Skip to content

Instantly share code, notes, and snippets.

@mcdurdin
Created April 20, 2021 00:02
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save mcdurdin/8385f3b801869e70a43ac57cb69d50fa to your computer and use it in GitHub Desktop.
Save mcdurdin/8385f3b801869e70a43ac57cb69d50fa to your computer and use it in GitHub Desktop.
Deadlock chain in Explorer: https://aka.ms/AAbzzc4
************* Path validation summary **************
Response Time (ms) Location
Deferred srv*c:\symbols*https://msdl.microsoft.com/download/symbols
Symbol search path is: srv*c:\symbols*https://msdl.microsoft.com/download/symbols
Executable search path is:
ModLoad: 00007ff7`9fd60000 00007ff7`a01d9000 C:\Windows\Explorer.EXE
ModLoad: 00007ffc`28370000 00007ffc`28565000 C:\Windows\SYSTEM32\ntdll.dll
ModLoad: 00007ffc`26e40000 00007ffc`26efd000 C:\Windows\System32\KERNEL32.DLL
ModLoad: 00007ffc`25c30000 00007ffc`25ef8000 C:\Windows\System32\KERNELBASE.dll
ModLoad: 00007ffc`25b90000 00007ffc`25c2d000 C:\Windows\System32\msvcp_win.dll
ModLoad: 00007ffc`262d0000 00007ffc`263d0000 C:\Windows\System32\ucrtbase.dll
ModLoad: 00007ffc`27d40000 00007ffc`28095000 C:\Windows\System32\combase.dll
ModLoad: 00007ffc`267b0000 00007ffc`268db000 C:\Windows\System32\RPCRT4.dll
ModLoad: 00007ffc`27480000 00007ffc`2754d000 C:\Windows\System32\OLEAUT32.dll
ModLoad: 00007ffc`263d0000 00007ffc`2647e000 C:\Windows\System32\shcore.dll
ModLoad: 00007ffc`28290000 00007ffc`2832e000 C:\Windows\System32\msvcrt.dll
ModLoad: 00007ffc`26690000 00007ffc`2673c000 C:\Windows\System32\advapi32.dll
ModLoad: 00007ffc`27550000 00007ffc`275eb000 C:\Windows\System32\sechost.dll
ModLoad: 00007ffc`26f00000 00007ffc`26f55000 C:\Windows\System32\shlwapi.dll
ModLoad: 00007ffc`268e0000 00007ffc`26a80000 C:\Windows\System32\user32.dll
ModLoad: 00007ffc`25b60000 00007ffc`25b82000 C:\Windows\System32\win32u.dll
ModLoad: 00007ffc`26780000 00007ffc`267aa000 C:\Windows\System32\GDI32.dll
ModLoad: 00007ffc`261c0000 00007ffc`262cb000 C:\Windows\System32\gdi32full.dll
ModLoad: 00007ffc`275f0000 00007ffc`27d32000 C:\Windows\System32\SHELL32.dll
ModLoad: 00007ffb`fdb10000 00007ffb`fdba2000 C:\Windows\SYSTEM32\AEPIC.dll
ModLoad: 00007ffc`25f00000 00007ffc`25f27000 C:\Windows\System32\bcrypt.dll
ModLoad: 00007ffb`f4250000 00007ffb`f42f8000 C:\Windows\SYSTEM32\TWINAPI.dll
ModLoad: 00007ffc`259b0000 00007ffc`259de000 C:\Windows\SYSTEM32\USERENV.dll
ModLoad: 00007ffc`25060000 00007ffc`250ab000 C:\Windows\SYSTEM32\powrprof.dll
ModLoad: 00007ffc`23bb0000 00007ffc`24341000 C:\Windows\SYSTEM32\windows.storage.dll
ModLoad: 00007ffc`243b0000 00007ffc`244a3000 C:\Windows\SYSTEM32\dxgi.dll
ModLoad: 00007ffc`239b0000 00007ffc`239c2000 C:\Windows\SYSTEM32\kernel.appcore.dll
ModLoad: 00007ffc`230e0000 00007ffc`231d7000 C:\Windows\SYSTEM32\PROPSYS.dll
ModLoad: 00007ffc`0eff0000 00007ffc`0f4cd000 C:\Windows\SYSTEM32\WININET.dll
ModLoad: 00007ffc`23410000 00007ffc`234ae000 C:\Windows\SYSTEM32\UxTheme.dll
ModLoad: 00007ffc`236c0000 00007ffc`236ef000 C:\Windows\SYSTEM32\dwmapi.dll
ModLoad: 00007ffc`25970000 00007ffc`259a1000 C:\Windows\SYSTEM32\SspiCli.dll
ModLoad: 00007ffc`1d480000 00007ffc`1d681000 C:\Windows\SYSTEM32\twinapi.appcore.dll
ModLoad: 00007ffc`1fa60000 00007ffc`1fa74000 C:\Windows\SYSTEM32\WTSAPI32.dll
ModLoad: 00007ffc`247b0000 00007ffc`247e3000 C:\Windows\SYSTEM32\ntmarta.dll
ModLoad: 00007ffc`25490000 00007ffc`254a8000 C:\Windows\SYSTEM32\cryptsp.dll
ModLoad: 00007ffc`25450000 00007ffc`2547c000 C:\Windows\SYSTEM32\Wldp.dll
ModLoad: 00007ffc`26140000 00007ffc`261c0000 C:\Windows\System32\bcryptPrimitives.dll
ModLoad: 00007ffc`26740000 00007ffc`26770000 C:\Windows\System32\IMM32.DLL
ModLoad: 00007ffc`24ed0000 00007ffc`24ee2000 C:\Windows\SYSTEM32\UMPDC.dll
ModLoad: 00007ffc`0b060000 00007ffc`0b0ca000 C:\Windows\SYSTEM32\NInput.dll
ModLoad: 00007ffc`26d20000 00007ffc`26e35000 C:\Windows\System32\MSCTF.dll
ModLoad: 00007ffc`26490000 00007ffc`265ba000 C:\Windows\System32\ole32.dll
ModLoad: 00007ffc`0ed20000 00007ffc`0efba000 C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.844_none_ca00b6081b84eb1d\comctl32.dll
ModLoad: 00007ffc`273d0000 00007ffc`27479000 C:\Windows\System32\clbcatq.dll
ModLoad: 00007ffb`f3c00000 00007ffb`f3c91000 C:\Windows\System32\appresolver.dll
ModLoad: 00007ffc`24640000 00007ffc`24669000 C:\Windows\System32\SLC.dll
ModLoad: 00007ffc`0aa10000 00007ffc`0aa6b000 C:\Windows\System32\Bcp47Langs.dll
ModLoad: 00007ffc`24610000 00007ffc`24635000 C:\Windows\System32\sppc.dll
ModLoad: 00007ffc`259f0000 00007ffc`25a0f000 C:\Windows\SYSTEM32\profapi.dll
ModLoad: 00007ffc`0e3c0000 00007ffc`0eb57000 C:\Windows\System32\OneCoreUAPCommonProxyStub.dll
ModLoad: 00007ffb`f2c50000 00007ffb`f31d2000 C:\Windows\System32\StartTileData.dll
ModLoad: 00007ffc`22df0000 00007ffc`22ee2000 C:\Windows\System32\CoreMessaging.dll
ModLoad: 00007ffc`28120000 00007ffc`2818b000 C:\Windows\System32\WS2_32.dll
ModLoad: 00007ffc`16990000 00007ffc`169bb000 C:\Windows\System32\IDStore.dll
ModLoad: 00007ffc`1fa30000 00007ffc`1fa46000 C:\Windows\SYSTEM32\usermgrcli.dll
ModLoad: 00007ffc`1b9d0000 00007ffc`1b9f4000 C:\Windows\System32\SAMLIB.dll
ModLoad: 00007ffb`fdf10000 00007ffb`fdfba000 C:\Windows\System32\wlidprov.dll
ModLoad: 00007ffc`1e120000 00007ffc`1e139000 C:\Windows\System32\samcli.dll
ModLoad: 00007ffc`211a0000 00007ffc`21240000 C:\Windows\SYSTEM32\policymanager.dll
ModLoad: 00007ffc`24c10000 00007ffc`24c9a000 C:\Windows\SYSTEM32\msvcp110_win.dll
ModLoad: 00007ffb`fe680000 00007ffb`fe7c6000 C:\Windows\System32\Windows.StateRepositoryPS.dll
ModLoad: 00007ffc`1d690000 00007ffc`1d776000 C:\Windows\System32\Windows.ApplicationModel.dll
ModLoad: 00007ffc`1d2d0000 00007ffc`1d3c9000 C:\Windows\System32\AppXDeploymentClient.dll
ModLoad: 00007ffc`1c560000 00007ffc`1c5b4000 C:\Windows\System32\usermgrproxy.dll
ModLoad: 00007ffb`f5ae0000 00007ffb`f5b20000 C:\Windows\System32\Windows.StateRepositoryClient.dll
ModLoad: 00007ffc`17210000 00007ffc`17403000 C:\Windows\System32\Windows.CloudStore.dll
ModLoad: 00007ffc`16f20000 00007ffc`1710e000 C:\Windows\System32\urlmon.dll
ModLoad: 00007ffc`16c70000 00007ffc`16f20000 C:\Windows\System32\iertutil.dll
ModLoad: 00007ffc`21e00000 00007ffc`21f54000 C:\Windows\System32\WinTypes.dll
ModLoad: 00007ffb`f37e0000 00007ffb`f3817000 C:\Windows\System32\AppExtension.dll
ModLoad: 00007ffb`f1cd0000 00007ffb`f1de8000 C:\Windows\system32\SettingSyncCore.dll
ModLoad: 00007ffc`1de20000 00007ffc`1de9d000 C:\Windows\System32\OneCoreCommonProxyStub.dll
ModLoad: 00007ffc`24860000 00007ffc`248ba000 C:\Windows\SYSTEM32\winsta.dll
ModLoad: 00007ffc`1e820000 00007ffc`1e870000 C:\Windows\SYSTEM32\SndVolSSO.DLL
ModLoad: 00007ffc`1eef0000 00007ffc`1ef75000 C:\Windows\SYSTEM32\MMDevAPI.DLL
ModLoad: 00007ffc`25860000 00007ffc`2588c000 C:\Windows\SYSTEM32\DEVOBJ.dll
ModLoad: 00007ffc`25f30000 00007ffc`25f7e000 C:\Windows\System32\cfgmgr32.dll
ModLoad: 00007ffc`1e7b0000 00007ffc`1e816000 C:\Windows\SYSTEM32\OLEACC.dll
ModLoad: 00007ffc`07cb0000 00007ffc`07d5c000 C:\Windows\SYSTEM32\TextShaping.dll
ModLoad: 00007ffc`0a6b0000 00007ffc`0a864000 C:\Windows\system32\windowscodecs.dll
ModLoad: 00007ffc`22520000 00007ffc`22705000 C:\Windows\SYSTEM32\dcomp.dll
ModLoad: 00007ffc`1e770000 00007ffc`1e7ae000 C:\Windows\system32\dataexchange.dll
ModLoad: 00007ffc`21b90000 00007ffc`21df4000 C:\Windows\system32\d3d11.dll
ModLoad: 00007ffc`23020000 00007ffc`230b0000 C:\Windows\SYSTEM32\apphelp.dll
ModLoad: 00007ffb`f57b0000 00007ffb`f584b000 C:\Windows\System32\TileDataRepository.dll
ModLoad: 00007ffc`1c320000 00007ffc`1c3d1000 C:\Windows\System32\StateRepository.Core.dll
ModLoad: 00007ffc`1bd10000 00007ffc`1c29e000 C:\Windows\System32\Windows.StateRepository.dll
ModLoad: 00007ffb`f1920000 00007ffb`f1b41000 C:\Windows\system32\explorerframe.dll
ModLoad: 00007ffc`19890000 00007ffc`198a1000 C:\Windows\SYSTEM32\windows.staterepositorycore.dll
ModLoad: 00007ffc`0d140000 00007ffc`0d234000 C:\Windows\System32\MrmCoreR.dll
ModLoad: 00007ffc`0a560000 00007ffc`0a6a1000 C:\Windows\System32\Windows.UI.dll
ModLoad: 00007ffc`0b3d0000 00007ffc`0b4c9000 C:\Windows\System32\TextInputFramework.dll
ModLoad: 00007ffc`0a8b0000 00007ffc`0a951000 C:\Windows\System32\WindowManagementAPI.dll
ModLoad: 00007ffc`095d0000 00007ffc`09722000 C:\Windows\System32\InputHost.dll
ModLoad: 00007ffc`22a90000 00007ffc`22dee000 C:\Windows\System32\CoreUIComponents.dll
ModLoad: 00007ffc`0a3d0000 00007ffc`0a3fd000 C:\Windows\SYSTEM32\languageoverlayutil.dll
ModLoad: 00007ffc`09290000 00007ffc`092bd000 C:\Windows\System32\bcp47mrm.dll
ModLoad: 00007ffc`280a0000 00007ffc`28119000 C:\Windows\System32\coml2.dll
ModLoad: 00007ffb`f18b0000 00007ffb`f1916000 C:\Windows\System32\thumbcache.dll
ModLoad: 00007ffb`f2430000 00007ffb`f2a2b000 C:\Windows\system32\twinui.pcshell.dll
ModLoad: 00007ffc`25f80000 00007ffc`260df000 C:\Windows\System32\CRYPT32.dll
ModLoad: 00007ffc`04730000 00007ffc`049af000 C:\Windows\system32\DWrite.dll
ModLoad: 00007ffb`f9570000 00007ffb`f9a11000 C:\Windows\system32\cdp.dll
ModLoad: 00007ffc`0aa70000 00007ffc`0aadf000 C:\Windows\system32\wincorlib.DLL
ModLoad: 00007ffc`1b2f0000 00007ffc`1b42b000 C:\Windows\system32\dsreg.dll
ModLoad: 00007ffc`1a7a0000 00007ffc`1a7c4000 C:\Windows\SYSTEM32\edputil.dll
ModLoad: 00007ffb`f17f0000 00007ffb`f18ae000 C:\Windows\System32\windows.immersiveshell.serviceprovider.dll
ModLoad: 00007ffc`1ca10000 00007ffc`1ca2d000 C:\Windows\SYSTEM32\MPR.dll
ModLoad: 00007ffc`20400000 00007ffc`2040c000 C:\Windows\System32\prl_np.dll
ModLoad: 00007ffc`1fda0000 00007ffc`1fdab000 C:\Windows\System32\drprov.dll
ModLoad: 00007ffc`1f250000 00007ffc`1f268000 C:\Windows\System32\ntlanman.dll
ModLoad: 00007ffc`1ec50000 00007ffc`1ec6e000 C:\Windows\System32\davclnt.dll
ModLoad: 00007ffc`1fd90000 00007ffc`1fd9d000 C:\Windows\System32\DAVHLPR.dll
ModLoad: 00007ffc`24ca0000 00007ffc`24cb7000 C:\Windows\System32\wkscli.dll
ModLoad: 00007ffc`19970000 00007ffc`19982000 C:\Windows\SYSTEM32\cscapi.dll
ModLoad: 00007ffc`25000000 00007ffc`2500c000 C:\Windows\System32\netutils.dll
ModLoad: 00007ffb`f56f0000 00007ffb`f5712000 C:\Windows\SYSTEM32\cldapi.dll
ModLoad: 00007ffc`1cd20000 00007ffc`1cd2b000 C:\Windows\SYSTEM32\FLTLIB.DLL
ModLoad: 00007ffb`f5270000 00007ffb`f5316000 C:\Windows\System32\twinui.appcore.dll
ModLoad: 00007ffb`f10f0000 00007ffb`f16e2000 C:\Windows\system32\twinui.dll
ModLoad: 00007ffc`15ac0000 00007ffc`15b14000 C:\Windows\system32\pdh.dll
ModLoad: 00007ffb`f1040000 00007ffb`f10e9000 C:\Windows\System32\ApplicationFrame.dll
ModLoad: 00007ffc`21f60000 00007ffc`22520000 C:\Windows\System32\d2d1.dll
ModLoad: 00007ffb`f5320000 00007ffb`f539d000 C:\Windows\SYSTEM32\ntshrui.dll
ModLoad: 00007ffc`1d030000 00007ffc`1d058000 C:\Windows\SYSTEM32\srvcli.dll
ModLoad: 00007ffb`f0e90000 00007ffb`f0f64000 C:\Windows\System32\HolographicExtensions.dll
ModLoad: 00007ffc`235d0000 00007ffc`235e4000 C:\Windows\System32\ResourcePolicyClient.dll
ModLoad: 00007ffc`1e750000 00007ffc`1e76c000 C:\Windows\System32\VirtualMonitorManager.dll
ModLoad: 00007ffc`06910000 00007ffc`06a48000 C:\Windows\System32\Windows.UI.Immersive.dll
ModLoad: 00007ffc`0efc0000 00007ffc`0efe7000 C:\Windows\SYSTEM32\WINMM.dll
ModLoad: 00007ffb`f0e20000 00007ffb`f0e8c000 C:\Windows\System32\AboveLockAppHost.dll
ModLoad: 00007ffc`1e740000 00007ffc`1e749000 C:\Windows\system32\IconCodecService.dll
ModLoad: 00007ffb`f0de0000 00007ffb`f0e15000 C:\Windows\System32\npsm.dll
ModLoad: 00007ffb`f0d80000 00007ffb`f0dd5000 C:\Windows\System32\Windows.Shell.BlueLightReduction.dll
ModLoad: 00007ffc`1f830000 00007ffc`1f8de000 C:\Windows\System32\mscms.dll
ModLoad: 00007ffc`1f780000 00007ffc`1f791000 C:\Windows\System32\ColorAdapterClient.dll
ModLoad: 00007ffb`f2280000 00007ffb`f2343000 C:\Windows\System32\Windows.Web.dll
ModLoad: 00007ffc`253b0000 00007ffc`253bc000 C:\Windows\SYSTEM32\CRYPTBASE.DLL
ModLoad: 00007ffb`f0c70000 00007ffb`f0d80000 C:\Windows\System32\Windows.Internal.Signals.dll
ModLoad: 00007ffc`244b0000 00007ffc`245cb000 C:\Windows\SYSTEM32\tdh.dll
ModLoad: 00007ffc`1e730000 00007ffc`1e73d000 C:\Windows\SYSTEM32\LINKINFO.dll
ModLoad: 00007ffb`f0af0000 00007ffb`f0c6e000 C:\Windows\System32\TaskFlowDataEngine.dll
ModLoad: 00007ffb`f3b50000 00007ffb`f3bf6000 C:\Windows\System32\StructuredQuery.dll
ModLoad: 00007ffb`f0a60000 00007ffb`f0ae8000 C:\Windows\System32\Windows.Data.Activities.dll
ModLoad: 00007ffb`f5990000 00007ffb`f5aad000 C:\Windows\System32\Windows.Security.Authentication.Web.Core.dll
ModLoad: 00007ffc`1dec0000 00007ffc`1df1c000 C:\Windows\System32\Windows.Internal.UI.Shell.WindowTabManager.dll
ModLoad: 00007ffb`f2380000 00007ffb`f23e0000 C:\Windows\System32\NotificationControllerPS.dll
ModLoad: 00007ffc`236f0000 00007ffc`2371a000 C:\Windows\System32\RMCLIENT.dll
ModLoad: 00007ffc`1ada0000 00007ffc`1ae27000 C:\Windows\System32\Windows.Devices.Enumeration.dll
ModLoad: 00007ffb`f3a10000 00007ffb`f3a56000 C:\Windows\System32\MSWB7.dll
ModLoad: 00007ffc`1acb0000 00007ffc`1acd0000 C:\Windows\System32\DevDispItemProvider.dll
ModLoad: 00007ffc`0ab90000 00007ffc`0ac31000 C:\Windows\System32\ActXPrxy.dll
ModLoad: 00007ffb`fb5b0000 00007ffb`fb669000 C:\Windows\System32\Windows.Networking.Connectivity.dll
ModLoad: 00007ffb`f09b0000 00007ffb`f0a5c000 C:\Windows\system32\lockcontroller.dll
ModLoad: 00007ffb`f07a0000 00007ffb`f09a9000 C:\Windows\system32\windowsudk.shellcommon.dll
ModLoad: 00007ffb`f0720000 00007ffb`f07a0000 C:\Windows\system32\DictationManager.dll
ModLoad: 00007ffc`049b0000 00007ffc`0602d000 C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_a086f01cc7be643a\igd10iumd64.dll
ModLoad: 00007ffc`25590000 00007ffc`255b7000 C:\Windows\SYSTEM32\ncrypt.dll
ModLoad: 00007ffc`25550000 00007ffc`2558b000 C:\Windows\SYSTEM32\NTASN1.dll
ModLoad: 00007ffc`1dea0000 00007ffc`1deb7000 C:\Windows\system32\NetworkExplorer.dll
ModLoad: 00007ffc`044f0000 00007ffc`0472f000 C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_a086f01cc7be643a\igdgmm64.dll
ModLoad: 00007ffb`f0700000 00007ffb`f0715000 C:\Windows\System32\dfscli.dll
ModLoad: 00007ffc`016d0000 00007ffc`04332000 C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_a086f01cc7be643a\igc64.dll
ModLoad: 00007ffc`1d080000 00007ffc`1d18b000 C:\Windows\System32\WINHTTP.dll
ModLoad: 00007ffc`24ef0000 00007ffc`24f2b000 C:\Windows\System32\IPHLPAPI.DLL
ModLoad: 00007ffc`26770000 00007ffc`26778000 C:\Windows\System32\NSI.dll
ModLoad: 00007ffc`1d3f0000 00007ffc`1d407000 C:\Windows\SYSTEM32\dhcpcsvc6.DLL
ModLoad: 00007ffc`1d3d0000 00007ffc`1d3ed000 C:\Windows\SYSTEM32\dhcpcsvc.DLL
ModLoad: 00007ffc`17410000 00007ffc`174ae000 C:\Windows\System32\webio.dll
ModLoad: 00007ffb`f0590000 00007ffb`f0694000 C:\Windows\System32\Windows.UI.Core.TextInput.dll
ModLoad: 00007ffc`25230000 00007ffc`2529a000 C:\Windows\system32\mswsock.dll
ModLoad: 00007ffc`1d8c0000 00007ffc`1d8cb000 C:\Windows\SYSTEM32\WINNSI.DLL
ModLoad: 00007ffc`24f30000 00007ffc`24ffc000 C:\Windows\SYSTEM32\DNSAPI.dll
ModLoad: 00007ffc`1edc0000 00007ffc`1edca000 C:\Windows\System32\rasadhlp.dll
ModLoad: 00007ffc`1cc30000 00007ffc`1ccaf000 C:\Windows\System32\fwpuclnt.dll
ModLoad: 00007ffb`f0540000 00007ffb`f0581000 C:\Windows\system32\shdocvw.dll
ModLoad: 00007ffc`06030000 00007ffc`0606b000 C:\Windows\SYSTEM32\dxcore.dll
ModLoad: 00007ffb`f23e0000 00007ffb`f2408000 C:\Windows\system32\mssprxy.dll
ModLoad: 00007ffc`0a400000 00007ffc`0a447000 C:\Windows\System32\UIAnimation.dll
ModLoad: 00007ffb`eef30000 00007ffb`f0534000 C:\Program Files\Google\Drive File Stream\46.0.3.0\drivefsext.dll
ModLoad: 00007ffc`1e320000 00007ffc`1e504000 C:\Windows\SYSTEM32\dbghelp.dll
ModLoad: 00007ffb`eed80000 00007ffb`eef2b000 C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.928_none_faefac437613c6cc\gdiplus.dll
ModLoad: 00007ffb`eece0000 00007ffb`eecf2000 C:\Windows\System32\PCShellCommonProxyStub.dll
ModLoad: 00007ffb`f5110000 00007ffb`f51be000 C:\Windows\SYSTEM32\daxexec.dll
ModLoad: 00007ffb`f50c0000 00007ffb`f5102000 C:\Windows\System32\container.dll
ModLoad: 00007ffc`1f130000 00007ffc`1f1a3000 C:\Windows\system32\cryptngc.dll
ModLoad: 00007ffb`eeb60000 00007ffb`eec07000 C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll
ModLoad: 00007ffb`eeb30000 00007ffb`eeb5f000 C:\Windows\SYSTEM32\cflapi.dll
ModLoad: 00007ffb`ee9b0000 00007ffb`eeb22000 C:\Users\mcdurdin\AppData\Local\Microsoft\OneDrive\21.052.0314.0001\amd64\FileSyncShell64.dll
ModLoad: 00007ffc`1e5a0000 00007ffc`1e5aa000 C:\Windows\SYSTEM32\VERSION.dll
ModLoad: 00007ffc`1da00000 00007ffc`1dbbc000 C:\Windows\SYSTEM32\MFPlat.DLL
ModLoad: 00007ffc`1ae30000 00007ffc`1ae60000 C:\Windows\SYSTEM32\RTWorkQ.DLL
ModLoad: 00007ffb`ea1b0000 00007ffb`ea202000 C:\Windows\system32\stobject.dll
ModLoad: 00007ffc`1d800000 00007ffc`1d811000 C:\Windows\system32\WMICLNT.dll
ModLoad: 00007ffc`258c0000 00007ffc`25962000 C:\Windows\SYSTEM32\sxs.dll
ModLoad: 00007ffc`17ce0000 00007ffc`17cef000 C:\Windows\system32\BatMeter.dll
ModLoad: 00007ffb`ea120000 00007ffb`ea1a8000 C:\Windows\System32\InputSwitch.dll
ModLoad: 00007ffc`26f60000 00007ffc`273c9000 C:\Windows\System32\SETUPAPI.dll
ModLoad: 00007ffc`260e0000 00007ffc`26140000 C:\Windows\System32\WINTRUST.dll
ModLoad: 00007ffc`256a0000 00007ffc`256b2000 C:\Windows\System32\MSASN1.dll
ModLoad: 00007ffc`1dfc0000 00007ffc`1e011000 C:\Windows\System32\vaultcli.dll
ModLoad: 00007ffb`ea100000 00007ffb`ea10e000 C:\Windows\System32\Windows.UI.Shell.dll
ModLoad: 00007ffb`f33a0000 00007ffb`f34ea000 C:\Windows\System32\wpnapps.dll
ModLoad: 00007ffc`1cac0000 00007ffc`1caf6000 C:\Windows\System32\XmlLite.dll
ModLoad: 00007ffc`1f470000 00007ffc`1f4dc000 C:\Windows\system32\es.dll
ModLoad: 00007ffb`e9dd0000 00007ffb`e9e0e000 C:\Windows\system32\prnfldr.dll
ModLoad: 00007ffb`e9ed0000 00007ffb`e9efd000 C:\Windows\System32\DeviceSetupManagerAPI.dll
ModLoad: 00007ffb`e9e40000 00007ffb`e9ec3000 C:\Windows\system32\dxp.dll
ModLoad: 00007ffc`1a770000 00007ffc`1a77d000 C:\Windows\SYSTEM32\atlthunk.dll
ModLoad: 00007ffb`e9d70000 00007ffb`e9dc3000 C:\Windows\System32\Actioncenter.dll
ModLoad: 00007ffc`1f3a0000 00007ffc`1f405000 C:\Windows\System32\wevtapi.dll
ModLoad: 00007ffc`20c30000 00007ffc`20c3d000 C:\Windows\System32\SystemEventsBrokerClient.dll
ModLoad: 00007ffb`e9e20000 00007ffb`e9e39000 C:\Windows\system32\Syncreg.dll
ModLoad: 00007ffc`15e70000 00007ffc`15ed2000 C:\Windows\System32\Windows.FileExplorer.Common.dll
ModLoad: 00007ffc`1af30000 00007ffc`1af40000 C:\Windows\System32\npmproxy.dll
ModLoad: 00007ffb`f2410000 00007ffb`f2421000 C:\Windows\System32\dusmapi.dll
ModLoad: 00007ffb`e83e0000 00007ffb`e83f5000 C:\Windows\system32\wpdshserviceobj.dll
ModLoad: 00007ffc`231e0000 00007ffc`23212000 C:\Windows\System32\PortableDeviceTypes.dll
ModLoad: 00007ffc`23240000 00007ffc`232e3000 C:\Windows\System32\PortableDeviceApi.dll
ModLoad: 00007ffb`e83b0000 00007ffb`e83dd000 C:\Windows\system32\SettingMonitor.dll
ModLoad: 00007ffb`e82e0000 00007ffb`e83ad000 C:\Windows\System32\cscui.dll
ModLoad: 00007ffb`e8290000 00007ffb`e82e0000 C:\Windows\System32\cscobj.dll
ModLoad: 00007ffc`1e560000 00007ffc`1e597000 C:\Windows\SYSTEM32\CompPkgSup.DLL
ModLoad: 00007ffc`1efa0000 00007ffc`1f121000 C:\Windows\SYSTEM32\AUDIOSES.DLL
ModLoad: 00007ffb`e7580000 00007ffb`e75ba000 C:\Windows\System32\srchadmin.dll
ModLoad: 00007ffb`ecf30000 00007ffb`ecff6000 C:\Windows\SYSTEM32\windows.storage.search.dll
ModLoad: 00007ffb`e72d0000 00007ffb`e74e9000 C:\Windows\System32\pnidui.dll
ModLoad: 00007ffc`19b20000 00007ffc`19b2a000 C:\Windows\System32\MobileNetworking.dll
ModLoad: 00007ffc`20b60000 00007ffc`20b9e000 C:\Windows\System32\netprofm.dll
ModLoad: 00007ffb`e7240000 00007ffb`e72c3000 C:\Windows\System32\SyncCenter.dll
ModLoad: 00007ffb`f53e0000 00007ffb`f544d000 C:\Windows\System32\NetworkUXBroker.dll
ModLoad: 00007ffb`e71b0000 00007ffb`e7234000 C:\Windows\System32\imapi2.dll
ModLoad: 00007ffb`f53a0000 00007ffb`f53d4000 C:\Windows\System32\EthernetMediaManager.dll
ModLoad: 00007ffb`f4300000 00007ffb`f43bd000 C:\Windows\System32\WlanMediaManager.dll
ModLoad: 00007ffc`1c5e0000 00007ffc`1c64a000 C:\Windows\SYSTEM32\wlanapi.dll
ModLoad: 00007ffc`15f20000 00007ffc`15f58000 C:\Windows\System32\TetheringStation.dll
ModLoad: 00007ffc`15ee0000 00007ffc`15f17000 C:\Windows\System32\BluetoothApis.dll
ModLoad: 00007ffb`f31e0000 00007ffb`f323e000 C:\Windows\System32\wpnclient.dll
ModLoad: 00007ffb`e7160000 00007ffb`e71a6000 C:\Windows\System32\bthprops.cpl
ModLoad: 00007ffb`e7090000 00007ffb`e710e000 C:\Windows\System32\Windows.ApplicationModel.LockScreen.dll
ModLoad: 00007ffc`0e3a0000 00007ffc`0e3b2000 C:\Windows\System32\deviceassociation.dll
ModLoad: 00007ffb`e6db0000 00007ffb`e6de8000 C:\Windows\System32\NPSMDesktopProvider.dll
ModLoad: 00007ffc`21430000 00007ffc`21495000 C:\Windows\System32\BthAvctpSvc.dll
ModLoad: 00007ffc`21260000 00007ffc`21267000 C:\Windows\System32\WppRecorderUM.dll
ModLoad: 00007ffc`1ebb0000 00007ffc`1ec01000 C:\Windows\SYSTEM32\capauthz.dll
ModLoad: 00007ffb`e0490000 00007ffb`e0be4000 C:\Windows\system32\ieframe.DLL
ModLoad: 00007ffc`185f0000 00007ffc`18608000 C:\Windows\system32\NETAPI32.dll
ModLoad: 00007ffc`061c0000 00007ffc`068b6000 C:\Windows\SYSTEM32\D3D10Warp.dll
ModLoad: 00007ffb`edd40000 00007ffb`ee035000 C:\Windows\SYSTEM32\UIAutomationCore.DLL
ModLoad: 00007ffc`15b20000 00007ffc`15e4c000 C:\Windows\System32\msi.dll
ModLoad: 00007ffc`24b80000 00007ffc`24bb4000 C:\Windows\system32\rsaenh.dll
ModLoad: 00007ffb`ee990000 00007ffb`ee9ad000 C:\Windows\SYSTEM32\licensemanagerapi.dll
ModLoad: 00007ffb`fb430000 00007ffb`fb446000 C:\Windows\SYSTEM32\pcacli.dll
ModLoad: 00007ffb`fd8f0000 00007ffb`fd902000 C:\Windows\System32\sfc_os.dll
ModLoad: 00007ffc`17c30000 00007ffc`17c3c000 C:\Windows\SYSTEM32\Secur32.dll
ModLoad: 00007ffc`177b0000 00007ffc`177f2000 C:\Windows\SYSTEM32\MLANG.dll
ModLoad: 00007ffc`081c0000 00007ffc`09282000 C:\Windows\System32\Windows.UI.Xaml.dll
ModLoad: 00007ffb`be610000 00007ffb`be85b000 C:\Windows\ShellComponents\WindowsInternal.ComposableShell.Experiences.Switcher.dll
ModLoad: 00007ffb`ca2b0000 00007ffb`ca32d000 C:\Windows\ShellExperiences\TileControl.dll
ModLoad: 00007ffb`be3f0000 00007ffb`be601000 C:\Windows\ShellComponents\TaskFlowUI.dll
ModLoad: 00007ffb`f51c0000 00007ffb`f5261000 C:\Windows\System32\UiaManager.dll
ModLoad: 00007ffb`fa150000 00007ffb`fa18c000 C:\Windows\System32\wscinterop.dll
ModLoad: 00007ffb`fc0e0000 00007ffb`fc12d000 C:\Windows\System32\WSCAPI.dll
ModLoad: 00007ffc`1f7c0000 00007ffc`1f7d9000 C:\Windows\System32\wscui.cpl
ModLoad: 00007ffb`bbc60000 00007ffb`bbd3e000 C:\Windows\System32\werconcpl.dll
ModLoad: 00007ffc`23720000 00007ffc`237fb000 C:\Windows\System32\wer.dll
ModLoad: 00007ffc`1d190000 00007ffc`1d1e2000 C:\Windows\System32\framedynos.dll
ModLoad: 00007ffc`1ef80000 00007ffc`1ef94000 C:\Windows\System32\hcproviders.dll
ModLoad: 00007ffb`bbb80000 00007ffb`bbc5d000 C:\Windows\System32\ieproxy.dll
ModLoad: 00007ffc`1e060000 00007ffc`1e119000 C:\Windows\system32\SettingSync.dll
ModLoad: 00007ffb`b6b40000 00007ffb`b6b6f000 C:\Windows\SYSTEM32\storageusage.dll
ModLoad: 00007ffc`1e960000 00007ffc`1e9ca000 C:\Windows\System32\oobe\UserOOBE.dll
ModLoad: 00007ffb`e0cd0000 00007ffb`e0ce1000 C:\Windows\SYSTEM32\credui.dll
ModLoad: 00007ffc`0ca40000 00007ffc`0cbee000 C:\Windows\SYSTEM32\DUI70.dll
ModLoad: 00007ffc`1ea70000 00007ffc`1eab3000 C:\Windows\SYSTEM32\wdscore.dll
ModLoad: 00007ffc`1ba00000 00007ffc`1ba2c000 C:\Windows\SYSTEM32\dbgcore.DLL
ModLoad: 00007ffb`eec10000 00007ffb`eecd4000 C:\Windows\System32\ShellCommonCommonProxyStub.dll
ModLoad: 00007ffc`1ff10000 00007ffc`1ff67000 C:\Windows\SYSTEM32\prnntfy.dll
ModLoad: 00007ffc`175b0000 00007ffc`1763e000 C:\Windows\SYSTEM32\WINSPOOL.DRV
ModLoad: 00007ffc`1fed0000 00007ffc`1ff06000 C:\Windows\SYSTEM32\puiapi.dll
ModLoad: 00007ffc`1fe10000 00007ffc`1fec4000 C:\Windows\SYSTEM32\printui.dll
ModLoad: 00007ffc`1e8e0000 00007ffc`1e956000 C:\Windows\System32\puiobj.dll
ModLoad: 00007ffc`21720000 00007ffc`2172c000 C:\Windows\System32\nlmproxy.dll
ModLoad: 00007ffb`ee040000 00007ffb`ee11a000 C:\Windows\System32\windows.internal.shell.broker.dll
ModLoad: 00007ffc`1ec90000 00007ffc`1ed25000 C:\Windows\SYSTEM32\DUser.dll
ModLoad: 00007ffc`16600000 00007ffc`16644000 C:\Windows\System32\DesktopSwitcherDataModel.dll
ModLoad: 00007ffc`0b510000 00007ffc`0b543000 C:\Windows\System32\SwitcherDataModel.dll
ModLoad: 00007ffc`1f1b0000 00007ffc`1f23d000 C:\Windows\System32\Windows.Graphics.dll
ModLoad: 00007ffb`fb010000 00007ffb`fb024000 C:\Windows\System32\threadpoolwinrt.dll
ModLoad: 00007ffc`075b0000 00007ffc`0764e000 C:\Windows\system32\directmanipulation.dll
ModLoad: 00007ffc`078d0000 00007ffc`07cad000 C:\Windows\System32\Windows.UI.Xaml.Controls.dll
ModLoad: 00007ffb`e9f00000 00007ffb`ea024000 C:\Windows\System32\Windows.Services.TargetedContent.dll
ModLoad: 00007ffb`f43c0000 00007ffb`f46ed000 C:\Windows\system32\tquery.dll
ModLoad: 00007ffc`254b0000 00007ffc`254c5000 C:\Windows\system32\cryptdll.dll
ModLoad: 00007ffb`f3990000 00007ffb`f39d3000 C:\Windows\SYSTEM32\wuceffects.dll
ModLoad: 00007ffb`faae0000 00007ffb`fab34000 C:\Windows\SYSTEM32\msIso.dll
ModLoad: 00007ffb`f58d0000 00007ffb`f593a000 C:\Windows\SYSTEM32\searchfolder.dll
ModLoad: 00007ffc`0c380000 00007ffc`0c39b000 C:\Windows\SYSTEM32\usbui.dll
ModLoad: 00007ffc`18ff0000 00007ffc`1924f000 C:\Windows\System32\msxml6.dll
ModLoad: 00007ffc`1eb20000 00007ffc`1eb3d000 C:\Windows\System32\nlaapi.dll
ModLoad: 00007ffc`24350000 00007ffc`2435d000 C:\Windows\SYSTEM32\HID.DLL
ModLoad: 00007ffc`0d610000 00007ffc`0d643000 C:\Windows\system32\twext.dll
ModLoad: 00007ffc`0d510000 00007ffc`0d54d000 C:\Windows\System32\WorkfoldersShell.dll
ModLoad: 00007ffc`0d2e0000 00007ffc`0d335000 C:\Program Files\Windows Defender\shellext.dll
ModLoad: 00007ffc`28190000 00007ffc`281ad000 C:\Windows\System32\imagehlp.dll
ModLoad: 00007ffc`24360000 00007ffc`24383000 C:\Windows\SYSTEM32\gpapi.dll
ModLoad: 00007ffb`99580000 00007ffb`9ad1c000 C:\Program Files\Google\Drive File Stream\47.0.19.0\drivefsext.dll
ModLoad: 00007ffc`0d2c0000 00007ffc`0d2d9000 C:\Windows\system32\acppage.dll
ModLoad: 00000000`07c90000 00000000`07c93000 C:\Windows\system32\sfc.dll
ModLoad: 00007ffb`df540000 00007ffb`df592000 C:\Windows\System32\smartscreenps.dll
ModLoad: 00007ffb`f3ce0000 00007ffb`f3cea000 C:\Windows\SYSTEM32\msiltcfg.dll
ModLoad: 00007ffb`ea300000 00007ffb`ea32c000 C:\Windows\SYSTEM32\srpapi.dll
ModLoad: 00007ffb`df610000 00007ffb`df662000 C:\Windows\system32\shutdownux.dll
ModLoad: 00007ffc`09320000 00007ffc`09355000 C:\Windows\system32\WINBRAND.dll
ModLoad: 00007ffb`bbd50000 00007ffb`bbdc0000 C:\Windows\System32\fhcfg.dll
ModLoad: 00007ffb`f3380000 00007ffb`f3392000 C:\Windows\System32\EFSUTIL.dll
ModLoad: 00007ffc`1e9d0000 00007ffc`1e9da000 C:\Windows\System32\DSROLE.dll
ModLoad: 00007ffc`1e8a0000 00007ffc`1e8de000 C:\Windows\System32\Windows.Internal.System.UserProfile.dll
ModLoad: 00007ffb`e9490000 00007ffb`e94e5000 C:\Windows\System32\CloudExperienceHostBroker.dll
ModLoad: 00007ffb`b71a0000 00007ffb`b71f8000 C:\Windows\System32\dlnashext.dll
ModLoad: 00007ffb`e2ca0000 00007ffb`e2cd7000 C:\Windows\System32\EhStorShell.dll
ModLoad: 00007ffb`f3240000 00007ffb`f32c1000 C:\Windows\SYSTEM32\PhotoMetadataHandler.dll
ModLoad: 00007ffb`e9840000 00007ffb`e9865000 C:\Windows\SYSTEM32\CHARTV.dll
ModLoad: 00007ffb`e8ba0000 00007ffb`e8be9000 C:\Windows\system32\zipfldr.dll
ModLoad: 00007ffc`15e50000 00007ffc`15e69000 C:\Windows\SYSTEM32\elscore.dll
ModLoad: 00007ffc`0d800000 00007ffc`0d8b0000 C:\Windows\system32\ElsLad.dll
ModLoad: 00007ffb`ec9d0000 00007ffb`ecd18000 C:\Windows\SYSTEM32\msftedit.dll
ModLoad: 00007ffb`f9a20000 00007ffb`fa146000 C:\Windows\System32\Windows.Media.dll
ModLoad: 00007ffb`a6d50000 00007ffb`a71de000 C:\Windows\System32\MFCORE.dll
ModLoad: 00007ffc`1ed90000 00007ffc`1ed99000 C:\Windows\System32\ksuser.dll
ModLoad: 00007ffc`0d7a0000 00007ffc`0d7f2000 C:\Windows\SYSTEM32\mrmdeploy.dll
ModLoad: 00007ffc`18630000 00007ffc`18669000 C:\Windows\SYSTEM32\rstrtmgr.dll
ModLoad: 00007ffc`1fdb0000 00007ffc`1fdd3000 C:\Windows\System32\UserDataTimeUtil.dll
ModLoad: 00007ffb`ea560000 00007ffb`ea59b000 C:\Windows\SYSTEM32\rometadata.dll
ModLoad: 00007ffc`0ac90000 00007ffc`0acb5000 C:\Windows\System32\GraphicsCapture.dll
ModLoad: 00007ffc`1f410000 00007ffc`1f469000 C:\Windows\System32\execmodelclient.dll
ModLoad: 00007ffb`fba30000 00007ffb`fba48000 C:\Windows\system32\execmodelproxy.dll
(2140.60e0): Break instruction exception - code 80000003 (first chance)
ntdll!DbgBreakPoint:
00007ffc`28410810 cc int 3
0:131> ~
0 Id: 2140.23c8 Suspend: 1 Teb: 00000000`00a09000 Unfrozen
1 Id: 2140.2684 Suspend: 1 Teb: 00000000`00a27000 Unfrozen
2 Id: 2140.26c8 Suspend: 1 Teb: 00000000`00a2d000 Unfrozen
3 Id: 2140.26cc Suspend: 1 Teb: 00000000`00a2f000 Unfrozen
4 Id: 2140.26d0 Suspend: 1 Teb: 00000000`00a31000 Unfrozen
5 Id: 2140.26d8 Suspend: 1 Teb: 00000000`00a33000 Unfrozen
6 Id: 2140.26dc Suspend: 1 Teb: 00000000`00a35000 Unfrozen
7 Id: 2140.2708 Suspend: 1 Teb: 00000000`00a3b000 Unfrozen
8 Id: 2140.270c Suspend: 1 Teb: 00000000`00a3d000 Unfrozen
9 Id: 2140.2710 Suspend: 1 Teb: 00000000`00a3f000 Unfrozen
10 Id: 2140.2714 Suspend: 1 Teb: 00000000`00a41000 Unfrozen
11 Id: 2140.2720 Suspend: 1 Teb: 00000000`00a47000 Unfrozen
12 Id: 2140.2724 Suspend: 1 Teb: 00000000`00a49000 Unfrozen
13 Id: 2140.273c Suspend: 1 Teb: 00000000`00a4d000 Unfrozen
14 Id: 2140.2740 Suspend: 1 Teb: 00000000`00a4f000 Unfrozen
15 Id: 2140.2744 Suspend: 1 Teb: 00000000`00a51000 Unfrozen
16 Id: 2140.2748 Suspend: 1 Teb: 00000000`00a53000 Unfrozen
17 Id: 2140.274c Suspend: 1 Teb: 00000000`00a55000 Unfrozen
18 Id: 2140.2750 Suspend: 1 Teb: 00000000`00a57000 Unfrozen
19 Id: 2140.2754 Suspend: 1 Teb: 00000000`00a59000 Unfrozen
20 Id: 2140.2758 Suspend: 1 Teb: 00000000`00a5b000 Unfrozen
21 Id: 2140.2770 Suspend: 1 Teb: 00000000`00a65000 Unfrozen
22 Id: 2140.2774 Suspend: 1 Teb: 00000000`00a67000 Unfrozen
23 Id: 2140.2778 Suspend: 1 Teb: 00000000`00a69000 Unfrozen
24 Id: 2140.277c Suspend: 1 Teb: 00000000`00a6b000 Unfrozen
25 Id: 2140.27cc Suspend: 1 Teb: 00000000`00a75000 Unfrozen
26 Id: 2140.24c4 Suspend: 1 Teb: 00000000`00a7b000 Unfrozen
27 Id: 2140.1328 Suspend: 1 Teb: 00000000`00a7d000 Unfrozen
28 Id: 2140.24cc Suspend: 1 Teb: 00000000`00a7f000 Unfrozen
29 Id: 2140.2814 Suspend: 1 Teb: 00000000`00a83000 Unfrozen
30 Id: 2140.29d4 Suspend: 1 Teb: 00000000`00aa5000 Unfrozen
31 Id: 2140.29d8 Suspend: 1 Teb: 00000000`00aa7000 Unfrozen
32 Id: 2140.29e0 Suspend: 1 Teb: 00000000`00aa9000 Unfrozen
33 Id: 2140.29e8 Suspend: 1 Teb: 00000000`00aab000 Unfrozen
34 Id: 2140.29f0 Suspend: 1 Teb: 00000000`00aaf000 Unfrozen
35 Id: 2140.29f4 Suspend: 1 Teb: 00000000`00ab1000 Unfrozen
36 Id: 2140.29f8 Suspend: 1 Teb: 00000000`00ab3000 Unfrozen
37 Id: 2140.29fc Suspend: 1 Teb: 00000000`00ab5000 Unfrozen
38 Id: 2140.2a08 Suspend: 1 Teb: 00000000`00ab7000 Unfrozen
39 Id: 2140.2a60 Suspend: 1 Teb: 00000000`00abb000 Unfrozen
40 Id: 2140.2a64 Suspend: 1 Teb: 00000000`00abd000 Unfrozen
41 Id: 2140.2a68 Suspend: 1 Teb: 00000000`00abf000 Unfrozen
42 Id: 2140.2a6c Suspend: 1 Teb: 00000000`00ac1000 Unfrozen
43 Id: 2140.2a8c Suspend: 1 Teb: 00000000`00acf000 Unfrozen
44 Id: 2140.2a98 Suspend: 1 Teb: 00000000`00ad5000 Unfrozen
45 Id: 2140.2a9c Suspend: 1 Teb: 00000000`00ad7000 Unfrozen
46 Id: 2140.2aa0 Suspend: 1 Teb: 00000000`00ad9000 Unfrozen
47 Id: 2140.2f04 Suspend: 1 Teb: 00000000`00add000 Unfrozen
48 Id: 2140.3538 Suspend: 1 Teb: 00000000`00aef000 Unfrozen
49 Id: 2140.3df0 Suspend: 1 Teb: 00000000`00af1000 Unfrozen
50 Id: 2140.3fe8 Suspend: 1 Teb: 00000000`00af5000 Unfrozen
51 Id: 2140.d68 Suspend: 1 Teb: 00000000`00b1b000 Unfrozen
52 Id: 2140.3dfc Suspend: 1 Teb: 00000000`00a43000 Unfrozen
53 Id: 2140.830 Suspend: 1 Teb: 00000000`00b0f000 Unfrozen
54 Id: 2140.4468 Suspend: 1 Teb: 00000000`00b11000 Unfrozen
55 Id: 2140.158c Suspend: 1 Teb: 00000000`00b1d000 Unfrozen
56 Id: 2140.fac Suspend: 1 Teb: 00000000`00b93000 Unfrozen
57 Id: 2140.2838 Suspend: 1 Teb: 00000000`00ba3000 Unfrozen
58 Id: 2140.210c Suspend: 1 Teb: 00000000`00b95000 Unfrozen
59 Id: 2140.2048 Suspend: 1 Teb: 00000000`00a0f000 Unfrozen
60 Id: 2140.42cc Suspend: 1 Teb: 00000000`00b87000 Unfrozen
61 Id: 2140.4118 Suspend: 1 Teb: 00000000`00b89000 Unfrozen
62 Id: 2140.638 Suspend: 1 Teb: 00000000`00b03000 Unfrozen
63 Id: 2140.1310 Suspend: 1 Teb: 00000000`00b55000 Unfrozen
64 Id: 2140.35c4 Suspend: 1 Teb: 00000000`00aa1000 Unfrozen
65 Id: 2140.2650 Suspend: 2 Teb: 00000000`00aa3000 Unfrozen
66 Id: 2140.4860 Suspend: 1 Teb: 00000000`00bd9000 Unfrozen
67 Id: 2140.3680 Suspend: 2 Teb: 00000000`00b4f000 Unfrozen
68 Id: 2140.4eec Suspend: 2 Teb: 00000000`00ba9000 Unfrozen
69 Id: 2140.4964 Suspend: 1 Teb: 00000000`00bd7000 Unfrozen
70 Id: 2140.114 Suspend: 1 Teb: 00000000`00bdd000 Unfrozen
71 Id: 2140.200c Suspend: 2 Teb: 00000000`00a29000 Unfrozen
72 Id: 2140.11e8 Suspend: 2 Teb: 00000000`00b7d000 Unfrozen
73 Id: 2140.2958 Suspend: 2 Teb: 00000000`00b37000 Unfrozen
74 Id: 2140.37c4 Suspend: 1 Teb: 00000000`00a99000 Unfrozen
75 Id: 2140.1b4c Suspend: 1 Teb: 00000000`00ac5000 Unfrozen
76 Id: 2140.4130 Suspend: 1 Teb: 00000000`00ac7000 Unfrozen
77 Id: 2140.1b94 Suspend: 1 Teb: 00000000`00ae5000 Unfrozen
78 Id: 2140.49fc Suspend: 1 Teb: 00000000`00bcd000 Unfrozen
79 Id: 2140.4f08 Suspend: 1 Teb: 00000000`00bd1000 Unfrozen
80 Id: 2140.31dc Suspend: 2 Teb: 00000000`00b05000 Unfrozen
81 Id: 2140.11cc Suspend: 1 Teb: 00000000`00a00000 Unfrozen
82 Id: 2140.4dd4 Suspend: 2 Teb: 00000000`00ad1000 Unfrozen
83 Id: 2140.4304 Suspend: 2 Teb: 00000000`00b49000 Unfrozen
84 Id: 2140.5594 Suspend: 2 Teb: 00000000`00bcb000 Unfrozen
85 Id: 2140.10d4 Suspend: 2 Teb: 00000000`00af3000 Unfrozen
86 Id: 2140.59c0 Suspend: 1 Teb: 00000000`00b71000 Unfrozen
87 Id: 2140.54d4 Suspend: 1 Teb: 00000000`00b85000 Unfrozen
88 Id: 2140.4fa0 Suspend: 1 Teb: 00000000`00b8d000 Unfrozen
89 Id: 2140.5e68 Suspend: 1 Teb: 00000000`00b9d000 Unfrozen
90 Id: 2140.2244 Suspend: 1 Teb: 00000000`00ba5000 Unfrozen
91 Id: 2140.58d0 Suspend: 1 Teb: 00000000`00ba7000 Unfrozen
92 Id: 2140.1a3c Suspend: 1 Teb: 00000000`00bab000 Unfrozen
93 Id: 2140.56e0 Suspend: 1 Teb: 00000000`00bad000 Unfrozen
94 Id: 2140.2d44 Suspend: 1 Teb: 00000000`00baf000 Unfrozen
95 Id: 2140.5064 Suspend: 1 Teb: 00000000`00bb1000 Unfrozen
96 Id: 2140.15d4 Suspend: 1 Teb: 00000000`00bb3000 Unfrozen
97 Id: 2140.2ad0 Suspend: 1 Teb: 00000000`00bb5000 Unfrozen
98 Id: 2140.4178 Suspend: 1 Teb: 00000000`00bb7000 Unfrozen
99 Id: 2140.4d40 Suspend: 1 Teb: 00000000`00bb9000 Unfrozen
100 Id: 2140.5b90 Suspend: 1 Teb: 00000000`00bbb000 Unfrozen
101 Id: 2140.5bc4 Suspend: 1 Teb: 00000000`00bbd000 Unfrozen
102 Id: 2140.5e7c Suspend: 1 Teb: 00000000`00bbf000 Unfrozen
103 Id: 2140.55d8 Suspend: 1 Teb: 00000000`00bc1000 Unfrozen
104 Id: 2140.60ac Suspend: 1 Teb: 00000000`00bc3000 Unfrozen
105 Id: 2140.3eb8 Suspend: 1 Teb: 00000000`00bc5000 Unfrozen
106 Id: 2140.60e4 Suspend: 1 Teb: 00000000`00bc7000 Unfrozen
107 Id: 2140.5f9c Suspend: 1 Teb: 00000000`00bd5000 Unfrozen
108 Id: 2140.3730 Suspend: 1 Teb: 00000000`00bdf000 Unfrozen
109 Id: 2140.5d5c Suspend: 1 Teb: 00000000`00a04000 Unfrozen
110 Id: 2140.15bc Suspend: 1 Teb: 00000000`00a5f000 Unfrozen
111 Id: 2140.4634 Suspend: 1 Teb: 00000000`00a89000 Unfrozen
112 Id: 2140.c54 Suspend: 1 Teb: 00000000`00acd000 Unfrozen
113 Id: 2140.3334 Suspend: 1 Teb: 00000000`00adb000 Unfrozen
114 Id: 2140.2238 Suspend: 1 Teb: 00000000`00aeb000 Unfrozen
115 Id: 2140.5a5c Suspend: 1 Teb: 00000000`00aed000 Unfrozen
116 Id: 2140.4b1c Suspend: 1 Teb: 00000000`00af9000 Unfrozen
117 Id: 2140.5f5c Suspend: 1 Teb: 00000000`00b15000 Unfrozen
118 Id: 2140.5e94 Suspend: 1 Teb: 00000000`00b35000 Unfrozen
119 Id: 2140.5fa4 Suspend: 1 Teb: 00000000`00b3b000 Unfrozen
120 Id: 2140.d58 Suspend: 1 Teb: 00000000`00b3f000 Unfrozen
121 Id: 2140.510c Suspend: 1 Teb: 00000000`00b41000 Unfrozen
122 Id: 2140.127c Suspend: 1 Teb: 00000000`00b43000 Unfrozen
123 Id: 2140.130c Suspend: 1 Teb: 00000000`00b45000 Unfrozen
124 Id: 2140.2248 Suspend: 1 Teb: 00000000`00b47000 Unfrozen
125 Id: 2140.5a64 Suspend: 1 Teb: 00000000`00b4b000 Unfrozen
126 Id: 2140.2488 Suspend: 1 Teb: 00000000`00b4d000 Unfrozen
127 Id: 2140.3338 Suspend: 1 Teb: 00000000`00b51000 Unfrozen
128 Id: 2140.62f0 Suspend: 1 Teb: 00000000`00b53000 Unfrozen
129 Id: 2140.62e8 Suspend: 1 Teb: 00000000`00b57000 Unfrozen
130 Id: 2140.6208 Suspend: 1 Teb: 00000000`00b59000 Unfrozen
.131 Id: 2140.60e0 Suspend: 1 Teb: 00000000`00b5b000 Unfrozen
0:131> !locks
CritSec windows_storage!g_csIconCache+0 at 00007ffc242c49a0
WaiterWoken No
LockCount 2
RecursionCount 2
OwningThread 5a5c
EntryCount 0
ContentionCount 51f
*** Locked
Scanned 147 critical sections
0:131> ~~[5a5c]k
# Child-SP RetAddr Call Site
00 00000000`10e0d728 00007ffc`25c5165e ntdll!NtWaitForSingleObject+0x14
01 00000000`10e0d730 00007ffb`f18c1dff KERNELBASE!WaitForSingleObjectEx+0x8e
02 00000000`10e0d7d0 00007ffb`f18c1dc4 thumbcache!HrWaitForSingleObject+0xb
03 00000000`10e0d800 00007ffb`f18c205e thumbcache!CThumbnailCache::_AcquireInitializationMutex+0x74
04 00000000`10e0da60 00007ffb`f18c3213 thumbcache!CThumbnailCache::CAcquireInitializationMutex::CAcquireInitializationMutex+0x3a
05 00000000`10e0da90 00007ffb`f18ba16e thumbcache!CThumbnailCache::AttemptInitialize+0xab
06 00000000`10e0dda0 00007ffb`f18b8ca4 thumbcache!CThumbnailCache::_Initialize+0x46
07 00000000`10e0ddd0 00007ffc`2769145c thumbcache!CThumbnailCache::AddImage+0x64
08 00000000`10e0def0 00007ffc`2769159d SHELL32!CIconCache::AddSparseIcon+0x30c
09 00000000`10e0e1d0 00007ffc`27690525 SHELL32!CIconCache::AddToBackIconTable+0x85
0a 00000000`10e0e4a0 00007ffc`23c3037b SHELL32!AddToBackIconTable+0x49
0b 00000000`10e0e4d0 00007ffc`23cd1dd4 windows_storage!SHAddIconsToCache+0x7f
0c 00000000`10e0e510 00007ffc`23cd1722 windows_storage!_GetILIndexGivenPXIcon+0x210
0d 00000000`10e0e9c0 00007ffc`23cd30f8 windows_storage!_GetILIndexFromItem+0x7e
0e 00000000`10e0ea60 00007ffc`23cd46ec windows_storage!SHGetIconIndexFromPIDL+0x50
0f 00000000`10e0eaa0 00007ffc`276c8162 windows_storage!CFSFolder::GetIconOf+0x20c
10 00000000`10e0f460 00007ffc`276c7d9c SHELL32!SHGetIconIndexFromPIDL+0x46
11 00000000`10e0f4a0 00007ffc`276c7cdb SHELL32!_SHMapIDListToSystemImageListIndex+0x70
12 00000000`10e0f510 00007ffc`276523d1 SHELL32!CGetIconTask::InternalResumeRT+0x7b
13 00000000`10e0f570 00007ffc`263d8d10 SHELL32!CRunnableTask::Run+0xc1
14 00000000`10e0f5c0 00007ffc`263d8b10 shcore!WorkThreadManager::CThread::ThreadProc+0x1d0
15 00000000`10e0f850 00007ffc`263d80f9 shcore!WorkThreadManager::CThread::s_ExecuteThreadProc+0x18
16 00000000`10e0f880 00007ffc`283e0c09 shcore!<lambda_142c425290ac4fbd4d5aee2fc3f7d711>::<lambda_invoker_cdecl>+0x29
17 00000000`10e0f8b0 00007ffc`283c315a ntdll!TppSimplepExecuteCallback+0x99
18 00000000`10e0f900 00007ffc`26e57034 ntdll!TppWorkerThread+0x68a
19 00000000`10e0fc00 00007ffc`283c2651 KERNEL32!BaseThreadInitThunk+0x14
1a 00000000`10e0fc30 00000000`00000000 ntdll!RtlUserThreadStart+0x21
0:131> ~~[5a5c]s
ntdll!NtWaitForSingleObject+0x14:
00007ffc`2840cda4 c3 ret
0:115> .frame 2
02 00000000`10e0d7d0 00007ffb`f18c1dc4 thumbcache!HrWaitForSingleObject+0xb
0:115> r
rax=0000000000000004 rbx=0000000000000000 rcx=00000000000038a0
rdx=0000000000000000 rsi=0000000000000000 rdi=00000000000038a0
rip=00007ffc2840cda4 rsp=0000000010e0d728 rbp=0000000010e0db90
r8=0000000029480090 r9=00000000000003d0 r10=0000000000ef0d20
r11=0000000000000246 r12=0000000010e0e4f0 r13=00000000050ca620
r14=00000000000038a0 r15=00007ffbf18f65d8
iopl=0 nv up ei pl zr na po nc
cs=0033 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00000244
ntdll!NtWaitForSingleObject+0x14:
00007ffc`2840cda4 c3 ret
0:115> !handle 38a0 f
Handle 38a0
Type Mutant
Attributes 0
GrantedAccess 0x1f0001:
Delete,ReadControl,WriteDac,WriteOwner,Synch
QueryState
HandleCount 43
PointerCount 1408974
Name \BaseNamedObjects\C::Users:mcdurdin:AppData:Local:Microsoft:Windows:Explorer:iconcache_idx.db!IconCacheInit
Object Specific Information
Mutex is Owned
Mutant Owner 2140.2244
0:115> ~~[2244]s
ntdll!NtWaitForSingleObject+0x14:
00007ffc`2840cda4 c3 ret
0:090> k
# Child-SP RetAddr Call Site
00 00000000`1943e948 00007ffc`25c5165e ntdll!NtWaitForSingleObject+0x14
01 00000000`1943e950 00007ffb`f18c1dff KERNELBASE!WaitForSingleObjectEx+0x8e
02 00000000`1943e9f0 00007ffb`f18c1ae2 thumbcache!HrWaitForSingleObject+0xb
03 00000000`1943ea20 00007ffb`f18c15a7 thumbcache!CThumbnailCache::_EnsureCacheFile+0x482
04 00000000`1943ec90 00007ffb`f18c4783 thumbcache!CThumbnailCache::_AddThumbnailToCache+0xb3
05 00000000`1943ed30 00007ffb`f18b8e22 thumbcache!CThumbnailCache::_AddBitmapToCache+0xaf
06 00000000`1943edc0 00007ffc`276923d1 thumbcache!CThumbnailCache::AddImage+0x1e2
07 00000000`1943eee0 00007ffc`27693603 SHELL32!CIconCache::SaveIcon+0x4f1
08 00000000`1943f250 00007ffc`0edab7ad SHELL32!CSparseCallback::ForceImagePresent+0x383
09 00000000`1943f580 00007ffc`0edab600 comctl32!CSparseImageList::_Callback_ForceImagePresent+0xa1
0a 00000000`1943f5d0 00007ffc`0ed9c453 comctl32!CSparseImageList::ForceImagePresent+0x100
0b 00000000`1943f620 00007ff7`9fd9948e comctl32!CImageListContainerBase::ForceImagePresent+0xa3
0c 00000000`1943f6b0 00007ff7`9fd99671 Explorer!ShellIconLoader::s_ForceImagePresent+0x96
0d 00000000`1943f6f0 00007ff7`9fd9ab49 Explorer!ShellIconLoader::s_SetIconAsync+0x31
0e 00000000`1943f730 00007ff7`9fddaaf0 Explorer!ShellIconLoader::CLoadIconTask::InternalResumeRT+0x19
0f 00000000`1943f760 00007ffc`263d8d10 Explorer!CRunnableTask::Run+0xb0
10 00000000`1943f790 00007ffc`263d8b10 shcore!WorkThreadManager::CThread::ThreadProc+0x1d0
11 00000000`1943fa20 00007ffc`263d8541 shcore!WorkThreadManager::CThread::s_ExecuteThreadProc+0x18
12 00000000`1943fa50 00007ffc`26e57034 shcore!<lambda_9844335fc14345151eefcc3593dd6895>::<lambda_invoker_cdecl>+0x11
13 00000000`1943fa80 00007ffc`283c2651 KERNEL32!BaseThreadInitThunk+0x14
14 00000000`1943fab0 00000000`00000000 ntdll!RtlUserThreadStart+0x21
0:090> .frame 2
02 00000000`1943e9f0 00007ffb`f18c1ae2 thumbcache!HrWaitForSingleObject+0xb
0:090> r
rax=0000000000000004 rbx=0000000000000000 rcx=0000000000004270
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000004270
rip=00007ffc2840cda4 rsp=000000001943e948 rbp=000000001943eb20
r8=0000000000000000 r9=0000000026da0000 r10=0000000000000000
r11=0000000012b9a510 r12=ffffffffffffffff r13=0000000000000000
r14=0000000000004270 r15=0000000000000001
iopl=0 nv up ei pl zr na po nc
cs=0033 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00000244
ntdll!NtWaitForSingleObject+0x14:
00007ffc`2840cda4 c3 ret
0:090> !handle 4270 f
Handle 4270
Type Mutant
Attributes 0
GrantedAccess 0x1f0001:
Delete,ReadControl,WriteDac,WriteOwner,Synch
QueryState
HandleCount 43
PointerCount 327674
Name \BaseNamedObjects\C::Users:mcdurdin:AppData:Local:Microsoft:Windows:Explorer:iconcache_32.db!dfMaintainer
Object Specific Information
Mutex is Owned
Mutant Owner 2140.5e68
0:090> ~~[5e68]s
ntdll!NtWaitForSingleObject+0x14:
00007ffc`2840cda4 c3 ret
0:089> k
# Child-SP RetAddr Call Site
00 00000000`1979e348 00007ffc`25c5165e ntdll!NtWaitForSingleObject+0x14
01 00000000`1979e350 00007ffb`f18c1dff KERNELBASE!WaitForSingleObjectEx+0x8e
02 00000000`1979e3f0 00007ffb`f18bc3d4 thumbcache!HrWaitForSingleObject+0xb
03 00000000`1979e420 00007ffb`f18b99b4 thumbcache!CReadersWriterLock::AcquireWriterLock+0xe4
04 00000000`1979e450 00007ffb`f18b98e0 thumbcache!CThumbnailCacheIndex::Delete+0x60
05 00000000`1979e4f0 00007ffb`f18c0f2a thumbcache!CThumbnailCacheDataFile::_TryReplaceThumbnail+0x60
06 00000000`1979e550 00007ffb`f18c1422 thumbcache!CThumbnailCacheDataFile::StoreThumbnailStream+0xb6
07 00000000`1979e5f0 00007ffb`f18c15e7 thumbcache!CThumbnailCacheDataFile::StoreThumbnail+0x142
08 00000000`1979e6a0 00007ffb`f18c4783 thumbcache!CThumbnailCache::_AddThumbnailToCache+0xf3
09 00000000`1979e740 00007ffb`f18b8e22 thumbcache!CThumbnailCache::_AddBitmapToCache+0xaf
0a 00000000`1979e7d0 00007ffc`276923d1 thumbcache!CThumbnailCache::AddImage+0x1e2
0b 00000000`1979e8f0 00007ffc`27693603 SHELL32!CIconCache::SaveIcon+0x4f1
0c 00000000`1979ec60 00007ffc`0edab7ad SHELL32!CSparseCallback::ForceImagePresent+0x383
0d 00000000`1979ef90 00007ffc`0edab600 comctl32!CSparseImageList::_Callback_ForceImagePresent+0xa1
0e 00000000`1979efe0 00007ffc`0ed9c453 comctl32!CSparseImageList::ForceImagePresent+0x100
0f 00000000`1979f030 00007ff7`9fd9948e comctl32!CImageListContainerBase::ForceImagePresent+0xa3
10 00000000`1979f0c0 00007ff7`9fd99671 Explorer!ShellIconLoader::s_ForceImagePresent+0x96
11 00000000`1979f100 00007ff7`9fd9ab49 Explorer!ShellIconLoader::s_SetIconAsync+0x31
12 00000000`1979f140 00007ff7`9fddaaf0 Explorer!ShellIconLoader::CLoadIconTask::InternalResumeRT+0x19
13 00000000`1979f170 00007ffc`263d8d10 Explorer!CRunnableTask::Run+0xb0
14 00000000`1979f1a0 00007ffc`263d8b10 shcore!WorkThreadManager::CThread::ThreadProc+0x1d0
15 00000000`1979f430 00007ffc`263d80f9 shcore!WorkThreadManager::CThread::s_ExecuteThreadProc+0x18
16 00000000`1979f460 00007ffc`283e0c09 shcore!<lambda_142c425290ac4fbd4d5aee2fc3f7d711>::<lambda_invoker_cdecl>+0x29
17 00000000`1979f490 00007ffc`283c315a ntdll!TppSimplepExecuteCallback+0x99
18 00000000`1979f4e0 00007ffc`26e57034 ntdll!TppWorkerThread+0x68a
19 00000000`1979f7e0 00007ffc`283c2651 KERNEL32!BaseThreadInitThunk+0x14
1a 00000000`1979f810 00000000`00000000 ntdll!RtlUserThreadStart+0x21
0:089> .frame 2
02 00000000`1979e3f0 00007ffb`f18bc3d4 thumbcache!HrWaitForSingleObject+0xb
0:089> r
rax=0000000000000004 rbx=0000000000000000 rcx=0000000000002cf0
rdx=0000000000000000 rsi=000000001979e378 rdi=0000000000002cf0
rip=00007ffc2840cda4 rsp=000000001979e348 rbp=0000000000000000
r8=000000001979e250 r9=000000001979e240 r10=0000000000000000
r11=000000001979e288 r12=0000000000000001 r13=0000000000000002
r14=0000000000002cf0 r15=9cfdff9ae44b0326
iopl=0 nv up ei pl zr na po nc
cs=0033 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00000244
ntdll!NtWaitForSingleObject+0x14:
00007ffc`2840cda4 c3 ret
0:089> !handle 2cf0 f
Handle 2cf0
Type Event
Attributes 0
GrantedAccess 0x1f0003:
Delete,ReadControl,WriteDac,WriteOwner,Synch
QueryState,ModifyState
HandleCount 43
PointerCount 881153
Name \BaseNamedObjects\C::Users:mcdurdin:AppData:Local:Microsoft:Windows:Explorer:iconcache_idx.db!rwWriterEvent
Object Specific Information
Event Type Manual Reset
Event is Waiting
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment