*******************************************************************************
* *
* Exception Analysis *
* *
*******************************************************************************
KEY_VALUES_STRING: 1
Key : AV.Dereference
Value: NullPtr
Key : AV.Fault
Value: Write
Key : Analysis.CPU.mSec
Value: 468
Key : Analysis.DebugAnalysisManager
Value: Create
Key : Analysis.Elapsed.mSec
Value: 174543
Key : Analysis.IO.Other.Mb
Value: 86
Key : Analysis.IO.Read.Mb
Value: 0
Key : Analysis.IO.Write.Mb
Value: 108
Key : Analysis.Init.CPU.mSec
Value: 202
Key : Analysis.Init.Elapsed.mSec
Value: 58008
Key : Analysis.Memory.CommitPeak.Mb
Value: 93
Key : Timeline.Process.Start.DeltaSec
Value: 1
Key : WER.OS.Branch
Value: 19h1_release
Key : WER.OS.Timestamp
Value: 2019-03-18T12:02:00Z
Key : WER.OS.Version
Value: 10.0.18362.1
Key : WER.Process.Version
Value: 3.5.5.46514
FILE_IN_CAB: 46514-utorrent.412d.dmp
CHKIMG_EXTENSION: !chkimg -lo 50 -d !shell32
76b91130-76b91162 51 bytes - shell32!DesktopData::GetDesktopKey+128
[ ff 7f 03 c2 2b d9 85 c0:16 b5 c2 2d fb 73 d8 01 ]
76b91164-76b911c6 99 bytes - shell32!DesktopData::GetDesktopKey+15c (+0x34)
[ 56 ff 15 38 ef f6 76 8b:4f 00 4f 00 4b 25 56 00 ]
76b911c8-76b911ff 56 bytes - shell32!wil::make_unique_string_nothrow<wil::unique_any_t<wil::details::unique_storage<wil::details::resource_policy<unsigned short *,void (__stdcall*)(void *),&CoTaskMemFree,wistd::integral_constant<unsigned int,0>,unsigned short *,unsigned short *,0,std::nu+28 (+0x64)
[ 00 00 b8 ff ff ff 7f 8b:09 03 63 00 72 00 61 00 ]
206 errors : !shell32 (76b91130-76b911ff)
CONTEXT: (.ecxr)
eax=00000000 ebx=0019df78 ecx=0019df1e edx=01d873fa esi=00000002 edi=0019df44
eip=76b911b0 esp=0019def8 ebp=0019df20 iopl=0 nv up ei pl nz na pe nc
cs=0023 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00210206
shell32!wil::make_unique_string_nothrow<wil::unique_any_t<wil::details::unique_storage<wil::details::resource_policy<unsigned short *,void (__stdcall*)(void *),&CoTaskMemFree,wistd::integral_constant<unsigned int,0>,unsigned short *,unsigned short *,0,std::nullptr_t> > > >+0x10:
76b911b0 0000 add byte ptr [eax],al ds:002b:00000000=??
Resetting default scope
EXCEPTION_RECORD: (.exr -1)
ExceptionAddress: 76b911b0 (shell32!wil::make_unique_string_nothrow<wil::unique_any_t<wil::details::unique_storage<wil::details::resource_policy<unsigned short *,void (__stdcall*)(void *),&CoTaskMemFree,wistd::integral_constant<unsigned int,0>,unsigned short *,unsigned short *,0,std::nullptr_t> > > >+0x00000010)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 00000001
Parameter[1]: 00000000
Attempt to write to address 00000000
PROCESS_NAME: uTorrent.exe
WRITE_ADDRESS: 00000000
ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at 0x%p referenced memory at 0x%p. The memory could not be %s.
EXCEPTION_CODE_STR: c0000005
EXCEPTION_PARAMETER1: 00000001
EXCEPTION_PARAMETER2: 00000000
ADDITIONAL_DEBUG_TEXT: Followup set based on attribute [Is_ChosenCrashFollowupThread] from Frame:[0] on thread:[PSEUDO_THREAD]
STACK_TEXT:
00000000 00000000 memory_corruption!shell32.dll+0x0
STACK_COMMAND: ** Pseudo Context ** ManagedPseudo ** Value: ffffffff ** ; kb
SYMBOL_NAME: memory_corruption!shell32.dll
FAILURE_BUCKET_ID: MEMORY_CORRUPTION_LARGE_c0000005_memory_corruption!shell32.dll
IMAGE_NAME: memory_corruption
MODULE_NAME: memory_corruption
OS_VERSION: 10.0.18362.1
BUILDLAB_STR: 19h1_release
OSPLATFORM_TYPE: x86
OSNAME: Windows 10
FAILURE_ID_HASH: {34b582c5-5aa9-5a11-9ed5-09cf2fbf67cf}
Followup: MachineOwner
---------
start end module name
00400000 0098d000 uTorrent T (no symbols)
65780000 659a9000 iertutil (deferred)
6d3a0000 6d52f000 dbghelp (deferred)
6e570000 6e594000 dbgcore (deferred)
73970000 739c2000 mswsock (deferred)
73ae0000 73b5a000 uxtheme (deferred)
73dc0000 73f29000 GdiPlus (deferred)
74850000 74a5f000 comctl32 # (pdb symbols) C:\ProgramData\Dbg\sym\comctl32.pdb\FC5FD36F9E4EE3C7346B0FC4344CA7551\comctl32.pdb
74e70000 750e5000 combase (private pdb symbols) C:\ProgramData\Dbg\sym\combase.pdb\ECACEC75D7FEBDFC07DFB214B29F36301\combase.pdb
75210000 753a7000 user32 # (pdb symbols) C:\ProgramData\Dbg\sym\wuser32.pdb\7FD29B06E1D24D80F6006F31570416C91\wuser32.pdb
75480000 75504000 SHCore (deferred)
75690000 756ef000 bcryptPrimitives (deferred)
75a90000 75bea000 gdi32full (deferred)
76040000 76061000 gdi32 (deferred)
761d0000 762b0000 kernel32 (deferred)
76490000 764a7000 win32u (deferred)
76680000 7687e000 KERNELBASE (pdb symbols) C:\ProgramData\Dbg\sym\wkernelbase.pdb\16D31E44984F0A04A379FD85FE74B7311\wkernelbase.pdb
76990000 76a4b000 rpcrt4 (deferred)
76a50000 76fca000 shell32 (pdb symbols) C:\ProgramData\Dbg\sym\shell32.pdb\EF1CAFADB47FA5E3434C96F414628B971\shell32.pdb
77040000 77605000 windows_storage (deferred)
77620000 777ba000 ntdll (pdb symbols) C:\ProgramData\Dbg\sym\wntdll.pdb\C426B34E4A17C490B9C8608C500F9F8A1\wntdll.pdb
# ChildEBP RetAddr Args to Child
00 0019c5ac 00000000 0000003e 0019c850 00000000 ntdll!NtGetContextThread+0xc (FPO: [2,0,0])