rendered paste body
Microsoft (R) DrWtsn32
Copyright (C) 1985-2001 Microsoft Corp. All rights reserved.
Application exception occurred:
App: C:\Un4seen\XMPlay\xmplay.exe (pid=3116)
When: 18-Sep-07 @ 21:50:15.326
Exception number: c0000005 (access violation)
*----> System Information <----*
Computer Name: KALI
User Name: Owner
Terminal Session Id: 0
Number of Processors: 2
Processor Type: x86 Family 15 Model 3 Stepping 4
Windows Version: 5.1
Current Build: 2600
Service Pack: 2
Current Type: Multiprocessor Free
Registered Organization:
Registered Owner: Thomas Ditmars
*----> Task List <----*
0 System Process
4 System
1020 smss.exe
1088 csrss.exe
1132 winlogon.exe
1184 services.exe
1196 lsass.exe
1368 Ati2evxx.exe
1396 svchost.exe
1548 svchost.exe
1688 svchost.exe
1788 Ati2evxx.exe
2024 svchost.exe
452 spoolsv.exe
680 AppleMobileDeviceService.exe
724 avgamsvr.exe
784 Explorer.EXE
864 avgupsvc.exe
920 avgemc.exe
936 BOCORE.exe
1100 persfw.exe
1156 PRISMXL.SYS
292 alg.exe
2352 svchost.exe
2420 CTHELPER.EXE
2512 avgcc.exe
2528 PDVDServ.exe
2620 BOC425.exe
2656 winpatrol.exe
2724 ctfmon.exe
2748 pg2.exe
2800 hm.exe
2836 hostssrv.exe
2884 taskbarshuffle.exe
2952 TeaTimer.exe
3064 iSproggler.exe
3144 daemon.exe
3196 atitray.exe
3428 GPGtray.exe
3568 nistime-32bit.exe
3560 iTunes.exe
3596 xchat.exe
740 LastFMHelper.exe
3492 LastFM.exe
384 iPodService.exe
3700 iTunesHelper.exe
3844 trillian.exe
3316 firefox.exe
3044 thunderbird.exe
1888 SAM.exe
3096 Skype.exe
3264 SkypePM.exe
3116 xmplay.exe
2460 drwtsn32.exe
*----> Module List <----*
(0000000000330000 - 0000000000339000: C:\WINDOWS\system32\Normaliz.dll
(0000000000400000 - 0000000000552000: C:\Un4seen\XMPlay\xmplay.exe
(0000000000e40000 - 0000000000e4f000: C:\Program Files\BillP Studios\WinPatrol\PATROLPRO.DLL
(0000000000e60000 - 0000000000f3c000: C:\Un4seen\XMPlay\Plugins\in_adlib.dll
(0000000001060000 - 00000000011a5000: C:\Un4seen\XMPlay\Plugins\in_flac.dll
(00000000011b0000 - 00000000012a1000: C:\Un4seen\XMPlay\Plugins\in_gsf.dll
(00000000012b0000 - 000000000136f000: C:\Un4seen\XMPlay\Plugins\in_mp3.dll
(00000000013b0000 - 0000000001426000: C:\Un4seen\XMPlay\Plugins\in_mp3PRO.dll
(0000000001440000 - 00000000014e0000: C:\Un4seen\XMPlay\Plugins\in_mp4.dll
(00000000014e0000 - 0000000001519000: C:\Un4seen\XMPlay\Plugins\in_mpc.dll
(0000000001520000 - 000000000169b000: C:\Un4seen\XMPlay\Plugins\in_msx.dll
(00000000016b0000 - 00000000017c0000: C:\Un4seen\XMPlay\Plugins\in_psf.dll
(00000000017e0000 - 0000000001866000: C:\Un4seen\XMPlay\Plugins\in_qsf.dll
(0000000001880000 - 0000000001990000: C:\Un4seen\XMPlay\Plugins\in_sap.dll
(0000000001aa0000 - 0000000001b6e000: C:\Un4seen\XMPlay\Plugins\in_snes.dll
(0000000001c80000 - 0000000001d24000: C:\Un4seen\XMPlay\Plugins\SNESAPU.DLL
(0000000001d40000 - 0000000001e27000: C:\Un4seen\XMPlay\Plugins\in_usf.dll
(0000000001e30000 - 0000000001f25000: C:\Un4seen\XMPlay\Plugins\in_vgm.dll
(0000000001f40000 - 0000000001f7c000: C:\Un4seen\XMPlay\Plugins\in_vorbis.dll
(0000000001f80000 - 0000000001f8b000: C:\Un4seen\XMPlay\Plugins\in_wave.dll
(0000000001f90000 - 0000000002033000: C:\Un4seen\XMPlay\Plugins\in_yansf.dll
(00000000021e0000 - 0000000002257000: C:\Un4seen\XMPlay\Plugins\nsfplug_ui.dll
(0000000002380000 - 0000000002386000: C:\WINDOWS\system32\ctagent.dll
(00000000024c0000 - 00000000024c8000: C:\Un4seen\XMPlay\Plugins\xmp-7z.dll
(00000000024d0000 - 0000000002513000: C:\Un4seen\XMPlay\Plugins\xmp-aac.dll
(0000000002520000 - 00000000025a8000: C:\Un4seen\XMPlay\Plugins\xmp-ahx.dll
(0000000003140000 - 000000000314c000: C:\Un4seen\XMPlay\Plugins\xmp-arj.dll
(0000000003150000 - 0000000003157000: C:\Un4seen\XMPlay\Plugins\xmp-asio.dll
(0000000003160000 - 0000000003169000: C:\Un4seen\XMPlay\Plugins\xmp-cd.dll
(0000000003170000 - 0000000003177000: C:\Un4seen\XMPlay\Plugins\xmp-ds.dll
(0000000003180000 - 000000000318e000: C:\Un4seen\XMPlay\Plugins\xmp-flac.dll
(0000000003190000 - 000000000319d000: C:\Un4seen\XMPlay\Plugins\xmp-lha.dll
(00000000031a0000 - 00000000031ad000: C:\Un4seen\XMPlay\Plugins\xmp-midi.dll
(00000000031b0000 - 00000000031b6000: C:\Un4seen\XMPlay\Plugins\xmp-mmcmp.dll
(00000000031c0000 - 00000000031cb000: C:\Un4seen\XMPlay\Plugins\xmp-modpacker.dll
(00000000031d0000 - 00000000031df000: C:\Un4seen\XMPlay\Plugins\xmp-mpc.dll
(00000000031e0000 - 00000000031e6000: C:\Un4seen\XMPlay\Plugins\xmp-pp.dll
(0000000003200000 - 000000000320f000: C:\Un4seen\XMPlay\Plugins\xmp-rar.dll
(0000000003220000 - 0000000003227000: C:\Un4seen\XMPlay\Plugins\xmp-wadsp.dll
(0000000003230000 - 0000000003238000: C:\Un4seen\XMPlay\Plugins\xmp-wma.dll
(0000000003260000 - 00000000032b6000: C:\WINDOWS\system32\MSVCR71.dll
(00000000032d0000 - 00000000032da000: C:\Un4seen\XMPlay\Plugins\xmp-zip.dll
(00000000032e0000 - 0000000003441000: C:\Un4seen\XMPlay\Plugins\xmp-psf.dll
(0000000003550000 - 00000000035d9000: C:\Un4seen\XMPlay\Plugins\xmp-sid.dll
(0000000007160000 - 00000000071a6000: C:\WINDOWS\system32\Audiodev.dll
(0000000010000000 - 0000000010044000: C:\Program Files\Ray Adams\ATI Tray Tools\raphook.dll
(0000000010930000 - 0000000010979000: C:\WINDOWS\system32\PortableDeviceApi.dll
(0000000011c70000 - 0000000011ca9000: C:\WINDOWS\system32\WMASF.DLL
(0000000015110000 - 000000001536a000: C:\WINDOWS\system32\WMVCore.DLL
(0000000016000000 - 0000000016028000: C:\Program Files\Trillian\events.dll
(0000000016080000 - 00000000160a5000: C:\Program Files\Bonjour\mdnsNSP.dll
(0000000016210000 - 000000001648e000: C:\WINDOWS\system32\wpdshext.dll
(0000000020000000 - 0000000020017000: C:\WINDOWS\system32\odbcint.dll
(0000000042990000 - 00000000429d5000: C:\WINDOWS\system32\iertutil.dll
(0000000042c10000 - 0000000042cdf000: C:\WINDOWS\system32\WININET.dll
(0000000042cf0000 - 0000000042e14000: C:\WINDOWS\system32\urlmon.dll
(000000004ec50000 - 000000004edf3000: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.2180_x-ww_522f9f82\gdiplus.dll
(000000005ad70000 - 000000005ada8000: C:\WINDOWS\system32\uxtheme.dll
(000000005b860000 - 000000005b8b4000: C:\WINDOWS\system32\netapi32.dll
(00000000629c0000 - 00000000629c9000: C:\WINDOWS\system32\LPK.DLL
(00000000662b0000 - 0000000066308000: C:\WINDOWS\system32\hnetcfg.dll
(0000000066ac0000 - 0000000066c50000: C:\Un4seen\XMPlay\Plugins\xmp-scrobbler.dll
(0000000071a50000 - 0000000071a8f000: C:\WINDOWS\system32\mswsock.dll
(0000000071a90000 - 0000000071a98000: C:\WINDOWS\System32\wshtcpip.dll
(0000000071aa0000 - 0000000071aa8000: C:\WINDOWS\system32\WS2HELP.dll
(0000000071ab0000 - 0000000071ac7000: C:\WINDOWS\system32\WS2_32.dll
(0000000071ad0000 - 0000000071ad9000: C:\WINDOWS\system32\WSOCK32.dll
(0000000071b20000 - 0000000071b32000: C:\WINDOWS\system32\MPR.dll
(0000000071bf0000 - 0000000071c03000: C:\WINDOWS\System32\SAMLIB.dll
(0000000071c10000 - 0000000071c1e000: C:\WINDOWS\System32\ntlanman.dll
(0000000071c80000 - 0000000071c87000: C:\WINDOWS\System32\NETRAP.dll
(0000000071c90000 - 0000000071cd0000: C:\WINDOWS\System32\NETUI1.dll
(0000000071cd0000 - 0000000071ce7000: C:\WINDOWS\System32\NETUI0.dll
(00000000722b0000 - 00000000722b5000: C:\WINDOWS\system32\sensapi.dll
(0000000072d10000 - 0000000072d18000: C:\WINDOWS\system32\msacm32.drv
(0000000072d20000 - 0000000072d29000: C:\WINDOWS\system32\wdmaud.drv
(0000000073000000 - 0000000073026000: C:\WINDOWS\system32\WINSPOOL.DRV
(0000000073d70000 - 0000000073d83000: C:\WINDOWS\system32\shgina.dll
(0000000073ee0000 - 0000000073ee4000: C:\WINDOWS\system32\KsUser.dll
(0000000073f10000 - 0000000073f6c000: C:\WINDOWS\system32\dsound.dll
(0000000074320000 - 000000007435d000: C:\WINDOWS\system32\ODBC32.dll
(0000000074720000 - 000000007476b000: C:\WINDOWS\system32\MSCTF.dll
(0000000074d90000 - 0000000074dfb000: C:\WINDOWS\system32\USP10.dll
(00000000755c0000 - 00000000755ee000: C:\WINDOWS\system32\msctfime.ime
(0000000075970000 - 0000000075a67000: C:\WINDOWS\system32\MSGINA.dll
(0000000075f60000 - 0000000075f67000: C:\WINDOWS\System32\drprov.dll
(0000000075f70000 - 0000000075f79000: C:\WINDOWS\System32\davclnt.dll
(0000000076360000 - 0000000076370000: C:\WINDOWS\system32\WINSTA.dll
(0000000076390000 - 00000000763ad000: C:\WINDOWS\system32\IMM32.DLL
(00000000763b0000 - 00000000763f9000: C:\WINDOWS\system32\comdlg32.dll
(0000000076600000 - 000000007661d000: C:\WINDOWS\System32\CSCDLL.dll
(00000000769c0000 - 0000000076a73000: C:\WINDOWS\system32\USERENV.dll
(0000000076b40000 - 0000000076b6d000: C:\WINDOWS\system32\WINMM.dll
(0000000076bf0000 - 0000000076bfb000: C:\WINDOWS\system32\PSAPI.DLL
(0000000076c30000 - 0000000076c5e000: C:\WINDOWS\system32\WINTRUST.dll
(0000000076c90000 - 0000000076cb8000: C:\WINDOWS\system32\IMAGEHLP.dll
(0000000076d60000 - 0000000076d79000: C:\WINDOWS\system32\iphlpapi.dll
(0000000076e80000 - 0000000076e8e000: C:\WINDOWS\system32\rtutils.dll
(0000000076e90000 - 0000000076ea2000: C:\WINDOWS\system32\rasman.dll
(0000000076eb0000 - 0000000076edf000: C:\WINDOWS\system32\TAPI32.dll
(0000000076ee0000 - 0000000076f1c000: C:\WINDOWS\system32\RASAPI32.dll
(0000000076f20000 - 0000000076f47000: C:\WINDOWS\system32\DNSAPI.dll
(0000000076f60000 - 0000000076f8c000: C:\WINDOWS\system32\WLDAP32.dll
(0000000076fb0000 - 0000000076fb8000: C:\WINDOWS\System32\winrnr.dll
(0000000076fc0000 - 0000000076fc6000: C:\WINDOWS\system32\rasadhlp.dll
(0000000076fd0000 - 000000007704f000: C:\WINDOWS\system32\CLBCATQ.DLL
(0000000077050000 - 0000000077115000: C:\WINDOWS\system32\COMRes.dll
(0000000077120000 - 00000000771ab000: C:\WINDOWS\system32\OLEAUT32.dll
(00000000773d0000 - 00000000774d3000: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\COMCTL32.dll
(00000000774e0000 - 000000007761d000: C:\WINDOWS\system32\ole32.dll
(0000000077920000 - 0000000077a13000: C:\WINDOWS\system32\SETUPAPI.dll
(0000000077a20000 - 0000000077a74000: C:\WINDOWS\System32\cscui.dll
(0000000077a80000 - 0000000077b14000: C:\WINDOWS\system32\CRYPT32.dll
(0000000077b20000 - 0000000077b32000: C:\WINDOWS\system32\MSASN1.dll
(0000000077b40000 - 0000000077b62000: C:\WINDOWS\system32\appHelp.dll
(0000000077bd0000 - 0000000077bd7000: C:\WINDOWS\system32\midimap.dll
(0000000077be0000 - 0000000077bf5000: C:\WINDOWS\system32\MSACM32.dll
(0000000077c00000 - 0000000077c08000: C:\WINDOWS\system32\VERSION.DLL
(0000000077c10000 - 0000000077c68000: C:\WINDOWS\system32\msvcrt.dll
(0000000077c70000 - 0000000077c93000: C:\WINDOWS\system32\msv1_0.dll
(0000000077dd0000 - 0000000077e6b000: C:\WINDOWS\system32\ADVAPI32.dll
(0000000077e70000 - 0000000077f01000: C:\WINDOWS\system32\RPCRT4.dll
(0000000077f10000 - 0000000077f57000: C:\WINDOWS\system32\GDI32.dll
(0000000077f60000 - 0000000077fd6000: C:\WINDOWS\system32\SHLWAPI.dll
(0000000077fe0000 - 0000000077ff1000: C:\WINDOWS\system32\Secur32.dll
(000000007c3a0000 - 000000007c41b000: C:\WINDOWS\system32\MSVCP71.dll
(000000007c800000 - 000000007c8f5000: C:\WINDOWS\system32\kernel32.dll
(000000007c900000 - 000000007c9b0000: C:\WINDOWS\system32\ntdll.dll
(000000007c9c0000 - 000000007d1d5000: C:\WINDOWS\system32\SHELL32.dll
(000000007e410000 - 000000007e4a0000: C:\WINDOWS\system32\USER32.dll
*----> State Dump for Thread Id 0x3b4 <----*
eax=0000000a ebx=005510b6 ecx=00000000 edx=0000000f esi=0012ff08 edi=00000000
eip=7c90eb94 esp=0012d7b0 ebp=0012d7d4 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00200246
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\ntdll.dll -
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
*** WARNING: Unable to verify checksum for C:\Un4seen\XMPlay\xmplay.exe
*** ERROR: Module load completed but symbols could not be loaded for C:\Un4seen\XMPlay\xmplay.exe
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\kernel32.dll -
ChildEBP RetAddr Args to Child
0012d7d4 0043da74 0012ff08 00000000 00000000 ntdll!KiFastSystemCallRet
0012ff24 00445cdf 00400000 00000000 0015232f xmplay+0x3da74
0012ffc0 7c816ff7 011dcd8c 7c90e1fe 7ffda000 xmplay+0x45cdf
0012fff0 00000000 00551039 00000000 78746341 kernel32!RegisterWaitForInputIdle+0x49
*----> Raw Stack Dump <----*
000000000012d7b0 be 91 41 7e 42 e0 42 7e - 08 ff 12 00 00 00 00 00 ..A~B.B~........
000000000012d7c0 00 00 00 00 00 00 00 00 - b6 10 55 00 00 00 00 00 ..........U.....
000000000012d7d0 02 e0 42 7e 24 ff 12 00 - 74 da 43 00 08 ff 12 00 ..B~$...t.C.....
000000000012d7e0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000012d7f0 8c cd 1d 01 2f 23 15 00 - ff 78 6d 70 2d 73 63 72 ..../#...xmp-scr
000000000012d800 6f 62 62 6c 65 72 2e 64 - 6c 6c 00 00 24 05 01 00 obbler.dll..$...
000000000012d810 00 00 5a 61 72 67 67 67 - 00 00 00 00 00 00 00 00 ..Zarggg........
000000000012d820 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000012d830 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000012d840 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000012d850 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000012d860 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000012d870 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000012d880 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000012d890 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000012d8a0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000012d8b0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000012d8c0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000012d8d0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000012d8e0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
*----> State Dump for Thread Id 0xc78 <----*
eax=00000001 ebx=0000000b ecx=00000000 edx=00000000 esi=00010000 edi=0000ffff
eip=7c90eb94 esp=0471fac8 ebp=0471ff3c iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0471ff3c 0041d841 d70114da 000000a6 0000000b ntdll!KiFastSystemCallRet
0471ff64 0043e042 00000038 00a85780 0471ffb4 xmplay+0x1d841
7e41c465 e87e41c4 ffffc14f e8084d8b ffffc057 xmplay+0x3e042
98680c6a 00000000 00000000 00000000 00000000 0xe87e41c4
*----> Raw Stack Dump <----*
000000000471fac8 02 71 f1 77 ad 70 f1 77 - da 14 01 d7 a6 00 00 00 .q.w.p.w........
000000000471fad8 0b 00 00 00 5d 21 01 6d - 90 a5 47 00 da 14 01 d7 ....]!.m..G.....
000000000471fae8 6f 00 72 00 6e 00 20 00 - 2d 00 20 00 57 00 61 00 o.r.n. .-. .W.a.
000000000471faf8 6c 00 6b 00 69 00 6e 00 - 7e fb 71 04 00 00 00 00 l.k.i.n.~.q.....
000000000471fb08 00 00 00 00 00 00 00 00 - 48 ff 71 04 ac 7d 42 00 ........H.q..}B.
000000000471fb18 28 ff 71 04 24 09 00 00 - 61 21 01 00 90 a5 47 00 (.q.$...a!....G.
000000000471fb28 da 14 01 d7 4e 69 67 68 - 74 77 69 73 68 20 2d 20 ....Nightwish -
000000000471fb38 4f 63 65 61 6e 62 6f 72 - 6e 20 2d 20 57 61 6c 6b Oceanborn - Walk
000000000471fb48 69 6e 67 20 69 6e 20 74 - 68 65 20 41 69 72 20 20 ing in the Air
000000000471fb58 20 20 20 20 4e 69 67 68 - 74 77 69 73 68 20 2d 20 Nightwish -
000000000471fb68 4f 63 65 61 6e 62 6f 72 - 6e 20 2d 20 57 61 6c 6b Oceanborn - Walk
000000000471fb78 69 6e 67 20 69 6e 00 74 - 00 77 03 01 18 77 03 01 ing in.t.w...w..
000000000471fb88 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000471fb98 24 00 00 00 ac 1d 91 7c - 1d 05 00 00 18 77 03 00 $......|.....w..
000000000471fba8 00 00 00 00 00 00 34 00 - 18 77 03 01 00 00 00 00 ......4..w......
000000000471fbb8 00 00 00 00 00 a0 03 01 - dc fb 71 04 00 00 f6 00 ..........q.....
000000000471fbc8 00 00 00 00 16 d9 00 00 - 04 fc 71 04 69 12 9c 62 ..........q.i..b
000000000471fbd8 76 20 01 59 02 00 00 00 - 00 00 00 00 01 00 00 00 v .Y............
000000000471fbe8 20 00 00 00 ff ff ff ff - 10 67 5d 06 08 00 00 00 ........g].....
000000000471fbf8 01 00 00 00 25 09 00 00 - 00 00 00 00 44 fc 71 04 ....%.......D.q.
*----> State Dump for Thread Id 0xca4 <----*
eax=04d6faf7 ebx=01026fe8 ecx=00000036 edx=00000000 esi=00000288 edi=00000000
eip=7c90eb94 esp=04d6fefc ebp=04d6ff60 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00200246
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\Un4seen\XMPlay\Plugins\xmp-scrobbler.dll -
ChildEBP RetAddr Args to Child
04d6ff60 7c802532 00000288 ffffffff 00000000 ntdll!KiFastSystemCallRet
04d6ff74 66ac760f 00000288 ffffffff 0269788c kernel32!WaitForSingleObject+0x12
04d6ffa4 66bb31a1 02695008 7c90e2dc 04d6ffec xmp-scrobbler!DllMain+0x624f
04d6ffb4 7c80b6a3 02695008 04c6f9e0 00000001 xmp-scrobbler+0xf31a1
04d6ffec 00000000 66bb3190 02695008 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
0000000004d6fefc c0 e9 90 7c cb 25 80 7c - 88 02 00 00 00 00 00 00 ...|.%.|........
0000000004d6ff0c 00 00 00 00 8c 78 69 02 - 08 50 69 02 e8 6f 02 01 .....xi..Pi..o..
0000000004d6ff1c 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000004d6ff2c 10 00 00 00 8c 78 69 02 - 08 50 69 02 00 a0 fd 7f .....xi..Pi.....
0000000004d6ff3c 00 90 fd 7f 00 00 00 00 - e3 c2 c2 77 10 ff d6 04 ...........w....
0000000004d6ff4c 30 ff d6 04 dc ff d6 04 - 30 9a 83 7c f8 25 80 7c 0.......0..|.%.|
0000000004d6ff5c 00 00 00 00 74 ff d6 04 - 32 25 80 7c 88 02 00 00 ....t...2%.|....
0000000004d6ff6c ff ff ff ff 00 00 00 00 - a4 ff d6 04 0f 76 ac 66 .............v.f
0000000004d6ff7c 88 02 00 00 ff ff ff ff - 8c 78 69 02 01 f4 6f 80 .........xi...o.
0000000004d6ff8c 00 00 00 00 50 34 90 84 - 00 00 00 00 08 50 69 02 ....P4.......Pi.
0000000004d6ff9c 01 00 00 00 e0 f9 c6 04 - b4 ff d6 04 a1 31 bb 66 .............1.f
0000000004d6ffac 08 50 69 02 dc e2 90 7c - ec ff d6 04 a3 b6 80 7c .Pi....|.......|
0000000004d6ffbc 08 50 69 02 e0 f9 c6 04 - 01 00 00 00 08 50 69 02 .Pi..........Pi.
0000000004d6ffcc 00 90 fd 7f 00 d6 fb 86 - c0 ff d6 04 30 ac 02 85 ............0...
0000000004d6ffdc ff ff ff ff 30 9a 83 7c - b0 b6 80 7c 00 00 00 00 ....0..|...|....
0000000004d6ffec 00 00 00 00 00 00 00 00 - 90 31 bb 66 08 50 69 02 .........1.f.Pi.
0000000004d6fffc 00 00 00 00 c8 00 00 00 - e6 01 00 00 ff ee ff ee ................
0000000004d7000c 02 10 00 00 00 00 00 00 - 00 fe 00 00 00 00 20 00 .............. .
0000000004d7001c 00 20 00 00 00 02 00 00 - 00 20 00 00 4e 04 00 00 . ....... ..N...
0000000004d7002c ff ef fd 7f 1d 00 08 06 - 00 00 00 00 00 00 00 00 ................
*----> State Dump for Thread Id 0x600 <----*
eax=72d230e8 ebx=04ecfef8 ecx=0000001e edx=00000000 esi=00000000 edi=7ffda000
eip=7c90eb94 esp=04ecfed0 ebp=04ecff6c iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\wdmaud.drv -
ChildEBP RetAddr Args to Child
04ecff6c 7c80a095 00000002 04ecffa4 00000000 ntdll!KiFastSystemCallRet
04ecff88 72d2312a 00000002 04ecffa4 00000000 kernel32!WaitForMultipleObjects+0x18
04ecffb4 7c80b6a3 00000000 00000000 00150000 wdmaud!midMessage+0x348
04ecffec 00000000 72d230e8 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
0000000004ecfed0 ab e9 90 7c 0b 95 80 7c - 02 00 00 00 f8 fe ec 04 ...|...|........
0000000004ecfee0 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000004ecfef0 00 00 00 00 00 00 00 00 - cc 02 00 00 b8 02 00 00 ................
0000000004ecff00 00 00 00 00 00 00 00 00 - 43 fd 6f 80 90 ac fa aa ........C.o.....
0000000004ecff10 27 f4 6f 80 00 0d db ba - 14 00 00 00 01 00 00 00 '.o.............
0000000004ecff20 00 00 00 00 00 00 00 00 - 10 00 00 00 f0 bb ec 84 ................
0000000004ecff30 24 bc ec 84 cc 0d 00 00 - 00 a0 fd 7f 00 80 fd 7f $...............
0000000004ecff40 f0 bb ec 84 00 00 00 00 - f8 fe ec 04 ac 9b 4f 80 ..............O.
0000000004ecff50 02 00 00 00 ec fe ec 04 - 00 00 00 00 dc ff ec 04 ................
0000000004ecff60 30 9a 83 7c 00 96 80 7c - 00 00 00 00 88 ff ec 04 0..|...|........
0000000004ecff70 95 a0 80 7c 02 00 00 00 - a4 ff ec 04 00 00 00 00 ...|............
0000000004ecff80 ff ff ff ff 00 00 00 00 - b4 ff ec 04 2a 31 d2 72 ............*1.r
0000000004ecff90 02 00 00 00 a4 ff ec 04 - 00 00 00 00 ff ff ff ff ................
0000000004ecffa0 00 00 15 00 cc 02 00 00 - b8 02 00 00 f2 fe 6f 80 ..............o.
0000000004ecffb0 dc e2 90 7c ec ff ec 04 - a3 b6 80 7c 00 00 00 00 ...|.......|....
0000000004ecffc0 00 00 00 00 00 00 15 00 - 00 00 00 00 00 80 fd 7f ................
0000000004ecffd0 00 d6 fb 86 c0 ff ec 04 - e0 73 ae 85 ff ff ff ff .........s......
0000000004ecffe0 30 9a 83 7c b0 b6 80 7c - 00 00 00 00 00 00 00 00 0..|...|........
0000000004ecfff0 00 00 00 00 e8 30 d2 72 - 00 00 00 00 00 00 00 00 .....0.r........
0000000004ed0000 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
*----> State Dump for Thread Id 0xb0c <----*
eax=73f1b94b ebx=001bfcf0 ecx=ffffffff edx=7c916928 esi=00000000 edi=7ffda000
eip=7c90eb94 esp=04fcfd88 ebp=04fcfe24 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\dsound.dll -
ChildEBP RetAddr Args to Child
04fcfe24 7c80a095 00000040 04fcfe78 00000000 ntdll!KiFastSystemCallRet
04fcfe40 73f114a2 00000040 04fcfe78 00000000 kernel32!WaitForMultipleObjects+0x18
04fcfe58 73f1294a 00000040 ffffffff 00000000 dsound+0x14a2
04fcff78 73f19fbf ffffffff 0000003f 04d76958 dsound+0x294a
04fcff98 73f1297e 04d72390 04d7690c 73f1b993 dsound!DirectSoundCreate+0x537c
04fcffb4 7c80b6a3 04d7690c 04d72390 04c6fcdc dsound+0x297e
04fcffec 00000000 73f1b94b 04d7690c 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
0000000004fcfd88 ab e9 90 7c 0b 95 80 7c - 40 00 00 00 f0 fc 1b 00 ...|...|@.......
0000000004fcfd98 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000004fcfda8 40 00 00 00 01 00 00 00 - 80 e3 fb 86 fa 02 55 80 @.............U.
0000000004fcfdb8 e6 01 55 80 00 00 00 00 - 38 00 00 00 23 00 00 00 ..U.....8...#...
0000000004fcfdc8 23 00 00 00 90 23 d7 04 - 14 00 00 00 01 00 00 00 #....#..........
0000000004fcfdd8 00 00 00 00 00 00 00 00 - 10 00 00 00 a6 68 91 7c .............h.|
0000000004fcfde8 79 06 81 7c 1b 00 00 00 - 00 a0 fd 7f 00 70 fd 7f y..|.........p..
0000000004fcfdf8 00 70 fd 7f 00 00 00 00 - f0 fc 1b 00 98 3c e3 86 .p...........<..
0000000004fcfe08 40 00 00 00 a4 fd fc 04 - c8 22 1e f7 dc ff fc 04 @........"......
0000000004fcfe18 30 9a 83 7c 00 96 80 7c - 00 00 00 00 40 fe fc 04 0..|...|....@...
0000000004fcfe28 95 a0 80 7c 40 00 00 00 - 78 fe fc 04 00 00 00 00 ...|@...x.......
0000000004fcfe38 ff ff ff ff 00 00 00 00 - 58 fe fc 04 a2 14 f1 73 ........X......s
0000000004fcfe48 40 00 00 00 78 fe fc 04 - 00 00 00 00 ff ff ff ff @...x...........
0000000004fcfe58 78 ff fc 04 4a 29 f1 73 - 40 00 00 00 ff ff ff ff x...J).s@.......
0000000004fcfe68 00 00 00 00 78 fe fc 04 - 0c 69 d7 04 0c 69 d7 04 ....x....i...i..
0000000004fcfe78 08 04 00 00 08 03 00 00 - 00 03 00 00 14 03 00 00 ................
0000000004fcfe88 1c 03 00 00 18 03 00 00 - 20 03 00 00 24 03 00 00 ........ ...$...
0000000004fcfe98 28 03 00 00 2c 03 00 00 - 30 03 00 00 34 03 00 00 (...,...0...4...
0000000004fcfea8 38 03 00 00 3c 03 00 00 - 40 03 00 00 44 03 00 00 8...<...@...D...
0000000004fcfeb8 48 03 00 00 4c 03 00 00 - 50 03 00 00 54 03 00 00 H...L...P...T...
*----> State Dump for Thread Id 0xec8 <----*
eax=00c90004 ebx=052cfdb8 ecx=052cfe60 edx=7c90eb94 esi=00000000 edi=7ffda000
eip=7c90eb94 esp=052cfd90 ebp=052cfe2c iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
052cfe2c 7c80a095 00000001 052cfe80 00000000 ntdll!KiFastSystemCallRet
052cfe48 73f114a2 00000001 052cfe80 00000000 kernel32!WaitForMultipleObjects+0x18
052cfe60 73f1294a 00000001 000001f4 00000000 dsound+0x14a2
052cff80 73f12a13 000001f4 00000000 00000000 dsound+0x294a
052cffb4 7c80b6a3 04d71efc 01000001 04c6fad4 dsound+0x2a13
052cffec 00000000 73f1b94b 04d71efc 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
00000000052cfd90 ab e9 90 7c 0b 95 80 7c - 01 00 00 00 b8 fd 2c 05 ...|...|......,.
00000000052cfda0 01 00 00 00 00 00 00 00 - ec fd 2c 05 00 00 00 00 ..........,.....
00000000052cfdb0 01 00 00 00 01 00 00 00 - 4c 04 00 00 4d 95 80 7c ........L...M..|
00000000052cfdc0 f4 fd 2c 05 3b 95 80 7c - e8 89 d7 04 00 00 00 00 ..,.;..|........
00000000052cfdd0 e0 fd 2c 05 00 00 00 00 - 14 00 00 00 01 00 00 00 ..,.............
00000000052cfde0 00 00 00 00 00 00 00 00 - 10 00 00 00 c0 b4 b3 ff ................
00000000052cfdf0 ff ff ff ff 68 8e d7 04 - 00 a0 fd 7f 00 50 fd 7f ....h........P..
00000000052cfe00 c8 05 91 7c ec fd 2c 05 - b8 fd 2c 05 51 05 91 7c ...|..,...,.Q..|
00000000052cfe10 01 00 00 00 ac fd 2c 05 - c8 05 91 7c dc ff 2c 05 ......,....|..,.
00000000052cfe20 30 9a 83 7c 00 96 80 7c - 00 00 00 00 48 fe 2c 05 0..|...|....H.,.
00000000052cfe30 95 a0 80 7c 01 00 00 00 - 80 fe 2c 05 00 00 00 00 ...|......,.....
00000000052cfe40 f4 01 00 00 00 00 00 00 - 60 fe 2c 05 a2 14 f1 73 ........`.,....s
00000000052cfe50 01 00 00 00 80 fe 2c 05 - 00 00 00 00 f4 01 00 00 ......,.........
00000000052cfe60 80 ff 2c 05 4a 29 f1 73 - 01 00 00 00 f4 01 00 00 ..,.J).s........
00000000052cfe70 00 00 00 00 80 fe 2c 05 - fc 1e d7 04 fc 1e d7 04 ......,.........
00000000052cfe80 4c 04 00 00 01 00 00 00 - 00 00 00 00 20 00 00 00 L........... ...
00000000052cfe90 04 00 00 00 f0 fd 2c 05 - ac fe 2c 05 dc ff 2c 05 ......,...,...,.
00000000052cfea0 18 ee 90 7c 70 05 91 7c - ab e9 90 7c 0b 95 80 7c ...|p..|...|...|
00000000052cfeb0 00 50 fd 7f 44 ff 2c 05 - 4d 95 80 7c f0 fe 2c 05 .P..D.,.M..|..,.
00000000052cfec0 3b 95 80 7c 00 00 00 00 - fc 1e d7 04 fc 1e d7 04 ;..|............
*----> State Dump for Thread Id 0x888 <----*
eax=00000102 ebx=00aa0000 ecx=0540fedc edx=7c90eb94 esi=0000046c edi=00000000
eip=7c90eb94 esp=0540fedc ebp=0540ff40 iopl=0 nv up ei ng nz ac po cy
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000297
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** WARNING: Unable to verify checksum for C:\Un4seen\XMPlay\Plugins\xmp-ds.dll
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\Un4seen\XMPlay\Plugins\xmp-ds.dll -
ChildEBP RetAddr Args to Child
0540ff40 7c802532 0000046c 0000004b 00000000 ntdll!KiFastSystemCallRet
0540ff54 03171527 0000046c 0000004b 7c911596 kernel32!WaitForSingleObject+0x12
0002ae4c 00000000 00000000 00000000 00000000 xmp-ds+0x1527
*----> Raw Stack Dump <----*
000000000540fedc c0 e9 90 7c cb 25 80 7c - 6c 04 00 00 00 00 00 00 ...|.%.|l.......
000000000540feec 10 ff 40 05 24 83 0d 05 - 80 00 00 00 00 00 aa 00 ..@.$...........
000000000540fefc 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000540ff0c 10 00 00 00 50 8e f4 ff - ff ff ff ff 00 a0 fd 7f ....P...........
000000000540ff1c 00 40 fd 7f 10 ff 40 05 - 02 01 00 00 f0 fe 40 05 .@....@.......@.
000000000540ff2c 00 00 00 00 a4 ff 40 05 - 30 9a 83 7c f8 25 80 7c ......@.0..|.%.|
000000000540ff3c 00 00 00 00 54 ff 40 05 - 32 25 80 7c 6c 04 00 00 ....T.@.2%.|l...
000000000540ff4c 4b 00 00 00 00 00 00 00 - 4c ae 02 00 27 15 17 03 K.......L...'...
000000000540ff5c 6c 04 00 00 4b 00 00 00 - 96 15 91 7c 60 74 aa 00 l...K......|`t..
000000000540ff6c b4 ff 40 05 10 c7 aa 00 - c4 02 00 00 60 80 0d 05 ..@.........`...
000000000540ff7c 24 42 00 00 88 ec 0f 05 - b0 a3 c3 77 00 00 00 00 $B.........w....
000000000540ff8c 96 15 91 7c eb 06 91 7c - 10 c7 aa 00 00 00 00 00 ...|...|........
000000000540ff9c 8c ff 40 05 00 00 00 00 - dc ff 40 05 94 5c c3 77 ..@.......@..\.w
000000000540ffac d8 40 c1 77 00 00 00 00 - ec ff 40 05 a3 b6 80 7c .@.w......@....|
000000000540ffbc 10 c7 aa 00 96 15 91 7c - eb 06 91 7c 10 c7 aa 00 .......|...|....
000000000540ffcc 00 40 fd 7f 00 d6 fb 86 - c0 ff 40 05 88 b9 1f 86 .@........@.....
000000000540ffdc ff ff ff ff 30 9a 83 7c - b0 b6 80 7c 00 00 00 00 ....0..|...|....
000000000540ffec 00 00 00 00 00 00 00 00 - 41 a3 c3 77 10 c7 aa 00 ........A..w....
000000000540fffc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000541000c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
*----> State Dump for Thread Id 0x2f0 <----*
eax=00000000 ebx=05503f58 ecx=05503f48 edx=05504460 esi=00000000 edi=05503f48
eip=77c48a0b esp=05503f10 ebp=05503f18 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\msvcrt.dll -
function: msvcrt!Gettnames
77c489f9 48 dec eax
77c489fa 48 dec eax
77c489fb 7440 jz msvcrt!Gettnames+0x476 (77c48a3d)
77c489fd 48 dec eax
77c489fe 48 dec eax
77c489ff 742b jz msvcrt!Gettnames+0x465 (77c48a2c)
77c48a01 48 dec eax
77c48a02 0f84d0000000 je msvcrt!Gettnames+0x511 (77c48ad8)
77c48a08 48 dec eax
77c48a09 75db jnz msvcrt!Gettnames+0x41f (77c489e6)
FAULT ->77c48a0b 8b4614 mov eax,[esi+0x14] ds:0023:00000014=????????
77c48a0e 99 cdq
77c48a0f 6a64 push 0x64
77c48a11 59 pop ecx
77c48a12 f7f9 idiv ecx
77c48a14 ff7514 push dword ptr [ebp+0x14]
77c48a17 6a04 push 0x4
77c48a19 83c013 add eax,0x13
77c48a1c 6bc064 imul eax,eax,0x64
77c48a1f 03c2 add eax,edx
77c48a21 5a pop edx
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
05503f18 77c4906a 77c5f7a0 00000000 77c5ff18 msvcrt!Gettnames+0x444
05503f3c 77c490c3 77c5f7a0 05504040 00000014 msvcrt!Gettnames+0xaa3
05503f5c 77c490e5 05504040 00000014 66bf381b msvcrt!Strftime+0x2f
05503f78 66ac8610 05504040 00000014 66bf381b msvcrt!strftime+0x18
05506d18 66ac8b6c 05507210 02695008 73697774 xmp-scrobbler!DllMain+0x7250
05507238 66ac464e 02695008 6867694e 73697774 xmp-scrobbler!DllMain+0x77ac
05507a68 66ac61c2 66bf3654 0550ff14 00000000 xmp-scrobbler!DllMain+0x328e
05507ab8 00420ae0 00000001 05507acc 00001089 xmp-scrobbler!DllMain+0x4e02
0550ff50 004202f7 00000000 00aa51b0 00aa8030 xmplay+0x20ae0
0550ff80 77c3a243 00000000 00000000 00000000 xmplay+0x202f7
0550ffb4 7c80b6a3 00aa8030 00000000 00000000 msvcrt!endthread+0xaf
0550ffec 00000000 77c3a1d7 00aa8030 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
0000000005503f10 18 ff c5 77 1c 38 bf 66 - 3c 3f 50 05 6a 90 c4 77 ...w.8.f<?P.j..w
0000000005503f20 a0 f7 c5 77 00 00 00 00 - 18 ff c5 77 00 00 00 00 ...w.......w....
0000000005503f30 02 00 00 00 60 40 50 05 - 14 00 00 00 5c 3f 50 05 ....`@P.....\?P.
0000000005503f40 c3 90 c4 77 a0 f7 c5 77 - 40 40 50 05 14 00 00 00 ...w...w@@P.....
0000000005503f50 1b 38 bf 66 00 00 00 00 - 14 00 00 00 78 3f 50 05 .8.f........x?P.
0000000005503f60 e5 90 c4 77 40 40 50 05 - 14 00 00 00 1b 38 bf 66 ...w@@P......8.f
0000000005503f70 00 00 00 00 00 00 00 00 - 18 6d 50 05 10 86 ac 66 .........mP....f
0000000005503f80 40 40 50 05 14 00 00 00 - 1b 38 bf 66 00 00 00 00 @@P......8.f....
0000000005503f90 04 00 00 00 d0 50 aa 00 - 04 00 00 00 40 50 aa 00 .....P......@P..
0000000005503fa0 04 00 00 00 e0 42 aa 00 - 04 00 00 00 01 01 00 00 .....B..........
0000000005503fb0 04 00 00 00 60 43 50 05 - 00 00 00 00 00 00 00 00 ....`CP.........
0000000005503fc0 00 00 00 00 00 00 00 00 - 00 00 00 00 4c 64 69 02 ............Ldi.
0000000005503fd0 00 00 00 00 00 00 00 00 - 20 70 aa 00 90 00 00 00 ........ p......
0000000005503fe0 73 00 00 00 46 00 00 00 - 0c 00 00 00 b0 53 aa 00 s...F........S..
0000000005503ff0 e0 42 aa 00 40 50 aa 00 - d0 50 aa 00 d0 52 aa 00 .B..@P...P...R..
0000000005504000 05 00 00 00 10 50 69 02 - 08 50 69 02 4c 71 50 05 .....Pi..Pi.LqP.
0000000005504010 02 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000005504020 00 00 00 00 e0 0e ba 66 - 6a 08 be 66 00 6d 50 05 .......fj..f.mP.
0000000005504030 b1 89 ac 66 80 3f 50 05 - 00 00 00 00 00 00 00 00 ...f.?P.........
0000000005504040 32 30 30 37 2d 30 39 2d - 31 37 20 30 35 3a 30 30 2007-09-17 05:00
*----> State Dump for Thread Id 0x114 <----*
eax=7c92798d ebx=00000000 ecx=00000000 edx=7ffd6c00 esi=00000000 edi=00000000
eip=7c90eb94 esp=0572ff9c ebp=0572ffb4 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0572ffb4 7c80b6a3 00000000 00000000 00000000 ntdll!KiFastSystemCallRet
0572ffec 00000000 7c92798d 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
000000000572ff9c 5c d8 90 7c d4 79 92 7c - 01 00 00 00 ac ff 72 05 \..|.y.|......r.
000000000572ffac 00 00 00 00 00 00 00 80 - ec ff 72 05 a3 b6 80 7c ..........r....|
000000000572ffbc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000572ffcc 00 e0 fa 7f 00 d6 fb 86 - c0 ff 72 05 30 ac 02 85 ..........r.0...
000000000572ffdc ff ff ff ff 30 9a 83 7c - b0 b6 80 7c 00 00 00 00 ....0..|...|....
000000000572ffec 00 00 00 00 00 00 00 00 - 8d 79 92 7c 00 00 00 00 .........y.|....
000000000572fffc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000573000c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000573001c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000573002c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000573003c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000573004c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000573005c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000573006c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000573007c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000573008c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000573009c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000057300ac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000057300bc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000057300cc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
Application exception occurred:
App: C:\Un4seen\XMPlay\xmplay.exe (pid=3376)
When: 18-Sep-07 @ 21:54:28.591
Exception number: c0000005 (access violation)
*----> System Information <----*
Computer Name: KALI
User Name: Owner
Terminal Session Id: 0
Number of Processors: 2
Processor Type: x86 Family 15 Model 3 Stepping 4
Windows Version: 5.1
Current Build: 2600
Service Pack: 2
Current Type: Multiprocessor Free
Registered Organization:
Registered Owner: Thomas Ditmars
*----> Task List <----*
0 System Process
4 System
1020 smss.exe
1088 csrss.exe
1132 winlogon.exe
1184 services.exe
1196 lsass.exe
1368 Ati2evxx.exe
1396 svchost.exe
1548 svchost.exe
1688 svchost.exe
1788 Ati2evxx.exe
2024 svchost.exe
452 spoolsv.exe
680 AppleMobileDeviceService.exe
724 avgamsvr.exe
784 Explorer.EXE
864 avgupsvc.exe
920 avgemc.exe
936 BOCORE.exe
1100 persfw.exe
1156 PRISMXL.SYS
292 alg.exe
2352 svchost.exe
2420 CTHELPER.EXE
2512 avgcc.exe
2528 PDVDServ.exe
2620 BOC425.exe
2656 winpatrol.exe
2724 ctfmon.exe
2748 pg2.exe
2800 hm.exe
2836 hostssrv.exe
2884 taskbarshuffle.exe
2952 TeaTimer.exe
3064 iSproggler.exe
3144 daemon.exe
3196 atitray.exe
3428 GPGtray.exe
3568 nistime-32bit.exe
3560 iTunes.exe
3596 xchat.exe
740 LastFMHelper.exe
3492 LastFM.exe
384 iPodService.exe
3700 iTunesHelper.exe
3844 trillian.exe
3316 firefox.exe
3044 thunderbird.exe
1888 SAM.exe
3096 Skype.exe
3264 SkypePM.exe
3100 Explorer.EXE
3020 EDITPLUS.EXE
3376 xmplay.exe
2124 drwtsn32.exe
*----> Module List <----*
(0000000000330000 - 0000000000339000: C:\WINDOWS\system32\Normaliz.dll
(0000000000400000 - 0000000000552000: C:\Un4seen\XMPlay\xmplay.exe
(0000000000e40000 - 0000000000e4f000: C:\Program Files\BillP Studios\WinPatrol\PATROLPRO.DLL
(0000000000e60000 - 0000000000f3c000: C:\Un4seen\XMPlay\Plugins\in_adlib.dll
(0000000001060000 - 00000000011a5000: C:\Un4seen\XMPlay\Plugins\in_flac.dll
(00000000011b0000 - 00000000012a1000: C:\Un4seen\XMPlay\Plugins\in_gsf.dll
(00000000012b0000 - 000000000136f000: C:\Un4seen\XMPlay\Plugins\in_mp3.dll
(00000000013b0000 - 0000000001426000: C:\Un4seen\XMPlay\Plugins\in_mp3PRO.dll
(0000000001440000 - 00000000014e0000: C:\Un4seen\XMPlay\Plugins\in_mp4.dll
(00000000014e0000 - 0000000001519000: C:\Un4seen\XMPlay\Plugins\in_mpc.dll
(0000000001520000 - 000000000169b000: C:\Un4seen\XMPlay\Plugins\in_msx.dll
(00000000016b0000 - 00000000017c0000: C:\Un4seen\XMPlay\Plugins\in_psf.dll
(00000000017e0000 - 0000000001866000: C:\Un4seen\XMPlay\Plugins\in_qsf.dll
(0000000001880000 - 0000000001990000: C:\Un4seen\XMPlay\Plugins\in_sap.dll
(0000000001aa0000 - 0000000001b6e000: C:\Un4seen\XMPlay\Plugins\in_snes.dll
(0000000001c80000 - 0000000001d24000: C:\Un4seen\XMPlay\Plugins\SNESAPU.DLL
(0000000001d40000 - 0000000001e27000: C:\Un4seen\XMPlay\Plugins\in_usf.dll
(0000000001e30000 - 0000000001f25000: C:\Un4seen\XMPlay\Plugins\in_vgm.dll
(0000000001f40000 - 0000000001f7c000: C:\Un4seen\XMPlay\Plugins\in_vorbis.dll
(0000000001f80000 - 0000000001f8b000: C:\Un4seen\XMPlay\Plugins\in_wave.dll
(0000000001f90000 - 0000000002033000: C:\Un4seen\XMPlay\Plugins\in_yansf.dll
(00000000021e0000 - 0000000002257000: C:\Un4seen\XMPlay\Plugins\nsfplug_ui.dll
(0000000002380000 - 0000000002386000: C:\WINDOWS\system32\ctagent.dll
(00000000024c0000 - 00000000024c8000: C:\Un4seen\XMPlay\Plugins\xmp-7z.dll
(00000000024d0000 - 0000000002513000: C:\Un4seen\XMPlay\Plugins\xmp-aac.dll
(0000000002520000 - 00000000025a8000: C:\Un4seen\XMPlay\Plugins\xmp-ahx.dll
(0000000003140000 - 000000000314c000: C:\Un4seen\XMPlay\Plugins\xmp-arj.dll
(0000000003150000 - 0000000003157000: C:\Un4seen\XMPlay\Plugins\xmp-asio.dll
(0000000003160000 - 0000000003169000: C:\Un4seen\XMPlay\Plugins\xmp-cd.dll
(0000000003170000 - 0000000003177000: C:\Un4seen\XMPlay\Plugins\xmp-ds.dll
(0000000003180000 - 000000000318e000: C:\Un4seen\XMPlay\Plugins\xmp-flac.dll
(0000000003190000 - 000000000319d000: C:\Un4seen\XMPlay\Plugins\xmp-lha.dll
(00000000031a0000 - 00000000031ad000: C:\Un4seen\XMPlay\Plugins\xmp-midi.dll
(00000000031b0000 - 00000000031b6000: C:\Un4seen\XMPlay\Plugins\xmp-mmcmp.dll
(00000000031c0000 - 00000000031cb000: C:\Un4seen\XMPlay\Plugins\xmp-modpacker.dll
(00000000031d0000 - 00000000031df000: C:\Un4seen\XMPlay\Plugins\xmp-mpc.dll
(00000000031e0000 - 00000000031e6000: C:\Un4seen\XMPlay\Plugins\xmp-pp.dll
(0000000003200000 - 000000000320f000: C:\Un4seen\XMPlay\Plugins\xmp-rar.dll
(0000000003220000 - 0000000003227000: C:\Un4seen\XMPlay\Plugins\xmp-wadsp.dll
(0000000003230000 - 0000000003238000: C:\Un4seen\XMPlay\Plugins\xmp-wma.dll
(0000000003260000 - 00000000032b6000: C:\WINDOWS\system32\MSVCR71.dll
(00000000032d0000 - 00000000032da000: C:\Un4seen\XMPlay\Plugins\xmp-zip.dll
(00000000032e0000 - 0000000003441000: C:\Un4seen\XMPlay\Plugins\xmp-psf.dll
(0000000003550000 - 00000000035d9000: C:\Un4seen\XMPlay\Plugins\xmp-sid.dll
(0000000010000000 - 0000000010044000: C:\Program Files\Ray Adams\ATI Tray Tools\raphook.dll
(0000000016000000 - 0000000016028000: C:\Program Files\Trillian\events.dll
(0000000016080000 - 00000000160a5000: C:\Program Files\Bonjour\mdnsNSP.dll
(0000000042990000 - 00000000429d5000: C:\WINDOWS\system32\iertutil.dll
(0000000042c10000 - 0000000042cdf000: C:\WINDOWS\system32\WININET.dll
(0000000042cf0000 - 0000000042e14000: C:\WINDOWS\system32\urlmon.dll
(000000005ad70000 - 000000005ada8000: C:\WINDOWS\system32\uxtheme.dll
(000000005b860000 - 000000005b8b4000: C:\WINDOWS\system32\NETAPI32.dll
(00000000629c0000 - 00000000629c9000: C:\WINDOWS\system32\LPK.DLL
(00000000662b0000 - 0000000066308000: C:\WINDOWS\system32\hnetcfg.dll
(0000000066ac0000 - 0000000066c50000: C:\Un4seen\XMPlay\Plugins\xmp-scrobbler.dll
(0000000071a50000 - 0000000071a8f000: C:\WINDOWS\System32\mswsock.dll
(0000000071a90000 - 0000000071a98000: C:\WINDOWS\System32\wshtcpip.dll
(0000000071aa0000 - 0000000071aa8000: C:\WINDOWS\system32\WS2HELP.dll
(0000000071ab0000 - 0000000071ac7000: C:\WINDOWS\system32\WS2_32.dll
(0000000071ad0000 - 0000000071ad9000: C:\WINDOWS\system32\WSOCK32.dll
(00000000722b0000 - 00000000722b5000: C:\WINDOWS\system32\sensapi.dll
(0000000072d10000 - 0000000072d18000: C:\WINDOWS\system32\msacm32.drv
(0000000072d20000 - 0000000072d29000: C:\WINDOWS\system32\wdmaud.drv
(0000000073000000 - 0000000073026000: C:\WINDOWS\system32\WINSPOOL.DRV
(0000000073ee0000 - 0000000073ee4000: C:\WINDOWS\system32\KsUser.dll
(0000000073f10000 - 0000000073f6c000: C:\WINDOWS\system32\dsound.dll
(0000000074720000 - 000000007476b000: C:\WINDOWS\system32\MSCTF.dll
(0000000074d90000 - 0000000074dfb000: C:\WINDOWS\system32\USP10.dll
(00000000755c0000 - 00000000755ee000: C:\WINDOWS\system32\msctfime.ime
(0000000076390000 - 00000000763ad000: C:\WINDOWS\system32\IMM32.DLL
(00000000763b0000 - 00000000763f9000: C:\WINDOWS\system32\comdlg32.dll
(00000000769c0000 - 0000000076a73000: C:\WINDOWS\system32\USERENV.dll
(0000000076b40000 - 0000000076b6d000: C:\WINDOWS\system32\WINMM.dll
(0000000076bf0000 - 0000000076bfb000: C:\WINDOWS\system32\PSAPI.DLL
(0000000076c30000 - 0000000076c5e000: C:\WINDOWS\system32\WINTRUST.dll
(0000000076c90000 - 0000000076cb8000: C:\WINDOWS\system32\IMAGEHLP.dll
(0000000076d60000 - 0000000076d79000: C:\WINDOWS\system32\iphlpapi.dll
(0000000076e80000 - 0000000076e8e000: C:\WINDOWS\system32\rtutils.dll
(0000000076e90000 - 0000000076ea2000: C:\WINDOWS\system32\rasman.dll
(0000000076eb0000 - 0000000076edf000: C:\WINDOWS\system32\TAPI32.dll
(0000000076ee0000 - 0000000076f1c000: C:\WINDOWS\system32\RASAPI32.dll
(0000000076f20000 - 0000000076f47000: C:\WINDOWS\system32\DNSAPI.dll
(0000000076f60000 - 0000000076f8c000: C:\WINDOWS\system32\WLDAP32.dll
(0000000076fb0000 - 0000000076fb8000: C:\WINDOWS\System32\winrnr.dll
(0000000076fc0000 - 0000000076fc6000: C:\WINDOWS\system32\rasadhlp.dll
(0000000077120000 - 00000000771ab000: C:\WINDOWS\system32\OLEAUT32.dll
(00000000773d0000 - 00000000774d3000: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\COMCTL32.dll
(00000000774e0000 - 000000007761d000: C:\WINDOWS\system32\ole32.dll
(0000000077920000 - 0000000077a13000: C:\WINDOWS\system32\SETUPAPI.dll
(0000000077a80000 - 0000000077b14000: C:\WINDOWS\system32\CRYPT32.dll
(0000000077b20000 - 0000000077b32000: C:\WINDOWS\system32\MSASN1.dll
(0000000077b40000 - 0000000077b62000: C:\WINDOWS\system32\Apphelp.dll
(0000000077bd0000 - 0000000077bd7000: C:\WINDOWS\system32\midimap.dll
(0000000077be0000 - 0000000077bf5000: C:\WINDOWS\system32\MSACM32.dll
(0000000077c00000 - 0000000077c08000: C:\WINDOWS\system32\VERSION.DLL
(0000000077c10000 - 0000000077c68000: C:\WINDOWS\system32\msvcrt.dll
(0000000077c70000 - 0000000077c93000: C:\WINDOWS\system32\msv1_0.dll
(0000000077dd0000 - 0000000077e6b000: C:\WINDOWS\system32\ADVAPI32.dll
(0000000077e70000 - 0000000077f01000: C:\WINDOWS\system32\RPCRT4.dll
(0000000077f10000 - 0000000077f57000: C:\WINDOWS\system32\GDI32.dll
(0000000077f60000 - 0000000077fd6000: C:\WINDOWS\system32\SHLWAPI.dll
(0000000077fe0000 - 0000000077ff1000: C:\WINDOWS\system32\Secur32.dll
(000000007c3a0000 - 000000007c41b000: C:\WINDOWS\system32\MSVCP71.dll
(000000007c800000 - 000000007c8f5000: C:\WINDOWS\system32\kernel32.dll
(000000007c900000 - 000000007c9b0000: C:\WINDOWS\system32\ntdll.dll
(000000007c9c0000 - 000000007d1d5000: C:\WINDOWS\system32\SHELL32.dll
(000000007e410000 - 000000007e4a0000: C:\WINDOWS\system32\USER32.dll
*----> State Dump for Thread Id 0x5d8 <----*
eax=0012ff08 ebx=005510b6 ecx=00000000 edx=7c90eb94 esi=0012ff08 edi=00000000
eip=7c90eb94 esp=0012d7b0 ebp=0012d7d4 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00200246
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\ntdll.dll -
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
*** WARNING: Unable to verify checksum for C:\Un4seen\XMPlay\xmplay.exe
*** ERROR: Module load completed but symbols could not be loaded for C:\Un4seen\XMPlay\xmplay.exe
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\kernel32.dll -
ChildEBP RetAddr Args to Child
0012d7d4 0043da74 0012ff08 00000000 00000000 ntdll!KiFastSystemCallRet
0012ff24 00445cdf 00400000 00000000 0015232f xmplay+0x3da74
0012ffc0 7c816ff7 011dcf78 00000018 7ffdb000 xmplay+0x45cdf
0012fff0 00000000 00551039 00000000 78746341 kernel32!RegisterWaitForInputIdle+0x49
*----> Raw Stack Dump <----*
000000000012d7b0 be 91 41 7e 42 e0 42 7e - 08 ff 12 00 00 00 00 00 ..A~B.B~........
000000000012d7c0 00 00 00 00 00 00 00 00 - b6 10 55 00 00 00 00 00 ..........U.....
000000000012d7d0 02 e0 42 7e 24 ff 12 00 - 74 da 43 00 08 ff 12 00 ..B~$...t.C.....
000000000012d7e0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000012d7f0 78 cf 1d 01 2f 23 15 00 - ff 78 6d 70 2d 73 63 72 x.../#...xmp-scr
000000000012d800 6f 62 62 6c 65 72 2e 64 - 6c 6c 00 00 24 05 01 00 obbler.dll..$...
000000000012d810 00 00 5a 61 72 67 67 67 - 00 00 00 00 00 00 00 00 ..Zarggg........
000000000012d820 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000012d830 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000012d840 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000012d850 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000012d860 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000012d870 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000012d880 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000012d890 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000012d8a0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000012d8b0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000012d8c0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000012d8d0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000012d8e0 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
*----> State Dump for Thread Id 0xb84 <----*
eax=00000000 ebx=00d6fed0 ecx=00d6fea8 edx=7c90eb94 esi=00000000 edi=7ffdb000
eip=7c90eb94 esp=00d6fea8 ebp=00d6ff44 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\ADVAPI32.dll -
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
00d6ff44 77df9b26 00000002 00d6ff6c 00000000 ntdll!KiFastSystemCallRet
00d6ffb4 7c80b6a3 00000000 7c9140bb 00000000 ADVAPI32!RegDeleteKeyW+0x2a2
00d6ffec 00000000 77df9981 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
0000000000d6fea8 ab e9 90 7c 0b 95 80 7c - 02 00 00 00 d0 fe d6 00 ...|...|........
0000000000d6feb8 01 00 00 00 01 00 00 00 - 04 ff d6 00 e8 3e b7 00 .............>..
0000000000d6fec8 40 65 e4 77 00 10 00 00 - 64 00 00 00 6c 00 00 00 @e.w....d...l...
0000000000d6fed8 c0 fe d6 00 48 72 40 e1 - dc ff d6 00 30 9a 83 7c ....Hr@.....0..|
0000000000d6fee8 d0 0a 81 7c 00 10 00 00 - 14 00 00 00 01 00 00 00 ...|............
0000000000d6fef8 00 00 00 00 00 00 00 00 - 10 00 00 00 00 a2 2f 4d ............../M
0000000000d6ff08 ff ff ff ff 00 10 00 00 - 00 b0 fd 7f 00 e0 fd 7f ................
0000000000d6ff18 dc ff d6 00 04 ff d6 00 - d0 fe d6 00 06 00 00 00 ................
0000000000d6ff28 02 00 00 00 c4 fe d6 00 - 06 00 00 00 dc ff d6 00 ................
0000000000d6ff38 30 9a 83 7c 00 96 80 7c - 00 00 00 00 b4 ff d6 00 0..|...|........
0000000000d6ff48 26 9b df 77 02 00 00 00 - 6c ff d6 00 00 00 00 00 &..w....l.......
0000000000d6ff58 e0 93 04 00 01 00 00 00 - bb 40 91 7c 00 00 00 00 .........@.|....
0000000000d6ff68 00 00 00 00 64 00 00 00 - 6c 00 00 00 00 10 00 00 ....d...l.......
0000000000d6ff78 e8 3e b7 00 00 00 00 00 - 00 10 00 00 e0 2e b7 00 .>..............
0000000000d6ff88 80 66 e4 77 30 00 00 00 - a0 66 e4 77 00 10 00 00 .f.w0....f.w....
0000000000d6ff98 00 00 00 00 80 66 e4 77 - e8 3e b7 00 a0 66 e4 77 .....f.w.>...f.w
0000000000d6ffa8 e5 03 00 00 00 10 00 00 - e0 2e b7 00 ec ff d6 00 ................
0000000000d6ffb8 a3 b6 80 7c 00 00 00 00 - bb 40 91 7c 00 00 00 00 ...|.....@.|....
0000000000d6ffc8 00 00 00 00 00 e0 fd 7f - 00 b6 fb 86 c0 ff d6 00 ................
0000000000d6ffd8 c8 00 ba 85 ff ff ff ff - 30 9a 83 7c b0 b6 80 7c ........0..|...|
*----> State Dump for Thread Id 0x838 <----*
eax=00000001 ebx=00000001 ecx=00000000 edx=00000000 esi=5a011478 edi=00000000
eip=7c90eb94 esp=047166dc ebp=04716720 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
04716720 0043eb70 5a011478 00000010 0000001c ntdll!KiFastSystemCallRet
0471ff64 0043e2ff 00000038 00a85420 0471ffb4 xmplay+0x3eb70
7e41c465 e87e41c4 ffffc14f e8084d8b ffffc057 xmplay+0x3e2ff
98680c6a 00000000 00000000 00000000 00000000 0xe87e41c4
*----> Raw Stack Dump <----*
00000000047166dc 36 bb f1 77 1f bb f1 77 - 78 14 01 5a 10 00 00 00 6..w...wx..Z....
00000000047166ec 1c 00 00 00 86 01 00 00 - 77 00 00 00 2b 22 01 12 ........w...+"..
00000000047166fc 00 00 00 00 00 00 00 00 - 86 01 00 00 77 00 00 00 ............w...
000000000471670c 20 00 cc 00 ff ff ff ff - 42 01 00 00 78 14 01 5a .......B...x..Z
000000000471671c 1c 00 00 00 64 ff 71 04 - 70 eb 43 00 78 14 01 5a ....d.q.p.C.x..Z
000000000471672c 10 00 00 00 1c 00 00 00 - 86 01 00 00 77 00 00 00 ............w...
000000000471673c 2b 22 01 12 00 00 00 00 - 00 00 00 00 86 01 00 00 +"..............
000000000471674c 77 00 00 00 20 00 cc 00 - 00 00 00 00 00 00 00 00 w... ...........
000000000471675c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000471676c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000471677c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000471678c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000471679c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000047167ac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000047167bc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000047167cc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000047167dc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000047167ec 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000047167fc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000471680c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
*----> State Dump for Thread Id 0xb2c <----*
eax=0499fc68 ebx=01027fe8 ecx=0499fc48 edx=00000001 esi=00000168 edi=00000000
eip=7c90eb94 esp=0499fefc ebp=0499ff60 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00200246
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\Un4seen\XMPlay\Plugins\xmp-scrobbler.dll -
ChildEBP RetAddr Args to Child
0499ff60 7c802532 00000168 ffffffff 00000000 ntdll!KiFastSystemCallRet
0499ff74 66ac760f 00000168 ffffffff 010245e4 kernel32!WaitForSingleObject+0x12
0499ffa4 66bb31a1 01021d60 7c90e2dc 0499ffec xmp-scrobbler!DllMain+0x624f
0499ffb4 7c80b6a3 01021d60 0489f9e0 00000001 xmp-scrobbler+0xf31a1
0499ffec 00000000 66bb3190 01021d60 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
000000000499fefc c0 e9 90 7c cb 25 80 7c - 68 01 00 00 00 00 00 00 ...|.%.|h.......
000000000499ff0c 00 00 00 00 e4 45 02 01 - 60 1d 02 01 e8 7f 02 01 .....E..`.......
000000000499ff1c 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000499ff2c 10 00 00 00 e4 45 02 01 - 60 1d 02 01 00 b0 fd 7f .....E..`.......
000000000499ff3c 00 a0 fd 7f 00 00 00 00 - e3 c2 c2 77 10 ff 99 04 ...........w....
000000000499ff4c 30 ff 99 04 dc ff 99 04 - 30 9a 83 7c f8 25 80 7c 0.......0..|.%.|
000000000499ff5c 00 00 00 00 74 ff 99 04 - 32 25 80 7c 68 01 00 00 ....t...2%.|h...
000000000499ff6c ff ff ff ff 00 00 00 00 - a4 ff 99 04 0f 76 ac 66 .............v.f
000000000499ff7c 68 01 00 00 ff ff ff ff - e4 45 02 01 01 00 00 00 h........E......
000000000499ff8c 00 00 00 00 a0 cd d9 84 - 00 00 00 00 60 1d 02 01 ............`...
000000000499ff9c 01 00 00 00 e0 f9 89 04 - b4 ff 99 04 a1 31 bb 66 .............1.f
000000000499ffac 60 1d 02 01 dc e2 90 7c - ec ff 99 04 a3 b6 80 7c `......|.......|
000000000499ffbc 60 1d 02 01 e0 f9 89 04 - 01 00 00 00 60 1d 02 01 `...........`...
000000000499ffcc 00 a0 fd 7f 00 d6 fb 86 - c0 ff 99 04 70 67 f1 84 ............pg..
000000000499ffdc ff ff ff ff 30 9a 83 7c - b0 b6 80 7c 00 00 00 00 ....0..|...|....
000000000499ffec 00 00 00 00 00 00 00 00 - 90 31 bb 66 60 1d 02 01 .........1.f`...
000000000499fffc 00 00 00 00 c8 00 00 00 - 82 01 00 00 ff ee ff ee ................
00000000049a000c 02 10 00 00 00 00 00 00 - 00 fe 00 00 00 00 10 00 ................
00000000049a001c 00 20 00 00 00 02 00 00 - 00 20 00 00 2f fc 01 00 . ....... ../...
00000000049a002c ff ef fd 7f 17 00 08 06 - 00 00 00 00 00 00 00 00 ................
*----> State Dump for Thread Id 0x8d8 <----*
eax=7ffd9000 ebx=c0000000 ecx=00000000 edx=045d2688 esi=00000000 edi=71a87558
eip=7c90eb94 esp=04b9ff7c ebp=04b9ffb4 iopl=0 nv up ei pl nz na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
04b9ffb4 7c80b6a3 71a5d8ec 0499f8e4 7c90ee18 ntdll!KiFastSystemCallRet
04b9ffec 00000000 71a5d5af 0018e478 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
0000000004b9ff7c 1b e3 90 7c 09 d6 a5 71 - cc 01 00 00 bc ff b9 04 ...|...q........
0000000004b9ff8c b0 ff b9 04 a4 ff b9 04 - 50 d6 a5 71 e4 f8 99 04 ........P..q....
0000000004b9ff9c 18 ee 90 7c 78 e4 18 00 - 00 00 00 00 00 00 00 00 ...|x...........
0000000004b9ffac 00 00 a5 71 08 28 5d 04 - ec ff b9 04 a3 b6 80 7c ...q.(]........|
0000000004b9ffbc ec d8 a5 71 e4 f8 99 04 - 18 ee 90 7c 78 e4 18 00 ...q.......|x...
0000000004b9ffcc 00 90 fd 7f 00 d6 fb 86 - c0 ff b9 04 b8 c8 80 84 ................
0000000004b9ffdc ff ff ff ff 30 9a 83 7c - b0 b6 80 7c 00 00 00 00 ....0..|...|....
0000000004b9ffec 00 00 00 00 00 00 00 00 - af d5 a5 71 78 e4 18 00 ...........qx...
0000000004b9fffc 00 00 00 00 c8 00 00 00 - 91 01 00 00 ff ee ff ee ................
0000000004ba000c 02 10 00 00 00 00 00 00 - 00 fe 00 00 00 00 10 00 ................
0000000004ba001c 00 20 00 00 00 02 00 00 - 00 20 00 00 f3 01 00 00 . ....... ......
0000000004ba002c ff ef fd 7f 1a 00 08 06 - 00 00 00 00 00 00 00 00 ................
0000000004ba003c 00 00 00 00 00 00 00 00 - 98 05 ba 04 0f 00 00 00 ................
0000000004ba004c f8 ff ff ff 50 00 ba 04 - 50 00 ba 04 40 06 ba 04 ....P...P...@...
0000000004ba005c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000004ba006c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000004ba007c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000004ba008c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000004ba009c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000004ba00ac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
*----> State Dump for Thread Id 0xcf0 <----*
eax=72d230e8 ebx=04d1fef8 ecx=0000005e edx=00000000 esi=00000000 edi=7ffdb000
eip=7c90eb94 esp=04d1fed0 ebp=04d1ff6c iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\wdmaud.drv -
ChildEBP RetAddr Args to Child
04d1ff6c 7c80a095 00000002 04d1ffa4 00000000 ntdll!KiFastSystemCallRet
04d1ff88 72d2312a 00000002 04d1ffa4 00000000 kernel32!WaitForMultipleObjects+0x18
04d1ffb4 7c80b6a3 00000000 00000000 00150000 wdmaud!midMessage+0x348
04d1ffec 00000000 72d230e8 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
0000000004d1fed0 ab e9 90 7c 0b 95 80 7c - 02 00 00 00 f8 fe d1 04 ...|...|........
0000000004d1fee0 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000004d1fef0 00 00 00 00 00 00 00 00 - 4c 02 00 00 0c 02 00 00 ........L.......
0000000004d1ff00 ac 04 ea 84 28 6c d6 aa - 00 00 00 00 27 f4 6f 80 ....(l......'.o.
0000000004d1ff10 08 00 00 00 46 02 00 00 - 14 00 00 00 01 00 00 00 ....F...........
0000000004d1ff20 00 00 00 00 00 00 00 00 - 10 00 00 00 10 03 ea 84 ................
0000000004d1ff30 44 03 ea 84 06 02 00 00 - 00 b0 fd 7f 00 80 fd 7f D...............
0000000004d1ff40 10 03 ea 84 00 00 00 00 - f8 fe d1 04 ac 9b 4f 80 ..............O.
0000000004d1ff50 02 00 00 00 ec fe d1 04 - 00 00 00 00 dc ff d1 04 ................
0000000004d1ff60 30 9a 83 7c 00 96 80 7c - 00 00 00 00 88 ff d1 04 0..|...|........
0000000004d1ff70 95 a0 80 7c 02 00 00 00 - a4 ff d1 04 00 00 00 00 ...|............
0000000004d1ff80 ff ff ff ff 00 00 00 00 - b4 ff d1 04 2a 31 d2 72 ............*1.r
0000000004d1ff90 02 00 00 00 a4 ff d1 04 - 00 00 00 00 ff ff ff ff ................
0000000004d1ffa0 00 00 15 00 4c 02 00 00 - 0c 02 00 00 f2 fe 6f 80 ....L.........o.
0000000004d1ffb0 dc e2 90 7c ec ff d1 04 - a3 b6 80 7c 00 00 00 00 ...|.......|....
0000000004d1ffc0 00 00 00 00 00 00 15 00 - 00 00 00 00 00 80 fd 7f ................
0000000004d1ffd0 00 d6 fb 86 c0 ff d1 04 - b8 c8 80 84 ff ff ff ff ................
0000000004d1ffe0 30 9a 83 7c b0 b6 80 7c - 00 00 00 00 00 00 00 00 0..|...|........
0000000004d1fff0 00 00 00 00 e8 30 d2 72 - 00 00 00 00 00 00 00 00 .....0.r........
0000000004d20000 43 6c 69 65 6e 74 20 55 - 72 6c 43 61 63 68 65 20 Client UrlCache
*----> State Dump for Thread Id 0x720 <----*
eax=7c92798d ebx=00000000 ecx=00000000 edx=7ffd7c00 esi=00000000 edi=00000000
eip=7c90eb94 esp=0511ff9c ebp=0511ffb4 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0511ffb4 7c80b6a3 00000000 00000000 00000000 ntdll!KiFastSystemCallRet
0511ffec 00000000 7c92798d 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
000000000511ff9c 5c d8 90 7c d4 79 92 7c - 01 00 00 00 ac ff 11 05 \..|.y.|........
000000000511ffac 00 00 00 00 00 00 00 80 - ec ff 11 05 a3 b6 80 7c ...............|
000000000511ffbc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000511ffcc 00 60 fd 7f 00 d6 fb 86 - c0 ff 11 05 38 0d 99 84 .`..........8...
000000000511ffdc ff ff ff ff 30 9a 83 7c - b0 b6 80 7c 00 00 00 00 ....0..|...|....
000000000511ffec 00 00 00 00 00 00 00 00 - 8d 79 92 7c 00 00 00 00 .........y.|....
000000000511fffc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000512000c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000512001c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000512002c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000512003c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000512004c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000512005c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000512006c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000512007c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000512008c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000512009c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000051200ac 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000051200bc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000051200cc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
*----> State Dump for Thread Id 0x324 <----*
eax=73f19f98 ebx=05fb34d8 ecx=04503ccc edx=7c90eb94 esi=00000000 edi=7ffdb000
eip=7c90eb94 esp=0501fd88 ebp=0501fe24 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\dsound.dll -
ChildEBP RetAddr Args to Child
0501fe24 7c80a095 00000040 0501fe78 00000000 ntdll!KiFastSystemCallRet
0501fe40 73f114a2 00000040 0501fe78 00000000 kernel32!WaitForMultipleObjects+0x18
0501fe58 73f1294a 00000040 ffffffff 00000000 dsound+0x14a2
0501ff78 73f19fbf ffffffff 0000003f 04506928 dsound+0x294a
0501ff98 73f1297e 04502270 04503ccc 73f1b993 dsound!DirectSoundCreate+0x537c
0501ffb4 7c80b6a3 04503ccc 04502270 0489fcdc dsound+0x297e
0501ffec 00000000 73f1b94b 04503ccc 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
000000000501fd88 ab e9 90 7c 0b 95 80 7c - 40 00 00 00 d8 34 fb 05 ...|...|@....4..
000000000501fd98 01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000501fda8 40 00 00 00 01 00 00 00 - 40 6d 29 e1 2c f0 39 e4 @.......@m).,.9.
000000000501fdb8 00 00 00 00 00 00 00 00 - 38 00 00 00 23 00 00 00 ........8...#...
000000000501fdc8 23 00 00 00 70 22 50 04 - 14 00 00 00 01 00 00 00 #...p"P.........
000000000501fdd8 00 00 00 00 00 00 00 00 - 10 00 00 00 a6 68 91 7c .............h.|
000000000501fde8 79 06 81 7c 1b 00 00 00 - 00 b0 fd 7f 00 70 fd 7f y..|.........p..
000000000501fdf8 00 70 fd 7f 00 00 00 00 - d8 34 fb 05 00 02 00 00 .p.......4......
000000000501fe08 40 00 00 00 a4 fd 01 05 - 2c f0 39 e4 dc ff 01 05 @.......,.9.....
000000000501fe18 30 9a 83 7c 00 96 80 7c - 00 00 00 00 40 fe 01 05 0..|...|....@...
000000000501fe28 95 a0 80 7c 40 00 00 00 - 78 fe 01 05 00 00 00 00 ...|@...x.......
000000000501fe38 ff ff ff ff 00 00 00 00 - 58 fe 01 05 a2 14 f1 73 ........X......s
000000000501fe48 40 00 00 00 78 fe 01 05 - 00 00 00 00 ff ff ff ff @...x...........
000000000501fe58 78 ff 01 05 4a 29 f1 73 - 40 00 00 00 ff ff ff ff x...J).s@.......
000000000501fe68 00 00 00 00 78 fe 01 05 - cc 3c 50 04 cc 3c 50 04 ....x....<P..<P.
000000000501fe78 c0 04 00 00 90 02 00 00 - 8c 02 00 00 cc 03 00 00 ................
000000000501fe88 d4 03 00 00 d0 03 00 00 - d8 03 00 00 dc 03 00 00 ................
000000000501fe98 e0 03 00 00 e4 03 00 00 - e8 03 00 00 ec 03 00 00 ................
000000000501fea8 f0 03 00 00 f4 03 00 00 - f8 03 00 00 fc 03 00 00 ................
000000000501feb8 00 04 00 00 04 04 00 00 - 08 04 00 00 0c 04 00 00 ................
*----> State Dump for Thread Id 0xc50 <----*
eax=04503f70 ebx=061afdb8 ecx=00000000 edx=0000000c esi=00000000 edi=7ffdb000
eip=7c90eb94 esp=061afd90 ebp=061afe2c iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
061afe2c 7c80a095 00000001 061afe80 00000000 ntdll!KiFastSystemCallRet
061afe48 73f114a2 00000001 061afe80 00000000 kernel32!WaitForMultipleObjects+0x18
061afe60 73f1294a 00000001 000001f4 00000000 dsound+0x14a2
061aff80 73f12a13 000001f4 00000000 00000000 dsound+0x294a
061affb4 7c80b6a3 04501efc 00000000 7c910732 dsound+0x2a13
061affec 00000000 73f1b94b 04501efc 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
00000000061afd90 ab e9 90 7c 0b 95 80 7c - 01 00 00 00 b8 fd 1a 06 ...|...|........
00000000061afda0 01 00 00 00 00 00 00 00 - ec fd 1a 06 00 00 00 00 ................
00000000061afdb0 01 00 00 00 01 00 00 00 - d4 04 00 00 4d 95 80 7c ............M..|
00000000061afdc0 00 00 00 00 3b 95 80 7c - e8 89 50 04 00 00 00 00 ....;..|..P.....
00000000061afdd0 e0 fd 1a 06 00 00 00 00 - 14 00 00 00 01 00 00 00 ................
00000000061afde0 00 00 00 00 00 00 00 00 - 10 00 00 00 c0 b4 b3 ff ................
00000000061afdf0 ff ff ff ff 84 fe 1a 06 - 00 b0 fd 7f 00 40 fd 7f .............@..
00000000061afe00 3b 95 80 7c ec fd 1a 06 - b8 fd 1a 06 1c fe 1a 06 ;..|............
00000000061afe10 01 00 00 00 ac fd 1a 06 - 30 55 50 04 dc ff 1a 06 ........0UP.....
00000000061afe20 30 9a 83 7c 00 96 80 7c - 00 00 00 00 48 fe 1a 06 0..|...|....H...
00000000061afe30 95 a0 80 7c 01 00 00 00 - 80 fe 1a 06 00 00 00 00 ...|............
00000000061afe40 f4 01 00 00 00 00 00 00 - 60 fe 1a 06 a2 14 f1 73 ........`......s
00000000061afe50 01 00 00 00 80 fe 1a 06 - 00 00 00 00 f4 01 00 00 ................
00000000061afe60 80 ff 1a 06 4a 29 f1 73 - 01 00 00 00 f4 01 00 00 ....J).s........
00000000061afe70 00 00 00 00 80 fe 1a 06 - fc 1e 50 04 fc 1e 50 04 ..........P...P.
00000000061afe80 d4 04 00 00 d8 55 50 04 - 20 00 00 00 b4 fe 00 06 .....UP. .......
00000000061afe90 00 00 00 00 d8 55 50 04 - ac fe 1a 06 df 24 f1 73 .....UP......$.s
00000000061afea0 e4 55 50 04 70 3f 50 04 - ab e9 90 7c 0b 95 80 7c .UP.p?P....|...|
00000000061afeb0 00 40 fd 7f 44 ff 1a 06 - 4d 95 80 7c f0 fe 1a 06 .@..D...M..|....
00000000061afec0 3b 95 80 7c 00 00 00 00 - fc 1e 50 04 fc 1e 50 04 ;..|......P...P.
*----> State Dump for Thread Id 0x650 <----*
eax=00000000 ebx=00a90000 ecx=7ffaf000 edx=03173138 esi=000004e4 edi=00000000
eip=7c90eb94 esp=062afedc ebp=062aff40 iopl=0 nv up ei ng nz ac po cy
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000297
function: ntdll!KiFastSystemCallRet
7c90eb89 90 nop
7c90eb8a 90 nop
ntdll!KiFastSystemCall:
7c90eb8b 8bd4 mov edx,esp
7c90eb8d 0f34 sysenter
7c90eb8f 90 nop
7c90eb90 90 nop
7c90eb91 90 nop
7c90eb92 90 nop
7c90eb93 90 nop
ntdll!KiFastSystemCallRet:
7c90eb94 c3 ret
7c90eb95 8da42400000000 lea esp,[esp]
7c90eb9c 8d642400 lea esp,[esp]
7c90eba0 90 nop
7c90eba1 90 nop
7c90eba2 90 nop
7c90eba3 90 nop
7c90eba4 90 nop
ntdll!KiIntSystemCall:
7c90eba5 8d542408 lea edx,[esp+0x8]
7c90eba9 cd2e int 2e
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** WARNING: Unable to verify checksum for C:\Un4seen\XMPlay\Plugins\xmp-ds.dll
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\Un4seen\XMPlay\Plugins\xmp-ds.dll -
ChildEBP RetAddr Args to Child
062aff40 7c802532 000004e4 0000004b 00000000 ntdll!KiFastSystemCallRet
062aff54 03171527 000004e4 0000004b 7c911596 kernel32!WaitForSingleObject+0x12
0002ae4c 00000000 00000000 00000000 00000000 xmp-ds+0x1527
*----> Raw Stack Dump <----*
00000000062afedc c0 e9 90 7c cb 25 80 7c - e4 04 00 00 00 00 00 00 ...|.%.|........
00000000062afeec 10 ff 2a 06 00 00 00 00 - 80 00 00 00 00 00 a9 00 ..*.............
00000000062afefc 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000062aff0c 10 00 00 00 50 8e f4 ff - ff ff ff ff 00 b0 fd 7f ....P...........
00000000062aff1c 00 f0 fa 7f 10 ff 2a 06 - 02 01 00 00 f0 fe 2a 06 ......*.......*.
00000000062aff2c 00 00 00 00 a4 ff 2a 06 - 30 9a 83 7c f8 25 80 7c ......*.0..|.%.|
00000000062aff3c 00 00 00 00 54 ff 2a 06 - 32 25 80 7c e4 04 00 00 ....T.*.2%.|....
00000000062aff4c 4b 00 00 00 00 00 00 00 - 4c ae 02 00 27 15 17 03 K.......L...'...
00000000062aff5c e4 04 00 00 4b 00 00 00 - 96 15 91 7c 50 9e a9 00 ....K......|P...
00000000062aff6c b4 ff 2a 06 e0 9e a9 00 - 00 00 00 00 00 00 00 00 ..*.............
00000000062aff7c e8 44 00 00 18 4f e3 04 - b0 a3 c3 77 00 00 00 00 .D...O.....w....
00000000062aff8c 96 15 91 7c eb 06 91 7c - e0 9e a9 00 00 00 00 00 ...|...|........
00000000062aff9c 8c ff 2a 06 00 00 00 00 - dc ff 2a 06 94 5c c3 77 ..*.......*..\.w
00000000062affac d8 40 c1 77 00 00 00 00 - ec ff 2a 06 a3 b6 80 7c .@.w......*....|
00000000062affbc e0 9e a9 00 96 15 91 7c - eb 06 91 7c e0 9e a9 00 .......|...|....
00000000062affcc 00 f0 fa 7f 00 d6 fb 86 - c0 ff 2a 06 98 43 f2 84 ..........*..C..
00000000062affdc ff ff ff ff 30 9a 83 7c - b0 b6 80 7c 00 00 00 00 ....0..|...|....
00000000062affec 00 00 00 00 00 00 00 00 - 41 a3 c3 77 e0 9e a9 00 ........A..w....
00000000062afffc 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000062b000c 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
*----> State Dump for Thread Id 0xb38 <----*
eax=00000000 ebx=063a39d0 ecx=063a39c0 edx=063a3ed8 esi=00000000 edi=063a39c0
eip=77c48a0b esp=063a3988 ebp=063a3990 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\WINDOWS\system32\msvcrt.dll -
function: msvcrt!Gettnames
77c489f9 48 dec eax
77c489fa 48 dec eax
77c489fb 7440 jz msvcrt!Gettnames+0x476 (77c48a3d)
77c489fd 48 dec eax
77c489fe 48 dec eax
77c489ff 742b jz msvcrt!Gettnames+0x465 (77c48a2c)
77c48a01 48 dec eax
77c48a02 0f84d0000000 je msvcrt!Gettnames+0x511 (77c48ad8)
77c48a08 48 dec eax
77c48a09 75db jnz msvcrt!Gettnames+0x41f (77c489e6)
FAULT ->77c48a0b 8b4614 mov eax,[esi+0x14] ds:0023:00000014=????????
77c48a0e 99 cdq
77c48a0f 6a64 push 0x64
77c48a11 59 pop ecx
77c48a12 f7f9 idiv ecx
77c48a14 ff7514 push dword ptr [ebp+0x14]
77c48a17 6a04 push 0x4
77c48a19 83c013 add eax,0x13
77c48a1c 6bc064 imul eax,eax,0x64
77c48a1f 03c2 add eax,edx
77c48a21 5a pop edx
*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
063a3990 77c4906a 77c5f7a0 00000000 77c5ff18 msvcrt!Gettnames+0x444
063a39b4 77c490c3 77c5f7a0 063a3ab8 00000014 msvcrt!Gettnames+0xaa3
063a39d4 77c490e5 063a3ab8 00000014 66bf381b msvcrt!Strftime+0x2f
063a39f0 66ac8610 063a3ab8 00000014 66bf381b msvcrt!strftime+0x18
063a6790 66ac8b6c 063a6c88 01021d60 694e2079 xmp-scrobbler!DllMain+0x7250
063a6cb0 66ac464e 01021d60 6e6e6f52 694e2079 xmp-scrobbler!DllMain+0x77ac
063a74e0 66ac61c2 66bf3654 00002274 03213fb0 xmp-scrobbler!DllMain+0x328e
063a7530 00420ae0 00000001 063a7544 0000113a xmp-scrobbler!DllMain+0x4e02
063aff50 004202f7 00000000 00a98040 00a99ee0 xmplay+0x20ae0
063aff80 77c3a243 00000000 00000000 00000000 xmplay+0x202f7
063affb4 7c80b6a3 00a99ee0 00000000 00000000 msvcrt!endthread+0xaf
063affec 00000000 77c3a1d7 00a99ee0 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> Raw Stack Dump <----*
00000000063a3988 18 ff c5 77 1c 38 bf 66 - b4 39 3a 06 6a 90 c4 77 ...w.8.f.9:.j..w
00000000063a3998 a0 f7 c5 77 00 00 00 00 - 18 ff c5 77 00 00 00 00 ...w.......w....
00000000063a39a8 02 00 00 00 d8 3a 3a 06 - 14 00 00 00 d4 39 3a 06 .....::......9:.
00000000063a39b8 c3 90 c4 77 a0 f7 c5 77 - b8 3a 3a 06 14 00 00 00 ...w...w.::.....
00000000063a39c8 1b 38 bf 66 00 00 00 00 - 14 00 00 00 f0 39 3a 06 .8.f.........9:.
00000000063a39d8 e5 90 c4 77 b8 3a 3a 06 - 14 00 00 00 1b 38 bf 66 ...w.::......8.f
00000000063a39e8 00 00 00 00 00 00 00 00 - 90 67 3a 06 10 86 ac 66 .........g:....f
00000000063a39f8 b8 3a 3a 06 14 00 00 00 - 1b 38 bf 66 00 00 00 00 .::......8.f....
00000000063a3a08 04 00 00 00 60 8e a9 00 - 04 00 00 00 20 9f a9 00 ....`....... ...
00000000063a3a18 04 00 00 00 f0 9e a9 00 - 04 00 00 00 01 01 00 00 ................
00000000063a3a28 04 00 00 00 d8 3d 3a 06 - 00 00 00 00 00 00 00 00 .....=:.........
00000000063a3a38 00 00 00 00 00 00 00 00 - 00 00 00 00 a4 31 02 01 .............1..
00000000063a3a48 00 00 00 00 00 00 00 00 - c0 95 a9 00 90 00 00 00 ................
00000000063a3a58 73 00 00 00 46 00 00 00 - 0c 00 00 00 00 8e a9 00 s...F...........
00000000063a3a68 f0 9e a9 00 20 9f a9 00 - 60 8e a9 00 e0 88 a9 00 .... ...`.......
00000000063a3a78 05 00 00 00 68 1d 02 01 - 60 1d 02 01 c4 6b 3a 06 ....h...`....k:.
00000000063a3a88 02 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
00000000063a3a98 00 00 00 00 e0 0e ba 66 - 6a 08 be 66 78 67 3a 06 .......fj..fxg:.
00000000063a3aa8 b1 89 ac 66 f8 39 3a 06 - 00 00 00 00 00 00 00 00 ...f.9:.........
00000000063a3ab8 32 30 30 37 2d 30 39 2d - 31 37 20 30 35 3a 30 30 2007-09-17 05:00