Hello, Hive!
I've been mapmaking for over 4 years now and during this time I've experienced crashing of Warcraft during games which is caused by trigger errors. All this time I had to examine the situation when the crash happens and wild guess the issue. Recently I found out that crash reports are saved in the Warcraft 3 folder. My question is, can we use the information provided by the crash report to precisely identify the problem? Help will be greatly appreciated.
Here are two examples of crash reports:
Warcraft III (build 6401)
Exe: E:\Warcraft 3\Warcraft III\war3.exe
Time: Nov 24, 2014 10:46:51.479 PM
User: User
Computer: USER-PC
This application has encountered a critical error:
Program: E:\Warcraft 3\Warcraft III\war3.exe
Exception: 0xC0000005 (ACCESS_VIOLATION) at 0023:026790C1
The instruction at '0x026790C1' referenced memory at '0x0000000C'.
The memory could not be 'read'.
Played Maps\Scenario\Sunken City v1.8.8..w3x
Player 0 SpasMaster Race Orc StartLoc 1
Player 1 Scaryfo Race Orc StartLoc 2
Player 2 Warsinshadow Race Orc StartLoc 0
Player 3 The Horde Race Orc StartLoc 3
Player 4 <Unused> Race NightElf StartLoc -1
Player 5 <Unused> Race NightElf StartLoc -1
Player 6 <Unused> Race NightElf StartLoc -1
Player 7 <Unused> Race NightElf StartLoc -1
Player 8 <Unused> Race Human StartLoc -1
Player 9 <Unused> Race NightElf StartLoc -1
Player 10 <Unused> Race Undead StartLoc -1
Player 11 Temple Habitants Race Undead StartLoc 4
x86 Registers
EAX=0018F418 EBX=2CDEFB34 ECX=00000000 EDX=0018F418 ESI=2DFD86AC
EDI=0D740C8C EBP=00000004 ESP=0018F408 EIP=026790C1 FLG=00210246
CS =0023 DS =002B ES =002B SS =002B FS =0053 GS =002B
Stack Trace (Manual)
Address Frame Logical addr Module
026790C1 00000004 0001:004780C1 E:\Warcraft 3\Warcraft III\Game.dll
Stack Trace (Using DBGHELP.DLL)
026790C1 Game.dll GameMain+4651121 (0x0018F418,0x2DFD86AC,0x3DCCCCCD,0x02455042)
Loaded Modules
0x00400000 - 0x0047D000 E:\Warcraft 3\Warcraft III\war3.exe
0x02200000 - 0x02DB5000 E:\Warcraft 3\Warcraft III\Game.dll
0x04950000 - 0x04A5A000 C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPI.dll
0x10000000 - 0x1001E000 D:\Garena Plus\Room\War3Hook.dll
0x15000000 - 0x15061000 E:\Warcraft 3\Warcraft III\Storm.dll
0x21100000 - 0x2115F000 E:\Warcraft 3\Warcraft III\mss32.dll
0x22600000 - 0x22616000 E:\Warcraft 3\Warcraft III\redist\miles\Mssfast.m3d
0x22700000 - 0x22717000 E:\Warcraft 3\Warcraft III\redist\miles\Mssdolby.m3d
0x22C00000 - 0x22C18000 E:\Warcraft 3\Warcraft III\redist\miles\Msseax2.m3d
0x24600000 - 0x24611000 E:\Warcraft 3\Warcraft III\redist\miles\Reverb3.flt
0x26F00000 - 0x26F2A000 E:\Warcraft 3\Warcraft III\redist\miles\Mp3dec.asi
0x60000000 - 0x6005D000 E:\Warcraft 3\Warcraft III\ijl15.dll
0x622F0000 - 0x623F5000 C:\Windows\system32\d3d8.dll
0x62400000 - 0x62422000 C:\Windows\system32\GLU32.dll
0x62430000 - 0x624F8000 C:\Windows\system32\OPENGL32.dll
0x6B600000 - 0x6B6EB000 C:\Windows\system32\dbghelp.dll
0x6BC60000 - 0x6BEE3000 C:\Windows\system32\nvapi.dll
0x6D520000 - 0x6D556000 C:\Windows\system32\AUDIOSES.DLL
0x6E560000 - 0x6E647000 C:\Windows\system32\DDRAW.dll
0x6E8A0000 - 0x6E8A6000 C:\Windows\system32\DCIMAN32.dll
0x6F0B0000 - 0x6F14B000 C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll
0x70A20000 - 0x70A59000 C:\Windows\System32\MMDevApi.dll
0x70D90000 - 0x71BFF000 C:\Windows\system32\nvd3dum.dll
0x73150000 - 0x73167000 C:\Windows\system32\bcrypt.dll
0x731C0000 - 0x731FD000 C:\Windows\SysWOW64\bcryptprimitives.dll
0x73240000 - 0x73247000 C:\Windows\system32\avrt.dll
0x73280000 - 0x732B8000 C:\Windows\system32\ncrypt.dll
0x73330000 - 0x7334C000 C:\Windows\system32\cryptnet.dll
0x73350000 - 0x73375000 C:\Windows\system32\powrprof.dll
0x73D90000 - 0x73E02000 C:\Windows\system32\DSOUND.DLL
0x73EF0000 - 0x73EF6000 C:\Windows\system32\SensApi.dll
0x73F10000 - 0x73F26000 C:\Windows\system32\GPAPI.dll
0x73F80000 - 0x73F86000 C:\Windows\system32\d3d8thk.dll
0x74040000 - 0x74061000 C:\Windows\system32\ntmarta.dll
0x740A0000 - 0x74195000 C:\Windows\System32\PROPSYS.dll
0x741C0000 - 0x74244000 C:\Windows\WinSxS\\COMCTL32.dll
0x74280000 - 0x74285000 C:\Windows\System32\wshtcpip.dll
0x74700000 - 0x7473C000 C:\Windows\system32\mswsock.dll
0x74870000 - 0x7487E000 D:\Garena Plus\Room\WC3J.dll
0x74A60000 - 0x74A9B000 C:\Windows\system32\rsaenh.dll
0x74AA0000 - 0x74AB7000 C:\Windows\system32\CRYPTSP.dll
0x74B10000 - 0x74B17000 C:\Windows\system32\WSOCK32.dll
0x74B30000 - 0x74B43000 C:\Windows\system32\dwmapi.dll
0x74B80000 - 0x74C00000 C:\Windows\system32\uxtheme.dll
0x74F10000 - 0x74F42000 C:\Windows\system32\WINMM.dll
0x74FA0000 - 0x74FA9000 C:\Windows\system32\VERSION.dll
0x74FD0000 - 0x74FDC000 C:\Windows\syswow64\CRYPTBASE.dll
0x74FE0000 - 0x75040000 C:\Windows\syswow64\SspiCli.dll
0x75040000 - 0x75087000 C:\Windows\syswow64\KERNELBASE.dll
0x75090000 - 0x75093000 C:\Windows\syswow64\normaliz.DLL
0x750A0000 - 0x75130000 C:\Windows\syswow64\GDI32.dll
0x75130000 - 0x75165000 C:\Windows\syswow64\WS2_32.dll
0x752C0000 - 0x753C0000 C:\Windows\syswow64\USER32.dll
0x753C0000 - 0x7555D000 C:\Windows\syswow64\SETUPAPI.dll
0x75560000 - 0x75572000 C:\Windows\syswow64\DEVOBJ.dll
0x75580000 - 0x755E0000 C:\Windows\syswow64\IMM32.dll
0x755E0000 - 0x7567D000 C:\Windows\syswow64\USP10.dll
0x75680000 - 0x762CA000 C:\Windows\syswow64\SHELL32.dll
0x762D0000 - 0x762D4000 C:\Windows\syswow64\api-ms-win-downlevel-version-l1-1-0.dll
0x762E0000 - 0x7636F000 C:\Windows\syswow64\OLEAUT32.dll
0x76370000 - 0x76375000 C:\Windows\syswow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
0x76470000 - 0x7647B000 C:\Windows\syswow64\profapi.dll
0x76480000 - 0x7654C000 C:\Windows\syswow64\MSCTF.dll
0x76550000 - 0x765D3000 C:\Windows\syswow64\CLBCatQ.DLL
0x765E0000 - 0x765E5000 C:\Windows\syswow64\PSAPI.DLL
0x765F0000 - 0x76711000 C:\Windows\syswow64\CRYPT32.dll
0x76720000 - 0x76724000 C:\Windows\syswow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
0x76730000 - 0x767D0000 C:\Windows\syswow64\ADVAPI32.dll
0x767D0000 - 0x767F7000 C:\Windows\syswow64\CFGMGR32.dll
0x76800000 - 0x76804000 C:\Windows\syswow64\api-ms-win-downlevel-user32-l1-1-0.dll
0x76810000 - 0x7681C000 C:\Windows\syswow64\MSASN1.dll
0x76820000 - 0x768CC000 C:\Windows\syswow64\msvcrt.dll
0x768D0000 - 0x76B02000 C:\Windows\syswow64\iertutil.dll
0x76B10000 - 0x76B1A000 C:\Windows\syswow64\LPK.dll
0x76B50000 - 0x76C60000 C:\Windows\syswow64\kernel32.dll
0x76C60000 - 0x76E36000 C:\Windows\syswow64\WININET.dll
0x76E70000 - 0x76EEB000 C:\Windows\syswow64\comdlg32.dll
0x76EF0000 - 0x76F09000 C:\Windows\SysWOW64\sechost.dll
0x76F20000 - 0x76F23000 C:\Windows\syswow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
0x76F30000 - 0x76F75000 C:\Windows\syswow64\WLDAP32.dll
0x76F80000 - 0x76FD7000 C:\Windows\syswow64\SHLWAPI.dll
0x76FE0000 - 0x76FF7000 C:\Windows\syswow64\USERENV.dll
0x77000000 - 0x770F0000 C:\Windows\syswow64\RPCRT4.dll
0x770F0000 - 0x7724C000 C:\Windows\syswow64\ole32.dll
0x77620000 - 0x77626000 C:\Windows\syswow64\NSI.dll
0x77650000 - 0x777D0000 C:\Windows\SysWOW64\ntdll.dll
Memory Dump
Code: 16 bytes starting at (EIP = 026790C1)
026790C1: 8B 51 0C 8B 49 08 56 57 E8 62 69 BC FF 8B 7C 24|$
Stack: 1024 bytes starting at (ESP = 0018F408)
* = addr ** *
0018F400: 00 00 00 00 AC 86 FD 2D 00 00 00 00 0F 32 24 02 .......-.....2$.
0018F410: 18 F4 18 00 AC 86 FD 2D CD CC CC 3D 42 50 45 02 .......-...=BPE.
0018F420: 2C 08 78 0D 68 08 78 0D 00 00 00 00 39 33 4B 02 ,.x.h.x.....93K.
0018F430: 00 00 80 BF 00 00 80 3F 00 00 00 00 6C 67 61 2B .......?....lga+
0018F440: E0 DD 1C 38 2C 08 78 0D 00 00 00 00 C6 34 4B 02 ...8,.x......4K.
0018F450: 34 FB DE 2C 0D D1 66 02 88 00 40 07 C0 34 4B 02 4..,[email protected].
0018F460: 5C F5 18 00 FF FF FF FF F4 D1 64 0D C0 34 4B 02 \.........d..4K.
0018F470: EA D1 66 02 34 FB DE 2C 88 00 40 07 01 00 00 00 ..f.4..,..@.....
0018F480: 34 FB DE 2C 35 4F 30 41 70 75 57 2B E2 34 4B 02 4..,5O0ApuW+.4K.
0018F490: 34 FB DE 2C 01 00 00 00 D7 82 5C 02 AC 38 B3 02 4..,......\..8..
0018F4A0: 08 F5 18 00 B8 D1 65 02 D3 A9 10 00 35 4F 30 41 ......e.....5O0A
0018F4B0: 35 4F 30 41 9C D1 65 02 38 AD 93 10 18 C0 92 06 5O0A..e.8.......
0018F4C0: 08 00 00 00 AB 39 1B 47 88 00 40 07 64 63 73 77 [email protected]
0018F4D0: BF 18 67 02 0B CA 17 01 D6 B7 65 02 18 C0 92 06 ..g.......e.....
0018F4E0: 10 F5 18 00 93 A0 65 02 90 1E 9B 6F 00 00 00 00 ......e....o....
0018F4F0: 10 F5 18 00 38 F5 18 00 28 E6 A2 02 00 00 00 00 ....8...(.......
0018F500: D3 A9 10 00 35 4F 30 41 50 AD 93 10 C8 31 8B 1D ....5O0AP....1..
0018F510: 10 00 00 00 50 AD 93 10 97 3C 03 15 10 1E 93 10 ....P....<......
0018F520: 50 AD 93 10 FF FF FF 7F A0 00 7E 07 50 7A 2C 07 P.........~.Pz,.
0018F530: F4 CD 64 02 10 1E 93 10 50 AD 93 10 08 00 00 00 ..d.....P.......
0018F540: 00 F5 18 00 14 7A 2C 07 90 00 F7 0F 04 00 00 00 .....z,.........
0018F550: 01 00 00 00 A0 82 5C 02 20 1F 9B 6F 04 00 00 00 ......\. ..o....
0018F560: AE EF 65 02 38 AD 93 10 10 1F 9B 6F 00 00 00 00 ..e.8......o....
0018F570: 18 C0 92 06 00 00 00 00 3C C0 92 06 00 00 0B 44 ........<......D
0018F580: 15 40 34 43 00 00 00 00 01 00 00 00 6A 00 00 00 [email protected]...
0018F590: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 8B 44 ...............D
0018F5A0: 00 04 00 00 00 00 00 3F B8 58 DF 2B 00 00 0B 44 .......?.X.+...D
0018F5B0: 18 C0 92 06 E4 F5 18 00 93 A0 65 02 BC 1F 9B 6F ..........e....o
0018F5C0: 00 00 00 00 E4 F5 18 00 0C F6 18 00 28 E6 A2 02 ............(...
0018F5D0: 00 00 00 00 32 E8 65 02 A0 1F 9B 6F 00 00 00 00 ....2.e....o....
0018F5E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0018F5F0: 00 00 00 00 01 00 00 00 01 00 00 00 E2 46 0B 00 .............F..
0018F600: 00 00 00 00 30 F7 18 00 A8 E8 A2 02 FF FF FF FF ....0...........
0018F610: 03 FC 65 02 C8 1A E9 13 BC F6 18 00 E0 93 04 00 ..e.............
0018F620: 00 00 00 00 81 07 00 00 18 C0 92 06 CC 00 A9 0D ................
0018F630: C0 00 A9 0D D4 B6 64 02 C8 1A E9 13 00 00 00 00 ......d.........
0018F640: BC F6 18 00 E0 93 04 00 00 00 00 00 00 00 00 00 ................
0018F650: BC F6 18 00 64 5A FA 2D 96 83 5A 02 00 00 00 00 ....dZ.-..Z.....
0018F660: BC F6 18 00 E0 93 04 00 00 00 00 00 00 00 00 00 ................
0018F670: 00 00 00 00 BC 3C E8 2B 00 00 00 00 A4 D1 AE 0D .....<.+........
0018F680: C4 A8 5B 02 81 07 00 00 BC F6 18 00 64 5A FA 2D ..[.........dZ.-
0018F690: 00 00 00 00 00 00 00 00 14 5A FA 2D 55 58 64 02 .........Z.-UXd.
0018F6A0: BC F6 18 00 64 5A FA 2D 00 00 00 00 00 00 00 00 ....dZ.-........
0018F6B0: 14 5A FA 2D 64 5A FA 2D 14 5A FA 2D 00 00 00 00 .Z.-dZ.-.Z.-....
0018F6C0: F6 73 64 02 64 5A FA 2D 00 00 00 00 14 5A FA 2D .sd.dZ.-.....Z.-
0018F6D0: 14 5A FA 2D 60 D8 73 25 38 5A FA 2D 00 00 00 00 .Z.-`.s%8Z.-....
0018F6E0: 60 D8 73 25 38 5A FA 2D 14 5A FA 2D 8F A5 05 D2 `.s%8Z.-.Z.-....
0018F6F0: 33 50 64 02 72 50 64 02 00 00 00 00 14 5A FA 2D 3Pd.rPd......Z.-
0018F700: 38 5A FA 2D 60 D8 73 25 82 7F 64 02 6C 1D 9B 6F 8Z.-`.s%..d.l..o
0018F710: FF FF FF FF 60 4E 59 26 64 3C BE 2C 88 00 40 07 ....`NY&d<.,..@.
0018F720: 24 4E 59 26 64 3C BE 2C 88 00 40 07 14 5A FA 2D $NY&d<.,[email protected]
0018F730: 90 F7 18 00 51 DE A2 02 FF FF FF FF 64 82 64 02 ....Q.......d.d.
0018F740: 60 4E 59 26 9B B1 A6 D9 00 00 00 00 2C 1D 9B 6F `NY&........,..o
0018F750: 24 4E 59 26 24 4E 59 26 D4 20 79 34 14 5A FA 2D $NY&$NY&. y4.Z.-
0018F760: 78 65 74 2B 6C 67 61 2B 78 65 74 2B 00 00 00 00 xet+lga+xet+....
0018F770: 9C E2 6D 0D 0C 72 CB 02 00 00 00 00 00 00 00 00 ..m..r..........
0018F780: 00 00 00 00 00 00 00 00 FF FF FF FF FF FF FF FF ................
0018F790: FC F7 18 00 A8 DE A2 02 00 00 00 00 CB 82 64 02 ..............d.
0018F7A0: 00 00 00 00 B4 27 74 0D 36 84 64 02 D4 92 9E 2C .....'t.6.d....,
0018F7B0: D4 92 9E 2C 4C 73 33 2C 5C CC 3C 2C FD A6 82 02 ...,Ls3,\.<,....
0018F7C0: B0 00 A2 03 B4 1D 9B 6F 64 3C BE 2C 64 3C BE 2C .......od<.,d<.,
0018F7D0: 88 3C BE 2C B4 27 74 0D 00 00 00 00 02 00 00 00 .<.,.'t.........
0018F7E0: 5C CC 3C 2C EC F7 18 00 D4 92 9E 2C D4 92 9E 2C \.<,.......,...,
0018F7F0: D4 20 79 34 00 00 00 00 B8 01 00 00 84 F8 18 00 . y4............
0018F800: 88 0A A4 02 00 00 00 00 D0 A7 82 02 34 02 08 00 ............4...
Warcraft III (build 6401)
Exe: e:\warcraft 3\warcraft iii\war3.exe
Time: Sep 29, 2014 8:14:39.566 PM
User: User
Computer: USER-PC
This application has encountered a critical error:
Program: e:\warcraft 3\warcraft iii\war3.exe
Exception: 0xC0000005 (ACCESS_VIOLATION) at 0023:6F4790C1
The instruction at '0x6F4790C1' referenced memory at '0x0000000C'.
The memory could not be 'read'.
Played Maps\Scenario\Sunken City v1.8.6..w3x
Player 0 SpasMaster Race Orc StartLoc 1
Player 1 hf. Race Orc StartLoc 0
Player 2 Vunjo Race Orc StartLoc 2
Player 3 The Horde Race Orc StartLoc 3
Player 4 <Unused> Race Human StartLoc -1
Player 5 <Unused> Race Undead StartLoc -1
Player 6 <Unused> Race NightElf StartLoc -1
Player 7 <Unused> Race Human StartLoc -1
Player 8 <Unused> Race Orc StartLoc -1
Player 9 <Unused> Race NightElf StartLoc -1
Player 10 <Unused> Race Human StartLoc -1
Player 11 Temple Habitants Race Undead StartLoc 3
x86 Registers
EAX=0018F7E4 EBX=00000001 ECX=00000000 EDX=0018F7E4 ESI=07A08EEC
EDI=00000005 EBP=00000005 ESP=0018F7D4 EIP=6F4790C1 FLG=00210246
CS =0023 DS =002B ES =002B SS =002B FS =0053 GS =002B
Stack Trace (Manual)
Address Frame Logical addr Module
6F4790C1 00000005 0001:004780C1 e:\warcraft 3\warcraft iii\Game.dll
Stack Trace (Using DBGHELP.DLL)
6F4790C1 Game.dll GameMain+4651121 (0x0018F7E4,0x07A08EEC,0x3F800000,0x6F3C725C)
Loaded Modules
0x00400000 - 0x0047D000 e:\warcraft 3\warcraft iii\war3.exe
0x02CD0000 - 0x02CD6000 C:\Windows\system32\SensApi.dll
0x03CC0000 - 0x04B2F000 C:\Windows\system32\nvd3dum.dll
0x05020000 - 0x0512A000 C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPI.dll
0x07D40000 - 0x07D79000 C:\Windows\System32\MMDevApi.dll
0x10000000 - 0x10175000 C:\Users\User\AppData\Local\Temp\{473b5f2d-3207-42b1-a305-387a0c7a1b17}\GameRanger.dll
0x15000000 - 0x15061000 e:\warcraft 3\warcraft iii\Storm.dll
0x21100000 - 0x2115F000 e:\warcraft 3\warcraft iii\mss32.dll
0x22600000 - 0x22616000 e:\warcraft 3\warcraft iii\redist\miles\Mssfast.m3d
0x22700000 - 0x22717000 e:\warcraft 3\warcraft iii\redist\miles\Mssdolby.m3d
0x22C00000 - 0x22C18000 e:\warcraft 3\warcraft iii\redist\miles\Msseax2.m3d
0x24600000 - 0x24611000 e:\warcraft 3\warcraft iii\redist\miles\Reverb3.flt
0x26F00000 - 0x26F2A000 e:\warcraft 3\warcraft iii\redist\miles\Mp3dec.asi
0x60000000 - 0x6005D000 e:\warcraft 3\warcraft iii\ijl15.dll
0x67220000 - 0x67325000 C:\Windows\system32\d3d8.dll
0x67330000 - 0x673F8000 C:\Windows\system32\OPENGL32.dll
0x676D0000 - 0x676F2000 C:\Windows\system32\GLU32.dll
0x67C00000 - 0x67E83000 C:\Windows\system32\nvapi.dll
0x6CB80000 - 0x6CC6B000 C:\Windows\system32\dbghelp.dll
0x6D730000 - 0x6D766000 C:\Windows\system32\AUDIOSES.DLL
0x6DB50000 - 0x6DB56000 C:\Windows\system32\DCIMAN32.dll
0x6DB60000 - 0x6DBD2000 C:\Windows\system32\DSOUND.DLL
0x6DBE0000 - 0x6DCC7000 C:\Windows\system32\DDRAW.dll
0x6EA60000 - 0x6EAFB000 C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll
0x6F000000 - 0x6FBB5000 e:\warcraft 3\warcraft iii\Game.dll
0x70950000 - 0x7096C000 C:\Windows\system32\cryptnet.dll
0x71D10000 - 0x71D26000 C:\Windows\system32\GPAPI.dll
0x728C0000 - 0x728FD000 C:\Windows\SysWOW64\bcryptprimitives.dll
0x72CC0000 - 0x72CE5000 C:\Windows\system32\powrprof.dll
0x72D20000 - 0x72D37000 C:\Windows\system32\bcrypt.dll
0x73370000 - 0x733A8000 C:\Windows\system32\ncrypt.dll
0x73550000 - 0x7358C000 C:\Windows\system32\mswsock.dll
0x73950000 - 0x73A45000 C:\Windows\System32\PROPSYS.dll
0x73BE0000 - 0x73BE6000 C:\Windows\system32\d3d8thk.dll
0x73C80000 - 0x73C87000 C:\Windows\system32\WSOCK32.dll
0x73CA0000 - 0x73CA7000 C:\Windows\system32\avrt.dll
0x73CC0000 - 0x73CC5000 C:\Windows\System32\wshtcpip.dll
0x73D70000 - 0x73D91000 C:\Windows\system32\ntmarta.dll
0x73E00000 - 0x73E84000 C:\Windows\WinSxS\\COMCTL32.dll
0x73F10000 - 0x73F23000 C:\Windows\system32\dwmapi.dll
0x74130000 - 0x74162000 C:\Windows\system32\WINMM.dll
0x74370000 - 0x743AB000 C:\Windows\system32\rsaenh.dll
0x743B0000 - 0x74430000 C:\Windows\system32\uxtheme.dll
0x74450000 - 0x74466000 C:\Windows\system32\CRYPTSP.dll
0x74890000 - 0x74899000 C:\Windows\system32\VERSION.dll
0x74EF0000 - 0x74EFC000 C:\Windows\syswow64\CRYPTBASE.dll
0x74F00000 - 0x74F60000 C:\Windows\syswow64\SspiCli.dll
0x74FF0000 - 0x74FF4000 C:\Windows\syswow64\api-ms-win-downlevel-user32-l1-1-0.dll
0x75000000 - 0x750CC000 C:\Windows\syswow64\MSCTF.dll
0x750D0000 - 0x750DA000 C:\Windows\syswow64\LPK.dll
0x750E0000 - 0x750E5000 C:\Windows\syswow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
0x750F0000 - 0x75117000 C:\Windows\syswow64\CFGMGR32.dll
0x75120000 - 0x75124000 C:\Windows\syswow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
0x75130000 - 0x75177000 C:\Windows\syswow64\KERNELBASE.dll
0x75180000 - 0x751C5000 C:\Windows\syswow64\WLDAP32.dll
0x751D0000 - 0x751D3000 C:\Windows\syswow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
0x751E0000 - 0x7528C000 C:\Windows\syswow64\msvcrt.dll
0x75290000 - 0x752A7000 C:\Windows\syswow64\USERENV.dll
0x752B0000 - 0x752B3000 C:\Windows\syswow64\normaliz.DLL
0x752C0000 - 0x753E0000 C:\Windows\syswow64\CRYPT32.dll
0x753E0000 - 0x754F0000 C:\Windows\syswow64\kernel32.dll
0x754F0000 - 0x75550000 C:\Windows\syswow64\IMM32.dll
0x75550000 - 0x75555000 C:\Windows\syswow64\PSAPI.DLL
0x75560000 - 0x755FD000 C:\Windows\syswow64\USP10.dll
0x75600000 - 0x75700000 C:\Windows\syswow64\USER32.dll
0x75830000 - 0x75834000 C:\Windows\syswow64\api-ms-win-downlevel-version-l1-1-0.dll
0x75840000 - 0x758C3000 C:\Windows\syswow64\CLBCatQ.DLL
0x758D0000 - 0x75A6D000 C:\Windows\syswow64\SETUPAPI.dll
0x75AA0000 - 0x75B1B000 C:\Windows\syswow64\comdlg32.dll
0x75B20000 - 0x75C7C000 C:\Windows\syswow64\ole32.dll
0x75C80000 - 0x75CAB000 C:\Windows\syswow64\IMAGEHLP.dll
0x75CB0000 - 0x75D50000 C:\Windows\syswow64\ADVAPI32.dll
0x75D50000 - 0x75DA7000 C:\Windows\syswow64\SHLWAPI.dll
0x75E10000 - 0x75FD2000 C:\Windows\syswow64\WININET.dll
0x75FE0000 - 0x76C2A000 C:\Windows\syswow64\SHELL32.dll
0x76C30000 - 0x76D20000 C:\Windows\syswow64\RPCRT4.dll
0x76D20000 - 0x76D55000 C:\Windows\syswow64\WS2_32.dll
0x76D70000 - 0x76D89000 C:\Windows\SysWOW64\sechost.dll
0x76D90000 - 0x76D96000 C:\Windows\syswow64\NSI.dll
0x76DA0000 - 0x76E2F000 C:\Windows\syswow64\OLEAUT32.dll
0x76E30000 - 0x76EC0000 C:\Windows\syswow64\GDI32.dll
0x76EC0000 - 0x76ECB000 C:\Windows\syswow64\profapi.dll
0x76ED0000 - 0x770EB000 C:\Windows\syswow64\iertutil.dll
0x770F0000 - 0x77102000 C:\Windows\syswow64\DEVOBJ.dll
0x774E0000 - 0x774EC000 C:\Windows\syswow64\MSASN1.dll
0x77510000 - 0x77690000 C:\Windows\SysWOW64\ntdll.dll
Memory Dump
Code: 16 bytes starting at (EIP = 6F4790C1)
6F4790C1: 8B 51 0C 8B 49 08 56 57 E8 62 69 BC FF 8B 7C 24|$
Stack: 1024 bytes starting at (ESP = 0018F7D4)
* = addr ** *
0018F7D0: EC 8E A0 07 00 00 00 00 8F 31 04 6F E4 F7 18 00 .........1.o....
0018F7E0: EC 8E A0 07 00 00 80 3F 5C 72 3C 6F FF FF FF FF .......?\r<o....
0018F7F0: 74 F8 18 00 C4 F8 18 00 C5 7B 94 6F B8 D1 45 6F t........{.o..Eo
0018F800: C9 AF 10 00 49 4F 30 41 05 00 00 00 A4 D1 45 6F ....IO0A......Eo
0018F810: 16 EA 44 6F C8 E4 17 31 05 00 00 00 9C D1 45 6F ..Do...1......Eo
0018F820: C8 E4 17 31 38 29 CA 39 08 00 00 00 00 00 96 43 ...18).9.......C
0018F830: 04 F9 18 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0018F840: D6 B7 45 6F 38 29 CA 39 78 F8 18 00 93 A0 45 6F ..Eo8).9x.....Eo
0018F850: 0A C4 1C 09 00 00 00 00 78 F8 18 00 A0 F8 18 00 ........x.......
0018F860: 28 E6 82 6F 00 00 00 00 C9 AF 10 00 49 4F 30 41 (..o........IO0A
0018F870: 05 00 00 00 00 00 00 00 48 F9 A7 6F FE FF FF FF ........H..o....
0018F880: 02 00 00 00 E0 01 BC 35 A8 E3 17 31 32 6B CB B2 .......5...12k..
0018F890: F7 41 45 6F A8 63 B6 35 00 00 00 00 00 00 00 00 .AEo.c.5........
0018F8A0: 00 00 00 00 0C 00 00 00 68 F8 18 00 C4 7E 96 02 ........h....~..
0018F8B0: 50 01 BC 35 FE FF FF FF 01 00 00 00 B0 71 3C 6F P..5.........q<o
0018F8C0: 9A C4 1C 09 04 00 00 00 AE EF 45 6F C8 E4 17 31 ..........Eo...1
0018F8D0: 8A C4 1C 09 00 00 00 00 38 29 CA 39 00 00 00 00 ........8).9....
0018F8E0: 5C 29 CA 39 00 00 80 3F CC BC CD 44 00 00 00 00 \).9...?...D....
0018F8F0: 04 00 00 00 8B 00 00 00 00 00 00 00 00 00 00 00 ................
0018F900: 00 00 00 00 48 5D 02 15 00 04 00 00 E2 5D 02 15 ....H].......]..
0018F910: 80 00 F8 38 D6 B7 45 6F 38 29 CA 39 4C F9 18 00 ...8..Eo8).9L...
0018F920: 93 A0 45 6F 76 C5 1C 09 00 00 00 00 4C F9 18 00 ..Eov.......L...
0018F930: 74 F9 18 00 28 E6 82 6F 00 00 00 00 32 E8 45 6F t...(..o....2.Eo
0018F940: 1A C5 1C 09 00 00 00 00 00 00 00 00 00 00 00 00 ................
0018F950: 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 ................
0018F960: 01 00 00 00 E0 AA 0A 00 00 00 00 00 98 FA 18 00 ................
0018F970: A8 E8 82 6F FF FF FF FF 03 FC 45 6F C8 AA 3C 35 ...o......Eo..<5
0018F980: 24 FA 18 00 E0 93 04 00 00 00 00 00 45 07 00 00 $...........E...
0018F990: 38 29 CA 39 B4 00 2D 07 A8 00 2D 07 D4 B6 44 6F 8).9..-...-...Do
0018F9A0: C8 AA 3C 35 00 00 00 00 24 FA 18 00 E0 93 04 00 ..<5....$.......
0018F9B0: 00 00 00 00 00 00 00 00 24 FA 18 00 34 5B E8 3A ........$...4[.:
0018F9C0: 96 83 3A 6F 00 00 00 00 24 FA 18 00 E0 93 04 00 ..
0018F9D0: 00 00 00 00 00 00 00 00 00 00 00 00 E4 3C 6D 22 .............<m"
0018F9E0: 00 00 00 00 AC C8 EA 0D C4 A8 3B 6F 45 07 00 00 ..........;oE...
0018F9F0: 24 FA 18 00 34 5B E8 3A 00 00 00 00 00 00 00 00 $...4[.:........
0018FA00: E4 5A E8 3A 55 58 44 6F 24 FA 18 00 34 5B E8 3A .Z.:UXDo$...4[.:
0018FA10: 00 00 00 00 00 00 00 00 E4 5A E8 3A 34 5B E8 3A .........Z.:4[.:
0018FA20: E4 5A E8 3A 00 00 00 00 F6 73 44 6F 34 5B E8 3A .Z.:.....sDo4[.:
0018FA30: 00 00 00 00 E4 5A E8 3A E4 5A E8 3A B0 D3 31 25 .....Z.:.Z.:..1%
0018FA40: 08 5B E8 3A 00 00 00 00 B0 D3 31 25 08 5B E8 3A .[.:......1%.[.:
0018FA50: E4 5A E8 3A BF A4 17 C5 33 50 44 6F 72 50 44 6F .Z.:....3PDorPDo
0018FA60: 00 00 00 00 E4 5A E8 3A 08 5B E8 3A B0 D3 31 25 .....Z.:.[.:..1%
0018FA70: 82 7F 44 6F 26 C6 1C 09 FF FF FF FF C4 11 6C 22 ..Do&.........l"
0018FA80: 00 00 00 00 88 00 53 07 88 11 6C 22 00 00 00 00 ......S...l"....
0018FA90: 88 00 53 07 E4 5A E8 3A F8 FA 18 00 51 DE 82 6F ..S..Z.:....Q..o
0018FAA0: FF FF FF FF 64 82 44 6F C4 11 6C 22 37 EE 93 DD ....d.Do..l"7...
0018FAB0: 00 00 00 00 E6 C6 1C 09 88 11 6C 22 88 11 6C 22 ..........l"..l"
0018FAC0: 00 00 00 00 E4 5A E8 3A 78 65 74 2B 6C 67 61 2B .....Z.:xet+lga+
0018FAD0: 78 65 74 2B 00 00 00 00 9C E2 12 22 0C 72 AB 6F xet+.......".r.o
0018FAE0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0018FAF0: FF FF FF FF FF FF FF FF 44 FB 18 00 A8 DE 82 6F ........D......o
0018FB00: 00 00 00 00 CB 82 44 6F 00 00 00 00 B4 27 B0 0D ......Do.....'..
0018FB10: 36 84 44 6F E8 01 B2 22 88 00 53 07 04 02 08 00 6.Do..."..S.....
0018FB20: 88 11 6C 22 C1 81 47 6F A0 3D A8 6F 6E C7 1C 09 ..l"..Go.=.on...
0018FB30: AC DF 4B 43 54 98 5C 24 F4 13 72 0A D0 00 34 03 ..KCT.\$..r...4.
0018FB40: 88 11 6C 22 E4 FB 18 00 B8 F9 82 6F 00 00 00 00 ..l".......o....
0018FB50: 38 D5 46 6F 54 98 5C 24 88 00 34 03 B4 E3 46 6F 8.FoT.\$..4...Fo
0018FB60: C8 00 34 03 88 00 34 03 AC DF 4B 43 61 E5 46 6F ..4...4...KCa.Fo
0018FB70: B8 00 63 07 2C 01 70 0A 6C FC 18 00 AC DF 4B 43 ..c.,.p.l.....KC
0018FB80: 00 00 80 3F 00 00 00 00 DB E9 46 6F 8E 0C 47 6F ...?......Fo..Go
0018FB90: 6C FC 18 00 D4 87 2D 2B F4 13 72 0A 58 49 2F 6F l.....-+..r.XI/o
0018FBA0: BE 75 53 6F FD A6 62 6F 58 FC 18 00 EE C7 1C 09 .uSo..boX.......
0018FBB0: 58 FC 18 00 BC 00 62 09 05 00 00 00 00 00 00 00 X.....b.........
0018FBC0: 00 00 00 00 42 00 00 00 D4 87 2D 2B 74 22 39 2F ....B.....-+t"9/
0018FBD0: 74 17 39 2F 74 17 39 2F 29 E6 7A 6F 00 00 00 00 t.9/t.9/).zo....
