Seite 1 von 1

Verfasst: 15.02.2009, 11:45
von mirko
Hallo,

das Problem kann natürlich durch externe Programme und Treiber verursacht werden, die natürlich nicht auf jedem Windows-System vorhanden sind. z.B. könnten die logitechbluetooth* Dateien schuld sein. Die gibt es natürlich nur wenn man von Logitech das entsprechende Gerät angeschlossen bzw. installiert hat.

Verfasst: 14.02.2009, 21:14
von Bunchi
Hallo
Ich habe genau das gleiche Problem!
Ebenfalls Win XP Sp3 und 0900 Warner neuste Version!
Ich kann auch bestätigen das es nicht jedes mal auftritt.
Habe mein System schon 5 mal neu installiert,es ändert sich nix!
Habe auch meinen Ram mit Memtest getestet,an dem liegt es aber nicht!
Dr.Watson meint:


Anwendungsausnahme aufgetreten:
Anwendung: ??C:WINDOWSsystem32winlogon.exe (pid=792)
Wann: 14.02.2009 @ 20:51:00.593
Ausnahmenummer: c0000005 (Zugriffsverletzung)

*----> Systeminformationen <Computername> Taskliste <0> Modulliste <0000000001000000> Statusabbild für Threadkennung 0x31c <----*

eax=75250000 ebx=00010026 ecx=00007b09 edx=76346020 esi=00000287 edi=005d27d8
eip=75263818 esp=0006f71c ebp=0006f73c iopl=0 nv up ei pl nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000206

Funktion: <nosymbols>
No prior disassembly possible
75263818 ?? ???
7526381a ?? ???
7526381c ?? ???
7526381e ?? ???
75263820 ?? ???
75263822 ?? ???
75263824 ?? ???
75263826 ?? ???
75263828 ?? ???
FEHLER ->75263818 ?? ???
Error 0x00000001
7526381a ?? ???
7526381c ?? ???
7526381e ?? ???
75263820 ?? ???
75263822 ?? ???
75263824 ?? ???
75263826 ?? ???
75263828 ?? ???
7526382a ?? ???
7526382c ?? ???

*----> Stack Back Trace <ERROR> Raw Stack Dump <000000000006f71c> Statusabbild für Threadkennung 0x338 <eax> Stack Back Trace <ERROR> Raw Stack Dump <----*
0000000000b7fe18 8c da 91 7c e3 65 e5 77 - 2c 01 00 00 74 ff b7 00 ...|.e.w,...t...
0000000000b7fe28 00 00 00 00 18 2f 08 00 - 00 00 00 00 00 00 00 00 ...../..........
0000000000b7fe38 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000b7fe48 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000b7fe58 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000b7fe68 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000b7fe78 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000b7fe88 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000b7fe98 00 00 00 00 00 00 00 00 - 43 7d 6e 80 28 7c 55 ba ........C}n.(|U.
0000000000b7fea8 27 74 6e 80 00 0d db ba - 00 00 00 00 00 00 00 00 \'tn.............
0000000000b7feb8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000b7fec8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000b7fed8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000b7fee8 00 00 00 00 1f 00 00 00 - ff ff ff ff 40 f5 df ff ............@...
0000000000b7fef8 00 00 00 00 10 74 6e 80 - 24 23 7f 89 28 7c 55 ba .....tn.$#..(|U.
0000000000b7ff08 00 00 00 00 27 74 6e 80 - 08 00 00 00 46 02 00 00 ....\'tn.....F...
0000000000b7ff18 68 38 50 80 f8 21 7f 89 - 88 21 7f 89 78 b0 4f 80 h8P..!...!..x.O.
0000000000b7ff28 f4 22 7f 89 80 ff b7 00 - ae df e5 77 48 ff b7 00 .\".........wH...
0000000000b7ff38 be df e5 77 e0 10 91 7c - 30 2d 08 00 58 2d 08 00 ...w...|0-..X-..
0000000000b7ff48 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff ../M.....]......

*----> Statusabbild für Threadkennung 0x33c <----*

eax=000000c0 ebx=00000000 ecx=4391d950 edx=00000045 esi=00000000 edi=0006f7f0
eip=7c91e4f4 esp=00bbff9c ebp=00bbffb4 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

Funktion: ntdll!KiFastSystemCallRet
7c91e4da e829000000 call ntdll!RtlRaiseException (7c91e508)
7c91e4df 8b0424 mov eax,[esp]
7c91e4e2 8be5 mov esp,ebp
7c91e4e4 5d pop ebp
7c91e4e5 c3 ret
7c91e4e6 8da42400000000 lea esp,[esp]
7c91e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c91e4f0 8bd4 mov edx,esp
7c91e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c91e4f4 c3 ret
7c91e4f5 8da42400000000 lea esp,[esp]
7c91e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c91e500 8d542408 lea edx,[esp+0x8]
7c91e504 cd2e int 2e
7c91e506 c3 ret
7c91e507 90 nop
ntdll!RtlRaiseException:
7c91e508 55 push ebp
7c91e509 8bec mov ebp,esp

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
00bbffb4 7c80b713 00000000 0006f7f0 00000000 ntdll!KiFastSystemCallRet
00bbffec 00000000 7c937ebb 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
0000000000bbff9c fc d1 91 7c 02 7f 93 7c - 01 00 00 00 ac ff bb 00 ...|...|........
0000000000bbffac 00 00 00 00 00 00 00 80 - ec ff bb 00 13 b7 80 7c ...............|
0000000000bbffbc 00 00 00 00 f0 f7 06 00 - 00 00 00 00 00 00 00 00 ................
0000000000bbffcc 00 a0 fd 7f 00 96 e3 89 - c0 ff bb 00 10 16 a1 89 ................
0000000000bbffdc ff ff ff ff c0 9a 83 7c - 20 b7 80 7c 00 00 00 00 .......| ..|....
0000000000bbffec 00 00 00 00 00 00 00 00 - bb 7e 93 7c 00 00 00 00 .........~.|....
0000000000bbfffc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000bc000c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000bc001c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000bc002c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000bc003c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000bc004c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000bc005c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000bc006c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000bc007c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000bc008c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000bc009c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000bc00ac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000bc00bc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000bc00cc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

*----> Statusabbild für Threadkennung 0x344 <----*

eax=76c28e2c ebx=00007530 ecx=00000000 edx=00000012 esi=00083b10 edi=00000000
eip=7c91e4f4 esp=00c3feac ebp=00c3fed8 iopl=0 nv up ei ng nz ac po cy
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000297

Funktion: ntdll!KiFastSystemCallRet
7c91e4da e829000000 call ntdll!RtlRaiseException (7c91e508)
7c91e4df 8b0424 mov eax,[esp]
7c91e4e2 8be5 mov esp,ebp
7c91e4e4 5d pop ebp
7c91e4e5 c3 ret
7c91e4e6 8da42400000000 lea esp,[esp]
7c91e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c91e4f0 8bd4 mov edx,esp
7c91e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c91e4f4 c3 ret
7c91e4f5 8da42400000000 lea esp,[esp]
7c91e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c91e500 8d542408 lea edx,[esp+0x8]
7c91e504 cd2e int 2e
7c91e506 c3 ret
7c91e507 90 nop
ntdll!RtlRaiseException:
7c91e508 55 push ebp
7c91e509 8bec mov ebp,esp

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
00c3fed8 77e5715c 0000017c 00c3ff10 00c3ff00 ntdll!KiFastSystemCallRet
00c3ff14 77e572a0 00007530 00c3ff6c 00c3ff70 RPCRT4!I_RpcBCacheFree+0xac9
00c3ff80 77e57328 00c3ffa8 77e56ad1 00083b10 RPCRT4!I_RpcBCacheFree+0xc0d
00c3ff88 77e56ad1 00083b10 0006f5a0 00000008 RPCRT4!I_RpcBCacheFree+0xc95
00c3ffa8 77e56c97 00072fc8 00c3ffec 7c80b713 RPCRT4!I_RpcBCacheFree+0x43e
00c3ffb4 7c80b713 00084508 0006f5a0 00000008 RPCRT4!I_RpcBCacheFree+0x604
00c3ffec 00000000 77e56c7d 00084508 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
0000000000c3feac 2c da 91 7c d6 a7 80 7c - 7c 01 00 00 00 ff c3 00 ,..|...||.......
0000000000c3febc f0 fe c3 00 d0 fe c3 00 - c8 fe c3 00 00 5d 1e ee .............]..
0000000000c3fecc ff ff ff ff 00 00 00 00 - 93 99 00 00 14 ff c3 00 ................
0000000000c3fedc 5c 71 e5 77 7c 01 00 00 - 10 ff c3 00 00 ff c3 00 q.w|...........
0000000000c3feec 08 ff c3 00 30 75 00 00 - 0a 98 80 7c 10 3b 08 00 ....0u.....|.;..
0000000000c3fefc 18 3d 08 00 38 6a e5 77 - 7c 01 00 00 99 80 e6 77 .=..8j.w|......w
0000000000c3ff0c 3c 3d 08 00 3c 3d 08 00 - 80 ff c3 00 a0 72 e5 77 <=..<=.......r.w
0000000000c3ff1c 30 75 00 00 6c ff c3 00 - 70 ff c3 00 78 ff c3 00 0u..l...p...x...
0000000000c3ff2c 64 ff c3 00 68 ff c3 00 - 74 ff c3 00 e0 10 91 7c d...h...t......|
0000000000c3ff3c e0 44 08 00 08 45 08 00 - 08 45 08 00 7c 01 00 00 .D...E...E..|...
0000000000c3ff4c 00 00 00 00 01 00 00 00 - 06 00 00 00 bb 05 00 00 ................
0000000000c3ff5c 00 00 00 00 30 75 00 00 - 93 99 00 00 00 00 00 00 ....0u..........
0000000000c3ff6c 00 00 00 00 00 00 00 00 - 00 00 00 00 7c 01 00 00 ............|...
0000000000c3ff7c 00 00 00 00 88 ff c3 00 - 28 73 e5 77 a8 ff c3 00 ........(s.w....
0000000000c3ff8c d1 6a e5 77 10 3b 08 00 - a0 f5 06 00 08 00 00 00 .j.w.;..........
0000000000c3ff9c 08 45 08 00 08 45 08 00 - 00 53 07 00 b4 ff c3 00 .E...E...S......
0000000000c3ffac 97 6c e5 77 c8 2f 07 00 - ec ff c3 00 13 b7 80 7c .l.w./.........|
0000000000c3ffbc 08 45 08 00 a0 f5 06 00 - 08 00 00 00 08 45 08 00 .E...........E..
0000000000c3ffcc 00 80 fd 7f 00 96 e3 89 - c0 ff c3 00 60 f7 8a 89 ............`...
0000000000c3ffdc ff ff ff ff c0 9a 83 7c - 20 b7 80 7c 00 00 00 00 .......| ..|....

*----> Statusabbild für Threadkennung 0x350 <----*

eax=000000c0 ebx=00000000 ecx=01000000 edx=00000000 esi=00000000 edi=00000001
eip=7c91e4f4 esp=00c7fcec ebp=00c7ffb4 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

Funktion: ntdll!KiFastSystemCallRet
7c91e4da e829000000 call ntdll!RtlRaiseException (7c91e508)
7c91e4df 8b0424 mov eax,[esp]
7c91e4e2 8be5 mov esp,ebp
7c91e4e4 5d pop ebp
7c91e4e5 c3 ret
7c91e4e6 8da42400000000 lea esp,[esp]
7c91e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c91e4f0 8bd4 mov edx,esp
7c91e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c91e4f4 c3 ret
7c91e4f5 8da42400000000 lea esp,[esp]
7c91e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c91e500 8d542408 lea edx,[esp+0x8]
7c91e504 cd2e int 2e
7c91e506 c3 ret
7c91e507 90 nop
ntdll!RtlRaiseException:
7c91e508 55 push ebp
7c91e509 8bec mov ebp,esp

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
00c7ffb4 7c80b713 00000000 7c91e900 7c920208 ntdll!KiFastSystemCallRet
00c7ffec 00000000 7c939b6f 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
0000000000c7fcec 2c df 91 7c 96 9c 93 7c - 08 00 00 00 30 fd c7 00 ,..|...|....0...
0000000000c7fcfc 01 00 00 00 01 00 00 00 - 00 00 00 00 00 e9 91 7c ...............|
0000000000c7fd0c 08 02 92 7c 00 00 00 00 - 80 c9 98 7c 80 c9 98 7c ...|.......|...|
0000000000c7fd1c a4 01 00 00 50 03 00 00 - 08 00 00 00 08 00 00 00 ....P...........
0000000000c7fd2c 07 00 00 00 a8 01 00 00 - ac 01 00 00 b8 01 00 00 ................
0000000000c7fd3c dc 04 00 00 d4 04 00 00 - ec 04 00 00 1c 05 00 00 ................
0000000000c7fd4c 50 07 00 00 50 07 00 00 - 50 07 00 00 c0 07 00 00 P...P...P.......
0000000000c7fd5c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000c7fd6c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000c7fd7c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000c7fd8c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000c7fd9c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000c7fdac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000c7fdbc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000c7fdcc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000c7fddc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000c7fdec 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000c7fdfc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000c7fe0c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000c7fe1c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

*----> Statusabbild für Threadkennung 0x39c <----*

eax=00e7c000 ebx=00000002 ecx=00affd08 edx=00002000 esi=76c229b8 edi=00000000
eip=7c91e4f4 esp=00afff64 ebp=00afffb4 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

Funktion: ntdll!KiFastSystemCallRet
7c91e4da e829000000 call ntdll!RtlRaiseException (7c91e508)
7c91e4df 8b0424 mov eax,[esp]
7c91e4e2 8be5 mov esp,ebp
7c91e4e4 5d pop ebp
7c91e4e5 c3 ret
7c91e4e6 8da42400000000 lea esp,[esp]
7c91e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c91e4f0 8bd4 mov edx,esp
7c91e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c91e4f4 c3 ret
7c91e4f5 8da42400000000 lea esp,[esp]
7c91e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c91e500 8d542408 lea edx,[esp+0x8]
7c91e504 cd2e int 2e
7c91e506 c3 ret
7c91e507 90 nop
ntdll!RtlRaiseException:
7c91e508 55 push ebp
7c91e509 8bec mov ebp,esp

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
00afffb4 7c80b713 00000000 76a0bd80 00e23400 ntdll!KiFastSystemCallRet
00afffec 00000000 76c2c80b 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
0000000000afff64 2c df 91 7c d9 cb c2 76 - 02 00 00 00 90 09 12 00 ,..|...v........
0000000000afff74 00 00 00 00 01 00 00 00 - 00 00 00 00 80 bd a0 76 ...............v
0000000000afff84 00 34 e2 00 00 00 00 00 - f4 60 08 00 70 1b 12 00 .4.......`..p...
0000000000afff94 68 1b 12 00 90 09 12 00 - 50 1b 12 00 00 00 00 00 h.......P.......
0000000000afffa4 88 3e e2 00 f0 60 08 00 - 48 36 e2 00 02 00 00 00 .>...`..H6......
0000000000afffb4 ec ff af 00 13 b7 80 7c - 00 00 00 00 80 bd a0 76 .......|.......v
0000000000afffc4 00 34 e2 00 00 00 00 00 - 00 e0 fd 7f 00 76 e3 89 .4...........v..
0000000000afffd4 c0 ff af 00 68 43 76 89 - ff ff ff ff c0 9a 83 7c ....hCv........|
0000000000afffe4 20 b7 80 7c 00 00 00 00 - 00 00 00 00 00 00 00 00 ..|............
0000000000affff4 0b c8 c2 76 00 00 00 00 - 00 00 00 00 00 00 00 00 ...v............
0000000000b00004 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000b00014 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000b00024 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000b00034 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000b00044 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000b00054 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000b00064 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000b00074 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000b00084 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000b00094 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

*----> Statusabbild für Threadkennung 0x3a0 <----*

eax=0012c900 ebx=00121b50 ecx=01f82808 edx=01df37cf esi=76c229b8 edi=00000000
eip=7c91e4f4 esp=00f4ff4c ebp=00f4ffb4 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202

Funktion: ntdll!KiFastSystemCallRet
7c91e4da e829000000 call ntdll!RtlRaiseException (7c91e508)
7c91e4df 8b0424 mov eax,[esp]
7c91e4e2 8be5 mov esp,ebp
7c91e4e4 5d pop ebp
7c91e4e5 c3 ret
7c91e4e6 8da42400000000 lea esp,[esp]
7c91e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c91e4f0 8bd4 mov edx,esp
7c91e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c91e4f4 c3 ret
7c91e4f5 8da42400000000 lea esp,[esp]
7c91e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c91e500 8d542408 lea edx,[esp+0x8]
7c91e504 cd2e int 2e
7c91e506 c3 ret
7c91e507 90 nop
ntdll!RtlRaiseException:
7c91e508 55 push ebp
7c91e509 8bec mov ebp,esp

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
00f4ffb4 7c80b713 00e7c8c8 7c91e900 0000030a ntdll!KiFastSystemCallRet
00f4ffec 00000000 76c2c54e 00121b50 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
0000000000f4ff4c 2c df 91 7c ca c7 c2 76 - 40 00 00 00 38 65 08 00 ,..|...v@...8e..
0000000000f4ff5c 01 00 00 00 01 00 00 00 - 00 00 00 00 00 e9 91 7c ...............|
0000000000f4ff6c 0a 03 00 00 50 1b 12 00 - 00 00 00 00 01 00 00 00 ....P...........
0000000000f4ff7c 02 00 00 00 04 00 00 00 - 08 00 00 00 10 00 00 00 ................
0000000000f4ff8c 00 00 00 00 a0 4d 7d 89 - 5a 2f 50 80 00 00 00 00 .....M}.Z/P.....
0000000000f4ff9c 00 00 00 00 00 00 00 00 - 00 00 00 00 48 36 e2 00 ............H6..
0000000000f4ffac f8 37 e2 00 0f 00 00 00 - ec ff f4 00 13 b7 80 7c .7.............|
0000000000f4ffbc c8 c8 e7 00 00 e9 91 7c - 0a 03 00 00 50 1b 12 00 .......|....P...
0000000000f4ffcc 00 40 fd 7f 00 96 e3 89 - c0 ff f4 00 68 43 76 89 .@..........hCv.
0000000000f4ffdc ff ff ff ff c0 9a 83 7c - 20 b7 80 7c 00 00 00 00 .......| ..|....
0000000000f4ffec 00 00 00 00 00 00 00 00 - 4e c5 c2 76 50 1b 12 00 ........N..vP...
0000000000f4fffc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000f5000c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000f5001c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000f5002c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000f5003c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000f5004c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000f5005c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000f5006c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000f5007c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

*----> Statusabbild für Threadkennung 0x3a4 <----*

eax=00000083 ebx=00121b5c ecx=00000010 edx=001cf99b esi=76c229b8 edi=00e7d0f0
eip=7c91e4f4 esp=00f8ff4c ebp=00f8ffb4 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

Funktion: ntdll!KiFastSystemCallRet
7c91e4da e829000000 call ntdll!RtlRaiseException (7c91e508)
7c91e4df 8b0424 mov eax,[esp]
7c91e4e2 8be5 mov esp,ebp
7c91e4e4 5d pop ebp
7c91e4e5 c3 ret
7c91e4e6 8da42400000000 lea esp,[esp]
7c91e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c91e4f0 8bd4 mov edx,esp
7c91e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c91e4f4 c3 ret
7c91e4f5 8da42400000000 lea esp,[esp]
7c91e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c91e500 8d542408 lea edx,[esp+0x8]
7c91e504 cd2e int 2e
7c91e506 c3 ret
7c91e507 90 nop
ntdll!RtlRaiseException:
7c91e508 55 push ebp
7c91e509 8bec mov ebp,esp

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
00f8ffb4 7c80b713 00e7cce0 7c91e900 0000030a ntdll!KiFastSystemCallRet
00f8ffec 00000000 76c2c54e 00121b5c 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
0000000000f8ff4c 2c df 91 7c ca c7 c2 76 - 1a 00 00 00 90 3e e2 00 ,..|...v.....>..
0000000000f8ff5c 01 00 00 00 01 00 00 00 - 00 00 00 00 00 e9 91 7c ...............|
0000000000f8ff6c 0a 03 00 00 5c 1b 12 00 - 00 00 00 00 01 00 00 00 ...............
0000000000f8ff7c 02 00 00 00 04 00 00 00 - 08 00 00 00 10 00 00 00 ................
0000000000f8ff8c 00 00 00 00 a0 4d 7d 89 - 5a 2f 50 80 00 00 00 00 .....M}.Z/P.....
0000000000f8ff9c 00 00 00 00 00 00 00 00 - 6a 2f 50 80 30 3c e2 00 ........j/P.0<..
0000000000f8ffac f2 7e 6e 80 fc d9 91 7c - ec ff f8 00 13 b7 80 7c .~n....|.......|
0000000000f8ffbc e0 cc e7 00 00 e9 91 7c - 0a 03 00 00 5c 1b 12 00 .......|.......
0000000000f8ffcc 00 f0 fa 7f 00 96 e3 89 - c0 ff f8 00 a0 43 76 89 .............Cv.
0000000000f8ffdc ff ff ff ff c0 9a 83 7c - 20 b7 80 7c 00 00 00 00 .......| ..|....
0000000000f8ffec 00 00 00 00 00 00 00 00 - 4e c5 c2 76 5c 1b 12 00 ........N..v...
0000000000f8fffc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000f9000c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000f9001c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000f9002c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000f9003c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000f9004c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000f9005c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000f9006c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000f9007c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

*----> Statusabbild für Threadkennung 0x438 <----*

eax=00000000 ebx=00000000 ecx=00000020 edx=00fcfe00 esi=00082748 edi=00082784
eip=7c91e4f4 esp=00fcfe18 ebp=00fcff80 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

Funktion: ntdll!KiFastSystemCallRet
7c91e4da e829000000 call ntdll!RtlRaiseException (7c91e508)
7c91e4df 8b0424 mov eax,[esp]
7c91e4e2 8be5 mov esp,ebp
7c91e4e4 5d pop ebp
7c91e4e5 c3 ret
7c91e4e6 8da42400000000 lea esp,[esp]
7c91e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c91e4f0 8bd4 mov edx,esp
7c91e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c91e4f4 c3 ret
7c91e4f5 8da42400000000 lea esp,[esp]
7c91e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c91e500 8d542408 lea edx,[esp+0x8]
7c91e504 cd2e int 2e
7c91e506 c3 ret
7c91e507 90 nop
ntdll!RtlRaiseException:
7c91e508 55 push ebp
7c91e509 8bec mov ebp,esp

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
00fcff80 77e56caf 00fcffa8 77e56ad1 00082748 ntdll!KiFastSystemCallRet
00fcff88 77e56ad1 00082748 00000000 00000000 RPCRT4!I_RpcBCacheFree+0x61c
00fcffa8 77e56c97 00072fc8 00fcffec 7c80b713 RPCRT4!I_RpcBCacheFree+0x43e
00fcffb4 7c80b713 000869c8 00000000 00000000 RPCRT4!I_RpcBCacheFree+0x604
00fcffec 00000000 77e56c7d 000869c8 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
0000000000fcfe18 8c da 91 7c e3 65 e5 77 - 50 01 00 00 74 ff fc 00 ...|.e.wP...t...
0000000000fcfe28 00 00 00 00 50 02 e8 00 - 00 00 00 00 ff ff ff 03 ....P...........
0000000000fcfe38 28 00 40 00 00 00 00 00 - 50 0f 00 00 10 09 00 00 (.@.....P.......
0000000000fcfe48 bf 82 03 00 00 00 00 00 - 02 00 00 00 01 00 4f 80 ..............O.
0000000000fcfe58 94 eb f0 ad 80 fd 3f c0 - 00 f0 fa 7f 00 00 00 00 ......?.........
0000000000fcfe68 78 fd 3f 02 70 eb f0 ad - 00 00 00 00 00 00 00 00 x.?.p...........
0000000000fcfe78 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000000fcfe88 00 00 00 00 f8 1f 60 c0 - 30 ec f0 ad 0a 40 52 80 ......`.0....@R.
0000000000fcfe98 94 eb f0 ad 00 00 00 00 - 43 7d 6e 80 28 ec f0 ad ........C}n.(...
0000000000fcfea8 27 74 6e 80 00 0d db ba - 00 00 00 00 00 00 00 00 \'tn.............
0000000000fcfeb8 78 fd 3f c0 88 51 83 89 - 00 00 00 00 00 00 00 00 x.?..Q..........
0000000000fcfec8 00 00 04 00 5f 09 00 00 - 7c 95 7a 89 ff ff 95 00 ...._...|.z.....
0000000000fcfed8 b0 94 7a 89 00 00 00 00 - 00 00 00 00 00 00 00 00 ..z.............
0000000000fcfee8 00 00 00 00 1f 00 00 00 - ff ff ff ff 40 f5 df ff ............@...
0000000000fcfef8 00 00 00 00 10 74 6e 80 - 9c 5d 81 89 28 ec f0 ad .....tn..]..(...
0000000000fcff08 00 00 00 00 27 74 6e 80 - 08 00 00 00 46 02 00 00 ....\'tn.....F...
0000000000fcff18 68 38 50 80 70 5c 81 89 - 00 5c 81 89 78 b0 4f 80 h8P.p.....x.O.
0000000000fcff28 6c 5d 81 89 80 ff fc 00 - ae df e5 77 48 ff fc 00 l].........wH...
0000000000fcff38 be df e5 77 e0 10 91 7c - c0 00 e8 00 c8 69 08 00 ...w...|.....i..
0000000000fcff48 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff ../M.....]......

*----> Statusabbild für Threadkennung 0x60c <----*

eax=000080b9 ebx=011dfe78 ecx=7c8095a4 edx=00000080 esi=00000000 edi=7ffdb000
eip=7c91e4f4 esp=011dfe50 ebp=011dfeec iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

Funktion: ntdll!KiFastSystemCallRet
7c91e4da e829000000 call ntdll!RtlRaiseException (7c91e508)
7c91e4df 8b0424 mov eax,[esp]
7c91e4e2 8be5 mov esp,ebp
7c91e4e4 5d pop ebp
7c91e4e5 c3 ret
7c91e4e6 8da42400000000 lea esp,[esp]
7c91e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c91e4f0 8bd4 mov edx,esp
7c91e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c91e4f4 c3 ret
7c91e4f5 8da42400000000 lea esp,[esp]
7c91e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c91e500 8d542408 lea edx,[esp+0x8]
7c91e504 cd2e int 2e
7c91e506 c3 ret
7c91e507 90 nop
ntdll!RtlRaiseException:
7c91e508 55 push ebp
7c91e509 8bec mov ebp,esp

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:WINDOWSsystem32cscdll.dll -
ChildEBP RetAddr Args to Child
011dfeec 7c80a105 00000004 011dff2c 00000000 ntdll!KiFastSystemCallRet
011dff08 765a1fb9 00000004 011dff2c 00000000 kernel32!WaitForMultipleObjects+0x18
011dff3c 765a3267 0009bfe9 00097b6d 00000000 cscdll!WinlogonStartShellEvent+0x13f
011dff54 765a323b 00000000 01039f18 011dff74 cscdll!MprServiceProc+0x1b
011dffb4 7c80b713 000967f0 0006fb74 00000023 cscdll!WinlogonStartupEvent+0x40
011dffec 00000000 01039e58 000967f0 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
00000000011dfe50 2c df 91 7c 74 95 80 7c - 04 00 00 00 78 fe 1d 01 ,..|t..|....x...
00000000011dfe60 01 00 00 00 00 00 00 00 - 00 00 00 00 29 98 00 00 ............)...
00000000011dfe70 01 00 00 00 2e 93 80 7c - b8 05 00 00 bc 05 00 00 .......|........
00000000011dfe80 c0 05 00 00 c8 05 00 00 - 40 0b 81 7c ff ff ff ff ........@..|....
00000000011dfe90 98 16 80 7c dc cf 91 7c - 14 00 00 00 01 00 00 00 ...|...|........
00000000011dfea0 00 00 00 00 00 00 00 00 - 10 00 00 00 c4 fe 1d 01 ................
00000000011dfeb0 44 22 5a 76 34 01 00 00 - 00 b0 fd 7f 00 b0 fa 7f D\"Zv4...........
00000000011dfec0 2e 93 80 7c 00 00 00 00 - 78 fe 1d 01 01 00 00 00 ...|....x.......
00000000011dfed0 04 00 00 00 6c fe 1d 01 - 00 01 00 00 a4 ff 1d 01 ....l...........
00000000011dfee0 c0 9a 83 7c 68 96 80 7c - 00 00 00 00 08 ff 1d 01 ...|h..|........
00000000011dfef0 05 a1 80 7c 04 00 00 00 - 2c ff 1d 01 00 00 00 00 ...|....,.......
00000000011dff00 ff ff ff ff 00 00 00 00 - 3c ff 1d 01 b9 1f 5a 76 ........<.....Zv
00000000011dff10 04 00 00 00 2c ff 1d 01 - 00 00 00 00 ff ff ff ff ....,...........
00000000011dff20 f0 67 09 00 00 00 00 00 - 80 c9 07 00 b8 05 00 00 .g..............
00000000011dff30 bc 05 00 00 c0 05 00 00 - c8 05 00 00 54 ff 1d 01 ............T...
00000000011dff40 67 32 5a 76 e9 bf 09 00 - 6d 7b 09 00 00 00 00 00 g2Zv....m{......
00000000011dff50 05 00 00 00 b4 ff 1d 01 - 3b 32 5a 76 00 00 00 00 ........;2Zv....
00000000011dff60 18 9f 03 01 74 ff 1d 01 - 74 fb 06 00 23 00 00 00 ....t...t...#...
00000000011dff70 f0 67 09 00 20 00 00 00 - 00 00 00 00 00 00 00 00 .g.. ...........
00000000011dff80 00 00 00 00 58 ca 07 00 - 00 00 00 00 b8 00 00 00 ....X...........

*----> Statusabbild für Threadkennung 0x618 <----*

eax=765a2d3c ebx=013dfee8 ecx=00173e50 edx=00000000 esi=00000000 edi=7ffdb000
eip=7c91e4f4 esp=013dfec0 ebp=013dff5c iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

Funktion: ntdll!KiFastSystemCallRet
7c91e4da e829000000 call ntdll!RtlRaiseException (7c91e508)
7c91e4df 8b0424 mov eax,[esp]
7c91e4e2 8be5 mov esp,ebp
7c91e4e4 5d pop ebp
7c91e4e5 c3 ret
7c91e4e6 8da42400000000 lea esp,[esp]
7c91e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c91e4f0 8bd4 mov edx,esp
7c91e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c91e4f4 c3 ret
7c91e4f5 8da42400000000 lea esp,[esp]
7c91e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c91e500 8d542408 lea edx,[esp+0x8]
7c91e504 cd2e int 2e
7c91e506 c3 ret
7c91e507 90 nop
ntdll!RtlRaiseException:
7c91e508 55 push ebp
7c91e509 8bec mov ebp,esp

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
013dff5c 7c80a105 00000002 013dff9c 00000000 ntdll!KiFastSystemCallRet
013dff78 765a2da8 00000002 013dff9c 00000000 kernel32!WaitForMultipleObjects+0x18
013dffb4 7c80b713 00000000 10000000 00000002 cscdll!WinlogonLogonEvent+0x972
013dffec 00000000 765a2d3c 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
00000000013dfec0 2c df 91 7c 74 95 80 7c - 02 00 00 00 e8 fe 3d 01 ,..|t..|......=.
00000000013dfed0 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 10 ................
00000000013dfee0 00 00 00 00 4c 32 5b 76 - cc 05 00 00 b0 05 00 00 ....L2[v........
00000000013dfef0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000013dff00 00 00 00 00 00 00 00 00 - 14 00 00 00 01 00 00 00 ................
00000000013dff10 00 00 00 00 00 00 00 00 - 10 00 00 00 00 00 00 00 ................
00000000013dff20 00 00 00 00 00 00 00 00 - 00 b0 fd 7f 00 80 fa 7f ................
00000000013dff30 00 00 00 00 00 00 00 00 - e8 fe 3d 01 00 00 00 00 ..........=.....
00000000013dff40 02 00 00 00 dc fe 3d 01 - 00 00 00 00 dc ff 3d 01 ......=.......=.
00000000013dff50 c0 9a 83 7c 68 96 80 7c - 00 00 00 00 78 ff 3d 01 ...|h..|....x.=.
00000000013dff60 05 a1 80 7c 02 00 00 00 - 9c ff 3d 01 00 00 00 00 ...|......=.....
00000000013dff70 ff ff ff ff 00 00 00 00 - b4 ff 3d 01 a8 2d 5a 76 ..........=..-Zv
00000000013dff80 02 00 00 00 9c ff 3d 01 - 00 00 00 00 ff ff ff ff ......=.........
00000000013dff90 00 00 00 10 02 00 00 00 - 00 00 00 00 cc 05 00 00 ................
00000000013dffa0 b0 05 00 00 6d 7b 09 00 - 00 00 00 00 ff ff 00 00 ....m{..........
00000000013dffb0 00 00 00 00 ec ff 3d 01 - 13 b7 80 7c 00 00 00 00 ......=....|....
00000000013dffc0 00 00 00 10 02 00 00 00 - 00 00 00 00 00 80 fa 7f ................
00000000013dffd0 00 96 e3 89 c0 ff 3d 01 - c0 06 84 89 ff ff ff ff ......=.........
00000000013dffe0 c0 9a 83 7c 20 b7 80 7c - 00 00 00 00 00 00 00 00 ...| ..|........
00000000013dfff0 00 00 00 00 3c 2d 5a 76 - 00 00 00 00 00 00 00 00 ....<-Zv........

*----> Statusabbild für Threadkennung 0x620 <----*

eax=01263000 ebx=0121f8dc ecx=0121ef4c edx=00001000 esi=00000000 edi=7ffdb000
eip=7c91e4f4 esp=0121f8b4 ebp=0121f950 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

Funktion: ntdll!KiFastSystemCallRet
7c91e4da e829000000 call ntdll!RtlRaiseException (7c91e508)
7c91e4df 8b0424 mov eax,[esp]
7c91e4e2 8be5 mov esp,ebp
7c91e4e4 5d pop ebp
7c91e4e5 c3 ret
7c91e4e6 8da42400000000 lea esp,[esp]
7c91e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c91e4f0 8bd4 mov edx,esp
7c91e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c91e4f4 c3 ret
7c91e4f5 8da42400000000 lea esp,[esp]
7c91e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c91e500 8d542408 lea edx,[esp+0x8]
7c91e504 cd2e int 2e
7c91e506 c3 ret
7c91e507 90 nop
ntdll!RtlRaiseException:
7c91e508 55 push ebp
7c91e509 8bec mov ebp,esp

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for c:programmegemeinsame dateienlogitechbluetoothLBTWlgn.dll -
ChildEBP RetAddr Args to Child
0121f950 7c80a105 00000002 0121f994 00000000 ntdll!KiFastSystemCallRet
0121f96c 10001213 00000002 0121f994 00000000 kernel32!WaitForMultipleObjects+0x18
00000604 00000000 00000000 00000000 00000000 LBTWlgn+0x1213

*----> Raw Stack Dump <----*
000000000121f8b4 2c df 91 7c 74 95 80 7c - 02 00 00 00 dc f8 21 01 ,..|t..|......!.
000000000121f8c4 01 00 00 00 00 00 00 00 - 00 00 00 00 10 2f 22 01 ............./\".
000000000121f8d4 10 06 00 00 00 00 22 01 - 04 06 00 00 10 06 00 00 ......\".........
000000000121f8e4 00 26 80 7c 10 2f 22 01 - c0 2e 22 01 00 00 22 01 .&.|./\"...\"...\".
000000000121f8f4 14 00 00 00 01 00 00 00 - 14 00 00 00 01 00 00 00 ................
000000000121f904 00 00 00 00 00 00 00 00 - 10 00 00 00 fc f4 21 01 ..............!.
000000000121f914 00 a0 fa 7f dc ff 21 01 - 00 b0 fd 7f 00 a0 fa 7f ......!.........
000000000121f924 ff ff ff ff 00 00 00 00 - dc f8 21 01 ff ff ff ff ..........!.....
000000000121f934 02 00 00 00 d0 f8 21 01 - 50 30 22 01 dc ff 21 01 ......!.P0\"...!.
000000000121f944 c0 9a 83 7c 68 96 80 7c - 00 00 00 00 6c f9 21 01 ...|h..|....l.!.
000000000121f954 05 a1 80 7c 02 00 00 00 - 94 f9 21 01 00 00 00 00 ...|......!.....
000000000121f964 ff ff ff ff 00 00 00 00 - 04 06 00 00 13 12 00 10 ................
000000000121f974 02 00 00 00 94 f9 21 01 - 00 00 00 00 ff ff ff ff ......!.........
000000000121f984 ec ff 21 01 38 fb 29 01 - 00 00 07 00 00 00 00 00 ..!.8.).........
000000000121f994 04 06 00 00 10 06 00 00 - 63 3a 5c 70 72 6f 67 72 ........c:progr
000000000121f9a4 61 6d 6d 65 5c 67 65 6d - 65 69 6e 73 61 6d 65 20 ammegemeinsame
000000000121f9b4 64 61 74 65 69 65 6e 5c - 6c 6f 67 69 74 65 63 68 dateienlogitech
000000000121f9c4 5c 62 6c 75 65 74 6f 6f - 74 68 5c 4c 42 54 53 65 bluetoothLBTSe
000000000121f9d4 72 76 2e 64 6c 6c 00 74 - 6c 44 65 63 6f 64 65 50 rv.dll.tlDecodeP
000000000121f9e4 6f 69 6e 74 65 72 00 74 - 65 72 00 00 d8 d7 00 00 ointer.ter......

*----> Statusabbild für Threadkennung 0x634 <----*

eax=00000689 ebx=00000610 ecx=00000000 edx=000000d1 esi=0145ff98 edi=0121f648
eip=7c91e4f4 esp=0145ff58 ebp=0145ff7c iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

Funktion: ntdll!KiFastSystemCallRet
7c91e4da e829000000 call ntdll!RtlRaiseException (7c91e508)
7c91e4df 8b0424 mov eax,[esp]
7c91e4e2 8be5 mov esp,ebp
7c91e4e4 5d pop ebp
7c91e4e5 c3 ret
7c91e4e6 8da42400000000 lea esp,[esp]
7c91e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c91e4f0 8bd4 mov edx,esp
7c91e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c91e4f4 c3 ret
7c91e4f5 8da42400000000 lea esp,[esp]
7c91e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c91e500 8d542408 lea edx,[esp+0x8]
7c91e504 cd2e int 2e
7c91e506 c3 ret
7c91e507 90 nop
ntdll!RtlRaiseException:
7c91e508 55 push ebp
7c91e509 8bec mov ebp,esp

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for c:programmegemeinsame dateienlogitechbluetoothLBTServ.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0145ff7c 01223d5b 0145ff98 00000000 00000000 ntdll!KiFastSystemCallRet
0145ffb4 7c80b713 00000610 0121f648 7c9110fd LBTServ+0x3d5b
0145ffec 00000000 01223d30 00000610 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
000000000145ff58 be 91 36 7e 6b 77 37 7e - 98 ff 45 01 00 00 00 00 ..6~kw7~..E.....
000000000145ff68 00 00 00 00 00 00 00 00 - 10 06 00 00 48 f6 21 01 ............H.!.
000000000145ff78 fd 10 91 7c b4 ff 45 01 - 5b 3d 22 01 98 ff 45 01 ...|..E.[=\"...E.
000000000145ff88 00 00 00 00 00 00 00 00 - 00 00 00 00 10 06 00 00 ................
000000000145ff98 4a 00 03 00 89 06 00 00 - 00 00 00 00 00 00 00 00 J...............
000000000145ffa8 c3 c9 18 00 9d 02 00 00 - 40 01 00 00 ec ff 45 01 ........@.....E.
000000000145ffb8 13 b7 80 7c 10 06 00 00 - 48 f6 21 01 fd 10 91 7c ...|....H.!....|
000000000145ffc8 10 06 00 00 00 90 fa 7f - 00 96 e3 89 c0 ff 45 01 ..............E.
000000000145ffd8 08 cb 82 89 ff ff ff ff - c0 9a 83 7c 20 b7 80 7c ...........| ..|
000000000145ffe8 00 00 00 00 00 00 00 00 - 00 00 00 00 30 3d 22 01 ............0=\".
000000000145fff8 10 06 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001460008 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001460018 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001460028 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001460038 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001460048 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001460058 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001460068 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001460078 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000001460088 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

*----> Statusabbild für Threadkennung 0x644 <----*

eax=00000000 ebx=0155fec0 ecx=00000600 edx=00000648 esi=00000000 edi=7ffdb000
eip=7c91e4f4 esp=0155fe98 ebp=0155ff34 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

Funktion: ntdll!KiFastSystemCallRet
7c91e4da e829000000 call ntdll!RtlRaiseException (7c91e508)
7c91e4df 8b0424 mov eax,[esp]
7c91e4e2 8be5 mov esp,ebp
7c91e4e4 5d pop ebp
7c91e4e5 c3 ret
7c91e4e6 8da42400000000 lea esp,[esp]
7c91e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c91e4f0 8bd4 mov edx,esp
7c91e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c91e4f4 c3 ret
7c91e4f5 8da42400000000 lea esp,[esp]
7c91e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c91e500 8d542408 lea edx,[esp+0x8]
7c91e504 cd2e int 2e
7c91e506 c3 ret
7c91e507 90 nop
ntdll!RtlRaiseException:
7c91e508 55 push ebp
7c91e509 8bec mov ebp,esp

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0155ff34 7c80a105 00000002 0155ff68 00000000 ntdll!KiFastSystemCallRet
0155ff50 01226154 00000002 0155ff68 00000000 kernel32!WaitForMultipleObjects+0x18
0155ff70 01223205 00000648 00000600 ffffffff LBTServ+0x6154
0155ffb4 7c80b713 00000000 7c922d58 01223d30 LBTServ!LGBT_Terminate+0x2f5
0155ffec 00000000 01223050 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
000000000155fe98 2c df 91 7c 74 95 80 7c - 02 00 00 00 c0 fe 55 01 ,..|t..|......U.
000000000155fea8 01 00 00 00 00 00 00 00 - 00 00 00 00 58 2d 92 7c ............X-.|
000000000155feb8 30 3d 22 01 00 00 00 00 - 48 06 00 00 00 06 00 00 0=\".....H.......
000000000155fec8 24 fe 55 01 12 00 12 00 - dc ff 55 01 00 e9 91 7c $.U.......U....|
000000000155fed8 40 00 92 7c ff ff ff ff - 14 00 00 00 01 00 00 00 @..|............
000000000155fee8 00 00 00 00 00 00 00 00 - 10 00 00 00 04 ff 55 01 ..............U.
000000000155fef8 62 04 92 7c e0 f4 e7 00 - 00 b0 fd 7f 00 30 fa 7f b..|.........0..
000000000155ff08 1e 79 da 77 00 00 00 00 - c0 fe 55 01 30 3d 22 01 .y.w......U.0=\".
000000000155ff18 02 00 00 00 b4 fe 55 01 - 00 00 00 00 dc ff 55 01 ......U.......U.
000000000155ff28 c0 9a 83 7c 68 96 80 7c - 00 00 00 00 50 ff 55 01 ...|h..|....P.U.
000000000155ff38 05 a1 80 7c 02 00 00 00 - 68 ff 55 01 00 00 00 00 ...|....h.U.....
000000000155ff48 ff ff ff ff 00 00 00 00 - 70 ff 55 01 54 61 22 01 ........p.U.Ta\".
000000000155ff58 02 00 00 00 68 ff 55 01 - 00 00 00 00 ff ff ff ff ....h.U.........
000000000155ff68 48 06 00 00 00 06 00 00 - b4 ff 55 01 05 32 22 01 H.........U..2\".
000000000155ff78 48 06 00 00 00 06 00 00 - ff ff ff ff c0 36 83 89 H............6..
000000000155ff88 01 00 00 00 00 00 00 00 - a0 4d 7d 89 01 00 00 00 .........M}.....
000000000155ff98 4c 06 00 00 50 06 00 00 - 00 00 00 00 40 65 e9 00 L...P.......@e..
000000000155ffa8 a0 3c ee ac a0 ff 55 01 - 00 00 00 00 ec ff 55 01 .<....U.......U.
000000000155ffb8 13 b7 80 7c 00 00 00 00 - 58 2d 92 7c 30 3d 22 01 ...|....X-.|0=\".
000000000155ffc8 00 00 00 00 00 30 fa 7f - 00 76 e3 89 c0 ff 55 01 .....0...v....U.

*----> Statusabbild für Threadkennung 0x794 <----*

eax=00000102 ebx=00000000 ecx=7ffa0000 edx=7c91e4f4 esi=7c98b420 edi=7c98b440
eip=7c91e4f4 esp=017aff70 ebp=017affb4 iopl=0 nv up ei ng nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000286

Funktion: ntdll!KiFastSystemCallRet
7c91e4da e829000000 call ntdll!RtlRaiseException (7c91e508)
7c91e4df 8b0424 mov eax,[esp]
7c91e4e2 8be5 mov esp,ebp
7c91e4e4 5d pop ebp
7c91e4e5 c3 ret
7c91e4e6 8da42400000000 lea esp,[esp]
7c91e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c91e4f0 8bd4 mov edx,esp
7c91e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c91e4f4 c3 ret
7c91e4f5 8da42400000000 lea esp,[esp]
7c91e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c91e500 8d542408 lea edx,[esp+0x8]
7c91e504 cd2e int 2e
7c91e506 c3 ret
7c91e507 90 nop
ntdll!RtlRaiseException:
7c91e508 55 push ebp
7c91e509 8bec mov ebp,esp

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
017affb4 7c80b713 00000000 00000000 00000000 ntdll!KiFastSystemCallRet
017affec 00000000 7c920230 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
00000000017aff70 2c da 91 7c 6d 02 92 7c - 78 01 00 00 ac ff 7a 01 ,..|m..|x.....z.
00000000017aff80 b0 ff 7a 01 98 ff 7a 01 - a0 ff 7a 01 00 00 00 00 ..z...z...z.....
00000000017aff90 00 00 00 00 00 00 00 00 - 00 00 00 00 88 e4 e9 00 ................
00000000017affa0 00 7c 28 e8 ff ff ff ff - a0 6c 03 ac c9 7a 93 7c .|(......l...z.|
00000000017affb0 20 da eb 00 ec ff 7a 01 - 13 b7 80 7c 00 00 00 00 .....z....|....
00000000017affc0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 fa 7f ................
00000000017affd0 00 96 e3 89 c0 ff 7a 01 - f8 c2 7d 89 ff ff ff ff ......z...}.....
00000000017affe0 c0 9a 83 7c 20 b7 80 7c - 00 00 00 00 00 00 00 00 ...| ..|........
00000000017afff0 00 00 00 00 30 02 92 7c - 00 00 00 00 00 00 00 00 ....0..|........
00000000017b0000 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000017b0010 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000017b0020 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000017b0030 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000017b0040 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000017b0050 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000017b0060 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000017b0070 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000017b0080 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000017b0090 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000017b00a0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

*----> Statusabbild für Threadkennung 0x71c <----*

eax=00000000 ebx=018efef4 ecx=00000000 edx=00000000 esi=00000000 edi=7ffdb000
eip=7c91e4f4 esp=018efecc ebp=018eff68 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

Funktion: ntdll!KiFastSystemCallRet
7c91e4da e829000000 call ntdll!RtlRaiseException (7c91e508)
7c91e4df 8b0424 mov eax,[esp]
7c91e4e2 8be5 mov esp,ebp
7c91e4e4 5d pop ebp
7c91e4e5 c3 ret
7c91e4e6 8da42400000000 lea esp,[esp]
7c91e4ed 8d4900 lea ecx,[ecx]
ntdll!KiFastSystemCall:
7c91e4f0 8bd4 mov edx,esp
7c91e4f2 0f34 sysenter
ntdll!KiFastSystemCallRet:
7c91e4f4 c3 ret
7c91e4f5 8da42400000000 lea esp,[esp]
7c91e4fc 8d642400 lea esp,[esp]
ntdll!KiIntSystemCall:
7c91e500 8d542408 lea edx,[esp+0x8]
7c91e504 cd2e int 2e
7c91e506 c3 ret
7c91e507 90 nop
ntdll!RtlRaiseException:
7c91e508 55 push ebp
7c91e509 8bec mov ebp,esp

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:WINDOWSsystem32USERENV.dll -
ChildEBP RetAddr Args to Child
018eff68 7c80a105 00000003 766c1348 00000000 ntdll!KiFastSystemCallRet
018eff84 766287bd 00000003 766c1348 00000000 kernel32!WaitForMultipleObjects+0x18
018effb4 7c80b713 00000000 00000000 0119f85c USERENV!RegisterGPNotification+0x1b6
018effec 00000000 76628761 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
00000000018efecc 2c df 91 7c 74 95 80 7c - 03 00 00 00 f4 fe 8e 01 ,..|t..|........
00000000018efedc 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000018efeec f0 13 6c 76 d7 9b 80 7c - b0 07 00 00 90 07 00 00 ..lv...|........
00000000018efefc c8 07 00 00 6c ff 8e 01 - 00 e9 91 7c 00 00 00 00 ....l......|....
00000000018eff0c e6 03 00 00 20 ff 8e 01 - 14 00 00 00 01 00 00 00 .... ...........
00000000018eff1c 00 00 00 00 00 00 00 00 - 10 00 00 00 fa 1b 80 7c ...............|
00000000018eff2c 00 00 00 00 5c f8 19 01 - 00 b0 fd 7f 00 e0 f9 7f ...............
00000000018eff3c c0 25 e8 00 00 00 00 00 - f4 fe 8e 01 00 00 00 00 .%..............
00000000018eff4c 03 00 00 00 e8 fe 8e 01 - 00 00 00 00 dc ff 8e 01 ................
00000000018eff5c c0 9a 83 7c 68 96 80 7c - 00 00 00 00 84 ff 8e 01 ...|h..|........
00000000018eff6c 05 a1 80 7c 03 00 00 00 - 48 13 6c 76 00 00 00 00 ...|....H.lv....
00000000018eff7c ff ff ff ff 00 00 00 00 - b4 ff 8e 01 bd 87 62 76 ..............bv
00000000018eff8c 03 00 00 00 48 13 6c 76 - 00 00 00 00 ff ff ff ff ....H.lv........
00000000018eff9c 00 00 00 00 5c f8 19 01 - 00 00 00 00 00 00 00 00 ...............
00000000018effac 03 00 00 00 00 00 00 00 - ec ff 8e 01 13 b7 80 7c ...............|
00000000018effbc 00 00 00 00 00 00 00 00 - 5c f8 19 01 00 00 00 00 ...............
00000000018effcc 00 e0 f9 7f 00 76 e3 89 - c0 ff 8e 01 e0 e1 8b 89 .....v..........
00000000018effdc ff ff ff ff c0 9a 83 7c - 20 b7 80 7c 00 00 00 00 .......| ..|....
00000000018effec 00 00 00 00 00 00 00 00 - 61 87 62 76 00 00 00 00 ........a.bv....
00000000018efffc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

*----> Statusabbild für Threadkennung 0x728 <----*

eax=00000000 ebx=0199fe28 ecx=00000000 edx=00000000 esi=00000000 edi=7ffdb000
eip=7c91e4f4 esp=0199fe00 ebp=0199fe9c iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

Funktion: ntdll!KiFastSystemCallRet
7c91e4da e829000000 call ntd

Verfasst: 20.01.2009, 21:08
von mirko
Tut mir leid, die Frage kann ich nicht beantworten. Vor allem wieso beim 7. Mal? Das schwierige ist halt die winlogon.exe, man weiss nie was Microsoft in dieser Datei z.B. beim 7. mal so macht.

Verfasst: 20.01.2009, 18:26
von Nutzer-xxx
Nach der Installation von 0190-Warner macht das System nach spätestens dem siebten Mal Ausschalten einmal oder mehrmals nacheinander einen Neustart.

Aufbau PC:
Vorher hatte ich einen Medion 1,8 GHz (Nov. 2001).
Da lief noch alles richtig mit dem Warner 4.1
außer dass der Begrüßungston beim Windows-Start fehlte.

Umbau PC:
Motherboard Gigabyte GA-G33M-DS2R Intel G33 S775
CPU Intel Core2 Duo E6550 2,33 GHz

System Windows XP mit SP3 neu installiert.

Nach der Installation von 0190-Warner 4.1 stürzte das System während des Startens ab.
Danach 0190-Warner 4.20 installiert und obiges Verhalten mit dem Neustart.

Dr. Watson meldet in C: Dok~ All~ Anw~ Microsoft drwtsn32.log:

Anwendungsausnahme aufgetreten:
Anwendung: ?? C: WINDOWS system32 winlogon.exe (pid=840)
Wann: 12.1.2009 @ 21:55:13.093
Ausnahmenummer: c0000005 (Zugriffsverletzung)

*----> Systeminformationen <----*
Computername: DAHEIM
Benutzername: SYSTEM
Terminalsitzungskennung: 0
Prozessoranzahl: 2
Prozessortyp: x86 Family 6 Model 15 Stepping 11
Windows-Version: 5.1
Aktuelles Build: 2600
Service Pack: 3
Aktueller Typ: Multiprocessor Free
......

Die comctl32.dll hat die Version 5.82 (xpsp.080413-2105) bzw. Produktversion 6.00. ....

Nach Deinstallation 0190-Warner 4.20 wieder alles OK.

Was ist falsch?