Delphi-PRAXiS
Seite 2 von 2     12   

Delphi-PRAXiS (https://www.delphipraxis.net/forum.php)
-   Betriebssysteme (https://www.delphipraxis.net/27-betriebssysteme/)
-   -   NT started nicht richtig (https://www.delphipraxis.net/53639-nt-started-nicht-richtig.html)

SKolberg 22. Sep 2005 06:58

Re: NT started nicht richtig
 
Guten Morgen,

Wenn die Platte in einem anderen Rechner eingebaut ist geht es NICHT mit dem Win-Regedit, es gibt ein Tool (den Namen habe ich vergessen) ist Freeware. Mit dem kann man die System.Dat öffnen und wie im Regedit bearbeiten. Allerdings könntest du das System auch so hochfahren und dann Taskmanager-> Neuer Task->Regedit sollte auch ohne den Explorer.exe laufen.


Mfg, Steve

SKolberg 22. Sep 2005 07:29

Re: NT started nicht richtig
 
Hi,

wurde gerade gefragt wie man die .dmp Dateien öffnet, also:

Zitat:

Geh mal auf:
http://www.microsoft.com/whdc/devtoo...nstallx86.mspx
Das ist ein Tool um sich .dmp .asv.... Dateien anzugucken.
Danach sieht es etwa so aus:

Zitat:

Microsoft (R) DrWtsn32
Copyright (C) 1985-2001 Microsoft Corp. Alle Rechte vorbehalten.



Anwendungsausnahme aufgetreten:
Anwendung: C:\WINDOWS\SideBar\SideBar.exe (pid=796)
Wann: 13.07.2005 @ 14:44:53.320
Ausnahmenummer: c000008f
()

*----> Systeminformationen <----*
Computername: STEVE
Benutzername: Administrator
Terminalsitzungskennung: 0
Prozessoranzahl: 1
Prozessortyp: x86 Family 15 Model 2 Stepping 7
Windows-Version: 5.1
Aktuelles Build: 2600
Service Pack: 2
Aktueller Typ: Uniprocessor Free
Firma: Privat
Besitzer: Steve Kolberg

*----> Taskliste <----*
0 System Process
4 System
484 smss.exe
540 csrss.exe
564 winlogon.exe
608 services.exe
620 lsass.exe
764 svchost.exe
848 svchost.exe
884 svchost.exe
936 svchost.exe
1080 svchost.exe
1284 spoolsv.exe
1616 alg.exe
1748 wscntfy.exe
1816 Explorer.EXE
128 msiexec.exe
524 CTFMON.EXE
796 SideBar.exe
1980 drwtsn32.exe

*----> Modulliste <----*
(0000000000400000 - 0000000000421000: C:\WINDOWS\SideBar\SideBar.exe
(00000000014b0000 - 0000000001789000: C:\WINDOWS\system32\xpsp2res.dll
(0000000010000000 - 000000001018d000: C:\WINDOWS\system32\macromed\flash\flash.ocx
(0000000020000000 - 000000002008e000: C:\WINDOWS\system32\shdoclc.dll
(00000000597d0000 - 0000000059824000: C:\WINDOWS\system32\NETAPI32.dll
(000000005b0f0000 - 000000005b128000: C:\WINDOWS\system32\uxtheme.dll
(000000005d450000 - 000000005d4e7000: C:\WINDOWS\system32\comctl32.dll
(000000005e6e0000 - 000000005e6ec000: C:\WINDOWS\system32\pngfilt.dll
(0000000066d10000 - 0000000066d1c000: C:\WINDOWS\system32\ImgUtil.dll
(000000006d910000 - 000000006d91a000: C:\WINDOWS\system32\ddrawex.dll
(0000000071a00000 - 0000000071a08000: C:\WINDOWS\system32\WS2HELP.dll
(0000000071a10000 - 0000000071a27000: C:\WINDOWS\system32\WS2_32.dll
(0000000071a30000 - 0000000071a3a000: C:\WINDOWS\system32\wsock32.dll
(0000000073390000 - 00000000734e4000: C:\WINDOWS\system32\MSVBVM60.DLL
(00000000736d0000 - 0000000073719000: C:\WINDOWS\system32\DDRAW.dll
(0000000073b30000 - 0000000073b36000: C:\WINDOWS\system32\DCIMAN32.dll
(0000000074640000 - 0000000074667000: C:\WINDOWS\system32\msls31.dll
(0000000074670000 - 000000007469a000: C:\WINDOWS\system32\msimtf.dll
(00000000746a0000 - 00000000746eb000: C:\WINDOWS\system32\MSCTF.dll
(0000000075bf0000 - 0000000075c5e000: C:\WINDOWS\system32\jscript.dll
(0000000075dc0000 - 0000000075e51000: C:\WINDOWS\system32\mlang.dll
(0000000076330000 - 000000007634d000: C:\WINDOWS\system32\IMM32.DLL
(0000000076350000 - 000000007639a000: C:\WINDOWS\system32\comdlg32.dll
(0000000076880000 - 0000000076905000: C:\WINDOWS\system32\CRYPTUI.dll
(0000000076970000 - 0000000076a21000: C:\WINDOWS\system32\SXS.DLL
(0000000076af0000 - 0000000076b1e000: C:\WINDOWS\system32\WINMM.dll
(0000000076bf0000 - 0000000076c1e000: C:\WINDOWS\system32\WINTRUST.dll
(0000000076c50000 - 0000000076c78000: C:\WINDOWS\system32\IMAGEHLP.dll
(0000000076f20000 - 0000000076f4d000: C:\WINDOWS\system32\WLDAP32.dll
(0000000076f90000 - 000000007700f000: C:\WINDOWS\system32\CLBCATQ.DLL
(0000000077010000 - 00000000770e3000: C:\WINDOWS\system32\COMRes.dll
(00000000770f0000 - 000000007717c000: C:\WINDOWS\system32\OLEAUT32.dll
(0000000077180000 - 0000000077227000: C:\WINDOWS\system32\WININET.dll
(0000000077230000 - 00000000772cd000: C:\WINDOWS\system32\urlmon.dll
(00000000773a0000 - 00000000774a2000: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
(00000000774b0000 - 00000000775ec000: C:\WINDOWS\system32\ole32.dll
(0000000077730000 - 000000007789c000: C:\WINDOWS\system32\shdocvw.dll
(00000000778f0000 - 00000000779e4000: C:\WINDOWS\system32\SETUPAPI.dll
(0000000077a50000 - 0000000077ae5000: C:\WINDOWS\system32\CRYPT32.dll
(0000000077af0000 - 0000000077b02000: C:\WINDOWS\system32\MSASN1.dll
(0000000077b10000 - 0000000077b32000: C:\WINDOWS\system32\appHelp.dll
(0000000077bd0000 - 0000000077bd8000: C:\WINDOWS\system32\VERSION.DLL
(0000000077be0000 - 0000000077c38000: C:\WINDOWS\system32\msvcrt.dll
(0000000077d10000 - 0000000077da0000: C:\WINDOWS\system32\USER32.dll
(0000000077da0000 - 0000000077e4a000: C:\WINDOWS\system32\ADVAPI32.dll
(0000000077e50000 - 0000000077ee1000: C:\WINDOWS\system32\RPCRT4.dll
(0000000077ef0000 - 0000000077f36000: C:\WINDOWS\system32\GDI32.dll
(0000000077f40000 - 0000000077fb6000: C:\WINDOWS\system32\SHLWAPI.dll
(0000000077fc0000 - 0000000077fd1000: C:\WINDOWS\system32\Secur32.dll
(000000007c800000 - 000000007c906000: C:\WINDOWS\system32\kernel32.dll
(000000007c910000 - 000000007c9c7000: C:\WINDOWS\system32\ntdll.dll
(000000007c9d0000 - 000000007d1ee000: C:\WINDOWS\system32\SHELL32.dll
(000000007d4b0000 - 000000007d792000: C:\WINDOWS\system32\mshtml.dll

*----> Statusabbild für Threadkennung 0x304 <----*

eax=0012fc80 ebx=0014a870 ecx=00000000 edx=7ffb001c esi=0012fcf0 edi=0014a870
eip=7c81eb33 esp=0012fc7c ebp=0012fcd0 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202

*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\kernel32.dll -
Funktion: kernel32!RaiseException
7c81eb1c c9 leave
7c81eb1d 894dc0 mov [ebp-0x40],ecx
7c81eb20 7407 jz kernel32!RaiseException+0x48 (7c81eb29)
7c81eb22 57 push edi
7c81eb23 8d7dc4 lea edi,[ebp-0x3c]
7c81eb26 f3a5 rep movsd
7c81eb28 5f pop edi
7c81eb29 8d45b0 lea eax,[ebp-0x50]
7c81eb2c 50 push eax
7c81eb2d ff150415807c call dword ptr [kernel32+0x1504 (7c801504)]
FEHLER ->7c81eb33 5e pop esi
7c81eb34 c9 leave
7c81eb35 c21000 ret 0x10
7c81eb38 85ff test edi,edi
7c81eb3a 0f8ee6d0feff jle kernel32!IsBadCodePtr+0xcf (7c80bc26)
7c81eb40 8b55fc mov edx,[ebp-0x4]
7c81eb43 89550c mov [ebp+0xc],edx
7c81eb46 0fb716 movzx edx,word ptr [esi]
7c81eb49 8b7df8 mov edi,[ebp-0x8]
7c81eb4c 8a143a mov dl,[edx+edi]
7c81eb4f 8811 mov [ecx],dl

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\MSVBVM60.DLL -
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0012fcd0 733b4e56 c000008f 00000001 00000002 kernel32!RaiseException+0x52
0012fcf0 733b4e0b 0014a870 800a9c68 0012fd74 MSVBVM60!_vbaHresultCheckObj+0x275
0014a7f8 00000000 00000000 00000000 00000001 MSVBVM60!_vbaHresultCheckObj+0x22a

*----> Raw Stack Dump <----*
000000000012fc7c 70 a8 14 00 8f 00 00 c0 - 01 00 00 00 00 00 00 00 p...............
000000000012fc8c 33 eb 81 7c 02 00 00 00 - fe ca ad de fe ca ad de 3..|............
000000000012fc9c 13 00 00 00 2a 9e 80 7c - fc 9b 19 00 1c 00 fb 7f ....*..|........
000000000012fcac 9f 49 40 00 8c 49 40 00 - 13 00 00 00 a5 48 0f 77 .I@..I@......H.w
000000000012fcbc 02 00 00 00 12 00 00 00 - 00 10 00 00 74 a8 14 00 ............t...
000000000012fccc 91 57 3b 73 f0 fc 12 00 - 56 4e 3b 73 8f 00 00 c0 .W;s....VN;s....
000000000012fcdc 01 00 00 00 02 00 00 00 - e8 fc 12 00 fe ca ad de ................
000000000012fcec fe ca ad de f8 a7 14 00 - 0b 4e 3b 73 70 a8 14 00 .........N;sp...
000000000012fcfc 68 9c 0a 80 74 fd 12 00 - 00 00 00 00 cf 56 3b 73 h...t........V;s
000000000012fd0c 70 a8 14 00 00 00 00 00 - b0 12 15 00 ec 5c 3d 73 p............\=s
000000000012fd1c 68 9c 00 00 33 8d 41 00 - 68 9c 0a 80 b0 12 15 00 h...3.A.h.......
000000000012fd2c 40 50 40 00 f8 06 00 00 - dc fd 12 00 b0 8c 41 00 @P@...........A.
000000000012fd3c 00 00 00 00 2c fd 12 00 - a9 09 6b 74 a0 fd 12 00 ....,.....kt....
000000000012fd4c 48 e5 6d 74 78 0e 6b 74 - 00 00 00 00 00 00 00 00 H.mtx.kt........
000000000012fd5c 1a ed d1 77 00 00 00 00 - f8 fd 12 00 16 19 40 00 ...w..........@.
000000000012fd6c 34 fd 12 00 f8 18 40 00 - a0 fd 12 00 09 87 d1 77 4.....@........w
000000000012fd7c fa 00 02 00 05 02 00 00 - 00 00 00 00 68 00 3e 01 ............h.>.
000000000012fd8c b0 8c 41 00 cd ab ba dc - 00 00 00 00 dc fd 12 00 ..A.............
000000000012fd9c b0 8c 41 00 08 fe 12 00 - eb 87 d1 77 b0 8c 41 00 ..A........w..A.
000000000012fdac fa 00 02 00 05 02 00 00 - 00 00 00 00 68 00 3e 01 ............h.>.

*----> Statusabbild für Threadkennung 0x6c8 <----*

eax=77dc9981 ebx=01fbfed0 ecx=00000006 edx=00000000 esi=00000000 edi=7ffd7000
eip=7c91eb94 esp=01fbfea8 ebp=01fbff44 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\ntdll.dll -
Funktion: ntdll!KiFastSystemCallRet
7c91eb89 90 nop
7c91eb8a 90 nop
ntdll!KiFastSystemCall:
7c91eb8b 8bd4 mov edx,esp
7c91eb8d 0f34 sysenter
7c91eb8f 90 nop
7c91eb90 90 nop
7c91eb91 90 nop
7c91eb92 90 nop
7c91eb93 90 nop
ntdll!KiFastSystemCallRet:
7c91eb94 c3 ret
7c91eb95 8da42400000000 lea esp,[esp]
7c91eb9c 8d642400 lea esp,[esp]
7c91eba0 90 nop
7c91eba1 90 nop
7c91eba2 90 nop
7c91eba3 90 nop
7c91eba4 90 nop
ntdll!KiIntSystemCall:
7c91eba5 8d542408 lea edx,[esp+0x8]
7c91eba9 cd2e int 2e

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\ADVAPI32.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
01fbff44 77dc9b26 00000002 01fbff6c 00000000 ntdll!KiFastSystemCallRet
01fbffb4 7c80b50b 00000000 7c9240bb 00000000 ADVAPI32!RegDeleteKeyW+0x2a2
01fbffec 00000000 77dc9981 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
0000000001fbfea8 ab e9 91 7c f2 94 80 7c - 02 00 00 00 d0 fe fb 01 ...|...|........
0000000001fbfeb8 01 00 00 00 01 00 00 00 - 04 ff fb 01 b0 30 93 01 .............0..
0000000001fbfec8 40 65 e1 77 00 10 00 00 - b0 02 00 00 bc 02 00 00 @e.w............
0000000001fbfed8 c0 fe fb 01 68 ec 5b f7 - dc ff fb 01 f3 99 83 7c ....h.[........|
0000000001fbfee8 c8 0c 81 7c 00 10 00 00 - 14 00 00 00 01 00 00 00 ...|............
0000000001fbfef8 00 00 00 00 00 00 00 00 - 10 00 00 00 00 a2 2f 4d ............../M
0000000001fbff08 ff ff ff ff 00 10 00 00 - 00 70 fd 7f 00 d0 fd 7f .........p......
0000000001fbff18 dc ff fb 01 04 ff fb 01 - d0 fe fb 01 06 00 00 00 ................
0000000001fbff28 02 00 00 00 c4 fe fb 01 - 06 00 00 00 dc ff fb 01 ................
0000000001fbff38 f3 99 83 7c 90 95 80 7c - 00 00 00 00 b4 ff fb 01 ...|...|........
0000000001fbff48 26 9b dc 77 02 00 00 00 - 6c ff fb 01 00 00 00 00 &..w....l.......
0000000001fbff58 e0 93 04 00 01 00 00 00 - bb 40 92 7c 00 00 00 00 .........@.|....
0000000001fbff68 00 00 00 00 b0 02 00 00 - bc 02 00 00 00 10 00 00 ................
0000000001fbff78 b0 30 93 01 00 00 00 00 - 00 10 00 00 b8 40 93 01 .0...........@..
0000000001fbff88 a0 66 e1 77 20 00 00 00 - 80 66 e1 77 00 10 00 00 .f.w ....f.w....
0000000001fbff98 00 00 00 00 a0 66 e1 77 - b0 30 93 01 80 66 e1 77 .....f.w.0...f.w
0000000001fbffa8 e5 03 00 00 00 10 00 00 - b8 40 93 01 ec ff fb 01 .........@......
0000000001fbffb8 0b b5 80 7c 00 00 00 00 - bb 40 92 7c 00 00 00 00 ...|.....@.|....
0000000001fbffc8 00 00 00 00 00 d0 fd 7f - 00 06 fc 81 c0 ff fb 01 ................
0000000001fbffd8 d0 01 be 81 ff ff ff ff - f3 99 83 7c 18 b5 80 7c ...........|...|

*----> Statusabbild für Threadkennung 0x6bc <----*

eax=77e56bf0 ebx=00000000 ecx=00000009 edx=7c920732 esi=0017ef40 edi=00000100
eip=7c91eb94 esp=020bfe1c ebp=020bff80 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

Funktion: ntdll!KiFastSystemCallRet
7c91eb89 90 nop
7c91eb8a 90 nop
ntdll!KiFastSystemCall:
7c91eb8b 8bd4 mov edx,esp
7c91eb8d 0f34 sysenter
7c91eb8f 90 nop
7c91eb90 90 nop
7c91eb91 90 nop
7c91eb92 90 nop
7c91eb93 90 nop
ntdll!KiFastSystemCallRet:
7c91eb94 c3 ret
7c91eb95 8da42400000000 lea esp,[esp]
7c91eb9c 8d642400 lea esp,[esp]
7c91eba0 90 nop
7c91eba1 90 nop
7c91eba2 90 nop
7c91eba3 90 nop
7c91eba4 90 nop
ntdll!KiIntSystemCall:
7c91eba5 8d542408 lea edx,[esp+0x8]
7c91eba9 cd2e int 2e

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\RPCRT4.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
020bff80 77e56c22 020bffa8 77e56a3b 0017ef40 ntdll!KiFastSystemCallRet
020bff88 77e56a3b 0017ef40 00000000 0012f138 RPCRT4!I_RpcBCacheFree+0x5ea
020bffa8 77e56c0a 00156e70 020bffec 7c80b50b RPCRT4!I_RpcBCacheFree+0x403
020bffb4 7c80b50b 00191a10 00000000 0012f138 RPCRT4!I_RpcBCacheFree+0x5d2
020bffec 00000000 77e56bf0 00191a10 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
00000000020bfe1c 99 e3 91 7c 03 67 e5 77 - d0 02 00 00 70 ff 0b 02 ...|.g.w....p...
00000000020bfe2c 00 00 00 00 90 2e 19 00 - 54 ff 0b 02 00 00 00 00 ........T.......
00000000020bfe3c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000020bfe4c 00 00 00 00 39 b7 54 80 - 00 00 00 00 46 02 00 00 ....9.T.....F...
00000000020bfe5c 4e 3f 4e 80 d8 77 dc 81 - 14 79 dc 81 e0 60 6e 80 N?N..w...y...`n.
00000000020bfe6c 6c ab 72 f7 fe 86 28 f8 - f4 78 dc 81 46 02 00 00 l.r...(..x..F...
00000000020bfe7c 08 87 28 f8 03 01 00 00 - 98 db d7 81 cc ab 72 f7 ..(...........r.
00000000020bfe8c 88 ab 72 f7 cf 3e 39 f8 - 00 00 00 00 f0 69 d6 81 ..r..>9......i..
00000000020bfe9c d4 ab 72 f7 98 db d7 81 - 98 db d7 81 a8 ab 72 f7 ..r...........r.
00000000020bfeac a3 3e 39 f8 00 00 00 00 - 98 db d7 81 b8 5d be 81 .>9..........]..
00000000020bfebc fc ab 72 f7 46 02 00 00 - 39 b7 54 80 e0 77 dc 81 ..r.F...9.T..w..
00000000020bfecc e0 ac 72 f7 d8 77 dc 81 - f0 69 d6 81 d4 ab 72 f7 ..r..w...i....r.
00000000020bfedc 00 ab 72 f7 e4 b3 37 f8 - b0 97 f7 81 00 77 dc 81 ..r...7......w..
00000000020bfeec 40 97 f7 81 40 97 f7 81 - e8 ab 72 f7 cc ad 72 f7 @...@.....r...r.
00000000020bfefc 46 02 00 00 e0 bd 4d 80 - 24 ac 72 f7 a0 48 e7 81 F.....M.$.r..H..
00000000020bff0c 20 f1 df ff cc fc c2 81 - 20 ac 72 f7 46 02 00 00 ....... .r.F...
00000000020bff1c 6a c8 4d 80 9c fc c2 81 - 30 fb c2 81 64 fb c2 81 j.M.....0...d...
00000000020bff2c e0 77 dc 81 80 ff 0b 02 - 99 66 e5 77 4c ff 0b 02 .w.......f.wL...
00000000020bff3c a9 66 e5 77 ed 10 91 7c - f8 01 18 00 10 1a 19 00 .f.w...|........
00000000020bff4c 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff ../M.....]......

*----> Statusabbild für Threadkennung 0x4b0 <----*

eax=774c319a ebx=00007530 ecx=7ffd7000 edx=00000000 esi=00000000 edi=021bff50
eip=7c91eb94 esp=021bff20 ebp=021bff78 iopl=0 nv up ei pl nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000206

Funktion: ntdll!KiFastSystemCallRet
7c91eb89 90 nop
7c91eb8a 90 nop
ntdll!KiFastSystemCall:
7c91eb8b 8bd4 mov edx,esp
7c91eb8d 0f34 sysenter
7c91eb8f 90 nop
7c91eb90 90 nop
7c91eb91 90 nop
7c91eb92 90 nop
7c91eb93 90 nop
ntdll!KiFastSystemCallRet:
7c91eb94 c3 ret
7c91eb95 8da42400000000 lea esp,[esp]
7c91eb9c 8d642400 lea esp,[esp]
7c91eba0 90 nop
7c91eba1 90 nop
7c91eba2 90 nop
7c91eba3 90 nop
7c91eba4 90 nop
ntdll!KiIntSystemCall:
7c91eba5 8d542408 lea edx,[esp+0x8]
7c91eba9 cd2e int 2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\ole32.dll -
ChildEBP RetAddr Args to Child
021bff78 7c802451 0000ea60 00000000 021bffb4 ntdll!KiFastSystemCallRet
021bff88 774c2fcb 0000ea60 0017d2a8 774c314d kernel32!Sleep+0xf
021bffb4 7c80b50b 0017d2a8 7c920945 7c92094e ole32!StringFromGUID2+0x2d1
021bffec 00000000 774c319a 0017d2a8 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
00000000021bff20 5c d8 91 7c ed 23 80 7c - 00 00 00 00 50 ff 1b 02 \..|.#.|....P...
00000000021bff30 50 25 80 7c f0 56 5d 77 - 30 75 00 00 14 00 00 00 P%.|.V]w0u......
00000000021bff40 01 00 00 00 00 00 00 00 - 00 00 00 00 10 00 00 00 ................
00000000021bff50 00 ba 3c dc ff ff ff ff - 08 4f 4b 77 50 ff 1b 02 ..<......OKwP...
00000000021bff60 30 ff 1b 02 10 55 14 00 - dc ff 1b 02 f3 99 83 7c 0....U.........|
00000000021bff70 58 24 80 7c 00 00 00 00 - 88 ff 1b 02 51 24 80 7c X$.|........Q$.|
00000000021bff80 60 ea 00 00 00 00 00 00 - b4 ff 1b 02 cb 2f 4c 77 `............/Lw
00000000021bff90 60 ea 00 00 a8 d2 17 00 - 4d 31 4c 77 00 00 00 00 `.......M1Lw....
00000000021bffa0 45 09 92 7c a8 d2 17 00 - 00 00 4b 77 b5 31 4c 77 E..|......Kw.1Lw
00000000021bffb0 4e 09 92 7c ec ff 1b 02 - 0b b5 80 7c a8 d2 17 00 N..|.......|....
00000000021bffc0 45 09 92 7c 4e 09 92 7c - a8 d2 17 00 00 b0 fd 7f E..|N..|........
00000000021bffd0 00 06 fc 81 c0 ff 1b 02 - d0 01 be 81 ff ff ff ff ................
00000000021bffe0 f3 99 83 7c 18 b5 80 7c - 00 00 00 00 00 00 00 00 ...|...|........
00000000021bfff0 00 00 00 00 9a 31 4c 77 - a8 d2 17 00 00 00 00 00 .....1Lw........
00000000021c0000 08 00 00 00 00 01 00 01 - ee ff ee ff 00 00 00 00 ................
00000000021c0010 00 00 85 00 00 30 03 00 - 00 00 1c 02 00 01 00 00 .....0..........
00000000021c0020 40 00 1c 02 00 00 2c 02 - be 00 00 00 18 00 00 00 @.....,.........
00000000021c0030 30 00 bd 02 00 00 00 00 - 08 a2 20 02 00 00 00 00 0......... .....
00000000021c0040 c0 02 08 00 9c 00 08 01 - f8 38 20 02 48 11 20 02 .........8 .H. .
00000000021c0050 20 06 00 00 00 00 00 00 - c8 07 00 00 03 00 00 00 ...............
Mfg, Steve

Olli 23. Sep 2005 12:05

Re: NT started nicht richtig
 
Lade dir doch mal von www.sysinternals.com das Tool AutoRuns runter. Dieses sollte es dir erlauben zu sehen, welche Shell-Extensions geladen werden. Wenn du dort eine findest, die verdächtig nach deinem Programm (XnView?!) aussieht, dann deaktiviere sie - aber Vorsicht: nicht wild irgendwas deaktivieren!!!


Alle Zeitangaben in WEZ +1. Es ist jetzt 11:56 Uhr.
Seite 2 von 2     12   

Powered by vBulletin® Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO © 2011, Crawlability, Inc.
Delphi-PRAXiS (c) 2002 - 2023 by Daniel R. Wolf, 2024 by Thomas Breitkreuz