Microsoft (R) Windows User-Mode Debugger Version 5.1.2600.0 Copyright (c) Microsoft Corporation. All rights reserved. CommandLine: "C:\Documents and Settings\Stefan\Downloads\EXAMPLE.EXE" Loaded dbghelp extension DLL Loaded exts extension DLL Loaded ntsdexts extension DLL Symbol search path is: SymSrv*SYMSRV.DLL*C:\Windows\Symbols*http://msdl.microsoft.com/download/symbols/ Executable search path is: ModLoad: 00400000 00403000 image00400000 ModLoad: 7c910000 7c9ca000 ntdll.dll AVRF: EXAMPLE.EXE: pid 0xC27C: flags 0x80000000: application verifier enabled ModLoad: 77da0000 77e4a000 C:\Windows\System32\ADVAPI32.DLL ModLoad: 7c800000 7c909000 C:\Windows\System32\KERNEL32.dll ModLoad: 77e50000 77ee3000 C:\Windows\System32\RPCRT4.dll ModLoad: 77fc0000 77fd1000 C:\Windows\System32\Secur32.dll ModLoad: 5b080000 5b0c9000 C:\Windows\System32\verifier.dll ModLoad: 10000000 1000b000 C:\Windows\System32\VrfKnthk.Dll VrfKnthk!DllMain(0x10000000, 0x00000004 = DLL_PROCESS_VERIFIER, 0x0012FAD8) AVRF: verifier.dll provider initialized for EXAMPLE.EXE with flags 0x80000000 VrfKnthk!DllMain(0x10000000, 0x00000001 = DLL_PROCESS_ATTACH, 0x00000000) VrfKnthk!DllMain: VerifierImage = 0x000208B0 = EXAMPLE.EXE, VerifierFlags = 0x80000000, VerifierDebug = 0x00000000 VrfKnthk!DllLoad: module 'EXAMPLE.EXE' loaded at 0x00400000, size 0x00003000 Break instruction exception - code 80000003 (first chance) eax=00351ec4 ebx=7ffdd000 ecx=00000000 edx=00000001 esi=00351f98 edi=00351ec4 eip=7c91120e esp=0012fb20 ebp=0012fc94 iopl=0 nv up ei pl nz na pe nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202 *** ERROR: Symbol file could not be found. Defaulted to export symbols for ntdll.dll - ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g LoadLibraryA(C:\Program Files\Common Files\System\WAB32.DLL) ModLoad: 471b0000 47231000 C:\Program Files\Common Files\System\WAB32.DLL ModLoad: 01560000 0156b000 C:\Documents and Settings\Stefan\Downloads\MSOERT2.dll ModLoad: 7e360000 7e3f1000 C:\Windows\System32\USER32.dll ModLoad: 77ef0000 77f3a000 C:\Windows\System32\GDI32.dll VrfKnthk!DllLoad: module 'GDI32.dll' loaded at 0x77EF0000, size 0x0004A000 VrfKnthk!DllLoad: module 'USER32.dll' loaded at 0x7E360000, size 0x00091000 VrfKnthk!DllLoad: module 'MSOERT2.dll' loaded at 0x01560000, size 0x0000B000 ModLoad: 76830000 76852000 C:\Windows\System32\MSOERT2.dll ModLoad: 774b0000 775ee000 C:\Windows\System32\ole32.dll ModLoad: 77be0000 77c38000 C:\Windows\System32\msvcrt.dll VrfKnthk!DllLoad: module 'msvcrt.dll' loaded at 0x77BE0000, size 0x00058000 VrfKnthk!DllLoad: module 'ole32.dll' loaded at 0x774B0000, size 0x0013E000 ModLoad: 77f40000 77fb7000 C:\Windows\System32\SHLWAPI.dll VrfKnthk!DllLoad: module 'SHLWAPI.dll' loaded at 0x77F40000, size 0x00077000 ModLoad: 770f0000 7717b000 C:\Windows\System32\OLEAUT32.dll VrfKnthk!DllLoad: module 'OLEAUT32.dll' loaded at 0x770F0000, size 0x0008B000 VrfKnthk!DllLoad: module 'MSOERT2.dll' loaded at 0x76830000, size 0x00022000 ModLoad: 7e670000 7ee92000 C:\Windows\System32\SHELL32.dll VrfKnthk!DllLoad: module 'SHELL32.dll' loaded at 0x7E670000, size 0x00822000 VrfKnthk!DllLoad: module 'WAB32.DLL' loaded at 0x471B0000, size 0x00081000 LoadLibraryW(C:\Windows\System32\IMM32.DLL) ModLoad: 76330000 7634d000 C:\Windows\System32\IMM32.DLL VrfKnthk!DllLoad: module 'IMM32.DLL' loaded at 0x76330000, size 0x0001D000 LoadLibraryW(C:\Windows\System32\APPINIT.DLL) ModLoad: 01d70000 01d76000 C:\Windows\System32\APPINIT.DLL VrfKnthk!DllLoad: module 'APPINIT.DLL' loaded at 0x01D70000, size 0x00006000 VrfKnthk!DllUnload: module 'APPINIT.DLL' unloaded from 0x01D70000, size 0x00006000 LoadLibraryW(rpcrt4.dll) =========================================================== VERIFIER STOP 0000FFFE: pid 0xC27C: The application or a component it uses called LoadLibrary*() with the filename or pathname of a not existing file (which might be searched via PATH). 7C80B00B : LoadLibraryW 77E5ED50 : rpcrt4.dll 77E6B525 : RPCRT4.dll+0x0001B525 77E6B83A : RPCRT4.dll+0x0001B83A =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=77e5ed50 ecx=7c92f927 edx=0012ea50 esi=0000fffe edi=7c80b00b eip=7c91120e esp=0012ec84 ebp=0012ec98 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g =========================================================== VERIFIER STOP 0000FFFF: pid 0xC27C: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C80B00B : LoadLibraryW 77E5ED50 : rpcrt4.dll 77E6B525 : RPCRT4.dll+0x0001B525 77E6B83A : RPCRT4.dll+0x0001B83A =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=77e5ed50 ecx=7c92f927 edx=0012ea50 esi=0000ffff edi=7c80b00b eip=7c91120e esp=0012ec84 ebp=0012ec98 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g LoadLibraryA(comctl32.dll) =========================================================== VERIFIER STOP 0000FFFF: pid 0xC27C: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C801B21 : LoadLibraryA 768334BC : comctl32.dll 768445A2 : MSOERT2.dll+0x000145A2 76844651 : MSOERT2.dll+0x00014651 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=768334bc ecx=7c92f927 edx=0012ef98 esi=0000ffff edi=7c801b21 eip=7c91120e esp=0012f1cc ebp=0012f1e0 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g ModLoad: 773a0000 774a3000 C:\Windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll VrfKnthk!DllLoad: module 'comctl32.dll' loaded at 0x773A0000, size 0x00103000 LoadLibraryW(comctl32.dll) =========================================================== VERIFIER STOP 0000FFFF: pid 0xC27C: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C80B00B : LoadLibraryW 7E682ED8 : comctl32.dll 7E6D7308 : SHELL32.dll+0x00067308 7E697643 : SHELL32.dll+0x00027643 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=7e682ed8 ecx=7c92f927 edx=0012eb80 esi=0000ffff edi=7c80b00b eip=7c91120e esp=0012edb4 ebp=0012edc8 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g LoadLibraryW(comctl32.dll) =========================================================== VERIFIER STOP 0000FFFF: pid 0xC27C: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C80B00B : LoadLibraryW 7E682ED8 : comctl32.dll 7E6D7436 : SHELL32.dll+0x00067436 7E6D7176 : SHELL32.dll+0x00067176 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=7e682ed8 ecx=7c92f927 edx=0012f008 esi=0000ffff edi=7c80b00b eip=7c91120e esp=0012f23c ebp=0012f250 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g ModLoad: 5d450000 5d4ea000 C:\Windows\System32\comctl32.dll VrfKnthk!DllLoad: module 'comctl32.dll' loaded at 0x5D450000, size 0x0009A000 LoadLibraryW(imm32.dll) =========================================================== VERIFIER STOP 0000FFFE: pid 0xC27C: The application or a component it uses called LoadLibrary*() with the filename or pathname of a not existing file (which might be searched via PATH). 7C80B00B : LoadLibraryW 5D4770A4 : imm32.dll 5D476EB1 : comctl32.dll+0x00026EB1 5D45354D : comctl32.dll+0x0000354D =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=5d4770a4 ecx=7c92f927 edx=0012e52c esi=0000fffe edi=7c80b00b eip=7c91120e esp=0012e760 ebp=0012e774 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g =========================================================== VERIFIER STOP 0000FFFF: pid 0xC27C: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C80B00B : LoadLibraryW 5D4770A4 : imm32.dll 5D476EB1 : comctl32.dll+0x00026EB1 5D45354D : comctl32.dll+0x0000354D =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=5d4770a4 ecx=7c92f927 edx=0012e52c esi=0000ffff edi=7c80b00b eip=7c91120e esp=0012e760 ebp=0012e774 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g LoadLibraryW(shlwapi.dll) =========================================================== VERIFIER STOP 0000FFFF: pid 0xC27C: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C80B00B : LoadLibraryW 471B2028 : shlwapi.dll 471B7091 : WAB32.DLL+0x00007091 471CA8B8 : WAB32.DLL+0x0001A8B8 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=471b2028 ecx=7c92f927 edx=0012ed84 esi=0000ffff edi=7c80b00b eip=7c91120e esp=0012efb8 ebp=0012efcc iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g LoadLibraryW(C:\Program Files\Common Files\System\wab32res.dll) ModLoad: 35f40000 35f81000 C:\Program Files\Common Files\System\wab32res.dll VrfKnthk!DllLoad: module 'wab32res.dll' loaded at 0x35F40000, size 0x00041000 LoadLibraryA(COMCTL32.dll) =========================================================== VERIFIER STOP 0000FFFF: pid 0xC27C: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C801B21 : LoadLibraryA 77FA97E0 : COMCTL32.dll 77F51850 : SHLWAPI.dll+0x00011850 77F5EB9A : SHLWAPI.dll+0x0001EB9A =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=77fa97e0 ecx=7c92f927 edx=0012e9cc esi=0000ffff edi=7c801b21 eip=7c91120e esp=0012ec00 ebp=0012ec14 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g LoadLibraryW(COMCTL32.DLL) =========================================================== VERIFIER STOP 0000FFFF: pid 0xC27C: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C80B00B : LoadLibraryW 471B5190 : COMCTL32.DLL 471B7091 : WAB32.DLL+0x00007091 471CA786 : WAB32.DLL+0x0001A786 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=471b5190 ecx=7c92f927 edx=0012efbc esi=0000ffff edi=7c80b00b eip=7c91120e esp=0012f1f0 ebp=0012f204 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g VrfKnthk!DllUnload: module 'WAB32.DLL' unloaded from 0x471B0000, size 0x00081000 VrfKnthk!DllUnload: module 'SHELL32.dll' unloaded from 0x7E670000, size 0x00822000 VrfKnthk!DllUnload: module 'MSOERT2.dll' unloaded from 0x01560000, size 0x0000B000 VrfKnthk!DllUnload: module 'wab32res.dll' unloaded from 0x35F40000, size 0x00041000 VrfKnthk!DllMain(0x10000000, 0x00000000 = DLL_PROCESS_DETACH, 0x00000001) VrfKnthk!DllMain: VerifierImage = 0x000208B0 = EXAMPLE.EXE, VerifierFlags = 0x80000000, VerifierDebug = 0x00000000 eax=00000000 ebx=00000000 ecx=7c800000 edx=7c98f120 esi=7c91de6e edi=00000000 eip=7c91e514 esp=0012fea8 ebp=0012ffa4 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!KiFastSystemCallRet: 7c91e514 c3 ret 0:000> q