Explorer keeps shutting down

Discussion in 'Computer Support' started by J.B, Jul 16, 2004.

  1. J.B

    J.B Guest

    Ok I thought this went away but it's back, any help would be greatly
    appreciated.
    Explorer started to close every time I went to it after copying some bitmaps
    to a folder on my HDD

    there is two error logs relating to explorer closing, created by dr.watson



    Application exception occurred:
    App: C:\WINDOWS\explorer.exe (pid=3288)
    When: 7/1/2004 @ 23:07:03.031
    Exception number: c0000005 (access violation)

    *----> System Information <----*
    Computer Name: SN027714820049
    User Name: James
    Terminal Session Id: 0
    Number of Processors: 1
    Processor Type: x86 Family 15 Model 2 Stepping 7
    Windows Version: 5.1
    Current Build: 2600
    Service Pack: 1
    Current Type: Uniprocessor Free
    Registered Organization:
    Registered Owner: James

    *----> Task List <----*
    0 System Process
    4 System
    396 smss.exe
    448 csrss.exe
    476 winlogon.exe
    524 services.exe
    536 lsass.exe
    716 svchost.exe
    780 svchost.exe
    876 svchost.exe
    900 svchost.exe
    964 ccSetMgr.exe
    988 ccEvtMgr.exe
    1152 spoolsv.exe
    1248 alg.exe
    1268 ccProxy.exe
    1336 mdm.exe
    1356 navapsvc.exe
    1404 SAVScan.exe
    1468 slserv.exe
    1512 symlcsvc.exe
    1584 khooker.exe
    940 CFD.exe
    220 ccApp.exe
    1764 hpztsb07.exe
    1940 point32.exe
    196 ctfmon.exe
    2452 SNDSrvc.exe
    3288 explorer.exe
    2804 wisptis.exe
    2680 realsched.exe
    340 wmplayer.exe
    3440 FRONTPG.EXE
    2544 AgentSvr.exe
    1304 iexplore.exe
    1892 drwtsn32.exe

    *----> Module List <----*
    (0000000001000000 - 00000000010f7000: C:\WINDOWS\explorer.exe
    (0000000001540000 - 0000000001741000: C:\WINDOWS\System32\msi.dll
    (0000000001a70000 - 0000000001a88000: C:\Program Files\Norton Internet
    Security\Norton AntiVirus\NavShExt.dll
    (0000000001cb0000 - 0000000001ce2000: C:\WINDOWS\System32\ODBC32.dll
    (0000000001d30000 - 0000000001d40000: C:\Program
    Files\SmartFTP\smarthook.dll
    (00000000020d0000 - 00000000020ee000: C:\Program Files\Common Files\Symantec
    Shared\Script Blocking\scrauth.dll
    (0000000002150000 - 0000000002170000: C:\Program Files\Common Files\Symantec
    Shared\Script Blocking\ScrBlock.dll
    (0000000007610000 - 0000000007627000: C:\PROGRA~1\WINDOW~2\wmpband.dll
    (0000000007680000 - 0000000007afa000: C:\WINDOWS\System32\wmp.dll
    (0000000008110000 - 00000000083de000: C:\WINDOWS\System32\wmploc.dll
    (000000000ffd0000 - 000000000fff3000: C:\WINDOWS\System32\rsaenh.dll
    (0000000010000000 - 0000000010030000:
    C:\PROGRA~1\COMMON~1\SYMANT~1\ANTISPAM\asOEHook.dll
    (000000001a400000 - 000000001a47a000: C:\WINDOWS\system32\urlmon.dll
    (000000001f850000 - 000000001f866000: C:\WINDOWS\System32\odbcint.dll
    (00000000559e0000 - 0000000055a51000: C:\WINDOWS\System32\themeui.dll
    (000000005ad70000 - 000000005ada4000: C:\WINDOWS\System32\UxTheme.dll
    (000000005b0a0000 - 000000005b0a7000: C:\WINDOWS\System32\umdmxfrm.dll
    (000000005cd70000 - 000000005cd77000: C:\WINDOWS\System32\serwvdrv.dll
    (00000000605d0000 - 00000000605d8000: C:\WINDOWS\System32\mslbui.dll
    (00000000629c0000 - 00000000629c8000: C:\WINDOWS\System32\LPK.DLL
    (0000000063000000 - 0000000063096000: C:\WINDOWS\system32\WININET.dll
    (000000006b700000 - 000000006b790000: c:\windows\system32\jscript.dll
    (0000000070a70000 - 0000000070ad5000: C:\WINDOWS\system32\SHLWAPI.dll
    (0000000071500000 - 00000000715fd000: C:\WINDOWS\System32\BROWSEUI.dll
    (0000000071700000 - 0000000071849000: C:\WINDOWS\System32\SHDOCVW.dll
    (0000000071950000 - 0000000071a34000:
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0
    ..2600.1331_x-ww_7abf6d02\comctl32.dll
    (0000000071aa0000 - 0000000071aa8000: C:\WINDOWS\system32\WS2HELP.dll
    (0000000071ab0000 - 0000000071ac4000: C:\WINDOWS\system32\WS2_32.dll
    (0000000071ad0000 - 0000000071ad8000: C:\WINDOWS\System32\wsock32.dll
    (0000000071b20000 - 0000000071b31000: C:\WINDOWS\system32\MPR.dll
    (0000000071bf0000 - 0000000071c01000: C:\WINDOWS\System32\SAMLIB.dll
    (0000000071c10000 - 0000000071c1d000: C:\WINDOWS\System32\ntlanman.dll
    (0000000071c20000 - 0000000071c6e000: C:\WINDOWS\System32\NETAPI32.dll
    (0000000071c80000 - 0000000071c86000: C:\WINDOWS\System32\NETRAP.dll
    (0000000071c90000 - 0000000071ccc000: C:\WINDOWS\System32\NETUI1.dll
    (0000000071cd0000 - 0000000071ce6000: C:\WINDOWS\System32\NETUI0.dll
    (0000000071d40000 - 0000000071d5b000: C:\WINDOWS\System32\actxprxy.dll
    (0000000072410000 - 0000000072429000: C:\WINDOWS\System32\mydocs.dll
    (0000000072d10000 - 0000000072d18000: C:\WINDOWS\System32\msacm32.drv
    (0000000072d20000 - 0000000072d29000: C:\WINDOWS\System32\wdmaud.drv
    (0000000072fa0000 - 0000000072ffa000: C:\WINDOWS\System32\USP10.dll
    (0000000073000000 - 0000000073023000: C:\WINDOWS\System32\WINSPOOL.DRV
    (0000000073030000 - 000000007303b000: C:\WINDOWS\System32\WZCSAPI.DLL
    (0000000073380000 - 00000000733d2000: C:\WINDOWS\System32\zipfldr.dll
    (0000000073bd0000 - 0000000073bf0000: C:\WINDOWS\System32\MSVFW32.dll
    (0000000074720000 - 0000000074764000: C:\WINDOWS\System32\MSCTF.dll
    (0000000074ad0000 - 0000000074ad7000: C:\WINDOWS\System32\POWRPROF.dll
    (0000000074ae0000 - 0000000074ae7000: C:\WINDOWS\System32\CFGMGR32.dll
    (0000000074af0000 - 0000000074af9000: C:\WINDOWS\System32\BatMeter.dll
    (0000000074b00000 - 0000000074b20000: C:\WINDOWS\System32\stobject.dll
    (0000000074b30000 - 0000000074b71000: C:\WINDOWS\System32\webcheck.dll
    (0000000074b80000 - 0000000074c02000: C:\WINDOWS\System32\printui.dll
    (0000000075970000 - 0000000075a62000: C:\WINDOWS\System32\MSGINA.dll
    (0000000075a70000 - 0000000075b15000: C:\WINDOWS\system32\USERENV.dll
    (0000000075cf0000 - 0000000075e81000: C:\WINDOWS\system32\NETSHELL.dll
    (0000000075e90000 - 0000000075f38000: C:\WINDOWS\System32\SXS.DLL
    (0000000075f40000 - 0000000075f5f000: C:\WINDOWS\system32\appHelp.dll
    (0000000075f60000 - 0000000075f66000: C:\WINDOWS\System32\drprov.dll
    (0000000075f70000 - 0000000075f79000: C:\WINDOWS\System32\davclnt.dll
    (0000000076170000 - 00000000761f8000: C:\WINDOWS\System32\shdoclc.dll
    (00000000762a0000 - 00000000762b0000: C:\WINDOWS\system32\MSASN1.dll
    (00000000762c0000 - 0000000076348000: C:\WINDOWS\system32\CRYPT32.dll
    (0000000076360000 - 000000007636f000: C:\WINDOWS\System32\WINSTA.dll
    (0000000076380000 - 0000000076385000: C:\WINDOWS\System32\MSIMG32.dll
    (00000000763b0000 - 00000000763f5000: C:\WINDOWS\system32\comdlg32.dll
    (0000000076600000 - 000000007661b000: C:\WINDOWS\System32\CSCDLL.dll
    (0000000076620000 - 000000007666e000: C:\WINDOWS\System32\cscui.dll
    (0000000076670000 - 0000000076757000: C:\WINDOWS\System32\SETUPAPI.dll
    (0000000076980000 - 0000000076987000: C:\WINDOWS\System32\LINKINFO.dll
    (0000000076990000 - 00000000769b4000: C:\WINDOWS\System32\ntshrui.dll
    (0000000076b20000 - 0000000076b35000: C:\WINDOWS\System32\ATL.DLL
    (0000000076b40000 - 0000000076b6c000: C:\WINDOWS\System32\WINMM.dll
    (0000000076c00000 - 0000000076c2d000: C:\WINDOWS\system32\credui.dll
    (0000000076c30000 - 0000000076c5b000: C:\WINDOWS\System32\WINTRUST.dll
    (0000000076c90000 - 0000000076cb2000: C:\WINDOWS\system32\IMAGEHLP.dll
    (0000000076ce0000 - 0000000076cff000: C:\WINDOWS\System32\NTMARTA.DLL
    (0000000076d40000 - 0000000076d56000: C:\WINDOWS\System32\MPRAPI.dll
    (0000000076d60000 - 0000000076d76000: C:\WINDOWS\system32\iphlpapi.dll
    (0000000076d80000 - 0000000076d9b000: C:\WINDOWS\System32\DHCPCSVC.DLL
    (0000000076e10000 - 0000000076e35000: C:\WINDOWS\System32\adsldpc.dll
    (0000000076e40000 - 0000000076e6f000: C:\WINDOWS\System32\ACTIVEDS.dll
    (0000000076e80000 - 0000000076e8d000: C:\WINDOWS\System32\rtutils.dll
    (0000000076f20000 - 0000000076f45000: C:\WINDOWS\System32\DNSAPI.dll
    (0000000076f50000 - 0000000076f58000: C:\WINDOWS\System32\WTSAPI32.dll
    (0000000076f60000 - 0000000076f8c000: C:\WINDOWS\system32\WLDAP32.dll
    (0000000076f90000 - 0000000076fa0000: C:\WINDOWS\System32\Secur32.dll
    (0000000077050000 - 0000000077115000: C:\WINDOWS\System32\COMRes.dll
    (0000000077120000 - 00000000771ab000: C:\WINDOWS\system32\OLEAUT32.dll
    (00000000771b0000 - 00000000772d4000: C:\WINDOWS\system32\ole32.dll
    (0000000077340000 - 00000000773cb000: C:\WINDOWS\system32\comctl32.dll
    (00000000773d0000 - 0000000077bc9000: C:\WINDOWS\system32\SHELL32.dll
    (0000000077bd0000 - 0000000077bd7000: C:\WINDOWS\System32\midimap.dll
    (0000000077be0000 - 0000000077bf4000: C:\WINDOWS\System32\MSACM32.dll
    (0000000077c00000 - 0000000077c07000: C:\WINDOWS\system32\VERSION.dll
    (0000000077c10000 - 0000000077c63000: C:\WINDOWS\system32\msvcrt.dll
    (0000000077d40000 - 0000000077dcc000: C:\WINDOWS\system32\USER32.dll
    (0000000077dd0000 - 0000000077e5d000: C:\WINDOWS\system32\ADVAPI32.dll
    (0000000077e60000 - 0000000077f46000: C:\WINDOWS\system32\kernel32.dll
    (0000000077f50000 - 0000000077ff7000: C:\WINDOWS\System32\ntdll.dll
    (0000000078000000 - 0000000078087000: C:\WINDOWS\system32\RPCRT4.dll
    (000000007c000000 - 000000007c054000: C:\WINDOWS\System32\MSVCR70.dll
    (000000007c080000 - 000000007c0f7000: C:\WINDOWS\System32\MSVCP70.dll
    (000000007c890000 - 000000007c911000: C:\WINDOWS\System32\CLBCATQ.DLL
    (000000007e090000 - 000000007e0d1000: C:\WINDOWS\system32\GDI32.dll

    *----> State Dump for Thread Id 0xa4c <----*

    eax=00000406 ebx=000cb608 ecx=77d440c6 edx=00000000 esi=000cb608
    edi=00000000
    eip=7ffe0304 esp=0006fefc ebp=0006ff14 iopl=0 nv up ei pl nz na pe
    nc
    cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
    efl=00000202

    function: <nosymbols>
    7ffe02f2 0000 add [eax],al
    7ffe02f4 0000 add [eax],al
    7ffe02f6 0000 add [eax],al
    *SharedUserSystemCall:
    7ffe02f8 0000 add [eax],al
    7ffe02fa 0000 add [eax],al
    7ffe02fc 0000 add [eax],al
    7ffe02fe 0000 add [eax],al
    7ffe0300 8bd4 mov edx,esp
    7ffe0302 0f34 sysenter
    7ffe0304 c3 ret
    7ffe0305 9c pushfd
    7ffe0306 810c2400010000 or dword ptr [esp],0x100
    7ffe030d 9d popfd
    7ffe030e c3 ret
    7ffe030f 8bd4 mov edx,esp
    7ffe0311 0f05 syscall
    7ffe0313 c3 ret
    7ffe0314 9c pushfd
    7ffe0315 810c2400010000 or dword ptr [esp],0x100
    7ffe031c 9d popfd

    *----> Stack Back Trace <----*
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for
    C:\WINDOWS\system32\USER32.dll -
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for
    C:\WINDOWS\system32\SHELL32.dll -
    WARNING: Stack unwind information not available. Following frames may be
    wrong.
    *** ERROR: Module load completed but symbols could not be loaded for
    C:\WINDOWS\explorer.exe
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for
    C:\WINDOWS\system32\kernel32.dll -
    ChildEBP RetAddr Args to Child
    0006fef8 77d43c53 774249e4 77e7a29b 000cb608 *SharedUserSystemCall+0xc (FPO:
    [0,0,0])
    0006ff14 7741aedd 00000000 0100b571 000cb608 USER32!WaitMessage+0xc
    0006ff5c 0100b6af 01000000 00000000 000205e2 SHELL32!Ordinal201+0x24
    0006ffc0 77e814c7 00000000 77f58a3e 7ffdf000 explorer+0xb6af
    0006fff0 00000000 0100b644 00000000 78746341
    kernel32!GetCurrentDirectoryW+0x44

    *----> Raw Stack Dump <----*
    000000000006fefc 53 3c d4 77 e4 49 42 77 - 9b a2 e7 77 08 b6 0c 00
    S<.w.IBw...w....
    000000000006ff0c 08 b6 0c 00 5c ff 06 00 - 5c ff 06 00 dd ae 41 77
    .....\...\.....Aw
    000000000006ff1c 00 00 00 00 71 b5 00 01 - 08 b6 0c 00 00 f0 fd 7f
    .....q...........
    000000000006ff2c c0 ff 06 00 00 00 00 00 - 18 ff 06 00 e4 bd f5 77
    ................w
    000000000006ff3c 99 ef e7 77 ff ff ff ff - 0c 00 00 00 84 c2 f5 77
    ....w...........w
    000000000006ff4c 7c ef e7 77 00 00 00 00 - 46 2d 0f 02 60 00 00 00
    |..w....F-..`...
    000000000006ff5c c0 ff 06 00 af b6 00 01 - 00 00 00 01 00 00 00 00
    .................
    000000000006ff6c e2 05 02 00 05 00 00 00 - 00 00 00 00 3e 8a f5 77
    .............>..w
    000000000006ff7c 44 00 00 00 34 06 02 00 - 14 06 02 00 e4 05 02 00
    D...4...........
    000000000006ff8c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000006ff9c 2e 00 00 00 00 00 00 00 - 66 f1 06 00 01 00 00 00
    .........f.......
    000000000006ffac 05 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000006ffbc 00 00 00 00 f0 ff 06 00 - c7 14 e8 77 00 00 00 00
    ............w....
    000000000006ffcc 3e 8a f5 77 00 f0 fd 7f - f0 1c 06 f1 c8 ff 06 00
    >..w............

    000000000006ffdc 04 44 53 80 ff ff ff ff - 09 48 e9 77 10 12 e9 77
    ..DS......H.w...w
    000000000006ffec 00 00 00 00 00 00 00 00 - 00 00 00 00 44 b6 00 01
    .............D...
    000000000006fffc 00 00 00 00 41 63 74 78 - 20 00 00 00 01 00 00 00
    .....Actx .......
    000000000007000c 4c 06 00 00 7c 00 00 00 - 00 00 00 00 20 00 00 00
    L...|....... ...
    000000000007001c 00 00 00 00 14 00 00 00 - 01 00 00 00 03 00 00 00
    .................
    000000000007002c 34 00 00 00 ac 00 00 00 - 01 00 00 00 00 00 00 00
    4...............

    *----> State Dump for Thread Id 0x134 <----*

    eax=000c0000 ebx=00000000 ecx=00000000 edx=00260608 esi=02306418
    edi=00260000
    eip=77f58e22 esp=00efef44 ebp=00eff000 iopl=0 nv up ei pl nz na pe
    nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
    efl=00000202

    *** ERROR: Symbol file could not be found. Defaulted to export symbols for
    C:\WINDOWS\System32\ntdll.dll -
    function: ntdll!RtlFreeHeap
    77f58e02 8500 test [eax],eax
    77f58e04 0000 add [eax],al
    77f58e06 8d46e8 lea eax,[esi-0x18]
    77f58e09 894584 mov [ebp-0x7c],eax
    77f58e0c 894580 mov [ebp-0x80],eax
    77f58e0f 8b08 mov ecx,[eax]
    77f58e11 898d7cffffff mov [ebp-0x84],ecx
    77f58e17 8b4004 mov eax,[eax+0x4]
    77f58e1a 898578ffffff mov [ebp-0x88],eax
    77f58e20 8908 mov [eax],ecx
    FAULT ->77f58e22 894104 mov [ecx+0x4],eax
    ds:0023:00000004=????????
    77f58e25 807de300 cmp byte ptr [ebp-0x1d],0x0
    77f58e29 740f jz ntdll!RtlFreeHeap+0x3fc (77f58e3a)
    77f58e2b ffb778050000 push dword ptr [edi+0x578]
    77f58e31 e84a250000 call ntdll!RtlLeaveCriticalSection
    (77f5b380)
    77f58e36 8065e300 and byte ptr [ebp-0x1d],0x0
    77f58e3a 8365cc00 and dword ptr [ebp-0x34],0x0
    77f58e3e 6800800000 push 0x8000
    77f58e43 8d45cc lea eax,[ebp-0x34]
    77f58e46 50 push eax
    77f58e47 8d4584 lea eax,[ebp-0x7c]

    *----> Stack Back Trace <----*
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for
    C:\WINDOWS\system32\msvcrt.dll -
    WARNING: Stack unwind information not available. Following frames may be
    wrong.
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for
    C:\WINDOWS\System32\wmp.dll -
    ChildEBP RetAddr Args to Child
    00eff000 77c2ab2e 00260000 00000000 02306420 ntdll!RtlFreeHeap+0x3e4
    00eff048 076a96da 02306420 022e9950 02306da8 msvcrt!free+0xc3
    00eff0b8 076acff6 02306da8 022e9900 00000000 wmp!Ordinal3000+0x20f2c
    00eff0dc 076a98b6 022e9900 00000000 02307178 wmp!Ordinal3000+0x24848
    00000003 00000000 00000000 00000000 00000000 wmp!Ordinal3000+0x21108

    *----> Raw Stack Dump <----*
    0000000000efef44 00 00 00 00 20 64 30 02 - 00 00 00 00 00 04 00 00 ....
    d0.........
    0000000000efef54 04 00 00 00 e8 ef ef 00 - 03 bb 6a 07 d2 07 00 00
    ...........j.....
    0000000000efef64 28 f0 ef 00 00 04 00 00 - 08 0a 32 02 c8 b3 74 07
    (.........2...t.
    0000000000efef74 00 00 00 00 00 00 0c 00 - 00 00 00 00 00 64 30 02
    ..............d0.
    0000000000efef84 00 64 30 02 b0 ef ef 00 - d3 9a 6a 07 08 0a 32 01
    ..d0.......j...2.
    0000000000efef94 d2 07 00 00 00 04 00 00 - 04 00 00 00 e8 ef ef 00
    .................
    0000000000efefa4 00 00 00 00 00 00 00 00 - 00 00 00 00 f8 ef ef 00
    .................
    0000000000efefb4 00 00 00 00 00 00 00 00 - 00 00 4b 01 c8 b3 74 07
    ...........K...t.
    0000000000efefc4 00 04 00 00 04 00 00 00 - e8 ef ef 00 00 00 00 00
    .................
    0000000000efefd4 00 00 00 00 00 00 00 00 - 7c f0 ef 00 00 99 01 01
    .........|.......
    0000000000efefe4 00 00 26 00 44 ef ef 00 - 6c eb ef 00 38 f0 ef 00
    ...&.D...l...8...
    0000000000efeff4 f0 88 fa 77 88 1c f5 77 - 01 00 00 00 48 f0 ef 00
    ....w...w....H...
    0000000000eff004 2e ab c2 77 00 00 26 00 - 00 00 00 00 20 64 30 02
    ....w..&..... d0.
    0000000000eff014 00 00 00 00 7c 99 2e 02 - 00 00 00 00 90 f0 ef 00
    .....|...........
    0000000000eff024 39 18 69 07 03 00 15 00 - 90 f0 ef 00 14 f0 ef 00
    9.i.............
    0000000000eff034 6c eb ef 00 98 fe ef 00 - b0 3e c3 77 30 20 c1 77
    l........>.w0 .w
    0000000000eff044 ff ff ff ff b8 f0 ef 00 - da 96 6a 07 20 64 30 02
    ...........j. d0.
    0000000000eff054 50 99 2e 02 a8 6d 30 02 - cf 3d 69 07 01 00 00 00
    P....m0..=i.....
    0000000000eff064 00 99 2e 02 50 99 2e 02 - 48 8e 6a 07 cc ef 2f 02
    .....P...H.j.../.
    0000000000eff074 00 00 00 00 00 99 2e 02 - d2 07 00 00 cc 96 73 07
    ...............s.

    *----> State Dump for Thread Id 0xec <----*

    eax=000000c0 ebx=00000000 ecx=00000000 edx=00000000 esi=000a3900
    edi=70a908d3
    eip=7ffe0304 esp=00f3ff9c ebp=00f3ffb4 iopl=0 nv up ei pl nz na pe
    nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
    efl=00000202

    function: <nosymbols>
    7ffe02f2 0000 add [eax],al
    7ffe02f4 0000 add [eax],al
    7ffe02f6 0000 add [eax],al
    *SharedUserSystemCall:
    7ffe02f8 0000 add [eax],al
    7ffe02fa 0000 add [eax],al
    7ffe02fc 0000 add [eax],al
    7ffe02fe 0000 add [eax],al
    7ffe0300 8bd4 mov edx,esp
    7ffe0302 0f34 sysenter
    7ffe0304 c3 ret
    7ffe0305 9c pushfd
    7ffe0306 810c2400010000 or dword ptr [esp],0x100
    7ffe030d 9d popfd
    7ffe030e c3 ret
    7ffe030f 8bd4 mov edx,esp
    7ffe0311 0f05 syscall
    7ffe0313 c3 ret
    7ffe0314 9c pushfd
    7ffe0315 810c2400010000 or dword ptr [esp],0x100
    7ffe031c 9d popfd

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be
    wrong.
    ChildEBP RetAddr Args to Child
    00f3ff98 77f5b7f4 77f88423 00000001 00f3ffac *SharedUserSystemCall+0xc (FPO:
    [0,0,0])
    00f3ffb4 77e7d33b 00000000 70a908d3 000a3900 ntdll!ZwDelayExecution+0xc
    00f3ffec 00000000 77f883de 00000000 00000000
    kernel32!RegisterWaitForInputIdle+0x43

    *----> Raw Stack Dump <----*
    0000000000f3ff9c f4 b7 f5 77 23 84 f8 77 - 01 00 00 00 ac ff f3 00
    ....w#..w........
    0000000000f3ffac 00 00 00 00 00 00 00 80 - ec ff f3 00 3b d3 e7 77
    .............;..w
    0000000000f3ffbc 00 00 00 00 d3 08 a9 70 - 00 39 0a 00 00 00 00 00
    ........p.9......
    0000000000f3ffcc 00 00 00 00 00 a0 fd 7f - c0 ff f3 00 07 00 00 00
    .................
    0000000000f3ffdc ff ff ff ff 09 48 e9 77 - b8 3d e8 77 00 00 00 00
    ......H.w.=.w....
    0000000000f3ffec 00 00 00 00 00 00 00 00 - de 83 f8 77 00 00 00 00
    ............w....
    0000000000f3fffc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000f4000c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000f4001c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000f4002c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000f4003c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000f4004c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000f4005c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000f4006c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000f4007c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000f4008c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000f4009c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000f400ac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000f400bc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000f400cc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................

    *----> State Dump for Thread Id 0xa7c <----*

    eax=000000c0 ebx=00000000 ecx=00000000 edx=00000000 esi=00000000
    edi=00000001
    eip=7ffe0304 esp=00fdfcec ebp=00fdffb4 iopl=0 nv up ei pl nz na pe
    nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
    efl=00000202

    function: <nosymbols>
    7ffe02f2 0000 add [eax],al
    7ffe02f4 0000 add [eax],al
    7ffe02f6 0000 add [eax],al
    *SharedUserSystemCall:
    7ffe02f8 0000 add [eax],al
    7ffe02fa 0000 add [eax],al
    7ffe02fc 0000 add [eax],al
    7ffe02fe 0000 add [eax],al
    7ffe0300 8bd4 mov edx,esp
    7ffe0302 0f34 sysenter
    7ffe0304 c3 ret
    7ffe0305 9c pushfd
    7ffe0306 810c2400010000 or dword ptr [esp],0x100
    7ffe030d 9d popfd
    7ffe030e c3 ret
    7ffe030f 8bd4 mov edx,esp
    7ffe0311 0f05 syscall
    7ffe0313 c3 ret
    7ffe0314 9c pushfd
    7ffe0315 810c2400010000 or dword ptr [esp],0x100
    7ffe031c 9d popfd

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be
    wrong.
    ChildEBP RetAddr Args to Child
    00fdfce8 77f5c524 77f91f83 00000016 00fdfd30 *SharedUserSystemCall+0xc (FPO:
    [0,0,0])
    00fdffb4 77e7d33b 00000000 00000020 00000020
    ntdll!NtWaitForMultipleObjects+0xc
    00fdffec 00000000 77f91e38 00000000 00000000
    kernel32!RegisterWaitForInputIdle+0x43

    *----> Raw Stack Dump <----*
    0000000000fdfcec 24 c5 f5 77 83 1f f9 77 - 16 00 00 00 30 fd fd 00
    $..w...w....0...
    0000000000fdfcfc 01 00 00 00 01 00 00 00 - 00 00 00 00 20 00 00 00
    ............. ...
    0000000000fdfd0c 20 00 00 00 00 00 00 00 - 20 5a fc 77 20 5a fc 77
    ........ Z.w Z.w
    0000000000fdfd1c b0 01 00 00 7c 0a 00 00 - 16 00 00 00 16 00 00 00
    .....|...........
    0000000000fdfd2c 15 00 00 00 ac 01 00 00 - 94 01 00 00 e0 03 00 00
    .................
    0000000000fdfd3c 64 04 00 00 6c 06 00 00 - 74 06 00 00 7c 06 00 00
    d...l...t...|...
    0000000000fdfd4c 88 06 00 00 a0 06 00 00 - a8 06 00 00 b4 06 00 00
    .................
    0000000000fdfd5c c4 06 00 00 d0 06 00 00 - d8 06 00 00 e4 06 00 00
    .................
    0000000000fdfd6c f0 06 00 00 fc 06 00 00 - 04 07 00 00 20 07 00 00
    ............. ...
    0000000000fdfd7c 2c 07 00 00 38 07 00 00 - 44 07 00 00 00 00 00 00
    ,...8...D.......
    0000000000fdfd8c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000fdfd9c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000fdfdac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000fdfdbc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000fdfdcc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000fdfddc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000fdfdec 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000fdfdfc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000fdfe0c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000fdfe1c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................

    *----> State Dump for Thread Id 0xcec <----*

    eax=00000008 ebx=0011a750 ecx=0113fddc edx=00000000 esi=00000000
    edi=7ffdf000
    eip=7ffe0304 esp=0113fd30 ebp=0113fdcc iopl=0 nv up ei pl nz na pe
    nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
    efl=00000202

    function: <nosymbols>
    7ffe02f2 0000 add [eax],al
    7ffe02f4 0000 add [eax],al
    7ffe02f6 0000 add [eax],al
    *SharedUserSystemCall:
    7ffe02f8 0000 add [eax],al
    7ffe02fa 0000 add [eax],al
    7ffe02fc 0000 add [eax],al
    7ffe02fe 0000 add [eax],al
    7ffe0300 8bd4 mov edx,esp
    7ffe0302 0f34 sysenter
    7ffe0304 c3 ret
    7ffe0305 9c pushfd
    7ffe0306 810c2400010000 or dword ptr [esp],0x100
    7ffe030d 9d popfd
    7ffe030e c3 ret
    7ffe030f 8bd4 mov edx,esp
    7ffe0311 0f05 syscall
    7ffe0313 c3 ret
    7ffe0314 9c pushfd
    7ffe0315 810c2400010000 or dword ptr [esp],0x100
    7ffe031c 9d popfd

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be
    wrong.
    ChildEBP RetAddr Args to Child
    0113fd2c 77f5c524 77e75ee0 00000009 0011a750 *SharedUserSystemCall+0xc (FPO:
    [0,0,0])
    0113fdcc 77d463eb 00000009 0113fdf4 00000000
    ntdll!NtWaitForMultipleObjects+0xc
    0113fe28 77424c73 00000008 0113fe50 ffffffff USER32!SetScrollInfo+0x21f
    0113ff4c 7741bfe7 70aac487 00000000 77f944cb SHELL32!DragAcceptFiles+0x63
    0113ffb4 77e7d33b 00000000 77f944cb 000d0be0 SHELL32!Ordinal753+0x29c
    0113ffec 00000000 70aac3f5 00eff630 00000000
    kernel32!RegisterWaitForInputIdle+0x43

    *----> Raw Stack Dump <----*
    000000000113fd30 24 c5 f5 77 e0 5e e7 77 - 09 00 00 00 50 a7 11 00
    $..w.^.w....P...
    000000000113fd40 01 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000113fd50 09 00 00 00 02 00 00 00 - 00 45 d4 77 25 45 d4 77
    ..........E.w%E.w
    000000000113fd60 00 00 00 00 03 04 00 00 - a8 05 00 00 09 00 00 00
    .................
    000000000113fd70 00 f0 fd 7f 00 70 fd 7f - 00 00 00 00 00 00 00 00
    ......p..........
    000000000113fd80 d0 fd 13 01 a3 5d f7 77 - 90 fd 13 01 18 00 00 00
    ......].w........
    000000000113fd90 88 94 50 00 03 04 00 00 - 50 a7 11 00 00 70 fd 7f
    ...P.....P....p..
    000000000113fda0 14 00 00 00 01 00 00 00 - 90 4f 0b 00 00 00 00 00
    ..........O......
    000000000113fdb0 00 00 00 00 4c fd 13 01 - 00 00 00 00 dc ff 13 01
    .....L...........
    000000000113fdc0 09 48 e9 77 78 32 e8 77 - 00 00 00 00 28 fe 13 01
    ..H.wx2.w....(...
    000000000113fdd0 eb 63 d4 77 09 00 00 00 - f4 fd 13 01 00 00 00 00
    ..c.w............
    000000000113fde0 ff ff ff ff 01 00 00 00 - c0 de 0a 00 08 00 00 00
    .................
    000000000113fdf0 00 00 00 00 44 05 00 00 - b8 05 00 00 dc 05 00 00
    .....D...........
    000000000113fe00 f0 03 00 00 48 03 00 00 - c8 01 00 00 dc 01 00 00
    .....H...........
    000000000113fe10 0c 02 00 00 d4 01 00 00 - 00 00 00 00 01 00 00 00
    .................
    000000000113fe20 00 70 fd 7f d4 01 00 00 - 4c ff 13 01 73 4c 42 77
    ..p......L...sLBw
    000000000113fe30 08 00 00 00 50 fe 13 01 - ff ff ff ff ff 04 00 00
    .....P...........
    000000000113fe40 f4 fd 13 01 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000113fe50 44 05 00 00 b8 05 00 00 - dc 05 00 00 f0 03 00 00
    D...............
    000000000113fe60 48 03 00 00 c8 01 00 00 - dc 01 00 00 0c 02 00 00
    H...............

    *----> State Dump for Thread Id 0xfc4 <----*

    eax=00000000 ebx=00004e20 ecx=0178f3d4 edx=00000000 esi=0178fd6c
    edi=77d43c54
    eip=7ffe0304 esp=0178fcfc ebp=0178fd18 iopl=0 nv up ei pl nz na pe
    nc
    cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
    efl=00000202

    function: <nosymbols>
    7ffe02f2 0000 add [eax],al
    7ffe02f4 0000 add [eax],al
    7ffe02f6 0000 add [eax],al
    *SharedUserSystemCall:
    7ffe02f8 0000 add [eax],al
    7ffe02fa 0000 add [eax],al
    7ffe02fc 0000 add [eax],al
    7ffe02fe 0000 add [eax],al
    7ffe0300 8bd4 mov edx,esp
    7ffe0302 0f34 sysenter
    7ffe0304 c3 ret
    7ffe0305 9c pushfd
    7ffe0306 810c2400010000 or dword ptr [esp],0x100
    7ffe030d 9d popfd
    7ffe030e c3 ret
    7ffe030f 8bd4 mov edx,esp
    7ffe0311 0f05 syscall
    7ffe0313 c3 ret
    7ffe0314 9c pushfd
    7ffe0315 810c2400010000 or dword ptr [esp],0x100
    7ffe031c 9d popfd

    *----> Stack Back Trace <----*
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for
    C:\WINDOWS\System32\stobject.dll -
    WARNING: Stack unwind information not available. Following frames may be
    wrong.
    ChildEBP RetAddr Args to Child
    0178fcf8 77d43a09 77d43c7d 0178fd6c 00000000 *SharedUserSystemCall+0xc (FPO:
    [0,0,0])
    0178fd18 74b01590 0178fd6c 00000000 00000000 USER32+0x3a09
    0178fd90 74b02f1b 74b00000 00000000 00040030 stobject+0x1590
    0178ffb4 77e7d33b 00000000 00000000 00000000 stobject+0x2f1b
    0178ffec 00000000 74b02ed6 00000000 00000000
    kernel32!RegisterWaitForInputIdle+0x43

    *----> Raw Stack Dump <----*
    000000000178fcfc 09 3a d4 77 7d 3c d4 77 - 6c fd 78 01 00 00 00 00
    ..:.w}<.wl.x.....
    000000000178fd0c 00 00 00 00 00 00 00 00 - 00 00 00 00 90 fd 78 01
    ...............x.
    000000000178fd1c 90 15 b0 74 6c fd 78 01 - 00 00 00 00 00 00 00 00
    ....tl.x.........
    000000000178fd2c 00 00 00 00 00 00 00 00 - 00 00 b0 74 00 00 00 00
    ............t....
    000000000178fd3c 30 00 00 00 00 40 00 00 - f0 12 b0 74 00 00 00 00
    0....@.....t....
    000000000178fd4c 1e 00 00 00 00 00 b0 74 - a7 00 1a 00 11 00 01 00
    ........t........
    000000000178fd5c 10 00 00 00 00 00 00 00 - f4 31 b0 74 00 00 00 00
    ..........1.t....
    000000000178fd6c 00 00 00 00 13 01 00 00 - bd 5a 00 00 29 64 d3 75
    ..........Z..)d.u
    000000000178fd7c a9 e9 f2 05 82 02 00 00 - b1 01 00 00 00 00 00 00
    .................
    000000000178fd8c 00 00 00 00 b4 ff 78 01 - 1b 2f b0 74 00 00 b0 74
    .......x../.t...t
    000000000178fd9c 00 00 00 00 30 00 04 00 - 01 00 00 00 00 00 00 00
    .....0...........
    000000000178fdac 43 00 3a 00 5c 00 57 00 - 49 00 4e 00 44 00 4f 00
    C.:.\.W.I.N.D.O.
    000000000178fdbc 57 00 53 00 5c 00 53 00 - 79 00 73 00 74 00 65 00
    W.S.\.S.y.s.t.e.
    000000000178fdcc 6d 00 33 00 32 00 5c 00 - 73 00 74 00 6f 00 62 00
    m.3.2.\.s.t.o.b.
    000000000178fddc 6a 00 65 00 63 00 74 00 - 2e 00 64 00 6c 00 6c 00
    j.e.c.t...d.l.l.
    000000000178fdec 00 00 00 00 00 02 00 00 - fc ff 78 01 23 00 00 00
    ...........x.#...
    000000000178fdfc 00 ef e7 e1 70 ef e7 e1 - 58 93 f4 e1 28 ef e7 e1
    .....p...X...(...
    000000000178fe0c 00 00 00 00 f4 8a e6 f0 - f4 8a e6 f0 b8 69 1b 81
    ..............i..
    000000000178fe1c 94 8c e6 f0 c0 23 6b 80 - 46 02 00 00 00 f7 d7 cc
    ......#k.F.......
    000000000178fe2c 7d 0b 53 80 01 c4 4e 80 - d1 00 00 00 01 00 00
    0 }.S...N.........

    *----> State Dump for Thread Id 0xf44 <----*

    eax=00000000 ebx=00132568 ecx=772be190 edx=00000000 esi=00000100
    edi=00000000
    eip=7ffe0304 esp=017cfe28 ebp=017cff90 iopl=0 nv up ei pl nz na pe
    nc
    cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
    efl=00000202

    function: <nosymbols>
    7ffe02f2 0000 add [eax],al
    7ffe02f4 0000 add [eax],al
    7ffe02f6 0000 add [eax],al
    *SharedUserSystemCall:
    7ffe02f8 0000 add [eax],al
    7ffe02fa 0000 add [eax],al
    7ffe02fc 0000 add [eax],al
    7ffe02fe 0000 add [eax],al
    7ffe0300 8bd4 mov edx,esp
    7ffe0302 0f34 sysenter
    7ffe0304 c3 ret
    7ffe0305 9c pushfd
    7ffe0306 810c2400010000 or dword ptr [esp],0x100
    7ffe030d 9d popfd
    7ffe030e c3 ret
    7ffe030f 8bd4 mov edx,esp
    7ffe0311 0f05 syscall
    7ffe0313 c3 ret
    7ffe0314 9c pushfd
    7ffe0315 810c2400010000 or dword ptr [esp],0x100
    7ffe031c 9d popfd

    *----> Stack Back Trace <----*
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for
    C:\WINDOWS\system32\RPCRT4.dll -
    WARNING: Stack unwind information not available. Following frames may be
    wrong.
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for
    C:\WINDOWS\system32\GDI32.dll -
    ChildEBP RetAddr Args to Child
    017cfe24 77f5c084 780016a4 00000164 017cff80 *SharedUserSystemCall+0xc (FPO:
    [0,0,0])
    017cff90 78001601 780019d4 000a02d0 00813770
    ntdll!NtReplyWaitReceivePortEx+0xc
    000da038 ffffffff 000003c4 000003b4 00000000 RPCRT4+0x1601
    00000000 00000000 00000000 00000000 00000000 0xffffffff

    *----> Raw Stack Dump <----*
    00000000017cfe28 84 c0 f5 77 a4 16 00 78 - 64 01 00 00 80 ff 7c 01
    ....w...xd.....|.
    00000000017cfe38 00 00 00 00 68 25 13 00 - 60 ff 7c 01 70 00 68 00
    .....h%..`.|.p.h.
    00000000017cfe48 00 00 00 00 a0 ff ff ff - 6e 6b 20 00 2c ff 27 f2
    .........nk .,.'.
    00000000017cfe58 39 5b c4 01 00 00 00 00 - 90 4a 1f 00 00 00 00 00
    9[.......J......
    00000000017cfe68 00 00 00 00 ff ff ff ff - ff ff ff ff 02 00 00 00
    .................
    00000000017cfe78 28 4c 1f 00 39 22 00 00 - ff ff ff ff 00 00 00 00
    (L..9"..........
    00000000017cfe88 00 00 00 00 1c 00 00 00 - 3c 00 00 00 00 00 00 00
    .........<.......
    00000000017cfe98 0e 00 00 00 49 6e 50 72 - 6f 63 53 65 72 76 65 72
    .....InProcServer
    00000000017cfea8 33 32 00 00 e8 ff ff ff - 76 6b 00 00 3c 00 00 00
    32......vk..<...
    00000000017cfeb8 a8 4b 1f 00 01 00 00 00 - 00 00 00 00 c0 ff ff ff
    ..K..............
    00000000017cfec8 43 00 3a 00 5c 00 57 00 - 49 00 4e 00 44 00 4f 00
    C.:.\.W.I.N.D.O.
    00000000017cfed8 57 00 53 00 5c 00 53 00 - 79 00 73 00 74 00 65 00
    W.S.\.S.y.s.t.e.
    00000000017cfee8 6d 00 33 00 32 00 5c 00 - 64 00 6d 00 69 00 6d 00
    m.3.2.\.d.m.i.m.
    00000000017cfef8 65 00 2e 00 64 00 6c 00 - 6c 00 00 00 f8 ff ff ff
    e...d.l.l.......
    00000000017cff08 a0 4c 1f 00 d8 ff ff ff - 76 6b 0e 00 0a 00 00 00
    ..L......vk......
    00000000017cff18 18 4c 1f 00 01 00 00 00 - f4 cc 54 ff 53 51 4f 80
    ..L........T.SQO.
    00000000017cff28 5b 51 4f 80 c4 cc 54 ff - 58 cb 54 ff c3 67 61 80
    [QO...T.X.T..ga.
    00000000017cff38 e0 59 1a 81 58 cb 54 ff - 2f 16 00 78 60 ff 7c 01
    ..Y..X.T./..x`.|.
    00000000017cff48 4a 16 00 78 88 01 0a 00 - 88 cc 0c 00 38 a0 0d 00
    J..x........8...
    00000000017cff58 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff
    .../M.....]......

    *----> State Dump for Thread Id 0xab8 <----*

    eax=72d22ecc ebx=0208ff1c ecx=000000fa edx=00000000 esi=00000000
    edi=7ffdf000
    eip=7ffe0304 esp=0208fed4 ebp=0208ff70 iopl=0 nv up ei pl nz na pe
    nc
    cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
    efl=00000202

    function: <nosymbols>
    7ffe02f2 0000 add [eax],al
    7ffe02f4 0000 add [eax],al
    7ffe02f6 0000 add [eax],al
    *SharedUserSystemCall:
    7ffe02f8 0000 add [eax],al
    7ffe02fa 0000 add [eax],al
    7ffe02fc 0000 add [eax],al
    7ffe02fe 0000 add [eax],al
    7ffe0300 8bd4 mov edx,esp
    7ffe0302 0f34 sysenter
    7ffe0304 c3 ret
    7ffe0305 9c pushfd
    7ffe0306 810c2400010000 or dword ptr [esp],0x100
    7ffe030d 9d popfd
    7ffe030e c3 ret
    7ffe030f 8bd4 mov edx,esp
    7ffe0311 0f05 syscall
    7ffe0313 c3 ret
    7ffe0314 9c pushfd
    7ffe0315 810c2400010000 or dword ptr [esp],0x100
    7ffe031c 9d popfd

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be
    wrong.
    ChildEBP RetAddr Args to Child
    0208fed0 77f5c524 77e75ee0 00000002 0208ff1c *SharedUserSystemCall+0xc (FPO:
    [0,0,0])
    0208ff70 77e75faa 00000002 0208ffa4 00000000
    ntdll!NtWaitForMultipleObjects+0xc
    0208ffb4 77e7d33b 00000000 00000021 41f59037
    kernel32!WaitForMultipleObjects+0x17
    0208ffec 00000000 72d22ecc 00000000 00000000
    kernel32!RegisterWaitForInputIdle+0x43

    *----> Raw Stack Dump <----*
    000000000208fed4 24 c5 f5 77 e0 5e e7 77 - 02 00 00 00 1c ff 08 02
    $..w.^.w........
    000000000208fee4 01 00 00 00 00 00 00 00 - 00 00 00 00 21 00 00 00
    .............!...
    000000000208fef4 00 00 00 00 00 00 00 00 - ff ff ff ff 88 5c 12 f0
    ..............\..
    000000000208ff04 00 00 00 00 00 80 00 00 - 48 33 99 ff 02 00 00 00
    .........H3......
    000000000208ff14 00 f0 fd 7f 00 60 fd 7f - 7c 03 00 00 c0 02 00 00
    ......`..|.......
    000000000208ff24 53 51 4f 80 5b 51 4f 80 - 8c 31 67 ff 20 30 67 ff
    SQO.[QO..1g. 0g.
    000000000208ff34 c3 67 61 80 e0 59 1a 81 - 1c ff 08 02 00 60 fd 7f
    ..ga..Y.......`..
    000000000208ff44 14 00 00 00 01 00 00 00 - 20 cc 12 00 00 00 00 00
    ......... .......
    000000000208ff54 00 00 00 00 f0 fe 08 02 - 00 00 00 00 dc ff 08 02
    .................
    000000000208ff64 09 48 e9 77 78 32 e8 77 - 00 00 00 00 b4 ff 08 02
    ..H.wx2.w........
    000000000208ff74 aa 5f e7 77 02 00 00 00 - a4 ff 08 02 00 00 00 00
    .._.w............
    000000000208ff84 ff ff ff ff 00 00 00 00 - 0c 2f d2 72 02 00 00 00
    ........../.r....
    000000000208ff94 a4 ff 08 02 00 00 00 00 - ff ff ff ff 37 90 f5 41
    .............7..A
    000000000208ffa4 7c 03 00 00 c0 02 00 00 - a8 5c 12 f0 f4 bf f5 77
    |........\.....w
    000000000208ffb4 ec ff 08 02 3b d3 e7 77 - 00 00 00 00 21 00 00 00
    .....;..w....!...
    000000000208ffc4 37 90 f5 41 00 00 00 00 - 08 00 20 00 00 60 fd 7f
    7..A...... ..`..
    000000000208ffd4 c0 ff 08 02 07 00 00 00 - ff ff ff ff 09 48 e9 77
    ..............H.w
    000000000208ffe4 b8 3d e8 77 00 00 00 00 - 00 00 00 00 00 00 00 00
    ..=.w............
    000000000208fff4 cc 2e d2 72 00 00 00 00 - 00 00 00 00 00 00 00 00
    ....r............
    0000000002090004 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................

    *----> State Dump for Thread Id 0xd6c <----*

    eax=00000001 ebx=00000584 ecx=00000007 edx=00000000 esi=020cff98
    edi=77d44377
    eip=7ffe0304 esp=020cff54 ebp=020cff78 iopl=0 nv up ei pl nz na pe
    nc
    cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
    efl=00000202

    function: <nosymbols>
    7ffe02f2 0000 add [eax],al
    7ffe02f4 0000 add [eax],al
    7ffe02f6 0000 add [eax],al
    *SharedUserSystemCall:
    7ffe02f8 0000 add [eax],al
    7ffe02fa 0000 add [eax],al
    7ffe02fc 0000 add [eax],al
    7ffe02fe 0000 add [eax],al
    7ffe0300 8bd4 mov edx,esp
    7ffe0302 0f34 sysenter
    7ffe0304 c3 ret
    7ffe0305 9c pushfd
    7ffe0306 810c2400010000 or dword ptr [esp],0x100
    7ffe030d 9d popfd
    7ffe030e c3 ret
    7ffe030f 8bd4 mov edx,esp
    7ffe0311 0f05 syscall
    7ffe0313 c3 ret
    7ffe0314 9c pushfd
    7ffe0315 810c2400010000 or dword ptr [esp],0x100
    7ffe031c 9d popfd

    *----> Stack Back Trace <----*
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for
    C:\WINDOWS\System32\WINMM.dll -
    WARNING: Stack unwind information not available. Following frames may be
    wrong.
    ChildEBP RetAddr Args to Child
    020cff50 77d43a09 77d443b5 020cff98 00000000 *SharedUserSystemCall+0xc (FPO:
    [0,0,0])
    020cff78 76b41c79 020cff98 00000000 00000000 USER32+0x3a09
    020cffb4 77e7d33b 00000584 00010003 00080000 WINMM!timeGetTime+0x1a1
    020cffec 00000000 76b41c14 00000584 00000000
    kernel32!RegisterWaitForInputIdle+0x43

    *----> Raw Stack Dump <----*
    00000000020cff54 09 3a d4 77 b5 43 d4 77 - 98 ff 0c 02 00 00 00 00
    ..:.w.C.w........
    00000000020cff64 00 00 00 00 00 00 00 00 - 84 05 00 00 77 43 d4 77
    .............wC.w
    00000000020cff74 00 00 00 00 b4 ff 0c 02 - 79 1c b4 76 98 ff 0c 02
    .........y..v....
    00000000020cff84 00 00 00 00 00 00 00 00 - 00 00 00 00 03 00 01 00
    .................
    00000000020cff94 00 00 08 00 46 01 2b 00 - cf c0 00 00 00 00 00 00
    .....F.+.........
    00000000020cffa4 00 00 00 00 4c 35 ef 05 - 2b 02 00 00 db 01 00 00
    .....L5..+.......
    00000000020cffb4 ec ff 0c 02 3b d3 e7 77 - 84 05 00 00 03 00 01 00
    .....;..w........
    00000000020cffc4 00 00 08 00 84 05 00 00 - e0 8c e6 f0 00 50 fd 7f
    ..............P..
    00000000020cffd4 c0 ff 0c 02 07 00 00 00 - ff ff ff ff 09 48 e9 77
    ..............H.w
    00000000020cffe4 b8 3d e8 77 00 00 00 00 - 00 00 00 00 00 00 00 00
    ..=.w............
    00000000020cfff4 14 1c b4 76 84 05 00 00 - 00 00 00 00 4d 5a 90 00
    ....v........MZ..
    00000000020d0004 03 00 00 00 04 00 00 00 - ff ff 00 00 b8 00 00 00
    .................
    00000000020d0014 00 00 00 00 40 00 00 00 - 00 00 00 00 00 00 00 00
    .....@...........
    00000000020d0024 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    00000000020d0034 00 00 00 00 00 00 00 00 - f8 00 00 00 0e 1f ba 0e
    .................
    00000000020d0044 00 b4 09 cd 21 b8 01 4c - cd 21 54 68 69 73 20 70
    .....!..L.!This p
    00000000020d0054 72 6f 67 72 61 6d 20 63 - 61 6e 6e 6f 74 20 62 65 rogram
    cannot be
    00000000020d0064 20 72 75 6e 20 69 6e 20 - 44 4f 53 20 6d 6f 64 65 run in
    DOS mode
    00000000020d0074 2e 0d 0d 0a 24 00 00 00 - 00 00 00 00 33 ed b4 8e
    .....$.......3...
    00000000020d0084 77 8c da dd 77 8c da dd - 77 8c da dd 0c 90 d6 dd
    w...w...w.......

    *----> State Dump for Thread Id 0xa30 <----*

    eax=00000000 ebx=0221ff18 ecx=7ffac000 edx=00000000 esi=00000000
    edi=7ffdf000
    eip=7ffe0304 esp=0221fed0 ebp=0221ff6c iopl=0 nv up ei pl nz na pe
    nc
    cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
    efl=00000202

    function: <nosymbols>
    7ffe02f2 0000 add [eax],al
    7ffe02f4 0000 add [eax],al
    7ffe02f6 0000 add [eax],al
    *SharedUserSystemCall:
    7ffe02f8 0000 add [eax],al
    7ffe02fa 0000 add [eax],al
    7ffe02fc 0000 add [eax],al
    7ffe02fe 0000 add [eax],al
    7ffe0300 8bd4 mov edx,esp
    7ffe0302 0f34 sysenter
    7ffe0304 c3 ret
    7ffe0305 9c pushfd
    7ffe0306 810c2400010000 or dword ptr [esp],0x100
    7ffe030d 9d popfd
    7ffe030e c3 ret
    7ffe030f 8bd4 mov edx,esp
    7ffe0311 0f05 syscall
    7ffe0313 c3 ret
    7ffe0314 9c pushfd
    7ffe0315 810c2400010000 or dword ptr [esp],0x100
    7ffe031c 9d popfd

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be
    wrong.
    ChildEBP RetAddr Args to Child
    0221fecc 77f5c524 77e75ee0 00000003 0221ff18 *SharedUserSystemCall+0xc (FPO:
    [0,0,0])
    0221ff6c 77e75faa 00000003 75b03300 00000000
    ntdll!NtWaitForMultipleObjects+0xc
    00000000 00000000 00000000 00000000 00000000
    kernel32!WaitForMultipleObjects+0x17

    *----> Raw Stack Dump <----*
    000000000221fed0 24 c5 f5 77 e0 5e e7 77 - 03 00 00 00 18 ff 21 02
    $..w.^.w......!.
    000000000221fee0 01 00 00 00 00 00 00 00 - 00 00 00 00 a4 33 b0 75
    ..............3.u
    000000000221fef0 00 00 00 00 f0 a6 e7 77 - 00 00 00 00 00 00 00 00
    ........w........
    000000000221ff00 00 00 00 00 00 00 01 00 - 00 00 08 00 03 00 00 00
    .................
    000000000221ff10 00 f0 fd 7f 00 c0 fa 7f - 8c 06 00 00 90 06 00 00
    .................
    000000000221ff20 b8 06 00 00 37 90 f5 77 - 2e d9 e7 77 00 00 08 00
    .....7..w...w....
    000000000221ff30 00 00 00 00 3e d9 e7 77 - 18 ff 21 02 00 00 08 00
    .....>..w..!.....
    000000000221ff40 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000221ff50 10 00 00 00 ec fe 21 02 - 16 00 18 00 dc ff 21 02
    .......!.......!.
    000000000221ff60 09 48 e9 77 78 32 e8 77 - 00 00 00 00 00 00 00 00
    ..H.wx2.w........
    000000000221ff70 aa 5f e7 77 03 00 00 00 - 00 33 b0 75 00 00 00 00
    .._.w.....3.u....
    000000000221ff80 ff ff ff ff 00 00 00 00 - 45 5b a7 75 03 00 00 00
    .........E[.u....
    000000000221ff90 00 33 b0 75 00 00 00 00 - ff ff ff ff 00 00 08 00
    ..3.u............
    000000000221ffa0 00 00 00 00 6c d1 ef 00 - ec ff 21 02 00 00 00 00
    .....l.....!.....
    000000000221ffb0 03 00 00 00 00 00 a7 75 - 3b d3 e7 77 00 00 00 00
    ........u;..w....
    000000000221ffc0 6c d1 ef 00 00 00 08 00 - 00 00 00 00 00 00 00 00
    l...............
    000000000221ffd0 00 c0 fa 7f c0 ff 21 02 - 07 00 00 00 ff ff ff ff
    .......!.........
    000000000221ffe0 09 48 e9 77 b8 3d e8 77 - 00 00 00 00 00 00 00 00
    ..H.w.=.w........
    000000000221fff0 00 00 00 00 ea 5a a7 75 - 00 00 00 00 00 00 00 00
    ......Z.u........
    0000000002220000 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................

    *----> State Dump for Thread Id 0x70c <----*

    eax=00161798 ebx=000a0214 ecx=05eb6875 edx=00000000 esi=01df15e0
    edi=000a0188
    eip=7ffe0304 esp=0240ff7c ebp=0240ff94 iopl=0 nv up ei pl nz na pe
    nc
    cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
    efl=00000202

    function: <nosymbols>
    7ffe02f2 0000 add [eax],al
    7ffe02f4 0000 add [eax],al
    7ffe02f6 0000 add [eax],al
    *SharedUserSystemCall:
    7ffe02f8 0000 add [eax],al
    7ffe02fa 0000 add [eax],al
    7ffe02fc 0000 add [eax],al
    7ffe02fe 0000 add [eax],al
    7ffe0300 8bd4 mov edx,esp
    7ffe0302 0f34 sysenter
    7ffe0304 c3 ret
    7ffe0305 9c pushfd
    7ffe0306 810c2400010000 or dword ptr [esp],0x100
    7ffe030d 9d popfd
    7ffe030e c3 ret
    7ffe030f 8bd4 mov edx,esp
    7ffe0311 0f05 syscall
    7ffe0313 c3 ret
    7ffe0314 9c pushfd
    7ffe0315 810c2400010000 or dword ptr [esp],0x100
    7ffe031c 9d popfd

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be
    wrong.
    ChildEBP RetAddr Args to Child
    0240ff78 77f5b7f4 78001aa3 00000001 0240ff8c *SharedUserSystemCall+0xc (FPO:
    [0,0,0])
    0240ff94 78001a21 00007530 00000018 00003000 ntdll!ZwDelayExecution+0xc
    001720d0 ffffffff 00000774 00000618 00000000 RPCRT4+0x1a21
    00000000 00000000 00000000 00000000 00000000 0xffffffff

    *----> Raw Stack Dump <----*
    000000000240ff7c f4 b7 f5 77 a3 1a 00 78 - 01 00 00 00 8c ff 40 02
    ....w...x......@.
    000000000240ff8c 00 5d 1e ee ff ff ff ff - d0 20 17 00 21 1a 00 78
    ..]....... ..!..x
    000000000240ff9c 30 75 00 00 18 00 00 00 - 00 30 00 00 ec ff 40 02
    0u.......0....@.
    000000000240ffac d0 20 17 00 f3 15 00 78 - 30 75 00 00 3b d3 e7 77 .
    ......x0u..;..w
    000000000240ffbc d0 20 17 00 18 00 00 00 - 00 30 00 00 d0 20 17 00 .
    ........0... ..
    000000000240ffcc 00 00 00 00 00 40 fd 7f - c0 ff 40 02 07 00 00 00
    ......@....@.....
    000000000240ffdc ff ff ff ff 09 48 e9 77 - b8 3d e8 77 00 00 00 00
    ......H.w.=.w....
    000000000240ffec 00 00 00 00 00 00 00 00 - dd 15 00 78 d0 20 17 00
    ............x. ..
    000000000240fffc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000241000c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000241001c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000241002c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000241003c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000241004c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000241005c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000241006c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000241007c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000241008c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000241009c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    00000000024100ac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................

    *----> State Dump for Thread Id 0x85c <----*

    eax=00000000 ebx=00135e78 ecx=000b1794 edx=00000000 esi=00000100
    edi=00000000
    eip=7ffe0304 esp=021cfe28 ebp=021cff90 iopl=0 nv up ei pl nz na pe
    nc
    cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
    efl=00000202

    function: <nosymbols>
    7ffe02f2 0000 add [eax],al
    7ffe02f4 0000 add [eax],al
    7ffe02f6 0000 add [eax],al
    *SharedUserSystemCall:
    7ffe02f8 0000 add [eax],al
    7ffe02fa 0000 add [eax],al
    7ffe02fc 0000 add [eax],al
    7ffe02fe 0000 add [eax],al
    7ffe0300 8bd4 mov edx,esp
    7ffe0302 0f34 sysenter
    7ffe0304 c3 ret
    7ffe0305 9c pushfd
    7ffe0306 810c2400010000 or dword ptr [esp],0x100
    7ffe030d 9d popfd
    7ffe030e c3 ret
    7ffe030f 8bd4 mov edx,esp
    7ffe0311 0f05 syscall
    7ffe0313 c3 ret
    7ffe0314 9c pushfd
    7ffe0315 810c2400010000 or dword ptr [esp],0x100
    7ffe031c 9d popfd

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be
    wrong.
    ChildEBP RetAddr Args to Child
    021cfe24 77f5c084 780016a4 00000164 021cff80 *SharedUserSystemCall+0xc (FPO:
    [0,0,0])
    021cff90 78001601 780019d4 000a02d0 00000000
    ntdll!NtReplyWaitReceivePortEx+0xc
    01dd2f08 ffffffff 00000178 00000628 00000000 RPCRT4+0x1601
    00000000 00000000 00000000 00000000 00000000 0xffffffff

    *----> Raw Stack Dump <----*
    00000000021cfe28 84 c0 f5 77 a4 16 00 78 - 64 01 00 00 80 ff 1c 02
    ....w...xd.......
    00000000021cfe38 00 00 00 00 78 5e 13 00 - 60 ff 1c 02 f0 6c 5e 80
    .....x^..`....l^.
    00000000021cfe48 0e 84 59 80 40 b0 2e 81 - 90 2a 18 81 78 2a 18 81
    ...Y.@....*..x*..
    00000000021cfe58 0b 0c 00 00 0a 0c 00 00 - 94 b0 2e 81 00 00 00 00
    .................
    00000000021cfe68 00 00 00 00 ad 8b 00 00 - 70 eb 31 81 00 00 00 00
    .........p.1.....
    00000000021cfe78 93 3a 53 80 38 22 00 00 - a0 d2 54 ff 2e 36 5e 80
    ..:S.8"....T..6^.
    00000000021cfe88 88 b5 4f e1 d8 02 00 00 - 40 b0 2e 81 88 b5 4f e1
    ...O.....@.....O.
    00000000021cfe98 78 2a 18 81 d8 02 00 00 - 00 00 00 00 9c b5 4f e1
    x*............O.
    00000000021cfea8 b0 c5 72 e1 79 2a 18 81 - b4 db 14 f0 10 3d 5e 80
    ...r.y*.......=^.
    00000000021cfeb8 88 b5 4f e1 b0 c5 72 e1 - 40 b0 2e 81 03 00 1f 00
    ...O...r.@.......
    00000000021cfec8 78 2a 18 81 d8 02 00 00 - fc db 14 f0 bb 89 59 80
    x*............Y.
    00000000021cfed8 88 b5 4f e1 00 00 00 00 - a8 f4 47 ff 00 00 00 00
    ...O.......G.....
    00000000021cfee8 78 2a 18 81 08 dc 14 f0 - 04 00 00 00 00 00 00 00
    x*..............
    00000000021cfef8 c8 b1 52 ff bc 4a 9e ff - c0 00 00 00 78 2a 18 81
    ...R..J......x*..
    00000000021cff08 03 00 1f 00 78 2a 18 81 - 88 b5 4f e1 2c dc 00 00
    .....x*....O.,...
    00000000021cff18 90 dc 14 f0 f7 d6 59 80 - b4 ac 50 ff 53 51 4f 80
    .......Y...P.SQO.
    00000000021cff28 5b 51 4f 80 84 ac 50 ff - 18 ab 50 ff c3 67 61 80
    [QO...P...P..ga.
    00000000021cff38 e0 59 1a 81 18 ab 50 ff - 2f 16 00 78 60 ff 1c 02
    ..Y....P./..x`...
    00000000021cff48 4a 16 00 78 88 01 0a 00 - 38 5c 16 00 08 2f dd 01
    J..x....8\.../..
    00000000021cff58 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff
    .../M.....]......

    *----> State Dump for Thread Id 0xfc0 <----*

    eax=00000fc0 ebx=00000000 ecx=7ffae000 edx=00000000 esi=77fc59a0
    edi=77fc59fc
    eip=7ffe0304 esp=00f7ff70 ebp=00f7ffb4 iopl=0 nv up ei pl nz na pe
    nc
    cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
    efl=00000202

    function: <nosymbols>
    7ffe02f2 0000 add [eax],al
    7ffe02f4 0000 add [eax],al
    7ffe02f6 0000 add [eax],al
    *SharedUserSystemCall:
    7ffe02f8 0000 add [eax],al
    7ffe02fa 0000 add [eax],al
    7ffe02fc 0000 add [eax],al
    7ffe02fe 0000 add [eax],al
    7ffe0300 8bd4 mov edx,esp
    7ffe0302 0f34 sysenter
    7ffe0304 c3 ret
    7ffe0305 9c pushfd
    7ffe0306 810c2400010000 or dword ptr [esp],0x100
    7ffe030d 9d popfd
    7ffe030e c3 ret
    7ffe030f 8bd4 mov edx,esp
    7ffe0311 0f05 syscall
    7ffe0313 c3 ret
    7ffe0314 9c pushfd
    7ffe0315 810c2400010000 or dword ptr [esp],0x100
    7ffe031c 9d popfd

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be
    wrong.
    ChildEBP RetAddr Args to Child
    00f7ff6c 77f5c024 77f95b41 000001a8 00f7ffac *SharedUserSystemCall+0xc (FPO:
    [0,0,0])
    00f7ffb4 77e7d33b 00000000 00000000 00000000 ntdll!ZwRemoveIoCompletion+0xc
    00f7ffec 00000000 77f95b06 00000000 00000000
    kernel32!RegisterWaitForInputIdle+0x43

    *----> Raw Stack Dump <----*
    0000000000f7ff70 24 c0 f5 77 41 5b f9 77 - a8 01 00 00 ac ff f7 00
    $..wA[.w........
    0000000000f7ff80 b0 ff f7 00 98 ff f7 00 - a0 ff f7 00 00 00 00 00
    .................
    0000000000f7ff90 00 00 00 00 00 00 00 00 - 00 00 00 00 a0 5f dc 01
    .............._..
    0000000000f7ffa0 00 7c 28 e8 ff ff ff ff - 98 ae 4f 80 26 61 f9 77
    ..|(.......O.&a.w
    0000000000f7ffb0 68 a0 dc 01 ec ff f7 00 - 3b d3 e7 77 00 00 00 00
    h.......;..w....
    0000000000f7ffc0 00 00 00 00 00 00 00 00 - 00 00 00 00 08 00 20 00
    ............... .
    0000000000f7ffd0 00 e0 fa 7f c0 ff f7 00 - 07 00 00 00 ff ff ff ff
    .................
    0000000000f7ffe0 09 48 e9 77 b8 3d e8 77 - 00 00 00 00 00 00 00 00
    ..H.w.=.w........
    0000000000f7fff0 00 00 00 00 06 5b f9 77 - 00 00 00 00 00 00 00 00
    ......[.w........
    0000000000f80000 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000f80010 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000f80020 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000f80030 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000f80040 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000f80050 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000f80060 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000f80070 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000f80080 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000f80090 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000f800a0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................

    *----> State Dump for Thread Id 0x94c <----*

    eax=024aff64 ebx=00007530 ecx=77f60336 edx=00000000 esi=00000000
    edi=024aff60
    eip=7ffe0304 esp=024aff20 ebp=024aff78 iopl=0 nv up ei pl nz na pe
    nc
    cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
    efl=00000202

    function: <nosymbols>
    7ffe02f2 0000 add [eax],al
    7ffe02f4 0000 add [eax],al
    7ffe02f6 0000 add [eax],al
    *SharedUserSystemCall:
    7ffe02f8 0000 add [eax],al
    7ffe02fa 0000 add [eax],al
    7ffe02fc 0000 add [eax],al
    7ffe02fe 0000 add [eax],al
    7ffe0300 8bd4 mov edx,esp
    7ffe0302 0f34 sysenter
    7ffe0304 c3 ret
    7ffe0305 9c pushfd
    7ffe0306 810c2400010000 or dword ptr [esp],0x100
    7ffe030d 9d popfd
    7ffe030e c3 ret
    7ffe030f 8bd4 mov edx,esp
    7ffe0311 0f05 syscall
    7ffe0313 c3 ret
    7ffe0314 9c pushfd
    7ffe0315 810c2400010000 or dword ptr [esp],0x100
    7ffe031c 9d popfd

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be
    wrong.
    ChildEBP RetAddr Args to Child
    024aff1c 77f5b7f4 77e7a37a 00000000 024aff44 *SharedUserSystemCall+0xc (FPO:
    [0,0,0])
    024aff78 77e61bf5 0000ea60 00000000 771c15f8 ntdll!ZwDelayExecution+0xc
    00000000 00000000 00000000 00000000 00000000 kernel32!Sleep+0xb

    *----> Raw Stack Dump <----*
    00000000024aff20 f4 b7 f5 77 7a a3 e7 77 - 00 00 00 00 44 ff 4a 02
    ....wz..w....D.J.
    00000000024aff30 a2 a5 e7 77 88 e1 2b 77 - 30 75 00 00 00 00 00 00
    ....w..+w0u......
    00000000024aff40 44 ff 4a 02 00 ba 3c dc - ff ff ff ff 14 00 00 00
    D.J...<.........
    00000000024aff50 01 00 00 00 00 00 00 00 - 00 00 00 00 10 00 00 00
    .................
    00000000024aff60 30 ff 4a 02 12 00 14 00 - dc ff 4a 02 09 48 e9 77
    0.J.......J..H.w
    00000000024aff70 d0 3a e8 77 00 00 00 00 - 00 00 00 00 f5 1b e6 77
    ..:.w...........w
    00000000024aff80 60 ea 00 00 00 00 00 00 - f8 15 1c 77 60 ea 00 00
    `..........w`...
    00000000024aff90 90 2c dd 01 aa 7e 1e 77 - 00 00 00 00 00 00 1b 77
    ..,...~.w.......w
    00000000024affa0 90 2c dd 01 90 2c dd 01 - ec ff 4a 02 09 7f 1e 77
    ..,...,....J....w
    00000000024affb0 00 00 00 00 00 00 00 00 - 3b d3 e7 77 90 2c dd 01
    .........;..w.,..
    00000000024affc0 00 00 00 00 00 00 00 00 - 90 2c dd 01 00 f0 df ff
    ..........,......
    00000000024affd0 00 d0 fd 7f c0 ff 4a 02 - 07 00 00 00 ff ff ff ff
    .......J.........
    00000000024affe0 09 48 e9 77 b8 3d e8 77 - 00 00 00 00 00 00 00 00
    ..H.w.=.w........
    00000000024afff0 00 00 00 00 ef 7e 1e 77 - 90 2c dd 01 00 00 00 00
    ......~.w.,......
    00000000024b0000 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    00000000024b0010 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    00000000024b0020 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    00000000024b0030 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    00000000024b0040 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    00000000024b0050 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................

    *----> State Dump for Thread Id 0xf38 <----*

    eax=780015dd ebx=000f0cd0 ecx=000a02d0 edx=00000000 esi=00000100
    edi=00000000
    eip=7ffe0304 esp=022cfe28 ebp=022cff90 iopl=0 nv up ei pl nz na pe
    nc
    cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
    efl=00000202

    function: <nosymbols>
    7ffe02f2 0000 add [eax],al
    7ffe02f4 0000 add [eax],al
    7ffe02f6 0000 add [eax],al
    *SharedUserSystemCall:
    7ffe02f8 0000 add [eax],al
    7ffe02fa 0000 add [eax],al
    7ffe02fc 0000 add [eax],al
    7ffe02fe 0000 add [eax],al
    7ffe0300 8bd4 mov edx,esp
    7ffe0302 0f34 sysenter
    7ffe0304 c3 ret
    7ffe0305 9c pushfd
    7ffe0306 810c2400010000 or dword ptr [esp],0x100
    7ffe030d 9d popfd
    7ffe030e c3 ret
    7ffe030f 8bd4 mov edx,esp
    7ffe0311 0f05 syscall
    7ffe0313 c3 ret
    7ffe0314 9c pushfd
    7ffe0315 810c2400010000 or dword ptr [esp],0x100
    7ffe031c 9d popfd

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be
    wrong.
    ChildEBP RetAddr Args to Child
    022cfe24 77f5c084 780016a4 00000164 022cff80 *SharedUserSystemCall+0xc (FPO:
    [0,0,0])
    022cff90 78001601 780019d4 000a02d0 00000000
    ntdll!NtReplyWaitReceivePortEx+0xc
    0017dcd0 ffffffff 00000314 000005a8 00000000 RPCRT4+0x1601
    00000000 00000000 00000000 00000000 00000000 0xffffffff

    *----> Raw Stack Dump <----*
    00000000022cfe28 84 c0 f5 77 a4 16 00 78 - 64 01 00 00 80 ff 2c 02
    ....w...xd.....,.
    00000000022cfe38 00 00 00 00 d0 0c 0f 00 - 60 ff 2c 02 cc 9b 24 f0
    .........`.,...$.
    00000000022cfe48 e5 80 59 80 ff 03 1f 00 - 00 33 31 81 00 00 00 00
    ...Y......31.....
    00000000022cfe58 ce 03 00 00 cd 03 00 00 - 54 33 31 81 00 40 fd 7f
    .........T31..@..
    00000000022cfe68 fc 07 30 c0 00 00 00 00 - ce 01 00 00 00 00 00 00
    ...0.............
    00000000022cfe78 00 00 00 00 00 00 00 00 - 00 00 00 00 a8 cd 3f fb
    ...............?.
    00000000022cfe88 01 00 00 00 d1 3f 51 80 - 00 00 00 00 94 cd 3f fb
    ......?Q.......?.
    00000000022cfe98 0e 40 51 80 00 40 fd 7f - 00 00 00 00 00 00 00 00
    ..@Q..@..........
    00000000022cfea8 e0 b3 52 ff bd 4c ac fa - f7 01 00 00 6c 83 2f 81
    ...R..L......l./.
    00000000022cfeb8 e8 80 2f 81 68 83 2f 81 - 5c bc ac fa 6c 83 2f 81
    .../.h./.\...l./.
    00000000022cfec8 10 4d 29 81 2a ab ac fa - f8 4e 29 81 6c 83 2f 81
    ..M).*....N).l./.
    00000000022cfed8 b0 1e 6b 80 34 d9 53 ff - f8 9b 24 f0 91 59 ac fa
    ...k.4.S...$..Y..
    00000000022cfee8 01 00 00 00 68 83 2f 81 - 00 00 00 00 06 02 00 00
    .....h./.........
    00000000022cfef8 4f 5f 4f 80 48 31 2a 81 - e8 80 2f 81 c0 f9 df ff
    O_O.H1*.../.....
    00000000022cff08 f8 4e 29 05 2c 9c 24 f0 - fe 7f ac fa 00 00 00 00
    ..N).,.$.........
    00000000022cff18 00 00 00 00 00 00 00 00 - 44 cf 3f fb 53 51 4f 80
    .........D.?.SQO.
    00000000022cff28 5b 51 4f 80 14 cf 3f fb - a8 cd 3f fb c3 67 61 80
    [QO...?...?..ga.
    00000000022cff38 e0 59 1a 81 a8 cd 3f fb - 2f 16 00 78 60 ff 2c 02
    ..Y....?./..x`.,.
    00000000022cff48 4a 16 00 78 88 01 0a 00 - 80 95 de 01 d0 dc 17 00
    J..x............
    00000000022cff58 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff
    .../M.....]......




    OK NUMBER 2 IS AS FOLLOWS:



    Application exception occurred:
    App: C:\WINDOWS\Explorer.EXE (pid=248)
    When: 7/7/2004 @ 04:10:27.984
    Exception number: 80000007
    ()

    *----> System Information <----*
    Computer Name: SN027714820049
    User Name: James
    Terminal Session Id: 0
    Number of Processors: 1
    Processor Type: x86 Family 15 Model 2 Stepping 7
    Windows Version: 5.1
    Current Build: 2600
    Service Pack: 1
    Current Type: Uniprocessor Free
    Registered Organization:
    Registered Owner: James

    *----> Task List <----*
    0 System Process
    4 System
    348 smss.exe
    468 csrss.exe
    492 winlogon.exe
    536 services.exe
    548 lsass.exe
    724 svchost.exe
    768 svchost.exe
    880 svchost.exe
    896 svchost.exe
    1008 spoolsv.exe
    1112 alg.exe
    1124 ccProxy.exe
    1144 ccSetMgr.exe
    1184 mdm.exe
    1204 navapsvc.exe
    1268 SAVScan.exe
    1344 slserv.exe
    1364 svchost.exe
    1376 symlcsvc.exe
    1416 ccEvtMgr.exe
    248 Explorer.EXE
    796 khooker.exe
    816 CFD.exe
    888 ccApp.exe
    1780 hpztsb07.exe
    1900 point32.exe
    1936 ctfmon.exe
    2380 msmsgs.exe
    228 SNDSrvc.exe
    4088 realsched.exe
    2696 drwtsn32.exe

    *----> Module List <----*
    (0000000000c40000 - 0000000000c5e000: C:\Program Files\Common Files\Symantec
    Shared\Script Blocking\scrauth.dll
    (0000000000c60000 - 0000000000c80000: C:\Program Files\Common Files\Symantec
    Shared\Script Blocking\ScrBlock.dll
    (0000000001000000 - 00000000010f7000: C:\WINDOWS\Explorer.EXE
    (0000000001500000 - 0000000001518000: C:\Program Files\Norton Internet
    Security\Norton AntiVirus\NavShExt.dll
    (0000000001530000 - 0000000001731000: C:\WINDOWS\System32\msi.dll
    (0000000001e00000 - 0000000001e10000: C:\Program
    Files\SmartFTP\smarthook.dll
    (0000000001ed0000 - 0000000001edc000: C:\Program Files\Adobe\Acrobat
    6.0\Reader\ActiveX\AcroIEHelper.dll
    (00000000021a0000 - 00000000021d2000: C:\WINDOWS\System32\ODBC32.dll
    (0000000007260000 - 0000000007299000: C:\WINDOWS\System32\WMASF.DLL
    (0000000007610000 - 0000000007627000: C:\Program Files\Windows Media
    Player\wmpband.dll
    (0000000007680000 - 0000000007afa000: C:\WINDOWS\System32\wmp.dll
    (0000000008110000 - 00000000083de000: C:\WINDOWS\System32\wmploc.dll
    (00000000083f0000 - 0000000008408000: C:\WINDOWS\System32\wmpshell.dll
    (0000000008530000 - 000000000872d000: C:\WINDOWS\System32\WMVCore.DLL
    (000000000ffd0000 - 000000000fff3000: C:\WINDOWS\System32\rsaenh.dll
    (0000000010000000 - 0000000010030000:
    C:\PROGRA~1\COMMON~1\SYMANT~1\ANTISPAM\asOEHook.dll
    (000000001a400000 - 000000001a47a000: C:\WINDOWS\System32\urlmon.dll
    (000000001f850000 - 000000001f866000: C:\WINDOWS\System32\odbcint.dll
    (00000000559e0000 - 0000000055a51000: C:\WINDOWS\System32\themeui.dll
    (000000005ad70000 - 000000005ada4000: C:\WINDOWS\System32\UxTheme.dll
    (000000005b0a0000 - 000000005b0a7000: C:\WINDOWS\System32\umdmxfrm.dll
    (000000005cad0000 - 000000005caf1000: C:\WINDOWS\System32\shmedia.dll
    (000000005cd70000 - 000000005cd77000: C:\WINDOWS\System32\serwvdrv.dll
    (00000000605d0000 - 00000000605d8000: C:\WINDOWS\System32\mslbui.dll
    (00000000629c0000 - 00000000629c8000: C:\WINDOWS\System32\LPK.DLL
    (0000000063000000 - 0000000063096000: C:\WINDOWS\system32\WININET.dll
    (000000006b700000 - 000000006b790000: c:\windows\system32\jscript.dll
    (000000006c1b0000 - 000000006c1f4000: C:\WINDOWS\System32\DUSER.dll
    (0000000070a70000 - 0000000070ad5000: C:\WINDOWS\system32\SHLWAPI.dll
    (0000000071500000 - 00000000715fd000: C:\WINDOWS\System32\BROWSEUI.dll
    (0000000071700000 - 0000000071849000: C:\WINDOWS\System32\SHDOCVW.dll
    (0000000071950000 - 0000000071a34000:
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0
    ..2600.1331_x-ww_7abf6d02\comctl32.dll
    (0000000071aa0000 - 0000000071aa8000: C:\WINDOWS\system32\WS2HELP.dll
    (0000000071ab0000 - 0000000071ac4000: C:\WINDOWS\system32\WS2_32.dll
    (0000000071ad0000 - 0000000071ad8000: C:\WINDOWS\System32\wsock32.dll
    (0000000071b20000 - 0000000071b31000: C:\WINDOWS\system32\MPR.dll
    (0000000071bf0000 - 0000000071c01000: C:\WINDOWS\System32\SAMLIB.dll
    (0000000071c10000 - 0000000071c1d000: C:\WINDOWS\System32\ntlanman.dll
    (0000000071c20000 - 0000000071c6e000: C:\WINDOWS\System32\NETAPI32.dll
    (0000000071c80000 - 0000000071c86000: C:\WINDOWS\System32\NETRAP.dll
    (0000000071c90000 - 0000000071ccc000: C:\WINDOWS\System32\NETUI1.dll
    (0000000071cd0000 - 0000000071ce6000: C:\WINDOWS\System32\NETUI0.dll
    (0000000071d40000 - 0000000071d5b000: C:\WINDOWS\System32\ACTXPRXY.DLL
    (00000000722b0000 - 00000000722b5000: C:\WINDOWS\System32\sensapi.dll
    (0000000072410000 - 0000000072429000: C:\WINDOWS\System32\mydocs.dll
    (0000000072430000 - 0000000072442000: C:\WINDOWS\System32\browselc.dll
    (0000000072d10000 - 0000000072d18000: C:\WINDOWS\System32\msacm32.drv
    (0000000072d20000 - 0000000072d29000: C:\WINDOWS\System32\wdmaud.drv
    (0000000072fa0000 - 0000000072ffa000: C:\WINDOWS\System32\USP10.dll
    (0000000073000000 - 0000000073023000: C:\WINDOWS\System32\WINSPOOL.DRV
    (0000000073030000 - 000000007303b000: C:\WINDOWS\System32\WZCSAPI.DLL
    (0000000073380000 - 00000000733d2000: C:\WINDOWS\System32\zipfldr.dll
    (0000000073b50000 - 0000000073b65000: C:\WINDOWS\System32\AVIFIL32.dll
    (0000000073bd0000 - 0000000073bf0000: C:\WINDOWS\System32\MSVFW32.dll
    (0000000074720000 - 0000000074764000: C:\WINDOWS\System32\MSCTF.dll
    (0000000074770000 - 00000000747ff000: C:\WINDOWS\System32\mlang.dll
    (0000000074ad0000 - 0000000074ad7000: C:\WINDOWS\System32\POWRPROF.dll
    (0000000074ae0000 - 0000000074ae7000: C:\WINDOWS\System32\CFGMGR32.dll
    (0000000074af0000 - 0000000074af9000: C:\WINDOWS\System32\BatMeter.dll
    (0000000074b00000 - 0000000074b20000: C:\WINDOWS\System32\stobject.dll
    (0000000074b30000 - 0000000074b71000: C:\WINDOWS\System32\webcheck.dll
    (0000000074b80000 - 0000000074c02000: C:\WINDOWS\System32\printui.dll
    (0000000075970000 - 0000000075a62000: C:\WINDOWS\System32\MSGINA.dll
    (0000000075a70000 - 0000000075b15000: C:\WINDOWS\system32\USERENV.dll
    (0000000075cf0000 - 0000000075e81000: C:\WINDOWS\system32\NETSHELL.dll
    (0000000075e90000 - 0000000075f38000: C:\WINDOWS\System32\SXS.DLL
    (0000000075f40000 - 0000000075f5f000: C:\WINDOWS\system32\appHelp.dll
    (0000000075f60000 - 0000000075f66000: C:\WINDOWS\System32\drprov.dll
    (0000000075f70000 - 0000000075f79000: C:\WINDOWS\System32\davclnt.dll
    (0000000076170000 - 00000000761f8000: C:\WINDOWS\System32\shdoclc.dll
    (00000000762a0000 - 00000000762b0000: C:\WINDOWS\system32\MSASN1.dll
    (00000000762c0000 - 0000000076348000: C:\WINDOWS\system32\CRYPT32.dll
    (0000000076360000 - 000000007636f000: C:\WINDOWS\System32\WINSTA.dll
    (0000000076380000 - 0000000076385000: C:\WINDOWS\System32\MSIMG32.dll
    (00000000763b0000 - 00000000763f5000: C:\WINDOWS\system32\comdlg32.dll
    (0000000076600000 - 000000007661b000: C:\WINDOWS\System32\CSCDLL.dll
    (0000000076620000 - 000000007666e000: C:\WINDOWS\System32\cscui.dll
    (0000000076670000 - 0000000076757000: C:\WINDOWS\System32\SETUPAPI.dll
    (0000000076980000 - 0000000076987000: C:\WINDOWS\System32\LINKINFO.dll
    (0000000076990000 - 00000000769b4000: C:\WINDOWS\System32\ntshrui.dll
    (0000000076b20000 - 0000000076b35000: C:\WINDOWS\System32\ATL.DLL
    (0000000076b40000 - 0000000076b6c000: C:\WINDOWS\System32\WINMM.dll
    (0000000076c00000 - 0000000076c2d000: C:\WINDOWS\system32\credui.dll
    (0000000076c30000 - 0000000076c5b000: C:\WINDOWS\System32\WINTRUST.dll
    (0000000076c90000 - 0000000076cb2000: C:\WINDOWS\system32\IMAGEHLP.dll
    (0000000076ce0000 - 0000000076cff000: C:\WINDOWS\System32\NTMARTA.DLL
    (0000000076d40000 - 0000000076d56000: C:\WINDOWS\System32\MPRAPI.dll
    (0000000076d60000 - 0000000076d76000: C:\WINDOWS\system32\iphlpapi.dll
    (0000000076d80000 - 0000000076d9b000: C:\WINDOWS\System32\DHCPCSVC.DLL
    (0000000076e10000 - 0000000076e35000: C:\WINDOWS\System32\adsldpc.dll
    (0000000076e40000 - 0000000076e6f000: C:\WINDOWS\System32\ACTIVEDS.dll
    (0000000076e80000 - 0000000076e8d000: C:\WINDOWS\System32\rtutils.dll
    (0000000076e90000 - 0000000076ea1000: C:\WINDOWS\System32\rasman.dll
    (0000000076eb0000 - 0000000076edb000: C:\WINDOWS\System32\TAPI32.dll
    (0000000076ee0000 - 0000000076f17000: C:\WINDOWS\System32\RASAPI32.DLL
    (0000000076f20000 - 0000000076f45000: C:\WINDOWS\System32\DNSAPI.dll
    (0000000076f50000 - 0000000076f58000: C:\WINDOWS\System32\WTSAPI32.dll
    (0000000076f60000 - 0000000076f8c000: C:\WINDOWS\system32\WLDAP32.dll
    (0000000076f90000 - 0000000076fa0000: C:\WINDOWS\System32\Secur32.dll
    (0000000077050000 - 0000000077115000: C:\WINDOWS\System32\COMRes.dll
    (0000000077120000 - 00000000771ab000: C:\WINDOWS\system32\OLEAUT32.dll
    (00000000771b0000 - 00000000772d4000: C:\WINDOWS\system32\ole32.dll
    (0000000077340000 - 00000000773cb000: C:\WINDOWS\system32\comctl32.dll
    (00000000773d0000 - 0000000077bc9000: C:\WINDOWS\system32\SHELL32.dll
    (0000000077bd0000 - 0000000077bd7000: C:\WINDOWS\System32\midimap.dll
    (0000000077be0000 - 0000000077bf4000: C:\WINDOWS\System32\MSACM32.dll
    (0000000077c00000 - 0000000077c07000: C:\WINDOWS\system32\VERSION.dll
    (0000000077c10000 - 0000000077c63000: C:\WINDOWS\system32\msvcrt.dll
    (0000000077d40000 - 0000000077dcc000: C:\WINDOWS\system32\USER32.dll
    (0000000077dd0000 - 0000000077e5d000: C:\WINDOWS\system32\ADVAPI32.dll
    (0000000077e60000 - 0000000077f46000: C:\WINDOWS\system32\kernel32.dll
    (0000000077f50000 - 0000000077ff7000: C:\WINDOWS\System32\ntdll.dll
    (0000000078000000 - 0000000078087000: C:\WINDOWS\system32\RPCRT4.dll
    (000000007c000000 - 000000007c054000: C:\WINDOWS\System32\MSVCR70.dll
    (000000007c080000 - 000000007c0f7000: C:\WINDOWS\System32\MSVCP70.dll
    (000000007c890000 - 000000007c911000: C:\WINDOWS\System32\CLBCATQ.DLL
    (000000007e090000 - 000000007e0d1000: C:\WINDOWS\system32\GDI32.dll

    *----> State Dump for Thread Id 0xfc <----*

    eax=71722d08 ebx=000c9008 ecx=00000000 edx=00000000 esi=000c9008
    edi=00000000
    eip=7ffe0304 esp=0006fefc ebp=0006ff14 iopl=0 nv up ei pl nz na pe
    nc
    cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
    efl=00000202

    function: <nosymbols>
    7ffe02f2 0000 add [eax],al
    7ffe02f4 0000 add [eax],al
    7ffe02f6 0000 add [eax],al
    *SharedUserSystemCall:
    7ffe02f8 0000 add [eax],al
    7ffe02fa 0000 add [eax],al
    7ffe02fc 0000 add [eax],al
    7ffe02fe 0000 add [eax],al
    7ffe0300 8bd4 mov edx,esp
    7ffe0302 0f34 sysenter
    FAULT ->7ffe0304 c3 ret
    7ffe0305 9c pushfd
    7ffe0306 810c2400010000 or dword ptr [esp],0x100
    7ffe030d 9d popfd
    7ffe030e c3 ret
    7ffe030f 8bd4 mov edx,esp
    7ffe0311 0f05 syscall
    7ffe0313 c3 ret
    7ffe0314 9c pushfd
    7ffe0315 810c2400010000 or dword ptr [esp],0x100
    7ffe031c 9d popfd

    *----> Stack Back Trace <----*
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for
    C:\WINDOWS\system32\USER32.dll -
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for
    C:\WINDOWS\system32\SHELL32.dll -
    WARNING: Stack unwind information not available. Following frames may be
    wrong.
    *** ERROR: Module load completed but symbols could not be loaded for
    C:\WINDOWS\Explorer.EXE
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for
    C:\WINDOWS\system32\kernel32.dll -
    ChildEBP RetAddr Args to Child
    0006fef8 77d43c53 774249e4 77e7a29b 000c9008 *SharedUserSystemCall+0xc (FPO:
    [0,0,0])
    0006ff14 7741aedd 00000000 0100b571 000c9008 USER32!WaitMessage+0xc
    0006ff5c 0100b6af 01000000 00000000 000205e2 SHELL32!Ordinal201+0x24
    0006ffc0 77e814c7 0006e630 00640067 7ffdf000 Explorer+0xb6af
    0006fff0 00000000 0100b644 00000000 78746341
    kernel32!GetCurrentDirectoryW+0x44

    *----> Raw Stack Dump <----*
    000000000006fefc 53 3c d4 77 e4 49 42 77 - 9b a2 e7 77 08 90 0c 00
    S<.w.IBw...w....
    000000000006ff0c 08 90 0c 00 5c ff 06 00 - 5c ff 06 00 dd ae 41 77
    .....\...\.....Aw
    000000000006ff1c 00 00 00 00 71 b5 00 01 - 08 90 0c 00 00 f0 fd 7f
    .....q...........
    000000000006ff2c c0 ff 06 00 00 00 00 00 - 18 ff 06 00 e4 bd f5 77
    ................w
    000000000006ff3c 99 ef e7 77 ff ff ff ff - 0c 00 00 00 84 c2 f5 77
    ....w...........w
    000000000006ff4c 7c ef e7 77 00 00 00 00 - 1e 29 01 00 60 00 00 00
    |..w.....)..`...
    000000000006ff5c c0 ff 06 00 af b6 00 01 - 00 00 00 01 00 00 00 00
    .................
    000000000006ff6c e2 05 02 00 01 00 00 00 - 30 e6 06 00 67 00 64 00
    .........0...g.d.
    000000000006ff7c 44 00 00 00 34 06 02 00 - 14 06 02 00 e4 05 02 00
    D...4...........
    000000000006ff8c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000006ff9c 0d 1c dd 77 44 00 00 00 - c4 f9 06 00 01 00 00 00
    ....wD...........
    000000000006ffac 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000006ffbc 00 00 00 00 f0 ff 06 00 - c7 14 e8 77 30 e6 06 00
    ............w0...
    000000000006ffcc 67 00 64 00 00 f0 fd 7f - f0 dc cd f0 c8 ff 06 00
    g.d.............
    000000000006ffdc 04 45 53 80 ff ff ff ff - 09 48 e9 77 10 12 e9 77
    ..ES......H.w...w
    000000000006ffec 00 00 00 00 00 00 00 00 - 00 00 00 00 44 b6 00 01
    .............D...
    000000000006fffc 00 00 00 00 41 63 74 78 - 20 00 00 00 01 00 00 00
    .....Actx .......
    000000000007000c 4c 06 00 00 7c 00 00 00 - 00 00 00 00 20 00 00 00
    L...|....... ...
    000000000007001c 00 00 00 00 14 00 00 00 - 01 00 00 00 03 00 00 00
    .................
    000000000007002c 34 00 00 00 ac 00 00 00 - 01 00 00 00 00 00 00 00
    4...............

    *----> State Dump for Thread Id 0x22c <----*

    eax=00def800 ebx=77d4546d ecx=00000001 edx=00000000 esi=0103e468
    edi=00000000
    eip=7ffe0304 esp=00deff18 ebp=00deff48 iopl=0 nv up ei pl nz na pe
    nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
    efl=00000202

    function: <nosymbols>
    7ffe02f2 0000 add [eax],al
    7ffe02f4 0000 add [eax],al
    7ffe02f6 0000 add [eax],al
    *SharedUserSystemCall:
    7ffe02f8 0000 add [eax],al
    7ffe02fa 0000 add [eax],al
    7ffe02fc 0000 add [eax],al
    7ffe02fe 0000 add [eax],al
    7ffe0300 8bd4 mov edx,esp
    7ffe0302 0f34 sysenter
    7ffe0304 c3 ret
    7ffe0305 9c pushfd
    7ffe0306 810c2400010000 or dword ptr [esp],0x100
    7ffe030d 9d popfd
    7ffe030e c3 ret
    7ffe030f 8bd4 mov edx,esp
    7ffe0311 0f05 syscall
    7ffe0313 c3 ret
    7ffe0314 9c pushfd
    7ffe0315 810c2400010000 or dword ptr [esp],0x100
    7ffe031c 9d popfd

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be
    wrong.
    ChildEBP RetAddr Args to Child
    00deff14 77d43c53 0101519d 00000000 0103e468 *SharedUserSystemCall+0xc (FPO:
    [0,0,0])
    00deff48 0101a935 00000000 70aac487 0103e468 USER32!WaitMessage+0xc
    00deffb4 77e7d33b 00000000 00000000 00000004 Explorer+0x1a935
    00deffec 00000000 70aac3f5 0006fed8 00000000
    kernel32!RegisterWaitForInputIdle+0x43

    *----> Raw Stack Dump <----*
    0000000000deff18 53 3c d4 77 9d 51 01 01 - 00 00 00 00 68 e4 03 01
    S<.w.Q......h...
    0000000000deff28 00 00 00 00 84 00 01 00 - 13 01 00 00 0a 00 00 00
    .................
    0000000000deff38 00 00 00 00 12 3c 90 00 - 70 02 00 00 b6 01 00 00
    ......<..p.......
    0000000000deff48 b4 ff de 00 35 a9 01 01 - 00 00 00 00 87 c4 aa 70
    .....5..........p
    0000000000deff58 68 e4 03 01 00 00 00 00 - 04 00 00 00 d8 fe 06 00
    h...............
    0000000000deff68 10 a9 01 01 02 c5 01 01 - 5c 01 00 00 68 e4 03 01
    .........\...h...
    0000000000deff78 08 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000deff88 00 00 00 00 01 33 db 43 - 00 00 00 00 a8 5d 12 81
    ......3.C.....]..
    0000000000deff98 78 ab 4f 80 00 00 00 00 - 00 00 00 00 00 00 00 00
    x.O.............
    0000000000deffa8 00 00 00 00 a8 6c d8 f0 - f4 bf f5 77 ec ff de 00
    ......l.....w....
    0000000000deffb8 3b d3 e7 77 00 00 00 00 - 00 00 00 00 04 00 00 00
    ;..w............
    0000000000deffc8 d8 fe 06 00 f8 3b fe 74 - 00 b0 fd 7f c0 ff de 00
    ......;.t........
    0000000000deffd8 07 00 00 00 ff ff ff ff - 09 48 e9 77 b8 3d e8 77
    ..........H.w.=.w
    0000000000deffe8 00 00 00 00 00 00 00 00 - 00 00 00 00 f5 c3 aa 70
    ................p
    0000000000defff8 d8 fe 06 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000df0008 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000df0018 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000df0028 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000df0038 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000df0048 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................

    *----> State Dump for Thread Id 0x25c <----*

    eax=000000c0 ebx=00000000 ecx=00000000 edx=00000000 esi=000a26e8
    edi=70a908d3
    eip=7ffe0304 esp=00e2ff9c ebp=00e2ffb4 iopl=0 nv up ei pl nz na pe
    nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
    efl=00000202

    function: <nosymbols>
    7ffe02f2 0000 add [eax],al
    7ffe02f4 0000 add [eax],al
    7ffe02f6 0000 add [eax],al
    *SharedUserSystemCall:
    7ffe02f8 0000 add [eax],al
    7ffe02fa 0000 add [eax],al
    7ffe02fc 0000 add [eax],al
    7ffe02fe 0000 add [eax],al
    7ffe0300 8bd4 mov edx,esp
    7ffe0302 0f34 sysenter
    7ffe0304 c3 ret
    7ffe0305 9c pushfd
    7ffe0306 810c2400010000 or dword ptr [esp],0x100
    7ffe030d 9d popfd
    7ffe030e c3 ret
    7ffe030f 8bd4 mov edx,esp
    7ffe0311 0f05 syscall
    7ffe0313 c3 ret
    7ffe0314 9c pushfd
    7ffe0315 810c2400010000 or dword ptr [esp],0x100
    7ffe031c 9d popfd

    *----> Stack Back Trace <----*
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for
    C:\WINDOWS\System32\ntdll.dll -
    WARNING: Stack unwind information not available. Following frames may be
    wrong.
    ChildEBP RetAddr Args to Child
    00e2ff98 77f5b7f4 77f88423 00000001 00e2ffac *SharedUserSystemCall+0xc (FPO:
    [0,0,0])
    00e2ffb4 77e7d33b 00000000 70a908d3 000a26e8 ntdll!ZwDelayExecution+0xc
    00e2ffec 00000000 77f883de 00000000 00000000
    kernel32!RegisterWaitForInputIdle+0x43

    *----> Raw Stack Dump <----*
    0000000000e2ff9c f4 b7 f5 77 23 84 f8 77 - 01 00 00 00 ac ff e2 00
    ....w#..w........
    0000000000e2ffac 00 00 00 00 00 00 00 80 - ec ff e2 00 3b d3 e7 77
    .............;..w
    0000000000e2ffbc 00 00 00 00 d3 08 a9 70 - e8 26 0a 00 00 00 00 00
    ........p.&......
    0000000000e2ffcc 56 5c 00 00 00 a0 fd 7f - c0 ff e2 00 07 00 00 00
    V\..............
    0000000000e2ffdc ff ff ff ff 09 48 e9 77 - b8 3d e8 77 00 00 00 00
    ......H.w.=.w....
    0000000000e2ffec 00 00 00 00 00 00 00 00 - de 83 f8 77 00 00 00 00
    ............w....
    0000000000e2fffc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000e3000c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000e3001c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000e3002c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000e3003c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000e3004c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000e3005c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000e3006c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000e3007c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000e3008c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000e3009c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000e300ac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000e300bc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000e300cc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................

    *----> State Dump for Thread Id 0x2a0 <----*

    eax=000000c0 ebx=00000000 ecx=00000000 edx=00000000 esi=00000000
    edi=00000001
    eip=7ffe0304 esp=00eafcec ebp=00eaffb4 iopl=0 nv up ei pl nz na pe
    nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
    efl=00000202

    function: <nosymbols>
    7ffe02f2 0000 add [eax],al
    7ffe02f4 0000 add [eax],al
    7ffe02f6 0000 add [eax],al
    *SharedUserSystemCall:
    7ffe02f8 0000 add [eax],al
    7ffe02fa 0000 add [eax],al
    7ffe02fc 0000 add [eax],al
    7ffe02fe 0000 add [eax],al
    7ffe0300 8bd4 mov edx,esp
    7ffe0302 0f34 sysenter
    7ffe0304 c3 ret
    7ffe0305 9c pushfd
    7ffe0306 810c2400010000 or dword ptr [esp],0x100
    7ffe030d 9d popfd
    7ffe030e c3 ret
    7ffe030f 8bd4 mov edx,esp
    7ffe0311 0f05 syscall
    7ffe0313 c3 ret
    7ffe0314 9c pushfd
    7ffe0315 810c2400010000 or dword ptr [esp],0x100
    7ffe031c 9d popfd

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be
    wrong.
    ChildEBP RetAddr Args to Child
    00eafce8 77f5c524 77f91f83 00000016 00eafd30 *SharedUserSystemCall+0xc (FPO:
    [0,0,0])
    00eaffb4 77e7d33b 00000000 00000020 00000020
    ntdll!NtWaitForMultipleObjects+0xc
    00eaffec 00000000 77f91e38 00000000 00000000
    kernel32!RegisterWaitForInputIdle+0x43

    *----> Raw Stack Dump <----*
    0000000000eafcec 24 c5 f5 77 83 1f f9 77 - 16 00 00 00 30 fd ea 00
    $..w...w....0...
    0000000000eafcfc 01 00 00 00 01 00 00 00 - 00 00 00 00 20 00 00 00
    ............. ...
    0000000000eafd0c 20 00 00 00 00 00 00 00 - 20 5a fc 77 20 5a fc 77
    ........ Z.w Z.w
    0000000000eafd1c 8c 01 00 00 a0 02 00 00 - 16 00 00 00 16 00 00 00
    .................
    0000000000eafd2c 15 00 00 00 88 01 00 00 - 70 01 00 00 d8 03 00 00
    .........p.......
    0000000000eafd3c 40 04 00 00 c0 01 00 00 - fc 08 00 00 f0 06 00 00
    @...............
    0000000000eafd4c 3c 08 00 00 f8 07 00 00 - 98 07 00 00 88 06 00 00
    <...............
    0000000000eafd5c 58 02 00 00 24 05 00 00 - 6c 06 00 00 c0 07 00 00
    X...$...l.......
    0000000000eafd6c 1c 08 00 00 18 08 00 00 - 90 08 00 00 f4 05 00 00
    .................
    0000000000eafd7c d8 06 00 00 1c 07 00 00 - c8 07 00 00 00 00 00 00
    .................
    0000000000eafd8c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000eafd9c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000eafdac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000eafdbc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000eafdcc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000eafddc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000eafdec 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000eafdfc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000eafe0c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000eafe1c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................

    *----> State Dump for Thread Id 0x228 <----*

    eax=00000301 ebx=01daa9f0 ecx=77f7e6d8 edx=00000000 esi=00000000
    edi=7ffdf000
    eip=7ffe0304 esp=00f2fd30 ebp=00f2fdcc iopl=0 nv up ei pl nz na pe
    nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
    efl=00000202

    function: <nosymbols>
    7ffe02f2 0000 add [eax],al
    7ffe02f4 0000 add [eax],al
    7ffe02f6 0000 add [eax],al
    *SharedUserSystemCall:
    7ffe02f8 0000 add [eax],al
    7ffe02fa 0000 add [eax],al
    7ffe02fc 0000 add [eax],al
    7ffe02fe 0000 add [eax],al
    7ffe0300 8bd4 mov edx,esp
    7ffe0302 0f34 sysenter
    7ffe0304 c3 ret
    7ffe0305 9c pushfd
    7ffe0306 810c2400010000 or dword ptr [esp],0x100
    7ffe030d 9d popfd
    7ffe030e c3 ret
    7ffe030f 8bd4 mov edx,esp
    7ffe0311 0f05 syscall
    7ffe0313 c3 ret
    7ffe0314 9c pushfd
    7ffe0315 810c2400010000 or dword ptr [esp],0x100
    7ffe031c 9d popfd

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be
    wrong.
    ChildEBP RetAddr Args to Child
    00f2fd2c 77f5c524 77e75ee0 0000000d 01daa9f0 *SharedUserSystemCall+0xc (FPO:
    [0,0,0])
    00f2fdcc 77d463eb 0000000d 000c34d0 00000000
    ntdll!NtWaitForMultipleObjects+0xc
    00f2fe28 77424c73 0000000c 00f2fe50 ffffffff USER32!SetScrollInfo+0x21f
    00f2ff4c 7741bfe7 70aac487 00000000 77f944cb SHELL32!DragAcceptFiles+0x63
    00f2ffb4 77e7d33b 00000000 77f944cb 000d8428 SHELL32!Ordinal753+0x29c
    00f2ffec 00000000 70aac3f5 00def630 00000000
    kernel32!RegisterWaitForInputIdle+0x43

    *----> Raw Stack Dump <----*
    0000000000f2fd30 24 c5 f5 77 e0 5e e7 77 - 0d 00 00 00 f0 a9 da 01
    $..w.^.w........
    0000000000f2fd40 01 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000f2fd50 0d 00 00 00 02 00 00 00 - 20 fe f2 00 40 ba 47 00
    ......... ...@.G.
    0000000000f2fd60 00 00 00 00 00 00 00 00 - 01 00 00 00 0d 00 00 00
    .................
    0000000000f2fd70 00 f0 fd 7f 00 70 fd 7f - 00 00 00 00 c8 fd f2 00
    ......p..........
    0000000000f2fd80 f0 88 fa 77 78 1c f5 77 - ff ff ff ff 3a 8a f5 77
    ....wx..w....:..w
    0000000000f2fd90 d4 a6 e7 77 00 00 08 00 - f0 a9 da 01 00 70 fd 7f
    ....w.........p..
    0000000000f2fda0 14 00 00 00 01 00 00 00 - 70 57 0b 00 00 00 00 00
    .........pW......
    0000000000f2fdb0 00 00 00 00 4c fd f2 00 - 00 00 00 00 dc ff f2 00
    .....L...........
    0000000000f2fdc0 09 48 e9 77 78 32 e8 77 - 00 00 00 00 28 fe f2 00
    ..H.wx2.w....(...
    0000000000f2fdd0 eb 63 d4 77 0d 00 00 00 - d0 34 0c 00 00 00 00 00
    ..c.w.....4......
    0000000000f2fde0 ff ff ff ff 01 00 00 00 - 40 87 0d 00 0c 00 00 00
    .........@.......
    0000000000f2fdf0 00 00 00 00 f1 3e d4 77 - 00 00 00 00 3c fe f2 00
    ......>.w....<...
    0000000000f2fe00 d4 4c 42 77 20 fe f2 00 - 00 00 00 00 00 00 00 00 .LBw
    ............
    0000000000f2fe10 00 00 00 00 01 00 00 00 - 00 00 00 00 01 00 00 00
    .................
    0000000000f2fe20 00 70 fd 7f d4 01 00 00 - 4c ff f2 00 73 4c 42 77
    ..p......L...sLBw
    0000000000f2fe30 0c 00 00 00 50 fe f2 00 - ff ff ff ff ff 04 00 00
    .....P...........
    0000000000f2fe40 d0 34 0c 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    ..4..............
    0000000000f2fe50 d0 09 00 00 cc 09 00 00 - dc 07 00 00 98 08 00 00
    .................
    0000000000f2fe60 f8 06 00 00 fc 06 00 00 - 78 06 00 00 e4 03 00 00
    .........x.......

    *----> State Dump for Thread Id 0x488 <----*

    eax=02ad0068 ebx=00004e20 ecx=5ac60000 edx=00000000 esi=0147fd6c
    edi=77d43c54
    eip=7ffe0304 esp=0147fcfc ebp=0147fd18 iopl=0 nv up ei pl nz na pe
    nc
    cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
    efl=00000202

    function: <nosymbols>
    7ffe02f2 0000 add [eax],al
    7ffe02f4 0000 add [eax],al
    7ffe02f6 0000 add [eax],al
    *SharedUserSystemCall:
    7ffe02f8 0000 add [eax],al
    7ffe02fa 0000 add [eax],al
    7ffe02fc 0000 add [eax],al
    7ffe02fe 0000 add [eax],al
    7ffe0300 8bd4 mov edx,esp
    7ffe0302 0f34 sysenter
    7ffe0304 c3 ret
    7ffe0305 9c pushfd
    7ffe0306 810c2400010000 or dword ptr [esp],0x100
    7ffe030d 9d popfd
    7ffe030e c3 ret
    7ffe030f 8bd4 mov edx,esp
    7ffe0311 0f05 syscall
    7ffe0313 c3 ret
    7ffe0314 9c pushfd
    7ffe0315 810c2400010000 or dword ptr [esp],0x100
    7ffe031c 9d popfd

    *----> Stack Back Trace <----*
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for
    C:\WINDOWS\System32\stobject.dll -
    WARNING: Stack unwind information not available. Following frames may be
    wrong.
    ChildEBP RetAddr Args to Child
    0147fcf8 77d43a09 77d43c7d 0147fd6c 00000000 *SharedUserSystemCall+0xc (FPO:
    [0,0,0])
    0147fd18 74b01590 0147fd6c 00000000 00000000 USER32+0x3a09
    0147fd90 74b02f1b 74b00000 00000000 000100b8 stobject+0x1590
    0147ffb4 77e7d33b 00000000 00000000 00000000 stobject+0x2f1b
    0147ffec 00000000 74b02ed6 00000000 00000000
    kernel32!RegisterWaitForInputIdle+0x43

    *----> Raw Stack Dump <----*
    000000000147fcfc 09 3a d4 77 7d 3c d4 77 - 6c fd 47 01 00 00 00 00
    ..:.w}<.wl.G.....
    000000000147fd0c 00 00 00 00 00 00 00 00 - 00 00 00 00 90 fd 47 01
    ...............G.
    000000000147fd1c 90 15 b0 74 6c fd 47 01 - 00 00 00 00 00 00 00 00
    ....tl.G.........
    000000000147fd2c 00 00 00 00 00 00 00 00 - 00 00 b0 74 00 00 00 00
    ............t....
    000000000147fd3c 30 00 00 00 00 40 00 00 - f0 12 b0 74 00 00 00 00
    0....@.....t....
    000000000147fd4c 1e 00 00 00 00 00 b0 74 - c7 00 04 00 11 00 01 00
    ........t........
    000000000147fd5c 10 00 00 00 00 00 00 00 - f4 31 b0 74 00 00 00 00
    ..........1.t....
    000000000147fd6c 00 00 00 00 13 01 00 00 - 5f 6d 00 00 29 64 d3 75
    ........._m..)d.u
    000000000147fd7c a8 3d 90 00 70 02 00 00 - b6 01 00 00 00 00 00 00
    ..=..p...........
    000000000147fd8c 00 00 00 00 b4 ff 47 01 - 1b 2f b0 74 00 00 b0 74
    .......G../.t...t
    000000000147fd9c 00 00 00 00 b8 00 01 00 - 01 00 00 00 00 00 00 00
    .................
    000000000147fdac 43 00 3a 00 5c 00 57 00 - 49 00 4e 00 44 00 4f 00
    C.:.\.W.I.N.D.O.
    000000000147fdbc 57 00 53 00 5c 00 53 00 - 79 00 73 00 74 00 65 00
    W.S.\.S.y.s.t.e.
    000000000147fdcc 6d 00 33 00 32 00 5c 00 - 73 00 74 00 6f 00 62 00
    m.3.2.\.s.t.o.b.
    000000000147fddc 6a 00 65 00 63 00 74 00 - 2e 00 64 00 6c 00 6c 00
    j.e.c.t...d.l.l.
    000000000147fdec 00 00 00 00 00 02 00 00 - fc ff 47 01 23 00 00 00
    ...........G.#...
    000000000147fdfc 65 6d 52 6f 6f 74 25 5c - 73 79 73 74 65 6d 33 32
    emRoot%\system32
    000000000147fe0c 5c 73 68 65 6c 6c 33 32 - 2e 64 6c 6c 2c 2d 32 32
    \shell32.dll,-22
    000000000147fe1c 30 35 38 0d 0a 41 63 74 - 69 76 61 74 65 20 57 69
    058..Activate Wi
    000000000147fe2c 6e 64 6f 77 73 2e 6c 6e - 6b 3d 40 25 53 79 73 74
    ndows.lnk=@%Syst

    *----> State Dump for Thread Id 0xda8 <----*

    eax=72d22ecc ebx=01e6ff1c ecx=000000fa edx=00000000 esi=00000000
    edi=7ffdf000
    eip=7ffe0304 esp=01e6fed4 ebp=01e6ff70 iopl=0 nv up ei pl nz na pe
    nc
    cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
    efl=00000202

    function: <nosymbols>
    7ffe02f2 0000 add [eax],al
    7ffe02f4 0000 add [eax],al
    7ffe02f6 0000 add [eax],al
    *SharedUserSystemCall:
    7ffe02f8 0000 add [eax],al
    7ffe02fa 0000 add [eax],al
    7ffe02fc 0000 add [eax],al
    7ffe02fe 0000 add [eax],al
    7ffe0300 8bd4 mov edx,esp
    7ffe0302 0f34 sysenter
    7ffe0304 c3 ret
    7ffe0305 9c pushfd
    7ffe0306 810c2400010000 or dword ptr [esp],0x100
    7ffe030d 9d popfd
    7ffe030e c3 ret
    7ffe030f 8bd4 mov edx,esp
    7ffe0311 0f05 syscall
    7ffe0313 c3 ret
    7ffe0314 9c pushfd
    7ffe0315 810c2400010000 or dword ptr [esp],0x100
    7ffe031c 9d popfd

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be
    wrong.
    ChildEBP RetAddr Args to Child
    01e6fed0 77f5c524 77e75ee0 00000002 01e6ff1c *SharedUserSystemCall+0xc (FPO:
    [0,0,0])
    01e6ff70 77e75faa 00000002 01e6ffa4 00000000
    ntdll!NtWaitForMultipleObjects+0xc
    01e6ffb4 77e7d33b 00000000 00000021 41f59037
    kernel32!WaitForMultipleObjects+0x17
    01e6ffec 00000000 72d22ecc 00000000 00000000
    kernel32!RegisterWaitForInputIdle+0x43

    *----> Raw Stack Dump <----*
    0000000001e6fed4 24 c5 f5 77 e0 5e e7 77 - 02 00 00 00 1c ff e6 01
    $..w.^.w........
    0000000001e6fee4 01 00 00 00 00 00 00 00 - 00 00 00 00 21 00 00 00
    .............!...
    0000000001e6fef4 00 00 00 00 00 00 00 00 - ff ff ff ff 88 fc f9 fa
    .................
    0000000001e6ff04 00 00 00 00 00 80 00 00 - b0 94 b9 ff 02 00 00 00
    .................
    0000000001e6ff14 00 f0 fd 7f 00 40 fd 7f - d8 05 00 00 28 05 00 00
    ......@......(...
    0000000001e6ff24 07 52 4f 80 0f 52 4f 80 - f4 06 a6 ff 88 05 a6 ff
    ..RO..RO.........
    0000000001e6ff34 69 6b 61 80 a8 5d 12 81 - 1c ff e6 01 00 40 fd 7f
    ika..].......@..
    0000000001e6ff44 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000001e6ff54 10 00 00 00 f0 fe e6 01 - 00 00 00 00 dc ff e6 01
    .................
    0000000001e6ff64 09 48 e9 77 78 32 e8 77 - 00 00 00 00 b4 ff e6 01
    ..H.wx2.w........
    0000000001e6ff74 aa 5f e7 77 02 00 00 00 - a4 ff e6 01 00 00 00 00
    .._.w............
    0000000001e6ff84 ff ff ff ff 00 00 00 00 - 0c 2f d2 72 02 00 00 00
    ........../.r....
    0000000001e6ff94 a4 ff e6 01 00 00 00 00 - ff ff ff ff 37 90 f5 41
    .............7..A
    0000000001e6ffa4 d8 05 00 00 28 05 00 00 - a8 fc f9 fa f4 bf f5 77
    .....(..........w
    0000000001e6ffb4 ec ff e6 01 3b d3 e7 77 - 00 00 00 00 21 00 00 00
    .....;..w....!...
    0000000001e6ffc4 37 90 f5 41 00 00 00 00 - e0 fc f9 fa 00 40 fd 7f
    7..A.........@..
    0000000001e6ffd4 c0 ff e6 01 07 00 00 00 - ff ff ff ff 09 48 e9 77
    ..............H.w
    0000000001e6ffe4 b8 3d e8 77 00 00 00 00 - 00 00 00 00 00 00 00 00
    ..=.w............
    0000000001e6fff4 cc 2e d2 72 00 00 00 00 - 00 00 00 00 00 00 00 00
    ....r............
    0000000001e70004 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................

    *----> State Dump for Thread Id 0xefc <----*

    eax=00000000 ebx=000005b8 ecx=77e75615 edx=00000000 esi=01eaff98
    edi=77d44377
    eip=7ffe0304 esp=01eaff54 ebp=01eaff78 iopl=0 nv up ei pl nz na pe
    nc
    cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
    efl=00000202

    function: <nosymbols>
    7ffe02f2 0000 add [eax],al
    7ffe02f4 0000 add [eax],al
    7ffe02f6 0000 add [eax],al
    *SharedUserSystemCall:
    7ffe02f8 0000 add [eax],al
    7ffe02fa 0000 add [eax],al
    7ffe02fc 0000 add [eax],al
    7ffe02fe 0000 add [eax],al
    7ffe0300 8bd4 mov edx,esp
    7ffe0302 0f34 sysenter
    7ffe0304 c3 ret
    7ffe0305 9c pushfd
    7ffe0306 810c2400010000 or dword ptr [esp],0x100
    7ffe030d 9d popfd
    7ffe030e c3 ret
    7ffe030f 8bd4 mov edx,esp
    7ffe0311 0f05 syscall
    7ffe0313 c3 ret
    7ffe0314 9c pushfd
    7ffe0315 810c2400010000 or dword ptr [esp],0x100
    7ffe031c 9d popfd

    *----> Stack Back Trace <----*
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for
    C:\WINDOWS\System32\WINMM.dll -
    WARNING: Stack unwind information not available. Following frames may be
    wrong.
    ChildEBP RetAddr Args to Child
    01eaff50 77d43a09 77d443b5 01eaff98 00000000 *SharedUserSystemCall+0xc (FPO:
    [0,0,0])
    01eaff78 76b41c79 01eaff98 00000000 00000000 USER32+0x3a09
    01eaffb4 77e7d33b 000005b8 00010003 00080000 WINMM!timeGetTime+0x1a1
    01eaffec 00000000 76b41c14 000005b8 00000000
    kernel32!RegisterWaitForInputIdle+0x43

    *----> Raw Stack Dump <----*
    0000000001eaff54 09 3a d4 77 b5 43 d4 77 - 98 ff ea 01 00 00 00 00
    ..:.w.C.w........
    0000000001eaff64 00 00 00 00 00 00 00 00 - b8 05 00 00 77 43 d4 77
    .............wC.w
    0000000001eaff74 00 00 00 00 b4 ff ea 01 - 79 1c b4 76 98 ff ea 01
    .........y..v....
    0000000001eaff84 00 00 00 00 00 00 00 00 - 00 00 00 00 03 00 01 00
    .................
    0000000001eaff94 00 00 08 00 d2 00 11 00 - bc 03 00 00 98 ae 0e 00
    .................
    0000000001eaffa4 00 00 00 00 aa 89 8f 00 - 02 01 00 00 d5 00 00 00
    .................
    0000000001eaffb4 ec ff ea 01 3b d3 e7 77 - b8 05 00 00 03 00 01 00
    .....;..w........
    0000000001eaffc4 00 00 08 00 b8 05 00 00 - a8 6c 00 00 00 f0 fa 7f
    ..........l......
    0000000001eaffd4 c0 ff ea 01 07 00 00 00 - ff ff ff ff 09 48 e9 77
    ..............H.w
    0000000001eaffe4 b8 3d e8 77 00 00 00 00 - 00 00 00 00 00 00 00 00
    ..=.w............
    0000000001eafff4 14 1c b4 76 b8 05 00 00 - 00 00 00 00 ff ff ff ff
    ....v............
    0000000001eb0004 ff ff ff ff ff ff ff ff - ff ff ff ff ff ff ff ff
    .................
    0000000001eb0014 ff ff ff ff ff ff ff ff - ff ff ff ff ff ff ff ff
    .................
    0000000001eb0024 ff ff ff ff ff ff ff ff - ff ff ff ff ff ff ff ff
    .................
    0000000001eb0034 ff ff ff ff ff ff ff ff - ff ff ff ff ff ff 00 00
    .................
    0000000001eb0044 ff ff ff ff ff ff ff ff - ff ff ff ff ff ff ff ff
    .................
    0000000001eb0054 ff ff ff ff ff ff ff ff - ff ff ff ff ff ff ff ff
    .................
    0000000001eb0064 ff ff ff ff ff ff ff ff - ff ff ff ff ff ff ff ff
    .................
    0000000001eb0074 ff ff ff ff ff ff ff ff - ff ff ff ff ff ff ff ff
    .................
    0000000001eb0084 ff ff 00 00 ff ff ff ff - ff ff ff ff ff ff ff ff
    .................

    *----> State Dump for Thread Id 0xe28 <----*

    eax=02010000 ebx=00000001 ecx=00001000 edx=00000000 esi=00000000
    edi=000009fc
    eip=7ffe0304 esp=01f7c960 ebp=01f7ce98 iopl=0 nv up ei pl nz na pe
    nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
    efl=00000202

    function: <nosymbols>
    7ffe02f2 0000 add [eax],al
    7ffe02f4 0000 add [eax],al
    7ffe02f6 0000 add [eax],al
    *SharedUserSystemCall:
    7ffe02f8 0000 add [eax],al
    7ffe02fa 0000 add [eax],al
    7ffe02fc 0000 add [eax],al
    7ffe02fe 0000 add [eax],al
    7ffe0300 8bd4 mov edx,esp
    7ffe0302 0f34 sysenter
    7ffe0304 c3 ret
    7ffe0305 9c pushfd
    7ffe0306 810c2400010000 or dword ptr [esp],0x100
    7ffe030d 9d popfd
    7ffe030e c3 ret
    7ffe030f 8bd4 mov edx,esp
    7ffe0311 0f05 syscall
    7ffe0313 c3 ret
    7ffe0314 9c pushfd
    7ffe0315 810c2400010000 or dword ptr [esp],0x100
    7ffe031c 9d popfd

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be
    wrong.
    ChildEBP RetAddr Args to Child
    01f7c95c 77f5c524 77e934de 00000002 01f7c988 *SharedUserSystemCall+0xc (FPO:
    [0,0,0])
    01f7ce98 77e98854 01f7cec0 77e94858 01f7cec8
    ntdll!NtWaitForMultipleObjects+0xc
    01f7ffec 00000000 77f95b06 00000000 00000000 kernel32!GetAtomNameA+0x125c

    *----> Raw Stack Dump <----*
    0000000001f7c960 24 c5 f5 77 de 34 e9 77 - 02 00 00 00 88 c9 f7 01
    $..w.4.w........
    0000000001f7c970 01 00 00 00 01 00 00 00 - 00 00 00 00 b8 3d e8 77
    ..............=.w
    0000000001f7c980 00 00 00 00 dc ff f7 01 - fc 09 00 00 0c 0a 00 00
    .................
    0000000001f7c990 0c 0a 00 00 c4 09 00 00 - 88 0a 00 00 e0 04 00 00
    .................
    0000000001f7c9a0 64 72 77 74 73 6e 33 32 - 20 2d 70 20 32 34 38 20
    drwtsn32 -p 248
    0000000001f7c9b0 2d 65 20 32 35 35 36 20 - 2d 67 00 77 17 00 00 00 -e
    2556 -g.w....
    0000000001f7c9c0 e8 c9 f7 01 7a db 1c 77 - 98 ec 2b 77 a4 cc f7 01
    .....z..w..+w....
    0000000001f7c9d0 00 00 00 00 00 00 00 00 - 0c d4 f7 01 59 dd 1c 77
    .............Y..w
    0000000001f7c9e0 48 ce f7 01 a4 cc f7 01 - 14 ca f7 01 11 c5 1c 77
    H..............w
    0000000001f7c9f0 98 ec 2b 77 00 00 00 00 - 48 ce f7 01 0c d4 f7 01
    ...+w....H.......
    0000000001f7ca00 48 ce f7 01 a4 cc f7 01 - 00 00 00 00 64 cc f7 01
    H...........d...
    0000000001f7ca10 7f c5 1c 77 64 cc f7 01 - a3 c5 1c 77 48 ce f7 01
    ....wd......wH...
    0000000001f7ca20 00 00 00 00 0c d4 f7 01 - 43 00 3a 00 5c 00 57 00
    .........C.:.\.W.
    0000000001f7ca30 49 00 4e 00 44 00 4f 00 - 57 00 53 00 5c 00 53 00
    I.N.D.O.W.S.\.S.
    0000000001f7ca40 79 00 73 00 74 00 65 00 - 6d 00 33 00 32 00 5c 00
    y.s.t.e.m.3.2.\.
    0000000001f7ca50 6d 00 6c 00 61 00 6e 00 - 67 00 2e 00 64 00 6c 00
    m.l.a.n.g...d.l.
    0000000001f7ca60 6c 00 00 00 fc ff ff ff - 04 00 00 00 00 00 00 00
    l...............
    0000000001f7ca70 60 47 fc 77 14 00 00 00 - d5 96 f8 77 62 cb f7 01
    `G.w.......wb...
    0000000001f7ca80 b0 ca f7 01 a5 02 f7 77 - 00 00 07 00 00 00 00 00
    ........w........
    0000000001f7ca90 04 00 00 00 1c cb f7 01 - 08 cb f7 01 00 00 00 00
    .................

    *----> State Dump for Thread Id 0x7a0 <----*

    eax=00000102 ebx=000abb88 ecx=00a5fe28 edx=00000000 esi=80110002
    edi=00000000
    eip=7ffe0304 esp=00a5fe28 ebp=00a5ff90 iopl=0 nv up ei pl nz na pe
    nc
    cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
    efl=00000202

    function: <nosymbols>
    7ffe02f2 0000 add [eax],al
    7ffe02f4 0000 add [eax],al
    7ffe02f6 0000 add [eax],al
    *SharedUserSystemCall:
    7ffe02f8 0000 add [eax],al
    7ffe02fa 0000 add [eax],al
    7ffe02fc 0000 add [eax],al
    7ffe02fe 0000 add [eax],al
    7ffe0300 8bd4 mov edx,esp
    7ffe0302 0f34 sysenter
    7ffe0304 c3 ret
    7ffe0305 9c pushfd
    7ffe0306 810c2400010000 or dword ptr [esp],0x100
    7ffe030d 9d popfd
    7ffe030e c3 ret
    7ffe030f 8bd4 mov edx,esp
    7ffe0311 0f05 syscall
    7ffe0313 c3 ret
    7ffe0314 9c pushfd
    7ffe0315 810c2400010000 or dword ptr [esp],0x100
    7ffe031c 9d popfd

    *----> Stack Back Trace <----*
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for
    C:\WINDOWS\system32\RPCRT4.dll -
    WARNING: Stack unwind information not available. Following frames may be
    wrong.
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for
    C:\WINDOWS\system32\GDI32.dll -
    ChildEBP RetAddr Args to Child
    00a5fe24 77f5c084 780016a4 00000140 00a5ff80 *SharedUserSystemCall+0xc (FPO:
    [0,0,0])
    00a5ff90 78001601 780019d4 0009ed78 00a1fb3c
    ntdll!NtReplyWaitReceivePortEx+0xc
    000ddd38 ffffffff 0000073c 0000085c 00000000 RPCRT4+0x1601
    00000000 00000000 00000000 00000000 00000000 0xffffffff

    *----> Raw Stack Dump <----*
    0000000000a5fe28 84 c0 f5 77 a4 16 00 78 - 40 01 00 00 80 ff a5 00
    ....w...x@.......
    0000000000a5fe38 00 00 00 00 88 bb 0a 00 - 58 ff a5 00 e4 d3 b0 ff
    .........X.......
    0000000000a5fe48 38 57 5b ff f7 43 4f 80 - 5c 62 ff fe ec 6b be ef
    8W[..CO.\b...k..
    0000000000a5fe58 00 00 00 00 bf 99 49 fa - f8 6b be ef 00 00 00 00
    .......I..k......
    0000000000a5fe68 03 00 00 00 02 00 00 00 - d8 db b8 ff 8c ab bb ff
    .................
    0000000000a5fe78 d3 5d 4f 80 1c 00 00 00 - 5c 62 ff fe 38 57 5b ff
    ..]O.....\b..8W[.
    0000000000a5fe88 01 00 00 00 00 00 00 00 - 9e f1 6a 80 fc db b8 ff
    ...........j.....
    0000000000a5fe98 02 00 00 00 d8 db b8 ff - ac 6b be ef 8c ab bb ff
    ..........k......
    0000000000a5fea8 41 00 00 00 d6 00 6b 80 - d8 db b8 ff f8 6b be ef
    A.....k......k..
    0000000000a5feb8 07 52 4f 80 0f 52 4f 80 - 00 00 00 00 37 7e 47 fa
    ..RO..RO.....7~G.
    0000000000a5fec8 4c d3 b0 ff d0 d3 b0 ff - 00 00 00 00 28 6c be ef
    L...........(l..
    0000000000a5fed8 73 68 49 fa 02 d3 b0 ff - d8 d3 b0 ff 01 00 00 00
    shI.............
    0000000000a5fee8 83 68 49 fa 00 00 00 00 - 24 d3 b0 ff 00 00 00 00
    ..hI.....$.......
    0000000000a5fef8 4e 9a 49 fa 28 9c 49 fa - 8c 6c be ef 00 a0 00 00
    N.I.(.I..l......
    0000000000a5ff08 20 d3 b0 ff e0 89 57 ff - 38 57 5b ff 00 bb 04 c0
    ......W.8W[.....
    0000000000a5ff18 01 00 00 00 00 6c be ef - 5c dc 0e ff 07 52 4f 80
    ......l..\....RO.
    0000000000a5ff28 0f 52 4f 80 2c dc 0e ff - c0 da 0e ff 69 6b 61 80
    ..RO.,.......ika.
    0000000000a5ff38 a8 5d 12 81 c0 da 0e ff - 2f 16 00 78 60 ff a5 00
    ..]....../..x`...
    0000000000a5ff48 4a 16 00 78 30 ec 09 00 - a8 98 cc 01 38 dd 0d 00
    J..x0.......8...
    0000000000a5ff58 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff
    .../M.....]......

    *----> State Dump for Thread Id 0x89c <----*

    eax=00173ff0 ebx=00132b30 ecx=0011b75c edx=00000000 esi=001a0004
    edi=00000000
    eip=7ffe0304 esp=00a9fe28 ebp=00a9ff90 iopl=0 nv up ei pl nz na pe
    nc
    cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
    efl=00000202

    function: <nosymbols>
    7ffe02f2 0000 add [eax],al
    7ffe02f4 0000 add [eax],al
    7ffe02f6 0000 add [eax],al
    *SharedUserSystemCall:
    7ffe02f8 0000 add [eax],al
    7ffe02fa 0000 add [eax],al
    7ffe02fc 0000 add [eax],al
    7ffe02fe 0000 add [eax],al
    7ffe0300 8bd4 mov edx,esp
    7ffe0302 0f34 sysenter
    7ffe0304 c3 ret
    7ffe0305 9c pushfd
    7ffe0306 810c2400010000 or dword ptr [esp],0x100
    7ffe030d 9d popfd
    7ffe030e c3 ret
    7ffe030f 8bd4 mov edx,esp
    7ffe0311 0f05 syscall
    7ffe0313 c3 ret
    7ffe0314 9c pushfd
    7ffe0315 810c2400010000 or dword ptr [esp],0x100
    7ffe031c 9d popfd

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be
    wrong.
    ChildEBP RetAddr Args to Child
    00a9fe24 77f5c084 780016a4 00000140 00a9ff80 *SharedUserSystemCall+0xc (FPO:
    [0,0,0])
    00a9ff90 78001601 780019d4 0009ed78 00000000
    ntdll!NtReplyWaitReceivePortEx+0xc
    0008f5e8 ffffffff 000003c4 00000808 00000000 RPCRT4+0x1601
    00000000 00000000 00000000 00000000 00000000 0xffffffff

    *----> Raw Stack Dump <----*
    0000000000a9fe28 84 c0 f5 77 a4 16 00 78 - 40 01 00 00 80 ff a9 00
    ....w...x@.......
    0000000000a9fe38 00 00 00 00 30 2b 13 00 - 60 ff a9 00 e4 d3 b0 ff
    .....0+..`.......
    0000000000a9fe48 08 e0 a0 ff f7 43 4f 80 - 5c e2 e0 fe ec 6b d3 ef
    ......CO.\....k..
    0000000000a9fe58 00 00 00 00 bf 99 49 fa - f8 6b d3 ef 00 00 00 00
    .......I..k......
    0000000000a9fe68 03 00 00 00 02 00 00 00 - d8 db b8 ff 8c ab bb ff
    .................
    0000000000a9fe78 d3 5d 4f 80 1e 00 00 00 - 5c e2 e0 fe 08 e0 a0 ff
    ..]O.....\.......
    0000000000a9fe88 01 00 00 00 00 00 00 00 - 9e f1 6a 80 fc db b8 ff
    ...........j.....
    0000000000a9fe98 02 00 00 00 d8 db b8 ff - ac 6b d3 ef 8c ab bb ff
    ..........k......
    0000000000a9fea8 41 00 00 00 d6 00 6b 80 - d8 db b8 ff f8 6b d3 ef
    A.....k......k..
    0000000000a9feb8 07 52 4f 80 0f 52 4f 80 - 00 00 00 00 37 7e 47 fa
    ..RO..RO.....7~G.
    0000000000a9fec8 4c d3 b0 ff d0 d3 b0 ff - 00 00 00 00 28 6c d3 ef
    L...........(l..
    0000000000a9fed8 73 68 49 fa 02 d3 b0 ff - d8 d3 b0 ff 01 00 00 00
    shI.............
    0000000000a9fee8 83 68 49 fa 00 00 00 00 - 24 d3 b0 ff 00 00 00 00
    ..hI.....$.......
    0000000000a9fef8 4e 9a 49 fa 28 9c 49 fa - 8c 6c d3 ef 00 a0 00 00
    N.I.(.I..l......
    0000000000a9ff08 20 d3 b0 ff e8 a8 18 81 - 08 e0 a0 ff 00 ba 04 c0
    ................
    0000000000a9ff18 01 00 00 00 00 6c d3 ef - 7c a7 ab ff 07 52 4f 80
    ......l..|....RO.
    0000000000a9ff28 0f 52 4f 80 4c a7 ab ff - e0 a5 ab ff 69 6b 61 80
    ..RO.L.......ika.
    0000000000a9ff38 a8 5d 12 81 e0 a5 ab ff - 2f 16 00 78 60 ff a9 00
    ..]....../..x`...
    0000000000a9ff48 4a 16 00 78 30 ec 09 00 - 90 02 0d 00 e8 f5 08 00
    J..x0...........
    0000000000a9ff58 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff
    .../M.....]......

    *----> State Dump for Thread Id 0x730 <----*

    eax=000dfac8 ebx=00000000 ecx=7ffdc000 edx=00000000 esi=77fc1774
    edi=00000000
    eip=7ffe0304 esp=00aefe28 ebp=00aefeb0 iopl=0 nv up ei pl nz na pe
    nc
    cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
    efl=00000202

    function: <nosymbols>
    7ffe02f2 0000 add [eax],al
    7ffe02f4 0000 add [eax],al
    7ffe02f6 0000 add [eax],al
    *SharedUserSystemCall:
    7ffe02f8 0000 add [eax],al
    7ffe02fa 0000 add [eax],al
    7ffe02fc 0000 add [eax],al
    7ffe02fe 0000 add [eax],al
    7ffe0300 8bd4 mov edx,esp
    7ffe0302 0f34 sysenter
    7ffe0304 c3 ret
    7ffe0305 9c pushfd
    7ffe0306 810c2400010000 or dword ptr [esp],0x100
    7ffe030d 9d popfd
    7ffe030e c3 ret
    7ffe030f 8bd4 mov edx,esp
    7ffe0311 0f05 syscall
    7ffe0313 c3 ret
    7ffe0314 9c pushfd
    7ffe0315 810c2400010000 or dword ptr [esp],0x100
    7ffe031c 9d popfd

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be
    wrong.
    ChildEBP RetAddr Args to Child
    00aefe24 77f5c534 77f69f68 00000250 00000000 *SharedUserSystemCall+0xc (FPO:
    [0,0,0])
    00aefeb0 77f5b2e6 01fc1774 77f60a80 77fc1774 ntdll!NtWaitForSingleObject+0xc
    00aeff98 77e73465 771b0000 771e7f1f 771b0000
    ntdll!RtlEnterCriticalSection+0x46
    00aeffec 00000000 771e7eef 01d37998 00000000
    kernel32!FreeLibraryAndExitThread+0x12

    *----> Raw Stack Dump <----*
    0000000000aefe28 34 c5 f5 77 68 9f f6 77 - 50 02 00 00 00 00 00 00
    4..wh..wP.......
    0000000000aefe38 00 00 00 00 00 00 1b 77 - 98 79 d3 01 00 f0 fd 7f
    ........w.y......
    0000000000aefe48 21 14 1c 77 38 69 0a 00 - 05 00 00 00 37 90 f5 77
    !..w8i......7..w
    0000000000aefe58 00 00 00 00 a8 e1 2b 77 - 00 00 00 00 90 21 d1 01
    .......+w.....!..
    0000000000aefe68 00 00 00 00 44 06 1c 77 - 58 e1 2b 77 f9 7d 1c 77
    .....D..wX.+w.}.w
    0000000000aefe78 71 06 1c 77 58 e1 2b 77 - e0 e3 2b 77 01 00 00 00
    q..wX.+w..+w....
    0000000000aefe88 01 00 00 00 00 00 00 00 - 00 00 00 00 f0 fa ae 00
    .................
    0000000000aefe98 00 00 00 00 dc ff ae 00 - 84 b6 01 78 90 d4 02 78
    ............x...x
    0000000000aefea8 00 00 00 00 50 02 00 00 - 98 ff ae 00 e6 b2 f5 77
    .....P..........w
    0000000000aefeb8 74 17 fc 01 80 0a f6 77 - 74 17 fc 77 00 00 1b 77
    t......wt..w...w
    0000000000aefec8 98 79 d3 01 98 79 d3 01 - 98 79 d3 01 98 79 d3 01
    ..y...y...y...y..
    0000000000aefed8 00 00 00 00 28 ff ae 00 - 00 00 00 00 00 00 00 00
    .....(...........
    0000000000aefee8 00 00 00 00 28 ff ae 00 - f5 7d 1e 77 00 00 01 00
    .....(....}.w....
    0000000000aefef8 00 00 08 00 58 fe ae 00 - 78 7d 1e 77 7f a6 f6 77
    .....X...x}.w...w
    0000000000aeff08 a2 a5 e7 77 98 79 d3 01 - 30 75 00 00 37 90 f5 77
    ....w.y..0u..7..w
    0000000000aeff18 95 7d 1e 77 00 c0 fd 7f - 78 ff ae 00 00 c0 fd 7f
    ..}.w....x.......
    0000000000aeff28 88 ff ae 00 5f a6 e7 77 - 5c ff ae 00 52 a6 e7 77
    ....._..w\...R..w
    0000000000aeff38 a2 a5 e7 77 98 79 d3 01 - 30 75 00 00 02 01 00 00
    ....w.y..0u......
    0000000000aeff48 4c ff ae 00 00 5d 1e ee - ff ff ff ff 04 00 00 00
    L....]..........
    0000000000aeff58 20 00 00 00 14 00 00 00 - 01 00 00 00 00 00 00 00
    ................

    *----> State Dump for Thread Id 0xf3c <----*

    eax=00000001 ebx=00131638 ecx=001143b8 edx=00000000 esi=80120003
    edi=00000000
    eip=7ffe0304 esp=00b7fe28 ebp=00b7ff90 iopl=0 nv up ei pl nz na pe
    nc
    cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
    efl=00000202

    function: <nosymbols>
    7ffe02f2 0000 add [eax],al
    7ffe02f4 0000 add [eax],al
    7ffe02f6 0000 add [eax],al
    *SharedUserSystemCall:
    7ffe02f8 0000 add [eax],al
    7ffe02fa 0000 add [eax],al
    7ffe02fc 0000 add [eax],al
    7ffe02fe 0000 add [eax],al
    7ffe0300 8bd4 mov edx,esp
    7ffe0302 0f34 sysenter
    7ffe0304 c3 ret
    7ffe0305 9c pushfd
    7ffe0306 810c2400010000 or dword ptr [esp],0x100
    7ffe030d 9d popfd
    7ffe030e c3 ret
    7ffe030f 8bd4 mov edx,esp
    7ffe0311 0f05 syscall
    7ffe0313 c3 ret
    7ffe0314 9c pushfd
    7ffe0315 810c2400010000 or dword ptr [esp],0x100
    7ffe031c 9d popfd

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be
    wrong.
    ChildEBP RetAddr Args to Child
    00b7fe24 77f5c084 780016a4 00000140 00b7ff80 *SharedUserSystemCall+0xc (FPO:
    [0,0,0])
    00b7ff90 78001601 780019d4 0009ed78 00000000
    ntdll!NtReplyWaitReceivePortEx+0xc
    01ccb4d8 ffffffff 00000460 00000404 00000000 RPCRT4+0x1601
    00000000 00000000 00000000 00000000 00000000 0xffffffff

    *----> Raw Stack Dump <----*
    0000000000b7fe28 84 c0 f5 77 a4 16 00 78 - 40 01 00 00 80 ff b7 00
    ....w...x@.......
    0000000000b7fe38 00 00 00 00 38 16 13 00 - 60 ff b7 00 00 00 00 00
    .....8...`.......
    0000000000b7fe48 9c 36 50 c0 9c 36 50 c0 - c8 84 a5 ff ae 05 00 00
    ..6P..6P.........
    0000000000b7fe58 32 3d 51 80 ae 05 00 00 - c8 84 a5 ff 00 00 fd 7f
    2=Q.............
    0000000000b7fe68 fc 07 30 c0 00 00 00 00 - ae 05 00 00 00 00 00 00
    ...0.............
    0000000000b7fe78 00 00 00 00 1d 00 00 00 - 00 00 00 00 70 e5 a8 ff
    .............p...
    0000000000b7fe88 c4 eb c6 ef b5 40 51 80 - fc 07 30 c0 c4 eb c6 ef
    ......@Q...0.....
    0000000000b7fe98 f2 40 51 80 00 a0 fd 7f - 00 00 00 00 00 00 00 00
    ..@Q.............
    0000000000b7fea8 18 54 ae ff d0 82 a5 ff - 01 83 a5 ff 00 00 00 00
    ..T..............
    0000000000b7feb8 68 ff 1f c0 d0 82 a5 ff - 00 00 00 00 00 00 c2 00
    h...............
    0000000000b7fec8 ff ff c1 00 00 00 00 00 - 00 00 c2 00 00 7f 00 c0
    .................
    0000000000b7fed8 d0 82 a5 ff 3c eb c6 ef - 78 0f 28 ff ff ff ff ff
    .....<...x.(.....
    0000000000b7fee8 60 6a 52 80 68 63 4d 80 - ff ff ff ff 00 a0 fd 7f
    `jR.hcM.........
    0000000000b7fef8 71 d5 52 80 ff ff ff ff - 88 ec c6 ef 8c ec c6 ef
    q.R.............
    0000000000b7ff08 00 80 00 00 b0 94 b9 ff - b8 94 b9 ff 00 00 00 00
    .................
    0000000000b7ff18 28 ec c6 ef 50 70 31 81 - 84 cb b8 ff 07 52 4f 80
    (...Pp1......RO.
    0000000000b7ff28 0f 52 4f 80 54 cb b8 ff - e8 c9 b8 ff 69 6b 61 80
    ..RO.T.......ika.
    0000000000b7ff38 a8 5d 12 81 e8 c9 b8 ff - 2f 16 00 78 60 ff b7 00
    ..]....../..x`...
    0000000000b7ff48 4a 16 00 78 30 ec 09 00 - 70 14 0d 00 d8 b4 cc 01
    J..x0...p.......
    0000000000b7ff58 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff
    .../M.....]......

    *----> State Dump for Thread Id 0x940 <----*

    eax=00000000 ebx=00cfff18 ecx=7ffad000 edx=00000000 esi=00000000
    edi=7ffdf000
    eip=7ffe0304 esp=00cffed0 ebp=00cfff6c iopl=0 nv up ei pl nz na pe
    nc
    cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
    efl=00000202

    function: <nosymbols>
    7ffe02f2 0000 add [eax],al
    7ffe02f4 0000 add [eax],al
    7ffe02f6 0000 add [eax],al
    *SharedUserSystemCall:
    7ffe02f8 0000 add [eax],al
    7ffe02fa 0000 add [eax],al
    7ffe02fc 0000 add [eax],al
    7ffe02fe 0000 add [eax],al
    7ffe0300 8bd4 mov edx,esp
    7ffe0302 0f34 sysenter
    7ffe0304 c3 ret
    7ffe0305 9c pushfd
    7ffe0306 810c2400010000 or dword ptr [esp],0x100
    7ffe030d 9d popfd
    7ffe030e c3 ret
    7ffe030f 8bd4 mov edx,esp
    7ffe0311 0f05 syscall
    7ffe0313 c3 ret
    7ffe0314 9c pushfd
    7ffe0315 810c2400010000 or dword ptr [esp],0x100
    7ffe031c 9d popfd

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be
    wrong.
    ChildEBP RetAddr Args to Child
    00cffecc 77f5c524 77e75ee0 00000003 00cfff18 *SharedUserSystemCall+0xc (FPO:
    [0,0,0])
    00cfff6c 77e75faa 00000003 75b03300 00000000
    ntdll!NtWaitForMultipleObjects+0xc
    00000000 00000000 00000000 00000000 00000000
    kernel32!WaitForMultipleObjects+0x17

    *----> Raw Stack Dump <----*
    0000000000cffed0 24 c5 f5 77 e0 5e e7 77 - 03 00 00 00 18 ff cf 00
    $..w.^.w........
    0000000000cffee0 01 00 00 00 00 00 00 00 - 00 00 00 00 a4 33 b0 75
    ..............3.u
    0000000000cffef0 00 00 00 00 f0 a6 e7 77 - 00 00 00 00 00 00 00 00
    ........w........
    0000000000cfff00 00 00 00 00 00 00 01 00 - 00 00 08 00 03 00 00 00
    .................
    0000000000cfff10 00 f0 fd 7f 00 d0 fa 7f - 58 08 00 00 04 08 00 00
    .........X.......
    0000000000cfff20 80 06 00 00 37 90 f5 77 - 2e d9 e7 77 00 00 08 00
    .....7..w...w....
    0000000000cfff30 00 00 00 00 3e d9 e7 77 - 18 ff cf 00 00 00 08 00
    .....>..w........
    0000000000cfff40 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000cfff50 10 00 00 00 ec fe cf 00 - 16 00 18 00 dc ff cf 00
    .................
    0000000000cfff60 09 48 e9 77 78 32 e8 77 - 00 00 00 00 00 00 00 00
    ..H.wx2.w........
    0000000000cfff70 aa 5f e7 77 03 00 00 00 - 00 33 b0 75 00 00 00 00
    .._.w.....3.u....
    0000000000cfff80 ff ff ff ff 00 00 00 00 - 45 5b a7 75 03 00 00 00
    .........E[.u....
    0000000000cfff90 00 33 b0 75 00 00 00 00 - ff ff ff ff 00 00 08 00
    ..3.u............
    0000000000cfffa0 00 00 00 00 6c d1 de 00 - ec ff cf 00 00 00 00 00
    .....l...........
    0000000000cfffb0 03 00 00 00 00 00 a7 75 - 3b d3 e7 77 00 00 00 00
    ........u;..w....
    0000000000cfffc0 6c d1 de 00 00 00 08 00 - 00 00 00 00 00 00 00 00
    l...............
    0000000000cfffd0 00 d0 fa 7f c0 ff cf 00 - 07 00 00 00 ff ff ff ff
    .................
    0000000000cfffe0 09 48 e9 77 b8 3d e8 77 - 00 00 00 00 00 00 00 00
    ..H.w.=.w........
    0000000000cffff0 00 00 00 00 ea 5a a7 75 - 00 00 00 00 00 00 00 00
    ......Z.u........
    0000000000d00000 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................

    *----> State Dump for Thread Id 0xf10 <----*

    eax=00008004 ebx=00000000 ecx=bf8830e9 edx=f005e4b4 esi=00260608
    edi=00000000
    eip=7ffe0304 esp=00d3d248 ebp=00d3d2d0 iopl=0 nv up ei pl nz na pe
    nc
    cs=001b ss=0023 ds=0060 es=0020 fs=0038 gs=0000
    efl=00000202

    function: <nosymbols>
    7ffe02f2 0000 add [eax],al
    7ffe02f4 0000 add [eax],al
    7ffe02f6 0000 add [eax],al
    *SharedUserSystemCall:
    7ffe02f8 0000 add [eax],al
    7ffe02fa 0000 add [eax],al
    7ffe02fc 0000 add [eax],al
    7ffe02fe 0000 add [eax],al
    7ffe0300 8bd4 mov edx,esp
    7ffe0302 0f34 sysenter
    7ffe0304 c3 ret
    7ffe0305 9c pushfd
    7ffe0306 810c2400010000 or dword ptr [esp],0x100
    7ffe030d 9d popfd
    7ffe030e c3 ret
    7ffe030f 8bd4 mov edx,esp
    7ffe0311 0f05 syscall
    7ffe0313 c3 ret
    7ffe0314 9c pushfd
    7ffe0315 810c2400010000 or dword ptr [esp],0x100
    7ffe031c 9d popfd

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be
    wrong.
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for
    C:\WINDOWS\system32\msvcrt.dll -
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for
    C:\WINDOWS\System32\UxTheme.dll -
    ChildEBP RetAddr Args to Child
    00d3d244 77f5c534 77f69f68 0000076c 00000000 *SharedUserSystemCall+0xc (FPO:
    [0,0,0])
    00d3d2d0 77f5b2e6 00260608 77f57e87 00260608 ntdll!NtWaitForSingleObject+0xc
    00d3d508 77c2ac14 00260000 00000000 00000478
    ntdll!RtlEnterCriticalSection+0x46
    00d3d548 77c2ac2a 00000478 77c28930 00000478 msvcrt!free+0x1a9
    00d3d58c 5ad7345d 0030027e 00000002 00d3d704 msvcrt!free+0x1bf
    00d3d5dc 77d4a8c2 0030027e 00000001 00000000 UxTheme!GetThemePartSize+0x62f
    00d3d648 77d444f5 000840b8 719cbaca 0030027e USER32!wsprintfA+0x1f3
    00d3d69c 77d4886b 004af628 00000001 00000000 USER32!PostMessageA+0xad
    00d3d6cc 77f75da3 00d3d6dc 00000060 00000060 USER32!MonitorFromRect+0x149
    00d3dbc0 77d48aa1 00000000 00f913aa 00000000
    ntdll!KiUserCallbackDispatcher+0x13
    00d3dc6c 77d48e9d 00000000 773def6c 00000000 USER32!MonitorFromRect+0x37f
    00d3dca8 7740f7c8 00000000 773def6c 00000000 USER32!CreateWindowExW+0x31
    00d3dd0c 77412732 00000000 773def6c 00000000 SHELL32!SHGetFolderPathA+0x43e
    00000200 00000000 00000000 00000000 00000000 SHELL32!OpenRegStream+0x27a

    *----> Raw Stack Dump <----*
    0000000000d3d248 34 c5 f5 77 68 9f f6 77 - 6c 07 00 00 00 00 00 00
    4..wh..wl.......
    0000000000d3d258 00 00 00 00 90 00 00 00 - 00 00 00 00 00 00 26 00
    ...............&.
    0000000000d3d268 2d 16 05 00 00 00 00 00 - 00 00 00 00 05 04 03
    0 -...............
    0000000000d3d278 00 00 00 00 00 00 00 00 - 10 0f 00 00 00 00 00 00
    .................
    0000000000d3d288 d1 47 d4 77 34 62 d7 5a - 28 00 00 00 02 00 00 00
    ..G.w4b.Z(.......
    0000000000d3d298 c4 d2 d3 00 08 02 00 00 - 00 00 00 00 d0 39 26 00
    ..............9&.
    0000000000d3d2a8 d0 39 26 00 ea 61 d7 5a - fc 61 d7 5a 10 3a 26 00
    ..9&..a.Z.a.Z.:&.
    0000000000d3d2b8 00 00 00 00 d0 39 26 00 - 7e 02 30 00 44 00 65 00
    ......9&.~.0.D.e.
    0000000000d3d2c8 00 00 00 00 6c 07 00 00 - 08 d5 d3 00 e6 b2 f5 77
    .....l..........w
    0000000000d3d2d8 08 06 26 00 87 7e f5 77 - 08 06 26 00 00 00 01 00
    ...&..~.w..&.....
    0000000000d3d2e8 78 04 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    x...............
    0000000000d3d2f8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000d3d308 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000d3d318 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000d3d328 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000d3d338 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000d3d348 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000d3d358 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000d3d368 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000d3d378 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................

    *----> State Dump for Thread Id 0x858 <----*

    eax=00eb1010 ebx=00d7fe08 ecx=00000002 edx=00000000 esi=00000000
    edi=7ffdf000
    eip=7ffe0304 esp=00d7fdc0 ebp=00d7fe5c iopl=0 nv up ei pl nz na pe
    nc
    cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000
    efl=00000202

    function: <nosymbols>
    7ffe02f2 0000 add [eax],al
    7ffe02f4 0000 add [eax],al
    7ffe02f6 0000 add [eax],al
    *SharedUserSystemCall:
    7ffe02f8 0000 add [eax],al
    7ffe02fa 0000 add [eax],al
    7ffe02fc 0000 add [eax],al
    7ffe02fe 0000 add [eax],al
    7ffe0300 8bd4 mov edx,esp
    7ffe0302 0f34 sysenter
    7ffe0304 c3 ret
    7ffe0305 9c pushfd
    7ffe0306 810c2400010000 or dword ptr [esp],0x100
    7ffe030d 9d popfd
    7ffe030e c3 ret
    7ffe030f 8bd4 mov edx,esp
    7ffe0311 0f05 syscall
    7ffe0313 c3 ret
    7ffe0314 9c pushfd
    7ffe0315 810c2400010000 or dword ptr [esp],0x100
    7ffe031c 9d popfd

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be
    wrong.
    *** ERROR: Symbol file could not be found. Defaulted to export symbols for
    C:\WINDOWS\System32\DUSER.dll -
    ChildEBP RetAddr Args to Child
    00d7fdbc 77f5c524 77e75ee0 00000002 00d7fe08 *SharedUserSystemCall+0xc (FPO:
    [0,0,0])
    00d7fe5c 77d463eb 00000002 00d7fe84 00000000
    ntdll!NtWaitForMultipleObjects+0xc
    00d7feb8 6c1ddfe0 00000001 00d7feec ffffffff USER32!SetScrollInfo+0x21f
    00d7fed8 6c1de207 000004ff ffffffff 00000001 DUSER+0x2dfe0
    00d7ff0c 6c1d88af 00d7ff4c 00000000 00000000 DUSER+0x2e207
    00d7ff2c 6c1d540e 00d7ff4c 00000000 00000000 DUSER!GetMessageExA+0x42
    00d7ff80 77c37fb8 00000000 00000012 002609e8 DUSER!DUserStopAnimation+0x90d5
    00d7ffb4 77e7d33b 0026bde0 00000012 002609e8 msvcrt!endthreadex+0xa0
    00d7ffec 00000000 77c37f49 0026bde0 00000000
    kernel32!RegisterWaitForInputIdle+0x43

    *----> Raw Stack Dump <----*
    0000000000d7fdc0 24 c5 f5 77 e0 5e e7 77 - 02 00 00 00 08 fe d7 00
    $..w.^.w........
    0000000000d7fdd0 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000d7fde0 02 00 00 00 04 00 00 00 - 02 00 00 00 00 00 00 00
    .................
    0000000000d7fdf0 00 00 00 00 f1 ab e7 77 - 00 00 b9 00 02 00 00 00
    ........w........
    0000000000d7fe00 00 f0 fd 7f 00 b0 fa 7f - 44 09 00 00 64 06 00 00
    .........D...d...
    0000000000d7fe10 00 20 eb 00 24 6c 1c 6c - 00 20 eb 00 00 00 00 00 .
    ...$l.l. ......
    0000000000d7fe20 30 6c 1c 6c 00 00 00 00 - 08 fe d7 00 00 20 eb 00
    0l.l......... ..
    0000000000d7fe30 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000d7fe40 10 00 00 00 dc fd d7 00 - 10 1e 1b 6c a4 ff d7 00
    ............l....
    0000000000d7fe50 09 48 e9 77 78 32 e8 77 - 00 00 00 00 b8 fe d7 00
    ..H.wx2.w........
    0000000000d7fe60 eb 63 d4 77 02 00 00 00 - 84 fe d7 00 00 00 00 00
    ..c.w............
    0000000000d7fe70 ff ff ff ff 00 00 00 00 - e0 88 0e 00 01 00 00 00
    .................
    0000000000d7fe80 4c ff d7 00 44 09 00 00 - 64 06 00 00 ff ff ff ff
    L...D...d.......
    0000000000d7fe90 9f 03 1e 6c 22 83 8f 00 - 08 40 db 01 01 00 00 00
    ....l"....@......
    0000000000d7fea0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    0000000000d7feb0 00 b0 fa 7f 64 06 00 00 - d8 fe d7 00 e0 df 1d 6c
    .....d..........l
    0000000000d7fec0 01 00 00 00 ec fe d7 00 - ff ff ff ff ff 04 00 00
    .................
    0000000000d7fed0 84 fe d7 00 ff ff ff ff - 0c ff d7 00 07 e2 1d 6c
    ................l
    0000000000d7fee0 ff 04 00 00 ff ff ff ff - 01 00 00 00 44 09 00 00
    .............D...
    0000000000d7fef0 00 00 00 00 00 00 00 00 - e0 bd 26 00 01 00 00 00
    ...........&.....

    *----> State Dump for Thread Id 0xe8c <----*

    eax=00000001 ebx=00000000 ecx=f0567b24 edx=f0567d64 esi=00260608
    edi=00000000
    eip=7ffe0304 esp=0202fb90 ebp=0202fc18 iopl=0 nv up ei pl nz na pe
    nc
    cs=001b ss=0023 ds=9326 es=0000 fs=0038 gs=0000
    efl=00000202

    function: <nosymbols>
    7ffe02f2 0000 add [eax],al
    7ffe02f4 0000 add [eax],al
    7ffe02f6 0000 add [eax],al
    *SharedUserSystemCall:
    7ffe02f8 0000 add [eax],al
    7ffe02fa 0000 add [eax],al
    7ffe02fc 0000 add [eax],al
    7ffe02fe 0000 add [eax],al
    7ffe0300 8bd4 mov edx,esp
    7ffe0302 0f34 sysenter
    7ffe0304 c3 ret
    7ffe0305 9c pushfd
    7ffe0306 810c2400010000 or dword ptr [esp],0x100
    7ffe030d 9d popfd
    7ffe030e c3 ret
    7ffe030f 8bd4 mov edx,esp
    7ffe0311 0f05 syscall
    7ffe0313 c3 ret
    7ffe0314 9c pushfd
    7ffe0315 810c2400010000 or dword ptr [esp],0x100
    7ffe031c 9d popfd

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be
    wrong.
    ChildEBP RetAddr Args to Child
    0202fb8c 77f5c534 77f69f68 0000076c 00000000 *SharedUserSystemCall+0xc (FPO:
    [0,0,0])
    0202fc18 77f5b2e6 00260608 77f57e87 00260608 ntdll!NtWaitForSingleObject+0xc
    0202fe50 77c2ac14 00260000 00000000 00000478
    ntdll!RtlEnterCriticalSection+0x46
    0202fe90 77c2ac2a 00000478 77c28930 00000478 msvcrt!free+0x1a9
    0202fed4 5ad743ef 00150260 00000002 00000005 msvcrt!free+0x1bf
    0202ff24 5ad71b48 00000000 00000000 00000001 UxTheme!CloseThemeData+0x118
    0202ff84 77d4a3b1 00150260 00000085 00000001
    UxTheme!DrawThemeParentBackground+0x4d1
    0202ffc0 77f75da3 0202ffd0 00000018 004a60b8 USER32!CharPrevA+0x95
    00000000 00000000 00000000 00000000 00000000
    ntdll!KiUserCallbackDispatcher+0x13

    *----> Raw Stack Dump <----*
    000000000202fb90 34 c5 f5 77 68 9f f6 77 - 6c 07 00 00 00 00 00 00
    4..wh..wl.......
    000000000202fba0 00 00 00 00 90 00 00 00 - 00 00 00 00 00 00 26 00
    ...............&.
    000000000202fbb0 5d 16 05 00 00 00 00 00 - 00 00 00 00 05 04 03
    0 ]...............
    000000000202fbc0 af 00 00 c0 00 00 00 00 - a0 fb 02 02 00 00 00 00
    .................
    000000000202fbd0 74 ff 02 02 b0 3e c3 77 - 60 20 c1 77 ff ff ff ff
    t....>.w` .w....
    000000000202fbe0 95 af c2 77 39 b3 d7 5a - 00 00 00 00 20 fe 02 02
    ....w9..Z.... ...
    000000000202fbf0 60 02 15 00 d0 39 26 00 - fc 61 d7 5a 10 3a 26 00
    `....9&..a.Z.:&.
    000000000202fc00 00 00 00 00 d0 39 26 00 - 60 02 15 00 00 00 00 00
    ......9&.`.......
    000000000202fc10 00 00 00 00 6c 07 00 00 - 50 fe 02 02 e6 b2 f5 77
    .....l...P......w
    000000000202fc20 08 06 26 00 87 7e f5 77 - 08 06 26 00 00 00 01 00
    ...&..~.w..&.....
    000000000202fc30 78 04 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    x...............
    000000000202fc40 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000202fc50 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000202fc60 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000202fc70 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000202fc80 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000202fc90 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000202fca0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000202fcb0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000202fcc0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................

    *----> State Dump for Thread Id 0xaa4 <----*

    eax=00000000 ebx=00000000 ecx=00000002 edx=00000000 esi=00260608
    edi=00000000
    eip=7ffe0304 esp=0201f8ec ebp=0201f974 iopl=0 nv up ei pl nz na pe
    nc
    cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
    efl=00000202

    function: <nosymbols>
    7ffe02f2 0000 add [eax],al
    7ffe02f4 0000 add [eax],al
    7ffe02f6 0000 add [eax],al
    *SharedUserSystemCall:
    7ffe02f8 0000 add [eax],al
    7ffe02fa 0000 add [eax],al
    7ffe02fc 0000 add [eax],al
    7ffe02fe 0000 add [eax],al
    7ffe0300 8bd4 mov edx,esp
    7ffe0302 0f34 sysenter
    7ffe0304 c3 ret
    7ffe0305 9c pushfd
    7ffe0306 810c2400010000 or dword ptr [esp],0x100
    7ffe030d 9d popfd
    7ffe030e c3 ret
    7ffe030f 8bd4 mov edx,esp
    7ffe0311 0f05 syscall
    7ffe0313 c3 ret
    7ffe0314 9c pushfd
    7ffe0315 810c2400010000 or dword ptr [esp],0x100
    7ffe031c 9d popfd

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be
    wrong.
    ChildEBP RetAddr Args to Child
    0201f8e8 77f5c534 77f69f68 0000076c 00000000 *SharedUserSystemCall+0xc (FPO:
    [0,0,0])
    0201f974 77f5b2e6 00260608 77f57e87 00260608 ntdll!NtWaitForSingleObject+0xc
    0201fbac 77c2aa33 00260000 00000008 00000088
    ntdll!RtlEnterCriticalSection+0x46
    0201fbec 77c1eaa3 00000001 00000088 00000000 msvcrt!calloc+0xee
    0201fc04 77f5b42c 77c10000 00000002 00000000 msvcrt!_getmainargs+0x19a
    0201fc24 77f62b48 77c1e94f 77c10000 00000002 ntdll!LdrInitializeThunk+0x24
    0201fc9c 77f553e5 0201fd2c 0201fd2c 00000004 ntdll!LdrShutdownThread+0x244
    0201fd18 77f75d87 0201fd2c 77f50000 00000000 ntdll+0x53e5
    00000000 00000000 00000000 00000000 00000000 ntdll!KiUserApcDispatcher+0x7

    *----> Raw Stack Dump <----*
    000000000201f8ec 34 c5 f5 77 68 9f f6 77 - 6c 07 00 00 00 00 00 00
    4..wh..wl.......
    000000000201f8fc 00 00 00 00 12 00 00 00 - 00 00 00 00 00 00 26 00
    ...............&.
    000000000201f90c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000201f91c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000201f92c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000201f93c 00 00 00 00 00 00 00 00 - 00 00 00 00 7c f9 01 02
    .............|...
    000000000201f94c 00 00 26 00 a8 44 f9 77 - 12 00 00 00 e8 09 26 00
    ...&..D.w......&.
    000000000201f95c 00 00 00 00 00 00 00 00 - 54 f9 01 02 00 00 00 00
    .........T.......
    000000000201f96c 00 00 00 00 6c 07 00 00 - ac fb 01 02 e6 b2 f5 77
    .....l..........w
    000000000201f97c 08 06 26 00 87 7e f5 77 - 08 06 26 00 00 00 00 00
    ...&..~.w..&.....
    000000000201f98c 88 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000201f99c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000201f9ac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000201f9bc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000201f9cc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000201f9dc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000201f9ec 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000201f9fc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000201fa0c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................
    000000000201fa1c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00
    .................





    Thanks in advance

    my email is number 1 at hotmail dot com, with 3 M's not one
    J.B, Jul 16, 2004
    #1
    1. Advertising

Want to reply to this thread or ask your own question?

It takes just 2 minutes to sign up (and it's free!). Just click the sign up button to choose a username and then you can ask your own questions on the forum.
Similar Threads
  1. Bob

    Re: Windows keeps shutting itself down

    Bob, Aug 12, 2003, in forum: Computer Support
    Replies:
    0
    Views:
    505
  2. National Enforment Team

    Re: Windows keeps shutting itself down

    National Enforment Team, Aug 12, 2003, in forum: Computer Support
    Replies:
    0
    Views:
    423
    National Enforment Team
    Aug 12, 2003
  3. William Poaster

    Re: Windows keeps shutting itself down

    William Poaster, Aug 12, 2003, in forum: Computer Support
    Replies:
    0
    Views:
    2,530
    William Poaster
    Aug 12, 2003
  4. Champagne Charlie

    PC keeps shutting down!

    Champagne Charlie, May 19, 2004, in forum: Computer Support
    Replies:
    3
    Views:
    62,721
    =?ISO-8859-1?Q?R=F4g=EAr?=
    May 19, 2004
  5. me

    Windows Explorer keeps shutting down

    me, Nov 29, 2004, in forum: Computer Information
    Replies:
    2
    Views:
    5,012
    Thagor
    Dec 1, 2004
Loading...

Share This Page