All pastes #702779 Raw Edit

drwtsn32.log

public text v1 · immutable
#702779 ·published 2007-09-19 02:17 UTC
rendered paste body

Microsoft (R) DrWtsn32
Copyright (C) 1985-2001 Microsoft Corp. All rights reserved.



Application exception occurred:
        App: C:\Un4seen\XMPlay\xmplay.exe (pid=3116)
        When: 18-Sep-07 @ 21:50:15.326
        Exception number: c0000005 (access violation)

*----> System Information <----*
        Computer Name: KALI
        User Name: Owner
        Terminal Session Id: 0
        Number of Processors: 2
        Processor Type: x86 Family 15 Model 3 Stepping 4
        Windows Version: 5.1
        Current Build: 2600
        Service Pack: 2
        Current Type: Multiprocessor Free
        Registered Organization: 
        Registered Owner: Thomas Ditmars

*----> Task List <----*
   0 System Process
   4 System
1020 smss.exe
1088 csrss.exe
1132 winlogon.exe
1184 services.exe
1196 lsass.exe
1368 Ati2evxx.exe
1396 svchost.exe
1548 svchost.exe
1688 svchost.exe
1788 Ati2evxx.exe
2024 svchost.exe
 452 spoolsv.exe
 680 AppleMobileDeviceService.exe
 724 avgamsvr.exe
 784 Explorer.EXE
 864 avgupsvc.exe
 920 avgemc.exe
 936 BOCORE.exe
1100 persfw.exe
1156 PRISMXL.SYS
 292 alg.exe
2352 svchost.exe
2420 CTHELPER.EXE
2512 avgcc.exe
2528 PDVDServ.exe
2620 BOC425.exe
2656 winpatrol.exe
2724 ctfmon.exe
2748 pg2.exe
2800 hm.exe
2836 hostssrv.exe
2884 taskbarshuffle.exe
2952 TeaTimer.exe
3064 iSproggler.exe
3144 daemon.exe
3196 atitray.exe
3428 GPGtray.exe
3568 nistime-32bit.exe
3560 iTunes.exe
3596 xchat.exe
 740 LastFMHelper.exe
3492 LastFM.exe
 384 iPodService.exe
3700 iTunesHelper.exe
3844 trillian.exe
3316 firefox.exe
3044 thunderbird.exe
1888 SAM.exe
3096 Skype.exe
3264 SkypePM.exe
3116 xmplay.exe
2460 drwtsn32.exe

*----> Module List <----*
(0000000000330000 - 0000000000339000: C:\WINDOWS\system32\Normaliz.dll
(0000000000400000 - 0000000000552000: C:\Un4seen\XMPlay\xmplay.exe
(0000000000e40000 - 0000000000e4f000: C:\Program Files\BillP Studios\WinPatrol\PATROLPRO.DLL
(0000000000e60000 - 0000000000f3c000: C:\Un4seen\XMPlay\Plugins\in_adlib.dll
(0000000001060000 - 00000000011a5000: C:\Un4seen\XMPlay\Plugins\in_flac.dll
(00000000011b0000 - 00000000012a1000: C:\Un4seen\XMPlay\Plugins\in_gsf.dll
(00000000012b0000 - 000000000136f000: C:\Un4seen\XMPlay\Plugins\in_mp3.dll
(00000000013b0000 - 0000000001426000: C:\Un4seen\XMPlay\Plugins\in_mp3PRO.dll
(0000000001440000 - 00000000014e0000: C:\Un4seen\XMPlay\Plugins\in_mp4.dll
(00000000014e0000 - 0000000001519000: C:\Un4seen\XMPlay\Plugins\in_mpc.dll
(0000000001520000 - 000000000169b000: C:\Un4seen\XMPlay\Plugins\in_msx.dll
(00000000016b0000 - 00000000017c0000: C:\Un4seen\XMPlay\Plugins\in_psf.dll
(00000000017e0000 - 0000000001866000: C:\Un4seen\XMPlay\Plugins\in_qsf.dll
(0000000001880000 - 0000000001990000: C:\Un4seen\XMPlay\Plugins\in_sap.dll
(0000000001aa0000 - 0000000001b6e000: C:\Un4seen\XMPlay\Plugins\in_snes.dll
(0000000001c80000 - 0000000001d24000: C:\Un4seen\XMPlay\Plugins\SNESAPU.DLL
(0000000001d40000 - 0000000001e27000: C:\Un4seen\XMPlay\Plugins\in_usf.dll
(0000000001e30000 - 0000000001f25000: C:\Un4seen\XMPlay\Plugins\in_vgm.dll
(0000000001f40000 - 0000000001f7c000: C:\Un4seen\XMPlay\Plugins\in_vorbis.dll
(0000000001f80000 - 0000000001f8b000: C:\Un4seen\XMPlay\Plugins\in_wave.dll
(0000000001f90000 - 0000000002033000: C:\Un4seen\XMPlay\Plugins\in_yansf.dll
(00000000021e0000 - 0000000002257000: C:\Un4seen\XMPlay\Plugins\nsfplug_ui.dll
(0000000002380000 - 0000000002386000: C:\WINDOWS\system32\ctagent.dll
(00000000024c0000 - 00000000024c8000: C:\Un4seen\XMPlay\Plugins\xmp-7z.dll
(00000000024d0000 - 0000000002513000: C:\Un4seen\XMPlay\Plugins\xmp-aac.dll
(0000000002520000 - 00000000025a8000: C:\Un4seen\XMPlay\Plugins\xmp-ahx.dll
(0000000003140000 - 000000000314c000: C:\Un4seen\XMPlay\Plugins\xmp-arj.dll
(0000000003150000 - 0000000003157000: C:\Un4seen\XMPlay\Plugins\xmp-asio.dll
(0000000003160000 - 0000000003169000: C:\Un4seen\XMPlay\Plugins\xmp-cd.dll
(0000000003170000 - 0000000003177000: C:\Un4seen\XMPlay\Plugins\xmp-ds.dll
(0000000003180000 - 000000000318e000: C:\Un4seen\XMPlay\Plugins\xmp-flac.dll
(0000000003190000 - 000000000319d000: C:\Un4seen\XMPlay\Plugins\xmp-lha.dll
(00000000031a0000 - 00000000031ad000: C:\Un4seen\XMPlay\Plugins\xmp-midi.dll
(00000000031b0000 - 00000000031b6000: C:\Un4seen\XMPlay\Plugins\xmp-mmcmp.dll
(00000000031c0000 - 00000000031cb000: C:\Un4seen\XMPlay\Plugins\xmp-modpacker.dll
(00000000031d0000 - 00000000031df000: C:\Un4seen\XMPlay\Plugins\xmp-mpc.dll
(00000000031e0000 - 00000000031e6000: C:\Un4seen\XMPlay\Plugins\xmp-pp.dll
(0000000003200000 - 000000000320f000: C:\Un4seen\XMPlay\Plugins\xmp-rar.dll
(0000000003220000 - 0000000003227000: C:\Un4seen\XMPlay\Plugins\xmp-wadsp.dll
(0000000003230000 - 0000000003238000: C:\Un4seen\XMPlay\Plugins\xmp-wma.dll
(0000000003260000 - 00000000032b6000: C:\WINDOWS\system32\MSVCR71.dll
(00000000032d0000 - 00000000032da000: C:\Un4seen\XMPlay\Plugins\xmp-zip.dll
(00000000032e0000 - 0000000003441000: C:\Un4seen\XMPlay\Plugins\xmp-psf.dll
(0000000003550000 - 00000000035d9000: C:\Un4seen\XMPlay\Plugins\xmp-sid.dll
(0000000007160000 - 00000000071a6000: C:\WINDOWS\system32\Audiodev.dll
(0000000010000000 - 0000000010044000: C:\Program Files\Ray Adams\ATI Tray Tools\raphook.dll
(0000000010930000 - 0000000010979000: C:\WINDOWS\system32\PortableDeviceApi.dll
(0000000011c70000 - 0000000011ca9000: C:\WINDOWS\system32\WMASF.DLL
(0000000015110000 - 000000001536a000: C:\WINDOWS\system32\WMVCore.DLL
(0000000016000000 - 0000000016028000: C:\Program Files\Trillian\events.dll
(0000000016080000 - 00000000160a5000: C:\Program Files\Bonjour\mdnsNSP.dll
(0000000016210000 - 000000001648e000: C:\WINDOWS\system32\wpdshext.dll
(0000000020000000 - 0000000020017000: C:\WINDOWS\system32\odbcint.dll
(0000000042990000 - 00000000429d5000: C:\WINDOWS\system32\iertutil.dll
(0000000042c10000 - 0000000042cdf000: C:\WINDOWS\system32\WININET.dll
(0000000042cf0000 - 0000000042e14000: C:\WINDOWS\system32\urlmon.dll
(000000004ec50000 - 000000004edf3000: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.2180_x-ww_522f9f82\gdiplus.dll
(000000005ad70000 - 000000005ada8000: C:\WINDOWS\system32\uxtheme.dll
(000000005b860000 - 000000005b8b4000: C:\WINDOWS\system32\netapi32.dll
(00000000629c0000 - 00000000629c9000: C:\WINDOWS\system32\LPK.DLL
(00000000662b0000 - 0000000066308000: C:\WINDOWS\system32\hnetcfg.dll
(0000000066ac0000 - 0000000066c50000: C:\Un4seen\XMPlay\Plugins\xmp-scrobbler.dll
(0000000071a50000 - 0000000071a8f000: C:\WINDOWS\system32\mswsock.dll
(0000000071a90000 - 0000000071a98000: C:\WINDOWS\System32\wshtcpip.dll
(0000000071aa0000 - 0000000071aa8000: C:\WINDOWS\system32\WS2HELP.dll
(0000000071ab0000 - 0000000071ac7000: C:\WINDOWS\system32\WS2_32.dll
(0000000071ad0000 - 0000000071ad9000: C:\WINDOWS\system32\WSOCK32.dll
(0000000071b20000 - 0000000071b32000: C:\WINDOWS\system32\MPR.dll
(0000000071bf0000 - 0000000071c03000: C:\WINDOWS\System32\SAMLIB.dll
(0000000071c10000 - 0000000071c1e000: C:\WINDOWS\System32\ntlanman.dll
(0000000071c80000 - 0000000071c87000: C:\WINDOWS\System32\NETRAP.dll
(0000000071c90000 - 0000000071cd0000: C:\WINDOWS\System32\NETUI1.dll
(0000000071cd0000 - 0000000071ce7000: C:\WINDOWS\System32\NETUI0.dll
(00000000722b0000 - 00000000722b5000: C:\WINDOWS\system32\sensapi.dll
(0000000072d10000 - 0000000072d18000: C:\WINDOWS\system32\msacm32.drv
(0000000072d20000 - 0000000072d29000: C:\WINDOWS\system32\wdmaud.drv
(0000000073000000 - 0000000073026000: C:\WINDOWS\system32\WINSPOOL.DRV
(0000000073d70000 - 0000000073d83000: C:\WINDOWS\system32\shgina.dll
(0000000073ee0000 - 0000000073ee4000: C:\WINDOWS\system32\KsUser.dll
(0000000073f10000 - 0000000073f6c000: C:\WINDOWS\system32\dsound.dll
(0000000074320000 - 000000007435d000: C:\WINDOWS\system32\ODBC32.dll
(0000000074720000 - 000000007476b000: C:\WINDOWS\system32\MSCTF.dll
(0000000074d90000 - 0000000074dfb000: C:\WINDOWS\system32\USP10.dll
(00000000755c0000 - 00000000755ee000: C:\WINDOWS\system32\msctfime.ime
(0000000075970000 - 0000000075a67000: C:\WINDOWS\system32\MSGINA.dll
(0000000075f60000 - 0000000075f67000: C:\WINDOWS\System32\drprov.dll
(0000000075f70000 - 0000000075f79000: C:\WINDOWS\System32\davclnt.dll
(0000000076360000 - 0000000076370000: C:\WINDOWS\system32\WINSTA.dll
(0000000076390000 - 00000000763ad000: C:\WINDOWS\system32\IMM32.DLL
(00000000763b0000 - 00000000763f9000: C:\WINDOWS\system32\comdlg32.dll
(0000000076600000 - 000000007661d000: C:\WINDOWS\System32\CSCDLL.dll
(00000000769c0000 - 0000000076a73000: C:\WINDOWS\system32\USERENV.dll
(0000000076b40000 - 0000000076b6d000: C:\WINDOWS\system32\WINMM.dll
(0000000076bf0000 - 0000000076bfb000: C:\WINDOWS\system32\PSAPI.DLL
(0000000076c30000 - 0000000076c5e000: C:\WINDOWS\system32\WINTRUST.dll
(0000000076c90000 - 0000000076cb8000: C:\WINDOWS\system32\IMAGEHLP.dll
(0000000076d60000 - 0000000076d79000: C:\WINDOWS\system32\iphlpapi.dll
(0000000076e80000 - 0000000076e8e000: C:\WINDOWS\system32\rtutils.dll
(0000000076e90000 - 0000000076ea2000: C:\WINDOWS\system32\rasman.dll
(0000000076eb0000 - 0000000076edf000: C:\WINDOWS\system32\TAPI32.dll
(0000000076ee0000 - 0000000076f1c000: C:\WINDOWS\system32\RASAPI32.dll
(0000000076f20000 - 0000000076f47000: C:\WINDOWS\system32\DNSAPI.dll
(0000000076f60000 - 0000000076f8c000: C:\WINDOWS\system32\WLDAP32.dll
(0000000076fb0000 - 0000000076fb8000: C:\WINDOWS\System32\winrnr.dll
(0000000076fc0000 - 0000000076fc6000: C:\WINDOWS\system32\rasadhlp.dll
(0000000076fd0000 - 000000007704f000: C:\WINDOWS\system32\CLBCATQ.DLL
(0000000077050000 - 0000000077115000: C:\WINDOWS\system32\COMRes.dll
(0000000077120000 - 00000000771ab000: C:\WINDOWS\system32\OLEAUT32.dll
(00000000773d0000 - 00000000774d3000: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\COMCTL32.dll
(00000000774e0000 - 000000007761d000: C:\WINDOWS\system32\ole32.dll
(0000000077920000 - 0000000077a13000: C:\WINDOWS\system32\SETUPAPI.dll
(0000000077a20000 - 0000000077a74000: C:\WINDOWS\System32\cscui.dll
(0000000077a80000 - 0000000077b14000: C:\WINDOWS\system32\CRYPT32.dll
(0000000077b20000 - 0000000077b32000: C:\WINDOWS\system32\MSASN1.dll
(0000000077b40000 - 0000000077b62000: C:\WINDOWS\system32\appHelp.dll
(0000000077bd0000 - 0000000077bd7000: C:\WINDOWS\system32\midimap.dll
(0000000077be0000 - 0000000077bf5000: C:\WINDOWS\system32\MSACM32.dll
(0000000077c00000 - 0000000077c08000: C:\WINDOWS\system32\VERSION.DLL
(0000000077c10000 - 0000000077c68000: C:\WINDOWS\system32\msvcrt.dll
(0000000077c70000 - 0000000077c93000: C:\WINDOWS\system32\msv1_0.dll
(0000000077dd0000 - 0000000077e6b000: C:\WINDOWS\system32\ADVAPI32.dll
(0000000077e70000 - 0000000077f01000: C:\WINDOWS\system32\RPCRT4.dll
(0000000077f10000 - 0000000077f57000: C:\WINDOWS\system32\GDI32.dll
(0000000077f60000 - 0000000077fd6000: C:\WINDOWS\system32\SHLWAPI.dll
(0000000077fe0000 - 0000000077ff1000: C:\WINDOWS\system32\Secur32.dll
(000000007c3a0000 - 000000007c41b000: C:\WINDOWS\system32\MSVCP71.dll
(000000007c800000 - 000000007c8f5000: C:\WINDOWS\system32\kernel32.dll
(000000007c900000 - 000000007c9b0000: C:\WINDOWS\system32\ntdll.dll
(000000007c9c0000 - 000000007d1d5000: C:\WINDOWS\system32\SHELL32.dll
(000000007e410000 - 000000007e4a0000: C:\WINDOWS\system32\USER32.dll

*----> State Dump for Thread Id 0x3b4 <----*

eax=0000000a ebx=005510b6 ecx=00000000 edx=0000000f esi=0012ff08 edi=00000000
eip=7c90eb94 esp=0012d7b0 ebp=0012d7d4 iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00200246

*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\ntdll.dll - 
function: ntdll!KiFastSystemCallRet
        7c90eb89 90               nop
        7c90eb8a 90               nop
        ntdll!KiFastSystemCall:
        7c90eb8b 8bd4             mov     edx,esp
        7c90eb8d 0f34             sysenter
        7c90eb8f 90               nop
        7c90eb90 90               nop
        7c90eb91 90               nop
        7c90eb92 90               nop
        7c90eb93 90               nop
        ntdll!KiFastSystemCallRet:
        7c90eb94 c3               ret
        7c90eb95 8da42400000000   lea     esp,[esp]
        7c90eb9c 8d642400         lea     esp,[esp]
        7c90eba0 90               nop
        7c90eba1 90               nop
        7c90eba2 90               nop
        7c90eba3 90               nop
        7c90eba4 90               nop
        ntdll!KiIntSystemCall:
        7c90eba5 8d542408         lea     edx,[esp+0x8]
        7c90eba9 cd2e             int     2e

*----> Stack Back Trace <----*
*** WARNING: Unable to verify checksum for C:\Un4seen\XMPlay\xmplay.exe
*** ERROR: Module load completed but symbols could not be loaded for C:\Un4seen\XMPlay\xmplay.exe
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\kernel32.dll - 
ChildEBP RetAddr  Args to Child              
0012d7d4 0043da74 0012ff08 00000000 00000000 ntdll!KiFastSystemCallRet
0012ff24 00445cdf 00400000 00000000 0015232f xmplay+0x3da74
0012ffc0 7c816ff7 011dcd8c 7c90e1fe 7ffda000 xmplay+0x45cdf
0012fff0 00000000 00551039 00000000 78746341 kernel32!RegisterWaitForInputIdle+0x49

*----> Raw Stack Dump <----*
000000000012d7b0  be 91 41 7e 42 e0 42 7e - 08 ff 12 00 00 00 00 00  ..A~B.B~........
000000000012d7c0  00 00 00 00 00 00 00 00 - b6 10 55 00 00 00 00 00  ..........U.....
000000000012d7d0  02 e0 42 7e 24 ff 12 00 - 74 da 43 00 08 ff 12 00  ..B~$...t.C.....
000000000012d7e0  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000012d7f0  8c cd 1d 01 2f 23 15 00 - ff 78 6d 70 2d 73 63 72  ..../#...xmp-scr
000000000012d800  6f 62 62 6c 65 72 2e 64 - 6c 6c 00 00 24 05 01 00  obbler.dll..$...
000000000012d810  00 00 5a 61 72 67 67 67 - 00 00 00 00 00 00 00 00  ..Zarggg........
000000000012d820  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000012d830  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000012d840  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000012d850  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000012d860  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000012d870  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000012d880  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000012d890  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000012d8a0  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000012d8b0  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000012d8c0  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000012d8d0  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000012d8e0  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................

*----> State Dump for Thread Id 0xc78 <----*

eax=00000001 ebx=0000000b ecx=00000000 edx=00000000 esi=00010000 edi=0000ffff
eip=7c90eb94 esp=0471fac8 ebp=0471ff3c iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246

function: ntdll!KiFastSystemCallRet
        7c90eb89 90               nop
        7c90eb8a 90               nop
        ntdll!KiFastSystemCall:
        7c90eb8b 8bd4             mov     edx,esp
        7c90eb8d 0f34             sysenter
        7c90eb8f 90               nop
        7c90eb90 90               nop
        7c90eb91 90               nop
        7c90eb92 90               nop
        7c90eb93 90               nop
        ntdll!KiFastSystemCallRet:
        7c90eb94 c3               ret
        7c90eb95 8da42400000000   lea     esp,[esp]
        7c90eb9c 8d642400         lea     esp,[esp]
        7c90eba0 90               nop
        7c90eba1 90               nop
        7c90eba2 90               nop
        7c90eba3 90               nop
        7c90eba4 90               nop
        ntdll!KiIntSystemCall:
        7c90eba5 8d542408         lea     edx,[esp+0x8]
        7c90eba9 cd2e             int     2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr  Args to Child              
0471ff3c 0041d841 d70114da 000000a6 0000000b ntdll!KiFastSystemCallRet
0471ff64 0043e042 00000038 00a85780 0471ffb4 xmplay+0x1d841
7e41c465 e87e41c4 ffffc14f e8084d8b ffffc057 xmplay+0x3e042
98680c6a 00000000 00000000 00000000 00000000 0xe87e41c4

*----> Raw Stack Dump <----*
000000000471fac8  02 71 f1 77 ad 70 f1 77 - da 14 01 d7 a6 00 00 00  .q.w.p.w........
000000000471fad8  0b 00 00 00 5d 21 01 6d - 90 a5 47 00 da 14 01 d7  ....]!.m..G.....
000000000471fae8  6f 00 72 00 6e 00 20 00 - 2d 00 20 00 57 00 61 00  o.r.n. .-. .W.a.
000000000471faf8  6c 00 6b 00 69 00 6e 00 - 7e fb 71 04 00 00 00 00  l.k.i.n.~.q.....
000000000471fb08  00 00 00 00 00 00 00 00 - 48 ff 71 04 ac 7d 42 00  ........H.q..}B.
000000000471fb18  28 ff 71 04 24 09 00 00 - 61 21 01 00 90 a5 47 00  (.q.$...a!....G.
000000000471fb28  da 14 01 d7 4e 69 67 68 - 74 77 69 73 68 20 2d 20  ....Nightwish - 
000000000471fb38  4f 63 65 61 6e 62 6f 72 - 6e 20 2d 20 57 61 6c 6b  Oceanborn - Walk
000000000471fb48  69 6e 67 20 69 6e 20 74 - 68 65 20 41 69 72 20 20  ing in the Air  
000000000471fb58  20 20 20 20 4e 69 67 68 - 74 77 69 73 68 20 2d 20      Nightwish - 
000000000471fb68  4f 63 65 61 6e 62 6f 72 - 6e 20 2d 20 57 61 6c 6b  Oceanborn - Walk
000000000471fb78  69 6e 67 20 69 6e 00 74 - 00 77 03 01 18 77 03 01  ing in.t.w...w..
000000000471fb88  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000471fb98  24 00 00 00 ac 1d 91 7c - 1d 05 00 00 18 77 03 00  $......|.....w..
000000000471fba8  00 00 00 00 00 00 34 00 - 18 77 03 01 00 00 00 00  ......4..w......
000000000471fbb8  00 00 00 00 00 a0 03 01 - dc fb 71 04 00 00 f6 00  ..........q.....
000000000471fbc8  00 00 00 00 16 d9 00 00 - 04 fc 71 04 69 12 9c 62  ..........q.i..b
000000000471fbd8  76 20 01 59 02 00 00 00 - 00 00 00 00 01 00 00 00  v .Y............
000000000471fbe8  20 00 00 00 ff ff ff ff - 10 67 5d 06 08 00 00 00   ........g].....
000000000471fbf8  01 00 00 00 25 09 00 00 - 00 00 00 00 44 fc 71 04  ....%.......D.q.

*----> State Dump for Thread Id 0xca4 <----*

eax=04d6faf7 ebx=01026fe8 ecx=00000036 edx=00000000 esi=00000288 edi=00000000
eip=7c90eb94 esp=04d6fefc ebp=04d6ff60 iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00200246

function: ntdll!KiFastSystemCallRet
        7c90eb89 90               nop
        7c90eb8a 90               nop
        ntdll!KiFastSystemCall:
        7c90eb8b 8bd4             mov     edx,esp
        7c90eb8d 0f34             sysenter
        7c90eb8f 90               nop
        7c90eb90 90               nop
        7c90eb91 90               nop
        7c90eb92 90               nop
        7c90eb93 90               nop
        ntdll!KiFastSystemCallRet:
        7c90eb94 c3               ret
        7c90eb95 8da42400000000   lea     esp,[esp]
        7c90eb9c 8d642400         lea     esp,[esp]
        7c90eba0 90               nop
        7c90eba1 90               nop
        7c90eba2 90               nop
        7c90eba3 90               nop
        7c90eba4 90               nop
        ntdll!KiIntSystemCall:
        7c90eba5 8d542408         lea     edx,[esp+0x8]
        7c90eba9 cd2e             int     2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\Un4seen\XMPlay\Plugins\xmp-scrobbler.dll - 
ChildEBP RetAddr  Args to Child              
04d6ff60 7c802532 00000288 ffffffff 00000000 ntdll!KiFastSystemCallRet
04d6ff74 66ac760f 00000288 ffffffff 0269788c kernel32!WaitForSingleObject+0x12
04d6ffa4 66bb31a1 02695008 7c90e2dc 04d6ffec xmp-scrobbler!DllMain+0x624f
04d6ffb4 7c80b6a3 02695008 04c6f9e0 00000001 xmp-scrobbler+0xf31a1
04d6ffec 00000000 66bb3190 02695008 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
0000000004d6fefc  c0 e9 90 7c cb 25 80 7c - 88 02 00 00 00 00 00 00  ...|.%.|........
0000000004d6ff0c  00 00 00 00 8c 78 69 02 - 08 50 69 02 e8 6f 02 01  .....xi..Pi..o..
0000000004d6ff1c  14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000004d6ff2c  10 00 00 00 8c 78 69 02 - 08 50 69 02 00 a0 fd 7f  .....xi..Pi.....
0000000004d6ff3c  00 90 fd 7f 00 00 00 00 - e3 c2 c2 77 10 ff d6 04  ...........w....
0000000004d6ff4c  30 ff d6 04 dc ff d6 04 - 30 9a 83 7c f8 25 80 7c  0.......0..|.%.|
0000000004d6ff5c  00 00 00 00 74 ff d6 04 - 32 25 80 7c 88 02 00 00  ....t...2%.|....
0000000004d6ff6c  ff ff ff ff 00 00 00 00 - a4 ff d6 04 0f 76 ac 66  .............v.f
0000000004d6ff7c  88 02 00 00 ff ff ff ff - 8c 78 69 02 01 f4 6f 80  .........xi...o.
0000000004d6ff8c  00 00 00 00 50 34 90 84 - 00 00 00 00 08 50 69 02  ....P4.......Pi.
0000000004d6ff9c  01 00 00 00 e0 f9 c6 04 - b4 ff d6 04 a1 31 bb 66  .............1.f
0000000004d6ffac  08 50 69 02 dc e2 90 7c - ec ff d6 04 a3 b6 80 7c  .Pi....|.......|
0000000004d6ffbc  08 50 69 02 e0 f9 c6 04 - 01 00 00 00 08 50 69 02  .Pi..........Pi.
0000000004d6ffcc  00 90 fd 7f 00 d6 fb 86 - c0 ff d6 04 30 ac 02 85  ............0...
0000000004d6ffdc  ff ff ff ff 30 9a 83 7c - b0 b6 80 7c 00 00 00 00  ....0..|...|....
0000000004d6ffec  00 00 00 00 00 00 00 00 - 90 31 bb 66 08 50 69 02  .........1.f.Pi.
0000000004d6fffc  00 00 00 00 c8 00 00 00 - e6 01 00 00 ff ee ff ee  ................
0000000004d7000c  02 10 00 00 00 00 00 00 - 00 fe 00 00 00 00 20 00  .............. .
0000000004d7001c  00 20 00 00 00 02 00 00 - 00 20 00 00 4e 04 00 00  . ....... ..N...
0000000004d7002c  ff ef fd 7f 1d 00 08 06 - 00 00 00 00 00 00 00 00  ................

*----> State Dump for Thread Id 0x600 <----*

eax=72d230e8 ebx=04ecfef8 ecx=0000001e edx=00000000 esi=00000000 edi=7ffda000
eip=7c90eb94 esp=04ecfed0 ebp=04ecff6c iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246

function: ntdll!KiFastSystemCallRet
        7c90eb89 90               nop
        7c90eb8a 90               nop
        ntdll!KiFastSystemCall:
        7c90eb8b 8bd4             mov     edx,esp
        7c90eb8d 0f34             sysenter
        7c90eb8f 90               nop
        7c90eb90 90               nop
        7c90eb91 90               nop
        7c90eb92 90               nop
        7c90eb93 90               nop
        ntdll!KiFastSystemCallRet:
        7c90eb94 c3               ret
        7c90eb95 8da42400000000   lea     esp,[esp]
        7c90eb9c 8d642400         lea     esp,[esp]
        7c90eba0 90               nop
        7c90eba1 90               nop
        7c90eba2 90               nop
        7c90eba3 90               nop
        7c90eba4 90               nop
        ntdll!KiIntSystemCall:
        7c90eba5 8d542408         lea     edx,[esp+0x8]
        7c90eba9 cd2e             int     2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\wdmaud.drv - 
ChildEBP RetAddr  Args to Child              
04ecff6c 7c80a095 00000002 04ecffa4 00000000 ntdll!KiFastSystemCallRet
04ecff88 72d2312a 00000002 04ecffa4 00000000 kernel32!WaitForMultipleObjects+0x18
04ecffb4 7c80b6a3 00000000 00000000 00150000 wdmaud!midMessage+0x348
04ecffec 00000000 72d230e8 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
0000000004ecfed0  ab e9 90 7c 0b 95 80 7c - 02 00 00 00 f8 fe ec 04  ...|...|........
0000000004ecfee0  01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000004ecfef0  00 00 00 00 00 00 00 00 - cc 02 00 00 b8 02 00 00  ................
0000000004ecff00  00 00 00 00 00 00 00 00 - 43 fd 6f 80 90 ac fa aa  ........C.o.....
0000000004ecff10  27 f4 6f 80 00 0d db ba - 14 00 00 00 01 00 00 00  '.o.............
0000000004ecff20  00 00 00 00 00 00 00 00 - 10 00 00 00 f0 bb ec 84  ................
0000000004ecff30  24 bc ec 84 cc 0d 00 00 - 00 a0 fd 7f 00 80 fd 7f  $...............
0000000004ecff40  f0 bb ec 84 00 00 00 00 - f8 fe ec 04 ac 9b 4f 80  ..............O.
0000000004ecff50  02 00 00 00 ec fe ec 04 - 00 00 00 00 dc ff ec 04  ................
0000000004ecff60  30 9a 83 7c 00 96 80 7c - 00 00 00 00 88 ff ec 04  0..|...|........
0000000004ecff70  95 a0 80 7c 02 00 00 00 - a4 ff ec 04 00 00 00 00  ...|............
0000000004ecff80  ff ff ff ff 00 00 00 00 - b4 ff ec 04 2a 31 d2 72  ............*1.r
0000000004ecff90  02 00 00 00 a4 ff ec 04 - 00 00 00 00 ff ff ff ff  ................
0000000004ecffa0  00 00 15 00 cc 02 00 00 - b8 02 00 00 f2 fe 6f 80  ..............o.
0000000004ecffb0  dc e2 90 7c ec ff ec 04 - a3 b6 80 7c 00 00 00 00  ...|.......|....
0000000004ecffc0  00 00 00 00 00 00 15 00 - 00 00 00 00 00 80 fd 7f  ................
0000000004ecffd0  00 d6 fb 86 c0 ff ec 04 - e0 73 ae 85 ff ff ff ff  .........s......
0000000004ecffe0  30 9a 83 7c b0 b6 80 7c - 00 00 00 00 00 00 00 00  0..|...|........
0000000004ecfff0  00 00 00 00 e8 30 d2 72 - 00 00 00 00 00 00 00 00  .....0.r........
0000000004ed0000  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................

*----> State Dump for Thread Id 0xb0c <----*

eax=73f1b94b ebx=001bfcf0 ecx=ffffffff edx=7c916928 esi=00000000 edi=7ffda000
eip=7c90eb94 esp=04fcfd88 ebp=04fcfe24 iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246

function: ntdll!KiFastSystemCallRet
        7c90eb89 90               nop
        7c90eb8a 90               nop
        ntdll!KiFastSystemCall:
        7c90eb8b 8bd4             mov     edx,esp
        7c90eb8d 0f34             sysenter
        7c90eb8f 90               nop
        7c90eb90 90               nop
        7c90eb91 90               nop
        7c90eb92 90               nop
        7c90eb93 90               nop
        ntdll!KiFastSystemCallRet:
        7c90eb94 c3               ret
        7c90eb95 8da42400000000   lea     esp,[esp]
        7c90eb9c 8d642400         lea     esp,[esp]
        7c90eba0 90               nop
        7c90eba1 90               nop
        7c90eba2 90               nop
        7c90eba3 90               nop
        7c90eba4 90               nop
        ntdll!KiIntSystemCall:
        7c90eba5 8d542408         lea     edx,[esp+0x8]
        7c90eba9 cd2e             int     2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\dsound.dll - 
ChildEBP RetAddr  Args to Child              
04fcfe24 7c80a095 00000040 04fcfe78 00000000 ntdll!KiFastSystemCallRet
04fcfe40 73f114a2 00000040 04fcfe78 00000000 kernel32!WaitForMultipleObjects+0x18
04fcfe58 73f1294a 00000040 ffffffff 00000000 dsound+0x14a2
04fcff78 73f19fbf ffffffff 0000003f 04d76958 dsound+0x294a
04fcff98 73f1297e 04d72390 04d7690c 73f1b993 dsound!DirectSoundCreate+0x537c
04fcffb4 7c80b6a3 04d7690c 04d72390 04c6fcdc dsound+0x297e
04fcffec 00000000 73f1b94b 04d7690c 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
0000000004fcfd88  ab e9 90 7c 0b 95 80 7c - 40 00 00 00 f0 fc 1b 00  ...|...|@.......
0000000004fcfd98  01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000004fcfda8  40 00 00 00 01 00 00 00 - 80 e3 fb 86 fa 02 55 80  @.............U.
0000000004fcfdb8  e6 01 55 80 00 00 00 00 - 38 00 00 00 23 00 00 00  ..U.....8...#...
0000000004fcfdc8  23 00 00 00 90 23 d7 04 - 14 00 00 00 01 00 00 00  #....#..........
0000000004fcfdd8  00 00 00 00 00 00 00 00 - 10 00 00 00 a6 68 91 7c  .............h.|
0000000004fcfde8  79 06 81 7c 1b 00 00 00 - 00 a0 fd 7f 00 70 fd 7f  y..|.........p..
0000000004fcfdf8  00 70 fd 7f 00 00 00 00 - f0 fc 1b 00 98 3c e3 86  .p...........<..
0000000004fcfe08  40 00 00 00 a4 fd fc 04 - c8 22 1e f7 dc ff fc 04  @........"......
0000000004fcfe18  30 9a 83 7c 00 96 80 7c - 00 00 00 00 40 fe fc 04  0..|...|....@...
0000000004fcfe28  95 a0 80 7c 40 00 00 00 - 78 fe fc 04 00 00 00 00  ...|@...x.......
0000000004fcfe38  ff ff ff ff 00 00 00 00 - 58 fe fc 04 a2 14 f1 73  ........X......s
0000000004fcfe48  40 00 00 00 78 fe fc 04 - 00 00 00 00 ff ff ff ff  @...x...........
0000000004fcfe58  78 ff fc 04 4a 29 f1 73 - 40 00 00 00 ff ff ff ff  x...J).s@.......
0000000004fcfe68  00 00 00 00 78 fe fc 04 - 0c 69 d7 04 0c 69 d7 04  ....x....i...i..
0000000004fcfe78  08 04 00 00 08 03 00 00 - 00 03 00 00 14 03 00 00  ................
0000000004fcfe88  1c 03 00 00 18 03 00 00 - 20 03 00 00 24 03 00 00  ........ ...$...
0000000004fcfe98  28 03 00 00 2c 03 00 00 - 30 03 00 00 34 03 00 00  (...,...0...4...
0000000004fcfea8  38 03 00 00 3c 03 00 00 - 40 03 00 00 44 03 00 00  8...<...@...D...
0000000004fcfeb8  48 03 00 00 4c 03 00 00 - 50 03 00 00 54 03 00 00  H...L...P...T...

*----> State Dump for Thread Id 0xec8 <----*

eax=00c90004 ebx=052cfdb8 ecx=052cfe60 edx=7c90eb94 esi=00000000 edi=7ffda000
eip=7c90eb94 esp=052cfd90 ebp=052cfe2c iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246

function: ntdll!KiFastSystemCallRet
        7c90eb89 90               nop
        7c90eb8a 90               nop
        ntdll!KiFastSystemCall:
        7c90eb8b 8bd4             mov     edx,esp
        7c90eb8d 0f34             sysenter
        7c90eb8f 90               nop
        7c90eb90 90               nop
        7c90eb91 90               nop
        7c90eb92 90               nop
        7c90eb93 90               nop
        ntdll!KiFastSystemCallRet:
        7c90eb94 c3               ret
        7c90eb95 8da42400000000   lea     esp,[esp]
        7c90eb9c 8d642400         lea     esp,[esp]
        7c90eba0 90               nop
        7c90eba1 90               nop
        7c90eba2 90               nop
        7c90eba3 90               nop
        7c90eba4 90               nop
        ntdll!KiIntSystemCall:
        7c90eba5 8d542408         lea     edx,[esp+0x8]
        7c90eba9 cd2e             int     2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr  Args to Child              
052cfe2c 7c80a095 00000001 052cfe80 00000000 ntdll!KiFastSystemCallRet
052cfe48 73f114a2 00000001 052cfe80 00000000 kernel32!WaitForMultipleObjects+0x18
052cfe60 73f1294a 00000001 000001f4 00000000 dsound+0x14a2
052cff80 73f12a13 000001f4 00000000 00000000 dsound+0x294a
052cffb4 7c80b6a3 04d71efc 01000001 04c6fad4 dsound+0x2a13
052cffec 00000000 73f1b94b 04d71efc 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
00000000052cfd90  ab e9 90 7c 0b 95 80 7c - 01 00 00 00 b8 fd 2c 05  ...|...|......,.
00000000052cfda0  01 00 00 00 00 00 00 00 - ec fd 2c 05 00 00 00 00  ..........,.....
00000000052cfdb0  01 00 00 00 01 00 00 00 - 4c 04 00 00 4d 95 80 7c  ........L...M..|
00000000052cfdc0  f4 fd 2c 05 3b 95 80 7c - e8 89 d7 04 00 00 00 00  ..,.;..|........
00000000052cfdd0  e0 fd 2c 05 00 00 00 00 - 14 00 00 00 01 00 00 00  ..,.............
00000000052cfde0  00 00 00 00 00 00 00 00 - 10 00 00 00 c0 b4 b3 ff  ................
00000000052cfdf0  ff ff ff ff 68 8e d7 04 - 00 a0 fd 7f 00 50 fd 7f  ....h........P..
00000000052cfe00  c8 05 91 7c ec fd 2c 05 - b8 fd 2c 05 51 05 91 7c  ...|..,...,.Q..|
00000000052cfe10  01 00 00 00 ac fd 2c 05 - c8 05 91 7c dc ff 2c 05  ......,....|..,.
00000000052cfe20  30 9a 83 7c 00 96 80 7c - 00 00 00 00 48 fe 2c 05  0..|...|....H.,.
00000000052cfe30  95 a0 80 7c 01 00 00 00 - 80 fe 2c 05 00 00 00 00  ...|......,.....
00000000052cfe40  f4 01 00 00 00 00 00 00 - 60 fe 2c 05 a2 14 f1 73  ........`.,....s
00000000052cfe50  01 00 00 00 80 fe 2c 05 - 00 00 00 00 f4 01 00 00  ......,.........
00000000052cfe60  80 ff 2c 05 4a 29 f1 73 - 01 00 00 00 f4 01 00 00  ..,.J).s........
00000000052cfe70  00 00 00 00 80 fe 2c 05 - fc 1e d7 04 fc 1e d7 04  ......,.........
00000000052cfe80  4c 04 00 00 01 00 00 00 - 00 00 00 00 20 00 00 00  L........... ...
00000000052cfe90  04 00 00 00 f0 fd 2c 05 - ac fe 2c 05 dc ff 2c 05  ......,...,...,.
00000000052cfea0  18 ee 90 7c 70 05 91 7c - ab e9 90 7c 0b 95 80 7c  ...|p..|...|...|
00000000052cfeb0  00 50 fd 7f 44 ff 2c 05 - 4d 95 80 7c f0 fe 2c 05  .P..D.,.M..|..,.
00000000052cfec0  3b 95 80 7c 00 00 00 00 - fc 1e d7 04 fc 1e d7 04  ;..|............

*----> State Dump for Thread Id 0x888 <----*

eax=00000102 ebx=00aa0000 ecx=0540fedc edx=7c90eb94 esi=0000046c edi=00000000
eip=7c90eb94 esp=0540fedc ebp=0540ff40 iopl=0         nv up ei ng nz ac po cy
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000297

function: ntdll!KiFastSystemCallRet
        7c90eb89 90               nop
        7c90eb8a 90               nop
        ntdll!KiFastSystemCall:
        7c90eb8b 8bd4             mov     edx,esp
        7c90eb8d 0f34             sysenter
        7c90eb8f 90               nop
        7c90eb90 90               nop
        7c90eb91 90               nop
        7c90eb92 90               nop
        7c90eb93 90               nop
        ntdll!KiFastSystemCallRet:
        7c90eb94 c3               ret
        7c90eb95 8da42400000000   lea     esp,[esp]
        7c90eb9c 8d642400         lea     esp,[esp]
        7c90eba0 90               nop
        7c90eba1 90               nop
        7c90eba2 90               nop
        7c90eba3 90               nop
        7c90eba4 90               nop
        ntdll!KiIntSystemCall:
        7c90eba5 8d542408         lea     edx,[esp+0x8]
        7c90eba9 cd2e             int     2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** WARNING: Unable to verify checksum for C:\Un4seen\XMPlay\Plugins\xmp-ds.dll
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\Un4seen\XMPlay\Plugins\xmp-ds.dll - 
ChildEBP RetAddr  Args to Child              
0540ff40 7c802532 0000046c 0000004b 00000000 ntdll!KiFastSystemCallRet
0540ff54 03171527 0000046c 0000004b 7c911596 kernel32!WaitForSingleObject+0x12
0002ae4c 00000000 00000000 00000000 00000000 xmp-ds+0x1527

*----> Raw Stack Dump <----*
000000000540fedc  c0 e9 90 7c cb 25 80 7c - 6c 04 00 00 00 00 00 00  ...|.%.|l.......
000000000540feec  10 ff 40 05 24 83 0d 05 - 80 00 00 00 00 00 aa 00  ..@.$...........
000000000540fefc  14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000540ff0c  10 00 00 00 50 8e f4 ff - ff ff ff ff 00 a0 fd 7f  ....P...........
000000000540ff1c  00 40 fd 7f 10 ff 40 05 - 02 01 00 00 f0 fe 40 05  .@....@.......@.
000000000540ff2c  00 00 00 00 a4 ff 40 05 - 30 9a 83 7c f8 25 80 7c  ......@.0..|.%.|
000000000540ff3c  00 00 00 00 54 ff 40 05 - 32 25 80 7c 6c 04 00 00  ....T.@.2%.|l...
000000000540ff4c  4b 00 00 00 00 00 00 00 - 4c ae 02 00 27 15 17 03  K.......L...'...
000000000540ff5c  6c 04 00 00 4b 00 00 00 - 96 15 91 7c 60 74 aa 00  l...K......|`t..
000000000540ff6c  b4 ff 40 05 10 c7 aa 00 - c4 02 00 00 60 80 0d 05  ..@.........`...
000000000540ff7c  24 42 00 00 88 ec 0f 05 - b0 a3 c3 77 00 00 00 00  $B.........w....
000000000540ff8c  96 15 91 7c eb 06 91 7c - 10 c7 aa 00 00 00 00 00  ...|...|........
000000000540ff9c  8c ff 40 05 00 00 00 00 - dc ff 40 05 94 5c c3 77  ..@.......@..\.w
000000000540ffac  d8 40 c1 77 00 00 00 00 - ec ff 40 05 a3 b6 80 7c  .@.w......@....|
000000000540ffbc  10 c7 aa 00 96 15 91 7c - eb 06 91 7c 10 c7 aa 00  .......|...|....
000000000540ffcc  00 40 fd 7f 00 d6 fb 86 - c0 ff 40 05 88 b9 1f 86  .@........@.....
000000000540ffdc  ff ff ff ff 30 9a 83 7c - b0 b6 80 7c 00 00 00 00  ....0..|...|....
000000000540ffec  00 00 00 00 00 00 00 00 - 41 a3 c3 77 10 c7 aa 00  ........A..w....
000000000540fffc  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000541000c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................

*----> State Dump for Thread Id 0x2f0 <----*

eax=00000000 ebx=05503f58 ecx=05503f48 edx=05504460 esi=00000000 edi=05503f48
eip=77c48a0b esp=05503f10 ebp=05503f18 iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246

*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\msvcrt.dll - 
function: msvcrt!Gettnames
        77c489f9 48               dec     eax
        77c489fa 48               dec     eax
        77c489fb 7440             jz      msvcrt!Gettnames+0x476 (77c48a3d)
        77c489fd 48               dec     eax
        77c489fe 48               dec     eax
        77c489ff 742b             jz      msvcrt!Gettnames+0x465 (77c48a2c)
        77c48a01 48               dec     eax
        77c48a02 0f84d0000000     je      msvcrt!Gettnames+0x511 (77c48ad8)
        77c48a08 48               dec     eax
        77c48a09 75db             jnz     msvcrt!Gettnames+0x41f (77c489e6)
FAULT ->77c48a0b 8b4614           mov     eax,[esi+0x14]    ds:0023:00000014=????????
        77c48a0e 99               cdq
        77c48a0f 6a64             push    0x64
        77c48a11 59               pop     ecx
        77c48a12 f7f9             idiv    ecx
        77c48a14 ff7514           push    dword ptr [ebp+0x14]
        77c48a17 6a04             push    0x4
        77c48a19 83c013           add     eax,0x13
        77c48a1c 6bc064           imul    eax,eax,0x64
        77c48a1f 03c2             add     eax,edx
        77c48a21 5a               pop     edx

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr  Args to Child              
05503f18 77c4906a 77c5f7a0 00000000 77c5ff18 msvcrt!Gettnames+0x444
05503f3c 77c490c3 77c5f7a0 05504040 00000014 msvcrt!Gettnames+0xaa3
05503f5c 77c490e5 05504040 00000014 66bf381b msvcrt!Strftime+0x2f
05503f78 66ac8610 05504040 00000014 66bf381b msvcrt!strftime+0x18
05506d18 66ac8b6c 05507210 02695008 73697774 xmp-scrobbler!DllMain+0x7250
05507238 66ac464e 02695008 6867694e 73697774 xmp-scrobbler!DllMain+0x77ac
05507a68 66ac61c2 66bf3654 0550ff14 00000000 xmp-scrobbler!DllMain+0x328e
05507ab8 00420ae0 00000001 05507acc 00001089 xmp-scrobbler!DllMain+0x4e02
0550ff50 004202f7 00000000 00aa51b0 00aa8030 xmplay+0x20ae0
0550ff80 77c3a243 00000000 00000000 00000000 xmplay+0x202f7
0550ffb4 7c80b6a3 00aa8030 00000000 00000000 msvcrt!endthread+0xaf
0550ffec 00000000 77c3a1d7 00aa8030 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
0000000005503f10  18 ff c5 77 1c 38 bf 66 - 3c 3f 50 05 6a 90 c4 77  ...w.8.f<?P.j..w
0000000005503f20  a0 f7 c5 77 00 00 00 00 - 18 ff c5 77 00 00 00 00  ...w.......w....
0000000005503f30  02 00 00 00 60 40 50 05 - 14 00 00 00 5c 3f 50 05  ....`@P.....\?P.
0000000005503f40  c3 90 c4 77 a0 f7 c5 77 - 40 40 50 05 14 00 00 00  ...w...w@@P.....
0000000005503f50  1b 38 bf 66 00 00 00 00 - 14 00 00 00 78 3f 50 05  .8.f........x?P.
0000000005503f60  e5 90 c4 77 40 40 50 05 - 14 00 00 00 1b 38 bf 66  ...w@@P......8.f
0000000005503f70  00 00 00 00 00 00 00 00 - 18 6d 50 05 10 86 ac 66  .........mP....f
0000000005503f80  40 40 50 05 14 00 00 00 - 1b 38 bf 66 00 00 00 00  @@P......8.f....
0000000005503f90  04 00 00 00 d0 50 aa 00 - 04 00 00 00 40 50 aa 00  .....P......@P..
0000000005503fa0  04 00 00 00 e0 42 aa 00 - 04 00 00 00 01 01 00 00  .....B..........
0000000005503fb0  04 00 00 00 60 43 50 05 - 00 00 00 00 00 00 00 00  ....`CP.........
0000000005503fc0  00 00 00 00 00 00 00 00 - 00 00 00 00 4c 64 69 02  ............Ldi.
0000000005503fd0  00 00 00 00 00 00 00 00 - 20 70 aa 00 90 00 00 00  ........ p......
0000000005503fe0  73 00 00 00 46 00 00 00 - 0c 00 00 00 b0 53 aa 00  s...F........S..
0000000005503ff0  e0 42 aa 00 40 50 aa 00 - d0 50 aa 00 d0 52 aa 00  .B..@P...P...R..
0000000005504000  05 00 00 00 10 50 69 02 - 08 50 69 02 4c 71 50 05  .....Pi..Pi.LqP.
0000000005504010  02 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000005504020  00 00 00 00 e0 0e ba 66 - 6a 08 be 66 00 6d 50 05  .......fj..f.mP.
0000000005504030  b1 89 ac 66 80 3f 50 05 - 00 00 00 00 00 00 00 00  ...f.?P.........
0000000005504040  32 30 30 37 2d 30 39 2d - 31 37 20 30 35 3a 30 30  2007-09-17 05:00

*----> State Dump for Thread Id 0x114 <----*

eax=7c92798d ebx=00000000 ecx=00000000 edx=7ffd6c00 esi=00000000 edi=00000000
eip=7c90eb94 esp=0572ff9c ebp=0572ffb4 iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246

function: ntdll!KiFastSystemCallRet
        7c90eb89 90               nop
        7c90eb8a 90               nop
        ntdll!KiFastSystemCall:
        7c90eb8b 8bd4             mov     edx,esp
        7c90eb8d 0f34             sysenter
        7c90eb8f 90               nop
        7c90eb90 90               nop
        7c90eb91 90               nop
        7c90eb92 90               nop
        7c90eb93 90               nop
        ntdll!KiFastSystemCallRet:
        7c90eb94 c3               ret
        7c90eb95 8da42400000000   lea     esp,[esp]
        7c90eb9c 8d642400         lea     esp,[esp]
        7c90eba0 90               nop
        7c90eba1 90               nop
        7c90eba2 90               nop
        7c90eba3 90               nop
        7c90eba4 90               nop
        ntdll!KiIntSystemCall:
        7c90eba5 8d542408         lea     edx,[esp+0x8]
        7c90eba9 cd2e             int     2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr  Args to Child              
0572ffb4 7c80b6a3 00000000 00000000 00000000 ntdll!KiFastSystemCallRet
0572ffec 00000000 7c92798d 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
000000000572ff9c  5c d8 90 7c d4 79 92 7c - 01 00 00 00 ac ff 72 05  \..|.y.|......r.
000000000572ffac  00 00 00 00 00 00 00 80 - ec ff 72 05 a3 b6 80 7c  ..........r....|
000000000572ffbc  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000572ffcc  00 e0 fa 7f 00 d6 fb 86 - c0 ff 72 05 30 ac 02 85  ..........r.0...
000000000572ffdc  ff ff ff ff 30 9a 83 7c - b0 b6 80 7c 00 00 00 00  ....0..|...|....
000000000572ffec  00 00 00 00 00 00 00 00 - 8d 79 92 7c 00 00 00 00  .........y.|....
000000000572fffc  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000573000c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000573001c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000573002c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000573003c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000573004c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000573005c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000573006c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000573007c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000573008c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000573009c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
00000000057300ac  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
00000000057300bc  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
00000000057300cc  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................



Application exception occurred:
        App: C:\Un4seen\XMPlay\xmplay.exe (pid=3376)
        When: 18-Sep-07 @ 21:54:28.591
        Exception number: c0000005 (access violation)

*----> System Information <----*
        Computer Name: KALI
        User Name: Owner
        Terminal Session Id: 0
        Number of Processors: 2
        Processor Type: x86 Family 15 Model 3 Stepping 4
        Windows Version: 5.1
        Current Build: 2600
        Service Pack: 2
        Current Type: Multiprocessor Free
        Registered Organization: 
        Registered Owner: Thomas Ditmars

*----> Task List <----*
   0 System Process
   4 System
1020 smss.exe
1088 csrss.exe
1132 winlogon.exe
1184 services.exe
1196 lsass.exe
1368 Ati2evxx.exe
1396 svchost.exe
1548 svchost.exe
1688 svchost.exe
1788 Ati2evxx.exe
2024 svchost.exe
 452 spoolsv.exe
 680 AppleMobileDeviceService.exe
 724 avgamsvr.exe
 784 Explorer.EXE
 864 avgupsvc.exe
 920 avgemc.exe
 936 BOCORE.exe
1100 persfw.exe
1156 PRISMXL.SYS
 292 alg.exe
2352 svchost.exe
2420 CTHELPER.EXE
2512 avgcc.exe
2528 PDVDServ.exe
2620 BOC425.exe
2656 winpatrol.exe
2724 ctfmon.exe
2748 pg2.exe
2800 hm.exe
2836 hostssrv.exe
2884 taskbarshuffle.exe
2952 TeaTimer.exe
3064 iSproggler.exe
3144 daemon.exe
3196 atitray.exe
3428 GPGtray.exe
3568 nistime-32bit.exe
3560 iTunes.exe
3596 xchat.exe
 740 LastFMHelper.exe
3492 LastFM.exe
 384 iPodService.exe
3700 iTunesHelper.exe
3844 trillian.exe
3316 firefox.exe
3044 thunderbird.exe
1888 SAM.exe
3096 Skype.exe
3264 SkypePM.exe
3100 Explorer.EXE
3020 EDITPLUS.EXE
3376 xmplay.exe
2124 drwtsn32.exe

*----> Module List <----*
(0000000000330000 - 0000000000339000: C:\WINDOWS\system32\Normaliz.dll
(0000000000400000 - 0000000000552000: C:\Un4seen\XMPlay\xmplay.exe
(0000000000e40000 - 0000000000e4f000: C:\Program Files\BillP Studios\WinPatrol\PATROLPRO.DLL
(0000000000e60000 - 0000000000f3c000: C:\Un4seen\XMPlay\Plugins\in_adlib.dll
(0000000001060000 - 00000000011a5000: C:\Un4seen\XMPlay\Plugins\in_flac.dll
(00000000011b0000 - 00000000012a1000: C:\Un4seen\XMPlay\Plugins\in_gsf.dll
(00000000012b0000 - 000000000136f000: C:\Un4seen\XMPlay\Plugins\in_mp3.dll
(00000000013b0000 - 0000000001426000: C:\Un4seen\XMPlay\Plugins\in_mp3PRO.dll
(0000000001440000 - 00000000014e0000: C:\Un4seen\XMPlay\Plugins\in_mp4.dll
(00000000014e0000 - 0000000001519000: C:\Un4seen\XMPlay\Plugins\in_mpc.dll
(0000000001520000 - 000000000169b000: C:\Un4seen\XMPlay\Plugins\in_msx.dll
(00000000016b0000 - 00000000017c0000: C:\Un4seen\XMPlay\Plugins\in_psf.dll
(00000000017e0000 - 0000000001866000: C:\Un4seen\XMPlay\Plugins\in_qsf.dll
(0000000001880000 - 0000000001990000: C:\Un4seen\XMPlay\Plugins\in_sap.dll
(0000000001aa0000 - 0000000001b6e000: C:\Un4seen\XMPlay\Plugins\in_snes.dll
(0000000001c80000 - 0000000001d24000: C:\Un4seen\XMPlay\Plugins\SNESAPU.DLL
(0000000001d40000 - 0000000001e27000: C:\Un4seen\XMPlay\Plugins\in_usf.dll
(0000000001e30000 - 0000000001f25000: C:\Un4seen\XMPlay\Plugins\in_vgm.dll
(0000000001f40000 - 0000000001f7c000: C:\Un4seen\XMPlay\Plugins\in_vorbis.dll
(0000000001f80000 - 0000000001f8b000: C:\Un4seen\XMPlay\Plugins\in_wave.dll
(0000000001f90000 - 0000000002033000: C:\Un4seen\XMPlay\Plugins\in_yansf.dll
(00000000021e0000 - 0000000002257000: C:\Un4seen\XMPlay\Plugins\nsfplug_ui.dll
(0000000002380000 - 0000000002386000: C:\WINDOWS\system32\ctagent.dll
(00000000024c0000 - 00000000024c8000: C:\Un4seen\XMPlay\Plugins\xmp-7z.dll
(00000000024d0000 - 0000000002513000: C:\Un4seen\XMPlay\Plugins\xmp-aac.dll
(0000000002520000 - 00000000025a8000: C:\Un4seen\XMPlay\Plugins\xmp-ahx.dll
(0000000003140000 - 000000000314c000: C:\Un4seen\XMPlay\Plugins\xmp-arj.dll
(0000000003150000 - 0000000003157000: C:\Un4seen\XMPlay\Plugins\xmp-asio.dll
(0000000003160000 - 0000000003169000: C:\Un4seen\XMPlay\Plugins\xmp-cd.dll
(0000000003170000 - 0000000003177000: C:\Un4seen\XMPlay\Plugins\xmp-ds.dll
(0000000003180000 - 000000000318e000: C:\Un4seen\XMPlay\Plugins\xmp-flac.dll
(0000000003190000 - 000000000319d000: C:\Un4seen\XMPlay\Plugins\xmp-lha.dll
(00000000031a0000 - 00000000031ad000: C:\Un4seen\XMPlay\Plugins\xmp-midi.dll
(00000000031b0000 - 00000000031b6000: C:\Un4seen\XMPlay\Plugins\xmp-mmcmp.dll
(00000000031c0000 - 00000000031cb000: C:\Un4seen\XMPlay\Plugins\xmp-modpacker.dll
(00000000031d0000 - 00000000031df000: C:\Un4seen\XMPlay\Plugins\xmp-mpc.dll
(00000000031e0000 - 00000000031e6000: C:\Un4seen\XMPlay\Plugins\xmp-pp.dll
(0000000003200000 - 000000000320f000: C:\Un4seen\XMPlay\Plugins\xmp-rar.dll
(0000000003220000 - 0000000003227000: C:\Un4seen\XMPlay\Plugins\xmp-wadsp.dll
(0000000003230000 - 0000000003238000: C:\Un4seen\XMPlay\Plugins\xmp-wma.dll
(0000000003260000 - 00000000032b6000: C:\WINDOWS\system32\MSVCR71.dll
(00000000032d0000 - 00000000032da000: C:\Un4seen\XMPlay\Plugins\xmp-zip.dll
(00000000032e0000 - 0000000003441000: C:\Un4seen\XMPlay\Plugins\xmp-psf.dll
(0000000003550000 - 00000000035d9000: C:\Un4seen\XMPlay\Plugins\xmp-sid.dll
(0000000010000000 - 0000000010044000: C:\Program Files\Ray Adams\ATI Tray Tools\raphook.dll
(0000000016000000 - 0000000016028000: C:\Program Files\Trillian\events.dll
(0000000016080000 - 00000000160a5000: C:\Program Files\Bonjour\mdnsNSP.dll
(0000000042990000 - 00000000429d5000: C:\WINDOWS\system32\iertutil.dll
(0000000042c10000 - 0000000042cdf000: C:\WINDOWS\system32\WININET.dll
(0000000042cf0000 - 0000000042e14000: C:\WINDOWS\system32\urlmon.dll
(000000005ad70000 - 000000005ada8000: C:\WINDOWS\system32\uxtheme.dll
(000000005b860000 - 000000005b8b4000: C:\WINDOWS\system32\NETAPI32.dll
(00000000629c0000 - 00000000629c9000: C:\WINDOWS\system32\LPK.DLL
(00000000662b0000 - 0000000066308000: C:\WINDOWS\system32\hnetcfg.dll
(0000000066ac0000 - 0000000066c50000: C:\Un4seen\XMPlay\Plugins\xmp-scrobbler.dll
(0000000071a50000 - 0000000071a8f000: C:\WINDOWS\System32\mswsock.dll
(0000000071a90000 - 0000000071a98000: C:\WINDOWS\System32\wshtcpip.dll
(0000000071aa0000 - 0000000071aa8000: C:\WINDOWS\system32\WS2HELP.dll
(0000000071ab0000 - 0000000071ac7000: C:\WINDOWS\system32\WS2_32.dll
(0000000071ad0000 - 0000000071ad9000: C:\WINDOWS\system32\WSOCK32.dll
(00000000722b0000 - 00000000722b5000: C:\WINDOWS\system32\sensapi.dll
(0000000072d10000 - 0000000072d18000: C:\WINDOWS\system32\msacm32.drv
(0000000072d20000 - 0000000072d29000: C:\WINDOWS\system32\wdmaud.drv
(0000000073000000 - 0000000073026000: C:\WINDOWS\system32\WINSPOOL.DRV
(0000000073ee0000 - 0000000073ee4000: C:\WINDOWS\system32\KsUser.dll
(0000000073f10000 - 0000000073f6c000: C:\WINDOWS\system32\dsound.dll
(0000000074720000 - 000000007476b000: C:\WINDOWS\system32\MSCTF.dll
(0000000074d90000 - 0000000074dfb000: C:\WINDOWS\system32\USP10.dll
(00000000755c0000 - 00000000755ee000: C:\WINDOWS\system32\msctfime.ime
(0000000076390000 - 00000000763ad000: C:\WINDOWS\system32\IMM32.DLL
(00000000763b0000 - 00000000763f9000: C:\WINDOWS\system32\comdlg32.dll
(00000000769c0000 - 0000000076a73000: C:\WINDOWS\system32\USERENV.dll
(0000000076b40000 - 0000000076b6d000: C:\WINDOWS\system32\WINMM.dll
(0000000076bf0000 - 0000000076bfb000: C:\WINDOWS\system32\PSAPI.DLL
(0000000076c30000 - 0000000076c5e000: C:\WINDOWS\system32\WINTRUST.dll
(0000000076c90000 - 0000000076cb8000: C:\WINDOWS\system32\IMAGEHLP.dll
(0000000076d60000 - 0000000076d79000: C:\WINDOWS\system32\iphlpapi.dll
(0000000076e80000 - 0000000076e8e000: C:\WINDOWS\system32\rtutils.dll
(0000000076e90000 - 0000000076ea2000: C:\WINDOWS\system32\rasman.dll
(0000000076eb0000 - 0000000076edf000: C:\WINDOWS\system32\TAPI32.dll
(0000000076ee0000 - 0000000076f1c000: C:\WINDOWS\system32\RASAPI32.dll
(0000000076f20000 - 0000000076f47000: C:\WINDOWS\system32\DNSAPI.dll
(0000000076f60000 - 0000000076f8c000: C:\WINDOWS\system32\WLDAP32.dll
(0000000076fb0000 - 0000000076fb8000: C:\WINDOWS\System32\winrnr.dll
(0000000076fc0000 - 0000000076fc6000: C:\WINDOWS\system32\rasadhlp.dll
(0000000077120000 - 00000000771ab000: C:\WINDOWS\system32\OLEAUT32.dll
(00000000773d0000 - 00000000774d3000: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\COMCTL32.dll
(00000000774e0000 - 000000007761d000: C:\WINDOWS\system32\ole32.dll
(0000000077920000 - 0000000077a13000: C:\WINDOWS\system32\SETUPAPI.dll
(0000000077a80000 - 0000000077b14000: C:\WINDOWS\system32\CRYPT32.dll
(0000000077b20000 - 0000000077b32000: C:\WINDOWS\system32\MSASN1.dll
(0000000077b40000 - 0000000077b62000: C:\WINDOWS\system32\Apphelp.dll
(0000000077bd0000 - 0000000077bd7000: C:\WINDOWS\system32\midimap.dll
(0000000077be0000 - 0000000077bf5000: C:\WINDOWS\system32\MSACM32.dll
(0000000077c00000 - 0000000077c08000: C:\WINDOWS\system32\VERSION.DLL
(0000000077c10000 - 0000000077c68000: C:\WINDOWS\system32\msvcrt.dll
(0000000077c70000 - 0000000077c93000: C:\WINDOWS\system32\msv1_0.dll
(0000000077dd0000 - 0000000077e6b000: C:\WINDOWS\system32\ADVAPI32.dll
(0000000077e70000 - 0000000077f01000: C:\WINDOWS\system32\RPCRT4.dll
(0000000077f10000 - 0000000077f57000: C:\WINDOWS\system32\GDI32.dll
(0000000077f60000 - 0000000077fd6000: C:\WINDOWS\system32\SHLWAPI.dll
(0000000077fe0000 - 0000000077ff1000: C:\WINDOWS\system32\Secur32.dll
(000000007c3a0000 - 000000007c41b000: C:\WINDOWS\system32\MSVCP71.dll
(000000007c800000 - 000000007c8f5000: C:\WINDOWS\system32\kernel32.dll
(000000007c900000 - 000000007c9b0000: C:\WINDOWS\system32\ntdll.dll
(000000007c9c0000 - 000000007d1d5000: C:\WINDOWS\system32\SHELL32.dll
(000000007e410000 - 000000007e4a0000: C:\WINDOWS\system32\USER32.dll

*----> State Dump for Thread Id 0x5d8 <----*

eax=0012ff08 ebx=005510b6 ecx=00000000 edx=7c90eb94 esi=0012ff08 edi=00000000
eip=7c90eb94 esp=0012d7b0 ebp=0012d7d4 iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00200246

*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\ntdll.dll - 
function: ntdll!KiFastSystemCallRet
        7c90eb89 90               nop
        7c90eb8a 90               nop
        ntdll!KiFastSystemCall:
        7c90eb8b 8bd4             mov     edx,esp
        7c90eb8d 0f34             sysenter
        7c90eb8f 90               nop
        7c90eb90 90               nop
        7c90eb91 90               nop
        7c90eb92 90               nop
        7c90eb93 90               nop
        ntdll!KiFastSystemCallRet:
        7c90eb94 c3               ret
        7c90eb95 8da42400000000   lea     esp,[esp]
        7c90eb9c 8d642400         lea     esp,[esp]
        7c90eba0 90               nop
        7c90eba1 90               nop
        7c90eba2 90               nop
        7c90eba3 90               nop
        7c90eba4 90               nop
        ntdll!KiIntSystemCall:
        7c90eba5 8d542408         lea     edx,[esp+0x8]
        7c90eba9 cd2e             int     2e

*----> Stack Back Trace <----*
*** WARNING: Unable to verify checksum for C:\Un4seen\XMPlay\xmplay.exe
*** ERROR: Module load completed but symbols could not be loaded for C:\Un4seen\XMPlay\xmplay.exe
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\kernel32.dll - 
ChildEBP RetAddr  Args to Child              
0012d7d4 0043da74 0012ff08 00000000 00000000 ntdll!KiFastSystemCallRet
0012ff24 00445cdf 00400000 00000000 0015232f xmplay+0x3da74
0012ffc0 7c816ff7 011dcf78 00000018 7ffdb000 xmplay+0x45cdf
0012fff0 00000000 00551039 00000000 78746341 kernel32!RegisterWaitForInputIdle+0x49

*----> Raw Stack Dump <----*
000000000012d7b0  be 91 41 7e 42 e0 42 7e - 08 ff 12 00 00 00 00 00  ..A~B.B~........
000000000012d7c0  00 00 00 00 00 00 00 00 - b6 10 55 00 00 00 00 00  ..........U.....
000000000012d7d0  02 e0 42 7e 24 ff 12 00 - 74 da 43 00 08 ff 12 00  ..B~$...t.C.....
000000000012d7e0  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000012d7f0  78 cf 1d 01 2f 23 15 00 - ff 78 6d 70 2d 73 63 72  x.../#...xmp-scr
000000000012d800  6f 62 62 6c 65 72 2e 64 - 6c 6c 00 00 24 05 01 00  obbler.dll..$...
000000000012d810  00 00 5a 61 72 67 67 67 - 00 00 00 00 00 00 00 00  ..Zarggg........
000000000012d820  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000012d830  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000012d840  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000012d850  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000012d860  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000012d870  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000012d880  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000012d890  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000012d8a0  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000012d8b0  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000012d8c0  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000012d8d0  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000012d8e0  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................

*----> State Dump for Thread Id 0xb84 <----*

eax=00000000 ebx=00d6fed0 ecx=00d6fea8 edx=7c90eb94 esi=00000000 edi=7ffdb000
eip=7c90eb94 esp=00d6fea8 ebp=00d6ff44 iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246

function: ntdll!KiFastSystemCallRet
        7c90eb89 90               nop
        7c90eb8a 90               nop
        ntdll!KiFastSystemCall:
        7c90eb8b 8bd4             mov     edx,esp
        7c90eb8d 0f34             sysenter
        7c90eb8f 90               nop
        7c90eb90 90               nop
        7c90eb91 90               nop
        7c90eb92 90               nop
        7c90eb93 90               nop
        ntdll!KiFastSystemCallRet:
        7c90eb94 c3               ret
        7c90eb95 8da42400000000   lea     esp,[esp]
        7c90eb9c 8d642400         lea     esp,[esp]
        7c90eba0 90               nop
        7c90eba1 90               nop
        7c90eba2 90               nop
        7c90eba3 90               nop
        7c90eba4 90               nop
        ntdll!KiIntSystemCall:
        7c90eba5 8d542408         lea     edx,[esp+0x8]
        7c90eba9 cd2e             int     2e

*----> Stack Back Trace <----*
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\ADVAPI32.dll - 
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr  Args to Child              
00d6ff44 77df9b26 00000002 00d6ff6c 00000000 ntdll!KiFastSystemCallRet
00d6ffb4 7c80b6a3 00000000 7c9140bb 00000000 ADVAPI32!RegDeleteKeyW+0x2a2
00d6ffec 00000000 77df9981 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
0000000000d6fea8  ab e9 90 7c 0b 95 80 7c - 02 00 00 00 d0 fe d6 00  ...|...|........
0000000000d6feb8  01 00 00 00 01 00 00 00 - 04 ff d6 00 e8 3e b7 00  .............>..
0000000000d6fec8  40 65 e4 77 00 10 00 00 - 64 00 00 00 6c 00 00 00  @e.w....d...l...
0000000000d6fed8  c0 fe d6 00 48 72 40 e1 - dc ff d6 00 30 9a 83 7c  ....Hr@.....0..|
0000000000d6fee8  d0 0a 81 7c 00 10 00 00 - 14 00 00 00 01 00 00 00  ...|............
0000000000d6fef8  00 00 00 00 00 00 00 00 - 10 00 00 00 00 a2 2f 4d  ............../M
0000000000d6ff08  ff ff ff ff 00 10 00 00 - 00 b0 fd 7f 00 e0 fd 7f  ................
0000000000d6ff18  dc ff d6 00 04 ff d6 00 - d0 fe d6 00 06 00 00 00  ................
0000000000d6ff28  02 00 00 00 c4 fe d6 00 - 06 00 00 00 dc ff d6 00  ................
0000000000d6ff38  30 9a 83 7c 00 96 80 7c - 00 00 00 00 b4 ff d6 00  0..|...|........
0000000000d6ff48  26 9b df 77 02 00 00 00 - 6c ff d6 00 00 00 00 00  &..w....l.......
0000000000d6ff58  e0 93 04 00 01 00 00 00 - bb 40 91 7c 00 00 00 00  .........@.|....
0000000000d6ff68  00 00 00 00 64 00 00 00 - 6c 00 00 00 00 10 00 00  ....d...l.......
0000000000d6ff78  e8 3e b7 00 00 00 00 00 - 00 10 00 00 e0 2e b7 00  .>..............
0000000000d6ff88  80 66 e4 77 30 00 00 00 - a0 66 e4 77 00 10 00 00  .f.w0....f.w....
0000000000d6ff98  00 00 00 00 80 66 e4 77 - e8 3e b7 00 a0 66 e4 77  .....f.w.>...f.w
0000000000d6ffa8  e5 03 00 00 00 10 00 00 - e0 2e b7 00 ec ff d6 00  ................
0000000000d6ffb8  a3 b6 80 7c 00 00 00 00 - bb 40 91 7c 00 00 00 00  ...|.....@.|....
0000000000d6ffc8  00 00 00 00 00 e0 fd 7f - 00 b6 fb 86 c0 ff d6 00  ................
0000000000d6ffd8  c8 00 ba 85 ff ff ff ff - 30 9a 83 7c b0 b6 80 7c  ........0..|...|

*----> State Dump for Thread Id 0x838 <----*

eax=00000001 ebx=00000001 ecx=00000000 edx=00000000 esi=5a011478 edi=00000000
eip=7c90eb94 esp=047166dc ebp=04716720 iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246

function: ntdll!KiFastSystemCallRet
        7c90eb89 90               nop
        7c90eb8a 90               nop
        ntdll!KiFastSystemCall:
        7c90eb8b 8bd4             mov     edx,esp
        7c90eb8d 0f34             sysenter
        7c90eb8f 90               nop
        7c90eb90 90               nop
        7c90eb91 90               nop
        7c90eb92 90               nop
        7c90eb93 90               nop
        ntdll!KiFastSystemCallRet:
        7c90eb94 c3               ret
        7c90eb95 8da42400000000   lea     esp,[esp]
        7c90eb9c 8d642400         lea     esp,[esp]
        7c90eba0 90               nop
        7c90eba1 90               nop
        7c90eba2 90               nop
        7c90eba3 90               nop
        7c90eba4 90               nop
        ntdll!KiIntSystemCall:
        7c90eba5 8d542408         lea     edx,[esp+0x8]
        7c90eba9 cd2e             int     2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr  Args to Child              
04716720 0043eb70 5a011478 00000010 0000001c ntdll!KiFastSystemCallRet
0471ff64 0043e2ff 00000038 00a85420 0471ffb4 xmplay+0x3eb70
7e41c465 e87e41c4 ffffc14f e8084d8b ffffc057 xmplay+0x3e2ff
98680c6a 00000000 00000000 00000000 00000000 0xe87e41c4

*----> Raw Stack Dump <----*
00000000047166dc  36 bb f1 77 1f bb f1 77 - 78 14 01 5a 10 00 00 00  6..w...wx..Z....
00000000047166ec  1c 00 00 00 86 01 00 00 - 77 00 00 00 2b 22 01 12  ........w...+"..
00000000047166fc  00 00 00 00 00 00 00 00 - 86 01 00 00 77 00 00 00  ............w...
000000000471670c  20 00 cc 00 ff ff ff ff - 42 01 00 00 78 14 01 5a   .......B...x..Z
000000000471671c  1c 00 00 00 64 ff 71 04 - 70 eb 43 00 78 14 01 5a  ....d.q.p.C.x..Z
000000000471672c  10 00 00 00 1c 00 00 00 - 86 01 00 00 77 00 00 00  ............w...
000000000471673c  2b 22 01 12 00 00 00 00 - 00 00 00 00 86 01 00 00  +"..............
000000000471674c  77 00 00 00 20 00 cc 00 - 00 00 00 00 00 00 00 00  w... ...........
000000000471675c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000471676c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000471677c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000471678c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000471679c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
00000000047167ac  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
00000000047167bc  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
00000000047167cc  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
00000000047167dc  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
00000000047167ec  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
00000000047167fc  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000471680c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................

*----> State Dump for Thread Id 0xb2c <----*

eax=0499fc68 ebx=01027fe8 ecx=0499fc48 edx=00000001 esi=00000168 edi=00000000
eip=7c90eb94 esp=0499fefc ebp=0499ff60 iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00200246

function: ntdll!KiFastSystemCallRet
        7c90eb89 90               nop
        7c90eb8a 90               nop
        ntdll!KiFastSystemCall:
        7c90eb8b 8bd4             mov     edx,esp
        7c90eb8d 0f34             sysenter
        7c90eb8f 90               nop
        7c90eb90 90               nop
        7c90eb91 90               nop
        7c90eb92 90               nop
        7c90eb93 90               nop
        ntdll!KiFastSystemCallRet:
        7c90eb94 c3               ret
        7c90eb95 8da42400000000   lea     esp,[esp]
        7c90eb9c 8d642400         lea     esp,[esp]
        7c90eba0 90               nop
        7c90eba1 90               nop
        7c90eba2 90               nop
        7c90eba3 90               nop
        7c90eba4 90               nop
        ntdll!KiIntSystemCall:
        7c90eba5 8d542408         lea     edx,[esp+0x8]
        7c90eba9 cd2e             int     2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\Un4seen\XMPlay\Plugins\xmp-scrobbler.dll - 
ChildEBP RetAddr  Args to Child              
0499ff60 7c802532 00000168 ffffffff 00000000 ntdll!KiFastSystemCallRet
0499ff74 66ac760f 00000168 ffffffff 010245e4 kernel32!WaitForSingleObject+0x12
0499ffa4 66bb31a1 01021d60 7c90e2dc 0499ffec xmp-scrobbler!DllMain+0x624f
0499ffb4 7c80b6a3 01021d60 0489f9e0 00000001 xmp-scrobbler+0xf31a1
0499ffec 00000000 66bb3190 01021d60 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
000000000499fefc  c0 e9 90 7c cb 25 80 7c - 68 01 00 00 00 00 00 00  ...|.%.|h.......
000000000499ff0c  00 00 00 00 e4 45 02 01 - 60 1d 02 01 e8 7f 02 01  .....E..`.......
000000000499ff1c  14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000499ff2c  10 00 00 00 e4 45 02 01 - 60 1d 02 01 00 b0 fd 7f  .....E..`.......
000000000499ff3c  00 a0 fd 7f 00 00 00 00 - e3 c2 c2 77 10 ff 99 04  ...........w....
000000000499ff4c  30 ff 99 04 dc ff 99 04 - 30 9a 83 7c f8 25 80 7c  0.......0..|.%.|
000000000499ff5c  00 00 00 00 74 ff 99 04 - 32 25 80 7c 68 01 00 00  ....t...2%.|h...
000000000499ff6c  ff ff ff ff 00 00 00 00 - a4 ff 99 04 0f 76 ac 66  .............v.f
000000000499ff7c  68 01 00 00 ff ff ff ff - e4 45 02 01 01 00 00 00  h........E......
000000000499ff8c  00 00 00 00 a0 cd d9 84 - 00 00 00 00 60 1d 02 01  ............`...
000000000499ff9c  01 00 00 00 e0 f9 89 04 - b4 ff 99 04 a1 31 bb 66  .............1.f
000000000499ffac  60 1d 02 01 dc e2 90 7c - ec ff 99 04 a3 b6 80 7c  `......|.......|
000000000499ffbc  60 1d 02 01 e0 f9 89 04 - 01 00 00 00 60 1d 02 01  `...........`...
000000000499ffcc  00 a0 fd 7f 00 d6 fb 86 - c0 ff 99 04 70 67 f1 84  ............pg..
000000000499ffdc  ff ff ff ff 30 9a 83 7c - b0 b6 80 7c 00 00 00 00  ....0..|...|....
000000000499ffec  00 00 00 00 00 00 00 00 - 90 31 bb 66 60 1d 02 01  .........1.f`...
000000000499fffc  00 00 00 00 c8 00 00 00 - 82 01 00 00 ff ee ff ee  ................
00000000049a000c  02 10 00 00 00 00 00 00 - 00 fe 00 00 00 00 10 00  ................
00000000049a001c  00 20 00 00 00 02 00 00 - 00 20 00 00 2f fc 01 00  . ....... ../...
00000000049a002c  ff ef fd 7f 17 00 08 06 - 00 00 00 00 00 00 00 00  ................

*----> State Dump for Thread Id 0x8d8 <----*

eax=7ffd9000 ebx=c0000000 ecx=00000000 edx=045d2688 esi=00000000 edi=71a87558
eip=7c90eb94 esp=04b9ff7c ebp=04b9ffb4 iopl=0         nv up ei pl nz na pe nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000202

function: ntdll!KiFastSystemCallRet
        7c90eb89 90               nop
        7c90eb8a 90               nop
        ntdll!KiFastSystemCall:
        7c90eb8b 8bd4             mov     edx,esp
        7c90eb8d 0f34             sysenter
        7c90eb8f 90               nop
        7c90eb90 90               nop
        7c90eb91 90               nop
        7c90eb92 90               nop
        7c90eb93 90               nop
        ntdll!KiFastSystemCallRet:
        7c90eb94 c3               ret
        7c90eb95 8da42400000000   lea     esp,[esp]
        7c90eb9c 8d642400         lea     esp,[esp]
        7c90eba0 90               nop
        7c90eba1 90               nop
        7c90eba2 90               nop
        7c90eba3 90               nop
        7c90eba4 90               nop
        ntdll!KiIntSystemCall:
        7c90eba5 8d542408         lea     edx,[esp+0x8]
        7c90eba9 cd2e             int     2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr  Args to Child              
04b9ffb4 7c80b6a3 71a5d8ec 0499f8e4 7c90ee18 ntdll!KiFastSystemCallRet
04b9ffec 00000000 71a5d5af 0018e478 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
0000000004b9ff7c  1b e3 90 7c 09 d6 a5 71 - cc 01 00 00 bc ff b9 04  ...|...q........
0000000004b9ff8c  b0 ff b9 04 a4 ff b9 04 - 50 d6 a5 71 e4 f8 99 04  ........P..q....
0000000004b9ff9c  18 ee 90 7c 78 e4 18 00 - 00 00 00 00 00 00 00 00  ...|x...........
0000000004b9ffac  00 00 a5 71 08 28 5d 04 - ec ff b9 04 a3 b6 80 7c  ...q.(]........|
0000000004b9ffbc  ec d8 a5 71 e4 f8 99 04 - 18 ee 90 7c 78 e4 18 00  ...q.......|x...
0000000004b9ffcc  00 90 fd 7f 00 d6 fb 86 - c0 ff b9 04 b8 c8 80 84  ................
0000000004b9ffdc  ff ff ff ff 30 9a 83 7c - b0 b6 80 7c 00 00 00 00  ....0..|...|....
0000000004b9ffec  00 00 00 00 00 00 00 00 - af d5 a5 71 78 e4 18 00  ...........qx...
0000000004b9fffc  00 00 00 00 c8 00 00 00 - 91 01 00 00 ff ee ff ee  ................
0000000004ba000c  02 10 00 00 00 00 00 00 - 00 fe 00 00 00 00 10 00  ................
0000000004ba001c  00 20 00 00 00 02 00 00 - 00 20 00 00 f3 01 00 00  . ....... ......
0000000004ba002c  ff ef fd 7f 1a 00 08 06 - 00 00 00 00 00 00 00 00  ................
0000000004ba003c  00 00 00 00 00 00 00 00 - 98 05 ba 04 0f 00 00 00  ................
0000000004ba004c  f8 ff ff ff 50 00 ba 04 - 50 00 ba 04 40 06 ba 04  ....P...P...@...
0000000004ba005c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000004ba006c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000004ba007c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000004ba008c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000004ba009c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000004ba00ac  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................

*----> State Dump for Thread Id 0xcf0 <----*

eax=72d230e8 ebx=04d1fef8 ecx=0000005e edx=00000000 esi=00000000 edi=7ffdb000
eip=7c90eb94 esp=04d1fed0 ebp=04d1ff6c iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246

function: ntdll!KiFastSystemCallRet
        7c90eb89 90               nop
        7c90eb8a 90               nop
        ntdll!KiFastSystemCall:
        7c90eb8b 8bd4             mov     edx,esp
        7c90eb8d 0f34             sysenter
        7c90eb8f 90               nop
        7c90eb90 90               nop
        7c90eb91 90               nop
        7c90eb92 90               nop
        7c90eb93 90               nop
        ntdll!KiFastSystemCallRet:
        7c90eb94 c3               ret
        7c90eb95 8da42400000000   lea     esp,[esp]
        7c90eb9c 8d642400         lea     esp,[esp]
        7c90eba0 90               nop
        7c90eba1 90               nop
        7c90eba2 90               nop
        7c90eba3 90               nop
        7c90eba4 90               nop
        ntdll!KiIntSystemCall:
        7c90eba5 8d542408         lea     edx,[esp+0x8]
        7c90eba9 cd2e             int     2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\wdmaud.drv - 
ChildEBP RetAddr  Args to Child              
04d1ff6c 7c80a095 00000002 04d1ffa4 00000000 ntdll!KiFastSystemCallRet
04d1ff88 72d2312a 00000002 04d1ffa4 00000000 kernel32!WaitForMultipleObjects+0x18
04d1ffb4 7c80b6a3 00000000 00000000 00150000 wdmaud!midMessage+0x348
04d1ffec 00000000 72d230e8 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
0000000004d1fed0  ab e9 90 7c 0b 95 80 7c - 02 00 00 00 f8 fe d1 04  ...|...|........
0000000004d1fee0  01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
0000000004d1fef0  00 00 00 00 00 00 00 00 - 4c 02 00 00 0c 02 00 00  ........L.......
0000000004d1ff00  ac 04 ea 84 28 6c d6 aa - 00 00 00 00 27 f4 6f 80  ....(l......'.o.
0000000004d1ff10  08 00 00 00 46 02 00 00 - 14 00 00 00 01 00 00 00  ....F...........
0000000004d1ff20  00 00 00 00 00 00 00 00 - 10 00 00 00 10 03 ea 84  ................
0000000004d1ff30  44 03 ea 84 06 02 00 00 - 00 b0 fd 7f 00 80 fd 7f  D...............
0000000004d1ff40  10 03 ea 84 00 00 00 00 - f8 fe d1 04 ac 9b 4f 80  ..............O.
0000000004d1ff50  02 00 00 00 ec fe d1 04 - 00 00 00 00 dc ff d1 04  ................
0000000004d1ff60  30 9a 83 7c 00 96 80 7c - 00 00 00 00 88 ff d1 04  0..|...|........
0000000004d1ff70  95 a0 80 7c 02 00 00 00 - a4 ff d1 04 00 00 00 00  ...|............
0000000004d1ff80  ff ff ff ff 00 00 00 00 - b4 ff d1 04 2a 31 d2 72  ............*1.r
0000000004d1ff90  02 00 00 00 a4 ff d1 04 - 00 00 00 00 ff ff ff ff  ................
0000000004d1ffa0  00 00 15 00 4c 02 00 00 - 0c 02 00 00 f2 fe 6f 80  ....L.........o.
0000000004d1ffb0  dc e2 90 7c ec ff d1 04 - a3 b6 80 7c 00 00 00 00  ...|.......|....
0000000004d1ffc0  00 00 00 00 00 00 15 00 - 00 00 00 00 00 80 fd 7f  ................
0000000004d1ffd0  00 d6 fb 86 c0 ff d1 04 - b8 c8 80 84 ff ff ff ff  ................
0000000004d1ffe0  30 9a 83 7c b0 b6 80 7c - 00 00 00 00 00 00 00 00  0..|...|........
0000000004d1fff0  00 00 00 00 e8 30 d2 72 - 00 00 00 00 00 00 00 00  .....0.r........
0000000004d20000  43 6c 69 65 6e 74 20 55 - 72 6c 43 61 63 68 65 20  Client UrlCache 

*----> State Dump for Thread Id 0x720 <----*

eax=7c92798d ebx=00000000 ecx=00000000 edx=7ffd7c00 esi=00000000 edi=00000000
eip=7c90eb94 esp=0511ff9c ebp=0511ffb4 iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246

function: ntdll!KiFastSystemCallRet
        7c90eb89 90               nop
        7c90eb8a 90               nop
        ntdll!KiFastSystemCall:
        7c90eb8b 8bd4             mov     edx,esp
        7c90eb8d 0f34             sysenter
        7c90eb8f 90               nop
        7c90eb90 90               nop
        7c90eb91 90               nop
        7c90eb92 90               nop
        7c90eb93 90               nop
        ntdll!KiFastSystemCallRet:
        7c90eb94 c3               ret
        7c90eb95 8da42400000000   lea     esp,[esp]
        7c90eb9c 8d642400         lea     esp,[esp]
        7c90eba0 90               nop
        7c90eba1 90               nop
        7c90eba2 90               nop
        7c90eba3 90               nop
        7c90eba4 90               nop
        ntdll!KiIntSystemCall:
        7c90eba5 8d542408         lea     edx,[esp+0x8]
        7c90eba9 cd2e             int     2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr  Args to Child              
0511ffb4 7c80b6a3 00000000 00000000 00000000 ntdll!KiFastSystemCallRet
0511ffec 00000000 7c92798d 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
000000000511ff9c  5c d8 90 7c d4 79 92 7c - 01 00 00 00 ac ff 11 05  \..|.y.|........
000000000511ffac  00 00 00 00 00 00 00 80 - ec ff 11 05 a3 b6 80 7c  ...............|
000000000511ffbc  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000511ffcc  00 60 fd 7f 00 d6 fb 86 - c0 ff 11 05 38 0d 99 84  .`..........8...
000000000511ffdc  ff ff ff ff 30 9a 83 7c - b0 b6 80 7c 00 00 00 00  ....0..|...|....
000000000511ffec  00 00 00 00 00 00 00 00 - 8d 79 92 7c 00 00 00 00  .........y.|....
000000000511fffc  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000512000c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000512001c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000512002c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000512003c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000512004c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000512005c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000512006c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000512007c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000512008c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000512009c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
00000000051200ac  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
00000000051200bc  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
00000000051200cc  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................

*----> State Dump for Thread Id 0x324 <----*

eax=73f19f98 ebx=05fb34d8 ecx=04503ccc edx=7c90eb94 esi=00000000 edi=7ffdb000
eip=7c90eb94 esp=0501fd88 ebp=0501fe24 iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246

function: ntdll!KiFastSystemCallRet
        7c90eb89 90               nop
        7c90eb8a 90               nop
        ntdll!KiFastSystemCall:
        7c90eb8b 8bd4             mov     edx,esp
        7c90eb8d 0f34             sysenter
        7c90eb8f 90               nop
        7c90eb90 90               nop
        7c90eb91 90               nop
        7c90eb92 90               nop
        7c90eb93 90               nop
        ntdll!KiFastSystemCallRet:
        7c90eb94 c3               ret
        7c90eb95 8da42400000000   lea     esp,[esp]
        7c90eb9c 8d642400         lea     esp,[esp]
        7c90eba0 90               nop
        7c90eba1 90               nop
        7c90eba2 90               nop
        7c90eba3 90               nop
        7c90eba4 90               nop
        ntdll!KiIntSystemCall:
        7c90eba5 8d542408         lea     edx,[esp+0x8]
        7c90eba9 cd2e             int     2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\dsound.dll - 
ChildEBP RetAddr  Args to Child              
0501fe24 7c80a095 00000040 0501fe78 00000000 ntdll!KiFastSystemCallRet
0501fe40 73f114a2 00000040 0501fe78 00000000 kernel32!WaitForMultipleObjects+0x18
0501fe58 73f1294a 00000040 ffffffff 00000000 dsound+0x14a2
0501ff78 73f19fbf ffffffff 0000003f 04506928 dsound+0x294a
0501ff98 73f1297e 04502270 04503ccc 73f1b993 dsound!DirectSoundCreate+0x537c
0501ffb4 7c80b6a3 04503ccc 04502270 0489fcdc dsound+0x297e
0501ffec 00000000 73f1b94b 04503ccc 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
000000000501fd88  ab e9 90 7c 0b 95 80 7c - 40 00 00 00 d8 34 fb 05  ...|...|@....4..
000000000501fd98  01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
000000000501fda8  40 00 00 00 01 00 00 00 - 40 6d 29 e1 2c f0 39 e4  @.......@m).,.9.
000000000501fdb8  00 00 00 00 00 00 00 00 - 38 00 00 00 23 00 00 00  ........8...#...
000000000501fdc8  23 00 00 00 70 22 50 04 - 14 00 00 00 01 00 00 00  #...p"P.........
000000000501fdd8  00 00 00 00 00 00 00 00 - 10 00 00 00 a6 68 91 7c  .............h.|
000000000501fde8  79 06 81 7c 1b 00 00 00 - 00 b0 fd 7f 00 70 fd 7f  y..|.........p..
000000000501fdf8  00 70 fd 7f 00 00 00 00 - d8 34 fb 05 00 02 00 00  .p.......4......
000000000501fe08  40 00 00 00 a4 fd 01 05 - 2c f0 39 e4 dc ff 01 05  @.......,.9.....
000000000501fe18  30 9a 83 7c 00 96 80 7c - 00 00 00 00 40 fe 01 05  0..|...|....@...
000000000501fe28  95 a0 80 7c 40 00 00 00 - 78 fe 01 05 00 00 00 00  ...|@...x.......
000000000501fe38  ff ff ff ff 00 00 00 00 - 58 fe 01 05 a2 14 f1 73  ........X......s
000000000501fe48  40 00 00 00 78 fe 01 05 - 00 00 00 00 ff ff ff ff  @...x...........
000000000501fe58  78 ff 01 05 4a 29 f1 73 - 40 00 00 00 ff ff ff ff  x...J).s@.......
000000000501fe68  00 00 00 00 78 fe 01 05 - cc 3c 50 04 cc 3c 50 04  ....x....<P..<P.
000000000501fe78  c0 04 00 00 90 02 00 00 - 8c 02 00 00 cc 03 00 00  ................
000000000501fe88  d4 03 00 00 d0 03 00 00 - d8 03 00 00 dc 03 00 00  ................
000000000501fe98  e0 03 00 00 e4 03 00 00 - e8 03 00 00 ec 03 00 00  ................
000000000501fea8  f0 03 00 00 f4 03 00 00 - f8 03 00 00 fc 03 00 00  ................
000000000501feb8  00 04 00 00 04 04 00 00 - 08 04 00 00 0c 04 00 00  ................

*----> State Dump for Thread Id 0xc50 <----*

eax=04503f70 ebx=061afdb8 ecx=00000000 edx=0000000c esi=00000000 edi=7ffdb000
eip=7c90eb94 esp=061afd90 ebp=061afe2c iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246

function: ntdll!KiFastSystemCallRet
        7c90eb89 90               nop
        7c90eb8a 90               nop
        ntdll!KiFastSystemCall:
        7c90eb8b 8bd4             mov     edx,esp
        7c90eb8d 0f34             sysenter
        7c90eb8f 90               nop
        7c90eb90 90               nop
        7c90eb91 90               nop
        7c90eb92 90               nop
        7c90eb93 90               nop
        ntdll!KiFastSystemCallRet:
        7c90eb94 c3               ret
        7c90eb95 8da42400000000   lea     esp,[esp]
        7c90eb9c 8d642400         lea     esp,[esp]
        7c90eba0 90               nop
        7c90eba1 90               nop
        7c90eba2 90               nop
        7c90eba3 90               nop
        7c90eba4 90               nop
        ntdll!KiIntSystemCall:
        7c90eba5 8d542408         lea     edx,[esp+0x8]
        7c90eba9 cd2e             int     2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr  Args to Child              
061afe2c 7c80a095 00000001 061afe80 00000000 ntdll!KiFastSystemCallRet
061afe48 73f114a2 00000001 061afe80 00000000 kernel32!WaitForMultipleObjects+0x18
061afe60 73f1294a 00000001 000001f4 00000000 dsound+0x14a2
061aff80 73f12a13 000001f4 00000000 00000000 dsound+0x294a
061affb4 7c80b6a3 04501efc 00000000 7c910732 dsound+0x2a13
061affec 00000000 73f1b94b 04501efc 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
00000000061afd90  ab e9 90 7c 0b 95 80 7c - 01 00 00 00 b8 fd 1a 06  ...|...|........
00000000061afda0  01 00 00 00 00 00 00 00 - ec fd 1a 06 00 00 00 00  ................
00000000061afdb0  01 00 00 00 01 00 00 00 - d4 04 00 00 4d 95 80 7c  ............M..|
00000000061afdc0  00 00 00 00 3b 95 80 7c - e8 89 50 04 00 00 00 00  ....;..|..P.....
00000000061afdd0  e0 fd 1a 06 00 00 00 00 - 14 00 00 00 01 00 00 00  ................
00000000061afde0  00 00 00 00 00 00 00 00 - 10 00 00 00 c0 b4 b3 ff  ................
00000000061afdf0  ff ff ff ff 84 fe 1a 06 - 00 b0 fd 7f 00 40 fd 7f  .............@..
00000000061afe00  3b 95 80 7c ec fd 1a 06 - b8 fd 1a 06 1c fe 1a 06  ;..|............
00000000061afe10  01 00 00 00 ac fd 1a 06 - 30 55 50 04 dc ff 1a 06  ........0UP.....
00000000061afe20  30 9a 83 7c 00 96 80 7c - 00 00 00 00 48 fe 1a 06  0..|...|....H...
00000000061afe30  95 a0 80 7c 01 00 00 00 - 80 fe 1a 06 00 00 00 00  ...|............
00000000061afe40  f4 01 00 00 00 00 00 00 - 60 fe 1a 06 a2 14 f1 73  ........`......s
00000000061afe50  01 00 00 00 80 fe 1a 06 - 00 00 00 00 f4 01 00 00  ................
00000000061afe60  80 ff 1a 06 4a 29 f1 73 - 01 00 00 00 f4 01 00 00  ....J).s........
00000000061afe70  00 00 00 00 80 fe 1a 06 - fc 1e 50 04 fc 1e 50 04  ..........P...P.
00000000061afe80  d4 04 00 00 d8 55 50 04 - 20 00 00 00 b4 fe 00 06  .....UP. .......
00000000061afe90  00 00 00 00 d8 55 50 04 - ac fe 1a 06 df 24 f1 73  .....UP......$.s
00000000061afea0  e4 55 50 04 70 3f 50 04 - ab e9 90 7c 0b 95 80 7c  .UP.p?P....|...|
00000000061afeb0  00 40 fd 7f 44 ff 1a 06 - 4d 95 80 7c f0 fe 1a 06  .@..D...M..|....
00000000061afec0  3b 95 80 7c 00 00 00 00 - fc 1e 50 04 fc 1e 50 04  ;..|......P...P.

*----> State Dump for Thread Id 0x650 <----*

eax=00000000 ebx=00a90000 ecx=7ffaf000 edx=03173138 esi=000004e4 edi=00000000
eip=7c90eb94 esp=062afedc ebp=062aff40 iopl=0         nv up ei ng nz ac po cy
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000297

function: ntdll!KiFastSystemCallRet
        7c90eb89 90               nop
        7c90eb8a 90               nop
        ntdll!KiFastSystemCall:
        7c90eb8b 8bd4             mov     edx,esp
        7c90eb8d 0f34             sysenter
        7c90eb8f 90               nop
        7c90eb90 90               nop
        7c90eb91 90               nop
        7c90eb92 90               nop
        7c90eb93 90               nop
        ntdll!KiFastSystemCallRet:
        7c90eb94 c3               ret
        7c90eb95 8da42400000000   lea     esp,[esp]
        7c90eb9c 8d642400         lea     esp,[esp]
        7c90eba0 90               nop
        7c90eba1 90               nop
        7c90eba2 90               nop
        7c90eba3 90               nop
        7c90eba4 90               nop
        ntdll!KiIntSystemCall:
        7c90eba5 8d542408         lea     edx,[esp+0x8]
        7c90eba9 cd2e             int     2e

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
*** WARNING: Unable to verify checksum for C:\Un4seen\XMPlay\Plugins\xmp-ds.dll
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\Un4seen\XMPlay\Plugins\xmp-ds.dll - 
ChildEBP RetAddr  Args to Child              
062aff40 7c802532 000004e4 0000004b 00000000 ntdll!KiFastSystemCallRet
062aff54 03171527 000004e4 0000004b 7c911596 kernel32!WaitForSingleObject+0x12
0002ae4c 00000000 00000000 00000000 00000000 xmp-ds+0x1527

*----> Raw Stack Dump <----*
00000000062afedc  c0 e9 90 7c cb 25 80 7c - e4 04 00 00 00 00 00 00  ...|.%.|........
00000000062afeec  10 ff 2a 06 00 00 00 00 - 80 00 00 00 00 00 a9 00  ..*.............
00000000062afefc  14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00  ................
00000000062aff0c  10 00 00 00 50 8e f4 ff - ff ff ff ff 00 b0 fd 7f  ....P...........
00000000062aff1c  00 f0 fa 7f 10 ff 2a 06 - 02 01 00 00 f0 fe 2a 06  ......*.......*.
00000000062aff2c  00 00 00 00 a4 ff 2a 06 - 30 9a 83 7c f8 25 80 7c  ......*.0..|.%.|
00000000062aff3c  00 00 00 00 54 ff 2a 06 - 32 25 80 7c e4 04 00 00  ....T.*.2%.|....
00000000062aff4c  4b 00 00 00 00 00 00 00 - 4c ae 02 00 27 15 17 03  K.......L...'...
00000000062aff5c  e4 04 00 00 4b 00 00 00 - 96 15 91 7c 50 9e a9 00  ....K......|P...
00000000062aff6c  b4 ff 2a 06 e0 9e a9 00 - 00 00 00 00 00 00 00 00  ..*.............
00000000062aff7c  e8 44 00 00 18 4f e3 04 - b0 a3 c3 77 00 00 00 00  .D...O.....w....
00000000062aff8c  96 15 91 7c eb 06 91 7c - e0 9e a9 00 00 00 00 00  ...|...|........
00000000062aff9c  8c ff 2a 06 00 00 00 00 - dc ff 2a 06 94 5c c3 77  ..*.......*..\.w
00000000062affac  d8 40 c1 77 00 00 00 00 - ec ff 2a 06 a3 b6 80 7c  .@.w......*....|
00000000062affbc  e0 9e a9 00 96 15 91 7c - eb 06 91 7c e0 9e a9 00  .......|...|....
00000000062affcc  00 f0 fa 7f 00 d6 fb 86 - c0 ff 2a 06 98 43 f2 84  ..........*..C..
00000000062affdc  ff ff ff ff 30 9a 83 7c - b0 b6 80 7c 00 00 00 00  ....0..|...|....
00000000062affec  00 00 00 00 00 00 00 00 - 41 a3 c3 77 e0 9e a9 00  ........A..w....
00000000062afffc  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
00000000062b000c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................

*----> State Dump for Thread Id 0xb38 <----*

eax=00000000 ebx=063a39d0 ecx=063a39c0 edx=063a3ed8 esi=00000000 edi=063a39c0
eip=77c48a0b esp=063a3988 ebp=063a3990 iopl=0         nv up ei pl zr na po nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246

*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\msvcrt.dll - 
function: msvcrt!Gettnames
        77c489f9 48               dec     eax
        77c489fa 48               dec     eax
        77c489fb 7440             jz      msvcrt!Gettnames+0x476 (77c48a3d)
        77c489fd 48               dec     eax
        77c489fe 48               dec     eax
        77c489ff 742b             jz      msvcrt!Gettnames+0x465 (77c48a2c)
        77c48a01 48               dec     eax
        77c48a02 0f84d0000000     je      msvcrt!Gettnames+0x511 (77c48ad8)
        77c48a08 48               dec     eax
        77c48a09 75db             jnz     msvcrt!Gettnames+0x41f (77c489e6)
FAULT ->77c48a0b 8b4614           mov     eax,[esi+0x14]    ds:0023:00000014=????????
        77c48a0e 99               cdq
        77c48a0f 6a64             push    0x64
        77c48a11 59               pop     ecx
        77c48a12 f7f9             idiv    ecx
        77c48a14 ff7514           push    dword ptr [ebp+0x14]
        77c48a17 6a04             push    0x4
        77c48a19 83c013           add     eax,0x13
        77c48a1c 6bc064           imul    eax,eax,0x64
        77c48a1f 03c2             add     eax,edx
        77c48a21 5a               pop     edx

*----> Stack Back Trace <----*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr  Args to Child              
063a3990 77c4906a 77c5f7a0 00000000 77c5ff18 msvcrt!Gettnames+0x444
063a39b4 77c490c3 77c5f7a0 063a3ab8 00000014 msvcrt!Gettnames+0xaa3
063a39d4 77c490e5 063a3ab8 00000014 66bf381b msvcrt!Strftime+0x2f
063a39f0 66ac8610 063a3ab8 00000014 66bf381b msvcrt!strftime+0x18
063a6790 66ac8b6c 063a6c88 01021d60 694e2079 xmp-scrobbler!DllMain+0x7250
063a6cb0 66ac464e 01021d60 6e6e6f52 694e2079 xmp-scrobbler!DllMain+0x77ac
063a74e0 66ac61c2 66bf3654 00002274 03213fb0 xmp-scrobbler!DllMain+0x328e
063a7530 00420ae0 00000001 063a7544 0000113a xmp-scrobbler!DllMain+0x4e02
063aff50 004202f7 00000000 00a98040 00a99ee0 xmplay+0x20ae0
063aff80 77c3a243 00000000 00000000 00000000 xmplay+0x202f7
063affb4 7c80b6a3 00a99ee0 00000000 00000000 msvcrt!endthread+0xaf
063affec 00000000 77c3a1d7 00a99ee0 00000000 kernel32!GetModuleFileNameA+0x1b4

*----> Raw Stack Dump <----*
00000000063a3988  18 ff c5 77 1c 38 bf 66 - b4 39 3a 06 6a 90 c4 77  ...w.8.f.9:.j..w
00000000063a3998  a0 f7 c5 77 00 00 00 00 - 18 ff c5 77 00 00 00 00  ...w.......w....
00000000063a39a8  02 00 00 00 d8 3a 3a 06 - 14 00 00 00 d4 39 3a 06  .....::......9:.
00000000063a39b8  c3 90 c4 77 a0 f7 c5 77 - b8 3a 3a 06 14 00 00 00  ...w...w.::.....
00000000063a39c8  1b 38 bf 66 00 00 00 00 - 14 00 00 00 f0 39 3a 06  .8.f.........9:.
00000000063a39d8  e5 90 c4 77 b8 3a 3a 06 - 14 00 00 00 1b 38 bf 66  ...w.::......8.f
00000000063a39e8  00 00 00 00 00 00 00 00 - 90 67 3a 06 10 86 ac 66  .........g:....f
00000000063a39f8  b8 3a 3a 06 14 00 00 00 - 1b 38 bf 66 00 00 00 00  .::......8.f....
00000000063a3a08  04 00 00 00 60 8e a9 00 - 04 00 00 00 20 9f a9 00  ....`....... ...
00000000063a3a18  04 00 00 00 f0 9e a9 00 - 04 00 00 00 01 01 00 00  ................
00000000063a3a28  04 00 00 00 d8 3d 3a 06 - 00 00 00 00 00 00 00 00  .....=:.........
00000000063a3a38  00 00 00 00 00 00 00 00 - 00 00 00 00 a4 31 02 01  .............1..
00000000063a3a48  00 00 00 00 00 00 00 00 - c0 95 a9 00 90 00 00 00  ................
00000000063a3a58  73 00 00 00 46 00 00 00 - 0c 00 00 00 00 8e a9 00  s...F...........
00000000063a3a68  f0 9e a9 00 20 9f a9 00 - 60 8e a9 00 e0 88 a9 00  .... ...`.......
00000000063a3a78  05 00 00 00 68 1d 02 01 - 60 1d 02 01 c4 6b 3a 06  ....h...`....k:.
00000000063a3a88  02 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
00000000063a3a98  00 00 00 00 e0 0e ba 66 - 6a 08 be 66 78 67 3a 06  .......fj..fxg:.
00000000063a3aa8  b1 89 ac 66 f8 39 3a 06 - 00 00 00 00 00 00 00 00  ...f.9:.........
00000000063a3ab8  32 30 30 37 2d 30 39 2d - 31 37 20 30 35 3a 30 30  2007-09-17 05:00