6 e8 77 - 1b 00 00 00 00 02 00 00
5..wP..w........
00fbfdf4 fc ff fb 00 23 00 00 00 - 01 40 26 81 40 c0 46 e1
....#....@&[email protected].
00fbfe04 c0 00 00 00 78 ac 47 81 - 77 ed 00 00 28 73 a3 81
....x.G.w...(s..
00fbfe14 00 07 00 00 ae cc 44 80 - 77 ed 00 00 28 73 a3 81
......D.w...(s..
00fbfe24 77 ed 00 00 28 73 a3 81 - 01 42 fd 7f 0d 0d 00 00
w...(s...B......
00fbfe34 41 d6 44 80 0d 0d 00 00 - 50 14 56 81 00 40 fd 7f
A.D.....P.V..@..
00fbfe44 fc 07 30 c0 00 00 00 00 - 94 7b c5 bc 0d 0d 00 00
..0......{......
00fbfe54 74 7b c5 bc 00 00 00 00 - 01 00 00 00 00 00 00 00
t{..............

State Dump for Thread Id 0x568

eax=00000000 ebx=77f8377b ecx=00000101 edx=00000000 esi=00000000
edi=00000001
eip=77f83786 esp=0114facc ebp=0114fb04 iopl=0 nv up ei ng nz
na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000286


function: NtWaitForSingleObject
77f8377b b8ea000000 mov eax,0xea
77f83780 8d542404 lea edx,[esp+0x4]
ss:01bcd09f=????????
77f83784 cd2e int 2e
77f83786 c20c00 ret 0xc

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0114FB04 74FD7EE6 00000288 0000028C 00000001 00000004
ntdll!NtWaitForSingleObject
0114FBF0 75031DA9 00000001 0114FE84 0114FC7C 0114FD80
msafd!WSPSetSockOpt
0114FC54 63017912 00000001 0114FE84 0114FC7C 0114FD80 ws2_32!select
0114FFB0 630176D8 77E8B2D8 000AC750 7FFDE000 00000040
wininet!InternetSetStatusCallbackA
0114FFEC 00000000 00000000 00000000 00000000 00000000
wininet!InternetSetStatusCallbackA

*----> Raw Stack Dump <----*
0114facc 62 bb fd 74 88 02 00 00 - 01 00 00 00 f0 fa 14 01
b..t............
0114fadc 84 fe 14 01 78 fb 14 01 - 68 fb 14 01 01 00 00 00
....x...h.......
0114faec e5 38 f8 77 c0 b4 b3 ff - ff ff ff ff 78 4e 09 00
.8.w........xN..
0114fafc 00 00 00 00 00 00 00 00 - f0 fb 14 01 e6 7e fd 74
.............~.t
0114fb0c 88 02 00 00 8c 02 00 00 - 01 00 00 00 04 00 00 00
................
0114fb1c 80 fd 14 01 10 7e 0b 00 - 7c fc 14 01 00 00 00 00
.....~..|.......
0114fb2c 00 00 00 00 80 0f 05 fd - ff ff ff ff 8c 02 00 00
................
0114fb3c 88 02 00 00 00 00 00 00 - 00 00 07 00 90 fb 14 01
................
0114fb4c 17 20 01 00 80 fb 14 01 - 10 00 00 00 00 00 00 00 .
..............
0114fb5c 06 00 00 00 00 00 00 00 - 00 00 00 00 80 0f 05 fd
................
0114fb6c ff ff ff ff 01 00 00 00 - 00 4e 09 00 8c 02 00 00
.........N......
0114fb7c 19 00 00 00 30 00 00 00 - 8c 02 00 00 88 60 c1 70
....0........`.p
0114fb8c 88 60 c1 70 dc fb 14 01 - 95 2b f8 77 08 36 f8 77
.`.p.....+.w.6.w
0114fb9c ff ff ff ff ec fb 14 01 - 36 91 e8 77 00 00 07 00
........6..w....
0114fbac 78 4e 09 00 24 00 00 00 - 00 00 00 00 68 fb 14 01
xN..$.......h...
0114fbbc 2c 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00
,...............
0114fbcc 00 00 00 00 1c 00 00 00 - 84 fb 14 01 1c fb 14 01
................
0114fbdc 24 fc 14 01 44 fc 14 01 - 36 df fd 74 78 30 fd 74
$...D...6..tx0.t
0114fbec ff ff ff ff 54 fc 14 01 - a9 1d 03 75 01 00 00 00
....T......u....
0114fbfc 84 fe 14 01 7c fc 14 01 - 80 fd 14 01 90 ff 14 01
....|...........

State Dump for Thread Id 0x5b8

eax=0118fe64 ebx=00000000 ecx=00071258 edx=00000000 esi=77f8377b
edi=0000014c
eip=77f83786 esp=0118ea0c ebp=0118ea30 iopl=0 nv up ei pl zr
na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000246


function: NtWaitForSingleObject
77f8377b b8ea000000 mov eax,0xea
77f83780 8d542404 lea edx,[esp+0x4]
ss:01c0bfdf=????????
77f83784 cd2e int 2e
77f83786 c20c00 ret 0xc

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0118EA30 77E8B32B 0000014C FFFFFFFF 00000000 630023B5
ntdll!NtWaitForSingleObject
0118EA68 63003BED 00000002 63066D90 6300B9FE 00000002
kernel32!WaitForSingleObject
0118EAE0 6301CEB6 024B6408 00119B50 0118EB00 00000002
wininet!InternetQueryOptionA
0118FF10 630090F2 024DC928 024B6408 024DC858 00000001
wininet!InternetSetCookieA
0118FF30 63008C1C 00000000 000B60A8 024DC858 6300849B
wininet!HttpQueryInfoA
0118FF84 70BDAF87 00000000 00070178 70BD0000 00000000
wininet!HttpQueryInfoA
0118FFAC 70BDAED7 00000000 77E8B2D8 00000000 00070178
SHLWAPI!PathRemoveFileSpecW
0118FFEC 00000000 00000000 00000000 00000000 00000000
SHLWAPI!PathRemoveFileSpecW

*----> Raw Stack Dump <----*
0118ea0c 35 9b ea 77 4c 01 00 00 - 00 00 00 00 00 00 00 00
5..wL...........
0118ea1c 64 ea 18 01 f8 7b 08 00 - 20 90 08 00 f8 7b 08 00 d....{..
....{..
0118ea2c f8 7b 08 00 68 ea 18 01 - 2b b3 e8 77 4c 01 00 00
.{..h...+..wL...
0118ea3c ff ff ff ff 00 00 00 00 - b5 23 00 63 4c 01 00 00
.........#.cL...
0118ea4c ff ff ff ff 00 00 00 00 - f8 7b 08 00 3f 24 00 63
.........{..?$.c
0118ea5c 64 ea 18 01 e8 00 00 00 - 00 00 00 00 e0 ea 18 01
d...............
0118ea6c ed 3b 00 63 02 00 00 00 - 90 6d 06 63 fe b9 00 63
.;.c.....m.c...c
0118ea7c 02 00 00 00 90 6d 06 63 - ba b9 00 63 02 00 00 00
.....m.c...c....
0118ea8c 90 6d 06 63 20 90 08 00 - 8c b9 00 63 60 6d 06 63 .m.c
......c`m.c
0118ea9c 73 c8 01 63 01 00 00 00 - 08 64 4b 02 28 c9 4d 02
s..c.....dK.(.M.
0118eaac ff ff ff ff ff ff ff 7f - d0 be db 01 0d 94 c3 01
................
0118eabc 00 00 00 00 02 00 00 00 - 01 00 00 00 0a eb 18 01
................
0118eacc 00 eb 18 01 a0 be 0a 00 - 08 20 10 00 3f eb 18 01 .........
..?...
0118eadc 2a eb 18 01 10 ff 18 01 - b6 ce 01 63 08 64 4b 02
*..........c.dK.
0118eaec 50 9b 11 00 00 eb 18 01 - 02 00 00 00 58 c8 4d 02
P...........X.M.
0118eafc 08 64 4b 02 72 37 44 30 - 41 46 31 44 44 00 42 44
.dK.r7D0AF1DD.BD
0118eb0c 73 76 4d 6a 6b 30 34 6d - 40 69 33 76 57 77 73 42
svMjk04m@i3vWwsB
0118eb1c 6b 2b 2b 3a 00 20 64 6f - 6d 61 69 6e 00 2e 6d 6f k++:.
domain..mo
0118eb2c 63 2e 6b 63 69 6c 63 65 - 75 6c 61 76 00 20 70 61
c.kcilceulav. pa
0118eb3c 74 68 00 2f 00 00 00 00 - 03 00 00 00 98 eb 18 01
th./............

State Dump for Thread Id 0x648

eax=012de6c0 ebx=011cff88 ecx=012de69c edx=00000000 esi=77f8377b
edi=0000026c
eip=77f83786 esp=011cff6c ebp=011cff90 iopl=0 nv up ei ng nz
ac po cy
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000297


function: NtWaitForSingleObject
77f8377b b8ea000000 mov eax,0xea
77f83780 8d542404 lea edx,[esp+0x4]
ss:01c4d53f=????????
77f83784 cd2e int 2e
77f83786 c20c00 ret 0xc

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
011CFF90 77E8B32B 0000026C 00007530 00000000 63045F68
ntdll!NtWaitForSingleObject
011CFFEC 00000000 00000000 00000000 00000000 00000000
kernel32!WaitForSingleObject

State Dump for Thread Id 0x518

eax=00000000 ebx=00050003 ecx=000b9bf8 edx=00000000 esi=0007e320
edi=00000100
eip=77f83bb8 esp=0120fe28 ebp=0120ff74 iopl=0 nv up ei pl nz
na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000202


function: NtReplyWaitReceivePortEx
77f83bad b8ac000000 mov eax,0xac
77f83bb2 8d542404 lea edx,[esp+0x4]
ss:01c8d3fb=????????
77f83bb6 cd2e int 2e
77f83bb8 c21400 ret 0x14

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0120FF74 77D5878E 77D42363 0007E320 00000000 00000000
ntdll!NtReplyWaitReceivePortEx
0120FFA8 77D3F139 0007C060 0120FFEC 77E8B2D8 000AD090
rpcrt4!TowerConstruct
0120FFB4 77E8B2D8 000AD090 00000000 00000000 000AD090
rpcrt4!I_RpcServerInqTransportType
0120FFEC 00000000 00000000 00000000 00000000 00000000
kernel32!lstrcmpiW

State Dump for Thread Id 0x604

eax=77ab3e61 ebx=00000102 ecx=00420043 edx=00000000 esi=77f8318c
edi=0124ff74
eip=77f83197 esp=0124ff60 ebp=0124ff7c iopl=0 nv up ei pl nz
na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000206


function: NtDelayExecution
77f8318c b832000000 mov eax,0x32
77f83191 8d542404 lea edx,[esp+0x4]
ss:01ccd533=????????
77f83195 cd2e int 2e
77f83197 c20800 ret 0x8

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0124FF7C 77EA9D5F 0000EA60 00000000 77AB7DC8 0000EA60
ntdll!NtDelayExecution
00007530 00000000 00000000 00000000 00000000 00000000 kernel32!Sleep

State Dump for Thread Id 0x65c

eax=00000000 ebx=00050003 ecx=0007e65c edx=00000000 esi=0007e320
edi=00000100
eip=77f83bb8 esp=0128fe28 ebp=0128ff74 iopl=0 nv up ei pl nz
na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000206


function: NtReplyWaitReceivePortEx
77f83bad b8ac000000 mov eax,0xac
77f83bb2 8d542404 lea edx,[esp+0x4]
ss:01d0d3fb=????????
77f83bb6 cd2e int 2e
77f83bb8 c21400 ret 0x14

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0128FF74 77D5878E 77D42363 0007E320 00000000 00000000
ntdll!NtReplyWaitReceivePortEx
0128FFA8 77D3F139 0007C060 0128FFEC 77E8B2D8 000ABB48
rpcrt4!TowerConstruct
0128FFB4 77E8B2D8 000ABB48 00000000 00000000 000ABB48
rpcrt4!I_RpcServerInqTransportType
0128FFEC 00000000 77D3F121 000ABB48 00000000 00000000
kernel32!lstrcmpiW

*----> Raw Stack Dump <----*
0128fe28 c4 8e d5 77 00 01 00 00 - 54 ff 28 01 00 00 00 00
...w....T.(.....
0128fe38 18 c1 0b 00 58 ff 28 01 - e8 bf 07 00 e8 76 0b 00
....X.(......v..
0128fe48 6d 31 f8 77 00 00 00 00 - 00 00 00 00 00 00 00 00
m1.w............
0128fe58 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
0128fe68 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
0128fe78 00 00 00 00 00 00 00 00 - 00 00 00 00 01 00 00 00
................
0128fe88 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
0128fe98 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
0128fea8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
0128feb8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
0128fec8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
0128fed8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
0128fee8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
0128fef8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
0128ff08 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
0128ff18 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
0128ff28 00 00 00 00 20 c2 43 81 - 20 05 4c 81 00 00 00 00 .... .C.
.L.....
0128ff38 b0 06 4c 81 60 7c 12 bc - 46 02 00 00 a4 da 42 80
..L.`|..F.....B.
0128ff48 10 2f 06 80 80 06 4c 81 - 20 05 4c 81 03 00 05 00 ./....L.
.L.....
0128ff58 00 a2 2f 4d ff ff ff ff - 50 fe 28 01 00 00 02 80
../M....P.(.....

State Dump for Thread Id 0x5d4

eax=0000ffff ebx=000e50e8 ecx=0250e5fc edx=00000000 esi=74fe93a0
edi=00000000
eip=77f837dc esp=0140ff84 ebp=0140ffb4 iopl=0 nv up ei pl nz
na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000202


function: ZwRemoveIoCompletion
77f837d1 b8a8000000 mov eax,0xa8
77f837d6 8d542404 lea edx,[esp+0x4]
ss:01e8d557=????????
77f837da cd2e int 2e
77f837dc c21400 ret 0x14
77f837df 53 push ebx
77f837e0 f7e1 mul ecx
77f837e2 8bd8 mov ebx,eax
77f837e4 8b442408 mov eax,[esp+0x8]
ss:01e8d557=????????
77f837e8 f7642414 mul dword ptr [esp+0x14]
ss:01e8d557=????????
77f837ec 03d8 add ebx,eax
77f837ee 8b442408 mov eax,[esp+0x8]
ss:01e8d557=????????
77f837f2 f7e1 mul ecx
77f837f4 03d3 add edx,ebx
77f837f6 5b pop ebx
77f837f7 c21000 ret 0x10

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0140FFB4 77E8B2D8 74FD8540 7FFDA000 00000000 000E50E8
ntdll!ZwRemoveIoCompletion
0140FFEC 00000000 74FD4766 000E50E8 00000000 00905A4D
kernel32!lstrcmpiW

*----> Raw Stack Dump <----*
0140ff84 b8 47 fd 74 34 03 00 00 - bc ff 40 01 b0 ff 40 01
.G.t4.....@...@.
0140ff94 a4 ff 40 01 28 2c fd 74 - 00 a0 fd 7f 00 00 00 00
..@.(,.t........
0140ffa4 00 00 00 00 1c 00 00 00 - 00 00 fd 74 c8 2d 4c 02
...........t.-L.
0140ffb4 ec ff 40 01 d8 b2 e8 77 - 40 85 fd 74 00 a0 fd 7f
[email protected]@..t....
0140ffc4 00 00 00 00 e8 50 0e 00 - 00 50 fd 7f 64 f7 18 01
.....P...P..d...
0140ffd4 c0 ff 40 01 64 f7 18 01 - ff ff ff ff 6c 13 ed 77
[email protected]
0140ffe4 98 2a e8 77 00 00 00 00 - 00 00 00 00 00 00 00 00
.*.w............
0140fff4 66 47 fd 74 e8 50 0e 00 - 00 00 00 00 4d 5a 90 00
fG.t.P......MZ..
01410004 03 00 00 00 04 00 00 00 - ff ff 00 00 b8 00 00 00
................
01410014 00 00 00 00 40 00 00 00 - 00 00 00 00 00 00 00 00
....@...........
01410024 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
01410034 00 00 00 00 00 00 00 00 - c0 00 00 00 0e 1f ba 0e
................
01410044 00 b4 09 cd 21 b8 01 4c - cd 21 54 68 69 73 20 70
....!..L.!This p
01410054 72 6f 67 72 61 6d 20 63 - 61 6e 6e 6f 74 20 62 65 rogram
cannot be
01410064 20 72 75 6e 20 69 6e 20 - 44 4f 53 20 6d 6f 64 65 run in
DOS mode
01410074 2e 0d 0d 0a 24 00 00 00 - 00 00 00 00 44 24 da f8
....$.......D$..
01410084 00 45 b4 ab 00 45 b4 ab - 00 45 b4 ab 00 45 b5 ab
.E...E...E...E..
01410094 55 47 b4 ab 59 66 a7 ab - 10 45 b4 ab 00 45 b4 ab
UG..Yf...E...E..
014100a4 7a 47 b4 ab 56 4d b2 ab - 01 45 b4 ab 52 69 63 68
zG..VM...E..Rich
014100b4 00 45 b4 ab 00 00 00 00 - 00 00 00 00 50 45 00 00
.E..........PE..

State Dump for Thread Id 0x64c

eax=00000015 ebx=01afff74 ecx=0000001a edx=00000000 esi=77f8377b
edi=0000032c
eip=77f83786 esp=01afff58 ebp=01afff7c iopl=0 nv up ei ng nz
ac pe cy
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000293
 
B

BWIL22

Yes thats norton. and pb70 is powerbuilder 7.0.
I can't easily identify other processes.
Also - I upgraded to IE 6 SP1 - and get a little more info
when it crashes - ModName: strmdll.dll. thanks.





George Hester said:
You have a few strange processes running. It would help us to know what
they are:

defwatch.exe
domtimec.exe
rtvscan.exe
nvsvc32.exe (Norton?)
vptray.exe
MAPISP32.exe (Not from Outlook I assure you)
omtsreco.exe
pb70.exe (Likely the culprit)
agentsvr.exe

--
George Hester

BWIL22 said:
Win 2K IE ver 5.5 SP1
I do re-install of win2k - media player works (streaming radio staion
- kgsr.com) Sometimes hrs, sometimes days later it begins to crash
with dialog box: IE has generated errors and will close.

event viewer description: The application, iexplore.exe, generated an
application error The error occurred on 10/16/2003 @ 15:09:12.554 The
exception generated was c0000005 at address 4802F544 (<nosymbols>)

(abbreviated)log file contents: (really long)

Microsoft (R) Windows 2000 (TM) Version 5.00 DrWtsn32
Copyright (C) 1985-1999 Microsoft Corp. All rights reserved.



Application exception occurred:
App: iexplore.exe (pid=1488)
When: 10/16/2003 @ 13:43:28.327
Exception number: c0000005 (access violation)

*----> System Information <----*
Computer Name: B000802500F11
User Name: nbk941i
Number of Processors: 1
Processor Type: x86 Family 15 Model 1 Stepping 2
Windows 2000 Version: 5.0
Current Build: 2195
Service Pack: 3
Current Type: Uniprocessor Free
Registered Organization: Bank of America
Registered Owner: Bank of America

*----> Task List <----*
0 Idle.exe
8 System.exe
136 SMSS.exe
160 CSRSS.exe
180 WINLOGON.exe
208 SERVICES.exe
220 LSASS.exe
388 svchost.exe
420 spoolsv.exe
488 defwatch.exe
508 domtimec.exe
532 svchost.exe
580 rtvscan.exe
628 nvsvc32.exe
648 regsvc.exe
664 mstask.exe
712 WinMgmt.exe
756 MsPMSPSv.exe
932 MSGSYS.exe
1076 explorer.exe
1224 vptray.exe
1216 promon.exe
316 OUTLOOK.exe
608 MAPISP32.exe
452 omtsreco.exe
1444 sndvol32.exe
1080 pb70.exe
1524 agentsvr.exe
1488 IEXPLORE.exe
736 DRWTSN32.exe
0 Total.exe

(00400000 - 00412000)
(77F80000 - 77FFB000)
(77E80000 - 77F31000)
(77E10000 - 77E6F000)
(77F40000 - 77F79000)
(70BD0000 - 70C1C000)
(77DB0000 - 77E0B000)
(77D30000 - 77D9D000)
(71500000 - 7161C000)
(78000000 - 78046000)
(71700000 - 7178A000)
(782F0000 - 78536000)
(77A50000 - 77B3A000)
(71110000 - 711D9000)
(775A0000 - 77626000)
(779B0000 - 77A4B000)
(71920000 - 7192B000)
(63000000 - 63079000)
(77530000 - 77552000)
(77840000 - 7787D000)
(770C0000 - 770E3000)
(10000000 - 100BC000)
(77880000 - 7790D000)
(77C10000 - 77C6D000)
(1A400000 - 1A472000)
(77820000 - 77827000)
(759B0000 - 759B6000)
(75050000 - 75058000)
(75030000 - 75043000)
(75020000 - 75028000)
(77440000 - 774B5000)
(77430000 - 77440000)
(76930000 - 7695B000)
(77920000 - 77943000)
(77570000 - 775A0000)
(774E0000 - 77512000)
(774C0000 - 774D1000)
(77830000 - 7783E000)
(75AB0000 - 75AB5000)
(75170000 - 751BF000)
(77BE0000 - 77BEF000)
(751C0000 - 751C6000)
(75150000 - 75160000)
(77950000 - 77978000)
(77980000 - 779A4000)
(01020000 - 01028000)
(76710000 - 76719000)
(76FA0000 - 76FAF000)
(773E0000 - 773F5000)
(76620000 - 76630000)
(75160000 - 7516C000)
(75210000 - 75225000)
(751D0000 - 75208000)
(718A0000 - 71902000)
(70420000 - 704A8000)
(74FD0000 - 74FED000)
(75010000 - 75017000)
(782C0000 - 782CC000)
(77340000 - 77353000)
(77520000 - 77525000)
(77320000 - 77337000)
(773B0000 - 773DE000)
(77380000 - 773A2000)
(77360000 - 77379000)
(777E0000 - 777E8000)
(777F0000 - 777F5000)
(70000000 - 70037000)
(71300000 - 71309000)
(012C0000 - 012C7000)
(6B700000 - 6B787000)
(01410000 - 016B3000)
(75E60000 - 75E7A000)
(75AC0000 - 75AE8000)
(72000000 - 72066000)
(77560000 - 77569000)
(77400000 - 77408000)
(77410000 - 77423000)
(75D40000 - 75D46000)
(69000000 - 6900C000)
(63700000 - 63716000)
(70F90000 - 70FCC000)
(77800000 - 7781E000)
(6B600000 - 6B66E000)
(038D0000 - 03A73000)
(76B30000 - 76B6D000)
(727F0000 - 727F9000)
(51000000 - 51044000)
(728A0000 - 728A6000)
(79170000 - 79191000)
(79410000 - 79422000)
(7C000000 - 7C054000)
(1D300000 - 1D3D0000)
(35500000 - 35620000)
(04990000 - 049A6000)
(35680000 - 3568F000)
(1FF00000 - 1FF7D000)
(41B00000 - 41B41000)
(48000000 - 4803F000)
(04A50000 - 04A57000)

State Dump for Thread Id 0x3f8

eax=000bfda8 ebx=00000000 ecx=00000200 edx=00000000 esi=0007ab58
edi=00000000
eip=77e58615 esp=0006dd48 ebp=0006dd8c iopl=0 nv up ei pl nz
na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000202


function: WaitMessage
77e5860a b836120000 mov eax,0x1236
77e5860f 8d542404 lea edx,[esp+0x4]
ss:00aeb31b=????????
77e58613 cd2e int 2e
77e58615 c3 ret

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0006DD8C 711219A5 00070110 0006EE88 0007A978 00000000
user32!WaitMessage
0006DE14 711218BF 0007A978 00000001 0007A978 00000000
BROWSEUI!Ordinal102
0006EE90 7151DC1B 0007A978 7151D997 0007A978 00000001
BROWSEUI!Ordinal102
0006FF00 004013B6 000728F2 00000001 00401A46 000728F2
shdocvw!Ordinal131
0006FF60 00401452 00400000 00000000 000728F2 00000001
iexplore!<nosymbols>
0006FFC0 77EA847C 00000000 00000000 7FFDF000 00000000
iexplore!<nosymbols>
0006FFF0 00000000 004013B9 00000000 000000C8 00000100
kernel32!ProcessIdToSessionId

*----> Raw Stack Dump <----*
0006dd48 49 1b 12 71 88 ee 06 00 - 78 a9 07 00 00 00 00 00
I..q....x.......
0006dd58 a8 01 03 00 0f 00 00 00 - 00 00 00 00 00 00 00 00
................
0006dd68 23 eb 85 04 a9 01 00 00 - 06 02 00 00 00 00 00 00
#...............
0006dd78 02 00 00 00 58 ab 07 00 - 01 44 00 80 18 53 07 00
....X....D...S..
0006dd88 00 00 00 00 14 de 06 00 - a5 19 12 71 10 01 07 00
...........q....
0006dd98 88 ee 06 00 78 a9 07 00 - 00 00 00 00 00 00 00 00
....x...........
0006dda8 e0 ff 06 00 e0 ff 06 00 - 00 de 06 00 1e 5b 11 71
.............[.q
0006ddb8 00 00 2f 78 0c 00 02 00 - 0b 01 09 00 60 00 00 00
../x........`...
0006ddc8 03 00 00 00 04 00 00 00 - 0c 00 00 00 01 00 00 00
................
0006ddd8 01 00 00 00 74 00 00 00 - 00 de 06 00 f3 55 12 71
....t........U.q
0006dde8 f8 c2 18 71 0c 00 00 00 - be 55 12 71 f8 c2 18 71
...q.....U.q...q
0006ddf8 0c 00 00 00 98 dd 06 00 - 00 00 00 00 e0 ff 06 00
................
0006de08 b1 8d 18 71 b8 4c 12 71 - 00 00 00 00 90 ee 06 00
...q.L.q........
0006de18 bf 18 12 71 78 a9 07 00 - 01 00 00 00 78 a9 07 00
...qx.......x...
0006de28 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
0006de38 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
0006de48 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
0006de58 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
0006de68 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
0006de78 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................

State Dump for Thread Id 0x5ac

eax=778321fe ebx=00000004 ecx=7ffde000 edx=00000000 esi=77f837a7
edi=00000004
eip=77f837b2 esp=00fbfd24 ebp=00fbfd70 iopl=0 nv up ei pl zr
na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000246


function: NtWaitForMultipleObjects
77f837a7 b8e9000000 mov eax,0xe9
77f837ac 8d542404 lea edx,[esp+0x4]
ss:01a3d2f7=????????
77f837b0 cd2e int 2e
77f837b2 c21400 ret 0x14

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
00FBFD70 77EA9C13 00FBFD48 00000001 00000000 00000000
ntdll!NtWaitForMultipleObjects
00FBFFB4 77E8B2D8 00000005 000A0A6C 7FFDE000 000A3290
kernel32!WaitForMultipleObjects
00FBFFEC 00000000 778321FE 000A3290 00000000 00000001
kernel32!lstrcmpiW

*----> Raw Stack Dump <----*
00fbfd24 00 9d ea 77 04 00 00 00 - 48 fd fb 00 01 00 00 00
...w....H.......
00fbfd34 00 00 00 00 00 00 00 00 - 01 00 00 00 90 32 0a 00
.............2..
00fbfd44 01 00 00 00 c4 01 00 00 - c8 01 00 00 d8 01 00 00
................
00fbfd54 14 03 00 00 60 d9 46 80 - 4a e7 49 80 00 00 00 00
....`.F.J.I.....
00fbfd64 e8 69 78 e2 60 d9 46 80 - 00 00 00 00 b4 ff fb 00
.ix.`.F.........
00fbfd74 13 9c ea 77 48 fd fb 00 - 01 00 00 00 00 00 00 00
...wH...........
00fbfd84 00 00 00 00 00 00 00 00 - b2 22 83 77 04 00 00 00
.........".w....
00fbfd94 b0 fe fb 00 00 00 00 00 - ff ff ff ff 90 32 0a 00
.............2..
00fbfda4 00 e0 fd 7f 6c 0a 0a 00 - a6 cf 52 80 d8 7b c5 bc
....l.....R..{..
00fbfdb4 c0 7a c5 bc 00 00 00 00 - 01 00 00 00 38 00 00 00
.z..........8...
00fbfdc4 23 00 00 00 23 00 00 00 - 6c 0a 0a 00 00 e0 fd 7f
#...#...l.......
00fbfdd4 90 32 0a 00 00 e0 fd 7f - 00 e0 fd 7f fe 21 83 77
.2...........!.w
00fbfde4 35 83 f8 77 50 b6 e8 77 - 1b 00 00 00 00 02 00 00
5..wP..w........
00fbfdf4 fc ff fb 00 23 00 00 00 - 01 40 26 81 40 c0 46 e1
....#....@&[email protected].
00fbfe04 c0 00 00 00 78 ac 47 81 - 77 ed 00 00 28 73 a3 81
....x.G.w...(s..
00fbfe14 00 07 00 00 ae cc 44 80 - 77 ed 00 00 28 73 a3 81
......D.w...(s..
00fbfe24 77 ed 00 00 28 73 a3 81 - 01 42 fd 7f 0d 0d 00 00
w...(s...B......
00fbfe34 41 d6 44 80 0d 0d 00 00 - 50 14 56 81 00 40 fd 7f
A.D.....P.V..@..
00fbfe44 fc 07 30 c0 00 00 00 00 - 94 7b c5 bc 0d 0d 00 00
..0......{......
00fbfe54 74 7b c5 bc 00 00 00 00 - 01 00 00 00 00 00 00 00
t{..............

State Dump for Thread Id 0x568

eax=00000000 ebx=77f8377b ecx=00000101 edx=00000000 esi=00000000
edi=00000001
eip=77f83786 esp=0114facc ebp=0114fb04 iopl=0 nv up ei ng nz
na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000286


function: NtWaitForSingleObject
77f8377b b8ea000000 mov eax,0xea
77f83780 8d542404 lea edx,[esp+0x4]
ss:01bcd09f=????????
77f83784 cd2e int 2e
77f83786 c20c00 ret 0xc

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0114FB04 74FD7EE6 00000288 0000028C 00000001 00000004
ntdll!NtWaitForSingleObject
0114FBF0 75031DA9 00000001 0114FE84 0114FC7C 0114FD80
msafd!WSPSetSockOpt
0114FC54 63017912 00000001 0114FE84 0114FC7C 0114FD80 ws2 32!select
0114FFB0 630176D8 77E8B2D8 000AC750 7FFDE000 00000040
wininet!InternetSetStatusCallbackA
0114FFEC 00000000 00000000 00000000 00000000 00000000
wininet!InternetSetStatusCallbackA

*----> Raw Stack Dump <----*
0114facc 62 bb fd 74 88 02 00 00 - 01 00 00 00 f0 fa 14 01
b..t............
0114fadc 84 fe 14 01 78 fb 14 01 - 68 fb 14 01 01 00 00 00
....x...h.......
0114faec e5 38 f8 77 c0 b4 b3 ff - ff ff ff ff 78 4e 09 00
.8.w........xN..
0114fafc 00 00 00 00 00 00 00 00 - f0 fb 14 01 e6 7e fd 74
.............~.t
0114fb0c 88 02 00 00 8c 02 00 00 - 01 00 00 00 04 00 00 00
................
0114fb1c 80 fd 14 01 10 7e 0b 00 - 7c fc 14 01 00 00 00 00
.....~..|.......
0114fb2c 00 00 00 00 80 0f 05 fd - ff ff ff ff 8c 02 00 00
................
0114fb3c 88 02 00 00 00 00 00 00 - 00 00 07 00 90 fb 14 01
................
0114fb4c 17 20 01 00 80 fb 14 01 - 10 00 00 00 00 00 00 00 .
..............
0114fb5c 06 00 00 00 00 00 00 00 - 00 00 00 00 80 0f 05 fd
................
0114fb6c ff ff ff ff 01 00 00 00 - 00 4e 09 00 8c 02 00 00
.........N......
0114fb7c 19 00 00 00 30 00 00 00 - 8c 02 00 00 88 60 c1 70
....0........`.p
0114fb8c 88 60 c1 70 dc fb 14 01 - 95 2b f8 77 08 36 f8 77
.`.p.....+.w.6.w
0114fb9c ff ff ff ff ec fb 14 01 - 36 91 e8 77 00 00 07 00
........6..w....
0114fbac 78 4e 09 00 24 00 00 00 - 00 00 00 00 68 fb 14 01
xN..$.......h...
0114fbbc 2c 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00
,...............
0114fbcc 00 00 00 00 1c 00 00 00 - 84 fb 14 01 1c fb 14 01
................
0114fbdc 24 fc 14 01 44 fc 14 01 - 36 df fd 74 78 30 fd 74
$...D...6..tx0.t
0114fbec ff ff ff ff 54 fc 14 01 - a9 1d 03 75 01 00 00 00
....T......u....
0114fbfc 84 fe 14 01 7c fc 14 01 - 80 fd 14 01 90 ff 14 01
....|...........

State Dump for Thread Id 0x5b8

eax=0118fe64 ebx=00000000 ecx=00071258 edx=00000000 esi=77f8377b
edi=0000014c
eip=77f83786 esp=0118ea0c ebp=0118ea30 iopl=0 nv up ei pl zr
na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000246


function: NtWaitForSingleObject
77f8377b b8ea000000 mov eax,0xea
77f83780 8d542404 lea edx,[esp+0x4]
ss:01c0bfdf=????????
77f83784 cd2e int 2e
77f83786 c20c00 ret 0xc

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0118EA30 77E8B32B 0000014C FFFFFFFF 00000000 630023B5
ntdll!NtWaitForSingleObject
0118EA68 63003BED 00000002 63066D90 6300B9FE 00000002
kernel32!WaitForSingleObject
0118EAE0 6301CEB6 024B6408 00119B50 0118EB00 00000002
wininet!InternetQueryOptionA
0118FF10 630090F2 024DC928 024B6408 024DC858 00000001
wininet!InternetSetCookieA
0118FF30 63008C1C 00000000 000B60A8 024DC858 6300849B
wininet!HttpQueryInfoA
0118FF84 70BDAF87 00000000 00070178 70BD0000 00000000
wininet!HttpQueryInfoA
0118FFAC 70BDAED7 00000000 77E8B2D8 00000000 00070178
SHLWAPI!PathRemoveFileSpecW
0118FFEC 00000000 00000000 00000000 00000000 00000000
SHLWAPI!PathRemoveFileSpecW

*----> Raw Stack Dump <----*
0118ea0c 35 9b ea 77 4c 01 00 00 - 00 00 00 00 00 00 00 00
5..wL...........
0118ea1c 64 ea 18 01 f8 7b 08 00 - 20 90 08 00 f8 7b 08 00 d....{..
....{..
0118ea2c f8 7b 08 00 68 ea 18 01 - 2b b3 e8 77 4c 01 00 00
.{..h...+..wL...
0118ea3c ff ff ff ff 00 00 00 00 - b5 23 00 63 4c 01 00 00
.........#.cL...
0118ea4c ff ff ff ff 00 00 00 00 - f8 7b 08 00 3f 24 00 63
.........{..?$.c
0118ea5c 64 ea 18 01 e8 00 00 00 - 00 00 00 00 e0 ea 18 01
d...............
0118ea6c ed 3b 00 63 02 00 00 00 - 90 6d 06 63 fe b9 00 63
.;.c.....m.c...c
0118ea7c 02 00 00 00 90 6d 06 63 - ba b9 00 63 02 00 00 00
.....m.c...c....
0118ea8c 90 6d 06 63 20 90 08 00 - 8c b9 00 63 60 6d 06 63 .m.c
......c`m.c
0118ea9c 73 c8 01 63 01 00 00 00 - 08 64 4b 02 28 c9 4d 02
s..c.....dK.(.M.
0118eaac ff ff ff ff ff ff ff 7f - d0 be db 01 0d 94 c3 01
................
0118eabc 00 00 00 00 02 00 00 00 - 01 00 00 00 0a eb 18 01
................
0118eacc 00 eb 18 01 a0 be 0a 00 - 08 20 10 00 3f eb 18 01 .........
..?...
0118eadc 2a eb 18 01 10 ff 18 01 - b6 ce 01 63 08 64 4b 02
*..........c.dK.
0118eaec 50 9b 11 00 00 eb 18 01 - 02 00 00 00 58 c8 4d 02
P...........X.M.
0118eafc 08 64 4b 02 72 37 44 30 - 41 46 31 44 44 00 42 44
.dK.r7D0AF1DD.BD
0118eb0c 73 76 4d 6a 6b 30 34 6d - 40 69 33 76 57 77 73 42
svMjk04m@i3vWwsB
0118eb1c 6b 2b 2b 3a 00 20 64 6f - 6d 61 69 6e 00 2e 6d 6f k++:.
domain..mo
0118eb2c 63 2e 6b 63 69 6c 63 65 - 75 6c 61 76 00 20 70 61
c.kcilceulav. pa
0118eb3c 74 68 00 2f 00 00 00 00 - 03 00 00 00 98 eb 18 01
th./............

State Dump for Thread Id 0x648

eax=012de6c0 ebx=011cff88 ecx=012de69c edx=00000000 esi=77f8377b
edi=0000026c
eip=77f83786 esp=011cff6c ebp=011cff90 iopl=0 nv up ei ng nz
ac po cy
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000297


function: NtWaitForSingleObject
77f8377b b8ea000000 mov eax,0xea
77f83780 8d542404 lea edx,[esp+0x4]
ss:01c4d53f=????????
77f83784 cd2e int 2e
77f83786 c20c00 ret 0xc

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
011CFF90 77E8B32B 0000026C 00007530 00000000 63045F68
ntdll!NtWaitForSingleObject
011CFFEC 00000000 00000000 00000000 00000000 00000000
kernel32!WaitForSingleObject

State Dump for Thread Id 0x518

eax=00000000 ebx=00050003 ecx=000b9bf8 edx=00000000 esi=0007e320
edi=00000100
eip=77f83bb8 esp=0120fe28 ebp=0120ff74 iopl=0 nv up ei pl nz
na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000202


function: NtReplyWaitReceivePortEx
77f83bad b8ac000000 mov eax,0xac
77f83bb2 8d542404 lea edx,[esp+0x4]
ss:01c8d3fb=????????
77f83bb6 cd2e int 2e
77f83bb8 c21400 ret 0x14

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0120FF74 77D5878E 77D42363 0007E320 00000000 00000000
ntdll!NtReplyWaitReceivePortEx
0120FFA8 77D3F139 0007C060 0120FFEC 77E8B2D8 000AD090
rpcrt4!TowerConstruct
0120FFB4 77E8B2D8 000AD090 00000000 00000000 000AD090
rpcrt4!I RpcServerInqTransportType
0120FFEC 00000000 00000000 00000000 00000000 00000000
kernel32!lstrcmpiW

State Dump for Thread Id 0x604

eax=77ab3e61 ebx=00000102 ecx=00420043 edx=00000000 esi=77f8318c
edi=0124ff74
eip=77f83197 esp=0124ff60 ebp=0124ff7c iopl=0 nv up ei pl nz
na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000206


function: NtDelayExecution
77f8318c b832000000 mov eax,0x32
77f83191 8d542404 lea edx,[esp+0x4]
ss:01ccd533=????????
77f83195 cd2e int 2e
77f83197 c20800 ret 0x8

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0124FF7C 77EA9D5F 0000EA60 00000000 77AB7DC8 0000EA60
ntdll!NtDelayExecution
00007530 00000000 00000000 00000000 00000000 00000000 kernel32!Sleep

State Dump for Thread Id 0x65c

eax=00000000 ebx=00050003 ecx=0007e65c edx=00000000 esi=0007e320
edi=00000100
eip=77f83bb8 esp=0128fe28 ebp=0128ff74 iopl=0 nv up ei pl nz
na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000206


function: NtReplyWaitReceivePortEx
77f83bad b8ac000000 mov eax,0xac
77f83bb2 8d542404 lea edx,[esp+0x4]
ss:01d0d3fb=????????
77f83bb6 cd2e int 2e
77f83bb8 c21400 ret 0x14

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0128FF74 77D5878E 77D42363 0007E320 00000000 00000000
ntdll!NtReplyWaitReceivePortEx
0128FFA8 77D3F139 0007C060 0128FFEC 77E8B2D8 000ABB48
rpcrt4!TowerConstruct
0128FFB4 77E8B2D8 000ABB48 00000000 00000000 000ABB48
rpcrt4!I RpcServerInqTransportType
0128FFEC 00000000 77D3F121 000ABB48 00000000 00000000
kernel32!lstrcmpiW

*----> Raw Stack Dump <----*
0128fe28 c4 8e d5 77 00 01 00 00 - 54 ff 28 01 00 00 00 00
...w....T.(.....
0128fe38 18 c1 0b 00 58 ff 28 01 - e8 bf 07 00 e8 76 0b 00
....X.(......v..
0128fe48 6d 31 f8 77 00 00 00 00 - 00 00 00 00 00 00 00 00
m1.w............
0128fe58 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
0128fe68 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
0128fe78 00 00 00 00 00 00 00 00 - 00 00 00 00 01 00 00 00
................
0128fe88 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
0128fe98 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
0128fea8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
0128feb8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
0128fec8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
0128fed8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
0128fee8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
0128fef8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
0128ff08 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
0128ff18 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
0128ff28 00 00 00 00 20 c2 43 81 - 20 05 4c 81 00 00 00 00 .... .C.
.L.....
0128ff38 b0 06 4c 81 60 7c 12 bc - 46 02 00 00 a4 da 42 80
..L.`|..F.....B.
0128ff48 10 2f 06 80 80 06 4c 81 - 20 05 4c 81 03 00 05 00 ./....L.
.L.....
0128ff58 00 a2 2f 4d ff ff ff ff - 50 fe 28 01 00 00 02 80
../M....P.(.....

State Dump for Thread Id 0x5d4

eax=0000ffff ebx=000e50e8 ecx=0250e5fc edx=00000000 esi=74fe93a0
edi=00000000
eip=77f837dc esp=0140ff84 ebp=0140ffb4 iopl=0 nv up ei pl nz
na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000202


function: ZwRemoveIoCompletion
77f837d1 b8a8000000 mov eax,0xa8
77f837d6 8d542404 lea edx,[esp+0x4]
ss:01e8d557=????????
77f837da cd2e int 2e
77f837dc c21400 ret 0x14
77f837df 53 push ebx
77f837e0 f7e1 mul ecx
77f837e2 8bd8 mov ebx,eax
77f837e4 8b442408 mov eax,[esp+0x8]
ss:01e8d557=????????
77f837e8 f7642414 mul dword ptr [esp+0x14]
ss:01e8d557=????????
77f837ec 03d8 add ebx,eax
77f837ee 8b442408 mov eax,[esp+0x8]
ss:01e8d557=????????
77f837f2 f7e1 mul ecx
77f837f4 03d3 add edx,ebx
77f837f6 5b pop ebx
77f837f7 c21000 ret 0x10

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0140FFB4 77E8B2D8 74FD8540 7FFDA000 00000000 000E50E8
ntdll!ZwRemoveIoCompletion
0140FFEC 00000000 74FD4766 000E50E8 00000000 00905A4D
kernel32!lstrcmpiW

*----> Raw Stack Dump <----*
0140ff84 b8 47 fd 74 34 03 00 00 - bc ff 40 01 b0 ff 40 01
.G.t4.....@...@.
0140ff94 a4 ff 40 01 28 2c fd 74 - 00 a0 fd 7f 00 00 00 00
..@.(,.t........
0140ffa4 00 00 00 00 1c 00 00 00 - 00 00 fd 74 c8 2d 4c 02
...........t.-L.
0140ffb4 ec ff 40 01 d8 b2 e8 77 - 40 85 fd 74 00 a0 fd 7f
[email protected]@..t....
0140ffc4 00 00 00 00 e8 50 0e 00 - 00 50 fd 7f 64 f7 18 01
.....P...P..d...
0140ffd4 c0 ff 40 01 64 f7 18 01 - ff ff ff ff 6c 13 ed 77
[email protected]
0140ffe4 98 2a e8 77 00 00 00 00 - 00 00 00 00 00 00 00 00
.*.w............
0140fff4 66 47 fd 74 e8 50 0e 00 - 00 00 00 00 4d 5a 90 00
fG.t.P......MZ..
01410004 03 00 00 00 04 00 00 00 - ff ff 00 00 b8 00 00 00
................
01410014 00 00 00 00 40 00 00 00 - 00 00 00 00 00 00 00 00
....@...........
01410024 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
................
01410034 00 00 00 00 00 00 00 00 - c0 00 00 00 0e 1f ba 0e
................
01410044 00 b4 09 cd 21 b8 01 4c - cd 21 54 68 69 73 20 70
....!..L.!This p
01410054 72 6f 67 72 61 6d 20 63 - 61 6e 6e 6f 74 20 62 65 rogram
cannot be
01410064 20 72 75 6e 20 69 6e 20 - 44 4f 53 20 6d 6f 64 65 run in
DOS mode
01410074 2e 0d 0d 0a 24 00 00 00 - 00 00 00 00 44 24 da f8
....$.......D$..
01410084 00 45 b4 ab 00 45 b4 ab - 00 45 b4 ab 00 45 b5 ab
.E...E...E...E..
01410094 55 47 b4 ab 59 66 a7 ab - 10 45 b4 ab 00 45 b4 ab
UG..Yf...E...E..
014100a4 7a 47 b4 ab 56 4d b2 ab - 01 45 b4 ab 52 69 63 68
zG..VM...E..Rich
014100b4 00 45 b4 ab 00 00 00 00 - 00 00 00 00 50 45 00 00
.E..........PE..

State Dump for Thread Id 0x64c

eax=00000015 ebx=01afff74 ecx=0000001a edx=00000000 esi=77f8377b
edi=0000032c
eip=77f83786 esp=01afff58 ebp=01afff7c iopl=0 nv up ei ng nz
ac pe cy
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000293
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top