Skip to content

Instantly share code, notes, and snippets.

@sarahhodne
Created May 12, 2009 10:59
Show Gist options
  • Save sarahhodne/110420 to your computer and use it in GitHub Desktop.
Save sarahhodne/110420 to your computer and use it in GitHub Desktop.
<?xml version="1.0" encoding="UTF-16"?>
<DATABASE>
<EXE NAME="SYSTEM INFO" FILTER="GRABMI_FILTER_SYSTEM">
<MATCHING_FILE NAME="advapi32.dll" SIZE="616960" CHECKSUM="0xD5DD4299" BIN_FILE_VERSION="5.1.2600.3520" BIN_PRODUCT_VERSION="5.1.2600.3520" PRODUCT_VERSION="5.1.2600.3520" FILE_DESCRIPTION="Advanced Windows 32 Base API" COMPANY_NAME="Microsoft Corporation" PRODUCT_NAME="Microsoft® Windows® Operating System" FILE_VERSION="5.1.2600.3520 (xpsp_sp2_gdr.090206-1233)" ORIGINAL_FILENAME="advapi32.dll" INTERNAL_NAME="advapi32.dll" LEGAL_COPYRIGHT="© Microsoft Corporation. All rights reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x9BE9E" LINKER_VERSION="0x50001" UPTO_BIN_FILE_VERSION="5.1.2600.3520" UPTO_BIN_PRODUCT_VERSION="5.1.2600.3520" LINK_DATE="02/09/2009 10:20:33" UPTO_LINK_DATE="02/09/2009 10:20:33" VER_LANGUAGE="English (United States) [0x409]" />
<MATCHING_FILE NAME="gdi32.dll" SIZE="283648" CHECKSUM="0xBDDF0091" BIN_FILE_VERSION="5.1.2600.3466" BIN_PRODUCT_VERSION="5.1.2600.3466" PRODUCT_VERSION="5.1.2600.3466" FILE_DESCRIPTION="GDI Client DLL" COMPANY_NAME="Microsoft Corporation" PRODUCT_NAME="Microsoft® Windows® Operating System" FILE_VERSION="5.1.2600.3466 (xpsp_sp2_gdr.081022-1254)" ORIGINAL_FILENAME="gdi32" INTERNAL_NAME="gdi32" LEGAL_COPYRIGHT="© Microsoft Corporation. All rights reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x4C8E2" LINKER_VERSION="0x50001" UPTO_BIN_FILE_VERSION="5.1.2600.3466" UPTO_BIN_PRODUCT_VERSION="5.1.2600.3466" LINK_DATE="10/23/2008 13:01:36" UPTO_LINK_DATE="10/23/2008 13:01:36" VER_LANGUAGE="English (United States) [0x409]" />
<MATCHING_FILE NAME="kernel32.dll" SIZE="986112" CHECKSUM="0x359DA0B2" BIN_FILE_VERSION="5.1.2600.3541" BIN_PRODUCT_VERSION="5.1.2600.3541" PRODUCT_VERSION="5.1.2600.3541" FILE_DESCRIPTION="Windows NT BASE API Client DLL" COMPANY_NAME="Microsoft Corporation" PRODUCT_NAME="Microsoft® Windows® Operating System" FILE_VERSION="5.1.2600.3541 (xpsp_sp2_gdr.090321-1320)" ORIGINAL_FILENAME="kernel32" INTERNAL_NAME="kernel32" LEGAL_COPYRIGHT="© Microsoft Corporation. All rights reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0xFEAFF" LINKER_VERSION="0x50001" UPTO_BIN_FILE_VERSION="5.1.2600.3541" UPTO_BIN_PRODUCT_VERSION="5.1.2600.3541" LINK_DATE="03/21/2009 14:18:57" UPTO_LINK_DATE="03/21/2009 14:18:57" VER_LANGUAGE="English (United States) [0x409]" />
<MATCHING_FILE NAME="ntdll.dll" SIZE="714752" CHECKSUM="0x19DE3F07" BIN_FILE_VERSION="5.1.2600.3520" BIN_PRODUCT_VERSION="5.1.2600.3520" PRODUCT_VERSION="5.1.2600.3520" FILE_DESCRIPTION="NT Layer DLL" COMPANY_NAME="Microsoft Corporation" PRODUCT_NAME="Microsoft® Windows® Operating System" FILE_VERSION="5.1.2600.3520 (xpsp_sp2_gdr.090206-1233)" ORIGINAL_FILENAME="ntdll.dll" INTERNAL_NAME="ntdll.dll" LEGAL_COPYRIGHT="© Microsoft Corporation. All rights reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0xBBA39" LINKER_VERSION="0x50001" UPTO_BIN_FILE_VERSION="5.1.2600.3520" UPTO_BIN_PRODUCT_VERSION="5.1.2600.3520" LINK_DATE="02/09/2009 10:20:32" UPTO_LINK_DATE="02/09/2009 10:20:32" VER_LANGUAGE="English (United States) [0x409]" />
<MATCHING_FILE NAME="ole32.dll" SIZE="1281536" CHECKSUM="0x8DD3141B" BIN_FILE_VERSION="5.1.2600.2180" BIN_PRODUCT_VERSION="5.1.2600.2180" PRODUCT_VERSION="5.1.2600.2180" FILE_DESCRIPTION="Microsoft OLE for Windows" COMPANY_NAME="Microsoft Corporation" PRODUCT_NAME="Microsoft® Windows® Operating System" FILE_VERSION="5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)" ORIGINAL_FILENAME="OLE32.DLL" INTERNAL_NAME="OLE32.DLL" LEGAL_COPYRIGHT="© Microsoft Corporation. All rights reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x1441FE" LINKER_VERSION="0x50001" UPTO_BIN_FILE_VERSION="5.1.2600.2180" UPTO_BIN_PRODUCT_VERSION="5.1.2600.2180" LINK_DATE="08/04/2004 07:57:38" UPTO_LINK_DATE="08/04/2004 07:57:38" VER_LANGUAGE="English (United States) [0x409]" />
<MATCHING_FILE NAME="oleaut32.dll" SIZE="553472" CHECKSUM="0x4155D7D" BIN_FILE_VERSION="5.1.2600.2180" BIN_PRODUCT_VERSION="5.1.2600.2180" PRODUCT_VERSION="5.1.2600.2180" COMPANY_NAME="Microsoft Corporation" FILE_VERSION="5.1.2600.2180" INTERNAL_NAME="OLEAUT32.DLL" LEGAL_COPYRIGHT="Copyright © Microsoft Corp. 1993-2001." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x96957" LINKER_VERSION="0x50001" UPTO_BIN_FILE_VERSION="5.1.2600.2180" UPTO_BIN_PRODUCT_VERSION="5.1.2600.2180" LINK_DATE="08/04/2004 07:57:39" UPTO_LINK_DATE="08/04/2004 07:57:39" VER_LANGUAGE="English (United States) [0x409]" />
<MATCHING_FILE NAME="shell32.dll" SIZE="8454656" CHECKSUM="0x27203A5" BIN_FILE_VERSION="6.0.2900.3402" BIN_PRODUCT_VERSION="6.0.2900.3402" PRODUCT_VERSION="6.00.2900.3402" FILE_DESCRIPTION="Windows Shell Common Dll" COMPANY_NAME="Microsoft Corporation" PRODUCT_NAME="Microsoft® Windows® Operating System" FILE_VERSION="6.00.2900.3402 (xpsp_sp2_gdr.080702-1233)" ORIGINAL_FILENAME="SHELL32.DLL" INTERNAL_NAME="SHELL32" LEGAL_COPYRIGHT="© Microsoft Corporation. All rights reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x81B86D" LINKER_VERSION="0x50001" UPTO_BIN_FILE_VERSION="6.0.2900.3402" UPTO_BIN_PRODUCT_VERSION="6.0.2900.3402" LINK_DATE="07/03/2008 13:16:56" UPTO_LINK_DATE="07/03/2008 13:16:56" VER_LANGUAGE="English (United States) [0x409]" />
<MATCHING_FILE NAME="user32.dll" SIZE="577024" CHECKSUM="0xF5C0D45B" BIN_FILE_VERSION="5.1.2600.2180" BIN_PRODUCT_VERSION="5.1.2600.2180" PRODUCT_VERSION="5.1.2600.2180" FILE_DESCRIPTION="Windows XP USER API Client DLL" COMPANY_NAME="Microsoft Corporation" PRODUCT_NAME="Microsoft® Windows® Operating System" FILE_VERSION="5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)" ORIGINAL_FILENAME="user32" INTERNAL_NAME="user32" LEGAL_COPYRIGHT="© Microsoft Corporation. All rights reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x9CA60" LINKER_VERSION="0x50001" UPTO_BIN_FILE_VERSION="5.1.2600.2180" UPTO_BIN_PRODUCT_VERSION="5.1.2600.2180" LINK_DATE="08/04/2004 07:56:40" UPTO_LINK_DATE="08/04/2004 07:56:40" VER_LANGUAGE="English (United States) [0x409]" />
<MATCHING_FILE NAME="wininet.dll" SIZE="659456" CHECKSUM="0xE2C47DD2" BIN_FILE_VERSION="6.0.2900.3527" BIN_PRODUCT_VERSION="6.0.2900.3527" PRODUCT_VERSION="6.00.2900.3527" FILE_DESCRIPTION="Internet Extensions for Win32" COMPANY_NAME="Microsoft Corporation" PRODUCT_NAME="Microsoft® Windows® Operating System" FILE_VERSION="6.00.2900.3527 (xpsp_sp2_gdr.090219-1253)" ORIGINAL_FILENAME="wininet.dll" INTERNAL_NAME="wininet.dll" LEGAL_COPYRIGHT="© Microsoft Corporation. All rights reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0xAF233" LINKER_VERSION="0x50001" UPTO_BIN_FILE_VERSION="6.0.2900.3527" UPTO_BIN_PRODUCT_VERSION="6.0.2900.3527" LINK_DATE="02/20/2009 08:30:23" UPTO_LINK_DATE="02/20/2009 08:30:23" VER_LANGUAGE="English (United States) [0x409]" />
<MATCHING_FILE NAME="winsock.dll" SIZE="2864" CHECKSUM="0x73AE8088" BIN_FILE_VERSION="3.10.0.103" BIN_PRODUCT_VERSION="3.10.0.103" PRODUCT_VERSION="3.10" FILE_DESCRIPTION="Windows Socket 16-Bit DLL" COMPANY_NAME="Microsoft Corporation" PRODUCT_NAME="Microsoft® Windows(TM) Operating System" FILE_VERSION="3.10" ORIGINAL_FILENAME="WINSOCK.DLL" INTERNAL_NAME="WINSOCK" LEGAL_COPYRIGHT="Copyright © Microsoft Corp. 1981-1996" VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x10001" VERFILETYPE="0x2" MODULE_TYPE="WIN16" S16BIT_DESCRIPTION="BSD Socket API for Windows" S16BIT_MODULE_NAME="WINSOCK" UPTO_BIN_FILE_VERSION="3.10.0.103" UPTO_BIN_PRODUCT_VERSION="3.10.0.103" VER_LANGUAGE="English (United States) [0x409]" />
</EXE>
<EXE NAME="USER32.dll" FILTER="GRABMI_FILTER_THISFILEONLY">
<MATCHING_FILE NAME="user32.dll" SIZE="577024" CHECKSUM="0xF5C0D45B" BIN_FILE_VERSION="5.1.2600.2180" BIN_PRODUCT_VERSION="5.1.2600.2180" PRODUCT_VERSION="5.1.2600.2180" FILE_DESCRIPTION="Windows XP USER API Client DLL" COMPANY_NAME="Microsoft Corporation" PRODUCT_NAME="Microsoft® Windows® Operating System" FILE_VERSION="5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)" ORIGINAL_FILENAME="user32" INTERNAL_NAME="user32" LEGAL_COPYRIGHT="© Microsoft Corporation. All rights reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x9CA60" LINKER_VERSION="0x50001" UPTO_BIN_FILE_VERSION="5.1.2600.2180" UPTO_BIN_PRODUCT_VERSION="5.1.2600.2180" LINK_DATE="08/04/2004 07:56:40" UPTO_LINK_DATE="08/04/2004 07:56:40" VER_LANGUAGE="English (United States) [0x409]" />
</EXE>
</DATABASE>
Error signature:
AppName: explorer.exe
ModVer: 5.1.2600.2180
AppVer: 6.0.2900.2180
Offset: 00009be9
ModName: user32.dll
Exception Information:
Code: 0xc0000005
Flags: 0x00000000
Record: 0x0000000000000000
Address: 0x0000000077d49be9
System Information:
Windows NT 5.1 Build: 2600
CPU Vendor Code: 756E6547 - 49656E69 - 6C65746E
CPU Version: 000006D8
CPU Feature Code: AFE9FBFF
CPU AMD Feature Code: 00B4E824
Module 1:
explorer.exe
Image Base: 0x01000000
Image Size: 0x00000000
Checksum: 0x00108809
Time Stamp: 0x41107ece
Version Information:
Signature: feef04bd
StrucVer: 00010000
FileVer: (6.0:2900.2180)
ProdVer: (6.0:2900.2180)
FlagMask: 0000003f
Flags: 00000000
OS: 00040004
FileType: 00000001
SubType: 00000000
FileDate: 00000000:00000000
Module 2:
ntdll.dll
Module 3:
kernel32.dll
Module 4:
msvcrt.dll
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Module 51:
MLANG.dll
Thread 1:
Thread ID: 0x00000be4
Context:
EDI: 0x00000000
EBX: 0x00000003
EIP: 0x7c90e514
ESI: 0x000dfb48
ECX: 0x00000001
EBP: 0x0007ff08
ESP: 0x0007fef0
EAX: 0x0007fc40
EDX: 0x000002f3
EFlags: 0x00000202
SegCs: 0x0000001b
SegSs: 0x00000023
Stack:
........ (CAN BE POSTED ON REQUEST) ........
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment