for attention of windbg team

i am sorry to pollute this list with troubles in windbg but i could not
locate the windbg alias
and if i didnt post the info i may not be able to repost it

anyway here is the trouble

i was trying to answer the conditional match post and i find windbg hanging
not able to acquire a mutex

while trying to evaluate a conditional expression
it seems it is looking for mscoreei.pdb (.net4 i think)

this is a paste of windbg attached to windbg that is hung

if i do a !analyze -v or !analyze -hang this windbg process also hangs

Microsoft (R) Windows Debugger Version 6.12.0002.633 X86
Copyright (c) Microsoft Corporation. All rights reserved.

*** wait with pending attach
Symbol search path is: SRV*F:\symbols*
http://msdl.microsoft.com/download/symbols
Executable search path is:
ModLoad: 01000000 01097000 F:\windbg\612windbg\windbg.exe
ModLoad: 7c900000 7c9b2000 C:\WINDOWS\system32\ntdll.dll
ModLoad: 7c800000 7c8f6000 C:\WINDOWS\system32\kernel32.dll
ModLoad: 64d00000 64d31000 C:\Program Files\Alwil
Software\Avast5\snxhk.dll
ModLoad: 77dd0000 77e6b000 C:\WINDOWS\system32\ADVAPI32.dll
ModLoad: 77e70000 77f02000 C:\WINDOWS\system32\RPCRT4.dll
ModLoad: 77fe0000 77ff1000 C:\WINDOWS\system32\Secur32.dll
ModLoad: 77f10000 77f59000 C:\WINDOWS\system32\GDI32.dll
ModLoad: 7e410000 7e4a1000 C:\WINDOWS\system32\USER32.dll
ModLoad: 77c10000 77c68000 C:\WINDOWS\system32\msvcrt.dll
ModLoad: 02000000 0239b000 F:\windbg\612windbg\dbgeng.dll
ModLoad: 03000000 03141000 F:\windbg\612windbg\dbghelp.dll
ModLoad: 77c00000 77c08000 C:\WINDOWS\system32\VERSION.dll
ModLoad: 774e0000 7761d000 C:\WINDOWS\system32\ole32.dll
ModLoad: 7c9c0000 7d1d7000 C:\WINDOWS\system32\SHELL32.dll
ModLoad: 77f60000 77fd6000 C:\WINDOWS\system32\SHLWAPI.dll
ModLoad: 773d0000 774d3000

C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\COMCTL32.dll
ModLoad: 71b20000 71b32000 C:\WINDOWS\system32\MPR.dll
ModLoad: 76390000 763ad000 C:\WINDOWS\system32\IMM32.DLL
ModLoad: 5ad70000 5ada8000 C:\WINDOWS\system32\uxtheme.dll
ModLoad: 4b400000 4b486000 C:\WINDOWS\system32\MSFTEDIT.DLL
ModLoad: 77b40000 77b62000 C:\WINDOWS\system32\apphelp.dll
ModLoad: 755c0000 755ee000 C:\WINDOWS\system32\msctfime.ime
ModLoad: 763b0000 763f9000 C:\WINDOWS\system32\comdlg32.dll
ModLoad: 76fd0000 7704f000 C:\WINDOWS\system32\CLBCATQ.DLL
ModLoad: 77050000 77115000 C:\WINDOWS\system32\COMRes.dll
ModLoad: 77120000 771ab000 C:\WINDOWS\system32\OLEAUT32.dll
ModLoad: 62830000 62856000 C:\WINDOWS\system32\AcSignIcon.dll
ModLoad: 73000000 73026000 C:\WINDOWS\system32\WINSPOOL.DRV
ModLoad: 74c80000 74cac000 C:\WINDOWS\system32\OLEACC.dll
ModLoad: 76080000 760e5000 C:\WINDOWS\system32\MSVCP60.dll
ModLoad: 77a20000 77a74000 C:\WINDOWS\System32\cscui.dll
ModLoad: 76600000 7661d000 C:\WINDOWS\System32\CSCDLL.dll
ModLoad: 75f80000 7607d000 C:\WINDOWS\system32\browseui.dll
ModLoad: 769c0000 76a74000 C:\WINDOWS\system32\USERENV.dll
ModLoad: 77920000 77a13000 C:\WINDOWS\system32\SETUPAPI.dll
ModLoad: 76990000 769b5000 C:\WINDOWS\system32\ntshrui.dll
ModLoad: 76b20000 76b31000 C:\WINDOWS\system32\ATL.DLL
ModLoad: 5b860000 5b8b5000 C:\WINDOWS\system32\NETAPI32.dll
ModLoad: 7e290000 7e401000 C:\WINDOWS\system32\shdocvw.dll
ModLoad: 77a80000 77b15000 C:\WINDOWS\system32\CRYPT32.dll
ModLoad: 77b20000 77b32000 C:\WINDOWS\system32\MSASN1.dll
ModLoad: 754d0000 75550000 C:\WINDOWS\system32\CRYPTUI.dll
ModLoad: 3d930000 3da16000 C:\WINDOWS\system32\WININET.dll
ModLoad: 00bf0000 00bf9000 C:\WINDOWS\system32\Normaliz.dll
ModLoad: 78130000 78263000 C:\WINDOWS\system32\urlmon.dll
ModLoad: 3dfd0000 3e1b8000 C:\WINDOWS\system32\iertutil.dll
ModLoad: 76c30000 76c5e000 C:\WINDOWS\system32\WINTRUST.dll
ModLoad: 76c90000 76cb8000 C:\WINDOWS\system32\IMAGEHLP.dll
ModLoad: 76f60000 76f8c000 C:\WINDOWS\system32\WLDAP32.dll
ModLoad: 75f60000 75f67000 C:\WINDOWS\System32\drprov.dll
ModLoad: 71c10000 71c1e000 C:\WINDOWS\System32\ntlanman.dll
ModLoad: 71cd0000 71ce7000 C:\WINDOWS\System32\NETUI0.dll
ModLoad: 71c90000 71cd0000 C:\WINDOWS\System32\NETUI1.dll
ModLoad: 71c80000 71c87000 C:\WINDOWS\System32\NETRAP.dll
ModLoad: 71bf0000 71c03000 C:\WINDOWS\System32\SAMLIB.dll
ModLoad: 75f70000 75f7a000 C:\WINDOWS\System32\davclnt.dll
ModLoad: 73d70000 73d83000 C:\WINDOWS\system32\shgina.dll
ModLoad: 75970000 75a68000 C:\WINDOWS\system32\MSGINA.dll
ModLoad: 74320000 7435d000 C:\WINDOWS\system32\ODBC32.dll
ModLoad: 76360000 76370000 C:\WINDOWS\system32\WINSTA.dll
ModLoad: 00fe0000 00ff7000 C:\WINDOWS\system32\odbcint.dll
ModLoad: 593f0000 59482000 C:\WINDOWS\system32\wiashext.dll
ModLoad: 4ec50000 4edfb000

C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6001.22319_x-ww_f0b4c2df\gdiplus.dll
ModLoad: 011a0000 01465000 C:\WINDOWS\system32\xpsp2res.dll
ModLoad: 73ba0000 73bb3000 C:\WINDOWS\system32\sti.dll
ModLoad: 74ae0000 74ae7000 C:\WINDOWS\system32\CFGMGR32.dll
ModLoad: 628e0000 62919000 C:\Program Files\Common Files\Autodesk
Shared\AcSignCore16.dll
ModLoad: 71ab0000 71ac7000 C:\WINDOWS\system32\WS2_32.dll
ModLoad: 71aa0000 71aa8000 C:\WINDOWS\system32\WS2HELP.dll
ModLoad: 01660000 01959000 F:\windbg\612windbg\winext\ext.dll
ModLoad: 01960000 019d5000 F:\windbg\612windbg\WINXP\exts.dll
ModLoad: 019e0000 019fd000 F:\windbg\612windbg\winext\uext.dll
ModLoad: 4ee80000 4ee96000 F:\windbg\612windbg\WINXP\ntsdexts.dll
ModLoad: 76bf0000 76bfb000 C:\WINDOWS\system32\psapi.dll
ModLoad: 01d00000 01d48000 F:\windbg\612windbg\symsrv.dll
ModLoad: 76ee0000 76f1c000 C:\WINDOWS\system32\RASAPI32.dll
ModLoad: 76e90000 76ea2000 C:\WINDOWS\system32\rasman.dll
ModLoad: 76eb0000 76edf000 C:\WINDOWS\system32\TAPI32.dll
ModLoad: 76e80000 76e8e000 C:\WINDOWS\system32\rtutils.dll
ModLoad: 76b40000 76b6d000 C:\WINDOWS\system32\WINMM.dll
ModLoad: 77c70000 77c94000 C:\WINDOWS\system32\msv1_0.dll
ModLoad: 76d60000 76d79000 C:\WINDOWS\system32\iphlpapi.dll
ModLoad: 722b0000 722b5000 C:\WINDOWS\system32\sensapi.dll
ModLoad: 71a50000 71a8f000 C:\WINDOWS\System32\mswsock.dll
ModLoad: 76fc0000 76fc6000 C:\WINDOWS\system32\rasadhlp.dll
ModLoad: 76f20000 76f47000 C:\WINDOWS\system32\DNSAPI.dll
ModLoad: 76fb0000 76fb8000 C:\WINDOWS\System32\winrnr.dll
ModLoad: 7d4b0000 7d4d2000 C:\WINDOWS\system32\DHCPCSVC.DLL
ModLoad: 77d00000 77d33000 C:\WINDOWS\system32\netman.dll
ModLoad: 76d40000 76d58000 C:\WINDOWS\system32\MPRAPI.dll
ModLoad: 77cc0000 77cf2000 C:\WINDOWS\system32\ACTIVEDS.dll
ModLoad: 76e10000 76e35000 C:\WINDOWS\system32\adsldpc.dll
ModLoad: 76400000 765a5000 C:\WINDOWS\system32\netshell.dll
ModLoad: 76c00000 76c2e000 C:\WINDOWS\system32\credui.dll
ModLoad: 478c0000 478ca000 C:\WINDOWS\system32\dot3api.dll
ModLoad: 736d0000 736d6000 C:\WINDOWS\system32\dot3dlg.dll
ModLoad: 5dca0000 5dcc8000 C:\WINDOWS\system32\OneX.DLL
ModLoad: 76f50000 76f58000 C:\WINDOWS\system32\WTSAPI32.dll
ModLoad: 745b0000 745d2000 C:\WINDOWS\system32\eappcfg.dll
ModLoad: 5dcd0000 5dcde000 C:\WINDOWS\system32\eappprxy.dll
ModLoad: 73030000 73040000 C:\WINDOWS\system32\WZCSAPI.DLL
ModLoad: 7db10000 7db9c000 C:\WINDOWS\system32\WZCSvc.DLL
ModLoad: 76d30000 76d34000 C:\WINDOWS\system32\WMI.dll
ModLoad: 72810000 7281b000 C:\WINDOWS\system32\EapolQec.dll
ModLoad: 726c0000 726d6000 C:\WINDOWS\system32\QUtil.dll
ModLoad: 606b0000 607bd000 C:\WINDOWS\system32\ESENT.dll
ModLoad: 75150000 75163000 C:\WINDOWS\system32\Cabinet.dll
(9b8.c8c): Break instruction exception - code 80000003 (first chance)
eax=7ffdf000 ebx=00000001 ecx=00000002 edx=00000003 esi=00000004
edi=00000005
eip=7c90120e esp=01b6ffcc ebp=01b6fff4 iopl=0 nv up ei pl zr na pe
nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
efl=00000246
ntdll!DbgBreakPoint:
7c90120e cc int 3
0:007> ~7kb
ChildEBP RetAddr Args to Child
00a97be0 7c90df5a 7c8025db 000003c0 00000000 ntdll!KiFastSystemCallRet
00a97be4 7c8025db 000003c0 00000000 00000000 ntdll!ZwWaitForSingleObject+0xc
00a97c48 7c802542 000003c0 ffffffff 00000000
kernel32!WaitForSingleObjectEx+0xa8
00a97c5c 3d934c8d 000003c0 ffffffff 99288239
kernel32!WaitForSingleObject+0x12
00a97ca0 3d93506b 00a97cc8 9928827d 00000000
WININET!URL_CONTAINER::LockContainer+0x33
00a97ce4 3d935250 00000000 00a97d08 00a97d0c
WININET!URL_CONTAINER::GetHeaderData+0x22
00a97cf4 3d94026e 00a97d08 00000000 00000000
WININET!GetCurrentSettingsVersion+0x2d
00a97d0c 3d94054a 00000001 00000000 00124880
WININET!InternetSettingsChanged+0x13
00a97e6c 3d94992e 00000000 00000000 00000000 WININET!FixProxySettings+0x42
00a97ec0 3d94f4af 00000000 00000000 00124880
WININET!FixProxySettingsForCurrentConnection+0x9a
00a97ed8 3d9457b3 00124be8 00000000 00000000
WININET!CFsm_HttpSendRequest::RunSM+0x61
00a97ef0 3d945c59 00124880 00000000 00000000 WININET!CFsm::Run+0x26
00a97f08 3d974958 00124be8 00000000 00000000 WININET!DoFsm+0x25
00a97f30 3d94fafd 00000000 00000000 00000000
WININET!HttpWrapSendRequest+0x136
00a97f68 01d1484a 00cc000c 00000000 00000000 WININET!HttpSendRequestW+0x5e
00a97f90 01d1451b 3d94fea6 05aff2f0 00a9fe30
symsrv!StoreWinInet::request+0x2a
00a97fc4 01d1410e 05aff2f0 00000490 00000001
symsrv!StoreWinInet::fileinfo+0x1b
00a97fd8 01d0f171 05aff926 05aff2f0 00002ee7 symsrv!StoreWinInet::get+0xbe
00a9881c 01d14283 05aff926 006d005c 00630073 symsrv!StoreHTTP::open+0x51
00a98a5c 01d060b7 00a990b8 00a9a5d4 ffffffff symsrv!StoreWinInet::find+0xd3
00a98b50 01d071f7 00000002 00a99068 00a990b8 symsrv!cascade+0x87
00a990a0 01d07007 00a99700 00a9a5d4 00a990b8
symsrv!SymbolServerByIndexW+0x127
00a992d0 0303004f 00a99700 00a9a5d4 00a9a7f8 symsrv!SymbolServerW+0x77
00a99b20 0301a427 00831e90 00a99d7c 00a99fa4 dbghelp!symsrvGetFile+0x17f
00a9a80c 0301b486 042fe3d8 042fec68 042fec58 dbghelp!diaLocatePdb+0x387
00a9aa88 03043c64 042fe3d8 00000000 00000004 dbghelp!diaGetPdb+0x206
00a9acac 03042095 042fe3d8 bbe9571b 00a9fe30 dbghelp!GetDebugData+0x2c4
00a9b154 03041c5a 000002f4 0631fb18 00831e90 dbghelp!modload+0x305
00a9b168 03034709 000002f4 0631fb18 00000000 dbghelp!LoadSymbols+0x9a
00a9b198 03036255 00831e90 603b0000 00000000 dbghelp!ModLoop+0xc9
00a9d16c 0303c539 000002f4 603b0000 00000000 dbghelp!EnumSymbols+0x155
00a9d19c 0224d99e 000002f4 603b0000 00000000 dbghelp!SymEnumSymbolsW+0x59
00a9d300 0224db7f 059a0888 00a9e14c 00000001
dbgeng!EnumModuleTypedData+0x1de
00a9dff8 02250cf5 00000000 00000000 00000000
dbgeng!EnumAllModuleTypedData+0x19f
00a9e310 0225112e 00ef0f40 01e55e48 00000000 dbgeng!EnumSymbolInfoRaw+0x295
00a9e4ac 02171f8e 00ef0f40 01e55e48 00000000 dbgeng!GetOffsetFromSym+0x34e
00a9e704 02174e5a 00a9e93c 00000000 00000000
dbgeng!MasmEvalExpression::EvalSymbol+0xde
00a9ea6c 02171d02 01d98d30 00000007 01d983d8
dbgeng!MasmEvalExpression::NextToken+0x289a
00a9ea88 02171535 00a9eac0 00a9eabc 020f1e8c
dbgeng!MasmEvalExpression::PeekToken+0x42
00a9eac8 02171373 bbe90cab 00a9eb68 00a9eaf4
dbgeng!MasmEvalExpression::GetAterm+0x25
00a9eb14 02171283 00a9ecc0 020d172b 01d983d8
dbgeng!MasmEvalExpression::GetShiftTerm+0x13
00a9eb48 02171023 00000000 00260024 00000000
dbgeng!MasmEvalExpression::GetLterm+0x13
00a9ebb4 02170f43 006f004c 00610063 01d983d8
dbgeng!MasmEvalExpression::GetLRterm+0x13
00a9ebe8 02170f1d 00000028 01d983d8 00a90028
dbgeng!MasmEvalExpression::StartExpr+0x13
00a9ebfc 021706ff 01d983d8 00a9fe30 0210bcd6
dbgeng!MasmEvalExpression::GetCommonExpression+0xcd
00a9ec10 02183ff3 00a9ee90 0202a448 00000000
dbgeng!MasmEvalExpression::Evaluate+0x4f
00a9ec84 02183b8d 00a9ee90 0202a448 00000000
dbgeng!EvalExpression::EvalNum+0x63
00a9ecc4 021d6158 00000000 00a9fea8 00ec03c0 dbgeng!GetExpression+0x5d
00a9eda8 021d71a9 00ec0b38 00000000 bbe90ba3 dbgeng!ProcessCommands+0x8c8
00a9edec 021076c9 00ec0b38 00000000 00000000
dbgeng!ProcessCommandsAndCatch+0x49
00a9f284 021d49ec 00ec0b38 00ec03c0 00000002 dbgeng!Execute+0x2b9
00a9f314 021d5c7f 00ec0b38 00a9fea8 00000027 dbgeng!ParseDollar+0x2dc
00a9f3f8 021d71a9 00ec0b38 00000000 bbe91273 dbgeng!ProcessCommands+0x3ef
00a9f43c 021076c9 00ec0b38 00000000 00000000
dbgeng!ProcessCommandsAndCatch+0x49
00a9f8d4 020ee25e 00ec0b38 0082d7c0 00000002 dbgeng!Execute+0x2b9
00a9f8f4 020ee3ae 00000000 00ec0b38 00000002 dbgeng!ExecuteEventCommand+0x7e
00a9f920 020e771a 00000000 01ddfa30 00ef0f40
dbgeng!NotifyBreakpointEvent+0x8e
00a9f93c 02177f20 00000000 020f46b2 00000000
dbgeng!NotifyHitBreakpoints+0xaa
00a9f960 02177ba0 00a9f974 00000002 ffffffff
dbgeng!CheckBreakpointOrStepTrace+0x2c0
00a9f99c 0217ca05 00a9fe58 00000001 bbe91c9f
dbgeng!ProcessBreakpointOrStepException+0xb0
00a9fad0 0217c770 00a9fe48 bbe91bef 00000000
dbgeng!LiveUserTargetInfo::ProcessEventException+0x1f5
00a9fda0 0217c1bb 00a9fe48 00000000 00000002
dbgeng!LiveUserTargetInfo::ProcessDebugEvent+0x460
00a9ff10 0210a3ff 00000000 000003e8 00000000
dbgeng!LiveUserTargetInfo::WaitForEvent+0x74b
00a9ff34 0210a7ce 00000000 000003e8 00000001 dbgeng!WaitForAnyTarget+0x5f
00a9ff80 0210aa60 00ec0b38 00000000 ffffffff dbgeng!RawWaitForEvent+0x2ae
00a9ff98 0102b6cf 00ec0b40 00000000 ffffffff
dbgeng!DebugClient::WaitForEvent+0xb0
00a9ffb4 7c80b729 00000000 7e428dd9 0014020c windbg!EngineLoop+0x13f
00a9ffec 00000000 0102b590 00000000 00000000 kernel32!BaseThreadStart+0x37
0:007> !handle 03c0 f
Handle 3c0
Type Mutant
Attributes 0
GrantedAccess 0x100000:
Synch
None
HandleCount 4
PointerCount 7
Name \BaseNamedObjects\c:!documents and settings!admin!local
settings!temporary internet

files!content.ie5!
Object Specific Information
Handle does not have required access to query basic mutant information
0:007> dd 00a99b24
00a99b24 0301a427 00831e90 00a99d7c 00a99fa4
00a99b34 00a9a5d4 00a9a7f8 00000002 00000000
00a99b44 00000000 00a99b6c 00820000 054fa668
00a99b54 00a99b88 00820000 7c910222 00a99b94
00a99b64 00a99b7c 00000000 00000000 00000000
00a99b74 00000000 00000000 00000000 00000000
00a99b84 00000000 00000000 00000000 00000000
00a99b94 00000000 00000000 00000000 00000000

0:007> ddu 00a99b24 l10
00a99b24 0301a427 “?..?..è”
00a99b28 00831e90 “?.?.?..???.”
00a99b2c 00a99d7c “srv*f:\symbols*http://msdl.microsoft.com/download/symbo
00a99b30 00a99fa4 “”
00a99b34 00a9a5d4 “mscoreei.pdb”
00a99b38 00a9a7f8 “.???.©?..?.?.?”
00a99b3c 00000002
00a99b40 00000000
00a99b44 00000000
00a99b48 00a99b6c “”
00a99b4c 00820000 “È”
00a99b50 054fa668 “…??.?.?.?.?.??›.?”
00a99b54 00a99b88 “”
00a99b58 00820000 “È”
00a99b5c 7c910222 “???..?.???..???.?.???.?.?.?.??.?.?.???.?.??.?.???.”
00a99b60 00a99b94 “”

0:007> ddu 00a9ec88
00a9ec88 02183b8d “???.??.???..?.?.??.???”
00a9ec8c 00a9ee90 " ( $spat( “${foo}”, “*chm*” ) == 0 ) gc ; da poi(esp+4)"
00a9ec90 0202a448 “Numeric expression missing from”
00a9ec94 00000000
00a9ec98 00a9ecb0 “??”
00a9ec9c bbe90a8b
00a9eca0 00000000
00a9eca4 00000000
00a9eca8 00000000
00a9ecac 01d983d8 “??Ÿ.”
00a9ecb0 77c39f8e “???.??.?.???.??”
00a9ecb4 00000000
00a9ecb8 00a9eddc “.©??.?”
00a9ecbc 02317598 “?.??.??.?.??.???.?.?.??.??.?.??.?.?..???”
00a9ecc0 00000000
00a9ecc4 00a9eda8 “.©???ì”
00a9ecc8 021d6158 “??.??.??.??.?.”
00a9eccc 00000000
00a9ecd0 00a9fea8 “…?..?”
00a9ecd4 00ec03c0 "as /ma ${/v:foo} poi(esp+4);.j ( $spat( “${foo}”, “*chm”
00a9ecd8 00a9ecc8 “??”
00a9ecdc 7c91a2a3 “???”
00a9ece0 00a9ef0c “.©.???..???”
00a9ece4 7c90e920 “??.???.?.?.”
00a9ece8 7c910228 “…?.???..???.?.???.?.?.?.??.?.?.???.?.??.?.???.?Ÿ?”
00a9ecec ffffffff
00a9ecf0 7c910222 “???..?.???..???.?.???.?.?.?.??.?.?.???.?.??.?.???.”
00a9ecf4 7c91019b “.??.?.?.???.?..?.?.?..???.ÿ”
00a9ecf8 7c9101db “???.ÿ”
00a9ecfc 00a9fe30 “.?`”
00a9ed00 0000000f
00a9ed04 00000000

the windbg has to be killed
it does not respond to ctrl+break , detach ctrl+c
cant activate ctrl+alt+d spew

it simply stays there *BUSY* until terminated


thanks and regards

raj_r

the earlier post seems to be cut off

the remaining part is pasted below

00a9acac 03042095 042fe3d8 bbe9571b 00a9fe30 dbghelp!GetDebugData+0x2c4
00a9b154 03041c5a 000002f4 0631fb18 00831e90 dbghelp!modload+0x305
00a9b168 03034709 000002f4 0631fb18 00000000 dbghelp!LoadSymbols+0x9a
00a9b198 03036255 00831e90 603b0000 00000000 dbghelp!ModLoop+0xc9
00a9d16c 0303c539 000002f4 603b0000 00000000 dbghelp!EnumSymbols+0x155
00a9d19c 0224d99e 000002f4 603b0000 00000000 dbghelp!SymEnumSymbolsW+0x59
00a9d300 0224db7f 059a0888 00a9e14c 00000001 dbgeng!EnumModuleTypedData+
0x1de
00a9dff8 02250cf5 00000000 00000000 00000000
dbgeng!EnumAllModuleTypedData+0x19f
00a9e310 0225112e 00ef0f40 01e55e48 00000000 dbgeng!EnumSymbolInfoRaw+0x295
00a9e4ac 02171f8e 00ef0f40 01e55e48 00000000 dbgeng!GetOffsetFromSym+0x34e
00a9e704 02174e5a 00a9e93c 00000000 00000000
dbgeng!MasmEvalExpression::EvalSymbol+0xde
00a9ea6c 02171d02 01d98d30 00000007 01d983d8
dbgeng!MasmEvalExpression::NextToken+0x289a
00a9ea88 02171535 00a9eac0 00a9eabc 020f1e8c
dbgeng!MasmEvalExpression::PeekToken+0x42
00a9eac8 02171373 bbe90cab 00a9eb68 00a9eaf4
dbgeng!MasmEvalExpression::GetAterm+0x25
00a9eb14 02171283 00a9ecc0 020d172b 01d983d8
dbgeng!MasmEvalExpression::GetShiftTerm+0x13
00a9eb48 02171023 00000000 00260024 00000000
dbgeng!MasmEvalExpression::GetLterm+0x13
00a9ebb4 02170f43 006f004c 00610063 01d983d8
dbgeng!MasmEvalExpression::GetLRterm+0x13
00a9ebe8 02170f1d 00000028 01d983d8 00a90028
dbgeng!MasmEvalExpression::StartExpr+0x13
00a9ebfc 021706ff 01d983d8 00a9fe30 0210bcd6
dbgeng!MasmEvalExpression::GetCommonExpression+0xcd
00a9ec10 02183ff3 00a9ee90 0202a448 00000000
dbgeng!MasmEvalExpression::Evaluate+0x4f
00a9ec84 02183b8d 00a9ee90 0202a448 00000000
dbgeng!EvalExpression::EvalNum+0x63
00a9ecc4 021d6158 00000000 00a9fea8 00ec03c0 dbgeng!GetExpression+0x5d
00a9eda8 021d71a9 00ec0b38 00000000 bbe90ba3 dbgeng!ProcessCommands+0x8c8
00a9edec 021076c9 00ec0b38 00000000 00000000
dbgeng!ProcessCommandsAndCatch+0x49
00a9f284 021d49ec 00ec0b38 00ec03c0 00000002 dbgeng!Execute+0x2b9
00a9f314 021d5c7f 00ec0b38 00a9fea8 00000027 dbgeng!ParseDollar+0x2dc
00a9f3f8 021d71a9 00ec0b38 00000000 bbe91273 dbgeng!ProcessCommands+0x3ef
00a9f43c 021076c9 00ec0b38 00000000 00000000
dbgeng!ProcessCommandsAndCatch+0x49
00a9f8d4 020ee25e 00ec0b38 0082d7c0 00000002 dbgeng!Execute+0x2b9
00a9f8f4 020ee3ae 00000000 00ec0b38 00000002 dbgeng!ExecuteEventCommand+0x7e
00a9f920 020e771a 00000000 01ddfa30 00ef0f40
dbgeng!NotifyBreakpointEvent+0x8e
00a9f93c 02177f20 00000000 020f46b2 00000000
dbgeng!NotifyHitBreakpoints+0xaa
00a9f960 02177ba0 00a9f974 00000002 ffffffff
dbgeng!CheckBreakpointOrStepTrace+0x2c0
00a9f99c 0217ca05 00a9fe58 00000001 bbe91c9f
dbgeng!ProcessBreakpointOrStepException+0xb0
00a9fad0 0217c770 00a9fe48 bbe91bef 00000000
dbgeng!LiveUserTargetInfo::ProcessEventException+0x1f5
00a9fda0 0217c1bb 00a9fe48 00000000 00000002
dbgeng!LiveUserTargetInfo::ProcessDebugEvent+0x460
00a9ff10 0210a3ff 00000000 000003e8 00000000
dbgeng!LiveUserTargetInfo::WaitForEvent+0x74b
00a9ff34 0210a7ce 00000000 000003e8 00000001 dbgeng!WaitForAnyTarget+0x5f
00a9ff80 0210aa60 00ec0b38 00000000 ffffffff dbgeng!RawWaitForEvent+0x2ae
00a9ff98 0102b6cf 00ec0b40 00000000 ffffffff
dbgeng!DebugClient::WaitForEvent+0xb0
00a9ffb4 7c80b729 00000000 7e428dd9 0014020c windbg!EngineLoop+0x13f
00a9ffec 00000000 0102b590 00000000 00000000 kernel32!BaseThreadStart+0x37
0:007> !handle 03c0 f
Handle 3c0
Type Mutant
Attributes 0
GrantedAccess 0x100000:
Synch
None
HandleCount 4
PointerCount 7
Name \BaseNamedObjects\c:!documents and settings!admin!local
settings!temporary internet

files!content.ie5!
Object Specific Information
Handle does not have required access to query basic mutant information
0:007> dd 00a99b24
00a99b24 0301a427 00831e90 00a99d7c 00a99fa4
00a99b34 00a9a5d4 00a9a7f8 00000002 00000000
00a99b44 00000000 00a99b6c 00820000 054fa668
00a99b54 00a99b88 00820000 7c910222 00a99b94
00a99b64 00a99b7c 00000000 00000000 00000000
00a99b74 00000000 00000000 00000000 00000000
00a99b84 00000000 00000000 00000000 00000000
00a99b94 00000000 00000000 00000000 00000000

0:007> ddu 00a99b24 l10
00a99b24 0301a427 “?..?..è”
00a99b28 00831e90 “?.?.?..???.”
00a99b2c 00a99d7c “srv*f:\symbols*http://msdl.microsoft.com/download/symbo
00a99b30 00a99fa4 “”
00a99b34 00a9a5d4 “mscoreei.pdb”
00a99b38 00a9a7f8 “.???.©?..?.?.?”
00a99b3c 00000002
00a99b40 00000000
00a99b44 00000000
00a99b48 00a99b6c “”
00a99b4c 00820000 “È”
00a99b50 054fa668 “…??.?.?.?.?.??›.?”
00a99b54 00a99b88 “”
00a99b58 00820000 “È”
00a99b5c 7c910222 “???..?.???..???.?.???.?.?.?.??.?.?.???.?.??.?.???.”
00a99b60 00a99b94 “”

0:007> ddu 00a9ec88
00a9ec88 02183b8d “???.??.???..?.?.??.???”
00a9ec8c 00a9ee90 " ( $spat( “${foo}”, “*chm*” ) == 0 ) gc ; da poi(esp+4)"
00a9ec90 0202a448 “Numeric expression missing from”
00a9ec94 00000000
00a9ec98 00a9ecb0 “??”
00a9ec9c bbe90a8b
00a9eca0 00000000
00a9eca4 00000000
00a9eca8 00000000
00a9ecac 01d983d8 “??Ÿ.”
00a9ecb0 77c39f8e “???.??.?.???.??”
00a9ecb4 00000000
00a9ecb8 00a9eddc “.©??.?”
00a9ecbc 02317598 “?.??.??.?.??.???.?.?.??.??.?.??.?.?..???”
00a9ecc0 00000000
00a9ecc4 00a9eda8 “.©???ì”
00a9ecc8 021d6158 “??.??.??.??.?.”
00a9eccc 00000000
00a9ecd0 00a9fea8 “…?..?”
00a9ecd4 00ec03c0 "as /ma ${/v:foo} poi(esp+4);.j ( $spat( “${foo}”, “*chm”
00a9ecd8 00a9ecc8 “??”
00a9ecdc 7c91a2a3 “???”
00a9ece0 00a9ef0c “.©.???..???”
00a9ece4 7c90e920 “??.???.?.?.”
00a9ece8 7c910228 “…?.???..???.?.???.?.?.?.??.?.?.???.?.??.?.???.?Ÿ?”
00a9ecec ffffffff
00a9ecf0 7c910222 “???..?.???..???.?.???.?.?.?.??.?.?.???.?.??.?.???.”
00a9ecf4 7c91019b “.??.?.?.???.?..?.?.?..???.ÿ”
00a9ecf8 7c9101db “???.ÿ”
00a9ecfc 00a9fe30 “.?`”
00a9ed00 0000000f
00a9ed04 00000000

the windbg has to be killed
it does not respond to ctrl+break , detach ctrl+c
cant activate ctrl+alt+d spew

it simply stays there *BUSY* until terminated