| Richard 2005-05-23, 1:23 pm |
| I received a Dr. Watson error that I need help with. Any ideas that could
help me debug this issue, is greatly appreciated.
Microsoft (R) Windows 2000 (TM) Version 5.00 DrWtsn32
Copyright (C) 1985-1999 Microsoft Corp. All rights reserved.
Application exception occurred:
App: (pid=3084)
When: 01/22/2005 @ 13:17:03.364
Exception number: c0000005 (access violation)
*----> System Information <----*
Computer Name: AHICNT01
User Name: Mradmin3
Number of Processors: 2
Processor Type: x86 Family 6 Model 8 Stepping 1
Windows 2000 Version: 5.0
Current Build: 2195
Service Pack: 4
Current Type: Multiprocessor Free
Registered Organization: American Hallmark
Registered Owner: AHICNT01
*----> Task List <----*
0 Idle.exe
8 System.exe
276 smss.exe
300 csrss.exe
324 WINLOGON.exe
352 services.exe
364 LSASS.exe
460 termsrv.exe
564 svchost.exe
612 svchost.exe
660 SPOOLSV.exe
704 msdtc.exe
860 cisvc.exe
876 defwatch.exe
980 sqlservr.exe
992 rtvscan.exe
1020 regsvc.exe
1032 mstask.exe
1124 winmgmt.exe
1140 svchost.exe
1152 beremote.exe
1260 dfssvc.exe
1284 mssearch.exe
1992 svchost.exe
996 dllhost.exe
3068 explorer.exe
2444 vptray.exe
2724 sqlmangr.exe
2740 sqlagent.exe
3640 csrss.exe
2656 WINLOGON.exe
2404 rdpclip.exe
3364 explorer.exe
3848 sqlmangr.exe
896 inetinfo.exe
2984 dllhost.exe
1952 mdm.exe
3788 cidaemon.exe
3208 dllhost.exe
1776 dllhost.exe
3564 dllhost.exe
2880 dllhost.exe
2508 dllhost.exe
1712 dllhost.exe
3456 dllhost.exe
864 dllhost.exe
3084 cwblmsrv.exe
3928 drwtsn32.exe
0 _Total.exe
(00400000 - 0040B000)
(77F80000 - 77FFD000)
(671A0000 - 671BC000)
(67670000 - 67678000)
(673A0000 - 673CA000)
(77E10000 - 77E75000)
(7C570000 - 7C623000)
(77F40000 - 77F7B000)
(78000000 - 78045000)
(780A0000 - 780B2000)
(674A0000 - 674A9000)
(67610000 - 67628000)
(719B0000 - 719B8000)
(7C2D0000 - 7C332000)
(77D30000 - 77DA1000)
(67600000 - 67606000)
(668D0000 - 668E2000)
(676D0000 - 676DB000)
(675B0000 - 675F1000)
(676B0000 - 676BD000)
(67480000 - 67486000)
(674E0000 - 674E9000)
(67490000 - 67496000)
(67170000 - 67177000)
(674B0000 - 674C8000)
(676C0000 - 676C6000)
(71710000 - 71794000)
(75050000 - 75058000)
(75030000 - 75044000)
(75020000 - 75028000)
(63670000 - 63674000)
(782C0000 - 782CC000)
(77980000 - 779A4000)
(77340000 - 77353000)
(77520000 - 77525000)
(77320000 - 77337000)
(75150000 - 7515F000)
(75170000 - 751BF000)
(7C340000 - 7C34F000)
(77BF0000 - 77C01000)
(77950000 - 7797A000)
(751C0000 - 751C6000)
(77A50000 - 77B3F000)
(779B0000 - 77A4B000)
(773B0000 - 773DF000)
(77380000 - 773A3000)
(77830000 - 7783E000)
(77880000 - 7790E000)
(7C0F0000 - 7C151000)
(774E0000 - 77513000)
(774C0000 - 774D1000)
(77530000 - 77552000)
(63180000 - 631E9000)
(77360000 - 77379000)
(777E0000 - 777E8000)
State Dump for Thread Id 0x8dc
eax=00518b10 ebx=00000000 ecx=00517730 edx=00000001 esi=0012fcd4 edi=00000000
eip=00401dc0 esp=0012fca4 ebp=7800831c iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000202
function: <nosymbols>
00401da9 8b03 mov eax,[ebx]
ds:00000000=????????
00401dab 5f pop edi
00401dac 5b pop ebx
00401dad c20400 ret 0x4
00401db0 8b8918010000 mov ecx,[ecx+0x118]
ds:00517848=00000000
00401db6 53 push ebx
00401db7 8b01 mov eax,[ecx]
ds:00517730=00517730
00401db9 3bc1 cmp eax,ecx
00401dbb 7410 jz 0040a8cd
00401dbd 8b5008 mov edx,[eax+0x8]
ds:00d329f6=????????
FAULT ->00401dc0 8a5a1c mov bl,[edx+0x1c]
ds:00819ee7=??
00401dc3 84db test bl,bl
00401dc5 750a jnz 0040a8d1
00401dc7 8b00 mov eax,[eax]
ds:00518b10=00518bb8
00401dc9 3bc1 cmp eax,ecx
00401dcb 75f0 jnz 004051bd
00401dcd 33c0 xor eax,eax
00401dcf 5b pop ebx
00401dd0 c3 ret
00401dd1 8b4808 mov ecx,[eax+0x8]
ds:00d329f6=????????
00401dd4 5b pop ebx
00401dd5 c6411c00 mov byte ptr [ecx+0x1c],0x0
ds:00d31616=??
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
7800831C FF33016A FF9001E8 59F08BFF 7459F685 8CE85646 !<nosymbols>
7C6A5756 00000000 00000000 00000000 00000000 00000000 <nosymbols>
*----> Raw Stack Dump <----*
0012fca4 00 00 00 00 48 1e 40 00 - 52 06 02 04 a0 8b 51 00 ....H.@.R.....Q.
0012fcb4 d4 fc 12 00 ca 49 40 00 - 04 00 00 00 af 3c 13 00 .....I@......<..
0012fcc4 c0 ff 12 00 00 00 00 00 - 00 00 00 00 52 06 02 04 ............R...
0012fcd4 50 03 eb 03 63 77 62 6c - 6d 5f 70 69 70 65 00 ff P...cwblm_pipe..
0012fce4 24 fd 12 00 00 00 65 00 - 09 00 00 00 00 57 65 00 $.....e......We.
0012fcf4 38 57 65 00 3c 01 00 00 - 08 73 13 00 01 76 13 00 8We.<....s...v..
0012fd04 00 00 00 00 8c fc 12 00 - b0 ff 12 00 b0 ff 12 00 ................
0012fd14 55 1f f8 77 28 25 f8 77 - ff ff ff ff 48 fd 12 00 U..w(%.w....H...
0012fd24 29 12 03 75 00 00 65 00 - 00 00 00 00 18 57 65 00 )..u..e......We.
0012fd34 b6 25 03 75 18 57 65 00 - 90 fd 12 00 90 1e 65 00 .%.u.We.......e.
0012fd44 d8 55 65 00 68 fd 12 00 - d6 28 03 75 18 57 65 00 .Ue.h....(.u.We.
0012fd54 00 00 00 00 ff 00 00 00 - 98 aa 40 00 d8 fd 12 00 ..........@.....
0012fd64 18 57 65 00 dc fe 12 00 - 0a 31 03 75 d4 fe 12 00 .We......1.u....
0012fd74 3c 01 00 00 00 00 00 00 - 20 14 04 75 d8 fe 12 00 <....... ..u....
0012fd84 04 00 00 00 10 90 40 00 - 00 00 00 00 3c 00 00 00 ......@.....<...
0012fd94 cc fd 12 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0012fda4 0c 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0012fdb4 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0012fdc4 00 00 00 00 d8 fd 12 00 - 61 68 69 63 6e 74 30 31 ........ahicnt01
0012fdd4 00 55 65 00 6c 01 00 00 - b8 88 00 00 00 00 00 00 .Ue.l...........
State Dump for Thread Id 0xb7c
eax=778321fe ebx=00000003 ecx=0012f124 edx=00000000 esi=77f82873 edi=00000003
eip=77f8287e esp=00befd24 ebp=00befd70 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000246
function: NtWaitForMultipleObj
ects
77f82873 b8e9000000 mov eax,0xe9
77f82878 8d542404 lea edx,[esp+0x4]
ss:01409c0b=????????
77f8287c cd2e int 2e
77f8287e c21400 ret 0x14
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
00BEFD70 7C59A0C2 00BEFD48 00000001 00000000 00000000
ntdll!NtWaitForMulti
pleObjects
00BEFFB4 7C57B388 00000004 000B000A 7C325107 0014C5B8
kernel32!WaitForMult
ipleObjects
00BEFFEC 00000000 778321FE 0014C5B8 00000000 000000C8 kernel32!lstrcmpiW
*----> Raw Stack Dump <----*
00befd24 af a1 59 7c 03 00 00 00 - 48 fd be 00 01 00 00 00 ..Y|....H.......
00befd34 00 00 00 00 00 00 00 00 - 00 00 00 00 b8 c5 14 00 ................
00befd44 01 00 00 00 e8 00 00 00 - ec 00 00 00 00 01 00 00 ................
00befd54 00 00 00 00 74 7f 05 89 - fc da d5 00 fc da d5 bb ....t...........
00befd64 45 94 4d 80 33 94 4d 80 - 40 00 00 00 b4 ff be 00 E.M.3.M.@.......
00befd74 c2 a0 59 7c 48 fd be 00 - 01 00 00 00 00 00 00 00 ..Y|H...........
00befd84 00 00 00 00 00 00 00 00 - b2 22 83 77 03 00 00 00 .........".w....
00befd94 b0 fe be 00 00 00 00 00 - ff ff ff ff b8 c5 14 00 ................
00befda4 07 51 32 7c 0a 00 0b 00 - 98 00 00 00 f8 00 00 00 .Q2|............
00befdb4 98 00 00 00 00 00 00 00 - 00 00 00 00 38 00 00 00 ............8...
00befdc4 23 00 00 00 23 00 00 00 - 0a 00 0b 00 07 51 32 7c #...#........Q2|
00befdd4 b8 c5 14 00 ff ff ff ff - 24 f1 12 00 fe 21 83 77 ........$....!.w
00befde4 f8 eb fd 7f 00 b7 57 7c - 1b 00 00 00 00 02 00 00 ......W|........
00befdf4 fc ff be 00 23 00 00 00 - 48 34 06 89 50 dc d5 bb ....#...H4..P...
00befe04 f8 10 00 e1 00 00 00 00 - 00 00 00 00 54 db d5 bb ............T...
00befe14 f8 25 45 80 01 00 00 00 - 40 7f 05 89 00 00 00 00 .%E.....@.......
00befe24 10 00 f8 00 8a 76 4f 87 - 7c 00 f8 00 9a 76 4f 87 .....vO.|....vO.
00befe34 50 db d5 bb f8 10 00 e1 - 48 34 06 89 10 11 00 e1 P.......H4......
00befe44 00 00 00 00 01 00 00 00 - 1f 00 00 00 30 d0 05 89 ............0...
00befe54 30 d0 05 89 00 00 00 00 - 01 00 00 00 b0 db d5 bb 0...............
State Dump for Thread Id 0x8c4
eax=004757e0 ebx=00000002 ecx=00000000 edx=00000000 esi=77f82873 edi=00000002
eip=77f8287e esp=00cffe74 ebp=00cffec0 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000246
function: NtWaitForMultipleObj
ects
77f82873 b8e9000000 mov eax,0xe9
77f82878 8d542404 lea edx,[esp+0x4]
ss:01519d5b=????????
77f8287c cd2e int 2e
77f8287e c21400 ret 0x14
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
00CFFEC0 77E119E6 00CFFE98 00000001 00000000 00000000
ntdll!NtWaitForMulti
pleObjects
00CFFF1C 77E11ACE 00CFFEE8 0012FE94 FFFFFFFF 000000FF
user32!MsgWaitForMul
tipleObjectsEx
00CFFF38 004044BA 00000001 0012FE94 00000000 FFFFFFFF
user32!MsgWaitForMul
tipleObjects
77E11AB1 104539C0 50C0950F FF1875FF 75FF1475 0875FF0C !<nosymbols>
33EC8B55 00000000 00000000 00000000 00000000 00000000 <nosymbols>
State Dump for Thread Id 0x89c
eax=00000350 ebx=00dfff38 ecx=003b0650 edx=00000000 esi=77f82865 edi=00000094
eip=77f82870 esp=00dfff1c ebp=00dfff40 iopl=0 nv up ei ng nz ac pe cy
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000293
function: NtWaitForSingleObjec
t
77f82865 b8ea000000 mov eax,0xea
77f8286a 8d542404 lea edx,[esp+0x4]
ss:01619e03=????????
77f8286e cd2e int 2e
77f82870 c20c00 ret 0xc
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
00DFFF40 7C57B3DB 00000094 00075FC2 00000000 00405B57
ntdll!NtWaitForSingl
eObject
0040AA84 00000098 000003EA 0012FDF8 0012FCD4 63696861
kernel32!WaitForSing
leObject
State Dump for Thread Id 0xe74
eax=00470650 ebx=7c579723 ecx=002f27c0 edx=00000000 esi=00efff64 edi=77e15f6c
eip=77e11555 esp=00efff14 ebp=00efff34 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000246
function: ScrollDC
77e11533 8d542404 lea edx,[esp+0x4]
ss:01719dfb=????????
77e11537 cd2e int 2e
77e11539 c21c00 ret 0x1c
77e1153c b838110000 mov eax,0x1138
77e11541 8d542404 lea edx,[esp+0x4]
ss:01719dfb=????????
77e11545 cd2e int 2e
77e11547 c20400 ret 0x4
77e1154a b89a110000 mov eax,0x119a
77e1154f 8d542404 lea edx,[esp+0x4]
ss:01719dfb=????????
77e11553 cd2e int 2e
77e11555 c21000 ret 0x10
77e11558 6a01 push 0x1
77e1155a 58 pop eax
77e1155b c20800 ret 0x8
77e1155e b839110000 mov eax,0x1139
77e11563 8d542404 lea edx,[esp+0x4]
ss:01719dfb=????????
77e11567 cd2e int 2e
77e11569 c20800 ret 0x8
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
00EFFF34 00401CAF 00EFFF64 03EB0350 00000000 00000000 user32!ScrollDC
77E15F5E DBE80824 C2FFFFBF 8B550004 144D8BEC 8B10558B !<nosymbols>
74FF016A 00000000 00000000 00000000 00000000 00000000 <nosymbols>
Application exception occurred:
App: (pid=2448)
When: 05/22/2005 @ 00:31:35.567
Exception number: c0000005 (access violation)
*----> System Information <----*
Computer Name: AHICNT01
User Name: Mradmin3
Number of Processors: 2
Processor Type: x86 Family 6 Model 8 Stepping 1
Windows 2000 Version: 5.0
Current Build: 2195
Service Pack: 4
Current Type: Multiprocessor Free
Registered Organization: American Hallmark
Registered Owner: AHICNT01
*----> Task List <----*
0 Idle.exe
8 System.exe
272 smss.exe
300 csrss.exe
296 WINLOGON.exe
352 services.exe
364 LSASS.exe
480 termsrv.exe
600 svchost.exe
628 SPOOLSV.exe
672 msdtc.exe
820 cisvc.exe
836 DefWatch.exe
856 svchost.exe
876 pds.exe
976 regsvc.exe
988 mstask.exe
1044 Rtvscan.exe
1076 winmgmt.exe
1132 dfssvc.exe
1168 mssearch.exe
1972 svchost.exe
2380 dllhost.exe
2156 cidaemon.exe
2528 cidaemon.exe
1104 beremote.exe
4068 explorer.exe
3328 VPTray.exe
2740 sqlmangr.exe
1932 sqlservr.exe
2736 sqlagent.exe
3412 taskmgr.exe
4256 csrss.exe
2232 WINLOGON.exe
3964 rdpclip.exe
3920 explorer.exe
2868 sqlmangr.exe
2732 cidaemon.exe
3988 cidaemon.exe
2780 cidaemon.exe
2428 cidaemon.exe
2852 inetinfo.exe
2448 dtsrun.exe
2604 dllhost.exe
4084 mdm.exe
2284 dllhost.exe
2432 dllhost.exe
3364 drwtsn32.exe
0 _Total.exe
(00400000 - 00409000)
(77F80000 - 77FFD000)
(7C570000 - 7C623000)
(78000000 - 78045000)
(77A50000 - 77B3F000)
(77D30000 - 77DA1000)
(7C2D0000 - 7C332000)
(77F40000 - 77F7B000)
(77E10000 - 77E75000)
(779B0000 - 77A4B000)
(41320000 - 41326000)
(42490000 - 42496000)
(775A0000 - 77630000)
(41450000 - 41555000)
(41100000 - 4110C000)
(76B30000 - 76B6E000)
(63180000 - 631E9000)
(71710000 - 71794000)
(782F0000 - 78535000)
(412F0000 - 412F6000)
(769A0000 - 769A7000)
(77800000 - 7781E000)
(76620000 - 76630000)
(77820000 - 77827000)
(759B0000 - 759B6000)
(1EC00000 - 1EC25000)
(7CA00000 - 7CA23000)
(7C0F0000 - 7C151000)
(7C740000 - 7C7C7000)
(77430000 - 77440000)
(75370000 - 753EB000)
(1F670000 - 1F693000)
(00B80000 - 00B95000)
(75170000 - 751BF000)
(7C340000 - 7C34F000)
(77BF0000 - 77C01000)
(77980000 - 779A4000)
(75050000 - 75058000)
(75030000 - 75044000)
(75020000 - 75028000)
(77950000 - 7797A000)
(751C0000 - 751C6000)
(75150000 - 7515F000)
(1F890000 - 1F8FC000)
(1F900000 - 1F911000)
(74CB0000 - 74CC2000)
(75500000 - 75504000)
(00E70000 - 00E91000)
(77340000 - 77353000)
(77520000 - 77525000)
(77320000 - 77337000)
(773B0000 - 773DF000)
(77380000 - 773A3000)
(77830000 - 7783E000)
(77880000 - 7790E000)
(774E0000 - 77513000)
(774C0000 - 774D1000)
(77530000 - 77552000)
(77360000 - 77379000)
(74FD0000 - 74FEE000)
(75010000 - 75017000)
(413D0000 - 4141B000)
(424B0000 - 424BF000)
(782C0000 - 782CC000)
(777E0000 - 777E8000)
(777F0000 - 777F5000)
(1F6B0000 - 1F6FA000)
(1F7A0000 - 1F7D6000)
(1F840000 - 1F857000)
(1F700000 - 1F704000)
(78740000 - 788AF000)
(6DE80000 - 6DEE4000)
(6DF80000 - 6E037000)
(6A7A0000 - 6A7B0000)
(73930000 - 73940000)
(689D0000 - 689DD000)
(66600000 - 6666A000)
(671A0000 - 671BC000)
(67670000 - 67678000)
(673A0000 - 673CA000)
(780A0000 - 780B2000)
(674A0000 - 674A9000)
(67610000 - 67628000)
(719B0000 - 719B8000)
(67600000 - 67606000)
(668D0000 - 668E2000)
(676D0000 - 676DB000)
(675B0000 - 675F1000)
(676B0000 - 676BD000)
(67480000 - 67486000)
(674E0000 - 674E9000)
(67490000 - 67496000)
(67170000 - 67177000)
(674B0000 - 674C8000)
(676C0000 - 676C6000)
(676A0000 - 676A7000)
(67060000 - 6708E000)
(67310000 - 6733F000)
(67190000 - 6719B000)
(673D0000 - 673E1000)
(67680000 - 67687000)
(67050000 - 6705E000)
(6C370000 - 6C46B000)
(780C0000 - 78121000)
(63670000 - 63674000)
(63460000 - 6346E000)
(1F7F0000 - 1F80A000)
(63740000 - 63745000)
State Dump for Thread Id 0xd88
eax=00922b50 ebx=7ffdf000 ecx=00922b50 edx=00000000 esi=00000000 edi=00000000
eip=41504ccc esp=0012fce0 ebp=0012fcf4 iopl=0 nv up ei ng nz ac po cy
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000297
function: <nosymbols>
41504cb1 8b4d08 mov ecx,[ebp+0x8]
ss:00949bda=0001ffff
41504cb4 83c108 add ecx,0x8
41504cb7 e86429ffff call 414f7620
41504cbc 8945fc mov [ebp+0xfc],eax
ss:00949bda=0001ffff
41504cbf 8b45fc mov eax,[ebp+0xfc]
ss:00949bda=0001ffff
41504cc2 8b08 mov ecx,[eax]
ds:00922b50=00000000
41504cc4 8b55fc mov edx,[ebp+0xfc]
ss:00949bda=0001ffff
41504cc7 8b02 mov eax,[edx]
ds:00000000=????????
41504cc9 8b10 mov edx,[eax]
ds:00922b50=00000000
41504ccb 51 push ecx
FAULT ->41504ccc ff5208 call dword ptr [edx+0x8]
ds:00819ee6=????????
41504ccf 8b45f0 mov eax,[ebp+0xf0]
ss:00949bda=0001ffff
41504cd2 50 push eax
41504cd3 8b4d08 mov ecx,[ebp+0x8]
ss:00949bda=0001ffff
41504cd6 83c108 add ecx,0x8
41504cd9 e8520a0000 call 41505730
41504cde 8b4d08 mov ecx,[ebp+0x8]
ss:00949bda=0001ffff
41504ce1 8b11 mov edx,[ecx]
ds:00922b50=00000000
41504ce3 8b4508 mov eax,[ebp+0x8]
ss:00949bda=0001ffff
41504ce6 50 push eax
41504ce7 ff5208 call dword ptr [edx+0x8]
ds:00819ee6=????????
41504cea 33c0 xor eax,eax
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0012FCF4 41479942 013F1040 00000001 013F1040 00B71EB8 !<nosymbols>
0012FD0C 41479A50 41453259 00B71EB8 00000000 0012FF64 !<nosymbols>
0012FD2C 414799CF 00B71EB8 0012FD54 41453875 00000001 !<nosymbols>
0012FD38 41453875 00000001 00000000 00B71EB8 00B71EB8 !<nosymbols>
0012FD54 414532D1 00000000 00000000 0012FD7C 41453404 !<nosymbols>
0012FD64 41453404 00B71EB8 00B71EB8 00000002 0012FDF8 !<nosymbols>
0012FD7C 414793CE 0012FF70 00401CAA 00B71ECC 00000000 !<nosymbols>
0012FD84 00401CAA 00B71ECC 00000000 00000000 7FFDF000 !<nosymbols>
0012FF70 0040285F 00000002 002F3920 002F29E8 00000000 !<nosymbols>
0012FFC0 7C59893D 00000000 00000000 7FFDF000 C0000005 !<nosymbols>
0012FFF0 00000000 00402760 00000000 000000C8 00000100
kernel32!ProcessIdTo
SessionId
*----> Raw Stack Dump <----*
0012fce0 50 2b 92 00 00 00 00 00 - 00 00 00 00 01 00 00 00 P+..............
0012fcf0 70 10 3f 01 0c fd 12 00 - 42 99 47 41 40 10 3f 01 p.?.....B.GA@.?.
0012fd00 01 00 00 00 40 10 3f 01 - b8 1e b7 00 2c fd 12 00 ....@.?.....,...
0012fd10 50 9a 47 41 59 32 45 41 - b8 1e b7 00 00 00 00 00 P.GAY2EA........
0012fd20 64 ff 12 00 1d c2 50 41 - 0d 00 00 00 38 fd 12 00 d.....PA....8...
0012fd30 cf 99 47 41 b8 1e b7 00 - 54 fd 12 00 75 38 45 41 ..GA....T...u8EA
0012fd40 01 00 00 00 00 00 00 00 - b8 1e b7 00 b8 1e b7 00 ................
0012fd50 b8 1e b7 00 64 fd 12 00 - d1 32 45 41 00 00 00 00 ....d....2EA....
0012fd60 00 00 00 00 7c fd 12 00 - 04 34 45 41 b8 1e b7 00 ....|....4EA....
0012fd70 b8 1e b7 00 02 00 00 00 - f8 fd 12 00 84 fd 12 00 ................
0012fd80 ce 93 47 41 70 ff 12 00 - aa 1c 40 00 cc 1e b7 00 ..GAp.....@.....
0012fd90 00 00 00 00 00 00 00 00 - 00 f0 fd 7f 80 7f b7 00 ................
0012fda0 80 7f b7 00 70 01 3d 01 - 70 01 3d 01 f0 2b b7 00 ....p.=.p.=..+..
0012fdb0 54 80 3d 01 f0 2b b7 00 - 50 2b 92 00 03 00 00 00 T.=..+..P+......
0012fdc0 fc fe 12 00 50 00 00 00 - fc fe 12 00 50 2b 92 00 ....P.......P+..
0012fdd0 50 2b 92 00 00 00 00 00 - 00 00 00 00 04 00 00 00 P+..............
0012fde0 00 00 00 00 fc fe 12 00 - 00 00 00 00 fc fe 12 00 ................
0012fdf0 50 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 P...............
0012fe00 00 00 00 00 00 00 00 00 - d4 58 40 00 d8 58 40 00 .........X@..X@.
0012fe10 00 00 00 00 00 00 00 00 - 00 00 00 00 d8 58 40 00 .............X@.
State Dump for Thread Id 0xda8
eax=00000014 ebx=80020000 ecx=00000001 edx=00000000 esi=0013f080 edi=0013f0c0
eip=77f83310 esp=00a6fe28 ebp=00a6ff74 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000202
function: ZwReplyWaitReceivePo
rtEx
77f83305 b8ac000000 mov eax,0xac
77f8330a 8d542404 lea edx,[esp+0x4]
ss:01289d0f=????????
77f8330e cd2e int 2e
77f83310 c21400 ret 0x14
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
00A6FF74 77D37B4C 77D35924 0013F080 77D33E01 00130000
ntdll!ZwReplyWaitRec
eivePortEx
00A6FFA8 77D358D6 0013E980 00A6FFEC 7C57B388 0013F168
rpcrt4!NdrCorrelatio
nInitialize
00A6FFB4 7C57B388 0013F168 77D33E01 00130000 0013F168 rpcrt4!RpcBindingFre
e
00A6FFEC 00000000 00000000 00000000 00000000 00000000 kernel32!lstrcmpiW
State Dump for Thread Id 0xa1c
eax=778321fe ebx=00000004 ecx=0012b780 edx=00000000 esi=77f82873 edi=00000004
eip=77f8287e esp=00f9fd24 ebp=00f9fd70 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000246
function: NtWaitForMultipleObj
ects
77f82873 b8e9000000 mov eax,0xe9
77f82878 8d542404 lea edx,[esp+0x4]
ss:017b9c0b=????????
77f8287c cd2e int 2e
77f8287e c21400 ret 0x14
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
00F9FD70 7C59A0C2 00F9FD48 00000001 00000000 00000000
ntdll!NtWaitForMulti
pleObjects
00F9FFB4 7C57B388 00000005 000B000A 7C325107 00153C30
kernel32!WaitForMult
ipleObjects
00F9FFEC 00000000 778321FE 00153C30 00000000 000000C8 kernel32!lstrcmpiW
*----> Raw Stack Dump <----*
00f9fd24 af a1 59 7c 04 00 00 00 - 48 fd f9 00 01 00 00 00 ..Y|....H.......
00f9fd34 00 00 00 00 00 00 00 00 - 01 00 00 00 30 3c 15 00 ............0<..
00f9fd44 01 00 00 00 4c 02 00 00 - 48 02 00 00 30 02 00 00 ....L...H...0...
00f9fd54 3c 01 00 00 fd 00 43 80 - c8 35 e4 88 48 92 8f 88 <.....C..5..H...
00f9fd64 40 01 00 00 11 00 00 00 - 02 00 00 00 b4 ff f9 00 @...............
00f9fd74 c2 a0 59 7c 48 fd f9 00 - 01 00 00 00 00 00 00 00 ..Y|H...........
00f9fd84 00 00 00 00 00 00 00 00 - b2 22 83 77 04 00 00 00 .........".w....
00f9fd94 b0 fe f9 00 00 00 00 00 - ff ff ff ff 30 3c 15 00 ............0<..
00f9fda4 07 51 32 7c 0a 00 0b 00 - c8 0f 37 e2 78 00 8a 87 .Q2|......7.x...
00f9fdb4 00 00 00 00 00 00 00 00 - 01 00 00 00 38 00 00 00 ............8...
00f9fdc4 23 00 00 00 23 00 00 00 - 0a 00 0b 00 07 51 32 7c #...#........Q2|
00f9fdd4 30 3c 15 00 ff ff ff ff - 80 b7 12 00 fe 21 83 77 0<...........!.w
00f9fde4 f8 eb fd 7f 00 b7 57 7c - 1b 00 00 00 00 02 00 00 ......W|........
00f9fdf4 fc ff f9 00 23 00 00 00 - 78 00 8a 87 d4 6a 83 aa ....#...x....j..
00f9fe04 98 6b 83 aa 98 6b 83 aa - 06 1c 52 f6 6f 53 41 80 .k...k....R.oSA.
00f9fe14 00 00 00 00 00 00 00 00 - 08 00 8a 87 c8 0f 37 e2 ..............7.
00f9fe24 10 a5 a9 88 00 00 00 00 - a8 6b 83 aa ed 4c 52 f6 .........k...LR.
00f9fe34 b5 4c 52 f6 f0 8b f4 88 - 08 00 8a 87 e0 4b 06 80 .LR..........K..
00f9fe44 e0 ae 05 89 c0 2e 19 86 - a8 2e 19 86 a8 0f 37 e2 ..............7.
00f9fe54 01 00 00 00 48 00 00 00 - 02 00 00 00 00 00 00 00 ....H...........
State Dump for Thread Id 0xe28
eax=00000000 ebx=02f5fd74 ecx=00989680 edx=00000000 esi=77f82865 edi=000000ec
eip=77f82870 esp=02f5fd58 ebp=02f5fd7c iopl=0 nv up ei ng nz ac po cy
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000297
function: NtWaitForSingleObjec
t
77f82865 b8ea000000 mov eax,0xea
77f8286a 8d542404 lea edx,[esp+0x4]
ss:03779c3f=????????
77f8286e cd2e int 2e
77f82870 c20c00 ret 0xc
*----> Stack Back Trace <----*
FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
02F5FD7C 7C57B3DB 000000EC 00002710 00000000 7878DB85
ntdll!NtWaitForSingl
eObject
00000000 00000000 00000000 00000000 00000000 00000000
kernel32!WaitForSing
leObject
*----> Raw Stack Dump <----*
02f5fd58 e4 9f 59 7c ec 00 00 00 - 00 00 00 00 74 fd f5 02 ..Y|........t...
02f5fd68 9c ff 16 00 00 00 00 00 - b4 ff 16 00 00 1f 0a fa ................
02f5fd78 ff ff ff ff 00 00 00 00 - db b3 57 7c ec 00 00 00 ..........W|....
02f5fd88 10 27 00 00 00 00 00 00 - 85 db 78 78 ec 00 00 00 .'........xx....
02f5fd98 10 27 00 00 00 00 00 00 - 24 f4 a1 02 ec ff f5 02 .'......$.......
02f5fda8 9c ff 16 00 00 00 74 78 - 43 00 3a 00 5c 00 57 00 ......txC.:.\.W.
02f5fdb8 49 00 4e 00 4e 00 54 00 - 5c 00 73 00 79 00 73 00 I.N.N.T.\.s.y.s.
02f5fdc8 74 00 65 00 6d 00 33 00 - 32 00 5c 00 63 00 6f 00 t.e.m.3.2.\.c.o.
02f5fdd8 6d 00 73 00 76 00 63 00 - 73 00 2e 00 64 00 6c 00 m.s.v.c.s...d.l.
02f5fde8 6c 00 00 00 1b 00 00 00 - 00 02 00 00 fc ff f5 02 l...............
02f5fdf8 23 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 #...............
02f5fe08 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
02f5fe18 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
02f5fe28 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
02f5fe38 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
02f5fe48 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
02f5fe58 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
02f5fe68 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
02f5fe78 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
02f5fe88 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
|