[wINDOWS XP] Pb passage en SP2 - 0xC000021A

jean-marie69 Messages postés 3 Statut Membre -  
jean-marie69 Messages postés 3 Statut Membre -
Bonjour,

Suite au page de Windows XP Pro vers SP2, le lancement de Windows s'arrête sur l'écran bleu avec le message STOP 0xC000021A.

J'ai suivi les préconisations du site support Microsoft https://docs.microsoft.com/fr-fr/troubleshoot/windows-server/performance/troubleshoot-stop-0xc000021a-error et j'ai effectué un dump avec Dr Watson (en mode sans échec) qui donne l'erreur suivante :
Une exception d'application s'est produite :
App : C:\WINDOWS\explorer.exe (pid=1916)
Lorsque : 16/07/2006 @ 15:51:58.515
Numéro d'exception : c0000005 (violation d'accès)

D'ou vient l'erreur et comment la corriger ?

Ci-joint le dump :

Une exception d'application s'est produite :
App : C:\WINDOWS\explorer.exe (pid=1916)
Lorsque : 16/07/2006 @ 15:51:58.515
Numéro d'exception : c0000005 (violation d'accès)

*----> Informations système <----*
Nom ordinateur : JULIA
Nom utilisateur : Julia
ID de la session Terminal : 0
Nombre de processeurs : 1
Type de processeur : x86 Family 15 Model 47 Stepping 2
Version de Windows : 5.1
Numéro actuel : 2600
Service Pack : 1
Type actuel : Uniprocessor Free
Organisation enregistrée :
Propriétaire enregistré : Julia

*----> Liste des tâches <----*
0 System Process
4 System
672 smss.exe
736 csrss.exe
760 winlogon.exe
804 services.exe
816 lsass.exe
984 svchost.exe
1028 svchost.exe
1212 svchost.exe
1272 svchost.exe
1568 spoolsv.exe
1660 alg.exe
1696 mdm.exe
1744 nvsvc32.exe
1824 wdfmgr.exe
1928 xcommsvr.exe
1968 bdss.exe
384 vsserv.exe
448 SOUNDMAN.EXE
740 RUNDLL32.EXE
820 bdmcon.exe
1264 em_exec.exe
1472 realsched.exe
1484 ctfmon.exe
1500 BackWeb-8876480.exe
1716 dslmon.exe
852 wmplayer.exe
2400 wuauclt.exe
1916 explorer.exe
2272 iexplore.exe
944 emule.exe
1880 msmoney.exe
3588 drwtsn32.exe

*----> Liste des modules <----*
(0000000000260000 - 0000000000381000: C:\WINDOWS\system32\ole32.dll
(00000000009f0000 - 00000000009f6000: C:\DOCUME~1\Julia\LOCALS~1\TempIadHide3.dll
(0000000000a10000 - 0000000000a17000: C:\Program Files\Logitech\MouseWare\System\LgWndHk.dll
(0000000001000000 - 00000000010f9000: C:\WINDOWS\explorer.exe
(0000000001140000 - 000000000114b000: C:\Program Files\Fichiers communs\Logitech\Scrolling\LgMsgHk.dll
(0000000001320000 - 00000000015e6000: C:\WINDOWS\System32\msi.dll
(0000000001d90000 - 0000000001d98000: C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
(00000000027b0000 - 00000000027f4000: C:\WINDOWS\System32\NVRSFR.DLL
(00000000070d0000 - 000000000710a000: C:\WINDOWS\System32\WMASF.DLL
(00000000074a0000 - 00000000074b3000: C:\PROGRA~1\WINDOW~2\wmpband.dll
(0000000007510000 - 0000000007a57000: C:\WINDOWS\System32\wmp.dll
(0000000008270000 - 00000000085b4000: C:\WINDOWS\System32\wmploc.dll
(00000000085c0000 - 00000000085d5000: C:\WINDOWS\System32\wmpshell.dll
(00000000086d0000 - 0000000008916000: C:\WINDOWS\System32\WMVCore.DLL
(000000000ffd0000 - 000000000fff3000: C:\WINDOWS\System32\rsaenh.dll
(0000000010000000 - 0000000010036000: C:\WINDOWS\System32\sockspy.dll
(000000001f7b0000 - 000000001f7e1000: C:\WINDOWS\System32\ODBC32.dll
(000000001f850000 - 000000001f868000: C:\WINDOWS\System32\odbcint.dll
(000000005b090000 - 000000005b0c4000: C:\WINDOWS\System32\UxTheme.dll
(000000005b950000 - 000000005b9c2000: C:\WINDOWS\System32\themeui.dll
(000000005ce00000 - 000000005ce23000: C:\WINDOWS\System32\shmedia.dll
(000000005ffb0000 - 000000005ffe0000: C:\WINDOWS\System32\msutb.dll
(000000006c650000 - 000000006c694000: C:\WINDOWS\System32\DUSER.dll
(00000000719e0000 - 00000000719e8000: C:\WINDOWS\system32\WS2HELP.dll
(00000000719f0000 - 0000000071a05000: C:\WINDOWS\system32\WS2_32.dll
(0000000071a60000 - 0000000071a71000: C:\WINDOWS\system32\MPR.dll
(0000000071b50000 - 0000000071b61000: C:\WINDOWS\System32\SAMLIB.dll
(0000000071b70000 - 0000000071b7d000: C:\WINDOWS\System32\ntlanman.dll
(0000000071b80000 - 0000000071bce000: C:\WINDOWS\System32\netapi32.dll
(0000000071be0000 - 0000000071be6000: C:\WINDOWS\System32\NETRAP.dll
(0000000071bf0000 - 0000000071c2c000: C:\WINDOWS\System32\NETUI1.dll
(0000000071c30000 - 0000000071c46000: C:\WINDOWS\System32\NETUI0.dll
(0000000071ca0000 - 0000000071cbb000: C:\WINDOWS\System32\actxprxy.dll
(00000000723a0000 - 00000000723b3000: C:\WINDOWS\System32\browselc.dll
(0000000072c60000 - 0000000072c68000: C:\WINDOWS\System32\msacm32.drv
(0000000072c70000 - 0000000072c79000: C:\WINDOWS\System32\wdmaud.drv
(0000000072f50000 - 0000000072f73000: C:\WINDOWS\System32\WINSPOOL.DRV
(0000000073a80000 - 0000000073a93000: C:\WINDOWS\System32\mscms.dll
(0000000073aa0000 - 0000000073ab5000: C:\WINDOWS\System32\AVIFIL32.dll
(0000000073b20000 - 0000000073b40000: C:\WINDOWS\System32\MSVFW32.dll
(0000000074690000 - 00000000746d4000: C:\WINDOWS\System32\MSCTF.dll
(00000000746e0000 - 000000007476f000: C:\WINDOWS\System32\MLANG.dll
(0000000074a40000 - 0000000074a47000: C:\WINDOWS\System32\POWRPROF.dll
(0000000074a50000 - 0000000074a57000: C:\WINDOWS\System32\CFGMGR32.dll
(0000000074a60000 - 0000000074a69000: C:\WINDOWS\System32\BatMeter.dll
(0000000074a70000 - 0000000074a90000: C:\WINDOWS\System32\stobject.dll
(0000000074aa0000 - 0000000074ae3000: C:\WINDOWS\System32\webcheck.dll
(0000000074af0000 - 0000000074b76000: C:\WINDOWS\System32\printui.dll
(0000000074f30000 - 0000000074f41000: C:\WINDOWS\System32\CLUSAPI.dll
(0000000075570000 - 0000000075604000: C:\WINDOWS\System32\netcfgx.dll
(0000000075900000 - 00000000759f3000: C:\WINDOWS\System32\MSGINA.dll
(0000000075a00000 - 0000000075aa7000: C:\WINDOWS\system32\USERENV.dll
(0000000075be0000 - 0000000075c71000: C:\WINDOWS\System32\jscript.dll
(0000000075c80000 - 0000000075e15000: C:\WINDOWS\system32\NETSHELL.dll
(0000000075e20000 - 0000000075ec8000: C:\WINDOWS\System32\SXS.DLL
(0000000075ed0000 - 0000000075eef000: C:\WINDOWS\system32\appHelp.dll
(0000000075ef0000 - 0000000075ef6000: C:\WINDOWS\System32\drprov.dll
(0000000075f00000 - 0000000075f09000: C:\WINDOWS\System32\davclnt.dll
(0000000075f10000 - 000000007600c000: C:\WINDOWS\System32\BROWSEUI.dll
(0000000076010000 - 0000000076071000: C:\WINDOWS\System32\MSVCP60.dll
(0000000076080000 - 00000000760fa000: C:\WINDOWS\system32\urlmon.dll
(0000000076100000 - 000000007618e000: C:\WINDOWS\System32\shdoclc.dll
(0000000076190000 - 0000000076229000: C:\WINDOWS\system32\WININET.dll
(0000000076230000 - 000000007623f000: C:\WINDOWS\system32\MSASN1.dll
(0000000076250000 - 00000000762dd000: C:\WINDOWS\system32\CRYPT32.dll
(00000000762f0000 - 00000000762ff000: C:\WINDOWS\System32\WINSTA.dll
(0000000076310000 - 0000000076315000: C:\WINDOWS\System32\MSIMG32.dll
(0000000076340000 - 0000000076386000: C:\WINDOWS\system32\comdlg32.dll
(0000000076590000 - 00000000765ab000: C:\WINDOWS\System32\CSCDLL.dll
(00000000765b0000 - 0000000076601000: C:\WINDOWS\System32\cscui.dll
(0000000076610000 - 00000000766fc000: C:\WINDOWS\System32\SETUPAPI.dll
(0000000076920000 - 0000000076927000: C:\WINDOWS\System32\LINKINFO.dll
(0000000076930000 - 0000000076955000: C:\WINDOWS\System32\ntshrui.dll
(0000000076960000 - 0000000076aaa000: C:\WINDOWS\System32\SHDOCVW.dll
(0000000076ac0000 - 0000000076ad5000: C:\WINDOWS\System32\ATL.DLL
(0000000076ae0000 - 0000000076b0e000: C:\WINDOWS\System32\WINMM.dll
(0000000076bb0000 - 0000000076bde000: C:\WINDOWS\system32\credui.dll
(0000000076be0000 - 0000000076c0b000: C:\WINDOWS\System32\WINTRUST.dll
(0000000076c40000 - 0000000076c62000: C:\WINDOWS\system32\IMAGEHLP.dll
(0000000076c90000 - 0000000076caf000: C:\WINDOWS\System32\NTMARTA.DLL
(0000000076d10000 - 0000000076d27000: C:\WINDOWS\system32\iphlpapi.dll
(0000000076dc0000 - 0000000076de5000: C:\WINDOWS\System32\adsldpc.dll
(0000000076df0000 - 0000000076e1f000: C:\WINDOWS\System32\ACTIVEDS.dll
(0000000076e30000 - 0000000076e3d000: C:\WINDOWS\System32\rtutils.dll
(0000000076e40000 - 0000000076e51000: C:\WINDOWS\System32\rasman.dll
(0000000076e60000 - 0000000076e8b000: C:\WINDOWS\System32\TAPI32.dll
(0000000076e90000 - 0000000076ec7000: C:\WINDOWS\System32\RASAPI32.dll
(0000000076ed0000 - 0000000076ef5000: C:\WINDOWS\System32\DNSAPI.dll
(0000000076f00000 - 0000000076f08000: C:\WINDOWS\System32\WTSAPI32.dll
(0000000076f10000 - 0000000076f3d000: C:\WINDOWS\system32\WLDAP32.dll
(0000000076f40000 - 0000000076f50000: C:\WINDOWS\System32\Secur32.dll
(0000000076f80000 - 0000000076ff8000: C:\WINDOWS\System32\CLBCATQ.DLL
(0000000077000000 - 00000000770d4000: C:\WINDOWS\System32\COMRes.dll
(00000000770e0000 - 000000007716b000: C:\WINDOWS\system32\OLEAUT32.dll
(0000000077290000 - 00000000772f4000: C:\WINDOWS\system32\SHLWAPI.dll
(0000000077300000 - 000000007738b000: C:\WINDOWS\system32\comctl32.dll
(0000000077390000 - 0000000077b95000: C:\WINDOWS\system32\SHELL32.dll
(0000000077ba0000 - 0000000077ba7000: C:\WINDOWS\System32\midimap.dll
(0000000077bb0000 - 0000000077bc4000: C:\WINDOWS\System32\MSACM32.dll
(0000000077bd0000 - 0000000077bd7000: C:\WINDOWS\system32\VERSION.dll
(0000000077be0000 - 0000000077c33000: C:\WINDOWS\system32\msvcrt.dll
(0000000077c40000 - 0000000077c80000: C:\WINDOWS\system32\GDI32.dll
(0000000077d10000 - 0000000077d9c000: C:\WINDOWS\system32\USER32.dll
(0000000077da0000 - 0000000077e3e000: C:\WINDOWS\system32\ADVAPI32.dll
(0000000077e40000 - 0000000077f36000: C:\WINDOWS\system32\kernel32.dll
(0000000077f40000 - 0000000077fee000: C:\WINDOWS\System32\ntdll.dll
(0000000078000000 - 0000000078086000: C:\WINDOWS\system32\RPCRT4.dll
(0000000078090000 - 0000000078174000: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805\comctl32.dll
(0000000078190000 - 0000000078331000: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.10.0_x-ww_712befd8\gdiplus.dll

*----> Vidage de l'état de la thread 0xfe0 <----*

eax=00000418 ebx=000f3640 ecx=000f3640 edx=00000000 esi=000f3640 edi=00000000
eip=7ffe0304 esp=0006fefc ebp=0006ff14 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000202

fonction : <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 8bd4 mov edx,esp
7ffe0307 0f05 syscall
7ffe0309 c3 ret
7ffe030a 8ac8 mov cl,al
7ffe030c ff1570464d80 call dword ptr [804d4670]
7ffe0312 8b4510 mov eax,[ebp+0x10]
7ffe0315 33c9 xor ecx,ecx
7ffe0317 663908 cmp [eax],cx
7ffe031a 894dfc mov [ebp-0x4],ecx
7ffe031d 0f840d000000 je 7ffe0330

*----> Suivi arrière de la pile <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\USER32.dll -
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\SHELL32.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Module load completed but symbols could not be loaded for C:\WINDOWS\explorer.exe
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\kernel32.dll -
ChildEBP RetAddr Args to Child
0006fef8 77d13c6b 773e62a7 77e5a29b 000f3640 *SharedUserSystemCall+0xc (FPO: [0,0,0])
0006ff14 773dc7d4 00000000 0101243e 000f3640 USER32!WaitMessage+0xc
0006ff5c 01016132 01000000 00000000 000205e2 SHELL32!Ordinal201+0x24
0006ffc0 77e614c7 77e62441 0006fd1c 7ffdf000 explorer+0x16132
0006fff0 00000000 010160cc 00000000 78746341 kernel32!GetCurrentDirectoryW+0x44

*----> Vidage brut de la pile <----*
000000000006fefc 6b 3c d1 77 a7 62 3e 77 - 9b a2 e5 77 40 36 0f 00 k<.w.b>w...w@6..
000000000006ff0c 40 36 0f 00 5c ff 06 00 - 5c ff 06 00 d4 c7 3d 77 @6..\...\.....=w
000000000006ff1c 00 00 00 00 3e 24 01 01 - 40 36 0f 00 00 f0 fd 7f ....>$..@6......
000000000006ff2c c0 ff 06 00 00 00 00 00 - 18 ff 06 00 41 60 f6 77 ............A`.w
000000000006ff3c 99 ef e5 77 ff ff ff ff - 0c 00 00 00 97 64 f6 77 ...w.........d.w
000000000006ff4c 7c ef e5 77 00 00 00 00 - d5 27 15 00 60 00 00 00 |..w.....'..`...
000000000006ff5c c0 ff 06 00 32 61 01 01 - 00 00 00 01 00 00 00 00 ....2a..........
000000000006ff6c e2 05 02 00 05 00 00 00 - 41 24 e6 77 1c fd 06 00 ........A$.w....
000000000006ff7c 44 00 00 00 34 06 02 00 - 14 06 02 00 e4 05 02 00 D...4...........
000000000006ff8c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000006ff9c 2e 00 00 00 00 00 00 00 - 66 f1 06 00 01 00 00 00 ........f.......
000000000006ffac 05 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000006ffbc 00 00 00 00 f0 ff 06 00 - c7 14 e6 77 41 24 e6 77 ...........wA$.w
000000000006ffcc 1c fd 06 00 00 f0 fd 7f - f0 cc 60 b9 c8 ff 06 00 ..........`.....
000000000006ffdc 8f c8 53 80 ff ff ff ff - 09 48 e7 77 10 12 e7 77 ..S......H.w...w
000000000006ffec 00 00 00 00 00 00 00 00 - 00 00 00 00 cc 60 01 01 .............`..
000000000006fffc 00 00 00 00 41 63 74 78 - 20 00 00 00 01 00 00 00 ....Actx .......
000000000007000c 4c 06 00 00 7c 00 00 00 - 00 00 00 00 20 00 00 00 L...|....... ...
000000000007001c 00 00 00 00 14 00 00 00 - 01 00 00 00 03 00 00 00 ................
000000000007002c 34 00 00 00 ac 00 00 00 - 01 00 00 00 00 00 00 00 4...............

*----> Vidage de l'état de la thread 0x634 <----*

eax=75c56f60 ebx=00390000 ecx=00000001 edx=00390178 esi=0039e930 edi=00000006
eip=77f42a84 esp=0113ec00 ebp=0113ee24 iopl=0 nv up ei pl nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000206

*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\System32\ntdll.dll -
fonction : ntdll!RtlLogStackBackTrace
77f42a62 778d ja ntdll!RtlLogStackBackTrace+0x1ba (77f429f1)
77f42a64 04c2 add al,0xc2
77f42a66 8945a8 mov [ebp-0x58],eax
77f42a69 8b7004 mov esi,[eax+0x4]
77f42a6c 83ee08 sub esi,0x8
77f42a6f 8975a4 mov [ebp-0x5c],esi
77f42a72 8b4608 mov eax,[esi+0x8]
77f42a75 898564ffffff mov [ebp-0x9c],eax
77f42a7b 8b4e0c mov ecx,[esi+0xc]
77f42a7e 898d60ffffff mov [ebp-0xa0],ecx
FAUTE ->77f42a84 8901 mov [ecx],eax ds:0023:00000001=????????
77f42a86 894804 mov [eax+0x4],ecx
77f42a89 3bc1 cmp eax,ecx
77f42a8b 0f85c0f8ffff jne ntdll!stricmp+0x291 (77f42351)
77f42a91 0fb70e movzx ecx,word ptr [esi]
77f42a94 8bc1 mov eax,ecx
77f42a96 c1e803 shr eax,0x3
77f42a99 89855cffffff mov [ebp-0xa4],eax
77f42a9f 83e107 and ecx,0x7
77f42aa2 33d2 xor edx,edx
77f42aa4 42 inc edx

*----> Suivi arrière de la pile <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\msvcrt.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\System32\jscript.dll -
ChildEBP RetAddr Args to Child
0113ee24 77bfac14 00390000 00000000 00000028 ntdll!RtlLogStackBackTrace+0x24d
0113ee64 77bfac2a 00000028 77bf8930 00000028 msvcrt!free+0x1a9
01a52938 75c57500 75c58518 75c58500 75c58424 msvcrt!free+0x1bf
75c57100 75be10ed 75be10cc 75be8d25 75bf2a38 jscript+0x77500
75be7e9e 85561424 840f57ed 00033204 18245c8b jscript+0x10ed
6c8b5553 00000000 00000000 00000000 00000000 0x85561424

*----> Vidage brut de la pile <----*
000000000113ec00 07 00 00 00 28 00 00 00 - 28 b7 39 00 ff ff ff ff ....(...(.9.....
000000000113ec10 04 00 00 00 01 00 00 00 - c8 01 39 00 c8 01 39 00 ..........9...9.
000000000113ec20 00 04 82 9f 5c 01 39 00 - 00 00 00 00 88 66 aa 01 ....\.9......f..
000000000113ec30 b0 f4 a1 01 90 b8 39 00 - 98 b8 39 00 78 01 39 00 ......9...9.x.9.
000000000113ec40 c8 c5 a2 01 b0 0f a5 01 - b0 ff a2 01 78 01 39 00 ............x.9.
000000000113ec50 34 ed 13 01 a8 f4 a1 01 - 00 00 00 00 b0 0f a5 01 4...............
000000000113ec60 c8 01 39 00 00 00 00 00 - 00 00 00 00 00 00 70 01 ..9...........p.
000000000113ec70 22 00 00 00 10 01 00 00 - e0 90 a1 01 06 00 00 00 "...............
000000000113ec80 30 00 00 00 28 03 01 00 - 00 00 39 00 e8 eb 13 01 0...(.....9.....
000000000113ec90 30 00 00 00 dc ec 13 00 - b8 0f a5 01 00 00 39 00 0.............9.
000000000113eca0 94 ea 13 01 6a 16 f4 77 - e8 ec 13 01 05 90 f6 77 ....j..w.......w
000000000113ecb0 e0 d5 f5 77 ff ff ff ff - b2 17 f4 77 14 ac bf 77 ...w.......w...w
000000000113ecc0 00 00 39 00 00 00 00 00 - 19 ac bf 77 00 00 00 00 ..9........w....
000000000113ecd0 38 29 a5 01 e0 90 a1 01 - e0 ed a2 01 98 fe 13 01 8)..............
000000000113ece0 42 10 be 75 b4 2a a5 01 - b4 2a a5 01 38 29 a5 01 B..u.*...*..8)..
000000000113ecf0 64 ee 13 01 b4 2a a5 01 - e8 ec 13 01 2c 4f be 75 d....*......,O.u
000000000113ed00 98 fe 13 01 fb 2d c5 75 - 98 43 c5 75 ff ff ff ff .....-.u.C.u....
000000000113ed10 dc 4e be 75 04 c7 39 00 - 00 00 00 00 38 29 a5 01 .N.u..9.....8)..
000000000113ed20 f4 ee 13 01 40 00 00 c0 - 00 c7 39 00 00 00 00 00 ....@.....9.....
000000000113ed30 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

*----> Vidage de l'état de la thread 0x688 <----*

eax=000000c0 ebx=00000000 ecx=00000000 edx=00000000 esi=772960ed edi=77e54e36
eip=7ffe0304 esp=0118ff9c ebp=0118ffb4 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202

fonction : <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 8bd4 mov edx,esp
7ffe0307 0f05 syscall
7ffe0309 c3 ret
7ffe030a 8ac8 mov cl,al
7ffe030c ff1570464d80 call dword ptr [804d4670]
7ffe0312 8b4510 mov eax,[ebp+0x10]
7ffe0315 33c9 xor ecx,ecx
7ffe0317 663908 cmp [eax],cx
7ffe031a 894dfc mov [ebp-0x4],ecx
7ffe031d 0f840d000000 je 7ffe0330

*----> Suivi arrière de la pile <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0118ff98 77f65ab4 77f5c2c7 00000001 0118ffac *SharedUserSystemCall+0xc (FPO: [0,0,0])
0118ffb4 77e5d33b 00000000 77e54e36 772960ed ntdll!ZwDelayExecution+0xc
0118ffec 00000000 77f5c282 00000000 00000000 kernel32!RegisterWaitForInputIdle+0x43

*----> Vidage brut de la pile <----*
000000000118ff9c b4 5a f6 77 c7 c2 f5 77 - 01 00 00 00 ac ff 18 01 .Z.w...w........
000000000118ffac 00 00 00 00 00 00 00 80 - ec ff 18 01 3b d3 e5 77 ............;..w
000000000118ffbc 00 00 00 00 36 4e e5 77 - ed 60 29 77 00 00 00 00 ....6N.w.`)w....
000000000118ffcc 00 00 00 00 00 b0 fd 7f - c0 ff 18 01 07 00 00 00 ................
000000000118ffdc ff ff ff ff 09 48 e7 77 - b8 3d e6 77 00 00 00 00 .....H.w.=.w....
000000000118ffec 00 00 00 00 00 00 00 00 - 82 c2 f5 77 00 00 00 00 ...........w....
000000000118fffc 00 00 00 00 80 03 00 00 - 00 10 00 00 99 9e 36 00 ..............6.
000000000119000c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000119001c 00 00 00 00 2d 1b 00 00 - 00 00 00 00 15 00 00 00 ....-...........
000000000119002c 00 00 00 00 2a 00 00 00 - 00 00 00 00 05 00 00 00 ....*...........
000000000119003c 09 00 00 00 01 00 00 00 - 03 00 00 00 00 00 00 00 ................
000000000119004c 0e 00 00 00 03 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000119005c 00 00 00 00 68 0e 19 01 - 68 00 19 01 00 00 00 00 ....h...h.......
000000000119006c 68 8d f8 02 60 fa f7 02 - 48 06 43 02 00 00 00 00 h...`...H.C.....
000000000119007c 00 00 00 00 68 d7 42 02 - 48 69 44 02 00 00 00 00 ....h.B.HiD.....
000000000119008c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000119009c 00 00 00 00 00 00 00 00 - a8 f5 f7 02 00 00 00 00 ................
00000000011900ac 90 d2 43 02 00 00 00 00 - a8 ac 42 02 60 1b f9 02 ..C.......B.`...
00000000011900bc a8 e0 43 02 00 00 00 00 - 70 92 44 02 e0 c3 42 02 ..C.....p.D...B.
00000000011900cc 08 ed 43 02 00 00 00 00 - 48 c8 43 02 38 f5 44 02 ..C.....H.C.8.D.

*----> Vidage de l'état de la thread 0x168 <----*

eax=000000c0 ebx=00000000 ecx=00000000 edx=00000000 esi=00000000 edi=00000001
eip=7ffe0304 esp=0120fcec ebp=0120ffb4 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202

fonction : <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 8bd4 mov edx,esp
7ffe0307 0f05 syscall
7ffe0309 c3 ret
7ffe030a 8ac8 mov cl,al
7ffe030c ff1570464d80 call dword ptr [804d4670]
7ffe0312 8b4510 mov eax,[ebp+0x10]
7ffe0315 33c9 xor ecx,ecx
7ffe0317 663908 cmp [eax],cx
7ffe031a 894dfc mov [ebp-0x4],ecx
7ffe031d 0f840d000000 je 7ffe0330

*----> Suivi arrière de la pile <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0120fce8 77f6670b 77f5b5f4 00000003 0120fd30 *SharedUserSystemCall+0xc (FPO: [0,0,0])
0120ffb4 77e5d33b 00000000 00000020 00000020 ntdll!ZwWaitForMultipleObjects+0xc
0120ffec 00000000 77f5b4bf 00000000 00000000 kernel32!RegisterWaitForInputIdle+0x43

*----> Vidage brut de la pile <----*
000000000120fcec 0b 67 f6 77 f4 b5 f5 77 - 03 00 00 00 30 fd 20 01 .g.w...w....0. .
000000000120fcfc 01 00 00 00 01 00 00 00 - 00 00 00 00 20 00 00 00 ............ ...
000000000120fd0c 20 00 00 00 00 00 00 00 - e8 49 fb 77 e8 49 fb 77 ........I.w.I.w
000000000120fd1c a0 01 00 00 68 01 00 00 - 03 00 00 00 03 00 00 00 ....h...........
000000000120fd2c 02 00 00 00 9c 01 00 00 - 84 01 00 00 28 04 00 00 ............(...
000000000120fd3c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000120fd4c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000120fd5c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000120fd6c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000120fd7c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000120fd8c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000120fd9c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000120fdac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000120fdbc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000120fdcc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000120fddc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000120fdec 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000120fdfc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000120fe0c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000120fe1c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

*----> Vidage de l'état de la thread 0x4c4 <----*

eax=01750010 ebx=026e2640 ecx=04000000 edx=00000000 esi=00000000 edi=7ffdf000
eip=7ffe0304 esp=0129fd30 ebp=0129fdcc iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202

fonction : <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 8bd4 mov edx,esp
7ffe0307 0f05 syscall
7ffe0309 c3 ret
7ffe030a 8ac8 mov cl,al
7ffe030c ff1570464d80 call dword ptr [804d4670]
7ffe0312 8b4510 mov eax,[ebp+0x10]
7ffe0315 33c9 xor ecx,ecx
7ffe0317 663908 cmp [eax],cx
7ffe031a 894dfc mov [ebp-0x4],ecx
7ffe031d 0f840d000000 je 7ffe0330

*----> Suivi arrière de la pile <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0129fd2c 77f6670b 77e55ee0 0000000b 026e2640 *SharedUserSystemCall+0xc (FPO: [0,0,0])
0129fdcc 77d163ff 0000000b 00176e18 00000000 ntdll!ZwWaitForMultipleObjects+0xc
0129fe28 773e6536 0000000a 0129fe50 ffffffff USER32!SetScrollInfo+0x21f
0129ff4c 773dd8bc 7729df5f 00000000 77f41690 SHELL32!DragAcceptFiles+0x63
0129ffb4 77e5d33b 00000000 77f41690 000dd498 SHELL32!Ordinal753+0x27a
0129ffec 00000000 7729def2 0113f630 00000000 kernel32!RegisterWaitForInputIdle+0x43

*----> Vidage brut de la pile <----*
000000000129fd30 0b 67 f6 77 e0 5e e5 77 - 0b 00 00 00 40 26 6e 02 .g.w.^.w....@&n.
000000000129fd40 01 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000129fd50 0b 00 00 00 02 00 00 00 - 20 fe 29 01 68 17 5b 00 ........ .).h.[.
000000000129fd60 00 00 00 00 00 00 00 00 - 01 00 00 00 0b 00 00 00 ................
000000000129fd70 00 f0 fd 7f 00 80 fd 7f - 00 00 00 00 c8 fd 29 01 ..............).
000000000129fd80 05 90 f6 77 e0 d5 f5 77 - ff ff ff ff b2 17 f4 77 ...w...w.......w
000000000129fd90 d4 a6 e5 77 00 00 08 00 - 40 26 6e 02 00 80 fd 7f ...w....@&n.....
000000000129fda0 14 00 00 00 01 00 00 00 - 10 b2 0b 00 00 00 00 00 ................
000000000129fdb0 00 00 00 00 4c fd 29 01 - 02 00 00 00 dc ff 29 01 ....L.).......).
000000000129fdc0 09 48 e7 77 78 32 e6 77 - 00 00 00 00 28 fe 29 01 .H.wx2.w....(.).
000000000129fdd0 ff 63 d1 77 0b 00 00 00 - 18 6e 17 00 00 00 00 00 .c.w.....n......
000000000129fde0 ff ff ff ff 01 00 00 00 - e0 4b 0b 00 0a 00 00 00 .........K......
000000000129fdf0 00 00 00 00 09 3f d1 77 - 00 00 00 00 3c fe 29 01 .....?.w....<.).
000000000129fe00 9a 65 3e 77 20 fe 29 01 - 00 00 00 00 00 00 00 00 .e>w .).........
000000000129fe10 00 00 00 00 34 fe 29 01 - 00 00 00 00 01 00 00 00 ....4.).........
000000000129fe20 00 80 fd 7f b4 01 00 00 - 4c ff 29 01 36 65 3e 77 ........L.).6e>w
000000000129fe30 0a 00 00 00 50 fe 29 01 - ff ff ff ff ff 04 00 00 ....P.).........
000000000129fe40 18 6e 17 00 00 00 00 00 - 00 00 00 00 00 00 00 00 .n..............
000000000129fe50 e8 02 00 00 04 07 00 00 - c0 06 00 00 4c 07 00 00 ............L...
000000000129fe60 34 04 00 00 80 02 00 00 - 7c 02 00 00 a8 01 00 00 4.......|.......

*----> Vidage de l'état de la thread 0xd6c <----*

eax=016e0010 ebx=00004e20 ecx=00000000 edx=00000000 esi=01cbfd6c edi=77d13c6c
eip=7ffe0304 esp=01cbfcfc ebp=01cbfd18 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000202

fonction : <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 8bd4 mov edx,esp
7ffe0307 0f05 syscall
7ffe0309 c3 ret
7ffe030a 8ac8 mov cl,al
7ffe030c ff1570464d80 call dword ptr [804d4670]
7ffe0312 8b4510 mov eax,[ebp+0x10]
7ffe0315 33c9 xor ecx,ecx
7ffe0317 663908 cmp [eax],cx
7ffe031a 894dfc mov [ebp-0x4],ecx
7ffe031d 0f840d000000 je 7ffe0330

*----> Suivi arrière de la pile <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\System32\stobject.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
01cbfcf8 77d13a21 77d13c95 01cbfd6c 00000000 *SharedUserSystemCall+0xc (FPO: [0,0,0])
01cbfd18 74a71590 01cbfd6c 00000000 00000000 USER32+0x3a21
01cbfd90 74a72f1b 74a70000 00000000 000301c4 stobject+0x1590
01cbffb4 77e5d33b 00000000 00000000 00000000 stobject+0x2f1b
01cbffec 00000000 74a72ed6 00000000 00000000 kernel32!RegisterWaitForInputIdle+0x43

*----> Vidage brut de la pile <----*
0000000001cbfcfc 21 3a d1 77 95 3c d1 77 - 6c fd cb 01 00 00 00 00 !:.w.<.wl.......
0000000001cbfd0c 00 00 00 00 00 00 00 00 - 00 00 00 00 90 fd cb 01 ................
0000000001cbfd1c 90 15 a7 74 6c fd cb 01 - 00 00 00 00 00 00 00 00 ...tl...........
0000000001cbfd2c 00 00 00 00 00 00 00 00 - 00 00 a7 74 00 00 00 00 ...........t....
0000000001cbfd3c 30 00 00 00 00 40 00 00 - f0 12 a7 74 00 00 00 00 0....@.....t....
0000000001cbfd4c 1e 00 00 00 00 00 a7 74 - 43 02 1b 00 11 00 01 00 .......tC.......
0000000001cbfd5c 10 00 00 00 00 00 00 00 - f4 31 a7 74 00 00 00 00 .........1.t....
0000000001cbfd6c c4 01 03 00 e6 c0 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001cbfd7c 01 90 62 01 03 01 00 00 - 4d 02 00 00 00 00 00 00 ..b.....M.......
0000000001cbfd8c 00 00 00 00 b4 ff cb 01 - 1b 2f a7 74 00 00 a7 74 ........./.t...t
0000000001cbfd9c 00 00 00 00 c4 01 03 00 - 01 00 00 00 00 00 00 00 ................
0000000001cbfdac 43 00 3a 00 5c 00 57 00 - 49 00 4e 00 44 00 4f 00 C.:.\.W.I.N.D.O.
0000000001cbfdbc 57 00 53 00 5c 00 53 00 - 79 00 73 00 74 00 65 00 W.S.\.S.y.s.t.e.
0000000001cbfdcc 6d 00 33 00 32 00 5c 00 - 73 00 74 00 6f 00 62 00 m.3.2.\.s.t.o.b.
0000000001cbfddc 6a 00 65 00 63 00 74 00 - 2e 00 64 00 6c 00 6c 00 j.e.c.t...d.l.l.
0000000001cbfdec 00 00 00 00 00 02 00 00 - fc ff cb 01 23 00 00 00 ............#...
0000000001cbfdfc 30 94 75 e2 10 03 5f e1 - 00 00 00 00 ec ca 60 b9 0.u..._.......`.
0000000001cbfe0c ec ca 60 b9 00 00 04 00 - 00 00 00 00 50 bf 4e 80 ..`.........P.N.
0000000001cbfe1c 00 00 00 00 08 29 f1 85 - 00 00 00 00 cd f4 4e 80 .....)........N.
0000000001cbfe2c 70 cc 60 b9 01 00 00 00 - 00 00 00 00 00 00 00 00 p.`.............

*----> Vidage de l'état de la thread 0xd70 <----*

eax=00000001 ebx=01c7ff1c ecx=01c7ff68 edx=00000000 esi=00000000 edi=7ffdf000
eip=7ffe0304 esp=01c7fed4 ebp=01c7ff70 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000202

fonction : <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 8bd4 mov edx,esp
7ffe0307 0f05 syscall
7ffe0309 c3 ret
7ffe030a 8ac8 mov cl,al
7ffe030c ff1570464d80 call dword ptr [804d4670]
7ffe0312 8b4510 mov eax,[ebp+0x10]
7ffe0315 33c9 xor ecx,ecx
7ffe0317 663908 cmp [eax],cx
7ffe031a 894dfc mov [ebp-0x4],ecx
7ffe031d 0f840d000000 je 7ffe0330

*----> Suivi arrière de la pile <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
01c7fed0 77f6670b 77e55ee0 00000002 01c7ff1c *SharedUserSystemCall+0xc (FPO: [0,0,0])
01c7ff70 77e55faa 00000002 01c7ffa4 00000000 ntdll!ZwWaitForMultipleObjects+0xc
01c7ffb4 77e5d33b 00000000 00000021 41f4166a kernel32!WaitForMultipleObjects+0x17
01c7ffec 00000000 72c72ecc 00000000 00000000 kernel32!RegisterWaitForInputIdle+0x43

*----> Vidage brut de la pile <----*
0000000001c7fed4 0b 67 f6 77 e0 5e e5 77 - 02 00 00 00 1c ff c7 01 .g.w.^.w........
0000000001c7fee4 01 00 00 00 00 00 00 00 - 00 00 00 00 21 00 00 00 ............!...
0000000001c7fef4 00 00 00 00 00 00 00 00 - 00 c0 fa 7f 60 ff c7 01 ............`...
0000000001c7ff04 00 00 00 00 34 ff c7 01 - 52 a6 e5 77 02 00 00 00 ....4...R..w....
0000000001c7ff14 00 f0 fd 7f 00 c0 fa 7f - 00 04 00 00 e8 03 00 00 ................
0000000001c7ff24 00 00 00 00 57 7d ae 76 - 00 f0 fd 7f 00 c0 fa 7f ....W}.v........
0000000001c7ff34 14 00 00 00 01 00 00 00 - 1c ff c7 01 00 00 00 00 ................
0000000001c7ff44 14 00 00 00 01 00 00 00 - 28 18 15 00 00 00 00 00 ........(.......
0000000001c7ff54 00 00 00 00 f0 fe c7 01 - ff ff ff ff dc ff c7 01 ................
0000000001c7ff64 09 48 e7 77 78 32 e6 77 - 00 00 00 00 b4 ff c7 01 .H.wx2.w........
0000000001c7ff74 aa 5f e5 77 02 00 00 00 - a4 ff c7 01 00 00 00 00 ._.w............
0000000001c7ff84 ff ff ff ff 00 00 00 00 - 0c 2f c7 72 02 00 00 00 ........./.r....
0000000001c7ff94 a4 ff c7 01 00 00 00 00 - ff ff ff ff 6a 16 f4 41 ............j..A
0000000001c7ffa4 00 04 00 00 e8 03 00 00 - 01 00 00 00 01 00 00 00 ................
0000000001c7ffb4 ec ff c7 01 3b d3 e5 77 - 00 00 00 00 21 00 00 00 ....;..w....!...
0000000001c7ffc4 6a 16 f4 41 00 00 00 00 - 00 00 00 00 00 c0 fa 7f j..A............
0000000001c7ffd4 c0 ff c7 01 07 00 00 00 - ff ff ff ff 09 48 e7 77 .............H.w
0000000001c7ffe4 b8 3d e6 77 00 00 00 00 - 00 00 00 00 00 00 00 00 .=.w............
0000000001c7fff4 cc 2e c7 72 00 00 00 00 - 00 00 00 00 00 00 00 00 ...r............
0000000001c80004 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

*----> Vidage de l'état de la thread 0xdcc <----*

eax=00185000 ebx=00000000 ecx=00185000 edx=00000000 esi=0016edc8 edi=00000000
eip=7ffe0304 esp=01e3fcd4 ebp=01e3ff28 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000202

fonction : <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 8bd4 mov edx,esp
7ffe0307 0f05 syscall
7ffe0309 c3 ret
7ffe030a 8ac8 mov cl,al
7ffe030c ff1570464d80 call dword ptr [804d4670]
7ffe0312 8b4510 mov eax,[ebp+0x10]
7ffe0315 33c9 xor ecx,ecx
7ffe0317 663908 cmp [eax],cx
7ffe031a 894dfc mov [ebp-0x4],ecx
7ffe031d 0f840d000000 je 7ffe0330

*----> Suivi arrière de la pile <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\System32\BROWSEUI.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
01e3fcd0 77d13c6b 75f1cbf3 00000000 00000000 *SharedUserSystemCall+0xc (FPO: [0,0,0])
01e3ff28 75f258bd 00000000 00000000 00000000 USER32!WaitMessage+0xc
01e3ffb4 77e5d33b 0016a550 00000000 00000000 BROWSEUI!Ordinal123+0x558
01e3ffec 00000000 75f25879 0016a550 00000000 kernel32!RegisterWaitForInputIdle+0x43

*----> Vidage brut de la pile <----*
0000000001e3fcd4 6b 3c d1 77 f3 cb f1 75 - 00 00 00 00 00 00 00 00 k<.w...u........
0000000001e3fce4 00 00 00 00 45 00 78 00 - 70 00 6c 00 6f 00 72 00 ....E.x.p.l.o.r.
0000000001e3fcf4 61 00 74 00 65 00 75 00 - 72 00 20 00 57 00 69 00 a.t.e.u.r. .W.i.
0000000001e3fd04 6e 00 64 00 6f 00 77 00 - 73 00 00 00 10 00 00 00 n.d.o.w.s.......
0000000001e3fd14 29 b8 00 78 44 3b 08 00 - 32 b8 00 78 2c 3b 08 00 )..xD;..2..x,;..
0000000001e3fd24 01 00 00 00 8c fe e3 01 - 00 00 00 00 cc b7 00 78 ...............x
0000000001e3fd34 20 33 08 00 07 00 00 00 - 10 00 00 00 8c fe e3 01 3..............
0000000001e3fd44 8c fe e3 01 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001e3fd54 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001e3fd64 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001e3fd74 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001e3fd84 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001e3fd94 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001e3fda4 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001e3fdb4 00 00 00 00 00 00 00 00 - 00 00 00 00 38 00 00 00 ............8...
0000000001e3fdc4 a7 4d d1 77 e0 c3 d6 77 - 00 00 00 00 00 00 00 00 .M.w...w........
0000000001e3fdd4 00 00 00 00 00 00 08 00 - fc e2 06 00 79 58 f2 75 ............yX.u
0000000001e3fde4 0c e4 06 00 42 d3 e5 77 - 1b 00 00 00 00 02 00 00 ....B..w........
0000000001e3fdf4 fc ff e3 01 23 00 00 00 - 42 d3 e5 77 1b 00 00 00 ....#...B..w....
0000000001e3fe04 00 02 00 00 fc ff 8c 00 - 23 00 00 00 42 d3 e5 77 ........#...B..w

*----> Vidage de l'état de la thread 0xdf0 <----*

eax=000011f9 ebx=00000630 ecx=0010dd00 edx=00000000 esi=02dfff98 edi=77d1438f
eip=7ffe0304 esp=02dfff54 ebp=02dfff78 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000202

fonction : <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 8bd4 mov edx,esp
7ffe0307 0f05 syscall
7ffe0309 c3 ret
7ffe030a 8ac8 mov cl,al
7ffe030c ff1570464d80 call dword ptr [804d4670]
7ffe0312 8b4510 mov eax,[ebp+0x10]
7ffe0315 33c9 xor ecx,ecx
7ffe0317 663908 cmp [eax],cx
7ffe031a 894dfc mov [ebp-0x4],ecx
7ffe031d 0f840d000000 je 7ffe0330

*----> Suivi arrière de la pile <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\System32\WINMM.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
02dfff50 77d13a21 77d143cd 02dfff98 00000000 *SharedUserSystemCall+0xc (FPO: [0,0,0])
02dfff78 76ae1c79 02dfff98 00000000 00000000 USER32+0x3a21
02dfffb4 77e5d33b 00000630 00010003 00080000 WINMM!timeGetTime+0x1a1
02dfffec 00000000 76ae1c14 00000630 00000000 kernel32!RegisterWaitForInputIdle+0x43

*----> Vidage brut de la pile <----*
0000000002dfff54 21 3a d1 77 cd 43 d1 77 - 98 ff df 02 00 00 00 00 !:.w.C.w........
0000000002dfff64 00 00 00 00 00 00 00 00 - 30 06 00 00 8f 43 d1 77 ........0....C.w
0000000002dfff74 00 00 00 00 b4 ff df 02 - 79 1c ae 76 98 ff df 02 ........y..v....
0000000002dfff84 00 00 00 00 00 00 00 00 - 00 00 00 00 03 00 01 00 ................
0000000002dfff94 00 00 08 00 60 03 07 00 - e6 c0 00 00 00 00 00 00 ....`...........
0000000002dfffa4 00 00 00 00 01 90 62 01 - 03 01 00 00 4d 02 00 00 ......b.....M...
0000000002dfffb4 ec ff df 02 3b d3 e5 77 - 30 06 00 00 03 00 01 00 ....;..w0.......
0000000002dfffc4 00 00 08 00 30 06 00 00 - e0 6c 8c b9 00 a0 fa 7f ....0....l......
0000000002dfffd4 c0 ff df 02 07 00 00 00 - ff ff ff ff 09 48 e7 77 .............H.w
0000000002dfffe4 b8 3d e6 77 00 00 00 00 - 00 00 00 00 00 00 00 00 .=.w............
0000000002dffff4 14 1c ae 76 30 06 00 00 - 00 00 00 00 c1 00 00 00 ...v0...........
0000000002e00004 00 01 00 00 ff ee ff ee - 03 10 00 00 01 00 00 00 ................
0000000002e00014 00 fe 00 00 00 00 10 00 - 00 20 00 00 00 02 00 00 ......... ......
0000000002e00024 00 20 00 00 37 01 00 00 - ff ef fd 7f 10 00 08 06 . ..7...........
0000000002e00034 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000002e00044 98 05 e0 02 0f 00 00 00 - f8 ff ff ff 50 00 e0 02 ............P...
0000000002e00054 50 00 e0 02 08 06 e0 02 - 00 00 00 00 00 00 00 00 P...............
0000000002e00064 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000002e00074 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000002e00084 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

*----> Vidage de l'état de la thread 0x6fc <----*

eax=00000001 ebx=00000000 ecx=01a0fcd4 edx=00000000 esi=0272d340 edi=00000000
eip=7ffe0304 esp=01a0fcd4 ebp=01a0ff28 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000202

fonction : <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 8bd4 mov edx,esp
7ffe0307 0f05 syscall
7ffe0309 c3 ret
7ffe030a 8ac8 mov cl,al
7ffe030c ff1570464d80 call dword ptr [804d4670]
7ffe0312 8b4510 mov eax,[ebp+0x10]
7ffe0315 33c9 xor ecx,ecx
7ffe0317 663908 cmp [eax],cx
7ffe031a 894dfc mov [ebp-0x4],ecx
7ffe031d 0f840d000000 je 7ffe0330

*----> Suivi arrière de la pile <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
01a0fcd0 77d13c6b 75f1cbf3 0006fe54 77e74809 *SharedUserSystemCall+0xc (FPO: [0,0,0])
01a0ff28 75f258bd 00000000 0006fe54 77e74809 USER32!WaitMessage+0xc
01a0ffb4 77e5d33b 026f99f0 0006fe54 77e74809 BROWSEUI!Ordinal123+0x558
01a0ffec 00000000 75f25879 026f99f0 00000000 kernel32!RegisterWaitForInputIdle+0x43

*----> Vidage brut de la pile <----*
0000000001a0fcd4 6b 3c d1 77 f3 cb f1 75 - 54 fe 06 00 09 48 e7 77 k<.w...uT....H.w
0000000001a0fce4 00 00 00 00 45 00 78 00 - 70 00 6c 00 6f 00 72 00 ....E.x.p.l.o.r.
0000000001a0fcf4 61 00 74 00 65 00 75 00 - 72 00 20 00 57 00 69 00 a.t.e.u.r. .W.i.
0000000001a0fd04 6e 00 64 00 6f 00 77 00 - 73 00 00 00 10 00 00 00 n.d.o.w.s.......
0000000001a0fd14 29 b8 00 78 c4 36 08 00 - 32 b8 00 78 ac 36 08 00 )..x.6..2..x.6..
0000000001a0fd24 01 00 00 00 8c fe a0 01 - 00 00 00 00 cc b7 00 78 ...............x
0000000001a0fd34 20 33 08 00 03 00 00 00 - 10 00 00 00 8c fe a0 01 3..............
0000000001a0fd44 8c fe a0 01 00 00 00 00 - 00 56 c8 39 5e 55 c8 b9 .........V.9^U..
0000000001a0fd54 50 54 c8 39 44 56 c8 b9 - 51 54 c8 39 c0 54 c8 b9 PT.9DV..QT.9.T..
0000000001a0fd64 62 57 c8 39 22 52 c8 b9 - cd 56 c8 39 11 56 c8 b9 bW.9"R...V.9.V..
0000000001a0fd74 e2 52 c8 39 89 56 c8 b9 - ab 55 c8 39 96 53 c8 b9 .R.9.V...U.9.S..
0000000001a0fd84 b4 56 c8 39 d5 53 c8 b9 - 54 56 c8 39 b5 54 c8 b9 .V.9.S..TV.9.T..
0000000001a0fd94 3a 54 c8 39 ef 56 c8 b9 - 30 54 c8 39 22 54 c8 b9 :T.9.V..0T.9"T..
0000000001a0fda4 b8 57 c8 39 a7 52 c8 b9 - 45 56 c8 39 c0 55 c8 b9 .W.9.R..EV.9.U..
0000000001a0fdb4 8b 53 c8 39 96 56 c8 b9 - 00 00 00 00 38 00 00 00 .S.9.V......8...
0000000001a0fdc4 a7 4d d1 77 e0 c3 d6 77 - 54 fe 06 00 09 48 e7 77 .M.w...wT....H.w
0000000001a0fdd4 00 00 00 00 ff ff ff ff - e1 b5 e5 77 79 58 f2 75 ...........wyX.u
0000000001a0fde4 01 00 00 00 42 d3 e5 77 - 1b 00 00 00 00 02 00 00 ....B..w........
0000000001a0fdf4 fc ff a0 01 23 00 00 00 - 00 00 00 00 28 77 fb 85 ....#.......(w..
0000000001a0fe04 58 34 97 85 50 fb d0 ba - 2b 85 d5 f6 e4 77 fb 85 X4..P...+....w..

*----> Vidage de l'état de la thread 0xe0 <----*

eax=00000000 ebx=0016ac48 ecx=00000000 edx=00000000 esi=00000100 edi=00000000
eip=7ffe0304 esp=00fefe28 ebp=00feff90 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000202

fonction : <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 8bd4 mov edx,esp
7ffe0307 0f05 syscall
7ffe0309 c3 ret
7ffe030a 8ac8 mov cl,al
7ffe030c ff1570464d80 call dword ptr [804d4670]
7ffe0312 8b4510 mov eax,[ebp+0x10]
7ffe0315 33c9 xor ecx,ecx
7ffe0317 663908 cmp [eax],cx
7ffe031a 894dfc mov [ebp-0x4],ecx
7ffe031d 0f840d000000 je 7ffe0330

*----> Suivi arrière de la pile <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\RPCRT4.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\GDI32.dll -
ChildEBP RetAddr Args to Child
00fefe24 77f662b7 780016a4 00000158 00feff80 *SharedUserSystemCall+0xc (FPO: [0,0,0])
00feff90 78001601 780019d6 0008cfc0 77f5d5f0 ntdll!ZwReplyWaitReceivePortEx+0xc
000a80e8 ffffffff 0000077c 00000350 00000000 RPCRT4+0x1601
00000000 00000000 00000000 00000000 00000000 0xffffffff

*----> Vidage brut de la pile <----*
0000000000fefe28 b7 62 f6 77 a4 16 00 78 - 58 01 00 00 80 ff fe 00 .b.w...xX.......
0000000000fefe38 00 00 00 00 48 ac 16 00 - 60 ff fe 00 60 2a 63 85 ....H...`...`*c.
0000000000fefe48 e0 92 52 85 e0 92 4f 85 - e8 fc 53 85 18 5c 30 86 ..R...O...S..\0.
0000000000fefe58 f0 d2 88 85 c0 d0 9e 85 - 80 69 0d 86 00 00 52 85 .........i....R.
0000000000fefe68 30 35 ca 85 e8 47 88 85 - 70 f7 f4 85 40 8d f1 85 05...G..p...@...
0000000000fefe78 70 d3 ce 85 ce cd 01 00 - 18 6a f2 85 e0 9b 6c 85 p........j....l.
0000000000fefe88 18 4b 6c 85 58 e7 4e 85 - 80 3d d9 85 b8 3d 40 85 .Kl.X.N..=...=@.
0000000000fefe98 70 c7 29 85 f8 ee cc 85 - e0 0c f0 85 d0 2b 7d 85 p.)..........+}.
0000000000fefea8 08 31 2e 86 40 54 45 85 - 68 ce 06 86 20 a2 cd 85 .1..@TE.h... ...
0000000000fefeb8 d8 a7 84 85 88 3d c9 85 - 60 33 56 85 70 c4 34 85 .....=..`3V.p.4.
0000000000fefec8 c8 0e f6 85 38 d3 f3 85 - 30 55 2f 86 c0 f3 99 85 ....8...0U/.....
0000000000fefed8 c8 e2 0a 86 a0 ca 07 86 - 90 07 7d 85 28 a9 4a 85 ..........}.(.J.
0000000000fefee8 38 46 9a 85 90 38 99 85 - 6b 0c 00 00 00 30 50 c0 8F...8..k....0P.
0000000000fefef8 7d 03 00 00 9c 36 50 c0 - a0 00 00 00 6b 0c 00 00 }....6P.....k...
0000000000feff08 00 30 50 c0 08 0c 63 b9 - 60 95 4f 80 9c 36 50 c0 .0P...c.`.O..6P.
0000000000feff18 58 f6 03 86 00 00 c4 76 - ac d9 30 86 00 ca 4e 80 X......v..0...N.
0000000000feff28 08 ca 4e 80 7c d9 30 86 - 10 d8 30 86 63 ed 58 80 ..N.|.0...0.c.X.
0000000000feff38 40 72 30 86 10 d8 30 86 - 2f 16 00 78 60 ff fe 00 @r0...0./..x`...
0000000000feff48 4a 16 00 78 38 df 09 00 - c0 c5 12 00 e8 80 0a 00 J..x8...........
0000000000feff58 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff ../M.....]......

*----> Vidage de l'état de la thread 0x9bc <----*

eax=00000020 ebx=00000000 ecx=00000020 edx=00000000 esi=77fb32c0 edi=77fb32e0
eip=7ffe0304 esp=0251ff70 ebp=0251ffb4 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000202

fonction : <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 8bd4 mov edx,esp
7ffe0307 0f05 syscall
7ffe0309 c3 ret
7ffe030a 8ac8 mov cl,al
7ffe030c ff1570464d80 call dword ptr [804d4670]
7ffe0312 8b4510 mov eax,[ebp+0x10]
7ffe0315 33c9 xor ecx,ecx
7ffe0317 663908 cmp [eax],cx
7ffe031a 894dfc mov [ebp-0x4],ecx
7ffe031d 0f840d000000 je 7ffe0330

*----> Suivi arrière de la pile <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0251ff6c 77f6625d 77f419b1 00000198 0251ffac *SharedUserSystemCall+0xc (FPO: [0,0,0])
0251ffb4 77e5d33b 00000000 00000000 00000000 ntdll!ZwRemoveIoCompletion+0xc
0251ffec 00000000 77f41976 00000000 00000000 kernel32!RegisterWaitForInputIdle+0x43

*----> Vidage brut de la pile <----*
000000000251ff70 5d 62 f6 77 b1 19 f4 77 - 98 01 00 00 ac ff 51 02 ]b.w...w......Q.
000000000251ff80 b0 ff 51 02 98 ff 51 02 - a0 ff 51 02 00 00 00 00 ..Q...Q...Q.....
000000000251ff90 00 00 00 00 00 00 00 00 - 00 00 00 00 20 0c 6b 02 ............ .k.
000000000251ffa0 00 7c 28 e8 ff ff ff ff - 6e b8 4f 80 4c bf f5 77 .|(.....n.O.L..w
000000000251ffb0 18 16 15 00 ec ff 51 02 - 3b d3 e5 77 00 00 00 00 ......Q.;..w....
000000000251ffc0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000251ffd0 00 f0 fa 7f c0 ff 51 02 - 07 00 00 00 ff ff ff ff ......Q.........
000000000251ffe0 09 48 e7 77 b8 3d e6 77 - 00 00 00 00 00 00 00 00 .H.w.=.w........
000000000251fff0 00 00 00 00 76 19 f4 77 - 00 00 00 00 00 00 00 00 ....v..w........
0000000002520000 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000002520010 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000002520020 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000002520030 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000002520040 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000002520050 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000002520060 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000002520070 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000002520080 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000002520090 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000025200a0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

*----> Vidage de l'état de la thread 0xb04 <----*

eax=00000000 ebx=02715240 ecx=7ffae000 edx=00000000 esi=00000100 edi=00000000
eip=7ffe0304 esp=0255fe28 ebp=0255ff90 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000202

fonction : <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 8bd4 mov edx,esp
7ffe0307 0f05 syscall
7ffe0309 c3 ret
7ffe030a 8ac8 mov cl,al
7ffe030c ff1570464d80 call dword ptr [804d4670]
7ffe0312 8b4510 mov eax,[ebp+0x10]
7ffe0315 33c9 xor ecx,ecx
7ffe0317 663908 cmp [eax],cx
7ffe031a 894dfc mov [ebp-0x4],ecx
7ffe031d 0f840d000000 je 7ffe0330

*----> Suivi arrière de la pile <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0255fe24 77f662b7 780016a4 00000158 0255ff80 *SharedUserSystemCall+0xc (FPO: [0,0,0])
0255ff90 78001601 780019d6 0008cfc0 00000025 ntdll!ZwReplyWaitReceivePortEx+0xc
0010ac88 ffffffff 000006d8 000001c0 00000000 RPCRT4+0x1601
00000000 00000000 00000000 00000000 00000000 0xffffffff

*----> Vidage brut de la pile <----*
000000000255fe28 b7 62 f6 77 a4 16 00 78 - 58 01 00 00 80 ff 55 02 .b.w...xX.....U.
000000000255fe38 00 00 00 00 40 52 71 02 - 60 ff 55 02 00 00 00 00 ....@Rq.`.U.....
000000000255fe48 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000255fe58 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000255fe68 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000255fe78 00 00 00 00 cc cd 01 00 - 00 00 00 00 00 00 00 00 ................
000000000255fe88 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000255fe98 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000255fea8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000255feb8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000255fec8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000255fed8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000255fee8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000255fef8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000255ff08 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000255ff18 00 00 00 00 00 00 00 00 - 84 8a 32 85 00 ca 4e 80 ..........2...N.
000000000255ff28 08 ca 4e 80 54 8a 32 85 - e8 88 32 85 63 ed 58 80 ..N.T.2...2.c.X.
000000000255ff38 40 72 30 86 e8 88 32 85 - 2f 16 00 78 60 ff 55 02 @r0...2./..x`.U.
000000000255ff48 4a 16 00 78 38 df 09 00 - e0 a4 10 00 88 ac 10 00 J..x8...........
000000000255ff58 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff ../M.....]......

*----> Vidage de l'état de la thread 0x7ec <----*

eax=00000003 ebx=0010d560 ecx=0010b7d4 edx=00000000 esi=00000100 edi=00000000
eip=7ffe0304 esp=020bfe28 ebp=020bff90 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000202

fonction : <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 8bd4 mov edx,esp
7ffe0307 0f05 syscall
7ffe0309 c3 ret
7ffe030a 8ac8 mov cl,al
7ffe030c ff1570464d80 call dword ptr [804d4670]
7ffe0312 8b4510 mov eax,[ebp+0x10]
7ffe0315 33c9 xor ecx,ecx
7ffe0317 663908 cmp [eax],cx
7ffe031a 894dfc mov [ebp-0x4],ecx
7ffe031d 0f840d000000 je 7ffe0330

*----> Suivi arrière de la pile <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
020bfe24 77f662b7 780016a4 00000158 020bff80 *SharedUserSystemCall+0xc (FPO: [0,0,0])
020bff90 78001601 780019d6 0008cfc0 000b6ab0 ntdll!ZwReplyWaitReceivePortEx+0xc
0010b6b8 ffffffff 000005a0 00000504 00000000 RPCRT4+0x1601
00000000 00000000 00000000 00000000 00000000 0xffffffff

*----> Vidage brut de la pile <----*
00000000020bfe28 b7 62 f6 77 a4 16 00 78 - 58 01 00 00 80 ff 0b 02 .b.w...xX.......
00000000020bfe38 00 00 00 00 60 d5 10 00 - 60 ff 0b 02 10 94 55 e1 ....`...`.....U.
00000000020bfe48 f0 09 00 00 78 ab 68 b9 - 8e 50 58 80 d8 84 63 e2 ....x.h..PX...c.
00000000020bfe58 00 00 00 00 28 aa 08 86 - 00 00 00 00 00 00 55 e1 ....(.........U.
00000000020bfe68 01 00 1f 00 08 20 a7 e1 - d8 84 63 e2 00 00 00 00 ..... ....c.....
00000000020bfe78 f0 ab 68 b9 cd cd 01 00 - 10 94 55 e1 01 00 1f 00 ..h.......U.....
00000000020bfe88 10 94 55 e1 d8 84 63 e2 - 20 20 00 00 0c ac 68 b9 ..U...c. ....h.
00000000020bfe98 8d 4f 58 80 28 aa 08 86 - 00 00 00 00 00 00 00 00 .OX.(...........
00000000020bfea8 10 94 55 e1 28 94 55 e1 - 0c ac 68 b9 d1 4f 58 80 ..U.(.U...h..OX.
00000000020bfeb8 00 00 00 00 18 48 3d e3 - 28 94 55 e1 08 ac 68 b9 .....H=.(.U...h.
00000000020bfec8 40 c3 4e 80 98 fd 36 86 - d0 0b fe 85 b8 64 10 86 @.N...6......d..
00000000020bfed8 00 f0 df ff fc ab 68 b9 - 5a a3 c0 f6 d0 0b fe 85 ......h.Z.......
00000000020bfee8 ff ff ff ff 02 02 00 00 - 5b 0f 00 00 00 30 50 c0 ........[....0P.
00000000020bfef8 e9 07 00 00 9c 36 50 c0 - a0 00 00 00 5b 0f 00 00 .....6P.....[...
00000000020bff08 00 30 50 c0 08 ac 68 b9 - 60 95 4f 80 9c 36 50 c0 .0P...h.`.O..6P.
00000000020bff18 58 f6 03 86 11 17 86 74 - cc d8 34 85 00 ca 4e 80 X......t..4...N.
00000000020bff28 08 ca 4e 80 9c d8 34 85 - 30 d7 34 85 63 ed 58 80 ..N...4.0.4.c.X.
00000000020bff38 40 72 3
A voir également:

4 réponses

flo88 Messages postés 28801 Date d'inscription   Statut Contributeur Dernière intervention   Ambassadeur 5 109
 
Le rapport du premier message est le suivant:

STATUS_SYSTEM_PROCESS_TERMINATED - code : 0xC000021A
[1] Vous avez installé des services IIS et vous avez attribué à votre ordinateur un nom non autorisé (par exemple, system).
[2] Le message survient quand vous ouvrez une session Terminal Server. Installez le Service Pack 2.
Windows n'a plus accès au système de fichiers. Le problème dû à un logiciel qu'il faut alors désinstaller.
[3] Le problème apparaît quand vous installez Roxio GoBack. Désinstallez-le et installez une version plus récente.
[4] La source du problème pourrait être Internet Explorer 6. Installez le dernier Service Pack.


4
jean-marie69 Messages postés 3 Statut Membre
 
Bonjour Flo,

Merci pour votre réponse.

Je ne suis pas concerné a priori par les cas [1] [2] et [3]

Pour [4], j'ai installé le dernier service pack d'IE (je suis en version IE 6.00.2900.2180 xpsp-sp2-rtm.040803-2158IS), mais cela ne change rien au démarrage j'ai toujours l'écran bleu avec le message suivant :
STOP : C000021a {Erreur systeme irrecuperable}
Le processus systeme Windows Logon Process s'est terminé de façon inattendue avec l'état 0xC000005 (0c00000000 0x00000000)
Le système a été arrêté

Seul le mode sans échec permet de revenir sous Windows en mode dégradé.

Comment exploiter plus précisement le dump de Dr Watson ?

Merci à toute personne qui pourrait me dépanner

Cordialement

Jean-Marie
0
flo88 Messages postés 28801 Date d'inscription   Statut Contributeur Dernière intervention   Ambassadeur 5 109
 
0
jean-marie69 Messages postés 3 Statut Membre
 
Rebonsoir Flo,

Je retrouve les rubriques que vous m'avez précédemment communiquées mais rien qui me permettre d'avancer dans le diagnostic.

Merci quand même.

La solution va consister à revenir au XP SP1 car chaque tentative de passer à SP2 s'avère infructueuse.

Cordialement
0