
Microsoft (R) DrWtsn32
Copyright (C) 1985-2001 Microsoft Corp. All rights reserved.



Application exception occurred:
        App: C:\Program Files\USB PC Camera\VideoCap.exe (pid=1400)
        When: 11/25/2011 @ 11:59:49.500
        Exception number: c0000005 (access violation)

*----> System Information <----*
        Computer Name: THAILA
        User Name: Thaila Riden
        Terminal Session Id: 0
        Number of Processors: 2
        Processor Type: x86 Family 15 Model 4 Stepping 7
        Windows Version: 5.1
        Current Build: 2600
        Service Pack: 3
        Current Type: Multiprocessor Free
        Registered Organization: TGB
        Registered Owner: Thaila Riden

*----> Task List <----*
   0 System Process
   4 System
 592 smss.exe
 644 csrss.exe
 668 winlogon.exe
 712 services.exe
 724 lsass.exe
 876 nvsvc32.exe
 948 svchost.exe
1016 svchost.exe
1056 svchost.exe
1160 svchost.exe
1216 svchost.exe
1384 AvastSvc.exe
1464 Explorer.EXE
1528 avastUI.exe
1548 M-AudioTaskBarIcon.exe
1564 CTHELPER.EXE
1592 RUNDLL32.EXE
1648 DTLite.exe
 312 firefox.exe
1456 spoolsv.exe
2976 svchost.exe
3012 MMERefresh.exe
3068 svchost.exe
1584 alg.exe
2392 plugin-container.exe
 264 plugin-container.exe
2448 googletalkplugin.exe
2560 wscntfy.exe
1400 VideoCap.exe
3156 drwtsn32.exe

*----> Module List <----*
(0000000000400000 - 0000000000430000: C:\Program Files\USB PC Camera\VideoCap.exe
(0000000000e40000 - 0000000000e49000: C:\WINDOWS\system32\cam1690.ax
(0000000001ce0000 - 0000000001fa5000: C:\WINDOWS\system32\xpsp2res.dll
(0000000010000000 - 0000000010011000: C:\WINDOWS\system32\ctagent.dll
(000000004ec50000 - 000000004edfb000: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.22509_x-ww_c7dad023\gdiplus.dll
(0000000058010000 - 0000000058029000: C:\WINDOWS\system32\kswdmcap.ax
(000000005d090000 - 000000005d12a000: C:\WINDOWS\system32\COMCTL32.dll
(000000005e030000 - 000000005e053000: C:\WINDOWS\system32\ksproxy.ax
(000000005edd0000 - 000000005ede7000: C:\WINDOWS\system32\OLEPRO32.DLL
(0000000060ca0000 - 0000000060d2c000: C:\WINDOWS\system32\qedit.dll
(0000000064d00000 - 0000000064d34000: C:\Program Files\Alwil Software\Avast5\snxhk.dll
(0000000072d10000 - 0000000072d18000: C:\WINDOWS\system32\msacm32.drv
(0000000072d20000 - 0000000072d29000: C:\WINDOWS\system32\wdmaud.drv
(00000000736b0000 - 00000000736b7000: C:\WINDOWS\system32\msdmo.dll
(0000000073760000 - 00000000737ab000: C:\WINDOWS\system32\DDRAW.dll
(0000000073940000 - 0000000073a10000: C:\WINDOWS\system32\D3DIM700.DLL
(0000000073bc0000 - 0000000073bc6000: C:\WINDOWS\system32\DCIMAN32.dll
(0000000073dd0000 - 0000000073ec2000: C:\WINDOWS\system32\MFC42.DLL
(0000000073ee0000 - 0000000073ee4000: C:\WINDOWS\system32\ksuser.dll
(0000000073f10000 - 0000000073f6c000: C:\WINDOWS\system32\DSOUND.dll
(0000000074810000 - 000000007497e000: C:\WINDOWS\system32\quartz.dll
(00000000757f0000 - 0000000075822000: C:\WINDOWS\system32\qcap.dll
(0000000075a70000 - 0000000075a91000: C:\WINDOWS\system32\MSVFW32.dll
(0000000075f40000 - 0000000075f51000: C:\WINDOWS\system32\devenum.dll
(00000000763b0000 - 00000000763f9000: C:\WINDOWS\system32\comdlg32.dll
(0000000076b40000 - 0000000076b6d000: C:\WINDOWS\system32\WINMM.dll
(0000000076c30000 - 0000000076c5e000: C:\WINDOWS\system32\WINTRUST.dll
(0000000076c90000 - 0000000076cb8000: C:\WINDOWS\system32\IMAGEHLP.dll
(0000000076fd0000 - 000000007704f000: C:\WINDOWS\system32\CLBCATQ.DLL
(0000000077050000 - 0000000077115000: C:\WINDOWS\system32\COMRes.dll
(0000000077120000 - 00000000771ab000: C:\WINDOWS\system32\OLEAUT32.dll
(00000000773d0000 - 00000000774d3000: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
(00000000774e0000 - 000000007761e000: C:\WINDOWS\system32\ole32.dll
(0000000077920000 - 0000000077a13000: C:\WINDOWS\system32\setupapi.dll
(0000000077a80000 - 0000000077b15000: C:\WINDOWS\system32\CRYPT32.dll
(0000000077b20000 - 0000000077b32000: C:\WINDOWS\system32\MSASN1.dll
(0000000077b40000 - 0000000077b62000: C:\WINDOWS\system32\Apphelp.dll
(0000000077bd0000 - 0000000077bd7000: C:\WINDOWS\system32\midimap.dll
(0000000077be0000 - 0000000077bf5000: C:\WINDOWS\system32\MSACM32.dll
(0000000077c00000 - 0000000077c08000: C:\WINDOWS\system32\VERSION.dll
(0000000077c10000 - 0000000077c68000: C:\WINDOWS\system32\msvcrt.dll
(0000000077dd0000 - 0000000077e6b000: C:\WINDOWS\system32\ADVAPI32.dll
(0000000077e70000 - 0000000077f03000: C:\WINDOWS\system32\RPCRT4.dll
(0000000077f10000 - 0000000077f59000: C:\WINDOWS\system32\GDI32.dll
(0000000077f60000 - 0000000077fd6000: C:\WINDOWS\system32\SHLWAPI.dll
(0000000077fe0000 - 0000000077ff1000: C:\WINDOWS\system32\Secur32.dll
(000000007c800000 - 000000007c8f6000: C:\WINDOWS\system32\kernel32.dll
(000000007c900000 - 000000007c9b2000: C:\WINDOWS\system32\ntdll.dll
(000000007c9c0000 - 000000007d1d7000: C:\WINDOWS\system32\SHELL32.dll
(000000007e410000 - 000000007e4a1000: C:\WINDOWS\system32\USER32.dll

*----> State Dump for Thread Id 0x5cc <----*

eax=00000000 ebx=00a57bf0 ecx=00a59e64 edx=00a59e64 esi=00000000 edi=00000000
eip=00402fe8 esp=0022fb00 ebp=0022fc8c iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246

*** WARNING: Unable to verify checksum for C:\Program Files\USB PC Camera\VideoCap.exe
*** ERROR: Module load completed but symbols could not be loaded for C:\Program Files\USB PC Camera\VideoCap.exe
function: VideoCap
        00402fcf d7               xlat
        00402fd0 41               inc     ecx
        00402fd1 00e8             add     al,ch
        00402fd3 19f8             sbb     eax,edi
        00402fd5 ffff             ???
        00402fd7 83c404           add     esp,0x4
        00402fda 33c0             xor     eax,eax
        00402fdc c3               ret
        00402fdd 8b15fc354200     mov     edx,[VideoCap+0x235fc (004235fc)]
        00402fe3 a1f4324200       mov     eax,[VideoCap+0x232f4 (004232f4)]
FAULT ->00402fe8 8b08             mov     ecx,[eax]         ds:0023:00000000=????????
        00402fea 68dcd74100       push    0x41d7dc
        00402fef 52               push    edx
        00402ff0 50               push    eax
        00402ff1 ff510c           call    dword ptr [ecx+0xc]
        00402ff4 a1fc354200       mov     eax,[VideoCap+0x235fc (004235fc)]
        00402ff9 8b08             mov     ecx,[eax]
        00402ffb 68f0344200       push    0x4234f0
        00403000 68ace44100       push    0x41e4ac
        00403005 50               push    eax
        00403006 ff11             call    dword ptr [ecx]

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr  Args to Child              
0022fc8c 00409d3a 00a57bf0 00000000 0022fdc8 VideoCap+0x2fe8
00000011 00000000 00000000 00000000 00000000 VideoCap+0x9d3a

*----> Raw Stack Dump <----*
000000000022fb00  9a 51 40 00 11 00 00 00 - b0 a6 40 00 00 00 00 00  .Q@.......@.....
000000000022fb10  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000022fb20  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000022fb30  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000022fb40  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000022fb50  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000022fb60  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000022fb70  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000022fb80  00 00 00 00 00 00 00 00 - 00 00 00 00 00 a6 40 00  ..............@.
000000000022fb90  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000022fba0  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000022fbb0  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000022fbc0  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000022fbd0  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000022fbe0  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000022fbf0  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000022fc00  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000022fc10  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000022fc20  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000022fc30  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................

*----> State Dump for Thread Id 0xb78 <----*

eax=72d230e8 ebx=00e2fef8 ecx=0000005a edx=00000141 esi=00000000 edi=7ffdb000
eip=7c90e514 esp=00e2fed0 ebp=00e2ff6c iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246

*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\ntdll.dll - 
function: ntdll!KiFastSystemCallRet
        7c90e4fa e829000000       call    ntdll!RtlRaiseException (7c90e528)
        7c90e4ff 8b0424           mov     eax,[esp]
        7c90e502 8be5             mov     esp,ebp
        7c90e504 5d               pop     ebp
        7c90e505 c3               ret
        7c90e506 8da42400000000   lea     esp,[esp]
        7c90e50d 8d4900           lea     ecx,[ecx]
        ntdll!KiFastSystemCall:
        7c90e510 8bd4             mov     edx,esp
        7c90e512 0f34             sysenter
        ntdll!KiFastSystemCallRet:
        7c90e514 c3               ret
        7c90e515 8da42400000000   lea     esp,[esp]
        7c90e51c 8d642400         lea     esp,[esp]
        ntdll!KiIntSystemCall:
        7c90e520 8d542408         lea     edx,[esp+0x8]
        7c90e524 cd2e             int     2e
        7c90e526 c3               ret
        7c90e527 90               nop
        ntdll!RtlRaiseException:
        7c90e528 55               push    ebp
        7c90e529 8bec             mov     ebp,esp

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\kernel32.dll - 
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\wdmaud.drv - 
ChildEBP RetAddr  Args to Child              
00e2ff6c 7c80a115 00000002 00e2ffa4 00000000 ntdll!KiFastSystemCallRet
00e2ff88 72d2312a 00000002 00e2ffa4 00000000 kernel32!WaitForMultipleObjects+0x18
00e2ffb4 7c80b729 00000000 00000000 00250000 wdmaud!midMessage+0x348
00e2ffec 00000000 72d230e8 00000000 00000000 kernel32!GetModuleFileNameA+0x1ba

*----> Raw Stack Dump <----*
0000000000e2fed0  4a df 90 7c 90 95 80 7c - 02 00 00 00 f8 fe e2 00  J..|...|........
0000000000e2fee0  01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000000e2fef0  00 00 00 00 00 00 00 00 - 74 01 00 00 5c 01 00 00  ........t...\...
0000000000e2ff00  5c cd 0a 83 28 3c 56 b8 - 00 00 00 00 27 74 6e 80  \...(<V.....'tn.
0000000000e2ff10  08 00 00 00 46 02 00 00 - 14 00 00 00 01 00 00 00  ....F...........
0000000000e2ff20  00 00 00 00 00 00 00 00 - 10 00 00 00 c0 cb 0a 83  ................
0000000000e2ff30  f4 cb 0a 83 01 00 00 00 - 00 b0 fd 7f 00 e0 fd 7f  ................
0000000000e2ff40  c0 cb 0a 83 00 00 00 00 - f8 fe e2 00 8c 2f 50 80  ............./P.
0000000000e2ff50  02 00 00 00 ec fe e2 00 - 00 00 00 00 dc ff e2 00  ................
0000000000e2ff60  d8 9a 83 7c 80 96 80 7c - 00 00 00 00 88 ff e2 00  ...|...|........
0000000000e2ff70  15 a1 80 7c 02 00 00 00 - a4 ff e2 00 00 00 00 00  ...|............
0000000000e2ff80  ff ff ff ff 00 00 00 00 - b4 ff e2 00 2a 31 d2 72  ............*1.r
0000000000e2ff90  02 00 00 00 a4 ff e2 00 - 00 00 00 00 ff ff ff ff  ................
0000000000e2ffa0  00 00 25 00 74 01 00 00 - 5c 01 00 00 f2 7e 6e 80  ..%.t...\....~n.
0000000000e2ffb0  1a da 90 7c ec ff e2 00 - 29 b7 80 7c 00 00 00 00  ...|....)..|....
0000000000e2ffc0  00 00 00 00 00 00 25 00 - 00 00 00 00 00 e0 fd 7f  ......%.........
0000000000e2ffd0  00 c6 9a 84 c0 ff e2 00 - 50 44 9f fe ff ff ff ff  ........PD......
0000000000e2ffe0  d8 9a 83 7c 30 b7 80 7c - 00 00 00 00 00 00 00 00  ...|0..|........
0000000000e2fff0  00 00 00 00 e8 30 d2 72 - 00 00 00 00 00 00 00 00  .....0.r........
0000000000e30000  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................

*----> State Dump for Thread Id 0x500 <----*

eax=00000000 ebx=00000000 ecx=0028f338 edx=ffffffff esi=00252ff8 edi=0025309c
eip=7c90e514 esp=021afe18 ebp=021aff80 iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246

function: ntdll!KiFastSystemCallRet
        7c90e4fa e829000000       call    ntdll!RtlRaiseException (7c90e528)
        7c90e4ff 8b0424           mov     eax,[esp]
        7c90e502 8be5             mov     esp,ebp
        7c90e504 5d               pop     ebp
        7c90e505 c3               ret
        7c90e506 8da42400000000   lea     esp,[esp]
        7c90e50d 8d4900           lea     ecx,[ecx]
        ntdll!KiFastSystemCall:
        7c90e510 8bd4             mov     edx,esp
        7c90e512 0f34             sysenter
        ntdll!KiFastSystemCallRet:
        7c90e514 c3               ret
        7c90e515 8da42400000000   lea     esp,[esp]
        7c90e51c 8d642400         lea     esp,[esp]
        ntdll!KiIntSystemCall:
        7c90e520 8d542408         lea     edx,[esp+0x8]
        7c90e524 cd2e             int     2e
        7c90e526 c3               ret
        7c90e527 90               nop
        ntdll!RtlRaiseException:
        7c90e528 55               push    ebp
        7c90e529 8bec             mov     ebp,esp

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\RPCRT4.dll - 
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr  Args to Child              
021aff80 77e76caf 021affa8 77e76ad1 00252ff8 ntdll!KiFastSystemCallRet
021aff88 77e76ad1 00252ff8 00272278 0022ea58 RPCRT4!I_RpcBCacheFree+0x61c
021affa8 77e76c97 00264820 021affec 7c80b729 RPCRT4!I_RpcBCacheFree+0x43e
021affb4 7c80b729 0028f338 00272278 0022ea58 RPCRT4!I_RpcBCacheFree+0x604
021affec 00000000 77e76c7d 0028f338 00000000 kernel32!GetModuleFileNameA+0x1ba

*----> Raw Stack Dump <----*
00000000021afe18  aa da 90 7c e3 65 e7 77 - 18 03 00 00 74 ff 1a 02  ...|.e.w....t...
00000000021afe28  00 00 00 00 f8 1b 29 00 - 48 ff 1a 02 ff ff ff 03  ......).H.......
00000000021afe38  ff ff ff 03 ac be 93 82 - 00 00 00 00 fc 3c 88 c0  .............<..
00000000021afe48  88 07 63 83 40 f5 df ff - 00 00 00 00 72 b5 4f 80  ..c.@.......r.O.
00000000021afe58  94 1b 4c a9 70 fd 3f c0 - 00 d0 fa 7f 00 00 00 00  ..L.p.?.........
00000000021afe68  68 fd 3f 02 70 1b 4c a9 - cb 38 52 80 00 d0 fa 7f  h.?.p.L..8R.....
00000000021afe78  01 00 00 00 00 00 00 00 - 68 fd 3f c0 00 00 00 00  ........h.?.....
00000000021afe88  00 00 00 00 f8 1f 60 c0 - 30 1c 4c a9 2a 40 52 80  ......`.0.L.*@R.
00000000021afe98  94 1b 4c a9 00 00 00 00 - 43 7d 6e 80 28 1c 4c a9  ..L.....C}n.(.L.
00000000021afea8  27 74 6e 80 00 0d db ba - 00 00 00 00 20 d0 bd fe  'tn......... ...
00000000021afeb8  88 1c 4c a9 00 00 00 00 - 08 d1 bd fe 01 88 9a 84  ..L.............
00000000021afec8  a0 1c 4c a9 68 5a cb f7 - 02 02 00 00 3a 5c 54 80  ..L.hZ......:\T.
00000000021afed8  d7 5a 54 80 e0 1b 4c a9 - 00 00 00 00 00 00 00 00  .ZT...L.........
00000000021afee8  00 00 00 00 1f 00 00 00 - ff ff ff ff 40 f5 df ff  ............@...
00000000021afef8  00 00 00 00 10 74 6e 80 - bc d1 bd fe 28 1c 4c a9  .....tn.....(.L.
00000000021aff08  00 00 00 00 27 74 6e 80 - 08 00 00 00 46 02 00 00  ....'tn.....F...
00000000021aff18  72 38 50 80 90 d0 bd fe - 20 d0 bd fe 78 b0 4f 80  r8P..... ...x.O.
00000000021aff28  8c d1 bd fe 80 ff 1a 02 - 85 d1 e7 77 48 ff 1a 02  ...........wH...
00000000021aff38  95 d1 e7 77 e0 10 90 7c - e8 eb 28 00 38 f3 28 00  ...w...|..(.8.(.
00000000021aff48  00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff  ../M.....]......

*----> State Dump for Thread Id 0xa78 <----*

eax=774fe4df ebx=00007530 ecx=7c9100b8 edx=00000000 esi=00000000 edi=023aff50
eip=7c90e514 esp=023aff20 ebp=023aff78 iopl=0         nv up ei pl nz na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000206

function: ntdll!KiFastSystemCallRet
        7c90e4fa e829000000       call    ntdll!RtlRaiseException (7c90e528)
        7c90e4ff 8b0424           mov     eax,[esp]
        7c90e502 8be5             mov     esp,ebp
        7c90e504 5d               pop     ebp
        7c90e505 c3               ret
        7c90e506 8da42400000000   lea     esp,[esp]
        7c90e50d 8d4900           lea     ecx,[ecx]
        ntdll!KiFastSystemCall:
        7c90e510 8bd4             mov     edx,esp
        7c90e512 0f34             sysenter
        ntdll!KiFastSystemCallRet:
        7c90e514 c3               ret
        7c90e515 8da42400000000   lea     esp,[esp]
        7c90e51c 8d642400         lea     esp,[esp]
        ntdll!KiIntSystemCall:
        7c90e520 8d542408         lea     edx,[esp+0x8]
        7c90e524 cd2e             int     2e
        7c90e526 c3               ret
        7c90e527 90               nop
        ntdll!RtlRaiseException:
        7c90e528 55               push    ebp
        7c90e529 8bec             mov     ebp,esp

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\ole32.dll - 
ChildEBP RetAddr  Args to Child              
023aff78 7c802455 0000ea60 00000000 023affb4 ntdll!KiFastSystemCallRet
023aff88 774fe3d3 0000ea60 0028ee98 774fe492 kernel32!Sleep+0xf
023affb4 7c80b729 0028ee98 00000000 7c91043e ole32!StringFromGUID2+0x51d
023affec 00000000 774fe4df 0028ee98 00000000 kernel32!GetModuleFileNameA+0x1ba

*----> Raw Stack Dump <----*
00000000023aff20  1a d2 90 7c f1 23 80 7c - 00 00 00 00 50 ff 3a 02  ...|.#.|....P.:.
00000000023aff30  50 25 80 7c f8 7d 60 77 - 30 75 00 00 14 00 00 00  P%.|.}`w0u......
00000000023aff40  01 00 00 00 00 00 00 00 - 00 00 00 00 10 00 00 00  ................
00000000023aff50  00 ba 3c dc ff ff ff ff - 10 d1 4e 77 50 ff 3a 02  ..<.......NwP.:.
00000000023aff60  30 ff 3a 02 10 39 25 00 - dc ff 3a 02 d8 9a 83 7c  0.:..9%...:....|
00000000023aff70  60 24 80 7c 00 00 00 00 - 88 ff 3a 02 55 24 80 7c  `$.|......:.U$.|
00000000023aff80  60 ea 00 00 00 00 00 00 - b4 ff 3a 02 d3 e3 4f 77  `.........:...Ow
00000000023aff90  60 ea 00 00 98 ee 28 00 - 92 e4 4f 77 00 00 00 00  `.....(...Ow....
00000000023affa0  00 00 00 00 98 ee 28 00 - 00 00 4e 77 fa e4 4f 77  ......(...Nw..Ow
00000000023affb0  3e 04 91 7c ec ff 3a 02 - 29 b7 80 7c 98 ee 28 00  >..|..:.)..|..(.
00000000023affc0  00 00 00 00 3e 04 91 7c - 98 ee 28 00 00 50 fd 7f  ....>..|..(..P..
00000000023affd0  00 c6 9a 84 c0 ff 3a 02 - 68 65 68 fe ff ff ff ff  ......:.heh.....
00000000023affe0  d8 9a 83 7c 30 b7 80 7c - 00 00 00 00 00 00 00 00  ...|0..|........
00000000023afff0  00 00 00 00 df e4 4f 77 - 98 ee 28 00 00 00 00 00  ......Ow..(.....
00000000023b0000  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
00000000023b0010  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
00000000023b0020  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
00000000023b0030  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
00000000023b0040  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
00000000023b0050  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................

*----> State Dump for Thread Id 0xaa0 <----*

eax=77e76c7d ebx=00000000 ecx=00000000 edx=00000000 esi=00252ff8 edi=00000000
eip=7c90e514 esp=025afe18 ebp=025aff80 iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246

function: ntdll!KiFastSystemCallRet
        7c90e4fa e829000000       call    ntdll!RtlRaiseException (7c90e528)
        7c90e4ff 8b0424           mov     eax,[esp]
        7c90e502 8be5             mov     esp,ebp
        7c90e504 5d               pop     ebp
        7c90e505 c3               ret
        7c90e506 8da42400000000   lea     esp,[esp]
        7c90e50d 8d4900           lea     ecx,[ecx]
        ntdll!KiFastSystemCall:
        7c90e510 8bd4             mov     edx,esp
        7c90e512 0f34             sysenter
        ntdll!KiFastSystemCallRet:
        7c90e514 c3               ret
        7c90e515 8da42400000000   lea     esp,[esp]
        7c90e51c 8d642400         lea     esp,[esp]
        ntdll!KiIntSystemCall:
        7c90e520 8d542408         lea     edx,[esp+0x8]
        7c90e524 cd2e             int     2e
        7c90e526 c3               ret
        7c90e527 90               nop
        ntdll!RtlRaiseException:
        7c90e528 55               push    ebp
        7c90e529 8bec             mov     ebp,esp

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr  Args to Child              
025aff80 77e76caf 025affa8 77e76ad1 00252ff8 ntdll!KiFastSystemCallRet
025aff88 77e76ad1 00252ff8 00000000 00000000 RPCRT4!I_RpcBCacheFree+0x61c
025affa8 77e76c97 00264820 025affec 7c80b729 RPCRT4!I_RpcBCacheFree+0x43e
025affb4 7c80b729 00292d60 00000000 00000000 RPCRT4!I_RpcBCacheFree+0x604
025affec 00000000 77e76c7d 00292d60 00000000 kernel32!GetModuleFileNameA+0x1ba

*----> Raw Stack Dump <----*
00000000025afe18  aa da 90 7c e3 65 e7 77 - 18 03 00 00 74 ff 5a 02  ...|.e.w....t.Z.
00000000025afe28  00 00 00 00 70 22 29 00 - 50 ff 5a 02 ff ff ff 03  ....p").P.Z.....
00000000025afe38  ff ff ff 03 c0 4e c8 82 - 00 00 00 00 fc 3c 88 c0  .....N.......<..
00000000025afe48  88 47 50 83 40 85 33 b8 - 00 00 00 00 72 b5 4f 80  .GP.@.3.....r.O.
00000000025afe58  94 9b 4c aa c8 fe 3f c0 - 00 80 fd 7f 00 00 00 00  ..L...?.........
00000000025afe68  c0 fe 3f 02 70 9b 4c aa - cb 38 52 80 00 80 fd 7f  ..?.p.L..8R.....
00000000025afe78  01 00 00 00 00 00 00 00 - c0 fe 3f c0 00 00 00 00  ..........?.....
00000000025afe88  00 00 00 00 f8 1f 60 c0 - 30 9c 4c aa 2a 40 52 80  ......`.0.L.*@R.
00000000025afe98  94 9b 4c aa 00 00 00 00 - 43 7d 6e 80 28 9c 4c aa  ..L.....C}n.(.L.
00000000025afea8  27 74 6e 80 00 0d db ba - 00 00 00 00 00 00 00 00  'tn.............
00000000025afeb8  c0 fe 3f c0 e0 32 12 ab - 00 2a 00 00 fe ff ff ff  ..?..2...*......
00000000025afec8  00 3c 11 ab c6 3e 11 ab - d4 9b 4c aa f8 9b 4c aa  .<...>....L...L.
00000000025afed8  80 9c 4c aa 3c 3e 11 ab - 00 00 00 00 00 00 00 00  ..L.<>..........
00000000025afee8  00 00 00 00 1f 00 00 00 - ff ff ff ff 40 f5 df ff  ............@...
00000000025afef8  00 00 00 00 10 74 6e 80 - dc 9e 1b f9 28 9c 4c aa  .....tn.....(.L.
00000000025aff08  00 00 00 00 27 74 6e 80 - 08 00 00 00 46 02 00 00  ....'tn.....F...
00000000025aff18  72 38 50 80 b0 9d 1b f9 - 40 9d 1b f9 78 b0 4f 80  r8P.....@...x.O.
00000000025aff28  ac 9e 1b f9 80 ff 5a 02 - 85 d1 e7 77 48 ff 5a 02  ......Z....wH.Z.
00000000025aff38  95 d1 e7 77 e0 10 90 7c - 08 1f 29 00 60 2d 29 00  ...w...|..).`-).
00000000025aff48  00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff  ../M.....]......

