locked
Application Error: WGAtray.exe RRS feed

  • Question

  • Hi all,

     

    After rebooting PC today and system got out onto desktop, I recieved a Microsoft Error dialog that WGAtray.exe had encountered a problem and would need to Close. First time, I've ever seen this error, so I've sent the Error report onto Microsoft. 

     

    I have posted the WGA item from the Event Viewer to see if someone might be able to shed some light on whats going on.

     

     Event Type: Error
    Event Source: Application Error
    Event Category: None
    Event ID: 1000
    Date:  6/23/2007
    Time:  1:36:29 PM
    User:  N/A
    Computer: SELF-DB******F3
    Description:
    Faulting application wgatray.exe, version 1.7.18.5, faulting module cryptnet.dll, version 5.131.2600.2180, fault address 0x00007011.

    For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
    Data:
    0000: 41 70 70 6c 69 63 61 74   Applicat
    0008: 69 6f 6e 20 46 61 69 6c   ion Fail
    0010: 75 72 65 20 20 77 67 61   ure  wga
    0018: 74 72 61 79 2e 65 78 65   tray.exe
    0020: 20 31 2e 37 2e 31 38 2e    1.7.18.
    0028: 35 20 69 6e 20 63 72 79   5 in cry
    0030: 70 74 6e 65 74 2e 64 6c   ptnet.dl
    0038: 6c 20 35 2e 31 33 31 2e   l 5.131.
    0040: 32 36 30 30 2e 32 31 38   2600.218
    0048: 30 20 61 74 20 6f 66 66   0 at off
    0050: 73 65 74 20 30 30 30 30   set 0000
    0058: 37 30 31 31 0d 0a         7011.. 

    When I clicked on the link above, IE encountered a problem and also needed to close. the Faulting Module info and the Fault address were the same for both errors.  Seems fine now after rebooting a 2nd time.   Looked for a Drwtsn32 log concerning both, but there were none.

     

    Thanks.

    C J.

    Saturday, June 23, 2007 9:44 PM

Answers

  • Just Another:

     

    Apologies for the delay in response. We normally do not "leave people hanging" - but due to the Holiday season here ... Smile.

     

    Anyhow, our developers have been able to identify the issue with your system. It seems that the Licdll.dll file in your windows\system32 directory (which is used to check system licensing files in Windows) has an issue. I would highly suggest going to the command prompt (start->run then type in CMD and press enter).

     

    Upon the new screen, type in "regsvr32 licdll.dll /u" which should unregister licdll.dll. By default, Windows will then use licwmi.dll in the same directory for checking license files as a backup. This rarely happens, but the primary cause is either from:

     

    1 - a very fragmented installation of Windows (would suggest to defragment your harddrive)

    2 - corrupted file (would suggest a repair installation of Windows to recover the files).

     

     

    I hope this helps,

    -phil

    Friday, July 6, 2007 10:22 PM
  •  

    Hi Phil...

     

      I defragmented the drive using AusLogic Disk Defrag on Sun (July 1.) funny you mention doing this.  I've had some other problems as well - which were not related to the Windows Installation itself (Clean install was 10months old and has run pretty well, up until recently). 

     

    I started getting "Disk Error press ctrl -alt - del to restart" messages on Wednesday, and couldn't boot from this drive. I fixed that lastnight. I replaced old primary ide cable. Then using another XP Pro disk drive I have for this PC -- I ran chkdsk /r on all three partitions of this drive from CMD.  The extended partition of this drive (harddrive 0\ D) is damaged.  I'm looking at Imaging what I have now, then I'll do a low level format. 

     

    Hopefully, what I restore back from image will not have to be repair installed.

     

    Went ahead and unregistered licdll.dll in the meantime.

     

    Friday, July 6, 2007 11:21 PM
  • C J I'm assuming it worked just fine for you? Smile

     

    -phil

    Friday, July 13, 2007 10:12 PM
  • Unregistering the File seemed to do the trick. There has been no reoccurence of the error. I'm still waiting for my new hard drive to arrive.  I want to get this PC up and working again now the reason for the Drive Error problem is understood (what caused it) Thanks everyone for the help.
    Friday, July 13, 2007 11:46 PM

All replies

  • Just another c j,

    Please follow these steps for assistance:

    Step 1 is to run the utility at this link http://go.microsoft.com/fwlink/?linkid=52012, then click the Windows tab, click the "Copy" button, then paste the report into a response in this thread.

    Step 2 is to look on the computer or with the materials you received with the computer or with your retail purchase of  Windows to see if you have a Certificate of Authenticity (COA).  If you have one, tell us about the COA.  Tell us:

    1.  What edition of Windows XP is it for, Home, Pro, or Media Center, or another version of Windows?

    2.  Does it read "OEM Software" or "OEM Product" in black lettering?

    3.  Or, does it have the computer manufacturer's name in black lettering?

    4.  DO NOT post the Product Key.

    Not sure what to look for?  See this page for reference:  http://www.microsoft.com/resources/howtotell/en/coa.mspx

    Sunday, June 24, 2007 8:37 PM
  • Hi Dan,

    Here is the report you requested and CoA sticker info below that.

     

    Diagnostic Report (1.7.0012.0):
    -----------------------------------------
    WGA Data-->
    Validation Status: Genuine
    Detailed Status: N/A
    Windows Product Key: *****-*****-47XJH-2HDMX-JMRP8
    Windows Product Key Hash: 7J/k4JlkIOZETLRPf7kOLFxGDjQ=
    Windows Product ID: 76487-017-7819755-22956
    Windows Product ID Type: 5
    Windows License Type: Retail
    Windows OS version: 5.1.2600.2.00010100.2.0.pro
    ID: a6a8152f-c5d1-49b7-ad1c-4bb93a2c4510
    Is Admin: Yes
    AutoDial: No
    Registry: 0x0
    WGA Version: Registered, 1.7.36.0
    Signed By: Microsoft
    Product Name: N/A
    Architecture: N/A
    Build lab: N/A
    TTS Error: N/A
    Validation Diagnostic:
    Resolution Status: N/A

    Notifications Data-->
    Cached Result: 0
    File Exists: Yes
    Version: 1.7.18.5
    WgaTray.exe Signed By: Microsoft
    WgaLogon.dll Signed By: Microsoft

    OGA Data-->
    Office Status: 109 N/A
    OGA Version: Failed to retrieve file version. - 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: FCEE394C-3178-80070002

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE; Win32)
    Default Browser: C:\Program Files\Internet Explorer\iexplore.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>a6a8152f-c5d1-49b7-ad1c-4bb93a2c4510</UGUID><Version>1.7.0012.0</Version><OS>5.1.2600.2.00010100.2.0.pro</OS><PKey>*****-*****-*****-*****-JMRP8</PKey><PID>76487-017-7819755-22956</PID><PIDType>5</PIDType><SID>S-1-5-21-484763869-1409082233-682003330</SID><SYSTEM><Manufacturer>INTEL_</Manufacturer><Model>D845EBG2</Model></SYSTEM><BIOS><Manufacturer>Intel Corp.</Manufacturer><Version>PT84520A.86A.0015.P08.0302261328</Version><SMBIOSVersion major="2" minor="3"/><Date>20030226000000.000000+000</Date></BIOS><HWID>E363364701842162</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Pacific Standard Time(GMT-08:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM/></MachineData>   <Software><Office><Result>109</Result><Products/></Office></Software></GenuineResults> 

     

    This version of Windows XP Professional SP 2 has what looks like a Paper type(?) CoA affixed on top of the box it shipped in (could be faded) Doesn't indicate "OEM Product" or "OEM Software" on CoA. Sticker conforms to Microsoft CoA (large Oval with tearing around inside edges "GENUINE" displaying on metal like ribbon inside) Info on Tag.... :

     =======================================================================

    [BAR CODE]

     

    E85-02665 

    PO 4400005674                                 Line 2                 [Bar code] 99994-567-789-359

    WO 393719                                        Team: SDUN

                                                                                             [Bar code] 8||0 5 5 2 9||8 3 1 2 7||8 

    Windows XP Professional English NA                          

    Made in Puerto Rico

    For Distribution in US and Canada Only

    ========================================================================

     

    Sunday, June 24, 2007 9:27 PM
  • Just Another C J:

     

    Thanks for bringing this to our attention. I'll have my developers look at this immediately!

     

    Standby for follow-up Smile

     

    -phil

    Monday, June 25, 2007 11:47 PM
  •  

    Some additional information for you guys:  After WGAtray.exe faulted...a second App Error - Fault Bucket: 400355456 was logged in EV and was followed by the IE 6 error containing Same info Re cryptnet.dll  - for WGAtray.exe.

     

          

     

     

    Tuesday, June 26, 2007 2:44 AM
  • I was alerted there was a reply posted to this thread.  Came back and didn't find anything new??
    Friday, July 6, 2007 4:06 AM
  •  

    IT HAPPENED AGAIN....

     

    This time I was ready for it,  please find info produced below:

    ===============================================================================================

    Event Viewer

    ===============================================================================================


    Event Type: Error
    Event Source: Application Error
    Event Category: None
    Event ID: 1000
    Date:  7/6/2007
    Time:  9:35:13 AM
    User:  N/A
    Computer: SELF-DBXXXXXXF3
    Description:
    Faulting application wgatray.exe, version 1.7.18.5, faulting module unknown,

    version 0.0.0.0, fault address 0x611d9955.

    For more information, see Help

    and Support Center at hxxp://xx.microsoft.com/fwlink/events.asp.
    Data:
    0000: 41 70 70 6c 69 63 61 74   Applicat
    0008: 69 6f 6e 20 46 61 69 6c   ion Fail
    0010: 75 72 65 20 20 77 67 61   ure  wga
    0018: 74 72 61 79 2e 65 78 65   tray.exe
    0020: 20 31 2e 37 2e 31 38 2e    1.7.18.
    0028: 35 20 69 6e 20 75 6e 6b   5 in unk
    0030: 6e 6f 77 6e 20 30 2e 30   nown 0.0
    0038: 2e 30 2e 30 20 61 74 20   .0.0 at
    0040: 6f 66 66 73 65 74 20 36   offset 6
    0048: 31 31 64 39 39 35 35 0d   11d9955.
    0050: 0a                        .      

    Event Type: Error
    Event Source: Application Error
    Event Category: None
    Event ID: 1001
    Date:  7/6/2007
    Time:  9:35:50 AM
    User:  N/A
    Computer: SELF-DBXXXXXXF3
    Description:
    Fault bucket 419109394.

    For more information, see Help and Support

    Center at hxxp://xx.microsoft.com/fwlink/events.asp.
    Data:
    0000: 42 75 63 6b 65 74 3a 20   Bucket:
    0008: 34 31 39 31 30 39 33 39   41910939
    0010: 34 0d 0a                  4..    

     

    ===============================================================================================

    Dr Watson Details

    ===============================================================================================


    Microsoft (R) DrWtsn32
    Copyright (C) 1985-2001 Microsoft Corp. All rights reserved.

     

    Application exception occurred:
            App: C:\WINDOWS\system32\WgaTray.exe (pid=2036)
            When: 7/6/2007 @ 09:35:52.187
            Exception number: c0000005 (access violation)

    *----> System Information <----*
            Computer Name: SELF-DXXXXXXF3
            User Name: Chris
            Terminal Session Id: 0
            Number of Processors: 1
            Processor Type: x86 Family 15 Model 2 Stepping 4
            Windows Version: 5.1
            Current Build: 2600
            Service Pack: 2
            Current Type: Uniprocessor Free
            Registered Organization: self
            Registered Owner: Chris

    *----> Task List <----*
       0 System Process
       4 System
     608 smss.exe
     660 csrss.exe
     684 winlogon.exe
     728 services.exe
     740 lsass.exe
     896 svchost.exe
     976 svchost.exe
    1076 svchost.exe
    1320 spoolsv.exe
    1428 btwdins.exe
    1448 CTsvcCDA.EXE
    1532 nod32krn.exe
    1592 ssoftsrv.exe
    1652 svchost.exe
    1680 wdfmgr.exe
    1720 uphclean.exe
    1764 MsPMSPSv.exe
     200 alg.exe
    1380 Explorer.EXE
    2004 Error 0xD0000022
    2016 ybrwicon.exe
    2028 jusched.exe
    2036 WgaTray.exe
     152 Smtray.exe
     208 ycommon.exe
     244 nod32kui.exe
     408 AHQTB.EXE
     468 BTTray.exe
     496 mad.exe
     592 mpbtn.exe
     628 devldr32.exe
     916 wmiprvse.exe
    1260 MOTIVE~1.EXE
    1984 Error 0xD0000022
    2260 Error 0xD000000D
    2944 wuauclt.exe
    2688 drwtsn32.exe

    *----> Module List <----*
    (0000000001000000 - 0000000001052000: C:\WINDOWS\system32\WgaTray.exe
    (0000000001210000 - 000000000137b000: C:\WINDOWS\system32\LegitCheckControl.DLL
    (000000000ffd0000 - 000000000fff8000: C:\WINDOWS\system32\rsaenh.dll
    (0000000020000000 - 00000000202c5000: C:\WINDOWS\system32\xpsp2res.dll
    (000000004d4f0000 - 000000004d548000: C:\WINDOWS\system32\WINHTTP.dll
    (000000005b860000 - 000000005b8b4000: C:\WINDOWS\system32\netapi32.dll
    (0000000061050000 - 00000000610ba000: C:\WINDOWS\system32\licdll.dll
    (0000000071aa0000 - 0000000071aa8000: C:\WINDOWS\system32\WS2HELP.dll
    (0000000071ab0000 - 0000000071ac7000: C:\WINDOWS\system32\WS2_32.dll
    (0000000071ad0000 - 0000000071ad9000: C:\WINDOWS\system32\wsock32.dll
    (00000000722b0000 - 00000000722b5000: C:\WINDOWS\system32\SensApi.dll
    (0000000074980000 - 0000000074a8e000: C:\WINDOWS\system32\msxml3.dll
    (0000000074ed0000 - 0000000074ede000: C:\WINDOWS\system32\wbem\wbemsvc.dll
    (0000000074ef0000 - 0000000074ef8000: C:\WINDOWS\system32\wbem\wbemprox.dll
    (0000000075290000 - 00000000752c7000: C:\WINDOWS\system32\wbem\wbemcomn.dll
    (0000000075690000 - 0000000075706000: C:\WINDOWS\system32\wbem\fastprox.dll
    (0000000075e60000 - 0000000075e73000: C:\WINDOWS\system32\cryptnet.dll
    (0000000075e90000 - 0000000075f40000: C:\WINDOWS\system32\SXS.DLL
    (0000000076080000 - 00000000760e5000: C:\WINDOWS\system32\MSVCP60.dll
    (00000000767a0000 - 00000000767b3000: C:\WINDOWS\system32\NTDSAPI.dll
    (00000000769c0000 - 0000000076a73000: C:\WINDOWS\system32\userenv.dll
    (0000000076f20000 - 0000000076f47000: C:\WINDOWS\system32\DNSAPI.dll
    (0000000076f60000 - 0000000076f8c000: C:\WINDOWS\system32\WLDAP32.dll
    (0000000076fd0000 - 000000007704f000: C:\WINDOWS\system32\CLBCATQ.DLL
    (0000000077050000 - 0000000077115000: C:\WINDOWS\system32\COMRes.dll
    (0000000077120000 - 00000000771ac000: C:\WINDOWS\system32\OLEAUT32.dll
    (00000000771b0000 - 0000000077256000: C:\WINDOWS\system32\WININET.dll
    (00000000773d0000 - 00000000774d3000: C:\WINDOWS\WinSxS\X86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\COMCTL32.dll
    (00000000774e0000 - 000000007761d000: C:\WINDOWS\system32\ole32.dll
    (0000000077920000 - 0000000077a13000: C:\WINDOWS\system32\SETUPAPI.dll
    (0000000077a80000 - 0000000077b14000: C:\WINDOWS\system32\CRYPT32.dll
    (0000000077b20000 - 0000000077b32000: C:\WINDOWS\system32\MSASN1.dll
    (0000000077b40000 - 0000000077b62000: C:\WINDOWS\system32\Apphelp.dll
    (0000000077c00000 - 0000000077c08000: C:\WINDOWS\system32\VERSION.dll
    (0000000077c10000 - 0000000077c68000: C:\WINDOWS\system32\msvcrt.dll
    (0000000077dd0000 - 0000000077e6b000: C:\WINDOWS\system32\ADVAPI32.dll
    (0000000077e70000 - 0000000077f01000: C:\WINDOWS\system32\RPCRT4.dll
    (0000000077f10000 - 0000000077f57000: C:\WINDOWS\system32\GDI32.dll
    (0000000077f60000 - 0000000077fd6000: C:\WINDOWS\system32\SHLWAPI.dll
    (0000000077fe0000 - 0000000077ff1000: C:\WINDOWS\system32\secur32.dll
    (000000007c800000 - 000000007c8f5000: C:\WINDOWS\system32\kernel32.dll
    (000000007c900000 - 000000007c9b0000: C:\WINDOWS\system32\ntdll.dll
    (000000007c9c0000 - 000000007d1d5000: C:\WINDOWS\system32\SHELL32.dll
    (000000007e410000 - 000000007e4a0000: C:\WINDOWS\system32\USER32.dll

    *----> State Dump for Thread Id 0x7f8 <----*

    eax=7ffdf000 ebx=00000000 ecx=00000000 edx=00140014 esi=0006ea6c edi=0006ea68
    eip=611d9955 esp=0006e640 ebp=0006ea34 iopl=0         nv up ei pl zr na po nc
    cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246

    function: <nosymbols>
    No prior disassembly possible
            611d9955 ??               ???
            611d9957 ??               ???
            611d9959 ??               ???
            611d995b ??               ???
            611d995d ??               ???
            611d995f ??               ???
            611d9961 ??               ???
            611d9963 ??               ???
            611d9965 ??               ???
    FAULT ->611d9955 ??               ???
    Error 0x00000001
            611d9957 ??               ???
            611d9959 ??               ???
            611d995b ??               ???
            611d995d ??               ???
            611d995f ??               ???
            611d9961 ??               ???
            611d9963 ??               ???
            611d9965 ??               ???
            611d9967 ??               ???
            611d9969 ??               ???

    *----> Stack Back Trace <----*
    *** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\licdll.dll -
    WARNING: Stack unwind information not available. Following frames may be wrong.
    *** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\LegitCheckControl.DLL -
    *** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\OLEAUT32.dll -
    *** ERROR: Module load completed but symbols could not be loaded for C:\WINDOWS\system32\WgaTray.exe
    *** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\kernel32.dll -
    ChildEBP RetAddr  Args to Child             
    0006e63c 610ad13f 610af878 61051000 07610000 0x611d9955
    0006ea34 62ba08cc 0006ea6c 0006ea68 00000000 licdll+0x5d13f
    0006ed90 6106920e 0000c475 00000004 00000000 0x62ba08cc
    0006eda8 0124750a 00777c20 0000c475 00000004 licdll!DllUnregisterServer+0x52b
    0006ede4 012477d3 0006ee0c 0006ee10 013839bc LegitCheckControl+0x3750a
    0006ee28 0124790f 0006ee54 0006ee6b 00000000 LegitCheckControl+0x377d3
    0006ee5c 01239ff6 013839c4 003839bc 013839c0 LegitCheckControl+0x3790f
    0006eecc 0122ae2e 013839b4 013839a8 01339c50 LegitCheckControl+0x29ff6
    0006ef38 0122b0f6 00000000 0006ef68 0006ef64 LegitCheckControl+0x1ae2e
    0006f8b0 771273d0 013839a8 0006f910 0006f9d0 LegitCheckControl+0x1b0f6
    0006f8cc 771279e0 013839a8 0000001c 00000004 OLEAUT32!DispCallFunc+0xc3
    0006f95c 0122be9d 0014bd1c 013839a8 00000000 OLEAUT32!DispCallFunc+0x6d3
    0006f988 01009999 013839a8 00000001 01002df0 LegitCheckControl+0x1be9d
    0006fa20 0100aea8 0006fa4c 0006fa60 0006fa68 WgaTray+0x9999
    0006fc8c 0100bd90 01043020 09064000 01043024 WgaTray+0xaea8
    0006ff10 0100dcd2 01000000 00000000 00020662 WgaTray+0xbd90
    0006ffa8 0103011b 00074440 01a4f944 7ffd6000 WgaTray+0xdcd2
    0006ffc0 7c816fd7 00074440 01a4f944 7ffd6000 WgaTray+0x3011b
    0006fff0 00000000 010300a4 00000000 78746341 kernel32!RegisterWaitForInputIdle+0x49

    *----> Raw Stack Dump <----*
    000000000006e640  3f d1 0a 61 78 f8 0a 61 - 00 10 05 61 00 00 61 07  ?..ax..a...a..a.
    000000000006e650  05 c8 0a 61 88 e6 06 00 - 1f 00 00 00 38 15 05 61  ...a........8..a
    000000000006e660  6c ea 06 00 88 e6 06 00 - 68 ea 06 00 6c ea 06 00  l.......h...l...
    000000000006e670  34 ea 06 00 88 e6 06 00 - 00 00 00 00 00 00 00 00  4...............
    000000000006e680  00 46 c3 23 00 00 00 00 - 46 02 00 00 5c 8f 77 00  .F.#....F...\.w.
    000000000006e690  00 00 00 00 28 7c 77 00 - 3e 11 00 00 1f e0 00 00  ....(|w.>.......
    000000000006e6a0  1f e0 37 6e 75 d5 3b e2 - d4 e6 06 00 a5 44 06 61  ..7nu.;......D.a
    000000000006e6b0  d4 e6 06 00 16 45 06 61 - ba 14 af 47 be e0 57 19  .....E.a...G..W.
    000000000006e6c0  1f e0 00 00 1f e0 37 6e - 75 d5 3b e2 f8 e6 06 00  ......7nu.;.....
    000000000006e6d0  a5 44 06 61 f0 e6 06 00 - c0 14 af 47 c0 14 af 47  .D.a.......G...G
    000000000006e6e0  50 00 af 47 5c 8f 77 00 - 00 00 00 00 28 7c 77 00  P..G\.w.....(|w.
    000000000006e6f0  66 e0 96 2c 10 44 c3 7e - 00 00 af 47 01 00 00 00  f..,.D.~...G....
    000000000006e700  18 e7 06 00 7c 43 06 61 - 19 00 00 00 87 43 06 61  ....|C.a.....C.a
    000000000006e710  5c 8f 77 00 18 ea 06 00 - 04 ea 06 00 aa 41 06 61  \.w..........A.a
    000000000006e720  00 00 00 00 5c 8f 77 00 - 00 00 00 00 28 7c 77 00  ....\.w.....(|w.
    000000000006e730  00 00 00 00 00 00 3b 9f - 0a 00 00 00 00 00 00 00  ......;.........
    000000000006e740  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
    000000000006e750  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
    000000000006e760  00 00 00 00 00 00 00 00 - 00 00 00 00 ff ff ff ff  ................
    000000000006e770  24 ea 06 00 18 ea 06 00 - 00 00 00 00 00 00 00 00  $...............

    *----> State Dump for Thread Id 0x164 <----*

    eax=000000c0 ebx=00000000 ecx=00000000 edx=00000000 esi=00000000 edi=00000001
    eip=7c90eb94 esp=00e4fcec ebp=00e4ffb4 iopl=0         nv up ei pl zr na po nc
    cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246

    *** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\ntdll.dll -
    function: ntdll!KiFastSystemCallRet
            7c90eb89 90               nop
            7c90eb8a 90               nop
            ntdll!KiFastSystemCall:
            7c90eb8b 8bd4             mov     edx,esp
            7c90eb8d 0f34             sysenter
            7c90eb8f 90               nop
            7c90eb90 90               nop
            7c90eb91 90               nop
            7c90eb92 90               nop
            7c90eb93 90               nop
            ntdll!KiFastSystemCallRet:
            7c90eb94 c3               ret
            7c90eb95 8da42400000000   lea     esp,[esp]
            7c90eb9c 8d642400         lea     esp,[esp]
            7c90eba0 90               nop
            7c90eba1 90               nop
            7c90eba2 90               nop
            7c90eba3 90               nop
            7c90eba4 90               nop
            ntdll!KiIntSystemCall:
            7c90eba5 8d542408         lea     edx,[esp+0x8]
            7c90eba9 cd2e             int     2e

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be wrong.
    ChildEBP RetAddr  Args to Child             
    00e4ffb4 7c80b683 00000000 00090000 00000000 ntdll!KiFastSystemCallRet
    00e4ffec 00000000 7c929fae 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

    *----> Raw Stack Dump <----*
    0000000000e4fcec  ab e9 90 7c d5 a0 92 7c - 14 00 00 00 30 fd e4 00  ...|...|....0...
    0000000000e4fcfc  01 00 00 00 01 00 00 00 - 00 00 00 00 00 00 09 00  ................
    0000000000e4fd0c  00 00 00 00 00 00 00 00 - 08 e5 97 7c 08 e5 97 7c  ...........|...|
    0000000000e4fd1c  70 01 00 00 64 01 00 00 - 14 00 00 00 14 00 00 00  p...d...........
    0000000000e4fd2c  13 00 00 00 68 01 00 00 - 40 00 00 00 ac 01 00 00  ....h...@.......
    0000000000e4fd3c  bc 01 00 00 d8 01 00 00 - e4 01 00 00 f0 01 00 00  ................
    0000000000e4fd4c  20 02 00 00 24 02 00 00 - 2c 02 00 00 38 02 00 00   ...$...,...8...
    0000000000e4fd5c  40 02 00 00 4c 02 00 00 - 58 02 00 00 64 02 00 00  @...L...X...d...
    0000000000e4fd6c  6c 02 00 00 78 02 00 00 - 84 02 00 00 90 02 00 00  l...x...........
    0000000000e4fd7c  98 02 00 00 b8 02 00 00 - c4 02 00 00 d0 02 00 00  ................
    0000000000e4fd8c  dc 02 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
    0000000000e4fd9c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
    0000000000e4fdac  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
    0000000000e4fdbc  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
    0000000000e4fdcc  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
    0000000000e4fddc  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
    0000000000e4fdec  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
    0000000000e4fdfc  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
    0000000000e4fe0c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
    0000000000e4fe1c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................

    *----> State Dump for Thread Id 0x1ac <----*

    eax=769c8831 ebx=00e8fef4 ecx=0006efa4 edx=0006f258 esi=00000000 edi=7ffd6000
    eip=7c90eb94 esp=00e8fecc ebp=00e8ff68 iopl=0         nv up ei pl zr na po nc
    cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246

    function: ntdll!KiFastSystemCallRet
            7c90eb89 90               nop
            7c90eb8a 90               nop
            ntdll!KiFastSystemCall:
            7c90eb8b 8bd4             mov     edx,esp
            7c90eb8d 0f34             sysenter
            7c90eb8f 90               nop
            7c90eb90 90               nop
            7c90eb91 90               nop
            7c90eb92 90               nop
            7c90eb93 90               nop
            ntdll!KiFastSystemCallRet:
            7c90eb94 c3               ret
            7c90eb95 8da42400000000   lea     esp,[esp]
            7c90eb9c 8d642400         lea     esp,[esp]
            7c90eba0 90               nop
            7c90eba1 90               nop
            7c90eba2 90               nop
            7c90eba3 90               nop
            7c90eba4 90               nop
            ntdll!KiIntSystemCall:
            7c90eba5 8d542408         lea     edx,[esp+0x8]
            7c90eba9 cd2e             int     2e

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be wrong.
    *** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\userenv.dll -
    ChildEBP RetAddr  Args to Child             
    00e8ff68 7c80a075 00000003 76a60310 00000000 ntdll!KiFastSystemCallRet
    00e8ff84 769c888d 00000003 76a60310 00000000 kernel32!WaitForMultipleObjects+0x18
    00e8ffb4 7c80b683 00000000 00000000 00000000 userenv!UnregisterGPNotification+0x15c
    00e8ffec 00000000 769c8831 00000000 00000000 kernel32!GetModuleFileNameA+0x1b4

    *----> Raw Stack Dump <----*
    0000000000e8fecc  ab e9 90 7c e2 94 80 7c - 03 00 00 00 f4 fe e8 00  ...|...|........
    0000000000e8fedc  01 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
    0000000000e8feec  b8 03 a6 76 47 9b 80 7c - c0 01 00 00 c4 01 00 00  ...vG..|........
    0000000000e8fefc  c8 01 00 00 5c fe e8 00 - 6c ff e8 00 6c ff e8 00  ....\...l...l...
    0000000000e8ff0c  18 ee 90 7c 70 05 91 7c - 14 00 00 00 01 00 00 00  ...|p..|........
    0000000000e8ff1c  00 00 00 00 00 00 00 00 - 10 00 00 00 f6 1b 80 7c  ...............|
    0000000000e8ff2c  00 00 00 00 00 00 00 00 - 00 60 fd 7f 00 c0 fd 7f  .........`......
    0000000000e8ff3c  50 46 09 00 00 00 00 00 - f4 fe e8 00 00 00 00 00  PF..............
    0000000000e8ff4c  03 00 00 00 e8 fe e8 00 - 00 00 00 00 dc ff e8 00  ................
    0000000000e8ff5c  a8 9a 83 7c d8 95 80 7c - 00 00 00 00 84 ff e8 00  ...|...|........
    0000000000e8ff6c  75 a0 80 7c 03 00 00 00 - 10 03 a6 76 00 00 00 00  u..|.......v....
    0000000000e8ff7c  ff ff ff ff 00 00 00 00 - b4 ff e8 00 8d 88 9c 76  ...............v
    0000000000e8ff8c  03 00 00 00 10 03 a6 76 - 00 00 00 00 ff ff ff ff  .......v........
    0000000000e8ff9c  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 9c 76  ...............v
    0000000000e8ffac  03 00 00 00 00 00 00 00 - ec ff e8 00 83 b6 80 7c  ...............|
    0000000000e8ffbc  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
    0000000000e8ffcc  00 c0 fd 7f 00 06 7c 86 - c0 ff e8 00 98 66 ef 84  ......|......f..
    0000000000e8ffdc  ff ff ff ff a8 9a 83 7c - 90 b6 80 7c 00 00 00 00  .......|...|....
    0000000000e8ffec  00 00 00 00 00 00 00 00 - 31 88 9c 76 00 00 00 00  ........1..v....
    0000000000e8fffc  00 00 00 00 ff ff ff ff - ff ff ff ff 00 00 00 00  ................

    *----> State Dump for Thread Id 0x248 <----*

    eax=77e76bf0 ebx=00000000 ecx=00000009 edx=7c910732 esi=0014cdf0 edi=00000100
    eip=7c90eb94 esp=014ffe1c ebp=014fff80 iopl=0         nv up ei pl zr na po nc
    cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246

    function: ntdll!KiFastSystemCallRet
            7c90eb89 90               nop
            7c90eb8a 90               nop
            ntdll!KiFastSystemCall:
            7c90eb8b 8bd4             mov     edx,esp
            7c90eb8d 0f34             sysenter
            7c90eb8f 90               nop
            7c90eb90 90               nop
            7c90eb91 90               nop
            7c90eb92 90               nop
            7c90eb93 90               nop
            ntdll!KiFastSystemCallRet:
            7c90eb94 c3               ret
            7c90eb95 8da42400000000   lea     esp,[esp]
            7c90eb9c 8d642400         lea     esp,[esp]
            7c90eba0 90               nop
            7c90eba1 90               nop
            7c90eba2 90               nop
            7c90eba3 90               nop
            7c90eba4 90               nop
            ntdll!KiIntSystemCall:
            7c90eba5 8d542408         lea     edx,[esp+0x8]
            7c90eba9 cd2e             int     2e

    *----> Stack Back Trace <----*
    *** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\RPCRT4.dll -
    WARNING: Stack unwind information not available. Following frames may be wrong.
    ChildEBP RetAddr  Args to Child             
    014fff80 77e76c22 014fffa8 77e76a3b 0014cdf0 ntdll!KiFastSystemCallRet
    014fff88 77e76a3b 0014cdf0 00000000 0006db74 RPCRT4!I_RpcBCacheFree+0x5ea
    014fffa8 77e76c0a 000a6c20 014fffec 7c80b683 RPCRT4!I_RpcBCacheFree+0x403
    014fffb4 7c80b683 000b99f8 00000000 0006db74 RPCRT4!I_RpcBCacheFree+0x5d2
    014fffec 00000000 77e76bf0 000b99f8 00000000 kernel32!GetModuleFileNameA+0x1b4

    *----> Raw Stack Dump <----*
    00000000014ffe1c  99 e3 90 7c 03 67 e7 77 - 30 03 00 00 70 ff 4f 01  ...|.g.w0...p.O.
    00000000014ffe2c  00 00 00 00 e0 1f 14 00 - 54 ff 4f 01 00 d0 c9 e1  ........T.O.....
    00000000014ffe3c  8b 2e 00 00 3c 00 c0 c0 - 48 7b 78 ee 20 91 4e 80  ....<...H{x. .N.
    00000000014ffe4c  50 7b 78 ee 02 d0 c9 e1 - 00 00 55 80 06 02 00 00  P{x.......U.....
    00000000014ffe5c  e6 33 4e 80 80 f9 df ff - f6 32 4e 80 fd 32 4e 80  .3N......2N..2N.
    00000000014ffe6c  02 00 00 00 d1 00 00 00 - 1c 7c 78 ee 35 49 6f 80  .........|x.5Io.
    00000000014ffe7c  00 0d db ba 00 d4 00 00 - 40 aa 68 ee f8 7c f1 84  ........@.h..|..
    00000000014ffe8c  0c 7d f1 84 00 7d f1 84 - 00 00 00 00 01 00 00 00  .}...}..........
    00000000014ffe9c  40 96 68 ee 88 7b 78 ee - c8 7c f1 84 00 00 00 00  @.h..{x..|......
    00000000014ffeac  b4 7b 78 ee 00 d4 00 00 - d0 a1 b0 85 00 00 08 00  .{x.............
    00000000014ffebc  ae 6d 7a f7 77 01 00 00 - 74 b3 77 86 e8 b0 77 86  .mz.w...t.w...w.
    00000000014ffecc  70 b3 77 86 c0 7b 78 ee - 29 e7 7a f7 4a d7 32 f7  p.w..{x.).z.J.2.
    00000000014ffedc  88 a1 b0 85 7a d7 32 f7 - 00 00 08 17 c8 a1 b0 85  ....z.2.........
    00000000014ffeec  fe 13 33 f7 1f 00 00 00 - ce d7 2d f7 58 d4 2d f7  ..3.......-.X.-.
    00000000014ffefc  a0 b4 6c 84 28 b5 6c 84 - 00 00 00 00 20 7c 78 ee  ..l.(.l..... |x.
    00000000014fff0c  22 09 30 f7 02 b5 6c 84 - ac 4b ed 84 24 7c 78 ee  ".0...l..K..$|x.
    00000000014fff1c  b2 c2 4d 80 ba c2 4d 80 - 7c 4b ed 84 10 4a ed 84  ..M...M.|K...J..
    00000000014fff2c  44 4a ed 84 80 ff 4f 01 - 99 66 e7 77 4c ff 4f 01  DJ....O..f.wL.O.
    00000000014fff3c  a9 66 e7 77 ed 10 90 7c - d0 07 15 00 f8 99 0b 00  .f.w...|........
    00000000014fff4c  00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff  ../M.....]......

    *----> State Dump for Thread Id 0x24c <----*

    eax=774fe429 ebx=00007530 ecx=7ffd6000 edx=00000000 esi=00000000 edi=0153ff50
    eip=7c90eb94 esp=0153ff20 ebp=0153ff78 iopl=0         nv up ei pl nz na po nc
    cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000206

    function: ntdll!KiFastSystemCallRet
            7c90eb89 90               nop
            7c90eb8a 90               nop
            ntdll!KiFastSystemCall:
            7c90eb8b 8bd4             mov     edx,esp
            7c90eb8d 0f34             sysenter
            7c90eb8f 90               nop
            7c90eb90 90               nop
            7c90eb91 90               nop
            7c90eb92 90               nop
            7c90eb93 90               nop
            ntdll!KiFastSystemCallRet:
            7c90eb94 c3               ret
            7c90eb95 8da42400000000   lea     esp,[esp]
            7c90eb9c 8d642400         lea     esp,[esp]
            7c90eba0 90               nop
            7c90eba1 90               nop
            7c90eba2 90               nop
            7c90eba3 90               nop
            7c90eba4 90               nop
            ntdll!KiIntSystemCall:
            7c90eba5 8d542408         lea     edx,[esp+0x8]
            7c90eba9 cd2e             int     2e

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be wrong.
    *** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\WINDOWS\system32\ole32.dll -
    ChildEBP RetAddr  Args to Child             
    0153ff78 7c802451 0000ea60 00000000 0153ffb4 ntdll!KiFastSystemCallRet
    0153ff88 774fe31d 0000ea60 0015d3e8 774fe3dc kernel32!Sleep+0xf
    0153ffb4 7c80b683 0015d3e8 7c910945 00000004 ole32!StringFromGUID2+0x51b
    0153ffec 00000000 774fe429 0015d3e8 00000000 kernel32!GetModuleFileNameA+0x1b4

    *----> Raw Stack Dump <----*
    000000000153ff20  5c d8 90 7c ed 23 80 7c - 00 00 00 00 50 ff 53 01  \..|.#.|....P.S.
    000000000153ff30  40 25 80 7c f8 6d 60 77 - 30 75 00 00 14 00 00 00  @%.|.m`w0u......
    000000000153ff40  01 00 00 00 00 00 00 00 - 00 00 00 00 10 00 00 00  ................
    000000000153ff50  00 ba 3c dc ff ff ff ff - 00 d1 4e 77 50 ff 53 01  ..<.......NwP.S.
    000000000153ff60  30 ff 53 01 50 46 09 00 - dc ff 53 01 a8 9a 83 7c  0.S.PF....S....|
    000000000153ff70  58 24 80 7c 00 00 00 00 - 88 ff 53 01 51 24 80 7c  X$.|......S.Q$.|
    000000000153ff80  60 ea 00 00 00 00 00 00 - b4 ff 53 01 1d e3 4f 77  `.........S...Ow
    000000000153ff90  60 ea 00 00 e8 d3 15 00 - dc e3 4f 77 00 00 00 00  `.........Ow....
    000000000153ffa0  45 09 91 7c e8 d3 15 00 - 00 00 4e 77 44 e4 4f 77  E..|......NwD.Ow
    000000000153ffb0  04 00 00 00 ec ff 53 01 - 83 b6 80 7c e8 d3 15 00  ......S....|....
    000000000153ffc0  45 09 91 7c 04 00 00 00 - e8 d3 15 00 00 a0 fd 7f  E..|............
    000000000153ffd0  00 06 7c 86 c0 ff 53 01 - d0 03 ee 84 ff ff ff ff  ..|...S.........
    000000000153ffe0  a8 9a 83 7c 90 b6 80 7c - 00 00 00 00 00 00 00 00  ...|...|........
    000000000153fff0  00 00 00 00 29 e4 4f 77 - e8 d3 15 00 00 00 00 00  ....).Ow........
    0000000001540000  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
    0000000001540010  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
    0000000001540020  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
    0000000001540030  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
    0000000001540040  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................
    0000000001540050  00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00  ................

    *----> State Dump for Thread Id 0x74 <----*

    eax=00000000 ebx=00000000 ecx=0015c850 edx=77606f58 esi=0014cdf0 edi=0014ce94
    eip=7c90eb94 esp=0157fe1c ebp=0157ff80 iopl=0         nv up ei pl zr na po nc
    cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246

    function: ntdll!KiFastSystemCallRet
            7c90eb89 90               nop
            7c90eb8a 90               nop
            ntdll!KiFastSystemCall:
            7c90eb8b 8bd4             mov     edx,esp
            7c90eb8d 0f34             sysenter
            7c90eb8f 90               nop
            7c90eb90 90               nop
            7c90eb91 90               nop
            7c90eb92 90               nop
            7c90eb93 90               nop
            ntdll!KiFastSystemCallRet:
            7c90eb94 c3               ret
            7c90eb95 8da42400000000   lea     esp,[esp]
            7c90eb9c 8d642400         lea     esp,[esp]
            7c90eba0 90               nop
            7c90eba1 90               nop
            7c90eba2 90               nop
            7c90eba3 90               nop
            7c90eba4 90               nop
            ntdll!KiIntSystemCall:
            7c90eba5 8d542408         lea     edx,[esp+0x8]
            7c90eba9 cd2e             int     2e

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be wrong.
    ChildEBP RetAddr  Args to Child             
    0157ff80 77e76c22 0157ffa8 77e76a3b 0014cdf0 ntdll!KiFastSystemCallRet
    0157ff88 77e76a3b 0014cdf0 00000040 014ffb58 RPCRT4!I_RpcBCacheFree+0x5ea
    0157ffa8 77e76c0a 000a6c20 0157ffec 7c80b683 RPCRT4!I_RpcBCacheFree+0x403
    0157ffb4 7c80b683 00143580 00000040 014ffb58 RPCRT4!I_RpcBCacheFree+0x5d2
    0157ffec 00000000 77e76bf0 00143580 00000000 kernel32!GetModuleFileNameA+0x1b4

    *----> Raw Stack Dump <----*
    000000000157fe1c  99 e3 90 7c 03 67 e7 77 - 30 03 00 00 70 ff 57 01  ...|.g.w0...p.W.
    000000000157fe2c  00 00 00 00 18 3e 0c 00 - 4c ff 57 01 00 12 7c 86  .....>..L.W...|.
    000000000157fe3c  38 ab 54 80 00 00 00 00 - 60 ae ef 84 00 00 00 00  8.T.....`.......
    000000000157fe4c  2b 88 4e 80 02 00 00 00 - 00 00 50 ee e8 ae ef 84  +.N.......P.....
    000000000157fe5c  00 00 00 00 00 00 00 00 - 98 00 00 00 43 3a 56 80  ............C:V.
    000000000157fe6c  01 00 00 00 05 00 00 00 - 78 4b 50 ee 85 3a 56 80  ........xKP..:V.
    000000000157fe7c  58 ae ef 84 46 69 6c e5 - 90 90 7e 86 40 90 7e 86  X...Fil...~.@.~.
    000000000157fe8c  00 00 00 00 58 ae ef 84 - 58 ae ef 84 90 4b 50 ee  ....X...X....KP.
    000000000157fe9c  ff 3a 56 80 60 ae ef 84 - 00 00 00 00 00 00 00 00  .:V.`...........
    000000000157feac  40 90 7e 86 b4 4b 50 ee - d5 36 4e 80 78 ae ef 84  @.~..KP..6N.x...
    000000000157febc  00 00 00 00 00 12 00 00 - 60 ae ef 84 00 00 00 00  ........`.......
    000000000157fecc  78 ae ef 84 60 ae ef 84 - cc 4b 50 ee b3 6c 56 80  x...`....KP..lV.
    000000000157fedc  30 68 7c 86 48 1c 00 e1 - a0 55 ed 84 40 90 7e 86  0h|.H....U..@.~.
    000000000157feec  14 4c 50 ee 1c 6d 56 80 - 48 1c 00 e1 78 ae ef 84  .LP..mV.H...x...
    000000000157fefc  00 12 00 00 00 00 00 00 - 01 00 10 00 00 00 00 00  ................
    000000000157ff0c  34 4c 50 ee b0 4c 50 ee - 44 5f ed 84 24 4c 50 ee  4LP..LP.D_..$LP.
    000000000157ff1c  b2 c2 4d 80 ba c2 4d 80 - 14 5f ed 84 a8 5d ed 84  ..M...M.._...]..
    000000000157ff2c  dc 5d ed 84 80 ff 57 01 - 99 66 e7 77 4c ff 57 01  .]....W..f.wL.W.
    000000000157ff3c  a9 66 e7 77 ed 10 90 7c - d0 7b 15 00 80 35 14 00  .f.w...|.{...5..
    000000000157ff4c  00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff  ../M.....]......

    *----> State Dump for Thread Id 0x27c <----*

    eax=77e76bf0 ebx=00000000 ecx=0157faac edx=7c809740 esi=0014cdf0 edi=0014ce94
    eip=7c90eb94 esp=015bfe1c ebp=015bff80 iopl=0         nv up ei pl zr na po nc
    cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00000246

    function: ntdll!KiFastSystemCallRet
            7c90eb89 90               nop
            7c90eb8a 90               nop
            ntdll!KiFastSystemCall:
            7c90eb8b 8bd4             mov     edx,esp
            7c90eb8d 0f34             sysenter
            7c90eb8f 90               nop
            7c90eb90 90               nop
            7c90eb91 90               nop
            7c90eb92 90               nop
            7c90eb93 90               nop
            ntdll!KiFastSystemCallRet:
            7c90eb94 c3               ret
            7c90eb95 8da42400000000   lea     esp,[esp]
            7c90eb9c 8d642400         lea     esp,[esp]
            7c90eba0 90               nop
            7c90eba1 90               nop
            7c90eba2 90               nop
            7c90eba3 90               nop
            7c90eba4 90               nop
            ntdll!KiIntSystemCall:
            7c90eba5 8d542408         lea     edx,[esp+0x8]
            7c90eba9 cd2e             int     2e

    *----> Stack Back Trace <----*
    WARNING: Stack unwind information not available. Following frames may be wrong.
    ChildEBP RetAddr  Args to Child             
    015bff80 77e76c22 015bffa8 77e76a3b 0014cdf0 ntdll!KiFastSystemCallRet
    015bff88 77e76a3b 0014cdf0 00000004 0157fb58 RPCRT4!I_RpcBCacheFree+0x5ea
    015bffa8 77e76c0a 000a6c20 015bffec 7c80b683 RPCRT4!I_RpcBCacheFree+0x403
    015bffb4 7c80b683 0015a378 00000004 0157fb58 RPCRT4!I_RpcBCacheFree+0x5d2
    015bffec 00000000 77e76bf0 0015a378 00000000 kernel32!GetModuleFileNameA+0x1b4

    *----> Raw Stack Dump <----*
    00000000015bfe1c  99 e3 90 7c 03 67 e7 77 - 30 03 00 00 70 ff 5b 01  ...|.g.w0...p.[.
    00000000015bfe2c  00 00 00 00 78 26 0c 00 - 4c ff 5b 01 8b 93 06 00  ....x&..L.[.....
    00000000015bfe3c  ba bf 6b 00 e5 e7 c8 00 - f5 f5 e9 00 ff ff ff 00  ..k.............
    00000000015bfe4c  ff ff ff 00 ff ff ff 00 - f1 f2 e9 00 dd de c7 00  ................
    00000000015bfe5c  a4 a7 68 00 65 6b 00 00 - 65 6b 00 00 65 6b 00 00  ..h.ek..ek..ek..
    00000000015bfe6c  65 6b 00 00 65 6b 00 00 - 65 6b 00 00 ff ff ff 00  ek..ek..ek......
    00000000015bfe7c  ff ff ff 00 ff ff ff 00 - ff ff ff 00 da dc bd 00  ................
    00000000015bfe8c  f2 f3 e9 00 ff ff ff 00 - ff ff ff 00 ea ea d9 00  ................
    00000000015bfe9c  be c2 8c 00 7e 85 00 00 - a0 a8 1b 00 9f a7 1a 00  ....~...........
    00000000015bfeac  a9 b1 24 00 ad b5 28 00 - a9 b1 24 00 e9 eb c7 00  ..$...(...$.....
    00000000015bfebc  fc fc f9 00 ff ff ff 00 - ff ff ff 00 ef f0 db 00  ................
    00000000015bfecc  be c3 7c 00 ff ff ff 00 - ff ff ff 00 ff ff ff 00  ..|.............
    00000000015bfedc  ff ff ff 00 87 8f 02 00 - 82 8a 00 00 85 8d 00 00  ................
    00000000015bfeec  82 8a 00 00 d6 d9 a9 00 - f8 f9 f1 00 ff ff ff 00  ................
    00000000015bfefc  ff ff ff 00 f9 fa f2 00 - cd d1 89 00 ff ff ff 00  ................
    00000000015bff0c  ff ff ff 00 ff ff ff 00 - dc 48 ed 84 24 0c 50 ee  .........H..$.P.
    00000000015bff1c  b2 c2 4d 80 ba c2 4d 80 - ac 48 ed 84 40 47 ed 84  ..M...M..H..@G..
    00000000015bff2c  74 47 ed 84 80 ff 5b 01 - 99 66 e7 77 4c ff 5b 01  tG....[..f.wL.[.
    00000000015bff3c  a9 66 e7 77 ed 10 90 7c - 38 09 0c 00 78 a3 15 00  .f.w...|8...x...
    00000000015bff4c  00 a2 2f 4d ff ff ff ff - 00 5d 1e ee ff ff ff ff  ../M.....]......

     


     

    Friday, July 6, 2007 4:53 PM
  • CJ

     

    I forwarded the information to our developer team and we are looking @ this problem. As soon as we can get a solution we will contact you.  Thank you again :-)

     

     

    Stephen Holm, MS

    Friday, July 6, 2007 8:08 PM
  • Just Another:

     

    Apologies for the delay in response. We normally do not "leave people hanging" - but due to the Holiday season here ... Smile.

     

    Anyhow, our developers have been able to identify the issue with your system. It seems that the Licdll.dll file in your windows\system32 directory (which is used to check system licensing files in Windows) has an issue. I would highly suggest going to the command prompt (start->run then type in CMD and press enter).

     

    Upon the new screen, type in "regsvr32 licdll.dll /u" which should unregister licdll.dll. By default, Windows will then use licwmi.dll in the same directory for checking license files as a backup. This rarely happens, but the primary cause is either from:

     

    1 - a very fragmented installation of Windows (would suggest to defragment your harddrive)

    2 - corrupted file (would suggest a repair installation of Windows to recover the files).

     

     

    I hope this helps,

    -phil

    Friday, July 6, 2007 10:22 PM
  •  

    Hi Phil...

     

      I defragmented the drive using AusLogic Disk Defrag on Sun (July 1.) funny you mention doing this.  I've had some other problems as well - which were not related to the Windows Installation itself (Clean install was 10months old and has run pretty well, up until recently). 

     

    I started getting "Disk Error press ctrl -alt - del to restart" messages on Wednesday, and couldn't boot from this drive. I fixed that lastnight. I replaced old primary ide cable. Then using another XP Pro disk drive I have for this PC -- I ran chkdsk /r on all three partitions of this drive from CMD.  The extended partition of this drive (harddrive 0\ D) is damaged.  I'm looking at Imaging what I have now, then I'll do a low level format. 

     

    Hopefully, what I restore back from image will not have to be repair installed.

     

    Went ahead and unregistered licdll.dll in the meantime.

     

    Friday, July 6, 2007 11:21 PM
  • C J I'm assuming it worked just fine for you? Smile

     

    -phil

    Friday, July 13, 2007 10:12 PM
  • Unregistering the File seemed to do the trick. There has been no reoccurence of the error. I'm still waiting for my new hard drive to arrive.  I want to get this PC up and working again now the reason for the Drive Error problem is understood (what caused it) Thanks everyone for the help.
    Friday, July 13, 2007 11:46 PM
  •  

    Diagnostic Report (1.7.0066.0):
    -----------------------------------------
    WGA Data-->
    Validation Status: Genuine
    Validation Code: 0
    Online Validation Code: N/A
    Cached Validation Code: N/A
    Windows Product Key: *****-*****-9TCCK-JPCBM-B2FQ8
    Windows Product Key Hash: B/IohRcCzV6LJrex8WpCdnxgTvg=
    Windows Product ID: 76487-OEM-2211906-00803
    Windows Product ID Type: 2
    Windows License Type: OEM SLP
    Windows OS version: 5.1.2600.2.00010100.2.0.med
    CSVLK Server: N/A
    CSVLK PID: N/A
    ID: {F1B38A3E-94AB-4F17-8986-FC83C3867BCB}(3)
    Is Admin: Yes
    TestCab: 0x0
    WGA Version: Registered, 1.7.59.1
    Signed By: Microsoft
    Product Name: N/A
    Architecture: N/A
    Build lab: N/A
    TTS Error: N/A
    Validation Diagnostic: 025D1FF3-171-1
    Resolution Status: N/A

    Notifications Data-->
    Cached Result: N/A
    File Exists: No
    Version: N/A, hr = 0x80070002
    WgaTray.exe Signed By: N/A, hr = 0x80070002
    WgaLogon.dll Signed By: N/A, hr = 0x80070002

    OGA Data-->
    Office Status: 109 N/A
    OGA Version: N/A, 0x80070002
    Signed By: N/A, hr = 0x80070002
    Office Diagnostics: FCEE394C-2989-80070002

    Browser Data-->
    Proxy settings: N/A
    User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Win32)
    Default Browser: C:\Program Files\Internet Explorer\iexplore.exe
    Download signed ActiveX controls: Prompt
    Download unsigned ActiveX controls: Disabled
    Run ActiveX controls and plug-ins: Allowed
    Initialize and script ActiveX controls not marked as safe: Disabled
    Allow scripting of Internet Explorer Webbrowser control: Disabled
    Active scripting: Allowed
    Script ActiveX controls marked as safe for scripting: Allowed

    File Scan Data-->

    Other data-->
    Office Details: <GenuineResults><MachineData><UGUID>{F1B38A3E-94AB-4F17-8986-FC83C3867BCB}</UGUID><Version>1.7.0066.0</Version><OS>5.1.2600.2.00010100.2.0.med</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-B2FQ8</PKey><PID>76487-OEM-2211906-00803</PID><PIDType>2</PIDType><SID>S-1-5-21-2563860517-393726927-2106853058</SID><SYSTEM><Manufacturer>HP Pavilion 061</Manufacturer><Model>EX513AA-ABA A1473W</Model></SYSTEM><BIOS><Manufacturer>American Megatrends Inc.</Manufacturer><Version>3.11</Version><SMBIOSVersion major="2" minor="4"/><Date>20060410000000.000000+000</Date><SLPBIOS>HP PAVILION</SLPBIOS></BIOS><HWID>E8293A5F0184C06C</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Central Standard Time(GMT-06:00)</TimeZone><iJoin>0</iJoin><SBID><stat>2</stat><msppid></msppid><name>Hewlett-Packard Company</name><model>HP Pavilion</model></SBID><OEM/><BRT/></MachineData>   <Software><Office><Result>109</Result><Products/></Office></Software></GenuineResults> 

     

    Sunday, January 27, 2008 3:02 PM
  • Hello Wendy,

    From your diagnostic information it appears your copy of Windows is genuine.  Can you please tell us what problem you are having and any error messages you receive.

     

    Thank you,

    Matt Prall, MS
    WGA Forum Manager

    Tuesday, January 29, 2008 7:12 PM