HyperHacker Posted April 18, 2006 Posted April 18, 2006 I just right-clicked in Explorer, and it crashed, with a strange dialog that I've never seen before. It had a "Send error report" button, but it didn't work. It also had this in a text box:OS: Windows XP Professional, SP2CPU: AuthenticAMD, AMD AMD Sempron Processor 2800+, MMX @ 1680 MHzApplication data:VmVyc2lvbjogV2xGQlhVSlFWRlphUkU1RFJrTlZKQ2xTT3lRN1ZpQXNBQWRWUHlFOEl6QnpaSHQrZHpNa0lqc2tJelpGY25SOWVHcC9SemM3UjNKNGIzRkRNUT09DQpJbWFnZUJhc2U6IDA2RTUwMDAwDQpFaXA6IDc4QzdFMzANCkVheDogMzdBMDAwMA0KRWN4OiA3MDk0QTk0DQpFZHg6IDANCkVieDogMA0KRXNpOiA3MDk0OURDDQpFZGk6IDcwNTAwMDANCkVicDogMjMyRTY0Qw0KRXNwOiAyMzJFNTIwDQotMQ0KQ29kZSA9IFsyMDRdDQotIDANCi0gMjA0DQotIDIyNw0KLSAwDQotIFtdDQo+IEM6XFdJTkRPV1NcRXhwbG9yZXIuRVhFDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcbnRkbGwuZGxsDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJca2VybmVsMzIuZGxsDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcbXN2Y3J0LmRsbA0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXEFEVkFQSTMyLmRsbA0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXFJQQ1JUNC5kbGwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxHREkzMi5kbGwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxVU0VSMzIuZGxsDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcU0hMV0FQSS5kbGwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxTSEVMTDMyLmRsbA0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXG9sZTMyLmRsbA0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXE9MRUFVVDMyLmRsbA0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXEJST1dTRVVJLmRsbA0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXFNIRE9DVlcuZGxsDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcQ1JZUFQzMi5kbGwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxNU0FTTjEuZGxsDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcQ1JZUFRVSS5kbGwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxXSU5UUlVTVC5kbGwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxJTUFHRUhMUC5kbGwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxORVRBUEkzMi5kbGwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxXSU5JTkVULmRsbA0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXFdMREFQMzIuZGxsDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcVkVSU0lPTi5kbGwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxVeFRoZW1lLmRsbA0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXFNoaW1FbmcuZGxsDQo+IEM6XFdJTkRPV1NcQXBwUGF0Y2hcQWNHZW5yYWwuRExMDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcV0lOTU0uZGxsDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcTVNBQ00zMi5kbGwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxVU0VSRU5WLmRsbA0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXElNTTMyLkRMTA0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXExQSy5ETEwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxVU1AxMC5kbGwNCj4gQzpcV0lORE9XU1xXaW5TeFNceDg2X01pY3Jvc29mdC5XaW5kb3dzLkNvbW1vbi1Db250cm9sc182NTk1YjY0MTQ0Y2NmMWRmXzYuMC4yNjAwLjIxODBfeC13d19hODRmMWZmOVxjb21jdGwzMi5kbGwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxjb21jdGwzMi5kbGwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxhcHBoZWxwLmRsbA0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXG1zY3RmaW1lLmltZQ0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXENMQkNBVFEuRExMDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcQ09NUmVzLmRsbA0KPiBDOlxXSU5ET1dTXFN5c3RlbTMyXGNzY3VpLmRsbA0KPiBDOlxXSU5ET1dTXFN5c3RlbTMyXENTQ0RMTC5kbGwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlx0aGVtZXVpLmRsbA0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXFNlY3VyMzIuZGxsDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcTVNJTUczMi5kbGwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlx4cHNwMnJlcy5kbGwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxhY3R4cHJ4eS5kbGwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxTQU1MSUIuZGxsDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcbnRzaHJ1aS5kbGwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxBVEwuRExMDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcbXNpLmRsbA0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXFNFVFVQQVBJLmRsbA0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXExJTktJTkZPLmRsbA0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXHVybG1vbi5kbGwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxyc2FlbmguZGxsDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcV0lOU1RBLmRsbA0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXHdlYmNoZWNrLmRsbA0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXFdTT0NLMzIuZGxsDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcV1MyXzMyLmRsbA0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXFdTMkhFTFAuZGxsDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcc3RvYmplY3QuZGxsDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcQmF0TWV0ZXIuZGxsDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcUE9XUlBST0YuZGxsDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcV1RTQVBJMzIuZGxsDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcd2RtYXVkLmRydg0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXG1zYWNtMzIuZHJ2DQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcbWlkaW1hcC5kbGwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxORVRTSEVMTC5kbGwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxydHV0aWxzLmRsbA0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXGNyZWR1aS5kbGwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxpcGhscGFwaS5kbGwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxicm93c2VsYy5kbGwNCj4gQzpcUHJvZ3JhbSBGaWxlc1xBZG9iZVxBY3JvYmF0IDcuMFxBY3RpdmVYXEFjcm9JRUhlbHBlci5kbGwNCg0KQWRvYmUgU3lzdGVtcyBJbmNvcnBvcmF0ZWQNCkFkb2JlIEFjcm9iYXQgSUUgSGVscGVyIFZlcnNpb24gNy4wIGZvciBBY3RpdmVYDQo3LjAuMC4yMDA0MTIxNDAwDQpBY3JvSUVIZWxwZXINCkNvcHlyaWdodCAxOTg0LTIwMDQgQWRvYmUgU3lzdGVtcyBJbmNvcnBvcmF0ZWQgYW5kIGl0cyBsaWNlbnNvcnMuIEFsbCByaWdodHMgcmVzZXJ2ZWQuDQpBY3JvSUVIZWxwZXIuRExMDQo3LCAwLCAwLCAwDQpBY3JvSUVIZWxwZXIgTGlicmFyeQ0KDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcTVNWQ1I3MS5kbGwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxTWFMuRExMDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcRFVTRVIuZGxsDQo+IEM6XFByb2dyYW0gRmlsZXNcSGFyZGxpbmtTaGVsbEV4dFxIYXJkTGluay5kbGwNCg0KSGFyZExpbmsgRExMDQoxLCA2LCAwLCAxDQpIYXJkTGluaw0KQ29weXJpZ2h0IKkgMTk5OQ0KSGFyZExpbmsuRExMDQoxLCA2LCAwLCAxDQpIYXJkTGluayBEeW5hbWljIExpbmsgTGlicmFyeQ0KDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcTUZDNDJ1LkRMTA0KPiBDOlxQcm9ncmFtIEZpbGVzXEZvbGRlclNpemVcRm9sZGVyU2l6ZUNvbHVtbi5kbGwNCg0KQnJpbw0KRm9sZGVyIFNpemUgY29sdW1uIGhhbmRsZXINCjEsIDAsIDAsIDANCkZvbGRlclNpemVDb2x1bW4NCkNvcHlyaWdodCCpIDIwMDUNCkZvbGRlclNpemVDb2x1bW4uZGxsDQoyLCAwLCAwLCAwDQpGb2xkZXIgU2l6ZSBmb3IgV2luZG93cw0KDQo+IEM6XFByb2dyYW0gRmlsZXNcQWRvYmVcQWNyb2JhdCA3LjBcQWN0aXZlWFxQREZTaGVsbC5kbGwNCg0KQWRvYmUgU3lzdGVtcywgSW5jLg0KUERGIFNoZWxsIEV4dGVuc2lvbg0KNy4wLjAuMA0KUERGU2hlbGwNCkNvcHlyaWdodCAyMDAwLTIwMDQgQWRvYmUgU3lzdGVtcywgSW5jLg0KUERGU2hlbGwuZGxsDQo3LjAuMC4wDQpBZG9iZSBQREYgU2hlbGwgRXh0ZW5zaW9uDQoNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxzaGRvY2xjLmRsbA0KPiBDOlxQcm9ncmFtIEZpbGVzXFdpblJBUlxyYXJleHQuZGxsDQo+IEM6XFByb2dyYW0gRmlsZXNcVGV4dFBhZCA0XFN5c3RlbVxzaGVsbGV4dC5kbGwNCkFkZHMgVGV4dFBhZCBjb21tYW5kIHRvIEV4cGxvcmVyJ3MgY29udGV4dCBtZW51DQpIZWxpb3MgU29mdHdhcmUgU29sdXRpb25zDQpUZXh0UGFkIHNoZWxsIGV4dGVuc2lvbiBETEwNCjEuNA0KU0hFTExFWFQNCkNvcHlyaWdodCCpIDIwMDMgSGVsaW9zIFNvZnR3YXJlIFNvbHV0aW9ucw0KU0hFTExFWFQuRExMDQoxLjQNClRleHRQYWQgQWRkLU9uDQoNCj4gQzpcUHJvZ3JhbSBGaWxlc1xCcmVha1BvaW50IFNvZnR3YXJlXEhleCBXb3Jrc2hvcCA0LjJcaHdleHQuZGxsDQpodHRwOi8vd3d3LmJwc29mdC5jb20NCkJyZWFrUG9pbnQgU29mdHdhcmUsIEluYy4NCkhleCBXb3Jrc2hvcCBTaGVsbCBFeHRlbnNpb24NCjQuMjMNCkhXRVhUDQpDb3B5cmlnaHQgqSAxOTk1LTIwMDQgQnJlYWtQb2ludCBTb2Z0d2FyZSwgSW5jLiAgQWxsIFJpZ2h0cyBSZXNlcnZlZC4NCkhXRVhULkRMTA0KNC4yMw0KSGV4IFdvcmtzaG9wDQoNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxzeW5jdWkuZGxsDQo+IEM6XFByb2dyYW0gRmlsZXNcR3Jpc29mdFxBVkcgRnJlZVxhdmdzZS5kbGwNCg0KR1JJU09GVCwgcy5yLm8uDQpBVkcgU2hlbGwgRXh0ZW5zaW9uDQo3LDEsMCwzNTQNCkFWRyBTRQ0KQ29weXJpZ2h0IKkgMjAwNSwgR1JJU09GVCwgcy5yLm8uDQphdmdzZS5kbGwNCjcuMS4wLjM1NA0KQVZHIEFudGktVmlydXMgU3lzdGVtDQo3LjEsIEJ1aWxkIDM1NCBBVkdGUkVFX1JlbGVhc2VGcmVlTmV0X18yMDA1XzA5MTlfMDEyNzIwICwgU1ZOUmV2IDM2MjcwDQpSZWxlYXNlIEZyZWUNCg0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXE1TVkNQNzEuZGxsDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcbXlkb2NzLmRsbA0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXE1QUi5kbGwNCj4gQzpcV0lORE9XU1xTeXN0ZW0zMlxkcnByb3YuZGxsDQo+IEM6XFdJTkRPV1NcU3lzdGVtMzJcbnRsYW5tYW4uZGxsDQo+IEM6XFdJTkRPV1NcU3lzdGVtMzJcTkVUVUkwLmRsbA0KPiBDOlxXSU5ET1dTXFN5c3RlbTMyXE5FVFVJMS5kbGwNCj4gQzpcV0lORE9XU1xTeXN0ZW0zMlxORVRSQVAuZGxsDQo+IEM6XFdJTkRPV1NcU3lzdGVtMzJcZGF2Y2xudC5kbGwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxOVE1BUlRBLkRMTA0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXHNoaW1ndncuZGxsDQo+IEM6XFdJTkRPV1NcV2luU3hTXHg4Nl9NaWNyb3NvZnQuV2luZG93cy5HZGlQbHVzXzY1OTViNjQxNDRjY2YxZGZfMS4wLjI2MDAuMjE4MF94LXd3XzUyMmY5ZjgyXGdkaXBsdXMuZGxsDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcbXNjbXMuZGxsDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcV0lOU1BPT0wuRFJWDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcTVNWRlczMi5kbGwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlx3bXZjb3JlLmRsbA0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXHdtaWR4LmRsbA0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXFdNQVNGLkRMTA0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXG1zZG1vLmRsbA0KDQo2LjUuMjYwMC4yMTgwDQo2LjUuMjYwMC4yMTgwDQoNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxEUk1DbGllbi5ETEwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxtbGFuZy5kbGwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxERVZNR1IuRExMDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcV01JLmRsbA0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXENhYmluZXQuZGxsDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcaWNtMzIuZGxsDQoNCk1pY3Jvc29mdCBDb3Jwb3JhdGlvbg0KTWljcm9zb2Z0IENvbG9yIE1hbmFnZW1lbnQgTW9kdWxlIChDTU0pDQo1LjEuMjYwMC4yMTgwICh4cHNwX3NwMl9ydG0uMDQwODAzLTIxNTgpDQpJQ00zMi5ETEwNCkNvcHlyaWdodCCpMTk5NS0xOTk3IEhlaWRlbGJlcmdlciBEcnVja21hc2NoaW5lbiBBRw0KSUNNMzIuRExMDQo1LjEuMjYwMC4yMTgwDQpNaWNyb3NvZnSuIFdpbmRvd3OuIE9wZXJhdGluZyBTeXN0ZW0NCg0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXERUTWVudUV4LmRsbA0KDQpYR0kgVGVjaG5vbG9neSwgSW5jLg0KRGVza1RvcE1lbnVJdGVtRXggTW9kdWxlDQo2LjE0LjAxLjExMzANCkRlc2tUb3BNZW51SXRlbUV4DQpDb3B5cmlnaHQgKEMpIDIwMDMtMjAwNCBYR0kgVGVjaG5vbG9neSwgSW5jLg0KRGVza1RvcE1lbnVJdGVtRXguRExMDQo2LjE0LjAxLjExMzANCkRlc2tUb3BNZW51SXRlbUV4IE1vZHVsZQ0KDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcR2VuQ3RybC5kbGwNCg0KWEdJIFRlY2hub2xvZ3ksIEluYy4NCkdlbmVyYWxEZXZpY2VDdHJsQ21wbnQgTW9kdWxlDQo2LjE0LjAxLjExMzANCkdlbmVyYWxEZXZpY2VDdHJsQ21wbnQNCkNvcHlyaWdodCAoQykgMjAwMy0yMDA0IFhHSSBUZWNobm9sb2d5LCBJbmMuDQpHZW5lcmFsRGV2aWNlQ3RybENtcG50LkRMTA0KNi4xNC4wMS4xMTMwDQpHZW5lcmFsRGV2aWNlQ3RybENtcG50IE1vZHVsZQ0KDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcemlwZmxkci5kbGwNCj4gQzpcV0lORE9XU1xkcm9wY3B5ci5kbGwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxEU09VTkQuZGxsDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcUGF0aENvcHlFeC5kbGwNCg0KUGF0aENvcHlFeCBNb2R1bGUNCjEsIDAsIDAsIDENClBhdGhDb3B5RXgNCkNvcHlyaWdodCAyMDAwDQpQYXRoQ29weUV4LkRMTA0KMSwgMCwgMCwgMQ0KUGF0aENvcHlFeCBNb2R1bGUNCg0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXHhwc3AxcmVzLmRsbA0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXGRpc2tjb3B5LmRsbA0KPiBDOlxQcm9ncmFtIEZpbGVzXEFsZXggRmVpbm1hblxJU08gUmVjb3JkZXJcSVNPUmVjb3JkZXIuZGxsDQoNCkFsZXggRmVpbm1hbg0KSVNPIFJlY29yZGVyDQoyLjAuMS4wDQpJU09SZWNvcmRlci5kbGwNCjIwMDQgKGMpIEFsZXggRmVpbm1hbi4gIEFsbCByaWdodHMgcmVzZXJ2ZWQuDQpJU09SZWNvcmRlci5kbGwNCjIuMC4xLjANCklTTyBSZWNvcmRlcg0KQmV0YSAyDQpCZXRhIDENCg0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXGNvbWRsZzMyLmRsbA0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXFdJTkhUVFAuZGxsDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcV1pDU0FQSS5ETEwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlx3emNkbGcuZGxsDQo+IEM6XFByb2dyYW0gRmlsZXNcU3Bpcml0UHlyZSBFeHRlbnNpb25zXEZpbGVFeHRUb2dnbGUgRXh0ZW5zaW9uXEZpbGVFeHRUb2dnbGVfMi4wLmRsbA0KDQpGaWxlRXh0VG9nZ2xlIE1vZHVsZQ0KMSwgMCwgMCwgMQ0KRmlsZUV4dFRvZ2dsZQ0KQ29weXJpZ2h0IDIwMDUNCkZpbGVFeHRUb2dnbGUuRExMDQoxLCAwLCAwLCAxDQpGaWxlRXh0VG9nZ2xlIE1vZHVsZQ0KDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcUkFTQVBJMzIuRExMDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJccmFzbWFuLmRsbA0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXFRBUEkzMi5kbGwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxtc3YxXzAuZGxsDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcc2Vuc2FwaS5kbGwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlx1c2J1aS5kbGwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxzaG1lZGlhLmRsbA0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXEFWSUZJTDMyLmRsbA0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXHFlZGl0LmRsbA0KDQo2LjUuMjYwMC4yMTgwDQo2LjUuMjYwMC4yMTgwDQoNCj4gQzpcUHJvZ3JhbSBGaWxlc1xLLUxpdGUgQ29kZWMgUGFja1xmaWx0ZXJzXE9nZ0RTLmRsbA0KRW5qb3kNCk9nZyBEaXJlY3RTaG93KHRtKSBGaWx0ZXIgQ29sbGVjdGlvbg0KMCwgOSwgOSwgNQ0KT2dnRFMNCkNvcHlyaWdodCAoQykgMjAwMiBUb2JpYXMgV2FsZHZvZ2VsDQpPZ2cgYW5kIFZvcmJpcyBhcmUgcmVnaXN0ZXJlZCAgdHJhZGVtYXJrcyBvZiBYaXBoLCBEaXJlY3RTaG93IGlzIGEgcmVnaXN0ZXJlZCB0cmFkZW1hcmsgb2YgTWljcm9zb2Z0IENvcnAuDQpPZ2dEUy5ETEwNCjAsIDksIDksIDUNCk9nZyBEaXJlY3RTaG93KHRtKSBGaWx0ZXIgQ29sbGVjdGlvbg0KDQo+IEM6XFByb2dyYW0gRmlsZXNcSy1MaXRlIENvZGVjIFBhY2tcZmlsdGVyc1x2b3JiaXMuZGxsDQo+IEM6XFByb2dyYW0gRmlsZXNcSy1MaXRlIENvZGVjIFBhY2tcZmlsdGVyc1xvZ2cuZGxsDQo+IEM6XFByb2dyYW0gRmlsZXNcSy1MaXRlIENvZGVjIFBhY2tcZmlsdGVyc1x2b3JiaXNlbmMuZGxsDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcRERSQVcuZGxsDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcRENJTUFOMzIuZGxsDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcRDNESU03MDAuRExMDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcZHhtYXNmLmRsbA0KDQo2LjQuOS4xMTI1DQo2LjQuOS4xMTI1DQoNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxrc3VzZXIuZGxsDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcbXN2Y3A2MC5kbGwNCj4gQzpcUHJvZ3JhbSBGaWxlc1xDb21tb24gRmlsZXNcQWhlYWRcTGliXEFkdnJDbnRyLmRsbA0KDQpBaGVhZCBTb2Z0d2FyZSBBRw0KQWR2ckNudHIgTW9kdWxlDQoxLDIsOCwgMjMwNA0KQWR2ckNudHINCkNvcHlyaWdodCAoYykgMTk5NS0yMDAzIEFoZWFkIFNvZnR3YXJlIGFuZCBpdHMgbGljZW5zb3JzDQpBZHZyQ250ci5ETEwNCjEsMiw4LCAyMzA0DQpBZHZyQ250ciBNb2R1bGUNCg0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXGxhbWVBQ00uYWNtDQpUaGlzIGlzIGFuIEFDTSBkcml2ZXIgZm9yIFdpbjMyIHVzaW5nIExhbWUgdG8gZW5jb2RlDQpodHRwOi8vd3d3Lm1wM2Rldi5vcmcvDQpMYW1lIE1QMyBjb2RlYyBlbmdpbmUNCjAuOS4xDQpsYW1lQUNNDQpDb3B5cmlnaHQgqSAyMDAyIFN0ZXZlIExob21tZSwgQ29weXJpZ2h0IKkgMjAwMi0yMDA0IFRoZSBMQU1FIFByb2plY3QNCkxHUEwgKHNlZSBnbnUub3JnKQ0KbGFtZUFDTS5hY20NCjAuOS4xDQpMYW1lIE1QMyBjb2RlYw0KDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcVVJMLmRsbA0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXHN0aS5kbGwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxDRkdNR1IzMi5kbGwNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxxdWFydHouZGxsDQoNCjYuNS4yNjAwLjIxODANCjYuNS4yNjAwLjIxODANCg0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXGRldmVudW0uZGxsDQoNCjYuNS4yNjAwLjIxODANCjYuNS4yNjAwLjIxODANCg0KPiBDOlxQcm9ncmFtIEZpbGVzXEstTGl0ZSBDb2RlYyBQYWNrXGZpbHRlcnNcdnNmaWx0ZXIuZGxsDQpWaXNpdCBodHRwOi8vZ2FiZXN0Lm9yZy8gZm9yIHVwZGF0ZXMuDQpHYWJlc3QNClZvYlN1YiAmIFRleHRTdWIgZmlsdGVyIGZvciBEaXJlY3RTaG93L1ZpcnR1YWxEdWIvQXZpc3ludGgNCjEsIDAsIDAsIDkNClZTRmlsdGVyDQpDb3B5cmlnaHQgKEMpIDIwMDEtMjAwNCBHYWJlc3QNClZTRmlsdGVyLkRMTA0KMSwgMCwgMCwgOQ0KVlNGaWx0ZXINCg0KPiBDOlxQcm9ncmFtIEZpbGVzXEdCQSBNZWRpYVxSRUFMXFJlYWxNZWRpYVNwbGl0dGVyLmF4DQpodHRwOi8vZ2FiZXN0Lm9yZy8NCkdhYmVzdA0KUmVhbE1lZGlhIFNwbGl0dGVyDQoxLCAwLCAwLCA3DQpSZWFsTWVkaWEgU3BsaXR0ZXINCkNvcHlyaWdodCAoQykgMjAwMw0KUmVhbE1lZGlhU3BsaXR0ZXIuYXgNCjEsIDAsIDAsIDcNClJlYWxNZWRpYSBTcGxpdHRlcg0KDQo+IEM6XFByb2dyYW0gRmlsZXNcSy1MaXRlIENvZGVjIFBhY2tcZmZkc2hvd1xmZmRzaG93LmF4DQoNCkRpcmVjdFNob3cgYW5kIFZGVyB2aWRlbyBhbmQgYXVkaW8gZGVjb2RpbmcvZW5jb2RpbmcvcHJvY2Vzc2luZyBmaWx0ZXINCjEuMC4yLjI0DQpmZmRzaG93DQpDb3B5cmlnaHQgqSAyMDAyLTIwMDUgTWlsYW4gQ3V0a2ENCkdOVSBHUEwNCmZmZHNob3cuYXgNCjEuMC4yLjI0DQpmZmRzaG93DQoNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxESU5QVVQuZGxsDQo+IEM6XFByb2dyYW0gRmlsZXNcSy1MaXRlIENvZGVjIFBhY2tcZmlsdGVyc1wzaXZ4RFNEZWNvZGVyLmF4DQoNCjNpdnguY29tDQozaXZ4IEQ0IDQuNS4xIFBybyBEaXJlY3RTaG93IFZpZGVvIERlY29kZXINCjQsIDUsIDEsIDMwDQozaXZ4RFNEZWNvZGVyDQpDb3B5cmlnaHQgKEMpIDNpdnguY29tLCAxOTk5LTIwMDQuIEFsbCByaWdodHMgcmVzZXJ2ZWQuDQozaXZ4RFNEZWNvZGVyLmF4DQo0LCA1LCAxLCAzMA0KM2l2eCBENCA0LjUuMSBQcm8NCg0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXDNpdnguZGxsDQoNCjNpdnguY29tDQozaXZ4IEQ0IDQuNS4xIFBybyBDb3JlDQo0LCA1LCAxLCAzMA0KM2l2eENvcmUNCkNvcHlyaWdodCAoQykgM2l2eC5jb20sIDE5OTktMjAwNC4gQWxsIHJpZ2h0cyByZXNlcnZlZC4NCjNpdnguZGxsDQo0LCA1LCAxLCAzMA0KM2l2eCBENCA0LjUuMSBQcm8NCg0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXHdtcHNoZWxsLmRsbA0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXHFhc2YuZGxsDQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJcd212ZG1vZC5kbGwNCj4gQzpcUHJvZ3JhbSBGaWxlc1xHQkEgTWVkaWFcWHZpZFx4dmlkLmF4DQo+IEM6XFdJTkRPV1Ncc3lzdGVtMzJccGVyZm9zLmRsbA0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXG1zcmxlMzIuZGxsDQo+IEM6XFByb2dyYW0gRmlsZXNcQ29tbW9uIEZpbGVzXEFoZWFkXERTRmlsdGVyXE5lU3BsaXR0ZXIuYXgNCg0KTmVybyBBRw0KU3BsaXR0ZXIgRmlsdGVyDQozLDIsMCwxOA0KQ29weXJpZ2h0IChjKSAxOTk1LTIwMDUgTmVybyBBRyBhbmQgaXRzIGxpY2Vuc29ycw0KTmVTcGxpdHRlci5heA0KMSwgMCwgMiwgOQ0KTmVybyBTaG93VGltZQ0KDQo+IEM6XFByb2dyYW0gRmlsZXNcSy1MaXRlIENvZGVjIFBhY2tcZmlsdGVyc1wzaXZ4RFNNZWRpYVNwbGl0dGVyLmF4DQoNCjNpdnguY29tDQozaXZ4IEQ0IDQuNS4xIFBybyBEaXJlY3RTaG93IE1lZGlhIFNwbGl0dGVyDQo0LCA1LCAxLCAzMA0KM2l2eERTTWVkaWFTcGxpdHRlcg0KQ29weXJpZ2h0IChDKSAzaXZ4LmNvbSwgMTk5OS0yMDA0LiBBbGwgcmlnaHRzIHJlc2VydmVkLg0KM2l2eERTTWVkaWFTcGxpdHRlci5heA0KNCwgNSwgMSwgMzANCjNpdnggRDQgNC41LjEgUHJvDQoNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxPcGVuUXVpY2t0aW1lTGliLmRsbA0KPiBDOlxXSU5ET1dTXHN5c3RlbTMyXHdtcGFzZi5kbGwNCj4gQzpcUHJvZ3JhbSBGaWxlc1xHQkEgTWVkaWFcRFZEXG1wZzJzcGx0LmF4DQoNCjYuNS4xLjkwMA0KNi41LjEuOTAwDQoNCj4gQzpcUHJvZ3JhbSBGaWxlc1xLLUxpdGUgQ29kZWMgUGFja1xmaWx0ZXJzXFdhdlBhY2tEU1NwbGl0dGVyLmF4DQp3d3cud2F2cGFjay5jb20NCi0NCldhdlBhY2sgQXVkaW8gRGlyZWN0U2hvdyBTcGxpdHRlcg0KMSwgMCwgMywgMjc3DQpXYXZQYWNrRFNTcGxpdHRlcg0KQ29weXJpZ2h0IKkgMjAwNQ0KV2F2UGFja0RTU3BsaXR0ZXIuYXgNCjEsIDAsIDMsIDI3Nw0KV2F2UGFjayBBdWRpbyBEaXJlY3RTaG93IFNwbGl0dGVyDQoNCj4gQzpcV0lORE9XU1xzeXN0ZW0zMlxzdHJtZGxsLmRsbA0KPiBDOlxQcm9ncmFtIEZpbGVzXENvbW1vbiBGaWxlc1xBaGVhZFxEU0ZpbHRlclxOZVZpZGVvLmF4DQoNCk5lcm8gQUcNCk1QRUctMS8yLzQgJiBBVkMgdmlkZW8gZGVjb2RlciB3LyBEeFZBDQozLDIsMCwxOA0KQ29weXJpZ2h0IChjKSAyMDA1IE5lcm8gQUcgYW5kIGl0cyBsaWNlbnNvcnMNCk5lVmlkZW8uYXgNCjIsIDAsIDIsIDQ2DQpOZXJvIFN1aXRlDQo=What the heck?
cluberti Posted April 18, 2006 Posted April 18, 2006 Oh my, that's pretty odd. Did, per chance, Dr Watson create any dumps in your %userprofile%\Application Data\Dr Watson or All Users\Application Data\Dr Watson folders?If not, open a command prompt and type:drwtsn32 -i (hit enter)drwtsn32 (hit enterSet the log type to be full, and make sure that dump all thread contents, visual notification, and create crash dump file are all checked.Then, stop and disable the error reporting service (start > run > services.msc) and see if you can make it happen again - if so, Dr Watson should create a dump of it...
HyperHacker Posted April 18, 2006 Author Posted April 18, 2006 Hm, neither of those exist, and error reporting is already off. I think something's just messed up, planning to reinstall soon. Just wondering what program that might have been.
LLXX Posted April 18, 2006 Posted April 18, 2006 The base64 encoded body reads as follows:Version: WlFBXUJQVFZaRE5DRkNVJClSOyQ7ViAsAAdVPyE8IzBzZHt+dzMkIjskIzZFcnR9eGp/Rzc7R3J4b3FDMQ==ImageBase: 06E50000Eip: 78C7E30Eax: 37A0000Ecx: 7094A94Edx: 0Ebx: 0Esi: 70949DCEdi: 7050000Ebp: 232E64CEsp: 232E520-1Code = [204]- 0- 204- 227- 0- []> C:\WINDOWS\Explorer.EXE> C:\WINDOWS\system32\ntdll.dll> C:\WINDOWS\system32\kernel32.dll> C:\WINDOWS\system32\msvcrt.dll> C:\WINDOWS\system32\ADVAPI32.dll> C:\WINDOWS\system32\RPCRT4.dll> C:\WINDOWS\system32\GDI32.dll> C:\WINDOWS\system32\USER32.dll> C:\WINDOWS\system32\SHLWAPI.dll> C:\WINDOWS\system32\SHELL32.dll> C:\WINDOWS\system32\ole32.dll> C:\WINDOWS\system32\OLEAUT32.dll> C:\WINDOWS\system32\BROWSEUI.dll> C:\WINDOWS\system32\SHDOCVW.dll> C:\WINDOWS\system32\CRYPT32.dll> C:\WINDOWS\system32\MSASN1.dll> C:\WINDOWS\system32\CRYPTUI.dll> C:\WINDOWS\system32\WINTRUST.dll> C:\WINDOWS\system32\IMAGEHLP.dll> C:\WINDOWS\system32\NETAPI32.dll> C:\WINDOWS\system32\WININET.dll> C:\WINDOWS\system32\WLDAP32.dll> C:\WINDOWS\system32\VERSION.dll> C:\WINDOWS\system32\UxTheme.dll> C:\WINDOWS\system32\ShimEng.dll> C:\WINDOWS\AppPatch\AcGenral.DLL> C:\WINDOWS\system32\WINMM.dll> C:\WINDOWS\system32\MSACM32.dll> C:\WINDOWS\system32\USERENV.dll> C:\WINDOWS\system32\IMM32.DLL> C:\WINDOWS\system32\LPK.DLL> C:\WINDOWS\system32\USP10.dll> C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll> C:\WINDOWS\system32\comctl32.dll> C:\WINDOWS\system32\apphelp.dll> C:\WINDOWS\system32\msctfime.ime> C:\WINDOWS\system32\CLBCATQ.DLL> C:\WINDOWS\system32\COMRes.dll> C:\WINDOWS\System32\cscui.dll> C:\WINDOWS\System32\CSCDLL.dll> C:\WINDOWS\system32\themeui.dll> C:\WINDOWS\system32\Secur32.dll> C:\WINDOWS\system32\MSIMG32.dll> C:\WINDOWS\system32\xpsp2res.dll> C:\WINDOWS\system32\actxprxy.dll> C:\WINDOWS\system32\SAMLIB.dll> C:\WINDOWS\system32\ntshrui.dll> C:\WINDOWS\system32\ATL.DLL> C:\WINDOWS\system32\msi.dll> C:\WINDOWS\system32\SETUPAPI.dll> C:\WINDOWS\system32\LINKINFO.dll> C:\WINDOWS\system32\urlmon.dll> C:\WINDOWS\system32\rsaenh.dll> C:\WINDOWS\system32\WINSTA.dll> C:\WINDOWS\system32\webcheck.dll> C:\WINDOWS\system32\WSOCK32.dll> C:\WINDOWS\system32\WS2_32.dll> C:\WINDOWS\system32\WS2HELP.dll> C:\WINDOWS\system32\stobject.dll> C:\WINDOWS\system32\BatMeter.dll> C:\WINDOWS\system32\POWRPROF.dll> C:\WINDOWS\system32\WTSAPI32.dll> C:\WINDOWS\system32\wdmaud.drv> C:\WINDOWS\system32\msacm32.drv> C:\WINDOWS\system32\midimap.dll> C:\WINDOWS\system32\NETSHELL.dll> C:\WINDOWS\system32\rtutils.dll> C:\WINDOWS\system32\credui.dll> C:\WINDOWS\system32\iphlpapi.dll> C:\WINDOWS\system32\browselc.dll> C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dllAdobe Systems IncorporatedAdobe Acrobat IE Helper Version 7.0 for ActiveX7.0.0.2004121400AcroIEHelperCopyright 1984-2004 Adobe Systems Incorporated and its licensors. All rights reserved.AcroIEHelper.DLL7, 0, 0, 0AcroIEHelper Library> C:\WINDOWS\system32\MSVCR71.dll> C:\WINDOWS\system32\SXS.DLL> C:\WINDOWS\system32\DUSER.dll> C:\Program Files\HardlinkShellExt\HardLink.dllHardLink DLL1, 6, 0, 1HardLinkCopyright © 1999HardLink.DLL1, 6, 0, 1HardLink Dynamic Link Library> C:\WINDOWS\system32\MFC42u.DLL> C:\Program Files\FolderSize\FolderSizeColumn.dllBrioFolder Size column handler1, 0, 0, 0FolderSizeColumnCopyright © 2005FolderSizeColumn.dll2, 0, 0, 0Folder Size for Windows> C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dllAdobe Systems, Inc.PDF Shell Extension7.0.0.0PDFShellCopyright 2000-2004 Adobe Systems, Inc.PDFShell.dll7.0.0.0Adobe PDF Shell Extension> C:\WINDOWS\system32\shdoclc.dll> C:\Program Files\WinRAR\rarext.dll> C:\Program Files\TextPad 4\System\shellext.dllAdds TextPad command to Explorer's context menuHelios Software SolutionsTextPad shell extension DLL1.4SHELLEXTCopyright © 2003 Helios Software SolutionsSHELLEXT.DLL1.4TextPad Add-On> C:\Program Files\BreakPoint Software\Hex Workshop 4.2\hwext.dllhttp://www.bpsoft.comBreakPoint Software, Inc.Hex Workshop Shell Extension4.23HWEXTCopyright © 1995-2004 BreakPoint Software, Inc. All Rights Reserved.HWEXT.DLL4.23Hex Workshop> C:\WINDOWS\system32\syncui.dll> C:\Program Files\Grisoft\AVG Free\avgse.dllGRISOFT, s.r.o.AVG Shell Extension7,1,0,354AVG SECopyright © 2005, GRISOFT, s.r.o.avgse.dll7.1.0.354AVG Anti-Virus System7.1, Build 354 AVGFREE_ReleaseFreeNet__2005_0919_012720 , SVNRev 36270Release Free> C:\WINDOWS\system32\MSVCP71.dll> C:\WINDOWS\system32\mydocs.dll> C:\WINDOWS\system32\MPR.dll> C:\WINDOWS\System32\drprov.dll> C:\WINDOWS\System32\ntlanman.dll> C:\WINDOWS\System32\NETUI0.dll> C:\WINDOWS\System32\NETUI1.dll> C:\WINDOWS\System32\NETRAP.dll> C:\WINDOWS\System32\davclnt.dll> C:\WINDOWS\system32\NTMARTA.DLL> C:\WINDOWS\system32\shimgvw.dll> C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.2180_x-ww_522f9f82\gdiplus.dll> C:\WINDOWS\system32\mscms.dll> C:\WINDOWS\system32\WINSPOOL.DRV> C:\WINDOWS\system32\MSVFW32.dll> C:\WINDOWS\system32\wmvcore.dll> C:\WINDOWS\system32\wmidx.dll> C:\WINDOWS\system32\WMASF.DLL> C:\WINDOWS\system32\msdmo.dll6.5.2600.21806.5.2600.2180> C:\WINDOWS\system32\DRMClien.DLL> C:\WINDOWS\system32\mlang.dll> C:\WINDOWS\system32\DEVMGR.DLL> C:\WINDOWS\system32\WMI.dll> C:\WINDOWS\system32\Cabinet.dll> C:\WINDOWS\system32\icm32.dllMicrosoft CorporationMicrosoft Color Management Module (CMM)5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)ICM32.DLLCopyright ©1995-1997 Heidelberger Druckmaschinen AGICM32.DLL5.1.2600.2180Microsoft® Windows® Operating System> C:\WINDOWS\system32\DTMenuEx.dllXGI Technology, Inc.DeskTopMenuItemEx Module6.14.01.1130DeskTopMenuItemExCopyright © 2003-2004 XGI Technology, Inc.DeskTopMenuItemEx.DLL6.14.01.1130DeskTopMenuItemEx Module> C:\WINDOWS\system32\GenCtrl.dllXGI Technology, Inc.GeneralDeviceCtrlCmpnt Module6.14.01.1130GeneralDeviceCtrlCmpntCopyright © 2003-2004 XGI Technology, Inc.GeneralDeviceCtrlCmpnt.DLL6.14.01.1130GeneralDeviceCtrlCmpnt Module> C:\WINDOWS\system32\zipfldr.dll> C:\WINDOWS\dropcpyr.dll> C:\WINDOWS\system32\DSOUND.dll> C:\WINDOWS\system32\PathCopyEx.dllPathCopyEx Module1, 0, 0, 1PathCopyExCopyright 2000PathCopyEx.DLL1, 0, 0, 1PathCopyEx Module> C:\WINDOWS\system32\xpsp1res.dll> C:\WINDOWS\system32\diskcopy.dll> C:\Program Files\Alex Feinman\ISO Recorder\ISORecorder.dllAlex FeinmanISO Recorder2.0.1.0ISORecorder.dll2004 © Alex Feinman. All rights reserved.ISORecorder.dll2.0.1.0ISO RecorderBeta 2Beta 1> C:\WINDOWS\system32\comdlg32.dll> C:\WINDOWS\system32\WINHTTP.dll> C:\WINDOWS\system32\WZCSAPI.DLL> C:\WINDOWS\system32\wzcdlg.dll> C:\Program Files\SpiritPyre Extensions\FileExtToggle Extension\FileExtToggle_2.0.dllFileExtToggle Module1, 0, 0, 1FileExtToggleCopyright 2005FileExtToggle.DLL1, 0, 0, 1FileExtToggle Module> C:\WINDOWS\system32\RASAPI32.DLL> C:\WINDOWS\system32\rasman.dll> C:\WINDOWS\system32\TAPI32.dll> C:\WINDOWS\system32\msv1_0.dll> C:\WINDOWS\system32\sensapi.dll> C:\WINDOWS\system32\usbui.dll> C:\WINDOWS\system32\shmedia.dll> C:\WINDOWS\system32\AVIFIL32.dll> C:\WINDOWS\system32\qedit.dll6.5.2600.21806.5.2600.2180> C:\Program Files\K-Lite Codec Pack\filters\OggDS.dllEnjoyOgg DirectShow Filter Collection0, 9, 9, 5OggDSCopyright © 2002 Tobias WaldvogelOgg and Vorbis are registered trademarks of Xiph, DirectShow is a registered trademark of Microsoft Corp.OggDS.DLL0, 9, 9, 5Ogg DirectShow Filter Collection> C:\Program Files\K-Lite Codec Pack\filters\vorbis.dll> C:\Program Files\K-Lite Codec Pack\filters\ogg.dll> C:\Program Files\K-Lite Codec Pack\filters\vorbisenc.dll> C:\WINDOWS\system32\DDRAW.dll> C:\WINDOWS\system32\DCIMAN32.dll> C:\WINDOWS\system32\D3DIM700.DLL> C:\WINDOWS\system32\dxmasf.dll6.4.9.11256.4.9.1125> C:\WINDOWS\system32\ksuser.dll> C:\WINDOWS\system32\msvcp60.dll> C:\Program Files\Common Files\Ahead\Lib\AdvrCntr.dllAhead Software AGAdvrCntr Module1,2,8, 2304AdvrCntrCopyright © 1995-2003 Ahead Software and its licensorsAdvrCntr.DLL1,2,8, 2304AdvrCntr Module> C:\WINDOWS\system32\lameACM.acmThis is an ACM driver for Win32 using Lame to encodehttp://www.mp3dev.org/Lame MP3 codec engine0.9.1lameACMCopyright © 2002 Steve Lhomme, Copyright © 2002-2004 The LAME ProjectLGPL (see gnu.org)lameACM.acm0.9.1Lame MP3 codec> C:\WINDOWS\system32\URL.dll> C:\WINDOWS\system32\sti.dll> C:\WINDOWS\system32\CFGMGR32.dll> C:\WINDOWS\system32\quartz.dll6.5.2600.21806.5.2600.2180> C:\WINDOWS\system32\devenum.dll6.5.2600.21806.5.2600.2180> C:\Program Files\K-Lite Codec Pack\filters\vsfilter.dllVisit http://gabest.org/ for updates.GabestVobSub & TextSub filter for DirectShow/VirtualDub/Avisynth1, 0, 0, 9VSFilterCopyright © 2001-2004 GabestVSFilter.DLL1, 0, 0, 9VSFilter> C:\Program Files\GBA Media\REAL\RealMediaSplitter.axhttp://gabest.org/GabestRealMedia Splitter1, 0, 0, 7RealMedia SplitterCopyright © 2003RealMediaSplitter.ax1, 0, 0, 7RealMedia Splitter> C:\Program Files\K-Lite Codec Pack\ffdshow\ffdshow.axDirectShow and VFW video and audio decoding/encoding/processing filter1.0.2.24ffdshowCopyright © 2002-2005 Milan CutkaGNU GPLffdshow.ax1.0.2.24ffdshow> C:\WINDOWS\system32\DINPUT.dll> C:\Program Files\K-Lite Codec Pack\filters\3ivxDSDecoder.ax3ivx.com3ivx D4 4.5.1 Pro DirectShow Video Decoder4, 5, 1, 303ivxDSDecoderCopyright © 3ivx.com, 1999-2004. All rights reserved.3ivxDSDecoder.ax4, 5, 1, 303ivx D4 4.5.1 Pro> C:\WINDOWS\system32\3ivx.dll3ivx.com3ivx D4 4.5.1 Pro Core4, 5, 1, 303ivxCoreCopyright © 3ivx.com, 1999-2004. All rights reserved.3ivx.dll4, 5, 1, 303ivx D4 4.5.1 Pro> C:\WINDOWS\system32\wmpshell.dll> C:\WINDOWS\system32\qasf.dll> C:\WINDOWS\system32\wmvdmod.dll> C:\Program Files\GBA Media\Xvid\xvid.ax> C:\WINDOWS\system32\perfos.dll> C:\WINDOWS\system32\msrle32.dll> C:\Program Files\Common Files\Ahead\DSFilter\NeSplitter.axNero AGSplitter Filter3,2,0,18Copyright © 1995-2005 Nero AG and its licensorsNeSplitter.ax1, 0, 2, 9Nero ShowTime> C:\Program Files\K-Lite Codec Pack\filters\3ivxDSMediaSplitter.ax3ivx.com3ivx D4 4.5.1 Pro DirectShow Media Splitter4, 5, 1, 303ivxDSMediaSplitterCopyright © 3ivx.com, 1999-2004. All rights reserved.3ivxDSMediaSplitter.ax4, 5, 1, 303ivx D4 4.5.1 Pro> C:\WINDOWS\system32\OpenQuicktimeLib.dll> C:\WINDOWS\system32\wmpasf.dll> C:\Program Files\GBA Media\DVD\mpg2splt.ax6.5.1.9006.5.1.900> C:\Program Files\K-Lite Codec Pack\filters\WavPackDSSplitter.axwww.wavpack.com-WavPack Audio DirectShow Splitter1, 0, 3, 277WavPackDSSplitterCopyright © 2005WavPackDSSplitter.ax1, 0, 3, 277WavPack Audio DirectShow Splitter> C:\WINDOWS\system32\strmdll.dll> C:\Program Files\Common Files\Ahead\DSFilter\NeVideo.axNero AGMPEG-1/2/4 & AVC video decoder w/ DxVA3,2,0,18Copyright © 2005 Nero AG and its licensorsNeVideo.ax2, 0, 2, 46Nero SuiteDoes that help to explain?
cluberti Posted April 18, 2006 Posted April 18, 2006 Well, the output gives us processor state and memory address, but the file at that address is still obscured. Hopefully we can get a Dr Watson dump of this happening.
LLXX Posted April 19, 2006 Posted April 19, 2006 Version string is base64 encoded so I decoded it again, nothing too useful output though:ZQA]BPTVZDNCFCU$)R;$;V ,U?!<#0sd{~w3$";$#6Ert}xjG7;GrxoqC1However, from the line "ImageBase: 06E50000" I can guess that it occurred in a DLL, EXEs normally have an imagebase of 401000. That imagebase looks unique, if there was only a tool to mass-examine the imagebase of all the DLLs on the machine it would be possible to find which one it was...
pistachoo Posted October 29, 2006 Posted October 29, 2006 I've been trying to find a solution to this annoyance for days now. All I've discovered is that it seems related to opening / moving certain .avi files (or, in my case, downloading them using bittorent). One solution offered was as follows: Go to C:\Program Files\Common Files\Ahead\DSFilter\NeVideo.axrename it C:\Program Files\Common Files\Ahead\DSFilter\NeVideo.ax1It hasn't worked for me, however.Can anyone help??? Screenshot:
LLXX Posted October 29, 2006 Posted October 29, 2006 This maybe a property sheet handler that's attempting to read the file's contents, essentially stealing it away from uTorrent.Start -> Run -> "regedit"Open the hkey_classes_root and find the .AVI folder, click on it. If it has a subfolder called ShellEx with some other folder {xxxxxxxx-xxxx-xxxx-... } inside it, rename ShellEx to _ShellEx or something else so it doesn't find it.Note the value of the {default} entry and scroll down in the left pane, past all the extensions, until you find a folder named that entry (probably avifile or something like that). Open it, and again rename any ShellEx to _ShellEx.This should disable all context menu and property sheet handlers for the .AVI file type. See if that works.
jcarle Posted October 29, 2006 Posted October 29, 2006 I'm willing to bet that google desktop is responsible.And there should be a way to stab all you people that post 500 mile long pastes. Notepad => TXT file people! C'mon!
Jeremy Posted October 29, 2006 Posted October 29, 2006 I'm willing to bet that google desktop is responsible.And there should be a way to stab all you people that post 500 mile long pastes. Notepad => TXT file people! C'mon!<Zybl0re> get up<Zybl0re> get on up<Zybl0re> get up<Zybl0re> get on up<phxl|paper> and DANCE* nmp3bot dances -<* nmp3bot dances |-<* nmp3bot dances :D/-<<[sA]HatfulOfHollow> i'm going to become rich and famous after i invent a device that allows you to stab people in the face over the internet#4281 on www.bash.org
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now