Ticket #3727: drwtsn32.log

File drwtsn32.log, 76.2 KB (added by Brandon Aiken, 13 years ago)

da_chicken's Dr. Watson log

Line 
1
2Microsoft (R) DrWtsn32
3Copyright (C) 1985-2001 Microsoft Corp. All rights reserved.
4
5
6
7Application exception occurred:
8 App: C:\Program Files\FileZilla Client\filezilla.exe (pid=4280)
9 When: 9/29/2008 @ 17:59:43.990
10 Exception number: 80000003 (hardcoded breakpoint)
11
12*----> System Information <----*
13 Computer Name: SIBER
14 User Name: b
15 Terminal Session Id: 0
16 Number of Processors: 1
17 Processor Type: x86 Family 15 Model 39 Stepping 1
18 Windows Version: 5.1
19 Current Build: 2600
20 Service Pack: 3
21 Current Type: Uniprocessor Free
22 Registered Organization:
23 Registered Owner: B
24
25*----> Task List <----*
26 0 System Process
27 4 System
28 936 smss.exe
29 996 csrss.exe
301020 winlogon.exe
311068 services.exe
321080 lsass.exe
331240 svchost.exe
341340 svchost.exe
351460 svchost.exe
361504 svchost.exe
371560 svchost.exe
381912 spoolsv.exe
39 300 TSVNCache.exe
40 492 NVMixerTray.exe
41 508 LCDMon.exe
42 592 LGDCore.exe
43 652 ClamTray.exe
44 660 ctfmon.exe
45 688 LCDMedia.exe
46 704 LCDClock.exe
47 740 TeaTimer.exe
48 776 GoogleUpdate.exe
49 808 SUMo.exe
501152 Desktops.exe
512040 cvpnd.exe
52 260 FileZilla Server.exe
531608 FolderSizeSvc.exe
54 872 MDM.EXE
552064 ntpd.exe
562096 nvsvc32.exe
572212 svchost.exe
582416 cmd.exe
592444 VisualSVNServer.exe
602508 VisualSVNServer.exe
613656 alg.exe
62 820 svchost.exe
632196 Steam.exe
642276 mDNSResponder.exe
654148 pidgin.exe
663200 fdm.exe
674236 AppleMobileDeviceService.exe
684956 iPodService.exe
694156 iTunesHelper.exe
703860 utorrent.exe
715640 firefox.exe
725792 notepad++.exe
733040 explorer.exe
744280 filezilla.exe
754208 cmd.exe
763816 procexp.exe
774736 drwtsn32.exe
78
79*----> Module List <----*
80(0000000000400000 - 0000000000ae2000: C:\Program Files\FileZilla Client\filezilla.exe
81(0000000001530000 - 00000000017f5000: C:\WINDOWS\system32\xpsp2res.dll
82(0000000001d20000 - 0000000001dda000: C:\Program Files\TortoiseSVN\bin\TortoiseSVN.dll
83(0000000001df0000 - 0000000001df9000: C:\WINDOWS\system32\Normaliz.dll
84(0000000005940000 - 000000000594e000: C:\Program Files\TortoiseSVN\bin\TortoiseStub.dll
85(0000000005960000 - 0000000005977000: C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
86(0000000010000000 - 0000000010012000: C:\Program Files\TortoiseSVN\bin\intl3_tsvn.dll
87(0000000016080000 - 00000000160a5000: C:\Program Files\Bonjour\mdnsNSP.dll
88(000000004b400000 - 000000004b486000: C:\WINDOWS\system32\msftedit.dll
89(000000005ad70000 - 000000005ada8000: C:\WINDOWS\system32\uxtheme.dll
90(000000005b860000 - 000000005b8b5000: C:\WINDOWS\system32\NETAPI32.DLL
91(00000000605d0000 - 00000000605d9000: C:\WINDOWS\system32\mslbui.dll
92(00000000662b0000 - 0000000066308000: C:\WINDOWS\system32\hnetcfg.dll
93(000000006ee60000 - 000000006ee89000: C:\Program Files\TortoiseSVN\bin\libaprutil_tsvn.dll
94(000000006eec0000 - 000000006eee0000: C:\Program Files\TortoiseSVN\bin\libapr_tsvn.dll
95(000000006fbc0000 - 000000006fbc8000: C:\Program Files\FileZilla Client\mingwm10.dll
96(0000000071a50000 - 0000000071a8f000: C:\WINDOWS\system32\MSWSOCK.dll
97(0000000071a90000 - 0000000071a98000: C:\WINDOWS\System32\wshtcpip.dll
98(0000000071aa0000 - 0000000071aa8000: C:\WINDOWS\system32\WS2HELP.dll
99(0000000071ab0000 - 0000000071ac7000: C:\WINDOWS\system32\WS2_32.DLL
100(0000000071ad0000 - 0000000071ad9000: C:\WINDOWS\system32\WSOCK32.DLL
101(0000000074720000 - 000000007476c000: C:\WINDOWS\system32\MSCTF.dll
102(00000000754d0000 - 0000000075550000: C:\WINDOWS\system32\CRYPTUI.dll
103(00000000755c0000 - 00000000755ee000: C:\WINDOWS\system32\msctfime.ime
104(0000000075f80000 - 000000007607d000: C:\WINDOWS\system32\browseui.dll
105(0000000076380000 - 0000000076385000: C:\WINDOWS\system32\msimg32.dll
106(0000000076390000 - 00000000763ad000: C:\WINDOWS\system32\IMM32.DLL
107(00000000763b0000 - 00000000763f9000: C:\WINDOWS\system32\COMDLG32.DLL
108(0000000076600000 - 000000007661d000: C:\WINDOWS\System32\CSCDLL.dll
109(0000000076780000 - 0000000076789000: C:\WINDOWS\system32\SHFOLDER.dll
110(0000000076990000 - 00000000769b5000: C:\WINDOWS\system32\ntshrui.dll
111(00000000769c0000 - 0000000076a74000: C:\WINDOWS\system32\USERENV.dll
112(0000000076b20000 - 0000000076b31000: C:\WINDOWS\system32\ATL.DLL
113(0000000076b40000 - 0000000076b6d000: C:\WINDOWS\system32\WINMM.DLL
114(0000000076c30000 - 0000000076c5e000: C:\WINDOWS\system32\WINTRUST.dll
115(0000000076c90000 - 0000000076cb8000: C:\WINDOWS\system32\IMAGEHLP.dll
116(0000000076d60000 - 0000000076d79000: C:\WINDOWS\system32\Iphlpapi.dll
117(0000000076f20000 - 0000000076f47000: C:\WINDOWS\system32\DNSAPI.dll
118(0000000076f60000 - 0000000076f8c000: C:\WINDOWS\system32\WLDAP32.dll
119(0000000076fc0000 - 0000000076fc6000: C:\WINDOWS\system32\rasadhlp.dll
120(0000000076fd0000 - 000000007704f000: C:\WINDOWS\system32\CLBCATQ.DLL
121(0000000077050000 - 0000000077115000: C:\WINDOWS\system32\COMRes.dll
122(0000000077120000 - 00000000771ab000: C:\WINDOWS\system32\OLEAUT32.DLL
123(00000000773d0000 - 00000000774d3000: C:\WINDOWS\WinSxS\X86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\COMCTL32.DLL
124(00000000774e0000 - 000000007761d000: C:\WINDOWS\system32\OLE32.dll
125(0000000077920000 - 0000000077a13000: C:\WINDOWS\system32\SETUPAPI.dll
126(0000000077a20000 - 0000000077a74000: C:\WINDOWS\System32\cscui.dll
127(0000000077a80000 - 0000000077b15000: C:\WINDOWS\system32\CRYPT32.dll
128(0000000077b20000 - 0000000077b32000: C:\WINDOWS\system32\MSASN1.dll
129(0000000077b40000 - 0000000077b62000: C:\WINDOWS\system32\appHelp.dll
130(0000000077c00000 - 0000000077c08000: C:\WINDOWS\system32\VERSION.dll
131(0000000077c10000 - 0000000077c68000: C:\WINDOWS\system32\msvcrt.dll
132(0000000077dd0000 - 0000000077e6b000: C:\WINDOWS\system32\ADVAPI32.DLL
133(0000000077e70000 - 0000000077f02000: C:\WINDOWS\system32\RPCRT4.dll
134(0000000077f10000 - 0000000077f59000: C:\WINDOWS\system32\GDI32.dll
135(0000000077f60000 - 0000000077fd6000: C:\WINDOWS\system32\SHLWAPI.dll
136(0000000077fe0000 - 0000000077ff1000: C:\WINDOWS\system32\Secur32.dll
137(0000000078000000 - 0000000078045000: C:\WINDOWS\system32\iertutil.dll
138(0000000078050000 - 0000000078120000: C:\WINDOWS\system32\WININET.dll
139(0000000078480000 - 000000007850e000: C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\MSVCP90.dll
140(0000000078520000 - 00000000785c3000: C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\MSVCR90.dll
141(000000007c800000 - 000000007c8f6000: C:\WINDOWS\system32\kernel32.dll
142(000000007c900000 - 000000007c9af000: C:\WINDOWS\system32\ntdll.dll
143(000000007c9c0000 - 000000007d1d7000: C:\WINDOWS\system32\SHELL32.dll
144(000000007e290000 - 000000007e401000: C:\WINDOWS\system32\shdocvw.dll
145(000000007e410000 - 000000007e4a1000: C:\WINDOWS\system32\USER32.dll
146
147*----> State Dump for Thread Id 0xe38 <----*
148
149eax=012b71e0 ebx=012fca78 ecx=00000001 edx=00000001 esi=00000308 edi=00000000
150eip=7c90e4f4 esp=0022efe0 ebp=0022f044 iopl=0 nv up ei pl zr na po nc
151cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
152
153*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\ntdll.dll -
154function: ntdll!KiFastSystemCallRet
155 7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
156 7c90e4df 8b0424 mov eax,[esp]
157 7c90e4e2 8be5 mov esp,ebp
158 7c90e4e4 5d pop ebp
159 7c90e4e5 c3 ret
160 7c90e4e6 8da42400000000 lea esp,[esp]
161 7c90e4ed 8d4900 lea ecx,[ecx]
162 ntdll!KiFastSystemCall:
163 7c90e4f0 8bd4 mov edx,esp
164 7c90e4f2 0f34 sysenter
165 ntdll!KiFastSystemCallRet:
166 7c90e4f4 c3 ret
167 7c90e4f5 8da42400000000 lea esp,[esp]
168 7c90e4fc 8d642400 lea esp,[esp]
169 ntdll!KiIntSystemCall:
170 7c90e500 8d542408 lea edx,[esp+0x8]
171 7c90e504 cd2e int 2e
172 7c90e506 c3 ret
173 7c90e507 90 nop
174 ntdll!RtlRaiseException:
175 7c90e508 55 push ebp
176 7c90e509 8bec mov ebp,esp
177
178*----> Stack Back Trace <----*
179*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\kernel32.dll -
180WARNING: Stack unwind information not available. Following frames may be wrong.
181*** ERROR: Module load completed but symbols could not be loaded for C:\Program Files\FileZilla Client\filezilla.exe
182*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\USER32.dll -
183ChildEBP RetAddr Args to Child
1840022f044 7c802542 00000308 ffffffff 00000000 ntdll!KiFastSystemCallRet
1850022f058 00818186 00000308 ffffffff 0022f0c8 kernel32!WaitForSingleObject+0x12
1860022f078 0081820e 012fca78 ffffffff 008deadf filezilla+0x418186
1870022f098 00565d92 012e9110 0022f0e8 0022f0c8 filezilla+0x41820e
1880022f0c8 005a3077 012fc2a8 00000000 0022f15c filezilla+0x165d92
1890022f128 005594d1 0130a038 012e86b4 0022f15c filezilla+0x1a3077
1900022f148 0055a4a4 012b7138 00000001 009db62c filezilla+0x1594d1
1910022f168 00815f4f 012b7138 00000802 0055ecf0 filezilla+0x15a4a4
1920022f198 00816760 00aa6570 012b7138 0022f244 filezilla+0x415f4f
1930022f1c8 00816a9b 00aa653c 0022f244 012b7138 filezilla+0x416760
1940022f1e8 0072aa24 012b7138 0022f244 00002715 filezilla+0x416a9b
1950022f278 0072a246 012b71a0 0022f310 0022f2a8 filezilla+0x32aa24
1960022f2a8 7e418734 00000000 00000113 00006f7f filezilla+0x32a246
1970022f2d4 7e419857 0072a200 00000000 00000113 USER32!GetDC+0x6d
1980022f33c 7e419791 00000000 0072a200 00000000 USER32!IsChild+0x149
1990022f394 7e418a10 0022f42c 00000000 0022f3c4 USER32!IsChild+0x83
2000022f3a4 007c6eca 0022f42c 0022f42c 00000000 USER32!DispatchMessageW+0xf
2010022f3c4 007c706a 012fc4f0 0022f42c 012fc4f0 filezilla+0x3c6eca
2020022f454 007cb824 012fc4f0 012fce58 00000000 filezilla+0x3c706a
2030022f4c4 0070f178 012fc4f0 0022f678 00000000 filezilla+0x3cb824
2040022f554 006efe4f 0022f678 01309118 00000001 filezilla+0x30f178
2050022f574 005175c2 0022f678 01309118 0000001a filezilla+0x2efe4f
2060022f614 00477e6a 0022f678 0113cd20 00477bf0 filezilla+0x1175c2
2070022f944 00815f4f 0113cd20 0022fa30 00477bf0 filezilla+0x77e6a
2080022f974 00816760 00aa3568 0113cd20 0022fa30 filezilla+0x415f4f
2090022f9a4 00816a9b 00aa3264 0022fa30 0113cd20 filezilla+0x416760
2100022f9c4 00793e29 0113cd20 0022fa30 0113cd20 filezilla+0x416a9b
2110022fa74 00790d65 0113cd20 000000b9 00000000 filezilla+0x393e29
2120022fa94 007929f3 0113cd20 000000b9 00000000 filezilla+0x390d65
2130022fad4 006fe825 0113cd20 00000111 000000b9 filezilla+0x3929f3
2140022fb04 7e418734 00e0075a 00000111 000000b9 filezilla+0x2fe825
2150022fb30 7e418816 006fe7d0 00e0075a 00000111 USER32!GetDC+0x6d
2160022fb98 7e4189cd 00000000 006fe7d0 00e0075a USER32!GetDC+0x14f
2170022fbf8 7e418a10 0022fc90 00000000 0022fc28 USER32!GetWindowLongW+0x127
2180022fc08 007c6eca 0022fc90 0022fc90 00000000 USER32!DispatchMessageW+0xf
2190022fc28 007c706a 01306438 0022fc90 01306438 filezilla+0x3c6eca
2200022fcb8 007cb824 01306438 00400000 0022fd28 filezilla+0x3c706a
2210022fd28 0076de0a 01306438 00370035 0022fda8 filezilla+0x3cb824
2220022fda8 0088d217 01112e80 003f6bb8 00aa2010 filezilla+0x36de0a
2230022fe08 0076c009 0022fea8 003f6bb8 00000001 filezilla+0x48d217
2240022feb8 00429d4b 00400000 00000000 00252342 filezilla+0x36c009
2250022fed8 008de579 00400000 00000000 00252342 filezilla+0x29d4b
2260022ff58 004010a7 004012f0 009ac7a4 0022ff78 filezilla+0x4de579
2270022ffa0 00401123 00000002 8061750d 7c90dc9c filezilla+0x10a7
2280022ffc0 7c817067 00370035 00360034 7ffdf000 filezilla+0x1123
2290022fff0 00000000 00401110 00000000 78746341 kernel32!RegisterWaitForInputIdle+0x49
230
231*----> Raw Stack Dump <----*
232000000000022efe0 3c df 90 7c db 25 80 7c - 08 03 00 00 00 00 00 00 <..|.%.|........
233000000000022eff0 00 00 00 00 00 00 00 00 - a8 c2 2f 01 78 ca 2f 01 ........../.x./.
234000000000022f000 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
235000000000022f010 10 00 00 00 e0 fb 2e 01 - 38 f0 22 00 00 f0 fd 7f ........8.".....
236000000000022f020 00 e0 fd 7f 00 00 00 00 - 01 00 00 00 f4 ef 22 00 ..............".
237000000000022f030 e0 fb 2e 01 2c f3 22 00 - c0 9a 83 7c 08 26 80 7c ....,."....|.&.|
238000000000022f040 00 00 00 00 58 f0 22 00 - 42 25 80 7c 08 03 00 00 ....X.".B%.|....
239000000000022f050 ff ff ff ff 00 00 00 00 - 78 f0 22 00 86 81 81 00 ........x.".....
240000000000022f060 08 03 00 00 ff ff ff ff - c8 f0 22 00 54 b5 9a 00 ..........".T...
241000000000022f070 80 c2 9a 00 38 71 2b 01 - 98 f0 22 00 0e 82 81 00 ....8q+...".....
242000000000022f080 78 ca 2f 01 ff ff ff ff - df ea 8d 00 df ea 8d 00 x./.............
243000000000022f090 e8 f0 22 00 00 00 00 00 - c8 f0 22 00 92 5d 56 00 .."......."..]V.
244000000000022f0a0 10 91 2e 01 e8 f0 22 00 - c8 f0 22 00 df ea 8d 00 ......"...".....
245000000000022f0b0 0f 00 00 00 08 f2 22 00 - 01 00 00 00 38 71 2b 01 ......".....8q+.
246000000000022f0c0 02 08 00 00 a8 c2 2f 01 - 28 f1 22 00 77 30 5a 00 ....../.(.".w0Z.
247000000000022f0d0 a8 c2 2f 01 00 00 00 00 - 5c f1 22 00 01 00 00 00 ../.....\.".....
248000000000022f0e0 00 f1 22 00 68 6f 2d 01 - 08 f2 22 00 01 00 00 00 ..".ho-...".....
249000000000022f0f0 50 cf 2f 01 d8 e5 a9 00 - 08 f2 22 00 02 00 00 00 P./.......".....
250000000000022f100 80 c2 9a 00 3a 22 9b 00 - 1c f1 22 00 cf 30 5a 00 ....:"...."..0Z.
251000000000022f110 e0 f0 22 00 0a 16 9b 00 - 3c f1 22 00 38 71 2b 01 ..".....<.".8q+.
252
253*----> State Dump for Thread Id 0x105c <----*
254
255eax=00000000 ebx=00000000 ecx=002698f8 edx=ffffffff esi=002697a0 edi=00269844
256eip=7c90e4f4 esp=019ffe18 ebp=019fff80 iopl=0 nv up ei pl zr na po nc
257cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
258
259function: ntdll!KiFastSystemCallRet
260 7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
261 7c90e4df 8b0424 mov eax,[esp]
262 7c90e4e2 8be5 mov esp,ebp
263 7c90e4e4 5d pop ebp
264 7c90e4e5 c3 ret
265 7c90e4e6 8da42400000000 lea esp,[esp]
266 7c90e4ed 8d4900 lea ecx,[ecx]
267 ntdll!KiFastSystemCall:
268 7c90e4f0 8bd4 mov edx,esp
269 7c90e4f2 0f34 sysenter
270 ntdll!KiFastSystemCallRet:
271 7c90e4f4 c3 ret
272 7c90e4f5 8da42400000000 lea esp,[esp]
273 7c90e4fc 8d642400 lea esp,[esp]
274 ntdll!KiIntSystemCall:
275 7c90e500 8d542408 lea edx,[esp+0x8]
276 7c90e504 cd2e int 2e
277 7c90e506 c3 ret
278 7c90e507 90 nop
279 ntdll!RtlRaiseException:
280 7c90e508 55 push ebp
281 7c90e509 8bec mov ebp,esp
282
283*----> Stack Back Trace <----*
284*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\RPCRT4.dll -
285WARNING: Stack unwind information not available. Following frames may be wrong.
286ChildEBP RetAddr Args to Child
287019fff80 77e76caf 019fffa8 77e76ad1 002697a0 ntdll!KiFastSystemCallRet
288019fff88 77e76ad1 002697a0 00000000 0022f300 RPCRT4!I_RpcBCacheFree+0x61c
289019fffa8 77e76c97 00267340 019fffec 7c80b713 RPCRT4!I_RpcBCacheFree+0x43e
290019fffb4 7c80b713 002698f8 00000000 0022f300 RPCRT4!I_RpcBCacheFree+0x604
291019fffec 00000000 77e76c7d 002698f8 00000000 kernel32!GetModuleFileNameA+0x1b4
292
293*----> Raw Stack Dump <----*
29400000000019ffe18 8c da 90 7c e3 65 e7 77 - e0 00 00 00 74 ff 9f 01 ...|.e.w....t...
29500000000019ffe28 00 00 00 00 f0 fd 26 00 - 48 ff 9f 01 50 c5 b5 86 ......&.H...P...
29600000000019ffe38 40 00 00 00 30 3d dc 86 - 00 00 00 00 c4 c5 b5 86 @...0=..........
29700000000019ffe48 3a ac 00 00 50 c5 b5 86 - 39 ac 00 00 58 02 9c e1 :...P...9...X...
29800000000019ffe58 36 00 f8 00 76 02 9c e1 - b4 28 d6 86 56 e6 52 80 6...v....(..V.R.
29900000000019ffe68 58 2b 0d 88 04 c6 b5 86 - 04 7c 57 80 08 e3 d0 86 X+.......|W.....
30000000000019ffe78 89 1f 9d f5 f0 84 70 86 - 7b 4c 9d f5 50 57 9e f5 ......p.{L..PW..
30100000000019ffe88 ff ff ff 00 10 08 96 85 - 08 00 00 00 00 00 00 00 ................
30200000000019ffe98 a0 63 84 85 0c c5 74 86 - a0 63 84 85 a0 63 84 85 .c....t..c...c..
30300000000019ffea8 9c 2b 0d 88 2c 0e 50 80 - 10 64 84 85 02 c5 74 86 .+..,.P..d....t.
30400000000019ffeb8 00 00 00 00 06 02 00 00 - 59 17 54 80 02 00 00 00 ........Y.T.....
30500000000019ffec8 20 90 4f 80 78 7b c5 86 - 48 02 c7 86 80 c5 74 86 .O.x{..H.....t.
30600000000019ffed8 cc 2b 0d 88 8b f6 80 f7 - ac 02 c7 86 00 00 00 00 .+..............
30700000000019ffee8 00 00 00 00 e0 2b 0d 88 - 9f 0b 61 b2 a8 02 c7 86 .....+....a.....
30800000000019ffef8 00 00 00 00 30 c1 74 86 - 08 2c 0d 88 2a 81 1c f7 ....0.t..,..*...
30900000000019fff08 08 e0 66 84 48 02 c7 86 - 39 81 1c f7 bc c1 8d 85 ..f.H...9.......
31000000000019fff18 24 2c 0d 88 7d 9e 4f 80 - 85 9e 4f 80 8c c1 8d 85 $,..}.O...O.....
31100000000019fff28 20 c0 8d 85 80 ff 9f 01 - ae df e7 77 48 ff 9f 01 ..........wH...
31200000000019fff38 be df e7 77 e0 10 90 7c - 00 82 26 00 f8 98 26 00 ...w...|..&...&.
31300000000019fff48 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff ../M.....]......
314
315*----> State Dump for Thread Id 0xae0 <----*
316
317eax=77df845a ebx=0212fed0 ecx=00000006 edx=00000000 esi=00000000 edi=7ffdf000
318eip=7c90e4f4 esp=0212fea8 ebp=0212ff44 iopl=0 nv up ei pl zr na po nc
319cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
320
321function: ntdll!KiFastSystemCallRet
322 7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
323 7c90e4df 8b0424 mov eax,[esp]
324 7c90e4e2 8be5 mov esp,ebp
325 7c90e4e4 5d pop ebp
326 7c90e4e5 c3 ret
327 7c90e4e6 8da42400000000 lea esp,[esp]
328 7c90e4ed 8d4900 lea ecx,[ecx]
329 ntdll!KiFastSystemCall:
330 7c90e4f0 8bd4 mov edx,esp
331 7c90e4f2 0f34 sysenter
332 ntdll!KiFastSystemCallRet:
333 7c90e4f4 c3 ret
334 7c90e4f5 8da42400000000 lea esp,[esp]
335 7c90e4fc 8d642400 lea esp,[esp]
336 ntdll!KiIntSystemCall:
337 7c90e500 8d542408 lea edx,[esp+0x8]
338 7c90e504 cd2e int 2e
339 7c90e506 c3 ret
340 7c90e507 90 nop
341 ntdll!RtlRaiseException:
342 7c90e508 55 push ebp
343 7c90e509 8bec mov ebp,esp
344
345*----> Stack Back Trace <----*
346*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\ADVAPI32.DLL -
347WARNING: Stack unwind information not available. Following frames may be wrong.
348ChildEBP RetAddr Args to Child
3490212ff44 77df8601 00000002 0212ff6c 00000000 ntdll!KiFastSystemCallRet
3500212ffb4 7c80b713 00000000 7c91428f 00000000 ADVAPI32!WmiFreeBuffer+0x24e
3510212ffec 00000000 77df845a 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4
352
353*----> Raw Stack Dump <----*
354000000000212fea8 2c df 90 7c 74 95 80 7c - 02 00 00 00 d0 fe 12 02 ,..|t..|........
355000000000212feb8 01 00 00 00 01 00 00 00 - 04 ff 12 02 e0 2e e3 01 ................
356000000000212fec8 60 66 e4 77 00 10 00 00 - cc 01 00 00 d8 01 00 00 `f.w............
357000000000212fed8 c0 fe 12 02 08 00 00 00 - dc ff 12 02 c0 9a 83 7c ...............|
358000000000212fee8 40 0b 81 7c 00 10 00 00 - 14 00 00 00 01 00 00 00 @..|............
359000000000212fef8 d0 28 28 00 00 00 00 00 - 00 00 00 00 00 a2 2f 4d .((.........../M
360000000000212ff08 ff ff ff ff 00 10 00 00 - 00 f0 fd 7f 00 b0 fd 7f ................
361000000000212ff18 dc ff 12 02 04 ff 12 02 - d0 fe 12 02 06 00 00 00 ................
362000000000212ff28 02 00 00 00 c4 fe 12 02 - 06 00 00 00 dc ff 12 02 ................
363000000000212ff38 c0 9a 83 7c 68 96 80 7c - 00 00 00 00 b4 ff 12 02 ...|h..|........
364000000000212ff48 01 86 df 77 02 00 00 00 - 6c ff 12 02 00 00 00 00 ...w....l.......
365000000000212ff58 e0 93 04 00 01 00 00 00 - 8f 42 91 7c 00 00 00 00 .........B.|....
366000000000212ff68 00 00 00 00 cc 01 00 00 - d8 01 00 00 00 10 00 00 ................
367000000000212ff78 e0 2e e3 01 00 00 00 00 - 00 10 00 00 e8 3e e3 01 .............>..
368000000000212ff88 00 67 e4 77 28 00 00 00 - e0 66 e4 77 00 10 00 00 .g.w(....f.w....
369000000000212ff98 00 00 00 00 00 67 e4 77 - e0 2e e3 01 e0 66 e4 77 .....g.w.....f.w
370000000000212ffa8 e5 03 00 00 00 10 00 00 - e8 3e e3 01 ec ff 12 02 .........>......
371000000000212ffb8 13 b7 80 7c 00 00 00 00 - 8f 42 91 7c 00 00 00 00 ...|.....B.|....
372000000000212ffc8 00 00 00 00 00 b0 fd 7f - 00 46 dc 86 c0 ff 12 02 .........F......
373000000000212ffd8 a8 7e bf 86 ff ff ff ff - c0 9a 83 7c 20 b7 80 7c .~.........| ..|
374
375*----> State Dump for Thread Id 0x1594 <----*
376
377eax=71a5d2c6 ebx=c0000000 ecx=7c912d58 edx=ffffffff esi=00000000 edi=71a8793c
378eip=7c90e4f4 esp=029bff7c ebp=029bffb4 iopl=0 nv up ei pl nz na pe nc
379cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202
380
381function: ntdll!KiFastSystemCallRet
382 7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
383 7c90e4df 8b0424 mov eax,[esp]
384 7c90e4e2 8be5 mov esp,ebp
385 7c90e4e4 5d pop ebp
386 7c90e4e5 c3 ret
387 7c90e4e6 8da42400000000 lea esp,[esp]
388 7c90e4ed 8d4900 lea ecx,[ecx]
389 ntdll!KiFastSystemCall:
390 7c90e4f0 8bd4 mov edx,esp
391 7c90e4f2 0f34 sysenter
392 ntdll!KiFastSystemCallRet:
393 7c90e4f4 c3 ret
394 7c90e4f5 8da42400000000 lea esp,[esp]
395 7c90e4fc 8d642400 lea esp,[esp]
396 ntdll!KiIntSystemCall:
397 7c90e500 8d542408 lea edx,[esp+0x8]
398 7c90e504 cd2e int 2e
399 7c90e506 c3 ret
400 7c90e507 90 nop
401 ntdll!RtlRaiseException:
402 7c90e508 55 push ebp
403 7c90e509 8bec mov ebp,esp
404
405*----> Stack Back Trace <----*
406WARNING: Stack unwind information not available. Following frames may be wrong.
407ChildEBP RetAddr Args to Child
408029bffb4 7c80b713 71a5d65f 027bf978 7c90e900 ntdll!KiFastSystemCallRet
409029bffec 00000000 71a5d2c6 00296358 00000000 kernel32!GetModuleFileNameA+0x1b4
410
411*----> Raw Stack Dump <----*
41200000000029bff7c 2c da 90 7c 20 d3 a5 71 - e0 02 00 00 bc ff 9b 02 ,..| ..q........
41300000000029bff8c b0 ff 9b 02 a4 ff 9b 02 - 68 d3 a5 71 78 f9 7b 02 ........h..qx.{.
41400000000029bff9c 00 e9 90 7c 58 63 29 00 - 00 00 00 00 00 00 00 00 ...|Xc).........
41500000000029bffac 00 00 a5 71 68 3d 2a 00 - ec ff 9b 02 13 b7 80 7c ...qh=*........|
41600000000029bffbc 5f d6 a5 71 78 f9 7b 02 - 00 e9 90 7c 58 63 29 00 _..qx.{....|Xc).
41700000000029bffcc 00 90 fd 7f 00 46 dc 86 - c0 ff 9b 02 08 b7 b7 86 .....F..........
41800000000029bffdc ff ff ff ff c0 9a 83 7c - 20 b7 80 7c 00 00 00 00 .......| ..|....
41900000000029bffec 00 00 00 00 00 00 00 00 - c6 d2 a5 71 58 63 29 00 ...........qXc).
42000000000029bfffc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
42100000000029c000c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
42200000000029c001c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
42300000000029c002c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
42400000000029c003c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
42500000000029c004c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
42600000000029c005c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
42700000000029c006c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
42800000000029c007c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
42900000000029c008c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
43000000000029c009c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
43100000000029c00ac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
432
433*----> State Dump for Thread Id 0x8a0 <----*
434
435eax=7c927ebb ebx=00000000 ecx=00000000 edx=7ffdec00 esi=00000000 edi=00000000
436eip=7c90e4f4 esp=027bff9c ebp=027bffb4 iopl=0 nv up ei pl zr na po nc
437cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
438
439function: ntdll!KiFastSystemCallRet
440 7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
441 7c90e4df 8b0424 mov eax,[esp]
442 7c90e4e2 8be5 mov esp,ebp
443 7c90e4e4 5d pop ebp
444 7c90e4e5 c3 ret
445 7c90e4e6 8da42400000000 lea esp,[esp]
446 7c90e4ed 8d4900 lea ecx,[ecx]
447 ntdll!KiFastSystemCall:
448 7c90e4f0 8bd4 mov edx,esp
449 7c90e4f2 0f34 sysenter
450 ntdll!KiFastSystemCallRet:
451 7c90e4f4 c3 ret
452 7c90e4f5 8da42400000000 lea esp,[esp]
453 7c90e4fc 8d642400 lea esp,[esp]
454 ntdll!KiIntSystemCall:
455 7c90e500 8d542408 lea edx,[esp+0x8]
456 7c90e504 cd2e int 2e
457 7c90e506 c3 ret
458 7c90e507 90 nop
459 ntdll!RtlRaiseException:
460 7c90e508 55 push ebp
461 7c90e509 8bec mov ebp,esp
462
463*----> Stack Back Trace <----*
464WARNING: Stack unwind information not available. Following frames may be wrong.
465ChildEBP RetAddr Args to Child
466027bffb4 7c80b713 00000000 00000000 00000000 ntdll!KiFastSystemCallRet
467027bffec 00000000 7c927ebb 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4
468
469*----> Raw Stack Dump <----*
47000000000027bff9c fc d1 90 7c 02 7f 92 7c - 01 00 00 00 ac ff 7b 02 ...|...|......{.
47100000000027bffac 00 00 00 00 00 00 00 80 - ec ff 7b 02 13 b7 80 7c ..........{....|
47200000000027bffbc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
47300000000027bffcc 00 a0 fd 7f 00 46 dc 86 - c0 ff 7b 02 68 3a 8a 85 .....F....{.h:..
47400000000027bffdc ff ff ff ff c0 9a 83 7c - 20 b7 80 7c 00 00 00 00 .......| ..|....
47500000000027bffec 00 00 00 00 00 00 00 00 - bb 7e 92 7c 00 00 00 00 .........~.|....
47600000000027bfffc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
47700000000027c000c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
47800000000027c001c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
47900000000027c002c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
48000000000027c003c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
48100000000027c004c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
48200000000027c005c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
48300000000027c006c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
48400000000027c007c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
48500000000027c008c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
48600000000027c009c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
48700000000027c00ac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
48800000000027c00bc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
48900000000027c00cc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
490
491*----> State Dump for Thread Id 0x240 <----*
492
493eax=012fc2a8 ebx=00000000 ecx=012fc2a8 edx=00000000 esi=012e90e8 edi=012e9114
494eip=008f7ca5 esp=030bfe78 ebp=030bfec0 iopl=0 nv up ei pl nz na pe nc
495cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202
496
497function: filezilla
498 008f7c8b 8d5624 lea edx,[esi+0x24]
499 008f7c8e 8a4631 mov al,[esi+0x31]
500 008f7c91 83c410 add esp,0x10
501 008f7c94 8955b8 mov [ebp-0x48],edx
502 008f7c97 84c0 test al,al
503 008f7c99 7530 jnz filezilla+0x4f7ccb (008f7ccb)
504 008f7c9b 90 nop
505 008f7c9c 8d742600 lea esi,[esi]
506 008f7ca0 8b4618 mov eax,[esi+0x18]
507 008f7ca3 85c0 test eax,eax
508 008f7ca5 740e jz filezilla+0x4f7cb5 (008f7cb5) [br=0]
509 008f7ca7 8b5e34 mov ebx,[esi+0x34]
510 008f7caa 85db test ebx,ebx
511 008f7cac 7537 jnz filezilla+0x4f7ce5 (008f7ce5)
512 008f7cae 8b4e1c mov ecx,[esi+0x1c]
513 008f7cb1 85c9 test ecx,ecx
514 008f7cb3 7530 jnz filezilla+0x4f7ce5 (008f7ce5)
515 008f7cb5 83ec0c sub esp,0xc
516 008f7cb8 c6465001 mov byte ptr [esi+0x50],0x1
517 008f7cbc 57 push edi
518 008f7cbd e82e0ef2ff call filezilla+0x418af0 (00818af0)
519
520*----> Stack Back Trace <----*
521WARNING: Stack unwind information not available. Following frames may be wrong.
522*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\msvcrt.dll -
523ChildEBP RetAddr Args to Child
524030bfec0 008fdb44 012e90e8 86c57b78 86c52320 filezilla+0x4f7ca5
525030bfee0 0081a0fb 0130a008 0130a008 b2610b9f filezilla+0x4fdb44
526030bff50 0081a254 0130a008 00000000 804fdb52 filezilla+0x41a0fb
527030bff80 77c3a3b0 0130a008 0022db34 003f0000 filezilla+0x41a254
528030bffb4 7c80b713 0130c750 0022db34 003f0000 msvcrt!endthreadex+0xa9
529030bffec 00000000 77c3a341 0130c750 00000000 kernel32!GetModuleFileNameA+0x1b4
530
531*----> Raw Stack Dump <----*
53200000000030bfe78 0c 91 2e 01 10 91 2e 01 - 10 00 00 00 50 c7 30 01 ............P.0.
53300000000030bfe88 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
53400000000030bfe98 a0 63 84 85 08 00 00 00 - a0 63 84 85 a0 63 84 85 .c.......c...c..
53500000000030bfea8 00 ff 0b 03 00 00 00 00 - e0 fe 0b 03 08 a0 30 01 ..............0.
53600000000030bfeb8 00 ff 0b 03 e0 8b 81 87 - e0 fe 0b 03 44 db 8f 00 ............D...
53700000000030bfec8 e8 90 2e 01 78 7b c5 86 - 20 23 c5 86 10 a0 30 01 ....x{.. #....0.
53800000000030bfed8 11 00 00 00 00 ff 0b 03 - 50 ff 0b 03 fb a0 81 00 ........P.......
53900000000030bfee8 08 a0 30 01 08 a0 30 01 - 9f 0b 61 b2 80 23 c5 86 ..0...0...a..#..
54000000000030bfef8 ff ff ff ff 46 02 00 00 - 00 00 00 00 04 00 00 00 ....F...........
54100000000030bff08 50 04 bc 86 20 f1 df ff - ec 05 bc 86 f8 0c 50 80 P... .........P.
54200000000030bff18 80 c2 9a 00 04 85 9b 00 - 44 ff 0b 03 1f a1 81 00 ........D.......
54300000000030bff28 f8 fe 0b 03 00 e9 90 7c - 40 00 91 7c ff ff ff ff .......|@..|....
54400000000030bff38 00 00 91 7c 20 82 81 00 - 08 a0 30 01 10 a0 30 01 ...| .....0...0.
54500000000030bff48 08 a0 30 01 34 db 22 00 - 80 ff 0b 03 54 a2 81 00 ..0.4.".....T...
54600000000030bff58 08 a0 30 01 00 00 00 00 - 52 db 4f 80 00 00 00 00 ..0.....R.O.....
54700000000030bff68 4c ff 0b 03 0e dc 4f 80 - a4 ff 0b 03 50 c7 30 01 L.....O.....P.0.
54800000000030bff78 e0 c7 30 01 34 db 22 00 - b4 ff 0b 03 b0 a3 c3 77 ..0.4."........w
54900000000030bff88 08 a0 30 01 34 db 22 00 - 00 00 3f 00 50 c7 30 01 ..0.4."...?.P.0.
55000000000030bff98 00 00 00 00 8c ff 0b 03 - 70 0c 50 80 dc ff 0b 03 ........p.P.....
55100000000030bffa8 94 5c c3 77 d8 40 c1 77 - 00 00 00 00 ec ff 0b 03 .\.w.@.w........
552
553*----> State Dump for Thread Id 0x2d4 <----*
554
555eax=77e76c7d ebx=00000000 ecx=00000000 edx=00000000 esi=002697a0 edi=00269844
556eip=7c90e4f4 esp=032bfe18 ebp=032bff80 iopl=0 nv up ei pl zr na po nc
557cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
558
559function: ntdll!KiFastSystemCallRet
560 7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
561 7c90e4df 8b0424 mov eax,[esp]
562 7c90e4e2 8be5 mov esp,ebp
563 7c90e4e4 5d pop ebp
564 7c90e4e5 c3 ret
565 7c90e4e6 8da42400000000 lea esp,[esp]
566 7c90e4ed 8d4900 lea ecx,[ecx]
567 ntdll!KiFastSystemCall:
568 7c90e4f0 8bd4 mov edx,esp
569 7c90e4f2 0f34 sysenter
570 ntdll!KiFastSystemCallRet:
571 7c90e4f4 c3 ret
572 7c90e4f5 8da42400000000 lea esp,[esp]
573 7c90e4fc 8d642400 lea esp,[esp]
574 ntdll!KiIntSystemCall:
575 7c90e500 8d542408 lea edx,[esp+0x8]
576 7c90e504 cd2e int 2e
577 7c90e506 c3 ret
578 7c90e507 90 nop
579 ntdll!RtlRaiseException:
580 7c90e508 55 push ebp
581 7c90e509 8bec mov ebp,esp
582
583*----> Stack Back Trace <----*
584WARNING: Stack unwind information not available. Following frames may be wrong.
585ChildEBP RetAddr Args to Child
586032bff80 77e76caf 032bffa8 77e76ad1 002697a0 ntdll!KiFastSystemCallRet
587032bff88 77e76ad1 002697a0 00000000 00000000 RPCRT4!I_RpcBCacheFree+0x61c
588032bffa8 77e76c97 00267340 032bffec 7c80b713 RPCRT4!I_RpcBCacheFree+0x43e
589032bffb4 7c80b713 002a1cd0 00000000 00000000 RPCRT4!I_RpcBCacheFree+0x604
590032bffec 00000000 77e76c7d 002a1cd0 00000000 kernel32!GetModuleFileNameA+0x1b4
591
592*----> Raw Stack Dump <----*
59300000000032bfe18 8c da 90 7c e3 65 e7 77 - e0 00 00 00 74 ff 2b 03 ...|.e.w....t.+.
59400000000032bfe28 00 00 00 00 38 a3 29 00 - 48 ff 2b 03 00 00 00 00 ....8.).H.+.....
59500000000032bfe38 66 28 6d 80 08 00 00 00 - 02 02 00 00 f3 aa 4f 80 f(m...........O.
59600000000032bfe48 e8 f9 bf 86 a8 f9 bf 86 - 04 00 00 00 18 fe db 02 ................
59700000000032bfe58 48 8d 81 87 31 2c 5c 80 - 18 fe db 02 04 00 00 00 H...1,\.........
59800000000032bfe68 cd 3a 5c 80 64 8d 81 87 - 18 fe db 02 fc 2b 5c 80 .:\.d........+\.
59900000000032bfe78 00 00 00 00 a8 f9 bf 86 - 00 00 00 00 90 8f 86 85 ................
60000000000032bfe88 00 00 00 00 02 00 4c fa - 24 8c 81 00 24 8c 81 87 ......L.$...$...
60100000000032bfe98 46 8d 5c b2 24 20 01 00 - 24 8a 5c b2 a8 f9 bf 86 F.\.$ ..$.\.....
60200000000032bfea8 18 2d 8f e5 18 b4 08 e1 - 29 f9 d4 84 b4 8b 81 87 .-......).......
60300000000032bfeb8 24 48 60 80 00 2d 8f e5 - 18 b4 08 e1 70 7e dc 86 $H`..-......p~..
60400000000032bfec8 03 00 1f 00 28 f9 d4 84 - 0c 02 00 00 fc 8b 81 87 ....(...........
60500000000032bfed8 01 33 5b 80 00 2d 8f e5 - 00 00 00 00 30 26 e4 84 .3[..-......0&..
60600000000032bfee8 90 8f 86 85 00 00 00 00 - 90 04 00 00 02 00 00 00 ................
60700000000032bfef8 e0 8b 81 87 00 1d 5b 80 - 84 fa bf 86 44 8c 81 87 ......[.....D...
60800000000032bff08 c4 aa 75 86 00 00 00 00 - 30 09 5a 84 8c b8 9c 84 ..u.....0.Z.....
60900000000032bff18 24 8c 81 87 7d 9e 4f 80 - 85 9e 4f 80 5c b8 9c 84 $...}.O...O.\...
61000000000032bff28 f0 b6 9c 84 80 ff 2b 03 - ae df e7 77 48 ff 2b 03 ......+....wH.+.
61100000000032bff38 be df e7 77 e0 10 90 7c - f0 3c 2a 00 d0 1c 2a 00 ...w...|.<*...*.
61200000000032bff48 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff ../M.....]......
613
614*----> State Dump for Thread Id 0xe58 <----*
615
616eax=7ffdf000 ebx=00000001 ecx=00000002 edx=00000003 esi=00000004 edi=00000005
617eip=7c90120e esp=01a0ffcc ebp=01a0fff4 iopl=0 nv up ei pl zr na po nc
618cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000246
619
620function: ntdll!DbgBreakPoint
621 7c9011e6 64a118000000 mov eax,fs:[00000018]
622 7c9011ec 803d94b0977c00 cmp byte ptr [ntdll!fltused+0x4c (7c97b094)],0x0
623 7c9011f3 8b7508 mov esi,[ebp+0x8]
624 7c9011f6 8945fc mov [ebp-0x4],eax
625 7c9011f9 0f85d7ec0000 jne ntdll!RtlInitUnicodeStringEx+0x61 (7c90fed6)
626 7c9011ff f6461010 test byte ptr [esi+0x10],0x10
627 7c901203 0f84cdec0000 je ntdll!RtlInitUnicodeStringEx+0x61 (7c90fed6)
628 7c901209 5e pop esi
629 7c90120a c9 leave
630 7c90120b c20400 ret 0x4
631FAULT ->ntdll!DbgBreakPoint:
6327c90120e cc int 3
633 7c90120f c3 ret
634 7c901210 8bff mov edi,edi
635 ntdll!DbgUserBreakPoint:
636 7c901212 cc int 3
637 7c901213 c3 ret
638 7c901214 8bff mov edi,edi
639 7c901216 8b442404 mov eax,[esp+0x4]
640 7c90121a cc int 3
641 7c90121b c20400 ret 0x4
642 ntdll!NtCurrentTeb:
643
644*----> Stack Back Trace <----*
645WARNING: Stack unwind information not available. Following frames may be wrong.
646ChildEBP RetAddr Args to Child
64701a0fff4 00000000 00000000 00000008 009ed50c ntdll!DbgBreakPoint
648
649*----> Raw Stack Dump <----*
6500000000001a0ffcc 10 00 95 7c 05 00 00 00 - 04 00 00 00 01 00 00 00 ...|............
6510000000001a0ffdc d0 ff a0 01 88 dd 04 b1 - ff ff ff ff 00 e9 90 7c ...............|
6520000000001a0ffec 30 00 95 7c 00 00 00 00 - 00 00 00 00 00 00 00 00 0..|............
6530000000001a0fffc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
6540000000001a1000c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
6550000000001a1001c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
6560000000001a1002c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
6570000000001a1003c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
6580000000001a1004c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
6590000000001a1005c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
6600000000001a1006c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
6610000000001a1007c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
6620000000001a1008c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
6630000000001a1009c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
6640000000001a100ac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
6650000000001a100bc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
6660000000001a100cc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
6670000000001a100dc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
6680000000001a100ec 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
6690000000001a100fc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
670