Microsoft (R) Windows User-Mode Debugger Version 5.1.2600.0 Copyright (c) Microsoft Corporation. All rights reserved. CommandLine: "C:\Documents and Settings\Stefan\Downloads\EXAMPLE.EXE" Loaded dbghelp extension DLL Loaded exts extension DLL Loaded ntsdexts extension DLL Symbol search path is: SymSrv*SYMSRV.DLL*C:\Windows\Symbols*http://msdl.microsoft.com/download/symbols/ Executable search path is: ModLoad: 00400000 00403000 image00400000 ModLoad: 7c910000 7c9ca000 ntdll.dll AVRF: EXAMPLE.EXE: pid 0x4860: flags 0x80000000: application verifier enabled ModLoad: 77da0000 77e4a000 C:\Windows\System32\ADVAPI32.DLL ModLoad: 7c800000 7c909000 C:\Windows\System32\KERNEL32.dll ModLoad: 77e50000 77ee3000 C:\Windows\System32\RPCRT4.dll ModLoad: 77fc0000 77fd1000 C:\Windows\System32\Secur32.dll ModLoad: 5b080000 5b0c9000 C:\Windows\System32\verifier.dll ModLoad: 10000000 1000b000 C:\Windows\System32\VrfKnthk.Dll VrfKnthk!DllMain(0x10000000, 0x00000004 = DLL_PROCESS_VERIFIER, 0x0012FAD8) AVRF: verifier.dll provider initialized for EXAMPLE.EXE with flags 0x80000000 VrfKnthk!DllMain(0x10000000, 0x00000001 = DLL_PROCESS_ATTACH, 0x00000000) VrfKnthk!DllMain: VerifierImage = 0x000208B0 = EXAMPLE.EXE, VerifierFlags = 0x80000000, VerifierDebug = 0x00000000 VrfKnthk!DllLoad: module 'EXAMPLE.EXE' loaded at 0x00400000, size 0x00003000 Break instruction exception - code 80000003 (first chance) eax=00351ec4 ebx=7ffda000 ecx=00000000 edx=00000001 esi=00351f98 edi=00351ec4 eip=7c91120e esp=0012fb20 ebp=0012fc94 iopl=0 nv up ei pl nz na pe nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202 *** ERROR: Symbol file could not be found. Defaulted to export symbols for ntdll.dll - ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g LoadLibraryA(C:\Windows\System32\CRYPTUI.DLL) ModLoad: 76880000 76905000 C:\Windows\System32\CRYPTUI.DLL ModLoad: 77a50000 77ae8000 C:\Windows\System32\CRYPT32.dll ModLoad: 77af0000 77b02000 C:\Windows\System32\MSASN1.dll ModLoad: 77be0000 77c38000 C:\Windows\System32\msvcrt.dll VrfKnthk!DllLoad: module 'msvcrt.dll' loaded at 0x77BE0000, size 0x00058000 ModLoad: 7e360000 7e3f1000 C:\Windows\System32\USER32.dll ModLoad: 77ef0000 77f3a000 C:\Windows\System32\GDI32.dll VrfKnthk!DllLoad: module 'GDI32.dll' loaded at 0x77EF0000, size 0x0004A000 VrfKnthk!DllLoad: module 'USER32.dll' loaded at 0x7E360000, size 0x00091000 VrfKnthk!DllLoad: module 'MSASN1.dll' loaded at 0x77AF0000, size 0x00012000 VrfKnthk!DllLoad: module 'CRYPT32.dll' loaded at 0x77A50000, size 0x00098000 ModLoad: 597d0000 59825000 C:\Windows\System32\NETAPI32.dll VrfKnthk!DllLoad: module 'NETAPI32.dll' loaded at 0x597D0000, size 0x00055000 ModLoad: 770f0000 7717b000 C:\Windows\System32\OLEAUT32.dll ModLoad: 774b0000 775ee000 C:\Windows\System32\ole32.dll VrfKnthk!DllLoad: module 'ole32.dll' loaded at 0x774B0000, size 0x0013E000 VrfKnthk!DllLoad: module 'OLEAUT32.dll' loaded at 0x770F0000, size 0x0008B000 ModLoad: 77f40000 77fb7000 C:\Windows\System32\SHLWAPI.dll VrfKnthk!DllLoad: module 'SHLWAPI.dll' loaded at 0x77F40000, size 0x00077000 ModLoad: 77bd0000 77bd8000 C:\Windows\System32\VERSION.dll VrfKnthk!DllLoad: module 'VERSION.dll' loaded at 0x77BD0000, size 0x00008000 ModLoad: 77180000 7722b000 C:\Windows\System32\WININET.dll VrfKnthk!DllLoad: module 'WININET.dll' loaded at 0x77180000, size 0x000AB000 ModLoad: 76bf0000 76c1e000 C:\Windows\System32\WINTRUST.dll ModLoad: 76c50000 76c79000 C:\Windows\System32\IMAGEHLP.dll VrfKnthk!DllLoad: module 'IMAGEHLP.dll' loaded at 0x76C50000, size 0x00029000 VrfKnthk!DllLoad: module 'WINTRUST.dll' loaded at 0x76BF0000, size 0x0002E000 ModLoad: 76f20000 76f4d000 C:\Windows\System32\WLDAP32.dll VrfKnthk!DllLoad: module 'WLDAP32.dll' loaded at 0x76F20000, size 0x0002D000 VrfKnthk!DllLoad: module 'CRYPTUI.DLL' loaded at 0x76880000, size 0x00085000 LoadLibraryW(C:\Windows\System32\IMM32.DLL) ModLoad: 76330000 7634d000 C:\Windows\System32\IMM32.DLL VrfKnthk!DllLoad: module 'IMM32.DLL' loaded at 0x76330000, size 0x0001D000 LoadLibraryW(C:\Windows\System32\APPINIT.DLL) ModLoad: 01e90000 01e96000 C:\Windows\System32\APPINIT.DLL VrfKnthk!DllLoad: module 'APPINIT.DLL' loaded at 0x01E90000, size 0x00006000 VrfKnthk!DllUnload: module 'APPINIT.DLL' unloaded from 0x01E90000, size 0x00006000 LoadLibraryA(advapi32.dll) =========================================================== VERIFIER STOP 0000FFFE: pid 0x4860: The application or a component it uses called LoadLibrary*() with the filename or pathname of a not existing file (which might be searched via PATH). 7C801B21 : LoadLibraryA 77A56EB0 : advapi32.dll 77A56566 : CRYPT32.dll+0x00006566 77A576E4 : CRYPT32.dll+0x000076E4 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=77a56eb0 ecx=7c92f927 edx=0012f10c esi=0000fffe edi=7c801b21 eip=7c91120e esp=0012f340 ebp=0012f354 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g =========================================================== VERIFIER STOP 0000FFFF: pid 0x4860: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C801B21 : LoadLibraryA 77A56EB0 : advapi32.dll 77A56566 : CRYPT32.dll+0x00006566 77A576E4 : CRYPT32.dll+0x000076E4 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=77a56eb0 ecx=7c92f927 edx=0012f10c esi=0000ffff edi=7c801b21 eip=7c91120e esp=0012f340 ebp=0012f354 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g LoadLibraryA(kernel32.dll) =========================================================== VERIFIER STOP 0000FFFE: pid 0x4860: The application or a component it uses called LoadLibrary*() with the filename or pathname of a not existing file (which might be searched via PATH). 7C801B21 : LoadLibraryA 77A5455C : kernel32.dll 77A57982 : CRYPT32.dll+0x00007982 77A51932 : CRYPT32.dll+0x00001932 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=77a5455c ecx=7c92f927 edx=0012f0ec esi=0000fffe edi=7c801b21 eip=7c91120e esp=0012f320 ebp=0012f334 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g =========================================================== VERIFIER STOP 0000FFFF: pid 0x4860: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C801B21 : LoadLibraryA 77A5455C : kernel32.dll 77A57982 : CRYPT32.dll+0x00007982 77A51932 : CRYPT32.dll+0x00001932 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=77a5455c ecx=7c92f927 edx=0012f0ec esi=0000ffff edi=7c801b21 eip=7c91120e esp=0012f320 ebp=0012f334 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g LoadLibraryA(advapi32.dll) =========================================================== VERIFIER STOP 0000FFFE: pid 0x4860: The application or a component it uses called LoadLibrary*() with the filename or pathname of a not existing file (which might be searched via PATH). 7C801B21 : LoadLibraryA 0012F554 : advapi32.dll 77AF35EA : MSASN1.dll+0x000035EA 77AF3570 : MSASN1.dll+0x00003570 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=0012f554 ecx=7c92f927 edx=0012f044 esi=0000fffe edi=7c801b21 eip=7c91120e esp=0012f278 ebp=0012f28c iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g =========================================================== VERIFIER STOP 0000FFFF: pid 0x4860: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C801B21 : LoadLibraryA 0012F554 : advapi32.dll 77AF35EA : MSASN1.dll+0x000035EA 77AF3570 : MSASN1.dll+0x00003570 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=0012f554 ecx=7c92f927 edx=0012f044 esi=0000ffff edi=7c801b21 eip=7c91120e esp=0012f278 ebp=0012f28c iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g LoadLibraryW(comctl32.dll) =========================================================== VERIFIER STOP 0000FFFF: pid 0x4860: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C80B00B : LoadLibraryW 771A1120 : comctl32.dll 77F5A6E7 : SHLWAPI.dll+0x0001A6E7 771A1168 : WININET.dll+0x00021168 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=771a1120 ecx=7c92f927 edx=0012e94c esi=0000ffff edi=7c80b00b eip=7c91120e esp=0012eb80 ebp=0012eb94 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g ModLoad: 773a0000 774a3000 C:\Windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll VrfKnthk!DllLoad: module 'comctl32.dll' loaded at 0x773A0000, size 0x00103000 LoadLibraryW(Comctl32.dll) =========================================================== VERIFIER STOP 0000FFFF: pid 0x4860: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C80B00B : LoadLibraryW 768817BC : Comctl32.dll 7688198D : CRYPTUI.DLL+0x0000198D 76881A69 : CRYPTUI.DLL+0x00001A69 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=768817bc ecx=7c92f927 edx=0012ed30 esi=0000ffff edi=7c80b00b eip=7c91120e esp=0012ef64 ebp=0012ef78 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g LoadLibraryA(RichEd20.dll) =========================================================== VERIFIER STOP 0000FFFF: pid 0x4860: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C801B21 : LoadLibraryA 768817D8 : RichEd20.dll 76881DD8 : CRYPTUI.DLL+0x00001DD8 76881D80 : CRYPTUI.DLL+0x00001D80 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=768817d8 ecx=7c92f927 edx=0012f0ec esi=0000ffff edi=7c801b21 eip=7c91120e esp=0012f320 ebp=0012f334 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g ModLoad: 01ea0000 01ea9000 C:\Documents and Settings\Stefan\Downloads\RichEd20.dll VrfKnthk!DllLoad: module 'RichEd20.dll' loaded at 0x01EA0000, size 0x00009000 LoadLibraryW(rpcrt4.dll) =========================================================== VERIFIER STOP 0000FFFE: pid 0x4860: The application or a component it uses called LoadLibrary*() with the filename or pathname of a not existing file (which might be searched via PATH). 7C80B00B : LoadLibraryW 77E5ED50 : rpcrt4.dll 77E6B525 : RPCRT4.dll+0x0001B525 77E6B83A : RPCRT4.dll+0x0001B83A =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=77e5ed50 ecx=7c92f927 edx=0012e034 esi=0000fffe edi=7c80b00b eip=7c91120e esp=0012e268 ebp=0012e27c iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g =========================================================== VERIFIER STOP 0000FFFF: pid 0x4860: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C80B00B : LoadLibraryW 77E5ED50 : rpcrt4.dll 77E6B525 : RPCRT4.dll+0x0001B525 77E6B83A : RPCRT4.dll+0x0001B83A =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=77e5ed50 ecx=7c92f927 edx=0012e034 esi=0000ffff edi=7c80b00b eip=7c91120e esp=0012e268 ebp=0012e27c iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g VrfKnthk!DllUnload: module 'RichEd20.dll' unloaded from 0x01EA0000, size 0x00009000 LoadLibraryW(Comctl32.dll) =========================================================== VERIFIER STOP 0000FFFF: pid 0x4860: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C80B00B : LoadLibraryW 768817BC : Comctl32.dll 76881CA1 : CRYPTUI.DLL+0x00001CA1 76881C22 : CRYPTUI.DLL+0x00001C22 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=768817bc ecx=7c92f927 edx=0012ef5c esi=0000ffff edi=7c80b00b eip=7c91120e esp=0012f190 ebp=0012f1a4 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g VrfKnthk!DllUnload: module 'CRYPTUI.DLL' unloaded from 0x76880000, size 0x00085000 VrfKnthk!DllUnload: module 'WLDAP32.dll' unloaded from 0x76F20000, size 0x0002D000 VrfKnthk!DllUnload: module 'WINTRUST.dll' unloaded from 0x76BF0000, size 0x0002E000 VrfKnthk!DllUnload: module 'IMAGEHLP.dll' unloaded from 0x76C50000, size 0x00029000 VrfKnthk!DllUnload: module 'WININET.dll' unloaded from 0x77180000, size 0x000AB000 VrfKnthk!DllUnload: module 'VERSION.dll' unloaded from 0x77BD0000, size 0x00008000 VrfKnthk!DllUnload: module 'OLEAUT32.dll' unloaded from 0x770F0000, size 0x0008B000 VrfKnthk!DllUnload: module 'ole32.dll' unloaded from 0x774B0000, size 0x0013E000 VrfKnthk!DllUnload: module 'NETAPI32.dll' unloaded from 0x597D0000, size 0x00055000 VrfKnthk!DllUnload: module 'CRYPT32.dll' unloaded from 0x77A50000, size 0x00098000 VrfKnthk!DllUnload: module 'MSASN1.dll' unloaded from 0x77AF0000, size 0x00012000 VrfKnthk!DllMain(0x10000000, 0x00000000 = DLL_PROCESS_DETACH, 0x00000001) VrfKnthk!DllMain: VerifierImage = 0x000208B0 = EXAMPLE.EXE, VerifierFlags = 0x80000000, VerifierDebug = 0x00000000 eax=00000000 ebx=00000000 ecx=7c800000 edx=7c98f120 esi=7c91de6e edi=00000000 eip=7c91e514 esp=0012fea8 ebp=0012ffa4 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!KiFastSystemCallRet: 7c91e514 c3 ret 0:000> q