M
Martin.J
Guest
Hi.
We are having issues with IE11 and crashes because of faulty modules. The moduels in question are always different and a strange thing is that they do not exist on the affected machines and when we google them, we get zero results. Here are some examples of their names:
x_vowvefcy.dll, l_kugvbvgg.dll, t_npwhdkyo.dll, t_sylwjwrz.dll, s_uovezglz.dll, r_uazhanix.dll
The crashes happen when we use a web application that is based upon Silverlight.
Does anyone have any idea of what is happening here, based on the crash dumps below?
Has anyone seen this behavior before?
Application.evtx
Faulting application name: IEXPLORE.EXE, version: 11.0.17134.1, time stamp: 0x6639744d
Faulting module name: x_vowvefcy.dll, version: 0.0.0.0, time stamp: 0x3da51fd0
Exception code: 0xe0434352
Fault offset: 0x00111812
Faulting process id: 0x2f60
Faulting application start time: 0x01d4e49ba425dc1b
Faulting application path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
Faulting module path: C:\WINDOWS\System32\x_vowvefcy.dll
Report Id: 5e70b464-6659-4d0d-b08c-60080315a563
Faulting package full name:
Faulting package-relative application ID:
Report.wer
Version=1
EventType=APPCRASH
EventTime=131981675744718844
ReportType=2
Consent=1
UploadTime=131981675753671313
ReportStatus=268435464
ReportIdentifier=4a0e8a0c-0ab0-4f7c-b271-a20c9b852b7b
IntegratorReportIdentifier=5e70b464-6659-4d0d-b08c-60080315a563
Wow64Host=34404
Wow64Guest=332
NsAppName=IEXPLORE.EXE
OriginalFilename=IEXPLORE.EXE
AppSessionGuid=00002f60-0002-0015-1bdc-25a49be4d401
TargetAppId=W:0000f519feec486de87ed73cb92d3cac802400000000!00000b603b11d39ffaf773bf71df3fe854cd652c1a05!iexplore.exe
TargetAppVer=2024//05//07:00:22:37!ce6ac!iexplore.exe
BootId=4294967295
ServiceSplit=2004198290
TargetAsId=2611
IsFatal=1
Response.BucketId=1d1cf9767c45deee5f33c5eb6a702b5b
Response.BucketTable=1
Response.LegacyBucketId=2248358253881731931
Response.type=4
Response.CabId=2281034263510210651
Response.CabGuid=4e764e0f-5592-49d8-8fa7-dc93c505585b
Sig[0].Name=Application Name
Sig[0].Value=IEXPLORE.EXE
Sig[1].Name=Application Version
Sig[1].Value=11.0.17134.1
Sig[2].Name=Application Timestamp
Sig[2].Value=6639744d
Sig[3].Name=Fault Module Name
Sig[3].Value=x_vowvefcy.dll
Sig[4].Name=Fault Module Version
Sig[4].Value=0.0.0.0
Sig[5].Name=Fault Module Timestamp
Sig[5].Value=3da51fd0
Sig[6].Name=Exception Code
Sig[6].Value=e0434352
Sig[7].Name=Exception Offset
Sig[7].Value=00111812
DynamicSig[1].Name=OS-version
DynamicSig[1].Value=10.0.17134.2.0.0.256.4
DynamicSig[2].Name=Locale ID
DynamicSig[2].Value=1053
DynamicSig[22].Name=Additional Information 1
DynamicSig[22].Value=0a79
DynamicSig[23].Name=Additional Information 2
DynamicSig[23].Value=0a79e927101e4291be6dfd93905f3f25
DynamicSig[24].Name=Additional Information 3
DynamicSig[24].Value=ca45
DynamicSig[25].Name=Additional Information 4
DynamicSig[25].Value=ca456bb1b53bd153907850bc16fc6260
UI[2]=C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
LoadedModule[0]=C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
LoadedModule[1]=C:\WINDOWS\SYSTEM32\adejk.dll
LoadedModule[2]=C:\WINDOWS\SYSTEM32\ntdll.dll
LoadedModule[3]=C:\WINDOWS\System32\kernel32.dll
LoadedModule[4]=C:\WINDOWS\System32\e_oxycdd.dll
LoadedModule[5]=C:\WINDOWS\System32\kernelbase.dll
LoadedModule[6]=C:\WINDOWS\System32\x_vowvefcy.dll
LoadedModule[7]=C:\WINDOWS\SYSTEM32\apphelp.dll
LoadedModule[8]=C:\WINDOWS\System32\USER32.dll
LoadedModule[9]=C:\WINDOWS\System32\win32u.dll
LoadedModule[10]=C:\WINDOWS\System32\GDI32.dll
LoadedModule[11]=C:\WINDOWS\System32\gdi32full.dll
LoadedModule[12]=C:\WINDOWS\System32\msvcp_win.dll
LoadedModule[13]=C:\WINDOWS\System32\ucrtbase.dll
LoadedModule[14]=C:\WINDOWS\System32\msvcrt.dll
LoadedModule[15]=C:\WINDOWS\System32\ADVAPI32.dll
LoadedModule[16]=C:\WINDOWS\System32\sechost.dll
LoadedModule[17]=C:\WINDOWS\System32\RPCRT4.dll
LoadedModule[18]=C:\WINDOWS\System32\SspiCli.dll
LoadedModule[19]=C:\WINDOWS\System32\CRYPTBASE.dll
LoadedModule[20]=C:\WINDOWS\System32\bcryptPrimitives.dll
LoadedModule[21]=C:\WINDOWS\System32\combase.dll
LoadedModule[22]=C:\WINDOWS\SYSTEM32\iertutil.dll
LoadedModule[23]=C:\WINDOWS\System32\shcore.dll
LoadedModule[24]=C:\WINDOWS\System32\IMM32.DLL
LoadedModule[25]=C:\WINDOWS\System32\SHELL32.dll
LoadedModule[26]=C:\WINDOWS\System32\cfgmgr32.dll
LoadedModule[27]=C:\WINDOWS\System32\windows.storage.dll
LoadedModule[28]=C:\WINDOWS\System32\shlwapi.dll
LoadedModule[29]=C:\WINDOWS\System32\kernel.appcore.dll
LoadedModule[30]=C:\WINDOWS\System32\profapi.dll
LoadedModule[31]=C:\WINDOWS\System32\powrprof.dll
LoadedModule[32]=C:\WINDOWS\System32\FLTLIB.DLL
LoadedModule[33]=C:\WINDOWS\System32\ole32.dll
LoadedModule[34]=C:\WINDOWS\SYSTEM32\dbghelp.dll
LoadedModule[35]=C:\WINDOWS\SYSTEM32\VERSION.dll
LoadedModule[36]=C:\WINDOWS\SYSTEM32\ntmarta.dll
LoadedModule[37]=C:\WINDOWS\SYSTEM32\msIso.dll
LoadedModule[38]=C:\WINDOWS\SYSTEM32\IEFRAME.dll
LoadedModule[39]=C:\WINDOWS\System32\OLEAUT32.dll
LoadedModule[40]=C:\WINDOWS\SYSTEM32\NETAPI32.dll
LoadedModule[41]=C:\WINDOWS\SYSTEM32\WINHTTP.dll
LoadedModule[42]=C:\WINDOWS\SYSTEM32\WKSCLI.DLL
LoadedModule[43]=C:\WINDOWS\SYSTEM32\bcrypt.dll
LoadedModule[44]=C:\WINDOWS\SYSTEM32\NETUTILS.DLL
LoadedModule[45]=C:\WINDOWS\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17134.523_none_42edd4b044e3535c\comctl32.dll
LoadedModule[46]=C:\Program Files (x86)\Internet Explorer\IEShims.dll
LoadedModule[47]=C:\WINDOWS\System32\comdlg32.dll
LoadedModule[48]=C:\WINDOWS\system32\uxtheme.dll
LoadedModule[49]=C:\WINDOWS\SYSTEM32\MSHTML.dll
LoadedModule[50]=C:\WINDOWS\SYSTEM32\urlmon.dll
LoadedModule[51]=C:\WINDOWS\System32\clbcatq.dll
LoadedModule[52]=C:\WINDOWS\SYSTEM32\WININET.dll
LoadedModule[53]=C:\WINDOWS\SYSTEM32\TOKENBINDING.dll
LoadedModule[54]=C:\WINDOWS\System32\WS2_32.dll
LoadedModule[55]=C:\WINDOWS\SYSTEM32\ondemandconnroutehelper.dll
LoadedModule[56]=C:\WINDOWS\SYSTEM32\IPHLPAPI.DLL
LoadedModule[57]=C:\WINDOWS\system32\mswsock.dll
LoadedModule[58]=C:\WINDOWS\SYSTEM32\WINNSI.DLL
LoadedModule[59]=C:\WINDOWS\System32\NSI.dll
LoadedModule[60]=C:\Windows\System32\ieproxy.dll
LoadedModule[61]=C:\WINDOWS\system32\dwmapi.dll
LoadedModule[62]=C:\WINDOWS\System32\MSCTF.dll
LoadedModule[63]=C:\WINDOWS\SYSTEM32\d2d1.dll
LoadedModule[64]=C:\WINDOWS\SYSTEM32\ieapfltr.dll
LoadedModule[65]=C:\WINDOWS\SYSTEM32\CRYPTSP.dll
LoadedModule[66]=C:\WINDOWS\SYSTEM32\DWrite.dll
LoadedModule[67]=C:\WINDOWS\SYSTEM32\dxgi.dll
LoadedModule[68]=C:\WINDOWS\SYSTEM32\d3d11.dll
LoadedModule[69]=C:\WINDOWS\SYSTEM32\igd10iumd32.dll
LoadedModule[70]=C:\WINDOWS\SYSTEM32\ncrypt.dll
LoadedModule[71]=C:\WINDOWS\SYSTEM32\NTASN1.dll
LoadedModule[72]=C:\WINDOWS\SYSTEM32\igc32.dll
LoadedModule[73]=C:\WINDOWS\system32\dataexchange.dll
LoadedModule[74]=C:\WINDOWS\system32\dcomp.dll
LoadedModule[75]=C:\WINDOWS\system32\twinapi.appcore.dll
LoadedModule[76]=C:\WINDOWS\system32\RMCLIENT.dll
LoadedModule[77]=C:\WINDOWS\SYSTEM32\dhcpcsvc6.DLL
LoadedModule[78]=C:\WINDOWS\SYSTEM32\dhcpcsvc.DLL
LoadedModule[79]=C:\WINDOWS\SYSTEM32\srpapi.dll
LoadedModule[80]=C:\WINDOWS\System32\CRYPT32.dll
LoadedModule[81]=C:\WINDOWS\System32\MSASN1.dll
LoadedModule[82]=C:\WINDOWS\SYSTEM32\ninput.dll
LoadedModule[83]=C:\WINDOWS\SYSTEM32\WLDP.DLL
LoadedModule[84]=C:\WINDOWS\System32\WINTRUST.dll
LoadedModule[85]=C:\WINDOWS\system32\rsaenh.dll
LoadedModule[86]=C:\WINDOWS\SYSTEM32\DNSAPI.dll
LoadedModule[87]=C:\WINDOWS\SYSTEM32\IEUI.dll
LoadedModule[88]=C:\WINDOWS\System32\fwpuclnt.dll
LoadedModule[89]=C:\Windows\System32\rasadhlp.dll
LoadedModule[90]=C:\Windows\System32\OneCoreCommonProxyStub.dll
LoadedModule[91]=C:\WINDOWS\System32\schannel.dll
LoadedModule[92]=C:\WINDOWS\System32\TextInputFramework.dll
LoadedModule[93]=C:\WINDOWS\System32\CoreUIComponents.dll
LoadedModule[94]=C:\WINDOWS\System32\CoreMessaging.dll
LoadedModule[95]=C:\WINDOWS\SYSTEM32\wintypes.dll
LoadedModule[96]=C:\WINDOWS\SYSTEM32\mskeyprotect.dll
LoadedModule[97]=C:\WINDOWS\system32\ncryptsslp.dll
LoadedModule[98]=C:\WINDOWS\SYSTEM32\DPAPI.DLL
LoadedModule[99]=C:\WINDOWS\system32\Oleacc.dll
LoadedModule[100]=C:\Windows\System32\cryptnet.dll
LoadedModule[101]=C:\Windows\System32\jscript9.dll
LoadedModule[102]=C:\WINDOWS\system32\msimtf.dll
LoadedModule[103]=C:\WINDOWS\system32\directmanipulation.dll
LoadedModule[104]=C:\WINDOWS\SYSTEM32\sxs.dll
LoadedModule[105]=C:\Windows\System32\vaultcli.dll
LoadedModule[106]=C:\WINDOWS\SYSTEM32\Secur32.dll
LoadedModule[107]=C:\WINDOWS\SYSTEM32\MLANG.dll
LoadedModule[108]=C:\WINDOWS\SYSTEM32\PROPSYS.dll
LoadedModule[109]=C:\WINDOWS\System32\coml2.dll
LoadedModule[110]=C:\WINDOWS\SYSTEM32\XmlLite.dll
LoadedModule[111]=c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll
LoadedModule[112]=C:\WINDOWS\System32\PSAPI.DLL
LoadedModule[113]=c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\agcore.dll
LoadedModule[114]=C:\WINDOWS\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.17134.523_none_40fda94a45138881\COMCTL32.dll
LoadedModule[115]=C:\WINDOWS\SYSTEM32\WINMM.dll
LoadedModule[116]=C:\WINDOWS\SYSTEM32\MSIMG32.dll
LoadedModule[117]=C:\WINDOWS\SYSTEM32\WINMMBASE.dll
LoadedModule[118]=C:\WINDOWS\SYSTEM32\SAMCLI.DLL
LoadedModule[119]=C:\WINDOWS\system32\windowscodecs.dll
LoadedModule[120]=c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\coreclr.dll
LoadedModule[121]=c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\sv\mscorrc.dll
LoadedModule[122]=C:\WINDOWS\SYSTEM32\windows.globalization.dll
LoadedModule[123]=C:\WINDOWS\SYSTEM32\Bcp47Langs.dll
LoadedModule[124]=C:\WINDOWS\SYSTEM32\bcp47mrm.dll
LoadedModule[125]=C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroPDF.dll
LoadedModule[126]=C:\WINDOWS\SYSTEM32\Cabinet.dll
LoadedModule[127]=C:\WINDOWS\SYSTEM32\globinputhost.dll
LoadedModule[128]=C:\WINDOWS\System32\UIAnimation.dll
LoadedModule[129]=C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOXMLMF.DLL
LoadedModule[130]=C:\WINDOWS\SYSTEM32\VCRUNTIME140.dll
LoadedModule[131]=c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrlUI.dll
LoadedModule[132]=C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroPDFImpl.dll
LoadedModule[133]=C:\WINDOWS\SYSTEM32\MPR.dll
LoadedModule[134]=C:\WINDOWS\SYSTEM32\MSVCP140.dll
LoadedModule[135]=C:\WINDOWS\SYSTEM32\atlthunk.dll
State[0].Key=Transport.DoneStage1
State[0].Value=1
OsInfo[0].Key=vermaj
OsInfo[0].Value=10
OsInfo[1].Key=vermin
OsInfo[1].Value=0
OsInfo[2].Key=verbld
OsInfo[2].Value=17134
OsInfo[3].Key=ubr
OsInfo[3].Value=523
OsInfo[4].Key=versp
OsInfo[4].Value=0
OsInfo[5].Key=arch
OsInfo[5].Value=9
OsInfo[6].Key=lcid
OsInfo[6].Value=1053
OsInfo[7].Key=geoid
OsInfo[7].Value=221
OsInfo[8].Key=sku
OsInfo[8].Value=4
OsInfo[9].Key=domain
OsInfo[9].Value=1
OsInfo[10].Key=prodsuite
OsInfo[10].Value=256
OsInfo[11].Key=ntprodtype
OsInfo[11].Value=1
OsInfo[12].Key=platid
OsInfo[12].Value=10
OsInfo[13].Key=sr
OsInfo[13].Value=0
OsInfo[14].Key=tmsi
OsInfo[14].Value=83651
OsInfo[15].Key=osinsty
OsInfo[15].Value=2
OsInfo[16].Key=iever
OsInfo[16].Value=11.523.17134.0-11.0.105
OsInfo[17].Key=portos
OsInfo[17].Value=0
OsInfo[18].Key=ram
OsInfo[18].Value=8079
OsInfo[19].Key=svolsz
OsInfo[19].Value=237
OsInfo[20].Key=wimbt
OsInfo[20].Value=0
OsInfo[21].Key=blddt
OsInfo[21].Value=180410
OsInfo[22].Key=bldtm
OsInfo[22].Value=1804
OsInfo[23].Key=bldbrch
OsInfo[23].Value=rs4_release
OsInfo[24].Key=bldchk
OsInfo[24].Value=0
OsInfo[25].Key=wpvermaj
OsInfo[25].Value=0
OsInfo[26].Key=wpvermin
OsInfo[26].Value=0
OsInfo[27].Key=wpbuildmaj
OsInfo[27].Value=0
OsInfo[28].Key=wpbuildmin
OsInfo[28].Value=0
OsInfo[29].Key=osver
OsInfo[29].Value=10.0.17134.523.amd64fre.rs4_release.180410-1804
OsInfo[30].Key=buildflightid
OsInfo[31].Key=edition
OsInfo[31].Value=Enterprise
OsInfo[32].Key=ring
OsInfo[33].Key=expid
OsInfo[34].Key=containerid
OsInfo[35].Key=containertype
OsInfo[36].Key=edu
OsInfo[36].Value=0
File[0].CabName=minidump.mdmp
File[0].Path=WER1A1B.tmp.mdmp
File[0].Flags=539820035
File[0].Type=2
File[0].Original.Path=\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER1A1B.tmp.mdmp
File[1].CabName=WERInternalMetadata.xml
File[1].Path=WER1D0A.tmp.WERInternalMetadata.xml
File[1].Flags=851971
File[1].Type=5
File[1].Original.Path=\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER1D0A.tmp.WERInternalMetadata.xml
File[2].CabName=WERInternalRequest.xml
File[2].Path=WER1D3A.tmp.xml
File[2].Flags=851971
File[2].Type=5
File[2].Original.Path=\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER1D3A.tmp.xml
File[3].CabName=memory.csv
File[3].Path=WER1D48.tmp.csv
File[3].Flags=851971
File[3].Type=5
File[3].Original.Path=\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER1D48.tmp.csv
File[4].CabName=sysinfo.txt
File[4].Path=WER1D78.tmp.txt
File[4].Flags=851971
File[4].Type=5
File[4].Original.Path=\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER1D78.tmp.txt
File[5].CabName=AppCompat.txt
File[5].Path=WER2152.tmp.appcompat.txt
File[5].Flags=17629187
File[5].Type=5
File[5].Original.Path=\\?\C:\Users\xxxxx\AppData\Local\Temp\WER2152.tmp.appcompat.txt
File[6].CabName=WERDataCollectionStatus.txt
File[6].Path=WER21A1.tmp.WERDataCollectionStatus.txt
File[6].Flags=851971
File[6].Type=5
File[6].Original.Path=\\?\C:\Users\xxxxx\AppData\Local\Temp\WER21A1.tmp.WERDataCollectionStatus.txt
File[7].CabName=Report.zip
File[7].Path=Report.zip
File[7].Flags=65536
File[7].Type=11
File[7].Original.Path=\\?\C:\WINDOWS\system32\Report.zip
FriendlyEventName=Stopped working
ConsentKey=APPCRASH
AppName=Internet Explorer
AppPath=C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
NsPartner=windows
NsGroup=windows8
ApplicationIdentity=3BD0E57EF652AF04909B6A81774D1117
MetadataHash=283408690
Continue reading...
We are having issues with IE11 and crashes because of faulty modules. The moduels in question are always different and a strange thing is that they do not exist on the affected machines and when we google them, we get zero results. Here are some examples of their names:
x_vowvefcy.dll, l_kugvbvgg.dll, t_npwhdkyo.dll, t_sylwjwrz.dll, s_uovezglz.dll, r_uazhanix.dll
The crashes happen when we use a web application that is based upon Silverlight.
Does anyone have any idea of what is happening here, based on the crash dumps below?
Has anyone seen this behavior before?
Application.evtx
Faulting application name: IEXPLORE.EXE, version: 11.0.17134.1, time stamp: 0x6639744d
Faulting module name: x_vowvefcy.dll, version: 0.0.0.0, time stamp: 0x3da51fd0
Exception code: 0xe0434352
Fault offset: 0x00111812
Faulting process id: 0x2f60
Faulting application start time: 0x01d4e49ba425dc1b
Faulting application path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
Faulting module path: C:\WINDOWS\System32\x_vowvefcy.dll
Report Id: 5e70b464-6659-4d0d-b08c-60080315a563
Faulting package full name:
Faulting package-relative application ID:
Report.wer
Version=1
EventType=APPCRASH
EventTime=131981675744718844
ReportType=2
Consent=1
UploadTime=131981675753671313
ReportStatus=268435464
ReportIdentifier=4a0e8a0c-0ab0-4f7c-b271-a20c9b852b7b
IntegratorReportIdentifier=5e70b464-6659-4d0d-b08c-60080315a563
Wow64Host=34404
Wow64Guest=332
NsAppName=IEXPLORE.EXE
OriginalFilename=IEXPLORE.EXE
AppSessionGuid=00002f60-0002-0015-1bdc-25a49be4d401
TargetAppId=W:0000f519feec486de87ed73cb92d3cac802400000000!00000b603b11d39ffaf773bf71df3fe854cd652c1a05!iexplore.exe
TargetAppVer=2024//05//07:00:22:37!ce6ac!iexplore.exe
BootId=4294967295
ServiceSplit=2004198290
TargetAsId=2611
IsFatal=1
Response.BucketId=1d1cf9767c45deee5f33c5eb6a702b5b
Response.BucketTable=1
Response.LegacyBucketId=2248358253881731931
Response.type=4
Response.CabId=2281034263510210651
Response.CabGuid=4e764e0f-5592-49d8-8fa7-dc93c505585b
Sig[0].Name=Application Name
Sig[0].Value=IEXPLORE.EXE
Sig[1].Name=Application Version
Sig[1].Value=11.0.17134.1
Sig[2].Name=Application Timestamp
Sig[2].Value=6639744d
Sig[3].Name=Fault Module Name
Sig[3].Value=x_vowvefcy.dll
Sig[4].Name=Fault Module Version
Sig[4].Value=0.0.0.0
Sig[5].Name=Fault Module Timestamp
Sig[5].Value=3da51fd0
Sig[6].Name=Exception Code
Sig[6].Value=e0434352
Sig[7].Name=Exception Offset
Sig[7].Value=00111812
DynamicSig[1].Name=OS-version
DynamicSig[1].Value=10.0.17134.2.0.0.256.4
DynamicSig[2].Name=Locale ID
DynamicSig[2].Value=1053
DynamicSig[22].Name=Additional Information 1
DynamicSig[22].Value=0a79
DynamicSig[23].Name=Additional Information 2
DynamicSig[23].Value=0a79e927101e4291be6dfd93905f3f25
DynamicSig[24].Name=Additional Information 3
DynamicSig[24].Value=ca45
DynamicSig[25].Name=Additional Information 4
DynamicSig[25].Value=ca456bb1b53bd153907850bc16fc6260
UI[2]=C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
LoadedModule[0]=C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
LoadedModule[1]=C:\WINDOWS\SYSTEM32\adejk.dll
LoadedModule[2]=C:\WINDOWS\SYSTEM32\ntdll.dll
LoadedModule[3]=C:\WINDOWS\System32\kernel32.dll
LoadedModule[4]=C:\WINDOWS\System32\e_oxycdd.dll
LoadedModule[5]=C:\WINDOWS\System32\kernelbase.dll
LoadedModule[6]=C:\WINDOWS\System32\x_vowvefcy.dll
LoadedModule[7]=C:\WINDOWS\SYSTEM32\apphelp.dll
LoadedModule[8]=C:\WINDOWS\System32\USER32.dll
LoadedModule[9]=C:\WINDOWS\System32\win32u.dll
LoadedModule[10]=C:\WINDOWS\System32\GDI32.dll
LoadedModule[11]=C:\WINDOWS\System32\gdi32full.dll
LoadedModule[12]=C:\WINDOWS\System32\msvcp_win.dll
LoadedModule[13]=C:\WINDOWS\System32\ucrtbase.dll
LoadedModule[14]=C:\WINDOWS\System32\msvcrt.dll
LoadedModule[15]=C:\WINDOWS\System32\ADVAPI32.dll
LoadedModule[16]=C:\WINDOWS\System32\sechost.dll
LoadedModule[17]=C:\WINDOWS\System32\RPCRT4.dll
LoadedModule[18]=C:\WINDOWS\System32\SspiCli.dll
LoadedModule[19]=C:\WINDOWS\System32\CRYPTBASE.dll
LoadedModule[20]=C:\WINDOWS\System32\bcryptPrimitives.dll
LoadedModule[21]=C:\WINDOWS\System32\combase.dll
LoadedModule[22]=C:\WINDOWS\SYSTEM32\iertutil.dll
LoadedModule[23]=C:\WINDOWS\System32\shcore.dll
LoadedModule[24]=C:\WINDOWS\System32\IMM32.DLL
LoadedModule[25]=C:\WINDOWS\System32\SHELL32.dll
LoadedModule[26]=C:\WINDOWS\System32\cfgmgr32.dll
LoadedModule[27]=C:\WINDOWS\System32\windows.storage.dll
LoadedModule[28]=C:\WINDOWS\System32\shlwapi.dll
LoadedModule[29]=C:\WINDOWS\System32\kernel.appcore.dll
LoadedModule[30]=C:\WINDOWS\System32\profapi.dll
LoadedModule[31]=C:\WINDOWS\System32\powrprof.dll
LoadedModule[32]=C:\WINDOWS\System32\FLTLIB.DLL
LoadedModule[33]=C:\WINDOWS\System32\ole32.dll
LoadedModule[34]=C:\WINDOWS\SYSTEM32\dbghelp.dll
LoadedModule[35]=C:\WINDOWS\SYSTEM32\VERSION.dll
LoadedModule[36]=C:\WINDOWS\SYSTEM32\ntmarta.dll
LoadedModule[37]=C:\WINDOWS\SYSTEM32\msIso.dll
LoadedModule[38]=C:\WINDOWS\SYSTEM32\IEFRAME.dll
LoadedModule[39]=C:\WINDOWS\System32\OLEAUT32.dll
LoadedModule[40]=C:\WINDOWS\SYSTEM32\NETAPI32.dll
LoadedModule[41]=C:\WINDOWS\SYSTEM32\WINHTTP.dll
LoadedModule[42]=C:\WINDOWS\SYSTEM32\WKSCLI.DLL
LoadedModule[43]=C:\WINDOWS\SYSTEM32\bcrypt.dll
LoadedModule[44]=C:\WINDOWS\SYSTEM32\NETUTILS.DLL
LoadedModule[45]=C:\WINDOWS\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17134.523_none_42edd4b044e3535c\comctl32.dll
LoadedModule[46]=C:\Program Files (x86)\Internet Explorer\IEShims.dll
LoadedModule[47]=C:\WINDOWS\System32\comdlg32.dll
LoadedModule[48]=C:\WINDOWS\system32\uxtheme.dll
LoadedModule[49]=C:\WINDOWS\SYSTEM32\MSHTML.dll
LoadedModule[50]=C:\WINDOWS\SYSTEM32\urlmon.dll
LoadedModule[51]=C:\WINDOWS\System32\clbcatq.dll
LoadedModule[52]=C:\WINDOWS\SYSTEM32\WININET.dll
LoadedModule[53]=C:\WINDOWS\SYSTEM32\TOKENBINDING.dll
LoadedModule[54]=C:\WINDOWS\System32\WS2_32.dll
LoadedModule[55]=C:\WINDOWS\SYSTEM32\ondemandconnroutehelper.dll
LoadedModule[56]=C:\WINDOWS\SYSTEM32\IPHLPAPI.DLL
LoadedModule[57]=C:\WINDOWS\system32\mswsock.dll
LoadedModule[58]=C:\WINDOWS\SYSTEM32\WINNSI.DLL
LoadedModule[59]=C:\WINDOWS\System32\NSI.dll
LoadedModule[60]=C:\Windows\System32\ieproxy.dll
LoadedModule[61]=C:\WINDOWS\system32\dwmapi.dll
LoadedModule[62]=C:\WINDOWS\System32\MSCTF.dll
LoadedModule[63]=C:\WINDOWS\SYSTEM32\d2d1.dll
LoadedModule[64]=C:\WINDOWS\SYSTEM32\ieapfltr.dll
LoadedModule[65]=C:\WINDOWS\SYSTEM32\CRYPTSP.dll
LoadedModule[66]=C:\WINDOWS\SYSTEM32\DWrite.dll
LoadedModule[67]=C:\WINDOWS\SYSTEM32\dxgi.dll
LoadedModule[68]=C:\WINDOWS\SYSTEM32\d3d11.dll
LoadedModule[69]=C:\WINDOWS\SYSTEM32\igd10iumd32.dll
LoadedModule[70]=C:\WINDOWS\SYSTEM32\ncrypt.dll
LoadedModule[71]=C:\WINDOWS\SYSTEM32\NTASN1.dll
LoadedModule[72]=C:\WINDOWS\SYSTEM32\igc32.dll
LoadedModule[73]=C:\WINDOWS\system32\dataexchange.dll
LoadedModule[74]=C:\WINDOWS\system32\dcomp.dll
LoadedModule[75]=C:\WINDOWS\system32\twinapi.appcore.dll
LoadedModule[76]=C:\WINDOWS\system32\RMCLIENT.dll
LoadedModule[77]=C:\WINDOWS\SYSTEM32\dhcpcsvc6.DLL
LoadedModule[78]=C:\WINDOWS\SYSTEM32\dhcpcsvc.DLL
LoadedModule[79]=C:\WINDOWS\SYSTEM32\srpapi.dll
LoadedModule[80]=C:\WINDOWS\System32\CRYPT32.dll
LoadedModule[81]=C:\WINDOWS\System32\MSASN1.dll
LoadedModule[82]=C:\WINDOWS\SYSTEM32\ninput.dll
LoadedModule[83]=C:\WINDOWS\SYSTEM32\WLDP.DLL
LoadedModule[84]=C:\WINDOWS\System32\WINTRUST.dll
LoadedModule[85]=C:\WINDOWS\system32\rsaenh.dll
LoadedModule[86]=C:\WINDOWS\SYSTEM32\DNSAPI.dll
LoadedModule[87]=C:\WINDOWS\SYSTEM32\IEUI.dll
LoadedModule[88]=C:\WINDOWS\System32\fwpuclnt.dll
LoadedModule[89]=C:\Windows\System32\rasadhlp.dll
LoadedModule[90]=C:\Windows\System32\OneCoreCommonProxyStub.dll
LoadedModule[91]=C:\WINDOWS\System32\schannel.dll
LoadedModule[92]=C:\WINDOWS\System32\TextInputFramework.dll
LoadedModule[93]=C:\WINDOWS\System32\CoreUIComponents.dll
LoadedModule[94]=C:\WINDOWS\System32\CoreMessaging.dll
LoadedModule[95]=C:\WINDOWS\SYSTEM32\wintypes.dll
LoadedModule[96]=C:\WINDOWS\SYSTEM32\mskeyprotect.dll
LoadedModule[97]=C:\WINDOWS\system32\ncryptsslp.dll
LoadedModule[98]=C:\WINDOWS\SYSTEM32\DPAPI.DLL
LoadedModule[99]=C:\WINDOWS\system32\Oleacc.dll
LoadedModule[100]=C:\Windows\System32\cryptnet.dll
LoadedModule[101]=C:\Windows\System32\jscript9.dll
LoadedModule[102]=C:\WINDOWS\system32\msimtf.dll
LoadedModule[103]=C:\WINDOWS\system32\directmanipulation.dll
LoadedModule[104]=C:\WINDOWS\SYSTEM32\sxs.dll
LoadedModule[105]=C:\Windows\System32\vaultcli.dll
LoadedModule[106]=C:\WINDOWS\SYSTEM32\Secur32.dll
LoadedModule[107]=C:\WINDOWS\SYSTEM32\MLANG.dll
LoadedModule[108]=C:\WINDOWS\SYSTEM32\PROPSYS.dll
LoadedModule[109]=C:\WINDOWS\System32\coml2.dll
LoadedModule[110]=C:\WINDOWS\SYSTEM32\XmlLite.dll
LoadedModule[111]=c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll
LoadedModule[112]=C:\WINDOWS\System32\PSAPI.DLL
LoadedModule[113]=c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\agcore.dll
LoadedModule[114]=C:\WINDOWS\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.17134.523_none_40fda94a45138881\COMCTL32.dll
LoadedModule[115]=C:\WINDOWS\SYSTEM32\WINMM.dll
LoadedModule[116]=C:\WINDOWS\SYSTEM32\MSIMG32.dll
LoadedModule[117]=C:\WINDOWS\SYSTEM32\WINMMBASE.dll
LoadedModule[118]=C:\WINDOWS\SYSTEM32\SAMCLI.DLL
LoadedModule[119]=C:\WINDOWS\system32\windowscodecs.dll
LoadedModule[120]=c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\coreclr.dll
LoadedModule[121]=c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\sv\mscorrc.dll
LoadedModule[122]=C:\WINDOWS\SYSTEM32\windows.globalization.dll
LoadedModule[123]=C:\WINDOWS\SYSTEM32\Bcp47Langs.dll
LoadedModule[124]=C:\WINDOWS\SYSTEM32\bcp47mrm.dll
LoadedModule[125]=C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroPDF.dll
LoadedModule[126]=C:\WINDOWS\SYSTEM32\Cabinet.dll
LoadedModule[127]=C:\WINDOWS\SYSTEM32\globinputhost.dll
LoadedModule[128]=C:\WINDOWS\System32\UIAnimation.dll
LoadedModule[129]=C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOXMLMF.DLL
LoadedModule[130]=C:\WINDOWS\SYSTEM32\VCRUNTIME140.dll
LoadedModule[131]=c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrlUI.dll
LoadedModule[132]=C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroPDFImpl.dll
LoadedModule[133]=C:\WINDOWS\SYSTEM32\MPR.dll
LoadedModule[134]=C:\WINDOWS\SYSTEM32\MSVCP140.dll
LoadedModule[135]=C:\WINDOWS\SYSTEM32\atlthunk.dll
State[0].Key=Transport.DoneStage1
State[0].Value=1
OsInfo[0].Key=vermaj
OsInfo[0].Value=10
OsInfo[1].Key=vermin
OsInfo[1].Value=0
OsInfo[2].Key=verbld
OsInfo[2].Value=17134
OsInfo[3].Key=ubr
OsInfo[3].Value=523
OsInfo[4].Key=versp
OsInfo[4].Value=0
OsInfo[5].Key=arch
OsInfo[5].Value=9
OsInfo[6].Key=lcid
OsInfo[6].Value=1053
OsInfo[7].Key=geoid
OsInfo[7].Value=221
OsInfo[8].Key=sku
OsInfo[8].Value=4
OsInfo[9].Key=domain
OsInfo[9].Value=1
OsInfo[10].Key=prodsuite
OsInfo[10].Value=256
OsInfo[11].Key=ntprodtype
OsInfo[11].Value=1
OsInfo[12].Key=platid
OsInfo[12].Value=10
OsInfo[13].Key=sr
OsInfo[13].Value=0
OsInfo[14].Key=tmsi
OsInfo[14].Value=83651
OsInfo[15].Key=osinsty
OsInfo[15].Value=2
OsInfo[16].Key=iever
OsInfo[16].Value=11.523.17134.0-11.0.105
OsInfo[17].Key=portos
OsInfo[17].Value=0
OsInfo[18].Key=ram
OsInfo[18].Value=8079
OsInfo[19].Key=svolsz
OsInfo[19].Value=237
OsInfo[20].Key=wimbt
OsInfo[20].Value=0
OsInfo[21].Key=blddt
OsInfo[21].Value=180410
OsInfo[22].Key=bldtm
OsInfo[22].Value=1804
OsInfo[23].Key=bldbrch
OsInfo[23].Value=rs4_release
OsInfo[24].Key=bldchk
OsInfo[24].Value=0
OsInfo[25].Key=wpvermaj
OsInfo[25].Value=0
OsInfo[26].Key=wpvermin
OsInfo[26].Value=0
OsInfo[27].Key=wpbuildmaj
OsInfo[27].Value=0
OsInfo[28].Key=wpbuildmin
OsInfo[28].Value=0
OsInfo[29].Key=osver
OsInfo[29].Value=10.0.17134.523.amd64fre.rs4_release.180410-1804
OsInfo[30].Key=buildflightid
OsInfo[31].Key=edition
OsInfo[31].Value=Enterprise
OsInfo[32].Key=ring
OsInfo[33].Key=expid
OsInfo[34].Key=containerid
OsInfo[35].Key=containertype
OsInfo[36].Key=edu
OsInfo[36].Value=0
File[0].CabName=minidump.mdmp
File[0].Path=WER1A1B.tmp.mdmp
File[0].Flags=539820035
File[0].Type=2
File[0].Original.Path=\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER1A1B.tmp.mdmp
File[1].CabName=WERInternalMetadata.xml
File[1].Path=WER1D0A.tmp.WERInternalMetadata.xml
File[1].Flags=851971
File[1].Type=5
File[1].Original.Path=\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER1D0A.tmp.WERInternalMetadata.xml
File[2].CabName=WERInternalRequest.xml
File[2].Path=WER1D3A.tmp.xml
File[2].Flags=851971
File[2].Type=5
File[2].Original.Path=\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER1D3A.tmp.xml
File[3].CabName=memory.csv
File[3].Path=WER1D48.tmp.csv
File[3].Flags=851971
File[3].Type=5
File[3].Original.Path=\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER1D48.tmp.csv
File[4].CabName=sysinfo.txt
File[4].Path=WER1D78.tmp.txt
File[4].Flags=851971
File[4].Type=5
File[4].Original.Path=\\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER1D78.tmp.txt
File[5].CabName=AppCompat.txt
File[5].Path=WER2152.tmp.appcompat.txt
File[5].Flags=17629187
File[5].Type=5
File[5].Original.Path=\\?\C:\Users\xxxxx\AppData\Local\Temp\WER2152.tmp.appcompat.txt
File[6].CabName=WERDataCollectionStatus.txt
File[6].Path=WER21A1.tmp.WERDataCollectionStatus.txt
File[6].Flags=851971
File[6].Type=5
File[6].Original.Path=\\?\C:\Users\xxxxx\AppData\Local\Temp\WER21A1.tmp.WERDataCollectionStatus.txt
File[7].CabName=Report.zip
File[7].Path=Report.zip
File[7].Flags=65536
File[7].Type=11
File[7].Original.Path=\\?\C:\WINDOWS\system32\Report.zip
FriendlyEventName=Stopped working
ConsentKey=APPCRASH
AppName=Internet Explorer
AppPath=C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
NsPartner=windows
NsGroup=windows8
ApplicationIdentity=3BD0E57EF652AF04909B6A81774D1117
MetadataHash=283408690
Continue reading...