__exception__
April 14, 2023, 6:02 p.m.
stacktrace:
exception.instruction_r:
90 9c 56 68 31 37 93 54 8b 74 24 00 e8 dc e2 b8
exception.instruction:
nop
exception.module:
74134271465999811757.bin
exception.exception_code:
0x80000004
exception.offset:
8320758
exception.address:
0xbef6f6
registers.esp:
1636216
registers.edi:
0
registers.eax:
2947484310
registers.ebp:
1638240
registers.edx:
42
registers.ebx:
4194304
registers.esi:
0
registers.ecx:
1968898048
1
0
0
__exception__
April 14, 2023, 6:02 p.m.
stacktrace:
RtlAllocateHeap+0xac RtlFreeAnsiString-0x54 ntdll+0x2e0d2 @ 0x76f3e0d2
SdbGetTagFromTagID+0x333 SdbReadDWORDTag-0x1ad apphelp+0x3993 @ 0x73143993
SdbReadWORDTag+0x9b SdbCloseLocalDatabase-0x550 apphelp+0x64f9 @ 0x731464f9
SdbGetNthUserSdb+0x3ef SdbFindFirstStringIndexedTag-0x1fd apphelp+0x77e7 @ 0x731477e7
SdbCloseLocalDatabase+0x380 SdbGetNthUserSdb-0x62f apphelp+0x6dc9 @ 0x73146dc9
SdbCloseLocalDatabase+0x857 SdbGetNthUserSdb-0x158 apphelp+0x72a0 @ 0x731472a0
SdbCloseLocalDatabase+0x7ed SdbGetNthUserSdb-0x1c2 apphelp+0x7236 @ 0x73147236
SdbInitDatabaseEx+0xa28 SdbGetFileInfo-0x57b apphelp+0x5064 @ 0x73145064
SdbGetFileInfo+0x1c1 SdbGetIndex-0x3d9 apphelp+0x57a0 @ 0x731457a0
SdbInitDatabaseEx+0x68c SdbGetFileInfo-0x917 apphelp+0x4cc8 @ 0x73144cc8
ApphelpCreateAppcompatData+0x46b ApphelpCheckRunAppEx-0x1f6 apphelp+0x2f2d @ 0x73142f2d
ApphelpCheckRunAppEx+0xa7 SdbGetStringTagPtr-0xdf apphelp+0x31ca @ 0x731431ca
BaseCheckRunApp+0x1e4 SearchPathA-0x1bd kernel32+0x29f9f @ 0x755d9f9f
BaseCheckRunApp+0x46 SearchPathA-0x35b kernel32+0x29e01 @ 0x755d9e01
BasepCheckBadapp+0x1a1 CheckElevationEnabled-0x64 kernel32+0x230fa @ 0x755d30fa
BaseCheckAppcompatCacheEx+0xcdd BasepCheckBadapp-0x16 kernel32+0x22f43 @ 0x755d2f43
CreateProcessInternalW+0x961 BasepFreeAppCompatData-0x7dd kernel32+0x24554 @ 0x755d4554
New_kernel32_CreateProcessInternalW@48+0x185 New_kernel32_CreateRemoteThread@28-0x16b @ 0x736e7747
CreateProcessW+0x2c CreateProcessA-0x9 kernel32+0x11069 @ 0x755c1069
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x755c33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x76f49ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x76f49ea5
exception.instruction_r:
0f b7 06 99 0f a4 c2 10 c1 e0 10 0b f8 0b da 89
exception.symbol:
RtlInitUnicodeString+0xec RtlMultiByteToUnicodeN-0x251 ntdll+0x2e2f4
exception.instruction:
movzx eax, word ptr [esi]
exception.module:
ntdll.dll
exception.exception_code:
0xc0000005
exception.offset:
189172
exception.address:
0x76f3e2f4
registers.esp:
1630796
registers.edi:
49
registers.eax:
15309016
registers.ebp:
1630928
registers.edx:
14974144
registers.ebx:
72
registers.esi:
15309024
registers.ecx:
15041456
1
0
0
__exception__
April 14, 2023, 6:02 p.m.
stacktrace:
RtlAllocateHeap+0xac RtlFreeAnsiString-0x54 ntdll+0x2e0d2 @ 0x76f3e0d2
SdbGetTagFromTagID+0x333 SdbReadDWORDTag-0x1ad apphelp+0x3993 @ 0x73143993
SdbReadWORDTag+0x9b SdbCloseLocalDatabase-0x550 apphelp+0x64f9 @ 0x731464f9
SdbGetNthUserSdb+0x3ef SdbFindFirstStringIndexedTag-0x1fd apphelp+0x77e7 @ 0x731477e7
SdbCloseLocalDatabase+0x380 SdbGetNthUserSdb-0x62f apphelp+0x6dc9 @ 0x73146dc9
SdbCloseLocalDatabase+0x857 SdbGetNthUserSdb-0x158 apphelp+0x72a0 @ 0x731472a0
SdbCloseLocalDatabase+0x7ed SdbGetNthUserSdb-0x1c2 apphelp+0x7236 @ 0x73147236
SdbInitDatabaseEx+0xa28 SdbGetFileInfo-0x57b apphelp+0x5064 @ 0x73145064
SdbGetFileInfo+0x1c1 SdbGetIndex-0x3d9 apphelp+0x57a0 @ 0x731457a0
SdbInitDatabaseEx+0x68c SdbGetFileInfo-0x917 apphelp+0x4cc8 @ 0x73144cc8
ApphelpCreateAppcompatData+0x46b ApphelpCheckRunAppEx-0x1f6 apphelp+0x2f2d @ 0x73142f2d
ApphelpCheckRunAppEx+0xa7 SdbGetStringTagPtr-0xdf apphelp+0x31ca @ 0x731431ca
BaseCheckRunApp+0x1e4 SearchPathA-0x1bd kernel32+0x29f9f @ 0x755d9f9f
BaseCheckRunApp+0x46 SearchPathA-0x35b kernel32+0x29e01 @ 0x755d9e01
BasepCheckBadapp+0x1a1 CheckElevationEnabled-0x64 kernel32+0x230fa @ 0x755d30fa
BaseCheckAppcompatCacheEx+0xcdd BasepCheckBadapp-0x16 kernel32+0x22f43 @ 0x755d2f43
CreateProcessInternalW+0x961 BasepFreeAppCompatData-0x7dd kernel32+0x24554 @ 0x755d4554
New_kernel32_CreateProcessInternalW@48+0x185 New_kernel32_CreateRemoteThread@28-0x16b @ 0x736e7747
CreateProcessW+0x2c CreateProcessA-0x9 kernel32+0x11069 @ 0x755c1069
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x755c33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x76f49ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x76f49ea5
exception.instruction_r:
0f b7 06 99 0f a4 c2 10 c1 e0 10 0b d8 0b fa 89
exception.symbol:
LdrUnlockLoaderLock+0x2cc RtlInitUnicodeStringEx-0xe6b ntdll+0x36f08
exception.instruction:
movzx eax, word ptr [esi]
exception.module:
ntdll.dll
exception.exception_code:
0xc0000005
exception.offset:
225032
exception.address:
0x76f46f08
registers.esp:
1630796
registers.edi:
72
registers.eax:
15309016
registers.ebp:
1630928
registers.edx:
1968308274
registers.ebx:
49
registers.esi:
15309024
registers.ecx:
15041456
1
0
0
__exception__
April 14, 2023, 6:02 p.m.
stacktrace:
RtlAllocateHeap+0xac RtlFreeAnsiString-0x54 ntdll+0x2e0d2 @ 0x76f3e0d2
SdbGetTagFromTagID+0x333 SdbReadDWORDTag-0x1ad apphelp+0x3993 @ 0x73143993
SdbReadWORDTag+0x9b SdbCloseLocalDatabase-0x550 apphelp+0x64f9 @ 0x731464f9
SdbGetNthUserSdb+0x3ef SdbFindFirstStringIndexedTag-0x1fd apphelp+0x77e7 @ 0x731477e7
SdbCloseLocalDatabase+0x380 SdbGetNthUserSdb-0x62f apphelp+0x6dc9 @ 0x73146dc9
SdbCloseLocalDatabase+0x857 SdbGetNthUserSdb-0x158 apphelp+0x72a0 @ 0x731472a0
SdbCloseLocalDatabase+0x7ed SdbGetNthUserSdb-0x1c2 apphelp+0x7236 @ 0x73147236
SdbInitDatabaseEx+0xa28 SdbGetFileInfo-0x57b apphelp+0x5064 @ 0x73145064
SdbGetFileInfo+0x1c1 SdbGetIndex-0x3d9 apphelp+0x57a0 @ 0x731457a0
SdbInitDatabaseEx+0x68c SdbGetFileInfo-0x917 apphelp+0x4cc8 @ 0x73144cc8
ApphelpCreateAppcompatData+0x46b ApphelpCheckRunAppEx-0x1f6 apphelp+0x2f2d @ 0x73142f2d
ApphelpCheckRunAppEx+0xa7 SdbGetStringTagPtr-0xdf apphelp+0x31ca @ 0x731431ca
BaseCheckRunApp+0x1e4 SearchPathA-0x1bd kernel32+0x29f9f @ 0x755d9f9f
BaseCheckRunApp+0x46 SearchPathA-0x35b kernel32+0x29e01 @ 0x755d9e01
BasepCheckBadapp+0x1a1 CheckElevationEnabled-0x64 kernel32+0x230fa @ 0x755d30fa
BaseCheckAppcompatCacheEx+0xcdd BasepCheckBadapp-0x16 kernel32+0x22f43 @ 0x755d2f43
CreateProcessInternalW+0x961 BasepFreeAppCompatData-0x7dd kernel32+0x24554 @ 0x755d4554
New_kernel32_CreateProcessInternalW@48+0x185 New_kernel32_CreateRemoteThread@28-0x16b @ 0x736e7747
CreateProcessW+0x2c CreateProcessA-0x9 kernel32+0x11069 @ 0x755c1069
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x755c33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x76f49ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x76f49ea5
exception.instruction_r:
0f b7 06 99 0f a4 c2 10 c1 e0 10 0b d8 0b fa 89
exception.symbol:
LdrUnlockLoaderLock+0x2cc RtlInitUnicodeStringEx-0xe6b ntdll+0x36f08
exception.instruction:
movzx eax, word ptr [esi]
exception.module:
ntdll.dll
exception.exception_code:
0xc0000005
exception.offset:
225032
exception.address:
0x76f46f08
registers.esp:
1630796
registers.edi:
72
registers.eax:
15309016
registers.ebp:
1630928
registers.edx:
1968308274
registers.ebx:
49
registers.esi:
15309024
registers.ecx:
15041456
1
0
0
__exception__
April 14, 2023, 6:02 p.m.
stacktrace:
RtlFreeHeap+0x7e RtlAllocateHeap-0x23 ntdll+0x2e003 @ 0x76f3e003
ApphelpCheckRunAppEx+0xd4 SdbGetStringTagPtr-0xb2 apphelp+0x31f7 @ 0x731431f7
SdbFindFirstStringIndexedTag+0x23b SdbMakeIndexKeyFromString-0x1e9 apphelp+0x7c1f @ 0x73147c1f
SdbFindFirstStringIndexedTag+0x176 SdbMakeIndexKeyFromString-0x2ae apphelp+0x7b5a @ 0x73147b5a
SdbInitDatabaseEx+0x70b SdbGetFileInfo-0x898 apphelp+0x4d47 @ 0x73144d47
ApphelpCreateAppcompatData+0x46b ApphelpCheckRunAppEx-0x1f6 apphelp+0x2f2d @ 0x73142f2d
ApphelpCheckRunAppEx+0xa7 SdbGetStringTagPtr-0xdf apphelp+0x31ca @ 0x731431ca
BaseCheckRunApp+0x1e4 SearchPathA-0x1bd kernel32+0x29f9f @ 0x755d9f9f
BaseCheckRunApp+0x46 SearchPathA-0x35b kernel32+0x29e01 @ 0x755d9e01
BasepCheckBadapp+0x1a1 CheckElevationEnabled-0x64 kernel32+0x230fa @ 0x755d30fa
BaseCheckAppcompatCacheEx+0xcdd BasepCheckBadapp-0x16 kernel32+0x22f43 @ 0x755d2f43
CreateProcessInternalW+0x961 BasepFreeAppCompatData-0x7dd kernel32+0x24554 @ 0x755d4554
New_kernel32_CreateProcessInternalW@48+0x185 New_kernel32_CreateRemoteThread@28-0x16b @ 0x736e7747
CreateProcessW+0x2c CreateProcessA-0x9 kernel32+0x11069 @ 0x755c1069
BaseThreadInitThunk+0x12 VerifyConsoleIoHandle-0xb3 kernel32+0x133ca @ 0x755c33ca
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x76f49ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x76f49ea5
exception.instruction_r:
8b 46 04 89 45 f4 c6 47 07 80 c6 47 06 00 8b 5e
exception.symbol:
RtlInitUnicodeString+0x196 RtlMultiByteToUnicodeN-0x1a7 ntdll+0x2e39e
exception.instruction:
mov eax, dword ptr [esi + 4]
exception.module:
ntdll.dll
exception.exception_code:
0xc0000005
exception.offset:
189342
exception.address:
0x76f3e39e
registers.esp:
1631992
registers.edi:
15070704
registers.eax:
537529613
registers.ebp:
1632044
registers.edx:
15070712
registers.ebx:
15070712
registers.esi:
723607234
registers.ecx:
14942208
1
0
0