Skip to content

Instantly share code, notes, and snippets.

@filipnavara
Last active September 10, 2018 08:19
Show Gist options
  • Save filipnavara/9519487fda3ac5d2655a296672f89391 to your computer and use it in GitHub Desktop.
Save filipnavara/9519487fda3ac5d2655a296672f89391 to your computer and use it in GitHub Desktop.
Microsoft (R) Windows Debugger Version 10.0.10586.567 X86
Copyright (c) Microsoft Corporation. All rights reserved.
Loading Dump File [C:\Users\Filip Navara\Downloads\MailClient.exe.9480.dmp]
User Mini Dump File: Only registers, stack and portions of memory are available
Symbol search path is: srv*
Executable search path is:
Windows 10 Version 17134 MP (8 procs) Free x86 compatible
Product: WinNt, suite: SingleUserTS
Built by: 17134.1.x86fre.rs4_release.180410-1804
Machine Name:
Debug session time: Fri Jun 15 11:51:06.000 2018 (UTC + 2:00)
System Uptime: not available
Process Uptime: 0 days 1:38:17.000
................................................................
................................................................
................................................................
...............................................................
Loading unloaded module list
................................................................
This dump file has an exception of interest stored in it.
The stored exception information can be accessed via .ecxr.
(2508.3498): Access violation - code c0000005 (first/second chance not available)
eax=00000000 ebx=00000000 ecx=2e352e32 edx=000000ff esi=00000003 edi=00000003
eip=77dfa7bc esp=10a3eae0 ebp=10a3ec70 iopl=0 nv up ei pl nz ac po nc
cs=0023 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00000212
ntdll!NtWaitForMultipleObjects+0xc:
77dfa7bc c21400 ret 14h
0:047> !analyze -v
*******************************************************************************
* *
* Exception Analysis *
* *
*******************************************************************************
Unable to load image C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a5805dd044dd9d13b4349c862f767035\mscorlib.ni.dll, Win32 error 0n2
*** WARNING: Unable to verify checksum for System.Windows.Forms.ni.dll
Unable to load image C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient\6bcc80bc3f726e9a938c8acf1e49ceea\MailClient.ni.exe, Win32 error 0n2
*** WARNING: Unable to verify checksum for MailClient.ni.exe
*** ERROR: Module load completed but symbols could not be loaded for MailClient.ni.exe
Unable to load image C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.Common.UI\efbba1da0ff562663b535ee0be19ec9f\MailClient.Common.UI.ni.dll, Win32 error 0n2
*** WARNING: Unable to verify checksum for MailClient.Common.UI.ni.dll
*** ERROR: Module load completed but symbols could not be loaded for MailClient.Common.UI.ni.dll
*** WARNING: Unable to verify checksum for libcef.dll
*** ERROR: Symbol file could not be found. Defaulted to export symbols for libcef.dll -
Unable to load image C:\Windows\assembly\NativeImages_v4.0.30319_32\Xilium.CefGlue\0b595fd303f21479b5a589395184bde8\Xilium.CefGlue.ni.dll, Win32 error 0n2
*** WARNING: Unable to verify checksum for Xilium.CefGlue.ni.dll
*** ERROR: Module load completed but symbols could not be loaded for Xilium.CefGlue.ni.dll
*** WARNING: Unable to verify checksum for System.Management.ni.dll
Unable to load image C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.Storage\f351bd152e6c8339a6e8339fae8356e5\MailClient.Storage.ni.dll, Win32 error 0n2
*** WARNING: Unable to verify checksum for MailClient.Storage.ni.dll
*** ERROR: Module load completed but symbols could not be loaded for MailClient.Storage.ni.dll
*** WARNING: Unable to verify checksum for MailClient.Accounts.ni.dll
*** ERROR: Module load completed but symbols could not be loaded for MailClient.Accounts.ni.dll
Unable to load image C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runt73a1fc9d#\a952e26e940fbee238210e7052d74f83\System.Runtime.Remoting.ni.dll, Win32 error 0n2
*** WARNING: Unable to verify checksum for System.Runtime.Remoting.ni.dll
Unable to load image C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.Commands\be3072f5d36eb9ca7e3962f24a7a6b91\MailClient.Commands.ni.dll, Win32 error 0n2
*** WARNING: Unable to verify checksum for MailClient.Commands.ni.dll
*** ERROR: Module load completed but symbols could not be loaded for MailClient.Commands.ni.dll
*** WARNING: Unable to verify checksum for System.ni.dll
Unable to load image C:\Windows\assembly\NativeImages_v4.0.30319_32\MailClient.Imap.Base\af84eec21a9f73af4aaf305314ba3f07\MailClient.Imap.Base.ni.dll, Win32 error 0n2
*** WARNING: Unable to verify checksum for MailClient.Imap.Base.ni.dll
*** ERROR: Module load completed but symbols could not be loaded for MailClient.Imap.Base.ni.dll
GetUrlPageData2 (WinHttp) failed: 12002.
DUMP_CLASS: 2
DUMP_QUALIFIER: 400
CONTEXT: (.ecxr)
eax=c0033338 ebx=00000000 ecx=2e352e32 edx=000000ff esi=1bb1b3c0 edi=2e352e32
eip=2e352e32 esp=10a3f4c0 ebp=10a3f4f8 iopl=0 nv up ei pl nz na po nc
cs=0023 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00010202
2e352e32 ?? ???
Resetting default scope
FAULTING_IP:
unknown!printable+0
2e352e32 ?? ???
EXCEPTION_RECORD: (.exr -1)
ExceptionAddress: 2e352e32
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 00000008
Parameter[1]: 2e352e32
Attempt to execute non-executable address 2e352e32
PROCESS_NAME: MailClient.exe
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.
EXCEPTION_CODE_STR: c0000005
EXCEPTION_PARAMETER1: 00000008
EXCEPTION_PARAMETER2: 2e352e32
WRITE_ADDRESS: 2e352e32
FOLLOWUP_IP:
unknown!printable+0
2e352e32 ?? ???
FAILED_INSTRUCTION_ADDRESS:
unknown!printable+0
2e352e32 ?? ???
WATSON_BKT_PROCSTAMP: 5b058b90
WATSON_BKT_PROCVER: 7.1.32845.0
WATSON_BKT_MODULE: unknown
WATSON_BKT_MODVER: 0.0.0.0
WATSON_BKT_MODOFFSET: 2e352e32
WATSON_BKT_MODSTAMP: bbbbbbb4
BUILD_VERSION_STRING: 10.0.17134.111 (WinBuild.160101.0800)
MODLIST_WITH_TSCHKSUM_HASH: 50a5738b06b647a98139c883a5ecaa1c6678d09f
MODLIST_SHA1_HASH: f0942f66faf6287772dd6164499d36921b43ee52
NTGLOBALFLAG: 0
APPLICATION_VERIFIER_FLAGS: 0
DUMP_FLAGS: 94
DUMP_TYPE: 1
APP: mailclient.exe
MISSING_CLR_SYMBOL: 0
ANALYSIS_SESSION_HOST: DESKTOP-REOLCRO
ANALYSIS_SESSION_TIME: 09-10-2018 10:12:46.0851
ANALYSIS_VERSION: 10.0.10586.567 x86fre
MANAGED_CODE: 1
MANAGED_ENGINE_MODULE: clr
MANAGED_ANALYSIS_PROVIDER: SOS
THREAD_ATTRIBUTES:
OS_LOCALE: DEU
PROBLEM_CLASSES:
SOFTWARE_NX_FAULT
Tid [0x3498]
Frame [0x00]: unknown!printable
INVALID
Tid [0x3498]
Frame [0x00]: unknown!printable
Failure Bucketing
NOSOS
Tid [0x3498]
Failure Bucketing
BUGCHECK_STR: SOFTWARE_NX_FAULT_NOSOS_INVALID
DEFAULT_BUCKET_ID: SOFTWARE_NX_FAULT_NOSOS_INVALID
LAST_CONTROL_TRANSFER: from 7475dc0c to 2e352e32
STACK_TEXT:
WARNING: Frame IP not in any known module. Following frames may be wrong.
10a3f4bc 7475dc0c 10a3f6c8 00000001 000000ff 0x2e352e32
10a3f4f8 7476338f 10a3f6c8 00000001 000000ff crypt32!TlgAggregateInternalRegisteredProviderEtwCallback+0x4c
10a3f534 77de391e 10a3f6c8 00000001 000000ff crypt32!_TlgEnableCallback+0x366ff
10a3f5dc 77de36f3 10a3f690 10a3f690 214d24b0 ntdll!EtwpEventApiCallback+0x104
10a3f60c 77df4d60 214d24b0 10a3f690 00000000 ntdll!EtwpUpdateEnableInfoAndCallback+0xca
10a3f628 77df4b9e 10a3f648 10a3f654 10a3f65e ntdll!EtwpProcessNotification+0xb5
10a3f660 77df4a4d 10a3f690 02970680 77df49e0 ntdll!EtwDeliverDataBlock+0x8e
10a3f794 77de1314 10a3f8c0 00000040 02970680 ntdll!EtwpNotificationThread+0x6d
10a3f7c0 77de18ea 00000000 029707b0 02970778 ntdll!TppExecuteWaitCallback+0x89
10a3f7dc 77ddcf93 10a3f8c0 02970778 02970680 ntdll!TppWaitCompletion+0x8a
10a3f994 77138484 029707b0 77138460 774c90f2 ntdll!TppWorkerThread+0x6d3
10a3f9a8 77df2fea 029707b0 57efacac 00000000 kernel32!BaseThreadInitThunk+0x24
10a3f9f0 77df2fba ffffffff 77e0ec26 00000000 ntdll!__RtlUserThreadStart+0x2f
10a3fa00 00000000 77ddc8c0 029707b0 00000000 ntdll!_RtlUserThreadStart+0x1b
THREAD_SHA1_HASH_MOD_FUNC: 808b0733a346ae3fcdc7121ca49333e6077c419f
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: dc8363ad43f785725409e247565e34488c392074
THREAD_SHA1_HASH_MOD: ceddc07de3624aa6cbca28224e4d1fa802c45607
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: unknown!printable+0
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: unknown
IMAGE_NAME: unknown.dll
DEBUG_FLR_IMAGE_TIMESTAMP: 0
STACK_COMMAND: .ecxr ; kb
FAILURE_BUCKET_ID: SOFTWARE_NX_FAULT_NOSOS_INVALID_c0000005_unknown.dll!printable
BUCKET_ID: SOFTWARE_NX_FAULT_NOSOS_INVALID_BAD_IP_unknown!printable+0
PRIMARY_PROBLEM_CLASS: SOFTWARE_NX_FAULT_NOSOS_INVALID_BAD_IP_unknown!printable+0
BUCKET_ID_OFFSET: 0
BUCKET_ID_MODULE_STR: unknown
BUCKET_ID_MODTIMEDATESTAMP: 0
BUCKET_ID_MODCHECKSUM: 0
BUCKET_ID_MODVER_STR:
BUCKET_ID_PREFIX_STR: SOFTWARE_NX_FAULT_NOSOS_INVALID_BAD_IP_
FAILURE_PROBLEM_CLASS: SOFTWARE_NX_FAULT_NOSOS_INVALID
FAILURE_EXCEPTION_CODE: c0000005
FAILURE_IMAGE_NAME: unknown.dll
FAILURE_FUNCTION_NAME: printable
BUCKET_ID_FUNCTION_STR: printable
FAILURE_SYMBOL_NAME: unknown.dll!printable
WATSON_STAGEONE_URL: http://watson.microsoft.com/StageOne/MailClient.exe/7.1.32845.0/5b058b90/unknown/0.0.0.0/bbbbbbb4/c0000005/2e352e32.htm?Retriage=1
TARGET_TIME: 2018-06-15T09:51:06.000Z
OSBUILD: 17134
OSSERVICEPACK: 1
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 256
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x86
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt SingleUserTS
USER_LCID: 0
OSBUILD_TIMESTAMP: unknown_date
BUILDDATESTAMP_STR: 160101.0800
BUILDLAB_STR: WinBuild
BUILDOSVER_STR: 10.0.17134.111
ANALYSIS_SESSION_ELAPSED_TIME: d39b
ANALYSIS_SOURCE: UM
FAILURE_ID_HASH_STRING: um:software_nx_fault_nosos_invalid_c0000005_unknown.dll!printable
FAILURE_ID_HASH: {08372e1e-01ef-b75e-d5fe-7204d9741f24}
Followup: MachineOwner
---------
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment