blue screen with 'c0000005 (access violation)' on Winlogon.exe
- From: "petew" <Peter.Whipple@xxxxxxxxxxx>
- Date: 9 Oct 2006 05:30:20 -0700
I've got a number of PCs in my organization that are starting to blue
screen on bootup with the above error. Some of these are on fresh
installs. I can power off/on the computer and it will work fine for a
while and then the error. Not sure about this one. Here is my Dr.
Watson log.
###Begin Log###
Microsoft (R) DrWtsn32
Copyright (C) 1985-2001 Microsoft Corp. All rights reserved.
Application exception occurred:
App: \??\C:\WINDOWS\system32\winlogon.exe (pid=516)
When: 8/30/2006 @ 08:04:44.027
Exception number: c0000005 (access violation)
*----> System Information <----*
Computer Name: US04DXP1049
User Name: SYSTEM
Terminal Session Id: 0
Number of Processors: 1
Processor Type: x86 Family 15 Model 1 Stepping 2
Windows Version: 5.1
Current Build: 2600
Service Pack: 2
Current Type: Multiprocessor Free
Registered Organization: Tarkett Inc.
Registered Owner: Tarkett Inc.
*----> Task List <----*
0 System Process
4 System
436 smss.exe
492 csrss.exe
516 winlogon.exe
560 services.exe
572 lsass.exe
768 svchost.exe
816 svchost.exe
880 svchost.exe
924 svchost.exe
976 svchost.exe
1132 spoolsv.exe
1260 cam.exe
1280 dmprimer.exe
1344 mdm.exe
1420 ntrtscan.exe
1492 rcHost.exe
1560 SDSERV.EXE
1592 svchost.exe
1628 tmlisten.exe
1668 UMCSTUB.EXE
1700 OfcPfwSvc.exe
1792 TRIGGAG.EXE
2020 DLBDD7.EXE
576 alg.exe
708 drwtsn32.exe
988 TSC.EXE
*----> Module List <----*
(0000000001000000 - 0000000001080000:
\??\C:\WINDOWS\system32\winlogon.exe
(0000000001270000 - 000000000131e000: C:\WINDOWS\system32\WgaLogon.dll
(0000000001c60000 - 0000000001f25000: C:\WINDOWS\system32\xpsp2res.dll
(000000000ffd0000 - 000000000fff8000: C:\WINDOWS\system32\rsaenh.dll
(0000000020000000 - 0000000020017000: C:\WINDOWS\system32\odbcint.dll
(000000004d4f0000 - 000000004d548000: C:\WINDOWS\system32\WINHTTP.dll
(000000005ad70000 - 000000005ada8000: C:\WINDOWS\system32\uxtheme.dll
(000000005b860000 - 000000005b8b4000: C:\WINDOWS\system32\NETAPI32.dll
(000000005d090000 - 000000005d127000: C:\WINDOWS\system32\COMCTL32.dll
(00000000662b0000 - 0000000066308000: C:\WINDOWS\system32\hnetcfg.dll
(0000000071a50000 - 0000000071a8f000: C:\WINDOWS\System32\mswsock.dll
(0000000071a90000 - 0000000071a98000: C:\WINDOWS\System32\wshtcpip.dll
(0000000071aa0000 - 0000000071aa8000: C:\WINDOWS\system32\WS2HELP.dll
(0000000071ab0000 - 0000000071ac7000: C:\WINDOWS\system32\WS2_32.dll
(0000000071ad0000 - 0000000071ad9000: C:\WINDOWS\system32\wsock32.dll
(0000000071b20000 - 0000000071b32000: C:\WINDOWS\system32\MPR.dll
(0000000071bf0000 - 0000000071c03000: C:\WINDOWS\system32\SAMLIB.dll
(0000000071cf0000 - 0000000071d3b000: C:\WINDOWS\system32\kerberos.dll
(00000000723d0000 - 00000000723ec000: C:\WINDOWS\system32\WINSCARD.DLL
(0000000073000000 - 0000000073026000: C:\WINDOWS\system32\WINSPOOL.DRV
(0000000074290000 - 0000000074294000: C:\WINDOWS\system32\icmp.dll
(0000000074320000 - 000000007435d000: C:\WINDOWS\system32\ODBC32.dll
(0000000074410000 - 000000007443e000: C:\WINDOWS\system32\scecli.dll
(0000000075150000 - 0000000075164000: C:\WINDOWS\system32\Cabinet.dll
(0000000075930000 - 000000007593a000: C:\WINDOWS\system32\PROFMAP.dll
(0000000075940000 - 0000000075948000: C:\WINDOWS\system32\NDdeApi.dll
(0000000075950000 - 000000007596a000: C:\WINDOWS\system32\WlNotify.dll
(0000000075970000 - 0000000075a67000: C:\WINDOWS\system32\MSGINA.dll
(0000000075e90000 - 0000000075f40000: C:\WINDOWS\system32\sxs.dll
(0000000076360000 - 0000000076370000: C:\WINDOWS\system32\WINSTA.dll
(00000000763b0000 - 00000000763f9000: C:\WINDOWS\system32\comdlg32.dll
(0000000076600000 - 000000007661d000: C:\WINDOWS\system32\cscdll.dll
(0000000076790000 - 000000007679c000: C:\WINDOWS\system32\cryptdll.dll
(00000000767a0000 - 00000000767b3000: C:\WINDOWS\system32\NTDSAPI.DLL
(00000000769c0000 - 0000000076a73000: C:\WINDOWS\system32\USERENV.dll
(0000000076b20000 - 0000000076b31000: C:\WINDOWS\system32\ATL.DLL
(0000000076b40000 - 0000000076b6d000: C:\WINDOWS\system32\WINMM.dll
(0000000076bb0000 - 0000000076bb5000: C:\WINDOWS\system32\sfc.dll
(0000000076bc0000 - 0000000076bcf000: C:\WINDOWS\system32\REGAPI.dll
(0000000076bf0000 - 0000000076bfb000: C:\WINDOWS\system32\PSAPI.DLL
(0000000076c30000 - 0000000076c5e000: C:\WINDOWS\system32\WINTRUST.dll
(0000000076c60000 - 0000000076c8a000: C:\WINDOWS\system32\sfc_os.dll
(0000000076c90000 - 0000000076cb8000: C:\WINDOWS\system32\IMAGEHLP.dll
(0000000076d40000 - 0000000076d58000: C:\WINDOWS\system32\MPRAPI.dll
(0000000076d60000 - 0000000076d79000: C:\WINDOWS\system32\iphlpapi.dll
(0000000076e10000 - 0000000076e35000: C:\WINDOWS\system32\adsldpc.dll
(0000000076e80000 - 0000000076e8e000: C:\WINDOWS\system32\rtutils.dll
(0000000076f20000 - 0000000076f47000: C:\WINDOWS\system32\DNSAPI.dll
(0000000076f50000 - 0000000076f58000: C:\WINDOWS\system32\WTSAPI32.dll
(0000000076f60000 - 0000000076f8c000: C:\WINDOWS\system32\WLDAP32.dll
(0000000076fd0000 - 000000007704f000: C:\WINDOWS\system32\CLBCATQ.DLL
(0000000077050000 - 0000000077115000: C:\WINDOWS\system32\COMRes.dll
(0000000077120000 - 00000000771ac000: C:\WINDOWS\system32\OLEAUT32.dll
(00000000773d0000 - 00000000774d2000:
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
(00000000774e0000 - 000000007761d000: C:\WINDOWS\system32\ole32.dll
(0000000077690000 - 00000000776b1000: C:\WINDOWS\system32\NTMARTA.DLL
(00000000776c0000 - 00000000776d1000: C:\WINDOWS\system32\AUTHZ.dll
(00000000776e0000 - 0000000077703000: C:\WINDOWS\system32\SHSVCS.dll
(0000000077920000 - 0000000077a13000: C:\WINDOWS\system32\SETUPAPI.dll
(0000000077a80000 - 0000000077b14000: C:\WINDOWS\system32\CRYPT32.dll
(0000000077b20000 - 0000000077b32000: C:\WINDOWS\system32\MSASN1.dll
(0000000077b40000 - 0000000077b62000: C:\WINDOWS\system32\Apphelp.dll
(0000000077c00000 - 0000000077c08000: C:\WINDOWS\system32\VERSION.dll
(0000000077c10000 - 0000000077c68000: C:\WINDOWS\system32\msvcrt.dll
(0000000077cc0000 - 0000000077cf2000: C:\WINDOWS\system32\ACTIVEDS.dll
(0000000077d40000 - 0000000077dd0000: C:\WINDOWS\system32\USER32.dll
(0000000077dd0000 - 0000000077e6b000: C:\WINDOWS\system32\ADVAPI32.dll
(0000000077e70000 - 0000000077f01000: C:\WINDOWS\system32\RPCRT4.dll
(0000000077f10000 - 0000000077f57000: C:\WINDOWS\system32\GDI32.dll
(0000000077f60000 - 0000000077fd6000: C:\WINDOWS\system32\SHLWAPI.dll
(0000000077fe0000 - 0000000077ff1000: C:\WINDOWS\system32\Secur32.dll
(000000007c800000 - 000000007c8f4000: C:\WINDOWS\system32\kernel32.dll
(000000007c900000 - 000000007c9b0000: C:\WINDOWS\system32\ntdll.dll
(000000007c9c0000 - 000000007d1d5000: C:\WINDOWS\system32\SHELL32.dll
*----> State Dump for Thread Id 0x208 <----*
eax=00000000 ebx=00000000 ecx=00000000 edx=00000000 esi=00572ee8
edi=00000001
eip=7c90eb94 esp=0006fb78 ebp=0006fbac iopl=0 nv up ei pl zr na
po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for C:\WINDOWS\system32\ntdll.dll -
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for C:\WINDOWS\system32\USER32.dll -
WARNING: Stack unwind information not available. Following frames may
be wrong.
*** ERROR: Module load completed but symbols could not be loaded for
\??\C:\WINDOWS\system32\winlogon.exe
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for C:\WINDOWS\system32\MSGINA.dll -
ChildEBP RetAddr Args to Child
0006fbac 77d561c6 00020034 00000000 00000010 ntdll!KiFastSystemCallRet
0006fbd4 77d56208 75970000 759a0778 00000000 USER32!DrawStateW+0x1f2
0006fbf4 77d5666b 75970000 759a0778 00000000
USER32!DialogBoxIndirectParamAorW+0x36
0006fc18 0103cfbe 75970000 00000578 00000000
USER32!DialogBoxParamW+0x3f
0006fc3c 0102cab7 75970000 00000578 00000000 winlogon+0x3cfbe
0006fc78 0103b13d 00079af0 75970000 00000578 winlogon+0x2cab7
0006fcb0 7597bfec 00079af0 75970000 00000578 winlogon+0x3b13d
0006fcd8 0103771e 00133648 00079af0 00072364
MSGINA!WlxDisplaySASNotice+0x45
0006fcfc 010315d5 00079af0 7c80b529 00000000 winlogon+0x3771e
0006ff50 0103d4d0 01000000 00000000 00072364 winlogon+0x315d5
0006fff4 00000000 7ffdd000 000000c8 000001f4 winlogon+0x3d4d0
*----> Raw Stack Dump <----*
000000000006fb78 18 94 d4 77 a2 e2 d5 77 - 00 00 00 00 00 00 00 00
....w...w........
000000000006fb88 00 00 00 00 26 00 01 00 - 13 01 00 00 01 00 00 00
.....&...........
000000000006fb98 00 00 00 00 27 cf 00 00 - 00 02 00 00 80 01 00 00
.....'...........
000000000006fba8 00 00 00 00 d4 fb 06 00 - c6 61 d5 77 34 00 02 00
..........a.w4...
000000000006fbb8 00 00 00 00 10 00 00 00 - 00 00 00 00 80 9b 07 00
.................
000000000006fbc8 ff ff ff ff 00 00 00 00 - 00 00 00 00 f4 fb 06 00
.................
000000000006fbd8 08 62 d5 77 00 00 97 75 - 78 07 9a 75 00 00 00 00
..b.w...ux..u....
000000000006fbe8 59 ac 03 01 a8 fc 06 00 - 01 00 00 00 18 fc 06 00
Y...............
000000000006fbf8 6b 66 d5 77 00 00 97 75 - 78 07 9a 75 00 00 00 00
kf.w...ux..u....
000000000006fc08 59 ac 03 01 a8 fc 06 00 - 00 00 00 00 f0 9a 07 00
Y...............
000000000006fc18 3c fc 06 00 be cf 03 01 - 00 00 97 75 78 05 00 00
<..........ux...
000000000006fc28 00 00 00 00 59 ac 03 01 - a8 fc 06 00 f0 9a 07 00
.....Y...........
000000000006fc38 09 00 08 12 78 fc 06 00 - b7 ca 02 01 00 00 97 75
.....x..........u
000000000006fc48 78 05 00 00 00 00 00 00 - 59 ac 03 01 a8 fc 06 00
x.......Y.......
000000000006fc58 f0 9a 07 00 1d 70 44 77 - 00 00 00 00 00 00 00 00
......pDw........
000000000006fc68 00 00 00 01 00 00 00 00 - 11 00 01 00 06 00 00 00
.................
000000000006fc78 b0 fc 06 00 3d b1 03 01 - f0 9a 07 00 00 00 97 75
.....=..........u
000000000006fc88 78 05 00 00 00 00 00 00 - 59 ac 03 01 a8 fc 06 00
x.......Y.......
000000000006fc98 00 00 00 10 00 00 00 00 - 02 00 00 00 f0 9a 07 00
.................
000000000006fca8 f0 9a 07 00 80 9b 07 00 - d8 fc 06 00 ec bf 97 75
................u
*----> State Dump for Thread Id 0x21c <----*
eax=7ffdc000 ebx=00000000 ecx=7c809a20 edx=00000802 esi=00086e98
edi=000877f8
eip=7c90eb94 esp=00a4fe1c ebp=00a4ff80 iopl=0 nv up ei pl zr na
po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for C:\WINDOWS\system32\RPCRT4.dll -
WARNING: Stack unwind information not available. Following frames may
be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for C:\WINDOWS\system32\kernel32.dll -
ChildEBP RetAddr Args to Child
00a4ff80 77e76c22 00a4ffa8 77e76a3b 00086e98 ntdll!KiFastSystemCallRet
00a4ff88 77e76a3b 00086e98 7c90ee18 0006f688
RPCRT4!I_RpcBCacheFree+0x5ea
00a4ffa8 77e76c0a 00086ad8 00a4ffec 7c80b50b
RPCRT4!I_RpcBCacheFree+0x403
00a4ffb4 7c80b50b 00087088 7c90ee18 0006f688
RPCRT4!I_RpcBCacheFree+0x5d2
00a4ffec 00000000 77e76bf0 00087088 00000000
kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
0000000000a4fe1c 99 e3 90 7c 03 67 e7 77 - 44 01 00 00 70 ff a4 00
....|.g.wD...p...
0000000000a4fe2c 38 fe a4 00 f8 77 08 00 - 54 ff a4 00 28 00 40 00
8....w..T...(.@.
0000000000a4fe3c 00 00 00 00 30 02 00 00 - cc 06 00 00 87 27 00 00
.....0........'..
0000000000a4fe4c 00 00 00 00 02 da 99 81 - 01 00 00 00 00 00 00 00
.................
0000000000a4fe5c 7c 9b ec f9 0c 60 4f 80 - 1f 00 00 00 a8 ed 99 81
|....`O.........
0000000000a4fe6c 38 f5 df ff 00 00 00 00 - 00 00 00 00 00 00 00 00
8...............
0000000000a4fe7c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000a4fe8c d2 1b 4e 80 c8 a9 bc 81 - a8 ed 99 81 7a f9 4e 80
...N.........z.N.
0000000000a4fe9c 00 00 00 00 a8 ed 99 81 - 00 00 00 00 20 aa bc 81
............. ...
0000000000a4feac 00 9c ec f9 18 9c ec f9 - fd 38 57 80 00 00 00 00
..........8W.....
0000000000a4febc a8 ed 99 81 f0 ef 99 81 - 00 00 00 00 08 00 20 00
............... .
0000000000a4fecc 06 00 00 00 68 d8 99 81 - fc ff 3f 00 10 14 30 c0
.....h.....?...0.
0000000000a4fedc 00 00 00 00 e2 07 55 80 - 00 00 00 00 00 60 62 e1
.......U......`b.
0000000000a4feec 00 00 00 00 c8 a9 bc 81 - a8 ed 99 81 00 00 00 00
.................
0000000000a4fefc 58 18 00 e1 02 42 00 00 - 30 d0 0a 81 98 41 00 c0
X....B..0....A..
0000000000a4ff0c e7 41 00 00 00 00 00 00 - 00 00 00 00 38 f5 df ff
..A..........8...
0000000000a4ff1c 66 c7 4d 80 00 6a 8e 81 - 2f c5 4d 80 e4 6b 8e 81
f.M..j../.M..k..
0000000000a4ff2c 78 6a 8e 81 80 ff a4 00 - 99 66 e7 77 4c ff a4 00
xj.......f.wL...
0000000000a4ff3c a9 66 e7 77 ed 10 90 7c - 60 70 08 00 88 70 08 00
..f.w...|`p...p..
0000000000a4ff4c 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff
.../M.....]......
*----> State Dump for Thread Id 0x220 <----*
eax=77e76bf0 ebx=00000000 ecx=0006f8d4 edx=000003fa esi=00087228
edi=000872cc
eip=7c90eb94 esp=00a8fe1c ebp=00a8ff80 iopl=0 nv up ei pl zr na
po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
00a8ff80 77e76c22 00a8ffa8 77e76a3b 00087228 ntdll!KiFastSystemCallRet
00a8ff88 77e76a3b 00087228 00000000 00086f78
RPCRT4!I_RpcBCacheFree+0x5ea
00a8ffa8 77e76c0a 00086ad8 00a8ffec 7c80b50b
RPCRT4!I_RpcBCacheFree+0x403
00a8ffb4 7c80b50b 00087398 00000000 00086f78
RPCRT4!I_RpcBCacheFree+0x5d2
00a8ffec 00000000 77e76bf0 00087398 00000000
kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
0000000000a8fe1c 99 e3 90 7c 03 67 e7 77 - 20 01 00 00 70 ff a8 00
....|.g.w ...p...
0000000000a8fe2c 00 00 00 00 08 79 08 00 - 54 ff a8 00 00 00 00 00
......y..T.......
0000000000a8fe3c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000a8fe4c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000a8fe5c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000a8fe6c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000a8fe7c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000a8fe8c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000a8fe9c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000a8feac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000a8febc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000a8fecc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000a8fedc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000a8feec 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000a8fefc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000a8ff0c 00 00 00 00 00 00 00 00 - 00 00 00 00 38 f5 df ff
.............8...
0000000000a8ff1c 66 c7 4d 80 00 9d 9b 81 - 2f c5 4d 80 14 9f 9b 81
f.M...../.M.....
0000000000a8ff2c a8 9d 9b 81 80 ff a8 00 - 99 66 e7 77 4c ff a8 00
..........f.wL...
0000000000a8ff3c a9 66 e7 77 ed 10 90 7c - 70 73 08 00 98 73 08 00
..f.w...|ps...s..
0000000000a8ff4c 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff
.../M.....]......
*----> State Dump for Thread Id 0x224 <----*
eax=000000c0 ebx=00000000 ecx=4300a234 edx=00000045 esi=00000000
edi=0006f7f0
eip=7c90eb94 esp=00adff9c ebp=00adffb4 iopl=0 nv up ei pl zr na
po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
00adffb4 7c80b50b 00000000 0006f7f0 00000000 ntdll!KiFastSystemCallRet
00adffec 00000000 7c92798d 00000000 00000000
kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
0000000000adff9c 5c d8 90 7c d4 79 92 7c - 01 00 00 00 ac ff ad 00
\..|.y.|........
0000000000adffac 00 00 00 00 00 00 00 80 - ec ff ad 00 0b b5 80 7c
................|
0000000000adffbc 00 00 00 00 f0 f7 06 00 - 00 00 00 00 00 00 00 00
.................
0000000000adffcc 00 a0 fd 7f 00 46 bc 81 - c0 ff ad 00 a0 60 9a 81
......F.......`..
0000000000adffdc ff ff ff ff f3 99 83 7c - 18 b5 80 7c 00 00 00 00
........|...|....
0000000000adffec 00 00 00 00 00 00 00 00 - 8d 79 92 7c 00 00 00 00
..........y.|....
0000000000adfffc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000ae000c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000ae001c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000ae002c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000ae003c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000ae004c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000ae005c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000ae006c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000ae007c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000ae008c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000ae009c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000ae00ac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000ae00bc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000ae00cc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
*----> State Dump for Thread Id 0x228 <----*
eax=00def000 ebx=00000000 ecx=00b1f57c edx=00001000 esi=7c97c380
edi=7c97c3a0
eip=7c90eb94 esp=00b1ff70 ebp=00b1ffb4 iopl=0 nv up ei ng nz na
po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000286
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
00b1ffb4 7c80b50b 00000000 0006f7f0 00000000 ntdll!KiFastSystemCallRet
00b1ffec 00000000 7c910760 00000000 00000000
kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
0000000000b1ff70 1b e3 90 7c 9d 07 91 7c - 6c 01 00 00 ac ff b1 00
....|...|l.......
0000000000b1ff80 b0 ff b1 00 98 ff b1 00 - a0 ff b1 00 f0 f7 06 00
.................
0000000000b1ff90 00 00 00 00 00 00 00 00 - 00 00 00 00 f0 9a 07 00
.................
0000000000b1ffa0 00 7c 28 e8 ff ff ff ff - a0 7c 3b f9 69 75 92 7c
..|(......|;.iu.|
0000000000b1ffb0 08 5a e0 00 ec ff b1 00 - 0b b5 80 7c 00 00 00 00
..Z.........|....
0000000000b1ffc0 f0 f7 06 00 00 00 00 00 - 00 00 00 00 00 90 fd 7f
.................
0000000000b1ffd0 00 46 bc 81 c0 ff b1 00 - a0 60 9a 81 ff ff ff ff
..F.......`......
0000000000b1ffe0 f3 99 83 7c 18 b5 80 7c - 00 00 00 00 00 00 00 00
....|...|........
0000000000b1fff0 00 00 00 00 60 07 91 7c - 00 00 00 00 00 00 00 00
.....`..|........
0000000000b20000 d2 d2 d2 d2 d2 d2 d2 d2 - d2 d2 d2 d2 d2 d2 d2 d2
.................
0000000000b20010 d2 d2 d2 d2 d2 d2 d2 d2 - d2 d2 d2 d2 d2 d2 d2 d2
.................
0000000000b20020 d2 d2 d2 d2 d2 d2 d2 d2 - d2 d2 d2 d2 d2 d2 d2 d2
.................
0000000000b20030 d2 d2 d2 d2 d2 d2 d2 d2 - d2 d2 d2 d2 d2 d2 d2 d2
.................
0000000000b20040 d2 d2 d2 d2 d2 d2 d2 d2 - d2 d2 d2 d2 d2 d2 d2 d2
.................
0000000000b20050 d2 d2 d2 d2 d2 d2 d2 d2 - d2 d2 d2 d2 d2 d2 d2 d2
.................
0000000000b20060 d2 d2 d2 d2 d2 d2 d2 d2 - d2 d2 d2 d2 d2 d2 d2 d2
.................
0000000000b20070 d2 d2 e0 e0 df e1 df df - df 0c 0c 0c 0c 0c 0c 0c
.................
0000000000b20080 0c 0c 0c f6 f6 f6 f6 f6 - f6 f6 07 07 07 07 07 07
.................
0000000000b20090 07 07 07 49 07 49 49 49 - 49 49 24 24 24 24 24 24
....I.IIIII$$$$$$
0000000000b200a0 24 30 30 30 30 36 36 36 - 36 21 21 21 21 32 32 32
$00006666!!!!222
*----> State Dump for Thread Id 0x22c <----*
eax=77e76bf0 ebx=00007530 ecx=0000021a edx=7c913e88 esi=00000000
edi=00000000
eip=7c90eb94 esp=00b6feac ebp=00b6fed8 iopl=0 nv up ei ng nz ac
po cy
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000297
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
00b6fed8 77e772fa 00000170 00b6ff10 00b6ff00 ntdll!KiFastSystemCallRet
00b6ff14 77e7722b 00007530 00b6ff6c 00b6ff70
RPCRT4!I_RpcBCacheFree+0xcc2
00b6ff80 77e773a9 00b6ffa8 77e76a3b 00088a38
RPCRT4!I_RpcBCacheFree+0xbf3
00b6ff88 77e76a3b 00088a38 0006f5a0 00000008
RPCRT4!I_RpcBCacheFree+0xd71
00b6ffa8 77e76c0a 00086ad8 00b6ffec 7c80b50b
RPCRT4!I_RpcBCacheFree+0x403
00b6ffb4 7c80b50b 00089430 0006f5a0 00000008
RPCRT4!I_RpcBCacheFree+0x5d2
00b6ffec 00000000 77e76bf0 00089430 00000000
kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
0000000000b6feac 1b e3 90 7c d9 cb 80 7c - 70 01 00 00 00 ff b6 00
....|...|p.......
0000000000b6febc f0 fe b6 00 d0 fe b6 00 - c8 fe b6 00 00 5d 1e ee
..............]..
0000000000b6fecc ff ff ff ff 00 00 00 00 - ac 0f e0 00 14 ff b6 00
.................
0000000000b6fedc fa 72 e7 77 70 01 00 00 - 10 ff b6 00 00 ff b6 00
..r.wp...........
0000000000b6feec 08 ff b6 00 30 75 00 00 - 94 97 80 7c 38 8a 08 00
.....0u.....|8...
0000000000b6fefc 00 00 00 00 10 00 00 00 - 70 01 00 00 00 00 00 00
.........p.......
0000000000b6ff0c 00 00 00 00 00 00 00 00 - 80 ff b6 00 2b 72 e7 77
.............+r.w
0000000000b6ff1c 30 75 00 00 6c ff b6 00 - 70 ff b6 00 78 ff b6 00
0u..l...p...x...
0000000000b6ff2c 64 ff b6 00 68 ff b6 00 - 74 ff b6 00 ed 10 90 7c
d...h...t......|
0000000000b6ff3c 08 94 08 00 30 94 08 00 - 30 94 08 00 70 01 00 00
.....0...0...p...
0000000000b6ff4c 3c b9 4f 80 00 00 00 00 - 00 00 00 00 00 00 00 00
<.O.............
0000000000b6ff5c 00 00 00 00 30 75 00 00 - f4 05 4f 80 00 00 00 00
.....0u....O.....
0000000000b6ff6c 00 00 00 00 74 ce 4d 80 - 00 00 00 00 70 01 00 00
.....t.M.....p...
0000000000b6ff7c 00 00 00 00 88 ff b6 00 - a9 73 e7 77 a8 ff b6 00
..........s.w....
0000000000b6ff8c 3b 6a e7 77 38 8a 08 00 - a0 f5 06 00 08 00 00 00
;j.w8...........
0000000000b6ff9c 30 94 08 00 30 94 08 00 - 30 94 08 00 b4 ff b6 00
0...0...0.......
0000000000b6ffac 0a 6c e7 77 d8 6a 08 00 - ec ff b6 00 0b b5 80 7c
..l.w.j.........|
0000000000b6ffbc 30 94 08 00 a0 f5 06 00 - 08 00 00 00 30 94 08 00
0...........0...
0000000000b6ffcc 00 80 fd 7f 00 46 bc 81 - c0 ff b6 00 28 ea 7a 81
......F......(.z.
0000000000b6ffdc ff ff ff ff f3 99 83 7c - 18 b5 80 7c 00 00 00 00
........|...|....
*----> State Dump for Thread Id 0x238 <----*
eax=000000c0 ebx=00000000 ecx=7c9106ab edx=7c910732 esi=00000000
edi=00000001
eip=7c90eb94 esp=00bafcec ebp=00baffb4 iopl=0 nv up ei pl zr na
po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
00baffb4 7c80b50b 00000000 7c90ee18 7c910738 ntdll!KiFastSystemCallRet
00baffec 00000000 7c929fae 00000000 00000000
kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
0000000000bafcec ab e9 90 7c d5 a0 92 7c - 0a 00 00 00 30 fd ba 00
....|...|....0...
0000000000bafcfc 01 00 00 00 01 00 00 00 - 00 00 00 00 18 ee 90 7c
................|
0000000000bafd0c 38 07 91 7c 00 00 00 00 - 08 e5 97 7c 08 e5 97 7c
8..|.......|...|
0000000000bafd1c 90 01 00 00 38 02 00 00 - 0a 00 00 00 0a 00 00 00
.....8...........
0000000000bafd2c 09 00 00 00 94 01 00 00 - 98 01 00 00 a4 01 00 00
.................
0000000000bafd3c b4 01 00 00 24 02 00 00 - d0 05 00 00 f4 05 00 00
.....$...........
0000000000bafd4c 88 06 00 00 04 07 00 00 - 00 07 00 00 00 00 00 00
.................
0000000000bafd5c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000bafd6c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000bafd7c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000bafd8c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000bafd9c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000bafdac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000bafdbc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000bafdcc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000bafddc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000bafdec 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000bafdfc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000bafe0c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000bafe1c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
*----> State Dump for Thread Id 0x270 <----*
eax=0102bda1 ebx=00000000 ecx=00000040 edx=0006fa14 esi=0000019c
edi=00000000
eip=7c90eb94 esp=00c2fe84 ebp=00c2fee8 iopl=0 nv up ei ng nz ac
po cy
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000297
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
00c2fee8 7c802542 0000019c 0000ea60 00000000 ntdll!KiFastSystemCallRet
00c2fefc 0102be0e 0000019c 0000ea60 00000010
kernel32!WaitForSingleObject+0x12
00c2ffb4 7c80b50b 00000000 00000010 00000018 winlogon+0x2be0e
00c2ffec 00000000 0102bda1 00000000 00000000
kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
0000000000c2fe84 c0 e9 90 7c db 25 80 7c - 9c 01 00 00 00 00 00 00
....|.%.|........
0000000000c2fe94 b8 fe c2 00 9c 01 00 00 - 60 ea 00 00 00 00 00 00
.........`.......
0000000000c2fea4 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000c2feb4 10 00 00 00 00 ba 3c dc - ff ff ff ff 00 d0 fd 7f
.......<.........
0000000000c2fec4 00 e0 fd 7f b8 fe c2 00 - 00 00 00 00 98 fe c2 00
.................
0000000000c2fed4 24 00 00 00 dc ff c2 00 - f3 99 83 7c 08 26 80 7c
$..........|.&.|
0000000000c2fee4 00 00 00 00 fc fe c2 00 - 42 25 80 7c 9c 01 00 00
.........B%.|....
0000000000c2fef4 60 ea 00 00 00 00 00 00 - b4 ff c2 00 0e be 02 01
`...............
0000000000c2ff04 9c 01 00 00 60 ea 00 00 - 10 00 00 00 18 00 00 00
.....`...........
0000000000c2ff14 9c 00 00 00 05 00 00 00 - 01 00 00 00 28 0a 00 00
.............(...
0000000000c2ff24 02 00 00 00 53 65 72 76 - 69 63 65 20 50 61 63 6b
.....Service Pack
0000000000c2ff34 20 32 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
2..............
0000000000c2ff44 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000c2ff54 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000c2ff64 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000c2ff74 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000c2ff84 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000c2ff94 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000c2ffa4 00 00 00 00 02 00 00 00 - 00 01 01 00 1c b6 00 00
.................
0000000000c2ffb4 ec ff c2 00 0b b5 80 7c - 00 00 00 00 10 00 00 00
........|........
*----> State Dump for Thread Id 0x2a0 <----*
eax=00dd9000 ebx=00000002 ecx=00e7fd08 edx=00002000 esi=76c629d8
edi=00000000
eip=7c90eb94 esp=00e7ff64 ebp=00e7ffb4 iopl=0 nv up ei pl zr na
po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
00e7ffb4 7c80b50b 00000000 75f2bd60 00d5ff38 ntdll!KiFastSystemCallRet
00e7ffec 00000000 76c6c86b 00000000 00000000
kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
0000000000e7ff64 ab e9 90 7c 39 cc c6 76 - 02 00 00 00 80 84 12 00
....|9..v........
0000000000e7ff74 00 00 00 00 01 00 00 00 - 00 00 00 00 60 bd f2 75
.............`..u
0000000000e7ff84 38 ff d5 00 00 00 00 00 - 0c b0 08 00 e8 0c d6 00
8...............
0000000000e7ff94 e0 0c d6 00 80 84 12 00 - c8 0c d6 00 00 00 00 00
.................
0000000000e7ffa4 c0 0c d6 00 08 b0 08 00 - 80 01 d6 00 02 00 00 00
.................
0000000000e7ffb4 ec ff e7 00 0b b5 80 7c - 00 00 00 00 60 bd f2 75
........|....`..u
0000000000e7ffc4 38 ff d5 00 00 00 00 00 - 00 50 fd 7f 00 46 bc 81
8........P...F..
0000000000e7ffd4 c0 ff e7 00 d0 a0 95 81 - ff ff ff ff f3 99 83 7c
................|
0000000000e7ffe4 18 b5 80 7c 00 00 00 00 - 00 00 00 00 00 00 00 00
....|............
0000000000e7fff4 6b c8 c6 76 00 00 00 00 - 00 00 00 00 00 00 00 00
k..v............
0000000000e80004 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000e80014 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000e80024 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000e80034 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000e80044 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000e80054 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000e80064 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000e80074 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000e80084 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000e80094 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
*----> State Dump for Thread Id 0x2a4 <----*
eax=76c6c5ae ebx=00d60cc8 ecx=00e7fc74 edx=7c911538 esi=76c629d8
edi=00000000
eip=7c90eb94 esp=00ebff4c ebp=00ebffb4 iopl=0 nv up ei pl nz na
pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000202
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
00ebffb4 7c80b50b 00dd99a8 7c90ee18 000002ee ntdll!KiFastSystemCallRet
00ebffec 00000000 76c6c5ae 00d60cc8 00000000
kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
0000000000ebff4c ab e9 90 7c 2a c8 c6 76 - 40 00 00 00 e8 0c d6 00
....|*..v@.......
0000000000ebff5c 01 00 00 00 01 00 00 00 - 00 00 00 00 18 ee 90 7c
................|
0000000000ebff6c ee 02 00 00 c8 0c d6 00 - 00 00 00 00 01 00 00 00
.................
0000000000ebff7c 02 00 00 00 04 00 00 00 - 08 00 00 00 10 00 00 00
.................
0000000000ebff8c 00 00 00 00 20 10 9f 81 - 1c b9 4f 80 00 00 00 00
..... .....O.....
0000000000ebff9c 00 00 00 00 00 00 00 00 - 00 00 00 00 80 01 d6 00
.................
0000000000ebffac e0 01 d6 00 1e 00 00 00 - ec ff eb 00 0b b5 80 7c
................|
0000000000ebffbc a8 99 dd 00 18 ee 90 7c - ee 02 00 00 c8 0c d6 00
........|........
0000000000ebffcc 00 40 fd 7f 00 46 bc 81 - c0 ff eb 00 d0 a0 95 81
..@...F..........
0000000000ebffdc ff ff ff ff f3 99 83 7c - 18 b5 80 7c 00 00 00 00
........|...|....
0000000000ebffec 00 00 00 00 00 00 00 00 - ae c5 c6 76 c8 0c d6 00
............v....
0000000000ebfffc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000ec000c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000ec001c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000ec002c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000ec003c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000ec004c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000ec005c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000ec006c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000ec007c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
*----> State Dump for Thread Id 0x2a8 <----*
eax=00000083 ebx=00d60cd4 ecx=00000010 edx=001bb3b7 esi=76c629d8
edi=00dda1d0
eip=7c90eb94 esp=00efff4c ebp=00efffb4 iopl=0 nv up ei pl zr na
po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
00efffb4 7c80b50b 00dd9dc0 7c90ee18 000002ee ntdll!KiFastSystemCallRet
00efffec 00000000 76c6c5ae 00d60cd4 00000000
kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
0000000000efff4c ab e9 90 7c 2a c8 c6 76 - 3a 00 00 00 f0 0d d6 00
....|*..v:.......
0000000000efff5c 01 00 00 00 01 00 00 00 - 00 00 00 00 18 ee 90 7c
................|
0000000000efff6c ee 02 00 00 d4 0c d6 00 - 00 00 00 00 01 00 00 00
.................
0000000000efff7c 02 00 00 00 04 00 00 00 - 08 00 00 00 10 00 00 00
.................
0000000000efff8c 00 00 00 00 20 10 9f 81 - 1c b9 4f 80 00 00 00 00
..... .....O.....
0000000000efff9c 00 00 00 00 00 00 00 00 - 24 b9 4f 80 68 07 d6 00
.........$.O.h...
0000000000efffac f2 fe 6f 80 dc e2 90 7c - ec ff ef 00 0b b5 80 7c
...o....|.......|
0000000000efffbc c0 9d dd 00 18 ee 90 7c - ee 02 00 00 d4 0c d6 00
........|........
0000000000efffcc 00 f0 fa 7f 00 46 bc 81 - c0 ff ef 00 08 a0 95 81
......F..........
0000000000efffdc ff ff ff ff f3 99 83 7c - 18 b5 80 7c 00 00 00 00
........|...|....
0000000000efffec 00 00 00 00 00 00 00 00 - ae c5 c6 76 d4 0c d6 00
............v....
0000000000effffc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000f0000c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000f0001c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000f0002c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000f0003c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000f0004c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000f0005c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000f0006c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000000f0007c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
*----> State Dump for Thread Id 0x328 <----*
eax=00000201 ebx=00000000 ecx=00000210 edx=001be8f4 esi=00086e98
edi=00ddc9c8
eip=7c90eb94 esp=00f3fe1c ebp=00f3ff80 iopl=0 nv up ei pl zr na
po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
00f3ff80 77e76c22 00f3ffa8 77e76a3b 00086e98 ntdll!KiFastSystemCallRet
00f3ff88 77e76a3b 00086e98 00000000 00000000
RPCRT4!I_RpcBCacheFree+0x5ea
00f3ffa8 77e76c0a 00086ad8 00f3ffec 7c80b50b
RPCRT4!I_RpcBCacheFree+0x403
00f3ffb4 7c80b50b 0008b728 00000000 00000000
RPCRT4!I_RpcBCacheFree+0x5d2
00f3ffec 00000000 77e76bf0 0008b728 00000000
kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
0000000000f3fe1c 99 e3 90 7c 03 67 e7 77 - 44 01 00 00 70 ff f3 00
....|.g.wD...p...
0000000000f3fe2c 38 fe f3 00 c8 c9 dd 00 - 54 ff f3 00 58 00 70 00
8.......T...X.p.
0000000000f3fe3c 00 00 00 00 30 02 00 00 - cc 06 00 00 88 27 00 00
.....0........'..
0000000000f3fe4c 00 00 00 00 02 00 00 00 - 01 00 a5 01 24 b7 00 00
.............$...
0000000000f3fe5c 60 cb 15 81 00 00 00 00 - 9c 36 50 c0 98 ef aa 81
`........6P.....
0000000000f3fe6c 67 02 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
g...............
0000000000f3fe7c 00 00 00 00 00 00 00 00 - 00 00 00 00 b0 3b 87 f5
..............;..
0000000000f3fe8c bc fe 1f c0 90 3b 87 f5 - db a6 4e 80 00 e0 fa 7f
......;....N.....
0000000000f3fe9c 01 00 00 00 00 00 00 00 - b8 fe 1f c0 00 00 00 00
.................
0000000000f3feac fc 07 30 c0 48 3c 87 f5 - 4a ed 4e 80 b0 3b 87 f5
...0.H<..J.N..;..
0000000000f3febc 00 00 00 00 00 00 00 00 - 78 03 9d 81 a0 ed aa 81
.........x.......
0000000000f3fecc 01 ee aa 81 00 00 00 00 - b8 fe 1f c0 00 00 00 00
.................
0000000000f3fedc 00 68 d6 ca ff ff a1 00 - 00 00 04 00 1f 0a 00 00
..h..............
0000000000f3feec 6c ee aa 81 a0 ed aa 81 - 00 00 00 00 00 00 00 00
l...............
0000000000f3fefc 00 00 a2 00 64 3b 87 f5 - fc 3b 87 f5 ff ff ff ff
.....d;...;......
0000000000f3ff0c d8 2e 4e 80 00 e0 fa 7f - ff ff ff ff 38 f5 df ff
...N.........8...
0000000000f3ff1c 66 c7 4d 80 00 2d 7b 81 - 2f c5 4d 80 7c 2e 7b 81
f.M..-{./.M.|.{.
0000000000f3ff2c 10 2d 7b 81 80 ff f3 00 - 99 66 e7 77 4c ff f3 00
..-{......f.wL...
0000000000f3ff3c a9 66 e7 77 ed 10 90 7c - 70 c5 dd 00 28 b7 08 00
..f.w...|p...(...
0000000000f3ff4c 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff
.../M.....]......
*----> State Dump for Thread Id 0x5a0 <----*
eax=769c8831 ebx=0114fef4 ecx=00de3790 edx=00070000 esi=00000000
edi=7ffdd000
eip=7c90eb94 esp=0114fecc ebp=0114ff68 iopl=0 nv up ei pl zr na
po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for C:\WINDOWS\system32\USERENV.dll -
ChildEBP RetAddr Args to Child
0114ff68 7c809c86 00000002 76a60310 00000000 ntdll!KiFastSystemCallRet
0114ff84 769c888d 00000002 76a60310 00000000
kernel32!WaitForMultipleObjects+0x18
0114ffb4 7c80b50b 00000000 7c910f46 00000188
USERENV!UnregisterGPNotification+0x15c
0114ffec 00000000 769c8831 00000000 00000000
kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
000000000114fecc ab e9 90 7c f2 94 80 7c - 02 00 00 00 f4 fe 14 01
....|...|........
000000000114fedc 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
000000000114feec b8 03 a6 76 77 9b 80 7c - 8c 06 00 00 90 06 00 00
....vw..|........
000000000114fefc 6c 00 00 00 5c fe 14 01 - 6c ff 14 01 6c ff 14 01
l...\...l...l...
000000000114ff0c 18 ee 90 7c 70 05 91 7c - 14 00 00 00 01 00 00 00
....|p..|........
000000000114ff1c 00 00 00 00 00 00 00 00 - 10 00 00 00 f6 1b 80 7c
................|
000000000114ff2c 46 0f 91 7c 88 01 00 00 - 00 d0 fd 7f 00 c0 fa 7f
F..|............
000000000114ff3c 28 4a 07 00 00 00 00 00 - f4 fe 14 01 00 00 00 00
(J..............
000000000114ff4c 02 00 00 00 e8 fe 14 01 - 00 00 00 00 dc ff 14 01
.................
000000000114ff5c f3 99 83 7c 90 95 80 7c - 00 00 00 00 84 ff 14 01
....|...|........
000000000114ff6c 86 9c 80 7c 02 00 00 00 - 10 03 a6 76 00 00 00 00
....|.......v....
000000000114ff7c ff ff ff ff 00 00 00 00 - b4 ff 14 01 8d 88 9c 76
................v
000000000114ff8c 02 00 00 00 10 03 a6 76 - 00 00 00 00 ff ff ff ff
........v........
000000000114ff9c 46 0f 91 7c 88 01 00 00 - 00 00 00 00 00 00 9c 76
F..|...........v
000000000114ffac 02 00 00 00 00 00 00 00 - ec ff 14 01 0b b5 80 7c
................|
000000000114ffbc 00 00 00 00 46 0f 91 7c - 88 01 00 00 00 00 00 00
.....F..|........
000000000114ffcc 00 c0 fa 7f 00 46 bc 81 - c0 ff 14 01 d0 c4 5c 81
......F........\.
000000000114ffdc ff ff ff ff f3 99 83 7c - 18 b5 80 7c 00 00 00 00
........|...|....
000000000114ffec 00 00 00 00 00 00 00 00 - 31 88 9c 76 00 00 00 00
.........1..v....
000000000114fffc 00 00 00 00 44 62 75 67 - 00 00 00 00 00 00 15 01
.....Dbug........
*----> State Dump for Thread Id 0xd8 <----*
eax=71a5d5af ebx=c0000000 ecx=7c913288 edx=ffffffff esi=00000000
edi=71a87558
eip=7c90eb94 esp=0119ff7c ebp=0119ffb4 iopl=0 nv up ei pl nz na
pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000202
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
0119ffb4 7c80b50b 71a5d8ec 0110e0d8 7c90ee18 ntdll!KiFastSystemCallRet
0119ffec 00000000 71a5d5af 00df2b40 00000000
kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
000000000119ff7c 1b e3 90 7c 09 d6 a5 71 - 10 07 00 00 bc ff 19 01
....|...q........
000000000119ff8c b0 ff 19 01 a4 ff 19 01 - 50 d6 a5 71 d8 e0 10 01
.........P..q....
000000000119ff9c 18 ee 90 7c 40 2b df 00 - 00 00 00 00 00 00 00 00
....|@+..........
000000000119ffac 00 00 a5 71 18 60 df 00 - ec ff 19 01 0b b5 80 7c
....q.`.........|
000000000119ffbc ec d8 a5 71 d8 e0 10 01 - 18 ee 90 7c 40 2b df 00
....q.......|@+..
000000000119ffcc 00 b0 fa 7f 00 46 bc 81 - c0 ff 19 01 70 12 5b 81
......F......p.[.
000000000119ffdc ff ff ff ff f3 99 83 7c - 18 b5 80 7c 00 00 00 00
........|...|....
000000000119ffec 00 00 00 00 00 00 00 00 - af d5 a5 71 40 2b df 00
............q@+..
000000000119fffc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
00000000011a000c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
00000000011a001c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
00000000011a002c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
00000000011a003c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
00000000011a004c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
00000000011a005c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
00000000011a006c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
00000000011a007c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
00000000011a008c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
00000000011a009c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
00000000011a00ac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
*----> State Dump for Thread Id 0x1a8 <----*
eax=00000000 ebx=00000000 ecx=00000000 edx=776061a8 esi=00000000
edi=00000000
eip=77516777 esp=011dec34 ebp=011dec58 iopl=0 nv up ei pl zr na
po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for C:\WINDOWS\system32\ole32.dll -
function: ole32!CoGetClassObject
7751676a 90 nop
7751676b 90 nop
7751676c 90 nop
7751676d 90 nop
7751676e 90 nop
7751676f 8bff mov edi,edi
77516771 53 push ebx
77516772 56 push esi
77516773 8bf1 mov esi,ecx
77516775 33db xor ebx,ebx
FAULT ->77516777 f6463901 test byte ptr [esi+0x39],0x1
ds:0023:00000039=??
7751677b 57 push edi
7751677c 743f jz ole32!CoGetClassObject+0xa0b
(775167bd)
7751677e e8e1010000 call ole32!CoGetClassObject+0xbb2
(77516964)
77516783 8bf8 mov edi,eax
77516785 85ff test edi,edi
77516787 0f84bbf70400 je
ole32!CoWaitForMultipleHandles+0xee07 (77565f48)
7751678d 6856fa5077 push 0x7750fa56
77516792 6afc push 0xfc
77516794 57 push edi
77516795 897e3c mov [esi+0x3c],edi
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for C:\WINDOWS\system32\scecli.dll -
ChildEBP RetAddr Args to Child
011dec58 7751cdc9 77606dcc 011df0fc 77520890
ole32!CoGetClassObject+0x9c5
011decb8 77520a71 011df0fc 011df648 00000004 ole32!CoGetPSClsid+0x18ad
011def04 7752cddf 77607114 00000000 00000000 ole32!CoRevertToSelf+0x712
011def44 7752cc24 011df0fc 00000000 011df648
ole32!CreateGenericComposite+0x28d4
011df6f4 774ffaba 74ef1a5c 00000000 00000014
ole32!CreateGenericComposite+0x2719
011df71c 774ffa89 74ef1a5c 00000000 00000014
ole32!CoCreateInstanceEx+0x4f
011df740 74ef18c1 74ef1a5c 00000000 00000014
ole32!CoCreateInstanceEx+0x1e
011df774 74ef186e 011df7dc 00000001 00000000 0x74ef18c1
011df7b8 74ef15db 011df7dc 00000001 00000000 0x74ef186e
011df874 74ef17e4 00df7bbc 00000000 00000000 0x74ef15db
011df8a0 74ef1ee1 00df7bbc 00000000 00000000 0x74ef17e4
011df8e0 769d207e 01abffd8 00df7bbc 00000000 0x74ef1ee1
011df94c 769d1f51 00de3798 769d2c00 00000001 USERENV!FreeGPOListW+0x547
011df978 76a2faef 00de3798 769d2c00 00000001 USERENV!FreeGPOListW+0x41a
011dff68 744290e7 74436338 000e0b40 00000000
USERENV!ProcessGroupPolicyCompletedEx+0x41a
011dffb4 7c80b50b 00df7f98 7c913288 00000000 scecli!SceGetAreas+0x490
011dffec 00000000 74428fb9 00df7f98 00000000
kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
00000000011dec34 58 e0 dd 00 a0 61 60 77 - b3 63 51 77 14 71 60 77
X....a`w.cQw.q`w
00000000011dec44 cc 6d 60 77 00 00 00 00 - ae 00 60 77 fc f0 1d 01
..m`w......`w....
00000000011dec54 58 e0 dd 00 b8 ec 1d 01 - c9 cd 51 77 cc 6d 60 77
X.........Qw.m`w
00000000011dec64 fc f0 1d 01 90 08 52 77 - 00 00 00 00 fc f0 1d 01
.......Rw........
00000000011dec74 14 71 60 77 dc cf 4e 77 - a4 ec 1d 01 01 00 00 00
..q`w..Nw........
00000000011dec84 00 00 00 00 10 bb 4e 77 - e0 cf 4e 77 48 f6 1d 01
.......Nw..NwH...
00000000011dec94 b4 ec 1d 01 d9 ba 51 77 - 04 00 00 00 dc cf 4e 77
.......Qw......Nw
00000000011deca4 14 ef 1d 01 14 71 60 77 - 00 00 00 00 fc f0 1d 01
......q`w........
00000000011decb4 af 56 00 00 04 ef 1d 01 - 71 0a 52 77 fc f0 1d 01
..V......q.Rw....
00000000011decc4 48 f6 1d 01 04 00 00 00 - ec 00 9d 00 00 00 9d 00
H...............
00000000011decd4 14 ed 1d 01 33 52 91 7c - fc ec 1d 01 10 00 00 00
.....3R.|........
00000000011dece4 88 17 9d 00 88 17 9d 00 - 08 ed 1d 01 d6 52 91 7c
..............R.|
00000000011decf4 40 ed 1d 01 a8 07 00 00 - 50 ed 1d 01 f0 f6 1d 01
@.......P.......
00000000011ded04 44 15 9d 00 60 ed 1d 01 - 4c 93 92 7c 40 ed 1d 01
D...`...L..|@...
00000000011ded14 88 17 9d 00 01 00 00 00 - 1c 00 00 00 70 93 92 7c
.............p..|
00000000011ded24 44 15 9d 00 08 00 15 c0 - 67 93 92 7c c4 ed 1d 01
D.......g..|....
00000000011ded34 04 00 00 00 e0 f6 1d 01 - 00 d0 fd 7f 5e f0 c3 8b
.............^...
00000000011ded44 fc ff ff ff 00 00 00 00 - 00 a0 fa 7f b0 ed 1d 01
.................
00000000011ded54 2a 26 80 7c 6c ed 1d 01 - 3d fb 90 7c 18 ee 1d 01
*&.|l...=..|....
00000000011ded64 00 00 00 00 98 ed 1d 01 - 6c fb 90 7c 71 fb 90 7c
.........l..|q..|
*----> State Dump for Thread Id 0x1ac <----*
eax=769d3cf1 ebx=0121fe2c ecx=00070000 edx=000706e8 esi=00000000
edi=7ffdd000
eip=7c90eb94 esp=0121fe04 ebp=0121fea0 iopl=0 nv up ei pl zr na
po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
0121fea0 7c809c86 00000004 0121ff10 00000000 ntdll!KiFastSystemCallRet
0121febc 769d3ed2 00000004 0121ff10 00000000
kernel32!WaitForMultipleObjects+0x18
0121ffb4 7c80b50b 00de3798 00070000 7c910732 USERENV!Ordinal147+0x257
0121ffec 00000000 769d3cf1 00de3798 00000000
kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
000000000121fe04 ab e9 90 7c f2 94 80 7c - 04 00 00 00 2c fe 21 01
....|...|....,.!.
000000000121fe14 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
000000000121fe24 98 37 de 00 31 03 91 7c - 84 06 00 00 98 06 00 00
..7..1..|........
000000000121fe34 9c 06 00 00 14 01 00 00 - a8 fe 21 01 b9 ab d4 77
...........!....w
000000000121fe44 7c ff 21 01 7c ff 21 01 - 14 00 00 00 01 00 00 00
|.!.|.!.........
000000000121fe54 00 00 00 00 00 00 00 00 - 10 00 00 00 31 03 91 7c
.............1..|
000000000121fe64 3c aa d4 77 00 00 00 00 - 00 d0 fd 7f 00 90 fa 7f
<..w............
000000000121fe74 00 00 00 00 00 00 00 00 - 2c fe 21 01 89 e7 90 7c
.........,.!....|
000000000121fe84 04 00 00 00 20 fe 21 01 - e0 fe 21 01 dc ff 21 01
..... .!...!...!.
000000000121fe94 f3 99 83 7c 90 95 80 7c - 00 00 00 00 bc fe 21 01
....|...|......!.
000000000121fea4 86 9c 80 7c 04 00 00 00 - 10 ff 21 01 00 00 00 00
....|......!.....
000000000121feb4 ff ff ff ff 00 00 00 00 - b4 ff 21 01 d2 3e 9d 76
...........!..>.v
000000000121fec4 04 00 00 00 10 ff 21 01 - 00 00 00 00 ff ff ff ff
.......!.........
000000000121fed4 00 00 07 00 32 07 91 7c - 98 37 de 00 00 0c b5 56
.....2..|.7.....V
000000000121fee4 f7 ff ff ff 3c 03 a6 76 - 00 00 9c 76 00 00 00 00
.....<..v...v....
000000000121fef4 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
000000000121ff04 00 00 00 00 00 00 00 00 - 00 00 00 00 84 06 00 00
.................
000000000121ff14 98 06 00 00 9c 06 00 00 - 14 01 00 00 00 42 90 81
..............B..
000000000121ff24 04 00 00 00 60 90 0f 00 - 40 c3 38 00 04 00 00 00
.....`...@.8.....
000000000121ff34 14 01 00 00 75 00 73 00 - 65 00 72 00 65 00 6e 00
.....u.s.e.r.e.n.
*----> State Dump for Thread Id 0x148 <----*
eax=77e42700 ebx=0110fe78 ecx=76613270 edx=7c90eb94 esi=00000000
edi=7ffdd000
eip=7c90eb94 esp=0110fe50 ebp=0110feec iopl=0 nv up ei pl zr na
po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols
for C:\WINDOWS\system32\cscdll.dll -
ChildEBP RetAddr Args to Child
0110feec 7c809c86 00000004 0110ff2c 00000000 ntdll!KiFastSystemCallRet
0110ff08 76602041 00000004 0110ff2c 00000000
kernel32!WaitForMultipleObjects+0x18
0110ff3c 766032f7 0009ca87 0009ca87 00000000
cscdll!WinlogonStartShellEvent+0x13f
0110ff54 766032cb 00000000 01039216 0110ff74 cscdll!MprServiceProc+0x1b
0110ffb4 7c80b50b 00dde310 00010246 0006fb78
cscdll!WinlogonStartupEvent+0x40
0110ffec 00000000 01039156 00dde310 00000000
kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
000000000110fe50 ab e9 90 7c f2 94 80 7c - 04 00 00 00 78 fe 10 01
....|...|....x...
000000000110fe60 01 00 00 00 00 00 00 00 - 00 00 00 00 c7 a2 00 00
.................
000000000110fe70 01 00 00 00 ac 92 80 7c - 2c 07 00 00 18 07 00 00
........|,.......
000000000110fe80 30 07 00 00 38 07 00 00 - 94 fe 10 01 2f 1f 60 76
0...8......./.`v
000000000110fe90 70 32 61 76 f8 fe 10 01 - 14 00 00 00 01 00 00 00
p2av............
000000000110fea0 00 00 00 00 00 00 00 00 - 10 00 00 00 00 00 00 00
.................
000000000110feb0 00 00 00 00 00 00 00 00 - 00 d0 fd 7f 00 d0 fa 7f
.................
000000000110fec0 00 00 00 00 00 00 00 00 - 78 fe 10 01 01 00 00 00
.........x.......
000000000110fed0 04 00 00 00 6c fe 10 01 - 00 00 00 00 a4 ff 10 01
.....l...........
000000000110fee0 f3 99 83 7c 90 95 80 7c - 00 00 00 00 08 ff 10 01
....|...|........
000000000110fef0 86 9c 80 7c 04 00 00 00 - 2c ff 10 01 00 00 00 00
....|....,.......
000000000110ff00 ff ff ff ff 00 00 00 00 - 3c ff 10 01 41 20 60 76
.........<...A `v
000000000110ff10 04 00 00 00 2c ff 10 01 - 00 00 00 00 ff ff ff ff
.....,...........
000000000110ff20 10 e3 dd 00 00 00 00 00 - f8 af 07 00 2c 07 00 00
.............,...
000000000110ff30 18 07 00 00 30 07 00 00 - 38 07 00 00 54 ff 10 01
.....0...8...T...
000000000110ff40 f7 32 60 76 87 ca 09 00 - 87 ca 09 00 00 00 00 00
..2`v............
000000000110ff50 05 00 00 00 b4 ff 10 01 - cb 32 60 76 00 00 00 00
..........2`v....
000000000110ff60 16 92 03 01 74 ff 10 01 - 46 02 01 00 78 fb 06 00
.....t...F...x...
000000000110ff70 10 e3 dd 00 20 00 00 00 - 00 00 00 00 00 00 00 00
..... ...........
000000000110ff80 00 00 00 00 d0 b0 07 00 - 00 00 00 00 b0 00 00 00
.................
*----> State Dump for Thread Id 0x1bc <----*
eax=76602dc9 ebx=0126fee8 ecx=00174790 edx=00000000 esi=00000000
edi=7ffdd000
eip=7c90eb94 esp=0126fec0 ebp=0126ff5c iopl=0 nv up ei pl zr na
po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
0126ff5c 7c809c86 00000002 0126ff9c 00000000 ntdll!KiFastSystemCallRet
0126ff78 76602e35 00000002 0126ff9c 00000000
kernel32!WaitForMultipleObjects+0x18
0126ffb4 7c80b50b 00000000 0110fbe4 76f61341
cscdll!WinlogonLogonEvent+0x976
0126ffec 00000000 76602dc9 00000000 00000000
kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
000000000126fec0 ab e9 90 7c f2 94 80 7c - 02 00 00 00 e8 fe 26 01
....|...|......&.
000000000126fed0 01 00 00 00 00 00 00 00 - 00 00 00 00 e4 fb 10 01
.................
000000000126fee0 00 00 00 00 8c 32 61 76 - 3c 07 00 00 e0 06 00 00
......2av<.......
000000000126fef0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
000000000126ff00 00 00 00 00 00 00 00 00 - 14 00 00 00 01 00 00 00
.................
000000000126ff10 00 00 00 00 00 00 00 00 - 10 00 00 00 00 00 00 00
.................
000000000126ff20 00 00 00 00 00 00 00 00 - 00 d0 fd 7f 00 80 fa 7f
.................
000000000126ff30 00 00 00 00 00 00 00 00 - e8 fe 26 01 00 00 00 00
...........&.....
000000000126ff40 02 00 00 00 dc fe 26 01 - 00 00 00 00 dc ff 26 01
.......&.......&.
000000000126ff50 f3 99 83 7c 90 95 80 7c - 00 00 00 00 78 ff 26 01
....|...|....x.&.
000000000126ff60 86 9c 80 7c 02 00 00 00 - 9c ff 26 01 00 00 00 00
....|......&.....
000000000126ff70 ff ff ff ff 00 00 00 00 - b4 ff 26 01 35 2e 60 76
...........&.5.`v
000000000126ff80 02 00 00 00 9c ff 26 01 - 00 00 00 00 ff ff ff ff
.......&.........
000000000126ff90 e4 fb 10 01 41 13 f6 76 - 00 00 00 00 3c 07 00 00
.....A..v....<...
000000000126ffa0 e0 06 00 00 87 ca 09 00 - 00 00 00 00 ff ff 00 00
.................
000000000126ffb0 00 00 00 00 ec ff 26 01 - 0b b5 80 7c 00 00 00 00
.......&....|....
000000000126ffc0 e4 fb 10 01 41 13 f6 76 - 00 00 00 00 00 80 fa 7f
.....A..v........
000000000126ffd0 00 46 bc 81 c0 ff 26 01 - a0 c4 a6 81 ff ff ff ff
..F....&.........
000000000126ffe0 f3 99 83 7c 18 b5 80 7c - 00 00 00 00 00 00 00 00
....|...|........
000000000126fff0 00 00 00 00 c9 2d 60 76 - 00 00 00 00 00 00 00 00
......-`v........
*----> State Dump for Thread Id 0x1dc <----*
eax=77e76bf0 ebx=00000000 ecx=8a885d04 edx=00000000 esi=00df6060
edi=00000100
eip=7c90eb94 esp=01b2fe1c ebp=01b2ff80 iopl=0 nv up ei pl zr na
po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000246
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
01b2ff80 77e76c22 01b2ffa8 77e76a3b 00df6060 ntdll!KiFastSystemCallRet
01b2ff88 77e76a3b 00df6060 00000000 00000000
RPCRT4!I_RpcBCacheFree+0x5ea
01b2ffa8 77e76c0a 00086ad8 01b2ffec 7c80b50b
RPCRT4!I_RpcBCacheFree+0x403
01b2ffb4 7c80b50b 00df76d8 00000000 00000000
RPCRT4!I_RpcBCacheFree+0x5d2
01b2ffec 00000000 77e76bf0 00df76d8 00000000
kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
0000000001b2fe1c 99 e3 90 7c 03 67 e7 77 - 50 08 00 00 70 ff b2 01
....|.g.wP...p...
0000000001b2fe2c 00 00 00 00 30 56 e1 00 - 54 ff b2 01 ec eb 56 80
.....0V..T.....V.
0000000001b2fe3c 50 34 a7 e1 6c 0d 00 00 - e4 9b 69 f5 50 34 a7 e1
P4..l.....i.P4..
0000000001b2fe4c 00 00 00 00 6c 0d 00 00 - 00 00 00 00 d8 2a d6 e1
.....l........*..
0000000001b2fe5c 5c 9b 69 f5 dc ec 56 80 - 50 34 a7 e1 d8 2a d6 e1
\.i...V.P4...*..
0000000001b2fe6c e4 9b 69 f5 00 00 00 00 - 00 00 00 00 6c 0d 00 00
...i.........l...
0000000001b2fe7c a8 9b 69 f5 84 c3 56 80 - 50 34 a7 e1 90 9b 69 f5
...i...V.P4....i.
0000000001b2fe8c 00 00 00 00 00 00 00 00 - 50 74 d9 e1 8a e7 01 00
.........Pt......
0000000001b2fe9c 00 00 00 00 89 e7 01 00 - 00 00 00 00 a0 9b 69 f5
...............i.
0000000001b2feac 75 ba 56 80 38 74 d9 e1 - 08 00 00 00 50 f1 be 81
u.V.8t......P...
0000000001b2febc 38 74 d9 e1 00 00 00 00 - bb ba 00 00 00 00 00 00
8t..............
0000000001b2fecc 00 9c 69 f5 50 74 d9 e1 - d5 ba 56 80 00 9c 69 f5
...i.Pt....V...i.
0000000001b2fedc cc 9b 69 f5 22 bb 56 80 - 00 9c 69 f5 4c f3 24 01
...i.".V...i.L.$.
0000000001b2feec 0c 00 00 00 e4 9b 69 f5 - 07 ef 56 80 50 f3 24 01
.......i...V.P.$.
0000000001b2fefc 48 3b 5f 81 90 3d 5f 81 - 50 74 d9 e1 59 98 57 80
H;_..=_.Pt..Y.W.
0000000001b2ff0c 00 00 00 00 00 00 00 00 - 50 9c 69 f5 38 f5 df ff
.........P.i.8...
0000000001b2ff1c 66 c7 4d 80 00 65 95 81 - 2f c5 4d 80 cc 66 95 81
f.M..e../.M..f..
0000000001b2ff2c 60 65 95 81 80 ff b2 01 - 99 66 e7 77 4c ff b2 01
`e.......f.wL...
0000000001b2ff3c a9 66 e7 77 ed 10 90 7c - 98 ff df 00 d8 76 df 00
..f.w...|.....v..
0000000001b2ff4c 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff
.../M.....]......
*----> State Dump for Thread Id 0x2c0 <----*
eax=774fe429 ebx=00007530 ecx=00000000 edx=00000000 esi=00000000
edi=00ffff50
eip=7c90eb94 esp=00ffff20 ebp=00ffff78 iopl=0 nv up ei pl nz na
po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
efl=00000206
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may
be wrong.
ChildEBP RetAddr Args to Child
00ffff78 7c802451 0000ea60 00000000 00ffffb4 ntdll!KiFastSystemCallRet
00ffff88 774fe31d 0000ea60 00df4f18 774fe3dc kernel32!Sleep+0xf
00ffffb4 7c80b50b 00df4f18 00000000 00000000
ole32!StringFromGUID2+0x51b
00ffffec 00000000 774fe429 00df4f18 00000000
kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
0000000000ffff20 5c d8 90 7c ed 23 80 7c - 00 00 00 00 50 ff ff 00
\..|.#.|....P...
0000000000ffff30 50 25 80 7c f8 6d 60 77 - 30 75 00 00 14 00 00 00
P%.|.m`w0u......
0000000000ffff40 01 00 00 00 00 00 00 00 - 00 00 00 00 10 00 00 00
.................
0000000000ffff50 00 ba 3c dc ff ff ff ff - 00 d1 4e 77 50 ff ff 00
...<.......NwP...
0000000000ffff60 30 ff ff 00 f0 ec 07 00 - dc ff ff 00 f3 99 83 7c
0..............|
0000000000ffff70 58 24 80 7c 00 00 00 00 - 88 ff ff 00 51 24 80 7c
X$.|........Q$.|
0000000000ffff80 60 ea 00 00 00 00 00 00 - b4 ff ff 00 1d e3 4f 77
`.............Ow
0000000000ffff90 60 ea 00 00 18 4f df 00 - dc e3 4f 77 00 00 00 00
`....O....Ow....
0000000000ffffa0 00 00 00 00 18 4f df 00 - 00 00 4e 77 44 e4 4f 77
......O....NwD.Ow
0000000000ffffb0 00 00 00 00 ec ff ff 00 - 0b b5 80 7c 18 4f df 00
............|.O..
0000000000ffffc0 00 00 00 00 00 00 00 00 - 18 4f df 00 00 e0 fa 7f
..........O......
0000000000ffffd0 00 46 bc 81 c0 ff ff 00 - 78 f0 9e 81 ff ff ff ff
..F......x.......
0000000000ffffe0 f3 99 83 7c 18 b5 80 7c - 00 00 00 00 00 00 00 00
....|...|........
0000000000fffff0 00 00 00 00 29 e4 4f 77 - 18 4f df 00 00 00 00 00
.....).Ow.O......
0000000001000000 4d 5a 90 00 03 00 00 00 - 04 00 00 00 ff ff 00 00
MZ..............
0000000001000010 b8 00 00 00 00 00 00 00 - 40 00 00 00 00 00 00 00
.........@.......
0000000001000020 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
.................
0000000001000030 00 00 00 00 00 00 00 00 - 00 00 00 00 f0 00 00 00
.................
0000000001000040 0e 1f ba 0e 00 b4 09 cd - 21 b8 01 4c cd 21 54 68
.........!..L.!Th
0000000001000050 69 73 20 70 72 6f 67 72 - 61 6d 20 63 61 6e 6e 6f is
program canno
### End Log ###
.
- Prev by Date: Re: MSCONFIG
- Next by Date: Re: missing microsoft work and excel
- Previous by thread: wav sound
- Next by thread: Re: missing microsoft work and excel
- Index(es):
Relevant Pages
|