Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 0:014> !heap -s
- NtGlobalFlag enables following debugging aids for new heaps:
- stack back traces
- LFH Key : 0x5fd192a6
- Termination on corruption : ENABLED
- Heap Flags Reserv Commit Virt Free List UCR Virt Lock Fast
- (k) (k) (k) (k) length blocks cont. heap
- -----------------------------------------------------------------------------
- 00530000 08000002 2048 1308 2048 19 28 2 0 0 LFH
- 00650000 08001002 1088 80 1088 70 3 2 0 0
- 00980000 08001002 3136 2996 3136 466 80 3 0 0 LFH
- External fragmentation 15 % (80 free blocks)
- 05410000 08001002 256 24 256 3 8 1 0 0
- Virtual block: 09250000 - 09250000 (size 00000000)
- Virtual block: 09430000 - 09430000 (size 00000000)
- Virtual block: 092e0000 - 092e0000 (size 00000000)
- 008b0000 08001002 31616 17660 31616 1347 262 6 3 0 LFH
- 05800000 08001002 64 12 64 3 2 1 0 0
- 053d0000 08001002 64 4 64 2 1 1 0 0
- 05f90000 08011002 256 16 256 11 2 1 0 0
- 060e0000 08001002 256 4 256 1 2 1 0 0
- 08110000 08001002 256 92 256 4 4 1 0 0 LFH
- 08310000 08001002 256 156 256 10 5 1 0 0 LFH
- 08520000 08001002 64 8 64 5 1 1 0 0
- 08470000 08001002 1088 380 1088 278 3 2 0 0
- 09420000 08001002 64 4 64 2 1 1 0 0
- 0bab0000 08001002 64 4 64 2 1 1 0 0
- 0f9a0000 08001002 256 100 256 52 4 1 0 0
- 12310000 08001002 3328 1892 3328 22 25 3 0 0 LFH
- -----------------------------------------------------------------------------
- 0:014> !heap -s
- NtGlobalFlag enables following debugging aids for new heaps:
- stack back traces
- LFH Key : 0x5fd192a6
- Termination on corruption : ENABLED
- Heap Flags Reserv Commit Virt Free List UCR Virt Lock Fast
- (k) (k) (k) (k) length blocks cont. heap
- -----------------------------------------------------------------------------
- 00530000 08000002 16384 8768 16384 167 70 5 0 0 LFH
- 00650000 08001002 1088 80 1088 70 3 2 0 0
- 00980000 08001002 3136 2996 3136 466 80 3 0 0 LFH
- External fragmentation 15 % (80 free blocks)
- 05410000 08001002 256 24 256 3 7 1 0 0
- Virtual block: 09250000 - 09250000 (size 00000000)
- Virtual block: 09430000 - 09430000 (size 00000000)
- Virtual block: 092e0000 - 092e0000 (size 00000000)
- 008b0000 08001002 31616 17016 31616 1054 266 7 3 0 LFH
- 05800000 08001002 64 12 64 3 2 1 0 0
- 053d0000 08001002 64 4 64 2 1 1 0 0
- 05f90000 08011002 256 16 256 11 2 1 0 0
- 060e0000 08001002 256 4 256 1 2 1 0 0
- 08110000 08001002 256 92 256 4 3 1 0 0 LFH
- 08310000 08001002 256 156 256 10 6 1 0 0 LFH
- 08520000 08001002 64 8 64 5 1 1 0 0
- 08470000 08001002 1088 380 1088 277 3 2 0 0
- 09420000 08001002 64 4 64 2 1 1 0 0
- 0bab0000 08001002 64 4 64 2 1 1 0 0
- 0f9a0000 08001002 256 100 256 52 4 1 0 0
- 12310000 08001002 31808 26480 31808 103 37 6 0 0 LFH
- -----------------------------------------------------------------------------
- 0:014> !heap -stat -h 12310000
- heap @ 12310000
- group-by: TOTSIZE max-display: 20
- size #blocks total ( %) (percent of total busy bytes)
- 18d4 cba - 13bfa08 (82.26)
- 190 180a - 258fa0 (9.78)
- c0 cba - 98b80 (2.48)
- 191 43e - 6a51e (1.73)
- 188 2d4 - 454a0 (1.13)
- 186 2d4 - 44ef8 (1.12)
- 24 1985 - 396b4 (0.93)
- 187 16a - 228e6 (0.56)
- 14 b - dc (0.00)
- 56 2 - ac (0.00)
- 86 1 - 86 (0.00)
- 68 1 - 68 (0.00)
- 64 1 - 64 (0.00)
- 20 3 - 60 (0.00)
- 18 4 - 60 (0.00)
- 5c 1 - 5c (0.00)
- 5a 1 - 5a (0.00)
- 28 2 - 50 (0.00)
- 4e 1 - 4e (0.00)
- 4c 1 - 4c (0.00)
- 0:014> !heap -p -a 15af03f0
- address 15af03f0 found in
- _HEAP @ 12310000
- HEAP_ENTRY Size Prev Flags UserPtr UserSize - state
- 15af03d8 0321 0000 [00] 15af03f0 018d4 - (busy)
- 77b6df42 ntdll!RtlAllocateHeap+0x00000274
- 5c1995fc fastprox!CBasicBlobControl::sAllocate+0x0000004b
- 5c19e471 fastprox!CWbemObjectArrayPacket::GetInstanceObject+0x0000007b
- 5c19e3e0 fastprox!CWbemObjectArrayPacket::UnmarshalPacket+0x0000015a
- 5c19eb93 fastprox!CWbemSmartEnumNextPacket::UnmarshalPacket+0x00000170
- 5c19e71b fastprox!CEnumProxyBuffer::XEnumFacelet::Next+0x000000bf
- // ...
- 15a84360 0035 0035 [00] 15a84378 00190 - (busy)
- fastprox!CWbemInstance::`vftable'
- 0:014> !heap -p -a 15a84378
- address 15a84378 found in
- _HEAP @ 12310000
- HEAP_ENTRY Size Prev Flags UserPtr UserSize - state
- 15a84360 0035 0000 [00] 15a84378 00190 - (busy)
- fastprox!CWbemInstance::`vftable'
- 77b6df42 ntdll!RtlAllocateHeap+0x00000274
- 5c240df7 wbemcomn!CWin32DefaultArena::WbemMemAlloc+0x0000001c
- 5c19e4a8 fastprox!CWbemObjectArrayPacket::GetInstanceObject+0x000000ae
- 5c19e3e0 fastprox!CWbemObjectArrayPacket::UnmarshalPacket+0x0000015a
- 5c19eb93 fastprox!CWbemSmartEnumNextPacket::UnmarshalPacket+0x00000170
- 5c19e71b fastprox!CEnumProxyBuffer::XEnumFacelet::Next+0x000000bf
- // ...
- 1599a120 001b 001b [00] 1599a138 000c0 - (busy)
- fastprox!CEnumProxyBuffer::`vftable'
- 0:014> !heap -p -a 1599a138
- address 1599a138 found in
- _HEAP @ 12310000
- HEAP_ENTRY Size Prev Flags UserPtr UserSize - state
- 1599a120 001b 0000 [00] 1599a138 000c0 - (busy)
- fastprox!CEnumProxyBuffer::`vftable'
- 77b6df42 ntdll!RtlAllocateHeap+0x00000274
- 5c240df7 wbemcomn!CWin32DefaultArena::WbemMemAlloc+0x0000001c
- 5c19ea0f fastprox!CEnumFactoryBuffer::XEnumFactory::CreateProxy+0x00000050
- 7554fe80 ole32!CStdMarshal::CreateProxy+0x000000d0
- 7554fb6a ole32!CStdMarshal::MakeCliIPIDEntry+0x0000001f
- 7554fb3e ole32!CStdMarshal::UnmarshalIPID+0x00000066
- 755500a5 ole32!CStdMarshal::UnmarshalObjRef+0x00000113
- 75552253 ole32!UnmarshalSwitch+0x00000025
- 7555221e ole32!UnmarshalObjRef+0x00000090
- 7554f1b3 ole32!CoUnmarshalInterface+0x000000f1
- 7554f735 ole32!NdrExtInterfacePointerUnmarshall+0x000001cb
- 76ed4215 RPCRT4!NdrpPointerUnmarshall+0x000000cb
- 76eb915c RPCRT4!NdrPointerUnmarshall+0x00000030
- 76eb90df RPCRT4!NdrpPointerUnmarshall+0x000002bf
- 76eb915c RPCRT4!NdrPointerUnmarshall+0x00000030
- 76eb7116 RPCRT4!NdrpClientUnMarshal+0x00000157
- 76f5015a RPCRT4!NdrClientCall2+0x0000026f
- 7565c8e2 ole32!ObjectStublessClient+0x000000a2
- 755598ad ole32!ObjectStubless+0x0000000f
- 5c19ec64 fastprox!CWbemSvcWrapper::XWbemServices::ExecQuery+0x0000008c
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement