Ok, I wasn't very satisfied not having a stack trace on that iret, so I tried it
another way:
bp 436:1cc #where int 2f lives
bp ff33:43ac #where the infamous iret lives.
g
Trap 3, system state: stopped
AX=2c00 BX=0b10 CX=023a DX=385e SI=07cf DI=0001 SP=7f18 BP=7f20
DS=2a5f ES=2932 FS=0000 GS=0000 FL=3046
CS:IP=ff33:43ac SS:SP=2a5f:7f18
ff33:43ac CF iret
g
Trap 3, system state: stopped
AX=1123 BX=0010 CX=751f DX=0184 SI=0184 DI=03be SP=0908 BP=0444
DS=2932 ES=00c9 FS=0000 GS=0000 FL=3046
CS:IP=0436:01cc SS:SP=00c9:0908
0436:01cc EA58013504 jmp 0435:0158 #qualify remote filename
d ds:si
2932:0184 65 78 65 63 2E 6C 6F 67 00 32 39 38 32 2E 30 30 exec.log.2982.00
2932:0194 20 31 33 2E 33 36 00 20 20 20 20 20 20 20 20 20 13.36.
2932:01a4 20 20 20 20 20 20 00 20 20 20 20 20 20 20 20 20 .
2932:01b4 20 20 20 20 00 20 20 20 20 20 20 20 20 20 20 20 .
2932:01c4 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20
2932:01d4 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
2932:01e4 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
2932:01f4 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
g
Trap 3, system state: stopped
AX=0012 BX=0008 CX=0301 DX=0184 SI=0301 DI=0000 SP=7ef2 BP=7efe
DS=2932 ES=2a5f FS=0000 GS=0000 FL=3046
CS:IP=ff33:43ac SS:SP=2a5f:7ef2
ff33:43ac CF iret
d ss:7ee0
2a5f:7ee0 12 00 08 00 01 03 84 01 01 03 00 00 FE 7E 32 29 ............~~2)
2a5f:7ef0 5F 2A 6B 06 74 20 02 32 5F 2A 80 15 00 00 1A 7F _*k.t .2_*.....
2a5f:7f00 F5 1F 74 20 84 01 32 29 01 03 A4 01 A4 01 BA 00 u.t ..2)..$.$.:.
2a5f:7f10 00 00 01 00 00 00 02 FF 01 00 36 7F 2A 02 74 20 .........6*.t
2a5f:7f20 84 01 32 29 08 0C 5F 2A 00 00 F2 15 5F 2A BA 00 ..2).._*..r._*:.
2a5f:7f30 4C 7F 8E E2 5F 2A 46 7F 45 02 74 20 84 01 32 29 L.b_*FE.t ..2)
2a5f:7f40 07 0C 5F 2A 00 00 5C 7F 76 0C DE 15 84 01 32 29 .._*..\v.^...2)
2a5f:7f50 07 0C 5F 2A BA 00 00 00 00 00 01 00 70 7F 4F 57 .._*:.......pOW
g
Trap 3, system state: stopped
AX=1123 BX=0012 CX=0000 DX=0184 SI=0184 DI=03be SP=0908 BP=0444
DS=2932 ES=00c9 FS=0000 GS=0000 FL=3046
CS:IP=0436:01cc SS:SP=00c9:0908
0436:01cc EA58013504 jmp 0435:0158
d ds:si
2932:0184 65 78 65 63 2E 6C 6F 67 00 32 39 38 32 2E 30 30 exec.log.2982.00
2932:0194 20 31 33 2E 33 36 00 20 20 20 20 20 20 20 20 20 13.36.
2932:01a4 20 20 20 20 20 20 00 20 20 20 20 20 20 20 20 20 .
2932:01b4 20 20 20 20 00 20 20 20 20 20 20 20 20 20 20 20 .
2932:01c4 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20
2932:01d4 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
2932:01e4 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
2932:01f4 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
g
Trap 3, system state: stopped
AX=0020 BX=0012 CX=0020 DX=0184 SI=0301 DI=0000 SP=7ef2 BP=7efe
DS=2932 ES=2a5f FS=0000 GS=0000 FL=3046
CS:IP=ff33:43ac SS:SP=2a5f:7ef2
ff33:43ac CF iret
d ss:7ee0
2a5f:7ee0 20 00 12 00 20 00 84 01 01 03 00 00 FE 7E 32 29 ... .......~~2)
2a5f:7ef0 5F 2A 9D 07 74 20 46 32 5F 2A 80 01 00 00 1A 7F _*..t F2_*.....
2a5f:7f00 F5 1F 74 20 84 01 32 29 01 03 A4 01 A4 01 BA 00 u.t ..2)..$.$.:.
2a5f:7f10 00 00 01 00 00 00 02 FF 01 00 36 7F 2A 02 74 20 .........6*.t
2a5f:7f20 84 01 32 29 08 0C 5F 2A 00 00 F2 15 5F 2A BA 00 ..2).._*..r._*:.
2a5f:7f30 4C 7F 8E E2 5F 2A 46 7F 45 02 74 20 84 01 32 29 L.b_*FE.t ..2)
2a5f:7f40 07 0C 5F 2A 00 00 5C 7F 76 0C DE 15 84 01 32 29 .._*..\v.^...2)
2a5f:7f50 07 0C 5F 2A BA 00 00 00 00 00 01 00 70 7F 4F 57 .._*:.......pOW
g
Trap 3, system state: stopped
AX=1120 BX=ffff CX=0000 DX=0000 SI=0008 DI=f9b0 SP=090c BP=ffff
DS=00c9 ES=ffff FS=0000 GS=0000 FL=3046
CS:IP=0436:01cc SS:SP=00c9:090c
0436:01cc EA58013504 jmp 0435:0158 #flush disk buffers
g
Trap 3, system state: stopped
AX=0dff BX=0080 CX=0000 DX=0000 SI=0008 DI=0000 SP=7e2e BP=7e3c
DS=2a5f ES=2932 FS=0000 GS=0000 FL=3046
CS:IP=ff33:43ac SS:SP=2a5f:7e2e
ff33:43ac CF iret
d ss:7e10
2a5f:7e10 00 00 00 00 00 00 00 00 00 00 1C 7E FF 0D 80 00 ...........~...
2a5f:7e20 00 00 00 00 08 00 00 00 3C 7E 5F 2A 32 29 76 83 ........<~_*2)v.
2a5f:7e30 DE 15 02 32 5F 2A 32 29 08 00 00 00 2E 7F 92 C9 ^..2_*2)......I
g
Trap 3, system state: stopped
AX=1123 BX=2a3f CX=0000 DX=107c SI=107c DI=03be SP=090c BP=0444
DS=2a5f ES=00c9 FS=0000 GS=0000 FL=3046
CS:IP=0436:01cc SS:SP=00c9:090c
0436:01cc EA58013504 jmp 0435:0158
d ds:si
2a5f:107c 43 3A 5C 00 4F 4D 4D 41 4E 44 2E 43 4F 4D 00 00 C:\.OMMAND.COM..
g
Trap 3, system state: stopped
AX=0000 BX=2a3f CX=0000 DX=107c SI=343c DI=343a SP=7d8e BP=7da0
DS=2a5f ES=2a5f FS=0000 GS=0000 FL=3046
CS:IP=ff33:43ac SS:SP=2a5f:7d8e
ff33:43ac CF iret
d ss:7d70
2a5f:7d70 00 00 00 00 00 00 00 00 00 01 03 00 00 00 3F 2A ..............?*
2a5f:7d80 00 00 7C 10 3C 34 3A 34 A0 7D 5F 2A 5F 2A CE A7 ..|.<4:4 }_*_*N'
2a5f:7d90 DE 15 46 32 00 00 08 00 5F 2A 5F 2A 1E 00 03 00 ^.F2...._*_*....
g
Trap 3, system state: stopped
AX=1123 BX=2a3f CX=0002 DX=3e54 SI=3e54 DI=03be SP=090c BP=0444
DS=2a5f ES=00c9 FS=0000 GS=0000 FL=3046
CS:IP=0436:01cc SS:SP=00c9:090c
0436:01cc EA58013504 jmp 0435:0158
d ds:si
2a5f:3e54 43 3A 5C 41 52 53 00 00 00 00 00 00 00 00 00 00 C:\ARS..........
g
Trap 3, system state: stopped
AX=0000 BX=2a3f CX=0002 DX=3e54 SI=343b DI=343c SP=7d8e BP=7da0
DS=2a5f ES=2a5f FS=0000 GS=0000 FL=3046
CS:IP=ff33:43ac SS:SP=2a5f:7d8e
ff33:43ac CF iret
d ss:7d70
2a5f:7d70 00 00 00 00 00 00 00 00 00 01 03 00 00 00 3F 2A ..............?*
2a5f:7d80 02 00 54 3E 3B 34 3C 34 A0 7D 5F 2A 5F 2A 10 A8 ..T>;4<4 }_*_*.(
2a5f:7d90 DE 15 46 32 00 00 08 00 5F 2A 5F 2A 1E 00 03 00 ^.F2...._*_*....
g
Trap 3, system state: stopped
AX=1123 BX=0080 CX=0016 DX=107c SI=107c DI=03be SP=090c BP=0444
DS=2a5f ES=00c9 FS=0000 GS=0000 FL=3046
CS:IP=0436:01cc SS:SP=00c9:090c
0436:01cc EA58013504 jmp 0435:0158
d ds:si
2a5f:107c 43 3A 5C 43 4F 4D 4D 41 4E 44 2E 43 4F 4D 00 00 C:\COMMAND.COM..
g
Trap 3, system state: stopped
AX=0000 BX=0080 CX=0016 DX=107c SI=353f DI=108a SP=7d8a BP=7da0
DS=2a5f ES=0605 FS=0000 GS=0000 FL=3046
CS:IP=ff33:43ac SS:SP=2a5f:7d8a
ff33:43ac CF iret
d ss:7d70
2a5f:7d70 00 00 00 00 00 00 00 00 00 00 80 00 16 00 7C 10 ..............|.
2a5f:7d80 3F 35 8A 10 A0 7D 5F 2A 05 06 99 A8 DE 15 02 32 ?5.. }_*...(^..2
2a5f:7d90 05 06 80 00 00 00 08 00 5F 2A 5F 2A 1E 00 03 00 ........_*_*....
Trap 3, system state: stopped
AX=1123 BX=2a3f CX=0000 DX=373e SI=373e DI=03be SP=090c BP=0444
DS=2a5f ES=00c9 FS=0000 GS=0000 FL=3046
CS:IP=0436:01cc SS:SP=00c9:090c
0436:01cc EA58013504 jmp 0435:0158
d ds:si
2a5f:373e 43 3A 2E 00 00 00 00 00 00 00 00 00 00 00 00 00 C:..............
g
Trap 3, system state: stopped
AX=0000 BX=2a3f CX=0000 DX=373e SI=343d DI=343a SP=7d98 BP=7daa
DS=2a5f ES=2a5f FS=0000 GS=0000 FL=3046
CS:IP=ff33:43ac SS:SP=2a5f:7d98
ff33:43ac CF iret
d ss:7d80
2a5f:7d80 78 01 00 01 03 00 00 00 3F 2A 00 00 3E 37 3D 34 x.......?*..>7=4
2a5f:7d90 3A 34 AA 7D 5F 2A 5F 2A CE A7 DE 15 46 32 00 00 :4*}_*_*N'^.F2..
2a5f:7da0 0C 00 5F 2A 5F 2A 08 00 03 00 E6 7D 65 8C DE 15 .._*_*....f}e.^.
g
Trap 3, system state: stopped
AX=1123 BX=2a3f CX=0005 DX=3e54 SI=3e54 DI=03be SP=090c BP=0444
DS=2a5f ES=00c9 FS=0000 GS=0000 FL=3046
CS:IP=0436:01cc SS:SP=00c9:090c
0436:01cc EA58013504 jmp 0435:0158
d ds:si
2a5f:3e54 43 3A 5C 41 52 53 00 44 20 43 4F 4D 16 0E 00 00 C:\ARS.D COM....
g
Trap 3, system state: stopped
AX=0000 BX=2a3f CX=0005 DX=3e54 SI=343b DI=3440 SP=7d98 BP=7daa
DS=2a5f ES=2a5f FS=0000 GS=0000 FL=3046
CS:IP=ff33:43ac SS:SP=2a5f:7d98
ff33:43ac CF iret
d ss:7d80
2a5f:7d80 78 01 00 01 03 00 00 00 3F 2A 05 00 54 3E 3B 34 x.......?*..T>;4
g
Trap 3, system state: stopped
AX=1123 BX=2a3f CX=0005 DX=373e SI=373e DI=03be SP=0908 BP=0444
DS=2a5f ES=00c9 FS=0000 GS=0000 FL=3046
CS:IP=0436:01cc SS:SP=00c9:0908
0436:01cc EA58013504 jmp 0435:0158
d ds:si
2a5f:373e 43 3A 5C 41 52 53 00 00 00 00 00 00 00 00 00 00 C:\ARS..........
g
Trap 3, system state: stopped
AX=0010 BX=2a3f CX=0010 DX=373e SI=3440 DI=3743 SP=7d98 BP=7daa
DS=2a5f ES=2a5f FS=0000 GS=0000 FL=3046
CS:IP=ff33:43ac SS:SP=2a5f:7d98
ff33:43ac CF iret
d ss:7d80
2a5f:7d80 78 01 00 01 03 00 10 00 3F 2A 10 00 3E 37 40 34 x.......?*..>7@4
2a5f:7d90 43 37 AA 7D 5F 2A 5F 2A 53 A8 DE 15 12 32 00 00 C7*}_*_*S(^..2..
2a5f:7da0 0C 00 5F 2A 5F 2A 08 10 03 00 E6 7D 65 8C DE 15 .._*_*....f}e.^.
g
Trap 3, system state: stopped
AX=1123 BX=0003 CX=751f DX=00bc SI=00bc DI=03be SP=08e4 BP=0444
DS=0605 ES=00c9 FS=0000 GS=0000 FL=3046
CS:IP=0436:01cc SS:SP=00c9:08e4
0436:01cc EA58013504 jmp 0435:0158
d ds:si
0605:00bc 43 3A 5C 43 4F 4D 4D 41 4E 44 2E 43 4F 4D 00 00 C:\COMMAND.COM..
g
****
leavedos(4) called, at termination point of DOSEMU
****
system state: stopped
AX=0005 BX=1042 CX=0000 DX=0000 SI=0000 DI=0000 SP=f012 BP=43ad
DS=ff33 ES=3006 FS=0000 GS=0000 FL=3206
CS:IP=ff33:11fc SS:SP=0750:f012
ff33:11fc FFFF ??? di
Now I am really stuck and it is way past bed time. Maybe I wake up to some new
instructions next morning. Good night!
-Marcel Landman