BSOD 000021a when logoff and login to different user

Discussion in 'Software' started by ofirad, Aug 4, 2008.

  1. ofirad

    ofirad Private E-2

    please help!
    on windows xp sp3 i have 3 user when i logof from one user and log in to administrator i receive a BSOD stop error 000021a and when i start Drwotson
    the log file say that Winlogon make an access violation error
    see Drwotson log:


    Microsoft (R) DrWtsn32
    Copyright (C) 1985-2001 Microsoft Corp. All rights reserved.



    Application exception occurred:
    App: \??\C:\WINDOWS\system32\winlogon.exe (pid=476)
    When: 8/4/2008 @ 09:51:01.515
    Exception number: c0000005 (access violation)

    *----> System Information <----*
    Computer Name: ORION_02
    User Name: SYSTEM
    Terminal Session Id: 0
    Number of Processors: 4
    Processor Type: x86 Family 15 Model 33 Stepping 2
    Windows Version: 5.1
    Current Build: 2600
    Service Pack: 3
    Current Type: Multiprocessor Free
    Registered Organization: USER
    Registered Owner: USER

    *----> Task List <----*
    0 System Process
    4 System
    404 smss.exe
    452 csrss.exe
    476 winlogon.exe
    520 services.exe
    532 lsass.exe
    732 Ati2evxx.exe
    748 svchost.exe
    804 svchost.exe
    872 svchost.exe
    948 svchost.exe
    1024 spoolsv.exe
    1732 svchost.exe
    1800 ntrtscan.exe
    1820 OfcPfwSvc.exe
    1872 tmlisten.exe
    288 SS37CC.EXE
    1080 Ati2evxx.exe
    2132 userinit.exe
    168 Explorer.EXE
    2276 ACSCSRV.EXE
    2316 AoiStat.exe
    2396 pccntmon.exe
    2408 ctfmon.exe
    2432 Pop3Trap.exe
    436 drwtsn32.exe

    *----> Module List <----*
    (0000000000980000 - 0000000000997000: C:\WINDOWS\system32\odbcint.dll
    (0000000001000000 - 0000000001081000: \??\C:\WINDOWS\system32\winlogon.exe
    (0000000001860000 - 0000000001b25000: C:\WINDOWS\system32\xpsp2res.dll
    (0000000005000000 - 0000000005001500: C:\WINDOWS\system32\antiwpa.dll
    (0000000010000000 - 0000000010010000: C:\WINDOWS\system32\Ati2evxx.dll
    (0000000047020000 - 0000000047028000: C:\WINDOWS\System32\dimsntfy.dll
    (000000004d4f0000 - 000000004d549000: C:\WINDOWS\system32\WINHTTP.dll
    (000000005ad70000 - 000000005ada8000: C:\WINDOWS\system32\uxtheme.dll
    (000000005b860000 - 000000005b8b5000: C:\WINDOWS\system32\NETAPI32.dll
    (000000005cf10000 - 000000005cf19000: C:\WINDOWS\system32\sclgntfy.dll
    (000000005d090000 - 000000005d12a000: C:\WINDOWS\system32\COMCTL32.dll
    (00000000629c0000 - 00000000629c9000: C:\WINDOWS\system32\LPK.DLL
    (0000000068000000 - 0000000068036000: C:\WINDOWS\system32\rsaenh.dll
    (0000000071aa0000 - 0000000071aa8000: C:\WINDOWS\system32\WS2HELP.dll
    (0000000071ab0000 - 0000000071ac7000: C:\WINDOWS\system32\WS2_32.dll
    (0000000071b00000 - 0000000071b0f000: C:\WINDOWS\system32\MPRUI.dll
    (0000000071b20000 - 0000000071b32000: C:\WINDOWS\system32\MPR.dll
    (0000000071b40000 - 0000000071b6c000: C:\WINDOWS\system32\netmsg.dll
    (0000000071ba0000 - 0000000071bee000: C:\WINDOWS\system32\NETUI2.dll
    (0000000071bf0000 - 0000000071c03000: C:\WINDOWS\system32\SAMLIB.dll
    (0000000071c10000 - 0000000071c1e000: C:\WINDOWS\System32\ntlanman.dll
    (0000000071c80000 - 0000000071c87000: C:\WINDOWS\System32\NETRAP.dll
    (0000000071c90000 - 0000000071cd0000: C:\WINDOWS\System32\NETUI1.dll
    (0000000071cd0000 - 0000000071ce7000: C:\WINDOWS\System32\NETUI0.dll
    (00000000722b0000 - 00000000722b5000: C:\WINDOWS\system32\SensApi.dll
    (00000000723d0000 - 00000000723ec000: C:\WINDOWS\system32\WINSCARD.DLL
    (0000000073000000 - 0000000073026000: C:\WINDOWS\system32\WINSPOOL.DRV
    (0000000074320000 - 000000007435d000: C:\WINDOWS\system32\ODBC32.dll
    (0000000074d90000 - 0000000074dfb000: C:\WINDOWS\system32\USP10.dll
    (00000000755c0000 - 00000000755ee000: C:\WINDOWS\system32\msctfime.ime
    (0000000075930000 - 000000007593a000: C:\WINDOWS\system32\PROFMAP.dll
    (0000000075940000 - 0000000075948000: C:\WINDOWS\system32\NDdeApi.dll
    (0000000075950000 - 000000007596a000: C:\WINDOWS\system32\WlNotify.dll
    (0000000075970000 - 0000000075a68000: C:\WINDOWS\system32\MSGINA.dll
    (0000000075e60000 - 0000000075e73000: C:\WINDOWS\system32\cryptnet.dll
    (0000000075f60000 - 0000000075f67000: C:\WINDOWS\System32\drprov.dll
    (0000000075f70000 - 0000000075f7a000: C:\WINDOWS\System32\davclnt.dll
    (0000000076360000 - 0000000076370000: C:\WINDOWS\system32\WINSTA.dll
    (0000000076390000 - 00000000763ad000: C:\WINDOWS\system32\IMM32.DLL
    (00000000763b0000 - 00000000763f9000: C:\WINDOWS\system32\comdlg32.dll
    (0000000076600000 - 000000007661d000: C:\WINDOWS\system32\cscdll.dll
    (00000000769c0000 - 0000000076a74000: C:\WINDOWS\system32\USERENV.dll
    (0000000076b40000 - 0000000076b6d000: C:\WINDOWS\system32\WINMM.dll
    (0000000076bb0000 - 0000000076bb5000: C:\WINDOWS\system32\sfc.dll
    (0000000076bc0000 - 0000000076bcf000: C:\WINDOWS\system32\REGAPI.dll
    (0000000076bf0000 - 0000000076bfb000: C:\WINDOWS\system32\PSAPI.DLL
    (0000000076c30000 - 0000000076c5e000: C:\WINDOWS\system32\WINTRUST.dll
    (0000000076c60000 - 0000000076c8a000: C:\WINDOWS\system32\sfc_os.dll
    (0000000076c90000 - 0000000076cb8000: C:\WINDOWS\system32\IMAGEHLP.dll
    (0000000076d60000 - 0000000076d79000: C:\WINDOWS\system32\iphlpapi.dll
    (0000000076e80000 - 0000000076e8e000: C:\WINDOWS\system32\rtutils.dll
    (0000000076e90000 - 0000000076ea2000: C:\WINDOWS\system32\rasman.dll
    (0000000076eb0000 - 0000000076edf000: C:\WINDOWS\system32\TAPI32.dll
    (0000000076ee0000 - 0000000076f1c000: C:\WINDOWS\system32\RASAPI32.dll
    (0000000076f50000 - 0000000076f58000: C:\WINDOWS\system32\WTSAPI32.dll
    (0000000076f60000 - 0000000076f8c000: C:\WINDOWS\system32\WLDAP32.dll
    (0000000076fd0000 - 000000007704f000: C:\WINDOWS\system32\CLBCATQ.DLL
    (0000000077050000 - 0000000077115000: C:\WINDOWS\system32\COMRes.dll
    (0000000077120000 - 00000000771ab000: C:\WINDOWS\system32\OLEAUT32.dll
    (00000000773d0000 - 00000000774d3000: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
    (00000000774e0000 - 000000007761d000: C:\WINDOWS\system32\ole32.dll
    (0000000077690000 - 00000000776b1000: C:\WINDOWS\system32\NTMARTA.DLL
    (00000000776c0000 - 00000000776d2000: C:\WINDOWS\system32\AUTHZ.dll
    (00000000776e0000 - 0000000077703000: C:\WINDOWS\system32\SHSVCS.dll
    (0000000077920000 - 0000000077a13000: C:\WINDOWS\system32\SETUPAPI.dll
    (0000000077a20000 - 0000000077a74000: C:\WINDOWS\system32\cscui.dll
    (0000000077a80000 - 0000000077b15000: C:\WINDOWS\system32\CRYPT32.dll
    (0000000077b20000 - 0000000077b32000: C:\WINDOWS\system32\MSASN1.dll
    (0000000077b40000 - 0000000077b62000: C:\WINDOWS\system32\Apphelp.dll
    (0000000077c00000 - 0000000077c08000: C:\WINDOWS\system32\VERSION.dll
    (0000000077c10000 - 0000000077c68000: C:\WINDOWS\system32\msvcrt.dll
    (0000000077c70000 - 0000000077c94000: C:\WINDOWS\system32\msv1_0.dll
    (0000000077dd0000 - 0000000077e6b000: C:\WINDOWS\system32\ADVAPI32.dll
    (0000000077e70000 - 0000000077f02000: C:\WINDOWS\system32\RPCRT4.dll
    (0000000077f10000 - 0000000077f59000: C:\WINDOWS\system32\GDI32.dll
    (0000000077f60000 - 0000000077fd6000: C:\WINDOWS\system32\SHLWAPI.dll
    (0000000077fe0000 - 0000000077ff1000: C:\WINDOWS\system32\Secur32.dll
    (000000007c800000 - 000000007c8f6000: C:\WINDOWS\system32\kernel32.dll
    (000000007c900000 - 000000007c9af000: C:\WINDOWS\system32\ntdll.dll
    (000000007c9c0000 - 000000007d1d7000: C:\WINDOWS\system32\SHELL32.dll
    (000000007e410000 - 000000007e4a1000: C:\WINDOWS\system32\USER32.dll
    (000000007e720000 - 000000007e7d0000: C:\WINDOWS\system32\sxs.dll

    *----> State Dump for Thread Id 0x1e0 <----*

    eax=00000001 ebx=00000000 ecx=000077c8 edx=7c97b420 esi=005d3a70 edi=00000001
    eip=7c90e4f4 esp=0006fb80 ebp=0006fbb4 iopl=0 nv up ei pl zr na po nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

    *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\ntdll.dll -
    function: ntdll!KiFastSystemCallRet
    7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
    7c90e4df 8b0424 mov eax,[esp]
    7c90e4e2 8be5 mov esp,ebp
    7c90e4e4 5d pop ebp
    7c90e4e5 c3 ret
    7c90e4e6 8da42400000000 lea esp,[esp]
    7c90e4ed 8d4900 lea ecx,[ecx]
    ntdll!KiFastSystemCall:
    7c90e4f0 8bd4 mov edx,esp
    7c90e4f2 0f34 sysenter
    ntdll!KiFastSystemCallRet:
    7c90e4f4 c3 ret
    7c90e4f5 8da42400000000 lea esp,[esp]
    7c90e4fc 8d642400 lea esp,[esp]
    ntdll!KiIntSystemCall:
    7c90e500 8d542408 lea edx,[esp+0x8]
    7c90e504 cd2e int 2e
    7c90e506 c3 ret
    7c90e507 90 nop
    ntdll!RtlRaiseException:
    7c90e508 55 push ebp
    7c90e509 8bec mov ebp,esp

    *----> Stack Back Trace <----*
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\USER32.dll -
    WARNING: Stack unwind information not available. Following frames may be wrong.
    *** ERROR: Module load completed but symbols could not be loaded for \??\C:\WINDOWS\system32\winlogon.exe
    ChildEBP RetAddr Args to Child
    0006fbb4 7e4249c4 000a0052 00000000 00000010 ntdll!KiFastSystemCallRet
    0006fbdc 7e424a06 01000000 01077dd0 00000000 USER32!GetCursorFrameInfo+0x1cc
    0006fbfc 7e4247ea 01000000 01077dd0 00000000 USER32!DialogBoxIndirectParamAorW+0x36
    0006fc20 0103e24c 01000000 00000578 00000000 USER32!DialogBoxParamW+0x3f
    0006fc44 0102d13a 01000000 00000578 00000000 winlogon+0x3e24c
    0006fc80 0103bef0 0007b0a0 01000000 00000578 winlogon+0x2d13a
    0006fcb8 01037372 0007b0a0 01000000 00000578 winlogon+0x3bef0
    0006fcd8 01038b3b 0007b0a0 0007b0a0 00072364 winlogon+0x37372
    0006fcfc 01031c7e 0007b0a0 7c80b731 00000000 winlogon+0x38b3b
    0006ff50 0103e75e 01000000 00000000 00072364 winlogon+0x31c7e
    0006fff4 00000000 7ffdf000 000000c8 00000121 winlogon+0x3e75e

    *----> Raw Stack Dump <----*
    000000000006fb80 18 94 41 7e 0a 77 42 7e - 00 00 00 00 00 00 00 00 ..A~.wB~........
    000000000006fb90 00 00 00 00 24 00 01 00 - 4c 00 00 00 09 00 00 00 ....$...L.......
    000000000006fba0 07 00 00 00 c9 27 07 00 - 71 02 00 00 06 03 00 00 .....'..q.......
    000000000006fbb0 00 00 00 00 dc fb 06 00 - c4 49 42 7e 52 00 0a 00 .........IB~R...
    000000000006fbc0 00 00 00 00 10 00 00 00 - 00 00 00 00 30 b1 07 00 ............0...
    000000000006fbd0 ff ff ff ff 00 00 00 00 - 00 00 00 00 fc fb 06 00 ................
    000000000006fbe0 06 4a 42 7e 00 00 00 01 - d0 7d 07 01 00 00 00 00 .JB~.....}......
    000000000006fbf0 e9 b9 03 01 b0 fc 06 00 - 01 00 00 00 20 fc 06 00 ............ ...
    000000000006fc00 ea 47 42 7e 00 00 00 01 - d0 7d 07 01 00 00 00 00 .GB~.....}......
    000000000006fc10 e9 b9 03 01 b0 fc 06 00 - 00 00 00 00 a0 b0 07 00 ................
    000000000006fc20 44 fc 06 00 4c e2 03 01 - 00 00 00 01 78 05 00 00 D...L.......x...
    000000000006fc30 00 00 00 00 e9 b9 03 01 - b0 fc 06 00 a0 b0 07 00 ................
    000000000006fc40 17 00 e0 11 80 fc 06 00 - 3a d1 02 01 00 00 00 01 ........:.......
    000000000006fc50 78 05 00 00 00 00 00 00 - e9 b9 03 01 b0 fc 06 00 x...............
    000000000006fc60 a0 b0 07 00 10 00 00 00 - 80 0f 05 fd ff ff ff ff ................
    000000000006fc70 00 f0 fd 7f 00 e0 fd 7f - 68 fc 06 00 00 00 00 00 ........h.......
    000000000006fc80 b8 fc 06 00 f0 be 03 01 - a0 b0 07 00 00 00 00 01 ................
    000000000006fc90 78 05 00 00 00 00 00 00 - e9 b9 03 01 b0 fc 06 00 x...............
    000000000006fca0 00 00 00 10 00 00 00 00 - 02 00 00 00 a0 b0 07 00 ................
    000000000006fcb0 a0 b0 07 00 30 b1 07 00 - d8 fc 06 00 72 73 03 01 ....0.......rs..

    *----> State Dump for Thread Id 0x1f4 <----*

    eax=00f734dc ebx=00007530 ecx=00121f18 edx=77fee054 esi=00083dc8 edi=00000000
    eip=7c90e4f4 esp=00bbfeac ebp=00bbfed8 iopl=0 nv up ei ng nz ac po cy
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000297

    function: ntdll!KiFastSystemCallRet
    7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
    7c90e4df 8b0424 mov eax,[esp]
    7c90e4e2 8be5 mov esp,ebp
    7c90e4e4 5d pop ebp
    7c90e4e5 c3 ret
    7c90e4e6 8da42400000000 lea esp,[esp]
    7c90e4ed 8d4900 lea ecx,[ecx]
    ntdll!KiFastSystemCall:
    7c90e4f0 8bd4 mov edx,esp
    7c90e4f2 0f34 sysenter
    ntdll!KiFastSystemCallRet:
    7c90e4f4 c3 ret
    7c90e4f5 8da42400000000 lea esp,[esp]
    7c90e4fc 8d642400 lea esp,[esp]
    ntdll!KiIntSystemCall:
    7c90e500 8d542408 lea edx,[esp+0x8]
    7c90e504 cd2e int 2e
    7c90e506 c3 ret
    7c90e507 90 nop
    ntdll!RtlRaiseException:
    7c90e508 55 push ebp
    7c90e509 8bec mov ebp,esp

    *----> Stack Back Trace <----*
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\RPCRT4.dll -
    WARNING: Stack unwind information not available. Following frames may be wrong.
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\kernel32.dll -
    ChildEBP RetAddr Args to Child
    00bbfed8 77e7715c 0000017c 00bbff10 00bbff00 ntdll!KiFastSystemCallRet
    00bbff14 77e772a0 00007530 00bbff6c 00bbff70 RPCRT4!I_RpcBCacheFree+0xac9
    00bbff80 77e77328 00bbffa8 77e76ad1 00083dc8 RPCRT4!I_RpcBCacheFree+0xc0d
    00bbff88 77e76ad1 00083dc8 7c90e900 0006f688 RPCRT4!I_RpcBCacheFree+0xc95
    00bbffa8 77e76c97 00082378 00bbffec 7c80b713 RPCRT4!I_RpcBCacheFree+0x43e
    00bbffb4 7c80b713 00082928 7c90e900 0006f688 RPCRT4!I_RpcBCacheFree+0x604
    00bbffec 00000000 77e76c7d 00082928 00000000 kernel32!GetModuleFileNameA+0x1b4

    *----> Raw Stack Dump <----*
    0000000000bbfeac 2c da 90 7c d6 a7 80 7c - 7c 01 00 00 00 ff bb 00 ,..|...||.......
    0000000000bbfebc f0 fe bb 00 d0 fe bb 00 - c8 fe bb 00 00 5d 1e ee .............]..
    0000000000bbfecc ff ff ff ff ac fa f8 00 - 48 00 00 00 14 ff bb 00 ........H.......
    0000000000bbfedc 5c 71 e7 77 7c 01 00 00 - 10 ff bb 00 00 ff bb 00 \q.w|...........
    0000000000bbfeec 08 ff bb 00 30 75 00 00 - 0a 98 80 7c c8 3d 08 00 ....0u.....|.=..
    0000000000bbfefc d0 3f 08 00 14 ff bb 00 - 7c 01 00 00 00 00 00 00 .?......|.......
    0000000000bbff0c 90 d5 f6 00 a4 d5 f6 00 - 80 ff bb 00 a0 72 e7 77 .............r.w
    0000000000bbff1c 30 75 00 00 6c ff bb 00 - 70 ff bb 00 78 ff bb 00 0u..l...p...x...
    0000000000bbff2c 64 ff bb 00 68 ff bb 00 - 74 ff bb 00 e0 10 90 7c d...h...t......|
    0000000000bbff3c 00 29 08 00 28 29 08 00 - 28 29 08 00 7c 01 00 00 .)..()..()..|...
    0000000000bbff4c ff ff ff ff 00 5d 1e ee - 00 00 00 00 02 00 00 00 .....]..........
    0000000000bbff5c 00 00 00 00 30 75 00 00 - 64 00 00 00 00 00 00 00 ....0u..d.......
    0000000000bbff6c 00 00 00 00 00 00 00 00 - 64 00 00 00 7c 01 00 00 ........d...|...
    0000000000bbff7c 00 00 00 00 88 ff bb 00 - 28 73 e7 77 a8 ff bb 00 ........(s.w....
    0000000000bbff8c d1 6a e7 77 c8 3d 08 00 - 00 e9 90 7c 88 f6 06 00 .j.w.=.....|....
    0000000000bbff9c 28 29 08 00 28 29 08 00 - 30 75 00 00 b4 ff bb 00 ()..()..0u......
    0000000000bbffac 97 6c e7 77 78 23 08 00 - ec ff bb 00 13 b7 80 7c .l.wx#.........|
    0000000000bbffbc 28 29 08 00 00 e9 90 7c - 88 f6 06 00 28 29 08 00 ().....|....()..
    0000000000bbffcc 00 c0 fd 7f 00 a6 64 8a - c0 ff bb 00 68 7f 94 89 ......d.....h...
    0000000000bbffdc ff ff ff ff c0 9a 83 7c - 20 b7 80 7c 00 00 00 00 .......| ..|....

    *----> State Dump for Thread Id 0x1fc <----*

    eax=000000c0 ebx=00000000 ecx=4390d950 edx=00000045 esi=00000000 edi=0006f7f0
    eip=7c90e4f4 esp=00c3ff9c ebp=00c3ffb4 iopl=0 nv up ei pl zr na po nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

    function: ntdll!KiFastSystemCallRet
    7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
    7c90e4df 8b0424 mov eax,[esp]
    7c90e4e2 8be5 mov esp,ebp
    7c90e4e4 5d pop ebp
    7c90e4e5 c3 ret
    7c90e4e6 8da42400000000 lea esp,[esp]
    7c90e4ed 8d4900 lea ecx,[ecx]
    ntdll!KiFastSystemCall:
    7c90e4f0 8bd4 mov edx,esp
    7c90e4f2 0f34 sysenter
    ntdll!KiFastSystemCallRet:
    7c90e4f4 c3 ret
    7c90e4f5 8da42400000000 lea esp,[esp]
    7c90e4fc 8d642400 lea esp,[esp]
    ntdll!KiIntSystemCall:
    7c90e500 8d542408 lea edx,[esp+0x8]
    7c90e504 cd2e int 2e
    7c90e506 c3 ret
    7c90e507 90 nop
    ntdll!RtlRaiseException:
    7c90e508 55 push ebp
    7c90e509 8bec mov ebp,esp

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be wrong.
    ChildEBP RetAddr Args to Child
    00c3ffb4 7c80b713 00000000 0006f7f0 00000000 ntdll!KiFastSystemCallRet
    00c3ffec 00000000 7c927ebb 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

    *----> Raw Stack Dump <----*
    0000000000c3ff9c fc d1 90 7c 02 7f 92 7c - 01 00 00 00 ac ff c3 00 ...|...|........
    0000000000c3ffac 00 00 00 00 00 00 00 80 - ec ff c3 00 13 b7 80 7c ...............|
    0000000000c3ffbc 00 00 00 00 f0 f7 06 00 - 00 00 00 00 00 00 00 00 ................
    0000000000c3ffcc 00 a0 fd 7f 00 a6 64 8a - c0 ff c3 00 90 c2 a7 89 ......d.........
    0000000000c3ffdc ff ff ff ff c0 9a 83 7c - 20 b7 80 7c 00 00 00 00 .......| ..|....
    0000000000c3ffec 00 00 00 00 00 00 00 00 - bb 7e 92 7c 00 00 00 00 .........~.|....
    0000000000c3fffc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000000c4000c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000000c4001c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000000c4002c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000000c4003c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000000c4004c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000000c4005c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000000c4006c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000000c4007c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000000c4008c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000000c4009c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000000c400ac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000000c400bc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000000c400cc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

    *----> State Dump for Thread Id 0x204 <----*

    eax=00000000 ebx=00000000 ecx=00000102 edx=00cbff08 esi=00f75548 edi=00f755ec
    eip=7c90e4f4 esp=00cbfe18 ebp=00cbff80 iopl=0 nv up ei pl zr na po nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

    function: ntdll!KiFastSystemCallRet
    7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
    7c90e4df 8b0424 mov eax,[esp]
    7c90e4e2 8be5 mov esp,ebp
    7c90e4e4 5d pop ebp
    7c90e4e5 c3 ret
    7c90e4e6 8da42400000000 lea esp,[esp]
    7c90e4ed 8d4900 lea ecx,[ecx]
    ntdll!KiFastSystemCall:
    7c90e4f0 8bd4 mov edx,esp
    7c90e4f2 0f34 sysenter
    ntdll!KiFastSystemCallRet:
    7c90e4f4 c3 ret
    7c90e4f5 8da42400000000 lea esp,[esp]
    7c90e4fc 8d642400 lea esp,[esp]
    ntdll!KiIntSystemCall:
    7c90e500 8d542408 lea edx,[esp+0x8]
    7c90e504 cd2e int 2e
    7c90e506 c3 ret
    7c90e507 90 nop
    ntdll!RtlRaiseException:
    7c90e508 55 push ebp
    7c90e509 8bec mov ebp,esp

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be wrong.
    ChildEBP RetAddr Args to Child
    00cbff80 77e76caf 00cbffa8 77e76ad1 00f75548 ntdll!KiFastSystemCallRet
    00cbff88 77e76ad1 00f75548 0006f5a0 00000008 RPCRT4!I_RpcBCacheFree+0x61c
    00cbffa8 77e76c97 00082378 00cbffec 7c80b713 RPCRT4!I_RpcBCacheFree+0x43e
    00cbffb4 7c80b713 000847b8 0006f5a0 00000008 RPCRT4!I_RpcBCacheFree+0x604
    00cbffec 00000000 77e76c7d 000847b8 00000000 kernel32!GetModuleFileNameA+0x1b4

    *----> Raw Stack Dump <----*
    0000000000cbfe18 8c da 90 7c e3 65 e7 77 - dc 08 00 00 74 ff cb 00 ...|.e.w....t...
    0000000000cbfe28 00 00 00 00 c8 be f9 00 - 48 ff cb 00 00 00 00 00 ........H.......
    0000000000cbfe38 c0 55 08 00 c0 55 08 00 - 38 4b f8 00 00 04 00 00 .U...U..8K......
    0000000000cbfe48 54 fe cb 00 00 00 00 00 - 8c 55 08 00 00 00 00 00 T........U......
    0000000000cbfe58 00 00 00 00 84 fe cb 00 - 58 1e e8 77 24 07 00 00 ........X..w$...
    0000000000cbfe68 38 4b f8 00 00 04 00 00 - 64 1e e8 77 ac 55 08 00 8K......d..w.U..
    0000000000cbfe78 01 00 00 80 00 00 00 00 - 8c 55 08 00 98 fe cb 00 .........U......
    0000000000cbfe88 e5 1d e8 77 60 00 00 00 - 38 4b f8 00 f8 53 08 00 ...w`...8K...S..
    0000000000cbfe98 00 ff cb 00 a9 1c e8 77 - 54 80 e7 77 04 54 08 00 .......wT..w.T..
    0000000000cbfea8 f8 53 08 00 2c da 90 7c - d6 a7 80 7c 00 00 00 00 .S..,..|...|....
    0000000000cbfeb8 c8 3d 08 00 d8 fe cb 00 - 1c a8 80 7c 02 01 00 00 .=.........|....
    0000000000cbfec8 00 5d 1e ee ff ff ff ff - 6c 4f f8 00 48 00 00 00 .]......lO..H...
    0000000000cbfed8 cc dc 90 7c 9f 27 81 7c - 7c 01 00 00 11 00 00 00 ...|.'.||.......
    0000000000cbfee8 00 00 00 00 00 00 00 00 - 93 99 00 00 05 00 00 00 ................
    0000000000cbfef8 14 ff cb 00 de 7d e8 77 - 7c 01 00 00 93 99 00 00 .....}.w|.......
    0000000000cbff08 11 00 00 00 00 00 00 00 - c8 3d 08 00 28 ff cb 00 .........=..(...
    0000000000cbff18 47 7e e8 77 11 00 00 00 - fe 79 e7 77 78 3d 08 00 G~.w.....y.wx=..
    0000000000cbff28 c8 3d 08 00 80 ff cb 00 - ae df e7 77 48 ff cb 00 .=.........wH...
    0000000000cbff38 be df e7 77 e0 10 90 7c - 90 47 08 00 b8 47 08 00 ...w...|.G...G..
    0000000000cbff48 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff ../M.....]......

    *----> State Dump for Thread Id 0x210 <----*

    eax=000000c0 ebx=00000000 ecx=7c91003d edx=02a30006 esi=00000000 edi=00000001
    eip=7c90e4f4 esp=00cffcec ebp=00cfffb4 iopl=0 nv up ei pl zr na po nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

    function: ntdll!KiFastSystemCallRet
    7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
    7c90e4df 8b0424 mov eax,[esp]
    7c90e4e2 8be5 mov esp,ebp
    7c90e4e4 5d pop ebp
    7c90e4e5 c3 ret
    7c90e4e6 8da42400000000 lea esp,[esp]
    7c90e4ed 8d4900 lea ecx,[ecx]
    ntdll!KiFastSystemCall:
    7c90e4f0 8bd4 mov edx,esp
    7c90e4f2 0f34 sysenter
    ntdll!KiFastSystemCallRet:
    7c90e4f4 c3 ret
    7c90e4f5 8da42400000000 lea esp,[esp]
    7c90e4fc 8d642400 lea esp,[esp]
    ntdll!KiIntSystemCall:
    7c90e500 8d542408 lea edx,[esp+0x8]
    7c90e504 cd2e int 2e
    7c90e506 c3 ret
    7c90e507 90 nop
    ntdll!RtlRaiseException:
    7c90e508 55 push ebp
    7c90e509 8bec mov ebp,esp

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be wrong.
    ChildEBP RetAddr Args to Child
    00cfffb4 7c80b713 00000000 7c90e900 7c910208 ntdll!KiFastSystemCallRet
    00cfffec 00000000 7c929b6f 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

    *----> Raw Stack Dump <----*
    0000000000cffcec 2c df 90 7c 96 9c 92 7c - 0a 00 00 00 30 fd cf 00 ,..|...|....0...
    0000000000cffcfc 01 00 00 00 01 00 00 00 - 00 00 00 00 00 e9 90 7c ...............|
    0000000000cffd0c 08 02 91 7c 00 00 00 00 - 80 c9 97 7c 80 c9 97 7c ...|.......|...|
    0000000000cffd1c b4 01 00 00 10 02 00 00 - 0a 00 00 00 0a 00 00 00 ................
    0000000000cffd2c 09 00 00 00 b8 01 00 00 - bc 01 00 00 c8 01 00 00 ................
    0000000000cffd3c 50 03 00 00 b4 02 00 00 - 60 03 00 00 2c 06 00 00 P.......`...,...
    0000000000cffd4c 30 06 00 00 20 09 00 00 - 00 09 00 00 34 07 00 00 0... .......4...
    0000000000cffd5c b0 08 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000000cffd6c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000000cffd7c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000000cffd8c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000000cffd9c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000000cffdac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000000cffdbc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000000cffdcc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000000cffddc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000000cffdec 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000000cffdfc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000000cffe0c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000000cffe1c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

    *----> State Dump for Thread Id 0x2b4 <----*

    eax=00f6c000 ebx=00000002 ecx=010cfd08 edx=00002000 esi=76c629b8 edi=00000000
    eip=7c90e4f4 esp=010cff64 ebp=010cffb4 iopl=0 nv up ei pl zr na po nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

    function: ntdll!KiFastSystemCallRet
    7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
    7c90e4df 8b0424 mov eax,[esp]
    7c90e4e2 8be5 mov esp,ebp
    7c90e4e4 5d pop ebp
    7c90e4e5 c3 ret
    7c90e4e6 8da42400000000 lea esp,[esp]
    7c90e4ed 8d4900 lea ecx,[ecx]
    ntdll!KiFastSystemCall:
    7c90e4f0 8bd4 mov edx,esp
    7c90e4f2 0f34 sysenter
    ntdll!KiFastSystemCallRet:
    7c90e4f4 c3 ret
    7c90e4f5 8da42400000000 lea esp,[esp]
    7c90e4fc 8d642400 lea esp,[esp]
    ntdll!KiIntSystemCall:
    7c90e500 8d542408 lea edx,[esp+0x8]
    7c90e504 cd2e int 2e
    7c90e506 c3 ret
    7c90e507 90 nop
    ntdll!RtlRaiseException:
    7c90e508 55 push ebp
    7c90e509 8bec mov ebp,esp

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be wrong.
    ChildEBP RetAddr Args to Child
    010cffb4 7c80b713 00000000 7e7bbd80 00ef2d58 ntdll!KiFastSystemCallRet
    010cffec 00000000 76c6c80b 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

    *----> Raw Stack Dump <----*
    00000000010cff64 2c df 90 7c d9 cb c6 76 - 02 00 00 00 20 64 12 00 ,..|...v.... d..
    00000000010cff74 00 00 00 00 01 00 00 00 - 00 00 00 00 80 bd 7b 7e ..............{~
    00000000010cff84 58 2d ef 00 00 00 00 00 - c4 68 12 00 a0 df ed 00 X-.......h......
    00000000010cff94 98 df ed 00 20 64 12 00 - 80 df ed 00 00 00 00 00 .... d..........
    00000000010cffa4 e0 3a ef 00 c0 68 12 00 - a0 2f ef 00 02 00 00 00 .:...h.../......
    00000000010cffb4 ec ff 0c 01 13 b7 80 7c - 00 00 00 00 80 bd 7b 7e .......|......{~
    00000000010cffc4 58 2d ef 00 00 00 00 00 - 00 d0 fd 7f 00 46 64 8a X-...........Fd.
    00000000010cffd4 c0 ff 0c 01 68 de 8a 89 - ff ff ff ff c0 9a 83 7c ....h..........|
    00000000010cffe4 20 b7 80 7c 00 00 00 00 - 00 00 00 00 00 00 00 00 ..|............
    00000000010cfff4 0b c8 c6 76 00 00 00 00 - 00 00 00 00 00 00 00 00 ...v............
    00000000010d0004 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    00000000010d0014 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    00000000010d0024 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    00000000010d0034 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    00000000010d0044 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    00000000010d0054 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    00000000010d0064 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    00000000010d0074 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    00000000010d0084 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    00000000010d0094 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

    *----> State Dump for Thread Id 0x2b8 <----*

    eax=00ed06f8 ebx=00eddf80 ecx=1535c97f edx=1536e5a8 esi=76c629b8 edi=00000000
    eip=7c90e4f4 esp=00d3ff4c ebp=00d3ffb4 iopl=0 nv up ei pl nz na pe nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202

    function: ntdll!KiFastSystemCallRet
    7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
    7c90e4df 8b0424 mov eax,[esp]
    7c90e4e2 8be5 mov esp,ebp
    7c90e4e4 5d pop ebp
    7c90e4e5 c3 ret
    7c90e4e6 8da42400000000 lea esp,[esp]
    7c90e4ed 8d4900 lea ecx,[ecx]
    ntdll!KiFastSystemCall:
    7c90e4f0 8bd4 mov edx,esp
    7c90e4f2 0f34 sysenter
    ntdll!KiFastSystemCallRet:
    7c90e4f4 c3 ret
    7c90e4f5 8da42400000000 lea esp,[esp]
    7c90e4fc 8d642400 lea esp,[esp]
    ntdll!KiIntSystemCall:
    7c90e500 8d542408 lea edx,[esp+0x8]
    7c90e504 cd2e int 2e
    7c90e506 c3 ret
    7c90e507 90 nop
    ntdll!RtlRaiseException:
    7c90e508 55 push ebp
    7c90e509 8bec mov ebp,esp

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be wrong.
    ChildEBP RetAddr Args to Child
    00d3ffb4 7c80b713 00f6c6f8 7c90e900 00000344 ntdll!KiFastSystemCallRet
    00d3ffec 00000000 76c6c54e 00eddf80 00000000 kernel32!GetModuleFileNameA+0x1b4

    *----> Raw Stack Dump <----*
    0000000000d3ff4c 2c df 90 7c ca c7 c6 76 - 40 00 00 00 e8 3a ef 00 ,..|...v@....:..
    0000000000d3ff5c 01 00 00 00 01 00 00 00 - 00 00 00 00 00 e9 90 7c ...............|
    0000000000d3ff6c 44 03 00 00 80 df ed 00 - 00 00 00 00 01 00 00 00 D...............
    0000000000d3ff7c 02 00 00 00 04 00 00 00 - 08 00 00 00 10 00 00 00 ................
    0000000000d3ff8c 00 00 00 00 a0 8a 67 89 - 4a 2f 50 80 00 00 00 00 ......g.J/P.....
    0000000000d3ff9c 00 00 00 00 00 00 00 00 - 00 00 00 00 a0 2f ef 00 ............./..
    0000000000d3ffac b8 2f ef 00 1c 00 00 00 - ec ff d3 00 13 b7 80 7c ./.............|
    0000000000d3ffbc f8 c6 f6 00 00 e9 90 7c - 44 03 00 00 80 df ed 00 .......|D.......
    0000000000d3ffcc 00 60 fd 7f 77 00 a3 a0 - c0 ff d3 00 58 8b 5c 89 .`..w.......X.\.
    0000000000d3ffdc ff ff ff ff c0 9a 83 7c - 20 b7 80 7c 00 00 00 00 .......| ..|....
    0000000000d3ffec 00 00 00 00 00 00 00 00 - 4e c5 c6 76 80 df ed 00 ........N..v....
    0000000000d3fffc 00 00 00 00 ff ff ff ff - ff ff ff ff 00 00 00 00 ................
    0000000000d4000c 00 10 00 00 00 01 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000000d4001c 00 00 00 00 01 00 00 00 - 00 01 00 00 a4 1a d4 00 ................
    0000000000d4002c 54 1a d4 00 34 12 d4 00 - d8 19 d4 00 58 fd 53 4d T...4.......X.SM
    0000000000d4003c 00 00 00 00 04 00 00 00 - 20 00 00 00 00 10 00 00 ........ .......
    0000000000d4004c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000000d4005c 02 00 00 00 00 00 00 00 - 90 cd 53 4d 00 00 00 00 ..........SM....
    0000000000d4006c 50 ce 53 4d 00 00 00 00 - 00 04 08 00 40 00 03 00 P.SM........@...
    0000000000d4007c 00 00 00 01 01 00 00 00 - 00 00 00 00 00 00 00 00 ................

    *----> State Dump for Thread Id 0x2bc <----*

    eax=76c6c54e ebx=00eddf8c ecx=010cfc74 edx=7c911008 esi=76c629b8 edi=00f6cf20
    eip=7c90e4f4 esp=0110ff4c ebp=0110ffb4 iopl=0 nv up ei pl zr na po nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

    function: ntdll!KiFastSystemCallRet
    7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
    7c90e4df 8b0424 mov eax,[esp]
    7c90e4e2 8be5 mov esp,ebp
    7c90e4e4 5d pop ebp
    7c90e4e5 c3 ret
    7c90e4e6 8da42400000000 lea esp,[esp]
    7c90e4ed 8d4900 lea ecx,[ecx]
    ntdll!KiFastSystemCall:
    7c90e4f0 8bd4 mov edx,esp
    7c90e4f2 0f34 sysenter
    ntdll!KiFastSystemCallRet:
    7c90e4f4 c3 ret
    7c90e4f5 8da42400000000 lea esp,[esp]
    7c90e4fc 8d642400 lea esp,[esp]
    ntdll!KiIntSystemCall:
    7c90e500 8d542408 lea edx,[esp+0x8]
    7c90e504 cd2e int 2e
    7c90e506 c3 ret
    7c90e507 90 nop
    ntdll!RtlRaiseException:
    7c90e508 55 push ebp
    7c90e509 8bec mov ebp,esp

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be wrong.
    ChildEBP RetAddr Args to Child
    0110ffb4 7c80b713 00f6cb10 7c90e900 00000344 ntdll!KiFastSystemCallRet
    0110ffec 00000000 76c6c54e 00eddf8c 00000000 kernel32!GetModuleFileNameA+0x1b4

    *----> Raw Stack Dump <----*
    000000000110ff4c 2c df 90 7c ca c7 c6 76 - 3a 00 00 00 f0 3b ef 00 ,..|...v:....;..
    000000000110ff5c 01 00 00 00 01 00 00 00 - 00 00 00 00 00 e9 90 7c ...............|
    000000000110ff6c 44 03 00 00 8c df ed 00 - 00 00 00 00 01 00 00 00 D...............
    000000000110ff7c 02 00 00 00 04 00 00 00 - 08 00 00 00 10 00 00 00 ................
    000000000110ff8c 00 00 00 00 a0 8a 67 89 - 4a 2f 50 80 00 00 00 00 ......g.J/P.....
    000000000110ff9c 00 00 00 00 00 00 00 00 - 5a 2f 50 80 88 35 ef 00 ........Z/P..5..
    000000000110ffac f2 6e 6e 80 fc d9 90 7c - ec ff 10 01 13 b7 80 7c .nn....|.......|
    000000000110ffbc 10 cb f6 00 00 e9 90 7c - 44 03 00 00 8c df ed 00 .......|D.......
    000000000110ffcc 00 40 fd 7f 00 46 64 8a - c0 ff 10 01 68 de 8a 89 .@...Fd.....h...
    000000000110ffdc ff ff ff ff c0 9a 83 7c - 20 b7 80 7c 00 00 00 00 .......| ..|....
    000000000110ffec 00 00 00 00 00 00 00 00 - 4e c5 c6 76 8c df ed 00 ........N..v....
    000000000110fffc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    000000000111000c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    000000000111001c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    000000000111002c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    000000000111003c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    000000000111004c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    000000000111005c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    000000000111006c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    000000000111007c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

    *----> State Dump for Thread Id 0x31c <----*

    eax=00000102 ebx=00000000 ecx=00000102 edx=7c90e4f4 esi=00082ac8 edi=00082b6c
    eip=7c90e4f4 esp=0114fe18 ebp=0114ff80 iopl=0 nv up ei pl zr na po nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

    function: ntdll!KiFastSystemCallRet
    7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
    7c90e4df 8b0424 mov eax,[esp]
    7c90e4e2 8be5 mov esp,ebp
    7c90e4e4 5d pop ebp
    7c90e4e5 c3 ret
    7c90e4e6 8da42400000000 lea esp,[esp]
    7c90e4ed 8d4900 lea ecx,[ecx]
    ntdll!KiFastSystemCall:
    7c90e4f0 8bd4 mov edx,esp
    7c90e4f2 0f34 sysenter
    ntdll!KiFastSystemCallRet:
    7c90e4f4 c3 ret
    7c90e4f5 8da42400000000 lea esp,[esp]
    7c90e4fc 8d642400 lea esp,[esp]
    ntdll!KiIntSystemCall:
    7c90e500 8d542408 lea edx,[esp+0x8]
    7c90e504 cd2e int 2e
    7c90e506 c3 ret
    7c90e507 90 nop
    ntdll!RtlRaiseException:
    7c90e508 55 push ebp
    7c90e509 8bec mov ebp,esp

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be wrong.
    ChildEBP RetAddr Args to Child
    0114ff80 77e76caf 0114ffa8 77e76ad1 00082ac8 ntdll!KiFastSystemCallRet
    0114ff88 77e76ad1 00082ac8 00000000 00000000 RPCRT4!I_RpcBCacheFree+0x61c
    0114ffa8 77e76c97 00082378 0114ffec 7c80b713 RPCRT4!I_RpcBCacheFree+0x43e
    0114ffb4 7c80b713 00f6cf28 00000000 00000000 RPCRT4!I_RpcBCacheFree+0x604
    0114ffec 00000000 77e76c7d 00f6cf28 00000000 kernel32!GetModuleFileNameA+0x1b4

    *----> Raw Stack Dump <----*
    000000000114fe18 8c da 90 7c e3 65 e7 77 - 2c 01 00 00 74 ff 14 01 ...|.e.w,...t...
    000000000114fe28 00 00 00 00 08 d0 f6 00 - 50 ff 14 01 08 00 00 00 ........P.......
    000000000114fe38 28 00 40 00 00 00 00 00 - 08 02 00 00 0c 02 00 00 (.@.............
    000000000114fe48 2b 08 00 00 00 00 00 00 - 02 00 00 00 01 00 4f 80 +.............O.
    000000000114fe58 94 ab 43 ac 78 fd 3f c0 - 00 e0 fa 7f 00 00 00 00 ..C.x.?.........
    000000000114fe68 70 fd 3f 02 70 ab 43 ac - 00 00 00 00 00 00 00 00 p.?.p.C.........
    000000000114fe78 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    000000000114fe88 00 00 00 00 f8 1f 60 c0 - 30 ac 43 ac fa 3f 52 80 ......`.0.C..?R.
    000000000114fe98 94 ab 43 ac 00 00 00 00 - 43 6d 6e 80 28 ac 43 ac ..C.....Cmn.(.C.
    000000000114fea8 27 64 6e 80 00 0d db ba - 00 00 00 00 00 00 00 00 'dn.............
    000000000114feb8 70 fd 3f c0 e0 1b 8d 89 - 00 00 00 00 3c 7f 9a 89 p.?.........<...
    000000000114fec8 00 00 04 00 9f 09 00 00 - dc 6b 82 89 ff ff 99 00 .........k......
    000000000114fed8 10 6b 82 89 00 00 00 00 - 00 00 00 00 00 00 00 00 .k..............
    000000000114fee8 00 00 00 00 1f 00 00 00 - ff ff ff ff 40 f5 df ff ............@...
    000000000114fef8 00 00 00 00 10 64 6e 80 - 64 5e 8e 89 28 ac 43 ac .....dn.d^..(.C.
    000000000114ff08 00 00 00 00 27 64 6e 80 - 08 00 00 00 46 02 00 00 ....'dn.....F...
    000000000114ff18 58 38 50 80 38 5d 8e 89 - c8 5c 8e 89 68 b0 4f 80 X8P.8]...\..h.O.
    000000000114ff28 34 5e 8e 89 80 ff 14 01 - ae df e7 77 48 ff 14 01 4^.........wH...
    000000000114ff38 be df e7 77 e0 10 90 7c - a8 c0 f6 00 28 cf f6 00 ...w...|....(...
    000000000114ff48 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff ../M.....]......

    *----> State Dump for Thread Id 0x450 <----*

    eax=00000001 ebx=0129fce8 ecx=0129fd78 edx=7c90e4f4 esi=00000000 edi=7ffdf000
    eip=7c90e4f4 esp=0129fcc0 ebp=0129fd5c iopl=0 nv up ei pl zr na po nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

    function: ntdll!KiFastSystemCallRet
    7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
    7c90e4df 8b0424 mov eax,[esp]
    7c90e4e2 8be5 mov esp,ebp
    7c90e4e4 5d pop ebp
    7c90e4e5 c3 ret
    7c90e4e6 8da42400000000 lea esp,[esp]
    7c90e4ed 8d4900 lea ecx,[ecx]
    ntdll!KiFastSystemCall:
    7c90e4f0 8bd4 mov edx,esp
    7c90e4f2 0f34 sysenter
    ntdll!KiFastSystemCallRet:
    7c90e4f4 c3 ret
    7c90e4f5 8da42400000000 lea esp,[esp]
    7c90e4fc 8d642400 lea esp,[esp]
    ntdll!KiIntSystemCall:
    7c90e500 8d542408 lea edx,[esp+0x8]
    7c90e504 cd2e int 2e
    7c90e506 c3 ret
    7c90e507 90 nop
    ntdll!RtlRaiseException:
    7c90e508 55 push ebp
    7c90e509 8bec mov ebp,esp

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be wrong.
    *** WARNING: Unable to verify checksum for C:\WINDOWS\system32\Ati2evxx.dll
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\Ati2evxx.dll -
    ChildEBP RetAddr Args to Child
    0129fd5c 7c80a105 00000002 0129fda0 00000000 ntdll!KiFastSystemCallRet
    0129fd78 10002e30 00000002 0129fda0 00000000 kernel32!WaitForMultipleObjects+0x18
    7c80a0cb 0875ffec 14a015ff c0857c80 fed48c0f Ati2evxx+0x2e30
    8b55ff8b 00000000 00000000 00000000 00000000 0x875ffec

    *----> Raw Stack Dump <----*
    000000000129fcc0 2c df 90 7c 74 95 80 7c - 02 00 00 00 e8 fc 29 01 ,..|t..|......).
    000000000129fcd0 01 00 00 00 00 00 00 00 - 00 00 00 00 b0 ff 29 01 ..............).
    000000000129fce0 00 00 00 00 01 00 00 00 - 48 09 00 00 94 06 00 00 ........H.......
    000000000129fcf0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    000000000129fd00 00 00 00 00 00 00 00 00 - 14 00 00 00 01 00 00 00 ................
    000000000129fd10 00 00 00 00 00 00 00 00 - 10 00 00 00 b0 ff 29 01 ..............).
    000000000129fd20 00 00 00 00 01 00 00 00 - 00 f0 fd 7f 00 b0 fa 7f ................
    000000000129fd30 00 00 00 00 00 00 00 00 - e8 fc 29 01 00 00 00 00 ..........).....
    000000000129fd40 02 00 00 00 dc fc 29 01 - ec d7 90 7c dc ff 29 01 ......)....|..).
    000000000129fd50 c0 9a 83 7c 68 96 80 7c - 00 00 00 00 78 fd 29 01 ...|h..|....x.).
    000000000129fd60 05 a1 80 7c 02 00 00 00 - a0 fd 29 01 00 00 00 00 ...|......).....
    000000000129fd70 ff ff ff ff 00 00 00 00 - cb a0 80 7c 30 2e 00 10 ...........|0...
    000000000129fd80 02 00 00 00 a0 fd 29 01 - 00 00 00 00 ff ff ff ff ......).........
    000000000129fd90 ff ff ff ff 58 2d 91 7c - b4 ff 29 01 00 00 00 00 ....X-.|..).....
    000000000129fda0 48 09 00 00 94 06 00 00 - 04 00 01 40 03 01 00 00 H..........@....
    000000000129fdb0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    000000000129fdc0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    000000000129fdd0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    000000000129fde0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    000000000129fdf0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

    *----> State Dump for Thread Id 0x454 <----*

    eax=0016240e ebx=7c80a0a7 ecx=00000022 edx=0230000f esi=00000000 edi=012dff64
    eip=7c90e4f4 esp=012dff34 ebp=012dff8c iopl=0 nv up ei pl nz na pe nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202

    function: ntdll!KiFastSystemCallRet
    7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
    7c90e4df 8b0424 mov eax,[esp]
    7c90e4e2 8be5 mov esp,ebp
    7c90e4e4 5d pop ebp
    7c90e4e5 c3 ret
    7c90e4e6 8da42400000000 lea esp,[esp]
    7c90e4ed 8d4900 lea ecx,[ecx]
    ntdll!KiFastSystemCall:
    7c90e4f0 8bd4 mov edx,esp
    7c90e4f2 0f34 sysenter
    ntdll!KiFastSystemCallRet:
    7c90e4f4 c3 ret
    7c90e4f5 8da42400000000 lea esp,[esp]
    7c90e4fc 8d642400 lea esp,[esp]
    ntdll!KiIntSystemCall:
    7c90e500 8d542408 lea edx,[esp+0x8]
    7c90e504 cd2e int 2e
    7c90e506 c3 ret
    7c90e507 90 nop
    ntdll!RtlRaiseException:
    7c90e508 55 push ebp
    7c90e509 8bec mov ebp,esp

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be wrong.
    ChildEBP RetAddr Args to Child
    012dff8c 7c802455 00001388 00000000 7c809bd7 ntdll!KiFastSystemCallRet
    012dff9c 10001564 00001388 ffffffff 7c912d58 kernel32!Sleep+0xf
    7c809bd7 18a164ec 8b000000 458b3048 f4f88308 Ati2evxx+0x1564
    8b55ff8b 00000000 00000000 00000000 00000000 0x18a164ec

    *----> Raw Stack Dump <----*
    00000000012dff34 fc d1 90 7c f1 23 80 7c - 00 00 00 00 64 ff 2d 01 ...|.#.|....d.-.
    00000000012dff44 9c 32 81 7c 58 2d 91 7c - a7 a0 80 7c 14 00 00 00 .2.|X-.|...|....
    00000000012dff54 01 00 00 00 00 00 00 00 - 00 00 00 00 10 00 00 00 ................
    00000000012dff64 80 0f 05 fd ff ff ff ff - 00 00 00 00 64 ff 2d 01 ............d.-.
    00000000012dff74 44 ff 2d 01 00 00 00 00 - dc ff 2d 01 c0 9a 83 7c D.-.......-....|
    00000000012dff84 60 24 80 7c 00 00 00 00 - 9c ff 2d 01 55 24 80 7c `$.|......-.U$.|
    00000000012dff94 88 13 00 00 00 00 00 00 - d7 9b 80 7c 64 15 00 10 ...........|d...
    00000000012dffa4 88 13 00 00 ff ff ff ff - 58 2d 91 7c ec ff 2d 01 ........X-.|..-.
    00000000012dffb4 00 00 00 00 13 b7 80 7c - 00 00 00 00 ff ff ff ff .......|........
    00000000012dffc4 58 2d 91 7c 00 00 00 00 - 00 a0 fa 7f 00 86 64 8a X-.|..........d.
    00000000012dffd4 c0 ff 2d 01 58 62 82 89 - ff ff ff ff c0 9a 83 7c ..-.Xb.........|
    00000000012dffe4 20 b7 80 7c 00 00 00 00 - 00 00 00 00 00 00 00 00 ..|............
    00000000012dfff4 00 15 00 10 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    00000000012e0004 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    00000000012e0014 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    00000000012e0024 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    00000000012e0034 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    00000000012e0044 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    00000000012e0054 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    00000000012e0064 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

    *----> State Dump for Thread Id 0x45c <----*

    eax=0131fe08 ebx=0131fe78 ecx=00000001 edx=0000008d esi=00000000 edi=7ffdf000
    eip=7c90e4f4 esp=0131fe50 ebp=0131feec iopl=0 nv up ei pl zr na po nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

    function: ntdll!KiFastSystemCallRet
    7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
    7c90e4df 8b0424 mov eax,[esp]
    7c90e4e2 8be5 mov esp,ebp
    7c90e4e4 5d pop ebp
    7c90e4e5 c3 ret
    7c90e4e6 8da42400000000 lea esp,[esp]
    7c90e4ed 8d4900 lea ecx,[ecx]
    ntdll!KiFastSystemCall:
    7c90e4f0 8bd4 mov edx,esp
    7c90e4f2 0f34 sysenter
    ntdll!KiFastSystemCallRet:
    7c90e4f4 c3 ret
    7c90e4f5 8da42400000000 lea esp,[esp]
    7c90e4fc 8d642400 lea esp,[esp]
    ntdll!KiIntSystemCall:
    7c90e500 8d542408 lea edx,[esp+0x8]
    7c90e504 cd2e int 2e
    7c90e506 c3 ret
    7c90e507 90 nop
    ntdll!RtlRaiseException:
    7c90e508 55 push ebp
    7c90e509 8bec mov ebp,esp

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be wrong.
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\cscdll.dll -
    ChildEBP RetAddr Args to Child
    0131feec 7c80a105 00000004 0131ff2c 00000000 ntdll!KiFastSystemCallRet
    0131ff08 76601fb9 00000004 0131ff2c 00000000 kernel32!WaitForMultipleObjects+0x18
    0131ff3c 76603267 0009b52b 00097207 00000000 cscdll!WinlogonStartShellEvent+0x13f
    0131ff54 7660323b 00000000 01039f18 0131ff74 cscdll!MprServiceProc+0x1b
    0131ffb4 7c80b713 00f77850 0006fb74 00000023 cscdll!WinlogonStartupEvent+0x40
    0131ffec 00000000 01039e58 00f77850 00000000 kernel32!GetModuleFileNameA+0x1b4

    *----> Raw Stack Dump <----*
    000000000131fe50 2c df 90 7c 74 95 80 7c - 04 00 00 00 78 fe 31 01 ,..|t..|....x.1.
    000000000131fe60 01 00 00 00 00 00 00 00 - 00 00 00 00 6b 8d 00 00 ............k...
    000000000131fe70 01 00 00 00 2e 93 80 7c - 10 01 00 00 d4 06 00 00 .......|........
    000000000131fe80 d8 06 00 00 e0 06 00 00 - 40 0b 81 7c ff ff ff ff ........@..|....
    000000000131fe90 98 16 80 7c dc cf 90 7c - 14 00 00 00 01 00 00 00 ...|...|........
    000000000131fea0 00 00 00 00 00 00 00 00 - 10 00 00 00 c4 fe 31 01 ..............1.
    000000000131feb0 44 22 60 76 b8 06 00 00 - 00 f0 fd 7f 00 90 fa 7f D"`v............
    000000000131fec0 2e 93 80 7c 00 00 00 00 - 78 fe 31 01 01 00 00 00 ...|....x.1.....
    000000000131fed0 04 00 00 00 6c fe 31 01 - 00 01 00 00 a4 ff 31 01 ....l.1.......1.
    000000000131fee0 c0 9a 83 7c 68 96 80 7c - 00 00 00 00 08 ff 31 01 ...|h..|......1.
    000000000131fef0 05 a1 80 7c 04 00 00 00 - 2c ff 31 01 00 00 00 00 ...|....,.1.....
    000000000131ff00 ff ff ff ff 00 00 00 00 - 3c ff 31 01 b9 1f 60 76 ........<.1...`v
    000000000131ff10 04 00 00 00 2c ff 31 01 - 00 00 00 00 ff ff ff ff ....,.1.........
    000000000131ff20 50 78 f7 00 00 00 00 00 - a8 c5 07 00 10 01 00 00 Px..............
    000000000131ff30 d4 06 00 00 d8 06 00 00 - e0 06 00 00 54 ff 31 01 ............T.1.
    000000000131ff40 67 32 60 76 2b b5 09 00 - 07 72 09 00 00 00 00 00 g2`v+....r......
    000000000131ff50 05 00 00 00 b4 ff 31 01 - 3b 32 60 76 00 00 00 00 ......1.;2`v....
    000000000131ff60 18 9f 03 01 74 ff 31 01 - 74 fb 06 00 23 00 00 00 ....t.1.t...#...
    000000000131ff70 50 78 f7 00 20 00 00 00 - 00 00 00 00 00 00 00 00 Px.. ...........
    000000000131ff80 00 00 00 00 80 c6 07 00 - 00 00 00 00 b8 00 00 00 ................

    *----> State Dump for Thread Id 0x464 <----*

    eax=76602d3c ebx=013dfee8 ecx=00173d70 edx=00000002 esi=00000000 edi=7ffdf000
    eip=7c90e4f4 esp=013dfec0 ebp=013dff5c iopl=0 nv up ei pl zr na po nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

    function: ntdll!KiFastSystemCallRet
    7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
    7c90e4df 8b0424 mov eax,[esp]
    7c90e4e2 8be5 mov esp,ebp
    7c90e4e4 5d pop ebp
    7c90e4e5 c3 ret
    7c90e4e6 8da42400000000 lea esp,[esp]
    7c90e4ed 8d4900 lea ecx,[ecx]
    ntdll!KiFastSystemCall:
    7c90e4f0 8bd4 mov edx,esp
    7c90e4f2 0f34 sysenter
    ntdll!KiFastSystemCallRet:
    7c90e4f4 c3 ret
    7c90e4f5 8da42400000000 lea esp,[esp]
    7c90e4fc 8d642400 lea esp,[esp]
    ntdll!KiIntSystemCall:
    7c90e500 8d542408 lea edx,[esp+0x8]
    7c90e504 cd2e int 2e
    7c90e506 c3 ret
    7c90e507 90 nop
    ntdll!RtlRaiseException:
    7c90e508 55 push ebp
    7c90e509 8bec mov ebp,esp

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be wrong.
    ChildEBP RetAddr Args to Child
    013dff5c 7c80a105 00000002 013dff9c 00000000 ntdll!KiFastSystemCallRet
    013dff78 76602da8 00000002 013dff9c 00000000 kernel32!WaitForMultipleObjects+0x18
    013dffb4 7c80b713 00000000 00000001 774fd159 cscdll!WinlogonLogonEvent+0x972
    013dffec 00000000 76602d3c 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

    *----> Raw Stack Dump <----*
    00000000013dfec0 2c df 90 7c 74 95 80 7c - 02 00 00 00 e8 fe 3d 01 ,..|t..|......=.
    00000000013dfed0 01 00 00 00 00 00 00 00 - 00 00 00 00 01 00 00 00 ................
    00000000013dfee0 00 00 00 00 4c 32 61 76 - e4 06 00 00 d0 06 00 00 ....L2av........
    00000000013dfef0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    00000000013dff00 00 00 00 00 00 00 00 00 - 14 00 00 00 01 00 00 00 ................
    00000000013dff10 00 00 00 00 00 00 00 00 - 10 00 00 00 00 00 00 00 ................
    00000000013dff20 00 00 00 00 00 00 00 00 - 00 f0 fd 7f 00 70 fa 7f .............p..
    00000000013dff30 00 00 00 00 00 00 00 00 - e8 fe 3d 01 00 00 00 00 ..........=.....
    00000000013dff40 02 00 00 00 dc fe 3d 01 - 00 00 00 00 dc ff 3d 01 ......=.......=.
    00000000013dff50 c0 9a 83 7c 68 96 80 7c - 00 00 00 00 78 ff 3d 01 ...|h..|....x.=.
    00000000013dff60 05 a1 80 7c 02 00 00 00 - 9c ff 3d 01 00 00 00 00 ...|......=.....
    00000000013dff70 ff ff ff ff 00 00 00 00 - b4 ff 3d 01 a8 2d 60 76 ..........=..-`v
    00000000013dff80 02 00 00 00 9c ff 3d 01 - 00 00 00 00 ff ff ff ff ......=.........
    00000000013dff90 01 00 00 00 59 d1 4f 77 - 00 00 00 00 e4 06 00 00 ....Y.Ow........
    00000000013dffa0 d0 06 00 00 07 72 09 00 - 00 00 00 00 ff ff 00 00 .....r..........
    00000000013dffb0 00 00 00 00 ec ff 3d 01 - 13 b7 80 7c 00 00 00 00 ......=....|....
    00000000013dffc0 01 00 00 00 59 d1 4f 77 - 00 00 00 00 00 70 fa 7f ....Y.Ow.....p..
    00000000013dffd0 00 a6 64 8a c0 ff 3d 01 - 68 d1 a8 89 ff ff ff ff ..d...=.h.......
    00000000013dffe0 c0 9a 83 7c 20 b7 80 7c - 00 00 00 00 00 00 00 00 ...| ..|........
    00000000013dfff0 00 00 00 00 3c 2d 60 76 - 00 00 00 00 00 00 00 00 ....<-`v........

    *----> State Dump for Thread Id 0x488 <----*

    eax=00000001 ebx=00000000 ecx=0121fe4c edx=7c90e4f4 esi=7c97b420 edi=7c97b440
    eip=7c90e4f4 esp=0121ff70 ebp=0121ffb4 iopl=0 nv up ei ng nz na po nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000286

    function: ntdll!KiFastSystemCallRet
    7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
    7c90e4df 8b0424 mov eax,[esp]
    7c90e4e2 8be5 mov esp,ebp
    7c90e4e4 5d pop ebp
    7c90e4e5 c3 ret
    7c90e4e6 8da42400000000 lea esp,[esp]
    7c90e4ed 8d4900 lea ecx,[ecx]
    ntdll!KiFastSystemCall:
    7c90e4f0 8bd4 mov edx,esp
    7c90e4f2 0f34 sysenter
    ntdll!KiFastSystemCallRet:
    7c90e4f4 c3 ret
    7c90e4f5 8da42400000000 lea esp,[esp]
    7c90e4fc 8d642400 lea esp,[esp]
    ntdll!KiIntSystemCall:
    7c90e500 8d542408 lea edx,[esp+0x8]
    7c90e504 cd2e int 2e
    7c90e506 c3 ret
    7c90e507 90 nop
    ntdll!RtlRaiseException:
    7c90e508 55 push ebp
    7c90e509 8bec mov ebp,esp

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be wrong.
    ChildEBP RetAddr Args to Child
    0121ffb4 7c80b713 00000000 00000001 0006ef40 ntdll!KiFastSystemCallRet
    0121ffec 00000000 7c910230 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

    *----> Raw Stack Dump <----*
    000000000121ff70 2c da 90 7c 6d 02 91 7c - 78 01 00 00 ac ff 21 01 ,..|m..|x.....!.
    000000000121ff80 b0 ff 21 01 98 ff 21 01 - a0 ff 21 01 01 00 00 00 ..!...!...!.....
    000000000121ff90 40 ef 06 00 00 00 00 00 - 00 00 00 00 a0 b0 07 00 @...............
    000000000121ffa0 00 7c 28 e8 ff ff ff ff - a0 1c 08 a6 c9 7a 92 7c .|(..........z.|
    000000000121ffb0 68 f9 f8 00 ec ff 21 01 - 13 b7 80 7c 00 00 00 00 h.....!....|....
    000000000121ffc0 01 00 00 00 40 ef 06 00 - 00 00 00 00 00 d0 fa 7f ....@...........
    000000000121ffd0 00 a6 64 8a c0 ff 21 01 - f8 4d a8 89 ff ff ff ff ..d...!..M......
    000000000121ffe0 c0 9a 83 7c 20 b7 80 7c - 00 00 00 00 00 00 00 00 ...| ..|........
    000000000121fff0 00 00 00 00 30 02 91 7c - 00 00 00 00 00 00 00 00 ....0..|........
    0000000001220000 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000001220010 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000001220020 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000001220030 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000001220040 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000001220050 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000001220060 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000001220070 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000001220080 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000001220090 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    00000000012200a0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

    *----> State Dump for Thread Id 0x624 <----*

    eax=769c8761 ebx=011dfef4 ecx=77de6568 edx=0125f864 esi=00000000 edi=7ffdf000
    eip=7c90e4f4 esp=011dfecc ebp=011dff68 iopl=0 nv up ei pl zr na po nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

    function: ntdll!KiFastSystemCallRet
    7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
    7c90e4df 8b0424 mov eax,[esp]
    7c90e4e2 8be5 mov esp,ebp
    7c90e4e4 5d pop ebp
    7c90e4e5 c3 ret
    7c90e4e6 8da42400000000 lea esp,[esp]
    7c90e4ed 8d4900 lea ecx,[ecx]
    ntdll!KiFastSystemCall:
    7c90e4f0 8bd4 mov edx,esp
    7c90e4f2 0f34 sysenter
    ntdll!KiFastSystemCallRet:
    7c90e4f4 c3 ret
    7c90e4f5 8da42400000000 lea esp,[esp]
    7c90e4fc 8d642400 lea esp,[esp]
    ntdll!KiIntSystemCall:
    7c90e500 8d542408 lea edx,[esp+0x8]
    7c90e504 cd2e int 2e
    7c90e506 c3 ret
    7c90e507 90 nop
    ntdll!RtlRaiseException:
    7c90e508 55 push ebp
    7c90e509 8bec mov ebp,esp

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be wrong.
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\USERENV.dll -
    ChildEBP RetAddr Args to Child
    011dff68 7c80a105 00000003 76a61348 00000000 ntdll!KiFastSystemCallRet
    011dff84 769c87bd 00000003 76a61348 00000000 kernel32!WaitForMultipleObjects+0x18
    011dffb4 7c80b713 00000000 00000000 0125f85c USERENV!RegisterGPNotification+0x1b6
    011dffec 00000000 769c8761 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

    *----> Raw Stack Dump <----*
    00000000011dfecc 2c df 90 7c 74 95 80 7c - 03 00 00 00 f4 fe 1d 01 ,..|t..|........
    00000000011dfedc 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    00000000011dfeec f0 13 a6 76 d7 9b 80 7c - 64 06 00 00 34 01 00 00 ...v...|d...4...
    00000000011dfefc 38 08 00 00 5c fe 1d 01 - 6c ff 1d 01 6c ff 1d 01 8...\...l...l...
    00000000011dff0c 00 e9 90 7c 40 00 91 7c - 14 00 00 00 01 00 00 00 ...|@..|........
    00000000011dff1c 00 00 00 00 00 00 00 00 - 10 00 00 00 fa 1b 80 7c ...............|
    00000000011dff2c 00 00 00 00 5c f8 25 01 - 00 f0 fd 7f 00 e0 fa 7f ....\.%.........
    00000000011dff3c c0 79 f7 00 00 00 00 00 - f4 fe 1d 01 00 00 00 00 .y..............
    00000000011dff4c 03 00 00 00 e8 fe 1d 01 - 00 00 00 00 dc ff 1d 01 ................
    00000000011dff5c c0 9a 83 7c 68 96 80 7c - 00 00 00 00 84 ff 1d 01 ...|h..|........
    00000000011dff6c 05 a1 80 7c 03 00 00 00 - 48 13 a6 76 00 00 00 00 ...|....H..v....
    00000000011dff7c ff ff ff ff 00 00 00 00 - b4 ff 1d 01 bd 87 9c 76 ...............v
    00000000011dff8c 03 00 00 00 48 13 a6 76 - 00 00 00 00 ff ff ff ff ....H..v........
    00000000011dff9c 00 00 00 00 5c f8 25 01 - 00 00 00 00 00 00 9c 76 ....\.%........v
    00000000011dffac 03 00 00 00 00 00 00 00 - ec ff 1d 01 13 b7 80 7c ...............|
    00000000011dffbc 00 00 00 00 00 00 00 00 - 5c f8 25 01 00 00 00 00 ........\.%.....
    00000000011dffcc 00 e0 fa 7f 30 94 10 e2 - c0 ff 1d 01 b0 a2 83 89 ....0...........
    00000000011dffdc ff ff ff ff c0 9a 83 7c - 20 b7 80 7c 00 00 00 00 .......| ..|....
    00000000011dffec 00 00 00 00 00 00 00 00 - 61 87 9c 76 00 00 00 00 ........a..v....
    00000000011dfffc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

    *----> State Dump for Thread Id 0x628 <----*

    eax=0167ff38 ebx=0167fe28 ecx=00000130 edx=00000037 esi=00000000 edi=7ffdf000
    eip=7c90e4f4 esp=0167fe00 ebp=0167fe9c iopl=0 nv up ei pl zr na po nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

    function: ntdll!KiFastSystemCallRet
    7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
    7c90e4df 8b0424 mov eax,[esp]
    7c90e4e2 8be5 mov esp,ebp
    7c90e4e4 5d pop ebp
    7c90e4e5 c3 ret
    7c90e4e6 8da42400000000 lea esp,[esp]
    7c90e4ed 8d4900 lea ecx,[ecx]
    ntdll!KiFastSystemCall:
    7c90e4f0 8bd4 mov edx,esp
    7c90e4f2 0f34 sysenter
    ntdll!KiFastSystemCallRet:
    7c90e4f4 c3 ret
    7c90e4f5 8da42400000000 lea esp,[esp]
    7c90e4fc 8d642400 lea esp,[esp]
    ntdll!KiIntSystemCall:
    7c90e500 8d542408 lea edx,[esp+0x8]
    7c90e504 cd2e int 2e
    7c90e506 c3 ret
    7c90e507 90 nop
    ntdll!RtlRaiseException:
    7c90e508 55 push ebp
    7c90e509 8bec mov ebp,esp

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be wrong.
    ChildEBP RetAddr Args to Child
    0167fe9c 7c80a105 00000004 0167ff0c 00000000 ntdll!KiFastSystemCallRet
    0167feb8 769d3df2 00000004 0167ff0c 00000000 kernel32!WaitForMultipleObjects+0x18
    0167ffb4 7c80b713 00f84278 00070000 7c910202 USERENV!Ordinal147+0x257
    0167ffec 00000000 769d3c11 00f84278 00000000 kernel32!GetModuleFileNameA+0x1b4

    *----> Raw Stack Dump <----*
    000000000167fe00 2c df 90 7c 74 95 80 7c - 04 00 00 00 28 fe 67 01 ,..|t..|....(.g.
    000000000167fe10 01 00 00 00 00 00 00 00 - 00 00 00 00 01 fe 90 7c ...............|
    000000000167fe20 78 42 f8 00 00 00 00 00 - 54 06 00 00 3c 08 00 00 xB......T...<...
    000000000167fe30 40 07 00 00 a8 07 00 00 - a4 fe 67 01 b9 ab 41 7e @.........g...A~
    000000000167fe40 7e ff 67 01 7e ff 67 01 - 14 00 00 00 01 00 00 00 ~.g.~.g.........
    000000000167fe50 00 00 00 00 00 00 00 00 - 10 00 00 00 00 00 00 00 ................
    000000000167fe60 3c aa 41 7e 00 00 00 00 - 00 f0 fd 7f 00 30 fa 7f <.A~.........0..
    000000000167fe70 00 00 00 00 00 00 00 00 - 28 fe 67 01 8c dd 90 7c ........(.g....|
    000000000167fe80 04 00 00 00 1c fe 67 01 - e0 fe 67 01 dc ff 67 01 ......g...g...g.
    000000000167fe90 c0 9a 83 7c 68 96 80 7c - 00 00 00 00 b8 fe 67 01 ...|h..|......g.
    000000000167fea0 05 a1 80 7c 04 00 00 00 - 0c ff 67 01 00 00 00 00 ...|......g.....
    000000000167feb0 ff ff ff ff 00 00 00 00 - b4 ff 67 01 f2 3d 9d 76 ..........g..=.v
    000000000167fec0 04 00 00 00 0c ff 67 01 - 00 00 00 00 ff ff ff ff ......g.........
    000000000167fed0 00 00 07 00 02 02 91 7c - 78 42 f8 00 b0 9a 53 80 .......|xB....S.
    000000000167fee0 00 06 89 ba f2 ff ff ff - 00 00 9c 76 74 13 a6 76 ...........vt..v
    000000000167fef0 ff ff ff ff 40 05 b4 ba - 00 00 00 00 10 64 6e 80 ....@........dn.
    000000000167ff00 8c 18 88 89 28 3c c4 a2 - 00 00 00 00 54 06 00 00 ....(<......T...
    000000000167ff10 3c 08 00 00 40 07 00 00 - a8 07 00 00 60 17 88 89 <...@.......`...
    000000000167ff20 00 00 00 00 68 b0 4f 80 - e0 93 04 00 a0 f9 56 00 ....h.O.......V.
    000000000167ff30 24 17 88 89 00 00 00 00 - 75 00 73 00 65 00 72 00 $.......u.s.e.r.

    *----> State Dump for Thread Id 0x780 <----*

    eax=00048ede ebx=00000000 ecx=00f75548 edx=000006f8 esi=00f75548 edi=00f755ec
    eip=7c90e4f4 esp=0170fe18 ebp=0170ff80 iopl=0 nv up ei pl zr na po nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

    function: ntdll!KiFastSystemCallRet
    7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
    7c90e4df 8b0424 mov eax,[esp]
    7c90e4e2 8be5 mov esp,ebp
    7c90e4e4 5d pop ebp
    7c90e4e5 c3 ret
    7c90e4e6 8da42400000000 lea esp,[esp]
    7c90e4ed 8d4900 lea ecx,[ecx]
    ntdll!KiFastSystemCall:
    7c90e4f0 8bd4 mov edx,esp
    7c90e4f2 0f34 sysenter
    ntdll!KiFastSystemCallRet:
    7c90e4f4 c3 ret
    7c90e4f5 8da42400000000 lea esp,[esp]
    7c90e4fc 8d642400 lea esp,[esp]
    ntdll!KiIntSystemCall:
    7c90e500 8d542408 lea edx,[esp+0x8]
    7c90e504 cd2e int 2e
    7c90e506 c3 ret
    7c90e507 90 nop
    ntdll!RtlRaiseException:
    7c90e508 55 push ebp
    7c90e509 8bec mov ebp,esp

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be wrong.
    ChildEBP RetAddr Args to Child
    0170ff80 77e76caf 0170ffa8 77e76ad1 00f75548 ntdll!KiFastSystemCallRet
    0170ff88 77e76ad1 00f75548 00000000 00000000 RPCRT4!I_RpcBCacheFree+0x61c
    0170ffa8 77e76c97 00082378 0170ffec 7c80b713 RPCRT4!I_RpcBCacheFree+0x43e
    0170ffb4 7c80b713 00f8a980 00000000 00000000 RPCRT4!I_RpcBCacheFree+0x604
    0170ffec 00000000 77e76c7d 00f8a980 00000000 kernel32!GetModuleFileNameA+0x1b4

    *----> Raw Stack Dump <----*
    000000000170fe18 8c da 90 7c e3 65 e7 77 - dc 08 00 00 74 ff 70 01 ...|.e.w....t.p.
    000000000170fe28 00 00 00 00 60 f8 f8 00 - 50 ff 70 01 ff ff ff 03 ....`...P.p.....
    000000000170fe38 ff ff ff 03 d4 57 f9 81 - 00 00 00 00 fc 3c 88 c0 .....W.......<..
    000000000170fe48 d8 9b 8f 89 40 05 b4 ba - 00 00 00 00 62 b5 4f 80 ....@.......b.O.
    000000000170fe58 94 bb bd a2 f8 fc 3f c0 - 00 e0 f9 7f 00 00 00 00 ......?.........
    000000000170fe68 f0 fc 3f 02 70 bb bd a2 - 9b 38 52 80 00 e0 f9 7f ..?.p....8R.....
    000000000170fe78 01 00 00 00 00 00 00 00 - f0 fc 3f c0 00 00 00 00 ..........?.....
    000000000170fe88 00 00 00 00 f8 1f 60 c0 - 30 bc bd a2 fa 3f 52 80 ......`.0....?R.
    000000000170fe98 94 bb bd a2 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    000000000170fea8 38 93 ac 89 e0 99 8f 89 - 01 9a 8f 89 00 00 00 00 8...............
    000000000170feb8 f0 fc 3f c0 68 2c 85 89 - 00 00 00 00 01 00 00 00 ..?.h,..........
    000000000170fec8 00 00 04 00 4f 13 00 00 - ac 9a 8f 89 ff ff 34 01 ....O.........4.
    000000000170fed8 e0 99 8f 89 00 00 00 00 - 43 23 50 80 00 00 35 01 ........C#P...5.
    000000000170fee8 50 bb bd a2 2c d6 e2 15 - ff ff ff ff 00 e0 f9 7f P...,...........
    000000000170fef8 60 9e 4d 80 ff ff ff ff - 4a 36 5b 80 1c 16 54 80 `.M.....J6[...T.
    000000000170ff08 ff ff ff ff d0 bc bd a2 - d4 bc bd a2 00 80 00 00 ................
    000000000170ff18 38 05 b5 ba b4 58 54 80 - 00 6b 2c 89 a4 b1 4f 80 8....XT..k,...O.
    000000000170ff28 34 6d 2c 89 80 ff 70 01 - ae df e7 77 48 ff 70 01 4m,...p....wH.p.
    000000000170ff38 be df e7 77 e0 10 90 7c - e0 9f f9 00 80 a9 f8 00 ...w...|........
    000000000170ff48 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff ../M.....]......

    *----> State Dump for Thread Id 0x1bc <----*

    eax=77e76c7d ebx=00000000 ecx=00000000 edx=00264660 esi=00082ac8 edi=00082b6c
    eip=7c90e4f4 esp=00c7fe18 ebp=00c7ff80 iopl=0 nv up ei pl zr na po nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

    function: ntdll!KiFastSystemCallRet
    7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
    7c90e4df 8b0424 mov eax,[esp]
    7c90e4e2 8be5 mov esp,ebp
    7c90e4e4 5d pop ebp
    7c90e4e5 c3 ret
    7c90e4e6 8da42400000000 lea esp,[esp]
    7c90e4ed 8d4900 lea ecx,[ecx]
    ntdll!KiFastSystemCall:
    7c90e4f0 8bd4 mov edx,esp
    7c90e4f2 0f34 sysenter
    ntdll!KiFastSystemCallRet:
    7c90e4f4 c3 ret
    7c90e4f5 8da42400000000 lea esp,[esp]
    7c90e4fc 8d642400 lea esp,[esp]
    ntdll!KiIntSystemCall:
    7c90e500 8d542408 lea edx,[esp+0x8]
    7c90e504 cd2e int 2e
    7c90e506 c3 ret
    7c90e507 90 nop
    ntdll!RtlRaiseException:
    7c90e508 55 push ebp
    7c90e509 8bec mov ebp,esp

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be wrong.
    ChildEBP RetAddr Args to Child
    00c7ff80 77e76caf 00c7ffa8 77e76ad1 00082ac8 ntdll!KiFastSystemCallRet
    00c7ff88 77e76ad1 00082ac8 00000000 00000000 RPCRT4!I_RpcBCacheFree+0x61c
    00c7ffa8 77e76c97 00082378 00c7ffec 7c80b713 RPCRT4!I_RpcBCacheFree+0x43e
    00c7ffb4 7c80b713 00f71ef8 00000000 00000000 RPCRT4!I_RpcBCacheFree+0x604
    00c7ffec 00000000 77e76c7d 00f71ef8 00000000 kernel32!GetModuleFileNameA+0x1b4

    *----> Raw Stack Dump <----*
    0000000000c7fe18 8c da 90 7c e3 65 e7 77 - 2c 01 00 00 74 ff c7 00 ...|.e.w,...t...
    0000000000c7fe28 00 00 00 00 88 ce f7 00 - 50 ff c7 00 40 ab b6 a2 ........P...@...
    0000000000c7fe38 00 83 64 8a ed b6 54 80 - 16 02 00 00 91 fc 4f 80 ..d...T.......O.
    0000000000c7fe48 08 00 00 00 00 80 f9 7f - 08 00 00 00 30 b5 4f 80 ............0.O.
    0000000000c7fe58 08 00 00 00 08 00 00 00 - 40 05 b4 ba 00 00 00 00 ........@.......
    0000000000c7fe68 62 b5 4f 80 94 ab b6 a2 - c0 fc 3f c0 00 70 f9 7f b.O.......?..p..
    0000000000c7fe78 00 00 00 00 b8 fc 3f 02 - 70 ab b6 a2 9b 38 52 80 ......?.p....8R.
    0000000000c7fe88 00 70 f9 7f 01 00 00 00 - 00 00 00 00 b8 fc 3f c0 .p............?.
    0000000000c7fe98 00 00 00 00 00 00 00 00 - 43 6d 6e 80 28 ac b6 a2 ........Cmn.(...
    0000000000c7fea8 27 64 6e 80 00 0d db ba - 00 00 00 00 43 6d 6e 80 'dn.........Cmn.
    0000000000c7feb8 28 ac b6 a2 27 64 6e 80 - 00 0d db ba 00 00 00 00 (...'dn.........
    0000000000c7fec8 00 00 00 00 b8 fc 3f c0 - 48 2a 92 89 00 00 00 00 ......?.H*......
    0000000000c7fed8 00 00 00 00 00 00 04 00 - 00 00 00 00 00 00 00 00 ................
    0000000000c7fee8 00 00 00 00 1f 00 00 00 - ff ff ff ff 40 05 b4 ba ............@...
    0000000000c7fef8 00 00 00 00 10 64 6e 80 - ac 6b 26 89 28 ac b6 a2 .....dn..k&.(...
    0000000000c7ff08 00 00 00 00 27 64 6e 80 - 08 00 00 00 46 02 00 00 ....'dn.....F...
    0000000000c7ff18 58 38 50 80 80 6a 26 89 - 10 6a 26 89 68 b0 4f 80 X8P..j&..j&.h.O.
    0000000000c7ff28 7c 6b 26 89 80 ff c7 00 - ae df e7 77 48 ff c7 00 |k&........wH...
    0000000000c7ff38 be df e7 77 e0 10 90 7c - 78 f5 f7 00 f8 1e f7 00 ...w...|x.......
    0000000000c7ff48 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff ../M.....]......

    *----> State Dump for Thread Id 0x1c8 <----*

    eax=00000001 ebx=00000000 ecx=7ffa0000 edx=00082774 esi=00082738 edi=00082774
    eip=7c90e4f4 esp=0181fe18 ebp=0181ff80 iopl=0 nv up ei pl zr na po nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

    function: ntdll!KiFastSystemCallRet
    7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
    7c90e4df 8b0424 mov eax,[esp]
    7c90e4e2 8be5 mov esp,ebp
    7c90e4e4 5d pop ebp
    7c90e4e5 c3 ret
    7c90e4e6 8da42400000000 lea esp,[esp]
    7c90e4ed 8d4900 lea ecx,[ecx]
    ntdll!KiFastSystemCall:
    7c90e4f0 8bd4 mov edx,esp
    7c90e4f2 0f34 sysenter
    ntdll!KiFastSystemCallRet:
    7c90e4f4 c3 ret
    7c90e4f5 8da42400000000 lea esp,[esp]
    7c90e4fc 8d642400 lea esp,[esp]
    ntdll!KiIntSystemCall:
    7c90e500 8d542408 lea edx,[esp+0x8]
    7c90e504 cd2e int 2e
    7c90e506 c3 ret
    7c90e507 90 nop
    ntdll!RtlRaiseException:
    7c90e508 55 push ebp
    7c90e509 8bec mov ebp,esp

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be wrong.
    ChildEBP RetAddr Args to Child
    0181ff80 77e76caf 0181ffa8 77e76ad1 00082738 ntdll!KiFastSystemCallRet
    0181ff88 77e76ad1 00082738 00000fa0 00263b01 RPCRT4!I_RpcBCacheFree+0x61c
    0181ffa8 77e76c97 00082378 0181ffec 7c80b713 RPCRT4!I_RpcBCacheFree+0x43e
    0181ffb4 7c80b713 00f84f58 00000fa0 00263b01 RPCRT4!I_RpcBCacheFree+0x604
    0181ffec 00000000 77e76c7d 00f84f58 00000000 kernel32!GetModuleFileNameA+0x1b4

    *----> Raw Stack Dump <----*
    000000000181fe18 8c da 90 7c e3 65 e7 77 - 50 01 00 00 74 ff 81 01 ...|.e.wP...t...
    000000000181fe28 00 00 00 00 38 f8 07 00 - 00 00 00 00 ff ff ff 03 ....8...........
    000000000181fe38 ff ff ff 03 50 bd 37 81 - 00 00 00 00 fc 3c 88 c0 ....P.7......<..
    000000000181fe48 d8 9b 8f 89 40 85 b4 ba - 00 00 00 00 62 b5 4f 80 ....@.......b.O.
    000000000181fe58 94 2b b6 a2 b0 fc 3f c0 - 00 50 f9 7f 00 00 00 00 .+....?..P......
    000000000181fe68 a8 fc 3f 02 70 2b b6 a2 - 9b 38 52 80 00 50 f9 7f ..?.p+...8R..P..
    000000000181fe78 01 00 00 00 00 00 00 00 - a8 fc 3f c0 00 00 00 00 ..........?.....
    000000000181fe88 00 00 00 00 f8 1f 60 c0 - 30 2c b6 a2 fa 3f 52 80 ......`.0,...?R.
    000000000181fe98 94 2b b6 a2 00 00 00 00 - 43 6d 6e 80 28 2c b6 a2 .+......Cmn.(,..
    000000000181fea8 27 64 6e 80 00 0d db ba - 00 00 00 00 00 00 00 00 'dn.............
    000000000181feb8 a8 fc 3f c0 18 c2 2e 89 - 00 00 00 00 00 00 00 00 ..?.............
    000000000181fec8 00 00 04 00 cf 17 00 00 - ac 9a 8f 89 ff ff 7c 01 ..............|.
    000000000181fed8 e0 99 8f 89 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    000000000181fee8 00 00 00 00 1f 00 00 00 - ff ff ff ff 40 05 b5 ba ............@...
    000000000181fef8 00 00 00 00 10 64 6e 80 - 64 ea 96 89 28 2c b6 a2 .....dn.d...(,..
    000000000181ff08 00 00 00 00 27 64 6e 80 - 08 00 00 00 46 02 00 00 ....'dn.....F...
    000000000181ff18 58 38 50 80 38 e9 96 89 - c8 e8 96 89 68 b0 4f 80 X8P.8.......h.O.
    000000000181ff28 34 ea 96 89 80 ff 81 01 - ae df e7 77 48 ff 81 01 4..........wH...
    000000000181ff38 be df e7 77 e0 10 90 7c - b8 cf f6 00 58 4f f8 00 ...w...|....XO..
    000000000181ff48 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff ../M.....]......

    *----> State Dump for Thread Id 0xf64 <----*

    eax=00f85550 ebx=00007530 ecx=e28ac215 edx=0162fba0 esi=00083dc8 edi=00000000
    eip=7c90e4f4 esp=0162feac ebp=0162fed8 iopl=0 nv up ei ng nz ac po cy
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000297

    function: ntdll!KiFastSystemCallRet
    7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
    7c90e4df 8b0424 mov eax,[esp]
    7c90e4e2 8be5 mov esp,ebp
    7c90e4e4 5d pop ebp
    7c90e4e5 c3 ret
    7c90e4e6 8da42400000000 lea esp,[esp]
    7c90e4ed 8d4900 lea ecx,[ecx]
    ntdll!KiFastSystemCall:
    7c90e4f0 8bd4 mov edx,esp
    7c90e4f2 0f34 sysenter
    ntdll!KiFastSystemCallRet:
    7c90e4f4 c3 ret
    7c90e4f5 8da42400000000 lea esp,[esp]
    7c90e4fc 8d642400 lea esp,[esp]
    ntdll!KiIntSystemCall:
    7c90e500 8d542408 lea edx,[esp+0x8]
    7c90e504 cd2e int 2e
    7c90e506 c3 ret
    7c90e507 90 nop
    ntdll!RtlRaiseException:
    7c90e508 55 push ebp
    7c90e509 8bec mov ebp,esp

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be wrong.
    ChildEBP RetAddr Args to Child
    0162fed8 77e7715c 00000184 0162ff10 0162ff00 ntdll!KiFastSystemCallRet
    0162ff14 77e772a0 00007530 0162ff6c 0162ff70 RPCRT4!I_RpcBCacheFree+0xac9
    0162ff80 77e77328 0162ffa8 77e76ad1 00083dc8 RPCRT4!I_RpcBCacheFree+0xc0d
    0162ff88 77e76ad1 00083dc8 ffffffff 7c9101bb RPCRT4!I_RpcBCacheFree+0xc95
    0162ffa8 77e76c97 00082378 0162ffec 7c80b713 RPCRT4!I_RpcBCacheFree+0x43e
    0162ffb4 7c80b713 00f84fe8 ffffffff 7c9101bb RPCRT4!I_RpcBCacheFree+0x604
    0162ffec 00000000 77e76c7d 00f84fe8 00000000 kernel32!GetModuleFileNameA+0x1b4

    *----> Raw Stack Dump <----*
    000000000162feac 2c da 90 7c d6 a7 80 7c - 84 01 00 00 00 ff 62 01 ,..|...|......b.
    000000000162febc f0 fe 62 01 d0 fe 62 01 - c8 fe 62 01 00 5d 1e ee ..b...b...b..]..
    000000000162fecc ff ff ff ff bc 55 08 00 - 00 00 00 00 14 ff 62 01 .....U........b.
    000000000162fedc 5c 71 e7 77 84 01 00 00 - 10 ff 62 01 00 ff 62 01 \q.w......b...b.
    000000000162feec 08 ff 62 01 30 75 00 00 - 0a 98 80 7c c8 3d 08 00 ..b.0u.....|.=..
    000000000162fefc d0 3f 08 00 14 ff 62 01 - 84 01 00 00 00 00 00 00 .?....b.........
    000000000162ff0c 38 4b f8 00 60 00 00 00 - 80 ff 62 01 a0 72 e7 77 8K..`.....b..r.w
    000000000162ff1c 30 75 00 00 6c ff 62 01 - 70 ff 62 01 78 ff 62 01 0u..l.b.p.b.x.b.
    000000000162ff2c 64 ff 62 01 68 ff 62 01 - 74 ff 62 01 e0 10 90 7c d.b.h.b.t.b....|
    000000000162ff3c f8 82 f8 00 e8 4f f8 00 - e8 4f f8 00 84 01 00 00 .....O...O......
    000000000162ff4c 00 00 00 00 01 00 00 00 - 00 00 00 00 05 00 00 00 ................
    000000000162ff5c 00 00 00 00 30 75 00 00 - 60 00 00 00 00 00 00 00 ....0u..`.......
    000000000162ff6c 00 00 00 00 00 00 00 00 - 60 00 00 00 84 01 00 00 ........`.......
    000000000162ff7c 00 00 00 00 88 ff 62 01 - 28 73 e7 77 a8 ff 62 01 ......b.(s.w..b.
    000000000162ff8c d1 6a e7 77 c8 3d 08 00 - ff ff ff ff bb 01 91 7c .j.w.=.........|
    000000000162ff9c e8 4f f8 00 e8 4f f8 00 - e8 4f f8 00 b4 ff 62 01 .O...O...O....b.
    000000000162ffac 97 6c e7 77 78 23 08 00 - ec ff 62 01 13 b7 80 7c .l.wx#....b....|
    000000000162ffbc e8 4f f8 00 ff ff ff ff - bb 01 91 7c e8 4f f8 00 .O.........|.O..
    000000000162ffcc 00 50 fa 7f 00 66 64 8a - c0 ff 62 01 68 03 20 89 .P...fd...b.h. .
    000000000162ffdc ff ff ff ff c0 9a 83 7c - 20 b7 80 7c 00 00 00 00 .......| ..|....

    *----> State Dump for Thread Id 0xd40 <----*

    eax=774fe43b ebx=00007530 ecx=0185edec edx=00070000 esi=00000000 edi=01b6ff50
    eip=7c90e4f4 esp=01b6ff20 ebp=01b6ff78 iopl=0 nv up ei pl nz na po nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000206

    function: ntdll!KiFastSystemCallRet
    7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
    7c90e4df 8b0424 mov eax,[esp]
    7c90e4e2 8be5 mov esp,ebp
    7c90e4e4 5d pop ebp
    7c90e4e5 c3 ret
    7c90e4e6 8da42400000000 lea esp,[esp]
    7c90e4ed 8d4900 lea ecx,[ecx]
    ntdll!KiFastSystemCall:
    7c90e4f0 8bd4 mov edx,esp
    7c90e4f2 0f34 sysenter
    ntdll!KiFastSystemCallRet:
    7c90e4f4 c3 ret
    7c90e4f5 8da42400000000 lea esp,[esp]
    7c90e4fc 8d642400 lea esp,[esp]
    ntdll!KiIntSystemCall:
    7c90e500 8d542408 lea edx,[esp+0x8]
    7c90e504 cd2e int 2e
    7c90e506 c3 ret
    7c90e507 90 nop
    ntdll!RtlRaiseException:
    7c90e508 55 push ebp
    7c90e509 8bec mov ebp,esp

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be wrong.
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\ole32.dll -
    ChildEBP RetAddr Args to Child
    01b6ff78 7c802455 0000ea60 00000000 01b6ffb4 ntdll!KiFastSystemCallRet
    01b6ff88 774fe32f 0000ea60 00f99f98 774fe3ee kernel32!Sleep+0xf
    01b6ffb4 7c80b713 00f99f98 00070188 00000010 ole32!StringFromGUID2+0x51d
    01b6ffec 00000000 774fe43b 00f99f98 00000000 kernel32!GetModuleFileNameA+0x1b4

    *----> Raw Stack Dump <----*
    0000000001b6ff20 fc d1 90 7c f1 23 80 7c - 00 00 00 00 50 ff b6 01 ...|.#.|....P...
    0000000001b6ff30 50 25 80 7c f8 6d 60 77 - 30 75 00 00 14 00 00 00 P%.|.m`w0u......
    0000000001b6ff40 01 00 00 00 00 00 00 00 - 00 00 00 00 10 00 00 00 ................
    0000000001b6ff50 00 ba 3c dc ff ff ff ff - 10 d1 4e 77 50 ff b6 01 ..<.......NwP...
    0000000001b6ff60 30 ff b6 01 c0 79 f7 00 - dc ff b6 01 c0 9a 83 7c 0....y.........|
    0000000001b6ff70 60 24 80 7c 00 00 00 00 - 88 ff b6 01 55 24 80 7c `$.|........U$.|
    0000000001b6ff80 60 ea 00 00 00 00 00 00 - b4 ff b6 01 2f e3 4f 77 `.........../.Ow
    0000000001b6ff90 60 ea 00 00 98 9f f9 00 - ee e3 4f 77 00 00 00 00 `.........Ow....
    0000000001b6ffa0 88 01 07 00 98 9f f9 00 - 00 00 4e 77 56 e4 4f 77 ..........NwV.Ow
    0000000001b6ffb0 10 00 00 00 ec ff b6 01 - 13 b7 80 7c 98 9f f9 00 ...........|....
    0000000001b6ffc0 88 01 07 00 10 00 00 00 - 98 9f f9 00 00 c0 fa 7f ................
    0000000001b6ffd0 0f 00 00 00 c0 ff b6 01 - 88 52 20 89 ff ff ff ff .........R .....
    0000000001b6ffe0 c0 9a 83 7c 20 b7 80 7c - 00 00 00 00 00 00 00 00 ...| ..|........
    0000000001b6fff0 00 00 00 00 3b e4 4f 77 - 98 9f f9 00 00 00 00 00 ....;.Ow........
    0000000001b70000 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000001b70010 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000001b70020 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000001b70030 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000001b70040 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000001b70050 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

    *----> State Dump for Thread Id 0xd98 <----*

    eax=0185ff14 ebx=0185fef4 ecx=0185fecc edx=7c90e4f4 esi=00000000 edi=7ffdf000
    eip=7c90e4f4 esp=0185fecc ebp=0185ff68 iopl=0 nv up ei pl zr na po nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

    function: ntdll!KiFastSystemCallRet
    7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
    7c90e4df 8b0424 mov eax,[esp]
    7c90e4e2 8be5 mov esp,ebp
    7c90e4e4 5d pop ebp
    7c90e4e5 c3 ret
    7c90e4e6 8da42400000000 lea esp,[esp]
    7c90e4ed 8d4900 lea ecx,[ecx]
    ntdll!KiFastSystemCall:
    7c90e4f0 8bd4 mov edx,esp
    7c90e4f2 0f34 sysenter
    ntdll!KiFastSystemCallRet:
    7c90e4f4 c3 ret
    7c90e4f5 8da42400000000 lea esp,[esp]
    7c90e4fc 8d642400 lea esp,[esp]
    ntdll!KiIntSystemCall:
    7c90e500 8d542408 lea edx,[esp+0x8]
    7c90e504 cd2e int 2e
    7c90e506 c3 ret
    7c90e507 90 nop
    ntdll!RtlRaiseException:
    7c90e508 55 push ebp
    7c90e509 8bec mov ebp,esp

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be wrong.
    ChildEBP RetAddr Args to Child
    0185ff68 7c80a105 00000003 01c589a4 00000000 ntdll!KiFastSystemCallRet
    0185ff84 76a19216 00000003 01c589a4 00000000 kernel32!WaitForMultipleObjects+0x18
    0185ffb4 7c80b713 00000000 77de0a15 00000000 USERENV!Ordinal145+0x10dd
    0185ffec 00000000 76a1970d 01c589a0 00000000 kernel32!GetModuleFileNameA+0x1b4

    *----> Raw Stack Dump <----*
    000000000185fecc 2c df 90 7c 74 95 80 7c - 03 00 00 00 f4 fe 85 01 ,..|t..|........
    000000000185fedc 01 00 00 00 00 00 00 00 - 00 00 00 00 20 2a a6 76 ............ *.v
    000000000185feec a0 89 c5 01 00 00 00 00 - 44 07 00 00 90 00 00 00 ........D.......
    000000000185fefc 14 01 00 00 b4 fd 80 89 - 28 0c c4 a7 00 00 00 00 ........(.......
    000000000185ff0c 27 64 6e 80 08 00 00 00 - 14 00 00 00 01 00 00 00 'dn.............
    000000000185ff1c 00 00 00 00 00 00 00 00 - 10 00 00 00 84 fd 80 89 ................
    000000000185ff2c 18 fc 80 89 4c fc 80 89 - 00 f0 fd 7f 00 80 fa 7f ....L...........
    000000000185ff3c a0 8a 67 89 00 00 00 00 - f4 fe 85 01 00 00 00 00 ..g.............
    000000000185ff4c 03 00 00 00 e8 fe 85 01 - 05 00 00 00 dc ff 85 01 ................
    000000000185ff5c c0 9a 83 7c 68 96 80 7c - 00 00 00 00 84 ff 85 01 ...|h..|........
    000000000185ff6c 05 a1 80 7c 03 00 00 00 - a4 89 c5 01 00 00 00 00 ...|............
    000000000185ff7c ff ff ff ff 00 00 00 00 - b4 ff 85 01 16 92 a1 76 ...............v
    000000000185ff8c 03 00 00 00 a4 89 c5 01 - 00 00 00 00 ff ff ff ff ................
    000000000185ff9c a0 89 c5 01 15 0a de 77 - 00 00 00 00 20 2a a6 76 .......w.... *.v
    000000000185ffac 00 00 00 00 00 00 00 00 - ec ff 85 01 13 b7 80 7c ...............|
    000000000185ffbc 00 00 00 00 15 0a de 77 - 00 00 00 00 a0 89 c5 01 .......w........
    000000000185ffcc 00 80 fa 7f 00 46 64 8a - c0 ff 85 01 60 4a 31 89 .....Fd.....`J1.
    000000000185ffdc ff ff ff ff c0 9a 83 7c - 20 b7 80 7c 00 00 00 00 .......| ..|....
    000000000185ffec 00 00 00 00 00 00 00 00 - 0d 97 a1 76 a0 89 c5 01 ...........v....
    000000000185fffc 00 00 00 00 4d 5a 90 00 - 03 00 00 00 04 00 00 00 ....MZ..........

    *----> State Dump for Thread Id 0xe2c <----*

    eax=00000005 ebx=00000000 ecx=00000000 edx=00000004 esi=7c97b420 edi=7c97b440
    eip=7c90e4f4 esp=01c2ff70 ebp=01c2ffb4 iopl=0 nv up ei ng nz na po nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000286

    function: ntdll!KiFastSystemCallRet
    7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
    7c90e4df 8b0424 mov eax,[esp]
    7c90e4e2 8be5 mov esp,ebp
    7c90e4e4 5d pop ebp
    7c90e4e5 c3 ret
    7c90e4e6 8da42400000000 lea esp,[esp]
    7c90e4ed 8d4900 lea ecx,[ecx]
    ntdll!KiFastSystemCall:
    7c90e4f0 8bd4 mov edx,esp
    7c90e4f2 0f34 sysenter
    ntdll!KiFastSystemCallRet:
    7c90e4f4 c3 ret
    7c90e4f5 8da42400000000 lea esp,[esp]
    7c90e4fc 8d642400 lea esp,[esp]
    ntdll!KiIntSystemCall:
    7c90e500 8d542408 lea edx,[esp+0x8]
    7c90e504 cd2e int 2e
    7c90e506 c3 ret
    7c90e507 90 nop
    ntdll!RtlRaiseException:
    7c90e508 55 push ebp
    7c90e509 8bec mov ebp,esp

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be wrong.
    ChildEBP RetAddr Args to Child
    01c2ffb4 7c80b713 00000000 00000000 00000000 ntdll!KiFastSystemCallRet
    01c2ffec 00000000 7c910230 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

    *----> Raw Stack Dump <----*
    0000000001c2ff70 2c da 90 7c 6d 02 91 7c - 78 01 00 00 ac ff c2 01 ,..|m..|x.......
    0000000001c2ff80 b0 ff c2 01 98 ff c2 01 - a0 ff c2 01 00 00 00 00 ................
    0000000001c2ff90 00 00 00 00 00 00 00 00 - 00 00 00 00 a0 b0 07 00 ................
    0000000001c2ffa0 00 7c 28 e8 ff ff ff ff - a0 9c 9a a2 c9 7a 92 7c .|(..........z.|
    0000000001c2ffb0 58 7a f8 00 ec ff c2 01 - 13 b7 80 7c 00 00 00 00 Xz.........|....
    0000000001c2ffc0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 f0 f9 7f ................
    0000000001c2ffd0 50 a3 e9 e4 c0 ff c2 01 - 98 f0 64 8a ff ff ff ff P.........d.....
    0000000001c2ffe0 c0 9a 83 7c 20 b7 80 7c - 00 00 00 00 00 00 00 00 ...| ..|........
    0000000001c2fff0 00 00 00 00 30 02 91 7c - 00 00 00 00 00 00 00 00 ....0..|........
    0000000001c30000 08 00 00 00 00 01 00 01 - ee ff ee ff 00 00 00 00 ................
    0000000001c30010 00 00 26 00 00 e0 0a 00 - 00 00 c3 01 00 01 00 00 ..&.............
    0000000001c30020 40 00 c3 01 00 00 d3 01 - ec 00 00 00 03 00 00 00 @...............
    0000000001c30030 98 05 26 00 00 00 00 00 - b8 05 c6 01 00 00 00 00 ..&.............
    0000000001c30040 83 00 08 00 29 00 0e 01 - a0 ed 26 00 78 01 26 00 ....).....&.x.&.
    0000000001c30050 23 00 02 00 2b 00 08 01 - 90 02 26 00 90 02 26 00 #...+.....&...&.
    0000000001c30060 21 00 02 00 2d 00 08 01 - 80 02 26 00 60 be 26 00 !...-.....&.`.&.
    0000000001c30070 90 32 00 00 3c 00 00 00 - 09 00 00 00 00 00 00 00 .2..<...........
    0000000001c30080 cc 32 00 00 b0 00 00 00 - 01 00 00 00 00 00 00 00 .2..............
    0000000001c30090 7c 33 00 00 cc 00 00 00 - 02 00 00 00 00 00 00 00 |3..............
    0000000001c300a0 48 34 00 00 d4 00 00 00 - 03 00 00 00 00 00 00 00 H4..............

    *----> State Dump for Thread Id 0x794 <----*

    eax=00000000 ebx=00000000 ecx=0103e801 edx=7c9032bc esi=00000000 edi=00000000
    eip=0103e801 esp=0135efa4 ebp=0135efc4 iopl=0 nv up ei pl zr na po nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

    function: winlogon
    0103e7f0 c3 ret
    0103e7f1 8b4df0 mov ecx,[ebp-0x10]
    0103e7f4 6764890e0000 mov fs:[0000],ecx
    0103e7fa 59 pop ecx
    0103e7fb 5f pop edi
    0103e7fc 5e pop esi
    0103e7fd 5b pop ebx
    0103e7fe c9 leave
    0103e7ff 51 push ecx
    0103e800 c3 ret
    FAULT ->*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\msvcrt.dll -
    0103e801 ff25d8150001 jmp dword ptr [winlogon+0x15d8 (010015d8)]{msvcrt!except_handler3 (77c35c94)} ds:0023:010015d8=77c35c94
    0103e807 8b442408 mov eax,[esp+0x8]
    0103e80b 8b4c2410 mov ecx,[esp+0x10]
    0103e80f 0bc8 or ecx,eax
    0103e811 8b4c240c mov ecx,[esp+0xc]
    0103e815 7509 jnz winlogon+0x3e820 (0103e820)
    0103e817 8b442404 mov eax,[esp+0x4]
    0103e81b f7e1 mul ecx
    0103e81d c21000 ret 0x10
    0103e820 53 push ebx
    0103e821 f7e1 mul ecx

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be wrong.
    ChildEBP RetAddr Args to Child
    0135efc4 7c90327a 0135f08c 0135ffa4 0135f0a8 winlogon+0x3e801
    0135f074 7c90e46a 0135ffa4 0135f0a8 0135f08c ntdll!RtlConvertUlongToLargeInteger+0x3c
    0135ffb4 7c80b713 00f8aa88 7c90f63c 7c90f641 ntdll!KiUserExceptionDispatcher+0xe
    0135ffec 00000000 01039e58 00f8aa88 00000000 kernel32!GetModuleFileNameA+0x1b4

    *----> Raw Stack Dump <----*
    000000000135efa4 a8 32 90 7c 8c f0 35 01 - a4 ff 35 01 a8 f0 35 01 .2.|..5...5...5.
    000000000135efb4 60 f0 35 01 b0 f3 35 01 - bc 32 90 7c a4 ff 35 01 `.5...5..2.|..5.
    000000000135efc4 74 f0 35 01 7a 32 90 7c - 8c f0 35 01 a4 ff 35 01 t.5.z2.|..5...5.
    000000000135efd4 a8 f0 35 01 60 f0 35 01 - 01 e8 03 01 02 00 00 00 ..5.`.5.........
    000000000135efe4 8c f0 35 01 a4 ff 35 01 - ef a9 92 7c 8c f0 35 01 ..5...5....|..5.
    000000000135eff4 a4 ff 35 01 a8 f0 35 01 - 60 f0 35 01 01 e8 03 01 ..5...5.`.5.....
    000000000135f004 00 00 00 00 8c f0 35 01 - 00 00 00 00 00 00 00 00 ......5.........
    000000000135f014 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    000000000135f024 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    000000000135f034 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    000000000135f044 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    000000000135f054 00 00 00 00 00 00 00 00 - 00 00 00 00 a4 ff 35 01 ..............5.
    000000000135f064 00 00 00 00 00 00 36 01 - 00 00 35 01 00 00 00 00 ......6...5.....
    000000000135f074 b4 ff 35 01 6a e4 90 7c - a4 ff 35 01 a8 f0 35 01 ..5.j..|..5...5.
    000000000135f084 8c f0 35 01 a8 f0 35 01 - 05 00 00 c0 10 00 00 00 ..5...5.........
    000000000135f094 00 00 00 00 66 9f 03 01 - 02 00 00 00 08 00 00 00 ....f...........
    000000000135f0a4 66 9f 03 01 3f 00 01 00 - 00 00 00 00 00 00 00 00 f...?...........
    000000000135f0b4 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    000000000135f0c4 7f 02 ff ff 00 00 ff ff - ff ff ff ff 00 00 00 00 ................
    000000000135f0d4 00 00 00 00 00 00 00 00 - 00 00 ff ff 40 00 00 00 ............@...

    *----> State Dump for Thread Id 0xdc <----*

    eax=00000000 ebx=01befc88 ecx=00126da8 edx=00070608 esi=00000000 edi=7ffdf000
    eip=7c90e4f4 esp=01befc60 ebp=01befcfc iopl=0 nv up ei pl zr na po nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246

    function: ntdll!KiFastSystemCallRet
    7c90e4da e829000000 call ntdll!RtlRaiseException (7c90e508)
    7c90e4df 8b0424 mov eax,[esp]
    7c90e4e2 8be5 mov esp,ebp
    7c90e4e4 5d pop ebp
    7c90e4e5 c3 ret
    7c90e4e6 8da42400000000 lea esp,[esp]
    7c90e4ed 8d4900 lea ecx,[ecx]
    ntdll!KiFastSystemCall:
    7c90e4f0 8bd4 mov edx,esp
    7c90e4f2 0f34 sysenter
    ntdll!KiFastSystemCallRet:
    7c90e4f4 c3 ret
    7c90e4f5 8da42400000000 lea esp,[esp]
    7c90e4fc 8d642400 lea esp,[esp]
    ntdll!KiIntSystemCall:
    7c90e500 8d542408 lea edx,[esp+0x8]
    7c90e504 cd2e int 2e
    7c90e506 c3 ret
    7c90e507 90 nop
    ntdll!RtlRaiseException:
    7c90e508 55 push ebp
    7c90e509 8bec mov ebp,esp

    *----> Stack Back Trace <----*
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\WlNotify.dll -
    WARNING: Stack unwind information not available. Following frames may be wrong.
    ChildEBP RetAddr Args to Child
    01befcfc 75951551 00000002 01befd24 00000000 ntdll!KiFastSystemCallRet
    01beffb4 7c80b713 75962144 75e60000 00000002 WlNotify+0x1551
    01beffec 00000000 759514de 75962144 00000000 kernel32!GetModuleFileNameA+0x1b4

    *----> Raw Stack Dump <----*
    0000000001befc60 2c df 90 7c 74 95 80 7c - 02 00 00 00 88 fc be 01 ,..|t..|........
    0000000001befc70 01 00 00 00 00 00 00 00 - bc fc be 01 00 00 e6 75 ...............u
    0000000001befc80 44 21 96 75 00 00 00 00 - b4 02 00 00 0c 09 00 00 D!.u............
    0000000001befc90 7b 27 3d 72 83 27 3d 72 - 00 00 e6 75 01 00 00 00 {'=r.'=r...u....
    0000000001befca0 01 00 00 00 01 00 00 00 - 14 00 00 00 01 00 00 00 ................
    0000000001befcb0 00 00 00 00 00 00 00 00 - 10 00 00 00 00 74 79 b8 .............ty.
    0000000001befcc0 ff ff ff ff 83 27 3d 72 - 00 f0 fd 7f 00 10 fa 7f .....'=r........
    0000000001befcd0 b4 02 00 00 bc fc be 01 - 88 fc be 01 a8 6d 12 00 .............m..
    0000000001befce0 02 00 00 00 7c fc be 01 - 44 21 96 75 dc ff be 01 ....|...D!.u....
    0000000001befcf0 c0 9a 83 7c 68 96 80 7c - 00 00 00 00 b4 ff be 01 ...|h..|........
    0000000001befd00 51 15 95 75 02 00 00 00 - 24 fd be 01 00 00 00 00 Q..u....$.......
    0000000001befd10 c0 d4 01 00 00 00 00 00 - 00 00 e6 75 02 00 00 00 ...........u....
    0000000001befd20 44 21 96 75 b4 02 00 00 - 0c 09 00 00 01 00 00 00 D!.u............
    0000000001befd30 17 00 01 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
    0000000001befd40 00 00 00 00 00 00 00 00 - 00 00 00 00 80 df 00 c0 ................
    0000000001befd50 78 b4 4f 80 00 00 00 00 - c8 aa 73 02 64 aa 73 a2 x.O.......s.d.s.
    0000000001befd60 79 38 52 80 02 00 00 00 - c8 aa 73 a2 01 00 00 00 y8R.......s.....
    0000000001befd70 00 00 00 00 8c aa 73 a2 - 00 00 00 00 00 00 00 00 ......s.........
    0000000001befd80 68 00 60 c0 24 ab 73 a2 - fa 3f 52 80 88 aa 73 a2 h.`.$.s..?R...s.
    0000000001befd90 00 00 00 00 00 00 00 00 - 00 00 00 00 ff ff be 01 ................

    *----> Symbol Table <----*
    \??\C:\WINDOWS\system32\winlogon.exe

    please help
    ofir
     
  2. mcsmc

    mcsmc MajorGeek

    For future reference, it's best to attach logs as text files, instead of pasting them in-line... makes the thread easier to read and follow. :)
     
  3. ofirad

    ofirad Private E-2

    ok 4 next time i will
    any ideas for this problem?
     
  4. mcsmc

    mcsmc MajorGeek

    To be honest, I'm not good with decrypting Windows logs yet. :) However, a few suggestions:

    1. Run chkdsk (Click Start, Run..., type "cmd" without the quotes, press Enter, type "chkdsk /r" without the quotes, press enter. It will likely tell you it can't run chkdsk on C: right now, and ask to do it on next reboot, press Y, and reboot... allow chkdsk to complete).

    2. Run CCleaner with the default options checked, and reboot.

    I'm sure someone that knows more than I do will be along soon to help you out more. :-D
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds