Hi all,
I'm running Win 2K Pro SP2 on a Toshiba Satellite 4080XCDT notebook (PII 366Mhtz, 128Mb RAM, 6.03Gb HDD which is partitioned into C (3.59Gb) & D (2.44Gb)).

I am having an intermittent problem which only shows itself right after bootup. The system seems to have begun corretly and I'm logged in to my User Account, but when I try to do anything I immediately get an Error message saying "Explorer has caused errors and will be shut down. You will need to restart this program."
The application Event Viewer shows the following error message:

Event Type: Information
Event Source: Winlogon
Event Category: None
Event ID: 1002
Date: 30/09/2001
Time: 07:54:46
User: N/A
Computer: JRP-TOSHIBA-01
Description:
The shell stopped unexpectedly and Explorer.exe was restarted.

And Dr. Watson shows the error message, which is pasted at the end of this message.

Once Explorer.exe restarts I loose 75% of my System Tray Icons and unless I either log off and back on, or reboot the system, it remains unstable and prone to further crashes.

Programs I have starting up with Windows are:
McAfee AntiVirus 5.21 (with latest Scan Engine and Dats)
Adaptect Direct CD Wizard (3.05)
MS Intellimouse (4.01)
GetRight (4.5)
ZoneAlarm Pro 2.6.231
PGP Personal Security 7.0.3
Also Toshiba PowerSaver Utility (2.00.04)

Any advice as to what is causing this problem and how to circumvent it would be most welcome.

Thank you,

Rtn. Jonathan R. Portwood.


Dr. Watson Error Message:
Application exception occurred:
App: explorer.exe (pid=1240)
When: 30/09/2001 @ 07:51:55.458
Exception number: c0000005 (access violation)

*----> System Information <----*
Computer Name: JRP-TOSHIBA-01
User Name: Jonathan
Number of Processors: 1
Processor Type: x86 Family 6 Model 6 Stepping 10
Windows 2000 Version: 5.0
Current Build: 2195
Service Pack: 2
Current Type: Uniprocessor Free
Registered Organization: Neighbours South Asia
Registered Owner: Jonathan R. Portwood

*----> Task List <----*
0 Idle.exe
8 System.exe
180 SMSS.exe
208 CSRSS.exe
228 WINLOGON.exe
256 SERVICES.exe
268 LSASS.exe
404 svchost.exe
460 svchost.exe
512 spoolsv.exe
544 Avsynmgr.exe
560 cisvc.exe
576 DKService.exe
616 Mcshield.exe
660 PGPsdkServ.exe
732 LOCATOR.exe
756 stisvc.exe
844 thotkey.exe
876 TMESRV.exe
892 VSStat.exe
900 vsmon.exe
932 vshwin32.exe
960 WinMgmt.exe
1016 PGPservice.exe
1048 WebScanX.exe
1136 minilog.exe
1240 explorer.exe
1268 NTVDM.exe
1204 TPWRTRAY.exe
1300 TDEVDETECT.exe
1312 TFUNCKEY.exe
1320 TPWRICON.exe
1116 directcd.exe
696 point32.exe
1336 AlogServ.exe
1352 internat.exe
1364 datray.exe
1380 AcroTray.exe
1424 getright.exe
1440 PGPtray.exe
1452 zapro.exe
1332 MSOFFICE.exe
1532 cidaemon.exe
1560 DRWTSN32.exe
0 _Total.exe

(00400000 - 0043E000)
(77F80000 - 77FFB000)
(77DB0000 - 77E0B000)
(77E80000 - 77F35000)
(77D40000 - 77DAC000)
(77F40000 - 77F7C000)
(77E10000 - 77E74000)
(70BD0000 - 70C1C000)
(71700000 - 7178A000)
(6CA60000 - 6CA68000)
(66650000 - 666A4000)
(20000000 - 20025000)
(23000000 - 2304B000)
(782F0000 - 78532000)
(77A50000 - 77B3A000)
(775A0000 - 77625000)
(779B0000 - 77A4B000)
(78000000 - 78046000)
(77840000 - 7787C000)
(770C0000 - 770E3000)
(71500000 - 7161B000)
(71110000 - 711D9000)
(5F400000 - 5F4F2000)
(00FA0000 - 00FA7000)
(76F20000 - 76F95000)
(75030000 - 75043000)
(75020000 - 75028000)
(76DF0000 - 76E01000)
(77C10000 - 77C6D000)
(75090000 - 750A0000)
(75160000 - 7516C000)
(75210000 - 75225000)
(751D0000 - 75208000)
(75170000 - 751BF000)
(77BE0000 - 77BEF000)
(751C0000 - 751C6000)
(75150000 - 75160000)
(77950000 - 77979000)
(77980000 - 779A4000)
(75050000 - 75058000)
(11C00000 - 11C36000)
(77820000 - 77827000)
(759B0000 - 759B6000)
(70320000 - 70362000)
(10000000 - 10012000)
(766D0000 - 766E8000)
(76740000 - 76748000)
(77880000 - 7790D000)
(766F0000 - 766F7000)
(77570000 - 775A0000)
(770F0000 - 772A7000)
(013A0000 - 013DA000)
(76B30000 - 76B6E000)
(12000000 - 1213C000)
(01640000 - 0168C000)
(01820000 - 01847000)
(74FF0000 - 75002000)
(01960000 - 01966000)
(11400000 - 1144B000)
(11D00000 - 11D10000)
(11A00000 - 11A41000)
(11700000 - 11751000)
(13000000 - 1300D000)
(77560000 - 77569000)
(77400000 - 77408000)
(77410000 - 77423000)
(6B050000 - 6B13A000)
(66130000 - 66178000)
(63000000 - 63079000)
(77530000 - 77552000)
(76710000 - 76719000)
(76FA0000 - 76FAF000)
(773E0000 - 773F2000)
(76290000 - 762CC000)
(6DE80000 - 6DEE1000)
(03220000 - 03227000)
(61220000 - 6122B000)
(6E420000 - 6E426000)
(75E60000 - 75E7A000)
(61210000 - 61219000)
(032A0000 - 032A9000)
(690A0000 - 690AB000)

State Dump for Thread Id 0x4e8

eax=0006f9bc ebx=00000000 ecx=00000148 edx=0000037c esi=01113e90 edi=690a0000
eip=00000000 esp=0006f988 ebp=011121c0 iopl=0 nv up ei pl nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000206


function: <nosymbols>
FAULT ->00000000 ???
00000001 ???
00000002 ???
00000003 ???

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0006F984 11C08701 0000037C 01113E90 00000148 0006F9BC explorer!<nosymbols>
011121C0 011121A0 01112140 751C0000 75150000 77950000 !ScanXUnLoadOtherDlls
61210000 00000003 00000004 0000FFFF 000000B8 00000000 <nosymbols>

*----> Raw Stack Dump <----*
0006f988 01 87 c0 11 7c 03 00 00 - 90 3e 11 01 48 01 00 00 ....|....>..H...
0006f998 bc f9 06 00 38 fe 06 00 - 00 00 2a 03 00 fe 06 00 ....8.....*.....
0006f9a8 00 00 00 00 48 01 00 00 - 00 00 00 ff f8 f9 06 00 ....H...........
0006f9b8 00 00 0a 69 00 00 00 00 - 90 3e 11 01 00 00 00 00 ...i.....>......
0006f9c8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0006f9d8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0006f9e8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0006f9f8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0006fa08 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0006fa18 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0006fa28 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0006fa38 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0006fa48 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0006fa58 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0006fa68 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0006fa78 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0006fa88 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0006fa98 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0006faa8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0006fab8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

State Dump for Thread Id 0x2ac

eax=00000001 ebx=00449fb0 ecx=11c1c470 edx=00000000 esi=00000411 edi=000004d0
eip=77e1392f esp=00def950 ebp=00def984 iopl=0 nv up ei pl nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000206


function: GetQueueStatus
77e13916 e177 loope IsRectEmpty+0x38 (77e15d8f)
77e13918 2439 and al,0x39
77e1391a e177 loope IsRectEmpty+0x3c (77e15d93)
77e1391c 2439 and al,0x39
77e1391e e177 loope IsRectEmpty+0x40 (77e15d97)
77e13920 2439 and al,0x39
77e13922 e177 loope LookupIconIdFromDirectoryEx+0x1e3 (77e1f19b)
77e13924 b8bc110000 mov eax,0x11bc
77e13929 8d542404 lea edx,[esp+0x4] ss:019acf23=????????
77e1392d cd2e int 2e
77e1392f c21c00 ret 0x1c
77e13932 8b442404 mov eax,[esp+0x4] ss:019acf23=????????
77e13936 cd2b int 2b
77e13938 e9de740300 jmp SetClassLongW+0x641 (77e4ae1b)
77e1393d 55 push ebp
77e1393e 8bec mov ebp,esp
77e13940 83ec0c sub esp,0xc
77e13943 8b4508 mov eax,[ebp+0x8] ss:019acf56=????????
77e13946 8365f800 and dword ptr [ebp+0xf8],0x0 ss:019acf56=????????
77e1394a 8365fc00 and dword ptr [ebp+0xfc],0x0 ss:019acf56=????????
77e1394e ff7010 push dword ptr [eax+0x10] ds:00bbd5d3=????????
77e13951 ff700c push dword ptr [eax+0xc] ds:00bbd5d3=????????

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
00DEF984 77E15B27 00449FB0 00000411 000004D0 000004D8 user32!GetQueueStatus
00DEF9A4 78316825 000200F2 00000411 000004D0 000004D8 user32!SendMessageW
00DEF9E8 78323AE0 000202BA 00008003 0C02B7FF 0000C0B2 shell32!Ordinal2
00DEFA08 7111E1C0 000202BA 00008003 0C02B7FF 0000C0B2 shell32!Ordinal640
00DEFA30 7111E1EA 000202BA 0000C0B2 00091898 0C02B7FF BROWSEUI!DllCanUnloadNow
00DEFAAC 7111CEDC 000202A8 80004005 000BB4E8 000D0F8C BROWSEUI!DllCanUnloadNow
00DEFAD4 70BE6206 000BB4EC 00000000 000D0F5C 000BB4E8 BROWSEUI!DllCanUnloadNow
00DEFAF0 7112E656 000BB4EC 000D0F5C 00000000 000AB5D8 SHLWAPI!Ordinal174
000D0F80 000BB4E8 000BB524 00000000 00000006 00000000 BROWSEUI!DllGetClassObject
00000000 00000000 00000000 00000000 00000000 00000000 <nosymbols>

*----> Raw Stack Dump <----*
00def950 9c 4a e1 77 f2 00 02 00 - 11 04 00 00 d0 04 00 00 .J.w............
00def960 d8 04 00 00 00 00 00 00 - ae 02 00 00 00 00 00 00 ................
00def970 d0 04 00 00 11 04 00 00 - 28 fa de 00 f2 00 02 00 ........(.......
00def980 58 0b 00 00 a4 f9 de 00 - 27 5b e1 77 b0 9f 44 00 X.......'[.w..D.
00def990 11 04 00 00 d0 04 00 00 - d8 04 00 00 00 00 00 00 ................
00def9a0 00 00 00 80 e8 f9 de 00 - 25 68 31 78 f2 00 02 00 ........%h1x....
00def9b0 11 04 00 00 d0 04 00 00 - d8 04 00 00 dd 63 be 70 .............c.p
00def9c0 bc 15 0a 00 40 15 0a 00 - b2 c0 00 00 ba 02 02 00 ....@...........
00def9d0 00 80 00 00 f2 00 02 00 - 00 00 00 00 00 00 00 00 ................
00def9e0 d8 04 00 00 00 00 00 00 - 08 fa de 00 e0 3a 32 78 .............:2x
00def9f0 ba 02 02 00 03 80 00 00 - ff b7 02 0c b2 c0 00 00 ................
00defa00 01 00 00 00 28 fa de 00 - 30 fa de 00 c0 e1 11 71 ....(...0......q
00defa10 ba 02 02 00 03 80 00 00 - ff b7 02 0c b2 c0 00 00 ................
00defa20 01 00 00 00 28 fa de 00 - 98 18 09 00 01 00 00 00 ....(...........
00defa30 ac fa de 00 ea e1 11 71 - ba 02 02 00 b2 c0 00 00 .......q........
00defa40 98 18 09 00 ff b7 02 0c - 03 80 00 00 01 00 00 00 ................
00defa50 40 15 0a 00 3f 90 12 71 - ba 02 02 00 98 18 09 00 @...?..q........
00defa60 ff b7 02 0c 03 00 00 00 - 40 15 0a 00 fc 8f 12 71 [email protected]
00defa70 20 16 0a 00 98 f2 12 71 - c2 1c bd 70 20 16 0a 00 ......q...p ...
00defa80 00 00 00 00 02 0e 13 71 - a8 02 02 00 44 b5 0b 00 .......q....D...

State Dump for Thread Id 0x4bc

eax=032a0004 ebx=00000007 ecx=00008000 edx=00000000 esi=77f8281e edi=00000007
eip=77f82829 esp=00fefd98 ebp=00fefde4 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000246


function: NtWaitForMultipleObjects
77f8281e b8e9000000 mov eax,0xe9
77f82823 8d542404 lea edx,[esp+0x4] ss:01bad36b=00000000
77f82827 cd2e int 2e
77f82829 c21400 ret 0x14

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
00FEFDE4 77E1375E 00FEFDBC 00000001 00000000 00000000 ntdll!NtWaitForMultipleObjects
00FEFE40 77E1382B 00FEFE0C 00FEFEB8 FFFFFFFF 000000FF user32!MsgWaitForMultipleObjectsEx
00FEFE5C 782F3546 00000006 00FEFEB8 00000000 FFFFFFFF user32!MsgWaitForMultipleObjects
7840A2F0 FFFFFFFF 00000000 00000000 00000180 00000000 shell32!Ordinal200
77FD0120 7840A2F0 77FD0148 77FD0108 00000037 00000037 <nosymbols>
00000000 00000000 00000000 00000000 00000000 00000000 shell32!<nosymbols>

State Dump for Thread Id 0x500

eax=7118940c ebx=00000002 ecx=00000156 edx=00000000 esi=77f8281e edi=00000002
eip=77f82829 esp=0103fe5c ebp=0103fea8 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000246


function: NtWaitForMultipleObjects
77f8281e b8e9000000 mov eax,0xe9
77f82823 8d542404 lea edx,[esp+0x4] ss:01bfd42f=????????
77f82827 cd2e int 2e
77f82829 c21400 ret 0x14

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0103FEA8 77E1375E 0103FE80 00000001 00000000 0103FEA0 ntdll!NtWaitForMultipleObjects
0103FF04 77E1382B 0103FED0 70C160A8 0000EA60 00000041 user32!MsgWaitForMultipleObjectsEx
0103FF20 70BD189D 00000001 70C160A8 00000000 0000EA60 user32!MsgWaitForMultipleObjects
0103FF74 70BDAF71 0103FFA0 0103FFA4 0103FFA8 0103FF9C SHLWAPI!Ordinal60
0103FFAC 70BDAED7 00000000 77E8758A 00000000 7FFDE000 SHLWAPI!PathRemoveFileSpecW
0103FFEC 00000000 00000000 00000000 00000000 00000000 SHLWAPI!PathRemoveFileSpecW

State Dump for Thread Id 0x278

eax=000000c0 ebx=00defcfc ecx=77e8b80f edx=00000000 esi=ffffffff edi=00000557
eip=77f82231 esp=0139ffa0 ebp=0139ffb4 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246


function: ZwDelayExecution
77f82226 b832000000 mov eax,0x32
77f8222b 8d542404 lea edx,[esp+0x4] ss:01f5d573=4f26bcd7
77f8222f cd2e int 2e
77f82231 c20800 ret 0x8

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0139FFB4 77E8758A 00DEFCFC 00000557 FFFFFFFF 00DEFCFC ntdll!ZwDelayExecution
0139FFEC 00000000 77F89D5D 00DEFCFC 00000000 00905A4D kernel32!SetFilePointer

*----> Raw Stack Dump <----*
0139ffa0 9f 9d f8 77 01 00 00 00 - ac ff 39 01 00 00 00 00 ...w......9.....
0139ffb0 00 00 00 80 ec ff 39 01 - 8a 75 e8 77 fc fc de 00 ......9..u.w....
0139ffc0 57 05 00 00 ff ff ff ff - fc fc de 00 00 70 fd 7f W............p..
0139ffd0 0f b8 e8 77 c0 ff 39 01 - 0f b8 e8 77 ff ff ff ff ...w..9....w....
0139ffe0 5b 61 e8 77 80 b5 e8 77 - 00 00 00 00 00 00 00 00 [a.w...w........
0139fff0 00 00 00 00 5d 9d f8 77 - fc fc de 00 00 00 00 00 ....]..w........
013a0000 4d 5a 90 00 03 00 00 00 - 04 00 00 00 ff ff 00 00 MZ..............
013a0010 b8 00 00 00 00 00 00 00 - 40 00 00 00 00 00 00 00 ........@.......
013a0020 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
013a0030 00 00 00 00 00 00 00 00 - 00 00 00 00 e0 00 00 00 ................
013a0040 0e 1f ba 0e 00 b4 09 cd - 21 b8 01 4c cd 21 54 68 ........!..L.!Th
013a0050 69 73 20 70 72 6f 67 72 - 61 6d 20 63 61 6e 6e 6f is program canno
013a0060 74 20 62 65 20 72 75 6e - 20 69 6e 20 44 4f 53 20 t be run in DOS
013a0070 6d 6f 64 65 2e 0d 0d 0a - 24 00 00 00 00 00 00 00 mode....$.......
013a0080 0d 71 f0 75 49 10 9e 26 - 49 10 9e 26 49 10 9e 26 .q.uI..&I..&I..&
013a0090 32 0c 92 26 48 10 9e 26 - ca 0c 90 26 51 10 9e 26 2..&H..&...&Q..&
013a00a0 49 10 9f 26 f3 10 9e 26 - 10 33 8d 26 5a 10 9e 26 I..&...&.3.&Z..&
013a00b0 a1 0f 95 26 4a 10 9e 26 - a1 0f 94 26 34 10 9e 26 ...&J..&...&4..&
013a00c0 f1 16 98 26 48 10 9e 26 - a1 0f 9a 26 48 10 9e 26 ...&H..&...&H..&
013a00d0 52 69 63 68 49 10 9e 26 - 00 00 00 00 00 00 00 00 RichI..&........

State Dump for Thread Id 0x174

eax=76f24ca8 ebx=00000000 ecx=00458760 edx=00000000 esi=0152fed8 edi=00000000
eip=77e1325c esp=0152fe98 ebp=0152feb0 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000246


function: TranslateMessageEx
77e1323a 0f8500c40200 jne EnumDesktopWindows+0xd88 (77e3f640)
77e13240 33c0 xor eax,eax
77e13242 c20800 ret 0x8
77e13245 ff742408 push dword ptr [esp+0x8] ss:020ed46b=????????
77e13249 51 push ecx
77e1324a e8b7370000 call GetKeyState+0x92 (77e16a06)
77e1324f ebf1 jmp DialogBoxIndirectParamAorW+0x6ba (77e1eb42)
77e13251 b89a110000 mov eax,0x119a
77e13256 8d542404 lea edx,[esp+0x4] ss:020ed46b=????????
77e1325a cd2e int 2e
77e1325c c21000 ret 0x10

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0152FEB0 76F218F0 0152FED8 00000000 00000000 00000000 user32!TranslateMessageEx
00000001 00000000 00000000 00000000 00000000 00000000 netshell!DllGetClassObject

*----> Raw Stack Dump <----*
0152fe98 86 32 e1 77 d8 fe 52 01 - 00 00 00 00 00 00 00 00 .2.w..R.........
0152fea8 00 00 00 00 5f 32 e1 77 - 01 00 00 00 f0 18 f2 76 ...._2.w.......v
0152feb8 d8 fe 52 01 00 00 00 00 - 00 00 00 00 00 00 00 00 ..R.............
0152fec8 00 00 00 00 80 9f 09 00 - 28 ff 52 01 40 9c 00 00 ........(.R.@...
0152fed8 0a 01 01 00 18 02 00 00 - 0a 00 00 00 00 00 00 00 ................
0152fee8 a1 1d 09 00 55 03 00 00 - d9 02 00 00 b7 a2 f8 77 ....U..........w
0152fef8 00 00 00 00 00 00 00 00 - 00 00 00 00 40 9c 00 00 ............@...
0152ff08 30 f4 fc 77 30 f4 fc 77 - fc fe 52 01 30 f4 fc 77 0..w0..w..R.0..w
0152ff18 a4 ff 52 01 a7 9d fb 77 - 00 a3 f8 77 00 00 00 00 ..R....w...w....
0152ff28 b4 ff 52 01 d0 9e f8 77 - 00 00 00 00 00 00 00 00 ..R....w........
0152ff38 80 9f 09 00 04 01 00 00 - 00 00 00 00 e8 fc de 00 ................
0152ff48 10 2f 06 80 00 4f 4c 83 - a0 4d 4c 83 00 00 00 00 ./...OL..ML.....
0152ff58 2c fb 31 e1 00 00 00 00 - 28 fb 39 e1 00 00 00 00 ,.1.....(.9.....
0152ff68 ac 8c 55 ef 00 00 00 00 - 30 4f 4c 83 05 00 00 00 ..U.....0OL.....
0152ff78 00 00 00 00 00 00 00 00 - 00 7c 28 e8 ff ff ff ff .........|(.....
0152ff88 00 00 00 00 63 a2 f8 77 - 0b 0c 43 80 60 9d 2a 83 ....c..w..C.`.*.
0152ff98 80 9f 09 00 3c ff 52 01 - 01 01 00 00 dc ff 52 01 ....<.R.......R.
0152ffa8 a7 9d fb 77 e8 69 f9 77 - 00 00 00 00 ec ff 52 01 ...w.i.w......R.
0152ffb8 8a 75 e8 77 e8 fc de 00 - 04 01 00 00 00 00 00 00 .u.w............
0152ffc8 e8 fc de 00 00 60 fd 7f - 20 00 00 00 c0 ff 52 01 .....`.. .....R.

State Dump for Thread Id 0x3e4

eax=703241c4 ebx=00000003 ecx=00010101 edx=00000000 esi=77f8281e edi=00000003
eip=77f82829 esp=016cff20 ebp=016cff6c iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000246


function: NtWaitForMultipleObjects
77f8281e b8e9000000 mov eax,0xe9
77f82823 8d542404 lea edx,[esp+0x4] ss:0228d4f3=????????
77f82827 cd2e int 2e
77f82829 c21400 ret 0x14

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
016CFF6C 77E86E1A 016CFF44 00000001 00000000 00000000 ntdll!NtWaitForMultipleObjects
016CFFB4 77E8758A 00000000 00000000 00DEFA40 00000000 kernel32!WaitForMultipleObjects
016CFFEC 00000000 00000000 00000000 00000000 00000000 kernel32!SetFilePointer

State Dump for Thread Id 0x4d4

eax=0170004f ebx=00000000 ecx=00000002 edx=00000000 esi=0170fd78 edi=00000000
eip=77f8116c esp=0170fbd0 ebp=0170fc0c iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000246


function: ZwPowerInformation
77f81161 b873000000 mov eax,0x73
77f81166 8d542404 lea edx,[esp+0x4] ss:022cd1a3=????????
77f8116a cd2e int 2e
77f8116c c21400 ret 0x14

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0170FC0C 766D19B1 0170FC1C C0000000 00000001 00000001 ntdll!ZwPowerInformation
0170FC28 766D33AF 766D3BF9 00010112 0000000A 00000000 stobject!DllGetClassObject
0170FC48 77E12E98 00010112 00000218 0000000A 00000000 stobject!DllCanUnloadNow
0170FC68 77E130E0 766D284E 00010112 00000218 0000000A user32!ScrollDC
0170FCF4 77E1320F 0170FD70 00000000 77E19B25 0170FD70 user32!ScrollDC
0170FD24 766D16C8 00010112 00459ED8 00003000 766D0000 user32!DispatchMessageW
0170FD90 766D159D 00010112 00000000 766D2458 00000001 stobject!DllGetClassObject
0170FFB4 77E8758A 00000000 00003000 016CFFFC 00000000 stobject!DllGetClassObject
0170FFEC 00000000 766D1558 00000000 00000000 000000C8 kernel32!SetFilePointer

*----> Raw Stack Dump <----*
0170fbd0 b6 2c e8 77 05 00 00 00 - 00 00 00 00 00 00 00 00 .,.w............
0170fbe0 ec fb 70 01 20 00 00 00 - 00 00 00 c0 00 00 00 00 ..p. ...........
0170fbf0 c9 00 0f 00 19 01 0f 00 - 00 00 00 00 00 00 00 00 ................
0170fc00 01 00 00 00 ff ff ff ff - ff ff ff ff 28 fc 70 01 ............(.p.
0170fc10 b1 19 6d 76 1c fc 70 01 - 00 00 00 c0 01 00 00 00 ..mv..p.........
0170fc20 01 00 00 00 01 00 00 00 - 48 fc 70 01 af 33 6d 76 ........H.p..3mv
0170fc30 f9 3b 6d 76 12 01 01 00 - 0a 00 00 00 00 00 00 00 .;mv............
0170fc40 70 fd 70 01 78 fd 70 01 - 68 fc 70 01 98 2e e1 77 p.p.x.p.h.p....w
0170fc50 12 01 01 00 18 02 00 00 - 0a 00 00 00 00 00 00 00 ................
0170fc60 78 fd 70 01 cd ab ba dc - f4 fc 70 01 e0 30 e1 77 x.p.......p..0.w
0170fc70 4e 28 6d 76 12 01 01 00 - 18 02 00 00 0a 00 00 00 N(mv............
0170fc80 00 00 00 00 d8 9e 45 00 - 70 fd 70 01 02 00 00 00 ......E.p.p.....
0170fc90 dc ff 70 01 8a 1c e6 77 - 20 46 e2 77 ff ff ff ff ..p....w F.w....
0170fca0 c4 fc 70 01 4f 46 e2 77 - d4 fc 70 01 e4 fc 70 01 ..p.OF.w..p...p.
0170fcb0 5f 46 e2 77 00 00 00 00 - 00 00 00 00 20 00 00 00 _F.w........ ...
0170fcc0 e4 fc 70 01 1c fd 70 01 - 2f 03 fa 77 00 00 00 00 ..p...p./..w....
0170fcd0 0a 00 00 00 00 00 00 00 - d8 9e 45 00 84 fc 70 01 ..........E...p.
0170fce0 70 fd 70 01 dc ff 70 01 - 8a 1c e6 77 f8 31 e1 77 p.p...p....w.1.w
0170fcf0 ff ff ff ff 24 fd 70 01 - 0f 32 e1 77 70 fd 70 01 ....$.p..2.wp.p.
0170fd00 00 00 00 00 25 9b e1 77 - 70 fd 70 01 5f 32 e1 77 ....%..wp.p._2.w

State Dump for Thread Id 0x4b8

eax=77562bda ebx=00000002 ecx=00000000 edx=00000000 esi=77f8281e edi=00000002
eip=77f82829 esp=01e6ff24 ebp=01e6ff70 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000246


function: NtWaitForMultipleObjects
77f8281e b8e9000000 mov eax,0xe9
77f82823 8d542404 lea edx,[esp+0x4] ss:02a2d4f7=????????
77f82827 cd2e int 2e
77f82829 c21400 ret 0x14

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
01E6FF70 77E86E1A 01E6FF48 00000001 00000000 00000000 ntdll!NtWaitForMultipleObjects
01E6FFB4 77E8758A 00000000 00000000 0170F520 00000000 kernel32!WaitForMultipleObjects
01E6FFEC 00000000 77562BDA 00000000 00000000 00000008 kernel32!SetFilePointer

*----> Raw Stack Dump <----*
01e6ff24 da 6d e8 77 02 00 00 00 - 48 ff e6 01 01 00 00 00 .m.w....H.......
01e6ff34 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
01e6ff44 00 00 00 00 90 03 00 00 - 64 03 00 00 a0 fd 0a 81 ........d.......
01e6ff54 70 3c 75 ef 01 10 f4 77 - 00 20 50 c0 79 00 00 00 p<u....w. P.y...
01e6ff64 00 00 00 00 ac 3c 75 ef - 00 00 00 00 b4 ff e6 01 .....<u.........
01e6ff74 1a 6e e8 77 48 ff e6 01 - 01 00 00 00 00 00 00 00 .n.wH...........
01e6ff84 00 00 00 00 00 00 00 00 - 1a 2c 56 77 02 00 00 00 .........,Vw....
01e6ff94 a4 ff e6 01 00 00 00 00 - ff ff ff ff 20 f5 70 01 ............ .p.
01e6ffa4 90 03 00 00 64 03 00 00 - 00 00 00 00 7b 10 43 80 ....d.......{.C.
01e6ffb4 ec ff e6 01 8a 75 e8 77 - 00 00 00 00 00 00 00 00 .....u.w........
01e6ffc4 20 f5 70 01 00 00 00 00 - 00 f0 fa 7f 00 00 00 00 .p.............
01e6ffd4 c0 ff e6 01 00 00 00 00 - ff ff ff ff 5b 61 e8 77 ............[a.w
01e6ffe4 80 b5 e8 77 00 00 00 00 - 00 00 00 00 00 00 00 00 ...w............
01e6fff4 da 2b 56 77 00 00 00 00 - 00 00 00 00 08 00 00 00 .+Vw............
01e70004 01 01 00 00 ee ff ee ff - 00 00 00 00 00 00 53 01 ..............S.
01e70014 00 00 00 00 00 00 e7 01 - 00 01 00 00 40 00 e7 01 ............@...
01e70024 00 00 f7 01 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
01e70034 00 00 00 00 e0 fc f6 01 - 00 00 00 00 db 1f 08 00 ................
01e70044 01 01 08 00 81 07 07 02 - 00 00 00 00 00 83 02 1b ................
01e70054 00 a1 05 1b 1b a2 14 a1 - 05 d2 11 00 ca 5d a8 00 .............]..

State Dump for Thread Id 0x48c

eax=77d4f05a ebx=000493e0 ecx=77f89656 edx=00000000 esi=00084bb0 edi=000493e0
eip=77f82837 esp=022dfebc ebp=022dfee4 iopl=0 nv up ei ng nz ac po cy
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000297


function: NtRemoveIoCompletion
77f8282c b8a8000000 mov eax,0xa8
77f82831 8d542404 lea edx,[esp+0x4] ss:02e9d48f=????????
77f82835 cd2e int 2e
77f82837 c21400 ret 0x14

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
022DFEE4 77D8F6D6 00000124 022DFF1C 022DFF0C 022DFF14 ntdll!NtRemoveIoCompletion
022DFF20 77D604A0 000493E0 022DFF60 022DFF5C 022DFF70 rpcrt4!I_RpcTransGetAddressList
022DFF74 77D602D9 77D521F0 00084BB0 00000008 0170F62C rpcrt4!TowerConstruct
022DFFA8 77D4F072 000B7C50 022DFFEC 77E8758A 000B5AA8 rpcrt4!TowerConstruct
022DFFB4 77E8758A 000B5AA8 00000008 0170F62C 000B5AA8 rpcrt4!I_RpcServerInqTransportType
022DFFEC 00000000 77D4F05A 000B5AA8 00000000 0000C249 kernel32!SetFilePointer

*----> Raw Stack Dump <----*
022dfebc 69 6b e8 77 24 01 00 00 - 0c ff 2d 02 fc fe 2d 02 ik.w$.....-...-.
022dfecc dc fe 2d 02 d4 fe 2d 02 - 00 a2 2f 4d ff ff ff ff ..-...-.../M....
022dfedc 00 00 00 00 00 00 00 00 - 20 ff 2d 02 d6 f6 d8 77 ........ .-....w
022dfeec 24 01 00 00 1c ff 2d 02 - 0c ff 2d 02 14 ff 2d 02 $.....-...-...-.
022dfefc e0 93 04 00 e0 93 04 00 - b0 4b 08 00 6a 66 e8 77 .........K..jf.w
022dff0c 10 00 00 00 24 01 00 00 - 00 00 00 00 64 dc 95 ef ....$.......d...
022dff1c 00 00 00 00 74 ff 2d 02 - a0 04 d6 77 e0 93 04 00 ....t.-....w....
022dff2c 60 ff 2d 02 5c ff 2d 02 - 70 ff 2d 02 58 ff 2d 02 `.-.\.-.p.-.X.-.
022dff3c 64 ff 2d 02 6c ff 2d 02 - c0 8d 07 00 50 7c 0b 00 d.-.l.-.....P|..
022dff4c a8 5a 0b 00 24 01 00 00 - 00 00 00 00 00 00 00 00 .Z..$...........
022dff5c 00 00 00 00 00 00 00 00 - 00 00 00 00 01 00 00 00 ................
022dff6c 00 00 00 00 24 01 00 00 - a8 ff 2d 02 d9 02 d6 77 ....$.....-....w
022dff7c f0 21 d5 77 b0 4b 08 00 - 08 00 00 00 2c f6 70 01 .!.w.K......,.p.
022dff8c a8 5a 0b 00 0b 0c 43 80 - 60 9d 2a 83 c0 8b 70 83 .Z....C.`.*...p.
022dff9c ff ff ff ff 77 0d 43 80 - a8 5a 0b 00 b4 ff 2d 02 ....w.C..Z....-.
022dffac 72 f0 d4 77 50 7c 0b 00 - ec ff 2d 02 8a 75 e8 77 r..wP|....-..u.w
022dffbc a8 5a 0b 00 08 00 00 00 - 2c f6 70 01 a8 5a 0b 00 .Z......,.p..Z..
022dffcc 00 e0 fa 7f 56 96 f8 77 - c0 ff 2d 02 56 96 f8 77 ....V..w..-.V..w
022dffdc ff ff ff ff 5b 61 e8 77 - 80 b5 e8 77 00 00 00 00 ....[a.w...w....
022dffec 00 00 00 00 00 00 00 00 - 5a f0 d4 77 a8 5a 0b 00 ........Z..w.Z..

State Dump for Thread Id 0x4ac

eax=11c02a90 ebx=00000002 ecx=00000000 edx=00000000 esi=77f8281e edi=00000002
eip=77f82829 esp=0233ff20 ebp=0233ff6c iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000246


function: NtWaitForMultipleObjects
77f8281e b8e9000000 mov eax,0xe9
77f82823 8d542404 lea edx,[esp+0x4] ss:02efd4f3=????????
77f82827 cd2e int 2e
77f82829 c21400 ret 0x14

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0233FF6C 77E86E1A 0233FF44 00000001 00000000 00000000 ntdll!NtWaitForMultipleObjects
77E86A2E 74FF0C24 7EE80C24 C2FFFFFF 006A0008 082474FF kernel32!WaitForMultipleObjects
74FF006A 6F6D2053 0D2E6564 00240A0D 00000000 32520000 mswsock!<nosymbols>
4F44206E 00000000 00000000 00000000 00000000 00000000 <nosymbols>

State Dump for Thread Id 0x50c

eax=00000000 ebx=00050002 ecx=00400000 edx=00000000 esi=00085b88 edi=00000100
eip=77f82a84 esp=0237fe28 ebp=0237ff74 iopl=0 nv up ei pl nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000206


function: ZwReplyWaitReceivePortEx
77f82a79 b8ac000000 mov eax,0xac
77f82a7e 8d542404 lea edx,[esp+0x4] ss:02f3d3fb=????????
77f82a82 cd2e int 2e
77f82a84 c21400 ret 0x14

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0237FF74 77D684C2 77D522C0 00085B88 00000000 00000000 ntdll!ZwReplyWaitReceivePortEx
0237FFA8 77D4F072 00078E38 0237FFEC 77E8758A 000B6F28 rpcrt4!TowerConstruct
0237FFB4 77E8758A 000B6F28 00000000 00000000 000B6F28 rpcrt4!I_RpcServerInqTransportType
0237FFEC 00000000 77D4F05A 000B6F28 00000000 00000000 kernel32!SetFilePointer

*----> Raw Stack Dump <----*
0237fe28 c8 8b d6 77 20 01 00 00 - 54 ff 37 02 00 00 00 00 ...w ...T.7.....
0237fe38 d8 8f 0b 00 58 ff 37 02 - c0 8d 07 00 a0 08 0a 00 ....X.7.........
0237fe48 07 22 f8 77 90 a9 49 81 - b4 8b 55 ef d0 0c 45 80 .".w..I...U...E.
0237fe58 34 00 00 c0 a0 71 49 81 - 71 36 4a 80 58 87 00 e1 4....qI.q6J.X...
0237fe68 b0 8c 00 00 58 87 00 e1 - 00 00 00 00 00 00 00 00 ....X...........
0237fe78 02 02 00 00 68 10 45 80 - 01 00 00 00 05 00 00 00 ....h.E.........
0237fe88 00 00 00 00 10 00 f8 00 - 2a 1d 28 81 7c 00 f8 00 ........*.(.|...
0237fe98 3a 1d 28 81 28 a9 49 81 - 58 87 00 e1 00 00 00 00 :.(.(.I.X.......
0237fea8 1f 00 00 00 90 a9 49 81 - 90 a9 49 81 00 00 00 00 ......I...I.....
0237feb8 01 00 00 00 10 8c 55 ef - 00 00 00 00 b8 55 5d e2 ......U......U].
0237fec8 d4 8b 55 ef 00 00 00 00 - 91 4e 41 80 b0 aa 49 81 ..U......NA...I.
0237fed8 a0 71 49 81 c4 8c 55 ef - a8 04 45 80 04 00 00 00 .qI...U...E.....
0237fee8 28 1d 28 81 97 db 49 80 - 80 f3 05 01 00 00 00 00 (.(...I.........
0237fef8 48 f3 05 01 91 23 03 00 - 00 00 00 00 00 00 00 00 H....#..........
0237ff08 01 00 00 00 19 00 02 00 - 7b 00 00 00 7a 00 00 00 ........{...z...
0237ff18 00 00 00 00 00 00 00 00 - 7d 00 00 00 01 00 00 00 ........}.......
0237ff28 00 20 50 c0 60 9d 2a 83 - 20 5b 65 83 00 00 00 00 . P.`.*. [e.....
0237ff38 b0 5c 65 83 60 8c 55 ef - 46 02 00 00 ec d8 42 80 .\e.`.U.F.....B.
0237ff48 10 2f 06 80 80 5c 65 83 - 20 5b 65 83 02 00 05 00 ./...\e. [e.....
0237ff58 00 a2 2f 4d ff ff ff ff - 50 fe 37 02 00 00 02 80 ../M....P.7.....

State Dump for Thread Id 0x2d0

eax=000b7084 ebx=00083f30 ecx=77a5fef8 edx=00000000 esi=00000000 edi=0317fd1c
eip=77f8224d esp=0317faa8 ebp=0317fad0 iopl=0 nv up ei pl nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000206


function: NtRequestWaitReplyPort
77f82242 b8b0000000 mov eax,0xb0
77f82247 8d542404 lea edx,[esp+0x4] ss:03d3d07b=????????
77f8224b cd2e int 2e
77f8224d c20c00 ret 0xc

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0317FAD0 77D47A7F 0317FCD0 0317FEC8 77D7A7A9 0317FCD0 ntdll!NtRequestWaitReplyPort
0317FADC 77D7A7A9 0317FCD0 00084170 0317FF34 77A632D8 rpcrt4!I_RpcSendReceive
0317FEC8 77A7B82B 77A63160 77A63280 0317FEE0 77AAB0DA rpcrt4!NdrSendReceive
0317FF10 77AB7C18 00000000 0317FF34 0317FF34 00000000 ole32!OpenOrCreateStream
0317FF88 77AB7CB1 00000000 77AB3D96 00000000 77A50000 ole32!UpdateDCOMSettings
00007530 00000000 00000000 00000000 00000000 00000000 ole32!UpdateDCOMSettings

*----> Raw Stack Dump <----*
0317faa8 35 e2 d5 77 e8 00 00 00 - 08 41 08 00 08 41 08 00 5..w.....A...A..
0317fab8 1c fd 17 03 d0 fc 17 03 - 34 00 00 00 ed d2 d7 77 ........4......w
0317fac8 00 00 00 00 00 00 00 00 - dc fa 17 03 7f 7a d4 77 .............z.w
0317fad8 d0 fc 17 03 c8 fe 17 03 - a9 a7 d7 77 d0 fc 17 03 ...........w....
0317fae8 70 41 08 00 34 ff 17 03 - d8 32 a6 77 06 0c da 77 pA..4....2.w...w
0317faf8 1c fd 17 03 74 41 08 00 - 00 fb 17 03 00 fb 17 03 ....tA..........
0317fb08 17 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0317fb18 00 00 00 00 01 00 00 00 - 00 00 00 00 02 00 00 00 ................
0317fb28 00 00 fb 76 02 00 00 00 - 03 00 00 00 00 00 00 00 ...v............
0317fb38 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0317fb48 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0317fb58 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0317fb68 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0317fb78 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0317fb88 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0317fb98 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0317fba8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0317fbb8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0317fbc8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0317fbd8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

State Dump for Thread Id 0x52c

eax=766d56d0 ebx=00000000 ecx=77f82600 edx=00000000 esi=77f827dd edi=000003f8
eip=77f827e8 esp=0321ff70 ebp=0321ff94 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000246


function: NtWaitForSingleObject
77f827dd b8ea000000 mov eax,0xea
77f827e2 8d542404 lea edx,[esp+0x4] ss:03ddd543=????????
77f827e6 cd2e int 2e
77f827e8 c20c00 ret 0xc
77f827eb 8b4124 mov eax,[ecx+0x24] ds:78b3fbd2=????????
77f827ee 39420c cmp [edx+0xc],eax ds:00bbd5d2=????????
77f827f1 0f85c9100000 jne NtQueryDefaultLocale+0x115 (77f838c0)
77f827f7 ff4208 inc dword ptr [edx+0x8] ds:00bbd5d2=????????
77f827fa 33c0 xor eax,eax
77f827fc c20400 ret 0x4
77f827ff 90 nop
77f82800 ff4a04 dec dword ptr [edx+0x4] ds:00bbd5d2=????????
77f82803 c20400 ret 0x4

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0321FF94 77E86A3D 000003F8 FFFFFFFF 00000000 766D56FC ntdll!NtWaitForSingleObject
0321FFEC 00000000 766D56D0 0002012E 00000000 00905A4D kernel32!WaitForSingleObject

*----> Raw Stack Dump <----*
0321ff70 15 6a e8 77 f8 03 00 00 - 00 00 00 00 00 00 00 00 .j.w............
0321ff80 e4 f7 70 01 2e 6a e8 77 - 2e 01 02 00 01 01 00 00 ..p..j.w........
0321ff90 01 01 00 00 ec ff 21 03 - 3d 6a e8 77 f8 03 00 00 ......!.=j.w....
0321ffa0 ff ff ff ff 00 00 00 00 - fc 56 6d 76 f8 03 00 00 .........Vmv....
0321ffb0 ff ff ff ff 10 e3 0c 00 - 8a 75 e8 77 2e 01 02 00 .........u.w....
0321ffc0 e4 f7 70 01 10 e3 0c 00 - 2e 01 02 00 00 a0 fa 7f ..p.............
0321ffd0 00 26 f8 77 c0 ff 21 03 - 00 26 f8 77 ff ff ff ff .&.w..!..&.w....
0321ffe0 5b 61 e8 77 80 b5 e8 77 - 00 00 00 00 00 00 00 00 [a.w...w........
0321fff0 00 00 00 00 d0 56 6d 76 - 2e 01 02 00 00 00 00 00 .....Vmv........
03220000 4d 5a 90 00 03 00 00 00 - 04 00 00 00 ff ff 00 00 MZ..............
03220010 b8 00 00 00 00 00 00 00 - 40 00 00 00 00 00 00 00 ........@.......
03220020 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
03220030 00 00 00 00 00 00 00 00 - 00 00 00 00 d0 00 00 00 ................
03220040 0e 1f ba 0e 00 b4 09 cd - 21 b8 01 4c cd 21 54 68 ........!..L.!Th
03220050 69 73 20 70 72 6f 67 72 - 61 6d 20 63 61 6e 6e 6f is program canno
03220060 74 20 62 65 20 72 75 6e - 20 69 6e 20 44 4f 53 20 t be run in DOS
03220070 6d 6f 64 65 2e 0d 0d 0a - 24 00 00 00 00 00 00 00 mode....$.......
03220080 99 1f 82 fd dd 7e ec ae - dd 7e ec ae dd 7e ec ae .....~...~...~..
03220090 dd 7e ec ae d9 7e ec ae - dd 7e ed ae fb 7e ec ae .~...~...~...~..
032200a0 bf 61 ff ae d4 7e ec ae - 82 5c e7 ae dc 7e ec ae .a...~...\...~..

State Dump for Thread Id 0x5a4

eax=77d4f05a ebx=000c9740 ecx=000d15a8 edx=00000000 esi=00085b88 edi=00000100
eip=77f82a84 esp=0326fe28 ebp=0326ff74 iopl=0 nv up ei pl nz na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs=0000 efl=00000206


function: ZwReplyWaitReceivePortEx
77f82a79 b8ac000000 mov eax,0xac
77f82a7e 8d542404 lea edx,[esp+0x4] ss:03e2d3fb=????????
77f82a82 cd2e int 2e
77f82a84 c21400 ret 0x14

*----> Stack Back Trace <----*

FramePtr ReturnAd Param#1 Param#2 Param#3 Param#4 Function Name
0326FF74 77D684C2 77D521F0 00085B88 00000000 0237FA74 ntdll!ZwReplyWaitReceivePortEx
0326FFA8 77D4F072 000BFA68 0326FFEC 77E8758A 000C9740 rpcrt4!TowerConstruct
0326FFB4 77E8758A 000C9740 00000000 0237FA74 000C9740 rpcrt4!I_RpcServerInqTransportType
0326FFEC 00000000 77D4F05A 000C9740 00000000 6E420000 kernel32!SetFilePointer

*----> Raw Stack Dump <----*
0326fe28 c8 8b d6 77 20 01 00 00 - 54 ff 26 03 00 00 00 00 ...w ...T.&.....
0326fe38 78 37 0d 00 58 ff 26 03 - c0 8d 07 00 68 fa 0b 00 x7..X.&.....h...
0326fe48 40 97 0c 00 90 a9 49 81 - b4 db bb ef d0 0c 45 80 @.....I.......E.
0326fe58 34 00 00 c0 a0 71 49 81 - 71 36 4a 80 58 87 00 e1 4....qI.q6J.X...
0326fe68 b0 dc bb ef 58 87 00 e1 - 00 00 00 00 00 00 00 00 ....X...........
0326fe78 06 02 00 00 68 10 45 80 - 01 00 00 00 a0 71 49 81 ....h.E......qI.
0326fe88 00 00 00 00 10 00 f8 00 - ca 88 25 81 7c 00 f8 00 ..........%.|...
0326fe98 da 88 25 81 28 a9 49 81 - 58 87 00 e1 00 00 00 00 ..%.(.I.X.......
0326fea8 1f 00 00 00 90 a9 49 81 - 90 a9 49 81 00 00 00 00 ......I...I.....
0326feb8 01 00 00 00 10 dc bb ef - 00 00 00 00 38 a7 80 e2 ............8...
0326fec8 d4 db bb ef 00 00 00 00 - 91 4e 41 80 b0 aa 49 81 .........NA...I.
0326fed8 a0 71 49 81 c4 dc bb ef - a8 04 45 80 04 00 00 00 .qI.......E.....
0326fee8 c8 88 25 81 97 db 49 80 - 80 f3 12 00 00 00 00 00 ..%...I.........
0326fef8 48 f3 12 00 8a 7c 03 00 - 00 00 00 00 00 00 00 00 H....|..........
0326ff08 01 00 00 00 19 00 02 00 - e0 29 50 c0 7a 00 00 00 .........)P.z...
0326ff18 00 00 00 00 00 00 00 00 - ce 00 00 00 01 00 00 00 ................
0326ff28 00 20 50 c0 60 9d 2a 83 - 80 ba 28 81 00 00 00 00 . P.`.*...(.....
0326ff38 10 bc 28 81 60 dc bb ef - 46 02 00 00 ec d8 42 80 ..(.`...F.....B.
0326ff48 10 2f 06 80 e0 bb 28 81 - 80 ba 28 81 70 dc bb ef ./....(...(.p...
0326ff58 00 a2 2f 4d ff ff ff ff - 50 fe 26 03 ff ff ff ff ../M....P.&.....