I used OSR online to decode the dump file:
Crash Dump Analysis provided by OSR Open Systems Resources, Inc. (http://www.osr.com)
Online Crash Dump Analysis Service
See http://www.osronline.com for more information
Windows 7 Version 7601 (Service Pack 1) MP (8 procs) Free x86 compatible
Product: WinNt, suite: TerminalServer
Machine Name:
Debug session time: Fri Jan 11 05:23:17.000 2019 (UTC - 5:00)
System Uptime: not available
Process Uptime: not available
TRIAGER: Could not open triage file : e:\dump_analysis\program\triage\oca.ini, error 2
TRIAGER: Could not open triage file : e:\dump_analysis\program\winxp\triage.ini, error 2
TRIAGER: Could not open triage file : e:\dump_analysis\program\triage\user.ini, error 2
*** WARNING: Unable to verify timestamp for ntdll.dll
*** ERROR: Module load completed but symbols could not be loaded for ntdll.dll
*******************************************************************************
* *
* Exception Analysis *
* *
*******************************************************************************
***** OS symbols are WRONG. Please fix symbols to do analysis.
Unable to load image C:\windows\system32\KERNEL32.dll, Win32 error 0n2
*** WARNING: Unable to verify timestamp for KERNEL32.dll
*** ERROR: Module load completed but symbols could not be loaded for KERNEL32.dll
TRIAGER: Could not open triage file : e:\dump_analysis\program\triage\guids.ini, error 2
Unable to load image C:\windows\system32\ole32.dll, Win32 error 0n2
*** WARNING: Unable to verify timestamp for ole32.dll
*** ERROR: Module load completed but symbols could not be loaded for ole32.dll
*** WARNING: Unable to verify timestamp for winepulse.drv
*** ERROR: Module load completed but symbols could not be loaded for winepulse.drv
*** WARNING: Unable to verify timestamp for advapi32.dll
*** ERROR: Module load completed but symbols could not be loaded for advapi32.dll
*** WARNING: Unable to verify timestamp for mmdevapi.dll
*** ERROR: Module load completed but symbols could not be loaded for mmdevapi.dll
*** WARNING: Unable to verify timestamp for _audio2.dll
*** ERROR: Module load completed but symbols could not be loaded for _audio2.dll
*** WARNING: Unable to verify timestamp for python27.dll
*** ERROR: Module load completed but symbols could not be loaded for python27.dll
*** WARNING: Unable to verify timestamp for msvcr100.dll
*** ERROR: Module load completed but symbols could not be loaded for msvcr100.dll
*** WARNING: Unable to verify timestamp for blue.dll
*** ERROR: Module load completed but symbols could not be loaded for blue.dll
TRIAGER: Could not open triage file : e:\dump_analysis\program\triage\modclass.ini, error 2
GetUrlPageData2 (WinHttp) failed: 12029.
FAULTING_IP:
+752f336431343930
f4d7589b 8b81700f0000 mov eax,dword ptr [ecx+0F70h]
EXCEPTION_RECORD: ffffffff -- (.exr 0xffffffffffffffff)
ExceptionAddress: f4d7589b
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 00000000
Parameter[1]: 00000f70
Attempt to read from address 00000f70
PROCESS_NAME: exefile.exe
ADDITIONAL_DEBUG_TEXT:
Use '!findthebuild' command to search for the target build information.
If the build information is available, run '!findthebuild -s ; .reload' to set symbol path and load symbols.
FAULTING_MODULE: 7bc10000 ntdll
DEBUG_FLR_IMAGE_TIMESTAMP: 0
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s".
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s".
EXCEPTION_PARAMETER1: 00000000
EXCEPTION_PARAMETER2: 00000f70
READ_ADDRESS: 00000f70
FOLLOWUP_IP:
xaudio2_7+1589b
f4d7589b ?? ???
IP_ON_HEAP: f7ff0087
The fault address in not in any loaded module, please check your build's rebase
log at \bin\build_logs\timebuild\ntrebase.log for module which may
contain the address if it were loaded.
FAULTING_THREAD: 0000005e
DEFAULT_BUCKET_ID: WRONG_SYMBOLS
PRIMARY_PROBLEM_CLASS: WRONG_SYMBOLS
BUGCHECK_STR: APPLICATION_FAULT_WRONG_SYMBOLS_NULL_CLASS_PTR_READ
LAST_CONTROL_TRANSFER: from 03e10000 to f4d7589b
STACK_TEXT:
WARNING: Stack unwind information not available. Following frames may be wrong.
1c80e81c 03e10000 00001016 1c80e858 f7dd0f12 xaudio2_7+0x1589b
1c80e978 f4d7608f 00000960 00004b00 1c80eb08 cairo
1c80e9f8 7bc83c40 9a039c26 00000000 7bcdb000 xaudio2_7+0x1608f
1c80ea18 7bc86e4d f4d75e00 00186488 1c80ea98 ntdll+0x73c40
1c80eae8 7bc83c1e f4d75e00 00186488 1c80eb08 ntdll+0x76e4d
1c80eb08 7bc8ee68 f4d75e00 00186488 00000000 ntdll+0x73c1e
1c80f358 f7dc8fd2 81f68fb8 7cac6dd0 0000000c ntdll+0x7ee68
1c80f428 f7cde1a6 1c80fb40 00000000 00000000 0xf7dc8fd2
00000000 00000000 00000000 00000000 00000000 0xf7cde1a6
STACK_COMMAND: ~1s; .ecxr ; kb
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: xaudio2_7+1589b
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: xaudio2_7
IMAGE_NAME: xaudio2_7.dll
BUCKET_ID: WRONG_SYMBOLS
FAILURE_BUCKET_ID: WRONG_SYMBOLS_c0000005_xaudio2_7.dll!Unknown
WATSON_STAGEONE_URL: http://watson.microsoft.com/StageOne/exefile_exe/2018_11_141_3802/5c0941d3/unknown/0_0_0_0/bbbbbbb4/c0000005/f4d7589b.htm?Retriage=1
Followup: MachineOwner
---------
This free analysis is provided by OSR Open Systems Resources, Inc.
Want a deeper understanding of crash dump analysis? Check out our Windows Kernel Debugging and Crash Dump Analysis Seminar (opens in new tab/window)
Hide DivLoaded Module List
start end module name
00340000 00376000 _yaml _yaml.pyd
003b0000 003c9000 cairo_script cairo-script.dll
00400000 00489000 exefile exefile.exe
02e30000 02f27000 _ssl _ssl.pyd
03030000 030d7000 d3dinfo d3dinfo.pyd
030e0000 03e03000 _trinity_dx9_deploy _trinity_dx9_deploy.dll
03e10000 03f36000 cairo cairo.dll
03f40000 03f8d000 tbb tbb.dll
04810000 04850000 _evelocalization _evelocalization.dll
04850000 04882000 geo2 geo2.dll
04890000 04954000 pyFSD pyFSD.dll
04960000 0496d000 character_colorLocationsLoader character_colorLocationsLoader.pyd
04970000 0497d000 character_colorNamesLoader character_colorNamesLoader.pyd
04980000 0498d000 character_modifierLocationsLoader character_modifierLocationsLoader.pyd
04990000 0499d000 character_resourcesLoader character_resourcesLoader.pyd
049a0000 049ad000 character_sculptingLocationsLoader character_sculptingLocationsLoader.pyd
049b0000 049d3000 pyexpat pyexpat.pyd
049e0000 049f3000 graphicIDsLoader graphicIDsLoader.pyd
04a00000 04a0e000 graphicMaterialSetsLoader graphicMaterialSetsLoader.pyd
04a10000 04a9d000 _destiny _destiny.dll
04aa0000 04ab3000 spacemouse spacemouse.pyd
04ac0000 04c9e000 _audio2 _audio2.dll
04ca0000 04cb3000 explosionBucketIDsLoader explosionBucketIDsLoader.pyd
04cc0000 04ccd000 explosionIDsLoader explosionIDsLoader.pyd
04cd0000 04cdc000 soundIDsLoader soundIDsLoader.pyd
04ce0000 04cf2000 graphicLocationsLoader graphicLocationsLoader.pyd
05060000 05214000 _videoplayer _videoplayer.dll
05330000 053db000 unicodedata unicodedata.pyd
053e0000 053ee000 iconIDsLoader iconIDsLoader.pyd
053f0000 05401000 activityNodesLoader activityNodesLoader.pyd
05410000 05422000 pychartdir27 pychartdir27.pyd
05c50000 05cf9000 pyEvePathfinder pyEvePathfinder.dll
05d00000 05d2e000 _PlanetResources _PlanetResources.dll
05d30000 05d42000 groupGraphicsLoader groupGraphicsLoader.pyd
05d50000 05d63000 effectSequencesLoader effectSequencesLoader.pyd
05d70000 05d7f000 effectsLoader effectsLoader.pyd
05d80000 05d8d000 newFeaturesLoader newFeaturesLoader.pyd
05d90000 05da1000 loginRewardsLoader loginRewardsLoader.pyd
05f50000 05f63000 dynamicItemAttributesLoader dynamicItemAttributesLoader.pyd
0e1e0000 0e416000 chartdir chartdir.dll
10000000 103f6000 blue blue.dll
1d1a0000 1d1b7000 _ctypes _ctypes.pyd
1e000000 1e3c2000 python27 python27.dll
7a820000 7a924000 opengl32 opengl32.dll
7b410000 7b6a3000 KERNEL32 KERNEL32.dll
7bc10000 7bcf8000 ntdll ntdll.dll
7d600000 7d61a000 imm32 imm32.dll
7d840000 7d85b000 mpr mpr.dll
7d8b0000 7d909000 wininet wininet.dll
7d910000 7d98e000 rpcrt4 rpcrt4.dll
7d9b0000 7dad5000 ole32 ole32.dll
7daf0000 7dc1c000 oleaut32 oleaut32.dll
7dc20000 7dc5e000 winhttp winhttp.dll
7dc70000 7dcd5000 shlwapi shlwapi.dll
7dce0000 7dedd000 shell32 shell32.dll
7df00000 7dfb8000 msvcr100 msvcr100.dll
7dff0000 7e0d5000 msvcp100 msvcp100.dll
7e900000 7e910000 jsproxy jsproxy.dll
7e920000 7e95e000 wldap32 wldap32.dll
7e970000 7e99b000 ws2_32 ws2_32.dll
7e9a0000 7e9c5000 iphlpapi iphlpapi.dll
7e9d0000 7e9df000 version version.dll
7e9f0000 7ea5e000 advapi32 advapi32.dll
7ea70000 7eb8f000 gdi32 gdi32.dll
7eba0000 7ece4000 user32 user32.dll
7ecf0000 7ed7a000 crypt32 crypt32.dll
f4d60000 f4d84000 xaudio2_7 xaudio2_7.dll
f53e0000 f5400000 winepulse winepulse.drv
f5730000 f5748000 mmdevapi mmdevapi.dll
f5750000 f576f000 msacm32 msacm32.dll
f5780000 f57be000 winmm winmm.dll
f57d0000 f5825000 setupapi setupapi.dll
f5830000 f586b000 usp10 usp10.dll
f5870000 f58aa000 d3d9 d3d9.dll
f58b0000 f58be000 msimg32 msimg32.dll
f58c0000 f5926000 d3d11 d3d11.dll
f78f0000 f7972000 winex11 winex11.drv
f79a0000 f7ace000 wined3d wined3d.dll
f7ad0000 f7af8000 dxgi dxgi.dll
f7b00000 f7b0c000 psapi psapi.dll
f7b10000 f7b24000 wtsapi32 wtsapi32.dll
f7b30000 f7b67000 rsaenh rsaenh.dll
f7b70000 f7bd0000 dbghelp dbghelp.dll
Hide DivRaw Stack Contents
*************************************************************************
*** ***
*** ***
*** Either you specified an unqualified symbol, or your debugger ***
*** doesn't have full symbol information. Unqualified symbol ***
*** resolution is turned off by default. Please either specify a ***
*** fully qualified symbol module!symbolname, or enable resolution ***
*** of unqualified symbols by typing ".symopt- 100". Note that ***
*** enabling unqualified symbol resolution with network symbol ***
*** server shares in the symbol path may cause the debugger to ***
*** appear to hang for long periods of time when an incorrect ***
*** symbol name is typed or the network symbol server is down. ***
*** ***
*** For some commands to work properly, your symbol path ***
*** must point to .pdb files that have full type information. ***
*** ***
*** Certain .pdb files (such as the public OS symbols) do not ***
*** contain the required information. Contact the group that ***
*** provided you with these symbols if you need this command to ***
*** work. ***
*** ***
*** Type referenced: ntdll!_NT_TIB ***
*** ***
*************************************************************************
Couldn't resolve error at 'ntdll!_NT_TIB *)@$teb)->StackLimit) @@(((ntdll!_NT_TIB *)@$teb)->StackBase)'
Hide DivDump Header Information
----- User Mini Dump Analysis
MINIDUMP_HEADER:
Version A793 (0)
NumberOfStreams 8
Flags 40
0040 MiniDumpWithIndirectlyReferencedMemory
Streams:
Stream 0: type SystemInfoStream (7), size 00000038, RVA 00000080
ProcessorArchitecture 0000 (PROCESSOR_ARCHITECTURE_INTEL)
ProcessorLevel 0006
ProcessorRevision 8E0A
NumberOfProcessors 08
MajorVersion 00000006
MinorVersion 00000001
BuildNumber 00001DB1 (7601)
PlatformId 00000002 (VER_PLATFORM_WIN32_NT)
CSDVersionRva 000000EA
Length: 28
Buffer: {'Service Pack 1'}
Product: WinNt, suite: TerminalServer
Stream 1: type ThreadListStream (3), size 00000784, RVA 0000010A
40 threads
RVA 0000010E, ID 5F, Teb:0000000081F64000
RVA 0000013E, ID 5E, Teb:0000000081F68000
RVA 0000016E, ID 5D, Teb:0000000081F6C000
RVA 0000019E, ID 5C, Teb:0000000081F70000
RVA 000001CE, ID 5B, Teb:0000000081F74000
RVA 000001FE, ID 5A, Teb:0000000081F78000
RVA 0000022E, ID 59, Teb:0000000081F7C000
RVA 0000025E, ID 58, Teb:0000000081F80000
RVA 0000028E, ID 57, Teb:0000000081F84000
RVA 000002BE, ID 55, Teb:0000000081F8C000
RVA 000002EE, ID 54, Teb:0000000081F90000
RVA 0000031E, ID 53, Teb:0000000081F94000
RVA 0000034E, ID 52, Teb:0000000081F98000
RVA 0000037E, ID 51, Teb:0000000081F9C000
RVA 000003AE, ID 50, Teb:0000000081FA0000
RVA 000003DE, ID 4F, Teb:0000000081FA4000
RVA 0000040E, ID 4E, Teb:0000000081FA8000
RVA 0000043E, ID 4D, Teb:0000000081FAC000
RVA 0000046E, ID 4C, Teb:0000000081FB0000
RVA 0000049E, ID 4B, Teb:0000000081FB4000
RVA 000004CE, ID 4A, Teb:0000000081FB8000
RVA 000004FE, ID 49, Teb:0000000081FBC000
RVA 0000052E, ID 48, Teb:0000000081FC0000
RVA 0000055E, ID 47, Teb:0000000081FC4000
RVA 0000058E, ID 46, Teb:0000000081FC8000
RVA 000005BE, ID 45, Teb:0000000081FCC000
RVA 000005EE, ID 44, Teb:0000000081FD0000
RVA 0000061E, ID 43, Teb:0000000081FD4000
RVA 0000064E, ID 42, Teb:0000000081FD8000
RVA 0000067E, ID 41, Teb:0000000081FDC000
RVA 000006AE, ID 40, Teb:0000000081FE0000
RVA 000006DE, ID 3F, Teb:0000000081FE4000
RVA 0000070E, ID 3E, Teb:0000000081FE8000
RVA 0000073E, ID 3D, Teb:0000000081FEC000
RVA 0000076E, ID 3C, Teb:0000000081FF0000
RVA 0000079E, ID 3B, Teb:0000000081FF4000
RVA 000007CE, ID 3A, Teb:0000000081FF8000
RVA 000007FE, ID 39, Teb:0000000081FFC000
RVA 0000082E, ID 38, Teb:00000000FFFEC000
RVA 0000085E, ID 37, Teb:000000007FFD8000
Stream 2: type ModuleListStream (4), size 00002308, RVA 0000786E
83 modules
RVA 00007872, 00400000 - 00489000: 'C:\tq\bin\exefile.exe'
RVA 000078DE, 7bc10000 - 7bcf8000: 'C:\windows\system32\ntdll.dll'
RVA 0000794A, 7b410000 - 7b6a3000: 'C:\windows\system32\KERNEL32.dll'
RVA 000079B6, 10000000 - 103f6000: 'C:\tq\bin\blue.dll'
RVA 00007A22, 7ecf0000 - 7ed7a000: 'C:\windows\system32\crypt32.dll'
RVA 00007A8E, 7eba0000 - 7ece4000: 'C:\windows\system32\user32.dll'
RVA 00007AFA, 7ea70000 - 7eb8f000: 'C:\windows\system32\gdi32.dll'
RVA 00007B66, 7e9f0000 - 7ea5e000: 'C:\windows\system32\advapi32.dll'
RVA 00007BD2, 7e9d0000 - 7e9df000: 'C:\windows\system32\version.dll'
RVA 00007C3E, 7e9a0000 - 7e9c5000: 'C:\windows\system32\iphlpapi.dll'
RVA 00007CAA, 7e970000 - 7e99b000: 'C:\windows\system32\ws2_32.dll'
RVA 00007D16, 7e920000 - 7e95e000: 'C:\windows\system32\wldap32.dll'
RVA 00007D82, 7dff0000 - 7e0d5000: 'C:\windows\system32\msvcp100.dll'
RVA 00007DEE, 7df00000 - 7dfb8000: 'C:\windows\system32\msvcr100.dll'
RVA 00007E5A, 1e000000 - 1e3c2000: 'C:\tq\bin\python27.dll'
RVA 00007EC6, 7dce0000 - 7dedd000: 'C:\windows\system32\shell32.dll'
RVA 00007F32, 7dc70000 - 7dcd5000: 'C:\windows\system32\shlwapi.dll'
RVA 00007F9E, 7dc20000 - 7dc5e000: 'C:\windows\system32\winhttp.dll'
RVA 0000800A, 7e900000 - 7e910000: 'C:\windows\system32\jsproxy.dll'
RVA 00008076, 7daf0000 - 7dc1c000: 'C:\windows\system32\oleaut32.dll'
RVA 000080E2, 7d9b0000 - 7dad5000: 'C:\windows\system32\ole32.dll'
RVA 0000814E, 7d910000 - 7d98e000: 'C:\windows\system32\rpcrt4.dll'
RVA 000081BA, 7d8b0000 - 7d909000: 'C:\windows\system32\wininet.dll'
RVA 00008226, 7d840000 - 7d85b000: 'C:\windows\system32\mpr.dll'
RVA 00008292, 7d600000 - 7d61a000: 'C:\windows\system32\imm32.dll'
RVA 000082FE, f7b70000 - f7bd0000: 'C:\windows\system32\dbghelp.dll'
RVA 0000836A, f7b30000 - f7b67000: 'C:\windows\system32\rsaenh.dll'
RVA 000083D6, f7b10000 - f7b24000: 'C:\windows\system32\wtsapi32.dll'
RVA 00008442, f7b00000 - f7b0c000: 'C:\windows\system32\psapi.dll'
RVA 000084AE, 00340000 - 00376000: 'C:\tq\bin\_yaml.pyd'
RVA 0000851A, 1d1a0000 - 1d1b7000: 'C:\tq\bin\_ctypes.pyd'
RVA 00008586, 02e30000 - 02f27000: 'C:\tq\bin\_ssl.pyd'
RVA 000085F2, 03030000 - 030d7000: 'C:\tq\bin\d3dinfo.pyd'
RVA 0000865E, 7a820000 - 7a924000: 'C:\windows\system32\opengl32.dll'
RVA 000086CA, f78f0000 - f7972000: 'C:\windows\system32\winex11.drv'
RVA 00008736, f7ad0000 - f7af8000: 'C:\windows\system32\dxgi.dll'
RVA 000087A2, f79a0000 - f7ace000: 'C:\windows\system32\wined3d.dll'
RVA 0000880E, f58c0000 - f5926000: 'C:\windows\system32\d3d11.dll'
RVA 0000887A, 030e0000 - 03e03000: 'C:\tq\bin\_trinity_dx9_deploy.dll'
RVA 000088E6, 003b0000 - 003c9000: 'C:\tq\bin\cairo-script.dll'
RVA 00008952, 03e10000 - 03f36000: 'C:\tq\bin\cairo.dll'
RVA 000089BE, f58b0000 - f58be000: 'C:\windows\system32\msimg32.dll'
RVA 00008A2A, f5870000 - f58aa000: 'C:\windows\system32\d3d9.dll'
RVA 00008A96, 03f40000 - 03f8d000: 'C:\tq\bin\tbb.dll'
RVA 00008B02, 04810000 - 04850000: 'C:\tq\bin\_evelocalization.dll'
RVA 00008B6E, f5830000 - f586b000: 'C:\windows\system32\usp10.dll'
RVA 00008BDA, 04850000 - 04882000: 'C:\tq\bin\geo2.dll'
RVA 00008C46, 04890000 - 04954000: 'C:\tq\bin\pyFSD.dll'
RVA 00008CB2, 04960000 - 0496d000: 'C:\tq\bin\character_colorLocationsLoader.pyd'
RVA 00008D1E, 04970000 - 0497d000: 'C:\tq\bin\character_colorNamesLoader.pyd'
RVA 00008D8A, 04980000 - 0498d000: 'C:\tq\bin\character_modifierLocationsLoader.pyd'
RVA 00008DF6, 04990000 - 0499d000: 'C:\tq\bin\character_resourcesLoader.pyd'
RVA 00008E62, 049a0000 - 049ad000: 'C:\tq\bin\character_sculptingLocationsLoader.pyd'
RVA 00008ECE, 049b0000 - 049d3000: 'C:\tq\bin\pyexpat.pyd'
RVA 00008F3A, 049e0000 - 049f3000: 'C:\tq\bin\graphicIDsLoader.pyd'
RVA 00008FA6, 04a00000 - 04a0e000: 'C:\tq\bin\graphicMaterialSetsLoader.pyd'
RVA 00009012, 04a10000 - 04a9d000: 'C:\tq\bin\_destiny.dll'
RVA 0000907E, 04aa0000 - 04ab3000: 'C:\tq\bin\spacemouse.pyd'
RVA 000090EA, 04ac0000 - 04c9e000: 'C:\tq\bin\_audio2.dll'
RVA 00009156, f57d0000 - f5825000: 'C:\windows\system32\setupapi.dll'
RVA 000091C2, 04ca0000 - 04cb3000: 'C:\tq\bin\explosionBucketIDsLoader.pyd'
RVA 0000922E, 04cc0000 - 04ccd000: 'C:\tq\bin\explosionIDsLoader.pyd'
RVA 0000929A, 04cd0000 - 04cdc000: 'C:\tq\bin\soundIDsLoader.pyd'
RVA 00009306, 05060000 - 05214000: 'C:\tq\bin\_videoplayer.dll'
RVA 00009372, f5780000 - f57be000: 'C:\windows\system32\winmm.dll'
RVA 000093DE, f5750000 - f576f000: 'C:\windows\system32\msacm32.dll'
RVA 0000944A, 05330000 - 053db000: 'C:\tq\bin\unicodedata.pyd'
RVA 000094B6, 04ce0000 - 04cf2000: 'C:\tq\bin\graphicLocationsLoader.pyd'
RVA 00009522, 053e0000 - 053ee000: 'C:\tq\bin\iconIDsLoader.pyd'
RVA 0000958E, 053f0000 - 05401000: 'C:\tq\bin\activityNodesLoader.pyd'
RVA 000095FA, 05410000 - 05422000: 'C:\tq\bin\pychartdir27.pyd'
RVA 00009666, 0e1e0000 - 0e416000: 'C:\tq\bin\chartdir.dll'
RVA 000096D2, 05f50000 - 05f63000: 'C:\tq\bin\dynamicItemAttributesLoader.pyd'
RVA 0000973E, 05c50000 - 05cf9000: 'C:\tq\bin\pyEvePathfinder.dll'
RVA 000097AA, 05d00000 - 05d2e000: 'C:\tq\bin\_PlanetResources.dll'
RVA 00009816, 05d30000 - 05d42000: 'C:\tq\bin\groupGraphicsLoader.pyd'
RVA 00009882, 05d50000 - 05d63000: 'C:\tq\bin\effectSequencesLoader.pyd'
RVA 000098EE, 05d70000 - 05d7f000: 'C:\tq\bin\effectsLoader.pyd'
RVA 0000995A, 05d80000 - 05d8d000: 'C:\tq\bin\newFeaturesLoader.pyd'
RVA 000099C6, 05d90000 - 05da1000: 'C:\tq\bin\loginRewardsLoader.pyd'
RVA 00009A32, f5730000 - f5748000: 'C:\windows\system32\mmdevapi.dll'
RVA 00009A9E, f53e0000 - f5400000: 'C:\windows\system32\winepulse.drv'
RVA 00009B0A, f4d60000 - f4d84000: 'C:\windows\system32\xaudio2_7.dll'
Stream 3: type ??? (65520), size 00000004, RVA 0000B090
Dir entry 3, ??? stream has unknown stream type 65520
Stream 4: type MemoryListStream (5), size 00000504, RVA 0000B094
80 memory ranges
range# RVA Address Size
0 0000B598 1c90e8fc 00001704
1 0000CC9C f7ff0009 00000100
2 0000CD9C 1c80ddbc 00002244
3 0000EFE0 f7ff0007 00000100
4 0000F0E0 1c70e04c 00001fb4
5 00011094 f7ff0007 00000100
6 00011194 1c60e68c 00001974
7 00012B08 f7ff0007 00000100
8 00012C08 0ffae50c 00001af4
9 000146FC f7ff0007 00000100
10 000147FC 0feae50c 00001af4
11 000162F0 f7ff0007 00000100
12 000163F0 0fdabda4 0000425c
13 0001A64C f7ff0009 00000100
14 0001A74C 0fcae52c 00001ad4
15 0001C220 f7ff0007 00000100
16 0001C320 0fa9e50c 00001af4
17 0001DE14 f7ff0007 00000100
18 0001DF14 0e51e50c 00001af4
19 0001FA08 f7ff0007 00000100
20 0001FB08 03029ccc 00006334
21 00025E3C f7ff0007 00000100
22 00025F3C 02e2e50c 00001af4
23 00027A30 f7ff0007 00000100
24 00027B30 0275e4dc 00001b24
25 00029654 f7ff0007 00000100
26 00029754 0232e45c 00001ba4
27 0002B2F8 f7ff0007 00000100
28 0002B3F8 0222e45c 00001ba4
29 0002CF9C f7ff0007 00000100
30 0002D09C 0212e45c 00001ba4
31 0002EC40 f7ff0007 00000100
32 0002ED40 0202e45c 00001ba4
33 000308E4 f7ff0007 00000100
34 000309E4 01f2e45c 00001ba4
35 00032588 f7ff0007 00000100
36 00032688 01e2e45c 00001ba4
37 0003422C f7ff0007 00000100
38 0003432C 01d2e45c 00001ba4
39 00035ED0 f7ff0007 00000100
40 00035FD0 01c2e45c 00001ba4
41 00037B74 f7ff0007 00000100
42 00037C74 01b2e45c 00001ba4
43 00039818 f7ff0007 00000100
44 00039918 01a2e45c 00001ba4
45 0003B4BC f7ff0007 00000100
46 0003B5BC 0192e45c 00001ba4
47 0003D160 f7ff0007 00000100
48 0003D260 0182e45c 00001ba4
49 0003EE04 f7ff0007 00000100
50 0003EF04 0172e45c 00001ba4
51 00040AA8 f7ff0007 00000100
52 00040BA8 0162e45c 00001ba4
53 0004274C f7ff0007 00000100
54 0004284C 0152e45c 00001ba4
55 000443F0 f7ff0007 00000100
56 000444F0 0142e45c 00001ba4
57 00046094 f7ff0007 00000100
58 00046194 0132e45c 00001ba4
59 00047D38 f7ff0007 00000100
60 00047E38 0122e45c 00001ba4
61 000499DC f7ff0007 00000100
62 00049ADC 0112e45c 00001ba4
63 0004B680 f7ff0007 00000100
64 0004B780 0102e45c 00001ba4
65 0004D324 f7ff0007 00000100
66 0004D424 00f2e45c 00001ba4
67 0004EFC8 f7ff0007 00000100
68 0004F0C8 00e2e45c 00001ba4
69 00050C6C f7ff0007 00000100
70 00050D6C 00d2e45c 00001ba4
71 00052910 f7ff0007 00000100
72 00052A10 00c2e45c 00001ba4
73 000545B4 f7ff0007 00000100
74 000546B4 00a32000 000fe000
75 001526B4 f4d7581b 00000100
76 001527B4 0069e8ac 00001754
77 00153F08 f7ff0009 00000100
78 00154008 0033a04c 00005fb4
79 00159FBC f7ff0009 00000100
Total memory: 14eb24
Stream 5: type MiscInfoStream (15), size 00000018, RVA 0015A0BC
Stream 6: type ExceptionStream (6), size 000000A8, RVA 0015A0D4
ThreadID 94
ExceptionCode C0000005
ExceptionRecord 0
ExceptionAddress f4d7589b
Context record RVA 15a17c, size 2cc
Stream 7: type ??? (1197932545), size 0000000C, RVA 0015A448
Dir entry 7, ??? stream has unknown stream type 1197932545
Hide DivStrings
GenuineIntel
wine-2.6
4.18.0-3-amd64
Service Pack 1(
C:\tq\bin\exefile.exe
C:\windows\system32\ntdll.dll
C:\windows\system32\KERNEL32.dll
C:\tq\bin\blue.dll
C:\windows\system32\crypt32.dll
C:\windows\system32\user32.dll
C:\windows\system32\gdi32.dll
C:\windows\system32\advapi32.dll
C:\windows\system32\version.dll
C:\windows\system32\iphlpapi.dll
C:\windows\system32\ws2_32.dll
C:\windows\system32\wldap32.dll
C:\windows\system32\msvcp100.dll
C:\windows\system32\msvcr100.dll
C:\tq\bin\python27.dll
C:\windows\system32\shell32.dll
C:\windows\system32\shlwapi.dll
C:\windows\system32\winhttp.dll
C:\windows\system32\jsproxy.dll
C:\windows\system32\oleaut32.dll
C:\windows\system32\ole32.dll
C:\windows\system32\rpcrt4.dll
C:\windows\system32\wininet.dll
C:\windows\system32\mpr.dll
C:\windows\system32\imm32.dll
C:\windows\system32\dbghelp.dll
C:\windows\system32\rsaenh.dll
C:\windows\system32\wtsapi32.dll
C:\windows\system32\psapi.dll
C:\tq\bin\_yaml.pyd
C:\tq\bin\_ctypes.pyd
C:\tq\bin\_ssl.pyd
C:\tq\bin\d3dinfo.pyd
C:\windows\system32\opengl32.dll
C:\windows\system32\winex11.drv
C:\windows\system32\dxgi.dll
C:\windows\system32\wined3d.dll
C:\windows\system32\d3d11.dll
C:\tq\bin\_trinity_dx9_deploy.dll
C:\tq\bin\cairo-script.dll
C:\tq\bin\cairo.dll
C:\windows\system32\msimg32.dll
C:\windows\system32\d3d9.dll
C:\tq\bin\tbb.dll
C:\tq\bin\_evelocalization.dll
C:\windows\system32\usp10.dll
C:\tq\bin\geo2.dll
C:\tq\bin\pyFSD.dll
C:\tq\bin\character_colorLocationsLoader.pyd
C:\tq\bin\character_colorNamesLoader.pyd
C:\tq\bin\character_modifierLocationsLoader.pyd
C:\tq\bin\character_resourcesLoader.pyd
C:\tq\bin\character_sculptingLocationsLoader.pyd
C:\tq\bin\pyexpat.pyd
C:\tq\bin\graphicIDsLoader.pyd
C:\tq\bin\graphicMaterialSetsLoader.pyd
C:\tq\bin\_destiny.dll
C:\tq\bin\spacemouse.pyd
C:\tq\bin\_audio2.dll
C:\windows\system32\setupapi.dll
C:\tq\bin\explosionBucketIDsLoader.pyd
C:\tq\bin\explosionIDsLoader.pyd
C:\tq\bin\soundIDsLoader.pyd
C:\tq\bin\_videoplayer.dll
C:\windows\system32\winmm.dll
C:\windows\system32\msacm32.dll
C:\tq\bin\unicodedata.pyd
C:\tq\bin\graphicLocationsLoader.pyd
C:\tq\bin\iconIDsLoader.pyd
C:\tq\bin\activityNodesLoader.pyd
C:\tq\bin\pychartdir27.pyd
C:\tq\bin\chartdir.dll
C:\tq\bin\dynamicItemAttributesLoader.pyd
C:\tq\bin\pyEvePathfinder.dll
C:\tq\bin\_PlanetResources.dll
C:\tq\bin\groupGraphicsLoader.pyd
C:\tq\bin\effectSequencesLoader.pyd
C:\tq\bin\effectsLoader.pyd
C:\tq\bin\newFeaturesLoader.pyd
C:\tq\bin\loginRewardsLoader.pyd
C:\windows\system32\mmdevapi.dll
C:\windows\system32\winepulse.drv
C:\windows\system32\xaudio2_7.dll
Software\Wine\Drivers\winepulse.drv
L"{%08X-%04X-%04X-%02X%02X-%02X%02X%02X%02X%02X%02X},%d"
L"{A45C254E-DF1C-4EFD-8020-67D146A850E0},14"
e\.eve
Files\
Z:\home\alice\.eve\ResFiles\91\910c629bce5
Z:\home\alice\.eve\ResFiles\91\910c629bce572150_baefcdeaff8bfc70d9e4c43dc7e9f00a
..ANETRESOURCES.PICKLE
w7\9h/
ktkwh1.zaq.ne.jp
MSVCP120.DLLRT-MATH-L1-1-0.DLLLL
API-~BXW.DLL
kernel32.dllore-shlwapi-legacy-l1-1-0.dll1-0.dlldllacy-l1-1-0
ourcC:\windows\system32\xaudio2_7.dll
C:\win
C:\win
GenuineIntel
Service Pack 1
L"wine"
L"wine"
WeakRefSite/mRefs
WeakRefSite/mRefs
WeakRefSite/mRef8
WeakRefS<*1
WeakRefSite/mRef
WeakRefS<*1
3res:/dx9/model/spaceobjectfactory/data.red
C:\tq\bin\_yaml.pyd
er.dll
oy.dll
C:\tq\code.ccp
JC:\tq\code.ccp
ode.ccp
{BLUE.DLL
3blue.dll
3CHAR~SGS.PYD
er_res
3CARBON
10323f5c
etRefCounts
StacklessMain
C:\users\alice\Local Settings\Application Data\CCP\EVE\crash_history.crs