Well I hope this means something to someone, cause that took hours.
Initially had a corrupted cfc, so rewrote the disk, made the changes (saved it this time), but
ended up not seeing explorer as the last proc.??
Basically did the following.
Proc list ;Wrote down all the proc's
Proc attach ;Attach to one a the time
Thread list ;Wrote down all the thread Numbers for that proc
Thread attach
BI ;Detail printed to Hyper terminal.
I did this for all the proc's and threads.
Code: Select all
Entered debugger on embedded INT3 at 0x0008:0x808c1fc2.
kdb:> proc list
PID State Filename
*0x00000004 In Memory System
0x00000044 In Memory smss.exe
0x0000007c In Memory csrss.exe
0x000000a0 In Memory winlogon.exe
0x000000bc In Memory services.exe
0x000000c4 In Memory lsass.exe
0x000000e4 In Memory eventlog.exe
0x000000f4 In Memory setup.exe
0x00000104 In Memory spoolsv.exe
0x00000118 In Memory rpcss.exe
0x0000012c In Memory dhcp.exe
0x0000017c In Memory umpnpmgr.exe
'==================================================================System
kdb:> proc attach 0x04
Attached to process 0x00000004, thread 0x00000008.
kdb:> thread list
TID State Prior. Affinity EBP EIP
*0x00000008 Waiting 0 0x00000001 0x80f19748 0x00000000
0x0000000c Waiting 13 0x00000001 0x80f1b758 0xffdffb78
0x00000010 Waiting 13 0x00000001 0x80f1ba88 0xffdffb78
0x00000014 Waiting 13 0x00000001 0x80f1bdb8 0xffdffb78
0x00000018 Waiting 13 0x00000001 0x80f1c108 0xffdffb78
0x0000001c Waiting 13 0x00000001 0x815d7890 0xffdffb50
0x00000020 Waiting 12 0x00000001 0x80f1c768 0xffdffb70
0x00000024 Waiting 12 0x00000001 0x80f1ca98 0xffdffb70
0x00000028 Running 12 0x00000001 0x00000000 0x00000000
0x0000002c Waiting 15 0x00000001 0x80f197a8 0xffdffb10
0x00000030 Waiting 14 0x00000001 0x80f1d098 0x00000000
0x00000034 Waiting 8 0x00000001 0x80f0d528 0x00000000
0x00000038 Waiting 17 0x00000001 0x8156c990 0xffdffb50
0x0000003c Waiting 8 0x00000001 0x80f01018 0x00000000
0x00000040 Waiting 16 0x00000001 0x80f012c8 0x00000000
0x00000090 Waiting 19 0x00000001 0x80f1d0f8 0xffdffb80
0x00000094 Waiting 19 0x00000001 0x80f1ca98 0xffdffb70
0x00000098 Waiting 19 0x00000001 0x811a3b80 0x50414d52
0x0000014c Waiting 8 0x00000001 0x815103a8 0xffdffb50
kdb:> thread attach 0x8
Attached to thread 0x00000008.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<NTOSKRNL.EXE:7c420 (ntoskrnl/mm/freelist.c:985 (MmZeroPageThreadMain@4))>
<NTOSKRNL.EXE:376ee (ntoskrnl/ex/init.c:1922 (Phase1Initialization@4))>
<NTOSKRNL.EXE:afcf2 (ntoskrnl/ps/thread.c:159 (PspSystemThreadStartup@8))>
<NTOSKRNL.EXE:b9dbe (ntoskrnl\ke\i386\ctxswitch.S:306 (KiThreadStartup@156))>
kdb:> thread attach 0xc
Attached to thread 0x0000000c.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:c3f4 (ntoskrnl/ke/queue.c:403 (KeRemoveQueue@12))>
<NTOSKRNL.EXE:402d7 (ntoskrnl/ex/work.c:150 (ExpWorkerThreadEntryPoint@4))>
<NTOSKRNL.EXE:afcf2 (ntoskrnl/ps/thread.c:159 (PspSystemThreadStartup@8))>
<NTOSKRNL.EXE:b9dbe (ntoskrnl\ke\i386\ctxswitch.S:306 (KiThreadStartup@156))>
kdb:> thread attach 0x10
Attached to thread 0x00000010.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:c3f4 (ntoskrnl/ke/queue.c:403 (KeRemoveQueue@12))>
<NTOSKRNL.EXE:402d7 (ntoskrnl/ex/work.c:150 (ExpWorkerThreadEntryPoint@4))>
<NTOSKRNL.EXE:afcf2 (ntoskrnl/ps/thread.c:159 (PspSystemThreadStartup@8))>
<NTOSKRNL.EXE:b9dbe (ntoskrnl\ke\i386\ctxswitch.S:306 (KiThreadStartup@156))>
kdb:> thread attach 0x14
Attached to thread 0x00000014.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:c3f4 (ntoskrnl/ke/queue.c:403 (KeRemoveQueue@12))>
<NTOSKRNL.EXE:402d7 (ntoskrnl/ex/work.c:150 (ExpWorkerThreadEntryPoint@4))>
<NTOSKRNL.EXE:afcf2 (ntoskrnl/ps/thread.c:159 (PspSystemThreadStartup@8))>
<NTOSKRNL.EXE:b9dbe (ntoskrnl\ke\i386\ctxswitch.S:306 (KiThreadStartup@156))>
kdb:> thread attach 0x18
Attached to thread 0x00000018.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:c3f4 (ntoskrnl/ke/queue.c:403 (KeRemoveQueue@12))>
<NTOSKRNL.EXE:402d7 (ntoskrnl/ex/work.c:150 (ExpWorkerThreadEntryPoint@4))>
<NTOSKRNL.EXE:afcf2 (ntoskrnl/ps/thread.c:159 (PspSystemThreadStartup@8))>
<NTOSKRNL.EXE:b9dbe (ntoskrnl\ke\i386\ctxswitch.S:306 (KiThreadStartup@156))>
kdb:> thread attach 0x1c
Attached to thread 0x0000001c.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:c3f4 (ntoskrnl/ke/queue.c:403 (KeRemoveQueue@12))>
<NTOSKRNL.EXE:402d7 (ntoskrnl/ex/work.c:150 (ExpWorkerThreadEntryPoint@4))>
<NTOSKRNL.EXE:afcf2 (ntoskrnl/ps/thread.c:159 (PspSystemThreadStartup@8))>
<NTOSKRNL.EXE:b9dbe (ntoskrnl\ke\i386\ctxswitch.S:306 (KiThreadStartup@156))>
kdb:> thread attach 0x20
Attached to thread 0x00000020.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:c3f4 (ntoskrnl/ke/queue.c:403 (KeRemoveQueue@12))>
<NTOSKRNL.EXE:402d7 (ntoskrnl/ex/work.c:150 (ExpWorkerThreadEntryPoint@4))>
<NTOSKRNL.EXE:afcf2 (ntoskrnl/ps/thread.c:159 (PspSystemThreadStartup@8))>
<NTOSKRNL.EXE:b9dbe (ntoskrnl\ke\i386\ctxswitch.S:306 (KiThreadStartup@156))>
kdb:> thread attach 0x24
Attached to thread 0x00000024.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:c3f4 (ntoskrnl/ke/queue.c:403 (KeRemoveQueue@12))>
<NTOSKRNL.EXE:402d7 (ntoskrnl/ex/work.c:150 (ExpWorkerThreadEntryPoint@4))>
<NTOSKRNL.EXE:afcf2 (ntoskrnl/ps/thread.c:159 (PspSystemThreadStartup@8))>
<NTOSKRNL.EXE:b9dbe (ntoskrnl\ke\i386\ctxswitch.S:306 (KiThreadStartup@156))>
kdb:> thread attach 0x28
Attached to thread 0x00000028.
kdb:> bt
Eip:
<NTOSKRNL.EXE:c1fc3 (lib\rtl\i386\debug_asm.S:33 (DbgBreakPoint@0))>
Frames:
<NTOSKRNL.EXE:6bc76 (ntoskrnl/kd/kdmain.c:416 (KdSystemDebugControl@28))>
<i8042prt.sys:2335 (drivers/input/i8042prt/keyboard.c:51 (i8042DebugWorkItem@8))
>
<NTOSKRNL.EXE:5565d (ntoskrnl/io/iomgr/iowork.c:30 (IopWorkItemCallback@4))>
<NTOSKRNL.EXE:40301 (ntoskrnl/ex/work.c:162 (ExpWorkerThreadEntryPoint@4))>
<NTOSKRNL.EXE:afcf2 (ntoskrnl/ps/thread.c:159 (PspSystemThreadStartup@8))>
<NTOSKRNL.EXE:b9dbe (ntoskrnl\ke\i386\ctxswitch.S:306 (KiThreadStartup@156))>
kdb:> thread attach 0x2c
Attached to thread 0x0000002c.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:c3f4 (ntoskrnl/ke/queue.c:403 (KeRemoveQueue@12))>
<NTOSKRNL.EXE:402d7 (ntoskrnl/ex/work.c:150 (ExpWorkerThreadEntryPoint@4))>
<NTOSKRNL.EXE:afcf2 (ntoskrnl/ps/thread.c:159 (PspSystemThreadStartup@8))>
<NTOSKRNL.EXE:b9dbe (ntoskrnl\ke\i386\ctxswitch.S:306 (KiThreadStartup@156))>
kdb:> thread attach 0x30
Attached to thread 0x00000030.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:1137e (ntoskrnl/ke/wait.c:813 (KeWaitForMultipleObjects@32))>
<NTOSKRNL.EXE:406af (ntoskrnl/ex/work.c:458 (ExpWorkerThreadBalanceManager@4))>
<NTOSKRNL.EXE:afcf2 (ntoskrnl/ps/thread.c:159 (PspSystemThreadStartup@8))>
<NTOSKRNL.EXE:b9dbe (ntoskrnl\ke\i386\ctxswitch.S:306 (KiThreadStartup@156))>
kdb:> thread attach 0x34
Attached to thread 0x00000034.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:1137e (ntoskrnl/ke/wait.c:813 (KeWaitForMultipleObjects@32))>
<9d9fd5a2>
<NTOSKRNL.EXE:afcf2 (ntoskrnl/ps/thread.c:159 (PspSystemThreadStartup@8))>
<NTOSKRNL.EXE:b9dbe (ntoskrnl\ke\i386\ctxswitch.S:306 (KiThreadStartup@156))>
kdb:> thread attach 0x38
Attached to thread 0x00000038.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:1137e (ntoskrnl/ke/wait.c:813 (KeWaitForMultipleObjects@32))>
<NTOSKRNL.EXE:79a60 (ntoskrnl/mm/balance.c:327 (MiBalancerThread@4))>
<NTOSKRNL.EXE:afcf2 (ntoskrnl/ps/thread.c:159 (PspSystemThreadStartup@8))>
<NTOSKRNL.EXE:b9dbe (ntoskrnl\ke\i386\ctxswitch.S:306 (KiThreadStartup@156))>
kdb:> thread attach 0x3c
Attached to thread 0x0000003c.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<NTOSKRNL.EXE:80759 (ntoskrnl/mm/mpw.c:71 (MmMpwThreadMain@4))>
<NTOSKRNL.EXE:afcf2 (ntoskrnl/ps/thread.c:159 (PspSystemThreadStartup@8))>
<NTOSKRNL.EXE:b9dbe (ntoskrnl\ke\i386\ctxswitch.S:306 (KiThreadStartup@156))>
kdb:> thread attach 0x40
Attached to thread 0x00000040.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:1137e (ntoskrnl/ke/wait.c:813 (KeWaitForMultipleObjects@32))>
<NTOSKRNL.EXE:5a9b (ntoskrnl/ke/balmgr.c:173 (KeBalanceSetManager@4))>
<NTOSKRNL.EXE:afcf2 (ntoskrnl/ps/thread.c:159 (PspSystemThreadStartup@8))>
<NTOSKRNL.EXE:b9dbe (ntoskrnl\ke\i386\ctxswitch.S:306 (KiThreadStartup@156))>
kdb:> thread attach 0x90
Attached to thread 0x00000090.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:1137e (ntoskrnl/ke/wait.c:813 (KeWaitForMultipleObjects@32))>
<win32k.sys:69205 (include/ddk/ntddkbd.h:907 (RawInputThreadMain@4))>
<NTOSKRNL.EXE:afcf2 (ntoskrnl/ps/thread.c:159 (PspSystemThreadStartup@8))>
<NTOSKRNL.EXE:b9dbe (ntoskrnl\ke\i386\ctxswitch.S:306 (KiThreadStartup@156))>
kdb:> thread attach 0x94
Attached to thread 0x00000094.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<NTOSKRNL.EXE:500f2 (ntoskrnl/io/iomgr/iofunc.c:167 (IopPerformSynchronousReques
t@28))>
<NTOSKRNL.EXE:5273d (ntoskrnl/io/iomgr/iofunc.c:2178 (NtReadFile@36))>
<win32k.sys:68d24 (include/ddk/ntddkbd.h:565 (KeyboardThreadMain@4))>
<NTOSKRNL.EXE:afcf2 (ntoskrnl/ps/thread.c:159 (PspSystemThreadStartup@8))>
<NTOSKRNL.EXE:b9dbe (ntoskrnl\ke\i386\ctxswitch.S:306 (KiThreadStartup@156))>
kdb:> thread attach 0x98
Attached to thread 0x00000098.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<NTOSKRNL.EXE:500f2 (ntoskrnl/io/iomgr/iofunc.c:167 (IopPerformSynchronousReques
t@28))>
<NTOSKRNL.EXE:5273d (ntoskrnl/io/iomgr/iofunc.c:2178 (NtReadFile@36))>
<win32k.sys:6895a (include/ddk/ntddkbd.h:268 (MouseThreadMain@4))>
<NTOSKRNL.EXE:afcf2 (ntoskrnl/ps/thread.c:159 (PspSystemThreadStartup@8))>
<NTOSKRNL.EXE:b9dbe (ntoskrnl\ke\i386\ctxswitch.S:306 (KiThreadStartup@156))>
kdb:> thread attach 0x14c
Attached to thread 0x0000014c.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:1137e (ntoskrnl/ke/wait.c:813 (KeWaitForMultipleObjects@32))>
<npfs.sys:3a20 (drivers/filesystems/npfs/rw.c:148 (NpfsWaiterThread@4))>
<NTOSKRNL.EXE:afcf2 (ntoskrnl/ps/thread.c:159 (PspSystemThreadStartup@8))>
<NTOSKRNL.EXE:b9dbe (ntoskrnl\ke\i386\ctxswitch.S:306 (KiThreadStartup@156))>
'================================================================================SMSS
kdb:>proc attach 0x44
Attached to process 0x00000044, thread 0x0000004c.
kdb:> thread list
TID State Prior. Affinity EBP EIP
*0x0000004c Waiting 9 0x00000001 0x0070fff4 0x7c9061d5
0x00000050 Waiting 9 0x00000001 0x0090fff4 0x7c9061d5
0x00000074 Waiting 8 0x00000001 0x00b0fff4 0x7c9061d5
0x00000078 Waiting 8 0x00000001 0x00d0fff4 0x7c9061d5
kdb:> thread attach 0x4c
Attached to thread 0x0000004c.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<NTOSKRNL.EXE:71ec2 (ntoskrnl/lpc/reply.c:383 (NtReplyWaitReceivePortEx@20))>
<NTOSKRNL.EXE:726ec (ntoskrnl/lpc/reply.c:542 (NtReplyWaitReceivePort@16))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<00000000>
kdb:> thread attach 0x50
Attached to thread 0x00000050.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<NTOSKRNL.EXE:71ec2 (ntoskrnl/lpc/reply.c:383 (NtReplyWaitReceivePortEx@20))>
<NTOSKRNL.EXE:726ec (ntoskrnl/lpc/reply.c:542 (NtReplyWaitReceivePort@16))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<00000000>
kdb:> thread attach 0x74
Attached to thread 0x00000074.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<NTOSKRNL.EXE:71ec2 (ntoskrnl/lpc/reply.c:383 (NtReplyWaitReceivePortEx@20))>
<NTOSKRNL.EXE:726ec (ntoskrnl/lpc/reply.c:542 (NtReplyWaitReceivePort@16))>
<NTOSKRNL.EXE:70832 (ntoskrnl/lpc/listen.c:39 (NtListenPort@8))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<00000000>
kdb:> thread attach 0x78
Attached to thread 0x00000078.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<NTOSKRNL.EXE:71ec2 (ntoskrnl/lpc/reply.c:383 (NtReplyWaitReceivePortEx@20))>
<NTOSKRNL.EXE:726ec (ntoskrnl/lpc/reply.c:542 (NtReplyWaitReceivePort@16))>
<NTOSKRNL.EXE:70832 (ntoskrnl/lpc/listen.c:39 (NtListenPort@8))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<00000000>
'============================================================================CSRSS
kdb:> proc attach 0x7c
Attached to process 0x0000007c, thread 0x00000088.
kdb:> thread list
TID State Prior. Affinity EBP EIP
*0x00000088 Waiting 8 0x00000001 0x0092fff4 0x7c9061d5
0x000000ac Waiting 9 0x00000001 0x0136fff4 0x7c9061d5
0x000000b0 Waiting 8 0x00000001 0x0196ff5c 0x7c9061d5
0x000000b4 Waiting 8 0x00000001 0x01b6ff5c 0x7c9061d5
0x000000b8 Waiting 8 0x00000001 0x0216ff5c 0x7c9061d5
0x000000d4 Waiting 9 0x00000001 0x0296fff4 0x7c9061d5
0x00000114 Waiting 9 0x00000001 0x02f6fff4 0x7c9061d5
0x00000138 Waiting 9 0x00000001 0x0336fff4 0x7c9061d5
0x00000184 Waiting 9 0x00000001 0x0356fff4 0x7c9061d5
0x0000023c Waiting 9 0x00000001 0x0396fff4 0x7c9061d5
0x00000250 Waiting 9 0x00000001 0x0376fff4 0x7c9061d5
0x00000264 Waiting 9 0x00000001 0x0276fff4 0x7c9061d5
0x00000274 Waiting 9 0x00000001 0x00b3fff4 0x7c9061d5
0x00000284 Waiting 8 0x00000001 0x0316fff4 0x7c9061d5
0x0000029c Waiting 8 0x00000001 0x0116fff4 0x7c9061d5
0x000002b0 Waiting 8 0x00000001 0x02d6fff4 0x7c9061d5
kdb:> thread attach 0x88
Attached to thread 0x00000088.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<NTOSKRNL.EXE:71ec2 (ntoskrnl/lpc/reply.c:383 (NtReplyWaitReceivePortEx@20))>
<NTOSKRNL.EXE:726ec (ntoskrnl/lpc/reply.c:542 (NtReplyWaitReceivePort@16))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<00000000>
kdb:> thread attach 0xac
Attached to thread 0x000000ac.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<NTOSKRNL.EXE:71ec2 (ntoskrnl/lpc/reply.c:383 (NtReplyWaitReceivePortEx@20))>
<NTOSKRNL.EXE:726ec (ntoskrnl/lpc/reply.c:542 (NtReplyWaitReceivePort@16))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<00000000>
kdb:> thread attach 0xb0
Attached to thread 0x000000b0.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:1137e (ntoskrnl/ke/wait.c:813 (KeWaitForMultipleObjects@32))>
<win32k.sys:73068 (subsystems/win32/win32k/ntuser/msgqueue.c:1392 (@co_MsqWaitFo
rNewMessages@16))>
<win32k.sys:6e772 (subsystems/win32/win32k/ntuser/message.c:1084 (@co_IntWaitMes
sage@12))>
<win32k.sys:6e7d3 (subsystems/win32/win32k/ntuser/message.c:1187 (NtUserGetMessa
ge@16))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<win32csr.dll:5497>
<kernel32.dll:26efc>
<00000000>
kdb:> thread attach 0xb8
Attached to thread 0x000000b8.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:1137e (ntoskrnl/ke/wait.c:813 (KeWaitForMultipleObjects@32))>
<win32k.sys:73068 (subsystems/win32/win32k/ntuser/msgqueue.c:1392 (@co_MsqWaitFo
rNewMessages@16))>
<win32k.sys:6e772 (subsystems/win32/win32k/ntuser/message.c:1084 (@co_IntWaitMes
sage@12))>
<win32k.sys:6e7d3 (subsystems/win32/win32k/ntuser/message.c:1187 (NtUserGetMessa
ge@16))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<win32csr.dll:5497>
<kernel32.dll:26efc>
<00000000>
kdb:> thread attach 0xd4
Attached to thread 0x000000d4.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<NTOSKRNL.EXE:71ec2 (ntoskrnl/lpc/reply.c:383 (NtReplyWaitReceivePortEx@20))>
<NTOSKRNL.EXE:726ec (ntoskrnl/lpc/reply.c:542 (NtReplyWaitReceivePort@16))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<00000000>
kdb:> thread attach 0x114
Attached to thread 0x00000114.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<NTOSKRNL.EXE:71ec2 (ntoskrnl/lpc/reply.c:383 (NtReplyWaitReceivePortEx@20))>
<NTOSKRNL.EXE:726ec (ntoskrnl/lpc/reply.c:542 (NtReplyWaitReceivePort@16))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<00000000>
kdb:> thread attach 0x138
Attached to thread 0x00000138.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<NTOSKRNL.EXE:71ec2 (ntoskrnl/lpc/reply.c:383 (NtReplyWaitReceivePortEx@20))>
<NTOSKRNL.EXE:726ec (ntoskrnl/lpc/reply.c:542 (NtReplyWaitReceivePort@16))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<00000000>
kdb:> thread attach 0x184
Attached to thread 0x00000184.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<NTOSKRNL.EXE:71ec2 (ntoskrnl/lpc/reply.c:383 (NtReplyWaitReceivePortEx@20))>
<NTOSKRNL.EXE:726ec (ntoskrnl/lpc/reply.c:542 (NtReplyWaitReceivePort@16))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<00000000>
kdb:> thread attach 0x23c
Attached to thread 0x0000023c.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<NTOSKRNL.EXE:71ec2 (ntoskrnl/lpc/reply.c:383 (NtReplyWaitReceivePortEx@20))>
<NTOSKRNL.EXE:726ec (ntoskrnl/lpc/reply.c:542 (NtReplyWaitReceivePort@16))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<00000000>
kdb:> thread attach 0x250
Attached to thread 0x00000250.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<NTOSKRNL.EXE:71ec2 (ntoskrnl/lpc/reply.c:383 (NtReplyWaitReceivePortEx@20))>
<NTOSKRNL.EXE:726ec (ntoskrnl/lpc/reply.c:542 (NtReplyWaitReceivePort@16))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<00000000>
kdb:> thread attach 0x264
Attached to thread 0x00000264.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<NTOSKRNL.EXE:71ec2 (ntoskrnl/lpc/reply.c:383 (NtReplyWaitReceivePortEx@20))>
<NTOSKRNL.EXE:726ec (ntoskrnl/lpc/reply.c:542 (NtReplyWaitReceivePort@16))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<00000000>
kdb:> thread attach 0x274
Attached to thread 0x00000274.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<NTOSKRNL.EXE:71ec2 (ntoskrnl/lpc/reply.c:383 (NtReplyWaitReceivePortEx@20))>
<NTOSKRNL.EXE:726ec (ntoskrnl/lpc/reply.c:542 (NtReplyWaitReceivePort@16))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<00000000>
kdb:> thread attach 0x284
Attached to thread 0x00000284.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<NTOSKRNL.EXE:71ec2 (ntoskrnl/lpc/reply.c:383 (NtReplyWaitReceivePortEx@20))>
<NTOSKRNL.EXE:726ec (ntoskrnl/lpc/reply.c:542 (NtReplyWaitReceivePort@16))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<00000000>
kdb:> thread attach 0x29c
Attached to thread 0x0000029c.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<NTOSKRNL.EXE:71ec2 (ntoskrnl/lpc/reply.c:383 (NtReplyWaitReceivePortEx@20))>
<NTOSKRNL.EXE:726ec (ntoskrnl/lpc/reply.c:542 (NtReplyWaitReceivePort@16))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<00000000>
kdb:> thread attach 0x2b0
Attached to thread 0x000002b0.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<NTOSKRNL.EXE:71ec2 (ntoskrnl/lpc/reply.c:383 (NtReplyWaitReceivePortEx@20))>
<NTOSKRNL.EXE:726ec (ntoskrnl/lpc/reply.c:542 (NtReplyWaitReceivePort@16))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<00000000>
'==============================================================================WINLOGON
kdb:>proc attach 0xa0
Attached to process 0x000000a0, thread 0x000000a4.
kdb:> thread list
TID State Prior. Affinity EBP EIP
*0x000000a4 Waiting 9 0x00000001 0x0063fecc 0x7c9061d5
0x000000f0 Waiting 8 0x00000001 0x0139faf4 0x7c9061d5
kdb:> thread attach 0xa4
Attached to thread 0x000000a4.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:1137e (ntoskrnl/ke/wait.c:813 (KeWaitForMultipleObjects@32))>
<win32k.sys:73068 (subsystems/win32/win32k/ntuser/msgqueue.c:1392 (@co_MsqWaitFo
rNewMessages@16))>
<win32k.sys:6e772 (subsystems/win32/win32k/ntuser/message.c:1084 (@co_IntWaitMes
sage@12))>
<win32k.sys:6e7d3 (subsystems/win32/win32k/ntuser/message.c:1187 (NtUserGetMessa
ge@16))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<winlogon.exe:3352>
<winlogon.exe:4e34>
<winlogon.exe:4c07>
<winlogon.exe:4d2b>
<00000000>
kdb:> thread attach 0xf0
Attached to thread 0x000000f0.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<NTOSKRNL.EXE:a3386 (ntoskrnl/ob/obwait.c:407 (NtWaitForSingleObject@12))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<kernel32.dll:267d8>
<winlogon.exe:2fa6>
<kernel32.dll:26efc>
<00000000>
'============================================================================SERVICES
kdb:> proc attach 0xbc
Attached to process 0x000000bc, thread 0x000000c0.
kdb:> thread list
TID State Prior. Affinity EBP EIP
*0x000000c0 Waiting 9 0x00000001 0x0063fee4 0x7c9061d5
0x000000dc Waiting 8 0x00000001 0x0117ff44 0x7c9061d5
0x00000160 Waiting 8 0x00000001 0x019bfff4 0x7c9061d5
0x00000168 Waiting 8 0x00000001 0x01bbfff4 0x7c9061d5
0x00000178 Waiting 8 0x00000001 0x01dbfe70 0x7c9061d5
0x00000290 Waiting 8 0x00000001 0x01fcfff4 0x7c9061d5
0x000002bc Waiting 8 0x00000001 0x015bfff4 0x7c9061d5
kdb:> thread attach 0xc0
Attached to thread 0x000000c0.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<NTOSKRNL.EXE:a3386 (ntoskrnl/ob/obwait.c:407 (NtWaitForSingleObject@12))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<kernel32.dll:267d8>
<services.exe:76b6>
<services.exe:7c0b>
<services.exe:79f8>
<services.exe:7af0>
<kernel32.dll:23038>
<00000000>
kdb:> thread attach 0xdc
Attached to thread 0x000000dc.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:1137e (ntoskrnl/ke/wait.c:813 (KeWaitForMultipleObjects@32))>
<NTOSKRNL.EXE:a30d9 (ntoskrnl/ob/obwait.c:250 (NtWaitForMultipleObjects@20))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<rpcrt4.dll:1eae3>
<rpcrt4.dll:1c7a2>
<kernel32.dll:26efc>
<00000000>
kdb:> thread attach 0x160
Attached to thread 0x00000160.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:c3f4 (ntoskrnl/ke/queue.c:403 (KeRemoveQueue@12))>
<NTOSKRNL.EXE:4f947 (ntoskrnl/io/iomgr/iocomp.c:509 (NtRemoveIoCompletion@20))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<00000000>
kdb:> thread attach 0x168
Attached to thread 0x00000168.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:c3f4 (ntoskrnl/ke/queue.c:403 (KeRemoveQueue@12))>
<NTOSKRNL.EXE:4f947 (ntoskrnl/io/iomgr/iocomp.c:509 (NtRemoveIoCompletion@20))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<00000000>
kdb:> thread attach 0x178
Attached to thread 0x00000178.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<NTOSKRNL.EXE:a3386 (ntoskrnl/ob/obwait.c:407 (NtWaitForSingleObject@12))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<kernel32.dll:267d8>
<kernel32.dll:42e8>
<rpcrt4.dll:1e4f3>
<rpcrt4.dll:1ab1b>
<rpcrt4.dll:1a90d>
<rpcrt4.dll:1ab6e>
<rpcrt4.dll:1b0e1>
<rpcrt4.dll:1c592>
<kernel32.dll:26efc>
<00000000>
kdb:> thread attach 0x290
Attached to thread 0x00000290.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:c3f4 (ntoskrnl/ke/queue.c:403 (KeRemoveQueue@12))>
<NTOSKRNL.EXE:4f947 (ntoskrnl/io/iomgr/iocomp.c:509 (NtRemoveIoCompletion@20))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<00000000>
kdb:> thread attach 0x2bc
Attached to thread 0x000002bc.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:c3f4 (ntoskrnl/ke/queue.c:403 (KeRemoveQueue@12))>
<NTOSKRNL.EXE:4f947 (ntoskrnl/io/iomgr/iocomp.c:509 (NtRemoveIoCompletion@20))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<00000000>
'===============================================================================LSASS
kdb:>proc attach 0xc4
Attached to process 0x000000c4, thread 0x000000d8.
kdb:> thread list
TID State Prior. Affinity EBP EIP
*0x000000d8 Waiting 9 0x00000001 0x0116ff4c 0x7c9061d5
0x000000e0 Waiting 8 0x00000001 0x00c5ff44 0x7c9061d5
kdb:> thread attach 0xd8
Attached to thread 0x000000d8.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<NTOSKRNL.EXE:a3386 (ntoskrnl/ob/obwait.c:407 (NtWaitForSingleObject@12))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<kernel32.dll:267d8>
<rpcrt4.dll:1d9ba>
<rpcrt4.dll:1d968>
<lsasrv.dll:2492>
<kernel32.dll:26efc>
<00000000>
kdb:> thread attach 0xc0
Attached to thread 0x000000c0.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<NTOSKRNL.EXE:a3386 (ntoskrnl/ob/obwait.c:407 (NtWaitForSingleObject@12))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<kernel32.dll:267d8>
<services.exe:76b6>
<services.exe:7c0b>
<services.exe:79f8>
<services.exe:7af0>
<kernel32.dll:23038>
<00000000>
'===========================================================================EVENTLOG
kdb:> proc attach 0xe4
Attached to process 0x000000e4, thread 0x000000e8.
kdb:> thread list
TID State Prior. Affinity EBP EIP
*0x000000e8 Waiting 8 0x00000001 0x0063fcbc 0x7c9061d5
0x0000010c Waiting 8 0x00000001 0x0148ff88 0x7c9061d5
0x00000110 Waiting 9 0x00000001 0x0168ff4c 0x7c9061d5
0x00000124 Waiting 8 0x00000001 0x0128ff44 0x7c9061d5
kdb:> thread attach 0xe8
Attached to thread 0x000000e8.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<npfs.sys:30dd (drivers/filesystems/npfs/rw.c:466 (NpfsRead@8))>
<NTOSKRNL.EXE:56791 (ntoskrnl/io/iomgr/irp.c:1137 (@IofCallDriver@8))>
<NTOSKRNL.EXE:4ffe9 (ntoskrnl/io/iomgr/iofunc.c:137 (IopPerformSynchronousReques
t@28))>
<NTOSKRNL.EXE:5273d (ntoskrnl/io/iomgr/iofunc.c:2178 (NtReadFile@36))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<advapi32.dll:1c6c0>
<advapi32.dll:1cf1e>
<eventlog.exe:14b1>
<eventlog.exe:3390>
<eventlog.exe:3488>
<kernel32.dll:23038>
<00000000>
kdb:> thread attach 0x10c
Attached to thread 0x0000010c.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<NTOSKRNL.EXE:71ec2 (ntoskrnl/lpc/reply.c:383 (NtReplyWaitReceivePortEx@20))>
<NTOSKRNL.EXE:726ec (ntoskrnl/lpc/reply.c:542 (NtReplyWaitReceivePort@16))>
<NTOSKRNL.EXE:70832 (ntoskrnl/lpc/listen.c:39 (NtListenPort@8))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<eventlog.exe:1795>
<kernel32.dll:26efc>
<00000000>
kdb:> thread attach 0x110
Attached to thread 0x00000110.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<NTOSKRNL.EXE:a3386 (ntoskrnl/ob/obwait.c:407 (NtWaitForSingleObject@12))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<kernel32.dll:267d8>
<rpcrt4.dll:1d9ba>
<rpcrt4.dll:1d968>
<eventlog.exe:2044>
<kernel32.dll:26efc>
<00000000>
kdb:> thread attach 0x124
Attached to thread 0x00000124.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:1137e (ntoskrnl/ke/wait.c:813 (KeWaitForMultipleObjects@32))>
<NTOSKRNL.EXE:a30d9 (ntoskrnl/ob/obwait.c:250 (NtWaitForMultipleObjects@20))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<rpcrt4.dll:1eae3>
<rpcrt4.dll:1c7a2>
<kernel32.dll:26efc>
<00000000>
'==============================================================================SETUP
kdb:> proc attach 0xf4
Attached to process 0x000000f4, thread 0x000000f8.
kdb:> thread list
TID State Prior. Affinity EBP EIP
*0x000000f8 Ready 8 0x00000001 0x0062fb98 0x7c9061d5
0x00000174 Waiting 8 0x00000001 0x0120ff5c 0x7c9061d5
kdb:> thread attach 0xf8
Attached to thread 0x000000f8.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:1137e (ntoskrnl/ke/wait.c:813 (KeWaitForMultipleObjects@32))>
<win32k.sys:73068 (subsystems/win32/win32k/ntuser/msgqueue.c:1392 (@co_MsqWaitFo
rNewMessages@16))>
<win32k.sys:6e772 (subsystems/win32/win32k/ntuser/message.c:1084 (@co_IntWaitMes
sage@12))>
<win32k.sys:6e7d3 (subsystems/win32/win32k/ntuser/message.c:1187 (NtUserGetMessa
ge@16))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<comctl32.dll:30abe>
<comctl32.dll:30e91>
<syssetup.dll:4bbc>
<syssetup.dll:1f36>
<setup.exe:109e>
<setup.exe:15cb>
<setup.exe:13b8>
<setup.exe:14c9>
<kernel32.dll:23038>
<00000000>
kdb:> thread attach 0x174
Attached to thread 0x00000174.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:1137e (ntoskrnl/ke/wait.c:813 (KeWaitForMultipleObjects@32))>
<win32k.sys:73068 (subsystems/win32/win32k/ntuser/msgqueue.c:1392 (@co_MsqWaitFo
rNewMessages@16))>
<win32k.sys:6e772 (subsystems/win32/win32k/ntuser/message.c:1084 (@co_IntWaitMes
sage@12))>
<win32k.sys:6e7d3 (subsystems/win32/win32k/ntuser/message.c:1187 (NtUserGetMessa
ge@16))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<syssetup.dll:17f7>
<kernel32.dll:26efc>
<00000000>
'==============================================================================SPOOLSV
kdb:> proc attach 0x104
Attached to process 0x00000104, thread 0x00000108.
kdb:> thread list
TID State Prior. Affinity EBP EIP
*0x00000108 Waiting 8 0x00000001 0x0062feac 0x7c9061d5
kdb:> thread attach 0x108
Attached to thread 0x00000108.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<npfs.sys:30dd (drivers/filesystems/npfs/rw.c:466 (NpfsRead@8))>
<NTOSKRNL.EXE:56791 (ntoskrnl/io/iomgr/irp.c:1137 (@IofCallDriver@8))>
<NTOSKRNL.EXE:4ffe9 (ntoskrnl/io/iomgr/iofunc.c:137 (IopPerformSynchronousReques
t@28))>
<NTOSKRNL.EXE:5273d (ntoskrnl/io/iomgr/iofunc.c:2178 (NtReadFile@36))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<advapi32.dll:1c6c0>
<advapi32.dll:1cf1e>
<spoolsv.exe:1038>
<spoolsv.exe:1364>
<spoolsv.exe:145c>
<kernel32.dll:23038>
<00000000>
'============================================================================RPCSS
kdb:>proc attach 0x11c
Attached to process 0x0000011c, thread 0x00000120.
kdb:> thread list
TID State Prior. Affinity EBP EIP
*0x00000120 Waiting 8 0x00000001 0x0062feac 0x7c9061d5
0x0000015c Waiting 8 0x00000001 0x0156ff44 0x7c9061d5
0x00000164 Waiting 8 0x00000001 0x0176ff44 0x7c9061d5
kdb:> thread attach 0x120
Attached to thread 0x00000120.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<npfs.sys:30dd (drivers/filesystems/npfs/rw.c:466 (NpfsRead@8))>
<NTOSKRNL.EXE:56791 (ntoskrnl/io/iomgr/irp.c:1137 (@IofCallDriver@8))>
<NTOSKRNL.EXE:4ffe9 (ntoskrnl/io/iomgr/iofunc.c:137 (IopPerformSynchronousReques
t@28))>
<NTOSKRNL.EXE:5273d (ntoskrnl/io/iomgr/iofunc.c:2178 (NtReadFile@36))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<advapi32.dll:1c6c0>
<advapi32.dll:1cf1e>
<rpcss.exe:2005>
<rpcss.exe:2440>
<rpcss.exe:2538>
<kernel32.dll:23038>
<00000000>
kdb:> thread attach 0x15c
Attached to thread 0x0000015c.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:1137e (ntoskrnl/ke/wait.c:813 (KeWaitForMultipleObjects@32))>
<NTOSKRNL.EXE:a30d9 (ntoskrnl/ob/obwait.c:250 (NtWaitForMultipleObjects@20))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<rpcrt4.dll:1eae3>
<rpcrt4.dll:1c7a2>
<kernel32.dll:26efc>
<00000000>
kdb:> thread attach 0x164
Attached to thread 0x00000164.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:1137e (ntoskrnl/ke/wait.c:813 (KeWaitForMultipleObjects@32))>
<NTOSKRNL.EXE:a30d9 (ntoskrnl/ob/obwait.c:250 (NtWaitForMultipleObjects@20))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<rpcrt4.dll:1eae3>
<rpcrt4.dll:1c7a2>
<kernel32.dll:26efc>
<00000000>
'=====================================================================DHCPP
kdb:> proc attach 0x130
Attached to process 0x00000130, thread 0x00000134.
kdb:> thread list
TID State Prior. Affinity EBP EIP
*0x00000134 Waiting 8 0x00000001 0x0064fec0 0x7c9061d5
0x0000013c Waiting 8 0x00000001 0x0118ff58 0x7c9061d5
0x00000140 Waiting 8 0x00000001 0x0138fe00 0x7c9061d5
kdb:> thread attach 0x134
Attached to thread 0x00000134.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<npfs.sys:30dd (drivers/filesystems/npfs/rw.c:466 (NpfsRead@8))>
<NTOSKRNL.EXE:56791 (ntoskrnl/io/iomgr/irp.c:1137 (@IofCallDriver@8))>
<NTOSKRNL.EXE:4ffe9 (ntoskrnl/io/iomgr/iofunc.c:137 (IopPerformSynchronousReques
t@28))>
<NTOSKRNL.EXE:5273d (ntoskrnl/io/iomgr/iofunc.c:2178 (NtReadFile@36))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<advapi32.dll:1c6c0>
<advapi32.dll:1cce9>
<dhcp.exe:51c0>
<dhcp.exe:7adb>
<dhcp.exe:7be6>
<kernel32.dll:23038>
<00000000>
kdb:> thread attach 0x13c
Attached to thread 0x0000013c.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<npfs.sys:23d7 (drivers/filesystems/npfs/fsctrl.c:170 (NpfsFileSystemControl@8))
>
<NTOSKRNL.EXE:56791 (ntoskrnl/io/iomgr/irp.c:1137 (@IofCallDriver@8))>
<NTOSKRNL.EXE:4ffe9 (ntoskrnl/io/iomgr/iofunc.c:137 (IopPerformSynchronousReques
t@28))>
<NTOSKRNL.EXE:50369 (ntoskrnl/io/iomgr/iofunc.c:506 (IopDeviceFsIoControl@44))>
<NTOSKRNL.EXE:50e3a (ntoskrnl/io/iomgr/iofunc.c:951 (NtFsControlFile@40))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<dhcp.exe:6b9b>
<kernel32.dll:26efc>
<00000000>
kdb:> thread attach 0x140
Attached to thread 0x00000140.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:104e5 (ntoskrnl/ke/wait.c:357 (KeDelayExecutionThread@12))>
<NTOSKRNL.EXE:114cb (ntoskrnl/ke/wait.c:880 (NtDelayExecution@8))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<kernel32.dll:27655>
<ws2_32.dll:2883>
<dhcp.exe:5773>
<dhcp.exe:536c>
<advapi32.dll:1c197>
<kernel32.dll:26efc>
<00000000>
'==========================================================================UMPNPMGR
kdb:> proc attach 0x17c
Attached to process 0x0000017c, thread 0x00000180.
kdb:> thread list
TID State Prior. Affinity EBP EIP
*0x00000180 Waiting 8 0x00000001 0x0063fec4 0x7c9061d5
0x0000018c Waiting 8 0x00000001 0x0137ff94 0x7c9061d5
0x00000190 Waiting 9 0x00000001 0x0157ff48 0x7c9061d5
0x00000194 Waiting 8 0x00000001 0x0177fc6c 0x7c9061d5
0x00000198 Waiting 8 0x00000001 0x0117ff44 0x7c9061d5
0x000001b8 Waiting 8 0x00000001 0x01f8fff4 0x7c9061d5
0x000001cc Waiting 8 0x00000001 0x0238fff4 0x7c9061d5
0x000001d0 Waiting 8 0x00000001 0x0258fff4 0x7c9061d5
0x000002c0 Waiting 8 0x00000001 0x01a5fff4 0x7c9061d5
kdb:> thread attach 0x180
Attached to thread 0x00000180.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<npfs.sys:30dd (drivers/filesystems/npfs/rw.c:466 (NpfsRead@8))>
<NTOSKRNL.EXE:56791 (ntoskrnl/io/iomgr/irp.c:1137 (@IofCallDriver@8))>
<NTOSKRNL.EXE:4ffe9 (ntoskrnl/io/iomgr/iofunc.c:137 (IopPerformSynchronousReques
t@28))>
<NTOSKRNL.EXE:5273d (ntoskrnl/io/iomgr/iofunc.c:2178 (NtReadFile@36))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<advapi32.dll:1c6c0>
<advapi32.dll:1cf1e>
<umpnpmgr.exe:1b86>
<umpnpmgr.exe:2e9c>
<umpnpmgr.exe:2f94>
<kernel32.dll:23038>
<00000000>
kdb:> thread attach 0x18c
Attached to thread 0x0000018c.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<NTOSKRNL.EXE:5aab3 (ntoskrnl/io/pnpmgr/plugplay.c:679 (NtGetPlugPlayEvent@16))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<kernel32.dll:26efc>
<00000000>
kdb:> thread attach 0x190-
Attached to thread 0x00000190.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<NTOSKRNL.EXE:a3386 (ntoskrnl/ob/obwait.c:407 (NtWaitForSingleObject@12))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<kernel32.dll:267d8>
<rpcrt4.dll:1d9ba>
<rpcrt4.dll:1d968>
<umpnpmgr.exe:2467>
<kernel32.dll:26efc>
<00000000>
kdb:> thread attach 0x194
Attached to thread 0x00000194.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:10b7a (ntoskrnl/ke/wait.c:530 (KeWaitForSingleObject@20))>
<NTOSKRNL.EXE:a3386 (ntoskrnl/ob/obwait.c:407 (NtWaitForSingleObject@12))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<kernel32.dll:267d8>
<umpnpmgr.exe:22a0>
<kernel32.dll:26efc>
<00000000>
kdb:> thread attach 0x198
Attached to thread 0x00000198.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:1137e (ntoskrnl/ke/wait.c:813 (KeWaitForMultipleObjects@32))>
<NTOSKRNL.EXE:a30d9 (ntoskrnl/ob/obwait.c:250 (NtWaitForMultipleObjects@20))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<rpcrt4.dll:1eae3>
<rpcrt4.dll:1c7a2>
<kernel32.dll:26efc>
<00000000>
kdb:> thread attach 0x1b8
Attached to thread 0x000001b8.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:c3f4 (ntoskrnl/ke/queue.c:403 (KeRemoveQueue@12))>
<NTOSKRNL.EXE:4f947 (ntoskrnl/io/iomgr/iocomp.c:509 (NtRemoveIoCompletion@20))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<00000000>
kdb:> thread attach 0x1cc
Attached to thread 0x000001cc.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:c3f4 (ntoskrnl/ke/queue.c:403 (KeRemoveQueue@12))>
<NTOSKRNL.EXE:4f947 (ntoskrnl/io/iomgr/iocomp.c:509 (NtRemoveIoCompletion@20))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<00000000>
kdb:> thread attach 0x1d0
Attached to thread 0x000001d0.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:c3f4 (ntoskrnl/ke/queue.c:403 (KeRemoveQueue@12))>
<NTOSKRNL.EXE:4f947 (ntoskrnl/io/iomgr/iocomp.c:509 (NtRemoveIoCompletion@20))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<00000000>
kdb:> thread attach 0x2c0
Attached to thread 0x000002c0.
kdb:> bt
Eip:
<NTOSKRNL.EXE:d39a (ntoskrnl/ke/thrdschd.c:370 (@KiSwapThread@8))>
Frames:
<NTOSKRNL.EXE:c3f4 (ntoskrnl/ke/queue.c:403 (KeRemoveQueue@12))>
<NTOSKRNL.EXE:4f947 (ntoskrnl/io/iomgr/iocomp.c:509 (NtRemoveIoCompletion@20))>
<NTOSKRNL.EXE:ba5c4 (ntoskrnl\ke\i386\trap.s:244 (KiFastCallEntry))>
<ntdll.dll:61d5>
<00000000>
'============================================================================
kdb:>
Regards