Beth - I rechecked, and as I suspected, I had already deleted the wordtoys
since that log was generated. During my initial efforts to resolve my
problem, I tried deleting lots of things, including the entire office
installation. Here's my latest errors from log which might point out
something useful to you.
Application exception occurred:
App: C:\Program Files\Microsoft Office\Office\WINWORD.EXE (pid=3612)
When: 10/27/2004 @ 00:32:28.988
Exception number: c0000005 (access violation)
*----> System Information <----*
Computer Name: D3JJFF31
User Name: Susan
Terminal Session Id: 0
Number of Processors: 1
Processor Type: x86 Family 15 Model 2 Stepping 7
Windows Version: 5.1
Current Build: 2600
Service Pack: 1
Current Type: Uniprocessor Free
Registered Organization:
Registered Owner: Susan
*----> Task List <----*
0 System Process
4 Error 0xD0000022
956 Error 0xD0000022
1060 Error 0xD0000022
1084 Error 0xD0000022
1128 Error 0xD0000022
1140 Error 0xD0000022
1324 Error 0xD0000022
1524 Error 0xD0000022
1776 Error 0xD0000022
1836 Error 0xD0000022
412 Error 0xD0000022
544 Error 0xD0000022
556 Error 0xD0000022
640 Error 0xD0000022
668 Error 0xD0000022
688 Error 0xD0000022
736 Error 0xD0000022
812 Error 0xD0000022
884 Error 0xD0000022
1376 Error 0xD0000022
1392 Error 0xD0000022
1416 Error 0xD0000022
224 Error 0xD0000022
1552 Apoint.exe
1652 atiptaxx.exe
1664 DSentry.exe
1704 quickset.exe
1736 ccApp.exe
1196 Error 0xD0000022
1816 RoboTaskBarIcon.exe
1844 anagram.exe
2112 Apntex.exe
2764 Error 0xD0000022
252 explorer.exe
3080 YahooPOPs.exe
1612 ntvdm.exe
1520 Error 0xD0000022
3612 WINWORD.EXE
3872 drwtsn32.exe
*----> Module List <----*
(00000000015f0000 - 000000000160b000: C:\WINDOWS\System32\CSCDLL.dll
(0000000028b70000 - 0000000028b87000: C:\Program Files\Microsoft
Office\Office\msohev.dll
(0000000030000000 - 0000000030871000: C:\Program Files\Microsoft
Office\Office\WINWORD.EXE
(00000000308c0000 - 0000000030e1d000: C:\Program Files\Microsoft
Office\Office\MSO9.DLL
(000000004f510000 - 000000004fd21000: C:\WINDOWS\system32\SHELL32.dll
(0000000055100000 - 00000000552e0000: C:\WINDOWS\AppPatch\AcGenral.DLL
(000000005ad70000 - 000000005ada4000: C:\WINDOWS\System32\UxTheme.dll
(000000005cb70000 - 000000005cb95000: C:\WINDOWS\System32\ShimEng.dll
(0000000060040000 - 0000000060049000: C:\Program
Files\Textual\anagram\MessageHook.dll
(0000000070a70000 - 0000000070ad9000: C:\WINDOWS\system32\SHLWAPI.dll
(0000000071950000 - 0000000071a34000:
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.1579_x-ww_7bbf8d08\comctl32.dll
(0000000071c20000 - 0000000071c6e000: C:\WINDOWS\System32\NETAPI32.dll
(0000000073000000 - 0000000073023000: C:\WINDOWS\System32\WINSPOOL.DRV
(0000000074720000 - 0000000074764000: C:\WINDOWS\System32\msctf.dll
(0000000074e30000 - 0000000074e9a000: C:\WINDOWS\System32\riched20.dll
(0000000075a70000 - 0000000075b15000: C:\WINDOWS\system32\USERENV.dll
(0000000075e90000 - 0000000075f3d000: C:\WINDOWS\System32\SXS.DLL
(0000000075f40000 - 0000000075f5f000: C:\WINDOWS\system32\appHelp.dll
(0000000076400000 - 0000000076601000: C:\WINDOWS\System32\msi.dll
(0000000076620000 - 000000007666e000: C:\WINDOWS\System32\cscui.dll
(0000000076670000 - 0000000076757000: C:\WINDOWS\System32\SETUPAPI.dll
(0000000076980000 - 0000000076987000: C:\WINDOWS\System32\LINKINFO.dll
(0000000076990000 - 00000000769b4000: C:\WINDOWS\System32\ntshrui.dll
(0000000076b20000 - 0000000076b35000: C:\WINDOWS\System32\ATL.DLL
(0000000076b40000 - 0000000076b6c000: C:\WINDOWS\System32\WINMM.dll
(0000000077050000 - 0000000077115000: C:\WINDOWS\System32\COMRes.dll
(0000000077120000 - 00000000771ab000: C:\WINDOWS\system32\OLEAUT32.dll
(00000000771b0000 - 00000000772d4000: C:\WINDOWS\system32\ole32.dll
(0000000077340000 - 00000000773cb000: C:\WINDOWS\system32\comctl32.dll
(0000000077be0000 - 0000000077bf4000: C:\WINDOWS\System32\MSACM32.dll
(0000000077c00000 - 0000000077c07000: C:\WINDOWS\system32\VERSION.dll
(0000000077c10000 - 0000000077c63000: C:\WINDOWS\system32\msvcrt.dll
(0000000077d40000 - 0000000077dcc000: C:\WINDOWS\system32\USER32.dll
(0000000077dd0000 - 0000000077e5d000: C:\WINDOWS\system32\ADVAPI32.dll
(0000000077e60000 - 0000000077f46000: C:\WINDOWS\system32\kernel32.dll
(0000000077f50000 - 0000000077ff7000: C:\WINDOWS\System32\ntdll.dll
(0000000078000000 - 0000000078087000: C:\WINDOWS\system32\RPCRT4.dll
(000000007c890000 - 000000007c911000: C:\WINDOWS\System32\CLBCATQ.DLL
(000000007f000000 - 000000007f041000: C:\WINDOWS\system32\GDI32.dll
*----> State Dump for Thread Id 0x9a0 <----*
eax=0000000c ebx=01500000 ecx=0000e054 edx=0041f4c8 esi=000003f5 edi=0041e054
eip=308e0a2e esp=0013c684 ebp=01501474 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\Program Files\Microsoft Office\Office\MSO9.DLL -
function: MSO9!_MsoPvFree
308e0a09 89442420 mov [esp+0x20],eax
308e0a0d 8d1438 lea edx,[eax+edi]
308e0a10 3bd1 cmp edx,ecx
308e0a12 0f84b0000000 je MSO9!_MsoPvFree+0x1d0 (308e0ac8)
308e0a18 668b03 mov ax,[ebx]
308e0a1b 8bcf mov ecx,edi
308e0a1d 81e1ffff0000 and ecx,0xffff
308e0a23 66894500 mov [ebp],ax
308e0a27 66897d02 mov [ebp+0x2],di
308e0a2b 66892b mov [ebx],bp
FAULT ->308e0a2e 66897c29fe mov [ecx+ebp-0x2],di
ds:0023:0150f4c6=????
308e0a33 8b442418 mov eax,[esp+0x18]
308e0a37 5f pop edi
308e0a38 5e pop esi
308e0a39 5d pop ebp
308e0a3a 85c0 test eax,eax
308e0a3c 5b pop ebx
308e0a3d 0f8532010000 jne MSO9!_MsoPvFree+0x27d (308e0b75)
308e0a43 83c40c add esp,0xc
308e0a46 c20800 ret 0x8
308e0a49 680851d630 push 0x30d65108
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be
wrong.
ChildEBP RetAddr Args to Child
01501474 001014c0 00000024 0079004d 00440020 MSO9!_MsoPvFree+0x136
e054000c 00000000 00000000 00000000 00000000 0x1014c0
*----> Raw Stack Dump <----*
000000000013c684 01 00 00 00 60 f1 41 00 - e4 c6 13 00 50 e0 41 00
.....`.A.....P.A.
000000000013c694 74 14 50 01 00 00 15 00 - 01 00 00 00 f5 1e 8e 30
t.P............0
000000000013c6a4 74 14 00 00 54 e0 41 00 - 72 f3 a6 30 78 14 50 01
t...T.A.r..0x.P.
000000000013c6b4 04 00 00 00 60 f1 41 00 - 1e f3 a6 30 60 f1 41 00
.....`.A....0`.A.
000000000013c6c4 4f 47 a6 30 05 00 00 00 - 50 e0 41 00 17 46 a6 30
OG.0....P.A..F.0
000000000013c6d4 8c ca 41 00 50 e0 41 00 - f4 57 a6 30 cc bf 41 00
...A.P.A..W.0..A.
000000000013c6e4 5c c8 13 00 43 18 a8 30 - 01 00 00 00 01 80 00 00
\...C..0........
000000000013c6f4 9f ee e7 77 41 00 00 00 - 7f 02 ff ff 00 00 ff ff
....wA...........
000000000013c704 ff ff ff ff 00 00 00 00 - 1b 00 00 00 00 44 d8 5a
..............D.Z
000000000013c714 23 00 ff ff 00 00 00 00 - 00 00 00 00 ff ff 00 00
#...............
000000000013c724 00 00 00 00 00 00 ff ff - 00 00 00 00 00 00 00 00
.................
000000000013c734 ff ff 00 00 00 00 00 00 - 00 00 ff ff 00 00 00 00
.................
000000000013c744 00 00 00 00 00 00 00 00 - 00 00 00 00 00 80 ff 3f
................?
000000000013c754 00 00 00 00 00 00 00 98 - 03 40 00 00 00 00 00 00
..........@......
000000000013c764 00 80 ff 3f 5c c8 13 00 - cc bf 41 00 50 e0 41 00
....?\.....A.P.A.
000000000013c774 1f 00 00 00 e4 c6 13 00 - 51 17 a8 30 68 fe 13 00
.........Q..0h...
000000000013c784 00 00 00 00 30 32 43 56 - 00 00 00 00 a0 b1 bd 00
.....02CV........
000000000013c794 36 f0 8d 30 6c b1 bd 00 - 13 06 8e 30 b8 c7 13 00
6..0l......0....
000000000013c7a4 20 00 00 00 00 00 00 00 - 00 00 00 00 5c c8 13 00
............\...
000000000013c7b4 50 e0 41 00 00 00 00 00 - 00 00 00 00 e4 c6 13 00
P.A.............
*----> State Dump for Thread Id 0x908 <----*
eax=780015dd ebx=001949c0 ecx=77f57f98 edx=00000000 esi=f17ffca0 edi=00000000
eip=7ffe0304 esp=00e3fe28 ebp=00e3ff90 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000202
function: <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 8bd4 mov edx,esp
7ffe0307 0f05 syscall
7ffe0309 c3 ret
7ffe030a 8ac8 mov cl,al
7ffe030c ff1570464d80 call dword ptr [804d4670]
7ffe0312 8b4510 mov eax,[ebp+0x10]
7ffe0315 33c9 xor ecx,ecx
7ffe0317 663908 cmp [eax],cx
7ffe031a 894dfc mov [ebp-0x4],ecx
7ffe031d 0f84cc000000 je 7ffe03ef
*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\System32\ntdll.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\RPCRT4.dll -
WARNING: Stack unwind information not available. Following frames may be
wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\GDI32.dll -
ChildEBP RetAddr Args to Child
00e3fe24 77f5c084 780016a4 000001a4 00e3ff80 *SharedUserSystemCall+0xc (FPO:
[0,0,0])
00e3ff90 78001601 780019d4 00174740 77fa88f0
ntdll!NtReplyWaitReceivePortEx+0xc
0017c280 ffffffff 000001b4 000001b8 00000000 RPCRT4+0x1601
00000000 00000000 00000000 00000000 00000000 0xffffffff
*----> Raw Stack Dump <----*
0000000000e3fe28 84 c0 f5 77 a4 16 00 78 - a4 01 00 00 80 ff e3 00
....w...x........
0000000000e3fe38 00 00 00 00 c0 49 19 00 - 58 ff e3 00 d6 ca 58 80
......I..X.....X.
0000000000e3fe48 40 00 00 00 98 93 d4 82 - 00 c9 a7 e1 93 07 00 00
@...............
0000000000e3fe58 92 07 00 00 6c 58 fc 82 - a8 0d 5b 82 00 00 00 00
.....lX....[.....
0000000000e3fe68 e8 f7 5d 82 00 00 00 00 - 00 00 00 00 10 fa e1 82
...].............
0000000000e3fe78 05 00 00 00 00 4c 4f 80 - 00 00 00 00 00 00 00 00
......LO.........
0000000000e3fe88 a8 0d 5b 82 4f 11 58 80 - 05 00 00 00 05 00 00 00
...[.O.X.........
0000000000e3fe98 b8 9a 92 e2 68 5b 03 e1 - 02 00 00 00 fe ff f8 00
.....h[..........
0000000000e3fea8 a0 72 a7 e1 b8 9a 92 e2 - 5b 05 58 00 00 00 00 00
..r......[.X.....
0000000000e3feb8 00 00 00 00 5c 00 52 00 - ff ff ff ff 2c fc 7f f1
.....\.R.....,...
0000000000e3fec8 9e 0f 58 80 e9 02 00 00 - 34 00 00 c0 98 93 d4 82
...X.....4.......
0000000000e3fed8 48 04 01 e1 3c 94 d4 82 - d0 1c b1 82 bb 89 4e 80
H...<.........N.
0000000000e3fee8 04 fc 7f f1 04 00 00 00 - 00 00 00 00 d0 1c b1 82
.................
0000000000e3fef8 dc 41 ef 82 18 02 ea 82 - 10 00 f8 00 55 00 00 00
..A..........U...
0000000000e3ff08 ff 00 00 00 00 00 00 00 - 28 fc 7f f1 d8 88 4e 80
.........(.....N.
0000000000e3ff18 00 e0 46 82 bc 41 d8 82 - 46 02 00 00 2c cd 4e 80
...F..A..F...,.N.
0000000000e3ff28 8c 41 d8 82 20 40 d8 82 - 54 40 d8 82 ff ff ff ff .A..
@..T@......
0000000000e3ff38 55 00 00 00 c1 06 59 80 - 2f 16 00 78 60 ff e3 00
U.....Y./..x`...
0000000000e3ff48 4a 16 00 78 80 49 17 00 - b8 b9 17 00 80 c2 17 00
J..x.I..........
0000000000e3ff58 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff
.../M.....]......
Application exception occurred:
App: C:\Program Files\Microsoft Office\Office\WINWORD.EXE (pid=108)
When: 10/27/2004 @ 01:53:35.947
Exception number: c0000005 (access violation)
*----> System Information <----*
Computer Name: D3JJFF31
User Name: Susan
Terminal Session Id: 0
Number of Processors: 1
Processor Type: x86 Family 15 Model 2 Stepping 7
Windows Version: 5.1
Current Build: 2600
Service Pack: 1
Current Type: Uniprocessor Free
Registered Organization:
Registered Owner: Susan
*----> Task List <----*
0 System Process
4 Error 0xD0000022
956 Error 0xD0000022
1060 Error 0xD0000022
1084 Error 0xD0000022
1128 Error 0xD0000022
1140 Error 0xD0000022
1324 Error 0xD0000022
1524 Error 0xD0000022
1776 Error 0xD0000022
1836 Error 0xD0000022
412 Error 0xD0000022
544 Error 0xD0000022
556 Error 0xD0000022
640 Error 0xD0000022
668 Error 0xD0000022
688 Error 0xD0000022
736 Error 0xD0000022
812 Error 0xD0000022
884 Error 0xD0000022
1376 Error 0xD0000022
1392 Error 0xD0000022
1416 Error 0xD0000022
224 Error 0xD0000022
1552 Apoint.exe
1652 atiptaxx.exe
1664 DSentry.exe
1704 quickset.exe
1736 ccApp.exe
1196 Error 0xD0000022
1816 RoboTaskBarIcon.exe
1844 anagram.exe
2112 Apntex.exe
2764 Error 0xD0000022
252 explorer.exe
3080 YahooPOPs.exe
1612 ntvdm.exe
3300 OUTLOOK.EXE
108 WINWORD.EXE
3180 WINWORD.EXE
876 drwtsn32.exe
*----> Module List <----*
(00000000015f0000 - 000000000160b000: C:\WINDOWS\System32\CSCDLL.dll
(0000000028b70000 - 0000000028b87000: C:\Program Files\Microsoft
Office\Office\msohev.dll
(0000000030000000 - 0000000030871000: C:\Program Files\Microsoft
Office\Office\WINWORD.EXE
(00000000308c0000 - 0000000030e1d000: C:\Program Files\Microsoft
Office\Office\MSO9.DLL
(000000004f510000 - 000000004fd21000: C:\WINDOWS\system32\SHELL32.dll
(0000000055100000 - 00000000552e0000: C:\WINDOWS\AppPatch\AcGenral.DLL
(000000005ad70000 - 000000005ada4000: C:\WINDOWS\System32\UxTheme.dll
(000000005cb70000 - 000000005cb95000: C:\WINDOWS\System32\ShimEng.dll
(0000000060040000 - 0000000060049000: C:\Program
Files\Textual\anagram\MessageHook.dll
(0000000070a70000 - 0000000070ad9000: C:\WINDOWS\system32\SHLWAPI.dll
(0000000071950000 - 0000000071a34000:
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.1579_x-ww_7bbf8d08\comctl32.dll
(0000000071c20000 - 0000000071c6e000: C:\WINDOWS\System32\NETAPI32.dll
(0000000073000000 - 0000000073023000: C:\WINDOWS\System32\WINSPOOL.DRV
(0000000074720000 - 0000000074764000: C:\WINDOWS\System32\msctf.dll
(0000000074e30000 - 0000000074e9a000: C:\WINDOWS\System32\riched20.dll
(0000000075a70000 - 0000000075b15000: C:\WINDOWS\system32\USERENV.dll
(0000000075e90000 - 0000000075f3d000: C:\WINDOWS\System32\SXS.DLL
(0000000075f40000 - 0000000075f5f000: C:\WINDOWS\system32\appHelp.dll
(0000000076400000 - 0000000076601000: C:\WINDOWS\System32\msi.dll
(0000000076620000 - 000000007666e000: C:\WINDOWS\System32\cscui.dll
(0000000076670000 - 0000000076757000: C:\WINDOWS\System32\SETUPAPI.dll
(0000000076980000 - 0000000076987000: C:\WINDOWS\System32\LINKINFO.dll
(0000000076990000 - 00000000769b4000: C:\WINDOWS\System32\ntshrui.dll
(0000000076b20000 - 0000000076b35000: C:\WINDOWS\System32\ATL.DLL
(0000000076b40000 - 0000000076b6c000: C:\WINDOWS\System32\WINMM.dll
(0000000077050000 - 0000000077115000: C:\WINDOWS\System32\COMRes.dll
(0000000077120000 - 00000000771ab000: C:\WINDOWS\system32\OLEAUT32.dll
(00000000771b0000 - 00000000772d4000: C:\WINDOWS\system32\ole32.dll
(0000000077340000 - 00000000773cb000: C:\WINDOWS\system32\comctl32.dll
(0000000077be0000 - 0000000077bf4000: C:\WINDOWS\System32\MSACM32.dll
(0000000077c00000 - 0000000077c07000: C:\WINDOWS\system32\VERSION.dll
(0000000077c10000 - 0000000077c63000: C:\WINDOWS\system32\msvcrt.dll
(0000000077d40000 - 0000000077dcc000: C:\WINDOWS\system32\USER32.dll
(0000000077dd0000 - 0000000077e5d000: C:\WINDOWS\system32\ADVAPI32.dll
(0000000077e60000 - 0000000077f46000: C:\WINDOWS\system32\kernel32.dll
(0000000077f50000 - 0000000077ff7000: C:\WINDOWS\System32\ntdll.dll
(0000000078000000 - 0000000078087000: C:\WINDOWS\system32\RPCRT4.dll
(000000007c890000 - 000000007c911000: C:\WINDOWS\System32\CLBCATQ.DLL
(000000007f000000 - 000000007f041000: C:\WINDOWS\system32\GDI32.dll
*----> State Dump for Thread Id 0xc34 <----*
eax=0000000c ebx=01510000 ecx=0000e110 edx=0041f584 esi=000003f5 edi=0041e110
eip=308e0a2e esp=0013c684 ebp=01511474 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\Program Files\Microsoft Office\Office\MSO9.DLL -
function: MSO9!_MsoPvFree
308e0a09 89442420 mov [esp+0x20],eax
308e0a0d 8d1438 lea edx,[eax+edi]
308e0a10 3bd1 cmp edx,ecx
308e0a12 0f84b0000000 je MSO9!_MsoPvFree+0x1d0 (308e0ac8)
308e0a18 668b03 mov ax,[ebx]
308e0a1b 8bcf mov ecx,edi
308e0a1d 81e1ffff0000 and ecx,0xffff
308e0a23 66894500 mov [ebp],ax
308e0a27 66897d02 mov [ebp+0x2],di
308e0a2b 66892b mov [ebx],bp
FAULT ->308e0a2e 66897c29fe mov [ecx+ebp-0x2],di
ds:0023:0151f582=????
308e0a33 8b442418 mov eax,[esp+0x18]
308e0a37 5f pop edi
308e0a38 5e pop esi
308e0a39 5d pop ebp
308e0a3a 85c0 test eax,eax
308e0a3c 5b pop ebx
308e0a3d 0f8532010000 jne MSO9!_MsoPvFree+0x27d (308e0b75)
308e0a43 83c40c add esp,0xc
308e0a46 c20800 ret 0x8
308e0a49 680851d630 push 0x30d65108
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be
wrong.
ChildEBP RetAddr Args to Child
01511474 001014c0 00000024 0079004d 00440020 MSO9!_MsoPvFree+0x136
e110000c 00000000 00000000 00000000 00000000 0x1014c0
*----> Raw Stack Dump <----*
000000000013c684 01 00 00 00 1c f2 41 00 - e4 c6 13 00 0c e1 41 00
.......A.......A.
000000000013c694 74 14 51 01 00 00 15 00 - 01 00 00 00 f5 1e 8e 30
t.Q............0
000000000013c6a4 74 14 00 00 10 e1 41 00 - 72 f3 a6 30 78 14 51 01
t.....A.r..0x.Q.
000000000013c6b4 04 00 00 00 1c f2 41 00 - 1e f3 a6 30 1c f2 41 00
.......A....0..A.
000000000013c6c4 4f 47 a6 30 05 00 00 00 - 0c e1 41 00 17 46 a6 30
OG.0......A..F.0
000000000013c6d4 98 ca 41 00 0c e1 41 00 - f4 57 a6 30 d8 bf 41 00
...A...A..W.0..A.
000000000013c6e4 5c c8 13 00 43 18 a8 30 - 01 00 00 00 01 80 00 00
\...C..0........
000000000013c6f4 9f ee e7 77 41 00 00 00 - 7f 02 ff ff 00 00 ff ff
....wA...........
000000000013c704 ff ff ff ff 00 00 00 00 - ff bb 00 00 88 d6 da e1
.................
000000000013c714 84 e7 ff ff 9f 8b 98 bf - 60 07 99 bf ff ff 67 61
.........`.....ga
000000000013c724 83 bf 10 ec b0 f0 00 00 - 10 c8 67 bc 48 4e e9 e2
...........g.HN..
000000000013c734 43 00 72 00 6f 00 67 00 - 72 00 61 00 69 00 6c 00
C.r.o.g.r.a.i.l.
000000000013c744 65 00 73 00 5c 00 72 00 - 6f 00 73 00 6f 00 66 00
e.s.\.r.o.s.o.f.
000000000013c754 66 00 66 00 69 00 63 00 - 65 00 66 00 69 00 63 00
f.f.i.c.e.f.i.c.
000000000013c764 65 00 5c 00 5c c8 13 00 - d8 bf 41 00 0c e1 41 00
e.\.\.....A...A.
000000000013c774 1f 00 00 00 e4 c6 13 00 - 51 17 a8 30 68 fe 13 00
.........Q..0h...
000000000013c784 00 00 00 00 30 32 43 56 - 00 00 00 00 24 ad bd 00
.....02CV....$...
000000000013c794 36 f0 8d 30 f0 ac bd 00 - 13 06 8e 30 b8 c7 13 00
6..0.......0....
000000000013c7a4 20 00 00 00 00 00 00 00 - 00 00 00 00 5c c8 13 00
............\...
000000000013c7b4 0c e1 41 00 00 00 00 00 - 00 00 00 00 e4 c6 13 00
...A.............
*----> State Dump for Thread Id 0xe70 <----*
eax=780015dd ebx=00193d48 ecx=77f57f98 edx=00000000 esi=00000100 edi=00000000
eip=7ffe0304 esp=00e3fe28 ebp=00e3ff90 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000202
function: <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 8bd4 mov edx,esp
7ffe0307 0f05 syscall
7ffe0309 c3 ret
7ffe030a 8ac8 mov cl,al
7ffe030c ff1570464d80 call dword ptr [804d4670]
7ffe0312 8b4510 mov eax,[ebp+0x10]
7ffe0315 33c9 xor ecx,ecx
7ffe0317 663908 cmp [eax],cx
7ffe031a 894dfc mov [ebp-0x4],ecx
7ffe031d 0f84cc000000 je 7ffe03ef
*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\System32\ntdll.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\RPCRT4.dll -
WARNING: Stack unwind information not available. Following frames may be
wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\GDI32.dll -
ChildEBP RetAddr Args to Child
00e3fe24 77f5c084 780016a4 000001a4 00e3ff80 *SharedUserSystemCall+0xc (FPO:
[0,0,0])
00e3ff90 78001601 780019d4 00174740 77fa88f0
ntdll!NtReplyWaitReceivePortEx+0xc
0017c280 ffffffff 000001b4 000001b8 00000000 RPCRT4+0x1601
00000000 00000000 00000000 00000000 00000000 0xffffffff
*----> Raw Stack Dump <----*
0000000000e3fe28 84 c0 f5 77 a4 16 00 78 - a4 01 00 00 80 ff e3 00
....w...x........
0000000000e3fe38 00 00 00 00 48 3d 19 00 - 60 ff e3 00 d6 ca 58 80
.....H=..`.....X.
0000000000e3fe48 40 00 00 00 30 e9 dc 82 - 10 34 03 e3 9f 08 00 00
@...0....4......
0000000000e3fe58 9e 08 00 00 6c 58 fc 82 - 78 f9 ad 82 01 00 00 00
.....lX..x.......
0000000000e3fe68 58 9e a5 82 00 00 00 00 - 00 00 00 00 c0 78 a6 82
X............x..
0000000000e3fe78 05 00 00 00 00 4c 4f 80 - 00 00 00 00 03 00 00 00
......LO.........
0000000000e3fe88 78 f9 ad 82 4f 11 58 80 - 05 00 00 00 05 00 00 00
x...O.X.........
0000000000e3fe98 d0 2d 04 e1 68 5b 03 e1 - 02 00 00 00 fe ff f8 00
..-..h[..........
0000000000e3fea8 48 aa f3 e1 d0 2d 04 e1 - 5b 05 58 00 00 00 00 00
H....-..[.X.....
0000000000e3feb8 00 00 00 00 5c 00 52 00 - ff ff ff ff 2c ec 56 f1
.....\.R.....,.V.
0000000000e3fec8 9e 0f 58 80 e9 02 00 00 - 34 00 00 c0 30 e9 dc 82
...X.....4...0...
0000000000e3fed8 48 04 01 e1 d4 e9 dc 82 - 08 10 5d 82 bb 89 4e 80
H.........]...N.
0000000000e3fee8 04 ec 56 f1 04 00 00 00 - 00 00 00 00 08 10 5d 82
...V...........].
0000000000e3fef8 dc 41 ef 82 30 3d ef 82 - 10 00 f8 00 55 00 00 00
..A..0=......U...
0000000000e3ff08 ff 00 00 00 00 00 00 00 - 28 ec 56 f1 d8 88 4e 80
.........(.V...N.
0000000000e3ff18 00 a0 38 82 44 78 4f 82 - 46 02 00 00 2c cd 4e 80
...8.DxO.F...,.N.
0000000000e3ff28 14 78 4f 82 a8 76 4f 82 - dc 76 4f 82 ff ff ff ff
..xO..vO..vO.....
0000000000e3ff38 55 00 00 00 c1 06 59 80 - 2f 16 00 78 60 ff e3 00
U.....Y./..x`...
0000000000e3ff48 4a 16 00 78 80 49 17 00 - b8 b9 17 00 80 c2 17 00
J..x.I..........
0000000000e3ff58 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff
.../M.....]......
*----> State Dump for Thread Id 0x768 <----*
eax=00000000 ebx=00007530 ecx=00f3ffb0 edx=00000000 esi=00000000 edi=00f3ff60
eip=7ffe0304 esp=00f3ff20 ebp=00f3ff78 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000202
function: <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 8bd4 mov edx,esp
7ffe0307 0f05 syscall
7ffe0309 c3 ret
7ffe030a 8ac8 mov cl,al
7ffe030c ff1570464d80 call dword ptr [804d4670]
7ffe0312 8b4510 mov eax,[ebp+0x10]
7ffe0315 33c9 xor ecx,ecx
7ffe0317 663908 cmp [eax],cx
7ffe031a 894dfc mov [ebp-0x4],ecx
7ffe031d 0f84cc000000 je 7ffe03ef
*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for
C:\WINDOWS\system32\kernel32.dll -
WARNING: Stack unwind information not available. Following frames may be
wrong.
ChildEBP RetAddr Args to Child
00f3ff1c 77f5b7f4 77e7a2cd 00000000 00f3ff44 *SharedUserSystemCall+0xc (FPO:
[0,0,0])
00f3ff78 77e61bf5 0000ea60 00000000 771c15f8 ntdll!ZwDelayExecution+0xc
00000000 00000000 00000000 00000000 00000000 kernel32!Sleep+0xb
*----> Raw Stack Dump <----*
0000000000f3ff20 f4 b7 f5 77 cd a2 e7 77 - 00 00 00 00 44 ff f3 00
....w...w....D...
0000000000f3ff30 f5 a4 e7 77 88 e1 2b 77 - 30 75 00 00 00 00 00 00
....w..+w0u......
0000000000f3ff40 44 ff f3 00 00 ba 3c dc - ff ff ff ff 14 00 00 00
D.....<.........
0000000000f3ff50 01 00 00 00 00 00 00 00 - 00 00 00 00 10 00 00 00
.................
0000000000f3ff60 30 ff f3 00 12 00 14 00 - dc ff f3 00 e5 b2 e9 77
0..............w
0000000000f3ff70 28 3a e8 77 00 00 00 00 - 00 00 00 00 f5 1b e6 77
.w...........w
0000000000f3ff80 60 ea 00 00 00 00 00 00 - f8 15 1c 77 60 ea 00 00
`..........w`...
0000000000f3ff90 78 3e 19 00 aa 7e 1e 77 - 00 00 00 00 00 00 1b 77
x>...~.w.......w
0000000000f3ffa0 78 3e 19 00 78 3e 19 00 - ec ff f3 00 09 7f 1e 77
x>..x>.........w
0000000000f3ffb0 78 01 15 00 78 01 15 00 - 8e d2 e7 77 78 3e 19 00
x...x......wx>..
0000000000f3ffc0 78 01 15 00 78 01 15 00 - 78 3e 19 00 e0 ec 55 f1
x...x...x>....U.
0000000000f3ffd0 00 c0 fd 7f c0 ff f3 00 - 07 00 00 00 ff ff ff ff
.................
0000000000f3ffe0 e5 b2 e9 77 70 a8 e8 77 - 00 00 00 00 00 00 00 00
....wp..w........
0000000000f3fff0 00 00 00 00 ef 7e 1e 77 - 78 3e 19 00 00 00 00 00
......~.wx>......
0000000000f40000 34 6f 40 76 00 80 f8 03 - 01 00 00 00 44 02 00 00
[email protected]...
0000000000f40010 74 96 8e 30 00 00 00 00 - 00 00 00 00 00 00 00 00
t..0............
0000000000f40020 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000f40030 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000f40040 00 00 00 00 00 00 00 00 - 00 00 00 00 d8 1f b9 00
.................
0000000000f40050 40 9c 7b 30 35 00 40 00 - 04 00 08 00 00 01 00 00
@.{05.@.........