crashing with violation in module ntdll.dll
Posted: 11.03.2015, 03:45
Hi,
since a fresh install of Win7 (64 Bit), my FreeCommander crashes regularly, sometimes after some file action, sometimes even after hours of idle without having anything done with it.
I did a clean re-install, and a "sfc scannow". All is ok...
Any hints?
Thx,
Dietmar
exception class : EAccessViolation
exception message : Access violation at address 77DD2685 in module 'ntdll.dll'. Read of address 6B1539B1.
thread $f30:
77dd2685 +84 ntdll.dll
77dd25da +79 ntdll.dll RtlReAllocateHeap
596bfaa1 +15 DUI70.dll ?Register@ClassInfoBase@DirectUI@@QAEJXZ
596c662d +10 DUI70.dll ?Register@HWNDHost@DirectUI@@SGJXZ
596c660c +1b DUI70.dll RegisterBaseControls
596c4b85 +00 DUI70.dll RegisterAllControls
004d068d +0d FreeCommander.exe madExcept CallThreadProcSafe
004d06f7 +37 FreeCommander.exe madExcept ThreadExceptFrame
77213388 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($16e8) at:
758c450f +00 SHLWAPI.dll
main thread ($16e8):
77db0156 +00e ntdll.dll NtWaitForMultipleObjects
75a215f1 +0fa KERNELBASE.dll WaitForMultipleObjectsEx
772119f3 +089 kernel32.dll WaitForMultipleObjectsEx
75930864 +000 USER32.dll MsgWaitForMultipleObjectsEx
75930b64 +01a USER32.dll MsgWaitForMultipleObjects
758cacc4 +037 SHLWAPI.dll #194
758c4587 +013 SHLWAPI.dll SHCreateThread
76499712 +00a shell32.dll SHFileOperationW
0089e272 +08e FreeCommander.exe fcFileOperationController 636 +15 TfcFileOperationController.ShellFileDelete
0089e0ba +176 FreeCommander.exe fcFileOperationController 603 +25 TfcFileOperationController.ShellFileDelete
008a269f +067 FreeCommander.exe fcFileDataSupplierBase 1090 +8 TfcFileDataSupplierBase.Delete
00b03ffe +15a FreeCommander.exe fcController 1983 +24 TfcController.DeleteSelectedItems
00b59c73 +067 FreeCommander.exe FcMain 5410 +6 TFcFormMain.actFileDeletePermanentlyExecute
0048ecef +00f FreeCommander.exe System.Classes TBasicAction.Execute
0050abb1 +031 FreeCommander.exe Vcl.ActnList TContainedAction.Execute
0050b99c +050 FreeCommander.exe Vcl.ActnList TCustomAction.Execute
0050ba35 +005 FreeCommander.exe Vcl.ActnList TCustomAction.HandleShortCut
0050afe7 +08b FreeCommander.exe Vcl.ActnList TCustomActionList.IsShortCut
005ff42f +047 FreeCommander.exe Vcl.Forms DispatchShortCut
005ff4bd +059 FreeCommander.exe Vcl.Forms TCustomForm.IsShortCut
0052df3c +068 FreeCommander.exe Vcl.Controls TWinControl.IsMenuKey
0052df89 +01d FreeCommander.exe Vcl.Controls TWinControl.CNKeyDown
00527171 +2bd FreeCommander.exe Vcl.Controls TControl.WndProc
0052bacf +5b3 FreeCommander.exe Vcl.Controls TWinControl.WndProc
00580b8a +0a2 FreeCommander.exe Vcl.ComCtrls TCustomListView.WndProc
0052b124 +02c FreeCommander.exe Vcl.Controls TWinControl.MainWndProc
0048f9e4 +014 FreeCommander.exe System.Classes StdWndProc
77da0107 +02b ntdll.dll KiUserCallbackDispatcher
77213388 +010 kernel32.dll BaseThreadInitThunk
thread $18ac:
77db0156 +0e ntdll.dll NtWaitForMultipleObjects
77213388 +10 kernel32.dll BaseThreadInitThunk
thread $14ec:
77dafd8a +0e ntdll.dll NtDelayExecution
75a23bcf +5f KERNELBASE.dll SleepEx
75a244a0 +0a KERNELBASE.dll Sleep
004d068d +0d FreeCommander.exe madExcept CallThreadProcSafe
004d06f7 +37 FreeCommander.exe madExcept ThreadExceptFrame
77213388 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($16e8) at:
6cecba5c +00 Boxcryptor.Ext.dll
thread $1ce0 (TWorkerThread):
77db0156 +0e ntdll.dll NtWaitForMultipleObjects
75a215f1 +fa KERNELBASE.dll WaitForMultipleObjectsEx
772119f3 +89 kernel32.dll WaitForMultipleObjectsEx
772141fb +13 kernel32.dll WaitForMultipleObjects
008baafe +2e FreeCommander.exe csWorkerThreadPool 433 +5 TWorkerThreadJobLists.WaitForNextJob
008bac93 +13 FreeCommander.exe csWorkerThreadPool 521 +3 TWorkerThread.Execute
004d07ab +2b FreeCommander.exe madExcept HookedTThreadExecute
0048c95a +42 FreeCommander.exe System.Classes ThreadProc
00408890 +28 FreeCommander.exe System 24 +0 ThreadWrapper
004d068d +0d FreeCommander.exe madExcept CallThreadProcSafe
004d06f7 +37 FreeCommander.exe madExcept ThreadExceptFrame
77213388 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($16e8) at:
008babee +1e FreeCommander.exe csWorkerThreadPool 465 +1 TWorkerThread.Create
thread $1ce4 (TWorkerThread):
77db0156 +0e ntdll.dll NtWaitForMultipleObjects
75a215f1 +fa KERNELBASE.dll WaitForMultipleObjectsEx
772119f3 +89 kernel32.dll WaitForMultipleObjectsEx
772141fb +13 kernel32.dll WaitForMultipleObjects
008baafe +2e FreeCommander.exe csWorkerThreadPool 433 +5 TWorkerThreadJobLists.WaitForNextJob
008bac93 +13 FreeCommander.exe csWorkerThreadPool 521 +3 TWorkerThread.Execute
004d07ab +2b FreeCommander.exe madExcept HookedTThreadExecute
0048c95a +42 FreeCommander.exe System.Classes ThreadProc
00408890 +28 FreeCommander.exe System 24 +0 ThreadWrapper
004d068d +0d FreeCommander.exe madExcept CallThreadProcSafe
004d06f7 +37 FreeCommander.exe madExcept ThreadExceptFrame
77213388 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($16e8) at:
008babee +1e FreeCommander.exe csWorkerThreadPool 465 +1 TWorkerThread.Create
thread $1ce8 (TWorkerThread):
77db0156 +0e ntdll.dll NtWaitForMultipleObjects
75a215f1 +fa KERNELBASE.dll WaitForMultipleObjectsEx
772119f3 +89 kernel32.dll WaitForMultipleObjectsEx
772141fb +13 kernel32.dll WaitForMultipleObjects
008baafe +2e FreeCommander.exe csWorkerThreadPool 433 +5 TWorkerThreadJobLists.WaitForNextJob
008bac93 +13 FreeCommander.exe csWorkerThreadPool 521 +3 TWorkerThread.Execute
004d07ab +2b FreeCommander.exe madExcept HookedTThreadExecute
0048c95a +42 FreeCommander.exe System.Classes ThreadProc
00408890 +28 FreeCommander.exe System 24 +0 ThreadWrapper
004d068d +0d FreeCommander.exe madExcept CallThreadProcSafe
004d06f7 +37 FreeCommander.exe madExcept ThreadExceptFrame
77213388 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($16e8) at:
008babee +1e FreeCommander.exe csWorkerThreadPool 465 +1 TWorkerThread.Create
thread $1cec (TWorkerThread):
77db0156 +0e ntdll.dll NtWaitForMultipleObjects
75a215f1 +fa KERNELBASE.dll WaitForMultipleObjectsEx
772119f3 +89 kernel32.dll WaitForMultipleObjectsEx
772141fb +13 kernel32.dll WaitForMultipleObjects
008baafe +2e FreeCommander.exe csWorkerThreadPool 433 +5 TWorkerThreadJobLists.WaitForNextJob
008bac93 +13 FreeCommander.exe csWorkerThreadPool 521 +3 TWorkerThread.Execute
004d07ab +2b FreeCommander.exe madExcept HookedTThreadExecute
0048c95a +42 FreeCommander.exe System.Classes ThreadProc
00408890 +28 FreeCommander.exe System 24 +0 ThreadWrapper
004d068d +0d FreeCommander.exe madExcept CallThreadProcSafe
004d06f7 +37 FreeCommander.exe madExcept ThreadExceptFrame
77213388 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($16e8) at:
008babee +1e FreeCommander.exe csWorkerThreadPool 465 +1 TWorkerThread.Create
thread $1240:
77db1f3f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
77213388 +10 kernel32.dll BaseThreadInitThunk
thread $13f0:
77dafd8a +0e ntdll.dll NtDelayExecution
75a23bcf +5f KERNELBASE.dll SleepEx
75a244a0 +0a KERNELBASE.dll Sleep
004d068d +0d FreeCommander.exe madExcept CallThreadProcSafe
004d06f7 +37 FreeCommander.exe madExcept ThreadExceptFrame
77213388 +10 kernel32.dll BaseThreadInitThunk
>> created by thread $20bc at:
770cda8e +00 ole32.dll
thread $1e78 (TRzChangeHandlerThread):
77db0156 +0e ntdll.dll NtWaitForMultipleObjects
75a215f1 +fa KERNELBASE.dll WaitForMultipleObjectsEx
772119f3 +89 kernel32.dll WaitForMultipleObjectsEx
772141fb +13 kernel32.dll WaitForMultipleObjects
006e8dc5 +6d FreeCommander.exe RzShellCtrls 3856 +11 TRzChangeHandlerThread.Execute
004d07ab +2b FreeCommander.exe madExcept HookedTThreadExecute
0048c95a +42 FreeCommander.exe System.Classes ThreadProc
00408890 +28 FreeCommander.exe System 24 +0 ThreadWrapper
004d068d +0d FreeCommander.exe madExcept CallThreadProcSafe
004d06f7 +37 FreeCommander.exe madExcept ThreadExceptFrame
77213388 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($16e8) at:
006e8a8e +1e FreeCommander.exe RzShellCtrls 3742 +4 TRzChangeHandlerThread.Create
thread $2174:
77db1f3f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
77213388 +10 kernel32.dll BaseThreadInitThunk
thread $20bc:
77db1f3f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
77213388 +10 kernel32.dll BaseThreadInitThunk
thread $1ea4:
77db1f3f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
77213388 +10 kernel32.dll BaseThreadInitThunk
thread $1080:
77db1f3f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
77213388 +10 kernel32.dll BaseThreadInitThunk
stack dump:
08ebfc28 63 f7 04 7f 00 00 f2 00 - 38 00 00 00 18 1a ec 04 c.......8.......
08ebfc38 4c fc eb 08 00 00 00 00 - 34 fc eb 08 00 00 00 00 L.......4.......
08ebfc48 70 77 f4 00 43 00 3a 00 - 5c 00 57 00 69 00 6e 00 pw..C.:.\.W.i.n.
08ebfc58 64 00 6f 00 77 00 73 00 - 5c 00 57 00 69 00 6e 00 d.o.w.s.\.W.i.n.
08ebfc68 53 00 78 00 53 00 5c 00 - 78 00 38 00 36 00 5f 00 S.x.S.\.x.8.6._.
08ebfc78 6d 00 69 00 63 00 72 00 - 8c e3 db 77 47 f7 04 7f m.i.c.r....wG...
08ebfc88 0e 00 07 80 a4 01 f2 00 - 00 00 f2 00 99 01 dc 77 ...............w
08ebfc98 8a fd eb 08 0d 00 88 1d - ab 02 00 00 67 f7 04 7f ............g...
08ebfca8 38 fd eb 08 16 00 00 00 - 8c e3 db 77 0e 00 00 00 8..........w....
08ebfcb8 ab 02 00 00 b4 01 f2 00 - 00 00 f2 00 e0 8d f2 00 ................
08ebfcc8 b2 04 00 00 12 00 00 00 - 00 00 00 00 00 00 00 00 ................
08ebfcd8 20 1e ec 04 d0 8a f2 00 - 00 00 f2 00 18 1a ec 04 ...............
08ebfce8 30 8f f2 00 00 00 00 00 - 84 fc eb 08 e0 8d f2 00 0...............
08ebfcf8 60 ff eb 08 f5 71 e0 77 - 37 d8 34 00 10 1a ec 04 `....q.w7.4.....
08ebfd08 8c e3 db 00 00 00 f2 00 - 02 00 00 00 28 fc eb 08 ............(...
08ebfd18 f0 f7 eb 08 60 ff eb 08 - f5 71 e0 77 df c7 34 00 ....`....q.w..4.
08ebfd28 fe ff ff ff a0 fd eb 08 - df 25 dd 77 18 1a ec 04 .........%.w....
08ebfd38 38 00 00 00 07 00 00 00 - c8 01 ec 04 18 1a ec 04 8...............
08ebfd48 00 00 00 00 08 0d ff 00 - c9 2c dc 77 08 0d ff 00 .........,.w....
08ebfd58 00 00 00 00 08 00 00 00 - 44 fe eb 08 00 00 00 00 ........D.......
disassembling:
[...]
77dd2676 shr edx, 3
77dd2679 mov eax, [eax]
77dd267b xor eax, edx
77dd267d xor eax, [$77e900a4]
77dd2683 xor eax, edi
77dd2685 > mov ax, [eax+$10]
77dd2689 movzx esi, ax
77dd268c mov al, [ecx]
77dd268e cmp al, 5
77dd2690 jz loc_77e1dcb2
77dd2696 test al, $40
[...]
since a fresh install of Win7 (64 Bit), my FreeCommander crashes regularly, sometimes after some file action, sometimes even after hours of idle without having anything done with it.
I did a clean re-install, and a "sfc scannow". All is ok...
Any hints?
Thx,
Dietmar
exception class : EAccessViolation
exception message : Access violation at address 77DD2685 in module 'ntdll.dll'. Read of address 6B1539B1.
thread $f30:
77dd2685 +84 ntdll.dll
77dd25da +79 ntdll.dll RtlReAllocateHeap
596bfaa1 +15 DUI70.dll ?Register@ClassInfoBase@DirectUI@@QAEJXZ
596c662d +10 DUI70.dll ?Register@HWNDHost@DirectUI@@SGJXZ
596c660c +1b DUI70.dll RegisterBaseControls
596c4b85 +00 DUI70.dll RegisterAllControls
004d068d +0d FreeCommander.exe madExcept CallThreadProcSafe
004d06f7 +37 FreeCommander.exe madExcept ThreadExceptFrame
77213388 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($16e8) at:
758c450f +00 SHLWAPI.dll
main thread ($16e8):
77db0156 +00e ntdll.dll NtWaitForMultipleObjects
75a215f1 +0fa KERNELBASE.dll WaitForMultipleObjectsEx
772119f3 +089 kernel32.dll WaitForMultipleObjectsEx
75930864 +000 USER32.dll MsgWaitForMultipleObjectsEx
75930b64 +01a USER32.dll MsgWaitForMultipleObjects
758cacc4 +037 SHLWAPI.dll #194
758c4587 +013 SHLWAPI.dll SHCreateThread
76499712 +00a shell32.dll SHFileOperationW
0089e272 +08e FreeCommander.exe fcFileOperationController 636 +15 TfcFileOperationController.ShellFileDelete
0089e0ba +176 FreeCommander.exe fcFileOperationController 603 +25 TfcFileOperationController.ShellFileDelete
008a269f +067 FreeCommander.exe fcFileDataSupplierBase 1090 +8 TfcFileDataSupplierBase.Delete
00b03ffe +15a FreeCommander.exe fcController 1983 +24 TfcController.DeleteSelectedItems
00b59c73 +067 FreeCommander.exe FcMain 5410 +6 TFcFormMain.actFileDeletePermanentlyExecute
0048ecef +00f FreeCommander.exe System.Classes TBasicAction.Execute
0050abb1 +031 FreeCommander.exe Vcl.ActnList TContainedAction.Execute
0050b99c +050 FreeCommander.exe Vcl.ActnList TCustomAction.Execute
0050ba35 +005 FreeCommander.exe Vcl.ActnList TCustomAction.HandleShortCut
0050afe7 +08b FreeCommander.exe Vcl.ActnList TCustomActionList.IsShortCut
005ff42f +047 FreeCommander.exe Vcl.Forms DispatchShortCut
005ff4bd +059 FreeCommander.exe Vcl.Forms TCustomForm.IsShortCut
0052df3c +068 FreeCommander.exe Vcl.Controls TWinControl.IsMenuKey
0052df89 +01d FreeCommander.exe Vcl.Controls TWinControl.CNKeyDown
00527171 +2bd FreeCommander.exe Vcl.Controls TControl.WndProc
0052bacf +5b3 FreeCommander.exe Vcl.Controls TWinControl.WndProc
00580b8a +0a2 FreeCommander.exe Vcl.ComCtrls TCustomListView.WndProc
0052b124 +02c FreeCommander.exe Vcl.Controls TWinControl.MainWndProc
0048f9e4 +014 FreeCommander.exe System.Classes StdWndProc
77da0107 +02b ntdll.dll KiUserCallbackDispatcher
77213388 +010 kernel32.dll BaseThreadInitThunk
thread $18ac:
77db0156 +0e ntdll.dll NtWaitForMultipleObjects
77213388 +10 kernel32.dll BaseThreadInitThunk
thread $14ec:
77dafd8a +0e ntdll.dll NtDelayExecution
75a23bcf +5f KERNELBASE.dll SleepEx
75a244a0 +0a KERNELBASE.dll Sleep
004d068d +0d FreeCommander.exe madExcept CallThreadProcSafe
004d06f7 +37 FreeCommander.exe madExcept ThreadExceptFrame
77213388 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($16e8) at:
6cecba5c +00 Boxcryptor.Ext.dll
thread $1ce0 (TWorkerThread):
77db0156 +0e ntdll.dll NtWaitForMultipleObjects
75a215f1 +fa KERNELBASE.dll WaitForMultipleObjectsEx
772119f3 +89 kernel32.dll WaitForMultipleObjectsEx
772141fb +13 kernel32.dll WaitForMultipleObjects
008baafe +2e FreeCommander.exe csWorkerThreadPool 433 +5 TWorkerThreadJobLists.WaitForNextJob
008bac93 +13 FreeCommander.exe csWorkerThreadPool 521 +3 TWorkerThread.Execute
004d07ab +2b FreeCommander.exe madExcept HookedTThreadExecute
0048c95a +42 FreeCommander.exe System.Classes ThreadProc
00408890 +28 FreeCommander.exe System 24 +0 ThreadWrapper
004d068d +0d FreeCommander.exe madExcept CallThreadProcSafe
004d06f7 +37 FreeCommander.exe madExcept ThreadExceptFrame
77213388 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($16e8) at:
008babee +1e FreeCommander.exe csWorkerThreadPool 465 +1 TWorkerThread.Create
thread $1ce4 (TWorkerThread):
77db0156 +0e ntdll.dll NtWaitForMultipleObjects
75a215f1 +fa KERNELBASE.dll WaitForMultipleObjectsEx
772119f3 +89 kernel32.dll WaitForMultipleObjectsEx
772141fb +13 kernel32.dll WaitForMultipleObjects
008baafe +2e FreeCommander.exe csWorkerThreadPool 433 +5 TWorkerThreadJobLists.WaitForNextJob
008bac93 +13 FreeCommander.exe csWorkerThreadPool 521 +3 TWorkerThread.Execute
004d07ab +2b FreeCommander.exe madExcept HookedTThreadExecute
0048c95a +42 FreeCommander.exe System.Classes ThreadProc
00408890 +28 FreeCommander.exe System 24 +0 ThreadWrapper
004d068d +0d FreeCommander.exe madExcept CallThreadProcSafe
004d06f7 +37 FreeCommander.exe madExcept ThreadExceptFrame
77213388 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($16e8) at:
008babee +1e FreeCommander.exe csWorkerThreadPool 465 +1 TWorkerThread.Create
thread $1ce8 (TWorkerThread):
77db0156 +0e ntdll.dll NtWaitForMultipleObjects
75a215f1 +fa KERNELBASE.dll WaitForMultipleObjectsEx
772119f3 +89 kernel32.dll WaitForMultipleObjectsEx
772141fb +13 kernel32.dll WaitForMultipleObjects
008baafe +2e FreeCommander.exe csWorkerThreadPool 433 +5 TWorkerThreadJobLists.WaitForNextJob
008bac93 +13 FreeCommander.exe csWorkerThreadPool 521 +3 TWorkerThread.Execute
004d07ab +2b FreeCommander.exe madExcept HookedTThreadExecute
0048c95a +42 FreeCommander.exe System.Classes ThreadProc
00408890 +28 FreeCommander.exe System 24 +0 ThreadWrapper
004d068d +0d FreeCommander.exe madExcept CallThreadProcSafe
004d06f7 +37 FreeCommander.exe madExcept ThreadExceptFrame
77213388 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($16e8) at:
008babee +1e FreeCommander.exe csWorkerThreadPool 465 +1 TWorkerThread.Create
thread $1cec (TWorkerThread):
77db0156 +0e ntdll.dll NtWaitForMultipleObjects
75a215f1 +fa KERNELBASE.dll WaitForMultipleObjectsEx
772119f3 +89 kernel32.dll WaitForMultipleObjectsEx
772141fb +13 kernel32.dll WaitForMultipleObjects
008baafe +2e FreeCommander.exe csWorkerThreadPool 433 +5 TWorkerThreadJobLists.WaitForNextJob
008bac93 +13 FreeCommander.exe csWorkerThreadPool 521 +3 TWorkerThread.Execute
004d07ab +2b FreeCommander.exe madExcept HookedTThreadExecute
0048c95a +42 FreeCommander.exe System.Classes ThreadProc
00408890 +28 FreeCommander.exe System 24 +0 ThreadWrapper
004d068d +0d FreeCommander.exe madExcept CallThreadProcSafe
004d06f7 +37 FreeCommander.exe madExcept ThreadExceptFrame
77213388 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($16e8) at:
008babee +1e FreeCommander.exe csWorkerThreadPool 465 +1 TWorkerThread.Create
thread $1240:
77db1f3f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
77213388 +10 kernel32.dll BaseThreadInitThunk
thread $13f0:
77dafd8a +0e ntdll.dll NtDelayExecution
75a23bcf +5f KERNELBASE.dll SleepEx
75a244a0 +0a KERNELBASE.dll Sleep
004d068d +0d FreeCommander.exe madExcept CallThreadProcSafe
004d06f7 +37 FreeCommander.exe madExcept ThreadExceptFrame
77213388 +10 kernel32.dll BaseThreadInitThunk
>> created by thread $20bc at:
770cda8e +00 ole32.dll
thread $1e78 (TRzChangeHandlerThread):
77db0156 +0e ntdll.dll NtWaitForMultipleObjects
75a215f1 +fa KERNELBASE.dll WaitForMultipleObjectsEx
772119f3 +89 kernel32.dll WaitForMultipleObjectsEx
772141fb +13 kernel32.dll WaitForMultipleObjects
006e8dc5 +6d FreeCommander.exe RzShellCtrls 3856 +11 TRzChangeHandlerThread.Execute
004d07ab +2b FreeCommander.exe madExcept HookedTThreadExecute
0048c95a +42 FreeCommander.exe System.Classes ThreadProc
00408890 +28 FreeCommander.exe System 24 +0 ThreadWrapper
004d068d +0d FreeCommander.exe madExcept CallThreadProcSafe
004d06f7 +37 FreeCommander.exe madExcept ThreadExceptFrame
77213388 +10 kernel32.dll BaseThreadInitThunk
>> created by main thread ($16e8) at:
006e8a8e +1e FreeCommander.exe RzShellCtrls 3742 +4 TRzChangeHandlerThread.Create
thread $2174:
77db1f3f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
77213388 +10 kernel32.dll BaseThreadInitThunk
thread $20bc:
77db1f3f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
77213388 +10 kernel32.dll BaseThreadInitThunk
thread $1ea4:
77db1f3f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
77213388 +10 kernel32.dll BaseThreadInitThunk
thread $1080:
77db1f3f +0b ntdll.dll NtWaitForWorkViaWorkerFactory
77213388 +10 kernel32.dll BaseThreadInitThunk
stack dump:
08ebfc28 63 f7 04 7f 00 00 f2 00 - 38 00 00 00 18 1a ec 04 c.......8.......
08ebfc38 4c fc eb 08 00 00 00 00 - 34 fc eb 08 00 00 00 00 L.......4.......
08ebfc48 70 77 f4 00 43 00 3a 00 - 5c 00 57 00 69 00 6e 00 pw..C.:.\.W.i.n.
08ebfc58 64 00 6f 00 77 00 73 00 - 5c 00 57 00 69 00 6e 00 d.o.w.s.\.W.i.n.
08ebfc68 53 00 78 00 53 00 5c 00 - 78 00 38 00 36 00 5f 00 S.x.S.\.x.8.6._.
08ebfc78 6d 00 69 00 63 00 72 00 - 8c e3 db 77 47 f7 04 7f m.i.c.r....wG...
08ebfc88 0e 00 07 80 a4 01 f2 00 - 00 00 f2 00 99 01 dc 77 ...............w
08ebfc98 8a fd eb 08 0d 00 88 1d - ab 02 00 00 67 f7 04 7f ............g...
08ebfca8 38 fd eb 08 16 00 00 00 - 8c e3 db 77 0e 00 00 00 8..........w....
08ebfcb8 ab 02 00 00 b4 01 f2 00 - 00 00 f2 00 e0 8d f2 00 ................
08ebfcc8 b2 04 00 00 12 00 00 00 - 00 00 00 00 00 00 00 00 ................
08ebfcd8 20 1e ec 04 d0 8a f2 00 - 00 00 f2 00 18 1a ec 04 ...............
08ebfce8 30 8f f2 00 00 00 00 00 - 84 fc eb 08 e0 8d f2 00 0...............
08ebfcf8 60 ff eb 08 f5 71 e0 77 - 37 d8 34 00 10 1a ec 04 `....q.w7.4.....
08ebfd08 8c e3 db 00 00 00 f2 00 - 02 00 00 00 28 fc eb 08 ............(...
08ebfd18 f0 f7 eb 08 60 ff eb 08 - f5 71 e0 77 df c7 34 00 ....`....q.w..4.
08ebfd28 fe ff ff ff a0 fd eb 08 - df 25 dd 77 18 1a ec 04 .........%.w....
08ebfd38 38 00 00 00 07 00 00 00 - c8 01 ec 04 18 1a ec 04 8...............
08ebfd48 00 00 00 00 08 0d ff 00 - c9 2c dc 77 08 0d ff 00 .........,.w....
08ebfd58 00 00 00 00 08 00 00 00 - 44 fe eb 08 00 00 00 00 ........D.......
disassembling:
[...]
77dd2676 shr edx, 3
77dd2679 mov eax, [eax]
77dd267b xor eax, edx
77dd267d xor eax, [$77e900a4]
77dd2683 xor eax, edi
77dd2685 > mov ax, [eax+$10]
77dd2689 movzx esi, ax
77dd268c mov al, [ecx]
77dd268e cmp al, 5
77dd2690 jz loc_77e1dcb2
77dd2696 test al, $40
[...]