PDA

View Full Version : Non posso usare Firefox


lunaticgate
27-01-2005, 11:42
Dopo un errore grave del sistema Firefox non è più eseguibile (sto scrivendo con IE) l'errore nel registro è il seguente, io non ci capisco niente!

Exception dell'applicazione:
App: C:\Programmi\Mozilla Firefox\firefox.exe (pid=1964)
Ora: 26/01/2005 @ 16:29:06.656
Numero exception: c0000005 (access violation)

*----> System Information <----*
Nome computer: WAKON
Nome utente: Masaru
Id sessione terminal: 0
Numero processori: 1
Tipo processore: x86 Family 15 Model 31 Stepping 0
Versione di Windows: 5.1
Build corrente: 2600
Service Pack: 1
Tipo corrente: Uniprocessor Free
Organizzazione registrata: *********
Proprietario autorizzato: Masaru

*----> Elenco Task <----*
0 System Process
4 System
384 smss.exe
448 csrss.exe
472 winlogon.exe
516 services.exe
528 lsass.exe
696 svchost.exe
740 svchost.exe
852 svchost.exe
880 svchost.exe
1044 Explorer.EXE
1092 spoolsv.exe
1212 nvsvc32.exe
1464 SOUNDMAN.EXE
1540 GSICON.EXE
1548 dslagent.exe
1560 ctfmon.exe
1248 emule.exe
1964 firefox.exe
1440 drwtsn32.exe

*----> Elenco moduli <----*
(0000000000270000 - 00000000002d0000: C:\Programmi\Mozilla Firefox\xpcom.dll
(00000000002d0000 - 00000000002d7000: C:\Programmi\Mozilla Firefox\plc4.dll
(00000000002e0000 - 00000000002e6000: C:\Programmi\Mozilla Firefox\plds4.dll
(00000000002f0000 - 000000000030a000: C:\Programmi\Mozilla Firefox\smime3.dll
(0000000000310000 - 0000000000365000: C:\Programmi\Mozilla Firefox\nss3.dll
(0000000000370000 - 00000000003ca000: C:\Programmi\Mozilla Firefox\softokn3.dll
(00000000003d0000 - 00000000003eb000: C:\Programmi\Mozilla Firefox\ssl3.dll
(0000000000400000 - 0000000000a66000: C:\Programmi\Mozilla Firefox\firefox.exe
(0000000000a70000 - 0000000000b91000: C:\WINDOWS\system32\ole32.dll
(0000000000ba0000 - 0000000000bb4000: C:\Programmi\Mozilla Firefox\xpcom_compat.dll
(0000000001800000 - 000000000180d000: C:\Programmi\Mozilla Firefox\components\jar50.dll
(0000000002c10000 - 0000000002c42000: C:\Programmi\Mozilla Firefox\nssckbi.dll
(0000000003570000 - 00000000036fe000: C:\Programmi\Mozilla Firefox\plugins\npswf32.dll
(000000000ffd0000 - 000000000fff3000: C:\windows\System32\rsaenh.dll
(0000000010000000 - 0000000010054000: C:\Programmi\Mozilla Firefox\js3250.dll
(0000000030000000 - 0000000030026000: C:\Programmi\Mozilla Firefox\nspr4.dll
(0000000041b00000 - 0000000041b43000: C:\windows\System32\DRMClien.DLL
(00000000582e0000 - 000000005831a000: C:\windows\System32\msadds32.ax
(000000005b180000 - 000000005b1b4000: C:\WINDOWS\System32\uxtheme.dll
(000000005c080000 - 000000005c0bf000: C:\windows\System32\strmdll.dll
(000000005e3c0000 - 000000005e41a000: C:\windows\System32\qdvd.dll
(000000006c450000 - 000000006c4ce000: C:\windows\System32\dxmasf.dll
(000000006e9c0000 - 000000006e9c8000: C:\WINDOWS\System32\corpol.dll
(00000000719d0000 - 0000000071a0c000: C:\WINDOWS\system32\mswsock.dll
(0000000071a10000 - 0000000071a18000: C:\WINDOWS\System32\wshtcpip.dll
(0000000071a20000 - 0000000071a28000: C:\WINDOWS\System32\WS2HELP.dll
(0000000071a30000 - 0000000071a45000: C:\WINDOWS\System32\WS2_32.dll
(0000000071a50000 - 0000000071a59000: C:\WINDOWS\System32\WSOCK32.dll
(0000000071bb0000 - 0000000071bfe000: C:\WINDOWS\System32\NETAPI32.dll
(0000000072240000 - 0000000072245000: C:\WINDOWS\System32\sensapi.dll
(0000000072b60000 - 0000000072c31000: C:\windows\System32\msdxm.ocx
(0000000072c80000 - 0000000072c88000: C:\WINDOWS\System32\msacm32.drv
(0000000072c90000 - 0000000072c99000: C:\WINDOWS\System32\wdmaud.drv
(0000000072f70000 - 0000000072f93000: C:\WINDOWS\System32\WINSPOOL.DRV
(0000000073240000 - 0000000073245000: C:\WINDOWS\System32\SOFTPUB.DLL
(0000000073250000 - 0000000073255000: C:\WINDOWS\System32\riched32.dll
(0000000073620000 - 0000000073627000: C:\WINDOWS\System32\msdmo.dll
(00000000736d0000 - 0000000073714000: C:\WINDOWS\System32\DDRAW.dll
(00000000738b0000 - 0000000073977000: C:\WINDOWS\System32\D3DIM700.DLL
(0000000073b30000 - 0000000073b36000: C:\WINDOWS\System32\DCIMAN32.dll
(0000000073cc0000 - 0000000073cd0000: C:\WINDOWS\System32\cryptnet.dll
(0000000073e50000 - 0000000073e54000: C:\WINDOWS\System32\KsUser.dll
(0000000073e60000 - 0000000073e6f000: C:\windows\System32\devenum.dll
(0000000073e80000 - 0000000073ed5000: C:\WINDOWS\System32\DSOUND.DLL
(0000000073ee0000 - 000000007402b000: C:\windows\System32\Quartz.dll
(00000000746b0000 - 00000000746f4000: C:\WINDOWS\System32\MSCTF.dll
(0000000074700000 - 000000007478f000: C:\windows\System32\mlang.dll
(0000000074dc0000 - 0000000074e2a000: C:\WINDOWS\System32\RICHED20.dll
(00000000750e0000 - 00000000750f3000: C:\WINDOWS\System32\Cabinet.dll
(00000000751f0000 - 0000000075217000: C:\WINDOWS\System32\ADVPACK.DLL
(0000000075a20000 - 0000000075ac6000: C:\WINDOWS\system32\USERENV.dll
(0000000075e40000 - 0000000075ee7000: C:\WINDOWS\System32\SXS.DLL
(0000000075ef0000 - 0000000075f0e000: C:\WINDOWS\system32\appHelp.dll
(00000000760a0000 - 000000007611a000: C:\WINDOWS\system32\urlmon.dll
(00000000761b0000 - 0000000076249000: C:\WINDOWS\system32\WININET.dll
(0000000076250000 - 000000007625f000: C:\WINDOWS\system32\MSASN1.dll
(0000000076270000 - 00000000762fc000: C:\WINDOWS\system32\CRYPT32.dll
(0000000076330000 - 0000000076335000: C:\WINDOWS\System32\msimg32.dll
(0000000076360000 - 00000000763a6000: C:\WINDOWS\system32\comdlg32.dll
(0000000076630000 - 000000007671b000: C:\WINDOWS\System32\SETUPAPI.dll
(0000000076950000 - 0000000076975000: C:\WINDOWS\System32\ntshrui.dll
(0000000076980000 - 0000000076aca000: C:\WINDOWS\System32\SHDOCVW.dll
(0000000076ae0000 - 0000000076af5000: C:\WINDOWS\System32\ATL.DLL
(0000000076b00000 - 0000000076b2d000: C:\WINDOWS\System32\WINMM.dll
(0000000076bf0000 - 0000000076c1b000: C:\WINDOWS\System32\wintrust.dll
(0000000076c20000 - 0000000076c49000: C:\WINDOWS\System32\sfc_os.dll
(0000000076c50000 - 0000000076c72000: C:\WINDOWS\system32\IMAGEHLP.dll
(0000000076e40000 - 0000000076e4d000: C:\WINDOWS\System32\rtutils.dll
(0000000076e50000 - 0000000076e61000: C:\WINDOWS\System32\rasman.dll
(0000000076e70000 - 0000000076e9b000: C:\WINDOWS\System32\TAPI32.dll
(0000000076ea0000 - 0000000076ed7000: C:\WINDOWS\System32\RASAPI32.DLL
(0000000076ee0000 - 0000000076f05000: C:\WINDOWS\System32\DNSAPI.dll
(0000000076f20000 - 0000000076f4d000: C:\WINDOWS\system32\WLDAP32.dll
(0000000076f50000 - 0000000076f60000: C:\WINDOWS\System32\Secur32.dll
(0000000076f70000 - 0000000076f77000: C:\WINDOWS\System32\winrnr.dll
(0000000076f80000 - 0000000076f85000: C:\WINDOWS\System32\rasadhlp.dll
(0000000076f90000 - 0000000077008000: C:\WINDOWS\System32\CLBCATQ.DLL
(0000000077010000 - 00000000770e2000: C:\WINDOWS\System32\COMRes.dll
(00000000770f0000 - 000000007717b000: C:\WINDOWS\system32\OLEAUT32.dll
(00000000772a0000 - 0000000077304000: C:\WINDOWS\system32\SHLWAPI.dll
(00000000773a0000 - 0000000077b9e000: C:\WINDOWS\system32\SHELL32.dll
(0000000077ba0000 - 0000000077ba7000: C:\WINDOWS\System32\midimap.dll
(0000000077bb0000 - 0000000077bc4000: C:\WINDOWS\System32\MSACM32.dll
(0000000077bd0000 - 0000000077bd7000: C:\WINDOWS\system32\VERSION.dll
(0000000077be0000 - 0000000077c33000: C:\WINDOWS\system32\msvcrt.dll
(0000000077c40000 - 0000000077c80000: C:\WINDOWS\system32\GDI32.dll
(0000000077d10000 - 0000000077d9c000: C:\WINDOWS\system32\USER32.dll
(0000000077da0000 - 0000000077e3d000: C:\WINDOWS\system32\ADVAPI32.dll
(0000000077e40000 - 0000000077f31000: C:\WINDOWS\system32\kernel32.dll
(0000000077f40000 - 0000000077fed000: C:\WINDOWS\System32\ntdll.dll
(0000000078000000 - 0000000078086000: C:\WINDOWS\system32\RPCRT4.dll
(0000000078090000 - 0000000078174000: C:\WINDOWS\WinSxS\X86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805\COMCTL32.dll

*----> Scarico dello stato per l'id del thread 0x7b0 <----*

eax=00000001 ebx=01570d00 ecx=00000000 edx=00000000 esi=014970ec edi=04e80609
eip=002b2c3e esp=0012f9c8 ebp=0012fa28 iopl=0 nv up ei pl nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000206

*** WARNING: Unable to verify checksum for C:\Programmi\Mozilla Firefox\xpcom.dll
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\Programmi\Mozilla Firefox\xpcom.dll -
funzione: xpcom!nsCStringArray__`vftable'
002b2c20 96 xchg eax,esi
002b2c21 5d pop ebp
002b2c22 dc9f11d1c183 fcomp qword ptr [edi+0x83c1d111]
002b2c28 d498 aam ???
002b2c2a 2900 sub [eax],eax
002b2c2c 15d22a00de adc eax,0xde002ad2
002b2c31 98 cwde
002b2c32 2900 sub [eax],eax
002b2c34 11942900249429 adc [ecx+ebp+0x29942400],edx
002b2c3b 004790 add [edi-0x70],al
FAULT ->002b2c3e 2900 sub [eax],eax ds:0023:00000001=????????
002b2c40 e0dc loopne xpcom!nsCStringArray__`vftable'+0x20a6 (002b2c1e)
002b2c42 2900 sub [eax],eax
002b2c44 f9 stc
002b2c45 90 nop
002b2c46 2900 sub [eax],eax
002b2c48 3b932900bb92 cmp edx,[ebx+0x92bb0029]
002b2c4e 2900 sub [eax],eax
002b2c50 fb sti
002b2c51 92 xchg eax,edx
002b2c52 2900 sub [eax],eax

*----> Back Trace dello stack <----*
*** WARNING: Unable to verify checksum for C:\Programmi\Mozilla Firefox\firefox.exe
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\Programmi\Mozilla Firefox\firefox.exe -
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\kernel32.dll -
ChildEBP RetAddr Args to Child
0012fa28 0078b586 014970e0 00402741 013070f0 xpcom!nsCStringArray__`vftable'+0x20c6
0012ff04 00401012 003fbef4 013070f0 008a7fbc firefox!nsPrintSettings__GetStartPageRange+0x78ec4
0012ffc0 77e614c7 772a1a29 80000002 7ffdf000 firefox+0x1012
0012fff0 00000000 008a2c60 00000000 78746341 kernel32!GetCurrentDirectoryW+0x44

*----> Scarico Raw Stack <----*
000000000012f9c8 5e 98 29 00 00 0d 57 01 - 80 71 30 01 00 00 00 00 ^.)...W..q0.....
000000000012f9d8 ee d3 2a 00 09 2c 51 00 - e0 70 49 01 00 00 00 80 ..*..,Q..pI.....
000000000012f9e8 ee d3 2a 00 00 00 00 00 - 28 01 05 00 28 c1 00 00 ..*.....(...(...
000000000012f9f8 00 00 00 00 c8 ba 32 01 - 3a 8c 7c 01 da 01 00 00 ......2.:.|.....
000000000012fa08 89 02 00 00 f0 ff 2a 00 - 74 8e a0 00 00 00 00 00 ......*.t.......
000000000012fa18 1c fa 12 00 00 00 00 00 - 01 00 00 00 01 00 00 00 ................
000000000012fa28 04 ff 12 00 86 b5 78 00 - e0 70 49 01 41 27 40 00 ......x..pI.A'@.
000000000012fa38 f0 70 30 01 29 1a 2a 77 - d8 c9 c2 77 00 00 00 00 .p0.).*w...w....
000000000012fa48 32 30 30 34 31 31 31 30 - 31 35 00 00 14 fb 12 00 2004111015......
000000000012fa58 00 01 00 00 bd 53 da 77 - 00 00 00 00 5c fb 12 00 .....S.w....\...
000000000012fa68 08 00 00 00 80 84 e0 77 - 60 84 e0 77 75 5c da 77 .......w`..wu\.w
000000000012fa78 fc fa 12 00 60 84 e0 77 - 00 00 00 00 c0 fc 12 00 ....`..w........
000000000012fa88 03 00 00 00 24 fb 12 00 - 10 fb 12 00 08 fb 12 00 ....$...........
000000000012fa98 08 00 15 c0 00 00 00 00 - 00 f0 fd 7f 00 e0 fd 7f ................
000000000012faa8 c8 fa 12 00 82 50 f4 77 - ec fa 12 00 24 fb 12 00 .....P.w....$...
000000000012fab8 10 fb 12 00 c4 fa 12 00 - 1d 5b f6 77 30 56 e5 77 .........[.w0V.w
000000000012fac8 60 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 `...............
000000000012fad8 fc fa 12 00 08 00 39 00 - 80 84 e0 77 00 01 00 00 ......9....w....
000000000012fae8 9c fb 12 00 15 56 e5 77 - 00 00 00 00 c0 fc 12 00 .....V.w........
000000000012faf8 00 00 00 00 6f 77 6b d1 - f5 0b 4b 30 06 50 c2 1a ....owk...K0.P..

*----> Scarico dello stato per l'id del thread 0x7b4 <----*

eax=99e4a000 ebx=003f807c ecx=77f41566 edx=00000000 esi=00000160 edi=00000000
eip=7ffe0304 esp=012bfe64 ebp=012bfec8 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000202

funzione: <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 8bd4 mov edx,esp
7ffe0307 0f05 syscall
7ffe0309 c3 ret
7ffe030a 8ac8 mov cl,al
7ffe030c ff1570464d80 call dword ptr [804d4670]
7ffe0312 8b4510 mov eax,[ebp+0x10]
7ffe0315 33c9 xor ecx,ecx
7ffe0317 663908 cmp [eax],cx
7ffe031a 894dfc mov [ebp-0x4],ecx
7ffe031d 0f840d000000 je 7ffe0330

*----> Back Trace dello stack <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\System32\ntdll.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
012bfe60 77f6671a 77e5a62d 00000160 00000000 *SharedUserSystemCall+0xc (FPO: [0,0,0])
012bfec8 77e5ac21 00000160 0000ea60 00000000 ntdll!NtWaitForSingleObject+0xc
0000ea60 00000000 00000000 00000000 00000000 kernel32!WaitForSingleObject+0xf

*----> Scarico Raw Stack <----*
00000000012bfe64 1a 67 f6 77 2d a6 e5 77 - 60 01 00 00 00 00 00 00 .g.w-..w`.......
00000000012bfe74 8c fe 2b 01 64 81 3f 00 - 30 82 3f 00 7c 80 3f 00 ..+.d.?.0.?.|.?.
00000000012bfe84 00 00 00 00 8c fe 2b 01 - 00 ba 3c dc ff ff ff ff ......+...<.....
00000000012bfe94 00 f0 fd 7f 00 d0 fd 7f - 14 00 00 00 01 00 00 00 ................
00000000012bfea4 00 00 00 00 00 00 00 00 - 10 00 00 00 78 fe 2b 01 ............x.+.
00000000012bfeb4 f5 81 01 30 a4 ff 2b 01 - 09 48 e7 77 e0 3a e6 77 ...0..+..H.w.:.w
00000000012bfec4 00 00 00 00 60 ea 00 00 - 21 ac e5 77 60 01 00 00 ....`...!..w`...
00000000012bfed4 60 ea 00 00 00 00 00 00 - 5c 7e 01 30 60 01 00 00 `.......\~.0`...
00000000012bfee4 60 ea 00 00 60 80 3f 00 - 30 82 3f 00 54 ff 2b 01 `...`.?.0.?.T.+.
00000000012bfef4 60 80 3f 00 fc 41 01 30 - 64 81 3f 00 7c 80 3f 00 `.?..A.0d.?.|.?.
00000000012bff04 98 34 33 00 b0 45 01 30 - 98 34 33 00 43 43 01 30 .43..E.0.43.CC.0
00000000012bff14 30 82 3f 00 f0 80 3f 00 - 60 80 3f 00 98 34 33 00 0.?...?.`.?..43.
00000000012bff24 70 6f 3f 00 50 d0 29 00 - f0 80 3f 00 98 34 33 00 po?.P.)...?..43.
00000000012bff34 dc 82 3f 00 8c 81 3f 00 - 40 84 3f 00 a8 35 2b 00 ..?...?.@.?..5+.
00000000012bff44 b0 98 2c 00 0a 00 00 00 - 01 00 00 00 01 00 00 00 ..,.............
00000000012bff54 b4 ff 2b 01 55 75 29 00 - 00 00 00 00 30 82 3f 00 ..+.Uu).....0.?.
00000000012bff64 11 4c 01 30 80 81 3f 00 - 40 45 3f 00 40 45 3f 00 .L.0..?.@E?.@E?.
00000000012bff74 12 00 00 00 60 e6 3f 00 - 3b 6d 01 30 30 82 3f 00 ....`.?.;m.00.?.
00000000012bff84 b8 7f c0 77 30 82 3f 00 - 12 00 00 00 e8 09 3f 00 ...w0.?.......?.
00000000012bff94 40 84 3f 00 6b b8 4f 80 - 8c ff 2b 01 00 00 00 00 @.?.k.O...+.....

*----> Scarico dello stato per l'id del thread 0x7bc <----*

eax=05a9a958 ebx=0016d240 ecx=014a85b0 edx=00000000 esi=7fffffff edi=ffffffff
eip=7ffe0304 esp=017dcd54 ebp=017dcd90 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000202

funzione: <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 8bd4 mov edx,esp
7ffe0307 0f05 syscall
7ffe0309 c3 ret
7ffe030a 8ac8 mov cl,al
7ffe030c ff1570464d80 call dword ptr [804d4670]
7ffe0312 8b4510 mov eax,[ebp+0x10]
7ffe0315 33c9 xor ecx,ecx
7ffe0317 663908 cmp [eax],cx
7ffe031a 894dfc mov [ebp-0x4],ecx
7ffe031d 0f840d000000 je 7ffe0330

*----> Back Trace dello stack <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\mswsock.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\System32\WS2_32.dll -
*** WARNING: Unable to verify checksum for C:\Programmi\Mozilla Firefox\nspr4.dll
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\Programmi\Mozilla Firefox\nspr4.dll -
ChildEBP RetAddr Args to Child
017dcd50 77f6671a 719d1f97 000001e4 00000001 *SharedUserSystemCall+0xc (FPO: [0,0,0])
017dcd90 719d20a4 000001e4 000001b8 00000000 ntdll!NtWaitForSingleObject+0xc
017dce74 71a31930 00000000 017ddf20 00000000 mswsock+0x20a4
017dcec4 30019969 00000000 017ddf20 00000000 WS2_32!select+0xa0
00000000 00000000 00000000 00000000 00000000 nspr4!PR_MD_UNLOCK+0x1789

*----> Scarico Raw Stack <----*
00000000017dcd54 1a 67 f6 77 97 1f 9d 71 - e4 01 00 00 01 00 00 00 .g.w...q........
00000000017dcd64 7c cd 7d 01 10 ce 7d 01 - 20 df 7d 01 00 ce 7d 01 |.}...}. .}...}.
00000000017dcd74 fa 27 a2 c4 bb 03 c5 01 - ff ff ff ff ff ff ff 7f .'..............
00000000017dcd84 40 d2 16 00 00 00 00 00 - 00 00 00 00 74 ce 7d 01 @...........t.}.
00000000017dcd94 a4 20 9d 71 e4 01 00 00 - b8 01 00 00 00 00 00 00 . .q............
00000000017dcda4 04 00 00 00 00 00 00 00 - b8 cf 16 00 00 00 00 00 ................
00000000017dcdb4 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000017dcdc4 00 00 00 00 3b 5b f6 77 - 1b f0 e5 77 00 00 00 00 ....;[.w...w....
00000000017dcdd4 00 00 00 00 00 00 00 00 - 1c 00 00 00 00 00 00 00 ................
00000000017dcde4 ca 11 a2 71 d8 90 f4 01 - 18 f7 18 00 38 a0 24 03 ...q........8.$.
00000000017dcdf4 38 a0 24 03 00 00 00 00 - 1c ce 7d 01 ff ff ff ff 8.$.......}.....
00000000017dce04 ff ff ff 7f 01 00 00 00 - 00 90 9e 71 b8 01 00 00 ...........q....
00000000017dce14 19 00 00 00 00 00 00 00 - c4 09 00 00 19 00 00 00 ................
00000000017dce24 00 00 00 00 c4 09 00 00 - 02 01 00 00 18 ce 7d 01 ..............}.
00000000017dce34 fc 02 00 00 02 01 00 00 - bc 2a 9f 71 28 43 9f 71 .........*.q(C.q
00000000017dce44 1c 00 00 00 01 00 00 00 - 00 00 00 00 00 ce 7d 01 ..............}.
00000000017dce54 00 00 00 00 40 d2 16 00 - a8 cd 7d 01 00 82 01 30 ....@.....}....0
00000000017dce64 b4 ce 7d 01 bc 2a 9f 71 - 80 b7 9d 71 ff ff ff ff ..}..*.q...q....
00000000017dce74 c4 ce 7d 01 30 19 a3 71 - 00 00 00 00 20 df 7d 01 ..}.0..q.... .}.
00000000017dce84 00 00 00 00 00 00 00 00 - 00 00 00 00 a4 ce 7d 01 ..............}.

*----> Scarico dello stato per l'id del thread 0x7e4 <----*

eax=01adffa4 ebx=013569dc ecx=01359058 edx=00000000 esi=000001fc edi=00000000
eip=7ffe0304 esp=01adfe74 ebp=01adfed8 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000202

funzione: <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 8bd4 mov edx,esp
7ffe0307 0f05 syscall
7ffe0309 c3 ret
7ffe030a 8ac8 mov cl,al
7ffe030c ff1570464d80 call dword ptr [804d4670]
7ffe0312 8b4510 mov eax,[ebp+0x10]
7ffe0315 33c9 xor ecx,ecx
7ffe0317 663908 cmp [eax],cx
7ffe031a 894dfc mov [ebp-0x4],ecx
7ffe031d 0f840d000000 je 7ffe0330

*----> Back Trace dello stack <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
01adfe70 77f6671a 77e5a62d 000001fc 00000000 *SharedUserSystemCall+0xc (FPO: [0,0,0])
01adfed8 77e5ac21 000001fc 00009bc1 00000000 ntdll!NtWaitForSingleObject+0xc
00009bc1 00000000 00000000 00000000 00000000 kernel32!WaitForSingleObject+0xf

*----> Scarico Raw Stack <----*
0000000001adfe74 1a 67 f6 77 2d a6 e5 77 - fc 01 00 00 00 00 00 00 .g.w-..w........
0000000001adfe84 9c fe ad 01 8c 8f 35 01 - 58 90 35 01 dc 69 35 01 ......5.X.5..i5.
0000000001adfe94 01 00 00 00 9c fe ad 01 - f0 dc 3b e8 ff ff ff ff ..........;.....
0000000001adfea4 00 f0 fd 7f 00 90 fd 7f - 14 00 00 00 01 00 00 00 ................
0000000001adfeb4 00 00 00 00 00 00 00 00 - 10 00 00 00 88 fe ad 01 ................
0000000001adfec4 00 00 00 00 a4 ff ad 01 - 09 48 e7 77 e0 3a e6 77 .........H.w.:.w
0000000001adfed4 00 00 00 00 c1 9b 00 00 - 21 ac e5 77 fc 01 00 00 ........!..w....
0000000001adfee4 c1 9b 00 00 00 00 00 00 - 5c 7e 01 30 fc 01 00 00 ........\~.0....
0000000001adfef4 c1 9b 00 00 c0 69 35 01 - 58 90 35 01 78 8e 35 01 .....i5.X.5.x.5.
0000000001adff04 c0 69 35 01 fc 41 01 30 - 8c 8f 35 01 dc 69 35 01 .i5..A.0..5..i5.
0000000001adff14 66 07 22 00 60 27 4d 01 - 66 07 22 00 43 43 01 30 f.".`'M.f.".CC.0
0000000001adff24 58 90 35 01 18 8f 35 01 - c0 69 35 01 66 07 22 00 X.5...5..i5.f.".
0000000001adff34 58 8e 35 01 7a a9 29 00 - 18 8f 35 01 66 07 22 00 X.5.z.)...5.f.".
0000000001adff44 04 91 35 01 b4 8f 35 01 - b4 ff ad 01 68 92 35 01 ..5...5.....h.5.
0000000001adff54 66 07 22 00 55 75 29 00 - e9 7f 2a 53 58 90 35 01 f.".Uu)...*SX.5.
0000000001adff64 11 4c 01 30 a8 8f 35 01 - 40 45 3f 00 40 45 3f 00 .L.0..5.@E?.@E?.
0000000001adff74 12 00 00 00 80 67 35 01 - 3b 6d 01 30 58 90 35 01 .....g5.;m.0X.5.
0000000001adff84 b8 7f c0 77 58 90 35 01 - 12 00 00 00 e8 09 3f 00 ...wX.5.......?.
0000000001adff94 68 92 35 01 6b b8 4f 80 - 8c ff ad 01 00 00 00 00 h.5.k.O.........
0000000001adffa4 dc ff ad 01 b0 3e c0 77 - c8 40 be 77 00 00 00 00 .....>.w.@.w....

*----> Scarico dello stato per l'id del thread 0x64c <----*

eax=72c92ecc ebx=0300ff1c ecx=000000fc edx=00000000 esi=00000000 edi=7ffdf000
eip=7ffe0304 esp=0300fed4 ebp=0300ff70 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000202

funzione: <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 8bd4 mov edx,esp
7ffe0307 0f05 syscall
7ffe0309 c3 ret
7ffe030a 8ac8 mov cl,al
7ffe030c ff1570464d80 call dword ptr [804d4670]
7ffe0312 8b4510 mov eax,[ebp+0x10]
7ffe0315 33c9 xor ecx,ecx
7ffe0317 663908 cmp [eax],cx
7ffe031a 894dfc mov [ebp-0x4],ecx
7ffe031d 0f840d000000 je 7ffe0330

*----> Back Trace dello stack <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0300fed0 77f6670b 77e55ee0 00000002 0300ff1c *SharedUserSystemCall+0xc (FPO: [0,0,0])
0300ff70 77e55faa 00000002 0300ffa4 00000000 ntdll!ZwWaitForMultipleObjects+0xc
0300ffb4 77e5d33b 00000000 00000021 41f4166a kernel32!WaitForMultipleObjects+0x17
0300ffec 00000000 72c92ecc 00000000 00000000 kernel32!RegisterWaitForInputIdle+0x43

*----> Scarico Raw Stack <----*
000000000300fed4 0b 67 f6 77 e0 5e e5 77 - 02 00 00 00 1c ff 00 03 .g.w.^.w........
000000000300fee4 01 00 00 00 00 00 00 00 - 00 00 00 00 21 00 00 00 ............!...
000000000300fef4 00 00 00 00 00 00 00 00 - f8 ab 46 f0 25 d5 4e 80 ..........F.%.N.
000000000300ff04 00 00 00 00 00 00 00 00 - b0 21 75 86 02 00 00 00 .........!u.....
000000000300ff14 00 f0 fd 7f 00 60 fd 7f - 68 03 00 00 54 03 00 00 .....`..h...T...
000000000300ff24 00 ca 4e 80 08 ca 4e 80 - 14 5f d6 85 a8 5d d6 85 ..N...N.._...]..
000000000300ff34 63 ed 58 80 00 ba 17 86 - 1c ff 00 03 00 60 fd 7f c.X..........`..
000000000300ff44 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000300ff54 10 00 00 00 f0 fe 00 03 - 00 00 00 00 dc ff 00 03 ................
000000000300ff64 09 48 e7 77 78 32 e6 77 - 00 00 00 00 b4 ff 00 03 .H.wx2.w........
000000000300ff74 aa 5f e5 77 02 00 00 00 - a4 ff 00 03 00 00 00 00 ._.w............
000000000300ff84 ff ff ff ff 00 00 00 00 - 0c 2f c9 72 02 00 00 00 ........./.r....
000000000300ff94 a4 ff 00 03 00 00 00 00 - ff ff ff ff 6a 16 f4 41 ............j..A
000000000300ffa4 68 03 00 00 54 03 00 00 - a8 ac 46 f0 30 62 f6 77 h...T.....F.0b.w
000000000300ffb4 ec ff 00 03 3b d3 e5 77 - 00 00 00 00 21 00 00 00 ....;..w....!...
000000000300ffc4 6a 16 f4 41 00 00 00 00 - 00 00 00 00 00 60 fd 7f j..A.........`..
000000000300ffd4 c0 ff 00 03 07 00 00 00 - ff ff ff ff 09 48 e7 77 .............H.w
000000000300ffe4 b8 3d e6 77 00 00 00 00 - 00 00 00 00 00 00 00 00 .=.w............
000000000300fff4 cc 2e c9 72 00 00 00 00 - 00 00 00 00 00 00 00 00 ...r............
0000000003010004 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

*----> Scarico dello stato per l'id del thread 0x460 <----*

eax=00000001 ebx=00000000 ecx=7ffaf000 edx=00000000 esi=00000001 edi=00000000
eip=7ffe0304 esp=0316ff08 ebp=0316ff40 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000202

funzione: <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 8bd4 mov edx,esp
7ffe0307 0f05 syscall
7ffe0309 c3 ret
7ffe030a 8ac8 mov cl,al
7ffe030c ff1570464d80 call dword ptr [804d4670]
7ffe0312 8b4510 mov eax,[ebp+0x10]
7ffe0315 33c9 xor ecx,ecx
7ffe0317 663908 cmp [eax],cx
7ffe031a 894dfc mov [ebp-0x4],ecx
7ffe031d 0f840d000000 je 7ffe0330

*----> Back Trace dello stack <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0316ff04 77f6670b 76b09dbe 00000002 0316ff6c *SharedUserSystemCall+0xc (FPO: [0,0,0])
0316ffb4 77e5d33b 00000000 00000000 00000000 ntdll!ZwWaitForMultipleObjects+0xc
0316ffec 00000000 76b09d87 00000000 00000000 kernel32!RegisterWaitForInputIdle+0x43

*----> Scarico Raw Stack <----*
000000000316ff08 0b 67 f6 77 be 9d b0 76 - 02 00 00 00 6c ff 16 03 .g.w...v....l...
000000000316ff18 01 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000316ff28 50 c9 4e 80 00 08 00 00 - 82 08 00 00 93 08 00 00 P.N.............
000000000316ff38 93 08 00 00 65 08 00 00 - 65 08 00 00 06 02 00 00 ....e...e.......
000000000316ff48 00 00 00 00 90 ac 46 f0 - 86 b8 4f 80 00 00 00 00 ......F...O.....
000000000316ff58 05 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000316ff68 48 b8 4f 80 9c 03 00 00 - b0 03 00 00 64 04 00 00 H.O.........d...
000000000316ff78 24 04 00 00 24 04 00 00 - c0 04 00 00 c0 04 00 00 $...$...........
000000000316ff88 68 04 00 00 01 ac 46 f0 - 00 00 00 00 00 ba 17 86 h.....F.........
000000000316ff98 6b b8 4f 80 00 00 00 00 - 00 00 00 00 00 00 00 00 k.O.............
000000000316ffa8 6e b8 4f 80 a8 ac 46 f0 - 02 00 00 00 ec ff 16 03 n.O...F.........
000000000316ffb8 3b d3 e5 77 00 00 00 00 - 00 00 00 00 00 00 00 00 ;..w............
000000000316ffc8 00 00 00 00 00 00 00 00 - 00 f0 fa 7f c0 ff 16 03 ................
000000000316ffd8 07 00 00 00 ff ff ff ff - 09 48 e7 77 b8 3d e6 77 .........H.w.=.w
000000000316ffe8 00 00 00 00 00 00 00 00 - 00 00 00 00 87 9d b0 76 ...............v
000000000316fff8 00 00 00 00 00 00 00 00 - 08 00 00 00 02 01 00 00 ................
0000000003170008 ee ff ee ff 00 00 00 00 - 00 00 15 00 00 00 00 00 ................
0000000003170018 00 00 17 03 00 02 00 00 - 40 00 17 03 00 00 37 03 ........@.....7.
0000000003170028 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000003170038 40 00 17 03 00 00 00 00 - f7 00 08 00 02 00 0c 00 @...............

*----> Scarico dello stato per l'id del thread 0x80 <----*

eax=77f5c282 ebx=00000000 ecx=00000000 edx=00000000 esi=00000000 edi=00000000
eip=7ffe0304 esp=0346ff9c ebp=0346ffb4 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000202

funzione: <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 8bd4 mov edx,esp
7ffe0307 0f05 syscall
7ffe0309 c3 ret
7ffe030a 8ac8 mov cl,al
7ffe030c ff1570464d80 call dword ptr [804d4670]
7ffe0312 8b4510 mov eax,[ebp+0x10]
7ffe0315 33c9 xor ecx,ecx
7ffe0317 663908 cmp [eax],cx
7ffe031a 894dfc mov [ebp-0x4],ecx
7ffe031d 0f840d000000 je 7ffe0330

*----> Back Trace dello stack <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0346ff98 77f65ab4 77f5c2c7 00000001 0346ffac *SharedUserSystemCall+0xc (FPO: [0,0,0])
0346ffb4 77e5d33b 00000000 00000000 00000000 ntdll!ZwDelayExecution+0xc
0346ffec 00000000 77f5c282 00000000 00000000 kernel32!RegisterWaitForInputIdle+0x43

*----> Scarico Raw Stack <----*
000000000346ff9c b4 5a f6 77 c7 c2 f5 77 - 01 00 00 00 ac ff 46 03 .Z.w...w......F.
000000000346ffac 00 00 00 00 00 00 00 80 - ec ff 46 03 3b d3 e5 77 ..........F.;..w
000000000346ffbc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000346ffcc 00 00 00 00 00 50 fd 7f - c0 ff 46 03 07 00 00 00 .....P....F.....
000000000346ffdc ff ff ff ff 09 48 e7 77 - b8 3d e6 77 00 00 00 00 .....H.w.=.w....
000000000346ffec 00 00 00 00 00 00 00 00 - 82 c2 f5 77 00 00 00 00 ...........w....
000000000346fffc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000347000c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000347001c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000347002c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000347003c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000347004c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000347005c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000347006c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000347007c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000347008c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000347009c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000034700ac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000034700bc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000034700cc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

*----> Scarico dello stato per l'id del thread 0x7a0 <----*

eax=71a40b38 ebx=71a42268 ecx=71a360be edx=00000000 esi=00000584 edi=00000000
eip=7ffe0304 esp=0856ff24 ebp=0856ff88 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000202

funzione: <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 8bd4 mov edx,esp
7ffe0307 0f05 syscall
7ffe0309 c3 ret
7ffe030a 8ac8 mov cl,al
7ffe030c ff1570464d80 call dword ptr [804d4670]
7ffe0312 8b4510 mov eax,[ebp+0x10]
7ffe0315 33c9 xor ecx,ecx
7ffe0317 663908 cmp [eax],cx
7ffe031a 894dfc mov [ebp-0x4],ecx
7ffe031d 0f840d000000 je 7ffe0330

*----> Back Trace dello stack <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0856ff20 77f6671a 77e5a62d 00000584 00000000 *SharedUserSystemCall+0xc (FPO: [0,0,0])
0856ff88 77e5ac21 00000584 ffffffff 00000000 ntdll!NtWaitForSingleObject+0xc
77f655de 8b000000 83042454 7500147a 42fff03b kernel32!WaitForSingleObject+0xf
180d8b64 00000000 00000000 00000000 00000000 0x8b000000

*----> Scarico Raw Stack <----*
000000000856ff24 1a 67 f6 77 2d a6 e5 77 - 84 05 00 00 00 00 00 00 .g.w-..w........
000000000856ff34 00 00 00 00 88 08 17 03 - 88 08 17 03 68 22 a4 71 ............h".q
000000000856ff44 b3 05 00 00 00 00 00 00 - 58 00 00 00 0a 00 00 00 ........X.......
000000000856ff54 00 f0 fd 7f 00 a0 fa 7f - 14 00 00 00 01 00 00 00 ................
000000000856ff64 00 00 00 00 00 00 00 00 - 10 00 00 00 38 ff 56 08 ............8.V.
000000000856ff74 dc ff 56 08 dc ff 56 08 - 09 48 e7 77 e0 3a e6 77 ..V...V..H.w.:.w
000000000856ff84 00 00 00 00 de 55 f6 77 - 21 ac e5 77 84 05 00 00 .....U.w!..w....
000000000856ff94 ff ff ff ff 00 00 00 00 - d7 87 a3 71 84 05 00 00 ...........q....
000000000856ffa4 ff ff ff ff f0 d5 f5 77 - 05 90 f6 77 ec ff 56 08 .......w...w..V.
000000000856ffb4 88 08 17 03 3b d3 e5 77 - 84 05 00 00 05 90 f6 77 ....;..w.......w
000000000856ffc4 f0 d5 f5 77 88 08 17 03 - 00 00 00 00 00 a0 fa 7f ...w............
000000000856ffd4 c0 ff 56 08 07 00 00 00 - ff ff ff ff 09 48 e7 77 ..V..........H.w
000000000856ffe4 b8 3d e6 77 00 00 00 00 - 00 00 00 00 00 00 00 00 .=.w............
000000000856fff4 a7 87 a3 71 88 08 17 03 - 00 00 00 00 00 00 00 00 ...q............
0000000008570004 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000008570014 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000008570024 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000008570034 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000008570044 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000008570054 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

*----> Scarico dello stato per l'id del thread 0x7dc <----*

eax=71a036a0 ebx=02e35d10 ecx=0016c6f0 edx=00000000 esi=7fffffff edi=ffffffff
eip=7ffe0304 esp=0866fae4 ebp=0866fb20 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000202

funzione: <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 8bd4 mov edx,esp
7ffe0307 0f05 syscall
7ffe0309 c3 ret
7ffe030a 8ac8 mov cl,al
7ffe030c ff1570464d80 call dword ptr [804d4670]
7ffe0312 8b4510 mov eax,[ebp+0x10]
7ffe0315 33c9 xor ecx,ecx
7ffe0317 663908 cmp [eax],cx
7ffe031a 894dfc mov [ebp-0x4],ecx
7ffe031d 0f840d000000 je 7ffe0330

*----> Back Trace dello stack <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\WININET.dll -
ChildEBP RetAddr Args to Child
0866fae0 77f6671a 719d1f97 00000680 00000001 *SharedUserSystemCall+0xc (FPO: [0,0,0])
0866fb20 719d20a4 00000680 0000067c 00000000 ntdll!NtWaitForSingleObject+0xc
0866fc04 71a31930 00000001 0866fe84 0866fc7c mswsock+0x20a4
0866fc54 761d387c 00000001 0866fe84 0866fc7c WS2_32!select+0xa0
0866ffb0 761d4485 77e5d33b 042d0070 00150808 WININET!GetUrlCacheEntryInfoW+0x73d
0866ffec 00000000 761d447c 042d0070 00000000 WININET!InternetCrackUrlW+0x9dd

*----> Scarico Raw Stack <----*
000000000866fae4 1a 67 f6 77 97 1f 9d 71 - 80 06 00 00 01 00 00 00 .g.w...q........
000000000866faf4 0c fb 66 08 a0 fb 66 08 - 84 fe 66 08 90 fb 66 08 ..f...f...f...f.
000000000866fb04 e2 1a 13 c4 bb 03 c5 01 - ff ff ff ff ff ff ff 7f ................
000000000866fb14 10 5d e3 02 00 00 00 00 - 00 00 00 00 04 fc 66 08 .]............f.
000000000866fb24 a4 20 9d 71 80 06 00 00 - 7c 06 00 00 00 00 00 00 . .q....|.......
000000000866fb34 04 00 00 00 80 fd 66 08 - 40 18 d2 03 7c fc 66 08 ......f.@...|.f.
000000000866fb44 20 01 2d 04 00 00 00 00 - 00 00 00 00 00 00 df 02 .-.............
000000000866fb54 00 80 c3 03 08 80 c3 03 - 78 01 15 00 e8 93 24 03 ........x.....$.
000000000866fb64 30 19 e1 02 00 00 00 00 - 10 00 00 00 00 00 00 00 0...............
000000000866fb74 00 00 00 00 00 00 00 00 - 00 00 00 00 80 0f 05 fd ................
000000000866fb84 ff ff ff ff 00 00 00 00 - ac fb 66 08 80 0f 05 fd ..........f.....
000000000866fb94 ff ff ff ff 01 00 00 00 - 00 26 f4 77 7c 06 00 00 .........&.w|...
000000000866fba4 19 00 00 00 26 00 00 00 - 08 01 00 00 e0 97 17 00 ....&...........
000000000866fbb4 fc fb 66 08 05 90 f6 77 - c8 d5 01 01 00 00 15 00 ..f....w........
000000000866fbc4 20 fb 66 08 cb 60 e5 77 - 14 fc 66 08 05 90 f6 77 .f..`.w..f....w
000000000866fbd4 1c 00 00 00 01 00 00 00 - 00 00 00 00 90 fb 66 08 ..............f.
000000000866fbe4 00 00 00 00 10 5d e3 02 - 38 fb 66 08 10 b7 22 76 .....]..8.f..."v
000000000866fbf4 44 fc 66 08 bc 2a 9f 71 - 80 b7 9d 71 ff ff ff ff D.f..*.q...q....
000000000866fc04 54 fc 66 08 30 19 a3 71 - 01 00 00 00 84 fe 66 08 T.f.0..q......f.
000000000866fc14 7c fc 66 08 80 fd 66 08 - 88 ff 66 08 34 fc 66 08 |.f...f...f.4.f.

*----> Scarico dello stato per l'id del thread 0x7f8 <----*

eax=000000c0 ebx=00000000 ecx=00000000 edx=00000000 esi=00000000 edi=00000001
eip=7ffe0304 esp=08b6fcec ebp=08b6ffb4 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202

funzione: <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 8bd4 mov edx,esp
7ffe0307 0f05 syscall
7ffe0309 c3 ret
7ffe030a 8ac8 mov cl,al
7ffe030c ff1570464d80 call dword ptr [804d4670]
7ffe0312 8b4510 mov eax,[ebp+0x10]
7ffe0315 33c9 xor ecx,ecx
7ffe0317 663908 cmp [eax],cx
7ffe031a 894dfc mov [ebp-0x4],ecx
7ffe031d 0f840d000000 je 7ffe0330

*----> Back Trace dello stack <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
08b6fce8 77f6670b 77f5b5f4 00000018 08b6fd30 *SharedUserSystemCall+0xc (FPO: [0,0,0])
08b6ffb4 77e5d33b 00000000 00000000 00000000 ntdll!ZwWaitForMultipleObjects+0xc
08b6ffec 00000000 77f5b4bf 00000000 00000000 kernel32!RegisterWaitForInputIdle+0x43

*----> Scarico Raw Stack <----*
0000000008b6fcec 0b 67 f6 77 f4 b5 f5 77 - 18 00 00 00 30 fd b6 08 .g.w...w....0...
0000000008b6fcfc 01 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000008b6fd0c 00 00 00 00 00 00 00 00 - e8 49 fb 77 e8 49 fb 77 .........I.w.I.w
0000000008b6fd1c 08 06 00 00 f8 07 00 00 - 18 00 00 00 18 00 00 00 ................
0000000008b6fd2c 17 00 00 00 0c 06 00 00 - d0 03 00 00 10 07 00 00 ................
0000000008b6fd3c 18 07 00 00 20 07 00 00 - 2c 07 00 00 44 07 00 00 .... ...,...D...
0000000008b6fd4c 4c 07 00 00 58 07 00 00 - 68 07 00 00 74 07 00 00 L...X...h...t...
0000000008b6fd5c 7c 07 00 00 88 07 00 00 - 94 07 00 00 a0 07 00 00 |...............
0000000008b6fd6c a8 07 00 00 b4 07 00 00 - e4 07 00 00 f0 07 00 00 ................
0000000008b6fd7c fc 07 00 00 1c 08 00 00 - 28 08 00 00 34 08 00 00 ........(...4...
0000000008b6fd8c 40 08 00 00 44 08 00 00 - 00 00 00 00 00 00 00 00 @...D...........
0000000008b6fd9c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000008b6fdac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000008b6fdbc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000008b6fdcc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000008b6fddc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000008b6fdec 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000008b6fdfc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000008b6fe0c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000008b6fe1c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

*----> Scarico dello stato per l'id del thread 0xb0 <----*

eax=00000000 ebx=08c6ff18 ecx=7ffa5000 edx=00000000 esi=00000000 edi=7ffdf000
eip=7ffe0304 esp=08c6fed0 ebp=08c6ff6c iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000202

funzione: <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 8bd4 mov edx,esp
7ffe0307 0f05 syscall
7ffe0309 c3 ret
7ffe030a 8ac8 mov cl,al
7ffe030c ff1570464d80 call dword ptr [804d4670]
7ffe0312 8b4510 mov eax,[ebp+0x10]
7ffe0315 33c9 xor ecx,ecx
7ffe0317 663908 cmp [eax],cx
7ffe031a 894dfc mov [ebp-0x4],ecx
7ffe031d 0f840d000000 je 7ffe0330

*----> Back Trace dello stack <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
08c6fecc 77f6670b 77e55ee0 00000003 08c6ff18 *SharedUserSystemCall+0xc (FPO: [0,0,0])
08c6ff6c 77e55faa 00000003 75ab3300 00000000 ntdll!ZwWaitForMultipleObjects+0xc
00000000 00000000 00000000 00000000 00000000 kernel32!WaitForMultipleObjects+0x17

*----> Scarico Raw Stack <----*
0000000008c6fed0 0b 67 f6 77 e0 5e e5 77 - 03 00 00 00 18 ff c6 08 .g.w.^.w........
0000000008c6fee0 01 00 00 00 00 00 00 00 - 00 00 00 00 a4 33 ab 75 .............3.u
0000000008c6fef0 00 00 00 00 f0 a6 e5 77 - 00 00 00 00 00 00 00 00 .......w........
0000000008c6ff00 00 00 00 00 00 00 01 00 - 00 00 15 00 03 00 00 00 ................
0000000008c6ff10 00 f0 fd 7f 00 50 fa 7f - 30 07 00 00 34 07 00 00 .....P..0...4...
0000000008c6ff20 5c 07 00 00 6a 16 f4 77 - 2e d9 e5 77 00 00 15 00 \...j..w...w....
0000000008c6ff30 00 00 00 00 3e d9 e5 77 - 18 ff c6 08 00 00 15 00 ....>..w........
0000000008c6ff40 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000008c6ff50 10 00 00 00 ec fe c6 08 - 16 00 18 00 dc ff c6 08 ................
0000000008c6ff60 09 48 e7 77 78 32 e6 77 - 00 00 00 00 00 00 00 00 .H.wx2.w........
0000000008c6ff70 aa 5f e5 77 03 00 00 00 - 00 33 ab 75 00 00 00 00 ._.w.....3.u....
0000000008c6ff80 ff ff ff ff 00 00 00 00 - 45 5b a2 75 03 00 00 00 ........E[.u....
0000000008c6ff90 00 33 ab 75 00 00 00 00 - ff ff ff ff 00 00 15 00 .3.u............
0000000008c6ffa0 00 00 00 00 fc c9 12 00 - ec ff c6 08 00 00 00 00 ................
0000000008c6ffb0 03 00 00 00 00 00 a2 75 - 3b d3 e5 77 00 00 00 00 .......u;..w....
0000000008c6ffc0 fc c9 12 00 00 00 15 00 - 00 00 00 00 00 00 00 00 ................
0000000008c6ffd0 00 50 fa 7f c0 ff c6 08 - 07 00 00 00 ff ff ff ff .P..............
0000000008c6ffe0 09 48 e7 77 b8 3d e6 77 - 00 00 00 00 00 00 00 00 .H.w.=.w........
0000000008c6fff0 00 00 00 00 ea 5a a2 75 - 00 00 00 00 00 00 00 00 .....Z.u........
0000000008c70000 f8 3f 00 00 00 00 00 00 - 10 00 00 00 00 00 00 00 .?..............

*----> Scarico dello stato per l'id del thread 0x30c <----*

eax=780015dd ebx=0323d3a0 ecx=019dfb40 edx=00000000 esi=00000000 edi=00000000
eip=7ffe0304 esp=07ebfe28 ebp=07ebff90 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000202

funzione: <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 8bd4 mov edx,esp
7ffe0307 0f05 syscall
7ffe0309 c3 ret
7ffe030a 8ac8 mov cl,al
7ffe030c ff1570464d80 call dword ptr [804d4670]
7ffe0312 8b4510 mov eax,[ebp+0x10]
7ffe0315 33c9 xor ecx,ecx
7ffe0317 663908 cmp [eax],cx
7ffe031a 894dfc mov [ebp-0x4],ecx
7ffe031d 0f840d000000 je 7ffe0330

*----> Back Trace dello stack <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\RPCRT4.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\System32\WSOCK32.dll -
ChildEBP RetAddr Args to Child
07ebfe24 77f662b7 780016a4 0000021c 07ebff80 *SharedUserSystemCall+0xc (FPO: [0,0,0])
07ebff90 78001601 780019d6 001530f8 019dfb3c ntdll!ZwReplyWaitReceivePortEx+0xc
03246908 ffffffff 0000057c 0000044c 00000000 RPCRT4+0x1601
00000000 00000000 00000000 00000000 00000000 0xffffffff

*----> Scarico Raw Stack <----*
0000000007ebfe28 b7 62 f6 77 a4 16 00 78 - 1c 02 00 00 80 ff eb 07 .b.w...x........
0000000007ebfe38 00 00 00 00 a0 d3 23 03 - 60 ff eb 07 00 00 00 00 ......#.`.......
0000000007ebfe48 9c 36 50 c0 9c 36 50 c0 - e8 38 34 86 55 02 00 00 .6P..6P..84.U...
0000000007ebfe58 c4 9b 4f 80 55 02 00 00 - e8 38 34 86 00 00 fd 7f ..O.U....84.....
0000000007ebfe68 fc 07 30 c0 00 00 00 00 - 55 02 00 00 00 00 00 00 ..0.....U.......
0000000007ebfe78 00 00 00 00 5f 00 00 00 - 00 00 00 00 a8 e1 31 86 ...._.........1.
0000000007ebfe88 c4 eb cd f0 38 9d 4f 80 - fc 07 30 c0 c4 eb cd f0 ....8.O...0.....
0000000007ebfe98 f1 9c 4f 80 00 70 fd 7f - 00 00 00 00 00 00 00 00 ..O..p..........
0000000007ebfea8 28 ee d5 85 f0 36 34 86 - 01 37 34 86 00 00 00 00 (....64..74.....
0000000007ebfeb8 5c ff 1f c0 f0 36 34 86 - 00 00 00 00 00 00 6d 00 \....64.......m.
0000000007ebfec8 ff ff 6c 00 00 00 00 00 - 00 00 6d 00 00 00 00 00 ..l.......m.....
0000000007ebfed8 f0 36 34 86 3c eb cd f0 - 00 00 00 00 ff ff ff ff .64.<...........
0000000007ebfee8 da 0e 51 80 90 3b 50 80 - ff ff ff ff 00 70 fd 7f ..Q..;P......p..
0000000007ebfef8 40 a1 4d 80 ff ff ff ff - 88 ec cd f0 8c ec cd f0 @.M.............
0000000007ebff08 00 80 00 00 00 32 50 86 - 08 32 50 86 00 00 00 00 .....2P..2P.....
0000000007ebff18 28 ec cd f0 28 50 7f 86 - 44 7f e8 85 00 ca 4e 80 (...(P..D.....N.
0000000007ebff28 08 ca 4e 80 14 7f e8 85 - a8 7d e8 85 63 ed 58 80 ..N......}..c.X.
0000000007ebff38 00 ba 17 86 a8 7d e8 85 - 2f 16 00 78 60 ff eb 07 .....}../..x`...
0000000007ebff48 4a 16 00 78 a0 ed 15 00 - b8 16 23 03 2c ee 15 00 J..x......#.,...
0000000007ebff58 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff ../M.....]......

*----> Scarico dello stato per l'id del thread 0x118 <----*

eax=719d19c4 ebx=c0000000 ecx=77f4248c edx=00000000 esi=00000000 edi=71a032ac
eip=7ffe0304 esp=0414ff80 ebp=719d0000 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000202

funzione: <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 8bd4 mov edx,esp
7ffe0307 0f05 syscall
7ffe0309 c3 ret
7ffe030a 8ac8 mov cl,al
7ffe030c ff1570464d80 call dword ptr [804d4670]
7ffe0312 8b4510 mov eax,[ebp+0x10]
7ffe0315 33c9 xor ecx,ecx
7ffe0317 663908 cmp [eax],cx
7ffe031a 894dfc mov [ebp-0x4],ecx
7ffe031d 0f840d000000 je 7ffe0330

*----> Back Trace dello stack <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0414ff7c 77f6625d 719d1a1b 000001c0 0414ffbc *SharedUserSystemCall+0xc (FPO: [0,0,0])
719d0000 00000003 00000004 0000ffff 000000b8 ntdll!ZwRemoveIoCompletion+0xc

*----> Scarico Raw Stack <----*
000000000414ff80 5d 62 f6 77 1b 1a 9d 71 - c0 01 00 00 bc ff 14 04 ]b.w...q........
000000000414ff90 ac ff 14 04 b0 ff 14 04 - 40 b7 9d 71 93 2f 00 78 ........@..q./.x
000000000414ffa0 94 09 00 00 ec ff 14 04 - d8 6e e3 02 d0 5f 24 03 .........n..._$.
000000000414ffb0 00 00 00 00 00 00 00 00 - 3b d3 e5 77 a5 4b 9d 71 ........;..w.K.q
000000000414ffc0 93 2f 00 78 94 09 00 00 - d8 6e e3 02 00 00 00 00 ./.x.....n......
000000000414ffd0 00 70 fd 7f c0 ff 14 04 - 07 00 00 00 ff ff ff ff .p..............
000000000414ffe0 09 48 e7 77 b8 3d e6 77 - 00 00 00 00 00 00 00 00 .H.w.=.w........
000000000414fff0 00 00 00 00 c4 19 9d 71 - d8 6e e3 02 00 00 00 00 .......q.n......
0000000004150000 3f 3f 3f 3c 3c 3c 3b 3b - 3b 40 40 40 43 43 43 4f ???<<<;;;@@@CCCO
0000000004150010 4f 4f 58 58 58 69 69 69 - 59 59 59 50 50 50 4a 4a OOXXXiiiYYYPPPJJ
0000000004150020 4a 55 55 55 56 56 56 63 - 63 63 55 55 55 5a 5a 5a JUUUVVVcccUUUZZZ
0000000004150030 6a 6a 6a 64 64 64 5c 5c - 5c 5f 5f 5f 73 73 73 74 jjjddd\\\___ssst
0000000004150040 74 74 67 67 67 82 82 82 - 7d 7d 7d 79 79 79 8b 8b ttggg...}}}yyy..
0000000004150050 8b 79 79 79 74 74 74 73 - 73 73 66 66 66 7f 7f 7f .yyytttsssfff...
0000000004150060 8e 8e 8e 7a 7a 7a 75 75 - 75 6c 6c 6c 76 76 76 67 ...zzzuuulllvvvg
0000000004150070 67 67 5e 5e 5e 62 62 62 - 66 66 66 5c 5c 5c 5f 5f gg^^^bbbfff\\\__
0000000004150080 5f 66 66 66 75 75 75 7a - 7a 7a 8e 8e 8e 7b 7b 7b _fffuuuzzz...{{{
0000000004150090 79 79 79 86 86 86 7c 7c - 7c 84 84 84 7d 7d 7d 83 yyy...|||...}}}.
00000000041500a0 83 83 91 91 91 76 76 76 - 72 72 72 70 70 70 6f 6f .....vvvrrrpppoo
00000000041500b0 6f 87 87 87 7f 7f 7f 7d - 7d 7d 7b 7b 7b 84 84 84 o......}}}{{{...

*----> Scarico dello stato per l'id del thread 0x2d0 <----*

eax=780015dd ebx=0336ff00 ecx=07ebfb40 edx=00000000 esi=f03aed40 edi=00000000
eip=7ffe0304 esp=019dfe28 ebp=019dff90 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000202

funzione: <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 8bd4 mov edx,esp
7ffe0307 0f05 syscall
7ffe0309 c3 ret
7ffe030a 8ac8 mov cl,al
7ffe030c ff1570464d80 call dword ptr [804d4670]
7ffe0312 8b4510 mov eax,[ebp+0x10]
7ffe0315 33c9 xor ecx,ecx
7ffe0317 663908 cmp [eax],cx
7ffe031a 894dfc mov [ebp-0x4],ecx
7ffe031d 0f840d000000 je 7ffe0330

*----> Back Trace dello stack <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
019dfe24 77f662b7 780016a4 0000021c 019dff80 *SharedUserSystemCall+0xc (FPO: [0,0,0])
019dff90 78001601 780019d6 001530f8 07ebfb3c ntdll!ZwReplyWaitReceivePortEx+0xc
032316e0 ffffffff 000007d0 000009c0 00000000 RPCRT4+0x1601
00000000 00000000 00000000 00000000 00000000 0xffffffff

*----> Scarico Raw Stack <----*
00000000019dfe28 b7 62 f6 77 a4 16 00 78 - 1c 02 00 00 80 ff 9d 01 .b.w...x........
00000000019dfe38 00 00 00 00 00 ff 36 03 - 58 ff 9d 01 58 8d 60 86 ......6.X...X.`.
00000000019dfe48 38 43 66 86 e0 51 d2 f0 - 00 00 00 00 50 eb 3a f0 8Cf..Q......P.:.
00000000019dfe58 93 aa 6c 80 00 00 00 00 - 00 00 00 00 50 eb 3a f0 ..l.........P.:.
00000000019dfe68 00 00 00 00 00 00 00 00 - 20 02 00 00 00 00 00 00 ........ .......
00000000019dfe78 a4 be 38 e2 40 54 8e e2 - b0 37 df 85 2d 14 58 80 ..8.@T...7..-.X.
00000000019dfe88 98 be 38 e2 18 03 00 00 - f8 bb 7c 86 98 be 38 e2 ..8.......|...8.
00000000019dfe98 18 fb e3 85 18 03 00 00 - 01 00 00 00 24 fe bd 01 ............$...
00000000019dfea8 01 00 00 00 00 00 00 00 - 00 00 00 00 e5 13 58 80 ..............X.
00000000019dfeb8 f0 ec 3a f0 30 56 8e e2 - f8 c9 38 86 b0 37 df 85 ..:.0V....8..7..
00000000019dfec8 01 00 00 00 e0 eb 3a f0 - 00 00 00 00 f6 a6 6c 80 ......:.......l.
00000000019dfed8 08 00 00 00 02 02 00 00 - cc 48 4f 80 f8 c9 38 86 .........HO...8.
00000000019dfee8 b8 c9 38 86 00 00 00 00 - af 4d 4f 80 f8 c9 38 86 ..8......MO...8.
00000000019dfef8 00 37 df 85 14 ec 3a f0 - ce 49 4f 80 f8 c9 38 86 .7....:..IO...8.
00000000019dff08 70 8b 4f 86 00 00 00 00 - 00 00 00 00 48 ec 3a f0 p.O.........H.:.
00000000019dff18 94 00 00 00 f0 d2 4e 80 - 5c 0d d6 85 00 ca 4e 80 ......N.\.....N.
00000000019dff28 08 ca 4e 80 2c 0d d6 85 - c0 0b d6 85 63 ed 58 80 ..N.,.......c.X.
00000000019dff38 00 ba 17 86 c0 0b d6 85 - 2f 16 00 78 60 ff 9d 01 ......../..x`...
00000000019dff48 4a 16 00 78 a0 ed 15 00 - e0 a4 f0 02 e0 16 23 03 J..x..........#.
00000000019dff58 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff ../M.....]......

*----> Scarico dello stato per l'id del thread 0x4ac <----*

eax=0000001c ebx=013563e4 ecx=01bded6c edx=00000000 esi=000003ec edi=00000000
eip=7ffe0304 esp=01bdfe7c ebp=01bdfee0 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000202

funzione: <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 8bd4 mov edx,esp
7ffe0307 0f05 syscall
7ffe0309 c3 ret
7ffe030a 8ac8 mov cl,al
7ffe030c ff1570464d80 call dword ptr [804d4670]
7ffe0312 8b4510 mov eax,[ebp+0x10]
7ffe0315 33c9 xor ecx,ecx
7ffe0317 663908 cmp [eax],cx
7ffe031a 894dfc mov [ebp-0x4],ecx
7ffe031d 0f840d000000 je 7ffe0330

*----> Back Trace dello stack <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
01bdfe78 77f6671a 77e5a62d 000003ec 00000000 *SharedUserSystemCall+0xc (FPO: [0,0,0])
01bdfee0 77e5ac21 000003ec 0000ea60 00000000 ntdll!NtWaitForSingleObject+0xc
0000ea60 00000000 00000000 00000000 00000000 kernel32!WaitForSingleObject+0xf

*----> Scarico Raw Stack <----*
0000000001bdfe7c 1a 67 f6 77 2d a6 e5 77 - ec 03 00 00 00 00 00 00 .g.w-..w........
0000000001bdfe8c a4 fe bd 01 cc 64 35 01 - 08 86 dd 01 e4 63 35 01 .....d5......c5.
0000000001bdfe9c 05 90 f6 77 a4 fe bd 01 - 00 ba 3c dc ff ff ff ff ...w......<.....
0000000001bdfeac 00 f0 fd 7f 00 a0 fd 7f - 14 00 00 00 01 00 00 00 ................
0000000001bdfebc 00 00 00 00 00 00 00 00 - 10 00 00 00 90 fe bd 01 ................
0000000001bdfecc 00 00 3f 00 a4 ff bd 01 - 09 48 e7 77 e0 3a e6 77 ..?......H.w.:.w
0000000001bdfedc 00 00 00 00 60 ea 00 00 - 21 ac e5 77 ec 03 00 00 ....`...!..w....
0000000001bdfeec 60 ea 00 00 00 00 00 00 - 5c 7e 01 30 ec 03 00 00 `.......\~.0....
0000000001bdfefc 60 ea 00 00 c8 63 35 01 - 08 86 dd 01 98 34 33 00 `....c5......43.
0000000001bdff0c b0 63 35 01 fc 41 01 30 - cc 64 35 01 e4 63 35 01 .c5..A.0.d5..c5.
0000000001bdff1c 98 34 33 00 90 63 35 01 - 98 34 33 00 43 43 01 30 .43..c5..43.CC.0
0000000001bdff2c 08 86 dd 01 58 64 35 01 - c8 63 35 01 98 34 33 00 ....Xd5..c5..43.
0000000001bdff3c b0 63 35 01 d2 da 44 00 - 58 64 35 01 98 34 33 00 .c5...D.Xd5..43.
0000000001bdff4c b4 86 dd 01 08 86 dd 01 - b4 ff bd 01 88 74 ae 06 .............t..
0000000001bdff5c c8 63 35 01 90 63 35 01 - 11 4c 01 30 bf af 1f 53 .c5..c5..L.0...S
0000000001bdff6c 40 45 3f 00 40 45 3f 00 - 12 00 00 00 c8 4c db 05 @E?.@E?......L..
0000000001bdff7c 3b 6d 01 30 08 86 dd 01 - b8 7f c0 77 08 86 dd 01 ;m.0.......w....
0000000001bdff8c 12 00 00 00 e8 09 3f 00 - 88 74 ae 06 6b b8 4f 80 ......?..t..k.O.
0000000001bdff9c 8c ff bd 01 00 00 00 00 - dc ff bd 01 b0 3e c0 77 .............>.w
0000000001bdffac c8 40 be 77 00 00 00 00 - ec ff bd 01 3b d3 e5 77 .@.w........;..w

*----> Scarico dello stato per l'id del thread 0x37c <----*

eax=0000001c ebx=013563e4 ecx=0404ed6c edx=00000000 esi=00000568 edi=00000000
eip=7ffe0304 esp=0404fe7c ebp=0404fee0 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000202

funzione: <nosymbols>
7ffe02f2 0000 add [eax],al
7ffe02f4 0000 add [eax],al
7ffe02f6 0000 add [eax],al
*SharedUserSystemCall:
7ffe02f8 0000 add [eax],al
7ffe02fa 0000 add [eax],al
7ffe02fc 0000 add [eax],al
7ffe02fe 0000 add [eax],al
7ffe0300 8bd4 mov edx,esp
7ffe0302 0f34 sysenter
7ffe0304 c3 ret
7ffe0305 8bd4 mov edx,esp
7ffe0307 0f05 syscall
7ffe0309 c3 ret
7ffe030a 8ac8 mov cl,al
7ffe030c ff1570464d80 call dword ptr [804d4670]
7ffe0312 8b4510 mov eax,[ebp+0x10]
7ffe0315 33c9 xor ecx,ecx
7ffe0317 663908 cmp [eax],cx
7ffe031a 894dfc mov [ebp-0x4],ecx
7ffe031d 0f840d000000 je 7ffe0330

*----> Back Trace dello stack <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0404fe78 77f6671a 77e5a62d 00000568 00000000 *SharedUserSystemCall+0xc (FPO: [0,0,0])
0404fee0 77e5ac21 00000568 0000ea60 00000000 ntdll!NtWaitForSingleObject+0xc
0000ea60 00000000 00000000 00000000 00000000 kernel32!WaitForSingleObject+0xf

*----> Scarico Raw Stack <----*
000000000404fe7c 1a 67 f6 77 2d a6 e5 77 - 68 05 00 00 00 00 00 00 .g.w-..wh.......
000000000404fe8c a4 fe 04 04 cc 64 35 01 - a0 76 3d 06 e4 63 35 01 .....d5..v=..c5.
000000000404fe9c 05 90 f6 77 a4 fe 04 04 - 00 ba 3c dc ff ff ff ff ...w......<.....
000000000404feac 00 f0 fd 7f 00 40 fd 7f - 14 00 00 00 01 00 00 00 .....@..........
000000000404febc 00 00 00 00 00 00 00 00 - 10 00 00 00 90 fe 04 04 ................
000000000404fecc 00 00 3f 00 a4 ff 04 04 - 09 48 e7 77 e0 3a e6 77 ..?......H.w.:.w
000000000404fedc 00 00 00 00 60 ea 00 00 - 21 ac e5 77 68 05 00 00 ....`...!..wh...
000000000404feec 60 ea 00 00 00 00 00 00 - 5c 7e 01 30 68 05 00 00 `.......\~.0h...
000000000404fefc 60 ea 00 00 c8 63 35 01 - a0 76 3d 06 98 34 33 00 `....c5..v=..43.
000000000404ff0c b0 63 35 01 fc 41 01 30 - cc 64 35 01 e4 63 35 01 .c5..A.0.d5..c5.
000000000404ff1c 98 34 33 00 90 63 35 01 - 98 34 33 00 43 43 01 30 .43..c5..43.CC.0
000000000404ff2c a0 76 3d 06 58 64 35 01 - c8 63 35 01 98 34 33 00 .v=.Xd5..c5..43.
000000000404ff3c b0 63 35 01 d2 da 44 00 - 58 64 35 01 98 34 33 00 .c5...D.Xd5..43.
000000000404ff4c 4c 77 3d 06 a0 76 3d 06 - b4 ff 04 04 18 83 7a 02 Lw=..v=.......z.
000000000404ff5c c8 63 35 01 90 63 35 01 - 11 4c 01 30 98 ad 1f 53 .c5..c5..L.0...S
000000000404ff6c 40 45 3f 00 40 45 3f 00 - 12 00 00 00 e0 7e e5 05 @E?.@E?......~..
000000000404ff7c 3b 6d 01 30 a0 76 3d 06 - b8 7f c0 77 a0 76 3d 06 ;m.0.v=....w.v=.
000000000404ff8c 12 00 00 00 e8 09 3f 00 - 18 83 7a 02 6b b8 4f 80 ......?...z.k.O.
000000000404ff9c 8c ff 04 04 00 00 00 00 - dc ff 04 04 b0 3e c0 77 .............>.w
000000000404ffac c8 40 be 77 00 00 00 00 - ec ff 04 04 3b d3 e5 77 .@.w........;..w

:eek:

kaioh
27-01-2005, 11:54
già tentato un ripristino?

Jack 85
27-01-2005, 12:21
forse qualche virus.. fai una scansione:)