Application exception occurred: App: \??\C:\WINDOWS\system32\winlogon.exe (pid=724) When: 17/08/2012 @ 11:00:09.640 Exception number: c0000005 (access violation) *----> System Information <----* Computer Name: OPTI790-BUILD User Name: SYSTEM Terminal Session Id: 0 Number of Processors: 4 Processor Type: x86 Family 6 Model 42 Stepping 7 Windows Version: 5.1 Current Build: 2600 Service Pack: 3 Current Type: Multiprocessor Free *----> Task List <----* 0 System Process 4 System 644 smss.exe 700 csrss.exe 724 winlogon.exe 768 services.exe 780 lsass.exe 964 svchost.exe 1052 svchost.exe 1172 svchost.exe 1292 svchost.exe 1328 svchost.exe 1468 spoolsv.exe 1564 svchost.exe 1700 jqs.exe 1720 LMS.exe 1808 UNS.exe 1244 alg.exe 1008 drwtsn32.exe *----> Module List <----* (0000000000970000 - 0000000000987000: C:\WINDOWS\system32\odbcint.dll (0000000001000000 - 0000000001081000: \??\C:\WINDOWS\system32\winlogon.exe (0000000001220000 - 000000000125c000: C:\WINDOWS\system32\WgaLogon.dll (0000000001660000 - 0000000001925000: C:\WINDOWS\system32\xpsp2res.dll (000000003dfd0000 - 000000003e1bb000: C:\WINDOWS\system32\iertutil.dll (000000003e1c0000 - 000000003ec5c000: C:\WINDOWS\system32\ieframe.dll (0000000047020000 - 0000000047028000: C:\WINDOWS\System32\dimsntfy.dll (000000004d4f0000 - 000000004d549000: C:\WINDOWS\system32\WINHTTP.dll (000000005ad70000 - 000000005ada8000: C:\WINDOWS\system32\uxtheme.dll (000000005b860000 - 000000005b8b5000: C:\WINDOWS\system32\NETAPI32.dll (000000005d090000 - 000000005d12a000: C:\WINDOWS\system32\COMCTL32.dll (0000000065000000 - 000000006502e000: C:\WINDOWS\system32\ADVPACK.dll (00000000662b0000 - 0000000066308000: C:\WINDOWS\system32\hnetcfg.dll (0000000068000000 - 0000000068036000: C:\WINDOWS\system32\rsaenh.dll (0000000071a50000 - 0000000071a8f000: C:\WINDOWS\System32\mswsock.dll (0000000071a90000 - 0000000071a98000: C:\WINDOWS\System32\wshtcpip.dll (0000000071aa0000 - 0000000071aa8000: C:\WINDOWS\system32\WS2HELP.dll (0000000071ab0000 - 0000000071ac7000: C:\WINDOWS\system32\WS2_32.dll (0000000071ad0000 - 0000000071ad9000: C:\WINDOWS\system32\wsock32.dll (0000000071b20000 - 0000000071b32000: C:\WINDOWS\system32\MPR.dll (0000000071bf0000 - 0000000071c03000: C:\WINDOWS\system32\SAMLIB.dll (0000000071c10000 - 0000000071c1e000: C:\WINDOWS\System32\ntlanman.dll (0000000071c80000 - 0000000071c87000: C:\WINDOWS\System32\NETRAP.dll (0000000071c90000 - 0000000071cd0000: C:\WINDOWS\System32\NETUI1.dll (0000000071cd0000 - 0000000071ce7000: C:\WINDOWS\System32\NETUI0.dll (0000000071cf0000 - 0000000071d3c000: C:\WINDOWS\system32\kerberos.dll (0000000071d40000 - 0000000071d5b000: C:\WINDOWS\system32\actxprxy.dll (00000000722b0000 - 00000000722b5000: C:\WINDOWS\system32\sensapi.dll (00000000723d0000 - 00000000723ec000: C:\WINDOWS\system32\WINSCARD.DLL (0000000073000000 - 0000000073026000: C:\WINDOWS\system32\WINSPOOL.DRV (0000000074290000 - 0000000074294000: C:\WINDOWS\system32\icmp.dll (0000000074320000 - 000000007435d000: C:\WINDOWS\system32\ODBC32.dll (0000000074980000 - 0000000074aa3000: C:\WINDOWS\system32\msxml3.dll (0000000074ed0000 - 0000000074ede000: C:\WINDOWS\system32\wbem\wbemsvc.dll (0000000074ef0000 - 0000000074ef8000: C:\WINDOWS\system32\wbem\wbemprox.dll (0000000075150000 - 0000000075163000: C:\WINDOWS\system32\Cabinet.dll (0000000075290000 - 00000000752c7000: C:\WINDOWS\system32\wbem\wbemcomn.dll (00000000755c0000 - 00000000755ee000: C:\WINDOWS\system32\msctfime.ime (0000000075690000 - 0000000075706000: C:\WINDOWS\system32\wbem\fastprox.dll (0000000075930000 - 000000007593a000: C:\WINDOWS\system32\PROFMAP.dll (0000000075940000 - 0000000075948000: C:\WINDOWS\system32\NDdeApi.dll (0000000075950000 - 000000007596a000: C:\WINDOWS\system32\WlNotify.dll (0000000075970000 - 0000000075a68000: C:\WINDOWS\system32\MSGINA.dll (0000000075e60000 - 0000000075e73000: C:\WINDOWS\system32\cryptnet.dll (0000000075f60000 - 0000000075f67000: C:\WINDOWS\System32\drprov.dll (0000000075f70000 - 0000000075f7a000: C:\WINDOWS\System32\davclnt.dll (0000000076080000 - 00000000760e5000: C:\WINDOWS\system32\MSVCP60.dll (0000000076360000 - 0000000076370000: C:\WINDOWS\system32\WINSTA.dll (0000000076390000 - 00000000763ad000: C:\WINDOWS\system32\IMM32.DLL (00000000763b0000 - 00000000763f9000: C:\WINDOWS\system32\comdlg32.dll (0000000076600000 - 000000007661d000: C:\WINDOWS\system32\cscdll.dll (0000000076780000 - 0000000076789000: C:\WINDOWS\system32\SHFOLDER.dll (0000000076790000 - 000000007679c000: C:\WINDOWS\system32\cryptdll.dll (00000000767a0000 - 00000000767b3000: C:\WINDOWS\system32\NTDSAPI.DLL (00000000769c0000 - 0000000076a74000: C:\WINDOWS\system32\USERENV.dll (0000000076b20000 - 0000000076b31000: C:\WINDOWS\system32\ATL.DLL (0000000076b40000 - 0000000076b6d000: C:\WINDOWS\system32\WINMM.dll (0000000076bb0000 - 0000000076bb5000: C:\WINDOWS\system32\sfc.dll (0000000076bc0000 - 0000000076bcf000: C:\WINDOWS\system32\REGAPI.dll (0000000076bf0000 - 0000000076bfb000: C:\WINDOWS\system32\PSAPI.DLL (0000000076c30000 - 0000000076c5e000: C:\WINDOWS\system32\WINTRUST.dll (0000000076c60000 - 0000000076c8a000: C:\WINDOWS\system32\sfc_os.dll (0000000076c90000 - 0000000076cb8000: C:\WINDOWS\system32\IMAGEHLP.dll (0000000076d40000 - 0000000076d58000: C:\WINDOWS\system32\MPRAPI.dll (0000000076d60000 - 0000000076d79000: C:\WINDOWS\system32\iphlpapi.dll (0000000076e10000 - 0000000076e35000: C:\WINDOWS\system32\adsldpc.dll (0000000076e80000 - 0000000076e8e000: C:\WINDOWS\system32\rtutils.dll (0000000076e90000 - 0000000076ea2000: C:\WINDOWS\system32\rasman.dll (0000000076eb0000 - 0000000076edf000: C:\WINDOWS\system32\TAPI32.dll (0000000076ee0000 - 0000000076f1c000: C:\WINDOWS\system32\RASAPI32.dll (0000000076f20000 - 0000000076f47000: C:\WINDOWS\system32\DNSAPI.dll (0000000076f50000 - 0000000076f58000: C:\WINDOWS\system32\WTSAPI32.dll (0000000076f60000 - 0000000076f8c000: C:\WINDOWS\system32\WLDAP32.dll (0000000076fd0000 - 000000007704f000: C:\WINDOWS\system32\CLBCATQ.DLL (0000000077050000 - 0000000077115000: C:\WINDOWS\system32\COMRes.dll (0000000077120000 - 00000000771ab000: C:\WINDOWS\system32\OLEAUT32.dll (00000000773d0000 - 00000000774d3000: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (00000000774e0000 - 000000007761e000: C:\WINDOWS\system32\ole32.dll (0000000077690000 - 00000000776b1000: C:\WINDOWS\system32\NTMARTA.DLL (00000000776c0000 - 00000000776d2000: C:\WINDOWS\system32\AUTHZ.dll (00000000776e0000 - 0000000077703000: C:\WINDOWS\system32\SHSVCS.dll (0000000077920000 - 0000000077a13000: C:\WINDOWS\system32\SETUPAPI.dll (0000000077a80000 - 0000000077b15000: C:\WINDOWS\system32\CRYPT32.dll (0000000077b20000 - 0000000077b32000: C:\WINDOWS\system32\MSASN1.dll (0000000077b40000 - 0000000077b62000: C:\WINDOWS\system32\Apphelp.dll (0000000077c00000 - 0000000077c08000: C:\WINDOWS\system32\VERSION.dll (0000000077c10000 - 0000000077c68000: C:\WINDOWS\system32\msvcrt.dll (0000000077c70000 - 0000000077c95000: C:\WINDOWS\system32\msv1_0.dll (0000000077cc0000 - 0000000077cf2000: C:\WINDOWS\system32\ACTIVEDS.dll (0000000077dd0000 - 0000000077e6b000: C:\WINDOWS\system32\ADVAPI32.dll (0000000077e70000 - 0000000077f03000: C:\WINDOWS\system32\RPCRT4.dll (0000000077f10000 - 0000000077f59000: C:\WINDOWS\system32\GDI32.dll (0000000077f60000 - 0000000077fd6000: C:\WINDOWS\system32\SHLWAPI.dll (0000000077fe0000 - 0000000077ff1000: C:\WINDOWS\system32\Secur32.dll (0000000078130000 - 0000000078263000: C:\WINDOWS\system32\urlmon.dll (000000007c800000 - 000000007c8f6000: C:\WINDOWS\system32\kernel32.dll (000000007c900000 - 000000007c9b2000: C:\WINDOWS\system32\ntdll.dll (000000007c9c0000 - 000000007d1d7000: C:\WINDOWS\system32\SHELL32.dll (000000007e410000 - 000000007e4a1000: C:\WINDOWS\system32\USER32.dll (000000007e720000 - 000000007e7d0000: C:\WINDOWS\system32\sxs.dll *----> State Dump for Thread Id 0x2d8 <----* eax=01072ab4 ebx=00f805d8 ecx=00000050 edx=01072ab4 esi=00000818 edi=00000000 eip=7c90e514 esp=0006fc34 ebp=0006fc98 iopl=0 nv up ei ng nz ac po cy cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000297 *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\ntdll.dll - function: ntdll!KiFastSystemCallRet 7c90e4fa e829000000 call ntdll!RtlRaiseException (7c90e528) 7c90e4ff 8b0424 mov eax,[esp] 7c90e502 8be5 mov esp,ebp 7c90e504 5d pop ebp 7c90e505 c3 ret 7c90e506 8da42400000000 lea esp,[esp] 7c90e50d 8d4900 lea ecx,[ecx] ntdll!KiFastSystemCall: 7c90e510 8bd4 mov edx,esp 7c90e512 0f34 sysenter ntdll!KiFastSystemCallRet: 7c90e514 c3 ret 7c90e515 8da42400000000 lea esp,[esp] 7c90e51c 8d642400 lea esp,[esp] ntdll!KiIntSystemCall: 7c90e520 8d542408 lea edx,[esp+0x8] 7c90e524 cd2e int 2e 7c90e526 c3 ret 7c90e527 90 nop ntdll!RtlRaiseException: 7c90e528 55 push ebp 7c90e529 8bec mov ebp,esp *----> Stack Back Trace <----* *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\kernel32.dll - WARNING: Stack unwind information not available. Following frames may be wrong. *** ERROR: Module load completed but symbols could not be loaded for \??\C:\WINDOWS\system32\winlogon.exe ChildEBP RetAddr Args to Child 0006fc98 7c802542 00000818 00001388 00000000 ntdll!KiFastSystemCallRet 0006fcac 0103a0a7 00000818 00001388 00000000 kernel32!WaitForSingleObject+0x12 0006fcd4 01038a08 000795e8 00000000 000795e8 winlogon+0x3a0a7 0006fcfc 01031c7e 000795e8 7c80b741 00000000 winlogon+0x38a08 0006ff50 0103e75e 01000000 00000000 00072364 winlogon+0x31c7e 0006fff4 00000000 7ffd6000 000000c8 000001b0 winlogon+0x3e75e *----> Raw Stack Dump <----* 000000000006fc34 5a df 90 7c db 25 80 7c - 18 08 00 00 00 00 00 00 Z..|.%.|........ 000000000006fc44 68 fc 06 00 14 00 00 00 - 18 23 13 00 d8 05 f8 00 h........#...... 000000000006fc54 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................ 000000000006fc64 10 00 00 00 80 0f 05 fd - ff ff ff ff 00 60 fd 7f .............`.. 000000000006fc74 00 f0 fd 7f 68 fc 06 00 - 02 01 00 00 48 fc 06 00 ....h.......H... 000000000006fc84 00 00 00 00 e4 ff 06 00 - d8 9a 83 7c 08 26 80 7c ...........|.&.| 000000000006fc94 00 00 00 00 ac fc 06 00 - 42 25 80 7c 18 08 00 00 ........B%.|.... 000000000006fca4 88 13 00 00 00 00 00 00 - d4 fc 06 00 a7 a0 03 01 ................ 000000000006fcb4 18 08 00 00 88 13 00 00 - 00 00 00 00 02 00 00 00 ................ 000000000006fcc4 e8 95 07 00 9c 06 00 00 - 01 00 00 00 18 08 00 00 ................ 000000000006fcd4 fc fc 06 00 08 8a 03 01 - e8 95 07 00 00 00 00 00 ................ 000000000006fce4 e8 95 07 00 64 23 07 00 - 00 00 00 00 00 00 00 00 ....d#.......... 000000000006fcf4 01 00 00 00 50 ff 06 00 - 50 ff 06 00 7e 1c 03 01 ....P...P...~... 000000000006fd04 e8 95 07 00 41 b7 80 7c - 00 00 00 00 08 99 91 7c ....A..|.......| 000000000006fd14 ff ff ff ff 34 30 07 00 - 6c 00 00 00 06 00 00 00 ....40..l....... 000000000006fd24 00 00 00 00 3c 03 00 00 - 28 3e 26 00 00 00 00 00 ....<...(>&..... 000000000006fd34 00 00 00 00 00 00 00 00 - e8 95 07 00 00 00 00 00 ................ 000000000006fd44 00 00 00 00 00 44 93 8a - 78 01 07 00 20 9b 53 80 .....D..x... .S. 000000000006fd54 70 95 4d 80 00 00 00 00 - 00 00 00 00 7c b7 57 80 p.M.........|.W. 000000000006fd64 40 06 07 00 78 4a 1d a8 - 07 00 00 00 40 06 07 00 @...xJ......@... *----> State Dump for Thread Id 0x2ec <----* eax=00000201 ebx=00000000 ecx=00000210 edx=001ed36e esi=00081bb8 edi=00081bf4 eip=7c90e514 esp=00bafe18 ebp=00baff80 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 function: ntdll!KiFastSystemCallRet 7c90e4fa e829000000 call ntdll!RtlRaiseException (7c90e528) 7c90e4ff 8b0424 mov eax,[esp] 7c90e502 8be5 mov esp,ebp 7c90e504 5d pop ebp 7c90e505 c3 ret 7c90e506 8da42400000000 lea esp,[esp] 7c90e50d 8d4900 lea ecx,[ecx] ntdll!KiFastSystemCall: 7c90e510 8bd4 mov edx,esp 7c90e512 0f34 sysenter ntdll!KiFastSystemCallRet: 7c90e514 c3 ret 7c90e515 8da42400000000 lea esp,[esp] 7c90e51c 8d642400 lea esp,[esp] ntdll!KiIntSystemCall: 7c90e520 8d542408 lea edx,[esp+0x8] 7c90e524 cd2e int 2e 7c90e526 c3 ret 7c90e527 90 nop ntdll!RtlRaiseException: 7c90e528 55 push ebp 7c90e529 8bec mov ebp,esp *----> Stack Back Trace <----* *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\RPCRT4.dll - WARNING: Stack unwind information not available. Following frames may be wrong. ChildEBP RetAddr Args to Child 00baff80 77e76caf 00baffa8 77e76ad1 00081bb8 ntdll!KiFastSystemCallRet 00baff88 77e76ad1 00081bb8 7c90e920 0006f688 RPCRT4!I_RpcBCacheFree+0x61c 00baffa8 77e76c97 000817f8 00baffec 7c80b729 RPCRT4!I_RpcBCacheFree+0x43e 00baffb4 7c80b729 00081da8 7c90e920 0006f688 RPCRT4!I_RpcBCacheFree+0x604 00baffec 00000000 77e76c7d 00081da8 00000000 kernel32!GetModuleFileNameA+0x1ba *----> Raw Stack Dump <----* 0000000000bafe18 aa da 90 7c e3 65 e7 77 - 44 01 00 00 74 ff ba 00 ...|.e.wD...t... 0000000000bafe28 00 00 00 00 88 20 08 00 - 00 00 00 00 00 00 00 00 ..... .......... 0000000000bafe38 28 00 40 00 00 00 00 00 - 00 03 00 00 b4 00 00 00 (.@............. 0000000000bafe48 7f 08 00 00 00 00 00 00 - 02 56 df e1 01 00 1d a8 .........V...... 0000000000bafe58 96 d1 5b 80 e0 fe b3 8a - 40 00 00 00 70 ce e5 8a ..[.....@...p... 0000000000bafe68 bc 4b 1d a8 e8 38 df 8a - 00 00 00 00 00 00 00 00 .K...8.......... 0000000000bafe78 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000bafe88 00 00 00 00 38 52 dc e1 - 00 00 00 00 64 4b 1d a8 ....8R......dK.. 0000000000bafe98 01 00 00 00 06 00 00 00 - 43 7d 6e 80 28 4c 1d a8 ........C}n.(L.. 0000000000bafea8 27 74 6e 80 00 0d db ba - 00 00 00 00 f0 67 95 e1 'tn..........g.. 0000000000bafeb8 34 00 00 00 00 30 88 c0 - d0 00 00 00 21 12 41 7e 4....0......!.A~ 0000000000bafec8 b8 f8 3b 00 e8 11 e1 8a - ac 4b 1d a8 c7 f0 53 80 ..;......K....S. 0000000000bafed8 bc 4b 1d a8 04 00 00 00 - 00 00 00 00 00 00 00 00 .K.............. 0000000000bafee8 00 00 00 00 1f 00 00 00 - ff ff ff ff 40 f5 df ff ............@... 0000000000bafef8 00 00 00 00 10 74 6e 80 - 3c 6f 8a 8a 28 4c 1d a8 .....tn. State Dump for Thread Id 0x2f4 <----* eax=000000c0 ebx=00000000 ecx=7c90d96e edx=0006f468 esi=7c90f65c edi=0006f424 eip=7c90e514 esp=00c2ff9c ebp=00c2ffb4 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 function: ntdll!KiFastSystemCallRet 7c90e4fa e829000000 call ntdll!RtlRaiseException (7c90e528) 7c90e4ff 8b0424 mov eax,[esp] 7c90e502 8be5 mov esp,ebp 7c90e504 5d pop ebp 7c90e505 c3 ret 7c90e506 8da42400000000 lea esp,[esp] 7c90e50d 8d4900 lea ecx,[ecx] ntdll!KiFastSystemCall: 7c90e510 8bd4 mov edx,esp 7c90e512 0f34 sysenter ntdll!KiFastSystemCallRet: 7c90e514 c3 ret 7c90e515 8da42400000000 lea esp,[esp] 7c90e51c 8d642400 lea esp,[esp] ntdll!KiIntSystemCall: 7c90e520 8d542408 lea edx,[esp+0x8] 7c90e524 cd2e int 2e 7c90e526 c3 ret 7c90e527 90 nop ntdll!RtlRaiseException: 7c90e528 55 push ebp 7c90e529 8bec mov ebp,esp *----> Stack Back Trace <----* WARNING: Stack unwind information not available. Following frames may be wrong. ChildEBP RetAddr Args to Child 00c2ffb4 7c80b729 00000000 0006f424 7c90f65c ntdll!KiFastSystemCallRet 00c2ffec 00000000 7c927d83 00000000 00000000 kernel32!GetModuleFileNameA+0x1ba *----> Raw Stack Dump <----* 0000000000c2ff9c 1a d2 90 7c ca 7d 92 7c - 01 00 00 00 ac ff c2 00 ...|.}.|........ 0000000000c2ffac 00 00 00 00 00 00 00 80 - ec ff c2 00 29 b7 80 7c ............)..| 0000000000c2ffbc 00 00 00 00 24 f4 06 00 - 5c f6 90 7c 00 00 00 00 ....$...\..|.... 0000000000c2ffcc 00 b0 fd 7f 00 16 e6 8a - c0 ff c2 00 58 be b2 8a ............X... 0000000000c2ffdc ff ff ff ff d8 9a 83 7c - 30 b7 80 7c 00 00 00 00 .......|0..|.... 0000000000c2ffec 00 00 00 00 00 00 00 00 - 83 7d 92 7c 00 00 00 00 .........}.|.... 0000000000c2fffc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000c3000c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000c3001c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000c3002c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000c3003c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000c3004c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000c3005c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000c3006c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000c3007c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000c3008c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000c3009c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000c300ac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000c300bc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000c300cc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ *----> State Dump for Thread Id 0x2f8 <----* eax=000205b8 ebx=00000000 ecx=77de6d15 edx=00740002 esi=7c97e440 edi=7c97e460 eip=7c90e514 esp=00c6ff70 ebp=00c6ffb4 iopl=0 nv up ei ng nz na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000286 function: ntdll!KiFastSystemCallRet 7c90e4fa e829000000 call ntdll!RtlRaiseException (7c90e528) 7c90e4ff 8b0424 mov eax,[esp] 7c90e502 8be5 mov esp,ebp 7c90e504 5d pop ebp 7c90e505 c3 ret 7c90e506 8da42400000000 lea esp,[esp] 7c90e50d 8d4900 lea ecx,[ecx] ntdll!KiFastSystemCall: 7c90e510 8bd4 mov edx,esp 7c90e512 0f34 sysenter ntdll!KiFastSystemCallRet: 7c90e514 c3 ret 7c90e515 8da42400000000 lea esp,[esp] 7c90e51c 8d642400 lea esp,[esp] ntdll!KiIntSystemCall: 7c90e520 8d542408 lea edx,[esp+0x8] 7c90e524 cd2e int 2e 7c90e526 c3 ret 7c90e527 90 nop ntdll!RtlRaiseException: 7c90e528 55 push ebp 7c90e529 8bec mov ebp,esp *----> Stack Back Trace <----* WARNING: Stack unwind information not available. Following frames may be wrong. ChildEBP RetAddr Args to Child 00c6ffb4 7c80b729 00000000 0006f424 7c90f65c ntdll!KiFastSystemCallRet 00c6ffec 00000000 7c910250 00000000 00000000 kernel32!GetModuleFileNameA+0x1ba *----> Raw Stack Dump <----* 0000000000c6ff70 4a da 90 7c 8d 02 91 7c - 6c 01 00 00 ac ff c6 00 J..|...|l....... 0000000000c6ff80 b0 ff c6 00 98 ff c6 00 - a0 ff c6 00 24 f4 06 00 ............$... 0000000000c6ff90 5c f6 90 7c 00 00 00 00 - 00 00 00 00 10 fd f9 00 \..|............ 0000000000c6ffa0 00 7c 28 e8 ff ff ff ff - a0 cc 1b a8 91 79 92 7c .|(..........y.| 0000000000c6ffb0 18 f6 f9 00 ec ff c6 00 - 29 b7 80 7c 00 00 00 00 ........)..|.... 0000000000c6ffc0 24 f4 06 00 5c f6 90 7c - 00 00 00 00 00 a0 fd 7f $...\..|........ 0000000000c6ffd0 00 16 e6 8a c0 ff c6 00 - 50 f1 b0 8a ff ff ff ff ........P....... 0000000000c6ffe0 d8 9a 83 7c 30 b7 80 7c - 00 00 00 00 00 00 00 00 ...|0..|........ 0000000000c6fff0 00 00 00 00 50 02 91 7c - 00 00 00 00 00 00 00 00 ....P..|........ 0000000000c70000 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000c70010 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000c70020 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000c70030 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000c70040 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000c70050 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000c70060 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000c70070 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000c70080 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000c70090 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000c700a0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ *----> State Dump for Thread Id 0x2fc <----* eax=0007e150 ebx=00000000 ecx=00000000 edx=00000002 esi=00f8a158 edi=00000100 eip=7c90e514 esp=00cafe18 ebp=00caff80 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 function: ntdll!KiFastSystemCallRet 7c90e4fa e829000000 call ntdll!RtlRaiseException (7c90e528) 7c90e4ff 8b0424 mov eax,[esp] 7c90e502 8be5 mov esp,ebp 7c90e504 5d pop ebp 7c90e505 c3 ret 7c90e506 8da42400000000 lea esp,[esp] 7c90e50d 8d4900 lea ecx,[ecx] ntdll!KiFastSystemCall: 7c90e510 8bd4 mov edx,esp 7c90e512 0f34 sysenter ntdll!KiFastSystemCallRet: 7c90e514 c3 ret 7c90e515 8da42400000000 lea esp,[esp] 7c90e51c 8d642400 lea esp,[esp] ntdll!KiIntSystemCall: 7c90e520 8d542408 lea edx,[esp+0x8] 7c90e524 cd2e int 2e 7c90e526 c3 ret 7c90e527 90 nop ntdll!RtlRaiseException: 7c90e528 55 push ebp 7c90e529 8bec mov ebp,esp *----> Stack Back Trace <----* WARNING: Stack unwind information not available. Following frames may be wrong. ChildEBP RetAddr Args to Child 00caff80 77e76caf 00caffa8 77e76ad1 00f8a158 ntdll!KiFastSystemCallRet 00caff88 77e76ad1 00f8a158 00000008 000a0008 RPCRT4!I_RpcBCacheFree+0x61c 00caffa8 77e76c97 000817f8 00caffec 7c80b729 RPCRT4!I_RpcBCacheFree+0x43e 00caffb4 7c80b729 00083a68 00000008 000a0008 RPCRT4!I_RpcBCacheFree+0x604 00caffec 00000000 77e76c7d 00083a68 00000000 kernel32!GetModuleFileNameA+0x1ba *----> Raw Stack Dump <----* 0000000000cafe18 aa da 90 7c e3 65 e7 77 - ac 08 00 00 74 ff ca 00 ...|.e.w....t... 0000000000cafe28 00 00 00 00 90 23 08 00 - 50 ff ca 00 00 00 00 00 .....#..P....... 0000000000cafe38 60 4a 08 00 60 4a 08 00 - 28 9f f6 00 00 04 00 00 `J..`J..(....... 0000000000cafe48 54 fe ca 00 00 00 00 00 - 2c 4a 08 00 00 00 00 00 T.......,J...... 0000000000cafe58 00 00 00 00 84 fe ca 00 - 58 1f e8 77 f0 06 00 00 ........X..w.... 0000000000cafe68 28 9f f6 00 00 04 00 00 - 64 1f e8 77 4c 4a 08 00 (.......d..wLJ.. 0000000000cafe78 01 00 00 80 00 00 00 00 - 2c 4a 08 00 98 fe ca 00 ........,J...... 0000000000cafe88 e5 1e e8 77 60 00 00 00 - 28 9f f6 00 98 48 08 00 ...w`...(....H.. 0000000000cafe98 00 ff ca 00 a9 1d e8 77 - 54 80 e7 77 a4 48 08 00 .......wT..w.H.. 0000000000cafea8 98 48 08 00 4a da 90 7c - e6 a7 80 7c 00 00 00 00 .H..J..|...|.... 0000000000cafeb8 68 30 08 00 d8 fe ca 00 - 2c a8 80 7c 02 01 00 00 h0......,..|.... 0000000000cafec8 00 5d 1e ee ff ff ff ff - 24 bc f5 00 48 00 00 00 .]......$...H... 0000000000cafed8 14 ff ca 00 5c 71 e7 77 - 70 01 00 00 10 ff ca 00 ....\q.wp....... 0000000000cafee8 00 ff ca 00 08 ff ca 00 - 3d 73 e7 77 1a 98 80 7c ........=s.w...| 0000000000cafef8 68 30 08 00 70 32 08 00 - 14 ff ca 00 70 01 00 00 h0..p2......p... 0000000000caff08 00 00 00 00 28 9f f6 00 - 3c 9f f6 00 80 ff ca 00 ....(...<....... 0000000000caff18 a0 72 e7 77 22 67 e7 77 - fe 79 e7 77 18 30 08 00 .r.w"g.w.y.w.0.. 0000000000caff28 68 30 08 00 80 ff ca 00 - 85 d1 e7 77 48 ff ca 00 h0.........wH... 0000000000caff38 95 d1 e7 77 e0 10 90 7c - 40 3a 08 00 68 3a 08 00 ...w...|@:..h:.. 0000000000caff48 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff ../M.....]...... *----> State Dump for Thread Id 0x308 <----* eax=000000c0 ebx=00000000 ecx=7c91019b edx=7c910222 esi=00000000 edi=00000001 eip=7c90e514 esp=00cefcec ebp=00ceffb4 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 function: ntdll!KiFastSystemCallRet 7c90e4fa e829000000 call ntdll!RtlRaiseException (7c90e528) 7c90e4ff 8b0424 mov eax,[esp] 7c90e502 8be5 mov esp,ebp 7c90e504 5d pop ebp 7c90e505 c3 ret 7c90e506 8da42400000000 lea esp,[esp] 7c90e50d 8d4900 lea ecx,[ecx] ntdll!KiFastSystemCall: 7c90e510 8bd4 mov edx,esp 7c90e512 0f34 sysenter ntdll!KiFastSystemCallRet: 7c90e514 c3 ret 7c90e515 8da42400000000 lea esp,[esp] 7c90e51c 8d642400 lea esp,[esp] ntdll!KiIntSystemCall: 7c90e520 8d542408 lea edx,[esp+0x8] 7c90e524 cd2e int 2e 7c90e526 c3 ret 7c90e527 90 nop ntdll!RtlRaiseException: 7c90e528 55 push ebp 7c90e529 8bec mov ebp,esp *----> Stack Back Trace <----* WARNING: Stack unwind information not available. Following frames may be wrong. ChildEBP RetAddr Args to Child 00ceffb4 7c80b729 00000000 7c90e920 7c910228 ntdll!KiFastSystemCallRet 00ceffec 00000000 7c92a3f3 00000000 00000000 kernel32!GetModuleFileNameA+0x1ba *----> Raw Stack Dump <----* 0000000000cefcec 4a df 90 7c 1a a5 92 7c - 0e 00 00 00 30 fd ce 00 J..|...|....0... 0000000000cefcfc 01 00 00 00 01 00 00 00 - 00 00 00 00 20 e9 90 7c ............ ..| 0000000000cefd0c 28 02 91 7c 00 00 00 00 - a0 f9 97 7c a0 f9 97 7c (..|.......|...| 0000000000cefd1c a8 01 00 00 08 03 00 00 - 0e 00 00 00 0e 00 00 00 ................ 0000000000cefd2c 0d 00 00 00 ac 01 00 00 - b0 01 00 00 bc 01 00 00 ................ 0000000000cefd3c e0 05 00 00 ac 02 00 00 - f0 05 00 00 14 06 00 00 ................ 0000000000cefd4c e8 06 00 00 70 07 00 00 - 3c 07 00 00 e0 07 00 00 ....p...<....... 0000000000cefd5c 6c 06 00 00 14 01 00 00 - dc 07 00 00 00 00 00 00 l............... 0000000000cefd6c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000cefd7c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000cefd8c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000cefd9c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000cefdac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000cefdbc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000cefdcc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000cefddc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000cefdec 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000cefdfc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000cefe0c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000cefe1c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ *----> State Dump for Thread Id 0x380 <----* eax=00f5a000 ebx=00000002 ecx=00fffb88 edx=00001000 esi=76c629b8 edi=00000000 eip=7c90e514 esp=00ffff64 ebp=00ffffb4 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 function: ntdll!KiFastSystemCallRet 7c90e4fa e829000000 call ntdll!RtlRaiseException (7c90e528) 7c90e4ff 8b0424 mov eax,[esp] 7c90e502 8be5 mov esp,ebp 7c90e504 5d pop ebp 7c90e505 c3 ret 7c90e506 8da42400000000 lea esp,[esp] 7c90e50d 8d4900 lea ecx,[ecx] ntdll!KiFastSystemCall: 7c90e510 8bd4 mov edx,esp 7c90e512 0f34 sysenter ntdll!KiFastSystemCallRet: 7c90e514 c3 ret 7c90e515 8da42400000000 lea esp,[esp] 7c90e51c 8d642400 lea esp,[esp] ntdll!KiIntSystemCall: 7c90e520 8d542408 lea edx,[esp+0x8] 7c90e524 cd2e int 2e 7c90e526 c3 ret 7c90e527 90 nop ntdll!RtlRaiseException: 7c90e528 55 push ebp 7c90e529 8bec mov ebp,esp *----> Stack Back Trace <----* WARNING: Stack unwind information not available. Following frames may be wrong. ChildEBP RetAddr Args to Child 00ffffb4 7c80b729 00000000 00ee0920 00000016 ntdll!KiFastSystemCallRet 00ffffec 00000000 76c6c80b 00000000 00000000 kernel32!GetModuleFileNameA+0x1ba *----> Raw Stack Dump <----* 0000000000ffff64 4a df 90 7c d9 cb c6 76 - 02 00 00 00 f8 ff 16 00 J..|...v........ 0000000000ffff74 00 00 00 00 01 00 00 00 - 00 00 00 00 20 09 ee 00 ............ ... 0000000000ffff84 16 00 00 00 00 00 00 00 - 44 56 08 00 80 17 ee 00 ........DV...... 0000000000ffff94 78 17 ee 00 f8 ff 16 00 - 60 17 ee 00 00 00 00 00 x.......`....... 0000000000ffffa4 58 17 ee 00 40 56 08 00 - 18 0c ee 00 02 00 00 00 X...@V.......... 0000000000ffffb4 ec ff ff 00 29 b7 80 7c - 00 00 00 00 20 09 ee 00 ....)..|.... ... 0000000000ffffc4 16 00 00 00 00 00 00 00 - 00 e0 fd 7f 00 56 e6 8a .............V.. 0000000000ffffd4 c0 ff ff 00 38 51 8b 8a - ff ff ff ff d8 9a 83 7c ....8Q.........| 0000000000ffffe4 30 b7 80 7c 00 00 00 00 - 00 00 00 00 00 00 00 00 0..|............ 0000000000fffff4 0b c8 c6 76 00 00 00 00 - 00 00 00 00 4d 5a 90 00 ...v........MZ.. 0000000001000004 03 00 00 00 04 00 00 00 - ff ff 00 00 b8 00 00 00 ................ 0000000001000014 00 00 00 00 40 00 00 00 - 00 00 00 00 00 00 00 00 ....@........... 0000000001000024 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000001000034 00 00 00 00 00 00 00 00 - f0 00 00 00 0e 1f ba 0e ................ 0000000001000044 00 b4 09 cd 21 b8 01 4c - cd 21 54 68 69 73 20 70 ....!..L.!This p 0000000001000054 72 6f 67 72 61 6d 20 63 - 61 6e 6e 6f 74 20 62 65 rogram cannot be 0000000001000064 20 72 75 6e 20 69 6e 20 - 44 4f 53 20 6d 6f 64 65 run in DOS mode 0000000001000074 2e 0d 0d 0a 24 00 00 00 - 00 00 00 00 4d 6f b8 0d ....$.......Mo.. 0000000001000084 09 0e d6 5e 09 0e d6 5e - 09 0e d6 5e b8 01 89 5e ...^...^...^...^ 0000000001000094 2b 0e d6 5e ca 01 d9 5e - 0e 0e d6 5e 09 0e d7 5e +..^...^...^...^ *----> State Dump for Thread Id 0x384 <----* eax=76c6c54e ebx=00ee1760 ecx=00fffc74 edx=7c911028 esi=76c629b8 edi=00000000 eip=7c90e514 esp=00d2ff4c ebp=00d2ffb4 iopl=0 nv up ei pl nz na pe nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202 function: ntdll!KiFastSystemCallRet 7c90e4fa e829000000 call ntdll!RtlRaiseException (7c90e528) 7c90e4ff 8b0424 mov eax,[esp] 7c90e502 8be5 mov esp,ebp 7c90e504 5d pop ebp 7c90e505 c3 ret 7c90e506 8da42400000000 lea esp,[esp] 7c90e50d 8d4900 lea ecx,[ecx] ntdll!KiFastSystemCall: 7c90e510 8bd4 mov edx,esp 7c90e512 0f34 sysenter ntdll!KiFastSystemCallRet: 7c90e514 c3 ret 7c90e515 8da42400000000 lea esp,[esp] 7c90e51c 8d642400 lea esp,[esp] ntdll!KiIntSystemCall: 7c90e520 8d542408 lea edx,[esp+0x8] 7c90e524 cd2e int 2e 7c90e526 c3 ret 7c90e527 90 nop ntdll!RtlRaiseException: 7c90e528 55 push ebp 7c90e529 8bec mov ebp,esp *----> Stack Back Trace <----* WARNING: Stack unwind information not available. Following frames may be wrong. ChildEBP RetAddr Args to Child 00d2ffb4 7c80b729 00f5a380 7c90e920 000001b3 ntdll!KiFastSystemCallRet 00d2ffec 00000000 76c6c54e 00ee1760 00000000 kernel32!GetModuleFileNameA+0x1ba *----> Raw Stack Dump <----* 0000000000d2ff4c 4a df 90 7c ca c7 c6 76 - 40 00 00 00 80 17 ee 00 J..|...v@....... 0000000000d2ff5c 01 00 00 00 01 00 00 00 - 00 00 00 00 20 e9 90 7c ............ ..| 0000000000d2ff6c b3 01 00 00 60 17 ee 00 - 00 00 00 00 01 00 00 00 ....`........... 0000000000d2ff7c 02 00 00 00 04 00 00 00 - 08 00 00 00 10 00 00 00 ................ 0000000000d2ff8c 00 00 00 00 50 9c 7f 8a - 80 2f 50 80 00 00 00 00 ....P..../P..... 0000000000d2ff9c 00 00 00 00 00 00 00 00 - 00 00 00 00 18 0c ee 00 ................ 0000000000d2ffac 30 0c ee 00 1b 00 00 00 - ec ff d2 00 29 b7 80 7c 0...........)..| 0000000000d2ffbc 80 a3 f5 00 20 e9 90 7c - b3 01 00 00 60 17 ee 00 .... ..|....`... 0000000000d2ffcc 00 70 fd 7f 00 f6 e5 8a - c0 ff d2 00 38 51 8b 8a .p..........8Q.. 0000000000d2ffdc ff ff ff ff d8 9a 83 7c - 30 b7 80 7c 00 00 00 00 .......|0..|.... 0000000000d2ffec 00 00 00 00 00 00 00 00 - 4e c5 c6 76 60 17 ee 00 ........N..v`... 0000000000d2fffc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000d3000c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000d3001c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000d3002c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000d3003c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000d3004c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000d3005c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000d3006c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000000d3007c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ *----> State Dump for Thread Id 0x388 <----* eax=76c6c54e ebx=00ee176c ecx=00fffc74 edx=7c911028 esi=76c629b8 edi=00f5aba8 eip=7c90e514 esp=010cff4c ebp=010cffb4 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 function: ntdll!KiFastSystemCallRet 7c90e4fa e829000000 call ntdll!RtlRaiseException (7c90e528) 7c90e4ff 8b0424 mov eax,[esp] 7c90e502 8be5 mov esp,ebp 7c90e504 5d pop ebp 7c90e505 c3 ret 7c90e506 8da42400000000 lea esp,[esp] 7c90e50d 8d4900 lea ecx,[ecx] ntdll!KiFastSystemCall: 7c90e510 8bd4 mov edx,esp 7c90e512 0f34 sysenter ntdll!KiFastSystemCallRet: 7c90e514 c3 ret 7c90e515 8da42400000000 lea esp,[esp] 7c90e51c 8d642400 lea esp,[esp] ntdll!KiIntSystemCall: 7c90e520 8d542408 lea edx,[esp+0x8] 7c90e524 cd2e int 2e 7c90e526 c3 ret 7c90e527 90 nop ntdll!RtlRaiseException: 7c90e528 55 push ebp 7c90e529 8bec mov ebp,esp *----> Stack Back Trace <----* WARNING: Stack unwind information not available. Following frames may be wrong. ChildEBP RetAddr Args to Child 010cffb4 7c80b729 00f5a798 7c90e920 000001b3 ntdll!KiFastSystemCallRet 010cffec 00000000 76c6c54e 00ee176c 00000000 kernel32!GetModuleFileNameA+0x1ba *----> Raw Stack Dump <----* 00000000010cff4c 4a df 90 7c ca c7 c6 76 - 3a 00 00 00 88 18 ee 00 J..|...v:....... 00000000010cff5c 01 00 00 00 01 00 00 00 - 00 00 00 00 20 e9 90 7c ............ ..| 00000000010cff6c b3 01 00 00 6c 17 ee 00 - 00 00 00 00 01 00 00 00 ....l........... 00000000010cff7c 02 00 00 00 04 00 00 00 - 08 00 00 00 10 00 00 00 ................ 00000000010cff8c 00 00 00 00 50 9c 7f 8a - 80 2f 50 80 00 00 00 00 ....P..../P..... 00000000010cff9c 00 00 00 00 00 00 00 00 - 88 2f 50 80 00 12 ee 00 ........./P..... 00000000010cffac f2 7e 6e 80 1a da 90 7c - ec ff 0c 01 29 b7 80 7c .~n....|....)..| 00000000010cffbc 98 a7 f5 00 20 e9 90 7c - b3 01 00 00 6c 17 ee 00 .... ..|....l... 00000000010cffcc 00 40 fd 7f 00 16 e6 8a - c0 ff 0c 01 60 d2 d1 8a .@..........`... 00000000010cffdc ff ff ff ff d8 9a 83 7c - 30 b7 80 7c 00 00 00 00 .......|0..|.... 00000000010cffec 00 00 00 00 00 00 00 00 - 4e c5 c6 76 6c 17 ee 00 ........N..vl... 00000000010cfffc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 00000000010d000c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 00000000010d001c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 00000000010d002c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 00000000010d003c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 00000000010d004c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 00000000010d005c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 00000000010d006c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 00000000010d007c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ *----> State Dump for Thread Id 0x580 <----* eax=003f9808 ebx=0121fe78 ecx=00000000 edx=0121fc60 esi=00000000 edi=7ffd6000 eip=7c90e514 esp=0121fe50 ebp=0121feec iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 function: ntdll!KiFastSystemCallRet 7c90e4fa e829000000 call ntdll!RtlRaiseException (7c90e528) 7c90e4ff 8b0424 mov eax,[esp] 7c90e502 8be5 mov esp,ebp 7c90e504 5d pop ebp 7c90e505 c3 ret 7c90e506 8da42400000000 lea esp,[esp] 7c90e50d 8d4900 lea ecx,[ecx] ntdll!KiFastSystemCall: 7c90e510 8bd4 mov edx,esp 7c90e512 0f34 sysenter ntdll!KiFastSystemCallRet: 7c90e514 c3 ret 7c90e515 8da42400000000 lea esp,[esp] 7c90e51c 8d642400 lea esp,[esp] ntdll!KiIntSystemCall: 7c90e520 8d542408 lea edx,[esp+0x8] 7c90e524 cd2e int 2e 7c90e526 c3 ret 7c90e527 90 nop ntdll!RtlRaiseException: 7c90e528 55 push ebp 7c90e529 8bec mov ebp,esp *----> Stack Back Trace <----* WARNING: Stack unwind information not available. Following frames may be wrong. *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\cscdll.dll - ChildEBP RetAddr Args to Child 0121feec 7c80a115 00000004 0121ff2c 00000000 ntdll!KiFastSystemCallRet 0121ff08 76601fb9 00000004 0121ff2c 00000000 kernel32!WaitForMultipleObjects+0x18 0121ff3c 76603267 00527ca3 00523e04 00000000 cscdll!WinlogonStartShellEvent+0x13f 0121ff54 7660323b 00000000 01039f18 0121ff74 cscdll!MprServiceProc+0x1b 0121ffb4 7c80b729 00087138 0006fb74 00000023 cscdll!WinlogonStartupEvent+0x40 0121ffec 00000000 01039e58 00087138 00000000 kernel32!GetModuleFileNameA+0x1ba *----> Raw Stack Dump <----* 000000000121fe50 4a df 90 7c 90 95 80 7c - 04 00 00 00 78 fe 21 01 J..|...|....x.!. 000000000121fe60 01 00 00 00 00 00 00 00 - 00 00 00 00 e3 54 49 00 .............TI. 000000000121fe70 00 00 00 00 4a 93 80 7c - f8 00 00 00 7c 06 00 00 ....J..|....|... 000000000121fe80 80 06 00 00 8c 06 00 00 - 50 0b 81 7c ff ff ff ff ........P..|.... 000000000121fe90 98 16 80 7c 37 22 60 76 - 14 00 00 00 01 00 00 00 ...|7"`v........ 000000000121fea0 00 00 00 00 00 00 00 00 - 10 00 00 00 c7 a0 80 7c ...............| 000000000121feb0 fc 00 00 00 00 00 00 00 - 00 60 fd 7f 00 c0 fa 7f .........`...... 000000000121fec0 1d 3b 60 76 00 00 00 00 - 78 fe 21 01 e3 54 49 00 .;`v....x.!..TI. 000000000121fed0 04 00 00 00 6c fe 21 01 - 00 01 00 00 a4 ff 21 01 ....l.!.......!. 000000000121fee0 d8 9a 83 7c 80 96 80 7c - 00 00 00 00 08 ff 21 01 ...|...|......!. 000000000121fef0 15 a1 80 7c 04 00 00 00 - 2c ff 21 01 00 00 00 00 ...|....,.!..... 000000000121ff00 ff ff ff ff 00 00 00 00 - 3c ff 21 01 b9 1f 60 76 ........<.!...`v 000000000121ff10 04 00 00 00 2c ff 21 01 - 00 00 00 00 ff ff ff ff ....,.!......... 000000000121ff20 38 71 08 00 00 00 00 00 - c8 2f 07 00 f8 00 00 00 8q......./...... 000000000121ff30 7c 06 00 00 80 06 00 00 - 8c 06 00 00 54 ff 21 01 |...........T.!. 000000000121ff40 67 32 60 76 a3 7c 52 00 - 04 3e 52 00 00 00 00 00 g2`v.|R..>R..... 000000000121ff50 05 00 00 00 b4 ff 21 01 - 3b 32 60 76 00 00 00 00 ......!.;2`v.... 000000000121ff60 18 9f 03 01 74 ff 21 01 - 74 fb 06 00 23 00 00 00 ....t.!.t...#... 000000000121ff70 38 71 08 00 20 00 00 00 - 00 00 00 00 00 00 00 00 8q.. ........... 000000000121ff80 00 00 00 00 a0 30 07 00 - 00 00 00 00 ac 00 00 00 .....0.......... *----> State Dump for Thread Id 0x588 <----* eax=00000102 ebx=0129fee8 ecx=7c802600 edx=7c90e514 esi=00000000 edi=7ffd6000 eip=7c90e514 esp=0129fec0 ebp=0129ff5c iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 function: ntdll!KiFastSystemCallRet 7c90e4fa e829000000 call ntdll!RtlRaiseException (7c90e528) 7c90e4ff 8b0424 mov eax,[esp] 7c90e502 8be5 mov esp,ebp 7c90e504 5d pop ebp 7c90e505 c3 ret 7c90e506 8da42400000000 lea esp,[esp] 7c90e50d 8d4900 lea ecx,[ecx] ntdll!KiFastSystemCall: 7c90e510 8bd4 mov edx,esp 7c90e512 0f34 sysenter ntdll!KiFastSystemCallRet: 7c90e514 c3 ret 7c90e515 8da42400000000 lea esp,[esp] 7c90e51c 8d642400 lea esp,[esp] ntdll!KiIntSystemCall: 7c90e520 8d542408 lea edx,[esp+0x8] 7c90e524 cd2e int 2e 7c90e526 c3 ret 7c90e527 90 nop ntdll!RtlRaiseException: 7c90e528 55 push ebp 7c90e529 8bec mov ebp,esp *----> Stack Back Trace <----* WARNING: Stack unwind information not available. Following frames may be wrong. ChildEBP RetAddr Args to Child 0129ff5c 7c80a115 00000002 0129ff9c 00000000 ntdll!KiFastSystemCallRet 0129ff78 76602da8 00000002 0129ff9c 00000000 kernel32!WaitForMultipleObjects+0x18 0129ffb4 7c80b729 00000000 00000001 774fd111 cscdll!WinlogonLogonEvent+0x972 0129ffec 00000000 76602d3c 00000000 00000000 kernel32!GetModuleFileNameA+0x1ba *----> Raw Stack Dump <----* 000000000129fec0 4a df 90 7c 90 95 80 7c - 02 00 00 00 e8 fe 29 01 J..|...|......). 000000000129fed0 01 00 00 00 00 00 00 00 - 00 00 00 00 0f f7 49 00 ..............I. 000000000129fee0 00 00 00 00 4c 32 61 76 - 90 06 00 00 fc 00 00 00 ....L2av........ 000000000129fef0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 000000000129ff00 00 00 00 00 00 00 00 00 - 14 00 00 00 01 00 00 00 ................ 000000000129ff10 00 00 00 00 00 00 00 00 - 10 00 00 00 00 00 00 00 ................ 000000000129ff20 00 00 00 00 00 00 00 00 - 00 60 fd 7f 00 a0 fa 7f .........`...... 000000000129ff30 00 00 00 00 00 00 00 00 - e8 fe 29 01 00 00 00 00 ..........)..... 000000000129ff40 02 00 00 00 dc fe 29 01 - 00 00 00 00 dc ff 29 01 ......).......). 000000000129ff50 d8 9a 83 7c 80 96 80 7c - 00 00 00 00 78 ff 29 01 ...|...|....x.). 000000000129ff60 15 a1 80 7c 02 00 00 00 - 9c ff 29 01 00 00 00 00 ...|......)..... 000000000129ff70 ff ff ff ff 00 00 00 00 - b4 ff 29 01 a8 2d 60 76 ..........)..-`v 000000000129ff80 02 00 00 00 9c ff 29 01 - 00 00 00 00 ff ff ff ff ......)......... 000000000129ff90 01 00 00 00 11 d1 4f 77 - 00 00 00 00 90 06 00 00 ......Ow........ 000000000129ffa0 fc 00 00 00 e9 51 52 00 - 00 00 00 00 00 00 00 00 .....QR......... 000000000129ffb0 00 00 00 00 ec ff 29 01 - 29 b7 80 7c 00 00 00 00 ......).)..|.... 000000000129ffc0 01 00 00 00 11 d1 4f 77 - 00 00 00 00 00 a0 fa 7f ......Ow........ 000000000129ffd0 00 16 e6 8a c0 ff 29 01 - f8 13 7e 8a ff ff ff ff ......)...~..... 000000000129ffe0 d8 9a 83 7c 30 b7 80 7c - 00 00 00 00 00 00 00 00 ...|0..|........ 000000000129fff0 00 00 00 00 3c 2d 60 76 - 00 00 00 00 00 00 00 00 ....<-`v........ *----> State Dump for Thread Id 0x1a4 <----* eax=769c8761 ebx=0149fef4 ecx=00000000 edx=00000005 esi=00000000 edi=7ffd6000 eip=7c90e514 esp=0149fecc ebp=0149ff68 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 function: ntdll!KiFastSystemCallRet 7c90e4fa e829000000 call ntdll!RtlRaiseException (7c90e528) 7c90e4ff 8b0424 mov eax,[esp] 7c90e502 8be5 mov esp,ebp 7c90e504 5d pop ebp 7c90e505 c3 ret 7c90e506 8da42400000000 lea esp,[esp] 7c90e50d 8d4900 lea ecx,[ecx] ntdll!KiFastSystemCall: 7c90e510 8bd4 mov edx,esp 7c90e512 0f34 sysenter ntdll!KiFastSystemCallRet: 7c90e514 c3 ret 7c90e515 8da42400000000 lea esp,[esp] 7c90e51c 8d642400 lea esp,[esp] ntdll!KiIntSystemCall: 7c90e520 8d542408 lea edx,[esp+0x8] 7c90e524 cd2e int 2e 7c90e526 c3 ret 7c90e527 90 nop ntdll!RtlRaiseException: 7c90e528 55 push ebp 7c90e529 8bec mov ebp,esp *----> Stack Back Trace <----* WARNING: Stack unwind information not available. Following frames may be wrong. *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\USERENV.dll - ChildEBP RetAddr Args to Child 0149ff68 7c80a115 00000003 76a61348 00000000 ntdll!KiFastSystemCallRet 0149ff84 769c87bd 00000003 76a61348 00000000 kernel32!WaitForMultipleObjects+0x18 0149ffb4 7c80b729 00000000 00000048 011df85c USERENV!RegisterGPNotification+0x1b6 0149ffec 00000000 769c8761 00000000 00000000 kernel32!GetModuleFileNameA+0x1ba *----> Raw Stack Dump <----* 000000000149fecc 4a df 90 7c 90 95 80 7c - 03 00 00 00 f4 fe 49 01 J..|...|......I. 000000000149fedc 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 000000000149feec f0 13 a6 76 e7 9b 80 7c - 78 07 00 00 74 07 00 00 ...v...|x...t... 000000000149fefc 20 08 00 00 5c fe 49 01 - 6c ff 49 01 6c ff 49 01 ...\.I.l.I.l.I. 000000000149ff0c 20 e9 90 7c 60 00 91 7c - 14 00 00 00 01 00 00 00 ..|`..|........ 000000000149ff1c 00 00 00 00 00 00 00 00 - 10 00 00 00 fa 1b 80 7c ...............| 000000000149ff2c 48 00 00 00 5c f8 1d 01 - 00 60 fd 7f 00 90 fa 7f H...\....`...... 000000000149ff3c 88 95 f6 00 00 00 00 00 - f4 fe 49 01 00 00 00 00 ..........I..... 000000000149ff4c 03 00 00 00 e8 fe 49 01 - 00 00 00 00 dc ff 49 01 ......I.......I. 000000000149ff5c d8 9a 83 7c 80 96 80 7c - 00 00 00 00 84 ff 49 01 ...|...|......I. 000000000149ff6c 15 a1 80 7c 03 00 00 00 - 48 13 a6 76 00 00 00 00 ...|....H..v.... 000000000149ff7c ff ff ff ff 00 00 00 00 - b4 ff 49 01 bd 87 9c 76 ..........I....v 000000000149ff8c 03 00 00 00 48 13 a6 76 - 00 00 00 00 ff ff ff ff ....H..v........ 000000000149ff9c 48 00 00 00 5c f8 1d 01 - 00 00 00 00 00 00 9c 76 H...\..........v 000000000149ffac 03 00 00 00 00 00 00 00 - ec ff 49 01 29 b7 80 7c ..........I.)..| 000000000149ffbc 00 00 00 00 48 00 00 00 - 5c f8 1d 01 00 00 00 00 ....H...\....... 000000000149ffcc 00 90 fa 7f 00 56 e6 8a - c0 ff 49 01 28 3c 81 8a .....V....I.(<.. 000000000149ffdc ff ff ff ff d8 9a 83 7c - 30 b7 80 7c 00 00 00 00 .......|0..|.... 000000000149ffec 00 00 00 00 00 00 00 00 - 61 87 9c 76 00 00 00 00 ........a..v.... 000000000149fffc 00 00 00 00 c8 00 00 00 - dd 01 00 00 ff ee ff ee ................ *----> State Dump for Thread Id 0x460 <----* eax=769d3c11 ebx=0155fe28 ecx=00070000 edx=000706e8 esi=00000000 edi=7ffd6000 eip=7c90e514 esp=0155fe00 ebp=0155fe9c iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 function: ntdll!KiFastSystemCallRet 7c90e4fa e829000000 call ntdll!RtlRaiseException (7c90e528) 7c90e4ff 8b0424 mov eax,[esp] 7c90e502 8be5 mov esp,ebp 7c90e504 5d pop ebp 7c90e505 c3 ret 7c90e506 8da42400000000 lea esp,[esp] 7c90e50d 8d4900 lea ecx,[ecx] ntdll!KiFastSystemCall: 7c90e510 8bd4 mov edx,esp 7c90e512 0f34 sysenter ntdll!KiFastSystemCallRet: 7c90e514 c3 ret 7c90e515 8da42400000000 lea esp,[esp] 7c90e51c 8d642400 lea esp,[esp] ntdll!KiIntSystemCall: 7c90e520 8d542408 lea edx,[esp+0x8] 7c90e524 cd2e int 2e 7c90e526 c3 ret 7c90e527 90 nop ntdll!RtlRaiseException: 7c90e528 55 push ebp 7c90e529 8bec mov ebp,esp *----> Stack Back Trace <----* WARNING: Stack unwind information not available. Following frames may be wrong. ChildEBP RetAddr Args to Child 0155fe9c 7c80a115 00000004 0155ff0c 00000000 ntdll!KiFastSystemCallRet 0155feb8 769d3df2 00000004 0155ff0c 00000000 kernel32!WaitForMultipleObjects+0x18 0155ffb4 7c80b729 00f5abb0 00070000 7c910222 USERENV!Ordinal147+0x257 0155ffec 00000000 769d3c11 00f5abb0 00000000 kernel32!GetModuleFileNameA+0x1ba *----> Raw Stack Dump <----* 000000000155fe00 4a df 90 7c 90 95 80 7c - 04 00 00 00 28 fe 55 01 J..|...|....(.U. 000000000155fe10 01 00 00 00 00 00 00 00 - 00 00 00 00 21 fe 90 7c ............!..| 000000000155fe20 b0 ab f5 00 00 00 00 00 - 7c 07 00 00 84 07 00 00 ........|....... 000000000155fe30 80 07 00 00 e4 07 00 00 - a4 fe 55 01 b9 ab 41 7e ..........U...A~ 000000000155fe40 7e ff 55 01 7e ff 55 01 - 14 00 00 00 01 00 00 00 ~.U.~.U......... 000000000155fe50 00 00 00 00 00 00 00 00 - 10 00 00 00 00 00 00 00 ................ 000000000155fe60 3c aa 41 7e 00 00 00 00 - 00 60 fd 7f 00 60 fa 7f <.A~.....`...`.. 000000000155fe70 00 00 00 00 00 00 00 00 - 28 fe 55 01 aa dd 90 7c ........(.U....| 000000000155fe80 04 00 00 00 1c fe 55 01 - e0 fe 55 01 dc ff 55 01 ......U...U...U. 000000000155fe90 d8 9a 83 7c 80 96 80 7c - 00 00 00 00 b8 fe 55 01 ...|...|......U. 000000000155fea0 15 a1 80 7c 04 00 00 00 - 0c ff 55 01 00 00 00 00 ...|......U..... 000000000155feb0 ff ff ff ff 00 00 00 00 - b4 ff 55 01 f2 3d 9d 76 ..........U..=.v 000000000155fec0 04 00 00 00 0c ff 55 01 - 00 00 00 00 ff ff ff ff ......U......... 000000000155fed0 00 00 07 00 22 02 91 7c - b0 ab f5 00 00 00 00 00 ...."..|........ 000000000155fee0 00 78 9e e9 f0 ff ff ff - 00 00 9c 76 74 13 a6 76 .x.........vt..v 000000000155fef0 ff ff ff ff 40 f5 df ff - 00 00 00 00 10 74 6e 80 ....@........tn. 000000000155ff00 cc ce 91 8a 28 ac a9 a7 - 00 00 00 00 7c 07 00 00 ....(.......|... 000000000155ff10 84 07 00 00 80 07 00 00 - e4 07 00 00 a0 cd 91 8a ................ 000000000155ff20 00 00 00 00 94 b0 4f 80 - c0 7a 10 00 80 e0 62 00 ......O..z....b. 000000000155ff30 64 cd 91 8a 00 00 00 00 - 75 00 73 00 65 00 72 00 d.......u.s.e.r. *----> State Dump for Thread Id 0x7ec <----* eax=77e76c7d ebx=00000000 ecx=00000000 edx=00264420 esi=00081f48 edi=00081f84 eip=7c90e514 esp=011dfe18 ebp=011dff80 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 function: ntdll!KiFastSystemCallRet 7c90e4fa e829000000 call ntdll!RtlRaiseException (7c90e528) 7c90e4ff 8b0424 mov eax,[esp] 7c90e502 8be5 mov esp,ebp 7c90e504 5d pop ebp 7c90e505 c3 ret 7c90e506 8da42400000000 lea esp,[esp] 7c90e50d 8d4900 lea ecx,[ecx] ntdll!KiFastSystemCall: 7c90e510 8bd4 mov edx,esp 7c90e512 0f34 sysenter ntdll!KiFastSystemCallRet: 7c90e514 c3 ret 7c90e515 8da42400000000 lea esp,[esp] 7c90e51c 8d642400 lea esp,[esp] ntdll!KiIntSystemCall: 7c90e520 8d542408 lea edx,[esp+0x8] 7c90e524 cd2e int 2e 7c90e526 c3 ret 7c90e527 90 nop ntdll!RtlRaiseException: 7c90e528 55 push ebp 7c90e529 8bec mov ebp,esp *----> Stack Back Trace <----* WARNING: Stack unwind information not available. Following frames may be wrong. ChildEBP RetAddr Args to Child 011dff80 77e76caf 011dffa8 77e76ad1 00081f48 ntdll!KiFastSystemCallRet 011dff88 77e76ad1 00081f48 00000000 00000000 RPCRT4!I_RpcBCacheFree+0x61c 011dffa8 77e76c97 000817f8 011dffec 7c80b729 RPCRT4!I_RpcBCacheFree+0x43e 011dffb4 7c80b729 00f92be8 00000000 00000000 RPCRT4!I_RpcBCacheFree+0x604 011dffec 00000000 77e76c7d 00f92be8 00000000 kernel32!GetModuleFileNameA+0x1ba *----> Raw Stack Dump <----* 00000000011dfe18 aa da 90 7c e3 65 e7 77 - 20 01 00 00 74 ff 1d 01 ...|.e.w ...t... 00000000011dfe28 00 00 00 00 68 2e f9 00 - 00 00 00 00 00 00 00 00 ....h........... 00000000011dfe38 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 00000000011dfe48 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 00000000011dfe58 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 00000000011dfe68 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 00000000011dfe78 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 00000000011dfe88 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 00000000011dfe98 00 00 00 00 00 00 00 00 - 43 7d 6e 80 28 6c 9a a7 ........C}n.(l.. 00000000011dfea8 27 74 6e 80 00 0d db ba - 00 00 00 00 00 00 00 00 'tn............. 00000000011dfeb8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 00000000011dfec8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 00000000011dfed8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 00000000011dfee8 00 00 00 00 1f 00 00 00 - ff ff ff ff 40 85 b3 b9 ............@... 00000000011dfef8 00 00 00 00 10 74 6e 80 - ec 54 8c 8a 28 6c 9a a7 .....tn..T..(l.. 00000000011dff08 00 00 00 00 27 74 6e 80 - 08 00 00 00 46 02 00 00 ....'tn.....F... 00000000011dff18 86 38 50 80 c0 53 8c 8a - 50 53 8c 8a 94 b0 4f 80 .8P..S..PS....O. 00000000011dff28 bc 54 8c 8a 80 ff 1d 01 - 85 d1 e7 77 48 ff 1d 01 .T.........wH... 00000000011dff38 95 d1 e7 77 e0 10 90 7c - 38 9d f5 00 e8 2b f9 00 ...w...|8....+.. 00000000011dff48 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff ../M.....]...... *----> State Dump for Thread Id 0x244 <----* eax=77e76c7d ebx=00007530 ecx=00cafdb8 edx=00000000 esi=00083068 edi=00000000 eip=7c90e514 esp=0110feac ebp=0110fed8 iopl=0 nv up ei ng nz ac po cy cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000297 function: ntdll!KiFastSystemCallRet 7c90e4fa e829000000 call ntdll!RtlRaiseException (7c90e528) 7c90e4ff 8b0424 mov eax,[esp] 7c90e502 8be5 mov esp,ebp 7c90e504 5d pop ebp 7c90e505 c3 ret 7c90e506 8da42400000000 lea esp,[esp] 7c90e50d 8d4900 lea ecx,[ecx] ntdll!KiFastSystemCall: 7c90e510 8bd4 mov edx,esp 7c90e512 0f34 sysenter ntdll!KiFastSystemCallRet: 7c90e514 c3 ret 7c90e515 8da42400000000 lea esp,[esp] 7c90e51c 8d642400 lea esp,[esp] ntdll!KiIntSystemCall: 7c90e520 8d542408 lea edx,[esp+0x8] 7c90e524 cd2e int 2e 7c90e526 c3 ret 7c90e527 90 nop ntdll!RtlRaiseException: 7c90e528 55 push ebp 7c90e529 8bec mov ebp,esp *----> Stack Back Trace <----* WARNING: Stack unwind information not available. Following frames may be wrong. ChildEBP RetAddr Args to Child 0110fed8 77e7715c 00000178 0110ff10 0110ff00 ntdll!KiFastSystemCallRet 0110ff14 77e772a0 00007530 0110ff6c 0110ff70 RPCRT4!I_RpcBCacheFree+0xac9 0110ff80 77e77328 0110ffa8 77e76ad1 00083068 RPCRT4!I_RpcBCacheFree+0xc0d 0110ff88 77e76ad1 00083068 00070000 00000000 RPCRT4!I_RpcBCacheFree+0xc95 0110ffa8 77e76c97 000817f8 0110ffec 7c80b729 RPCRT4!I_RpcBCacheFree+0x43e 0110ffb4 7c80b729 000821d0 00070000 00000000 RPCRT4!I_RpcBCacheFree+0x604 0110ffec 00000000 77e76c7d 000821d0 00000000 kernel32!GetModuleFileNameA+0x1ba *----> Raw Stack Dump <----* 000000000110feac 4a da 90 7c e6 a7 80 7c - 78 01 00 00 00 ff 10 01 J..|...|x....... 000000000110febc f0 fe 10 01 d0 fe 10 01 - c8 fe 10 01 00 5d 1e ee .............].. 000000000110fecc ff ff ff ff 44 4a 08 00 - 5c 4a 08 00 14 ff 10 01 ....DJ..\J...... 000000000110fedc 5c 71 e7 77 78 01 00 00 - 10 ff 10 01 00 ff 10 01 \q.wx........... 000000000110feec 08 ff 10 01 30 75 00 00 - 1a 98 80 7c 68 30 08 00 ....0u.....|h0.. 000000000110fefc 70 32 08 00 14 ff 10 01 - 78 01 00 00 12 10 02 c0 p2......x....... 000000000110ff0c 00 00 00 00 93 99 00 00 - 80 ff 10 01 a0 72 e7 77 .............r.w 000000000110ff1c 30 75 00 00 6c ff 10 01 - 70 ff 10 01 78 ff 10 01 0u..l...p...x... 000000000110ff2c 64 ff 10 01 68 ff 10 01 - 74 ff 10 01 e0 10 90 7c d...h...t......| 000000000110ff3c 08 ce f5 00 d0 21 08 00 - d0 21 08 00 78 01 00 00 .....!...!..x... 000000000110ff4c 00 00 00 00 01 00 00 00 - 00 00 00 00 03 00 00 00 ................ 000000000110ff5c 00 00 00 00 30 75 00 00 - 93 99 00 00 00 00 00 00 ....0u.......... 000000000110ff6c 00 00 00 00 12 10 02 c0 - 00 00 00 00 78 01 00 00 ............x... 000000000110ff7c 00 00 00 00 88 ff 10 01 - 28 73 e7 77 a8 ff 10 01 ........(s.w.... 000000000110ff8c d1 6a e7 77 68 30 08 00 - 00 00 07 00 00 00 00 00 .j.wh0.......... 000000000110ff9c d0 21 08 00 d0 21 08 00 - d0 21 08 00 b4 ff 10 01 .!...!...!...... 000000000110ffac 97 6c e7 77 f8 17 08 00 - ec ff 10 01 29 b7 80 7c .l.w........)..| 000000000110ffbc d0 21 08 00 00 00 07 00 - 00 00 00 00 d0 21 08 00 .!...........!.. 000000000110ffcc 00 50 fd 7f 00 56 e6 8a - c0 ff 10 01 30 72 b6 8a .P...V......0r.. 000000000110ffdc ff ff ff ff d8 9a 83 7c - 30 b7 80 7c 00 00 00 00 .......|0..|.... *----> State Dump for Thread Id 0x488 <----* eax=7ffaf000 ebx=013efe94 ecx=013efe6c edx=7c90e514 esi=00000000 edi=7ffd6000 eip=7c90e514 esp=013efe6c ebp=013eff08 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 function: ntdll!KiFastSystemCallRet 7c90e4fa e829000000 call ntdll!RtlRaiseException (7c90e528) 7c90e4ff 8b0424 mov eax,[esp] 7c90e502 8be5 mov esp,ebp 7c90e504 5d pop ebp 7c90e505 c3 ret 7c90e506 8da42400000000 lea esp,[esp] 7c90e50d 8d4900 lea ecx,[ecx] ntdll!KiFastSystemCall: 7c90e510 8bd4 mov edx,esp 7c90e512 0f34 sysenter ntdll!KiFastSystemCallRet: 7c90e514 c3 ret 7c90e515 8da42400000000 lea esp,[esp] 7c90e51c 8d642400 lea esp,[esp] ntdll!KiIntSystemCall: 7c90e520 8d542408 lea edx,[esp+0x8] 7c90e524 cd2e int 2e 7c90e526 c3 ret 7c90e527 90 nop ntdll!RtlRaiseException: 7c90e528 55 push ebp 7c90e529 8bec mov ebp,esp *----> Stack Back Trace <----* *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\USER32.dll - WARNING: Stack unwind information not available. Following frames may be wrong. *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\MSGINA.dll - ChildEBP RetAddr Args to Child 013eff08 7e4195f9 00000002 013eff30 00000000 ntdll!KiFastSystemCallRet 013eff64 75975a6d 00000001 013effa8 ffffffff USER32!GetLastInputInfo+0x105 013effb4 7c80b729 00150168 0006df9c 0006e374 MSGINA!WlxActivateUserShell+0x2120 013effec 00000000 759759df 00150168 00000000 kernel32!GetModuleFileNameA+0x1ba *----> Raw Stack Dump <----* 00000000013efe6c 4a df 90 7c 90 95 80 7c - 02 00 00 00 94 fe 3e 01 J..|...|......>. 00000000013efe7c 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 00000000013efe8c 02 00 00 00 04 00 00 00 - 18 06 00 00 60 08 00 00 ............`... 00000000013efe9c 14 00 00 00 01 00 00 00 - 18 06 00 00 00 00 00 00 ................ 00000000013efeac 10 00 00 00 00 00 00 00 - 14 00 00 00 01 00 00 00 ................ 00000000013efebc 00 00 00 00 00 00 00 00 - 10 00 00 00 00 00 00 00 ................ 00000000013efecc 2c ff 3e 01 8f 04 44 7e - 00 60 fd 7f 00 f0 fa 7f ,.>...D~.`...... 00000000013efedc 2a 88 41 7e 00 00 00 00 - 94 fe 3e 01 3a 3d 42 7e *.A~......>.:=B~ 00000000013efeec 02 00 00 00 88 fe 3e 01 - 00 00 00 00 dc ff 3e 01 ......>.......>. 00000000013efefc d8 9a 83 7c 80 96 80 7c - 00 00 00 00 64 ff 3e 01 ...|...|....d.>. 00000000013eff0c f9 95 41 7e 02 00 00 00 - 30 ff 3e 01 00 00 00 00 ..A~....0.>..... 00000000013eff1c ff ff ff ff 00 00 00 00 - 45 96 41 7e 68 01 15 00 ........E.A~h... 00000000013eff2c ff 05 00 00 18 06 00 00 - 60 08 00 00 00 f0 fa 7f ........`....... 00000000013eff3c 2c ff 3e 01 02 01 00 00 - 0c ff 3e 01 00 00 00 00 ,.>.......>..... 00000000013eff4c dc ff 3e 01 d8 9a 83 7c - 00 00 00 00 00 00 00 00 ..>....|........ 00000000013eff5c 00 f0 fa 7f 60 08 00 00 - b4 ff 3e 01 6d 5a 97 75 ....`.....>.mZ.u 00000000013eff6c 01 00 00 00 a8 ff 3e 01 - ff ff ff ff ff 05 00 00 ......>......... 00000000013eff7c 30 ff 3e 01 9c df 06 00 - 74 e3 06 00 68 01 15 00 0.>.....t...h... 00000000013eff8c 36 00 06 00 13 01 00 00 - 00 00 00 00 00 00 00 00 6............... 00000000013eff9c 5c 0c 4a 00 80 02 00 00 - 00 02 00 00 18 06 00 00 \.J............. *----> State Dump for Thread Id 0x69c <----* eax=00f99890 ebx=00070260 ecx=d130c13c edx=00070608 esi=00f99888 edi=00070000 eip=7c910b2c esp=0119f524 ebp=0119f5e0 iopl=0 nv up ei ng nz na pe nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000282 function: ntdll!wcsncpy 7c910b11 c9 leave 7c910b12 8a08 mov cl,[eax] 7c910b14 0bca or ecx,edx 7c910b16 8808 mov [eax],cl 7c910b18 8d4608 lea eax,[esi+0x8] 7c910b1b 89856cffffff mov [ebp-0x94],eax 7c910b21 8b4b04 mov ecx,[ebx+0x4] 7c910b24 894d84 mov [ebp-0x7c],ecx 7c910b27 8918 mov [eax],ebx 7c910b29 894804 mov [eax+0x4],ecx FAULT ->7c910b2c 8901 mov [ecx],eax ds:0023:d130c13c=???????? 7c910b2e 894304 mov [ebx+0x4],eax 7c910b31 8b45e4 mov eax,[ebp-0x1c] 7c910b34 014728 add [edi+0x28],eax 7c910b37 e9ccfdffff jmp ntdll!wcsncpy+0x389 (7c910908) 7c910b3c ff4618 inc dword ptr [esi+0x18] 7c910b3f 32c0 xor al,al 7c910b41 e974f5ffff jmp ntdll!RtlFreeHeap+0x18d (7c9100ba) 7c910b46 90 nop 7c910b47 90 nop 7c910b48 0800 or [eax],al *----> Stack Back Trace <----* *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\ole32.dll - WARNING: Stack unwind information not available. Following frames may be wrong. *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\wbem\fastprox.dll - ChildEBP RetAddr Args to Child 0119f5e0 774fda80 00070000 00000000 00f99890 ntdll!wcsncpy+0x5ad 0119f5f4 7750c7f9 00f99890 00f99890 0119f618 ole32!IsValidInterface+0x787 0119f604 7750c967 00000001 00f6899c 00f68918 ole32!StringFromCLSID+0x221 0119f618 756bfecc 80000000 0119f634 769d49c3 ole32!StringFromCLSID+0x38f 0119f624 769d49c3 015e01f4 00f68918 0119fd18 fastprox!CImpl__Release+0x1a 0119f634 769d4cb8 00f68918 00000000 00f68918 USERENV!Ordinal151+0x540 0119fd18 769cf581 00f68918 00000000 00072fc8 USERENV!Ordinal151+0x835 0119fd80 0102e905 00000006 76a61374 0000083c USERENV!Ordinal140+0x1f0 0119ff5c 01039f18 0119ff74 7c90f65c 7c90f661 winlogon+0x2e905 0119ffb4 7c80b729 00f805d8 7c90f65c 7c90f661 winlogon+0x39f18 0119ffec 00000000 01039e58 00f805d8 00000000 kernel32!GetModuleFileNameA+0x1ba *----> Raw Stack Dump <----* 000000000119f524 38 99 f9 00 90 98 f9 00 - 00 00 00 00 00 00 00 00 8............... 000000000119f534 90 f4 19 01 88 98 f9 00 - 78 f5 19 01 20 e9 90 7c ........x... ..| 000000000119f544 60 00 91 7c ff ff ff ff - 90 98 f9 00 52 14 91 7c `..|........R..| 000000000119f554 83 14 91 7c 20 e1 97 7c - 60 14 91 7c b0 95 f9 00 ...| ..|`..|.... 000000000119f564 3c c1 30 d1 d8 98 f9 00 - 00 c0 fd 7f 60 f5 19 01 <.0.........`... 000000000119f574 20 e9 90 7c 60 02 07 00 - 20 e9 90 7c e8 00 00 00 ..|`... ..|.... 000000000119f584 ff ff ff ff 60 14 91 7c - e1 13 91 7c f2 13 91 7c ....`..|...|...| 000000000119f594 94 98 f9 00 d8 98 f9 00 - 00 00 00 00 f8 94 f9 00 ................ 000000000119f5a4 70 95 f9 00 00 00 07 00 - 90 95 f9 00 00 00 00 00 p............... 000000000119f5b4 94 f5 19 01 00 00 00 00 - 00 00 00 00 20 e9 01 01 ............ ... 000000000119f5c4 1d 00 00 00 24 f5 19 01 - 48 f1 19 01 08 fd 19 01 ....$...H....... 000000000119f5d4 20 e9 90 7c 60 00 91 7c - 01 00 00 00 f4 f5 19 01 ..|`..|........ 000000000119f5e4 80 da 4f 77 00 00 07 00 - 00 00 00 00 90 98 f9 00 ..Ow............ 000000000119f5f4 04 f6 19 01 f9 c7 50 77 - 90 98 f9 00 90 98 f9 00 ......Pw........ 000000000119f604 18 f6 19 01 67 c9 50 77 - 01 00 00 00 9c 89 f6 00 ....g.Pw........ 000000000119f614 18 89 f6 00 24 f6 19 01 - cc fe 6b 75 00 00 00 80 ....$.....ku.... 000000000119f624 34 f6 19 01 c3 49 9d 76 - f4 01 5e 01 18 89 f6 00 4....I.v..^..... 000000000119f634 18 fd 19 01 b8 4c 9d 76 - 18 89 f6 00 00 00 00 00 .....L.v........ 000000000119f644 18 89 f6 00 00 00 01 00 - 00 00 00 00 dc f6 19 01 ................ 000000000119f654 8c f6 19 01 a8 f6 19 01 - 34 e5 80 7c 01 00 00 00 ........4..|.... *----> State Dump for Thread Id 0x3ec <----* eax=71a5d2c6 ebx=c0000000 ecx=7c912228 edx=ffffffff esi=00000000 edi=71a8793c eip=7c90e514 esp=0145ff7c ebp=0145ffb4 iopl=0 nv up ei pl nz na pe nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202 function: ntdll!KiFastSystemCallRet 7c90e4fa e829000000 call ntdll!RtlRaiseException (7c90e528) 7c90e4ff 8b0424 mov eax,[esp] 7c90e502 8be5 mov esp,ebp 7c90e504 5d pop ebp 7c90e505 c3 ret 7c90e506 8da42400000000 lea esp,[esp] 7c90e50d 8d4900 lea ecx,[ecx] ntdll!KiFastSystemCall: 7c90e510 8bd4 mov edx,esp 7c90e512 0f34 sysenter ntdll!KiFastSystemCallRet: 7c90e514 c3 ret 7c90e515 8da42400000000 lea esp,[esp] 7c90e51c 8d642400 lea esp,[esp] ntdll!KiIntSystemCall: 7c90e520 8d542408 lea edx,[esp+0x8] 7c90e524 cd2e int 2e 7c90e526 c3 ret 7c90e527 90 nop ntdll!RtlRaiseException: 7c90e528 55 push ebp 7c90e529 8bec mov ebp,esp *----> Stack Back Trace <----* WARNING: Stack unwind information not available. Following frames may be wrong. ChildEBP RetAddr Args to Child 0145ffb4 7c80b729 71a5d65f 0119e2e4 7c90e920 ntdll!KiFastSystemCallRet 0145ffec 00000000 71a5d2c6 00f90408 00000000 kernel32!GetModuleFileNameA+0x1ba *----> Raw Stack Dump <----* 000000000145ff7c 4a da 90 7c 20 d3 a5 71 - d0 07 00 00 bc ff 45 01 J..| ..q......E. 000000000145ff8c b0 ff 45 01 a4 ff 45 01 - 68 d3 a5 71 e4 e2 19 01 ..E...E.h..q.... 000000000145ff9c 20 e9 90 7c 08 04 f9 00 - 00 00 00 00 00 00 00 00 ..|............ 000000000145ffac 00 00 a5 71 90 28 4a 01 - ec ff 45 01 29 b7 80 7c ...q.(J...E.)..| 000000000145ffbc 5f d6 a5 71 e4 e2 19 01 - 20 e9 90 7c 08 04 f9 00 _..q.... ..|.... 000000000145ffcc 00 e0 fa 7f 00 16 e6 8a - c0 ff 45 01 60 40 92 8a ..........E.`@.. 000000000145ffdc ff ff ff ff d8 9a 83 7c - 30 b7 80 7c 00 00 00 00 .......|0..|.... 000000000145ffec 00 00 00 00 00 00 00 00 - c6 d2 a5 71 08 04 f9 00 ...........q.... 000000000145fffc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 000000000146000c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 000000000146001c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 000000000146002c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 000000000146003c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 000000000146004c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 000000000146005c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 000000000146006c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 000000000146007c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 000000000146008c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 000000000146009c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 00000000014600ac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ *----> State Dump for Thread Id 0x114 <----* eax=774fe4ef ebx=00007530 ecx=7ffd6000 edx=00000000 esi=00000000 edi=0151ff50 eip=7c90e514 esp=0151ff20 ebp=0151ff78 iopl=0 nv up ei pl nz na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000206 function: ntdll!KiFastSystemCallRet 7c90e4fa e829000000 call ntdll!RtlRaiseException (7c90e528) 7c90e4ff 8b0424 mov eax,[esp] 7c90e502 8be5 mov esp,ebp 7c90e504 5d pop ebp 7c90e505 c3 ret 7c90e506 8da42400000000 lea esp,[esp] 7c90e50d 8d4900 lea ecx,[ecx] ntdll!KiFastSystemCall: 7c90e510 8bd4 mov edx,esp 7c90e512 0f34 sysenter ntdll!KiFastSystemCallRet: 7c90e514 c3 ret 7c90e515 8da42400000000 lea esp,[esp] 7c90e51c 8d642400 lea esp,[esp] ntdll!KiIntSystemCall: 7c90e520 8d542408 lea edx,[esp+0x8] 7c90e524 cd2e int 2e 7c90e526 c3 ret 7c90e527 90 nop ntdll!RtlRaiseException: 7c90e528 55 push ebp 7c90e529 8bec mov ebp,esp *----> Stack Back Trace <----* WARNING: Stack unwind information not available. Following frames may be wrong. ChildEBP RetAddr Args to Child 0151ff78 7c802455 0000ea60 00000000 0151ffb4 ntdll!KiFastSystemCallRet 0151ff88 774fe3e3 0000ea60 00f89278 774fe4a2 kernel32!Sleep+0xf 0151ffb4 7c80b729 00f89278 7c910435 7c91043e ole32!StringFromGUID2+0x51d 0151ffec 00000000 774fe4ef 00f89278 00000000 kernel32!GetModuleFileNameA+0x1ba *----> Raw Stack Dump <----* 000000000151ff20 1a d2 90 7c f1 23 80 7c - 00 00 00 00 50 ff 51 01 ...|.#.|....P.Q. 000000000151ff30 50 25 80 7c f8 7d 60 77 - 30 75 00 00 14 00 00 00 P%.|.}`w0u...... 000000000151ff40 01 00 00 00 00 00 00 00 - 00 00 00 00 10 00 00 00 ................ 000000000151ff50 00 ba 3c dc ff ff ff ff - 10 d1 4e 77 50 ff 51 01 ..<.......NwP.Q. 000000000151ff60 30 ff 51 01 10 e9 07 00 - dc ff 51 01 d8 9a 83 7c 0.Q.......Q....| 000000000151ff70 60 24 80 7c 00 00 00 00 - 88 ff 51 01 55 24 80 7c `$.|......Q.U$.| 000000000151ff80 60 ea 00 00 00 00 00 00 - b4 ff 51 01 e3 e3 4f 77 `.........Q...Ow 000000000151ff90 60 ea 00 00 78 92 f8 00 - a2 e4 4f 77 00 00 00 00 `...x.....Ow.... 000000000151ffa0 35 04 91 7c 78 92 f8 00 - 00 00 4e 77 0a e5 4f 77 5..|x.....Nw..Ow 000000000151ffb0 3e 04 91 7c ec ff 51 01 - 29 b7 80 7c 78 92 f8 00 >..|..Q.)..|x... 000000000151ffc0 35 04 91 7c 3e 04 91 7c - 78 92 f8 00 00 b0 fa 7f 5..|>..|x....... 000000000151ffd0 00 36 e6 8a c0 ff 51 01 - 98 4b 80 8a ff ff ff ff .6....Q..K...... 000000000151ffe0 d8 9a 83 7c 30 b7 80 7c - 00 00 00 00 00 00 00 00 ...|0..|........ 000000000151fff0 00 00 00 00 ef e4 4f 77 - 78 92 f8 00 00 00 00 00 ......Owx....... 0000000001520000 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000001520010 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000001520020 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000001520030 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000001520040 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000001520050 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ *----> State Dump for Thread Id 0xa8 <----* eax=012a53a4 ebx=0196fed0 ecx=7ffa8000 edx=77e46660 esi=00000000 edi=7ffd6000 eip=7c90e514 esp=0196fea8 ebp=0196ff44 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 function: ntdll!KiFastSystemCallRet 7c90e4fa e829000000 call ntdll!RtlRaiseException (7c90e528) 7c90e4ff 8b0424 mov eax,[esp] 7c90e502 8be5 mov esp,ebp 7c90e504 5d pop ebp 7c90e505 c3 ret 7c90e506 8da42400000000 lea esp,[esp] 7c90e50d 8d4900 lea ecx,[ecx] ntdll!KiFastSystemCall: 7c90e510 8bd4 mov edx,esp 7c90e512 0f34 sysenter ntdll!KiFastSystemCallRet: 7c90e514 c3 ret 7c90e515 8da42400000000 lea esp,[esp] 7c90e51c 8d642400 lea esp,[esp] ntdll!KiIntSystemCall: 7c90e520 8d542408 lea edx,[esp+0x8] 7c90e524 cd2e int 2e 7c90e526 c3 ret 7c90e527 90 nop ntdll!RtlRaiseException: 7c90e528 55 push ebp 7c90e529 8bec mov ebp,esp *----> Stack Back Trace <----* *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\ADVAPI32.dll - WARNING: Stack unwind information not available. Following frames may be wrong. ChildEBP RetAddr Args to Child 0196ff44 77df8631 00000002 0196ff6c 00000000 ntdll!KiFastSystemCallRet 0196ffb4 7c80b729 00000000 7c90d5da 7c91bcb0 ADVAPI32!WmiFreeBuffer+0x24e 0196ffec 00000000 77df848a 00000000 00000000 kernel32!GetModuleFileNameA+0x1ba *----> Raw Stack Dump <----* 000000000196fea8 4a df 90 7c 90 95 80 7c - 02 00 00 00 d0 fe 96 01 J..|...|........ 000000000196feb8 01 00 00 00 01 00 00 00 - 04 ff 96 01 e0 2e 2a 01 ..............*. 000000000196fec8 60 66 e4 77 00 10 00 00 - c4 06 00 00 d4 06 00 00 `f.w............ 000000000196fed8 c0 fe 96 01 00 30 d4 05 - dc ff 96 01 d8 9a 83 7c .....0.........| 000000000196fee8 50 0b 81 7c ff ff ff ff - 14 00 00 00 01 00 00 00 P..|............ 000000000196fef8 00 00 00 00 00 00 00 00 - 10 00 00 00 00 a2 2f 4d ............../M 000000000196ff08 ff ff ff ff 00 10 00 00 - 00 60 fd 7f 00 80 fa 7f .........`...... 000000000196ff18 00 10 00 00 04 ff 96 01 - d0 fe 96 01 88 66 e4 77 .............f.w 000000000196ff28 02 00 00 00 c4 fe 96 01 - 20 00 00 00 dc ff 96 01 ........ ....... 000000000196ff38 d8 9a 83 7c 80 96 80 7c - 00 00 00 00 b4 ff 96 01 ...|...|........ 000000000196ff48 31 86 df 77 02 00 00 00 - 6c ff 96 01 00 00 00 00 1..w....l....... 000000000196ff58 e0 93 04 00 01 00 00 00 - da d5 90 7c 00 00 00 00 ...........|.... 000000000196ff68 b0 bc 91 7c c4 06 00 00 - d4 06 00 00 00 10 00 00 ...|............ 000000000196ff78 e0 2e 2a 01 00 00 00 00 - 00 10 00 00 e8 3e 2a 01 ..*..........>*. 000000000196ff88 00 67 e4 77 58 00 00 00 - e0 66 e4 77 00 10 00 00 .g.wX....f.w.... 000000000196ff98 00 00 00 00 00 00 00 00 - e0 2e 2a 01 e0 66 e4 77 ..........*..f.w 000000000196ffa8 e5 03 00 00 00 10 00 00 - e8 3e 2a 01 ec ff 96 01 .........>*..... 000000000196ffb8 29 b7 80 7c 00 00 00 00 - da d5 90 7c b0 bc 91 7c )..|.......|...| 000000000196ffc8 00 00 00 00 00 80 fa 7f - 00 56 e6 8a c0 ff 96 01 .........V...... 000000000196ffd8 18 79 d1 8a ff ff ff ff - d8 9a 83 7c 30 b7 80 7c .y.........|0..| *----> State Dump for Thread Id 0x1b4 <----* eax=01a0f654 ebx=00050060 ecx=77607e00 edx=77607e00 esi=01a0ff54 edi=00000000 eip=7c90e514 esp=01a0ff14 ebp=01a0ff30 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 function: ntdll!KiFastSystemCallRet 7c90e4fa e829000000 call ntdll!RtlRaiseException (7c90e528) 7c90e4ff 8b0424 mov eax,[esp] 7c90e502 8be5 mov esp,ebp 7c90e504 5d pop ebp 7c90e505 c3 ret 7c90e506 8da42400000000 lea esp,[esp] 7c90e50d 8d4900 lea ecx,[ecx] ntdll!KiFastSystemCall: 7c90e510 8bd4 mov edx,esp 7c90e512 0f34 sysenter ntdll!KiFastSystemCallRet: 7c90e514 c3 ret 7c90e515 8da42400000000 lea esp,[esp] 7c90e51c 8d642400 lea esp,[esp] ntdll!KiIntSystemCall: 7c90e520 8d542408 lea edx,[esp+0x8] 7c90e524 cd2e int 2e 7c90e526 c3 ret 7c90e527 90 nop ntdll!RtlRaiseException: 7c90e528 55 push ebp 7c90e529 8bec mov ebp,esp *----> Stack Back Trace <----* WARNING: Stack unwind information not available. Following frames may be wrong. ChildEBP RetAddr Args to Child 01a0ff30 7752ff76 01a0ff54 00000000 00000000 ntdll!KiFastSystemCallRet 01a0ff70 77526499 00007530 7c802550 00fa3978 ole32!CoFreeUnusedLibrariesEx+0x214 01a0ff8c 775263cc 01a0ffb4 774fe4a2 77607c28 ole32!CoGetObject+0x1843 01a0ff94 774fe4a2 77607c28 00000000 00fa3978 ole32!CoGetObject+0x1776 01a0ffb4 7c80b729 00fa3978 00000000 00000000 ole32!StringFromGUID2+0x5dc 01a0ffec 00000000 774fe4ef 00fa3978 00000000 kernel32!GetModuleFileNameA+0x1ba *----> Raw Stack Dump <----* 0000000001a0ff14 be 91 41 7e f1 91 41 7e - 54 ff a0 01 00 00 00 00 ..A~..A~T....... 0000000001a0ff24 00 00 00 00 00 00 00 00 - c6 91 41 7e 70 ff a0 01 ..........A~p... 0000000001a0ff34 76 ff 52 77 54 ff a0 01 - 00 00 00 00 00 00 00 00 v.RwT........... 0000000001a0ff44 00 00 00 00 00 00 00 00 - 28 7c 60 77 00 00 00 00 ........(|`w.... 0000000001a0ff54 60 00 05 00 00 04 00 00 - be ba 00 00 9c 0d f6 00 `............... 0000000001a0ff64 9c bb 49 00 80 02 00 00 - 00 02 00 00 8c ff a0 01 ..I............. 0000000001a0ff74 99 64 52 77 30 75 00 00 - 50 25 80 7c 78 39 fa 00 .dRw0u..P%.|x9.. 0000000001a0ff84 b0 09 00 00 b8 40 fa 00 - 94 ff a0 01 cc 63 52 77 .....@.......cRw 0000000001a0ff94 b4 ff a0 01 a2 e4 4f 77 - 28 7c 60 77 00 00 00 00 ......Ow(|`w.... 0000000001a0ffa4 78 39 fa 00 00 00 4e 77 - 0a e5 4f 77 00 00 00 00 x9....Nw..Ow.... 0000000001a0ffb4 ec ff a0 01 29 b7 80 7c - 78 39 fa 00 00 00 00 00 ....)..|x9...... 0000000001a0ffc4 00 00 00 00 78 39 fa 00 - 00 70 fa 7f 00 56 e6 8a ....x9...p...V.. 0000000001a0ffd4 c0 ff a0 01 30 8d a9 8a - ff ff ff ff d8 9a 83 7c ....0..........| 0000000001a0ffe4 30 b7 80 7c 00 00 00 00 - 00 00 00 00 00 00 00 00 0..|............ 0000000001a0fff4 ef e4 4f 77 78 39 fa 00 - 00 00 00 00 41 63 74 78 ..Owx9......Actx 0000000001a10004 20 00 00 00 01 00 00 00 - 44 19 00 00 7c 00 00 00 .......D...|... 0000000001a10014 00 00 00 00 20 00 00 00 - 00 00 00 00 14 00 00 00 .... ........... 0000000001a10024 01 00 00 00 03 00 00 00 - 34 00 00 00 bc 00 00 00 ........4....... 0000000001a10034 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................ 0000000001a10044 00 00 00 00 00 00 00 00 - 02 00 00 00 00 00 00 00 ................