Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 0:014> ~* kp
- 0 Id: 5d4.874 Suspend: 1 Teb: 00007ff5`ffffd000 Unfrozen
- Child-SP RetAddr Call Site
- 00000000`01c86488 00007ffa`c8892601 user32!NtUserValidateTimerCallback+0xa
- 00000000`01c86490 00007ffa`c88c5cd3 user32!DispatchMessageWorker+0x237
- 00000000`01c86510 00007ffa`c88c7732 user32!DialogBox2+0x22d
- 00000000`01c865a0 00007ffa`c88c99f2 user32!InternalDialogBox+0x132
- 00000000`01c86600 00007ffa`c88c918d user32!SoftModalMessageBox+0xee1
- 00000000`01c86740 00007ffa`c89181fa user32!MessageBoxWorker+0x2eb
- 00000000`01c868f0 00007ffa`c891826e user32!MessageBoxTimeoutW+0xba
- *** WARNING: Unable to verify timestamp for c:\ntapps\totalcmd\TOTALCMD64.EXE
- *** ERROR: Module load completed but symbols could not be loaded for c:\ntapps\totalcmd\TOTALCMD64.EXE
- 00000000`01c869f0 00000000`0042fd66 user32!MessageBoxW+0x4e
- 00000000`01c86a30 00000000`00000001 TOTALCMD64+0x2fd66
- 00000000`01c86a38 00000000`00000000 0x1
- 1 Id: 5d4.1698 Suspend: 1 Teb: 00007ff5`ffffb000 Unfrozen
- Child-SP RetAddr Call Site
- 00000000`0492cfc8 00007ffa`c83113ed ntdll!NtWaitForMultipleObjects+0xa
- 00000000`0492cfd0 00007ffa`c88930f0 KERNELBASE!WaitForMultipleObjectsEx+0xe1
- 00000000`0492d2b0 00007ffa`c88931c4 user32!RealMsgWaitForMultipleObjectsEx+0x100
- 00000000`0492d360 00000000`00629a63 user32!MsgWaitForMultipleObjects+0x6c
- 00000000`0492d3b0 00000000`00415460 TOTALCMD64+0x229a63
- 00000000`0492d3b8 00000000`0492fdc0 TOTALCMD64+0x15460
- 00000000`0492d3c0 00000000`00234a20 0x492fdc0
- 00000000`0492d3c8 00000000`00000000 0x234a20
- 2 Id: 5d4.a30 Suspend: 1 Teb: 00007ff5`ffff7000 Unfrozen
- Child-SP RetAddr Call Site
- 00000000`0880fbf8 00007ffa`c8311118 ntdll!NtWaitForSingleObject+0xa
- 00000000`0880fc00 00000000`0073d2f8 KERNELBASE!WaitForSingleObjectEx+0x94
- 00000000`0880fca0 00000000`00415460 TOTALCMD64+0x33d2f8
- 00000000`0880fca8 00000000`00000000 TOTALCMD64+0x15460
- 3 Id: 5d4.1084 Suspend: 1 Teb: 00007ff5`ffff5000 Unfrozen
- Child-SP RetAddr Call Site
- 00000000`0980f6f8 00007ffa`c83113ed ntdll!NtWaitForMultipleObjects+0xa
- 00000000`0980f700 00007ffa`c88930f0 KERNELBASE!WaitForMultipleObjectsEx+0xe1
- 00000000`0980f9e0 00007ffa`c88931c4 user32!RealMsgWaitForMultipleObjectsEx+0x100
- 00000000`0980fa90 00000000`0073b863 user32!MsgWaitForMultipleObjects+0x6c
- 00000000`0980fae0 00000000`00415460 TOTALCMD64+0x33b863
- 00000000`0980fae8 00000000`0980fdc0 TOTALCMD64+0x15460
- 00000000`0980faf0 00000000`00237e80 0x980fdc0
- 00000000`0980faf8 00000000`00000000 0x237e80
- 4 Id: 5d4.cc Suspend: 1 Teb: 00007ff5`ffece000 Unfrozen
- Child-SP RetAddr Call Site
- 00000000`0a80fb78 00007ffa`cb0e90f6 ntdll!NtWaitForWorkViaWorkerFactory+0xa
- 00000000`0a80fb80 00007ffa`c87413d2 ntdll!TppWorkerThread+0x746
- 00000000`0a80ff60 00007ffa`cb0c54e4 KERNEL32!BaseThreadInitThunk+0x22
- 00000000`0a80ff90 00000000`00000000 ntdll!RtlUserThreadStart+0x34
- 5 Id: 5d4.d58 Suspend: 1 Teb: 00007ff5`ffecc000 Unfrozen
- Child-SP RetAddr Call Site
- 00000000`0b80fb78 00007ffa`cb0e90f6 ntdll!NtWaitForWorkViaWorkerFactory+0xa
- 00000000`0b80fb80 00007ffa`c87413d2 ntdll!TppWorkerThread+0x746
- 00000000`0b80ff60 00007ffa`cb0c54e4 KERNEL32!BaseThreadInitThunk+0x22
- 00000000`0b80ff90 00000000`00000000 ntdll!RtlUserThreadStart+0x34
- 6 Id: 5d4.1560 Suspend: 1 Teb: 00007ff5`ffeca000 Unfrozen
- Child-SP RetAddr Call Site
- 00000000`0c80f938 00007ffa`c83113ed ntdll!NtWaitForMultipleObjects+0xa
- 00000000`0c80f940 00007ffa`c91b8dee KERNELBASE!WaitForMultipleObjectsEx+0xe1
- 00000000`0c80fc20 00007ffa`c91b8ea8 combase!WaitCoalesced(void * timer = 0x00000000`000002c4, unsigned int cHandlesOuter = 0, void ** pHandles = 0x00000000`00000000, unsigned long delayInMs = <Value unavailable error>, unsigned long tolerableDelayInMs = 0xfa0, int alertable = 0n0, unsigned long * waitResult = <Value unavailable error>)+0xaa [d:\blue\com\published\comutils\coalescedwait.cxx @ 72]
- 00000000`0c80fe70 00007ffa`c91b9082 combase!CROIDTable::WorkerThreadLoop(void * param = 0x00000000`00000000)+0x78 [d:\blue\com\combase\dcomrem\refcache.cxx @ 1480]
- 00000000`0c80fec0 00007ffa`c91b90a5 combase!CRpcThread::WorkerLoop(void)+0x162 [d:\blue\com\combase\dcomrem\threads.cxx @ 260]
- 00000000`0c80ff30 00007ffa`c87413d2 combase!CRpcThreadCache::RpcWorkerThreadEntry(void * param = 0x00000000`0030aa40)+0x46 [d:\blue\com\combase\dcomrem\threads.cxx @ 67]
- 00000000`0c80ff60 00007ffa`cb0c54e4 KERNEL32!BaseThreadInitThunk+0x22
- 00000000`0c80ff90 00000000`00000000 ntdll!RtlUserThreadStart+0x34
- 7 Id: 5d4.608 Suspend: 1 Teb: 00007ff5`ffec6000 Unfrozen
- Child-SP RetAddr Call Site
- 00000000`0faaf8f8 00007ffa`c83113ed ntdll!NtWaitForMultipleObjects+0xa
- 00000000`0faaf900 00007ffa`c91b8dee KERNELBASE!WaitForMultipleObjectsEx+0xe1
- 00000000`0faafbe0 00007ffa`c91b92c2 combase!WaitCoalesced(void * timer = 0x00000000`000003a4, unsigned int cHandlesOuter = 1, void ** pHandles = 0x00000000`0faafe88, unsigned long delayInMs = <Value unavailable error>, unsigned long tolerableDelayInMs = 0xea60, int alertable = 0n0, unsigned long * waitResult = <Value unavailable error>)+0xaa [d:\blue\com\published\comutils\coalescedwait.cxx @ 72]
- 00000000`0faafe30 00007ffa`c91b6840 combase!CDllHost::MTAWorkerLoop(void * hEventWakeUp = 0x00000000`00000384)+0x76 [d:\blue\com\combase\objact\dllhost.cxx @ 1018]
- 00000000`0faafe80 00007ffa`c91a60b3 combase!CDllHost::WorkerThread(void)+0x122 [d:\blue\com\combase\objact\dllhost.cxx @ 939]
- 00000000`0faafec0 00007ffa`c91b90a5 combase!CRpcThread::WorkerLoop(void)+0x175 [d:\blue\com\combase\dcomrem\threads.cxx @ 260]
- 00000000`0faaff30 00007ffa`c87413d2 combase!CRpcThreadCache::RpcWorkerThreadEntry(void * param = 0x00000000`04a12280)+0x46 [d:\blue\com\combase\dcomrem\threads.cxx @ 67]
- 00000000`0faaff60 00007ffa`cb0c54e4 KERNEL32!BaseThreadInitThunk+0x22
- 00000000`0faaff90 00000000`00000000 ntdll!RtlUserThreadStart+0x34
- 8 Id: 5d4.12d8 Suspend: 1 Teb: 00007ff5`ffec4000 Unfrozen
- Child-SP RetAddr Call Site
- 00000000`10aafdd8 00007ffa`c8892685 user32!NtUserGetMessage+0xa
- 00000000`10aafde0 00007ffa`c9143167 user32!GetMessageW+0x25
- 00000000`10aafe10 00007ffa`c91a6182 combase!CDllHost::STAWorkerLoop(void)+0x67 [d:\blue\com\combase\objact\dllhost.cxx @ 1093]
- 00000000`10aafe80 00007ffa`c91a60b3 combase!CDllHost::WorkerThread(void)+0xbe [d:\blue\com\combase\objact\dllhost.cxx @ 952]
- 00000000`10aafec0 00007ffa`c91b90a5 combase!CRpcThread::WorkerLoop(void)+0x175 [d:\blue\com\combase\dcomrem\threads.cxx @ 260]
- 00000000`10aaff30 00007ffa`c87413d2 combase!CRpcThreadCache::RpcWorkerThreadEntry(void * param = 0x00000000`04a128c0)+0x46 [d:\blue\com\combase\dcomrem\threads.cxx @ 67]
- 00000000`10aaff60 00007ffa`cb0c54e4 KERNEL32!BaseThreadInitThunk+0x22
- 00000000`10aaff90 00000000`00000000 ntdll!RtlUserThreadStart+0x34
- 9 Id: 5d4.17f4 Suspend: 1 Teb: 00007ff5`ffec2000 Unfrozen
- Child-SP RetAddr Call Site
- 00000000`11b7fb78 00007ffa`cb0e90f6 ntdll!NtWaitForWorkViaWorkerFactory+0xa
- 00000000`11b7fb80 00007ffa`c87413d2 ntdll!TppWorkerThread+0x746
- 00000000`11b7ff60 00007ffa`cb0c54e4 KERNEL32!BaseThreadInitThunk+0x22
- 00000000`11b7ff90 00000000`00000000 ntdll!RtlUserThreadStart+0x34
- 10 Id: 5d4.ad4 Suspend: 1 Teb: 00007ff5`ffec0000 Unfrozen
- Child-SP RetAddr Call Site
- 00000000`12b7fb78 00007ffa`cb0e90f6 ntdll!NtWaitForWorkViaWorkerFactory+0xa
- 00000000`12b7fb80 00007ffa`c87413d2 ntdll!TppWorkerThread+0x746
- 00000000`12b7ff60 00007ffa`cb0c54e4 KERNEL32!BaseThreadInitThunk+0x22
- 00000000`12b7ff90 00000000`00000000 ntdll!RtlUserThreadStart+0x34
- 11 Id: 5d4.163c Suspend: 1 Teb: 00007ff5`ffebe000 Unfrozen
- Child-SP RetAddr Call Site
- 00000000`13b7f988 00007ffa`c83113ed ntdll!NtWaitForMultipleObjects+0xa
- 00000000`13b7f990 00007ffa`c91b8dee KERNELBASE!WaitForMultipleObjectsEx+0xe1
- 00000000`13b7fc70 00007ffa`c91b9021 combase!WaitCoalesced(void * timer = 0x00000000`00000418, unsigned int cHandlesOuter = 1, void ** pHandles = 0x00000000`06783b20, unsigned long delayInMs = <Value unavailable error>, unsigned long tolerableDelayInMs = 0x7530, int alertable = 0n1, unsigned long * waitResult = <Value unavailable error>)+0xaa [d:\blue\com\published\comutils\coalescedwait.cxx @ 72]
- 00000000`13b7fec0 00007ffa`c91b90a5 combase!CRpcThread::WorkerLoop(void)+0x109 [d:\blue\com\combase\dcomrem\threads.cxx @ 312]
- 00000000`13b7ff30 00007ffa`c87413d2 combase!CRpcThreadCache::RpcWorkerThreadEntry(void * param = 0x00000000`06783b20)+0x46 [d:\blue\com\combase\dcomrem\threads.cxx @ 67]
- 00000000`13b7ff60 00007ffa`cb0c54e4 KERNEL32!BaseThreadInitThunk+0x22
- 00000000`13b7ff90 00000000`00000000 ntdll!RtlUserThreadStart+0x34
- 12 Id: 5d4.7ac Suspend: 1 Teb: 00007ff5`ffebc000 Unfrozen
- Child-SP RetAddr Call Site
- 00000000`14b9ebf8 00007ffa`c83113ed ntdll!NtWaitForMultipleObjects+0xa
- 00000000`14b9ec00 00007ffa`c88930f0 KERNELBASE!WaitForMultipleObjectsEx+0xe1
- 00000000`14b9eee0 00007ffa`c88931c4 user32!RealMsgWaitForMultipleObjectsEx+0x100
- 00000000`14b9ef90 00000000`004f6b7e user32!MsgWaitForMultipleObjects+0x6c
- 00000000`14b9efe0 00000000`00415460 TOTALCMD64+0xf6b7e
- 00000000`14b9efe8 00000000`14b9fdc0 TOTALCMD64+0x15460
- 00000000`14b9eff0 00000000`002356c0 0x14b9fdc0
- 00000000`14b9eff8 00000000`00000000 0x2356c0
- 13 Id: 5d4.9cc Suspend: 1 Teb: 00007ff5`ffeba000 Unfrozen
- Child-SP RetAddr Call Site
- 00000000`15b9f7c8 00007ffa`c83113ed ntdll!NtWaitForMultipleObjects+0xa
- 00000000`15b9f7d0 00007ffa`c88930f0 KERNELBASE!WaitForMultipleObjectsEx+0xe1
- 00000000`15b9fab0 00007ffa`c88931c4 user32!RealMsgWaitForMultipleObjectsEx+0x100
- 00000000`15b9fb60 00000000`004fbeb6 user32!MsgWaitForMultipleObjects+0x6c
- 00000000`15b9fbb0 00000000`00415460 TOTALCMD64+0xfbeb6
- 00000000`15b9fbb8 00000000`15b9fdc0 TOTALCMD64+0x15460
- 00000000`15b9fbc0 00000000`002374c0 0x15b9fdc0
- 00000000`15b9fbc8 00000000`00000000 0x2374c0
- # 14 Id: 5d4.7b0 Suspend: 1 Teb: 00007ff5`ffff9000 Unfrozen
- Child-SP RetAddr Call Site
- 00000000`077fff28 00007ffa`cb16f3a4 ntdll!DbgBreakPoint
- 00000000`077fff30 00007ffa`c87413d2 ntdll!DbgUiRemoteBreakin+0x34
- 00000000`077fff60 00007ffa`cb0c54e4 KERNEL32!BaseThreadInitThunk+0x22
- 00000000`077fff90 00000000`00000000 ntdll!RtlUserThreadStart+0x34
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement