*----> 线程 ID 0xdd8 的状态转储 <----*
eax=000000e6 ebx=7c9210ed ecx=00000001 edx=000000fb esi=000001bc edi=00000000
eip=7c92eb94 esp=0256ff20 ebp=0256ff84 iopl=0 nv up ei pl zr na po nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
函数: ntdll!KiFastSystemCallRet
7c92eb89 90 nop
7c92eb8a 90 nop
ntdll!KiFastSystemCall:
7c92eb8b 8bd4 mov edx,esp
7c92eb8d 0f34 sysenter
7c92eb8f 90 nop
7c92eb90 90 nop
7c92eb91 90 nop
7c92eb92 90 nop
7c92eb93 90 nop
ntdll!KiFastSystemCallRet:
7c92eb94 c3 ret
7c92eb95 8da42400000000 lea esp,[esp]
7c92eb9c 8d642400 lea esp,[esp]
7c92eba0 90 nop
7c92eba1 90 nop
7c92eba2 90 nop
7c92eba3 90 nop
7c92eba4 90 nop
ntdll!KiIntSystemCall:
7c92eba5 8d542408 lea edx,[esp+0x8]
7c92eba9 cd2e int 2e
*----> 堆栈反向跟踪 <---*
WARNING: Stack unwind information not available. Following frames may be wrong.
ChildEBP RetAddr Args to Child
0256ff84 7c802542 000001bc ffffffff 00000000 ntdll!KiFastSystemCallRet
0256ff98 72c945e9 000001bc ffffffff 7c930738 kernel32!WaitForSingle
Object+0x12
0256ffb4 7c80b50b 000001bc 7c930738 ffffffff wdmaud!mxdMessage+0x129c
0256ffec 00000000 72c9457b 0014b938 00000000 kernel32!GetModuleFileNameA+0x1b4
*----> 原始堆栈转储 <----*
000000000256ff20 c0 e9 92 7c db 25 80 7c - bc 01 00 00 00 00 00 00 ...|.%.|........
000000000256ff30 00 00 00 00 05 10 92 7c - 38 b9 14 00 ed 10 92 7c .......|8......|
000000000256ff40 14 00 00 00 01 00 00 00 - 00 00 00 00 00 00 00 00 ................
000000000256ff50 10 00 00 00 ed 10 92 7c - 00 00 17 00 00 40 fd 7f .......|.....@..
000000000256ff60 00 c0 fd 7f 00 00 00 00 - dc ff 56 02 34 ff 56 02 ..........V.4.V.
000000000256ff70 90 9f 80 7c dc ff 56 02 - f3 99 83 7c 08 26 80 7c ...|..V....|.&.|
000000000256ff80 00 00 00 00 98 ff 56 02 - 42 25 80 7c bc 01 00 00 ......V.B%.|....
000000000256ff90 ff ff ff ff 00 00 00 00 - b4 ff 56 02 e9 45 c9 72 ..........V..E.r
000000000256ffa0 bc 01 00 00 ff ff ff ff - 38 07 93 7c ff ff ff ff ........8..|....
000000000256ffb0 38 b9 14 00 ec ff 56 02 - 0b b5 80 7c bc 01 00 00 8.....V....|....
000000000256ffc0 38 07 93 7c ff ff ff ff - 38 b9 14 00 00 c0 fd 7f 8..|....8.......
000000000256ffd0 00 66 f3 80 c0 ff 56 02 - 88 6b 61 ff ff ff ff ff .f....V..ka.....
000000000256ffe0 f3 99 83 7c 18 b5 80 7c - 00 00 00 00 00 00 00 00 ...|...|........
000000000256fff0 00 00 00 00 7b 45 c9 72 - 38 b9 14 00 00 00 00 00 ....{E.r8.......
0000000002570000 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000002570010 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000002570020 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000002570030 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000002570040 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0000000002570050 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
然后我打开WINDOWS里的系统信息,图在这: