| 1 |
|
|---|
| 2 | Microsoft (R) DrWtsn32
|
|---|
| 3 | Copyright (C) 1985-2001 Microsoft Corp. Tous droits réservés.
|
|---|
| 4 |
|
|---|
| 5 |
|
|---|
| 6 |
|
|---|
| 7 | Une exception d'application s'est produite :
|
|---|
| 8 | App : C:\Program Files\Oracle\VirtualBox\VirtualBox.exe (pid=3932)
|
|---|
| 9 | Lorsque : 16/01/2013 @ 13:55:32.642
|
|---|
| 10 | Numéro d'exception : c0000005 (violation d'accès)
|
|---|
| 11 |
|
|---|
| 12 | *----> Informations système <----*
|
|---|
| 13 | Nom ordinateur : C59S001642
|
|---|
| 14 | Nom utilisateur : c59ehur
|
|---|
| 15 | ID de la session Terminal : 0
|
|---|
| 16 | Nombre de processeurs : 2
|
|---|
| 17 | Type de processeur : x86 Family 6 Model 23 Stepping 10
|
|---|
| 18 | Version de Windows : 5.1
|
|---|
| 19 | Numéro actuel : 2600
|
|---|
| 20 | Service Pack : 3
|
|---|
| 21 | Type actuel : Multiprocessor Free
|
|---|
| 22 | Organisation enregistrée : MSA
|
|---|
| 23 | Propriétaire enregistré : MSA
|
|---|
| 24 |
|
|---|
| 25 | *----> Liste des tâches <----*
|
|---|
| 26 | 0 System Process
|
|---|
| 27 | 4 System
|
|---|
| 28 | 628 smss.exe
|
|---|
| 29 | 1064 csrss.exe
|
|---|
| 30 | 1088 winlogon.exe
|
|---|
| 31 | 1132 services.exe
|
|---|
| 32 | 1144 lsass.exe
|
|---|
| 33 | 1332 svchost.exe
|
|---|
| 34 | 1408 svchost.exe
|
|---|
| 35 | 236 svchost.exe
|
|---|
| 36 | 484 svchost.exe
|
|---|
| 37 | 780 svchost.exe
|
|---|
| 38 | 884 spoolsv.exe
|
|---|
| 39 | 1008 svchost.exe
|
|---|
| 40 | 1872 svchost.exe
|
|---|
| 41 | 1900 fsgk32st.exe
|
|---|
| 42 | 1920 FSMA32.EXE
|
|---|
| 43 | 1936 FSGK32.EXE
|
|---|
| 44 | 508 HumDisplayServer.exe
|
|---|
| 45 | 656 jqs.exe
|
|---|
| 46 | 312 FSHDLL32.EXE
|
|---|
| 47 | 760 mdm.exe
|
|---|
| 48 | 1208 snmp.exe
|
|---|
| 49 | 1592 ssonsvr.exe
|
|---|
| 50 | 1672 FNRB32.EXE
|
|---|
| 51 | 1772 fssm32.exe
|
|---|
| 52 | 2284 fsorsp.exe
|
|---|
| 53 | 2300 FIH32.EXE
|
|---|
| 54 | 3040 wmiapsrv.exe
|
|---|
| 55 | 3416 rbmonitor.exe
|
|---|
| 56 | 3792 Explorer.EXE
|
|---|
| 57 | 2224 alg.exe
|
|---|
| 58 | 3248 igfxtray.exe
|
|---|
| 59 | 1596 igfxsrvc.exe
|
|---|
| 60 | 612 hkcmd.exe
|
|---|
| 61 | 1532 igfxpers.exe
|
|---|
| 62 | 1852 RTHDCPL.EXE
|
|---|
| 63 | 2240 FSM32.EXE
|
|---|
| 64 | 2708 jusched.exe
|
|---|
| 65 | 1732 ctfmon.exe
|
|---|
| 66 | 1708 Free Ride Games.exe
|
|---|
| 67 | 3216 netsession_win.exe
|
|---|
| 68 | 3280 GoogleUpdate.exe
|
|---|
| 69 | 3468 PNAMAIN.EXE
|
|---|
| 70 | 3676 netsession_win.exe
|
|---|
| 71 | 1068 DynamicUSB.exe
|
|---|
| 72 | 3512 fsav32.exe
|
|---|
| 73 | 2796 WFCRUN32.EXE
|
|---|
| 74 | 348 WFICA32.EXE
|
|---|
| 75 | 1228 FAPA.Exe
|
|---|
| 76 | 2168 TBTray.exe
|
|---|
| 77 | 3940 thunderbird.exe
|
|---|
| 78 | 4024 EXCEL.EXE
|
|---|
| 79 | 3756 firefox.exe
|
|---|
| 80 | 1700 plugin-container.exe
|
|---|
| 81 | 3824 cmd.exe
|
|---|
| 82 | 2952 VirtualBox.exe
|
|---|
| 83 | 1392 VBoxSVC.exe
|
|---|
| 84 | 3932 VirtualBox.exe
|
|---|
| 85 | 3148 wmiprvse.exe
|
|---|
| 86 | 2252 drwtsn32.exe
|
|---|
| 87 |
|
|---|
| 88 | *----> Liste des modules <----*
|
|---|
| 89 | (0000000000330000 - 0000000000336000: C:\Program Files\Oracle\VirtualBox\VBoxREM.dll
|
|---|
| 90 | (0000000000400000 - 0000000000ad4000: C:\Program Files\Oracle\VirtualBox\VirtualBox.exe
|
|---|
| 91 | (0000000000ae0000 - 0000000000e19000: C:\Program Files\Oracle\VirtualBox\VBoxRT.dll
|
|---|
| 92 | (0000000000e20000 - 0000000000ebd000: C:\WINNT\system32\SHLWAPI.dll
|
|---|
| 93 | (0000000009bf0000 - 0000000009bf9000: C:\WINNT\system32\Normaliz.dll
|
|---|
| 94 | (0000000009c10000 - 000000000a121000: C:\WINNT\system32\xpsp2res.dll
|
|---|
| 95 | (000000000a830000 - 000000000a9d3000: C:\Program Files\Oracle\VirtualBox\VBoxC.dll
|
|---|
| 96 | (000000000a9e0000 - 000000000aa38000: C:\WINNT\system32\credui.dll
|
|---|
| 97 | (000000000ac90000 - 000000000ac95000: C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxPuelMain.DLL
|
|---|
| 98 | (000000000b460000 - 000000000b468000: C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL
|
|---|
| 99 | (000000000b670000 - 000000000b67a000: C:\Program Files\Oracle\VirtualBox\VBoxDragAndDropSvc.DLL
|
|---|
| 100 | (000000000b780000 - 000000000b842000: C:\Program Files\Oracle\VirtualBox\VBoxSharedCrOpenGL.DLL
|
|---|
| 101 | (000000000b850000 - 000000000b87b000: C:\Program Files\Oracle\VirtualBox\VBoxOGLhostcrutil.dll
|
|---|
| 102 | (000000000b880000 - 000000000b89b000: C:\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll
|
|---|
| 103 | (000000000b9a0000 - 000000000b9b8000: C:\Program Files\Oracle\VirtualBox\VBoxOGLhosterrorspu.dll
|
|---|
| 104 | (000000000bac0000 - 000000000be81000: C:\WINNT\system32\ig4icd32.dll
|
|---|
| 105 | (000000000c030000 - 000000000c267000: C:\WINNT\system32\ig4dev32.dll
|
|---|
| 106 | (000000000d6d0000 - 000000000d6db000: C:\Program Files\Oracle\VirtualBox\VBoxGuestPropSvc.DLL
|
|---|
| 107 | (000000000d7e0000 - 000000000d7ea000: C:\Program Files\Oracle\VirtualBox\VBoxGuestControlSvc.DLL
|
|---|
| 108 | (000000000f470000 - 000000000f698000: C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL
|
|---|
| 109 | (000000000f6a0000 - 000000000f6ed000: C:\Program Files\Oracle\VirtualBox\VBoxDDU.dll
|
|---|
| 110 | (000000000f6f0000 - 000000000f720000: C:\Program Files\Oracle\VirtualBox\VBoxDD2.dll
|
|---|
| 111 | (000000000f720000 - 000000000f72b000: C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxEhciR3.DLL
|
|---|
| 112 | (000000000f730000 - 000000000f741000: C:\Program Files\Oracle\VirtualBox\ExtensionPacks\Oracle_VM_VirtualBox_Extension_Pack\win.x86\VBoxUsbCardReaderR3.DLL
|
|---|
| 113 | (000000000fed0000 - 000000000fed9000: C:\Program Files\Oracle\VirtualBox\VBoxSharedFolders.DLL
|
|---|
| 114 | (000000000ff90000 - 000000000ff9e000: C:\WINNT\system32\eappprxy.dll
|
|---|
| 115 | (0000000010000000 - 00000000101a2000: C:\Program Files\Oracle\VirtualBox\VBoxVMM.dll
|
|---|
| 116 | (00000000404a0000 - 0000000040586000: C:\WINNT\system32\WININET.dll
|
|---|
| 117 | (0000000040b40000 - 0000000040d2b000: C:\WINNT\system32\iertutil.dll
|
|---|
| 118 | (0000000045180000 - 00000000452b3000: C:\WINNT\system32\urlmon.dll
|
|---|
| 119 | (0000000058a10000 - 0000000058a51000: C:\WINNT\system32\icm32.dll
|
|---|
| 120 | (0000000058b50000 - 0000000058bea000: C:\WINNT\system32\COMCTL32.dll
|
|---|
| 121 | (000000005abc0000 - 000000005ad2d000: C:\WINNT\system32\newdev.dll
|
|---|
| 122 | (000000005b090000 - 000000005b0c8000: C:\WINNT\system32\uxtheme.dll
|
|---|
| 123 | (000000005b660000 - 000000005b66a000: C:\WINNT\system32\dot3api.dll
|
|---|
| 124 | (000000005bdf0000 - 000000005be06000: C:\WINNT\system32\QUtil.dll
|
|---|
| 125 | (000000005f070000 - 000000005f13c000: C:\WINNT\system32\OPENGL32.dll
|
|---|
| 126 | (0000000061380000 - 0000000061461000: D:/tinderbox/win-4.2/out/win.x86/release/obj/VBoxRemPrimary/VBoxREM32.dll
|
|---|
| 127 | (0000000062e40000 - 0000000062e99000: C:\WINNT\system32\hnetcfg.dll
|
|---|
| 128 | (0000000063000000 - 00000000630b1000: C:\Program Files\Oracle\VirtualBox\QtOpenGLVBox4.dll
|
|---|
| 129 | (0000000064000000 - 00000000640d7000: C:\Program Files\Oracle\VirtualBox\QtNetworkVBox4.dll
|
|---|
| 130 | (0000000065000000 - 00000000657ee000: C:\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll
|
|---|
| 131 | (0000000067000000 - 0000000067236000: C:\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll
|
|---|
| 132 | (000000006cef0000 - 000000006cf11000: C:\WINNT\system32\GLU32.dll
|
|---|
| 133 | (000000006da60000 - 000000006da82000: C:\WINNT\system32\eappcfg.dll
|
|---|
| 134 | (000000006f890000 - 000000006f9a1000: C:\WINNT\system32\ESENT.dll
|
|---|
| 135 | (000000006fee0000 - 000000006ff35000: C:\WINNT\system32\NETAPI32.dll
|
|---|
| 136 | (0000000071780000 - 000000007178b000: C:\WINNT\system32\EapolQec.dll
|
|---|
| 137 | (0000000071990000 - 00000000719d0000: C:\WINNT\System32\mswsock.dll
|
|---|
| 138 | (00000000719d0000 - 00000000719d8000: C:\WINNT\System32\wshtcpip.dll
|
|---|
| 139 | (00000000719e0000 - 00000000719e8000: C:\WINNT\system32\WS2HELP.dll
|
|---|
| 140 | (00000000719f0000 - 0000000071a07000: C:\WINNT\system32\WS2_32.dll
|
|---|
| 141 | (0000000071b50000 - 0000000071b63000: C:\WINNT\system32\SAMLIB.dll
|
|---|
| 142 | (0000000072640000 - 0000000072646000: C:\WINNT\system32\dot3dlg.dll
|
|---|
| 143 | (0000000072c60000 - 0000000072c68000: C:\WINNT\system32\msacm32.drv
|
|---|
| 144 | (0000000072c70000 - 0000000072c79000: C:\WINNT\system32\wdmaud.drv
|
|---|
| 145 | (0000000072f50000 - 0000000072f76000: C:\WINNT\system32\WINSPOOL.DRV
|
|---|
| 146 | (0000000072f80000 - 0000000072f90000: C:\WINNT\system32\WZCSAPI.DLL
|
|---|
| 147 | (00000000736b0000 - 00000000736fb000: C:\WINNT\system32\DDRAW.dll
|
|---|
| 148 | (0000000073990000 - 00000000739b8000: C:\WINNT\system32\OneX.DLL
|
|---|
| 149 | (0000000073a80000 - 0000000073a95000: C:\WINNT\system32\mscms.dll
|
|---|
| 150 | (0000000073b10000 - 0000000073b16000: C:\WINNT\system32\DCIMAN32.dll
|
|---|
| 151 | (0000000073e30000 - 0000000073e34000: C:\WINNT\system32\KsUser.dll
|
|---|
| 152 | (0000000073e60000 - 0000000073ebc000: C:\WINNT\system32\dsound.dll
|
|---|
| 153 | (0000000074690000 - 00000000746dc000: C:\WINNT\system32\MSCTF.dll
|
|---|
| 154 | (0000000075140000 - 000000007516e000: C:\WINNT\system32\msctfime.ime
|
|---|
| 155 | (0000000076010000 - 0000000076075000: C:\WINNT\system32\MSVCP60.dll
|
|---|
| 156 | (00000000762f0000 - 0000000076300000: C:\WINNT\system32\WINSTA.dll
|
|---|
| 157 | (0000000076320000 - 000000007633d000: C:\WINNT\system32\IMM32.dll
|
|---|
| 158 | (0000000076340000 - 000000007638a000: C:\WINNT\system32\COMDLG32.dll
|
|---|
| 159 | (0000000076390000 - 00000000766e8000: C:\WINNT\system32\netshell.dll
|
|---|
| 160 | (0000000076960000 - 0000000076a16000: C:\WINNT\system32\userenv.dll
|
|---|
| 161 | (0000000076ac0000 - 0000000076ad1000: C:\WINNT\system32\ATL.DLL
|
|---|
| 162 | (0000000076ae0000 - 0000000076b0f000: C:\WINNT\system32\WINMM.dll
|
|---|
| 163 | (0000000076be0000 - 0000000076c0e000: C:\WINNT\system32\WINTRUST.dll
|
|---|
| 164 | (0000000076c40000 - 0000000076c68000: C:\WINNT\system32\IMAGEHLP.dll
|
|---|
| 165 | (0000000076ce0000 - 0000000076ce4000: C:\WINNT\system32\WMI.dll
|
|---|
| 166 | (0000000076cf0000 - 0000000076d08000: C:\WINNT\system32\MPRAPI.dll
|
|---|
| 167 | (0000000076d10000 - 0000000076d29000: C:\WINNT\system32\IPHLPAPI.DLL
|
|---|
| 168 | (0000000076dc0000 - 0000000076de5000: C:\WINNT\system32\adsldpc.dll
|
|---|
| 169 | (0000000076e30000 - 0000000076e3e000: C:\WINNT\system32\rtutils.dll
|
|---|
| 170 | (0000000076e40000 - 0000000076e52000: C:\WINNT\system32\rasman.dll
|
|---|
| 171 | (0000000076e60000 - 0000000076e8f000: C:\WINNT\system32\TAPI32.dll
|
|---|
| 172 | (0000000076e90000 - 0000000076ecc000: C:\WINNT\system32\RASAPI32.dll
|
|---|
| 173 | (0000000076ed0000 - 0000000076ef7000: C:\WINNT\system32\DNSAPI.dll
|
|---|
| 174 | (0000000076f00000 - 0000000076f08000: C:\WINNT\system32\WTSAPI32.dll
|
|---|
| 175 | (0000000076f10000 - 0000000076f3d000: C:\WINNT\system32\WLDAP32.dll
|
|---|
| 176 | (0000000076f60000 - 0000000076f68000: C:\WINNT\System32\winrnr.dll
|
|---|
| 177 | (0000000076f80000 - 0000000076fff000: C:\WINNT\system32\CLBCATQ.DLL
|
|---|
| 178 | (0000000077000000 - 00000000770d4000: C:\WINNT\system32\COMRes.dll
|
|---|
| 179 | (00000000770e0000 - 000000007716b000: C:\WINNT\system32\OLEAUT32.dll
|
|---|
| 180 | (0000000077210000 - 00000000772c1000: C:\WINNT\system32\SXS.DLL
|
|---|
| 181 | (0000000077390000 - 0000000077493000: C:\WINNT\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
|
|---|
| 182 | (00000000774a0000 - 00000000775de000: C:\WINNT\system32\ole32.dll
|
|---|
| 183 | (00000000778e0000 - 00000000779d8000: C:\WINNT\system32\SETUPAPI.dll
|
|---|
| 184 | (00000000779e0000 - 0000000077a77000: C:\WINNT\system32\CRYPT32.dll
|
|---|
| 185 | (0000000077a80000 - 0000000077a92000: C:\WINNT\system32\MSASN1.dll
|
|---|
| 186 | (0000000077b50000 - 0000000077b72000: C:\WINNT\system32\Apphelp.dll
|
|---|
| 187 | (0000000077ba0000 - 0000000077ba7000: C:\WINNT\system32\midimap.dll
|
|---|
| 188 | (0000000077bb0000 - 0000000077bc5000: C:\WINNT\system32\MSACM32.dll
|
|---|
| 189 | (0000000077bd0000 - 0000000077bd8000: C:\WINNT\system32\VERSION.dll
|
|---|
| 190 | (0000000077be0000 - 0000000077c38000: C:\WINNT\system32\msvcrt.dll
|
|---|
| 191 | (0000000077c90000 - 0000000077cc2000: C:\WINNT\system32\ACTIVEDS.dll
|
|---|
| 192 | (0000000077cd0000 - 0000000077d03000: C:\WINNT\system32\netman.dll
|
|---|
| 193 | (0000000077da0000 - 0000000077e4c000: C:\WINNT\system32\ADVAPI32.dll
|
|---|
| 194 | (0000000077e50000 - 0000000077ee3000: C:\WINNT\system32\RPCRT4.dll
|
|---|
| 195 | (0000000077ef0000 - 0000000077f39000: C:\WINNT\system32\GDI32.dll
|
|---|
| 196 | (0000000077fc0000 - 0000000077fd1000: C:\WINNT\system32\Secur32.dll
|
|---|
| 197 | (0000000078050000 - 00000000780b9000: C:\Program Files\Oracle\VirtualBox\MSVCP100.dll
|
|---|
| 198 | (0000000078aa0000 - 0000000078b5f000: C:\Program Files\Oracle\VirtualBox\MSVCR100.dll
|
|---|
| 199 | (000000007c800000 - 000000007c906000: C:\WINNT\system32\kernel32.dll
|
|---|
| 200 | (000000007c910000 - 000000007c9c9000: C:\WINNT\system32\ntdll.dll
|
|---|
| 201 | (000000007c9d0000 - 000000007d1f5000: C:\WINNT\system32\SHELL32.dll
|
|---|
| 202 | (000000007d200000 - 000000007d4bc000: C:\WINNT\system32\msi.dll
|
|---|
| 203 | (000000007d4d0000 - 000000007d4f2000: C:\WINNT\system32\DHCPCSVC.DLL
|
|---|
| 204 | (000000007db30000 - 000000007dbbc000: C:\WINNT\system32\WZCSvc.DLL
|
|---|
| 205 | (000000007e390000 - 000000007e421000: C:\WINNT\system32\USER32.dll
|
|---|
| 206 |
|
|---|
| 207 | *----> Vidage de l'état de la thread 0x13c <----*
|
|---|
| 208 |
|
|---|
| 209 | eax=9a07259c ebx=00000102 ecx=00000000 edx=00000000 esi=0012e010 edi=00000000
|
|---|
| 210 | eip=7c91e460 esp=0012df3c ebp=0012dfa4 iopl=0 nv up ei pl zr na po nc
|
|---|
| 211 | cs=001b ss=0023 ds=0001 es=058c fs=003b gs=0020 efl=00000246
|
|---|
| 212 |
|
|---|
| 213 | *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINNT\system32\ntdll.dll -
|
|---|
| 214 | fonction : ntdll!KiUserCallbackDispatcher
|
|---|
| 215 | 7c91e44e 90 nop
|
|---|
| 216 | 7c91e44f 90 nop
|
|---|
| 217 | ntdll!KiUserApcDispatcher:
|
|---|
| 218 | 7c91e450 8d7c2410 lea edi,[esp+0x10]
|
|---|
| 219 | 7c91e454 58 pop eax
|
|---|
| 220 | 7c91e455 ffd0 call eax
|
|---|
| 221 | 7c91e457 6a01 push 0x1
|
|---|
| 222 | 7c91e459 57 push edi
|
|---|
| 223 | 7c91e45a e8ffebffff call ntdll!ZwContinue (7c91d05e)
|
|---|
| 224 | 7c91e45f 90 nop
|
|---|
| 225 | ntdll!KiUserCallbackDispatcher:
|
|---|
| 226 | 7c91e460 83c404 add esp,0x4
|
|---|
| 227 | 7c91e463 5a pop edx
|
|---|
| 228 | 7c91e464 64a118000000 mov eax,fs:[00000018]
|
|---|
| 229 | 7c91e46a 8b4030 mov eax,[eax+0x30]
|
|---|
| 230 | 7c91e46d 8b402c mov eax,[eax+0x2c]
|
|---|
| 231 | 7c91e470 ff1490 call dword ptr [eax+edx*4]
|
|---|
| 232 | 7c91e473 33c9 xor ecx,ecx
|
|---|
| 233 | 7c91e475 33d2 xor edx,edx
|
|---|
| 234 | 7c91e477 cd2b int 2b
|
|---|
| 235 | 7c91e479 cc int 3
|
|---|
| 236 | 7c91e47a 8bff mov edi,edi
|
|---|
| 237 |
|
|---|
| 238 | *----> Suivi arrière de la pile <----*
|
|---|
| 239 | *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINNT\system32\USER32.dll -
|
|---|
| 240 | WARNING: Stack unwind information not available. Following frames may be wrong.
|
|---|
| 241 | *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\Program Files\Oracle\VirtualBox\QtCoreVBox4.dll -
|
|---|
| 242 | *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\Program Files\Oracle\VirtualBox\QtGuiVBox4.dll -
|
|---|
| 243 | ChildEBP RetAddr Args to Child
|
|---|
| 244 | 0012dfa4 7e399402 0012e010 00000000 00000000 ntdll!KiUserCallbackDispatcher
|
|---|
| 245 | 0012dfd0 67108242 0012e010 00000000 00000000 USER32!PeekMessageW+0x167
|
|---|
| 246 | 003dd110 003dd120 00020014 000c01f1 671af638 QtCoreVBox4!QEventDispatcherWin32__processEvents+0x252
|
|---|
| 247 | 655801ac 65510ca4 65510caa 6506eb10 65510cb0 0x3dd120
|
|---|
| 248 | 65510c9e 25ff6557 65577abc 7ac025ff 25ff6557 QtGuiVBox4!QTouchEvent__operator=+0x134
|
|---|
| 249 | 7ab825ff 00000000 00000000 00000000 00000000 0x25ff6557
|
|---|
| 250 |
|
|---|
| 251 | *----> Vidage brut de la pile <----*
|
|---|
| 252 | 000000000012df3c 00 00 00 00 16 00 00 00 - 4c df 12 00 30 00 00 00 ........L...0...
|
|---|
| 253 | 000000000012df4c 28 e5 13 01 46 00 00 00 - 00 00 00 00 ae 05 1f 00 (...F...........
|
|---|
| 254 | 000000000012df5c a8 04 06 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 255 | 000000000012df6c 00 00 00 00 13 00 00 00 - 2a 91 15 75 53 8e 3a 7e ........*..uS.:~
|
|---|
| 256 | 000000000012df7c e9 93 39 7e a8 93 39 7e - 10 e0 12 00 00 00 00 00 ..9~..9~........
|
|---|
| 257 | 000000000012df8c 00 00 00 00 00 00 00 00 - 01 00 00 00 f8 a8 13 01 ................
|
|---|
| 258 | 000000000012df9c 00 f0 fd 7f 20 d1 3d 00 - d0 df 12 00 02 94 39 7e .... .=.......9~
|
|---|
| 259 | 000000000012dfac 10 e0 12 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 260 | 000000000012dfbc 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 261 | 000000000012dfcc 20 d1 3d 00 10 d1 3d 00 - 42 82 10 67 10 e0 12 00 .=...=.B..g....
|
|---|
| 262 | 000000000012dfdc 00 00 00 00 00 00 00 00 - 00 00 00 00 01 00 00 00 ................
|
|---|
| 263 | 000000000012dfec e0 ee 6b 72 28 ed 36 0a - 28 ed 36 0a f4 fd 12 00 ..kr(.6.(.6.....
|
|---|
| 264 | 000000000012dffc 24 00 00 00 00 00 00 01 - 00 00 00 00 10 d1 3d 00 $.............=.
|
|---|
| 265 | 000000000012e00c 20 d1 3d 00 8c 05 05 00 - 00 02 00 00 00 00 00 00 .=.............
|
|---|
| 266 | 000000000012e01c eb 01 64 01 db 78 59 01 - f3 03 00 00 47 02 00 00 ..d..xY.....G...
|
|---|
| 267 | 000000000012e02c 01 00 00 00 84 95 0e 77 - 07 00 61 00 00 00 00 00 .......w..a.....
|
|---|
| 268 | 000000000012e03c 00 00 59 00 00 e0 1b 00 - ae 05 1f 00 13 01 00 00 ..Y.............
|
|---|
| 269 | 000000000012e04c 01 00 00 00 00 00 00 00 - 91 65 59 01 7a 03 00 00 .........eY.z...
|
|---|
| 270 | 000000000012e05c e7 01 00 00 04 0f 92 7c - 86 10 92 7c db 01 92 7c .......|...|...|
|
|---|
| 271 | 000000000012e06c 00 00 00 00 e0 4a 1c 00 - 34 4c 1c 00 28 02 92 7c .....J..4L..(..|
|
|---|
| 272 |
|
|---|
| 273 | *----> Vidage de l'état de la thread 0x6e8 <----*
|
|---|
| 274 |
|
|---|
| 275 | eax=72c730e8 ebx=0989fef8 ecx=00000083 edx=001616a8 esi=00000000 edi=7ffd8000
|
|---|
| 276 | eip=7c91e514 esp=0989fed0 ebp=0989ff6c iopl=0 nv up ei pl zr na po nc
|
|---|
| 277 | cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
|
|---|
| 278 |
|
|---|
| 279 | fonction : ntdll!KiFastSystemCallRet
|
|---|
| 280 | 7c91e4fa e829000000 call ntdll!RtlRaiseException (7c91e528)
|
|---|
| 281 | 7c91e4ff 8b0424 mov eax,[esp]
|
|---|
| 282 | 7c91e502 8be5 mov esp,ebp
|
|---|
| 283 | 7c91e504 5d pop ebp
|
|---|
| 284 | 7c91e505 c3 ret
|
|---|
| 285 | 7c91e506 8da42400000000 lea esp,[esp]
|
|---|
| 286 | 7c91e50d 8d4900 lea ecx,[ecx]
|
|---|
| 287 | ntdll!KiFastSystemCall:
|
|---|
| 288 | 7c91e510 8bd4 mov edx,esp
|
|---|
| 289 | 7c91e512 0f34 sysenter
|
|---|
| 290 | ntdll!KiFastSystemCallRet:
|
|---|
| 291 | 7c91e514 c3 ret
|
|---|
| 292 | 7c91e515 8da42400000000 lea esp,[esp]
|
|---|
| 293 | 7c91e51c 8d642400 lea esp,[esp]
|
|---|
| 294 | ntdll!KiIntSystemCall:
|
|---|
| 295 | 7c91e520 8d542408 lea edx,[esp+0x8]
|
|---|
| 296 | 7c91e524 cd2e int 2e
|
|---|
| 297 | 7c91e526 c3 ret
|
|---|
| 298 | 7c91e527 90 nop
|
|---|
| 299 | ntdll!RtlRaiseException:
|
|---|
| 300 | 7c91e528 55 push ebp
|
|---|
| 301 | 7c91e529 8bec mov ebp,esp
|
|---|
| 302 |
|
|---|
| 303 | *----> Suivi arrière de la pile <----*
|
|---|
| 304 | *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINNT\system32\kernel32.dll -
|
|---|
| 305 | WARNING: Stack unwind information not available. Following frames may be wrong.
|
|---|
| 306 | *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINNT\system32\wdmaud.drv -
|
|---|
| 307 | ChildEBP RetAddr Args to Child
|
|---|
| 308 | 0989ff6c 7c80a115 00000002 0989ffa4 00000000 ntdll!KiFastSystemCallRet
|
|---|
| 309 | 0989ff88 72c7312a 00000002 0989ffa4 00000000 kernel32!WaitForMultipleObjects+0x18
|
|---|
| 310 | 0989ffb4 7c80b729 00000000 00000000 020a0014 wdmaud!midMessage+0x348
|
|---|
| 311 | 0989ffec 00000000 72c730e8 00000000 00000000 kernel32!GetModuleFileNameA+0x1ba
|
|---|
| 312 |
|
|---|
| 313 | *----> Vidage brut de la pile <----*
|
|---|
| 314 | 000000000989fed0 4a df 91 7c 90 95 80 7c - 02 00 00 00 f8 fe 89 09 J..|...|........
|
|---|
| 315 | 000000000989fee0 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 316 | 000000000989fef0 00 00 00 00 00 00 00 00 - cc 0e 00 00 d0 0e 00 00 ................
|
|---|
| 317 | 000000000989ff00 46 02 00 00 1b 5a 54 80 - 28 6c 4a 96 98 2b e0 88 F....ZT.(lJ..+..
|
|---|
| 318 | 000000000989ff10 20 f1 df ff 34 2d e0 88 - 14 00 00 00 01 00 00 00 ...4-..........
|
|---|
| 319 | 000000000989ff20 00 00 00 00 00 00 00 00 - 10 00 00 00 98 2b e0 88 .............+..
|
|---|
| 320 | 000000000989ff30 cc 2b e0 88 01 00 00 00 - 00 80 fd 7f 00 e0 fd 7f .+..............
|
|---|
| 321 | 000000000989ff40 98 2b e0 88 00 00 00 00 - f8 fe 89 09 8c 2f 50 80 .+.........../P.
|
|---|
| 322 | 000000000989ff50 02 00 00 00 ec fe 89 09 - 00 00 00 00 dc ff 89 09 ................
|
|---|
| 323 | 000000000989ff60 d8 9a 83 7c 80 96 80 7c - 00 00 00 00 88 ff 89 09 ...|...|........
|
|---|
| 324 | 000000000989ff70 15 a1 80 7c 02 00 00 00 - a4 ff 89 09 00 00 00 00 ...|............
|
|---|
| 325 | 000000000989ff80 ff ff ff ff 00 00 00 00 - b4 ff 89 09 2a 31 c7 72 ............*1.r
|
|---|
| 326 | 000000000989ff90 02 00 00 00 a4 ff 89 09 - 00 00 00 00 ff ff ff ff ................
|
|---|
| 327 | 000000000989ffa0 14 00 0a 02 cc 0e 00 00 - d0 0e 00 00 f2 7e 6e 80 .............~n.
|
|---|
| 328 | 000000000989ffb0 1a da 91 7c ec ff 89 09 - 29 b7 80 7c 00 00 00 00 ...|....)..|....
|
|---|
| 329 | 000000000989ffc0 00 00 00 00 14 00 0a 02 - 00 00 00 00 00 e0 fd 7f ................
|
|---|
| 330 | 000000000989ffd0 00 56 4f 8a c0 ff 89 09 - 30 d1 bb 88 ff ff ff ff .VO.....0.......
|
|---|
| 331 | 000000000989ffe0 d8 9a 83 7c 30 b7 80 7c - 00 00 00 00 00 00 00 00 ...|0..|........
|
|---|
| 332 | 000000000989fff0 00 00 00 00 e8 30 c7 72 - 00 00 00 00 00 00 00 00 .....0.r........
|
|---|
| 333 | 00000000098a0000 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 334 |
|
|---|
| 335 | *----> Vidage de l'état de la thread 0x28c <----*
|
|---|
| 336 |
|
|---|
| 337 | eax=7ffd8000 ebx=00002000 ecx=099aedac edx=7c91e514 esi=0d351ab0 edi=0d351bd4
|
|---|
| 338 | eip=7c91e514 esp=099afcb0 ebp=099afde0 iopl=0 nv up ei pl zr na po nc
|
|---|
| 339 | cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
|
|---|
| 340 |
|
|---|
| 341 | fonction : ntdll!KiFastSystemCallRet
|
|---|
| 342 | 7c91e4fa e829000000 call ntdll!RtlRaiseException (7c91e528)
|
|---|
| 343 | 7c91e4ff 8b0424 mov eax,[esp]
|
|---|
| 344 | 7c91e502 8be5 mov esp,ebp
|
|---|
| 345 | 7c91e504 5d pop ebp
|
|---|
| 346 | 7c91e505 c3 ret
|
|---|
| 347 | 7c91e506 8da42400000000 lea esp,[esp]
|
|---|
| 348 | 7c91e50d 8d4900 lea ecx,[ecx]
|
|---|
| 349 | ntdll!KiFastSystemCall:
|
|---|
| 350 | 7c91e510 8bd4 mov edx,esp
|
|---|
| 351 | 7c91e512 0f34 sysenter
|
|---|
| 352 | ntdll!KiFastSystemCallRet:
|
|---|
| 353 | 7c91e514 c3 ret
|
|---|
| 354 | 7c91e515 8da42400000000 lea esp,[esp]
|
|---|
| 355 | 7c91e51c 8d642400 lea esp,[esp]
|
|---|
| 356 | ntdll!KiIntSystemCall:
|
|---|
| 357 | 7c91e520 8d542408 lea edx,[esp+0x8]
|
|---|
| 358 | 7c91e524 cd2e int 2e
|
|---|
| 359 | 7c91e526 c3 ret
|
|---|
| 360 | 7c91e527 90 nop
|
|---|
| 361 | ntdll!RtlRaiseException:
|
|---|
| 362 | 7c91e528 55 push ebp
|
|---|
| 363 | 7c91e529 8bec mov ebp,esp
|
|---|
| 364 |
|
|---|
| 365 | *----> Suivi arrière de la pile <----*
|
|---|
| 366 | *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINNT\system32\RPCRT4.dll -
|
|---|
| 367 | WARNING: Stack unwind information not available. Following frames may be wrong.
|
|---|
| 368 | ChildEBP RetAddr Args to Child
|
|---|
| 369 | 099afde0 77e6947d 0d351bd4 099afdf4 00143240 ntdll!KiFastSystemCallRet
|
|---|
| 370 | 099afdf8 77e80013 41105760 00143240 001c7f08 RPCRT4!RpcBindingSetAuthInfoExW+0x199
|
|---|
| 371 | 099afe1c 77e5b7b6 0014327c 099afe38 001c7f08 RPCRT4!I_RpcAsyncSetHandle+0x4a
|
|---|
| 372 | 099aff80 77e56caf 099affa8 77e56ad1 00143240 RPCRT4!NdrSimpleStructFree+0x114
|
|---|
| 373 | 099aff88 77e56ad1 00143240 001603b0 0012de3c RPCRT4!I_RpcBCacheFree+0x61c
|
|---|
| 374 | 099affa8 77e56c97 00153588 099affec 7c80b729 RPCRT4!I_RpcBCacheFree+0x43e
|
|---|
| 375 | 099affb4 7c80b729 0015f308 001603b0 0012de3c RPCRT4!I_RpcBCacheFree+0x604
|
|---|
| 376 | 099affec 00000000 77e56c7d 0015f308 00000000 kernel32!GetModuleFileNameA+0x1ba
|
|---|
| 377 |
|
|---|
| 378 | *----> Vidage brut de la pile <----*
|
|---|
| 379 | 00000000099afcb0 ea da 91 7c b1 f6 e6 77 - 50 03 00 00 38 fe 9a 09 ...|...wP...8...
|
|---|
| 380 | 00000000099afcc0 dc fc 9a 09 e0 10 91 7c - b0 1a 35 0d b0 1a 35 0d .......|..5...5.
|
|---|
| 381 | 00000000099afcd0 f4 fd 9a 09 d7 99 e5 77 - 00 00 00 00 d4 1b 35 0d .......w......5.
|
|---|
| 382 | 00000000099afce0 bb 06 00 00 01 00 00 00 - d8 fc 9a 09 36 cf 4e 77 ............6.Nw
|
|---|
| 383 | 00000000099afcf0 dc ff 9a 09 98 f9 e7 77 - e0 99 e5 77 ff ff ff ff .......w...w....
|
|---|
| 384 | 00000000099afd00 b0 1a 35 0d 54 fd 9a 09 - 8a 99 e5 77 00 00 00 00 ..5.T......w....
|
|---|
| 385 | 00000000099afd10 00 00 00 00 00 00 00 00 - a8 7d 1c 00 d4 1b 35 0d .........}....5.
|
|---|
| 386 | 00000000099afd20 4c 02 00 00 90 fd 9a 09 - 98 57 10 41 f6 a5 4e 77 L........W.A..Nw
|
|---|
| 387 | 00000000099afd30 08 9e 19 00 01 00 00 00 - 4c 02 00 00 00 00 00 00 ........L.......
|
|---|
| 388 | 00000000099afd40 01 00 00 00 2d a4 01 00 - 5c 0f ff ff 08 f3 15 00 ....-...\.......
|
|---|
| 389 | 00000000099afd50 00 00 00 00 78 fd 9a 09 - 5d 98 e5 77 00 00 00 00 ....x...]..w....
|
|---|
| 390 | 00000000099afd60 00 00 00 00 81 98 e5 77 - a0 7e 1c 00 a8 7d 1c 00 .......w.~...}..
|
|---|
| 391 | 00000000099afd70 d4 1b 35 0d b0 1a 35 0d - b8 fd 9a 09 f0 23 e8 77 ..5...5......#.w
|
|---|
| 392 | 00000000099afd80 00 00 00 00 00 00 00 00 - c8 bf 4a 77 ec fd 9a 09 ..........Jw....
|
|---|
| 393 | 00000000099afd90 68 32 36 0d 08 f3 15 00 - fb 23 e8 77 ec fd 9a 09 h26......#.w....
|
|---|
| 394 | 00000000099afda0 c8 bf 4a 77 00 00 00 00 - 00 00 00 00 00 00 00 00 ..Jw............
|
|---|
| 395 | 00000000099afdb0 00 00 00 00 10 53 00 00 - f8 fd 9a 09 31 24 e8 77 .....S......1$.w
|
|---|
| 396 | 00000000099afdc0 9e 99 e5 77 53 ba e5 77 - 00 00 00 00 f8 fd 9a 09 ...wS..w........
|
|---|
| 397 | 00000000099afdd0 26 ba e5 77 e0 10 91 7c - 40 32 14 00 10 53 00 00 &..w...|@2...S..
|
|---|
| 398 | 00000000099afde0 f8 fd 9a 09 7d 94 e6 77 - d4 1b 35 0d f4 fd 9a 09 ....}..w..5.....
|
|---|
| 399 |
|
|---|
| 400 | *----> Vidage de l'état de la thread 0xcb4 <----*
|
|---|
| 401 |
|
|---|
| 402 | eax=774be4df ebx=00007530 ecx=7ffd8000 edx=00000000 esi=00000000 edi=09aaff50
|
|---|
| 403 | eip=7c91e514 esp=09aaff20 ebp=09aaff78 iopl=0 nv up ei pl nz na po nc
|
|---|
| 404 | cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000206
|
|---|
| 405 |
|
|---|
| 406 | fonction : ntdll!KiFastSystemCallRet
|
|---|
| 407 | 7c91e4fa e829000000 call ntdll!RtlRaiseException (7c91e528)
|
|---|
| 408 | 7c91e4ff 8b0424 mov eax,[esp]
|
|---|
| 409 | 7c91e502 8be5 mov esp,ebp
|
|---|
| 410 | 7c91e504 5d pop ebp
|
|---|
| 411 | 7c91e505 c3 ret
|
|---|
| 412 | 7c91e506 8da42400000000 lea esp,[esp]
|
|---|
| 413 | 7c91e50d 8d4900 lea ecx,[ecx]
|
|---|
| 414 | ntdll!KiFastSystemCall:
|
|---|
| 415 | 7c91e510 8bd4 mov edx,esp
|
|---|
| 416 | 7c91e512 0f34 sysenter
|
|---|
| 417 | ntdll!KiFastSystemCallRet:
|
|---|
| 418 | 7c91e514 c3 ret
|
|---|
| 419 | 7c91e515 8da42400000000 lea esp,[esp]
|
|---|
| 420 | 7c91e51c 8d642400 lea esp,[esp]
|
|---|
| 421 | ntdll!KiIntSystemCall:
|
|---|
| 422 | 7c91e520 8d542408 lea edx,[esp+0x8]
|
|---|
| 423 | 7c91e524 cd2e int 2e
|
|---|
| 424 | 7c91e526 c3 ret
|
|---|
| 425 | 7c91e527 90 nop
|
|---|
| 426 | ntdll!RtlRaiseException:
|
|---|
| 427 | 7c91e528 55 push ebp
|
|---|
| 428 | 7c91e529 8bec mov ebp,esp
|
|---|
| 429 |
|
|---|
| 430 | *----> Suivi arrière de la pile <----*
|
|---|
| 431 | WARNING: Stack unwind information not available. Following frames may be wrong.
|
|---|
| 432 | *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINNT\system32\ole32.dll -
|
|---|
| 433 | ChildEBP RetAddr Args to Child
|
|---|
| 434 | 09aaff78 7c802455 0000ea60 00000000 09aaffb4 ntdll!KiFastSystemCallRet
|
|---|
| 435 | 09aaff88 774be3d3 0000ea60 0016b008 774be492 kernel32!Sleep+0xf
|
|---|
| 436 | 09aaffb4 7c80b729 0016b008 7c920435 7c92043e ole32!StringFromGUID2+0x51d
|
|---|
| 437 | 09aaffec 00000000 774be4df 0016b008 00000000 kernel32!GetModuleFileNameA+0x1ba
|
|---|
| 438 |
|
|---|
| 439 | *----> Vidage brut de la pile <----*
|
|---|
| 440 | 0000000009aaff20 1a d2 91 7c f1 23 80 7c - 00 00 00 00 50 ff aa 09 ...|.#.|....P...
|
|---|
| 441 | 0000000009aaff30 50 25 80 7c f8 7d 5c 77 - 30 75 00 00 14 00 00 00 P%.|.}\w0u......
|
|---|
| 442 | 0000000009aaff40 01 00 00 00 00 00 00 00 - 00 00 00 00 10 00 00 00 ................
|
|---|
| 443 | 0000000009aaff50 00 ba 3c dc ff ff ff ff - 10 d1 4a 77 50 ff aa 09 ..<.......JwP...
|
|---|
| 444 | 0000000009aaff60 30 ff aa 09 38 4c 14 00 - dc ff aa 09 d8 9a 83 7c 0...8L.........|
|
|---|
| 445 | 0000000009aaff70 60 24 80 7c 00 00 00 00 - 88 ff aa 09 55 24 80 7c `$.|........U$.|
|
|---|
| 446 | 0000000009aaff80 60 ea 00 00 00 00 00 00 - b4 ff aa 09 d3 e3 4b 77 `.............Kw
|
|---|
| 447 | 0000000009aaff90 60 ea 00 00 08 b0 16 00 - 92 e4 4b 77 00 00 00 00 `.........Kw....
|
|---|
| 448 | 0000000009aaffa0 35 04 92 7c 08 b0 16 00 - 00 00 4a 77 fa e4 4b 77 5..|......Jw..Kw
|
|---|
| 449 | 0000000009aaffb0 3e 04 92 7c ec ff aa 09 - 29 b7 80 7c 08 b0 16 00 >..|....)..|....
|
|---|
| 450 | 0000000009aaffc0 35 04 92 7c 3e 04 92 7c - 08 b0 16 00 00 c0 fd 7f 5..|>..|........
|
|---|
| 451 | 0000000009aaffd0 00 76 4f 8a c0 ff aa 09 - 38 9d 88 89 ff ff ff ff .vO.....8.......
|
|---|
| 452 | 0000000009aaffe0 d8 9a 83 7c 30 b7 80 7c - 00 00 00 00 00 00 00 00 ...|0..|........
|
|---|
| 453 | 0000000009aafff0 00 00 00 00 df e4 4b 77 - 08 b0 16 00 00 00 00 00 ......Kw........
|
|---|
| 454 | 0000000009ab0000 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 455 | 0000000009ab0010 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 456 | 0000000009ab0020 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 457 | 0000000009ab0030 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 458 | 0000000009ab0040 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 459 | 0000000009ab0050 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 460 |
|
|---|
| 461 | *----> Vidage de l'état de la thread 0x1d8 <----*
|
|---|
| 462 |
|
|---|
| 463 | eax=00000000 ebx=00000000 ecx=00170e28 edx=00000000 esi=00143240 edi=00000100
|
|---|
| 464 | eip=7c91e514 esp=09bafe18 ebp=09baff80 iopl=0 nv up ei pl zr na po nc
|
|---|
| 465 | cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
|
|---|
| 466 |
|
|---|
| 467 | fonction : ntdll!KiFastSystemCallRet
|
|---|
| 468 | 7c91e4fa e829000000 call ntdll!RtlRaiseException (7c91e528)
|
|---|
| 469 | 7c91e4ff 8b0424 mov eax,[esp]
|
|---|
| 470 | 7c91e502 8be5 mov esp,ebp
|
|---|
| 471 | 7c91e504 5d pop ebp
|
|---|
| 472 | 7c91e505 c3 ret
|
|---|
| 473 | 7c91e506 8da42400000000 lea esp,[esp]
|
|---|
| 474 | 7c91e50d 8d4900 lea ecx,[ecx]
|
|---|
| 475 | ntdll!KiFastSystemCall:
|
|---|
| 476 | 7c91e510 8bd4 mov edx,esp
|
|---|
| 477 | 7c91e512 0f34 sysenter
|
|---|
| 478 | ntdll!KiFastSystemCallRet:
|
|---|
| 479 | 7c91e514 c3 ret
|
|---|
| 480 | 7c91e515 8da42400000000 lea esp,[esp]
|
|---|
| 481 | 7c91e51c 8d642400 lea esp,[esp]
|
|---|
| 482 | ntdll!KiIntSystemCall:
|
|---|
| 483 | 7c91e520 8d542408 lea edx,[esp+0x8]
|
|---|
| 484 | 7c91e524 cd2e int 2e
|
|---|
| 485 | 7c91e526 c3 ret
|
|---|
| 486 | 7c91e527 90 nop
|
|---|
| 487 | ntdll!RtlRaiseException:
|
|---|
| 488 | 7c91e528 55 push ebp
|
|---|
| 489 | 7c91e529 8bec mov ebp,esp
|
|---|
| 490 |
|
|---|
| 491 | *----> Suivi arrière de la pile <----*
|
|---|
| 492 | WARNING: Stack unwind information not available. Following frames may be wrong.
|
|---|
| 493 | ChildEBP RetAddr Args to Child
|
|---|
| 494 | 09baff80 77e56caf 09baffa8 77e56ad1 00143240 ntdll!KiFastSystemCallRet
|
|---|
| 495 | 09baff88 77e56ad1 00143240 003d0178 00000000 RPCRT4!I_RpcBCacheFree+0x61c
|
|---|
| 496 | 09baffa8 77e56c97 00153588 09baffec 7c80b729 RPCRT4!I_RpcBCacheFree+0x43e
|
|---|
| 497 | 09baffb4 7c80b729 001702c0 003d0178 00000000 RPCRT4!I_RpcBCacheFree+0x604
|
|---|
| 498 | 09baffec 00000000 77e56c7d 001702c0 00000000 kernel32!GetModuleFileNameA+0x1ba
|
|---|
| 499 |
|
|---|
| 500 | *----> Vidage brut de la pile <----*
|
|---|
| 501 | 0000000009bafe18 aa da 91 7c e3 65 e5 77 - e4 0d 00 00 74 ff ba 09 ...|.e.w....t...
|
|---|
| 502 | 0000000009bafe28 00 00 00 00 88 01 17 00 - 50 ff ba 09 00 00 00 00 ........P.......
|
|---|
| 503 | 0000000009bafe38 30 00 48 00 00 00 00 00 - 70 05 00 00 3c 05 00 00 0.H.....p...<...
|
|---|
| 504 | 0000000009bafe48 00 00 00 00 00 00 00 00 - 02 00 00 00 01 00 00 00 ................
|
|---|
| 505 | 0000000009bafe58 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 506 | 0000000009bafe68 00 00 00 00 8f 00 00 00 - 01 00 00 00 00 00 00 00 ................
|
|---|
| 507 | 0000000009bafe78 00 00 00 00 09 00 00 00 - 12 00 00 00 09 00 00 00 ................
|
|---|
| 508 | 0000000009bafe88 31 00 30 00 2e 00 30 00 - 2e 00 32 00 2e 00 31 00 1.0...0...2...1.
|
|---|
| 509 | 0000000009bafe98 35 00 30 00 30 00 31 00 - 66 ae 7e 6f dd cb d9 12 5.0.0.1.f.~o....
|
|---|
| 510 | 0000000009bafea8 55 73 65 72 00 00 00 00 - 00 00 00 00 00 00 00 00 User............
|
|---|
| 511 | 0000000009bafeb8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 512 | 0000000009bafec8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 513 | 0000000009bafed8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 514 | 0000000009bafee8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 515 | 0000000009bafef8 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 516 | 0000000009baff08 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 517 | 0000000009baff18 38 05 33 ba 34 59 54 80 - 00 87 89 88 b4 b1 4f 80 8.3.4YT.......O.
|
|---|
| 518 | 0000000009baff28 54 89 89 88 80 ff ba 09 - 85 d1 e5 77 48 ff ba 09 T..........wH...
|
|---|
| 519 | 0000000009baff38 95 d1 e5 77 e0 10 91 7c - 58 b2 16 00 c0 02 17 00 ...w...|X.......
|
|---|
| 520 | 0000000009baff48 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff ../M.....]......
|
|---|
| 521 |
|
|---|
| 522 | *----> Vidage de l'état de la thread 0xe04 <----*
|
|---|
| 523 |
|
|---|
| 524 | eax=00017cb8 ebx=00000000 ecx=0000073e edx=00017cb8 esi=00143240 edi=00000100
|
|---|
| 525 | eip=7c91e514 esp=0a22fe18 ebp=0a22ff80 iopl=0 nv up ei pl zr na po nc
|
|---|
| 526 | cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
|
|---|
| 527 |
|
|---|
| 528 | fonction : ntdll!KiFastSystemCallRet
|
|---|
| 529 | 7c91e4fa e829000000 call ntdll!RtlRaiseException (7c91e528)
|
|---|
| 530 | 7c91e4ff 8b0424 mov eax,[esp]
|
|---|
| 531 | 7c91e502 8be5 mov esp,ebp
|
|---|
| 532 | 7c91e504 5d pop ebp
|
|---|
| 533 | 7c91e505 c3 ret
|
|---|
| 534 | 7c91e506 8da42400000000 lea esp,[esp]
|
|---|
| 535 | 7c91e50d 8d4900 lea ecx,[ecx]
|
|---|
| 536 | ntdll!KiFastSystemCall:
|
|---|
| 537 | 7c91e510 8bd4 mov edx,esp
|
|---|
| 538 | 7c91e512 0f34 sysenter
|
|---|
| 539 | ntdll!KiFastSystemCallRet:
|
|---|
| 540 | 7c91e514 c3 ret
|
|---|
| 541 | 7c91e515 8da42400000000 lea esp,[esp]
|
|---|
| 542 | 7c91e51c 8d642400 lea esp,[esp]
|
|---|
| 543 | ntdll!KiIntSystemCall:
|
|---|
| 544 | 7c91e520 8d542408 lea edx,[esp+0x8]
|
|---|
| 545 | 7c91e524 cd2e int 2e
|
|---|
| 546 | 7c91e526 c3 ret
|
|---|
| 547 | 7c91e527 90 nop
|
|---|
| 548 | ntdll!RtlRaiseException:
|
|---|
| 549 | 7c91e528 55 push ebp
|
|---|
| 550 | 7c91e529 8bec mov ebp,esp
|
|---|
| 551 |
|
|---|
| 552 | *----> Suivi arrière de la pile <----*
|
|---|
| 553 | WARNING: Stack unwind information not available. Following frames may be wrong.
|
|---|
| 554 | ChildEBP RetAddr Args to Child
|
|---|
| 555 | 0a22ff80 77e56caf 0a22ffa8 77e56ad1 00143240 ntdll!KiFastSystemCallRet
|
|---|
| 556 | 0a22ff88 77e56ad1 00143240 003d0178 00000000 RPCRT4!I_RpcBCacheFree+0x61c
|
|---|
| 557 | 0a22ffa8 77e56c97 00153588 0a22ffec 7c80b729 RPCRT4!I_RpcBCacheFree+0x43e
|
|---|
| 558 | 0a22ffb4 7c80b729 00170870 003d0178 00000000 RPCRT4!I_RpcBCacheFree+0x604
|
|---|
| 559 | 0a22ffec 00000000 77e56c7d 00170870 00000000 kernel32!GetModuleFileNameA+0x1ba
|
|---|
| 560 |
|
|---|
| 561 | *----> Vidage brut de la pile <----*
|
|---|
| 562 | 000000000a22fe18 aa da 91 7c e3 65 e5 77 - e4 0d 00 00 74 ff 22 0a ...|.e.w....t.".
|
|---|
| 563 | 000000000a22fe28 00 00 00 00 e8 c8 34 0d - 50 ff 22 0a 00 90 fd 7f ......4.P.".....
|
|---|
| 564 | 000000000a22fe38 2c 00 44 00 00 00 38 00 - 70 05 00 00 9c 0c 00 00 ,.D...8.p.......
|
|---|
| 565 | 000000000a22fe48 00 00 00 00 00 00 00 00 - 02 00 00 00 04 00 3f c0 ..............?.
|
|---|
| 566 | 000000000a22fe58 00 00 00 00 00 00 00 00 - f8 1f 60 c0 04 dc 5a 9a ..........`...Z.
|
|---|
| 567 | 000000000a22fe68 2a 40 52 80 8e 00 00 00 - 01 00 00 00 08 90 2d 41 *@R...........-A
|
|---|
| 568 | 000000000a22fe78 f4 7c 01 00 0c 00 00 00 - 18 00 00 00 0c 00 00 00 .|..............
|
|---|
| 569 | 000000000a22fe88 30 00 38 00 30 00 30 00 - 32 00 37 00 44 00 30 00 0.8.0.0.2.7.D.0.
|
|---|
| 570 | 000000000a22fe98 42 00 30 00 30 00 31 00 - 69 ae 7e 6f dd cb d9 12 B.0.0.1.i.~o....
|
|---|
| 571 | 000000000a22fea8 55 73 65 72 00 00 00 00 - 00 00 00 00 00 00 00 00 User............
|
|---|
| 572 | 000000000a22feb8 00 00 00 00 24 db 5a 9a - 01 00 00 00 ff ff ff ff ....$.Z.........
|
|---|
| 573 | 000000000a22fec8 00 90 fd 7f 68 9e 4d 80 - ff ff ff ff 7e 36 5b 80 ....h.M.....~6[.
|
|---|
| 574 | 000000000a22fed8 7c 16 54 80 ff ff ff ff - a4 dc 5a 9a a8 dc 5a 9a |.T.......Z...Z.
|
|---|
| 575 | 000000000a22fee8 00 80 00 00 e8 dc 5a 9a - c9 03 50 80 00 0d db ba ......Z...P.....
|
|---|
| 576 | 000000000a22fef8 44 dc 5a 9a 10 ba 81 89 - 20 dc 5a 9a 00 57 4f 8a D.Z..... .Z..WO.
|
|---|
| 577 | 000000000a22ff08 ed b6 54 80 80 41 c8 88 - 58 da 26 89 24 db 26 89 ..T..A..X.&.$.&.
|
|---|
| 578 | 000000000a22ff18 38 05 33 ba 34 59 54 80 - 00 0a 4e 88 b4 b1 4f 80 8.3.4YT...N...O.
|
|---|
| 579 | 000000000a22ff28 c4 0b 4e 88 80 ff 22 0a - 85 d1 e5 77 48 ff 22 0a ..N..."....wH.".
|
|---|
| 580 | 000000000a22ff38 95 d1 e5 77 e0 10 91 7c - d0 64 18 00 70 08 17 00 ...w...|.d..p...
|
|---|
| 581 | 000000000a22ff48 00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff ../M.....]......
|
|---|
| 582 |
|
|---|
| 583 | *----> Vidage de l'état de la thread 0x3fc <----*
|
|---|
| 584 |
|
|---|
| 585 | eax=00000001 ebx=000493e0 ecx=775c7a18 edx=7c91e514 esi=00000c74 edi=00000000
|
|---|
| 586 | eip=7c91e514 esp=0a62fed8 ebp=0a62ff3c iopl=0 nv up ei ng nz ac po cy
|
|---|
| 587 | cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000297
|
|---|
| 588 |
|
|---|
| 589 | fonction : ntdll!KiFastSystemCallRet
|
|---|
| 590 | 7c91e4fa e829000000 call ntdll!RtlRaiseException (7c91e528)
|
|---|
| 591 | 7c91e4ff 8b0424 mov eax,[esp]
|
|---|
| 592 | 7c91e502 8be5 mov esp,ebp
|
|---|
| 593 | 7c91e504 5d pop ebp
|
|---|
| 594 | 7c91e505 c3 ret
|
|---|
| 595 | 7c91e506 8da42400000000 lea esp,[esp]
|
|---|
| 596 | 7c91e50d 8d4900 lea ecx,[ecx]
|
|---|
| 597 | ntdll!KiFastSystemCall:
|
|---|
| 598 | 7c91e510 8bd4 mov edx,esp
|
|---|
| 599 | 7c91e512 0f34 sysenter
|
|---|
| 600 | ntdll!KiFastSystemCallRet:
|
|---|
| 601 | 7c91e514 c3 ret
|
|---|
| 602 | 7c91e515 8da42400000000 lea esp,[esp]
|
|---|
| 603 | 7c91e51c 8d642400 lea esp,[esp]
|
|---|
| 604 | ntdll!KiIntSystemCall:
|
|---|
| 605 | 7c91e520 8d542408 lea edx,[esp+0x8]
|
|---|
| 606 | 7c91e524 cd2e int 2e
|
|---|
| 607 | 7c91e526 c3 ret
|
|---|
| 608 | 7c91e527 90 nop
|
|---|
| 609 | ntdll!RtlRaiseException:
|
|---|
| 610 | 7c91e528 55 push ebp
|
|---|
| 611 | 7c91e529 8bec mov ebp,esp
|
|---|
| 612 |
|
|---|
| 613 | *----> Suivi arrière de la pile <----*
|
|---|
| 614 | WARNING: Stack unwind information not available. Following frames may be wrong.
|
|---|
| 615 | ChildEBP RetAddr Args to Child
|
|---|
| 616 | 0a62ff3c 7c802542 00000c74 000493e0 00000000 ntdll!KiFastSystemCallRet
|
|---|
| 617 | 0a62ff50 77556c92 00000c74 000493e0 00000000 kernel32!WaitForSingleObject+0x12
|
|---|
| 618 | 0a62ff6c 77527089 00000c74 00007530 7c802550 ole32!CoInstall+0x10b
|
|---|
| 619 | 0a62ff8c 774e63ac 0a62ffb4 774be492 775c7a18 ole32!CoWaitForMultipleHandles+0xff10
|
|---|
| 620 | 0a62ff94 774be492 775c7a18 0041002d 001931d8 ole32!CoGetObject+0x1776
|
|---|
| 621 | 0a62ffb4 7c80b729 001931d8 0041002d 00380033 ole32!StringFromGUID2+0x5dc
|
|---|
| 622 | 0a62ffec 00000000 774be4df 001931d8 00000000 kernel32!GetModuleFileNameA+0x1ba
|
|---|
| 623 |
|
|---|
| 624 | *----> Vidage brut de la pile <----*
|
|---|
| 625 | 000000000a62fed8 5a df 91 7c db 25 80 7c - 74 0c 00 00 00 00 00 00 Z..|.%.|t.......
|
|---|
| 626 | 000000000a62fee8 0c ff 62 0a 00 00 00 00 - 30 25 80 7c e0 93 04 00 ..b.....0%.|....
|
|---|
| 627 | 000000000a62fef8 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 628 | 000000000a62ff08 10 00 00 00 00 a2 2f 4d - ff ff ff ff 00 80 fd 7f ....../M........
|
|---|
| 629 | 000000000a62ff18 00 70 fd 7f 0c ff 62 0a - 40 ff 62 0a ec fe 62 0a .p....b.@.b...b.
|
|---|
| 630 | 000000000a62ff28 97 d1 4b 77 dc ff 62 0a - d8 9a 83 7c 08 26 80 7c ..Kw..b....|.&.|
|
|---|
| 631 | 000000000a62ff38 00 00 00 00 50 ff 62 0a - 42 25 80 7c 74 0c 00 00 ....P.b.B%.|t...
|
|---|
| 632 | 000000000a62ff48 e0 93 04 00 00 00 00 00 - 6c ff 62 0a 92 6c 55 77 ........l.b..lUw
|
|---|
| 633 | 000000000a62ff58 74 0c 00 00 e0 93 04 00 - 00 00 00 00 18 7a 5c 77 t............z\w
|
|---|
| 634 | 000000000a62ff68 74 0c 00 00 8c ff 62 0a - 89 70 52 77 74 0c 00 00 t.....b..pRwt...
|
|---|
| 635 | 000000000a62ff78 30 75 00 00 50 25 80 7c - d8 31 19 00 80 0c 00 00 0u..P%.|.1......
|
|---|
| 636 | 000000000a62ff88 08 33 18 00 94 ff 62 0a - ac 63 4e 77 b4 ff 62 0a .3....b..cNw..b.
|
|---|
| 637 | 000000000a62ff98 92 e4 4b 77 18 7a 5c 77 - 2d 00 41 00 d8 31 19 00 ..Kw.z\w-.A..1..
|
|---|
| 638 | 000000000a62ffa8 00 00 4a 77 fa e4 4b 77 - 33 00 38 00 ec ff 62 0a ..Jw..Kw3.8...b.
|
|---|
| 639 | 000000000a62ffb8 29 b7 80 7c d8 31 19 00 - 2d 00 41 00 33 00 38 00 )..|.1..-.A.3.8.
|
|---|
| 640 | 000000000a62ffc8 d8 31 19 00 00 70 fd 7f - 00 76 4f 8a c0 ff 62 0a .1...p...vO...b.
|
|---|
| 641 | 000000000a62ffd8 58 7e 2a 89 ff ff ff ff - d8 9a 83 7c 30 b7 80 7c X~*........|0..|
|
|---|
| 642 | 000000000a62ffe8 00 00 00 00 00 00 00 00 - 00 00 00 00 df e4 4b 77 ..............Kw
|
|---|
| 643 | 000000000a62fff8 d8 31 19 00 00 00 00 00 - 2f 12 62 e7 00 00 00 00 .1....../.b.....
|
|---|
| 644 | 000000000a630008 2f 22 62 e7 00 00 00 00 - 2f 32 62 e7 00 00 00 00 /"b...../2b.....
|
|---|
| 645 |
|
|---|
| 646 | *----> Vidage de l'état de la thread 0xf94 <----*
|
|---|
| 647 |
|
|---|
| 648 | eax=77dc848a ebx=0ac5fed0 ecx=00000000 edx=00000011 esi=00000000 edi=7ffd8000
|
|---|
| 649 | eip=7c91e514 esp=0ac5fea8 ebp=0ac5ff44 iopl=0 nv up ei pl zr na po nc
|
|---|
| 650 | cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
|
|---|
| 651 |
|
|---|
| 652 | fonction : ntdll!KiFastSystemCallRet
|
|---|
| 653 | 7c91e4fa e829000000 call ntdll!RtlRaiseException (7c91e528)
|
|---|
| 654 | 7c91e4ff 8b0424 mov eax,[esp]
|
|---|
| 655 | 7c91e502 8be5 mov esp,ebp
|
|---|
| 656 | 7c91e504 5d pop ebp
|
|---|
| 657 | 7c91e505 c3 ret
|
|---|
| 658 | 7c91e506 8da42400000000 lea esp,[esp]
|
|---|
| 659 | 7c91e50d 8d4900 lea ecx,[ecx]
|
|---|
| 660 | ntdll!KiFastSystemCall:
|
|---|
| 661 | 7c91e510 8bd4 mov edx,esp
|
|---|
| 662 | 7c91e512 0f34 sysenter
|
|---|
| 663 | ntdll!KiFastSystemCallRet:
|
|---|
| 664 | 7c91e514 c3 ret
|
|---|
| 665 | 7c91e515 8da42400000000 lea esp,[esp]
|
|---|
| 666 | 7c91e51c 8d642400 lea esp,[esp]
|
|---|
| 667 | ntdll!KiIntSystemCall:
|
|---|
| 668 | 7c91e520 8d542408 lea edx,[esp+0x8]
|
|---|
| 669 | 7c91e524 cd2e int 2e
|
|---|
| 670 | 7c91e526 c3 ret
|
|---|
| 671 | 7c91e527 90 nop
|
|---|
| 672 | ntdll!RtlRaiseException:
|
|---|
| 673 | 7c91e528 55 push ebp
|
|---|
| 674 | 7c91e529 8bec mov ebp,esp
|
|---|
| 675 |
|
|---|
| 676 | *----> Suivi arrière de la pile <----*
|
|---|
| 677 | *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINNT\system32\ADVAPI32.dll -
|
|---|
| 678 | WARNING: Stack unwind information not available. Following frames may be wrong.
|
|---|
| 679 | ChildEBP RetAddr Args to Child
|
|---|
| 680 | 0ac5ff44 77dc8631 00000002 0ac5ff6c 00000000 ntdll!KiFastSystemCallRet
|
|---|
| 681 | 0ac5ffb4 7c80b729 00000000 00000000 77dc8ae4 ADVAPI32!WmiFreeBuffer+0x24e
|
|---|
| 682 | 0ac5ffec 00000000 77dc848a 00000000 00000000 kernel32!GetModuleFileNameA+0x1ba
|
|---|
| 683 |
|
|---|
| 684 | *----> Vidage brut de la pile <----*
|
|---|
| 685 | 000000000ac5fea8 4a df 91 7c 90 95 80 7c - 02 00 00 00 d0 fe c5 0a J..|...|........
|
|---|
| 686 | 000000000ac5feb8 01 00 00 00 01 00 00 00 - 04 ff c5 0a e0 2e a6 0a ................
|
|---|
| 687 | 000000000ac5fec8 60 66 e1 77 00 10 00 00 - e4 0b 00 00 d8 0b 00 00 `f.w............
|
|---|
| 688 | 000000000ac5fed8 c0 fe c5 0a 93 d8 5b 80 - dc ff c5 0a d8 9a 83 7c ......[........|
|
|---|
| 689 | 000000000ac5fee8 50 0b 81 7c 00 10 00 00 - 14 00 00 00 01 00 00 00 P..|............
|
|---|
| 690 | 000000000ac5fef8 b0 27 18 00 00 00 00 00 - 00 00 00 00 00 a2 2f 4d .'............/M
|
|---|
| 691 | 000000000ac5ff08 ff ff ff ff 00 10 00 00 - 00 80 fd 7f 00 40 fd 7f .............@..
|
|---|
| 692 | 000000000ac5ff18 dc ff c5 0a 04 ff c5 0a - d0 fe c5 0a 06 00 00 00 ................
|
|---|
| 693 | 000000000ac5ff28 02 00 00 00 c4 fe c5 0a - 06 00 00 00 dc ff c5 0a ................
|
|---|
| 694 | 000000000ac5ff38 d8 9a 83 7c 80 96 80 7c - 00 00 00 00 b4 ff c5 0a ...|...|........
|
|---|
| 695 | 000000000ac5ff48 31 86 dc 77 02 00 00 00 - 6c ff c5 0a 00 00 00 00 1..w....l.......
|
|---|
| 696 | 000000000ac5ff58 e0 93 04 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 697 | 000000000ac5ff68 e4 8a dc 77 e4 0b 00 00 - d8 0b 00 00 00 10 00 00 ...w............
|
|---|
| 698 | 000000000ac5ff78 e0 2e a6 0a 00 00 00 00 - 00 10 00 00 e8 3e a6 0a .............>..
|
|---|
| 699 | 000000000ac5ff88 00 67 e1 77 40 00 00 00 - e0 66 e1 77 00 10 00 00 .g.w@....f.w....
|
|---|
| 700 | 000000000ac5ff98 00 00 00 00 00 67 e1 77 - e0 2e a6 0a e0 66 e1 77 .....g.w.....f.w
|
|---|
| 701 | 000000000ac5ffa8 e5 03 00 00 00 10 00 00 - e8 3e a6 0a ec ff c5 0a .........>......
|
|---|
| 702 | 000000000ac5ffb8 29 b7 80 7c 00 00 00 00 - 00 00 00 00 e4 8a dc 77 )..|...........w
|
|---|
| 703 | 000000000ac5ffc8 00 00 00 00 00 40 fd 7f - 00 56 4f 8a c0 ff c5 0a .....@...VO.....
|
|---|
| 704 | 000000000ac5ffd8 30 d1 bb 88 ff ff ff ff - d8 9a 83 7c 30 b7 80 7c 0..........|0..|
|
|---|
| 705 |
|
|---|
| 706 | *----> Vidage de l'état de la thread 0xd78 <----*
|
|---|
| 707 |
|
|---|
| 708 | eax=001a370c ebx=001868f8 ecx=774a2338 edx=00000000 esi=00186944 edi=00170a20
|
|---|
| 709 | eip=7c91e514 esp=0a32f75c ebp=0a32f7a8 iopl=0 nv up ei pl nz na po nc
|
|---|
| 710 | cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000206
|
|---|
| 711 |
|
|---|
| 712 | fonction : ntdll!KiFastSystemCallRet
|
|---|
| 713 | 7c91e4fa e829000000 call ntdll!RtlRaiseException (7c91e528)
|
|---|
| 714 | 7c91e4ff 8b0424 mov eax,[esp]
|
|---|
| 715 | 7c91e502 8be5 mov esp,ebp
|
|---|
| 716 | 7c91e504 5d pop ebp
|
|---|
| 717 | 7c91e505 c3 ret
|
|---|
| 718 | 7c91e506 8da42400000000 lea esp,[esp]
|
|---|
| 719 | 7c91e50d 8d4900 lea ecx,[ecx]
|
|---|
| 720 | ntdll!KiFastSystemCall:
|
|---|
| 721 | 7c91e510 8bd4 mov edx,esp
|
|---|
| 722 | 7c91e512 0f34 sysenter
|
|---|
| 723 | ntdll!KiFastSystemCallRet:
|
|---|
| 724 | 7c91e514 c3 ret
|
|---|
| 725 | 7c91e515 8da42400000000 lea esp,[esp]
|
|---|
| 726 | 7c91e51c 8d642400 lea esp,[esp]
|
|---|
| 727 | ntdll!KiIntSystemCall:
|
|---|
| 728 | 7c91e520 8d542408 lea edx,[esp+0x8]
|
|---|
| 729 | 7c91e524 cd2e int 2e
|
|---|
| 730 | 7c91e526 c3 ret
|
|---|
| 731 | 7c91e527 90 nop
|
|---|
| 732 | ntdll!RtlRaiseException:
|
|---|
| 733 | 7c91e528 55 push ebp
|
|---|
| 734 | 7c91e529 8bec mov ebp,esp
|
|---|
| 735 |
|
|---|
| 736 | *----> Suivi arrière de la pile <----*
|
|---|
| 737 | WARNING: Stack unwind information not available. Following frames may be wrong.
|
|---|
| 738 | *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\Program Files\Oracle\VirtualBox\VBoxC.dll -
|
|---|
| 739 | *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\Program Files\Oracle\VirtualBox\VBoxRT.dll -
|
|---|
| 740 | *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\Program Files\Oracle\VirtualBox\MSVCR100.dll -
|
|---|
| 741 | ChildEBP RetAddr Args to Child
|
|---|
| 742 | 0a32f7a8 77e5a80e 0015f0d0 0a32f7d0 775c26bb ntdll!KiFastSystemCallRet
|
|---|
| 743 | 0a32f7b4 775c26bb 00170a20 001a370c 0a32f8b4 RPCRT4!I_RpcSendReceive+0x23
|
|---|
| 744 | 0a32f7d0 775c21a6 00000000 00000000 00000000 ole32!StgGetIFillLockBytesOnFile+0x114db
|
|---|
| 745 | 0a32f7ec 775c208a 0a32f8b4 0a32f9c4 001a370c ole32!StgGetIFillLockBytesOnFile+0x10fc6
|
|---|
| 746 | 0a32f8cc 774ec962 001a370c 0a32f9c4 0a32f9b4 ole32!StgGetIFillLockBytesOnFile+0x10eaa
|
|---|
| 747 | 0a32f938 774ec8fa 001a370c 0a32f9c4 0a32f9b4 ole32!ReleaseStgMedium+0x12e7
|
|---|
| 748 | 0a32f98c 77ed5db5 001a370c 0a32f9c4 0a32f9b4 ole32!ReleaseStgMedium+0x127f
|
|---|
| 749 | 0a32f9a8 77ed5ead 001bb80c 0a32f9f0 0300002c RPCRT4!NdrProxySendReceive+0x40
|
|---|
| 750 | 0a32fd8c 77ed5e42 001c9020 001c95c2 0a32fdc4 RPCRT4!NdrProxySendReceive+0x138
|
|---|
| 751 | 0a32fdac 77e68519 00000048 00000021 0a32fed8 RPCRT4!NdrProxySendReceive+0xcd
|
|---|
| 752 | 0a32fdbc 0a8b436c 001bb80c 03000000 00000000 RPCRT4!CreateStubFromTypeInfo+0x11c
|
|---|
| 753 | 0a32fed8 0a8b4e43 00000032 00000000 0a32ff24 VBoxC+0x8436c
|
|---|
| 754 | 0a32fee8 00b39015 0957a670 095061b0 00000032 VBoxC+0x84e43
|
|---|
| 755 | 0a32ff24 00b11523 0957d7a8 0957a670 0957d7a8 VBoxRT!RTTimerLRChangeInterval+0x1a5
|
|---|
| 756 | 0a32ff50 00b5517b 0957d7a8 00000d78 0957dd24 VBoxRT!RTThreadFromNative+0x1e3
|
|---|
| 757 | 0a32ff70 78afc556 0957d7a8 784bb953 0950836c VBoxRT!RTSymlinkRead+0x2eb
|
|---|
| 758 | 0a32ffa8 78afc600 00000000 0a32ffec 7c80b729 MSVCR100!endthreadex+0x3a
|
|---|
| 759 | 0a32ffb4 7c80b729 09570f20 0950836c 00000000 MSVCR100!endthreadex+0xe4
|
|---|
| 760 | 0a32ffec 00000000 78afc59c 09570f20 00000000 kernel32!GetModuleFileNameA+0x1ba
|
|---|
| 761 |
|
|---|
| 762 | *----> Vidage brut de la pile <----*
|
|---|
| 763 | 000000000a32f75c ea da 91 7c 72 c6 e5 77 - b4 0d 00 00 98 f0 15 00 ...|r..w........
|
|---|
| 764 | 000000000a32f76c 98 f0 15 00 00 00 00 00 - c8 09 17 00 20 0a 17 00 ............ ...
|
|---|
| 765 | 000000000a32f77c a8 f7 32 0a a8 0a 17 00 - 00 00 00 00 00 00 00 00 ..2.............
|
|---|
| 766 | 000000000a32f78c 34 bf e5 77 ca d1 4b 77 - 68 82 5c 77 97 d1 4b 77 4..w..Kwh.\w..Kw
|
|---|
| 767 | 000000000a32f79c 68 82 5c 77 dd 4d 4d 77 - 00 00 00 00 b4 f7 32 0a h.\w.MMw......2.
|
|---|
| 768 | 000000000a32f7ac 0e a8 e5 77 d0 f0 15 00 - d0 f7 32 0a bb 26 5c 77 ...w......2..&\w
|
|---|
| 769 | 000000000a32f7bc 20 0a 17 00 0c 37 1a 00 - b4 f8 32 0a c8 09 17 00 ....7....2.....
|
|---|
| 770 | 000000000a32f7cc 0c 37 1a 00 ec f7 32 0a - a6 21 5c 77 00 00 00 00 .7....2..!\w....
|
|---|
| 771 | 000000000a32f7dc 00 00 00 00 00 00 00 00 - 0c 37 1a 00 0c 37 1a 00 .........7...7..
|
|---|
| 772 | 000000000a32f7ec cc f8 32 0a 8a 20 5c 77 - b4 f8 32 0a c4 f9 32 0a ..2.. \w..2...2.
|
|---|
| 773 | 000000000a32f7fc 0c 37 1a 00 b4 f9 32 0a - 01 00 00 00 20 12 17 00 .7....2..... ...
|
|---|
| 774 | 000000000a32f80c 48 9f 17 00 78 f8 32 0a - a8 bb e5 77 c8 61 18 00 H...x.2....w.a..
|
|---|
| 775 | 000000000a32f81c 98 f8 32 0a 20 0a 17 00 - 90 c0 1b 00 20 0a 17 00 ..2. ....... ...
|
|---|
| 776 | 000000000a32f82c c8 61 18 00 bf bb e5 77 - 20 0a 17 00 98 f8 32 0a .a.....w .....2.
|
|---|
| 777 | 000000000a32f83c 10 00 00 00 90 c0 1b 00 - 3c 62 18 00 7c 62 18 00 ........<b..|b..
|
|---|
| 778 | 000000000a32f84c 4c 85 e5 77 48 9f 17 00 - 00 00 00 00 00 00 00 00 L..wH...........
|
|---|
| 779 | 000000000a32f85c 00 01 00 00 c8 22 14 00 - 80 f8 32 0a ba a1 4e 77 ....."....2...Nw
|
|---|
| 780 | 000000000a32f86c 00 0a 17 00 c9 4c 4d 77 - 10 53 00 00 a4 f8 32 0a .....LMw.S....2.
|
|---|
| 781 | 000000000a32f87c ba ba e5 77 20 0a 17 00 - f8 68 18 00 a0 f8 32 0a ...w ....h....2.
|
|---|
| 782 | 000000000a32f88c d1 bf e5 77 88 9d 19 00 - 20 0a 17 00 00 00 00 00 ...w.... .......
|
|---|
| 783 |
|
|---|
| 784 | *----> Vidage de l'état de la thread 0xf70 <----*
|
|---|
| 785 |
|
|---|
| 786 | eax=78afc59c ebx=0a22f50c ecx=00000000 edx=00000000 esi=00000b08 edi=00000000
|
|---|
| 787 | eip=7c91e514 esp=0ad9fe90 ebp=0ad9fef4 iopl=0 nv up ei pl zr na po nc
|
|---|
| 788 | cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
|
|---|
| 789 |
|
|---|
| 790 | fonction : ntdll!KiFastSystemCallRet
|
|---|
| 791 | 7c91e4fa e829000000 call ntdll!RtlRaiseException (7c91e528)
|
|---|
| 792 | 7c91e4ff 8b0424 mov eax,[esp]
|
|---|
| 793 | 7c91e502 8be5 mov esp,ebp
|
|---|
| 794 | 7c91e504 5d pop ebp
|
|---|
| 795 | 7c91e505 c3 ret
|
|---|
| 796 | 7c91e506 8da42400000000 lea esp,[esp]
|
|---|
| 797 | 7c91e50d 8d4900 lea ecx,[ecx]
|
|---|
| 798 | ntdll!KiFastSystemCall:
|
|---|
| 799 | 7c91e510 8bd4 mov edx,esp
|
|---|
| 800 | 7c91e512 0f34 sysenter
|
|---|
| 801 | ntdll!KiFastSystemCallRet:
|
|---|
| 802 | 7c91e514 c3 ret
|
|---|
| 803 | 7c91e515 8da42400000000 lea esp,[esp]
|
|---|
| 804 | 7c91e51c 8d642400 lea esp,[esp]
|
|---|
| 805 | ntdll!KiIntSystemCall:
|
|---|
| 806 | 7c91e520 8d542408 lea edx,[esp+0x8]
|
|---|
| 807 | 7c91e524 cd2e int 2e
|
|---|
| 808 | 7c91e526 c3 ret
|
|---|
| 809 | 7c91e527 90 nop
|
|---|
| 810 | ntdll!RtlRaiseException:
|
|---|
| 811 | 7c91e528 55 push ebp
|
|---|
| 812 | 7c91e529 8bec mov ebp,esp
|
|---|
| 813 |
|
|---|
| 814 | *----> Suivi arrière de la pile <----*
|
|---|
| 815 | WARNING: Stack unwind information not available. Following frames may be wrong.
|
|---|
| 816 | ChildEBP RetAddr Args to Child
|
|---|
| 817 | 0ad9fef4 7c802542 00000b08 ffffffff 00000000 ntdll!KiFastSystemCallRet
|
|---|
| 818 | 0ad9ff08 0a8d6618 00000b08 ffffffff 0957e048 kernel32!WaitForSingleObject+0x12
|
|---|
| 819 | 0ad9ff24 00b11523 0957e030 00000b18 0957e030 VBoxC+0xa6618
|
|---|
| 820 | 0ad9ff50 00b5517b 0957e030 00000f70 0957e5ac VBoxRT!RTThreadFromNative+0x1e3
|
|---|
| 821 | 0ad9ff70 78afc556 0957e030 78a0b953 0a336dc0 VBoxRT!RTSymlinkRead+0x2eb
|
|---|
| 822 | 0ad9ffa8 78afc600 0000f101 0ad9ffec 7c80b729 MSVCR100!endthreadex+0x3a
|
|---|
| 823 | 0ad9ffb4 7c80b729 09570f20 0a336dc0 0000f101 MSVCR100!endthreadex+0xe4
|
|---|
| 824 | 0ad9ffec 00000000 78afc59c 09570f20 00000000 kernel32!GetModuleFileNameA+0x1ba
|
|---|
| 825 |
|
|---|
| 826 | *----> Vidage brut de la pile <----*
|
|---|
| 827 | 000000000ad9fe90 5a df 91 7c db 25 80 7c - 08 0b 00 00 00 00 00 00 Z..|.%.|........
|
|---|
| 828 | 000000000ad9fea0 00 00 00 00 08 0b 00 00 - 0c 0b 00 00 0c f5 22 0a ..............".
|
|---|
| 829 | 000000000ad9feb0 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 830 | 000000000ad9fec0 10 00 00 00 00 ff d9 0a - ae a7 80 7c 00 80 fd 7f ...........|....
|
|---|
| 831 | 000000000ad9fed0 00 f0 f4 7f 00 00 00 00 - 0c f5 22 0a a4 fe d9 0a ..........".....
|
|---|
| 832 | 000000000ad9fee0 a8 fe d9 0a 98 ff d9 0a - d8 9a 83 7c 08 26 80 7c ...........|.&.|
|
|---|
| 833 | 000000000ad9fef0 00 00 00 00 08 ff d9 0a - 42 25 80 7c 08 0b 00 00 ........B%.|....
|
|---|
| 834 | 000000000ad9ff00 ff ff ff ff 00 00 00 00 - 24 ff d9 0a 18 66 8d 0a ........$....f..
|
|---|
| 835 | 000000000ad9ff10 08 0b 00 00 ff ff ff ff - 48 e0 57 09 30 e0 57 09 ........H.W.0.W.
|
|---|
| 836 | 000000000ad9ff20 65 9c 80 7c 50 ff d9 0a - 23 15 b1 00 30 e0 57 09 e..|P...#...0.W.
|
|---|
| 837 | 000000000ad9ff30 18 0b 00 00 30 e0 57 09 - 06 00 00 00 30 e0 57 09 ....0.W.....0.W.
|
|---|
| 838 | 000000000ad9ff40 70 0f 00 00 70 0f 00 00 - 30 e0 57 09 65 9c 80 7c p...p...0.W.e..|
|
|---|
| 839 | 000000000ad9ff50 70 ff d9 0a 7b 51 b5 00 - 30 e0 57 09 70 0f 00 00 p...{Q..0.W.p...
|
|---|
| 840 | 000000000ad9ff60 ac e5 57 09 c0 6d 33 0a - 01 f1 00 00 20 0f 57 09 ..W..m3..... .W.
|
|---|
| 841 | 000000000ad9ff70 a8 ff d9 0a 56 c5 af 78 - 30 e0 57 09 53 b9 a0 78 ....V..x0.W.S..x
|
|---|
| 842 | 000000000ad9ff80 c0 6d 33 0a 01 f1 00 00 - 20 0f 57 09 7c ff d9 0a .m3..... .W.|...
|
|---|
| 843 | 000000000ad9ff90 7c ff d9 0a dc ff d9 0a - dc ff d9 0a 5a b6 b2 78 |...........Z..x
|
|---|
| 844 | 000000000ad9ffa0 7b 83 d6 0a 00 00 00 00 - b4 ff d9 0a 00 c6 af 78 {..............x
|
|---|
| 845 | 000000000ad9ffb0 01 f1 00 00 ec ff d9 0a - 29 b7 80 7c 20 0f 57 09 ........)..| .W.
|
|---|
| 846 | 000000000ad9ffc0 c0 6d 33 0a 01 f1 00 00 - 20 0f 57 09 00 f0 f4 7f .m3..... .W.....
|
|---|
| 847 |
|
|---|
| 848 | *----> Vidage de l'état de la thread 0xf24 <----*
|
|---|
| 849 |
|
|---|
| 850 | eax=0a376000 ebx=7c802550 ecx=0b0dfb5c edx=00001000 esi=00000a20 edi=00000000
|
|---|
| 851 | eip=7c91e514 esp=0b0dfdd4 ebp=0b0dfe38 iopl=0 nv up ei pl zr na po nc
|
|---|
| 852 | cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
|
|---|
| 853 |
|
|---|
| 854 | fonction : ntdll!KiFastSystemCallRet
|
|---|
| 855 | 7c91e4fa e829000000 call ntdll!RtlRaiseException (7c91e528)
|
|---|
| 856 | 7c91e4ff 8b0424 mov eax,[esp]
|
|---|
| 857 | 7c91e502 8be5 mov esp,ebp
|
|---|
| 858 | 7c91e504 5d pop ebp
|
|---|
| 859 | 7c91e505 c3 ret
|
|---|
| 860 | 7c91e506 8da42400000000 lea esp,[esp]
|
|---|
| 861 | 7c91e50d 8d4900 lea ecx,[ecx]
|
|---|
| 862 | ntdll!KiFastSystemCall:
|
|---|
| 863 | 7c91e510 8bd4 mov edx,esp
|
|---|
| 864 | 7c91e512 0f34 sysenter
|
|---|
| 865 | ntdll!KiFastSystemCallRet:
|
|---|
| 866 | 7c91e514 c3 ret
|
|---|
| 867 | 7c91e515 8da42400000000 lea esp,[esp]
|
|---|
| 868 | 7c91e51c 8d642400 lea esp,[esp]
|
|---|
| 869 | ntdll!KiIntSystemCall:
|
|---|
| 870 | 7c91e520 8d542408 lea edx,[esp+0x8]
|
|---|
| 871 | 7c91e524 cd2e int 2e
|
|---|
| 872 | 7c91e526 c3 ret
|
|---|
| 873 | 7c91e527 90 nop
|
|---|
| 874 | ntdll!RtlRaiseException:
|
|---|
| 875 | 7c91e528 55 push ebp
|
|---|
| 876 | 7c91e529 8bec mov ebp,esp
|
|---|
| 877 |
|
|---|
| 878 | *----> Suivi arrière de la pile <----*
|
|---|
| 879 | WARNING: Stack unwind information not available. Following frames may be wrong.
|
|---|
| 880 | ChildEBP RetAddr Args to Child
|
|---|
| 881 | 0b0dfe38 00b54365 00000a20 ffffffff 00000001 ntdll!KiFastSystemCallRet
|
|---|
| 882 | 0b0dfe64 00b5444a 0a38d6f8 00000050 00000000 VBoxRT!RTSemEventMultiReset+0x1f5
|
|---|
| 883 | 0b0dfe80 00b4801a 0a38d6f8 00000050 00000000 VBoxRT!RTSemEventMultiWaitEx+0x1a
|
|---|
| 884 | 0b0dfe98 0a9068ee 0a38d6f8 ffffffff 0b0dff00 VBoxRT!RTSemEventMultiWait+0x1a
|
|---|
| 885 | 0b0dfeb8 0a906d27 0b0dff00 00000000 0a378578 VBoxC!VBoxDriversRegister+0x2c09e
|
|---|
| 886 | 0b0dfecc 0a909e8d 80000001 0b0dff00 00000000 VBoxC!VBoxDriversRegister+0x2c4d7
|
|---|
| 887 | 0b0dff08 0a9065a0 80000001 00000000 0a358670 VBoxC!VBoxDriversRegister+0x2f63d
|
|---|
| 888 | 0b0dff24 00b11523 0a358670 0a356870 0a358670 VBoxC!VBoxDriversRegister+0x2bd50
|
|---|
| 889 | 0b0dff50 00b5517b 0a358670 00000f24 0a358bec VBoxRT!RTThreadFromNative+0x1e3
|
|---|
| 890 | 0b0dff70 78afc556 0a358670 7974b953 00000000 VBoxRT!RTSymlinkRead+0x2eb
|
|---|
| 891 | 0b0dffa8 78afc600 09bb0178 0b0dffec 7c80b729 MSVCR100!endthreadex+0x3a
|
|---|
| 892 | 0b0dffb4 7c80b729 09570f20 00000000 09bb0178 MSVCR100!endthreadex+0xe4
|
|---|
| 893 | 0b0dffec 00000000 78afc59c 09570f20 00000000 kernel32!GetModuleFileNameA+0x1ba
|
|---|
| 894 |
|
|---|
| 895 | *----> Vidage brut de la pile <----*
|
|---|
| 896 | 000000000b0dfdd4 5a df 91 7c db 25 80 7c - 20 0a 00 00 01 00 00 00 Z..|.%.| .......
|
|---|
| 897 | 000000000b0dfde4 00 00 00 00 ff ff ff ff - 10 00 00 00 50 25 80 7c ............P%.|
|
|---|
| 898 | 000000000b0dfdf4 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 899 | 000000000b0dfe04 10 00 00 00 74 90 b2 00 - 18 fe 0d 0b 00 80 fd 7f ....t...........
|
|---|
| 900 | 000000000b0dfe14 00 d0 f4 7f 00 00 00 00 - bc e7 98 0a e8 fd 0d 0b ................
|
|---|
| 901 | 000000000b0dfe24 6c 66 40 0a 98 ff 0d 0b - d8 9a 83 7c 08 26 80 7c lf@........|.&.|
|
|---|
| 902 | 000000000b0dfe34 00 00 00 00 64 fe 0d 0b - 65 43 b5 00 20 0a 00 00 ....d...eC.. ...
|
|---|
| 903 | 000000000b0dfe44 ff ff ff ff 01 00 00 00 - 00 80 b4 00 70 68 35 0a ............ph5.
|
|---|
| 904 | 000000000b0dfe54 70 41 b5 00 ff ff ff ff - ff ff ff ff 70 86 35 0a pA..........p.5.
|
|---|
| 905 | 000000000b0dfe64 80 fe 0d 0b 4a 44 b5 00 - f8 d6 38 0a 50 00 00 00 ....JD....8.P...
|
|---|
| 906 | 000000000b0dfe74 00 00 00 00 00 00 00 00 - 00 00 00 00 98 fe 0d 0b ................
|
|---|
| 907 | 000000000b0dfe84 1a 80 b4 00 f8 d6 38 0a - 50 00 00 00 00 00 00 00 ......8.P.......
|
|---|
| 908 | 000000000b0dfe94 00 00 00 00 b8 fe 0d 0b - ee 68 90 0a f8 d6 38 0a .........h....8.
|
|---|
| 909 | 000000000b0dfea4 ff ff ff ff 00 ff 0d 0b - 70 68 35 0a d8 65 40 0a ........ph5..e@.
|
|---|
| 910 | 000000000b0dfeb4 70 68 35 0a cc fe 0d 0b - 27 6d 90 0a 00 ff 0d 0b ph5.....'m......
|
|---|
| 911 | 000000000b0dfec4 00 00 00 00 78 85 37 0a - 08 ff 0d 0b 8d 9e 90 0a ....x.7.........
|
|---|
| 912 | 000000000b0dfed4 01 00 00 80 00 ff 0d 0b - 00 00 00 00 70 68 35 0a ............ph5.
|
|---|
| 913 | 000000000b0dfee4 65 9c 80 7c 00 00 00 00 - 70 6e 37 0a d8 65 40 0a e..|....pn7..e@.
|
|---|
| 914 | 000000000b0dfef4 60 79 37 0a 78 85 37 0a - 78 85 37 0a d8 eb 86 29 `y7.x.7.x.7....)
|
|---|
| 915 | 000000000b0dff04 65 9c 80 00 24 ff 0d 0b - a0 65 90 0a 01 00 00 80 e...$....e......
|
|---|
| 916 |
|
|---|
| 917 | *----> Vidage de l'état de la thread 0x668 <----*
|
|---|
| 918 |
|
|---|
| 919 | eax=00000000 ebx=00000000 ecx=0ecec2f0 edx=000040f0 esi=73eb6050 edi=73eb6050
|
|---|
| 920 | eip=7c91e514 esp=0b1dfbf0 ebp=0b1dfc50 iopl=0 nv up ei pl nz na po nc
|
|---|
| 921 | cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00200206
|
|---|
| 922 |
|
|---|
| 923 | fonction : ntdll!KiFastSystemCallRet
|
|---|
| 924 | 7c91e4fa e829000000 call ntdll!RtlRaiseException (7c91e528)
|
|---|
| 925 | 7c91e4ff 8b0424 mov eax,[esp]
|
|---|
| 926 | 7c91e502 8be5 mov esp,ebp
|
|---|
| 927 | 7c91e504 5d pop ebp
|
|---|
| 928 | 7c91e505 c3 ret
|
|---|
| 929 | 7c91e506 8da42400000000 lea esp,[esp]
|
|---|
| 930 | 7c91e50d 8d4900 lea ecx,[ecx]
|
|---|
| 931 | ntdll!KiFastSystemCall:
|
|---|
| 932 | 7c91e510 8bd4 mov edx,esp
|
|---|
| 933 | 7c91e512 0f34 sysenter
|
|---|
| 934 | ntdll!KiFastSystemCallRet:
|
|---|
| 935 | 7c91e514 c3 ret
|
|---|
| 936 | 7c91e515 8da42400000000 lea esp,[esp]
|
|---|
| 937 | 7c91e51c 8d642400 lea esp,[esp]
|
|---|
| 938 | ntdll!KiIntSystemCall:
|
|---|
| 939 | 7c91e520 8d542408 lea edx,[esp+0x8]
|
|---|
| 940 | 7c91e524 cd2e int 2e
|
|---|
| 941 | 7c91e526 c3 ret
|
|---|
| 942 | 7c91e527 90 nop
|
|---|
| 943 | ntdll!RtlRaiseException:
|
|---|
| 944 | 7c91e528 55 push ebp
|
|---|
| 945 | 7c91e529 8bec mov ebp,esp
|
|---|
| 946 |
|
|---|
| 947 | *----> Suivi arrière de la pile <----*
|
|---|
| 948 | *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINNT\system32\dsound.dll -
|
|---|
| 949 | WARNING: Stack unwind information not available. Following frames may be wrong.
|
|---|
| 950 | *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\Program Files\Oracle\VirtualBox\VBoxDD.DLL -
|
|---|
| 951 | *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\Program Files\Oracle\VirtualBox\VBoxVMM.dll -
|
|---|
| 952 | ChildEBP RetAddr Args to Child
|
|---|
| 953 | 0b1dfc50 73e621a2 00000390 002f0003 0b1dfcb8 ntdll!KiFastSystemCallRet
|
|---|
| 954 | 0b1dfc88 73e62bf4 00000390 002f0003 0b1dfcb8 dsound+0x21a2
|
|---|
| 955 | 0b1dfcd0 73e9fa72 00000390 73e62ba0 00000005 dsound+0x2bf4
|
|---|
| 956 | 0b1dfd0c 73e8a287 0b1dfd28 0b1dfd24 00000000 dsound+0x3fa72
|
|---|
| 957 | 0b1dfd2c 73e8af97 0b1dfd80 00000000 0eca90a0 dsound!DirectSoundCaptureEnumerateW+0x31a3
|
|---|
| 958 | 0b1dfd40 0f5361ca 22c29e48 0b1dfd80 00000000 dsound!DirectSoundCaptureEnumerateW+0x3eb3
|
|---|
| 959 | 0b1dfd78 0f4cd5d3 0eca90a0 0d826510 80000372 VBoxDD+0xc61ca
|
|---|
| 960 | 0b1dfda4 0f4c94cb 0eca90a0 0d826510 0f6563e8 VBoxDD+0x5d5d3
|
|---|
| 961 | 0b1dfdc4 0f4c97d3 0f6563e8 0f6563e8 0d824860 VBoxDD+0x594cb
|
|---|
| 962 | 0b1dfdd8 1007097e 0ec65bb8 0d824860 0f6563e8 VBoxDD+0x597d3
|
|---|
| 963 | 0b1dfe08 10073a70 0b330000 0d802c30 27e52c3f VBoxVMM!TMR3TimerDestroy+0xfee
|
|---|
| 964 | 0b1dfe40 1007a363 0b330000 0b34b000 0a35fca0 VBoxVMM!TMR3TimerQueuesDo+0x100
|
|---|
| 965 | 0b1dfe98 1007aa9d 0a35fc00 00000207 8051069d VBoxVMM!VMR3Create+0xeb3
|
|---|
| 966 | 0b1dfec4 10020db8 0b330000 0b34b000 00000207 VBoxVMM!VMR3WaitHalted+0xfd
|
|---|
| 967 | 0b1dfef0 1007b2ba 0b330000 0b34b000 0a36ccb0 VBoxVMM!EMR3ExecuteVM+0x2e8
|
|---|
| 968 | 0b1dff10 1007b304 0a36cc98 0a35fca0 00000000 VBoxVMM!VMR3WaitU+0x7da
|
|---|
| 969 | 0b1dff24 00b11523 0a36cc98 0a35fca0 0a36cc98 VBoxVMM!VMR3WaitU+0x824
|
|---|
| 970 | 0b1dff50 00b5517b 0a36cc98 00000668 0a36d214 VBoxRT!RTThreadFromNative+0x1e3
|
|---|
| 971 | 0b1dff70 78afc556 0a36cc98 7964b953 0afdf9d8 VBoxRT!RTSymlinkRead+0x2eb
|
|---|
| 972 | 0b1dffa8 78afc600 774ecde9 0b1dffec 7c80b729 MSVCR100!endthreadex+0x3a
|
|---|
| 973 | 0b1dffb4 7c80b729 09570f20 0afdf9d8 774ecde9 MSVCR100!endthreadex+0xe4
|
|---|
| 974 | 0b1dffec 00000000 78afc59c 09570f20 00000000 kernel32!GetModuleFileNameA+0x1ba
|
|---|
| 975 |
|
|---|
| 976 | *----> Vidage brut de la pile <----*
|
|---|
| 977 | 000000000b1dfbf0 8a d2 91 7c c2 16 80 7c - 90 03 00 00 fc 05 00 00 ...|...|........
|
|---|
| 978 | 000000000b1dfc00 00 00 00 00 50 60 eb 73 - 50 60 eb 73 03 00 2f 00 ....P`.sP`.s../.
|
|---|
| 979 | 000000000b1dfc10 b8 fc 1d 0b 18 00 00 00 - fc fc 1d 0b 10 00 00 00 ................
|
|---|
| 980 | 000000000b1dfc20 50 60 eb 73 50 60 eb 73 - a8 fc 1d 0b 00 0b 81 0d P`.sP`.s........
|
|---|
| 981 | 000000000b1dfc30 80 74 33 0b 15 00 00 00 - 20 fc 1d 0b 6a d8 09 10 .t3..... ...j...
|
|---|
| 982 | 000000000b1dfc40 98 ff 1d 0b d8 9a 83 7c - 50 0b 81 7c ff ff ff ff .......|P..|....
|
|---|
| 983 | 000000000b1dfc50 88 fc 1d 0b a2 21 e6 73 - 90 03 00 00 03 00 2f 00 .....!.s....../.
|
|---|
| 984 | 000000000b1dfc60 b8 fc 1d 0b 18 00 00 00 - fc fc 1d 0b 10 00 00 00 ................
|
|---|
| 985 | 000000000b1dfc70 a8 fc 1d 0b 50 60 eb 73 - c8 fc 1d 0b b0 2b e6 73 ....P`.s.....+.s
|
|---|
| 986 | 000000000b1dfc80 90 1b 00 00 00 00 00 00 - d0 fc 1d 0b f4 2b e6 73 .............+.s
|
|---|
| 987 | 000000000b1dfc90 90 03 00 00 03 00 2f 00 - b8 fc 1d 0b 18 00 00 00 ....../.........
|
|---|
| 988 | 000000000b1dfca0 fc fc 1d 0b 10 00 00 00 - ff ff ff ff 00 00 00 00 ................
|
|---|
| 989 | 000000000b1dfcb0 00 00 00 00 68 9a c2 22 - a0 aa ff 45 1b 6e d0 11 ....h.."...E.n..
|
|---|
| 990 | 000000000b1dfcc0 bc f2 44 45 53 54 00 00 - 05 00 00 00 01 00 00 00 ..DEST..........
|
|---|
| 991 | 000000000b1dfcd0 0c fd 1d 0b 72 fa e9 73 - 90 03 00 00 a0 2b e6 73 ....r..s.....+.s
|
|---|
| 992 | 000000000b1dfce0 05 00 00 00 fc fc 1d 0b - 10 00 00 00 00 00 00 00 ................
|
|---|
| 993 | 000000000b1dfcf0 02 00 00 00 48 9e c2 22 - 18 26 b1 22 90 1b 05 00 ....H..".&."....
|
|---|
| 994 | 000000000b1dfd00 00 00 00 00 90 de 04 00 - 00 00 00 00 2c fd 1d 0b ............,...
|
|---|
| 995 | 000000000b1dfd10 87 a2 e8 73 28 fd 1d 0b - 24 fd 1d 0b 00 00 00 00 ...s(...$.......
|
|---|
| 996 | 000000000b1dfd20 02 00 00 00 18 26 b1 22 - 18 26 b1 22 40 fd 1d 0b .....&.".&."@...
|
|---|
| 997 |
|
|---|
| 998 | *----> Vidage de l'état de la thread 0xf48 <----*
|
|---|
| 999 |
|
|---|
| 1000 | eax=0158c2f8 ebx=7c802550 ecx=0b46601c edx=00008498 esi=00000974 edi=00000000
|
|---|
| 1001 | eip=7c91e514 esp=0b45fde8 ebp=0b45fe4c iopl=0 nv up ei pl zr na po nc
|
|---|
| 1002 | cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
|
|---|
| 1003 |
|
|---|
| 1004 | fonction : ntdll!KiFastSystemCallRet
|
|---|
| 1005 | 7c91e4fa e829000000 call ntdll!RtlRaiseException (7c91e528)
|
|---|
| 1006 | 7c91e4ff 8b0424 mov eax,[esp]
|
|---|
| 1007 | 7c91e502 8be5 mov esp,ebp
|
|---|
| 1008 | 7c91e504 5d pop ebp
|
|---|
| 1009 | 7c91e505 c3 ret
|
|---|
| 1010 | 7c91e506 8da42400000000 lea esp,[esp]
|
|---|
| 1011 | 7c91e50d 8d4900 lea ecx,[ecx]
|
|---|
| 1012 | ntdll!KiFastSystemCall:
|
|---|
| 1013 | 7c91e510 8bd4 mov edx,esp
|
|---|
| 1014 | 7c91e512 0f34 sysenter
|
|---|
| 1015 | ntdll!KiFastSystemCallRet:
|
|---|
| 1016 | 7c91e514 c3 ret
|
|---|
| 1017 | 7c91e515 8da42400000000 lea esp,[esp]
|
|---|
| 1018 | 7c91e51c 8d642400 lea esp,[esp]
|
|---|
| 1019 | ntdll!KiIntSystemCall:
|
|---|
| 1020 | 7c91e520 8d542408 lea edx,[esp+0x8]
|
|---|
| 1021 | 7c91e524 cd2e int 2e
|
|---|
| 1022 | 7c91e526 c3 ret
|
|---|
| 1023 | 7c91e527 90 nop
|
|---|
| 1024 | ntdll!RtlRaiseException:
|
|---|
| 1025 | 7c91e528 55 push ebp
|
|---|
| 1026 | 7c91e529 8bec mov ebp,esp
|
|---|
| 1027 |
|
|---|
| 1028 | *----> Suivi arrière de la pile <----*
|
|---|
| 1029 | WARNING: Stack unwind information not available. Following frames may be wrong.
|
|---|
| 1030 | ChildEBP RetAddr Args to Child
|
|---|
| 1031 | 0b45fe4c 00b54365 00000974 ffffffff 00000001 ntdll!KiFastSystemCallRet
|
|---|
| 1032 | 0b45fe78 00b5444a 0954ab48 00000050 00000000 VBoxRT!RTSemEventMultiReset+0x1f5
|
|---|
| 1033 | 0b45fe94 00b4801a 0954ab48 00000050 00000000 VBoxRT!RTSemEventMultiWaitEx+0x1a
|
|---|
| 1034 | 0b45feac 0a9068ee 0954ab48 ffffffff 0b45ff04 VBoxRT!RTSemEventMultiWait+0x1a
|
|---|
| 1035 | 0b45fecc 0a906d27 0b45ff04 0a3500b0 2986efa8 VBoxC!VBoxDriversRegister+0x2c09e
|
|---|
| 1036 | 0b45fee0 0a907bb5 80000003 0b45ff04 00000000 VBoxC!VBoxDriversRegister+0x2c4d7
|
|---|
| 1037 | 0b45ff08 0a9065a0 80000003 003500b0 0a375fc0 VBoxC!VBoxDriversRegister+0x2d365
|
|---|
| 1038 | 0b45ff24 00b11523 0a375fc0 09548550 0a375fc0 VBoxC!VBoxDriversRegister+0x2bd50
|
|---|
| 1039 | 0b45ff50 00b5517b 0a375fc0 00000f48 0a37653c VBoxRT!RTThreadFromNative+0x1e3
|
|---|
| 1040 | 0b45ff70 78afc556 0a375fc0 793cb953 003d0178 VBoxRT!RTSymlinkRead+0x2eb
|
|---|
| 1041 | 0b45ffa8 78afc600 0a358e28 0b45ffec 7c80b729 MSVCR100!endthreadex+0x3a
|
|---|
| 1042 | 0b45ffb4 7c80b729 09570f20 003d0178 0a358e28 MSVCR100!endthreadex+0xe4
|
|---|
| 1043 | 0b45ffec 00000000 78afc59c 09570f20 00000000 kernel32!GetModuleFileNameA+0x1ba
|
|---|
| 1044 |
|
|---|
| 1045 | *----> Vidage brut de la pile <----*
|
|---|
| 1046 | 000000000b45fde8 5a df 91 7c db 25 80 7c - 74 09 00 00 01 00 00 00 Z..|.%.|t.......
|
|---|
| 1047 | 000000000b45fdf8 00 00 00 00 ff ff ff ff - 10 00 00 00 50 25 80 7c ............P%.|
|
|---|
| 1048 | 000000000b45fe08 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 1049 | 000000000b45fe18 10 00 00 00 5d 00 92 7c - 6a 01 ab 78 00 80 fd 7f ....]..|j..x....
|
|---|
| 1050 | 000000000b45fe28 00 b0 f4 7f 00 00 00 00 - 00 00 00 00 fc fd 45 0b ..............E.
|
|---|
| 1051 | 000000000b45fe38 a8 ef 86 29 98 ff 45 0b - d8 9a 83 7c 08 26 80 7c ...)..E....|.&.|
|
|---|
| 1052 | 000000000b45fe48 00 00 00 00 78 fe 45 0b - 65 43 b5 00 74 09 00 00 ....x.E.eC..t...
|
|---|
| 1053 | 000000000b45fe58 ff ff ff ff 01 00 00 00 - 00 80 b4 00 50 85 54 09 ............P.T.
|
|---|
| 1054 | 000000000b45fe68 70 41 b5 00 ff ff ff ff - ff ff ff ff c0 5f 37 0a pA..........._7.
|
|---|
| 1055 | 000000000b45fe78 94 fe 45 0b 4a 44 b5 00 - 48 ab 54 09 50 00 00 00 ..E.JD..H.T.P...
|
|---|
| 1056 | 000000000b45fe88 00 00 00 00 00 00 00 00 - 00 00 00 00 ac fe 45 0b ..............E.
|
|---|
| 1057 | 000000000b45fe98 1a 80 b4 00 48 ab 54 09 - 50 00 00 00 00 00 00 00 ....H.T.P.......
|
|---|
| 1058 | 000000000b45fea8 00 00 00 00 cc fe 45 0b - ee 68 90 0a 48 ab 54 09 ......E..h..H.T.
|
|---|
| 1059 | 000000000b45feb8 ff ff ff ff 04 ff 45 0b - 50 85 54 09 b8 10 e7 0e ......E.P.T.....
|
|---|
| 1060 | 000000000b45fec8 50 85 54 09 e0 fe 45 0b - 27 6d 90 0a 04 ff 45 0b P.T...E.'m....E.
|
|---|
| 1061 | 000000000b45fed8 b0 00 35 0a a8 ef 86 29 - 08 ff 45 0b b5 7b 90 0a ..5....)..E..{..
|
|---|
| 1062 | 000000000b45fee8 03 00 00 80 04 ff 45 0b - 00 00 00 00 50 85 54 09 ......E.....P.T.
|
|---|
| 1063 | 000000000b45fef8 65 9c 80 7c e1 19 b1 00 - f0 ef 86 29 a8 ef 86 29 e..|.......)...)
|
|---|
| 1064 | 000000000b45ff08 24 ff 45 0b a0 65 90 0a - 03 00 00 80 b0 00 35 00 $.E..e........5.
|
|---|
| 1065 | 000000000b45ff18 c0 5f 37 0a d8 5f 37 0a - c0 5f 37 0a 50 ff 45 0b ._7.._7.._7.P.E.
|
|---|
| 1066 |
|
|---|
| 1067 | *----> Vidage de l'état de la thread 0x150 <----*
|
|---|
| 1068 |
|
|---|
| 1069 | eax=78afc59c ebx=7e398bf6 ecx=00000000 edx=00000000 esi=0b56ff00 edi=00000000
|
|---|
| 1070 | eip=7c91e514 esp=0b56fe90 ebp=0b56feb4 iopl=0 nv up ei pl zr na po nc
|
|---|
| 1071 | cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
|
|---|
| 1072 |
|
|---|
| 1073 | fonction : ntdll!KiFastSystemCallRet
|
|---|
| 1074 | 7c91e4fa e829000000 call ntdll!RtlRaiseException (7c91e528)
|
|---|
| 1075 | 7c91e4ff 8b0424 mov eax,[esp]
|
|---|
| 1076 | 7c91e502 8be5 mov esp,ebp
|
|---|
| 1077 | 7c91e504 5d pop ebp
|
|---|
| 1078 | 7c91e505 c3 ret
|
|---|
| 1079 | 7c91e506 8da42400000000 lea esp,[esp]
|
|---|
| 1080 | 7c91e50d 8d4900 lea ecx,[ecx]
|
|---|
| 1081 | ntdll!KiFastSystemCall:
|
|---|
| 1082 | 7c91e510 8bd4 mov edx,esp
|
|---|
| 1083 | 7c91e512 0f34 sysenter
|
|---|
| 1084 | ntdll!KiFastSystemCallRet:
|
|---|
| 1085 | 7c91e514 c3 ret
|
|---|
| 1086 | 7c91e515 8da42400000000 lea esp,[esp]
|
|---|
| 1087 | 7c91e51c 8d642400 lea esp,[esp]
|
|---|
| 1088 | ntdll!KiIntSystemCall:
|
|---|
| 1089 | 7c91e520 8d542408 lea edx,[esp+0x8]
|
|---|
| 1090 | 7c91e524 cd2e int 2e
|
|---|
| 1091 | 7c91e526 c3 ret
|
|---|
| 1092 | 7c91e527 90 nop
|
|---|
| 1093 | ntdll!RtlRaiseException:
|
|---|
| 1094 | 7c91e528 55 push ebp
|
|---|
| 1095 | 7c91e529 8bec mov ebp,esp
|
|---|
| 1096 |
|
|---|
| 1097 | *----> Suivi arrière de la pile <----*
|
|---|
| 1098 | *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\Program Files\Oracle\VirtualBox\VBoxSharedClipboard.DLL -
|
|---|
| 1099 | WARNING: Stack unwind information not available. Following frames may be wrong.
|
|---|
| 1100 | ChildEBP RetAddr Args to Child
|
|---|
| 1101 | 0b56feb4 0b462a28 0b56ff00 00000000 00000000 ntdll!KiFastSystemCallRet
|
|---|
| 1102 | 0b56ff24 00b11523 0a376860 00000000 0a376860 VBoxSharedClipboard+0x2a28
|
|---|
| 1103 | 0b56ff50 00b5517b 0a376860 00000150 0a376ddc VBoxRT!RTThreadFromNative+0x1e3
|
|---|
| 1104 | 0b56ff70 78afc556 0a376860 792fb953 00000000 VBoxRT!RTSymlinkRead+0x2eb
|
|---|
| 1105 | 0b56ffa8 78afc600 00000000 0b56ffec 7c80b729 MSVCR100!endthreadex+0x3a
|
|---|
| 1106 | 0b56ffb4 7c80b729 09570f20 00000000 00000000 MSVCR100!endthreadex+0xe4
|
|---|
| 1107 | 0b56ffec 00000000 78afc59c 09570f20 00000000 kernel32!GetModuleFileNameA+0x1ba
|
|---|
| 1108 |
|
|---|
| 1109 | *----> Vidage brut de la pile <----*
|
|---|
| 1110 | 000000000b56fe90 be 91 39 7e 6b 77 3a 7e - 00 ff 56 0b 00 00 00 00 ..9~kw:~..V.....
|
|---|
| 1111 | 000000000b56fea0 00 00 00 00 00 00 00 00 - f6 8b 39 7e 00 00 00 00 ..........9~....
|
|---|
| 1112 | 000000000b56feb0 2b 77 3a 7e 24 ff 56 0b - 28 2a 46 0b 00 ff 56 0b +w:~$.V.(*F...V.
|
|---|
| 1113 | 000000000b56fec0 00 00 00 00 00 00 00 00 - 00 00 00 00 60 68 37 0a ............`h7.
|
|---|
| 1114 | 000000000b56fed0 78 68 37 0a 65 9c 80 7c - 00 02 00 00 20 25 46 0b xh7.e..|.... %F.
|
|---|
| 1115 | 000000000b56fee0 00 00 00 00 00 00 00 00 - 00 00 40 00 00 00 00 00 ..........@.....
|
|---|
| 1116 | 000000000b56fef0 00 00 00 00 02 00 00 00 - 00 00 00 00 00 60 46 0b .............`F.
|
|---|
| 1117 | 000000000b56ff00 ac 05 07 00 13 01 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 1118 | 000000000b56ff10 38 5f 59 01 7a 03 00 00 - e7 01 00 00 95 c2 00 00 8_Y.z...........
|
|---|
| 1119 | 000000000b56ff20 00 00 40 00 50 ff 56 0b - 23 15 b1 00 60 68 37 0a ..@.P.V.#...`h7.
|
|---|
| 1120 | 000000000b56ff30 00 00 00 00 60 68 37 0a - 0a 00 00 00 60 68 37 0a ....`h7.....`h7.
|
|---|
| 1121 | 000000000b56ff40 50 01 00 00 50 01 00 00 - 60 68 37 0a 65 9c 80 7c P...P...`h7.e..|
|
|---|
| 1122 | 000000000b56ff50 70 ff 56 0b 7b 51 b5 00 - 60 68 37 0a 50 01 00 00 p.V.{Q..`h7.P...
|
|---|
| 1123 | 000000000b56ff60 dc 6d 37 0a 00 00 00 00 - 00 00 00 00 20 0f 57 09 .m7......... .W.
|
|---|
| 1124 | 000000000b56ff70 a8 ff 56 0b 56 c5 af 78 - 60 68 37 0a 53 b9 2f 79 ..V.V..x`h7.S./y
|
|---|
| 1125 | 000000000b56ff80 00 00 00 00 00 00 00 00 - 20 0f 57 09 7c ff 56 0b ........ .W.|.V.
|
|---|
| 1126 | 000000000b56ff90 7c ff 56 0b dc ff 56 0b - dc ff 56 0b 5a b6 b2 78 |.V...V...V.Z..x
|
|---|
| 1127 | 000000000b56ffa0 7b 83 d6 0a 00 00 00 00 - b4 ff 56 0b 00 c6 af 78 {.........V....x
|
|---|
| 1128 | 000000000b56ffb0 00 00 00 00 ec ff 56 0b - 29 b7 80 7c 20 0f 57 09 ......V.)..| .W.
|
|---|
| 1129 | 000000000b56ffc0 00 00 00 00 00 00 00 00 - 20 0f 57 09 00 a0 f4 7f ........ .W.....
|
|---|
| 1130 |
|
|---|
| 1131 | *----> Vidage de l'état de la thread 0xb9c <----*
|
|---|
| 1132 |
|
|---|
| 1133 | eax=7c802838 ebx=7c802550 ecx=7c809036 edx=0b677600 esi=00000948 edi=00000000
|
|---|
| 1134 | eip=7c91e514 esp=0b66fde8 ebp=0b66fe4c iopl=0 nv up ei pl zr na po nc
|
|---|
| 1135 | cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
|
|---|
| 1136 |
|
|---|
| 1137 | fonction : ntdll!KiFastSystemCallRet
|
|---|
| 1138 | 7c91e4fa e829000000 call ntdll!RtlRaiseException (7c91e528)
|
|---|
| 1139 | 7c91e4ff 8b0424 mov eax,[esp]
|
|---|
| 1140 | 7c91e502 8be5 mov esp,ebp
|
|---|
| 1141 | 7c91e504 5d pop ebp
|
|---|
| 1142 | 7c91e505 c3 ret
|
|---|
| 1143 | 7c91e506 8da42400000000 lea esp,[esp]
|
|---|
| 1144 | 7c91e50d 8d4900 lea ecx,[ecx]
|
|---|
| 1145 | ntdll!KiFastSystemCall:
|
|---|
| 1146 | 7c91e510 8bd4 mov edx,esp
|
|---|
| 1147 | 7c91e512 0f34 sysenter
|
|---|
| 1148 | ntdll!KiFastSystemCallRet:
|
|---|
| 1149 | 7c91e514 c3 ret
|
|---|
| 1150 | 7c91e515 8da42400000000 lea esp,[esp]
|
|---|
| 1151 | 7c91e51c 8d642400 lea esp,[esp]
|
|---|
| 1152 | ntdll!KiIntSystemCall:
|
|---|
| 1153 | 7c91e520 8d542408 lea edx,[esp+0x8]
|
|---|
| 1154 | 7c91e524 cd2e int 2e
|
|---|
| 1155 | 7c91e526 c3 ret
|
|---|
| 1156 | 7c91e527 90 nop
|
|---|
| 1157 | ntdll!RtlRaiseException:
|
|---|
| 1158 | 7c91e528 55 push ebp
|
|---|
| 1159 | 7c91e529 8bec mov ebp,esp
|
|---|
| 1160 |
|
|---|
| 1161 | *----> Suivi arrière de la pile <----*
|
|---|
| 1162 | WARNING: Stack unwind information not available. Following frames may be wrong.
|
|---|
| 1163 | ChildEBP RetAddr Args to Child
|
|---|
| 1164 | 0b66fe4c 00b54365 00000948 ffffffff 00000001 ntdll!KiFastSystemCallRet
|
|---|
| 1165 | 0b66fe78 00b5444a 0a377168 00000050 00000000 VBoxRT!RTSemEventMultiReset+0x1f5
|
|---|
| 1166 | 0b66fe94 00b4801a 0a377168 00000050 00000000 VBoxRT!RTSemEventMultiWaitEx+0x1a
|
|---|
| 1167 | 0b66feac 0a9068ee 0a377168 ffffffff 0b66ff04 VBoxRT!RTSemEventMultiWait+0x1a
|
|---|
| 1168 | 0b66fecc 0a906d27 0b66ff04 0a3767e0 0954a760 VBoxC!VBoxDriversRegister+0x2c09e
|
|---|
| 1169 | 0b66fee0 0a907bb5 8000000a 0b66ff04 00000000 VBoxC!VBoxDriversRegister+0x2c4d7
|
|---|
| 1170 | 0b66ff08 0a9065a0 8000000a 003767e0 0a377188 VBoxC!VBoxDriversRegister+0x2d365
|
|---|
| 1171 | 0b66ff24 00b11523 0a377188 0a3770e8 0a377188 VBoxC!VBoxDriversRegister+0x2bd50
|
|---|
| 1172 | 0b66ff50 00b5517b 0a377188 00000b9c 0a377704 VBoxRT!RTThreadFromNative+0x1e3
|
|---|
| 1173 | 0b66ff70 78afc556 0a377188 791fb953 003d0178 VBoxRT!RTSymlinkRead+0x2eb
|
|---|
| 1174 | 0b66ffa8 78afc600 0a358e28 0b66ffec 7c80b729 MSVCR100!endthreadex+0x3a
|
|---|
| 1175 | 0b66ffb4 7c80b729 09570f20 003d0178 0a358e28 MSVCR100!endthreadex+0xe4
|
|---|
| 1176 | 0b66ffec 00000000 78afc59c 09570f20 00000000 kernel32!GetModuleFileNameA+0x1ba
|
|---|
| 1177 |
|
|---|
| 1178 | *----> Vidage brut de la pile <----*
|
|---|
| 1179 | 000000000b66fde8 5a df 91 7c db 25 80 7c - 48 09 00 00 01 00 00 00 Z..|.%.|H.......
|
|---|
| 1180 | 000000000b66fdf8 00 00 00 00 ff ff ff ff - 10 00 00 00 50 25 80 7c ............P%.|
|
|---|
| 1181 | 000000000b66fe08 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 1182 | 000000000b66fe18 10 00 00 00 74 90 00 00 - 00 00 3d 00 00 80 fd 7f ....t.....=.....
|
|---|
| 1183 | 000000000b66fe28 00 90 f4 7f 00 00 00 00 - 20 e9 91 7c fc fd 66 0b ........ ..|..f.
|
|---|
| 1184 | 000000000b66fe38 ff ff ff ff 98 ff 66 0b - d8 9a 83 7c 08 26 80 7c ......f....|.&.|
|
|---|
| 1185 | 000000000b66fe48 00 00 00 00 78 fe 66 0b - 65 43 b5 00 48 09 00 00 ....x.f.eC..H...
|
|---|
| 1186 | 000000000b66fe58 ff ff ff ff 01 00 00 00 - 00 80 b4 00 e8 70 37 0a .............p7.
|
|---|
| 1187 | 000000000b66fe68 70 41 b5 00 ff ff ff ff - ff ff ff ff 88 71 37 0a pA...........q7.
|
|---|
| 1188 | 000000000b66fe78 94 fe 66 0b 4a 44 b5 00 - 68 71 37 0a 50 00 00 00 ..f.JD..hq7.P...
|
|---|
| 1189 | 000000000b66fe88 00 00 00 00 00 00 00 00 - 00 00 00 00 ac fe 66 0b ..............f.
|
|---|
| 1190 | 000000000b66fe98 1a 80 b4 00 68 71 37 0a - 50 00 00 00 00 00 00 00 ....hq7.P.......
|
|---|
| 1191 | 000000000b66fea8 00 00 00 00 cc fe 66 0b - ee 68 90 0a 68 71 37 0a ......f..h..hq7.
|
|---|
| 1192 | 000000000b66feb8 ff ff ff ff 04 ff 66 0b - e8 70 37 0a 18 f1 e6 0e ......f..p7.....
|
|---|
| 1193 | 000000000b66fec8 e8 70 37 0a e0 fe 66 0b - 27 6d 90 0a 04 ff 66 0b .p7...f.'m....f.
|
|---|
| 1194 | 000000000b66fed8 e0 67 37 0a 60 a7 54 09 - 08 ff 66 0b b5 7b 90 0a .g7.`.T...f..{..
|
|---|
| 1195 | 000000000b66fee8 0a 00 00 80 04 ff 66 0b - 00 00 00 00 e8 70 37 0a ......f......p7.
|
|---|
| 1196 | 000000000b66fef8 65 9c 80 7c e1 19 b1 00 - a8 a7 54 09 60 a7 54 09 e..|......T.`.T.
|
|---|
| 1197 | 000000000b66ff08 24 ff 66 0b a0 65 90 0a - 0a 00 00 80 e0 67 37 00 $.f..e.......g7.
|
|---|
| 1198 | 000000000b66ff18 88 71 37 0a a0 71 37 0a - 88 71 37 0a 50 ff 66 0b .q7..q7..q7.P.f.
|
|---|
| 1199 |
|
|---|
| 1200 | *----> Vidage de l'état de la thread 0xa74 <----*
|
|---|
| 1201 |
|
|---|
| 1202 | eax=411d58c0 ebx=00000000 ecx=00000000 edx=0000000f esi=40fcb060 edi=0c2245f0
|
|---|
| 1203 | eip=0c070ffe esp=0b77eedc ebp=00000001 iopl=0 nv up ei pl nz na pe nc
|
|---|
| 1204 | cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202
|
|---|
| 1205 |
|
|---|
| 1206 | *** WARNING: Unable to verify checksum for C:\WINNT\system32\ig4dev32.dll
|
|---|
| 1207 | *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINNT\system32\ig4dev32.dll -
|
|---|
| 1208 | fonction : ig4dev32
|
|---|
| 1209 | 0c070fe7 49 dec ecx
|
|---|
| 1210 | 0c070fe8 48 dec eax
|
|---|
| 1211 | 0c070fe9 3b4818 cmp ecx,[eax+0x18]
|
|---|
| 1212 | 0c070fec 7314 jnb ig4dev32+0x41002 (0c071002)
|
|---|
| 1213 | 0c070fee 8b4024 mov eax,[eax+0x24]
|
|---|
| 1214 | 0c070ff1 8b3c88 mov edi,[eax+ecx*4]
|
|---|
| 1215 | 0c070ff4 eb0e jmp ig4dev32+0x41004 (0c071004)
|
|---|
| 1216 | 0c070ff6 395818 cmp [eax+0x18],ebx
|
|---|
| 1217 | 0c070ff9 7607 jbe ig4dev32+0x41002 (0c071002)
|
|---|
| 1218 | 0c070ffb 8b4824 mov ecx,[eax+0x24]
|
|---|
| 1219 | FAUTE ->0c070ffe 8b39 mov edi,[ecx] ds:0023:00000000=????????
|
|---|
| 1220 | 0c071000 eb02 jmp ig4dev32+0x41004 (0c071004)
|
|---|
| 1221 | 0c071002 33ff xor edi,edi
|
|---|
| 1222 | 0c071004 8d8c24a0000000 lea ecx,[esp+0xa0]
|
|---|
| 1223 | 0c07100b e85028ffff call ig4dev32+0x33860 (0c063860)
|
|---|
| 1224 | 0c071010 89bc24c0000000 mov [esp+0xc0],edi
|
|---|
| 1225 | 0c071017 8d54242c lea edx,[esp+0x2c]
|
|---|
| 1226 | 0c07101b 8dbe50050000 lea edi,[esi+0x550]
|
|---|
| 1227 | 0c071021 52 push edx
|
|---|
| 1228 | 0c071022 8d442414 lea eax,[esp+0x14]
|
|---|
| 1229 | 0c071026 8bcf mov ecx,edi
|
|---|
| 1230 |
|
|---|
| 1231 | *----> Suivi arrière de la pile <----*
|
|---|
| 1232 | WARNING: Stack unwind information not available. Following frames may be wrong.
|
|---|
| 1233 | ChildEBP RetAddr Args to Child
|
|---|
| 1234 | 00000001 00000000 00000000 00000000 00000000 ig4dev32+0x40ffe
|
|---|
| 1235 |
|
|---|
| 1236 | *----> Vidage brut de la pile <----*
|
|---|
| 1237 | 000000000b77eedc 40 f3 77 0b 60 b0 fc 40 - 04 00 00 00 00 00 00 00 @.w.`..@........
|
|---|
| 1238 | 000000000b77eeec 58 ef 77 0b e0 45 22 0c - 00 00 00 00 b0 b5 fc 40 X.w..E"........@
|
|---|
| 1239 | 000000000b77eefc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 ed 77 0b ..............w.
|
|---|
| 1240 | 000000000b77ef0c 64 ef 77 0b 00 00 00 40 - 00 00 00 00 00 00 00 00 d.w....@........
|
|---|
| 1241 | 000000000b77ef1c f0 45 22 0c 89 34 03 0c - 00 f3 77 0b 38 ba 21 0c .E"..4....w.8.!.
|
|---|
| 1242 | 000000000b77ef2c 00 00 00 00 00 00 00 00 - 00 00 00 00 0f 00 00 00 ................
|
|---|
| 1243 | 000000000b77ef3c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 1244 | 000000000b77ef4c 00 00 00 00 00 00 00 00 - 01 00 00 00 02 00 00 00 ................
|
|---|
| 1245 | 000000000b77ef5c 03 00 00 00 ff ff ff ff - 00 00 00 00 01 00 00 00 ................
|
|---|
| 1246 | 000000000b77ef6c 00 00 00 00 01 00 00 40 - 01 01 01 01 04 00 00 00 .......@........
|
|---|
| 1247 | 000000000b77ef7c f0 45 22 0c 01 00 00 40 - 00 b5 fc 40 0f 14 00 00 .E"....@...@....
|
|---|
| 1248 | 000000000b77ef8c 01 00 00 00 01 00 00 00 - 00 00 00 00 0f 00 00 00 ................
|
|---|
| 1249 | 000000000b77ef9c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 1250 | 000000000b77efac 00 00 00 00 00 00 00 00 - 01 00 00 00 02 00 00 00 ................
|
|---|
| 1251 | 000000000b77efbc 03 00 00 00 ff ff ff ff - 01 00 00 40 c4 f0 77 0b ...........@..w.
|
|---|
| 1252 | 000000000b77efcc 40 f3 77 0b 60 b0 fc 40 - 01 01 01 01 04 00 00 00 @.w.`..@........
|
|---|
| 1253 | 000000000b77efdc 0c f3 77 0b 6c c3 21 0c - 04 00 00 00 b1 1d 07 0c ..w.l.!.........
|
|---|
| 1254 | 000000000b77efec 6b 00 00 00 90 4e 01 42 - 40 f3 77 0b 10 f0 77 0b k....N.B@.w...w.
|
|---|
| 1255 | 000000000b77effc 4c f0 77 0b 88 f3 77 0b - 02 00 00 00 62 00 00 00 L.w...w.....b...
|
|---|
| 1256 | 000000000b77f00c 60 b0 fc 40 04 00 00 00 - 00 00 00 00 c0 00 00 00 `..@............
|
|---|
| 1257 |
|
|---|
| 1258 | *----> Vidage de l'état de la thread 0x4c4 <----*
|
|---|
| 1259 |
|
|---|
| 1260 | eax=00000001 ebx=7c80a0b7 ecx=7ff47000 edx=00f81658 esi=0babff98 edi=294800a4
|
|---|
| 1261 | eip=7c91e514 esp=0babff50 ebp=0babff74 iopl=0 nv up ei pl zr na po nc
|
|---|
| 1262 | cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
|
|---|
| 1263 |
|
|---|
| 1264 | fonction : ntdll!KiFastSystemCallRet
|
|---|
| 1265 | 7c91e4fa e829000000 call ntdll!RtlRaiseException (7c91e528)
|
|---|
| 1266 | 7c91e4ff 8b0424 mov eax,[esp]
|
|---|
| 1267 | 7c91e502 8be5 mov esp,ebp
|
|---|
| 1268 | 7c91e504 5d pop ebp
|
|---|
| 1269 | 7c91e505 c3 ret
|
|---|
| 1270 | 7c91e506 8da42400000000 lea esp,[esp]
|
|---|
| 1271 | 7c91e50d 8d4900 lea ecx,[ecx]
|
|---|
| 1272 | ntdll!KiFastSystemCall:
|
|---|
| 1273 | 7c91e510 8bd4 mov edx,esp
|
|---|
| 1274 | 7c91e512 0f34 sysenter
|
|---|
| 1275 | ntdll!KiFastSystemCallRet:
|
|---|
| 1276 | 7c91e514 c3 ret
|
|---|
| 1277 | 7c91e515 8da42400000000 lea esp,[esp]
|
|---|
| 1278 | 7c91e51c 8d642400 lea esp,[esp]
|
|---|
| 1279 | ntdll!KiIntSystemCall:
|
|---|
| 1280 | 7c91e520 8d542408 lea edx,[esp+0x8]
|
|---|
| 1281 | 7c91e524 cd2e int 2e
|
|---|
| 1282 | 7c91e526 c3 ret
|
|---|
| 1283 | 7c91e527 90 nop
|
|---|
| 1284 | ntdll!RtlRaiseException:
|
|---|
| 1285 | 7c91e528 55 push ebp
|
|---|
| 1286 | 7c91e529 8bec mov ebp,esp
|
|---|
| 1287 |
|
|---|
| 1288 | *----> Suivi arrière de la pile <----*
|
|---|
| 1289 | *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\Program Files\Oracle\VirtualBox\VBoxOGLrenderspu.dll -
|
|---|
| 1290 | WARNING: Stack unwind information not available. Following frames may be wrong.
|
|---|
| 1291 | ChildEBP RetAddr Args to Child
|
|---|
| 1292 | 0babff74 0b8835cc 0babff98 00000000 00000000 ntdll!KiFastSystemCallRet
|
|---|
| 1293 | 0babffb4 7c80b729 00000000 00000000 0b77eefc VBoxOGLrenderspu!renderspuReparentWindow+0xe5c
|
|---|
| 1294 | 0babffec 00000000 0b883480 00000000 00000000 kernel32!GetModuleFileNameA+0x1ba
|
|---|
| 1295 |
|
|---|
| 1296 | *----> Vidage brut de la pile <----*
|
|---|
| 1297 | 000000000babff50 be 91 39 7e 6b 77 3a 7e - 98 ff ab 0b 00 00 00 00 ..9~kw:~........
|
|---|
| 1298 | 000000000babff60 00 00 00 00 00 00 00 00 - b7 a0 80 7c a4 00 48 29 ...........|..H)
|
|---|
| 1299 | 000000000babff70 54 fc 77 0b b4 ff ab 0b - cc 35 88 0b 98 ff ab 0b T.w......5......
|
|---|
| 1300 | 000000000babff80 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 1301 | 000000000babff90 fc ee 77 0b 00 00 00 00 - 36 03 2a 00 0f 00 00 00 ..w.....6.*.....
|
|---|
| 1302 | 000000000babffa0 00 00 00 00 00 00 00 00 - db 78 59 01 f3 03 00 00 .........xY.....
|
|---|
| 1303 | 000000000babffb0 47 02 00 00 ec ff ab 0b - 29 b7 80 7c 00 00 00 00 G.......)..|....
|
|---|
| 1304 | 000000000babffc0 00 00 00 00 fc ee 77 0b - 00 00 00 00 00 70 f4 7f ......w......p..
|
|---|
| 1305 | 000000000babffd0 00 76 4f 8a c0 ff ab 0b - 90 24 37 89 ff ff ff ff .vO......$7.....
|
|---|
| 1306 | 000000000babffe0 d8 9a 83 7c 30 b7 80 7c - 00 00 00 00 00 00 00 00 ...|0..|........
|
|---|
| 1307 | 000000000babfff0 00 00 00 00 80 34 88 0b - 00 00 00 00 00 00 00 00 .....4..........
|
|---|
| 1308 | 000000000bac0000 4d 5a 90 00 03 00 00 00 - 04 00 00 00 ff ff 00 00 MZ..............
|
|---|
| 1309 | 000000000bac0010 b8 00 00 00 00 00 00 00 - 40 00 00 00 00 00 00 00 ........@.......
|
|---|
| 1310 | 000000000bac0020 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 1311 | 000000000bac0030 00 00 00 00 00 00 00 00 - 00 00 00 00 10 01 00 00 ................
|
|---|
| 1312 | 000000000bac0040 0e 1f ba 0e 00 b4 09 cd - 21 b8 01 4c cd 21 54 68 ........!..L.!Th
|
|---|
| 1313 | 000000000bac0050 69 73 20 70 72 6f 67 72 - 61 6d 20 63 61 6e 6e 6f is program canno
|
|---|
| 1314 | 000000000bac0060 74 20 62 65 20 72 75 6e - 20 69 6e 20 44 4f 53 20 t be run in DOS
|
|---|
| 1315 | 000000000bac0070 6d 6f 64 65 2e 0d 0d 0a - 24 00 00 00 00 00 00 00 mode....$.......
|
|---|
| 1316 | 000000000bac0080 69 31 cc 5c 2d 50 a2 0f - 2d 50 a2 0f 2d 50 a2 0f i1.\-P..-P..-P..
|
|---|
| 1317 |
|
|---|
| 1318 | *----> Vidage de l'état de la thread 0xfd4 <----*
|
|---|
| 1319 |
|
|---|
| 1320 | eax=78afc59c ebx=7c809c65 ecx=0b77ef14 edx=00000000 esi=000008bc edi=00000000
|
|---|
| 1321 | eip=7c91e514 esp=0d5cfe54 ebp=0d5cfeb8 iopl=0 nv up ei pl zr na po nc
|
|---|
| 1322 | cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
|
|---|
| 1323 |
|
|---|
| 1324 | fonction : ntdll!KiFastSystemCallRet
|
|---|
| 1325 | 7c91e4fa e829000000 call ntdll!RtlRaiseException (7c91e528)
|
|---|
| 1326 | 7c91e4ff 8b0424 mov eax,[esp]
|
|---|
| 1327 | 7c91e502 8be5 mov esp,ebp
|
|---|
| 1328 | 7c91e504 5d pop ebp
|
|---|
| 1329 | 7c91e505 c3 ret
|
|---|
| 1330 | 7c91e506 8da42400000000 lea esp,[esp]
|
|---|
| 1331 | 7c91e50d 8d4900 lea ecx,[ecx]
|
|---|
| 1332 | ntdll!KiFastSystemCall:
|
|---|
| 1333 | 7c91e510 8bd4 mov edx,esp
|
|---|
| 1334 | 7c91e512 0f34 sysenter
|
|---|
| 1335 | ntdll!KiFastSystemCallRet:
|
|---|
| 1336 | 7c91e514 c3 ret
|
|---|
| 1337 | 7c91e515 8da42400000000 lea esp,[esp]
|
|---|
| 1338 | 7c91e51c 8d642400 lea esp,[esp]
|
|---|
| 1339 | ntdll!KiIntSystemCall:
|
|---|
| 1340 | 7c91e520 8d542408 lea edx,[esp+0x8]
|
|---|
| 1341 | 7c91e524 cd2e int 2e
|
|---|
| 1342 | 7c91e526 c3 ret
|
|---|
| 1343 | 7c91e527 90 nop
|
|---|
| 1344 | ntdll!RtlRaiseException:
|
|---|
| 1345 | 7c91e528 55 push ebp
|
|---|
| 1346 | 7c91e529 8bec mov ebp,esp
|
|---|
| 1347 |
|
|---|
| 1348 | *----> Suivi arrière de la pile <----*
|
|---|
| 1349 | WARNING: Stack unwind information not available. Following frames may be wrong.
|
|---|
| 1350 | *** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\Program Files\Oracle\VirtualBox\VBoxSharedCrOpenGL.DLL -
|
|---|
| 1351 | ChildEBP RetAddr Args to Child
|
|---|
| 1352 | 0d5cfeb8 00b53f70 000008bc ffffffff 00000001 ntdll!KiFastSystemCallRet
|
|---|
| 1353 | 0d5cfed4 00b47f99 0a403eb0 ffffffff 0a403ee0 VBoxRT!RTSemEventWaitNoResume+0x50
|
|---|
| 1354 | 0d5cfef0 0b782016 0a403eb0 ffffffff 7e1b7174 VBoxRT!RTSemEventWait+0x19
|
|---|
| 1355 | 0d5cff24 00b11523 0a403ec8 00000000 0a403ec8 VBoxSharedCrOpenGL+0x2016
|
|---|
| 1356 | 0d5cff50 00b5517b 0a403ec8 00000fd4 0a404444 VBoxRT!RTThreadFromNative+0x1e3
|
|---|
| 1357 | 0d5cff70 78afc556 0a403ec8 7f25b953 0b77ef18 VBoxRT!RTSymlinkRead+0x2eb
|
|---|
| 1358 | 0d5cffa8 78afc600 78ab0350 0d5cffec 7c80b729 MSVCR100!endthreadex+0x3a
|
|---|
| 1359 | 0d5cffb4 7c80b729 0a404480 0b77ef18 78ab0350 MSVCR100!endthreadex+0xe4
|
|---|
| 1360 | 0d5cffec 00000000 78afc59c 0a404480 00000000 kernel32!GetModuleFileNameA+0x1ba
|
|---|
| 1361 |
|
|---|
| 1362 | *----> Vidage brut de la pile <----*
|
|---|
| 1363 | 000000000d5cfe54 5a df 91 7c db 25 80 7c - bc 08 00 00 01 00 00 00 Z..|.%.|........
|
|---|
| 1364 | 000000000d5cfe64 00 00 00 00 c8 3e 40 0a - b0 3e 40 0a 65 9c 80 7c .....>@..>@.e..|
|
|---|
| 1365 | 000000000d5cfe74 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 1366 | 000000000d5cfe84 10 00 00 00 b8 00 92 7c - 78 44 40 0a 00 80 fd 7f .......|xD@.....
|
|---|
| 1367 | 000000000d5cfe94 00 60 f4 7f 00 00 00 00 - 5d 00 92 7c 68 fe 5c 0d .`......]..|h.\.
|
|---|
| 1368 | 000000000d5cfea4 80 44 40 0a 18 ff 5c 0d - d8 9a 83 7c 08 26 80 7c .D@...\....|.&.|
|
|---|
| 1369 | 000000000d5cfeb4 00 00 00 00 d4 fe 5c 0d - 70 3f b5 00 bc 08 00 00 ......\.p?......
|
|---|
| 1370 | 000000000d5cfec4 ff ff ff ff 01 00 00 00 - e0 3e 40 0a b0 3e 40 0a .........>@..>@.
|
|---|
| 1371 | 000000000d5cfed4 f0 fe 5c 0d 99 7f b4 00 - b0 3e 40 0a ff ff ff ff ..\......>@.....
|
|---|
| 1372 | 000000000d5cfee4 e0 3e 40 0a c8 3e 40 0a - 65 9c 80 7c 24 ff 5c 0d .>@..>@.e..|$.\.
|
|---|
| 1373 | 000000000d5cfef4 16 20 78 0b b0 3e 40 0a - ff ff ff ff 74 71 1b 7e . x..>@.....tq.~
|
|---|
| 1374 | 000000000d5cff04 e0 3e 40 0a c8 3e 40 0a - 65 9c 80 7c 03 00 00 00 .>@..>@.e..|....
|
|---|
| 1375 | 000000000d5cff14 28 ff 5c 0d 98 ff 5c 0d - 48 4b 81 0b ff ff ff ff (.\...\.HK......
|
|---|
| 1376 | 000000000d5cff24 50 ff 5c 0d 23 15 b1 00 - c8 3e 40 0a 00 00 00 00 P.\.#....>@.....
|
|---|
| 1377 | 000000000d5cff34 c8 3e 40 0a 0a 00 00 00 - c8 3e 40 0a d4 0f 00 00 .>@......>@.....
|
|---|
| 1378 | 000000000d5cff44 d4 0f 00 00 c8 3e 40 0a - 65 9c 80 7c 70 ff 5c 0d .....>@.e..|p.\.
|
|---|
| 1379 | 000000000d5cff54 7b 51 b5 00 c8 3e 40 0a - d4 0f 00 00 44 44 40 0a {Q...>@.....DD@.
|
|---|
| 1380 | 000000000d5cff64 18 ef 77 0b 50 03 ab 78 - 80 44 40 0a a8 ff 5c 0d ..w.P..x.D@...\.
|
|---|
| 1381 | 000000000d5cff74 56 c5 af 78 c8 3e 40 0a - 53 b9 25 7f 18 ef 77 0b V..x.>@.S.%...w.
|
|---|
| 1382 | 000000000d5cff84 50 03 ab 78 80 44 40 0a - 7c ff 5c 0d 7c ff 5c 0d P..x.D@.|.\.|.\.
|
|---|
| 1383 |
|
|---|
| 1384 | *----> Vidage de l'état de la thread 0x910 <----*
|
|---|
| 1385 |
|
|---|
| 1386 | eax=0b330000 ebx=7c802550 ecx=00000003 edx=00000000 esi=000008a0 edi=00000000
|
|---|
| 1387 | eip=7c91e514 esp=0d6cfde8 ebp=0d6cfe4c iopl=0 nv up ei pl zr na po nc
|
|---|
| 1388 | cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
|
|---|
| 1389 |
|
|---|
| 1390 | fonction : ntdll!KiFastSystemCallRet
|
|---|
| 1391 | 7c91e4fa e829000000 call ntdll!RtlRaiseException (7c91e528)
|
|---|
| 1392 | 7c91e4ff 8b0424 mov eax,[esp]
|
|---|
| 1393 | 7c91e502 8be5 mov esp,ebp
|
|---|
| 1394 | 7c91e504 5d pop ebp
|
|---|
| 1395 | 7c91e505 c3 ret
|
|---|
| 1396 | 7c91e506 8da42400000000 lea esp,[esp]
|
|---|
| 1397 | 7c91e50d 8d4900 lea ecx,[ecx]
|
|---|
| 1398 | ntdll!KiFastSystemCall:
|
|---|
| 1399 | 7c91e510 8bd4 mov edx,esp
|
|---|
| 1400 | 7c91e512 0f34 sysenter
|
|---|
| 1401 | ntdll!KiFastSystemCallRet:
|
|---|
| 1402 | 7c91e514 c3 ret
|
|---|
| 1403 | 7c91e515 8da42400000000 lea esp,[esp]
|
|---|
| 1404 | 7c91e51c 8d642400 lea esp,[esp]
|
|---|
| 1405 | ntdll!KiIntSystemCall:
|
|---|
| 1406 | 7c91e520 8d542408 lea edx,[esp+0x8]
|
|---|
| 1407 | 7c91e524 cd2e int 2e
|
|---|
| 1408 | 7c91e526 c3 ret
|
|---|
| 1409 | 7c91e527 90 nop
|
|---|
| 1410 | ntdll!RtlRaiseException:
|
|---|
| 1411 | 7c91e528 55 push ebp
|
|---|
| 1412 | 7c91e529 8bec mov ebp,esp
|
|---|
| 1413 |
|
|---|
| 1414 | *----> Suivi arrière de la pile <----*
|
|---|
| 1415 | WARNING: Stack unwind information not available. Following frames may be wrong.
|
|---|
| 1416 | ChildEBP RetAddr Args to Child
|
|---|
| 1417 | 0d6cfe4c 00b54365 000008a0 ffffffff 00000001 ntdll!KiFastSystemCallRet
|
|---|
| 1418 | 0d6cfe78 00b5444a 0a404718 00000050 00000000 VBoxRT!RTSemEventMultiReset+0x1f5
|
|---|
| 1419 | 0d6cfe94 00b4801a 0a404718 00000050 00000000 VBoxRT!RTSemEventMultiWaitEx+0x1a
|
|---|
| 1420 | 0d6cfeac 0a9068ee 0a404718 ffffffff 0d6cff04 VBoxRT!RTSemEventMultiWait+0x1a
|
|---|
| 1421 | 0d6cfecc 0a906d27 0d6cff04 0a378578 00000000 VBoxC!VBoxDriversRegister+0x2c09e
|
|---|
| 1422 | 0d6cfee0 0a907bb5 80000018 0d6cff04 00000000 VBoxC!VBoxDriversRegister+0x2c4d7
|
|---|
| 1423 | 0d6cff08 0a9065a0 80000018 00378578 0a4049f0 VBoxC!VBoxDriversRegister+0x2d365
|
|---|
| 1424 | 0d6cff24 00b11523 0a4049f0 0a404948 0a4049f0 VBoxC!VBoxDriversRegister+0x2bd50
|
|---|
| 1425 | 0d6cff50 00b5517b 0a4049f0 00000910 0a404f6c VBoxRT!RTThreadFromNative+0x1e3
|
|---|
| 1426 | 0d6cff70 78afc556 0a4049f0 7f15b953 003d0178 VBoxRT!RTSymlinkRead+0x2eb
|
|---|
| 1427 | 0d6cffa8 78afc600 0a358e28 0d6cffec 7c80b729 MSVCR100!endthreadex+0x3a
|
|---|
| 1428 | 0d6cffb4 7c80b729 0a404480 003d0178 0a358e28 MSVCR100!endthreadex+0xe4
|
|---|
| 1429 | 0d6cffec 00000000 78afc59c 0a404480 00000000 kernel32!GetModuleFileNameA+0x1ba
|
|---|
| 1430 |
|
|---|
| 1431 | *----> Vidage brut de la pile <----*
|
|---|
| 1432 | 000000000d6cfde8 5a df 91 7c db 25 80 7c - a0 08 00 00 01 00 00 00 Z..|.%.|........
|
|---|
| 1433 | 000000000d6cfdf8 00 00 00 00 ff ff ff ff - 10 00 00 00 50 25 80 7c ............P%.|
|
|---|
| 1434 | 000000000d6cfe08 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 1435 | 000000000d6cfe18 10 00 00 00 74 90 b2 00 - 2c fe 6c 0d 00 80 fd 7f ....t...,.l.....
|
|---|
| 1436 | 000000000d6cfe28 00 50 f4 7f 00 00 00 00 - bc e7 98 0a fc fd 6c 0d .P............l.
|
|---|
| 1437 | 000000000d6cfe38 6c 66 40 0a 98 ff 6c 0d - d8 9a 83 7c 08 26 80 7c lf@...l....|.&.|
|
|---|
| 1438 | 000000000d6cfe48 00 00 00 00 78 fe 6c 0d - 65 43 b5 00 a0 08 00 00 ....x.l.eC......
|
|---|
| 1439 | 000000000d6cfe58 ff ff ff ff 01 00 00 00 - 00 80 b4 00 48 49 40 0a ............HI@.
|
|---|
| 1440 | 000000000d6cfe68 70 41 b5 00 ff ff ff ff - ff ff ff ff f0 49 40 0a pA...........I@.
|
|---|
| 1441 | 000000000d6cfe78 94 fe 6c 0d 4a 44 b5 00 - 18 47 40 0a 50 00 00 00 ..l.JD...G@.P...
|
|---|
| 1442 | 000000000d6cfe88 00 00 00 00 00 00 00 00 - 00 00 00 00 ac fe 6c 0d ..............l.
|
|---|
| 1443 | 000000000d6cfe98 1a 80 b4 00 18 47 40 0a - 50 00 00 00 00 00 00 00 .....G@.P.......
|
|---|
| 1444 | 000000000d6cfea8 00 00 00 00 cc fe 6c 0d - ee 68 90 0a 18 47 40 0a ......l..h...G@.
|
|---|
| 1445 | 000000000d6cfeb8 ff ff ff ff 04 ff 6c 0d - 48 49 40 0a e0 ec 86 29 ......l.HI@....)
|
|---|
| 1446 | 000000000d6cfec8 48 49 40 0a e0 fe 6c 0d - 27 6d 90 0a 04 ff 6c 0d HI@...l.'m....l.
|
|---|
| 1447 | 000000000d6cfed8 78 85 37 0a 00 00 00 00 - 08 ff 6c 0d b5 7b 90 0a x.7.......l..{..
|
|---|
| 1448 | 000000000d6cfee8 18 00 00 80 04 ff 6c 0d - 00 00 00 00 48 49 40 0a ......l.....HI@.
|
|---|
| 1449 | 000000000d6cfef8 65 9c 80 7c e1 19 b1 00 - e8 02 35 0a e0 ec 86 29 e..|......5....)
|
|---|
| 1450 | 000000000d6cff08 24 ff 6c 0d a0 65 90 0a - 18 00 00 80 78 85 37 00 $.l..e......x.7.
|
|---|
| 1451 | 000000000d6cff18 f0 49 40 0a 08 4a 40 0a - f0 49 40 0a 50 ff 6c 0d .I@..J@..I@.P.l.
|
|---|
| 1452 |
|
|---|
| 1453 | *----> Vidage de l'état de la thread 0x214 <----*
|
|---|
| 1454 |
|
|---|
| 1455 | eax=0a407000 ebx=7c802550 ecx=0d7defa0 edx=00001000 esi=00000884 edi=00000000
|
|---|
| 1456 | eip=7c91e514 esp=0d7dfde8 ebp=0d7dfe4c iopl=0 nv up ei pl zr na po nc
|
|---|
| 1457 | cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
|
|---|
| 1458 |
|
|---|
| 1459 | fonction : ntdll!KiFastSystemCallRet
|
|---|
| 1460 | 7c91e4fa e829000000 call ntdll!RtlRaiseException (7c91e528)
|
|---|
| 1461 | 7c91e4ff 8b0424 mov eax,[esp]
|
|---|
| 1462 | 7c91e502 8be5 mov esp,ebp
|
|---|
| 1463 | 7c91e504 5d pop ebp
|
|---|
| 1464 | 7c91e505 c3 ret
|
|---|
| 1465 | 7c91e506 8da42400000000 lea esp,[esp]
|
|---|
| 1466 | 7c91e50d 8d4900 lea ecx,[ecx]
|
|---|
| 1467 | ntdll!KiFastSystemCall:
|
|---|
| 1468 | 7c91e510 8bd4 mov edx,esp
|
|---|
| 1469 | 7c91e512 0f34 sysenter
|
|---|
| 1470 | ntdll!KiFastSystemCallRet:
|
|---|
| 1471 | 7c91e514 c3 ret
|
|---|
| 1472 | 7c91e515 8da42400000000 lea esp,[esp]
|
|---|
| 1473 | 7c91e51c 8d642400 lea esp,[esp]
|
|---|
| 1474 | ntdll!KiIntSystemCall:
|
|---|
| 1475 | 7c91e520 8d542408 lea edx,[esp+0x8]
|
|---|
| 1476 | 7c91e524 cd2e int 2e
|
|---|
| 1477 | 7c91e526 c3 ret
|
|---|
| 1478 | 7c91e527 90 nop
|
|---|
| 1479 | ntdll!RtlRaiseException:
|
|---|
| 1480 | 7c91e528 55 push ebp
|
|---|
| 1481 | 7c91e529 8bec mov ebp,esp
|
|---|
| 1482 |
|
|---|
| 1483 | *----> Suivi arrière de la pile <----*
|
|---|
| 1484 | WARNING: Stack unwind information not available. Following frames may be wrong.
|
|---|
| 1485 | ChildEBP RetAddr Args to Child
|
|---|
| 1486 | 0d7dfe4c 00b54365 00000884 ffffffff 00000001 ntdll!KiFastSystemCallRet
|
|---|
| 1487 | 0d7dfe78 00b5444a 0a4057c0 00000050 00000000 VBoxRT!RTSemEventMultiReset+0x1f5
|
|---|
| 1488 | 0d7dfe94 00b4801a 0a4057c0 00000050 00000000 VBoxRT!RTSemEventMultiWaitEx+0x1a
|
|---|
| 1489 | 0d7dfeac 0a9068ee 0a4057c0 ffffffff 0d7dff04 VBoxRT!RTSemEventMultiWait+0x1a
|
|---|
| 1490 | 0d7dfecc 0a906d27 0d7dff04 0a4065d8 0ee69258 VBoxC!VBoxDriversRegister+0x2c09e
|
|---|
| 1491 | 0d7dfee0 0a907bb5 8000002b 0d7dff04 00000000 VBoxC!VBoxDriversRegister+0x2c4d7
|
|---|
| 1492 | 0d7dff08 0a9065a0 8000002b 004065d8 0a4066d8 VBoxC!VBoxDriversRegister+0x2d365
|
|---|
| 1493 | 0d7dff24 00b11523 0a4066d8 0a406658 0a4066d8 VBoxC!VBoxDriversRegister+0x2bd50
|
|---|
| 1494 | 0d7dff50 00b5517b 0a4066d8 00000214 0a406c54 VBoxRT!RTThreadFromNative+0x1e3
|
|---|
| 1495 | 0d7dff70 78afc556 0a4066d8 7f04b953 003d0178 VBoxRT!RTSymlinkRead+0x2eb
|
|---|
| 1496 | 0d7dffa8 78afc600 0a358e28 0d7dffec 7c80b729 MSVCR100!endthreadex+0x3a
|
|---|
| 1497 | 0d7dffb4 7c80b729 0a404480 003d0178 0a358e28 MSVCR100!endthreadex+0xe4
|
|---|
| 1498 | 0d7dffec 00000000 78afc59c 0a404480 00000000 kernel32!GetModuleFileNameA+0x1ba
|
|---|
| 1499 |
|
|---|
| 1500 | *----> Vidage brut de la pile <----*
|
|---|
| 1501 | 000000000d7dfde8 5a df 91 7c db 25 80 7c - 84 08 00 00 01 00 00 00 Z..|.%.|........
|
|---|
| 1502 | 000000000d7dfdf8 00 00 00 00 ff ff ff ff - 10 00 00 00 50 25 80 7c ............P%.|
|
|---|
| 1503 | 000000000d7dfe08 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 1504 | 000000000d7dfe18 10 00 00 00 00 00 00 00 - 90 81 35 0a 00 80 fd 7f ..........5.....
|
|---|
| 1505 | 000000000d7dfe28 00 40 f4 7f 00 00 00 00 - f0 6f 40 0a fc fd 7d 0d .@.......o@...}.
|
|---|
| 1506 | 000000000d7dfe38 73 ba 3e 7e 98 ff 7d 0d - d8 9a 83 7c 08 26 80 7c s.>~..}....|.&.|
|
|---|
| 1507 | 000000000d7dfe48 00 00 00 00 78 fe 7d 0d - 65 43 b5 00 84 08 00 00 ....x.}.eC......
|
|---|
| 1508 | 000000000d7dfe58 ff ff ff ff 01 00 00 00 - 00 80 b4 00 58 66 40 0a ............Xf@.
|
|---|
| 1509 | 000000000d7dfe68 70 41 b5 00 ff ff ff ff - ff ff ff ff d8 66 40 0a pA...........f@.
|
|---|
| 1510 | 000000000d7dfe78 94 fe 7d 0d 4a 44 b5 00 - c0 57 40 0a 50 00 00 00 ..}.JD...W@.P...
|
|---|
| 1511 | 000000000d7dfe88 00 00 00 00 00 00 00 00 - 00 00 00 00 ac fe 7d 0d ..............}.
|
|---|
| 1512 | 000000000d7dfe98 1a 80 b4 00 c0 57 40 0a - 50 00 00 00 00 00 00 00 .....W@.P.......
|
|---|
| 1513 | 000000000d7dfea8 00 00 00 00 cc fe 7d 0d - ee 68 90 0a c0 57 40 0a ......}..h...W@.
|
|---|
| 1514 | 000000000d7dfeb8 ff ff ff ff 04 ff 7d 0d - 58 66 40 0a a0 a1 e2 0e ......}.Xf@.....
|
|---|
| 1515 | 000000000d7dfec8 58 66 40 0a e0 fe 7d 0d - 27 6d 90 0a 04 ff 7d 0d Xf@...}.'m....}.
|
|---|
| 1516 | 000000000d7dfed8 d8 65 40 0a 58 92 e6 0e - 08 ff 7d 0d b5 7b 90 0a .e@.X.....}..{..
|
|---|
| 1517 | 000000000d7dfee8 2b 00 00 80 04 ff 7d 0d - 00 00 00 00 58 66 40 0a +.....}.....Xf@.
|
|---|
| 1518 | 000000000d7dfef8 65 9c 80 7c e1 19 b1 00 - a0 92 e6 0e 58 92 e6 0e e..|........X...
|
|---|
| 1519 | 000000000d7dff08 24 ff 7d 0d a0 65 90 0a - 2b 00 00 80 d8 65 40 00 $.}..e..+....e@.
|
|---|
| 1520 | 000000000d7dff18 d8 66 40 0a f0 66 40 0a - d8 66 40 0a 50 ff 7d 0d .f@..f@..f@.P.}.
|
|---|
| 1521 |
|
|---|
| 1522 | *----> Vidage de l'état de la thread 0xf4c <----*
|
|---|
| 1523 |
|
|---|
| 1524 | eax=00000000 ebx=7c809c65 ecx=0f0cfe94 edx=7c91e514 esi=00000840 edi=00000000
|
|---|
| 1525 | eip=7c91e514 esp=0f0cfe94 ebp=0f0cfef8 iopl=0 nv up ei pl zr na po nc
|
|---|
| 1526 | cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
|
|---|
| 1527 |
|
|---|
| 1528 | fonction : ntdll!KiFastSystemCallRet
|
|---|
| 1529 | 7c91e4fa e829000000 call ntdll!RtlRaiseException (7c91e528)
|
|---|
| 1530 | 7c91e4ff 8b0424 mov eax,[esp]
|
|---|
| 1531 | 7c91e502 8be5 mov esp,ebp
|
|---|
| 1532 | 7c91e504 5d pop ebp
|
|---|
| 1533 | 7c91e505 c3 ret
|
|---|
| 1534 | 7c91e506 8da42400000000 lea esp,[esp]
|
|---|
| 1535 | 7c91e50d 8d4900 lea ecx,[ecx]
|
|---|
| 1536 | ntdll!KiFastSystemCall:
|
|---|
| 1537 | 7c91e510 8bd4 mov edx,esp
|
|---|
| 1538 | 7c91e512 0f34 sysenter
|
|---|
| 1539 | ntdll!KiFastSystemCallRet:
|
|---|
| 1540 | 7c91e514 c3 ret
|
|---|
| 1541 | 7c91e515 8da42400000000 lea esp,[esp]
|
|---|
| 1542 | 7c91e51c 8d642400 lea esp,[esp]
|
|---|
| 1543 | ntdll!KiIntSystemCall:
|
|---|
| 1544 | 7c91e520 8d542408 lea edx,[esp+0x8]
|
|---|
| 1545 | 7c91e524 cd2e int 2e
|
|---|
| 1546 | 7c91e526 c3 ret
|
|---|
| 1547 | 7c91e527 90 nop
|
|---|
| 1548 | ntdll!RtlRaiseException:
|
|---|
| 1549 | 7c91e528 55 push ebp
|
|---|
| 1550 | 7c91e529 8bec mov ebp,esp
|
|---|
| 1551 |
|
|---|
| 1552 | *----> Suivi arrière de la pile <----*
|
|---|
| 1553 | WARNING: Stack unwind information not available. Following frames may be wrong.
|
|---|
| 1554 | ChildEBP RetAddr Args to Child
|
|---|
| 1555 | 0f0cfef8 00b557bf 00000840 ffffffff 00000000 ntdll!KiFastSystemCallRet
|
|---|
| 1556 | 0f0cff24 00b11523 0a52d778 0a355728 0a52d778 VBoxRT!RTTimeLocalExplode+0x1bf
|
|---|
| 1557 | 0f0cff50 00b5517b 0a52d778 00000f4c 0a52dcf4 VBoxRT!RTThreadFromNative+0x1e3
|
|---|
| 1558 | 0f0cff70 78afc556 0a52d778 7d75b953 7c928cd9 VBoxRT!RTSymlinkRead+0x2eb
|
|---|
| 1559 | 0f0cffa8 78afc600 00000973 0f0cffec 7c80b729 MSVCR100!endthreadex+0x3a
|
|---|
| 1560 | 0f0cffb4 7c80b729 0a52dd10 7c928cd9 00000973 MSVCR100!endthreadex+0xe4
|
|---|
| 1561 | 0f0cffec 00000000 78afc59c 0a52dd10 00000000 kernel32!GetModuleFileNameA+0x1ba
|
|---|
| 1562 |
|
|---|
| 1563 | *----> Vidage brut de la pile <----*
|
|---|
| 1564 | 000000000f0cfe94 5a df 91 7c db 25 80 7c - 40 08 00 00 00 00 00 00 Z..|.%.|@.......
|
|---|
| 1565 | 000000000f0cfea4 00 00 00 00 a1 96 80 7c - 28 57 35 0a 65 9c 80 7c .......|(W5.e..|
|
|---|
| 1566 | 000000000f0cfeb4 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 1567 | 000000000f0cfec4 10 00 00 00 00 00 00 00 - 00 00 00 00 00 80 fd 7f ................
|
|---|
| 1568 | 000000000f0cfed4 00 30 f4 7f 00 00 00 00 - a1 96 80 7c a8 fe 0c 0f .0.........|....
|
|---|
| 1569 | 000000000f0cfee4 65 9c 80 7c 98 ff 0c 0f - d8 9a 83 7c 08 26 80 7c e..|.......|.&.|
|
|---|
| 1570 | 000000000f0cfef4 00 00 00 00 24 ff 0c 0f - bf 57 b5 00 40 08 00 00 ....$....W..@...
|
|---|
| 1571 | 000000000f0cff04 ff ff ff ff 00 00 00 00 - 90 d7 52 0a 78 d7 52 0a ..........R.x.R.
|
|---|
| 1572 | 000000000f0cff14 60 79 fe ff ff ff ff ff - 60 79 fe ff ff ff ff ff `y......`y......
|
|---|
| 1573 | 000000000f0cff24 50 ff 0c 0f 23 15 b1 00 - 78 d7 52 0a 28 57 35 0a P...#...x.R.(W5.
|
|---|
| 1574 | 000000000f0cff34 78 d7 52 0a 0b 00 00 00 - 78 d7 52 0a 4c 0f 00 00 x.R.....x.R.L...
|
|---|
| 1575 | 000000000f0cff44 4c 0f 00 00 78 d7 52 0a - 65 9c 80 7c 70 ff 0c 0f L...x.R.e..|p...
|
|---|
| 1576 | 000000000f0cff54 7b 51 b5 00 78 d7 52 0a - 4c 0f 00 00 f4 dc 52 0a {Q..x.R.L.....R.
|
|---|
| 1577 | 000000000f0cff64 d9 8c 92 7c 73 09 00 00 - 10 dd 52 0a a8 ff 0c 0f ...|s.....R.....
|
|---|
| 1578 | 000000000f0cff74 56 c5 af 78 78 d7 52 0a - 53 b9 75 7d d9 8c 92 7c V..xx.R.S.u}...|
|
|---|
| 1579 | 000000000f0cff84 73 09 00 00 10 dd 52 0a - 7c ff 0c 0f 7c ff 0c 0f s.....R.|...|...
|
|---|
| 1580 | 000000000f0cff94 dc ff 0c 0f dc ff 0c 0f - 5a b6 b2 78 7b 83 d6 0a ........Z..x{...
|
|---|
| 1581 | 000000000f0cffa4 00 00 00 00 b4 ff 0c 0f - 00 c6 af 78 73 09 00 00 ...........xs...
|
|---|
| 1582 | 000000000f0cffb4 ec ff 0c 0f 29 b7 80 7c - 10 dd 52 0a d9 8c 92 7c ....)..|..R....|
|
|---|
| 1583 | 000000000f0cffc4 73 09 00 00 10 dd 52 0a - 00 30 f4 7f 00 56 4f 8a s.....R..0...VO.
|
|---|
| 1584 |
|
|---|
| 1585 | *----> Vidage de l'état de la thread 0x81c <----*
|
|---|
| 1586 |
|
|---|
| 1587 | eax=00000000 ebx=00000000 ecx=7c802413 edx=7c91e514 esi=0ec2fbcc edi=0ec2fbc8
|
|---|
| 1588 | eip=00b5539f esp=0f46fee0 ebp=0f46fee0 iopl=0 nv up ei pl zr na po nc
|
|---|
| 1589 | cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
|
|---|
| 1590 |
|
|---|
| 1591 | fonction : VBoxRT!RTThreadSleep
|
|---|
| 1592 | 00b5538d cc int 3
|
|---|
| 1593 | 00b5538e cc int 3
|
|---|
| 1594 | 00b5538f cc int 3
|
|---|
| 1595 | VBoxRT!RTThreadSleep:
|
|---|
| 1596 | 00b55390 55 push ebp
|
|---|
| 1597 | 00b55391 8bec mov ebp,esp
|
|---|
| 1598 | 00b55393 8b4508 mov eax,[ebp+0x8]
|
|---|
| 1599 | 00b55396 50 push eax
|
|---|
| 1600 | 00b55397 ff156812cc00 call dword ptr [VBoxRT!SSLeay+0x1978 (00cc1268)]
|
|---|
| 1601 | 00b5539d 33c0 xor eax,eax
|
|---|
| 1602 | 00b5539f 5d pop ebp
|
|---|
| 1603 | 00b553a0 c3 ret
|
|---|
| 1604 | 00b553a1 cc int 3
|
|---|
| 1605 | 00b553a2 cc int 3
|
|---|
| 1606 | 00b553a3 cc int 3
|
|---|
| 1607 | 00b553a4 cc int 3
|
|---|
| 1608 | 00b553a5 cc int 3
|
|---|
| 1609 | 00b553a6 cc int 3
|
|---|
| 1610 | 00b553a7 cc int 3
|
|---|
| 1611 | 00b553a8 cc int 3
|
|---|
| 1612 | 00b553a9 cc int 3
|
|---|
| 1613 |
|
|---|
| 1614 | *----> Suivi arrière de la pile <----*
|
|---|
| 1615 | WARNING: Stack unwind information not available. Following frames may be wrong.
|
|---|
| 1616 | ChildEBP RetAddr Args to Child
|
|---|
| 1617 | 0f46fee0 10116e70 00000064 0ec30510 00000000 VBoxRT!RTThreadSleep+0xf
|
|---|
| 1618 | 0f46ff04 1003e12b 0b330000 0ec2fc10 0ec30528 VBoxVMM!PDMR3NsBwGroupSetLimit+0xc0
|
|---|
| 1619 | 0f46ff24 00b11523 0ec30510 00000000 0ec30510 VBoxVMM!PDMR3ThreadSleep+0xdb
|
|---|
| 1620 | 0f46ff50 00b5517b 0ec30510 0000081c 0ec30a8c VBoxRT!RTThreadFromNative+0x1e3
|
|---|
| 1621 | 0f46ff70 78afc556 0ec30510 7d3fb953 0ec2a468 VBoxRT!RTSymlinkRead+0x2eb
|
|---|
| 1622 | 0f46ffa8 78afc600 003d0000 0f46ffec 7c80b729 MSVCR100!endthreadex+0x3a
|
|---|
| 1623 | 0f46ffb4 7c80b729 0a52dd10 0ec2a468 003d0000 MSVCR100!endthreadex+0xe4
|
|---|
| 1624 | 0f46ffec 00000000 78afc59c 0a52dd10 00000000 kernel32!GetModuleFileNameA+0x1ba
|
|---|
| 1625 |
|
|---|
| 1626 | *----> Vidage brut de la pile <----*
|
|---|
| 1627 | 000000000f46fee0 04 ff 46 0f 70 6e 11 10 - 64 00 00 00 10 05 c3 0e ..F.pn..d.......
|
|---|
| 1628 | 000000000f46fef0 00 00 00 00 10 fc c2 0e - 10 9a 33 0a c8 fb c2 0e ..........3.....
|
|---|
| 1629 | 000000000f46ff00 10 fc c2 0e 24 ff 46 0f - 2b e1 03 10 00 00 33 0b ....$.F.+.....3.
|
|---|
| 1630 | 000000000f46ff10 10 fc c2 0e 28 05 c3 0e - 10 05 c3 0e 65 9c 80 7c ....(.......e..|
|
|---|
| 1631 | 000000000f46ff20 00 e0 35 0a 50 ff 46 0f - 23 15 b1 00 10 05 c3 0e ..5.P.F.#.......
|
|---|
| 1632 | 000000000f46ff30 00 00 00 00 10 05 c3 0e - 0a 00 00 00 10 05 c3 0e ................
|
|---|
| 1633 | 000000000f46ff40 1c 08 00 00 1c 08 00 00 - 10 05 c3 0e 65 9c 80 7c ............e..|
|
|---|
| 1634 | 000000000f46ff50 70 ff 46 0f 7b 51 b5 00 - 10 05 c3 0e 1c 08 00 00 p.F.{Q..........
|
|---|
| 1635 | 000000000f46ff60 8c 0a c3 0e 68 a4 c2 0e - 00 00 3d 00 10 dd 52 0a ....h.....=...R.
|
|---|
| 1636 | 000000000f46ff70 a8 ff 46 0f 56 c5 af 78 - 10 05 c3 0e 53 b9 3f 7d ..F.V..x....S.?}
|
|---|
| 1637 | 000000000f46ff80 68 a4 c2 0e 00 00 3d 00 - 10 dd 52 0a 7c ff 46 0f h.....=...R.|.F.
|
|---|
| 1638 | 000000000f46ff90 7c ff 46 0f dc ff 46 0f - dc ff 46 0f 5a b6 b2 78 |.F...F...F.Z..x
|
|---|
| 1639 | 000000000f46ffa0 7b 83 d6 0a 00 00 00 00 - b4 ff 46 0f 00 c6 af 78 {.........F....x
|
|---|
| 1640 | 000000000f46ffb0 00 00 3d 00 ec ff 46 0f - 29 b7 80 7c 10 dd 52 0a ..=...F.)..|..R.
|
|---|
| 1641 | 000000000f46ffc0 68 a4 c2 0e 00 00 3d 00 - 10 dd 52 0a 00 20 f4 7f h.....=...R.. ..
|
|---|
| 1642 | 000000000f46ffd0 00 76 4f 8a c0 ff 46 0f - 40 01 8a 88 ff ff ff ff .vO...F.@.......
|
|---|
| 1643 | 000000000f46ffe0 d8 9a 83 7c 30 b7 80 7c - 00 00 00 00 00 00 00 00 ...|0..|........
|
|---|
| 1644 | 000000000f46fff0 00 00 00 00 9c c5 af 78 - 10 dd 52 0a 00 00 00 00 .......x..R.....
|
|---|
| 1645 | 000000000f470000 4d 5a 90 00 03 00 00 00 - 04 00 00 00 ff ff 00 00 MZ..............
|
|---|
| 1646 | 000000000f470010 b8 00 00 00 00 00 00 00 - 40 00 00 00 00 00 00 00 ........@.......
|
|---|
| 1647 |
|
|---|
| 1648 | *----> Vidage de l'état de la thread 0x924 <----*
|
|---|
| 1649 |
|
|---|
| 1650 | eax=00000000 ebx=7c802550 ecx=0000061c edx=0000c000 esi=0000079c edi=00000000
|
|---|
| 1651 | eip=7c91e514 esp=0fecfde8 ebp=0fecfe4c iopl=0 nv up ei pl zr na po nc
|
|---|
| 1652 | cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
|
|---|
| 1653 |
|
|---|
| 1654 | fonction : ntdll!KiFastSystemCallRet
|
|---|
| 1655 | 7c91e4fa e829000000 call ntdll!RtlRaiseException (7c91e528)
|
|---|
| 1656 | 7c91e4ff 8b0424 mov eax,[esp]
|
|---|
| 1657 | 7c91e502 8be5 mov esp,ebp
|
|---|
| 1658 | 7c91e504 5d pop ebp
|
|---|
| 1659 | 7c91e505 c3 ret
|
|---|
| 1660 | 7c91e506 8da42400000000 lea esp,[esp]
|
|---|
| 1661 | 7c91e50d 8d4900 lea ecx,[ecx]
|
|---|
| 1662 | ntdll!KiFastSystemCall:
|
|---|
| 1663 | 7c91e510 8bd4 mov edx,esp
|
|---|
| 1664 | 7c91e512 0f34 sysenter
|
|---|
| 1665 | ntdll!KiFastSystemCallRet:
|
|---|
| 1666 | 7c91e514 c3 ret
|
|---|
| 1667 | 7c91e515 8da42400000000 lea esp,[esp]
|
|---|
| 1668 | 7c91e51c 8d642400 lea esp,[esp]
|
|---|
| 1669 | ntdll!KiIntSystemCall:
|
|---|
| 1670 | 7c91e520 8d542408 lea edx,[esp+0x8]
|
|---|
| 1671 | 7c91e524 cd2e int 2e
|
|---|
| 1672 | 7c91e526 c3 ret
|
|---|
| 1673 | 7c91e527 90 nop
|
|---|
| 1674 | ntdll!RtlRaiseException:
|
|---|
| 1675 | 7c91e528 55 push ebp
|
|---|
| 1676 | 7c91e529 8bec mov ebp,esp
|
|---|
| 1677 |
|
|---|
| 1678 | *----> Suivi arrière de la pile <----*
|
|---|
| 1679 | WARNING: Stack unwind information not available. Following frames may be wrong.
|
|---|
| 1680 | ChildEBP RetAddr Args to Child
|
|---|
| 1681 | 0fecfe4c 00b54365 0000079c ffffffff 00000001 ntdll!KiFastSystemCallRet
|
|---|
| 1682 | 0fecfe78 00b5444a 0ec58ea0 00000050 00000000 VBoxRT!RTSemEventMultiReset+0x1f5
|
|---|
| 1683 | 0fecfe94 00b4801a 0ec58ea0 00000050 00000000 VBoxRT!RTSemEventMultiWaitEx+0x1a
|
|---|
| 1684 | 0fecfeac 0a9068ee 0ec58ea0 ffffffff 0fecff04 VBoxRT!RTSemEventMultiWait+0x1a
|
|---|
| 1685 | 0fecfecc 0a906d27 0fecff04 0ec56180 0954a760 VBoxC!VBoxDriversRegister+0x2c09e
|
|---|
| 1686 | 0fecfee0 0a907bb5 80000030 0fecff04 00000000 VBoxC!VBoxDriversRegister+0x2c4d7
|
|---|
| 1687 | 0fecff08 0a9065a0 80000030 00c56180 0ec58f90 VBoxC!VBoxDriversRegister+0x2d365
|
|---|
| 1688 | 0fecff24 00b11523 0ec58f90 0ec58f00 0ec58f90 VBoxC!VBoxDriversRegister+0x2bd50
|
|---|
| 1689 | 0fecff50 00b5517b 0ec58f90 00000924 0ec5950c VBoxRT!RTThreadFromNative+0x1e3
|
|---|
| 1690 | 0fecff70 78afc556 0ec58f90 7d95b953 003d0178 VBoxRT!RTSymlinkRead+0x2eb
|
|---|
| 1691 | 0fecffa8 78afc600 0a358e28 0fecffec 7c80b729 MSVCR100!endthreadex+0x3a
|
|---|
| 1692 | 0fecffb4 7c80b729 0a52dd10 003d0178 0a358e28 MSVCR100!endthreadex+0xe4
|
|---|
| 1693 | 0fecffec 00000000 78afc59c 0a52dd10 00000000 kernel32!GetModuleFileNameA+0x1ba
|
|---|
| 1694 |
|
|---|
| 1695 | *----> Vidage brut de la pile <----*
|
|---|
| 1696 | 000000000fecfde8 5a df 91 7c db 25 80 7c - 9c 07 00 00 01 00 00 00 Z..|.%.|........
|
|---|
| 1697 | 000000000fecfdf8 00 00 00 00 ff ff ff ff - 10 00 00 00 50 25 80 7c ............P%.|
|
|---|
| 1698 | 000000000fecfe08 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 1699 | 000000000fecfe18 10 00 00 00 00 00 00 00 - 60 a7 54 09 00 80 fd 7f ........`.T.....
|
|---|
| 1700 | 000000000fecfe28 00 10 f4 7f 00 00 00 00 - 00 00 00 00 fc fd ec 0f ................
|
|---|
| 1701 | 000000000fecfe38 a4 5f 90 0a 98 ff ec 0f - d8 9a 83 7c 08 26 80 7c ._.........|.&.|
|
|---|
| 1702 | 000000000fecfe48 00 00 00 00 78 fe ec 0f - 65 43 b5 00 9c 07 00 00 ....x...eC......
|
|---|
| 1703 | 000000000fecfe58 ff ff ff ff 01 00 00 00 - 00 80 b4 00 00 8f c5 0e ................
|
|---|
| 1704 | 000000000fecfe68 70 41 b5 00 ff ff ff ff - ff ff ff ff 90 8f c5 0e pA..............
|
|---|
| 1705 | 000000000fecfe78 94 fe ec 0f 4a 44 b5 00 - a0 8e c5 0e 50 00 00 00 ....JD......P...
|
|---|
| 1706 | 000000000fecfe88 00 00 00 00 00 00 00 00 - 00 00 00 00 ac fe ec 0f ................
|
|---|
| 1707 | 000000000fecfe98 1a 80 b4 00 a0 8e c5 0e - 50 00 00 00 00 00 00 00 ........P.......
|
|---|
| 1708 | 000000000fecfea8 00 00 00 00 cc fe ec 0f - ee 68 90 0a a0 8e c5 0e .........h......
|
|---|
| 1709 | 000000000fecfeb8 ff ff ff ff 04 ff ec 0f - 00 8f c5 0e f8 14 e7 0e ................
|
|---|
| 1710 | 000000000fecfec8 00 8f c5 0e e0 fe ec 0f - 27 6d 90 0a 04 ff ec 0f ........'m......
|
|---|
| 1711 | 000000000fecfed8 80 61 c5 0e 60 a7 54 09 - 08 ff ec 0f b5 7b 90 0a .a..`.T......{..
|
|---|
| 1712 | 000000000fecfee8 30 00 00 80 04 ff ec 0f - 00 00 00 00 00 8f c5 0e 0...............
|
|---|
| 1713 | 000000000fecfef8 65 9c 80 7c e1 19 b1 00 - a8 a7 54 09 60 a7 54 09 e..|......T.`.T.
|
|---|
| 1714 | 000000000fecff08 24 ff ec 0f a0 65 90 0a - 30 00 00 80 80 61 c5 00 $....e..0....a..
|
|---|
| 1715 | 000000000fecff18 90 8f c5 0e a8 8f c5 0e - 90 8f c5 0e 50 ff ec 0f ............P...
|
|---|
| 1716 |
|
|---|
| 1717 | *----> Vidage de l'état de la thread 0xe94 <----*
|
|---|
| 1718 |
|
|---|
| 1719 | eax=00df8ed0 ebx=0ec6b6c0 ecx=00000f48 edx=0022801c esi=00000760 edi=00000000
|
|---|
| 1720 | eip=7c91e514 esp=2039fdf0 ebp=2039fe54 iopl=0 nv up ei pl zr na po nc
|
|---|
| 1721 | cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
|
|---|
| 1722 |
|
|---|
| 1723 | fonction : ntdll!KiFastSystemCallRet
|
|---|
| 1724 | 7c91e4fa e829000000 call ntdll!RtlRaiseException (7c91e528)
|
|---|
| 1725 | 7c91e4ff 8b0424 mov eax,[esp]
|
|---|
| 1726 | 7c91e502 8be5 mov esp,ebp
|
|---|
| 1727 | 7c91e504 5d pop ebp
|
|---|
| 1728 | 7c91e505 c3 ret
|
|---|
| 1729 | 7c91e506 8da42400000000 lea esp,[esp]
|
|---|
| 1730 | 7c91e50d 8d4900 lea ecx,[ecx]
|
|---|
| 1731 | ntdll!KiFastSystemCall:
|
|---|
| 1732 | 7c91e510 8bd4 mov edx,esp
|
|---|
| 1733 | 7c91e512 0f34 sysenter
|
|---|
| 1734 | ntdll!KiFastSystemCallRet:
|
|---|
| 1735 | 7c91e514 c3 ret
|
|---|
| 1736 | 7c91e515 8da42400000000 lea esp,[esp]
|
|---|
| 1737 | 7c91e51c 8d642400 lea esp,[esp]
|
|---|
| 1738 | ntdll!KiIntSystemCall:
|
|---|
| 1739 | 7c91e520 8d542408 lea edx,[esp+0x8]
|
|---|
| 1740 | 7c91e524 cd2e int 2e
|
|---|
| 1741 | 7c91e526 c3 ret
|
|---|
| 1742 | 7c91e527 90 nop
|
|---|
| 1743 | ntdll!RtlRaiseException:
|
|---|
| 1744 | 7c91e528 55 push ebp
|
|---|
| 1745 | 7c91e529 8bec mov ebp,esp
|
|---|
| 1746 |
|
|---|
| 1747 | *----> Suivi arrière de la pile <----*
|
|---|
| 1748 | WARNING: Stack unwind information not available. Following frames may be wrong.
|
|---|
| 1749 | ChildEBP RetAddr Args to Child
|
|---|
| 1750 | 2039fe54 00b53f70 00000760 ffffffff 00000001 ntdll!KiFastSystemCallRet
|
|---|
| 1751 | 2039fe70 00b47f99 0a332a90 ffffffff 0ec6b6e0 VBoxRT!RTSemEventWaitNoResume+0x50
|
|---|
| 1752 | 2039fe8c 101164c6 0a332a90 ffffffff 0ec6bf68 VBoxRT!RTSemEventWait+0x19
|
|---|
| 1753 | 2039ff24 00b11523 0ec6bf50 0ec6b600 0ec6bf50 VBoxVMM!PDMR3AsyncCompletionBwMgrSetMaxForFile+0x31b6
|
|---|
| 1754 | 2039ff50 00b5517b 0ec6bf50 00000e94 0ec6c4cc VBoxRT!RTThreadFromNative+0x1e3
|
|---|
| 1755 | 2039ff70 78afc556 0ec6bf50 5240b953 75000c7e VBoxRT!RTSymlinkRead+0x2eb
|
|---|
| 1756 | 2039ffa8 78afc600 74f68504 2039ffec 7c80b729 MSVCR100!endthreadex+0x3a
|
|---|
| 1757 | 2039ffb4 7c80b729 0a52dd10 75000c7e 74f68504 MSVCR100!endthreadex+0xe4
|
|---|
| 1758 | 2039ffec 00000000 78afc59c 0a52dd10 00000000 kernel32!GetModuleFileNameA+0x1ba
|
|---|
| 1759 |
|
|---|
| 1760 | *----> Vidage brut de la pile <----*
|
|---|
| 1761 | 000000002039fdf0 5a df 91 7c db 25 80 7c - 60 07 00 00 01 00 00 00 Z..|.%.|`.......
|
|---|
| 1762 | 000000002039fe00 00 00 00 00 50 bf c6 0e - 90 2a 33 0a c0 b6 c6 0e ....P....*3.....
|
|---|
| 1763 | 000000002039fe10 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 1764 | 000000002039fe20 10 00 00 00 40 c0 36 0a - 00 00 00 00 00 80 fd 7f ....@.6.........
|
|---|
| 1765 | 000000002039fe30 00 00 f4 7f 00 00 00 00 - 48 ed 86 29 04 fe 39 20 ........H..)..9
|
|---|
| 1766 | 000000002039fe40 7c fe 39 20 98 ff 39 20 - d8 9a 83 7c 08 26 80 7c |.9 ..9 ...|.&.|
|
|---|
| 1767 | 000000002039fe50 00 00 00 00 70 fe 39 20 - 70 3f b5 00 60 07 00 00 ....p.9 p?..`...
|
|---|
| 1768 | 000000002039fe60 ff ff ff ff 01 00 00 00 - e0 b6 c6 0e 90 2a 33 0a .............*3.
|
|---|
| 1769 | 000000002039fe70 8c fe 39 20 99 7f b4 00 - 90 2a 33 0a ff ff ff ff ..9 .....*3.....
|
|---|
| 1770 | 000000002039fe80 e0 b6 c6 0e d4 b6 c6 0e - c0 b6 c6 0e 24 ff 39 20 ............$.9
|
|---|
| 1771 | 000000002039fe90 c6 64 11 10 90 2a 33 0a - ff ff ff ff 68 bf c6 0e .d...*3.....h...
|
|---|
| 1772 | 000000002039fea0 50 bf c6 0e 65 9c 80 7c - 58 0f 47 29 00 00 00 00 P...e..|X.G)....
|
|---|
| 1773 | 000000002039feb0 00 c0 ec 0f 78 ca 69 b8 - 60 f6 07 c0 00 00 00 00 ....x.i.`.......
|
|---|
| 1774 | 000000002039fec0 14 00 00 00 00 00 00 00 - f0 d4 8d 89 d0 6b 4b 96 .............kK.
|
|---|
| 1775 | 000000002039fed0 78 ca 69 b8 ea cf 91 7c - e9 a0 80 7c 58 0f 00 00 x.i....|...|X...
|
|---|
| 1776 | 000000002039fee0 ec fe 39 20 9d 41 b5 00 - 58 0f 00 00 18 ff 39 20 ..9 .A..X.....9
|
|---|
| 1777 | 000000002039fef0 1a dc 91 7c c7 a0 80 7c - 58 0f 00 00 00 00 00 00 ...|...|X.......
|
|---|
| 1778 | 000000002039ff00 e5 77 59 01 00 00 00 00 - 00 00 00 00 d4 b6 c6 0e .wY.............
|
|---|
| 1779 | 000000002039ff10 00 02 00 00 01 00 00 00 - 00 00 00 00 01 ff 39 20 ..............9
|
|---|
| 1780 | 000000002039ff20 01 3d b5 00 50 ff 39 20 - 23 15 b1 00 50 bf c6 0e .=..P.9 #...P...
|
|---|
| 1781 |
|
|---|
| 1782 | *----> Vidage de l'état de la thread 0x23c <----*
|
|---|
| 1783 |
|
|---|
| 1784 | eax=78afc59c ebx=0d81e208 ecx=0b1df7fc edx=003d0178 esi=00000730 edi=00000000
|
|---|
| 1785 | eip=7c91e514 esp=2049fe50 ebp=2049feb4 iopl=0 nv up ei pl zr na po nc
|
|---|
| 1786 | cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
|
|---|
| 1787 |
|
|---|
| 1788 | fonction : ntdll!KiFastSystemCallRet
|
|---|
| 1789 | 7c91e4fa e829000000 call ntdll!RtlRaiseException (7c91e528)
|
|---|
| 1790 | 7c91e4ff 8b0424 mov eax,[esp]
|
|---|
| 1791 | 7c91e502 8be5 mov esp,ebp
|
|---|
| 1792 | 7c91e504 5d pop ebp
|
|---|
| 1793 | 7c91e505 c3 ret
|
|---|
| 1794 | 7c91e506 8da42400000000 lea esp,[esp]
|
|---|
| 1795 | 7c91e50d 8d4900 lea ecx,[ecx]
|
|---|
| 1796 | ntdll!KiFastSystemCall:
|
|---|
| 1797 | 7c91e510 8bd4 mov edx,esp
|
|---|
| 1798 | 7c91e512 0f34 sysenter
|
|---|
| 1799 | ntdll!KiFastSystemCallRet:
|
|---|
| 1800 | 7c91e514 c3 ret
|
|---|
| 1801 | 7c91e515 8da42400000000 lea esp,[esp]
|
|---|
| 1802 | 7c91e51c 8d642400 lea esp,[esp]
|
|---|
| 1803 | ntdll!KiIntSystemCall:
|
|---|
| 1804 | 7c91e520 8d542408 lea edx,[esp+0x8]
|
|---|
| 1805 | 7c91e524 cd2e int 2e
|
|---|
| 1806 | 7c91e526 c3 ret
|
|---|
| 1807 | 7c91e527 90 nop
|
|---|
| 1808 | ntdll!RtlRaiseException:
|
|---|
| 1809 | 7c91e528 55 push ebp
|
|---|
| 1810 | 7c91e529 8bec mov ebp,esp
|
|---|
| 1811 |
|
|---|
| 1812 | *----> Suivi arrière de la pile <----*
|
|---|
| 1813 | WARNING: Stack unwind information not available. Following frames may be wrong.
|
|---|
| 1814 | ChildEBP RetAddr Args to Child
|
|---|
| 1815 | 2049feb4 00b53f70 00000730 ffffffff 00000001 ntdll!KiFastSystemCallRet
|
|---|
| 1816 | 2049fed0 00b47f99 095707f8 ffffffff 00000000 VBoxRT!RTSemEventWaitNoResume+0x50
|
|---|
| 1817 | 2049feec 0f490624 095707f8 ffffffff 0ec9b858 VBoxRT!RTSemEventWait+0x19
|
|---|
| 1818 | 2049ff24 00b11523 0ec9b858 0d81e208 0ec9b858 VBoxDD+0x20624
|
|---|
| 1819 | 2049ff50 00b5517b 0ec9b858 0000023c 0ec9bdd4 VBoxRT!RTThreadFromNative+0x1e3
|
|---|
| 1820 | 2049ff70 78afc556 0ec9b858 5230b953 0017b79e VBoxRT!RTSymlinkRead+0x2eb
|
|---|
| 1821 | 2049ffa8 78afc600 003d0178 2049ffec 7c80b729 MSVCR100!endthreadex+0x3a
|
|---|
| 1822 | 2049ffb4 7c80b729 0a52dd10 0017b79e 003d0178 MSVCR100!endthreadex+0xe4
|
|---|
| 1823 | 2049ffec 00000000 78afc59c 0a52dd10 00000000 kernel32!GetModuleFileNameA+0x1ba
|
|---|
| 1824 |
|
|---|
| 1825 | *----> Vidage brut de la pile <----*
|
|---|
| 1826 | 000000002049fe50 5a df 91 7c db 25 80 7c - 30 07 00 00 01 00 00 00 Z..|.%.|0.......
|
|---|
| 1827 | 000000002049fe60 00 00 00 00 58 b8 c9 0e - f8 07 57 09 08 e2 81 0d ....X.....W.....
|
|---|
| 1828 | 000000002049fe70 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 1829 | 000000002049fe80 10 00 00 00 00 00 00 00 - 00 00 00 00 00 80 fd 7f ................
|
|---|
| 1830 | 000000002049fe90 00 f0 f3 7f 00 00 00 00 - d8 9a 83 7c 64 fe 49 20 ...........|d.I
|
|---|
| 1831 | 000000002049fea0 00 00 00 00 98 ff 49 20 - d8 9a 83 7c 08 26 80 7c ......I ...|.&.|
|
|---|
| 1832 | 000000002049feb0 00 00 00 00 d0 fe 49 20 - 70 3f b5 00 30 07 00 00 ......I p?..0...
|
|---|
| 1833 | 000000002049fec0 ff ff ff ff 01 00 00 00 - 00 00 00 00 f8 07 57 09 ..............W.
|
|---|
| 1834 | 000000002049fed0 ec fe 49 20 99 7f b4 00 - f8 07 57 09 ff ff ff ff ..I ......W.....
|
|---|
| 1835 | 000000002049fee0 00 00 00 00 00 00 00 00 - 08 e2 81 0d 24 ff 49 20 ............$.I
|
|---|
| 1836 | 000000002049fef0 24 06 49 0f f8 07 57 09 - ff ff ff ff 58 b8 c9 0e $.I...W.....X...
|
|---|
| 1837 | 000000002049ff00 70 b8 c9 0e 65 9c 80 7c - d6 c1 80 7c 00 00 00 00 p...e..|...|....
|
|---|
| 1838 | 000000002049ff10 3c 9f 00 00 00 00 00 00 - 04 00 00 00 00 00 00 00 <...............
|
|---|
| 1839 | 000000002049ff20 00 00 00 00 50 ff 49 20 - 23 15 b1 00 58 b8 c9 0e ....P.I #...X...
|
|---|
| 1840 | 000000002049ff30 08 e2 81 0d 58 b8 c9 0e - 0a 00 00 00 58 b8 c9 0e ....X.......X...
|
|---|
| 1841 | 000000002049ff40 3c 02 00 00 3c 02 00 00 - 58 b8 c9 0e 65 9c 80 7c <...<...X...e..|
|
|---|
| 1842 | 000000002049ff50 70 ff 49 20 7b 51 b5 00 - 58 b8 c9 0e 3c 02 00 00 p.I {Q..X...<...
|
|---|
| 1843 | 000000002049ff60 d4 bd c9 0e 9e b7 17 00 - 78 01 3d 00 10 dd 52 0a ........x.=...R.
|
|---|
| 1844 | 000000002049ff70 a8 ff 49 20 56 c5 af 78 - 58 b8 c9 0e 53 b9 30 52 ..I V..xX...S.0R
|
|---|
| 1845 | 000000002049ff80 9e b7 17 00 78 01 3d 00 - 10 dd 52 0a 7c ff 49 20 ....x.=...R.|.I
|
|---|
| 1846 |
|
|---|
| 1847 | *----> Vidage de l'état de la thread 0xb0 <----*
|
|---|
| 1848 |
|
|---|
| 1849 | eax=00000000 ebx=0d81e7f8 ecx=00000000 edx=00000010 esi=00000714 edi=00000000
|
|---|
| 1850 | eip=7c91e514 esp=2059fe50 ebp=2059feb4 iopl=0 nv up ei pl zr na po nc
|
|---|
| 1851 | cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
|
|---|
| 1852 |
|
|---|
| 1853 | fonction : ntdll!KiFastSystemCallRet
|
|---|
| 1854 | 7c91e4fa e829000000 call ntdll!RtlRaiseException (7c91e528)
|
|---|
| 1855 | 7c91e4ff 8b0424 mov eax,[esp]
|
|---|
| 1856 | 7c91e502 8be5 mov esp,ebp
|
|---|
| 1857 | 7c91e504 5d pop ebp
|
|---|
| 1858 | 7c91e505 c3 ret
|
|---|
| 1859 | 7c91e506 8da42400000000 lea esp,[esp]
|
|---|
| 1860 | 7c91e50d 8d4900 lea ecx,[ecx]
|
|---|
| 1861 | ntdll!KiFastSystemCall:
|
|---|
| 1862 | 7c91e510 8bd4 mov edx,esp
|
|---|
| 1863 | 7c91e512 0f34 sysenter
|
|---|
| 1864 | ntdll!KiFastSystemCallRet:
|
|---|
| 1865 | 7c91e514 c3 ret
|
|---|
| 1866 | 7c91e515 8da42400000000 lea esp,[esp]
|
|---|
| 1867 | 7c91e51c 8d642400 lea esp,[esp]
|
|---|
| 1868 | ntdll!KiIntSystemCall:
|
|---|
| 1869 | 7c91e520 8d542408 lea edx,[esp+0x8]
|
|---|
| 1870 | 7c91e524 cd2e int 2e
|
|---|
| 1871 | 7c91e526 c3 ret
|
|---|
| 1872 | 7c91e527 90 nop
|
|---|
| 1873 | ntdll!RtlRaiseException:
|
|---|
| 1874 | 7c91e528 55 push ebp
|
|---|
| 1875 | 7c91e529 8bec mov ebp,esp
|
|---|
| 1876 |
|
|---|
| 1877 | *----> Suivi arrière de la pile <----*
|
|---|
| 1878 | WARNING: Stack unwind information not available. Following frames may be wrong.
|
|---|
| 1879 | ChildEBP RetAddr Args to Child
|
|---|
| 1880 | 2059feb4 00b53f70 00000714 ffffffff 00000001 ntdll!KiFastSystemCallRet
|
|---|
| 1881 | 2059fed0 00b47f99 095701f0 ffffffff 00000000 VBoxRT!RTSemEventWaitNoResume+0x50
|
|---|
| 1882 | 2059feec 0f490624 095701f0 ffffffff 0ec6ea08 VBoxRT!RTSemEventWait+0x19
|
|---|
| 1883 | 2059ff24 00b11523 0ec6ea08 00000000 0ec6ea08 VBoxDD+0x20624
|
|---|
| 1884 | 2059ff50 00b5517b 0ec6ea08 000000b0 0ec6ef84 VBoxRT!RTThreadFromNative+0x1e3
|
|---|
| 1885 | 2059ff70 78afc556 0ec6ea08 5220b953 0017b79e VBoxRT!RTSymlinkRead+0x2eb
|
|---|
| 1886 | 2059ffa8 78afc600 003d0178 2059ffec 7c80b729 MSVCR100!endthreadex+0x3a
|
|---|
| 1887 | 2059ffb4 7c80b729 0a52dd10 0017b79e 003d0178 MSVCR100!endthreadex+0xe4
|
|---|
| 1888 | 2059ffec 00000000 78afc59c 0a52dd10 00000000 kernel32!GetModuleFileNameA+0x1ba
|
|---|
| 1889 |
|
|---|
| 1890 | *----> Vidage brut de la pile <----*
|
|---|
| 1891 | 000000002059fe50 5a df 91 7c db 25 80 7c - 14 07 00 00 01 00 00 00 Z..|.%.|........
|
|---|
| 1892 | 000000002059fe60 00 00 00 00 08 ea c6 0e - f0 01 57 09 f8 e7 81 0d ..........W.....
|
|---|
| 1893 | 000000002059fe70 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 1894 | 000000002059fe80 10 00 00 00 00 80 fd 7f - 00 e0 f3 7f 00 80 fd 7f ................
|
|---|
| 1895 | 000000002059fe90 00 e0 f3 7f 00 00 00 00 - 00 00 00 00 64 fe 59 20 ............d.Y
|
|---|
| 1896 | 000000002059fea0 d8 9a 83 7c 98 ff 59 20 - d8 9a 83 7c 08 26 80 7c ...|..Y ...|.&.|
|
|---|
| 1897 | 000000002059feb0 00 00 00 00 d0 fe 59 20 - 70 3f b5 00 14 07 00 00 ......Y p?......
|
|---|
| 1898 | 000000002059fec0 ff ff ff ff 01 00 00 00 - 00 00 00 00 f0 01 57 09 ..............W.
|
|---|
| 1899 | 000000002059fed0 ec fe 59 20 99 7f b4 00 - f0 01 57 09 ff ff ff ff ..Y ......W.....
|
|---|
| 1900 | 000000002059fee0 00 00 00 00 00 00 00 00 - f8 e7 81 0d 24 ff 59 20 ............$.Y
|
|---|
| 1901 | 000000002059fef0 24 06 49 0f f0 01 57 09 - ff ff ff ff 08 ea c6 0e $.I...W.........
|
|---|
| 1902 | 000000002059ff00 20 ea c6 0e 65 9c 80 7c - d6 c1 80 7c 00 00 00 00 ...e..|...|....
|
|---|
| 1903 | 000000002059ff10 a3 55 01 00 00 00 00 00 - 00 00 00 00 00 00 00 00 .U..............
|
|---|
| 1904 | 000000002059ff20 00 00 00 00 50 ff 59 20 - 23 15 b1 00 08 ea c6 0e ....P.Y #.......
|
|---|
| 1905 | 000000002059ff30 00 00 00 00 08 ea c6 0e - 0a 00 00 00 08 ea c6 0e ................
|
|---|
| 1906 | 000000002059ff40 b0 00 00 00 b0 00 00 00 - 08 ea c6 0e 65 9c 80 7c ............e..|
|
|---|
| 1907 | 000000002059ff50 70 ff 59 20 7b 51 b5 00 - 08 ea c6 0e b0 00 00 00 p.Y {Q..........
|
|---|
| 1908 | 000000002059ff60 84 ef c6 0e 9e b7 17 00 - 78 01 3d 00 10 dd 52 0a ........x.=...R.
|
|---|
| 1909 | 000000002059ff70 a8 ff 59 20 56 c5 af 78 - 08 ea c6 0e 53 b9 20 52 ..Y V..x....S. R
|
|---|
| 1910 | 000000002059ff80 9e b7 17 00 78 01 3d 00 - 10 dd 52 0a 7c ff 59 20 ....x.=...R.|.Y
|
|---|
| 1911 |
|
|---|
| 1912 | *----> Vidage de l'état de la thread 0x67c <----*
|
|---|
| 1913 |
|
|---|
| 1914 | eax=2fd8fff7 ebx=00b47f80 ecx=2290be38 edx=000000d8 esi=0000063c edi=00000000
|
|---|
| 1915 | eip=7c91e514 esp=2290fe4c ebp=2290feb0 iopl=0 nv up ei pl zr na po nc
|
|---|
| 1916 | cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
|
|---|
| 1917 |
|
|---|
| 1918 | fonction : ntdll!KiFastSystemCallRet
|
|---|
| 1919 | 7c91e4fa e829000000 call ntdll!RtlRaiseException (7c91e528)
|
|---|
| 1920 | 7c91e4ff 8b0424 mov eax,[esp]
|
|---|
| 1921 | 7c91e502 8be5 mov esp,ebp
|
|---|
| 1922 | 7c91e504 5d pop ebp
|
|---|
| 1923 | 7c91e505 c3 ret
|
|---|
| 1924 | 7c91e506 8da42400000000 lea esp,[esp]
|
|---|
| 1925 | 7c91e50d 8d4900 lea ecx,[ecx]
|
|---|
| 1926 | ntdll!KiFastSystemCall:
|
|---|
| 1927 | 7c91e510 8bd4 mov edx,esp
|
|---|
| 1928 | 7c91e512 0f34 sysenter
|
|---|
| 1929 | ntdll!KiFastSystemCallRet:
|
|---|
| 1930 | 7c91e514 c3 ret
|
|---|
| 1931 | 7c91e515 8da42400000000 lea esp,[esp]
|
|---|
| 1932 | 7c91e51c 8d642400 lea esp,[esp]
|
|---|
| 1933 | ntdll!KiIntSystemCall:
|
|---|
| 1934 | 7c91e520 8d542408 lea edx,[esp+0x8]
|
|---|
| 1935 | 7c91e524 cd2e int 2e
|
|---|
| 1936 | 7c91e526 c3 ret
|
|---|
| 1937 | 7c91e527 90 nop
|
|---|
| 1938 | ntdll!RtlRaiseException:
|
|---|
| 1939 | 7c91e528 55 push ebp
|
|---|
| 1940 | 7c91e529 8bec mov ebp,esp
|
|---|
| 1941 |
|
|---|
| 1942 | *----> Suivi arrière de la pile <----*
|
|---|
| 1943 | WARNING: Stack unwind information not available. Following frames may be wrong.
|
|---|
| 1944 | ChildEBP RetAddr Args to Child
|
|---|
| 1945 | 2290feb0 00b53f70 0000063c ffffffff 00000001 ntdll!KiFastSystemCallRet
|
|---|
| 1946 | 2290fecc 00b47f99 0a355868 ffffffff 00b0f260 VBoxRT!RTSemEventWaitNoResume+0x50
|
|---|
| 1947 | 2290fee8 0f51726a 0a355868 ffffffff 0eca6718 VBoxRT!RTSemEventWait+0x19
|
|---|
| 1948 | 2290ff04 1003e11c 00000000 0eca6718 0eca6798 VBoxDD+0xa726a
|
|---|
| 1949 | 2290ff24 00b11523 0eca6780 00000000 0eca6780 VBoxVMM!PDMR3ThreadSleep+0xcc
|
|---|
| 1950 | 2290ff50 00b5517b 0eca6780 0000067c 0eca6cfc VBoxRT!RTThreadFromNative+0x1e3
|
|---|
| 1951 | 2290ff70 78afc556 0eca6780 50e9b953 ffffff00 VBoxRT!RTSymlinkRead+0x2eb
|
|---|
| 1952 | 2290ffa8 78afc600 00640041 2290ffec 7c80b729 MSVCR100!endthreadex+0x3a
|
|---|
| 1953 | 2290ffb4 7c80b729 0a52dd10 ffffff00 00640041 MSVCR100!endthreadex+0xe4
|
|---|
| 1954 | 2290ffec 00000000 78afc59c 0a52dd10 00000000 kernel32!GetModuleFileNameA+0x1ba
|
|---|
| 1955 |
|
|---|
| 1956 | *----> Vidage brut de la pile <----*
|
|---|
| 1957 | 000000002290fe4c 5a df 91 7c db 25 80 7c - 3c 06 00 00 01 00 00 00 Z..|.%.|<.......
|
|---|
| 1958 | 000000002290fe5c 00 00 00 00 80 67 ca 0e - 68 58 35 0a 80 7f b4 00 .....g..hX5.....
|
|---|
| 1959 | 000000002290fe6c 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 1960 | 000000002290fe7c 10 00 00 00 98 ff 90 22 - d8 9a 83 7c 00 80 fd 7f ......."...|....
|
|---|
| 1961 | 000000002290fe8c 00 d0 f3 7f 00 00 00 00 - ac fe 90 22 60 fe 90 22 ..........."`.."
|
|---|
| 1962 | 000000002290fe9c 01 67 ca 0e 98 ff 90 22 - d8 9a 83 7c 08 26 80 7c .g....."...|.&.|
|
|---|
| 1963 | 000000002290feac 00 00 00 00 cc fe 90 22 - 70 3f b5 00 3c 06 00 00 ......."p?..<...
|
|---|
| 1964 | 000000002290febc ff ff ff ff 01 00 00 00 - 60 f2 b0 00 68 58 35 0a ........`...hX5.
|
|---|
| 1965 | 000000002290fecc e8 fe 90 22 99 7f b4 00 - 68 58 35 0a ff ff ff ff ..."....hX5.....
|
|---|
| 1966 | 000000002290fedc 60 f2 b0 00 70 34 34 0a - 80 7f b4 00 04 ff 90 22 `...p44........"
|
|---|
| 1967 | 000000002290feec 6a 72 51 0f 68 58 35 0a - ff ff ff ff 18 67 ca 0e jrQ.hX5......g..
|
|---|
| 1968 | 000000002290fefc 00 00 00 00 80 67 ca 0e - 24 ff 90 22 1c e1 03 10 .....g..$.."....
|
|---|
| 1969 | 000000002290ff0c 00 00 00 00 18 67 ca 0e - 98 67 ca 0e 80 67 ca 0e .....g...g...g..
|
|---|
| 1970 | 000000002290ff1c 65 9c 80 7c 00 e0 35 0a - 50 ff 90 22 23 15 b1 00 e..|..5.P.."#...
|
|---|
| 1971 | 000000002290ff2c 80 67 ca 0e 00 00 00 00 - 80 67 ca 0e 0a 00 00 00 .g.......g......
|
|---|
| 1972 | 000000002290ff3c 80 67 ca 0e 7c 06 00 00 - 7c 06 00 00 80 67 ca 0e .g..|...|....g..
|
|---|
| 1973 | 000000002290ff4c 65 9c 80 7c 70 ff 90 22 - 7b 51 b5 00 80 67 ca 0e e..|p.."{Q...g..
|
|---|
| 1974 | 000000002290ff5c 7c 06 00 00 fc 6c ca 0e - 00 ff ff ff 41 00 64 00 |....l......A.d.
|
|---|
| 1975 | 000000002290ff6c 10 dd 52 0a a8 ff 90 22 - 56 c5 af 78 80 67 ca 0e ..R...."V..x.g..
|
|---|
| 1976 | 000000002290ff7c 53 b9 e9 50 00 ff ff ff - 41 00 64 00 10 dd 52 0a S..P....A.d...R.
|
|---|
| 1977 |
|
|---|
| 1978 | *----> Vidage de l'état de la thread 0xe4 <----*
|
|---|
| 1979 |
|
|---|
| 1980 | eax=22a0b000 ebx=00b47f80 ecx=22a0be20 edx=d0270001 esi=00000638 edi=00000000
|
|---|
| 1981 | eip=7c91e514 esp=22a0fe4c ebp=22a0feb0 iopl=0 nv up ei pl zr na po nc
|
|---|
| 1982 | cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
|
|---|
| 1983 |
|
|---|
| 1984 | fonction : ntdll!KiFastSystemCallRet
|
|---|
| 1985 | 7c91e4fa e829000000 call ntdll!RtlRaiseException (7c91e528)
|
|---|
| 1986 | 7c91e4ff 8b0424 mov eax,[esp]
|
|---|
| 1987 | 7c91e502 8be5 mov esp,ebp
|
|---|
| 1988 | 7c91e504 5d pop ebp
|
|---|
| 1989 | 7c91e505 c3 ret
|
|---|
| 1990 | 7c91e506 8da42400000000 lea esp,[esp]
|
|---|
| 1991 | 7c91e50d 8d4900 lea ecx,[ecx]
|
|---|
| 1992 | ntdll!KiFastSystemCall:
|
|---|
| 1993 | 7c91e510 8bd4 mov edx,esp
|
|---|
| 1994 | 7c91e512 0f34 sysenter
|
|---|
| 1995 | ntdll!KiFastSystemCallRet:
|
|---|
| 1996 | 7c91e514 c3 ret
|
|---|
| 1997 | 7c91e515 8da42400000000 lea esp,[esp]
|
|---|
| 1998 | 7c91e51c 8d642400 lea esp,[esp]
|
|---|
| 1999 | ntdll!KiIntSystemCall:
|
|---|
| 2000 | 7c91e520 8d542408 lea edx,[esp+0x8]
|
|---|
| 2001 | 7c91e524 cd2e int 2e
|
|---|
| 2002 | 7c91e526 c3 ret
|
|---|
| 2003 | 7c91e527 90 nop
|
|---|
| 2004 | ntdll!RtlRaiseException:
|
|---|
| 2005 | 7c91e528 55 push ebp
|
|---|
| 2006 | 7c91e529 8bec mov ebp,esp
|
|---|
| 2007 |
|
|---|
| 2008 | *----> Suivi arrière de la pile <----*
|
|---|
| 2009 | WARNING: Stack unwind information not available. Following frames may be wrong.
|
|---|
| 2010 | ChildEBP RetAddr Args to Child
|
|---|
| 2011 | 22a0feb0 00b53f70 00000638 ffffffff 00000001 ntdll!KiFastSystemCallRet
|
|---|
| 2012 | 22a0fecc 00b47f99 0a355940 ffffffff 00b0f260 VBoxRT!RTSemEventWaitNoResume+0x50
|
|---|
| 2013 | 22a0fee8 0f5172fa 0a355940 ffffffff 0eca6f58 VBoxRT!RTSemEventWait+0x19
|
|---|
| 2014 | 22a0ff04 1003e11c 00000000 0eca6f58 0eca6ff8 VBoxDD+0xa72fa
|
|---|
| 2015 | 22a0ff24 00b11523 0eca6fe0 00000000 0eca6fe0 VBoxVMM!PDMR3ThreadSleep+0xcc
|
|---|
| 2016 | 22a0ff50 00b5517b 0eca6fe0 000000e4 0eca755c VBoxRT!RTThreadFromNative+0x1e3
|
|---|
| 2017 | 22a0ff70 78afc556 0eca6fe0 50d9b953 ffffff00 VBoxRT!RTSymlinkRead+0x2eb
|
|---|
| 2018 | 22a0ffa8 78afc600 00640041 22a0ffec 7c80b729 MSVCR100!endthreadex+0x3a
|
|---|
| 2019 | 22a0ffb4 7c80b729 0a52dd10 ffffff00 00640041 MSVCR100!endthreadex+0xe4
|
|---|
| 2020 | 22a0ffec 00000000 78afc59c 0a52dd10 00000000 kernel32!GetModuleFileNameA+0x1ba
|
|---|
| 2021 |
|
|---|
| 2022 | *----> Vidage brut de la pile <----*
|
|---|
| 2023 | 0000000022a0fe4c 5a df 91 7c db 25 80 7c - 38 06 00 00 01 00 00 00 Z..|.%.|8.......
|
|---|
| 2024 | 0000000022a0fe5c 00 00 00 00 e0 6f ca 0e - 40 59 35 0a 80 7f b4 00 .....o..@Y5.....
|
|---|
| 2025 | 0000000022a0fe6c 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 2026 | 0000000022a0fe7c 10 00 00 00 98 ff a0 22 - d8 9a 83 7c 00 80 fd 7f ......."...|....
|
|---|
| 2027 | 0000000022a0fe8c 00 c0 f3 7f 00 00 00 00 - ac fe a0 22 60 fe a0 22 ..........."`.."
|
|---|
| 2028 | 0000000022a0fe9c 01 6f ca 0e 98 ff a0 22 - d8 9a 83 7c 08 26 80 7c .o....."...|.&.|
|
|---|
| 2029 | 0000000022a0feac 00 00 00 00 cc fe a0 22 - 70 3f b5 00 38 06 00 00 ......."p?..8...
|
|---|
| 2030 | 0000000022a0febc ff ff ff ff 01 00 00 00 - 60 f2 b0 00 40 59 35 0a ........`...@Y5.
|
|---|
| 2031 | 0000000022a0fecc e8 fe a0 22 99 7f b4 00 - 40 59 35 0a ff ff ff ff ..."....@Y5.....
|
|---|
| 2032 | 0000000022a0fedc 60 f2 b0 00 70 34 34 0a - 80 7f b4 00 04 ff a0 22 `...p44........"
|
|---|
| 2033 | 0000000022a0feec fa 72 51 0f 40 59 35 0a - ff ff ff ff 58 6f ca 0e .rQ.@Y5.....Xo..
|
|---|
| 2034 | 0000000022a0fefc 00 00 00 00 e0 6f ca 0e - 24 ff a0 22 1c e1 03 10 .....o..$.."....
|
|---|
| 2035 | 0000000022a0ff0c 00 00 00 00 58 6f ca 0e - f8 6f ca 0e e0 6f ca 0e ....Xo...o...o..
|
|---|
| 2036 | 0000000022a0ff1c 65 9c 80 7c 00 e0 35 0a - 50 ff a0 22 23 15 b1 00 e..|..5.P.."#...
|
|---|
| 2037 | 0000000022a0ff2c e0 6f ca 0e 00 00 00 00 - e0 6f ca 0e 0a 00 00 00 .o.......o......
|
|---|
| 2038 | 0000000022a0ff3c e0 6f ca 0e e4 00 00 00 - e4 00 00 00 e0 6f ca 0e .o...........o..
|
|---|
| 2039 | 0000000022a0ff4c 65 9c 80 7c 70 ff a0 22 - 7b 51 b5 00 e0 6f ca 0e e..|p.."{Q...o..
|
|---|
| 2040 | 0000000022a0ff5c e4 00 00 00 5c 75 ca 0e - 00 ff ff ff 41 00 64 00 ....\u......A.d.
|
|---|
| 2041 | 0000000022a0ff6c 10 dd 52 0a a8 ff a0 22 - 56 c5 af 78 e0 6f ca 0e ..R...."V..x.o..
|
|---|
| 2042 | 0000000022a0ff7c 53 b9 d9 50 00 ff ff ff - 41 00 64 00 10 dd 52 0a S..P....A.d...R.
|
|---|
| 2043 |
|
|---|
| 2044 | *----> Vidage de l'état de la thread 0xd94 <----*
|
|---|
| 2045 |
|
|---|
| 2046 | eax=43712983 ebx=22b0fe60 ecx=093a5fb0 edx=0b8a2de0 esi=00000000 edi=7ffd8000
|
|---|
| 2047 | eip=7c91e514 esp=22b0fe38 ebp=22b0fed4 iopl=0 nv up ei pl zr na po nc
|
|---|
| 2048 | cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
|
|---|
| 2049 |
|
|---|
| 2050 | fonction : ntdll!KiFastSystemCallRet
|
|---|
| 2051 | 7c91e4fa e829000000 call ntdll!RtlRaiseException (7c91e528)
|
|---|
| 2052 | 7c91e4ff 8b0424 mov eax,[esp]
|
|---|
| 2053 | 7c91e502 8be5 mov esp,ebp
|
|---|
| 2054 | 7c91e504 5d pop ebp
|
|---|
| 2055 | 7c91e505 c3 ret
|
|---|
| 2056 | 7c91e506 8da42400000000 lea esp,[esp]
|
|---|
| 2057 | 7c91e50d 8d4900 lea ecx,[ecx]
|
|---|
| 2058 | ntdll!KiFastSystemCall:
|
|---|
| 2059 | 7c91e510 8bd4 mov edx,esp
|
|---|
| 2060 | 7c91e512 0f34 sysenter
|
|---|
| 2061 | ntdll!KiFastSystemCallRet:
|
|---|
| 2062 | 7c91e514 c3 ret
|
|---|
| 2063 | 7c91e515 8da42400000000 lea esp,[esp]
|
|---|
| 2064 | 7c91e51c 8d642400 lea esp,[esp]
|
|---|
| 2065 | ntdll!KiIntSystemCall:
|
|---|
| 2066 | 7c91e520 8d542408 lea edx,[esp+0x8]
|
|---|
| 2067 | 7c91e524 cd2e int 2e
|
|---|
| 2068 | 7c91e526 c3 ret
|
|---|
| 2069 | 7c91e527 90 nop
|
|---|
| 2070 | ntdll!RtlRaiseException:
|
|---|
| 2071 | 7c91e528 55 push ebp
|
|---|
| 2072 | 7c91e529 8bec mov ebp,esp
|
|---|
| 2073 |
|
|---|
| 2074 | *----> Suivi arrière de la pile <----*
|
|---|
| 2075 | WARNING: Stack unwind information not available. Following frames may be wrong.
|
|---|
| 2076 | ChildEBP RetAddr Args to Child
|
|---|
| 2077 | 22b0fed4 0f5179a6 00000003 0ec9c968 00000000 ntdll!KiFastSystemCallRet
|
|---|
| 2078 | 22b0ff04 1003e11c 00000003 0eca7810 0eca78b0 VBoxDD+0xa79a6
|
|---|
| 2079 | 22b0ff24 00b11523 0eca7898 00000000 0eca7898 VBoxVMM!PDMR3ThreadSleep+0xcc
|
|---|
| 2080 | 22b0ff50 00b5517b 0eca7898 00000d94 0eca7e14 VBoxRT!RTThreadFromNative+0x1e3
|
|---|
| 2081 | 22b0ff70 78afc556 0eca7898 50c9b953 00000038 VBoxRT!RTSymlinkRead+0x2eb
|
|---|
| 2082 | 22b0ffa8 78afc600 00000020 22b0ffec 7c80b729 MSVCR100!endthreadex+0x3a
|
|---|
| 2083 | 22b0ffb4 7c80b729 0a52dd10 00000038 00000020 MSVCR100!endthreadex+0xe4
|
|---|
| 2084 | 22b0ffec 00000000 78afc59c 0a52dd10 00000000 kernel32!GetModuleFileNameA+0x1ba
|
|---|
| 2085 |
|
|---|
| 2086 | *----> Vidage brut de la pile <----*
|
|---|
| 2087 | 0000000022b0fe38 4a df 91 7c 90 95 80 7c - 03 00 00 00 60 fe b0 22 J..|...|....`.."
|
|---|
| 2088 | 0000000022b0fe48 01 00 00 00 00 00 00 00 - 94 fe b0 22 01 00 00 00 ..........."....
|
|---|
| 2089 | 0000000022b0fe58 10 35 34 0a 10 78 ca 0e - e0 06 00 00 2c 06 00 00 .54..x......,...
|
|---|
| 2090 | 0000000022b0fe68 e8 06 00 00 e8 06 00 00 - df 1f 00 00 9c fe b0 22 ..............."
|
|---|
| 2091 | 0000000022b0fe78 80 65 99 71 c0 27 8a 0b - 14 00 00 00 01 00 00 00 .e.q.'..........
|
|---|
| 2092 | 0000000022b0fe88 00 00 00 00 00 00 00 00 - 10 00 00 00 00 98 3b 9e ..............;.
|
|---|
| 2093 | 0000000022b0fe98 f7 ff ff ff c0 fe b0 22 - 00 80 fd 7f 00 b0 f3 7f ......."........
|
|---|
| 2094 | 0000000022b0fea8 d0 5e 3a 09 94 fe b0 22 - 60 fe b0 22 08 c0 c9 0e .^:...."`.."....
|
|---|
| 2095 | 0000000022b0feb8 03 00 00 00 54 fe b0 22 - e0 fe b0 22 98 ff b0 22 ....T.."..."..."
|
|---|
| 2096 | 0000000022b0fec8 d8 9a 83 7c 80 96 80 7c - 00 00 00 00 04 ff b0 22 ...|...|......."
|
|---|
| 2097 | 0000000022b0fed8 a6 79 51 0f 03 00 00 00 - 68 c9 c9 0e 00 00 00 00 .yQ.....h.......
|
|---|
| 2098 | 0000000022b0fee8 80 ee 36 00 00 00 00 00 - 10 78 ca 0e 98 78 ca 0e ..6......x...x..
|
|---|
| 2099 | 0000000022b0fef8 00 00 00 00 68 c9 c9 0e - 6b 00 00 00 24 ff b0 22 ....h...k...$.."
|
|---|
| 2100 | 0000000022b0ff08 1c e1 03 10 03 00 00 00 - 10 78 ca 0e b0 78 ca 0e .........x...x..
|
|---|
| 2101 | 0000000022b0ff18 98 78 ca 0e 65 9c 80 7c - 00 e0 35 0a 50 ff b0 22 .x..e..|..5.P.."
|
|---|
| 2102 | 0000000022b0ff28 23 15 b1 00 98 78 ca 0e - 00 00 00 00 98 78 ca 0e #....x.......x..
|
|---|
| 2103 | 0000000022b0ff38 0a 00 00 00 98 78 ca 0e - 94 0d 00 00 94 0d 00 00 .....x..........
|
|---|
| 2104 | 0000000022b0ff48 98 78 ca 0e 65 9c 80 7c - 70 ff b0 22 7b 51 b5 00 .x..e..|p.."{Q..
|
|---|
| 2105 | 0000000022b0ff58 98 78 ca 0e 94 0d 00 00 - 14 7e ca 0e 38 00 00 00 .x.......~..8...
|
|---|
| 2106 | 0000000022b0ff68 20 00 00 00 10 dd 52 0a - a8 ff b0 22 56 c5 af 78 .....R...."V..x
|
|---|
| 2107 |
|
|---|
| 2108 | *----> Vidage de l'état de la thread 0xb8c <----*
|
|---|
| 2109 |
|
|---|
| 2110 | eax=73e6b2a1 ebx=0bfebe90 ecx=ffffffff edx=7c926e90 esi=00000000 edi=7ffd8000
|
|---|
| 2111 | eip=7c91e514 esp=22c1fd88 ebp=22c1fe24 iopl=0 nv up ei pl zr na po nc
|
|---|
| 2112 | cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
|
|---|
| 2113 |
|
|---|
| 2114 | fonction : ntdll!KiFastSystemCallRet
|
|---|
| 2115 | 7c91e4fa e829000000 call ntdll!RtlRaiseException (7c91e528)
|
|---|
| 2116 | 7c91e4ff 8b0424 mov eax,[esp]
|
|---|
| 2117 | 7c91e502 8be5 mov esp,ebp
|
|---|
| 2118 | 7c91e504 5d pop ebp
|
|---|
| 2119 | 7c91e505 c3 ret
|
|---|
| 2120 | 7c91e506 8da42400000000 lea esp,[esp]
|
|---|
| 2121 | 7c91e50d 8d4900 lea ecx,[ecx]
|
|---|
| 2122 | ntdll!KiFastSystemCall:
|
|---|
| 2123 | 7c91e510 8bd4 mov edx,esp
|
|---|
| 2124 | 7c91e512 0f34 sysenter
|
|---|
| 2125 | ntdll!KiFastSystemCallRet:
|
|---|
| 2126 | 7c91e514 c3 ret
|
|---|
| 2127 | 7c91e515 8da42400000000 lea esp,[esp]
|
|---|
| 2128 | 7c91e51c 8d642400 lea esp,[esp]
|
|---|
| 2129 | ntdll!KiIntSystemCall:
|
|---|
| 2130 | 7c91e520 8d542408 lea edx,[esp+0x8]
|
|---|
| 2131 | 7c91e524 cd2e int 2e
|
|---|
| 2132 | 7c91e526 c3 ret
|
|---|
| 2133 | 7c91e527 90 nop
|
|---|
| 2134 | ntdll!RtlRaiseException:
|
|---|
| 2135 | 7c91e528 55 push ebp
|
|---|
| 2136 | 7c91e529 8bec mov ebp,esp
|
|---|
| 2137 |
|
|---|
| 2138 | *----> Suivi arrière de la pile <----*
|
|---|
| 2139 | WARNING: Stack unwind information not available. Following frames may be wrong.
|
|---|
| 2140 | ChildEBP RetAddr Args to Child
|
|---|
| 2141 | 22c1fe24 7c80a115 00000040 22c1fe78 00000000 ntdll!KiFastSystemCallRet
|
|---|
| 2142 | 22c1fe40 73e614a2 00000040 22c1fe78 00000000 kernel32!WaitForMultipleObjects+0x18
|
|---|
| 2143 | 22c1fe58 73e62862 00000040 ffffffff 00000000 dsound+0x14a2
|
|---|
| 2144 | 22c1ff78 73e698df ffffffff 0000003f 22b14f30 dsound+0x2862
|
|---|
| 2145 | 22c1ff98 73e62896 00000000 22b14ee4 73e6b2e9 dsound!DirectSoundCreate+0x51a4
|
|---|
| 2146 | 22c1ffb4 7c80b729 22b14ee4 00000000 0b1df8e4 dsound+0x2896
|
|---|
| 2147 | 22c1ffec 00000000 73e6b2a1 22b14ee4 00000000 kernel32!GetModuleFileNameA+0x1ba
|
|---|
| 2148 |
|
|---|
| 2149 | *----> Vidage brut de la pile <----*
|
|---|
| 2150 | 0000000022c1fd88 4a df 91 7c 90 95 80 7c - 40 00 00 00 90 be fe 0b J..|...|@.......
|
|---|
| 2151 | 0000000022c1fd98 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
|
|---|
| 2152 | 0000000022c1fda8 40 00 00 00 01 00 00 00 - 80 3c 2a 89 00 00 00 00 @........<*.....
|
|---|
| 2153 | 0000000022c1fdb8 00 00 00 00 00 00 00 00 - 38 00 00 00 23 00 00 00 ........8...#...
|
|---|
| 2154 | 0000000022c1fdc8 23 00 00 00 00 00 00 00 - 14 00 00 00 01 00 00 00 #...............
|
|---|
| 2155 | 0000000022c1fdd8 00 00 00 00 00 00 00 00 - 10 00 00 00 08 6e 92 7c .............n.|
|
|---|
| 2156 | 0000000022c1fde8 f9 06 81 7c 1b 00 00 00 - 00 80 fd 7f 00 a0 f3 7f ...|............
|
|---|
| 2157 | 0000000022c1fdf8 00 a0 f3 7f 00 00 00 00 - 90 be fe 0b 00 0d db ba ................
|
|---|
| 2158 | 0000000022c1fe08 40 00 00 00 a4 fd c1 22 - 00 00 00 00 dc ff c1 22 @......"......."
|
|---|
| 2159 | 0000000022c1fe18 d8 9a 83 7c 80 96 80 7c - 00 00 00 00 40 fe c1 22 ...|...|....@.."
|
|---|
| 2160 | 0000000022c1fe28 15 a1 80 7c 40 00 00 00 - 78 fe c1 22 00 00 00 00 ...|@...x.."....
|
|---|
| 2161 | 0000000022c1fe38 ff ff ff ff 00 00 00 00 - 58 fe c1 22 a2 14 e6 73 ........X.."...s
|
|---|
| 2162 | 0000000022c1fe48 40 00 00 00 78 fe c1 22 - 00 00 00 00 ff ff ff ff @...x.."........
|
|---|
| 2163 | 0000000022c1fe58 78 ff c1 22 62 28 e6 73 - 40 00 00 00 ff ff ff ff x.."b(.s@.......
|
|---|
| 2164 | 0000000022c1fe68 00 00 00 00 78 fe c1 22 - e4 4e b1 22 e4 4e b1 22 ....x..".N.".N."
|
|---|
| 2165 | 0000000022c1fe78 dc 04 00 00 f4 05 00 00 - e8 05 00 00 d0 05 00 00 ................
|
|---|
| 2166 | 0000000022c1fe88 c8 05 00 00 cc 05 00 00 - c4 05 00 00 c0 05 00 00 ................
|
|---|
| 2167 | 0000000022c1fe98 bc 05 00 00 b8 05 00 00 - b4 05 00 00 b0 05 00 00 ................
|
|---|
| 2168 | 0000000022c1fea8 ac 05 00 00 a8 05 00 00 - a4 05 00 00 a0 05 00 00 ................
|
|---|
| 2169 | 0000000022c1feb8 9c 05 00 00 98 05 00 00 - 94 05 00 00 90 05 00 00 ................
|
|---|
| 2170 |
|
|---|
| 2171 | *----> Vidage de l'état de la thread 0xa8c <----*
|
|---|
| 2172 |
|
|---|
| 2173 | eax=2e310004 ebx=22e1fdb8 ecx=22e1fe60 edx=7c91e514 esi=00000000 edi=7ffd8000
|
|---|
| 2174 | eip=7c91e514 esp=22e1fd90 ebp=22e1fe2c iopl=0 nv up ei pl zr na po nc
|
|---|
| 2175 | cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
|
|---|
| 2176 |
|
|---|
| 2177 | fonction : ntdll!KiFastSystemCallRet
|
|---|
| 2178 | 7c91e4fa e829000000 call ntdll!RtlRaiseException (7c91e528)
|
|---|
| 2179 | 7c91e4ff 8b0424 mov eax,[esp]
|
|---|
| 2180 | 7c91e502 8be5 mov esp,ebp
|
|---|
| 2181 | 7c91e504 5d pop ebp
|
|---|
| 2182 | 7c91e505 c3 ret
|
|---|
| 2183 | 7c91e506 8da42400000000 lea esp,[esp]
|
|---|
| 2184 | 7c91e50d 8d4900 lea ecx,[ecx]
|
|---|
| 2185 | ntdll!KiFastSystemCall:
|
|---|
| 2186 | 7c91e510 8bd4 mov edx,esp
|
|---|
| 2187 | 7c91e512 0f34 sysenter
|
|---|
| 2188 | ntdll!KiFastSystemCallRet:
|
|---|
| 2189 | 7c91e514 c3 ret
|
|---|
| 2190 | 7c91e515 8da42400000000 lea esp,[esp]
|
|---|
| 2191 | 7c91e51c 8d642400 lea esp,[esp]
|
|---|
| 2192 | ntdll!KiIntSystemCall:
|
|---|
| 2193 | 7c91e520 8d542408 lea edx,[esp+0x8]
|
|---|
| 2194 | 7c91e524 cd2e int 2e
|
|---|
| 2195 | 7c91e526 c3 ret
|
|---|
| 2196 | 7c91e527 90 nop
|
|---|
| 2197 | ntdll!RtlRaiseException:
|
|---|
| 2198 | 7c91e528 55 push ebp
|
|---|
| 2199 | 7c91e529 8bec mov ebp,esp
|
|---|
| 2200 |
|
|---|
| 2201 | *----> Suivi arrière de la pile <----*
|
|---|
| 2202 | WARNING: Stack unwind information not available. Following frames may be wrong.
|
|---|
| 2203 | ChildEBP RetAddr Args to Child
|
|---|
| 2204 | 22e1fe2c 7c80a115 00000001 22e1fe80 00000000 ntdll!KiFastSystemCallRet
|
|---|
| 2205 | 22e1fe48 73e614a2 00000001 22e1fe80 00000000 kernel32!WaitForMultipleObjects+0x18
|
|---|
| 2206 | 22e1fe60 73e62862 00000001 000001f4 00000000 dsound+0x14a2
|
|---|
| 2207 | 22e1ff80 73e6292b 000001f4 00000000 00000000 dsound+0x2862
|
|---|
| 2208 | 22e1ffb4 7c80b729 22b11efc 01000001 0b1df6dc dsound+0x292b
|
|---|
| 2209 | 22e1ffec 00000000 73e6b2a1 22b11efc 00000000 kernel32!GetModuleFileNameA+0x1ba
|
|---|
| 2210 |
|
|---|
| 2211 | *----> Vidage brut de la pile <----*
|
|---|
| 2212 | 0000000022e1fd90 4a df 91 7c 90 95 80 7c - 01 00 00 00 b8 fd e1 22 J..|...|......."
|
|---|
| 2213 | 0000000022e1fda0 01 00 00 00 00 00 00 00 - ec fd e1 22 00 00 00 00 ..........."....
|
|---|
| 2214 | 0000000022e1fdb0 01 00 00 00 01 00 00 00 - b8 04 00 00 d2 95 80 7c ...............|
|
|---|
| 2215 | 0000000022e1fdc0 f4 fd e1 22 c0 95 80 7c - 00 6e b1 22 00 00 00 00 ..."...|.n."....
|
|---|
| 2216 | 0000000022e1fdd0 e0 fd e1 22 00 00 00 00 - 14 00 00 00 01 00 00 00 ..."............
|
|---|
| 2217 | 0000000022e1fde0 00 00 00 00 00 00 00 00 - 10 00 00 00 c0 b4 b3 ff ................
|
|---|
| 2218 | 0000000022e1fdf0 ff ff ff ff 00 c4 b1 22 - 00 80 fd 7f 00 90 f3 7f ......."........
|
|---|
| 2219 | 0000000022e1fe00 b8 00 92 7c ec fd e1 22 - b8 fd e1 22 41 00 92 7c ...|..."..."A..|
|
|---|
| 2220 | 0000000022e1fe10 01 00 00 00 ac fd e1 22 - b8 00 92 7c dc ff e1 22 ......."...|..."
|
|---|
| 2221 | 0000000022e1fe20 d8 9a 83 7c 80 96 80 7c - 00 00 00 00 48 fe e1 22 ...|...|....H.."
|
|---|
| 2222 | 0000000022e1fe30 15 a1 80 7c 01 00 00 00 - 80 fe e1 22 00 00 00 00 ...|......."....
|
|---|
| 2223 | 0000000022e1fe40 f4 01 00 00 00 00 00 00 - 60 fe e1 22 a2 14 e6 73 ........`.."...s
|
|---|
| 2224 | 0000000022e1fe50 01 00 00 00 80 fe e1 22 - 00 00 00 00 f4 01 00 00 ......."........
|
|---|
| 2225 | 0000000022e1fe60 80 ff e1 22 62 28 e6 73 - 01 00 00 00 f4 01 00 00 ..."b(.s........
|
|---|
| 2226 | 0000000022e1fe70 00 00 00 00 80 fe e1 22 - fc 1e b1 22 fc 1e b1 22 ......."..."..."
|
|---|
| 2227 | 0000000022e1fe80 b8 04 00 00 01 00 00 00 - 00 00 00 00 20 00 00 00 ............ ...
|
|---|
| 2228 | 0000000022e1fe90 04 00 00 00 f0 fd e1 22 - ac fe e1 22 dc ff e1 22 ......."..."..."
|
|---|
| 2229 | 0000000022e1fea0 20 e9 91 7c 60 00 92 7c - 4a df 91 7c 90 95 80 7c ..|`..|J..|...|
|
|---|
| 2230 | 0000000022e1feb0 00 90 f3 7f 44 ff e1 22 - d2 95 80 7c f0 fe e1 22 ....D.."...|..."
|
|---|
| 2231 | 0000000022e1fec0 c0 95 80 7c 00 00 00 00 - fc 1e b1 22 fc 1e b1 22 ...|......."..."
|
|---|
| 2232 |
|
|---|
| 2233 | *----> Vidage de l'état de la thread 0x5f4 <----*
|
|---|
| 2234 |
|
|---|
| 2235 | eax=73e61b5c ebx=22f1fec4 ecx=22c28724 edx=7c91e514 esi=00000000 edi=7ffd8000
|
|---|
| 2236 | eip=7c91e514 esp=22f1fe9c ebp=22f1ff38 iopl=0 nv up ei pl zr na po nc
|
|---|
| 2237 | cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
|
|---|
| 2238 |
|
|---|
| 2239 | fonction : ntdll!KiFastSystemCallRet
|
|---|
| 2240 | 7c91e4fa e829000000 call ntdll!RtlRaiseException (7c91e528)
|
|---|
| 2241 | 7c91e4ff 8b0424 mov eax,[esp]
|
|---|
| 2242 | 7c91e502 8be5 mov esp,ebp
|
|---|
| 2243 | 7c91e504 5d pop ebp
|
|---|
| 2244 | 7c91e505 c3 ret
|
|---|
| 2245 | 7c91e506 8da42400000000 lea esp,[esp]
|
|---|
| 2246 | 7c91e50d 8d4900 lea ecx,[ecx]
|
|---|
| 2247 | ntdll!KiFastSystemCall:
|
|---|
| 2248 | 7c91e510 8bd4 mov edx,esp
|
|---|
| 2249 | 7c91e512 0f34 sysenter
|
|---|
| 2250 | ntdll!KiFastSystemCallRet:
|
|---|
| 2251 | 7c91e514 c3 ret
|
|---|
| 2252 | 7c91e515 8da42400000000 lea esp,[esp]
|
|---|
| 2253 | 7c91e51c 8d642400 lea esp,[esp]
|
|---|
| 2254 | ntdll!KiIntSystemCall:
|
|---|
| 2255 | 7c91e520 8d542408 lea edx,[esp+0x8]
|
|---|
| 2256 | 7c91e524 cd2e int 2e
|
|---|
| 2257 | 7c91e526 c3 ret
|
|---|
| 2258 | 7c91e527 90 nop
|
|---|
| 2259 | ntdll!RtlRaiseException:
|
|---|
| 2260 | 7c91e528 55 push ebp
|
|---|
| 2261 | 7c91e529 8bec mov ebp,esp
|
|---|
| 2262 |
|
|---|
| 2263 | *----> Suivi arrière de la pile <----*
|
|---|
| 2264 | WARNING: Stack unwind information not available. Following frames may be wrong.
|
|---|
| 2265 | ChildEBP RetAddr Args to Child
|
|---|
| 2266 | 22f1ff38 7c80a115 00000002 22f1ff6c 00000000 ntdll!KiFastSystemCallRet
|
|---|
| 2267 | 22f1ff54 73e728bb 00000002 22f1ff6c 00000000 kernel32!WaitForMultipleObjects+0x18
|
|---|
| 2268 | 22f1ff74 73e7288d 000003a0 00000000 22c286fc dsound!DllGetClassObject+0x1ef6
|
|---|
| 2269 | 22f1ff98 73e62896 00000000 22c286fc 73e6b2e9 dsound!DllGetClassObject+0x1ec8
|
|---|
| 2270 | 22f1ffb4 7c80b729 22c286fc 00000000 0b1df924 dsound+0x2896
|
|---|
| 2271 | 22f1ffec 00000000 73e6b2a1 22c286fc 00000000 kernel32!GetModuleFileNameA+0x1ba
|
|---|
| 2272 |
|
|---|
| 2273 | *----> Vidage brut de la pile <----*
|
|---|
| 2274 | 0000000022f1fe9c 4a df 91 7c 90 95 80 7c - 02 00 00 00 c4 fe f1 22 J..|...|......."
|
|---|
| 2275 | 0000000022f1feac 01 00 00 00 00 00 00 00 - 00 00 00 00 01 00 00 00 ................
|
|---|
| 2276 | 0000000022f1febc fc 86 c2 22 fc 86 c2 22 - 0c 06 00 00 a0 03 00 00 ..."..."........
|
|---|
| 2277 | 0000000022f1fecc 4c 04 00 00 48 04 00 00 - 44 04 00 00 40 04 00 00 L...H...D...@...
|
|---|
| 2278 | 0000000022f1fedc 3c 04 00 00 38 04 00 00 - 14 00 00 00 01 00 00 00 <...8...........
|
|---|
| 2279 | 0000000022f1feec 00 00 00 00 00 00 00 00 - 10 00 00 00 20 04 00 00 ............ ...
|
|---|
| 2280 | 0000000022f1fefc 1c 04 00 00 18 04 00 00 - 00 80 fd 7f 00 80 f3 7f ................
|
|---|
| 2281 | 0000000022f1ff0c 0c 04 00 00 00 00 00 00 - c4 fe f1 22 00 04 00 00 ..........."....
|
|---|
| 2282 | 0000000022f1ff1c 02 00 00 00 b8 fe f1 22 - f4 03 00 00 dc ff f1 22 ......."......."
|
|---|
| 2283 | 0000000022f1ff2c d8 9a 83 7c 80 96 80 7c - 00 00 00 00 54 ff f1 22 ...|...|....T.."
|
|---|
| 2284 | 0000000022f1ff3c 15 a1 80 7c 02 00 00 00 - 6c ff f1 22 00 00 00 00 ...|....l.."....
|
|---|
| 2285 | 0000000022f1ff4c ff ff ff ff 00 00 00 00 - 74 ff f1 22 bb 28 e7 73 ........t..".(.s
|
|---|
| 2286 | 0000000022f1ff5c 02 00 00 00 6c ff f1 22 - 00 00 00 00 ff ff ff ff ....l.."........
|
|---|
| 2287 | 0000000022f1ff6c 0c 06 00 00 a0 03 00 00 - 98 ff f1 22 8d 28 e7 73 ...........".(.s
|
|---|
| 2288 | 0000000022f1ff7c a0 03 00 00 00 00 00 00 - fc 86 c2 22 d1 59 e7 73 ...........".Y.s
|
|---|
| 2289 | 0000000022f1ff8c 00 00 00 00 fc 86 c2 22 - 00 00 00 00 b4 ff f1 22 ......."......."
|
|---|
| 2290 | 0000000022f1ff9c 96 28 e6 73 00 00 00 00 - fc 86 c2 22 e9 b2 e6 73 .(.s......."...s
|
|---|
| 2291 | 0000000022f1ffac 24 f9 1d 0b ae b2 e6 73 - ec ff f1 22 29 b7 80 7c $......s...")..|
|
|---|
| 2292 | 0000000022f1ffbc fc 86 c2 22 00 00 00 00 - 24 f9 1d 0b fc 86 c2 22 ..."....$......"
|
|---|
| 2293 | 0000000022f1ffcc 00 80 f3 7f 00 76 4f 8a - c0 ff f1 22 00 1c b0 88 .....vO...."....
|
|---|
| 2294 |
|
|---|
| 2295 | *----> Vidage de l'état de la thread 0xad0 <----*
|
|---|
| 2296 |
|
|---|
| 2297 | eax=78afc41c ebx=2302fea4 ecx=00b39fed edx=0b1df798 esi=00000000 edi=7ffd8000
|
|---|
| 2298 | eip=7c91e514 esp=2302fe7c ebp=2302ff18 iopl=0 nv up ei pl zr na po nc
|
|---|
| 2299 | cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
|
|---|
| 2300 |
|
|---|
| 2301 | fonction : ntdll!KiFastSystemCallRet
|
|---|
| 2302 | 7c91e4fa e829000000 call ntdll!RtlRaiseException (7c91e528)
|
|---|
| 2303 | 7c91e4ff 8b0424 mov eax,[esp]
|
|---|
| 2304 | 7c91e502 8be5 mov esp,ebp
|
|---|
| 2305 | 7c91e504 5d pop ebp
|
|---|
| 2306 | 7c91e505 c3 ret
|
|---|
| 2307 | 7c91e506 8da42400000000 lea esp,[esp]
|
|---|
| 2308 | 7c91e50d 8d4900 lea ecx,[ecx]
|
|---|
| 2309 | ntdll!KiFastSystemCall:
|
|---|
| 2310 | 7c91e510 8bd4 mov edx,esp
|
|---|
| 2311 | 7c91e512 0f34 sysenter
|
|---|
| 2312 | ntdll!KiFastSystemCallRet:
|
|---|
| 2313 | 7c91e514 c3 ret
|
|---|
| 2314 | 7c91e515 8da42400000000 lea esp,[esp]
|
|---|
| 2315 | 7c91e51c 8d642400 lea esp,[esp]
|
|---|
| 2316 | ntdll!KiIntSystemCall:
|
|---|
| 2317 | 7c91e520 8d542408 lea edx,[esp+0x8]
|
|---|
| 2318 | 7c91e524 cd2e int 2e
|
|---|
| 2319 | 7c91e526 c3 ret
|
|---|
| 2320 | 7c91e527 90 nop
|
|---|
| 2321 | ntdll!RtlRaiseException:
|
|---|
| 2322 | 7c91e528 55 push ebp
|
|---|
| 2323 | 7c91e529 8bec mov ebp,esp
|
|---|
| 2324 |
|
|---|
| 2325 | *----> Suivi arrière de la pile <----*
|
|---|
| 2326 | WARNING: Stack unwind information not available. Following frames may be wrong.
|
|---|
| 2327 | ChildEBP RetAddr Args to Child
|
|---|
| 2328 | 2302ff18 7c80a115 00000003 0a3641d8 00000000 ntdll!KiFastSystemCallRet
|
|---|
| 2329 | 2302ff34 670221b4 00000003 0a3641d8 00000000 kernel32!WaitForMultipleObjects+0x18
|
|---|
| 2330 | ffffffff 00000000 00000000 00000000 00000000 QtCoreVBox4!QThread__start+0x404
|
|---|
| 2331 |
|
|---|
| 2332 | *----> Vidage brut de la pile <----*
|
|---|
| 2333 | 000000002302fe7c 4a df 91 7c 90 95 80 7c - 03 00 00 00 a4 fe 02 23 J..|...|.......#
|
|---|
| 2334 | 000000002302fe8c 01 00 00 00 00 00 00 00 - 00 00 00 00 03 00 00 00 ................
|
|---|
| 2335 | 000000002302fe9c 00 00 00 00 01 00 00 00 - 58 03 00 00 5c 03 00 00 ........X...\...
|
|---|
| 2336 | 000000002302feac 6c 03 00 00 00 c0 5c 0d - a4 6b 58 96 60 ae 06 c0 l.....\..kX.`...
|
|---|
| 2337 | 000000002302febc 00 00 00 00 20 00 00 00 - 14 00 00 00 01 00 00 00 .... ...........
|
|---|
| 2338 | 000000002302fecc 00 00 00 00 00 00 00 00 - 10 00 00 00 ff cf 5c 0d ..............\.
|
|---|
| 2339 | 000000002302fedc cc d5 00 00 97 5f 50 80 - 00 80 fd 7f 00 70 f3 7f ....._P......p..
|
|---|
| 2340 | 000000002302feec 00 00 00 00 00 00 00 00 - a4 fe 02 23 00 00 00 00 ...........#....
|
|---|
| 2341 | 000000002302fefc 03 00 00 00 98 fe 02 23 - 04 00 00 00 6c ff 02 23 .......#....l..#
|
|---|
| 2342 | 000000002302ff0c d8 9a 83 7c 80 96 80 7c - 00 00 00 00 34 ff 02 23 ...|...|....4..#
|
|---|
| 2343 | 000000002302ff1c 15 a1 80 7c 03 00 00 00 - d8 41 36 0a 00 00 00 00 ...|.....A6.....
|
|---|
| 2344 | 000000002302ff2c ff ff ff ff 00 00 00 00 - ff ff ff ff b4 21 02 67 .............!.g
|
|---|
| 2345 | 000000002302ff3c 03 00 00 00 d8 41 36 0a - 00 00 00 00 ff ff ff ff .....A6.........
|
|---|
| 2346 | 000000002302ff4c 40 ce 7b 51 78 01 3d 00 - 01 00 00 00 ac ff 02 23 @.{Qx.=........#
|
|---|
| 2347 | 000000002302ff5c 98 cd e0 0e c8 41 36 0a - 26 07 ab 78 00 00 00 00 .....A6.&..x....
|
|---|
| 2348 | 000000002302ff6c 9c ff 02 23 30 81 13 67 - 00 00 00 00 d4 c3 af 78 ...#0..g.......x
|
|---|
| 2349 | 000000002302ff7c 00 00 00 00 57 b9 7b 51 - 78 01 3d 00 01 00 00 00 ....W.{Qx.=.....
|
|---|
| 2350 | 000000002302ff8c 98 cd e0 0e 80 ff 02 23 - 80 ff 02 23 dc ff 02 23 .......#...#...#
|
|---|
| 2351 | 000000002302ff9c dc ff 02 23 5a b6 b2 78 - fb 82 d6 0a 00 00 00 00 ...#Z..x........
|
|---|
| 2352 | 000000002302ffac b4 ff 02 23 74 c4 af 78 - ec ff 02 23 29 b7 80 7c ...#t..x...#)..|
|
|---|
| 2353 |
|
|---|
| 2354 | *----> Vidage de l'état de la thread 0xfac <----*
|
|---|
| 2355 |
|
|---|
| 2356 | eax=77e56c7d ebx=00153614 ecx=0014f69c edx=774bd5ec esi=3b731a78 edi=7c9110e0
|
|---|
| 2357 | eip=7c91e514 esp=2cf9ff70 ebp=2cf9ff88 iopl=0 nv up ei ng nz na po nc
|
|---|
| 2358 | cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000286
|
|---|
| 2359 |
|
|---|
| 2360 | fonction : ntdll!KiFastSystemCallRet
|
|---|
| 2361 | 7c91e4fa e829000000 call ntdll!RtlRaiseException (7c91e528)
|
|---|
| 2362 | 7c91e4ff 8b0424 mov eax,[esp]
|
|---|
| 2363 | 7c91e502 8be5 mov esp,ebp
|
|---|
| 2364 | 7c91e504 5d pop ebp
|
|---|
| 2365 | 7c91e505 c3 ret
|
|---|
| 2366 | 7c91e506 8da42400000000 lea esp,[esp]
|
|---|
| 2367 | 7c91e50d 8d4900 lea ecx,[ecx]
|
|---|
| 2368 | ntdll!KiFastSystemCall:
|
|---|
| 2369 | 7c91e510 8bd4 mov edx,esp
|
|---|
| 2370 | 7c91e512 0f34 sysenter
|
|---|
| 2371 | ntdll!KiFastSystemCallRet:
|
|---|
| 2372 | 7c91e514 c3 ret
|
|---|
| 2373 | 7c91e515 8da42400000000 lea esp,[esp]
|
|---|
| 2374 | 7c91e51c 8d642400 lea esp,[esp]
|
|---|
| 2375 | ntdll!KiIntSystemCall:
|
|---|
| 2376 | 7c91e520 8d542408 lea edx,[esp+0x8]
|
|---|
| 2377 | 7c91e524 cd2e int 2e
|
|---|
| 2378 | 7c91e526 c3 ret
|
|---|
| 2379 | 7c91e527 90 nop
|
|---|
| 2380 | ntdll!RtlRaiseException:
|
|---|
| 2381 | 7c91e528 55 push ebp
|
|---|
| 2382 | 7c91e529 8bec mov ebp,esp
|
|---|
| 2383 |
|
|---|
| 2384 | *----> Suivi arrière de la pile <----*
|
|---|
| 2385 | WARNING: Stack unwind information not available. Following frames may be wrong.
|
|---|
| 2386 | ChildEBP RetAddr Args to Child
|
|---|
| 2387 | 2cf9ff88 77e56b1c 00007530 7c9201db 00000000 ntdll!KiFastSystemCallRet
|
|---|
| 2388 | 2cf9ffa8 77e56c97 00153588 2cf9ffec 7c80b729 RPCRT4!I_RpcBCacheFree+0x489
|
|---|
| 2389 | 2cf9ffb4 7c80b729 001a4008 7c9201db 00000000 RPCRT4!I_RpcBCacheFree+0x604
|
|---|
| 2390 | 2cf9ffec 00000000 77e56c7d 001a4008 00000000 kernel32!GetModuleFileNameA+0x1ba
|
|---|
| 2391 |
|
|---|
| 2392 | *----> Vidage brut de la pile <----*
|
|---|
| 2393 | 000000002cf9ff70 1a d2 91 7c 99 6b e5 77 - 01 00 00 00 80 ff f9 2c ...|.k.w.......,
|
|---|
| 2394 | 000000002cf9ff80 00 5d 1e ee ff ff ff ff - a8 ff f9 2c 1c 6b e5 77 .].........,.k.w
|
|---|
| 2395 | 000000002cf9ff90 30 75 00 00 db 01 92 7c - 00 00 00 00 08 40 1a 00 0u.....|.....@..
|
|---|
| 2396 | 000000002cf9ffa0 08 40 1a 00 30 75 00 00 - b4 ff f9 2c 97 6c e5 77 .@..0u.....,.l.w
|
|---|
| 2397 | 000000002cf9ffb0 88 35 15 00 ec ff f9 2c - 29 b7 80 7c 08 40 1a 00 .5.....,)..|.@..
|
|---|
| 2398 | 000000002cf9ffc0 db 01 92 7c 00 00 00 00 - 08 40 1a 00 00 60 fd 7f ...|.....@...`..
|
|---|
| 2399 | 000000002cf9ffd0 00 56 4f 8a c0 ff f9 2c - 58 27 c5 88 ff ff ff ff .VO....,X'......
|
|---|
| 2400 | 000000002cf9ffe0 d8 9a 83 7c 30 b7 80 7c - 00 00 00 00 00 00 00 00 ...|0..|........
|
|---|
| 2401 | 000000002cf9fff0 00 00 00 00 7d 6c e5 77 - 08 40 1a 00 00 00 00 00 ....}l.w.@......
|
|---|
| 2402 | 000000002cfa0000 53 55 56 57 8b 5c 24 14 - ff 93 40 13 00 00 be 40 SUVW.\$...@....@
|
|---|
| 2403 | 000000002cfa0010 81 ea 0b 89 a3 44 13 00 - 00 81 e4 e0 ff ff ff b8 .....D..........
|
|---|
| 2404 | 000000002cfa0020 f0 00 00 00 b9 00 00 00 - 00 89 8b 54 13 00 00 88 ...........T....
|
|---|
| 2405 | 000000002cfa0030 84 0b b0 13 00 00 b8 f0 - 00 00 00 b9 00 00 00 00 ................
|
|---|
| 2406 | 000000002cfa0040 89 8b 50 13 00 00 88 84 - 0b d0 13 00 00 b8 00 00 ..P.............
|
|---|
| 2407 | 000000002cfa0050 00 00 b9 00 00 00 00 89 - 8b 5c 13 00 00 89 84 8b .........\......
|
|---|
| 2408 | 000000002cfa0060 90 13 00 00 b8 00 00 00 - 00 b9 00 00 00 00 89 8b ................
|
|---|
| 2409 | 000000002cfa0070 58 13 00 00 89 84 8b 70 - 13 00 00 b8 f0 00 00 00 X......p........
|
|---|
| 2410 | 000000002cfa0080 89 83 48 13 00 00 f3 0f - 10 83 10 02 00 00 f3 0f ..H.............
|
|---|
| 2411 | 000000002cfa0090 10 8e c0 00 00 00 f3 0f - 59 c8 f3 0f 10 93 14 02 ........Y.......
|
|---|
| 2412 | 000000002cfa00a0 00 00 f3 0f 10 9e d0 00 - 00 00 f3 0f 59 da f3 0f ............Y...
|
|---|
| 2413 |
|
|---|
| 2414 | *----> Table des symboles <----*
|
|---|
| 2415 | C:\WINNT\system32\ig4dev32.dll
|
|---|
| 2416 |
|
|---|
| 2417 | 0c0451a0 ig4dev32!devProcessAttach
|
|---|