Microsoft (R) Windows User-Mode Debugger Version 5.1.2600.0 Copyright (c) Microsoft Corporation. All rights reserved. CommandLine: "C:\Documents and Settings\Stefan\Downloads\EXAMPLE.EXE" Loaded dbghelp extension DLL Loaded exts extension DLL Loaded ntsdexts extension DLL Symbol search path is: SymSrv*SYMSRV.DLL*C:\Windows\Symbols*http://msdl.microsoft.com/download/symbols/ Executable search path is: ModLoad: 00400000 00403000 image00400000 ModLoad: 7c910000 7c9ca000 ntdll.dll AVRF: EXAMPLE.EXE: pid 0xB1A4: flags 0x80000000: application verifier enabled ModLoad: 77da0000 77e4a000 C:\Windows\System32\ADVAPI32.DLL ModLoad: 7c800000 7c909000 C:\Windows\System32\KERNEL32.dll ModLoad: 77e50000 77ee3000 C:\Windows\System32\RPCRT4.dll ModLoad: 77fc0000 77fd1000 C:\Windows\System32\Secur32.dll ModLoad: 5b080000 5b0c9000 C:\Windows\System32\verifier.dll ModLoad: 10000000 1000b000 C:\Windows\System32\VrfKnthk.Dll VrfKnthk!DllMain(0x10000000, 0x00000004 = DLL_PROCESS_VERIFIER, 0x0012FAD8) AVRF: verifier.dll provider initialized for EXAMPLE.EXE with flags 0x80000000 VrfKnthk!DllMain(0x10000000, 0x00000001 = DLL_PROCESS_ATTACH, 0x00000000) VrfKnthk!DllMain: VerifierImage = 0x000208B0 = EXAMPLE.EXE, VerifierFlags = 0x80000000, VerifierDebug = 0x00000000 ModLoad: 774b0000 775ee000 C:\Windows\System32\ole32.dll ModLoad: 77ef0000 77f3a000 C:\Windows\System32\GDI32.dll ModLoad: 7e360000 7e3f1000 C:\Windows\System32\USER32.dll VrfKnthk!DllLoad: module 'USER32.dll' loaded at 0x7E360000, size 0x00091000 VrfKnthk!DllLoad: module 'GDI32.dll' loaded at 0x77EF0000, size 0x0004A000 ModLoad: 77be0000 77c38000 C:\Windows\System32\msvcrt.dll VrfKnthk!DllLoad: module 'msvcrt.dll' loaded at 0x77BE0000, size 0x00058000 VrfKnthk!DllLoad: module 'ole32.dll' loaded at 0x774B0000, size 0x0013E000 ModLoad: 7e670000 7ee92000 C:\Windows\System32\SHELL32.dll ModLoad: 77f40000 77fb7000 C:\Windows\System32\SHLWAPI.dll VrfKnthk!DllLoad: module 'SHLWAPI.dll' loaded at 0x77F40000, size 0x00077000 VrfKnthk!DllLoad: module 'SHELL32.dll' loaded at 0x7E670000, size 0x00822000 VrfKnthk!DllLoad: module 'EXAMPLE.EXE' loaded at 0x00400000, size 0x00003000 Break instruction exception - code 80000003 (first chance) eax=00351ec4 ebx=7ffd6000 ecx=00000007 edx=00000080 esi=00351f98 edi=00351ec4 eip=7c91120e esp=0012fb20 ebp=0012fc94 iopl=0 nv up ei pl nz na pe nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000202 *** ERROR: Symbol file could not be found. Defaulted to export symbols for ntdll.dll - ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g LoadLibraryW(C:\Windows\System32\IMM32.DLL) ModLoad: 76330000 7634d000 C:\Windows\System32\IMM32.DLL VrfKnthk!DllLoad: module 'IMM32.DLL' loaded at 0x76330000, size 0x0001D000 LoadLibraryW(C:\Windows\System32\APPINIT.DLL) ModLoad: 01d60000 01d66000 C:\Windows\System32\APPINIT.DLL VrfKnthk!DllLoad: module 'APPINIT.DLL' loaded at 0x01D60000, size 0x00006000 VrfKnthk!DllUnload: module 'APPINIT.DLL' unloaded from 0x01D60000, size 0x00006000 LoadLibraryW(comctl32.dll) =========================================================== VERIFIER STOP 0000FFFF: pid 0xB1A4: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C80B00B : LoadLibraryW 7E682ED8 : comctl32.dll 7E6D7308 : SHELL32.dll+0x00067308 7E697643 : SHELL32.dll+0x00027643 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=7e682ed8 ecx=7c92f927 edx=0012ef64 esi=0000ffff edi=7c80b00b eip=7c91120e esp=0012f198 ebp=0012f1ac iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g ModLoad: 773a0000 774a3000 C:\Windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll VrfKnthk!DllLoad: module 'comctl32.dll' loaded at 0x773A0000, size 0x00103000 LoadLibraryW(comctl32.dll) =========================================================== VERIFIER STOP 0000FFFF: pid 0xB1A4: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C80B00B : LoadLibraryW 7E682ED8 : comctl32.dll 7E6D7436 : SHELL32.dll+0x00067436 7E6D7176 : SHELL32.dll+0x00067176 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=7e682ed8 ecx=7c92f927 edx=0012f3ec esi=0000ffff edi=7c80b00b eip=7c91120e esp=0012f620 ebp=0012f634 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g ModLoad: 5d450000 5d4ea000 C:\Windows\System32\comctl32.dll VrfKnthk!DllLoad: module 'comctl32.dll' loaded at 0x5D450000, size 0x0009A000 LoadLibraryW(imm32.dll) =========================================================== VERIFIER STOP 0000FFFE: pid 0xB1A4: The application or a component it uses called LoadLibrary*() with the filename or pathname of a not existing file (which might be searched via PATH). 7C80B00B : LoadLibraryW 5D4770A4 : imm32.dll 5D476EB1 : comctl32.dll+0x00026EB1 5D45354D : comctl32.dll+0x0000354D =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=5d4770a4 ecx=7c92f927 edx=0012e910 esi=0000fffe edi=7c80b00b eip=7c91120e esp=0012eb44 ebp=0012eb58 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g =========================================================== VERIFIER STOP 0000FFFF: pid 0xB1A4: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C80B00B : LoadLibraryW 5D4770A4 : imm32.dll 5D476EB1 : comctl32.dll+0x00026EB1 5D45354D : comctl32.dll+0x0000354D =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=5d4770a4 ecx=7c92f927 edx=0012e910 esi=0000ffff edi=7c80b00b eip=7c91120e esp=0012eb44 ebp=0012eb58 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g LoadLibraryExW(C:\Windows\System32\MSCTF.dll, 0x00000000, 0x00000008) ModLoad: 746a0000 746ec000 C:\Windows\System32\MSCTF.dll VrfKnthk!DllLoad: module 'MSCTF.dll' loaded at 0x746A0000, size 0x0004C000 LoadLibraryW(rpcrt4.dll) =========================================================== VERIFIER STOP 0000FFFE: pid 0xB1A4: The application or a component it uses called LoadLibrary*() with the filename or pathname of a not existing file (which might be searched via PATH). 7C80B00B : LoadLibraryW 77E5ED50 : rpcrt4.dll 77E6B525 : RPCRT4.dll+0x0001B525 77E6B83A : RPCRT4.dll+0x0001B83A =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=77e5ed50 ecx=7c92f927 edx=0012df84 esi=0000fffe edi=7c80b00b eip=7c91120e esp=0012e1b8 ebp=0012e1cc iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g =========================================================== VERIFIER STOP 0000FFFF: pid 0xB1A4: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C80B00B : LoadLibraryW 77E5ED50 : rpcrt4.dll 77E6B525 : RPCRT4.dll+0x0001B525 77E6B83A : RPCRT4.dll+0x0001B83A =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=77e5ed50 ecx=7c92f927 edx=0012df84 esi=0000ffff edi=7c80b00b eip=7c91120e esp=0012e1b8 ebp=0012e1cc iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g ShellExecuteA(0x00000000, (null), .., (null), (null), 0x00000001) =========================================================== VERIFIER STOP 0000FFFF: pid 0xB1A4: The application or a component it uses called ShellExecute*() without providing an absolute local pathname for the file to execute. 7E6F12C0 : ShellExecuteA 0040201C : .. 00401024 : EXAMPLE.EXE+0x00001024 00000000 : unknown caller's caller =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=0040201c ecx=7c92f927 edx=0012fae8 esi=0000ffff edi=7e6f12c0 eip=7c91120e esp=0012fd1c ebp=0012fd30 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g LoadLibraryA(ole32.dll) =========================================================== VERIFIER STOP 0000FFFE: pid 0xB1A4: The application or a component it uses called LoadLibrary*() with the filename or pathname of a not existing file (which might be searched via PATH). 7C801B21 : LoadLibraryA 7E868700 : ole32.dll 7E6B468D : SHELL32.dll+0x0004468D 7E6B4661 : SHELL32.dll+0x00044661 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=7e868700 ecx=7c92f927 edx=0012e720 esi=0000fffe edi=7c801b21 eip=7c91120e esp=0012e954 ebp=0012e968 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g =========================================================== VERIFIER STOP 0000FFFF: pid 0xB1A4: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C801B21 : LoadLibraryA 7E868700 : ole32.dll 7E6B468D : SHELL32.dll+0x0004468D 7E6B4661 : SHELL32.dll+0x00044661 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=7e868700 ecx=7c92f927 edx=0012e720 esi=0000ffff edi=7c801b21 eip=7c91120e esp=0012e954 ebp=0012e968 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g LoadLibraryA(netapi32) =========================================================== VERIFIER STOP 0000FFFE: pid 0xB1A4: The application or a component it uses called LoadLibrary*() with the filename or pathname of a not existing file (which might be searched via PATH). 7C801B21 : LoadLibraryA 77F51D54 : netapi32 77F51D39 : SHLWAPI.dll+0x00011D39 77F51D6D : SHLWAPI.dll+0x00011D6D =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=77f51d54 ecx=7c92f927 edx=0012e6e0 esi=0000fffe edi=7c801b21 eip=7c91120e esp=0012e914 ebp=0012e928 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g =========================================================== VERIFIER STOP 0000FFFF: pid 0xB1A4: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C801B21 : LoadLibraryA 77F51D54 : netapi32 77F51D39 : SHLWAPI.dll+0x00011D39 77F51D6D : SHLWAPI.dll+0x00011D6D =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=77f51d54 ecx=7c92f927 edx=0012e6e0 esi=0000ffff edi=7c801b21 eip=7c91120e esp=0012e914 ebp=0012e928 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g ModLoad: 597d0000 59825000 C:\Windows\System32\netapi32.dll VrfKnthk!DllLoad: module 'netapi32.dll' loaded at 0x597D0000, size 0x00055000 LoadLibraryA(appHelp.dll) =========================================================== VERIFIER STOP 0000FFFE: pid 0xB1A4: The application or a component it uses called LoadLibrary*() with the filename or pathname of a not existing file (which might be searched via PATH). 7C801B21 : LoadLibraryA 77FA97C0 : appHelp.dll 77F51850 : SHLWAPI.dll+0x00011850 77F51914 : SHLWAPI.dll+0x00011914 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=77fa97c0 ecx=7c92f927 edx=0012e0f8 esi=0000fffe edi=7c801b21 eip=7c91120e esp=0012e32c ebp=0012e340 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g =========================================================== VERIFIER STOP 0000FFFF: pid 0xB1A4: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C801B21 : LoadLibraryA 77FA97C0 : appHelp.dll 77F51850 : SHLWAPI.dll+0x00011850 77F51914 : SHLWAPI.dll+0x00011914 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=77fa97c0 ecx=7c92f927 edx=0012e0f8 esi=0000ffff edi=7c801b21 eip=7c91120e esp=0012e32c ebp=0012e340 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g ModLoad: 77b10000 77b32000 C:\Windows\System32\appHelp.dll VrfKnthk!DllLoad: module 'appHelp.dll' loaded at 0x77B10000, size 0x00022000 LoadLibraryA(ole32.dll) =========================================================== VERIFIER STOP 0000FFFE: pid 0xB1A4: The application or a component it uses called LoadLibrary*() with the filename or pathname of a not existing file (which might be searched via PATH). 7C801B21 : LoadLibraryA 77FA97B0 : ole32.dll 77F51850 : SHLWAPI.dll+0x00011850 77F51888 : SHLWAPI.dll+0x00011888 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=77fa97b0 ecx=7c92f927 edx=0012e0f0 esi=0000fffe edi=7c801b21 eip=7c91120e esp=0012e324 ebp=0012e338 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g =========================================================== VERIFIER STOP 0000FFFF: pid 0xB1A4: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C801B21 : LoadLibraryA 77FA97B0 : ole32.dll 77F51850 : SHLWAPI.dll+0x00011850 77F51888 : SHLWAPI.dll+0x00011888 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=77fa97b0 ecx=7c92f927 edx=0012e0f0 esi=0000ffff edi=7c801b21 eip=7c91120e esp=0012e324 ebp=0012e338 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g LoadLibraryA(CLBCATQ.DLL) =========================================================== VERIFIER STOP 0000FFFE: pid 0xB1A4: The application or a component it uses called LoadLibrary*() with the filename or pathname of a not existing file (which might be searched via PATH). 7C801B21 : LoadLibraryA 774BD84C : CLBCATQ.DLL 774E2CD5 : ole32.dll+0x00032CD5 774E2DE8 : ole32.dll+0x00032DE8 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=774bd84c ecx=7c92f927 edx=0012df38 esi=0000fffe edi=7c801b21 eip=7c91120e esp=0012e16c ebp=0012e180 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g =========================================================== VERIFIER STOP 0000FFFF: pid 0xB1A4: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C801B21 : LoadLibraryA 774BD84C : CLBCATQ.DLL 774E2CD5 : ole32.dll+0x00032CD5 774E2DE8 : ole32.dll+0x00032DE8 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=774bd84c ecx=7c92f927 edx=0012df38 esi=0000ffff edi=7c801b21 eip=7c91120e esp=0012e16c ebp=0012e180 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g ModLoad: 02010000 0201a000 C:\Documents and Settings\Stefan\Downloads\CLBCATQ.DLL VrfKnthk!DllLoad: module 'CLBCATQ.DLL' loaded at 0x02010000, size 0x0000A000 ModLoad: 76f90000 7700f000 C:\Windows\System32\CLBCATQ.dll ModLoad: 02030000 02039000 C:\Documents and Settings\Stefan\Downloads\COMRes.dll VrfKnthk!DllLoad: module 'COMRes.dll' loaded at 0x02030000, size 0x00009000 ModLoad: 77010000 770e3000 C:\Windows\System32\COMRES.dll VrfKnthk!DllLoad: module 'COMRES.dll' loaded at 0x77010000, size 0x000D3000 ModLoad: 770f0000 7717b000 C:\Windows\System32\OLEAUT32.dll VrfKnthk!DllLoad: module 'OLEAUT32.dll' loaded at 0x770F0000, size 0x0008B000 ModLoad: 77bd0000 77bd8000 C:\Windows\System32\VERSION.dll VrfKnthk!DllLoad: module 'VERSION.dll' loaded at 0x77BD0000, size 0x00008000 VrfKnthk!DllLoad: module 'CLBCATQ.dll' loaded at 0x76F90000, size 0x0007F000 LoadLibraryA(CLBCATQ.DLL) =========================================================== VERIFIER STOP 0000FFFE: pid 0xB1A4: The application or a component it uses called LoadLibrary*() with the filename or pathname of a not existing file (which might be searched via PATH). 7C801B21 : LoadLibraryA 774BD84C : CLBCATQ.DLL 774E34B1 : ole32.dll+0x000334B1 774E33E8 : ole32.dll+0x000333E8 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=774bd84c ecx=7c92f927 edx=0012df38 esi=0000fffe edi=7c801b21 eip=7c91120e esp=0012e16c ebp=0012e180 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g =========================================================== VERIFIER STOP 0000FFFF: pid 0xB1A4: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C801B21 : LoadLibraryA 774BD84C : CLBCATQ.DLL 774E34B1 : ole32.dll+0x000334B1 774E33E8 : ole32.dll+0x000333E8 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=774bd84c ecx=7c92f927 edx=0012df38 esi=0000ffff edi=7c801b21 eip=7c91120e esp=0012e16c ebp=0012e180 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g LoadLibraryExW(C:\Windows\System32\shdocvw.dll, 0x00000000, 0x00002008) ModLoad: 7e1e0000 7e353000 C:\Windows\System32\shdocvw.dll ModLoad: 77a50000 77ae8000 C:\Windows\System32\CRYPT32.dll ModLoad: 77af0000 77b02000 C:\Windows\System32\MSASN1.dll VrfKnthk!DllLoad: module 'MSASN1.dll' loaded at 0x77AF0000, size 0x00012000 VrfKnthk!DllLoad: module 'CRYPT32.dll' loaded at 0x77A50000, size 0x00098000 ModLoad: 76880000 76905000 C:\Windows\System32\CRYPTUI.dll ModLoad: 77180000 7722b000 C:\Windows\System32\WININET.dll VrfKnthk!DllLoad: module 'WININET.dll' loaded at 0x77180000, size 0x000AB000 ModLoad: 76bf0000 76c1e000 C:\Windows\System32\WINTRUST.dll ModLoad: 76c50000 76c79000 C:\Windows\System32\IMAGEHLP.dll VrfKnthk!DllLoad: module 'IMAGEHLP.dll' loaded at 0x76C50000, size 0x00029000 VrfKnthk!DllLoad: module 'WINTRUST.dll' loaded at 0x76BF0000, size 0x0002E000 ModLoad: 76f20000 76f4d000 C:\Windows\System32\WLDAP32.dll VrfKnthk!DllLoad: module 'WLDAP32.dll' loaded at 0x76F20000, size 0x0002D000 VrfKnthk!DllLoad: module 'CRYPTUI.dll' loaded at 0x76880000, size 0x00085000 VrfKnthk!DllLoad: module 'shdocvw.dll' loaded at 0x7E1E0000, size 0x00173000 LoadLibraryA(advapi32.dll) =========================================================== VERIFIER STOP 0000FFFE: pid 0xB1A4: The application or a component it uses called LoadLibrary*() with the filename or pathname of a not existing file (which might be searched via PATH). 7C801B21 : LoadLibraryA 77A56EB0 : advapi32.dll 77A56566 : CRYPT32.dll+0x00006566 77A576E4 : CRYPT32.dll+0x000076E4 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=77a56eb0 ecx=7c92f927 edx=0012c6cc esi=0000fffe edi=7c801b21 eip=7c91120e esp=0012c900 ebp=0012c914 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g =========================================================== VERIFIER STOP 0000FFFF: pid 0xB1A4: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C801B21 : LoadLibraryA 77A56EB0 : advapi32.dll 77A56566 : CRYPT32.dll+0x00006566 77A576E4 : CRYPT32.dll+0x000076E4 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=77a56eb0 ecx=7c92f927 edx=0012c6cc esi=0000ffff edi=7c801b21 eip=7c91120e esp=0012c900 ebp=0012c914 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g LoadLibraryA(kernel32.dll) =========================================================== VERIFIER STOP 0000FFFE: pid 0xB1A4: The application or a component it uses called LoadLibrary*() with the filename or pathname of a not existing file (which might be searched via PATH). 7C801B21 : LoadLibraryA 77A5455C : kernel32.dll 77A57982 : CRYPT32.dll+0x00007982 77A51932 : CRYPT32.dll+0x00001932 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=77a5455c ecx=7c92f927 edx=0012c6ac esi=0000fffe edi=7c801b21 eip=7c91120e esp=0012c8e0 ebp=0012c8f4 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g =========================================================== VERIFIER STOP 0000FFFF: pid 0xB1A4: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C801B21 : LoadLibraryA 77A5455C : kernel32.dll 77A57982 : CRYPT32.dll+0x00007982 77A51932 : CRYPT32.dll+0x00001932 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=77a5455c ecx=7c92f927 edx=0012c6ac esi=0000ffff edi=7c801b21 eip=7c91120e esp=0012c8e0 ebp=0012c8f4 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g LoadLibraryA(advapi32.dll) =========================================================== VERIFIER STOP 0000FFFE: pid 0xB1A4: The application or a component it uses called LoadLibrary*() with the filename or pathname of a not existing file (which might be searched via PATH). 7C801B21 : LoadLibraryA 0012CB14 : advapi32.dll 77AF35EA : MSASN1.dll+0x000035EA 77AF3570 : MSASN1.dll+0x00003570 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=0012cb14 ecx=7c92f927 edx=0012c604 esi=0000fffe edi=7c801b21 eip=7c91120e esp=0012c838 ebp=0012c84c iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g =========================================================== VERIFIER STOP 0000FFFF: pid 0xB1A4: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C801B21 : LoadLibraryA 0012CB14 : advapi32.dll 77AF35EA : MSASN1.dll+0x000035EA 77AF3570 : MSASN1.dll+0x00003570 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=0012cb14 ecx=7c92f927 edx=0012c604 esi=0000ffff edi=7c801b21 eip=7c91120e esp=0012c838 ebp=0012c84c iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g LoadLibraryW(comctl32.dll) =========================================================== VERIFIER STOP 0000FFFF: pid 0xB1A4: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C80B00B : LoadLibraryW 771A1120 : comctl32.dll 77F5A6E7 : SHLWAPI.dll+0x0001A6E7 771A1168 : WININET.dll+0x00021168 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=771a1120 ecx=7c92f927 edx=0012bf0c esi=0000ffff edi=7c80b00b eip=7c91120e esp=0012c140 ebp=0012c154 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g LoadLibraryW(Comctl32.dll) =========================================================== VERIFIER STOP 0000FFFF: pid 0xB1A4: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C80B00B : LoadLibraryW 768817BC : Comctl32.dll 7688198D : CRYPTUI.dll+0x0000198D 76881A69 : CRYPTUI.dll+0x00001A69 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=768817bc ecx=7c92f927 edx=0012c2f0 esi=0000ffff edi=7c80b00b eip=7c91120e esp=0012c524 ebp=0012c538 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g LoadLibraryA(RichEd20.dll) =========================================================== VERIFIER STOP 0000FFFF: pid 0xB1A4: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C801B21 : LoadLibraryA 768817D8 : RichEd20.dll 76881DD8 : CRYPTUI.dll+0x00001DD8 76881D80 : CRYPTUI.dll+0x00001D80 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=768817d8 ecx=7c92f927 edx=0012c6ac esi=0000ffff edi=7c801b21 eip=7c91120e esp=0012c8e0 ebp=0012c8f4 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g ModLoad: 02070000 02079000 C:\Documents and Settings\Stefan\Downloads\RichEd20.dll VrfKnthk!DllLoad: module 'RichEd20.dll' loaded at 0x02070000, size 0x00009000 VrfKnthk!DllUnload: module 'RichEd20.dll' unloaded from 0x02070000, size 0x00009000 LoadLibraryW(Comctl32.dll) =========================================================== VERIFIER STOP 0000FFFF: pid 0xB1A4: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C80B00B : LoadLibraryW 768817BC : Comctl32.dll 76881CA1 : CRYPTUI.dll+0x00001CA1 76881C22 : CRYPTUI.dll+0x00001C22 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=768817bc ecx=7c92f927 edx=0012c51c esi=0000ffff edi=7c80b00b eip=7c91120e esp=0012c750 ebp=0012c764 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g LoadLibraryW(comctl32.dll) =========================================================== VERIFIER STOP 0000FFFF: pid 0xB1A4: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C80B00B : LoadLibraryW 7E1E79D0 : comctl32.dll 77F5A6E7 : SHLWAPI.dll+0x0001A6E7 7E1F700A : shdocvw.dll+0x0001700A =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=7e1e79d0 ecx=7c92f927 edx=0012bf10 esi=0000ffff edi=7c80b00b eip=7c91120e esp=0012c144 ebp=0012c158 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g LoadLibraryA(SHELL32.dll) =========================================================== VERIFIER STOP 0000FFFE: pid 0xB1A4: The application or a component it uses called LoadLibrary*() with the filename or pathname of a not existing file (which might be searched via PATH). 7C801B21 : LoadLibraryA 7E2B8220 : SHELL32.dll 7E1F64EB : shdocvw.dll+0x000164EB 7E1F64C7 : shdocvw.dll+0x000164C7 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=7e2b8220 ecx=7c92f927 edx=0012e558 esi=0000fffe edi=7c801b21 eip=7c91120e esp=0012e78c ebp=0012e7a0 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g =========================================================== VERIFIER STOP 0000FFFF: pid 0xB1A4: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C801B21 : LoadLibraryA 7E2B8220 : SHELL32.dll 7E1F64EB : shdocvw.dll+0x000164EB 7E1F64C7 : shdocvw.dll+0x000164C7 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=7e2b8220 ecx=7c92f927 edx=0012e558 esi=0000ffff edi=7c801b21 eip=7c91120e esp=0012e78c ebp=0012e7a0 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g LoadLibraryExW(C:\Windows\System32\SHELL32.dll, 0x00000000, 0x00000000) LoadLibraryA(SETUPAPI.dll) =========================================================== VERIFIER STOP 0000FFFE: pid 0xB1A4: The application or a component it uses called LoadLibrary*() with the filename or pathname of a not existing file (which might be searched via PATH). 7C801B21 : LoadLibraryA 7E868890 : SETUPAPI.dll 7E6B468D : SHELL32.dll+0x0004468D 7E6AFA14 : SHELL32.dll+0x0003FA14 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=7e868890 ecx=7c92f927 edx=0012dc00 esi=0000fffe edi=7c801b21 eip=7c91120e esp=0012de34 ebp=0012de48 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g =========================================================== VERIFIER STOP 0000FFFF: pid 0xB1A4: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C801B21 : LoadLibraryA 7E868890 : SETUPAPI.dll 7E6B468D : SHELL32.dll+0x0004468D 7E6AFA14 : SHELL32.dll+0x0003FA14 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=7e868890 ecx=7c92f927 edx=0012dc00 esi=0000ffff edi=7c801b21 eip=7c91120e esp=0012de34 ebp=0012de48 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g ModLoad: 02090000 020a4000 C:\Documents and Settings\Stefan\Downloads\SETUPAPI.dll VrfKnthk!DllLoad: module 'SETUPAPI.dll' loaded at 0x02090000, size 0x00014000 ModLoad: 778f0000 779e4000 C:\Windows\System32\SETUPAPI.dll VrfKnthk!DllLoad: module 'SETUPAPI.dll' loaded at 0x778F0000, size 0x000F4000 LoadLibraryA(SHELL32.dll) =========================================================== VERIFIER STOP 0000FFFE: pid 0xB1A4: The application or a component it uses called LoadLibrary*() with the filename or pathname of a not existing file (which might be searched via PATH). 7C801B21 : LoadLibraryA 77FA9870 : SHELL32.dll 77F51850 : SHLWAPI.dll+0x00011850 77F517B8 : SHLWAPI.dll+0x000117B8 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=77fa9870 ecx=7c92f927 edx=0012c2f0 esi=0000fffe edi=7c801b21 eip=7c91120e esp=0012c524 ebp=0012c538 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g =========================================================== VERIFIER STOP 0000FFFF: pid 0xB1A4: The application or a component it uses called LoadLibrary*() without providing an absolute local pathname for the module to load. 7C801B21 : LoadLibraryA 77FA9870 : SHELL32.dll 77F51850 : SHLWAPI.dll+0x00011850 77F517B8 : SHLWAPI.dll+0x000117B8 =========================================================== Break instruction exception - code 80000003 (first chance) eax=00000000 ebx=77fa9870 ecx=7c92f927 edx=0012c2f0 esi=0000ffff edi=7c801b21 eip=7c91120e esp=0012c524 ebp=0012c538 iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!DbgBreakPoint: 7c91120e cc int 3 0:000> g VrfKnthk!DllUnload: module 'shdocvw.dll' unloaded from 0x7E1E0000, size 0x00173000 VrfKnthk!DllUnload: module 'CRYPTUI.dll' unloaded from 0x76880000, size 0x00085000 VrfKnthk!DllUnload: module 'WLDAP32.dll' unloaded from 0x76F20000, size 0x0002D000 VrfKnthk!DllUnload: module 'WINTRUST.dll' unloaded from 0x76BF0000, size 0x0002E000 VrfKnthk!DllUnload: module 'IMAGEHLP.dll' unloaded from 0x76C50000, size 0x00029000 VrfKnthk!DllUnload: module 'WININET.dll' unloaded from 0x77180000, size 0x000AB000 VrfKnthk!DllUnload: module 'CRYPT32.dll' unloaded from 0x77A50000, size 0x00098000 VrfKnthk!DllUnload: module 'MSASN1.dll' unloaded from 0x77AF0000, size 0x00012000 VrfKnthk!DllMain(0x10000000, 0x00000000 = DLL_PROCESS_DETACH, 0x00000001) VrfKnthk!DllMain: VerifierImage = 0x000208B0 = EXAMPLE.EXE, VerifierFlags = 0x80000000, VerifierDebug = 0x00000000 eax=00000000 ebx=00000000 ecx=7c800000 edx=7c98f120 esi=7c91de6e edi=00000021 eip=7c91e514 esp=0012fea0 ebp=0012ff9c iopl=0 nv up ei pl zr na po nc cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246 ntdll!KiFastSystemCallRet: 7c91e514 c3 ret 0:000> q